Skip to content

fix: handle pending OpenSSL errors when reading legacy PKCS12 certificates - #67

Merged
vitormattos merged 2 commits into
mainfrom
test/pkcs12-openssl-error-queue
Sep 23, 2026
Merged

vitormattos merged 2 commits into
mainfrom
test/pkcs12-openssl-error-queue

Conversation

@vitormattos

@vitormattos vitormattos commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

fix: handle pending OpenSSL errors when reading legacy PKCS12 certificates

Description

Fixes legacy PKCS#12 handling when the OpenSSL error queue already contains errors from previous operations.

The regression test covers multiple sources of pending OpenSSL errors and demonstrates that the same valid legacy certificate could otherwise be reported as having an invalid password.

The PKCS#12 read flow now:

  • clears pending OpenSSL errors before reading the certificate;
  • collects all errors produced by a failed read;
  • detects the legacy algorithm error across the collected errors;
  • verifies that the repacked certificate can be read successfully.

The regression test failed with the previous implementation and passes with this change.

Signed-off-by: Vitor Mattos <1079143+vitormattos@users.noreply.github.com>
@vitormattos vitormattos changed the title test: cover legacy PKCS12 with pending OpenSSL errors fix: handle pending OpenSSL errors when reading legacy PKCS12 certificates Sep 23, 2026
@vitormattos
vitormattos merged commit 6f15037 into main Sep 23, 2026
9 checks passed
@vitormattos
vitormattos deleted the test/pkcs12-openssl-error-queue branch September 23, 2026 21:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant