@@ -13874,10 +13874,9 @@ run_test "TLS 1.2 ClientHello indicating support for deflate compression meth
1387413874
1387513875# Handshake defragmentation testing
1387613876
13877- # To warrant that the handhake messages are large enough and need to be split
13877+ # To guarantee that the handhake messages are large enough and need to be split
1387813878# into fragments, the tests require certificate authentication. The party in control
13879- # of the fragmentation operations is OpenSSL and will always use server5.crt (548 Bytes)
13880- # either from O_NEXT_SRV or test data.
13879+ # of the fragmentation operations is OpenSSL and will always use server5.crt (548 Bytes).
1388113880requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1388213881requires_certificate_authentication
1388313882run_test "Handshake defragmentation on client (no fragmentation, for reference)" \
@@ -13897,9 +13896,7 @@ run_test "Handshake defragmentation on client: len=512, TLS 1.3" \
1389713896 -c "handshake fragment: 0 \\.\\. 512 of [0-9]\\+ msglen 512" \
1389813897 -c "waiting for more fragments (512 of [0-9]\\+"
1389913898
13900- # Since the removal of the DHE-RSA key exchange, the default openssl server
13901- # certificate does not match what is provided by the testing client. Those
13902- # use-cases are out of scope for defregmentation testing, and should be skipped.
13899+ #The server uses an ECDSA cert, so make sure we have a compatible key exchange
1390313900requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1390413901requires_certificate_authentication
1390513902requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
@@ -14220,12 +14217,12 @@ run_test "Handshake defragmentation on server: len=128, TLS 1.3" \
1422014217 -s "handshake fragment: 0 \\.\\. 128 of [0-9]\\+ msglen 128" \
1422114218 -s "waiting for more fragments (128"
1422214219
14223- # Server-side ClientHello degfragmentation is only supported for MBEDTLS_SSL_PROTO_TLS1_3. For TLS 1.2 testing
14220+ # Server-side ClientHello defragmentationis only supported for MBEDTLS_SSL_PROTO_TLS1_3. For TLS 1.2 testing
1422414221# the server should suport both protocols and downgrade to client-requested TL1.2 after proccessing the ClientHello.
1422514222requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1422614223requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1422714224requires_certificate_authentication
14228- run_test "Handshake defragmentation on server: len=128, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake " \
14225+ run_test "Handshake defragmentation on server: len=128, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake " \
1422914226 "$P_SRV debug_level=4 auth_mode=required" \
1423014227 "$O_NEXT_CLI -tls1_2 -split_send_frag 128 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1423114228 0 \
@@ -14246,7 +14243,7 @@ run_test "Handshake defragmentation on server: len=64, TLS 1.3" \
1424614243requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1424714244requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1424814245requires_certificate_authentication
14249- run_test "Handshake defragmentation on server: len=64, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake " \
14246+ run_test "Handshake defragmentation on server: len=64, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake " \
1425014247 "$P_SRV debug_level=4 auth_mode=required" \
1425114248 "$O_NEXT_CLI -tls1_2 -split_send_frag 64 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1425214249 0 \
@@ -14267,7 +14264,7 @@ run_test "Handshake defragmentation on server: len=36, TLS 1.3" \
1426714264requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1426814265requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1426914266requires_certificate_authentication
14270- run_test "Handshake defragmentation on server: len=36, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake " \
14267+ run_test "Handshake defragmentation on server: len=36, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake " \
1427114268 "$P_SRV debug_level=4 auth_mode=required" \
1427214269 "$O_NEXT_CLI -tls1_2 -split_send_frag 36 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1427314270 0 \
@@ -14288,7 +14285,7 @@ run_test "Handshake defragmentation on server: len=32, TLS 1.3" \
1428814285requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1428914286requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1429014287requires_certificate_authentication
14291- run_test "Handshake defragmentation on server: len=32, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake " \
14288+ run_test "Handshake defragmentation on server: len=32, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake " \
1429214289 "$P_SRV debug_level=4 auth_mode=required" \
1429314290 "$O_NEXT_CLI -tls1_2 -split_send_frag 32 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1429414291 0 \
@@ -14309,7 +14306,7 @@ run_test "Handshake defragmentation on server: len=16, TLS 1.3" \
1430914306requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1431014307requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1431114308requires_certificate_authentication
14312- run_test "Handshake defragmentation on server: len=16, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake " \
14309+ run_test "Handshake defragmentation on server: len=16, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake " \
1431314310 "$P_SRV debug_level=4 auth_mode=required" \
1431414311 "$O_NEXT_CLI -tls1_2 -split_send_frag 16 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1431514312 0 \
@@ -14330,7 +14327,7 @@ run_test "Handshake defragmentation on server: len=13, TLS 1.3" \
1433014327requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1433114328requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1433214329requires_certificate_authentication
14333- run_test "Handshake defragmentation on server: len=13, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake " \
14330+ run_test "Handshake defragmentation on server: len=13, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake " \
1433414331 "$P_SRV debug_level=4 auth_mode=required" \
1433514332 "$O_NEXT_CLI -tls1_2 -split_send_frag 13 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1433614333 0 \
@@ -14351,7 +14348,7 @@ run_test "Handshake defragmentation on server: len=5, TLS 1.3" \
1435114348requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1435214349requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1435314350requires_certificate_authentication
14354- run_test "Handshake defragmentation on server: len=5, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake " \
14351+ run_test "Handshake defragmentation on server: len=5, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake " \
1435514352 "$P_SRV debug_level=4 auth_mode=required" \
1435614353 "$O_NEXT_CLI -tls1_2 -split_send_frag 5 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1435714354 0 \
@@ -14372,7 +14369,7 @@ run_test "Handshake defragmentation on server: len=4, TLS 1.3" \
1437214369requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1437314370requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1437414371requires_certificate_authentication
14375- run_test "Handshake defragmentation on server: len=4, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake " \
14372+ run_test "Handshake defragmentation on server: len=4, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake " \
1437614373 "$P_SRV debug_level=4 auth_mode=required" \
1437714374 "$O_NEXT_CLI -tls1_2 -split_send_frag 4 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1437814375 0 \
@@ -14393,7 +14390,7 @@ run_test "Handshake defragmentation on server: len=3, TLS 1.3" \
1439314390requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1439414391requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1439514392requires_certificate_authentication
14396- run_test "Handshake defragmentation on server: len=3, TLS 1.3 Client-Hallo -> 1.2 Handhsake " \
14393+ run_test "Handshake defragmentation on server: len=3, TLS 1.3 ClientHello -> 1.2 Handshake " \
1439714394 "$P_SRV debug_level=4 auth_mode=required" \
1439814395 "$O_NEXT_CLI -tls1_2 -split_send_frag 3 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1439914396 1 \
@@ -14404,7 +14401,7 @@ run_test "Handshake defragmentation on server: len=3, TLS 1.3 Client-Hallo ->
1440414401requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1440514402requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1440614403requires_certificate_authentication
14407- run_test "Handshake defragmentation on server: len=32, TLS 1.3 Client-Hallo -> 1.2 Handhsake " \
14404+ run_test "Handshake defragmentation on server: len=32, TLS 1.2 ClientHello " \
1440814405 "$P_SRV debug_level=4 force_version=tls12 auth_mode=required" \
1440914406 "$O_NEXT_CLI -tls1_2 -split_send_frag 32 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1441014407 1 \
0 commit comments