dotnet / dotnet/runtime

NoIssuanceChainPolicy is only reported on Windows

Open
#130,268 1 comment 0 reactions 0 assignees View on GitHub
area-System.Security
Dominant language
C#
Stars
18.3k
Forks
5.6k
PR merge metrics
PR metrics pending

Description

### Description

Some shapes of X.509 Chain cause Windows to validate the structure of the chain policy, independent of asking the chain policy questions. When this validation fails, Windows reports NoIssuanceChainPolicy. That code doesn't appear on any of the other OSes.

### Reproduction Steps

There are a few tests in the tree (and some being added in parallel) that demonstrate this, but the easiest one to explain looks like:

* Root Certificate
* Basic Constraints: CA:true
* Policy Constraints: Inhibit Mapping, SkipCerts=0
* Intermediate Certificate:
* Basic Constraints: CA:true
* Policy Constraints: Require Explicit Policy, SkipCerts=0
* Certificate Policies: PolicyA
* Certificate Policy Mappings: PolicyA=>PolicyB
* EE Certificate:
* Basic Constraints: CA:false
* Certificate Policies: PolicyB

The Require Explicit Policy seems to trigger Windows into validating the chain structure. Since there are non-zero policies in the EE certificate that successfully trace up to the root without the mapping, and that mapping was forbidden, NoIssuanceChainPolicy is reported. (If the intermediate has PolicyA and PolicyC, and gives the EE PolicyB and PolicyC, the error is not raised.)

### Expected behavior

NoIssuanceChainPolicy

### Actual behavior

NoError

### Regression?

_No response_

### Known Workarounds

_No response_

### Configuration

_No response_

### Other information

_No response_

Contributor guide

Open the contributing guide

Research direction

Locate the existing X.509 chain-policy tests mentioned in the issue and run the relevant validation tests across Windows and the other operating systems. Trace the chain-policy handling for the Require Explicit Policy and forbidden mapping combination, then add coverage so the expected NoIssuanceChainPolicy result is reported consistently.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
cryptography, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.