Skip to content

Add LDAP CRL download support - #624

Open
Roytak wants to merge 1 commit into
develfrom
ldap-crl-support
Open

Add LDAP CRL download support#624
Roytak wants to merge 1 commit into
develfrom
ldap-crl-support

Conversation

@Roytak

@Roytak Roytak commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Add native LDAP CRL download support by fetching the LDIF response via CURL and parsing it to extract the base64-encoded CRL. Also restrict allowed CURL protocols to HTTP(s) and, if supported by libcurl, LDAP(s) to prevent SSRF via malicious CRL distribution point URIs.

Fixes #604

Restrict allowed CURL protocols to HTTP(S) and, if supported by libcurl,
LDAP(S) to prevent SSRF via malicious CRL distribution point URIs. Add
native LDAP CRL download support by fetching the LDIF response via CURL
and parsing it to extract the base64-encoded CRL.

The LDIF parser handles curl's tab-indented output, folded continuation
lines and CRLF/LF line endings. Only known CRL attribute names
(certificateRevocationList, authorityRevocationList, deltaRevocationList,
optionally with ;binary per RFC 4523) are accepted, instead of any
binary attribute. URL scheme dispatch is case-insensitive per RFC 3986.

Fix nc_base64_decode_wrap (OpenSSL) to strip base64 padding from
EVP_DecodeBlock's return value, matching the documented contract and
the mbedTLS backend.

Fixes #604
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant