2 # Test for NISCC Parasitic key bearing certs.
3 # This version should only succeed if both system-wide key size prefs are
4 # set to > 16K (RSAMaxKeySize, RSAMaxPublicExponent in com.apple.crypto).
6 # The easy way to set these is via the cspxutils/keySizePref program; compile it and
7 # run it like this as root:
10 # keySizePref set keysize 20000
11 # keySizePref set pubexpsize 20000
14 allowUnverified = true
15 crlNetFetchEnable = false
16 certNetFetchEnable = false
17 useSystemAnchors = false
20 test = "locally generated 6K keys"
23 verifyTime = 20060726000000
30 verifyTime = 20060726000000
33 test = "test1, uee16k.pem"
37 verifyTime = 20060726000000
40 test = "test2a, huge pkint8k.pem CA"
44 verifyTime = 20060726000000
47 test = "test2a, bad pkint8k.pem CA, wrong root"
51 error = CSSMERR_TP_NOT_TRUSTED
52 verifyTime = 20060726000000
55 test = "test2b, huge pkint16k.pem CA"
59 verifyTime = 20060726000000
62 test = "test2b, bad pkint16k.pem CA, wrong root"
66 error = CSSMERR_TP_NOT_TRUSTED
67 verifyTime = 20060726000000