github.com/maenmax/kairep@v0.0.0-20210218001208-55bf3df36788/src/golang.org/x/crypto/ocsp/ocsp_test.go (about) 1 // Copyright 2013 The Go Authors. All rights reserved. 2 // Use of this source code is governed by a BSD-style 3 // license that can be found in the LICENSE file. 4 5 package ocsp 6 7 import ( 8 "bytes" 9 "crypto" 10 "crypto/sha1" 11 "crypto/x509" 12 "crypto/x509/pkix" 13 "encoding/asn1" 14 "encoding/hex" 15 "math/big" 16 "reflect" 17 "testing" 18 "time" 19 ) 20 21 func TestOCSPDecode(t *testing.T) { 22 responseBytes, _ := hex.DecodeString(ocspResponseHex) 23 resp, err := ParseResponse(responseBytes, nil) 24 if err != nil { 25 t.Error(err) 26 } 27 28 expected := Response{ 29 Status: Good, 30 SerialNumber: big.NewInt(0x1d0fa), 31 RevocationReason: Unspecified, 32 ThisUpdate: time.Date(2010, 7, 7, 15, 1, 5, 0, time.UTC), 33 NextUpdate: time.Date(2010, 7, 7, 18, 35, 17, 0, time.UTC), 34 } 35 36 if !reflect.DeepEqual(resp.ThisUpdate, expected.ThisUpdate) { 37 t.Errorf("resp.ThisUpdate: got %d, want %d", resp.ThisUpdate, expected.ThisUpdate) 38 } 39 40 if !reflect.DeepEqual(resp.NextUpdate, expected.NextUpdate) { 41 t.Errorf("resp.NextUpdate: got %d, want %d", resp.NextUpdate, expected.NextUpdate) 42 } 43 44 if resp.Status != expected.Status { 45 t.Errorf("resp.Status: got %d, want %d", resp.Status, expected.Status) 46 } 47 48 if resp.SerialNumber.Cmp(expected.SerialNumber) != 0 { 49 t.Errorf("resp.SerialNumber: got %x, want %x", resp.SerialNumber, expected.SerialNumber) 50 } 51 52 if resp.RevocationReason != expected.RevocationReason { 53 t.Errorf("resp.RevocationReason: got %d, want %d", resp.RevocationReason, expected.RevocationReason) 54 } 55 } 56 57 func TestOCSPDecodeWithoutCert(t *testing.T) { 58 responseBytes, _ := hex.DecodeString(ocspResponseWithoutCertHex) 59 _, err := ParseResponse(responseBytes, nil) 60 if err != nil { 61 t.Error(err) 62 } 63 } 64 65 func TestOCSPDecodeWithExtensions(t *testing.T) { 66 responseBytes, _ := hex.DecodeString(ocspResponseWithCriticalExtensionHex) 67 _, err := ParseResponse(responseBytes, nil) 68 if err == nil { 69 t.Error(err) 70 } 71 72 responseBytes, _ = hex.DecodeString(ocspResponseWithExtensionHex) 73 response, err := ParseResponse(responseBytes, nil) 74 if err != nil { 75 t.Fatal(err) 76 } 77 78 if len(response.Extensions) != 1 { 79 t.Errorf("len(response.Extensions): got %v, want %v", len(response.Extensions), 1) 80 } 81 82 extensionBytes := response.Extensions[0].Value 83 expectedBytes, _ := hex.DecodeString(ocspExtensionValueHex) 84 if !bytes.Equal(extensionBytes, expectedBytes) { 85 t.Errorf("response.Extensions[0]: got %x, want %x", extensionBytes, expectedBytes) 86 } 87 } 88 89 func TestOCSPSignature(t *testing.T) { 90 issuerCert, _ := hex.DecodeString(startComHex) 91 issuer, err := x509.ParseCertificate(issuerCert) 92 if err != nil { 93 t.Fatal(err) 94 } 95 96 response, _ := hex.DecodeString(ocspResponseHex) 97 if _, err := ParseResponse(response, issuer); err != nil { 98 t.Error(err) 99 } 100 } 101 102 func TestOCSPRequest(t *testing.T) { 103 leafCert, _ := hex.DecodeString(leafCertHex) 104 cert, err := x509.ParseCertificate(leafCert) 105 if err != nil { 106 t.Fatal(err) 107 } 108 109 issuerCert, _ := hex.DecodeString(issuerCertHex) 110 issuer, err := x509.ParseCertificate(issuerCert) 111 if err != nil { 112 t.Fatal(err) 113 } 114 115 request, err := CreateRequest(cert, issuer, nil) 116 if err != nil { 117 t.Fatal(err) 118 } 119 120 expectedBytes, _ := hex.DecodeString(ocspRequestHex) 121 if !bytes.Equal(request, expectedBytes) { 122 t.Errorf("request: got %x, wanted %x", request, expectedBytes) 123 } 124 125 decodedRequest, err := ParseRequest(expectedBytes) 126 if err != nil { 127 t.Fatal(err) 128 } 129 130 if decodedRequest.HashAlgorithm != crypto.SHA1 { 131 t.Errorf("request.HashAlgorithm: got %v, want %v", decodedRequest.HashAlgorithm, crypto.SHA1) 132 } 133 134 var publicKeyInfo struct { 135 Algorithm pkix.AlgorithmIdentifier 136 PublicKey asn1.BitString 137 } 138 _, err = asn1.Unmarshal(issuer.RawSubjectPublicKeyInfo, &publicKeyInfo) 139 if err != nil { 140 t.Fatal(err) 141 } 142 143 h := sha1.New() 144 h.Write(publicKeyInfo.PublicKey.RightAlign()) 145 issuerKeyHash := h.Sum(nil) 146 147 h.Reset() 148 h.Write(issuer.RawSubject) 149 issuerNameHash := h.Sum(nil) 150 151 if got := decodedRequest.IssuerKeyHash; !bytes.Equal(got, issuerKeyHash) { 152 t.Errorf("request.IssuerKeyHash: got %x, want %x", got, issuerKeyHash) 153 } 154 155 if got := decodedRequest.IssuerNameHash; !bytes.Equal(got, issuerNameHash) { 156 t.Errorf("request.IssuerKeyHash: got %x, want %x", got, issuerNameHash) 157 } 158 159 if got := decodedRequest.SerialNumber; got.Cmp(cert.SerialNumber) != 0 { 160 t.Errorf("request.SerialNumber: got %x, want %x", got, cert.SerialNumber) 161 } 162 } 163 164 func TestOCSPResponse(t *testing.T) { 165 leafCert, _ := hex.DecodeString(leafCertHex) 166 leaf, err := x509.ParseCertificate(leafCert) 167 if err != nil { 168 t.Fatal(err) 169 } 170 171 issuerCert, _ := hex.DecodeString(issuerCertHex) 172 issuer, err := x509.ParseCertificate(issuerCert) 173 if err != nil { 174 t.Fatal(err) 175 } 176 177 responderCert, _ := hex.DecodeString(responderCertHex) 178 responder, err := x509.ParseCertificate(responderCert) 179 if err != nil { 180 t.Fatal(err) 181 } 182 183 responderPrivateKeyDER, _ := hex.DecodeString(responderPrivateKeyHex) 184 responderPrivateKey, err := x509.ParsePKCS1PrivateKey(responderPrivateKeyDER) 185 if err != nil { 186 t.Fatal(err) 187 } 188 189 extensionBytes, _ := hex.DecodeString(ocspExtensionValueHex) 190 extensions := []pkix.Extension{ 191 pkix.Extension{ 192 Id: ocspExtensionOID, 193 Critical: false, 194 Value: extensionBytes, 195 }, 196 } 197 198 producedAt := time.Now().Truncate(time.Minute) 199 thisUpdate := time.Date(2010, 7, 7, 15, 1, 5, 0, time.UTC) 200 nextUpdate := time.Date(2010, 7, 7, 18, 35, 17, 0, time.UTC) 201 template := Response{ 202 Status: Revoked, 203 SerialNumber: leaf.SerialNumber, 204 ThisUpdate: thisUpdate, 205 NextUpdate: nextUpdate, 206 RevokedAt: thisUpdate, 207 RevocationReason: KeyCompromise, 208 Certificate: responder, 209 ExtraExtensions: extensions, 210 } 211 212 responseBytes, err := CreateResponse(issuer, responder, template, responderPrivateKey) 213 if err != nil { 214 t.Fatal(err) 215 } 216 217 resp, err := ParseResponse(responseBytes, nil) 218 if err != nil { 219 t.Fatal(err) 220 } 221 222 if !reflect.DeepEqual(resp.ThisUpdate, template.ThisUpdate) { 223 t.Errorf("resp.ThisUpdate: got %d, want %d", resp.ThisUpdate, template.ThisUpdate) 224 } 225 226 if !reflect.DeepEqual(resp.NextUpdate, template.NextUpdate) { 227 t.Errorf("resp.NextUpdate: got %d, want %d", resp.NextUpdate, template.NextUpdate) 228 } 229 230 if !reflect.DeepEqual(resp.RevokedAt, template.RevokedAt) { 231 t.Errorf("resp.RevokedAt: got %d, want %d", resp.RevokedAt, template.RevokedAt) 232 } 233 234 if !reflect.DeepEqual(resp.Extensions, template.ExtraExtensions) { 235 t.Errorf("resp.Extensions: got %v, want %v", resp.Extensions, template.ExtraExtensions) 236 } 237 238 if !resp.ProducedAt.Equal(producedAt) { 239 t.Errorf("resp.ProducedAt: got %d, want %d", resp.ProducedAt, producedAt) 240 } 241 242 if resp.Status != template.Status { 243 t.Errorf("resp.Status: got %d, want %d", resp.Status, template.Status) 244 } 245 246 if resp.SerialNumber.Cmp(template.SerialNumber) != 0 { 247 t.Errorf("resp.SerialNumber: got %x, want %x", resp.SerialNumber, template.SerialNumber) 248 } 249 250 if resp.RevocationReason != template.RevocationReason { 251 t.Errorf("resp.RevocationReason: got %d, want %d", resp.RevocationReason, template.RevocationReason) 252 } 253 } 254 255 func TestErrorResponse(t *testing.T) { 256 responseBytes, _ := hex.DecodeString(errorResponseHex) 257 _, err := ParseResponse(responseBytes, nil) 258 259 respErr, ok := err.(ResponseError) 260 if !ok { 261 t.Fatalf("expected ResponseError from ParseResponse but got %#v", err) 262 } 263 if respErr.Status != Malformed { 264 t.Fatalf("expected Malformed status from ParseResponse but got %d", respErr.Status) 265 } 266 } 267 268 // This OCSP response was taken from Thawte's public OCSP responder. 269 // To recreate: 270 // $ openssl s_client -tls1 -showcerts -servername www.google.com -connect www.google.com:443 271 // Copy and paste the first certificate into /tmp/cert.crt and the second into 272 // /tmp/intermediate.crt 273 // $ openssl ocsp -issuer /tmp/intermediate.crt -cert /tmp/cert.crt -url http://ocsp.thawte.com -resp_text -respout /tmp/ocsp.der 274 // Then hex encode the result: 275 // $ python -c 'print file("/tmp/ocsp.der", "r").read().encode("hex")' 276 277 const ocspResponseHex = "308206bc0a0100a08206b5308206b106092b0601050507300101048206a23082069e3081" + 278 "c9a14e304c310b300906035504061302494c31163014060355040a130d5374617274436f" + 279 "6d204c74642e312530230603550403131c5374617274436f6d20436c6173732031204f43" + 280 "5350205369676e6572180f32303130303730373137333531375a30663064303c30090605" + 281 "2b0e03021a050004146568874f40750f016a3475625e1f5c93e5a26d580414eb4234d098" + 282 "b0ab9ff41b6b08f7cc642eef0e2c45020301d0fa8000180f323031303037303731353031" + 283 "30355aa011180f32303130303730373138333531375a300d06092a864886f70d01010505" + 284 "000382010100ab557ff070d1d7cebbb5f0ec91a15c3fed22eb2e1b8244f1b84545f013a4" + 285 "fb46214c5e3fbfbebb8a56acc2b9db19f68fd3c3201046b3824d5ba689f99864328710cb" + 286 "467195eb37d84f539e49f859316b32964dc3e47e36814ce94d6c56dd02733b1d0802f7ff" + 287 "4eebdbbd2927dcf580f16cbc290f91e81b53cb365e7223f1d6e20a88ea064104875e0145" + 288 "672b20fc14829d51ca122f5f5d77d3ad6c83889c55c7dc43680ba2fe3cef8b05dbcabdc0" + 289 "d3e09aaf9725597f8c858c2fa38c0d6aed2e6318194420dd1a1137445d13e1c97ab47896" + 290 "17a4e08925f46f867b72e3a4dc1f08cb870b2b0717f7207faa0ac512e628a029aba7457a" + 291 "e63dcf3281e2162d9349a08204ba308204b6308204b23082039aa003020102020101300d" + 292 "06092a864886f70d010105050030818c310b300906035504061302494c31163014060355" + 293 "040a130d5374617274436f6d204c74642e312b3029060355040b13225365637572652044" + 294 "69676974616c204365727469666963617465205369676e696e6731383036060355040313" + 295 "2f5374617274436f6d20436c6173732031205072696d61727920496e7465726d65646961" + 296 "746520536572766572204341301e170d3037313032353030323330365a170d3132313032" + 297 "333030323330365a304c310b300906035504061302494c31163014060355040a130d5374" + 298 "617274436f6d204c74642e312530230603550403131c5374617274436f6d20436c617373" + 299 "2031204f435350205369676e657230820122300d06092a864886f70d0101010500038201" + 300 "0f003082010a0282010100b9561b4c45318717178084e96e178df2255e18ed8d8ecc7c2b" + 301 "7b51a6c1c2e6bf0aa3603066f132fe10ae97b50e99fa24b83fc53dd2777496387d14e1c3" + 302 "a9b6a4933e2ac12413d085570a95b8147414a0bc007c7bcf222446ef7f1a156d7ea1c577" + 303 "fc5f0facdfd42eb0f5974990cb2f5cefebceef4d1bdc7ae5c1075c5a99a93171f2b0845b" + 304 "4ff0864e973fcfe32f9d7511ff87a3e943410c90a4493a306b6944359340a9ca96f02b66" + 305 "ce67f028df2980a6aaee8d5d5d452b8b0eb93f923cc1e23fcccbdbe7ffcb114d08fa7a6a" + 306 "3c404f825d1a0e715935cf623a8c7b59670014ed0622f6089a9447a7a19010f7fe58f841" + 307 "29a2765ea367824d1c3bb2fda308530203010001a382015c30820158300c0603551d1301" + 308 "01ff04023000300b0603551d0f0404030203a8301e0603551d250417301506082b060105" + 309 "0507030906092b0601050507300105301d0603551d0e0416041445e0a36695414c5dd449" + 310 "bc00e33cdcdbd2343e173081a80603551d230481a030819d8014eb4234d098b0ab9ff41b" + 311 "6b08f7cc642eef0e2c45a18181a47f307d310b300906035504061302494c311630140603" + 312 "55040a130d5374617274436f6d204c74642e312b3029060355040b132253656375726520" + 313 "4469676974616c204365727469666963617465205369676e696e67312930270603550403" + 314 "13205374617274436f6d2043657274696669636174696f6e20417574686f726974798201" + 315 "0a30230603551d12041c301a8618687474703a2f2f7777772e737461727473736c2e636f" + 316 "6d2f302c06096086480186f842010d041f161d5374617274436f6d205265766f63617469" + 317 "6f6e20417574686f72697479300d06092a864886f70d01010505000382010100182d2215" + 318 "8f0fc0291324fa8574c49bb8ff2835085adcbf7b7fc4191c397ab6951328253fffe1e5ec" + 319 "2a7da0d50fca1a404e6968481366939e666c0a6209073eca57973e2fefa9ed1718e8176f" + 320 "1d85527ff522c08db702e3b2b180f1cbff05d98128252cf0f450f7dd2772f4188047f19d" + 321 "c85317366f94bc52d60f453a550af58e308aaab00ced33040b62bf37f5b1ab2a4f7f0f80" + 322 "f763bf4d707bc8841d7ad9385ee2a4244469260b6f2bf085977af9074796048ecc2f9d48" + 323 "a1d24ce16e41a9941568fec5b42771e118f16c106a54ccc339a4b02166445a167902e75e" + 324 "6d8620b0825dcd18a069b90fd851d10fa8effd409deec02860d26d8d833f304b10669b42" 325 326 const startComHex = "308206343082041ca003020102020118300d06092a864886f70d0101050500307d310b30" + 327 "0906035504061302494c31163014060355040a130d5374617274436f6d204c74642e312b" + 328 "3029060355040b1322536563757265204469676974616c20436572746966696361746520" + 329 "5369676e696e6731293027060355040313205374617274436f6d20436572746966696361" + 330 "74696f6e20417574686f72697479301e170d3037313032343230353431375a170d313731" + 331 "3032343230353431375a30818c310b300906035504061302494c31163014060355040a13" + 332 "0d5374617274436f6d204c74642e312b3029060355040b13225365637572652044696769" + 333 "74616c204365727469666963617465205369676e696e67313830360603550403132f5374" + 334 "617274436f6d20436c6173732031205072696d61727920496e7465726d65646961746520" + 335 "53657276657220434130820122300d06092a864886f70d01010105000382010f00308201" + 336 "0a0282010100b689c6acef09527807ac9263d0f44418188480561f91aee187fa3250b4d3" + 337 "4706f0e6075f700e10f71dc0ce103634855a0f92ac83c6ac58523fba38e8fce7a724e240" + 338 "a60876c0926e9e2a6d4d3f6e61200adb59ded27d63b33e46fefa215118d7cd30a6ed076e" + 339 "3b7087b4f9faebee823c056f92f7a4dc0a301e9373fe07cad75f809d225852ae06da8b87" + 340 "2369b0e42ad8ea83d2bdf371db705a280faf5a387045123f304dcd3baf17e50fcba0a95d" + 341 "48aab16150cb34cd3c5cc30be810c08c9bf0030362feb26c3e720eee1c432ac9480e5739" + 342 "c43121c810c12c87fe5495521f523c31129b7fe7c0a0a559d5e28f3ef0d5a8e1d77031a9" + 343 "c4b3cfaf6d532f06f4a70203010001a38201ad308201a9300f0603551d130101ff040530" + 344 "030101ff300e0603551d0f0101ff040403020106301d0603551d0e04160414eb4234d098" + 345 "b0ab9ff41b6b08f7cc642eef0e2c45301f0603551d230418301680144e0bef1aa4405ba5" + 346 "17698730ca346843d041aef2306606082b06010505070101045a3058302706082b060105" + 347 "05073001861b687474703a2f2f6f6373702e737461727473736c2e636f6d2f6361302d06" + 348 "082b060105050730028621687474703a2f2f7777772e737461727473736c2e636f6d2f73" + 349 "667363612e637274305b0603551d1f045430523027a025a0238621687474703a2f2f7777" + 350 "772e737461727473736c2e636f6d2f73667363612e63726c3027a025a023862168747470" + 351 "3a2f2f63726c2e737461727473736c2e636f6d2f73667363612e63726c3081800603551d" + 352 "20047930773075060b2b0601040181b5370102013066302e06082b060105050702011622" + 353 "687474703a2f2f7777772e737461727473736c2e636f6d2f706f6c6963792e7064663034" + 354 "06082b060105050702011628687474703a2f2f7777772e737461727473736c2e636f6d2f" + 355 "696e7465726d6564696174652e706466300d06092a864886f70d01010505000382020100" + 356 "2109493ea5886ee00b8b48da314d8ff75657a2e1d36257e9b556f38545753be5501f048b" + 357 "e6a05a3ee700ae85d0fbff200364cbad02e1c69172f8a34dd6dee8cc3fa18aa2e37c37a7" + 358 "c64f8f35d6f4d66e067bdd21d9cf56ffcb302249fe8904f385e5aaf1e71fe875904dddf9" + 359 "46f74234f745580c110d84b0c6da5d3ef9019ee7e1da5595be741c7bfc4d144fac7e5547" + 360 "7d7bf4a50d491e95e8f712c1ccff76a62547d0f37535be97b75816ebaa5c786fec5330af" + 361 "ea044dcca902e3f0b60412f630b1113d904e5664d7dc3c435f7339ef4baf87ebf6fe6888" + 362 "4472ead207c669b0c1a18bef1749d761b145485f3b2021e95bb2ccf4d7e931f50b15613b" + 363 "7a94e3ebd9bc7f94ae6ae3626296a8647cb887f399327e92a252bebbf865cfc9f230fc8b" + 364 "c1c2a696d75f89e15c3480f58f47072fb491bfb1a27e5f4b5ad05b9f248605515a690365" + 365 "434971c5e06f94346bf61bd8a9b04c7e53eb8f48dfca33b548fa364a1a53a6330cd089cd" + 366 "4915cd89313c90c072d7654b52358a461144b93d8e2865a63e799e5c084429adb035112e" + 367 "214eb8d2e7103e5d8483b3c3c2e4d2c6fd094b7409ddf1b3d3193e800da20b19f038e7c5" + 368 "c2afe223db61e29d5c6e2089492e236ab262c145b49faf8ba7f1223bf87de290d07a19fb" + 369 "4a4ce3d27d5f4a8303ed27d6239e6b8db459a2d9ef6c8229dd75193c3f4c108defbb7527" + 370 "d2ae83a7a8ce5ba7" 371 372 const ocspResponseWithoutCertHex = "308201d40a0100a08201cd308201c906092b0601050507300101048201ba3082" + 373 "01b630819fa2160414884451ff502a695e2d88f421bad90cf2cecbea7c180f3230313330" + 374 "3631383037323434335a30743072304a300906052b0e03021a0500041448b60d38238df8" + 375 "456e4ee5843ea394111802979f0414884451ff502a695e2d88f421bad90cf2cecbea7c02" + 376 "1100f78b13b946fc9635d8ab49de9d2148218000180f3230313330363138303732343433" + 377 "5aa011180f32303133303632323037323434335a300d06092a864886f70d010105050003" + 378 "82010100103e18b3d297a5e7a6c07a4fc52ac46a15c0eba96f3be17f0ffe84de5b8c8e05" + 379 "5a8f577586a849dc4abd6440eb6fedde4622451e2823c1cbf3558b4e8184959c9fe96eff" + 380 "8bc5f95866c58c6d087519faabfdae37e11d9874f1bc0db292208f645dd848185e4dd38b" + 381 "6a8547dfa7b74d514a8470015719064d35476b95bebb03d4d2845c5ca15202d2784878f2" + 382 "0f904c24f09736f044609e9c271381713400e563023d212db422236440c6f377bbf24b2b" + 383 "9e7dec8698e36a8df68b7592ad3489fb2937afb90eb85d2aa96b81c94c25057dbd4759d9" + 384 "20a1a65c7f0b6427a224b3c98edd96b9b61f706099951188b0289555ad30a216fb774651" + 385 "5a35fca2e054dfa8" 386 387 // PKIX nonce extension 388 var ocspExtensionOID = asn1.ObjectIdentifier{1, 3, 6, 1, 5, 5, 7, 48, 1, 2} 389 var ocspExtensionValueHex = "0403000000" 390 391 const ocspResponseWithCriticalExtensionHex = "308204fe0a0100a08204f7308204f306092b0601050507300101048204e4308204e03081" + 392 "dba003020100a11b3019311730150603550403130e4f43535020526573706f6e64657218" + 393 "0f32303136303130343137303130305a3081a53081a23049300906052b0e03021a050004" + 394 "14c0fe0278fc99188891b3f212e9c7e1b21ab7bfc004140dfc1df0a9e0f01ce7f2b21317" + 395 "7e6f8d157cd4f60210017f77deb3bcbb235d44ccc7dba62e72a116180f32303130303730" + 396 "373135303130355aa0030a0101180f32303130303730373135303130355aa011180f3230" + 397 "3130303730373138333531375aa1193017301506092b06010505073001020101ff040504" + 398 "03000000300d06092a864886f70d01010b0500038201010031c730ca60a7a0d92d8e4010" + 399 "911b469de95b4d27e89de6537552436237967694f76f701cf6b45c932bd308bca4a8d092" + 400 "5c604ba94796903091d9e6c000178e72c1f0a24a277dd262835af5d17d3f9d7869606c9f" + 401 "e7c8e708a41645699895beee38bfa63bb46296683761c5d1d65439b8ab868dc3017c9eeb" + 402 "b70b82dbf3a31c55b457d48bb9e82b335ed49f445042eaf606b06a3e0639824924c89c63" + 403 "eccddfe85e6694314138b2536f5e15e07085d0f6e26d4b2f8244bab0d70de07283ac6384" + 404 "a0501fc3dea7cf0adfd4c7f34871080900e252ddc403e3f0265f2a704af905d3727504ed" + 405 "28f3214a219d898a022463c78439799ca81c8cbafdbcec34ea937cd6a08202ea308202e6" + 406 "308202e2308201caa003020102020101300d06092a864886f70d01010b05003019311730" + 407 "150603550403130e4f43535020526573706f6e646572301e170d31353031333031353530" + 408 "33335a170d3136303133303135353033335a3019311730150603550403130e4f43535020" + 409 "526573706f6e64657230820122300d06092a864886f70d01010105000382010f00308201" + 410 "0a0282010100e8155f2d3e6f2e8d14c62a788bd462f9f844e7a6977c83ef1099f0f6616e" + 411 "c5265b56f356e62c5400f0b06a2e7945a82752c636df32a895152d6074df1701dc6ccfbc" + 412 "bec75a70bd2b55ae2be7e6cad3b5fd4cd5b7790ab401a436d3f5f346074ffde8a99d5b72" + 413 "3350f0a112076614b12ef79c78991b119453445acf2416ab0046b540db14c9fc0f27b898" + 414 "9ad0f63aa4b8aefc91aa8a72160c36307c60fec78a93d3fddf4259902aa77e7332971c7d" + 415 "285b6a04f648993c6922a3e9da9adf5f81508c3228791843e5d49f24db2f1290bafd97e6" + 416 "55b1049a199f652cd603c4fafa330c390b0da78fbbc67e8fa021cbd74eb96222b12ace31" + 417 "a77dcf920334dc94581b0203010001a3353033300e0603551d0f0101ff04040302078030" + 418 "130603551d25040c300a06082b06010505070309300c0603551d130101ff04023000300d" + 419 "06092a864886f70d01010b05000382010100718012761b5063e18f0dc44644d8e6ab8612" + 420 "31c15fd5357805425d82aec1de85bf6d3e30fce205e3e3b8b795bbe52e40a439286d2288" + 421 "9064f4aeeb150359b9425f1da51b3a5c939018555d13ac42c565a0603786a919328f3267" + 422 "09dce52c22ad958ecb7873b9771d1148b1c4be2efe80ba868919fc9f68b6090c2f33c156" + 423 "d67156e42766a50b5d51e79637b7e58af74c2a951b1e642fa7741fec982cc937de37eff5" + 424 "9e2005d5939bfc031589ca143e6e8ab83f40ee08cc20a6b4a95a318352c28d18528dcaf9" + 425 "66705de17afa19d6e8ae91ddf33179d16ebb6ac2c69cae8373d408ebf8c55308be6c04d9" + 426 "3a25439a94299a65a709756c7a3e568be049d5c38839" 427 428 const ocspResponseWithExtensionHex = "308204fb0a0100a08204f4308204f006092b0601050507300101048204e1308204dd3081" + 429 "d8a003020100a11b3019311730150603550403130e4f43535020526573706f6e64657218" + 430 "0f32303136303130343136353930305a3081a230819f3049300906052b0e03021a050004" + 431 "14c0fe0278fc99188891b3f212e9c7e1b21ab7bfc004140dfc1df0a9e0f01ce7f2b21317" + 432 "7e6f8d157cd4f60210017f77deb3bcbb235d44ccc7dba62e72a116180f32303130303730" + 433 "373135303130355aa0030a0101180f32303130303730373135303130355aa011180f3230" + 434 "3130303730373138333531375aa1163014301206092b0601050507300102040504030000" + 435 "00300d06092a864886f70d01010b05000382010100c09a33e0b2324c852421bb83f85ac9" + 436 "9113f5426012bd2d2279a8166e9241d18a33c870894250622ffc7ed0c4601b16d624f90b" + 437 "779265442cdb6868cf40ab304ab4b66e7315ed02cf663b1601d1d4751772b31bc299db23" + 438 "9aebac78ed6797c06ed815a7a8d18d63cfbb609cafb47ec2e89e37db255216eb09307848" + 439 "d01be0a3e943653c78212b96ff524b74c9ec456b17cdfb950cc97645c577b2e09ff41dde" + 440 "b03afb3adaa381cc0f7c1d95663ef22a0f72f2c45613ae8e2b2d1efc96e8463c7d1d8a1d" + 441 "7e3b35df8fe73a301fc3f804b942b2b3afa337ff105fc1462b7b1c1d75eb4566c8665e59" + 442 "f80393b0adbf8004ff6c3327ed34f007cb4a3348a7d55e06e3a08202ea308202e6308202" + 443 "e2308201caa003020102020101300d06092a864886f70d01010b05003019311730150603" + 444 "550403130e4f43535020526573706f6e646572301e170d3135303133303135353033335a" + 445 "170d3136303133303135353033335a3019311730150603550403130e4f43535020526573" + 446 "706f6e64657230820122300d06092a864886f70d01010105000382010f003082010a0282" + 447 "010100e8155f2d3e6f2e8d14c62a788bd462f9f844e7a6977c83ef1099f0f6616ec5265b" + 448 "56f356e62c5400f0b06a2e7945a82752c636df32a895152d6074df1701dc6ccfbcbec75a" + 449 "70bd2b55ae2be7e6cad3b5fd4cd5b7790ab401a436d3f5f346074ffde8a99d5b723350f0" + 450 "a112076614b12ef79c78991b119453445acf2416ab0046b540db14c9fc0f27b8989ad0f6" + 451 "3aa4b8aefc91aa8a72160c36307c60fec78a93d3fddf4259902aa77e7332971c7d285b6a" + 452 "04f648993c6922a3e9da9adf5f81508c3228791843e5d49f24db2f1290bafd97e655b104" + 453 "9a199f652cd603c4fafa330c390b0da78fbbc67e8fa021cbd74eb96222b12ace31a77dcf" + 454 "920334dc94581b0203010001a3353033300e0603551d0f0101ff04040302078030130603" + 455 "551d25040c300a06082b06010505070309300c0603551d130101ff04023000300d06092a" + 456 "864886f70d01010b05000382010100718012761b5063e18f0dc44644d8e6ab861231c15f" + 457 "d5357805425d82aec1de85bf6d3e30fce205e3e3b8b795bbe52e40a439286d22889064f4" + 458 "aeeb150359b9425f1da51b3a5c939018555d13ac42c565a0603786a919328f326709dce5" + 459 "2c22ad958ecb7873b9771d1148b1c4be2efe80ba868919fc9f68b6090c2f33c156d67156" + 460 "e42766a50b5d51e79637b7e58af74c2a951b1e642fa7741fec982cc937de37eff59e2005" + 461 "d5939bfc031589ca143e6e8ab83f40ee08cc20a6b4a95a318352c28d18528dcaf966705d" + 462 "e17afa19d6e8ae91ddf33179d16ebb6ac2c69cae8373d408ebf8c55308be6c04d93a2543" + 463 "9a94299a65a709756c7a3e568be049d5c38839" 464 465 const ocspRequestHex = "3051304f304d304b3049300906052b0e03021a05000414c0fe0278fc99188891b3f212e9" + 466 "c7e1b21ab7bfc004140dfc1df0a9e0f01ce7f2b213177e6f8d157cd4f60210017f77deb3" + 467 "bcbb235d44ccc7dba62e72" 468 469 const leafCertHex = "308203c830820331a0030201020210017f77deb3bcbb235d44ccc7dba62e72300d06092a" + 470 "864886f70d01010505003081ba311f301d060355040a1316566572695369676e20547275" + 471 "7374204e6574776f726b31173015060355040b130e566572695369676e2c20496e632e31" + 472 "333031060355040b132a566572695369676e20496e7465726e6174696f6e616c20536572" + 473 "766572204341202d20436c617373203331493047060355040b13407777772e7665726973" + 474 "69676e2e636f6d2f43505320496e636f72702e6279205265662e204c494142494c495459" + 475 "204c54442e286329393720566572695369676e301e170d3132303632313030303030305a" + 476 "170d3133313233313233353935395a3068310b3009060355040613025553311330110603" + 477 "550408130a43616c69666f726e6961311230100603550407130950616c6f20416c746f31" + 478 "173015060355040a130e46616365626f6f6b2c20496e632e311730150603550403140e2a" + 479 "2e66616365626f6f6b2e636f6d30819f300d06092a864886f70d010101050003818d0030" + 480 "818902818100ae94b171e2deccc1693e051063240102e0689ae83c39b6b3e74b97d48d7b" + 481 "23689100b0b496ee62f0e6d356bcf4aa0f50643402f5d1766aa972835a7564723f39bbef" + 482 "5290ded9bcdbf9d3d55dfad23aa03dc604c54d29cf1d4b3bdbd1a809cfae47b44c7eae17" + 483 "c5109bee24a9cf4a8d911bb0fd0415ae4c3f430aa12a557e2ae10203010001a382011e30" + 484 "82011a30090603551d130402300030440603551d20043d303b3039060b6086480186f845" + 485 "01071703302a302806082b06010505070201161c68747470733a2f2f7777772e76657269" + 486 "7369676e2e636f6d2f727061303c0603551d1f043530333031a02fa02d862b687474703a" + 487 "2f2f535652496e746c2d63726c2e766572697369676e2e636f6d2f535652496e746c2e63" + 488 "726c301d0603551d250416301406082b0601050507030106082b06010505070302300b06" + 489 "03551d0f0404030205a0303406082b0601050507010104283026302406082b0601050507" + 490 "30018618687474703a2f2f6f6373702e766572697369676e2e636f6d30270603551d1104" + 491 "20301e820e2a2e66616365626f6f6b2e636f6d820c66616365626f6f6b2e636f6d300d06" + 492 "092a864886f70d0101050500038181005b6c2b75f8ed30aa51aad36aba595e555141951f" + 493 "81a53b447910ac1f76ff78fc2781616b58f3122afc1c87010425e9ed43df1a7ba6498060" + 494 "67e2688af03db58c7df4ee03309a6afc247ccb134dc33e54c6bc1d5133a532a73273b1d7" + 495 "9cadc08e7e1a83116d34523340b0305427a21742827c98916698ee7eaf8c3bdd71700817" 496 497 const issuerCertHex = "30820383308202eca003020102021046fcebbab4d02f0f926098233f93078f300d06092a" + 498 "864886f70d0101050500305f310b300906035504061302555331173015060355040a130e" + 499 "566572695369676e2c20496e632e31373035060355040b132e436c617373203320507562" + 500 "6c6963205072696d6172792043657274696669636174696f6e20417574686f7269747930" + 501 "1e170d3937303431373030303030305a170d3136313032343233353935395a3081ba311f" + 502 "301d060355040a1316566572695369676e205472757374204e6574776f726b3117301506" + 503 "0355040b130e566572695369676e2c20496e632e31333031060355040b132a5665726953" + 504 "69676e20496e7465726e6174696f6e616c20536572766572204341202d20436c61737320" + 505 "3331493047060355040b13407777772e766572697369676e2e636f6d2f43505320496e63" + 506 "6f72702e6279205265662e204c494142494c495459204c54442e28632939372056657269" + 507 "5369676e30819f300d06092a864886f70d010101050003818d0030818902818100d88280" + 508 "e8d619027d1f85183925a2652be1bfd405d3bce6363baaf04c6c5bb6e7aa3c734555b2f1" + 509 "bdea9742ed9a340a15d4a95cf54025ddd907c132b2756cc4cabba3fe56277143aa63f530" + 510 "3e9328e5faf1093bf3b74d4e39f75c495ab8c11dd3b28afe70309542cbfe2b518b5a3c3a" + 511 "f9224f90b202a7539c4f34e7ab04b27b6f0203010001a381e33081e0300f0603551d1304" + 512 "0830060101ff02010030440603551d20043d303b3039060b6086480186f8450107010130" + 513 "2a302806082b06010505070201161c68747470733a2f2f7777772e766572697369676e2e" + 514 "636f6d2f43505330340603551d25042d302b06082b0601050507030106082b0601050507" + 515 "030206096086480186f8420401060a6086480186f845010801300b0603551d0f04040302" + 516 "0106301106096086480186f842010104040302010630310603551d1f042a30283026a024" + 517 "a0228620687474703a2f2f63726c2e766572697369676e2e636f6d2f706361332e63726c" + 518 "300d06092a864886f70d010105050003818100408e4997968a73dd8e4def3e61b7caa062" + 519 "adf40e0abb753de26ed82cc7bff4b98c369bcaa2d09c724639f6a682036511c4bcbf2da6" + 520 "f5d93b0ab598fab378b91ef22b4c62d5fdb27a1ddf33fd73f9a5d82d8c2aead1fcb028b6" + 521 "e94948134b838a1b487b24f738de6f4154b8ab576b06dfc7a2d4a9f6f136628088f28b75" + 522 "d68071" 523 524 // Key and certificate for the OCSP responder were not taken from the Thawte 525 // responder, since CreateResponse requires that we have the private key. 526 // Instead, they were generated randomly. 527 const responderPrivateKeyHex = "308204a40201000282010100e8155f2d3e6f2e8d14c62a788bd462f9f844e7a6977c83ef" + 528 "1099f0f6616ec5265b56f356e62c5400f0b06a2e7945a82752c636df32a895152d6074df" + 529 "1701dc6ccfbcbec75a70bd2b55ae2be7e6cad3b5fd4cd5b7790ab401a436d3f5f346074f" + 530 "fde8a99d5b723350f0a112076614b12ef79c78991b119453445acf2416ab0046b540db14" + 531 "c9fc0f27b8989ad0f63aa4b8aefc91aa8a72160c36307c60fec78a93d3fddf4259902aa7" + 532 "7e7332971c7d285b6a04f648993c6922a3e9da9adf5f81508c3228791843e5d49f24db2f" + 533 "1290bafd97e655b1049a199f652cd603c4fafa330c390b0da78fbbc67e8fa021cbd74eb9" + 534 "6222b12ace31a77dcf920334dc94581b02030100010282010100bcf0b93d7238bda329a8" + 535 "72e7149f61bcb37c154330ccb3f42a85c9002c2e2bdea039d77d8581cd19bed94078794e" + 536 "56293d601547fc4bf6a2f9002fe5772b92b21b254403b403585e3130cc99ccf08f0ef81a" + 537 "575b38f597ba4660448b54f44bfbb97072b5a2bf043bfeca828cf7741d13698e3f38162b" + 538 "679faa646b82abd9a72c5c7d722c5fc577a76d2c2daac588accad18516d1bbad10b0dfa2" + 539 "05cfe246b59e28608a43942e1b71b0c80498075121de5b900d727c31c42c78cf1db5c0aa" + 540 "5b491e10ea4ed5c0962aaf2ae025dd81fa4ce490d9d6b4a4465411d8e542fc88617e5695" + 541 "1aa4fc8ea166f2b4d0eb89ef17f2b206bd5f1014bf8fe0e71fe62f2cccf102818100f2dc" + 542 "ddf878d553286daad68bac4070a82ffec3dc4666a2750f47879eec913f91836f1d976b60" + 543 "daf9356e078446dafab5bd2e489e5d64f8572ba24a4ba4f3729b5e106c4dd831cc2497a7" + 544 "e6c7507df05cb64aeb1bbc81c1e340d58b5964cf39cff84ea30c29ec5d3f005ee1362698" + 545 "07395037955955655292c3e85f6187fa1f9502818100f4a33c102630840705f8c778a47b" + 546 "87e8da31e68809af981ac5e5999cf1551685d761cdf0d6520361b99aebd5777a940fa64d" + 547 "327c09fa63746fbb3247ec73a86edf115f1fe5c83598db803881ade71c33c6e956118345" + 548 "497b98b5e07bb5be75971465ec78f2f9467e1b74956ca9d4c7c3e314e742a72d8b33889c" + 549 "6c093a466cef0281801d3df0d02124766dd0be98349b19eb36a508c4e679e793ba0a8bef" + 550 "4d786888c1e9947078b1ea28938716677b4ad8c5052af12eb73ac194915264a913709a0b" + 551 "7b9f98d4a18edd781a13d49899f91c20dbd8eb2e61d991ba19b5cdc08893f5cb9d39e5a6" + 552 "0629ea16d426244673b1b3ee72bd30e41fac8395acac40077403de5efd028180050731dd" + 553 "d71b1a2b96c8d538ba90bb6b62c8b1c74c03aae9a9f59d21a7a82b0d572ef06fa9c807bf" + 554 "c373d6b30d809c7871df96510c577421d9860c7383fda0919ece19996b3ca13562159193" + 555 "c0c246471e287f975e8e57034e5136aaf44254e2650def3d51292474c515b1588969112e" + 556 "0a85cc77073e9d64d2c2fc497844284b02818100d71d63eabf416cf677401ebf965f8314" + 557 "120b568a57dd3bd9116c629c40dc0c6948bab3a13cc544c31c7da40e76132ef5dd3f7534" + 558 "45a635930c74326ae3df0edd1bfb1523e3aa259873ac7cf1ac31151ec8f37b528c275622" + 559 "48f99b8bed59fd4da2576aa6ee20d93a684900bf907e80c66d6e2261ae15e55284b4ed9d" + 560 "6bdaa059" 561 562 const responderCertHex = "308202e2308201caa003020102020101300d06092a864886f70d01010b05003019311730" + 563 "150603550403130e4f43535020526573706f6e646572301e170d31353031333031353530" + 564 "33335a170d3136303133303135353033335a3019311730150603550403130e4f43535020" + 565 "526573706f6e64657230820122300d06092a864886f70d01010105000382010f00308201" + 566 "0a0282010100e8155f2d3e6f2e8d14c62a788bd462f9f844e7a6977c83ef1099f0f6616e" + 567 "c5265b56f356e62c5400f0b06a2e7945a82752c636df32a895152d6074df1701dc6ccfbc" + 568 "bec75a70bd2b55ae2be7e6cad3b5fd4cd5b7790ab401a436d3f5f346074ffde8a99d5b72" + 569 "3350f0a112076614b12ef79c78991b119453445acf2416ab0046b540db14c9fc0f27b898" + 570 "9ad0f63aa4b8aefc91aa8a72160c36307c60fec78a93d3fddf4259902aa77e7332971c7d" + 571 "285b6a04f648993c6922a3e9da9adf5f81508c3228791843e5d49f24db2f1290bafd97e6" + 572 "55b1049a199f652cd603c4fafa330c390b0da78fbbc67e8fa021cbd74eb96222b12ace31" + 573 "a77dcf920334dc94581b0203010001a3353033300e0603551d0f0101ff04040302078030" + 574 "130603551d25040c300a06082b06010505070309300c0603551d130101ff04023000300d" + 575 "06092a864886f70d01010b05000382010100718012761b5063e18f0dc44644d8e6ab8612" + 576 "31c15fd5357805425d82aec1de85bf6d3e30fce205e3e3b8b795bbe52e40a439286d2288" + 577 "9064f4aeeb150359b9425f1da51b3a5c939018555d13ac42c565a0603786a919328f3267" + 578 "09dce52c22ad958ecb7873b9771d1148b1c4be2efe80ba868919fc9f68b6090c2f33c156" + 579 "d67156e42766a50b5d51e79637b7e58af74c2a951b1e642fa7741fec982cc937de37eff5" + 580 "9e2005d5939bfc031589ca143e6e8ab83f40ee08cc20a6b4a95a318352c28d18528dcaf9" + 581 "66705de17afa19d6e8ae91ddf33179d16ebb6ac2c69cae8373d408ebf8c55308be6c04d9" + 582 "3a25439a94299a65a709756c7a3e568be049d5c38839" 583 584 const errorResponseHex = "30030a0101"