Skip to content

Commit ab16374

Browse files
committed
Clarify PKIXNameConstraints divergence from bc-csharp
1 parent 3835693 commit ab16374

1 file changed

Lines changed: 7 additions & 2 deletions

File tree

‎prov/src/test/java/org/bouncycastle/jce/provider/test/PKIXNameConstraintsTest.java‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -335,8 +335,13 @@ private void testEmptyLabelRefused() throws Exception
335335
isTrue("a doubled dot in a quoted local part must not be refused, and the host still matches",
336336
isExcluded(emailName("bank.com"), emailName("\"a..b\"@bank.com")));
337337

338-
// a bare "." is the root label, not an empty one, and is left alone.
339-
isTrue("a bare root label must not be refused", !isExcluded(dnsName("example.com"), dnsName(".")));
338+
// a bare "." is the root label, not an empty one: it is not refused as malformed, it is simply
339+
// outside the subtree in both directions. (bc-csharp fails it closed as a tested name; aligning
340+
// that is deferred to a broader constraint-name vs tested-name rework.)
341+
isTrue("a bare root label as a tested name must not be refused",
342+
!isExcluded(dnsName("example.com"), dnsName(".")));
343+
isTrue("a bare root label as a tested name must not be permitted",
344+
!isPermitted(dnsName("example.com"), dnsName(".")));
340345

341346
// nothing is refused where no constraint of that type is in force.
342347
isTrue("an empty label is immaterial with no dNSName constraint",

0 commit comments

Comments
 (0)