[openssl-users] X509_V_ERR_INVALID_PURPOSE when validating TLS client with "any purpose" EKU (

Alan Egerton eggyal at gmail.com
Thu Jun 11 20:05:47 UTC 2015

Dear OpenSSL Users,

When attempting to validate a TLS client whose cert has a number of
EKU purposes including "any" (, but not "Client
Authentication" (, I am seeing validation fail with

Looking at <https://github.com/openssl/openssl/blob/master/crypto/x509v3/v3_purp.c>,
particularly the definitions of both the check_purpose_ssl_client()
function and the xku_reject() macro, it seems that OpenSSL does not
check for the any purpose EKU.  One presumes this is a bug?

Or am I doing something wrong?

Kind regards,
-- Alan

More information about the openssl-users mailing list