tests: add SNI and peer name checks

- connect to DNS names with trailing dot
- connect to DNS names with double trailing dot
- rustls, always give `peer->hostname` and let it
  figure out SNI itself
- add SNI tests for ip address and localhost
- document in code and TODO that QUIC with ngtcp2+wolfssl
  does not do proper peer verification of the certificate
- mbedtls, skip tests with ip address verification as not
  supported by the library

Closes #13486
This commit is contained in:
Stefan Eissing 2024-04-26 14:13:23 +02:00 committed by Daniel Stenberg
parent c04664ad35
commit b06619d0a3
No known key found for this signature in database
GPG key ID: 5CC908FDB71E12C2
6 changed files with 88 additions and 9 deletions

View file

@ -126,6 +126,7 @@
13.13 Make sure we forbid TLS 1.3 post-handshake authentication
13.14 Support the clienthello extension
13.15 Select signature algorithms
13.16 QUIC peer verification with wolfSSL
14. GnuTLS
14.2 check connection
@ -921,6 +922,11 @@
https://github.com/curl/curl/issues/12982
13.16 QUIC peer verification with wolfSSL
Peer certificate verification is missing in the QUIC (ngtcp2) implementation
using wolfSSL.
14. GnuTLS
14.2 check connection