Skip to content

Missing make rule for test/fixtures/keys/0-dns-* #10228

Description

@kapouer

Part of ssl 1.1.0 transition will require to rebuild old certificates fixtures
to use stronger encryption, and i don't find how to rebuild those files.

Activity

  1. added
    cryptoIssues and PRs related to the crypto subsystem.
    opensslIssues and PRs related to the OpenSSL dependency.
    testIssues and PRs related to Node.js core tests and test infrastructure.
    on Dec 11, 2016
  2. addaleax commented on Dec 11, 2016

    @addaleax
    Member
  3. sam-github commented on Dec 12, 2016

    @sam-github
    Contributor

    I skimmed #8491, and don't understand why a new ossl should require cert rebuild. Please explain.

    However, it would be good if the Makefile built all the certs, and it doesn't. It would be even nicer if it only build the ones that were missing... so that it was easy to add new cert variants without regenerating the root keys and rebuilding their certs.

    Unfortunately, ossl doesn't seem capable of building certs completely from CLI args, it needs custom config files. I've been poking at this a bit, but haven't had the time to get anywhere (I want more certs issued by sub-CAs, among other things).

  4. kapouer commented on Dec 12, 2016

    @kapouer
    ContributorAuthor

    The reason is simple, openssl throw errors about using too short keys, so new, longer keys, must be regenerated.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    cryptoIssues and PRs related to the crypto subsystem.opensslIssues and PRs related to the OpenSSL dependency.testIssues and PRs related to Node.js core tests and test infrastructure.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions