From 8a41468e95010d9d5bcf8d23a5acaab272777aa7 Mon Sep 17 00:00:00 2001 From: Gilles Peskine Date: Thu, 7 May 2026 18:20:39 +0200 Subject: [PATCH] Add CA:TRUE version of server5-selfsigned.crt Signed-off-by: Gilles Peskine --- data_files/Makefile | 12 ++++++++++++ data_files/server5-ca.der | Bin 0 -> 461 bytes 2 files changed, 12 insertions(+) create mode 100644 data_files/server5-ca.der diff --git a/data_files/Makefile b/data_files/Makefile index b8f1c39f2..7b39d031f 100644 --- a/data_files/Makefile +++ b/data_files/Makefile @@ -473,6 +473,18 @@ server5-selfsigned.crt.der: server5-selfsigned.crt $(OPENSSL) x509 -inform PEM -in $< -outform DER -out $@ all_final += server5-selfsigned.crt.der +server5-ca.der: server5.key + openssl req -x509 -key server5.key \ + -sha256 -days 3650 -nodes \ + -addext basicConstraints=critical,CA:TRUE \ + -addext keyUsage=critical,digitalSignature \ + -addext subjectKeyIdentifier=hash \ + -addext authorityKeyIdentifier=none \ + -set_serial 0x53a2cb4b124ead837da894b2 \ + -subj "/CN=selfsigned/OU=testing/O=PolarSSL/C=NL" \ + -outform DER -out $@ +all_final += server5-ca.der + # Create a certificate which is almost identical to "server3.crt", i.e. # it contains a public EC key and it is signed with RSA. The main difference # compared to "server3.crt" is that in this case we use a secp256r1 key ("server5.key") diff --git a/data_files/server5-ca.der b/data_files/server5-ca.der new file mode 100644 index 0000000000000000000000000000000000000000..1216a10dad70857f2b66d10d42f9a0feee10c896 GIT binary patch literal 461 zcmXqLVmxWk#8|L^nTe5!i6?l`X>TFFwav9Frff3cV&l+i^EhYA!pvmgZYXRZ$i^JX z!py@}oSKtXoSB}Nnqnwmzy}iK=3y^MEiTE-OE(lW;0K9t@o)s>=Oh*d2m2Uu8*qYz z*o2wU&zhn{{E4H_*<4|@v zZ|K=BExuojC$_x(zu3vZ0qjdzVMfOPEUX61KnffXviu+cV0f`N7{~(sEX&6t#v&4s zxU~NY`_1c3j66?M>wA*jmJ9Dg4qRq;1_Ku+1;4$EtREcX$c+s6ob}P+T=Xy5!~5LD yXL4009FVhUDF4W$z|~_sDRO#`dHjOV%~ew-%-(NdUFvWCKG^r(pY%zxstN#AA%^t; literal 0 HcmV?d00001