]> WPIA git - nre.git/blobdiff - generateTime.sh
upd: find libfaketime platform independently
[nre.git] / generateTime.sh
index 71aa918f08ca896f6c46d9bb5e05c6ece7b223d4..300d823857f7c2ab8a3eaae120fb926b7d99f4c7 100755 (executable)
@@ -6,13 +6,18 @@
 [ "$1" == "" ] && echo "Usage: $0 <year>" && exit 1
 year=$1
 
+cd generated
+
 genTimeCA(){ #csr,ca to sign with,start,end
     cat <<TESTCA > timesubca.cnf
 basicConstraints = CA:true
-subjectKeyIdentifier = hash
 keyUsage = keyCertSign, cRLSign
-crlDistributionPoints=URI:http://g2.crl.cacert.org/g2/$2.crl
-authorityInfoAccess = OCSP;URI:http://g2.ocsp.cacert.org,caIssuers;URI:http://g2.crt.cacert.org/$2.crt
+
+subjectKeyIdentifier = hash
+authorityKeyIdentifier = keyid:always
+
+crlDistributionPoints=URI:http://g2.crl.${DOMAIN}/g2/$2.crl
+authorityInfoAccess = OCSP;URI:http://g2.ocsp.${DOMAIN},caIssuers;URI:http://g2.crt.${DOMAIN}/g2/$2.crt
 TESTCA
     caSign $1 $2 timesubca.cnf "$3" "$4"
     rm timesubca.cnf
@@ -21,19 +26,23 @@ TESTCA
 mkdir -p $year/ca
 
 
-STARTDATE="${year}"
-ENDDATE="$((${year} + 2))"
-
 for i in $TIME_IDX; do
-    point=${points[${i}]}
-    . CAs/env
+    point=${year}${points[${i}]}
+    nextp=${points[$((${i} + 1))]}
+    if [[ "$nextp" == "" ]]; then
+       epoint=$((${year} + 3 ))${epoints[${i}]}
+    else
+       epoint=$((${year} + 2 ))${epoints[${i}]}
+    fi
+
+    . ../CAs/env
     genca "/CN=$name ${year}-${i}" $year/ca/env_${year}_${i}
-    genTimeCA $year/ca/env_${year}_${i}.ca/key env "$STARTDATE$point" "$ENDDATE$point"
+    genTimeCA $year/ca/env_${year}_${i}.ca/key env "$point" "$epoint"
     
     for ca in $STRUCT_CAS; do
        [ "$ca" == "env" ] && continue
-       . CAs/$ca
+       . ../CAs/$ca
        genKey "/CN=$name ${year}-${i}" $year/ca/${ca}_${year}_${i}
-       genTimeCA $year/ca/${ca}_${year}_${i} $ca "$STARTDATE$point" "$ENDDATE$point"
+       genTimeCA $year/ca/${ca}_${year}_${i} $ca "$point" "$epoint"
     done
 done