Skip to content

Local TLS test credentials

These deliberately public test keys MUST NOT be trusted or used for deployment. The root private key is discarded. Every certificate is valid from 2020-01-01 to 2100-01-01 so tests do not depend on a developer's certificate issuance date.

generate.py creates RSA-2048/SHA-256 fixtures with Python cryptography. To regenerate explicitly: uv run --with cryptography tests/fixtures/tls/generate.py. Normal tests only use the standard library and AnyIO; no certificate generation, network service, OpenSSL command, or optional cryptography install is needed.

  • server.pem: SAN dNSName localhost; server.key serves all server fixtures.
  • cn-only.pem: CN localhost with no SAN, which RTR MUST reject.
  • wrong-san.pem: SAN unrelated.example despite CN localhost.
  • ip-only.pem: only SAN iPAddress 127.0.0.1, insufficient for DNS-ID.
  • client.pem: SAN iPAddress 127.0.0.1 and ::1.
  • client-wrong-ip.pem: SAN iPAddress 192.0.2.1.
  • client-no-san.pem: missing the required IP identity.
  • client-combined.pem: valid client certificate and client.key in one PEM.
  • client-encrypted.key: client key encrypted with public test password public-test-password; the built-in loader must fail without prompting.

The root's OpenSSL subject hash is 13c2b432, recorded with openssl x509 -in ca.pem -noout -subject_hash. Default-directory trust tests copy this fixed root to 13c2b432.0; they do not require OpenSSL commands or symlink privileges at test time. Regenerating a different root subject requires updating this hash and its directory-trust test together.

TLS contracts derive from RFC 8210 §9.2 and draft-ietf-sidrops-8210bis-27 §9.2. The test cache independently checks the client's certificate SAN against the socket peer address. It is a test endpoint, not a production RTR server or an independent implementation interoperability result.