Bug 12909 - mozroots fails to import certs on Linux
Summary: mozroots fails to import certs on Linux
Alias: None
Product: Tools
Classification: Mono
Component: other ()
Version: unspecified
Hardware: PC Mac OS
: --- normal
Target Milestone: ---
Assignee: Sebastien Pouliot
Depends on:
Reported: 2013-06-26 17:19 UTC by Bojan Rajkovic [MSFT]
Modified: 2013-06-26 19:58 UTC (History)
1 user (show)

Is this bug a regression?: ---
Last known good build:

Notice (2018-05-24): bugzilla.xamarin.com is now in read-only mode.

Please join us on Visual Studio Developer Community and in the Xamarin and Mono organizations on GitHub to continue tracking issues. Bugzilla will remain available for reference in read-only mode. We will continue to work on open Bugzilla bugs, copy them to the new locations as needed for follow-up, and add the new items under Related Links.

Our sincere thanks to everyone who has contributed on this bug tracker over the years. Thanks also for your understanding as we make these adjustments and improvements for the future.

Please create a new report on GitHub or Developer Community with your current version information, steps to reproduce, and relevant error messages or log files if you are hitting an issue that looks similar to this resolved bug and you do not yet see a matching new report.

Related Links:

Description Bojan Rajkovic [MSFT] 2013-06-26 17:19:48 UTC
Mono version 3.0.12, built from the tarball, fails to import certs with the following exception:

Error: System.Security.Cryptography.CryptographicException: Unsupported hash algorithm: 1.2.840.10045.4.3.3
 at Mono.Security.Cryptography.PKCS1.HashNameFromOid (System.String oid)

Full excpetion at http://cl.ly/image/2V2D411Q0V0O, but too hard to retype the whole thing. :)
Comment 1 Sebastien Pouliot 2013-06-26 17:34:46 UTC
1.2.840.10045.4.3.3 uses ECC which Mono does not support (it's sha384ECDSA). 

The Hash property used to return null but now throws an exception (since recent refactoring).

It might be better to ignore/report this inside mozroot, before we silently ignored that CA.
Comment 2 Sebastien Pouliot 2013-06-26 19:58:37 UTC
Fixed in 85cb07992dcab999cd0503b5f82fe6f3462e1366

We won't throw, like before, to ensure we do not regress any other code/tool (beside mozroots). Installing a newer Mono.Security.dll will solve the issue in existing systems.