virnettlscontexttest.c 25.0 KB
Newer Older
1
/*
2
 * Copyright (C) 2011-2012 Red Hat, Inc.
3 4 5 6 7 8 9 10 11 12 13 14
 *
 * This library is free software; you can redistribute it and/or
 * modify it under the terms of the GNU Lesser General Public
 * License as published by the Free Software Foundation; either
 * version 2.1 of the License, or (at your option) any later version.
 *
 * This library is distributed in the hope that it will be useful,
 * but WITHOUT ANY WARRANTY; without even the implied warranty of
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
 * Lesser General Public License for more details.
 *
 * You should have received a copy of the GNU Lesser General Public
15
 * License along with this library.  If not, see
O
Osier Yang 已提交
16
 * <http://www.gnu.org/licenses/>.
17 18 19 20 21 22 23 24 25 26 27
 *
 * Author: Daniel P. Berrange <berrange@redhat.com>
 */

#include <config.h>

#include <stdlib.h>
#include <fcntl.h>
#include <sys/socket.h>

#include "testutils.h"
28
#include "virnettlshelpers.h"
29
#include "virutil.h"
30
#include "virerror.h"
31
#include "viralloc.h"
32
#include "virlog.h"
33
#include "virfile.h"
34
#include "vircommand.h"
35
#include "virsocketaddr.h"
36

37
#if !defined WIN32 && HAVE_LIBTASN1_H && LIBGNUTLS_VERSION_NUMBER >= 0x020600
38 39 40 41 42 43 44

# include "rpc/virnettlscontext.h"

# define VIR_FROM_THIS VIR_FROM_RPC

struct testTLSContextData {
    bool isServer;
45 46
    const char *cacrt;
    const char *crt;
47 48 49 50 51 52 53 54 55 56
    bool expectFail;
};


/*
 * This tests sanity checking of our own certificates
 *
 * This code is done when libvirtd starts up, or before
 * a libvirt client connects. The test is ensuring that
 * the creation of virNetTLSContextPtr fails if we
J
Ján Tomko 已提交
57
 * give bogus certs, or succeeds for good certs
58 59 60 61 62 63 64 65
 */
static int testTLSContextInit(const void *opaque)
{
    struct testTLSContextData *data = (struct testTLSContextData *)opaque;
    virNetTLSContextPtr ctxt = NULL;
    int ret = -1;

    if (data->isServer) {
66
        ctxt = virNetTLSContextNewServer(data->cacrt,
67
                                         NULL,
68
                                         data->crt,
69 70 71 72 73
                                         keyfile,
                                         NULL,
                                         true,
                                         true);
    } else {
74
        ctxt = virNetTLSContextNewClient(data->cacrt,
75
                                         NULL,
76
                                         data->crt,
77 78 79 80 81 82 83 84
                                         keyfile,
                                         true,
                                         true);
    }

    if (ctxt) {
        if (data->expectFail) {
            VIR_WARN("Expected failure %s against %s",
85
                     data->cacrt, data->crt);
86 87 88 89 90 91
            goto cleanup;
        }
    } else {
        virErrorPtr err = virGetLastError();
        if (!data->expectFail) {
            VIR_WARN("Unexpected failure %s against %s",
92
                     data->cacrt, data->crt);
93 94 95 96 97 98 99 100
            goto cleanup;
        }
        VIR_DEBUG("Got error %s", err ? err->message : "<unknown>");
    }

    ret = 0;

cleanup:
101
    virObjectUnref(ctxt);
102 103 104 105 106 107 108 109 110 111
    return ret;
}



static int
mymain(void)
{
    int ret = 0;

112
    testTLSInit();
113

114
# define DO_CTX_TEST(_isServer, _caCrt, _crt, _expectFail)              \
115
    do {                                                                \
116 117
        static struct testTLSContextData data;                          \
        data.isServer = _isServer;                                      \
118 119
        data.cacrt = _caCrt;                                            \
        data.crt = _crt;                                                \
120
        data.expectFail = _expectFail;                                  \
121
        if (virtTestRun("TLS Context " #_caCrt  " + " #_crt, 1,         \
122
                        testTLSContextInit, &data) < 0)                 \
123 124 125
            ret = -1;                                                   \
    } while (0)

126 127 128 129
# define TLS_CERT_REQ(varname, cavarname,                               \
                      co, cn, an1, an2, ia1, ia2, bce, bcc, bci,        \
                      kue, kuc, kuv, kpe, kpc, kpo1, kpo2, so, eo)      \
    static struct testTLSCertReq varname = {                            \
130
        NULL, #varname "-ctx.pem",                                      \
131 132 133 134 135 136 137 138 139
        co, cn, an1, an2, ia1, ia2, bce, bcc, bci,                      \
        kue, kuc, kuv, kpe, kpc, kpo1, kpo2, so, eo                     \
    };                                                                  \
    testTLSGenerateCert(&varname, cavarname.crt)

# define TLS_ROOT_REQ(varname,                                          \
                      co, cn, an1, an2, ia1, ia2, bce, bcc, bci,        \
                      kue, kuc, kuv, kpe, kpc, kpo1, kpo2, so, eo)      \
    static struct testTLSCertReq varname = {                            \
140
        NULL, #varname "-ctx.pem",                                      \
141 142 143 144 145 146
        co, cn, an1, an2, ia1, ia2, bce, bcc, bci,                      \
        kue, kuc, kuv, kpe, kpc, kpo1, kpo2, so, eo                     \
    };                                                                  \
    testTLSGenerateCert(&varname, NULL)


147 148 149
    /* A perfect CA, perfect client & perfect server */

    /* Basic:CA:critical */
150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168
    TLS_ROOT_REQ(cacertreq,
                 "UK", "libvirt CA", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);

    TLS_CERT_REQ(servercertreq, cacertreq,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
    TLS_CERT_REQ(clientcertreq, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, 0);
169

170 171
    DO_CTX_TEST(true, cacertreq.filename, servercertreq.filename, false);
    DO_CTX_TEST(false, cacertreq.filename, clientcertreq.filename, false);
172 173 174 175 176


    /* Some other CAs which are good */

    /* Basic:CA:critical */
177 178 179 180 181 182 183 184 185 186 187 188 189
    TLS_ROOT_REQ(cacert1req,
                 "UK", "libvirt CA 1", NULL, NULL, NULL, NULL,
                 true, true, true,
                 false, false, 0,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert1req, cacert1req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);

190
    /* Basic:CA:not-critical */
191 192 193 194 195 196 197 198 199 200 201 202 203
    TLS_ROOT_REQ(cacert2req,
                 "UK", "libvirt CA 2", NULL, NULL, NULL, NULL,
                 true, false, true,
                 false, false, 0,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert2req, cacert2req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);

204
    /* Key usage:cert-sign:critical */
205 206 207 208 209 210 211 212 213 214 215 216 217
    TLS_ROOT_REQ(cacert3req,
                 "UK", "libvirt CA 3", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert3req, cacert3req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);

218 219 220
    DO_CTX_TEST(true, cacert1req.filename, servercert1req.filename, false);
    DO_CTX_TEST(true, cacert2req.filename, servercert2req.filename, false);
    DO_CTX_TEST(true, cacert3req.filename, servercert3req.filename, false);
221 222 223

    /* Now some bad certs */

D
Daniel P. Berrange 已提交
224
    /* Key usage:dig-sig:not-critical */
225 226 227 228 229 230 231 232 233 234 235 236
    TLS_ROOT_REQ(cacert4req,
                 "UK", "libvirt CA 4", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, false, GNUTLS_KEY_DIGITAL_SIGNATURE,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert4req, cacert4req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
237
    /* no-basic */
238 239 240 241 242 243 244 245 246 247 248 249
    TLS_ROOT_REQ(cacert5req,
                 "UK", "libvirt CA 5", NULL, NULL, NULL, NULL,
                 false, false, false,
                 false, false, 0,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert5req, cacert5req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
250
    /* Key usage:dig-sig:critical */
251 252 253 254 255 256 257 258 259 260 261 262
    TLS_ROOT_REQ(cacert6req,
                 "UK", "libvirt CA 6", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercert6req, cacert6req,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
263

D
Daniel P. Berrange 已提交
264 265 266 267 268
    /* Technically a CA cert with basic constraints
     * key purpose == key signing + non-critical should
     * be rejected. GNUTLS < 3 does not reject it and
     * we don't anticipate them changing this behaviour
     */
269 270 271
    DO_CTX_TEST(true, cacert4req.filename, servercert4req.filename, GNUTLS_VERSION_MAJOR >= 3);
    DO_CTX_TEST(true, cacert5req.filename, servercert5req.filename, true);
    DO_CTX_TEST(true, cacert6req.filename, servercert6req.filename, true);
272 273 274 275


    /* Various good servers */
    /* no usage or purpose */
276 277 278 279 280 281
    TLS_CERT_REQ(servercert7req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 false, false, NULL, NULL,
                 0, 0);
282
    /* usage:cert-sign+dig-sig+encipher:critical */
283 284 285 286 287 288
    TLS_CERT_REQ(servercert8req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT | GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
289
    /* usage:cert-sign:not-critical */
290 291 292 293 294 295
    TLS_CERT_REQ(servercert9req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, false, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
296
    /* purpose:server:critical */
297 298 299 300 301 302
    TLS_CERT_REQ(servercert10req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
303
    /* purpose:server:not-critical */
304 305 306 307 308 309
    TLS_CERT_REQ(servercert11req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, false, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
310
    /* purpose:client+server:critical */
311 312 313 314 315 316
    TLS_CERT_REQ(servercert12req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, GNUTLS_KP_TLS_WWW_SERVER,
                 0, 0);
317
    /* purpose:client+server:not-critical */
318 319 320 321 322 323 324
    TLS_CERT_REQ(servercert13req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, false, GNUTLS_KP_TLS_WWW_CLIENT, GNUTLS_KP_TLS_WWW_SERVER,
                 0, 0);

325 326 327 328 329 330 331
    DO_CTX_TEST(true, cacertreq.filename, servercert7req.filename, false);
    DO_CTX_TEST(true, cacertreq.filename, servercert8req.filename, false);
    DO_CTX_TEST(true, cacertreq.filename, servercert9req.filename, false);
    DO_CTX_TEST(true, cacertreq.filename, servercert10req.filename, false);
    DO_CTX_TEST(true, cacertreq.filename, servercert11req.filename, false);
    DO_CTX_TEST(true, cacertreq.filename, servercert12req.filename, false);
    DO_CTX_TEST(true, cacertreq.filename, servercert13req.filename, false);
332 333 334
    /* Bad servers */

    /* usage:cert-sign:critical */
335 336 337 338 339 340
    TLS_CERT_REQ(servercert14req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
341
    /* purpose:client:critical */
342 343 344 345 346 347
    TLS_CERT_REQ(servercert15req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, 0);
348
    /* usage: none:critical */
349 350 351 352 353 354
    TLS_CERT_REQ(servercert16req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, 0,
                 false, false, NULL, NULL,
                 0, 0);
355

356 357 358
    DO_CTX_TEST(true, cacertreq.filename, servercert14req.filename, true);
    DO_CTX_TEST(true, cacertreq.filename, servercert15req.filename, true);
    DO_CTX_TEST(true, cacertreq.filename, servercert16req.filename, true);
359 360 361 362 363



    /* Various good clients */
    /* no usage or purpose */
364 365 366 367 368 369
    TLS_CERT_REQ(clientcert1req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 false, false, NULL, NULL,
                 0, 0);
370
    /* usage:cert-sign+dig-sig+encipher:critical */
371 372 373 374 375 376
    TLS_CERT_REQ(clientcert2req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT | GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
377
    /* usage:cert-sign:not-critical */
378 379 380 381 382 383
    TLS_CERT_REQ(clientcert3req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, false, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
384
    /* purpose:client:critical */
385 386 387 388 389 390
    TLS_CERT_REQ(clientcert4req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, 0);
391
    /* purpose:client:not-critical */
392 393 394 395 396 397
    TLS_CERT_REQ(clientcert5req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, false, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, 0);
398
    /* purpose:client+client:critical */
399 400 401 402 403 404
    TLS_CERT_REQ(clientcert6req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, GNUTLS_KP_TLS_WWW_SERVER,
                 0, 0);
405
    /* purpose:client+client:not-critical */
406 407 408 409 410 411
    TLS_CERT_REQ(clientcert7req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, false, GNUTLS_KP_TLS_WWW_CLIENT, GNUTLS_KP_TLS_WWW_SERVER,
                 0, 0);
412

413 414 415 416 417 418 419
    DO_CTX_TEST(false, cacertreq.filename, clientcert1req.filename, false);
    DO_CTX_TEST(false, cacertreq.filename, clientcert2req.filename, false);
    DO_CTX_TEST(false, cacertreq.filename, clientcert3req.filename, false);
    DO_CTX_TEST(false, cacertreq.filename, clientcert4req.filename, false);
    DO_CTX_TEST(false, cacertreq.filename, clientcert5req.filename, false);
    DO_CTX_TEST(false, cacertreq.filename, clientcert6req.filename, false);
    DO_CTX_TEST(false, cacertreq.filename, clientcert7req.filename, false);
420 421 422
    /* Bad clients */

    /* usage:cert-sign:critical */
423 424 425 426 427 428
    TLS_CERT_REQ(clientcert8req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
429
    /* purpose:client:critical */
430 431 432 433 434 435
    TLS_CERT_REQ(clientcert9req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 false, false, 0,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
436
    /* usage: none:critical */
437 438 439 440 441 442
    TLS_CERT_REQ(clientcert10req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, 0,
                 false, false, NULL, NULL,
                 0, 0);
443

444 445 446
    DO_CTX_TEST(false, cacertreq.filename, clientcert8req.filename, true);
    DO_CTX_TEST(false, cacertreq.filename, clientcert9req.filename, true);
    DO_CTX_TEST(false, cacertreq.filename, clientcert10req.filename, true);
447 448 449 450 451



    /* Expired stuff */

452 453 454 455 456 457 458 459 460 461 462 463 464 465 466 467 468 469 470 471 472 473 474 475 476
    TLS_ROOT_REQ(cacertexpreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, -1);
    TLS_CERT_REQ(servercertexpreq, cacertexpreq,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
    TLS_CERT_REQ(servercertexp1req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, -1);
    TLS_CERT_REQ(clientcertexp1req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, -1);

477 478 479
    DO_CTX_TEST(true, cacertexpreq.filename, servercertexpreq.filename, true);
    DO_CTX_TEST(true, cacertreq.filename, servercertexp1req.filename, true);
    DO_CTX_TEST(false, cacertreq.filename, clientcertexp1req.filename, true);
480 481 482 483


    /* Not activated stuff */

484 485 486 487 488 489 490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508
    TLS_ROOT_REQ(cacertnewreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 1, 2);
    TLS_CERT_REQ(servercertnewreq, cacertnewreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
    TLS_CERT_REQ(servercertnew1req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 1, 2);
    TLS_CERT_REQ(clientcertnew1req, cacertreq,
                 "UK", "libvirt", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 1, 2);

509 510 511
    DO_CTX_TEST(true, cacertnewreq.filename, servercertnewreq.filename, true);
    DO_CTX_TEST(true, cacertreq.filename, servercertnew1req.filename, true);
    DO_CTX_TEST(false, cacertreq.filename, clientcertnew1req.filename, true);
512

513 514 515 516 517 518 519 520 521 522 523 524 525 526 527 528 529 530 531 532 533 534 535 536 537 538 539 540 541 542 543 544 545 546 547 548 549 550 551 552 553 554 555 556 557 558 559 560 561 562 563
    TLS_ROOT_REQ(cacertrootreq,
                 "UK", "libvirt root", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(cacertlevel1areq, cacertrootreq,
                 "UK", "libvirt level 1a", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(cacertlevel1breq, cacertrootreq,
                 "UK", "libvirt level 1b", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(cacertlevel2areq, cacertlevel1areq,
                 "UK", "libvirt level 2a", NULL, NULL, NULL, NULL,
                 true, true, true,
                 true, true, GNUTLS_KEY_KEY_CERT_SIGN,
                 false, false, NULL, NULL,
                 0, 0);
    TLS_CERT_REQ(servercertlevel3areq, cacertlevel2areq,
                 "UK", "libvirt.org", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_SERVER, NULL,
                 0, 0);
    TLS_CERT_REQ(clientcertlevel2breq, cacertlevel1breq,
                 "UK", "libvirt client level 2b", NULL, NULL, NULL, NULL,
                 true, true, false,
                 true, true, GNUTLS_KEY_DIGITAL_SIGNATURE | GNUTLS_KEY_KEY_ENCIPHERMENT,
                 true, true, GNUTLS_KP_TLS_WWW_CLIENT, NULL,
                 0, 0);

    gnutls_x509_crt_t certchain[] = {
        cacertrootreq.crt,
        cacertlevel1areq.crt,
        cacertlevel1breq.crt,
        cacertlevel2areq.crt,
    };

    testTLSWriteCertChain("cacertchain.pem",
                          certchain,
                          ARRAY_CARDINALITY(certchain));

    DO_CTX_TEST(true, "cacertchain.pem", servercertlevel3areq.filename, false);
    DO_CTX_TEST(false, "cacertchain.pem", clientcertlevel2breq.filename, false);

564 565 566 567 568 569 570 571 572 573 574 575 576 577 578 579 580 581 582 583 584 585 586 587 588 589 590 591 592 593 594 595 596 597 598 599 600 601 602 603 604 605 606 607 608 609 610
    testTLSDiscardCert(&cacertreq);
    testTLSDiscardCert(&cacert1req);
    testTLSDiscardCert(&cacert2req);
    testTLSDiscardCert(&cacert3req);
    testTLSDiscardCert(&cacert4req);
    testTLSDiscardCert(&cacert5req);
    testTLSDiscardCert(&cacert6req);

    testTLSDiscardCert(&servercertreq);
    testTLSDiscardCert(&servercert1req);
    testTLSDiscardCert(&servercert2req);
    testTLSDiscardCert(&servercert3req);
    testTLSDiscardCert(&servercert4req);
    testTLSDiscardCert(&servercert5req);
    testTLSDiscardCert(&servercert6req);
    testTLSDiscardCert(&servercert7req);
    testTLSDiscardCert(&servercert8req);
    testTLSDiscardCert(&servercert9req);
    testTLSDiscardCert(&servercert10req);
    testTLSDiscardCert(&servercert11req);
    testTLSDiscardCert(&servercert12req);
    testTLSDiscardCert(&servercert13req);
    testTLSDiscardCert(&servercert14req);
    testTLSDiscardCert(&servercert15req);
    testTLSDiscardCert(&servercert16req);

    testTLSDiscardCert(&clientcertreq);
    testTLSDiscardCert(&clientcert1req);
    testTLSDiscardCert(&clientcert2req);
    testTLSDiscardCert(&clientcert3req);
    testTLSDiscardCert(&clientcert4req);
    testTLSDiscardCert(&clientcert5req);
    testTLSDiscardCert(&clientcert6req);
    testTLSDiscardCert(&clientcert7req);
    testTLSDiscardCert(&clientcert8req);
    testTLSDiscardCert(&clientcert9req);
    testTLSDiscardCert(&clientcert10req);

    testTLSDiscardCert(&cacertexpreq);
    testTLSDiscardCert(&servercertexpreq);
    testTLSDiscardCert(&servercertexp1req);
    testTLSDiscardCert(&clientcertexp1req);

    testTLSDiscardCert(&cacertnewreq);
    testTLSDiscardCert(&servercertnewreq);
    testTLSDiscardCert(&servercertnew1req);
    testTLSDiscardCert(&clientcertnew1req);
611

612 613 614 615 616 617 618 619
    testTLSDiscardCert(&cacertrootreq);
    testTLSDiscardCert(&cacertlevel1areq);
    testTLSDiscardCert(&cacertlevel1breq);
    testTLSDiscardCert(&cacertlevel2areq);
    testTLSDiscardCert(&servercertlevel3areq);
    testTLSDiscardCert(&clientcertlevel2breq);
    unlink("cacertchain.pem");

620
    testTLSCleanup();
621

622
    return ret==0 ? EXIT_SUCCESS : EXIT_FAILURE;
623 624
}

E
Eric Blake 已提交
625 626
VIRT_TEST_MAIN(mymain)

627
#else
628

E
Eric Blake 已提交
629
int
630
main(void)
631
{
632
    return EXIT_AM_SKIP;
633
}
634

635
#endif