Index: net/data/verify_certificate_chain_unittest/root-basic-constraints-ca-false/generate-chains.py |
diff --git a/net/data/verify_certificate_chain_unittest/root-basic-constraints-ca-false/generate-chains.py b/net/data/verify_certificate_chain_unittest/root-basic-constraints-ca-false/generate-chains.py |
index 4919d354567d909b03fca1f2cfa35f654e27de26..23a313caf524b2847dd22471b97f12280c37766a 100755 |
--- a/net/data/verify_certificate_chain_unittest/root-basic-constraints-ca-false/generate-chains.py |
+++ b/net/data/verify_certificate_chain_unittest/root-basic-constraints-ca-false/generate-chains.py |
@@ -3,18 +3,15 @@ |
# Use of this source code is governed by a BSD-style license that can be |
# found in the LICENSE file. |
-"""Certificate chain with 1 intermediate and a trust anchor. The trust anchor |
-has a basic constraints extension that indicates it is NOT a CA. Verification |
-is expected to succeed even though the trust anchor enforces constraints, since |
-the CA part of basic constraints is not enforced.""" |
+"""Certificate chain where the root certificate contains a basic constraints |
+extension that indicates it is NOT a CA.""" |
import sys |
sys.path += ['..'] |
import common |
-# Self-signed root certificate (used as trust anchor) with non-CA basic |
-# constraints. |
+# Self-signed root certificate with non-CA basic constraints. |
root = common.create_self_signed_root_certificate('Root') |
root.get_extensions().set_property('basicConstraints', 'critical,CA:false') |