Summary: This changes the start date of all generated certificates to be 1h in the past. Why? To allow for clock skew, and allow clock manipulation in tests. To do this, I had to switch from `openssl x509 req`, to `openssl ca` for generating them, because it has the startdate parameter. This variant is a bit more complicated to use, so I've added an openssl.conf and some extra files. I also changed the org from Sonar to Flipper because it now needs to match the CSRs coming from the mobile apps, and they use Flipper. Reviewed By: passy Differential Revision: D16223722 fbshipit-source-id: bdbd61bce1bc1b54d7b0b3cc6741675aa68d2cf6
324 KiB
324 KiB