test066-autoca revision 1.1.1.2 1 1.1 christos #! /bin/sh
2 1.1 christos # $OpenLDAP$
3 1.1 christos ## This work is part of OpenLDAP Software <http://www.openldap.org/>.
4 1.1 christos ##
5 1.1.1.2 christos ## Copyright 1998-2024 The OpenLDAP Foundation.
6 1.1 christos ## All rights reserved.
7 1.1 christos ##
8 1.1 christos ## Redistribution and use in source and binary forms, with or without
9 1.1 christos ## modification, are permitted only as authorized by the OpenLDAP
10 1.1 christos ## Public License.
11 1.1 christos ##
12 1.1 christos ## A copy of this license is available in the file LICENSE in the
13 1.1 christos ## top-level directory of the distribution or, alternatively, at
14 1.1 christos ## <http://www.OpenLDAP.org/license.html>.
15 1.1 christos
16 1.1 christos echo "running defines.sh"
17 1.1 christos . $SRCDIR/scripts/defines.sh
18 1.1 christos
19 1.1 christos if test $AUTOCA = autocano; then
20 1.1 christos echo "Automatic CA overlay not available, test skipped"
21 1.1 christos exit 0
22 1.1 christos fi
23 1.1 christos
24 1.1.1.2 christos if test $BACKEND = ldif ; then
25 1.1.1.2 christos # autoca tries to modify an entry in a search response,
26 1.1.1.2 christos # which deadlocks because the tree is readlocked by the search.
27 1.1.1.2 christos echo "Test does not support $BACKEND backend, test skipped"
28 1.1.1.2 christos exit 0
29 1.1.1.2 christos fi
30 1.1.1.2 christos
31 1.1 christos CFDIR=$TESTDIR/slapd.d
32 1.1 christos
33 1.1 christos mkdir -p $TESTDIR $CFDIR $DBDIR1
34 1.1 christos
35 1.1 christos $SLAPPASSWD -g -n >$CONFIGPWF
36 1.1 christos
37 1.1 christos #
38 1.1 christos # Test operation of autoca:
39 1.1 christos # - configure over ldap without TLS
40 1.1 christos # - populate over ldap
41 1.1 christos # - add host entry
42 1.1 christos # - add autoca overlay
43 1.1 christos # - generate server and user certs
44 1.1 christos # - check for TLS operation
45 1.1 christos #
46 1.1 christos
47 1.1 christos echo "Starting slapd on TCP/IP port $PORT1..."
48 1.1 christos . $CONFFILTER $BACKEND < $DYNAMICCONF > $CONFLDIF
49 1.1 christos $SLAPADD -F $CFDIR -n 0 -l $CONFLDIF
50 1.1.1.2 christos RC=$?
51 1.1.1.2 christos if test $RC != 0 ; then
52 1.1.1.2 christos echo "slapadd failed ($RC)!"
53 1.1.1.2 christos exit $RC
54 1.1.1.2 christos fi
55 1.1.1.2 christos
56 1.1 christos $SLAPD -F $CFDIR -h $URIP1 -d $LVL > $LOG1 2>&1 &
57 1.1 christos PID=$!
58 1.1 christos if test $WAIT != 0 ; then
59 1.1 christos echo PID $PID
60 1.1 christos read foo
61 1.1 christos fi
62 1.1 christos KILLPIDS="$PID"
63 1.1 christos cd $TESTWD
64 1.1 christos
65 1.1 christos sleep 1
66 1.1 christos
67 1.1 christos echo "Using ldapsearch to check that slapd is running..."
68 1.1 christos for i in 0 1 2 3 4 5; do
69 1.1 christos $LDAPSEARCH -s base -b "" -H $URIP1 \
70 1.1 christos 'objectclass=*' > /dev/null 2>&1
71 1.1 christos RC=$?
72 1.1 christos if test $RC = 0 ; then
73 1.1 christos break
74 1.1 christos fi
75 1.1 christos echo "Waiting 5 seconds for slapd to start..."
76 1.1 christos sleep 5
77 1.1 christos done
78 1.1 christos
79 1.1 christos if test $RC != 0 ; then
80 1.1 christos echo "ldapsearch failed ($RC)!"
81 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
82 1.1 christos exit $RC
83 1.1 christos fi
84 1.1 christos
85 1.1 christos echo "Adding schema and databases on slapd..."
86 1.1 christos $LDAPADD -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >>$TESTOUT 2>&1
87 1.1 christos include: file://$ABS_SCHEMADIR/core.ldif
88 1.1 christos
89 1.1 christos include: file://$ABS_SCHEMADIR/cosine.ldif
90 1.1 christos
91 1.1 christos include: file://$ABS_SCHEMADIR/inetorgperson.ldif
92 1.1 christos
93 1.1 christos include: file://$ABS_SCHEMADIR/openldap.ldif
94 1.1 christos
95 1.1 christos include: file://$ABS_SCHEMADIR/nis.ldif
96 1.1 christos EOF
97 1.1 christos RC=$?
98 1.1 christos if test $RC != 0 ; then
99 1.1 christos echo "ldapadd failed for schema config ($RC)!"
100 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
101 1.1 christos exit $RC
102 1.1 christos fi
103 1.1 christos
104 1.1 christos nullExclude="" nullOK=""
105 1.1 christos test $BACKEND = null && nullExclude="# " nullOK="OK"
106 1.1 christos
107 1.1 christos if [ "$BACKENDTYPE" = mod ]; then
108 1.1 christos $LDAPADD -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >>$TESTOUT 2>&1
109 1.1 christos dn: cn=module,cn=config
110 1.1 christos objectClass: olcModuleList
111 1.1 christos cn: module
112 1.1 christos olcModulePath: $TESTWD/../servers/slapd/back-$BACKEND
113 1.1 christos olcModuleLoad: back_$BACKEND.la
114 1.1 christos EOF
115 1.1 christos RC=$?
116 1.1 christos if test $RC != 0 ; then
117 1.1 christos echo "ldapadd failed for backend config ($RC)!"
118 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
119 1.1 christos exit $RC
120 1.1 christos fi
121 1.1 christos fi
122 1.1 christos
123 1.1 christos $LDAPADD -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >>$TESTOUT 2>&1
124 1.1 christos dn: olcDatabase={1}$BACKEND,cn=config
125 1.1 christos objectClass: olcDatabaseConfig
126 1.1 christos ${nullExclude}objectClass: olc${BACKEND}Config
127 1.1 christos olcDatabase: {1}$BACKEND
128 1.1 christos olcSuffix: $BASEDN
129 1.1 christos ${nullExclude}olcDbDirectory: $DBDIR1
130 1.1 christos olcRootDN: $MANAGERDN
131 1.1 christos olcRootPW: $PASSWD
132 1.1 christos EOF
133 1.1 christos RC=$?
134 1.1 christos if test $RC != 0 ; then
135 1.1 christos echo "ldapadd failed for database config ($RC)!"
136 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
137 1.1 christos exit $RC
138 1.1 christos fi
139 1.1 christos
140 1.1 christos if test $INDEXDB = indexdb ; then
141 1.1 christos $LDAPMODIFY -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >>$TESTOUT 2>&1
142 1.1 christos dn: olcDatabase={1}$BACKEND,cn=config
143 1.1 christos changetype: modify
144 1.1 christos add: olcDbIndex
145 1.1 christos olcDbIndex: objectClass,entryUUID,entryCSN eq
146 1.1 christos olcDbIndex: cn,uid pres,eq,sub
147 1.1 christos EOF
148 1.1 christos RC=$?
149 1.1 christos if test $RC != 0 ; then
150 1.1 christos echo "ldapadd modify for database config ($RC)!"
151 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
152 1.1 christos exit $RC
153 1.1 christos fi
154 1.1 christos fi
155 1.1 christos
156 1.1 christos echo "Using ldapadd to populate slapd..."
157 1.1 christos $LDAPADD -D "$MANAGERDN" -H $URIP1 -w $PASSWD -f $LDIFORDERED \
158 1.1 christos >> $TESTOUT 2>&1
159 1.1 christos RC=$?
160 1.1 christos if test $RC != 0 ; then
161 1.1 christos echo "ldapadd failed for database populate ($RC)!"
162 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
163 1.1 christos exit $RC
164 1.1 christos fi
165 1.1 christos
166 1.1 christos echo "Adding server entries to slapd..."
167 1.1 christos $LDAPADD -D "$MANAGERDN" -H $URIP1 -w $PASSWD <<EOF >> $TESTOUT 2>&1
168 1.1 christos dn: ou=Servers,$BASEDN
169 1.1 christos objectClass: organizationalUnit
170 1.1 christos ou: Servers
171 1.1 christos
172 1.1 christos dn: cn=localhost,ou=Servers,$BASEDN
173 1.1 christos objectClass: device
174 1.1 christos objectClass: ipHost
175 1.1 christos cn: localhost
176 1.1 christos ipHostNumber: 127.0.0.1
177 1.1 christos
178 1.1 christos dn: cn=www.example.com,ou=Servers,$BASEDN
179 1.1 christos objectClass: device
180 1.1 christos objectClass: ipHost
181 1.1 christos cn: localhost
182 1.1 christos ipHostNumber: 93.184.216.34
183 1.1 christos EOF
184 1.1 christos RC=$?
185 1.1 christos if test $RC != 0 ; then
186 1.1 christos echo "ldapadd failed for database populate ($RC)!"
187 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
188 1.1 christos exit $RC
189 1.1 christos fi
190 1.1 christos
191 1.1 christos echo "Inserting autoca overlay on slapd..."
192 1.1 christos if [ "$AUTOCA" = autocamod ]; then
193 1.1 christos $LDAPADD -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF > $TESTOUT 2>&1
194 1.1 christos dn: cn=module,cn=config
195 1.1 christos objectClass: olcModuleList
196 1.1 christos cn: module
197 1.1 christos olcModulePath: $TESTWD/../servers/slapd/overlays
198 1.1 christos olcModuleLoad: autoca.la
199 1.1 christos EOF
200 1.1 christos RC=$?
201 1.1 christos if test $RC != 0 ; then
202 1.1 christos echo "ldapadd failed for moduleLoad ($RC)!"
203 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
204 1.1 christos exit $RC
205 1.1 christos fi
206 1.1 christos fi
207 1.1 christos $LDAPMODIFY -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >> $TESTOUT 2>&1
208 1.1 christos dn: olcOverlay=autoca,olcDatabase={1}$BACKEND,cn=config
209 1.1 christos changetype: add
210 1.1 christos objectClass: olcOverlayConfig
211 1.1 christos objectClass: olcAutoCAConfig
212 1.1 christos olcOverlay: autoca
213 1.1 christos olcAutoCAlocalDN: cn=localhost,ou=Servers,$BASEDN
214 1.1 christos EOF
215 1.1 christos RC=$?
216 1.1 christos if test $RC != 0 ; then
217 1.1 christos echo "ldapmodify failed for autoca config ($RC)!"
218 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
219 1.1 christos exit $RC
220 1.1 christos fi
221 1.1 christos echo "Using ldapsearch to retrieve CA cert..."
222 1.1 christos $LDAPSEARCH -b $BASEDN -D $MANAGERDN -H $URIP1 -w $PASSWD -s base \
223 1.1 christos 'objectclass=*' 'cACertificate;binary' > $SEARCHOUT 2>&1
224 1.1 christos RC=$?
225 1.1 christos
226 1.1 christos if test $RC != 0 ; then
227 1.1 christos echo "ldapsearch failed ($RC)!"
228 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
229 1.1 christos exit $RC
230 1.1 christos fi
231 1.1 christos
232 1.1 christos echo "Setting up CA cert..."
233 1.1 christos echo "-----BEGIN CERTIFICATE-----" > $TESTDIR/cacert.pem
234 1.1 christos sed -e "/^dn:/d" -e "s/cACertificate;binary:://" -e "/^$/d" $SEARCHOUT >> $TESTDIR/cacert.pem
235 1.1 christos echo "-----END CERTIFICATE-----" >> $TESTDIR/cacert.pem
236 1.1 christos
237 1.1 christos echo "Using ldapsearch to generate localhost cert..."
238 1.1 christos $LDAPSEARCH -b cn=localhost,ou=Servers,$BASEDN -D $MANAGERDN -H $URIP1 -w $PASSWD -s base \
239 1.1 christos -A 'objectclass=*' 'userCertificate;binary' 'userPrivateKey;binary' >> $TESTOUT 2>&1
240 1.1 christos RC=$?
241 1.1 christos
242 1.1 christos if test $RC != 0 ; then
243 1.1 christos echo "ldapsearch failed ($RC)!"
244 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
245 1.1 christos exit $RC
246 1.1 christos fi
247 1.1 christos
248 1.1 christos echo "Using ldapsearch to attempt TLS..."
249 1.1 christos unset LDAPNOINIT
250 1.1 christos LDAPTLS_CACERT=$TESTDIR/cacert.pem
251 1.1 christos export LDAPTLS_CACERT
252 1.1 christos $LDAPSEARCH -b $BASEDN -D $MANAGERDN -H $URIP1 -w $PASSWD -s base -ZZ \
253 1.1 christos 'objectclass=*' >> $TESTOUT 2>&1
254 1.1 christos RC=$?
255 1.1 christos
256 1.1 christos if test $RC != 0 ; then
257 1.1 christos echo "ldapsearch failed ($RC)!"
258 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
259 1.1 christos exit $RC
260 1.1 christos fi
261 1.1 christos
262 1.1 christos if test $WITH_SASL = no ; then
263 1.1 christos echo "SASL support not available, skipping client cert authentication"
264 1.1 christos else
265 1.1 christos # note - the attrs are being saved in raw DER form.
266 1.1 christos # they need to be base64 encoded into PEM for most programs to use them
267 1.1 christos # so we ignore those files for now.
268 1.1 christos echo "Using ldapsearch to generate user cert..."
269 1.1 christos $LDAPSEARCH -b "$BABSDN" -D $MANAGERDN -H $URIP1 -w $PASSWD -s base -ZZ \
270 1.1 christos -T $TESTDIR -t 'objectclass=*' 'userCertificate;binary' 'userPrivateKey;binary' >> $TESTOUT 2>&1
271 1.1 christos RC=$?
272 1.1 christos
273 1.1 christos if test $RC != 0 ; then
274 1.1 christos echo "ldapsearch failed ($RC)!"
275 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
276 1.1 christos exit $RC
277 1.1 christos fi
278 1.1 christos
279 1.1 christos echo "Using ldapsearch to retrieve user cert..."
280 1.1 christos $LDAPSEARCH -b "$BABSDN" -D $MANAGERDN -H $URIP1 -w $PASSWD -s base -ZZ \
281 1.1 christos 'objectclass=*' 'userCertificate;binary' > $SEARCHOUT 2>&1
282 1.1 christos RC=$?
283 1.1 christos
284 1.1 christos if test $RC != 0 ; then
285 1.1 christos echo "ldapsearch failed ($RC)!"
286 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
287 1.1 christos exit $RC
288 1.1 christos fi
289 1.1 christos
290 1.1 christos echo "Setting up user cert..."
291 1.1 christos echo "-----BEGIN CERTIFICATE-----" > $TESTDIR/usercert.pem
292 1.1 christos sed -e "/^dn:/d" -e "/^ dc=com/d" -e "s/userCertificate;binary:://" -e "/^$/d" $SEARCHOUT >> $TESTDIR/usercert.pem
293 1.1 christos echo "-----END CERTIFICATE-----" >> $TESTDIR/usercert.pem
294 1.1 christos
295 1.1 christos echo "Using ldapsearch to retrieve user key..."
296 1.1 christos $LDAPSEARCH -b "$BABSDN" -D $MANAGERDN -H $URIP1 -w $PASSWD -s base -ZZ \
297 1.1 christos 'objectclass=*' 'userPrivateKey;binary' > $SEARCHOUT 2>&1
298 1.1 christos RC=$?
299 1.1 christos
300 1.1 christos if test $RC != 0 ; then
301 1.1 christos echo "ldapsearch failed ($RC)!"
302 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
303 1.1 christos exit $RC
304 1.1 christos fi
305 1.1 christos
306 1.1 christos echo "Setting up user key..."
307 1.1 christos echo "-----BEGIN PRIVATE KEY-----" > $TESTDIR/userkey.pem
308 1.1 christos sed -e "/^dn:/d" -e "/^ dc=com/d" -e "s/userPrivateKey;binary:://" -e "/^$/d" $SEARCHOUT >> $TESTDIR/userkey.pem
309 1.1 christos echo "-----END PRIVATE KEY-----" >> $TESTDIR/userkey.pem
310 1.1 christos
311 1.1 christos LDAPTLS_CERT=$TESTDIR/usercert.pem
312 1.1 christos LDAPTLS_KEY=$TESTDIR/userkey.pem
313 1.1 christos export LDAPTLS_CERT
314 1.1 christos export LDAPTLS_KEY
315 1.1 christos
316 1.1 christos echo "Setting TLSVerifyClient to try..."
317 1.1 christos $LDAPMODIFY -D cn=config -H $URIP1 -y $CONFIGPWF <<EOF >> $TESTOUT 2>&1
318 1.1 christos dn: cn=config
319 1.1 christos changetype: modify
320 1.1 christos replace: olcTLSVerifyClient
321 1.1 christos olcTLSVerifyClient: try
322 1.1 christos EOF
323 1.1 christos RC=$?
324 1.1 christos if test $RC != 0 ; then
325 1.1 christos echo "ldapmodify failed for autoca config ($RC)!"
326 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
327 1.1 christos exit $RC
328 1.1 christos fi
329 1.1 christos
330 1.1 christos $CLIENTDIR/ldapwhoami -Y EXTERNAL -H $URIP1 -ZZ
331 1.1 christos
332 1.1 christos if test $RC != 0 ; then
333 1.1 christos echo "ldapwhoami failed ($RC)!"
334 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
335 1.1 christos exit $RC
336 1.1 christos fi
337 1.1 christos fi
338 1.1 christos
339 1.1 christos test $KILLSERVERS != no && kill -HUP $KILLPIDS
340 1.1 christos
341 1.1 christos echo ">>>>> Test succeeded"
342 1.1 christos
343 1.1 christos test $KILLSERVERS != no && wait
344 1.1 christos
345 1.1 christos exit 0
346