1// Copyright Joyent, Inc. and other Node contributors.
2//
3// Permission is hereby granted, free of charge, to any person obtaining a
4// copy of this software and associated documentation files (the
5// "Software"), to deal in the Software without restriction, including
6// without limitation the rights to use, copy, modify, merge, publish,
7// distribute, sublicense, and/or sell copies of the Software, and to permit
8// persons to whom the Software is furnished to do so, subject to the
9// following conditions:
10//
11// The above copyright notice and this permission notice shall be included
12// in all copies or substantial portions of the Software.
13//
14// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
15// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
16// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN
17// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
18// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
19// OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
20// USE OR OTHER DEALINGS IN THE SOFTWARE.
21
22'use strict';
23const common = require('../common');
24if (!common.hasCrypto)
25  common.skip('missing crypto');
26
27const assert = require('assert');
28const tls = require('tls');
29const fixtures = require('../common/fixtures');
30
31const options = {
32  key: fixtures.readKey('rsa_private.pem'),
33  cert: fixtures.readKey('rsa_cert.crt')
34};
35
36const server = tls.createServer(options, function(cleartext) {
37  cleartext.end('World');
38});
39
40server.once('secureConnection', common.mustCall(function(socket) {
41  const cert = socket.getCertificate();
42  // The server's local cert is the client's peer cert.
43  assert.deepStrictEqual(
44    cert.subject.OU,
45    ['Test TLS Certificate', 'Engineering']
46  );
47}));
48
49server.listen(0, common.mustCall(function() {
50  const socket = tls.connect({
51    port: this.address().port,
52    rejectUnauthorized: false
53  }, common.mustCall(function() {
54    const peerCert = socket.getPeerCertificate();
55    assert.deepStrictEqual(
56      peerCert.subject.OU,
57      ['Test TLS Certificate', 'Engineering']
58    );
59    server.close();
60  }));
61  socket.end('Hello');
62}));
63