Mercurial > hg > nginx-tests
comparison ssl_stapling.t @ 1488:dbce8fb5f5f8
Tests: align with OpenSSL security level 2.
This updates minimum requirements to 2048 bit RSA keys and SHA-2 message digest.
author | Sergey Kandaurov <pluknet@nginx.com> |
---|---|
date | Tue, 09 Jul 2019 13:37:55 +0300 |
parents | e8ba4ae5e3ac |
children | 2d371452658c |
comparison
equal
deleted
inserted
replaced
1487:fe0765147e15 | 1488:dbce8fb5f5f8 |
---|---|
122 my $d = $t->testdir(); | 122 my $d = $t->testdir(); |
123 my $p = port(8081); | 123 my $p = port(8081); |
124 | 124 |
125 $t->write_file('openssl.conf', <<EOF); | 125 $t->write_file('openssl.conf', <<EOF); |
126 [ req ] | 126 [ req ] |
127 default_bits = 1024 | 127 default_bits = 2048 |
128 encrypt_key = no | 128 encrypt_key = no |
129 distinguished_name = req_distinguished_name | 129 distinguished_name = req_distinguished_name |
130 [ req_distinguished_name ] | 130 [ req_distinguished_name ] |
131 EOF | 131 EOF |
132 | 132 |
135 default_ca = myca | 135 default_ca = myca |
136 | 136 |
137 [ myca ] | 137 [ myca ] |
138 new_certs_dir = $d | 138 new_certs_dir = $d |
139 database = $d/certindex | 139 database = $d/certindex |
140 default_md = sha1 | 140 default_md = sha256 |
141 policy = myca_policy | 141 policy = myca_policy |
142 serial = $d/certserial | 142 serial = $d/certserial |
143 default_days = 1 | 143 default_days = 1 |
144 x509_extensions = myca_extensions | 144 x509_extensions = myca_extensions |
145 | 145 |