mirror of
https://github.com/curl/curl.git
synced 2026-08-25 21:03:34 +03:00
GHA/macos: enable HTTPS tests with stunnel
- Install stunnel. - Regenerate certificates (as SecureTransport requires a validity period less than 398 days). - Restart server if it is unresponsive. - Do not hardcode the SHA-256 base64 public pinned key. - Ignore test 313 as SecureTransport does not support crl file. - Ignore tests 1631 and 1632 as SecureTransport is not yet able to shut down FTP over HTTPS gracefully. - Add a CMake target for generating certificates. Closes #14486
This commit is contained in:
parent
7c0b6eb3bd
commit
fa461b4eff
13 changed files with 262 additions and 133 deletions
48
tests/certs/CMakeLists.txt
Normal file
48
tests/certs/CMakeLists.txt
Normal file
|
|
@ -0,0 +1,48 @@
|
|||
#***************************************************************************
|
||||
# _ _ ____ _
|
||||
# Project ___| | | | _ \| |
|
||||
# / __| | | | |_) | |
|
||||
# | (__| |_| | _ <| |___
|
||||
# \___|\___/|_| \_\_____|
|
||||
#
|
||||
# Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
|
||||
#
|
||||
# This software is licensed as described in the file COPYING, which
|
||||
# you should have received as part of this distribution. The terms
|
||||
# are also available at https://curl.se/docs/copyright.html.
|
||||
#
|
||||
# You may opt to use, copy, modify, merge, publish, distribute and/or sell
|
||||
# copies of the Software, and permit persons to whom the Software is
|
||||
# furnished to do so, under the terms of the COPYING file.
|
||||
#
|
||||
# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
|
||||
# KIND, either express or implied.
|
||||
#
|
||||
# SPDX-License-Identifier: curl
|
||||
#
|
||||
###########################################################################
|
||||
find_program(SH_EXECUTABLE "sh")
|
||||
mark_as_advanced(SH_EXECUTABLE)
|
||||
if(SH_EXECUTABLE)
|
||||
# Get 'CERTCONFIGS', 'GENERATEDCERTS', 'SRPFILES' variables
|
||||
transform_makefile_inc("Makefile.inc" "${CMAKE_CURRENT_BINARY_DIR}/Makefile.inc.cmake")
|
||||
include("${CMAKE_CURRENT_BINARY_DIR}/Makefile.inc.cmake")
|
||||
|
||||
add_custom_target(clean-certs
|
||||
COMMAND ${CMAKE_COMMAND} -E remove ${GENERATEDCERTS}
|
||||
WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR}
|
||||
)
|
||||
|
||||
add_custom_target(build-certs
|
||||
DEPENDS ${CERTCONFIGS} ${SRPFILES}
|
||||
COMMAND "${CMAKE_CURRENT_SOURCE_DIR}/scripts/genroot.sh" EdelCurlRoot
|
||||
COMMAND "${CMAKE_CURRENT_SOURCE_DIR}/scripts/genserv.sh" Server-localhost EdelCurlRoot
|
||||
COMMAND "${CMAKE_CURRENT_SOURCE_DIR}/scripts/genserv.sh" Server-localhost.nn EdelCurlRoot
|
||||
COMMAND "${CMAKE_CURRENT_SOURCE_DIR}/scripts/genserv.sh" Server-localhost0h EdelCurlRoot
|
||||
COMMAND "${CMAKE_CURRENT_SOURCE_DIR}/scripts/genserv.sh" Server-localhost-firstSAN EdelCurlRoot
|
||||
COMMAND "${CMAKE_CURRENT_SOURCE_DIR}/scripts/genserv.sh" Server-localhost-lastSAN EdelCurlRoot
|
||||
COMMAND "${CMAKE_CURRENT_SOURCE_DIR}/scripts/genserv.sh" stunnel EdelCurlRoot
|
||||
COMMAND ${CMAKE_COMMAND} -E copy "${CMAKE_CURRENT_SOURCE_DIR}/stunnel-sv.pem" "${CMAKE_CURRENT_SOURCE_DIR}/../stunnel.pem"
|
||||
WORKING_DIRECTORY ${CMAKE_CURRENT_SOURCE_DIR}
|
||||
)
|
||||
endif()
|
||||
|
|
@ -25,89 +25,9 @@ AUTOMAKE_OPTIONS = foreign
|
|||
|
||||
SUBDIRS = scripts
|
||||
|
||||
CERTCONFIGS = \
|
||||
EdelCurlRoot-ca.prm \
|
||||
EdelCurlRoot-ca.cnf \
|
||||
Server-localhost-sv.prm \
|
||||
Server-localhost.nn-sv.prm \
|
||||
Server-localhost0h-sv.prm \
|
||||
Server-localhost-firstSAN-sv.prm \
|
||||
Server-localhost-lastSAN-sv.prm \
|
||||
stunnel-sv.prm
|
||||
include Makefile.inc
|
||||
|
||||
GENERATEDCERTS = \
|
||||
EdelCurlRoot-ca.cacert \
|
||||
EdelCurlRoot-ca.crt \
|
||||
EdelCurlRoot-ca.csr \
|
||||
EdelCurlRoot-ca.der \
|
||||
EdelCurlRoot-ca.key \
|
||||
Server-localhost-sv.crl \
|
||||
Server-localhost-sv.crt \
|
||||
Server-localhost-sv.csr \
|
||||
Server-localhost-sv.der \
|
||||
Server-localhost-sv.dhp \
|
||||
Server-localhost-sv.key \
|
||||
Server-localhost-sv.pem \
|
||||
Server-localhost-sv.pub.der \
|
||||
Server-localhost-sv.pub.pem \
|
||||
Server-localhost-sv.pubkey-pinned \
|
||||
Server-localhost.nn-sv.crl \
|
||||
Server-localhost.nn-sv.crt \
|
||||
Server-localhost.nn-sv.csr \
|
||||
Server-localhost.nn-sv.der \
|
||||
Server-localhost.nn-sv.dhp \
|
||||
Server-localhost.nn-sv.key \
|
||||
Server-localhost.nn-sv.pem \
|
||||
Server-localhost.nn-sv.pub.der \
|
||||
Server-localhost.nn-sv.pub.pem \
|
||||
Server-localhost.nn-sv.pubkey-pinned \
|
||||
Server-localhost0h-sv.crl \
|
||||
Server-localhost0h-sv.crt \
|
||||
Server-localhost0h-sv.csr \
|
||||
Server-localhost0h-sv.der \
|
||||
Server-localhost0h-sv.dhp \
|
||||
Server-localhost0h-sv.key \
|
||||
Server-localhost0h-sv.pem \
|
||||
Server-localhost0h-sv.pub.der \
|
||||
Server-localhost0h-sv.pub.pem \
|
||||
Server-localhost0h-sv.pubkey-pinned \
|
||||
Server-localhost-firstSAN-sv.crl \
|
||||
Server-localhost-firstSAN-sv.crt \
|
||||
Server-localhost-firstSAN-sv.csr \
|
||||
Server-localhost-firstSAN-sv.der \
|
||||
Server-localhost-firstSAN-sv.dhp \
|
||||
Server-localhost-firstSAN-sv.key \
|
||||
Server-localhost-firstSAN-sv.pem \
|
||||
Server-localhost-firstSAN-sv.pub.der \
|
||||
Server-localhost-firstSAN-sv.pub.pem \
|
||||
Server-localhost-firstSAN-sv.pubkey-pinned \
|
||||
Server-localhost-lastSAN-sv.crl \
|
||||
Server-localhost-lastSAN-sv.crt \
|
||||
Server-localhost-lastSAN-sv.csr \
|
||||
Server-localhost-lastSAN-sv.der \
|
||||
Server-localhost-lastSAN-sv.dhp \
|
||||
Server-localhost-lastSAN-sv.key \
|
||||
Server-localhost-lastSAN-sv.pem \
|
||||
Server-localhost-lastSAN-sv.pub.der \
|
||||
Server-localhost-lastSAN-sv.pub.pem \
|
||||
Server-localhost-lastSAN-sv.pubkey-pinned \
|
||||
stunnel-sv.crl \
|
||||
stunnel-sv.crt \
|
||||
stunnel-sv.csr \
|
||||
stunnel-sv.der \
|
||||
stunnel-sv.dhp \
|
||||
stunnel-sv.key \
|
||||
stunnel-sv.pem \
|
||||
stunnel-sv.der \
|
||||
stunnel-sv.pub.der \
|
||||
stunnel-sv.pub.pem \
|
||||
stunnel-sv.pubkey-pinned
|
||||
|
||||
SRPFILES = \
|
||||
srp-verifier-conf \
|
||||
srp-verifier-db
|
||||
|
||||
EXTRA_DIST = $(CERTCONFIGS) $(GENERATEDCERTS) $(SRPFILES)
|
||||
EXTRA_DIST = $(CERTCONFIGS) $(GENERATEDCERTS) $(SRPFILES) CMakeLists.txt
|
||||
|
||||
# Rebuild the certificates
|
||||
|
||||
|
|
@ -117,7 +37,7 @@ clean-certs:
|
|||
build-certs: $(srcdir)/EdelCurlRoot-ca.cacert $(srcdir)/Server-localhost-sv.pem \
|
||||
$(srcdir)/Server-localhost.nn-sv.pem $(srcdir)/Server-localhost0h-sv.pem \
|
||||
$(srcdir)/Server-localhost-firstSAN-sv.pem $(srcdir)/Server-localhost-lastSAN-sv.pem \
|
||||
$(srcdir)/stunnel-sv.pem ../stunnel.pem
|
||||
$(srcdir)/stunnel-sv.pem $(srcdir)/../stunnel.pem
|
||||
|
||||
$(srcdir)/EdelCurlRoot-ca.cacert:
|
||||
cd $(srcdir); scripts/genroot.sh EdelCurlRoot
|
||||
|
|
@ -140,5 +60,5 @@ $(srcdir)/Server-localhost-lastSAN-sv.pem: $(srcdir)/EdelCurlRoot-ca.cacert
|
|||
$(srcdir)/stunnel-sv.pem: $(srcdir)/EdelCurlRoot-ca.cacert
|
||||
cd $(srcdir); scripts/genserv.sh stunnel EdelCurlRoot
|
||||
|
||||
../stunnel.pem: $(srcdir)/stunnel-sv.pem
|
||||
$(srcdir)/../stunnel.pem: $(srcdir)/stunnel-sv.pem
|
||||
cp $< $@
|
||||
|
|
|
|||
104
tests/certs/Makefile.inc
Normal file
104
tests/certs/Makefile.inc
Normal file
|
|
@ -0,0 +1,104 @@
|
|||
#***************************************************************************
|
||||
# _ _ ____ _
|
||||
# Project ___| | | | _ \| |
|
||||
# / __| | | | |_) | |
|
||||
# | (__| |_| | _ <| |___
|
||||
# \___|\___/|_| \_\_____|
|
||||
#
|
||||
# Copyright (C) Daniel Stenberg, <daniel@haxx.se>, et al.
|
||||
#
|
||||
# This software is licensed as described in the file COPYING, which
|
||||
# you should have received as part of this distribution. The terms
|
||||
# are also available at https://curl.se/docs/copyright.html.
|
||||
#
|
||||
# You may opt to use, copy, modify, merge, publish, distribute and/or sell
|
||||
# copies of the Software, and permit persons to whom the Software is
|
||||
# furnished to do so, under the terms of the COPYING file.
|
||||
#
|
||||
# This software is distributed on an "AS IS" basis, WITHOUT WARRANTY OF ANY
|
||||
# KIND, either express or implied.
|
||||
#
|
||||
# SPDX-License-Identifier: curl
|
||||
#
|
||||
###########################################################################
|
||||
CERTCONFIGS = \
|
||||
EdelCurlRoot-ca.prm \
|
||||
EdelCurlRoot-ca.cnf \
|
||||
Server-localhost-sv.prm \
|
||||
Server-localhost.nn-sv.prm \
|
||||
Server-localhost0h-sv.prm \
|
||||
Server-localhost-firstSAN-sv.prm \
|
||||
Server-localhost-lastSAN-sv.prm \
|
||||
stunnel-sv.prm
|
||||
|
||||
GENERATEDCERTS = \
|
||||
EdelCurlRoot-ca.cacert \
|
||||
EdelCurlRoot-ca.crt \
|
||||
EdelCurlRoot-ca.csr \
|
||||
EdelCurlRoot-ca.der \
|
||||
EdelCurlRoot-ca.key \
|
||||
Server-localhost-sv.crl \
|
||||
Server-localhost-sv.crt \
|
||||
Server-localhost-sv.csr \
|
||||
Server-localhost-sv.der \
|
||||
Server-localhost-sv.dhp \
|
||||
Server-localhost-sv.key \
|
||||
Server-localhost-sv.pem \
|
||||
Server-localhost-sv.pub.der \
|
||||
Server-localhost-sv.pub.pem \
|
||||
Server-localhost-sv.pubkey-pinned \
|
||||
Server-localhost.nn-sv.crl \
|
||||
Server-localhost.nn-sv.crt \
|
||||
Server-localhost.nn-sv.csr \
|
||||
Server-localhost.nn-sv.der \
|
||||
Server-localhost.nn-sv.dhp \
|
||||
Server-localhost.nn-sv.key \
|
||||
Server-localhost.nn-sv.pem \
|
||||
Server-localhost.nn-sv.pub.der \
|
||||
Server-localhost.nn-sv.pub.pem \
|
||||
Server-localhost.nn-sv.pubkey-pinned \
|
||||
Server-localhost0h-sv.crl \
|
||||
Server-localhost0h-sv.crt \
|
||||
Server-localhost0h-sv.csr \
|
||||
Server-localhost0h-sv.der \
|
||||
Server-localhost0h-sv.dhp \
|
||||
Server-localhost0h-sv.key \
|
||||
Server-localhost0h-sv.pem \
|
||||
Server-localhost0h-sv.pub.der \
|
||||
Server-localhost0h-sv.pub.pem \
|
||||
Server-localhost0h-sv.pubkey-pinned \
|
||||
Server-localhost-firstSAN-sv.crl \
|
||||
Server-localhost-firstSAN-sv.crt \
|
||||
Server-localhost-firstSAN-sv.csr \
|
||||
Server-localhost-firstSAN-sv.der \
|
||||
Server-localhost-firstSAN-sv.dhp \
|
||||
Server-localhost-firstSAN-sv.key \
|
||||
Server-localhost-firstSAN-sv.pem \
|
||||
Server-localhost-firstSAN-sv.pub.der \
|
||||
Server-localhost-firstSAN-sv.pub.pem \
|
||||
Server-localhost-firstSAN-sv.pubkey-pinned \
|
||||
Server-localhost-lastSAN-sv.crl \
|
||||
Server-localhost-lastSAN-sv.crt \
|
||||
Server-localhost-lastSAN-sv.csr \
|
||||
Server-localhost-lastSAN-sv.der \
|
||||
Server-localhost-lastSAN-sv.dhp \
|
||||
Server-localhost-lastSAN-sv.key \
|
||||
Server-localhost-lastSAN-sv.pem \
|
||||
Server-localhost-lastSAN-sv.pub.der \
|
||||
Server-localhost-lastSAN-sv.pub.pem \
|
||||
Server-localhost-lastSAN-sv.pubkey-pinned \
|
||||
stunnel-sv.crl \
|
||||
stunnel-sv.crt \
|
||||
stunnel-sv.csr \
|
||||
stunnel-sv.der \
|
||||
stunnel-sv.dhp \
|
||||
stunnel-sv.key \
|
||||
stunnel-sv.pem \
|
||||
stunnel-sv.der \
|
||||
stunnel-sv.pub.der \
|
||||
stunnel-sv.pub.pem \
|
||||
stunnel-sv.pubkey-pinned
|
||||
|
||||
SRPFILES = \
|
||||
srp-verifier-conf \
|
||||
srp-verifier-db
|
||||
|
|
@ -37,7 +37,7 @@ HOME=$(pwd)
|
|||
cd "$HOME"
|
||||
|
||||
KEYSIZE=2048
|
||||
DURATION=3000
|
||||
DURATION=300
|
||||
# The -sha256 option was introduced in OpenSSL 1.0.1
|
||||
DIGESTALGO=-sha256
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue