Skip to content

Commit 969438b

Browse files
committed
#524 Revocation of NOC root certificates
Enable revoking NOC Root certs Signed-off-by: Abdulbois <abdulbois.tursunov@dsr-corporation.com> Signed-off-by: Abdulbois <abdulbois123@gmail.com>
1 parent 252b7ee commit 969438b

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

49 files changed

+5334
-320
lines changed

integration_tests/cli/pki-noc-certs.sh

+127-1
Original file line numberDiff line numberDiff line change
@@ -7,6 +7,9 @@ noc_root_cert_1_subject_key_id="44:EB:4C:62:6B:25:48:CD:A2:B3:1C:87:41:5A:08:E7:
77
noc_root_cert_1_serial_number="47211865327720222621302679792296833381734533449"
88
noc_root_cert_1_subject_as_text="CN=NOC-1,OU=Testing Division,O=Example Company,L=Tashkent,ST=Some State,C=UZ"
99

10+
noc_root_cert_1_copy_path="integration_tests/constants/noc_root_cert_1_copy"
11+
noc_root_cert_1_copy_serial_number="460647353168152946606945669687905527879095841977"
12+
1013
noc_root_cert_2_path="integration_tests/constants/noc_root_cert_2"
1114
noc_root_cert_2_subject="MHoxCzAJBgNVBAYTAlVaMRMwEQYDVQQIDApTb21lIFN0YXRlMREwDwYDVQQHDAhUYXNoa2VudDEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMQ4wDAYDVQQDDAVOT0MtMg=="
1215
noc_root_cert_2_subject_key_id="CF:E6:DD:37:2B:4C:B2:B9:A9:F2:75:30:1C:AA:B1:37:1B:11:7F:1B"
@@ -22,13 +25,18 @@ noc_root_cert_3_subject_as_text="CN=NOC-3,O=Internet Widgits Pty Ltd,ST=Some-Sta
2225
noc_cert_1_path="integration_tests/constants/noc_cert_1"
2326
noc_cert_1_subject="MIGCMQswCQYDVQQGEwJVWjETMBEGA1UECAwKU29tZSBTdGF0ZTETMBEGA1UEBwwKU29tZSBTdGF0ZTEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMRQwEgYDVQQDDAtOT0MtY2hpbGQtMQ=="
2427
noc_cert_1_subject_key_id="02:72:6E:BC:BB:EF:D6:BD:8D:9B:42:AE:D4:3C:C0:55:5F:66:3A:B3"
25-
noc_cert_1_serial_number="674670448117546613288490437900193266085116131998"
28+
noc_cert_1_serial_number="631388393741945881054190991612463928825155142122"
2629

2730
noc_cert_2_path="integration_tests/constants/noc_cert_2"
2831
noc_cert_2_subject="MIGCMQswCQYDVQQGEwJVWjETMBEGA1UECAwKU29tZSBTdGF0ZTETMBEGA1UEBwwKU29tZSBTdGF0ZTEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMRQwEgYDVQQDDAtOT0MtY2hpbGQtMg=="
2932
noc_cert_2_subject_key_id="87:48:A2:33:12:1F:51:5C:93:E6:90:40:4A:2C:AB:9E:D6:19:E5:AD"
3033
noc_cert_2_serial_number="361372967010167010646904372658654439710639340814"
3134

35+
noc_leaf_cert_1_path="integration_tests/constants/noc_leaf_cert_1"
36+
noc_leaf_cert_1_subject="MIGBMQswCQYDVQQGEwJVWjETMBEGA1UECAwKU29tZSBTdGF0ZTETMBEGA1UEBwwKU29tZSBTdGF0ZTEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMRMwEQYDVQQDDApOT0MtbGVhZi0x"
37+
noc_leaf_cert_1_subject_key_id="77:1F:DB:C4:4C:B1:29:7E:3C:EB:3E:D8:2A:38:0B:63:06:07:00:01"
38+
noc_leaf_cert_1_serial_number="281347277961838999749763518155363401757954575313"
39+
3240
trustee_account="jack"
3341
second_trustee_account="alice"
3442

@@ -237,4 +245,122 @@ check_response "$result" "\"subjectKeyId\": \"$noc_cert_2_subject_key_id\""
237245
check_response "$result" "\"serialNumber\": \"$noc_cert_2_serial_number\""
238246
echo $result | jq
239247

248+
test_divider
249+
250+
echo "Add third NOC root certificate by vendor with VID = $vid"
251+
result=$(echo "$passphrase" | dcld tx pki add-noc-x509-root-cert --certificate="$noc_root_cert_1_copy_path" --from $vendor_account --yes)
252+
check_response "$result" "\"code\": 0"
253+
254+
echo "Add NOC leaf certificate by vendor with VID = $vid"
255+
result=$(echo "$passphrase" | dcld tx pki add-noc-x509-cert --certificate="$noc_leaf_cert_1_path" --from $vendor_account --yes)
256+
check_response "$result" "\"code\": 0"
257+
258+
echo "Request All NOC root certificate"
259+
result=$(dcld query pki all-noc-x509-root-certs)
260+
echo $result | jq
261+
check_response "$result" "\"serialNumber\": \"$noc_root_cert_1_serial_number\""
262+
check_response "$result" "\"serialNumber\": \"$noc_root_cert_1_copy_serial_number\""
263+
check_response "$result" "\"serialNumber\": \"$noc_root_cert_2_serial_number\""
264+
265+
echo "Request all NOC certificates"
266+
result=$(dcld query pki all-noc-x509-certs)
267+
echo $result | jq
268+
check_response "$result" "\"serialNumber\": \"$noc_cert_1_serial_number\""
269+
check_response "$result" "\"serialNumber\": \"$noc_cert_2_serial_number\""
270+
check_response "$result" "\"serialNumber\": \"$noc_leaf_cert_1_serial_number\""
271+
272+
echo "Try to revoke intermediate with different VID = $vid_2"
273+
result=$(echo "$passphrase" | dcld tx pki revoke-noc-x509-root-cert --subject="$noc_root_cert_1_subject" --subject-key-id="$noc_root_cert_1_subject_key_id" --from $vendor_account_2 --yes)
274+
check_response "$result" "\"code\": 439"
275+
276+
echo "$vendor_account Vendor revokes only root certificate, it should not revoke intermediate certificates"
277+
result=$(echo "$passphrase" | dcld tx pki revoke-noc-x509-root-cert --subject="$noc_root_cert_1_subject" --subject-key-id="$noc_root_cert_1_subject_key_id" --from=$vendor_account --yes)
278+
check_response "$result" "\"code\": 0"
279+
280+
echo "Request all revoked certificates should contain two root certificates only"
281+
result=$(dcld query pki all-revoked-x509-certs)
282+
echo $result | jq
283+
check_response "$result" "\"subject\": \"$noc_root_cert_1_subject"
284+
check_response "$result" "\"subjectKeyId\": \"$noc_root_cert_1_subject_key_id\""
285+
check_response "$result" "\"serialNumber\": \"$noc_root_cert_1_serial_number\""
286+
check_response "$result" "\"serialNumber\": \"$noc_root_cert_1_copy_serial_number\""
287+
response_does_not_contain "$result" "\"subject\": \"$noc_cert_1_subject\""
288+
response_does_not_contain "$result" "\"subject\": \"$noc_leaf_cert_1_subject\""
289+
290+
echo "Request all revoked noc root certificates should contain two root certificates"
291+
result=$(dcld query pki all-revoked-noc-x509-root-certs)
292+
echo $result | jq
293+
check_response "$result" "\"subject\": \"$noc_root_cert_1_subject"
294+
check_response "$result" "\"subjectKeyId\": \"$noc_root_cert_1_subject_key_id\""
295+
check_response "$result" "\"serialNumber\": \"$noc_root_cert_1_serial_number\""
296+
check_response "$result" "\"serialNumber\": \"$noc_root_cert_1_copy_serial_number\""
297+
response_does_not_contain "$result" "\"subject\": \"$noc_cert_1_subject\""
298+
response_does_not_contain "$result" "\"subject\": \"$noc_leaf_cert_1_subject\""
299+
300+
echo "Request revoked noc root certificate by subject and subjectKeyId should contain two root certificates"
301+
result=$(dcld query pki revoked-noc-x509-root-cert --subject="$noc_root_cert_1_subject" --subject-key-id="$noc_root_cert_1_subject_key_id")
302+
echo $result | jq
303+
check_response "$result" "\"subject\": \"$noc_root_cert_1_subject"
304+
check_response "$result" "\"subjectKeyId\": \"$noc_root_cert_1_subject_key_id\""
305+
check_response "$result" "\"serialNumber\": \"$noc_root_cert_1_serial_number\""
306+
check_response "$result" "\"serialNumber\": \"$noc_root_cert_1_copy_serial_number\""
307+
response_does_not_contain "$result" "\"subject\": \"$noc_root_cert_2_subject\""
308+
response_does_not_contain "$result" "\"subject\": \"$noc_root_cert_3_subject\""
309+
310+
echo "Request all x509 root revoked certificates should not contain revoked NOC root certificates"
311+
result=$(dcld query pki all-revoked-x509-root-certs)
312+
response_does_not_contain "$result" "\"subject\": \"$noc_root_cert_1_subject\""
313+
response_does_not_contain "$result" "\"subjectKeyId\": \"$noc_root_cert_1_subject_key_id\""
314+
response_does_not_contain "$result" "\"serialNumber\": \"$noc_root_cert_1_serial_number\""
315+
response_does_not_contain "$result" "\"serialNumber\": \"$noc_root_cert_1_copy_serial_number\""
316+
echo $result | jq
317+
318+
echo "Request NOC certificate by VID must not contain revoked root certificates"
319+
result=$(dcld query pki noc-x509-root-certs --vid="$vid")
320+
check_response "$result" "Not Found"
321+
response_does_not_contain "$result" "\"subject\": \"$noc_root_cert_1_subject\""
322+
response_does_not_contain "$result" "\"subjectKeyId\": \"$noc_root_cert_1_subject_key_id\""
323+
response_does_not_contain "$result" "\"serialNumber\": \"$noc_root_cert_1_serial_number\""
324+
response_does_not_contain "$result" "\"serialNumber\": \"$noc_root_cert_1_copy_serial_number\""
325+
echo $result | jq
326+
327+
echo "Request all certificates by subject must be empty"
328+
result=$(dcld query pki all-subject-x509-certs --subject="$noc_root_cert_1_subject")
329+
response_does_not_contain "$result" "\"subject\": \"$noc_root_cert_1_subject\""
330+
response_does_not_contain "$result" "\"subjectKeyId\": \"$noc_root_cert_1_subject_key_id\""
331+
echo $result | jq
332+
333+
echo "Request all certificates by subjectKeyId must be empty"
334+
result=$(dcld query pki x509-cert --subject-key-id="$noc_root_cert_1_subject_key_id")
335+
check_response "$result" "Not Found"
336+
response_does_not_contain "$result" "\"subject\": \"$noc_root_cert_1_subject\""
337+
response_does_not_contain "$result" "\"subjectKeyId\": \"$noc_root_cert_1_subject_key_id\""
338+
response_does_not_contain "$result" "\"serialNumber\": \"$noc_root_cert_1_serial_number\""
339+
response_does_not_contain "$result" "\"serialNumber\": \"$noc_root_cert_1_copy_serial_number\""
340+
echo $result | jq
341+
342+
echo "Request NOC certificate by VID = $vid should contain intermediate and leaf certificates"
343+
result=$(dcld query pki noc-x509-certs --vid="$vid")
344+
echo $result | jq
345+
check_response "$result" "\"subject\": \"$noc_cert_1_subject\""
346+
check_response "$result" "\"subject\": \"$noc_leaf_cert_1_subject\""
347+
check_response "$result" "\"subjectKeyId\": \"$noc_cert_1_subject_key_id\""
348+
check_response "$result" "\"subjectKeyId\": \"$noc_leaf_cert_1_subject_key_id\""
349+
check_response "$result" "\"serialNumber\": \"$noc_cert_1_serial_number\""
350+
check_response "$result" "\"serialNumber\": \"$noc_leaf_cert_1_serial_number\""
351+
352+
echo "Request all approved certificates should not contain revoked NOC root certificates"
353+
result=$(dcld query pki all-x509-certs)
354+
check_response "$result" "\"subject\": \"$noc_cert_1_subject\""
355+
check_response "$result" "\"subjectKeyId\": \"$noc_cert_1_subject_key_id\""
356+
check_response "$result" "\"serialNumber\": \"$noc_cert_1_serial_number\""
357+
check_response "$result" "\"subject\": \"$noc_leaf_cert_1_subject\""
358+
check_response "$result" "\"subjectKeyId\": \"$noc_leaf_cert_1_subject_key_id\""
359+
check_response "$result" "\"serialNumber\": \"$noc_leaf_cert_1_serial_number\""
360+
response_does_not_contain "$result" "\"subject\": \"$noc_root_cert_1_subject\""
361+
response_does_not_contain "$result" "\"subjectKeyId\": \"$noc_root_cert_1_subject_key_id\""
362+
response_does_not_contain "$result" "\"serialNumber\": \"$noc_root_cert_1_serial_number\""
363+
response_does_not_contain "$result" "\"serialNumber\": \"$noc_root_cert_1_copy_serial_number\""
364+
echo $result | jq
365+
240366
test_divider
+8-8
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,15 @@
11
-----BEGIN CERTIFICATE-----
2-
MIICQzCCAemgAwIBAgIUdi1E6xKBzdiOtwcjbQ/7wusqOp4wCgYIKoZIzj0EAwIw
2+
MIICUjCCAfegAwIBAgIUbphvTQvJM1AaArsW9AbHWp7fweowCgYIKoZIzj0EAwIw
33
ejELMAkGA1UEBhMCVVoxEzARBgNVBAgMClNvbWUgU3RhdGUxETAPBgNVBAcMCFRh
44
c2hrZW50MRgwFgYDVQQKDA9FeGFtcGxlIENvbXBhbnkxGTAXBgNVBAsMEFRlc3Rp
5-
bmcgRGl2aXNpb24xDjAMBgNVBAMMBU5PQy0xMCAXDTI0MDMwNTA2Mjg1NVoYDzMw
6-
MjMwNzA3MDYyODU1WjCBgjELMAkGA1UEBhMCVVoxEzARBgNVBAgMClNvbWUgU3Rh
5+
bmcgRGl2aXNpb24xDjAMBgNVBAMMBU5PQy0xMCAXDTI0MDMxMjExMDYyOFoYDzMw
6+
MjMwNzE0MTEwNjI4WjCBgjELMAkGA1UEBhMCVVoxEzARBgNVBAgMClNvbWUgU3Rh
77
dGUxEzARBgNVBAcMClNvbWUgU3RhdGUxGDAWBgNVBAoMD0V4YW1wbGUgQ29tcGFu
88
eTEZMBcGA1UECwwQVGVzdGluZyBEaXZpc2lvbjEUMBIGA1UEAwwLTk9DLWNoaWxk
99
LTEwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAATOPY6vbvv8no8NcIdfa/MbkJep
10-
FkUcfOYym0gajL2yph8a/wk0RpYqL+M+KJ4oja70oKK/igBmEitRD4VB3mXQo0Iw
11-
QDAdBgNVHQ4EFgQUAnJuvLvv1r2Nm0Ku1DzAVV9mOrMwHwYDVR0jBBgwFoAUROtM
12-
YmslSM2isxyHQVoI5yu5gyYwCgYIKoZIzj0EAwIDSAAwRQIhAOhW3b4ekIdwqn0R
13-
olz9kHN89goHOoRGTXAXUDkWptO1AiAbh5P/xEJZDKZbsUM9IFUyzG2xAk3+GOFQ
14-
LhNMpjD/KQ==
10+
FkUcfOYym0gajL2yph8a/wk0RpYqL+M+KJ4oja70oKK/igBmEitRD4VB3mXQo1Aw
11+
TjAdBgNVHQ4EFgQUAnJuvLvv1r2Nm0Ku1DzAVV9mOrMwHwYDVR0jBBgwFoAUROtM
12+
YmslSM2isxyHQVoI5yu5gyYwDAYDVR0TBAUwAwEB/zAKBggqhkjOPQQDAgNJADBG
13+
AiEAzUSg9uY1+hn4Xe5ZyxmhEe5ycTtA7o94jA3x1ygGXcECIQD8mYhLsOss/API
14+
/xNPu7fcgPAwhltZAf6Cf9QVxRme/Q==
1515
-----END CERTIFICATE-----

integration_tests/constants/noc_constants.go

+54-11
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,22 @@ FgQUROtMYmslSM2isxyHQVoI5yu5gyYwHwYDVR0jBBgwFoAUROtMYmslSM2isxyH
1515
QVoI5yu5gyYwDAYDVR0TBAUwAwEB/zAKBggqhkjOPQQDAgNJADBGAiEAuieAwmim
1616
npvmoTg56q4mrS0P8OywMwpdoKalWTyiaJICIQDoeyqpCZA8E6GpudrsBk4oiNOQ
1717
v2eIe9+M9tp4hvDATQ==
18+
-----END CERTIFICATE-----`
19+
20+
NocRootCert1Copy = `-----BEGIN CERTIFICATE-----
21+
MIICRzCCAe6gAwIBAgIUULAkR20O0d0hLOesMcEm8O40dLkwCgYIKoZIzj0EAwIw
22+
ejELMAkGA1UEBhMCVVoxEzARBgNVBAgMClNvbWUgU3RhdGUxETAPBgNVBAcMCFRh
23+
c2hrZW50MRgwFgYDVQQKDA9FeGFtcGxlIENvbXBhbnkxGTAXBgNVBAsMEFRlc3Rp
24+
bmcgRGl2aXNpb24xDjAMBgNVBAMMBU5PQy0xMCAXDTI0MDMxMjA2MjAwNVoYDzMw
25+
MjMwNzE0MDYyMDA1WjB6MQswCQYDVQQGEwJVWjETMBEGA1UECAwKU29tZSBTdGF0
26+
ZTERMA8GA1UEBwwIVGFzaGtlbnQxGDAWBgNVBAoMD0V4YW1wbGUgQ29tcGFueTEZ
27+
MBcGA1UECwwQVGVzdGluZyBEaXZpc2lvbjEOMAwGA1UEAwwFTk9DLTEwWTATBgcq
28+
hkjOPQIBBggqhkjOPQMBBwNCAAQKxbUDnEpO/ipt9SxSnvhtA2WQlXoZkvn1v4+C
29+
ovKrs/U8y0krcvs2aKxS92xPV1ivWwzMMQrpm5qOSmQh95Xeo1AwTjAdBgNVHQ4E
30+
FgQUROtMYmslSM2isxyHQVoI5yu5gyYwHwYDVR0jBBgwFoAUROtMYmslSM2isxyH
31+
QVoI5yu5gyYwDAYDVR0TBAUwAwEB/zAKBggqhkjOPQQDAgNHADBEAiAyBxbQmr+E
32+
2/0pq+oIW95kG4U+PKmq3hIYRncm+m/z9gIgBDJzAN68hvnHg0inVYrg2MN5axao
33+
tWtwwBf6dHZ91KU=
1834
-----END CERTIFICATE-----`
1935

2036
NocRootCert2 = `-----BEGIN CERTIFICATE-----
@@ -50,19 +66,19 @@ F5UqAiEAshHfXxUpdfxqiLoTjQjkNf0AHVYBFhLdB+iIFspwTyg=
5066
`
5167

5268
NocCert1 = `-----BEGIN CERTIFICATE-----
53-
MIICQzCCAemgAwIBAgIUdi1E6xKBzdiOtwcjbQ/7wusqOp4wCgYIKoZIzj0EAwIw
69+
MIICUjCCAfegAwIBAgIUbphvTQvJM1AaArsW9AbHWp7fweowCgYIKoZIzj0EAwIw
5470
ejELMAkGA1UEBhMCVVoxEzARBgNVBAgMClNvbWUgU3RhdGUxETAPBgNVBAcMCFRh
5571
c2hrZW50MRgwFgYDVQQKDA9FeGFtcGxlIENvbXBhbnkxGTAXBgNVBAsMEFRlc3Rp
56-
bmcgRGl2aXNpb24xDjAMBgNVBAMMBU5PQy0xMCAXDTI0MDMwNTA2Mjg1NVoYDzMw
57-
MjMwNzA3MDYyODU1WjCBgjELMAkGA1UEBhMCVVoxEzARBgNVBAgMClNvbWUgU3Rh
72+
bmcgRGl2aXNpb24xDjAMBgNVBAMMBU5PQy0xMCAXDTI0MDMxMjExMDYyOFoYDzMw
73+
MjMwNzE0MTEwNjI4WjCBgjELMAkGA1UEBhMCVVoxEzARBgNVBAgMClNvbWUgU3Rh
5874
dGUxEzARBgNVBAcMClNvbWUgU3RhdGUxGDAWBgNVBAoMD0V4YW1wbGUgQ29tcGFu
5975
eTEZMBcGA1UECwwQVGVzdGluZyBEaXZpc2lvbjEUMBIGA1UEAwwLTk9DLWNoaWxk
6076
LTEwWTATBgcqhkjOPQIBBggqhkjOPQMBBwNCAATOPY6vbvv8no8NcIdfa/MbkJep
61-
FkUcfOYym0gajL2yph8a/wk0RpYqL+M+KJ4oja70oKK/igBmEitRD4VB3mXQo0Iw
62-
QDAdBgNVHQ4EFgQUAnJuvLvv1r2Nm0Ku1DzAVV9mOrMwHwYDVR0jBBgwFoAUROtM
63-
YmslSM2isxyHQVoI5yu5gyYwCgYIKoZIzj0EAwIDSAAwRQIhAOhW3b4ekIdwqn0R
64-
olz9kHN89goHOoRGTXAXUDkWptO1AiAbh5P/xEJZDKZbsUM9IFUyzG2xAk3+GOFQ
65-
LhNMpjD/KQ==
77+
FkUcfOYym0gajL2yph8a/wk0RpYqL+M+KJ4oja70oKK/igBmEitRD4VB3mXQo1Aw
78+
TjAdBgNVHQ4EFgQUAnJuvLvv1r2Nm0Ku1DzAVV9mOrMwHwYDVR0jBBgwFoAUROtM
79+
YmslSM2isxyHQVoI5yu5gyYwDAYDVR0TBAUwAwEB/zAKBggqhkjOPQQDAgNJADBG
80+
AiEAzUSg9uY1+hn4Xe5ZyxmhEe5ycTtA7o94jA3x1ygGXcECIQD8mYhLsOss/API
81+
/xNPu7fcgPAwhltZAf6Cf9QVxRme/Q==
6682
-----END CERTIFICATE-----`
6783

6884
NocCert2 = `-----BEGIN CERTIFICATE-----
@@ -79,13 +95,34 @@ QDAdBgNVHQ4EFgQUh0iiMxIfUVyT5pBASiyrntYZ5a0wHwYDVR0jBBgwFoAUz+bd
7995
NytMsrmp8nUwHKqxNxsRfxswCgYIKoZIzj0EAwIDSAAwRQIgV9R3OgmjB/YTFk2N
8096
6ojiUIh8+OjlGca5B//lyzaq/0ICIQDGB7S1/LrmDdN1OJBUYrwFhEcJMl2cdvcW
8197
BQTbJS3ZSQ==
98+
-----END CERTIFICATE-----`
99+
100+
NocLeafCert1 = `-----BEGIN CERTIFICATE-----
101+
MIICWjCCAf+gAwIBAgIUMUgMW6iOeiqCuProDLAW/Wnui9EwCgYIKoZIzj0EAwIw
102+
gYIxCzAJBgNVBAYTAlVaMRMwEQYDVQQIDApTb21lIFN0YXRlMRMwEQYDVQQHDApT
103+
b21lIFN0YXRlMRgwFgYDVQQKDA9FeGFtcGxlIENvbXBhbnkxGTAXBgNVBAsMEFRl
104+
c3RpbmcgRGl2aXNpb24xFDASBgNVBAMMC05PQy1jaGlsZC0xMCAXDTI0MDMxMjEx
105+
MDgzMVoYDzMwMjMwNzE0MTEwODMxWjCBgTELMAkGA1UEBhMCVVoxEzARBgNVBAgM
106+
ClNvbWUgU3RhdGUxEzARBgNVBAcMClNvbWUgU3RhdGUxGDAWBgNVBAoMD0V4YW1w
107+
bGUgQ29tcGFueTEZMBcGA1UECwwQVGVzdGluZyBEaXZpc2lvbjETMBEGA1UEAwwK
108+
Tk9DLWxlYWYtMTBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABImxHSKEsY2bvle9
109+
o4FwLOaRYswT+M4K6X5vHrIzvRKi436vWt1P+YjyjmPnytl+4y8ZXjAmuvTk2OOy
110+
Z1Y7yuejUDBOMB0GA1UdDgQWBBR3H9vETLEpfjzrPtgqOAtjBgcAATAfBgNVHSME
111+
GDAWgBQCcm68u+/WvY2bQq7UPMBVX2Y6szAMBgNVHRMEBTADAQH/MAoGCCqGSM49
112+
BAMCA0kAMEYCIQDzsjB569j1SsltNIP8CMTD4kRsTulqSp+O7JbQdWyzPAIhAODV
113+
zodhpBXZfzhHDvINejK8wzwWgf7Ds8wk3oENlmAj
82114
-----END CERTIFICATE-----`
83115

84116
NocRootCert1Subject = "MHoxCzAJBgNVBAYTAlVaMRMwEQYDVQQIDApTb21lIFN0YXRlMREwDwYDVQQHDAhUYXNoa2VudDEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMQ4wDAYDVQQDDAVOT0MtMQ=="
85117
NocRootCert1SubjectKeyID = "44:EB:4C:62:6B:25:48:CD:A2:B3:1C:87:41:5A:08:E7:2B:B9:83:26"
86118
NocRootCert1SerialNumber = "47211865327720222621302679792296833381734533449"
87119
NocRootCert1SubjectAsText = "CN=NOC-1,OU=Testing Division,O=Example Company,L=Tashkent,ST=Some State,C=UZ"
88120

121+
NocRootCert1CopySubject = "MHoxCzAJBgNVBAYTAlVaMRMwEQYDVQQIDApTb21lIFN0YXRlMREwDwYDVQQHDAhUYXNoa2VudDEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMQ4wDAYDVQQDDAVOT0MtMQ=="
122+
NocRootCert1CopySubjectKeyID = "44:EB:4C:62:6B:25:48:CD:A2:B3:1C:87:41:5A:08:E7:2B:B9:83:26"
123+
NocRootCert1CopySerialNumber = "460647353168152946606945669687905527879095841977"
124+
NocRootCert1CopySubjectAsText = "CN=NOC-1,OU=Testing Division,O=Example Company,L=Tashkent,ST=Some State,C=UZ"
125+
89126
NocRootCert2Subject = "MHoxCzAJBgNVBAYTAlVaMRMwEQYDVQQIDApTb21lIFN0YXRlMREwDwYDVQQHDAhUYXNoa2VudDEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMQ4wDAYDVQQDDAVOT0MtMg=="
90127
NocRootCert2SubjectKeyID = "CF:E6:DD:37:2B:4C:B2:B9:A9:F2:75:30:1C:AA:B1:37:1B:11:7F:1B"
91128
NocRootCert2SerialNumber = "332802481233145945539125204504842614737181725760"
@@ -97,14 +134,20 @@ BQTbJS3ZSQ==
97134
NocRootCert3SubjectAsText = "CN=NOC-3,O=Internet Widgits Pty Ltd,ST=Some-State,C=AU"
98135

99136
NocCert1Subject = "MIGCMQswCQYDVQQGEwJVWjETMBEGA1UECAwKU29tZSBTdGF0ZTETMBEGA1UEBwwKU29tZSBTdGF0ZTEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMRQwEgYDVQQDDAtOT0MtY2hpbGQtMQ=="
100-
NocCert1Issuer = "MHoxCzAJBgNVBAYTAlVaMRMwEQYDVQQIDApTb21lIFN0YXRlMREwDwYDVQQHDAhUYXNoa2VudDEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMQ4wDAYDVQQDDAVOT0MtMQ=="
137+
NocCert1Issuer = NocRootCert1Subject
101138
NocCert1SubjectKeyID = "02:72:6E:BC:BB:EF:D6:BD:8D:9B:42:AE:D4:3C:C0:55:5F:66:3A:B3"
102-
NocCert1SerialNumber = "674670448117546613288490437900193266085116131998"
139+
NocCert1SerialNumber = "631388393741945881054190991612463928825155142122"
103140
NocCert1SubjectAsText = "CN=NOC-child-1,OU=Testing Division,O=Example Company,L=Some State,ST=Some State,C=UZ"
104141

105142
NocCert2Subject = "MIGCMQswCQYDVQQGEwJVWjETMBEGA1UECAwKU29tZSBTdGF0ZTETMBEGA1UEBwwKU29tZSBTdGF0ZTEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMRQwEgYDVQQDDAtOT0MtY2hpbGQtMg=="
106-
NocCert2Issuer = "MHoxCzAJBgNVBAYTAlVaMRMwEQYDVQQIDApTb21lIFN0YXRlMREwDwYDVQQHDAhUYXNoa2VudDEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMQ4wDAYDVQQDDAVOT0MtMg=="
143+
NocCert2Issuer = NocRootCert2Subject
107144
NocCert2SubjectKeyID = "87:48:A2:33:12:1F:51:5C:93:E6:90:40:4A:2C:AB:9E:D6:19:E5:AD"
108145
NocCert2SerialNumber = "361372967010167010646904372658654439710639340814"
109146
NocCert2SubjectAsText = "CN=NOC-child-2,OU=Testing Division,O=Example Company,L=Some State,ST=Some State,C=UZ"
147+
148+
NocLeafCert1Subject = "MIGBMQswCQYDVQQGEwJVWjETMBEGA1UECAwKU29tZSBTdGF0ZTETMBEGA1UEBwwKU29tZSBTdGF0ZTEYMBYGA1UECgwPRXhhbXBsZSBDb21wYW55MRkwFwYDVQQLDBBUZXN0aW5nIERpdmlzaW9uMRMwEQYDVQQDDApOT0MtbGVhZi0x"
149+
NocLeafCert1Issuer = NocCert1Subject
150+
NocLeafCert1SubjectKeyID = "77:1F:DB:C4:4C:B1:29:7E:3C:EB:3E:D8:2A:38:0B:63:06:07:00:01"
151+
NocLeafCert1SerialNumber = "281347277961838999749763518155363401757954575313"
152+
NocLeafCert1SubjectAsText = "CN=NOC-leaf-1,OU=Testing Division,O=Example Company,L=Some State,ST=Some State,C=UZ"
110153
)
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
-----BEGIN CERTIFICATE-----
2+
MIICWjCCAf+gAwIBAgIUMUgMW6iOeiqCuProDLAW/Wnui9EwCgYIKoZIzj0EAwIw
3+
gYIxCzAJBgNVBAYTAlVaMRMwEQYDVQQIDApTb21lIFN0YXRlMRMwEQYDVQQHDApT
4+
b21lIFN0YXRlMRgwFgYDVQQKDA9FeGFtcGxlIENvbXBhbnkxGTAXBgNVBAsMEFRl
5+
c3RpbmcgRGl2aXNpb24xFDASBgNVBAMMC05PQy1jaGlsZC0xMCAXDTI0MDMxMjEx
6+
MDgzMVoYDzMwMjMwNzE0MTEwODMxWjCBgTELMAkGA1UEBhMCVVoxEzARBgNVBAgM
7+
ClNvbWUgU3RhdGUxEzARBgNVBAcMClNvbWUgU3RhdGUxGDAWBgNVBAoMD0V4YW1w
8+
bGUgQ29tcGFueTEZMBcGA1UECwwQVGVzdGluZyBEaXZpc2lvbjETMBEGA1UEAwwK
9+
Tk9DLWxlYWYtMTBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABImxHSKEsY2bvle9
10+
o4FwLOaRYswT+M4K6X5vHrIzvRKi436vWt1P+YjyjmPnytl+4y8ZXjAmuvTk2OOy
11+
Z1Y7yuejUDBOMB0GA1UdDgQWBBR3H9vETLEpfjzrPtgqOAtjBgcAATAfBgNVHSME
12+
GDAWgBQCcm68u+/WvY2bQq7UPMBVX2Y6szAMBgNVHRMEBTADAQH/MAoGCCqGSM49
13+
BAMCA0kAMEYCIQDzsjB569j1SsltNIP8CMTD4kRsTulqSp+O7JbQdWyzPAIhAODV
14+
zodhpBXZfzhHDvINejK8wzwWgf7Ds8wk3oENlmAj
15+
-----END CERTIFICATE-----

0 commit comments

Comments
 (0)