2018-03-27 23:50:17 +00:00
|
|
|
package api
|
|
|
|
|
|
|
|
import (
|
2018-06-21 23:54:59 +00:00
|
|
|
"strings"
|
2018-03-27 23:50:17 +00:00
|
|
|
"testing"
|
|
|
|
|
2018-05-10 16:04:33 +00:00
|
|
|
"github.com/hashicorp/consul/testutil"
|
|
|
|
"github.com/hashicorp/consul/testutil/retry"
|
2018-03-27 23:50:17 +00:00
|
|
|
"github.com/stretchr/testify/require"
|
|
|
|
)
|
|
|
|
|
|
|
|
func TestAPI_ConnectCARoots_empty(t *testing.T) {
|
|
|
|
t.Parallel()
|
|
|
|
|
|
|
|
require := require.New(t)
|
2018-05-10 16:04:33 +00:00
|
|
|
c, s := makeClientWithConfig(t, nil, func(c *testutil.TestServerConfig) {
|
|
|
|
// Don't bootstrap CA
|
|
|
|
c.Connect = nil
|
|
|
|
})
|
2018-03-27 23:50:17 +00:00
|
|
|
defer s.Stop()
|
|
|
|
|
|
|
|
connect := c.Connect()
|
|
|
|
list, meta, err := connect.CARoots(nil)
|
2018-05-10 16:04:33 +00:00
|
|
|
require.NoError(err)
|
2018-06-13 19:01:05 +00:00
|
|
|
require.Equal(uint64(1), meta.LastIndex)
|
2018-03-27 23:50:17 +00:00
|
|
|
require.Len(list.Roots, 0)
|
2018-05-10 16:04:33 +00:00
|
|
|
require.Empty(list.TrustDomain)
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestAPI_ConnectCARoots_list(t *testing.T) {
|
|
|
|
t.Parallel()
|
|
|
|
|
|
|
|
c, s := makeClient(t)
|
|
|
|
defer s.Stop()
|
|
|
|
|
|
|
|
// This fails occasionally if server doesn't have time to bootstrap CA so
|
|
|
|
// retry
|
|
|
|
retry.Run(t, func(r *retry.R) {
|
|
|
|
connect := c.Connect()
|
|
|
|
list, meta, err := connect.CARoots(nil)
|
|
|
|
r.Check(err)
|
|
|
|
if meta.LastIndex <= 0 {
|
|
|
|
r.Fatalf("expected roots raft index to be > 0")
|
|
|
|
}
|
|
|
|
if v := len(list.Roots); v != 1 {
|
|
|
|
r.Fatalf("expected 1 root, got %d", v)
|
|
|
|
}
|
|
|
|
// connect.TestClusterID causes import cycle so hard code it
|
|
|
|
if list.TrustDomain != "11111111-2222-3333-4444-555555555555.consul" {
|
|
|
|
r.Fatalf("expected fixed trust domain got '%s'", list.TrustDomain)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
|
2018-03-27 23:50:17 +00:00
|
|
|
}
|
2018-05-23 21:44:24 +00:00
|
|
|
|
|
|
|
func TestAPI_ConnectCAConfig_get_set(t *testing.T) {
|
|
|
|
t.Parallel()
|
|
|
|
|
|
|
|
c, s := makeClient(t)
|
|
|
|
defer s.Stop()
|
|
|
|
|
|
|
|
// This fails occasionally if server doesn't have time to bootstrap CA so
|
|
|
|
// retry
|
|
|
|
retry.Run(t, func(r *retry.R) {
|
|
|
|
connect := c.Connect()
|
|
|
|
|
|
|
|
conf, _, err := connect.CAGetConfig(nil)
|
|
|
|
r.Check(err)
|
|
|
|
if conf.Provider != "consul" {
|
|
|
|
r.Fatalf("expected default provider, got %q", conf.Provider)
|
|
|
|
}
|
2018-06-21 23:54:59 +00:00
|
|
|
_, err = ParseConsulCAConfig(conf.Config)
|
2018-05-23 21:44:24 +00:00
|
|
|
r.Check(err)
|
|
|
|
|
|
|
|
// Change a config value and update
|
2018-06-21 23:54:59 +00:00
|
|
|
conf.Config["PrivateKey"] = "invalid"
|
2018-05-23 21:44:24 +00:00
|
|
|
_, err = connect.CASetConfig(conf, nil)
|
2018-06-21 23:54:59 +00:00
|
|
|
if err == nil || !strings.Contains(err.Error(),
|
|
|
|
"error parsing private key \"invalid\": no PEM-encoded data found") {
|
|
|
|
r.Fatal(err)
|
|
|
|
}
|
2018-05-23 21:44:24 +00:00
|
|
|
})
|
|
|
|
}
|