Skip to content

Forge accepts a certificate whose serial number is zero #1147

Description

@Jennifer-first

Forge accepts a certificate whose serial number is zero which is forbidden by RFC 5280 and its errata. The certificate should be rejected according to Sec. 4.1.2.2 in RFC 5280 "The serial number MUST be a positive integer assigned by the CA to each certificate" and the errata openssl/openssl#3200 "The serial number MUST be a positive non-zero integer assigned by the CA to each certificate".

To Reproduce:

const { pki } = require('node-forge');
const fs = require('fs');
const [, , caPath, certPath] = process.argv;
const caCert = pki.certificateFromPem(fs.readFileSync(caPath, 'utf8'));
const serverCert = pki.certificateFromPem(fs.readFileSync(certPath, 'utf8'));
const caStore = pki.createCaStore([caCert]);
console.log(pki.verifyCertificateChain(caStore, [serverCert]));

node verify.js ca.pem seed.pem

Expected behavior:
Verification failed.

test.zip

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions