<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/regress/lib/libcrypto/x509, branch master</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=master</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2026-04-13T17:04:23+00:00</updated>
<entry>
<title>Prior to this we substring matched and allowed a leading .</title>
<updated>2026-04-13T17:04:23+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2026-04-13T17:04:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=cf3eec32e7a6acbaecd14871fb75ad34fb76c3e7'/>
<id>urn:sha1:cf3eec32e7a6acbaecd14871fb75ad34fb76c3e7</id>
<content type='text'>
on a SAN DNSname constraint. This is not correct, as with
a DNSname constraint, it may exacly match or match zero or
more additional components on the front of the candidte to
match.

Spotted by Haruto Kimura &lt;hkimura2026@gmail.com&gt;

ok tb@ kenjiro@
</content>
</entry>
<entry>
<title>Adjust depth check to match change in verifier.</title>
<updated>2026-04-01T14:39:11+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2026-04-01T14:39:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=89eb797db1e499a83313d47457a8fa9fe9272e8c'/>
<id>urn:sha1:89eb797db1e499a83313d47457a8fa9fe9272e8c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add additional X.509 verifier test cases.</title>
<updated>2026-03-31T13:39:48+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2026-03-31T13:39:48+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=848a8ff0f8b9bd889cd059b6040b85d5cd2cc980'/>
<id>urn:sha1:848a8ff0f8b9bd889cd059b6040b85d5cd2cc980</id>
<content type='text'>
The second case (14b) currently triggers a bug in the new verifier.
</content>
</entry>
<entry>
<title>rfc3779 regress: explain where the range comes from</title>
<updated>2026-03-13T06:47:34+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2026-03-13T06:47:34+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=7d892da013d87af304d51aa7b2f8d8e284b459ae'/>
<id>urn:sha1:7d892da013d87af304d51aa7b2f8d8e284b459ae</id>
<content type='text'>
</content>
</entry>
<entry>
<title>rfc3779 regress: add an actual range</title>
<updated>2026-03-13T06:40:56+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2026-03-13T06:40:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=f82cf34cdfda5cb110c15fef4f54ba94e1beb3a9'/>
<id>urn:sha1:f82cf34cdfda5cb110c15fef4f54ba94e1beb3a9</id>
<content type='text'>
This improves the test coverage of make_addressRange() where there is an
annoyance with unused bits in the RFC 3779 ASN.1 encoding versus trailing
ones in the network encoding that the X509v3_addr_add_range() API expects.
</content>
</entry>
<entry>
<title>policy test: parital -&gt; partial</title>
<updated>2026-01-22T10:15:53+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2026-01-22T10:15:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=05ece0fed5d8feb08352c44b1558f269488e96ca'/>
<id>urn:sha1:05ece0fed5d8feb08352c44b1558f269488e96ca</id>
<content type='text'>
</content>
</entry>
<entry>
<title>constaints -&gt; constraints</title>
<updated>2025-12-31T17:04:22+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2025-12-31T17:04:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=cf05aaf03232b61ed182ae5868d7f3863bc87921'/>
<id>urn:sha1:cf05aaf03232b61ed182ae5868d7f3863bc87921</id>
<content type='text'>
</content>
</entry>
<entry>
<title>regress/libcrypto/x509/bettertls: switch to eopenssl35</title>
<updated>2025-07-23T07:46:12+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2025-07-23T07:46:12+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=339127e5807b8c7377a338837d8ef5f0a2465548'/>
<id>urn:sha1:339127e5807b8c7377a338837d8ef5f0a2465548</id>
<content type='text'>
</content>
</entry>
<entry>
<title>merge the x509name test into x509_name_test.c</title>
<updated>2025-05-05T06:33:35+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2025-05-05T06:33:35+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=2a0f3895acaf23f878605da0faa4df7e3d62bbe3'/>
<id>urn:sha1:2a0f3895acaf23f878605da0faa4df7e3d62bbe3</id>
<content type='text'>
Remove the old x509name test and its Makefile rule. Its logic has
been fully integrated into x509_name_test.c using a new table-driven
approach. Each x509 name entry is added and validated step by step,
checking both the string representation produced by X509_NAME_print_ex()
and the internal RDN set structure.

This makes the test easier to extend and maintain, and eliminates the need
for an external .expected file or output diff.

From Kenjiro Nakayama (with tiny tweaks)
</content>
</entry>
<entry>
<title>Adjust x509_name_regress to the X509_NAME_print() fix in a_strex.c r1.38</title>
<updated>2025-03-19T11:19:17+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2025-03-19T11:19:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=c42edd4c666ac7c3fb91cc79e1ea50486f509a74'/>
<id>urn:sha1:c42edd4c666ac7c3fb91cc79e1ea50486f509a74</id>
<content type='text'>
</content>
</entry>
</feed>
