comparison ssl_sni_reneg.t @ 1853:36a4563f7f00

Tests: stick ssl_sni_reneg.t with TLSv1.2. To make it run after enabling TLSv1.3 by default in nginx 1.23.4.
author Sergey Kandaurov <pluknet@nginx.com>
date Tue, 11 Apr 2023 16:48:15 +0400
parents fd440d324700
children 0e1865aa9b33
comparison
equal deleted inserted replaced
1852:1197c152215b 1853:36a4563f7f00
53 http { 53 http {
54 %%TEST_GLOBALS_HTTP%% 54 %%TEST_GLOBALS_HTTP%%
55 55
56 ssl_certificate_key localhost.key; 56 ssl_certificate_key localhost.key;
57 ssl_certificate localhost.crt; 57 ssl_certificate localhost.crt;
58 ssl_protocols TLSv1.2;
58 59
59 server { 60 server {
60 listen 127.0.0.1:8080 ssl; 61 listen 127.0.0.1:8080 ssl;
61 listen 127.0.0.1:8081 ssl; 62 listen 127.0.0.1:8081 ssl;
62 server_name localhost; 63 server_name localhost;
91 . ">>$d/openssl.out 2>&1") == 0 92 . ">>$d/openssl.out 2>&1") == 0
92 or die "Can't create certificate for $name: $!\n"; 93 or die "Can't create certificate for $name: $!\n";
93 } 94 }
94 95
95 $t->run(); 96 $t->run();
96
97 {
98 my (undef, $ssl) = get_ssl_socket(8080);
99 plan(skip_all => "TLS 1.3 forbids renegotiation")
100 if Net::SSLeay::version($ssl) > 0x0303;
101 }
102
103 $t->plan(8); 97 $t->plan(8);
104 98
105 ############################################################################### 99 ###############################################################################
106 100
107 my ($s, $ssl) = get_ssl_socket(8080); 101 my ($s, $ssl) = get_ssl_socket(8080);