diff options
author | Daniel Baumann <daniel.baumann@progress-linux.org> | 2024-04-15 16:28:20 +0000 |
---|---|---|
committer | Daniel Baumann <daniel.baumann@progress-linux.org> | 2024-04-15 16:28:20 +0000 |
commit | dcc721a95bef6f0d8e6d8775b8efe33e5aecd562 (patch) | |
tree | 66a2774cd0ee294d019efd71d2544c70f42b2842 /tests/sndrcv_tls_certvalid_expired.sh | |
parent | Initial commit. (diff) | |
download | rsyslog-dcc721a95bef6f0d8e6d8775b8efe33e5aecd562.tar.xz rsyslog-dcc721a95bef6f0d8e6d8775b8efe33e5aecd562.zip |
Adding upstream version 8.2402.0.upstream/8.2402.0
Signed-off-by: Daniel Baumann <daniel.baumann@progress-linux.org>
Diffstat (limited to 'tests/sndrcv_tls_certvalid_expired.sh')
-rwxr-xr-x | tests/sndrcv_tls_certvalid_expired.sh | 63 |
1 files changed, 63 insertions, 0 deletions
diff --git a/tests/sndrcv_tls_certvalid_expired.sh b/tests/sndrcv_tls_certvalid_expired.sh new file mode 100755 index 0000000..bab916c --- /dev/null +++ b/tests/sndrcv_tls_certvalid_expired.sh @@ -0,0 +1,63 @@ +#!/bin/bash +# This file is part of the rsyslog project, released under ASL 2.0 +. ${srcdir:=.}/diag.sh init +printf 'using TLS driver: %s\n' ${RS_TLS_DRIVER:=gtls} + +# start up the instances +# export RSYSLOG_DEBUG="debug nostdout noprintmutexaction" +export RSYSLOG_DEBUGLOG="$RSYSLOG_DYNNAME.receiver.debuglog" +generate_conf +add_conf ' +global( + defaultNetstreamDriverCAFile="'$srcdir/testsuites/x.509/ca.pem'" + defaultNetstreamDriverCertFile="'$srcdir/testsuites/x.509/client-cert.pem'" + defaultNetstreamDriverKeyFile="'$srcdir/testsuites/x.509/client-key.pem'" + defaultNetstreamDriver="'$RS_TLS_DRIVER'" +# debug.whitelist="on" +# debug.files=["nsd_ossl.c", "tcpsrv.c", "nsdsel_ossl.c", "nsdpoll_ptcp.c", "dnscache.c"] +) + +module( load="../plugins/imtcp/.libs/imtcp" + StreamDriver.Name="'$RS_TLS_DRIVER'" + StreamDriver.Mode="1" + StreamDriver.AuthMode="x509/certvalid" + StreamDriver.PermitExpiredCerts="off" + ) +input(type="imtcp" port="0" listenPortFileName="'$RSYSLOG_DYNNAME'.tcpflood_port") + +action(type="omfile" file="'$RSYSLOG_OUT_LOG'") +' +startup +export PORT_RCVR=$TCPFLOOD_PORT +export RSYSLOG_DEBUGLOG="$RSYSLOG_DYNNAME.sender.debuglog" +#valgrind="valgrind" +generate_conf 2 +add_conf ' +global( + defaultNetstreamDriverCAFile="'$srcdir/testsuites/x.509/ca.pem'" + defaultNetstreamDriverCertFile="'$srcdir/testsuites/x.509/client-expired-cert.pem'" + defaultNetstreamDriverKeyFile="'$srcdir/testsuites/x.509/client-expired-key.pem'" + defaultNetstreamDriver="'$RS_TLS_DRIVER'" +) + +# set up the action +$ActionSendStreamDriverMode 1 # require TLS for the connection +$ActionSendStreamDriverAuthMode anon +*.* @@127.0.0.1:'$PORT_RCVR' +' 2 +startup 2 + +# now inject the messages into instance 2. It will connect to instance 1, +# and that instance will record the data. +injectmsg2 + +# shut down sender when everything is sent, receiver continues to run concurrently +shutdown_when_empty 2 +wait_shutdown 2 +# now it is time to stop the receiver as well +shutdown_when_empty +wait_shutdown + +content_check --regex "not permitted to talk to peer '.*', certificate invalid: certificate expired" + +exit_test |