Update - OpenSSL 1.1.1-pre7-dev
This commit is contained in:
@@ -7,6 +7,8 @@
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
use strict;
|
||||
use feature 'state';
|
||||
|
||||
use OpenSSL::Test qw/:DEFAULT cmdstr srctop_file bldtop_dir/;
|
||||
use OpenSSL::Test::Utils;
|
||||
use TLSProxy::Proxy;
|
||||
@@ -37,6 +39,7 @@ use constant {
|
||||
};
|
||||
|
||||
my $testtype;
|
||||
my $fatal_alert = 0; # set by filter on fatal alert
|
||||
|
||||
$ENV{OPENSSL_ia32cap} = '~0x200000200000000';
|
||||
my $proxy = TLSProxy::Proxy->new(
|
||||
@@ -98,11 +101,13 @@ sub inject_duplicate_extension_clienthello
|
||||
my $proxy = shift;
|
||||
|
||||
# We're only interested in the initial ClientHello
|
||||
if ($proxy->flight != 0) {
|
||||
if ($proxy->flight == 0) {
|
||||
inject_duplicate_extension($proxy, TLSProxy::Message::MT_CLIENT_HELLO);
|
||||
return;
|
||||
}
|
||||
|
||||
inject_duplicate_extension($proxy, TLSProxy::Message::MT_CLIENT_HELLO);
|
||||
my $last_record = @{$proxy->{record_list}}[-1];
|
||||
$fatal_alert = 1 if $last_record->is_fatal_alert(1);
|
||||
}
|
||||
|
||||
sub inject_duplicate_extension_serverhello
|
||||
@@ -110,26 +115,43 @@ sub inject_duplicate_extension_serverhello
|
||||
my $proxy = shift;
|
||||
|
||||
# We're only interested in the initial ServerHello
|
||||
if ($proxy->flight != 1) {
|
||||
if ($proxy->flight == 0) {
|
||||
return;
|
||||
} elsif ($proxy->flight == 1) {
|
||||
inject_duplicate_extension($proxy, TLSProxy::Message::MT_SERVER_HELLO);
|
||||
return;
|
||||
}
|
||||
|
||||
inject_duplicate_extension($proxy, TLSProxy::Message::MT_SERVER_HELLO);
|
||||
my $last_record = @{$proxy->{record_list}}[-1];
|
||||
$fatal_alert = 1 if $last_record->is_fatal_alert(0);
|
||||
}
|
||||
|
||||
sub inject_unsolicited_extension
|
||||
{
|
||||
my $proxy = shift;
|
||||
my $message;
|
||||
state $sent_unsolisited_extension;
|
||||
|
||||
if ($proxy->flight == 0) {
|
||||
$sent_unsolisited_extension = 0;
|
||||
return;
|
||||
}
|
||||
|
||||
# We're only interested in the initial ServerHello/EncryptedExtensions
|
||||
if ($proxy->flight != 1) {
|
||||
if ($sent_unsolisited_extension) {
|
||||
my $last_record = @{$proxy->record_list}[-1];
|
||||
$fatal_alert = 1 if $last_record->is_fatal_alert(0);
|
||||
}
|
||||
return;
|
||||
}
|
||||
|
||||
if ($testtype == UNSOLICITED_SERVER_NAME_TLS13) {
|
||||
$message = ${$proxy->message_list}[2];
|
||||
die "Expecting EE message ".($message->mt).", ".${$proxy->message_list}[1]->mt.", ".${$proxy->message_list}[3]->mt if $message->mt != TLSProxy::Message::MT_ENCRYPTED_EXTENSIONS;
|
||||
return if (!defined($message = ${$proxy->message_list}[2]));
|
||||
die "Expecting EE message ".($message->mt).","
|
||||
.${$proxy->message_list}[1]->mt.", "
|
||||
.${$proxy->message_list}[3]->mt
|
||||
if $message->mt != TLSProxy::Message::MT_ENCRYPTED_EXTENSIONS;
|
||||
} else {
|
||||
$message = ${$proxy->message_list}[1];
|
||||
}
|
||||
@@ -148,17 +170,19 @@ sub inject_unsolicited_extension
|
||||
}
|
||||
$message->set_extension($type, $ext);
|
||||
$message->repack();
|
||||
$sent_unsolisited_extension = 1;
|
||||
}
|
||||
|
||||
# Test 1-2: Sending a duplicate extension should fail.
|
||||
$proxy->start() or plan skip_all => "Unable to start up Proxy for tests";
|
||||
plan tests => 7;
|
||||
ok(TLSProxy::Message->fail(), "Duplicate ClientHello extension");
|
||||
ok($fatal_alert, "Duplicate ClientHello extension");
|
||||
|
||||
$fatal_alert = 0;
|
||||
$proxy->clear();
|
||||
$proxy->filter(\&inject_duplicate_extension_serverhello);
|
||||
$proxy->start();
|
||||
ok(TLSProxy::Message->fail(), "Duplicate ServerHello extension");
|
||||
ok($fatal_alert, "Duplicate ServerHello extension");
|
||||
|
||||
SKIP: {
|
||||
skip "TLS <= 1.2 disabled", 3 if $no_below_tls13;
|
||||
@@ -170,12 +194,13 @@ SKIP: {
|
||||
ok(TLSProxy::Message->success, "Zero extension length test");
|
||||
|
||||
#Test 4: Inject an unsolicited extension (<= TLSv1.2)
|
||||
$fatal_alert = 0;
|
||||
$proxy->clear();
|
||||
$proxy->filter(\&inject_unsolicited_extension);
|
||||
$testtype = UNSOLICITED_SERVER_NAME;
|
||||
$proxy->clientflags("-no_tls1_3 -noservername");
|
||||
$proxy->start();
|
||||
ok(TLSProxy::Message->fail(), "Unsolicited server name extension");
|
||||
ok($fatal_alert, "Unsolicited server name extension");
|
||||
|
||||
#Test 5: Inject a noncompliant supported_groups extension (<= TLSv1.2)
|
||||
$proxy->clear();
|
||||
@@ -190,20 +215,22 @@ SKIP: {
|
||||
skip "TLS <= 1.2 or CT disabled", 1
|
||||
if $no_below_tls13 || disabled("ct");
|
||||
#Test 6: Same as above for the SCT extension which has special handling
|
||||
$fatal_alert = 0;
|
||||
$proxy->clear();
|
||||
$testtype = UNSOLICITED_SCT;
|
||||
$proxy->clientflags("-no_tls1_3");
|
||||
$proxy->start();
|
||||
ok(TLSProxy::Message->fail(), "Unsolicited sct extension");
|
||||
ok($fatal_alert, "Unsolicited sct extension");
|
||||
}
|
||||
|
||||
SKIP: {
|
||||
skip "TLS 1.3 disabled", 1 if disabled("tls1_3");
|
||||
#Test 7: Inject an unsolicited extension (TLSv1.3)
|
||||
$fatal_alert = 0;
|
||||
$proxy->clear();
|
||||
$proxy->filter(\&inject_unsolicited_extension);
|
||||
$testtype = UNSOLICITED_SERVER_NAME_TLS13;
|
||||
$proxy->clientflags("-noservername");
|
||||
$proxy->start();
|
||||
ok(TLSProxy::Message->fail(), "Unsolicited server name extension (TLSv1.3)");
|
||||
ok($fatal_alert, "Unsolicited server name extension (TLSv1.3)");
|
||||
}
|
||||
Reference in New Issue
Block a user