feat: cluster addons
This commit is contained in:
37
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/Makefile
generated
vendored
Normal file
37
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/Makefile
generated
vendored
Normal file
@ -0,0 +1,37 @@
|
||||
all: ca
|
||||
|
||||
# The following private keys are never regenerated.
|
||||
SERVER_PRIVKEYS=gossiper.privkey.pem
|
||||
|
||||
# Server public keys are derived from the corresponding private keys.
|
||||
SERVER_PUBKEYS=$(subst .privkey,.pubkey,$(SERVER_PRIVKEYS))
|
||||
|
||||
# Build public keys from private keys
|
||||
pubkeys: $(SERVER_PUBKEYS)
|
||||
gossiper.pubkey.pem: gossiper.privkey.pem
|
||||
openssl ec -in $< -pubout -out $@ -passin pass:$(GOSSIPER_PWD)
|
||||
|
||||
ROOT_CA_PRIVKEY=gossiper.privkey.pem
|
||||
ROOT_CA_PWD=hissing-sid
|
||||
|
||||
ca: root-ca.cert
|
||||
|
||||
# Fake Root CA
|
||||
root-ca.cert: gossiper.privkey.pem root-ca.cfg
|
||||
openssl req -new -x509 -config root-ca.cfg -set_serial 0x0406cafe -days 3650 -extensions v3_ca -inform pem -key gossiper.privkey.pem -passin pass:$(ROOT_CA_PWD) -out $@
|
||||
show-ca: root-ca.cert
|
||||
openssl x509 -inform pem -in $< -text -noout
|
||||
|
||||
# clean removes things that regenerate exactly the same.
|
||||
clean:
|
||||
rm -f $(SERVER_PUBKEYS)
|
||||
# distclean removes things that regenerate with changes (e.g. timestamped, randomized).
|
||||
distclean: clean
|
||||
rm -f $(SERVER_PUBKEYS) root-ca.cert
|
||||
|
||||
# The newkey target creates a fresh private key; should never be needed.
|
||||
newkey: fresh.privkey.pem
|
||||
fresh.privkey.pem:
|
||||
openssl ecparam -genkey -name prime256v1 -noout -out $@.unencrypted
|
||||
openssl ec -in $@.unencrypted -out $@ -des # Prompts for password
|
||||
rm -f $@.unencrypted
|
32
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/dup-source-name.cfg
generated
vendored
Normal file
32
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/dup-source-name.cfg
generated
vendored
Normal file
@ -0,0 +1,32 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
public_key: {
|
||||
der: "\x30\x59\x30\x13\x06\x07\x2a\x86\x48\xce\x3d\x02\x01\x06\x08\x2a\x86\x48\xce\x3d\x03\x01\x07\x03\x42\x00\x04\x07\xf8\x51\xaf\xaa\x8c\x56\x83\x90\x31\xb7\x80\xe3\xd6\x1a\xf7\x2f\x36\x06\x71\xec\xdd\x3b\xbe\x7e\x36\x6f\x0d\x1c\x1c\x60\x0b\x7f\xf5\x9f\xff\xe5\x24\x49\x34\x56\xf2\x4b\x10\x5f\xbf\x08\x1f\xf9\x0e\xcf\x35\xb5\x8a\x8a\x8b\x30\x0a\x54\xb7\xbf\x1d\x4d\xb9"
|
||||
}
|
||||
>
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source-2"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
public_key: {
|
||||
der: "\x30\x59\x30\x13\x06\x07\x2a\x86\x48\xce\x3d\x02\x01\x06\x08\x2a\x86\x48\xce\x3d\x03\x01\x07\x03\x42\x00\x04\x07\xf8\x51\xaf\xaa\x8c\x56\x83\x90\x31\xb7\x80\xe3\xd6\x1a\xf7\x2f\x36\x06\x71\xec\xdd\x3b\xbe\x7e\x36\x6f\x0d\x1c\x1c\x60\x0b\x7f\xf5\x9f\xff\xe5\x24\x49\x34\x56\xf2\x4b\x10\x5f\xbf\x08\x1f\xf9\x0e\xcf\x35\xb5\x8a\x8a\x8b\x30\x0a\x54\xb7\xbf\x1d\x4d\xb9"
|
||||
}
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013hissing-sid"
|
||||
>
|
17
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/goshawk.cfg
generated
vendored
Normal file
17
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/goshawk.cfg
generated
vendored
Normal file
@ -0,0 +1,17 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
public_key: {
|
||||
der: "\x30\x59\x30\x13\x06\x07\x2a\x86\x48\xce\x3d\x02\x01\x06\x08\x2a\x86\x48\xce\x3d\x03\x01\x07\x03\x42\x00\x04\x07\xf8\x51\xaf\xaa\x8c\x56\x83\x90\x31\xb7\x80\xe3\xd6\x1a\xf7\x2f\x36\x06\x71\xec\xdd\x3b\xbe\x7e\x36\x6f\x0d\x1c\x1c\x60\x0b\x7f\xf5\x9f\xff\xe5\x24\x49\x34\x56\xf2\x4b\x10\x5f\xbf\x08\x1f\xf9\x0e\xcf\x35\xb5\x8a\x8a\x8b\x30\x0a\x54\xb7\xbf\x1d\x4d\xb9"
|
||||
}
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
8
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/gossiper.privkey.pem
generated
vendored
Normal file
8
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/gossiper.privkey.pem
generated
vendored
Normal file
@ -0,0 +1,8 @@
|
||||
-----BEGIN EC PRIVATE KEY-----
|
||||
Proc-Type: 4,ENCRYPTED
|
||||
DEK-Info: DES-CBC,559BE893ECD7A88C
|
||||
|
||||
UOwSw+WlSv5LLiBZSCnR12FX13Hk1a3vavdpUde4W4qawQgJSMqLa3it8Lfadtnm
|
||||
GfGVqN+gF5KFiNWxgMs2qRcbdQ03ZlMmoH8Z8jPQHXvKseJvME8tZQWPvJ15rbXh
|
||||
G9Lcx7NYlm0miHPy3ras8ci58HSDqz9Z7yOdgHzPpiU=
|
||||
-----END EC PRIVATE KEY-----
|
27
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/hawk-dup-source-name.cfg
generated
vendored
Normal file
27
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/hawk-dup-source-name.cfg
generated
vendored
Normal file
@ -0,0 +1,27 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
public_key: {
|
||||
der: "\x30\x59\x30\x13\x06\x07\x2a\x86\x48\xce\x3d\x02\x01\x06\x08\x2a\x86\x48\xce\x3d\x03\x01\x07\x03\x42\x00\x04\x07\xf8\x51\xaf\xaa\x8c\x56\x83\x90\x31\xb7\x80\xe3\xd6\x1a\xf7\x2f\x36\x06\x71\xec\xdd\x3b\xbe\x7e\x36\x6f\x0d\x1c\x1c\x60\x0b\x7f\xf5\x9f\xff\xe5\x24\x49\x34\x56\xf2\x4b\x10\x5f\xbf\x08\x1f\xf9\x0e\xcf\x35\xb5\x8a\x8a\x8b\x30\x0a\x54\xb7\xbf\x1d\x4d\xb9"
|
||||
}
|
||||
>
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source-2"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
public_key: {
|
||||
der: "\x30\x59\x30\x13\x06\x07\x2a\x86\x48\xce\x3d\x02\x01\x06\x08\x2a\x86\x48\xce\x3d\x03\x01\x07\x03\x42\x00\x04\x07\xf8\x51\xaf\xaa\x8c\x56\x83\x90\x31\xb7\x80\xe3\xd6\x1a\xf7\x2f\x36\x06\x71\xec\xdd\x3b\xbe\x7e\x36\x6f\x0d\x1c\x1c\x60\x0b\x7f\xf5\x9f\xff\xe5\x24\x49\x34\x56\xf2\x4b\x10\x5f\xbf\x08\x1f\xf9\x0e\xcf\x35\xb5\x8a\x8a\x8b\x30\x0a\x54\xb7\xbf\x1d\x4d\xb9"
|
||||
}
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
13
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/hawk-no-dest-name.cfg
generated
vendored
Normal file
13
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/hawk-no-dest-name.cfg
generated
vendored
Normal file
@ -0,0 +1,13 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
>
|
||||
dest_log: <
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
7
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/hawk-no-source-log.cfg
generated
vendored
Normal file
7
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/hawk-no-source-log.cfg
generated
vendored
Normal file
@ -0,0 +1,7 @@
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
13
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/hawk-no-source-name.cfg
generated
vendored
Normal file
13
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/hawk-no-source-name.cfg
generated
vendored
Normal file
@ -0,0 +1,13 @@
|
||||
source_log: <
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
19
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/invalid-private-key.cfg
generated
vendored
Normal file
19
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/invalid-private-key.cfg
generated
vendored
Normal file
@ -0,0 +1,19 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gone.privkey.pem\022\013hissing-sid"
|
||||
>
|
19
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/invalid-root-cert.cfg
generated
vendored
Normal file
19
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/invalid-root-cert.cfg
generated
vendored
Normal file
@ -0,0 +1,19 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CARTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013hissing-sid"
|
||||
>
|
20
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/invalid-source-duration.cfg
generated
vendored
Normal file
20
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/invalid-source-duration.cfg
generated
vendored
Normal file
@ -0,0 +1,20 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 10
|
||||
nanos: -20
|
||||
>
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013hissing-sid"
|
||||
>
|
22
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/invalid-source-pubkey.cfg
generated
vendored
Normal file
22
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/invalid-source-pubkey.cfg
generated
vendored
Normal file
@ -0,0 +1,22 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
public_key: {
|
||||
der: "\x30\x59\x30\x13\x06\x07\x2a\x86\x48\xce\x3d\x02\x01\x06\x08\x2a\x86\x48\xce\x3d\x03\x01\x07\x03\x42\x00\x04\x07\xf8\x51\xaf\xaa\x8c\x56\x83\x90\x31\xb7\x80\xe3\xd6\x1a\xf7\x2f\x36\x06\x71\xec\xdd\x3b\xbe\x7e\x36\x6f\x0d\x1c\x1c\x60\x0b\x7f\xf5\x9f\xff\xe5\x24\x49\x34\x56\xf2\x4b\x10\x5f\xbf\x08\x1f\xf9\x0e\xcf\x35\xb5\x8a\x8a\x8b\x30\x0a\x54\xb7\xbf\x1d\x4d"
|
||||
}
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013hissing-sid"
|
||||
>
|
15
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-dest-log.cfg
generated
vendored
Normal file
15
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-dest-log.cfg
generated
vendored
Normal file
@ -0,0 +1,15 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
public_key: {
|
||||
der: "\x30\x59\x30\x13\x06\x07\x2a\x86\x48\xce\x3d\x02\x01\x06\x08\x2a\x86\x48\xce\x3d\x03\x01\x07\x03\x42\x00\x04\x07\xf8\x51\xaf\xaa\x8c\x56\x83\x90\x31\xb7\x80\xe3\xd6\x1a\xf7\x2f\x36\x06\x71\xec\xdd\x3b\xbe\x7e\x36\x6f\x0d\x1c\x1c\x60\x0b\x7f\xf5\x9f\xff\xe5\x24\x49\x34\x56\xf2\x4b\x10\x5f\xbf\x08\x1f\xf9\x0e\xcf\x35\xb5\x8a\x8a\x8b\x30\x0a\x54\xb7\xbf\x1d\x4d\xb9"
|
||||
}
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013hissing-sid"
|
||||
>
|
18
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-dest-name.cfg
generated
vendored
Normal file
18
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-dest-name.cfg
generated
vendored
Normal file
@ -0,0 +1,18 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
>
|
||||
dest_log: <
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013hissing-sid"
|
||||
>
|
15
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-private-key.cfg
generated
vendored
Normal file
15
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-private-key.cfg
generated
vendored
Normal file
@ -0,0 +1,15 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
18
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-root-cert.cfg
generated
vendored
Normal file
18
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-root-cert.cfg
generated
vendored
Normal file
@ -0,0 +1,18 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013hissing-sid"
|
||||
>
|
12
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-source-log.cfg
generated
vendored
Normal file
12
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-source-log.cfg
generated
vendored
Normal file
@ -0,0 +1,12 @@
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013hissing-sid"
|
||||
>
|
18
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-source-name.cfg
generated
vendored
Normal file
18
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/no-source-name.cfg
generated
vendored
Normal file
@ -0,0 +1,18 @@
|
||||
source_log: <
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013hissing-sid"
|
||||
>
|
15
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/root-ca.cert
generated
vendored
Normal file
15
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/root-ca.cert
generated
vendored
Normal file
@ -0,0 +1,15 @@
|
||||
-----BEGIN CERTIFICATE-----
|
||||
MIICQTCCAeegAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP
|
||||
MA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds
|
||||
ZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4
|
||||
MDIyNTA4MTA1M1oXDTI4MDIyMzA4MTA1M1owaTELMAkGA1UEBhMCR0IxDzANBgNV
|
||||
BAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK
|
||||
BgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49
|
||||
AgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH
|
||||
ccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijfTB7MB0GA1UdDgQWBBRq
|
||||
6hoXslGgHhrCVJMu4jrYlksyZjAfBgNVHSMEGDAWgBRq6hoXslGgHhrCVJMu4jrY
|
||||
lksyZjASBgNVHRMBAf8ECDAGAQH/AgEDMA4GA1UdDwEB/wQEAwICBDAVBgNVHSUE
|
||||
DjAMBgorBgEEAdZ5AgQGMAoGCCqGSM49BAMCA0gAMEUCIQCQCnWTIOlC6LqkcdH0
|
||||
fWZeNo5E3AaZBb9Tkv76ET2fJAIgOeGJvfiiOIlDV41/bIOg5eTHb/fxg80TCQBe
|
||||
6ia6ZS8=
|
||||
-----END CERTIFICATE-----
|
28
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/root-ca.cfg
generated
vendored
Normal file
28
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/root-ca.cfg
generated
vendored
Normal file
@ -0,0 +1,28 @@
|
||||
# OpenSSL configuration file.
|
||||
|
||||
[ req ]
|
||||
# Options for the `req` tool (`man req`).
|
||||
default_bits = 2048
|
||||
distinguished_name = req_distinguished_name
|
||||
prompt = no
|
||||
# SHA-1 is deprecated, so use SHA-2 instead.
|
||||
default_md = sha256
|
||||
# Extension to add when the -x509 option is used.
|
||||
x509_extensions = v3_ca
|
||||
# Try to force use of PrintableString throughout
|
||||
string_mask = pkix
|
||||
|
||||
[ req_distinguished_name ]
|
||||
C=GB
|
||||
ST=London
|
||||
L=London
|
||||
O=Google
|
||||
OU=Eng
|
||||
CN=TestGossiperRoot
|
||||
|
||||
[ v3_ca ]
|
||||
subjectKeyIdentifier = hash
|
||||
authorityKeyIdentifier = keyid:always,issuer
|
||||
basicConstraints = critical, CA:true, pathlen:3
|
||||
keyUsage = critical, keyCertSign
|
||||
extendedKeyUsage = 1.3.6.1.4.1.11129.2.4.6
|
22
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/test.cfg
generated
vendored
Normal file
22
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/test.cfg
generated
vendored
Normal file
@ -0,0 +1,22 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
public_key: {
|
||||
der: "\x30\x59\x30\x13\x06\x07\x2a\x86\x48\xce\x3d\x02\x01\x06\x08\x2a\x86\x48\xce\x3d\x03\x01\x07\x03\x42\x00\x04\x07\xf8\x51\xaf\xaa\x8c\x56\x83\x90\x31\xb7\x80\xe3\xd6\x1a\xf7\x2f\x36\x06\x71\xec\xdd\x3b\xbe\x7e\x36\x6f\x0d\x1c\x1c\x60\x0b\x7f\xf5\x9f\xff\xe5\x24\x49\x34\x56\xf2\x4b\x10\x5f\xbf\x08\x1f\xf9\x0e\xcf\x35\xb5\x8a\x8a\x8b\x30\x0a\x54\xb7\xbf\x1d\x4d\xb9"
|
||||
}
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013hissing-sid"
|
||||
>
|
19
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/wrong-password-private-key.cfg
generated
vendored
Normal file
19
vendor/github.com/google/certificate-transparency-go/gossip/minimal/testdata/wrong-password-private-key.cfg
generated
vendored
Normal file
@ -0,0 +1,19 @@
|
||||
source_log: <
|
||||
name: "theSourceOfAllSTHs"
|
||||
url: "http://example.com/ct-source"
|
||||
min_req_interval: <
|
||||
seconds: 3600
|
||||
>
|
||||
>
|
||||
dest_log: <
|
||||
name: "theDestinationOfAllSTHs"
|
||||
url: "http://example.com/ct-dest"
|
||||
min_req_interval: <
|
||||
seconds: 60
|
||||
>
|
||||
>
|
||||
root_cert: "-----BEGIN CERTIFICATE-----\nMIICCzCCAbCgAwIBAgIEBAbK/jAKBggqhkjOPQQDAjBpMQswCQYDVQQGEwJHQjEP\nMA0GA1UECBMGTG9uZG9uMQ8wDQYDVQQHEwZMb25kb24xDzANBgNVBAoTBkdvb2ds\nZTEMMAoGA1UECxMDRW5nMRkwFwYDVQQDExBUZXN0R29zc2lwZXJSb290MB4XDTE4\nMDIyMzEzNDUyOVoXDTI4MDIyMTEzNDUyOVowaTELMAkGA1UEBhMCR0IxDzANBgNV\nBAgTBkxvbmRvbjEPMA0GA1UEBxMGTG9uZG9uMQ8wDQYDVQQKEwZHb29nbGUxDDAK\nBgNVBAsTA0VuZzEZMBcGA1UEAxMQVGVzdEdvc3NpcGVyUm9vdDBZMBMGByqGSM49\nAgEGCCqGSM49AwEHA0IABOqzZufPSU6hMJOIbljkjklDvQKBGYW9VenI6i7HSiyH\nccPUuh3F3fbbe2MrLtuRCjH7nqvcELPqBJsL3IVgQJijRjBEMA0GA1UdDgQGBAQR\nEhMUMA8GA1UdIwQIMAaABBESExQwEgYDVR0TAQH/BAgwBgEB/wIBAzAOBgNVHQ8B\nAf8EBAMCAgQwCgYIKoZIzj0EAwIDSQAwRgIhAICXxzQ+EulZALo8em3KujsOCpNY\n6lvLF5lqBMLS9fxwAiEAkh54N7Dq6P+3Sl/u15TA5DKhFPqgnvnB51wXGAsDhN0=\n-----END CERTIFICATE-----"
|
||||
private_key: <
|
||||
type_url: "type.googleapis.com/keyspb.PEMKeyFile"
|
||||
value: "\n\035testdata/gossiper.privkey.pem\022\013passing-sid"
|
||||
>
|
91
vendor/github.com/google/certificate-transparency-go/gossip/minimal/x509ext/x509ext.go
generated
vendored
Normal file
91
vendor/github.com/google/certificate-transparency-go/gossip/minimal/x509ext/x509ext.go
generated
vendored
Normal file
@ -0,0 +1,91 @@
|
||||
// Copyright 2018 Google Inc. All Rights Reserved.
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
// Package x509ext holds extensions types and values for minimal gossip.
|
||||
package x509ext
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
|
||||
"github.com/google/certificate-transparency-go"
|
||||
"github.com/google/certificate-transparency-go/asn1"
|
||||
"github.com/google/certificate-transparency-go/tls"
|
||||
"github.com/google/certificate-transparency-go/x509"
|
||||
)
|
||||
|
||||
// OIDExtensionCTSTH is the OID value for an X.509 extension that holds
|
||||
// a log STH value.
|
||||
// TODO(drysdale): get an official OID value
|
||||
var OIDExtensionCTSTH = asn1.ObjectIdentifier{1, 3, 6, 1, 4, 1, 11129, 2, 4, 5}
|
||||
|
||||
// OIDExtKeyUsageCTMinimalGossip is the OID value for an extended key usage
|
||||
// (EKU) that indicates a leaf certificate is used for the validation of STH
|
||||
// values from public CT logs.
|
||||
// TODO(drysdale): get an official OID value
|
||||
var OIDExtKeyUsageCTMinimalGossip = asn1.ObjectIdentifier{1, 3, 6, 1, 4, 1, 11129, 2, 4, 6}
|
||||
|
||||
// LogSTHInfo is the structure that gets TLS-encoded into the X.509 extension
|
||||
// identified by OIDExtensionCTSTH.
|
||||
type LogSTHInfo struct {
|
||||
LogURL []byte `tls:"maxlen:255"`
|
||||
Version tls.Enum `tls:"maxval:255"`
|
||||
TreeSize uint64
|
||||
Timestamp uint64
|
||||
SHA256RootHash ct.SHA256Hash
|
||||
TreeHeadSignature ct.DigitallySigned
|
||||
}
|
||||
|
||||
// LogSTHInfoFromCert retrieves the STH information embedded in a certificate.
|
||||
func LogSTHInfoFromCert(cert *x509.Certificate) (*LogSTHInfo, error) {
|
||||
for _, ext := range cert.Extensions {
|
||||
if ext.Id.Equal(OIDExtensionCTSTH) {
|
||||
var sthInfo LogSTHInfo
|
||||
rest, err := tls.Unmarshal(ext.Value, &sthInfo)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("failed to unmarshal STH: %v", err)
|
||||
} else if len(rest) > 0 {
|
||||
return nil, fmt.Errorf("trailing data (%d bytes) after STH", len(rest))
|
||||
}
|
||||
return &sthInfo, nil
|
||||
}
|
||||
}
|
||||
return nil, errors.New("no STH extension found")
|
||||
}
|
||||
|
||||
// HasSTHInfo indicates whether a certificate has embedded STH information.
|
||||
func HasSTHInfo(cert *x509.Certificate) bool {
|
||||
for _, ext := range cert.Extensions {
|
||||
if ext.Id.Equal(OIDExtensionCTSTH) {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
// STHFromCert retrieves the STH embedded in a certificate; note the returned STH
|
||||
// does not have the LogID field filled in.
|
||||
func STHFromCert(cert *x509.Certificate) (*ct.SignedTreeHead, error) {
|
||||
sthInfo, err := LogSTHInfoFromCert(cert)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return &ct.SignedTreeHead{
|
||||
Version: ct.Version(sthInfo.Version),
|
||||
TreeSize: sthInfo.TreeSize,
|
||||
Timestamp: sthInfo.Timestamp,
|
||||
SHA256RootHash: sthInfo.SHA256RootHash,
|
||||
TreeHeadSignature: sthInfo.TreeHeadSignature,
|
||||
}, nil
|
||||
}
|
150
vendor/github.com/google/certificate-transparency-go/gossip/minimal/x509ext/x509ext_test.go
generated
vendored
Normal file
150
vendor/github.com/google/certificate-transparency-go/gossip/minimal/x509ext/x509ext_test.go
generated
vendored
Normal file
@ -0,0 +1,150 @@
|
||||
// Copyright 2018 Google Inc. All Rights Reserved.
|
||||
//
|
||||
// Licensed under the Apache License, Version 2.0 (the "License");
|
||||
// you may not use this file except in compliance with the License.
|
||||
// You may obtain a copy of the License at
|
||||
//
|
||||
// http://www.apache.org/licenses/LICENSE-2.0
|
||||
//
|
||||
// Unless required by applicable law or agreed to in writing, software
|
||||
// distributed under the License is distributed on an "AS IS" BASIS,
|
||||
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
// See the License for the specific language governing permissions and
|
||||
// limitations under the License.
|
||||
|
||||
package x509ext_test
|
||||
|
||||
import (
|
||||
"encoding/hex"
|
||||
"encoding/pem"
|
||||
"fmt"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/google/certificate-transparency-go"
|
||||
"github.com/google/certificate-transparency-go/gossip/minimal/x509ext"
|
||||
"github.com/google/certificate-transparency-go/tls"
|
||||
"github.com/google/certificate-transparency-go/x509"
|
||||
"github.com/google/certificate-transparency-go/x509/pkix"
|
||||
)
|
||||
|
||||
var (
|
||||
// pilotPubKeyPEM is the public key for Google's Pilot log.
|
||||
pilotPubKeyPEM = []byte(`-----BEGIN PUBLIC KEY-----
|
||||
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEfahLEimAoz2t01p3uMziiLOl/fHT
|
||||
DM0YDOhBRuiBARsV4UvxG2LdNgoIGLrtCzWE0J5APC2em4JlvR8EEEFMoA==
|
||||
-----END PUBLIC KEY-----`)
|
||||
)
|
||||
|
||||
func TestSTHFromCert(t *testing.T) {
|
||||
rawPubKey, _ := pem.Decode(pilotPubKeyPEM)
|
||||
pubKey, _, _, err := ct.PublicKeyFromPEM(pilotPubKeyPEM)
|
||||
if err != nil {
|
||||
t.Fatalf("failed to decode test pubkey data: %v", err)
|
||||
}
|
||||
validSTH := x509ext.LogSTHInfo{
|
||||
LogURL: []byte("http://ct.example.com/log"),
|
||||
Version: 0,
|
||||
TreeSize: 7834120,
|
||||
Timestamp: 1519395540364,
|
||||
SHA256RootHash: [...]byte{
|
||||
0xfe, 0xc0, 0xed, 0xe1, 0xbe, 0xf1, 0xa2, 0x25, 0xc3, 0x72, 0xa6, 0x44, 0x1b, 0xa2, 0xd5, 0xdd, 0x3b, 0xbb, 0x9b, 0x7b, 0xa9, 0x79, 0xd1, 0xa7, 0x03, 0xe7, 0xfe, 0x81, 0x49, 0x75, 0x85, 0xfb,
|
||||
},
|
||||
TreeHeadSignature: ct.DigitallySigned{
|
||||
Algorithm: tls.SignatureAndHashAlgorithm{Hash: tls.SHA256, Signature: tls.ECDSA},
|
||||
Signature: dehex("220164e031604aa2a0b68887ba668cefb3e0046e455d6323c3df38b8d50108895d70220146199ee1d759a029d8b37ce8701d2ca47a387bad8ac8ef1cb84b77bc0820ed"),
|
||||
},
|
||||
}
|
||||
sthData, err := tls.Marshal(validSTH)
|
||||
if err != nil {
|
||||
t.Fatalf("failed to marshal STH: %v", err)
|
||||
}
|
||||
|
||||
var tests = []struct {
|
||||
name string
|
||||
cert x509.Certificate
|
||||
wantErr string
|
||||
}{
|
||||
{
|
||||
name: "ValidSTH",
|
||||
cert: x509.Certificate{
|
||||
NotBefore: time.Now(),
|
||||
NotAfter: time.Now().Add(24 * time.Hour),
|
||||
PublicKey: pubKey,
|
||||
RawSubjectPublicKeyInfo: rawPubKey.Bytes,
|
||||
Subject: pkix.Name{
|
||||
CommonName: "Test STH holder",
|
||||
},
|
||||
Extensions: []pkix.Extension{
|
||||
{Id: x509ext.OIDExtensionCTSTH, Critical: false, Value: sthData},
|
||||
},
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "MissingSTH",
|
||||
cert: x509.Certificate{
|
||||
NotBefore: time.Now(),
|
||||
NotAfter: time.Now().Add(24 * time.Hour),
|
||||
Subject: pkix.Name{
|
||||
CommonName: "Test STH holder",
|
||||
},
|
||||
},
|
||||
wantErr: "no STH extension found",
|
||||
},
|
||||
{
|
||||
name: "TrailingData",
|
||||
cert: x509.Certificate{
|
||||
NotBefore: time.Now(),
|
||||
NotAfter: time.Now().Add(24 * time.Hour),
|
||||
Subject: pkix.Name{
|
||||
CommonName: "Test STH holder",
|
||||
},
|
||||
Extensions: []pkix.Extension{
|
||||
{Id: x509ext.OIDExtensionCTSTH, Critical: false, Value: append(sthData, 0xff)},
|
||||
},
|
||||
},
|
||||
wantErr: "trailing data",
|
||||
},
|
||||
{
|
||||
name: "InvalidSTH",
|
||||
cert: x509.Certificate{
|
||||
NotBefore: time.Now(),
|
||||
NotAfter: time.Now().Add(24 * time.Hour),
|
||||
Subject: pkix.Name{
|
||||
CommonName: "Test STH holder",
|
||||
},
|
||||
Extensions: []pkix.Extension{
|
||||
{Id: x509ext.OIDExtensionCTSTH, Critical: false, Value: []byte{0xff}},
|
||||
},
|
||||
},
|
||||
wantErr: "failed to unmarshal",
|
||||
},
|
||||
}
|
||||
|
||||
for _, test := range tests {
|
||||
t.Run(test.name, func(t *testing.T) {
|
||||
got, err := x509ext.STHFromCert(&test.cert)
|
||||
if err != nil {
|
||||
if test.wantErr == "" {
|
||||
t.Errorf("STHFromCert(%+v)=nil,%v; want _,nil", test.cert, err)
|
||||
} else if !strings.Contains(err.Error(), test.wantErr) {
|
||||
t.Errorf("STHFromCert(%+v)=nil,%v; want nil,err containing %q", test.cert, err, test.wantErr)
|
||||
}
|
||||
return
|
||||
}
|
||||
if test.wantErr != "" {
|
||||
t.Errorf("STHFromCert(%+v)=_,nil; want nil,err containing %q", test.cert, test.wantErr)
|
||||
}
|
||||
t.Logf("retrieved STH %+v", got)
|
||||
})
|
||||
}
|
||||
}
|
||||
|
||||
func dehex(h string) []byte {
|
||||
d, err := hex.DecodeString(h)
|
||||
if err != nil {
|
||||
panic(fmt.Sprintf("hard-coded data %q failed to decode! %v", h, err))
|
||||
}
|
||||
return d
|
||||
}
|
Reference in New Issue
Block a user