create SSL certificates with a more realistic expiration date
authorSantiago Vila <sanvila@debian.org>
Tue, 21 May 2024 15:49:40 +0000 (18:49 +0300)
committerDmitry Shachnev <mitya57@debian.org>
Tue, 21 May 2024 15:49:40 +0000 (18:49 +0300)
Forwarded: not-needed
Last-Update: 2023-12-09

Gbp-Pq: Name extend-expiration-time-for-ssl-certs.patch

tests/auto/external_IODevice/cert/generate.sh

index b79c8629b06b0a326efe3cf426b58b12b1bf0efe..2de165195e9c385e263fe777c3a977fe8041f048 100644 (file)
@@ -30,7 +30,7 @@
 # Generate the CA key
 openssl genrsa -out rootCA.key 2048
 # Generate the CA cert
-openssl req -x509 -key rootCA.key -out rootCA.pem -sha256 -nodes -subj "/CN=QtRO CA" -days 836
+openssl req -x509 -key rootCA.key -out rootCA.pem -sha256 -nodes -subj "/CN=QtRO CA" -days 3651
 
 # genFiles stem [extra args to signing]
 genFiles () {
@@ -42,7 +42,7 @@ genFiles () {
     openssl req -new -key $stem.key -out $stem.csr -subj "/CN=127.0.0.1"
     # Generate and sign the certificate
     openssl x509 -req -in $stem.csr -out $stem.crt \
-                 -CA rootCA.pem -CAkey rootCA.key -CAcreateserial -days 825 -sha256 "$@"
+                 -CA rootCA.pem -CAkey rootCA.key -CAcreateserial -days 3650 -sha256 "$@"
     # Delete the signing request, no longer needed
     rm $stem.csr
 }