crypto/x509
#70477 opened 17 hours ago by rossigee
#70324 opened 1 week ago by chris-jansson
#70074 opened 3 weeks ago by dulanshuangqiao
#69023 opened 3 months ago by kindermoumoute
func (*Certificate) CheckSignatureFromWaitingForInfo
#68626 opened 3 months ago by yan-di
wrong value of RevocationList.AuthorityKeyIdNeedsInvestigation
#67571 opened 6 months ago by andrewkostevich
TestPlatformVerifier failures on Windows due to broken connections [1.22 backport]CherryPickApprovedSecurityTesting
#67352 opened 6 months ago by gopherbot
TestPlatformVerifier failures on Windows due to broken connections [1.21 backport]CherryPickApprovedSecurityTesting
#67351 opened 6 months ago by gopherbot
certificate validation issuesWaitingForInfo
#67024 opened 7 months ago by joyantaDebnath
ParseCertificate duplicate extensions errors should include OID of the affected extensionNeedsInvestigation
#66880 opened 7 months ago by Techassi
#66273 opened 8 months ago by gopherbot
#66249 opened 8 months ago by rsc
#65990 opened 8 months ago by fancycode
#65829 opened 9 months ago by staverne
#65633 opened 9 months ago by VictorLowther
TestPlatformVerifier failures on macOS due to mismatched error textNeedsInvestigationOS-DarwinSecurity
#65461 opened 9 months ago by gopherbot
Verify panics on certificates with an unknown public key algorithm [CVE-2024-24783]NeedsFixSecurityrelease-blocker
#65390 opened 9 months ago by neild
TestIssue51759 consistently failing on `gotip-darwin-amd64_10.15` LUCI builder [1.21 backport]CherryPickApprovedTesting
#65380 opened 9 months ago by gopherbot
TestIssue51759 consistently failing on `gotip-darwin-amd64_10.15` LUCI builder [1.20 backport]CherryPickApprovedTesting
#65379 opened 9 months ago by gopherbot
#65074 opened 10 months ago by phlipse
TestIssue51759 consistently failing on `gotip-darwin-amd64_10.15` LUCI builderNeedsFixOS-DarwinSecurityTesting
#64677 opened 11 months ago by bcmills
gate marshaling of Policies on a GODEBUG [freeze exception]NeedsFixProposalProposal-Acceptedrelease-blocker
#64248 opened 1 year ago by mateusz834
#64012 opened 1 year ago by mateusz834
code signing certificates fail to verify in macOS Ventura and later NeedsInvestigationOS-DarwinWaitingForInfo
#63995 opened 1 year ago by sinukus
CreateCertificate will generate duplicate certificate policies if PolicyIdentifiers and Policies and populatedNeedsFixrelease-blocker
#63909 opened 1 year ago by rolandshoemaker
crash and spurious errors in `(*Certificate).Verify` on macOS when argv[0] contains `//../`FrozenDueToAgeNeedsInvestigationOS-DarwinSecurity
#61000 opened 1 year ago by knz
#60947 opened 1 year ago by gopherbot
#60925 opened 1 year ago by heschi
introduce new robust OID type & use it for certificate policiesFrozenDueToAgeProposalProposal-AcceptedProposal-Crypto
#60665 opened 1 year ago by rolandshoemaker
TestPlatformVerifier fails on windows-amd64-longtest-oldcc builder on 1.19 release branch FrozenDueToAgeNeedsFixSecurityTesting
#60118 opened 2 years ago by cherrymui
IsEncryptedPEMBlock, EncryptPEMBlock, and DecryptPEMBlock should not be deprecatedFrozenDueToAgeProposalProposal-Crypto
#59961 opened 2 years ago by bustedware
#59171 opened 2 years ago by rittneje
#58930 opened 2 years ago by gopherbot
add android user trusted CA folder as a possible source for certificate retrievalFrozenDueToAgeOS-AndroidProposalProposal-AcceptedProposal-Crypto
#58922 opened 2 years ago by odeke-em
TestIssue51759 has started to fail on darwin-amd64-10_15FrozenDueToAgeNeedsFixOS-DarwinTestingrelease-blocker
#58812 opened 2 years ago by dmitshur
TestSystemVerify consistently failing [1.20 backport]CherryPickApprovedFrozenDueToAgerelease-blocker
#58811 opened 2 years ago by gopherbot
TestSystemVerify consistently failing [1.19 backport]CherryPickApprovedFrozenDueToAgerelease-blocker
#58810 opened 2 years ago by gopherbot
#58795 opened 2 years ago by gopherbot
Incorrect documentation for `ParsePKCS8PrivateKey` [1.20 backport]CherryPickApprovedDocumentationFrozenDueToAge
#58793 opened 2 years ago by gopherbot
#58791 opened 2 years ago by bcmills
#58789 opened 2 years ago by babolivier
#57635 opened 2 years ago by gopherbot
#57556 opened 2 years ago by FiloSottile
#57461 opened 2 years ago by hujun-open
#57427 opened 2 years ago by rolandshoemaker
#57426 opened 2 years ago by gopherbot
#57178 opened 2 years ago by rolandshoemaker
#56901 opened 2 years ago by cipherboy
#56891 opened 2 years ago by wneessen
#56798 opened 2 years ago by gopherbot
TestPlatformVerifier failures on Windows due to broken connectionsNeedsInvestigationOS-WindowsSecurity
#56791 opened 2 years ago by gopherbot
#56438 opened 2 years ago by gopherbot
#56437 opened 2 years ago by gopherbot
#56436 opened 2 years ago by rsc
#56140 opened 2 years ago by TheJimmyBlaze
#55897 opened 2 years ago by haydentherapper
#54936 opened 2 years ago by robstradling
#54590 opened 2 years ago by radhus
#54295 opened 2 years ago by gopherbot
#54288 opened 2 years ago by FnuGk
Incorrect TBSCertificateList.Issuer field when using non-pkix.Name-encodable Issuer [1.19 backport]CherryPickCandidateFrozenDueToAge
#53944 opened 2 years ago by sgmiller
Incorrect TBSCertificateList.Issuer field when using non-pkix.Name-encodable Issuer [1.18 backport]CherryPickCandidateFrozenDueToAge
#53943 opened 2 years ago by sgmiller
#53755 opened 2 years ago by cipherboy
Incorrect TBSCertificateList.Issuer field when using non-pkix.Name-encodable IssuerFrozenDueToAgeNeedsFix
#53754 opened 2 years ago by cipherboy
ParseRevocationList does not populate Number and AuthorityKeyId fieldsFrozenDueToAgeNeedsFixrelease-blocker
#53726 opened 2 years ago by aarongable
#53592 opened 2 years ago by aarongable
surface ReasonCode inside x509.RevocationList entriesFrozenDueToAgeProposalProposal-AcceptedProposal-CryptoProposal-FinalCommentPeriod
#53573 opened 2 years ago by aarongable
CreateRevocationList() does not enforce that the CRL Number is at most 20 octetsFrozenDueToAgeNeedsInvestigation
#53543 opened 2 years ago by aarongable
Certificate.Verify on darwin no longer returns UnknownAuthorityError when the system verifier is usedFrozenDueToAge
#53401 opened 2 years ago by dnephin
Certificates with an Email ... failed parsing cause of @ versus ASN1 + InsecureSkipVerify never checkFrozenDueToAgeNeedsInvestigation
#52964 opened 2 years ago by OlivierMary
#52955 opened 2 years ago by dchaofei
macOS flakes due to "certificate is not standards compliant"BuildersFrozenDueToAgeNeedsInvestigationOS-Darwinrelease-blocker
#52854 opened 2 years ago by neild
failed to parse X509 certificateFrozenDueToAge
#52742 opened 2 years ago by alxchk
#52659 opened 2 years ago by rolandshoemaker
#52444 opened 2 years ago by rolandshoemaker
#52370 opened 2 years ago by dims
#52319 opened 2 years ago by rolandshoemaker
#52112 opened 2 years ago by tmm1
#52094 opened 2 years ago by heschi
go1.18 stops returning typed errors when using system roots on darwinFrozenDueToAgeNeedsInvestigation
#52010 opened 2 years ago by liggitt
x509 certificate with issuerUniqueID and/or subjectUniqueID parse error [1.18 backport]CherryPickApprovedFrozenDueToAge
#51859 opened 2 years ago by gopherbot
x509 certificate with issuerUniqueID and/or subjectUniqueID parse error [1.17 backport]CherryPickApprovedFrozenDueToAge
#51858 opened 2 years ago by gopherbot
#51852 opened 2 years ago by gopherbot
Certificate.Verify crash on macOS with Go 1.18 (CVE-2022-27536) [1.18 backport]CherryPickApprovedFrozenDueToAgeSecurityrelease-blocker
#51763 opened 2 years ago by gopherbot
#51759 opened 2 years ago by bradfitz
#51754 opened 2 years ago by mic6090
#51752 opened 2 years ago by tie
TestHybridPool failures on Windows with `x509: certificate signed by unknown authority`FrozenDueToAgeNeedsInvestigationOS-Windowsokay-after-beta1release-blocker
#51599 opened 2 years ago by bcmills
intermittent failures on darwin/amd64 with ‘x509: “…” certificate is expired’ since 2021-11-06FrozenDueToAgeNeedsFixOS-Darwinrelease-blocker
#51209 opened 2 years ago by bcmills
invalid RDNSequence: invalid attribute value: unsupported string type: 18 [1.17 backport]CherryPickApprovedFrozenDueToAge
#51000 opened 2 years ago by gopherbot
ParseCertificate and ParseCertificateRequest should return an error when there are duplicate x509 extensionsFrozenDueToAgeNeedsFix
#50988 opened 2 years ago by aaomidi
add ParseRevocationList, deprecate ParseCRL & ParseDERCRLFrozenDueToAgeProposalProposal-AcceptedProposal-CryptoProposal-FinalCommentPeriod
#50674 opened 2 years ago by rolandshoemaker
unhandled error FrozenDueToAge
#50570 opened 2 years ago by walkerxiong
#50165 opened 2 years ago by gopherbot
#49678 opened 3 years ago by umlublin
#49414 opened 3 years ago by solyard
#49135 opened 3 years ago by tenntenn
Verify fails to find valid path when some paths have EKU constraint violationsFrozenDueToAgeNeedsInvestigation
#48869 opened 3 years ago by JackOfMostTrades
#48808 opened 3 years ago by sding3
#48171 opened 3 years ago by mic6090
parse SAN DirectoryNameFrozenDueToAge
#47618 opened 3 years ago by tracefinder
go.1.15 onwards CreateCertificate signed by CA cert adds unparseable ASN1 blocks under x509.Certificate.ExtensionsFrozenDueToAge
#47526 opened 3 years ago by manuullas
#46937 opened 3 years ago by alanhamlett
invalid authority key identifier parsing older root "Starfield Class 2 Certification Authority"FrozenDueToAgeNeedsFixrelease-blocker
#46854 opened 3 years ago by joeshaw
use platform verifier on Windows, macOS and iOSFrozenDueToAgeProposalProposal-AcceptedProposal-CryptoProposal-FinalCommentPeriod
#46287 opened 3 years ago by FiloSottile
#46284 opened 3 years ago by FiloSottile
#46057 opened 3 years ago by dnephin
#45990 opened 3 years ago by ycongal-smile
#45904 opened 3 years ago by wzzhu
CertPools do not equal each other in 1.16FrozenDueToAge
#45891 opened 3 years ago by pcman312
#45856 opened 3 years ago by FiloSottile
#44299 opened 3 years ago by rolandshoemaker
#44237 opened 3 years ago by zzma
add SetFallbackRoots and golang.org/x/crypto/x509roots/fallback packageFrozenDueToAgeProposalProposal-AcceptedProposal-CryptoProposal-FinalCommentPeriod
#43958 opened 3 years ago by breml
#43954 opened 3 years ago by elgohr
investigate signature verification added to CreateCertificate in Go 1.16FrozenDueToAgeNeedsInvestigationrelease-blocker
#43928 opened 3 years ago by dmitshur
#43504 opened 3 years ago by pschou
#43477 opened 3 years ago by AGWA
#42414 opened 4 years ago by Poor12
#42125 opened 4 years ago by rolandshoemaker
IsEncryptedPEMBlock returns false on valid encrypted keys. ParseRawPrivateKeyWithPassphrase fails on PKCS8 format encrypted key.DocumentationFrozenDueToAgeNeedsFix
#41949 opened 4 years ago by HarikrishnanBalagopal
#41682 opened 4 years ago by FiloSottile
#41407 opened 4 years ago by rolandshoemaker
CreateCertificate should return a meaningful error instead of panic when passed an unknown ExtKeyUsageFrozenDueToAgeNeedsFix
#41169 opened 4 years ago by rolandshoemaker
#41035 opened 4 years ago by cespare
Google Cloud SQL TLS connections broken in Go 1.15+NeedsInvestigation
#40748 opened 4 years ago by kristiandrucker
#40679 opened 4 years ago by PeterNovotney
#40604 opened 4 years ago by SparrowLii
#40458 opened 4 years ago by rolandshoemaker
#40370 opened 4 years ago by wrschneider
Certificate.Verify method seemingly ignoring EKU requirements on Windows [Go 1.14]CherryPickApprovedFrozenDueToAgeSecurity
#40210 opened 4 years ago by katiehockman
Certificate.Verify method seemingly ignoring EKU requirements on Windows [Go 1.13]CherryPickApprovedFrozenDueToAgeSecurity
#40209 opened 4 years ago by katiehockman
#39568 opened 4 years ago by kevinburke1
#39503 opened 4 years ago by nodece
#39429 opened 4 years ago by rolandshoemaker
Certificate.Verify method seemingly ignoring EKU requirements on WindowsFrozenDueToAgeNeedsFixOS-Windows
#39360 opened 4 years ago by niallnsec
#39241 opened 4 years ago by shibe2
#38888 opened 4 years ago by FiloSottile
#38843 opened 4 years ago by FiloSottile
#38710 opened 4 years ago by bradfitz
CGO_ENABLED=0 x509: certificate signed by unknown authorityFrozenDueToAgeNeedsInvestigationOS-DarwinWaitingForInfo
#38365 opened 4 years ago by kotyara85
#38216 opened 4 years ago by m-j-jam
#38215 opened 4 years ago by deitch
#38181 opened 4 years ago by bamiaux
#38014 opened 4 years ago by Demi-Marie
documentation about SSL_CERT_FILE and SSL_CERT_DIR is incorrectDocumentationFrozenDueToAgeNeedsInvestigation
#37907 opened 4 years ago by elagergren-spideroak
#37845 opened 4 years ago by shoobyban
Certificate parsing/verification supports non-compliant dNSName constraintsFrozenDueToAgeNeedsInvestigation
#37535 opened 4 years ago by rolandshoemaker
#37172 opened 4 years ago by chauncyc
MarshalPKCS8PrivateKey doc says RSA private key while it supports more than that [1.14 backport]CherryPickApprovedFrozenDueToAge
#37068 opened 4 years ago by gopherbot
MarshalPKCS8PrivateKey doc says RSA private key while it supports more than that [1.13 backport]CherryPickApprovedFrozenDueToAge
#37067 opened 4 years ago by gopherbot
certificate signed by unknown authority, macOSFrozenDueToAge
#37017 opened 4 years ago by fcjr
#36839 opened 4 years ago by katiehockman
#36838 opened 4 years ago by katiehockman
#36837 opened 4 years ago by katiehockman
#36836 opened 4 years ago by katiehockman
#36835 opened 4 years ago by katiehockman
#36834 opened 4 years ago by katiehockman
incorrect mention of "EC Public Key" for ParseECPrivateKey docs, should be "EC Private Key"DocumentationFrozenDueToAgeNeedsInvestigation
#36788 opened 4 years ago by matthew119427
MarshalPKCS8PrivateKey doc says RSA private key while it supports more than thatDocumentationFrozenDueToAgeNeedsFix
#36735 opened 4 years ago by gmichelo
#36044 opened 5 years ago by jajohnsonpro
certificate verification does not correctly compare subject and issuer names for equalityFrozenDueToAge
#36027 opened 5 years ago by paulgriffiths
#35841 opened 5 years ago by egonk
#35631 opened 5 years ago by mariusgrigoriu
Other Names in x509 Certificate SAN causing certificate verification failureFrozenDueToAgeNeedsInvestigation
#35467 opened 5 years ago by chrisbrowning
#35428 opened 5 years ago by jefferai
SSL_CERT_DIR should support multiple directories separated by a colon like OpenSSL and BoringSSL doFrozenDueToAgeNeedsFix
#35325 opened 5 years ago by freedge
Reference SubjectPublicKeyInfo in MarshalPKIXPublicKeyDocumentationFrozenDueToAgeNeedsFixhelp wanted
#35313 opened 5 years ago by jsha
#35052 opened 5 years ago by graywolf
#35044 opened 5 years ago by wbl
#34844 opened 5 years ago by denisvolin
#34252 opened 5 years ago by tmthrgd
#33888 opened 5 years ago by kevinburke1
#33560 opened 5 years ago by Frozen-Tofu
any plans to implement RID and dirName SANs?FrozenDueToAge
#33504 opened 5 years ago by pedromreis
#33317 opened 5 years ago by bodgit
#33310 opened 5 years ago by azsn
#32891 opened 5 years ago by tommyknows
#32878 opened 5 years ago by vitaliy-kuzmich
#32777 opened 5 years ago by micahhyman1
return informative error if wrong type passed to MarshalPKIXPublicKeyFrozenDueToAgeNeedsFixhelp wanted
#32640 opened 5 years ago by mathieudevos
#32604 opened 5 years ago by FiloSottile
macos 10.14 SIGSEGV in crypto/x509._Cfunc_FetchPEMRoots [1.12 backport]CherryPickApprovedFrozenDueToAge
#32282 opened 5 years ago by gopherbot
macos 10.14 SIGSEGV in crypto/x509._Cfunc_FetchPEMRoots [1.11 backport]CherryPickApprovedFrozenDueToAge
#32281 opened 5 years ago by gopherbot
#32172 opened 5 years ago by yyq2013
recently updated Xcode command line tools results in errorFrozenDueToAgeNeedsInvestigationWaitingForInfo
#31250 opened 5 years ago by gilgameshskytrooper
FetchPEMRoots in CGO crashed with signal SIGSEGV when using http.Client.Do() on https URLFrozenDueToAgeOS-Darwin
#30889 opened 5 years ago by marques-work
frequent panics when doing HTTPS requests on DarwinFrozenDueToAgeNeedsInvestigationOS-Darwinrelease-blocker
#30763 opened 5 years ago by leonklingele
root_cgo_darwin omits intermediate CAs with an empty policy settings or an unspecified trust type settingFrozenDueToAgeNeedsFixOS-Darwin
#30672 opened 5 years ago by penglei
#30471 opened 5 years ago by vdobler
#30444 opened 5 years ago by bradfitz
offer a useful error when ParsePKCS8PrivateKey/ParseECPrivateKey/ParsePKCS1PrivateKey or ParsePKIXPublicKey/ParsePKCS1PrivateKey are mixed upFrozenDueToAgeNeedsFixhelp wanted
#30094 opened 5 years ago by FiloSottile
certificates with AKID don't chain to parents without SKID [1.11 backport]CherryPickApprovedFrozenDueToAge
#30081 opened 5 years ago by gopherbot
certificates with AKID don't chain to parents without SKID [1.10 backport]CherryPickApprovedFrozenDueToAgeNeedsFix
#30080 opened 5 years ago by gopherbot
#30079 opened 5 years ago by FiloSottile
TestSystemRoots failing when keychain contains expired or untrusted certificatesFrozenDueToAgeNeedsFixOS-Darwin
#29497 opened 5 years ago by akamensky
#29238 opened 6 years ago by FiloSottile
#29237 opened 6 years ago by FiloSottile
#29233 opened 6 years ago by dmitshur
#29141 opened 6 years ago by ThreeFx
#28743 opened 6 years ago by empijei
#28276 opened 6 years ago by imirkin
#28199 opened 6 years ago by afbjorklund
#28092 opened 6 years ago by akamensky
Go does not load root CA from System keychain on macOSFrozenDueToAgeNeedsInvestigationOS-DarwinSecurity
#28025 opened 6 years ago by adamrothman
#27969 opened 6 years ago by alexkohler
if system keychain has a cert with an empty but valid trust settings array, cert should be trusted but Go does not trust itFrozenDueToAgeNeedsInvestigationOS-DarwinSecurity
#27958 opened 6 years ago by jhump
#27880 opened 6 years ago by azr
Partial wildcards are not supportedFrozenDueToAge
#27629 opened 6 years ago by agunnerson-ibm
#27591 opened 6 years ago by int-tt
SystemCertPool documentation is not clear that modifications to the cert pool supplied are isolated from other pools returned by the functionDocumentationFrozenDueToAgeNeedsFix
#27385 opened 6 years ago by leighmcculloch
#27175 opened 6 years ago by brunetto
add functions to download certificates from windows update, and retrieve certificates from windows x509storesFrozenDueToAgeOS-WindowsProposalProposal-Crypto
#26950 opened 6 years ago by jeet-parekh
#26830 opened 6 years ago by FiloSottile
#26676 opened 6 years ago by FiloSottile
#26624 opened 6 years ago by adamdecaf
#26614 opened 6 years ago by btoews
create typed versions of ParsePKCS8PrivateKeyFrozenDueToAgeNeedsInvestigationProposalProposal-Crypto
#26485 opened 6 years ago by HaraldNordgren
#26362 opened 6 years ago by FiloSottile
#26093 opened 6 years ago by medzin
#26073 opened 6 years ago by rsc
root_cgo_darwin and root_nocgo_darwin omit some system certs [1.9 backport]CherryPickCandidateFrozenDueToAge
#26040 opened 6 years ago by gopherbot
root_cgo_darwin and root_nocgo_darwin omit some system certs [1.11 backport]CherryPickApprovedFrozenDueToAge
#26039 opened 6 years ago by gopherbot
#25667 opened 6 years ago by Trane9991
root_cgo_darwin omits certs with number of trust settings 0 erroneously when CGO_ENABLED=1FrozenDueToAgeNeedsInvestigationOS-Darwin
#25649 opened 6 years ago by dlamotte
#25355 opened 6 years ago by FiloSottile
#25258 opened 6 years ago by gopherbot
#25016 opened 6 years ago by gopherbot
partial wildcards not supportedFrozenDueToAge
#24888 opened 6 years ago by kmala
#24685 opened 6 years ago by nolith
#24652 opened 6 years ago by jdhenke
#24590 opened 6 years ago by robstradling
#24561 opened 6 years ago by FiloSottile
#24540 opened 6 years ago by frankgreco
#24437 opened 6 years ago by avinashrd
#24425 opened 6 years ago by avinashrd
#24293 opened 6 years ago by gibma
multi-value RDN sequence is not properly DER-orderedFrozenDueToAgeNeedsFixearly-in-cyclerelease-blocker
#24254 opened 6 years ago by mrogers950
FetchPEMRoots in CGO crashed with signal SIGSEGV on go get gopkg.in/sourcemap.v1 on macOS Sierra (10.12.6)FrozenDueToAgeNeedsInvestigationOS-Darwin
#24190 opened 6 years ago by ericreis
VerifyOptions.KeyUsages went from any required to all required in 1.10CherryPickApprovedFrozenDueToAge
#24162 opened 6 years ago by grittygrease
#24151 opened 6 years ago by thsnr
#24084 opened 6 years ago by adamdecaf
#24070 opened 6 years ago by hanikesn
#23995 opened 6 years ago by freman
#23847 opened 6 years ago by conradoplg
#23711 opened 6 years ago by magiconair
Go should be lenient in parsing CRL Distribution Points that do not conform to RFC 5280 4.2.1.13FrozenDueToAgeNeedsDecision
#23403 opened 6 years ago by christopher-henderson
add support to get SSL context from certificate store on windowsFrozenDueToAgeOS-WindowsProposalProposal-Crypto
#23282 opened 6 years ago by tsaridas
#23217 opened 7 years ago by mmiranda96
#23032 opened 7 years ago by parazyd
Trailing data in the IssuerAlternativeName extension value does not return an error when parsing certificate.FrozenDueToAgeNeedsInvestigation
#23016 opened 7 years ago by szank
#22922 opened 7 years ago by rikatz
#22616 opened 7 years ago by pcarrier
#22261 opened 7 years ago by rsc
intermediates with unknown critical extensions not rejectedCherryPickApprovedFrozenDueToAgerelease-blocker
#22260 opened 7 years ago by rsc
#22256 opened 7 years ago by rsc
#22249 opened 7 years ago by optnfast
#22181 opened 7 years ago by acohn
#22017 opened 7 years ago by Tasssadar
#21858 opened 7 years ago by realmfoo
cannot generate version 1 or 2 certificatesFrozenDueToAge
#21593 opened 7 years ago by CRThaze
#21502 opened 7 years ago by vickiniu
Entrust broken cert link no longer valid, please consider removing the workaroundFrozenDueToAgerelease-blocker
#21488 opened 7 years ago by mrmagooey
#21416 opened 7 years ago by martisch
#21405 opened 7 years ago by champtar
#21363 opened 7 years ago by cryslith
#21339 opened 7 years ago by tonyjt
#21118 opened 7 years ago by agl
missing MarshalPKCS1PublicKey and ParsePKCS1PublicKeyFrozenDueToAge
#21029 opened 7 years ago by tmc
root_darwin.go does not include trusted root certificates from System/Login keychainsFrozenDueToAgeOS-Darwin
#20990 opened 7 years ago by raszi
#20801 opened 7 years ago by dmitshur
#19972 opened 7 years ago by jameshartig
export CertPool’s certificatesFrozenDueToAge
#19606 opened 7 years ago by stapelberg
TestSystemVerify failures on windows-*-2008 buildersBuildersFrozenDueToAgeOS-WindowsTestingokay-after-beta1release-blocker
#19564 opened 7 years ago by josharian
FetchPEMRoots on macOS takes 20 seconds when there are a lot of trust settingsFrozenDueToAgeNeedsInvestigationOS-Darwin
#19561 opened 7 years ago by tbodt
honor OS X certificate trust settings possible regressionFrozenDueToAgeNeedsInvestigationOS-DarwinWaitingForInfohelp wanted
#19436 opened 7 years ago by dharmapunk82
ParseCertificate returns a certificate with MaxPathLen of -1 if pathLenConstraint is not setDocumentationFrozenDueToAgeNeedsDecision
#19285 opened 7 years ago by cyli
docs for CreateCertificate omit template.AuthorityKeyId yet it is used in codeDocumentationFrozenDueToAge
#18962 opened 7 years ago by taylortrimble
#18899 opened 7 years ago by lwithers
#18813 opened 7 years ago by joegrasse
#18688 opened 7 years ago by cblecker
ParseCertificate ignores all but first value from Subject's []string{} fieldsFrozenDueToAgeNeedsInvestigation
#18654 opened 7 years ago by joemiller
Go 1.8's SystemCertPool() on Windows does not return all Windows root CAsFrozenDueToAgeNeedsFixhelp wanted
#18609 opened 7 years ago by mkrautz
#18224 opened 8 years ago by YoshikiShibata
#18203 opened 8 years ago by phacker
#18141 opened 8 years ago by quentinmit
#17972 opened 8 years ago by nhooyr
#17732 opened 8 years ago by AxbB36
certificates at /etc/ssl/certs/ ignored on FreeBSD, etcFrozenDueToAgeNeedsInvestigationOS-FreeBSDhelp wanted
#16920 opened 8 years ago by buro1983
distributionPointName not compliant with RFC 5280FrozenDueToAge
#16858 opened 8 years ago by zhengping12
#16836 opened 8 years ago by tv42
bad error messageFrozenDueToAge
#16834 opened 8 years ago by joneskoo
#16800 opened 8 years ago by ramoas
#16763 opened 8 years ago by agl
#16736 opened 8 years ago by bradfitz
#16686 opened 8 years ago by jefferai
#16660 opened 8 years ago by ghost
#16603 opened 8 years ago by jefferai
error "x509: certificate signed by unknown authority" on valid SSL chainFrozenDueToAgeNeedsInvestigation
#16589 opened 8 years ago by rasky
darwin only loads system.root keychain should also load system keychainFrozenDueToAgeNeedsFixOS-Darwinhelp wantedrelease-blocker
#16532 opened 8 years ago by jostockley
#16508 opened 8 years ago by bradfitz
0xb01dfacedebac1e crash on Mac OS X 10.8FrozenDueToAge
#16473 opened 8 years ago by bradfitz
#16347 opened 8 years ago by floridoo
#16166 opened 8 years ago by szank
#15958 opened 8 years ago by lwithers
#15749 opened 8 years ago by mckn
#15452 opened 8 years ago by runeaune
Wrong error text when failing to unmarshal key-idFrozenDueToAge
#15371 opened 8 years ago by phayes
#15256 opened 8 years ago by huang195
AuthorityKeyId on self-signed certificatesFrozenDueToAge
#15194 opened 8 years ago by vanbroup
#14955 opened 8 years ago by jsha
invalid implementation of Permitted DNS NamesFrozenDueToAge
#14833 opened 8 years ago by ayufan
#14776 opened 8 years ago by perillo
#14688 opened 8 years ago by ianlancetaylor
oidSignatureDSAWithSHA256 has incorrect valueFrozenDueToAge
#14663 opened 8 years ago by AGWA
#14649 opened 8 years ago by voutasaurus
#14514 opened 8 years ago by mwielgoszewski
#14512 opened 8 years ago by wpc
better documentation for ParsePKIXPublicKeyFrozenDueToAge
#14355 opened 8 years ago by dndx
#14311 opened 8 years ago by raspy
#14129 opened 8 years ago by nurio
#14125 opened 8 years ago by boumenot
#14022 opened 8 years ago by lifeforms
#13931 opened 8 years ago by hujun-open
#13739 opened 9 years ago by nejisama
Panics on some ECDSA keysFrozenDueToAge
#13699 opened 9 years ago by hlandau
#13519 opened 9 years ago by rolandshoemaker
add support for marshalling PKCS#8 private keysFrozenDueToAge
#13487 opened 9 years ago by AGWA
export systemRootsPool or equivilantFrozenDueToAge
#13335 opened 9 years ago by phemmer
#12184 opened 9 years ago by deafgoat
add /etc/ssl/certs to certificate directoriesFrozenDueToAge
#12139 opened 9 years ago by deafgoat
x509 DN orderingFrozenDueToAge
#11966 opened 9 years ago by szechyjs
Go uses the wrong type for parsing CSR attributesFrozenDueToAge
#11897 opened 9 years ago by agl
cannot build for iOS simulatorFrozenDueToAge
#11736 opened 9 years ago by crawshaw
#11730 opened 9 years ago by chai2010
division by zeroFrozenDueToAge
#11233 opened 9 years ago by dvyukov
input not full blocksFrozenDueToAge
#11215 opened 9 years ago by dvyukov
test is sometimes very slowFrozenDueToAge
#10692 opened 9 years ago by rsc
reading certificates from PKCS12 files FrozenDueToAge
#10621 opened 9 years ago by paulmey
ParsePKIXPublicKey ignores tail of ASN.1 encodingFrozenDueToAge
#10583 opened 9 years ago by rsc
#10459 opened 9 years ago by nathany
Support MD5 signatures for certificatesFrozenDueToAge
#10436 opened 9 years ago by gonzojive
#10431 opened 9 years ago by mvanotti
#10421 opened 9 years ago by SunRunAway
#10171 opened 9 years ago by diogomonica
#9964 opened 9 years ago by mvanotti
#9834 opened 9 years ago by agl
matchHostnames doesn't work with absolute domain namesFrozenDueToAge
#9828 opened 9 years ago by rubyist
missing certificate location on netbsdFrozenDueToAge
#9285 opened 10 years ago by 0-wiz-0
#9146 opened 10 years ago by gopherbot
certFiles needs updating for Solaris 11.2+FrozenDueToAge
#9078 opened 10 years ago by gopherbot
typo in CreateCertificateRequest docsFrozenDueToAge
#8936 opened 10 years ago by gopherbot
ParsePKCS8PrivateKey does not support loading DSA keysFrozenDueToAge
#8919 opened 10 years ago by gopherbot
cert from google fails to parseFrozenDueToAge
#8387 opened 10 years ago by gopherbot
failed to load system roots and no roots provided.FrozenDueToAge
#8349 opened 10 years ago by gopherbot
#8265 opened 10 years ago by gopherbot
An invalid certificate chain may be returned by "Certificate.Verify(opts VerifyOptions)"FrozenDueToAge
#8029 opened 10 years ago by gopherbot
No expected chain matchedFrozenDueToAge
#7824 opened 10 years ago by peterGo
#7523 opened 10 years ago by rsc
#7516 opened 10 years ago by gopherbot
support DSA keys.FrozenDueToAge
#6868 opened 11 years ago by hanwen
#6831 opened 11 years ago by gopherbot
error in documentation for CreateCertificateFrozenDueToAge
#6633 opened 11 years ago by jstemmer
#6391 opened 11 years ago by gopherbot
#6267 opened 11 years ago by dsymonds
does not expose URIs in SubjectAltName extensionFrozenDueToAge
#5752 opened 11 years ago by gopherbot
support CSRsFrozenDueToAge
#5303 opened 11 years ago by gopherbot
respect SignatureAlgorithm in CreateCertificateFrozenDueToAge
#5302 opened 11 years ago by gopherbot
certificate with signature RMD160 shows wrong error messageFrozenDueToAgeNeedsInvestigationhelp wanted
#5301 opened 11 years ago by gopherbot
confusing error for missing hash functionFrozenDueToAge
#5058 opened 11 years ago by rsc
Wildcard Cerficate Validation WeaknessFrozenDueToAge
#4658 opened 12 years ago by gopherbot
windows test exe crashes while calling syscall.CertGetCertificateChain during TestSystemVerifyFrozenDueToAgeUnfortunate
#4165 opened 12 years ago by gopherbot
allow cert bundle path to be set by environment variableFrozenDueToAge
#3905 opened 12 years ago by gopherbot
cannot parse Facebook certFrozenDueToAge
#3731 opened 12 years ago by gopherbot
TLS connection problems due to cert verification failureFrozenDueToAge
#993 opened 14 years ago by gopherbot
#988 opened 14 years ago by gopherbot