-
Notifications
You must be signed in to change notification settings - Fork 1.2k
Expand file tree
/
Copy pathpki_test.go
More file actions
94 lines (89 loc) · 2.67 KB
/
Copy pathpki_test.go
File metadata and controls
94 lines (89 loc) · 2.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
package nebula
import (
"strings"
"testing"
"github.com/slackhq/nebula/cert"
"github.com/stretchr/testify/assert"
"github.com/stretchr/testify/require"
)
func TestNewCipherSuite(t *testing.T) {
tests := []struct {
name string
curve cert.Curve
cipher string
fips140Enforced bool
wantErr string
// wantName is the full expected CipherSuite name (<DH>_<Cipher>_<Hash>),
// only checked when wantErr is empty. Asserting the whole name makes both
// the curve and cipher selection load-bearing.
wantName string
}{
{
name: "curve25519 aesgcm, not enforced",
curve: cert.Curve_CURVE25519,
cipher: "aesgcm",
wantName: "25519_AESGCM_SHA256",
},
{
name: "curve25519 chachapoly, not enforced",
curve: cert.Curve_CURVE25519,
cipher: "chachapoly",
wantName: "25519_ChaChaPoly_SHA256",
},
{
name: "p256 aesgcm, not enforced",
curve: cert.Curve_P256,
cipher: "aesgcm",
wantName: "P256_AESGCM_SHA256",
},
{
name: "p256 aesgcm, enforced is allowed",
curve: cert.Curve_P256,
cipher: "aesgcm",
fips140Enforced: true,
wantName: "P256_AESGCM_SHA256",
},
{
name: "curve25519 rejected when enforced",
curve: cert.Curve_CURVE25519,
cipher: "aesgcm",
fips140Enforced: true,
wantErr: "pki: use of Curve25519 is not allowed in FIPS 140-only mode",
},
{
name: "chachapoly rejected when enforced",
curve: cert.Curve_P256,
cipher: "chachapoly",
fips140Enforced: true,
wantErr: "pki: use of ChaChaPoly is not allowed in FIPS 140-only mode",
},
{
// Curve is checked before cipher, so a Curve25519+ChaChaPoly
// request reports the Curve25519 rejection.
name: "curve25519 chachapoly rejected on curve when enforced",
curve: cert.Curve_CURVE25519,
cipher: "chachapoly",
fips140Enforced: true,
wantErr: "pki: use of Curve25519 is not allowed in FIPS 140-only mode",
},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
cs, err := newCipherSuite(tt.curve, false, tt.cipher, tt.fips140Enforced)
if tt.wantErr != "" {
require.EqualError(t, err, tt.wantErr)
assert.Nil(t, cs)
return
}
require.NoError(t, err)
require.NotNil(t, cs)
assert.Equal(t, tt.wantName, string(cs.Name()))
})
}
}
func TestNewCipherSuiteUnsupportedCurve(t *testing.T) {
cs, err := newCipherSuite(cert.Curve(99), false, "aesgcm", false)
require.Error(t, err)
assert.True(t, strings.HasPrefix(err.Error(), "unsupported curve:"), "got: %v", err)
assert.Nil(t, cs)
}