]>
Commit | Line | Data |
---|---|---|
afcd1c2f DB |
1 | QA output created by 233 |
2 | ||
3 | == preparing TLS creds == | |
4 | Generating a self signed certificate... | |
5 | Generating a self signed certificate... | |
6 | Generating a signed certificate... | |
7 | Generating a signed certificate... | |
8 | Generating a signed certificate... | |
b25e12da | 9 | Generating a signed certificate... |
10cc95c3 DB |
10 | Generating a random key for user 'psk1' |
11 | Generating a random key for user 'psk2' | |
afcd1c2f DB |
12 | |
13 | == preparing image == | |
14 | Formatting 'TEST_DIR/t.IMGFMT', fmt=IMGFMT size=67108864 | |
bb39c47d EB |
15 | wrote 1048576/1048576 bytes at offset 1048576 |
16 | 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) | |
afcd1c2f DB |
17 | |
18 | == check TLS client to plain server fails == | |
19 | qemu-img: Could not open 'driver=nbd,host=127.0.0.1,port=PORT,tls-creds=tls0': Denied by server for option 5 (starttls) | |
20 | server reported: TLS not configured | |
ddd09448 | 21 | qemu-nbd: Denied by server for option 5 (starttls) |
afcd1c2f DB |
22 | |
23 | == check plain client to TLS server fails == | |
5de47735 | 24 | qemu-img: Could not open 'nbd://localhost:PORT': TLS negotiation required before option 7 (go) |
1b5c15ce | 25 | Did you forget a valid tls-creds? |
5de47735 EB |
26 | server reported: Option 0x7 not permitted before TLS |
27 | qemu-nbd: TLS negotiation required before option 3 (list) | |
afcd1c2f DB |
28 | |
29 | == check TLS works == | |
30 | image: nbd://127.0.0.1:PORT | |
31 | file format: nbd | |
de38b500 | 32 | virtual size: 64 MiB (67108864 bytes) |
afcd1c2f | 33 | disk size: unavailable |
b25e12da DB |
34 | image: nbd://127.0.0.1:PORT |
35 | file format: nbd | |
de38b500 | 36 | virtual size: 64 MiB (67108864 bytes) |
b25e12da | 37 | disk size: unavailable |
ddd09448 EB |
38 | exports available: 1 |
39 | export: '' | |
40 | size: 67108864 | |
b0245d64 | 41 | min block: 1 |
afcd1c2f | 42 | |
3da93d4b DB |
43 | == check TLS fail over TCP with mismatched hostname == |
44 | qemu-img: Could not open 'driver=nbd,host=localhost,port=PORT,tls-creds=tls0': Certificate does not match the hostname localhost | |
45 | qemu-nbd: Certificate does not match the hostname localhost | |
46 | ||
47 | == check TLS works over TCP with mismatched hostname and override == | |
48 | image: nbd://localhost:PORT | |
49 | file format: nbd | |
50 | virtual size: 64 MiB (67108864 bytes) | |
51 | disk size: unavailable | |
52 | exports available: 1 | |
53 | export: '' | |
54 | size: 67108864 | |
55 | min block: 1 | |
56 | ||
afcd1c2f | 57 | == check TLS with different CA fails == |
afcd1c2f | 58 | qemu-img: Could not open 'driver=nbd,host=127.0.0.1,port=PORT,tls-creds=tls0': The certificate hasn't got a known issuer |
ddd09448 | 59 | qemu-nbd: The certificate hasn't got a known issuer |
bb39c47d EB |
60 | |
61 | == perform I/O over TLS == | |
62 | read 1048576/1048576 bytes at offset 1048576 | |
63 | 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) | |
64 | wrote 1048576/1048576 bytes at offset 1048576 | |
65 | 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) | |
66 | read 1048576/1048576 bytes at offset 1048576 | |
67 | 1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec) | |
d0898051 | 68 | |
b25e12da | 69 | == check TLS with authorization == |
876df72d HR |
70 | qemu-img: Could not open 'driver=nbd,host=127.0.0.1,port=PORT,tls-creds=tls0': Failed to read option reply: Cannot read from TLS channel: Software caused connection abort |
71 | qemu-img: Could not open 'driver=nbd,host=127.0.0.1,port=PORT,tls-creds=tls0': Failed to read option reply: Cannot read from TLS channel: Software caused connection abort | |
b25e12da | 72 | |
f0620835 DB |
73 | == check TLS fail over UNIX with no hostname == |
74 | qemu-img: Could not open 'driver=nbd,path=SOCK_DIR/qemu-nbd.sock,tls-creds=tls0': No hostname for certificate validation | |
75 | qemu-nbd: No hostname for certificate validation | |
76 | ||
77 | == check TLS works over UNIX with hostname override == | |
78 | image: nbd+unix://?socket=SOCK_DIR/qemu-nbd.sock | |
79 | file format: nbd | |
80 | virtual size: 64 MiB (67108864 bytes) | |
81 | disk size: unavailable | |
82 | exports available: 1 | |
83 | export: '' | |
84 | size: 67108864 | |
85 | min block: 1 | |
86 | ||
10cc95c3 DB |
87 | == check TLS works over UNIX with PSK == |
88 | image: nbd+unix://?socket=SOCK_DIR/qemu-nbd.sock | |
89 | file format: nbd | |
90 | virtual size: 64 MiB (67108864 bytes) | |
91 | disk size: unavailable | |
92 | exports available: 1 | |
93 | export: '' | |
94 | size: 67108864 | |
95 | min block: 1 | |
96 | ||
97 | == check TLS fails over UNIX with mismatch PSK == | |
98 | qemu-img: Could not open 'driver=nbd,path=SOCK_DIR/qemu-nbd.sock,tls-creds=tls0': TLS handshake failed: The TLS connection was non-properly terminated. | |
99 | qemu-nbd: TLS handshake failed: The TLS connection was non-properly terminated. | |
100 | ||
d0898051 | 101 | == final server log == |
3da93d4b DB |
102 | qemu-nbd: option negotiation failed: Failed to read opts magic: Cannot read from TLS channel: Software caused connection abort |
103 | qemu-nbd: option negotiation failed: Failed to read opts magic: Cannot read from TLS channel: Software caused connection abort | |
d0898051 | 104 | qemu-nbd: option negotiation failed: Verify failed: No certificate was found. |
ddd09448 | 105 | qemu-nbd: option negotiation failed: Verify failed: No certificate was found. |
a6d2bb25 DB |
106 | qemu-nbd: option negotiation failed: TLS x509 authz check for DISTINGUISHED-NAME is denied |
107 | qemu-nbd: option negotiation failed: TLS x509 authz check for DISTINGUISHED-NAME is denied | |
f0620835 DB |
108 | qemu-nbd: option negotiation failed: Failed to read opts magic: Cannot read from TLS channel: Software caused connection abort |
109 | qemu-nbd: option negotiation failed: Failed to read opts magic: Cannot read from TLS channel: Software caused connection abort | |
10cc95c3 DB |
110 | qemu-nbd: option negotiation failed: TLS handshake failed: An illegal parameter has been received. |
111 | qemu-nbd: option negotiation failed: TLS handshake failed: An illegal parameter has been received. | |
afcd1c2f | 112 | *** done |