[PYTHON-CRYPTO] Need server certificates that include multiple commonName/subjectAltName fields for testing

Heikki Toivonen heikki at OSAFOUNDATION.ORG
Thu Mar 23 20:35:20 CET 2006


Michael Ströder wrote:
> Heikki Toivonen wrote:
>> Need server certificates that include multiple commonName/subjectAltName
>> fields for testing.
> 
> Do you really need multiple CN attrs in the subject DN of a server cert?
> Never saw this out in the wild. Which does not mean that it's
> impossible... ;-)

Exactly. If someone knows of such real world usage I want to see it and
test against it.

> Why don't you create some yourself with OpenSSL?

I could, but there are no guarantees they would be exactly like real
certs in the wild. I'd rather confirm with real certs that are in use,
or part of known-to-be-good test certificates.

> I vaguely remember that someone (Peter Gutmann?) provided a collection
> of really weird certs which I used when implementing mspki (certificate
> parsing in web2ldap).

Thanks for the tip, I'll try searching for those.

-- 
  Heikki Toivonen


-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 251 bytes
Desc: OpenPGP digital signature
URL: <http://mail.python.org/pipermail/python-crypto/attachments/20060323/bd56a5ca/attachment.pgp>


More information about the python-crypto mailing list