Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

libspdm_verify_set_cert_leaf_cert_basic_constraints needs to be updated for SPDM 1.3 #2731

Open
steven-bellock opened this issue Jun 18, 2024 · 0 comments · May be fixed by #2850
Open

libspdm_verify_set_cert_leaf_cert_basic_constraints needs to be updated for SPDM 1.3 #2731

steven-bellock opened this issue Jun 18, 2024 · 0 comments · May be fixed by #2850
Assignees
Labels
bug Something isn't working stable For upcoming stable release

Comments

@steven-bellock
Copy link
Contributor

Follow-up to #2657.

libspdm_verify_set_cert_leaf_cert_basic_constraints currently allows the existence of a device certificate's CA field to be optional. This is mandatory for SPDM 1.3 and its value must be true. In addition the function should handle generic certificates the same as device certificates. The current logic treats generic certificates the same as alias certificates, which is incorrect.

@steven-bellock steven-bellock added the bug Something isn't working label Jun 18, 2024
@steven-bellock steven-bellock self-assigned this Jun 24, 2024
@steven-bellock steven-bellock added the stable For upcoming stable release label Sep 23, 2024
steven-bellock added a commit to steven-bellock/libspdm that referenced this issue Sep 24, 2024
@steven-bellock steven-bellock linked a pull request Sep 24, 2024 that will close this issue
steven-bellock added a commit to steven-bellock/libspdm that referenced this issue Sep 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working stable For upcoming stable release
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant