Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 1 | /* BEGIN_HEADER */ |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 2 | #include <polarssl/x509write.h> |
| 3 | #include <polarssl/x509.h> |
| 4 | #include <polarssl/pem.h> |
Paul Bakker | c70b982 | 2013-04-07 22:00:46 +0200 | [diff] [blame] | 5 | #include <polarssl/oid.h> |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 6 | /* END_HEADER */ |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 7 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 8 | /* BEGIN_DEPENDENCIES |
| 9 | * depends_on:POLARSSL_X509_WRITE_C:POLARSSL_BIGNUM_C |
| 10 | * END_DEPENDENCIES |
| 11 | */ |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 12 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 13 | /* BEGIN_CASE */ |
Paul Bakker | 82e2945 | 2013-08-25 11:01:31 +0200 | [diff] [blame] | 14 | void x509_csr_check( char *key_file, int md_type, |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 15 | char *cert_req_check_file ) |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 16 | { |
| 17 | rsa_context rsa; |
| 18 | pem_context pem; |
Paul Bakker | cd35803 | 2013-09-09 12:08:11 +0200 | [diff] [blame] | 19 | x509write_csr req; |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 20 | unsigned char *c; |
| 21 | unsigned char buf[4000]; |
| 22 | unsigned char check_buf[4000]; |
| 23 | int ret; |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame^] | 24 | size_t olen = sizeof( check_buf ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 25 | FILE *f; |
Paul Bakker | 2130796 | 2013-08-25 10:33:27 +0200 | [diff] [blame] | 26 | char *subject_name = "C=NL,O=PolarSSL,CN=PolarSSL Server 1"; |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 27 | |
| 28 | memset( &rsa, 0, sizeof(rsa_context) ); |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 29 | ret = x509parse_keyfile_rsa( &rsa, key_file, NULL ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 30 | TEST_ASSERT( ret == 0 ); |
| 31 | if( ret != 0 ) |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 32 | return; |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 33 | |
Paul Bakker | 82e2945 | 2013-08-25 11:01:31 +0200 | [diff] [blame] | 34 | x509write_csr_init( &req ); |
| 35 | x509write_csr_set_md_alg( &req, md_type ); |
| 36 | x509write_csr_set_rsa_key( &req, &rsa ); |
| 37 | TEST_ASSERT( x509write_csr_set_subject_name( &req, subject_name ) == 0 ); |
Paul Bakker | 8eabfc1 | 2013-08-25 10:18:25 +0200 | [diff] [blame] | 38 | |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame^] | 39 | ret = x509write_csr_der( &req, buf, sizeof( buf ) ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 40 | TEST_ASSERT( ret >= 0 ); |
| 41 | |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame^] | 42 | c = buf + sizeof( buf ) - ret; |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 43 | |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 44 | f = fopen( cert_req_check_file, "r" ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 45 | TEST_ASSERT( f != NULL ); |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame^] | 46 | fread( check_buf, 1, sizeof( check_buf ), f ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 47 | fclose( f ); |
| 48 | |
| 49 | pem_init( &pem ); |
| 50 | pem_read_buffer( &pem, "-----BEGIN CERTIFICATE REQUEST-----", "-----END CERTIFICATE REQUEST-----", check_buf, NULL, 0, &olen ); |
| 51 | |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 52 | TEST_ASSERT( pem.buflen == (size_t) ret ); |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame^] | 53 | TEST_ASSERT( memcmp( c, pem.buf, pem.buflen ) == 0 ); |
Paul Bakker | 58ef6ec | 2013-01-03 11:33:48 +0100 | [diff] [blame] | 54 | |
Paul Bakker | 82e2945 | 2013-08-25 11:01:31 +0200 | [diff] [blame] | 55 | x509write_csr_free( &req ); |
Paul Bakker | 58ef6ec | 2013-01-03 11:33:48 +0100 | [diff] [blame] | 56 | rsa_free( &rsa ); |
| 57 | pem_free( &pem ); |
Paul Bakker | 6d62050 | 2012-02-16 14:09:13 +0000 | [diff] [blame] | 58 | } |
Paul Bakker | 33b43f1 | 2013-08-20 11:48:36 +0200 | [diff] [blame] | 59 | /* END_CASE */ |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 60 | |
| 61 | /* BEGIN_CASE */ |
| 62 | void x509_crt_check( char *subject_key_file, char *subject_pwd, |
| 63 | char *subject_name, char *issuer_key_file, |
| 64 | char *issuer_pwd, char *issuer_name, |
| 65 | char *serial_str, char *not_before, char *not_after, |
| 66 | int md_type, char *cert_check_file ) |
| 67 | { |
| 68 | rsa_context subject_rsa, issuer_rsa; |
| 69 | pem_context pem; |
| 70 | x509write_cert crt; |
| 71 | unsigned char *c; |
| 72 | unsigned char buf[4000]; |
| 73 | unsigned char check_buf[5000]; |
| 74 | mpi serial; |
| 75 | int ret; |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame^] | 76 | size_t olen = sizeof( check_buf ); |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 77 | FILE *f; |
| 78 | |
| 79 | mpi_init( &serial ); |
| 80 | rsa_init( &subject_rsa, RSA_PKCS_V15, 0 ); |
| 81 | rsa_init( &issuer_rsa, RSA_PKCS_V15, 0 ); |
| 82 | |
| 83 | TEST_ASSERT( x509parse_keyfile_rsa( &subject_rsa, subject_key_file, |
| 84 | subject_pwd ) == 0 ); |
| 85 | TEST_ASSERT( x509parse_keyfile_rsa( &issuer_rsa, issuer_key_file, |
| 86 | issuer_pwd ) == 0 ); |
| 87 | TEST_ASSERT( mpi_read_string( &serial, 10, serial_str ) == 0 ); |
| 88 | |
| 89 | x509write_crt_init( &crt ); |
| 90 | x509write_crt_set_serial( &crt, &serial ); |
| 91 | TEST_ASSERT( x509write_crt_set_validity( &crt, not_before, |
| 92 | not_after ) == 0 ); |
| 93 | x509write_crt_set_md_alg( &crt, md_type ); |
| 94 | TEST_ASSERT( x509write_crt_set_issuer_name( &crt, issuer_name ) == 0 ); |
| 95 | TEST_ASSERT( x509write_crt_set_subject_name( &crt, subject_name ) == 0 ); |
| 96 | x509write_crt_set_subject_key( &crt, &subject_rsa ); |
| 97 | x509write_crt_set_issuer_key( &crt, &issuer_rsa ); |
| 98 | |
| 99 | TEST_ASSERT( x509write_crt_set_basic_constraints( &crt, 0, 0 ) == 0 ); |
| 100 | TEST_ASSERT( x509write_crt_set_subject_key_identifier( &crt ) == 0 ); |
| 101 | TEST_ASSERT( x509write_crt_set_authority_key_identifier( &crt ) == 0 ); |
| 102 | |
| 103 | ret = x509write_crt_der( &crt, buf, sizeof(buf) ); |
| 104 | TEST_ASSERT( ret >= 0 ); |
| 105 | |
Manuel Pégourié-Gonnard | 27d87fa | 2013-09-11 17:33:28 +0200 | [diff] [blame^] | 106 | c = buf + sizeof( buf ) - ret; |
Paul Bakker | 2397cf3 | 2013-09-08 15:58:15 +0200 | [diff] [blame] | 107 | |
| 108 | f = fopen( cert_check_file, "r" ); |
| 109 | TEST_ASSERT( f != NULL ); |
| 110 | TEST_ASSERT( fread( check_buf, 1, sizeof(check_buf), f ) < sizeof(check_buf) ); |
| 111 | fclose( f ); |
| 112 | |
| 113 | pem_init( &pem ); |
| 114 | TEST_ASSERT( pem_read_buffer( &pem, "-----BEGIN CERTIFICATE-----", "-----END CERTIFICATE-----", check_buf, NULL, 0, &olen ) >= 0 ); |
| 115 | |
| 116 | TEST_ASSERT( pem.buflen == (size_t) ret ); |
| 117 | TEST_ASSERT( memcmp( c, pem.buf, pem.buflen ) == 0 ); |
| 118 | |
| 119 | x509write_crt_free( &crt ); |
| 120 | rsa_free( &issuer_rsa ); |
| 121 | rsa_free( &subject_rsa ); |
| 122 | pem_free( &pem ); |
| 123 | mpi_free( &serial ); |
| 124 | } |
| 125 | /* END_CASE */ |