c03c218190
First, I spelled the wildcard name constraint in many_constraints.pem wrong. It's .test, not *.test for name constraints. (This doesn't matter for some_names*.pem, but it does to avoid a false negative in many_names3.pem.) Second, the CN of certs should be a host, not "Leaf". OpenSSL 1.1.0 checks "host-like" CNs against name constraints too and "Leaf" is host-like. I've also made the generator deterministic and checked it in, as PEM blobs are not reviewable. Change-Id: I195d9846315168a792cca829aff25c986339b8f5 Reviewed-on: https://boringssl-review.googlesource.com/20584 Reviewed-by: David Benjamin <davidben@google.com> |
||
---|---|---|
.. | ||
a_digest.c | ||
a_sign.c | ||
a_strex.c | ||
a_verify.c | ||
algorithm.c | ||
asn1_gen.c | ||
by_dir.c | ||
by_file.c | ||
charmap.h | ||
CMakeLists.txt | ||
i2d_pr.c | ||
internal.h | ||
make_many_constraints.go | ||
many_constraints.pem | ||
many_names1.pem | ||
many_names2.pem | ||
many_names3.pem | ||
rsa_pss.c | ||
some_names1.pem | ||
some_names2.pem | ||
some_names3.pem | ||
t_crl.c | ||
t_req.c | ||
t_x509.c | ||
t_x509a.c | ||
vpm_int.h | ||
x509_att.c | ||
x509_cmp.c | ||
x509_d2.c | ||
x509_def.c | ||
x509_ext.c | ||
x509_lu.c | ||
x509_obj.c | ||
x509_r2x.c | ||
x509_req.c | ||
x509_set.c | ||
x509_test.cc | ||
x509_trs.c | ||
x509_txt.c | ||
x509_v3.c | ||
x509_vfy.c | ||
x509_vpm.c | ||
x509.c | ||
x509cset.c | ||
x509name.c | ||
x509rset.c | ||
x509spki.c | ||
x_algor.c | ||
x_all.c | ||
x_attrib.c | ||
x_crl.c | ||
x_exten.c | ||
x_info.c | ||
x_name.c | ||
x_pkey.c | ||
x_pubkey.c | ||
x_req.c | ||
x_sig.c | ||
x_spki.c | ||
x_val.c | ||
x_x509.c | ||
x_x509a.c |