• Home
  • Line#
  • Scopes#
  • Navigate#
  • Raw
  • Download
1The test credentials (CONFIRMEDTESTKEY) have been generated with the following
2commands:
3
4Bad credentials (badclient.* / badserver.*):
5============================================
6
7These are self-signed certificates:
8
9$ openssl req -x509 -newkey rsa:1024 -keyout badserver.key -out badserver.pem \
10  -days 3650 -nodes
11
12When prompted for certificate information, everything is default except the
13common name which is set to badserver.test.google.com.
14
15
16Valid test credentials:
17=======================
18
19The ca is self-signed:
20----------------------
21
22$ openssl req -x509 -new -newkey rsa:1024 -nodes -out ca.pem -config ca-openssl.cnf -days 3650 -extensions v3_req
23When prompted for certificate information, everything is default.
24
25client is issued by CA:
26-----------------------
27
28$ openssl genrsa -out client.key.rsa 1024
29$ openssl pkcs8 -topk8 -in client.key.rsa -out client.key -nocrypt
30$ rm client.key.rsa
31$ openssl req -new -key client.key -out client.csr
32
33When prompted for certificate information, everything is default except the
34common name which is set to testclient.
35
36$ openssl ca -in client.csr -out client.pem
37
38server0 is issued by CA:
39------------------------
40
41$ openssl genrsa -out server0.key.rsa 1024
42$ openssl pkcs8 -topk8 -in server0.key.rsa -out server0.key -nocrypt
43$ rm server0.key.rsa
44$ openssl req -new -key server0.key -out server0.csr
45
46When prompted for certificate information, everything is default except the
47common name which is set to *.test.google.com.au.
48
49$ openssl ca -in server0.csr -out server0.pem
50
51server1 is issued by CA with a special config for subject alternative names:
52----------------------------------------------------------------------------
53
54$ openssl genrsa -out server1.key.rsa 1024
55$ openssl pkcs8 -topk8 -in server1.key.rsa -out server1.key -nocrypt
56$ rm server1.key.rsa
57$ openssl req -new -key server1.key -out server1.csr -config server1-openssl.cnf
58
59When prompted for certificate information, everything is default except the
60common name which is set to *.test.google.com.
61
62$ openssl ca -in server1.csr -out server1.pem
63