08-ssl-connect-cert-auth-revoked.py 1.8 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758
  1. #!/usr/bin/env python3
  2. from mosq_test_helper import *
  3. if sys.version < '2.7':
  4. print("WARNING: SSL not supported on Python 2.6")
  5. exit(0)
  6. def write_config(filename, port1, port2):
  7. with open(filename, 'w') as f:
  8. f.write("port %d\n" % (port2))
  9. f.write("allow_anonymous true\n")
  10. f.write("listener %d\n" % (port1))
  11. f.write("allow_anonymous true\n")
  12. f.write("cafile ../ssl/all-ca.crt\n")
  13. f.write("certfile ../ssl/server.crt\n")
  14. f.write("keyfile ../ssl/server.key\n")
  15. f.write("require_certificate true\n")
  16. f.write("crlfile ../ssl/crl.pem\n")
  17. (port1, port2) = mosq_test.get_port(2)
  18. conf_file = os.path.basename(__file__).replace('.py', '.conf')
  19. write_config(conf_file, port1, port2)
  20. rc = 1
  21. keepalive = 10
  22. connect_packet = mosq_test.gen_connect("connect-revoked-test", keepalive=keepalive)
  23. broker = mosq_test.start_broker(filename=os.path.basename(__file__), port=port2, use_conf=True)
  24. try:
  25. sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
  26. ssock = ssl.wrap_socket(sock, ca_certs="../ssl/test-root-ca.crt", certfile="../ssl/client-revoked.crt", keyfile="../ssl/client-revoked.key", cert_reqs=ssl.CERT_REQUIRED)
  27. ssock.settimeout(20)
  28. try:
  29. ssock.connect(("localhost", port1))
  30. mosq_test.do_send_receive(ssock, connect_packet, "", "connack")
  31. except ssl.SSLError as err:
  32. if err.errno == 1 and "certificate revoked" in err.strerror:
  33. rc = 0
  34. else:
  35. broker.terminate()
  36. print(err.strerror)
  37. raise ValueError(err.errno)
  38. except mosq_test.TestError:
  39. pass
  40. finally:
  41. os.remove(conf_file)
  42. time.sleep(0.5)
  43. broker.terminate()
  44. broker.wait()
  45. (stdo, stde) = broker.communicate()
  46. if rc:
  47. print(stde.decode('utf-8'))
  48. exit(rc)