Add test certificate with basicConstraints containing only an INTEGER

The basicConstraints extension contains only an INTEGER. According to
RFC 5280, this should be cA=FALSE and a pathLenConstraint value which is
effectively ignored. But Mbed TLS parses it as cA=TRUE if the integer value
is nonzero.

This certificate is syntactically valid, but RFC 5280 forbids CAs from
emitting it. Compliant X.509 parsers treat it as cA=FALSE.

Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
3 files changed
tree: 6bdf283f0f99b24250f112aa2788ed65689b593c
  1. .github/
  2. data_files/
  3. docs/
  4. history/
  5. psasim/
  6. scripts/
  7. tests/
  8. util/
  9. .gitignore
  10. CMakeLists.txt
  11. CONTRIBUTING.md
  12. dco.txt
  13. exported.make
  14. LICENSE
  15. README.md
README.md

Mbed TLS framework

This repository contains a version-independent build and test framework for TF-PSA-Crypto and Mbed TLS.

You need this repository as a Git submodule in a branch of one of the above repositories if:

  • You want to build, test or contribute to Mbed TLS 3.6.0 or above, and you are working from a snapshot of a Git commit on a development branch.
  • You want to build, test or contribute to TF-PSA-Crypto, and you are working from a snapshot of a Git commit on a development branch.

You do not need this repository if:

  • You are working with Mbed TLS 2.28.
  • You want to build a release of Mbed TLS and run its unit tests.

Contributing

We gratefully accept bug reports and contributions from the community. Please see the contributing guidelines for details on how to do this.

License

Unless specifically indicated otherwise in a file, Mbed TLS framework files are provided under a dual Apache-2.0 OR GPL-2.0-or-later license. See the LICENSE file for the full text of these licenses, and the ‘License and Copyright’ section in the contributing guidelines for more information.