REDHAT-BUG-2456335
When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2456335?
The severity of REDHAT-BUG-2456335 is considered moderate due to the impact on certificate validation processes.
How do I fix REDHAT-BUG-2456335?
To fix REDHAT-BUG-2456335, ensure you update the Go crypto/x509 library to the latest version that addresses this issue.
Who is affected by REDHAT-BUG-2456335?
Users and organizations utilizing the Go crypto/x509 library for certificate validation are affected by REDHAT-BUG-2456335.
What are the implications of REDHAT-BUG-2456335?
The implications of REDHAT-BUG-2456335 include potential failures in validating wildcard DNS certificates, which may bypass security constraints.
When was REDHAT-BUG-2456335 reported?
REDHAT-BUG-2456335 was reported in the Red Hat bug tracking system and is documented for remediation.