diff options
author | agl@chromium.org <agl@chromium.org@0039d316-1c4b-4281-b951-d872f2087c98> | 2013-12-16 18:41:01 +0000 |
---|---|---|
committer | agl@chromium.org <agl@chromium.org@0039d316-1c4b-4281-b951-d872f2087c98> | 2013-12-16 18:41:01 +0000 |
commit | f5a393db1b2c9e947682a8bbbcb42e4de1abec0a (patch) | |
tree | 5afd449626f921e7e8385ebd6af8123344323ea3 /net/data | |
parent | 6847bc4c6ab1870bcb272ebe5fe6d024a79bebff (diff) | |
download | chromium_src-f5a393db1b2c9e947682a8bbbcb42e4de1abec0a.zip chromium_src-f5a393db1b2c9e947682a8bbbcb42e4de1abec0a.tar.gz chromium_src-f5a393db1b2c9e947682a8bbbcb42e4de1abec0a.tar.bz2 |
net: add name constraints for ANSSI root.
BUG=326787
R=felt@chromium.org, palmer@chromium.org, rsleevi@chromium.org
Review URL: https://codereview.chromium.org/109483005
git-svn-id: svn://svn.chromium.org/chrome/trunk/src@240942 0039d316-1c4b-4281-b951-d872f2087c98
Diffstat (limited to 'net/data')
-rw-r--r-- | net/data/ssl/certificates/name_constraint_bad.crt | 109 | ||||
-rw-r--r-- | net/data/ssl/certificates/name_constraint_ok.crt | 109 |
2 files changed, 218 insertions, 0 deletions
diff --git a/net/data/ssl/certificates/name_constraint_bad.crt b/net/data/ssl/certificates/name_constraint_bad.crt new file mode 100644 index 0000000..d73312b --- /dev/null +++ b/net/data/ssl/certificates/name_constraint_bad.crt @@ -0,0 +1,109 @@ +-----BEGIN RSA PRIVATE KEY----- +MIIEowIBAAKCAQEAzNtr+fM1JtFhOTaJsZVJr/UYpLxylg28jY/V3SLItFrnYQOs +XrwjoWI3osQjBe34PrhI7XmHIEACprY5q/bKTOz+PgBiX2tp9oieXtLi9O3qDrlC +Z0HentNomdR0yojK5nPAloSCgdgX2sA+c6oyzKAmReKlReXEgh0hI43YVILKLLnO +I4O1jowGVg/QATR12OQGYswUJuApW8KQeT7bI9ZCewacZD1UiiAlQ57w2rZ41fJh +4W4nKKjkuH43wSNW7BH7VWECt1RrxkeSdFh6GPYwMrkT+KDs8aqzMXdlRN1CXCpv +4CbrLM2j5B4dLkhuU9KZAiOXBSew9TJrZ9ga9wIDAQABAoIBAEw8V/mDpcMVZm4J +OsLIgMynlI0xyB7Ja+LupTMPT8u2jKbQ3CPBNi1HxNag0TvSrHCC2jjt4fiBebsa +02mIhQ6Nn6vpLrK94YgqnW1CY82sgE8MaIbOv48xs5qTswbwUznh18jr9Tlm9rGk +m1kl/JOkAbo+Ny1E7ZVSS9PUZK5F94oYbq8H/IT9Vh5doyMG66fwhGfZaXSv7+tF +R8dEkfkyfVBhwcR8H738MkcGVjPRkGGUgaUTHktr3l642YXYYSRbZ1lNIpXM2oHH +qCRqWy/tg6p2AIMSqRXy+jEn1YSlGI+hndMXDvPJoH8rqbuTIxzNKLneZiSDNVqq +K9+XalkCgYEA6FhwTyc/4QEyFP2HWArpkcxvws6OVIrJG76K+j/c+G1pUfmhIICY +Rx/xEAXA7iT7B4S0DWqYMG2eYos6bd2Qj1nK8x/ishM2awlyN4mYjn1fr/AI7fbD +omtFlUDwQLD0KB630I+KyNLBoHgV70559MHk93uYCq/2cRl+KvDuLL0CgYEA4baP +qu32Ln9JmThVD9GotlEUJMHkfkSLeXFe+tPjQLuFoeijvMFai60sZ1J/OXf7yMiR +u6j4QIlepqK1TlvCfIjQeg620az4v1kap3JL9XNWOXjdOzsBeJPPE/dp0akeG5uB +XXvTSwRWLcxzkfzaEPuy8HWPdphrQ+PleZQiE8MCgYAjQ8EQEnn8kazjSLOxJj7b +NTdFTwqFRGdPwbTgVK8aOakBmyzcfQgfy3ZQIz9sJcrAEmEtpB8jQpAGjvE4Waem +Sk+mZRGIS6g3yMBAM68m+Vp7nqgMTibVUQjHpYqRlwoHyNnHWvIKlwpya6eQoc2a +248ADQ8/mAOEmQTwSY8s1QKBgQC27lnz45aBSsJgfspZ3sdIs9+KhuZj+7O6gkrD +KRVmclS0yzJhGagDyh9RwgfAkOCscvnByQkibPMcRISC9FVkzxF/ywsaVoDnvBSh +Hz42uPpp6+4JQiJIEitjeEL4HIN9RoQLOv8dLm+WALyt1er6lrQItI7IRHGy/TIP +XiJcNwKBgDc4CCqWTS1D3mB8L9Dwom3lrFQRitUbeNmI/787x8Mh2x5kYJZWLXj5 +r8ZCugcUO2N7hW4sZSBXH7N8Udbyud1fLk2pVJmJ4QCk4wvNpITM3ZMSJp7LAKhs +cmxcrrVKAk47W9EOnTb50THDlsWfO/vO7XhE82N27cnEPPCi+umS +-----END RSA PRIVATE KEY----- + +Certificate: + Data: + Version: 3 (0x2) + Serial Number: 24598234 (0x17756da) + Signature Algorithm: sha1WithRSAEncryption + Issuer: CN=Test Root CA + Validity + Not Before: Jan 1 10:00:00 2013 GMT + Not After : Dec 31 10:00:00 2023 GMT + Subject: O=Acme Co, CN=Leaf certificate + Subject Public Key Info: + Public Key Algorithm: rsaEncryption + Public-Key: (2048 bit) + Modulus: + 00:cc:db:6b:f9:f3:35:26:d1:61:39:36:89:b1:95: + 49:af:f5:18:a4:bc:72:96:0d:bc:8d:8f:d5:dd:22: + c8:b4:5a:e7:61:03:ac:5e:bc:23:a1:62:37:a2:c4: + 23:05:ed:f8:3e:b8:48:ed:79:87:20:40:02:a6:b6: + 39:ab:f6:ca:4c:ec:fe:3e:00:62:5f:6b:69:f6:88: + 9e:5e:d2:e2:f4:ed:ea:0e:b9:42:67:41:de:9e:d3: + 68:99:d4:74:ca:88:ca:e6:73:c0:96:84:82:81:d8: + 17:da:c0:3e:73:aa:32:cc:a0:26:45:e2:a5:45:e5: + c4:82:1d:21:23:8d:d8:54:82:ca:2c:b9:ce:23:83: + b5:8e:8c:06:56:0f:d0:01:34:75:d8:e4:06:62:cc: + 14:26:e0:29:5b:c2:90:79:3e:db:23:d6:42:7b:06: + 9c:64:3d:54:8a:20:25:43:9e:f0:da:b6:78:d5:f2: + 61:e1:6e:27:28:a8:e4:b8:7e:37:c1:23:56:ec:11: + fb:55:61:02:b7:54:6b:c6:47:92:74:58:7a:18:f6: + 30:32:b9:13:f8:a0:ec:f1:aa:b3:31:77:65:44:dd: + 42:5c:2a:6f:e0:26:eb:2c:cd:a3:e4:1e:1d:2e:48: + 6e:53:d2:99:02:23:97:05:27:b0:f5:32:6b:67:d8: + 1a:f7 + Exponent: 65537 (0x10001) + X509v3 extensions: + X509v3 Key Usage: critical + Digital Signature, Key Encipherment + X509v3 Extended Key Usage: + TLS Web Server Authentication + X509v3 Basic Constraints: critical + CA:FALSE + X509v3 Authority Key Identifier: + keyid:2B:88:93:E1:D2:54:50:F4:B8:A4:20:BD:B1:79:E6:0B:AA:EB:EC:1A + + X509v3 Subject Alternative Name: + DNS:test.ExAmPlE.CoM, DNS:test.ExAmPlE.OrG + Signature Algorithm: sha1WithRSAEncryption + 08:2e:7b:ca:45:c2:2d:d8:4b:52:ca:af:b0:86:60:58:71:6f: + e8:40:2d:fd:e6:44:10:b5:75:d0:81:19:47:05:34:97:0c:6b: + 4e:c2:67:7d:7f:72:fe:c7:28:12:a3:b7:a9:9f:11:ef:66:f7: + 8f:00:0b:e2:8f:18:9b:1e:06:ee:2a:e0:fa:bd:f7:79:3a:63: + 7f:0e:94:b7:56:02:62:a6:65:17:e1:5e:10:13:3a:56:db:b3: + 50:54:44:60:d3:36:9e:f3:e9:74:89:35:4a:d6:2b:a5:ba:03: + 82:ba:53:9a:21:9e:78:eb:4b:fb:dc:f1:1e:eb:8c:29:57:ab: + da:a6:0b:b6:a8:b8:07:d6:92:f3:40:fd:b8:52:8b:eb:53:5e: + 4a:d2:9e:cc:aa:85:52:a4:09:02:05:ce:3f:65:82:4e:ec:a9: + fa:44:87:bf:35:3c:c2:b8:ba:7d:92:c1:41:45:1d:de:d9:a0: + fd:b8:99:6c:c4:75:a6:3e:9d:c9:d0:a4:3b:47:96:97:f8:78: + f3:cb:b5:93:19:79:8c:38:70:1c:6f:27:f1:13:d8:a6:4e:6a: + 85:b4:df:2f:23:1d:47:5a:76:8c:2a:ea:ac:21:91:16:4c:f3: + 74:86:68:57:f1:93:7b:3d:3d:f3:8b:f4:5b:97:d4:13:4a:80: + 35:65:78:c7 +-----BEGIN CERTIFICATE----- +MIIDRTCCAi+gAwIBAgIEAXdW2jALBgkqhkiG9w0BAQUwFzEVMBMGA1UEAwwMVGVz +dCBSb290IENBMB4XDTEzMDEwMTEwMDAwMFoXDTIzMTIzMTEwMDAwMFowLTEQMA4G +A1UEChMHQWNtZSBDbzEZMBcGA1UEAxMQTGVhZiBjZXJ0aWZpY2F0ZTCCASIwDQYJ +KoZIhvcNAQEBBQADggEPADCCAQoCggEBAMzba/nzNSbRYTk2ibGVSa/1GKS8cpYN +vI2P1d0iyLRa52EDrF68I6FiN6LEIwXt+D64SO15hyBAAqa2Oav2ykzs/j4AYl9r +afaInl7S4vTt6g65QmdB3p7TaJnUdMqIyuZzwJaEgoHYF9rAPnOqMsygJkXipUXl +xIIdISON2FSCyiy5ziODtY6MBlYP0AE0ddjkBmLMFCbgKVvCkHk+2yPWQnsGnGQ9 +VIogJUOe8Nq2eNXyYeFuJyio5Lh+N8EjVuwR+1VhArdUa8ZHknRYehj2MDK5E/ig +7PGqszF3ZUTdQlwqb+Am6yzNo+QeHS5IblPSmQIjlwUnsPUya2fYGvcCAwEAAaOB +hjCBgzAOBgNVHQ8BAf8EBAMCAKAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDAYDVR0T +AQH/BAIwADAfBgNVHSMEGDAWgBQriJPh0lRQ9LikIL2xeeYLquvsGjAtBgNVHREE +JjAkghB0ZXN0LkV4QW1QbEUuQ29NghB0ZXN0LkV4QW1QbEUuT3JHMAsGCSqGSIb3 +DQEBBQOCAQEACC57ykXCLdhLUsqvsIZgWHFv6EAt/eZEELV10IEZRwU0lwxrTsJn +fX9y/scoEqO3qZ8R72b3jwAL4o8Ymx4G7irg+r33eTpjfw6Ut1YCYqZlF+FeEBM6 +VtuzUFREYNM2nvPpdIk1StYrpboDgrpTmiGeeOtL+9zxHuuMKVer2qYLtqi4B9aS +80D9uFKL61NeStKezKqFUqQJAgXOP2WCTuyp+kSHvzU8wri6fZLBQUUd3tmg/biZ +bMR1pj6dydCkO0eWl/h488u1kxl5jDhwHG8n8RPYpk5qhbTfLyMdR1p2jCrqrCGR +FkzzdIZoV/GTez0984v0W5fUE0qANWV4xw== +-----END CERTIFICATE----- diff --git a/net/data/ssl/certificates/name_constraint_ok.crt b/net/data/ssl/certificates/name_constraint_ok.crt new file mode 100644 index 0000000..d429323 --- /dev/null +++ b/net/data/ssl/certificates/name_constraint_ok.crt @@ -0,0 +1,109 @@ +-----BEGIN RSA PRIVATE KEY----- +MIIEowIBAAKCAQEAzNtr+fM1JtFhOTaJsZVJr/UYpLxylg28jY/V3SLItFrnYQOs +XrwjoWI3osQjBe34PrhI7XmHIEACprY5q/bKTOz+PgBiX2tp9oieXtLi9O3qDrlC +Z0HentNomdR0yojK5nPAloSCgdgX2sA+c6oyzKAmReKlReXEgh0hI43YVILKLLnO +I4O1jowGVg/QATR12OQGYswUJuApW8KQeT7bI9ZCewacZD1UiiAlQ57w2rZ41fJh +4W4nKKjkuH43wSNW7BH7VWECt1RrxkeSdFh6GPYwMrkT+KDs8aqzMXdlRN1CXCpv +4CbrLM2j5B4dLkhuU9KZAiOXBSew9TJrZ9ga9wIDAQABAoIBAEw8V/mDpcMVZm4J +OsLIgMynlI0xyB7Ja+LupTMPT8u2jKbQ3CPBNi1HxNag0TvSrHCC2jjt4fiBebsa +02mIhQ6Nn6vpLrK94YgqnW1CY82sgE8MaIbOv48xs5qTswbwUznh18jr9Tlm9rGk +m1kl/JOkAbo+Ny1E7ZVSS9PUZK5F94oYbq8H/IT9Vh5doyMG66fwhGfZaXSv7+tF +R8dEkfkyfVBhwcR8H738MkcGVjPRkGGUgaUTHktr3l642YXYYSRbZ1lNIpXM2oHH +qCRqWy/tg6p2AIMSqRXy+jEn1YSlGI+hndMXDvPJoH8rqbuTIxzNKLneZiSDNVqq +K9+XalkCgYEA6FhwTyc/4QEyFP2HWArpkcxvws6OVIrJG76K+j/c+G1pUfmhIICY +Rx/xEAXA7iT7B4S0DWqYMG2eYos6bd2Qj1nK8x/ishM2awlyN4mYjn1fr/AI7fbD +omtFlUDwQLD0KB630I+KyNLBoHgV70559MHk93uYCq/2cRl+KvDuLL0CgYEA4baP +qu32Ln9JmThVD9GotlEUJMHkfkSLeXFe+tPjQLuFoeijvMFai60sZ1J/OXf7yMiR +u6j4QIlepqK1TlvCfIjQeg620az4v1kap3JL9XNWOXjdOzsBeJPPE/dp0akeG5uB +XXvTSwRWLcxzkfzaEPuy8HWPdphrQ+PleZQiE8MCgYAjQ8EQEnn8kazjSLOxJj7b +NTdFTwqFRGdPwbTgVK8aOakBmyzcfQgfy3ZQIz9sJcrAEmEtpB8jQpAGjvE4Waem +Sk+mZRGIS6g3yMBAM68m+Vp7nqgMTibVUQjHpYqRlwoHyNnHWvIKlwpya6eQoc2a +248ADQ8/mAOEmQTwSY8s1QKBgQC27lnz45aBSsJgfspZ3sdIs9+KhuZj+7O6gkrD +KRVmclS0yzJhGagDyh9RwgfAkOCscvnByQkibPMcRISC9FVkzxF/ywsaVoDnvBSh +Hz42uPpp6+4JQiJIEitjeEL4HIN9RoQLOv8dLm+WALyt1er6lrQItI7IRHGy/TIP +XiJcNwKBgDc4CCqWTS1D3mB8L9Dwom3lrFQRitUbeNmI/787x8Mh2x5kYJZWLXj5 +r8ZCugcUO2N7hW4sZSBXH7N8Udbyud1fLk2pVJmJ4QCk4wvNpITM3ZMSJp7LAKhs +cmxcrrVKAk47W9EOnTb50THDlsWfO/vO7XhE82N27cnEPPCi+umS +-----END RSA PRIVATE KEY----- + +Certificate: + Data: + Version: 3 (0x2) + Serial Number: 54358835 (0x33d7333) + Signature Algorithm: sha512WithRSAEncryption + Issuer: CN=Test Root CA + Validity + Not Before: Jan 1 10:00:00 2013 GMT + Not After : Dec 31 10:00:00 2023 GMT + Subject: O=Acme Co, CN=Leaf certificate + Subject Public Key Info: + Public Key Algorithm: rsaEncryption + Public-Key: (2048 bit) + Modulus: + 00:cc:db:6b:f9:f3:35:26:d1:61:39:36:89:b1:95: + 49:af:f5:18:a4:bc:72:96:0d:bc:8d:8f:d5:dd:22: + c8:b4:5a:e7:61:03:ac:5e:bc:23:a1:62:37:a2:c4: + 23:05:ed:f8:3e:b8:48:ed:79:87:20:40:02:a6:b6: + 39:ab:f6:ca:4c:ec:fe:3e:00:62:5f:6b:69:f6:88: + 9e:5e:d2:e2:f4:ed:ea:0e:b9:42:67:41:de:9e:d3: + 68:99:d4:74:ca:88:ca:e6:73:c0:96:84:82:81:d8: + 17:da:c0:3e:73:aa:32:cc:a0:26:45:e2:a5:45:e5: + c4:82:1d:21:23:8d:d8:54:82:ca:2c:b9:ce:23:83: + b5:8e:8c:06:56:0f:d0:01:34:75:d8:e4:06:62:cc: + 14:26:e0:29:5b:c2:90:79:3e:db:23:d6:42:7b:06: + 9c:64:3d:54:8a:20:25:43:9e:f0:da:b6:78:d5:f2: + 61:e1:6e:27:28:a8:e4:b8:7e:37:c1:23:56:ec:11: + fb:55:61:02:b7:54:6b:c6:47:92:74:58:7a:18:f6: + 30:32:b9:13:f8:a0:ec:f1:aa:b3:31:77:65:44:dd: + 42:5c:2a:6f:e0:26:eb:2c:cd:a3:e4:1e:1d:2e:48: + 6e:53:d2:99:02:23:97:05:27:b0:f5:32:6b:67:d8: + 1a:f7 + Exponent: 65537 (0x10001) + X509v3 extensions: + X509v3 Key Usage: critical + Digital Signature, Key Encipherment + X509v3 Extended Key Usage: + TLS Web Server Authentication + X509v3 Basic Constraints: critical + CA:FALSE + X509v3 Authority Key Identifier: + keyid:2B:88:93:E1:D2:54:50:F4:B8:A4:20:BD:B1:79:E6:0B:AA:EB:EC:1A + + X509v3 Subject Alternative Name: + DNS:test.ExAmPlE.CoM, DNS:example.notarealtld + Signature Algorithm: sha512WithRSAEncryption + 4f:71:b7:f3:77:b7:66:31:6b:7d:9b:8d:32:fa:18:02:3c:1f: + 54:2e:7d:3c:8d:f9:e7:65:f3:18:64:00:3a:6f:c7:ef:3b:69: + 0d:d6:3d:d6:dd:79:1d:e7:ca:fb:8c:36:32:98:38:7b:3c:de: + 52:b9:0e:a5:dd:c5:12:eb:aa:e8:e9:1b:64:df:25:a7:72:3b: + 87:4d:bd:69:a2:56:dc:1e:38:29:62:0a:18:c2:43:19:df:7e: + 1d:31:db:b6:5c:cb:aa:70:13:58:c0:ca:8a:66:2a:17:49:d7: + 2b:45:5b:bb:f3:2e:4e:53:85:80:7d:47:69:4f:cf:f4:ef:6b: + 39:8c:1d:5c:70:d4:5d:29:6b:79:14:2d:41:4d:da:49:8e:c1: + b0:65:3e:c8:0b:97:72:b4:21:10:f2:bb:a1:55:cb:43:57:6d: + c8:fe:6e:3f:19:57:52:f0:47:e6:04:89:71:28:31:7a:b5:a3: + b1:10:7d:ef:c4:a5:f2:80:c0:0a:71:e6:0d:bd:9c:59:a1:32: + 94:83:65:2f:f7:e1:47:19:e4:cc:c8:66:2a:fa:f4:ad:c3:c9: + 4d:28:d8:37:91:60:1b:b6:24:16:e5:9d:16:36:ca:fd:5e:4e: + 0f:4e:18:10:12:34:0a:a4:66:84:ee:6e:df:84:01:5a:ac:34: + 0e:68:df:c6 +-----BEGIN CERTIFICATE----- +MIIDSDCCAjKgAwIBAgIEAz1zMzALBgkqhkiG9w0BAQ0wFzEVMBMGA1UEAwwMVGVz +dCBSb290IENBMB4XDTEzMDEwMTEwMDAwMFoXDTIzMTIzMTEwMDAwMFowLTEQMA4G +A1UEChMHQWNtZSBDbzEZMBcGA1UEAxMQTGVhZiBjZXJ0aWZpY2F0ZTCCASIwDQYJ +KoZIhvcNAQEBBQADggEPADCCAQoCggEBAMzba/nzNSbRYTk2ibGVSa/1GKS8cpYN +vI2P1d0iyLRa52EDrF68I6FiN6LEIwXt+D64SO15hyBAAqa2Oav2ykzs/j4AYl9r +afaInl7S4vTt6g65QmdB3p7TaJnUdMqIyuZzwJaEgoHYF9rAPnOqMsygJkXipUXl +xIIdISON2FSCyiy5ziODtY6MBlYP0AE0ddjkBmLMFCbgKVvCkHk+2yPWQnsGnGQ9 +VIogJUOe8Nq2eNXyYeFuJyio5Lh+N8EjVuwR+1VhArdUa8ZHknRYehj2MDK5E/ig +7PGqszF3ZUTdQlwqb+Am6yzNo+QeHS5IblPSmQIjlwUnsPUya2fYGvcCAwEAAaOB +iTCBhjAOBgNVHQ8BAf8EBAMCAKAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwDAYDVR0T +AQH/BAIwADAfBgNVHSMEGDAWgBQriJPh0lRQ9LikIL2xeeYLquvsGjAwBgNVHREE +KTAnghB0ZXN0LkV4QW1QbEUuQ29NghNleGFtcGxlLm5vdGFyZWFsdGxkMAsGCSqG +SIb3DQEBDQOCAQEAT3G383e3ZjFrfZuNMvoYAjwfVC59PI3552XzGGQAOm/H7ztp +DdY91t15HefK+4w2Mpg4ezzeUrkOpd3FEuuq6OkbZN8lp3I7h029aaJW3B44KWIK +GMJDGd9+HTHbtlzLqnATWMDKimYqF0nXK0Vbu/MuTlOFgH1HaU/P9O9rOYwdXHDU +XSlreRQtQU3aSY7BsGU+yAuXcrQhEPK7oVXLQ1dtyP5uPxlXUvBH5gSJcSgxerWj +sRB978Sl8oDACnHmDb2cWaEylINlL/fhRxnkzMhmKvr0rcPJTSjYN5FgG7YkFuWd +FjbK/V5OD04YEBI0CqRmhO5u34QBWqw0Dmjfxg== +-----END CERTIFICATE----- |