06-sni-ticket.conf.in 3.0 KB
Newer Older
T
Todd Short 已提交
1 2 3 4 5 6 7 8 9
# -*- mode: perl; -*-
# Copyright 2016-2016 The OpenSSL Project Authors. All Rights Reserved.
#
# Licensed under the OpenSSL license (the "License").  You may not use
# this file except in compliance with the License.  You can obtain a copy
# in the file LICENSE in the source distribution or at
# https://www.openssl.org/source/license.html


10
## Test SNI/Session tickets
T
Todd Short 已提交
11 12 13 14 15 16 17 18 19

use strict;
use warnings;

package ssltests;


our @tests = ();

20 21 22
#Note: MaxProtocol is set to TLSv1.2 as session tickets work differently in
#TLSv1.3.
#TODO(TLS1.3): Implement TLSv1.3 style session tickets
T
Todd Short 已提交
23 24
sub generate_tests() {
    foreach my $c ("SessionTicket", "-SessionTicket") {
25 26 27 28
        foreach my $s1 ("SessionTicket", "-SessionTicket") {
            foreach my $s2 ("SessionTicket", "-SessionTicket") {
                foreach my $n ("server1", "server2") {
                    my $result = expected_result($c, $s1, $s2, $n);
T
Todd Short 已提交
29 30 31 32
                    push @tests, {
                        "name" => "sni-session-ticket",
                        "client" => {
                            "Options" => $c,
E
Emilia Kasper 已提交
33 34 35
                            "extra" => {
                                "ServerName" => $n,
                            },
36
                            "MaxProtocol" => "TLSv1.2"
T
Todd Short 已提交
37 38 39
                        },
                        "server" => {
                            "Options" => $s1,
E
Emilia Kasper 已提交
40 41 42 43
                            "extra" => {
                                # We don't test mismatch here.
                                "ServerNameCallback" => "IgnoreMismatch",
                            },
T
Todd Short 已提交
44
                        },
45 46 47
                        "server2" => {
                            "Options" => $s2,
                        },
T
Todd Short 已提交
48
                        "test" => {
49
                            "ExpectedServerName" => $n,
T
Todd Short 已提交
50
                            "ExpectedResult" => "Success",
51
                            "SessionTicketExpected" => $result,
T
Todd Short 已提交
52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78
                        }
                    };
                }
            }
        }
    }
}

# If the client has session tickets disabled, then No support
# If the server initial_ctx has session tickets disabled, then No support
# If SNI is in use, then if the "switched-to" context has session tickets disabled,
#    then No support
sub expected_result {
    my ($c, $s1, $s2, $n) = @_;

    return "No" if $c eq "-SessionTicket";
    return "No" if $s1 eq "-SessionTicket";
    return "No" if ($s2 eq "-SessionTicket" && $n eq "server2");

    return "Yes";

}

# Add a "Broken" case.
push @tests, {
    "name" => "sni-session-ticket",
    "client" => {
79 80
        "MaxProtocol" => "TLSv1.2",
        "Options" => "SessionTicket",
E
Emilia Kasper 已提交
81 82 83
        "extra" => {
            "ServerName" => "server1",
        }
T
Todd Short 已提交
84 85
    },
    "server" => {
86
        "Options" => "SessionTicket",
E
Emilia Kasper 已提交
87 88 89
        "extra" => {
              "BrokenSessionTicket" => "Yes",
        },
T
Todd Short 已提交
90 91
    },
    "server2" => {
92
        "Options" => "SessionTicket",
T
Todd Short 已提交
93 94
    },
    "test" => {
95 96
        "ExpectedResult" => "Success",
        "SessionTicketExpected" => "No",
T
Todd Short 已提交
97 98 99 100
    }
};

generate_tests();