grpc/grpc-go · error
CRL only contains some certificate types
Error message
CRL only contains some certificate types
What it means
Returned by parseCRLExtensions when the IssuingDistributionPoint extension indicates the CRL only covers a subset of cert types: onlyContainsUserCerts, onlyContainsCACerts, or onlyContainsAttributeCerts is set. grpc-go's CRL handling does not implement type-scoped revocation lists; such a partial CRL could give wrong answers, so it is rejected.
Solutions
- Use a complete (unscoped) CRL from the CA, i.e. one whose IDP extension does not restrict cert types.
- If only scoped CRLs are available, request the CA publish a full CRL or use OCSP for the scoped subset.
- Confirm the URL/file the CRL provider points at is the base CRL, not a partitioned/shard CRL.
Defensive patterns
Strategy: validation
Validate before calling
// Reject scoped CRLs before handing them to advancedtls.
func isFullCRL(crlDER []byte) (bool, error) {
l, err := x509.ParseRevocationList(crlDER)
if err != nil { return false, err }
for _, ext := range l.Extensions {
if ext.Id.Equal(oidIssuingDistributionPoint) {
var dp issuingDistributionPoint
if _, err := asn1.Unmarshal(ext.Value, &dp); err != nil { return false, err }
if dp.OnlyContainsUserCerts || dp.OnlyContainsCACerts || dp.OnlyContainsAttributeCerts {
return false, nil
}
}
}
return true, nil
} Try / catch
When loading CRLs, skip type-scoped ones with a logged warning; keep the previous full CRL active. Do not fall back to no-CRL silently.
Prevention
- Document which CRL distribution points serve full vs scoped CRLs.
- Add a pre-install check rejecting scoped CRLs for grpc-go workloads.
- Coordinate with PKI team to publish at least one base CRL per CA.
When it happens
Trigger: The CRL's IDP extension has one of OnlyContainsUserCerts / OnlyContainsCACerts / OnlyContainsAttributeCerts = true. Triggered during CRL parsing in the advancedtls package when loading a type-restricted CRL.
Common situations: A CA publishes separate CRLs for end-entity and CA certs (a common PKI practice). The operator pointed grpc-go's CRL provider at one of these scoped CRLs instead of a complete CRL. Enterprise PKI that uses attribute-cert CRLs.
Understand the failure class
- SSL/TLS and certificate errors — how TLS handshakes and certificate validation fail.
Related errors
- onlySomeReasons unsupported
- authority key identifier extension missing
- extractCRLIssuer: invalid ASN.1 encoding
- indirect CRLs unsupported
- no DN found in certificate issuer
AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11).
Data as JSON: /api/errors/ac9b671e4d245756.
Report an issue: GitHub.
Appendix: source
Thrown at security/advancedtls/crl.go:345
case oidAuthorityKeyIdentifier.Equal(ext.Id):
var a authKeyID
if rest, err := asn1.Unmarshal(ext.Value, &a); err != nil {
return nil, fmt.Errorf("asn1.Unmarshal failed: %v", err)
} else if len(rest) != 0 {
return nil, errors.New("trailing data after AKID extension")
}
certList.authorityKeyID = a.ID
case oidIssuingDistributionPoint.Equal(ext.Id):
var dp issuingDistributionPoint
if rest, err := asn1.Unmarshal(ext.Value, &dp); err != nil {
return nil, fmt.Errorf("asn1.Unmarshal failed: %v", err)
} else if len(rest) != 0 {
return nil, errors.New("trailing data after IssuingDistributionPoint extension")
}
if dp.OnlyContainsUserCerts || dp.OnlyContainsCACerts || dp.OnlyContainsAttributeCerts {
return nil, errors.New("CRL only contains some certificate types")
}
if dp.IndirectCRL {
return nil, errors.New("indirect CRLs unsupported")
}
if dp.OnlySomeReasons.BitLength != 0 {
return nil, errors.New("onlySomeReasons unsupported")
}
case ext.Critical:
return nil, fmt.Errorf("unsupported critical extension: %v", ext.Id)
}
}
if len(certList.authorityKeyID) == 0 {
return nil, errors.New("authority key identifier extension missing")
}
return certList, nil
}View on GitHub (pinned to 0c51461d27)