2 # Test for NISCC Parasitic key bearing certs, with the RSAMaxKeySize set to > 16k.
3 # The easy way to set this is via the cspxutils/keySizePref program; compile it and
4 # run it like this as root:
6 # keySizePref set keysize 20000
10 crlNetFetchEnable = false
11 certNetFetchEnable = false
12 useSystemAnchors = false
15 test = "locally generated 6K keys"
18 verifyTime = 20060726000000
25 verifyTime = 20060726000000
27 error = CSSMERR_TP_INVALID_CERTIFICATE
30 test = "test1, uee16k.pem"
34 verifyTime = 20060726000000
36 error = CSSMERR_TP_INVALID_CERTIFICATE
39 test = "test2a, huge pkint8k.pem CA"
43 verifyTime = 20060726000000
44 # leaf is OK, other certs have pub exponent too large
45 error = CSSMERR_TP_NOT_TRUSTED
48 test = "test2a, bad pkint8k.pem CA, wrong root"
52 verifyTime = 20060726000000
53 error = CSSMERR_TP_NOT_TRUSTED
56 test = "test2b, huge pkint16k.pem CA"
60 verifyTime = 20060726000000
61 # leaf is OK, other certs have pub exponent too large
62 error = CSSMERR_TP_NOT_TRUSTED
65 test = "test2b, bad pkint16k.pem CA, wrong root"
69 verifyTime = 20060726000000
70 error = CSSMERR_TP_NOT_TRUSTED