testssl.sh/etc
2016-03-13 20:38:06 +01:00
..
curves.txt checkin (for future work) 2016-02-06 15:42:55 +01:00
linux.pem - NEW: chain of trust -- for openssl 1.0.2 only 2015-09-22 15:05:59 +02:00
mapping-rfc.txt Fix typo in etc/mapping-rfc.txt 2016-02-05 14:53:19 -05:00
microsoft.pem - updated, see #317 2016-03-13 20:38:06 +01:00
mozilla.pem - updated Mozilla truststore from http://curl.haxx.se/ instead of local firefox install, #317 2016-03-12 18:19:15 +01:00
README.md - updated, see #317 2016-03-13 20:38:06 +01:00

Certification stores

The certificate stores were retrieved by

  • Mozilla; see https://curl.haxx.se/docs/caextract.html
  • Linux: Just copied from a uptodate Linux machine
  • Microsoft: under Windows >= 7,2008 MS decided not to provide a full certificate store. It's being populated with time -- supposed you use e.g. IE while browsing. This store was destilled from three different windows installations via certmgr.msc and export of "Trusted Root Certification Authorities" --> "Certificates". Third Party Root Certificates were deliberately omitted.

In this directory you can also save e.g. your company Root CAs in PEM format. You will still get a warning for the other certificate stores though while scanning internal networks. If you scan other hosts in the internet the check against your Root CA will fail, too. This will be fixed in the future, see #230.

Mapping file

The file mapping-rfc.txt uses the hexcode to map OpenSSL names against the RFC/IAMA names