{"record":{"id":"5a68df2a75469ca9","repo":"grpc/grpc-go","slug":"onlysomereasons-unsupported","errorCode":null,"errorMessage":"onlySomeReasons unsupported","messagePattern":"onlySomeReasons unsupported","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"security/advancedtls/crl.go","lineNumber":351,"sourceCode":"\t\t\t}\n\t\t\tcertList.authorityKeyID = a.ID\n\n\t\tcase oidIssuingDistributionPoint.Equal(ext.Id):\n\t\t\tvar dp issuingDistributionPoint\n\t\t\tif rest, err := asn1.Unmarshal(ext.Value, &dp); err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"asn1.Unmarshal failed: %v\", err)\n\t\t\t} else if len(rest) != 0 {\n\t\t\t\treturn nil, errors.New(\"trailing data after IssuingDistributionPoint extension\")\n\t\t\t}\n\n\t\t\tif dp.OnlyContainsUserCerts || dp.OnlyContainsCACerts || dp.OnlyContainsAttributeCerts {\n\t\t\t\treturn nil, errors.New(\"CRL only contains some certificate types\")\n\t\t\t}\n\t\t\tif dp.IndirectCRL {\n\t\t\t\treturn nil, errors.New(\"indirect CRLs unsupported\")\n\t\t\t}\n\t\t\tif dp.OnlySomeReasons.BitLength != 0 {\n\t\t\t\treturn nil, errors.New(\"onlySomeReasons unsupported\")\n\t\t\t}\n\n\t\tcase ext.Critical:\n\t\t\treturn nil, fmt.Errorf(\"unsupported critical extension: %v\", ext.Id)\n\t\t}\n\t}\n\n\tif len(certList.authorityKeyID) == 0 {\n\t\treturn nil, errors.New(\"authority key identifier extension missing\")\n\t}\n\treturn certList, nil\n}\n\nfunc verifyCRL(crl *CRL, chain []*x509.Certificate) error {\n\t// RFC5280, 6.3.3 (f) Obtain and validate the certification path for the issuer of the complete CRL\n\t// We intentionally limit our CRLs to be signed with the same certificate path as the certificate\n\t// so we can use the chain from the connection.\n","sourceCodeStart":333,"sourceCodeEnd":369,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/security/advancedtls/crl.go#L333-L369","documentation":"Returned by parseCRLExtensions when the IssuingDistributionPoint extension carries a non-empty onlySomeReasons bit string. onlySomeReasons narrows a CRL to revocations for specific reason codes (e.g. keyCompromise only); grpc-go does not implement reason-scoped revocation matching, so such CRLs are rejected to avoid false 'unrevoked' answers.","triggerScenarios":"The CRL's IDP extension has OnlySomeReasons with a non-zero BitLength. Encountered while parsing the CRL in the advancedtls CRL verifier.","commonSituations":"A CA publishes reason-partitioned CRLs (one for keyCompromise, one for caCompromise, etc.). Operator pointed the CRL provider at one of these partitions. Specialized enterprise PKI that splits revocation by reason.","solutions":["Provide a full CRL whose IDP does not set onlySomeReasons.","If reason partitioning is mandatory, fall back to OCSP for revocation status.","Confirm with the CA that a base (unpartitioned) CRL is available at a different distribution point."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Reject reason-scoped CRLs up front.\nfunc isUnscopedCRL(crlDER []byte) (bool, error) {\n    l, err := x509.ParseRevocationList(crlDER)\n    if err != nil { return false, err }\n    for _, ext := range l.Extensions {\n        if ext.Id.Equal(oidIssuingDistributionPoint) {\n            var dp issuingDistributionPoint\n            if _, err := asn1.Unmarshal(ext.Value, &dp); err != nil { return false, err }\n            if dp.OnlySomeReasons.BitLength != 0 { return false, nil }\n        }\n    }\n    return true, nil\n}","typeGuard":null,"tryCatchPattern":"Treat the parse error as 'CRL not usable'; keep the previous unscoped CRL active. Alert PKI/ops so a base CRL is published.","preventionTips":["Inventory your CA's CRL distribution points by scope.","Prefer OCSP for chains that only publish reason-partitioned CRLs.","Add a deployment-time check that rejects onlySomeReasons CRLs."],"tags":["tls","crl","advancedtls","pkix","issuing-distribution-point","reason-codes"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}