blob: 1d463645255d23e9f6a41d983b2cdd66d030a53b [file] [log] [blame]
Paul Elliottd6635432021-11-18 22:35:48 +00001/* BEGIN_HEADER */
2#include "mbedtls/pkcs12.h"
Paul Elliott6e7deb12021-12-03 18:55:31 +00003#include "common.h"
Paul Elliottd6635432021-11-18 22:35:48 +00004
Gilles Peskine449bd832023-01-11 14:50:10 +01005typedef enum {
6 USE_NULL_INPUT = 0,
7 USE_GIVEN_INPUT = 1,
Paul Elliottd6635432021-11-18 22:35:48 +00008} input_usage_method_t;
9
10/* END_HEADER */
11
12/* BEGIN_DEPENDENCIES
Paul Elliott3584ae42021-11-30 16:21:27 +000013 * depends_on:MBEDTLS_PKCS12_C
Paul Elliottd6635432021-11-18 22:35:48 +000014 * END_DEPENDENCIES
15 */
16
Waleed Elmelegy8317e912023-09-07 15:46:58 +010017/* BEGIN_CASE */
Gilles Peskine449bd832023-01-11 14:50:10 +010018void pkcs12_derive_key(int md_type, int key_size_arg,
19 data_t *password_arg, int password_usage,
20 data_t *salt_arg, int salt_usage,
21 int iterations,
22 data_t *expected_output, int expected_status)
Paul Elliottd6635432021-11-18 22:35:48 +000023
24{
Gilles Peskine449bd832023-01-11 14:50:10 +010025 unsigned char *output_data = NULL;
Paul Elliottd6635432021-11-18 22:35:48 +000026
Gilles Peskine449bd832023-01-11 14:50:10 +010027 unsigned char *password = NULL;
28 size_t password_len = 0;
29 unsigned char *salt = NULL;
30 size_t salt_len = 0;
31 size_t key_size = key_size_arg;
Paul Elliottd6635432021-11-18 22:35:48 +000032
Manuel Pégourié-Gonnardbe97afe2023-03-16 10:00:54 +010033 MD_PSA_INIT();
34
Gilles Peskine449bd832023-01-11 14:50:10 +010035 if (password_usage == USE_GIVEN_INPUT) {
36 password = password_arg->x;
37 }
Paul Elliott4768a302021-11-30 16:39:51 +000038
Gilles Peskine449bd832023-01-11 14:50:10 +010039 password_len = password_arg->len;
Paul Elliottd6635432021-11-18 22:35:48 +000040
Gilles Peskine449bd832023-01-11 14:50:10 +010041 if (salt_usage == USE_GIVEN_INPUT) {
42 salt = salt_arg->x;
43 }
Paul Elliott4768a302021-11-30 16:39:51 +000044
Gilles Peskine449bd832023-01-11 14:50:10 +010045 salt_len = salt_arg->len;
Paul Elliottd6635432021-11-18 22:35:48 +000046
Waleed Elmelegy8317e912023-09-07 15:46:58 +010047 TEST_CALLOC(output_data, key_size);
Paul Elliottd6635432021-11-18 22:35:48 +000048
Gilles Peskine449bd832023-01-11 14:50:10 +010049 int ret = mbedtls_pkcs12_derivation(output_data,
Gilles Peskinea844b4b2022-09-15 21:05:04 +020050 key_size,
51 password,
52 password_len,
53 salt,
54 salt_len,
55 md_type,
56 MBEDTLS_PKCS12_DERIVE_KEY,
Gilles Peskine449bd832023-01-11 14:50:10 +010057 iterations);
Paul Elliottd6635432021-11-18 22:35:48 +000058
Gilles Peskine449bd832023-01-11 14:50:10 +010059 TEST_EQUAL(ret, expected_status);
Paul Elliottd6635432021-11-18 22:35:48 +000060
Gilles Peskine449bd832023-01-11 14:50:10 +010061 if (expected_status == 0) {
Waleed Elmelegy75b9eb32023-09-07 17:02:37 +010062 TEST_MEMORY_COMPARE(expected_output->x, expected_output->len,
Waleed Elmelegy09601702023-09-07 17:48:40 +010063 output_data, key_size);
Gilles Peskine449bd832023-01-11 14:50:10 +010064 }
Paul Elliott6e7deb12021-12-03 18:55:31 +000065
Paul Elliottd6635432021-11-18 22:35:48 +000066exit:
Gilles Peskine449bd832023-01-11 14:50:10 +010067 mbedtls_free(output_data);
Manuel Pégourié-Gonnardbe97afe2023-03-16 10:00:54 +010068 MD_PSA_DONE();
Paul Elliottd6635432021-11-18 22:35:48 +000069}
70/* END_CASE */
Waleed Elmelegy255db802023-09-04 15:11:22 +010071
Waleed Elmelegy8317e912023-09-07 15:46:58 +010072/* BEGIN_CASE */
Waleed Elmelegy15de8092023-09-05 15:51:48 +010073void pkcs12_pbe_encrypt(int cipher, int md, data_t *params_hex, data_t *pw,
Waleed Elmelegy255db802023-09-04 15:11:22 +010074 data_t *data, int ref_ret, data_t *ref_out)
75{
76 int my_ret;
Waleed Elmelegy15de8092023-09-05 15:51:48 +010077 mbedtls_asn1_buf pbe_params;
Waleed Elmelegy255db802023-09-04 15:11:22 +010078 unsigned char *my_out = NULL;
Waleed Elmelegy15de8092023-09-05 15:51:48 +010079 mbedtls_cipher_type_t cipher_alg = (mbedtls_cipher_type_t) cipher;
80 mbedtls_md_type_t md_alg = (mbedtls_md_type_t) md;
81 size_t block_size;
Waleed Elmelegy255db802023-09-04 15:11:22 +010082
83 MD_PSA_INIT();
84
Waleed Elmelegy15de8092023-09-05 15:51:48 +010085 block_size = mbedtls_cipher_info_get_block_size(mbedtls_cipher_info_from_type(cipher_alg));
Waleed Elmelegy8317e912023-09-07 15:46:58 +010086 TEST_CALLOC(my_out, ((data->len/block_size) + 1) * block_size);
Waleed Elmelegy255db802023-09-04 15:11:22 +010087
Waleed Elmelegy15de8092023-09-05 15:51:48 +010088 pbe_params.tag = params_hex->x[0];
89 pbe_params.len = params_hex->x[1];
90 pbe_params.p = params_hex->x + 2;
Waleed Elmelegy255db802023-09-04 15:11:22 +010091
92 my_ret = mbedtls_pkcs12_pbe(&pbe_params, MBEDTLS_PKCS12_PBE_ENCRYPT, cipher_alg,
93 md_alg, pw->x, pw->len, data->x, data->len, my_out);
94 TEST_EQUAL(my_ret, ref_ret);
95 if (ref_ret == 0) {
96 ASSERT_COMPARE(my_out, ref_out->len,
97 ref_out->x, ref_out->len);
98 }
99
100exit:
101 mbedtls_free(my_out);
102 MD_PSA_DONE();
103}
104/* END_CASE */
105
Waleed Elmelegy8317e912023-09-07 15:46:58 +0100106/* BEGIN_CASE */
Waleed Elmelegy15de8092023-09-05 15:51:48 +0100107void pkcs12_pbe_decrypt(int cipher, int md, data_t *params_hex, data_t *pw,
Waleed Elmelegy255db802023-09-04 15:11:22 +0100108 data_t *data, int ref_ret, data_t *ref_out)
109{
110 int my_ret;
Waleed Elmelegy15de8092023-09-05 15:51:48 +0100111 mbedtls_asn1_buf pbe_params;
Waleed Elmelegy255db802023-09-04 15:11:22 +0100112 unsigned char *my_out = NULL;
Waleed Elmelegy15de8092023-09-05 15:51:48 +0100113 mbedtls_cipher_type_t cipher_alg = (mbedtls_cipher_type_t) cipher;
114 mbedtls_md_type_t md_alg = (mbedtls_md_type_t) md;
Waleed Elmelegy255db802023-09-04 15:11:22 +0100115
116 MD_PSA_INIT();
117
Waleed Elmelegy8317e912023-09-07 15:46:58 +0100118 TEST_CALLOC(my_out, data->len);
Waleed Elmelegy255db802023-09-04 15:11:22 +0100119
Waleed Elmelegy15de8092023-09-05 15:51:48 +0100120 pbe_params.tag = params_hex->x[0];
121 pbe_params.len = params_hex->x[1];
122 pbe_params.p = params_hex->x + 2;
Waleed Elmelegy255db802023-09-04 15:11:22 +0100123
124 my_ret = mbedtls_pkcs12_pbe(&pbe_params, MBEDTLS_PKCS12_PBE_DECRYPT, cipher_alg,
125 md_alg, pw->x, pw->len, data->x, data->len, my_out);
126 TEST_EQUAL(my_ret, ref_ret);
127 if (ref_ret == 0) {
128 ASSERT_COMPARE(my_out, ref_out->len,
129 ref_out->x, ref_out->len);
130 }
131
132exit:
133 mbedtls_free(my_out);
134 MD_PSA_DONE();
135}
136/* END_CASE */