You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
hmz007 36ed224bac
Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a)
2 years ago
..
basic-constraints-pathlen-0-self-issued Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
expired-intermediate Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
expired-root Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
expired-target Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
incorrect-trust-anchor Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-and-target-wrong-signature Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-basic-constraints-ca-false Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-basic-constraints-not-critical Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-eku-any-and-clientauth Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-eku-clientauth Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-eku-server-gated-crypto Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-lacks-basic-constraints Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-lacks-signing-key-usage Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-signed-with-sha1 Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-unknown-critical-extension Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-unknown-non-critical-extension Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
intermediate-wrong-signature-no-authority-key-identifier Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
issuer-and-subject-not-byte-for-byte-equal Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
key-rollover Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
many-names Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
non-self-signed-root Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
pkits_errors Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policies-inhibit-anypolicy-by-root-fail Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policies-inhibit-anypolicy-by-root-ok Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policies-inhibit-mapping-by-root-fail Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policies-inhibit-mapping-by-root-ok Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policies-ok Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policies-on-root-ok Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policies-on-root-wrong Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policies-required-by-root-fail Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policies-required-by-root-ok Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policy-mappings-on-root-fail Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
policy-mappings-on-root-ok Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
root-basic-constraints-ca-false Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
root-eku-clientauth Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
root-lacks-basic-constraints Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
root-lacks-keycertsign-key-usage Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-and-intermediate Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-eku-any Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-eku-clientauth Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-eku-many Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-eku-none Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-has-512bit-rsa-key Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-has-ca-basic-constraints Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-has-keycertsign-but-not-ca Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-has-pathlen-but-not-ca Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-not-end-entity Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-only Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-selfissued Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-selfsigned Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-serverauth-various-keyusages Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-signed-by-512bit-rsa Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-signed-using-ecdsa Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-signed-with-sha1 Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-unknown-critical-extension Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-wrong-signature Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
target-wrong-signature-no-authority-key-identifier Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
unknown-critical-policy-qualifier Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
unknown-non-critical-policy-qualifier Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
violates-basic-constraints-pathlen-0 Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
violates-pathlen-1-from-root Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
README Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
generate-all.sh Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago
rebase-errors.py Rockchip Anroid14_SDK 20240628-rkr5 (2556df1a) 2 years ago

README

This directory contains test data for verifying certificate chains.

Tests are grouped into directories that contain the keys, python to generate
chains, and test expectations. "DIR" is used as a generic placeholder below to
identify such a directory.

===============================
DIR/generate-chains.py
===============================

Python script that generates one or more ".pem" file containing a sequence of
CERTIFICATE blocks. In most cases it will generate a single chain called
"chain.pem".

===============================
DIR/keys/*.key
===============================

The keys used (as well as generated) by the .py file generate-chains.py. The
private keys shouldn't be needed to run the tests, however are useful when
re-generating the test data to have stable results (at least for signature
types which are deterministic, like RSASSA PKCS#1 which is used by most of the
certificates data).

===============================
DIR/*.pem
===============================

A sequence of CERTIFICATE blocks that was created by the generate-chains.py
script. (Although in a few cases there are manually created .pem files that
lack a generator script).

===============================
DIR/*.test
===============================

A sequence of key-value pairs that identify the inputs to certificate
verification, as well as the expected outputs. The format is essentially a
newline separated sequence of key/value pairs:

key: value\n

All keys must be specified by tests, although they can be in any order.
The possible keys are:

  "chain" - The value is a file path (relative to the test file) to a .pem
      containing the CERTIFICATE chain.

  "last_cert_trust" - The value identifies the trustedness of the last
      certificate in the chain (i.e. whether it is a trust anchor or not). This
      maps to the CertificateTrustType enum. Possible values are:
          "TRUSTED_ANCHOR"
          "TRUSTED_ANCHOR_WITH_EXPIRATION"
          "TRUSTED_ANCHOR_WITH_CONSTRAINTS"
          "UNSPECIFIED"
          "DISTRUSTED"

  "utc_time" - A string encoding for the generalized time at which verification
      should be done. Example "150302120000Z"

  "key_purpose" - The expected EKU to use when verifying. Maps to
      KeyPurpose enum. Possible values are:
      "ANY_EKU"
      "SERVER_AUTH"
      "CLIENT_AUTH"

  "errors" - This has special parsing rules: it is interpreted as the
      final key in the file. All lines after "errors:\n" are read as being the
      error string (this allows embedding newlines in it).

Additionally, it is possible to add python-style comments by starting a line
with "#".

===============================
pkits_errors/*.txt
===============================

These files contain the expected errors for PKITS tests
(third_party/nist-pkits). The file name correspond so the PKITS tests number.
They are baselined specifically for VerifyCertificateChain().

===============================
generate-all.sh
===============================

Runs all of the generate-chains.py scripts and cleans up the temp files
afterwards.