Accept CRLs whose IDP names the issuer of a certificate without CDP
When a certificate has no CRL distribution points extension (or none of its distribution points matches the CRL), crl_crldp_check() accepted a CRL issued by the certificate issuer only if the CRL had no issuing distribution point extension or the IDP carried no distribution point name. A CRL whose IDP names the certificate issuer was rejected with X509_V_ERR_DIFFERENT_CRL_SCOPE. RFC 5280, section 6.3.3, last paragraph, requires the opposite: If the revocation status has not been determined, repeat the process above with any available CRLs not specified in a distribution point but issued by the certificate issuer. For the processing of such a CRL, assume a DP with both the reasons and the cRLIssuer fields omitted and a distribution point name of the certificate issuer. That is, the sequence of names in fullName is generated from the certificate issuer field as well as the certificate issuerAltName extension. Step (b)(2)(i) of the same section then requires that "one of the names in the IDP matches one of the names in the DP", i.e. the IDP is in scope if one of its names is the certificate issuer name or one of the names in the certificate's issuerAltName extension. Implement that check in a new idp_check_issuer() and use it in the fallback at the end of crl_crldp_check(). An IDP that only carries a URI, or a nameRelativeToCRLIssuer, does not match the certificate issuer and is still rejected as out of scope, as before. Extend make_empty_crl() in test/recipes/25-test_verify.t to accept CRL extensions and add two cases: a CRL whose IDP fullName is the CA's directoryName is accepted for a certificate without CDP, and one whose IDP fullName is only a URI is still rejected with "different CRL scope". Fixes #23325 Assisted-by: Claude:claude-fable-5 Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation> Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com> Merge-date: Mon Sep 7 18:38:10 2026 Merged-from: https://github.com/openssl/openssl/pull/32553
P
Paul Grubbs committed
97fd91933df73cfdc73b53832a41b8b9d0d9cefd
Parent: 1802f56
Committed by Tomas Mraz <tomas@openssl.foundation>
on 9/7/2026, 6:38:09 PM