Skip to content
Prev Previous commit
Next Next commit
Also mark cert as untrusted if the chain in constructed invalidly
Signed-off-by: Jannik Hollenbach <jannik.hollenbach@iteratec.com>
  • Loading branch information
J12934 committed Nov 5, 2025
commit cc762345fa8f82182d888ab5049e437035df6b8a
10 changes: 8 additions & 2 deletions scanners/sslyze/parser/parser.js
Original file line number Diff line number Diff line change
Expand Up @@ -249,10 +249,16 @@ function analyseCertificateDeployment(certificateDeployment) {
);
};

// Determine if the certificate is missing required extension
// Determine if the certificate has an untrusted root
// This can be indicated by multiple error patterns:
// 1. "Certificate is missing required extension"
// 2. "chain construction exceeds max depth"
const hasMissingRequiredExtension = hasErrorContaining(
"Certificate is missing required extension"
);
const hasChainDepthExceeded = hasErrorContaining(
"chain construction exceeds max depth"
);

return {
// To be trusted no openssl errors should have occurred and should match hostname
Expand All @@ -262,6 +268,6 @@ function analyseCertificateDeployment(certificateDeployment) {
),
selfSigned: isSelfSigned,
expired: hasErrorContaining("cert is not valid at validation time"),
untrustedRoot: hasMissingRequiredExtension && !isSelfSigned,
untrustedRoot: (hasMissingRequiredExtension || hasChainDepthExceeded) && !isSelfSigned,
};
}