About this question
I'm trying to create an CA using cross-singing, and verify a certificate issued against one of the CAs, all using openssl. The best I got so far is getting openssl into an endless loop while verifying (the loop is terminated at level 100).
I've published all of the certs I created. Now, there are a number of assumptions that I'm making, and largely based on this Oasis document to build the model. Here are my assumptions:
- There should be 4 certificates, self-signed from authorities #1 and #2, and cross-signed, where authority #1 is signed by authority #2 and vice versa.
- There are only 2 actual subjects (DNs) used (the same subject used by an authority for self-signed is what it has signed by the other authority, albeit in a different cert).
- All 4 certificates should be the part of the end-user trust.
- The keys used by the same authority, for both self- and cross- signed certificates should be the same
- AKI should not be used (May be "shouldn't" is too of a strong word, but not using it shouldn't hurt. Because of the same keys rule, it shouldn't matter though)
- I tried setting CA:TRUE for cross-signed certs, with the same result.
What I understand from cross-signing, is that it gives the verification process alternative paths. Considering that I see openssl loop, it seems to be picking certificates with cross-signing every time. So the crux of the question is - what would make the verification process to favor the self-signed certificate over the one with cross-signing, considering both have the same subject.
Here is a test leaf certificate, I can't make openssl verify to verify it successfully.