Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(656)

Side by Side Diff: net/data/verify_certificate_chain_unittest/unconstrained-root-bad-eku/generate-chains.py

Issue 2805213004: Refactor how net/data/verify_certificate_chain_unittest/* (Closed)
Patch Set: fix android Created 3 years, 7 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 #!/usr/bin/python 1 #!/usr/bin/python
2 # Copyright (c) 2017 The Chromium Authors. All rights reserved. 2 # Copyright (c) 2017 The Chromium Authors. All rights reserved.
3 # Use of this source code is governed by a BSD-style license that can be 3 # Use of this source code is governed by a BSD-style license that can be
4 # found in the LICENSE file. 4 # found in the LICENSE file.
5 5
6 """Certificate chain with 1 intermediate and a trust anchor. The trust anchor 6 """Certificate chain with 1 intermediate and a trust anchor. The trust anchor
7 has an EKU that restricts it to clientAuth. Verification is expected to fail as 7 has an EKU that restricts it to clientAuth. Verification is expected to fail as
8 the end-entity is verified for serverAuth, and the trust anchor enforces 8 the end-entity is verified for serverAuth, and the trust anchor enforces
9 constraints.""" 9 constraints."""
10 10
11 import sys
12 sys.path += ['..']
13
11 import common 14 import common
12 15
13 # Self-signed root certificate (used as trust anchor) with non-CA basic 16 # Self-signed root certificate (used as trust anchor) with non-CA basic
14 # constraints. 17 # constraints.
15 root = common.create_self_signed_root_certificate('Root') 18 root = common.create_self_signed_root_certificate('Root')
16 root.get_extensions().set_property('extendedKeyUsage', 'clientAuth') 19 root.get_extensions().set_property('extendedKeyUsage', 'clientAuth')
17 20
18 # Intermediate certificate. 21 # Intermediate certificate.
19 intermediate = common.create_intermediate_certificate('Intermediate', root) 22 intermediate = common.create_intermediate_certificate('Intermediate', root)
20 23
21 # Target certificate. 24 # Target certificate.
22 target = common.create_end_entity_certificate('Target', intermediate) 25 target = common.create_end_entity_certificate('Target', intermediate)
23 26
24 chain = [target, intermediate] 27 chain = [target, intermediate, root]
25 trusted = common.TrustAnchor(root, constrained=True) 28 common.write_chain(__doc__, chain, 'chain.pem')
26 time = common.DEFAULT_TIME
27 key_purpose = common.KEY_PURPOSE_SERVER_AUTH
28 verify_result = False
29 errors = """----- Certificate i=2 (CN=Root) -----
30 ERROR: The extended key usage does not include server auth
31
32 """
33
34 common.write_test_file(__doc__, chain, trusted, time, key_purpose,
35 verify_result, errors)
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698