Commit message (Collapse) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | add additional increment tests | Paul Kehrer | 2015-07-01 | 1 | -8/+18 |
| | |||||
* | put the AAD and encrypted byte limit checks in the parent context | Paul Kehrer | 2015-07-01 | 1 | -0/+30 |
| | |||||
* | Merge pull request #2084 from reaperhulk/name-constraints-ossl | Alex Gaynor | 2015-07-01 | 1 | -0/+44 |
|\ | | | | | Name constraints ossl | ||||
| * | support name constraints in the openssl backend | Paul Kehrer | 2015-06-29 | 1 | -0/+44 |
| | | |||||
* | | Merge pull request #2073 from glyph/no-c-random | Paul Kehrer | 2015-06-30 | 2 | -8/+38 |
|\ \ | |/ |/| | Replace C implementation of OS Random engine with Python one that just calls os.urandom | ||||
| * | test libressl when there is no libressl | Glyph | 2015-06-30 | 1 | -2/+15 |
| | | |||||
| * | pep8 | Glyph | 2015-06-30 | 1 | -0/+1 |
| | | |||||
| * | Detect and ignore LibreSSL. | Glyph | 2015-06-30 | 1 | -1/+3 |
| | | |||||
| * | the output of RAND_bytes is os.urandom's result | Glyph | 2015-06-29 | 1 | -0/+14 |
| | | |||||
| * | handle previous registration by raising RuntimeError | Glyph | 2015-06-27 | 1 | -2/+2 |
| | | |||||
| * | pointer shenanigans | Glyph | 2015-06-26 | 1 | -9/+8 |
| | | | | | | | | | | | | | | | | apparently (?) ENGINE_by_id treats its ID as an opaque *pointer* key and not actually as a string, and while CPython's CFFI support seems to manage to preserve the pointer identity when using the same Python string, PyPy doesn't. Fix things to use a cffi-wrapped pointer again and tests pass on PyPy. | ||||
| * | remove remaining vestiges, make adding twice work | Glyph | 2015-06-26 | 2 | -4/+2 |
| | | |||||
| * | compare contents and not pointers | Glyph | 2015-06-26 | 1 | -9/+12 |
| | | |||||
* | | fix | Alex Gaynor | 2015-06-27 | 1 | -1/+2 |
| | | |||||
* | | Simplified code in the test loaders and improved branch coverage in the x509 ↵ | Alex Gaynor | 2015-06-27 | 2 | -53/+47 |
| | | | | | | | | tests | ||||
* | | require serialization in asym tests | Paul Kehrer | 2015-06-27 | 4 | -164/+70 |
| | | |||||
* | | More branch coverage improvements. By virtue of reorganization and a new test | Alex Gaynor | 2015-06-27 | 1 | -0/+21 |
| | | |||||
* | | Fixed #2067 -- raise an error if a CSRbuilder doesn't hav a subject | Alex Gaynor | 2015-06-27 | 1 | -1/+11 |
| | | |||||
* | | Merge pull request #2071 from reaperhulk/wildcard-oh-no | Alex Gaynor | 2015-06-27 | 1 | -0/+31 |
|\ \ | |/ |/| | handle wildcard DNSNames with IDNA. | ||||
| * | handle wildcard DNSNames with IDNA. | Paul Kehrer | 2015-06-26 | 1 | -0/+31 |
| | | | | | | | | fixes #2054 | ||||
* | | fix this test | Alex Gaynor | 2015-06-26 | 1 | -1/+1 |
| | | |||||
* | | Merge branch 'master' into param-ordering | Alex Gaynor | 2015-06-26 | 1 | -3/+31 |
|\| | |||||
| * | test notimplementederror for unsupported csr extensions in backends | Paul Kehrer | 2015-06-26 | 1 | -0/+14 |
| | | |||||
| * | add test for CSR builder setting subject twice | Paul Kehrer | 2015-06-26 | 1 | -3/+17 |
| | | |||||
* | | Make the parameter ordering in sign() consistent with other code | Alex Gaynor | 2015-06-26 | 1 | -16/+6 |
|/ | |||||
* | simplify x509 csr builder tests | Paul Kehrer | 2015-06-26 | 1 | -40/+0 |
| | |||||
* | Use SECP256R1 instead of SECT283K1 in CSR tests | Ian Cordasco | 2015-06-24 | 2 | -4/+4 |
| | |||||
* | Add test for unicode attributes in CSRs | Ian Cordasco | 2015-06-24 | 1 | -0/+32 |
| | | | | | This creates a CSR, converts it to bytes, and then loads it again to ensure that the unicode strings are parsed properly. | ||||
* | Skip tests when the EC curve is unsupported | Ian Cordasco | 2015-06-24 | 2 | -0/+3 |
| | |||||
* | Add tests to the CSR Builder for EC and DSA keys | Ian Cordasco | 2015-06-24 | 2 | -4/+108 |
| | | | | | | This skips certain tests on certain versions of differences in how X509_REQ_sign works on those versions. A separate pull request will address those differences. | ||||
* | Simplify test for unsupported extensions | Ian Cordasco | 2015-06-24 | 1 | -9/+1 |
| | |||||
* | Address review comments around add_extension method | Ian Cordasco | 2015-06-24 | 1 | -2/+3 |
| | | | | | | | | | - Fix typo in the docs (s/buidlder/builder/) - Remove default from the method declaration and docs - Replace ValueError with NotImpelementedError for unsupported X.509 extensions - Add TODO comment as requested by Alex - Fix test to pass critical=False since it no longer is a default value | ||||
* | Properly use RSA fixtures to generate private keys | Ian Cordasco | 2015-06-24 | 1 | -4/+10 |
| | |||||
* | Update CSR tests and implementation | Ian Cordasco | 2015-06-24 | 1 | -21/+5 |
| | | | | | | | | | | - Use keyword arguments for x509.BasicConstraints in tests (missed in b790edbdc8fb9a026353d6fb99994326197705c7). - Place X509_request garbage collection under assertion. - Assert that X509 extensions created are not null. - Don't copy the extensions list in CertificateSigningBuilder. They're never appended to, so copying isn't necessary. - Use RSA key fixtures instead of generating new ones on each test run | ||||
* | Fix new tests to pass text value to NameAttribute | Ian Cordasco | 2015-06-24 | 1 | -20/+20 |
| | |||||
* | Address code review regarding style and gc | Ian Cordasco | 2015-06-24 | 1 | -2/+2 |
| | | | | | | | | | - Use keyword arguments for x509.BasicConstraints in several places - Use SHA256 instead of SHA1 in documented examples - Give function variables meaningful names in _encode_asn1_str - Accept a x509.BasicConstraints object in _encode_basic_constraints - Properly garbage-collect some things - Raise a NotImplementedError instead of a ValueError | ||||
* | Fixes PEP8 issue in tests. | Andre Caron | 2015-06-24 | 1 | -5/+0 |
| | |||||
* | Removes set_ prefix on CSR builder method. | Andre Caron | 2015-06-24 | 1 | -4/+4 |
| | |||||
* | Changes builder extension API. | Andre Caron | 2015-06-24 | 1 | -31/+14 |
| | |||||
* | Removes CSR builder version setter. | Andre Caron | 2015-06-24 | 1 | -23/+18 |
| | |||||
* | Adds method chaining to CSR builder. | Andre Caron | 2015-06-24 | 1 | -29/+30 |
| | |||||
* | Renames sign_509_request to create_x509_csr. | Andre Caron | 2015-06-24 | 1 | -0/+6 |
| | |||||
* | Adds CSR builder. | Andre Caron | 2015-06-24 | 1 | -0/+147 |
| | |||||
* | fix ec_cdata_to_evp_pkey bug | Paul Kehrer | 2015-06-22 | 1 | -0/+18 |
| | | | | | | We weren't actually returning the object and the tests weren't catching it because we didn't try to use the evp_pkey property in the tests. The added test confirms it actually works. | ||||
* | Remove our workarounds for pyasn.1 bugs, a new pyasn.1 is out! | Alex Gaynor | 2015-06-22 | 1 | -2/+2 |
| | |||||
* | add eq/ne support to NameConstraints | Paul Kehrer | 2015-06-21 | 1 | -0/+29 |
| | |||||
* | add nameconstraints classes | Paul Kehrer | 2015-06-21 | 1 | -0/+68 |
| | |||||
* | Merge pull request #2036 from major/master | Alex Gaynor | 2015-06-21 | 1 | -0/+33 |
|\ | | | | | Added a repr() method to x509._Certificate | ||||
| * | Added a repr() method to x509._Certificate | Major Hayden | 2015-06-21 | 1 | -0/+33 |
| | | |||||
* | | Refs #1947 -- add support for IAN to the OpenSSL backend | Alex Gaynor | 2015-06-20 | 1 | -0/+17 |
| | |