Local TLS test credentials
These deliberately public test keys MUST NOT be trusted or used for deployment. The root private key is discarded. Every certificate is valid from 2020-01-01 to 2100-01-01 so tests do not depend on a developer's certificate issuance date.
generate.py creates RSA-2048/SHA-256 fixtures with Python cryptography. To
regenerate explicitly: uv run --with cryptography tests/fixtures/tls/generate.py.
Normal tests only use the standard library and AnyIO; no certificate generation,
network service, OpenSSL command, or optional cryptography install is needed.
server.pem: SAN dNSNamelocalhost;server.keyserves all server fixtures.cn-only.pem: CNlocalhostwith no SAN, which RTR MUST reject.wrong-san.pem: SANunrelated.exampledespite CNlocalhost.ip-only.pem: only SAN iPAddress127.0.0.1, insufficient for DNS-ID.client.pem: SAN iPAddress127.0.0.1and::1.client-wrong-ip.pem: SAN iPAddress192.0.2.1.client-no-san.pem: missing the required IP identity.client-combined.pem: valid client certificate andclient.keyin one PEM.client-encrypted.key: client key encrypted with public test passwordpublic-test-password; the built-in loader must fail without prompting.
The root's OpenSSL subject hash is 13c2b432, recorded with
openssl x509 -in ca.pem -noout -subject_hash. Default-directory trust tests
copy this fixed root to 13c2b432.0; they do not require OpenSSL commands or
symlink privileges at test time. Regenerating a different root subject requires
updating this hash and its directory-trust test together.
TLS contracts derive from RFC 8210 §9.2 and draft-ietf-sidrops-8210bis-27 §9.2. The test cache independently checks the client's certificate SAN against the socket peer address. It is a test endpoint, not a production RTR server or an independent implementation interoperability result.