Home | History | Annotate | Line # | Download | only in scripts
test066-autoca revision 1.1.1.2
      1      1.1  christos #! /bin/sh
      2      1.1  christos # $OpenLDAP$
      3      1.1  christos ## This work is part of OpenLDAP Software <http://www.openldap.org/>.
      4      1.1  christos ##
      5  1.1.1.2  christos ## Copyright 1998-2024 The OpenLDAP Foundation.
      6      1.1  christos ## All rights reserved.
      7      1.1  christos ##
      8      1.1  christos ## Redistribution and use in source and binary forms, with or without
      9      1.1  christos ## modification, are permitted only as authorized by the OpenLDAP
     10      1.1  christos ## Public License.
     11      1.1  christos ##
     12      1.1  christos ## A copy of this license is available in the file LICENSE in the
     13      1.1  christos ## top-level directory of the distribution or, alternatively, at
     14      1.1  christos ## <http://www.OpenLDAP.org/license.html>.
     15      1.1  christos 
     16      1.1  christos echo "running defines.sh"
     17      1.1  christos . $SRCDIR/scripts/defines.sh
     18      1.1  christos 
     19      1.1  christos if test $AUTOCA = autocano; then 
     20      1.1  christos 	echo "Automatic CA overlay not available, test skipped"
     21      1.1  christos 	exit 0
     22      1.1  christos fi 
     23      1.1  christos 
     24  1.1.1.2  christos if test $BACKEND = ldif ; then
     25  1.1.1.2  christos 	# autoca tries to modify an entry in a search response,
     26  1.1.1.2  christos 	# which deadlocks because the tree is readlocked by the search.
     27  1.1.1.2  christos 	echo "Test does not support $BACKEND backend, test skipped"
     28  1.1.1.2  christos 	exit 0
     29  1.1.1.2  christos fi
     30  1.1.1.2  christos 
     31      1.1  christos CFDIR=$TESTDIR/slapd.d
     32      1.1  christos 
     33      1.1  christos mkdir -p $TESTDIR $CFDIR $DBDIR1
     34      1.1  christos 
     35      1.1  christos $SLAPPASSWD -g -n >$CONFIGPWF
     36      1.1  christos 
     37      1.1  christos #
     38      1.1  christos # Test operation of autoca:
     39      1.1  christos # - configure over ldap without TLS
     40      1.1  christos # - populate over ldap
     41      1.1  christos # - add host entry
     42      1.1  christos # - add autoca overlay
     43      1.1  christos # - generate server and user certs
     44      1.1  christos # - check for TLS operation
     45      1.1  christos #
     46      1.1  christos 
     47      1.1  christos echo "Starting slapd on TCP/IP port $PORT1..."
     48      1.1  christos . $CONFFILTER $BACKEND < $DYNAMICCONF > $CONFLDIF
     49      1.1  christos $SLAPADD -F $CFDIR -n 0 -l $CONFLDIF
     50  1.1.1.2  christos RC=$?
     51  1.1.1.2  christos if test $RC != 0 ; then
     52  1.1.1.2  christos 	echo "slapadd failed ($RC)!"
     53  1.1.1.2  christos 	exit $RC
     54  1.1.1.2  christos fi
     55  1.1.1.2  christos 
     56      1.1  christos $SLAPD -F $CFDIR -h $URIP1 -d $LVL > $LOG1 2>&1 &
     57      1.1  christos PID=$!
     58      1.1  christos if test $WAIT != 0 ; then
     59      1.1  christos     echo PID $PID
     60      1.1  christos     read foo
     61      1.1  christos fi
     62      1.1  christos KILLPIDS="$PID"
     63      1.1  christos cd $TESTWD
     64      1.1  christos 
     65      1.1  christos sleep 1
     66      1.1  christos 
     67      1.1  christos echo "Using ldapsearch to check that slapd is running..."
     68      1.1  christos for i in 0 1 2 3 4 5; do
     69      1.1  christos 	$LDAPSEARCH -s base -b "" -H $URIP1 \
     70      1.1  christos 		'objectclass=*' > /dev/null 2>&1
     71      1.1  christos 	RC=$?
     72      1.1  christos 	if test $RC = 0 ; then
     73      1.1  christos 		break
     74      1.1  christos 	fi
     75      1.1  christos 	echo "Waiting 5 seconds for slapd to start..."
     76      1.1  christos 	sleep 5
     77      1.1  christos done
     78      1.1  christos 
     79      1.1  christos if test $RC != 0 ; then
     80      1.1  christos 	echo "ldapsearch failed ($RC)!"
     81      1.1  christos 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
     82      1.1  christos 	exit $RC
     83      1.1  christos fi
     84      1.1  christos 
     85      1.1  christos echo "Adding schema and databases on slapd..."
     86      1.1  christos $LDAPADD -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >>$TESTOUT 2>&1
     87      1.1  christos include: file://$ABS_SCHEMADIR/core.ldif
     88      1.1  christos 
     89      1.1  christos include: file://$ABS_SCHEMADIR/cosine.ldif
     90      1.1  christos 
     91      1.1  christos include: file://$ABS_SCHEMADIR/inetorgperson.ldif
     92      1.1  christos 
     93      1.1  christos include: file://$ABS_SCHEMADIR/openldap.ldif
     94      1.1  christos 
     95      1.1  christos include: file://$ABS_SCHEMADIR/nis.ldif
     96      1.1  christos EOF
     97      1.1  christos RC=$?
     98      1.1  christos if test $RC != 0 ; then
     99      1.1  christos 	echo "ldapadd failed for schema config ($RC)!"
    100      1.1  christos 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    101      1.1  christos 	exit $RC
    102      1.1  christos fi
    103      1.1  christos 
    104      1.1  christos nullExclude="" nullOK=""
    105      1.1  christos test $BACKEND = null && nullExclude="# " nullOK="OK"
    106      1.1  christos 
    107      1.1  christos if [ "$BACKENDTYPE" = mod ]; then
    108      1.1  christos 	$LDAPADD -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >>$TESTOUT 2>&1
    109      1.1  christos dn: cn=module,cn=config
    110      1.1  christos objectClass: olcModuleList
    111      1.1  christos cn: module
    112      1.1  christos olcModulePath: $TESTWD/../servers/slapd/back-$BACKEND
    113      1.1  christos olcModuleLoad: back_$BACKEND.la
    114      1.1  christos EOF
    115      1.1  christos 	RC=$?
    116      1.1  christos 	if test $RC != 0 ; then
    117      1.1  christos 		echo "ldapadd failed for backend config ($RC)!"
    118      1.1  christos 		test $KILLSERVERS != no && kill -HUP $KILLPIDS
    119      1.1  christos 		exit $RC
    120      1.1  christos 	fi
    121      1.1  christos fi
    122      1.1  christos 
    123      1.1  christos $LDAPADD -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >>$TESTOUT 2>&1
    124      1.1  christos dn: olcDatabase={1}$BACKEND,cn=config
    125      1.1  christos objectClass: olcDatabaseConfig
    126      1.1  christos ${nullExclude}objectClass: olc${BACKEND}Config
    127      1.1  christos olcDatabase: {1}$BACKEND
    128      1.1  christos olcSuffix: $BASEDN
    129      1.1  christos ${nullExclude}olcDbDirectory: $DBDIR1
    130      1.1  christos olcRootDN: $MANAGERDN
    131      1.1  christos olcRootPW: $PASSWD
    132      1.1  christos EOF
    133      1.1  christos RC=$?
    134      1.1  christos if test $RC != 0 ; then
    135      1.1  christos 	echo "ldapadd failed for database config ($RC)!"
    136      1.1  christos 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    137      1.1  christos 	exit $RC
    138      1.1  christos fi
    139      1.1  christos 
    140      1.1  christos if test $INDEXDB = indexdb ; then
    141      1.1  christos 	$LDAPMODIFY -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >>$TESTOUT 2>&1
    142      1.1  christos dn: olcDatabase={1}$BACKEND,cn=config
    143      1.1  christos changetype: modify
    144      1.1  christos add: olcDbIndex
    145      1.1  christos olcDbIndex: objectClass,entryUUID,entryCSN eq
    146      1.1  christos olcDbIndex: cn,uid pres,eq,sub
    147      1.1  christos EOF
    148      1.1  christos 	RC=$?
    149      1.1  christos 	if test $RC != 0 ; then
    150      1.1  christos 		echo "ldapadd modify for database config ($RC)!"
    151      1.1  christos 		test $KILLSERVERS != no && kill -HUP $KILLPIDS
    152      1.1  christos 		exit $RC
    153      1.1  christos 	fi
    154      1.1  christos fi
    155      1.1  christos 
    156      1.1  christos echo "Using ldapadd to populate slapd..."
    157      1.1  christos $LDAPADD -D "$MANAGERDN" -H $URIP1 -w $PASSWD -f $LDIFORDERED \
    158      1.1  christos 	>> $TESTOUT 2>&1
    159      1.1  christos RC=$?
    160      1.1  christos if test $RC != 0 ; then
    161      1.1  christos 	echo "ldapadd failed for database populate ($RC)!"
    162      1.1  christos 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    163      1.1  christos 	exit $RC
    164      1.1  christos fi
    165      1.1  christos 
    166      1.1  christos echo "Adding server entries to slapd..."
    167      1.1  christos $LDAPADD -D "$MANAGERDN" -H $URIP1 -w $PASSWD <<EOF >> $TESTOUT 2>&1
    168      1.1  christos dn: ou=Servers,$BASEDN
    169      1.1  christos objectClass: organizationalUnit
    170      1.1  christos ou: Servers
    171      1.1  christos 
    172      1.1  christos dn: cn=localhost,ou=Servers,$BASEDN
    173      1.1  christos objectClass: device
    174      1.1  christos objectClass: ipHost
    175      1.1  christos cn: localhost
    176      1.1  christos ipHostNumber: 127.0.0.1
    177      1.1  christos 
    178      1.1  christos dn: cn=www.example.com,ou=Servers,$BASEDN
    179      1.1  christos objectClass: device
    180      1.1  christos objectClass: ipHost
    181      1.1  christos cn: localhost
    182      1.1  christos ipHostNumber: 93.184.216.34
    183      1.1  christos EOF
    184      1.1  christos RC=$?
    185      1.1  christos if test $RC != 0 ; then
    186      1.1  christos 	echo "ldapadd failed for database populate ($RC)!"
    187      1.1  christos 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    188      1.1  christos 	exit $RC
    189      1.1  christos fi
    190      1.1  christos 
    191      1.1  christos echo "Inserting autoca overlay on slapd..."
    192      1.1  christos if [ "$AUTOCA" = autocamod ]; then
    193      1.1  christos 	$LDAPADD -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF > $TESTOUT 2>&1
    194      1.1  christos dn: cn=module,cn=config
    195      1.1  christos objectClass: olcModuleList
    196      1.1  christos cn: module
    197      1.1  christos olcModulePath: $TESTWD/../servers/slapd/overlays
    198      1.1  christos olcModuleLoad: autoca.la
    199      1.1  christos EOF
    200      1.1  christos 	RC=$?
    201      1.1  christos 	if test $RC != 0 ; then
    202      1.1  christos 		echo "ldapadd failed for moduleLoad ($RC)!"
    203      1.1  christos 		test $KILLSERVERS != no && kill -HUP $KILLPIDS
    204      1.1  christos 		exit $RC
    205      1.1  christos 	fi
    206      1.1  christos fi
    207      1.1  christos $LDAPMODIFY -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >> $TESTOUT 2>&1
    208      1.1  christos dn: olcOverlay=autoca,olcDatabase={1}$BACKEND,cn=config
    209      1.1  christos changetype: add
    210      1.1  christos objectClass: olcOverlayConfig
    211      1.1  christos objectClass: olcAutoCAConfig
    212      1.1  christos olcOverlay: autoca
    213      1.1  christos olcAutoCAlocalDN: cn=localhost,ou=Servers,$BASEDN
    214      1.1  christos EOF
    215      1.1  christos RC=$?
    216      1.1  christos if test $RC != 0 ; then
    217      1.1  christos 	echo "ldapmodify failed for autoca config ($RC)!"
    218      1.1  christos 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    219      1.1  christos 	exit $RC
    220      1.1  christos fi
    221      1.1  christos echo "Using ldapsearch to retrieve CA cert..."
    222      1.1  christos $LDAPSEARCH -b $BASEDN -D $MANAGERDN -H $URIP1 -w $PASSWD -s base \
    223      1.1  christos 	'objectclass=*' 'cACertificate;binary'  > $SEARCHOUT 2>&1
    224      1.1  christos RC=$?
    225      1.1  christos 
    226      1.1  christos if test $RC != 0 ; then
    227      1.1  christos 	echo "ldapsearch failed ($RC)!"
    228      1.1  christos 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    229      1.1  christos 	exit $RC
    230      1.1  christos fi
    231      1.1  christos 
    232      1.1  christos echo "Setting up CA cert..."
    233      1.1  christos echo "-----BEGIN CERTIFICATE-----" > $TESTDIR/cacert.pem
    234      1.1  christos sed -e "/^dn:/d" -e "s/cACertificate;binary:://" -e "/^$/d" $SEARCHOUT >> $TESTDIR/cacert.pem
    235      1.1  christos echo "-----END CERTIFICATE-----" >> $TESTDIR/cacert.pem
    236      1.1  christos 
    237      1.1  christos echo "Using ldapsearch to generate localhost cert..."
    238      1.1  christos $LDAPSEARCH -b cn=localhost,ou=Servers,$BASEDN -D $MANAGERDN -H $URIP1 -w $PASSWD -s base \
    239      1.1  christos 	-A 'objectclass=*' 'userCertificate;binary' 'userPrivateKey;binary'  >> $TESTOUT 2>&1
    240      1.1  christos RC=$?
    241      1.1  christos 
    242      1.1  christos if test $RC != 0 ; then
    243      1.1  christos 	echo "ldapsearch failed ($RC)!"
    244      1.1  christos 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    245      1.1  christos 	exit $RC
    246      1.1  christos fi
    247      1.1  christos 
    248      1.1  christos echo "Using ldapsearch to attempt TLS..."
    249      1.1  christos unset LDAPNOINIT
    250      1.1  christos LDAPTLS_CACERT=$TESTDIR/cacert.pem
    251      1.1  christos export LDAPTLS_CACERT
    252      1.1  christos $LDAPSEARCH -b $BASEDN -D $MANAGERDN -H $URIP1 -w $PASSWD -s base -ZZ \
    253      1.1  christos 	'objectclass=*' >> $TESTOUT 2>&1
    254      1.1  christos RC=$?
    255      1.1  christos 
    256      1.1  christos if test $RC != 0 ; then
    257      1.1  christos 	echo "ldapsearch failed ($RC)!"
    258      1.1  christos 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    259      1.1  christos 	exit $RC
    260      1.1  christos fi
    261      1.1  christos 
    262      1.1  christos if test $WITH_SASL = no ; then
    263      1.1  christos 	echo "SASL support not available, skipping client cert authentication"
    264      1.1  christos else
    265      1.1  christos 	# note - the attrs are being saved in raw DER form.
    266      1.1  christos 	# they need to be base64 encoded into PEM for most programs to use them
    267      1.1  christos 	# so we ignore those files for now.
    268      1.1  christos 	echo "Using ldapsearch to generate user cert..."
    269      1.1  christos 	$LDAPSEARCH -b "$BABSDN" -D $MANAGERDN -H $URIP1 -w $PASSWD -s base -ZZ \
    270      1.1  christos 		-T $TESTDIR -t 'objectclass=*' 'userCertificate;binary' 'userPrivateKey;binary'  >> $TESTOUT 2>&1
    271      1.1  christos 	RC=$?
    272      1.1  christos 
    273      1.1  christos 	if test $RC != 0 ; then
    274      1.1  christos 		echo "ldapsearch failed ($RC)!"
    275      1.1  christos 		test $KILLSERVERS != no && kill -HUP $KILLPIDS
    276      1.1  christos 		exit $RC
    277      1.1  christos 	fi
    278      1.1  christos 
    279      1.1  christos 	echo "Using ldapsearch to retrieve user cert..."
    280      1.1  christos 	$LDAPSEARCH -b "$BABSDN" -D $MANAGERDN -H $URIP1 -w $PASSWD -s base -ZZ \
    281      1.1  christos 		'objectclass=*' 'userCertificate;binary' > $SEARCHOUT 2>&1
    282      1.1  christos 	RC=$?
    283      1.1  christos 
    284      1.1  christos 	if test $RC != 0 ; then
    285      1.1  christos 		echo "ldapsearch failed ($RC)!"
    286      1.1  christos 		test $KILLSERVERS != no && kill -HUP $KILLPIDS
    287      1.1  christos 		exit $RC
    288      1.1  christos 	fi
    289      1.1  christos 
    290      1.1  christos 	echo "Setting up user cert..."
    291      1.1  christos 	echo "-----BEGIN CERTIFICATE-----" > $TESTDIR/usercert.pem
    292      1.1  christos 	sed -e "/^dn:/d" -e "/^ dc=com/d" -e "s/userCertificate;binary:://" -e "/^$/d" $SEARCHOUT >> $TESTDIR/usercert.pem
    293      1.1  christos 	echo "-----END CERTIFICATE-----" >> $TESTDIR/usercert.pem
    294      1.1  christos 
    295      1.1  christos 	echo "Using ldapsearch to retrieve user key..."
    296      1.1  christos 	$LDAPSEARCH -b "$BABSDN" -D $MANAGERDN -H $URIP1 -w $PASSWD -s base -ZZ \
    297      1.1  christos 		'objectclass=*' 'userPrivateKey;binary' > $SEARCHOUT 2>&1
    298      1.1  christos 	RC=$?
    299      1.1  christos 
    300      1.1  christos 	if test $RC != 0 ; then
    301      1.1  christos 		echo "ldapsearch failed ($RC)!"
    302      1.1  christos 		test $KILLSERVERS != no && kill -HUP $KILLPIDS
    303      1.1  christos 		exit $RC
    304      1.1  christos 	fi
    305      1.1  christos 
    306      1.1  christos 	echo "Setting up user key..."
    307      1.1  christos 	echo "-----BEGIN PRIVATE KEY-----" > $TESTDIR/userkey.pem
    308      1.1  christos 	sed -e "/^dn:/d" -e "/^ dc=com/d" -e "s/userPrivateKey;binary:://" -e "/^$/d" $SEARCHOUT >> $TESTDIR/userkey.pem
    309      1.1  christos 	echo "-----END PRIVATE KEY-----" >> $TESTDIR/userkey.pem
    310      1.1  christos 
    311      1.1  christos 	LDAPTLS_CERT=$TESTDIR/usercert.pem
    312      1.1  christos 	LDAPTLS_KEY=$TESTDIR/userkey.pem
    313      1.1  christos 	export LDAPTLS_CERT
    314      1.1  christos 	export LDAPTLS_KEY
    315      1.1  christos 
    316      1.1  christos 	echo "Setting TLSVerifyClient to try..."
    317      1.1  christos 	$LDAPMODIFY -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >> $TESTOUT 2>&1
    318      1.1  christos dn: cn=config
    319      1.1  christos changetype: modify
    320      1.1  christos replace: olcTLSVerifyClient
    321      1.1  christos olcTLSVerifyClient: try
    322      1.1  christos EOF
    323      1.1  christos 	RC=$?
    324      1.1  christos 	if test $RC != 0 ; then
    325      1.1  christos 		echo "ldapmodify failed for autoca config ($RC)!"
    326      1.1  christos 		test $KILLSERVERS != no && kill -HUP $KILLPIDS
    327      1.1  christos 		exit $RC
    328      1.1  christos 	fi
    329      1.1  christos 
    330      1.1  christos 	$CLIENTDIR/ldapwhoami -Y EXTERNAL -H $URIP1 -ZZ
    331      1.1  christos 
    332      1.1  christos 	if test $RC != 0 ; then
    333      1.1  christos 		echo "ldapwhoami failed ($RC)!"
    334      1.1  christos 		test $KILLSERVERS != no && kill -HUP $KILLPIDS
    335      1.1  christos 		exit $RC
    336      1.1  christos 	fi
    337      1.1  christos fi
    338      1.1  christos 
    339      1.1  christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
    340      1.1  christos 
    341      1.1  christos echo ">>>>> Test succeeded"
    342      1.1  christos 
    343      1.1  christos test $KILLSERVERS != no && wait
    344      1.1  christos 
    345      1.1  christos exit 0
    346