Uploaded image for project: 'WildFly Core'
  1. WildFly Core
  2. WFCORE-5587

maximum-cert-path does not work with empty certificate-revocation-list in Elytron trust-manager

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 17.0.0.Final
    • 17.0.0.Beta7
    • Security
    • None

      CRL can be configured by distribution point extension in certificates. To allow such case we have to set empty certificate-revocation-lists, which works as expected. However, in case we set empty certificate-revocation-list (the attribute from the initial implementation, also valid configuration), maximum-cert-path is not taken into account, no warning for a user. Also setting just certificate-revocation-list.maximum-cert-path cannot be used and results in NullPointerException.

      The issue was probably introduced with the certificate-revocation-lists feature.

            rhn-support-rmartinc Ricardo Martin Camarero
            okotek@redhat.com Ondrej Kotek
            Votes:
            0 Vote for this issue
            Watchers:
            3 Start watching this issue

              Created:
              Updated:
              Resolved: