mirror of https://github.com/ctz/rustls
a3f0d06c4b
Previously the test-ca `build-a-pki.sh` script would revoke each key type's client certificate to produce a `client.revoked.crl.pem` CRL. In this commit we update the script to do the same for each key type's intermediate cert (`inter.cert`) to produce a `inter.revoked.crl.pem`, as well as the server ee cert (`end.cert`) to produce a `end.revoked.crl.pem` file. This will be useful for testing the chain depth revocation controls, and the server verifier CRL support. |
||
---|---|---|
.. | ||
ecdsa | ||
eddsa | ||
rsa | ||
build-a-pki.sh | ||
crl-openssl.cnf | ||
openssl.cnf |