mirror of
https://github.com/drwetter/testssl.sh.git
synced 2026-09-14 05:38:16 +02:00
Try fix problems
- MacOS: LibreSSL doesn't understand -naccept, so we use homebrew's OpenSSL - Ubuntu: No idea why that still fails. Maybe the DNS setup is borked, so that scanning and listening is split between IPv4 and IPv6 (weak guess)
This commit is contained in:
+19
-12
@@ -1,6 +1,6 @@
|
|||||||
#!/usr/bin/env perl
|
#!/usr/bin/env perl
|
||||||
|
|
||||||
# As the name indicates: Check for TLS 1.3 only hosts. It just run the protocol section, there
|
# As the name indicates: Check for TLS 1.3 only hosts. It just runs the protocol section, there
|
||||||
# it checks for TLS 1.2 (disabled) and TLS 1.3 (enabled)
|
# it checks for TLS 1.2 (disabled) and TLS 1.3 (enabled)
|
||||||
|
|
||||||
use strict;
|
use strict;
|
||||||
@@ -14,16 +14,26 @@ my $port = 1443;
|
|||||||
my $temp_dir = tempdir(CLEANUP => 1);
|
my $temp_dir = tempdir(CLEANUP => 1);
|
||||||
my $server_script = "$temp_dir/start_server.sh";
|
my $server_script = "$temp_dir/start_server.sh";
|
||||||
|
|
||||||
# 1. The Shell Script as HEREDOC
|
|
||||||
|
# Shell script as HEREDOC - aim is reusability
|
||||||
my $shell_code = <<'HEREDOC';
|
my $shell_code = <<'HEREDOC';
|
||||||
#!/bin/bash
|
#!/bin/bash
|
||||||
# Configuration
|
# Configuration
|
||||||
PORT=1443
|
PORT=1443
|
||||||
|
IP=127.0.0.1
|
||||||
CERT="server.pem"
|
CERT="server.pem"
|
||||||
KEY="server.key"
|
KEY="server.key"
|
||||||
# This OpenSSL version will support TLS 1.3
|
# This OpenSSL version will support TLS 1.3
|
||||||
OPENSSL=/usr/bin/openssl
|
OPENSSL=/usr/bin/openssl
|
||||||
|
|
||||||
|
if [[ $(openssl version) =~ LibreSSL ]]; then # MacOS. LibreSSL doesn't know "-naccept"
|
||||||
|
if [[ -x /opt/homebrew/bin/openssl.NOPE ]]; then
|
||||||
|
OPENSSL=/opt/homebrew/bin/openssl.NOPE # We hid that during GHA CI checks
|
||||||
|
elif [[ -x /opt/homebrew/bin/openssl ]]; then
|
||||||
|
OPENSSL=/opt/homebrew/bin/openssl # If you intend this to run
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
# Force a specific TLS 1.3 cipher suite when needed
|
# Force a specific TLS 1.3 cipher suite when needed
|
||||||
# CIPHER_SUITE="TLS_AES_256_GCM_SHA384"
|
# CIPHER_SUITE="TLS_AES_256_GCM_SHA384"
|
||||||
|
|
||||||
@@ -35,8 +45,9 @@ fi
|
|||||||
|
|
||||||
# Start OpenSSL server
|
# Start OpenSSL server
|
||||||
echo "Starting server on port $PORT..."
|
echo "Starting server on port $PORT..."
|
||||||
# $OPENSSL s_server -accept "$PORT" -cert "$CERT" -key "$KEY" -tls1_3 -ciphersuites "$CIPHER_SUITE" -naccept 4242
|
# $OPENSSL s_server -accept "$IP:$PORT" -cert "$CERT" -key "$KEY" -tls1_3 -ciphersuites "$CIPHER_SUITE" -naccept 4242
|
||||||
$OPENSSL s_server -accept "$PORT" -cert "$CERT" -key "$KEY" -tls1_3 -naccept 4242
|
$OPENSSL s_server -accept "$IP:$PORT" -cert "$CERT" -key "$KEY" -tls1_3 -naccept 4242
|
||||||
|
|
||||||
HEREDOC
|
HEREDOC
|
||||||
|
|
||||||
|
|
||||||
@@ -62,10 +73,11 @@ elsif ($pid > 0) {
|
|||||||
# Wait for the server to be listening on the port
|
# Wait for the server to be listening on the port
|
||||||
my $socket;
|
my $socket;
|
||||||
my $ready = 0;
|
my $ready = 0;
|
||||||
|
my $listenip = '127.0.0.1';
|
||||||
|
|
||||||
for my $i (1..30) {
|
for my $i (1..30) {
|
||||||
$socket = IO::Socket::INET->new(
|
$socket = IO::Socket::INET->new(
|
||||||
PeerAddr => 'localhost',
|
PeerAddr => $listenip,
|
||||||
PeerPort => $port,
|
PeerPort => $port,
|
||||||
Proto => 'tcp',
|
Proto => 'tcp',
|
||||||
Timeout => 2,
|
Timeout => 2,
|
||||||
@@ -79,12 +91,12 @@ elsif ($pid > 0) {
|
|||||||
sleep 1;
|
sleep 1;
|
||||||
}
|
}
|
||||||
|
|
||||||
ok($ready, "Server is listening on port $port");
|
ok($ready, "Server is listening on $listenip:$port");
|
||||||
|
|
||||||
if ($ready) {
|
if ($ready) {
|
||||||
# Run testssl.sh, capture both stdout and stderr.
|
# Run testssl.sh, capture both stdout and stderr.
|
||||||
# We're using the OpenSSL version testssl.sh picks up
|
# We're using the OpenSSL version testssl.sh picks up
|
||||||
my $testssl_output = `./testssl.sh --protocols localhost:$port 2>&1`;
|
my $testssl_output = `./testssl.sh --protocols $listenip:$port 2>&1`;
|
||||||
|
|
||||||
# Check if TLS 1.3 is found
|
# Check if TLS 1.3 is found
|
||||||
like($testssl_output, qr/TLS 1\.3/, "TLS 1.3 is supported");
|
like($testssl_output, qr/TLS 1\.3/, "TLS 1.3 is supported");
|
||||||
@@ -92,8 +104,6 @@ elsif ($pid > 0) {
|
|||||||
# Check if TLS 1.2 is NOT found
|
# Check if TLS 1.2 is NOT found
|
||||||
unlike($testssl_output, qr/OFFERED\s+TLS 1\.2/, "TLS 1.2 is NOT offered");
|
unlike($testssl_output, qr/OFFERED\s+TLS 1\.2/, "TLS 1.2 is NOT offered");
|
||||||
|
|
||||||
# diag("Test output:\n$testssl_output");
|
|
||||||
|
|
||||||
} else {
|
} else {
|
||||||
my $log = '';
|
my $log = '';
|
||||||
if (open my $lfh, '<', "$temp_dir/server.log") {
|
if (open my $lfh, '<', "$temp_dir/server.log") {
|
||||||
@@ -103,9 +113,6 @@ elsif ($pid > 0) {
|
|||||||
}
|
}
|
||||||
diag("Server failed to start. Log:\n$log");
|
diag("Server failed to start. Log:\n$log");
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
# Cleanup: Kill the server process
|
# Cleanup: Kill the server process
|
||||||
kill 9, $pid;
|
kill 9, $pid;
|
||||||
waitpid($pid, 0);
|
waitpid($pid, 0);
|
||||||
|
|||||||
Reference in New Issue
Block a user