mirror of
https://github.com/curl/curl.git
synced 2026-07-23 04:07:20 +03:00
TLS: drop support for TLS-SRP
The options will simply do nothing. Closes #21965
This commit is contained in:
parent
d169ad68fa
commit
69ac867f98
63 changed files with 133 additions and 932 deletions
|
|
@ -421,8 +421,6 @@ mark_as_advanced(CURL_ENABLE_EXPORT_TARGET)
|
|||
|
||||
option(CURL_DISABLE_ALTSVC "Disable alt-svc support" OFF)
|
||||
mark_as_advanced(CURL_DISABLE_ALTSVC)
|
||||
option(CURL_DISABLE_SRP "Disable TLS-SRP support" OFF)
|
||||
mark_as_advanced(CURL_DISABLE_SRP)
|
||||
option(CURL_DISABLE_COOKIES "Disable cookies support" OFF)
|
||||
mark_as_advanced(CURL_DISABLE_COOKIES)
|
||||
option(CURL_DISABLE_BASIC_AUTH "Disable Basic authentication" OFF)
|
||||
|
|
@ -936,15 +934,6 @@ if(CURL_USE_GNUTLS)
|
|||
set(_valid_default_ssl_backend TRUE)
|
||||
endif()
|
||||
set(_curl_ca_bundle_supported TRUE)
|
||||
|
||||
if(NOT DEFINED HAVE_GNUTLS_SRP AND NOT CURL_DISABLE_SRP)
|
||||
cmake_push_check_state()
|
||||
list(APPEND CMAKE_REQUIRED_LIBRARIES CURL::gnutls)
|
||||
# In GnuTLS 3.8.0 (2023-02-10) and upper, this check always succeeds.
|
||||
# Detecting actual TLS-SRP support needs poking the API at runtime.
|
||||
check_symbol_exists("gnutls_srp_verifier" "gnutls/gnutls.h" HAVE_GNUTLS_SRP)
|
||||
cmake_pop_check_state()
|
||||
endif()
|
||||
endif()
|
||||
|
||||
if(CURL_USE_RUSTLS)
|
||||
|
|
@ -1012,7 +1001,6 @@ macro(curl_openssl_check_exists)
|
|||
cmake_push_check_state()
|
||||
if(USE_OPENSSL)
|
||||
list(APPEND CMAKE_REQUIRED_LIBRARIES OpenSSL::SSL OpenSSL::Crypto)
|
||||
list(APPEND CMAKE_REQUIRED_DEFINITIONS "-DOPENSSL_SUPPRESS_DEPRECATED") # for SSL_CTX_set_srp_username deprecated since 3.0.0
|
||||
if(HAVE_LIBZ)
|
||||
list(APPEND CMAKE_REQUIRED_LIBRARIES ZLIB::ZLIB)
|
||||
endif()
|
||||
|
|
@ -1077,9 +1065,6 @@ if(USE_OPENSSL)
|
|||
if(NOT DEFINED HAVE_SSL_SET0_WBIO)
|
||||
curl_openssl_check_exists("SSL_set0_wbio" HAVE_SSL_SET0_WBIO)
|
||||
endif()
|
||||
if(NOT DEFINED HAVE_OPENSSL_SRP AND NOT CURL_DISABLE_SRP)
|
||||
curl_openssl_check_exists("SSL_CTX_set_srp_username" "openssl/ssl.h" HAVE_OPENSSL_SRP)
|
||||
endif()
|
||||
endif()
|
||||
|
||||
option(USE_HTTPSRR "Enable HTTPS RR support (experimental)" OFF)
|
||||
|
|
@ -1204,10 +1189,6 @@ if(USE_PROXY_HTTP3)
|
|||
endif()
|
||||
endif()
|
||||
|
||||
if(NOT CURL_DISABLE_SRP AND (HAVE_GNUTLS_SRP OR HAVE_OPENSSL_SRP))
|
||||
set(USE_TLS_SRP 1)
|
||||
endif()
|
||||
|
||||
if(NOT CURL_DISABLE_LDAP)
|
||||
if(WIN32 AND NOT WINDOWS_STORE)
|
||||
option(USE_WIN32_LDAP "Use Windows LDAP implementation" ON)
|
||||
|
|
@ -2062,7 +2043,6 @@ curl_add_if("Kerberos" NOT CURL_DISABLE_KERBEROS_AUTH AND
|
|||
(HAVE_GSSAPI OR USE_WINDOWS_SSPI))
|
||||
curl_add_if("NTLM" CURL_ENABLE_NTLM AND
|
||||
(_use_curl_ntlm_core OR USE_WINDOWS_SSPI))
|
||||
curl_add_if("TLS-SRP" USE_TLS_SRP)
|
||||
curl_add_if("HTTP2" USE_NGHTTP2)
|
||||
curl_add_if("HTTP3" USE_NGTCP2 OR USE_QUICHE)
|
||||
curl_add_if("proxy-HTTP3" USE_PROXY_HTTP3)
|
||||
|
|
|
|||
33
configure.ac
33
configure.ac
|
|
@ -174,7 +174,6 @@ dnl initialize all the info variables
|
|||
curl_zstd_msg="no (--with-zstd)"
|
||||
curl_gss_msg="no (--with-gssapi)"
|
||||
curl_gsasl_msg="no (--with-gsasl)"
|
||||
curl_tls_srp_msg="no (--enable-tls-srp)"
|
||||
curl_res_msg="blocking (--enable-ares / --enable-threaded-resolver)"
|
||||
curl_ipv6_msg="no (--enable-ipv6)"
|
||||
curl_unix_sockets_msg="no (--enable-unix-sockets)"
|
||||
|
|
@ -4584,33 +4583,6 @@ AS_HELP_STRING([--disable-ntlm],[Disable NTLM support]),
|
|||
AC_MSG_RESULT(no)
|
||||
)
|
||||
|
||||
dnl ************************************************************
|
||||
dnl disable TLS-SRP authentication
|
||||
dnl
|
||||
AC_MSG_CHECKING([whether to enable TLS-SRP authentication])
|
||||
AC_ARG_ENABLE(tls-srp,
|
||||
AS_HELP_STRING([--enable-tls-srp],[Enable TLS-SRP authentication])
|
||||
AS_HELP_STRING([--disable-tls-srp],[Disable TLS-SRP authentication]),
|
||||
[ case "$enableval" in
|
||||
no)
|
||||
AC_MSG_RESULT(no)
|
||||
want_tls_srp=no
|
||||
;;
|
||||
*)
|
||||
AC_MSG_RESULT(yes)
|
||||
want_tls_srp=yes
|
||||
;;
|
||||
esac ],
|
||||
AC_MSG_RESULT(yes)
|
||||
want_tls_srp=yes
|
||||
)
|
||||
|
||||
if test "$want_tls_srp" = "yes" && (test "$HAVE_GNUTLS_SRP" = "1" || test "$HAVE_OPENSSL_SRP" = "1"); then
|
||||
AC_DEFINE(USE_TLS_SRP, 1, [Use TLS-SRP authentication])
|
||||
USE_TLS_SRP=1
|
||||
curl_tls_srp_msg="enabled"
|
||||
fi
|
||||
|
||||
dnl ************************************************************
|
||||
dnl disable Unix domain sockets support
|
||||
dnl
|
||||
|
|
@ -5279,10 +5251,6 @@ if test "$CURL_ENABLE_NTLM" = "1"; then
|
|||
fi
|
||||
fi
|
||||
|
||||
if test "$USE_TLS_SRP" = "1"; then
|
||||
SUPPORT_FEATURES="$SUPPORT_FEATURES TLS-SRP"
|
||||
fi
|
||||
|
||||
if test "$USE_NGHTTP2" = "1"; then
|
||||
SUPPORT_FEATURES="$SUPPORT_FEATURES HTTP2"
|
||||
fi
|
||||
|
|
@ -5558,7 +5526,6 @@ AC_MSG_NOTICE([Configured to build curl/libcurl:
|
|||
zstd: ${curl_zstd_msg}
|
||||
GSS-API: ${curl_gss_msg}
|
||||
GSASL: ${curl_gsasl_msg}
|
||||
TLS-SRP: ${curl_tls_srp_msg}
|
||||
resolver: ${curl_res_msg}
|
||||
IPv6: ${curl_ipv6_msg}
|
||||
Unix sockets: ${curl_unix_sockets_msg}
|
||||
|
|
|
|||
|
|
@ -224,9 +224,8 @@ the following way:
|
|||
|
||||
* When the set string starts with '+', '-' or '!' it is *appended* to the
|
||||
priority string libcurl itself generates (separated by ':'). This initial
|
||||
priority depends other settings such as CURLOPT_SSLVERSION(3),
|
||||
CURLOPT_TLSAUTH_USERNAME(3) (for SRP) or if HTTP/3 (QUIC)
|
||||
is being negotiated.
|
||||
priority depends other settings such as CURLOPT_SSLVERSION(3) or if HTTP/3
|
||||
(QUIC) is being negotiated.
|
||||
* Otherwise, the set string fully *replaces* the libcurl generated one. While
|
||||
giving full control to the application, the set priority needs to
|
||||
provide for everything the transfer may need to negotiate. Example: if
|
||||
|
|
|
|||
|
|
@ -12,14 +12,6 @@ email the
|
|||
as soon as possible and explain to us why this is a problem for you and
|
||||
how your use case cannot be satisfied properly using a workaround.
|
||||
|
||||
## TLS-SRP Authentication
|
||||
|
||||
Transport Layer Security Secure Remote Password is a TLS feature that does not
|
||||
work with TLS 1.3 or QUIC and is virtually unused by curl users and in
|
||||
general.
|
||||
|
||||
TLS-SRP support gets removed in August 2026.
|
||||
|
||||
## drop SMB support
|
||||
|
||||
The SMB protocol has weak security and is rarely used these days.
|
||||
|
|
@ -83,3 +75,4 @@ Local crypto gets removed in October 2026.
|
|||
- SMB (became opt-in in 8.20.0)
|
||||
- NTLM (became opt-in in 8.20.0)
|
||||
- c-ares < 1.16.0 (removed in 8.20.0)
|
||||
- TLS-SRP (removed in 8.22.0)
|
||||
|
|
|
|||
|
|
@ -299,7 +299,6 @@ target_link_libraries(my_target PRIVATE CURL::libcurl)
|
|||
- `CURL_DISABLE_SHUFFLE_DNS`: Disable shuffle DNS feature. Default: `OFF`
|
||||
- `CURL_DISABLE_SMTP`: Disable SMTP. Default: `OFF`
|
||||
- `CURL_DISABLE_SOCKETPAIR`: Disable use of socketpair for curl_multi_poll(). Default: `OFF`
|
||||
- `CURL_DISABLE_SRP`: Disable TLS-SRP support. Default: `OFF`
|
||||
- `CURL_DISABLE_TELNET`: Disable Telnet. Default: `OFF`
|
||||
- `CURL_DISABLE_TFTP`: Disable TFTP. Default: `OFF`
|
||||
- `CURL_DISABLE_TYPECHECK`: Disable curl_easy_setopt()/curl_easy_getinfo() type checking. Default: `OFF`
|
||||
|
|
@ -516,11 +515,9 @@ the parent project, ideally in the "extra" find package redirect file:
|
|||
Available variables:
|
||||
|
||||
- `HAVE_DES_ECB_ENCRYPT`: `DES_ecb_encrypt` present in OpenSSL (or fork).
|
||||
- `HAVE_GNUTLS_SRP`: `gnutls_srp_verifier` present in GnuTLS.
|
||||
- `HAVE_LDAP_INIT_FD`: `ldap_init_fd` present in LDAP library.
|
||||
- `HAVE_LDAP_URL_PARSE`: `ldap_url_parse` present in LDAP library.
|
||||
- `HAVE_MBEDTLS_DES_CRYPT_ECB`: `mbedtls_des_crypt_ecb` present in mbedTLS <4.
|
||||
- `HAVE_OPENSSL_SRP`: `SSL_CTX_set_srp_username` present in OpenSSL (or fork).
|
||||
- `HAVE_QUICHE_CONN_SET_QLOG_FD`: `quiche_conn_set_qlog_fd` present in quiche.
|
||||
- `HAVE_RUSTLS_SUPPORTED_HPKE`: `rustls_supported_hpke` present in Rustls
|
||||
(unused if Rustls is detected via `pkg-config`).
|
||||
|
|
|
|||
|
|
@ -634,7 +634,6 @@ disabling support for some features (run `./configure --help` to see them all):
|
|||
- `--disable-proxy` (HTTP and SOCKS proxies)
|
||||
- `--disable-socketpair` (socketpair for asynchronous name resolving)
|
||||
- `--disable-threaded-resolver` (threaded name resolver)
|
||||
- `--disable-tls-srp` (Secure Remote Password authentication for TLS)
|
||||
- `--disable-unix-sockets` (Unix sockets)
|
||||
- `--disable-verbose` (eliminates debugging strings and error code strings)
|
||||
- `--disable-versioned-symbols` (versioned symbols)
|
||||
|
|
|
|||
|
|
@ -17,6 +17,8 @@ Example:
|
|||
|
||||
# `--proxy-tlsauthtype`
|
||||
|
||||
Deprecated option. This has no functionality since 8.22.0.
|
||||
|
||||
Set TLS authentication type with HTTPS proxy. The only supported option is
|
||||
`SRP`, for TLS-SRP (RFC 5054). This option works only if the underlying
|
||||
libcurl is built with TLS-SRP support.
|
||||
|
|
|
|||
|
|
@ -16,6 +16,8 @@ Example:
|
|||
|
||||
# `--proxy-tlspassword`
|
||||
|
||||
Deprecated option. This has no functionality since 8.22.0.
|
||||
|
||||
Set password to use with the TLS authentication method specified with
|
||||
--proxy-tlsauthtype when using HTTPS proxy. Requires that --proxy-tlsuser is
|
||||
set.
|
||||
|
|
|
|||
|
|
@ -16,6 +16,8 @@ Example:
|
|||
|
||||
# `--proxy-tlsuser`
|
||||
|
||||
Deprecated option. This has no functionality since 8.22.0.
|
||||
|
||||
Set username for use for HTTPS proxy with the TLS authentication method
|
||||
specified with --proxy-tlsauthtype. Requires that --proxy-tlspassword also is
|
||||
set.
|
||||
|
|
|
|||
|
|
@ -16,6 +16,8 @@ Example:
|
|||
|
||||
# `--tlsauthtype`
|
||||
|
||||
Deprecated option. This has no functionality since 8.22.0.
|
||||
|
||||
Set TLS authentication type. Currently, the only supported option is `SRP`,
|
||||
for TLS-SRP (RFC 5054). If --tlsuser and --tlspassword are specified but
|
||||
--tlsauthtype is not, then this option defaults to `SRP`. This option works
|
||||
|
|
|
|||
|
|
@ -16,6 +16,8 @@ Example:
|
|||
|
||||
# `--tlspassword`
|
||||
|
||||
Deprecated option. This has no functionality since 8.22.0.
|
||||
|
||||
Set password to use with the TLS authentication method specified with
|
||||
--tlsauthtype. Requires that --tlsuser is set.
|
||||
|
||||
|
|
|
|||
|
|
@ -16,6 +16,8 @@ Example:
|
|||
|
||||
# `--tlsuser`
|
||||
|
||||
Deprecated option. This has no functionality since 8.22.0.
|
||||
|
||||
Set username for use with the TLS authentication method specified with
|
||||
--tlsauthtype. Requires that --tlspassword also is set.
|
||||
|
||||
|
|
|
|||
|
|
@ -121,9 +121,6 @@ This build supports TLS session export/import, like with the --ssl-sessions.
|
|||
## `SSPI`
|
||||
SSPI is supported.
|
||||
|
||||
## `TLS-SRP`
|
||||
SRP (Secure Remote Password) authentication is supported for TLS.
|
||||
|
||||
## `Unicode`
|
||||
Unicode support on Windows.
|
||||
|
||||
|
|
|
|||
|
|
@ -55,9 +55,7 @@ Examples:
|
|||
Different configurations produce different keys which is what curl needs when
|
||||
handling SSL session tickets.
|
||||
|
||||
One important thing: peer keys do not contain confidential information. If you
|
||||
configure a client certificate or SRP authentication with username/password,
|
||||
these are not part of the peer key.
|
||||
One important thing: peer keys do not contain confidential information.
|
||||
|
||||
Peer keys carry the hostnames you use curl for. They *do* leak the privacy of
|
||||
your communication. We recommend to *not* persist peer keys for this reason.
|
||||
|
|
@ -76,10 +74,9 @@ its own peer_key and calls into the cache. The cache then looks for a ticket
|
|||
with exactly this peer_key. Peer keys between proxy SSL filters and SSL
|
||||
filters talking through a tunnel differ, as they talk to different peers.
|
||||
|
||||
If the connection filter wants to use a client certificate or SRP
|
||||
authentication, the cache checks those as well. If the cache peer carries
|
||||
client cert or SRP auth, the connection filter must have those with the same
|
||||
values (and vice versa).
|
||||
If the connection filter wants to use a client certificate, the cache checks
|
||||
those as well. If the cache peer carries client certs, the connection filter
|
||||
must have those with the same values (and vice versa).
|
||||
|
||||
On a match, the connection filter gets the session ticket and feeds that to
|
||||
the TLS implementation which, on accepting it, tries to resume it for a
|
||||
|
|
|
|||
|
|
@ -867,15 +867,18 @@ Proxy TLS 1.3 cipher suites to use. See CURLOPT_PROXY_TLS13_CIPHERS(3)
|
|||
|
||||
## CURLOPT_PROXY_TLSAUTH_PASSWORD
|
||||
|
||||
Proxy TLS authentication password. See CURLOPT_PROXY_TLSAUTH_PASSWORD(3)
|
||||
**Deprecated option**. Proxy TLS authentication password. See
|
||||
CURLOPT_PROXY_TLSAUTH_PASSWORD(3)
|
||||
|
||||
## CURLOPT_PROXY_TLSAUTH_TYPE
|
||||
|
||||
Proxy TLS authentication methods. See CURLOPT_PROXY_TLSAUTH_TYPE(3)
|
||||
**Deprecated option**. Proxy TLS authentication methods. See
|
||||
CURLOPT_PROXY_TLSAUTH_TYPE(3)
|
||||
|
||||
## CURLOPT_PROXY_TLSAUTH_USERNAME
|
||||
|
||||
Proxy TLS authentication username. See CURLOPT_PROXY_TLSAUTH_USERNAME(3)
|
||||
**Deprecated option**. Proxy TLS authentication username. See
|
||||
CURLOPT_PROXY_TLSAUTH_USERNAME(3)
|
||||
|
||||
## CURLOPT_PROXY_TRANSFER_MODE
|
||||
|
||||
|
|
@ -1244,15 +1247,16 @@ TLS 1.3 cipher suites to use. See CURLOPT_TLS13_CIPHERS(3)
|
|||
|
||||
## CURLOPT_TLSAUTH_PASSWORD
|
||||
|
||||
TLS authentication password. See CURLOPT_TLSAUTH_PASSWORD(3)
|
||||
**Deprecated option**. TLS authentication password. See CURLOPT_TLSAUTH_PASSWORD(3)
|
||||
|
||||
## CURLOPT_TLSAUTH_TYPE
|
||||
|
||||
TLS authentication methods. See CURLOPT_TLSAUTH_TYPE(3)
|
||||
**Deprecated option**. TLS authentication methods. See CURLOPT_TLSAUTH_TYPE(3)
|
||||
|
||||
## CURLOPT_TLSAUTH_USERNAME
|
||||
|
||||
TLS authentication username. See CURLOPT_TLSAUTH_USERNAME(3)
|
||||
**Deprecated option**. TLS authentication username. See
|
||||
CURLOPT_TLSAUTH_USERNAME(3)
|
||||
|
||||
## CURLOPT_TRAILERDATA
|
||||
|
||||
|
|
|
|||
|
|
@ -60,8 +60,7 @@ persisted: either **session_key** or **shamc** and always **sdata**. All
|
|||
other parameters are informative, e.g. allow the callback to act only
|
||||
on specific session tickets.
|
||||
|
||||
Note that SSL sessions that involve a client certificate or SRP
|
||||
username/password are not exported.
|
||||
Note that SSL sessions that involve a client certificate are not exported.
|
||||
|
||||
# Export Function Parameter
|
||||
|
||||
|
|
|
|||
|
|
@ -47,6 +47,10 @@ previous ones. Set it to NULL to disable its use again.
|
|||
|
||||
NULL
|
||||
|
||||
# DEPRECATED
|
||||
|
||||
This option was deprecated in 8.22.0.
|
||||
|
||||
# %PROTOCOLS%
|
||||
|
||||
# EXAMPLE
|
||||
|
|
|
|||
|
|
@ -54,6 +54,10 @@ options.
|
|||
|
||||
blank
|
||||
|
||||
# DEPRECATED
|
||||
|
||||
This option was deprecated in 8.22.0.
|
||||
|
||||
# %PROTOCOLS%
|
||||
|
||||
# EXAMPLE
|
||||
|
|
|
|||
|
|
@ -47,6 +47,10 @@ previous ones. Set it to NULL to disable its use again.
|
|||
|
||||
NULL
|
||||
|
||||
# DEPRECATED
|
||||
|
||||
This option was deprecated in 8.22.0.
|
||||
|
||||
# %PROTOCOLS%
|
||||
|
||||
# EXAMPLE
|
||||
|
|
|
|||
|
|
@ -30,6 +30,8 @@ CURLcode curl_easy_setopt(CURL *handle, CURLOPT_TLSAUTH_PASSWORD, char *pwd);
|
|||
|
||||
# DESCRIPTION
|
||||
|
||||
Deprecated option. It serves no purpose anymore.
|
||||
|
||||
Pass a char pointer as parameter, which should point to the null-terminated
|
||||
password to use for the TLS authentication method specified with the
|
||||
CURLOPT_TLSAUTH_TYPE(3) option. Requires that the CURLOPT_TLSAUTH_USERNAME(3)
|
||||
|
|
@ -47,6 +49,10 @@ This feature relies on TLS-SRP which does not work with TLS 1.3.
|
|||
|
||||
NULL
|
||||
|
||||
# DEPRECATED
|
||||
|
||||
This option was deprecated in 8.22.0.
|
||||
|
||||
# %PROTOCOLS%
|
||||
|
||||
# EXAMPLE
|
||||
|
|
|
|||
|
|
@ -29,6 +29,8 @@ CURLcode curl_easy_setopt(CURL *handle, CURLOPT_TLSAUTH_TYPE, char *type);
|
|||
|
||||
# DESCRIPTION
|
||||
|
||||
Deprecated option. It serves no purpose anymore.
|
||||
|
||||
Pass a pointer to a null-terminated string as parameter. The string should be
|
||||
the method of the TLS authentication. Supported method is "SRP".
|
||||
|
||||
|
|
@ -51,6 +53,10 @@ TLS-SRP does not work with TLS 1.3.
|
|||
|
||||
blank
|
||||
|
||||
# DEPRECATED
|
||||
|
||||
This option was deprecated in 8.22.0.
|
||||
|
||||
# %PROTOCOLS%
|
||||
|
||||
# EXAMPLE
|
||||
|
|
|
|||
|
|
@ -29,6 +29,8 @@ CURLcode curl_easy_setopt(CURL *handle, CURLOPT_TLSAUTH_USERNAME, char *user);
|
|||
|
||||
# DESCRIPTION
|
||||
|
||||
Deprecated option. It serves no purpose anymore.
|
||||
|
||||
Pass a char pointer as parameter, which should point to the null-terminated
|
||||
username to use for the TLS authentication method specified with the
|
||||
CURLOPT_TLSAUTH_TYPE(3) option. Requires that the CURLOPT_TLSAUTH_PASSWORD(3)
|
||||
|
|
@ -46,6 +48,10 @@ This feature relies on TLS-SRP which does not work with TLS 1.3.
|
|||
|
||||
NULL
|
||||
|
||||
# DEPRECATED
|
||||
|
||||
This option was deprecated in 8.22.0.
|
||||
|
||||
# %PROTOCOLS%
|
||||
|
||||
# EXAMPLE
|
||||
|
|
|
|||
|
|
@ -151,8 +151,8 @@ CURL_TIMECOND_IFMODSINCE 7.9.7
|
|||
CURL_TIMECOND_IFUNMODSINCE 7.9.7
|
||||
CURL_TIMECOND_LASTMOD 7.9.7
|
||||
CURL_TIMECOND_NONE 7.9.7
|
||||
CURL_TLSAUTH_NONE 7.21.4
|
||||
CURL_TLSAUTH_SRP 7.21.4
|
||||
CURL_TLSAUTH_NONE 7.21.4 8.22.0
|
||||
CURL_TLSAUTH_SRP 7.21.4 8.22.0
|
||||
CURL_TRAILERFUNC_ABORT 7.64.0
|
||||
CURL_TRAILERFUNC_OK 7.64.0
|
||||
CURL_UPKEEP_INTERVAL_DEFAULT 7.62.0
|
||||
|
|
@ -184,7 +184,7 @@ CURL_VERSION_SPNEGO 7.10.8
|
|||
CURL_VERSION_SSL 7.10
|
||||
CURL_VERSION_SSPI 7.13.2
|
||||
CURL_VERSION_THREADSAFE 7.84.0
|
||||
CURL_VERSION_TLSAUTH_SRP 7.21.4
|
||||
CURL_VERSION_TLSAUTH_SRP 7.21.4 8.22.0
|
||||
CURL_VERSION_UNICODE 7.72.0
|
||||
CURL_VERSION_UNIX_SOCKETS 7.40.0
|
||||
CURL_VERSION_ZSTD 7.72.0
|
||||
|
|
@ -791,9 +791,9 @@ CURLOPT_PROXY_SSLKEY_BLOB 7.71.0
|
|||
CURLOPT_PROXY_SSLKEYTYPE 7.52.0
|
||||
CURLOPT_PROXY_SSLVERSION 7.52.0
|
||||
CURLOPT_PROXY_TLS13_CIPHERS 7.61.0
|
||||
CURLOPT_PROXY_TLSAUTH_PASSWORD 7.52.0
|
||||
CURLOPT_PROXY_TLSAUTH_TYPE 7.52.0
|
||||
CURLOPT_PROXY_TLSAUTH_USERNAME 7.52.0
|
||||
CURLOPT_PROXY_TLSAUTH_PASSWORD 7.52.0 8.22.0
|
||||
CURLOPT_PROXY_TLSAUTH_TYPE 7.52.0 8.22.0
|
||||
CURLOPT_PROXY_TLSAUTH_USERNAME 7.52.0 8.22.0
|
||||
CURLOPT_PROXY_TRANSFER_MODE 7.18.0
|
||||
CURLOPT_PROXYAUTH 7.10.7
|
||||
CURLOPT_PROXYHEADER 7.37.0
|
||||
|
|
@ -901,9 +901,9 @@ CURLOPT_TIMEOUT_MS 7.16.2
|
|||
CURLOPT_TIMEVALUE 7.1
|
||||
CURLOPT_TIMEVALUE_LARGE 7.59.0
|
||||
CURLOPT_TLS13_CIPHERS 7.61.0
|
||||
CURLOPT_TLSAUTH_PASSWORD 7.21.4
|
||||
CURLOPT_TLSAUTH_TYPE 7.21.4
|
||||
CURLOPT_TLSAUTH_USERNAME 7.21.4
|
||||
CURLOPT_TLSAUTH_PASSWORD 7.21.4 8.22.0
|
||||
CURLOPT_TLSAUTH_TYPE 7.21.4 8.22.0
|
||||
CURLOPT_TLSAUTH_USERNAME 7.21.4 8.22.0
|
||||
CURLOPT_TRAILERDATA 7.64.0
|
||||
CURLOPT_TRAILERFUNCTION 7.64.0
|
||||
CURLOPT_TRANSFER_ENCODING 7.21.6
|
||||
|
|
|
|||
|
|
@ -445,8 +445,6 @@ What server(s) this test case requires/uses. Available servers:
|
|||
- `https`
|
||||
- `https-proxy`
|
||||
- `https-mtls`
|
||||
- `httptls+srp`
|
||||
- `httptls+srp-ipv6`
|
||||
- `http-unix`
|
||||
- `imap`
|
||||
- `mqtt`
|
||||
|
|
|
|||
|
|
@ -1863,13 +1863,16 @@ typedef enum {
|
|||
CURLOPT(CURLOPT_RESOLVE, CURLOPTTYPE_SLISTPOINT, 203),
|
||||
|
||||
/* Set a username for authenticated TLS */
|
||||
CURLOPT(CURLOPT_TLSAUTH_USERNAME, CURLOPTTYPE_STRINGPOINT, 204),
|
||||
CURLOPTDEPRECATED(CURLOPT_TLSAUTH_USERNAME, CURLOPTTYPE_STRINGPOINT, 204,
|
||||
8.22.0, "Support was removed"),
|
||||
|
||||
/* Set a password for authenticated TLS */
|
||||
CURLOPT(CURLOPT_TLSAUTH_PASSWORD, CURLOPTTYPE_STRINGPOINT, 205),
|
||||
CURLOPTDEPRECATED(CURLOPT_TLSAUTH_PASSWORD, CURLOPTTYPE_STRINGPOINT, 205,
|
||||
8.22.0, "Support was removed"),
|
||||
|
||||
/* Set authentication type for authenticated TLS */
|
||||
CURLOPT(CURLOPT_TLSAUTH_TYPE, CURLOPTTYPE_STRINGPOINT, 206),
|
||||
CURLOPTDEPRECATED(CURLOPT_TLSAUTH_TYPE, CURLOPTTYPE_STRINGPOINT, 206,
|
||||
8.22.0, "Support was removed"),
|
||||
|
||||
/* Set to 1 to enable the "TE:" header in HTTP requests to ask for
|
||||
compressed transfer-encoded responses. Set to 0 to disable the use of TE:
|
||||
|
|
@ -2030,13 +2033,16 @@ typedef enum {
|
|||
CURLOPT(CURLOPT_PROXY_SSLVERSION, CURLOPTTYPE_VALUES, 250),
|
||||
|
||||
/* Set a username for authenticated TLS for proxy */
|
||||
CURLOPT(CURLOPT_PROXY_TLSAUTH_USERNAME, CURLOPTTYPE_STRINGPOINT, 251),
|
||||
CURLOPTDEPRECATED(CURLOPT_PROXY_TLSAUTH_USERNAME, CURLOPTTYPE_STRINGPOINT,
|
||||
251, 8.22.0, "Support was removed"),
|
||||
|
||||
/* Set a password for authenticated TLS for proxy */
|
||||
CURLOPT(CURLOPT_PROXY_TLSAUTH_PASSWORD, CURLOPTTYPE_STRINGPOINT, 252),
|
||||
CURLOPTDEPRECATED(CURLOPT_PROXY_TLSAUTH_PASSWORD, CURLOPTTYPE_STRINGPOINT,
|
||||
252, 8.22.0, "Support was removed"),
|
||||
|
||||
/* Set authentication type for authenticated TLS for proxy */
|
||||
CURLOPT(CURLOPT_PROXY_TLSAUTH_TYPE, CURLOPTTYPE_STRINGPOINT, 253),
|
||||
CURLOPTDEPRECATED(CURLOPT_PROXY_TLSAUTH_TYPE, CURLOPTTYPE_STRINGPOINT, 253,
|
||||
8.22.0, "Support was removed"),
|
||||
|
||||
/* name of the file keeping your private SSL-certificate for proxy */
|
||||
CURLOPT(CURLOPT_PROXY_SSLCERT, CURLOPTTYPE_STRINGPOINT, 254),
|
||||
|
|
|
|||
|
|
@ -770,15 +770,6 @@ ${SIZEOF_TIME_T_CODE}
|
|||
/* to enable Apple OS-native certificate verification */
|
||||
#cmakedefine USE_APPLE_SECTRUST 1
|
||||
|
||||
/* Define to 1 if OpenSSL has the SSL_CTX_set_srp_username function. */
|
||||
#cmakedefine HAVE_OPENSSL_SRP 1
|
||||
|
||||
/* Define to 1 if GnuTLS has the gnutls_srp_verifier function. */
|
||||
#cmakedefine HAVE_GNUTLS_SRP 1
|
||||
|
||||
/* Define to 1 to enable TLS-SRP support. */
|
||||
#cmakedefine USE_TLS_SRP 1
|
||||
|
||||
/* Define to 1 to query for HTTPSRR when using DoH */
|
||||
#cmakedefine USE_HTTPSRR 1
|
||||
|
||||
|
|
|
|||
|
|
@ -1577,7 +1577,7 @@ typedef struct sockaddr_un {
|
|||
#ifdef USE_OPENSSL
|
||||
/* OpenSSL 3 marks these functions deprecated but we have no replacements (yet)
|
||||
so tell the compiler to not warn for them:
|
||||
- DES_* (for NTLM), SSL_CTX_set_srp_* (for TLS-SRP)
|
||||
- DES_* (for NTLM)
|
||||
- EVP_PKEY_get1_RSA, MD5_*, RSA_flags, RSA_free (auto-skipped for OpenSSL
|
||||
built with no-deprecated) */
|
||||
# define OPENSSL_SUPPRESS_DEPRECATED
|
||||
|
|
|
|||
15
lib/setopt.c
15
lib/setopt.c
|
|
@ -2404,26 +2404,13 @@ static CURLcode setopt_cptr_misc(struct Curl_easy *data, CURLoption option,
|
|||
s->rtp_out = ptr;
|
||||
break;
|
||||
#endif /* !CURL_DISABLE_RTSP */
|
||||
#ifdef USE_TLS_SRP
|
||||
case CURLOPT_TLSAUTH_USERNAME:
|
||||
return Curl_setstropt(&s->str[STRING_TLSAUTH_USERNAME], ptr);
|
||||
case CURLOPT_TLSAUTH_PASSWORD:
|
||||
return Curl_setstropt(&s->str[STRING_TLSAUTH_PASSWORD], ptr);
|
||||
case CURLOPT_TLSAUTH_TYPE:
|
||||
if(ptr && !curl_strequal(ptr, "SRP"))
|
||||
result = CURLE_BAD_FUNCTION_ARGUMENT;
|
||||
break;
|
||||
#ifndef CURL_DISABLE_PROXY
|
||||
case CURLOPT_PROXY_TLSAUTH_USERNAME:
|
||||
return Curl_setstropt(&s->str[STRING_TLSAUTH_USERNAME_PROXY], ptr);
|
||||
case CURLOPT_PROXY_TLSAUTH_PASSWORD:
|
||||
return Curl_setstropt(&s->str[STRING_TLSAUTH_PASSWORD_PROXY], ptr);
|
||||
case CURLOPT_PROXY_TLSAUTH_TYPE:
|
||||
if(ptr && !curl_strequal(ptr, "SRP"))
|
||||
result = CURLE_BAD_FUNCTION_ARGUMENT;
|
||||
break;
|
||||
#endif
|
||||
#endif
|
||||
return CURLE_NOT_BUILT_IN;
|
||||
#ifndef CURL_DISABLE_HSTS
|
||||
case CURLOPT_HSTSREADDATA:
|
||||
s->hsts_read_userp = ptr;
|
||||
|
|
|
|||
|
|
@ -835,14 +835,6 @@ enum dupstring {
|
|||
#ifndef CURL_DISABLE_SMTP
|
||||
STRING_MAIL_FROM,
|
||||
STRING_MAIL_AUTH,
|
||||
#endif
|
||||
#ifdef USE_TLS_SRP
|
||||
STRING_TLSAUTH_USERNAME, /* TLS auth <username> */
|
||||
STRING_TLSAUTH_PASSWORD, /* TLS auth <password> */
|
||||
#ifndef CURL_DISABLE_PROXY
|
||||
STRING_TLSAUTH_USERNAME_PROXY, /* TLS auth <username> */
|
||||
STRING_TLSAUTH_PASSWORD_PROXY, /* TLS auth <password> */
|
||||
#endif
|
||||
#endif
|
||||
STRING_BEARER, /* <bearer>, if used */
|
||||
#ifdef USE_UNIX_SOCKETS
|
||||
|
|
|
|||
|
|
@ -521,9 +521,6 @@ static const struct feat features_table[] = {
|
|||
#ifdef GLOBAL_INIT_IS_THREADSAFE
|
||||
FEATURE("threadsafe", NULL, CURL_VERSION_THREADSAFE),
|
||||
#endif
|
||||
#ifdef USE_TLS_SRP
|
||||
FEATURE("TLS-SRP", NULL, CURL_VERSION_TLSAUTH_SRP),
|
||||
#endif
|
||||
#if defined(_WIN32) && defined(UNICODE) && defined(_UNICODE)
|
||||
FEATURE("Unicode", NULL, CURL_VERSION_UNICODE),
|
||||
#endif
|
||||
|
|
|
|||
|
|
@ -313,10 +313,6 @@ static gnutls_x509_crt_fmt_t gnutls_do_file_type(const char *type)
|
|||
|
||||
#define GNUTLS_CIPHERS "NORMAL:%PROFILE_MEDIUM:-ARCFOUR-128:" \
|
||||
"-CTYPE-ALL:+CTYPE-X509"
|
||||
/* If GnuTLS was compiled without support for SRP it errors out if SRP is
|
||||
requested in the priority string, so treat it specially
|
||||
*/
|
||||
#define GNUTLS_SRP "+SRP"
|
||||
|
||||
#define QUIC_PRIORITY \
|
||||
"NORMAL:%PROFILE_MEDIUM:-VERS-ALL:+VERS-TLS1.3:-CIPHER-ALL:+AES-128-GCM:" \
|
||||
|
|
@ -846,19 +842,6 @@ static CURLcode gtls_set_priority(struct Curl_cfilter *cf,
|
|||
|
||||
curlx_dyn_init(&buf, 4096);
|
||||
|
||||
#ifdef USE_GNUTLS_SRP
|
||||
if(conn_config->username) {
|
||||
/* Only add SRP to the cipher list if SRP is requested. Otherwise
|
||||
* GnuTLS disables TLS 1.3 support. */
|
||||
result = curlx_dyn_add(&buf, priority);
|
||||
if(!result)
|
||||
result = curlx_dyn_add(&buf, ":" GNUTLS_SRP);
|
||||
if(result)
|
||||
goto out;
|
||||
priority = curlx_dyn_ptr(&buf);
|
||||
}
|
||||
#endif
|
||||
|
||||
if(conn_config->cipher_list) {
|
||||
if((conn_config->cipher_list[0] == '+') ||
|
||||
(conn_config->cipher_list[0] == '-') ||
|
||||
|
|
@ -915,33 +898,6 @@ static CURLcode gtls_client_init(struct Curl_cfilter *cf,
|
|||
if(result)
|
||||
return result;
|
||||
|
||||
#ifdef USE_GNUTLS_SRP
|
||||
if(config->username && Curl_auth_allowed_to_host(data)) {
|
||||
infof(data, "Using TLS-SRP username: %s", config->username);
|
||||
|
||||
rc = gnutls_srp_allocate_client_credentials(>ls->srp_client_cred);
|
||||
if(rc == GNUTLS_E_UNIMPLEMENTED_FEATURE) {
|
||||
failf(data, "GnuTLS: TLS-SRP support not built in: %s",
|
||||
gnutls_strerror(rc));
|
||||
return CURLE_NOT_BUILT_IN;
|
||||
}
|
||||
else if(rc != GNUTLS_E_SUCCESS) {
|
||||
failf(data, "gnutls_srp_allocate_client_cred() failed: %s",
|
||||
gnutls_strerror(rc));
|
||||
return CURLE_OUT_OF_MEMORY;
|
||||
}
|
||||
|
||||
rc = gnutls_srp_set_client_credentials(gtls->srp_client_cred,
|
||||
config->username,
|
||||
config->password);
|
||||
if(rc != GNUTLS_E_SUCCESS) {
|
||||
failf(data, "gnutls_srp_set_client_cred() failed: %s",
|
||||
gnutls_strerror(rc));
|
||||
return CURLE_BAD_FUNCTION_ARGUMENT;
|
||||
}
|
||||
}
|
||||
#endif
|
||||
|
||||
ssl_config->certverifyresult = 0;
|
||||
|
||||
/* Initialize TLS session as a client */
|
||||
|
|
@ -1056,25 +1012,11 @@ static CURLcode gtls_client_init(struct Curl_cfilter *cf,
|
|||
}
|
||||
}
|
||||
|
||||
#ifdef USE_GNUTLS_SRP
|
||||
/* put the credentials to the current session */
|
||||
if(config->username) {
|
||||
rc = gnutls_credentials_set(gtls->session, GNUTLS_CRD_SRP,
|
||||
gtls->srp_client_cred);
|
||||
if(rc != GNUTLS_E_SUCCESS) {
|
||||
failf(data, "gnutls_credentials_set() failed: %s", gnutls_strerror(rc));
|
||||
return CURLE_SSL_CONNECT_ERROR;
|
||||
}
|
||||
}
|
||||
else
|
||||
#endif
|
||||
{
|
||||
rc = gnutls_credentials_set(gtls->session, GNUTLS_CRD_CERTIFICATE,
|
||||
gtls->shared_creds->creds);
|
||||
if(rc != GNUTLS_E_SUCCESS) {
|
||||
failf(data, "gnutls_credentials_set() failed: %s", gnutls_strerror(rc));
|
||||
return CURLE_SSL_CONNECT_ERROR;
|
||||
}
|
||||
rc = gnutls_credentials_set(gtls->session, GNUTLS_CRD_CERTIFICATE,
|
||||
gtls->shared_creds->creds);
|
||||
if(rc != GNUTLS_E_SUCCESS) {
|
||||
failf(data, "gnutls_credentials_set() failed: %s", gnutls_strerror(rc));
|
||||
return CURLE_SSL_CONNECT_ERROR;
|
||||
}
|
||||
|
||||
if(config->verifystatus) {
|
||||
|
|
@ -1728,21 +1670,10 @@ CURLcode Curl_gtls_verifyserver(struct Curl_cfilter *cf,
|
|||
if(config->verifypeer ||
|
||||
config->verifyhost ||
|
||||
config->issuercert) {
|
||||
#ifdef USE_GNUTLS_SRP
|
||||
if(ssl_config->primary.username && !config->verifypeer &&
|
||||
gnutls_cipher_get(session)) {
|
||||
/* no peer cert, but auth is ok if we have SRP user and cipher and no
|
||||
peer verify */
|
||||
}
|
||||
else {
|
||||
#endif
|
||||
failf(data, "failed to get server cert");
|
||||
*certverifyresult = GNUTLS_E_NO_CERTIFICATE_FOUND;
|
||||
result = CURLE_PEER_FAILED_VERIFICATION;
|
||||
goto out;
|
||||
#ifdef USE_GNUTLS_SRP
|
||||
}
|
||||
#endif
|
||||
failf(data, "failed to get server cert");
|
||||
*certverifyresult = GNUTLS_E_NO_CERTIFICATE_FOUND;
|
||||
result = CURLE_PEER_FAILED_VERIFICATION;
|
||||
goto out;
|
||||
}
|
||||
infof(data, " common name: WARNING could not obtain");
|
||||
}
|
||||
|
|
@ -2275,12 +2206,6 @@ static void gtls_close(struct Curl_cfilter *cf,
|
|||
if(backend->gtls.shared_creds) {
|
||||
Curl_gtls_shared_creds_free(&backend->gtls.shared_creds);
|
||||
}
|
||||
#ifdef USE_GNUTLS_SRP
|
||||
if(backend->gtls.srp_client_cred) {
|
||||
gnutls_srp_free_client_credentials(backend->gtls.srp_client_cred);
|
||||
backend->gtls.srp_client_cred = NULL;
|
||||
}
|
||||
#endif
|
||||
}
|
||||
|
||||
static CURLcode gtls_recv(struct Curl_cfilter *cf,
|
||||
|
|
|
|||
|
|
@ -31,14 +31,6 @@
|
|||
|
||||
#include "curlx/timeval.h"
|
||||
|
||||
#ifdef HAVE_GNUTLS_SRP
|
||||
/* the function exists */
|
||||
#ifdef USE_TLS_SRP
|
||||
/* the functionality is not disabled */
|
||||
#define USE_GNUTLS_SRP
|
||||
#endif
|
||||
#endif
|
||||
|
||||
struct Curl_easy;
|
||||
struct Curl_cfilter;
|
||||
struct alpn_spec;
|
||||
|
|
@ -64,9 +56,6 @@ void Curl_gtls_shared_creds_free(struct gtls_shared_creds **pcreds);
|
|||
struct gtls_ctx {
|
||||
gnutls_session_t session;
|
||||
struct gtls_shared_creds *shared_creds;
|
||||
#ifdef USE_GNUTLS_SRP
|
||||
gnutls_srp_client_credentials_t srp_client_cred;
|
||||
#endif
|
||||
CURLcode io_result; /* result of last IO cfilter operation */
|
||||
BIT(sent_shutdown);
|
||||
};
|
||||
|
|
|
|||
|
|
@ -3935,31 +3935,6 @@ CURLcode Curl_ossl_ctx_init(struct ossl_ctx *octx,
|
|||
}
|
||||
#endif
|
||||
|
||||
#if defined(HAVE_OPENSSL_SRP) && defined(USE_TLS_SRP)
|
||||
if(ssl_config->primary.username && Curl_auth_allowed_to_host(data)) {
|
||||
char * const ssl_username = ssl_config->primary.username;
|
||||
char * const ssl_password = ssl_config->primary.password;
|
||||
infof(data, "Using TLS-SRP username: %s", ssl_username);
|
||||
|
||||
if(!SSL_CTX_set_srp_username(octx->ssl_ctx, ssl_username)) {
|
||||
failf(data, "Unable to set SRP username");
|
||||
return CURLE_BAD_FUNCTION_ARGUMENT;
|
||||
}
|
||||
if(!SSL_CTX_set_srp_password(octx->ssl_ctx, ssl_password)) {
|
||||
failf(data, "failed setting SRP password");
|
||||
return CURLE_BAD_FUNCTION_ARGUMENT;
|
||||
}
|
||||
if(!conn_config->cipher_list) {
|
||||
infof(data, "Setting cipher list SRP");
|
||||
|
||||
if(!SSL_CTX_set_cipher_list(octx->ssl_ctx, "SRP")) {
|
||||
failf(data, "failed setting SRP cipher list");
|
||||
return CURLE_SSL_CIPHER;
|
||||
}
|
||||
}
|
||||
}
|
||||
#endif /* HAVE_OPENSSL_SRP && USE_TLS_SRP */
|
||||
|
||||
/* OpenSSL always tries to verify the peer. By setting the failure mode
|
||||
* to NONE, we allow the connect to complete, regardless of the outcome.
|
||||
* We then explicitly check the result and may try alternatives like
|
||||
|
|
|
|||
|
|
@ -133,10 +133,6 @@ void Curl_ssl_config_cleanup(struct ssl_primary_config *sslc)
|
|||
curlx_safefree(sslc->key);
|
||||
curlx_safefree(sslc->key_type);
|
||||
curlx_safefree(sslc->key_passwd);
|
||||
#ifdef USE_TLS_SRP
|
||||
curlx_safefree(sslc->username);
|
||||
curlx_safefree(sslc->password);
|
||||
#endif
|
||||
sslc->deep_copy = FALSE;
|
||||
}
|
||||
}
|
||||
|
|
@ -160,10 +156,6 @@ static bool match_ssl_primary_config(struct Curl_easy *data,
|
|||
Curl_safecmp(c1->CAfile, c2->CAfile) &&
|
||||
Curl_safecmp(c1->issuercert, c2->issuercert) &&
|
||||
Curl_safecmp(c1->clientcert, c2->clientcert) &&
|
||||
#ifdef USE_TLS_SRP
|
||||
!Curl_timestrcmp(c1->username, c2->username) &&
|
||||
!Curl_timestrcmp(c1->password, c2->password) &&
|
||||
#endif
|
||||
curl_strequal(c1->cipher_list, c2->cipher_list) &&
|
||||
curl_strequal(c1->cipher_list13, c2->cipher_list13) &&
|
||||
curl_strequal(c1->curves, c2->curves) &&
|
||||
|
|
@ -219,18 +211,13 @@ static bool clone_ssl_primary_config(struct ssl_primary_config *source,
|
|||
CLONE_STRING(curves);
|
||||
CLONE_STRING(signature_algorithms);
|
||||
CLONE_STRING(CRLfile);
|
||||
/* SSL credentials: client certificate, SRP auth */
|
||||
/* SSL credentials: client certificate */
|
||||
CLONE_STRING(clientcert);
|
||||
CLONE_STRING(cert_type);
|
||||
CLONE_STRING(key);
|
||||
CLONE_STRING(key_type);
|
||||
CLONE_STRING(key_passwd);
|
||||
CLONE_BLOB(key_blob);
|
||||
#ifdef USE_TLS_SRP
|
||||
CLONE_STRING(username);
|
||||
CLONE_STRING(password);
|
||||
#endif
|
||||
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
|
|
@ -307,10 +294,6 @@ CURLcode Curl_ssl_easy_config_complete(struct Curl_easy *data,
|
|||
sslc->primary.key_passwd = data->set.str[STRING_KEY_PASSWD];
|
||||
sslc->primary.clientcert = data->set.str[STRING_CERT];
|
||||
sslc->primary.key_blob = data->set.blobs[BLOB_KEY];
|
||||
#ifdef USE_TLS_SRP
|
||||
sslc->primary.username = data->set.str[STRING_TLSAUTH_USERNAME];
|
||||
sslc->primary.password = data->set.str[STRING_TLSAUTH_PASSWORD];
|
||||
#endif
|
||||
}
|
||||
else {
|
||||
sslc->primary.pinned_key = NULL;
|
||||
|
|
@ -321,10 +304,6 @@ CURLcode Curl_ssl_easy_config_complete(struct Curl_easy *data,
|
|||
sslc->primary.key_passwd = NULL;
|
||||
sslc->primary.clientcert = NULL;
|
||||
sslc->primary.key_blob = NULL;
|
||||
#ifdef USE_TLS_SRP
|
||||
sslc->primary.username = NULL;
|
||||
sslc->primary.password = NULL;
|
||||
#endif
|
||||
}
|
||||
|
||||
#ifndef CURL_DISABLE_PROXY
|
||||
|
|
@ -370,10 +349,6 @@ CURLcode Curl_ssl_easy_config_complete(struct Curl_easy *data,
|
|||
sslc->primary.key_passwd = data->set.str[STRING_KEY_PASSWD_PROXY];
|
||||
sslc->primary.clientcert = data->set.str[STRING_CERT_PROXY];
|
||||
sslc->primary.key_blob = data->set.blobs[BLOB_KEY_PROXY];
|
||||
#ifdef USE_TLS_SRP
|
||||
sslc->primary.username = data->set.str[STRING_TLSAUTH_USERNAME_PROXY];
|
||||
sslc->primary.password = data->set.str[STRING_TLSAUTH_PASSWORD_PROXY];
|
||||
#endif
|
||||
#endif /* CURL_DISABLE_PROXY */
|
||||
|
||||
return CURLE_OK;
|
||||
|
|
|
|||
|
|
@ -47,10 +47,6 @@ struct ssl_primary_config {
|
|||
struct curl_blob *ca_info_blob;
|
||||
struct curl_blob *issuercert_blob;
|
||||
struct curl_blob *key_blob;
|
||||
#ifdef USE_TLS_SRP
|
||||
char *username; /* TLS username (for, e.g., SRP) */
|
||||
char *password; /* TLS password (for, e.g., SRP) */
|
||||
#endif
|
||||
char *curves; /* list of curves to use */
|
||||
uint32_t version_max; /* max supported version the client wants to use */
|
||||
uint8_t ssl_options; /* the CURLOPT_SSL_OPTIONS bitmask */
|
||||
|
|
|
|||
|
|
@ -51,8 +51,6 @@ struct Curl_ssl_scache_peer {
|
|||
char *ssl_peer_key; /* id for peer + relevant TLS configuration */
|
||||
char *clientcert;
|
||||
char *key_passwd;
|
||||
char *srp_username;
|
||||
char *srp_password;
|
||||
struct Curl_llist sessions;
|
||||
void *sobj; /* object instance or NULL */
|
||||
Curl_ssl_scache_obj_dtor *sobj_free; /* free `sobj` callback */
|
||||
|
|
@ -321,13 +319,6 @@ static CURLcode ssl_peer_key_build(struct ssl_primary_config *ssl,
|
|||
result = cf_ssl_peer_key_add_mtls(&buf, ssl, &is_local);
|
||||
if(result)
|
||||
goto out;
|
||||
#ifdef USE_TLS_SRP
|
||||
if(ssl->username || ssl->password) {
|
||||
result = curlx_dyn_add(&buf, ":SRP-AUTH");
|
||||
if(result)
|
||||
goto out;
|
||||
}
|
||||
#endif
|
||||
|
||||
if(!tls_id || !tls_id[0]) {
|
||||
result = CURLE_FAILED_INIT;
|
||||
|
|
@ -516,10 +507,6 @@ static void cf_ssl_scache_clear_peer(struct Curl_ssl_scache_peer *peer)
|
|||
peer->sobj_free = NULL;
|
||||
curlx_safefree(peer->clientcert);
|
||||
curlx_safefree(peer->key_passwd);
|
||||
#ifdef USE_TLS_SRP
|
||||
curlx_safefree(peer->srp_username);
|
||||
curlx_safefree(peer->srp_password);
|
||||
#endif
|
||||
curlx_safefree(peer->ssl_peer_key);
|
||||
peer->age = 0;
|
||||
peer->hmac_set = FALSE;
|
||||
|
|
@ -545,7 +532,6 @@ static void cf_ssl_cache_peer_update(struct Curl_ssl_scache_peer *peer)
|
|||
* imported using only the salt+hmac
|
||||
* - the peer key is global, e.g. carrying no relative paths */
|
||||
peer->exportable = (!peer->clientcert && !peer->key_passwd &&
|
||||
!peer->srp_username && !peer->srp_password &&
|
||||
(!peer->ssl_peer_key ||
|
||||
cf_ssl_peer_key_is_global(peer->ssl_peer_key)));
|
||||
}
|
||||
|
|
@ -554,8 +540,6 @@ static CURLcode cf_ssl_scache_peer_init(struct Curl_ssl_scache_peer *peer,
|
|||
const char *ssl_peer_key,
|
||||
const char *clientcert,
|
||||
const char *key_passwd,
|
||||
const char *srp_username,
|
||||
const char *srp_password,
|
||||
const unsigned char *salt,
|
||||
const unsigned char *hmac)
|
||||
{
|
||||
|
|
@ -587,17 +571,6 @@ static CURLcode cf_ssl_scache_peer_init(struct Curl_ssl_scache_peer *peer,
|
|||
if(!peer->key_passwd)
|
||||
goto out;
|
||||
}
|
||||
if(srp_username) {
|
||||
peer->srp_username = curlx_strdup(srp_username);
|
||||
if(!peer->srp_username)
|
||||
goto out;
|
||||
}
|
||||
if(srp_password) {
|
||||
peer->srp_password = curlx_strdup(srp_password);
|
||||
if(!peer->srp_password)
|
||||
goto out;
|
||||
}
|
||||
|
||||
cf_ssl_cache_peer_update(peer);
|
||||
result = CURLE_OK;
|
||||
out:
|
||||
|
|
@ -730,21 +703,12 @@ static bool cf_ssl_scache_match_auth(struct Curl_ssl_scache_peer *peer,
|
|||
if(!conn_config) {
|
||||
if(peer->clientcert || peer->key_passwd)
|
||||
return FALSE;
|
||||
#ifdef USE_TLS_SRP
|
||||
if(peer->srp_username || peer->srp_password)
|
||||
return FALSE;
|
||||
#endif
|
||||
return TRUE;
|
||||
}
|
||||
else if(!Curl_safecmp(peer->clientcert, conn_config->clientcert))
|
||||
return FALSE;
|
||||
if(Curl_timestrcmp(peer->key_passwd, conn_config->key_passwd))
|
||||
return FALSE;
|
||||
#ifdef USE_TLS_SRP
|
||||
if(Curl_timestrcmp(peer->srp_username, conn_config->username) ||
|
||||
Curl_timestrcmp(peer->srp_password, conn_config->password))
|
||||
return FALSE;
|
||||
#endif
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
|
|
@ -869,11 +833,6 @@ static CURLcode cf_ssl_add_peer(struct Curl_easy *data,
|
|||
char buffer[64];
|
||||
const char *ccert = conn_config ? conn_config->clientcert : NULL;
|
||||
const char *kpasswd = conn_config ? conn_config->key_passwd : NULL;
|
||||
const char *username = NULL, *password = NULL;
|
||||
#ifdef USE_TLS_SRP
|
||||
username = conn_config ? conn_config->username : NULL;
|
||||
password = conn_config ? conn_config->password : NULL;
|
||||
#endif
|
||||
if(!ccert && conn_config && conn_config->cert_blob) {
|
||||
/* when using a client cert blob, create a name for it */
|
||||
curl_msnprintf(buffer, sizeof(buffer),
|
||||
|
|
@ -881,7 +840,7 @@ static CURLcode cf_ssl_add_peer(struct Curl_easy *data,
|
|||
ccert = buffer; /* data is strduped by cf_ssl_scache_peer_init */
|
||||
}
|
||||
result = cf_ssl_scache_peer_init(peer, ssl_peer_key, ccert, kpasswd,
|
||||
username, password, NULL, NULL);
|
||||
NULL, NULL);
|
||||
if(result)
|
||||
goto out;
|
||||
/* all ready */
|
||||
|
|
@ -1259,7 +1218,7 @@ CURLcode Curl_ssl_session_import(struct Curl_easy *data,
|
|||
peer = cf_ssl_get_free_peer(scache);
|
||||
if(peer) {
|
||||
result = cf_ssl_scache_peer_init(peer, ssl_peer_key, NULL, NULL,
|
||||
NULL, NULL, salt, hmac);
|
||||
salt, hmac);
|
||||
if(result)
|
||||
goto out;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -199,17 +199,5 @@ if test "$GNUTLS_ENABLED" = "1"; then
|
|||
if test "$USE_GNUTLS_NETTLE" = "1"; then
|
||||
LIBCURL_PC_REQUIRES_PRIVATE="$LIBCURL_PC_REQUIRES_PRIVATE nettle"
|
||||
fi
|
||||
|
||||
dnl ---
|
||||
dnl We require GnuTLS with SRP support.
|
||||
dnl
|
||||
dnl In GnuTLS 3.8.0 (2023-02-10) and upper, this check always succeeds.
|
||||
dnl Detecting actual TLS-SRP support needs poking the API at runtime.
|
||||
dnl ---
|
||||
AC_CHECK_LIB(gnutls, gnutls_srp_verifier,
|
||||
[
|
||||
AC_DEFINE(HAVE_GNUTLS_SRP, 1, [if you have the function gnutls_srp_verifier])
|
||||
HAVE_GNUTLS_SRP=1
|
||||
])
|
||||
fi
|
||||
])
|
||||
|
|
|
|||
|
|
@ -356,28 +356,6 @@ if test "$OPENSSL_ENABLED" = "1"; then
|
|||
AC_MSG_RESULT([no])
|
||||
])
|
||||
|
||||
dnl ---
|
||||
dnl We require OpenSSL with SRP support.
|
||||
dnl ---
|
||||
AC_MSG_CHECKING([for SRP support in OpenSSL])
|
||||
AC_LINK_IFELSE([
|
||||
AC_LANG_PROGRAM([[
|
||||
#ifndef OPENSSL_SUPPRESS_DEPRECATED
|
||||
#define OPENSSL_SUPPRESS_DEPRECATED
|
||||
#endif
|
||||
#include <openssl/ssl.h>
|
||||
]],[[
|
||||
SSL_CTX_set_srp_username(NULL, NULL);
|
||||
SSL_CTX_set_srp_password(NULL, NULL);
|
||||
]])
|
||||
],[
|
||||
AC_MSG_RESULT([yes])
|
||||
AC_DEFINE(HAVE_OPENSSL_SRP, 1, [if you have the functions SSL_CTX_set_srp_username and SSL_CTX_set_srp_password])
|
||||
HAVE_OPENSSL_SRP=1
|
||||
],[
|
||||
AC_MSG_RESULT([no])
|
||||
])
|
||||
|
||||
dnl ---
|
||||
dnl Whether the OpenSSL configuration is loaded automatically
|
||||
dnl ---
|
||||
|
|
|
|||
|
|
@ -54,7 +54,6 @@ my @longline = (
|
|||
'^renovate\.json$',
|
||||
'^docs/DISTROS\.md$',
|
||||
'^projects/Windows/tmpl/.+\.vcxproj$',
|
||||
'^tests/certs/srp-verifier-',
|
||||
'^tests/data/test',
|
||||
);
|
||||
|
||||
|
|
|
|||
|
|
@ -786,27 +786,6 @@ static CURLcode proxy_setopts(struct OperationConfig *config, CURL *curl)
|
|||
return result;
|
||||
}
|
||||
|
||||
static CURLcode tls_srp_setopts(struct OperationConfig *config, CURL *curl)
|
||||
{
|
||||
CURLcode result = CURLE_OK;
|
||||
if(config->tls_username)
|
||||
MY_SETOPT_STR(curl, CURLOPT_TLSAUTH_USERNAME, config->tls_username);
|
||||
if(config->tls_password)
|
||||
MY_SETOPT_STR(curl, CURLOPT_TLSAUTH_PASSWORD, config->tls_password);
|
||||
if(config->tls_authtype)
|
||||
MY_SETOPT_STR(curl, CURLOPT_TLSAUTH_TYPE, config->tls_authtype);
|
||||
if(config->proxy_tls_username)
|
||||
MY_SETOPT_STR(curl, CURLOPT_PROXY_TLSAUTH_USERNAME,
|
||||
config->proxy_tls_username);
|
||||
if(config->proxy_tls_password)
|
||||
MY_SETOPT_STR(curl, CURLOPT_PROXY_TLSAUTH_PASSWORD,
|
||||
config->proxy_tls_password);
|
||||
if(config->proxy_tls_authtype)
|
||||
MY_SETOPT_STR(curl, CURLOPT_PROXY_TLSAUTH_TYPE,
|
||||
config->proxy_tls_authtype);
|
||||
return result;
|
||||
}
|
||||
|
||||
static CURLcode setopt_post(struct OperationConfig *config, CURL *curl)
|
||||
{
|
||||
CURLcode result = CURLE_OK;
|
||||
|
|
@ -982,12 +961,6 @@ static CURLcode protocol_setopts(struct OperationConfig *config,
|
|||
#endif
|
||||
}
|
||||
|
||||
if(feature_tls_srp) {
|
||||
result = tls_srp_setopts(config, curl);
|
||||
if(setopt_bad(result))
|
||||
return result;
|
||||
}
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
|
|
@ -1071,6 +1044,16 @@ static CURLcode misc_setopts(struct OperationConfig *config, CURL *curl)
|
|||
if(config->proto_redir_present)
|
||||
MY_SETOPT_STR(curl, CURLOPT_REDIR_PROTOCOLS_STR, config->proto_redir_str);
|
||||
|
||||
my_setopt_slist(curl, CURLOPT_RESOLVE, config->resolve);
|
||||
my_setopt_slist(curl, CURLOPT_CONNECT_TO, config->connect_to);
|
||||
|
||||
if(config->gssapi_delegation)
|
||||
my_setopt_long(curl, CURLOPT_GSSAPI_DELEGATION, config->gssapi_delegation);
|
||||
|
||||
MY_SETOPT_STR(curl, CURLOPT_MAIL_AUTH, config->mail_auth);
|
||||
MY_SETOPT_STR(curl, CURLOPT_SASL_AUTHZID, config->sasl_authzid);
|
||||
my_setopt_long(curl, CURLOPT_SASL_IR, config->sasl_ir);
|
||||
|
||||
if(config->unix_socket_path) {
|
||||
if(config->abstract_unix_socket)
|
||||
MY_SETOPT_STR(curl, CURLOPT_ABSTRACT_UNIX_SOCKET,
|
||||
|
|
|
|||
|
|
@ -81,12 +81,6 @@ static void free_config_fields(struct OperationConfig *config)
|
|||
curlx_safefree(config->range);
|
||||
|
||||
curlx_safefree(config->userpwd);
|
||||
curlx_safefree(config->tls_username);
|
||||
curlx_safefree(config->tls_password);
|
||||
curlx_safefree(config->tls_authtype);
|
||||
curlx_safefree(config->proxy_tls_username);
|
||||
curlx_safefree(config->proxy_tls_password);
|
||||
curlx_safefree(config->proxy_tls_authtype);
|
||||
curlx_safefree(config->proxyuserpwd);
|
||||
curlx_safefree(config->proxy);
|
||||
|
||||
|
|
|
|||
|
|
@ -77,12 +77,6 @@ struct OperationConfig {
|
|||
char *dns_ipv6_addr; /* dot notation */
|
||||
char *userpwd;
|
||||
char *login_options;
|
||||
char *tls_username;
|
||||
char *tls_password;
|
||||
char *tls_authtype;
|
||||
char *proxy_tls_username;
|
||||
char *proxy_tls_password;
|
||||
char *proxy_tls_authtype;
|
||||
char *proxyuserpwd;
|
||||
char *proxy;
|
||||
char *noproxy;
|
||||
|
|
|
|||
|
|
@ -264,9 +264,11 @@ static const struct LongShort aliases[] = {
|
|||
{"proxy-ssl-auto-client-cert", ARG_BOOL|ARG_TLS, ' ',
|
||||
C_PROXY_SSL_AUTO_CLIENT_CERT},
|
||||
{"proxy-tls13-ciphers", ARG_STRG|ARG_TLS, ' ', C_PROXY_TLS13_CIPHERS},
|
||||
{"proxy-tlsauthtype", ARG_STRG|ARG_TLS, ' ', C_PROXY_TLSAUTHTYPE},
|
||||
{"proxy-tlspassword", ARG_STRG|ARG_TLS|ARG_CLEAR, ' ', C_PROXY_TLSPASSWORD},
|
||||
{"proxy-tlsuser", ARG_STRG|ARG_TLS|ARG_CLEAR, ' ', C_PROXY_TLSUSER},
|
||||
{"proxy-tlsauthtype", ARG_STRG|ARG_TLS|ARG_DEPR, ' ', C_PROXY_TLSAUTHTYPE},
|
||||
{"proxy-tlspassword", ARG_STRG|ARG_TLS|ARG_CLEAR|ARG_DEPR, ' ',
|
||||
C_PROXY_TLSPASSWORD},
|
||||
{"proxy-tlsuser", ARG_STRG|ARG_TLS|ARG_CLEAR|ARG_DEPR, ' ',
|
||||
C_PROXY_TLSUSER},
|
||||
{"proxy-tlsv1", ARG_NONE|ARG_TLS, ' ', C_PROXY_TLSV1},
|
||||
{"proxy-user", ARG_STRG|ARG_CLEAR, 'U', C_PROXY_USER},
|
||||
{"proxy1.0", ARG_STRG, ' ', C_PROXY1_0},
|
||||
|
|
@ -338,9 +340,9 @@ static const struct LongShort aliases[] = {
|
|||
{"tls-earlydata", ARG_BOOL|ARG_TLS, ' ', C_TLS_EARLYDATA},
|
||||
{"tls-max", ARG_STRG|ARG_TLS, ' ', C_TLS_MAX},
|
||||
{"tls13-ciphers", ARG_STRG|ARG_TLS, ' ', C_TLS13_CIPHERS},
|
||||
{"tlsauthtype", ARG_STRG|ARG_TLS, ' ', C_TLSAUTHTYPE},
|
||||
{"tlspassword", ARG_STRG|ARG_TLS|ARG_CLEAR, ' ', C_TLSPASSWORD},
|
||||
{"tlsuser", ARG_STRG|ARG_TLS|ARG_CLEAR, ' ', C_TLSUSER},
|
||||
{"tlsauthtype", ARG_STRG|ARG_TLS|ARG_DEPR, ' ', C_TLSAUTHTYPE},
|
||||
{"tlspassword", ARG_STRG|ARG_TLS|ARG_CLEAR|ARG_DEPR, ' ', C_TLSPASSWORD},
|
||||
{"tlsuser", ARG_STRG|ARG_TLS|ARG_CLEAR|ARG_DEPR, ' ', C_TLSUSER},
|
||||
{"tlsv1", ARG_NONE|ARG_TLS, '1', C_TLSV1},
|
||||
{"tlsv1.0", ARG_NONE|ARG_TLS, ' ', C_TLSV1_0},
|
||||
{"tlsv1.1", ARG_NONE|ARG_TLS, ' ', C_TLSV1_1},
|
||||
|
|
@ -2787,55 +2789,12 @@ static ParameterError opt_string(struct OperationConfig *config,
|
|||
case C_HOSTPUBSHA256: /* --hostpubsha256 */
|
||||
err = getstr(&config->hostpubsha256, nextarg, DENY_BLANK);
|
||||
break;
|
||||
case C_TLSUSER: /* --tlsuser */
|
||||
if(!feature_tls_srp)
|
||||
err = PARAM_LIBCURL_DOESNT_SUPPORT;
|
||||
else
|
||||
err = getstr(&config->tls_username, nextarg, DENY_BLANK);
|
||||
break;
|
||||
case C_TLSPASSWORD: /* --tlspassword */
|
||||
if(!feature_tls_srp)
|
||||
err = PARAM_LIBCURL_DOESNT_SUPPORT;
|
||||
else
|
||||
err = getstr(&config->tls_password, nextarg, ALLOW_BLANK);
|
||||
break;
|
||||
case C_TLSAUTHTYPE: /* --tlsauthtype */
|
||||
if(!feature_tls_srp)
|
||||
err = PARAM_LIBCURL_DOESNT_SUPPORT;
|
||||
else {
|
||||
err = getstr(&config->tls_authtype, nextarg, DENY_BLANK);
|
||||
if(!err && config->tls_authtype && strcmp(config->tls_authtype, "SRP"))
|
||||
err = PARAM_LIBCURL_DOESNT_SUPPORT; /* only support TLS-SRP */
|
||||
}
|
||||
break;
|
||||
case C_PINNEDPUBKEY: /* --pinnedpubkey */
|
||||
err = getstr(&config->pinnedpubkey, nextarg, DENY_BLANK);
|
||||
break;
|
||||
case C_PROXY_PINNEDPUBKEY: /* --proxy-pinnedpubkey */
|
||||
err = getstr(&config->proxy_pinnedpubkey, nextarg, DENY_BLANK);
|
||||
break;
|
||||
case C_PROXY_TLSUSER: /* --proxy-tlsuser */
|
||||
if(!feature_tls_srp)
|
||||
err = PARAM_LIBCURL_DOESNT_SUPPORT;
|
||||
else
|
||||
err = getstr(&config->proxy_tls_username, nextarg, ALLOW_BLANK);
|
||||
break;
|
||||
case C_PROXY_TLSPASSWORD: /* --proxy-tlspassword */
|
||||
if(!feature_tls_srp)
|
||||
err = PARAM_LIBCURL_DOESNT_SUPPORT;
|
||||
else
|
||||
err = getstr(&config->proxy_tls_password, nextarg, DENY_BLANK);
|
||||
break;
|
||||
case C_PROXY_TLSAUTHTYPE: /* --proxy-tlsauthtype */
|
||||
if(!feature_tls_srp)
|
||||
err = PARAM_LIBCURL_DOESNT_SUPPORT;
|
||||
else {
|
||||
err = getstr(&config->proxy_tls_authtype, nextarg, DENY_BLANK);
|
||||
if(!err && config->proxy_tls_authtype &&
|
||||
strcmp(config->proxy_tls_authtype, "SRP"))
|
||||
err = PARAM_LIBCURL_DOESNT_SUPPORT; /* only support TLS-SRP */
|
||||
}
|
||||
break;
|
||||
case C_PROXY_CERT_TYPE: /* --proxy-cert-type */
|
||||
err = getstr(&config->proxy_cert_type, nextarg, DENY_BLANK);
|
||||
break;
|
||||
|
|
@ -3069,6 +3028,8 @@ ParameterError getparameter(const char *flag, /* f or -long-flag */
|
|||
*usedarg = consumearg; /* mark it as used */
|
||||
}
|
||||
if(a->desc & ARG_DEPR) {
|
||||
if(a->desc & ARG_CLEAR)
|
||||
cleanarg(CURL_UNCONST(nextarg));
|
||||
opt_depr(a);
|
||||
break;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -75,7 +75,6 @@ bool feature_ntlm = FALSE;
|
|||
bool feature_ntlm_wb = FALSE;
|
||||
bool feature_spnego = FALSE;
|
||||
bool feature_ssl = FALSE;
|
||||
bool feature_tls_srp = FALSE;
|
||||
bool feature_zstd = FALSE;
|
||||
bool feature_ech = FALSE;
|
||||
bool feature_ssls_export = FALSE;
|
||||
|
|
@ -112,7 +111,6 @@ static struct feature_name_presentp {
|
|||
{ "SSPI", NULL, CURL_VERSION_SSPI },
|
||||
{ "SSLS-EXPORT", &feature_ssls_export, 0 },
|
||||
{ "threadsafe", NULL, CURL_VERSION_THREADSAFE },
|
||||
{ "TLS-SRP", &feature_tls_srp, CURL_VERSION_TLSAUTH_SRP },
|
||||
{ "Unicode", NULL, CURL_VERSION_UNICODE },
|
||||
{ "UnixSockets", NULL, CURL_VERSION_UNIX_SOCKETS },
|
||||
{ "zstd", &feature_zstd, CURL_VERSION_ZSTD },
|
||||
|
|
|
|||
|
|
@ -58,7 +58,6 @@ extern bool feature_ntlm;
|
|||
extern bool feature_ntlm_wb;
|
||||
extern bool feature_spnego;
|
||||
extern bool feature_ssl;
|
||||
extern bool feature_tls_srp;
|
||||
extern bool feature_zstd;
|
||||
extern bool feature_ech;
|
||||
extern bool feature_ssls_export;
|
||||
|
|
|
|||
|
|
@ -23,10 +23,10 @@
|
|||
###########################################################################
|
||||
AUTOMAKE_OPTIONS = foreign
|
||||
|
||||
# Get CERTCONFIG_CA, CERTCONFIGS, GENERATEDCERTS, SRPFILES variables
|
||||
# Get CERTCONFIG_CA, CERTCONFIGS, GENERATEDCERTS variables
|
||||
include Makefile.inc
|
||||
|
||||
EXTRA_DIST = $(CERTCONFIG_CA) $(CERTCONFIGS) $(SRPFILES) CMakeLists.txt \
|
||||
EXTRA_DIST = $(CERTCONFIG_CA) $(CERTCONFIGS) CMakeLists.txt \
|
||||
genserv.pl
|
||||
|
||||
CLEANFILES = $(GENERATEDCERTS)
|
||||
|
|
|
|||
|
|
@ -82,7 +82,3 @@ GENERATEDCERTS = \
|
|||
test-localhost0h.pem \
|
||||
test-localhost0h.pub.der \
|
||||
test-localhost0h.pub.pem
|
||||
|
||||
SRPFILES = \
|
||||
srp-verifier-conf \
|
||||
srp-verifier-db
|
||||
|
|
|
|||
|
|
@ -1,3 +0,0 @@
|
|||
1:Ewl2hcjiutMd3Fu2lgFnUXWSc67TVyy2vwYCKoS9MLsrdJVT9RgWTCuEqWJrfB6uE3LsE9GkOlaZabS7M29sj5TnzUqOLJMjiwEzArfiLr9WbMRANlF68N5AVLcPWvNx6Zjl3m5Scp0BzJBz9TkgfhzKJZ.WtP3Mv/67I/0wmRZ:2
|
||||
2:dUyyhxav9tgnyIg65wHxkzkb7VIPh4o0lkwfOKiPp4rVJrzLRYVBtb76gKlaO7ef5LYGEw3G.4E0jbMxcYBetDy2YdpiP/3GWJInoBbvYHIRO9uBuxgsFKTKWu7RnR7yTau/IrFTdQ4LY/q.AvoCzMxV0PKvD9Odso/LFIItn8PbTov3VMn/ZEH2SqhtpBUkWtmcIkEflhX/YY/fkBKfBbe27/zUaKUUZEUYZ2H2nlCL60.JIPeZJSzsu/xHDVcx:2
|
||||
3:2iQzj1CagQc/5ctbuJYLWlhtAsPHc7xWVyCPAKFRLWKADpASkqe9djWPFWTNTdeJtL8nAhImCn3Sr/IAdQ1FrGw0WvQUstPx3FO9KNcXOwisOQ1VlL.gheAHYfbYyBaxXL.NcJx9TUwgWDT0hRzFzqSrdGGTN3FgSTA1v4QnHtEygNj3eZ.u0MThqWUaDiP87nqha7XnT66bkTCkQ8.7T8L4KZjIImrNrUftedTTBi.WCi.zlrBxDuOM0da0JbUkQlXqvp0yvJAPpC11nxmmZOAbQOywZGmu9nhZNuwTlxjfIro0FOdthaDTuZRL9VL7MRPUDo/DQEyW.d4H.UIlzp:2
|
||||
|
|
@ -1,2 +0,0 @@
|
|||
jsmith:34fPk7u.w3R/M1k2sQ9F.04GZqLKAsqDn44CHGu7ML0M8VWwu1p79OLxi6jRhSNdSM46Kx9GRVyJLXz7eok53..A6X5p3NdnMSYX8WwYrDmuseHDr.eua7gjd04S4EoY4ZuKix2.WGAsMTwk86AmTvcqyzqsH7GDhGOHEhjP5zs:lTjBBoK04K9vTKiL10rI/:1
|
||||
alice:3IIP1g1HDTN6VEUr8DUkMleocoC1cpuFZnmunDaGhMyIsw8LAwCc7ZapWaC66gZSyis4ezSuCqvhsJdwdc.0es2UrH6PBkBQflcQDuC.dEpjhWgAcH2Dw.2qU.E0ApQzLkcKOjXMQ2R6jMBL14kEUPjjHS3aa16yB.Afj3bNPdf:1JxU4GkweUEii6.b0grkzU:1
|
||||
|
|
@ -27,10 +27,6 @@
|
|||
# per line.
|
||||
# Lines starting with '#' letters are treated as comments.
|
||||
#
|
||||
# Uses SRP to "a server not supporting it" but modern stunnel versions
|
||||
# silently accept it and remain happy
|
||||
323
|
||||
#
|
||||
594
|
||||
836
|
||||
882
|
||||
|
|
|
|||
|
|
@ -60,7 +60,7 @@ test280 test281 test282 test283 test284 test285 test286 test287 test288 \
|
|||
test289 test290 test291 test292 test293 test294 test295 test296 test297 \
|
||||
test298 test299 test300 test301 test302 test303 test304 test305 test306 \
|
||||
test307 test308 test309 test310 test311 test312 test313 test314 test315 \
|
||||
test316 test317 test318 test319 test320 test321 test322 test323 test324 \
|
||||
test316 test317 test318 test319 \
|
||||
test325 test326 test327 test328 test329 test330 test331 test332 test333 \
|
||||
test334 test335 test336 test337 test338 test339 test340 test341 test342 \
|
||||
test343 test344 test345 test346 test347 test348 test349 test350 test351 \
|
||||
|
|
@ -292,7 +292,7 @@ test3400 test3401 \
|
|||
\
|
||||
test4000 test4001
|
||||
|
||||
EXTRA_DIST = $(TESTCASES) DISABLED data-xml1 data320.html \
|
||||
EXTRA_DIST = $(TESTCASES) DISABLED data-xml1 \
|
||||
data1461.txt data1463.txt \
|
||||
data1400.c data1401.c data1402.c data1403.c data1404.c data1405.c data1406.c \
|
||||
data1407.c data1420.c data1465.c data1481.c \
|
||||
|
|
|
|||
|
|
@ -1,19 +0,0 @@
|
|||
<HTML><BODY>
|
||||
<CENTER><H1>This is <a href="http://www.gnu.org/software/gnutls">GnuTLS</a></H1></CENTER>
|
||||
|
||||
<p>Session ID: <i>003030000100000001000000000000000030330001000000B062410001000000</i></p>
|
||||
<h5>If your browser supports session resuming, then you should see the same session ID, when you press the <b>reload</b> button.</h5>
|
||||
<p>Connected as user 'jsmith'.</p>
|
||||
<P>
|
||||
<TABLE border=1><TR><TD>Protocol version:</TD><TD>TLS1.2</TD></TR>
|
||||
<TR><TD>Key Exchange:</TD><TD>SRP</TD></TR>
|
||||
<TR><TD>Compression</TD><TD>NULL</TD></TR>
|
||||
<TR><TD>Cipher</TD><TD>AES-NNN-CBC</TD></TR>
|
||||
<TR><TD>MAC</TD><TD>SHA1</TD></TR>
|
||||
<TR><TD>Ciphersuite</TD><TD>SRP_SHA_AES_NNN_CBC_SHA1</TD></TR></p></TABLE>
|
||||
<hr><P>Your HTTP header was:<PRE>Host: localhost:9011%CR
|
||||
User-Agent: curl-test-suite%CR
|
||||
Accept: */*%CR
|
||||
%CR
|
||||
</PRE></P>
|
||||
</BODY></HTML>
|
||||
|
|
@ -1,55 +0,0 @@
|
|||
<?xml version="1.0" encoding="US-ASCII"?>
|
||||
<testcase>
|
||||
<info>
|
||||
<keywords>
|
||||
HTTPS
|
||||
HTTP GET
|
||||
TLS-SRP
|
||||
</keywords>
|
||||
</info>
|
||||
|
||||
# Server-side
|
||||
<reply>
|
||||
<data nocheck="yes">
|
||||
%includetext %SRCDIR/data/data%TESTNUMBER.html%
|
||||
</data>
|
||||
</reply>
|
||||
|
||||
# Client-side
|
||||
<client>
|
||||
<server>
|
||||
httptls+srp
|
||||
</server>
|
||||
<features>
|
||||
TLS-SRP
|
||||
</features>
|
||||
<name>
|
||||
simple TLS-SRP HTTPS GET, check user in response
|
||||
</name>
|
||||
<command>
|
||||
--insecure --tlsauthtype SRP --tlsuser jsmith --tlspassword abc -A curl-test-suite https://%HOSTIP:%HTTPTLSPORT
|
||||
</command>
|
||||
</client>
|
||||
|
||||
# Verify data after the test has been "shot"
|
||||
<verify>
|
||||
<file name="%LOGDIR/curl%TESTNUMBER.out" crlf="headers">
|
||||
HTTP/1.0 200 OK
|
||||
Content-type: text/html
|
||||
|
||||
FINE
|
||||
User-Agent: curl-test-suite
|
||||
Accept: */*
|
||||
|
||||
</file>
|
||||
<stripfile>
|
||||
s/^%LTp%GTConnected as user 'jsmith'.*/FINE/
|
||||
s/Protocol version:.*[0-9]//
|
||||
s/GNUTLS/GnuTLS/
|
||||
s/(AES[-_])\d\d\d([-_]CBC)/$1NNN$2/
|
||||
s/^%LT.*\n//
|
||||
s/^\n//
|
||||
</stripfile>
|
||||
</verify>
|
||||
|
||||
</testcase>
|
||||
|
|
@ -1,33 +0,0 @@
|
|||
<?xml version="1.0" encoding="US-ASCII"?>
|
||||
<testcase>
|
||||
<info>
|
||||
<keywords>
|
||||
HTTPS
|
||||
TLS-SRP
|
||||
</keywords>
|
||||
</info>
|
||||
|
||||
# Client-side
|
||||
<client>
|
||||
<server>
|
||||
httptls+srp
|
||||
</server>
|
||||
<features>
|
||||
TLS-SRP
|
||||
</features>
|
||||
<name>
|
||||
TLS-SRP with bad username and password
|
||||
</name>
|
||||
<command>
|
||||
--insecure --tlsauthtype SRP --tlsuser baduser --tlspassword badpass https://%HOSTIP:%HTTPTLSPORT
|
||||
</command>
|
||||
</client>
|
||||
|
||||
# Verify data after the test has been "shot"
|
||||
<verify>
|
||||
<errorcode>
|
||||
35
|
||||
</errorcode>
|
||||
</verify>
|
||||
|
||||
</testcase>
|
||||
|
|
@ -1,33 +0,0 @@
|
|||
<?xml version="1.0" encoding="US-ASCII"?>
|
||||
<testcase>
|
||||
<info>
|
||||
<keywords>
|
||||
HTTPS
|
||||
TLS-SRP
|
||||
</keywords>
|
||||
</info>
|
||||
|
||||
# Client-side
|
||||
<client>
|
||||
<server>
|
||||
httptls+srp
|
||||
</server>
|
||||
<features>
|
||||
TLS-SRP
|
||||
</features>
|
||||
<name>
|
||||
TLS-SRP with bad password
|
||||
</name>
|
||||
<command>
|
||||
--insecure --tlsauthtype SRP --tlsuser jsmith --tlspassword badpass https://%HOSTIP:%HTTPTLSPORT
|
||||
</command>
|
||||
</client>
|
||||
|
||||
# Verify data after the test has been "shot"
|
||||
<verify>
|
||||
<errorcode>
|
||||
35
|
||||
</errorcode>
|
||||
</verify>
|
||||
|
||||
</testcase>
|
||||
|
|
@ -1,33 +0,0 @@
|
|||
<?xml version="1.0" encoding="US-ASCII"?>
|
||||
<testcase>
|
||||
<info>
|
||||
<keywords>
|
||||
HTTPS
|
||||
TLS-SRP
|
||||
</keywords>
|
||||
</info>
|
||||
|
||||
# Client-side
|
||||
<client>
|
||||
<server>
|
||||
https
|
||||
</server>
|
||||
<features>
|
||||
TLS-SRP
|
||||
</features>
|
||||
<name>
|
||||
TLS-SRP to non-TLS-SRP server
|
||||
</name>
|
||||
<command>
|
||||
--insecure --tlsauthtype SRP --tlsuser jsmith --tlspassword badpass https://%HOSTIP:%HTTPSPORT/want/%TESTNUMBER
|
||||
</command>
|
||||
</client>
|
||||
|
||||
# Verify data after the test has been "shot"
|
||||
<verify>
|
||||
<errorcode>
|
||||
35
|
||||
</errorcode>
|
||||
</verify>
|
||||
|
||||
</testcase>
|
||||
|
|
@ -1,33 +0,0 @@
|
|||
<?xml version="1.0" encoding="US-ASCII"?>
|
||||
<testcase>
|
||||
<info>
|
||||
<keywords>
|
||||
HTTPS
|
||||
TLS-SRP
|
||||
</keywords>
|
||||
</info>
|
||||
|
||||
# Client-side
|
||||
<client>
|
||||
<server>
|
||||
httptls+srp
|
||||
</server>
|
||||
<features>
|
||||
TLS-SRP
|
||||
</features>
|
||||
<name>
|
||||
TLS-SRP with server cert checking
|
||||
</name>
|
||||
<command> # no --insecure
|
||||
--tlsauthtype SRP --tlsuser jsmith --tlspassword abc https://%HOSTIP:%HTTPTLSPORT/want/fails
|
||||
</command>
|
||||
</client>
|
||||
|
||||
# Verify data after the test has been "shot"
|
||||
<verify>
|
||||
<errorcode>
|
||||
60
|
||||
</errorcode>
|
||||
</verify>
|
||||
|
||||
</testcase>
|
||||
|
|
@ -697,8 +697,6 @@ sub checksystemfeatures {
|
|||
$feature{"Kerberos"} = $feat =~ /Kerberos/i;
|
||||
# SPNEGO enabled
|
||||
$feature{"SPNEGO"} = $feat =~ /SPNEGO/i;
|
||||
# TLS-SRP enabled
|
||||
$feature{"TLS-SRP"} = $feat =~ /TLS-SRP/i;
|
||||
# PSL enabled
|
||||
$feature{"PSL"} = $feat =~ /PSL/i;
|
||||
# alt-svc enabled
|
||||
|
|
@ -739,27 +737,6 @@ sub checksystemfeatures {
|
|||
$feature{"HTTPSRR"} = $feat =~ /HTTPSRR/;
|
||||
$feature{"ECH"} = $feat =~ /ECH/;
|
||||
}
|
||||
#
|
||||
# Test harness currently uses a non-stunnel server in order to
|
||||
# run HTTP TLS-SRP tests required when curl is built with https
|
||||
# protocol support and TLS-SRP feature enabled. For convenience
|
||||
# 'httptls' may be included in the test harness protocols array
|
||||
# to differentiate this from classic stunnel based 'https' test
|
||||
# harness server.
|
||||
#
|
||||
if($feature{"TLS-SRP"}) {
|
||||
my $add_httptls;
|
||||
for(@protocols) {
|
||||
if($_ =~ /^https(-ipv6|)$/) {
|
||||
$add_httptls = 1;
|
||||
last;
|
||||
}
|
||||
}
|
||||
if($add_httptls && (! grep /^httptls$/, @protocols)) {
|
||||
push @protocols, 'httptls';
|
||||
push @protocols, 'httptls-ipv6';
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if($torture) {
|
||||
|
|
|
|||
|
|
@ -67,10 +67,9 @@ use testutil qw(
|
|||
our $logfile; # server log filename, for logmsg
|
||||
|
||||
#***************************************************************************
|
||||
# For convenience, test harness uses 'https' and 'httptls' literals as
|
||||
# values for 'proto' variable in order to differentiate different servers.
|
||||
# 'https' literal is used for stunnel based https test servers, and 'httptls'
|
||||
# is used for non-stunnel https test servers.
|
||||
# For convenience, test harness uses 'https' literal as values for 'proto'
|
||||
# variable in order to differentiate different servers. 'https' literal is
|
||||
# used for stunnel based https test servers.
|
||||
|
||||
#**********************************************************************
|
||||
# logmsg is general message logging subroutine for our test servers.
|
||||
|
|
@ -105,7 +104,7 @@ sub serverfactors {
|
|||
$ipvnum = ($4 && ($4 =~ /6$/)) ? 6 : 4;
|
||||
}
|
||||
elsif($server =~
|
||||
/^(dns|tftp|sftp|socks|ssh|rtsp|gopher|httptls)(\d*)(-ipv6|)$/) {
|
||||
/^(dns|tftp|sftp|socks|ssh|rtsp|gopher)(\d*)(-ipv6|)$/) {
|
||||
$proto = $1;
|
||||
$idnum = ($2 && ($2 > 1)) ? $2 : 1;
|
||||
$ipvnum = ($3 && ($3 =~ /6$/)) ? 6 : 4;
|
||||
|
|
@ -124,7 +123,7 @@ sub servername_str {
|
|||
|
||||
$proto = uc($proto) if($proto);
|
||||
die "unsupported protocol: '$proto'" unless($proto &&
|
||||
($proto =~ /^(((DNS|FTP|HTTP|HTTP\/2|HTTP\/3|IMAP|POP3|GOPHER|SMTP|HTTPS-MTLS)S?)|(TFTP|SFTP|SOCKS|SSH|RTSP|HTTPTLS|DICT|SMB|SMBS|TELNET|MQTT|MQTTS))$/));
|
||||
($proto =~ /^(((DNS|FTP|HTTP|HTTP\/2|HTTP\/3|IMAP|POP3|GOPHER|SMTP|HTTPS-MTLS)S?)|(TFTP|SFTP|SOCKS|SSH|RTSP|DICT|SMB|SMBS|TELNET|MQTT|MQTTS))$/));
|
||||
|
||||
$ipver = (not $ipver) ? 'ipv4' : lc($ipver);
|
||||
die "unsupported IP version: '$ipver'" unless($ipver &&
|
||||
|
|
|
|||
223
tests/servers.pm
223
tests/servers.pm
|
|
@ -96,7 +96,6 @@ use sshhelp qw(
|
|||
find_sshd
|
||||
find_ssh
|
||||
find_sftp
|
||||
find_httptlssrv
|
||||
sshversioninfo
|
||||
);
|
||||
|
||||
|
|
@ -125,7 +124,6 @@ my $sshderror; # for socks server, ssh daemon version error
|
|||
my %doesntrun; # servers that do not work, identified by pidfile
|
||||
my %PORT = (nolisten => 47); # port we use for a local non-listening service
|
||||
my $server_response_maxtime = 13;
|
||||
my $httptlssrv = find_httptlssrv();
|
||||
my %run; # running server
|
||||
my %runcert; # cert file currently in use by an SSL running server
|
||||
my $CLIENTIP = "127.0.0.1"; # address which curl uses for incoming connections
|
||||
|
|
@ -236,7 +234,7 @@ sub init_serverpidfile_hash {
|
|||
}
|
||||
}
|
||||
}
|
||||
for my $proto (('tftp', 'sftp', 'socks', 'ssh', 'rtsp', 'httptls',
|
||||
for my $proto (('tftp', 'sftp', 'socks', 'ssh', 'rtsp',
|
||||
'dict', 'smb', 'smbs', 'telnet', 'mqtt', 'mqtts',
|
||||
'https-mtls', 'dns')) {
|
||||
for my $ipvnum ((4, 6)) {
|
||||
|
|
@ -301,10 +299,6 @@ sub serverfortest {
|
|||
my $server = "${1}";
|
||||
my $lnrest = "${2}";
|
||||
my $tlsext;
|
||||
if($server =~ /^(httptls)(\+)(ext|srp)(\d*)(-ipv6|)$/) {
|
||||
$server = "${1}${4}${5}";
|
||||
$tlsext = uc("TLS-${3}");
|
||||
}
|
||||
|
||||
my @lprotocols = @protocols;
|
||||
|
||||
|
|
@ -789,88 +783,6 @@ sub verifysftp {
|
|||
return $verified;
|
||||
}
|
||||
|
||||
#######################################################################
|
||||
# Verify that the non-stunnel HTTP TLS extensions capable server that runs
|
||||
# on $ip, $port is our server. This also implies that we can speak with it,
|
||||
# as there might be occasions when the server runs fine but we cannot talk
|
||||
# to it ("Failed to connect to ::1: Cannot assign requested address")
|
||||
#
|
||||
sub verifyhttptls {
|
||||
my ($proto, $ipvnum, $idnum, $ip, $port) = @_;
|
||||
my $server = servername_id($proto, $ipvnum, $idnum);
|
||||
my $pidfile = server_pidfilename("$LOGDIR/$PIDDIR", $proto, $ipvnum,
|
||||
$idnum);
|
||||
|
||||
my $verifyout = "$LOGDIR/".
|
||||
servername_canon($proto, $ipvnum, $idnum) .'_verify.out';
|
||||
unlink($verifyout) if(-f $verifyout);
|
||||
|
||||
my $verifylog = "$LOGDIR/".
|
||||
servername_canon($proto, $ipvnum, $idnum) .'_verify.log';
|
||||
unlink($verifylog) if(-f $verifylog);
|
||||
|
||||
my $flags = "--max-time $server_response_maxtime ";
|
||||
$flags .= "--output $verifyout ";
|
||||
$flags .= "--verbose ";
|
||||
$flags .= "--globoff ";
|
||||
$flags .= "--insecure ";
|
||||
$flags .= "--tlsauthtype SRP ";
|
||||
$flags .= "--tlsuser jsmith ";
|
||||
$flags .= "--tlspassword abc ";
|
||||
if($proxy_address) {
|
||||
$flags .= getexternalproxyflags();
|
||||
}
|
||||
$flags .= "\"https://$ip:$port/verifiedserver\"";
|
||||
|
||||
my $cmd = exerunner() . "$VCURL $flags 2>$verifylog";
|
||||
|
||||
# verify if our/any server is running on this port
|
||||
logmsg "RUN: $cmd\n" if($verbose);
|
||||
my $res = runclient($cmd);
|
||||
|
||||
$res >>= 8; # rotate the result
|
||||
if($res & 128) {
|
||||
logmsg "RUN: curl command died with a coredump\n";
|
||||
return -1;
|
||||
}
|
||||
|
||||
if($res && $verbose) {
|
||||
logmsg "RUN: curl command returned $res\n";
|
||||
if(open(my $file, "<", $verifylog)) {
|
||||
while(my $string = <$file>) {
|
||||
logmsg "RUN: $string" if($string !~ /^([ \t]*)$/);
|
||||
}
|
||||
close($file);
|
||||
}
|
||||
}
|
||||
|
||||
my $data;
|
||||
if(open(my $file, "<", $verifyout)) {
|
||||
while(my $string = <$file>) {
|
||||
$data .= $string;
|
||||
}
|
||||
close($file);
|
||||
}
|
||||
|
||||
my $pid = 0;
|
||||
if($data && ($data =~ /(GNUTLS|GnuTLS)/) && ($pid = processexists($pidfile))) {
|
||||
if($pid < 0) {
|
||||
logmsg "RUN: $server server has died after starting up\n";
|
||||
}
|
||||
return $pid;
|
||||
}
|
||||
elsif($res == 6) {
|
||||
# curl: (6) Could not resolve hostname '::1'
|
||||
logmsg "RUN: failed to resolve host (https://$ip:$port/verifiedserver)\n";
|
||||
return -1;
|
||||
}
|
||||
elsif($data || ($res && ($res != 7))) {
|
||||
logmsg "RUN: Unknown server on our $server port: $port ($res)\n";
|
||||
return -1;
|
||||
}
|
||||
return $pid;
|
||||
}
|
||||
|
||||
#######################################################################
|
||||
# For verifying mqtt and socks
|
||||
#
|
||||
|
|
@ -1012,10 +924,9 @@ sub verifytelnet {
|
|||
# particular can take a long time to start if it needs to generate
|
||||
# keys on a slow or loaded host.
|
||||
#
|
||||
# For convenience, test harness uses 'https' and 'httptls' literals
|
||||
# For convenience, test harness uses 'https' literal
|
||||
# as values for 'proto' variable in order to differentiate different
|
||||
# servers. 'https' literal is used for stunnel based https test servers,
|
||||
# and 'httptls' is used for non-stunnel https test servers.
|
||||
# servers. 'https' literal is used for stunnel based https test servers.
|
||||
#
|
||||
|
||||
my %protofunc = ('http' => \&verifyhttp,
|
||||
|
|
@ -1038,7 +949,6 @@ my %protofunc = ('http' => \&verifyhttp,
|
|||
'socks' => \&verifypid,
|
||||
'socks5unix' => \&verifypid,
|
||||
'gopher' => \&verifyhttp,
|
||||
'httptls' => \&verifyhttptls,
|
||||
'dict' => \&verifyftp,
|
||||
'smb' => \&verifysmb,
|
||||
'telnet' => \&verifytelnet);
|
||||
|
|
@ -1367,66 +1277,6 @@ sub runhttpsserver {
|
|||
return (0+!$httpspid, $httpspid, $pid2, $port);
|
||||
}
|
||||
|
||||
#######################################################################
|
||||
# start the non-stunnel HTTP TLS extensions capable server
|
||||
#
|
||||
sub runhttptlsserver {
|
||||
my ($verb, $ipv6) = @_;
|
||||
my $proto = "httptls";
|
||||
my $ip = ($ipv6 && ($ipv6 =~ /6$/)) ? $HOST6IP : $HOSTIP;
|
||||
my $ipvnum = ($ipv6 && ($ipv6 =~ /6$/)) ? 6 : 4;
|
||||
my $idnum = 1;
|
||||
|
||||
if(!$httptlssrv) {
|
||||
return (4, 0, 0);
|
||||
}
|
||||
|
||||
my $server = servername_id($proto, $ipvnum, $idnum);
|
||||
|
||||
my $pidfile = $serverpidfile{$server};
|
||||
|
||||
# do not retry if the server does not work
|
||||
if($doesntrun{$pidfile}) {
|
||||
return (2, 0, 0, 0);
|
||||
}
|
||||
|
||||
my $pid = processexists($pidfile);
|
||||
if($pid > 0) {
|
||||
stopserver($server, $pid);
|
||||
}
|
||||
unlink($pidfile) if(-f $pidfile);
|
||||
|
||||
my $srvrname = servername_str($proto, $ipvnum, $idnum);
|
||||
my $logfile = server_logfilename($LOGDIR, $proto, $ipvnum, $idnum);
|
||||
|
||||
my $flags = "";
|
||||
$flags .= "--http ";
|
||||
$flags .= "--debug 1 " if($debugprotocol);
|
||||
$flags .= "--priority NORMAL:+SRP ";
|
||||
$flags .= "--srppasswd $srcdir/certs/srp-verifier-db ";
|
||||
$flags .= "--srppasswdconf $srcdir/certs/srp-verifier-conf";
|
||||
|
||||
my $port = getfreeport($ipvnum);
|
||||
my $allflags = "--port $port $flags";
|
||||
my $cmd = "$httptlssrv $allflags > $logfile 2>&1";
|
||||
my ($httptlspid, $pid2) = startnew($cmd, $pidfile, 10, 1);
|
||||
|
||||
if($httptlspid <= 0 || !pidexists($httptlspid)) {
|
||||
# it is NOT alive
|
||||
stopserver($server, $pid2);
|
||||
$doesntrun{$pidfile} = 1;
|
||||
$httptlspid = $pid2 = 0;
|
||||
logmsg "RUN: failed to start the $srvrname server\n";
|
||||
return (3, 0, 0, 0);
|
||||
}
|
||||
$doesntrun{$pidfile} = 0;
|
||||
|
||||
if($verb) {
|
||||
logmsg "RUN: $srvrname server PID $httptlspid port $port\n";
|
||||
}
|
||||
return (0+!$httptlspid, $httptlspid, $pid2, $port);
|
||||
}
|
||||
|
||||
#######################################################################
|
||||
# start the pingpong server (FTP, POP3, IMAP, SMTP)
|
||||
#
|
||||
|
|
@ -2372,27 +2222,6 @@ sub responsive_dns_server {
|
|||
return &responsiveserver($proto, $ipvnum, $idnum, $ip, $port);
|
||||
}
|
||||
|
||||
#######################################################################
|
||||
# Single shot non-stunnel HTTP TLS extensions capable server
|
||||
# responsiveness test. This should only be used to verify that a
|
||||
# server present in %run hash is still functional
|
||||
#
|
||||
sub responsive_httptls_server {
|
||||
my ($verb, $ipv6) = @_;
|
||||
my $ipvnum = ($ipv6 && ($ipv6 =~ /6$/)) ? 6 : 4;
|
||||
my $proto = "httptls";
|
||||
my $port = protoport($proto);
|
||||
my $ip = $HOSTIP;
|
||||
my $idnum = 1;
|
||||
|
||||
if($ipvnum == 6) {
|
||||
$port = protoport("httptls6");
|
||||
$ip = $HOST6IP;
|
||||
}
|
||||
|
||||
return &responsiveserver($proto, $ipvnum, $idnum, $ip, $port);
|
||||
}
|
||||
|
||||
#######################################################################
|
||||
# startservers() starts all the named servers
|
||||
#
|
||||
|
|
@ -2831,50 +2660,6 @@ sub startservers {
|
|||
$run{'https-proxy'} = "$pid $pid2";
|
||||
}
|
||||
}
|
||||
elsif($what eq "httptls") {
|
||||
if(!$httptlssrv) {
|
||||
# for now, we cannot run http TLS-EXT tests without gnutls-serv
|
||||
return ("no gnutls-serv (with SRP support)", 4);
|
||||
}
|
||||
if($run{'httptls'} &&
|
||||
!responsive_httptls_server($verbose, "IPv4")) {
|
||||
if(stopserver('httptls')) {
|
||||
return ("failed stopping unresponsive HTTPTLS server", 3);
|
||||
}
|
||||
}
|
||||
if(!$run{'httptls'}) {
|
||||
($serr, $pid, $pid2, $PORT{'httptls'}) =
|
||||
runhttptlsserver($verbose, "IPv4");
|
||||
if($pid <= 0) {
|
||||
return ("failed starting HTTPTLS server (gnutls-serv)", $serr);
|
||||
}
|
||||
logmsg sprintf("* pid httptls => %d %d\n", $pid, $pid2)
|
||||
if($verbose);
|
||||
$run{'httptls'} = "$pid $pid2";
|
||||
}
|
||||
}
|
||||
elsif($what eq "httptls-ipv6") {
|
||||
if(!$httptlssrv) {
|
||||
# for now, we cannot run http TLS-EXT tests without gnutls-serv
|
||||
return ("no gnutls-serv", 4);
|
||||
}
|
||||
if($run{'httptls-ipv6'} &&
|
||||
!responsive_httptls_server($verbose, "ipv6")) {
|
||||
if(stopserver('httptls-ipv6')) {
|
||||
return ("failed stopping unresponsive HTTPTLS-IPv6 server", 3);
|
||||
}
|
||||
}
|
||||
if(!$run{'httptls-ipv6'}) {
|
||||
($serr, $pid, $pid2, $PORT{"httptls6"}) =
|
||||
runhttptlsserver($verbose, "ipv6");
|
||||
if($pid <= 0) {
|
||||
return ("failed starting HTTPTLS-IPv6 server (gnutls-serv)", $serr);
|
||||
}
|
||||
logmsg sprintf("* pid httptls-ipv6 => %d %d\n", $pid, $pid2)
|
||||
if($verbose);
|
||||
$run{'httptls-ipv6'} = "$pid $pid2";
|
||||
}
|
||||
}
|
||||
elsif($what eq "dns") {
|
||||
if($run{'dns'} &&
|
||||
!responsive_dns_server("", $verbose)) {
|
||||
|
|
@ -3137,7 +2922,7 @@ sub subvariables {
|
|||
'FTP', 'FTP6', 'FTPS',
|
||||
'GOPHER', 'GOPHER6', 'GOPHERS',
|
||||
'HTTP', 'HTTP6', 'HTTPS', 'HTTPS-MTLS',
|
||||
'HTTPSPROXY', 'HTTPTLS', 'HTTPTLS6',
|
||||
'HTTPSPROXY',
|
||||
'HTTP2', 'HTTP2TLS',
|
||||
'HTTP3',
|
||||
'IMAP', 'IMAP6', 'IMAPS',
|
||||
|
|
|
|||
|
|
@ -72,7 +72,7 @@ sub scanconf_cmake {
|
|||
while(<S>) {
|
||||
if(/(CURL_DISABLE_[A-Z0-9_]+)/g) {
|
||||
my ($sym) = ($1);
|
||||
if(not $sym =~ /^(CURL_DISABLE_INSTALL|CURL_DISABLE_SRP|CURL_DISABLE_TYPECHECK)$/) {
|
||||
if(not $sym =~ /^(CURL_DISABLE_INSTALL|CURL_DISABLE_TYPECHECK)$/) {
|
||||
$hashr->{$sym} = 1;
|
||||
}
|
||||
}
|
||||
|
|
|
|||
|
|
@ -66,6 +66,7 @@ while(<$s>) {
|
|||
}
|
||||
close($s);
|
||||
$sourcename{'NTLM_WB'}++; # deprecated, fake its presence in code
|
||||
$sourcename{'TLS-SRP'}++; # deprecated, fake its presence in code
|
||||
|
||||
for my $h (keys %headerversion) {
|
||||
if(!$manversion{$h}) {
|
||||
|
|
|
|||
|
|
@ -26,8 +26,8 @@
|
|||
* Verifies that Curl_ssl_peer_key_build() produces distinct keys when two
|
||||
* handles differ only on key, key_type or cert_type. key_passwd is NOT
|
||||
* embedded in the peer key; it is compared separately at session lookup via
|
||||
* cf_ssl_scache_match_auth(), following the same pattern as SRP
|
||||
* credentials. */
|
||||
* cf_ssl_scache_match_auth().
|
||||
*/
|
||||
|
||||
#include "unitcheck.h"
|
||||
#include "urldata.h"
|
||||
|
|
@ -88,7 +88,7 @@ static CURLcode test_unit3304(const char *arg)
|
|||
curlx_safefree(key2);
|
||||
|
||||
/* key_passwd is NOT in the peer key: lookup uses timing-safe comparison
|
||||
* via cf_ssl_scache_match_auth(), same as SRP credentials. */
|
||||
* via cf_ssl_scache_match_auth(). */
|
||||
fail_unless(!Curl_ssl_peer_key_make(&peer, &ssl, "test", &key1),
|
||||
"peer key build failed");
|
||||
ssl.key_passwd = NULL;
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue