]> granicus.if.org Git - postgresql/commit
Update ssl test certificates and keys
authorPeter Eisentraut <peter_e@gmx.net>
Tue, 27 Nov 2018 14:16:14 +0000 (15:16 +0100)
committerPeter Eisentraut <peter_e@gmx.net>
Tue, 27 Nov 2018 14:16:14 +0000 (15:16 +0100)
commitf17889b2214194d7bd33900509bf08959d5a7efa
tree26f2dc188a1658adbdb99e67cfdf8886c957ffed
parent4c8750a9cc3402e4d8ec0b47901c2f9ca416b718
Update ssl test certificates and keys

Debian testing and newer now require that RSA and DHE keys are at
least 2048 bit long and no longer allow SHA-1 for signatures in
certificates.  This is currently causing the ssl tests to fail there
because the test certificates and keys have been created in violation
of those conditions.

Update the parameters to create the test files and create a new set of
test files.

Author: Kyotaro HORIGUCHI <horiguchi.kyotaro@lab.ntt.co.jp>
Reported-by: Michael Paquier <michael@paquier.xyz>
Discussion: https://www.postgresql.org/message-id/flat/20180917131340.GE31460%40paquier.xyz
37 files changed:
src/test/ssl/Makefile
src/test/ssl/cas.config
src/test/ssl/ssl/both-cas-1.crt
src/test/ssl/ssl/both-cas-2.crt
src/test/ssl/ssl/client+client_ca.crt
src/test/ssl/ssl/client-revoked.crt
src/test/ssl/ssl/client-revoked.key
src/test/ssl/ssl/client.crl
src/test/ssl/ssl/client.crt
src/test/ssl/ssl/client.key
src/test/ssl/ssl/client_ca.crt
src/test/ssl/ssl/client_ca.key
src/test/ssl/ssl/root+client.crl
src/test/ssl/ssl/root+client_ca.crt
src/test/ssl/ssl/root+server.crl
src/test/ssl/ssl/root+server_ca.crt
src/test/ssl/ssl/root.crl
src/test/ssl/ssl/root_ca.crt
src/test/ssl/ssl/root_ca.key
src/test/ssl/ssl/server-cn-and-alt-names.crt
src/test/ssl/ssl/server-cn-and-alt-names.key
src/test/ssl/ssl/server-cn-only.crt
src/test/ssl/ssl/server-cn-only.key
src/test/ssl/ssl/server-multiple-alt-names.crt
src/test/ssl/ssl/server-multiple-alt-names.key
src/test/ssl/ssl/server-no-names.crt
src/test/ssl/ssl/server-no-names.key
src/test/ssl/ssl/server-password.key
src/test/ssl/ssl/server-revoked.crt
src/test/ssl/ssl/server-revoked.key
src/test/ssl/ssl/server-single-alt-name.crt
src/test/ssl/ssl/server-single-alt-name.key
src/test/ssl/ssl/server-ss.crt
src/test/ssl/ssl/server-ss.key
src/test/ssl/ssl/server.crl
src/test/ssl/ssl/server_ca.crt
src/test/ssl/ssl/server_ca.key