ruby/tls-minimal-version/cert.conf
Jun Aruga 9cbd536c42 Add a test for Ruby OpenSSL to respect crypto-policies TLS minimal version.
Add a test to test Ruby OpenSSL to respect cypto-policies TLS minimal version,
and test the issue identified at the ticket RHEL-21019.
https://issues.redhat.com/browse/RHEL-21019

If Ruby OpenSSL doesn't include the following upstream patch, the test fails as follows.
https://github.com/ruby/openssl/pull/710

```
$ tmt -c distro=fedora-rawhide run --all provision -h virtual -i fedora-rawhide tests -n '^/tls-minimal-version$'
/var/tmp/tmt/run-007
...
total: 1 test failed

$ tmt run --id run-007 report -vvv
...
                    :: [ 16:03:29 ] :: [  BEGIN   ] :: Running Ruby OpenSSL client :: actually running 'ruby /var/tmp/tmt/run-007/plans/all/discover/default-0/tests/tls-minimal-version/test.rb -v'
                    STDOUT: Loaded suite /var/tmp/tmt/run-007/plans/all/discover/default-0/tests/tls-minimal-version/test
                    STDOUT: Started
                    STDOUT: TestRubyOpenSSLTLSMin:
                    STDOUT:   test_connection_to_tls_1_2_server_to_fail:		F
                    STDOUT: ===============================================================================
                    STDOUT: Failure: test_connection_to_tls_1_2_server_to_fail(TestRubyOpenSSLTLSMin): <OpenSSL::SSL::SSLError> exception was expected but none was thrown.
                    STDOUT: /var/tmp/tmt/run-007/plans/all/discover/default-0/tests/tls-minimal-version/test.rb:13:in `test_connection_to_tls_1_2_server_to_fail'
                    STDOUT:      10:
                    STDOUT:      11: class TestRubyOpenSSLTLSMin < Test::Unit::TestCase
                    STDOUT:      12:   def test_connection_to_tls_1_2_server_to_fail
                    STDOUT:   => 13:     assert_raise_with_message(OpenSSL::SSL::SSLError,
                    STDOUT:      14:                               /tlsv1 alert protocol version/) do
                    STDOUT:      15:       connect(CONFIG_ITEMS[:tls_1_2][:host], CONFIG_ITEMS[:tls_1_2][:port])
                    STDOUT:      16:     end
                    STDOUT: ===============================================================================
                    STDOUT: : (0.075125)
                    STDOUT:   test_onnection_to_tls_1_3_server_to_pass:		.: (0.013862)
                    STDOUT:
                    STDOUT: Finished in 0.089378126 seconds.
                    STDOUT: -------------------------------------------------------------------------------
                    STDOUT: 2 tests, 2 assertions, 1 failures, 0 errors, 0 pendings, 0 omissions, 0 notifications
                    STDOUT: 50% passed
                    STDOUT: -------------------------------------------------------------------------------
                    STDOUT: 22.38 tests/s, 22.38 assertions/s
                    :: [ 16:03:30 ] :: [   FAIL   ] :: Running Ruby OpenSSL client (Expected 0, got 1)
...
total: 1 test failed
```
2024-12-17 14:53:43 +01:00

10 lines
386 B
Text

# See the manual openssl-req(1) for details.
[ req ]
distinguished_name = req_distinguished_name
[ req_distinguished_name ]
# The commonName is required. The openssl command fails with "Error: No objects
# specified in config file" without this setting.
commonName = Common Name (hostname, IP, or your name)
# Enable all the sub-domains of the domain.
commonName_default = *.localhost