amazon-archives / certlint

X.509 certificate linter
Apache License 2.0
157 stars 42 forks source link

.onion certs must have 2.23.140.1.31 extension #62

Open acohn opened 6 years ago

acohn commented 6 years ago

Ballot 201, effective 7 July 2017, requires that EV certificates for Tor .onion domains must have an extension (OID 2.23.140.1.31) containing a hash of the Tor service descriptor's public key.

At least one currently-valid certificate does not have this extension.