google / google/certificate-transparency-go

Expired certificate in root_darwin_armx.go

Open
#1,655 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
1.2k
Forks
323
Avg merge
3d 4h
Merged PRs (30d)
5

Description

Hi - Was just curious if expired certificates will be removed. One has just expired on 2025-02-10 at 00:18:14 GMT

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 1 (0x1)
        Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=Apple Computer, Inc., OU=Apple Computer Certificate Authority, CN=Apple Root Certificate Authority
        Validity
            Not Before: Feb 10 00:18:14 2005 GMT
            Not After : Feb 10 00:18:14 2025 GMT
        Subject: C=US, O=Apple Computer, Inc., OU=Apple Computer Certificate Authority, CN=Apple Root Certificate Authority
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:e4:91:a9:09:1f:91:db:1e:47:50:eb:05:ed:5e:
                    79:84:2d:eb:36:a2:57:4c:55:ec:8b:19:89:de:f9:
                    4b:6c:f5:07:ab:22:30:02:e8:18:3e:f8:50:09:d3:
                    7f:41:a8:98:f9:d1:ca:66:9c:24:6b:11:d0:a3:bb:
                    e4:1b:2a:c3:1f:95:9e:7a:0c:a4:47:8b:5b:d4:16:
                    37:33:cb:c4:0f:4d:ce:14:69:d1:c9:19:72:f5:5d:
                    0e:d5:7f:5f:9b:f2:25:03:ba:55:8f:4d:5d:0d:f1:
                    64:35:23:15:4b:15:59:1d:b3:94:f7:f6:9c:9e:cf:
                    50:ba:c1:58:50:67:8f:08:b4:20:f7:cb:ac:2c:20:
                    6f:70:b6:3f:01:30:8c:b7:43:cf:0f:9d:3d:f3:2b:
                    49:28:1a:c8:fe:ce:b5:b9:0e:d9:5e:1c:d6:cb:3d:
                    b5:3a:ad:f4:0f:0e:00:92:0b:b1:21:16:2e:74:d5:
                    3c:0d:db:62:16:ab:a3:71:92:47:53:55:c1:af:2f:
                    41:b3:f8:fb:e3:70:cd:e6:a3:4c:45:7e:1f:4c:6b:
                    50:96:41:89:c4:74:62:0b:10:83:41:87:33:8a:81:
                    b1:30:58:ec:5a:04:32:8c:68:b3:8f:1d:de:65:73:
                    ff:67:5e:65:bc:49:d8:76:9f:33:14:65:a1:77:94:
                    c9:2d
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Certificate Sign, CRL Sign
            X509v3 Basic Constraints: critical
                CA:TRUE
            X509v3 Subject Key Identifier:
                2B:D0:69:47:94:76:09:FE:F4:6B:8D:2E:40:A6:F7:47:4D:7F:08:5E
            X509v3 Authority Key Identifier:
                2B:D0:69:47:94:76:09:FE:F4:6B:8D:2E:40:A6:F7:47:4D:7F:08:5E
            X509v3 Certificate Policies:
                Policy: 1.2.840.113635.100.5.1
                  CPS: https://www.apple.com/certificateauthority/terms.html
                  User Notice:
                    Explicit Text: Reliance on this certificate by any party assumes acceptance of the then applicable standard terms and conditions of use, certificate policy and certification practice statements.
            X509v3 CRL Distribution Points:
                Full Name:
                  URI:https://www.apple.com/certificateauthority/root.crl
            Authority Information Access:
                CA Issuers - URI:https://www.apple.com/certificateauthority/casigners.html
    Signature Algorithm: sha1WithRSAEncryption
    Signature Value:
        9d:da:2d:28:58:2f:7d:76:04:b9:04:d3:3e:ce:b7:66:63:4e:
        8f:2f:d4:fe:4b:ad:72:bd:a3:39:c6:52:4d:05:98:52:f5:89:
        51:01:24:79:be:1a:32:f7:e5:44:8b:4b:44:07:39:82:d6:5a:
        ca:b4:20:5e:d9:ae:15:5d:1d:8c:1d:32:bf:38:31:62:48:5d:
        c7:e1:90:b1:f8:24:40:f8:5f:58:9b:51:5d:57:9d:c1:e5:ff:
        3c:cc:72:21:6e:c4:e9:e9:a1:77:d7:2c:17:26:c3:3f:eb:9a:
        e8:0b:03:ba:e9:b3:4a:72:eb:33:09:5b:ad:e6:62:31:6a:e8:
        af:2f:d5:af:1e:57:76:8f:7f:37:2d:2e:02:5c:dd:63:c9:f2:
        71:b8:26:40:df:15:8d:75:44:3f:79:bd:e6:1d:99:e1:43:2c:
        3e:ad:6f:be:b9:a4:fe:0e:35:19:51:63:b1:c3:de:b5:92:3e:
        51:78:01:73:8a:a4:23:ca:a4:88:f1:1e:5c:1f:41:16:2d:7e:
        95:0a:aa:e9:89:41:98:1b:1a:dd:cb:20:bf:47:5e:0c:26:c5:
        55:35:4d:c6:30:8b:99:67:14:c7:09:1f:ba:47:c7:da:01:09:
        87:24:42:95:bd:13:60:19:0a:ef:ea:7f:0e:6e:cd:c1:44:43:
        3a:4a:d5:e3

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by inspecting root_darwin_armx.go around lines 364-396 and determine how the expired Apple certificate is represented. Confirm whether expired roots should remain in this trust store, then make the appropriate certificate-list update and verify the affected Go code still builds and tests successfully.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.