<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/curl.git/tests/certs/Server-localhost-sv.pem, branch bagder/https-proxyu-req-http</title>
<subtitle>github.com: bagder/curl.git
</subtitle>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/'/>
<entry>
<title>certs: generate tests certs with sha256 digest algorithm</title>
<updated>2018-09-20T07:06:21+00:00</updated>
<author>
<name>Daniel Stenberg</name>
<email>daniel@haxx.se</email>
</author>
<published>2018-09-19T07:04:48+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=ba782baac3009e44295589743bb8ae8220793e74'/>
<id>ba782baac3009e44295589743bb8ae8220793e74</id>
<content type='text'>
As OpenSSL 1.1.1 starts to complain and fail on sha1 CAs:

"SSL certificate problem: CA signature digest algorithm too weak"

Closes #3014
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
As OpenSSL 1.1.1 starts to complain and fail on sha1 CAs:

"SSL certificate problem: CA signature digest algorithm too weak"

Closes #3014
</pre>
</div>
</content>
</entry>
<entry>
<title>tests/certs: rebuild certs with 2048-bit RSA keys</title>
<updated>2018-09-12T14:09:17+00:00</updated>
<author>
<name>Yiming Jing</name>
<email>jingyiming@baidu.com</email>
</author>
<published>2018-09-10T18:32:23+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=92f9db17466c4e28998a5cf849c7a861093eff23'/>
<id>92f9db17466c4e28998a5cf849c7a861093eff23</id>
<content type='text'>
The previous test certificates contained RSA keys of only 1024 bits.
However, RSA claims that 1024-bit RSA keys are likely to become
crackable some time before 2010. The NIST recommends at least 2048-bit
keys for RSA for now.

Better use full 2048 also for testing.

Closes #2973
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The previous test certificates contained RSA keys of only 1024 bits.
However, RSA claims that 1024-bit RSA keys are likely to become
crackable some time before 2010. The NIST recommends at least 2048-bit
keys for RSA for now.

Better use full 2048 also for testing.

Closes #2973
</pre>
</div>
</content>
</entry>
<entry>
<title>spelling fixes</title>
<updated>2017-03-26T21:56:23+00:00</updated>
<author>
<name>klemens</name>
<email>ka7@github.com</email>
</author>
<published>2017-03-26T15:02:22+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=f7df67cff0a756eefc8daea36e6468df694a43d0'/>
<id>f7df67cff0a756eefc8daea36e6468df694a43d0</id>
<content type='text'>
Closes #1356
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Closes #1356
</pre>
</div>
</content>
</entry>
<entry>
<title>tests/certs: rebuild certificates with modified key usage bits</title>
<updated>2015-03-21T15:33:58+00:00</updated>
<author>
<name>Dan Fandrich</name>
<email>dan@coneharvesters.com</email>
</author>
<published>2015-03-21T15:20:34+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=f9251a5c86f86388bb9aaa078738fcf49870ca3f'/>
<id>f9251a5c86f86388bb9aaa078738fcf49870ca3f</id>
<content type='text'>
The certificates were missing the digitalSignature and keyAgreement
usage types, of which at least digitalSignature was checked by CyaSSL.
This caused the test server in test 310 (among others) to fail the
startup verification and therefore run (see
http://curl.haxx.se/mail/lib-2014-07/0303.html).
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
The certificates were missing the digitalSignature and keyAgreement
usage types, of which at least digitalSignature was checked by CyaSSL.
This caused the test server in test 310 (among others) to fail the
startup verification and therefore run (see
http://curl.haxx.se/mail/lib-2014-07/0303.html).
</pre>
</div>
</content>
</entry>
<entry>
<title>tests/certs: re-generated because of lost pass-phrase</title>
<updated>2010-05-27T21:39:54+00:00</updated>
<author>
<name>Kamil Dudka</name>
<email>kdudka@redhat.com</email>
</author>
<published>2010-05-27T21:39:54+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=99179da4ccd66af7d9f84410ff66ab91102d6e18'/>
<id>99179da4ccd66af7d9f84410ff66ab91102d6e18</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>- Added Diffie-Hellman parameters to several test harness certificate files in</title>
<updated>2009-11-28T10:01:21+00:00</updated>
<author>
<name>Yang Tse</name>
<email>yangsita@gmail.com</email>
</author>
<published>2009-11-28T10:01:21+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=4d922545d571d002129412d22b19031a4056d3b9'/>
<id>4d922545d571d002129412d22b19031a4056d3b9</id>
<content type='text'>
  PEM format. Required by several stunnel versions used by our test harness.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
  PEM format. Required by several stunnel versions used by our test harness.
</pre>
</div>
</content>
</entry>
<entry>
<title>- Peter Sylvester made the HTTPS test server use specific certificates for</title>
<updated>2009-08-11T21:48:58+00:00</updated>
<author>
<name>Daniel Stenberg</name>
<email>daniel@haxx.se</email>
</author>
<published>2009-08-11T21:48:58+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/curl.git/commit/?id=e73fe837a8877c0197721b91e0d5ec40cb7a2cd0'/>
<id>e73fe837a8877c0197721b91e0d5ec40cb7a2cd0</id>
<content type='text'>
  each test, so that the test suite can now be used to actually test the
  verification of cert names etc. This made an error show up in the OpenSSL-
  specific code where it would attempt to match the CN field even if a
  subjectAltName exists that doesn't match. This is now fixed and verified
  in test 311.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
  each test, so that the test suite can now be used to actually test the
  verification of cert names etc. This made an error show up in the OpenSSL-
  specific code where it would attempt to match the CN field even if a
  subjectAltName exists that doesn't match. This is now fixed and verified
  in test 311.
</pre>
</div>
</content>
</entry>
</feed>
