Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(1140)

Unified Diff: net/data/ssl/certificates/README

Issue 724543002: Reject certificates that are valid for too long. (Closed) Base URL: https://chromium.googlesource.com/chromium/src.git@master
Patch Set: Whitespace nit(s). Created 5 years, 11 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View side-by-side diff with in-line comments
Download patch
Index: net/data/ssl/certificates/README
diff --git a/net/data/ssl/certificates/README b/net/data/ssl/certificates/README
index 5d1faf2602e93cac097843f2fd24e1b62a7401b7..61d978513272afa1a4beba6499358edb3c05570e 100644
--- a/net/data/ssl/certificates/README
+++ b/net/data/ssl/certificates/README
@@ -70,6 +70,9 @@ unit tests.
- comodo.chain.pem : A certificate chain for www.comodo.com which should be
recognised as EV. Expires Jun 20 2015.
+- twitter-chain.pem : A certificate chain for twitter.com which should be
+ valid. Expires May 9 2016.
+
===== Manually generated certificates
- client.p12 : A PKCS #12 file containing a client certificate and a private
key created for testing. The password is "12345".
@@ -129,8 +132,8 @@ unit tests.
- expired_cert.pem
- ok_cert.pem
- root_ca_cert.pem
- These certificates are the common certificates used by the Python test
- server for simulating HTTPS connections.
+ These certificates are the common certificates used by the Python test
+ server for simulating HTTPS connections.
- name_constraint_bad.pem
- name_constraint_good.pem
@@ -147,6 +150,23 @@ unit tests.
- punycodetest.pem : A test self-signed server certificate with punycode name.
The common name is "xn--wgv71a119e.com" (日本語.com)
+- 10_year_validity.pem
+- 11_year_validity.pem
+- 39_months_after_2015_04.pem
+- 40_months_after_2015_04.pem
+- 60_months_after_2012_07.pem
+- 61_months_after_2012_07.pem
+- pre_br_validity_bad_121.pem
+- pre_br_validity_bad_2020.pem
+- pre_br_validity_ok.pem
+- start_after_expiry.pem
+ Certs to test that the maximum validity durations set by the CA/Browser
+ Forum Baseline Requirements are enforced.
+
+- reject_intranet_hosts.pem
+ A certificate with a non-IANA delegated domain, which is rejected since a CA
+ cannot validate the applicant controls that domain.
+
===== From net/data/ssl/scripts/generate-weak-test-chains.sh
- 2048-rsa-root.pem
- {768-rsa,1024-rsa,2048-rsa,prime256v1-ecdsa}-intermediate.pem
@@ -252,5 +272,3 @@ unit tests.
containing the intermediate, which can be served via a URLRequestFilter.
aia-intermediate.der is stored in DER form for convenience, since that is
the form expected of certificates discovered via AIA.
-
-
« no previous file with comments | « net/data/ssl/certificates/61_months_after_2012_07.pem ('k') | net/data/ssl/certificates/pre_br_validity_bad_121.pem » ('j') | no next file with comments »

Powered by Google App Engine
This is Rietveld 408576698