testcert

package
v0.9.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 4, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Overview

Package testcert provides a static X509 client certificate for use in tests.

Tests which need a trusted TLS client certificate should use the certificate provided here instead of embedding their own copy, so the expected fingerprint only has to be maintained in a single place.

Index

Constants

View Source
const ClientCertificate = `` /* 716-byte string literal not displayed */

ClientCertificate is a X509 PEM encoded client certificate with the same properties as a certificate generated by GenerateMemCert(true, false) from github.com/lxc/incus/v7/shared/tls, but with a generic subject, which does not reference any real host or user.

It can be regenerated with openssl as follows:

cat > openssl.cnf <<'EOF'
[req]
distinguished_name = dn
prompt             = no
x509_extensions    = client_cert

[dn]
O  = Linux Containers
CN = user@host.some.tld

[client_cert]
keyUsage               = critical, digitalSignature, keyEncipherment
extendedKeyUsage       = clientAuth
basicConstraints       = critical, CA:FALSE
subjectKeyIdentifier   = none
authorityKeyIdentifier = none
EOF

openssl ecparam -name secp384r1 -genkey -noout -out client.key
openssl req -new -x509 -sha384 -key client.key -out client.crt -days 3650 -config openssl.cnf

Regenerating the certificate does change its fingerprint, therefore ClientCertificateFingerprint has to be updated as well.

View Source
const ClientCertificateFingerprint = "b4e08ef4c7fb1c14b4b73422e9375fa3bdd992836ed58bc78673dcd532083ad0"

ClientCertificateFingerprint is the canonical SHA256 fingerprint of ClientCertificate, in the lower case, colon free form used by CertFingerprint from github.com/lxc/incus/v7/shared/tls.

It can be calculated with openssl as follows:

openssl x509 -in client.crt -noout -fingerprint -sha256 | sed 's/.*=//; s/://g' | tr '[:upper:]' '[:lower:]'
View Source
const SecondClientCertificate = `` /* 720-byte string literal not displayed */

SecondClientCertificate is a second X509 PEM encoded client certificate for tests, which need to distinguish between two clients. It is generated the same way as ClientCertificate, but with "other@host.some.tld" as common name.

View Source
const SecondClientCertificateFingerprint = "11f365352f3d4e2c4d501b6b5786457627dbd525689aa86a2623069a4d840765"

SecondClientCertificateFingerprint is the canonical SHA256 fingerprint of SecondClientCertificate.

Variables

This section is empty.

Functions

This section is empty.

Types

This section is empty.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL