Add CABF Subscriber EKU test cases - #534
Open
jvdprng wants to merge 1 commit into
Open
Conversation
Contributor
Author
|
Since the bot cannot run when the PR comes from a fork, here is a copy from our fork for informational purposes: New testcasesThere are new testcases in this change. openssl-3.5.4
pyca-cryptography-46.0.3
rust-webpki
openssl-3.6.0
gnutls-certtool-3.8.3
certvalidator-0.11.1
gocryptox509-go1.25.4
openssl-3.2.6
openssl-3.0.18
openssl-3.4.3
rustls-webpki
openssl-3.3.5
openssl-1.1
|
facutuesca
force-pushed
the
add-testcase-cabf-subscriber-eku
branch
from
February 10, 2026 23:13
c76f1cd to
aeabde4
Compare
facutuesca
force-pushed
the
add-testcase-cabf-subscriber-eku
branch
from
March 2, 2026 20:05
aeabde4 to
7814b1a
Compare
🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude <noreply@anthropic.com>
facutuesca
force-pushed
the
add-testcase-cabf-subscriber-eku
branch
from
March 2, 2026 20:10
7814b1a to
a7dc70d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR adds test cases for CABF Baseline Requirements 7.1.2.7.10 regarding subscriber Extended Key Usage (EKU) validation.
There are 8 new test cases:
ee_clientauth_only: Tests rejection when onlyclientAuthis present (serverAuthis missing)ee_precertificate_only: Tests rejection when only precertificate OID is present (serverAuthis missing)ee_precertificate_with_serverauth: Tests rejection ofserverAuthand precertificate OIDee_serverauth_with_additional: Tests acceptance whenserverAuthandclientAuthare presentee_codesigning_with_serverauth: Tests rejection ofserverAuthandcodeSigningee_emailprotection_with_serverauth: Tests rejection ofserverAuthandemailProtectionee_timestamping_with_serverauth: Tests rejection ofserverAuthandtimeStampingee_ocspsigning_with_serverauth: Tests rejection ofserverAuthandOCSPSigning🤖 Generated with Claude Code