Index: net/data/parse_ocsp_unittest/ocsp_sign_bad_indirect.pem |
diff --git a/net/data/parse_ocsp_unittest/ocsp_sign_bad_indirect.pem b/net/data/parse_ocsp_unittest/ocsp_sign_bad_indirect.pem |
new file mode 100644 |
index 0000000000000000000000000000000000000000..f4bbe7155daaea0d65f32ad98b5f982762608b2d |
--- /dev/null |
+++ b/net/data/parse_ocsp_unittest/ocsp_sign_bad_indirect.pem |
@@ -0,0 +1,165 @@ |
+# Signed through an intermediate without the correct key usage |
+$ openssl asn1parse -i < [OCSP RESPONSE] |
+ 0:d=0 hl=4 l= 755 cons: SEQUENCE |
+ 4:d=1 hl=2 l= 1 prim: ENUMERATED :00 |
+ 7:d=1 hl=4 l= 748 cons: cont [ 0 ] |
+ 11:d=2 hl=4 l= 744 cons: SEQUENCE |
+ 15:d=3 hl=2 l= 9 prim: OBJECT :Basic OCSP Response |
+ 26:d=3 hl=4 l= 729 prim: OCTET STRING |
+ 0:d=0 hl=4 l= 725 cons: SEQUENCE |
+ 4:d=1 hl=3 l= 140 cons: SEQUENCE |
+ 7:d=2 hl=2 l= 3 cons: cont [ 0 ] |
+ 9:d=3 hl=2 l= 1 prim: INTEGER :01 |
+ 12:d=2 hl=2 l= 35 cons: cont [ 1 ] |
+ 14:d=3 hl=2 l= 33 cons: SEQUENCE |
+ 16:d=4 hl=2 l= 31 cons: SET |
+ 18:d=5 hl=2 l= 29 cons: SEQUENCE |
+ 20:d=6 hl=2 l= 3 prim: OBJECT :commonName |
+ 25:d=6 hl=2 l= 22 prim: PRINTABLESTRING :Test False OCSP Signer |
+ 49:d=2 hl=2 l= 15 prim: GENERALIZEDTIME :20160217114335Z |
+ 66:d=2 hl=2 l= 79 cons: SEQUENCE |
+ 68:d=3 hl=2 l= 77 cons: SEQUENCE |
+ 70:d=4 hl=2 l= 56 cons: SEQUENCE |
+ 72:d=5 hl=2 l= 7 cons: SEQUENCE |
+ 74:d=6 hl=2 l= 5 prim: OBJECT :sha1 |
+ 81:d=5 hl=2 l= 20 prim: OCTET STRING [HEX DUMP]:02FF75DA24DE8ADD150FAB689DCCE6E6636D0901 |
+ 103:d=5 hl=2 l= 20 prim: OCTET STRING [HEX DUMP]:8A0A9DED379293AC0D8BC476A0E8508A52615259 |
+ 125:d=5 hl=2 l= 1 prim: INTEGER :03 |
+ 128:d=4 hl=2 l= 0 prim: cont [ 0 ] |
+ 130:d=4 hl=2 l= 15 prim: GENERALIZEDTIME :20160217114335Z |
+ 147:d=1 hl=2 l= 13 cons: SEQUENCE |
+ 149:d=2 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption |
+ 160:d=2 hl=2 l= 0 prim: NULL |
+ 162:d=1 hl=3 l= 129 prim: BIT STRING |
+ 294:d=1 hl=4 l= 431 cons: cont [ 0 ] |
+ 298:d=2 hl=4 l= 427 cons: SEQUENCE |
+ 302:d=3 hl=4 l= 423 cons: SEQUENCE |
+ 306:d=4 hl=4 l= 272 cons: SEQUENCE |
+ 310:d=5 hl=2 l= 3 cons: cont [ 0 ] |
+ 312:d=6 hl=2 l= 1 prim: INTEGER :02 |
+ 315:d=5 hl=2 l= 1 prim: INTEGER :02 |
+ 318:d=5 hl=2 l= 13 cons: SEQUENCE |
+ 320:d=6 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption |
+ 331:d=6 hl=2 l= 0 prim: NULL |
+ 333:d=5 hl=2 l= 18 cons: SEQUENCE |
+ 335:d=6 hl=2 l= 16 cons: SET |
+ 337:d=7 hl=2 l= 14 cons: SEQUENCE |
+ 339:d=8 hl=2 l= 3 prim: OBJECT :commonName |
+ 344:d=8 hl=2 l= 7 prim: PRINTABLESTRING :Test CA |
+ 353:d=5 hl=2 l= 30 cons: SEQUENCE |
+ 355:d=6 hl=2 l= 13 prim: UTCTIME :160217164335Z |
+ 370:d=6 hl=2 l= 13 prim: UTCTIME :260214164335Z |
+ 385:d=5 hl=2 l= 33 cons: SEQUENCE |
+ 387:d=6 hl=2 l= 31 cons: SET |
+ 389:d=7 hl=2 l= 29 cons: SEQUENCE |
+ 391:d=8 hl=2 l= 3 prim: OBJECT :commonName |
+ 396:d=8 hl=2 l= 22 prim: PRINTABLESTRING :Test False OCSP Signer |
+ 420:d=5 hl=3 l= 159 cons: SEQUENCE |
+ 423:d=6 hl=2 l= 13 cons: SEQUENCE |
+ 425:d=7 hl=2 l= 9 prim: OBJECT :rsaEncryption |
+ 436:d=7 hl=2 l= 0 prim: NULL |
+ 438:d=6 hl=3 l= 141 prim: BIT STRING |
+ 582:d=4 hl=2 l= 13 cons: SEQUENCE |
+ 584:d=5 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption |
+ 595:d=5 hl=2 l= 0 prim: NULL |
+ 597:d=4 hl=3 l= 129 prim: BIT STRING |
+-----BEGIN OCSP RESPONSE----- |
+MIIC8woBAKCCAuwwggLoBgkrBgEFBQcwAQEEggLZMIIC1TCBjKADAgEBoSMwITEfMB0GA1UEAxM |
+WVGVzdCBGYWxzZSBPQ1NQIFNpZ25lchgPMjAxNjAyMTcxMTQzMzVaME8wTTA4MAcGBSsOAwIaBB |
+QC/3XaJN6K3RUPq2idzObmY20JAQQUigqd7TeSk6wNi8R2oOhQilJhUlkCAQOAABgPMjAxNjAyM |
+TcxMTQzMzVaMA0GCSqGSIb3DQEBBQUAA4GBAAZEHQUvIBx4Jq3DBV0DEZ1Jmg9oEIp2wHkM5srt |
+/Q8/TMbviNVwioOuukfo7srT4o9JwAW8bs/DDfrZBSNMzP4BxWABvG5hQDH7E4d5UDGXlITgyJy |
+apqVVf236aFmi4mg31nYcJRZARKyVomvVwt/lOQUIcIsLdtK1/4OxNiZ3oIIBrzCCAaswggGnMI |
+IBEKADAgECAgECMA0GCSqGSIb3DQEBBQUAMBIxEDAOBgNVBAMTB1Rlc3QgQ0EwHhcNMTYwMjE3M |
+TY0MzM1WhcNMjYwMjE0MTY0MzM1WjAhMR8wHQYDVQQDExZUZXN0IEZhbHNlIE9DU1AgU2lnbmVy |
+MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCiKtn/A/PuIGEV+LFYJIAUVFNilUqUKXAXG+w |
+elsfSCfbPWd9TYvG67v6sDQGFso+KJ+aOCCXWh1+FbC59/T48HyDSEkNWXUg+eAGAP3ubS8t0k1 |
+A2KFGZPyaxTVLeXOpJJsWkiDlccyKRqM8HRcWyFjL9U2vtYOv9+QZYkQVEnQIDAQABMA0GCSqGS |
+Ib3DQEBBQUAA4GBACA0Q7pNDCGyCA77Do/PpuOvKsv34J+2sWvAJ8E7ix2eIcYt5EzsbyBvBRsz |
+arV2p89JdCaWiZJ9gEgwJSdNmAPp4bpD3+BGkaCLhVhdQgcrHhNzKzM0UvvRcxVC9HqydOxzwUP |
+7nV1NNza4nfvFq7779OSfLvYMKx8u2d730azv |
+-----END OCSP RESPONSE----- |
+ |
+$ openssl asn1parse -i < [CA CERTIFICATE] |
+ 0:d=0 hl=4 l= 408 cons: SEQUENCE |
+ 4:d=1 hl=4 l= 257 cons: SEQUENCE |
+ 8:d=2 hl=2 l= 3 cons: cont [ 0 ] |
+ 10:d=3 hl=2 l= 1 prim: INTEGER :02 |
+ 13:d=2 hl=2 l= 1 prim: INTEGER :00 |
+ 16:d=2 hl=2 l= 13 cons: SEQUENCE |
+ 18:d=3 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption |
+ 29:d=3 hl=2 l= 0 prim: NULL |
+ 31:d=2 hl=2 l= 18 cons: SEQUENCE |
+ 33:d=3 hl=2 l= 16 cons: SET |
+ 35:d=4 hl=2 l= 14 cons: SEQUENCE |
+ 37:d=5 hl=2 l= 3 prim: OBJECT :commonName |
+ 42:d=5 hl=2 l= 7 prim: PRINTABLESTRING :Test CA |
+ 51:d=2 hl=2 l= 30 cons: SEQUENCE |
+ 53:d=3 hl=2 l= 13 prim: UTCTIME :160217164335Z |
+ 68:d=3 hl=2 l= 13 prim: UTCTIME :260214164335Z |
+ 83:d=2 hl=2 l= 18 cons: SEQUENCE |
+ 85:d=3 hl=2 l= 16 cons: SET |
+ 87:d=4 hl=2 l= 14 cons: SEQUENCE |
+ 89:d=5 hl=2 l= 3 prim: OBJECT :commonName |
+ 94:d=5 hl=2 l= 7 prim: PRINTABLESTRING :Test CA |
+ 103:d=2 hl=3 l= 159 cons: SEQUENCE |
+ 106:d=3 hl=2 l= 13 cons: SEQUENCE |
+ 108:d=4 hl=2 l= 9 prim: OBJECT :rsaEncryption |
+ 119:d=4 hl=2 l= 0 prim: NULL |
+ 121:d=3 hl=3 l= 141 prim: BIT STRING |
+ 265:d=1 hl=2 l= 13 cons: SEQUENCE |
+ 267:d=2 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption |
+ 278:d=2 hl=2 l= 0 prim: NULL |
+ 280:d=1 hl=3 l= 129 prim: BIT STRING |
+-----BEGIN CA CERTIFICATE----- |
+MIIBmDCCAQGgAwIBAgIBADANBgkqhkiG9w0BAQUFADASMRAwDgYDVQQDEwdUZXN0IENBMB4XDTE |
+2MDIxNzE2NDMzNVoXDTI2MDIxNDE2NDMzNVowEjEQMA4GA1UEAxMHVGVzdCBDQTCBnzANBgkqhk |
+iG9w0BAQEFAAOBjQAwgYkCgYEApRGdydM+hBl3FK9BMy2i0GuR3H9iASfSoirvHgSCPRJ91AbMf |
+/RlOprdI8HHFqNC5FfTipY6zYnHkMaHAM5w8FdqgbDRoJmMy2a37EKHhb4s8jF76PlJrD27n+3t |
+5rmyIOqhXV8tVsIKtKuXVjUsBFSmMsF8TJbv6EjtJxVLhuUCAwEAATANBgkqhkiG9w0BAQUFAAO |
+BgQAZI4He2sX/RYcL3jwdDmTAyyMMmSeQX4JHdH2MptBehktuq32YG5Lb4dJJpMYvatZYmOurcD |
+hduryAgVxT2mEbpbQ9oZDjZHC6AwxECSJS/HP8llURBfJU7tanXBk6NiIpkKAYm6RIUq6sodVTB |
+HxcagPzH2K9s99RKXBBjL7wgA== |
+-----END CA CERTIFICATE----- |
+ |
+$ openssl asn1parse -i < [CERTIFICATE] |
+ 0:d=0 hl=4 l= 410 cons: SEQUENCE |
+ 4:d=1 hl=4 l= 259 cons: SEQUENCE |
+ 8:d=2 hl=2 l= 3 cons: cont [ 0 ] |
+ 10:d=3 hl=2 l= 1 prim: INTEGER :02 |
+ 13:d=2 hl=2 l= 1 prim: INTEGER :03 |
+ 16:d=2 hl=2 l= 13 cons: SEQUENCE |
+ 18:d=3 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption |
+ 29:d=3 hl=2 l= 0 prim: NULL |
+ 31:d=2 hl=2 l= 18 cons: SEQUENCE |
+ 33:d=3 hl=2 l= 16 cons: SET |
+ 35:d=4 hl=2 l= 14 cons: SEQUENCE |
+ 37:d=5 hl=2 l= 3 prim: OBJECT :commonName |
+ 42:d=5 hl=2 l= 7 prim: PRINTABLESTRING :Test CA |
+ 51:d=2 hl=2 l= 30 cons: SEQUENCE |
+ 53:d=3 hl=2 l= 13 prim: UTCTIME :160217164335Z |
+ 68:d=3 hl=2 l= 13 prim: UTCTIME :260214164335Z |
+ 83:d=2 hl=2 l= 20 cons: SEQUENCE |
+ 85:d=3 hl=2 l= 18 cons: SET |
+ 87:d=4 hl=2 l= 16 cons: SEQUENCE |
+ 89:d=5 hl=2 l= 3 prim: OBJECT :commonName |
+ 94:d=5 hl=2 l= 9 prim: PRINTABLESTRING :Test Cert |
+ 105:d=2 hl=3 l= 159 cons: SEQUENCE |
+ 108:d=3 hl=2 l= 13 cons: SEQUENCE |
+ 110:d=4 hl=2 l= 9 prim: OBJECT :rsaEncryption |
+ 121:d=4 hl=2 l= 0 prim: NULL |
+ 123:d=3 hl=3 l= 141 prim: BIT STRING |
+ 267:d=1 hl=2 l= 13 cons: SEQUENCE |
+ 269:d=2 hl=2 l= 9 prim: OBJECT :sha1WithRSAEncryption |
+ 280:d=2 hl=2 l= 0 prim: NULL |
+ 282:d=1 hl=3 l= 129 prim: BIT STRING |
+-----BEGIN CERTIFICATE----- |
+MIIBmjCCAQOgAwIBAgIBAzANBgkqhkiG9w0BAQUFADASMRAwDgYDVQQDEwdUZXN0IENBMB4XDTE |
+2MDIxNzE2NDMzNVoXDTI2MDIxNDE2NDMzNVowFDESMBAGA1UEAxMJVGVzdCBDZXJ0MIGfMA0GCS |
+qGSIb3DQEBAQUAA4GNADCBiQKBgQCmC4zqGNC+KHEtS+PnHTwZKfnrCYycpIa2htLwJ2V+LBdtZ |
+YAWNjJlPdDsayPiu0LzW2sN+E+js3mKVEX0qfzK11vO/17KkXei2G7/nzm8qgOmafyojlnQxYEY |
+DXcW9WlMEAMU1MFuOkXeFwMkQUAAuOEc27BQAK7JX85346ivdQIDAQABMA0GCSqGSIb3DQEBBQU |
+AA4GBADIktrU1l+Og5OsdNW01mav5ajZnpBEaIx1M5PvEd4Cf4OKhGneAXeMluLAs2Ypi4zQKHi |
+Zj2YcWe5c36QDpryWQ5czcNX5zU2FLspAyD3zgUDJDIIykqV8xhph5Q8eiOgV0aM2oW4qk5AxfR |
+9I9NNsEWDJcJ7OGHjRsThaOrth4 |
+-----END CERTIFICATE----- |