summaryrefslogtreecommitdiff
path: root/t/ssl_proto_version.t
blob: 97f310be336fcd4c77ffccd46fcf704754e6361b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
#!/usr/bin/env perl

use warnings;
use Test::More;
use FindBin qw($Bin);
use lib "$Bin/lib";
use MemcachedTest;

if (!enabled_tls_testing()) {
    plan skip_all => 'SSL testing is not enabled';
    exit 0;
}

my $server;
my $is_tls_13_available = 0;

eval {
    # ssl_min_version=3 is not recognized when compiled with OpenSSL < 1.1.1
    $server = new_memcached('-o ssl_min_version=3');
    $is_tls_13_available = 1;
};

SKIP: {
    skip 'TLS v1.3 not available', 1 if !$is_tls_13_available;
    # Unsupported protocol version
    $sock = $server->new_sock(undef, 'TLSv1_2');
    is(undef, $sock, "handshake failure on unsupported proto version");
}

$server = new_memcached('-o ssl_min_version=2');

# Minimum supported protocol version
$sock = $server->new_sock(undef, 'TLSv1_2');
print $sock "version\r\n";
like(scalar <$sock>, qr/VERSION/, "handshake with minimum proto version");

SKIP: {
    skip 'TLS v1.3 not available', 1 if !$is_tls_13_available;
    # Above minimum supported protocol version
    $sock = $server->new_sock(undef, 'TLSv1_3');
    print $sock "version\r\n";
    like(scalar <$sock>, qr/VERSION/, "handshake above minimum proto version");
}

done_testing();