mirror of
https://github.com/rsyslog/rsyslog.git
synced 2025-12-15 10:30:40 +01:00
- Extracted basic OpenSSL helper functions into own module net_ossl.h/net_ossl.c Both are compiled into lmnsd_ossl. - Cleanup of OpenSSL code, fixed minor compiler and linking issues. - Added DTLS Sender option DTLS into tcpflood for testbench. - Add initial implementation of imdtls input module. Added to configure and makefile - Add initial implementation of omdtls output module. Added to configure and makefile - Add multiple basic tests for imdtls receiving data by using tcpflood. - Add multiple send-receive test for imdtls and omdtls based on existing tls tests. - Add timeout and sessionbreak tests for imdtls stress testing. closes: https://github.com/rsyslog/rsyslog/issues/5211
47 lines
1.3 KiB
Bash
Executable File
47 lines
1.3 KiB
Bash
Executable File
#!/bin/bash
|
|
# added 2018-04-27 by alorbach
|
|
# This file is part of the rsyslog project, released under ASL 2.0
|
|
. ${srcdir:=.}/diag.sh init
|
|
export NUMMESSAGES=10
|
|
generate_conf
|
|
export PORT_RCVR="$(get_free_port)"
|
|
|
|
add_conf '
|
|
global( defaultNetstreamDriverCAFile="'$srcdir/tls-certs/ca.pem'"
|
|
defaultNetstreamDriverCertFile="'$srcdir/tls-certs/cert.pem'"
|
|
defaultNetstreamDriverKeyFile="'$srcdir/tls-certs/key.pem'"
|
|
)
|
|
|
|
module( load="../plugins/imdtls/.libs/imdtls" )
|
|
input( type="imdtls"
|
|
tls.tlscfgcmd="Protocol=ALL,-SSLv2,-SSLv3,-TLSv1,-TLSv1.1,-TLSv1.3
|
|
Options=Bugs"
|
|
port="'$PORT_RCVR'")
|
|
|
|
action(type="omfile" file="'$RSYSLOG_OUT_LOG'")
|
|
'
|
|
startup
|
|
|
|
# now inject the messages which will fail due protocol configuration
|
|
tcpflood --check-only -k "Protocol=-ALL,TLSv1.3" -p$PORT_RCVR -m$NUMMESSAGES -Tdtls -x$srcdir/tls-certs/ca.pem -Z$srcdir/tls-certs/cert.pem -z$srcdir/tls-certs/key.pem
|
|
|
|
shutdown_when_empty
|
|
wait_shutdown
|
|
|
|
if content_check --check-only "TLS library does not support SSL_CONF_cmd"
|
|
then
|
|
echo "SKIP: TLS library does not support SSL_CONF_cmd"
|
|
skip_test
|
|
else
|
|
if content_check --check-only "DTLSv1_listen"
|
|
then
|
|
# Found DTLSv1_listen error, no further check needed
|
|
exit_test
|
|
else
|
|
# Check for OpenSSL Error Stack
|
|
content_check "OpenSSL Error Stack:"
|
|
fi
|
|
fi
|
|
|
|
exit_test
|