blob: a9635e17d13576dc7998188aa8d5e2643e3cc827 [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/rsa.h"
3#include "mbedtls/md.h"
Paul Bakker33b43f12013-08-20 11:48:36 +02004/* END_HEADER */
Paul Bakker9dcc3222011-03-08 14:16:06 +00005
Paul Bakker33b43f12013-08-20 11:48:36 +02006/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +02007 * depends_on:MBEDTLS_PKCS1_V21:MBEDTLS_RSA_C:MBEDTLS_SHA1_C
Paul Bakker33b43f12013-08-20 11:48:36 +02008 * END_DEPENDENCIES
9 */
Paul Bakker5690efc2011-05-26 13:16:06 +000010
Paul Bakker33b43f12013-08-20 11:48:36 +020011/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +010012void pkcs1_rsaes_oaep_encrypt( int mod, int radix_N, char * input_N,
13 int radix_E, char * input_E, int hash,
Azim Khan5fcca462018-06-29 11:05:32 +010014 data_t * message_str, data_t * rnd_buf,
15 data_t * result_hex_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +000016{
Paul Bakker9dcc3222011-03-08 14:16:06 +000017 unsigned char output[1000];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020018 mbedtls_rsa_context ctx;
Paul Bakker4cce2bb2011-03-13 16:56:35 +000019 rnd_buf_info info;
Hanno Becker6326a6d2017-08-23 06:38:22 +010020 mbedtls_mpi N, E;
Paul Bakker9dcc3222011-03-08 14:16:06 +000021
Azim Khand30ca132017-06-09 04:32:58 +010022 info.buf = rnd_buf->x;
23 info.length = rnd_buf->len;
Paul Bakker9dcc3222011-03-08 14:16:06 +000024
Hanno Becker6326a6d2017-08-23 06:38:22 +010025 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020026 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Paul Bakker9dcc3222011-03-08 14:16:06 +000027 memset( output, 0x00, 1000 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000028
Hanno Becker6326a6d2017-08-23 06:38:22 +010029 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
30 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
31 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
32 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020033 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000034
Paul Bakker9dcc3222011-03-08 14:16:06 +000035
Azim Khand30ca132017-06-09 04:32:58 +010036 TEST_ASSERT( mbedtls_rsa_pkcs1_encrypt( &ctx, &rnd_buffer_rand, &info, MBEDTLS_RSA_PUBLIC, message_str->len, message_str->x, output ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +020037 if( result == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +000038 {
Paul Bakker9dcc3222011-03-08 14:16:06 +000039
Azim Khand30ca132017-06-09 04:32:58 +010040 TEST_ASSERT( hexcmp( output, result_hex_str->x, ctx.len, result_hex_str->len ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000041 }
Paul Bakker58ef6ec2013-01-03 11:33:48 +010042
Paul Bakkerbd51b262014-07-10 15:26:12 +020043exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +010044 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020045 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +000046}
Paul Bakker33b43f12013-08-20 11:48:36 +020047/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +000048
Paul Bakker33b43f12013-08-20 11:48:36 +020049/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +010050void pkcs1_rsaes_oaep_decrypt( int mod, int radix_P, char * input_P,
51 int radix_Q, char * input_Q, int radix_N,
52 char * input_N, int radix_E, char * input_E,
Azim Khan5fcca462018-06-29 11:05:32 +010053 int hash, data_t * result_hex_str,
54 char * seed, data_t * message_str,
Azim Khand30ca132017-06-09 04:32:58 +010055 int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +000056{
Paul Bakker9dcc3222011-03-08 14:16:06 +000057 unsigned char output[1000];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020058 mbedtls_rsa_context ctx;
Paul Bakkerf4a3f302011-04-24 15:53:29 +000059 size_t output_len;
Paul Bakker548957d2013-08-30 10:30:02 +020060 rnd_pseudo_info rnd_info;
Hanno Becker6326a6d2017-08-23 06:38:22 +010061 mbedtls_mpi N, P, Q, E;
Paul Bakkerdbd443d2013-08-16 13:38:47 +020062 ((void) seed);
Paul Bakker9dcc3222011-03-08 14:16:06 +000063
Hanno Becker6326a6d2017-08-23 06:38:22 +010064 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
65 mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
66
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020067 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Paul Bakker9dcc3222011-03-08 14:16:06 +000068
Paul Bakker9dcc3222011-03-08 14:16:06 +000069 memset( output, 0x00, 1000 );
Paul Bakker548957d2013-08-30 10:30:02 +020070 memset( &rnd_info, 0, sizeof( rnd_pseudo_info ) );
Paul Bakker9dcc3222011-03-08 14:16:06 +000071
Hanno Becker6326a6d2017-08-23 06:38:22 +010072 TEST_ASSERT( mbedtls_mpi_read_string( &P, radix_P, input_P ) == 0 );
73 TEST_ASSERT( mbedtls_mpi_read_string( &Q, radix_Q, input_Q ) == 0 );
74 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
75 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Paul Bakker548957d2013-08-30 10:30:02 +020076
Hanno Becker6326a6d2017-08-23 06:38:22 +010077 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
78 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Hanno Becker7f25f852017-10-10 16:56:22 +010079 TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020080 TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000081
Paul Bakker9dcc3222011-03-08 14:16:06 +000082
Azim Khand30ca132017-06-09 04:32:58 +010083 TEST_ASSERT( mbedtls_rsa_pkcs1_decrypt( &ctx, &rnd_pseudo_rand, &rnd_info, MBEDTLS_RSA_PRIVATE, &output_len, message_str->x, output, 1000 ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +020084 if( result == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +000085 {
Paul Bakker9dcc3222011-03-08 14:16:06 +000086
Azim Khand30ca132017-06-09 04:32:58 +010087 TEST_ASSERT( hexcmp( output, result_hex_str->x, output_len, result_hex_str->len ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +000088 }
Paul Bakker6c591fa2011-05-05 11:49:20 +000089
Paul Bakkerbd51b262014-07-10 15:26:12 +020090exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +010091 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
92 mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020093 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +000094}
Paul Bakker33b43f12013-08-20 11:48:36 +020095/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +000096
Paul Bakker33b43f12013-08-20 11:48:36 +020097/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +010098void pkcs1_rsassa_pss_sign( int mod, int radix_P, char * input_P, int radix_Q,
99 char * input_Q, int radix_N, char * input_N,
100 int radix_E, char * input_E, int digest, int hash,
Azim Khan5fcca462018-06-29 11:05:32 +0100101 data_t * message_str, data_t * rnd_buf,
102 data_t * result_hex_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +0000103{
Paul Bakker9dcc3222011-03-08 14:16:06 +0000104 unsigned char hash_result[1000];
105 unsigned char output[1000];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200106 mbedtls_rsa_context ctx;
Paul Bakker4cce2bb2011-03-13 16:56:35 +0000107 rnd_buf_info info;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100108 mbedtls_mpi N, P, Q, E;
Paul Bakker9dcc3222011-03-08 14:16:06 +0000109
Azim Khand30ca132017-06-09 04:32:58 +0100110 info.buf = rnd_buf->x;
111 info.length = rnd_buf->len;
Paul Bakker9dcc3222011-03-08 14:16:06 +0000112
Hanno Becker6326a6d2017-08-23 06:38:22 +0100113 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
114 mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200115 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000116
Paul Bakker9dcc3222011-03-08 14:16:06 +0000117 memset( hash_result, 0x00, 1000 );
118 memset( output, 0x00, 1000 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000119
Hanno Becker6326a6d2017-08-23 06:38:22 +0100120 TEST_ASSERT( mbedtls_mpi_read_string( &P, radix_P, input_P ) == 0 );
121 TEST_ASSERT( mbedtls_mpi_read_string( &Q, radix_Q, input_Q ) == 0 );
122 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
123 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000124
Hanno Becker6326a6d2017-08-23 06:38:22 +0100125 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
126 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Hanno Becker7f25f852017-10-10 16:56:22 +0100127 TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200128 TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000129
Paul Bakker9dcc3222011-03-08 14:16:06 +0000130
Hanno Beckera5cedbc2019-07-17 11:21:02 +0100131 if( mbedtls_md_info_from_type( digest ) != MBEDTLS_MD_INVALID_HANDLE )
132 {
Azim Khand30ca132017-06-09 04:32:58 +0100133 TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( digest ), message_str->x, message_str->len, hash_result ) == 0 );
Hanno Beckera5cedbc2019-07-17 11:21:02 +0100134 }
Paul Bakker9dcc3222011-03-08 14:16:06 +0000135
Hanno Becker6326a6d2017-08-23 06:38:22 +0100136 TEST_ASSERT( mbedtls_rsa_pkcs1_sign( &ctx, &rnd_buffer_rand, &info, MBEDTLS_RSA_PRIVATE,
137 digest, 0, hash_result, output ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +0200138 if( result == 0 )
Paul Bakker9dcc3222011-03-08 14:16:06 +0000139 {
Paul Bakker9dcc3222011-03-08 14:16:06 +0000140
Azim Khand30ca132017-06-09 04:32:58 +0100141 TEST_ASSERT( hexcmp( output, result_hex_str->x, ctx.len, result_hex_str->len ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000142 }
Paul Bakker6c591fa2011-05-05 11:49:20 +0000143
Paul Bakkerbd51b262014-07-10 15:26:12 +0200144exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100145 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
146 mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200147 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000148}
Paul Bakker33b43f12013-08-20 11:48:36 +0200149/* END_CASE */
Paul Bakker9dcc3222011-03-08 14:16:06 +0000150
Paul Bakker33b43f12013-08-20 11:48:36 +0200151/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100152void pkcs1_rsassa_pss_verify( int mod, int radix_N, char * input_N,
153 int radix_E, char * input_E, int digest,
Azim Khan5fcca462018-06-29 11:05:32 +0100154 int hash, data_t * message_str, char * salt,
155 data_t * result_str, int result )
Paul Bakker9dcc3222011-03-08 14:16:06 +0000156{
Paul Bakker9dcc3222011-03-08 14:16:06 +0000157 unsigned char hash_result[1000];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200158 mbedtls_rsa_context ctx;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100159 mbedtls_mpi N, E;
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200160 ((void) salt);
Paul Bakker9dcc3222011-03-08 14:16:06 +0000161
Hanno Becker6326a6d2017-08-23 06:38:22 +0100162 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200163 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, hash );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000164 memset( hash_result, 0x00, 1000 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000165
Hanno Becker6326a6d2017-08-23 06:38:22 +0100166 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
167 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000168
Hanno Becker6326a6d2017-08-23 06:38:22 +0100169 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
170 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200171 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000172
Paul Bakker9dcc3222011-03-08 14:16:06 +0000173
Hanno Beckera5cedbc2019-07-17 11:21:02 +0100174 if( mbedtls_md_info_from_type( digest ) != MBEDTLS_MD_INVALID_HANDLE )
175 {
Azim Khand30ca132017-06-09 04:32:58 +0100176 TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( digest ), message_str->x, message_str->len, hash_result ) == 0 );
Hanno Beckera5cedbc2019-07-17 11:21:02 +0100177 }
Paul Bakker9dcc3222011-03-08 14:16:06 +0000178
Azim Khand30ca132017-06-09 04:32:58 +0100179 TEST_ASSERT( mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC, digest, 0, hash_result, result_str->x ) == result );
Paul Bakker58ef6ec2013-01-03 11:33:48 +0100180
Paul Bakkerbd51b262014-07-10 15:26:12 +0200181exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100182 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200183 mbedtls_rsa_free( &ctx );
Paul Bakker9dcc3222011-03-08 14:16:06 +0000184}
Paul Bakker33b43f12013-08-20 11:48:36 +0200185/* END_CASE */
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200186
187/* BEGIN_CASE */
Azim Khanf1aaec92017-05-30 14:23:15 +0100188void pkcs1_rsassa_pss_verify_ext( int mod, int radix_N, char * input_N,
189 int radix_E, char * input_E,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200190 int msg_digest_id, int ctx_hash,
191 int mgf_hash, int salt_len,
Azim Khan5fcca462018-06-29 11:05:32 +0100192 data_t * message_str,
193 data_t * result_str, int result_simple,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200194 int result_full )
195{
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200196 unsigned char hash_result[1000];
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200197 mbedtls_rsa_context ctx;
Azim Khanf1aaec92017-05-30 14:23:15 +0100198 size_t hash_len;
Hanno Becker6326a6d2017-08-23 06:38:22 +0100199 mbedtls_mpi N, E;
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200200
Hanno Becker6326a6d2017-08-23 06:38:22 +0100201 mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200202 mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V21, ctx_hash );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200203 memset( hash_result, 0x00, 1000 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200204
Hanno Becker6326a6d2017-08-23 06:38:22 +0100205 TEST_ASSERT( mbedtls_mpi_read_string( &N, radix_N, input_N ) == 0 );
206 TEST_ASSERT( mbedtls_mpi_read_string( &E, radix_E, input_E ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200207
Hanno Becker6326a6d2017-08-23 06:38:22 +0100208 TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
209 TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( ( mod + 7 ) / 8 ) );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200210 TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200211
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200212
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200213 if( msg_digest_id != MBEDTLS_MD_NONE )
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200214 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200215 TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( msg_digest_id ),
Azim Khand30ca132017-06-09 04:32:58 +0100216 message_str->x, message_str->len, hash_result ) == 0 );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200217 hash_len = 0;
218 }
219 else
220 {
Azim Khand30ca132017-06-09 04:32:58 +0100221 memcpy( hash_result, message_str->x, message_str->len );
222 hash_len = message_str->len;
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200223 }
224
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200225 TEST_ASSERT( mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200226 msg_digest_id, hash_len, hash_result,
Azim Khand30ca132017-06-09 04:32:58 +0100227 result_str->x ) == result_simple );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200228
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200229 TEST_ASSERT( mbedtls_rsa_rsassa_pss_verify_ext( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC,
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200230 msg_digest_id, hash_len, hash_result,
231 mgf_hash, salt_len,
Azim Khand30ca132017-06-09 04:32:58 +0100232 result_str->x ) == result_full );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200233
Paul Bakkerbd51b262014-07-10 15:26:12 +0200234exit:
Hanno Becker6326a6d2017-08-23 06:38:22 +0100235 mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200236 mbedtls_rsa_free( &ctx );
Manuel Pégourié-Gonnard5ec628a2014-06-03 11:44:06 +0200237}
238/* END_CASE */