cloudflare / cloudflare/cfssl

signed certs have empty AKI?

Open
#1,403 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
9.5k
Forks
1.2k
PR merge metrics
No merged PRs in 30d

Description

i run the following sequence of commands to generate a self-signed root ca, and sign a `server` cert with it
```sh
cfssl genkey -initca csr.json | cfssljson -bare root
cfssl genkey csr.json | cfssljson -bare server
cfssl sign -ca root.pem -ca-key root-key.pem server.csr | cfssljson -bare server
```

`csr.json` contents:
```json
{
"hosts": ["localhost", "127.0.0.1"],
"key": {
"algo": "ecdsa",
"size": 256
},
"CN": "localhost",
"names": []
}
```

i see no errors in the process

then i run
```sh
cfssl certinfo -cert server.pem
```

and see the following line
```json
"authority_key_id": ""
```

i have an app with gRPC using TLS that fails (most likely because of the issue) with the following error

```
transport: authentication handshake failed: tls: failed to verify certificate: x509: certificate signed by unknown authority
```

my cfssl

```sh
cfssl version
```
outputs
```yaml
Version: 1.6.5
Runtime: go1.23.0
```

i see in README that AKI is not set for self-signed certs which is perfectly reasonable, but `server` here is not self-signed.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.