Adjust ssl_test_new for SHA1 security level
[openssl.git] / test / ssl-tests / 18-dtls-renegotiate.cnf.in
index b8ec735eb2f2683134ac7817b355249ef56df04e..400ec67d31168aeeac528e85f02816f9699af857 100644 (file)
@@ -15,20 +15,26 @@ use warnings;
 package ssltests;
 use OpenSSL::Test::Utils;
 
+our $fips_mode;
+
 our @tests = ();
 
 foreach my $sctp ("No", "Yes")
 {
     next if disabled("sctp") && $sctp eq "Yes";
+    next if disabled("dtls1_2") && $fips_mode;
 
     my $suffix = ($sctp eq "No") ? "" : "-sctp";
     our @tests_basic = (
         {
             name => "renegotiate-client-no-resume".$suffix,
             server => {
+                "CipherString" => 'DEFAULT:@SECLEVEL=0',
                 "Options" => "NoResumptionOnRenegotiation"
             },
-            client => {},
+            client => {
+                "CipherString" => 'DEFAULT:@SECLEVEL=0'
+            },
             test => {
                 "Method" => "DTLS",
                 "UseSCTP" => $sctp,
@@ -39,8 +45,12 @@ foreach my $sctp ("No", "Yes")
         },
         {
             name => "renegotiate-client-resume".$suffix,
-            server => {},
-            client => {},
+            server => {
+                "CipherString" => 'DEFAULT:@SECLEVEL=0'
+            },
+            client => {
+                "CipherString" => 'DEFAULT:@SECLEVEL=0'
+            },
             test => {
                 "Method" => "DTLS",
                 "UseSCTP" => $sctp,
@@ -60,8 +70,12 @@ foreach my $sctp ("No", "Yes")
         # and if so, what to?
         {
             name => "renegotiate-server-resume".$suffix,
-            server => {},
-            client => {},
+            server => {
+                "CipherString" => 'DEFAULT:@SECLEVEL=0'
+            },
+            client => {
+                "CipherString" => 'DEFAULT:@SECLEVEL=0'
+            },
             test => {
                 "Method" => "DTLS",
                 "UseSCTP" => $sctp,
@@ -75,10 +89,12 @@ foreach my $sctp ("No", "Yes")
             server => {
                 "VerifyCAFile" => test_pem("root-cert.pem"),
                 "VerifyMode" => "Require",
+                "CipherString" => 'DEFAULT:@SECLEVEL=0'
             },
             client => {
                 "Certificate" => test_pem("ee-client-chain.pem"),
                 "PrivateKey"  => test_pem("ee-key.pem"),
+                "CipherString" => 'DEFAULT:@SECLEVEL=0'
             },
             test => {
                 "Method" => "DTLS",
@@ -93,10 +109,12 @@ foreach my $sctp ("No", "Yes")
             server => {
                 "VerifyCAFile" => test_pem("root-cert.pem"),
                 "VerifyMode" => "Once",
+                "CipherString" => 'DEFAULT:@SECLEVEL=0'
             },
             client => {
                 "Certificate" => test_pem("ee-client-chain.pem"),
                 "PrivateKey"  => test_pem("ee-key.pem"),
+                "CipherString" => 'DEFAULT:@SECLEVEL=0'
             },
             test => {
                 "Method" => "DTLS",