| Index: net/data/verify_certificate_chain_unittest/generate-constrained-root-basic-constraints-ca-false.py
|
| diff --git a/net/data/verify_certificate_chain_unittest/generate-intermediate-basic-constraints-ca-false.py b/net/data/verify_certificate_chain_unittest/generate-constrained-root-basic-constraints-ca-false.py
|
| similarity index 57%
|
| copy from net/data/verify_certificate_chain_unittest/generate-intermediate-basic-constraints-ca-false.py
|
| copy to net/data/verify_certificate_chain_unittest/generate-constrained-root-basic-constraints-ca-false.py
|
| index 41bfe0a1ba3a0e2589370fb002d75f9ffddd6b9c..98e7fce0de9fdbb2de5278654552a40cd2ad8d90 100755
|
| --- a/net/data/verify_certificate_chain_unittest/generate-intermediate-basic-constraints-ca-false.py
|
| +++ b/net/data/verify_certificate_chain_unittest/generate-constrained-root-basic-constraints-ca-false.py
|
| @@ -3,26 +3,27 @@
|
| # Use of this source code is governed by a BSD-style license that can be
|
| # found in the LICENSE file.
|
|
|
| -"""Certificate chain with 1 intermediate and a trusted root. The intermediate
|
| +"""Certificate chain with 1 intermediate and a trust anchor. The trust anchor
|
| has a basic constraints extension that indicates it is NOT a CA. Verification
|
| -is expected to fail."""
|
| +is expected to succeed even though the trust anchor enforces constraints, since
|
| +the CA part of basic constraints is not enforced."""
|
|
|
| import common
|
|
|
| -# Self-signed root certificate (used as trust anchor).
|
| +# Self-signed root certificate (used as trust anchor) with non-CA basic
|
| +# constraints.
|
| root = common.create_self_signed_root_certificate('Root')
|
| +root.get_extensions().set_property('basicConstraints', 'critical,CA:false')
|
|
|
| -# Intermediate with incorrect basic constraints.
|
| +# Intermediate certificate.
|
| intermediate = common.create_intermediate_certificate('Intermediate', root)
|
| -intermediate.get_extensions().set_property('basicConstraints',
|
| - 'critical,CA:false')
|
|
|
| # Target certificate.
|
| target = common.create_end_entity_certificate('Target', intermediate)
|
|
|
| chain = [target, intermediate]
|
| -trusted = common.TrustAnchor(root, constrained=False)
|
| +trusted = common.TrustAnchor(root, constrained=True)
|
| time = common.DEFAULT_TIME
|
| -verify_result = False
|
| +verify_result = True
|
|
|
| common.write_test_file(__doc__, chain, trusted, time, verify_result)
|
|
|