Skip to content

Commit 76957cc

Browse files
ssl-opt: Minor typos and documentation fixes.
Signed-off-by: Minos Galanakis <[email protected]>
1 parent 19dbbe0 commit 76957cc

File tree

1 file changed

+14
-17
lines changed

1 file changed

+14
-17
lines changed

tests/ssl-opt.sh

Lines changed: 14 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -13874,10 +13874,9 @@ run_test "TLS 1.2 ClientHello indicating support for deflate compression meth
1387413874

1387513875
# Handshake defragmentation testing
1387613876

13877-
# To warrant that the handhake messages are large enough and need to be split
13877+
# To guarantee that the handhake messages are large enough and need to be split
1387813878
# into fragments, the tests require certificate authentication. The party in control
13879-
# of the fragmentation operations is OpenSSL and will always use server5.crt (548 Bytes)
13880-
# either from O_NEXT_SRV or test data.
13879+
# of the fragmentation operations is OpenSSL and will always use server5.crt (548 Bytes).
1388113880
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1388213881
requires_certificate_authentication
1388313882
run_test "Handshake defragmentation on client (no fragmentation, for reference)" \
@@ -13897,9 +13896,7 @@ run_test "Handshake defragmentation on client: len=512, TLS 1.3" \
1389713896
-c "handshake fragment: 0 \\.\\. 512 of [0-9]\\+ msglen 512" \
1389813897
-c "waiting for more fragments (512 of [0-9]\\+"
1389913898

13900-
# Since the removal of the DHE-RSA key exchange, the default openssl server
13901-
# certificate does not match what is provided by the testing client. Those
13902-
# use-cases are out of scope for defregmentation testing, and should be skipped.
13899+
#The server uses an ECDSA cert, so make sure we have a compatible key exchange
1390313900
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1390413901
requires_certificate_authentication
1390513902
requires_config_enabled MBEDTLS_KEY_EXCHANGE_ECDHE_ECDSA_ENABLED
@@ -14220,12 +14217,12 @@ run_test "Handshake defragmentation on server: len=128, TLS 1.3" \
1422014217
-s "handshake fragment: 0 \\.\\. 128 of [0-9]\\+ msglen 128" \
1422114218
-s "waiting for more fragments (128"
1422214219

14223-
# Server-side ClientHello degfragmentation is only supported for MBEDTLS_SSL_PROTO_TLS1_3. For TLS 1.2 testing
14220+
# Server-side ClientHello defragmentationis only supported for MBEDTLS_SSL_PROTO_TLS1_3. For TLS 1.2 testing
1422414221
# the server should suport both protocols and downgrade to client-requested TL1.2 after proccessing the ClientHello.
1422514222
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1422614223
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1422714224
requires_certificate_authentication
14228-
run_test "Handshake defragmentation on server: len=128, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake" \
14225+
run_test "Handshake defragmentation on server: len=128, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake" \
1422914226
"$P_SRV debug_level=4 auth_mode=required" \
1423014227
"$O_NEXT_CLI -tls1_2 -split_send_frag 128 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1423114228
0 \
@@ -14246,7 +14243,7 @@ run_test "Handshake defragmentation on server: len=64, TLS 1.3" \
1424614243
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1424714244
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1424814245
requires_certificate_authentication
14249-
run_test "Handshake defragmentation on server: len=64, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake" \
14246+
run_test "Handshake defragmentation on server: len=64, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake" \
1425014247
"$P_SRV debug_level=4 auth_mode=required" \
1425114248
"$O_NEXT_CLI -tls1_2 -split_send_frag 64 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1425214249
0 \
@@ -14267,7 +14264,7 @@ run_test "Handshake defragmentation on server: len=36, TLS 1.3" \
1426714264
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1426814265
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1426914266
requires_certificate_authentication
14270-
run_test "Handshake defragmentation on server: len=36, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake" \
14267+
run_test "Handshake defragmentation on server: len=36, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake" \
1427114268
"$P_SRV debug_level=4 auth_mode=required" \
1427214269
"$O_NEXT_CLI -tls1_2 -split_send_frag 36 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1427314270
0 \
@@ -14288,7 +14285,7 @@ run_test "Handshake defragmentation on server: len=32, TLS 1.3" \
1428814285
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1428914286
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1429014287
requires_certificate_authentication
14291-
run_test "Handshake defragmentation on server: len=32, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake" \
14288+
run_test "Handshake defragmentation on server: len=32, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake" \
1429214289
"$P_SRV debug_level=4 auth_mode=required" \
1429314290
"$O_NEXT_CLI -tls1_2 -split_send_frag 32 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1429414291
0 \
@@ -14309,7 +14306,7 @@ run_test "Handshake defragmentation on server: len=16, TLS 1.3" \
1430914306
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1431014307
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1431114308
requires_certificate_authentication
14312-
run_test "Handshake defragmentation on server: len=16, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake" \
14309+
run_test "Handshake defragmentation on server: len=16, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake" \
1431314310
"$P_SRV debug_level=4 auth_mode=required" \
1431414311
"$O_NEXT_CLI -tls1_2 -split_send_frag 16 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1431514312
0 \
@@ -14330,7 +14327,7 @@ run_test "Handshake defragmentation on server: len=13, TLS 1.3" \
1433014327
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1433114328
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1433214329
requires_certificate_authentication
14333-
run_test "Handshake defragmentation on server: len=13, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake" \
14330+
run_test "Handshake defragmentation on server: len=13, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake" \
1433414331
"$P_SRV debug_level=4 auth_mode=required" \
1433514332
"$O_NEXT_CLI -tls1_2 -split_send_frag 13 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1433614333
0 \
@@ -14351,7 +14348,7 @@ run_test "Handshake defragmentation on server: len=5, TLS 1.3" \
1435114348
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1435214349
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1435314350
requires_certificate_authentication
14354-
run_test "Handshake defragmentation on server: len=5, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake" \
14351+
run_test "Handshake defragmentation on server: len=5, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake" \
1435514352
"$P_SRV debug_level=4 auth_mode=required" \
1435614353
"$O_NEXT_CLI -tls1_2 -split_send_frag 5 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1435714354
0 \
@@ -14372,7 +14369,7 @@ run_test "Handshake defragmentation on server: len=4, TLS 1.3" \
1437214369
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1437314370
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1437414371
requires_certificate_authentication
14375-
run_test "Handshake defragmentation on server: len=4, TLS 1.2 TLS 1.3 Client-Hallo -> 1.2 Handhsake" \
14372+
run_test "Handshake defragmentation on server: len=4, TLS 1.2 TLS 1.3 ClientHello -> 1.2 Handshake" \
1437614373
"$P_SRV debug_level=4 auth_mode=required" \
1437714374
"$O_NEXT_CLI -tls1_2 -split_send_frag 4 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1437814375
0 \
@@ -14393,7 +14390,7 @@ run_test "Handshake defragmentation on server: len=3, TLS 1.3" \
1439314390
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1439414391
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1439514392
requires_certificate_authentication
14396-
run_test "Handshake defragmentation on server: len=3, TLS 1.3 Client-Hallo -> 1.2 Handhsake" \
14393+
run_test "Handshake defragmentation on server: len=3, TLS 1.3 ClientHello -> 1.2 Handshake" \
1439714394
"$P_SRV debug_level=4 auth_mode=required" \
1439814395
"$O_NEXT_CLI -tls1_2 -split_send_frag 3 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1439914396
1 \
@@ -14404,7 +14401,7 @@ run_test "Handshake defragmentation on server: len=3, TLS 1.3 Client-Hallo ->
1440414401
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_2
1440514402
requires_config_enabled MBEDTLS_SSL_PROTO_TLS1_3
1440614403
requires_certificate_authentication
14407-
run_test "Handshake defragmentation on server: len=32, TLS 1.3 Client-Hallo -> 1.2 Handhsake" \
14404+
run_test "Handshake defragmentation on server: len=32, TLS 1.2 ClientHello" \
1440814405
"$P_SRV debug_level=4 force_version=tls12 auth_mode=required" \
1440914406
"$O_NEXT_CLI -tls1_2 -split_send_frag 32 -cert $DATA_FILES_PATH/server5.crt -key $DATA_FILES_PATH/server5.key" \
1441014407
1 \

0 commit comments

Comments
 (0)