1// Copyright Joyent, Inc. and other Node contributors.
2//
3// Permission is hereby granted, free of charge, to any person obtaining a
4// copy of this software and associated documentation files (the
5// "Software"), to deal in the Software without restriction, including
6// without limitation the rights to use, copy, modify, merge, publish,
7// distribute, sublicense, and/or sell copies of the Software, and to permit
8// persons to whom the Software is furnished to do so, subject to the
9// following conditions:
10//
11// The above copyright notice and this permission notice shall be included
12// in all copies or substantial portions of the Software.
13//
14// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
15// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
16// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN
17// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
18// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
19// OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
20// USE OR OTHER DEALINGS IN THE SOFTWARE.
21
22'use strict';
23const common = require('../common');
24const fixtures = require('../common/fixtures');
25
26if (!common.hasCrypto)
27  common.skip('missing crypto');
28
29if (!common.opensslCli)
30  common.skip('missing openssl-cli');
31
32const assert = require('assert');
33const tls = require('tls');
34
35const exec = require('child_process').exec;
36
37const options = {
38  key: fixtures.readKey('agent2-key.pem'),
39  cert: fixtures.readKey('agent2-cert.pem'),
40  ciphers: '-ALL:ECDHE-RSA-AES128-SHA256',
41  ecdhCurve: 'prime256v1',
42  maxVersion: 'TLSv1.2'
43};
44
45const reply = 'I AM THE WALRUS'; // Something recognizable
46
47const server = tls.createServer(options, common.mustCall(function(conn) {
48  conn.end(reply);
49}));
50
51server.listen(0, '127.0.0.1', common.mustCall(function() {
52  const cmd = `"${common.opensslCli}" s_client -cipher ${
53    options.ciphers} -connect 127.0.0.1:${this.address().port}`;
54
55  exec(cmd, common.mustSucceed((stdout, stderr) => {
56    assert(stdout.includes(reply));
57    server.close();
58  }));
59}));
60