Index: net/data/verify_certificate_chain_unittest/target-has-keycertsign-but-not-ca/chain.pem |
diff --git a/net/data/verify_certificate_chain_unittest/target-has-keycertsign-but-not-ca/chain.pem b/net/data/verify_certificate_chain_unittest/target-has-keycertsign-but-not-ca/chain.pem |
index 6ddc5ff7f68cee89372a48520d56ad1bb4c8b363..b168de1787cb0830581ba50d525f8ef3014fa659 100644 |
--- a/net/data/verify_certificate_chain_unittest/target-has-keycertsign-but-not-ca/chain.pem |
+++ b/net/data/verify_certificate_chain_unittest/target-has-keycertsign-but-not-ca/chain.pem |
@@ -1,9 +1,8 @@ |
[Created by: generate-chains.py] |
-Certificate chain with 1 intermediate, a trusted root, and a target |
-certificate that is not a CA, and yet has the keyCertSign bit set. Verification |
-is expected to fail, since keyCertSign should only be asserted when CA is |
-true. |
+Certificate chain where the leaf certificate asserts the keyCertSign key |
+usage, however does not have CA=true in the basic constraints extension to |
+indicate it is a CA. |
Certificate: |
Data: |