Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion source/server/server.cc
Original file line number Diff line number Diff line change
Expand Up @@ -276,7 +276,7 @@ void InstanceImpl::updateServerStats() {
server_stats_->total_connections_.set(listener_manager_->numConnections() +
parent_stats.parent_connections_);
server_stats_->days_until_first_cert_expiring_.set(
sslContextManager().daysUntilFirstCertExpires().value());
sslContextManager().daysUntilFirstCertExpires().value_or(0));

auto secs_until_ocsp_response_expires =
sslContextManager().secondsUntilFirstOcspResponseExpires();
Expand Down
5 changes: 5 additions & 0 deletions test/config/integration/certs/BUILD
Original file line number Diff line number Diff line change
Expand Up @@ -20,3 +20,8 @@ envoy_cc_test_library(
name = "hashes",
hdrs = glob(["*hash.h"]),
)

envoy_cc_test_library(
name = "certs_info",
hdrs = glob(["*info.h"]),
)
9 changes: 7 additions & 2 deletions test/config/integration/certs/certs.sh
Original file line number Diff line number Diff line change
Expand Up @@ -27,10 +27,11 @@ generate_ecdsa_key() {
openssl ecparam -name secp256r1 -genkey -out "${1}key.pem"
}

# $1=<certificate name> $2=<CA name>
# $1=<certificate name> $2=<CA name> $3=[days]
generate_x509_cert() {
local days="${3:-730}"
openssl req -new -key "${1}key.pem" -out "${1}cert.csr" -config "${1}cert.cfg" -batch -sha256
openssl x509 -req -days 730 -in "${1}cert.csr" -sha256 -CA "${2}cert.pem" -CAkey \
openssl x509 -req -days "${days}" -in "${1}cert.csr" -sha256 -CA "${2}cert.pem" -CAkey \
"${2}key.pem" -CAcreateserial -out "${1}cert.pem" -extensions v3_ca -extfile "${1}cert.cfg"
echo -e "// NOLINT(namespace-envoy)\nconstexpr char TEST_$(echo "$1" | tr "[:lower:]" "[:upper:]")_CERT_HASH[] = \"$(openssl x509 -in "${1}cert.pem" -noout -fingerprint -sha256 | cut -d"=" -f2)\";" > "${1}cert_hash.h"
}
Expand Down Expand Up @@ -108,5 +109,9 @@ generate_x509_cert upstream upstreamca
generate_rsa_key upstreamlocalhost upstreamca
generate_x509_cert upstreamlocalhost upstreamca

# Generate expired_cert.pem as a self-signed, expired cert (will fail on macOS 10.13+ because of negative days value).
generate_rsa_key expired_
generate_x509_cert expired_ ca -365

rm ./*.csr
rm ./*.srl
37 changes: 37 additions & 0 deletions test/config/integration/certs/expired_cert.cfg
Original file line number Diff line number Diff line change
@@ -0,0 +1,37 @@
[req]
distinguished_name = req_distinguished_name
req_extensions = v3_req
x509_extensions = v3_ca

[req_distinguished_name]
countryName = US
countryName_default = US
stateOrProvinceName = California
stateOrProvinceName_default = California
localityName = San Francisco
localityName_default = San Francisco
organizationName = Lyft
organizationName_default = Lyft
organizationalUnitName = Lyft Engineering
organizationalUnitName_default = Lyft Engineering
commonName = Test Server
commonName_default = Test Server
commonName_max = 64

[v3_req]
basicConstraints = CA:FALSE
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
extendedKeyUsage = clientAuth, serverAuth
subjectAltName = @alt_names
subjectKeyIdentifier = hash

[v3_ca]
basicConstraints = critical, CA:FALSE
keyUsage = nonRepudiation, digitalSignature, keyEncipherment
extendedKeyUsage = clientAuth, serverAuth
subjectAltName = @alt_names
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always

[alt_names]
DNS.1 = server1.example.com
24 changes: 24 additions & 0 deletions test/config/integration/certs/expired_cert.pem
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
-----BEGIN CERTIFICATE-----
Comment thread
mattklein123 marked this conversation as resolved.
Outdated
MIIEHDCCAwSgAwIBAgIUGbk2QHZmHwMN0Ok8DcA627rnRUQwDQYJKoZIhvcNAQEL
BQAwdjELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFjAUBgNVBAcM
DVNhbiBGcmFuY2lzY28xDTALBgNVBAoMBEx5ZnQxGTAXBgNVBAsMEEx5ZnQgRW5n
aW5lZXJpbmcxEDAOBgNVBAMMB1Rlc3QgQ0EwHhcNMjIwNTI2MDMxNTQyWhcNMjEw
NTI2MDMxNTQyWjB6MQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2FsaWZvcm5pYTEW
MBQGA1UEBwwNU2FuIEZyYW5jaXNjbzENMAsGA1UECgwETHlmdDEZMBcGA1UECwwQ
THlmdCBFbmdpbmVlcmluZzEUMBIGA1UEAwwLVGVzdCBTZXJ2ZXIwggEiMA0GCSqG
SIb3DQEBAQUAA4IBDwAwggEKAoIBAQDPkJ0So8ELPmf9cFwlc5GuDdHyeZ61ufNY
Wh1ksodPiyJVVcBweP1aPQaUahyWoLl/kJUHBMaMAqww/8+/2EShb20IPwewMCbB
hxCkVl5t4fSh+nmbaH0hhTemDlkL9TSUuRvAmSu+S0pAFAOy4AxhS3/R98SW3Epf
Dop9g/iPJUdvXUQw5N0TOyHp3T5N1/+Qr5yYh+BHb5QVKgUiKBtjwgvjvzF3MgyZ
Fcf49FiHgVbkBrD0jWYyNT4h9sAvz0+l6eewAonNI5l4gF/rF97BIts38OrQ+ODh
uE2IQZW6xAreOKvjb4NPe3/ndQi+O9Fd3i81usIpxDELWo/TkOQHAgMBAAGjgZ0w
gZowDAYDVR0TAQH/BAIwADALBgNVHQ8EBAMCBeAwHQYDVR0lBBYwFAYIKwYBBQUH
AwIGCCsGAQUFBwMBMB4GA1UdEQQXMBWCE3NlcnZlcjEuZXhhbXBsZS5jb20wHQYD
VR0OBBYEFD9jZ/Q0IsoPMwQbWH/Vzf0N3nqRMB8GA1UdIwQYMBaAFOmnTrTMaEk1
Uq9oLs+yKvta8p6pMA0GCSqGSIb3DQEBCwUAA4IBAQAuCAcZch7LEG74BaFKEnka
XnylGMfbXAqQgIms5IPBzDmENSIwKEOnEs0VUJeME7mfIfv3TAFiImwSEYDy/XsZ
Oej8IFzAD03867KLqFd+g28q3RrrJJysUjQUwO6197za5Ygl+maadZOS80IB1Dnw
4wibTobo0cT/CtbUPTM1YAzwmvCWZPnQUMnRgP5Lf0AE6jUwxRM4td1IesI2CE6+
YxZA8t5yaGKd3+wv1QBWlpDBhPy7yGGrreSqbNc2yt1CEJ4mf51tZM5u3M9qOy7q
AOtvwFlHp1/t5RgE9881FV2KCNVG4BE5xvXE4QYbTKCXPR2hbgxco7yeOJpQKVWX
-----END CERTIFICATE-----
3 changes: 3 additions & 0 deletions test/config/integration/certs/expired_cert_hash.h
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
// NOLINT(namespace-envoy)
constexpr char TEST_EXPIRED__CERT_HASH[] = "FC:F7:07:14:C3:0D:B4:BE:0B:BF:23:9B:C2:09:DA:CD:54:66:"
"32:65:07:50:35:E8:D0:14:ED:D6:B1:96:A1:3C";
Comment on lines +1 to +3

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this is unused. Delete?

@daixiang0 daixiang0 May 28, 2022

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Now certs.sh will generate a hash file, not only here, but also in other tests, although some of the hash files are unused. Do we delete them as well?

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

OK I see, that's fine, thanks.

27 changes: 27 additions & 0 deletions test/config/integration/certs/expired_key.pem
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
-----BEGIN RSA PRIVATE KEY-----
MIIEpQIBAAKCAQEAz5CdEqPBCz5n/XBcJXORrg3R8nmetbnzWFodZLKHT4siVVXA
cHj9Wj0GlGoclqC5f5CVBwTGjAKsMP/Pv9hEoW9tCD8HsDAmwYcQpFZebeH0ofp5
m2h9IYU3pg5ZC/U0lLkbwJkrvktKQBQDsuAMYUt/0ffEltxKXw6KfYP4jyVHb11E
MOTdEzsh6d0+Tdf/kK+cmIfgR2+UFSoFIigbY8IL478xdzIMmRXH+PRYh4FW5Aaw
9I1mMjU+IfbAL89PpennsAKJzSOZeIBf6xfewSLbN/Dq0Pjg4bhNiEGVusQK3jir
42+DT3t/53UIvjvRXd4vNbrCKcQxC1qP05DkBwIDAQABAoIBAH9epoSBqDxWF0oW
YPU6bfL42BSLPTEW4pUc91yLkSzmnDLxZB2goRd2y0rXsqNcDXiSKGEeNRhFq5SF
5d47wCGwVp/wza74XU/0qemudlPHjG65XVZYUDD5pqRnuYz080cwMC+Hzqf/W5jm
rz5c7jvmMJGQETriA2FBcwqCqUxs34vKni7DF6US7Q8mFRyBzzzobt2b+5PkBOAj
7cTiVUg2/c3S6vKG/216QlKeXGF2zo1OmBqUNmvRDsK7T6J72TtfpgujrQFVEYW2
gvAbSwyJRH+Pca0XzSK8ILd5BhBRoudiJNN04e8JJzT9IVzu4vLdqunV6eKFpDW5
FBtUMgECgYEA/tbshUqrspF8zrHl0TtBxDDHGVQjzR/5SoRMHsCKig5W63do0FGH
ky+DkXR+0oBwWo89Grikw5dvVs9PrvcRwMj8/GGqImIjWW2uEGQ5ORdPQripz1pR
wpUVjUtI81hCXgG5AO7VuBB97Rp9HvK3yKDind802+5bZbavRvrp4CECgYEA0IKU
bnrdgtxSmuhm0qbJFQlJcy/zrP/YUCjfcORj6CUDM4pT4RZGMMPMrRc4eIiZaeVH
pIlWk23COHkjg07E0RII3jKHgWilLZb3iF4xICOclxDl7ztQ1lOAqP5SiFqDYtxd
XlQgDIHI04nFTeaBIdVFHhkNIenUnE44B5VT3ycCgYEA1BD0SEOIOBQb4UFnNsNy
ChpxRKGhHUyzPhBz689cOmCOcmou/dQq1w/eE8f21aNuW94BAmCPM/ir/XiNHdOa
oWxgIoH/e5dhRUUhaaCNgfXkzmgvX08Q5LT9d1QkA+T5bZNPafhWP1LyB8JYRs3C
pKFFlAyvxylGQ5FPsOiSgSECgYEAlHiGzOx8EpRj1Z4qqVDN2kbUoErCzqsXEm0o
PbDDWygP0YFsHNjJfivN8GqacWmDJB55FzYcCbqcE65elT9fcifPXLjKOGGVTJM1
C0tW27W/6OnFcMXh19t5v9voVONurtSPP33TnFRF9ish7Uh3Juo/3yCjc0SXef1Q
dEXmhP0CgYEA/m8D5/Wyw0BKSc+q2SDMnB10TKfCEWtwbKHOdCHSgZbNYUTM53Op
CGpxI2vvuNiOxFW8dMlhu3E0v1tqGnJ3Ms6CmczJREy4vvTLYPjF8M/2iXeuKYxM
j4hFx66+pRoUZ7tf0kMkp7lZX3nAg3KgXpu6w1xHfuQGa6FPuknr39M=
-----END RSA PRIVATE KEY-----
5 changes: 5 additions & 0 deletions test/config/integration/certs/servercert_info.h
Original file line number Diff line number Diff line change
@@ -0,0 +1,5 @@
// NOLINT(namespace-envoy)
constexpr char TEST_SERVER_CERT_HASH[] = "DC:E2:2B:65:90:43:9A:36:1C:8E:6D:CA:42:8A:8C:37:C7:A1:77:"
"00:5B:C1:3E:33:8A:B9:2D:04:2C:B1:3F:0A";
constexpr char TEST_SERVER_CERT_NOT_BEFORE[] = "Apr 7 16:46:35 2022 GMT";
constexpr char TEST_SERVER_CERT_NOT_AFTER[] = "Apr 6 16:46:35 2024 GMT";
Comment on lines +1 to +5

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you add comments on where this came from and how to regenerate it if needed?

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All are generated by certs.h, refer to https://github.com/envoyproxy/envoy/blob/main/test/config/integration/certs/README.md, or I can update that script and add comments during generating.

5 changes: 5 additions & 0 deletions test/integration/BUILD
Original file line number Diff line number Diff line change
Expand Up @@ -1064,6 +1064,9 @@ envoy_cc_test(
envoy_cc_test(
name = "stats_integration_test",
srcs = ["stats_integration_test.cc"],
data = [
"//test/config/integration/certs",
],
# The symbol table cluster memory tests take a while to run specially under tsan.
# Shard it to avoid test timeout.
shard_count = 2,
Expand All @@ -1073,10 +1076,12 @@ envoy_cc_test(
"//source/extensions/filters/http/router:config",
"//source/extensions/filters/network/http_connection_manager:config",
"//test/common/stats:stat_test_utility_lib",
"//test/config/integration/certs:certs_info",
"//test/test_common:network_utility_lib",
"//test/test_common:utility_lib",
"@envoy_api//envoy/config/bootstrap/v3:pkg_cc_proto",
"@envoy_api//envoy/config/core/v3:pkg_cc_proto",
"@envoy_api//envoy/extensions/transport_sockets/tls/v3:pkg_cc_proto",
],
)

Expand Down
85 changes: 85 additions & 0 deletions test/integration/stats_integration_test.cc
Original file line number Diff line number Diff line change
Expand Up @@ -2,13 +2,16 @@

#include "envoy/config/bootstrap/v3/bootstrap.pb.h"
#include "envoy/config/core/v3/address.pb.h"
#include "envoy/extensions/transport_sockets/tls/v3/cert.pb.h"
#include "envoy/stats/scope.h"
#include "envoy/stats/stats.h"

#include "source/common/config/well_known_names.h"
#include "source/common/memory/stats.h"

#include "test/common/stats/stat_test_utility.h"
#include "test/config/integration/certs/clientcert_hash.h"
#include "test/config/integration/certs/servercert_info.h"
#include "test/config/utility.h"
#include "test/integration/integration.h"
#include "test/test_common/network_utility.h"
Expand Down Expand Up @@ -151,6 +154,88 @@ TEST_P(StatsIntegrationTest, WithTagSpecifierWithFixedValue) {
EXPECT_EQ(live->tags()[0].value_, "xxx");
}

TEST_P(StatsIntegrationTest, WithoutCert) {
initialize();

EXPECT_EQ(test_server_->gauge("server.days_until_first_cert_expiring")->value(),
std::numeric_limits<uint32_t>::max());
}

TEST_P(StatsIntegrationTest, WithExpiringCert) {
config_helper_.addConfigModifier([](envoy::config::bootstrap::v3::Bootstrap& bootstrap) {
auto* transport_socket = bootstrap.mutable_static_resources()
->mutable_listeners(0)
->mutable_filter_chains(0)
->mutable_transport_socket();
envoy::extensions::transport_sockets::tls::v3::DownstreamTlsContext tls_context;
auto* common_tls_context = tls_context.mutable_common_tls_context();
common_tls_context->add_alpn_protocols(Http::Utility::AlpnNames::get().Http11);

common_tls_context->mutable_validation_context_sds_secret_config()->set_name(
"validation_context");
common_tls_context->add_tls_certificate_sds_secret_configs()->set_name("server_cert");
transport_socket->set_name("envoy.transport_sockets.tls");
transport_socket->mutable_typed_config()->PackFrom(tls_context);

auto* secret = bootstrap.mutable_static_resources()->add_secrets();
secret->set_name("validation_context");
auto* validation_context = secret->mutable_validation_context();
validation_context->mutable_trusted_ca()->set_filename(
TestEnvironment::runfilesPath("test/config/integration/certs/cacert.pem"));
validation_context->add_verify_certificate_hash(TEST_CLIENT_CERT_HASH);

secret = bootstrap.mutable_static_resources()->add_secrets();
secret->set_name("server_cert");
auto* tls_certificate = secret->mutable_tls_certificate();
tls_certificate->mutable_certificate_chain()->set_filename(
TestEnvironment::runfilesPath("test/config/integration/certs/servercert.pem"));
tls_certificate->mutable_private_key()->set_filename(
TestEnvironment::runfilesPath("test/config/integration/certs/serverkey.pem"));
});

initialize();
auto cert_expiry = TestUtility::parseTime(TEST_SERVER_CERT_NOT_AFTER, "%b %d %H:%M:%S %Y GMT");
int64_t days_until_expiry = absl::ToInt64Hours(cert_expiry - absl::Now()) / 24;
EXPECT_EQ(test_server_->gauge("server.days_until_first_cert_expiring")->value(),
days_until_expiry);
}

TEST_P(StatsIntegrationTest, WithExpiredCert) {
config_helper_.addConfigModifier([](envoy::config::bootstrap::v3::Bootstrap& bootstrap) {
auto* transport_socket = bootstrap.mutable_static_resources()
->mutable_listeners(0)
->mutable_filter_chains(0)
->mutable_transport_socket();
envoy::extensions::transport_sockets::tls::v3::DownstreamTlsContext tls_context;
auto* common_tls_context = tls_context.mutable_common_tls_context();
common_tls_context->add_alpn_protocols(Http::Utility::AlpnNames::get().Http11);

common_tls_context->mutable_validation_context_sds_secret_config()->set_name(
"validation_context");
common_tls_context->add_tls_certificate_sds_secret_configs()->set_name("server_cert");
transport_socket->set_name("envoy.transport_sockets.tls");
transport_socket->mutable_typed_config()->PackFrom(tls_context);

auto* secret = bootstrap.mutable_static_resources()->add_secrets();
secret->set_name("validation_context");
auto* validation_context = secret->mutable_validation_context();
validation_context->mutable_trusted_ca()->set_filename(
TestEnvironment::runfilesPath("test/config/integration/certs/cacert.pem"));
validation_context->add_verify_certificate_hash(TEST_CLIENT_CERT_HASH);

secret = bootstrap.mutable_static_resources()->add_secrets();
secret->set_name("server_cert");
auto* tls_certificate = secret->mutable_tls_certificate();
tls_certificate->mutable_certificate_chain()->set_filename(
TestEnvironment::runfilesPath("test/config/integration/certs/expired_cert.pem"));
tls_certificate->mutable_private_key()->set_filename(
TestEnvironment::runfilesPath("test/config/integration/certs/expired_key.pem"));
});

initialize();
EXPECT_EQ(test_server_->gauge("server.days_until_first_cert_expiring")->value(), 0);
}

// TODO(cmluciano) Refactor once https://github.com/envoyproxy/envoy/issues/5624 is solved
// TODO(cmluciano) Add options to measure multiple workers & without stats
// This class itself does not add additional tests. It is a helper for use in other tests measuring
Expand Down