Improve test coverage around NewSessionTicket message.
Test both when the peer doesn't support session tickets and when the server promises a NewSessionTicket message but doesn't deliver. Change-Id: I48f338094002beac2e6b80e41851c72822b3b9d5 Reviewed-on: https://boringssl-review.googlesource.com/1300 Reviewed-by: Adam Langley <agl@google.com>
This commit is contained in:
committed by
Adam Langley
parent
072334d943
commit
d23f412a8a
@@ -374,6 +374,10 @@ type ProtocolBugs struct {
|
||||
// zero disables this behavior. One and two configure variants for 0.9.8
|
||||
// and 1.0.1 modes, respectively.
|
||||
EarlyChangeCipherSpec int
|
||||
|
||||
// SkipNewSessionTicket causes the server to skip sending the
|
||||
// NewSessionTicket message despite promising to in ServerHello.
|
||||
SkipNewSessionTicket bool
|
||||
}
|
||||
|
||||
func (c *Config) serverInit() {
|
||||
|
||||
@@ -570,7 +570,7 @@ func (hs *serverHandshakeState) readFinished() error {
|
||||
}
|
||||
|
||||
func (hs *serverHandshakeState) sendSessionTicket() error {
|
||||
if !hs.hello.ticketSupported {
|
||||
if !hs.hello.ticketSupported || hs.c.config.Bugs.SkipNewSessionTicket {
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
@@ -284,6 +284,29 @@ var testCases = []testCase{
|
||||
shouldFail: true,
|
||||
expectedError: ":CCS_RECEIVED_EARLY:",
|
||||
},
|
||||
{
|
||||
name: "SessionTicketsDisabled-Client",
|
||||
config: Config{
|
||||
SessionTicketsDisabled: true,
|
||||
},
|
||||
},
|
||||
{
|
||||
testType: serverTest,
|
||||
name: "SessionTicketsDisabled-Server",
|
||||
config: Config{
|
||||
SessionTicketsDisabled: true,
|
||||
},
|
||||
},
|
||||
{
|
||||
name: "SkipNewSessionTicket",
|
||||
config: Config{
|
||||
Bugs: ProtocolBugs{
|
||||
SkipNewSessionTicket: true,
|
||||
},
|
||||
},
|
||||
shouldFail: true,
|
||||
expectedError: ":CCS_RECEIVED_EARLY:",
|
||||
},
|
||||
}
|
||||
|
||||
func doExchange(testType testType, config *Config, conn net.Conn, messageLen int) error {
|
||||
|
||||
Reference in New Issue
Block a user