@@ -226,6 +226,8 @@ ecce_library(eccetdat
226226# --- src/dsm -> 5 separate libraries, matching the old per-subdir mapping ---
227227ecce_library(eccexml src/dsm/chemistry src/dsm/xml)
228228ecce_library(eccecipc src/dsm/cipc)
229+ find_package(OpenSSL REQUIRED)
230+ target_link_libraries(eccecipc PUBLIC OpenSSL::SSL OpenSSL::Crypto)
229231ecce_library(eccedav src/dsm/dav)
230232ecce_library(eccedsi src/dsm/edsiimpl)
231233ecce_library(eccefaces src/dsm/faces)
@@ -1350,9 +1352,12 @@ set(CPACK_DEBIAN_PACKAGE_SHLIBDEPS ON)
13501352# perl: the whole job pipeline (ai.<code>, *.expt, gensub,
13511353# eccejobmonitor, processmachine) is Perl, and Getopt::Std and
13521354# Sys::Hostname are in perl-modules, which perl-base alone lacks.
1355+ # openssl: ecce-remote-setup --tls makes and checks certificates with the
1356+ # command line tool (#236); the libraries come from shlibdeps. Apache's
1357+ # mod_ssl is in the apache2 package on Debian but its own package on RPM.
13531358# xterm: editing an input file with the default editor (vi) opens it in
13541359# an xterm (UserEditor.C).
1355- set (CPACK_DEBIAN_PACKAGE_DEPENDS "apache2, apache2-utils, python3-wxgtk4.0, mosquitto, libaprutil1, perl, xterm" )
1360+ set (CPACK_DEBIAN_PACKAGE_DEPENDS "apache2, apache2-utils, python3-wxgtk4.0, mosquitto, libaprutil1, perl, xterm, openssl " )
13561361# NWChem is a real Debian package (confirmed working: /usr/bin/nwchem,
13571362# symlinked to nwchem.openmpi by the package itself) and the auto-register-
13581363# this-machine flow (RunMgmt::registerLocalMachine()) defaults new machine
@@ -1407,7 +1412,7 @@ if(RPMBUILD_EXECUTABLE)
14071412 set (CPACK_RPM_PACKAGE_LICENSE "ECL-2.0" )
14081413 set (CPACK_RPM_PACKAGE_GROUP "Applications/Engineering" )
14091414 set (CPACK_RPM_PACKAGE_URL "https://github.com/FriendsofECCE/ECCE" )
1410- set (CPACK_RPM_PACKAGE_REQUIRES "httpd, httpd-tools, python3-wxpython4, perl, xterm, mosquitto, apr-util${_coin_rpm} " )
1415+ set (CPACK_RPM_PACKAGE_REQUIRES "httpd, httpd-tools, mod_ssl, openssl, python3-wxpython4, perl, xterm, mosquitto, apr-util${_coin_rpm} " )
14111416 set (CPACK_RPM_PACKAGE_SUGGESTS "nwchem, openssh-clients, firefox" )
14121417 set (CPACK_RPM_FILE_NAME RPM-DEFAULT)
14131418 # /opt/ecce is ours, but /opt itself is owned by filesystem(5). Without
@@ -1551,7 +1556,7 @@ if(ECCE_SPLIT_PACKAGES)
15511556 # -remote client only needs the library, and the package's own system
15521557 # service is of no use to it.
15531558 set (CPACK_DEBIAN_CLIENT_PACKAGE_DEPENDS
1554- "python3-wxgtk4.0, perl, xterm, libmosquitto1, curl" )
1559+ "python3-wxgtk4.0, perl, xterm, libmosquitto1, curl, openssl " )
15551560 # A client on the SAME machine as a server benefits from it (the
15561561 # default "everything on one box" case this project still ships), but
15571562 # a client of an already-central server (#167/#138 -- the teaching
@@ -1574,7 +1579,7 @@ if(ECCE_SPLIT_PACKAGES)
15741579 # (launchjob, eccejobmaster, eccejobstore) ship in ecce-client, and a server
15751580 # needs them, so the server brings the client -- GUI libraries included,
15761581 # unused on a headless box. Accepted rather than a third package.
1577- set (CPACK_DEBIAN_SERVER_PACKAGE_DEPENDS "apache2, apache2-utils, mosquitto, libaprutil1, ecce-client (= ${_ecce_deb_version} )" )
1582+ set (CPACK_DEBIAN_SERVER_PACKAGE_DEPENDS "apache2, apache2-utils, mosquitto, libaprutil1, openssl, ecce-client (= ${_ecce_deb_version} )" )
15781583 set (CPACK_DEBIAN_SERVER_PACKAGE_BREAKS "ecce (<< ${ECCE_MONOLITHIC_BREAK_VERSION} )" )
15791584 set (CPACK_DEBIAN_SERVER_PACKAGE_REPLACES "ecce (<< ${ECCE_MONOLITHIC_BREAK_VERSION} )" )
15801585
@@ -1587,7 +1592,7 @@ if(ECCE_SPLIT_PACKAGES)
15871592 set (CPACK_RPM_CLIENT_FILE_NAME RPM-DEFAULT)
15881593 # mosquitto provides both the library and the broker on RPM distros.
15891594 set (CPACK_RPM_CLIENT_PACKAGE_REQUIRES
1590- "python3-wxpython4, perl, xterm, mosquitto, curl${_coin_rpm} " )
1595+ "python3-wxpython4, perl, xterm, mosquitto, curl, openssl ${_coin_rpm} " )
15911596 set (CPACK_RPM_CLIENT_PACKAGE_SUGGESTS
15921597 "ecce-server, nwchem, openssh-clients, firefox" )
15931598 # RPM has no direct Breaks/Replaces pair; Obsoletes+Provides is the
@@ -1600,7 +1605,7 @@ if(ECCE_SPLIT_PACKAGES)
16001605 set (CPACK_RPM_CLIENT_PACKAGE_CONFLICTS "ecce < ${ECCE_MONOLITHIC_BREAK_VERSION} " )
16011606 set (CPACK_RPM_SERVER_PACKAGE_NAME "ecce-server" )
16021607 set (CPACK_RPM_SERVER_FILE_NAME RPM-DEFAULT)
1603- set (CPACK_RPM_SERVER_PACKAGE_REQUIRES "httpd, httpd-tools, mosquitto, apr-util, ecce-client = ${_ecce_deb_version} " )
1608+ set (CPACK_RPM_SERVER_PACKAGE_REQUIRES "httpd, httpd-tools, mod_ssl, openssl, mosquitto, apr-util, ecce-client = ${_ecce_deb_version} " )
16041609 set (CPACK_RPM_SERVER_PACKAGE_OBSOLETES "ecce < ${ECCE_MONOLITHIC_BREAK_VERSION} " )
16051610 set (CPACK_RPM_SERVER_PACKAGE_CONFLICTS "ecce < ${ECCE_MONOLITHIC_BREAK_VERSION} " )
16061611 set (CPACK_RPM_EXCLUDE_FROM_AUTO_FILELIST_ADDITION "/opt" )
@@ -1682,6 +1687,30 @@ if(TARGET ecce_users_auth)
16821687 set_tests_properties (mqtt-auth-plugin PROPERTIES TIMEOUT 120 SKIP_RETURN_CODE 77)
16831688endif ()
16841689set_tests_properties (mqtt mqtt-auth PROPERTIES TIMEOUT 120 SKIP_RETURN_CODE 77)
1690+
1691+ # tests/tls -- https data-server client (#236): pinned certificate, CA mode
1692+ # with host-name check, certificate rejection, no fallback to plain http.
1693+ # Needs python3 and the openssl command line; SKIPs (77) without them.
1694+ add_executable (tls_client_test tests/tls/tls_client_test.C )
1695+ target_include_directories (tls_client_test PRIVATE ${XercesC_INCLUDE_DIRS} )
1696+ target_link_libraries (tls_client_test PRIVATE
1697+ eccedsi eccedav eccecipc eccefaces eccexml eccetdat ecceutil ${XercesC_LIBRARIES} )
1698+ add_test (NAME tls_client
1699+ COMMAND ${PYTHON3_EXECUTABLE} ${CMAKE_SOURCE_DIR } /tests/tls/run_tests.py
1700+ $<TARGET_FILE :tls_client_test > ${CMAKE_BINARY_DIR } /tls-test )
1701+ set_tests_properties (tls_client PROPERTIES TIMEOUT 120 SKIP_RETURN_CODE 77)
1702+
1703+ # The central server over TLS (#236): the real data server and broker scripts
1704+ # on loopback with a fresh certificate, then the clients with and without
1705+ # the right pin.
1706+ add_executable (tls_broker_test tests/tls/tls_broker_test.C )
1707+ target_include_directories (tls_broker_test PRIVATE ${XercesC_INCLUDE_DIRS} )
1708+ target_link_libraries (tls_broker_test PRIVATE ecceutil ${XercesC_LIBRARIES} )
1709+ add_test (NAME tls_server
1710+ COMMAND ${PYTHON3_EXECUTABLE} ${CMAKE_SOURCE_DIR } /tests/tls/server_tls.py
1711+ $<TARGET_FILE :tls_client_test > $<TARGET_FILE :tls_broker_test >
1712+ ${CMAKE_BINARY_DIR } ${CMAKE_BINARY_DIR } /tls-server-test )
1713+ set_tests_properties (tls_server PROPERTIES TIMEOUT 300 SKIP_RETURN_CODE 77)
16851714if (PYTHON3_EXECUTABLE)
16861715 add_test (NAME parsers
16871716 COMMAND ${PYTHON3_EXECUTABLE}
0 commit comments