From 3663ba3afd9681129bfcf57e335e35a17a0c7e56 Mon Sep 17 00:00:00 2001 From: Jacob Quinn Date: Wed, 30 Sep 2026 10:31:30 -0600 Subject: [PATCH] Pick a CA bundle root that has the fields ReadPEMCert checks The test took the second entry of Mozilla's CA bundle and asserted it has an OU. The bundle shipped with current Julia versions has no OU in that entry, so the test failed on Julia 1 and nightly for every PR. Co-authored-by: krynju <25935996+krynju@users.noreply.github.com> Co-Authored-By: Claude Opus 5.5 --- test/runtests.jl | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/test/runtests.jl b/test/runtests.jl index 15479d2..2e5d443 100644 --- a/test/runtests.jl +++ b/test/runtests.jl @@ -106,9 +106,9 @@ end start_line = "==========\n" certs_pem = split(file_content, start_line; keepempty=false) - cert = certs_pem[2] - - x509_cert = X509Certificate(cert) + # Mozilla's root list changes order over time, so use the first root whose subject has an OU + pems = filter(p -> occursin("-----BEGIN CERTIFICATE-----", p), certs_pem) + x509_cert = first(c for c in Iterators.map(X509Certificate, pems) if occursin("/OU=", String(c.subject_name))) @test occursin("/C=", String(x509_cert.subject_name)) @test occursin("/OU=", String(x509_cert.subject_name))