Mark Laing discovered in LXDs PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
Weakness
The product does not validate, or incorrectly validates, a certificate.
Potential Mitigations
References