Skip to content

Comments

add support to verify cert chains longer than 1#204

Merged
gh4683 merged 2 commits intomainfrom
add-chain-verify
Jan 30, 2026
Merged

add support to verify cert chains longer than 1#204
gh4683 merged 2 commits intomainfrom
add-chain-verify

Conversation

@gh4683
Copy link
Contributor

@gh4683 gh4683 commented Jan 30, 2026

Recently found a case where the IAK has both leaf and intermediate certs, and the ca only has the root cert, which was leading to cert verification failure. Fixed it by parsing all certs in the chain and adding the intermediates to the cert pool.

@gh4683 gh4683 requested a review from gscert January 30, 2026 21:41
@coveralls
Copy link

coveralls commented Jan 30, 2026

Pull Request Test Coverage Report for Build 21533221643

Details

  • 37 of 41 (90.24%) changed or added relevant lines in 1 file are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage increased (+0.2%) to 53.208%

Changes Missing Coverage Covered Lines Changed/Added Lines %
service/biz/tpm_cert_verifier.go 37 41 90.24%
Totals Coverage Status
Change from base Build 21499547841: 0.2%
Covered Lines: 2032
Relevant Lines: 3819

💛 - Coveralls

@gh4683 gh4683 marked this pull request as ready for review January 30, 2026 21:42
@gh4683 gh4683 requested a review from a team as a code owner January 30, 2026 21:42
@gh4683 gh4683 merged commit 6e23e3c into main Jan 30, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants