|
| 1 | +'use strict'; |
| 2 | +constcommon=require('../common'); |
| 3 | +constfixtures=require('../common/fixtures'); |
| 4 | + |
| 5 | +// This test starts an https server and tries |
| 6 | +// to connect to it using a self-signed certificate. |
| 7 | +// This certificate´s keyUsage does not include the keyCertSign |
| 8 | +// bit, which used to crash node. The test ensures node |
| 9 | +// will not crash. Key and certificate are from #37889. |
| 10 | +// Note: This test assumes that the connection will succeed. |
| 11 | + |
| 12 | +if(!common.hasCrypto) |
| 13 | +common.skip('missing crypto'); |
| 14 | + |
| 15 | +constcrypto=require('crypto'); |
| 16 | + |
| 17 | +// See #37990 for details on why this is problematic with FIPS. |
| 18 | +if(process.config.variables.openssl_is_fips) |
| 19 | +common.skip('Skipping as test uses non-fips compliant EC curve'); |
| 20 | + |
| 21 | +// This test will fail for OpenSSL < 1.1.1h |
| 22 | +constminOpenSSL=269488271; |
| 23 | + |
| 24 | +if(crypto.constants.OPENSSL_VERSION_NUMBER<minOpenSSL) |
| 25 | +common.skip('OpenSSL < 1.1.1h'); |
| 26 | + |
| 27 | +consthttps=require('https'); |
| 28 | +constpath=require('path'); |
| 29 | + |
| 30 | +constkey= |
| 31 | +fixtures.readKey(path.join('selfsigned-no-keycertsign','key.pem')); |
| 32 | + |
| 33 | +constcert= |
| 34 | +fixtures.readKey(path.join('selfsigned-no-keycertsign','cert.pem')); |
| 35 | + |
| 36 | +constserverOptions={ |
| 37 | +key: key, |
| 38 | +cert: cert |
| 39 | +}; |
| 40 | + |
| 41 | +// Start the server |
| 42 | +consthttpsServer=https.createServer(serverOptions,(req,res)=>{ |
| 43 | +res.writeHead(200); |
| 44 | +res.end('hello world\n'); |
| 45 | +}); |
| 46 | +httpsServer.listen(0); |
| 47 | + |
| 48 | +httpsServer.on('listening',()=>{ |
| 49 | +// Once the server started listening, built the client config |
| 50 | +// with the server´s used port |
| 51 | +constclientOptions={ |
| 52 | +hostname: '127.0.0.1', |
| 53 | +port: httpsServer.address().port, |
| 54 | +ca: cert |
| 55 | +}; |
| 56 | +// Try to connect |
| 57 | +constreq=https.request(clientOptions,common.mustCall((res)=>{ |
| 58 | +httpsServer.close(); |
| 59 | +})); |
| 60 | + |
| 61 | +req.on('error',common.mustNotCall()); |
| 62 | +req.end(); |
| 63 | +}); |
0 commit comments