Skip to content
Snippets Groups Projects
expired.t 1.01 KiB
Newer Older
  • Learn to ignore specific revisions
  • Nicholas Terranova's avatar
    Nicholas Terranova committed
    
    use Test::Nginx::Socket 'no_plan';
    
    run_tests();
    
    __DATA__
    
    === TEST 1: https with x509 client authentication, expired client certificate
    
    --- main_config
        load_module /etc/nginx/modules/ngx_http_voms_module.so;
    
    Nicholas Terranova's avatar
    Nicholas Terranova committed
    --- http_config
        server {
            error_log logs/error.log debug;
            listen 8443 ssl;
            ssl_certificate ../../certs/nginx_voms_example.cert.pem;
            ssl_certificate_key ../../certs/nginx_voms_example.key.pem;
            ssl_client_certificate ../../trust-anchors/igi-test-ca.pem;
            ssl_verify_depth 10;
            ssl_verify_client on;
    
    	location = / {
                default_type text/plain;
    
                return 200 "$ssl_client_s_dn\n";
    
    Nicholas Terranova's avatar
    Nicholas Terranova committed
        }
    --- config
        location = / {
    
            error_log logs/error-proxy.log debug;
    
    Nicholas Terranova's avatar
    Nicholas Terranova committed
            proxy_pass https://localhost:8443/;
            proxy_ssl_certificate ../../certs/2.cert.pem;
            proxy_ssl_certificate_key ../../certs/2.key.pem;
        }
    --- request
    GET /
    
    --- response_body_like eval
    qr/\n/ 
    
    Nicholas Terranova's avatar
    Nicholas Terranova committed
    --- error_log 
    certificate has expired
    
    --- error_code: 400