Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 5 additions & 3 deletions pkgs/ok_http/example/integration_test/certificate_test.dart
Original file line number Diff line number Diff line change
Expand Up @@ -106,8 +106,10 @@ void main() async {
.having((e) => e.message, 'message', contains('Handshake'))));
expect(
() async => await serverException.future,
throwsA(isA<io.HandshakeException>()
.having((e) => e.message, 'message', contains('Handshake'))));
throwsA(anyOf(
isA<io.HandshakeException>()
.having((e) => e.message, 'message', contains('Handshake')),
isA<io.SocketException>())));
});

test('ignore unknown server cert', () async {
Expand Down Expand Up @@ -189,7 +191,7 @@ void main() async {
expect(() => OkHttpClient(configuration: config), throwsArgumentError);
});

test('private key without cert chain', () async {
test('cert chain without private key', () async {
final certBytes =
await loadCertificateBytes('test_certs/test-combined.p12');

Expand Down
10 changes: 9 additions & 1 deletion pkgs/ok_http/example/test_certs/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,12 @@

The certificates and private keys used for `package:ok_http` TLS testing.

TODO: generate these files using a script.
- `server_chain.p12` and `server_key.p12`: the server certificate chain and
private key, with password `dartdart`. Copied from the Dart SDK's
[`tests/standalone/io/certificates`](https://github.com/dart-lang/sdk/tree/main/tests/standalone/io/certificates).
- `test-combined.p12`: a self-signed client certificate and its private key,
with password `1234`. Generated by running `generate_test_combined.sh`.

These files must be readable by the PKCS12 `KeyStore` on every supported
Android version. Older versions (e.g. API level 24) cannot read PKCS #12 files
protected using the default algorithms of OpenSSL 3.
36 changes: 36 additions & 0 deletions pkgs/ok_http/example/test_certs/generate_test_combined.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
#!/bin/bash
# Copyright (c) 2026, the Dart project authors. Please see the AUTHORS file
# for details. All rights reserved. Use of this source code is governed by a
# BSD-style license that can be found in the LICENSE file.

# Generates `test-combined.p12`: a PKCS #12 archive, with password "1234",
# containing a self-signed certificate and its private key.
#
# The archive is protected using legacy algorithms (a SHA-1 MAC and 3DES
# encryption) because the PKCS12 `KeyStore` in older versions of Android
# (e.g. API level 24) cannot read archives protected using the OpenSSL 3
# defaults (a SHA-256 MAC and PBES2/AES-256 encryption).

set -euo pipefail

cd "$(dirname "$0")"

tmp_dir="$(mktemp -d)"
trap 'rm -rf "$tmp_dir"' EXIT

# `certificate_test.dart` checks that the certificate issuer contains
# "Internet Widgits Pty Ltd".
openssl req -x509 -newkey rsa:2048 -nodes -sha256 \
-days 36500 \
-subj '/C=US/ST=CA/O=Internet Widgits Pty Ltd' \
-keyout "$tmp_dir/key.pem" \
-out "$tmp_dir/cert.pem"

openssl pkcs12 -export \
-inkey "$tmp_dir/key.pem" \
-in "$tmp_dir/cert.pem" \
-keypbe PBE-SHA1-3DES \
-certpbe PBE-SHA1-3DES \
-macalg sha1 \
-passout pass:1234 \
-out test-combined.p12
Binary file modified pkgs/ok_http/example/test_certs/test-combined.p12
Binary file not shown.
Loading