summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authordtucker <dtucker@openbsd.org>2013-05-16 04:26:10 +0000
committerdtucker <dtucker@openbsd.org>2013-05-16 04:26:10 +0000
commit532d2d8d740b4f0552332aed79155f4b9307dab1 (patch)
tree00739ef1dce1712cc58198d35450c3a02a985c16
parentAdd RekeyLimit to sshd with the same syntax as the client allowing rekeying (diff)
downloadwireguard-openbsd-532d2d8d740b4f0552332aed79155f4b9307dab1.tar.xz
wireguard-openbsd-532d2d8d740b4f0552332aed79155f4b9307dab1.zip
add server-side rekey test
-rw-r--r--regress/usr.bin/ssh/rekey.sh24
1 files changed, 20 insertions, 4 deletions
diff --git a/regress/usr.bin/ssh/rekey.sh b/regress/usr.bin/ssh/rekey.sh
index 9490d6ad177..d51f08dd5fa 100644
--- a/regress/usr.bin/ssh/rekey.sh
+++ b/regress/usr.bin/ssh/rekey.sh
@@ -1,4 +1,4 @@
-# $OpenBSD: rekey.sh,v 1.5 2013/05/16 03:33:30 dtucker Exp $
+# $OpenBSD: rekey.sh,v 1.6 2013/05/16 04:26:10 dtucker Exp $
# Placed in the Public Domain.
tid="rekey during transfer data"
@@ -11,7 +11,7 @@ rm -f ${COPY} ${LOG} ${DATA}
dd if=/dev/zero of=${DATA} bs=1k count=512 > /dev/null 2>&1
for s in 16 1k 128k 256k; do
- verbose "rekeylimit ${s}"
+ verbose "client rekeylimit ${s}"
rm -f ${COPY} ${LOG}
cat $DATA | \
${SSH} -oCompression=no -oRekeyLimit=$s \
@@ -29,7 +29,7 @@ for s in 16 1k 128k 256k; do
done
for s in 5 10; do
- verbose "rekeylimit default ${s}"
+ verbose "client rekeylimit default ${s}"
rm -f ${COPY} ${LOG}
cat $DATA | \
${SSH} -oCompression=no -oRekeyLimit="default $s" -F \
@@ -47,7 +47,7 @@ for s in 5 10; do
done
for s in 5 10; do
- verbose "rekeylimit default ${s} no data"
+ verbose "client rekeylimit default ${s} no data"
rm -f ${COPY} ${LOG}
${SSH} -oCompression=no -oRekeyLimit="default $s" -F \
$OBJ/ssh_proxy somehost "sleep $s;sleep 3"
@@ -62,4 +62,20 @@ for s in 5 10; do
fi
done
+echo "rekeylimit default 5" >>$OBJ/sshd_proxy
+for s in 5 10; do
+ verbose "server rekeylimit default ${s} no data"
+ rm -f ${COPY} ${LOG}
+ ${SSH} -oCompression=no -F $OBJ/ssh_proxy somehost "sleep $s;sleep 3"
+ if [ $? -ne 0 ]; then
+ fail "ssh failed"
+ fi
+ n=`grep 'NEWKEYS sent' ${LOG} | wc -l`
+ n=`expr $n - 1`
+ trace "$n rekeying(s)"
+ if [ $n -lt 1 ]; then
+ fail "no rekeying occured"
+ fi
+done
+
rm -f ${COPY} ${DATA}