Index: net/data/ssl/scripts/generate-test-certs.sh |
diff --git a/net/data/ssl/scripts/generate-test-certs.sh b/net/data/ssl/scripts/generate-test-certs.sh |
index c94ca6c3fbe2cc1ebe89870cc18d9f3cdd318a1b..d62bb988a5ddc2730068b83e4a0ce1e036d2cdc2 100755 |
--- a/net/data/ssl/scripts/generate-test-certs.sh |
+++ b/net/data/ssl/scripts/generate-test-certs.sh |
@@ -124,51 +124,7 @@ try openssl req -x509 -days 3650 -extensions req_san_sanity \ |
SUBJECT_NAME="req_punycode_dn" \ |
try openssl req -x509 -days 3650 -extensions req_punycode \ |
-config ../scripts/ee.cnf -newkey rsa:2048 -text \ |
- -out ../certificates/punycodetest.pem |
- |
-## Reject intranet hostnames in "publicly" trusted certs |
-# 365 * 3 = 1095 |
-SUBJECT_NAME="req_dn" \ |
- try openssl req -x509 -days 1095 \ |
- -config ../scripts/ee.cnf -newkey rsa:2048 -text \ |
- -out ../certificates/reject_intranet_hosts.pem |
- |
-## Validity too long |
-# 365 * 11 = 4015 |
-try openssl req -config ../scripts/ee.cnf \ |
- -newkey rsa:2048 -text -out ../certificates/11_year_validity.req |
-CA_COMMON_NAME="Test Root CA" \ |
- try openssl ca \ |
- -batch \ |
- -extensions user_cert \ |
- -startdate 141030000000Z \ |
- -days 4015 \ |
- -in ../certificates/11_year_validity.req \ |
- -out ../certificates/11_year_validity.pem \ |
- -config ca.cnf |
-try openssl req -config ../scripts/ee.cnf \ |
- -newkey rsa:2048 -text -out ../certificates/40_months_after_2015_04.req |
-CA_COMMON_NAME="Test Root CA" \ |
- try openssl ca \ |
- -batch \ |
- -extensions user_cert \ |
- -startdate 150402000000Z \ |
- -enddate 180901000000Z \ |
- -in ../certificates/40_months_after_2015_04.req \ |
- -out ../certificates/40_months_after_2015_04.pem \ |
- -config ca.cnf |
-try openssl req -config ../scripts/ee.cnf \ |
- -newkey rsa:2048 -text -out ../certificates/61_months_after_2012_07.req |
-# 30 * 61 = 1830 |
-CA_COMMON_NAME="Test Root CA" \ |
- try openssl ca \ |
- -batch \ |
- -extensions user_cert \ |
- -startdate 141030000000Z \ |
- -days 1830 \ |
- -in ../certificates/61_months_after_2012_07.req \ |
- -out ../certificates/61_months_after_2012_07.pem \ |
- -config ca.cnf |
+ -out ../certificates/punycodetest.pem |
# Regenerate CRLSets |
## Block a leaf cert directly by SPKI |