Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | Enable test-dhe-rsa-key-exchange-with-bad-messages.py | tb | 2020-06-01 | 1 | -4/+2 | |
| | ||||||
* | Fix printing long doubles on architectures with hm and lm bits. | mortimer | 2020-05-31 | 1 | -1/+9 | |
| | | | | | | Issue reported with initial patch by enh@google.com. ok deraadt@ | |||||
* | more tests after getopt_long.c rev. 1.32; | schwarze | 2020-05-27 | 1 | -10/+43 | |
| | | | | OK martijn@ | |||||
* | Previous commit caught a few errx() cases by accident. undo them. | tb | 2020-05-24 | 1 | -25/+25 | |
| | ||||||
* | include newlines in FAIL messages | tb | 2020-05-24 | 1 | -108/+108 | |
| | ||||||
* | address some nits from jsing | tb | 2020-05-24 | 1 | -7/+11 | |
| | ||||||
* | The version detection doesn't work on bluhm's test machine, causing | tb | 2020-05-24 | 1 | -3/+3 | |
| | | | | | | | the test to fail. Neuter it for now and just assume we do TLSv1.3. I have been intending to purge this version detection hack once I'm sure we can leave the 1.3 server enabled but I'll leave it here for now. | |||||
* | Define REGRESS_TARGETS explicitly. | tb | 2020-05-23 | 1 | -2/+4 | |
| | ||||||
* | Enforce that SNI hostnames be correct as per rfc 6066 and 5980. | beck | 2020-05-23 | 1 | -1/+79 | |
| | | | | | | | Correct SNI alerts to differentiate between illegal parameter and an unknown name. ok tb@` | |||||
* | beck fixed most of the keyupdate tests. update annotation | tb | 2020-05-21 | 1 | -3/+8 | |
| | ||||||
* | hook tlsfuzzer to regress | tb | 2020-05-21 | 1 | -1/+2 | |
| | ||||||
* | Add a harness that runs tests from tlsfuzzer | tb | 2020-05-21 | 2 | -0/+781 | |
| | | | | | | | | | | | | | This currently runs 54 tests from the tlsfuzzer suite against the TLSv1.3 server which exercise a large portion of the code. They already found a number of bugs and misbehaviors and also inspired a few diffs currently in the pipeline. This regress requires the py3-tlsfuzzer package to be installed, otherwise the tests are skipped. Many thanks to kmos for helping with the ports side and to beck for his positive feedback. ok beck | |||||
* | go fmt whitespace nit | tb | 2020-05-14 | 1 | -3/+3 | |
| | ||||||
* | reinstate an error check that was commented out while waiting for arm | tb | 2020-05-14 | 1 | -5/+4 | |
| | | | | packages to appear | |||||
* | move a #define after the last #include line | tb | 2020-05-14 | 1 | -3/+3 | |
| | ||||||
* | Add TLS versioning tests. | jsing | 2020-05-13 | 1 | -2/+96 | |
| | | | | | This ensures that a TLSv1.0, TLSv1.1, TLSv1.2 or TLSv1.3 client can talk with an appropriately configured server and vice versa. | |||||
* | Revise regress for TLSv1.3 server being enabled. | jsing | 2020-05-11 | 4 | -14/+17 | |
| | ||||||
* | Use tls_legacy_server_method() for SSLv2 record tests. | jsing | 2020-05-11 | 2 | -5/+7 | |
| | ||||||
* | Revise regress now that record overflows are propagated. | jsing | 2020-05-11 | 1 | -2/+2 | |
| | ||||||
* | Use a larger (2048 bit) RSA test key. | jsing | 2020-05-04 | 1 | -1/+63 | |
| | | | | Otherwise we fail to do PSS signatures since the key size is too small. | |||||
* | Fix out-of-bounds access in tables[][] that was exposed in bluhm's | tb | 2020-05-04 | 1 | -6/+8 | |
| | | | | | | regress on i386 after inoguchi moved some symbols to const. ok inoguchi jsing deraadt | |||||
* | Fix two bugs in the AES-CBC-PKCS5 tests that didn't hide failing tests: | tb | 2020-04-27 | 1 | -3/+3 | |
| | | | | | 1. Use the correct slice for comparing the cipher output 2. Fix logic error similar to the one in AES-GCM in the previous commit | |||||
* | Fix a logic error that hid the failing ZeroLengthIv tests. | tb | 2020-04-27 | 1 | -3/+3 | |
| | | | | This issue was fixed in lib/libcrypto/evp/e_aes.c r1.40. | |||||
* | Revise regress to match state transition changes. | jsing | 2020-04-22 | 1 | -11/+13 | |
| | ||||||
* | Update key share regress to match previous change. | jsing | 2020-04-17 | 1 | -4/+4 | |
| | ||||||
* | Revise test to handle the fact that TLSv1.3 cipher suites are now being | jsing | 2020-04-09 | 1 | -2/+4 | |
| | | | | included in the output from `openssl ciphers`. | |||||
* | Test both SSLv3 (aka pre-TLSv1.2) and TLSv1.2 cipher suites with TLS. | jsing | 2020-04-09 | 1 | -1/+1 | |
| | ||||||
* | Re-enable the client test now that it passes again. | jsing | 2020-04-06 | 1 | -2/+2 | |
| | ||||||
* | Minor code improvements. | jsing | 2020-04-06 | 1 | -3/+3 | |
| | ||||||
* | Add tests that cover TLSv1.2 and disable those that trigger TLSv1.3. | jsing | 2020-04-06 | 1 | -3/+32 | |
| | | | | This allows the test to pass again. | |||||
* | Zero the client random field in the TLSv1.2 golden value. | jsing | 2020-04-06 | 1 | -5/+5 | |
| | ||||||
* | Improve comparision with test data. | jsing | 2020-04-06 | 1 | -7/+9 | |
| | | | | | | First check the client random against the zeroed value, then zero the client random in the client hello, before comparing with the golden value. This makes failures more obvious and the test code more readable. | |||||
* | Dump the test data when the lengths differ in order to aid debugging. | jsing | 2020-04-06 | 1 | -0/+3 | |
| | ||||||
* | Use errx() if we fail to build the client hello. | jsing | 2020-04-06 | 1 | -1/+1 | |
| | ||||||
* | Add a test program for getopt(3) that is adequate for manual testing | schwarze | 2020-03-23 | 4 | -2/+174 | |
| | | | | | | | | and a compact test suite for getopt(3) intended automated regression testing, both written from scratch. The suite is intended to provide full coverage, except that it doesn't test manual changes of optind and optreset and except that it so far avoids the situation where we have a known bug. | |||||
* | Adapt to tls13_record_layer.c r1.30 (the sequence number shouldn't wrap). | tb | 2020-03-16 | 1 | -2/+2 | |
| | ||||||
* | Increment a few more sequence numbers where the carry is close to | tb | 2020-03-13 | 1 | -1/+41 | |
| | | | | crossing a byte boundary. | |||||
* | Add regress for TLSv1.3 sequence number handling. | jsing | 2020-03-13 | 3 | -1/+135 | |
| | ||||||
* | Add missing $OpenBSD$ tag. | jsing | 2020-03-13 | 1 | -0/+1 | |
| | ||||||
* | Add regress for CBB_add_space(). | jsing | 2020-03-13 | 1 | -1/+41 | |
| | ||||||
* | Update to follow handshake enum removal. | jsing | 2020-03-10 | 1 | -7/+1 | |
| | ||||||
* | Import openssl-1.1.1d test data to base64test.c | inoguchi | 2020-03-10 | 1 | -1/+97 | |
| | | | | ok bcook@ tb@ | |||||
* | Modify regress base64test.c | inoguchi | 2020-03-10 | 1 | -11/+14 | |
| | | | | | | | | | | | | | | | | | | | | | | | - Don't remove multi line CR/LF from bt->out when NL mode base64_encoding_test removes CR/LF from bt->out to compare with the encoding result. This is fine with NO NL mode, but it goes wrong with NL mode if encoding result is larger than 64 and multi line, like below. "eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4\neHh4eHh4eHh4eHh4\n" - Use memcpy instead of asprintf to avoid lost '\0' at the end of data This test data loses trailing '\0' if using asprintf. "\x61\x47\x56\x73\x62\x47\x38\x3d\x0a\x00" - Print original data if decoding result comparison fails This change is not for importing test data, but I just notice. It prints bt->out if fail to memcmp bt->in with decoding result. ok bcook@ tb@ | |||||
* | cstyle in illumos noticed some weird syntax, which this fixes. | dlg | 2020-03-09 | 1 | -4/+4 | |
| | | | | | | | | | | | | | | | | | | | some errx lines in if statements were terminated with commas, which caused the following statement to be considered part of the error handling. while it is bad style, ingo points out it was also a bug which which caused some tests in the code to be skipped. this reminds me of a haiku that Chris Pascoe (cpascoe@) had behind his desk: Also, that comma Should be a semi-colon. Cherry blossoms fall. this was found by Robert Mustacchi when porting the tests to illumos. ok schwarze@ stsp@ thank you robert. | |||||
* | Update protocol version test to include TLSv1.3. | jsing | 2020-02-16 | 2 | -0/+3 | |
| | ||||||
* | no need to declare "extern optarg" and "extern optind" | schwarze | 2020-02-14 | 3 | -9/+3 | |
| | | | | | | when <unistd.h> is included; patch from Jan Stary <hans at stare dot cz>; OK millert | |||||
* | Reset the key share so that we do not have an existing peer public key. | jsing | 2020-02-05 | 1 | -1/+7 | |
| | ||||||
* | Add missing new line to printf. Make clean should not require SUDO. | bluhm | 2020-02-02 | 2 | -7/+5 | |
| | ||||||
* | Tweak regress to match change made to tls13_key_share_peer_public(). | jsing | 2020-02-01 | 1 | -2/+1 | |
| | ||||||
* | Revise for TLSv1.3 key share changes. | jsing | 2020-01-30 | 1 | -8/+27 | |
| |