I want to ensure that client libraries (currently in Python, Ruby, PHP, Java, and .NET) are configured correctly and failing appropriately when SSL certificates are invalid. Shmatikov's paper, The Most Dangerous Code in the World: Validating SSL Certificates in Non-Browser Software, reveals how confusing SSL validation is so I want to thoroughly test the possible failures.

Based on research a certificate is invalid if:

  • It is used before its activation date
  • It is used after its expiry date
  • It has been revoked
  • Certificate hostnames don't match the site hostname
  • Certificate chain does not contain a trusted certificate authority

Ideally, I think I would have one test case for each of the invalid cases. To that end I am currently testing an HTTP site accessed over HTTPS, which leads to a failure that I can verify in a test like so:

self.assertRaises(SSLHandshakeError, lambda: api.call_to_unmatched_hostname())

This is incomplete (only covering one case) and potentially wrong, so...

How can you test that non-browser software properly validates SSL certificates?

Edit
Report