5065N/A<?xml version="1.0" encoding="UTF-8" standalone="no"?>
5065N/A<!DOCTYPE stax SYSTEM "/shared/stax.dtd">
5065N/A<!--
5065N/A ! CDDL HEADER START
5065N/A !
5065N/A ! The contents of this file are subject to the terms of the
5065N/A ! Common Development and Distribution License, Version 1.0 only
5065N/A ! (the "License"). You may not use this file except in compliance
5065N/A ! with the License.
5065N/A !
6982N/A ! You can obtain a copy of the license at legal-notices/CDDLv1_0.txt
6982N/A ! or http://forgerock.org/license/CDDLv1.0.html.
5065N/A ! See the License for the specific language governing permissions
5065N/A ! and limitations under the License.
5065N/A !
5065N/A ! When distributing Covered Code, include this CDDL HEADER in each
6982N/A ! file and include the License file at legal-notices/CDDLv1_0.txt.
6982N/A ! If applicable, add the following below this CDDL HEADER, with the
6982N/A ! fields enclosed by brackets "[]" replaced with your own identifying
6982N/A ! information:
5065N/A ! Portions Copyright [yyyy] [name of copyright owner]
5065N/A !
5065N/A ! CDDL HEADER END
5065N/A !
5065N/A ! Copyright 2010 Sun Microsystems, Inc.
6518N/A ! Portions Copyright 2013 ForgeRock AS
5065N/A ! -->
5065N/A<stax>
5065N/A
5065N/A <defaultcall function="clus_starttls_ldapcompare"/>
5065N/A
5065N/A <function name="clus_starttls_ldapcompare" scope="local">
5065N/A
5065N/A <sequence>
5065N/A
5065N/A <block name="'clus_starttls_ldapcompare'">
5065N/A
5065N/A <sequence>
5065N/A
5065N/A <!--- Test Suite information
5065N/A #@TestSuiteName StartTLS ldapcompare check behaviors
5065N/A #@TestSuitePurpose Test the results of StartTLS ldapcompare command.
5065N/A #@TestSuiteGroup ldapcompare check behavior tests
5065N/A #@TestScript clus_startTLS_ldapcompare.xml
5065N/A -->
5065N/A <script>
5065N/A if not CurrentTestPath.has_key('group'):
5065N/A CurrentTestPath['group'] = 'clu_secure'
5065N/A CurrentTestPath['suite'] = STAXCurrentBlock
5065N/A </script>
5065N/A
5065N/A <call function="'testSuite_Preamble'"/>
5065N/A
5065N/A <!--- Test Case information
5065N/A #@TestMarker StartTLS ldapcompare check behavior tests
5065N/A #@TestName Client use blind trust : ldapcompare successful
5065N/A #@TestPurpose Verify that the operation is successful and
5065N/A that the comparison is successful when client
5065N/A trust all server certificates.
5065N/A #@TestPreamble none
5065N/A #@TestStep Do an ldapcompare with correct options.
5065N/A #@TestPostamble none
5065N/A #@TestResult Success if ldapcompare return true
5065N/A -->
5065N/A <testcase name="getTestCaseName ('Client use blind trust : ldapcompare successful')">
5065N/A
5065N/A <sequence>
5065N/A
5065N/A <call function="'testCase_Preamble'"/>
5065N/A
5065N/A <message>
5065N/A 'Security: StartTLS Check behaviors : ldapcompare, client trustall\
5065N/A server cert'
5065N/A </message>
5065N/A
5065N/A <script>
5065N/A dncompare = 'uid=user.310,ou=people,dc=com'
5065N/A </script>
5065N/A <call function="'ldapCompareWithScript'">
5065N/A {
5065N/A 'dsInstanceHost' : DIRECTORY_INSTANCE_HOST ,
5065N/A 'dsInstancePort' : DIRECTORY_INSTANCE_PORT ,
5065N/A 'dsUseStartTLS' : ' ' ,
5065N/A 'dsTrustAll' : ' ' ,
5065N/A 'dsDn' : ['postalCode:6728' ,'%s' %dncompare],
6518N/A 'expectedRC' : 5
5065N/A }
5065N/A </call>
5065N/A
5065N/A <script>
5065N/A returnString = STAXResult[0][1]
5065N/A </script>
5065N/A <call function="'checktestString'">
5065N/A {
5065N/A 'returnString' : returnString ,
5065N/A 'expectedString' : 'Compare operation returned false'
5065N/A }
5065N/A </call>
5065N/A
5065N/A <call function="'ldapCompareWithScript'">
5065N/A {
5065N/A 'dsInstanceHost' : DIRECTORY_INSTANCE_HOST ,
5065N/A 'dsInstancePort' : DIRECTORY_INSTANCE_PORT ,
5065N/A 'dsUseStartTLS' : ' ' ,
5065N/A 'dsTrustAll' : ' ' ,
5065N/A 'dsDn' : ['postalCode:67258' ,'%s' %dncompare],
5065N/A }
5065N/A </call>
5065N/A
5065N/A <script>
5065N/A returnString = STAXResult[0][1]
5065N/A </script>
5065N/A <call function="'checktestString'">
5065N/A {
5065N/A 'returnString' : returnString ,
5065N/A 'expectedString' : 'Compare operation returned true'
5065N/A }
5065N/A </call>
5065N/A
5065N/A <call function="'testCase_Postamble'"/>
5065N/A
5065N/A </sequence>
5065N/A
5065N/A </testcase>
5065N/A
5065N/A <!--- Test Case information
5065N/A #@TestMarker StartTLS ldapcompare check behaviors
5065N/A #@TestName Client use TrustStore file :
5065N/A ldapcompare successful
5065N/A #@TestPurpose Verify that the operation is successful and
5065N/A that the comparison is successful when client
5065N/A uses TrustStore file.
5065N/A #@TestPreamble none
5065N/A #@TestStep Do an ldapcompare with correct options.
5065N/A #@TestPostamble none
5065N/A #@TestResult Success if ldapcompare return true
5065N/A -->
5065N/A <testcase name="getTestCaseName ('Client use TrustStore file : ldapcompare successful')">
5065N/A
5065N/A <sequence>
5065N/A
5065N/A <call function="'testCase_Preamble'"/>
5065N/A
5065N/A <message>
5065N/A 'Security:startTLS Check behaviors: ldapcompare, client trust \
5065N/A store file'
5065N/A </message>
5065N/A
5065N/A <script>
5065N/A dncompare2 = 'uid=user.311,ou=people,dc=com'
5065N/A </script>
5065N/A <call function="'ldapCompareWithScript'">
5065N/A {
5065N/A 'dsInstanceHost' : DIRECTORY_INSTANCE_HOST ,
5065N/A 'dsInstancePort' : DIRECTORY_INSTANCE_PORT ,
5065N/A 'dsUseStartTLS' : ' ' ,
5065N/A 'dsTrustStorePath' : '%s/client_cert/clientruststore' \
5065N/A % InstanceInstallDir,
5065N/A 'dsTrustStorePassword': 'clientruststorepass',
5065N/A 'dsDn' : ['description: This is for Amber Arbuckle.',\
5065N/A '%s' %dncompare2] ,
6518N/A 'expectedRC' : 5
5065N/A }
5065N/A </call>
5065N/A
5065N/A <script>
5065N/A returnString = STAXResult[0][1]
5065N/A </script>
5065N/A <call function="'checktestString'">
5065N/A {
5065N/A 'returnString' : returnString ,
5065N/A 'expectedString' : 'Compare operation returned false'
5065N/A }
5065N/A </call>
5065N/A
5065N/A <call function="'ldapCompareWithScript'">
5065N/A {
5065N/A 'dsInstanceHost' : DIRECTORY_INSTANCE_HOST ,
5065N/A 'dsInstancePort' : DIRECTORY_INSTANCE_PORT ,
5065N/A 'dsUseStartTLS' : ' ' ,
5065N/A 'dsTrustStorePath': '%s/client_cert/clientruststore' \
5065N/A % InstanceInstallDir,
5065N/A 'dsTrustStorePassword': 'clientruststorepass',
5065N/A 'dsDn' : ['description: This is the description for \
6518N/A Amber Arbuckle.' ,'%s' %dncompare2]
5065N/A }
5065N/A </call>
5065N/A
5065N/A <script>
5065N/A returnString = STAXResult[0][1]
5065N/A </script>
5065N/A <call function="'checktestString'">
5065N/A {
5065N/A 'returnString' : returnString ,
5065N/A 'expectedString' : 'Compare operation returned true'
5065N/A }
5065N/A </call>
5065N/A
5065N/A <call function="'testCase_Postamble'"/>
5065N/A
5065N/A </sequence>
5065N/A
5065N/A </testcase>
5065N/A
5065N/A <call function="'testSuite_Postamble'"/>
5065N/A
5065N/A </sequence>
5065N/A
5065N/A </block>
5065N/A
5065N/A </sequence>
5065N/A
5065N/A </function>
5065N/A
5065N/A</stax>
5065N/A
5065N/A