Fork TLSConfig for each encrypted connection (#5710)
* Fork TLSConfig for each encrypted connection Signed-off-by: sanyo <sanyo0714@163.com> Co-authored-by: sanyo <yeshengan.ysa@alibaba-inc.com>
This commit is contained in:
parent
575825a156
commit
9497644505
2 changed files with 52 additions and 29 deletions
|
@ -2,45 +2,66 @@ package test
|
|||
|
||||
import (
|
||||
"crypto/tls"
|
||||
"fmt"
|
||||
"testing"
|
||||
|
||||
"github.com/miekg/dns"
|
||||
)
|
||||
|
||||
func TestDNSoverTLS(t *testing.T) {
|
||||
corefile := `tls://.:1053 {
|
||||
func TestTLS(t *testing.T) {
|
||||
tempCorefile := `%s {
|
||||
tls ../plugin/tls/test_cert.pem ../plugin/tls/test_key.pem
|
||||
whoami
|
||||
}`
|
||||
qname := "example.com."
|
||||
qtype := dns.TypeA
|
||||
|
||||
dot, doh := ":1053", ":8443"
|
||||
m := new(dns.Msg)
|
||||
m.SetQuestion("example.com.", dns.TypeA)
|
||||
answerLength := 0
|
||||
|
||||
ex, _, tcp, err := CoreDNSServerAndPorts(corefile)
|
||||
if err != nil {
|
||||
t.Fatalf("Could not get CoreDNS serving instance: %s", err)
|
||||
}
|
||||
defer ex.Stop()
|
||||
|
||||
m := new(dns.Msg)
|
||||
m.SetQuestion(qname, qtype)
|
||||
client := dns.Client{
|
||||
Net: "tcp-tls",
|
||||
TLSConfig: &tls.Config{InsecureSkipVerify: true},
|
||||
}
|
||||
r, _, err := client.Exchange(m, tcp)
|
||||
|
||||
if err != nil {
|
||||
t.Fatalf("Could not exchange msg: %s", err)
|
||||
tests := []struct {
|
||||
server string
|
||||
tlsConfig *tls.Config
|
||||
}{
|
||||
{fmt.Sprintf("tls://.%s", dot),
|
||||
&tls.Config{InsecureSkipVerify: true},
|
||||
},
|
||||
{fmt.Sprintf("tls://.%s", dot),
|
||||
&tls.Config{InsecureSkipVerify: true, NextProtos: []string{"dot"}},
|
||||
},
|
||||
{fmt.Sprintf("tls://.%s https://.%s", dot, doh),
|
||||
&tls.Config{InsecureSkipVerify: true},
|
||||
},
|
||||
{fmt.Sprintf("tls://.%s https://.%s", dot, doh),
|
||||
&tls.Config{InsecureSkipVerify: true, NextProtos: []string{"dot"}},
|
||||
},
|
||||
}
|
||||
|
||||
if n := len(r.Answer); n != answerLength {
|
||||
t.Fatalf("Expected %v answers, got %v", answerLength, n)
|
||||
}
|
||||
if n := len(r.Extra); n != 2 {
|
||||
t.Errorf("Expected 2 RRs in additional section, but got %d", n)
|
||||
}
|
||||
if r.Rcode != dns.RcodeSuccess {
|
||||
t.Errorf("Expected success but got %d", r.Rcode)
|
||||
for _, tc := range tests {
|
||||
ex, _, _, err := CoreDNSServerAndPorts(fmt.Sprintf(tempCorefile, tc.server))
|
||||
if err != nil {
|
||||
t.Fatalf("Could not get CoreDNS serving instance: %s", err)
|
||||
}
|
||||
|
||||
client := dns.Client{
|
||||
Net: "tcp-tls",
|
||||
TLSConfig: tc.tlsConfig,
|
||||
}
|
||||
r, _, err := client.Exchange(m, dot)
|
||||
|
||||
if err != nil {
|
||||
t.Fatalf("Could not exchange msg: %s", err)
|
||||
}
|
||||
|
||||
if n := len(r.Answer); n != answerLength {
|
||||
t.Fatalf("Expected %v answers, got %v", answerLength, n)
|
||||
}
|
||||
if n := len(r.Extra); n != 2 {
|
||||
t.Errorf("Expected 2 RRs in additional section, but got %d", n)
|
||||
}
|
||||
if r.Rcode != dns.RcodeSuccess {
|
||||
t.Errorf("Expected success but got %d", r.Rcode)
|
||||
}
|
||||
ex.Stop()
|
||||
}
|
||||
}
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue