summaryrefslogtreecommitdiff
path: root/tests
diff options
context:
space:
mode:
authorKevin Jacobs <kjacobs@mozilla.com>2021-01-23 18:50:04 +0000
committerKevin Jacobs <kjacobs@mozilla.com>2021-01-23 18:50:04 +0000
commit34e04960e009510c84d419ec3edd6d31cfff1bea (patch)
tree05ce29cd536cb35bc6e91c384150483a89ffa9c2 /tests
parente6e489c764ee179ad2a6e1daf194430f68ee4d9e (diff)
downloadnss-hg-34e04960e009510c84d419ec3edd6d31cfff1bea.tar.gz
Bug 1686134 - Renew two chains libpkix test certificates. r=rrelyea
Differential Revision: https://phabricator.services.mozilla.com/D102670
Diffstat (limited to 'tests')
-rw-r--r--tests/chains/scenarios/nameconstraints.cfg12
-rw-r--r--tests/libpkix/certs/NameConstraints.ipaca.certbin981 -> 1000 bytes
-rw-r--r--tests/libpkix/certs/NameConstraints.ocsp1.certbin898 -> 956 bytes
3 files changed, 10 insertions, 2 deletions
diff --git a/tests/chains/scenarios/nameconstraints.cfg b/tests/chains/scenarios/nameconstraints.cfg
index 4a149032b..a2de4be44 100644
--- a/tests/chains/scenarios/nameconstraints.cfg
+++ b/tests/chains/scenarios/nameconstraints.cfg
@@ -159,12 +159,20 @@ verify NameConstraints.dcissblocked:x
verify NameConstraints.dcissallowed:x
result pass
-# Subject: "O = IPA.LOCAL 201901211552, CN = OCSP Subsystem"
+# Subject: "O = IPA.LOCAL 20200120, CN = OCSP and IPSEC"
+# EKUs: OCSPSigning,ipsecUser
#
# This tests that a non server certificate (i.e. id-kp-serverAuth
# not present in EKU) does *NOT* have CN treated as dnsName for
-# purposes of Name Constraints validation
+# purposes of Name Constraints validation (certificateUsageStatusResponder)
+# https://hg.mozilla.org/projects/nss/rev/0b30eb1c3650
verify NameConstraints.ocsp1:x
usage 10
result pass
+# This tests that a non server certificate (i.e. id-kp-serverAuth
+# not present in EKU) does *NOT* have CN treated as dnsName for
+# purposes of Name Constraints validation (certificateUsageIPsec)
+verify NameConstraints.ocsp1:x
+ usage 12
+ result pass
diff --git a/tests/libpkix/certs/NameConstraints.ipaca.cert b/tests/libpkix/certs/NameConstraints.ipaca.cert
index 6c7d68c77..4a451f342 100644
--- a/tests/libpkix/certs/NameConstraints.ipaca.cert
+++ b/tests/libpkix/certs/NameConstraints.ipaca.cert
Binary files differ
diff --git a/tests/libpkix/certs/NameConstraints.ocsp1.cert b/tests/libpkix/certs/NameConstraints.ocsp1.cert
index ce7325fca..817faafe3 100644
--- a/tests/libpkix/certs/NameConstraints.ocsp1.cert
+++ b/tests/libpkix/certs/NameConstraints.ocsp1.cert
Binary files differ