-/* $OpenBSD: rsc.c,v 1.8 2022/06/01 10:59:21 tb Exp $ */
+/* $OpenBSD: rsc.c,v 1.9 2022/06/04 02:14:21 tb Exp $ */
/*
* Copyright (c) 2022 Theo Buehler <tb@openbsd.org>
* Copyright (c) 2022 Job Snijders <job@fastly.com>
goto out;
}
- switch(rsc_version) {
+ switch (rsc_version) {
case 0:
warnx("%s: RSC: incorrect version encoding", p->fn);
goto out;
goto out;
}
+ if (X509_get_ext_by_NID(*x509, NID_sinfo_access, -1) != -1) {
+ warnx("%s: EE certificate MUST NOT have SIA extension", fn);
+ goto out;
+ }
+
at = X509_get0_notAfter(*x509);
if (at == NULL) {
warnx("%s: X509_get0_notAfter failed", fn);