Werk #16225: Ignore certificates with negative serial numbers
Komponente | Setup |
Titel | Ignore certificates with negative serial numbers |
Datum | 24.11.2023 |
Checkmk Edition | Checkmk Raw (CRE) |
Checkmk-Version | 2.3.0b1 |
Level | Kleine Änderung |
Klasse | Bugfix |
Kompatibilität | Inkompatibel - Manuelle Interaktion könnte erforderlich sein |
X509 certificates contain a serial number which is used for various purposes.
Since RFC5280 (May 2008) certificates must be a positive integer. There used to be certificates with negative serial numbers which were accepted. Our underlying libraries start to deprecate the support for these certificates, therefore Checkmk now deems them invalid.
Please note that these certificates are very uncommon.
If Checkmk encounters such a certificate it will log it to var/log/web.log
.