tray icon indicating copy to clipboard operation
tray copied to clipboard

Whitelisting certificates does not support standard X.509 chains

Open Simon-Boyer opened this issue 3 years ago • 1 comments

X.509 certificate chains can only be certificates chained one after the other. The line --START INTERMEDIATE CERT--, required in QZ Tray, is not required in X.509 standard. Also, I didn't test it, bu I doubt that chains with more than 2 certificates would work with the current implementation.

The certificate reading methods should use a library based on standards, like Bouncy Castle API, instead of .split() methods. Not sure if it is possible while maintaining a backward-compatible environment, but I think it should at least be investigated.

As I said in #799 , I might look into making a PR for this issue.

Simon-Boyer avatar May 04 '21 21:05 Simon-Boyer

I doubt that chains with more than 2 certificates would work with the current implementation.

As of #708, it should be very close to working. I agree, the intermediate chaining is implemented in a proprietary fashion. BouncyCastle is already used, so this should be a relatively small change. PRs which fix this are welcome.

As of #708, a self-signed cert can be generated through the software for demonstration purposes (QZ Tray 2.1.3 or higher).

tresf avatar May 05 '21 04:05 tresf