1 # OCSP test using http://ocsp.openvalidation.org
3 # See http://www.openvalidation.org/useocspservicenew.htm for details. We're
4 # using the CA1 certs obtained from
5 # http://www.openvalidation.org/download/downloadrootcertsCA1.htm
7 # Apparently all requests are signed by Server_CA2, even the ones for
8 # certs which are themselves signed by Server_CA1. So, we need both roots.
10 # This test does not run as of 10/25/06 because the OCSP responses we get
11 # are past their nextUpdate time of 20060816111203Z. We'll keep this here in
12 # case openvalidation.org updates their server.
15 certNetFetchEnable = false
16 useSystemAnchors = false
18 allowUnverified = false
21 echo "================================="
22 test = "no revocation just to make sure we have decent certs"
26 verifyTime=20050101000000
30 echo "================================="
31 test = "OCSP, good status, user cert, cache disabled"
36 responderURI = http://ocsp.openvalidation.org:80
37 responderCert = Server_CA2.crt
38 verifyTime=20050101000000
42 echo "================================="
43 test = "OCSP, good status, user cert, cache enable"
48 responderURI = http://ocsp.openvalidation.org:80
49 responderCert = Server_CA2.crt
51 verifyTime=20050101000000
54 echo "================================="
55 test = "OCSP, good status, user cert, cache disable, net disable, fail"
60 # responderURI = http://ocsp.openvalidation.org:80
61 requireOcspIfPresent = true
63 verifyTime=20050101000000
64 error = APPLETP_OCSP_UNAVAILABLE
65 certerror = 0:APPLETP_OCSP_UNAVAILABLE
68 echo "================================="
69 test = "OCSP, good status, user cert, cache enable, net disable, succeed"
74 # responderURI = http://ocsp.openvalidation.org:80
75 responderCert = Server_CA2.crt
76 reqOcspIfPresent = true
77 # no net but we get it from cache OK
79 ocspNetFetchDisable = true
80 verifyTime=20050101000000
83 echo "================================="
84 test = "OCSP, revoked status, user cert"
89 responderURI = http://ocsp.openvalidation.org:8083
90 responderCert = Server_CA2.crt
91 verifyTime=20050101000000
92 error = TP_CERT_REVOKED
93 certerror = 0:TP_CERT_REVOKED
94 reqOcspIfPresent = true
97 echo "================================="
98 test = "OCSP, unknown status, fail"
103 responderURI = http://ocsp.openvalidation.org:8084
104 responderCert = Server_CA2.crt
105 allowUnverified = false
106 verifyTime=20050101000000
107 # port 8084 yields the "I don't know this cert" failure, so the overall result
108 # when we require OCSP per cert is not available
109 error = APPLETP_OCSP_UNAVAILABLE
110 certerror = 0:APPLETP_OCSP_UNAVAILABLE
113 echo "================================="
114 test = "OCSP, unknown status, success"
119 responderURI = http://ocsp.openvalidation.org:8084
120 responderCert = Server_CA2.crt
121 allowUnverified = true
122 verifyTime=20050101000000