Artifact
294cc221a653dd2a02af017a1b08edba01aeabc24053268c2634db90bd8e6b0d:
0000: 23 20 41 75 74 6f 20 67 65 6e 65 72 61 74 65 64 # Auto generated
0010: 20 74 65 73 74 20 63 61 73 65 73 20 66 6f 72 20 test cases for
0020: 62 61 64 73 73 6c 2e 63 73 76 0a 0a 23 20 4c 6f badssl.csv..# Lo
0030: 61 64 20 54 63 6c 20 54 65 73 74 20 70 61 63 6b ad Tcl Test pack
0040: 61 67 65 0a 69 66 20 7b 5b 6c 73 65 61 72 63 68 age.if {[lsearch
0050: 20 5b 6e 61 6d 65 73 70 61 63 65 20 63 68 69 6c [namespace chil
0060: 64 72 65 6e 5d 20 3a 3a 74 63 6c 74 65 73 74 5d dren] ::tcltest]
0070: 20 3d 3d 20 2d 31 7d 20 7b 0a 09 70 61 63 6b 61 == -1} {..packa
0080: 67 65 20 72 65 71 75 69 72 65 20 74 63 6c 74 65 ge require tclte
0090: 73 74 0a 09 6e 61 6d 65 73 70 61 63 65 20 69 6d st..namespace im
00a0: 70 6f 72 74 20 3a 3a 74 63 6c 74 65 73 74 3a 3a port ::tcltest::
00b0: 2a 0a 7d 0a 0a 73 65 74 20 61 75 74 6f 5f 70 61 *.}..set auto_pa
00c0: 74 68 20 5b 63 6f 6e 63 61 74 20 5b 6c 69 73 74 th [concat [list
00d0: 20 5b 66 69 6c 65 20 64 69 72 6e 61 6d 65 20 5b [file dirname [
00e0: 66 69 6c 65 20 64 69 72 6e 61 6d 65 20 5b 69 6e file dirname [in
00f0: 66 6f 20 73 63 72 69 70 74 5d 5d 5d 5d 20 24 61 fo script]]]] $a
0100: 75 74 6f 5f 70 61 74 68 5d 0a 0a 70 61 63 6b 61 uto_path]..packa
0110: 67 65 20 72 65 71 75 69 72 65 20 74 6c 73 0a 0a ge require tls..
0120: 23 20 43 6f 6e 73 74 72 61 69 6e 74 73 0a 73 6f # Constraints.so
0130: 75 72 63 65 20 5b 66 69 6c 65 20 6a 6f 69 6e 20 urce [file join
0140: 5b 66 69 6c 65 20 64 69 72 6e 61 6d 65 20 5b 69 [file dirname [i
0150: 6e 66 6f 20 73 63 72 69 70 74 5d 5d 20 63 6f 6d nfo script]] com
0160: 6d 6f 6e 2e 74 63 6c 5d 0a 0a 23 20 48 65 6c 70 mon.tcl]..# Help
0170: 65 72 20 66 75 6e 63 74 69 6f 6e 73 0a 70 72 6f er functions.pro
0180: 63 20 62 61 64 73 73 6c 20 7b 75 72 6c 7d 20 7b c badssl {url} {
0190: 73 65 74 20 70 6f 72 74 20 34 34 33 3b 6c 61 73 set port 443;las
01a0: 73 69 67 6e 20 5b 73 70 6c 69 74 20 24 75 72 6c sign [split $url
01b0: 20 22 3a 22 5d 20 75 72 6c 20 70 6f 72 74 3b 69 ":"] url port;i
01c0: 66 20 7b 24 70 6f 72 74 20 65 71 20 22 22 7d 20 f {$port eq ""}
01d0: 7b 73 65 74 20 70 6f 72 74 20 34 34 33 7d 3b 73 {set port 443};s
01e0: 65 74 20 63 6d 64 20 5b 6c 69 73 74 20 74 6c 73 et cmd [list tls
01f0: 3a 3a 73 6f 63 6b 65 74 20 2d 61 75 74 6f 73 65 ::socket -autose
0200: 72 76 65 72 6e 61 6d 65 20 31 20 2d 72 65 71 75 rvername 1 -requ
0210: 69 72 65 20 31 5d 3b 69 66 20 7b 5b 69 6e 66 6f ire 1];if {[info
0220: 20 65 78 69 73 74 73 20 3a 3a 65 6e 76 28 53 53 exists ::env(SS
0230: 4c 5f 43 45 52 54 5f 46 49 4c 45 29 5d 7d 20 7b L_CERT_FILE)]} {
0240: 6c 61 70 70 65 6e 64 20 63 6d 64 20 2d 63 61 66 lappend cmd -caf
0250: 69 6c 65 20 24 3a 3a 65 6e 76 28 53 53 4c 5f 43 ile $::env(SSL_C
0260: 45 52 54 5f 46 49 4c 45 29 7d 3b 6c 61 70 70 65 ERT_FILE)};lappe
0270: 6e 64 20 63 6d 64 20 24 75 72 6c 20 24 70 6f 72 nd cmd $url $por
0280: 74 3b 73 65 74 20 63 68 20 5b 65 76 61 6c 20 24 t;set ch [eval $
0290: 63 6d 64 5d 3b 69 66 20 7b 5b 63 61 74 63 68 20 cmd];if {[catch
02a0: 7b 74 6c 73 3a 3a 68 61 6e 64 73 68 61 6b 65 20 {tls::handshake
02b0: 24 63 68 7d 20 65 72 72 5d 7d 20 7b 63 6c 6f 73 $ch} err]} {clos
02c0: 65 20 24 63 68 3b 72 65 74 75 72 6e 20 2d 63 6f e $ch;return -co
02d0: 64 65 20 65 72 72 6f 72 20 24 65 72 72 7d 20 65 de error $err} e
02e0: 6c 73 65 20 7b 63 6c 6f 73 65 20 24 63 68 7d 7d lse {close $ch}}
02f0: 0a 0a 23 20 42 61 64 53 53 4c 2e 63 6f 6d 20 54 ..# BadSSL.com T
0300: 65 73 74 73 0a 0a 0a 74 65 73 74 20 42 61 64 53 ests...test BadS
0310: 53 4c 2d 31 2e 31 20 7b 31 30 30 30 2d 73 61 6e SL-1.1 {1000-san
0320: 73 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 s} -body {..bads
0330: 73 6c 20 31 30 30 30 2d 73 61 6e 73 2e 62 61 64 sl 1000-sans.bad
0340: 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 2d 72 ssl.com. } -r
0350: 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 6b 65 esult {handshake
0360: 20 66 61 69 6c 65 64 3a 20 63 65 72 74 69 66 69 failed: certifi
0370: 63 61 74 65 20 76 65 72 69 66 79 20 66 61 69 6c cate verify fail
0380: 65 64 20 64 75 65 20 74 6f 20 22 63 65 72 74 69 ed due to "certi
0390: 66 69 63 61 74 65 20 68 61 73 20 65 78 70 69 72 ficate has expir
03a0: 65 64 22 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 ed"} -returnCode
03b0: 73 20 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 s {1}..test BadS
03c0: 53 4c 2d 31 2e 32 20 7b 31 30 30 30 30 2d 73 61 SL-1.2 {10000-sa
03d0: 6e 73 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 ns} -body {..bad
03e0: 73 73 6c 20 31 30 30 30 30 2d 73 61 6e 73 2e 62 ssl 10000-sans.b
03f0: 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 adssl.com. }
0400: 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 -result {handsha
0410: 6b 65 20 66 61 69 6c 65 64 3a 20 65 78 63 65 73 ke failed: exces
0420: 73 69 76 65 20 6d 65 73 73 61 67 65 20 73 69 7a sive message siz
0430: 65 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 e} -returnCodes
0440: 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c {1}..test BadSSL
0450: 2d 31 2e 33 20 7b 33 64 65 73 7d 20 2d 62 6f 64 -1.3 {3des} -bod
0460: 79 20 7b 0a 09 62 61 64 73 73 6c 20 33 64 65 73 y {..badssl 3des
0470: 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 .badssl.com.
0480: 7d 20 2d 6d 61 74 63 68 20 7b 67 6c 6f 62 7d 20 } -match {glob}
0490: 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 -result {handsha
04a0: 6b 65 20 66 61 69 6c 65 64 3a 20 2a 20 61 6c 65 ke failed: * ale
04b0: 72 74 20 68 61 6e 64 73 68 61 6b 65 20 66 61 69 rt handshake fai
04c0: 6c 75 72 65 7d 20 2d 72 65 74 75 72 6e 43 6f 64 lure} -returnCod
04d0: 65 73 20 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 es {1}..test Bad
04e0: 53 53 4c 2d 31 2e 34 20 7b 63 61 70 74 69 76 65 SSL-1.4 {captive
04f0: 2d 70 6f 72 74 61 6c 7d 20 2d 63 6f 6e 73 74 72 -portal} -constr
0500: 61 69 6e 74 73 20 7b 6f 6c 64 5f 61 70 69 7d 20 aints {old_api}
0510: 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 -body {..badssl
0520: 63 61 70 74 69 76 65 2d 70 6f 72 74 61 6c 2e 62 captive-portal.b
0530: 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 adssl.com. }
0540: 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 -result {handsha
0550: 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 72 74 69 ke failed: certi
0560: 66 69 63 61 74 65 20 76 65 72 69 66 79 20 66 61 ficate verify fa
0570: 69 6c 65 64 20 64 75 65 20 74 6f 20 22 48 6f 73 iled due to "Hos
0580: 74 6e 61 6d 65 20 6d 69 73 6d 61 74 63 68 22 7d tname mismatch"}
0590: 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 -returnCodes {1
05a0: 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 }..test BadSSL-1
05b0: 2e 35 20 7b 63 61 70 74 69 76 65 2d 70 6f 72 74 .5 {captive-port
05c0: 61 6c 7d 20 2d 63 6f 6e 73 74 72 61 69 6e 74 73 al} -constraints
05d0: 20 7b 6e 65 77 5f 61 70 69 7d 20 2d 62 6f 64 79 {new_api} -body
05e0: 20 7b 0a 09 62 61 64 73 73 6c 20 63 61 70 74 69 {..badssl capti
05f0: 76 65 2d 70 6f 72 74 61 6c 2e 62 61 64 73 73 6c ve-portal.badssl
0600: 2e 63 6f 6d 0a 20 20 20 20 7d 20 2d 72 65 73 75 .com. } -resu
0610: 6c 74 20 7b 68 61 6e 64 73 68 61 6b 65 20 66 61 lt {handshake fa
0620: 69 6c 65 64 3a 20 63 65 72 74 69 66 69 63 61 74 iled: certificat
0630: 65 20 76 65 72 69 66 79 20 66 61 69 6c 65 64 20 e verify failed
0640: 64 75 65 20 74 6f 20 22 68 6f 73 74 6e 61 6d 65 due to "hostname
0650: 20 6d 69 73 6d 61 74 63 68 22 7d 20 2d 72 65 74 mismatch"} -ret
0660: 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 urnCodes {1}..te
0670: 73 74 20 42 61 64 53 53 4c 2d 31 2e 36 20 7b 63 st BadSSL-1.6 {c
0680: 62 63 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 bc} -body {..bad
0690: 73 73 6c 20 63 62 63 2e 62 61 64 73 73 6c 2e 63 ssl cbc.badssl.c
06a0: 6f 6d 0a 20 20 20 20 7d 0a 0a 74 65 73 74 20 42 om. }..test B
06b0: 61 64 53 53 4c 2d 31 2e 37 20 7b 63 6c 69 65 6e adSSL-1.7 {clien
06c0: 74 2d 63 65 72 74 2d 6d 69 73 73 69 6e 67 7d 20 t-cert-missing}
06d0: 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 -body {..badssl
06e0: 63 6c 69 65 6e 74 2d 63 65 72 74 2d 6d 69 73 73 client-cert-miss
06f0: 69 6e 67 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 ing.badssl.com.
0700: 20 20 20 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 }..test BadSS
0710: 4c 2d 31 2e 38 20 7b 63 6c 69 65 6e 74 7d 20 2d L-1.8 {client} -
0720: 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 63 body {..badssl c
0730: 6c 69 65 6e 74 2e 62 61 64 73 73 6c 2e 63 6f 6d lient.badssl.com
0740: 0a 20 20 20 20 7d 0a 0a 74 65 73 74 20 42 61 64 . }..test Bad
0750: 53 53 4c 2d 31 2e 39 20 7b 64 68 2d 63 6f 6d 70 SSL-1.9 {dh-comp
0760: 6f 73 69 74 65 7d 20 2d 63 6f 6e 73 74 72 61 69 osite} -constrai
0770: 6e 74 73 20 7b 6f 6c 64 5f 61 70 69 7d 20 2d 62 nts {old_api} -b
0780: 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 64 68 ody {..badssl dh
0790: 2d 63 6f 6d 70 6f 73 69 74 65 2e 62 61 64 73 73 -composite.badss
07a0: 6c 2e 63 6f 6d 0a 20 20 20 20 7d 0a 0a 74 65 73 l.com. }..tes
07b0: 74 20 42 61 64 53 53 4c 2d 31 2e 31 30 20 7b 64 t BadSSL-1.10 {d
07c0: 68 2d 63 6f 6d 70 6f 73 69 74 65 7d 20 2d 63 6f h-composite} -co
07d0: 6e 73 74 72 61 69 6e 74 73 20 7b 6e 65 77 5f 61 nstraints {new_a
07e0: 70 69 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 pi} -body {..bad
07f0: 73 73 6c 20 64 68 2d 63 6f 6d 70 6f 73 69 74 65 ssl dh-composite
0800: 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 .badssl.com.
0810: 7d 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 } -result {hands
0820: 68 61 6b 65 20 66 61 69 6c 65 64 3a 20 64 68 20 hake failed: dh
0830: 6b 65 79 20 74 6f 6f 20 73 6d 61 6c 6c 7d 20 2d key too small} -
0840: 72 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a returnCodes {1}.
0850: 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 31 .test BadSSL-1.1
0860: 31 20 7b 64 68 2d 73 6d 61 6c 6c 2d 73 75 62 67 1 {dh-small-subg
0870: 72 6f 75 70 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 roup} -body {..b
0880: 61 64 73 73 6c 20 64 68 2d 73 6d 61 6c 6c 2d 73 adssl dh-small-s
0890: 75 62 67 72 6f 75 70 2e 62 61 64 73 73 6c 2e 63 ubgroup.badssl.c
08a0: 6f 6d 0a 20 20 20 20 7d 0a 0a 74 65 73 74 20 42 om. }..test B
08b0: 61 64 53 53 4c 2d 31 2e 31 32 20 7b 64 68 34 38 adSSL-1.12 {dh48
08c0: 30 7d 20 2d 63 6f 6e 73 74 72 61 69 6e 74 73 20 0} -constraints
08d0: 7b 6f 6c 64 5f 61 70 69 7d 20 2d 62 6f 64 79 20 {old_api} -body
08e0: 7b 0a 09 62 61 64 73 73 6c 20 64 68 34 38 30 2e {..badssl dh480.
08f0: 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d badssl.com. }
0900: 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 -result {handsh
0910: 61 6b 65 20 66 61 69 6c 65 64 3a 20 64 68 20 6b ake failed: dh k
0920: 65 79 20 74 6f 6f 20 73 6d 61 6c 6c 7d 20 2d 72 ey too small} -r
0930: 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a eturnCodes {1}..
0940: 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 31 33 test BadSSL-1.13
0950: 20 7b 64 68 34 38 30 7d 20 2d 63 6f 6e 73 74 72 {dh480} -constr
0960: 61 69 6e 74 73 20 7b 6e 65 77 5f 61 70 69 7d 20 aints {new_api}
0970: 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 -body {..badssl
0980: 64 68 34 38 30 2e 62 61 64 73 73 6c 2e 63 6f 6d dh480.badssl.com
0990: 0a 20 20 20 20 7d 20 2d 72 65 73 75 6c 74 20 7b . } -result {
09a0: 68 61 6e 64 73 68 61 6b 65 20 66 61 69 6c 65 64 handshake failed
09b0: 3a 20 6d 6f 64 75 6c 75 73 20 74 6f 6f 20 73 6d : modulus too sm
09c0: 61 6c 6c 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 all} -returnCode
09d0: 73 20 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 s {1}..test BadS
09e0: 53 4c 2d 31 2e 31 34 20 7b 64 68 35 31 32 7d 20 SL-1.14 {dh512}
09f0: 2d 63 6f 6e 73 74 72 61 69 6e 74 73 20 7b 6f 6c -constraints {ol
0a00: 64 5f 61 70 69 7d 20 2d 62 6f 64 79 20 7b 0a 09 d_api} -body {..
0a10: 62 61 64 73 73 6c 20 64 68 35 31 32 2e 62 61 64 badssl dh512.bad
0a20: 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 2d 72 ssl.com. } -r
0a30: 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 6b 65 esult {handshake
0a40: 20 66 61 69 6c 65 64 3a 20 64 68 20 6b 65 79 20 failed: dh key
0a50: 74 6f 6f 20 73 6d 61 6c 6c 7d 20 2d 72 65 74 75 too small} -retu
0a60: 72 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 73 rnCodes {1}..tes
0a70: 74 20 42 61 64 53 53 4c 2d 31 2e 31 35 20 7b 64 t BadSSL-1.15 {d
0a80: 68 35 31 32 7d 20 2d 63 6f 6e 73 74 72 61 69 6e h512} -constrain
0a90: 74 73 20 7b 6d 61 63 7d 20 2d 62 6f 64 79 20 7b ts {mac} -body {
0aa0: 0a 09 62 61 64 73 73 6c 20 64 68 35 31 32 2e 62 ..badssl dh512.b
0ab0: 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 adssl.com. }
0ac0: 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 -result {handsha
0ad0: 6b 65 20 66 61 69 6c 65 64 3a 20 75 6e 6b 6e 6f ke failed: unkno
0ae0: 77 6e 20 73 65 63 75 72 69 74 79 20 62 69 74 73 wn security bits
0af0: 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 7b } -returnCodes {
0b00: 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 1}..test BadSSL-
0b10: 31 2e 31 36 20 7b 64 68 31 30 32 34 7d 20 2d 63 1.16 {dh1024} -c
0b20: 6f 6e 73 74 72 61 69 6e 74 73 20 7b 6f 6c 64 5f onstraints {old_
0b30: 61 70 69 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 api} -body {..ba
0b40: 64 73 73 6c 20 64 68 31 30 32 34 2e 62 61 64 73 dssl dh1024.bads
0b50: 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 0a 0a 74 65 sl.com. }..te
0b60: 73 74 20 42 61 64 53 53 4c 2d 31 2e 31 37 20 7b st BadSSL-1.17 {
0b70: 64 68 31 30 32 34 7d 20 2d 63 6f 6e 73 74 72 61 dh1024} -constra
0b80: 69 6e 74 73 20 7b 6e 65 77 5f 61 70 69 7d 20 2d ints {new_api} -
0b90: 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 64 body {..badssl d
0ba0: 68 31 30 32 34 2e 62 61 64 73 73 6c 2e 63 6f 6d h1024.badssl.com
0bb0: 0a 20 20 20 20 7d 20 2d 72 65 73 75 6c 74 20 7b . } -result {
0bc0: 68 61 6e 64 73 68 61 6b 65 20 66 61 69 6c 65 64 handshake failed
0bd0: 3a 20 64 68 20 6b 65 79 20 74 6f 6f 20 73 6d 61 : dh key too sma
0be0: 6c 6c 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 ll} -returnCodes
0bf0: 20 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 {1}..test BadSS
0c00: 4c 2d 31 2e 31 38 20 7b 64 68 32 30 34 38 7d 20 L-1.18 {dh2048}
0c10: 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 -body {..badssl
0c20: 64 68 32 30 34 38 2e 62 61 64 73 73 6c 2e 63 6f dh2048.badssl.co
0c30: 6d 0a 20 20 20 20 7d 0a 0a 74 65 73 74 20 42 61 m. }..test Ba
0c40: 64 53 53 4c 2d 31 2e 31 39 20 7b 64 73 64 74 65 dSSL-1.19 {dsdte
0c50: 73 74 70 72 6f 76 69 64 65 72 7d 20 2d 62 6f 64 stprovider} -bod
0c60: 79 20 7b 0a 09 62 61 64 73 73 6c 20 64 73 64 74 y {..badssl dsdt
0c70: 65 73 74 70 72 6f 76 69 64 65 72 2e 62 61 64 73 estprovider.bads
0c80: 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 2d 72 65 sl.com. } -re
0c90: 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 6b 65 20 sult {handshake
0ca0: 66 61 69 6c 65 64 3a 20 63 65 72 74 69 66 69 63 failed: certific
0cb0: 61 74 65 20 76 65 72 69 66 79 20 66 61 69 6c 65 ate verify faile
0cc0: 64 20 64 75 65 20 74 6f 20 22 75 6e 61 62 6c 65 d due to "unable
0cd0: 20 74 6f 20 67 65 74 20 6c 6f 63 61 6c 20 69 73 to get local is
0ce0: 73 75 65 72 20 63 65 72 74 69 66 69 63 61 74 65 suer certificate
0cf0: 22 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 "} -returnCodes
0d00: 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c {1}..test BadSSL
0d10: 2d 31 2e 32 30 20 7b 65 63 63 32 35 36 7d 20 2d -1.20 {ecc256} -
0d20: 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 65 body {..badssl e
0d30: 63 63 32 35 36 2e 62 61 64 73 73 6c 2e 63 6f 6d cc256.badssl.com
0d40: 0a 20 20 20 20 7d 0a 0a 74 65 73 74 20 42 61 64 . }..test Bad
0d50: 53 53 4c 2d 31 2e 32 31 20 7b 65 63 63 33 38 34 SSL-1.21 {ecc384
0d60: 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 } -body {..badss
0d70: 6c 20 65 63 63 33 38 34 2e 62 61 64 73 73 6c 2e l ecc384.badssl.
0d80: 63 6f 6d 0a 20 20 20 20 7d 0a 0a 74 65 73 74 20 com. }..test
0d90: 42 61 64 53 53 4c 2d 31 2e 32 32 20 7b 65 64 65 BadSSL-1.22 {ede
0da0: 6c 6c 72 6f 6f 74 7d 20 2d 62 6f 64 79 20 7b 0a llroot} -body {.
0db0: 09 62 61 64 73 73 6c 20 65 64 65 6c 6c 72 6f 6f .badssl edellroo
0dc0: 74 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 t.badssl.com.
0dd0: 20 7d 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 } -result {hand
0de0: 73 68 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 shake failed: ce
0df0: 72 74 69 66 69 63 61 74 65 20 76 65 72 69 66 79 rtificate verify
0e00: 20 66 61 69 6c 65 64 20 64 75 65 20 74 6f 20 22 failed due to "
0e10: 75 6e 61 62 6c 65 20 74 6f 20 67 65 74 20 6c 6f unable to get lo
0e20: 63 61 6c 20 69 73 73 75 65 72 20 63 65 72 74 69 cal issuer certi
0e30: 66 69 63 61 74 65 22 7d 20 2d 72 65 74 75 72 6e ficate"} -return
0e40: 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 73 74 20 Codes {1}..test
0e50: 42 61 64 53 53 4c 2d 31 2e 32 33 20 7b 65 78 70 BadSSL-1.23 {exp
0e60: 69 72 65 64 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 ired} -body {..b
0e70: 61 64 73 73 6c 20 65 78 70 69 72 65 64 2e 62 61 adssl expired.ba
0e80: 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 2d dssl.com. } -
0e90: 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 6b result {handshak
0ea0: 65 20 66 61 69 6c 65 64 3a 20 63 65 72 74 69 66 e failed: certif
0eb0: 69 63 61 74 65 20 76 65 72 69 66 79 20 66 61 69 icate verify fai
0ec0: 6c 65 64 20 64 75 65 20 74 6f 20 22 63 65 72 74 led due to "cert
0ed0: 69 66 69 63 61 74 65 20 68 61 73 20 65 78 70 69 ificate has expi
0ee0: 72 65 64 22 7d 20 2d 72 65 74 75 72 6e 43 6f 64 red"} -returnCod
0ef0: 65 73 20 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 es {1}..test Bad
0f00: 53 53 4c 2d 31 2e 32 34 20 7b 65 78 74 65 6e 64 SSL-1.24 {extend
0f10: 65 64 2d 76 61 6c 69 64 61 74 69 6f 6e 7d 20 2d ed-validation} -
0f20: 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 65 body {..badssl e
0f30: 78 74 65 6e 64 65 64 2d 76 61 6c 69 64 61 74 69 xtended-validati
0f40: 6f 6e 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 on.badssl.com.
0f50: 20 20 7d 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e } -result {han
0f60: 64 73 68 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 dshake failed: c
0f70: 65 72 74 69 66 69 63 61 74 65 20 76 65 72 69 66 ertificate verif
0f80: 79 20 66 61 69 6c 65 64 20 64 75 65 20 74 6f 20 y failed due to
0f90: 22 63 65 72 74 69 66 69 63 61 74 65 20 68 61 73 "certificate has
0fa0: 20 65 78 70 69 72 65 64 22 7d 20 2d 72 65 74 75 expired"} -retu
0fb0: 72 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 73 rnCodes {1}..tes
0fc0: 74 20 42 61 64 53 53 4c 2d 31 2e 32 35 20 7b 68 t BadSSL-1.25 {h
0fd0: 73 74 73 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 sts} -body {..ba
0fe0: 64 73 73 6c 20 68 73 74 73 2e 62 61 64 73 73 6c dssl hsts.badssl
0ff0: 2e 63 6f 6d 0a 20 20 20 20 7d 0a 0a 74 65 73 74 .com. }..test
1000: 20 42 61 64 53 53 4c 2d 31 2e 32 36 20 7b 68 74 BadSSL-1.26 {ht
1010: 74 70 73 2d 65 76 65 72 79 77 68 65 72 65 7d 20 tps-everywhere}
1020: 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 -body {..badssl
1030: 68 74 74 70 73 2d 65 76 65 72 79 77 68 65 72 65 https-everywhere
1040: 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 .badssl.com.
1050: 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 }..test BadSSL-1
1060: 2e 32 37 20 7b 69 6e 63 6f 6d 70 6c 65 74 65 2d .27 {incomplete-
1070: 63 68 61 69 6e 7d 20 2d 62 6f 64 79 20 7b 0a 09 chain} -body {..
1080: 62 61 64 73 73 6c 20 69 6e 63 6f 6d 70 6c 65 74 badssl incomplet
1090: 65 2d 63 68 61 69 6e 2e 62 61 64 73 73 6c 2e 63 e-chain.badssl.c
10a0: 6f 6d 0a 20 20 20 20 7d 20 2d 72 65 73 75 6c 74 om. } -result
10b0: 20 7b 68 61 6e 64 73 68 61 6b 65 20 66 61 69 6c {handshake fail
10c0: 65 64 3a 20 63 65 72 74 69 66 69 63 61 74 65 20 ed: certificate
10d0: 76 65 72 69 66 79 20 66 61 69 6c 65 64 20 64 75 verify failed du
10e0: 65 20 74 6f 20 22 75 6e 61 62 6c 65 20 74 6f 20 e to "unable to
10f0: 67 65 74 20 6c 6f 63 61 6c 20 69 73 73 75 65 72 get local issuer
1100: 20 63 65 72 74 69 66 69 63 61 74 65 22 7d 20 2d certificate"} -
1110: 72 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a returnCodes {1}.
1120: 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 32 .test BadSSL-1.2
1130: 38 20 7b 69 6e 76 61 6c 69 64 2d 65 78 70 65 63 8 {invalid-expec
1140: 74 65 64 2d 73 63 74 7d 20 2d 62 6f 64 79 20 7b ted-sct} -body {
1150: 0a 09 62 61 64 73 73 6c 20 69 6e 76 61 6c 69 64 ..badssl invalid
1160: 2d 65 78 70 65 63 74 65 64 2d 73 63 74 2e 62 61 -expected-sct.ba
1170: 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 2d dssl.com. } -
1180: 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 6b result {handshak
1190: 65 20 66 61 69 6c 65 64 3a 20 63 65 72 74 69 66 e failed: certif
11a0: 69 63 61 74 65 20 76 65 72 69 66 79 20 66 61 69 icate verify fai
11b0: 6c 65 64 20 64 75 65 20 74 6f 20 22 75 6e 61 62 led due to "unab
11c0: 6c 65 20 74 6f 20 67 65 74 20 6c 6f 63 61 6c 20 le to get local
11d0: 69 73 73 75 65 72 20 63 65 72 74 69 66 69 63 61 issuer certifica
11e0: 74 65 22 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 te"} -returnCode
11f0: 73 20 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 s {1}..test BadS
1200: 53 4c 2d 31 2e 32 39 20 7b 6c 6f 6e 67 2d 65 78 SL-1.29 {long-ex
1210: 74 65 6e 64 65 64 2d 73 75 62 64 6f 6d 61 69 6e tended-subdomain
1220: 2d 6e 61 6d 65 2d 63 6f 6e 74 61 69 6e 69 6e 67 -name-containing
1230: 2d 6d 61 6e 79 2d 6c 65 74 74 65 72 73 2d 61 6e -many-letters-an
1240: 64 2d 64 61 73 68 65 73 7d 20 2d 62 6f 64 79 20 d-dashes} -body
1250: 7b 0a 09 62 61 64 73 73 6c 20 6c 6f 6e 67 2d 65 {..badssl long-e
1260: 78 74 65 6e 64 65 64 2d 73 75 62 64 6f 6d 61 69 xtended-subdomai
1270: 6e 2d 6e 61 6d 65 2d 63 6f 6e 74 61 69 6e 69 6e n-name-containin
1280: 67 2d 6d 61 6e 79 2d 6c 65 74 74 65 72 73 2d 61 g-many-letters-a
1290: 6e 64 2d 64 61 73 68 65 73 2e 62 61 64 73 73 6c nd-dashes.badssl
12a0: 2e 63 6f 6d 0a 20 20 20 20 7d 0a 0a 74 65 73 74 .com. }..test
12b0: 20 42 61 64 53 53 4c 2d 31 2e 33 30 20 7b 6c 6f BadSSL-1.30 {lo
12c0: 6e 67 65 78 74 65 6e 64 65 64 73 75 62 64 6f 6d ngextendedsubdom
12d0: 61 69 6e 6e 61 6d 65 77 69 74 68 6f 75 74 64 61 ainnamewithoutda
12e0: 73 68 65 73 69 6e 6f 72 64 65 72 74 6f 74 65 73 shesinordertotes
12f0: 74 77 6f 72 64 77 72 61 70 70 69 6e 67 7d 20 2d twordwrapping} -
1300: 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 6c body {..badssl l
1310: 6f 6e 67 65 78 74 65 6e 64 65 64 73 75 62 64 6f ongextendedsubdo
1320: 6d 61 69 6e 6e 61 6d 65 77 69 74 68 6f 75 74 64 mainnamewithoutd
1330: 61 73 68 65 73 69 6e 6f 72 64 65 72 74 6f 74 65 ashesinordertote
1340: 73 74 77 6f 72 64 77 72 61 70 70 69 6e 67 2e 62 stwordwrapping.b
1350: 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 0a adssl.com. }.
1360: 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 33 .test BadSSL-1.3
1370: 31 20 7b 6d 69 74 6d 2d 73 6f 66 74 77 61 72 65 1 {mitm-software
1380: 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 } -body {..badss
1390: 6c 20 6d 69 74 6d 2d 73 6f 66 74 77 61 72 65 2e l mitm-software.
13a0: 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d badssl.com. }
13b0: 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 -result {handsh
13c0: 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 72 74 ake failed: cert
13d0: 69 66 69 63 61 74 65 20 76 65 72 69 66 79 20 66 ificate verify f
13e0: 61 69 6c 65 64 20 64 75 65 20 74 6f 20 22 75 6e ailed due to "un
13f0: 61 62 6c 65 20 74 6f 20 67 65 74 20 6c 6f 63 61 able to get loca
1400: 6c 20 69 73 73 75 65 72 20 63 65 72 74 69 66 69 l issuer certifi
1410: 63 61 74 65 22 7d 20 2d 72 65 74 75 72 6e 43 6f cate"} -returnCo
1420: 64 65 73 20 7b 31 7d 0a 0a 74 65 73 74 20 42 61 des {1}..test Ba
1430: 64 53 53 4c 2d 31 2e 33 32 20 7b 6e 6f 2d 63 6f dSSL-1.32 {no-co
1440: 6d 6d 6f 6e 2d 6e 61 6d 65 7d 20 2d 62 6f 64 79 mmon-name} -body
1450: 20 7b 0a 09 62 61 64 73 73 6c 20 6e 6f 2d 63 6f {..badssl no-co
1460: 6d 6d 6f 6e 2d 6e 61 6d 65 2e 62 61 64 73 73 6c mmon-name.badssl
1470: 2e 63 6f 6d 0a 20 20 20 20 7d 20 2d 72 65 73 75 .com. } -resu
1480: 6c 74 20 7b 68 61 6e 64 73 68 61 6b 65 20 66 61 lt {handshake fa
1490: 69 6c 65 64 3a 20 63 65 72 74 69 66 69 63 61 74 iled: certificat
14a0: 65 20 76 65 72 69 66 79 20 66 61 69 6c 65 64 20 e verify failed
14b0: 64 75 65 20 74 6f 20 22 63 65 72 74 69 66 69 63 due to "certific
14c0: 61 74 65 20 68 61 73 20 65 78 70 69 72 65 64 22 ate has expired"
14d0: 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 7b } -returnCodes {
14e0: 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 1}..test BadSSL-
14f0: 31 2e 33 33 20 7b 6e 6f 2d 73 63 74 7d 20 2d 62 1.33 {no-sct} -b
1500: 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 6e 6f ody {..badssl no
1510: 2d 73 63 74 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a -sct.badssl.com.
1520: 20 20 20 20 7d 0a 0a 74 65 73 74 20 42 61 64 53 }..test BadS
1530: 53 4c 2d 31 2e 33 34 20 7b 6e 6f 2d 73 75 62 6a SL-1.34 {no-subj
1540: 65 63 74 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 ect} -body {..ba
1550: 64 73 73 6c 20 6e 6f 2d 73 75 62 6a 65 63 74 2e dssl no-subject.
1560: 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d badssl.com. }
1570: 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 -result {handsh
1580: 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 72 74 ake failed: cert
1590: 69 66 69 63 61 74 65 20 76 65 72 69 66 79 20 66 ificate verify f
15a0: 61 69 6c 65 64 20 64 75 65 20 74 6f 20 22 63 65 ailed due to "ce
15b0: 72 74 69 66 69 63 61 74 65 20 68 61 73 20 65 78 rtificate has ex
15c0: 70 69 72 65 64 22 7d 20 2d 72 65 74 75 72 6e 43 pired"} -returnC
15d0: 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 73 74 20 42 odes {1}..test B
15e0: 61 64 53 53 4c 2d 31 2e 33 35 20 7b 6e 75 6c 6c adSSL-1.35 {null
15f0: 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 } -body {..badss
1600: 6c 20 6e 75 6c 6c 2e 62 61 64 73 73 6c 2e 63 6f l null.badssl.co
1610: 6d 0a 20 20 20 20 7d 20 2d 6d 61 74 63 68 20 7b m. } -match {
1620: 67 6c 6f 62 7d 20 2d 72 65 73 75 6c 74 20 7b 68 glob} -result {h
1630: 61 6e 64 73 68 61 6b 65 20 66 61 69 6c 65 64 3a andshake failed:
1640: 20 2a 20 61 6c 65 72 74 20 68 61 6e 64 73 68 61 * alert handsha
1650: 6b 65 20 66 61 69 6c 75 72 65 7d 20 2d 72 65 74 ke failure} -ret
1660: 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 urnCodes {1}..te
1670: 73 74 20 42 61 64 53 53 4c 2d 31 2e 33 36 20 7b st BadSSL-1.36 {
1680: 70 69 6e 6e 69 6e 67 2d 74 65 73 74 7d 20 2d 62 pinning-test} -b
1690: 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 70 69 ody {..badssl pi
16a0: 6e 6e 69 6e 67 2d 74 65 73 74 2e 62 61 64 73 73 nning-test.badss
16b0: 6c 2e 63 6f 6d 0a 20 20 20 20 7d 0a 0a 74 65 73 l.com. }..tes
16c0: 74 20 42 61 64 53 53 4c 2d 31 2e 33 37 20 7b 70 t BadSSL-1.37 {p
16d0: 72 65 61 63 74 2d 63 6c 69 7d 20 2d 62 6f 64 79 react-cli} -body
16e0: 20 7b 0a 09 62 61 64 73 73 6c 20 70 72 65 61 63 {..badssl preac
16f0: 74 2d 63 6c 69 2e 62 61 64 73 73 6c 2e 63 6f 6d t-cli.badssl.com
1700: 0a 20 20 20 20 7d 20 2d 72 65 73 75 6c 74 20 7b . } -result {
1710: 68 61 6e 64 73 68 61 6b 65 20 66 61 69 6c 65 64 handshake failed
1720: 3a 20 63 65 72 74 69 66 69 63 61 74 65 20 76 65 : certificate ve
1730: 72 69 66 79 20 66 61 69 6c 65 64 20 64 75 65 20 rify failed due
1740: 74 6f 20 22 75 6e 61 62 6c 65 20 74 6f 20 67 65 to "unable to ge
1750: 74 20 6c 6f 63 61 6c 20 69 73 73 75 65 72 20 63 t local issuer c
1760: 65 72 74 69 66 69 63 61 74 65 22 7d 20 2d 72 65 ertificate"} -re
1770: 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 turnCodes {1}..t
1780: 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 33 38 20 est BadSSL-1.38
1790: 7b 70 72 65 6c 6f 61 64 65 64 2d 68 73 74 73 7d {preloaded-hsts}
17a0: 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c -body {..badssl
17b0: 20 70 72 65 6c 6f 61 64 65 64 2d 68 73 74 73 2e preloaded-hsts.
17c0: 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d badssl.com. }
17d0: 0a 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e ..test BadSSL-1.
17e0: 33 39 20 7b 72 63 34 2d 6d 64 35 7d 20 2d 62 6f 39 {rc4-md5} -bo
17f0: 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 72 63 34 dy {..badssl rc4
1800: 2d 6d 64 35 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a -md5.badssl.com.
1810: 20 20 20 20 7d 20 2d 6d 61 74 63 68 20 7b 67 6c } -match {gl
1820: 6f 62 7d 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e ob} -result {han
1830: 64 73 68 61 6b 65 20 66 61 69 6c 65 64 3a 20 2a dshake failed: *
1840: 20 61 6c 65 72 74 20 68 61 6e 64 73 68 61 6b 65 alert handshake
1850: 20 66 61 69 6c 75 72 65 7d 20 2d 72 65 74 75 72 failure} -retur
1860: 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 73 74 nCodes {1}..test
1870: 20 42 61 64 53 53 4c 2d 31 2e 34 30 20 7b 72 63 BadSSL-1.40 {rc
1880: 34 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 4} -body {..bads
1890: 73 6c 20 72 63 34 2e 62 61 64 73 73 6c 2e 63 6f sl rc4.badssl.co
18a0: 6d 0a 20 20 20 20 7d 20 2d 6d 61 74 63 68 20 7b m. } -match {
18b0: 67 6c 6f 62 7d 20 2d 72 65 73 75 6c 74 20 7b 68 glob} -result {h
18c0: 61 6e 64 73 68 61 6b 65 20 66 61 69 6c 65 64 3a andshake failed:
18d0: 20 2a 20 61 6c 65 72 74 20 68 61 6e 64 73 68 61 * alert handsha
18e0: 6b 65 20 66 61 69 6c 75 72 65 7d 20 2d 72 65 74 ke failure} -ret
18f0: 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 urnCodes {1}..te
1900: 73 74 20 42 61 64 53 53 4c 2d 31 2e 34 31 20 7b st BadSSL-1.41 {
1910: 72 65 76 6f 6b 65 64 7d 20 2d 62 6f 64 79 20 7b revoked} -body {
1920: 0a 09 62 61 64 73 73 6c 20 72 65 76 6f 6b 65 64 ..badssl revoked
1930: 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 .badssl.com.
1940: 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 }..test BadSSL-1
1950: 2e 34 32 20 7b 72 73 61 32 30 34 38 7d 20 2d 62 .42 {rsa2048} -b
1960: 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 72 73 ody {..badssl rs
1970: 61 32 30 34 38 2e 62 61 64 73 73 6c 2e 63 6f 6d a2048.badssl.com
1980: 0a 20 20 20 20 7d 0a 0a 74 65 73 74 20 42 61 64 . }..test Bad
1990: 53 53 4c 2d 31 2e 34 33 20 7b 72 73 61 34 30 39 SSL-1.43 {rsa409
19a0: 36 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 6} -body {..bads
19b0: 73 6c 20 72 73 61 34 30 39 36 2e 62 61 64 73 73 sl rsa4096.badss
19c0: 6c 2e 63 6f 6d 0a 20 20 20 20 7d 0a 0a 74 65 73 l.com. }..tes
19d0: 74 20 42 61 64 53 53 4c 2d 31 2e 34 34 20 7b 72 t BadSSL-1.44 {r
19e0: 73 61 38 31 39 32 7d 20 2d 62 6f 64 79 20 7b 0a sa8192} -body {.
19f0: 09 62 61 64 73 73 6c 20 72 73 61 38 31 39 32 2e .badssl rsa8192.
1a00: 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d badssl.com. }
1a10: 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 -result {handsh
1a20: 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 72 74 ake failed: cert
1a30: 69 66 69 63 61 74 65 20 76 65 72 69 66 79 20 66 ificate verify f
1a40: 61 69 6c 65 64 20 64 75 65 20 74 6f 20 22 63 65 ailed due to "ce
1a50: 72 74 69 66 69 63 61 74 65 20 68 61 73 20 65 78 rtificate has ex
1a60: 70 69 72 65 64 22 7d 20 2d 72 65 74 75 72 6e 43 pired"} -returnC
1a70: 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 73 74 20 42 odes {1}..test B
1a80: 61 64 53 53 4c 2d 31 2e 34 35 20 7b 73 65 6c 66 adSSL-1.45 {self
1a90: 2d 73 69 67 6e 65 64 7d 20 2d 63 6f 6e 73 74 72 -signed} -constr
1aa0: 61 69 6e 74 73 20 7b 6f 6c 64 5f 61 70 69 7d 20 aints {old_api}
1ab0: 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 -body {..badssl
1ac0: 73 65 6c 66 2d 73 69 67 6e 65 64 2e 62 61 64 73 self-signed.bads
1ad0: 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 2d 72 65 sl.com. } -re
1ae0: 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 6b 65 20 sult {handshake
1af0: 66 61 69 6c 65 64 3a 20 63 65 72 74 69 66 69 63 failed: certific
1b00: 61 74 65 20 76 65 72 69 66 79 20 66 61 69 6c 65 ate verify faile
1b10: 64 20 64 75 65 20 74 6f 20 22 73 65 6c 66 20 73 d due to "self s
1b20: 69 67 6e 65 64 20 63 65 72 74 69 66 69 63 61 74 igned certificat
1b30: 65 22 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 e"} -returnCodes
1b40: 20 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 {1}..test BadSS
1b50: 4c 2d 31 2e 34 36 20 7b 73 65 6c 66 2d 73 69 67 L-1.46 {self-sig
1b60: 6e 65 64 7d 20 2d 63 6f 6e 73 74 72 61 69 6e 74 ned} -constraint
1b70: 73 20 7b 6e 65 77 5f 61 70 69 7d 20 2d 62 6f 64 s {new_api} -bod
1b80: 79 20 7b 0a 09 62 61 64 73 73 6c 20 73 65 6c 66 y {..badssl self
1b90: 2d 73 69 67 6e 65 64 2e 62 61 64 73 73 6c 2e 63 -signed.badssl.c
1ba0: 6f 6d 0a 20 20 20 20 7d 20 2d 72 65 73 75 6c 74 om. } -result
1bb0: 20 7b 68 61 6e 64 73 68 61 6b 65 20 66 61 69 6c {handshake fail
1bc0: 65 64 3a 20 63 65 72 74 69 66 69 63 61 74 65 20 ed: certificate
1bd0: 76 65 72 69 66 79 20 66 61 69 6c 65 64 20 64 75 verify failed du
1be0: 65 20 74 6f 20 22 73 65 6c 66 2d 73 69 67 6e 65 e to "self-signe
1bf0: 64 20 63 65 72 74 69 66 69 63 61 74 65 22 7d 20 d certificate"}
1c00: 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d -returnCodes {1}
1c10: 0a 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e ..test BadSSL-1.
1c20: 34 37 20 7b 73 68 61 31 2d 32 30 31 36 7d 20 2d 47 {sha1-2016} -
1c30: 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 73 body {..badssl s
1c40: 68 61 31 2d 32 30 31 36 2e 62 61 64 73 73 6c 2e ha1-2016.badssl.
1c50: 63 6f 6d 0a 20 20 20 20 7d 20 2d 72 65 73 75 6c com. } -resul
1c60: 74 20 7b 68 61 6e 64 73 68 61 6b 65 20 66 61 69 t {handshake fai
1c70: 6c 65 64 3a 20 63 65 72 74 69 66 69 63 61 74 65 led: certificate
1c80: 20 76 65 72 69 66 79 20 66 61 69 6c 65 64 20 64 verify failed d
1c90: 75 65 20 74 6f 20 22 75 6e 61 62 6c 65 20 74 6f ue to "unable to
1ca0: 20 67 65 74 20 6c 6f 63 61 6c 20 69 73 73 75 65 get local issue
1cb0: 72 20 63 65 72 74 69 66 69 63 61 74 65 22 7d 20 r certificate"}
1cc0: 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d -returnCodes {1}
1cd0: 0a 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e ..test BadSSL-1.
1ce0: 34 38 20 7b 73 68 61 31 2d 32 30 31 37 7d 20 2d 48 {sha1-2017} -
1cf0: 63 6f 6e 73 74 72 61 69 6e 74 73 20 7b 6f 6c 64 constraints {old
1d00: 5f 61 70 69 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 _api} -body {..b
1d10: 61 64 73 73 6c 20 73 68 61 31 2d 32 30 31 37 2e adssl sha1-2017.
1d20: 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d badssl.com. }
1d30: 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 -result {handsh
1d40: 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 72 74 ake failed: cert
1d50: 69 66 69 63 61 74 65 20 76 65 72 69 66 79 20 66 ificate verify f
1d60: 61 69 6c 65 64 20 64 75 65 20 74 6f 20 22 63 65 ailed due to "ce
1d70: 72 74 69 66 69 63 61 74 65 20 68 61 73 20 65 78 rtificate has ex
1d80: 70 69 72 65 64 22 7d 20 2d 72 65 74 75 72 6e 43 pired"} -returnC
1d90: 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 73 74 20 42 odes {1}..test B
1da0: 61 64 53 53 4c 2d 31 2e 34 39 20 7b 73 68 61 31 adSSL-1.49 {sha1
1db0: 2d 32 30 31 37 7d 20 2d 63 6f 6e 73 74 72 61 69 -2017} -constrai
1dc0: 6e 74 73 20 7b 6e 65 77 5f 61 70 69 7d 20 2d 62 nts {new_api} -b
1dd0: 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 73 68 ody {..badssl sh
1de0: 61 31 2d 32 30 31 37 2e 62 61 64 73 73 6c 2e 63 a1-2017.badssl.c
1df0: 6f 6d 0a 20 20 20 20 7d 20 2d 72 65 73 75 6c 74 om. } -result
1e00: 20 7b 68 61 6e 64 73 68 61 6b 65 20 66 61 69 6c {handshake fail
1e10: 65 64 3a 20 63 65 72 74 69 66 69 63 61 74 65 20 ed: certificate
1e20: 76 65 72 69 66 79 20 66 61 69 6c 65 64 20 64 75 verify failed du
1e30: 65 20 74 6f 20 22 43 41 20 73 69 67 6e 61 74 75 e to "CA signatu
1e40: 72 65 20 64 69 67 65 73 74 20 61 6c 67 6f 72 69 re digest algori
1e50: 74 68 6d 20 74 6f 6f 20 77 65 61 6b 22 7d 20 2d thm too weak"} -
1e60: 72 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a returnCodes {1}.
1e70: 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 35 .test BadSSL-1.5
1e80: 30 20 7b 73 68 61 31 2d 69 6e 74 65 72 6d 65 64 0 {sha1-intermed
1e90: 69 61 74 65 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 iate} -body {..b
1ea0: 61 64 73 73 6c 20 73 68 61 31 2d 69 6e 74 65 72 adssl sha1-inter
1eb0: 6d 65 64 69 61 74 65 2e 62 61 64 73 73 6c 2e 63 mediate.badssl.c
1ec0: 6f 6d 0a 20 20 20 20 7d 20 2d 72 65 73 75 6c 74 om. } -result
1ed0: 20 7b 68 61 6e 64 73 68 61 6b 65 20 66 61 69 6c {handshake fail
1ee0: 65 64 3a 20 63 65 72 74 69 66 69 63 61 74 65 20 ed: certificate
1ef0: 76 65 72 69 66 79 20 66 61 69 6c 65 64 20 64 75 verify failed du
1f00: 65 20 74 6f 20 22 75 6e 61 62 6c 65 20 74 6f 20 e to "unable to
1f10: 67 65 74 20 6c 6f 63 61 6c 20 69 73 73 75 65 72 get local issuer
1f20: 20 63 65 72 74 69 66 69 63 61 74 65 22 7d 20 2d certificate"} -
1f30: 72 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a returnCodes {1}.
1f40: 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 35 .test BadSSL-1.5
1f50: 31 20 7b 73 68 61 32 35 36 7d 20 2d 62 6f 64 79 1 {sha256} -body
1f60: 20 7b 0a 09 62 61 64 73 73 6c 20 73 68 61 32 35 {..badssl sha25
1f70: 36 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 6.badssl.com.
1f80: 20 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c 2d }..test BadSSL-
1f90: 31 2e 35 32 20 7b 73 68 61 33 38 34 7d 20 2d 62 1.52 {sha384} -b
1fa0: 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 73 68 ody {..badssl sh
1fb0: 61 33 38 34 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a a384.badssl.com.
1fc0: 20 20 20 20 7d 20 2d 72 65 73 75 6c 74 20 7b 68 } -result {h
1fd0: 61 6e 64 73 68 61 6b 65 20 66 61 69 6c 65 64 3a andshake failed:
1fe0: 20 63 65 72 74 69 66 69 63 61 74 65 20 76 65 72 certificate ver
1ff0: 69 66 79 20 66 61 69 6c 65 64 20 64 75 65 20 74 ify failed due t
2000: 6f 20 22 63 65 72 74 69 66 69 63 61 74 65 20 68 o "certificate h
2010: 61 73 20 65 78 70 69 72 65 64 22 7d 20 2d 72 65 as expired"} -re
2020: 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 turnCodes {1}..t
2030: 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 35 33 20 est BadSSL-1.53
2040: 7b 73 68 61 35 31 32 7d 20 2d 62 6f 64 79 20 7b {sha512} -body {
2050: 0a 09 62 61 64 73 73 6c 20 73 68 61 35 31 32 2e ..badssl sha512.
2060: 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d badssl.com. }
2070: 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 -result {handsh
2080: 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 72 74 ake failed: cert
2090: 69 66 69 63 61 74 65 20 76 65 72 69 66 79 20 66 ificate verify f
20a0: 61 69 6c 65 64 20 64 75 65 20 74 6f 20 22 63 65 ailed due to "ce
20b0: 72 74 69 66 69 63 61 74 65 20 68 61 73 20 65 78 rtificate has ex
20c0: 70 69 72 65 64 22 7d 20 2d 72 65 74 75 72 6e 43 pired"} -returnC
20d0: 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 73 74 20 42 odes {1}..test B
20e0: 61 64 53 53 4c 2d 31 2e 35 34 20 7b 73 74 61 74 adSSL-1.54 {stat
20f0: 69 63 2d 72 73 61 7d 20 2d 62 6f 64 79 20 7b 0a ic-rsa} -body {.
2100: 09 62 61 64 73 73 6c 20 73 74 61 74 69 63 2d 72 .badssl static-r
2110: 73 61 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 sa.badssl.com.
2120: 20 20 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c }..test BadSSL
2130: 2d 31 2e 35 35 20 7b 73 75 62 64 6f 6d 61 69 6e -1.55 {subdomain
2140: 2e 70 72 65 6c 6f 61 64 65 64 2d 68 73 74 73 7d .preloaded-hsts}
2150: 20 2d 63 6f 6e 73 74 72 61 69 6e 74 73 20 7b 6f -constraints {o
2160: 6c 64 5f 61 70 69 7d 20 2d 62 6f 64 79 20 7b 0a ld_api} -body {.
2170: 09 62 61 64 73 73 6c 20 73 75 62 64 6f 6d 61 69 .badssl subdomai
2180: 6e 2e 70 72 65 6c 6f 61 64 65 64 2d 68 73 74 73 n.preloaded-hsts
2190: 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 .badssl.com.
21a0: 7d 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 } -result {hands
21b0: 68 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 72 hake failed: cer
21c0: 74 69 66 69 63 61 74 65 20 76 65 72 69 66 79 20 tificate verify
21d0: 66 61 69 6c 65 64 20 64 75 65 20 74 6f 20 22 48 failed due to "H
21e0: 6f 73 74 6e 61 6d 65 20 6d 69 73 6d 61 74 63 68 ostname mismatch
21f0: 22 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 "} -returnCodes
2200: 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c {1}..test BadSSL
2210: 2d 31 2e 35 36 20 7b 73 75 62 64 6f 6d 61 69 6e -1.56 {subdomain
2220: 2e 70 72 65 6c 6f 61 64 65 64 2d 68 73 74 73 7d .preloaded-hsts}
2230: 20 2d 63 6f 6e 73 74 72 61 69 6e 74 73 20 7b 6e -constraints {n
2240: 65 77 5f 61 70 69 7d 20 2d 62 6f 64 79 20 7b 0a ew_api} -body {.
2250: 09 62 61 64 73 73 6c 20 73 75 62 64 6f 6d 61 69 .badssl subdomai
2260: 6e 2e 70 72 65 6c 6f 61 64 65 64 2d 68 73 74 73 n.preloaded-hsts
2270: 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 .badssl.com.
2280: 7d 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 } -result {hands
2290: 68 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 72 hake failed: cer
22a0: 74 69 66 69 63 61 74 65 20 76 65 72 69 66 79 20 tificate verify
22b0: 66 61 69 6c 65 64 20 64 75 65 20 74 6f 20 22 68 failed due to "h
22c0: 6f 73 74 6e 61 6d 65 20 6d 69 73 6d 61 74 63 68 ostname mismatch
22d0: 22 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 "} -returnCodes
22e0: 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c {1}..test BadSSL
22f0: 2d 31 2e 35 37 20 7b 73 75 70 65 72 66 69 73 68 -1.57 {superfish
2300: 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 } -body {..badss
2310: 6c 20 73 75 70 65 72 66 69 73 68 2e 62 61 64 73 l superfish.bads
2320: 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 2d 72 65 sl.com. } -re
2330: 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 6b 65 20 sult {handshake
2340: 66 61 69 6c 65 64 3a 20 63 65 72 74 69 66 69 63 failed: certific
2350: 61 74 65 20 76 65 72 69 66 79 20 66 61 69 6c 65 ate verify faile
2360: 64 20 64 75 65 20 74 6f 20 22 75 6e 61 62 6c 65 d due to "unable
2370: 20 74 6f 20 67 65 74 20 6c 6f 63 61 6c 20 69 73 to get local is
2380: 73 75 65 72 20 63 65 72 74 69 66 69 63 61 74 65 suer certificate
2390: 22 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 "} -returnCodes
23a0: 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c {1}..test BadSSL
23b0: 2d 31 2e 35 38 20 7b 74 6c 73 2d 76 31 2d 30 3a -1.58 {tls-v1-0:
23c0: 31 30 31 30 7d 20 2d 63 6f 6e 73 74 72 61 69 6e 1010} -constrain
23d0: 74 73 20 7b 74 6c 73 31 20 6f 6c 64 5f 61 70 69 ts {tls1 old_api
23e0: 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 } -body {..badss
23f0: 6c 20 74 6c 73 2d 76 31 2d 30 2e 62 61 64 73 73 l tls-v1-0.badss
2400: 6c 2e 63 6f 6d 3a 31 30 31 30 0a 20 20 20 20 7d l.com:1010. }
2410: 0a 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e ..test BadSSL-1.
2420: 35 39 20 7b 74 6c 73 2d 76 31 2d 30 3a 31 30 31 59 {tls-v1-0:101
2430: 30 7d 20 2d 63 6f 6e 73 74 72 61 69 6e 74 73 20 0} -constraints
2440: 7b 74 6c 73 31 20 6e 65 77 5f 61 70 69 7d 20 2d {tls1 new_api} -
2450: 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 74 body {..badssl t
2460: 6c 73 2d 76 31 2d 30 2e 62 61 64 73 73 6c 2e 63 ls-v1-0.badssl.c
2470: 6f 6d 3a 31 30 31 30 0a 20 20 20 20 7d 20 2d 72 om:1010. } -r
2480: 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 6b 65 esult {handshake
2490: 20 66 61 69 6c 65 64 3a 20 75 6e 73 75 70 70 6f failed: unsuppo
24a0: 72 74 65 64 20 70 72 6f 74 6f 63 6f 6c 7d 20 2d rted protocol} -
24b0: 72 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a returnCodes {1}.
24c0: 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 36 .test BadSSL-1.6
24d0: 30 20 7b 74 6c 73 2d 76 31 2d 31 3a 31 30 31 31 0 {tls-v1-1:1011
24e0: 7d 20 2d 63 6f 6e 73 74 72 61 69 6e 74 73 20 7b } -constraints {
24f0: 74 6c 73 31 2e 31 20 6f 6c 64 5f 61 70 69 7d 20 tls1.1 old_api}
2500: 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 -body {..badssl
2510: 74 6c 73 2d 76 31 2d 31 2e 62 61 64 73 73 6c 2e tls-v1-1.badssl.
2520: 63 6f 6d 3a 31 30 31 31 0a 20 20 20 20 7d 0a 0a com:1011. }..
2530: 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 36 31 test BadSSL-1.61
2540: 20 7b 74 6c 73 2d 76 31 2d 31 3a 31 30 31 31 7d {tls-v1-1:1011}
2550: 20 2d 63 6f 6e 73 74 72 61 69 6e 74 73 20 7b 74 -constraints {t
2560: 6c 73 31 2e 31 20 6e 65 77 5f 61 70 69 7d 20 2d ls1.1 new_api} -
2570: 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c 20 74 body {..badssl t
2580: 6c 73 2d 76 31 2d 31 2e 62 61 64 73 73 6c 2e 63 ls-v1-1.badssl.c
2590: 6f 6d 3a 31 30 31 31 0a 20 20 20 20 7d 20 2d 72 om:1011. } -r
25a0: 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 6b 65 esult {handshake
25b0: 20 66 61 69 6c 65 64 3a 20 75 6e 73 75 70 70 6f failed: unsuppo
25c0: 72 74 65 64 20 70 72 6f 74 6f 63 6f 6c 7d 20 2d rted protocol} -
25d0: 72 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a returnCodes {1}.
25e0: 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 36 .test BadSSL-1.6
25f0: 32 20 7b 74 6c 73 2d 76 31 2d 32 3a 31 30 31 32 2 {tls-v1-2:1012
2600: 7d 20 2d 63 6f 6e 73 74 72 61 69 6e 74 73 20 7b } -constraints {
2610: 74 6c 73 31 2e 32 7d 20 2d 62 6f 64 79 20 7b 0a tls1.2} -body {.
2620: 09 62 61 64 73 73 6c 20 74 6c 73 2d 76 31 2d 32 .badssl tls-v1-2
2630: 2e 62 61 64 73 73 6c 2e 63 6f 6d 3a 31 30 31 32 .badssl.com:1012
2640: 0a 20 20 20 20 7d 0a 0a 74 65 73 74 20 42 61 64 . }..test Bad
2650: 53 53 4c 2d 31 2e 36 33 20 7b 75 6e 74 72 75 73 SSL-1.63 {untrus
2660: 74 65 64 2d 72 6f 6f 74 7d 20 2d 63 6f 6e 73 74 ted-root} -const
2670: 72 61 69 6e 74 73 20 7b 6f 6c 64 5f 61 70 69 7d raints {old_api}
2680: 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c -body {..badssl
2690: 20 75 6e 74 72 75 73 74 65 64 2d 72 6f 6f 74 2e untrusted-root.
26a0: 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d badssl.com. }
26b0: 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 -result {handsh
26c0: 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 72 74 ake failed: cert
26d0: 69 66 69 63 61 74 65 20 76 65 72 69 66 79 20 66 ificate verify f
26e0: 61 69 6c 65 64 20 64 75 65 20 74 6f 20 22 73 65 ailed due to "se
26f0: 6c 66 20 73 69 67 6e 65 64 20 63 65 72 74 69 66 lf signed certif
2700: 69 63 61 74 65 20 69 6e 20 63 65 72 74 69 66 69 icate in certifi
2710: 63 61 74 65 20 63 68 61 69 6e 22 7d 20 2d 72 65 cate chain"} -re
2720: 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 turnCodes {1}..t
2730: 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 36 34 20 est BadSSL-1.64
2740: 7b 75 6e 74 72 75 73 74 65 64 2d 72 6f 6f 74 7d {untrusted-root}
2750: 20 2d 63 6f 6e 73 74 72 61 69 6e 74 73 20 7b 6e -constraints {n
2760: 65 77 5f 61 70 69 7d 20 2d 62 6f 64 79 20 7b 0a ew_api} -body {.
2770: 09 62 61 64 73 73 6c 20 75 6e 74 72 75 73 74 65 .badssl untruste
2780: 64 2d 72 6f 6f 74 2e 62 61 64 73 73 6c 2e 63 6f d-root.badssl.co
2790: 6d 0a 20 20 20 20 7d 20 2d 72 65 73 75 6c 74 20 m. } -result
27a0: 7b 68 61 6e 64 73 68 61 6b 65 20 66 61 69 6c 65 {handshake faile
27b0: 64 3a 20 63 65 72 74 69 66 69 63 61 74 65 20 76 d: certificate v
27c0: 65 72 69 66 79 20 66 61 69 6c 65 64 20 64 75 65 erify failed due
27d0: 20 74 6f 20 22 73 65 6c 66 2d 73 69 67 6e 65 64 to "self-signed
27e0: 20 63 65 72 74 69 66 69 63 61 74 65 20 69 6e 20 certificate in
27f0: 63 65 72 74 69 66 69 63 61 74 65 20 63 68 61 69 certificate chai
2800: 6e 22 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 n"} -returnCodes
2810: 20 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 {1}..test BadSS
2820: 4c 2d 31 2e 36 35 20 7b 75 70 67 72 61 64 65 7d L-1.65 {upgrade}
2830: 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c -body {..badssl
2840: 20 75 70 67 72 61 64 65 2e 62 61 64 73 73 6c 2e upgrade.badssl.
2850: 63 6f 6d 0a 20 20 20 20 7d 0a 0a 74 65 73 74 20 com. }..test
2860: 42 61 64 53 53 4c 2d 31 2e 36 36 20 7b 77 65 62 BadSSL-1.66 {web
2870: 70 61 63 6b 2d 64 65 76 2d 73 65 72 76 65 72 7d pack-dev-server}
2880: 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 6c -body {..badssl
2890: 20 77 65 62 70 61 63 6b 2d 64 65 76 2d 73 65 72 webpack-dev-ser
28a0: 76 65 72 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 ver.badssl.com.
28b0: 20 20 20 7d 20 2d 72 65 73 75 6c 74 20 7b 68 61 } -result {ha
28c0: 6e 64 73 68 61 6b 65 20 66 61 69 6c 65 64 3a 20 ndshake failed:
28d0: 63 65 72 74 69 66 69 63 61 74 65 20 76 65 72 69 certificate veri
28e0: 66 79 20 66 61 69 6c 65 64 20 64 75 65 20 74 6f fy failed due to
28f0: 20 22 75 6e 61 62 6c 65 20 74 6f 20 67 65 74 20 "unable to get
2900: 6c 6f 63 61 6c 20 69 73 73 75 65 72 20 63 65 72 local issuer cer
2910: 74 69 66 69 63 61 74 65 22 7d 20 2d 72 65 74 75 tificate"} -retu
2920: 72 6e 43 6f 64 65 73 20 7b 31 7d 0a 0a 74 65 73 rnCodes {1}..tes
2930: 74 20 42 61 64 53 53 4c 2d 31 2e 36 37 20 7b 77 t BadSSL-1.67 {w
2940: 72 6f 6e 67 2e 68 6f 73 74 7d 20 2d 63 6f 6e 73 rong.host} -cons
2950: 74 72 61 69 6e 74 73 20 7b 6f 6c 64 5f 61 70 69 traints {old_api
2960: 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 61 64 73 73 } -body {..badss
2970: 6c 20 77 72 6f 6e 67 2e 68 6f 73 74 2e 62 61 64 l wrong.host.bad
2980: 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 7d 20 2d 72 ssl.com. } -r
2990: 65 73 75 6c 74 20 7b 68 61 6e 64 73 68 61 6b 65 esult {handshake
29a0: 20 66 61 69 6c 65 64 3a 20 63 65 72 74 69 66 69 failed: certifi
29b0: 63 61 74 65 20 76 65 72 69 66 79 20 66 61 69 6c cate verify fail
29c0: 65 64 20 64 75 65 20 74 6f 20 22 48 6f 73 74 6e ed due to "Hostn
29d0: 61 6d 65 20 6d 69 73 6d 61 74 63 68 22 7d 20 2d ame mismatch"} -
29e0: 72 65 74 75 72 6e 43 6f 64 65 73 20 7b 31 7d 0a returnCodes {1}.
29f0: 0a 74 65 73 74 20 42 61 64 53 53 4c 2d 31 2e 36 .test BadSSL-1.6
2a00: 38 20 7b 77 72 6f 6e 67 2e 68 6f 73 74 7d 20 2d 8 {wrong.host} -
2a10: 63 6f 6e 73 74 72 61 69 6e 74 73 20 7b 6e 65 77 constraints {new
2a20: 5f 61 70 69 7d 20 2d 62 6f 64 79 20 7b 0a 09 62 _api} -body {..b
2a30: 61 64 73 73 6c 20 77 72 6f 6e 67 2e 68 6f 73 74 adssl wrong.host
2a40: 2e 62 61 64 73 73 6c 2e 63 6f 6d 0a 20 20 20 20 .badssl.com.
2a50: 7d 20 2d 72 65 73 75 6c 74 20 7b 68 61 6e 64 73 } -result {hands
2a60: 68 61 6b 65 20 66 61 69 6c 65 64 3a 20 63 65 72 hake failed: cer
2a70: 74 69 66 69 63 61 74 65 20 76 65 72 69 66 79 20 tificate verify
2a80: 66 61 69 6c 65 64 20 64 75 65 20 74 6f 20 22 68 failed due to "h
2a90: 6f 73 74 6e 61 6d 65 20 6d 69 73 6d 61 74 63 68 ostname mismatch
2aa0: 22 7d 20 2d 72 65 74 75 72 6e 43 6f 64 65 73 20 "} -returnCodes
2ab0: 7b 31 7d 0a 0a 74 65 73 74 20 42 61 64 53 53 4c {1}..test BadSSL
2ac0: 2d 31 2e 36 39 20 7b 6d 6f 7a 69 6c 6c 61 2d 6d -1.69 {mozilla-m
2ad0: 6f 64 65 72 6e 7d 20 2d 62 6f 64 79 20 7b 0a 09 odern} -body {..
2ae0: 62 61 64 73 73 6c 20 6d 6f 7a 69 6c 6c 61 2d 6d badssl mozilla-m
2af0: 6f 64 65 72 6e 2e 62 61 64 73 73 6c 2e 63 6f 6d odern.badssl.com
2b00: 0a 20 20 20 20 7d 0a 0a 23 20 43 6c 65 61 6e 75 . }..# Cleanu
2b10: 70 0a 3a 3a 74 63 6c 74 65 73 74 3a 3a 63 6c 65 p.::tcltest::cle
2b20: 61 6e 75 70 54 65 73 74 73 0a 72 65 74 75 72 6e anupTests.return
2b30: 0a .