blob: a0c5f51013240637e7eaf4df75858f35b548633d [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/rsa.h"
3#include "mbedtls/md.h"
Paul Bakker33b43f12013-08-20 11:48:36 +02004/* END_HEADER */
Paul Bakker9dcc3222011-03-08 14:16:06 +00005
Paul Bakker33b43f12013-08-20 11:48:36 +02006/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02007 * depends_on:MBEDTLS_PKCS1_V21:MBEDTLS_RSA_C:MBEDTLS_SHA1_C
Paul Bakker33b43f12013-08-20 11:48:36 +02008 * END_DEPENDENCIES
9 */
Paul Bakker5690efc2011-05-26 13:16:06 +000010
Paul Bakker33b43f12013-08-20 11:48:36 +020011/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +010012void pkcs1_rsaes_oaep_encrypt( int mod, int radix_N, char * input_N,
13 int radix_E, char * input_E, int hash,
Azim Khan5fcca462018-06-29 11:05:32 +010014 data_t * message_str, data_t * rnd_buf,
Ronald Cronac6ae352020-06-26 14:33:03 +020015 data_t * result_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +000016{
Ron Eldor5b8f1202018-11-22 15:49:49 +020017 unsigned char output[256];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020018 mbedtls_rsa_context ctx;
Ronald Cron351f0ee2020-06-10 12:12:18 +020019 mbedtls_test_rnd_buf_info info;
Hanno Becker6326a6d2017-08-23 06:38:22 +010020 mbedtls_mpi N, E;
Paul Bakker9dcc3222011-03-08 14:16:06 +000021
Azim Khand30ca132017-06-09 04:32:58 +010022 info.buf = rnd_buf->x;
23 info.length = rnd_buf->len;
Paul Bakker9dcc3222011-03-08 14:16:06 +000024
Hanno Becker6326a6d2017-08-23 06:38:22 +010025 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020026 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Ron Eldor5b8f1202018-11-22 15:49:49 +020027 memset( output, 0x00, sizeof( output ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +000028
Hanno Becker6326a6d2017-08-23 06:38:22 +010029 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
30 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
31 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
32 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020033 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000034
Gilles Peskine85a6dd42018-10-15 16:32:42 +020035 if( message_str->len == 0 )
36 message_str->x = NULL;
Ronald Cron6c5bd7f2020-06-10 14:08:26 +020037 TEST_ASSERT( mbedtls_rsa_pkcs1_encrypt( &ctx,
38 &mbedtls_test_rnd_buffer_rand,
39 &info, MBEDTLS_RSA_PUBLIC,
40 message_str->len, message_str->x,
41 output ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +020042 if( result == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +000043 {
Ronald Cronac6ae352020-06-26 14:33:03 +020044 TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
45 ctx.len, result_str->len ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000046 }
Paul Bakker58ef6ec2013-01-03 11:33:48 +010047
Paul Bakkerbd51b262014-07-10 15:26:12 +020048exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +010049 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020050 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +000051}
Paul Bakker33b43f12013-08-20 11:48:36 +020052/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +000053
Paul Bakker33b43f12013-08-20 11:48:36 +020054/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +010055void pkcs1_rsaes_oaep_decrypt( int mod, int radix_P, char * input_P,
56 int radix_Q, char * input_Q, int radix_N,
57 char * input_N, int radix_E, char * input_E,
Ronald Cronac6ae352020-06-26 14:33:03 +020058 int hash, data_t * result_str,
Azim Khan5fcca462018-06-29 11:05:32 +010059 char * seed, data_t * message_str,
Azim Khand30ca132017-06-09 04:32:58 +010060 int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +000061{
Ron Eldor5b8f1202018-11-22 15:49:49 +020062 unsigned char output[64];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020063 mbedtls_rsa_context ctx;
Paul Bakkerf4a3f302011-04-24 15:53:29 +000064 size_t output_len;
Ronald Cron351f0ee2020-06-10 12:12:18 +020065 mbedtls_test_rnd_pseudo_info rnd_info;
Hanno Becker6326a6d2017-08-23 06:38:22 +010066 mbedtls_mpi N, P, Q, E;
Paul Bakkerdbd443d2013-08-16 13:38:47 +020067 ((void) seed);
Paul Bakker9dcc3222011-03-08 14:16:06 +000068
Hanno Becker6326a6d2017-08-23 06:38:22 +010069 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
70 mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
71
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020072 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Paul Bakker9dcc3222011-03-08 14:16:06 +000073
Ron Eldor5b8f1202018-11-22 15:49:49 +020074 memset( output, 0x00, sizeof( output ) );
Ronald Cron351f0ee2020-06-10 12:12:18 +020075 memset( &rnd_info, 0, sizeof( mbedtls_test_rnd_pseudo_info ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +000076
Hanno Becker6326a6d2017-08-23 06:38:22 +010077 TEST_ASSERT( mbedtls_mpi_read_string( &P, radix_P, input_P ) == 0 );
78 TEST_ASSERT( mbedtls_mpi_read_string( &Q, radix_Q, input_Q ) == 0 );
79 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
80 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Paul Bakker548957d2013-08-30 10:30:02 +020081
Hanno Becker6326a6d2017-08-23 06:38:22 +010082 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
83 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Hanno Becker7f25f852017-10-10 16:56:22 +010084 TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020085 TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000086
Ronald Cronac6ae352020-06-26 14:33:03 +020087 if( result_str->len == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +000088 {
Ronald Cron6c5bd7f2020-06-10 14:08:26 +020089 TEST_ASSERT( mbedtls_rsa_pkcs1_decrypt( &ctx,
90 &mbedtls_test_rnd_pseudo_rand,
91 &rnd_info,
92 MBEDTLS_RSA_PRIVATE,
93 &output_len, message_str->x,
94 NULL, 0 ) == result );
Gilles Peskine85a6dd42018-10-15 16:32:42 +020095 }
96 else
97 {
Ronald Cron6c5bd7f2020-06-10 14:08:26 +020098 TEST_ASSERT( mbedtls_rsa_pkcs1_decrypt( &ctx,
99 &mbedtls_test_rnd_pseudo_rand,
100 &rnd_info,
101 MBEDTLS_RSA_PRIVATE,
102 &output_len, message_str->x,
103 output,
Ron Eldor5b8f1202018-11-22 15:49:49 +0200104 sizeof( output ) ) == result );
Gilles Peskine85a6dd42018-10-15 16:32:42 +0200105 if( result == 0 )
106 {
Ronald Cronac6ae352020-06-26 14:33:03 +0200107 TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
Ronald Cron2dbba992020-06-10 11:42:32 +0200108 output_len,
Ronald Cronac6ae352020-06-26 14:33:03 +0200109 result_str->len ) == 0 );
Gilles Peskine85a6dd42018-10-15 16:32:42 +0200110 }
Paul Bakker9dcc3222011-03-08 14:16:06 +0000111 }
Paul Bakker6c591fa2011-05-05 11:49:20 +0000112
Paul Bakkerbd51b262014-07-10 15:26:12 +0200113exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100114 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
115 mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200116 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000117}
Paul Bakker33b43f12013-08-20 11:48:36 +0200118/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +0000119
Paul Bakker33b43f12013-08-20 11:48:36 +0200120/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100121void pkcs1_rsassa_pss_sign( int mod, int radix_P, char * input_P, int radix_Q,
122 char * input_Q, int radix_N, char * input_N,
123 int radix_E, char * input_E, int digest, int hash,
Azim Khan5fcca462018-06-29 11:05:32 +0100124 data_t * message_str, data_t * rnd_buf,
Ronald Cronac6ae352020-06-26 14:33:03 +0200125 data_t * result_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +0000126{
Ron Eldor5b8f1202018-11-22 15:49:49 +0200127 unsigned char hash_result[MBEDTLS_MD_MAX_SIZE];
128 unsigned char output[256];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200129 mbedtls_rsa_context ctx;
Ronald Cron351f0ee2020-06-10 12:12:18 +0200130 mbedtls_test_rnd_buf_info info;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100131 mbedtls_mpi N, P, Q, E;
Paul Bakker9dcc3222011-03-08 14:16:06 +0000132
Azim Khand30ca132017-06-09 04:32:58 +0100133 info.buf = rnd_buf->x;
134 info.length = rnd_buf->len;
Paul Bakker9dcc3222011-03-08 14:16:06 +0000135
Hanno Becker6326a6d2017-08-23 06:38:22 +0100136 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
137 mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200138 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000139
Ron Eldor5b8f1202018-11-22 15:49:49 +0200140 memset( hash_result, 0x00, sizeof( hash_result ) );
141 memset( output, 0x00, sizeof( output ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000142
Hanno Becker6326a6d2017-08-23 06:38:22 +0100143 TEST_ASSERT( mbedtls_mpi_read_string( &P, radix_P, input_P ) == 0 );
144 TEST_ASSERT( mbedtls_mpi_read_string( &Q, radix_Q, input_Q ) == 0 );
145 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
146 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000147
Hanno Becker6326a6d2017-08-23 06:38:22 +0100148 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
149 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Hanno Becker7f25f852017-10-10 16:56:22 +0100150 TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200151 TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000152
Paul Bakker9dcc3222011-03-08 14:16:06 +0000153
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200154 if( mbedtls_md_info_from_type( digest ) != NULL )
Azim Khand30ca132017-06-09 04:32:58 +0100155 TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( digest ), message_str->x, message_str->len, hash_result ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000156
Ronald Cron6c5bd7f2020-06-10 14:08:26 +0200157 TEST_ASSERT( mbedtls_rsa_pkcs1_sign( &ctx, &mbedtls_test_rnd_buffer_rand,
158 &info, MBEDTLS_RSA_PRIVATE, digest, 0,
159 hash_result, output ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +0200160 if( result == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +0000161 {
Cédric Meutera05cbec2020-04-25 15:02:34 +0200162 TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
163 ctx.len, result_str->len ) == 0 );
164 }
Paul Bakker9dcc3222011-03-08 14:16:06 +0000165
Cédric Meutera05cbec2020-04-25 15:02:34 +0200166 info.buf = rnd_buf->x;
167 info.length = rnd_buf->len;
168
169 TEST_ASSERT( mbedtls_rsa_rsassa_pss_sign_ext( &ctx, &mbedtls_test_rnd_buffer_rand,
170 &info, digest, 0, hash_result,
171 MBEDTLS_RSA_SALT_LEN_ANY, output ) == result );
172 if( result == 0 )
173 {
Ronald Cronac6ae352020-06-26 14:33:03 +0200174 TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
175 ctx.len, result_str->len ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000176 }
Paul Bakker6c591fa2011-05-05 11:49:20 +0000177
Paul Bakkerbd51b262014-07-10 15:26:12 +0200178exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100179 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
180 mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200181 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000182}
Paul Bakker33b43f12013-08-20 11:48:36 +0200183/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +0000184
Paul Bakker33b43f12013-08-20 11:48:36 +0200185/* BEGIN_CASE */
Cédric Meuter668a78d2020-04-30 11:57:04 +0200186void pkcs1_rsassa_pss_sign_ext( int mod, int radix_P, char * input_P, int radix_Q,
187 char * input_Q, int radix_N, char * input_N,
188 int radix_E, char * input_E, int digest, int hash,
189 data_t * message_str, data_t * rnd_buf,
190 data_t * result_str, int fixed_salt_length,
191 int result )
192{
193 unsigned char hash_result[MBEDTLS_MD_MAX_SIZE];
194 unsigned char output[512];
195 mbedtls_rsa_context ctx;
196 mbedtls_test_rnd_buf_info info;
197 mbedtls_mpi N, P, Q, E;
198
199 info.buf = rnd_buf->x;
200 info.length = rnd_buf->len;
201
202 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
203 mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
204 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
205
206 memset( hash_result, 0x00, sizeof( hash_result ) );
207 memset( output, 0x00, sizeof( output ) );
208
209 TEST_ASSERT( mbedtls_mpi_read_string( &P, radix_P, input_P ) == 0 );
210 TEST_ASSERT( mbedtls_mpi_read_string( &Q, radix_Q, input_Q ) == 0 );
211 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
212 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
213
214 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
215 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
216 TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
217 TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
218
219
220 if( mbedtls_md_info_from_type( digest ) != NULL )
221 TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( digest ), message_str->x, message_str->len, hash_result ) == 0 );
222
223 TEST_ASSERT( mbedtls_rsa_rsassa_pss_sign_ext( &ctx, &mbedtls_test_rnd_buffer_rand, &info, digest,
224 0, hash_result, fixed_salt_length, output ) == result );
225 if( result == 0 )
226 {
227 TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
228 ctx.len, result_str->len ) == 0 );
229 }
230
231exit:
232 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
233 mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
234 mbedtls_rsa_free( &ctx );
235}
236/* END_CASE */
237
238/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100239void pkcs1_rsassa_pss_verify( int mod, int radix_N, char * input_N,
240 int radix_E, char * input_E, int digest,
Azim Khan5fcca462018-06-29 11:05:32 +0100241 int hash, data_t * message_str, char * salt,
242 data_t * result_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +0000243{
Ron Eldor5b8f1202018-11-22 15:49:49 +0200244 unsigned char hash_result[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200245 mbedtls_rsa_context ctx;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100246 mbedtls_mpi N, E;
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200247 ((void) salt);
Paul Bakker9dcc3222011-03-08 14:16:06 +0000248
Hanno Becker6326a6d2017-08-23 06:38:22 +0100249 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200250 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Ron Eldor5b8f1202018-11-22 15:49:49 +0200251 memset( hash_result, 0x00, sizeof( hash_result ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000252
Hanno Becker6326a6d2017-08-23 06:38:22 +0100253 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
254 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000255
Hanno Becker6326a6d2017-08-23 06:38:22 +0100256 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
257 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200258 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000259
Paul Bakker9dcc3222011-03-08 14:16:06 +0000260
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200261 if( mbedtls_md_info_from_type( digest ) != NULL )
Azim Khand30ca132017-06-09 04:32:58 +0100262 TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( digest ), message_str->x, message_str->len, hash_result ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000263
Azim Khand30ca132017-06-09 04:32:58 +0100264 TEST_ASSERT( mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC, digest, 0, hash_result, result_str->x ) == result );
Paul Bakker58ef6ec2013-01-03 11:33:48 +0100265
Paul Bakkerbd51b262014-07-10 15:26:12 +0200266exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100267 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200268 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000269}
Paul Bakker33b43f12013-08-20 11:48:36 +0200270/* END_CASE */
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200271
272/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100273void pkcs1_rsassa_pss_verify_ext( int mod, int radix_N, char * input_N,
274 int radix_E, char * input_E,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200275 int msg_digest_id, int ctx_hash,
276 int mgf_hash, int salt_len,
Azim Khan5fcca462018-06-29 11:05:32 +0100277 data_t * message_str,
278 data_t * result_str, int result_simple,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200279 int result_full )
280{
Ron Eldor5b8f1202018-11-22 15:49:49 +0200281 unsigned char hash_result[MBEDTLS_MD_MAX_SIZE];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200282 mbedtls_rsa_context ctx;
Azim Khanf1aaec92017-05-30 14:23:15 +0100283 size_t hash_len;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100284 mbedtls_mpi N, E;
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200285
Hanno Becker6326a6d2017-08-23 06:38:22 +0100286 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200287 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, ctx_hash );
Ron Eldor5b8f1202018-11-22 15:49:49 +0200288 memset( hash_result, 0x00, sizeof( hash_result ) );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200289
Hanno Becker6326a6d2017-08-23 06:38:22 +0100290 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
291 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200292
Hanno Becker6326a6d2017-08-23 06:38:22 +0100293 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
294 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200295 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200296
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200297
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200298 if( msg_digest_id != MBEDTLS_MD_NONE )
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200299 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200300 TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( msg_digest_id ),
Azim Khand30ca132017-06-09 04:32:58 +0100301 message_str->x, message_str->len, hash_result ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200302 hash_len = 0;
303 }
304 else
305 {
Azim Khand30ca132017-06-09 04:32:58 +0100306 memcpy( hash_result, message_str->x, message_str->len );
307 hash_len = message_str->len;
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200308 }
309
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200310 TEST_ASSERT( mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200311 msg_digest_id, hash_len, hash_result,
Azim Khand30ca132017-06-09 04:32:58 +0100312 result_str->x ) == result_simple );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200313
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200314 TEST_ASSERT( mbedtls_rsa_rsassa_pss_verify_ext( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200315 msg_digest_id, hash_len, hash_result,
316 mgf_hash, salt_len,
Azim Khand30ca132017-06-09 04:32:58 +0100317 result_str->x ) == result_full );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200318
Paul Bakkerbd51b262014-07-10 15:26:12 +0200319exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100320 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200321 mbedtls_rsa_free( &ctx );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200322}
323/* END_CASE */