diff options
author | 2013-05-16 04:26:10 +0000 | |
---|---|---|
committer | 2013-05-16 04:26:10 +0000 | |
commit | 532d2d8d740b4f0552332aed79155f4b9307dab1 (patch) | |
tree | 00739ef1dce1712cc58198d35450c3a02a985c16 | |
parent | Add RekeyLimit to sshd with the same syntax as the client allowing rekeying (diff) | |
download | wireguard-openbsd-532d2d8d740b4f0552332aed79155f4b9307dab1.tar.xz wireguard-openbsd-532d2d8d740b4f0552332aed79155f4b9307dab1.zip |
add server-side rekey test
-rw-r--r-- | regress/usr.bin/ssh/rekey.sh | 24 |
1 files changed, 20 insertions, 4 deletions
diff --git a/regress/usr.bin/ssh/rekey.sh b/regress/usr.bin/ssh/rekey.sh index 9490d6ad177..d51f08dd5fa 100644 --- a/regress/usr.bin/ssh/rekey.sh +++ b/regress/usr.bin/ssh/rekey.sh @@ -1,4 +1,4 @@ -# $OpenBSD: rekey.sh,v 1.5 2013/05/16 03:33:30 dtucker Exp $ +# $OpenBSD: rekey.sh,v 1.6 2013/05/16 04:26:10 dtucker Exp $ # Placed in the Public Domain. tid="rekey during transfer data" @@ -11,7 +11,7 @@ rm -f ${COPY} ${LOG} ${DATA} dd if=/dev/zero of=${DATA} bs=1k count=512 > /dev/null 2>&1 for s in 16 1k 128k 256k; do - verbose "rekeylimit ${s}" + verbose "client rekeylimit ${s}" rm -f ${COPY} ${LOG} cat $DATA | \ ${SSH} -oCompression=no -oRekeyLimit=$s \ @@ -29,7 +29,7 @@ for s in 16 1k 128k 256k; do done for s in 5 10; do - verbose "rekeylimit default ${s}" + verbose "client rekeylimit default ${s}" rm -f ${COPY} ${LOG} cat $DATA | \ ${SSH} -oCompression=no -oRekeyLimit="default $s" -F \ @@ -47,7 +47,7 @@ for s in 5 10; do done for s in 5 10; do - verbose "rekeylimit default ${s} no data" + verbose "client rekeylimit default ${s} no data" rm -f ${COPY} ${LOG} ${SSH} -oCompression=no -oRekeyLimit="default $s" -F \ $OBJ/ssh_proxy somehost "sleep $s;sleep 3" @@ -62,4 +62,20 @@ for s in 5 10; do fi done +echo "rekeylimit default 5" >>$OBJ/sshd_proxy +for s in 5 10; do + verbose "server rekeylimit default ${s} no data" + rm -f ${COPY} ${LOG} + ${SSH} -oCompression=no -F $OBJ/ssh_proxy somehost "sleep $s;sleep 3" + if [ $? -ne 0 ]; then + fail "ssh failed" + fi + n=`grep 'NEWKEYS sent' ${LOG} | wc -l` + n=`expr $n - 1` + trace "$n rekeying(s)" + if [ $n -lt 1 ]; then + fail "no rekeying occured" + fi +done + rm -f ${COPY} ${DATA} |