X-Git-Url: https://git.exim.org/exim.git/blobdiff_plain/d502442ac32f8964f6cf86469869cecb035d12c0..bec360ab3e1060187724480d109884e56f912b0a:/test/scripts/5650-OCSP-GnuTLS/5650?ds=sidebyside diff --git a/test/scripts/5650-OCSP-GnuTLS/5650 b/test/scripts/5650-OCSP-GnuTLS/5650 index 440053ecb..e2259c7ed 100644 --- a/test/scripts/5650-OCSP-GnuTLS/5650 +++ b/test/scripts/5650-OCSP-GnuTLS/5650 @@ -2,9 +2,11 @@ # # # -# 1: Server sends good staple on request +exim -z '1: Server sends good staple on request' +**** +# exim -bd -oX PORT_D -DSERVER=server \ - -DOCSP=DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.ocsp.good.resp + -DOPTION=DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.ocsp.good.resp **** client-gnutls \ -ocsp aux-fixed/exim-ca/example.com/server1.example.com/ca_chain.pem \ @@ -16,9 +18,12 @@ ehlo rhu.barb ??? 250- ??? 250- ??? 250- +??? 250- ??? 250 starttls ??? 220 +helo test +??? 250 mail from: ??? 250 rcpt to: @@ -30,12 +35,13 @@ killdaemon # # # -# 2: Server does not staple an outdated response +exim -z '2: Server does not staple an outdated response' +**** +# This test fails on older GnuTLS versions, which do not check the resp on the server +# exim -bd -oX PORT_D -DSERVER=server \ - -DOCSP=DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.ocsp.dated.resp + -DOPTION=DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.ocsp.dated.resp **** -# XXX test sequence might not be quite right; this is for a server refusal -# and we're expecting a client refusal. client-gnutls -ocsp aux-fixed/exim-ca/expired1.example.com/CA.pem HOSTIPV4 PORT_D aux-fixed/cert2 aux-fixed/cert2 ??? 220 ehlo rhu.barb @@ -44,9 +50,10 @@ ehlo rhu.barb ??? 250- ??? 250- ??? 250- +??? 250- ??? 250 starttls -??? 220 +??? 454 **** killdaemon # @@ -54,9 +61,12 @@ killdaemon # # # -# 3: Server does not staple a response for a revoked cert +exim -z '3: Server does not staple a response for a revoked cert' +**** +# This test fails on older GnuTLS versions, which do not check the resp on the server +# exim -bd -oX PORT_D -DSERVER=server \ - -DOCSP=DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.ocsp.revoked.resp + -DOPTION=DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.ocsp.revoked.resp **** client-gnutls \ -ocsp aux-fixed/exim-ca/example.com/server1.example.com/ca_chain.pem \ @@ -68,9 +78,45 @@ ehlo rhu.barb ??? 250- ??? 250- ??? 250- +??? 250- +??? 250 +starttls +??? 454 +**** +killdaemon +# +# +# +# +# +exim -z '4: Connection functions when server is prepared to staple but client does not request it' +**** +# +exim -bd -oX PORT_D -DSERVER=server \ + -DOPTION=DIR/aux-fixed/exim-ca/example.com/server1.example.com/server1.example.com.ocsp.good.resp +**** +# +client-gnutls \ + HOSTIPV4 PORT_D aux-fixed/cert2 aux-fixed/cert2 +??? 220 +ehlo rhu.barb +??? 250- +??? 250- +??? 250- +??? 250- +??? 250- +??? 250- ??? 250 starttls ??? 220 +ehlo rhu.barb.tls +??? 250- +??? 250- +??? 250- +??? 250- +??? 250- +??? 250 +quit **** killdaemon #