mirror of
				https://github.com/Mbed-TLS/mbedtls.git
				synced 2025-11-03 20:33:16 +03:00 
			
		
		
		
	ssl-opt.sh: add tests for clent/server psa opaque dhe-psk key exchange
Signed-off-by: Przemek Stekiel <przemyslaw.stekiel@mobica.com>
This commit is contained in:
		
							
								
								
									
										183
									
								
								tests/ssl-opt.sh
									
									
									
									
									
								
							
							
						
						
									
										183
									
								
								tests/ssl-opt.sh
									
									
									
									
									
								
							@@ -6572,6 +6572,65 @@ run_test    "PSK callback: opaque ecdhe-psk on client, no callback, SHA-384, EMS
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: opaque dhe-psk on client, no callback" \
 | 
			
		||||
            "$P_SRV extended_ms=0 debug_level=1 psk=abc123 psk_identity=foo" \
 | 
			
		||||
            "$P_CLI extended_ms=0 debug_level=1 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-128-CBC-SHA256 \
 | 
			
		||||
            psk_identity=foo psk=abc123 psk_opaque=1" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -c "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -S "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -C "session hash for extended master secret"\
 | 
			
		||||
            -S "session hash for extended master secret"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: opaque dhe-psk on client, no callback, SHA-384" \
 | 
			
		||||
            "$P_SRV extended_ms=0 debug_level=1 psk=abc123 psk_identity=foo" \
 | 
			
		||||
            "$P_CLI extended_ms=0 debug_level=1 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-256-CBC-SHA384 \
 | 
			
		||||
            psk_identity=foo psk=abc123 psk_opaque=1" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -c "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -S "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -C "session hash for extended master secret"\
 | 
			
		||||
            -S "session hash for extended master secret"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: opaque dhe-psk on client, no callback, EMS" \
 | 
			
		||||
            "$P_SRV extended_ms=1 debug_level=3 psk=abc123 psk_identity=foo" \
 | 
			
		||||
            "$P_CLI extended_ms=1 debug_level=3 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-128-CBC-SHA \
 | 
			
		||||
            psk_identity=foo psk=abc123 psk_opaque=1" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -c "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -S "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -c "session hash for extended master secret"\
 | 
			
		||||
            -s "session hash for extended master secret"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: opaque dhe-psk on client, no callback, SHA-384, EMS" \
 | 
			
		||||
            "$P_SRV extended_ms=1 debug_level=3 psk=abc123 psk_identity=foo" \
 | 
			
		||||
            "$P_CLI extended_ms=1 debug_level=3 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-256-CBC-SHA384 \
 | 
			
		||||
            psk_identity=foo psk=abc123 psk_opaque=1" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -c "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -S "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -c "session hash for extended master secret"\
 | 
			
		||||
            -s "session hash for extended master secret"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
@@ -6759,6 +6818,68 @@ run_test    "PSK callback: raw ecdhe-psk on client, static opaque on server, no
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: raw dhe-psk on client, static opaque on server, no callback" \
 | 
			
		||||
            "$P_SRV extended_ms=0 debug_level=5 psk=abc123 psk_identity=foo psk_opaque=1 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-128-CBC-SHA" \
 | 
			
		||||
            "$P_CLI extended_ms=0 debug_level=5 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-128-CBC-SHA \
 | 
			
		||||
            psk_identity=foo psk=abc123" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -C "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -s "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -C "session hash for extended master secret"\
 | 
			
		||||
            -S "session hash for extended master secret"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: raw dhe-psk on client, static opaque on server, no callback, SHA-384" \
 | 
			
		||||
            "$P_SRV extended_ms=0 debug_level=1 psk=abc123 psk_identity=foo psk_opaque=1 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-256-CBC-SHA384" \
 | 
			
		||||
            "$P_CLI extended_ms=0 debug_level=1 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-256-CBC-SHA384 \
 | 
			
		||||
            psk_identity=foo psk=abc123" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -C "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -s "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -C "session hash for extended master secret"\
 | 
			
		||||
            -S "session hash for extended master secret"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: raw dhe-psk on client, static opaque on server, no callback, EMS" \
 | 
			
		||||
            "$P_SRV debug_level=3 psk=abc123 psk_identity=foo psk_opaque=1 min_version=tls12 \
 | 
			
		||||
            force_ciphersuite=TLS-DHE-PSK-WITH-AES-128-CBC-SHA extended_ms=1" \
 | 
			
		||||
            "$P_CLI debug_level=3 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-128-CBC-SHA \
 | 
			
		||||
            psk_identity=foo psk=abc123 extended_ms=1" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -c "session hash for extended master secret"\
 | 
			
		||||
            -s "session hash for extended master secret"\
 | 
			
		||||
            -C "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -s "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: raw dhe-psk on client, static opaque on server, no callback, EMS, SHA384" \
 | 
			
		||||
            "$P_SRV debug_level=3 psk=abc123 psk_identity=foo psk_opaque=1 min_version=tls12 \
 | 
			
		||||
            force_ciphersuite=TLS-DHE-PSK-WITH-AES-256-CBC-SHA384 extended_ms=1" \
 | 
			
		||||
            "$P_CLI debug_level=3 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-256-CBC-SHA384 \
 | 
			
		||||
            psk_identity=foo psk=abc123 extended_ms=1" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -c "session hash for extended master secret"\
 | 
			
		||||
            -s "session hash for extended master secret"\
 | 
			
		||||
            -C "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -s "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: raw psk on client, no static PSK on server, opaque PSK from callback" \
 | 
			
		||||
@@ -6945,6 +7066,68 @@ run_test    "PSK callback: raw ecdhe-psk on client, no static ECDHE-PSK on serve
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: raw dhe-psk on client, no static DHE-PSK on server, opaque DHE-PSK from callback" \
 | 
			
		||||
            "$P_SRV extended_ms=0 debug_level=3 psk_list=abc,dead,def,beef psk_list_opaque=1 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-128-CBC-SHA" \
 | 
			
		||||
            "$P_CLI extended_ms=0 debug_level=3 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-128-CBC-SHA \
 | 
			
		||||
            psk_identity=def psk=beef" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -C "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -s "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -C "session hash for extended master secret"\
 | 
			
		||||
            -S "session hash for extended master secret"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: raw dhe-psk on client, no static DHE-PSK on server, opaque DHE-PSK from callback, SHA-384" \
 | 
			
		||||
            "$P_SRV extended_ms=0 debug_level=3 psk_list=abc,dead,def,beef psk_list_opaque=1 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-256-CBC-SHA384" \
 | 
			
		||||
            "$P_CLI extended_ms=0 debug_level=3 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-256-CBC-SHA384 \
 | 
			
		||||
            psk_identity=def psk=beef" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -C "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -s "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -C "session hash for extended master secret"\
 | 
			
		||||
            -S "session hash for extended master secret"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: raw dhe-psk on client, no static DHE-PSK on server, opaque DHE-PSK from callback, EMS" \
 | 
			
		||||
            "$P_SRV debug_level=3 psk_list=abc,dead,def,beef psk_list_opaque=1 min_version=tls12 \
 | 
			
		||||
            force_ciphersuite=TLS-DHE-PSK-WITH-AES-128-CBC-SHA extended_ms=1" \
 | 
			
		||||
            "$P_CLI debug_level=3 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-128-CBC-SHA \
 | 
			
		||||
            psk_identity=abc psk=dead extended_ms=1" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -c "session hash for extended master secret"\
 | 
			
		||||
            -s "session hash for extended master secret"\
 | 
			
		||||
            -C "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -s "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: raw dhe-psk on client, no static DHE-PSK on server, opaque DHE-PSK from callback, EMS, SHA384" \
 | 
			
		||||
            "$P_SRV debug_level=3 psk_list=abc,dead,def,beef psk_list_opaque=1 min_version=tls12 \
 | 
			
		||||
            force_ciphersuite=TLS-DHE-PSK-WITH-AES-256-CBC-SHA384 extended_ms=1" \
 | 
			
		||||
            "$P_CLI debug_level=3 min_version=tls12 force_ciphersuite=TLS-DHE-PSK-WITH-AES-256-CBC-SHA384 \
 | 
			
		||||
            psk_identity=abc psk=dead extended_ms=1" \
 | 
			
		||||
            0 \
 | 
			
		||||
            -c "session hash for extended master secret"\
 | 
			
		||||
            -s "session hash for extended master secret"\
 | 
			
		||||
            -C "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -s "skip PMS generation for opaque DHE-PSK"\
 | 
			
		||||
            -S "SSL - The handshake negotiation failed" \
 | 
			
		||||
            -S "SSL - Unknown identity received" \
 | 
			
		||||
            -S "SSL - Verification of the message MAC failed"
 | 
			
		||||
 | 
			
		||||
requires_config_enabled MBEDTLS_USE_PSA_CRYPTO
 | 
			
		||||
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
 | 
			
		||||
run_test    "PSK callback: raw psk on client, mismatching static raw PSK on server, opaque PSK from callback" \
 | 
			
		||||
 
 | 
			
		||||
		Reference in New Issue
	
	Block a user