blob: c3ac92f00584b05bd40cf3b5e9e6e564eb108410 [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/rsa.h"
3#include "mbedtls/md.h"
Paul Bakker33b43f12013-08-20 11:48:36 +02004/* END_HEADER */
Paul Bakker9dcc3222011-03-08 14:16:06 +00005
Paul Bakker33b43f12013-08-20 11:48:36 +02006/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02007 * depends_on:MBEDTLS_PKCS1_V21:MBEDTLS_RSA_C:MBEDTLS_SHA1_C
Paul Bakker33b43f12013-08-20 11:48:36 +02008 * END_DEPENDENCIES
9 */
Paul Bakker5690efc2011-05-26 13:16:06 +000010
Paul Bakker33b43f12013-08-20 11:48:36 +020011/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +010012void pkcs1_rsaes_oaep_encrypt( int mod, int radix_N, char * input_N,
13 int radix_E, char * input_E, int hash,
Azim Khan5fcca462018-06-29 11:05:32 +010014 data_t * message_str, data_t * rnd_buf,
15 data_t * result_hex_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +000016{
Ron Eldor5b8f1202018-11-22 15:49:49 +020017 unsigned char output[256];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020018 mbedtls_rsa_context ctx;
Paul Bakker4cce2bb2011-03-13 16:56:35 +000019 rnd_buf_info info;
Hanno Becker6326a6d2017-08-23 06:38:22 +010020 mbedtls_mpi N, E;
Paul Bakker9dcc3222011-03-08 14:16:06 +000021
Azim Khand30ca132017-06-09 04:32:58 +010022 info.buf = rnd_buf->x;
23 info.length = rnd_buf->len;
Paul Bakker9dcc3222011-03-08 14:16:06 +000024
Hanno Becker6326a6d2017-08-23 06:38:22 +010025 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020026 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Ron Eldor5b8f1202018-11-22 15:49:49 +020027 memset( output, 0x00, sizeof( output ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +000028
Hanno Becker6326a6d2017-08-23 06:38:22 +010029 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
30 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
31 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
32 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020033 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000034
Gilles Peskine85a6dd42018-10-15 16:32:42 +020035 if( message_str->len == 0 )
36 message_str->x = NULL;
Azim Khand30ca132017-06-09 04:32:58 +010037 TEST_ASSERT( mbedtls_rsa_pkcs1_encrypt( &ctx, &rnd_buffer_rand, &info, MBEDTLS_RSA_PUBLIC, message_str->len, message_str->x, output ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +020038 if( result == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +000039 {
Ronald Cronde70b162020-06-10 11:03:08 +020040 TEST_ASSERT( mbedtls_test_hexcmp( output, result_hex_str->x, ctx.len, result_hex_str->len ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000041 }
Paul Bakker58ef6ec2013-01-03 11:33:48 +010042
Paul Bakkerbd51b262014-07-10 15:26:12 +020043exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +010044 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020045 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +000046}
Paul Bakker33b43f12013-08-20 11:48:36 +020047/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +000048
Paul Bakker33b43f12013-08-20 11:48:36 +020049/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +010050void pkcs1_rsaes_oaep_decrypt( int mod, int radix_P, char * input_P,
51 int radix_Q, char * input_Q, int radix_N,
52 char * input_N, int radix_E, char * input_E,
Azim Khan5fcca462018-06-29 11:05:32 +010053 int hash, data_t * result_hex_str,
54 char * seed, data_t * message_str,
Azim Khand30ca132017-06-09 04:32:58 +010055 int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +000056{
Ron Eldor5b8f1202018-11-22 15:49:49 +020057 unsigned char output[64];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020058 mbedtls_rsa_context ctx;
Paul Bakkerf4a3f302011-04-24 15:53:29 +000059 size_t output_len;
Paul Bakker548957d2013-08-30 10:30:02 +020060 rnd_pseudo_info rnd_info;
Hanno Becker6326a6d2017-08-23 06:38:22 +010061 mbedtls_mpi N, P, Q, E;
Paul Bakkerdbd443d2013-08-16 13:38:47 +020062 ((void) seed);
Paul Bakker9dcc3222011-03-08 14:16:06 +000063
Hanno Becker6326a6d2017-08-23 06:38:22 +010064 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
65 mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
66
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020067 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Paul Bakker9dcc3222011-03-08 14:16:06 +000068
Ron Eldor5b8f1202018-11-22 15:49:49 +020069 memset( output, 0x00, sizeof( output ) );
Paul Bakker548957d2013-08-30 10:30:02 +020070 memset( &rnd_info, 0, sizeof( rnd_pseudo_info ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +000071
Hanno Becker6326a6d2017-08-23 06:38:22 +010072 TEST_ASSERT( mbedtls_mpi_read_string( &P, radix_P, input_P ) == 0 );
73 TEST_ASSERT( mbedtls_mpi_read_string( &Q, radix_Q, input_Q ) == 0 );
74 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
75 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Paul Bakker548957d2013-08-30 10:30:02 +020076
Hanno Becker6326a6d2017-08-23 06:38:22 +010077 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
78 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Hanno Becker7f25f852017-10-10 16:56:22 +010079 TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020080 TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000081
Gilles Peskine85a6dd42018-10-15 16:32:42 +020082 if( result_hex_str->len == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +000083 {
Ron Eldor5b8f1202018-11-22 15:49:49 +020084 TEST_ASSERT( mbedtls_rsa_pkcs1_decrypt( &ctx, &rnd_pseudo_rand, &rnd_info,
85 MBEDTLS_RSA_PRIVATE, &output_len,
86 message_str->x, NULL, 0 ) == result );
Gilles Peskine85a6dd42018-10-15 16:32:42 +020087 }
88 else
89 {
Ron Eldor5b8f1202018-11-22 15:49:49 +020090 TEST_ASSERT( mbedtls_rsa_pkcs1_decrypt( &ctx, &rnd_pseudo_rand, &rnd_info,
91 MBEDTLS_RSA_PRIVATE, &output_len,
92 message_str->x, output,
93 sizeof( output ) ) == result );
Gilles Peskine85a6dd42018-10-15 16:32:42 +020094 if( result == 0 )
95 {
Ronald Cronde70b162020-06-10 11:03:08 +020096 TEST_ASSERT( mbedtls_test_hexcmp( output, result_hex_str->x, output_len, result_hex_str->len ) == 0 );
Gilles Peskine85a6dd42018-10-15 16:32:42 +020097 }
Paul Bakker9dcc3222011-03-08 14:16:06 +000098 }
Paul Bakker6c591fa2011-05-05 11:49:20 +000099
Paul Bakkerbd51b262014-07-10 15:26:12 +0200100exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100101 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
102 mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200103 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000104}
Paul Bakker33b43f12013-08-20 11:48:36 +0200105/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +0000106
Paul Bakker33b43f12013-08-20 11:48:36 +0200107/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100108void pkcs1_rsassa_pss_sign( int mod, int radix_P, char * input_P, int radix_Q,
109 char * input_Q, int radix_N, char * input_N,
110 int radix_E, char * input_E, int digest, int hash,
Azim Khan5fcca462018-06-29 11:05:32 +0100111 data_t * message_str, data_t * rnd_buf,
112 data_t * result_hex_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +0000113{
Ron Eldor5b8f1202018-11-22 15:49:49 +0200114 unsigned char hash_result[MBEDTLS_MD_MAX_SIZE];
115 unsigned char output[256];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200116 mbedtls_rsa_context ctx;
Paul Bakker4cce2bb2011-03-13 16:56:35 +0000117 rnd_buf_info info;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100118 mbedtls_mpi N, P, Q, E;
Paul Bakker9dcc3222011-03-08 14:16:06 +0000119
Azim Khand30ca132017-06-09 04:32:58 +0100120 info.buf = rnd_buf->x;
121 info.length = rnd_buf->len;
Paul Bakker9dcc3222011-03-08 14:16:06 +0000122
Hanno Becker6326a6d2017-08-23 06:38:22 +0100123 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
124 mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200125 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000126
Ron Eldor5b8f1202018-11-22 15:49:49 +0200127 memset( hash_result, 0x00, sizeof( hash_result ) );
128 memset( output, 0x00, sizeof( output ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000129
Hanno Becker6326a6d2017-08-23 06:38:22 +0100130 TEST_ASSERT( mbedtls_mpi_read_string( &P, radix_P, input_P ) == 0 );
131 TEST_ASSERT( mbedtls_mpi_read_string( &Q, radix_Q, input_Q ) == 0 );
132 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
133 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000134
Hanno Becker6326a6d2017-08-23 06:38:22 +0100135 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
136 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Hanno Becker7f25f852017-10-10 16:56:22 +0100137 TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200138 TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000139
Paul Bakker9dcc3222011-03-08 14:16:06 +0000140
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200141 if( mbedtls_md_info_from_type( digest ) != NULL )
Azim Khand30ca132017-06-09 04:32:58 +0100142 TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( digest ), message_str->x, message_str->len, hash_result ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000143
Hanno Becker6326a6d2017-08-23 06:38:22 +0100144 TEST_ASSERT( mbedtls_rsa_pkcs1_sign( &ctx, &rnd_buffer_rand, &info, MBEDTLS_RSA_PRIVATE,
145 digest, 0, hash_result, output ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +0200146 if( result == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +0000147 {
Paul Bakker9dcc3222011-03-08 14:16:06 +0000148
Ronald Cronde70b162020-06-10 11:03:08 +0200149 TEST_ASSERT( mbedtls_test_hexcmp( output, result_hex_str->x, ctx.len, result_hex_str->len ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000150 }
Paul Bakker6c591fa2011-05-05 11:49:20 +0000151
Paul Bakkerbd51b262014-07-10 15:26:12 +0200152exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100153 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
154 mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200155 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000156}
Paul Bakker33b43f12013-08-20 11:48:36 +0200157/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +0000158
Paul Bakker33b43f12013-08-20 11:48:36 +0200159/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100160void pkcs1_rsassa_pss_verify( int mod, int radix_N, char * input_N,
161 int radix_E, char * input_E, int digest,
Azim Khan5fcca462018-06-29 11:05:32 +0100162 int hash, data_t * message_str, char * salt,
163 data_t * result_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +0000164{
Ron Eldor5b8f1202018-11-22 15:49:49 +0200165 unsigned char hash_result[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200166 mbedtls_rsa_context ctx;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100167 mbedtls_mpi N, E;
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200168 ((void) salt);
Paul Bakker9dcc3222011-03-08 14:16:06 +0000169
Hanno Becker6326a6d2017-08-23 06:38:22 +0100170 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200171 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Ron Eldor5b8f1202018-11-22 15:49:49 +0200172 memset( hash_result, 0x00, sizeof( hash_result ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000173
Hanno Becker6326a6d2017-08-23 06:38:22 +0100174 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
175 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000176
Hanno Becker6326a6d2017-08-23 06:38:22 +0100177 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
178 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200179 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000180
Paul Bakker9dcc3222011-03-08 14:16:06 +0000181
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200182 if( mbedtls_md_info_from_type( digest ) != NULL )
Azim Khand30ca132017-06-09 04:32:58 +0100183 TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( digest ), message_str->x, message_str->len, hash_result ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000184
Azim Khand30ca132017-06-09 04:32:58 +0100185 TEST_ASSERT( mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC, digest, 0, hash_result, result_str->x ) == result );
Paul Bakker58ef6ec2013-01-03 11:33:48 +0100186
Paul Bakkerbd51b262014-07-10 15:26:12 +0200187exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100188 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200189 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000190}
Paul Bakker33b43f12013-08-20 11:48:36 +0200191/* END_CASE */
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200192
193/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100194void pkcs1_rsassa_pss_verify_ext( int mod, int radix_N, char * input_N,
195 int radix_E, char * input_E,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200196 int msg_digest_id, int ctx_hash,
197 int mgf_hash, int salt_len,
Azim Khan5fcca462018-06-29 11:05:32 +0100198 data_t * message_str,
199 data_t * result_str, int result_simple,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200200 int result_full )
201{
Ron Eldor5b8f1202018-11-22 15:49:49 +0200202 unsigned char hash_result[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200203 mbedtls_rsa_context ctx;
Azim Khanf1aaec92017-05-30 14:23:15 +0100204 size_t hash_len;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100205 mbedtls_mpi N, E;
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200206
Hanno Becker6326a6d2017-08-23 06:38:22 +0100207 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200208 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, ctx_hash );
Ron Eldor5b8f1202018-11-22 15:49:49 +0200209 memset( hash_result, 0x00, sizeof( hash_result ) );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200210
Hanno Becker6326a6d2017-08-23 06:38:22 +0100211 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
212 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200213
Hanno Becker6326a6d2017-08-23 06:38:22 +0100214 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
215 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200216 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200217
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200218
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200219 if( msg_digest_id != MBEDTLS_MD_NONE )
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200220 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200221 TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( msg_digest_id ),
Azim Khand30ca132017-06-09 04:32:58 +0100222 message_str->x, message_str->len, hash_result ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200223 hash_len = 0;
224 }
225 else
226 {
Azim Khand30ca132017-06-09 04:32:58 +0100227 memcpy( hash_result, message_str->x, message_str->len );
228 hash_len = message_str->len;
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200229 }
230
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200231 TEST_ASSERT( mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200232 msg_digest_id, hash_len, hash_result,
Azim Khand30ca132017-06-09 04:32:58 +0100233 result_str->x ) == result_simple );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200234
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200235 TEST_ASSERT( mbedtls_rsa_rsassa_pss_verify_ext( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200236 msg_digest_id, hash_len, hash_result,
237 mgf_hash, salt_len,
Azim Khand30ca132017-06-09 04:32:58 +0100238 result_str->x ) == result_full );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200239
Paul Bakkerbd51b262014-07-10 15:26:12 +0200240exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100241 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200242 mbedtls_rsa_free( &ctx );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200243}
244/* END_CASE */