]> git.ipfire.org Git - thirdparty/unbound.git/commitdiff
stream reuse, add tls test for stream reuse.
authorW.C.A. Wijngaards <wouter@nlnetlabs.nl>
Thu, 30 Jul 2020 15:51:49 +0000 (17:51 +0200)
committerW.C.A. Wijngaards <wouter@nlnetlabs.nl>
Thu, 30 Jul 2020 15:51:49 +0000 (17:51 +0200)
testdata/ssl_reuse.tdir/ssl_reuse.conf [new file with mode: 0644]
testdata/ssl_reuse.tdir/ssl_reuse.conf2 [new file with mode: 0644]
testdata/ssl_reuse.tdir/ssl_reuse.dsc [new file with mode: 0644]
testdata/ssl_reuse.tdir/ssl_reuse.post [new file with mode: 0644]
testdata/ssl_reuse.tdir/ssl_reuse.pre [new file with mode: 0644]
testdata/ssl_reuse.tdir/ssl_reuse.test [new file with mode: 0644]
testdata/ssl_reuse.tdir/unbound_control.key [new file with mode: 0644]
testdata/ssl_reuse.tdir/unbound_control.pem [new file with mode: 0644]
testdata/ssl_reuse.tdir/unbound_server.key [new file with mode: 0644]
testdata/ssl_reuse.tdir/unbound_server.pem [new file with mode: 0644]

diff --git a/testdata/ssl_reuse.tdir/ssl_reuse.conf b/testdata/ssl_reuse.tdir/ssl_reuse.conf
new file mode 100644 (file)
index 0000000..52857ca
--- /dev/null
@@ -0,0 +1,18 @@
+server:
+       verbosity: 5
+       # num-threads: 1
+       interface: 127.0.0.1
+       port: @PORT@
+       use-syslog: no
+       directory: .
+       pidfile: "unbound.pid"
+       chroot: ""
+       username: ""
+       do-not-query-localhost: no
+
+       tls-cert-bundle: "unbound_server.pem"
+       ssl-upstream: yes
+
+forward-zone:
+       name: "."
+       forward-addr: "127.0.0.1@@TOPORT@#unbound"
diff --git a/testdata/ssl_reuse.tdir/ssl_reuse.conf2 b/testdata/ssl_reuse.tdir/ssl_reuse.conf2
new file mode 100644 (file)
index 0000000..0b45255
--- /dev/null
@@ -0,0 +1,43 @@
+# this is the upstream server that has pipelining and responds to queries.
+server:
+       verbosity: 1
+       # num-threads: 1
+       interface: 127.0.0.1@@PORT@
+       port: @PORT@
+       use-syslog: no
+       directory: .
+       pidfile: "unbound2.pid"
+       chroot: ""
+       username: ""
+       do-not-query-localhost: no
+       tls-port: @PORT@
+       tls-service-key: "unbound_server.key"
+       tls-service-pem: "unbound_server.pem"
+       tcp-idle-timeout: 10000
+
+       log-queries: yes
+       log-replies: yes
+       log-identity: "upstream"
+
+       local-zone: "." refuse
+       local-zone: "example.com" static
+       local-data: "www.example.com  A 10.20.30.40"
+       local-data: "www1.example.com  A 10.20.30.41"
+       local-data: "www2.example.com  A 10.20.30.42"
+       local-data: "www3.example.com  A 10.20.30.43"
+       local-data: "www4.example.com  A 10.20.30.44"
+       local-data: "www5.example.com  A 10.20.30.45"
+       local-data: "www6.example.com  A 10.20.30.46"
+       local-data: "www7.example.com  A 10.20.30.47"
+
+       local-zone: "drop.net" deny
+       local-zone: "refuse.net" refuse
+
+       local-zone: "more.net" redirect
+       local-data: "more.net A 10.20.30.40"
+
+# if queries escape, send them to localhost
+forward-zone:
+       name: "."
+       forward-tls-upstream: yes
+       forward-addr: "127.0.0.1@@TOPORT@"
diff --git a/testdata/ssl_reuse.tdir/ssl_reuse.dsc b/testdata/ssl_reuse.tdir/ssl_reuse.dsc
new file mode 100644 (file)
index 0000000..ab2b67f
--- /dev/null
@@ -0,0 +1,16 @@
+BaseName: ssl_reuse
+Version: 1.0
+Description: Test ssl stream reuse.
+CreationDate: Wed Jun 30 16:37:00 CET 2020
+Maintainer: Wouter Wijngaards
+Category: 
+Component:
+CmdDepends: 
+Depends: 
+Help:
+Pre: ssl_reuse.pre
+Post: ssl_reuse.post
+Test: ssl_reuse.test
+AuxFiles: 
+Passed:
+Failure:
diff --git a/testdata/ssl_reuse.tdir/ssl_reuse.post b/testdata/ssl_reuse.tdir/ssl_reuse.post
new file mode 100644 (file)
index 0000000..4337af2
--- /dev/null
@@ -0,0 +1,19 @@
+# #-- ssl_reuse.post --#
+# source the master var file when it's there
+[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
+# source the test var file when it's there
+[ -f .tpkg.var.test ] && source .tpkg.var.test
+#
+# do your teardown here
+. ../common.sh
+kill_pid `cat unbound2.pid`
+if test -f unbound2.log; then
+       echo ">>> upstream log"
+       cat unbound2.log
+fi
+#kill_pid $UNBOUND_PID
+kill_pid `cat unbound.pid`
+if test -f unbound.log; then
+       echo ">>> unbound log"
+       cat unbound.log
+fi
diff --git a/testdata/ssl_reuse.tdir/ssl_reuse.pre b/testdata/ssl_reuse.tdir/ssl_reuse.pre
new file mode 100644 (file)
index 0000000..cc22486
--- /dev/null
@@ -0,0 +1,34 @@
+# #-- ssl_reuse.pre--#
+# source the master var file when it's there
+[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
+# use .tpkg.var.test for in test variable passing
+[ -f .tpkg.var.test ] && source .tpkg.var.test
+
+PRE="../.."
+. ../common.sh
+get_random_port 2
+UNBOUND_PORT=$RND_PORT
+UPSTREAM_PORT=$(($RND_PORT + 1))
+echo "UNBOUND_PORT=$UNBOUND_PORT" >> .tpkg.var.test
+echo "UPSTREAM_PORT=$UPSTREAM_PORT" >> .tpkg.var.test
+
+# make config file
+sed -e 's/@PORT\@/'$UNBOUND_PORT'/' -e 's/@TOPORT\@/'$UPSTREAM_PORT'/' < ssl_reuse.conf > ub.conf
+# start unbound in the background
+#$PRE/unbound -d -c ub.conf >unbound.log 2>&1 &
+valgrind $PRE/unbound -d -c ub.conf 2>&1 | tee unbound.log &
+UNBOUND_PID=$!
+echo "UNBOUND_PID=$UNBOUND_PID" >> .tpkg.var.test
+wait_unbound_up unbound.log
+
+# make upstream config file
+sed -e 's/@PORT\@/'$UPSTREAM_PORT'/' -e 's/@TOPORT\@/'$UPSTREAM_PORT'/' < ssl_reuse.conf2 > ub2.conf
+# start upstream unbound in the background
+#$PRE/unbound -d -c ub2.conf >unbound2.log 2>&1 &
+valgrind $PRE/unbound -d -c ub2.conf 2>&1 | tee unbound2.log &
+UPSTREAM_PID=$!
+echo "UPSTREAM_PID=$UPSTREAM_PID" >> .tpkg.var.test
+wait_unbound_up unbound2.log
+
+cat .tpkg.var.test
+
diff --git a/testdata/ssl_reuse.tdir/ssl_reuse.test b/testdata/ssl_reuse.tdir/ssl_reuse.test
new file mode 100644 (file)
index 0000000..d0106c1
--- /dev/null
@@ -0,0 +1,308 @@
+# #-- ssl_reuse.test --#
+# source the master var file when it's there
+[ -f ../.tpkg.var.master ] && source ../.tpkg.var.master
+# use .tpkg.var.test for in test variable passing
+[ -f .tpkg.var.test ] && source .tpkg.var.test
+
+PRE="../.."
+. ../common.sh
+
+get_make
+(cd $PRE; $MAKE streamtcp)
+
+echo "> query www1.example.com."
+$PRE/streamtcp -f 127.0.0.1@$UNBOUND_PORT www1.example.com. A IN >outfile 2>&1
+cat outfile
+if test "$?" -ne 0; then
+       echo "exit status not OK"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log 
+       cat unbound.log
+       echo "Not OK"
+       exit 1
+fi
+if grep "www1.example.com" outfile | grep "10.20.30.41"; then
+       echo "content OK"
+else
+       echo "result contents not OK, for www1.example.com"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log 
+       cat unbound.log
+       echo "result contents not OK, for www1.example.com"
+       exit 1
+fi
+echo "OK"
+echo ""
+
+# this should be reused on the same tcp stream:
+echo "> query www2.example.com."
+$PRE/streamtcp -f 127.0.0.1@$UNBOUND_PORT www2.example.com. A IN >outfile 2>&1
+cat outfile
+if test "$?" -ne 0; then
+       echo "exit status not OK"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log 
+       cat unbound.log
+       echo "Not OK"
+       exit 1
+fi
+if grep "www2.example.com" outfile | grep "10.20.30.42"; then
+       echo "content OK"
+else
+       echo "result contents not OK, for www2.example.com"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log 
+       cat unbound.log
+       echo "result contents not OK, for www2.example.com"
+       exit 1
+fi
+
+echo "> query refuse.net."
+$PRE/streamtcp -f 127.0.0.1@$UNBOUND_PORT refuse.net. A IN >outfile 2>&1
+cat outfile
+if test "$?" -ne 0; then
+       echo "exit status not OK"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log
+       cat unbound.log
+       echo "Not OK"
+       exit 1
+fi
+if grep "rcode: SERVFAIL" outfile; then
+       echo "content OK"
+else
+       echo "result contents not OK, for refuse.net"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log
+       cat unbound.log
+       echo "result contents not OK, for refuse.net"
+       exit 1
+fi
+
+echo "> query www3.example.com."
+echo "> query www4.example.com."
+echo "> query www5.example.com."
+echo "> query www6.example.com."
+$PRE/streamtcp -f 127.0.0.1@$UNBOUND_PORT www3.example.com. A IN >outfile3 2>&1 &
+$PRE/streamtcp -f 127.0.0.1@$UNBOUND_PORT www4.example.com. A IN >outfile4 2>&1 &
+$PRE/streamtcp -f 127.0.0.1@$UNBOUND_PORT www5.example.com. A IN >outfile5 2>&1 &
+$PRE/streamtcp -f 127.0.0.1@$UNBOUND_PORT www6.example.com. A IN >outfile6 2>&1 &
+wait
+if test "$?" -ne 0; then
+       echo "exit status not OK"
+       echo "> cat logfiles"
+       cat outfile3
+       cat outfile4
+       cat outfile5
+       cat outfile6
+       cat unbound2.log
+       cat unbound.log
+       echo "Not OK"
+       exit 1
+fi
+if grep "www3.example.com" outfile3 | grep "10.20.30.43"; then
+       echo "content OK"
+else
+       echo "result contents not OK, for www3.example.com"
+       echo "> cat logfiles"
+       cat outfile3
+       cat outfile4
+       cat outfile5
+       cat outfile6
+       cat unbound2.log
+       cat unbound.log
+       echo "result contents not OK, for www3.example.com"
+       exit 1
+fi
+if grep "www4.example.com" outfile4 | grep "10.20.30.44"; then
+       echo "content OK"
+else
+       echo "result contents not OK, for www4.example.com"
+       echo "> cat logfiles"
+       cat outfile3
+       cat outfile4
+       cat outfile5
+       cat outfile6
+       cat unbound2.log
+       cat unbound.log
+       echo "result contents not OK, for www4.example.com"
+       exit 1
+fi
+if grep "www5.example.com" outfile5 | grep "10.20.30.45"; then
+       echo "content OK"
+else
+       echo "result contents not OK, for www5.example.com"
+       echo "> cat logfiles"
+       cat outfile3
+       cat outfile4
+       cat outfile5
+       cat outfile6
+       cat unbound2.log
+       cat unbound.log
+       echo "result contents not OK, for www5.example.com"
+       exit 1
+fi
+if grep "www6.example.com" outfile6 | grep "10.20.30.46"; then
+       echo "content OK"
+else
+       echo "result contents not OK, for www6.example.com"
+       echo "> cat logfiles"
+       cat outfile3
+       cat outfile4
+       cat outfile5
+       cat outfile6
+       cat unbound2.log
+       cat unbound.log
+       echo "result contents not OK, for www6.example.com"
+       exit 1
+fi
+
+echo "> query a1.more.net a2.more.net a3.more.net a4.more.net a5.more.net"
+$PRE/streamtcp -a -f 127.0.0.1@$UNBOUND_PORT a1.more.net A IN a2.more.net A IN a3.more.net A IN a4.more.net A IN a5.more.net A IN >outfile 2>&1
+if test "$?" -ne 0; then
+       echo "exit status not OK"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log
+       cat unbound.log
+       echo "Not OK"
+       exit 1
+fi
+cat outfile
+for x in a1.more.net a2.more.net a3.more.net a4.more.net a5.more.net; do
+       if grep "$x" outfile | grep "10.20.30.40"; then
+               echo "content OK for $x"
+       else
+               echo "result contents not OK, for $x"
+               echo "> cat logfiles"
+               cat outfile
+               cat unbound2.log
+               cat unbound.log
+               echo "result contents not OK, for $x"
+               exit 1
+       fi
+done
+
+# make the server timeout to drop the upstream connection
+echo "> sleep 20"
+sleep 15
+# see if we are still up.
+echo "> query a7.more.net"
+$PRE/streamtcp -a -f 127.0.0.1@$UNBOUND_PORT a7.more.net A IN >outfile 2>&1
+if test "$?" -ne 0; then
+       echo "exit status not OK"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log
+       cat unbound.log
+       echo "Not OK"
+       exit 1
+fi
+cat outfile
+for x in a7.more.net; do
+       if grep "$x" outfile | grep "10.20.30.40"; then
+               echo "content OK for $x"
+       else
+               echo "result contents not OK, for $x"
+               echo "> cat logfiles"
+               cat outfile
+               cat unbound2.log
+               cat unbound.log
+               echo "result contents not OK, for $x"
+               exit 1
+       fi
+done
+
+# dropconn.drop.net make the server drop the connection.
+echo "> query a11.more.net a12.more.net dropconn.drop.net a14.more.net a15.more.net"
+$PRE/streamtcp -a -f 127.0.0.1@$UNBOUND_PORT a11.more.net A IN a12.more.net A IN dropconn.drop.net A IN a14.more.net A IN a15.more.net A IN >outfile 2>&1
+if test "$?" -ne 0; then
+       echo "exit status not OK"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log
+       cat unbound.log
+       echo "Not OK"
+       exit 1
+fi
+cat outfile
+# cannot really check outfile, because it may or may not have answers depending
+# on how fast the other server responds or the drop happens, but there are
+# a bunch of connection drops, whilst resolving the other queries.
+
+echo "> query drop.net."
+$PRE/streamtcp -f 127.0.0.1@$UNBOUND_PORT drop.net. A IN >outfile 2>&1
+cat outfile
+if test "$?" -ne 0; then
+       echo "exit status not OK"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log
+       cat unbound.log
+       echo "Not OK"
+       exit 1
+fi
+if grep "rcode: SERVFAIL" outfile; then
+       echo "content OK"
+else
+       echo "result contents not OK, for drop.net"
+       echo "> cat logfiles"
+       cat outfile
+       cat unbound2.log
+       cat unbound.log
+       echo "result contents not OK, for drop.net"
+       exit 1
+fi
+
+# timeouts at the end. (so that the server is not marked as failed for
+# the other tests).
+echo "> query q1.drop.net."
+echo "> query q2.drop.net."
+$PRE/streamtcp -f 127.0.0.1@$UNBOUND_PORT q1.drop.net. A IN >outfile1 2>&1 &
+$PRE/streamtcp -f 127.0.0.1@$UNBOUND_PORT q2.drop.net. A IN >outfile2 2>&1 &
+wait
+if test "$?" -ne 0; then
+       echo "exit status not OK"
+       echo "> cat logfiles"
+       cat outfile1
+       cat outfile2
+       cat unbound2.log
+       cat unbound.log
+       echo "Not OK"
+       exit 1
+fi
+cat outfile1
+cat outfile2
+if grep "rcode: SERVFAIL" outfile1; then
+       echo "content OK"
+else
+       echo "result contents not OK, for q1.drop.net"
+       echo "> cat logfiles"
+       cat outfile1
+       cat outfile2
+       cat unbound2.log
+       cat unbound.log
+       echo "result contents not OK, for q1.drop.net"
+       exit 1
+fi
+if grep "rcode: SERVFAIL" outfile2; then
+       echo "content OK"
+else
+       echo "result contents not OK, for q2.drop.net"
+       echo "> cat logfiles"
+       cat outfile1
+       cat outfile2
+       cat unbound2.log
+       cat unbound.log
+       echo "result contents not OK, for q2.drop.net"
+       exit 1
+fi
+
+echo "OK"
+exit 0
diff --git a/testdata/ssl_reuse.tdir/unbound_control.key b/testdata/ssl_reuse.tdir/unbound_control.key
new file mode 100644 (file)
index 0000000..753a4ef
--- /dev/null
@@ -0,0 +1,39 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIG4gIBAAKCAYEAstEp+Pyh8XGrtZ77A4FhYjvbeB3dMa7Q2rGWxobzlA9przhA
+1aChAvUtCOAuM+rB6NTNB8YWfZJbQHawyMNpmC77cg6vXLYCGUQHZyAqidN049RJ
+F5T7j4N8Vniv17LiRdr0S6swy4PRvEnIPPV43EQHZqC5jVvHsKkhIfmBF/Dj5TXR
+ypeawWV/m5jeU6/4HRYMfytBZdO1mPXuWLh0lgbQ4SCbgrOUVD3rniMk1yZIbQOm
+vlDHYqekjDb/vOW2KxUQLG04aZMJ1mWfdbwG0CKQkSjISEDZ1l76vhM6mTM0fwXb
+IvyFZ9yPPCle1mF5aSlxS2cmGuGVSRQaw8XF9fe3a9ACJJTr33HdSpyaZkKRAUzL
+cKqLCl323daKv3NwwAT03Tj4iQM416ASMoiyfFa/2GWTKQVjddu8Crar7tGaf5xr
+lig4DBmrBvdYA3njy72/RD71hLwmlRoCGU7dRuDr9O6KASUm1Ri91ONZ/qdjMvov
+15l2vj4GV+KXR00dAgMBAAECggGAHepIL1N0dEQkCdpy+/8lH54L9WhpnOo2HqAf
+LU9eaKK7d4jdr9+TkD8cLaPzltPrZNxVALvu/0sA4SP6J1wpyj/x6P7z73qzly5+
+Xo5PD4fEwmi9YaiW/UduAblnEZrnp/AddptJKoL/D5T4XtpiQddPtael4zQ7kB57
+YIexRSQTvEDovA/o3/nvA0TrzOxfgd4ycQP3iOWGN/TMzyLsvjydrUwbOB567iz9
+whL3Etdgvnwh5Sz2blbFfH+nAR8ctvFFz+osPvuIVR21VMEI6wm7kTpSNnQ6sh/c
+lrLb/bTADn4g7z/LpIZJ+MrLvyEcoqValrLYeFBhM9CV8woPxvkO2P3pU47HVGax
+tC7GV6a/kt5RoKFd/TNdiA3OC7NGZtaeXv9VkPf4fVwBtSO9d5ZZXTGEynDD/rUQ
+U4KFJe6OD23APjse08HiiKqTPhsOneOONU67iqoaTdIkT2R4EdlkVEDpXVtWb+G9
+Q+IqYzVljlzuyHrhWXLJw/FMa2aBAoHBAOnZbi4gGpH+P6886WDWVgIlTccuXoyc
+Mg9QQYk9UDeXxL0AizR5bZy49Sduegz9vkHpAiZARQsUnizHjZ8YlRcrmn4t6tx3
+ahTIKAjdprnxJfYINM580j8CGbXvX5LhIlm3O267D0Op+co3+7Ujy+cjsIuFQrP+
+1MqMgXSeBjzC1APivmps7HeFE+4w0k2PfN5wSMDNCzLo99PZuUG5XZ93OVOS5dpN
+b+WskdcD8NOoJy/X/5A08veEI/jYO/DyqQKBwQDDwUQCOWf41ecvJLtBHKmEnHDz
+ftzHino9DRKG8a9XaN4rmetnoWEaM2vHGX3pf3mwH+dAe8vJdAQueDhBKYeEpm6C
+TYNOpou1+Zs5s99BilCTNYo8fkMOAyqwRwmz9zgHS6QxXuPwsghKefLJGt6o6RFF
+tfWVTfLlYJ+I3GQe3ySsk3wjVz4oUTKiyiq5+KzD+HhEkS7u+RQ7Z0ZI2xd2cF8Y
+aN2hjKDpcOiFf3CDoqka5D1qMNLgIHO52AHww1UCgcA1h7o7AMpURRka6hyaODY0
+A4oMYEbwdQjYjIyT998W+rzkbu1us6UtzQEBZ760npkgyU/epbOoV63lnkCC/MOU
+LD0PST+L/CHiY/cWIHb79YG1EifUZKpUFg0Aoq0EGFkepF0MefGCkbRGYA5UZr9U
+R80wAu9D+L+JJiS0J0BSRF74DL196zUuHt5zFeXuLzxsRtPAnq9DliS08BACRYZy
+7H3I7cWD9Vn5/0jbKWHFcaaWwyETR6uekTcSzZzbCRECgcBeoE3/xUA9SSk34Mmj
+7/cB4522Ft0imA3+9RK/qJTZ7Bd5fC4PKjOGNtUiqW/0L2rjeIiQ40bfWvWqgPKw
+jSK1PL6uvkl6+4cNsFsYyZpiVDoe7wKju2UuoNlB3RUTqa2r2STFuNj2wRjA57I1
+BIgdnox65jqQsd14g/yaa+75/WP9CE45xzKEyrtvdcqxm0Pod3OrsYK+gikFjiar
+kT0GQ8u0QPzh2tjt/2ZnIfOBrl+QYERP0MofDZDjhUdq2wECgcB0Lu841+yP5cdR
+qbJhXO4zJNh7oWNcJlOuQp3ZMNFrA1oHpe9pmLukiROOy01k9WxIMQDzU5GSqRv3
+VLkYOIcbhJ3kClKAcM3j95SkKbU2H5/RENb3Ck52xtl4pNU1x/3PnVFZfDVuuHO9
+MZ9YBcIeK98MyP2jr5JtFKnOyPE7xKq0IHIhXadpbc2wjje5FtZ1cUtMyEECCXNa
+C1TpXebHGyXGpY9WdWXhjdE/1jPvfS+uO5WyuDpYPr339gsdq1g=
+-----END RSA PRIVATE KEY-----
diff --git a/testdata/ssl_reuse.tdir/unbound_control.pem b/testdata/ssl_reuse.tdir/unbound_control.pem
new file mode 100644 (file)
index 0000000..a1edf70
--- /dev/null
@@ -0,0 +1,22 @@
+-----BEGIN CERTIFICATE-----
+MIIDszCCAhsCFGD5193whHQ2bVdzbaQfdf1gc4SkMA0GCSqGSIb3DQEBCwUAMBIx
+EDAOBgNVBAMMB3VuYm91bmQwHhcNMjAwNzA4MTMzMjMwWhcNNDAwMzI1MTMzMjMw
+WjAaMRgwFgYDVQQDDA91bmJvdW5kLWNvbnRyb2wwggGiMA0GCSqGSIb3DQEBAQUA
+A4IBjwAwggGKAoIBgQCy0Sn4/KHxcau1nvsDgWFiO9t4Hd0xrtDasZbGhvOUD2mv
+OEDVoKEC9S0I4C4z6sHo1M0HxhZ9kltAdrDIw2mYLvtyDq9ctgIZRAdnICqJ03Tj
+1EkXlPuPg3xWeK/XsuJF2vRLqzDLg9G8Scg89XjcRAdmoLmNW8ewqSEh+YEX8OPl
+NdHKl5rBZX+bmN5Tr/gdFgx/K0Fl07WY9e5YuHSWBtDhIJuCs5RUPeueIyTXJkht
+A6a+UMdip6SMNv+85bYrFRAsbThpkwnWZZ91vAbQIpCRKMhIQNnWXvq+EzqZMzR/
+Bdsi/IVn3I88KV7WYXlpKXFLZyYa4ZVJFBrDxcX197dr0AIklOvfcd1KnJpmQpEB
+TMtwqosKXfbd1oq/c3DABPTdOPiJAzjXoBIyiLJ8Vr/YZZMpBWN127wKtqvu0Zp/
+nGuWKDgMGasG91gDeePLvb9EPvWEvCaVGgIZTt1G4Ov07ooBJSbVGL3U41n+p2My
++i/XmXa+PgZX4pdHTR0CAwEAATANBgkqhkiG9w0BAQsFAAOCAYEAd++Wen6l8Ifj
+4h3p/y16PhSsWJWuJ4wdNYy3/GM84S26wGjzlEEwiW76HpH6VJzPOiBAeWnFKE83
+hFyetEIxgJeIPbcs9ZP/Uoh8GZH9tRISBSN9Hgk2Slr9llo4t1H0g/XTgA5HqMQU
+9YydlBh43G7Vw3FVwh09OM6poNOGQKNc/tq2/QdKeUMtyBbLWpRmjH5XcCT35fbn
+ZiVOUldqSHD4kKrFO4nJYXZyipRbcXybsLiX9GP0GLemc3IgIvOXyJ2RPp06o/SJ
+pzlMlkcAfLJaSuEW57xRakhuNK7m051TKKzJzIEX+NFYOVdafFHS8VwGrYsdrFvD
+72tMfu+Fu55y3awdWWGc6YlaGogZiuMnJkvQphwgn+5qE/7CGEckoKEsH601rqIZ
+muaIc85+nEcHJeijd/ZlBN9zeltjFoMuqTUENgmv8+tUAdVm/UMY9Vjme6b43ydP
+uv6DS02+k9z8toxXworLiPr94BGaiGV1NxgwZKLZigYJt/Fi2Qte
+-----END CERTIFICATE-----
diff --git a/testdata/ssl_reuse.tdir/unbound_server.key b/testdata/ssl_reuse.tdir/unbound_server.key
new file mode 100644 (file)
index 0000000..370a7bb
--- /dev/null
@@ -0,0 +1,39 @@
+-----BEGIN RSA PRIVATE KEY-----
+MIIG5AIBAAKCAYEAvjSVSN2QMXudpzukdLCqgg/IOhCX8KYkD0FFFfWcQjgKq5wI
+0x41iG32a6wbGanre4IX7VxaSPu9kkHfnGgynCk5nwDRedE/FLFhAU78PoT0+Nqq
+GRS7XVQ24vLmIz9Hqc2Ozx1um1BXBTmIT0UfN2e22I0LWQ6a3seZlEDRj45gnk7Z
+uh9MDgotaBdm+v1JAbupSf6Zis4VEH3JNdvVGE3O1DHEIeuuz/3BDhpf6WBDH+8K
+WaBe1ca4TZHr9ThL2gEMEfAQl0wXDwRWRoi3NjNMH+mw0L1rjwThI5GXqNIee7o5
+FzUReSXZuTdFMyGe3Owcx+XoYnwi6cplSNoGsDBu4B9bKKglR9YleJVw4L4Xi8xP
+q6O9UPj4+nypHk/DOoC7DIM3ufN0yxPBsFo5TVowxfhdjZXJbbftd2TZv7AH8+XL
+A5UoZgRzXgzECelXSCTBFlMTnT48LfA9pMLydyjAz2UdPHs5Iv+TK5nnI+aJoeaP
+7kFZSngxdy1+A/bNAgMBAAECggGBALpTOIqQwVg4CFBylL/a8K1IWJTI/I65sklf
+XxYL7G7SB2HlEJ//z+E+F0+S4Vlao1vyLQ5QkgE82pAUB8FoMWvY1qF0Y8A5wtm6
+iZSGk4OLK488ZbT8Ii9i+AGKgPe2XbVxsJwj8N4k7Zooqec9hz73Up8ATEWJkRz7
+2u7oMGG4z91E0PULA64dOi3l/vOQe5w/Aa+CwVbAWtI05o7kMvQEBMDJn6C7CByo
+MB5op9wueJMnz7PM7hns+U7Dy6oE4ljuolJUy51bDzFWwoM54cRoQqLFNHd8JVQj
+WxldCkbfF43iyprlsEcUrTyUjtdA+ZeiG39vg/mtdmgNpGmdupHJZQvSuG8IcVlz
+O+eMSeQS1QXPD6Ik8UK4SU0h+zOl8xIWtRrsxQuh4fnTN40udm/YUWl/6gOebsBI
+IrVLlKGqJSfB3tMjpCRqdTzJ0dA9keVpkqm2ugZkxEf1+/efq/rFIQ2pUBLCqNTN
+qpNqruK8y8FphP30I2uI4Ej2UIB8AQKBwQDd2Yptj2FyDyaXCycsyde0wYkNyzGU
+dRnzdibfHnMZwjgTjwAwgIUBVIS8H0/z7ZJQKN7osJfddMrtjJtYYUk9g/dCpHXs
+bNh2QSoWah3FdzNGuWd0iRf9+LFxhjAAMo/FS8zFJAJKrFsBdCGTfFUMdsLC0bjr
+YjiWBuvV72uKf8XIZX5KIZruKdWBBcWukcb21R1UDyFYyXRBsly5XHaIYKZql3km
+7pV7MKWO0IYgHbHIqGUqPQlzZ/lkunS1jKECgcEA23wHffD6Ou9/x3okPx2AWpTr
+gh8rgqbyo6hQkBW5Y90Wz824cqaYebZDaBR/xlVx/YwjKkohv8Bde2lpH/ZxRZ1Z
+5Sk2s6GJ/vU0L9RsJZgCgj4L6Coal1NMxuZtCXAlnOpiCdxSZgfqbshbTVz30KsG
+ZJG361Cua1ScdAHxlZBxT52/1Sm0zRC2hnxL7h4qo7Idmtzs40LAJvYOKekR0pPN
+oWeJfra7vgx/jVNvMFWoOoSLpidVO4g+ot4ery6tAoHAdW3rCic1C2zdnmH28Iw+
+s50l8Lk3mz+I5wgJd1zkzCO0DxZIoWPGA3g7cmCYr6N3KRsZMs4W9NAXgjpFGDkW
+zYsG3K21BdpvkdjYcFjnPVjlOXB2RIc0vehf9Jl02wXoeCSxVUDEPcaRvWk9RJYx
+ZpGOchUU7vNkxHURbIJ4yCzuAi9G8/Jp0dsu+kaV5tufF5SjG5WOrzKjaQsCbdN1
+oqaWMCHRrTvov/Z2C+xwsptFOdN5CSyZzg6hQiI4GMlBAoHAXyb6KINcOEi0YMp3
+BFXJ23tMTnEs78tozcKeipigcsbaqORK3omS+NEnj+uzKUzJyl4CsMbKstK2tFYS
+mSTCHqgE3PBtIpsZtEqhgUraR8IK9GPpzZDTTl9ynZgwFTNlWw3RyuyVXF56J+T8
+kCGJ3hEHCHqT/ZRQyX85BKIDFhA0z4tYKxWVqIFiYBNq56R0X9tMMmMs36mEnF93
+7Ht6mowxTZQRa7nU0qOgeKh/P7ki4Zus3y+WJ+T9IqahLtlRAoHBAIhqMrcxSAB8
+RpB9jukJlAnidw2jCMPgrFE8tP0khhVvGrXMldxAUsMKntDIo8dGCnG1KTcWDI0O
+jepvSPHSsxVLFugL79h0eVIS5z4huW48i9xgU8VlHdgAcgEPIAOFcOw2BCu/s0Vp
+O+MM/EyUOdo3NsibB3qc/GJI6iNBYS7AljYEVo6rXo5V/MZvZUF4vClen6Obzsre
+MTTb+4sJjfqleWuvr1XNMeu2mBfXBQkWGZP1byBK0MvD/aQ2PWq92A==
+-----END RSA PRIVATE KEY-----
diff --git a/testdata/ssl_reuse.tdir/unbound_server.pem b/testdata/ssl_reuse.tdir/unbound_server.pem
new file mode 100644 (file)
index 0000000..9868073
--- /dev/null
@@ -0,0 +1,22 @@
+-----BEGIN CERTIFICATE-----
+MIIDqzCCAhMCFBHWXeQ6ZIa9QcQbXLFfC6tj+KA+MA0GCSqGSIb3DQEBCwUAMBIx
+EDAOBgNVBAMMB3VuYm91bmQwHhcNMjAwNzA4MTMzMjI5WhcNNDAwMzI1MTMzMjI5
+WjASMRAwDgYDVQQDDAd1bmJvdW5kMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIB
+igKCAYEAvjSVSN2QMXudpzukdLCqgg/IOhCX8KYkD0FFFfWcQjgKq5wI0x41iG32
+a6wbGanre4IX7VxaSPu9kkHfnGgynCk5nwDRedE/FLFhAU78PoT0+NqqGRS7XVQ2
+4vLmIz9Hqc2Ozx1um1BXBTmIT0UfN2e22I0LWQ6a3seZlEDRj45gnk7Zuh9MDgot
+aBdm+v1JAbupSf6Zis4VEH3JNdvVGE3O1DHEIeuuz/3BDhpf6WBDH+8KWaBe1ca4
+TZHr9ThL2gEMEfAQl0wXDwRWRoi3NjNMH+mw0L1rjwThI5GXqNIee7o5FzUReSXZ
+uTdFMyGe3Owcx+XoYnwi6cplSNoGsDBu4B9bKKglR9YleJVw4L4Xi8xPq6O9UPj4
++nypHk/DOoC7DIM3ufN0yxPBsFo5TVowxfhdjZXJbbftd2TZv7AH8+XLA5UoZgRz
+XgzECelXSCTBFlMTnT48LfA9pMLydyjAz2UdPHs5Iv+TK5nnI+aJoeaP7kFZSngx
+dy1+A/bNAgMBAAEwDQYJKoZIhvcNAQELBQADggGBABunf93MKaCUHiZgnoOTinsW
+84/EgInrgtKzAyH+BhnKkJOhhR0kkIAx5d9BpDlaSiRTACFon9moWCgDIIsK/Ar7
+JE0Kln9cV//wiiNoFU0O4mnzyGUIMvlaEX6QHMJJQYvL05+w/3AAcf5XmMJtR5ca
+fJ8FqvGC34b2WxX9lTQoyT52sRt+1KnQikiMEnEyAdKktMG+MwKsFDdOwDXyZhZg
+XZhRrfX3/NVJolqB6EahjWIGXDeKuSSKZVtCyib6LskyeMzN5lcRfvubKDdlqFVF
+qlD7rHBsKhQUWK/IO64mGf7y/de+CgHtED5vDvr/p2uj/9sABATfbrOQR3W/Of25
+sLBj4OEfrJ7lX8hQgFaxkMI3x6VFT3W8dTCp7xnQgb6bgROWB5fNEZ9jk/gjSRmD
+yIU+r0UbKe5kBk/CmZVFXL2TyJ92V5NYEQh8V4DGy19qZ6u/XKYyNJL4ocs35GGe
+CA8SBuyrmdhx38h1RHErR2Skzadi1S7MwGf1y431fQ==
+-----END CERTIFICATE-----