Add tests for ssl_set_renegotiation_enforced()
diff --git a/tests/ssl-opt.sh b/tests/ssl-opt.sh
index 6c2a92d..d4a4143 100755
--- a/tests/ssl-opt.sh
+++ b/tests/ssl-opt.sh
@@ -616,9 +616,11 @@
-c "found renegotiation extension" \
-c "=> renegotiate" \
-S "=> renegotiate" \
- -S "write hello request"
+ -S "write hello request" \
+ -c "SSL - An unexpected message was received from our peer" \
+ -c "failed"
-run_test "Renegotiation #5 (server-initiated, client-rejected)" \
+run_test "Renegotiation #5 (server-initiated, client-rejected, default)" \
"$P_SRV debug_level=4 renegotiation=1 renegotiate=1" \
"$P_CLI debug_level=4 renegotiation=0" \
0 \
@@ -633,6 +635,70 @@
-S "SSL - An unexpected message was received from our peer" \
-S "failed"
+run_test "Renegotiation #6 (server-initiated, client-rejected, not enforced)" \
+ "$P_SRV debug_level=4 renegotiation=1 renegotiate=1 \
+ renego_delay=-1" \
+ "$P_CLI debug_level=4 renegotiation=0" \
+ 0 \
+ -C "client hello, adding renegotiation extension" \
+ -s "received TLS_EMPTY_RENEGOTIATION_INFO" \
+ -S "found renegotiation extension" \
+ -s "server hello, secure renegotiation extension" \
+ -c "found renegotiation extension" \
+ -C "=> renegotiate" \
+ -S "=> renegotiate" \
+ -s "write hello request" \
+ -S "SSL - An unexpected message was received from our peer" \
+ -S "failed"
+
+run_test "Renegotiation #7 (server-initiated, client-rejected, delay 1)" \
+ "$P_SRV debug_level=4 renegotiation=1 renegotiate=1 \
+ renego_delay=1" \
+ "$P_CLI debug_level=4 renegotiation=0" \
+ 0 \
+ -C "client hello, adding renegotiation extension" \
+ -s "received TLS_EMPTY_RENEGOTIATION_INFO" \
+ -S "found renegotiation extension" \
+ -s "server hello, secure renegotiation extension" \
+ -c "found renegotiation extension" \
+ -C "=> renegotiate" \
+ -S "=> renegotiate" \
+ -s "write hello request" \
+ -S "SSL - An unexpected message was received from our peer" \
+ -S "failed"
+
+run_test "Renegotiation #8 (server-initiated, client-rejected, delay 0)" \
+ "$P_SRV debug_level=4 renegotiation=1 renegotiate=1 \
+ renego_delay=0" \
+ "$P_CLI debug_level=4 renegotiation=0" \
+ 0 \
+ -C "client hello, adding renegotiation extension" \
+ -s "received TLS_EMPTY_RENEGOTIATION_INFO" \
+ -S "found renegotiation extension" \
+ -s "server hello, secure renegotiation extension" \
+ -c "found renegotiation extension" \
+ -C "=> renegotiate" \
+ -S "=> renegotiate" \
+ -s "write hello request" \
+ -s "SSL - An unexpected message was received from our peer" \
+ -s "failed"
+
+run_test "Renegotiation #9 (server-initiated, client-accepted, delay 0)" \
+ "$P_SRV debug_level=4 renegotiation=1 renegotiate=1 \
+ renego_delay=0" \
+ "$P_CLI debug_level=4 renegotiation=1" \
+ 0 \
+ -c "client hello, adding renegotiation extension" \
+ -s "received TLS_EMPTY_RENEGOTIATION_INFO" \
+ -s "found renegotiation extension" \
+ -s "server hello, secure renegotiation extension" \
+ -c "found renegotiation extension" \
+ -c "=> renegotiate" \
+ -s "=> renegotiate" \
+ -s "write hello request" \
+ -S "SSL - An unexpected message was received from our peer" \
+ -S "failed"
+
# Tests for auth_mode
run_test "Authentication #1 (server badcert, client required)" \