08-npn.conf 24 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816
  1. # Generated with generate_ssl_tests.pl
  2. num_tests = 20
  3. test-0 = 0-npn-simple
  4. test-1 = 1-npn-client-finds-match
  5. test-2 = 2-npn-client-honours-server-pref
  6. test-3 = 3-npn-client-first-pref-on-mismatch
  7. test-4 = 4-npn-no-server-support
  8. test-5 = 5-npn-no-client-support
  9. test-6 = 6-npn-with-sni-no-context-switch
  10. test-7 = 7-npn-with-sni-context-switch
  11. test-8 = 8-npn-selected-sni-server-supports-npn
  12. test-9 = 9-npn-selected-sni-server-does-not-support-npn
  13. test-10 = 10-alpn-preferred-over-npn
  14. test-11 = 11-sni-npn-preferred-over-alpn
  15. test-12 = 12-npn-simple-resumption
  16. test-13 = 13-npn-server-switch-resumption
  17. test-14 = 14-npn-client-switch-resumption
  18. test-15 = 15-npn-client-first-pref-on-mismatch-resumption
  19. test-16 = 16-npn-no-server-support-resumption
  20. test-17 = 17-npn-no-client-support-resumption
  21. test-18 = 18-alpn-preferred-over-npn-resumption
  22. test-19 = 19-npn-used-if-alpn-not-supported-resumption
  23. # ===========================================================
  24. [0-npn-simple]
  25. ssl_conf = 0-npn-simple-ssl
  26. [0-npn-simple-ssl]
  27. server = 0-npn-simple-server
  28. client = 0-npn-simple-client
  29. [0-npn-simple-server]
  30. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  31. CipherString = DEFAULT
  32. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  33. [0-npn-simple-client]
  34. CipherString = DEFAULT
  35. MaxProtocol = TLSv1.2
  36. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  37. VerifyMode = Peer
  38. [test-0]
  39. ExpectedNPNProtocol = foo
  40. server = 0-npn-simple-server-extra
  41. client = 0-npn-simple-client-extra
  42. [0-npn-simple-server-extra]
  43. NPNProtocols = foo
  44. [0-npn-simple-client-extra]
  45. NPNProtocols = foo
  46. # ===========================================================
  47. [1-npn-client-finds-match]
  48. ssl_conf = 1-npn-client-finds-match-ssl
  49. [1-npn-client-finds-match-ssl]
  50. server = 1-npn-client-finds-match-server
  51. client = 1-npn-client-finds-match-client
  52. [1-npn-client-finds-match-server]
  53. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  54. CipherString = DEFAULT
  55. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  56. [1-npn-client-finds-match-client]
  57. CipherString = DEFAULT
  58. MaxProtocol = TLSv1.2
  59. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  60. VerifyMode = Peer
  61. [test-1]
  62. ExpectedNPNProtocol = bar
  63. server = 1-npn-client-finds-match-server-extra
  64. client = 1-npn-client-finds-match-client-extra
  65. [1-npn-client-finds-match-server-extra]
  66. NPNProtocols = baz,bar
  67. [1-npn-client-finds-match-client-extra]
  68. NPNProtocols = foo,bar
  69. # ===========================================================
  70. [2-npn-client-honours-server-pref]
  71. ssl_conf = 2-npn-client-honours-server-pref-ssl
  72. [2-npn-client-honours-server-pref-ssl]
  73. server = 2-npn-client-honours-server-pref-server
  74. client = 2-npn-client-honours-server-pref-client
  75. [2-npn-client-honours-server-pref-server]
  76. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  77. CipherString = DEFAULT
  78. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  79. [2-npn-client-honours-server-pref-client]
  80. CipherString = DEFAULT
  81. MaxProtocol = TLSv1.2
  82. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  83. VerifyMode = Peer
  84. [test-2]
  85. ExpectedNPNProtocol = bar
  86. server = 2-npn-client-honours-server-pref-server-extra
  87. client = 2-npn-client-honours-server-pref-client-extra
  88. [2-npn-client-honours-server-pref-server-extra]
  89. NPNProtocols = bar,foo
  90. [2-npn-client-honours-server-pref-client-extra]
  91. NPNProtocols = foo,bar
  92. # ===========================================================
  93. [3-npn-client-first-pref-on-mismatch]
  94. ssl_conf = 3-npn-client-first-pref-on-mismatch-ssl
  95. [3-npn-client-first-pref-on-mismatch-ssl]
  96. server = 3-npn-client-first-pref-on-mismatch-server
  97. client = 3-npn-client-first-pref-on-mismatch-client
  98. [3-npn-client-first-pref-on-mismatch-server]
  99. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  100. CipherString = DEFAULT
  101. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  102. [3-npn-client-first-pref-on-mismatch-client]
  103. CipherString = DEFAULT
  104. MaxProtocol = TLSv1.2
  105. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  106. VerifyMode = Peer
  107. [test-3]
  108. ExpectedNPNProtocol = foo
  109. server = 3-npn-client-first-pref-on-mismatch-server-extra
  110. client = 3-npn-client-first-pref-on-mismatch-client-extra
  111. [3-npn-client-first-pref-on-mismatch-server-extra]
  112. NPNProtocols = baz
  113. [3-npn-client-first-pref-on-mismatch-client-extra]
  114. NPNProtocols = foo,bar
  115. # ===========================================================
  116. [4-npn-no-server-support]
  117. ssl_conf = 4-npn-no-server-support-ssl
  118. [4-npn-no-server-support-ssl]
  119. server = 4-npn-no-server-support-server
  120. client = 4-npn-no-server-support-client
  121. [4-npn-no-server-support-server]
  122. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  123. CipherString = DEFAULT
  124. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  125. [4-npn-no-server-support-client]
  126. CipherString = DEFAULT
  127. MaxProtocol = TLSv1.2
  128. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  129. VerifyMode = Peer
  130. [test-4]
  131. client = 4-npn-no-server-support-client-extra
  132. [4-npn-no-server-support-client-extra]
  133. NPNProtocols = foo
  134. # ===========================================================
  135. [5-npn-no-client-support]
  136. ssl_conf = 5-npn-no-client-support-ssl
  137. [5-npn-no-client-support-ssl]
  138. server = 5-npn-no-client-support-server
  139. client = 5-npn-no-client-support-client
  140. [5-npn-no-client-support-server]
  141. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  142. CipherString = DEFAULT
  143. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  144. [5-npn-no-client-support-client]
  145. CipherString = DEFAULT
  146. MaxProtocol = TLSv1.2
  147. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  148. VerifyMode = Peer
  149. [test-5]
  150. server = 5-npn-no-client-support-server-extra
  151. [5-npn-no-client-support-server-extra]
  152. NPNProtocols = foo
  153. # ===========================================================
  154. [6-npn-with-sni-no-context-switch]
  155. ssl_conf = 6-npn-with-sni-no-context-switch-ssl
  156. [6-npn-with-sni-no-context-switch-ssl]
  157. server = 6-npn-with-sni-no-context-switch-server
  158. client = 6-npn-with-sni-no-context-switch-client
  159. server2 = 6-npn-with-sni-no-context-switch-server2
  160. [6-npn-with-sni-no-context-switch-server]
  161. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  162. CipherString = DEFAULT
  163. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  164. [6-npn-with-sni-no-context-switch-server2]
  165. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  166. CipherString = DEFAULT
  167. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  168. [6-npn-with-sni-no-context-switch-client]
  169. CipherString = DEFAULT
  170. MaxProtocol = TLSv1.2
  171. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  172. VerifyMode = Peer
  173. [test-6]
  174. ExpectedNPNProtocol = foo
  175. ExpectedServerName = server1
  176. server = 6-npn-with-sni-no-context-switch-server-extra
  177. server2 = 6-npn-with-sni-no-context-switch-server2-extra
  178. client = 6-npn-with-sni-no-context-switch-client-extra
  179. [6-npn-with-sni-no-context-switch-server-extra]
  180. NPNProtocols = foo
  181. ServerNameCallback = IgnoreMismatch
  182. [6-npn-with-sni-no-context-switch-server2-extra]
  183. NPNProtocols = bar
  184. [6-npn-with-sni-no-context-switch-client-extra]
  185. NPNProtocols = foo,bar
  186. ServerName = server1
  187. # ===========================================================
  188. [7-npn-with-sni-context-switch]
  189. ssl_conf = 7-npn-with-sni-context-switch-ssl
  190. [7-npn-with-sni-context-switch-ssl]
  191. server = 7-npn-with-sni-context-switch-server
  192. client = 7-npn-with-sni-context-switch-client
  193. server2 = 7-npn-with-sni-context-switch-server2
  194. [7-npn-with-sni-context-switch-server]
  195. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  196. CipherString = DEFAULT
  197. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  198. [7-npn-with-sni-context-switch-server2]
  199. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  200. CipherString = DEFAULT
  201. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  202. [7-npn-with-sni-context-switch-client]
  203. CipherString = DEFAULT
  204. MaxProtocol = TLSv1.2
  205. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  206. VerifyMode = Peer
  207. [test-7]
  208. ExpectedNPNProtocol = bar
  209. ExpectedServerName = server2
  210. server = 7-npn-with-sni-context-switch-server-extra
  211. server2 = 7-npn-with-sni-context-switch-server2-extra
  212. client = 7-npn-with-sni-context-switch-client-extra
  213. [7-npn-with-sni-context-switch-server-extra]
  214. NPNProtocols = foo
  215. ServerNameCallback = IgnoreMismatch
  216. [7-npn-with-sni-context-switch-server2-extra]
  217. NPNProtocols = bar
  218. [7-npn-with-sni-context-switch-client-extra]
  219. NPNProtocols = foo,bar
  220. ServerName = server2
  221. # ===========================================================
  222. [8-npn-selected-sni-server-supports-npn]
  223. ssl_conf = 8-npn-selected-sni-server-supports-npn-ssl
  224. [8-npn-selected-sni-server-supports-npn-ssl]
  225. server = 8-npn-selected-sni-server-supports-npn-server
  226. client = 8-npn-selected-sni-server-supports-npn-client
  227. server2 = 8-npn-selected-sni-server-supports-npn-server2
  228. [8-npn-selected-sni-server-supports-npn-server]
  229. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  230. CipherString = DEFAULT
  231. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  232. [8-npn-selected-sni-server-supports-npn-server2]
  233. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  234. CipherString = DEFAULT
  235. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  236. [8-npn-selected-sni-server-supports-npn-client]
  237. CipherString = DEFAULT
  238. MaxProtocol = TLSv1.2
  239. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  240. VerifyMode = Peer
  241. [test-8]
  242. ExpectedNPNProtocol = bar
  243. ExpectedServerName = server2
  244. server = 8-npn-selected-sni-server-supports-npn-server-extra
  245. server2 = 8-npn-selected-sni-server-supports-npn-server2-extra
  246. client = 8-npn-selected-sni-server-supports-npn-client-extra
  247. [8-npn-selected-sni-server-supports-npn-server-extra]
  248. ServerNameCallback = IgnoreMismatch
  249. [8-npn-selected-sni-server-supports-npn-server2-extra]
  250. NPNProtocols = bar
  251. [8-npn-selected-sni-server-supports-npn-client-extra]
  252. NPNProtocols = foo,bar
  253. ServerName = server2
  254. # ===========================================================
  255. [9-npn-selected-sni-server-does-not-support-npn]
  256. ssl_conf = 9-npn-selected-sni-server-does-not-support-npn-ssl
  257. [9-npn-selected-sni-server-does-not-support-npn-ssl]
  258. server = 9-npn-selected-sni-server-does-not-support-npn-server
  259. client = 9-npn-selected-sni-server-does-not-support-npn-client
  260. server2 = 9-npn-selected-sni-server-does-not-support-npn-server2
  261. [9-npn-selected-sni-server-does-not-support-npn-server]
  262. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  263. CipherString = DEFAULT
  264. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  265. [9-npn-selected-sni-server-does-not-support-npn-server2]
  266. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  267. CipherString = DEFAULT
  268. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  269. [9-npn-selected-sni-server-does-not-support-npn-client]
  270. CipherString = DEFAULT
  271. MaxProtocol = TLSv1.2
  272. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  273. VerifyMode = Peer
  274. [test-9]
  275. ExpectedServerName = server2
  276. server = 9-npn-selected-sni-server-does-not-support-npn-server-extra
  277. client = 9-npn-selected-sni-server-does-not-support-npn-client-extra
  278. [9-npn-selected-sni-server-does-not-support-npn-server-extra]
  279. NPNProtocols = bar
  280. ServerNameCallback = IgnoreMismatch
  281. [9-npn-selected-sni-server-does-not-support-npn-client-extra]
  282. NPNProtocols = foo,bar
  283. ServerName = server2
  284. # ===========================================================
  285. [10-alpn-preferred-over-npn]
  286. ssl_conf = 10-alpn-preferred-over-npn-ssl
  287. [10-alpn-preferred-over-npn-ssl]
  288. server = 10-alpn-preferred-over-npn-server
  289. client = 10-alpn-preferred-over-npn-client
  290. [10-alpn-preferred-over-npn-server]
  291. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  292. CipherString = DEFAULT
  293. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  294. [10-alpn-preferred-over-npn-client]
  295. CipherString = DEFAULT
  296. MaxProtocol = TLSv1.2
  297. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  298. VerifyMode = Peer
  299. [test-10]
  300. ExpectedALPNProtocol = foo
  301. server = 10-alpn-preferred-over-npn-server-extra
  302. client = 10-alpn-preferred-over-npn-client-extra
  303. [10-alpn-preferred-over-npn-server-extra]
  304. ALPNProtocols = foo
  305. NPNProtocols = bar
  306. [10-alpn-preferred-over-npn-client-extra]
  307. ALPNProtocols = foo
  308. NPNProtocols = bar
  309. # ===========================================================
  310. [11-sni-npn-preferred-over-alpn]
  311. ssl_conf = 11-sni-npn-preferred-over-alpn-ssl
  312. [11-sni-npn-preferred-over-alpn-ssl]
  313. server = 11-sni-npn-preferred-over-alpn-server
  314. client = 11-sni-npn-preferred-over-alpn-client
  315. server2 = 11-sni-npn-preferred-over-alpn-server2
  316. [11-sni-npn-preferred-over-alpn-server]
  317. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  318. CipherString = DEFAULT
  319. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  320. [11-sni-npn-preferred-over-alpn-server2]
  321. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  322. CipherString = DEFAULT
  323. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  324. [11-sni-npn-preferred-over-alpn-client]
  325. CipherString = DEFAULT
  326. MaxProtocol = TLSv1.2
  327. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  328. VerifyMode = Peer
  329. [test-11]
  330. ExpectedNPNProtocol = bar
  331. ExpectedServerName = server2
  332. server = 11-sni-npn-preferred-over-alpn-server-extra
  333. server2 = 11-sni-npn-preferred-over-alpn-server2-extra
  334. client = 11-sni-npn-preferred-over-alpn-client-extra
  335. [11-sni-npn-preferred-over-alpn-server-extra]
  336. ALPNProtocols = foo
  337. ServerNameCallback = IgnoreMismatch
  338. [11-sni-npn-preferred-over-alpn-server2-extra]
  339. NPNProtocols = bar
  340. [11-sni-npn-preferred-over-alpn-client-extra]
  341. ALPNProtocols = foo
  342. NPNProtocols = bar
  343. ServerName = server2
  344. # ===========================================================
  345. [12-npn-simple-resumption]
  346. ssl_conf = 12-npn-simple-resumption-ssl
  347. [12-npn-simple-resumption-ssl]
  348. server = 12-npn-simple-resumption-server
  349. client = 12-npn-simple-resumption-client
  350. resume-server = 12-npn-simple-resumption-server
  351. resume-client = 12-npn-simple-resumption-client
  352. [12-npn-simple-resumption-server]
  353. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  354. CipherString = DEFAULT
  355. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  356. [12-npn-simple-resumption-client]
  357. CipherString = DEFAULT
  358. MaxProtocol = TLSv1.2
  359. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  360. VerifyMode = Peer
  361. [test-12]
  362. ExpectedNPNProtocol = foo
  363. HandshakeMode = Resume
  364. ResumptionExpected = Yes
  365. server = 12-npn-simple-resumption-server-extra
  366. resume-server = 12-npn-simple-resumption-server-extra
  367. client = 12-npn-simple-resumption-client-extra
  368. resume-client = 12-npn-simple-resumption-client-extra
  369. [12-npn-simple-resumption-server-extra]
  370. NPNProtocols = foo
  371. [12-npn-simple-resumption-client-extra]
  372. NPNProtocols = foo
  373. # ===========================================================
  374. [13-npn-server-switch-resumption]
  375. ssl_conf = 13-npn-server-switch-resumption-ssl
  376. [13-npn-server-switch-resumption-ssl]
  377. server = 13-npn-server-switch-resumption-server
  378. client = 13-npn-server-switch-resumption-client
  379. resume-server = 13-npn-server-switch-resumption-resume-server
  380. resume-client = 13-npn-server-switch-resumption-client
  381. [13-npn-server-switch-resumption-server]
  382. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  383. CipherString = DEFAULT
  384. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  385. [13-npn-server-switch-resumption-resume-server]
  386. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  387. CipherString = DEFAULT
  388. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  389. [13-npn-server-switch-resumption-client]
  390. CipherString = DEFAULT
  391. MaxProtocol = TLSv1.2
  392. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  393. VerifyMode = Peer
  394. [test-13]
  395. ExpectedNPNProtocol = baz
  396. HandshakeMode = Resume
  397. ResumptionExpected = Yes
  398. server = 13-npn-server-switch-resumption-server-extra
  399. resume-server = 13-npn-server-switch-resumption-resume-server-extra
  400. client = 13-npn-server-switch-resumption-client-extra
  401. resume-client = 13-npn-server-switch-resumption-client-extra
  402. [13-npn-server-switch-resumption-server-extra]
  403. NPNProtocols = bar,foo
  404. [13-npn-server-switch-resumption-resume-server-extra]
  405. NPNProtocols = baz,foo
  406. [13-npn-server-switch-resumption-client-extra]
  407. NPNProtocols = foo,bar,baz
  408. # ===========================================================
  409. [14-npn-client-switch-resumption]
  410. ssl_conf = 14-npn-client-switch-resumption-ssl
  411. [14-npn-client-switch-resumption-ssl]
  412. server = 14-npn-client-switch-resumption-server
  413. client = 14-npn-client-switch-resumption-client
  414. resume-server = 14-npn-client-switch-resumption-server
  415. resume-client = 14-npn-client-switch-resumption-resume-client
  416. [14-npn-client-switch-resumption-server]
  417. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  418. CipherString = DEFAULT
  419. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  420. [14-npn-client-switch-resumption-client]
  421. CipherString = DEFAULT
  422. MaxProtocol = TLSv1.2
  423. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  424. VerifyMode = Peer
  425. [14-npn-client-switch-resumption-resume-client]
  426. CipherString = DEFAULT
  427. MaxProtocol = TLSv1.2
  428. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  429. VerifyMode = Peer
  430. [test-14]
  431. ExpectedNPNProtocol = bar
  432. HandshakeMode = Resume
  433. ResumptionExpected = Yes
  434. server = 14-npn-client-switch-resumption-server-extra
  435. resume-server = 14-npn-client-switch-resumption-server-extra
  436. client = 14-npn-client-switch-resumption-client-extra
  437. resume-client = 14-npn-client-switch-resumption-resume-client-extra
  438. [14-npn-client-switch-resumption-server-extra]
  439. NPNProtocols = foo,bar,baz
  440. [14-npn-client-switch-resumption-client-extra]
  441. NPNProtocols = foo,baz
  442. [14-npn-client-switch-resumption-resume-client-extra]
  443. NPNProtocols = bar,baz
  444. # ===========================================================
  445. [15-npn-client-first-pref-on-mismatch-resumption]
  446. ssl_conf = 15-npn-client-first-pref-on-mismatch-resumption-ssl
  447. [15-npn-client-first-pref-on-mismatch-resumption-ssl]
  448. server = 15-npn-client-first-pref-on-mismatch-resumption-server
  449. client = 15-npn-client-first-pref-on-mismatch-resumption-client
  450. resume-server = 15-npn-client-first-pref-on-mismatch-resumption-resume-server
  451. resume-client = 15-npn-client-first-pref-on-mismatch-resumption-client
  452. [15-npn-client-first-pref-on-mismatch-resumption-server]
  453. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  454. CipherString = DEFAULT
  455. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  456. [15-npn-client-first-pref-on-mismatch-resumption-resume-server]
  457. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  458. CipherString = DEFAULT
  459. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  460. [15-npn-client-first-pref-on-mismatch-resumption-client]
  461. CipherString = DEFAULT
  462. MaxProtocol = TLSv1.2
  463. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  464. VerifyMode = Peer
  465. [test-15]
  466. ExpectedNPNProtocol = foo
  467. HandshakeMode = Resume
  468. ResumptionExpected = Yes
  469. server = 15-npn-client-first-pref-on-mismatch-resumption-server-extra
  470. resume-server = 15-npn-client-first-pref-on-mismatch-resumption-resume-server-extra
  471. client = 15-npn-client-first-pref-on-mismatch-resumption-client-extra
  472. resume-client = 15-npn-client-first-pref-on-mismatch-resumption-client-extra
  473. [15-npn-client-first-pref-on-mismatch-resumption-server-extra]
  474. NPNProtocols = bar
  475. [15-npn-client-first-pref-on-mismatch-resumption-resume-server-extra]
  476. NPNProtocols = baz
  477. [15-npn-client-first-pref-on-mismatch-resumption-client-extra]
  478. NPNProtocols = foo,bar
  479. # ===========================================================
  480. [16-npn-no-server-support-resumption]
  481. ssl_conf = 16-npn-no-server-support-resumption-ssl
  482. [16-npn-no-server-support-resumption-ssl]
  483. server = 16-npn-no-server-support-resumption-server
  484. client = 16-npn-no-server-support-resumption-client
  485. resume-server = 16-npn-no-server-support-resumption-resume-server
  486. resume-client = 16-npn-no-server-support-resumption-client
  487. [16-npn-no-server-support-resumption-server]
  488. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  489. CipherString = DEFAULT
  490. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  491. [16-npn-no-server-support-resumption-resume-server]
  492. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  493. CipherString = DEFAULT
  494. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  495. [16-npn-no-server-support-resumption-client]
  496. CipherString = DEFAULT
  497. MaxProtocol = TLSv1.2
  498. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  499. VerifyMode = Peer
  500. [test-16]
  501. HandshakeMode = Resume
  502. ResumptionExpected = Yes
  503. server = 16-npn-no-server-support-resumption-server-extra
  504. client = 16-npn-no-server-support-resumption-client-extra
  505. resume-client = 16-npn-no-server-support-resumption-client-extra
  506. [16-npn-no-server-support-resumption-server-extra]
  507. NPNProtocols = foo
  508. [16-npn-no-server-support-resumption-client-extra]
  509. NPNProtocols = foo
  510. # ===========================================================
  511. [17-npn-no-client-support-resumption]
  512. ssl_conf = 17-npn-no-client-support-resumption-ssl
  513. [17-npn-no-client-support-resumption-ssl]
  514. server = 17-npn-no-client-support-resumption-server
  515. client = 17-npn-no-client-support-resumption-client
  516. resume-server = 17-npn-no-client-support-resumption-server
  517. resume-client = 17-npn-no-client-support-resumption-resume-client
  518. [17-npn-no-client-support-resumption-server]
  519. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  520. CipherString = DEFAULT
  521. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  522. [17-npn-no-client-support-resumption-client]
  523. CipherString = DEFAULT
  524. MaxProtocol = TLSv1.2
  525. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  526. VerifyMode = Peer
  527. [17-npn-no-client-support-resumption-resume-client]
  528. CipherString = DEFAULT
  529. MaxProtocol = TLSv1.2
  530. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  531. VerifyMode = Peer
  532. [test-17]
  533. HandshakeMode = Resume
  534. ResumptionExpected = Yes
  535. server = 17-npn-no-client-support-resumption-server-extra
  536. resume-server = 17-npn-no-client-support-resumption-server-extra
  537. client = 17-npn-no-client-support-resumption-client-extra
  538. [17-npn-no-client-support-resumption-server-extra]
  539. NPNProtocols = foo
  540. [17-npn-no-client-support-resumption-client-extra]
  541. NPNProtocols = foo
  542. # ===========================================================
  543. [18-alpn-preferred-over-npn-resumption]
  544. ssl_conf = 18-alpn-preferred-over-npn-resumption-ssl
  545. [18-alpn-preferred-over-npn-resumption-ssl]
  546. server = 18-alpn-preferred-over-npn-resumption-server
  547. client = 18-alpn-preferred-over-npn-resumption-client
  548. resume-server = 18-alpn-preferred-over-npn-resumption-resume-server
  549. resume-client = 18-alpn-preferred-over-npn-resumption-client
  550. [18-alpn-preferred-over-npn-resumption-server]
  551. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  552. CipherString = DEFAULT
  553. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  554. [18-alpn-preferred-over-npn-resumption-resume-server]
  555. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  556. CipherString = DEFAULT
  557. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  558. [18-alpn-preferred-over-npn-resumption-client]
  559. CipherString = DEFAULT
  560. MaxProtocol = TLSv1.2
  561. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  562. VerifyMode = Peer
  563. [test-18]
  564. ExpectedALPNProtocol = foo
  565. HandshakeMode = Resume
  566. ResumptionExpected = Yes
  567. server = 18-alpn-preferred-over-npn-resumption-server-extra
  568. resume-server = 18-alpn-preferred-over-npn-resumption-resume-server-extra
  569. client = 18-alpn-preferred-over-npn-resumption-client-extra
  570. resume-client = 18-alpn-preferred-over-npn-resumption-client-extra
  571. [18-alpn-preferred-over-npn-resumption-server-extra]
  572. NPNProtocols = bar
  573. [18-alpn-preferred-over-npn-resumption-resume-server-extra]
  574. ALPNProtocols = foo
  575. NPNProtocols = baz
  576. [18-alpn-preferred-over-npn-resumption-client-extra]
  577. ALPNProtocols = foo
  578. NPNProtocols = bar,baz
  579. # ===========================================================
  580. [19-npn-used-if-alpn-not-supported-resumption]
  581. ssl_conf = 19-npn-used-if-alpn-not-supported-resumption-ssl
  582. [19-npn-used-if-alpn-not-supported-resumption-ssl]
  583. server = 19-npn-used-if-alpn-not-supported-resumption-server
  584. client = 19-npn-used-if-alpn-not-supported-resumption-client
  585. resume-server = 19-npn-used-if-alpn-not-supported-resumption-resume-server
  586. resume-client = 19-npn-used-if-alpn-not-supported-resumption-client
  587. [19-npn-used-if-alpn-not-supported-resumption-server]
  588. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  589. CipherString = DEFAULT
  590. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  591. [19-npn-used-if-alpn-not-supported-resumption-resume-server]
  592. Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
  593. CipherString = DEFAULT
  594. PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
  595. [19-npn-used-if-alpn-not-supported-resumption-client]
  596. CipherString = DEFAULT
  597. MaxProtocol = TLSv1.2
  598. VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
  599. VerifyMode = Peer
  600. [test-19]
  601. ExpectedNPNProtocol = baz
  602. HandshakeMode = Resume
  603. ResumptionExpected = Yes
  604. server = 19-npn-used-if-alpn-not-supported-resumption-server-extra
  605. resume-server = 19-npn-used-if-alpn-not-supported-resumption-resume-server-extra
  606. client = 19-npn-used-if-alpn-not-supported-resumption-client-extra
  607. resume-client = 19-npn-used-if-alpn-not-supported-resumption-client-extra
  608. [19-npn-used-if-alpn-not-supported-resumption-server-extra]
  609. ALPNProtocols = foo
  610. NPNProtocols = bar
  611. [19-npn-used-if-alpn-not-supported-resumption-resume-server-extra]
  612. NPNProtocols = baz
  613. [19-npn-used-if-alpn-not-supported-resumption-client-extra]
  614. ALPNProtocols = foo
  615. NPNProtocols = bar,baz