Werk #16225: Ignore certificates with negative serial numbers

Komponente Setup
Titel Ignore certificates with negative serial numbers
Datum 24.11.2023
Checkmk Edition Checkmk Raw (CRE)
Checkmk-Version 2.3.0b1
Level Kleine Änderung
Klasse Bugfix
Kompatibilität Inkompatibel - Manuelle Interaktion könnte erforderlich sein

X509 certificates contain a serial number which is used for various purposes.

Since RFC5280 (May 2008) certificates must be a positive integer. There used to be certificates with negative serial numbers which were accepted. Our underlying libraries start to deprecate the support for these certificates, therefore Checkmk now deems them invalid.

Please note that these certificates are very uncommon. If Checkmk encounters such a certificate it will log it to var/log/web.log.

Zur Liste aller Werks