1# Generated with generate_ssl_tests.pl
2
3num_tests = 7
4
5test-0 = 0-disable-extended-master-secret-server-sha
6test-1 = 1-disable-extended-master-secret-client-sha
7test-2 = 2-disable-extended-master-secret-both-sha
8test-3 = 3-disable-extended-master-secret-both-resume
9test-4 = 4-disable-extended-master-secret-server-sha2
10test-5 = 5-disable-extended-master-secret-client-sha2
11test-6 = 6-disable-extended-master-secret-both-sha2
12# ===========================================================
13
14[0-disable-extended-master-secret-server-sha]
15ssl_conf = 0-disable-extended-master-secret-server-sha-ssl
16
17[0-disable-extended-master-secret-server-sha-ssl]
18server = 0-disable-extended-master-secret-server-sha-server
19client = 0-disable-extended-master-secret-server-sha-client
20
21[0-disable-extended-master-secret-server-sha-server]
22Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
23CipherString = DEFAULT
24Options = -ExtendedMasterSecret
25PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
26
27[0-disable-extended-master-secret-server-sha-client]
28CipherString = AES128-SHA
29MaxProtocol = TLSv1.2
30VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
31VerifyMode = Peer
32
33[test-0]
34ExpectedResult = Success
35FIPSversion = <=3.1.0
36
37
38# ===========================================================
39
40[1-disable-extended-master-secret-client-sha]
41ssl_conf = 1-disable-extended-master-secret-client-sha-ssl
42
43[1-disable-extended-master-secret-client-sha-ssl]
44server = 1-disable-extended-master-secret-client-sha-server
45client = 1-disable-extended-master-secret-client-sha-client
46
47[1-disable-extended-master-secret-client-sha-server]
48Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
49CipherString = DEFAULT
50PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
51
52[1-disable-extended-master-secret-client-sha-client]
53CipherString = AES128-SHA
54MaxProtocol = TLSv1.2
55Options = -ExtendedMasterSecret
56VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
57VerifyMode = Peer
58
59[test-1]
60ExpectedResult = Success
61FIPSversion = <=3.1.0
62
63
64# ===========================================================
65
66[2-disable-extended-master-secret-both-sha]
67ssl_conf = 2-disable-extended-master-secret-both-sha-ssl
68
69[2-disable-extended-master-secret-both-sha-ssl]
70server = 2-disable-extended-master-secret-both-sha-server
71client = 2-disable-extended-master-secret-both-sha-client
72
73[2-disable-extended-master-secret-both-sha-server]
74Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
75CipherString = DEFAULT
76Options = -ExtendedMasterSecret
77PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
78
79[2-disable-extended-master-secret-both-sha-client]
80CipherString = AES128-SHA
81MaxProtocol = TLSv1.2
82Options = -ExtendedMasterSecret
83VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
84VerifyMode = Peer
85
86[test-2]
87ExpectedResult = Success
88FIPSversion = <=3.1.0
89
90
91# ===========================================================
92
93[3-disable-extended-master-secret-both-resume]
94ssl_conf = 3-disable-extended-master-secret-both-resume-ssl
95
96[3-disable-extended-master-secret-both-resume-ssl]
97server = 3-disable-extended-master-secret-both-resume-server
98client = 3-disable-extended-master-secret-both-resume-client
99resume-server = 3-disable-extended-master-secret-both-resume-resume-server
100resume-client = 3-disable-extended-master-secret-both-resume-resume-client
101
102[3-disable-extended-master-secret-both-resume-server]
103Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
104CipherString = DEFAULT
105Options = -ExtendedMasterSecret
106PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
107
108[3-disable-extended-master-secret-both-resume-resume-server]
109Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
110CipherString = DEFAULT
111PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
112
113[3-disable-extended-master-secret-both-resume-client]
114CipherString = AES128-SHA
115MaxProtocol = TLSv1.2
116Options = -ExtendedMasterSecret
117VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
118VerifyMode = Peer
119
120[3-disable-extended-master-secret-both-resume-resume-client]
121CipherString = AES128-SHA
122MaxProtocol = TLSv1.2
123VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
124VerifyMode = Peer
125
126[test-3]
127ExpectedResult = Success
128FIPSversion = <=3.1.0
129HandshakeMode = Resume
130
131
132# ===========================================================
133
134[4-disable-extended-master-secret-server-sha2]
135ssl_conf = 4-disable-extended-master-secret-server-sha2-ssl
136
137[4-disable-extended-master-secret-server-sha2-ssl]
138server = 4-disable-extended-master-secret-server-sha2-server
139client = 4-disable-extended-master-secret-server-sha2-client
140
141[4-disable-extended-master-secret-server-sha2-server]
142Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
143CipherString = DEFAULT
144Options = -ExtendedMasterSecret
145PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
146
147[4-disable-extended-master-secret-server-sha2-client]
148CipherString = AES128-SHA256
149MaxProtocol = TLSv1.2
150VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
151VerifyMode = Peer
152
153[test-4]
154ExpectedResult = Success
155FIPSversion = <=3.1.0
156
157
158# ===========================================================
159
160[5-disable-extended-master-secret-client-sha2]
161ssl_conf = 5-disable-extended-master-secret-client-sha2-ssl
162
163[5-disable-extended-master-secret-client-sha2-ssl]
164server = 5-disable-extended-master-secret-client-sha2-server
165client = 5-disable-extended-master-secret-client-sha2-client
166
167[5-disable-extended-master-secret-client-sha2-server]
168Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
169CipherString = DEFAULT
170PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
171
172[5-disable-extended-master-secret-client-sha2-client]
173CipherString = AES128-SHA256
174MaxProtocol = TLSv1.2
175Options = -ExtendedMasterSecret
176VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
177VerifyMode = Peer
178
179[test-5]
180ExpectedResult = Success
181FIPSversion = <=3.1.0
182
183
184# ===========================================================
185
186[6-disable-extended-master-secret-both-sha2]
187ssl_conf = 6-disable-extended-master-secret-both-sha2-ssl
188
189[6-disable-extended-master-secret-both-sha2-ssl]
190server = 6-disable-extended-master-secret-both-sha2-server
191client = 6-disable-extended-master-secret-both-sha2-client
192
193[6-disable-extended-master-secret-both-sha2-server]
194Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
195CipherString = DEFAULT
196Options = -ExtendedMasterSecret
197PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
198
199[6-disable-extended-master-secret-both-sha2-client]
200CipherString = AES128-SHA256
201MaxProtocol = TLSv1.2
202Options = -ExtendedMasterSecret
203VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
204VerifyMode = Peer
205
206[test-6]
207ExpectedResult = Success
208FIPSversion = <=3.1.0
209
210
211