Joni Hahkala [Tue, 6 Nov 2012 17:12:20 +0000 (17:12 +0000)]
fix namespace definitions according to the eugridpma specificaiton
Joni Hahkala [Fri, 25 May 2012 15:24:49 +0000 (15:24 +0000)]
add copies of CAs in case the openssl is new to make the openssl s_client work
Joni Hahkala [Mon, 14 May 2012 23:47:10 +0000 (23:47 +0000)]
switch to use new hash instead of old one
Joni Hahkala [Mon, 14 May 2012 22:42:00 +0000 (22:42 +0000)]
typo
Joni Hahkala [Mon, 14 May 2012 22:37:09 +0000 (22:37 +0000)]
fall back to the hostname -f if the hostname -A returns empty string without error, like it seems to do in my sl6 installation.
Joni Hahkala [Wed, 15 Feb 2012 14:33:18 +0000 (14:33 +0000)]
Take only the first hostname if there are aliases
Joni Hahkala [Fri, 10 Feb 2012 13:42:31 +0000 (13:42 +0000)]
fixes from frantisek to make the hostname and ca name hashing work also on sl5 and 6
Joni Hahkala [Thu, 9 Feb 2012 23:03:33 +0000 (23:03 +0000)]
get the full hostname, often it is just the short version.
Joni Hahkala [Mon, 30 Jan 2012 12:35:59 +0000 (12:35 +0000)]
default to adding the keyUsage extension to all certificates as required by rfc 5280.
Joni Hahkala [Thu, 15 Dec 2011 22:48:24 +0000 (22:48 +0000)]
Add test certs for sha* signatures, make sha1 default also for all user certs, make md5 special case.
Joni Hahkala [Mon, 21 Mar 2011 20:49:49 +0000 (20:49 +0000)]
Change hte long validity to 5000 days as 10000 causes problems on some openssl versions
Joni Hahkala [Fri, 17 Dec 2010 12:49:52 +0000 (12:49 +0000)]
typo
Joni Hahkala [Thu, 16 Dec 2010 17:37:29 +0000 (17:37 +0000)]
remove extra code
Joni Hahkala [Thu, 16 Dec 2010 17:28:44 +0000 (17:28 +0000)]
Add test certs with hostname of the host generating the certs in altname and altname with just emailaddress.
Joni Hahkala [Wed, 20 Oct 2010 16:57:08 +0000 (16:57 +0000)]
regenrate to fix the slash CA DN, previously it had O RDN concatenated into OU value, now they're separate
Joni Hahkala [Wed, 13 Oct 2010 12:25:41 +0000 (12:25 +0000)]
Added CRLs with CRL extension, it's the .crl_ext files
Joni Hahkala [Tue, 12 Oct 2010 16:44:42 +0000 (16:44 +0000)]
fix slash client, the openssl can't parse dn with slashes without escaping the slashes and getting them through evaluated sed string was complicated
Joni Hahkala [Mon, 11 Oct 2010 16:48:36 +0000 (16:48 +0000)]
added grid-security/certificates-slashwithoutnamespaces ca directory to test .signing_policy with slashes and dots without masking it with .namespaces file.
Joni Hahkala [Mon, 11 Oct 2010 16:24:16 +0000 (16:24 +0000)]
regenerates to get a new namespace definitions for slash CA with certs with slashes and dots
Joni Hahkala [Thu, 8 Jul 2010 15:50:42 +0000 (15:50 +0000)]
fix properly the host_x certs
Joni Hahkala [Thu, 8 Jul 2010 14:56:08 +0000 (14:56 +0000)]
fix host test certs, don't mess up the CN, use separate CN.
Joni Hahkala [Thu, 8 Jul 2010 13:07:14 +0000 (13:07 +0000)]
add the host cert with emailaddress in DN generation
Joni Hahkala [Fri, 25 Jun 2010 22:34:17 +0000 (22:34 +0000)]
add bad ca
Joni Hahkala [Fri, 25 Jun 2010 22:18:42 +0000 (22:18 +0000)]
add bad ca, remove old files
Joni Hahkala [Fri, 25 Jun 2010 22:15:43 +0000 (22:15 +0000)]
- new CA with slash in the DN
- pkcs8 key for <ca-name>_client, <ca-name>_client.priv.pkcs8
- cleaning up leftover files
- remove duplicate DNs, new openssl is more strict, name clashes failed
Joni Hahkala [Tue, 23 Mar 2010 00:10:20 +0000 (00:10 +0000)]
add revoked certs to all CAs, not just trusted, new grid-cecurity/certificates* dirs for testing hierarchical CA namespaces,
full chain proxies for hierarchical CAs
Joni Hahkala [Fri, 19 Mar 2010 01:06:06 +0000 (01:06 +0000)]
add test certs for hierarchical CAs with CA chain, namespaces for the parent CAs
add parent CAs to the grid-security/certificates
Joni Hahkala [Tue, 2 Mar 2010 13:54:48 +0000 (13:54 +0000)]
add license
Joni Hahkala [Mon, 18 Jan 2010 16:36:01 +0000 (16:36 +0000)]
make key usage critical as it should be and add ca:false flag
Joni Hahkala [Thu, 10 Dec 2009 14:48:13 +0000 (14:48 +0000)]
a couple of additional rfc test certs
Joni Hahkala [Wed, 9 Dec 2009 17:39:06 +0000 (17:39 +0000)]
-less unnecessary cert for other than trusted ca
-rfc test certs
-all non-fake cas in grid-security/certificates directory
-regenrated cas to enable changes
Joni Hahkala [Tue, 24 Nov 2009 12:31:49 +0000 (12:31 +0000)]
cleanup
Joni Hahkala [Mon, 23 Nov 2009 22:53:48 +0000 (22:53 +0000)]
simplification, limited proxy, proxy with bad dn, combinations
Joni Hahkala [Wed, 18 Nov 2009 20:20:50 +0000 (20:20 +0000)]
new CAs, removed bad CA, namespaces added
Joni Hahkala [Wed, 18 Nov 2009 20:11:13 +0000 (20:11 +0000)]
regenerated with new scripts
Joni Hahkala [Wed, 18 Nov 2009 17:49:32 +0000 (17:49 +0000)]
combine conf files, cleanup scripts, namespaces, simplify, more test certs, bad certs for each CA, bad ca removed
Joni Hahkala [Sun, 15 Nov 2009 15:17:37 +0000 (15:17 +0000)]
add ca without key usage, root, subca, subsubca, move to single config file, use v3 ca files, use key usage flags and keyids.
Joni Hahkala [Wed, 11 Nov 2009 17:51:14 +0000 (17:51 +0000)]
add CA extensions to make valid CA certs
Joni Hahkala [Wed, 11 Nov 2009 17:50:46 +0000 (17:50 +0000)]
add key usage extensions
Joni Hahkala [Wed, 11 Nov 2009 17:15:04 +0000 (17:15 +0000)]
remove accidentially checked in crls
Joni Hahkala [Mon, 2 Nov 2009 13:32:43 +0000 (13:32 +0000)]
add missing files
Joni Hahkala [Mon, 2 Nov 2009 13:30:20 +0000 (13:30 +0000)]
update certs, long lived server proxy cert
Joni Hahkala [Mon, 2 Nov 2009 12:59:23 +0000 (12:59 +0000)]
forgot the server proxy lifetime extension
Joni Hahkala [Wed, 14 Oct 2009 16:37:47 +0000 (16:37 +0000)]
new try
Joni Hahkala [Wed, 14 Oct 2009 16:30:38 +0000 (16:30 +0000)]
fix the commit error
Joni Hahkala [Tue, 13 Oct 2009 15:07:23 +0000 (15:07 +0000)]
longer proxies
Joni Hahkala [Tue, 13 Oct 2009 15:04:38 +0000 (15:04 +0000)]
update proxies with longer lifetime
Joni Hahkala [Wed, 30 Sep 2009 15:05:47 +0000 (15:05 +0000)]
add altname cert generation
Joni Hahkala [Mon, 29 Jun 2009 10:52:59 +0000 (10:52 +0000)]
forgot these new files from Kalle
Joni Hahkala [Thu, 25 Jun 2009 15:42:54 +0000 (15:42 +0000)]
add kalle's bad CA
Joni Hahkala [Wed, 24 Oct 2007 14:43:43 +0000 (14:43 +0000)]
print openssl command and version
Joni Hahkala [Fri, 9 Mar 2007 10:42:06 +0000 (10:42 +0000)]
update version
Joni Hahkala [Fri, 9 Mar 2007 10:41:20 +0000 (10:41 +0000)]
disable voms certs by default
Akos Frohner [Thu, 21 Dec 2006 15:25:49 +0000 (15:25 +0000)]
getting into shape
Akos Frohner [Thu, 21 Dec 2006 14:08:01 +0000 (14:08 +0000)]
eticsifying
Akos Frohner [Thu, 31 Aug 2006 13:25:13 +0000 (13:25 +0000)]
preparing for release
Akos Frohner [Tue, 29 Aug 2006 16:04:31 +0000 (16:04 +0000)]
Generating an invalid VOMS certificate -- i.e. the issuer certificate is missing from VOMSDIR
Joni Hahkala [Thu, 3 Aug 2006 11:42:58 +0000 (11:42 +0000)]
add also certs with userid in the DN
Joni Hahkala [Wed, 2 Aug 2006 17:09:21 +0000 (17:09 +0000)]
add certificates with serialnumber and emailaddress in the DN.
Akos Frohner [Fri, 14 Jul 2006 11:48:03 +0000 (11:48 +0000)]
Adding default_md=sha1 to be compatible with OpenSSL 0.9.8x and be able to generate CRLs.
Joni Hahkala [Wed, 28 Jun 2006 16:22:31 +0000 (16:22 +0000)]
small fix to prevent clash between generated host certificate and the trusted_server cert.
Akos Frohner [Fri, 9 Jun 2006 08:53:00 +0000 (08:53 +0000)]
VO name has to be added to make a fake VOMS cert look like valid
Akos Frohner [Fri, 9 Jun 2006 07:40:42 +0000 (07:40 +0000)]
workaround #17362
Akos Frohner [Fri, 2 Jun 2006 21:23:24 +0000 (21:23 +0000)]
Setting LD_LIBRARY_PATH and PATH for voms-proxy-fake
Akos Frohner [Mon, 22 May 2006 13:38:41 +0000 (13:38 +0000)]
Proper postinstall script.
Akos Frohner [Mon, 22 May 2006 13:03:05 +0000 (13:03 +0000)]
Enabled daily RPM generation.
Akos Frohner [Mon, 22 May 2006 13:02:12 +0000 (13:02 +0000)]
Added a script to re-generate the host specific server certificate.
Akos Frohner [Mon, 22 May 2006 11:41:51 +0000 (11:41 +0000)]
Simplified the generation of signing_policy file for the Globus clients.
Akos Frohner [Mon, 22 May 2006 09:28:11 +0000 (09:28 +0000)]
More convenient defaults: 5 extra user certs and fake VOMS certs are created.
Akos Frohner [Mon, 22 May 2006 09:23:03 +0000 (09:23 +0000)]
Whitespace changes and variable name rationalization.
Akos Frohner [Mon, 22 May 2006 08:33:31 +0000 (08:33 +0000)]
make the VOMS certs valid for a week
Akos Frohner [Tue, 9 May 2006 22:48:12 +0000 (22:48 +0000)]
Previous changed missed to create a trusted proxy_proxy.proxy certificate -- fixed.
Akos Frohner [Fri, 5 May 2006 12:22:06 +0000 (12:22 +0000)]
voms proxies for the extra user certs too
Akos Frohner [Thu, 4 May 2006 16:16:48 +0000 (16:16 +0000)]
env settings for testing. Use --onlyenv to print these variables, nothing else
Akos Frohner [Thu, 4 May 2006 15:55:23 +0000 (15:55 +0000)]
VOMS proxies using voms-proxy-fake
Akos Frohner [Thu, 4 May 2006 14:34:18 +0000 (14:34 +0000)]
create_all calls create_some to generate some user certs
Akos Frohner [Thu, 4 May 2006 14:33:27 +0000 (14:33 +0000)]
generic update for better handling of temporary files
Joni Hahkala [Tue, 11 Apr 2006 19:39:51 +0000 (19:39 +0000)]
reduce verbosity
Joni Hahkala [Tue, 4 Apr 2006 21:15:06 +0000 (21:15 +0000)]
fix dn error cert names and revoked certs validity times
Joni Hahkala [Tue, 31 Jan 2006 18:22:43 +0000 (18:22 +0000)]
prepare for tagging
Joni Hahkala [Tue, 31 Jan 2006 18:08:47 +0000 (18:08 +0000)]
maybe this will remove the problems with test certs. clean before each build.
Akos Frohner [Tue, 2 Aug 2005 08:52:02 +0000 (08:52 +0000)]
printing the command line parameters
Akos Frohner [Tue, 2 Aug 2005 08:43:34 +0000 (08:43 +0000)]
generating extra user certificates for authorization tests
Joni Hahkala [Wed, 27 Jul 2005 12:22:09 +0000 (12:22 +0000)]
Added 4096bit cert to the set
John White [Mon, 6 Jun 2005 15:24:41 +0000 (15:24 +0000)]
build.xml now cleans user/host certs
John White [Fri, 3 Jun 2005 13:53:02 +0000 (13:53 +0000)]
Moved the version number to reflect a tag.
John White [Fri, 3 Jun 2005 12:48:59 +0000 (12:48 +0000)]
Added the user certificate to the proxy-proxy chain.
Marian Zurek [Thu, 26 May 2005 15:18:39 +0000 (15:18 +0000)]
inserted module.build.file
Marian Zurek [Tue, 12 Apr 2005 20:25:30 +0000 (20:25 +0000)]
"corrections"
Akos Frohner [Thu, 24 Mar 2005 11:03:03 +0000 (11:03 +0000)]
backported fix from RC1
John White [Thu, 3 Mar 2005 10:26:22 +0000 (10:26 +0000)]
Updated documentation to reflect new behaviour of test certificate script.
John White [Thu, 3 Mar 2005 09:57:15 +0000 (09:57 +0000)]
Added the correct permissions to the user key generated when the script is called without
the --all option.
John White [Wed, 2 Mar 2005 16:24:12 +0000 (16:24 +0000)]
Change the behaviour of the CA cert and signing policy file locations so as to exclude /etc/grid-security/certificates as a default location.
John White [Wed, 2 Mar 2005 14:36:49 +0000 (14:36 +0000)]
Changes made for bug number 6743. CA certs are now copied to /etc/grid-security/certificates and also the signing policy files are now generated.
John White [Fri, 28 Jan 2005 14:35:57 +0000 (14:35 +0000)]
I have fixed the proxy serial number problem. The test proxies now have
serial numbers different from one another.
Joni Hahkala [Fri, 21 Jan 2005 12:47:13 +0000 (12:47 +0000)]
adding the fixed to HEAD too.
Joni Hahkala [Wed, 19 Jan 2005 16:05:07 +0000 (16:05 +0000)]
bumping the version in the head version
Joni Hahkala [Fri, 14 Jan 2005 11:20:39 +0000 (11:20 +0000)]
moved to version 1.0.0
John White [Fri, 14 Jan 2005 11:02:47 +0000 (11:02 +0000)]
Updated all configuration files for test certs and proxies.
John White [Fri, 14 Jan 2005 10:38:45 +0000 (10:38 +0000)]
Added ca_proxy_conf.cnf files to the test/* directories.