Mercurial > hg > orthanc-tests
annotate Tests/CheckDicomTls.py @ 656:7bfc8992ab8f Orthanc-1.12.4
updated CITATION.cff
author | Sebastien Jodogne <s.jodogne@gmail.com> |
---|---|
date | Wed, 05 Jun 2024 17:53:34 +0200 |
parents | 5d7b6e43ab7d |
children | 31a7e52b3da6 |
rev | line source |
---|---|
610
ec657d1a62a6
fix compatibility with python3
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
588
diff
changeset
|
1 #!/usr/bin/python3 |
375 | 2 |
3 # Orthanc - A Lightweight, RESTful DICOM Store | |
4 # Copyright (C) 2012-2016 Sebastien Jodogne, Medical Physics | |
5 # Department, University Hospital of Liege, Belgium | |
649
5d7b6e43ab7d
updated copyright, as Orthanc Team now replaces Osimis
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
640
diff
changeset
|
6 # Copyright (C) 2017-2023 Osimis S.A., Belgium |
5d7b6e43ab7d
updated copyright, as Orthanc Team now replaces Osimis
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
640
diff
changeset
|
7 # Copyright (C) 2024-2024 Orthanc Team SRL, Belgium |
640
9f8276ac1cdd
update year to 2024
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
610
diff
changeset
|
8 # Copyright (C) 2021-2024 Sebastien Jodogne, ICTEAM UCLouvain, Belgium |
375 | 9 # |
10 # This program is free software: you can redistribute it and/or | |
11 # modify it under the terms of the GNU General Public License as | |
12 # published by the Free Software Foundation, either version 3 of the | |
13 # License, or (at your option) any later version. | |
14 # | |
15 # This program is distributed in the hope that it will be useful, but | |
16 # WITHOUT ANY WARRANTY; without even the implied warranty of | |
17 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU | |
18 # General Public License for more details. | |
19 # | |
20 # You should have received a copy of the GNU General Public License | |
21 # along with this program. If not, see <http://www.gnu.org/licenses/>. | |
22 | |
23 | |
24 | |
25 import argparse | |
26 import os | |
27 import pprint | |
28 import re | |
29 import sys | |
30 import subprocess | |
31 import unittest | |
32 | |
33 from Toolbox import * | |
34 | |
35 | |
36 ## | |
37 ## Parse the command-line arguments | |
38 ## | |
39 | |
40 parser = argparse.ArgumentParser(description = 'Run the integration tests for DICOM TLS in Orthanc.') | |
41 | |
42 parser.add_argument('--server', | |
43 default = 'localhost', | |
44 help = 'Address of the Orthanc server to test') | |
45 parser.add_argument('--aet', | |
46 default = 'ORTHANC', | |
47 help = 'AET of the Orthanc instance to test') | |
48 parser.add_argument('--dicom', | |
49 type = int, | |
50 default = 4242, | |
51 help = 'DICOM port of the Orthanc instance to test') | |
52 parser.add_argument('--rest', | |
53 type = int, | |
54 default = 8042, | |
55 help = 'Port to the REST API') | |
56 parser.add_argument('--username', | |
57 default = 'alice', | |
58 help = 'Username to the REST API') | |
59 parser.add_argument('--password', | |
60 default = 'orthanctest', | |
61 help = 'Password to the REST API') | |
62 parser.add_argument('--force', help = 'Do not warn the user', | |
63 action = 'store_true') | |
64 parser.add_argument('--config', help = 'Create the configuration files for this test in the current folder', | |
65 action = 'store_true') | |
66 parser.add_argument('options', metavar = 'N', nargs = '*', | |
67 help='Arguments to Python unittest') | |
68 | |
69 args = parser.parse_args() | |
70 | |
71 | |
72 ## | |
73 ## Configure the testing context | |
74 ## | |
75 | |
76 | |
77 if args.config: | |
78 def CreateCertificate(name): | |
79 subprocess.check_call([ 'openssl', 'req', '-x509', '-nodes', '-days', '365', '-newkey', 'rsa:2048', | |
80 '-keyout', '%s.key' % name, | |
81 '-out', '%s.crt' % name, | |
82 '-subj', '/C=BE/CN=localhost' ]) | |
83 | |
84 print('Writing configuration to folder: %s' % args.config) | |
85 CreateCertificate('dicom-tls-a') | |
86 CreateCertificate('dicom-tls-b') | |
87 CreateCertificate('dicom-tls-c') # Not trusted by Orthanc | |
88 | |
89 with open('dicom-tls-trusted.crt', 'w') as f: | |
90 for i in [ 'dicom-tls-a.crt', 'dicom-tls-b.crt' ]: | |
91 with open(i, 'r') as g: | |
92 f.write(g.read()) | |
93 | |
94 with open('dicom-tls.json', 'w') as f: | |
95 f.write(json.dumps({ | |
96 'DicomTlsEnabled' : True, | |
97 'DicomTlsCertificate' : 'dicom-tls-a.crt', | |
98 'DicomTlsPrivateKey' : 'dicom-tls-a.key', | |
99 'DicomTlsTrustedCertificates' : 'dicom-tls-trusted.crt', | |
100 'ExecuteLuaEnabled' : True, | |
101 'RemoteAccessAllowed' : True, | |
102 'RegisteredUsers' : { | |
103 'alice' : 'orthanctest' | |
104 }, | |
400
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
105 'DicomTlsRemoteCertificateRequired' : False, # New in Orthanc 1.9.3 |
375 | 106 })) |
107 | |
108 exit(0) | |
109 | |
110 | |
111 if not args.force: | |
112 print(""" | |
113 WARNING: This test will remove all the content of your | |
114 Orthanc instance running on %s! | |
115 | |
116 Are you sure ["yes" to go on]?""" % args.server) | |
117 | |
118 if sys.stdin.readline().strip() != 'yes': | |
119 print('Aborting...') | |
120 exit(0) | |
121 | |
122 | |
123 ORTHANC = DefineOrthanc(server = args.server, | |
124 username = args.username, | |
125 password = args.password, | |
126 restPort = args.rest, | |
127 aet = args.aet, | |
128 dicomPort = args.dicom) | |
129 | |
130 | |
131 ## | |
132 ## The tests | |
133 ## | |
134 | |
135 | |
136 FNULL = open(os.devnull, 'w') # Emulates "subprocess.DEVNULL" on Python 2.7 | |
137 | |
138 | |
139 class Orthanc(unittest.TestCase): | |
140 def setUp(self): | |
141 if (sys.version_info >= (3, 0)): | |
142 # Remove annoying warnings about unclosed socket in Python 3 | |
143 import warnings | |
144 warnings.simplefilter('ignore', ResourceWarning) | |
145 | |
146 DropOrthanc(ORTHANC) | |
147 | |
148 | |
149 def test_incoming(self): | |
150 # No certificate | |
151 self.assertRaises(Exception, lambda: subprocess.check_call([ | |
152 FindExecutable('echoscu'), | |
153 ORTHANC['Server'], | |
154 str(ORTHANC['DicomPort']), | |
155 '-aec', 'ORTHANC', | |
156 ], stderr = FNULL)) | |
157 | |
158 subprocess.check_call([ | |
159 FindExecutable('echoscu'), | |
160 ORTHANC['Server'], | |
161 str(ORTHANC['DicomPort']), | |
162 '-aec', 'ORTHANC', | |
163 '+tls', 'dicom-tls-b.key', 'dicom-tls-b.crt', | |
164 '+cf', 'dicom-tls-a.crt', | |
165 ], stderr = FNULL) | |
166 | |
167 self.assertRaises(Exception, lambda: subprocess.check_call([ | |
168 FindExecutable('echoscu'), | |
169 ORTHANC['Server'], | |
170 str(ORTHANC['DicomPort']), | |
171 '-aec', 'ORTHANC', | |
172 '+tls', 'dicom-tls-c.key', 'dicom-tls-c.crt', # Not trusted by Orthanc | |
173 '+cf', 'dicom-tls-a.crt', | |
174 ], stderr = FNULL)) | |
175 | |
176 self.assertRaises(Exception, lambda: subprocess.check_call([ | |
177 FindExecutable('echoscu'), | |
178 ORTHANC['Server'], | |
179 str(ORTHANC['DicomPort']), | |
180 '-aec', 'ORTHANC', | |
181 '+tls', 'dicom-tls-b.key', 'dicom-tls-b.crt', | |
182 '+cf', 'dicom-tls-b.crt', # Not the certificate of Orthanc | |
183 ], stderr = FNULL)) | |
184 | |
185 | |
186 def test_outgoing_to_self(self): | |
187 u = UploadInstance(ORTHANC, 'DummyCT.dcm') ['ID'] | |
188 | |
189 # Error, as DICOM TLS is not enabled | |
190 DoPut(ORTHANC, '/modalities/self', { | |
191 'AET' : 'ORTHANC', | |
192 'Host' : ORTHANC['Server'], | |
193 'Port' : ORTHANC['DicomPort'], | |
194 }) | |
195 | |
196 self.assertRaises(Exception, lambda: DoPost(ORTHANC, '/modalities/self/store', u)) | |
197 | |
198 # Retry using DICOM TLS | |
199 DoPut(ORTHANC, '/modalities/self', { | |
200 'AET' : 'ORTHANC', | |
201 'Host' : ORTHANC['Server'], | |
202 'Port' : ORTHANC['DicomPort'], | |
203 'UseDicomTls' : True, | |
204 }) | |
205 | |
206 self.assertEqual(1, DoPost(ORTHANC, '/modalities/self/store', u) ['InstancesCount']) | |
207 | |
400
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
208 |
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
209 def test_anonymous(self): |
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
210 # Fails on Orthanc <= 1.9.2 |
588
8aa101e126d0
migration to UCLouvain servers
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
511
diff
changeset
|
211 # https://orthanc.uclouvain.be/book/faq/dicom-tls.html#secure-tls-connections-without-certificate |
400
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
212 subprocess.check_call([ |
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
213 FindExecutable('echoscu'), |
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
214 ORTHANC['Server'], |
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
215 str(ORTHANC['DicomPort']), |
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
216 '-aec', 'ORTHANC', |
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
217 '--anonymous-tls', |
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
218 '+cf', 'dicom-tls-a.crt', |
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
219 ], stderr = FNULL) |
f454fe86061b
dicom tls: test_anonymous
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
375
diff
changeset
|
220 |
375 | 221 |
222 try: | |
223 print('\nStarting the tests...') | |
224 unittest.main(argv = [ sys.argv[0] ] + args.options) | |
225 | |
226 finally: | |
227 print('\nDone') |