glite-security-test-utils.git
12 years agofix namespace definitions according to the eugridpma specificaiton master
Joni Hahkala [Tue, 6 Nov 2012 17:12:20 +0000 (17:12 +0000)]
fix namespace definitions according to the eugridpma specificaiton

12 years agoadd copies of CAs in case the openssl is new to make the openssl s_client work
Joni Hahkala [Fri, 25 May 2012 15:24:49 +0000 (15:24 +0000)]
add copies of CAs in case the openssl is new to make the openssl s_client work

12 years agoswitch to use new hash instead of old one
Joni Hahkala [Mon, 14 May 2012 23:47:10 +0000 (23:47 +0000)]
switch to use new hash instead of old one

12 years agotypo
Joni Hahkala [Mon, 14 May 2012 22:42:00 +0000 (22:42 +0000)]
typo

12 years agofall back to the hostname -f if the hostname -A returns empty string without error...
Joni Hahkala [Mon, 14 May 2012 22:37:09 +0000 (22:37 +0000)]
fall back to the hostname -f if the hostname -A returns empty string without error, like it seems to do in my sl6 installation.

13 years agoTake only the first hostname if there are aliases
Joni Hahkala [Wed, 15 Feb 2012 14:33:18 +0000 (14:33 +0000)]
Take only the first hostname if there are aliases

13 years agofixes from frantisek to make the hostname and ca name hashing work also on sl5 and 6
Joni Hahkala [Fri, 10 Feb 2012 13:42:31 +0000 (13:42 +0000)]
fixes from frantisek to make the hostname and ca name hashing work also on sl5 and 6

13 years agoget the full hostname, often it is just the short version.
Joni Hahkala [Thu, 9 Feb 2012 23:03:33 +0000 (23:03 +0000)]
get the full hostname, often it is just the short version.

13 years agodefault to adding the keyUsage extension to all certificates as required by rfc 5280.
Joni Hahkala [Mon, 30 Jan 2012 12:35:59 +0000 (12:35 +0000)]
default to adding the keyUsage extension to all certificates as required by rfc 5280.

13 years agoAdd test certs for sha* signatures, make sha1 default also for all user certs, make...
Joni Hahkala [Thu, 15 Dec 2011 22:48:24 +0000 (22:48 +0000)]
Add test certs for sha* signatures, make sha1 default also for all user certs, make md5 special case.

14 years agoChange hte long validity to 5000 days as 10000 causes problems on some openssl versions
Joni Hahkala [Mon, 21 Mar 2011 20:49:49 +0000 (20:49 +0000)]
Change hte long validity to 5000 days as 10000 causes problems on some openssl versions

14 years agotypo
Joni Hahkala [Fri, 17 Dec 2010 12:49:52 +0000 (12:49 +0000)]
typo

14 years agoremove extra code
Joni Hahkala [Thu, 16 Dec 2010 17:37:29 +0000 (17:37 +0000)]
remove extra code

14 years agoAdd test certs with hostname of the host generating the certs in altname and altname...
Joni Hahkala [Thu, 16 Dec 2010 17:28:44 +0000 (17:28 +0000)]
Add test certs with hostname of the host generating the certs in altname and altname with just emailaddress.

14 years agoregenrate to fix the slash CA DN, previously it had O RDN concatenated into OU value...
Joni Hahkala [Wed, 20 Oct 2010 16:57:08 +0000 (16:57 +0000)]
regenrate to fix the slash CA DN, previously it had O RDN concatenated into OU value, now they're separate

14 years agoAdded CRLs with CRL extension, it's the .crl_ext files
Joni Hahkala [Wed, 13 Oct 2010 12:25:41 +0000 (12:25 +0000)]
Added CRLs with CRL extension, it's the .crl_ext files

14 years agofix slash client, the openssl can't parse dn with slashes without escaping the slashe...
Joni Hahkala [Tue, 12 Oct 2010 16:44:42 +0000 (16:44 +0000)]
fix slash client, the openssl can't parse dn with slashes without escaping the slashes and getting them through evaluated sed string was complicated

14 years agoadded grid-security/certificates-slashwithoutnamespaces ca directory to test .signing...
Joni Hahkala [Mon, 11 Oct 2010 16:48:36 +0000 (16:48 +0000)]
added grid-security/certificates-slashwithoutnamespaces ca directory to test .signing_policy with slashes and dots without masking it with .namespaces file.

14 years agoregenerates to get a new namespace definitions for slash CA with certs with slashes...
Joni Hahkala [Mon, 11 Oct 2010 16:24:16 +0000 (16:24 +0000)]
regenerates to get a new namespace definitions for slash CA with certs with slashes and dots

14 years agofix properly the host_x certs
Joni Hahkala [Thu, 8 Jul 2010 15:50:42 +0000 (15:50 +0000)]
fix properly the host_x certs

14 years agofix host test certs, don't mess up the CN, use separate CN.
Joni Hahkala [Thu, 8 Jul 2010 14:56:08 +0000 (14:56 +0000)]
fix host test certs, don't mess up the CN, use separate CN.

14 years agoadd the host cert with emailaddress in DN generation
Joni Hahkala [Thu, 8 Jul 2010 13:07:14 +0000 (13:07 +0000)]
add the host cert with emailaddress in DN generation

14 years agoadd bad ca
Joni Hahkala [Fri, 25 Jun 2010 22:34:17 +0000 (22:34 +0000)]
add bad ca

14 years agoadd bad ca, remove old files
Joni Hahkala [Fri, 25 Jun 2010 22:18:42 +0000 (22:18 +0000)]
add bad ca, remove old files

14 years ago- new CA with slash in the DN
Joni Hahkala [Fri, 25 Jun 2010 22:15:43 +0000 (22:15 +0000)]
- new CA with slash in the DN
- pkcs8 key for <ca-name>_client, <ca-name>_client.priv.pkcs8
- cleaning up leftover files
- remove duplicate DNs, new openssl is more strict, name clashes failed

15 years agoadd revoked certs to all CAs, not just trusted, new grid-cecurity/certificates* dirs...
Joni Hahkala [Tue, 23 Mar 2010 00:10:20 +0000 (00:10 +0000)]
add revoked certs to all CAs, not just trusted, new grid-cecurity/certificates* dirs for testing hierarchical CA namespaces,
full chain proxies for hierarchical CAs

15 years agoadd test certs for hierarchical CAs with CA chain, namespaces for the parent CAs
Joni Hahkala [Fri, 19 Mar 2010 01:06:06 +0000 (01:06 +0000)]
add test certs for hierarchical CAs with CA chain, namespaces for the parent CAs
add parent CAs to the grid-security/certificates

15 years agoadd license
Joni Hahkala [Tue, 2 Mar 2010 13:54:48 +0000 (13:54 +0000)]
add license

15 years agomake key usage critical as it should be and add ca:false flag
Joni Hahkala [Mon, 18 Jan 2010 16:36:01 +0000 (16:36 +0000)]
make key usage critical as it should be and add ca:false flag

15 years agoa couple of additional rfc test certs
Joni Hahkala [Thu, 10 Dec 2009 14:48:13 +0000 (14:48 +0000)]
a couple of additional rfc test certs

15 years ago-less unnecessary cert for other than trusted ca
Joni Hahkala [Wed, 9 Dec 2009 17:39:06 +0000 (17:39 +0000)]
-less unnecessary cert for other than trusted ca
-rfc test certs
-all non-fake cas in grid-security/certificates directory
-regenrated cas to enable changes

15 years agocleanup
Joni Hahkala [Tue, 24 Nov 2009 12:31:49 +0000 (12:31 +0000)]
cleanup

15 years agosimplification, limited proxy, proxy with bad dn, combinations
Joni Hahkala [Mon, 23 Nov 2009 22:53:48 +0000 (22:53 +0000)]
simplification, limited proxy, proxy with bad dn, combinations

15 years agonew CAs, removed bad CA, namespaces added
Joni Hahkala [Wed, 18 Nov 2009 20:20:50 +0000 (20:20 +0000)]
new CAs, removed bad CA, namespaces added

15 years agoregenerated with new scripts
Joni Hahkala [Wed, 18 Nov 2009 20:11:13 +0000 (20:11 +0000)]
regenerated with new scripts

15 years agocombine conf files, cleanup scripts, namespaces, simplify, more test certs, bad certs...
Joni Hahkala [Wed, 18 Nov 2009 17:49:32 +0000 (17:49 +0000)]
combine conf files, cleanup scripts, namespaces, simplify, more test certs, bad certs for each CA, bad ca removed

15 years agoadd ca without key usage, root, subca, subsubca, move to single config file, use...
Joni Hahkala [Sun, 15 Nov 2009 15:17:37 +0000 (15:17 +0000)]
add ca without key usage, root, subca, subsubca, move to single config file, use v3 ca files, use key usage flags and keyids.

15 years agoadd CA extensions to make valid CA certs
Joni Hahkala [Wed, 11 Nov 2009 17:51:14 +0000 (17:51 +0000)]
add CA extensions to make valid CA certs

15 years agoadd key usage extensions
Joni Hahkala [Wed, 11 Nov 2009 17:50:46 +0000 (17:50 +0000)]
add key usage extensions

15 years agoremove accidentially checked in crls
Joni Hahkala [Wed, 11 Nov 2009 17:15:04 +0000 (17:15 +0000)]
remove accidentially checked in crls

15 years agoadd missing files
Joni Hahkala [Mon, 2 Nov 2009 13:32:43 +0000 (13:32 +0000)]
add missing files

15 years agoupdate certs, long lived server proxy cert
Joni Hahkala [Mon, 2 Nov 2009 13:30:20 +0000 (13:30 +0000)]
update certs, long lived server proxy cert

15 years agoforgot the server proxy lifetime extension
Joni Hahkala [Mon, 2 Nov 2009 12:59:23 +0000 (12:59 +0000)]
forgot the server proxy lifetime extension

15 years agonew try
Joni Hahkala [Wed, 14 Oct 2009 16:37:47 +0000 (16:37 +0000)]
new try

15 years agofix the commit error
Joni Hahkala [Wed, 14 Oct 2009 16:30:38 +0000 (16:30 +0000)]
fix the commit error

15 years agolonger proxies
Joni Hahkala [Tue, 13 Oct 2009 15:07:23 +0000 (15:07 +0000)]
longer proxies

15 years agoupdate proxies with longer lifetime
Joni Hahkala [Tue, 13 Oct 2009 15:04:38 +0000 (15:04 +0000)]
update proxies with longer lifetime

15 years agoadd altname cert generation
Joni Hahkala [Wed, 30 Sep 2009 15:05:47 +0000 (15:05 +0000)]
add altname cert generation

15 years agoforgot these new files from Kalle
Joni Hahkala [Mon, 29 Jun 2009 10:52:59 +0000 (10:52 +0000)]
forgot these new files from Kalle

15 years agoadd kalle's bad CA
Joni Hahkala [Thu, 25 Jun 2009 15:42:54 +0000 (15:42 +0000)]
add kalle's bad CA

17 years agoprint openssl command and version glite-security-test-utils_R_1_6_2_1
Joni Hahkala [Wed, 24 Oct 2007 14:43:43 +0000 (14:43 +0000)]
print openssl command and version

18 years agoupdate version glite-security-test-utils_R_1_6_1_1
Joni Hahkala [Fri, 9 Mar 2007 10:42:06 +0000 (10:42 +0000)]
update version

18 years agodisable voms certs by default
Joni Hahkala [Fri, 9 Mar 2007 10:41:20 +0000 (10:41 +0000)]
disable voms certs by default

18 years agogetting into shape
Akos Frohner [Thu, 21 Dec 2006 15:25:49 +0000 (15:25 +0000)]
getting into shape

18 years agoeticsifying
Akos Frohner [Thu, 21 Dec 2006 14:08:01 +0000 (14:08 +0000)]
eticsifying

18 years agopreparing for release glite-security-test-utils_R_1_6_0 glite-security-test-utils_R_1_6_0_0
Akos Frohner [Thu, 31 Aug 2006 13:25:13 +0000 (13:25 +0000)]
preparing for release

18 years agoGenerating an invalid VOMS certificate -- i.e. the issuer certificate is missing...
Akos Frohner [Tue, 29 Aug 2006 16:04:31 +0000 (16:04 +0000)]
Generating an invalid VOMS certificate -- i.e. the issuer certificate is missing from VOMSDIR

18 years agoadd also certs with userid in the DN
Joni Hahkala [Thu, 3 Aug 2006 11:42:58 +0000 (11:42 +0000)]
add also certs with userid in the DN

18 years agoadd certificates with serialnumber and emailaddress in the DN.
Joni Hahkala [Wed, 2 Aug 2006 17:09:21 +0000 (17:09 +0000)]
add certificates with serialnumber and emailaddress in the DN.

18 years agoAdding default_md=sha1 to be compatible with OpenSSL 0.9.8x and be able to generate...
Akos Frohner [Fri, 14 Jul 2006 11:48:03 +0000 (11:48 +0000)]
Adding default_md=sha1 to be compatible with OpenSSL 0.9.8x and be able to generate CRLs.

18 years agosmall fix to prevent clash between generated host certificate and the trusted_server...
Joni Hahkala [Wed, 28 Jun 2006 16:22:31 +0000 (16:22 +0000)]
small fix to prevent clash between generated host certificate and the trusted_server cert.

18 years agoVO name has to be added to make a fake VOMS cert look like valid
Akos Frohner [Fri, 9 Jun 2006 08:53:00 +0000 (08:53 +0000)]
VO name has to be added to make a fake VOMS cert look like valid

18 years agoworkaround #17362
Akos Frohner [Fri, 9 Jun 2006 07:40:42 +0000 (07:40 +0000)]
workaround #17362

18 years agoSetting LD_LIBRARY_PATH and PATH for voms-proxy-fake
Akos Frohner [Fri, 2 Jun 2006 21:23:24 +0000 (21:23 +0000)]
Setting LD_LIBRARY_PATH and PATH for voms-proxy-fake

18 years agoProper postinstall script.
Akos Frohner [Mon, 22 May 2006 13:38:41 +0000 (13:38 +0000)]
Proper postinstall script.

18 years agoEnabled daily RPM generation.
Akos Frohner [Mon, 22 May 2006 13:03:05 +0000 (13:03 +0000)]
Enabled daily RPM generation.

18 years agoAdded a script to re-generate the host specific server certificate.
Akos Frohner [Mon, 22 May 2006 13:02:12 +0000 (13:02 +0000)]
Added a script to re-generate the host specific server certificate.

18 years agoSimplified the generation of signing_policy file for the Globus clients.
Akos Frohner [Mon, 22 May 2006 11:41:51 +0000 (11:41 +0000)]
Simplified the generation of signing_policy file for the Globus clients.

18 years agoMore convenient defaults: 5 extra user certs and fake VOMS certs are created.
Akos Frohner [Mon, 22 May 2006 09:28:11 +0000 (09:28 +0000)]
More convenient defaults: 5 extra user certs and fake VOMS certs are created.

18 years agoWhitespace changes and variable name rationalization.
Akos Frohner [Mon, 22 May 2006 09:23:03 +0000 (09:23 +0000)]
Whitespace changes and variable name rationalization.

18 years agomake the VOMS certs valid for a week
Akos Frohner [Mon, 22 May 2006 08:33:31 +0000 (08:33 +0000)]
make the VOMS certs valid for a week

19 years agoPrevious changed missed to create a trusted proxy_proxy.proxy certificate -- fixed.
Akos Frohner [Tue, 9 May 2006 22:48:12 +0000 (22:48 +0000)]
Previous changed missed to create a trusted proxy_proxy.proxy certificate -- fixed.

19 years agovoms proxies for the extra user certs too
Akos Frohner [Fri, 5 May 2006 12:22:06 +0000 (12:22 +0000)]
voms proxies for the extra user certs too

19 years agoenv settings for testing. Use --onlyenv to print these variables, nothing else
Akos Frohner [Thu, 4 May 2006 16:16:48 +0000 (16:16 +0000)]
env settings for testing. Use --onlyenv to print these variables, nothing else

19 years agoVOMS proxies using voms-proxy-fake
Akos Frohner [Thu, 4 May 2006 15:55:23 +0000 (15:55 +0000)]
VOMS proxies using voms-proxy-fake

19 years agocreate_all calls create_some to generate some user certs
Akos Frohner [Thu, 4 May 2006 14:34:18 +0000 (14:34 +0000)]
create_all calls create_some to generate some user certs

19 years agogeneric update for better handling of temporary files
Akos Frohner [Thu, 4 May 2006 14:33:27 +0000 (14:33 +0000)]
generic update for better handling of temporary files

19 years agoreduce verbosity
Joni Hahkala [Tue, 11 Apr 2006 19:39:51 +0000 (19:39 +0000)]
reduce verbosity

19 years agofix dn error cert names and revoked certs validity times
Joni Hahkala [Tue, 4 Apr 2006 21:15:06 +0000 (21:15 +0000)]
fix dn error cert names and revoked certs validity times

19 years agoprepare for tagging GLITE_RELEASE_1_5_1 GLITE_RELEASE_3_0_0 glite-security-test-utils_R_1_5_0
Joni Hahkala [Tue, 31 Jan 2006 18:22:43 +0000 (18:22 +0000)]
prepare for tagging

19 years agomaybe this will remove the problems with test certs. clean before each build.
Joni Hahkala [Tue, 31 Jan 2006 18:08:47 +0000 (18:08 +0000)]
maybe this will remove the problems with test certs. clean before each build.

19 years agoprinting the command line parameters
Akos Frohner [Tue, 2 Aug 2005 08:52:02 +0000 (08:52 +0000)]
printing the command line parameters

19 years agogenerating extra user certificates for authorization tests
Akos Frohner [Tue, 2 Aug 2005 08:43:34 +0000 (08:43 +0000)]
generating extra user certificates for authorization tests

19 years agoAdded 4096bit cert to the set
Joni Hahkala [Wed, 27 Jul 2005 12:22:09 +0000 (12:22 +0000)]
Added 4096bit cert to the set

19 years agobuild.xml now cleans user/host certs
John White [Mon, 6 Jun 2005 15:24:41 +0000 (15:24 +0000)]
build.xml now cleans user/host certs

19 years agoMoved the version number to reflect a tag.
John White [Fri, 3 Jun 2005 13:53:02 +0000 (13:53 +0000)]
Moved the version number to reflect a tag.

19 years agoAdded the user certificate to the proxy-proxy chain.
John White [Fri, 3 Jun 2005 12:48:59 +0000 (12:48 +0000)]
Added the user certificate to the proxy-proxy chain.

19 years agoinserted module.build.file
Marian Zurek [Thu, 26 May 2005 15:18:39 +0000 (15:18 +0000)]
inserted module.build.file

20 years ago"corrections"
Marian Zurek [Tue, 12 Apr 2005 20:25:30 +0000 (20:25 +0000)]
"corrections"

20 years agobackported fix from RC1
Akos Frohner [Thu, 24 Mar 2005 11:03:03 +0000 (11:03 +0000)]
backported fix from RC1

20 years agoUpdated documentation to reflect new behaviour of test certificate script.
John White [Thu, 3 Mar 2005 10:26:22 +0000 (10:26 +0000)]
Updated documentation to reflect new behaviour of test certificate script.

20 years agoAdded the correct permissions to the user key generated when the script is called...
John White [Thu, 3 Mar 2005 09:57:15 +0000 (09:57 +0000)]
Added the correct permissions to the user key generated when the script is called without
the --all option.

20 years agoChange the behaviour of the CA cert and signing policy file locations so as to exclud...
John White [Wed, 2 Mar 2005 16:24:12 +0000 (16:24 +0000)]
Change the behaviour of the CA cert and signing policy file locations so as to exclude /etc/grid-security/certificates as a default location.

20 years agoChanges made for bug number 6743. CA certs are now copied to /etc/grid-security/certi...
John White [Wed, 2 Mar 2005 14:36:49 +0000 (14:36 +0000)]
Changes made for bug number 6743. CA certs are now copied to /etc/grid-security/certificates and also the signing policy files are now generated.

20 years agoI have fixed the proxy serial number problem. The test proxies now have
John White [Fri, 28 Jan 2005 14:35:57 +0000 (14:35 +0000)]
I have fixed the proxy serial number problem. The test proxies now have
serial numbers different from one another.

20 years agoadding the fixed to HEAD too.
Joni Hahkala [Fri, 21 Jan 2005 12:47:13 +0000 (12:47 +0000)]
adding the fixed to HEAD too.

20 years agobumping the version in the head version
Joni Hahkala [Wed, 19 Jan 2005 16:05:07 +0000 (16:05 +0000)]
bumping the version in the head version

20 years agomoved to version 1.0.0
Joni Hahkala [Fri, 14 Jan 2005 11:20:39 +0000 (11:20 +0000)]
moved to version 1.0.0

20 years agoUpdated all configuration files for test certs and proxies.
John White [Fri, 14 Jan 2005 11:02:47 +0000 (11:02 +0000)]
Updated all configuration files for test certs and proxies.

20 years agoAdded ca_proxy_conf.cnf files to the test/* directories.
John White [Fri, 14 Jan 2005 10:38:45 +0000 (10:38 +0000)]
Added ca_proxy_conf.cnf files to the test/* directories.