(t *testing.T)
| 732 | } |
| 733 | |
| 734 | func TestTLSConfig(t *testing.T) { |
| 735 | configTLSConfig := TLSConfig{ |
| 736 | CAFile: TLSCAChainPath, |
| 737 | CertFile: ClientCertificatePath, |
| 738 | KeyFile: ClientKeyNoPassPath, |
| 739 | ServerName: "localhost", |
| 740 | InsecureSkipVerify: false, |
| 741 | } |
| 742 | |
| 743 | tlsCAChain, err := os.ReadFile(TLSCAChainPath) |
| 744 | if err != nil { |
| 745 | t.Fatalf("Can't read the CA certificate chain (%s)", |
| 746 | TLSCAChainPath) |
| 747 | } |
| 748 | rootCAs := x509.NewCertPool() |
| 749 | rootCAs.AppendCertsFromPEM(tlsCAChain) |
| 750 | |
| 751 | expectedTLSConfig := &tls.Config{ |
| 752 | RootCAs: rootCAs, |
| 753 | ServerName: configTLSConfig.ServerName, |
| 754 | InsecureSkipVerify: configTLSConfig.InsecureSkipVerify, |
| 755 | } |
| 756 | |
| 757 | tlsConfig, err := NewTLSConfig(&configTLSConfig) |
| 758 | if err != nil { |
| 759 | t.Fatalf("Can't create a new TLS Config from a configuration (%s).", err) |
| 760 | } |
| 761 | |
| 762 | clientCertificate, err := tls.LoadX509KeyPair(ClientCertificatePath, ClientKeyNoPassPath) |
| 763 | if err != nil { |
| 764 | t.Fatalf("Can't load the client key pair ('%s' and '%s'). Reason: %s", |
| 765 | ClientCertificatePath, ClientKeyNoPassPath, err) |
| 766 | } |
| 767 | cert, err := tlsConfig.GetClientCertificate(nil) |
| 768 | if err != nil { |
| 769 | t.Fatalf("unexpected error returned by tlsConfig.GetClientCertificate(): %s", err) |
| 770 | } |
| 771 | if !reflect.DeepEqual(cert, &clientCertificate) { |
| 772 | t.Fatalf("Unexpected client certificate result: \n\n%+v\n expected\n\n%+v", cert, clientCertificate) |
| 773 | } |
| 774 | |
| 775 | // tlsConfig.rootCAs.LazyCerts contains functions getCert() in go 1.16, which are |
| 776 | // never equal. Compare the Subjects instead. |
| 777 | //nolint:staticcheck // Ignore SA1019. (*CertPool).Subjects is deprecated because it may not include the system certs but it isn't the case here. |
| 778 | if !reflect.DeepEqual(tlsConfig.RootCAs.Subjects(), expectedTLSConfig.RootCAs.Subjects()) { |
| 779 | t.Fatalf("Unexpected RootCAs result: \n\n%+v\n expected\n\n%+v", tlsConfig.RootCAs.Subjects(), expectedTLSConfig.RootCAs.Subjects()) |
| 780 | } |
| 781 | tlsConfig.RootCAs = nil |
| 782 | expectedTLSConfig.RootCAs = nil |
| 783 | |
| 784 | // Non-nil functions are never equal. |
| 785 | tlsConfig.GetClientCertificate = nil |
| 786 | |
| 787 | if !reflect.DeepEqual(tlsConfig, expectedTLSConfig) { |
| 788 | t.Fatalf("Unexpected TLS Config result: \n\n%+v\n expected\n\n%+v", tlsConfig, expectedTLSConfig) |
| 789 | } |
| 790 | } |
| 791 |
nothing calls this directly
no test coverage detected