mirror of
https://github.com/vmware-tanzu/pinniped.git
synced 2026-01-07 14:05:50 +00:00
Use EC crypto (instead of RSA) to workaround weird test timeout
When we use RSA private keys to sign our test certificates, we run into strange test timeouts. The internal/controller/apicerts package was timing out on my machine more than once every 3 runs. When I changed the RSA crypto to EC crypto, this timeout goes away. I'm not gonna try to figure out what the deal is here because I think it would take longer than it would be worth (although I am sure it is some fun story involving prime numbers; the goroutine traces for timed out tests would always include some big.Int operations involving prime numbers...). Signed-off-by: Andrew Keesler <akeesler@vmware.com>
This commit is contained in:
@@ -7,8 +7,9 @@ package apicerts
|
||||
|
||||
import (
|
||||
"context"
|
||||
"crypto/ecdsa"
|
||||
"crypto/elliptic"
|
||||
"crypto/rand"
|
||||
"crypto/rsa"
|
||||
"crypto/x509"
|
||||
"errors"
|
||||
"testing"
|
||||
@@ -197,11 +198,12 @@ func TestExpirerControllerSync(t *testing.T) {
|
||||
{
|
||||
name: "parse cert failure",
|
||||
fillSecretData: func(t *testing.T, m map[string][]byte) {
|
||||
privateKey, err := rsa.GenerateKey(rand.Reader, 2048)
|
||||
privateKey, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
|
||||
require.NoError(t, err)
|
||||
|
||||
// See certs_manager.go for this constant.
|
||||
m["tlsCertificateChain"] = x509.MarshalPKCS1PrivateKey(privateKey)
|
||||
m["tlsCertificateChain"], err = x509.MarshalPKCS8PrivateKey(privateKey)
|
||||
require.NoError(t, err)
|
||||
},
|
||||
wantDelete: false,
|
||||
},
|
||||
|
||||
Reference in New Issue
Block a user