CKM: Get rid of early expiring certificates 46/278746/3
authorKrzysztof Jackiewicz <k.jackiewicz@samsung.com>
Mon, 25 Jul 2022 20:40:35 +0000 (22:40 +0200)
committerKrzysztof Jackiewicz <k.jackiewicz@samsung.com>
Tue, 2 Aug 2022 08:56:41 +0000 (10:56 +0200)
commitb6ffddb6bd81caa153e83b654dc9da1f480ec0a1
tree8d8f6f23e98ec5fd6157aa0cda5342cd2c0990d8
parent0d8101c69b069dd83876e7a6ab586198745212ab
CKM: Get rid of early expiring certificates

* Use OCSP chain with longer validity (Jan 28 2028)
* Use last CA certificate before root CA for OCSP tests (CA has longer
  validity than EE certificate)
* Remove "third party" chain to avoid expiration issues
* Replace above chain with "OCSP" or "test" chain where possible
* Simplify or remove tests that do not make sense with current chains

Change-Id: I22eba70ae8b73607cc4c8de1f18f014104fd12ea
src/ckm/privileged/main.cpp
src/ckm/test-certs.cpp
src/ckm/test-certs.h
src/ckm/unprivileged/async-api.cpp
src/ckm/unprivileged/capi-certificate-chains.cpp
src/ckm/unprivileged/capi-testcases.cpp
src/ckm/unprivileged/main.cpp