summaryrefslogtreecommitdiff
path: root/test/stdout/5820
diff options
context:
space:
mode:
authorJeremy Harris <jgh146exb@wizmail.org>2017-12-22 17:19:37 +0000
committerJeremy Harris <jgh146exb@wizmail.org>2017-12-22 20:42:38 +0000
commit94c1328507098238ae5ec784150c1ae58f3b3118 (patch)
tree33f9a1ecdf808459581ec9f5254cc5e5fd33ccb1 /test/stdout/5820
parent2b01e5359b79cfa9b31296700eb7fc5ae69162c5 (diff)
DANE/GnuTLS: split verification of mixed sets of TLSA records by usage
This is because we cannot do the required CA-anchor and names checks for TA-mode and not for EE-mode, without knowing which usage TLSA was used.
Diffstat (limited to 'test/stdout/5820')
-rw-r--r--test/stdout/58202
1 files changed, 2 insertions, 0 deletions
diff --git a/test/stdout/5820 b/test/stdout/5820
index 35e52c5d1..9bdf21c3f 100644
--- a/test/stdout/5820
+++ b/test/stdout/5820
@@ -24,6 +24,7 @@
### A server insecurely serving a good TLSA record, dane required (delivery should fail)
### A server insecurely serving a good A record, dane requested only (should deliver, non-DANE)
### A server insecurely serving a good A record, dane required (delivery should fail)
+### A server with a mixed-usage set of TLSAs - the EE-mode one failing verify (should deliver, DANE-mode)
### A server with a name not matching the cert. TA-mode; should fail
### A server with a name not matching the cert. EE-mode; should deliver and claim DANE mode
@@ -45,5 +46,6 @@
### A server insecurely serving a good TLSA record, dane required (delivery should fail)
### A server insecurely serving a good A record, dane requested only (should deliver, non-DANE)
### A server insecurely serving a good A record, dane required (delivery should fail)
+### A server with a mixed-usage set of TLSAs - the EE-mode one failing verify (should deliver, DANE-mode)
### A server with a name not matching the cert. TA-mode; should fail
### A server with a name not matching the cert. EE-mode; should deliver and claim DANE mode