Repository navigation
wolfx509: verify via X509_STORE and support Intermediates - #61
Merged
Merged
Conversation
Back CertPool with a WOLFSSL_X509_STORE instead of the CertManager and verify with X509_verify_cert, so VerifyOptions.Intermediates is now used to build the chain.
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The ownership, locking, verification, tests, and documentation consistently implement the intended intermediate-chain support.
Review effort: Balanced
Findings: None
What changed in this PR
Switches certificate verification to X509_STORE, enabling untrusted intermediate-chain support while preserving safe native certificate ownership.
Changes:
- Adds X509 store, context, reference, and error wrappers.
- Supports
VerifyOptions.Intermediatesand serializes shared-root verification. - Updates tests and documentation for chain and trust-anchor behavior.
| File | Description |
|---|---|
x509.go |
Adds required wolfSSL X509 wrappers. |
wolfx509/cert_pool.go |
Replaces CertManager pools with reference-counted X509 stores. |
wolfx509/verify.go |
Builds and verifies chains using intermediates. |
wolfx509/x509_test.go |
Tests chains, trust boundaries, and concurrency. |
wolfx509/README.md |
Documents verification behavior. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
mattia-moffa
approved these changes
Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CertPoolwas backed by aWOLFSSL_CERT_MANAGER, which can't take a separateintermediates pool, so
VerifyrejectedVerifyOptions.Intermediates. Thisswitches the pool to a
WOLFSSL_X509_STOREand verifies withX509_verify_cert, usingIntermediatesto build the chain.Behavior changes
VerifyOptions.Intermediateswas rejected; it'snow used to build the chain but never trusted.
Rootswas trusted.Now only self-signed certs in
Rootsare; a non-self-signed CA also needsits self-signed root in
Roots. Callers that loaded intermediates intoRoots(as the old README advised) should pass them inIntermediates.Verifycalls sharing aRootspool now run one at a time,because
X509_verify_certmutates the store.