Create scaffolding for configuring lints with issuers - #8923
Merged
Conversation
aarongable
requested review from
beautifulentropy,
ezekiel and
jsha
and removed request for
jsha
July 29, 2026 00:07
aarongable
force-pushed
the
configurable-lints
branch
from
July 29, 2026 21:13
3655bad to
e19eb5a
Compare
ezekiel
approved these changes
Jul 29, 2026
beautifulentropy
approved these changes
Jul 29, 2026
aarongable
added a commit
that referenced
this pull request
Jul 30, 2026
Add a new config field to cert-checker: `issuerCerts`, identical to the config field of the same name in the RA. Use this field to look up the intermediate CA certificate which issued each cert that cert-checker checks, and to add that issuer to our custom linter config, just like the CA and ceremony tool already do (as of #8923). This will allow the cert-checker to successfully run our upcoming custom CP/CPS lints, which require that the issuer be configured. To facilitate this new functionality, slightly refactor `linter.NewRegistryWithConfig` so that it is usable by both the ceremony tool and cert-checker.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Create the ability for lints to be configured with either an issuer certificate (useful for everything but self-signed roots), or an pre-existing certificate (useful for cross-signs), or both. Because zlint expects configs to be TOML strings, build some infrastructure that is capable of serializing and deserializing these configs, and augmenting them at runtime. This lets us combine the actual zlint config (which includes things like ignored lints and how to connect to PKIMetal) with the dynamic issuer or existing cert config.
Have the CA and Ceremony tool correctly configure zlint with the relevant additional certs. No lints use this yet, but our CP/CPS lints will soon.
This moves some of the refactoring out of #8485, so that PR can be more focused on the lints themselves.