SIGN IN SIGN UP

Accept CRLs whose IDP names the issuer of a certificate without CDP

When a certificate has no CRL distribution points extension (or none of
its distribution points matches the CRL), crl_crldp_check() accepted a
CRL issued by the certificate issuer only if the CRL had no issuing
distribution point extension or the IDP carried no distribution point
name.  A CRL whose IDP names the certificate issuer was rejected with
X509_V_ERR_DIFFERENT_CRL_SCOPE.

RFC 5280, section 6.3.3, last paragraph, requires the opposite:

   If the revocation status has not been determined, repeat the process
   above with any available CRLs not specified in a distribution point
   but issued by the certificate issuer.  For the processing of such a
   CRL, assume a DP with both the reasons and the cRLIssuer fields
   omitted and a distribution point name of the certificate issuer.
   That is, the sequence of names in fullName is generated from the
   certificate issuer field as well as the certificate issuerAltName
   extension.

Step (b)(2)(i) of the same section then requires that "one of the names
in the IDP matches one of the names in the DP", i.e. the IDP is in scope
if one of its names is the certificate issuer name or one of the names
in the certificate's issuerAltName extension.

Implement that check in a new idp_check_issuer() and use it in the
fallback at the end of crl_crldp_check().  An IDP that only carries a
URI, or a nameRelativeToCRLIssuer, does not match the certificate issuer
and is still rejected as out of scope, as before.

Extend make_empty_crl() in test/recipes/25-test_verify.t to accept CRL
extensions and add two cases: a CRL whose IDP fullName is the CA's
directoryName is accepted for a certificate without CDP, and one whose
IDP fullName is only a URI is still rejected with "different CRL scope".

Fixes #23325

Assisted-by: Claude:claude-fable-5
Reviewed-by: Jakub Zelenka <jakub.zelenka@openssl.foundation>
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com>
Merge-date: Mon Sep  7 18:38:10 2026
Merged-from: https://github.com/openssl/openssl/pull/32553
P
Paul Grubbs committed
97fd91933df73cfdc73b53832a41b8b9d0d9cefd
Parent: 1802f56
Committed by Tomas Mraz <tomas@openssl.foundation> on 9/7/2026, 6:38:09 PM