grpc/grpc-go · error

CRL only contains some certificate types

Error message

CRL only contains some certificate types

What it means

Returned by parseCRLExtensions when the IssuingDistributionPoint extension indicates the CRL only covers a subset of cert types: onlyContainsUserCerts, onlyContainsCACerts, or onlyContainsAttributeCerts is set. grpc-go's CRL handling does not implement type-scoped revocation lists; such a partial CRL could give wrong answers, so it is rejected.

Solutions

  1. Use a complete (unscoped) CRL from the CA, i.e. one whose IDP extension does not restrict cert types.
  2. If only scoped CRLs are available, request the CA publish a full CRL or use OCSP for the scoped subset.
  3. Confirm the URL/file the CRL provider points at is the base CRL, not a partitioned/shard CRL.
Defensive patterns

Strategy: validation

Validate before calling

// Reject scoped CRLs before handing them to advancedtls.
func isFullCRL(crlDER []byte) (bool, error) {
    l, err := x509.ParseRevocationList(crlDER)
    if err != nil { return false, err }
    for _, ext := range l.Extensions {
        if ext.Id.Equal(oidIssuingDistributionPoint) {
            var dp issuingDistributionPoint
            if _, err := asn1.Unmarshal(ext.Value, &dp); err != nil { return false, err }
            if dp.OnlyContainsUserCerts || dp.OnlyContainsCACerts || dp.OnlyContainsAttributeCerts {
                return false, nil
            }
        }
    }
    return true, nil
}

Try / catch

When loading CRLs, skip type-scoped ones with a logged warning; keep the previous full CRL active. Do not fall back to no-CRL silently.

Prevention

When it happens

Trigger: The CRL's IDP extension has one of OnlyContainsUserCerts / OnlyContainsCACerts / OnlyContainsAttributeCerts = true. Triggered during CRL parsing in the advancedtls package when loading a type-restricted CRL.

Common situations: A CA publishes separate CRLs for end-entity and CA certs (a common PKI practice). The operator pointed grpc-go's CRL provider at one of these scoped CRLs instead of a complete CRL. Enterprise PKI that uses attribute-cert CRLs.

Understand the failure class

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/ac9b671e4d245756. Report an issue: GitHub.

Appendix: source

Thrown at security/advancedtls/crl.go:345

		case oidAuthorityKeyIdentifier.Equal(ext.Id):
			var a authKeyID
			if rest, err := asn1.Unmarshal(ext.Value, &a); err != nil {
				return nil, fmt.Errorf("asn1.Unmarshal failed: %v", err)
			} else if len(rest) != 0 {
				return nil, errors.New("trailing data after AKID extension")
			}
			certList.authorityKeyID = a.ID

		case oidIssuingDistributionPoint.Equal(ext.Id):
			var dp issuingDistributionPoint
			if rest, err := asn1.Unmarshal(ext.Value, &dp); err != nil {
				return nil, fmt.Errorf("asn1.Unmarshal failed: %v", err)
			} else if len(rest) != 0 {
				return nil, errors.New("trailing data after IssuingDistributionPoint extension")
			}

			if dp.OnlyContainsUserCerts || dp.OnlyContainsCACerts || dp.OnlyContainsAttributeCerts {
				return nil, errors.New("CRL only contains some certificate types")
			}
			if dp.IndirectCRL {
				return nil, errors.New("indirect CRLs unsupported")
			}
			if dp.OnlySomeReasons.BitLength != 0 {
				return nil, errors.New("onlySomeReasons unsupported")
			}

		case ext.Critical:
			return nil, fmt.Errorf("unsupported critical extension: %v", ext.Id)
		}
	}

	if len(certList.authorityKeyID) == 0 {
		return nil, errors.New("authority key identifier extension missing")
	}
	return certList, nil
}

View on GitHub (pinned to 0c51461d27)