{"record":{"id":"ba17047667eaafb2","repo":"grpc/grpc-go","slug":"no-dn-found-in-certificate-issuer","errorCode":null,"errorMessage":"no DN found in certificate issuer","messagePattern":"no DN found in certificate issuer","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"warning","filePath":"security/advancedtls/crl.go","lineNumber":284,"sourceCode":"\t\t// otherName                       [0]     OtherName,\n\t\t// rfc822Name                      [1]     IA5String,\n\t\t// dNSName                         [2]     IA5String,\n\t\t// x400Address                     [3]     ORAddress,\n\t\t// directoryName                   [4]     Name,\n\t\t// ediPartyName                    [5]     EDIPartyName,\n\t\t// uniformResourceIdentifier       [6]     IA5String,\n\t\t// iPAddress                       [7]     OCTET STRING,\n\t\t// registeredID                    [8]     OBJECT IDENTIFIER }\n\t\tif generalName.Tag == tagDirectoryName {\n\t\t\treturn generalName.Bytes, nil\n\t\t}\n\t}\n\t// Conforming CRL issuers MUST include in this extension the\n\t// distinguished name (DN) from the issuer field of the certificate that\n\t// corresponds to this CRL entry.\n\t// If we couldn't get a directoryName, we can't reason about this file so cert status is\n\t// RevocationUndetermined.\n\treturn nil, errors.New(\"no DN found in certificate issuer\")\n}\n\n// RFC 5280,  4.2.1.1\ntype authKeyID struct {\n\tID []byte `asn1:\"optional,tag:0\"`\n}\n\n// RFC5280, 5.2.5\n// id-ce-issuingDistributionPoint OBJECT IDENTIFIER ::= { id-ce 28 }\n\n// IssuingDistributionPoint ::= SEQUENCE {\n// \t\tdistributionPoint          [0] DistributionPointName OPTIONAL,\n// \t\tonlyContainsUserCerts      [1] BOOLEAN DEFAULT FALSE,\n// \t\tonlyContainsCACerts        [2] BOOLEAN DEFAULT FALSE,\n// \t\tonlySomeReasons            [3] ReasonFlags OPTIONAL,\n// \t\tindirectCRL                [4] BOOLEAN DEFAULT FALSE,\n// \t\tonlyContainsAttributeCerts [5] BOOLEAN DEFAULT FALSE }\n","sourceCodeStart":266,"sourceCodeEnd":302,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/security/advancedtls/crl.go#L266-L302","documentation":"Returned by parseCertIssuerExt when parsing the CRL entry's Certificate Issuer extension (RFC 5280 5.3.3, only present in indirect CRLs). The code walks the GeneralNames sequence looking for a directoryName [4] entry to use as the issuer DN; if none is present, the library cannot correlate the entry to a certificate and the cert's revocation status is treated as undetermined.","triggerScenarios":"A CRL contains per-entry Certificate Issuer extensions (i.e. it is structured as an indirect CRL) but the issuer extension lists only non-directoryName GeneralNames (e.g. DNSName, URI) and no [4] directoryName. Encountered during revocation checking of a peer cert against such a CRL.","commonSituations":"An indirect-CRL-shaped revocation list from a CA that uses URI/DNS-based issuer naming instead of DNs. Compatibility mismatch: the CRL was generated by tooling that omits the directoryName variant. grpc-go's CRL support is intentionally narrow (see the indirect-CRL rejection elsewhere) so non-DN issuers are not handled.","solutions":["Regenerate the CRL so the Certificate Issuer extension includes a directoryName [4] entry matching the certificate's issuer DN, or stop using indirect CRLs entirely.","Switch to a direct CRL (issuer DN in the top-level tbsCertList.issuer matches the cert issuer).","If the CRL is from an upstream CA you don't control, request a direct-CRL variant or fall back to OCSP for revocation checks."],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":"Treat the error as revocation status RevocationUndetermined (the library already does this internally); do not fail the handshake hard. Configure the advancedtls verifier to decide undetermined as allow or deny per your security posture.","preventionTips":["Prefer direct CRLs (issuer == cert issuer) over indirect CRLs.","Validate CA-issued CRLs in CI against grpc-go's parser before deploying.","Document for PKI admins that grpc-go requires directoryName-based issuer entries."],"tags":["tls","crl","advancedtls","pkix","indirect-crl","asn1"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}