File
Blob: dev/validator/main_test.go
| 1 | package main |
| 2 | |
| 3 | import ( |
| 4 | "crypto/tls" |
| 5 | "crypto/x509" |
| 6 | "crypto/x509/pkix" |
| 7 | "math/big" |
| 8 | "testing" |
| 9 | |
| 10 | "github.com/stretchr/testify/require" |
| 11 | ) |
| 12 | |
| 13 | func TestPeerCertificateSerial(t *testing.T) { |
| 14 | valid := &x509.Certificate{ |
| 15 | DNSNames: []string{"dev.con.nect.sh"}, |
| 16 | SerialNumber: big.NewInt(42), |
| 17 | } |
| 18 | wrongHost := &x509.Certificate{ |
| 19 | Subject: pkix.Name{CommonName: "dev.con.nect.sh"}, |
| 20 | DNSNames: []string{"other.example.com"}, |
| 21 | SerialNumber: big.NewInt(43), |
| 22 | } |
| 23 | for _, tc := range []struct { |
| 24 | name string |
| 25 | chain []*x509.Certificate |
| 26 | valid bool |
| 27 | }{ |
| 28 | {name: "SAN without Common Name", chain: []*x509.Certificate{valid}, valid: true}, |
| 29 | {name: "missing certificate"}, |
| 30 | {name: "wrong SAN with matching Common Name", chain: []*x509.Certificate{wrongHost}}, |
| 31 | {name: "matching intermediate cannot replace leaf", chain: []*x509.Certificate{wrongHost, valid}}, |
| 32 | } { |
| 33 | t.Run(tc.name, func(t *testing.T) { |
| 34 | serial, err := peerCertificateSerial(tls.ConnectionState{PeerCertificates: tc.chain}, "dev.con.nect.sh") |
| 35 | if tc.valid { |
| 36 | require.NoError(t, err) |
| 37 | require.Equal(t, "42", serial) |
| 38 | } else { |
| 39 | require.Error(t, err) |
| 40 | require.Empty(t, serial) |
| 41 | } |
| 42 | }) |
| 43 | } |
| 44 | } |