client, csr: copy the renewed cert's subject and SAN into reenroll CSRs - #44
Merged
Merged
Conversation
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #44
Scan targets checked: wolfcert-src, wolfcert-bugs
Coverage: 1 of 5 in-scope changed file(s) opened by the reviewer; not opened: tests/integration/test_est_tls_roundtrip.c, tests/unit/test_csr.c, wolfcert/client.h, wolfcert/types.h
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
yosuke-wolfssl
force-pushed
the
fix/f_12109
branch
from
September 30, 2026 03:07
00d7ef4 to
11d33a9
Compare
- wolfcert_client_reenroll() builds its CSR with a new internal wolfcert_csr_build_ex(), which rejects a meta that sets the subject or any SAN and copies the renewed certificate's raw Subject and SAN after the customize callback. - The CSR buffer is sized for the Subject and SAN carried. - wolfcert-client reenroll rejects --subject and --san-* and uses wolfcert_client_reenroll(). - The link probes also check GetASNTag and GetLength. - Headers and docs describe the renewal rule and its limits; EMBEDDED.md corrects the Cert sizing figures. - Tests cover the copy, its refusals and the rejected options. Issue: F-12109
yosuke-wolfssl
force-pushed
the
fix/f_12109
branch
from
September 30, 2026 03:44
11d33a9 to
1572cb8
Compare
Frauschi
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
wolfcert_client_reenroll()built the/simplereenrollCSR from the caller'smetaalone, so its Subject and SAN could differ from the certificate being renewed. RFC 7030 section 4.2.2 requires them to be identical. The CLIreenrollhad the same flaw and required--subject. A conformant EST server rejects such a renewal; a lax one issues a renamed certificate. No privilege boundary is crossed (the caller already holds the current key), so this is a conformance fix.Fix (
src/csr.c)A new internal
wolfcert_csr_build_ex()takes the certificate being renewed. The publicwolfcert_csr_build()passes none, so enrollment output is unchanged. For a renewal it:metathat setssubject_dnor anysan_*(WOLFCERT_ERR_BAD_ARG);customizecallback, so the identity is byte-identical; an empty Subject stays empty;Cert(WOLFCERT_ERR_UNSUPPORTED);The CSR buffer is now sized for the Subject and SAN it carries, which also lifts the old limit on large SANs at enrollment.
wolfcert_client_reenroll()withmeta.subject_dn/san_*WOLFCERT_ERR_BAD_ARGwolfcert-client reenroll --subject/--san-*--subjectrequiredwolfcert-client reenrollnow goes throughwolfcert_client_reenroll()and prints the error detail. The link probes addGetASNTag/GetLength, which are exported under the same condition as the helpers already required.client.hlists the renewal error codes;types.hand ARCHITECTURE.md describe the copy; EMBEDDED.md adds the renewal Subject limit and corrects itsCertsizing figures (~23CertNamefields, ~5 KB for the trimmed example).Closes f-12109.
Tests
test_csr: empty Subject with critical and non-critical SAN, kept against acustomizecallback that sets a CN; a reverse-order multi-RDN certificate with an unknown critical extension (raw Subject compared byte for byte); extensions without a SAN; BMPString Subject refused; 60-name SAN; SAN added bycustomizedropped; key PEM passed as the certificate; each identity field inmetarejected.test_est_tls_roundtrip:metarejection, renamingcustomizecallback, rekey.cli_proto_scoping:--subjectand each--san-*rejected on reenroll.Verification
-Werrorclean.cmake-full-asan-ubsan, Linux).qemu_x86:wolfcert.unit.csrpasses in 6-20 s against its 180 s limit.Not in this PR
reenrolltest, which needs a CLI test driven against a running server.