summaryrefslogtreecommitdiff
path: root/tests/certs/scripts
Commit message (Collapse)AuthorAgeFilesLines
* whitespace fixesViktor Szakats2018-09-233-33/+30
| | | | | | | | | | | - replace tabs with spaces where possible - remove line ending spaces - remove double/triple newlines at EOF - fix a non-UTF-8 character - cleanup a few indentations/line continuations in manual examples Closes https://github.com/curl/curl/pull/3037
* certs: generate tests certs with sha256 digest algorithmDaniel Stenberg2018-09-202-4/+8
| | | | | | | | As OpenSSL 1.1.1 starts to complain and fail on sha1 CAs: "SSL certificate problem: CA signature digest algorithm too weak" Closes #3014
* tests/certs: rebuild certs with 2048-bit RSA keysYiming Jing2018-09-121-1/+1
| | | | | | | | | | | The previous test certificates contained RSA keys of only 1024 bits. However, RSA claims that 1024-bit RSA keys are likely to become crackable some time before 2010. The NIST recommends at least 2048-bit keys for RSA for now. Better use full 2048 also for testing. Closes #2973
* spelling fixesklemens2017-03-261-1/+1
| | | | Closes #1356
* URLs: change all http:// URLs to https://Daniel Stenberg2016-02-031-1/+1
|
* tests/certs: added make target to rebuild certificatesDan Fandrich2015-03-212-6/+6
| | | | | The certificate generation scripts were also updated to better match the format of the certificates currently checked in.
* SSL: Add PEM format support for public key pinningmoparisthebest2014-11-241-0/+3
|
* SSL: implement public key pinningmoparisthebest2014-10-071-0/+3
| | | | | | | | | | | | Option --pinnedpubkey takes a path to a public key in DER format and only connect if it matches (currently only implemented with OpenSSL). Provides CURLOPT_PINNEDPUBLICKEY for curl_easy_setopt(). Extract a public RSA key from a website like so: openssl s_client -connect google.com:443 2>&1 < /dev/null | \ sed -n '/-----BEGIN/,/-----END/p' | openssl x509 -noout -pubkey \ | openssl rsa -pubin -outform DER > google.com.der
* commit bc682cbd follow-upYang Tse2013-01-151-0/+1
|
* tests/Makefile.am: remove wildcard usage in EXTRA_DISTYang Tse2013-01-151-0/+28
|
* tests/certs/scripts: generate also CRLKamil Dudka2010-05-272-7/+16
| | | | ... and make it possible to do so without any user interaction
* removed trailing whitespaceYang Tse2010-02-142-11/+11
|
* - Peter Sylvester made the HTTPS test server use specific certificates forDaniel Stenberg2009-08-112-0/+169
each test, so that the test suite can now be used to actually test the verification of cert names etc. This made an error show up in the OpenSSL- specific code where it would attempt to match the CN field even if a subjectAltName exists that doesn't match. This is now fixed and verified in test 311.