mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2025-04-16 08:42:50 +00:00
ssl-opt.sh: Expand MbedTLS only version negotiation tests
Signed-off-by: Ronald Cron <ronald.cron@arm.com>
This commit is contained in:
parent
dcfd00c128
commit
114c5f0321
107
tests/ssl-opt.sh
107
tests/ssl-opt.sh
@ -6873,9 +6873,93 @@ run_test "Event-driven I/O, DTLS: session-id resume, UDP packing" \
|
|||||||
|
|
||||||
# Tests for version negotiation, MbedTLS client and server
|
# Tests for version negotiation, MbedTLS client and server
|
||||||
|
|
||||||
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C
|
||||||
|
requires_config_disabled MBEDTLS_SSL_PROTO_TLS1_3
|
||||||
|
requires_any_configs_enabled $TLS1_2_KEY_EXCHANGES_WITH_CERT
|
||||||
|
run_test "Version negotiation check m->m: 1.2 / 1.2 -> 1.2" \
|
||||||
|
"$P_SRV" \
|
||||||
|
"$P_CLI" \
|
||||||
|
0 \
|
||||||
|
-S "mbedtls_ssl_handshake returned" \
|
||||||
|
-C "mbedtls_ssl_handshake returned" \
|
||||||
|
-s "Protocol is TLSv1.2" \
|
||||||
|
-c "Protocol is TLSv1.2"
|
||||||
|
|
||||||
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
||||||
|
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3
|
||||||
|
requires_any_configs_enabled $TLS1_2_KEY_EXCHANGES_WITH_CERT
|
||||||
|
run_test "Version negotiation check m->m: 1.2 (max=1.2) / 1.2 (max=1.2) -> 1.2" \
|
||||||
|
"$P_SRV max_version=tls12" \
|
||||||
|
"$P_CLI max_version=tls12" \
|
||||||
|
0 \
|
||||||
|
-S "mbedtls_ssl_handshake returned" \
|
||||||
|
-C "mbedtls_ssl_handshake returned" \
|
||||||
|
-s "Protocol is TLSv1.2" \
|
||||||
|
-c "Protocol is TLSv1.2"
|
||||||
|
|
||||||
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
||||||
|
MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED
|
||||||
|
requires_config_disabled MBEDTLS_SSL_PROTO_TLS1_2
|
||||||
|
run_test "Version negotiation check m->m: 1.3 / 1.3 -> 1.3" \
|
||||||
|
"$P_SRV" \
|
||||||
|
"$P_CLI" \
|
||||||
|
0 \
|
||||||
|
-S "mbedtls_ssl_handshake returned" \
|
||||||
|
-C "mbedtls_ssl_handshake returned" \
|
||||||
|
-s "Protocol is TLSv1.3" \
|
||||||
|
-c "Protocol is TLSv1.3"
|
||||||
|
|
||||||
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
||||||
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3 \
|
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3 \
|
||||||
MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED
|
MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED
|
||||||
|
run_test "Version negotiation check m->m: 1.3 (min=1.3) / 1.3 (min=1.3) -> 1.3" \
|
||||||
|
"$P_SRV min_version=tls13" \
|
||||||
|
"$P_CLI min_version=tls13" \
|
||||||
|
0 \
|
||||||
|
-S "mbedtls_ssl_handshake returned" \
|
||||||
|
-C "mbedtls_ssl_handshake returned" \
|
||||||
|
-s "Protocol is TLSv1.3" \
|
||||||
|
-c "Protocol is TLSv1.3"
|
||||||
|
|
||||||
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
||||||
|
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3 \
|
||||||
|
MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED
|
||||||
|
run_test "Version negotiation check m->m: 1.2+1.3 / 1.2+1.3 -> 1.3" \
|
||||||
|
"$P_SRV" \
|
||||||
|
"$P_CLI" \
|
||||||
|
0 \
|
||||||
|
-S "mbedtls_ssl_handshake returned" \
|
||||||
|
-C "mbedtls_ssl_handshake returned" \
|
||||||
|
-s "Protocol is TLSv1.3" \
|
||||||
|
-c "Protocol is TLSv1.3"
|
||||||
|
|
||||||
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
||||||
|
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3 \
|
||||||
|
MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED
|
||||||
|
run_test "Version negotiation check m->m: 1.2+1.3 / 1.3 (min=1.3) -> 1.3" \
|
||||||
|
"$P_SRV min_version=tls13" \
|
||||||
|
"$P_CLI" \
|
||||||
|
0 \
|
||||||
|
-S "mbedtls_ssl_handshake returned" \
|
||||||
|
-C "mbedtls_ssl_handshake returned" \
|
||||||
|
-s "Protocol is TLSv1.3" \
|
||||||
|
-c "Protocol is TLSv1.3"
|
||||||
|
|
||||||
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
||||||
|
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3
|
||||||
|
requires_any_configs_enabled $TLS1_2_KEY_EXCHANGES_WITH_CERT
|
||||||
|
run_test "Version negotiation check m->m: 1.2+1.3 / 1.2 (max=1.2) -> 1.2" \
|
||||||
|
"$P_SRV max_version=tls12" \
|
||||||
|
"$P_CLI" \
|
||||||
|
0 \
|
||||||
|
-S "mbedtls_ssl_handshake returned" \
|
||||||
|
-C "mbedtls_ssl_handshake returned" \
|
||||||
|
-s "Protocol is TLSv1.2" \
|
||||||
|
-c "Protocol is TLSv1.2"
|
||||||
|
|
||||||
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
||||||
|
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3
|
||||||
|
requires_any_configs_enabled $TLS1_2_KEY_EXCHANGES_WITH_CERT
|
||||||
run_test "Version negotiation check m->m: 1.2 (max=1.2) / 1.2+1.3 -> 1.2" \
|
run_test "Version negotiation check m->m: 1.2 (max=1.2) / 1.2+1.3 -> 1.2" \
|
||||||
"$P_SRV" \
|
"$P_SRV" \
|
||||||
"$P_CLI max_version=tls12" \
|
"$P_CLI max_version=tls12" \
|
||||||
@ -6888,6 +6972,17 @@ run_test "Version negotiation check m->m: 1.2 (max=1.2) / 1.2+1.3 -> 1.2" \
|
|||||||
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
||||||
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3 \
|
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3 \
|
||||||
MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED
|
MBEDTLS_SSL_TLS1_3_KEY_EXCHANGE_MODE_EPHEMERAL_ENABLED
|
||||||
|
run_test "Version negotiation check m->m: 1.3 (min=1.3) / 1.2+1.3 -> 1.3" \
|
||||||
|
"$P_SRV" \
|
||||||
|
"$P_CLI min_version=tls13" \
|
||||||
|
0 \
|
||||||
|
-S "mbedtls_ssl_handshake returned" \
|
||||||
|
-C "mbedtls_ssl_handshake returned" \
|
||||||
|
-s "Protocol is TLSv1.3" \
|
||||||
|
-c "Protocol is TLSv1.3"
|
||||||
|
|
||||||
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
||||||
|
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3
|
||||||
run_test "Not supported version check m->m: 1.2 (max=1.2) / 1.3 (min=1.3)" \
|
run_test "Not supported version check m->m: 1.2 (max=1.2) / 1.3 (min=1.3)" \
|
||||||
"$P_SRV min_version=tls13" \
|
"$P_SRV min_version=tls13" \
|
||||||
"$P_CLI max_version=tls12" \
|
"$P_CLI max_version=tls12" \
|
||||||
@ -6898,6 +6993,18 @@ run_test "Not supported version check m->m: 1.2 (max=1.2) / 1.3 (min=1.3)" \
|
|||||||
-S "Protocol is TLSv1.3" \
|
-S "Protocol is TLSv1.3" \
|
||||||
-C "Protocol is TLSv1.3"
|
-C "Protocol is TLSv1.3"
|
||||||
|
|
||||||
|
requires_all_configs_enabled MBEDTLS_SSL_CLI_C MBEDTLS_SSL_SRV_C \
|
||||||
|
MBEDTLS_SSL_PROTO_TLS1_2 MBEDTLS_SSL_PROTO_TLS1_3
|
||||||
|
run_test "Not supported version check m->m: 1.3 (min=1.3) / 1.2 (max=1.2)" \
|
||||||
|
"$P_SRV max_version=tls12" \
|
||||||
|
"$P_CLI min_version=tls13" \
|
||||||
|
1 \
|
||||||
|
-s "The handshake negotiation failed" \
|
||||||
|
-S "Protocol is TLSv1.2" \
|
||||||
|
-C "Protocol is TLSv1.2" \
|
||||||
|
-S "Protocol is TLSv1.3" \
|
||||||
|
-C "Protocol is TLSv1.3"
|
||||||
|
|
||||||
# Tests of version negotiation on server side against GnuTLS client
|
# Tests of version negotiation on server side against GnuTLS client
|
||||||
|
|
||||||
requires_all_configs_enabled MBEDTLS_SSL_SRV_C MBEDTLS_SSL_PROTO_TLS1_2
|
requires_all_configs_enabled MBEDTLS_SSL_SRV_C MBEDTLS_SSL_PROTO_TLS1_2
|
||||||
|
Loading…
x
Reference in New Issue
Block a user