File: README

package info (click to toggle)
qtbase-opensource-src-gles 5.15.8%2Bdfsg-3
  • links: PTS, VCS
  • area: main
  • in suites: bookworm
  • size: 346,596 kB
  • sloc: cpp: 2,033,865; ansic: 304,070; xml: 117,563; python: 9,430; java: 7,393; asm: 4,023; perl: 2,047; sh: 1,939; yacc: 1,687; lex: 1,333; javascript: 878; makefile: 279; objc: 70
file content (9 lines) | stat: -rw-r--r-- 724 bytes parent folder | download | duplicates (9)
1
2
3
4
5
6
7
8
9
openssl verify -CAfile cacert.pem -untrusted test-intermediate-ca-cert.pem test-intermediate-is-ca-cert.pem
openssl verify -CAfile cacert.pem -untrusted test-ocsp-good-cert.pem test-intermediate-not-ca-cert.pem

1. cacert.pem is, obviously, a root CA certificate.
2. test-intermediate-ca-cert.pem is a certificate, signed by the root CA, an intermediate CA.
3. test-intermediate-is-ca-cert.pem is a certificate, signed by test-intermediate-ca-cert.pem.
4. test-ocsp-good-cert.pem is signed by root CA, it has CA:FALSE but keyUsage allowing to sign
   CSRs - this is how OpenSSL would report us 'invalid CA certificate' instead of 'No issuer found'.
5. test-intermediate-not-ca-cert.pem is signed by test-ocsp-good-cert.pem.