blob: 988661a7ef91d7443f66d02329c8ca7521ba8907 [file] [log] [blame]
Paul Bakker645ce3a2012-10-31 12:32:41 +00001killall -q openssl ssl_server ssl_server2
Paul Bakkerfab5c822012-02-06 16:45:10 +00002
Paul Bakker10cd2252012-04-12 21:26:34 +00003MODES="ssl3 tls1 tls1_1 tls1_2"
Paul Bakker1eeceae2012-11-23 14:25:34 +01004VERIFIES="NO YES"
Paul Bakker0c93d122012-09-13 14:26:09 +00005OPENSSL=openssl
Paul Bakker10cd2252012-04-12 21:26:34 +00006
Paul Bakker1eeceae2012-11-23 14:25:34 +01007for VERIFY in $VERIFIES;
8do
Paul Bakker10cd2252012-04-12 21:26:34 +00009if [ "X$VERIFY" = "XYES" ];
10then
Paul Bakker1eeceae2012-11-23 14:25:34 +010011 P_SERVER_ARGS="auth_mode=required crt_file=data_files/server1.crt key_file=data_files/server1.key ca_file=data_files/test-ca.crt"
12 P_CLIENT_ARGS="crt_file=data_files/server2.crt key_file=data_files/server2.key ca_file=data_files/test-ca.crt"
13 O_SERVER_ARGS="-verify 10 -CAfile data_files/test-ca.crt -cert data_files/server1.crt -key data_files/server1.key"
14 O_CLIENT_ARGS="-cert data_files/server2.crt -key data_files/server2.key -CAfile data_files/test-ca.crt"
Paul Bakker10cd2252012-04-12 21:26:34 +000015fi
Paul Bakker398cb512012-04-10 08:22:31 +000016
17for MODE in $MODES;
18do
Paul Bakker1eeceae2012-11-23 14:25:34 +010019echo "Running for $MODE (Verify: $VERIFY)"
Paul Bakker398cb512012-04-10 08:22:31 +000020echo "-----------"
21
Paul Bakker645ce3a2012-10-31 12:32:41 +000022P_CIPHERS=" \
23 TLS-DHE-RSA-WITH-AES-128-CBC-SHA \
24 TLS-DHE-RSA-WITH-AES-256-CBC-SHA \
25 TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA \
26 TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA \
27 TLS-DHE-RSA-WITH-3DES-EDE-CBC-SHA \
28 TLS-RSA-WITH-AES-256-CBC-SHA \
29 TLS-RSA-WITH-CAMELLIA-256-CBC-SHA \
30 TLS-RSA-WITH-AES-128-CBC-SHA \
31 TLS-RSA-WITH-CAMELLIA-128-CBC-SHA \
32 TLS-RSA-WITH-3DES-EDE-CBC-SHA \
33 TLS-RSA-WITH-RC4-128-SHA \
34 TLS-RSA-WITH-RC4-128-MD5 \
35 TLS-RSA-WITH-NULL-MD5 \
36 TLS-RSA-WITH-NULL-SHA \
37 TLS-RSA-WITH-DES-CBC-SHA \
38 TLS-DHE-RSA-WITH-DES-CBC-SHA \
Paul Bakker41c83d32013-03-20 14:39:14 +010039 TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA \
40 TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA \
41 TLS-ECDHE-RSA-WITH-3DES-EDE-CBC-SHA \
42 TLS-ECDHE-RSA-WITH-RC4-128-SHA \
Paul Bakker41c83d32013-03-20 14:39:14 +010043 TLS-ECDHE-RSA-WITH-NULL-SHA \
Paul Bakkerfab5c822012-02-06 16:45:10 +000044 "
45
Paul Bakker10cd2252012-04-12 21:26:34 +000046O_CIPHERS=" \
47 DHE-RSA-AES128-SHA \
48 DHE-RSA-AES256-SHA \
49 DHE-RSA-CAMELLIA128-SHA \
50 DHE-RSA-CAMELLIA256-SHA \
51 EDH-RSA-DES-CBC3-SHA \
52 AES256-SHA \
53 CAMELLIA256-SHA \
54 AES128-SHA \
55 CAMELLIA128-SHA \
56 DES-CBC3-SHA \
57 RC4-SHA \
58 RC4-MD5 \
59 NULL-MD5 \
60 NULL-SHA \
61 DES-CBC-SHA \
62 EDH-RSA-DES-CBC-SHA \
Paul Bakker41c83d32013-03-20 14:39:14 +010063 ECDHE-RSA-AES256-SHA \
64 ECDHE-RSA-AES128-SHA \
65 ECDHE-RSA-DES-CBC3-SHA \
66 ECDHE-RSA-RC4-SHA \
67 ECDHE-RSA-NULL-SHA \
Paul Bakker10cd2252012-04-12 21:26:34 +000068 "
69
Paul Bakker0c93d122012-09-13 14:26:09 +000070# Also add SHA256 ciphersuites
71#
Paul Bakker10cd2252012-04-12 21:26:34 +000072if [ "$MODE" = "tls1_2" ];
73then
Paul Bakker1eeceae2012-11-23 14:25:34 +010074 P_CIPHERS="$P_CIPHERS \
75 TLS-RSA-WITH-NULL-SHA256 \
76 TLS-RSA-WITH-AES-128-CBC-SHA256 \
77 TLS-DHE-RSA-WITH-AES-128-CBC-SHA256 \
78 TLS-RSA-WITH-AES-256-CBC-SHA256 \
79 TLS-DHE-RSA-WITH-AES-256-CBC-SHA256 \
Paul Bakker27714b12013-04-07 23:07:12 +020080 TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256 \
81 TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384 \
Paul Bakker1eeceae2012-11-23 14:25:34 +010082 "
83
84 O_CIPHERS="$O_CIPHERS \
85 NULL-SHA256 \
86 AES128-SHA256 \
87 DHE-RSA-AES128-SHA256 \
88 AES256-SHA256 \
89 DHE-RSA-AES256-SHA256 \
Paul Bakkera54e4932013-03-20 15:31:54 +010090 ECDHE-RSA-AES128-SHA256 \
91 ECDHE-RSA-AES256-SHA384 \
Paul Bakker1eeceae2012-11-23 14:25:34 +010092 "
93
Paul Bakker645ce3a2012-10-31 12:32:41 +000094 P_CIPHERS="$P_CIPHERS \
95 TLS-RSA-WITH-AES-128-GCM-SHA256 \
96 TLS-RSA-WITH-AES-256-GCM-SHA384 \
97 TLS-DHE-RSA-WITH-AES-128-GCM-SHA256 \
98 TLS-DHE-RSA-WITH-AES-256-GCM-SHA384 \
Paul Bakkera54e4932013-03-20 15:31:54 +010099 TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256 \
100 TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384 \
Paul Bakker10cd2252012-04-12 21:26:34 +0000101 "
102
103 O_CIPHERS="$O_CIPHERS \
Paul Bakkerca4ab492012-04-18 14:23:57 +0000104 AES128-GCM-SHA256 \
105 DHE-RSA-AES128-GCM-SHA256 \
106 AES256-GCM-SHA384 \
107 DHE-RSA-AES256-GCM-SHA384 \
Paul Bakkera54e4932013-03-20 15:31:54 +0100108 ECDHE-RSA-AES128-GCM-SHA256 \
109 ECDHE-RSA-AES256-GCM-SHA384 \
Paul Bakker10cd2252012-04-12 21:26:34 +0000110 "
111fi
112
Paul Bakker0c93d122012-09-13 14:26:09 +0000113$OPENSSL s_server -cert data_files/server2.crt -key data_files/server2.key -www -quiet -cipher NULL,ALL $O_SERVER_ARGS -$MODE &
Paul Bakker10cd2252012-04-12 21:26:34 +0000114PROCESS_ID=$!
115
116sleep 1
117
118for i in $P_CIPHERS;
Paul Bakkerfab5c822012-02-06 16:45:10 +0000119do
Paul Bakker10cd2252012-04-12 21:26:34 +0000120 RESULT="$( ../programs/ssl/ssl_client2 $P_CLIENT_ARGS force_ciphersuite=$i )"
Paul Bakkerfab5c822012-02-06 16:45:10 +0000121 EXIT=$?
122 echo -n "OpenSSL Server - PolarSSL Client - $i : $EXIT - "
123 if [ "$EXIT" = "2" ];
124 then
125 echo Ciphersuite not supported in client
126 elif [ "$EXIT" != "0" ];
127 then
128 echo Failed
129 echo $RESULT
130 else
131 echo Success
132 fi
133done
134kill $PROCESS_ID
135
Paul Bakker1eeceae2012-11-23 14:25:34 +0100136../programs/ssl/ssl_server2 $P_SERVER_ARGS > /dev/null &
Paul Bakkerfab5c822012-02-06 16:45:10 +0000137PROCESS_ID=$!
138
139sleep 1
140
Paul Bakker10cd2252012-04-12 21:26:34 +0000141for i in $O_CIPHERS;
Paul Bakkerfab5c822012-02-06 16:45:10 +0000142do
Paul Bakker1eeceae2012-11-23 14:25:34 +0100143 RESULT="$( ( echo -e 'GET HTTP/1.0'; echo; sleep 1 ) | $OPENSSL s_client -$MODE -cipher $i $O_CLIENT_ARGS 2>&1 )"
Paul Bakkerfab5c822012-02-06 16:45:10 +0000144 EXIT=$?
145 echo -n "PolarSSL Server - OpenSSL Client - $i : $EXIT - "
146
147 if [ "$EXIT" != "0" ];
148 then
149 SUPPORTED="$( echo $RESULT | grep 'Cipher is (NONE)' )"
150 if [ "X$SUPPORTED" != "X" ]
151 then
152 echo "Ciphersuite not supported in server"
153 else
154 echo Failed
Paul Bakker1eeceae2012-11-23 14:25:34 +0100155 echo ../programs/ssl/ssl_server2 $P_SERVER_ARGS
156 echo $OPENSSL s_client -$MODE -cipher $i $O_CLIENT_ARGS
Paul Bakkerfab5c822012-02-06 16:45:10 +0000157 echo $RESULT
158 fi
159 else
160 echo Success
161 fi
162done
163
164kill $PROCESS_ID
165
Paul Bakker1eeceae2012-11-23 14:25:34 +0100166../programs/ssl/ssl_server2 $P_SERVER_ARGS > /dev/null &
Paul Bakkerfab5c822012-02-06 16:45:10 +0000167PROCESS_ID=$!
168
169sleep 1
170
Paul Bakker27714b12013-04-07 23:07:12 +0200171# OpenSSL does not support RFC5246 and RFC6367 Camellia ciphers with SHA256
172# or SHA384
Paul Bakker10cd2252012-04-12 21:26:34 +0000173# Add for PolarSSL only test, which does support them.
174#
175if [ "$MODE" = "tls1_2" ];
176then
Paul Bakker645ce3a2012-10-31 12:32:41 +0000177 P_CIPHERS="$P_CIPHERS \
178 TLS-RSA-WITH-CAMELLIA-128-CBC-SHA256 \
179 TLS-DHE-RSA-WITH-CAMELLIA-128-CBC-SHA256 \
180 TLS-RSA-WITH-CAMELLIA-256-CBC-SHA256 \
181 TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA256 \
Paul Bakker27714b12013-04-07 23:07:12 +0200182 TLS-ECDHE-RSA-WITH-CAMELLIA-128-CBC-SHA256 \
183 TLS-ECDHE-RSA-WITH-CAMELLIA-256-CBC-SHA384 \
Paul Bakker10cd2252012-04-12 21:26:34 +0000184 "
185fi
Paul Bakkerfab5c822012-02-06 16:45:10 +0000186
Paul Bakker10cd2252012-04-12 21:26:34 +0000187for i in $P_CIPHERS;
Paul Bakkerfab5c822012-02-06 16:45:10 +0000188do
Paul Bakker1eeceae2012-11-23 14:25:34 +0100189 RESULT="$( ../programs/ssl/ssl_client2 force_ciphersuite=$i $P_CLIENT_ARGS )"
Paul Bakkerfab5c822012-02-06 16:45:10 +0000190 EXIT=$?
191 echo -n "PolarSSL Server - PolarSSL Client - $i : $EXIT - "
192 if [ "$EXIT" = "2" ];
193 then
194 echo Ciphersuite not supported in client
195 elif [ "$EXIT" != "0" ];
196 then
197 echo Failed
198 echo $RESULT
199 else
200 echo Success
201 fi
202done
203kill $PROCESS_ID
204
Paul Bakker398cb512012-04-10 08:22:31 +0000205done
Paul Bakker1eeceae2012-11-23 14:25:34 +0100206done