upstream commit

fix command-line option to match what was actually
 committed

Upstream-Regress-ID: 3e8c24a2044e8afd37e7ce17b69002ca817ac699
This commit is contained in:
djm@openbsd.org 2015-09-24 07:15:39 +00:00 committed by Damien Miller
parent e14ac43b75
commit 21ae8ee3b6
1 changed files with 9 additions and 7 deletions

View File

@ -1,4 +1,4 @@
# $OpenBSD: cert-file.sh,v 1.1 2015/09/24 06:16:53 djm Exp $ # $OpenBSD: cert-file.sh,v 1.2 2015/09/24 07:15:39 djm Exp $
# Placed in the Public Domain. # Placed in the Public Domain.
tid="ssh with certificates" tid="ssh with certificates"
@ -42,7 +42,7 @@ for p in ${SSH_PROTOCOLS}; do
fi fi
# Keys with untrusted cert should fail. # Keys with untrusted cert should fail.
opts3="$opts2 -z $OBJ/cert_user_key1_2.pub" opts3="$opts2 -oCertificateFile=$OBJ/cert_user_key1_2.pub"
${SSH} $opts3 somehost exit 5$p ${SSH} $opts3 somehost exit 5$p
r=$? r=$?
if [ $r -eq 5$p ]; then if [ $r -eq 5$p ]; then
@ -50,7 +50,8 @@ for p in ${SSH_PROTOCOLS}; do
fi fi
# Good cert with bad key should fail. # Good cert with bad key should fail.
opts3="$opts -i $OBJ/user_key2 -z $OBJ/cert_user_key1_1.pub" opts3="$opts -i $OBJ/user_key2"
opts3="$opts3 -oCertificateFile=$OBJ/cert_user_key1_1.pub"
${SSH} $opts3 somehost exit 5$p ${SSH} $opts3 somehost exit 5$p
r=$? r=$?
if [ $r -eq 5$p ]; then if [ $r -eq 5$p ]; then
@ -58,7 +59,7 @@ for p in ${SSH_PROTOCOLS}; do
fi fi
# Keys with one trusted cert, should succeed. # Keys with one trusted cert, should succeed.
opts3="$opts2 -z $OBJ/cert_user_key1_1.pub" opts3="$opts2 -oCertificateFile=$OBJ/cert_user_key1_1.pub"
${SSH} $opts3 somehost exit 5$p ${SSH} $opts3 somehost exit 5$p
r=$? r=$?
if [ $r -ne 5$p ]; then if [ $r -ne 5$p ]; then
@ -66,7 +67,8 @@ for p in ${SSH_PROTOCOLS}; do
fi fi
# Multiple certs and keys, with one trusted cert, should succeed. # Multiple certs and keys, with one trusted cert, should succeed.
opts3="$opts2 -z $OBJ/cert_user_key1_2.pub -z $OBJ/cert_user_key1_1.pub" opts3="$opts2 -oCertificateFile=$OBJ/cert_user_key1_2.pub"
opts3="$opts3 -oCertificateFile=$OBJ/cert_user_key1_1.pub"
${SSH} $opts3 somehost exit 5$p ${SSH} $opts3 somehost exit 5$p
r=$? r=$?
if [ $r -ne 5$p ]; then if [ $r -ne 5$p ]; then
@ -115,14 +117,14 @@ if [ $? -eq 52 ]; then
fi fi
#with an untrusted certificate, should fail #with an untrusted certificate, should fail
opts="$opts -z $OBJ/cert_user_key1_2.pub" opts="$opts -oCertificateFile=$OBJ/cert_user_key1_2.pub"
${SSH} -2 $opts somehost exit 52 ${SSH} -2 $opts somehost exit 52
if [ $? -eq 52 ]; then if [ $? -eq 52 ]; then
fail "ssh connect with agent in protocol 2 succeeded with bad cert" fail "ssh connect with agent in protocol 2 succeeded with bad cert"
fi fi
#with an additional trusted certificate, should succeed #with an additional trusted certificate, should succeed
opts="$opts -z $OBJ/cert_user_key1_1.pub" opts="$opts -oCertificateFile=$OBJ/cert_user_key1_1.pub"
${SSH} -2 $opts somehost exit 52 ${SSH} -2 $opts somehost exit 52
if [ $? -ne 52 ]; then if [ $? -ne 52 ]; then
fail "ssh connect with agent in protocol 2 failed with good cert" fail "ssh connect with agent in protocol 2 failed with good cert"