]> git.ipfire.org Git - thirdparty/postgresql.git/commit
Update ssl test certificates and keys
authorPeter Eisentraut <peter@eisentraut.org>
Thu, 3 Jan 2019 14:06:53 +0000 (15:06 +0100)
committerPeter Eisentraut <peter@eisentraut.org>
Thu, 3 Jan 2019 14:07:54 +0000 (15:07 +0100)
commit114635e552353585a53120539a6bdefba2324362
tree1017ef23e519aa0f9977f16ee3c0e04e637de254
parent64edc788b4a509427eb407b0d8faac75bac5e02b
Update ssl test certificates and keys

Debian testing and newer now require that RSA and DHE keys are at
least 2048 bit long and no longer allow SHA-1 for signatures in
certificates.  This is currently causing the ssl tests to fail there
because the test certificates and keys have been created in violation
of those conditions.

Update the parameters to create the test files and create a new set of
test files.

Author: Kyotaro HORIGUCHI <horiguchi.kyotaro@lab.ntt.co.jp>
Reported-by: Michael Paquier <michael@paquier.xyz>
Discussion: https://www.postgresql.org/message-id/flat/20180917131340.GE31460%40paquier.xyz
36 files changed:
src/test/ssl/Makefile
src/test/ssl/cas.config
src/test/ssl/ssl/both-cas-1.crt
src/test/ssl/ssl/both-cas-2.crt
src/test/ssl/ssl/client+client_ca.crt
src/test/ssl/ssl/client-revoked.crt
src/test/ssl/ssl/client-revoked.key
src/test/ssl/ssl/client.crl
src/test/ssl/ssl/client.crt
src/test/ssl/ssl/client.key
src/test/ssl/ssl/client_ca.crt
src/test/ssl/ssl/client_ca.key
src/test/ssl/ssl/root+client.crl
src/test/ssl/ssl/root+client_ca.crt
src/test/ssl/ssl/root+server.crl
src/test/ssl/ssl/root+server_ca.crt
src/test/ssl/ssl/root.crl
src/test/ssl/ssl/root_ca.crt
src/test/ssl/ssl/root_ca.key
src/test/ssl/ssl/server-cn-and-alt-names.crt
src/test/ssl/ssl/server-cn-and-alt-names.key
src/test/ssl/ssl/server-cn-only.crt
src/test/ssl/ssl/server-cn-only.key
src/test/ssl/ssl/server-multiple-alt-names.crt
src/test/ssl/ssl/server-multiple-alt-names.key
src/test/ssl/ssl/server-no-names.crt
src/test/ssl/ssl/server-no-names.key
src/test/ssl/ssl/server-revoked.crt
src/test/ssl/ssl/server-revoked.key
src/test/ssl/ssl/server-single-alt-name.crt
src/test/ssl/ssl/server-single-alt-name.key
src/test/ssl/ssl/server-ss.crt
src/test/ssl/ssl/server-ss.key
src/test/ssl/ssl/server.crl
src/test/ssl/ssl/server_ca.crt
src/test/ssl/ssl/server_ca.key