Uploaded image for project: 'Gazelle Security Suite'
  1. Gazelle Security Suite
  2. GSS-528

E subject attribute is interpreted by bouncycastle as EMAILADDRESS

    Details

    • Type: Bug
    • Status: Submitted
    • Priority: Medium
    • Resolution: Unresolved
    • Affects Version/s: 6.0.0
    • Fix Version/s: None
    • Component/s: PKI
    • Labels:
      None
    • Account:
      Maintenance 2018 (MAINTENANCE2018)

      Description

      The email subject attribute of a certificate is shorten by GSS as "E". However, bouncycastle transform "E" into "EMAILADDRESS" during X509 generation and at display. At the end the subject in the certificate database object and in the X509 certificate is different.

      It does not cause any trouble, expect while importing a certificate into GSS (CA mapping action) or trying to find a X509 certificate based on its GSS' subject, such as PKIX validation in certificate validator.

      The certificate subject must be created using the long attribute version : ie "EMAILADDRESS" instead of "E".
      It may also be interesting to replace all previous ",E=" substring by ",EMAILADDRESS=" in order certificate db objects match with their X509.

        Attachments

          Issue Links

            Activity

              People

              Assignee:
              ceoche Cédric Eoche-Duval
              Reporter:
              ceoche Cédric Eoche-Duval
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Dates

                Created:
                Updated:

                  Time Tracking

                  Estimated:
                  Original Estimate - 5 hours
                  5h
                  Remaining:
                  Remaining Estimate - 5 hours
                  5h
                  Logged:
                  Time Spent - Not Specified
                  Not Specified

                    Potential Duplicates