Skip to content

Commit bb9fe71

Browse files
hawkwdjc
authored andcommitted
Remove tests for common name handling
As suggested by @ctz in this comment: #167 (comment).
1 parent 0a8bd63 commit bb9fe71

2 files changed

Lines changed: 0 additions & 38 deletions

File tree

tests/generate.py

Lines changed: 0 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -312,13 +312,6 @@ def tls_server_certs(force: bool) -> None:
312312
permitted_subtrees=[x509.DNSName(".example.com")],
313313
)
314314

315-
generate_tls_server_cert_test(
316-
output,
317-
"disallow_subject_common_name",
318-
expected_error="NameConstraintViolation",
319-
subject_common_name="disallowed.example.com",
320-
excluded_subtrees=[x509.DNSName("disallowed.example.com")],
321-
)
322315
generate_tls_server_cert_test(
323316
output,
324317
"disallow_dns_san",
@@ -353,15 +346,6 @@ def tls_server_certs(force: bool) -> None:
353346
x509.DNSName("allowed-cn.example.com"),
354347
],
355348
)
356-
generate_tls_server_cert_test(
357-
output,
358-
"allow_dns_san_and_disallow_subject_common_name",
359-
expected_error="NameConstraintViolation",
360-
sans=[x509.DNSName("allowed-san.example.com")],
361-
subject_common_name="disallowed-cn.example.com",
362-
permitted_subtrees=[x509.DNSName("allowed-san.example.com")],
363-
excluded_subtrees=[x509.DNSName("disallowed-cn.example.com")],
364-
)
365349
generate_tls_server_cert_test(
366350
output,
367351
"disallow_dns_san_and_allow_subject_common_name",

tests/tls_server_certs.rs

Lines changed: 0 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -89,16 +89,6 @@ fn additional_dns_labels() {
8989
);
9090
}
9191

92-
#[test]
93-
fn disallow_subject_common_name() {
94-
let ee = include_bytes!("tls_server_certs/disallow_subject_common_name.ee.der");
95-
let ca = include_bytes!("tls_server_certs/disallow_subject_common_name.ca.der");
96-
assert_eq!(
97-
check_cert(ee, ca, &[], &[]),
98-
Err(webpki::Error::NameConstraintViolation)
99-
);
100-
}
101-
10292
#[test]
10393
fn disallow_dns_san() {
10494
let ee = include_bytes!("tls_server_certs/disallow_dns_san.ee.der");
@@ -138,18 +128,6 @@ fn allow_dns_san_and_subject_common_name() {
138128
);
139129
}
140130

141-
#[test]
142-
fn allow_dns_san_and_disallow_subject_common_name() {
143-
let ee =
144-
include_bytes!("tls_server_certs/allow_dns_san_and_disallow_subject_common_name.ee.der");
145-
let ca =
146-
include_bytes!("tls_server_certs/allow_dns_san_and_disallow_subject_common_name.ca.der");
147-
assert_eq!(
148-
check_cert(ee, ca, &[], &[]),
149-
Err(webpki::Error::NameConstraintViolation)
150-
);
151-
}
152-
153131
#[test]
154132
fn disallow_dns_san_and_allow_subject_common_name() {
155133
let ee =

0 commit comments

Comments
 (0)