11cb0ef41Sopenharmony_ci// Copyright Joyent, Inc. and other Node contributors.
21cb0ef41Sopenharmony_ci//
31cb0ef41Sopenharmony_ci// Permission is hereby granted, free of charge, to any person obtaining a
41cb0ef41Sopenharmony_ci// copy of this software and associated documentation files (the
51cb0ef41Sopenharmony_ci// "Software"), to deal in the Software without restriction, including
61cb0ef41Sopenharmony_ci// without limitation the rights to use, copy, modify, merge, publish,
71cb0ef41Sopenharmony_ci// distribute, sublicense, and/or sell copies of the Software, and to permit
81cb0ef41Sopenharmony_ci// persons to whom the Software is furnished to do so, subject to the
91cb0ef41Sopenharmony_ci// following conditions:
101cb0ef41Sopenharmony_ci//
111cb0ef41Sopenharmony_ci// The above copyright notice and this permission notice shall be included
121cb0ef41Sopenharmony_ci// in all copies or substantial portions of the Software.
131cb0ef41Sopenharmony_ci//
141cb0ef41Sopenharmony_ci// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
151cb0ef41Sopenharmony_ci// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
161cb0ef41Sopenharmony_ci// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN
171cb0ef41Sopenharmony_ci// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
181cb0ef41Sopenharmony_ci// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
191cb0ef41Sopenharmony_ci// OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
201cb0ef41Sopenharmony_ci// USE OR OTHER DEALINGS IN THE SOFTWARE.
211cb0ef41Sopenharmony_ci
221cb0ef41Sopenharmony_ci'use strict';
231cb0ef41Sopenharmony_ciconst common = require('../common');
241cb0ef41Sopenharmony_ciif (!common.hasCrypto)
251cb0ef41Sopenharmony_ci  common.skip('missing crypto');
261cb0ef41Sopenharmony_ci
271cb0ef41Sopenharmony_ciconst assert = require('assert');
281cb0ef41Sopenharmony_ciconst tls = require('tls');
291cb0ef41Sopenharmony_ciconst fixtures = require('../common/fixtures');
301cb0ef41Sopenharmony_ci
311cb0ef41Sopenharmony_ci
321cb0ef41Sopenharmony_cifunction loadPEM(n) {
331cb0ef41Sopenharmony_ci  return fixtures.readKey(`${n}.pem`);
341cb0ef41Sopenharmony_ci}
351cb0ef41Sopenharmony_ci
361cb0ef41Sopenharmony_ciconst serverOptions = {
371cb0ef41Sopenharmony_ci  key: loadPEM('agent2-key'),
381cb0ef41Sopenharmony_ci  cert: loadPEM('agent2-cert')
391cb0ef41Sopenharmony_ci};
401cb0ef41Sopenharmony_ci
411cb0ef41Sopenharmony_ciconst SNIContexts = {
421cb0ef41Sopenharmony_ci  'a.example.com': {
431cb0ef41Sopenharmony_ci    key: loadPEM('agent1-key'),
441cb0ef41Sopenharmony_ci    cert: loadPEM('agent1-cert')
451cb0ef41Sopenharmony_ci  },
461cb0ef41Sopenharmony_ci  'asterisk.test.com': {
471cb0ef41Sopenharmony_ci    key: loadPEM('agent3-key'),
481cb0ef41Sopenharmony_ci    cert: loadPEM('agent3-cert')
491cb0ef41Sopenharmony_ci  },
501cb0ef41Sopenharmony_ci  'chain.example.com': {
511cb0ef41Sopenharmony_ci    key: loadPEM('agent6-key'),
521cb0ef41Sopenharmony_ci    // NOTE: Contains ca3 chain cert
531cb0ef41Sopenharmony_ci    cert: loadPEM('agent6-cert')
541cb0ef41Sopenharmony_ci  }
551cb0ef41Sopenharmony_ci};
561cb0ef41Sopenharmony_ci
571cb0ef41Sopenharmony_citest(
581cb0ef41Sopenharmony_ci  {
591cb0ef41Sopenharmony_ci    ca: [loadPEM('ca1-cert')],
601cb0ef41Sopenharmony_ci    servername: 'a.example.com'
611cb0ef41Sopenharmony_ci  },
621cb0ef41Sopenharmony_ci  true,
631cb0ef41Sopenharmony_ci  'a.example.com'
641cb0ef41Sopenharmony_ci);
651cb0ef41Sopenharmony_ci
661cb0ef41Sopenharmony_citest(
671cb0ef41Sopenharmony_ci  {
681cb0ef41Sopenharmony_ci    ca: [loadPEM('ca2-cert')],
691cb0ef41Sopenharmony_ci    servername: 'b.test.com',
701cb0ef41Sopenharmony_ci  },
711cb0ef41Sopenharmony_ci  true,
721cb0ef41Sopenharmony_ci  'b.test.com'
731cb0ef41Sopenharmony_ci);
741cb0ef41Sopenharmony_ci
751cb0ef41Sopenharmony_citest(
761cb0ef41Sopenharmony_ci  {
771cb0ef41Sopenharmony_ci    ca: [loadPEM('ca2-cert')],
781cb0ef41Sopenharmony_ci    servername: 'a.b.test.com',
791cb0ef41Sopenharmony_ci  },
801cb0ef41Sopenharmony_ci  false,
811cb0ef41Sopenharmony_ci  'a.b.test.com'
821cb0ef41Sopenharmony_ci);
831cb0ef41Sopenharmony_ci
841cb0ef41Sopenharmony_citest(
851cb0ef41Sopenharmony_ci  {
861cb0ef41Sopenharmony_ci    ca: [loadPEM('ca1-cert')],
871cb0ef41Sopenharmony_ci    servername: 'c.wrong.com',
881cb0ef41Sopenharmony_ci  },
891cb0ef41Sopenharmony_ci  false,
901cb0ef41Sopenharmony_ci  'c.wrong.com'
911cb0ef41Sopenharmony_ci);
921cb0ef41Sopenharmony_ci
931cb0ef41Sopenharmony_citest(
941cb0ef41Sopenharmony_ci  {
951cb0ef41Sopenharmony_ci    ca: [loadPEM('ca1-cert')],
961cb0ef41Sopenharmony_ci    servername: 'chain.example.com',
971cb0ef41Sopenharmony_ci  },
981cb0ef41Sopenharmony_ci  true,
991cb0ef41Sopenharmony_ci  'chain.example.com'
1001cb0ef41Sopenharmony_ci);
1011cb0ef41Sopenharmony_ci
1021cb0ef41Sopenharmony_cifunction test(options, clientResult, serverResult) {
1031cb0ef41Sopenharmony_ci  const server = tls.createServer(serverOptions, (c) => {
1041cb0ef41Sopenharmony_ci    assert.strictEqual(c.servername, serverResult);
1051cb0ef41Sopenharmony_ci    assert.strictEqual(c.authorized, false);
1061cb0ef41Sopenharmony_ci  });
1071cb0ef41Sopenharmony_ci
1081cb0ef41Sopenharmony_ci  server.addContext('a.example.com', SNIContexts['a.example.com']);
1091cb0ef41Sopenharmony_ci  server.addContext('*.test.com', SNIContexts['asterisk.test.com']);
1101cb0ef41Sopenharmony_ci  server.addContext('chain.example.com', SNIContexts['chain.example.com']);
1111cb0ef41Sopenharmony_ci
1121cb0ef41Sopenharmony_ci  server.on('tlsClientError', common.mustNotCall());
1131cb0ef41Sopenharmony_ci
1141cb0ef41Sopenharmony_ci  server.listen(0, () => {
1151cb0ef41Sopenharmony_ci    const client = tls.connect({
1161cb0ef41Sopenharmony_ci      ...options,
1171cb0ef41Sopenharmony_ci      port: server.address().port,
1181cb0ef41Sopenharmony_ci      rejectUnauthorized: false
1191cb0ef41Sopenharmony_ci    }, () => {
1201cb0ef41Sopenharmony_ci      const result = client.authorizationError &&
1211cb0ef41Sopenharmony_ci        (client.authorizationError === 'ERR_TLS_CERT_ALTNAME_INVALID');
1221cb0ef41Sopenharmony_ci      assert.strictEqual(result, clientResult);
1231cb0ef41Sopenharmony_ci      client.end();
1241cb0ef41Sopenharmony_ci    });
1251cb0ef41Sopenharmony_ci
1261cb0ef41Sopenharmony_ci    client.on('close', common.mustCall(() => {
1271cb0ef41Sopenharmony_ci      server.close();
1281cb0ef41Sopenharmony_ci    }));
1291cb0ef41Sopenharmony_ci  });
1301cb0ef41Sopenharmony_ci}
131