Re: [pve-devel] [PATCH common] cert: fix invalid CSR version

2023-04-03 Thread Mira Limbeck
Looks like a python-cryptography maintainer opened a pull request on Github with the exact same change: https://github.com/proxmox/pve-common/pull/8 ___ pve-devel mailing list pve-devel@lists.proxmox.com https://lists.proxmox.com/cgi-bin/mailman/list

[pve-devel] [PATCH common] cert: fix invalid CSR version

2023-03-31 Thread Mira Limbeck
According to rfc2986 the only valid version is 0. No newer rfc changed that. See section 4.1: https://www.rfc-editor.org/rfc/rfc2986#section-4.1 Manually verifying the CSR with openssl results in the following error: ``` $ openssl req -in bad.csr -text -noout Certificate Request: Data: