Re: Can import multiple certificates with same subject?

Hubert Kario <[email protected]>
Newsgroups gmane.comp.mozilla.crypto
Message-ID <[email protected]>
On Wednesday, 31 January 2018 06:43:19 CET John Jiang wrote:
> In order to describing my point clearly, please consider the below simple
> example.
> 
> 1. Two certificates with same subject (CN=www.example.com) and different
> nicknames (respectively, example1 and example2). Both of them are in PKCS12
> format.
> 
> 2. Import the certificates to an existing database
> $ pk12util -i example1.p12 -d sql:exampledb -W 'example1pass'
> pk12util: PKCS12 IMPORT SUCCESSFU
> $ pk12util -i example2.p12 -d sql:exampledb -W 'example2pass'
> pk12util: PKCS12 IMPORT SUCCESSFU
> 
> 3. List the certificates
> $ certutil -d sql:exampledb -L
> Certificate Nickname                                         Trust
> Attributes
> 
> SSL,S/MIME,JAR/XPI
> 
> example1
>                                         u,u,u
> example1
>                                            u,u,u
> Only nickname "example1" is listed.
> 
> 4. Display certificate example1
> $ certutil -d sql:exampledb -L -n example1
> Here, in deed, certificate example2 is displayed.
>
> It looks a bug.

This is expected and is an artefact of the way NSS stores certificates in the 
database. Since a newer certificate will be used when requested by 
application, it should not cause any problems.

> Best regards,
> John Jiang
> 
> 2018-01-31 13:07 GMT+08:00 John Jiang <[email protected]>:
> > Hi,
> > I'm using NSS 3.35.
> > 
> > With my testing, it is not allowed to import multiple certificates with
> > same subject and different nicknames to a certificate database via
> > pk12util. I just want to confirm this point.
> > 
> > Best regards,
> > John Jiang


-- 
Regards,
Hubert Kario
Senior Quality Engineer, QE BaseOS Security team
Web: www.cz.redhat.com
Red Hat Czech s.r.o., Purkyňova 115, 612 00  Brno, Czech Republic

-- 
dev-tech-crypto mailing list
[email protected]
https://lists.mozilla.org/listinfo/dev-tech-crypto
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEYeeuxEU+3unL/K+dkqjRuAHS9fUFAlp0U7sACgkQkqjRuAHS
9fWDMA//U3Dzk+DunjamhriWtt0GqbpDf3cZymCSd/EzGH+p5MDiY9Spad0brK6o
iQ/xxzHO1LSl3s4vBVHIjB4wEVUW5QwolOWqgT8JKdoLXPVO7B27xpVwNKOZ76+O
V3vZujhnKxWIrr1osWEdMt0eZhIWTmlGpr6597E7JQlSMkb/JsXbeWawdsWzHmhe
C12q6/7G2TWTMy7Dq5cz2mbgYXAv9by/RS6QqC/l00GtDmikYdAN0v6gdMaxrKip
QkRsWGN8dM/t7A2Ys5mfbf74tB/QNNNIfTBnbM3zXi4kghZuX0iAf0tPMS4R3wvG
Po4oww0pTYVEVq8qzYgTY1Xz9NqvCnD4DqGktI0RFgY5rzCc0J6qPwVX40CEZu6V
pnkMU4pRqvvgRmV8G6XyFdl7h6mnbRhzuB2XoMamxVLUEpUOVgeJ33of+uR7nxBr
45lyFdHPdNEqr34LsWIruW3qlU0RivBQIwGb4udMnbBYJM9ZVrorc2hwRIqH6CGM
WKisdOoBF1lunYZTrBXcuEo3B48LJiQW5AiIiAKUuQnMnGiHuqs6RH9dCExEGAy8
dQldDPRqv2sP5Z0oC1QSktN/D3Pgb9PO1ZxGnrDCQcbeI1JaOP5IeHZ+zLWjm7BZ
L78Ayy1I/Jb3mMCELBahlKrGGgwGOaH+9psrerXAt2JMIT2IwOI=
=m/0v
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.