12 # Пререквизиты, которые должны быть установлены на машине:
13 # 1. tclsh. Может называться с версией (см. список версий ниже в цикле
15 # 2. ssh (что характерно, называться должен именно так). Должен быть
16 # настроен заход по ключам без пароля на lynx и все используемые эталонники.
17 # Ключи этих машин должны быть в knownhosts (с полными доменными именами
18 # серверов, то есть lynx.lan.cryptocom.ru и т.д.)
19 # 3. Под Windows скрипт выполняется в среде MinGW, при этом нужно "донастроить"
20 # ssh, а именно создать в разделе реестра
21 # HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
22 # DWORD-ключ DisableUserTOSSetting=0
24 CRYPTOPACK_MAIN_VERSION=3
26 : ${OPENSSL_APP:=$(which openssl 2>/dev/null)}
27 if [ -z "$OPENSSL_APP" ]; then
28 if [ "$OS" != "Windows NT" -a "$OS" != "Windows_NT" ]; then
29 if [ -x /opt/cryptopack$CRYPTOPACK_MAIN_VERSION/bin/openssl ]; then
30 OPENSSL_APP=/opt/cryptopack$CRYPTOPACK_MAIN_VERSION/bin/openssl
31 elif [ -x /usr/local/cryptopack$CRYPTOPACK_MAIN_VERSION/bin/openssl ];then
32 OPENSSL_APP=/usr/local/cryptopack$CRYPTOPACK_MAIN_VERSION/bin/openssl
35 if [ -x c:/cryptopack$CRYPTOPACK_MAIN_VERSION/bin/openssl.exe ] ; then
36 OPENSSL_APP=c:/cryptopack$CRYPTOPACK_MAIN_VERSION/bin/openssl.exe
40 if [ -z "$OPENSSL_APP" ]; then
41 echo "openssl not found"
44 echo "Using $OPENSSL_APP as openssl"
47 : ${TCLSH:=$(which tclsh)}
48 if [ -z "$TCLSH" ]; then
49 for version in "" 8.4 84 8.5 85 8.6 86; do
50 for command in tclsh$version; do
51 for dir in `echo "/opt/cryptopack/bin:$PATH" | sed -e 's/:/ /g'`; do
52 echo "Checking $dir/$command"
53 if [ -x $dir/$command ]; then
62 if [ -z "$TCLSH" ]; then
63 echo "tclsh not found in PATH, neither with nor without version, exiting"
66 echo "Using $TCLSH as tclsh"
68 TCLSH="$TCLSH -encoding utf-8"
70 APP_SUFFIX=`basename $OPENSSL_APP .exe|sed s/openssl//`
71 [ -n "$OPENSSL_APP" ]&& export OPENSSL_APP
72 ENGINE_NAME=`$TCLSH getengine.tcl`
74 TESTDIR=`hostname`-$ENGINE_NAME
75 [ -n "$APP_SUFFIX" ] && TESTDIR=${TESTDIR}-${APP_SUFFIX}
76 [ -d ${TESTDIR} ] && rm -rf ${TESTDIR}
81 case "$ENGINE_NAME" in
86 BASE_TESTS="engine dgst mac pkcs8 enc req-genpkey req-newkey ca smime smime2 smimeenc cms cms2 cmsenc pkcs12 nopath ocsp ts ssl smime_io cms_io smimeenc_io cmsenc_io"
87 OTHER_DIR=`echo $TESTDIR |sed 's/cryptocom/gost/'`
90 BASE_TESTS="engine dgst mac pkcs8 enc req-genpkey req-newkey ca smime smime2 smimeenc cms cms2 cmsenc pkcs12 nopath ocsp ts ssl smime_io cms_io smimeenc_io cmsenc_io"
91 OTHER_DIR=`echo $TESTDIR |sed 's/gost/cryptocom/'`
94 echo "No GOST=providing engine found" 1>&2
97 if [ -x copy_param ]; then
98 BASE_TESTS="$BASE_TESTS apache"
100 PKCS7_COMPATIBILITY_TESTS="smime_cs cmsenc_cs cmsenc_sc"
101 SERVER_TESTS="cp20 cp21 csp36r4 csp39 csp4 csp4r3 csp5"
102 CLIENT_TESTS="cp20 cp21"
103 WINCLIENT_TESTS="p1-1xa-tls1-v-cp36r4-srv p1-1xa-tls1-v-cp39-srv p1-1xa-tls1-v-cp4-01 p2-1xa-tls1-v-cp4-01 p2-2xa-tls1-v-cp4-12S p2-5xa-tls1-v-cp4-12L p1-1xa-tls1-v-cp4r3-01 p2-1xa-tls1-v-cp4r3-01 p2-2xa-tls1-v-cp4r3-01 p2-5xa-tls1-v-cp4r3-01 p1-1xa-tls1_1-v-cp4r3-01 p2-1xa-tls1_1-v-cp4r3-01 p2-2xa-tls1_1-v-cp4r3-01 p2-5xa-tls1_1-v-cp4r3-01 p1-1xa-tls1_2-v-cp4r3-01 p2-1xa-tls1_2-v-cp4r3-01 p2-2xa-tls1_2-v-cp4r3-01 p2-5xa-tls1_2-v-cp4r3-01 p1-1xa-tls1-v-cp5-01 p2-1xa-tls1-v-cp5-01 p2-2xa-tls1-v-cp5-01 p2-5xa-tls1-v-cp5-01 p1-1xa-tls1_1-v-cp5-01 p2-1xa-tls1_1-v-cp5-01 p2-2xa-tls1_1-v-cp5-01 p2-5xa-tls1_1-v-cp5-01 p1-1xa-tls1_2-v-cp5-01 p2-1xa-tls1_2-v-cp5-01 p2-2xa-tls1_2-v-cp5-01 p2-5xa-tls1_2-v-cp5-01 p8k-5xa-tls1_2-v-cp5-01 p8k-2xa-tls1_2-v-cp5-01 p8m-5xa-tls1_2-v-cp5-01 p8m-2xa-tls1_2-v-cp5-01"
104 OPENSSL_DEBUG_MEMORY=on
105 export OPENSSL_DEBUG_MEMORY
108 for t in $BASE_TESTS; do
109 $TCLSH $t.try || fail=1
112 if false; then # ignore some tests for a time
113 : ${OPENSSL_CONF:=$PWD/openssl-gost.cnf}
114 ALG_LIST="rsa:1024 gost2001:XA gost2012_256:XA gost2012_512:A" $TCLSH ssl.try -clientconf $OPENSSL_CONF || fail=1
115 ALG_LIST="rsa:1024 gost2001:XA gost2012_256:XA gost2012_512:A" $TCLSH ssl.try -serverconf $OPENSSL_CONF || fail=1
117 for t in $PKCS7_COMPATIBILITY_TESTS; do
118 $TCLSH $t.try || fail=1
120 for t in $SERVER_TESTS; do
121 $TCLSH server.try $t || fail=1
123 for t in $CLIENT_TESTS; do
124 $TCLSH client.try $t || fail=1
126 if [ -n "WINCLIENT_TESTS" ]; then
127 if [ -z "$CVS_RSH" ]; then
131 for t in $WINCLIENT_TESTS; do
132 $TCLSH wcli.try $t || fail=1
135 if [ -d $OTHER_DIR ]; then
136 OTHER_DIR=../${OTHER_DIR} $TCLSH interop.try
138 if [ -d OtherVersion ] ; then
139 case "$ENGINE_NAME" in
143 OTHER_DIR=../OtherVersion ALG_LIST="gost2001:A gost2001:B gost2001:C" ENC_LIST="gost2001:A:1.2.643.2.2.31.3 gost2001:B:1.2.643.2.2.31.4 gost2001:C:1.2.643.2.2.31.2 gost2001:A:" $TCLSH interop.try
146 OTHER_DIR=../OtherVersion ALG_LIST="gost2001:A gost2001:B gost2001:C" ENC_LIST="gost2001:A:1.2.643.2.2.31.3 gost2001:B:1.2.643.2.2.31.4 gost2001:C:1.2.643.2.2.31.2 gost2001:A:" $TCLSH interop.try
149 echo "No GOST=providing engine found" 1>&2
154 $TCLSH calcstat ${TESTDIR}/stats ${TESTDIR}/test.result
155 grep "leaked" ${TESTDIR}/*.log
156 if [ $fail -ne 0 ]; then
157 echo "Some tests FAILED."