Mercurial > hg > nginx-tests
annotate ssl_sni.t @ 1860:58951cf933e1
Tests: added has_feature() test for SSL libraries.
This makes it possible to further simplify various SSL tests. It also
avoids direct testing of the $t->{_configure_args} internal field, and
implements proper comparison of version numbers.
author | Maxim Dounin <mdounin@mdounin.ru> |
---|---|
date | Thu, 18 May 2023 18:07:06 +0300 |
parents | cdcd75657e52 |
children | a797d7428fa5 |
rev | line source |
---|---|
237 | 1 #!/usr/bin/perl |
2 | |
3 # (C) Maxim Dounin | |
4 # (C) Valentin Bartenev | |
5 | |
6 # Tests for Server Name Indication (SNI) TLS extension | |
7 | |
8 ############################################################################### | |
9 | |
10 use warnings; | |
11 use strict; | |
12 | |
13 use Test::More; | |
14 | |
15 BEGIN { use FindBin; chdir($FindBin::Bin); } | |
16 | |
17 use lib 'lib'; | |
18 use Test::Nginx; | |
19 | |
20 ############################################################################### | |
21 | |
22 select STDERR; $| = 1; | |
23 select STDOUT; $| = 1; | |
24 | |
1858
cdcd75657e52
Tests: added has_feature() tests for IO::Socket::SSL.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1841
diff
changeset
|
25 my $t = Test::Nginx->new()->has(qw/http http_ssl sni rewrite socket_ssl_sni/) |
cdcd75657e52
Tests: added has_feature() tests for IO::Socket::SSL.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1841
diff
changeset
|
26 ->has_daemon('openssl')->plan(8) |
237 | 27 ->write_file_expand('nginx.conf', <<'EOF'); |
28 | |
29 %%TEST_GLOBALS%% | |
30 | |
249
6a0d934950bc
Tests: remove extra spaces in "daemon off".
Maxim Dounin <mdounin@mdounin.ru>
parents:
246
diff
changeset
|
31 daemon off; |
237 | 32 |
33 events { | |
34 } | |
35 | |
36 http { | |
37 %%TEST_GLOBALS_HTTP%% | |
38 | |
39 server { | |
974
882267679006
Tests: simplified parallel modifications in tests.
Andrey Zelenkov <zelenkov@nginx.com>
parents:
952
diff
changeset
|
40 listen 127.0.0.1:8080 ssl; |
237 | 41 server_name localhost; |
42 | |
43 ssl_certificate_key localhost.key; | |
44 ssl_certificate localhost.crt; | |
45 | |
46 location / { | |
47 return 200 $server_name; | |
48 } | |
1478
f9718a0773b9
Tests: skip TLS 1.3 session reuse tests with older Perl modules.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1450
diff
changeset
|
49 |
f9718a0773b9
Tests: skip TLS 1.3 session reuse tests with older Perl modules.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1450
diff
changeset
|
50 location /protocol { |
f9718a0773b9
Tests: skip TLS 1.3 session reuse tests with older Perl modules.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1450
diff
changeset
|
51 return 200 $ssl_protocol; |
f9718a0773b9
Tests: skip TLS 1.3 session reuse tests with older Perl modules.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1450
diff
changeset
|
52 } |
237 | 53 } |
54 | |
55 server { | |
974
882267679006
Tests: simplified parallel modifications in tests.
Andrey Zelenkov <zelenkov@nginx.com>
parents:
952
diff
changeset
|
56 listen 127.0.0.1:8080; |
237 | 57 server_name example.com; |
58 | |
59 ssl_certificate_key example.com.key; | |
60 ssl_certificate example.com.crt; | |
61 | |
62 location / { | |
63 return 200 $server_name; | |
64 } | |
65 } | |
1449
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
66 |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
67 server { |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
68 listen 127.0.0.1:8081 ssl; |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
69 server_name localhost; |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
70 |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
71 ssl_certificate_key localhost.key; |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
72 ssl_certificate localhost.crt; |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
73 |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
74 location / { |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
75 return 200 $ssl_session_reused:$ssl_server_name; |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
76 } |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
77 } |
237 | 78 } |
79 | |
80 EOF | |
81 | |
82 $t->write_file('openssl.conf', <<EOF); | |
83 [ req ] | |
1488
dbce8fb5f5f8
Tests: align with OpenSSL security level 2.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1478
diff
changeset
|
84 default_bits = 2048 |
237 | 85 encrypt_key = no |
86 distinguished_name = req_distinguished_name | |
87 [ req_distinguished_name ] | |
88 EOF | |
89 | |
90 my $d = $t->testdir(); | |
91 | |
92 foreach my $name ('localhost', 'example.com') { | |
93 system('openssl req -x509 -new ' | |
1220
0af58b78df35
Tests: removed single quotes from system() calls.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1116
diff
changeset
|
94 . "-config $d/openssl.conf -subj /CN=$name/ " |
0af58b78df35
Tests: removed single quotes from system() calls.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1116
diff
changeset
|
95 . "-out $d/$name.crt -keyout $d/$name.key " |
237 | 96 . ">>$d/openssl.out 2>&1") == 0 |
97 or die "Can't create certificate for $name: $!\n"; | |
98 } | |
99 | |
100 $t->run(); | |
101 | |
102 ############################################################################### | |
103 | |
104 like(get_cert_cn(), qr!/CN=localhost!, 'default cert'); | |
105 like(get_cert_cn('example.com'), qr!/CN=example.com!, 'sni cert'); | |
106 | |
107 like(https_get_host('example.com'), qr!example.com!, | |
108 'host exists, sni exists, and host is equal sni'); | |
109 | |
110 like(https_get_host('example.com', 'example.org'), qr!example.com!, | |
111 'host exists, sni not found'); | |
112 | |
113 TODO: { | |
114 local $TODO = 'sni restrictions'; | |
115 | |
116 like(https_get_host('example.com', 'localhost'), qr!400 Bad Request!, | |
117 'host exists, sni exists, and host is not equal sni'); | |
118 | |
119 like(https_get_host('example.org', 'example.com'), qr!400 Bad Request!, | |
120 'host not found, sni exists'); | |
121 | |
122 } | |
123 | |
1449
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
124 # $ssl_server_name in sessions |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
125 |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
126 my $ctx = new IO::Socket::SSL::SSL_Context( |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
127 SSL_verify_mode => IO::Socket::SSL::SSL_VERIFY_NONE(), |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
128 SSL_session_cache_size => 100); |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
129 |
1450
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
130 like(get('/', 'localhost', 8081, $ctx), qr/^\.:localhost$/m, 'ssl server name'); |
1449
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
131 |
1841
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
132 TODO: { |
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
133 local $TODO = 'no TLSv1.3 sessions, old Net::SSLeay' |
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
134 if $Net::SSLeay::VERSION < 1.88 && test_tls13(); |
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
135 local $TODO = 'no TLSv1.3 sessions, old IO::Socket::SSL' |
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
136 if $IO::Socket::SSL::VERSION < 2.061 && test_tls13(); |
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
137 local $TODO = 'no TLSv1.3 sessions in LibreSSL' |
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
138 if $t->has_module('LibreSSL') && test_tls13(); |
1478
f9718a0773b9
Tests: skip TLS 1.3 session reuse tests with older Perl modules.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1450
diff
changeset
|
139 |
1450
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
140 like(get('/', 'localhost', 8081, $ctx), qr/^r:localhost$/m, |
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
141 'ssl server name - reused'); |
1449
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
142 |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
143 } |
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
144 |
237 | 145 ############################################################################### |
146 | |
1841
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
147 sub test_tls13 { |
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
148 get('/protocol', 'localhost') =~ /TLSv1.3/; |
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
149 } |
db6fd9184fa0
Tests: fixed ssl_sni.t with LibreSSL and TLSv1.3.
Maxim Dounin <mdounin@mdounin.ru>
parents:
1535
diff
changeset
|
150 |
237 | 151 sub get_ssl_socket { |
1449
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
152 my ($host, $port, $ctx) = @_; |
237 | 153 my $s; |
154 | |
155 eval { | |
156 local $SIG{ALRM} = sub { die "timeout\n" }; | |
157 local $SIG{PIPE} = sub { die "sigpipe\n" }; | |
1421
4e48bf51714f
Tests: aligned various generic read timeouts to http_end().
Sergey Kandaurov <pluknet@nginx.com>
parents:
1407
diff
changeset
|
158 alarm(8); |
237 | 159 $s = IO::Socket::SSL->new( |
160 Proto => 'tcp', | |
1449
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
161 PeerAddr => '127.0.0.1:' . port($port || 8080), |
237 | 162 SSL_hostname => $host, |
1449
eeababfd8726
Tests: moved $ssl_server_name tests in http to ssl_sni.t.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1421
diff
changeset
|
163 SSL_reuse_ctx => $ctx, |
246
6072306b7924
Tests: set SSL_verify_mode explicitly.
Homutov Vladimir <vl@nginx.com>
parents:
243
diff
changeset
|
164 SSL_verify_mode => IO::Socket::SSL::SSL_VERIFY_NONE(), |
237 | 165 SSL_error_trap => sub { die $_[1] } |
166 ); | |
167 alarm(0); | |
168 }; | |
169 alarm(0); | |
170 | |
171 if ($@) { | |
172 log_in("died: $@"); | |
173 return undef; | |
174 } | |
175 | |
176 return $s; | |
177 } | |
178 | |
179 sub get_cert_cn { | |
180 my ($host) = @_; | |
181 my $s = get_ssl_socket($host); | |
182 | |
183 return $s->dump_peer_certificate(); | |
184 } | |
185 | |
186 sub https_get_host { | |
243
de7338227832
Tests: removed trailing spaces.
Homutov Vladimir <vl@nginx.com>
parents:
237
diff
changeset
|
187 my ($host, $sni) = @_; |
237 | 188 my $s = get_ssl_socket($sni ? $sni : $host); |
189 | |
190 return http(<<EOF, socket => $s); | |
191 GET / HTTP/1.0 | |
192 Host: $host | |
193 | |
194 EOF | |
195 } | |
196 | |
1450
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
197 sub get { |
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
198 my ($uri, $host, $port, $ctx) = @_; |
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
199 my $s = get_ssl_socket($host, $port, $ctx) or return; |
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
200 my $r = http_get($uri, socket => $s); |
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
201 $s->close(); |
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
202 return $r; |
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
203 } |
5f53a1d6b83c
Tests: fixed session reuse in ssl_sni.t with OpenSSL 1.1.0+.
Sergey Kandaurov <pluknet@nginx.com>
parents:
1449
diff
changeset
|
204 |
237 | 205 ############################################################################### |