{"record":{"id":"6f0c15d2d81afb99","repo":"grpc/grpc-go","slug":"trailing-data-after-issuingdistributionpoint-exten","errorCode":null,"errorMessage":"trailing data after IssuingDistributionPoint extension","messagePattern":"trailing data after IssuingDistributionPoint extension","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"security/advancedtls/crl.go","lineNumber":341,"sourceCode":"\t\tswitch {\n\t\tcase oidDeltaCRLIndicator.Equal(ext.Id):\n\t\t\treturn nil, fmt.Errorf(\"delta CRLs unsupported\")\n\n\t\tcase oidAuthorityKeyIdentifier.Equal(ext.Id):\n\t\t\tvar a authKeyID\n\t\t\tif rest, err := asn1.Unmarshal(ext.Value, &a); err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"asn1.Unmarshal failed: %v\", err)\n\t\t\t} else if len(rest) != 0 {\n\t\t\t\treturn nil, errors.New(\"trailing data after AKID extension\")\n\t\t\t}\n\t\t\tcertList.authorityKeyID = a.ID\n\n\t\tcase oidIssuingDistributionPoint.Equal(ext.Id):\n\t\t\tvar dp issuingDistributionPoint\n\t\t\tif rest, err := asn1.Unmarshal(ext.Value, &dp); err != nil {\n\t\t\t\treturn nil, fmt.Errorf(\"asn1.Unmarshal failed: %v\", err)\n\t\t\t} else if len(rest) != 0 {\n\t\t\t\treturn nil, errors.New(\"trailing data after IssuingDistributionPoint extension\")\n\t\t\t}\n\n\t\t\tif dp.OnlyContainsUserCerts || dp.OnlyContainsCACerts || dp.OnlyContainsAttributeCerts {\n\t\t\t\treturn nil, errors.New(\"CRL only contains some certificate types\")\n\t\t\t}\n\t\t\tif dp.IndirectCRL {\n\t\t\t\treturn nil, errors.New(\"indirect CRLs unsupported\")\n\t\t\t}\n\t\t\tif dp.OnlySomeReasons.BitLength != 0 {\n\t\t\t\treturn nil, errors.New(\"onlySomeReasons unsupported\")\n\t\t\t}\n\n\t\tcase ext.Critical:\n\t\t\treturn nil, fmt.Errorf(\"unsupported critical extension: %v\", ext.Id)\n\t\t}\n\t}\n\n\tif len(certList.authorityKeyID) == 0 {","sourceCodeStart":323,"sourceCodeEnd":359,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/security/advancedtls/crl.go#L323-L359","documentation":"Returned by parseCRLExtensions when asn1.Unmarshal of the IssuingDistributionPoint extension decoded into issuingDistributionPoint but left trailing bytes. The IDP extension must be a single SEQUENCE; leftover bytes mean the encoding is malformed, so the CRL is rejected before use.","triggerScenarios":"The CRL's IssuingDistributionPoint extension has trailing bytes after the SEQUENCE (len(rest) != 0). Triggered while parsing extensions of a CRL supplied to the advancedtls CRL verifier.","commonSituations":"Corrupt CRL file. Non-conformant CA emits extra (unknown) fields inside the IDP extension. CRL transferred in text mode with byte-level corruption.","solutions":["Re-fetch the CRL from its distribution point.","Verify with openssl crl -inform DER -text -noout that the IDP extension parses cleanly.","If the issuer is consistently non-conformant, request a corrected CRL or remove CRL-based revocation for that chain."],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":"// Pre-check the IssuingDistributionPoint extension for trailing bytes.\nfunc precheckIDP(crlDER []byte) error {\n    l, err := x509.ParseRevocationList(crlDER)\n    if err != nil { return err }\n    for _, ext := range l.Extensions {\n        if ext.Id.Equal(oidIssuingDistributionPoint) {\n            var dp issuingDistributionPoint\n            rest, err := asn1.Unmarshal(ext.Value, &dp)\n            if err != nil { return err }\n            if len(rest) != 0 { return errors.New(\"IDP has trailing bytes\") }\n        }\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":"On parse error from CRL loading, log the CRL source, retain the previously known-good CRL, and schedule a retry. Do not silently skip revocation checks.","preventionTips":["Validate refreshed CRLs with openssl before swapping them in.","Pin CRL distribution points to TLS-verified HTTPS endpoints.","Alert on repeated parse failures of the same CRL distribution point."],"tags":["tls","crl","advancedtls","asn1","pkix","malformed"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}