Chromium Code Reviews
chromiumcodereview-hr@appspot.gserviceaccount.com (chromiumcodereview-hr) | Please choose your nickname with Settings | Help | Chromium Project | Gerrit Changes | Sign out
(161)

Side by Side Diff: components/ssl_errors/error_classification_unittest.cc

Issue 2777383002: Update SSL error handling code to account for Subject CN deprecation (Closed)
Patch Set: Address nits Created 3 years, 8 months ago
Use n/p to move between diff chunks; N/P to move between comments. Draft comments are only viewable by you.
Jump to:
View unified diff | Download patch
OLDNEW
1 // Copyright 2015 The Chromium Authors. All rights reserved. 1 // Copyright 2015 The Chromium Authors. All rights reserved.
2 // Use of this source code is governed by a BSD-style license that can be 2 // Use of this source code is governed by a BSD-style license that can be
3 // found in the LICENSE file. 3 // found in the LICENSE file.
4 4
5 #include "components/ssl_errors/error_classification.h" 5 #include "components/ssl_errors/error_classification.h"
6 6
7 #include "base/files/file_path.h" 7 #include "base/files/file_path.h"
8 #include "base/memory/ptr_util.h" 8 #include "base/memory/ptr_util.h"
9 #include "base/message_loop/message_loop.h" 9 #include "base/message_loop/message_loop.h"
10 #include "base/strings/string_split.h" 10 #include "base/strings/string_split.h"
11 #include "base/test/histogram_tester.h" 11 #include "base/test/histogram_tester.h"
12 #include "base/test/simple_test_clock.h" 12 #include "base/test/simple_test_clock.h"
13 #include "base/test/simple_test_tick_clock.h" 13 #include "base/test/simple_test_tick_clock.h"
14 #include "base/threading/thread_task_runner_handle.h" 14 #include "base/threading/thread_task_runner_handle.h"
15 #include "base/time/default_clock.h" 15 #include "base/time/default_clock.h"
16 #include "base/time/default_tick_clock.h" 16 #include "base/time/default_tick_clock.h"
17 #include "components/network_time/network_time_test_utils.h" 17 #include "components/network_time/network_time_test_utils.h"
18 #include "components/network_time/network_time_tracker.h" 18 #include "components/network_time/network_time_tracker.h"
19 #include "components/prefs/testing_pref_service.h" 19 #include "components/prefs/testing_pref_service.h"
20 #include "net/base/net_errors.h" 20 #include "net/base/net_errors.h"
21 #include "net/cert/x509_cert_types.h" 21 #include "net/cert/x509_cert_types.h"
22 #include "net/cert/x509_certificate.h" 22 #include "net/cert/x509_certificate.h"
23 #include "net/test/cert_test_util.h" 23 #include "net/test/cert_test_util.h"
24 #include "net/test/embedded_test_server/embedded_test_server.h" 24 #include "net/test/embedded_test_server/embedded_test_server.h"
25 #include "net/test/embedded_test_server/http_response.h" 25 #include "net/test/embedded_test_server/http_response.h"
26 #include "net/test/test_certificate_data.h" 26 #include "net/test/test_certificate_data.h"
27 #include "net/test/test_data_directory.h" 27 #include "net/test/test_data_directory.h"
28 #include "net/url_request/url_request_test_util.h" 28 #include "net/url_request/url_request_test_util.h"
29 #include "testing/gmock/include/gmock/gmock.h"
29 #include "testing/gtest/include/gtest/gtest.h" 30 #include "testing/gtest/include/gtest/gtest.h"
30 #include "url/gurl.h" 31 #include "url/gurl.h"
31 32
33 using testing::ElementsAre;
34
32 namespace { 35 namespace {
33 const char kNetworkTimeHistogram[] = "interstitial.ssl.clockstate.network3"; 36 const char kNetworkTimeHistogram[] = "interstitial.ssl.clockstate.network3";
34 37
35 static std::unique_ptr<net::test_server::HttpResponse> 38 static std::unique_ptr<net::test_server::HttpResponse>
36 NetworkErrorResponseHandler(const net::test_server::HttpRequest& request) { 39 NetworkErrorResponseHandler(const net::test_server::HttpRequest& request) {
37 return std::unique_ptr<net::test_server::HttpResponse>( 40 return std::unique_ptr<net::test_server::HttpResponse>(
38 new net::test_server::RawHttpResponse("", "")); 41 new net::test_server::RawHttpResponse("", ""));
39 } 42 }
40 43
41 } // namespace 44 } // namespace
42 45
43 class SSLErrorClassificationTest : public ::testing::Test { 46 class SSLErrorClassificationTest : public ::testing::Test {
44 public: 47 public:
45 SSLErrorClassificationTest() 48 SSLErrorClassificationTest()
46 : field_trial_test_(new network_time::FieldTrialTest()) {} 49 : field_trial_test_(new network_time::FieldTrialTest()) {}
47 network_time::FieldTrialTest* field_trial_test() { 50 network_time::FieldTrialTest* field_trial_test() {
48 return field_trial_test_.get(); 51 return field_trial_test_.get();
49 } 52 }
50 53
51 private: 54 private:
52 std::unique_ptr<network_time::FieldTrialTest> field_trial_test_; 55 std::unique_ptr<network_time::FieldTrialTest> field_trial_test_;
53 }; 56 };
54 57
55 TEST_F(SSLErrorClassificationTest, TestNameMismatch) { 58 TEST_F(SSLErrorClassificationTest, TestNameMismatch) {
56 scoped_refptr<net::X509Certificate> google_cert( 59 scoped_refptr<net::X509Certificate> example_cert = net::ImportCertFromFile(
57 net::X509Certificate::CreateFromBytes( 60 net::GetTestCertsDirectory(), "subjectAltName_www_example_com.pem");
58 reinterpret_cast<const char*>(google_der), sizeof(google_der))); 61 ASSERT_TRUE(example_cert.get());
59 ASSERT_TRUE(google_cert.get()); 62 std::vector<std::string> dns_names_example;
60 std::vector<std::string> dns_names_google; 63 example_cert->GetDNSNames(&dns_names_example);
61 google_cert->GetDNSNames(&dns_names_google); 64 ASSERT_THAT(dns_names_example, ElementsAre("www.example.com"));
62 ASSERT_EQ(1u, dns_names_google.size()); // ["www.google.com"] 65 std::vector<std::string> hostname_tokens_example =
63 std::vector<std::string> hostname_tokens_google = 66 ssl_errors::Tokenize(dns_names_example[0]);
64 ssl_errors::Tokenize(dns_names_google[0]); 67 ASSERT_THAT(hostname_tokens_example, ElementsAre("www", "example", "com"));
65 ASSERT_EQ(3u, hostname_tokens_google.size()); // ["www","google","com"] 68 std::vector<std::vector<std::string>> dns_name_tokens_example;
66 std::vector<std::vector<std::string>> dns_name_tokens_google; 69 dns_name_tokens_example.push_back(hostname_tokens_example);
67 dns_name_tokens_google.push_back(hostname_tokens_google); 70 ASSERT_EQ(1u, dns_name_tokens_example.size()); // [["www","example","com"]]
68 ASSERT_EQ(1u, dns_name_tokens_google.size()); // [["www","google","com"]] 71 ASSERT_THAT(dns_name_tokens_example[0], ElementsAre("www", "example", "com"));
69 72
70 { 73 {
71 GURL origin("https://google.com"); 74 GURL origin("https://example.com");
72 std::string www_host; 75 std::string www_host;
73 std::vector<std::string> host_name_tokens = base::SplitString( 76 std::vector<std::string> host_name_tokens = base::SplitString(
74 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); 77 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL);
75 EXPECT_TRUE( 78 EXPECT_TRUE(
76 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_google, &www_host)); 79 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_example, &www_host));
77 EXPECT_EQ("www.google.com", www_host); 80 EXPECT_EQ("www.example.com", www_host);
78 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, 81 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens,
79 dns_name_tokens_google)); 82 dns_name_tokens_example));
80 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_google, 83 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_example,
81 host_name_tokens)); 84 host_name_tokens));
82 EXPECT_FALSE(ssl_errors::IsSubDomainOutsideWildcard(origin, *google_cert)); 85 EXPECT_FALSE(ssl_errors::IsSubDomainOutsideWildcard(origin, *example_cert));
83 EXPECT_FALSE( 86 EXPECT_FALSE(
84 ssl_errors::IsCertLikelyFromMultiTenantHosting(origin, *google_cert)); 87 ssl_errors::IsCertLikelyFromMultiTenantHosting(origin, *example_cert));
85 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); 88 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *example_cert));
86 } 89 }
87 90
88 { 91 {
89 GURL origin("https://foo.blah.google.com"); 92 GURL origin("https://foo.blah.example.com");
90 std::string www_host; 93 std::string www_host;
91 std::vector<std::string> host_name_tokens = base::SplitString( 94 std::vector<std::string> host_name_tokens = base::SplitString(
92 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); 95 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL);
93 EXPECT_FALSE( 96 EXPECT_FALSE(
94 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_google, &www_host)); 97 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_example, &www_host));
95 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, 98 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens,
96 dns_name_tokens_google)); 99 dns_name_tokens_example));
97 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_google, 100 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_example,
98 host_name_tokens)); 101 host_name_tokens));
99 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); 102 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *example_cert));
100 } 103 }
101 104
102 { 105 {
103 GURL origin("https://foo.www.google.com"); 106 GURL origin("https://foo.www.example.com");
104 std::string www_host; 107 std::string www_host;
105 std::vector<std::string> host_name_tokens = base::SplitString( 108 std::vector<std::string> host_name_tokens = base::SplitString(
106 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); 109 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL);
107 EXPECT_FALSE( 110 EXPECT_FALSE(
108 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_google, &www_host)); 111 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_example, &www_host));
109 EXPECT_TRUE(ssl_errors::NameUnderAnyNames(host_name_tokens, 112 EXPECT_TRUE(ssl_errors::NameUnderAnyNames(host_name_tokens,
110 dns_name_tokens_google)); 113 dns_name_tokens_example));
111 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_google, 114 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_example,
112 host_name_tokens)); 115 host_name_tokens));
113 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); 116 EXPECT_TRUE(ssl_errors::IsCertLikelyFromSameDomain(origin, *example_cert));
114 } 117 }
115 118
116 { 119 {
117 GURL origin("https://www.google.com.foo"); 120 GURL origin("https://www.example.com.foo");
118 std::string www_host; 121 std::string www_host;
119 std::vector<std::string> host_name_tokens = base::SplitString( 122 std::vector<std::string> host_name_tokens = base::SplitString(
120 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); 123 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL);
121 EXPECT_FALSE( 124 EXPECT_FALSE(
122 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_google, &www_host)); 125 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_example, &www_host));
123 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, 126 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens,
124 dns_name_tokens_google)); 127 dns_name_tokens_example));
125 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_google, 128 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_example,
126 host_name_tokens)); 129 host_name_tokens));
130 EXPECT_FALSE(ssl_errors::IsCertLikelyFromSameDomain(origin, *example_cert));
131 }
132
133 {
134 GURL origin("https://www.fooexample.com.");
135 std::string www_host;
136 std::vector<std::string> host_name_tokens = base::SplitString(
137 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL);
138 EXPECT_FALSE(
139 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_example, &www_host));
140 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens,
141 dns_name_tokens_example));
142 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_example,
143 host_name_tokens));
144 EXPECT_FALSE(ssl_errors::IsCertLikelyFromSameDomain(origin, *example_cert));
145 }
146
147 // Ensure that a certificate with no SubjectAltNames does not fall back to
148 // the Subject CN when evaluating hostnames.
149 {
150 scoped_refptr<net::X509Certificate> google_cert(
151 net::X509Certificate::CreateFromBytes(
152 reinterpret_cast<const char*>(google_der), sizeof(google_der)));
153 ASSERT_TRUE(google_cert.get());
154
155 GURL origin("https://google.com");
156 EXPECT_FALSE(ssl_errors::IsWWWSubDomainMatch(origin, *google_cert));
127 EXPECT_FALSE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); 157 EXPECT_FALSE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert));
128 } 158 }
129 159
130 { 160 {
131 GURL origin("https://www.foogoogle.com."); 161 scoped_refptr<net::X509Certificate> webkit_cert(
132 std::string www_host; 162 net::X509Certificate::CreateFromBytes(
133 std::vector<std::string> host_name_tokens = base::SplitString( 163 reinterpret_cast<const char*>(webkit_der), sizeof(webkit_der)));
134 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); 164 ASSERT_TRUE(webkit_cert.get());
135 EXPECT_FALSE( 165 std::vector<std::string> dns_names_webkit;
136 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_google, &www_host)); 166 webkit_cert->GetDNSNames(&dns_names_webkit);
137 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, 167 ASSERT_EQ(2u, dns_names_webkit.size()); // ["*.webkit.org", "webkit.org"]
138 dns_name_tokens_google)); 168 std::vector<std::string> hostname_tokens_webkit_0 =
139 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_google, 169 ssl_errors::Tokenize(dns_names_webkit[0]);
140 host_name_tokens)); 170 ASSERT_EQ(3u, hostname_tokens_webkit_0.size()); // ["*", "webkit","org"]
141 EXPECT_FALSE(ssl_errors::IsCertLikelyFromSameDomain(origin, *google_cert)); 171 std::vector<std::string> hostname_tokens_webkit_1 =
142 } 172 ssl_errors::Tokenize(dns_names_webkit[1]);
143 173 ASSERT_EQ(2u, hostname_tokens_webkit_1.size()); // ["webkit","org"]
144 scoped_refptr<net::X509Certificate> webkit_cert( 174 std::vector<std::vector<std::string>> dns_name_tokens_webkit;
145 net::X509Certificate::CreateFromBytes( 175 dns_name_tokens_webkit.push_back(hostname_tokens_webkit_0);
146 reinterpret_cast<const char*>(webkit_der), sizeof(webkit_der))); 176 dns_name_tokens_webkit.push_back(hostname_tokens_webkit_1);
147 ASSERT_TRUE(webkit_cert.get()); 177 ASSERT_EQ(2u, dns_name_tokens_webkit.size());
148 std::vector<std::string> dns_names_webkit;
149 webkit_cert->GetDNSNames(&dns_names_webkit);
150 ASSERT_EQ(2u, dns_names_webkit.size()); // ["*.webkit.org", "webkit.org"]
151 std::vector<std::string> hostname_tokens_webkit_0 =
152 ssl_errors::Tokenize(dns_names_webkit[0]);
153 ASSERT_EQ(3u, hostname_tokens_webkit_0.size()); // ["*", "webkit","org"]
154 std::vector<std::string> hostname_tokens_webkit_1 =
155 ssl_errors::Tokenize(dns_names_webkit[1]);
156 ASSERT_EQ(2u, hostname_tokens_webkit_1.size()); // ["webkit","org"]
157 std::vector<std::vector<std::string>> dns_name_tokens_webkit;
158 dns_name_tokens_webkit.push_back(hostname_tokens_webkit_0);
159 dns_name_tokens_webkit.push_back(hostname_tokens_webkit_1);
160 ASSERT_EQ(2u, dns_name_tokens_webkit.size());
161 {
162 GURL origin("https://a.b.webkit.org"); 178 GURL origin("https://a.b.webkit.org");
163 std::string www_host; 179 std::string www_host;
164 std::vector<std::string> host_name_tokens = base::SplitString( 180 std::vector<std::string> host_name_tokens = base::SplitString(
165 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL); 181 origin.host(), ".", base::KEEP_WHITESPACE, base::SPLIT_WANT_ALL);
166 EXPECT_FALSE( 182 EXPECT_FALSE(
167 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_webkit, &www_host)); 183 ssl_errors::GetWWWSubDomainMatch(origin, dns_names_webkit, &www_host));
168 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens, 184 EXPECT_FALSE(ssl_errors::NameUnderAnyNames(host_name_tokens,
169 dns_name_tokens_webkit)); 185 dns_name_tokens_webkit));
170 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_webkit, 186 EXPECT_FALSE(ssl_errors::AnyNamesUnderName(dns_name_tokens_webkit,
171 host_name_tokens)); 187 host_name_tokens));
(...skipping 274 matching lines...) Expand 10 before | Expand all | Expand 10 after
446 clock->Advance(base::TimeDelta::FromDays(1)); 462 clock->Advance(base::TimeDelta::FromDays(1));
447 // GetClockState() will fall back to the build time heuristic. 463 // GetClockState() will fall back to the build time heuristic.
448 ssl_errors::GetClockState(clock->Now(), &network_time_tracker); 464 ssl_errors::GetClockState(clock->Now(), &network_time_tracker);
449 histograms.ExpectTotalCount(kNetworkTimeHistogram, 8); 465 histograms.ExpectTotalCount(kNetworkTimeHistogram, 8);
450 histograms.ExpectBucketCount( 466 histograms.ExpectBucketCount(
451 kNetworkTimeHistogram, ssl_errors::NETWORK_CLOCK_STATE_UNKNOWN_SYNC_LOST, 467 kNetworkTimeHistogram, ssl_errors::NETWORK_CLOCK_STATE_UNKNOWN_SYNC_LOST,
452 1); 468 1);
453 469
454 io_thread.Stop(); 470 io_thread.Stop();
455 } 471 }
OLDNEW

Powered by Google App Engine
This is Rietveld 408576698