summaryrefslogtreecommitdiff
path: root/jstests/ssl_linear/ssl_cert_selector.js
diff options
context:
space:
mode:
authorLucas de Castro Borges <lucas@gnuabordo.com.br>2025-02-11 15:07:35 -0300
committerLucas de Castro Borges <lucas@gnuabordo.com.br>2025-02-11 15:07:35 -0300
commit4cb8841196d0625dfa3825aa326f071cd27c7b8b (patch)
tree1682a647d4463397c119183369ae6f750d5fdcff /jstests/ssl_linear/ssl_cert_selector.js
parentaa03c6362cbaa767638e6eed9b031d86dd2643d1 (diff)
parent8f0827553e09872941945a093b647a4211a9db7f (diff)
Update upstream source from tag 'upstream/6.0.0'master
Update to upstream version '6.0.0' with Debian dir 5604a80ec1c96ca76f25f40d78e6ef855abec322
Diffstat (limited to 'jstests/ssl_linear/ssl_cert_selector.js')
-rw-r--r--jstests/ssl_linear/ssl_cert_selector.js71
1 files changed, 0 insertions, 71 deletions
diff --git a/jstests/ssl_linear/ssl_cert_selector.js b/jstests/ssl_linear/ssl_cert_selector.js
deleted file mode 100644
index d52e5d1d5fb..00000000000
--- a/jstests/ssl_linear/ssl_cert_selector.js
+++ /dev/null
@@ -1,71 +0,0 @@
-/**
- * Validate that the shell can load certificates from the certificate store and connect to the
- * server.
- */
-
-load('jstests/libs/python.js');
-load('jstests/ssl/libs/ssl_helpers.js');
-
-requireSSLProvider('windows', function() {
- 'use strict';
-
- if (_isWindows()) {
- assert.eq(0,
- runProgram(getPython3Binary(), "jstests/ssl_linear/windows_castore_cleanup.py"));
-
- // SChannel backed follows Windows rules and only trusts Root in LocalMachine
- runProgram("certutil.exe", "-addstore", "-f", "Root", "jstests\\libs\\ca.pem");
- // Import a pfx file since it contains both a cert and private key and is easy to import
- // via command line.
- runProgram("certutil.exe",
- "-importpfx",
- "-f",
- "-p",
- "qwerty",
- "jstests\\libs\\trusted-client.pfx");
- }
-
- try {
- const conn = MongoRunner.runMongod({
- sslMode: 'requireSSL',
- sslPEMKeyFile: "jstests\\libs\\trusted-server.pem",
- setParameter: {tlsUseSystemCA: true},
- });
-
- const testWithCert = function(certSelector) {
- jsTest.log(`Testing with SSL cert ${certSelector}`);
- const argv = [
- 'mongo',
- '--ssl',
- '--sslCertificateSelector',
- certSelector,
- '--port',
- conn.port,
- '--eval',
- 'db.runCommand({buildInfo: 1})'
- ];
-
- const exitStatus = runMongoProgram.apply(null, argv);
- assert.eq(exitStatus, 0, "successfully connected with SSL");
- };
-
- const trusted_client_thumbprint = cat('jstests/libs/trusted-client.pem.digest.sha1');
-
- assert.doesNotThrow(function() {
- testWithCert("thumbprint=" + trusted_client_thumbprint);
- });
-
- assert.doesNotThrow(function() {
- testWithCert("subject=Trusted Kernel Test Client");
- });
-
- MongoRunner.stopMongod(conn);
- } finally {
- if (_isWindows()) {
- const trusted_ca_thumbprint = cat('jstests/libs/trusted-ca.pem.digest.sha1');
- runProgram("certutil.exe", "-delstore", "-f", "Root", trusted_ca_thumbprint);
- const ca_thumbprint = cat('jstests/libs/ca.pem.digest.sha1');
- runProgram("certutil.exe", "-delstore", "-f", "Root", ca_thumbprint);
- }
- }
-});