source: mod_gnutls/debian/patches/0001-Fix-test-16-view-status-by-changing-priority-string.patch @ 5a0744e

debian/master
Last change on this file since 5a0744e was 5a0744e, checked in by Daniel Kahn Gillmor <dkg@…>, 14 months ago

Avoid deprecated ciphersuites in test suite (Closes: #907008)

  • Property mode set to 100644
File size: 1.7 KB
  • test/tests/16_view-status/gnutls-cli.args

    From: Sunil Mohan Adapa <sunil@medhas.org>
    Date: Tue, 18 Sep 2018 09:41:47 -0700
    Subject: Fix test 16-view-status by changing priority string
    
    From gnutls 3.5.19 release notes:
    
    "The ciphers utilizing HMAC-SHA384 and SHA256 have been removed from the default
    priority strings. They are not necessary for compatibility or other purpose and
    provide no advantage over their SHA1 counter-parts, as they all depend on the
    legacy TLS CBC block mode."
    
    Pick a new priority string such that the cipher suite matches the default
    negotiated by gnutls 3.5.19 server and client without explicitly setting a
    priority string.
    ---
     test/tests/16_view-status/gnutls-cli.args | 2 +-
     test/tests/16_view-status/output          | 2 +-
     2 files changed, 2 insertions(+), 2 deletions(-)
    
    diff --git a/test/tests/16_view-status/gnutls-cli.args b/test/tests/16_view-status/gnutls-cli.args
    index aca8ac0..470925b 100644
    a b  
    11--x509cafile=authority/x509.pem
    2 --priority=NONE:+VERS-TLS1.2:+AES-128-CBC:+SHA256:+RSA:+COMP-NULL:+SIGN-RSA-SHA256
     2--priority=NONE:+VERS-TLS1.2:+ECDHE-RSA:+CURVE-SECP256R1:+AES-256-GCM:+AEAD:+COMP-NULL:+SIGN-RSA-SHA1
  • test/tests/16_view-status/output

    diff --git a/test/tests/16_view-status/output b/test/tests/16_view-status/output
    index 7786244..8bfb45a 100644
    a b  
    11<dt>Using TLS:</dt><dd>yes</dd>
    2 <dt>Current TLS session:</dt><dd>(TLS1.2)-(RSA)-(AES-128-CBC)-(SHA256)</dd>
     2<dt>Current TLS session:</dt><dd>(TLS1.2)-(ECDHE-RSA-SECP256R1)-(AES-256-GCM)</dd>
    33</dl>
    44</body></html>
    55- Peer has closed the GnuTLS connection
Note: See TracBrowser for help on using the repository browser.