Skip to content

[Bug]: x509_v2: Tracebacks and output issues #69898

Description

@lkubb

What happened?

This is a collection of relatively minor bugs that came up during a review.

Tracebacks:

  • Malformed not_before/not_after/revocation_date results in a traceback instead of state error return
  • authorityInfoAccess specified as a list of dicts with a single critical string it was meant to skip causes a traceback
  • Adding an extension to an already-revoked entry in a CRL causes a traceback
  • Adding cRLNumber: auto to an existing CRL without a cRLNumber extension causes a traceback

Output inconsistencies:

  • create_private_key returns None for der/pkcs12 output written to a path, while the rest returns a "Private key written to {path}" message for the CLI
  • Typo onysomereasons in read_* output for issuingDistributionPoint extension
  • Typo organizataion in read_* output for certificatePolicies extension
  • An RFC822Name was rendered with a mail: prefix, when it should be email:

For reproductions, see PR.

Type of salt install

Official deb

Major version

3006.x

What supported OS are you seeing the problem on? Can select multiple. (If bug appears on an unsupported OS, please open a GitHub Discussion instead)

ubuntu-24.04

salt --versions-report output

Current HEAD of 3006.x

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugbroken, incorrect, or confusing behaviorneeds-triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions