{"record":{"id":"c1ad59e448ac4dfb","repo":"grpc/grpc-go","slug":"authority-key-identifier-extension-missing","errorCode":null,"errorMessage":"authority key identifier extension missing","messagePattern":"authority key identifier extension missing","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"security/advancedtls/crl.go","lineNumber":360,"sourceCode":"\t\t\t}\n\n\t\t\tif dp.OnlyContainsUserCerts || dp.OnlyContainsCACerts || dp.OnlyContainsAttributeCerts {\n\t\t\t\treturn nil, errors.New(\"CRL only contains some certificate types\")\n\t\t\t}\n\t\t\tif dp.IndirectCRL {\n\t\t\t\treturn nil, errors.New(\"indirect CRLs unsupported\")\n\t\t\t}\n\t\t\tif dp.OnlySomeReasons.BitLength != 0 {\n\t\t\t\treturn nil, errors.New(\"onlySomeReasons unsupported\")\n\t\t\t}\n\n\t\tcase ext.Critical:\n\t\t\treturn nil, fmt.Errorf(\"unsupported critical extension: %v\", ext.Id)\n\t\t}\n\t}\n\n\tif len(certList.authorityKeyID) == 0 {\n\t\treturn nil, errors.New(\"authority key identifier extension missing\")\n\t}\n\treturn certList, nil\n}\n\nfunc verifyCRL(crl *CRL, chain []*x509.Certificate) error {\n\t// RFC5280, 6.3.3 (f) Obtain and validate the certification path for the issuer of the complete CRL\n\t// We intentionally limit our CRLs to be signed with the same certificate path as the certificate\n\t// so we can use the chain from the connection.\n\n\tfor _, c := range chain {\n\t\t// Use the key where the subject and KIDs match.\n\t\t// This departs from RFC4158, 3.5.12 which states that KIDs\n\t\t// cannot eliminate certificates, but RFC5280, 5.2.1 states that\n\t\t// \"Conforming CRL issuers MUST use the key identifier method, and MUST\n\t\t// include this extension in all CRLs issued.\"\n\t\t// So, this is much simpler than RFC4158 and should be compatible.\n\t\tif bytes.Equal(c.SubjectKeyId, crl.authorityKeyID) && bytes.Equal(c.RawSubject, crl.rawIssuer) {\n\t\t\t// RFC5280, 6.3.3 (f) Key usage and cRLSign bit.","sourceCodeStart":342,"sourceCodeEnd":378,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/security/advancedtls/crl.go#L342-L378","documentation":"Returned by parseCRLExtensions after iterating all extensions of the CRL: certList.authorityKeyID is still empty. RFC 5280 5.2.1 mandates the AuthorityKeyIdentifier extension in conforming CRLs; grpc-go relies on it to correlate the CRL to the issuing certificate's SubjectKeyId during signature verification. Without it, the CRL cannot be validated and is rejected.","triggerScenarios":"A CRL was parsed successfully but contained no AuthorityKeyIdentifier extension (oid 2.5.29.35). Triggered when loading a CRL via the advancedtls CRL provider.","commonSituations":"Non-conformant CA that omits AKID from CRLs (older OpenSSL versions, lightweight CAs, test CAs). CRL generated by minimal tooling that skips optional-but-expected extensions. Stripped-down CRL used in a constrained environment.","solutions":["Regenerate the CRL with the AuthorityKeyIdentifier extension included (default for conformant CA tooling).","If using OpenSSL, ensure the CA cert has a subjectKeyIdentifier so the generated CRL includes AKID.","Switch CA software or request the operator include the AKID extension on the CRL."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Require the AuthorityKeyIdentifier extension on any CRL we install.\nfunc crlHasAKID(crlDER []byte) (bool, error) {\n    l, err := x509.ParseRevocationList(crlDER)\n    if err != nil { return false, err }\n    for _, ext := range l.Extensions {\n        if ext.Id.Equal(oidAuthorityKeyIdentifier) { return true, nil }\n    }\n    return false, nil\n}","typeGuard":null,"tryCatchPattern":"On parse failure citing missing AKID, retain the previous CRL and alert. Coordinate with the CA to reissue a conformant CRL.","preventionTips":["Ensure issuing CA certs carry a subjectKeyIdentifier so generated CRLs include AKID.","Validate CRLs with openssl -text in CI to spot missing extensions.","Maintain a known-good CRL cache so missing-AKID refreshes do not break revocation."],"tags":["tls","crl","advancedtls","pkix","authority-key-id","missing-extension"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}