80-test_ssl.t 32.9 KB
Newer Older
1 2 3 4 5 6 7 8
#! /usr/bin/perl

use strict;
use warnings;

use POSIX;
use File::Spec;
use File::Copy;
9
use OpenSSL::Test qw/:DEFAULT with bldtop_file srctop_file cmdstr/;
10
use OpenSSL::Test::Utils;
11 12 13

setup("test_ssl");

14 15
my ($no_rsa, $no_dsa, $no_dh, $no_ec, $no_srp, $no_psk,
    $no_ssl3, $no_tls1, $no_tls1_1, $no_tls1_2,
16
    $no_dtls, $no_dtls1, $no_dtls1_2, $no_ct) =
17 18
    anydisabled qw/rsa dsa dh ec srp psk
                   ssl3 tls1 tls1_1 tls1_2
19
                   dtls dtls1 dtls1_2 ct/;
20 21
my $no_anytls = alldisabled(available_protocols("tls"));
my $no_anydtls = alldisabled(available_protocols("dtls"));
22 23 24

plan skip_all => "No SSL/TLS/DTLS protocol is support by this OpenSSL build"
    if $no_anytls && $no_anydtls;
25

26 27 28 29
my $digest = "-sha1";
my @reqcmd = ("openssl", "req");
my @x509cmd = ("openssl", "x509", $digest);
my @verifycmd = ("openssl", "verify");
30
my $dummycnf = srctop_file("apps", "openssl.cnf");
31 32 33 34 35

my $CAkey = "keyCA.ss";
my $CAcert="certCA.ss";
my $CAserial="certCA.srl";
my $CAreq="reqCA.ss";
36
my $CAconf=srctop_file("test","CAss.cnf");
37 38
my $CAreq2="req2CA.ss";	# temp

39
my $Uconf=srctop_file("test","Uss.cnf");
40 41 42 43
my $Ukey="keyU.ss";
my $Ureq="reqU.ss";
my $Ucert="certU.ss";

44 45 46 47 48 49 50 51
my $Dkey="keyD.ss";
my $Dreq="reqD.ss";
my $Dcert="certD.ss";

my $Ekey="keyE.ss";
my $Ereq="reqE.ss";
my $Ecert="certE.ss";

52
my $P1conf=srctop_file("test","P1ss.cnf");
53 54 55 56 57
my $P1key="keyP1.ss";
my $P1req="reqP1.ss";
my $P1cert="certP1.ss";
my $P1intermediate="tmp_intP1.ss";

58
my $P2conf=srctop_file("test","P2ss.cnf");
59 60 61 62 63 64 65 66
my $P2key="keyP2.ss";
my $P2req="reqP2.ss";
my $P2cert="certP2.ss";
my $P2intermediate="tmp_intP2.ss";

plan tests =>
    1				# For testss
    + 1				# For ssltest -test_cipherlist
T
Todd Short 已提交
67
    + 13			# For the first testssl
R
Richard Levitte 已提交
68 69
    + 16			# For the first testsslproxy
    + 16			# For the second testsslproxy
70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93
    ;

subtest 'test_ss' => sub {
    if (testss()) {
	open OUT, ">", "intP1.ss";
	copy($CAcert, \*OUT); copy($Ucert, \*OUT);
	close OUT;

	open OUT, ">", "intP2.ss";
	copy($CAcert, \*OUT); copy($Ucert, \*OUT); copy($P1cert, \*OUT);
	close OUT;
    }
};

my $check = ok(run(test(["ssltest","-test_cipherlist"])), "running ssltest");

  SKIP: {
      skip "ssltest ended with error, skipping the rest", 3
	  if !$check;

      note('test_ssl -- key U');
      testssl("keyU.ss", $Ucert, $CAcert);

      note('test_ssl -- key P1');
R
Richard Levitte 已提交
94
      testsslproxy("keyP1.ss", "certP1.ss", "intP1.ss", "AB");
95 96

      note('test_ssl -- key P2');
R
Richard Levitte 已提交
97
      testsslproxy("keyP2.ss", "certP2.ss", "intP2.ss", "BC");
98 99 100 101 102 103 104 105 106
    }

# -----------
# subtest functions
sub testss {
    open RND, ">>", ".rnd";
    print RND "string to make the random number generator think it has entropy";
    close RND;

107
    my @req_dsa = ("-newkey",
108
                   "dsa:".srctop_file("apps", "dsa1024.pem"));
109
    my @req_new;
110
    if ($no_rsa) {
111
	@req_new = @req_dsa;
112 113 114 115
    } else {
	@req_new = ("-new");
    }

116
    plan tests => 17;
117 118

  SKIP: {
119
      skip 'failure', 16 unless
120 121 122 123 124
	  ok(run(app([@reqcmd, "-config", $CAconf,
		      "-out", $CAreq, "-keyout", $CAkey,
		      @req_new])),
	     'make cert request');

125
      skip 'failure', 15 unless
126 127 128 129 130 131
	  ok(run(app([@x509cmd, "-CAcreateserial", "-in", $CAreq, "-days", "30",
		      "-req", "-out", $CAcert, "-signkey", $CAkey,
		      "-extfile", $CAconf, "-extensions", "v3_ca"],
		     stdout => "err.ss")),
	     'convert request into self-signed cert');

132
      skip 'failure', 14 unless
133 134 135 136 137
	  ok(run(app([@x509cmd, "-in", $CAcert,
		      "-x509toreq", "-signkey", $CAkey, "-out", $CAreq2],
		     stdout => "err.ss")),
	     'convert cert into a cert request');

138
      skip 'failure', 13 unless
139 140 141 142 143
	  ok(run(app([@reqcmd, "-config", $dummycnf,
		      "-verify", "-in", $CAreq, "-noout"])),
	     'verify request 1');


144
      skip 'failure', 12 unless
145 146 147 148
	  ok(run(app([@reqcmd, "-config", $dummycnf,
		      "-verify", "-in", $CAreq2, "-noout"])),
	     'verify request 2');

149
      skip 'failure', 11 unless
150 151 152
	  ok(run(app([@verifycmd, "-CAfile", $CAcert, $CAcert])),
	     'verify signature');

153
      skip 'failure', 10 unless
154 155 156 157 158
	  ok(run(app([@reqcmd, "-config", $Uconf,
		      "-out", $Ureq, "-keyout", $Ukey, @req_new],
		     stdout => "err.ss")),
	     'make a user cert request');

159
      skip 'failure', 9 unless
160 161 162 163 164 165 166 167
	  ok(run(app([@x509cmd, "-CAcreateserial", "-in", $Ureq, "-days", "30",
		      "-req", "-out", $Ucert,
		      "-CA", $CAcert, "-CAkey", $CAkey, "-CAserial", $CAserial,
		      "-extfile", $Uconf, "-extensions", "v3_ee"],
		     stdout => "err.ss"))
	     && run(app([@verifycmd, "-CAfile", $CAcert, $Ucert])),
	     'sign user cert request');

168
      skip 'failure', 8 unless
169 170 171 172 173
	  ok(run(app([@x509cmd,
		      "-subject", "-issuer", "-startdate", "-enddate",
		      "-noout", "-in", $Ucert])),
	     'Certificate details');

174 175 176
      skip 'failure', 7 unless
          subtest 'DSA certificate creation' => sub {
              plan skip_all => "skipping DSA certificate creation"
177
                  if $no_dsa;
178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215

              plan tests => 4;

            SKIP: {
                $ENV{CN2} = "DSA Certificate";
                skip 'failure', 3 unless
                    ok(run(app([@reqcmd, "-config", $Uconf,
                                "-out", $Dreq, "-keyout", $Dkey,
                                @req_dsa],
                               stdout => "err.ss")),
                       "make a DSA user cert request");
                skip 'failure', 2 unless
                    ok(run(app([@x509cmd, "-CAcreateserial",
                                "-in", $Dreq,
                                "-days", "30",
                                "-req",
                                "-out", $Dcert,
                                "-CA", $CAcert, "-CAkey", $CAkey,
                                "-CAserial", $CAserial,
                                "-extfile", $Uconf,
                                "-extensions", "v3_ee_dsa"],
                               stdout => "err.ss")),
                       "sign DSA user cert request");
                skip 'failure', 1 unless
                    ok(run(app([@verifycmd, "-CAfile", $CAcert, $Dcert])),
                       "verify DSA user cert");
                skip 'failure', 0 unless
                    ok(run(app([@x509cmd,
                                "-subject", "-issuer",
                                "-startdate", "-enddate", "-noout",
                                "-in", $Dcert])),
                       "DSA Certificate details");
              }
      };

      skip 'failure', 6 unless
          subtest 'ECDSA/ECDH certificate creation' => sub {
              plan skip_all => "skipping ECDSA/ECDH certificate creation"
216
                  if $no_ec;
217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254

              plan tests => 5;

            SKIP: {
                $ENV{CN2} = "ECDSA Certificate";
                skip 'failure', 4 unless
                    ok(run(app(["openssl", "ecparam", "-name", "P-256",
                                "-out", "ecp.ss"])),
                       "make EC parameters");
                skip 'failure', 3 unless
                    ok(run(app([@reqcmd, "-config", $Uconf,
                                "-out", $Ereq, "-keyout", $Ekey,
                                "-newkey", "ec:ecp.ss"],
                               stdout => "err.ss")),
                       "make a ECDSA/ECDH user cert request");
                skip 'failure', 2 unless
                    ok(run(app([@x509cmd, "-CAcreateserial",
                                "-in", $Ereq,
                                "-days", "30",
                                "-req",
                                "-out", $Ecert,
                                "-CA", $CAcert, "-CAkey", $CAkey,
                                "-CAserial", $CAserial,
                                "-extfile", $Uconf,
                                "-extensions", "v3_ee_ec"],
                               stdout => "err.ss")),
                       "sign ECDSA/ECDH user cert request");
                skip 'failure', 1 unless
                    ok(run(app([@verifycmd, "-CAfile", $CAcert, $Ecert])),
                       "verify ECDSA/ECDH user cert");
                skip 'failure', 0 unless
                    ok(run(app([@x509cmd,
                                "-subject", "-issuer",
                                "-startdate", "-enddate", "-noout",
                                "-in", $Ecert])),
                       "ECDSA Certificate details");
              }
      };
255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308

      skip 'failure', 5 unless
	  ok(run(app([@reqcmd, "-config", $P1conf,
		      "-out", $P1req, "-keyout", $P1key, @req_new],
		     stdout => "err.ss")),
	     'make a proxy cert request');


      skip 'failure', 4 unless
	  ok(run(app([@x509cmd, "-CAcreateserial", "-in", $P1req, "-days", "30",
		      "-req", "-out", $P1cert,
		      "-CA", $Ucert, "-CAkey", $Ukey,
		      "-extfile", $P1conf, "-extensions", "v3_proxy"],
		     stdout => "err.ss")),
	     'sign proxy with user cert');

      copy($Ucert, $P1intermediate);
      run(app([@verifycmd, "-CAfile", $CAcert,
	       "-untrusted", $P1intermediate, $P1cert]));
      ok(run(app([@x509cmd,
		  "-subject", "-issuer", "-startdate", "-enddate",
		  "-noout", "-in", $P1cert])),
	 'Certificate details');

      skip 'failure', 2 unless
	  ok(run(app([@reqcmd, "-config", $P2conf,
		      "-out", $P2req, "-keyout", $P2key,
		      @req_new],
		     stdout => "err.ss")),
	     'make another proxy cert request');


      skip 'failure', 1 unless
	  ok(run(app([@x509cmd, "-CAcreateserial", "-in", $P2req, "-days", "30",
		      "-req", "-out", $P2cert,
		      "-CA", $P1cert, "-CAkey", $P1key,
		      "-extfile", $P2conf, "-extensions", "v3_proxy"],
		     stdout => "err.ss")),
	     'sign second proxy cert request with the first proxy cert');


      open OUT, ">", $P2intermediate;
      copy($Ucert, \*OUT); copy($P1cert, \*OUT);
      close OUT;
      run(app([@verifycmd, "-CAfile", $CAcert,
	       "-untrusted", $P2intermediate, $P2cert]));
      ok(run(app([@x509cmd,
		  "-subject", "-issuer", "-startdate", "-enddate",
		  "-noout", "-in", $P2cert])),
	 'Certificate details');
    }
}

sub testssl {
309 310
    my $key = shift || bldtop_file("apps","server.pem");
    my $cert = shift || bldtop_file("apps","server.pem");
311
    my $CAtmp = shift;
312
    my @CA = $CAtmp ? ("-CAfile", $CAtmp) : ("-CApath", bldtop_dir("certs"));
313 314 315
    my @extra = @_;

    my @ssltest = ("ssltest",
316
		   "-s_key", $key, "-s_cert", $cert,
317 318
		   "-c_key", $key, "-c_cert", $cert);

319
    my $serverinfo = srctop_file("test","serverinfo.pem");
320 321 322 323 324 325 326 327

    my $dsa_cert = 0;
    if (grep /DSA Public Key/, run(app(["openssl", "x509", "-in", $cert,
					"-text", "-noout"]), capture => 1)) {
	$dsa_cert = 1;
    }


328
    # plan tests => 11;
329 330 331

    subtest 'standard SSL tests' => sub {
	######################################################################
332
	plan tests => 29;
333

334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381 382 383 384 385 386 387 388 389 390
      SKIP: {
	  skip "SSLv3 is not supported by this OpenSSL build", 4
	      if disabled("ssl3");

	  ok(run(test([@ssltest, "-ssl3", @extra])),
	     'test sslv3');
	  ok(run(test([@ssltest, "-ssl3", "-server_auth", @CA, @extra])),
	     'test sslv3 with server authentication');
	  ok(run(test([@ssltest, "-ssl3", "-client_auth", @CA, @extra])),
	     'test sslv3 with client authentication');
	  ok(run(test([@ssltest, "-ssl3", "-server_auth", "-client_auth", @CA, @extra])),
	     'test sslv3 with both server and client authentication');
	}

      SKIP: {
	  skip "Neither SSLv3 nor any TLS version are supported by this OpenSSL build", 4
	      if $no_anytls;

	  ok(run(test([@ssltest, @extra])),
	     'test sslv2/sslv3');
	  ok(run(test([@ssltest, "-server_auth", @CA, @extra])),
	     'test sslv2/sslv3 with server authentication');
	  ok(run(test([@ssltest, "-client_auth", @CA, @extra])),
	     'test sslv2/sslv3 with client authentication');
	  ok(run(test([@ssltest, "-server_auth", "-client_auth", @CA, @extra])),
	     'test sslv2/sslv3 with both server and client authentication');
	}

      SKIP: {
	  skip "SSLv3 is not supported by this OpenSSL build", 4
	      if disabled("ssl3");

	  ok(run(test([@ssltest, "-bio_pair", "-ssl3", @extra])),
	     'test sslv3 via BIO pair');
	  ok(run(test([@ssltest, "-bio_pair", "-ssl3", "-server_auth", @CA, @extra])),
	     'test sslv3 with server authentication via BIO pair');
	  ok(run(test([@ssltest, "-bio_pair", "-ssl3", "-client_auth", @CA, @extra])),
	     'test sslv3 with client authentication via BIO pair');
	  ok(run(test([@ssltest, "-bio_pair", "-ssl3", "-server_auth", "-client_auth", @CA, @extra])),
	     'test sslv3 with both server and client authentication via BIO pair');
	}

      SKIP: {
	  skip "Neither SSLv3 nor any TLS version are supported by this OpenSSL build", 1
	      if $no_anytls;

	  ok(run(test([@ssltest, "-bio_pair", @extra])),
	     'test sslv2/sslv3 via BIO pair');
	}

      SKIP: {
	  skip "DTLSv1 is not supported by this OpenSSL build", 4
	      if disabled("dtls1");

	  ok(run(test([@ssltest, "-dtls1", @extra])),
	     'test dtlsv1');
	  ok(run(test([@ssltest, "-dtls1", "-server_auth", @CA, @extra])),
391
	   'test dtlsv1 with server authentication');
392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412
	  ok(run(test([@ssltest, "-dtls1", "-client_auth", @CA, @extra])),
	     'test dtlsv1 with client authentication');
	  ok(run(test([@ssltest, "-dtls1", "-server_auth", "-client_auth", @CA, @extra])),
	     'test dtlsv1 with both server and client authentication');
	}

      SKIP: {
	  skip "DTLSv1.2 is not supported by this OpenSSL build", 4
	      if disabled("dtls1_2");

	  ok(run(test([@ssltest, "-dtls12", @extra])),
	     'test dtlsv1.2');
	  ok(run(test([@ssltest, "-dtls12", "-server_auth", @CA, @extra])),
	     'test dtlsv1.2 with server authentication');
	  ok(run(test([@ssltest, "-dtls12", "-client_auth", @CA, @extra])),
	     'test dtlsv1.2 with client authentication');
	  ok(run(test([@ssltest, "-dtls12", "-server_auth", "-client_auth", @CA, @extra])),
	     'test dtlsv1.2 with both server and client authentication');
	}

      SKIP: {
413
	  skip "Neither SSLv3 nor any TLS version are supported by this OpenSSL build", 8
414 415 416 417 418 419 420 421 422 423 424 425 426 427 428 429 430 431 432
	      if $no_anytls;

	SKIP: {
	    skip "skipping test of sslv2/sslv3 w/o (EC)DHE test", 1 if $dsa_cert;

	    ok(run(test([@ssltest, "-bio_pair", "-no_dhe", "-no_ecdhe", @extra])),
	       'test sslv2/sslv3 w/o (EC)DHE via BIO pair');
	  }

	  ok(run(test([@ssltest, "-bio_pair", "-dhe1024dsa", "-v", @extra])),
	     'test sslv2/sslv3 with 1024bit DHE via BIO pair');
	  ok(run(test([@ssltest, "-bio_pair", "-server_auth", @CA, @extra])),
	     'test sslv2/sslv3 with server authentication');
	  ok(run(test([@ssltest, "-bio_pair", "-client_auth", @CA, @extra])),
	     'test sslv2/sslv3 with client authentication via BIO pair');
	  ok(run(test([@ssltest, "-bio_pair", "-server_auth", "-client_auth", @CA, @extra])),
	     'test sslv2/sslv3 with both client and server authentication via BIO pair');
	  ok(run(test([@ssltest, "-bio_pair", "-server_auth", "-client_auth", "-app_verify", @CA, @extra])),
	     'test sslv2/sslv3 with both client and server authentication via BIO pair and app verify');
433

434 435 436 437 438 439 440 441 442 443 444 445 446 447
        SKIP: {
            skip "No IPv4 available on this machine", 1
                unless have_IPv4();
            ok(run(test([@ssltest, "-ipv4", @extra])),
               'test TLS via IPv4');
          }
          
        SKIP: {
            skip "No IPv6 available on this machine", 1
                unless have_IPv6();
            ok(run(test([@ssltest, "-ipv6", @extra])),
               'test TLS via IPv6');
          }
        }
448 449 450 451
    };

    subtest "Testing ciphersuites" => sub {

452 453 454
        my @exkeys = ();
        my $ciphers = "-EXP:-PSK:-SRP:-kDH:-kECDHe";

455
        if ($no_dh) {
456 457 458
            note "skipping DHE tests\n";
            $ciphers .= ":-kDHE";
        }
459
        if ($no_dsa) {
460 461 462 463 464 465
            note "skipping DSA tests\n";
            $ciphers .= ":-aDSA";
        } else {
            push @exkeys, "-s_cert", "certD.ss", "-s_key", "keyD.ss";
        }

466
        if ($no_ec) {
467 468 469 470 471
            note "skipping EC tests\n";
            $ciphers .= ":!aECDSA:!kECDH";
        } else {
            push @exkeys, "-s_cert", "certE.ss", "-s_key", "keyE.ss";
        }
472

473
	my @protocols = ();
474
	# FIXME: I feel unsure about the following line, is that really just TLSv1.2, or is it all of the SSLv3/TLS protocols?
475 476
        push(@protocols, "TLSv1.2") unless $no_tls1_2;
        push(@protocols, "SSLv3") unless $no_ssl3;
477 478 479 480
	my $protocolciphersuitcount = 0;
	my %ciphersuites =
	    map { my @c =
		      map { split(/:/, $_) }
481 482
		      run(app(["openssl", "ciphers", "${_}:$ciphers"]),
                          capture => 1);
483
		  map { s/\R//; } @c;  # chomp @c;
484 485 486
		  $protocolciphersuitcount += scalar @c;
		  $_ => [ @c ] } @protocols;

487 488 489
        plan skip_all => "None of the ciphersuites to test are available in this OpenSSL build"
            if $protocolciphersuitcount + scalar(@protocols) == 0;

490 491 492
        # The count of protocols is because in addition to the ciphersuits
        # we got above, we're running a weak DH test for each protocol
	plan tests => $protocolciphersuitcount + scalar(@protocols);
493 494 495 496

	foreach my $protocol (@protocols) {
	    note "Testing ciphersuites for $protocol";
	    foreach my $cipher (@{$ciphersuites{$protocol}}) {
497
		ok(run(test([@ssltest, @exkeys, "-cipher", $cipher,
498 499 500
			     $protocol eq "SSLv3" ? ("-ssl3") : ()])),
		   "Testing $cipher");
	    }
501 502 503 504 505 506
            is(run(test([@ssltest,
                         "-s_cipher", "EDH",
                         "-c_cipher", 'EDH:@SECLEVEL=1',
                         "-dhe512",
                         $protocol eq "SSLv3" ? ("-ssl3") : ()])), 0,
               "testing connection with weak DH, expecting failure");
507 508 509 510 511 512 513 514
	}
    };

    subtest 'RSA/(EC)DHE/PSK tests' => sub {
	######################################################################

	plan tests => 5;

515 516 517
      SKIP: {
	  skip "TLSv1.0 is not supported by this OpenSSL build", 5
	      if $no_tls1;
518

519 520 521
	SKIP: {
	    skip "skipping anonymous DH tests", 1
	      if ($no_dh);
522

523 524 525
	    ok(run(test([@ssltest, "-v", "-bio_pair", "-tls1", "-cipher", "ADH", "-dhe1024dsa", "-num", "10", "-f", "-time", @extra])),
	       'test tlsv1 with 1024bit anonymous DH, multiple handshakes');
	  }
526

527 528 529
	SKIP: {
	    skip "skipping RSA tests", 2
		if $no_rsa;
530

531
	    ok(run(test(["ssltest", "-v", "-bio_pair", "-tls1", "-s_cert", srctop_file("apps","server2.pem"), "-no_dhe", "-no_ecdhe", "-num", "10", "-f", "-time", @extra])),
532
	       'test tlsv1 with 1024bit RSA, no (EC)DHE, multiple handshakes');
533

534 535 536
	    skip "skipping RSA+DHE tests", 1
		if $no_dh;

537
	    ok(run(test(["ssltest", "-v", "-bio_pair", "-tls1", "-s_cert", srctop_file("apps","server2.pem"), "-dhe1024dsa", "-num", "10", "-f", "-time", @extra])),
538 539 540 541 542
	       'test tlsv1 with 1024bit RSA, 1024bit DHE, multiple handshakes');
	  }

	SKIP: {
	    skip "skipping PSK tests", 2
D
Dr. Stephen Henson 已提交
543 544
	        if ($no_psk);

545 546
	    ok(run(test([@ssltest, "-tls1", "-cipher", "PSK", "-psk", "abc123", @extra])),
	       'test tls1 with PSK');
D
Dr. Stephen Henson 已提交
547

548 549 550 551
	    ok(run(test([@ssltest, "-bio_pair", "-tls1", "-cipher", "PSK", "-psk", "abc123", @extra])),
	       'test tls1 with PSK via BIO pair');
	  }
	}
552 553 554 555 556 557 558 559

    };

    subtest 'Next Protocol Negotiation Tests' => sub {
	######################################################################

	plan tests => 7;

560 561 562 563 564 565 566 567 568 569 570 571
      SKIP: {
	  skip "TLSv1.0 is not supported by this OpenSSL build", 7
	      if $no_tls1;

	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-npn_client"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-npn_server"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-npn_server_reject"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-npn_client", "-npn_server_reject"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-npn_client", "-npn_server"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-npn_client", "-npn_server", "-num", "2"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-npn_client", "-npn_server", "-num", "2", "-reuse"])));
	}
572 573 574 575 576 577 578
    };

    subtest 'Custom Extension tests' => sub {
	######################################################################

	plan tests => 1;

579
      SKIP: {
580
	  skip "TLSv1.0 is not supported by this OpenSSL build", 1
581 582 583 584 585
	      if $no_tls1;

	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-custom_ext"])),
	     'test tls1 with custom extensions');
	}
586 587 588 589 590 591 592
    };

    subtest 'Serverinfo tests' => sub {
	######################################################################

	plan tests => 5;

593 594 595 596 597 598 599 600 601 602 603
      SKIP: {
	  skip "TLSv1.0 is not supported by this OpenSSL build", 5
	      if $no_tls1;

	  note('echo test tls1 with serverinfo');
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-serverinfo_file", $serverinfo])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-serverinfo_file", $serverinfo, "-serverinfo_sct"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-serverinfo_file", $serverinfo, "-serverinfo_tack"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-serverinfo_file", $serverinfo, "-serverinfo_sct", "-serverinfo_tack"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-custom_ext", "-serverinfo_file", $serverinfo, "-serverinfo_sct", "-serverinfo_tack"])));
	}
604 605
    };

T
Todd Short 已提交
606 607 608 609 610 611 612 613 614 615 616 617 618 619 620 621 622 623 624
    subtest 'SNI tests' => sub {

	plan tests => 7;

      SKIP: {
	  skip "TLSv1.x is not supported by this OpenSSL build", 7
	      if $no_tls1 && $no_tls1_1 && $no_tls1_2;

	  ok(run(test([@ssltest, "-bio_pair", "-sn_client", "foo"])));
	  ok(run(test([@ssltest, "-bio_pair", "-sn_server1", "foo"])));
	  ok(run(test([@ssltest, "-bio_pair", "-sn_client", "foo", "-sn_server1", "foo", "-sn_expect1"])));
	  ok(run(test([@ssltest, "-bio_pair", "-sn_client", "foo", "-sn_server1", "bar", "-sn_expect1"])));
	  ok(run(test([@ssltest, "-bio_pair", "-sn_client", "foo", "-sn_server1", "foo", "-sn_server2", "bar", "-sn_expect1"])));
	  ok(run(test([@ssltest, "-bio_pair", "-sn_client", "bar", "-sn_server1", "foo", "-sn_server2", "bar", "-sn_expect2"])));
	  # Negative test - make sure it doesn't crash, and doesn't switch contexts
	  ok(run(test([@ssltest, "-bio_pair", "-sn_client", "foobar", "-sn_server1", "foo", "-sn_server2", "bar", "-sn_expect1"])));
	}
    };

625 626 627
    subtest 'ALPN tests' => sub {
	######################################################################

T
Todd Short 已提交
628
	plan tests => 12;
629

630 631 632 633
      SKIP: {
	  skip "TLSv1.0 is not supported by this OpenSSL build", 12
	      if $no_tls1;

634 635
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-alpn_client", "foo"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-alpn_server", "foo"])));
636 637 638 639 640 641
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-alpn_client", "foo", "-alpn_server", "foo", "-alpn_expected", "foo"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-alpn_client", "foo,bar", "-alpn_server", "foo", "-alpn_expected", "foo"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-alpn_client", "bar,foo", "-alpn_server", "foo", "-alpn_expected", "foo"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-alpn_client", "bar,foo", "-alpn_server", "foo,bar", "-alpn_expected", "foo"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-alpn_client", "bar,foo", "-alpn_server", "bar,foo", "-alpn_expected", "bar"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-alpn_client", "foo,bar", "-alpn_server", "bar,foo", "-alpn_expected", "bar"])));
642 643 644 645 646

	  is(run(test([@ssltest, "-bio_pair", "-tls1", "-alpn_client", "foo", "-alpn_server", "bar"])), 0,
             "Testing ALPN with protocol mismatch, expecting failure");
	  is(run(test([@ssltest, "-bio_pair", "-tls1", "-alpn_client", "baz", "-alpn_server", "bar,foo"])), 0,
             "Testing ALPN with protocol mismatch, expecting failure");
647

T
Todd Short 已提交
648 649 650 651 652 653 654 655 656 657 658 659 660
	  # ALPN + SNI
	  ok(run(test([@ssltest, "-bio_pair",
		       "-alpn_client", "foo,bar", "-sn_client", "alice",
		       "-alpn_server1", "foo,123", "-sn_server1", "alice",
		       "-alpn_server2", "bar,456", "-sn_server2", "bob",
		       "-alpn_expected", "foo"])));
	  ok(run(test([@ssltest, "-bio_pair",
		       "-alpn_client", "foo,bar", "-sn_client", "bob",
		       "-alpn_server1", "foo,123", "-sn_server1", "alice",
		       "-alpn_server2", "bar,456", "-sn_server2", "bob",
		       "-alpn_expected", "bar"])));
	}
    };
661

T
Todd Short 已提交
662
    subtest 'SRP tests' => sub {
663

T
Todd Short 已提交
664
	plan tests => 4;
665

T
Todd Short 已提交
666 667 668
      SKIP: {
	  skip "skipping SRP tests", 4
	      if $no_srp;
669

T
Todd Short 已提交
670 671 672 673 674 675 676 677 678 679 680
	  ok(run(test([@ssltest, "-tls1", "-cipher", "SRP", "-srpuser", "test", "-srppass", "abc123"])),
	     'test tls1 with SRP');

	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-cipher", "SRP", "-srpuser", "test", "-srppass", "abc123"])),
	     'test tls1 with SRP via BIO pair');

	  ok(run(test([@ssltest, "-tls1", "-cipher", "aSRP", "-srpuser", "test", "-srppass", "abc123"])),
	     'test tls1 with SRP auth');

	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-cipher", "aSRP", "-srpuser", "test", "-srppass", "abc123"])),
	     'test tls1 with SRP auth via BIO pair');
681 682 683 684 685 686 687 688
	}
    };

    subtest 'Multi-buffer tests' => sub {
	######################################################################

	plan tests => 2;

689 690 691 692 693 694 695 696 697 698 699 700 701 702
      SKIP: {
	  skip "Neither SSLv3 nor any TLS version are supported by this OpenSSL build", 2
	      if $no_anytls;

	  skip "skipping multi-buffer tests", 2
	      if @extra || (POSIX::uname())[4] ne "x86_64";

	  ok(run(test([@ssltest, "-cipher", "AES128-SHA",    "-bytes", "8m"])));

	  # We happen to know that AES128-SHA256 is TLSv1.2 only... for now.
	  skip "TLSv1.2 is not supported by this OpenSSL configuration", 1
	      if $no_tls1_2;

	  ok(run(test([@ssltest, "-cipher", "AES128-SHA256", "-bytes", "8m"])));
703 704
	}
    };
705

706 707 708 709 710 711 712 713 714 715 716 717
    subtest 'TLS Version min/max tests' => sub {
        my @protos;
        push(@protos, "ssl3") unless $no_ssl3;
        push(@protos, "tls1") unless $no_tls1;
        push(@protos, "tls1.1") unless $no_tls1_1;
        push(@protos, "tls1.2") unless $no_tls1_2;
        my @minprotos = (undef, @protos);
        my @maxprotos = (@protos, undef);
        my @shdprotos = (@protos, $protos[$#protos]);
        my $n = ((@protos+2) * (@protos+3))/2 - 2;
        my $ntests = $n * $n;
	plan tests => $ntests;
718
      SKIP: {
719 720 721 722 723 724 725 726 727 728 729 730 731 732 733 734 735 736 737 738 739 740 741 742 743 744 745 746 747 748 749 750 751
        skip "TLS disabled", 1 if $ntests == 1;

        my $should;
        for (my $smin = 0; $smin < @minprotos; ++$smin) {
        for (my $smax = $smin ? $smin - 1 : 0; $smax < @maxprotos; ++$smax) {
        for (my $cmin = 0; $cmin < @minprotos; ++$cmin) {
        for (my $cmax = $cmin ? $cmin - 1 : 0; $cmax < @maxprotos; ++$cmax) {
            if ($cmax < $smin-1) {
                $should = "fail-server";
            } elsif ($smax < $cmin-1) {
                $should = "fail-client";
            } elsif ($cmax > $smax) {
                $should = $shdprotos[$smax];
            } else {
                $should = $shdprotos[$cmax];
            }

            my @args = @ssltest;
            push(@args, "-should_negotiate", $should);
            push(@args, "-server_min_proto", $minprotos[$smin])
                if (defined($minprotos[$smin]));
            push(@args, "-server_max_proto", $maxprotos[$smax])
                if (defined($maxprotos[$smax]));
            push(@args, "-client_min_proto", $minprotos[$cmin])
                if (defined($minprotos[$cmin]));
            push(@args, "-client_max_proto", $maxprotos[$cmax])
                if (defined($maxprotos[$cmax]));
            my $ok = run(test[@args]);
            if (! $ok) {
                print STDERR "\nsmin=$smin, smax=$smax, cmin=$cmin, cmax=$cmax\n";
                print STDERR "\nFailed: @args\n";
            }
            ok($ok);
752
        }}}}}
753
    };
754

755 756 757 758 759 760 761 762 763 764
    subtest 'DTLS Version min/max tests' => sub {
        my @protos;
        push(@protos, "dtls1") unless ($no_dtls1 || $no_dtls);
        push(@protos, "dtls1.2") unless ($no_dtls1_2 || $no_dtls);
        my @minprotos = (undef, @protos);
        my @maxprotos = (@protos, undef);
        my @shdprotos = (@protos, $protos[$#protos]);
        my $n = ((@protos+2) * (@protos+3))/2 - 2;
        my $ntests = $n * $n;
	plan tests => $ntests;
765
      SKIP: {
766 767 768 769 770 771 772 773 774 775 776 777 778 779 780 781 782 783 784 785 786 787 788 789 790 791 792 793 794 795 796 797 798
        skip "DTLS disabled", 1 if $ntests == 1;

        my $should;
        for (my $smin = 0; $smin < @minprotos; ++$smin) {
        for (my $smax = $smin ? $smin - 1 : 0; $smax < @maxprotos; ++$smax) {
        for (my $cmin = 0; $cmin < @minprotos; ++$cmin) {
        for (my $cmax = $cmin ? $cmin - 1 : 0; $cmax < @maxprotos; ++$cmax) {
            if ($cmax < $smin-1) {
                $should = "fail-server";
            } elsif ($smax < $cmin-1) {
                $should = "fail-client";
            } elsif ($cmax > $smax) {
                $should = $shdprotos[$smax];
            } else {
                $should = $shdprotos[$cmax];
            }

            my @args = (@ssltest, "-dtls");
            push(@args, "-should_negotiate", $should);
            push(@args, "-server_min_proto", $minprotos[$smin])
                if (defined($minprotos[$smin]));
            push(@args, "-server_max_proto", $maxprotos[$smax])
                if (defined($maxprotos[$smax]));
            push(@args, "-client_min_proto", $minprotos[$cmin])
                if (defined($minprotos[$cmin]));
            push(@args, "-client_max_proto", $maxprotos[$cmax])
                if (defined($maxprotos[$cmax]));
            my $ok = run(test[@args]);
            if (! $ok) {
                print STDERR "\nsmin=$smin, smax=$smax, cmin=$cmin, cmax=$cmax\n";
                print STDERR "\nFailed: @args\n";
            }
            ok($ok);
799
        }}}}}
800
    };
801 802 803 804 805 806 807 808 809 810 811 812 813 814 815 816 817 818 819 820 821

    subtest 'Certificate Transparency tests' => sub {
	######################################################################

	plan tests => 3;

      SKIP: {
	  skip "Certificate Transparency is not supported by this OpenSSL build", 3
	      if $no_ct;
	  skip "TLSv1.0 is not supported by this OpenSSL build", 3
	      if $no_tls1;

    $ENV{CTLOG_FILE} = srctop_file("test", "ct", "log_list.conf");
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-noct"])));
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-requestct"])));
	  # No SCTs provided, so this should fail.
	  ok(run(test([@ssltest, "-bio_pair", "-tls1", "-requirect",
	               "-should_negotiate", "fail-client"])));
	}
    };

822 823 824
}

sub testsslproxy {
825 826
    my $key = shift || srctop_file("apps","server.pem");
    my $cert = shift || srctop_file("apps","server.pem");
R
Richard Levitte 已提交
827
    my $CAtmp = shift;
828
    my @CA = $CAtmp ? ("-CAfile", $CAtmp) : ("-CApath", bldtop_dir("certs"));
R
Richard Levitte 已提交
829 830 831 832 833
    my @extra = @_;

    my @ssltest = ("ssltest",
		   "-s_key", $key, "-s_cert", $cert,
		   "-c_key", $key, "-c_cert", $cert);
834 835 836 837

    # plan tests => 16;

    note('Testing a lot of proxy conditions.');
R
Richard Levitte 已提交
838 839 840 841 842 843 844 845 846 847 848 849 850 851 852 853 854 855 856 857 858 859 860 861 862 863 864 865 866 867 868 869 870 871 872 873 874 875 876 877 878 879 880

    # We happen to know that certP1.ss has policy letters "AB" and
    # certP2.ss has policy letters "BC".  However, because certP2.ss
    # has certP1.ss as issuer, when it's used, both their policy
    # letters get combined into just "B".
    # The policy letter(s) then get filtered with the given auth letter
    # in the table below, and the result gets tested with the given
    # condition.  For details, read ssltest.c
    #
    # certfilename => [ [ auth, cond, expected result ] ... ]
    my %expected = ( "certP1.ss" => [ [ [ 'A',  'A'      ], 1 ],
                                      [ [ 'A',  'B'      ], 0 ],
                                      [ [ 'A',  'C'      ], 0 ],
                                      [ [ 'A',  'A|B&!C' ], 1 ],
                                      [ [ 'B',  'A'      ], 0 ],
                                      [ [ 'B',  'B'      ], 1 ],
                                      [ [ 'B',  'C'      ], 0 ],
                                      [ [ 'B',  'A|B&!C' ], 1 ],
                                      [ [ 'C',  'A'      ], 0 ],
                                      [ [ 'C',  'B'      ], 0 ],
                                      [ [ 'C',  'C'      ], 0 ],
                                      [ [ 'C',  'A|B&!C' ], 0 ],
                                      [ [ 'BC', 'A'      ], 0 ],
                                      [ [ 'BC', 'B'      ], 1 ],
                                      [ [ 'BC', 'C'      ], 0 ],
                                      [ [ 'BC', 'A|B&!C' ], 1 ] ],
                     "certP2.ss" => [ [ [ 'A',  'A'      ], 0 ],
                                      [ [ 'A',  'B'      ], 0 ],
                                      [ [ 'A',  'C'      ], 0 ],
                                      [ [ 'A',  'A|B&!C' ], 0 ],
                                      [ [ 'B',  'A'      ], 0 ],
                                      [ [ 'B',  'B'      ], 1 ],
                                      [ [ 'B',  'C'      ], 0 ],
                                      [ [ 'B',  'A|B&!C' ], 1 ],
                                      [ [ 'C',  'A'      ], 0 ],
                                      [ [ 'C',  'B'      ], 0 ],
                                      [ [ 'C',  'C'      ], 0 ],
                                      [ [ 'C',  'A|B&!C' ], 0 ],
                                      [ [ 'BC', 'A'      ], 0 ],
                                      [ [ 'BC', 'B'      ], 1 ],
                                      [ [ 'BC', 'C'      ], 0 ],
                                      [ [ 'BC', 'A|B&!C' ], 1 ] ] );

881 882 883 884 885 886 887 888 889 890 891 892 893 894
  SKIP: {
      skip "Neither SSLv3 nor any TLS version are supported by this OpenSSL build", scalar(@{$expected{$cert}})
	  if $no_anytls;

      foreach (@{$expected{$cert}}) {
	  my $auth = $_->[0]->[0];
	  my $cond = $_->[0]->[1];
	  my $res  = $_->[1];
	  is(run(test([@ssltest, "-server_auth", @CA,
		       "-proxy", "-proxy_auth", $auth,
		       "-proxy_cond", $cond])), $res,
	     "test tlsv1, server auth, proxy auth $auth and cond $cond (expect "
	     .($res ? "success" : "failure").")");
      }
895 896
    }
}