crypto/x509
panic during tls handshake from http clientWaitingForInfo
#70374 opened 5 days ago by fishy
parser should error on Subject Information Access and Policy Constraints being makred as criticalNeedsInvestigation
#70278 opened 1 week ago by dulanshuangqiao
malformed signature algorithm identifier error while version and serialNumber swappedNeedsInvestigation
#70269 opened 1 week ago by dulanshuangqiao
ParseCertificate fails with "net/url: invalid userinfo"NeedsInvestigation
#69930 opened 1 month ago by dulanshuangqiao
no support for BitStringNeedsInvestigation
#69463 opened 2 months ago by TxI5
unrecognized failuresNeedsInvestigation
#68803 opened 3 months ago by gopherbot
Get "https://google.com": tls: failed to verify certificate: SecPolicyCreateSSL error: 0 when running in child after parent exitsNeedsInvestigationOS-Darwin
#68557 opened 4 months ago by NorseGaud
#68484 opened 4 months ago by satsrini
TestPlatformVerifierLegacy/expired_leaf failuresNeedsInvestigation
#67994 opened 5 months ago by gopherbot
TestPlatformVerifierLegacy/wrong_host_for_leaf failuresNeedsInvestigation
#67993 opened 5 months ago by gopherbot
TestPlatformVerifierLegacy/self-signed_leaf failuresNeedsInvestigation
#67992 opened 5 months ago by gopherbot
#67675 opened 5 months ago by rolandshoemaker
#67620 opened 6 months ago by mateusz834
#67338 opened 6 months ago by MadsRC
#66167 opened 8 months ago by rolandshoemaker
check Certificate.isValid on CertPool.AddNeedsInvestigation
#66166 opened 8 months ago by rolandshoemaker
#65626 opened 9 months ago by gopherbot
#65085 opened 10 months ago by woodruffw
relax boringcrypto certificate key size restrictions given the ongoing FIPS 140-3 validationNeedsInvestigation
#65042 opened 10 months ago by HakanSunay
Allow to pass flags to syscall.CertGetCertificateChain, when using TLS Transport under WindowsNeedsInvestigationOS-WindowsProposalProposal-Crypto
#63238 opened 1 year ago by jkroepke
TestPlatformVerifierLegacy failuresNeedsInvestigation
#62912 opened 1 year ago by gopherbot
AKI (Authority Key Id) exclusion logic is brokenNeedsInvestigation
#62060 opened 1 year ago by furkanmustafa
#62048 opened 1 year ago by rsc
#61576 opened 1 year ago by rolandshoemaker
RevocationList.CheckSignatureFrom doesn't check SubjectNeedsInvestigation
#60728 opened 1 year ago by thierry-f-78
#60718 opened 1 year ago by dachaac
go mod tidy reports certificate expired on a non-expired certificateNeedsInvestigation
#60653 opened 1 year ago by ysmilda
CreateRevocationList over-enforces KeyUsage checkNeedsInvestigation
#59669 opened 2 years ago by cipherboy
ParseCertificate should mention the ownership of the slice passed to it.DocumentationNeedsInvestigation
#59548 opened 2 years ago by mateusz834
Certificate.Verify rejects self-signed leafNeedsInvestigation
#58792 opened 2 years ago by rittneje
Certificate.Verify does not consistently return UnknownAuthorityErrorNeedsInvestigation
#58777 opened 2 years ago by rittneje
#58635 opened 2 years ago by FiloSottile
#58251 opened 2 years ago by rolandshoemaker
#57428 opened 2 years ago by dmitshur
#56866 opened 2 years ago by izolight
HTTP POST to Italian government web service fails with "x509: unhandled critical extension" error on Linux hostNeedsInvestigation
#55872 opened 2 years ago by genesio-systemlogic
Verification of ECDSA signed x509 cert, sanitized to LowS certs fails verification with go 1.19NeedsInvestigation
#54549 opened 2 years ago by C0rWin
#53841 opened 2 years ago by hherman1
pkix.Name.String() does not preserve correct order NeedsInvestigation
#52462 opened 2 years ago by bjanders
#52108 opened 2 years ago by rolandshoemaker
#51991 opened 2 years ago by dims
#51953 opened 2 years ago by haydentherapper
malformed x509 certificate is accepted since 1.17NeedsDecision
#51369 opened 2 years ago by bitmingw
#49519 opened 3 years ago by defacto64
unable to parse Attribute CertificateNeedsInvestigation
#49270 opened 3 years ago by salrashid123
invalid RDNSequence: invalid attribute value: unsupported string type: 4NeedsInvestigation
#48371 opened 3 years ago by c00w
unable to parse certificate with rsassa-pss algorithmNeedsInvestigation
#48314 opened 3 years ago by jpduckwo
inner and outer signature algorithm identifiers don't matchNeedsInvestigation
#47689 opened 3 years ago by groob
support OIDs for tcg-kp (2.23.133.8)NeedsInvestigation
#47620 opened 3 years ago by tracefinder
#45857 opened 3 years ago by FiloSottile
store stripped down trust anchorsNeedsInvestigation
#44298 opened 3 years ago by rolandshoemaker
#43780 opened 3 years ago by joeshaw
ParseCertificate and ParseCertificates return different errors with a single bad certificate suppliedNeedsInvestigation
#43113 opened 4 years ago by LujunWeng
#41888 opened 4 years ago by dtoubelis
check the Key Usage extensionNeedsFix
#40100 opened 4 years ago by FiloSottile
#40017 opened 4 years ago by FiloSottile
#39540 opened 4 years ago by stephen-fox
#39179 opened 4 years ago by stephen-fox
stop looking at first root storeNeedsFix
#38869 opened 4 years ago by FiloSottile
failed to parse Intermediate CA certificateNeedsInvestigation
#38737 opened 4 years ago by sebastien-rosset
support policyQualifiers in certificatePolicies extensionNeedsInvestigation
#38116 opened 4 years ago by rolandshoemaker
#37176 opened 4 years ago by ihgann
#35887 opened 5 years ago by wking
#34977 opened 5 years ago by SeanBurford
unable to parse certificate parsable by JavaNeedsDecision
#33259 opened 5 years ago by tomjamescn
#32874 opened 5 years ago by trung
#31440 opened 5 years ago by sneis
ObjectIdentifier and ParseCertificate do not support int > 31 bits, preventing support of OID 2.25 (/UUID) (follow-up on #19933)NeedsInvestigation
#30757 opened 5 years ago by vpelletier
#30416 opened 5 years ago by DenisKarch
DN OU orderingNeedsInvestigation
#29040 opened 6 years ago by rikkuness
verify checks root certificateNeedsInvestigation
#28971 opened 6 years ago by vit3k
#26731 opened 6 years ago by bradfitz
#24156 opened 6 years ago by FiloSottile
#21789 opened 7 years ago by SamWhited
AKI is left blank even for non-self-signed cert when subject matches CA's subject fieldNeedsInvestigation
#20002 opened 7 years ago by mikesmitty
CertificateRequest does not support attributes not covered by pkix.AttributeTypeAndValueSETNeedsInvestigation
#15995 opened 8 years ago by groob
#15196 opened 8 years ago by vanbroup
no support for parsing encrypted PKCS8 private keysFeatureRequest
#8860 opened 10 years ago by gopherbot
#7735 opened 10 years ago by agl