]> git.ipfire.org Git - thirdparty/openssh-portable.git/commitdiff
upstream: very basic testing of multiple files in RevokedKeys and
authordjm@openbsd.org <djm@openbsd.org>
Wed, 11 Feb 2026 22:58:23 +0000 (22:58 +0000)
committerDamien Miller <djm@mindrot.org>
Wed, 11 Feb 2026 23:30:23 +0000 (10:30 +1100)
RevokedHostkeys

OpenBSD-Regress-ID: 6cee76bcc4bd6840bc8d39dd0d32d724e1427aa7

regress/cert-hostkey.sh
regress/cert-userkey.sh

index f1551223280fe97830ec08fd4ddf68230e771713..0c160775388fd6e4c461db4e87755c64b152ee82 100644 (file)
@@ -1,4 +1,4 @@
-#      $OpenBSD: cert-hostkey.sh,v 1.30 2025/12/22 03:36:43 djm Exp $
+#      $OpenBSD: cert-hostkey.sh,v 1.31 2026/02/11 22:58:23 djm Exp $
 #      Placed in the Public Domain.
 
 tid="certified host keys"
@@ -143,6 +143,8 @@ for ktype in $PLAIN_TYPES ; do
        attempt_connect "$ktype basic connect"                  "yes"
        attempt_connect "$ktype empty KRL"                      "yes" \
            -oRevokedHostKeys=$OBJ/host_krl_empty
+       attempt_connect "$ktype multiple KRL files"             "no" \
+           -oRevokedHostKeys="/dev/null $OBJ/host_krl_plain"
        attempt_connect "$ktype KRL w/ plain key revoked"       "no" \
            -oRevokedHostKeys=$OBJ/host_krl_plain
        attempt_connect "$ktype KRL w/ cert revoked"            "no" \
index 6e2713bdd04b1d662ac1977693dfaa2102bba2c4..c0decf065cd3d32e73c62c56ee86cf18bb27469e 100644 (file)
@@ -1,4 +1,4 @@
-#      $OpenBSD: cert-userkey.sh,v 1.31 2025/12/22 01:50:46 djm Exp $
+#      $OpenBSD: cert-userkey.sh,v 1.32 2026/02/11 22:58:23 djm Exp $
 #      Placed in the Public Domain.
 
 tid="certified user keys"
@@ -226,7 +226,8 @@ basic_tests() {
                verbose "$tid: ${_prefix} revoked key"
                (
                        cat $OBJ/sshd_proxy_bak
-                       echo "RevokedKeys $OBJ/cert_user_key_revoked"
+                       # Also test multiple RevokedKeys files.
+                       echo "RevokedKeys /dev/null $OBJ/cert_user_key_revoked"
                        echo "PubkeyAcceptedAlgorithms ${t}"
                        echo "$extra_sshd"
                ) > $OBJ/sshd_proxy