mirror of
https://github.com/certbot/certbot.git
synced 2026-06-05 23:04:39 -04:00
* Validate OCSP response for responders that are not the certificate's issuer. * Improve OCSP tests using a issuer/responder pair for OCSP responses * Clean code * Update ocsp_test.py * Add various comments * Add several cases of ocsp responder. More factories for the resilience tests. * Update ocsp_test.py |
||
|---|---|---|
| .. | ||
| sample-archive | ||
| cert-5sans_512.pem | ||
| cert-nosans_nistp256.pem | ||
| cert-san_512.pem | ||
| cert_512.pem | ||
| cert_512_bad.pem | ||
| cert_2048.pem | ||
| cert_fullchain_2048.pem | ||
| cli.ini | ||
| csr-6sans_512.conf | ||
| csr-6sans_512.pem | ||
| csr-nonames_512.pem | ||
| csr-nosans_512.conf | ||
| csr-nosans_512.pem | ||
| csr-nosans_nistp256.pem | ||
| csr-san_512.pem | ||
| csr_512.der | ||
| csr_512.pem | ||
| nistp256_key.pem | ||
| ocsp_certificate.pem | ||
| ocsp_issuer_certificate.pem | ||
| ocsp_responder_certificate.pem | ||
| os-release | ||
| README | ||
| rsa256_key.pem | ||
| rsa512_key.pem | ||
| rsa2048_key.pem | ||
| sample-renewal-ancient.conf | ||
| sample-renewal.conf | ||
| webrootconftest.ini | ||
The following command has been used to generate test keys:
for x in 256 512 2048; do openssl genrsa -out rsa${k}_key.pem $k; done
and for the CSR PEM (Certificate Signing Request):
openssl req -new -out csr-Xsans_X.pem -key rsa512_key.pem [-config csr-Xsans_X.conf | -subj '/CN=example.com'] [-outform DER > csr_X.der]
and for the certificate:
openssl req -new -out cert_X.pem -key rsaX_key.pem -subj '/CN=example.com' -x509 [-outform DER > cert_X.der]