Skip to content
validation code for certificate & small nss patch for repeated certificate validation
Branch: master
Clone or download
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Type Name Latest commit message Commit time
Failed to load latest commit information.


Tools for validating certificate chains against using NSS.

  Small patch against nss, which disables the crl issuer cache. This makes
  it possible to check large volumes of chains, without the results being
  tainted because old certificates are still being held in memory
  Analyze the reasons for certificate<->hostname mismatches in greater detail.
  Requires the dev-hostname branch of the NSS bindings at
  Count the entries in a crl set as created by
  Mass-checking of certificate chains using NSS.
  Requires a patched version of NSS using nss.patch and the mozilla-functions branch
  of the NSS bindings at

  Please see the comments in the script - it describes the input file format as well
  as the locations where the certificates files are expected to be.
You can’t perform that action at this time.