Commit e24c7f21 authored by Kevin Jacobs's avatar Kevin Jacobs

Bug 1686134 - Renew two chains libpkix test certificates. r=rrelyea

Differential Revision: https://phabricator.services.mozilla.com/D102670

--HG--
extra : moz-landing-system : lando
parent 5fbb2d53
...@@ -159,12 +159,20 @@ verify NameConstraints.dcissblocked:x ...@@ -159,12 +159,20 @@ verify NameConstraints.dcissblocked:x
verify NameConstraints.dcissallowed:x verify NameConstraints.dcissallowed:x
result pass result pass
# Subject: "O = IPA.LOCAL 201901211552, CN = OCSP Subsystem" # Subject: "O = IPA.LOCAL 20200120, CN = OCSP and IPSEC"
# EKUs: OCSPSigning,ipsecUser
# #
# This tests that a non server certificate (i.e. id-kp-serverAuth # This tests that a non server certificate (i.e. id-kp-serverAuth
# not present in EKU) does *NOT* have CN treated as dnsName for # not present in EKU) does *NOT* have CN treated as dnsName for
# purposes of Name Constraints validation # purposes of Name Constraints validation (certificateUsageStatusResponder)
# https://hg.mozilla.org/projects/nss/rev/0b30eb1c3650
verify NameConstraints.ocsp1:x verify NameConstraints.ocsp1:x
usage 10 usage 10
result pass result pass
# This tests that a non server certificate (i.e. id-kp-serverAuth
# not present in EKU) does *NOT* have CN treated as dnsName for
# purposes of Name Constraints validation (certificateUsageIPsec)
verify NameConstraints.ocsp1:x
usage 12
result pass
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment