From 624f33dfeab938e907251e3cc3062aa45353384f Mon Sep 17 00:00:00 2001 From: Jeremy Harris Date: Sat, 8 Sep 2018 19:31:49 +0100 Subject: DANE - testcase for fail under GnuTLS with TA-mode to a selfsigned server cert --- test/confs/5822 | 67 +++++++++++++++++++++++++++++++++++++++++++++++++++++++++ test/confs/5842 | 64 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 2 files changed, 131 insertions(+) create mode 100644 test/confs/5822 create mode 100644 test/confs/5842 (limited to 'test/confs') diff --git a/test/confs/5822 b/test/confs/5822 new file mode 100644 index 000000000..80a8ef43b --- /dev/null +++ b/test/confs/5822 @@ -0,0 +1,67 @@ +# Exim test configuration 5822 +# DANE/GnuTLS + +SERVER= + +.include DIR/aux-var/tls_conf_prefix + +primary_hostname = myhost.test.ex + +# ----- Main settings ----- + +acl_smtp_rcpt = accept logwrite = "rcpt ACL" + +log_selector = +received_recipients +tls_peerdn +tls_certificate_verified + +queue_run_in_order + +tls_advertise_hosts = * +# needed to force generation +tls_dhparam = historic + +tls_certificate = ${if eq {SERVER}{server} {DIR/aux-fixed/cert1} fail} + +# ----- Routers ----- + +begin routers + +client: + driver = dnslookup + condition = ${if eq {SERVER}{}} + dnssec_request_domains = * + self = send + transport = send_to_server + errors_to = "" + +server: + driver = redirect + condition = ${if !eq {SERVER}{}} + data = :blackhole: + + +# ----- Transports ----- + +begin transports + +send_to_server: + driver = smtp + allow_localhost + port = PORT_D + + hosts_try_dane = * + hosts_require_dane = HOSTIPV4 + tls_verify_cert_hostnames = : + tls_try_verify_hosts = thishost.test.ex +# tls_verify_certificates = CDIR2/ca_chain.pem + + + +# ----- Retry ----- + + +begin retry + +* * F,5d,10s + + +# End diff --git a/test/confs/5842 b/test/confs/5842 new file mode 100644 index 000000000..be45e847c --- /dev/null +++ b/test/confs/5842 @@ -0,0 +1,64 @@ +# Exim test configuration 5822 +# DANE/OpenSSL + +SERVER= + +.include DIR/aux-var/tls_conf_prefix + +primary_hostname = myhost.test.ex + +# ----- Main settings ----- + +acl_smtp_rcpt = accept logwrite = "rcpt ACL" + +log_selector = +received_recipients +tls_peerdn +tls_certificate_verified + +queue_run_in_order + +tls_advertise_hosts = * + +tls_certificate = ${if eq {SERVER}{server} {DIR/aux-fixed/cert1} fail} + +# ----- Routers ----- + +begin routers + +client: + driver = dnslookup + condition = ${if eq {SERVER}{}} + dnssec_request_domains = * + self = send + transport = send_to_server + errors_to = "" + +server: + driver = redirect + data = :blackhole: + + +# ----- Transports ----- + +begin transports + +send_to_server: + driver = smtp + allow_localhost + port = PORT_D + + hosts_try_dane = * + hosts_require_dane = HOSTIPV4 + tls_verify_cert_hostnames = : + tls_try_verify_hosts = thishost.test.ex +# tls_verify_certificates = CDIR2/ca_chain.pem + + + +# ----- Retry ----- + + +begin retry + +* * F,5d,10s + + +# End -- cgit v1.2.3