Allow authority key identifier to be NULL, as seen on EL9 with CILogon client cert #120
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
CILogon client certificates do not have an X509v3 extension called
X509v3 Authority Key Identifier
. On EL7 (at least) when looking up that identifier the result is a structure with a-1
error indicator in it, but on EL9 (at least) the result is just NULL. This currently causes voms-proxy-init to exit (without a helpful error message even in-debug
mode, by the way). So silently ignore that condition instead of returning an error.