badssl.com
badssl.com copied to clipboard
Feature request: Test incorrect Authority Key ID
Normally a certificate chain is referenced both by
- certificate's issuer matches subject of signing certificate
- certificate's "certificate authority key ID " matches the "certificate subject key id" of the signing certificate
Chrome seems to only care about the issuer chain and accepts chains with invalid authority keys. CURL and openSSL seem to actually check.