aboutsummaryrefslogtreecommitdiff
path: root/src/crypto/tls/testdata/Server-TLSv12-ClientAuthRequestedNotGiven
diff options
context:
space:
mode:
authorFilippo Valsorda <filippo@golang.org>2019-06-13 18:33:33 -0400
committerFilippo Valsorda <filippo@golang.org>2019-06-19 19:59:14 +0000
commit0b3a57b5374bba3fdf88258e2be4c8be65e6a5de (patch)
tree60f2c993a944c3c0f7f82a5c265ac8d5d956b375 /src/crypto/tls/testdata/Server-TLSv12-ClientAuthRequestedNotGiven
parent0ab1cc33ef35147b0e1248f2a9d669ae193d6b3e (diff)
downloadgo-0b3a57b5374bba3fdf88258e2be4c8be65e6a5de.tar.xz
crypto/tls: disable RSA-PSS in TLS 1.2 again
Signing with RSA-PSS can uncover faulty crypto.Signer implementations, and it can fail for (broken) small keys. We'll have to take that breakage eventually, but it would be nice for it to be opt-out at first. TLS 1.3 requires RSA-PSS and is opt-out in Go 1.13. Instead of making a TLS 1.3 opt-out influence a TLS 1.2 behavior, let's wait to add RSA-PSS to TLS 1.2 until TLS 1.3 is on without opt-out. Note that since the Client Hello is sent before a protocol version is selected, we have to advertise RSA-PSS there to support TLS 1.3. That means that we still support RSA-PSS on the client in TLS 1.2 for verifying server certificates, which is fine, as all issues arise on the signing side. We have to be careful not to pick (or consider available) RSA-PSS on the client for client certificates, though. We'd expect tests to change only in TLS 1.2: * the server won't pick PSS to sign the key exchange (Server-TLSv12-* w/ RSA, TestHandshakeServerRSAPSS); * the server won't advertise PSS in CertificateRequest (Server-TLSv12-ClientAuthRequested*, TestClientAuth); * and the client won't pick PSS for its CertificateVerify (Client-TLSv12-ClientCert-RSA-*, TestHandshakeClientCertRSAPSS, Client-TLSv12-Renegotiate* because "R" requests a client cert). Client-TLSv13-ClientCert-RSA-RSAPSS was updated because of a fix in the test. This effectively reverts 88343530720a52c96b21f2bd5488c8fb607605d7. Testing was made more complex by the undocumented semantics of OpenSSL's -[client_]sigalgs (see openssl/openssl#9172). Updates #32425 Change-Id: Iaddeb2df1f5c75cd090cc8321df2ac8e8e7db349 Reviewed-on: https://go-review.googlesource.com/c/go/+/182339 Reviewed-by: Adam Langley <agl@golang.org>
Diffstat (limited to 'src/crypto/tls/testdata/Server-TLSv12-ClientAuthRequestedNotGiven')
-rw-r--r--src/crypto/tls/testdata/Server-TLSv12-ClientAuthRequestedNotGiven61
1 files changed, 30 insertions, 31 deletions
diff --git a/src/crypto/tls/testdata/Server-TLSv12-ClientAuthRequestedNotGiven b/src/crypto/tls/testdata/Server-TLSv12-ClientAuthRequestedNotGiven
index 833d331697..5711a3f6b6 100644
--- a/src/crypto/tls/testdata/Server-TLSv12-ClientAuthRequestedNotGiven
+++ b/src/crypto/tls/testdata/Server-TLSv12-ClientAuthRequestedNotGiven
@@ -1,7 +1,7 @@
>>> Flow 1 (client to server)
-00000000 16 03 01 00 97 01 00 00 93 03 03 af 6e 31 55 9f |............n1U.|
-00000010 fb 22 73 ce a2 0a b6 a3 3e 13 14 83 09 8c e2 98 |."s.....>.......|
-00000020 c3 6f a3 80 79 e4 7c c5 ff 4e a4 00 00 04 00 2f |.o..y.|..N...../|
+00000000 16 03 01 00 97 01 00 00 93 03 03 67 52 bd 6c 6c |...........gR.ll|
+00000010 76 8e 81 75 11 23 27 99 07 bf 64 96 13 0b 85 78 |v..u.#'...d....x|
+00000020 b4 5b b9 b0 a8 b5 fc 87 ef f2 0e 00 00 04 00 2f |.[............./|
00000030 00 ff 01 00 00 66 00 00 00 0e 00 0c 00 00 09 31 |.....f.........1|
00000040 32 37 2e 30 2e 30 2e 31 00 0b 00 04 03 00 01 02 |27.0.0.1........|
00000050 00 0a 00 0c 00 0a 00 1d 00 17 00 1e 00 19 00 18 |................|
@@ -51,37 +51,36 @@
00000260 f1 6c 04 ed 73 bb b3 43 77 8d 0c 1c f1 0f a1 d8 |.l..s..Cw.......|
00000270 40 83 61 c9 4c 72 2b 9d ae db 46 06 06 4d f4 c1 |@.a.Lr+...F..M..|
00000280 b3 3e c0 d1 bd 42 d4 db fe 3d 13 60 84 5c 21 d3 |.>...B...=.`.\!.|
-00000290 3b e9 fa e7 16 03 03 00 23 0d 00 00 1f 02 01 40 |;.......#......@|
-000002a0 00 18 08 04 04 03 08 07 08 05 08 06 04 01 05 01 |................|
-000002b0 06 01 05 03 06 03 02 01 02 03 00 00 16 03 03 00 |................|
-000002c0 04 0e 00 00 00 |.....|
+00000290 3b e9 fa e7 16 03 03 00 1d 0d 00 00 19 02 01 40 |;..............@|
+000002a0 00 12 04 01 04 03 08 07 05 01 06 01 05 03 06 03 |................|
+000002b0 02 01 02 03 00 00 16 03 03 00 04 0e 00 00 00 |...............|
>>> Flow 3 (client to server)
00000000 16 03 03 00 07 0b 00 00 03 00 00 00 16 03 03 00 |................|
-00000010 86 10 00 00 82 00 80 5b 78 d7 5b 4f e3 55 1f 34 |.......[x.[O.U.4|
-00000020 60 be e9 68 07 28 c0 42 b1 ff 31 2f ac 41 19 1e |`..h.(.B..1/.A..|
-00000030 5b c3 7a d4 e4 59 49 4a ed be b9 95 6c d5 58 4a |[.z..YIJ....l.XJ|
-00000040 4a f5 ea f7 00 39 8b f0 6a c6 5a 5f 4e 53 40 20 |J....9..j.Z_NS@ |
-00000050 70 88 5a d4 e0 9e 25 a2 d5 50 1e 22 ed 02 14 f9 |p.Z...%..P."....|
-00000060 eb 32 dd d2 9c 66 20 4c 4d a1 97 91 48 6f 39 cf |.2...f LM...Ho9.|
-00000070 ae e4 33 4e d9 4d 96 fa 13 39 1d b4 16 85 08 4a |..3N.M...9.....J|
-00000080 8f dc b6 f3 19 05 de 16 aa 3d 5e 71 e7 38 ff 3d |.........=^q.8.=|
-00000090 77 5b 63 df d2 32 3d 14 03 03 00 01 01 16 03 03 |w[c..2=.........|
-000000a0 00 40 d7 df c5 1f ec 3c 10 77 53 78 8f c7 8a 79 |.@.....<.wSx...y|
-000000b0 17 3a 31 57 6f e3 e8 85 3f 33 75 0a f8 a8 4d cc |.:1Wo...?3u...M.|
-000000c0 70 0a d9 d0 8b 87 b5 d4 74 c8 8d 30 3b 80 bd 8c |p.......t..0;...|
-000000d0 cb 42 6f e9 e5 c9 a6 28 16 6d 7a d8 13 cb 57 30 |.Bo....(.mz...W0|
-000000e0 3d 77 |=w|
+00000010 86 10 00 00 82 00 80 31 7f 5d 8c 38 ee d7 05 14 |.......1.].8....|
+00000020 4c 0f 9d 01 2d 80 e9 71 0a 51 69 7b af 75 43 76 |L...-..q.Qi{.uCv|
+00000030 d7 eb 18 14 11 00 82 df f4 e8 d1 83 5e 32 60 6e |............^2`n|
+00000040 49 6d 1a 3f b2 ac 85 9f f3 3c 3c cd f2 0d a8 e0 |Im.?.....<<.....|
+00000050 06 f3 6f 96 18 a0 76 06 c3 73 89 b4 de 30 ed 7b |..o...v..s...0.{|
+00000060 7e 71 2d 13 88 43 ff a7 42 bb 2c 17 73 5f 67 8f |~q-..C..B.,.s_g.|
+00000070 68 e7 52 84 72 34 08 69 c6 f5 1b e9 2b 42 93 90 |h.R.r4.i....+B..|
+00000080 3f 76 f3 89 9f 70 65 da 9c ce 8c bf a3 38 65 e3 |?v...pe......8e.|
+00000090 cf b9 f9 c6 d9 86 a5 14 03 03 00 01 01 16 03 03 |................|
+000000a0 00 40 e7 dd bf f7 33 bc f2 90 a3 43 fa 43 ec 7e |.@....3....C.C.~|
+000000b0 e6 06 28 c1 3f 83 c5 50 65 6d 6b e7 37 cf e7 4b |..(.?..Pemk.7..K|
+000000c0 85 34 3b df 4f 48 82 30 d0 43 f7 00 c4 3f 03 dd |.4;.OH.0.C...?..|
+000000d0 ef c0 d4 04 48 b4 9b ec f0 65 7c 2a bc 87 24 5f |....H....e|*..$_|
+000000e0 7a d5 |z.|
>>> Flow 4 (server to client)
00000000 14 03 03 00 01 01 16 03 03 00 40 00 00 00 00 00 |..........@.....|
-00000010 00 00 00 00 00 00 00 00 00 00 00 93 43 99 29 17 |............C.).|
-00000020 5b 96 2e 5b 22 fc 53 47 b2 85 76 46 d9 1a f2 12 |[..[".SG..vF....|
-00000030 58 e0 0e 0d 0f dc 88 a2 0f b1 00 39 ed d7 99 58 |X..........9...X|
-00000040 99 7b c5 ba 91 a3 72 05 1e 9e c2 17 03 03 00 40 |.{....r........@|
+00000010 00 00 00 00 00 00 00 00 00 00 00 da 0a 2a 09 ef |.............*..|
+00000020 39 6c c9 6d cc c3 ae 56 cd e1 a8 47 26 ec 9c b7 |9l.m...V...G&...|
+00000030 50 eb 2e 10 d4 15 3e 5e cc 65 78 2e 47 bf 18 e8 |P.....>^.ex.G...|
+00000040 62 59 bb 7c b7 2c 28 b1 ea 82 10 17 03 03 00 40 |bY.|.,(........@|
00000050 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |................|
-00000060 f3 ff e7 4d b6 ca 7c 95 ed 96 13 88 70 b3 2c 8b |...M..|.....p.,.|
-00000070 9b 0c 51 77 75 16 b4 c0 df 9f 1a c4 86 68 82 10 |..Qwu........h..|
-00000080 41 c7 1e e5 92 49 ce a3 6f c3 bc 0a 91 04 b6 fa |A....I..o.......|
+00000060 9e 53 10 86 89 0c 8f 14 0c 22 6c 32 33 34 64 83 |.S......."l234d.|
+00000070 28 7c 02 b3 59 b7 b2 60 5a ec f2 a7 1a 21 04 dd |(|..Y..`Z....!..|
+00000080 2a c0 ca 68 07 85 8f 7d 6b da 26 97 52 91 40 e8 |*..h...}k.&.R.@.|
00000090 15 03 03 00 30 00 00 00 00 00 00 00 00 00 00 00 |....0...........|
-000000a0 00 00 00 00 00 2c e7 ff bb 3a f5 00 08 d3 8c 3f |.....,...:.....?|
-000000b0 89 bf 97 de fc c4 91 59 2f 7b b3 b8 ea d0 b1 05 |.......Y/{......|
-000000c0 ca ff d0 78 9f |...x.|
+000000a0 00 00 00 00 00 f4 ae 69 5a bc af 94 f9 7f 60 d1 |.......iZ.....`.|
+000000b0 36 83 e7 23 13 79 ae c1 5a 3b 35 d0 ed 16 12 ac |6..#.y..Z;5.....|
+000000c0 52 b5 4e eb 31 |R.N.1|