tree aa78df3634e9a5dde18b7d5e59b7b75f497e1061
parent a3511b97c1065e79fb1ad5b6f90cd8cce34bd8bb
author Gilles Peskine <Gilles.Peskine@arm.com> 1598029774 +0200
committer Gilles Peskine <Gilles.Peskine@arm.com> 1598030151 +0200

Regenerate test client certificates with a PrintableString issuer

The test certificate used for clients in compat.sh, cert_sha256.crt,
had the issuer ON and CN encoded as UTF8String, but the corresponding
CA certificate test-ca_cat12.crt had them encoded as PrintableString.
The strings matched, which is sufficient according to RFC 5280 §7.1
and RFC 4518 §2.1. However, GnuTLS 3.4.10 requires the strings to have
the same encoding, so it did not accept that the certificate issued by
UTF8String "PolarSSL Test CA" was validly issued by the
PrintableString "PolarSSL Test CA" CA.

ebc1f40aa008f6a2ba42e7436e4596d8f780b612, merged via
https://github.com/ARMmbed/mbedtls/pull/1641 and released in Mbed TLS
2.14, updated these certificates.
4f928c0f374558ec352825061a399db7a37ca2fc merged, via
https://github.com/ARMmbed/mbedtls/pull/2418 fixed this in the 2.7 LTS
branch for the SHA-1 certificate which was used at the time. The
present commit applies the same fix for the SHA-256 certificate that
is now in use.

For uniformity, this commit regenerates all the cert_*.crt.

Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
