|
|
f64bd5 |
From 1c464828a5ad8f47a6acf7b6d6ec1f324fe63b51 Mon Sep 17 00:00:00 2001
|
|
|
f64bd5 |
From: Nalin Dahyabhai <nalin@redhat.com>
|
|
|
f64bd5 |
Date: Tue, 12 Jan 2016 17:27:18 -0500
|
|
|
f64bd5 |
Subject: [PATCH] Stop assuming RSA 512 works
|
|
|
f64bd5 |
|
|
|
f64bd5 |
For the sake of F24, stop assuming that we'll be able to generate
|
|
|
f64bd5 |
512-bit RSA keys. We use certutil to do some of it, and it doesn't give
|
|
|
f64bd5 |
us a way to toggle support on.
|
|
|
f64bd5 |
---
|
|
|
f64bd5 |
tests/001-keyiread-rsa/expected.out | 2 -
|
|
|
f64bd5 |
tests/001-keyiread-rsa/run.sh | 4 +-
|
|
|
f64bd5 |
tests/001-keyiread/expected.out | 2 -
|
|
|
f64bd5 |
tests/001-keyiread/run.sh | 4 +-
|
|
|
f64bd5 |
tests/002-keygen-dsa/expected.out | 6 --
|
|
|
f64bd5 |
tests/002-keygen-dsa/run.sh | 4 +-
|
|
|
f64bd5 |
tests/002-keygen-rsa/expected.out | 6 --
|
|
|
f64bd5 |
tests/002-keygen-rsa/run.sh | 4 +-
|
|
|
f64bd5 |
tests/002-keygen/expected.out | 18 -----
|
|
|
f64bd5 |
tests/002-keygen/run.sh | 4 +-
|
|
|
f64bd5 |
tests/003-csrgen-rsa/expected.out | 124 ++++++++++++++--------------
|
|
|
f64bd5 |
tests/003-csrgen-rsa/run.sh | 4 +-
|
|
|
f64bd5 |
tests/003-csrgen/expected.out | 157 +++++++++++++++++-------------------
|
|
|
f64bd5 |
tests/003-csrgen/run.sh | 4 +-
|
|
|
f64bd5 |
tests/004-selfsign-rsa/expected.out | 1 -
|
|
|
f64bd5 |
tests/004-selfsign-rsa/run.sh | 2 +-
|
|
|
f64bd5 |
tests/004-selfsign/expected.out | 1 -
|
|
|
f64bd5 |
tests/004-selfsign/run.sh | 2 +-
|
|
|
f64bd5 |
18 files changed, 152 insertions(+), 197 deletions(-)
|
|
|
f64bd5 |
|
|
|
f64bd5 |
diff --git a/tests/001-keyiread-rsa/expected.out b/tests/001-keyiread-rsa/expected.out
|
|
|
f64bd5 |
index fa3493c04b26eb676700abdab7895fe0a1ee3d6d..727897d14f9a3eb8eab8c3b12964fa7d38cefdef 100644
|
|
|
f64bd5 |
--- a/tests/001-keyiread-rsa/expected.out
|
|
|
f64bd5 |
+++ b/tests/001-keyiread-rsa/expected.out
|
|
|
f64bd5 |
@@ -1,10 +1,8 @@
|
|
|
f64bd5 |
-OK (RSA:512).
|
|
|
f64bd5 |
OK (RSA:1024).
|
|
|
f64bd5 |
OK (RSA:1536).
|
|
|
f64bd5 |
OK (RSA:2048).
|
|
|
f64bd5 |
OK (RSA:3072).
|
|
|
f64bd5 |
OK (RSA:4096).
|
|
|
f64bd5 |
-OK (RSA:512).
|
|
|
f64bd5 |
OK (RSA:1024).
|
|
|
f64bd5 |
OK (RSA:1536).
|
|
|
f64bd5 |
OK (RSA:2048).
|
|
|
f64bd5 |
diff --git a/tests/001-keyiread-rsa/run.sh b/tests/001-keyiread-rsa/run.sh
|
|
|
f64bd5 |
index b5ac7150b80af45a23a56be6a49f3884a9f5049a..c7b7768690e80a9f3fcba0e42fe4a96b60efe48c 100755
|
|
|
f64bd5 |
--- a/tests/001-keyiread-rsa/run.sh
|
|
|
f64bd5 |
+++ b/tests/001-keyiread-rsa/run.sh
|
|
|
f64bd5 |
@@ -5,7 +5,7 @@ cd "$tmpdir"
|
|
|
f64bd5 |
source "$srcdir"/functions
|
|
|
f64bd5 |
initnssdb "$tmpdir"
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
# Generate a self-signed cert.
|
|
|
f64bd5 |
run_certutil -d "$tmpdir" -S -g $size -n keyi$size \
|
|
|
f64bd5 |
-s "cn=T$size" -c "cn=T$size" \
|
|
|
f64bd5 |
@@ -30,7 +30,7 @@ for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
$toolsdir/keyiread entry.nss.$size
|
|
|
f64bd5 |
done
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
# Generate a key.
|
|
|
f64bd5 |
openssl genrsa $size > sample.$size 2> /dev/null
|
|
|
f64bd5 |
# Check the size of the key.
|
|
|
f64bd5 |
diff --git a/tests/001-keyiread/expected.out b/tests/001-keyiread/expected.out
|
|
|
f64bd5 |
index fa3493c04b26eb676700abdab7895fe0a1ee3d6d..727897d14f9a3eb8eab8c3b12964fa7d38cefdef 100644
|
|
|
f64bd5 |
--- a/tests/001-keyiread/expected.out
|
|
|
f64bd5 |
+++ b/tests/001-keyiread/expected.out
|
|
|
f64bd5 |
@@ -1,10 +1,8 @@
|
|
|
f64bd5 |
-OK (RSA:512).
|
|
|
f64bd5 |
OK (RSA:1024).
|
|
|
f64bd5 |
OK (RSA:1536).
|
|
|
f64bd5 |
OK (RSA:2048).
|
|
|
f64bd5 |
OK (RSA:3072).
|
|
|
f64bd5 |
OK (RSA:4096).
|
|
|
f64bd5 |
-OK (RSA:512).
|
|
|
f64bd5 |
OK (RSA:1024).
|
|
|
f64bd5 |
OK (RSA:1536).
|
|
|
f64bd5 |
OK (RSA:2048).
|
|
|
f64bd5 |
diff --git a/tests/001-keyiread/run.sh b/tests/001-keyiread/run.sh
|
|
|
f64bd5 |
index d95043d164e133ed23148719b74513d745ebec66..ce1428edd8d022d8a7f7f735154234bbdc4bf228 100755
|
|
|
f64bd5 |
--- a/tests/001-keyiread/run.sh
|
|
|
f64bd5 |
+++ b/tests/001-keyiread/run.sh
|
|
|
f64bd5 |
@@ -5,7 +5,7 @@ cd "$tmpdir"
|
|
|
f64bd5 |
source "$srcdir"/functions
|
|
|
f64bd5 |
initnssdb "$tmpdir"
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
# Generate a self-signed cert.
|
|
|
f64bd5 |
run_certutil -d "$tmpdir" -S -g $size -n keyi$size \
|
|
|
f64bd5 |
-s "cn=T$size" -c "cn=T$size" \
|
|
|
f64bd5 |
@@ -30,7 +30,7 @@ for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
$toolsdir/keyiread entry.nss.$size
|
|
|
f64bd5 |
done
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
# Generate a key.
|
|
|
f64bd5 |
openssl genrsa $size > sample.$size 2> /dev/null
|
|
|
f64bd5 |
# Check the size of the key.
|
|
|
f64bd5 |
diff --git a/tests/002-keygen-dsa/expected.out b/tests/002-keygen-dsa/expected.out
|
|
|
f64bd5 |
index f2a44d26286605c4186963f6c43b6dbd6e2e81cc..7445bcc2628dd78eef0cea4c90339c79fb3571cf 100644
|
|
|
f64bd5 |
--- a/tests/002-keygen-dsa/expected.out
|
|
|
f64bd5 |
+++ b/tests/002-keygen-dsa/expected.out
|
|
|
f64bd5 |
@@ -1,6 +1,3 @@
|
|
|
f64bd5 |
-[nss:512]
|
|
|
f64bd5 |
-OK.
|
|
|
f64bd5 |
-OK (DSA:512).
|
|
|
f64bd5 |
[nss:1024]
|
|
|
f64bd5 |
OK.
|
|
|
f64bd5 |
OK (DSA:1024).
|
|
|
f64bd5 |
@@ -20,9 +17,6 @@ OK (DSA:3072).
|
|
|
f64bd5 |
Failed to save NSS:${tmpdir}/rosubdir: need fs permissions.
|
|
|
f64bd5 |
[nss:rwsubdir]
|
|
|
f64bd5 |
Failed to save NSS:${tmpdir}/rwsubdir: need fs permissions.
|
|
|
f64bd5 |
-[openssl:512]
|
|
|
f64bd5 |
-OK.
|
|
|
f64bd5 |
-OK (DSA:512).
|
|
|
f64bd5 |
[openssl:1024]
|
|
|
f64bd5 |
OK.
|
|
|
f64bd5 |
OK (DSA:1024).
|
|
|
f64bd5 |
diff --git a/tests/002-keygen-dsa/run.sh b/tests/002-keygen-dsa/run.sh
|
|
|
f64bd5 |
index fad19de1d365466c0bfd739fbd8be1be9135a291..d9cff0e973bcdffcbeda4c702d3ee86b27d07e43 100755
|
|
|
f64bd5 |
--- a/tests/002-keygen-dsa/run.sh
|
|
|
f64bd5 |
+++ b/tests/002-keygen-dsa/run.sh
|
|
|
f64bd5 |
@@ -5,7 +5,7 @@ cd "$tmpdir"
|
|
|
f64bd5 |
source "$srcdir"/functions
|
|
|
f64bd5 |
initnssdb "$tmpdir"
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
echo "[nss:$size]"
|
|
|
f64bd5 |
# Generate a key.
|
|
|
f64bd5 |
cat > entry.$size <<- EOF
|
|
|
f64bd5 |
@@ -41,7 +41,7 @@ key_gen_type=DSA
|
|
|
f64bd5 |
EOF
|
|
|
f64bd5 |
$toolsdir/keygen entry.$size || true
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
echo "[openssl:$size]"
|
|
|
f64bd5 |
# Generate a key.
|
|
|
f64bd5 |
cat > entry.$size <<- EOF
|
|
|
f64bd5 |
diff --git a/tests/002-keygen-rsa/expected.out b/tests/002-keygen-rsa/expected.out
|
|
|
f64bd5 |
index 33f0f48ea92e0b7fa17ccc6a1938fe37d7335c8a..3e6e9f3c1b293a0a9c16085bfbf243d44e43e129 100644
|
|
|
f64bd5 |
--- a/tests/002-keygen-rsa/expected.out
|
|
|
f64bd5 |
+++ b/tests/002-keygen-rsa/expected.out
|
|
|
f64bd5 |
@@ -1,6 +1,3 @@
|
|
|
f64bd5 |
-[nss:512]
|
|
|
f64bd5 |
-OK.
|
|
|
f64bd5 |
-OK (RSA:512).
|
|
|
f64bd5 |
[nss:1024]
|
|
|
f64bd5 |
OK.
|
|
|
f64bd5 |
OK (RSA:1024).
|
|
|
f64bd5 |
@@ -20,9 +17,6 @@ OK (RSA:4096).
|
|
|
f64bd5 |
Failed to save NSS:${tmpdir}/rosubdir: need fs permissions.
|
|
|
f64bd5 |
[nss:rwsubdir]
|
|
|
f64bd5 |
Failed to save NSS:${tmpdir}/rwsubdir: need fs permissions.
|
|
|
f64bd5 |
-[openssl:512]
|
|
|
f64bd5 |
-OK.
|
|
|
f64bd5 |
-OK (RSA:512).
|
|
|
f64bd5 |
[openssl:1024]
|
|
|
f64bd5 |
OK.
|
|
|
f64bd5 |
OK (RSA:1024).
|
|
|
f64bd5 |
diff --git a/tests/002-keygen-rsa/run.sh b/tests/002-keygen-rsa/run.sh
|
|
|
f64bd5 |
index b133edd8535db75804c82f7505e055c9b1bd0aa2..476f412753511772c506e76d8f3bb9c128b8aa1e 100755
|
|
|
f64bd5 |
--- a/tests/002-keygen-rsa/run.sh
|
|
|
f64bd5 |
+++ b/tests/002-keygen-rsa/run.sh
|
|
|
f64bd5 |
@@ -5,7 +5,7 @@ cd "$tmpdir"
|
|
|
f64bd5 |
source "$srcdir"/functions
|
|
|
f64bd5 |
initnssdb "$tmpdir"
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
echo "[nss:$size]"
|
|
|
f64bd5 |
# Generate a key.
|
|
|
f64bd5 |
cat > entry.$size <<- EOF
|
|
|
f64bd5 |
@@ -41,7 +41,7 @@ key_gen_type=RSA
|
|
|
f64bd5 |
EOF
|
|
|
f64bd5 |
$toolsdir/keygen entry.$size || true
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
echo "[openssl:$size]"
|
|
|
f64bd5 |
# Generate a key.
|
|
|
f64bd5 |
cat > entry.$size <<- EOF
|
|
|
f64bd5 |
diff --git a/tests/002-keygen/expected.out b/tests/002-keygen/expected.out
|
|
|
f64bd5 |
index f47d2d564bfd36d8d944bc388119314ee41c3722..ff56372aac282743f79699b0b381fcf198bd5db4 100644
|
|
|
f64bd5 |
--- a/tests/002-keygen/expected.out
|
|
|
f64bd5 |
+++ b/tests/002-keygen/expected.out
|
|
|
f64bd5 |
@@ -1,12 +1,3 @@
|
|
|
f64bd5 |
-[nss:512]
|
|
|
f64bd5 |
-OK.
|
|
|
f64bd5 |
-OK (RSA:512).
|
|
|
f64bd5 |
-OK.
|
|
|
f64bd5 |
-OK (RSA:512 after RSA:512).
|
|
|
f64bd5 |
-OK.
|
|
|
f64bd5 |
-OK (RSA:512 after RSA:512).
|
|
|
f64bd5 |
-keyi512
|
|
|
f64bd5 |
-keyi512 (candidate (next))
|
|
|
f64bd5 |
[nss:1024]
|
|
|
f64bd5 |
OK.
|
|
|
f64bd5 |
OK (RSA:1024).
|
|
|
f64bd5 |
@@ -56,15 +47,6 @@ keyi4096 (candidate (next))
|
|
|
f64bd5 |
Failed to save NSS:${tmpdir}/rosubdir: need fs permissions.
|
|
|
f64bd5 |
[nss:rwsubdir]
|
|
|
f64bd5 |
Failed to save NSS:${tmpdir}/rwsubdir: need fs permissions.
|
|
|
f64bd5 |
-[openssl:512]
|
|
|
f64bd5 |
-OK.
|
|
|
f64bd5 |
-OK (RSA:512).
|
|
|
f64bd5 |
-OK.
|
|
|
f64bd5 |
-OK (RSA:512 after RSA:512).
|
|
|
f64bd5 |
-OK.
|
|
|
f64bd5 |
-OK (RSA:512 after RSA:512).
|
|
|
f64bd5 |
-${tmpdir}/sample.512
|
|
|
f64bd5 |
-${tmpdir}/sample.512.(next).key
|
|
|
f64bd5 |
[openssl:1024]
|
|
|
f64bd5 |
OK.
|
|
|
f64bd5 |
OK (RSA:1024).
|
|
|
f64bd5 |
diff --git a/tests/002-keygen/run.sh b/tests/002-keygen/run.sh
|
|
|
f64bd5 |
index a0867cf1e3fd0a9f18d275ab308ec93808936b4b..f550feebac5ed10a52500286bb8b779ed8e1526a 100755
|
|
|
f64bd5 |
--- a/tests/002-keygen/run.sh
|
|
|
f64bd5 |
+++ b/tests/002-keygen/run.sh
|
|
|
f64bd5 |
@@ -5,7 +5,7 @@ cd "$tmpdir"
|
|
|
f64bd5 |
source "$srcdir"/functions
|
|
|
f64bd5 |
initnssdb "$tmpdir"
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
echo "[nss:$size]"
|
|
|
f64bd5 |
# Generate a key.
|
|
|
f64bd5 |
cat > entry.$size <<- EOF
|
|
|
f64bd5 |
@@ -49,7 +49,7 @@ key_gen_size=$size
|
|
|
f64bd5 |
EOF
|
|
|
f64bd5 |
$toolsdir/keygen entry.$size || true
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
echo "[openssl:$size]"
|
|
|
f64bd5 |
# Generate a key.
|
|
|
f64bd5 |
cat > entry.$size <<- EOF
|
|
|
f64bd5 |
diff --git a/tests/003-csrgen-rsa/expected.out b/tests/003-csrgen-rsa/expected.out
|
|
|
f64bd5 |
index 7b67eab3b9e431b8d22b5a73bb6b5d2952e05d83..e058e8541c2de49fe5f446a7e3432b4138fbb876 100644
|
|
|
f64bd5 |
--- a/tests/003-csrgen-rsa/expected.out
|
|
|
f64bd5 |
+++ b/tests/003-csrgen-rsa/expected.out
|
|
|
f64bd5 |
@@ -1,9 +1,5 @@
|
|
|
f64bd5 |
pk12util: PKCS12 EXPORT SUCCESSFUL
|
|
|
f64bd5 |
MAC verified OK
|
|
|
f64bd5 |
-512 OK.
|
|
|
f64bd5 |
-Signature OK
|
|
|
f64bd5 |
-pk12util: PKCS12 EXPORT SUCCESSFUL
|
|
|
f64bd5 |
-MAC verified OK
|
|
|
f64bd5 |
1024 OK.
|
|
|
f64bd5 |
Signature OK
|
|
|
f64bd5 |
pk12util: PKCS12 EXPORT SUCCESSFUL
|
|
|
f64bd5 |
@@ -23,70 +19,70 @@ MAC verified OK
|
|
|
f64bd5 |
4096 OK.
|
|
|
f64bd5 |
Signature OK
|
|
|
f64bd5 |
The last CSR (the one with everything) was:
|
|
|
f64bd5 |
- 0:d=0 hl=4 l=1019 cons: SEQUENCE
|
|
|
f64bd5 |
- 4:d=1 hl=4 l= 933 cons: SEQUENCE
|
|
|
f64bd5 |
+ 0:d=0 hl=4 l=1413 cons: SEQUENCE
|
|
|
f64bd5 |
+ 4:d=1 hl=4 l=1133 cons: SEQUENCE
|
|
|
f64bd5 |
8:d=2 hl=2 l= 1 prim: INTEGER :00
|
|
|
f64bd5 |
11:d=2 hl=2 l= 22 cons: SEQUENCE
|
|
|
f64bd5 |
13:d=3 hl=2 l= 20 cons: SET
|
|
|
f64bd5 |
15:d=4 hl=2 l= 18 cons: SEQUENCE
|
|
|
f64bd5 |
17:d=5 hl=2 l= 3 prim: OBJECT :commonName
|
|
|
f64bd5 |
22:d=5 hl=2 l= 11 prim: PRINTABLESTRING :Babs Jensen
|
|
|
f64bd5 |
- 35:d=2 hl=2 l= 92 cons: SEQUENCE
|
|
|
f64bd5 |
- 37:d=3 hl=2 l= 13 cons: SEQUENCE
|
|
|
f64bd5 |
- 39:d=4 hl=2 l= 9 prim: OBJECT :rsaEncryption
|
|
|
f64bd5 |
- 50:d=4 hl=2 l= 0 prim: NULL
|
|
|
f64bd5 |
- 52:d=3 hl=2 l= 75 prim: BIT STRING
|
|
|
f64bd5 |
- 129:d=2 hl=4 l= 808 cons: cont [ 0 ]
|
|
|
f64bd5 |
- 133:d=3 hl=2 l= 52 cons: SEQUENCE
|
|
|
f64bd5 |
- 135:d=4 hl=2 l= 9 prim: OBJECT :challengePassword
|
|
|
f64bd5 |
- 146:d=4 hl=2 l= 39 cons: SET
|
|
|
f64bd5 |
- 148:d=5 hl=2 l= 37 prim: PRINTABLESTRING :ChallengePasswordIsEncodedInPlainText
|
|
|
f64bd5 |
- 187:d=3 hl=2 l= 61 cons: SEQUENCE
|
|
|
f64bd5 |
- 189:d=4 hl=2 l= 9 prim: OBJECT :friendlyName
|
|
|
f64bd5 |
- 200:d=4 hl=2 l= 48 cons: SET
|
|
|
f64bd5 |
- 202:d=5 hl=2 l= 46 prim: BMPSTRING
|
|
|
f64bd5 |
- 250:d=3 hl=4 l= 687 cons: SEQUENCE
|
|
|
f64bd5 |
- 254:d=4 hl=2 l= 9 prim: OBJECT :Extension Request
|
|
|
f64bd5 |
- 265:d=4 hl=4 l= 672 cons: SET
|
|
|
f64bd5 |
- 269:d=5 hl=4 l= 668 cons: SEQUENCE
|
|
|
f64bd5 |
- 273:d=6 hl=2 l= 14 cons: SEQUENCE
|
|
|
f64bd5 |
- 275:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Key Usage
|
|
|
f64bd5 |
- 280:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 283:d=7 hl=2 l= 4 prim: OCTET STRING [HEX DUMP]:030205E0
|
|
|
f64bd5 |
- 289:d=6 hl=4 l= 264 cons: SEQUENCE
|
|
|
f64bd5 |
- 293:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Subject Alternative Name
|
|
|
f64bd5 |
- 298:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 301:d=7 hl=3 l= 253 prim: OCTET STRING [HEX DUMP]:3081FA82096C6F63616C686F737482156C6F63616C686F73742E6C6F63616C646F6D61696E810E726F6F74406C6F63616C686F7374811A726F6F74406C6F63616C686F73742E6C6F63616C646F6D61696EA020060A2B060104018237140203A0120C10726F6F74404558414D504C452E434F4DA02E06062B0601050202A0243022A00D1B0B4558414D504C452E434F4DA111300FA003020101A10830061B04726F6F74A024060A2B060104018237140203A0160C14726F6F7440464F4F2E4558414D504C452E434F4DA03206062B0601050202A0283026A0111B0F464F4F2E4558414D504C452E434F4DA111300FA003020101A10830061B04726F6F74
|
|
|
f64bd5 |
- 557:d=6 hl=2 l= 32 cons: SEQUENCE
|
|
|
f64bd5 |
- 559:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Extended Key Usage
|
|
|
f64bd5 |
- 564:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 567:d=7 hl=2 l= 22 prim: OCTET STRING [HEX DUMP]:301406082B0601050507030206082B06010505070304
|
|
|
f64bd5 |
- 591:d=6 hl=2 l= 18 cons: SEQUENCE
|
|
|
f64bd5 |
- 593:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Basic Constraints
|
|
|
f64bd5 |
- 598:d=7 hl=2 l= 1 prim: BOOLEAN :255
|
|
|
f64bd5 |
- 601:d=7 hl=2 l= 8 prim: OCTET STRING [HEX DUMP]:30060101FF020103
|
|
|
f64bd5 |
- 611:d=6 hl=2 l= 34 cons: SEQUENCE
|
|
|
f64bd5 |
- 613:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Authority Key Identifier
|
|
|
f64bd5 |
- 618:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 621:d=7 hl=2 l= 24 prim: OCTET STRING [HEX DUMP]:30168014A9993E364706816ABA3E25717850C26C9CD0D89D
|
|
|
f64bd5 |
- 647:d=6 hl=2 l= 32 cons: SEQUENCE
|
|
|
f64bd5 |
- 649:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Subject Key Identifier
|
|
|
f64bd5 |
- 654:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 657:d=7 hl=2 l= 22 prim: OCTET STRING [HEX DUMP]:0414A9993E364706816ABA3E25717850C26C9CD0D89D
|
|
|
f64bd5 |
- 681:d=6 hl=2 l= 107 cons: SEQUENCE
|
|
|
f64bd5 |
- 683:d=7 hl=2 l= 8 prim: OBJECT :Authority Information Access
|
|
|
f64bd5 |
- 693:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 696:d=7 hl=2 l= 92 prim: OCTET STRING [HEX DUMP]:305A302B06082B06010505073001861F687474703A2F2F6F6373702D312E6578616D706C652E636F6D3A3132333435302B06082B06010505073001861F687474703A2F2F6F6373702D322E6578616D706C652E636F6D3A3132333435
|
|
|
f64bd5 |
- 790:d=6 hl=2 l= 96 cons: SEQUENCE
|
|
|
f64bd5 |
- 792:d=7 hl=2 l= 3 prim: OBJECT :X509v3 CRL Distribution Points
|
|
|
f64bd5 |
- 797:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 800:d=7 hl=2 l= 86 prim: OCTET STRING [HEX DUMP]:30543028A026A0248622687474703A2F2F63726C2D312E6578616D706C652E636F6D3A31323334352F6765743028A026A0248622687474703A2F2F63726C2D322E6578616D706C652E636F6D3A31323334352F676574
|
|
|
f64bd5 |
- 888:d=6 hl=2 l= 51 cons: SEQUENCE
|
|
|
f64bd5 |
- 890:d=7 hl=2 l= 9 prim: OBJECT :Netscape Comment
|
|
|
f64bd5 |
- 901:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 904:d=7 hl=2 l= 35 prim: OCTET STRING [HEX DUMP]:1621636572746D6F6E6765722067656E65726174656420746869732072657175657374
|
|
|
f64bd5 |
- 941:d=1 hl=2 l= 13 cons: SEQUENCE
|
|
|
f64bd5 |
- 943:d=2 hl=2 l= 9 prim: OBJECT :sha256WithRSAEncryption
|
|
|
f64bd5 |
- 954:d=2 hl=2 l= 0 prim: NULL
|
|
|
f64bd5 |
- 956:d=1 hl=2 l= 65 prim: BIT STRING
|
|
|
f64bd5 |
+ 35:d=2 hl=4 l= 290 cons: SEQUENCE
|
|
|
f64bd5 |
+ 39:d=3 hl=2 l= 13 cons: SEQUENCE
|
|
|
f64bd5 |
+ 41:d=4 hl=2 l= 9 prim: OBJECT :rsaEncryption
|
|
|
f64bd5 |
+ 52:d=4 hl=2 l= 0 prim: NULL
|
|
|
f64bd5 |
+ 54:d=3 hl=4 l= 271 prim: BIT STRING
|
|
|
f64bd5 |
+ 329:d=2 hl=4 l= 808 cons: cont [ 0 ]
|
|
|
f64bd5 |
+ 333:d=3 hl=2 l= 52 cons: SEQUENCE
|
|
|
f64bd5 |
+ 335:d=4 hl=2 l= 9 prim: OBJECT :challengePassword
|
|
|
f64bd5 |
+ 346:d=4 hl=2 l= 39 cons: SET
|
|
|
f64bd5 |
+ 348:d=5 hl=2 l= 37 prim: PRINTABLESTRING :ChallengePasswordIsEncodedInPlainText
|
|
|
f64bd5 |
+ 387:d=3 hl=2 l= 61 cons: SEQUENCE
|
|
|
f64bd5 |
+ 389:d=4 hl=2 l= 9 prim: OBJECT :friendlyName
|
|
|
f64bd5 |
+ 400:d=4 hl=2 l= 48 cons: SET
|
|
|
f64bd5 |
+ 402:d=5 hl=2 l= 46 prim: BMPSTRING
|
|
|
f64bd5 |
+ 450:d=3 hl=4 l= 687 cons: SEQUENCE
|
|
|
f64bd5 |
+ 454:d=4 hl=2 l= 9 prim: OBJECT :Extension Request
|
|
|
f64bd5 |
+ 465:d=4 hl=4 l= 672 cons: SET
|
|
|
f64bd5 |
+ 469:d=5 hl=4 l= 668 cons: SEQUENCE
|
|
|
f64bd5 |
+ 473:d=6 hl=2 l= 14 cons: SEQUENCE
|
|
|
f64bd5 |
+ 475:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Key Usage
|
|
|
f64bd5 |
+ 480:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 483:d=7 hl=2 l= 4 prim: OCTET STRING [HEX DUMP]:030205E0
|
|
|
f64bd5 |
+ 489:d=6 hl=4 l= 264 cons: SEQUENCE
|
|
|
f64bd5 |
+ 493:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Subject Alternative Name
|
|
|
f64bd5 |
+ 498:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 501:d=7 hl=3 l= 253 prim: OCTET STRING [HEX DUMP]:3081FA82096C6F63616C686F737482156C6F63616C686F73742E6C6F63616C646F6D61696E810E726F6F74406C6F63616C686F7374811A726F6F74406C6F63616C686F73742E6C6F63616C646F6D61696EA020060A2B060104018237140203A0120C10726F6F74404558414D504C452E434F4DA02E06062B0601050202A0243022A00D1B0B4558414D504C452E434F4DA111300FA003020101A10830061B04726F6F74A024060A2B060104018237140203A0160C14726F6F7440464F4F2E4558414D504C452E434F4DA03206062B0601050202A0283026A0111B0F464F4F2E4558414D504C452E434F4DA111300FA003020101A10830061B04726F6F74
|
|
|
f64bd5 |
+ 757:d=6 hl=2 l= 32 cons: SEQUENCE
|
|
|
f64bd5 |
+ 759:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Extended Key Usage
|
|
|
f64bd5 |
+ 764:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 767:d=7 hl=2 l= 22 prim: OCTET STRING [HEX DUMP]:301406082B0601050507030206082B06010505070304
|
|
|
f64bd5 |
+ 791:d=6 hl=2 l= 18 cons: SEQUENCE
|
|
|
f64bd5 |
+ 793:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Basic Constraints
|
|
|
f64bd5 |
+ 798:d=7 hl=2 l= 1 prim: BOOLEAN :255
|
|
|
f64bd5 |
+ 801:d=7 hl=2 l= 8 prim: OCTET STRING [HEX DUMP]:30060101FF020103
|
|
|
f64bd5 |
+ 811:d=6 hl=2 l= 34 cons: SEQUENCE
|
|
|
f64bd5 |
+ 813:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Authority Key Identifier
|
|
|
f64bd5 |
+ 818:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 821:d=7 hl=2 l= 24 prim: OCTET STRING [HEX DUMP]:30168014A9993E364706816ABA3E25717850C26C9CD0D89D
|
|
|
f64bd5 |
+ 847:d=6 hl=2 l= 32 cons: SEQUENCE
|
|
|
f64bd5 |
+ 849:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Subject Key Identifier
|
|
|
f64bd5 |
+ 854:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 857:d=7 hl=2 l= 22 prim: OCTET STRING [HEX DUMP]:0414A9993E364706816ABA3E25717850C26C9CD0D89D
|
|
|
f64bd5 |
+ 881:d=6 hl=2 l= 107 cons: SEQUENCE
|
|
|
f64bd5 |
+ 883:d=7 hl=2 l= 8 prim: OBJECT :Authority Information Access
|
|
|
f64bd5 |
+ 893:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 896:d=7 hl=2 l= 92 prim: OCTET STRING [HEX DUMP]:305A302B06082B06010505073001861F687474703A2F2F6F6373702D312E6578616D706C652E636F6D3A3132333435302B06082B06010505073001861F687474703A2F2F6F6373702D322E6578616D706C652E636F6D3A3132333435
|
|
|
f64bd5 |
+ 990:d=6 hl=2 l= 96 cons: SEQUENCE
|
|
|
f64bd5 |
+ 992:d=7 hl=2 l= 3 prim: OBJECT :X509v3 CRL Distribution Points
|
|
|
f64bd5 |
+ 997:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 1000:d=7 hl=2 l= 86 prim: OCTET STRING [HEX DUMP]:30543028A026A0248622687474703A2F2F63726C2D312E6578616D706C652E636F6D3A31323334352F6765743028A026A0248622687474703A2F2F63726C2D322E6578616D706C652E636F6D3A31323334352F676574
|
|
|
f64bd5 |
+ 1088:d=6 hl=2 l= 51 cons: SEQUENCE
|
|
|
f64bd5 |
+ 1090:d=7 hl=2 l= 9 prim: OBJECT :Netscape Comment
|
|
|
f64bd5 |
+ 1101:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 1104:d=7 hl=2 l= 35 prim: OCTET STRING [HEX DUMP]:1621636572746D6F6E6765722067656E65726174656420746869732072657175657374
|
|
|
f64bd5 |
+ 1141:d=1 hl=2 l= 13 cons: SEQUENCE
|
|
|
f64bd5 |
+ 1143:d=2 hl=2 l= 9 prim: OBJECT :sha256WithRSAEncryption
|
|
|
f64bd5 |
+ 1154:d=2 hl=2 l= 0 prim: NULL
|
|
|
f64bd5 |
+ 1156:d=1 hl=4 l= 257 prim: BIT STRING
|
|
|
f64bd5 |
Test complete (32 combinations).
|
|
|
f64bd5 |
diff --git a/tests/003-csrgen-rsa/run.sh b/tests/003-csrgen-rsa/run.sh
|
|
|
f64bd5 |
index c049dd00d411706b1470a1a8a9fb8ae59c36bf8b..7f1e7b41f195b3af429c1ba7129dd00b7ca2ed9d 100755
|
|
|
f64bd5 |
--- a/tests/003-csrgen-rsa/run.sh
|
|
|
f64bd5 |
+++ b/tests/003-csrgen-rsa/run.sh
|
|
|
f64bd5 |
@@ -5,7 +5,7 @@ cd "$tmpdir"
|
|
|
f64bd5 |
source "$srcdir"/functions
|
|
|
f64bd5 |
initnssdb "$tmpdir"
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
# Build a self-signed certificate.
|
|
|
f64bd5 |
run_certutil -d "$tmpdir" -S -g $size -n keyi$size \
|
|
|
f64bd5 |
-s "cn=T$size" -c "cn=T$size" \
|
|
|
f64bd5 |
@@ -216,7 +216,7 @@ for nscomment in "" "certmonger generated this request" ; do
|
|
|
f64bd5 |
done
|
|
|
f64bd5 |
nscomment=
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-size=512
|
|
|
f64bd5 |
+size=2048
|
|
|
f64bd5 |
subject="CN=Babs Jensen"
|
|
|
f64bd5 |
hostname=localhost,localhost.localdomain
|
|
|
f64bd5 |
email=root@localhost,root@localhost.localdomain
|
|
|
f64bd5 |
diff --git a/tests/003-csrgen/expected.out b/tests/003-csrgen/expected.out
|
|
|
f64bd5 |
index 7f4586cd2820be6c0a88bd6787c86a532f68643c..51083160df3dd69972292fd23d51e79714290d22 100644
|
|
|
f64bd5 |
--- a/tests/003-csrgen/expected.out
|
|
|
f64bd5 |
+++ b/tests/003-csrgen/expected.out
|
|
|
f64bd5 |
@@ -1,11 +1,6 @@
|
|
|
f64bd5 |
pk12util: PKCS12 EXPORT SUCCESSFUL
|
|
|
f64bd5 |
MAC verified OK
|
|
|
f64bd5 |
Signature OK
|
|
|
f64bd5 |
-minicert.openssl.512.pem: OK
|
|
|
f64bd5 |
-512 OK.
|
|
|
f64bd5 |
-pk12util: PKCS12 EXPORT SUCCESSFUL
|
|
|
f64bd5 |
-MAC verified OK
|
|
|
f64bd5 |
-Signature OK
|
|
|
f64bd5 |
minicert.openssl.1024.pem: OK
|
|
|
f64bd5 |
1024 OK.
|
|
|
f64bd5 |
pk12util: PKCS12 EXPORT SUCCESSFUL
|
|
|
f64bd5 |
@@ -29,86 +24,86 @@ Signature OK
|
|
|
f64bd5 |
minicert.openssl.4096.pem: OK
|
|
|
f64bd5 |
4096 OK.
|
|
|
f64bd5 |
The last CSR (the one with everything) was:
|
|
|
f64bd5 |
- 0:d=0 hl=4 l=1241 cons: SEQUENCE
|
|
|
f64bd5 |
- 4:d=1 hl=4 l=1155 cons: SEQUENCE
|
|
|
f64bd5 |
+ 0:d=0 hl=4 l=1635 cons: SEQUENCE
|
|
|
f64bd5 |
+ 4:d=1 hl=4 l=1355 cons: SEQUENCE
|
|
|
f64bd5 |
8:d=2 hl=2 l= 1 prim: INTEGER :00
|
|
|
f64bd5 |
11:d=2 hl=2 l= 22 cons: SEQUENCE
|
|
|
f64bd5 |
13:d=3 hl=2 l= 20 cons: SET
|
|
|
f64bd5 |
15:d=4 hl=2 l= 18 cons: SEQUENCE
|
|
|
f64bd5 |
17:d=5 hl=2 l= 3 prim: OBJECT :commonName
|
|
|
f64bd5 |
22:d=5 hl=2 l= 11 prim: PRINTABLESTRING :Babs Jensen
|
|
|
f64bd5 |
- 35:d=2 hl=2 l= 92 cons: SEQUENCE
|
|
|
f64bd5 |
- 37:d=3 hl=2 l= 13 cons: SEQUENCE
|
|
|
f64bd5 |
- 39:d=4 hl=2 l= 9 prim: OBJECT :rsaEncryption
|
|
|
f64bd5 |
- 50:d=4 hl=2 l= 0 prim: NULL
|
|
|
f64bd5 |
- 52:d=3 hl=2 l= 75 prim: BIT STRING
|
|
|
f64bd5 |
- 129:d=2 hl=4 l=1030 cons: cont [ 0 ]
|
|
|
f64bd5 |
- 133:d=3 hl=2 l= 52 cons: SEQUENCE
|
|
|
f64bd5 |
- 135:d=4 hl=2 l= 9 prim: OBJECT :challengePassword
|
|
|
f64bd5 |
- 146:d=4 hl=2 l= 39 cons: SET
|
|
|
f64bd5 |
- 148:d=5 hl=2 l= 37 prim: PRINTABLESTRING :ChallengePasswordIsEncodedInPlainText
|
|
|
f64bd5 |
- 187:d=3 hl=2 l= 61 cons: SEQUENCE
|
|
|
f64bd5 |
- 189:d=4 hl=2 l= 9 prim: OBJECT :friendlyName
|
|
|
f64bd5 |
- 200:d=4 hl=2 l= 48 cons: SET
|
|
|
f64bd5 |
- 202:d=5 hl=2 l= 46 prim: BMPSTRING
|
|
|
f64bd5 |
- 250:d=3 hl=4 l= 909 cons: SEQUENCE
|
|
|
f64bd5 |
- 254:d=4 hl=2 l= 9 prim: OBJECT :Extension Request
|
|
|
f64bd5 |
- 265:d=4 hl=4 l= 894 cons: SET
|
|
|
f64bd5 |
- 269:d=5 hl=4 l= 890 cons: SEQUENCE
|
|
|
f64bd5 |
- 273:d=6 hl=2 l= 14 cons: SEQUENCE
|
|
|
f64bd5 |
- 275:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Key Usage
|
|
|
f64bd5 |
- 280:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 283:d=7 hl=2 l= 4 prim: OCTET STRING [HEX DUMP]:030205E0
|
|
|
f64bd5 |
- 289:d=6 hl=4 l= 290 cons: SEQUENCE
|
|
|
f64bd5 |
- 293:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Subject Alternative Name
|
|
|
f64bd5 |
- 298:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 301:d=7 hl=4 l= 278 prim: OCTET STRING [HEX DUMP]:3082011282096C6F63616C686F737482156C6F63616C686F73742E6C6F63616C646F6D61696E810E726F6F74406C6F63616C686F7374811A726F6F74406C6F63616C686F73742E6C6F63616C646F6D61696EA020060A2B060104018237140203A0120C10726F6F74404558414D504C452E434F4DA02E06062B0601050202A0243022A00D1B0B4558414D504C452E434F4DA111300FA003020101A10830061B04726F6F74A024060A2B060104018237140203A0160C14726F6F7440464F4F2E4558414D504C452E434F4DA03206062B0601050202A0283026A0111B0F464F4F2E4558414D504C452E434F4DA111300FA003020101A10830061B04726F6F7487047F000001871000000000000000000000000000000001
|
|
|
f64bd5 |
- 583:d=6 hl=2 l= 32 cons: SEQUENCE
|
|
|
f64bd5 |
- 585:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Extended Key Usage
|
|
|
f64bd5 |
- 590:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 593:d=7 hl=2 l= 22 prim: OCTET STRING [HEX DUMP]:301406082B0601050507030206082B06010505070304
|
|
|
f64bd5 |
- 617:d=6 hl=2 l= 18 cons: SEQUENCE
|
|
|
f64bd5 |
- 619:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Basic Constraints
|
|
|
f64bd5 |
- 624:d=7 hl=2 l= 1 prim: BOOLEAN :255
|
|
|
f64bd5 |
- 627:d=7 hl=2 l= 8 prim: OCTET STRING [HEX DUMP]:30060101FF020103
|
|
|
f64bd5 |
- 637:d=6 hl=2 l= 34 cons: SEQUENCE
|
|
|
f64bd5 |
- 639:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Authority Key Identifier
|
|
|
f64bd5 |
- 644:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 647:d=7 hl=2 l= 24 prim: OCTET STRING [HEX DUMP]:30168014A9993E364706816ABA3E25717850C26C9CD0D89D
|
|
|
f64bd5 |
- 673:d=6 hl=2 l= 32 cons: SEQUENCE
|
|
|
f64bd5 |
- 675:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Subject Key Identifier
|
|
|
f64bd5 |
- 680:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 683:d=7 hl=2 l= 22 prim: OCTET STRING [HEX DUMP]:0414A9993E364706816ABA3E25717850C26C9CD0D89D
|
|
|
f64bd5 |
- 707:d=6 hl=2 l= 107 cons: SEQUENCE
|
|
|
f64bd5 |
- 709:d=7 hl=2 l= 8 prim: OBJECT :Authority Information Access
|
|
|
f64bd5 |
- 719:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 722:d=7 hl=2 l= 92 prim: OCTET STRING [HEX DUMP]:305A302B06082B06010505073001861F687474703A2F2F6F6373702D312E6578616D706C652E636F6D3A3132333435302B06082B06010505073001861F687474703A2F2F6F6373702D322E6578616D706C652E636F6D3A3132333435
|
|
|
f64bd5 |
- 816:d=6 hl=2 l= 96 cons: SEQUENCE
|
|
|
f64bd5 |
- 818:d=7 hl=2 l= 3 prim: OBJECT :X509v3 CRL Distribution Points
|
|
|
f64bd5 |
- 823:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 826:d=7 hl=2 l= 86 prim: OCTET STRING [HEX DUMP]:30543028A026A0248622687474703A2F2F63726C2D312E6578616D706C652E636F6D3A31323334352F6765743028A026A0248622687474703A2F2F63726C2D322E6578616D706C652E636F6D3A31323334352F676574
|
|
|
f64bd5 |
- 914:d=6 hl=2 l= 106 cons: SEQUENCE
|
|
|
f64bd5 |
- 916:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Freshest CRL
|
|
|
f64bd5 |
- 921:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 924:d=7 hl=2 l= 96 prim: OCTET STRING [HEX DUMP]:305E302DA02BA0298627687474703A2F2F63726C2D312E6578616D706C652E636F6D3A31323334352F67657464656C7461302DA02BA0298627687474703A2F2F63726C2D322E6578616D706C652E636F6D3A31323334352F67657464656C7461
|
|
|
f64bd5 |
- 1022:d=6 hl=2 l= 51 cons: SEQUENCE
|
|
|
f64bd5 |
- 1024:d=7 hl=2 l= 9 prim: OBJECT :Netscape Comment
|
|
|
f64bd5 |
- 1035:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 1038:d=7 hl=2 l= 35 prim: OCTET STRING [HEX DUMP]:1621636572746D6F6E6765722067656E65726174656420746869732072657175657374
|
|
|
f64bd5 |
- 1075:d=6 hl=2 l= 18 cons: SEQUENCE
|
|
|
f64bd5 |
- 1077:d=7 hl=2 l= 9 prim: OBJECT :OCSP No Check
|
|
|
f64bd5 |
- 1088:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 1091:d=7 hl=2 l= 2 prim: OCTET STRING [HEX DUMP]:0500
|
|
|
f64bd5 |
- 1095:d=6 hl=2 l= 44 cons: SEQUENCE
|
|
|
f64bd5 |
- 1097:d=7 hl=2 l= 9 prim: OBJECT :1.3.6.1.4.1.311.20.2
|
|
|
f64bd5 |
- 1108:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 1111:d=7 hl=2 l= 28 prim: OCTET STRING [HEX DUMP]:1E1A006300610041007700650073006F006D00650043006500720074
|
|
|
f64bd5 |
- 1141:d=6 hl=2 l= 20 cons: SEQUENCE
|
|
|
f64bd5 |
- 1143:d=7 hl=2 l= 9 prim: OBJECT :Netscape Cert Type
|
|
|
f64bd5 |
- 1154:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
- 1157:d=7 hl=2 l= 4 prim: OCTET STRING [HEX DUMP]:030205A0
|
|
|
f64bd5 |
- 1163:d=1 hl=2 l= 13 cons: SEQUENCE
|
|
|
f64bd5 |
- 1165:d=2 hl=2 l= 9 prim: OBJECT :sha256WithRSAEncryption
|
|
|
f64bd5 |
- 1176:d=2 hl=2 l= 0 prim: NULL
|
|
|
f64bd5 |
- 1178:d=1 hl=2 l= 65 prim: BIT STRING
|
|
|
f64bd5 |
+ 35:d=2 hl=4 l= 290 cons: SEQUENCE
|
|
|
f64bd5 |
+ 39:d=3 hl=2 l= 13 cons: SEQUENCE
|
|
|
f64bd5 |
+ 41:d=4 hl=2 l= 9 prim: OBJECT :rsaEncryption
|
|
|
f64bd5 |
+ 52:d=4 hl=2 l= 0 prim: NULL
|
|
|
f64bd5 |
+ 54:d=3 hl=4 l= 271 prim: BIT STRING
|
|
|
f64bd5 |
+ 329:d=2 hl=4 l=1030 cons: cont [ 0 ]
|
|
|
f64bd5 |
+ 333:d=3 hl=2 l= 52 cons: SEQUENCE
|
|
|
f64bd5 |
+ 335:d=4 hl=2 l= 9 prim: OBJECT :challengePassword
|
|
|
f64bd5 |
+ 346:d=4 hl=2 l= 39 cons: SET
|
|
|
f64bd5 |
+ 348:d=5 hl=2 l= 37 prim: PRINTABLESTRING :ChallengePasswordIsEncodedInPlainText
|
|
|
f64bd5 |
+ 387:d=3 hl=2 l= 61 cons: SEQUENCE
|
|
|
f64bd5 |
+ 389:d=4 hl=2 l= 9 prim: OBJECT :friendlyName
|
|
|
f64bd5 |
+ 400:d=4 hl=2 l= 48 cons: SET
|
|
|
f64bd5 |
+ 402:d=5 hl=2 l= 46 prim: BMPSTRING
|
|
|
f64bd5 |
+ 450:d=3 hl=4 l= 909 cons: SEQUENCE
|
|
|
f64bd5 |
+ 454:d=4 hl=2 l= 9 prim: OBJECT :Extension Request
|
|
|
f64bd5 |
+ 465:d=4 hl=4 l= 894 cons: SET
|
|
|
f64bd5 |
+ 469:d=5 hl=4 l= 890 cons: SEQUENCE
|
|
|
f64bd5 |
+ 473:d=6 hl=2 l= 14 cons: SEQUENCE
|
|
|
f64bd5 |
+ 475:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Key Usage
|
|
|
f64bd5 |
+ 480:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 483:d=7 hl=2 l= 4 prim: OCTET STRING [HEX DUMP]:030205E0
|
|
|
f64bd5 |
+ 489:d=6 hl=4 l= 290 cons: SEQUENCE
|
|
|
f64bd5 |
+ 493:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Subject Alternative Name
|
|
|
f64bd5 |
+ 498:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 501:d=7 hl=4 l= 278 prim: OCTET STRING [HEX DUMP]:3082011282096C6F63616C686F737482156C6F63616C686F73742E6C6F63616C646F6D61696E810E726F6F74406C6F63616C686F7374811A726F6F74406C6F63616C686F73742E6C6F63616C646F6D61696EA020060A2B060104018237140203A0120C10726F6F74404558414D504C452E434F4DA02E06062B0601050202A0243022A00D1B0B4558414D504C452E434F4DA111300FA003020101A10830061B04726F6F74A024060A2B060104018237140203A0160C14726F6F7440464F4F2E4558414D504C452E434F4DA03206062B0601050202A0283026A0111B0F464F4F2E4558414D504C452E434F4DA111300FA003020101A10830061B04726F6F7487047F000001871000000000000000000000000000000001
|
|
|
f64bd5 |
+ 783:d=6 hl=2 l= 32 cons: SEQUENCE
|
|
|
f64bd5 |
+ 785:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Extended Key Usage
|
|
|
f64bd5 |
+ 790:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 793:d=7 hl=2 l= 22 prim: OCTET STRING [HEX DUMP]:301406082B0601050507030206082B06010505070304
|
|
|
f64bd5 |
+ 817:d=6 hl=2 l= 18 cons: SEQUENCE
|
|
|
f64bd5 |
+ 819:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Basic Constraints
|
|
|
f64bd5 |
+ 824:d=7 hl=2 l= 1 prim: BOOLEAN :255
|
|
|
f64bd5 |
+ 827:d=7 hl=2 l= 8 prim: OCTET STRING [HEX DUMP]:30060101FF020103
|
|
|
f64bd5 |
+ 837:d=6 hl=2 l= 34 cons: SEQUENCE
|
|
|
f64bd5 |
+ 839:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Authority Key Identifier
|
|
|
f64bd5 |
+ 844:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 847:d=7 hl=2 l= 24 prim: OCTET STRING [HEX DUMP]:30168014A9993E364706816ABA3E25717850C26C9CD0D89D
|
|
|
f64bd5 |
+ 873:d=6 hl=2 l= 32 cons: SEQUENCE
|
|
|
f64bd5 |
+ 875:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Subject Key Identifier
|
|
|
f64bd5 |
+ 880:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 883:d=7 hl=2 l= 22 prim: OCTET STRING [HEX DUMP]:0414A9993E364706816ABA3E25717850C26C9CD0D89D
|
|
|
f64bd5 |
+ 907:d=6 hl=2 l= 107 cons: SEQUENCE
|
|
|
f64bd5 |
+ 909:d=7 hl=2 l= 8 prim: OBJECT :Authority Information Access
|
|
|
f64bd5 |
+ 919:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 922:d=7 hl=2 l= 92 prim: OCTET STRING [HEX DUMP]:305A302B06082B06010505073001861F687474703A2F2F6F6373702D312E6578616D706C652E636F6D3A3132333435302B06082B06010505073001861F687474703A2F2F6F6373702D322E6578616D706C652E636F6D3A3132333435
|
|
|
f64bd5 |
+ 1016:d=6 hl=2 l= 96 cons: SEQUENCE
|
|
|
f64bd5 |
+ 1018:d=7 hl=2 l= 3 prim: OBJECT :X509v3 CRL Distribution Points
|
|
|
f64bd5 |
+ 1023:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 1026:d=7 hl=2 l= 86 prim: OCTET STRING [HEX DUMP]:30543028A026A0248622687474703A2F2F63726C2D312E6578616D706C652E636F6D3A31323334352F6765743028A026A0248622687474703A2F2F63726C2D322E6578616D706C652E636F6D3A31323334352F676574
|
|
|
f64bd5 |
+ 1114:d=6 hl=2 l= 106 cons: SEQUENCE
|
|
|
f64bd5 |
+ 1116:d=7 hl=2 l= 3 prim: OBJECT :X509v3 Freshest CRL
|
|
|
f64bd5 |
+ 1121:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 1124:d=7 hl=2 l= 96 prim: OCTET STRING [HEX DUMP]:305E302DA02BA0298627687474703A2F2F63726C2D312E6578616D706C652E636F6D3A31323334352F67657464656C7461302DA02BA0298627687474703A2F2F63726C2D322E6578616D706C652E636F6D3A31323334352F67657464656C7461
|
|
|
f64bd5 |
+ 1222:d=6 hl=2 l= 51 cons: SEQUENCE
|
|
|
f64bd5 |
+ 1224:d=7 hl=2 l= 9 prim: OBJECT :Netscape Comment
|
|
|
f64bd5 |
+ 1235:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 1238:d=7 hl=2 l= 35 prim: OCTET STRING [HEX DUMP]:1621636572746D6F6E6765722067656E65726174656420746869732072657175657374
|
|
|
f64bd5 |
+ 1275:d=6 hl=2 l= 18 cons: SEQUENCE
|
|
|
f64bd5 |
+ 1277:d=7 hl=2 l= 9 prim: OBJECT :OCSP No Check
|
|
|
f64bd5 |
+ 1288:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 1291:d=7 hl=2 l= 2 prim: OCTET STRING [HEX DUMP]:0500
|
|
|
f64bd5 |
+ 1295:d=6 hl=2 l= 44 cons: SEQUENCE
|
|
|
f64bd5 |
+ 1297:d=7 hl=2 l= 9 prim: OBJECT :1.3.6.1.4.1.311.20.2
|
|
|
f64bd5 |
+ 1308:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 1311:d=7 hl=2 l= 28 prim: OCTET STRING [HEX DUMP]:1E1A006300610041007700650073006F006D00650043006500720074
|
|
|
f64bd5 |
+ 1341:d=6 hl=2 l= 20 cons: SEQUENCE
|
|
|
f64bd5 |
+ 1343:d=7 hl=2 l= 9 prim: OBJECT :Netscape Cert Type
|
|
|
f64bd5 |
+ 1354:d=7 hl=2 l= 1 prim: BOOLEAN :0
|
|
|
f64bd5 |
+ 1357:d=7 hl=2 l= 4 prim: OCTET STRING [HEX DUMP]:030205A0
|
|
|
f64bd5 |
+ 1363:d=1 hl=2 l= 13 cons: SEQUENCE
|
|
|
f64bd5 |
+ 1365:d=2 hl=2 l= 9 prim: OBJECT :sha256WithRSAEncryption
|
|
|
f64bd5 |
+ 1376:d=2 hl=2 l= 0 prim: NULL
|
|
|
f64bd5 |
+ 1378:d=1 hl=4 l= 257 prim: BIT STRING
|
|
|
f64bd5 |
Test complete (69 combinations).
|
|
|
f64bd5 |
diff --git a/tests/003-csrgen/run.sh b/tests/003-csrgen/run.sh
|
|
|
f64bd5 |
index 9a1c027fa7d9da0eec41e5e63e68b05645df9d6b..67b12064b55dd52bd64fbf1b1f9615655913c334 100755
|
|
|
f64bd5 |
--- a/tests/003-csrgen/run.sh
|
|
|
f64bd5 |
+++ b/tests/003-csrgen/run.sh
|
|
|
f64bd5 |
@@ -5,7 +5,7 @@ cd "$tmpdir"
|
|
|
f64bd5 |
source "$srcdir"/functions
|
|
|
f64bd5 |
initnssdb "$tmpdir"
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
# Build a self-signed certificate.
|
|
|
f64bd5 |
run_certutil -d "$tmpdir" -S -g $size -n keyi$size \
|
|
|
f64bd5 |
-s "cn=T$size" -c "cn=T$size" \
|
|
|
f64bd5 |
@@ -298,7 +298,7 @@ for ns_certtype in "" client server email objsign reserved sslca emailca objca c
|
|
|
f64bd5 |
done
|
|
|
f64bd5 |
ns_certtype=
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-size=512
|
|
|
f64bd5 |
+size=2048
|
|
|
f64bd5 |
subject="CN=Babs Jensen"
|
|
|
f64bd5 |
hostname=localhost,localhost.localdomain
|
|
|
f64bd5 |
email=root@localhost,root@localhost.localdomain
|
|
|
f64bd5 |
diff --git a/tests/004-selfsign-rsa/expected.out b/tests/004-selfsign-rsa/expected.out
|
|
|
f64bd5 |
index c50bd2ee0c1101f2df71738d4152e4fcf3bc9591..dd5029eca4f2b6e2cd354f64cd31b843c5857385 100644
|
|
|
f64bd5 |
--- a/tests/004-selfsign-rsa/expected.out
|
|
|
f64bd5 |
+++ b/tests/004-selfsign-rsa/expected.out
|
|
|
f64bd5 |
@@ -1,4 +1,3 @@
|
|
|
f64bd5 |
-512 OK.
|
|
|
f64bd5 |
1024 OK.
|
|
|
f64bd5 |
1536 OK.
|
|
|
f64bd5 |
2048 OK.
|
|
|
f64bd5 |
diff --git a/tests/004-selfsign-rsa/run.sh b/tests/004-selfsign-rsa/run.sh
|
|
|
f64bd5 |
index 8788bdb02fee287299e4cc389e18c7e0eb5ca91d..6f9285b65d4205fd4f24327fea9d934afc5fd68c 100755
|
|
|
f64bd5 |
--- a/tests/004-selfsign-rsa/run.sh
|
|
|
f64bd5 |
+++ b/tests/004-selfsign-rsa/run.sh
|
|
|
f64bd5 |
@@ -33,7 +33,7 @@ function setupca() {
|
|
|
f64bd5 |
EOF
|
|
|
f64bd5 |
}
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
# Build a self-signed certificate.
|
|
|
f64bd5 |
run_certutil -d "$tmpdir" -S -g $size -n keyi$size \
|
|
|
f64bd5 |
-s "cn=T$size" -c "cn=T$size" \
|
|
|
f64bd5 |
diff --git a/tests/004-selfsign/expected.out b/tests/004-selfsign/expected.out
|
|
|
f64bd5 |
index c50bd2ee0c1101f2df71738d4152e4fcf3bc9591..dd5029eca4f2b6e2cd354f64cd31b843c5857385 100644
|
|
|
f64bd5 |
--- a/tests/004-selfsign/expected.out
|
|
|
f64bd5 |
+++ b/tests/004-selfsign/expected.out
|
|
|
f64bd5 |
@@ -1,4 +1,3 @@
|
|
|
f64bd5 |
-512 OK.
|
|
|
f64bd5 |
1024 OK.
|
|
|
f64bd5 |
1536 OK.
|
|
|
f64bd5 |
2048 OK.
|
|
|
f64bd5 |
diff --git a/tests/004-selfsign/run.sh b/tests/004-selfsign/run.sh
|
|
|
f64bd5 |
index 7b2ee438d34d539ab7063b0bd1fc004421c97999..7bb368ec39d9675bff05c837c7e9a4cf64c5b714 100755
|
|
|
f64bd5 |
--- a/tests/004-selfsign/run.sh
|
|
|
f64bd5 |
+++ b/tests/004-selfsign/run.sh
|
|
|
f64bd5 |
@@ -43,7 +43,7 @@ function setupca() {
|
|
|
f64bd5 |
EOF
|
|
|
f64bd5 |
}
|
|
|
f64bd5 |
|
|
|
f64bd5 |
-for size in 512 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
+for size in 1024 1536 2048 3072 4096 ; do
|
|
|
f64bd5 |
# Build a self-signed certificate.
|
|
|
f64bd5 |
run_certutil -d "$tmpdir" -S -g $size -n keyi$size \
|
|
|
f64bd5 |
-s "cn=T$size" -c "cn=T$size" \
|
|
|
f64bd5 |
--
|
|
|
f64bd5 |
2.9.0
|
|
|
f64bd5 |
|