Randomize serial numbers of DVSNI challenge certificates.

This commit is contained in:
chrismarget 2016-05-11 12:01:53 -04:00
parent c799a2d57e
commit 639efaeb7b

View file

@ -203,7 +203,7 @@ def gen_ss_cert(key, domains, not_before=None,
"""
assert domains, "Must provide one or more hostnames for the cert."
cert = OpenSSL.crypto.X509()
cert.set_serial_number(1337)
cert.set_serial_number(int(OpenSSL.rand.bytes(16).encode("hex"), 16))
cert.set_version(2)
extensions = [