rustls/bogo/config.json

286 lines
16 KiB
JSON

{
"DisabledTests": {
"SendV2ClientHello-*": "only support TLS1.2",
"*SSL3*": "",
"*SSLv3*": "",
"*TLS1-*": "",
"*-TLS1": "",
"*TLS11-*": "",
"*-TLS11": "",
"ConflictingVersionNegotiation": "",
"SendFallbackSCSV": "fallback scsv not implemented",
"PointFormat-Server-Missing": "we require ecc",
"ECDSAKeyUsage-*": "TODO: we don't do anything with key usages",
"CheckRecordVersion-*": "we don't look at record version",
"TLS13-WrongOuterRecord": "we're lax on this",
"*DTLS*": "not supported",
"TokenBinding-*": "not supported",
"DummyPQPadding-*": "not supported",
"MTU*": "dtls only",
"DisableEverything": "not useful",
"SendEmptyRecords": "non-standard openssl/boringssl behaviour",
"SendEmptyRecords-Async": "",
"SendWarningAlerts": "",
"SendWarningAlerts-*": "",
"LargeMessage-Reject": "",
"Peek-*": "",
"*-Split": "",
"EchoTLS13CompatibilitySessionID": "",
"SendHelloRetryRequest-2-TLS13Draft23": "we accept any supported keyshare",
"OmitExtensions-ServerHello-TLS12": "bug in bogo if sct offered",
"EmptyExtensions-ServerHello-TLS12": "",
"CBCRecordSplitting*": "insane ciphersuites",
"*CBCPadding*": "",
"RSAEphemeralKey": "",
"BadRSAClientKeyExchange-*": "",
"SendClientVersion-RSA": "",
"Basic-Server-RSA-*": "",
"*-3DES-*": "",
"*-AES128-SHA*": "",
"*-AES256-SHA*": "",
"*-ECDSA-SHA1-*": "no ecdsa-sha1",
"*-Sign-RSA-PKCS1-SHA1-*": "no sha1",
"*-P-224-*": "no p224",
"*-P521-*": "no p521",
"CurveTest-Client-P-521-TLS12": "",
"CurveTest-Server-P-521-TLS12": "",
"CurveTest-Client-Compressed-P-521-TLS12": "",
"CurveTest-Server-Compressed-P-521-TLS12": "",
"CurveTest-Client-P-521-TLS13Draft23": "",
"CurveTest-Server-P-521-TLS13Draft23": "",
"CurveTest-Client-Compressed-P-521-TLS13Draft23": "",
"CurveTest-Server-Compressed-P-521-TLS13Draft23": "",
"*-Ed25519": "no ed25519 yet",
"*-Ed25519-*": "",
"GREASE-*": "not implemented",
"LargeMessage-Reject": "",
"SkipEarlyData*": "no 0rtt support",
"TLS13-DuplicateTicketEarlyDataInfo": "",
"NoCommonCurves": "nothing to fall back to",
"ClientHelloPadding": "hello padding extension not implemented",
"Resume-Client-CipherMismatch": "tries to vary to unimplemented CBC-mode cs",
"*Auth-SHA1-Fallback*": "",
"RSA-PSS-Large": "",
"TLS12-AES128-GCM-*": "no pfs",
"TLS12-AES256-GCM-*": "",
"OmitExtensions-ClientHello-TLS12": "",
"EmptyExtensions-ClientHello-TLS12": "",
"*-ECDSA-*-server": "ECDSA signing not yet implemented",
"ClientAuth-Sign-ECDSA-*": "",
"ServerAuth-Sign-ECDSA-*": "",
"*-Client-ClientAuth-ECDSA": "",
"Basic-Server-*-ECDSA-*": "",
"FallbackSCSV*": "fallback countermeasure not yet implemented",
"RequireAnyClientCertificate-TLS12": "we don't send an alert in this case",
"TooManyKeyUpdates": "no limit implemented",
"TooManyChangeCipherSpec-*": "",
"ServerBogusVersion": "we ignore legacy_version if there's an extension",
"Renegotiate-Client-*": "no reneg",
"Shutdown-Shim-Renegotiate-*": "",
"Shutdown-Shim-HelloRequest-*": "",
"Renegotiate-Server-*": "",
"SendHalfHelloRequest-*": "",
"RetainOnlySHA256-*": "",
"ExtendedMasterSecret-Renego-*": "",
"Draft-Downgrade-Server": "not implemented; TODO"
},
"ErrorMap": {
":HTTP_REQUEST:": ":GARBAGE:",
":HTTPS_PROXY_REQUEST:": ":GARBAGE:",
":WRONG_VERSION_NUMBER:": ":GARBAGE:",
":PEER_DID_NOT_RETURN_A_CERTIFICATE:": ":NO_CERTS:",
":UNEXPECTED_RECORD:": ":UNEXPECTED_MESSAGE:",
":NO_RENEGOTIATION:": ":UNEXPECTED_MESSAGE:",
":DIGEST_CHECK_FAILED:": ":DECRYPTION_FAILED_OR_BAD_RECORD_MAC:",
":APPLICATION_DATA_INSTEAD_OF_HANDSHAKE:": ":UNEXPECTED_MESSAGE:",
":ENCRYPTED_LENGTH_TOO_LONG:": ":GARBAGE:"
},
"TestErrorMap": {
"EmptyCertificateList": ":NO_CERTS:",
"SendInvalidRecordType": ":GARBAGE:",
"NoSharedCipher": ":HANDSHAKE_FAILURE:",
"NoSharedCipher-TLS13": ":HANDSHAKE_FAILURE:",
"InvalidECDHPoint-Client": ":PEER_MISBEHAVIOUR:",
"InvalidECDHPoint-Server": ":PEER_MISBEHAVIOUR:",
"TrailingMessageData-ClientHello": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-ServerHello": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-ServerCertificate": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-CertificateRequest": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-ClientCertificate": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-CertificateVerify": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-NewSessionTicket": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-ServerHelloDone": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-ServerKeyExchange": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-ClientKeyExchange": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-CertificateStatus": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-TLS13-ClientHello": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-TLS13-ServerHello": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-TLS13-EncryptedExtensions": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-TLS13-CertificateRequest": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-TLS13-ServerCertificate": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-TLS13-ServerCertificateVerify": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-TLS13-ServerFinished": ":DECRYPTION_FAILED_OR_BAD_RECORD_MAC:",
"TrailingMessageData-TLS13-ClientCertificate": ":BAD_HANDSHAKE_MSG:",
"TrailingMessageData-TLS13-ClientCertificateVerify": ":BAD_HANDSHAKE_MSG:",
"MissingKeyShare-Client-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"MissingKeyShare-Server-TLS13Draft23": ":INCOMPATIBLE:",
"EmptyEncryptedExtensions-TLS13Draft23": ":BAD_HANDSHAKE_MSG:",
"NoSupportedCurves": ":INCOMPATIBLE:",
"BadECDHECurve": ":PEER_MISBEHAVIOUR:",
"VersionTooLow": ":INCOMPATIBLE:",
"UnofferedExtension-Client": ":PEER_MISBEHAVIOUR:",
"ServerHelloBogusCipher": ":PEER_MISBEHAVIOUR:",
"ServerHelloBogusCipher-TLS13": ":PEER_MISBEHAVIOUR:",
"ALPNClient-RejectUnknown-TLS12": ":PEER_MISBEHAVIOUR:",
"ALPNClient-EmptyProtocolName-TLS12": ":PEER_MISBEHAVIOUR:",
"ALPNServer-EmptyProtocolName-TLS12": ":PEER_MISBEHAVIOUR:",
"Verify-ServerAuth-SignatureType": ":PEER_MISBEHAVIOUR:",
"ClientAuth-Enforced": ":PEER_MISBEHAVIOUR:",
"ServerAuth-Enforced": ":PEER_MISBEHAVIOUR:",
"UnofferedExtension-Client": ":PEER_MISBEHAVIOUR:",
"UnknownExtension-Client": ":PEER_MISBEHAVIOUR:",
"KeyUpdate-InvalidRequestMode": ":BAD_HANDSHAKE_MSG:",
"ExtraCompressionMethods-TLS13": ":PEER_MISBEHAVIOUR:",
"NoNullCompression-TLS12": ":INCOMPATIBLE:",
"NoNullCompression-TLS13": ":INCOMPATIBLE:",
"InvalidCompressionMethod": ":PEER_MISBEHAVIOUR:",
"TLS13Draft23-InvalidCompressionMethod": ":PEER_MISBEHAVIOUR:",
"TLS13Draft23-AES128-GCM-server": ":INCOMPATIBLE:",
"TLS13Draft23-AES128-GCM-client": ":PEER_MISBEHAVIOUR:",
"TLS13Draft23-AES256-GCM-server": ":INCOMPATIBLE:",
"TLS13Draft23-AES256-GCM-client": ":PEER_MISBEHAVIOUR:",
"TLS13Draft23-ECDHE-ECDSA-AES128-GCM-client": ":PEER_MISBEHAVIOUR:",
"TLS13Draft23-ECDHE-ECDSA-AES256-GCM-client": ":PEER_MISBEHAVIOUR:",
"TLS13Draft23-ECDHE-ECDSA-CHACHA20-POLY1305-client": ":PEER_MISBEHAVIOUR:",
"TLS13Draft23-ECDHE-RSA-AES128-GCM-server": ":INCOMPATIBLE:",
"TLS13Draft23-ECDHE-RSA-AES128-GCM-client": ":PEER_MISBEHAVIOUR:",
"TLS13Draft23-ECDHE-RSA-AES256-GCM-server": ":INCOMPATIBLE:",
"TLS13Draft23-ECDHE-RSA-AES256-GCM-client": ":PEER_MISBEHAVIOUR:",
"TLS13Draft23-ECDHE-RSA-CHACHA20-POLY1305-server": ":INCOMPATIBLE:",
"TLS13Draft23-ECDHE-RSA-CHACHA20-POLY1305-client": ":PEER_MISBEHAVIOUR:",
"TLS12-AEAD-CHACHA20-POLY1305-server": ":INCOMPATIBLE:",
"TLS12-AEAD-CHACHA20-POLY1305-client": ":PEER_MISBEHAVIOUR:",
"TLS12-AEAD-AES128-GCM-SHA256-server": ":INCOMPATIBLE:",
"TLS12-AEAD-AES128-GCM-SHA256-client": ":PEER_MISBEHAVIOUR:",
"TLS12-AEAD-AES256-GCM-SHA384-server": ":INCOMPATIBLE:",
"TLS12-AEAD-AES256-GCM-SHA384-client": ":PEER_MISBEHAVIOUR:",
"SkipHelloRetryRequest-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"NoSupportedVersions": ":INCOMPATIBLE:",
"ClientAuth-Verify-RSA-PKCS1-SHA1-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ServerAuth-Verify-RSA-PKCS1-SHA1-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ClientAuth-Verify-RSA-PKCS1-SHA256-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ServerAuth-Verify-RSA-PKCS1-SHA256-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ClientAuth-Verify-RSA-PKCS1-SHA384-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ServerAuth-Verify-RSA-PKCS1-SHA384-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ClientAuth-Verify-RSA-PKCS1-SHA512-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ServerAuth-Verify-RSA-PKCS1-SHA512-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ServerAuth-Sign-RSA-PKCS1-SHA256-TLS13Draft23": ":INCOMPATIBLE:",
"ServerAuth-Sign-RSA-PKCS1-SHA384-TLS13Draft23": ":INCOMPATIBLE:",
"ServerAuth-Sign-RSA-PKCS1-SHA512-TLS13Draft23": ":INCOMPATIBLE:",
"ClientAuth-Sign-RSA-PKCS1-SHA256-TLS13Draft23": ":INCOMPATIBLE:",
"ClientAuth-Sign-RSA-PKCS1-SHA384-TLS13Draft23": ":INCOMPATIBLE:",
"ClientAuth-Sign-RSA-PKCS1-SHA512-TLS13Draft23": ":INCOMPATIBLE:",
"ALPNClient-EmptyProtocolName-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ALPNServer-EmptyProtocolName-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ALPNClient-RejectUnknown-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"ClientAuth-NoFallback-TLS13": ":INCOMPATIBLE:",
"ServerAuth-NoFallback-TLS13": ":INCOMPATIBLE:",
"ClientAuth-Enforced-TLS13": ":PEER_MISBEHAVIOUR:",
"ServerAuth-Enforced-TLS13": ":PEER_MISBEHAVIOUR:",
"SecondClientHelloWrongCurve-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"SecondClientHelloMissingKeyShare-TLS13Draft23": ":INCOMPATIBLE:",
"Resume-Server-BinderWrongLength": ":PEER_MISBEHAVIOUR:",
"Resume-Server-NoPSKBinder": ":PEER_MISBEHAVIOUR:",
"Resume-Server-ExtraPSKBinder": ":PEER_MISBEHAVIOUR:",
"Resume-Server-ExtraIdentityNoBinder": ":PEER_MISBEHAVIOUR:",
"Resume-Server-InvalidPSKBinder": ":PEER_MISBEHAVIOUR:",
"Resume-Server-PSKBinderFirstExtension": ":PEER_MISBEHAVIOUR:",
"Resume-Server-UnofferedCipher": ":PEER_MISBEHAVIOUR:",
"Resume-Server-UnofferedCipher-TLS13": ":PEER_MISBEHAVIOUR:",
"Resume-Client-CipherMismatch-TLS13": ":PEER_MISBEHAVIOUR:",
"Resume-Client-PRFMismatch-TLS13": ":PEER_MISBEHAVIOUR:",
"Resume-Client-Mismatch-TLS12-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"Resume-Client-Mismatch-TLS13Draft23-TLS12": ":PEER_MISBEHAVIOUR:",
"NoSupportedCurves-TLS13": ":INCOMPATIBLE:",
"BadECDHECurve-TLS13": ":PEER_MISBEHAVIOUR:",
"InvalidECDHPoint-Client-TLS13": ":PEER_MISBEHAVIOUR:",
"InvalidECDHPoint-Server-TLS13": ":PEER_MISBEHAVIOUR:",
"InvalidPSKIdentity-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"AlwaysSelectPSKIdentity-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"TrailingKeyShareData-TLS13Draft23": ":BAD_HANDSHAKE_MSG:",
"HelloRetryRequestCurveMismatch-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"HelloRetryRequestVersionMismatch-TLS13Draft23": ":BAD_HANDSHAKE_MSG:",
"HelloRetryRequest-DuplicateCookie-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"HelloRetryRequest-DuplicateCurve-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"UnknownUnencryptedExtension-Client-TLS13": ":PEER_MISBEHAVIOUR:",
"UnexpectedUnencryptedExtension-Client-TLS13": ":PEER_MISBEHAVIOUR:",
"UnofferedExtension-Client-TLS13": ":PEER_MISBEHAVIOUR:",
"RenegotiationInfo-Forbidden-TLS13": ":PEER_MISBEHAVIOUR:",
"UnknownExtension-Client-TLS13": ":PEER_MISBEHAVIOUR:",
"RequestContextInHandshake-TLS13Draft23": ":BAD_HANDSHAKE_MSG:",
"UnnecessaryHelloRetryRequest-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"UnknownCurve-HelloRetryRequest-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"DisabledCurve-HelloRetryRequest-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"HelloRetryRequest-Empty-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"HelloRetryRequest-EmptyCookie-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"HelloRetryRequest-Unknown-TLS13Draft23": ":INCOMPATIBLE:",
"MinimumVersion-Client-TLS13Draft23-TLS12": ":INCOMPATIBLE:",
"MinimumVersion-Client2-TLS13Draft23-TLS12": ":INCOMPATIBLE:",
"MinimumVersion-Server-TLS13Draft23-TLS12": ":INCOMPATIBLE:",
"MinimumVersion-Server2-TLS13Draft23-TLS12": ":INCOMPATIBLE:",
"DuplicateKeyShares-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"PartialEncryptedExtensionsWithServerHello": ":PEER_MISBEHAVIOUR:",
"PartialClientFinishedWithClientHello": ":PEER_MISBEHAVIOUR:",
"PointFormat-EncryptedExtensions-TLS13": ":PEER_MISBEHAVIOUR:",
"Ticket-Forbidden-TLS13": ":PEER_MISBEHAVIOUR:",
"PointFormat-Server-MissingUncompressed": ":INCOMPATIBLE:",
"MissingSignatureAlgorithmsInCertificateRequest-TLS13Draft23": ":INCOMPATIBLE:",
"NegotiatePSKResumption-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"PointFormat-Client-MissingUncompressed": ":PEER_MISBEHAVIOUR:",
"SendUnsolicitedOCSPOnCertificate-TLS13": ":PEER_MISBEHAVIOUR:",
"SendUnsolicitedSCTOnCertificate-TLS13": ":PEER_MISBEHAVIOUR:",
"UnsolicitedServerNameAck-TLS12": ":PEER_MISBEHAVIOUR:",
"UnsolicitedServerNameAck-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"TicketSessionIDLength-33-TLS12": ":BAD_HANDSHAKE_MSG:",
"Ed25519DefaultDisable-NoAccept": ":PEER_MISBEHAVIOUR:",
"SendUnknownExtensionOnCertificate-TLS13": ":PEER_MISBEHAVIOUR:",
"SendDuplicateExtensionsOnCerts-TLS13": ":PEER_MISBEHAVIOUR:",
"SignedCertificateTimestampListEmpty-Client-TLS12": ":PEER_MISBEHAVIOUR:",
"SignedCertificateTimestampListEmpty-Client-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"SignedCertificateTimestampListEmptySCT-Client-TLS12": ":PEER_MISBEHAVIOUR:",
"SignedCertificateTimestampListEmptySCT-Client-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"EMS-Forbidden-TLS13": ":PEER_MISBEHAVIOUR:",
"Unclean-Shutdown": ":CLOSE_WITHOUT_CLOSE_NOTIFY:",
"SendExtensionOnClientCertificate-TLS13": ":PEER_MISBEHAVIOUR:",
"SendBogusAlertType": ":BAD_ALERT:",
"TLS13Draft23-HRR-InvalidCompressionMethod": ":BAD_HANDSHAKE_MSG:",
"CertificateCipherMismatch-RSA": ":PEER_MISBEHAVIOUR:",
"CertificateCipherMismatch-ECDSA": ":PEER_MISBEHAVIOUR:",
"ServerCipherFilter-RSA": ":INCOMPATIBLE:",
"SendServerHelloAsHelloRetryRequest": ":BAD_HANDSHAKE_MSG:",
"TLS13-OnlyPadding": ":PEER_MISBEHAVIOUR:",
"TLS13-EmptyRecords": ":PEER_MISBEHAVIOUR:",
"SupportedVersionSelection-TLS12": ":PEER_MISBEHAVIOUR:",
"HelloRetryRequestVersionMismatch-TLS13Draft23": ":INCOMPATIBLE:",
"HelloRetryRequest-CipherChange-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"CurveTest-Client-Compressed-P-256-TLS12": ":PEER_MISBEHAVIOUR:",
"CurveTest-Server-Compressed-P-256-TLS12": ":PEER_MISBEHAVIOUR:",
"CurveTest-Client-Compressed-P-256-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"CurveTest-Server-Compressed-P-256-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"CurveTest-Client-Compressed-P-384-TLS12": ":PEER_MISBEHAVIOUR:",
"CurveTest-Server-Compressed-P-384-TLS12": ":PEER_MISBEHAVIOUR:",
"CurveTest-Client-Compressed-P-384-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"CurveTest-Server-Compressed-P-384-TLS13Draft23": ":PEER_MISBEHAVIOUR:",
"QUICTransportParams-Client-Rejected-TLS12": ":PEER_MISBEHAVIOUR:",
"QUICTransportParams-Server-Rejected-TLS12": "missing peer quic transport params",
"ExtendedMasterSecret-NoToYes-Client": ":PEER_MISBEHAVIOUR:",
"ExtendedMasterSecret-YesToNo-Server": ":PEER_MISBEHAVIOUR:",
"ExtendedMasterSecret-YesToNo-Client": ":PEER_MISBEHAVIOUR:"
},
"TestLocalErrorMap": {
"SendServerHelloAsHelloRetryRequest": "remote error: error decoding message",
"GarbageCertificate-Server-TLS12": "remote error: access denied",
"GarbageCertificate-Server-TLS13Draft23": "remote error: access denied"
}
}