CKM: Adjust T1810_verify_get_certificate_chain to openssl1.1 90/207890/2
authorKrzysztof Jackiewicz <k.jackiewicz@samsung.com>
Thu, 13 Jun 2019 14:45:15 +0000 (16:45 +0200)
committerKrzysztof Jackiewicz <k.jackiewicz@samsung.com>
Fri, 14 Jun 2019 08:03:14 +0000 (10:03 +0200)
commit5ef2fae5da181f03e5e24c3622186e2e71c9fb17
tree337588c7d7e9e048b80b62fc1edfea4cd299abe1
parent4d5af2f4489ec50b82b08bce5abdd530c68302ba
CKM: Adjust T1810_verify_get_certificate_chain to openssl1.1

Since openssl1.1 all certificates in the chain (including trusted
ones) must include a 'basicConstrains' extension with 'CA' field set
to 'true'. Without that the verification will fail with
X509_V_ERR_INVALID_CA.

This commit recreates the chain of certificates used in T1810 with the
required extension included and updates related tests.

Change-Id: I6d2e9348a2ae6618103749d83e46a433608e65c3
13 files changed:
src/ckm/keys/pkcs12.tgz [deleted file]
src/ckm/keys/pkcs12/HOWTO.txt [new file with mode: 0644]
src/ckm/keys/pkcs12/ca-int.crt [new file with mode: 0644]
src/ckm/keys/pkcs12/ca-int.csr [new file with mode: 0644]
src/ckm/keys/pkcs12/ca-int.key [new file with mode: 0644]
src/ckm/keys/pkcs12/ca.crt [new file with mode: 0644]
src/ckm/keys/pkcs12/ca.key [new file with mode: 0644]
src/ckm/keys/pkcs12/chain.pem [new file with mode: 0644]
src/ckm/keys/pkcs12/server.crt [new file with mode: 0644]
src/ckm/keys/pkcs12/server.csr [new file with mode: 0644]
src/ckm/keys/pkcs12/server.key [new file with mode: 0644]
src/ckm/resource/pkcs.p12
src/ckm/unprivileged/main.cpp