gnutls/renegotiation-with-OpenSSL: Test extension#10
gnutls/renegotiation-with-OpenSSL: Test extension#10
Conversation
why it's not added? |
|
It's part of the #5 PR, so I'd like to avoid creating unnecessary merge conflicts. |
There was a problem hiding this comment.
Thanks, I'm not sure how it got there...
67891df to
b2d4123
Compare
|
first, the I'm postponing this PR until #5 is merged |
b2d4123 to
c377062
Compare
GnuTLS on RHEL 6 has minimal TLS 1.2 implementation and most of the ciphersuites/features used in this test don't work there.
c377062 to
862d098
Compare
|
I've disabled this test on RHEL 6 and applied a 'workaround' for The first handshake is completed successfully, but the renegotiation fails with following error: GnuTLS (client) OpenSSL (server) This happens with all tested ciphersuites. |
|
Downstream bugs for the issue: |
Wow, nice job! I guess then we need to mark those cases as irrelevant for RHEL-7.4 and earlier (hoping for fix in 7.5). It would be nice to have a fix in Fedora before merging though, but a check for version there is probably also acceptable... |
| if [[ $proto == "tls1_1" ]]; then | ||
| options+=(-tls1_1) | ||
| fi | ||
| rlRun -s "(sleep 0.5; echo R; sleep 0.5; echo Q) | ${options[*]}" |
There was a problem hiding this comment.
that's not reliable in my experience, but let's see how it works out...
|
given that RHBZ#1434091 won't be fixed any time soon, I wonder if we shouldn't workaround it, merge the workarounded version and either prepare a PR that removes the workaround or just create an issue that reminds us to check if it is fixed in next RHEL |
This PR extends the gnutls/renegotiation-with-OpenSSL test with following:
Also, the same issues as in #9 apply to this PR:
TLS_DHE_DSS_WITH_AES_128_CBC_SHAdoesn't work in GNUTLS when TLS 1.2 is disabledrlGetTestState