Page MenuHomeVyOS Platform

CRL generated by VyOS PKI lacks X.509 extensions required for strongSwan validation
Closed, ResolvedPublicBUG

Description

Summary

CRLs generated using the VyOS PKI subsystem do not include standard X.509 extensions (e.g., Authority Key Identifier, CRL Number). As a result, strongSwan cannot properly validate certificate revocation status during IKE authentication.

Steps to reproduce

  1. Generate a CA on VyOS:
run generate pki ca install <ca-name>
  1. Generate and sign certificates using that CA:
run generate pki certificate sign <ca-name> install <cert-A>
run generate pki certificate sign <ca-name> install <cert-B>
  1. Revoke one certificate:
set pki certificate <cert-B> revoke
  1. Generate and install the CRL:
run generate pki crl <ca-name> install
commit
  1. Configure IPsec site-to-site VPN using certificate authentication (referencing the CA and certificates)
  2. Check tunnel establishment — even though <cert-B> is revoked, the tunnel authentication still succeeds

Observed behavior

router-A charon[1234]: checking certificate status of "CN=<cert-B>"
router-A charon[1234]: certificate status is not available
router-A charon[1234]: authentication of 'CN=<cert-B>' with RSA_EMSA_PKCS1_SHA2_256 successful

This indicates that strongSwan is unable to verify certificate status using the CRL.

CRL inspection

openssl crl -text -noout -in /etc/swanctl/x509crl/<file>.pem

Output does not contain extensions:

Certificate Revocation List (CRL):
        Version 2 (0x1)
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN=<ca-name>
        Last Update: <timestamp>
        Next Update: <timestamp>
Revoked Certificates:
...

Example of CRL with required extensions:

Certificate Revocation List (CRL):
        Version 2 (0x1)
        Signature Algorithm: sha256WithRSAEncryption
        Issuer: CN=<ca-name>
        Last Update: <timestamp>
        Next Update: <timestamp>
        CRL extensions:
            X509v3 Authority Key Identifier:
                <key-id>
            X509v3 CRL Number:
                1
Revoked Certificates:
...

Expected behavior (CRL with proper extensions)

router-A charon[1234]: checking certificate status of "CN=<cert-B>"
router-A charon[1234]: using trusted certificate "CN=<ca-name>"
router-A charon[1234]: crl correctly signed by "CN=<ca-name>"
router-A charon[1234]: crl is valid: until Apr 28 00:28:05 2026
router-A charon[1234]: certificate was revoked on Apr 13 00:28:05 UTC 2026
router-A charon[1234]: generating IKE_AUTH response [ AUTH_FAILED ]

Conclusion

CRL generation in VyOS PKI lacks required X.509 extensions, preventing strongSwan from properly validating certificate revocation status.

Details

Version
1.4
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)