|
| 1 | +'use strict'; |
| 2 | +const common = require('../common'); |
| 3 | +if (!common.hasCrypto) common.skip('missing crypto'); |
| 4 | + |
| 5 | +const { isBoringSSL } = require('../common/crypto'); |
| 6 | +// BoringSSL rejects DNS-like CNs without SANs under name constraints, |
| 7 | +// even when the CN is permitted by those constraints. |
| 8 | +if (isBoringSSL) common.skip('requires OpenSSL CN name constraints'); |
| 9 | + |
| 10 | +const assert = require('assert'); |
| 11 | +const tls = require('tls'); |
| 12 | +const fixtures = require('../common/fixtures'); |
| 13 | + |
| 14 | +const ca = fixtures.readKey('name-constraints-ca-cert.pem'); |
| 15 | +const key = fixtures.readKey('agent1-key.pem'); |
| 16 | + |
| 17 | +// A DNS SAN prevents CN fallback; an email SAN does not. Name constraints |
| 18 | +// must cover the CN whenever hostname verification can use it. |
| 19 | +for (const version of ['TLSv1.2', 'TLSv1.3']) { |
| 20 | + for (const [name, servername, valid] of [ |
| 21 | + ['permitted', 'www.example.com', true], |
| 22 | + ['excluded', 'outside.invalid', false], |
| 23 | + ['dns-san', 'www.example.com', true], |
| 24 | + ['email-san', 'outside.invalid', false], |
| 25 | + ]) { |
| 26 | + for (const rejectUnauthorized of [true, false]) { |
| 27 | + const rejected = !valid && rejectUnauthorized; |
| 28 | + const server = tls.createServer({ |
| 29 | + key, |
| 30 | + cert: fixtures.readKey(`name-constraints-${name}-cert.pem`), |
| 31 | + minVersion: version, |
| 32 | + maxVersion: version, |
| 33 | + }, (socket) => socket.end()); |
| 34 | + server.on('tlsClientError', () => {}); |
| 35 | + server.listen(0, common.mustCall(() => { |
| 36 | + const client = tls.connect({ |
| 37 | + port: server.address().port, |
| 38 | + ca, |
| 39 | + servername, |
| 40 | + rejectUnauthorized, |
| 41 | + }); |
| 42 | + client.on('secureConnect', rejected ? common.mustNotCall() : common.mustCall(() => { |
| 43 | + assert.strictEqual(client.authorized, valid); |
| 44 | + if (!valid) assert.strictEqual(client.authorizationError, 'UNSPECIFIED'); |
| 45 | + client.end(); |
| 46 | + })); |
| 47 | + client.on('error', rejected ? common.mustCall((err) => { |
| 48 | + assert.strictEqual(err.code, 'UNSPECIFIED'); |
| 49 | + assert.match(err.message, /permitted subtree violation/); |
| 50 | + }) : common.mustNotCall()); |
| 51 | + client.on('close', common.mustCall(() => server.close())); |
| 52 | + })); |
| 53 | + } |
| 54 | + } |
| 55 | +} |
0 commit comments