Skip to content

wolfx509: verify via X509_STORE and support Intermediates - #61

Merged
mattia-moffa merged 2 commits into
masterfrom
wolfx509-x509-store-verify
Oct 6, 2026
Merged

mattia-moffa merged 2 commits into
masterfrom
wolfx509-x509-store-verify

Conversation

@lealem47

@lealem47 lealem47 commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

CertPool was backed by a WOLFSSL_CERT_MANAGER, which can't take a separate
intermediates pool, so Verify rejected VerifyOptions.Intermediates. This
switches the pool to a WOLFSSL_X509_STORE and verifies with
X509_verify_cert, using Intermediates to build the chain.

Behavior changes

  • Intermediates supported. VerifyOptions.Intermediates was rejected; it's
    now used to build the chain but never trusted.
  • Stricter trust anchors. Previously any CA cert in Roots was trusted.
    Now only self-signed certs in Roots are; a non-self-signed CA also needs
    its self-signed root in Roots. Callers that loaded intermediates into
    Roots (as the old README advised) should pass them in Intermediates.
  • Concurrency. Verify calls sharing a Roots pool now run one at a time,
    because X509_verify_cert mutates the store.

  Back CertPool with a WOLFSSL_X509_STORE instead of the CertManager
  and verify with X509_verify_cert, so VerifyOptions.Intermediates is
  now used to build the chain.
@lealem47 lealem47 self-assigned this Oct 6, 2026
Copilot AI balanced review requested due to automatic review settings October 6, 2026 01:09

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The ownership, locking, verification, tests, and documentation consistently implement the intended intermediate-chain support.

Review effort: Balanced
Findings: None

What changed in this PR

Switches certificate verification to X509_STORE, enabling untrusted intermediate-chain support while preserving safe native certificate ownership.

Changes:

  • Adds X509 store, context, reference, and error wrappers.
  • Supports VerifyOptions.Intermediates and serializes shared-root verification.
  • Updates tests and documentation for chain and trust-anchor behavior.
File Description
x509.go Adds required wolfSSL X509 wrappers.
wolfx509/​cert_pool.go Replaces CertManager pools with reference-counted X509 stores.
wolfx509/​verify.go Builds and verifies chains using intermediates.
wolfx509/​x509_test.go Tests chains, trust boundaries, and concurrency.
wolfx509/​README.md Documents verification behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@lealem47 lealem47 assigned mattia-moffa and unassigned lealem47 Oct 6, 2026
@lealem47
lealem47 requested a review from mattia-moffa October 6, 2026 01:43
@mattia-moffa
mattia-moffa merged commit a743031 into master Oct 6, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants