From efc290778073367caed9a3641b0f992b1a4a2be1 Mon Sep 17 00:00:00 2001 From: Radek Zikmund Date: Thu, 24 Feb 2022 16:00:09 +0100 Subject: [PATCH 1/4] Condition Windows SslCertificateTrust test on Registry value --- .../TestUtilities/System/PlatformDetection.cs | 34 +++++++++++++++---- .../SslStreamCertificateTrustTests.cs | 11 +++--- 2 files changed, 33 insertions(+), 12 deletions(-) diff --git a/src/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs b/src/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs index f348123953688f..88340d580cf9c2 100644 --- a/src/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs +++ b/src/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs @@ -238,11 +238,13 @@ private static bool GetAlpnSupport() private static Lazy s_supportsTls11 = new Lazy(GetTls11Support); private static Lazy s_supportsTls12 = new Lazy(GetTls12Support); private static Lazy s_supportsTls13 = new Lazy(GetTls13Support); + private static Lazy s_supportsSendingCANamesInTls = new Lazy(GetTlsHandshakeCAListSupport); public static bool SupportsTls10 => s_supportsTls10.Value; public static bool SupportsTls11 => s_supportsTls11.Value; public static bool SupportsTls12 => s_supportsTls12.Value; public static bool SupportsTls13 => s_supportsTls13.Value; + public static bool SupportsSendingCANamesInTls => s_supportsSendingCANamesInTls.Value; private static Lazy s_largeArrayIsNotSupported = new Lazy(IsLargeArrayNotSupported); @@ -295,7 +297,7 @@ private static bool GetStaticNonPublicBooleanPropertyValue(string typeName, stri public static bool IsInvariantGlobalization => m_isInvariant.Value; public static bool IsNotInvariantGlobalization => !IsInvariantGlobalization; - public static bool IsIcuGlobalization => ICUVersion > new Version(0,0,0,0); + public static bool IsIcuGlobalization => ICUVersion > new Version(0, 0, 0, 0); public static bool IsNlsGlobalization => IsNotInvariantGlobalization && !IsIcuGlobalization; public static bool IsSubstAvailable @@ -360,7 +362,7 @@ private static bool GetIsInContainer() private static bool GetProtocolSupportFromWindowsRegistry(SslProtocols protocol, bool defaultProtocolSupport) { - string registryProtocolName = protocol switch + string registryProtocolName = protocol switch { #pragma warning disable CS0618 // Ssl2 and Ssl3 are obsolete SslProtocols.Ssl3 => "SSL 3.0", @@ -410,7 +412,7 @@ private static bool GetSsl3Support() #pragma warning disable CS0618 // Ssl2 and Ssl3 are obsolete return GetProtocolSupportFromWindowsRegistry(SslProtocols.Ssl3, ssl3DefaultSupport); #pragma warning restore CS0618 - + } return (IsOSX || (IsLinux && OpenSslVersion < new Version(1, 0, 2) && !IsDebian)); @@ -437,7 +439,7 @@ private static bool GetTls10Support() if (IsOSXLike || IsAndroid) { return true; - } + } if (IsWindows) { return GetProtocolSupportFromWindowsRegistry(SslProtocols.Tls, true); @@ -466,7 +468,7 @@ private static bool GetTls11Support() private static bool GetTls12Support() { // TLS 1.1 and 1.2 can work on Windows7 but it is not enabled by default. - bool defaultProtocolSupport = !IsWindows7; + bool defaultProtocolSupport = !IsWindows7; return GetProtocolSupportFromWindowsRegistry(SslProtocols.Tls12, defaultProtocolSupport); } @@ -506,7 +508,27 @@ private static bool GetTls13Support() else if (IsOpenSslSupported) { // Covers Linux, FreeBSD, illumos and Solaris - return OpenSslVersion >= new Version(1,1,1); + return OpenSslVersion >= new Version(1, 1, 1); + } + + return false; + } + + private static bool GetTlsHandshakeCAListSupport() + { + if (IsOpenSslSupported || IsOSX) + { + return true; + } + + if (IsWindows) + { + // Sending TrustedIssuers is conditioned on the registry. + object val = Registry.GetValue(@"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL", "SendTrustedIssuerList", IsWindows7 ? 1 : 0); + if (val is int i) + { + return i == 1; + } } return false; diff --git a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs index fe3a977d479b69..49876427d6dfdb 100644 --- a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs +++ b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs @@ -15,9 +15,10 @@ namespace System.Net.Security.Tests public class SslStreamCertificateTrustTest { - [Fact] - // not supported on Windows, not implemented elsewhere - [PlatformSpecific(TestPlatforms.Linux | TestPlatforms.OSX)] + public static bool SupportsSendingCANamesInTls => PlatformDetection.SupportsSendingCANamesInTls; + + [ConditionalFact(nameof(SupportsSendingCANamesInTls))] + [SkipOnPlatform(TestPlatforms.Windows, "CertificateCollection-based SslCertificateTrust is not Supported on Windows")] public async Task SslStream_SendCertificateTrust_CertificateCollection() { (X509Certificate2 certificate, X509Certificate2Collection caCerts) = TestHelper.GenerateCertificates(nameof(SslStream_SendCertificateTrust_CertificateCollection)); @@ -29,9 +30,7 @@ public async Task SslStream_SendCertificateTrust_CertificateCollection() Assert.Equal(caCerts.Select(c => c.Subject), acceptableIssuers); } - [Fact] - [ActiveIssue("https://github.com/dotnet/runtime/issues/65515", TestPlatforms.Windows)] - [PlatformSpecific(TestPlatforms.Windows | TestPlatforms.Linux | TestPlatforms.OSX)] + [ConditionalFact(nameof(SupportsSendingCANamesInTls))] public async Task SslStream_SendCertificateTrust_CertificateStore() { using X509Store store = new X509Store("Root", StoreLocation.LocalMachine); From fc93cea69ebb14c03b7a5d8d972abe875c73eed9 Mon Sep 17 00:00:00 2001 From: Radek Zikmund Date: Wed, 2 Mar 2022 10:32:26 +0100 Subject: [PATCH 2/4] Improve platform detection for tests --- .../TestUtilities/System/PlatformDetection.cs | 15 ++++----- .../Net/Security/SslCertificateTrust.cs | 11 ++----- .../SslStreamCertificateTrustTests.cs | 27 ++++++++++++++-- .../tests/FunctionalTests/SslStreamEKUTest.cs | 5 +-- .../SslStreamNetworkStreamTest.cs | 31 +++++++------------ 5 files changed, 48 insertions(+), 41 deletions(-) diff --git a/src/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs b/src/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs index 88340d580cf9c2..39fc5d2b1b9028 100644 --- a/src/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs +++ b/src/libraries/Common/tests/TestUtilities/System/PlatformDetection.cs @@ -238,13 +238,14 @@ private static bool GetAlpnSupport() private static Lazy s_supportsTls11 = new Lazy(GetTls11Support); private static Lazy s_supportsTls12 = new Lazy(GetTls12Support); private static Lazy s_supportsTls13 = new Lazy(GetTls13Support); - private static Lazy s_supportsSendingCANamesInTls = new Lazy(GetTlsHandshakeCAListSupport); + private static Lazy s_sendsCAListByDefault = new Lazy(GetSendsCAListByDefault); public static bool SupportsTls10 => s_supportsTls10.Value; public static bool SupportsTls11 => s_supportsTls11.Value; public static bool SupportsTls12 => s_supportsTls12.Value; public static bool SupportsTls13 => s_supportsTls13.Value; - public static bool SupportsSendingCANamesInTls => s_supportsSendingCANamesInTls.Value; + public static bool SendsCAListByDefault => s_sendsCAListByDefault.Value; + public static bool SupportsSendingCustomCANamesInTls => UsesAppleCrypto || IsOpenSslSupported || (PlatformDetection.IsWindows8xOrLater && SendsCAListByDefault); private static Lazy s_largeArrayIsNotSupported = new Lazy(IsLargeArrayNotSupported); @@ -514,16 +515,12 @@ private static bool GetTls13Support() return false; } - private static bool GetTlsHandshakeCAListSupport() + private static bool GetSendsCAListByDefault() { - if (IsOpenSslSupported || IsOSX) - { - return true; - } - if (IsWindows) { - // Sending TrustedIssuers is conditioned on the registry. + // Sending TrustedIssuers is conditioned on the registry. Win7 sends trusted issuer list by default, + // newer Windows versions don't. object val = Registry.GetValue(@"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL", "SendTrustedIssuerList", IsWindows7 ? 1 : 0); if (val is int i) { diff --git a/src/libraries/System.Net.Security/src/System/Net/Security/SslCertificateTrust.cs b/src/libraries/System.Net.Security/src/System/Net/Security/SslCertificateTrust.cs index 98fd52fad3c5b6..b141a33f264be0 100644 --- a/src/libraries/System.Net.Security/src/System/Net/Security/SslCertificateTrust.cs +++ b/src/libraries/System.Net.Security/src/System/Net/Security/SslCertificateTrust.cs @@ -21,7 +21,9 @@ public static SslCertificateTrust CreateForX509Store(X509Store store, bool sendT throw new PlatformNotSupportedException(SR.net_ssl_trust_store); } #else - if (sendTrustInHandshake && !System.OperatingSystem.IsLinux() && !System.OperatingSystem.IsMacOS()) + if (sendTrustInHandshake && !System.OperatingSystem.IsLinux() && !System.OperatingSystem.IsMacOS() && + // Necessary functions are available only on win 8 onwards + !OperatingSystem.IsWindowsVersionAtLeast(6, 2)) { // to be removed when implemented. throw new PlatformNotSupportedException(SR.net_ssl_trust_handshake); @@ -43,16 +45,9 @@ public static SslCertificateTrust CreateForX509Collection(X509Certificate2Collec { if (sendTrustInHandshake && !System.OperatingSystem.IsLinux() && !System.OperatingSystem.IsMacOS()) { - // to be removed when implemented. throw new PlatformNotSupportedException(SR.net_ssl_trust_handshake); } -#if TARGET_WINDOWS - if (sendTrustInHandshake) - { - throw new PlatformNotSupportedException(SR.net_ssl_trust_collection); - } -#endif var trust = new SslCertificateTrust(); trust._trustList = trustList; trust._sendTrustInHandshake = sendTrustInHandshake; diff --git a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs index 49876427d6dfdb..b694fd36a66790 100644 --- a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs +++ b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs @@ -15,9 +15,10 @@ namespace System.Net.Security.Tests public class SslStreamCertificateTrustTest { - public static bool SupportsSendingCANamesInTls => PlatformDetection.SupportsSendingCANamesInTls; + public static bool SupportsSendingCustomCANamesInTls => PlatformDetection.SupportsSendingCustomCANamesInTls; + public static bool DoesNotSupportSendingCustomCANamesInTls => !PlatformDetection.SupportsSendingCustomCANamesInTls; - [ConditionalFact(nameof(SupportsSendingCANamesInTls))] + [ConditionalFact(nameof(SupportsSendingCustomCANamesInTls))] [SkipOnPlatform(TestPlatforms.Windows, "CertificateCollection-based SslCertificateTrust is not Supported on Windows")] public async Task SslStream_SendCertificateTrust_CertificateCollection() { @@ -30,7 +31,7 @@ public async Task SslStream_SendCertificateTrust_CertificateCollection() Assert.Equal(caCerts.Select(c => c.Subject), acceptableIssuers); } - [ConditionalFact(nameof(SupportsSendingCANamesInTls))] + [ConditionalFact(nameof(SupportsSendingCustomCANamesInTls))] public async Task SslStream_SendCertificateTrust_CertificateStore() { using X509Store store = new X509Store("Root", StoreLocation.LocalMachine); @@ -88,5 +89,25 @@ await TestConfiguration.WhenAllOrAnyFailedWithTimeout( return acceptableIssuers; } } + + [ConditionalFact(nameof(SupportsSendingCustomCANamesInTls))] + public void SslStream_SendCertificateTrust_CertificateCollection_ThrowsOnWindows() + { + (X509Certificate2 certificate, X509Certificate2Collection caCerts) = TestHelper.GenerateCertificates(nameof(SslStream_SendCertificateTrust_CertificateCollection)); + + Assert.Throws(() => SslCertificateTrust.CreateForX509Collection(caCerts, sendTrustInHandshake: true)); + } + + [ConditionalFact(nameof(DoesNotSupportSendingCustomCANamesInTls))] + [SkipOnPlatform(TestPlatform.Windows)] + public void SslStream_SendCertificateTrust_ThrowsOnUnsupportedPlatform() + { + (X509Certificate2 certificate, X509Certificate2Collection caCerts) = TestHelper.GenerateCertificates(nameof(SslStream_SendCertificateTrust_CertificateCollection)); + + using X509Store store = new X509Store("Root", StoreLocation.LocalMachine); + + Assert.Throws(() => SslCertificateTrust.CreateForX509Collection(caCerts, sendTrustInHandshake: true)); + Assert.Throws(() => SslCertificateTrust.CreateForX509Store(store, sendTrustInHandshake: true)); + } } } \ No newline at end of file diff --git a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamEKUTest.cs b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamEKUTest.cs index b49c99868bab8b..21880cdffab9f7 100644 --- a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamEKUTest.cs +++ b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamEKUTest.cs @@ -11,11 +11,12 @@ namespace System.Net.Security.Tests { - using Configuration = System.Net.Test.Common.Configuration; + using Configuration = System.Net.Test.Common.Configuration; public class SslStreamEKUTest { public static bool IsRootCertificateInstalled => Capability.IsTrustedRootCertificateInstalled(); + public static bool DoesNotSendCAListByDefault => !PlatformDetection.SendsCAListByDefault; public const int TestTimeoutMilliseconds = 15 * 1000; @@ -134,7 +135,7 @@ public async Task SslStream_ServerEKUClientAuth_Fails() } } - [ConditionalFact(nameof(IsRootCertificateInstalled))] + [ConditionalFact(nameof(IsRootCertificateInstalled), nameof(DoesNotSendCAListByDefault))] public async Task SslStream_SelfSignedClientEKUClientAuth_Ok() { var serverOptions = new HttpsTestServer.Options(); diff --git a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamNetworkStreamTest.cs b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamNetworkStreamTest.cs index 44dbc87d84b265..0364b0dbf4d076 100644 --- a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamNetworkStreamTest.cs +++ b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamNetworkStreamTest.cs @@ -275,8 +275,11 @@ public async Task SslStream_NegotiateClientCertificateAsyncNoRenego_Succeeds(boo return sendClientCertificate ? clientCertificate : null; }; - SslServerAuthenticationOptions serverOptions = new SslServerAuthenticationOptions() { ServerCertificate = serverCertificate, - AllowRenegotiation = false }; + SslServerAuthenticationOptions serverOptions = new SslServerAuthenticationOptions() + { + ServerCertificate = serverCertificate, + AllowRenegotiation = false + }; serverOptions.RemoteCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) => { if (negotiateClientCertificateCalled && sendClientCertificate) @@ -353,7 +356,7 @@ await TestConfiguration.WhenAllOrAnyFailedWithTimeout( // Send application data instead of Client hello. await client.WriteAsync(new byte[500], cts.Token); // Fail as it is not allowed to receive non handshake frames during handshake. - await Assert.ThrowsAsync(()=> t); + await Assert.ThrowsAsync(() => t); } } @@ -404,7 +407,7 @@ await TestConfiguration.WhenAllOrAnyFailedWithTimeout( int read = await server.ReadAsync(buffer, cts.Token); // Fail as there are still some undrained data (incomplete incoming TLS frame) - await Assert.ThrowsAsync(()=> + await Assert.ThrowsAsync(() => server.NegotiateClientCertificateAsync(cts.Token) ); @@ -472,17 +475,10 @@ await TestConfiguration.WhenAllOrAnyFailedWithTimeout( } [ConditionalTheory(typeof(PlatformDetection), nameof(PlatformDetection.SupportsTls13))] - [ActiveIssue("https://github.com/dotnet/runtime/issues/58927", TestPlatforms.Windows)] [InlineData(true)] [InlineData(false)] public async Task SslStream_NegotiateClientCertificateAsyncTls13_Succeeds(bool sendClientCertificate) { - if (PlatformDetection.IsWindows10Version22000OrGreater) - { - // [ActiveIssue("https://github.com/dotnet/runtime/issues/58927")] - throw new SkipTestException("Unstable on Windows 11"); - } - bool negotiateClientCertificateCalled = false; using CancellationTokenSource cts = new CancellationTokenSource(); cts.CancelAfter(TestConfiguration.PassingTestTimeout); @@ -727,12 +723,11 @@ await TestConfiguration.WhenAllOrAnyFailedWithTimeout( [Theory] [InlineData(true)] [InlineData(false)] - [ActiveIssue("https://github.com/dotnet/runtime/issues/46837", TestPlatforms.OSX)] public async Task SslStream_UntrustedCaWithCustomCallback_OK(bool usePartialChain) { int split = Random.Shared.Next(0, certificates.serverChain.Count - 1); - var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost" }; + var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost" }; clientOptions.RemoteCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) => { @@ -790,11 +785,10 @@ public async Task SslStream_UntrustedCaWithCustomCallback_OK(bool usePartialChai [PlatformSpecific(TestPlatforms.AnyUnix)] [InlineData(true)] [InlineData(false)] - [ActiveIssue("https://github.com/dotnet/runtime/issues/46837", TestPlatforms.OSX)] public async Task SslStream_UntrustedCaWithCustomCallback_Throws(bool customCallback) { string errorMessage; - var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost" }; + var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost" }; if (customCallback) { clientOptions.RemoteCertificateValidationCallback = @@ -836,8 +830,7 @@ public async Task SslStream_UntrustedCaWithCustomCallback_Throws(bool customCall } } - [ConditionalFact] - [ActiveIssue("https://github.com/dotnet/runtime/issues/46837", TestPlatforms.OSX)] + [Fact] public async Task SslStream_ClientCertificate_SendsChain() { List streams = new List(); @@ -864,7 +857,7 @@ public async Task SslStream_ClientCertificate_SendsChain() } } - var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost", }; + var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost", }; clientOptions.RemoteCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) => true; clientOptions.LocalCertificateSelectionCallback = (sender, target, certificates, remoteCertificate, issuers) => clientCertificate; @@ -908,7 +901,7 @@ public async Task SslStream_ClientCertificate_SendsChain() c.Dispose(); } - foreach (SslStream s in streams) + foreach (SslStream s in streams) { s.Dispose(); } From 8656a0ab171159d917c63786eaa14448b792694f Mon Sep 17 00:00:00 2001 From: Radek Zikmund Date: Wed, 2 Mar 2022 11:57:36 +0100 Subject: [PATCH 3/4] fixup! Improve platform detection for tests --- .../tests/FunctionalTests/SslStreamCertificateTrustTests.cs | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs index b694fd36a66790..5619b3cf7d3e9d 100644 --- a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs +++ b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamCertificateTrustTests.cs @@ -91,6 +91,7 @@ await TestConfiguration.WhenAllOrAnyFailedWithTimeout( } [ConditionalFact(nameof(SupportsSendingCustomCANamesInTls))] + [PlatformSpecific(TestPlatforms.Windows)] public void SslStream_SendCertificateTrust_CertificateCollection_ThrowsOnWindows() { (X509Certificate2 certificate, X509Certificate2Collection caCerts) = TestHelper.GenerateCertificates(nameof(SslStream_SendCertificateTrust_CertificateCollection)); @@ -99,7 +100,7 @@ public void SslStream_SendCertificateTrust_CertificateCollection_ThrowsOnWindows } [ConditionalFact(nameof(DoesNotSupportSendingCustomCANamesInTls))] - [SkipOnPlatform(TestPlatform.Windows)] + [SkipOnPlatform(TestPlatforms.Windows, "Windows tested separately")] public void SslStream_SendCertificateTrust_ThrowsOnUnsupportedPlatform() { (X509Certificate2 certificate, X509Certificate2Collection caCerts) = TestHelper.GenerateCertificates(nameof(SslStream_SendCertificateTrust_CertificateCollection)); From b637e18f03f3e37b36bcd66a9398e79c0555ed07 Mon Sep 17 00:00:00 2001 From: Radek Zikmund Date: Wed, 2 Mar 2022 14:27:09 +0100 Subject: [PATCH 4/4] Remove unwanted changes --- .../SslStreamNetworkStreamTest.cs | 31 ++++++++++++------- 1 file changed, 19 insertions(+), 12 deletions(-) diff --git a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamNetworkStreamTest.cs b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamNetworkStreamTest.cs index 0364b0dbf4d076..44dbc87d84b265 100644 --- a/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamNetworkStreamTest.cs +++ b/src/libraries/System.Net.Security/tests/FunctionalTests/SslStreamNetworkStreamTest.cs @@ -275,11 +275,8 @@ public async Task SslStream_NegotiateClientCertificateAsyncNoRenego_Succeeds(boo return sendClientCertificate ? clientCertificate : null; }; - SslServerAuthenticationOptions serverOptions = new SslServerAuthenticationOptions() - { - ServerCertificate = serverCertificate, - AllowRenegotiation = false - }; + SslServerAuthenticationOptions serverOptions = new SslServerAuthenticationOptions() { ServerCertificate = serverCertificate, + AllowRenegotiation = false }; serverOptions.RemoteCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) => { if (negotiateClientCertificateCalled && sendClientCertificate) @@ -356,7 +353,7 @@ await TestConfiguration.WhenAllOrAnyFailedWithTimeout( // Send application data instead of Client hello. await client.WriteAsync(new byte[500], cts.Token); // Fail as it is not allowed to receive non handshake frames during handshake. - await Assert.ThrowsAsync(() => t); + await Assert.ThrowsAsync(()=> t); } } @@ -407,7 +404,7 @@ await TestConfiguration.WhenAllOrAnyFailedWithTimeout( int read = await server.ReadAsync(buffer, cts.Token); // Fail as there are still some undrained data (incomplete incoming TLS frame) - await Assert.ThrowsAsync(() => + await Assert.ThrowsAsync(()=> server.NegotiateClientCertificateAsync(cts.Token) ); @@ -475,10 +472,17 @@ await TestConfiguration.WhenAllOrAnyFailedWithTimeout( } [ConditionalTheory(typeof(PlatformDetection), nameof(PlatformDetection.SupportsTls13))] + [ActiveIssue("https://github.com/dotnet/runtime/issues/58927", TestPlatforms.Windows)] [InlineData(true)] [InlineData(false)] public async Task SslStream_NegotiateClientCertificateAsyncTls13_Succeeds(bool sendClientCertificate) { + if (PlatformDetection.IsWindows10Version22000OrGreater) + { + // [ActiveIssue("https://github.com/dotnet/runtime/issues/58927")] + throw new SkipTestException("Unstable on Windows 11"); + } + bool negotiateClientCertificateCalled = false; using CancellationTokenSource cts = new CancellationTokenSource(); cts.CancelAfter(TestConfiguration.PassingTestTimeout); @@ -723,11 +727,12 @@ await TestConfiguration.WhenAllOrAnyFailedWithTimeout( [Theory] [InlineData(true)] [InlineData(false)] + [ActiveIssue("https://github.com/dotnet/runtime/issues/46837", TestPlatforms.OSX)] public async Task SslStream_UntrustedCaWithCustomCallback_OK(bool usePartialChain) { int split = Random.Shared.Next(0, certificates.serverChain.Count - 1); - var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost" }; + var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost" }; clientOptions.RemoteCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) => { @@ -785,10 +790,11 @@ public async Task SslStream_UntrustedCaWithCustomCallback_OK(bool usePartialChai [PlatformSpecific(TestPlatforms.AnyUnix)] [InlineData(true)] [InlineData(false)] + [ActiveIssue("https://github.com/dotnet/runtime/issues/46837", TestPlatforms.OSX)] public async Task SslStream_UntrustedCaWithCustomCallback_Throws(bool customCallback) { string errorMessage; - var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost" }; + var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost" }; if (customCallback) { clientOptions.RemoteCertificateValidationCallback = @@ -830,7 +836,8 @@ public async Task SslStream_UntrustedCaWithCustomCallback_Throws(bool customCall } } - [Fact] + [ConditionalFact] + [ActiveIssue("https://github.com/dotnet/runtime/issues/46837", TestPlatforms.OSX)] public async Task SslStream_ClientCertificate_SendsChain() { List streams = new List(); @@ -857,7 +864,7 @@ public async Task SslStream_ClientCertificate_SendsChain() } } - var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost", }; + var clientOptions = new SslClientAuthenticationOptions() { TargetHost = "localhost", }; clientOptions.RemoteCertificateValidationCallback = (sender, certificate, chain, sslPolicyErrors) => true; clientOptions.LocalCertificateSelectionCallback = (sender, target, certificates, remoteCertificate, issuers) => clientCertificate; @@ -901,7 +908,7 @@ public async Task SslStream_ClientCertificate_SendsChain() c.Dispose(); } - foreach (SslStream s in streams) + foreach (SslStream s in streams) { s.Dispose(); }