Repository navigation
Conversation
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 59 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (7)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Reproducible example for Build this PR: gh pr checkout 545
cargo build --locked
ICC="$PWD/target/debug/inspect-cert-chain"Save the public chain with curl. These commands were run with curl 8.7.1; use a build that supports curl --fail --silent --show-error --max-time 30 \
--output /dev/null --write-out '%{certs}' https://revoked.badssl.com \
| sed -n '/-----BEGIN CERTIFICATE-----/,/-----END CERTIFICATE-----/p' \
> revoked-chain.pemCheck the chain without a CRL: "$ICC" --file revoked-chain.pem --check \
--hostname revoked.badssl.com --fields subjectValidation excerpt from the captured output: Read the CRL URL from the leaf certificate and download it: crl_url=$(openssl x509 -in revoked-chain.pem -noout -ext crlDistributionPoints \
| sed -n 's/^[[:space:]]*URI://p' | head -n 1)
printf '%s\n' "$crl_url"
curl --fail --location --max-time 30 "$crl_url" --output issuer.crlThe URL in this capture was Supply the downloaded CRL: "$ICC" --file revoked-chain.pem --check \
--hostname revoked.badssl.com --fields subject --crl-file issuer.crlBoth inspections returned exit code |
Add repeatable
--crl-fileinputs for local and remote validation. Accept DER CRLs and PEM bundles, verify issuer, scope, signatures, signing usage, and update dates, and select the newest authoritative CRL.Report revoked certificates as INVALID and unverified revocation data as UNKNOWN. Preserve certificate inspection and PEM dumps. Without supplied CRLs, revocation remains not checked.
This is layer 3 of 4. CRL downloads follow separately. Tests cover signed, tampered, expired, future, unrelated, and scoped CRLs, bundle ordering, JSON, and supplied CRLs during remote inspection.
Validation on macOS:
just test(83 passed) andnix develop -c just check(formatting and Clippy passed).