diff --git a/ssl/ssl_test.cc b/ssl/ssl_test.cc index 404e38d91..3595204b7 100644 --- a/ssl/ssl_test.cc +++ b/ssl/ssl_test.cc @@ -8990,5 +8990,38 @@ TEST(SSLTest, NameLists) { } } +// Test that it is possible for the certificate to be configured on a mix of +// SSL_CTX and SSL. This ensures that we do not inadvertently overshare objects +// in SSL_new. +TEST(SSLTest, MixContextAndConnection) { + bssl::UniquePtr ctx(SSL_CTX_new(TLS_method())); + ASSERT_TRUE(ctx); + bssl::UniquePtr cert = GetTestCertificate(); + ASSERT_TRUE(cert); + bssl::UniquePtr key = GetTestKey(); + ASSERT_TRUE(key); + + // Configure the certificate, but not the private key, on the context. + ASSERT_TRUE(SSL_CTX_use_certificate(ctx.get(), cert.get())); + + bssl::UniquePtr ssl1(SSL_new(ctx.get())); + ASSERT_TRUE(ssl1.get()); + bssl::UniquePtr ssl2(SSL_new(ctx.get())); + ASSERT_TRUE(ssl2.get()); + + // There is no private key configured yet. + EXPECT_FALSE(SSL_CTX_get0_privatekey(ctx.get())); + EXPECT_FALSE(SSL_get_privatekey(ssl1.get())); + EXPECT_FALSE(SSL_get_privatekey(ssl2.get())); + + // Configuring the private key on |ssl1| works. + ASSERT_TRUE(SSL_use_PrivateKey(ssl1.get(), key.get())); + EXPECT_TRUE(SSL_get_privatekey(ssl1.get())); + + // It does not impact the other connection or the context. + EXPECT_FALSE(SSL_CTX_get0_privatekey(ctx.get())); + EXPECT_FALSE(SSL_get_privatekey(ssl2.get())); +} + } // namespace BSSL_NAMESPACE_END