| OLD | NEW |
| 1 // Copyright 2015 The Chromium Authors. All rights reserved. | 1 // Copyright 2015 The Chromium Authors. All rights reserved. |
| 2 // Use of this source code is governed by a BSD-style license that can be | 2 // Use of this source code is governed by a BSD-style license that can be |
| 3 // found in the LICENSE file. | 3 // found in the LICENSE file. |
| 4 | 4 |
| 5 #include "components/ssl_errors/error_classification.h" | 5 #include "components/ssl_errors/error_classification.h" |
| 6 | 6 |
| 7 #include "base/files/file_path.h" | 7 #include "base/files/file_path.h" |
| 8 #include "base/memory/ptr_util.h" | 8 #include "base/memory/ptr_util.h" |
| 9 #include "base/message_loop/message_loop.h" | 9 #include "base/message_loop/message_loop.h" |
| 10 #include "base/strings/string_split.h" | 10 #include "base/strings/string_split.h" |
| 11 #include "base/test/histogram_tester.h" | 11 #include "base/test/histogram_tester.h" |
| 12 #include "base/test/simple_test_clock.h" | 12 #include "base/test/simple_test_clock.h" |
| 13 #include "base/test/simple_test_tick_clock.h" | 13 #include "base/test/simple_test_tick_clock.h" |
| 14 #include "base/threading/thread_task_runner_handle.h" | 14 #include "base/threading/thread_task_runner_handle.h" |
| 15 #include "base/time/default_clock.h" | 15 #include "base/time/default_clock.h" |
| 16 #include "base/time/default_tick_clock.h" | 16 #include "base/time/default_tick_clock.h" |
| 17 #include "components/network_time/network_time_test_utils.h" | 17 #include "components/network_time/network_time_test_utils.h" |
| 18 #include "components/network_time/network_time_tracker.h" | 18 #include "components/network_time/network_time_tracker.h" |
| 19 #include "components/prefs/testing_pref_service.h" | 19 #include "components/prefs/testing_pref_service.h" |
| 20 #include "net/base/net_errors.h" | 20 #include "net/base/net_errors.h" |
| 21 #include "net/cert/x509_cert_types.h" | 21 #include "net/cert/x509_cert_types.h" |
| 22 #include "net/cert/x509_certificate.h" | 22 #include "net/cert/x509_certificate.h" |
| 23 #include "net/test/cert_test_util.h" | 23 #include "net/test/cert_test_util.h" |
| 24 #include "net/test/embedded_test_server/embedded_test_server.h" | 24 #include "net/test/embedded_test_server/embedded_test_server.h" |
| 25 #include "net/test/embedded_test_server/http_response.h" | 25 #include "net/test/embedded_test_server/http_response.h" |
| 26 #include "net/test/test_certificate_data.h" | 26 #include "net/test/test_certificate_data.h" |
| 27 #include "net/test/test_data_directory.h" | 27 #include "net/test/test_data_directory.h" |
| 28 #include "net/url_request/url_request_test_util.h" | 28 #include "net/url_request/url_request_test_util.h" |
| 29 #include "testing/gmock/include/gmock/gmock.h" |
| 29 #include "testing/gtest/include/gtest/gtest.h" | 30 #include "testing/gtest/include/gtest/gtest.h" |
| 30 #include "url/gurl.h" | 31 #include "url/gurl.h" |
| 31 | 32 |
| 33 using testing::ElementsAre; |
| 34 |
| 32 namespace { | 35 namespace { |
| 33 const char kNetworkTimeHistogram[] = "interstitial.ssl.clockstate.network3"; | 36 const char kNetworkTimeHistogram[] = "interstitial.ssl.clockstate.network3"; |
| 34 | 37 |
| 35 static std::unique_ptr<net::test_server::HttpResponse> | 38 static std::unique_ptr<net::test_server::HttpResponse> |
| 36 NetworkErrorResponseHandler(const net::test_server::HttpRequest& request) { | 39 NetworkErrorResponseHandler(const net::test_server::HttpRequest& request) { |
| 37 return std::unique_ptr<net::test_server::HttpResponse>( | 40 return std::unique_ptr<net::test_server::HttpResponse>( |
| 38 new net::test_server::RawHttpResponse("", "")); | 41 new net::test_server::RawHttpResponse("", "")); |
| 39 } | 42 } |
| 40 | 43 |
| 41 } // namespace | 44 } // namespace |
| 42 | 45 |
| 43 class SSLErrorClassificationTest : public ::testing::Test { | 46 class SSLErrorClassificationTest : public ::testing::Test { |
| 44 public: | 47 public: |
| 45 SSLErrorClassificationTest() | 48 SSLErrorClassificationTest() |
| 46 : field_trial_test_(new network_time::FieldTrialTest()) {} | 49 : field_trial_test_(new network_time::FieldTrialTest()) {} |
| 47 network_time::FieldTrialTest* field_trial_test() { | 50 network_time::FieldTrialTest* field_trial_test() { |
| 48 return field_trial_test_.get(); | 51 return field_trial_test_.get(); |
| 49 } | 52 } |
| 50 | 53 |
| 51 private: | 54 private: |
| 52 std::unique_ptr<network_time::FieldTrialTest> field_trial_test_; | 55 std::unique_ptr<network_time::FieldTrialTest> field_trial_test_; |
| 53 }; | 56 }; |
| 54 | 57 |
| 55 TEST_F(SSLErrorClassificationTest, TestNameMismatch) { | 58 TEST_F(SSLErrorClassificationTest, TestNameMismatch) { |
| 56 scoped_refptr<net::X509Certificate> google_cert( | 59 scoped_refptr<net::X509Certificate> example_cert = net::ImportCertFromFile( |
| 57 net::X509Certificate::CreateFromBytes( | 60 net::GetTestCertsDirectory(), "subjectAltName_www_example_com.pem"); |
| 58 reinterpret_cast<const char*>(google_der), sizeof(google_der))); | 61 ASSERT_TRUE(example_cert.get()); |
| 59 ASSERT_TRUE(google_cert.get()); | 62 std::vector<std::string> dns_names_example; |
| 60 std::vector<std::string> dns_names_google; | 63 example_cert->GetDNSNames(&dns_names_example); |
| 61 google_cert->GetDNSNames(&dns_names_google); | 64 ASSERT_THAT(dns_names_example, ElementsAre("www.example.com")); |
| 62 ASSERT_EQ(1u, dns_names_google.size()); // ["www.google.com"] | 65 std::vector<std::string> hostname_tokens_example = |
| 63 std::vector<std::string> hostname_tokens_google = | 66 ssl_errors::Tokenize(dns_names_example[0]); |
| 64 ssl_errors::Tokenize(dns_names_google[0]); | 67 ASSERT_THAT(hostname_tokens_example, ElementsAre("www", "example", "com")); |
| 65 ASSERT_EQ(3u, hostname_tokens_google.size()); // ["www","google","com"] | 68 std::vector<std::vector<std::string>> dns_name_tokens_example; |
| 66 std::vector<std::vector<std::string>> dns_name_tokens_google; | 69 dns_name_tokens_example.push_back(hostname_tokens_example); |
| 67 dns_name_tokens_google.push_back(hostname_tokens_google); | 70 ASSERT_EQ(1u, dns_name_tokens_example.size()); // [["www","example","com"]] |
| 68 ASSERT_EQ(1u, dns_name_tokens_google.size()); // [["www","google","com"]] | 71 ASSERT_THAT(dns_name_tokens_example[0], ElementsAre("www", "example", "com")); |
| 69 | 72 |
| 70 { | 73 { |
| 71 GURL origin("https://google.com"); | 74 GURL origin("https://example.com"); |
| 72 std::string www_host; | 75 std::string www_host; |
| 73 std::vector<std::string> host_name_tokens = base::SplitString( | 76 std::vector<std::string> host_name_tokens = base::SplitString( |
| 74 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); | 77 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); |
| 75 EXPECT_TRUE( | 78 EXPECT_TRUE( |
| 76 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_google, &www_host)); | 79 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_example, &www_host)); |
| 77 EXPECT_EQ("www.google.com", www_host); | 80 EXPECT_EQ("www.example.com", www_host); |
| 78 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, | 81 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, |
| 79 dns_name_tokens_google)); | 82 dns_name_tokens_example)); |
| 80 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_google, | 83 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_example, |
| 81 host_name_tokens)); | 84 host_name_tokens)); |
| 82 EXPECT_FALSE(ssl_errors::IsSubDomainOutsideWildcard(origin, *google_cert)); | 85 EXPECT_FALSE(ssl_errors::IsSubDomainOutsideWildcard(origin, *example_cert)); |
| 83 EXPECT_FALSE( | 86 EXPECT_FALSE( |
| 84 ssl_errors::IsCertLikelyFromMultiTenantHosting(origin, *google_cert)); | 87 ssl_errors::IsCertLikelyFromMultiTenantHosting(origin, *example_cert)); |
| 85 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); | 88 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *example_cert)); |
| 86 } | 89 } |
| 87 | 90 |
| 88 { | 91 { |
| 89 GURL origin("https://foo.blah.google.com"); | 92 GURL origin("https://foo.blah.example.com"); |
| 90 std::string www_host; | 93 std::string www_host; |
| 91 std::vector<std::string> host_name_tokens = base::SplitString( | 94 std::vector<std::string> host_name_tokens = base::SplitString( |
| 92 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); | 95 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); |
| 93 EXPECT_FALSE( | 96 EXPECT_FALSE( |
| 94 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_google, &www_host)); | 97 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_example, &www_host)); |
| 95 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, | 98 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, |
| 96 dns_name_tokens_google)); | 99 dns_name_tokens_example)); |
| 97 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_google, | 100 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_example, |
| 98 host_name_tokens)); | 101 host_name_tokens)); |
| 99 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); | 102 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *example_cert)); |
| 100 } | 103 } |
| 101 | 104 |
| 102 { | 105 { |
| 103 GURL origin("https://foo.www.google.com"); | 106 GURL origin("https://foo.www.example.com"); |
| 104 std::string www_host; | 107 std::string www_host; |
| 105 std::vector<std::string> host_name_tokens = base::SplitString( | 108 std::vector<std::string> host_name_tokens = base::SplitString( |
| 106 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); | 109 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); |
| 107 EXPECT_FALSE( | 110 EXPECT_FALSE( |
| 108 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_google, &www_host)); | 111 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_example, &www_host)); |
| 109 EXPECT_TRUE(ssl_errors::NameUnderAnyNames(host_name_tokens, | 112 EXPECT_TRUE(ssl_errors::NameUnderAnyNames(host_name_tokens, |
| 110 dns_name_tokens_google)); | 113 dns_name_tokens_example)); |
| 111 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_google, | 114 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_example, |
| 112 host_name_tokens)); | 115 host_name_tokens)); |
| 113 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); | 116 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *example_cert)); |
| 114 } | 117 } |
| 115 | 118 |
| 116 { | 119 { |
| 117 GURL origin("https://www.google.com.foo"); | 120 GURL origin("https://www.example.com.foo"); |
| 118 std::string www_host; | 121 std::string www_host; |
| 119 std::vector<std::string> host_name_tokens = base::SplitString( | 122 std::vector<std::string> host_name_tokens = base::SplitString( |
| 120 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); | 123 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); |
| 121 EXPECT_FALSE( | 124 EXPECT_FALSE( |
| 122 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_google, &www_host)); | 125 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_example, &www_host)); |
| 123 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, | 126 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, |
| 124 dns_name_tokens_google)); | 127 dns_name_tokens_example)); |
| 125 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_google, | 128 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_example, |
| 126 host_name_tokens)); | 129 host_name_tokens)); |
| 130 EXPECT_FALSE(ssl_errors::IsCertLikelyFromSameDomain(origin, *example_cert)); |
| 131 } |
| 132 |
| 133 { |
| 134 GURL origin("https://www.fooexample.com."); |
| 135 std::string www_host; |
| 136 std::vector<std::string> host_name_tokens = base::SplitString( |
| 137 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); |
| 138 EXPECT_FALSE( |
| 139 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_example, &www_host)); |
| 140 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, |
| 141 dns_name_tokens_example)); |
| 142 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_example, |
| 143 host_name_tokens)); |
| 144 EXPECT_FALSE(ssl_errors::IsCertLikelyFromSameDomain(origin, *example_cert)); |
| 145 } |
| 146 |
| 147 // Ensure that a certificate with no SubjectAltNames does not fall back to |
| 148 // the Subject CN when evaluating hostnames. |
| 149 { |
| 150 scoped_refptr<net::X509Certificate> google_cert( |
| 151 net::X509Certificate::CreateFromBytes( |
| 152 reinterpret_cast<const char*>(google_der), sizeof(google_der))); |
| 153 ASSERT_TRUE(google_cert.get()); |
| 154 |
| 155 GURL origin("https://google.com"); |
| 156 EXPECT_FALSE(ssl_errors::IsWWWSubDomainMatch(origin, *google_cert)); |
| 127 EXPECT_FALSE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); | 157 EXPECT_FALSE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); |
| 128 } | 158 } |
| 129 | 159 |
| 130 { | 160 { |
| 131 GURL origin("https://www.foogoogle.com."); | 161 scoped_refptr<net::X509Certificate> webkit_cert( |
| 132 std::string www_host; | 162 net::X509Certificate::CreateFromBytes( |
| 133 std::vector<std::string> host_name_tokens = base::SplitString( | 163 reinterpret_cast<const char*>(webkit_der), sizeof(webkit_der))); |
| 134 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); | 164 ASSERT_TRUE(webkit_cert.get()); |
| 135 EXPECT_FALSE( | 165 std::vector<std::string> dns_names_webkit; |
| 136 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_google, &www_host)); | 166 webkit_cert->GetDNSNames(&dns_names_webkit); |
| 137 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, | 167 ASSERT_EQ(2u, dns_names_webkit.size()); // ["*.webkit.org", "webkit.org"] |
| 138 dns_name_tokens_google)); | 168 std::vector<std::string> hostname_tokens_webkit_0 = |
| 139 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_google, | 169 ssl_errors::Tokenize(dns_names_webkit[0]); |
| 140 host_name_tokens)); | 170 ASSERT_EQ(3u, hostname_tokens_webkit_0.size()); // ["*", "webkit","org"] |
| 141 EXPECT_FALSE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); | 171 std::vector<std::string> hostname_tokens_webkit_1 = |
| 142 } | 172 ssl_errors::Tokenize(dns_names_webkit[1]); |
| 143 | 173 ASSERT_EQ(2u, hostname_tokens_webkit_1.size()); // ["webkit","org"] |
| 144 scoped_refptr<net::X509Certificate> webkit_cert( | 174 std::vector<std::vector<std::string>> dns_name_tokens_webkit; |
| 145 net::X509Certificate::CreateFromBytes( | 175 dns_name_tokens_webkit.push_back(hostname_tokens_webkit_0); |
| 146 reinterpret_cast<const char*>(webkit_der), sizeof(webkit_der))); | 176 dns_name_tokens_webkit.push_back(hostname_tokens_webkit_1); |
| 147 ASSERT_TRUE(webkit_cert.get()); | 177 ASSERT_EQ(2u, dns_name_tokens_webkit.size()); |
| 148 std::vector<std::string> dns_names_webkit; | |
| 149 webkit_cert->GetDNSNames(&dns_names_webkit); | |
| 150 ASSERT_EQ(2u, dns_names_webkit.size()); // ["*.webkit.org", "webkit.org"] | |
| 151 std::vector<std::string> hostname_tokens_webkit_0 = | |
| 152 ssl_errors::Tokenize(dns_names_webkit[0]); | |
| 153 ASSERT_EQ(3u, hostname_tokens_webkit_0.size()); // ["*", "webkit","org"] | |
| 154 std::vector<std::string> hostname_tokens_webkit_1 = | |
| 155 ssl_errors::Tokenize(dns_names_webkit[1]); | |
| 156 ASSERT_EQ(2u, hostname_tokens_webkit_1.size()); // ["webkit","org"] | |
| 157 std::vector<std::vector<std::string>> dns_name_tokens_webkit; | |
| 158 dns_name_tokens_webkit.push_back(hostname_tokens_webkit_0); | |
| 159 dns_name_tokens_webkit.push_back(hostname_tokens_webkit_1); | |
| 160 ASSERT_EQ(2u, dns_name_tokens_webkit.size()); | |
| 161 { | |
| 162 GURL origin("https://a.b.webkit.org"); | 178 GURL origin("https://a.b.webkit.org"); |
| 163 std::string www_host; | 179 std::string www_host; |
| 164 std::vector<std::string> host_name_tokens = base::SplitString( | 180 std::vector<std::string> host_name_tokens = base::SplitString( |
| 165 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); | 181 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); |
| 166 EXPECT_FALSE( | 182 EXPECT_FALSE( |
| 167 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_webkit, &www_host)); | 183 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_webkit, &www_host)); |
| 168 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, | 184 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, |
| 169 dns_name_tokens_webkit)); | 185 dns_name_tokens_webkit)); |
| 170 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_webkit, | 186 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_webkit, |
| 171 host_name_tokens)); | 187 host_name_tokens)); |
| (...skipping 274 matching lines...) Expand 10 before | Expand all | Expand 10 after Loading... |
| 446 clock->Advance(base::TimeDelta::FromDays(1)); | 462 clock->Advance(base::TimeDelta::FromDays(1)); |
| 447 // GetClockState() will fall back to the build time heuristic. | 463 // GetClockState() will fall back to the build time heuristic. |
| 448 ssl_errors::GetClockState(clock->Now(), &network_time_tracker); | 464 ssl_errors::GetClockState(clock->Now(), &network_time_tracker); |
| 449 histograms.ExpectTotalCount(kNetworkTimeHistogram, 8); | 465 histograms.ExpectTotalCount(kNetworkTimeHistogram, 8); |
| 450 histograms.ExpectBucketCount( | 466 histograms.ExpectBucketCount( |
| 451 kNetworkTimeHistogram, ssl_errors::NETWORK_CLOCK_STATE_UNKNOWN_SYNC_LOST, | 467 kNetworkTimeHistogram, ssl_errors::NETWORK_CLOCK_STATE_UNKNOWN_SYNC_LOST, |
| 452 1); | 468 1); |
| 453 | 469 |
| 454 io_thread.Stop(); | 470 io_thread.Stop(); |
| 455 } | 471 } |
| OLD | NEW |