Index: net/data/ssl/scripts/generate-test-certs.sh |
diff --git a/net/data/ssl/scripts/generate-test-certs.sh b/net/data/ssl/scripts/generate-test-certs.sh |
index a3e04e000d2cd2463cf5e74267ccae819f2de351..55c54bb3ff6dbff40e8cbd4e97fac193f7538514 100755 |
--- a/net/data/ssl/scripts/generate-test-certs.sh |
+++ b/net/data/ssl/scripts/generate-test-certs.sh |
@@ -371,6 +371,14 @@ CA_COMMON_NAME="Test Root CA" \ |
-out ../certificates/post_june_2016.pem \ |
-config ca.cnf |
+# Includes the TLS feature extension |
+try openssl req -x509 -newkey rsa:2048 \ |
+ -keyout out/tls_feature_extension.key \ |
+ -out ../certificates/tls_feature_extension.pem \ |
+ -days 365 \ |
+ -extensions req_extensions_with_tls_feature \ |
+ -nodes -config ee.cnf |
+ |
# Regenerate CRLSets |
## Block a leaf cert directly by SPKI |