[openssl-dev] [openssl.org #3979] New OpenSSL issue: valid certificate fails validation where subject text == issuer text

Matt Bogosian via RT rt at openssl.org
Tue Aug 4 18:25:25 UTC 2015


Later versions[1] of OpenSSL will (mistakenly) complain that if subject text == issuer text, then the certificate is self-signed (even if it isn't).

[1] I haven't narrowed down exactly which; 0.9.8 and 1.0.0 generally don't exhibit this problem, whereas 1.0.1 and 1.0.2 generally do.

A more detailed explanation (with examples) can be found here:

https://github.com/docker/compose/issues/890#issuecomment-127662092

Please let me know if you have any questions, and I'd be happy to elaborate.


Sincerely,
Matt Bogosian
+1.831.824.4442




-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 203 bytes
Desc: not available
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20150804/2f0e4bb6/attachment-0001.sig>
-------------- next part --------------
_______________________________________________
openssl-bugs-mod mailing list
openssl-bugs-mod at openssl.org
https://mta.openssl.org/mailman/listinfo/openssl-bugs-mod


More information about the openssl-dev mailing list