2023-03-28 20:12:41 +00:00
|
|
|
// Copyright (c) HashiCorp, Inc.
|
|
|
|
// SPDX-License-Identifier: MPL-2.0
|
|
|
|
|
2018-03-27 23:50:17 +00:00
|
|
|
package api
|
|
|
|
|
|
|
|
import (
|
|
|
|
"testing"
|
2018-06-22 16:48:41 +00:00
|
|
|
"time"
|
|
|
|
|
2021-07-05 23:10:23 +00:00
|
|
|
"github.com/stretchr/testify/require"
|
|
|
|
|
2019-03-27 12:54:56 +00:00
|
|
|
"github.com/hashicorp/consul/sdk/testutil"
|
|
|
|
"github.com/hashicorp/consul/sdk/testutil/retry"
|
2018-03-27 23:50:17 +00:00
|
|
|
)
|
|
|
|
|
|
|
|
func TestAPI_ConnectCARoots_empty(t *testing.T) {
|
|
|
|
t.Parallel()
|
|
|
|
|
2018-05-10 16:04:33 +00:00
|
|
|
c, s := makeClientWithConfig(t, nil, func(c *testutil.TestServerConfig) {
|
2022-11-09 17:29:55 +00:00
|
|
|
// Explicitly disable Connect to prevent CA being bootstrapped
|
|
|
|
c.Connect = map[string]interface{}{
|
|
|
|
"enabled": false,
|
|
|
|
}
|
2018-05-10 16:04:33 +00:00
|
|
|
})
|
2018-03-27 23:50:17 +00:00
|
|
|
defer s.Stop()
|
|
|
|
|
2019-02-22 18:38:21 +00:00
|
|
|
s.WaitForSerfCheck(t)
|
|
|
|
|
2018-03-27 23:50:17 +00:00
|
|
|
connect := c.Connect()
|
2018-07-25 19:26:27 +00:00
|
|
|
_, _, err := connect.CARoots(nil)
|
|
|
|
|
bulk rewrite using this script
set -euo pipefail
unset CDPATH
cd "$(dirname "$0")"
for f in $(git grep '\brequire := require\.New(' | cut -d':' -f1 | sort -u); do
echo "=== require: $f ==="
sed -i '/require := require.New(t)/d' $f
# require.XXX(blah) but not require.XXX(tblah) or require.XXX(rblah)
sed -i 's/\brequire\.\([a-zA-Z0-9_]*\)(\([^tr]\)/require.\1(t,\2/g' $f
# require.XXX(tblah) but not require.XXX(t, blah)
sed -i 's/\brequire\.\([a-zA-Z0-9_]*\)(\(t[^,]\)/require.\1(t,\2/g' $f
# require.XXX(rblah) but not require.XXX(r, blah)
sed -i 's/\brequire\.\([a-zA-Z0-9_]*\)(\(r[^,]\)/require.\1(t,\2/g' $f
gofmt -s -w $f
done
for f in $(git grep '\bassert := assert\.New(' | cut -d':' -f1 | sort -u); do
echo "=== assert: $f ==="
sed -i '/assert := assert.New(t)/d' $f
# assert.XXX(blah) but not assert.XXX(tblah) or assert.XXX(rblah)
sed -i 's/\bassert\.\([a-zA-Z0-9_]*\)(\([^tr]\)/assert.\1(t,\2/g' $f
# assert.XXX(tblah) but not assert.XXX(t, blah)
sed -i 's/\bassert\.\([a-zA-Z0-9_]*\)(\(t[^,]\)/assert.\1(t,\2/g' $f
# assert.XXX(rblah) but not assert.XXX(r, blah)
sed -i 's/\bassert\.\([a-zA-Z0-9_]*\)(\(r[^,]\)/assert.\1(t,\2/g' $f
gofmt -s -w $f
done
2022-01-20 16:46:23 +00:00
|
|
|
require.Error(t, err)
|
|
|
|
require.Contains(t, err.Error(), "Connect must be enabled")
|
2018-05-10 16:04:33 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
func TestAPI_ConnectCARoots_list(t *testing.T) {
|
|
|
|
t.Parallel()
|
|
|
|
|
|
|
|
c, s := makeClient(t)
|
|
|
|
defer s.Stop()
|
|
|
|
|
|
|
|
// This fails occasionally if server doesn't have time to bootstrap CA so
|
|
|
|
// retry
|
|
|
|
retry.Run(t, func(r *retry.R) {
|
|
|
|
connect := c.Connect()
|
|
|
|
list, meta, err := connect.CARoots(nil)
|
|
|
|
r.Check(err)
|
2020-05-14 21:02:52 +00:00
|
|
|
if meta.LastIndex == 0 {
|
2018-05-10 16:04:33 +00:00
|
|
|
r.Fatalf("expected roots raft index to be > 0")
|
|
|
|
}
|
|
|
|
if v := len(list.Roots); v != 1 {
|
|
|
|
r.Fatalf("expected 1 root, got %d", v)
|
|
|
|
}
|
|
|
|
// connect.TestClusterID causes import cycle so hard code it
|
|
|
|
if list.TrustDomain != "11111111-2222-3333-4444-555555555555.consul" {
|
|
|
|
r.Fatalf("expected fixed trust domain got '%s'", list.TrustDomain)
|
|
|
|
}
|
|
|
|
})
|
|
|
|
|
2018-03-27 23:50:17 +00:00
|
|
|
}
|
2018-05-23 21:44:24 +00:00
|
|
|
|
|
|
|
func TestAPI_ConnectCAConfig_get_set(t *testing.T) {
|
|
|
|
t.Parallel()
|
|
|
|
|
|
|
|
c, s := makeClient(t)
|
|
|
|
defer s.Stop()
|
|
|
|
|
2019-02-22 18:38:21 +00:00
|
|
|
s.WaitForSerfCheck(t)
|
2018-06-22 16:48:41 +00:00
|
|
|
expected := &ConsulCAProviderConfig{
|
2020-01-17 22:27:13 +00:00
|
|
|
IntermediateCertTTL: 365 * 24 * time.Hour,
|
2018-06-22 16:48:41 +00:00
|
|
|
}
|
2018-07-16 09:46:10 +00:00
|
|
|
expected.LeafCertTTL = 72 * time.Hour
|
2021-11-02 18:02:10 +00:00
|
|
|
expected.RootCertTTL = 10 * 365 * 24 * time.Hour
|
2018-06-22 16:48:41 +00:00
|
|
|
|
2018-05-23 21:44:24 +00:00
|
|
|
// This fails occasionally if server doesn't have time to bootstrap CA so
|
|
|
|
// retry
|
|
|
|
retry.Run(t, func(r *retry.R) {
|
|
|
|
connect := c.Connect()
|
|
|
|
|
|
|
|
conf, _, err := connect.CAGetConfig(nil)
|
|
|
|
r.Check(err)
|
|
|
|
if conf.Provider != "consul" {
|
|
|
|
r.Fatalf("expected default provider, got %q", conf.Provider)
|
|
|
|
}
|
2018-06-22 16:48:41 +00:00
|
|
|
parsed, err := ParseConsulCAConfig(conf.Config)
|
2018-05-23 21:44:24 +00:00
|
|
|
r.Check(err)
|
2019-03-29 15:29:27 +00:00
|
|
|
require.Equal(r, expected, parsed)
|
2018-05-23 21:44:24 +00:00
|
|
|
|
|
|
|
// Change a config value and update
|
2018-06-22 16:48:41 +00:00
|
|
|
conf.Config["PrivateKey"] = ""
|
2020-01-17 22:27:13 +00:00
|
|
|
conf.Config["IntermediateCertTTL"] = 300 * 24 * time.Hour
|
2021-11-02 18:02:10 +00:00
|
|
|
conf.Config["RootCertTTL"] = 11 * 365 * 24 * time.Hour
|
2020-01-17 22:27:13 +00:00
|
|
|
|
2019-11-21 17:40:29 +00:00
|
|
|
// Pass through some state as if the provider stored it so we can make sure
|
|
|
|
// we can read it again.
|
|
|
|
conf.Config["test_state"] = map[string]string{"foo": "bar"}
|
2020-01-17 22:27:13 +00:00
|
|
|
|
2018-05-23 21:44:24 +00:00
|
|
|
_, err = connect.CASetConfig(conf, nil)
|
2018-06-22 16:48:41 +00:00
|
|
|
r.Check(err)
|
|
|
|
|
|
|
|
updated, _, err := connect.CAGetConfig(nil)
|
|
|
|
r.Check(err)
|
2020-01-17 22:27:13 +00:00
|
|
|
expected.IntermediateCertTTL = 300 * 24 * time.Hour
|
2021-11-02 18:02:10 +00:00
|
|
|
expected.RootCertTTL = 11 * 365 * 24 * time.Hour
|
2018-06-22 16:48:41 +00:00
|
|
|
parsed, err = ParseConsulCAConfig(updated.Config)
|
|
|
|
r.Check(err)
|
2019-03-29 15:29:27 +00:00
|
|
|
require.Equal(r, expected, parsed)
|
2019-11-21 17:40:29 +00:00
|
|
|
require.Equal(r, "bar", updated.State["foo"])
|
2018-05-23 21:44:24 +00:00
|
|
|
})
|
|
|
|
}
|