Documentation
¶
Overview ¶
Package testcert provides a static X509 client certificate for use in tests.
Tests which need a trusted TLS client certificate should use the certificate provided here instead of embedding their own copy, so the expected fingerprint only has to be maintained in a single place.
Index ¶
Constants ¶
const ClientCertificate = `` /* 716-byte string literal not displayed */
ClientCertificate is a X509 PEM encoded client certificate with the same properties as a certificate generated by GenerateMemCert(true, false) from github.com/lxc/incus/v7/shared/tls, but with a generic subject, which does not reference any real host or user.
It can be regenerated with openssl as follows:
cat > openssl.cnf <<'EOF' [req] distinguished_name = dn prompt = no x509_extensions = client_cert [dn] O = Linux Containers CN = user@host.some.tld [client_cert] keyUsage = critical, digitalSignature, keyEncipherment extendedKeyUsage = clientAuth basicConstraints = critical, CA:FALSE subjectKeyIdentifier = none authorityKeyIdentifier = none EOF openssl ecparam -name secp384r1 -genkey -noout -out client.key openssl req -new -x509 -sha384 -key client.key -out client.crt -days 3650 -config openssl.cnf
Regenerating the certificate does change its fingerprint, therefore ClientCertificateFingerprint has to be updated as well.
const ClientCertificateFingerprint = "b4e08ef4c7fb1c14b4b73422e9375fa3bdd992836ed58bc78673dcd532083ad0"
ClientCertificateFingerprint is the canonical SHA256 fingerprint of ClientCertificate, in the lower case, colon free form used by CertFingerprint from github.com/lxc/incus/v7/shared/tls.
It can be calculated with openssl as follows:
openssl x509 -in client.crt -noout -fingerprint -sha256 | sed 's/.*=//; s/://g' | tr '[:upper:]' '[:lower:]'
const SecondClientCertificate = `` /* 720-byte string literal not displayed */
SecondClientCertificate is a second X509 PEM encoded client certificate for tests, which need to distinguish between two clients. It is generated the same way as ClientCertificate, but with "other@host.some.tld" as common name.
const SecondClientCertificateFingerprint = "11f365352f3d4e2c4d501b6b5786457627dbd525689aa86a2623069a4d840765"
SecondClientCertificateFingerprint is the canonical SHA256 fingerprint of SecondClientCertificate.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
This section is empty.