Changeset 20f8e99 in mod_gnutls


Ignore:
Timestamp:
May 30, 2016, 4:03:29 PM (2 years ago)
Author:
Thomas Klute <thomas2.klute@…>
Branches:
debian/master, debian/stretch-backports, master, upstream
Children:
4cc1edc
Parents:
94cb972
Message:

Provide full certificate chain to the server

The server will need CA certificate(s) to verify OCSP responses.

Location:
test
Files:
2 edited

Legend:

Unmodified
Added
Removed
  • test/Makefile.am

    r94cb972 r20f8e99  
    128128endif
    129129
     130if ENABLE_OCSP_TEST
    130131# rules to build OCSP database
    131 if ENABLE_OCSP_TEST
    132132check_DATA += authority/ocsp_index.txt
    133133MOSTLYCLEANFILES += authority/ocsp_index.txt authority/ocsp_index.txt.attr
     
    137137authority/ocsp_index.txt.attr: authority/secret.key
    138138        echo "unique_subject = no" > $@
     139
     140# build certificate chain file for server
     141check_DATA += server/x509-chain.pem
     142MOSTLYCLEANFILES += server/x509-chain.pem
     143%/x509-chain.pem: %/x509.pem authority/x509.pem
     144        cat $< authority/x509.pem > $@
    139145endif
    140146
  • test/tests/27_OCSP_server/apache.conf

    r94cb972 r20f8e99  
    1111        ServerName              ${TEST_HOST}
    1212        GnuTLSEnable            On
    13         GnuTLSCertificateFile   server/x509.pem
     13        GnuTLSCertificateFile   server/x509-chain.pem
    1414        GnuTLSKeyFile           server/secret.key
    1515        GnuTLSPriorities        NORMAL
Note: See TracChangeset for help on using the changeset viewer.