2 # License: GPL-1.0+ or Artistic-1.0-Perl
3 # from IO::Socket::SSL 2.063 / https://github.com/noxxi/p5-io-socket-ssl
6 use IO::Socket::SSL::Utils;
9 my $dir = -d 'certs' && -f 'Makefile.PL' ? './certs/' : './';
11 my $later = 0x7fffffff; # 2038 problems on 32-bit :<
13 Net::SSLeay::SSLeay_add_ssl_algorithms();
14 my $sha256 = Net::SSLeay::EVP_get_digestbyname('sha256') or die;
17 print $w.' sha256$'.unpack('H*',Net::SSLeay::X509_digest($cert, $sha256))."\n"
20 my %time_valid = (not_before => $now, not_after => $later);
24 subject => { CN => 'IO::Socket::SSL Demo CA' },
27 save('test-ca.pem',PEM_cert2string($ca[0]));
29 my @server = CERT_create(
31 subject => { CN => 'server.local' },
36 save('server-cert.pem',PEM_cert2string($server[0]));
37 save('server-key.pem',PEM_key2string($server[1]));
38 $printfp->(server => $server[0]);
40 @server = CERT_create(
42 subject => { CN => 'server2.local' },
47 save('server2-cert.pem',PEM_cert2string($server[0]));
48 save('server2-key.pem',PEM_key2string($server[1]));
49 $printfp->(server2 => $server[0]);
51 @server = CERT_create(
53 subject => { CN => 'server-ecc.local' },
56 key => KEY_create_ec(),
59 save('server-ecc-cert.pem',PEM_cert2string($server[0]));
60 save('server-ecc-key.pem',PEM_key2string($server[1]));
61 $printfp->('server-ecc' => $server[0]);
64 my @client = CERT_create(
66 subject => { CN => 'client.local' },
71 save('client-cert.pem',PEM_cert2string($client[0]));
72 save('client-key.pem',PEM_key2string($client[1]));
73 $printfp->(client => $client[0]);
75 my @swc = CERT_create(
77 subject => { CN => 'server.local' },
81 [ DNS => '*.server.local' ],
82 [ IP => '127.0.0.1' ],
83 [ DNS => 'www*.other.local' ],
84 [ DNS => 'smtp.mydomain.local' ],
85 [ DNS => 'xn--lwe-sna.idntest.local' ]
89 save('server-wildcard.pem',PEM_cert2string($swc[0]),PEM_key2string($swc[1]));
92 my @subca = CERT_create(
95 subject => { CN => 'IO::Socket::SSL Demo Sub CA' },
98 save('test-subca.pem',PEM_cert2string($subca[0]));
99 @server = CERT_create(
101 subject => { CN => 'server.local' },
106 save('sub-server.pem',PEM_cert2string($server[0]).PEM_key2string($server[1]));
110 my @cap = CERT_create(
112 subject => { CN => 'IO::Socket::SSL::Intercept' },
115 save('proxyca.pem',PEM_cert2string($cap[0]).PEM_key2string($cap[1]));
119 open(my $fd,'>',$dir.$file) or die $!;
126 openssl x509 -in server-cert.pem -out server-cert.der -outform der
127 openssl rsa -in server-key.pem -out server-key.der -outform der
128 openssl rsa -in server-key.pem -out server-key.enc -passout pass:bluebell
129 openssl rsa -in client-key.pem -out client-key.enc -passout pass:opossum
130 openssl pkcs12 -export -in server-cert.pem -inkey server-key.pem -out server.p12 -passout pass:
131 openssl pkcs12 -export -in server-cert.pem -inkey server-key.pem -out server_enc.p12 -passout pass:bluebell