Compat self-signed trust with reject-only aux data
When auxiliary data contains only reject entries, continue to trust
self-signed objects just as when no auxiliary data is present.
This makes it possible to reject specific uses without changing
what's accepted (and thus overring the underlying EKU).
Added new supported certs and doubled test count from 38 to 76.
Reviewed-by: NDr. Stephen Henson <steve@openssl.org>
Showing
test/certs/ca+anyEKU.pem
0 → 100644
test/certs/ca-anyEKU.pem
0 → 100644
test/certs/ca-clientAuth.pem
0 → 100644
test/certs/cca+anyEKU.pem
0 → 100644
test/certs/cca+clientAuth.pem
0 → 100644
test/certs/cca+serverAuth.pem
0 → 100644
test/certs/cca-anyEKU.pem
0 → 100644
test/certs/cca-cert.pem
0 → 100644
test/certs/cca-clientAuth.pem
0 → 100644
test/certs/cca-serverAuth.pem
0 → 100644
test/certs/croot+anyEKU.pem
0 → 100644
test/certs/croot+clientAuth.pem
0 → 100644
test/certs/croot+serverAuth.pem
0 → 100644
test/certs/croot-anyEKU.pem
0 → 100644
test/certs/croot-cert.pem
0 → 100644
test/certs/croot-clientAuth.pem
0 → 100644
test/certs/croot-serverAuth.pem
0 → 100644
test/certs/root-clientAuth.pem
0 → 100644
test/certs/sca+anyEKU.pem
0 → 100644
test/certs/sca+clientAuth.pem
0 → 100644
test/certs/sca+serverAuth.pem
0 → 100644
test/certs/sca-anyEKU.pem
0 → 100644
test/certs/sca-cert.pem
0 → 100644
test/certs/sca-clientAuth.pem
0 → 100644
test/certs/sca-serverAuth.pem
0 → 100644
test/certs/sroot+anyEKU.pem
0 → 100644
test/certs/sroot+clientAuth.pem
0 → 100644
test/certs/sroot+serverAuth.pem
0 → 100644
test/certs/sroot-anyEKU.pem
0 → 100644
test/certs/sroot-cert.pem
0 → 100644
test/certs/sroot-clientAuth.pem
0 → 100644
test/certs/sroot-serverAuth.pem
0 → 100644
想要评论请 注册 或 登录