Skip to content

certMatchesTemplate doesn't handle CKO_NSS_CRL #20

@JeremyRand

Description

@JeremyRand

My error logs indicate that occasionally, ncp11 is asked to match certs against a template that sets CKA_CLASS to CKO_NSS_CRL. Right now, ncp11 expects CKA_CLASS to always be either CKO_CERTIFICATE or CKO_NSS_TRUST, so it generates a warning (Template contains unknown CKA_CLASS 3461563217) in the error log. AFAICT the warning is harmless (ncp11 returns an empty list of objects, which is the correct behavior), but we should still fix it since it adds noise to the error logs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions