]> git.ipfire.org Git - thirdparty/openssl.git/blame - test/ssl-tests/04-client_auth.conf
Add options to check TLS signing hashes
[thirdparty/openssl.git] / test / ssl-tests / 04-client_auth.conf
CommitLineData
63936115
EK
1# Generated with generate_ssl_tests.pl
2
3num_tests = 20
4
5test-0 = 0-server-auth-flex
6test-1 = 1-client-auth-flex-request
7test-2 = 2-client-auth-flex-require-fail
8test-3 = 3-client-auth-flex-require
9test-4 = 4-client-auth-flex-noroot
10test-5 = 5-server-auth-TLSv1
11test-6 = 6-client-auth-TLSv1-request
12test-7 = 7-client-auth-TLSv1-require-fail
13test-8 = 8-client-auth-TLSv1-require
14test-9 = 9-client-auth-TLSv1-noroot
15test-10 = 10-server-auth-TLSv1.1
16test-11 = 11-client-auth-TLSv1.1-request
17test-12 = 12-client-auth-TLSv1.1-require-fail
18test-13 = 13-client-auth-TLSv1.1-require
19test-14 = 14-client-auth-TLSv1.1-noroot
20test-15 = 15-server-auth-TLSv1.2
21test-16 = 16-client-auth-TLSv1.2-request
22test-17 = 17-client-auth-TLSv1.2-require-fail
23test-18 = 18-client-auth-TLSv1.2-require
24test-19 = 19-client-auth-TLSv1.2-noroot
25# ===========================================================
26
27[0-server-auth-flex]
28ssl_conf = 0-server-auth-flex-ssl
29
30[0-server-auth-flex-ssl]
31server = 0-server-auth-flex-server
32client = 0-server-auth-flex-client
33
34[0-server-auth-flex-server]
35Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
36CipherString = DEFAULT
37PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
38
63936115
EK
39[0-server-auth-flex-client]
40CipherString = DEFAULT
41VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
42VerifyMode = Peer
43
63936115
EK
44[test-0]
45ExpectedResult = Success
46
47
48# ===========================================================
49
50[1-client-auth-flex-request]
51ssl_conf = 1-client-auth-flex-request-ssl
52
53[1-client-auth-flex-request-ssl]
54server = 1-client-auth-flex-request-server
55client = 1-client-auth-flex-request-client
56
57[1-client-auth-flex-request-server]
58Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
59CipherString = DEFAULT
60PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
61VerifyMode = Request
62
63936115
EK
63[1-client-auth-flex-request-client]
64CipherString = DEFAULT
65VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
66VerifyMode = Peer
67
63936115
EK
68[test-1]
69ExpectedResult = Success
70
71
72# ===========================================================
73
74[2-client-auth-flex-require-fail]
75ssl_conf = 2-client-auth-flex-require-fail-ssl
76
77[2-client-auth-flex-require-fail-ssl]
78server = 2-client-auth-flex-require-fail-server
79client = 2-client-auth-flex-require-fail-client
80
81[2-client-auth-flex-require-fail-server]
82Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
83CipherString = DEFAULT
84PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
85VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem
86VerifyMode = Require
87
63936115
EK
88[2-client-auth-flex-require-fail-client]
89CipherString = DEFAULT
90VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
91VerifyMode = Peer
92
63936115
EK
93[test-2]
94ExpectedResult = ServerFail
9f48bbac 95ExpectedServerAlert = HandshakeFailure
63936115
EK
96
97
98# ===========================================================
99
100[3-client-auth-flex-require]
101ssl_conf = 3-client-auth-flex-require-ssl
102
103[3-client-auth-flex-require-ssl]
104server = 3-client-auth-flex-require-server
105client = 3-client-auth-flex-require-client
106
107[3-client-auth-flex-require-server]
108Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
109CipherString = DEFAULT
110PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
111VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem
112VerifyMode = Request
113
63936115
EK
114[3-client-auth-flex-require-client]
115Certificate = ${ENV::TEST_CERTS_DIR}/ee-client-chain.pem
116CipherString = DEFAULT
117PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem
118VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
119VerifyMode = Peer
120
63936115 121[test-3]
a470f023 122ExpectedClientCertType = RSA
63936115
EK
123ExpectedResult = Success
124
125
126# ===========================================================
127
128[4-client-auth-flex-noroot]
129ssl_conf = 4-client-auth-flex-noroot-ssl
130
131[4-client-auth-flex-noroot-ssl]
132server = 4-client-auth-flex-noroot-server
133client = 4-client-auth-flex-noroot-client
134
135[4-client-auth-flex-noroot-server]
136Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
137CipherString = DEFAULT
138PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
139VerifyMode = Require
140
63936115
EK
141[4-client-auth-flex-noroot-client]
142Certificate = ${ENV::TEST_CERTS_DIR}/ee-client-chain.pem
143CipherString = DEFAULT
144PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem
145VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
146VerifyMode = Peer
147
63936115
EK
148[test-4]
149ExpectedResult = ServerFail
9f48bbac 150ExpectedServerAlert = UnknownCA
63936115
EK
151
152
153# ===========================================================
154
155[5-server-auth-TLSv1]
156ssl_conf = 5-server-auth-TLSv1-ssl
157
158[5-server-auth-TLSv1-ssl]
159server = 5-server-auth-TLSv1-server
160client = 5-server-auth-TLSv1-client
161
162[5-server-auth-TLSv1-server]
163Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
164CipherString = DEFAULT
78cbe94f
MC
165MaxProtocol = TLSv1
166MinProtocol = TLSv1
63936115 167PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115 168
63936115
EK
169[5-server-auth-TLSv1-client]
170CipherString = DEFAULT
78cbe94f
MC
171MaxProtocol = TLSv1
172MinProtocol = TLSv1
63936115
EK
173VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
174VerifyMode = Peer
175
63936115
EK
176[test-5]
177ExpectedResult = Success
178
179
180# ===========================================================
181
182[6-client-auth-TLSv1-request]
183ssl_conf = 6-client-auth-TLSv1-request-ssl
184
185[6-client-auth-TLSv1-request-ssl]
186server = 6-client-auth-TLSv1-request-server
187client = 6-client-auth-TLSv1-request-client
188
189[6-client-auth-TLSv1-request-server]
190Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
191CipherString = DEFAULT
78cbe94f
MC
192MaxProtocol = TLSv1
193MinProtocol = TLSv1
63936115 194PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
195VerifyMode = Request
196
63936115
EK
197[6-client-auth-TLSv1-request-client]
198CipherString = DEFAULT
78cbe94f
MC
199MaxProtocol = TLSv1
200MinProtocol = TLSv1
63936115
EK
201VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
202VerifyMode = Peer
203
63936115
EK
204[test-6]
205ExpectedResult = Success
206
207
208# ===========================================================
209
210[7-client-auth-TLSv1-require-fail]
211ssl_conf = 7-client-auth-TLSv1-require-fail-ssl
212
213[7-client-auth-TLSv1-require-fail-ssl]
214server = 7-client-auth-TLSv1-require-fail-server
215client = 7-client-auth-TLSv1-require-fail-client
216
217[7-client-auth-TLSv1-require-fail-server]
218Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
219CipherString = DEFAULT
78cbe94f
MC
220MaxProtocol = TLSv1
221MinProtocol = TLSv1
63936115 222PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
223VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem
224VerifyMode = Require
225
63936115
EK
226[7-client-auth-TLSv1-require-fail-client]
227CipherString = DEFAULT
78cbe94f
MC
228MaxProtocol = TLSv1
229MinProtocol = TLSv1
63936115
EK
230VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
231VerifyMode = Peer
232
63936115
EK
233[test-7]
234ExpectedResult = ServerFail
9f48bbac 235ExpectedServerAlert = HandshakeFailure
63936115
EK
236
237
238# ===========================================================
239
240[8-client-auth-TLSv1-require]
241ssl_conf = 8-client-auth-TLSv1-require-ssl
242
243[8-client-auth-TLSv1-require-ssl]
244server = 8-client-auth-TLSv1-require-server
245client = 8-client-auth-TLSv1-require-client
246
247[8-client-auth-TLSv1-require-server]
248Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
249CipherString = DEFAULT
78cbe94f
MC
250MaxProtocol = TLSv1
251MinProtocol = TLSv1
63936115 252PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
253VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem
254VerifyMode = Request
255
63936115
EK
256[8-client-auth-TLSv1-require-client]
257Certificate = ${ENV::TEST_CERTS_DIR}/ee-client-chain.pem
258CipherString = DEFAULT
78cbe94f
MC
259MaxProtocol = TLSv1
260MinProtocol = TLSv1
63936115 261PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem
63936115
EK
262VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
263VerifyMode = Peer
264
63936115 265[test-8]
a470f023 266ExpectedClientCertType = RSA
63936115
EK
267ExpectedResult = Success
268
269
270# ===========================================================
271
272[9-client-auth-TLSv1-noroot]
273ssl_conf = 9-client-auth-TLSv1-noroot-ssl
274
275[9-client-auth-TLSv1-noroot-ssl]
276server = 9-client-auth-TLSv1-noroot-server
277client = 9-client-auth-TLSv1-noroot-client
278
279[9-client-auth-TLSv1-noroot-server]
280Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
281CipherString = DEFAULT
78cbe94f
MC
282MaxProtocol = TLSv1
283MinProtocol = TLSv1
63936115 284PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
285VerifyMode = Require
286
63936115
EK
287[9-client-auth-TLSv1-noroot-client]
288Certificate = ${ENV::TEST_CERTS_DIR}/ee-client-chain.pem
289CipherString = DEFAULT
78cbe94f
MC
290MaxProtocol = TLSv1
291MinProtocol = TLSv1
63936115 292PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem
63936115
EK
293VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
294VerifyMode = Peer
295
63936115
EK
296[test-9]
297ExpectedResult = ServerFail
9f48bbac 298ExpectedServerAlert = UnknownCA
63936115
EK
299
300
301# ===========================================================
302
303[10-server-auth-TLSv1.1]
304ssl_conf = 10-server-auth-TLSv1.1-ssl
305
306[10-server-auth-TLSv1.1-ssl]
307server = 10-server-auth-TLSv1.1-server
308client = 10-server-auth-TLSv1.1-client
309
310[10-server-auth-TLSv1.1-server]
311Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
312CipherString = DEFAULT
78cbe94f
MC
313MaxProtocol = TLSv1.1
314MinProtocol = TLSv1.1
63936115 315PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115 316
63936115
EK
317[10-server-auth-TLSv1.1-client]
318CipherString = DEFAULT
78cbe94f
MC
319MaxProtocol = TLSv1.1
320MinProtocol = TLSv1.1
63936115
EK
321VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
322VerifyMode = Peer
323
63936115
EK
324[test-10]
325ExpectedResult = Success
326
327
328# ===========================================================
329
330[11-client-auth-TLSv1.1-request]
331ssl_conf = 11-client-auth-TLSv1.1-request-ssl
332
333[11-client-auth-TLSv1.1-request-ssl]
334server = 11-client-auth-TLSv1.1-request-server
335client = 11-client-auth-TLSv1.1-request-client
336
337[11-client-auth-TLSv1.1-request-server]
338Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
339CipherString = DEFAULT
78cbe94f
MC
340MaxProtocol = TLSv1.1
341MinProtocol = TLSv1.1
63936115 342PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
343VerifyMode = Request
344
63936115
EK
345[11-client-auth-TLSv1.1-request-client]
346CipherString = DEFAULT
78cbe94f
MC
347MaxProtocol = TLSv1.1
348MinProtocol = TLSv1.1
63936115
EK
349VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
350VerifyMode = Peer
351
63936115
EK
352[test-11]
353ExpectedResult = Success
354
355
356# ===========================================================
357
358[12-client-auth-TLSv1.1-require-fail]
359ssl_conf = 12-client-auth-TLSv1.1-require-fail-ssl
360
361[12-client-auth-TLSv1.1-require-fail-ssl]
362server = 12-client-auth-TLSv1.1-require-fail-server
363client = 12-client-auth-TLSv1.1-require-fail-client
364
365[12-client-auth-TLSv1.1-require-fail-server]
366Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
367CipherString = DEFAULT
78cbe94f
MC
368MaxProtocol = TLSv1.1
369MinProtocol = TLSv1.1
63936115 370PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
371VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem
372VerifyMode = Require
373
63936115
EK
374[12-client-auth-TLSv1.1-require-fail-client]
375CipherString = DEFAULT
78cbe94f
MC
376MaxProtocol = TLSv1.1
377MinProtocol = TLSv1.1
63936115
EK
378VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
379VerifyMode = Peer
380
63936115
EK
381[test-12]
382ExpectedResult = ServerFail
9f48bbac 383ExpectedServerAlert = HandshakeFailure
63936115
EK
384
385
386# ===========================================================
387
388[13-client-auth-TLSv1.1-require]
389ssl_conf = 13-client-auth-TLSv1.1-require-ssl
390
391[13-client-auth-TLSv1.1-require-ssl]
392server = 13-client-auth-TLSv1.1-require-server
393client = 13-client-auth-TLSv1.1-require-client
394
395[13-client-auth-TLSv1.1-require-server]
396Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
397CipherString = DEFAULT
78cbe94f
MC
398MaxProtocol = TLSv1.1
399MinProtocol = TLSv1.1
63936115 400PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
401VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem
402VerifyMode = Request
403
63936115
EK
404[13-client-auth-TLSv1.1-require-client]
405Certificate = ${ENV::TEST_CERTS_DIR}/ee-client-chain.pem
406CipherString = DEFAULT
78cbe94f
MC
407MaxProtocol = TLSv1.1
408MinProtocol = TLSv1.1
63936115 409PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem
63936115
EK
410VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
411VerifyMode = Peer
412
63936115 413[test-13]
a470f023 414ExpectedClientCertType = RSA
63936115
EK
415ExpectedResult = Success
416
417
418# ===========================================================
419
420[14-client-auth-TLSv1.1-noroot]
421ssl_conf = 14-client-auth-TLSv1.1-noroot-ssl
422
423[14-client-auth-TLSv1.1-noroot-ssl]
424server = 14-client-auth-TLSv1.1-noroot-server
425client = 14-client-auth-TLSv1.1-noroot-client
426
427[14-client-auth-TLSv1.1-noroot-server]
428Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
429CipherString = DEFAULT
78cbe94f
MC
430MaxProtocol = TLSv1.1
431MinProtocol = TLSv1.1
63936115 432PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
433VerifyMode = Require
434
63936115
EK
435[14-client-auth-TLSv1.1-noroot-client]
436Certificate = ${ENV::TEST_CERTS_DIR}/ee-client-chain.pem
437CipherString = DEFAULT
78cbe94f
MC
438MaxProtocol = TLSv1.1
439MinProtocol = TLSv1.1
63936115 440PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem
63936115
EK
441VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
442VerifyMode = Peer
443
63936115
EK
444[test-14]
445ExpectedResult = ServerFail
9f48bbac 446ExpectedServerAlert = UnknownCA
63936115
EK
447
448
449# ===========================================================
450
451[15-server-auth-TLSv1.2]
452ssl_conf = 15-server-auth-TLSv1.2-ssl
453
454[15-server-auth-TLSv1.2-ssl]
455server = 15-server-auth-TLSv1.2-server
456client = 15-server-auth-TLSv1.2-client
457
458[15-server-auth-TLSv1.2-server]
459Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
460CipherString = DEFAULT
78cbe94f
MC
461MaxProtocol = TLSv1.2
462MinProtocol = TLSv1.2
63936115 463PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115 464
63936115
EK
465[15-server-auth-TLSv1.2-client]
466CipherString = DEFAULT
78cbe94f
MC
467MaxProtocol = TLSv1.2
468MinProtocol = TLSv1.2
63936115
EK
469VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
470VerifyMode = Peer
471
63936115
EK
472[test-15]
473ExpectedResult = Success
474
475
476# ===========================================================
477
478[16-client-auth-TLSv1.2-request]
479ssl_conf = 16-client-auth-TLSv1.2-request-ssl
480
481[16-client-auth-TLSv1.2-request-ssl]
482server = 16-client-auth-TLSv1.2-request-server
483client = 16-client-auth-TLSv1.2-request-client
484
485[16-client-auth-TLSv1.2-request-server]
486Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
487CipherString = DEFAULT
78cbe94f
MC
488MaxProtocol = TLSv1.2
489MinProtocol = TLSv1.2
63936115 490PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
491VerifyMode = Request
492
63936115
EK
493[16-client-auth-TLSv1.2-request-client]
494CipherString = DEFAULT
78cbe94f
MC
495MaxProtocol = TLSv1.2
496MinProtocol = TLSv1.2
63936115
EK
497VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
498VerifyMode = Peer
499
63936115
EK
500[test-16]
501ExpectedResult = Success
502
503
504# ===========================================================
505
506[17-client-auth-TLSv1.2-require-fail]
507ssl_conf = 17-client-auth-TLSv1.2-require-fail-ssl
508
509[17-client-auth-TLSv1.2-require-fail-ssl]
510server = 17-client-auth-TLSv1.2-require-fail-server
511client = 17-client-auth-TLSv1.2-require-fail-client
512
513[17-client-auth-TLSv1.2-require-fail-server]
514Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
515CipherString = DEFAULT
78cbe94f
MC
516MaxProtocol = TLSv1.2
517MinProtocol = TLSv1.2
63936115 518PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
519VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem
520VerifyMode = Require
521
63936115
EK
522[17-client-auth-TLSv1.2-require-fail-client]
523CipherString = DEFAULT
78cbe94f
MC
524MaxProtocol = TLSv1.2
525MinProtocol = TLSv1.2
63936115
EK
526VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
527VerifyMode = Peer
528
63936115
EK
529[test-17]
530ExpectedResult = ServerFail
9f48bbac 531ExpectedServerAlert = HandshakeFailure
63936115
EK
532
533
534# ===========================================================
535
536[18-client-auth-TLSv1.2-require]
537ssl_conf = 18-client-auth-TLSv1.2-require-ssl
538
539[18-client-auth-TLSv1.2-require-ssl]
540server = 18-client-auth-TLSv1.2-require-server
541client = 18-client-auth-TLSv1.2-require-client
542
543[18-client-auth-TLSv1.2-require-server]
544Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
545CipherString = DEFAULT
78cbe94f
MC
546MaxProtocol = TLSv1.2
547MinProtocol = TLSv1.2
63936115 548PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
549VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem
550VerifyMode = Request
551
63936115
EK
552[18-client-auth-TLSv1.2-require-client]
553Certificate = ${ENV::TEST_CERTS_DIR}/ee-client-chain.pem
554CipherString = DEFAULT
78cbe94f
MC
555MaxProtocol = TLSv1.2
556MinProtocol = TLSv1.2
63936115 557PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem
63936115
EK
558VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
559VerifyMode = Peer
560
63936115 561[test-18]
a470f023 562ExpectedClientCertType = RSA
63936115
EK
563ExpectedResult = Success
564
565
566# ===========================================================
567
568[19-client-auth-TLSv1.2-noroot]
569ssl_conf = 19-client-auth-TLSv1.2-noroot-ssl
570
571[19-client-auth-TLSv1.2-noroot-ssl]
572server = 19-client-auth-TLSv1.2-noroot-server
573client = 19-client-auth-TLSv1.2-noroot-client
574
575[19-client-auth-TLSv1.2-noroot-server]
576Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
577CipherString = DEFAULT
78cbe94f
MC
578MaxProtocol = TLSv1.2
579MinProtocol = TLSv1.2
63936115 580PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
63936115
EK
581VerifyMode = Require
582
63936115
EK
583[19-client-auth-TLSv1.2-noroot-client]
584Certificate = ${ENV::TEST_CERTS_DIR}/ee-client-chain.pem
585CipherString = DEFAULT
78cbe94f
MC
586MaxProtocol = TLSv1.2
587MinProtocol = TLSv1.2
63936115 588PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem
63936115
EK
589VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
590VerifyMode = Peer
591
63936115
EK
592[test-19]
593ExpectedResult = ServerFail
9f48bbac 594ExpectedServerAlert = UnknownCA
63936115
EK
595
596