Skip to content

feat: download leaf CRLs during remote validation - #546

Open
robjtede wants to merge 1 commit into
validate-crl-filesfrom
download-leaf-crls
Open

robjtede wants to merge 1 commit into
validate-crl-filesfrom
download-leaf-crls

Conversation

@robjtede

@robjtede robjtede commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

When no CRL file is supplied, download leaf CRLs from HTTP or HTTPS distribution points. Use the configured system and custom roots for HTTPS.

Limit retrieval to eight URLs, 10 MiB per response, and five seconds within the fetch deadline. Report unavailable or unverified revocation data as UNKNOWN while preserving inspection and --dump. Local checks remain offline, and supplied CRL files take precedence.

This is layer 4 of 4. Includes local HTTP tests for revoked certificates, invalid signatures, unavailable services, and delayed responses, plus the live revoked BadSSL check.

Validation on macOS: just test (85 passed), nix develop -c just check (formatting and Clippy passed), and just test-badssl (7 passed).

@robjtede
robjtede added this pull request to stack #547 October 8, 2026 04:55
@coderabbitai

coderabbitai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 59 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 9f6628aa-8239-437f-b5ae-1c4f9039ea80
📥 Commits

Reviewing files that changed from the base of the PR and between 9897353 and 5252a8b.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (8)
  • CHANGELOG.md
  • Cargo.toml
  • README.md
  • src/fetch.rs
  • src/revocation.rs
  • src/validation.rs
  • tests/badssl.rs
  • tests/validation.rs
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@robjtede

robjtede commented Oct 8, 2026

Copy link
Copy Markdown
Member Author

Reproducible real-site examples for automatic CRL retrieval at 5252a8b. No --crl-file or manual CRL download is needed.

The key output lines below were verified by this commit's seven passing live BadSSL checks when the stack was split. Fresh manual captures on 2026-10-08 encountered TLS connection resets/timeouts from this environment, so these are tested expected excerpts, not a fresh stdout capture.

Build this PR:

gh pr checkout 546
cargo build --locked
ICC="$PWD/target/debug/inspect-cert-chain"

A revoked leaf:

"$ICC" --host revoked.badssl.com --timeout 30s --fields subject
Certificate chain: INVALID
Path validation: VALID
Hostname (revoked.badssl.com): VALID
Revocation (leaf): INVALID (certificate revoked)

A valid control:

"$ICC" --host sha256.badssl.com --timeout 30s --fields subject
Certificate chain: VALID
Path validation: VALID
Revocation (leaf): VALID

The live checks verified exit code 0 for both inspections. Compared with #531, the revoked site is now identified automatically: its path is valid, but its issuer's signed CRL marks the leaf as revoked.

CRL retrieval uses up to five seconds within the fetch deadline. If the CRL service is unavailable or its data cannot be verified, revocation reports UNKNOWN and inspection continues. A failure to fetch the TLS chain itself remains a nonzero fetch error.

To repeat all seven live assertions:

just test-badssl

The excerpts omit other certificate and validation lines. Public certificates and CRLs change over time, and the valid result depends on the CRL service being reachable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant