blob: ab4a2d0d355f21cbf9ac5750c7d75f27bea17344 [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Mohammad Azim Khancf32c452017-06-13 14:55:58 +01002#include "mbedtls/bignum.h"
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00003#include "mbedtls/x509_crt.h"
4#include "mbedtls/x509_csr.h"
5#include "mbedtls/pem.h"
6#include "mbedtls/oid.h"
Hanno Becker418a6222017-09-14 07:51:28 +01007#include "mbedtls/rsa.h"
Valerio Setti48e8fc72022-10-19 15:14:29 +02008#include "mbedtls/asn1write.h"
Valerio Setti178b5bd2023-02-13 10:04:28 +01009#include "mbedtls/pk.h"
Manuel Pégourié-Gonnard02b10d82023-03-28 12:33:20 +020010#include "md_psa.h"
Manuel Pégourié-Gonnardfeb03962020-08-20 09:59:33 +020011
Hanno Becker418a6222017-09-14 07:51:28 +010012#if defined(MBEDTLS_RSA_C)
Gilles Peskine449bd832023-01-11 14:50:10 +010013int mbedtls_rsa_decrypt_func(void *ctx, size_t *olen,
14 const unsigned char *input, unsigned char *output,
15 size_t output_max_len)
Hanno Becker418a6222017-09-14 07:51:28 +010016{
Gilles Peskine449bd832023-01-11 14:50:10 +010017 return mbedtls_rsa_pkcs1_decrypt((mbedtls_rsa_context *) ctx, NULL, NULL,
18 olen, input, output, output_max_len);
Hanno Becker418a6222017-09-14 07:51:28 +010019}
Gilles Peskine449bd832023-01-11 14:50:10 +010020int mbedtls_rsa_sign_func(void *ctx,
21 int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
22 mbedtls_md_type_t md_alg, unsigned int hashlen,
23 const unsigned char *hash, unsigned char *sig)
Hanno Becker418a6222017-09-14 07:51:28 +010024{
Gilles Peskine449bd832023-01-11 14:50:10 +010025 return mbedtls_rsa_pkcs1_sign((mbedtls_rsa_context *) ctx, f_rng, p_rng,
26 md_alg, hashlen, hash, sig);
Hanno Becker418a6222017-09-14 07:51:28 +010027}
Gilles Peskine449bd832023-01-11 14:50:10 +010028size_t mbedtls_rsa_key_len_func(void *ctx)
Hanno Becker418a6222017-09-14 07:51:28 +010029{
Gilles Peskine449bd832023-01-11 14:50:10 +010030 return ((const mbedtls_rsa_context *) ctx)->len;
Hanno Becker418a6222017-09-14 07:51:28 +010031}
32#endif /* MBEDTLS_RSA_C */
33
Gilles Peskinef4e672e2020-01-31 14:22:10 +010034#if defined(MBEDTLS_USE_PSA_CRYPTO) && \
35 defined(MBEDTLS_PEM_WRITE_C) && defined(MBEDTLS_X509_CSR_WRITE_C)
Gilles Peskine449bd832023-01-11 14:50:10 +010036static int x509_crt_verifycsr(const unsigned char *buf, size_t buflen)
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050037{
Przemek Stekiel54a54462022-08-01 13:59:12 +020038 unsigned char hash[PSA_HASH_MAX_SIZE];
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050039 mbedtls_x509_csr csr;
Hanno Beckerbf2dacb2019-06-03 16:28:24 +010040 int ret = 0;
41
Gilles Peskine449bd832023-01-11 14:50:10 +010042 mbedtls_x509_csr_init(&csr);
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050043
Gilles Peskine449bd832023-01-11 14:50:10 +010044 if (mbedtls_x509_csr_parse(&csr, buf, buflen) != 0) {
Hanno Beckerbf2dacb2019-06-03 16:28:24 +010045 ret = MBEDTLS_ERR_X509_BAD_INPUT_DATA;
46 goto cleanup;
47 }
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050048
Manuel Pégourié-Gonnard2d6d9932023-03-28 11:38:08 +020049 psa_algorithm_t psa_alg = mbedtls_md_psa_alg_from_type(csr.sig_md);
Przemek Stekiel54a54462022-08-01 13:59:12 +020050 size_t hash_size = 0;
Gilles Peskine449bd832023-01-11 14:50:10 +010051 psa_status_t status = psa_hash_compute(psa_alg, csr.cri.p, csr.cri.len,
52 hash, PSA_HASH_MAX_SIZE, &hash_size);
Przemek Stekiel54a54462022-08-01 13:59:12 +020053
Gilles Peskine449bd832023-01-11 14:50:10 +010054 if (status != PSA_SUCCESS) {
Andrzej Kurek4b114072018-11-19 18:04:01 -050055 /* Note: this can't happen except after an internal error */
Hanno Beckerbf2dacb2019-06-03 16:28:24 +010056 ret = MBEDTLS_ERR_X509_BAD_INPUT_DATA;
57 goto cleanup;
Andrzej Kurek4b114072018-11-19 18:04:01 -050058 }
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050059
Gilles Peskine449bd832023-01-11 14:50:10 +010060 if (mbedtls_pk_verify_ext(csr.sig_pk, csr.sig_opts, &csr.pk,
Manuel Pégourié-Gonnard9b41eb82023-03-28 11:14:24 +020061 csr.sig_md, hash, mbedtls_md_get_size_from_type(csr.sig_md),
Gilles Peskine449bd832023-01-11 14:50:10 +010062 csr.sig.p, csr.sig.len) != 0) {
Hanno Beckerbf2dacb2019-06-03 16:28:24 +010063 ret = MBEDTLS_ERR_X509_CERT_VERIFY_FAILED;
64 goto cleanup;
Andrzej Kurek4b114072018-11-19 18:04:01 -050065 }
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050066
Hanno Beckerbf2dacb2019-06-03 16:28:24 +010067cleanup:
68
Gilles Peskine449bd832023-01-11 14:50:10 +010069 mbedtls_x509_csr_free(&csr);
70 return ret;
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050071}
Gilles Peskinef4e672e2020-01-31 14:22:10 +010072#endif /* MBEDTLS_USE_PSA_CRYPTO && MBEDTLS_PEM_WRITE_C && MBEDTLS_X509_CSR_WRITE_C */
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050073
Valerio Setti48e8fc72022-10-19 15:14:29 +020074#if defined(MBEDTLS_X509_CSR_WRITE_C)
75
76/*
77 * The size of this temporary buffer is given by the sequence of functions
78 * called hereinafter:
79 * - mbedtls_asn1_write_oid()
80 * - 8 bytes for MBEDTLS_OID_EXTENDED_KEY_USAGE raw value
81 * - 1 byte for MBEDTLS_OID_EXTENDED_KEY_USAGE length
82 * - 1 byte for MBEDTLS_ASN1_OID tag
83 * - mbedtls_asn1_write_len()
84 * - 1 byte since we're dealing with sizes which are less than 0x80
85 * - mbedtls_asn1_write_tag()
86 * - 1 byte
87 *
88 * This length is fine as long as this function is called using the
89 * MBEDTLS_OID_SERVER_AUTH OID. If this is changed in the future, then this
90 * buffer's length should be adjusted accordingly.
91 * Unfortunately there's no predefined max size for OIDs which can be used
92 * to set an overall upper boundary which is always guaranteed.
93 */
94#define EXT_KEY_USAGE_TMP_BUF_MAX_LENGTH 12
95
Gilles Peskine449bd832023-01-11 14:50:10 +010096static int csr_set_extended_key_usage(mbedtls_x509write_csr *ctx,
97 const char *oid, size_t oid_len)
Valerio Setti48e8fc72022-10-19 15:14:29 +020098{
99 unsigned char buf[EXT_KEY_USAGE_TMP_BUF_MAX_LENGTH] = { 0 };
Gilles Peskine449bd832023-01-11 14:50:10 +0100100 unsigned char *p = buf + sizeof(buf);
Valerio Setti48e8fc72022-10-19 15:14:29 +0200101 int ret;
102 size_t len = 0;
103
104 /*
105 * Following functions fail anyway if the temporary buffer is not large,
106 * but we set an extra check here to emphasize a possible source of errors
107 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100108 if (oid_len > EXT_KEY_USAGE_TMP_BUF_MAX_LENGTH) {
Valerio Setti48e8fc72022-10-19 15:14:29 +0200109 return MBEDTLS_ERR_X509_BAD_INPUT_DATA;
110 }
111
Gilles Peskine449bd832023-01-11 14:50:10 +0100112 MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_oid(&p, buf, oid, oid_len));
113 MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_len(&p, buf, ret));
114 MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_tag(&p, buf,
115 MBEDTLS_ASN1_CONSTRUCTED |
116 MBEDTLS_ASN1_SEQUENCE));
Valerio Setti48e8fc72022-10-19 15:14:29 +0200117
Gilles Peskine449bd832023-01-11 14:50:10 +0100118 ret = mbedtls_x509write_csr_set_extension(ctx,
119 MBEDTLS_OID_EXTENDED_KEY_USAGE,
120 MBEDTLS_OID_SIZE(MBEDTLS_OID_EXTENDED_KEY_USAGE),
121 0,
122 p,
123 len);
Valerio Setti48e8fc72022-10-19 15:14:29 +0200124
125 return ret;
126}
127#endif /* MBEDTLS_X509_CSR_WRITE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +0200128/* END_HEADER */
Paul Bakker6d620502012-02-16 14:09:13 +0000129
Paul Bakker33b43f12013-08-20 11:48:36 +0200130/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200131 * depends_on:MBEDTLS_BIGNUM_C:MBEDTLS_FS_IO:MBEDTLS_PK_PARSE_C
Paul Bakker33b43f12013-08-20 11:48:36 +0200132 * END_DEPENDENCIES
133 */
Paul Bakker6d620502012-02-16 14:09:13 +0000134
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200135/* BEGIN_CASE depends_on:MBEDTLS_PEM_WRITE_C:MBEDTLS_X509_CSR_WRITE_C */
Gilles Peskine449bd832023-01-11 14:50:10 +0100136void x509_csr_check(char *key_file, char *cert_req_check_file, int md_type,
137 int key_usage, int set_key_usage, int cert_type,
138 int set_cert_type, int set_extension)
Paul Bakker6d620502012-02-16 14:09:13 +0000139{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200140 mbedtls_pk_context key;
141 mbedtls_x509write_csr req;
Andres AGe0af9952016-09-07 11:09:44 +0100142 unsigned char buf[4096];
Paul Bakker6d620502012-02-16 14:09:13 +0000143 int ret;
Neil Armstrongc23d2e32022-03-18 15:31:59 +0100144#if !defined(MBEDTLS_USE_PSA_CRYPTO)
145 unsigned char check_buf[4000];
Paul Bakker6d620502012-02-16 14:09:13 +0000146 FILE *f;
Neil Armstrongc23d2e32022-03-18 15:31:59 +0100147 size_t olen = 0;
148#endif /* !MBEDTLS_USE_PSA_CRYPTO */
149 size_t pem_len = 0, buf_index;
150 int der_len = -1;
Paul Bakker3a8cb6f2013-12-30 20:41:54 +0100151 const char *subject_name = "C=NL,O=PolarSSL,CN=PolarSSL Server 1";
Ronald Cron351f0ee2020-06-10 12:12:18 +0200152 mbedtls_test_rnd_pseudo_info rnd_info;
Przemek Stekiel8e83d3a2023-02-14 12:01:16 +0100153 mbedtls_x509_san_list san_ip;
154 mbedtls_x509_san_list san_dns;
155 mbedtls_x509_san_list san_uri;
156 mbedtls_x509_san_list *san_list = NULL;
157 const char san_ip_name[] = { 0x7f, 0x01, 0x01, 0x00 }; // 127.1.1.0
158 const char *san_dns_name = "example.com";
159 const char *san_uri_name = "http://pki.example.com/";
160
161 san_uri.node.type = MBEDTLS_X509_SAN_UNIFORM_RESOURCE_IDENTIFIER;
Przemek Stekiel5a49d3c2023-02-24 13:12:55 +0100162 san_uri.node.san.unstructured_name.p = (unsigned char *) san_uri_name;
163 san_uri.node.san.unstructured_name.len = strlen(san_uri_name);
Przemek Stekiel8e83d3a2023-02-14 12:01:16 +0100164 san_uri.next = NULL;
165 san_ip.node.type = MBEDTLS_X509_SAN_IP_ADDRESS;
Przemek Stekiel5a49d3c2023-02-24 13:12:55 +0100166 san_ip.node.san.unstructured_name.p = (unsigned char *) san_ip_name;
167 san_ip.node.san.unstructured_name.len = sizeof(san_ip_name);
Przemek Stekiel8e83d3a2023-02-14 12:01:16 +0100168 san_ip.next = &san_uri;
169 san_dns.node.type = MBEDTLS_X509_SAN_DNS_NAME;
Przemek Stekiel5a49d3c2023-02-24 13:12:55 +0100170 san_dns.node.san.unstructured_name.p = (unsigned char *) san_dns_name;
171 san_dns.node.san.unstructured_name.len = strlen(san_dns_name);
Przemek Stekiel8e83d3a2023-02-14 12:01:16 +0100172 san_dns.next = &san_ip;
173 san_list = &san_dns;
Paul Bakker6d620502012-02-16 14:09:13 +0000174
Gilles Peskine449bd832023-01-11 14:50:10 +0100175 memset(&rnd_info, 0x2a, sizeof(mbedtls_test_rnd_pseudo_info));
Manuel Pégourié-Gonnardee731792013-09-11 22:48:40 +0200176
Gilles Peskine449bd832023-01-11 14:50:10 +0100177 mbedtls_x509write_csr_init(&req);
Gilles Peskine449bd832023-01-11 14:50:10 +0100178 mbedtls_pk_init(&key);
valerio32f2ac92023-04-20 11:59:52 +0200179 MD_OR_USE_PSA_INIT();
180
Gilles Peskine449bd832023-01-11 14:50:10 +0100181 TEST_ASSERT(mbedtls_pk_parse_keyfile(&key, key_file, NULL,
182 mbedtls_test_rnd_std_rand, NULL) == 0);
Paul Bakker6d620502012-02-16 14:09:13 +0000183
Gilles Peskine449bd832023-01-11 14:50:10 +0100184 mbedtls_x509write_csr_set_md_alg(&req, md_type);
185 mbedtls_x509write_csr_set_key(&req, &key);
186 TEST_ASSERT(mbedtls_x509write_csr_set_subject_name(&req, subject_name) == 0);
187 if (set_key_usage != 0) {
188 TEST_ASSERT(mbedtls_x509write_csr_set_key_usage(&req, key_usage) == 0);
189 }
190 if (set_cert_type != 0) {
191 TEST_ASSERT(mbedtls_x509write_csr_set_ns_cert_type(&req, cert_type) == 0);
192 }
193 if (set_extension != 0) {
194 TEST_ASSERT(csr_set_extended_key_usage(&req, MBEDTLS_OID_SERVER_AUTH,
195 MBEDTLS_OID_SIZE(MBEDTLS_OID_SERVER_AUTH)) == 0);
Przemek Stekiel8e83d3a2023-02-14 12:01:16 +0100196
197 TEST_ASSERT(mbedtls_x509write_csr_set_subject_alternative_name(&req, san_list) == 0);
Gilles Peskine449bd832023-01-11 14:50:10 +0100198 }
Paul Bakker8eabfc12013-08-25 10:18:25 +0200199
Gilles Peskine449bd832023-01-11 14:50:10 +0100200 ret = mbedtls_x509write_csr_pem(&req, buf, sizeof(buf),
201 mbedtls_test_rnd_pseudo_rand, &rnd_info);
202 TEST_ASSERT(ret == 0);
Paul Bakker6d620502012-02-16 14:09:13 +0000203
Gilles Peskine449bd832023-01-11 14:50:10 +0100204 pem_len = strlen((char *) buf);
Paul Bakker6d620502012-02-16 14:09:13 +0000205
Gilles Peskine449bd832023-01-11 14:50:10 +0100206 for (buf_index = pem_len; buf_index < sizeof(buf); ++buf_index) {
207 TEST_ASSERT(buf[buf_index] == 0);
Paul Elliott557b8d62020-11-19 09:46:56 +0000208 }
209
Neil Armstrong5b320382022-02-21 17:22:10 +0100210#if defined(MBEDTLS_USE_PSA_CRYPTO)
211 // When using PSA crypto, RNG isn't controllable, so cert_req_check_file can't be used
Gilles Peskine449bd832023-01-11 14:50:10 +0100212 (void) cert_req_check_file;
Neil Armstrong5b320382022-02-21 17:22:10 +0100213 buf[pem_len] = '\0';
Gilles Peskine449bd832023-01-11 14:50:10 +0100214 TEST_ASSERT(x509_crt_verifycsr(buf, pem_len + 1) == 0);
Neil Armstrong5b320382022-02-21 17:22:10 +0100215#else
Gilles Peskine449bd832023-01-11 14:50:10 +0100216 f = fopen(cert_req_check_file, "r");
217 TEST_ASSERT(f != NULL);
218 olen = fread(check_buf, 1, sizeof(check_buf), f);
219 fclose(f);
Paul Bakker6d620502012-02-16 14:09:13 +0000220
Gilles Peskine449bd832023-01-11 14:50:10 +0100221 TEST_ASSERT(olen >= pem_len - 1);
222 TEST_ASSERT(memcmp(buf, check_buf, pem_len - 1) == 0);
Neil Armstrongc23d2e32022-03-18 15:31:59 +0100223#endif /* MBEDTLS_USE_PSA_CRYPTO */
Paul Bakker58ef6ec2013-01-03 11:33:48 +0100224
Gilles Peskine449bd832023-01-11 14:50:10 +0100225 der_len = mbedtls_x509write_csr_der(&req, buf, sizeof(buf),
226 mbedtls_test_rnd_pseudo_rand,
227 &rnd_info);
228 TEST_ASSERT(der_len >= 0);
Andres AGe0af9952016-09-07 11:09:44 +0100229
Gilles Peskine449bd832023-01-11 14:50:10 +0100230 if (der_len == 0) {
Andres AGe0af9952016-09-07 11:09:44 +0100231 goto exit;
Gilles Peskine449bd832023-01-11 14:50:10 +0100232 }
Andres AGe0af9952016-09-07 11:09:44 +0100233
Neil Armstrong5b320382022-02-21 17:22:10 +0100234#if defined(MBEDTLS_USE_PSA_CRYPTO)
235 // When using PSA crypto, RNG isn't controllable, result length isn't
236 // deterministic over multiple runs, removing a single byte isn't enough to
237 // go into the MBEDTLS_ERR_ASN1_BUF_TOO_SMALL error case
238 der_len /= 2;
239#else
240 der_len -= 1;
241#endif
Gilles Peskine449bd832023-01-11 14:50:10 +0100242 ret = mbedtls_x509write_csr_der(&req, buf, (size_t) (der_len),
243 mbedtls_test_rnd_pseudo_rand, &rnd_info);
244 TEST_ASSERT(ret == MBEDTLS_ERR_ASN1_BUF_TOO_SMALL);
Andres AGe0af9952016-09-07 11:09:44 +0100245
Paul Bakkerbd51b262014-07-10 15:26:12 +0200246exit:
Gilles Peskine449bd832023-01-11 14:50:10 +0100247 mbedtls_x509write_csr_free(&req);
248 mbedtls_pk_free(&key);
Manuel Pégourié-Gonnard33a13022023-03-17 14:02:49 +0100249 MD_OR_USE_PSA_DONE();
Paul Bakker6d620502012-02-16 14:09:13 +0000250}
Paul Bakker33b43f12013-08-20 11:48:36 +0200251/* END_CASE */
Paul Bakker2397cf32013-09-08 15:58:15 +0200252
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500253/* BEGIN_CASE depends_on:MBEDTLS_PEM_WRITE_C:MBEDTLS_X509_CSR_WRITE_C:MBEDTLS_USE_PSA_CRYPTO */
Gilles Peskine449bd832023-01-11 14:50:10 +0100254void x509_csr_check_opaque(char *key_file, int md_type, int key_usage,
255 int cert_type)
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500256{
257 mbedtls_pk_context key;
Ronald Cron5425a212020-08-04 14:58:35 +0200258 mbedtls_svc_key_id_t key_id = MBEDTLS_SVC_KEY_ID_INIT;
Neil Armstrong95974972022-04-22 13:57:44 +0200259 psa_algorithm_t md_alg_psa, alg_psa;
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500260 mbedtls_x509write_csr req;
261 unsigned char buf[4096];
262 int ret;
263 size_t pem_len = 0;
264 const char *subject_name = "C=NL,O=PolarSSL,CN=PolarSSL Server 1";
Ronald Cron351f0ee2020-06-10 12:12:18 +0200265 mbedtls_test_rnd_pseudo_info rnd_info;
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500266
valerio32f2ac92023-04-20 11:59:52 +0200267 mbedtls_x509write_csr_init(&req);
Valerio Setti569c1712023-04-19 14:53:36 +0200268 MD_OR_USE_PSA_INIT();
269
Gilles Peskine449bd832023-01-11 14:50:10 +0100270 memset(&rnd_info, 0x2a, sizeof(mbedtls_test_rnd_pseudo_info));
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500271
Manuel Pégourié-Gonnard2d6d9932023-03-28 11:38:08 +0200272 md_alg_psa = mbedtls_md_psa_alg_from_type((mbedtls_md_type_t) md_type);
Gilles Peskine449bd832023-01-11 14:50:10 +0100273 TEST_ASSERT(md_alg_psa != MBEDTLS_MD_NONE);
Andrzej Kurek967cfd12018-11-20 02:53:17 -0500274
Gilles Peskine449bd832023-01-11 14:50:10 +0100275 mbedtls_pk_init(&key);
276 TEST_ASSERT(mbedtls_pk_parse_keyfile(&key, key_file, NULL,
277 mbedtls_test_rnd_std_rand, NULL) == 0);
Neil Armstrong95974972022-04-22 13:57:44 +0200278
Gilles Peskine449bd832023-01-11 14:50:10 +0100279 if (mbedtls_pk_get_type(&key) == MBEDTLS_PK_ECKEY) {
280 alg_psa = PSA_ALG_ECDSA(md_alg_psa);
281 } else if (mbedtls_pk_get_type(&key) == MBEDTLS_PK_RSA) {
282 alg_psa = PSA_ALG_RSA_PKCS1V15_SIGN(md_alg_psa);
283 } else {
284 TEST_ASSUME(!"PK key type not supported in this configuration");
285 }
Neil Armstrong95974972022-04-22 13:57:44 +0200286
Gilles Peskine449bd832023-01-11 14:50:10 +0100287 TEST_ASSERT(mbedtls_pk_wrap_as_opaque(&key, &key_id, alg_psa,
288 PSA_KEY_USAGE_SIGN_HASH,
289 PSA_ALG_NONE) == 0);
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500290
Gilles Peskine449bd832023-01-11 14:50:10 +0100291 mbedtls_x509write_csr_set_md_alg(&req, md_type);
292 mbedtls_x509write_csr_set_key(&req, &key);
293 TEST_ASSERT(mbedtls_x509write_csr_set_subject_name(&req, subject_name) == 0);
294 if (key_usage != 0) {
295 TEST_ASSERT(mbedtls_x509write_csr_set_key_usage(&req, key_usage) == 0);
296 }
297 if (cert_type != 0) {
298 TEST_ASSERT(mbedtls_x509write_csr_set_ns_cert_type(&req, cert_type) == 0);
299 }
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500300
Gilles Peskine449bd832023-01-11 14:50:10 +0100301 ret = mbedtls_x509write_csr_pem(&req, buf, sizeof(buf) - 1,
302 mbedtls_test_rnd_pseudo_rand, &rnd_info);
Ronald Cron6c5bd7f2020-06-10 14:08:26 +0200303
Gilles Peskine449bd832023-01-11 14:50:10 +0100304 TEST_ASSERT(ret == 0);
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500305
Gilles Peskine449bd832023-01-11 14:50:10 +0100306 pem_len = strlen((char *) buf);
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500307 buf[pem_len] = '\0';
Gilles Peskine449bd832023-01-11 14:50:10 +0100308 TEST_ASSERT(x509_crt_verifycsr(buf, pem_len + 1) == 0);
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500309
Manuel Pégourié-Gonnardfeb03962020-08-20 09:59:33 +0200310
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500311exit:
Gilles Peskine449bd832023-01-11 14:50:10 +0100312 mbedtls_x509write_csr_free(&req);
313 mbedtls_pk_free(&key);
314 psa_destroy_key(key_id);
Valerio Setti569c1712023-04-19 14:53:36 +0200315 MD_OR_USE_PSA_DONE();
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500316}
317/* END_CASE */
318
Manuel Pégourié-Gonnarda9464892023-03-17 12:08:50 +0100319/* BEGIN_CASE depends_on:MBEDTLS_PEM_WRITE_C:MBEDTLS_X509_CRT_WRITE_C:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_MD_CAN_SHA1 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100320void x509_crt_check(char *subject_key_file, char *subject_pwd,
321 char *subject_name, char *issuer_key_file,
322 char *issuer_pwd, char *issuer_name,
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100323 data_t *serial_arg, char *not_before, char *not_after,
Gilles Peskine449bd832023-01-11 14:50:10 +0100324 int md_type, int key_usage, int set_key_usage,
325 char *ext_key_usage,
326 int cert_type, int set_cert_type, int auth_ident,
327 int ver, char *cert_check_file, int pk_wrap, int is_ca,
Andrzej Kurek76c96622023-04-04 06:57:08 -0400328 char *cert_verify_file, int set_subjectAltNames)
Paul Bakker2397cf32013-09-08 15:58:15 +0200329{
Hanno Becker418a6222017-09-14 07:51:28 +0100330 mbedtls_pk_context subject_key, issuer_key, issuer_key_alt;
331 mbedtls_pk_context *key = &issuer_key;
332
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200333 mbedtls_x509write_cert crt;
Andres AGe0af9952016-09-07 11:09:44 +0100334 unsigned char buf[4096];
Paul Bakker2397cf32013-09-08 15:58:15 +0200335 unsigned char check_buf[5000];
Werner Lewisacd01e52022-05-10 12:23:13 +0100336 unsigned char *p, *end;
337 unsigned char tag, sz;
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100338#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
339 mbedtls_mpi serial_mpi;
340#endif
Werner Lewisacd01e52022-05-10 12:23:13 +0100341 int ret, before_tag, after_tag;
Paul Elliott557b8d62020-11-19 09:46:56 +0000342 size_t olen = 0, pem_len = 0, buf_index = 0;
Andres AGe0af9952016-09-07 11:09:44 +0100343 int der_len = -1;
Paul Bakker2397cf32013-09-08 15:58:15 +0200344 FILE *f;
Ronald Cron351f0ee2020-06-10 12:12:18 +0200345 mbedtls_test_rnd_pseudo_info rnd_info;
Neil Armstrong98f899c2022-03-16 17:42:42 +0100346#if defined(MBEDTLS_USE_PSA_CRYPTO)
347 mbedtls_svc_key_id_t key_id = MBEDTLS_SVC_KEY_ID_INIT;
348#endif
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100349 mbedtls_pk_type_t issuer_key_type;
Andrzej Kurek76c96622023-04-04 06:57:08 -0400350 mbedtls_x509_san_list san_ip;
351 mbedtls_x509_san_list san_dns;
352 mbedtls_x509_san_list san_uri;
353 mbedtls_x509_san_list san_mail;
354 mbedtls_x509_san_list san_dn;
355 mbedtls_asn1_named_data *ext_san_dirname = NULL;
356 const char san_ip_name[] = { 0x01, 0x02, 0x03, 0x04 };
357 const char *san_dns_name = "example.com";
358 const char *san_dn_name = "C=UK,O=Mbed TLS,CN=SubjectAltName test";
359 const char *san_mail_name = "mail@example.com";
360 const char *san_uri_name = "http://pki.example.com";
361 mbedtls_x509_san_list *san_list = NULL;
362
363 if (set_subjectAltNames) {
364 san_mail.node.type = MBEDTLS_X509_SAN_RFC822_NAME;
365 san_mail.node.san.unstructured_name.p = (unsigned char *) san_mail_name;
Andrzej Kurek13c43f62023-04-04 10:43:38 -0400366 san_mail.node.san.unstructured_name.len = strlen(san_mail_name);
Andrzej Kurek76c96622023-04-04 06:57:08 -0400367 san_mail.next = NULL;
368
369 san_dns.node.type = MBEDTLS_X509_SAN_DNS_NAME;
370 san_dns.node.san.unstructured_name.p = (unsigned char *) san_dns_name;
371 san_dns.node.san.unstructured_name.len = strlen(san_dns_name);
372 san_dns.next = &san_mail;
373
374 san_dn.node.type = MBEDTLS_X509_SAN_DIRECTORY_NAME;
375 TEST_ASSERT(mbedtls_x509_string_to_names(&ext_san_dirname,
376 san_dn_name) == 0);
377 san_dn.node.san.directory_name = *ext_san_dirname;
378 san_dn.next = &san_dns;
379
380 san_ip.node.type = MBEDTLS_X509_SAN_IP_ADDRESS;
381 san_ip.node.san.unstructured_name.p = (unsigned char *) san_ip_name;
382 san_ip.node.san.unstructured_name.len = sizeof(san_ip_name);
383 san_ip.next = &san_dn;
384
385 san_uri.node.type = MBEDTLS_X509_SAN_UNIFORM_RESOURCE_IDENTIFIER;
386 san_uri.node.san.unstructured_name.p = (unsigned char *) san_uri_name;
387 san_uri.node.san.unstructured_name.len = strlen(san_uri_name);
388 san_uri.next = &san_ip;
389
390 san_list = &san_uri;
391 }
Paul Bakker2397cf32013-09-08 15:58:15 +0200392
Gilles Peskine449bd832023-01-11 14:50:10 +0100393 memset(&rnd_info, 0x2a, sizeof(mbedtls_test_rnd_pseudo_info));
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100394#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
395 mbedtls_mpi_init(&serial_mpi);
396#endif
Hanno Becker418a6222017-09-14 07:51:28 +0100397
Gilles Peskine449bd832023-01-11 14:50:10 +0100398 mbedtls_pk_init(&subject_key);
399 mbedtls_pk_init(&issuer_key);
400 mbedtls_pk_init(&issuer_key_alt);
Gilles Peskine449bd832023-01-11 14:50:10 +0100401 mbedtls_x509write_crt_init(&crt);
valerio32f2ac92023-04-20 11:59:52 +0200402 MD_OR_USE_PSA_INIT();
Paul Bakker2397cf32013-09-08 15:58:15 +0200403
Gilles Peskine449bd832023-01-11 14:50:10 +0100404 TEST_ASSERT(mbedtls_pk_parse_keyfile(&subject_key, subject_key_file,
405 subject_pwd, mbedtls_test_rnd_std_rand, NULL) == 0);
Hanno Becker418a6222017-09-14 07:51:28 +0100406
Gilles Peskine449bd832023-01-11 14:50:10 +0100407 TEST_ASSERT(mbedtls_pk_parse_keyfile(&issuer_key, issuer_key_file,
408 issuer_pwd, mbedtls_test_rnd_std_rand, NULL) == 0);
Hanno Becker418a6222017-09-14 07:51:28 +0100409
Gilles Peskine449bd832023-01-11 14:50:10 +0100410 issuer_key_type = mbedtls_pk_get_type(&issuer_key);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100411
Dave Rodgmandc3b1542023-01-20 11:39:00 +0000412#if defined(MBEDTLS_RSA_C) && defined(MBEDTLS_PK_RSA_ALT_SUPPORT)
Hanno Becker418a6222017-09-14 07:51:28 +0100413 /* For RSA PK contexts, create a copy as an alternative RSA context. */
Gilles Peskine449bd832023-01-11 14:50:10 +0100414 if (pk_wrap == 1 && issuer_key_type == MBEDTLS_PK_RSA) {
415 TEST_ASSERT(mbedtls_pk_setup_rsa_alt(&issuer_key_alt,
416 mbedtls_pk_rsa(issuer_key),
417 mbedtls_rsa_decrypt_func,
418 mbedtls_rsa_sign_func,
419 mbedtls_rsa_key_len_func) == 0);
Hanno Becker418a6222017-09-14 07:51:28 +0100420
421 key = &issuer_key_alt;
422 }
Manuel Pégourié-Gonnard147b28e2018-03-12 15:26:59 +0100423#endif
Hanno Becker418a6222017-09-14 07:51:28 +0100424
Neil Armstrong98f899c2022-03-16 17:42:42 +0100425#if defined(MBEDTLS_USE_PSA_CRYPTO)
426 /* For Opaque PK contexts, wrap key as an Opaque RSA context. */
Gilles Peskine449bd832023-01-11 14:50:10 +0100427 if (pk_wrap == 2) {
Neil Armstrong95974972022-04-22 13:57:44 +0200428 psa_algorithm_t alg_psa, md_alg_psa;
Neil Armstrong98f899c2022-03-16 17:42:42 +0100429
Manuel Pégourié-Gonnard2d6d9932023-03-28 11:38:08 +0200430 md_alg_psa = mbedtls_md_psa_alg_from_type((mbedtls_md_type_t) md_type);
Gilles Peskine449bd832023-01-11 14:50:10 +0100431 TEST_ASSERT(md_alg_psa != MBEDTLS_MD_NONE);
Neil Armstrong95974972022-04-22 13:57:44 +0200432
Gilles Peskine449bd832023-01-11 14:50:10 +0100433 if (mbedtls_pk_get_type(&issuer_key) == MBEDTLS_PK_ECKEY) {
434 alg_psa = PSA_ALG_ECDSA(md_alg_psa);
435 } else if (mbedtls_pk_get_type(&issuer_key) == MBEDTLS_PK_RSA) {
436 alg_psa = PSA_ALG_RSA_PKCS1V15_SIGN(md_alg_psa);
437 } else {
438 TEST_ASSUME(!"PK key type not supported in this configuration");
439 }
Neil Armstrong95974972022-04-22 13:57:44 +0200440
Gilles Peskine449bd832023-01-11 14:50:10 +0100441 TEST_ASSERT(mbedtls_pk_wrap_as_opaque(&issuer_key, &key_id, alg_psa,
442 PSA_KEY_USAGE_SIGN_HASH,
443 PSA_ALG_NONE) == 0);
Neil Armstrong98f899c2022-03-16 17:42:42 +0100444 }
445#endif /* MBEDTLS_USE_PSA_CRYPTO */
446
Gilles Peskine449bd832023-01-11 14:50:10 +0100447 if (pk_wrap == 2) {
448 TEST_ASSERT(mbedtls_pk_get_type(&issuer_key) == MBEDTLS_PK_OPAQUE);
449 }
Neil Armstrong98f899c2022-03-16 17:42:42 +0100450
Gilles Peskine449bd832023-01-11 14:50:10 +0100451 if (ver != -1) {
452 mbedtls_x509write_crt_set_version(&crt, ver);
453 }
Hanno Becker418a6222017-09-14 07:51:28 +0100454
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100455#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100456 TEST_ASSERT(mbedtls_mpi_read_binary(&serial_mpi, serial_arg->x,
457 serial_arg->len) == 0);
458 TEST_ASSERT(mbedtls_x509write_crt_set_serial(&crt, &serial_mpi) == 0);
Valerio Settida0afcc2023-01-05 16:46:59 +0100459#else
Valerio Settiaf4815c2023-01-26 17:43:09 +0100460 TEST_ASSERT(mbedtls_x509write_crt_set_serial_raw(&crt, serial_arg->x,
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100461 serial_arg->len) == 0);
Valerio Settida0afcc2023-01-05 16:46:59 +0100462#endif
Gilles Peskine449bd832023-01-11 14:50:10 +0100463 TEST_ASSERT(mbedtls_x509write_crt_set_validity(&crt, not_before,
464 not_after) == 0);
465 mbedtls_x509write_crt_set_md_alg(&crt, md_type);
466 TEST_ASSERT(mbedtls_x509write_crt_set_issuer_name(&crt, issuer_name) == 0);
467 TEST_ASSERT(mbedtls_x509write_crt_set_subject_name(&crt, subject_name) == 0);
468 mbedtls_x509write_crt_set_subject_key(&crt, &subject_key);
Hanno Becker418a6222017-09-14 07:51:28 +0100469
Gilles Peskine449bd832023-01-11 14:50:10 +0100470 mbedtls_x509write_crt_set_issuer_key(&crt, key);
Paul Bakker2397cf32013-09-08 15:58:15 +0200471
Gilles Peskine449bd832023-01-11 14:50:10 +0100472 if (crt.version >= MBEDTLS_X509_CRT_VERSION_3) {
Darren Krahn9c134ce2021-01-13 22:04:45 -0800473 /* For the CA case, a path length of -1 means unlimited. */
Gilles Peskine449bd832023-01-11 14:50:10 +0100474 TEST_ASSERT(mbedtls_x509write_crt_set_basic_constraints(&crt, is_ca,
475 (is_ca ? -1 : 0)) == 0);
476 TEST_ASSERT(mbedtls_x509write_crt_set_subject_key_identifier(&crt) == 0);
477 if (auth_ident) {
478 TEST_ASSERT(mbedtls_x509write_crt_set_authority_key_identifier(&crt) == 0);
479 }
480 if (set_key_usage != 0) {
481 TEST_ASSERT(mbedtls_x509write_crt_set_key_usage(&crt, key_usage) == 0);
482 }
483 if (set_cert_type != 0) {
484 TEST_ASSERT(mbedtls_x509write_crt_set_ns_cert_type(&crt, cert_type) == 0);
485 }
486 if (strcmp(ext_key_usage, "NULL") != 0) {
Dave Rodgmanec9f6b42022-07-27 14:34:58 +0100487 mbedtls_asn1_sequence exts[2];
Gilles Peskine449bd832023-01-11 14:50:10 +0100488 memset(exts, 0, sizeof(exts));
Dave Rodgman5f3f0d02022-08-11 14:38:26 +0100489
490#define SET_OID(x, oid) \
491 do { \
492 x.len = MBEDTLS_OID_SIZE(oid); \
Gilles Peskine449bd832023-01-11 14:50:10 +0100493 x.p = (unsigned char *) oid; \
Dave Rodgman5f3f0d02022-08-11 14:38:26 +0100494 x.tag = MBEDTLS_ASN1_OID; \
Dave Rodgmane2b772d2022-08-11 16:04:13 +0100495 } \
Gilles Peskine449bd832023-01-11 14:50:10 +0100496 while (0)
Dave Rodgman5f3f0d02022-08-11 14:38:26 +0100497
Gilles Peskine449bd832023-01-11 14:50:10 +0100498 if (strcmp(ext_key_usage, "serverAuth") == 0) {
499 SET_OID(exts[0].buf, MBEDTLS_OID_SERVER_AUTH);
500 } else if (strcmp(ext_key_usage, "codeSigning,timeStamping") == 0) {
501 SET_OID(exts[0].buf, MBEDTLS_OID_CODE_SIGNING);
Dave Rodgman5f3f0d02022-08-11 14:38:26 +0100502 exts[0].next = &exts[1];
Gilles Peskine449bd832023-01-11 14:50:10 +0100503 SET_OID(exts[1].buf, MBEDTLS_OID_TIME_STAMPING);
Nicholas Wilsonca841d32015-11-13 14:22:36 +0000504 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100505 TEST_ASSERT(mbedtls_x509write_crt_set_ext_key_usage(&crt, exts) == 0);
Nicholas Wilsonca841d32015-11-13 14:22:36 +0000506 }
Manuel Pégourié-Gonnard6c1a73e2014-03-28 14:03:22 +0100507 }
Paul Bakker2397cf32013-09-08 15:58:15 +0200508
Andrzej Kurek76c96622023-04-04 06:57:08 -0400509 if (set_subjectAltNames) {
510 TEST_ASSERT(mbedtls_x509write_crt_set_subject_alternative_name(&crt, san_list) == 0);
511 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100512 ret = mbedtls_x509write_crt_pem(&crt, buf, sizeof(buf),
513 mbedtls_test_rnd_pseudo_rand, &rnd_info);
514 TEST_ASSERT(ret == 0);
Paul Bakker2397cf32013-09-08 15:58:15 +0200515
Gilles Peskine449bd832023-01-11 14:50:10 +0100516 pem_len = strlen((char *) buf);
Paul Bakker2397cf32013-09-08 15:58:15 +0200517
Paul Elliott557b8d62020-11-19 09:46:56 +0000518 // check that the rest of the buffer remains clear
Gilles Peskine449bd832023-01-11 14:50:10 +0100519 for (buf_index = pem_len; buf_index < sizeof(buf); ++buf_index) {
520 TEST_ASSERT(buf[buf_index] == 0);
Paul Elliott557b8d62020-11-19 09:46:56 +0000521 }
522
Gilles Peskine449bd832023-01-11 14:50:10 +0100523 if (issuer_key_type != MBEDTLS_PK_RSA) {
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100524 mbedtls_x509_crt crt_parse, trusted;
525 uint32_t flags;
Paul Bakker2397cf32013-09-08 15:58:15 +0200526
Gilles Peskine449bd832023-01-11 14:50:10 +0100527 mbedtls_x509_crt_init(&crt_parse);
528 mbedtls_x509_crt_init(&trusted);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100529
Gilles Peskine449bd832023-01-11 14:50:10 +0100530 TEST_ASSERT(mbedtls_x509_crt_parse_file(&trusted,
531 cert_verify_file) == 0);
532 TEST_ASSERT(mbedtls_x509_crt_parse(&crt_parse,
533 buf, sizeof(buf)) == 0);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100534
Gilles Peskine449bd832023-01-11 14:50:10 +0100535 ret = mbedtls_x509_crt_verify(&crt_parse, &trusted, NULL, NULL, &flags,
536 NULL, NULL);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100537
Gilles Peskine449bd832023-01-11 14:50:10 +0100538 mbedtls_x509_crt_free(&crt_parse);
539 mbedtls_x509_crt_free(&trusted);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100540
Gilles Peskine449bd832023-01-11 14:50:10 +0100541 TEST_EQUAL(flags, 0);
542 TEST_EQUAL(ret, 0);
543 } else if (*cert_check_file != '\0') {
544 f = fopen(cert_check_file, "r");
545 TEST_ASSERT(f != NULL);
546 olen = fread(check_buf, 1, sizeof(check_buf), f);
547 fclose(f);
548 TEST_ASSERT(olen < sizeof(check_buf));
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100549
Gilles Peskine449bd832023-01-11 14:50:10 +0100550 TEST_EQUAL(olen, pem_len);
551 TEST_ASSERT(olen >= pem_len - 1);
552 TEST_ASSERT(memcmp(buf, check_buf, pem_len - 1) == 0);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100553 }
Paul Bakker2397cf32013-09-08 15:58:15 +0200554
Gilles Peskine449bd832023-01-11 14:50:10 +0100555 der_len = mbedtls_x509write_crt_der(&crt, buf, sizeof(buf),
556 mbedtls_test_rnd_pseudo_rand,
557 &rnd_info);
558 TEST_ASSERT(der_len >= 0);
Andres AGe0af9952016-09-07 11:09:44 +0100559
Gilles Peskine449bd832023-01-11 14:50:10 +0100560 if (der_len == 0) {
Andres AGe0af9952016-09-07 11:09:44 +0100561 goto exit;
Gilles Peskine449bd832023-01-11 14:50:10 +0100562 }
Andres AGe0af9952016-09-07 11:09:44 +0100563
Werner Lewisacd01e52022-05-10 12:23:13 +0100564 // Not testing against file, check date format
Gilles Peskine449bd832023-01-11 14:50:10 +0100565 if (*cert_check_file == '\0') {
Werner Lewisacd01e52022-05-10 12:23:13 +0100566 // UTC tag if before 2050, 2 digits less for year
Gilles Peskine449bd832023-01-11 14:50:10 +0100567 if (not_before[0] == '2' && (not_before[1] > '0' || not_before[2] > '4')) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100568 before_tag = MBEDTLS_ASN1_GENERALIZED_TIME;
Gilles Peskine449bd832023-01-11 14:50:10 +0100569 } else {
Werner Lewisacd01e52022-05-10 12:23:13 +0100570 before_tag = MBEDTLS_ASN1_UTC_TIME;
571 not_before += 2;
572 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100573 if (not_after[0] == '2' && (not_after[1] > '0' || not_after[2] > '4')) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100574 after_tag = MBEDTLS_ASN1_GENERALIZED_TIME;
Gilles Peskine449bd832023-01-11 14:50:10 +0100575 } else {
Werner Lewisacd01e52022-05-10 12:23:13 +0100576 after_tag = MBEDTLS_ASN1_UTC_TIME;
577 not_after += 2;
578 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100579 end = buf + sizeof(buf);
580 for (p = end - der_len; p < end;) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100581 tag = *p++;
582 sz = *p++;
Gilles Peskine449bd832023-01-11 14:50:10 +0100583 if (tag == MBEDTLS_ASN1_UTC_TIME || tag == MBEDTLS_ASN1_GENERALIZED_TIME) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100584 // Check correct tag and time written
Gilles Peskine449bd832023-01-11 14:50:10 +0100585 TEST_ASSERT(before_tag == tag);
586 TEST_ASSERT(memcmp(p, not_before, sz - 1) == 0);
Werner Lewisacd01e52022-05-10 12:23:13 +0100587 p += sz;
588 tag = *p++;
589 sz = *p++;
Gilles Peskine449bd832023-01-11 14:50:10 +0100590 TEST_ASSERT(after_tag == tag);
591 TEST_ASSERT(memcmp(p, not_after, sz - 1) == 0);
Werner Lewisacd01e52022-05-10 12:23:13 +0100592 break;
593 }
594 // Increment if long form ASN1 length
Gilles Peskine449bd832023-01-11 14:50:10 +0100595 if (sz & 0x80) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100596 p += sz & 0x0F;
Gilles Peskine449bd832023-01-11 14:50:10 +0100597 }
598 if (tag != (MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE)) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100599 p += sz;
Gilles Peskine449bd832023-01-11 14:50:10 +0100600 }
Werner Lewisacd01e52022-05-10 12:23:13 +0100601 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100602 TEST_ASSERT(p < end);
Werner Lewisacd01e52022-05-10 12:23:13 +0100603 }
604
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100605#if defined(MBEDTLS_USE_PSA_CRYPTO)
Neil Armstronge6ed23c2022-04-22 09:44:04 +0200606 // When using PSA crypto, RNG isn't controllable, result length isn't
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100607 // deterministic over multiple runs, removing a single byte isn't enough to
608 // go into the MBEDTLS_ERR_ASN1_BUF_TOO_SMALL error case
Gilles Peskine449bd832023-01-11 14:50:10 +0100609 if (issuer_key_type != MBEDTLS_PK_RSA) {
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100610 der_len /= 2;
Gilles Peskine449bd832023-01-11 14:50:10 +0100611 } else
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100612#endif
Gilles Peskine449bd832023-01-11 14:50:10 +0100613 der_len -= 1;
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100614
Gilles Peskine449bd832023-01-11 14:50:10 +0100615 ret = mbedtls_x509write_crt_der(&crt, buf, (size_t) (der_len),
616 mbedtls_test_rnd_pseudo_rand, &rnd_info);
617 TEST_ASSERT(ret == MBEDTLS_ERR_ASN1_BUF_TOO_SMALL);
Andres AGe0af9952016-09-07 11:09:44 +0100618
Paul Bakkerbd51b262014-07-10 15:26:12 +0200619exit:
Andrzej Kurek5da1d752023-04-05 08:30:59 -0400620 mbedtls_asn1_free_named_data_list(&ext_san_dirname);
Gilles Peskine449bd832023-01-11 14:50:10 +0100621 mbedtls_x509write_crt_free(&crt);
622 mbedtls_pk_free(&issuer_key_alt);
623 mbedtls_pk_free(&subject_key);
624 mbedtls_pk_free(&issuer_key);
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100625#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
626 mbedtls_mpi_free(&serial_mpi);
627#endif
Neil Armstrong98f899c2022-03-16 17:42:42 +0100628#if defined(MBEDTLS_USE_PSA_CRYPTO)
Gilles Peskine449bd832023-01-11 14:50:10 +0100629 psa_destroy_key(key_id);
Neil Armstrong98f899c2022-03-16 17:42:42 +0100630#endif
Manuel Pégourié-Gonnard33a13022023-03-17 14:02:49 +0100631 MD_OR_USE_PSA_DONE();
Paul Bakker2397cf32013-09-08 15:58:15 +0200632}
633/* END_CASE */
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200634
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100635/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_WRITE_C */
636void x509_set_serial_check()
637{
638 mbedtls_x509write_cert ctx;
639 uint8_t invalid_serial[MBEDTLS_X509_RFC5280_MAX_SERIAL_LEN + 1];
640
Valerio Setti569c1712023-04-19 14:53:36 +0200641 USE_PSA_INIT();
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100642 memset(invalid_serial, 0x01, sizeof(invalid_serial));
643
Valerio Settiea19d2d2023-01-09 17:21:17 +0100644#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100645 mbedtls_mpi serial_mpi;
646
647 mbedtls_mpi_init(&serial_mpi);
648 TEST_EQUAL(mbedtls_mpi_read_binary(&serial_mpi, invalid_serial,
649 sizeof(invalid_serial)), 0);
650 TEST_EQUAL(mbedtls_x509write_crt_set_serial(&ctx, &serial_mpi),
651 MBEDTLS_ERR_X509_BAD_INPUT_DATA);
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100652#endif
653
Valerio Settiaf4815c2023-01-26 17:43:09 +0100654 TEST_EQUAL(mbedtls_x509write_crt_set_serial_raw(&ctx, invalid_serial,
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100655 sizeof(invalid_serial)),
656 MBEDTLS_ERR_X509_BAD_INPUT_DATA);
657
Valerio Settia87f8392023-01-26 18:00:50 +0100658exit:
659#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
660 mbedtls_mpi_free(&serial_mpi);
661#else
662 ;
663#endif
Valerio Setti569c1712023-04-19 14:53:36 +0200664 USE_PSA_DONE();
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100665}
666/* END_CASE */
667
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200668/* BEGIN_CASE depends_on:MBEDTLS_X509_CREATE_C:MBEDTLS_X509_USE_C */
Gilles Peskine449bd832023-01-11 14:50:10 +0100669void mbedtls_x509_string_to_names(char *name, char *parsed_name, int result
670 )
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200671{
672 int ret;
673 size_t len = 0;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200674 mbedtls_asn1_named_data *names = NULL;
675 mbedtls_x509_name parsed, *parsed_cur, *parsed_prv;
Manuel Pégourié-Gonnard4fd0b252015-06-26 14:15:48 +0200676 unsigned char buf[1024], out[1024], *c;
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200677
Valerio Setti569c1712023-04-19 14:53:36 +0200678 USE_PSA_INIT();
679
Gilles Peskine449bd832023-01-11 14:50:10 +0100680 memset(&parsed, 0, sizeof(parsed));
681 memset(out, 0, sizeof(out));
682 memset(buf, 0, sizeof(buf));
683 c = buf + sizeof(buf);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200684
Gilles Peskine449bd832023-01-11 14:50:10 +0100685 ret = mbedtls_x509_string_to_names(&names, name);
686 TEST_ASSERT(ret == result);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200687
Gilles Peskine449bd832023-01-11 14:50:10 +0100688 if (ret != 0) {
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200689 goto exit;
Gilles Peskine449bd832023-01-11 14:50:10 +0100690 }
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200691
Gilles Peskine449bd832023-01-11 14:50:10 +0100692 ret = mbedtls_x509_write_names(&c, buf, names);
693 TEST_ASSERT(ret > 0);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200694
Gilles Peskine449bd832023-01-11 14:50:10 +0100695 TEST_ASSERT(mbedtls_asn1_get_tag(&c, buf + sizeof(buf), &len,
696 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE) == 0);
697 TEST_ASSERT(mbedtls_x509_get_name(&c, buf + sizeof(buf), &parsed) == 0);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200698
Gilles Peskine449bd832023-01-11 14:50:10 +0100699 ret = mbedtls_x509_dn_gets((char *) out, sizeof(out), &parsed);
700 TEST_ASSERT(ret > 0);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200701
Gilles Peskine449bd832023-01-11 14:50:10 +0100702 TEST_ASSERT(strcmp((char *) out, parsed_name) == 0);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200703
704exit:
Gilles Peskine449bd832023-01-11 14:50:10 +0100705 mbedtls_asn1_free_named_data_list(&names);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200706
707 parsed_cur = parsed.next;
Gilles Peskine449bd832023-01-11 14:50:10 +0100708 while (parsed_cur != 0) {
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200709 parsed_prv = parsed_cur;
710 parsed_cur = parsed_cur->next;
Gilles Peskine449bd832023-01-11 14:50:10 +0100711 mbedtls_free(parsed_prv);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200712 }
Valerio Setti569c1712023-04-19 14:53:36 +0200713 USE_PSA_DONE();
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200714}
715/* END_CASE */