tests: check for the case where a password is incorrectly entered

This is a reproducer for the issue reported in #323

Signed-off-by: Nikos Mavrogiannopoulos <n.mavrogiannopoulos@gmail.com>
This commit is contained in:
Nikos Mavrogiannopoulos
2026-04-03 12:29:01 +02:00
parent 9840050511
commit c45e3467bb
2 changed files with 14 additions and 0 deletions
+6
View File
@@ -41,6 +41,12 @@ echo "Connecting to obtain cookie with wrong password... "
( echo "tost" | LD_PRELOAD=libsocket_wrapper.so $OPENCONNECT -q $ADDRESS:$PORT -u test --servercert=pin-sha256:xp3scfzy3rOQsv9NcOve/8YVVv+pHr4qNCXEXrNl5s8= --cookieonly >/dev/null 2>&1 ) &&
fail $PID "Received cookie when we shouldn't"
# Regression test for https://gitlab.com/openconnect/ocserv/-/work_items/323:
# wrong password on first attempt followed by correct password must succeed.
echo "Connecting with wrong password first, then correct password (retry in same session)... "
( printf "wrongpass\ntest\n" | LD_PRELOAD=libsocket_wrapper.so $OPENCONNECT --passwd-on-stdin -q $ADDRESS:$PORT -u test --servercert=pin-sha256:xp3scfzy3rOQsv9NcOve/8YVVv+pHr4qNCXEXrNl5s8= --cookieonly ) ||
fail $PID "Could not obtain cookie after retrying with correct password in same session"
echo "Connecting to obtain cookie with empty password... "
( echo -e "\n" | LD_PRELOAD=libsocket_wrapper.so $OPENCONNECT -q $ADDRESS:$PORT -u test --servercert=pin-sha256:xp3scfzy3rOQsv9NcOve/8YVVv+pHr4qNCXEXrNl5s8= --cookieonly >/dev/null 2>&1 ) &&
fail $PID "Received cookie when we shouldn't"
+8
View File
@@ -45,6 +45,14 @@ echo -n "Connecting to obtain cookie (with certificate)... "
echo ok
# Regression test for https://gitlab.com/openconnect/ocserv/-/work_items/323:
# wrong password on first attempt followed by correct password must succeed.
echo -n "Connecting with wrong password then correct password with certificate (retry in same session)... "
( printf "wrongpass\ntest\n" | LD_PRELOAD=libsocket_wrapper.so $OPENCONNECT --passwd-on-stdin -q $ADDRESS:$PORT --sslkey ${srcdir}/certs/user-key.pem -c ${srcdir}/certs/user-cert.pem -u test --servercert=pin-sha256:xp3scfzy3rOQsv9NcOve/8YVVv+pHr4qNCXEXrNl5s8= --cookieonly ) ||
fail $PID "Could not obtain cookie after password retry with certificate in same session"
echo ok
echo -n "Connecting to obtain cookie (with incorrect certificate)... "
( echo "test" | LD_PRELOAD=libsocket_wrapper.so $OPENCONNECT -q $ADDRESS:$PORT --sslkey ${srcdir}/certs/user-key.pem -c ${srcdir}/certs/user-cert-wrong.pem -u test --servercert=pin-sha256:xp3scfzy3rOQsv9NcOve/8YVVv+pHr4qNCXEXrNl5s8= --cookieonly >/dev/null 2>&1 ) &&
fail $PID "Should not have connected with wrong certificate!"