curl/tests/data/test986
Patrick Monnerat 364f174724
ftp,imap,pop3: do not ignore --ssl-reqd
In imap and pop3, check if TLS is required even when capabilities
request has failed.

In ftp, ignore preauthentication (230 status of server greeting) if TLS
is required.

Bug: https://curl.se/docs/CVE-2021-22946.html

CVE-2021-22946
2021-09-13 16:51:31 +02:00

54 lines
726 B
Plaintext

<testcase>
<info>
<keywords>
FTP
STARTTLS
</keywords>
</info>
#
# Server-side
<reply>
<servercmd>
REPLY welcome 230 Welcome
REPLY AUTH 500 unknown command
</servercmd>
</reply>
# Client-side
<client>
<features>
SSL
</features>
<server>
ftp
</server>
<name>
FTP require STARTTLS while preauthenticated
</name>
<file name="log/test%TESTNUMBER.txt">
data
to
see
that FTPS
works
so does it?
</file>
<command>
--ssl-reqd --ftp-ssl-control ftp://%HOSTIP:%FTPPORT/%TESTNUMBER -T log/test%TESTNUMBER.txt -u user:secret
</command>
</client>
# Verify data after the test has been "shot"
<verify>
# 64 is CURLE_USE_SSL_FAILED
<errorcode>
64
</errorcode>
<protocol>
AUTH SSL
AUTH TLS
</protocol>
</verify>
</testcase>