Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 1 | /* BEGIN_HEADER */ |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 2 | #include <polarssl/x509write.h> |
| 3 | #include <polarssl/x509.h> |
| 4 | #include <polarssl/pem.h> |
Paul Bakker | c70b982 | 2013-04-07 22:00:46 +0200 | [diff] [blame] | 5 | #include <polarssl/oid.h> |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 6 | /* END_HEADER */ |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 7 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 8 | /* BEGIN_DEPENDENCIES |
| 9 | * depends_on:POLARSSL_X509_WRITE_C:POLARSSL_BIGNUM_C |
| 10 | * END_DEPENDENCIES |
| 11 | */ |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 12 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 13 | /* BEGIN_CASE */ |
Paul Bakker | 82e2945 | 2013-08-25 11:01:31 +0200 | [diff] [blame] | 14 | void x509_csr_check( char *key_file, int md_type, |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 15 | char *cert_req_check_file ) |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 16 | { |
Manuel Pégourié-Gonnard | ee73179 | 2013-09-11 22:48:40 +0200 | [diff] [blame] | 17 | pk_context key; |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 18 | pem_context pem; |
Paul Bakker | cd35803 | 2013-09-09 12:08:11 +0200 | [diff] [blame] | 19 | x509write_csr req; |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 20 | unsigned char *c; |
| 21 | unsigned char buf[4000]; |
| 22 | unsigned char check_buf[4000]; |
| 23 | int ret; |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame] | 24 | size_t olen = sizeof( check_buf ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 25 | FILE *f; |
Paul Bakker | 2130796 | 2013-08-25 10:33:27 +0200 | [diff] [blame] | 26 | char *subject_name = "C=NL,O=PolarSSL,CN=PolarSSL Server 1"; |
Manuel Pégourié-Gonnard | ee73179 | 2013-09-11 22:48:40 +0200 | [diff] [blame] | 27 | rnd_pseudo_info rnd_info; |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 28 | |
Manuel Pégourié-Gonnard | ee73179 | 2013-09-11 22:48:40 +0200 | [diff] [blame] | 29 | memset( &rnd_info, 0x2a, sizeof( rnd_pseudo_info ) ); |
| 30 | |
| 31 | pk_init( &key ); |
| 32 | TEST_ASSERT( x509parse_keyfile( &key, key_file, NULL ) == 0 ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 33 | |
Paul Bakker | 82e2945 | 2013-08-25 11:01:31 +0200 | [diff] [blame] | 34 | x509write_csr_init( &req ); |
| 35 | x509write_csr_set_md_alg( &req, md_type ); |
Manuel Pégourié-Gonnard | ee73179 | 2013-09-11 22:48:40 +0200 | [diff] [blame] | 36 | x509write_csr_set_key( &req, &key ); |
Paul Bakker | 82e2945 | 2013-08-25 11:01:31 +0200 | [diff] [blame] | 37 | TEST_ASSERT( x509write_csr_set_subject_name( &req, subject_name ) == 0 ); |
Paul Bakker | 8eabfc1 | 2013-08-25 10:18:25 +0200 | [diff] [blame] | 38 | |
Manuel Pégourié-Gonnard | ee73179 | 2013-09-11 22:48:40 +0200 | [diff] [blame] | 39 | ret = x509write_csr_der( &req, buf, sizeof( buf ), |
| 40 | rnd_pseudo_rand, &rnd_info ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 41 | TEST_ASSERT( ret >= 0 ); |
| 42 | |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame] | 43 | c = buf + sizeof( buf ) - ret; |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 44 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 45 | f = fopen( cert_req_check_file, "r" ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 46 | TEST_ASSERT( f != NULL ); |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame] | 47 | fread( check_buf, 1, sizeof( check_buf ), f ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 48 | fclose( f ); |
| 49 | |
| 50 | pem_init( &pem ); |
| 51 | pem_read_buffer( &pem, "-----BEGIN CERTIFICATE REQUEST-----", "-----END CERTIFICATE REQUEST-----", check_buf, NULL, 0, &olen ); |
| 52 | |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 53 | TEST_ASSERT( pem.buflen == (size_t) ret ); |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame] | 54 | TEST_ASSERT( memcmp( c, pem.buf, pem.buflen ) == 0 ); |
Paul Bakker | 58ef6ec | 2013-01-03 11:33:48 +0100 | [diff] [blame] | 55 | |
Paul Bakker | 82e2945 | 2013-08-25 11:01:31 +0200 | [diff] [blame] | 56 | x509write_csr_free( &req ); |
Paul Bakker | 58ef6ec | 2013-01-03 11:33:48 +0100 | [diff] [blame] | 57 | pem_free( &pem ); |
Manuel Pégourié-Gonnard | ee73179 | 2013-09-11 22:48:40 +0200 | [diff] [blame] | 58 | pk_free( &key ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 59 | } |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 60 | /* END_CASE */ |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 61 | |
| 62 | /* BEGIN_CASE */ |
| 63 | void x509_crt_check( char *subject_key_file, char *subject_pwd, |
| 64 | char *subject_name, char *issuer_key_file, |
| 65 | char *issuer_pwd, char *issuer_name, |
| 66 | char *serial_str, char *not_before, char *not_after, |
| 67 | int md_type, char *cert_check_file ) |
| 68 | { |
Manuel Pégourié-Gonnard | f38e71a | 2013-09-12 05:21:54 +0200 | [diff] [blame] | 69 | pk_context subject_key, issuer_key; |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 70 | pem_context pem; |
| 71 | x509write_cert crt; |
| 72 | unsigned char *c; |
| 73 | unsigned char buf[4000]; |
| 74 | unsigned char check_buf[5000]; |
| 75 | mpi serial; |
| 76 | int ret; |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame] | 77 | size_t olen = sizeof( check_buf ); |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 78 | FILE *f; |
Manuel Pégourié-Gonnard | 31e5940 | 2013-09-12 05:59:05 +0200 | [diff] [blame] | 79 | rnd_pseudo_info rnd_info; |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 80 | |
Manuel Pégourié-Gonnard | 31e5940 | 2013-09-12 05:59:05 +0200 | [diff] [blame] | 81 | memset( &rnd_info, 0x2a, sizeof( rnd_pseudo_info ) ); |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 82 | mpi_init( &serial ); |
Manuel Pégourié-Gonnard | f38e71a | 2013-09-12 05:21:54 +0200 | [diff] [blame] | 83 | pk_init( &subject_key ); |
| 84 | pk_init( &issuer_key ); |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 85 | |
Manuel Pégourié-Gonnard | f38e71a | 2013-09-12 05:21:54 +0200 | [diff] [blame] | 86 | TEST_ASSERT( x509parse_keyfile( &subject_key, subject_key_file, |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 87 | subject_pwd ) == 0 ); |
Manuel Pégourié-Gonnard | f38e71a | 2013-09-12 05:21:54 +0200 | [diff] [blame] | 88 | TEST_ASSERT( x509parse_keyfile( &issuer_key, issuer_key_file, |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 89 | issuer_pwd ) == 0 ); |
| 90 | TEST_ASSERT( mpi_read_string( &serial, 10, serial_str ) == 0 ); |
| 91 | |
| 92 | x509write_crt_init( &crt ); |
| 93 | x509write_crt_set_serial( &crt, &serial ); |
| 94 | TEST_ASSERT( x509write_crt_set_validity( &crt, not_before, |
| 95 | not_after ) == 0 ); |
| 96 | x509write_crt_set_md_alg( &crt, md_type ); |
| 97 | TEST_ASSERT( x509write_crt_set_issuer_name( &crt, issuer_name ) == 0 ); |
| 98 | TEST_ASSERT( x509write_crt_set_subject_name( &crt, subject_name ) == 0 ); |
Manuel Pégourié-Gonnard | f38e71a | 2013-09-12 05:21:54 +0200 | [diff] [blame] | 99 | x509write_crt_set_subject_key( &crt, &subject_key ); |
| 100 | x509write_crt_set_issuer_key( &crt, &issuer_key ); |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 101 | |
| 102 | TEST_ASSERT( x509write_crt_set_basic_constraints( &crt, 0, 0 ) == 0 ); |
| 103 | TEST_ASSERT( x509write_crt_set_subject_key_identifier( &crt ) == 0 ); |
| 104 | TEST_ASSERT( x509write_crt_set_authority_key_identifier( &crt ) == 0 ); |
| 105 | |
Manuel Pégourié-Gonnard | 31e5940 | 2013-09-12 05:59:05 +0200 | [diff] [blame] | 106 | ret = x509write_crt_der( &crt, buf, sizeof(buf), |
| 107 | rnd_pseudo_rand, &rnd_info ); |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 108 | TEST_ASSERT( ret >= 0 ); |
| 109 | |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame] | 110 | c = buf + sizeof( buf ) - ret; |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 111 | |
| 112 | f = fopen( cert_check_file, "r" ); |
| 113 | TEST_ASSERT( f != NULL ); |
| 114 | TEST_ASSERT( fread( check_buf, 1, sizeof(check_buf), f ) < sizeof(check_buf) ); |
| 115 | fclose( f ); |
| 116 | |
| 117 | pem_init( &pem ); |
| 118 | TEST_ASSERT( pem_read_buffer( &pem, "-----BEGIN CERTIFICATE-----", "-----END CERTIFICATE-----", check_buf, NULL, 0, &olen ) >= 0 ); |
| 119 | |
| 120 | TEST_ASSERT( pem.buflen == (size_t) ret ); |
| 121 | TEST_ASSERT( memcmp( c, pem.buf, pem.buflen ) == 0 ); |
| 122 | |
| 123 | x509write_crt_free( &crt ); |
Manuel Pégourié-Gonnard | f38e71a | 2013-09-12 05:21:54 +0200 | [diff] [blame] | 124 | pk_free( &issuer_key ); |
| 125 | pk_free( &subject_key ); |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 126 | pem_free( &pem ); |
| 127 | mpi_free( &serial ); |
| 128 | } |
| 129 | /* END_CASE */ |
Manuel Pégourié-Gonnard | 33250b0 | 2013-09-11 23:46:51 +0200 | [diff] [blame] | 130 | |
| 131 | /* BEGIN_CASE */ |
| 132 | void x509_pubkey_check( char *key_file ) |
| 133 | { |
| 134 | pk_context key; |
| 135 | unsigned char buf[5000]; |
| 136 | unsigned char check_buf[5000]; |
| 137 | int ret; |
Manuel Pégourié-Gonnard | 33250b0 | 2013-09-11 23:46:51 +0200 | [diff] [blame] | 138 | FILE *f; |
| 139 | |
| 140 | memset( buf, 0, sizeof( buf ) ); |
| 141 | memset( check_buf, 0, sizeof( check_buf ) ); |
| 142 | |
| 143 | pk_init( &key ); |
| 144 | TEST_ASSERT( x509parse_public_keyfile( &key, key_file ) == 0 ); |
| 145 | |
Manuel Pégourié-Gonnard | e1f821a | 2013-09-12 00:59:40 +0200 | [diff] [blame] | 146 | ret = x509write_pubkey_pem( &key, buf, sizeof( buf ) - 1); |
Manuel Pégourié-Gonnard | 33250b0 | 2013-09-11 23:46:51 +0200 | [diff] [blame] | 147 | TEST_ASSERT( ret >= 0 ); |
| 148 | |
| 149 | f = fopen( key_file, "r" ); |
| 150 | TEST_ASSERT( f != NULL ); |
| 151 | fread( check_buf, 1, sizeof( check_buf ) - 1, f ); |
| 152 | fclose( f ); |
| 153 | |
| 154 | TEST_ASSERT( strncmp( (char *) buf, (char *) check_buf, sizeof( buf ) ) == 0 ); |
| 155 | |
| 156 | pk_free( &key ); |
| 157 | } |
| 158 | /* END_CASE */ |
Manuel Pégourié-Gonnard | 7f1f092 | 2013-09-12 03:31:34 +0200 | [diff] [blame] | 159 | |
| 160 | /* BEGIN_CASE */ |
| 161 | void x509_key_check( char *key_file ) |
| 162 | { |
| 163 | pk_context key; |
| 164 | unsigned char buf[5000]; |
| 165 | unsigned char check_buf[5000]; |
| 166 | int ret; |
| 167 | FILE *f; |
| 168 | |
| 169 | memset( buf, 0, sizeof( buf ) ); |
| 170 | memset( check_buf, 0, sizeof( check_buf ) ); |
| 171 | |
| 172 | pk_init( &key ); |
| 173 | TEST_ASSERT( x509parse_keyfile( &key, key_file, NULL ) == 0 ); |
| 174 | |
Manuel Pégourié-Gonnard | 6de63e4 | 2013-09-12 04:59:34 +0200 | [diff] [blame] | 175 | ret = x509write_key_pem( &key, buf, sizeof( buf ) - 1); |
Manuel Pégourié-Gonnard | 7f1f092 | 2013-09-12 03:31:34 +0200 | [diff] [blame] | 176 | TEST_ASSERT( ret >= 0 ); |
| 177 | |
| 178 | f = fopen( key_file, "r" ); |
| 179 | TEST_ASSERT( f != NULL ); |
| 180 | fread( check_buf, 1, sizeof( check_buf ) - 1, f ); |
| 181 | fclose( f ); |
| 182 | |
| 183 | TEST_ASSERT( strncmp( (char *) buf, (char *) check_buf, sizeof( buf ) ) == 0 ); |
| 184 | |
| 185 | pk_free( &key ); |
| 186 | } |
| 187 | /* END_CASE */ |