Dr. David von Oheimb
|
0e7b1383e1
Fix issue 1418 by moving check of KU_KEY_CERT_SIGN and weakening check_issued()
|
4 éve |
Tomas Mraz
|
3cb55fe47c
Add test cases for the non CA certificate with pathlen:0
|
4 éve |
Kurt Roeckx
|
77c4d39724
Generate new Ed488 certificates
|
4 éve |
Kurt Roeckx
|
4d9e8c9554
Create a new embeddedSCTs1 that's signed using SHA256
|
4 éve |
Matt Caswell
|
39d9ea5e50
Add Restricted PSS certificate and key
|
5 éve |
Matt Caswell
|
83c81eebed
Add some test brainpool certificates
|
6 éve |
Viktor Dukhovni
|
d02d80b2e8
Limit scope of CN name constraints
|
6 éve |
Dr. Stephen Henson
|
9bf45ba4ca
Add certificates with PSS signatures
|
7 éve |
Dr. Stephen Henson
|
d83b7e1a58
Extend mkcert.sh to support nameConstraints generation and more complex
|
8 éve |
Dr. Stephen Henson
|
b58614d7f5
Fix generation of expired CA certificate.
|
8 éve |
Richard Levitte
|
71c8cd2085
Make it possible to generate proxy certs with test/certs/mkcert.sh
|
8 éve |
Viktor Dukhovni
|
fbb82a60dc
Move peer chain security checks into x509_vfy.c
|
8 éve |
Viktor Dukhovni
|
4d9e33acb2
Require intermediate CAs to have basicConstraints CA:true.
|
8 éve |
Viktor Dukhovni
|
1d85277235
Add tests for non-ca trusted roots and intermediates
|
8 éve |
Viktor Dukhovni
|
33cc5dde47
Compat self-signed trust with reject-only aux data
|
8 éve |
Viktor Dukhovni
|
0daccd4dc1
Check chain extensions also for trusted certificates
|
8 éve |
Viktor Dukhovni
|
8478351737
Scripts to generate verify test certs
|
8 éve |