Fix RSA key size typo in trust anchor validation#15358
Open
immanuwell wants to merge 1 commit into
Open
Conversation
Problem `checkRSACertRequirements` rejects keys that aren't 2048 or 4096 bits, but the error message says "2084 bit" (typo for 2048) and "at least" which is misleading since 8192-bit keys are also rejected. Solution Fix the error string to say "2048 or 4096 bit", matching both the actual condition and the adjacent message on the next line. Add unit tests for `CheckTrustAnchorAlgoRequirements` with RSA keys. Validation go test ./pkg/issuercerts/... Signed-off-by: immanuwell <pchpr.00@list.ru>
adleong
approved these changes
Jun 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
checkRSACertRequirementsrejects keys that aren't 2048 or 4096 bits, but the error message says "2084 bit" (typo for 2048) and "at least" which is misleading since 8192-bit keys are also rejected.The typo has been there since #8868 introduced RSA trust anchor support.
Users hit this when running
linkerd checkwith an RSA trust anchor that has an unsupported key size (e.g. 1024 or 3072 bits).Solution
Fix the error string to say "2048 or 4096 bit", consistent with the adjacent line that already says "RSA 2048/4096 bit key".
Add unit tests for
CheckTrustAnchorAlgoRequirementswith RSA keys (the package had zero test coverage before).Validation
go test ./pkg/issuercerts/...
Signed-off-by: immanuwell pchpr.00@list.ru