From: Steffan Karger Date: Sun, 18 Jun 2017 10:57:40 +0000 (+0200) Subject: Add a DSA test key/cert pair to sample-keys X-Git-Tag: v2.4.3~15 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=d937bb7eccc77ceb668cf64a8b2109329ed2aecd;p=thirdparty%2Fopenvpn.git Add a DSA test key/cert pair to sample-keys Makes it easier to test changes to DSA-related code. Signed-off-by: Steffan Karger Acked-by: Gert Doering Message-Id: <20170618105740.10090-1-steffan@karger.me> URL: https://www.mail-archive.com/search?l=mid&q=20170618105740.10090-1-steffan@karger.me Signed-off-by: Gert Doering (cherry picked from commit 3d215d4c9d107fa153082e2bba8a3a9c8865be5d) --- diff --git a/sample/sample-keys/gen-sample-keys.sh b/sample/sample-keys/gen-sample-keys.sh index 301cff280..920513a19 100755 --- a/sample/sample-keys/gen-sample-keys.sh +++ b/sample/sample-keys/gen-sample-keys.sh @@ -61,6 +61,22 @@ openssl ca -batch -config openssl.cnf \ openssl ca -config openssl.cnf -revoke sample-ca/client-revoked.crt openssl ca -config openssl.cnf -gencrl -out sample-ca/ca.crl +# Create DSA server and client cert (signed by 'regular' RSA CA) +openssl dsaparam -out sample-ca/dsaparams.pem 2048 + +openssl req -new -newkey dsa:sample-ca/dsaparams.pem -nodes -config openssl.cnf \ + -extensions server \ + -keyout sample-ca/server-dsa.key -out sample-ca/server-dsa.csr \ + -subj "/C=KG/ST=NA/O=OpenVPN-TEST/CN=Test-Server-DSA/emailAddress=me@myhost.mydomain" +openssl ca -batch -config openssl.cnf -extensions server \ + -out sample-ca/server-dsa.crt -in sample-ca/server-dsa.csr + +openssl req -new -newkey dsa:sample-ca/dsaparams.pem -nodes -config openssl.cnf \ + -keyout sample-ca/client-dsa.key -out sample-ca/client-dsa.csr \ + -subj "/C=KG/ST=NA/O=OpenVPN-TEST/CN=Test-Client-DSA/emailAddress=me@myhost.mydomain" +openssl ca -batch -config openssl.cnf \ + -out sample-ca/client-dsa.crt -in sample-ca/client-dsa.csr + # Create EC server and client cert (signed by 'regular' RSA CA) openssl ecparam -out sample-ca/secp256k1.pem -name secp256k1