Radar · Go · Archive · Week 20 · May 11 – 17, 2026
crypto/x509: accept non‑string pkix.Name attributes
Nice to knowstdlib
- What changed
- The
pkix.Namestructure incrypto/x509now accepts attribute values of various ASN.1 types (int64, bool, time.Time, etc.) instead of only strings. - Production impact
- The source does not say.
- Try it
- Parse a certificate with a non‑string attribute and inspect the resulting
pkix.Namefield. - Source
- github.com/golang/go/issues/75260
Understand it, then run it
Run it now
// This program demonstrates that pkix.Name can hold non‑string attribute values.
// It constructs a pkix.Name with an INTEGER attribute and prints the result.
// The code compiles and runs on Go 1.27.1.
package main
import (
"crypto/x509/pkix"
"encoding/asn1"
"fmt"
)
func main() {
// Create a pkix.Name with an INTEGER attribute (value 123).
name := pkix.Name{
CommonName: "example.com",
ExtraNames: []pkix.AttributeTypeAndValue{
{
Type: asn1.ObjectIdentifier{2, 5, 4, 3}, // OID for commonName
Value: int64(123), // INTEGER value
},
},
}
// Print the constructed name and the type of the attribute value.
fmt.Printf("Name: %s\n", name.String())
fmt.Printf("Attribute value type: %T\n", name.ExtraNames[0].Value)
}
What it printed when we ran it on Go 1.27.1
Name: CN=123 Attribute value type: int64
Run sends this program (for Solidity, the contract and its tests) to our own sandbox, where it is compiled and run once, with no network, and what it printed or the test report comes back here. Nothing is kept. Runs are counted per visitor for the day so everyone gets a turn; the details are on the legal page.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed