Latest update.
This commit is contained in:
+344
-12
@@ -37,6 +37,10 @@
|
||||
#include "internal/ktls.h"
|
||||
#include "../ssl/ssl_local.h"
|
||||
|
||||
DEFINE_STACK_OF(OCSP_RESPID)
|
||||
DEFINE_STACK_OF(X509)
|
||||
DEFINE_STACK_OF(X509_NAME)
|
||||
|
||||
static OPENSSL_CTX *libctx = NULL;
|
||||
static OSSL_PROVIDER *defctxnull = NULL;
|
||||
|
||||
@@ -655,7 +659,6 @@ end:
|
||||
|
||||
return testresult;
|
||||
}
|
||||
#endif
|
||||
|
||||
/*
|
||||
* Very focused test to exercise a single case in the server-side state
|
||||
@@ -767,6 +770,7 @@ end:
|
||||
|
||||
return testresult;
|
||||
}
|
||||
#endif
|
||||
|
||||
static int execute_test_large_message(const SSL_METHOD *smeth,
|
||||
const SSL_METHOD *cmeth,
|
||||
@@ -1477,7 +1481,7 @@ static SSL_SESSION *get_session_cb(SSL *ssl, const unsigned char *id, int len,
|
||||
}
|
||||
|
||||
static int execute_test_session(int maxprot, int use_int_cache,
|
||||
int use_ext_cache)
|
||||
int use_ext_cache, long s_options)
|
||||
{
|
||||
SSL_CTX *sctx = NULL, *cctx = NULL;
|
||||
SSL *serverssl1 = NULL, *clientssl1 = NULL;
|
||||
@@ -1520,6 +1524,10 @@ static int execute_test_session(int maxprot, int use_int_cache,
|
||||
| SSL_SESS_CACHE_NO_INTERNAL_STORE);
|
||||
}
|
||||
|
||||
if (s_options) {
|
||||
SSL_CTX_set_options(sctx, s_options);
|
||||
}
|
||||
|
||||
if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl1, &clientssl1,
|
||||
NULL, NULL))
|
||||
|| !TEST_true(create_ssl_connection(serverssl1, clientssl1,
|
||||
@@ -1764,12 +1772,12 @@ static int execute_test_session(int maxprot, int use_int_cache,
|
||||
static int test_session_with_only_int_cache(void)
|
||||
{
|
||||
#ifndef OPENSSL_NO_TLS1_3
|
||||
if (!execute_test_session(TLS1_3_VERSION, 1, 0))
|
||||
if (!execute_test_session(TLS1_3_VERSION, 1, 0, 0))
|
||||
return 0;
|
||||
#endif
|
||||
|
||||
#ifndef OPENSSL_NO_TLS1_2
|
||||
return execute_test_session(TLS1_2_VERSION, 1, 0);
|
||||
return execute_test_session(TLS1_2_VERSION, 1, 0, 0);
|
||||
#else
|
||||
return 1;
|
||||
#endif
|
||||
@@ -1778,12 +1786,12 @@ static int test_session_with_only_int_cache(void)
|
||||
static int test_session_with_only_ext_cache(void)
|
||||
{
|
||||
#ifndef OPENSSL_NO_TLS1_3
|
||||
if (!execute_test_session(TLS1_3_VERSION, 0, 1))
|
||||
if (!execute_test_session(TLS1_3_VERSION, 0, 1, 0))
|
||||
return 0;
|
||||
#endif
|
||||
|
||||
#ifndef OPENSSL_NO_TLS1_2
|
||||
return execute_test_session(TLS1_2_VERSION, 0, 1);
|
||||
return execute_test_session(TLS1_2_VERSION, 0, 1, 0);
|
||||
#else
|
||||
return 1;
|
||||
#endif
|
||||
@@ -1792,17 +1800,32 @@ static int test_session_with_only_ext_cache(void)
|
||||
static int test_session_with_both_cache(void)
|
||||
{
|
||||
#ifndef OPENSSL_NO_TLS1_3
|
||||
if (!execute_test_session(TLS1_3_VERSION, 1, 1))
|
||||
if (!execute_test_session(TLS1_3_VERSION, 1, 1, 0))
|
||||
return 0;
|
||||
#endif
|
||||
|
||||
#ifndef OPENSSL_NO_TLS1_2
|
||||
return execute_test_session(TLS1_2_VERSION, 1, 1);
|
||||
return execute_test_session(TLS1_2_VERSION, 1, 1, 0);
|
||||
#else
|
||||
return 1;
|
||||
#endif
|
||||
}
|
||||
|
||||
static int test_session_wo_ca_names(void)
|
||||
{
|
||||
#ifndef OPENSSL_NO_TLS1_3
|
||||
if (!execute_test_session(TLS1_3_VERSION, 1, 0, SSL_OP_DISABLE_TLSEXT_CA_NAMES))
|
||||
return 0;
|
||||
#endif
|
||||
|
||||
#ifndef OPENSSL_NO_TLS1_2
|
||||
return execute_test_session(TLS1_2_VERSION, 1, 0, SSL_OP_DISABLE_TLSEXT_CA_NAMES);
|
||||
#else
|
||||
return 1;
|
||||
#endif
|
||||
}
|
||||
|
||||
|
||||
#ifndef OPENSSL_NO_TLS1_3
|
||||
static SSL_SESSION *sesscache[6];
|
||||
static int do_cache;
|
||||
@@ -2089,6 +2112,148 @@ static int test_psk_tickets(void)
|
||||
|
||||
return testresult;
|
||||
}
|
||||
|
||||
static int test_extra_tickets(int idx)
|
||||
{
|
||||
SSL_CTX *sctx = NULL, *cctx = NULL;
|
||||
SSL *serverssl = NULL, *clientssl = NULL;
|
||||
BIO *bretry = BIO_new(bio_s_always_retry());
|
||||
BIO *tmp = NULL;
|
||||
int testresult = 0;
|
||||
int stateful = 0;
|
||||
size_t nbytes;
|
||||
unsigned char c, buf[1];
|
||||
|
||||
new_called = 0;
|
||||
do_cache = 1;
|
||||
|
||||
if (idx >= 3) {
|
||||
idx -= 3;
|
||||
stateful = 1;
|
||||
}
|
||||
|
||||
if (!TEST_ptr(bretry) || !setup_ticket_test(stateful, idx, &sctx, &cctx))
|
||||
goto end;
|
||||
SSL_CTX_sess_set_new_cb(sctx, new_session_cb);
|
||||
/* setup_ticket_test() uses new_cachesession_cb which we don't need. */
|
||||
SSL_CTX_sess_set_new_cb(cctx, new_session_cb);
|
||||
|
||||
if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl,
|
||||
&clientssl, NULL, NULL)))
|
||||
goto end;
|
||||
|
||||
/*
|
||||
* Note that we have new_session_cb on both sctx and cctx, so new_called is
|
||||
* incremented by both client and server.
|
||||
*/
|
||||
if (!TEST_true(create_ssl_connection(serverssl, clientssl,
|
||||
SSL_ERROR_NONE))
|
||||
/* Check we got the number of tickets we were expecting */
|
||||
|| !TEST_int_eq(idx * 2, new_called)
|
||||
|| !TEST_true(SSL_new_session_ticket(serverssl))
|
||||
|| !TEST_true(SSL_new_session_ticket(serverssl))
|
||||
|| !TEST_int_eq(idx * 2, new_called))
|
||||
goto end;
|
||||
|
||||
/* Now try a (real) write to actually send the tickets */
|
||||
c = '1';
|
||||
if (!TEST_true(SSL_write_ex(serverssl, &c, 1, &nbytes))
|
||||
|| !TEST_size_t_eq(1, nbytes)
|
||||
|| !TEST_int_eq(idx * 2 + 2, new_called)
|
||||
|| !TEST_true(SSL_read_ex(clientssl, buf, sizeof(buf), &nbytes))
|
||||
|| !TEST_int_eq(idx * 2 + 4, new_called)
|
||||
|| !TEST_int_eq(sizeof(buf), nbytes)
|
||||
|| !TEST_int_eq(c, buf[0])
|
||||
|| !TEST_false(SSL_read_ex(clientssl, buf, sizeof(buf), &nbytes)))
|
||||
goto end;
|
||||
|
||||
/* Try with only requesting one new ticket, too */
|
||||
c = '2';
|
||||
new_called = 0;
|
||||
if (!TEST_true(SSL_new_session_ticket(serverssl))
|
||||
|| !TEST_true(SSL_write_ex(serverssl, &c, sizeof(c), &nbytes))
|
||||
|| !TEST_size_t_eq(sizeof(c), nbytes)
|
||||
|| !TEST_int_eq(1, new_called)
|
||||
|| !TEST_true(SSL_read_ex(clientssl, buf, sizeof(buf), &nbytes))
|
||||
|| !TEST_int_eq(2, new_called)
|
||||
|| !TEST_size_t_eq(sizeof(buf), nbytes)
|
||||
|| !TEST_int_eq(c, buf[0]))
|
||||
goto end;
|
||||
|
||||
/* Do it again but use dummy writes to drive the ticket generation */
|
||||
c = '3';
|
||||
new_called = 0;
|
||||
if (!TEST_true(SSL_new_session_ticket(serverssl))
|
||||
|| !TEST_true(SSL_new_session_ticket(serverssl))
|
||||
|| !TEST_true(SSL_write_ex(serverssl, &c, 0, &nbytes))
|
||||
|| !TEST_size_t_eq(0, nbytes)
|
||||
|| !TEST_int_eq(2, new_called)
|
||||
|| !TEST_false(SSL_read_ex(clientssl, buf, sizeof(buf), &nbytes))
|
||||
|| !TEST_int_eq(4, new_called))
|
||||
goto end;
|
||||
|
||||
/*
|
||||
* Use the always-retry BIO to exercise the logic that forces ticket
|
||||
* generation to wait until a record boundary.
|
||||
*/
|
||||
c = '4';
|
||||
new_called = 0;
|
||||
tmp = SSL_get_wbio(serverssl);
|
||||
if (!TEST_ptr(tmp) || !TEST_true(BIO_up_ref(tmp))) {
|
||||
tmp = NULL;
|
||||
goto end;
|
||||
}
|
||||
SSL_set0_wbio(serverssl, bretry);
|
||||
bretry = NULL;
|
||||
if (!TEST_false(SSL_write_ex(serverssl, &c, 1, &nbytes))
|
||||
|| !TEST_int_eq(SSL_get_error(serverssl, 0), SSL_ERROR_WANT_WRITE)
|
||||
|| !TEST_size_t_eq(nbytes, 0))
|
||||
goto end;
|
||||
/* Restore a BIO that will let the write succeed */
|
||||
SSL_set0_wbio(serverssl, tmp);
|
||||
tmp = NULL;
|
||||
/* These calls should just queue the request and not send anything. */
|
||||
if (!TEST_true(SSL_new_session_ticket(serverssl))
|
||||
|| !TEST_true(SSL_new_session_ticket(serverssl))
|
||||
|| !TEST_int_eq(0, new_called))
|
||||
goto end;
|
||||
/* Re-do the write; still no tickets sent */
|
||||
if (!TEST_true(SSL_write_ex(serverssl, &c, 1, &nbytes))
|
||||
|| !TEST_size_t_eq(1, nbytes)
|
||||
|| !TEST_int_eq(0, new_called)
|
||||
|| !TEST_true(SSL_read_ex(clientssl, buf, sizeof(buf), &nbytes))
|
||||
|| !TEST_int_eq(0, new_called)
|
||||
|| !TEST_int_eq(sizeof(buf), nbytes)
|
||||
|| !TEST_int_eq(c, buf[0])
|
||||
|| !TEST_false(SSL_read_ex(clientssl, buf, sizeof(buf), &nbytes)))
|
||||
goto end;
|
||||
/* Now the *next* write should send the tickets */
|
||||
c = '5';
|
||||
if (!TEST_true(SSL_write_ex(serverssl, &c, 1, &nbytes))
|
||||
|| !TEST_size_t_eq(1, nbytes)
|
||||
|| !TEST_int_eq(2, new_called)
|
||||
|| !TEST_true(SSL_read_ex(clientssl, buf, sizeof(buf), &nbytes))
|
||||
|| !TEST_int_eq(4, new_called)
|
||||
|| !TEST_int_eq(sizeof(buf), nbytes)
|
||||
|| !TEST_int_eq(c, buf[0])
|
||||
|| !TEST_false(SSL_read_ex(clientssl, buf, sizeof(buf), &nbytes)))
|
||||
goto end;
|
||||
|
||||
SSL_shutdown(clientssl);
|
||||
SSL_shutdown(serverssl);
|
||||
testresult = 1;
|
||||
|
||||
end:
|
||||
BIO_free(bretry);
|
||||
BIO_free(tmp);
|
||||
SSL_free(serverssl);
|
||||
SSL_free(clientssl);
|
||||
SSL_CTX_free(sctx);
|
||||
SSL_CTX_free(cctx);
|
||||
clientssl = serverssl = NULL;
|
||||
sctx = cctx = NULL;
|
||||
return testresult;
|
||||
}
|
||||
#endif
|
||||
|
||||
#define USE_NULL 0
|
||||
@@ -2590,8 +2755,11 @@ static unsigned int psk_server_cb(SSL *ssl, const char *identity,
|
||||
#define MSG6 "test"
|
||||
#define MSG7 "message."
|
||||
|
||||
#define TLS13_AES_256_GCM_SHA384_BYTES ((const unsigned char *)"\x13\x02")
|
||||
#define TLS13_AES_128_GCM_SHA256_BYTES ((const unsigned char *)"\x13\x01")
|
||||
#define TLS13_AES_256_GCM_SHA384_BYTES ((const unsigned char *)"\x13\x02")
|
||||
#define TLS13_CHACHA20_POLY1305_SHA256_BYTES ((const unsigned char *)"\x13\x03")
|
||||
#define TLS13_AES_128_CCM_SHA256_BYTES ((const unsigned char *)"\x13\x04")
|
||||
#define TLS13_AES_128_CCM_8_SHA256_BYTES ((const unsigned char *)"\x13\05")
|
||||
|
||||
|
||||
static SSL_SESSION *create_a_psk(SSL *ssl)
|
||||
@@ -3524,6 +3692,113 @@ static int test_early_data_psk(int idx)
|
||||
return testresult;
|
||||
}
|
||||
|
||||
/*
|
||||
* Test TLSv1.3 PSK can be used to send early_data with all 5 ciphersuites
|
||||
* idx == 0: Test with TLS1_3_RFC_AES_128_GCM_SHA256
|
||||
* idx == 1: Test with TLS1_3_RFC_AES_256_GCM_SHA384
|
||||
* idx == 2: Test with TLS1_3_RFC_CHACHA20_POLY1305_SHA256,
|
||||
* idx == 3: Test with TLS1_3_RFC_AES_128_CCM_SHA256
|
||||
* idx == 4: Test with TLS1_3_RFC_AES_128_CCM_8_SHA256
|
||||
*/
|
||||
static int test_early_data_psk_with_all_ciphers(int idx)
|
||||
{
|
||||
SSL_CTX *cctx = NULL, *sctx = NULL;
|
||||
SSL *clientssl = NULL, *serverssl = NULL;
|
||||
int testresult = 0;
|
||||
SSL_SESSION *sess = NULL;
|
||||
unsigned char buf[20];
|
||||
size_t readbytes, written;
|
||||
const SSL_CIPHER *cipher;
|
||||
const char *cipher_str[] = {
|
||||
TLS1_3_RFC_AES_128_GCM_SHA256,
|
||||
TLS1_3_RFC_AES_256_GCM_SHA384,
|
||||
# if !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305)
|
||||
TLS1_3_RFC_CHACHA20_POLY1305_SHA256,
|
||||
# else
|
||||
NULL,
|
||||
# endif
|
||||
TLS1_3_RFC_AES_128_CCM_SHA256,
|
||||
TLS1_3_RFC_AES_128_CCM_8_SHA256
|
||||
};
|
||||
const unsigned char *cipher_bytes[] = {
|
||||
TLS13_AES_128_GCM_SHA256_BYTES,
|
||||
TLS13_AES_256_GCM_SHA384_BYTES,
|
||||
# if !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305)
|
||||
TLS13_CHACHA20_POLY1305_SHA256_BYTES,
|
||||
# else
|
||||
NULL,
|
||||
# endif
|
||||
TLS13_AES_128_CCM_SHA256_BYTES,
|
||||
TLS13_AES_128_CCM_8_SHA256_BYTES
|
||||
};
|
||||
|
||||
if (cipher_str[idx] == NULL)
|
||||
return 1;
|
||||
/* Skip ChaCha20Poly1305 as currently FIPS module does not support it */
|
||||
if (idx == 2 && is_fips == 1)
|
||||
return 1;
|
||||
|
||||
/* We always set this up with a final parameter of "2" for PSK */
|
||||
if (!TEST_true(setupearly_data_test(&cctx, &sctx, &clientssl,
|
||||
&serverssl, &sess, 2)))
|
||||
goto end;
|
||||
|
||||
if (!TEST_true(SSL_set_ciphersuites(clientssl, cipher_str[idx]))
|
||||
|| !TEST_true(SSL_set_ciphersuites(serverssl, cipher_str[idx])))
|
||||
goto end;
|
||||
|
||||
/*
|
||||
* 'setupearly_data_test' creates only one instance of SSL_SESSION
|
||||
* and assigns to both client and server with incremented reference
|
||||
* and the same instance is updated in 'sess'.
|
||||
* So updating ciphersuite in 'sess' which will get reflected in
|
||||
* PSK handshake using psk use sess and find sess cb.
|
||||
*/
|
||||
cipher = SSL_CIPHER_find(clientssl, cipher_bytes[idx]);
|
||||
if (!TEST_ptr(cipher) || !TEST_true(SSL_SESSION_set_cipher(sess, cipher)))
|
||||
goto end;
|
||||
|
||||
SSL_set_connect_state(clientssl);
|
||||
if (!TEST_true(SSL_write_early_data(clientssl, MSG1, strlen(MSG1),
|
||||
&written)))
|
||||
goto end;
|
||||
|
||||
if (!TEST_int_eq(SSL_read_early_data(serverssl, buf, sizeof(buf),
|
||||
&readbytes),
|
||||
SSL_READ_EARLY_DATA_SUCCESS)
|
||||
|| !TEST_mem_eq(buf, readbytes, MSG1, strlen(MSG1))
|
||||
|| !TEST_int_eq(SSL_get_early_data_status(serverssl),
|
||||
SSL_EARLY_DATA_ACCEPTED)
|
||||
|| !TEST_int_eq(SSL_connect(clientssl), 1)
|
||||
|| !TEST_int_eq(SSL_accept(serverssl), 1))
|
||||
goto end;
|
||||
|
||||
/* Send some normal data from client to server */
|
||||
if (!TEST_true(SSL_write_ex(clientssl, MSG2, strlen(MSG2), &written))
|
||||
|| !TEST_size_t_eq(written, strlen(MSG2)))
|
||||
goto end;
|
||||
|
||||
if (!TEST_true(SSL_read_ex(serverssl, buf, sizeof(buf), &readbytes))
|
||||
|| !TEST_mem_eq(buf, readbytes, MSG2, strlen(MSG2)))
|
||||
goto end;
|
||||
|
||||
testresult = 1;
|
||||
end:
|
||||
SSL_SESSION_free(sess);
|
||||
SSL_SESSION_free(clientpsk);
|
||||
SSL_SESSION_free(serverpsk);
|
||||
clientpsk = serverpsk = NULL;
|
||||
if (clientssl != NULL)
|
||||
SSL_shutdown(clientssl);
|
||||
if (serverssl != NULL)
|
||||
SSL_shutdown(serverssl);
|
||||
SSL_free(serverssl);
|
||||
SSL_free(clientssl);
|
||||
SSL_CTX_free(sctx);
|
||||
SSL_CTX_free(cctx);
|
||||
return testresult;
|
||||
}
|
||||
|
||||
/*
|
||||
* Test that a server that doesn't try to read early data can handle a
|
||||
* client sending some.
|
||||
@@ -5518,6 +5793,8 @@ static int test_pha_key_update(void)
|
||||
|
||||
static SRP_VBASE *vbase = NULL;
|
||||
|
||||
DEFINE_STACK_OF(SRP_user_pwd)
|
||||
|
||||
static int ssl_srp_cb(SSL *s, int *ad, void *arg)
|
||||
{
|
||||
int ret = SSL3_AL_FATAL;
|
||||
@@ -6060,6 +6337,7 @@ static struct {
|
||||
const char *srvrciphers;
|
||||
const char *srvrtls13ciphers;
|
||||
const char *shared;
|
||||
const char *fipsshared;
|
||||
} shared_ciphers_data[] = {
|
||||
/*
|
||||
* We can't establish a connection (even in TLSv1.1) with these ciphersuites if
|
||||
@@ -6072,14 +6350,29 @@ static struct {
|
||||
NULL,
|
||||
"AES256-SHA:DHE-RSA-AES128-SHA",
|
||||
NULL,
|
||||
"AES256-SHA",
|
||||
"AES256-SHA"
|
||||
},
|
||||
# if !defined(OPENSSL_NO_CHACHA) \
|
||||
&& !defined(OPENSSL_NO_POLY1305) \
|
||||
&& !defined(OPENSSL_NO_EC)
|
||||
{
|
||||
TLS1_2_VERSION,
|
||||
"AES128-SHA:ECDHE-RSA-CHACHA20-POLY1305",
|
||||
NULL,
|
||||
"AES128-SHA:ECDHE-RSA-CHACHA20-POLY1305",
|
||||
NULL,
|
||||
"AES128-SHA:ECDHE-RSA-CHACHA20-POLY1305",
|
||||
"AES128-SHA"
|
||||
},
|
||||
# endif
|
||||
{
|
||||
TLS1_2_VERSION,
|
||||
"AES128-SHA:DHE-RSA-AES128-SHA:AES256-SHA",
|
||||
NULL,
|
||||
"AES128-SHA:DHE-RSA-AES256-SHA:AES256-SHA",
|
||||
NULL,
|
||||
"AES128-SHA:AES256-SHA",
|
||||
"AES128-SHA:AES256-SHA"
|
||||
},
|
||||
{
|
||||
@@ -6088,6 +6381,7 @@ static struct {
|
||||
NULL,
|
||||
"AES128-SHA:DHE-RSA-AES128-SHA",
|
||||
NULL,
|
||||
"AES128-SHA",
|
||||
"AES128-SHA"
|
||||
},
|
||||
#endif
|
||||
@@ -6104,7 +6398,8 @@ static struct {
|
||||
"AES256-SHA:AES128-SHA256",
|
||||
NULL,
|
||||
"TLS_AES_256_GCM_SHA384:TLS_CHACHA20_POLY1305_SHA256:"
|
||||
"TLS_AES_128_GCM_SHA256:AES256-SHA"
|
||||
"TLS_AES_128_GCM_SHA256:AES256-SHA",
|
||||
"TLS_AES_256_GCM_SHA384:TLS_AES_128_GCM_SHA256:AES256-SHA"
|
||||
},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_TLS1_3
|
||||
@@ -6114,17 +6409,39 @@ static struct {
|
||||
"TLS_AES_256_GCM_SHA384",
|
||||
"AES256-SHA",
|
||||
"TLS_AES_256_GCM_SHA384",
|
||||
"TLS_AES_256_GCM_SHA384",
|
||||
"TLS_AES_256_GCM_SHA384"
|
||||
},
|
||||
#endif
|
||||
};
|
||||
|
||||
static int test_ssl_get_shared_ciphers(int tst)
|
||||
static int int_test_ssl_get_shared_ciphers(int tst, int clnt)
|
||||
{
|
||||
SSL_CTX *cctx = NULL, *sctx = NULL;
|
||||
SSL *clientssl = NULL, *serverssl = NULL;
|
||||
int testresult = 0;
|
||||
char buf[1024];
|
||||
OPENSSL_CTX *tmplibctx = OPENSSL_CTX_new();
|
||||
|
||||
if (!TEST_ptr(tmplibctx))
|
||||
goto end;
|
||||
|
||||
/*
|
||||
* Regardless of whether we're testing with the FIPS provider loaded into
|
||||
* libctx, we want one peer to always use the full set of ciphersuites
|
||||
* available. Therefore we use a separate libctx with the default provider
|
||||
* loaded into it. We run the same tests twice - once with the client side
|
||||
* having the full set of ciphersuites and once with the server side.
|
||||
*/
|
||||
if (clnt) {
|
||||
cctx = SSL_CTX_new_with_libctx(tmplibctx, NULL, TLS_client_method());
|
||||
if (!TEST_ptr(cctx))
|
||||
goto end;
|
||||
} else {
|
||||
sctx = SSL_CTX_new_with_libctx(tmplibctx, NULL, TLS_server_method());
|
||||
if (!TEST_ptr(sctx))
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(),
|
||||
TLS_client_method(),
|
||||
@@ -6153,7 +6470,11 @@ static int test_ssl_get_shared_ciphers(int tst)
|
||||
goto end;
|
||||
|
||||
if (!TEST_ptr(SSL_get_shared_ciphers(serverssl, buf, sizeof(buf)))
|
||||
|| !TEST_int_eq(strcmp(buf, shared_ciphers_data[tst].shared), 0)) {
|
||||
|| !TEST_int_eq(strcmp(buf,
|
||||
is_fips
|
||||
? shared_ciphers_data[tst].fipsshared
|
||||
: shared_ciphers_data[tst].shared),
|
||||
0)) {
|
||||
TEST_info("Shared ciphers are: %s\n", buf);
|
||||
goto end;
|
||||
}
|
||||
@@ -6165,10 +6486,18 @@ static int test_ssl_get_shared_ciphers(int tst)
|
||||
SSL_free(clientssl);
|
||||
SSL_CTX_free(sctx);
|
||||
SSL_CTX_free(cctx);
|
||||
OPENSSL_CTX_free(tmplibctx);
|
||||
|
||||
return testresult;
|
||||
}
|
||||
|
||||
static int test_ssl_get_shared_ciphers(int tst)
|
||||
{
|
||||
return int_test_ssl_get_shared_ciphers(tst, 0)
|
||||
&& int_test_ssl_get_shared_ciphers(tst, 1);
|
||||
}
|
||||
|
||||
|
||||
static const char *appdata = "Hello World";
|
||||
static int gen_tick_called, dec_tick_called, tick_key_cb_called;
|
||||
static int tick_key_renew = 0;
|
||||
@@ -7385,10 +7714,12 @@ int setup_tests(void)
|
||||
ADD_TEST(test_session_with_only_int_cache);
|
||||
ADD_TEST(test_session_with_only_ext_cache);
|
||||
ADD_TEST(test_session_with_both_cache);
|
||||
ADD_TEST(test_session_wo_ca_names);
|
||||
#ifndef OPENSSL_NO_TLS1_3
|
||||
ADD_ALL_TESTS(test_stateful_tickets, 3);
|
||||
ADD_ALL_TESTS(test_stateless_tickets, 3);
|
||||
ADD_TEST(test_psk_tickets);
|
||||
ADD_ALL_TESTS(test_extra_tickets, 6);
|
||||
#endif
|
||||
ADD_ALL_TESTS(test_ssl_set_bio, TOTAL_SSL_SET_BIO_TESTS);
|
||||
ADD_TEST(test_ssl_bio_pop_next_bio);
|
||||
@@ -7420,6 +7751,7 @@ int setup_tests(void)
|
||||
ADD_ALL_TESTS(test_early_data_skip_abort, 3);
|
||||
ADD_ALL_TESTS(test_early_data_not_sent, 3);
|
||||
ADD_ALL_TESTS(test_early_data_psk, 8);
|
||||
ADD_ALL_TESTS(test_early_data_psk_with_all_ciphers, 5);
|
||||
ADD_ALL_TESTS(test_early_data_not_expected, 3);
|
||||
# ifndef OPENSSL_NO_TLS1_2
|
||||
ADD_ALL_TESTS(test_early_data_tls1_2, 3);
|
||||
|
||||
Reference in New Issue
Block a user