Skip to content

feat: check leaf revocation from CRL files - #545

Open
robjtede wants to merge 1 commit into
t3code/validate-certificate-chainsfrom
validate-crl-files
Open

robjtede wants to merge 1 commit into
t3code/validate-certificate-chainsfrom
validate-crl-files

Conversation

@robjtede

@robjtede robjtede commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

Add repeatable --crl-file inputs for local and remote validation. Accept DER CRLs and PEM bundles, verify issuer, scope, signatures, signing usage, and update dates, and select the newest authoritative CRL.

Report revoked certificates as INVALID and unverified revocation data as UNKNOWN. Preserve certificate inspection and PEM dumps. Without supplied CRLs, revocation remains not checked.

This is layer 3 of 4. CRL downloads follow separately. Tests cover signed, tampered, expired, future, unrelated, and scoped CRLs, bundle ordering, JSON, and supplied CRLs during remote inspection.

Validation on macOS: just test (83 passed) and nix develop -c just check (formatting and Clippy passed).

@robjtede
robjtede added this pull request to stack #547 October 8, 2026 04:55
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 59 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 8b154276-f78a-4d9f-9766-790d8b3b99ea
📥 Commits

Reviewing files that changed from the base of the PR and between 64597d9 and 9897353.

📒 Files selected for processing (7)
  • CHANGELOG.md
  • README.md
  • src/fetch.rs
  • src/main.rs
  • src/revocation.rs
  • src/validation.rs
  • tests/validation.rs
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@robjtede

robjtede commented Oct 8, 2026

Copy link
Copy Markdown
Member Author

Reproducible example for 9897353, using the real revoked certificate from revoked.badssl.com and its issuer's CRL. Captured on macOS on 2026-10-08.

Build this PR:

gh pr checkout 545
cargo build --locked
ICC="$PWD/target/debug/inspect-cert-chain"

Save the public chain with curl. These commands were run with curl 8.7.1; use a build that supports %{certs}:

curl --fail --silent --show-error --max-time 30 \
  --output /dev/null --write-out '%{certs}' https://revoked.badssl.com \
  | sed -n '/-----BEGIN CERTIFICATE-----/,/-----END CERTIFICATE-----/p' \
  > revoked-chain.pem

Check the chain without a CRL:

"$ICC" --file revoked-chain.pem --check \
  --hostname revoked.badssl.com --fields subject

Validation excerpt from the captured output:

Certificate chain: VALID
Path validation: VALID
Hostname (revoked.badssl.com): VALID
Certificate 1 dates: VALID
Certificate 2 dates: VALID
Certificate 3 dates: VALID
Certificate 4 dates: VALID
Revocation (leaf): NOT CHECKED

Read the CRL URL from the leaf certificate and download it:

crl_url=$(openssl x509 -in revoked-chain.pem -noout -ext crlDistributionPoints \
  | sed -n 's/^[[:space:]]*URI://p' | head -n 1)
printf '%s\n' "$crl_url"
curl --fail --location --max-time 30 "$crl_url" --output issuer.crl

The URL in this capture was http://ye2.c.lencr.org/74.crl. Extract it again when reproducing; the certificate and URL can change.

Supply the downloaded CRL:

"$ICC" --file revoked-chain.pem --check \
  --hostname revoked.badssl.com --fields subject --crl-file issuer.crl
Certificate chain: INVALID
Path validation: VALID
Hostname (revoked.badssl.com): VALID
Certificate 1 dates: VALID
Certificate 2 dates: VALID
Certificate 3 dates: VALID
Certificate 4 dates: VALID
Revocation (leaf): INVALID (certificate revoked)

Both inspections returned exit code 0. The path and dates are valid; the signed CRL supplies the revocation result. The existing --check exit code remains date-based. This layer does not download CRLs itself.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant