srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/internal/ca/install_test.go
blob: 0f01f1f3a7cd1440f312e161ddfe06ef0d315f13 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
package ca

import (
	"strings"
	"testing"
)

// withCommands temporarily replaces commandExists with a fake that only
// reports the given names as present, restoring the real one after.
func withCommands(t *testing.T, present ...string) {
	t.Helper()
	set := make(map[string]bool, len(present))
	for _, p := range present {
		set[p] = true
	}
	orig := commandExists
	commandExists = func(name string) bool { return set[name] }
	t.Cleanup(func() { commandExists = orig })
}

func TestLinuxInstructionsPrefersTrust(t *testing.T) {
	withCommands(t, "trust", "update-ca-trust", "update-ca-certificates")
	got := linuxInstructions("/tmp/ca.pem")
	if !strings.Contains(got, "sudo trust anchor --store /tmp/ca.pem") {
		t.Errorf("expected trust anchor command when trust is available, got:\n%s", got)
	}
}

func TestLinuxInstructionsFallsBackToUpdateCaTrust(t *testing.T) {
	withCommands(t, "update-ca-trust")
	got := linuxInstructions("/tmp/ca.pem")
	if !strings.Contains(got, "update-ca-trust") || strings.Contains(got, "trust anchor") {
		t.Errorf("expected update-ca-trust path, got:\n%s", got)
	}
}

func TestLinuxInstructionsFallsBackToUpdateCaCertificates(t *testing.T) {
	withCommands(t, "update-ca-certificates")
	got := linuxInstructions("/tmp/ca.pem")
	if !strings.Contains(got, "update-ca-certificates") {
		t.Errorf("expected update-ca-certificates path, got:\n%s", got)
	}
}

func TestLinuxInstructionsNoneFound(t *testing.T) {
	withCommands(t)
	got := linuxInstructions("/tmp/ca.pem")
	if !strings.Contains(got, "No known trust-store tool") {
		t.Errorf("expected a no-tool-found message, got:\n%s", got)
	}
}

func TestLinuxInstructionsCertutilPresence(t *testing.T) {
	withCommands(t, "certutil")
	withCert := linuxInstructions("/tmp/ca.pem")
	if !strings.Contains(withCert, "certutil -d sql:") {
		t.Errorf("expected certutil NSS instructions when certutil is present, got:\n%s", withCert)
	}

	withCommands(t)
	withoutCert := linuxInstructions("/tmp/ca.pem")
	if !strings.Contains(withoutCert, "Import manually") {
		t.Errorf("expected manual-import fallback when certutil is absent, got:\n%s", withoutCert)
	}
}

func TestInstallInstructionsDispatchesByOS(t *testing.T) {
	withCommands(t)
	tests := []struct {
		goos string
		want string
	}{
		{"linux", "trust store"},
		{"darwin", "security add-trusted-cert"},
		{"windows", "certutil -addstore"},
		{"plan9", "No install steps known"},
	}
	for _, tt := range tests {
		got := InstallInstructions(tt.goos, "/tmp/ca.pem")
		if !strings.Contains(got, tt.want) {
			t.Errorf("InstallInstructions(%q, ...) = %q, want it to contain %q", tt.goos, got, tt.want)
		}
	}
}