Skip to content

Commit 2325c68

Browse files
committed
Address connection issues in ocsp-stapling test
1 parent c71a4dd commit 2325c68

File tree

3 files changed

+49
-64
lines changed

3 files changed

+49
-64
lines changed

certs/external/README.txt

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,2 @@
1-
ca_collection.pem contains the two possible Root CA's that login.live.com can
2-
return, either the Baltimore Cyber Trust Root CA or the DigiCert Global Sign
3-
Root CA.
1+
ca_collection.pem contains the Root CA certificates that login.live.com can
2+
return: DigiCert Global Root CA and DigiCert Global Root G2.

certs/external/ca_collection.pem

Lines changed: 23 additions & 60 deletions
Original file line numberDiff line numberDiff line change
@@ -1,63 +1,3 @@
1-
Certificate:
2-
Data:
3-
Version: 3 (0x2)
4-
Serial Number:
5-
08:3b:e0:56:90:42:46:b1:a1:75:6a:c9:59:91:c7:4a
6-
Signature Algorithm: sha1WithRSAEncryption
7-
Issuer: C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root CA
8-
Validity
9-
Not Before: Nov 10 00:00:00 2006 GMT
10-
Not After : Nov 10 00:00:00 2031 GMT
11-
Subject: C = US, O = DigiCert Inc, OU = www.digicert.com, CN = DigiCert Global Root CA
12-
Subject Public Key Info:
13-
Public Key Algorithm: rsaEncryption
14-
RSA Public-Key: (2048 bit)
15-
Modulus:
16-
00:e2:3b:e1:11:72:de:a8:a4:d3:a3:57:aa:50:a2:
17-
8f:0b:77:90:c9:a2:a5:ee:12:ce:96:5b:01:09:20:
18-
cc:01:93:a7:4e:30:b7:53:f7:43:c4:69:00:57:9d:
19-
e2:8d:22:dd:87:06:40:00:81:09:ce:ce:1b:83:bf:
20-
df:cd:3b:71:46:e2:d6:66:c7:05:b3:76:27:16:8f:
21-
7b:9e:1e:95:7d:ee:b7:48:a3:08:da:d6:af:7a:0c:
22-
39:06:65:7f:4a:5d:1f:bc:17:f8:ab:be:ee:28:d7:
23-
74:7f:7a:78:99:59:85:68:6e:5c:23:32:4b:bf:4e:
24-
c0:e8:5a:6d:e3:70:bf:77:10:bf:fc:01:f6:85:d9:
25-
a8:44:10:58:32:a9:75:18:d5:d1:a2:be:47:e2:27:
26-
6a:f4:9a:33:f8:49:08:60:8b:d4:5f:b4:3a:84:bf:
27-
a1:aa:4a:4c:7d:3e:cf:4f:5f:6c:76:5e:a0:4b:37:
28-
91:9e:dc:22:e6:6d:ce:14:1a:8e:6a:cb:fe:cd:b3:
29-
14:64:17:c7:5b:29:9e:32:bf:f2:ee:fa:d3:0b:42:
30-
d4:ab:b7:41:32:da:0c:d4:ef:f8:81:d5:bb:8d:58:
31-
3f:b5:1b:e8:49:28:a2:70:da:31:04:dd:f7:b2:16:
32-
f2:4c:0a:4e:07:a8:ed:4a:3d:5e:b5:7f:a3:90:c3:
33-
af:27
34-
Exponent: 65537 (0x10001)
35-
X509v3 extensions:
36-
X509v3 Key Usage: critical
37-
Digital Signature, Certificate Sign, CRL Sign
38-
X509v3 Basic Constraints: critical
39-
CA:TRUE
40-
X509v3 Subject Key Identifier:
41-
03:DE:50:35:56:D1:4C:BB:66:F0:A3:E2:1B:1B:C3:97:B2:3D:D1:55
42-
X509v3 Authority Key Identifier:
43-
keyid:03:DE:50:35:56:D1:4C:BB:66:F0:A3:E2:1B:1B:C3:97:B2:3D:D1:55
44-
45-
Signature Algorithm: sha1WithRSAEncryption
46-
cb:9c:37:aa:48:13:12:0a:fa:dd:44:9c:4f:52:b0:f4:df:ae:
47-
04:f5:79:79:08:a3:24:18:fc:4b:2b:84:c0:2d:b9:d5:c7:fe:
48-
f4:c1:1f:58:cb:b8:6d:9c:7a:74:e7:98:29:ab:11:b5:e3:70:
49-
a0:a1:cd:4c:88:99:93:8c:91:70:e2:ab:0f:1c:be:93:a9:ff:
50-
63:d5:e4:07:60:d3:a3:bf:9d:5b:09:f1:d5:8e:e3:53:f4:8e:
51-
63:fa:3f:a7:db:b4:66:df:62:66:d6:d1:6e:41:8d:f2:2d:b5:
52-
ea:77:4a:9f:9d:58:e2:2b:59:c0:40:23:ed:2d:28:82:45:3e:
53-
79:54:92:26:98:e0:80:48:a8:37:ef:f0:d6:79:60:16:de:ac:
54-
e8:0e:cd:6e:ac:44:17:38:2f:49:da:e1:45:3e:2a:b9:36:53:
55-
cf:3a:50:06:f7:2e:e8:c4:57:49:6c:61:21:18:d5:04:ad:78:
56-
3c:2c:3a:80:6b:a7:eb:af:15:14:e9:d8:89:c1:b9:38:6c:e2:
57-
91:6c:8a:ff:64:b9:77:25:57:30:c0:1b:24:a3:e1:dc:e9:df:
58-
47:7c:b5:b4:24:08:05:30:ec:2d:bd:0b:bf:45:bf:50:b9:a9:
59-
f3:eb:98:01:12:ad:c8:88:c6:98:34:5f:8d:0a:3c:c6:e9:d5:
60-
95:95:6d:de
611
-----BEGIN CERTIFICATE-----
622
MIIDrzCCApegAwIBAgIQCDvgVpBCRrGhdWrJWZHHSjANBgkqhkiG9w0BAQUFADBh
633
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
@@ -80,3 +20,26 @@ PnlUkiaY4IBIqDfv8NZ5YBberOgOzW6sRBc4L0na4UU+Krk2U886UAb3LujEV0ls
8020
YSEY1QSteDwsOoBrp+uvFRTp2InBuThs4pFsiv9kuXclVzDAGySj4dzp30d8tbQk
8121
CAUw7C29C79Fv1C5qfPrmAESrciIxpg0X40KPMbp1ZWVbd4=
8222
-----END CERTIFICATE-----
23+
24+
-----BEGIN CERTIFICATE-----
25+
MIIDjjCCAnagAwIBAgIQAzrx5qcRqaC7KGSxHQn65TANBgkqhkiG9w0BAQsFADBh
26+
MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMRkwFwYDVQQLExB3
27+
d3cuZGlnaWNlcnQuY29tMSAwHgYDVQQDExdEaWdpQ2VydCBHbG9iYWwgUm9vdCBH
28+
MjAeFw0xMzA4MDExMjAwMDBaFw0zODAxMTUxMjAwMDBaMGExCzAJBgNVBAYTAlVT
29+
MRUwEwYDVQQKEwxEaWdpQ2VydCBJbmMxGTAXBgNVBAsTEHd3dy5kaWdpY2VydC5j
30+
b20xIDAeBgNVBAMTF0RpZ2lDZXJ0IEdsb2JhbCBSb290IEcyMIIBIjANBgkqhkiG
31+
9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuzfNNNx7a8myaJCtSnX/RrohCgiN9RlUyfuI
32+
2/Ou8jqJkTx65qsGGmvPrC3oXgkkRLpimn7Wo6h+4FR1IAWsULecYxpsMNzaHxmx
33+
1x7e/dfgy5SDN67sH0NO3Xss0r0upS/kqbitOtSZpLYl6ZtrAGCSYP9PIUkY92eQ
34+
q2EGnI/yuum06ZIya7XzV+hdG82MHauVBJVJ8zUtluNJbd134/tJS7SsVQepj5Wz
35+
tCO7TG1F8PapspUwtP1MVYwnSlcUfIKdzXOS0xZKBgyMUNGPHgm+F6HmIcr9g+UQ
36+
vIOlCsRnKPZzFBQ9RnbDhxSJITRNrw9FDKZJobq7nMWxM4MphQIDAQABo0IwQDAP
37+
BgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBhjAdBgNVHQ4EFgQUTiJUIBiV
38+
5uNu5g/6+rkS7QYXjzkwDQYJKoZIhvcNAQELBQADggEBAGBnKJRvDkhj6zHd6mcY
39+
1Yl9PMWLSn/pvtsrF9+wX3N3KjITOYFnQoQj8kVnNeyIv/iPsGEMNKSuIEyExtv4
40+
NeF22d+mQrvHRAiGfzZ0JFrabA0UWTW98kndth/Jsw1HKj2ZL7tcu7XUIOGZX1NG
41+
Fdtom/DzMNU+MeKNhJ7jitralj41E6Vf8PlwUHBHQRFXGU7Aj64GxJUTFy8bJZ91
42+
8rGOmaFvE7FBcf6IKshPECBV1/MUReXgRPTqh5Uykw7+U0b6LJ3/iyK5S9kJRaTe
43+
pLiaWN0bfVKfjllDiIGknibVb63dDcY3fe0Dkhvld1927jyNxF1WW6LZZm6zNTfl
44+
MrY=
45+
-----END CERTIFICATE-----

scripts/ocsp-stapling.test

Lines changed: 24 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -119,6 +119,29 @@ remove_single_rF(){
119119
fi
120120
}
121121

122+
retry_with_backoff() {
123+
local max_attempts=$1
124+
shift
125+
local attempt=1
126+
local delay=1
127+
local status=0
128+
129+
while :; do
130+
"$@"
131+
status=$?
132+
if [ $status -eq 0 ]; then
133+
return 0
134+
fi
135+
if [ $attempt -ge $max_attempts ]; then
136+
return $status
137+
fi
138+
printf '%s\n' "Retry $attempt/$max_attempts failed, backing off ${delay}s..."
139+
sleep $delay
140+
attempt=$((attempt + 1))
141+
delay=$((delay * 2))
142+
done
143+
}
144+
122145
#create a configure file for cert generation with the port 0 solution
123146
create_new_cnf() {
124147
printf '%s\n' "Random Port Selected: $1"
@@ -304,7 +327,7 @@ server=login.live.com
304327
ca=./certs/external/ca_collection.pem
305328

306329
if [[ "$V4V6" == "4" ]]; then
307-
./examples/client/client -C -h $server -p 443 -A $ca -g -W 1
330+
retry_with_backoff 3 ./examples/client/client -C -h $server -p 443 -A $ca -g -W 1
308331
RESULT=$?
309332
[ $RESULT -ne 0 ] && echo -e "\n\nClient connection failed" && exit 1
310333
else

0 commit comments

Comments
 (0)