virnettlscontexttest.c 22.1 KB
Newer Older
1
/*
2
 * Copyright (C) 2011-2012 Red Hat, Inc.
3 4 5 6 7 8 9 10 11 12 13 14
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
15
 * License along with this library.  If not, see
O
Osier Yang 已提交
16
 * <http://www.gnu.org/licenses/>.
17 18 19 20 21 22 23 24 25 26 27
 *
 * Author: Daniel P. Berrange <berrange@redhat.com>
 */

#include <config.h>

#include <stdlib.h>
#include <fcntl.h>
#include <sys/socket.h>

#include "testutils.h"
28
#include "virnettlshelpers.h"
29
#include "virutil.h"
30
#include "virerror.h"
31
#include "viralloc.h"
32
#include "virlog.h"
33
#include "virfile.h"
34
#include "vircommand.h"
35
#include "virsocketaddr.h"
36

37
#if !defined WIN32 && HAVE_LIBTASN1_H && LIBGNUTLS_VERSION_NUMBER >= 0x020600
38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56

# include "rpc/virnettlscontext.h"

# define VIR_FROM_THIS VIR_FROM_RPC

struct testTLSContextData {
    bool isServer;
    struct testTLSCertReq careq;
    struct testTLSCertReq certreq;
    bool expectFail;
};


/*
 * This tests sanity checking of our own certificates
 *
 * This code is done when libvirtd starts up, or before
 * a libvirt client connects. The test is ensuring that
 * the creation of virNetTLSContextPtr fails if we
J
Ján Tomko 已提交
57
 * give bogus certs, or succeeds for good certs
58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100
 */
static int testTLSContextInit(const void *opaque)
{
    struct testTLSContextData *data = (struct testTLSContextData *)opaque;
    virNetTLSContextPtr ctxt = NULL;
    int ret = -1;

    if (data->isServer) {
        ctxt = virNetTLSContextNewServer(data->careq.filename,
                                         NULL,
                                         data->certreq.filename,
                                         keyfile,
                                         NULL,
                                         true,
                                         true);
    } else {
        ctxt = virNetTLSContextNewClient(data->careq.filename,
                                         NULL,
                                         data->certreq.filename,
                                         keyfile,
                                         true,
                                         true);
    }

    if (ctxt) {
        if (data->expectFail) {
            VIR_WARN("Expected failure %s against %s",
                     data->careq.filename, data->certreq.filename);
            goto cleanup;
        }
    } else {
        virErrorPtr err = virGetLastError();
        if (!data->expectFail) {
            VIR_WARN("Unexpected failure %s against %s",
                     data->careq.filename, data->certreq.filename);
            goto cleanup;
        }
        VIR_DEBUG("Got error %s", err ? err->message : "<unknown>");
    }

    ret = 0;

cleanup:
101
    virObjectUnref(ctxt);
102 103 104 105 106 107 108 109 110 111
    return ret;
}



static int
mymain(void)
{
    int ret = 0;

112
    testTLSInit();
113

114
# define DO_CTX_TEST(_isServer, _caReq, _certReq, _expectFail)          \
115
    do {                                                                \
116 117 118 119 120
        static struct testTLSContextData data;                          \
        data.isServer = _isServer;                                      \
        data.careq = _caReq;                                            \
        data.certreq = _certReq;                                        \
        data.expectFail = _expectFail;                                  \
121 122
        if (virtTestRun("TLS Context " #_caReq  " + " #_certReq, 1,     \
                        testTLSContextInit, &data) < 0)                 \
123 124 125
            ret = -1;                                                   \
    } while (0)

126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146
# define TLS_CERT_REQ(varname, cavarname,                               \
                      co, cn, an1, an2, ia1, ia2, bce, bcc, bci,        \
                      kue, kuc, kuv, kpe, kpc, kpo1, kpo2, so, eo)      \
    static struct testTLSCertReq varname = {                            \
        NULL, #varname ".pem",                                          \
        co, cn, an1, an2, ia1, ia2, bce, bcc, bci,                      \
        kue, kuc, kuv, kpe, kpc, kpo1, kpo2, so, eo                     \
    };                                                                  \
    testTLSGenerateCert(&varname, cavarname.crt)

# define TLS_ROOT_REQ(varname,                                          \
                      co, cn, an1, an2, ia1, ia2, bce, bcc, bci,        \
                      kue, kuc, kuv, kpe, kpc, kpo1, kpo2, so, eo)      \
    static struct testTLSCertReq varname = {                            \
        NULL, #varname ".pem",                                          \
        co, cn, an1, an2, ia1, ia2, bce, bcc, bci,                      \
        kue, kuc, kuv, kpe, kpc, kpo1, kpo2, so, eo                     \
    };                                                                  \
    testTLSGenerateCert(&varname, NULL)


147 148 149
    /* A perfect CA, perfect client & perfect server */

    /* Basic:CA:critical */
150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168
    TLS_ROOT_REQ(cacertreq,
                 "UK", "libvirt CA", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);

    TLS_CERT_REQ(servercertreq, cacertreq,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
    TLS_CERT_REQ(clientcertreq, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, 0);
169 170 171 172 173 174 175 176

    DO_CTX_TEST(true, cacertreq, servercertreq, false);
    DO_CTX_TEST(false, cacertreq, clientcertreq, false);


    /* Some other CAs which are good */

    /* Basic:CA:critical */
177 178 179 180 181 182 183 184 185 186 187 188 189
    TLS_ROOT_REQ(cacert1req,
                 "UK", "libvirt CA 1", NULL, NULL, NULL, NULL,
                 true, true, true,
                 false, false, 0,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert1req, cacert1req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);

190
    /* Basic:CA:not-critical */
191 192 193 194 195 196 197 198 199 200 201 202 203
    TLS_ROOT_REQ(cacert2req,
                 "UK", "libvirt CA 2", NULL, NULL, NULL, NULL,
                 true, false, true,
                 false, false, 0,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert2req, cacert2req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);

204
    /* Key usage:cert-sign:critical */
205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220
    TLS_ROOT_REQ(cacert3req,
                 "UK", "libvirt CA 3", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert3req, cacert3req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);

    DO_CTX_TEST(true, cacert1req, servercert1req, false);
    DO_CTX_TEST(true, cacert2req, servercert2req, false);
    DO_CTX_TEST(true, cacert3req, servercert3req, false);
221 222 223

    /* Now some bad certs */

D
Daniel P. Berrange 已提交
224
    /* Key usage:dig-sig:not-critical */
225 226 227 228 229 230 231 232 233 234 235 236
    TLS_ROOT_REQ(cacert4req,
                 "UK", "libvirt CA 4", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, false, GNUTLS_KEY_DIGITAL_SIGNATURE,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert4req, cacert4req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
237
    /* no-basic */
238 239 240 241 242 243 244 245 246 247 248 249
    TLS_ROOT_REQ(cacert5req,
                 "UK", "libvirt CA 5", NULL, NULL, NULL, NULL,
                 false, false, false,
                 false, false, 0,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert5req, cacert5req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
250
    /* Key usage:dig-sig:critical */
251 252 253 254 255 256 257 258 259 260 261 262
    TLS_ROOT_REQ(cacert6req,
                 "UK", "libvirt CA 6", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert6req, cacert6req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
263

D
Daniel P. Berrange 已提交
264 265 266 267 268
    /* Technically a CA cert with basic constraints
     * key purpose == key signing + non-critical should
     * be rejected. GNUTLS < 3 does not reject it and
     * we don't anticipate them changing this behaviour
     */
269 270 271
    DO_CTX_TEST(true, cacert4req, servercert4req, GNUTLS_VERSION_MAJOR >= 3);
    DO_CTX_TEST(true, cacert5req, servercert5req, true);
    DO_CTX_TEST(true, cacert6req, servercert6req, true);
272 273 274 275


    /* Various good servers */
    /* no usage or purpose */
276 277 278 279 280 281
    TLS_CERT_REQ(servercert7req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 false, false, NULL, NULL,
                 0, 0);
282
    /* usage:cert-sign+dig-sig+encipher:critical */
283 284 285 286 287 288
    TLS_CERT_REQ(servercert8req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT | GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
289
    /* usage:cert-sign:not-critical */
290 291 292 293 294 295
    TLS_CERT_REQ(servercert9req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, false, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
296
    /* purpose:server:critical */
297 298 299 300 301 302
    TLS_CERT_REQ(servercert10req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
303
    /* purpose:server:not-critical */
304 305 306 307 308 309
    TLS_CERT_REQ(servercert11req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, false, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
310
    /* purpose:client+server:critical */
311 312 313 314 315 316
    TLS_CERT_REQ(servercert12req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, GNUTLS_KP_TLS_WWW_SERVER,
                 0, 0);
317
    /* purpose:client+server:not-critical */
318 319 320 321 322 323 324
    TLS_CERT_REQ(servercert13req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, false, GNUTLS_KP_TLS_WWW_CLIENT, GNUTLS_KP_TLS_WWW_SERVER,
                 0, 0);

325
    DO_CTX_TEST(true, cacertreq, servercert7req, false);
326 327 328 329 330 331
    DO_CTX_TEST(true, cacertreq, servercert8req, false);
    DO_CTX_TEST(true, cacertreq, servercert9req, false);
    DO_CTX_TEST(true, cacertreq, servercert10req, false);
    DO_CTX_TEST(true, cacertreq, servercert11req, false);
    DO_CTX_TEST(true, cacertreq, servercert12req, false);
    DO_CTX_TEST(true, cacertreq, servercert13req, false);
332 333 334
    /* Bad servers */

    /* usage:cert-sign:critical */
335 336 337 338 339 340
    TLS_CERT_REQ(servercert14req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
341
    /* purpose:client:critical */
342 343 344 345 346 347
    TLS_CERT_REQ(servercert15req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, 0);
348
    /* usage: none:critical */
349 350 351 352 353 354
    TLS_CERT_REQ(servercert16req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, 0,
                 false, false, NULL, NULL,
                 0, 0);
355

356 357 358
    DO_CTX_TEST(true, cacertreq, servercert14req, true);
    DO_CTX_TEST(true, cacertreq, servercert15req, true);
    DO_CTX_TEST(true, cacertreq, servercert16req, true);
359 360 361 362 363



    /* Various good clients */
    /* no usage or purpose */
364 365 366 367 368 369
    TLS_CERT_REQ(clientcert1req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 false, false, NULL, NULL,
                 0, 0);
370
    /* usage:cert-sign+dig-sig+encipher:critical */
371 372 373 374 375 376
    TLS_CERT_REQ(clientcert2req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT | GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
377
    /* usage:cert-sign:not-critical */
378 379 380 381 382 383
    TLS_CERT_REQ(clientcert3req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, false, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
384
    /* purpose:client:critical */
385 386 387 388 389 390
    TLS_CERT_REQ(clientcert4req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, 0);
391
    /* purpose:client:not-critical */
392 393 394 395 396 397
    TLS_CERT_REQ(clientcert5req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, false, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, 0);
398
    /* purpose:client+client:critical */
399 400 401 402 403 404
    TLS_CERT_REQ(clientcert6req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, GNUTLS_KP_TLS_WWW_SERVER,
                 0, 0);
405
    /* purpose:client+client:not-critical */
406 407 408 409 410 411
    TLS_CERT_REQ(clientcert7req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, false, GNUTLS_KP_TLS_WWW_CLIENT, GNUTLS_KP_TLS_WWW_SERVER,
                 0, 0);
412 413 414 415 416 417 418 419 420 421 422

    DO_CTX_TEST(false, cacertreq, clientcert1req, false);
    DO_CTX_TEST(false, cacertreq, clientcert2req, false);
    DO_CTX_TEST(false, cacertreq, clientcert3req, false);
    DO_CTX_TEST(false, cacertreq, clientcert4req, false);
    DO_CTX_TEST(false, cacertreq, clientcert5req, false);
    DO_CTX_TEST(false, cacertreq, clientcert6req, false);
    DO_CTX_TEST(false, cacertreq, clientcert7req, false);
    /* Bad clients */

    /* usage:cert-sign:critical */
423 424 425 426 427 428
    TLS_CERT_REQ(clientcert8req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
429
    /* purpose:client:critical */
430 431 432 433 434 435
    TLS_CERT_REQ(clientcert9req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
436
    /* usage: none:critical */
437 438 439 440 441 442
    TLS_CERT_REQ(clientcert10req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, 0,
                 false, false, NULL, NULL,
                 0, 0);
443 444 445 446 447 448 449 450 451

    DO_CTX_TEST(false, cacertreq, clientcert8req, true);
    DO_CTX_TEST(false, cacertreq, clientcert9req, true);
    DO_CTX_TEST(false, cacertreq, clientcert10req, true);



    /* Expired stuff */

452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476 477 478 479
    TLS_ROOT_REQ(cacertexpreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, -1);
    TLS_CERT_REQ(servercertexpreq, cacertexpreq,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
    TLS_CERT_REQ(servercertexp1req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, -1);
    TLS_CERT_REQ(clientcertexp1req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, -1);

    DO_CTX_TEST(true, cacertexpreq, servercertexpreq, true);
    DO_CTX_TEST(true, cacertreq, servercertexp1req, true);
    DO_CTX_TEST(false, cacertreq, clientcertexp1req, true);
480 481 482 483


    /* Not activated stuff */

484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511 512 513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559
    TLS_ROOT_REQ(cacertnewreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 1, 2);
    TLS_CERT_REQ(servercertnewreq, cacertnewreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
    TLS_CERT_REQ(servercertnew1req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 1, 2);
    TLS_CERT_REQ(clientcertnew1req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 1, 2);

    DO_CTX_TEST(true, cacertnewreq, servercertnewreq, true);
    DO_CTX_TEST(true, cacertreq, servercertnew1req, true);
    DO_CTX_TEST(false, cacertreq, clientcertnew1req, true);

    testTLSDiscardCert(&cacertreq);
    testTLSDiscardCert(&cacert1req);
    testTLSDiscardCert(&cacert2req);
    testTLSDiscardCert(&cacert3req);
    testTLSDiscardCert(&cacert4req);
    testTLSDiscardCert(&cacert5req);
    testTLSDiscardCert(&cacert6req);

    testTLSDiscardCert(&servercertreq);
    testTLSDiscardCert(&servercert1req);
    testTLSDiscardCert(&servercert2req);
    testTLSDiscardCert(&servercert3req);
    testTLSDiscardCert(&servercert4req);
    testTLSDiscardCert(&servercert5req);
    testTLSDiscardCert(&servercert6req);
    testTLSDiscardCert(&servercert7req);
    testTLSDiscardCert(&servercert8req);
    testTLSDiscardCert(&servercert9req);
    testTLSDiscardCert(&servercert10req);
    testTLSDiscardCert(&servercert11req);
    testTLSDiscardCert(&servercert12req);
    testTLSDiscardCert(&servercert13req);
    testTLSDiscardCert(&servercert14req);
    testTLSDiscardCert(&servercert15req);
    testTLSDiscardCert(&servercert16req);

    testTLSDiscardCert(&clientcertreq);
    testTLSDiscardCert(&clientcert1req);
    testTLSDiscardCert(&clientcert2req);
    testTLSDiscardCert(&clientcert3req);
    testTLSDiscardCert(&clientcert4req);
    testTLSDiscardCert(&clientcert5req);
    testTLSDiscardCert(&clientcert6req);
    testTLSDiscardCert(&clientcert7req);
    testTLSDiscardCert(&clientcert8req);
    testTLSDiscardCert(&clientcert9req);
    testTLSDiscardCert(&clientcert10req);

    testTLSDiscardCert(&cacertexpreq);
    testTLSDiscardCert(&servercertexpreq);
    testTLSDiscardCert(&servercertexp1req);
    testTLSDiscardCert(&clientcertexp1req);

    testTLSDiscardCert(&cacertnewreq);
    testTLSDiscardCert(&servercertnewreq);
    testTLSDiscardCert(&servercertnew1req);
    testTLSDiscardCert(&clientcertnew1req);
560

561
    testTLSCleanup();
562

563
    return ret==0 ? EXIT_SUCCESS : EXIT_FAILURE;
564 565
}

E
Eric Blake 已提交
566 567
VIRT_TEST_MAIN(mymain)

568
#else
569

E
Eric Blake 已提交
570
int
571
main(void)
572
{
573
    return EXIT_AM_SKIP;
574
}
575

576
#endif