blob: a22c486def461230ec49e612419a5d3340952d14 [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Mohammad Azim Khancf32c452017-06-13 14:55:58 +01002#include "mbedtls/bignum.h"
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00003#include "mbedtls/x509_crt.h"
4#include "mbedtls/x509_csr.h"
Valerio Setti25b282e2024-01-17 10:55:32 +01005#include "x509_internal.h"
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00006#include "mbedtls/pem.h"
7#include "mbedtls/oid.h"
Hanno Becker418a6222017-09-14 07:51:28 +01008#include "mbedtls/rsa.h"
Valerio Setti48e8fc72022-10-19 15:14:29 +02009#include "mbedtls/asn1write.h"
Valerio Setti178b5bd2023-02-13 10:04:28 +010010#include "mbedtls/pk.h"
Valerio Setti384fbde2024-01-02 13:26:40 +010011#include "mbedtls/psa_util.h"
Manuel Pégourié-Gonnardfeb03962020-08-20 09:59:33 +020012
Michael Schuster275b6982024-06-07 01:51:54 +020013#if defined(MBEDTLS_PEM_WRITE_C) && \
14 defined(MBEDTLS_X509_CRT_WRITE_C) && \
15 defined(MBEDTLS_X509_CRT_PARSE_C) && \
16 defined(MBEDTLS_MD_CAN_SHA1) && \
17 defined(MBEDTLS_RSA_C) && defined(MBEDTLS_PK_RSA_ALT_SUPPORT)
Michael Schusterb1e33fb2024-06-04 02:30:22 +020018static int mbedtls_rsa_decrypt_func(void *ctx, size_t *olen,
Michael Schuster31b1cb82024-06-04 02:41:10 +020019 const unsigned char *input, unsigned char *output,
20 size_t output_max_len)
Hanno Becker418a6222017-09-14 07:51:28 +010021{
Gilles Peskine449bd832023-01-11 14:50:10 +010022 return mbedtls_rsa_pkcs1_decrypt((mbedtls_rsa_context *) ctx, NULL, NULL,
23 olen, input, output, output_max_len);
Hanno Becker418a6222017-09-14 07:51:28 +010024}
Michael Schusterb1e33fb2024-06-04 02:30:22 +020025static int mbedtls_rsa_sign_func(void *ctx,
Michael Schuster31b1cb82024-06-04 02:41:10 +020026 int (*f_rng)(void *, unsigned char *, size_t), void *p_rng,
27 mbedtls_md_type_t md_alg, unsigned int hashlen,
28 const unsigned char *hash, unsigned char *sig)
Hanno Becker418a6222017-09-14 07:51:28 +010029{
Gilles Peskine449bd832023-01-11 14:50:10 +010030 return mbedtls_rsa_pkcs1_sign((mbedtls_rsa_context *) ctx, f_rng, p_rng,
31 md_alg, hashlen, hash, sig);
Hanno Becker418a6222017-09-14 07:51:28 +010032}
Michael Schusterb1e33fb2024-06-04 02:30:22 +020033static size_t mbedtls_rsa_key_len_func(void *ctx)
Hanno Becker418a6222017-09-14 07:51:28 +010034{
Gilles Peskine449bd832023-01-11 14:50:10 +010035 return ((const mbedtls_rsa_context *) ctx)->len;
Hanno Becker418a6222017-09-14 07:51:28 +010036}
Michael Schuster275b6982024-06-07 01:51:54 +020037#endif
Hanno Becker418a6222017-09-14 07:51:28 +010038
Gilles Peskinef4e672e2020-01-31 14:22:10 +010039#if defined(MBEDTLS_USE_PSA_CRYPTO) && \
40 defined(MBEDTLS_PEM_WRITE_C) && defined(MBEDTLS_X509_CSR_WRITE_C)
Gilles Peskine449bd832023-01-11 14:50:10 +010041static int x509_crt_verifycsr(const unsigned char *buf, size_t buflen)
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050042{
Przemek Stekiel54a54462022-08-01 13:59:12 +020043 unsigned char hash[PSA_HASH_MAX_SIZE];
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050044 mbedtls_x509_csr csr;
Hanno Beckerbf2dacb2019-06-03 16:28:24 +010045 int ret = 0;
46
Gilles Peskine449bd832023-01-11 14:50:10 +010047 mbedtls_x509_csr_init(&csr);
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050048
Gilles Peskine449bd832023-01-11 14:50:10 +010049 if (mbedtls_x509_csr_parse(&csr, buf, buflen) != 0) {
Hanno Beckerbf2dacb2019-06-03 16:28:24 +010050 ret = MBEDTLS_ERR_X509_BAD_INPUT_DATA;
51 goto cleanup;
52 }
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050053
Manuel Pégourié-Gonnard2d6d9932023-03-28 11:38:08 +020054 psa_algorithm_t psa_alg = mbedtls_md_psa_alg_from_type(csr.sig_md);
Przemek Stekiel54a54462022-08-01 13:59:12 +020055 size_t hash_size = 0;
Gilles Peskine449bd832023-01-11 14:50:10 +010056 psa_status_t status = psa_hash_compute(psa_alg, csr.cri.p, csr.cri.len,
57 hash, PSA_HASH_MAX_SIZE, &hash_size);
Przemek Stekiel54a54462022-08-01 13:59:12 +020058
Gilles Peskine449bd832023-01-11 14:50:10 +010059 if (status != PSA_SUCCESS) {
Andrzej Kurek4b114072018-11-19 18:04:01 -050060 /* Note: this can't happen except after an internal error */
Hanno Beckerbf2dacb2019-06-03 16:28:24 +010061 ret = MBEDTLS_ERR_X509_BAD_INPUT_DATA;
62 goto cleanup;
Andrzej Kurek4b114072018-11-19 18:04:01 -050063 }
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050064
Gilles Peskine449bd832023-01-11 14:50:10 +010065 if (mbedtls_pk_verify_ext(csr.sig_pk, csr.sig_opts, &csr.pk,
Manuel Pégourié-Gonnard9b41eb82023-03-28 11:14:24 +020066 csr.sig_md, hash, mbedtls_md_get_size_from_type(csr.sig_md),
Gilles Peskine449bd832023-01-11 14:50:10 +010067 csr.sig.p, csr.sig.len) != 0) {
Hanno Beckerbf2dacb2019-06-03 16:28:24 +010068 ret = MBEDTLS_ERR_X509_CERT_VERIFY_FAILED;
69 goto cleanup;
Andrzej Kurek4b114072018-11-19 18:04:01 -050070 }
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050071
Hanno Beckerbf2dacb2019-06-03 16:28:24 +010072cleanup:
73
Gilles Peskine449bd832023-01-11 14:50:10 +010074 mbedtls_x509_csr_free(&csr);
75 return ret;
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050076}
Gilles Peskinef4e672e2020-01-31 14:22:10 +010077#endif /* MBEDTLS_USE_PSA_CRYPTO && MBEDTLS_PEM_WRITE_C && MBEDTLS_X509_CSR_WRITE_C */
Andrzej Kurek5f7bad32018-11-19 10:12:37 -050078
Valerio Setti48e8fc72022-10-19 15:14:29 +020079#if defined(MBEDTLS_X509_CSR_WRITE_C)
80
81/*
82 * The size of this temporary buffer is given by the sequence of functions
83 * called hereinafter:
84 * - mbedtls_asn1_write_oid()
85 * - 8 bytes for MBEDTLS_OID_EXTENDED_KEY_USAGE raw value
86 * - 1 byte for MBEDTLS_OID_EXTENDED_KEY_USAGE length
87 * - 1 byte for MBEDTLS_ASN1_OID tag
88 * - mbedtls_asn1_write_len()
89 * - 1 byte since we're dealing with sizes which are less than 0x80
90 * - mbedtls_asn1_write_tag()
91 * - 1 byte
92 *
93 * This length is fine as long as this function is called using the
94 * MBEDTLS_OID_SERVER_AUTH OID. If this is changed in the future, then this
95 * buffer's length should be adjusted accordingly.
96 * Unfortunately there's no predefined max size for OIDs which can be used
97 * to set an overall upper boundary which is always guaranteed.
98 */
99#define EXT_KEY_USAGE_TMP_BUF_MAX_LENGTH 12
100
Gilles Peskine449bd832023-01-11 14:50:10 +0100101static int csr_set_extended_key_usage(mbedtls_x509write_csr *ctx,
102 const char *oid, size_t oid_len)
Valerio Setti48e8fc72022-10-19 15:14:29 +0200103{
104 unsigned char buf[EXT_KEY_USAGE_TMP_BUF_MAX_LENGTH] = { 0 };
Gilles Peskine449bd832023-01-11 14:50:10 +0100105 unsigned char *p = buf + sizeof(buf);
Valerio Setti48e8fc72022-10-19 15:14:29 +0200106 int ret;
107 size_t len = 0;
108
109 /*
110 * Following functions fail anyway if the temporary buffer is not large,
111 * but we set an extra check here to emphasize a possible source of errors
112 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100113 if (oid_len > EXT_KEY_USAGE_TMP_BUF_MAX_LENGTH) {
Valerio Setti48e8fc72022-10-19 15:14:29 +0200114 return MBEDTLS_ERR_X509_BAD_INPUT_DATA;
115 }
116
Gilles Peskine449bd832023-01-11 14:50:10 +0100117 MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_oid(&p, buf, oid, oid_len));
118 MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_len(&p, buf, ret));
119 MBEDTLS_ASN1_CHK_ADD(len, mbedtls_asn1_write_tag(&p, buf,
120 MBEDTLS_ASN1_CONSTRUCTED |
121 MBEDTLS_ASN1_SEQUENCE));
Valerio Setti48e8fc72022-10-19 15:14:29 +0200122
Gilles Peskine449bd832023-01-11 14:50:10 +0100123 ret = mbedtls_x509write_csr_set_extension(ctx,
124 MBEDTLS_OID_EXTENDED_KEY_USAGE,
125 MBEDTLS_OID_SIZE(MBEDTLS_OID_EXTENDED_KEY_USAGE),
126 0,
127 p,
128 len);
Valerio Setti48e8fc72022-10-19 15:14:29 +0200129
130 return ret;
131}
132#endif /* MBEDTLS_X509_CSR_WRITE_C */
Gilles Peskinec94500b2023-09-21 18:01:05 +0200133
134/* Due to inconsistencies in the input size limits applied by different
135 * library functions, some write-parse tests may fail. */
136#define MAY_FAIL_GET_NAME 0x0001
137#define MAY_FAIL_DN_GETS 0x0002
138
Paul Bakker33b43f12013-08-20 11:48:36 +0200139/* END_HEADER */
Paul Bakker6d620502012-02-16 14:09:13 +0000140
Paul Bakker33b43f12013-08-20 11:48:36 +0200141/* BEGIN_DEPENDENCIES
Valerio Setti3580f442023-07-27 10:19:53 +0200142 * depends_on:MBEDTLS_FS_IO:MBEDTLS_PK_PARSE_C
Paul Bakker33b43f12013-08-20 11:48:36 +0200143 * END_DEPENDENCIES
144 */
Paul Bakker6d620502012-02-16 14:09:13 +0000145
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200146/* BEGIN_CASE depends_on:MBEDTLS_PEM_WRITE_C:MBEDTLS_X509_CSR_WRITE_C */
Gilles Peskine449bd832023-01-11 14:50:10 +0100147void x509_csr_check(char *key_file, char *cert_req_check_file, int md_type,
148 int key_usage, int set_key_usage, int cert_type,
149 int set_cert_type, int set_extension)
Paul Bakker6d620502012-02-16 14:09:13 +0000150{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200151 mbedtls_pk_context key;
152 mbedtls_x509write_csr req;
Andres AGe0af9952016-09-07 11:09:44 +0100153 unsigned char buf[4096];
Paul Bakker6d620502012-02-16 14:09:13 +0000154 int ret;
Neil Armstrongc23d2e32022-03-18 15:31:59 +0100155#if !defined(MBEDTLS_USE_PSA_CRYPTO)
156 unsigned char check_buf[4000];
Paul Bakker6d620502012-02-16 14:09:13 +0000157 FILE *f;
Neil Armstrongc23d2e32022-03-18 15:31:59 +0100158 size_t olen = 0;
159#endif /* !MBEDTLS_USE_PSA_CRYPTO */
160 size_t pem_len = 0, buf_index;
161 int der_len = -1;
Paul Bakker3a8cb6f2013-12-30 20:41:54 +0100162 const char *subject_name = "C=NL,O=PolarSSL,CN=PolarSSL Server 1";
Ronald Cron351f0ee2020-06-10 12:12:18 +0200163 mbedtls_test_rnd_pseudo_info rnd_info;
Przemek Stekiel8e83d3a2023-02-14 12:01:16 +0100164 mbedtls_x509_san_list san_ip;
165 mbedtls_x509_san_list san_dns;
166 mbedtls_x509_san_list san_uri;
Andrzej Kurek34ccd8d2023-07-07 06:32:17 -0400167 mbedtls_x509_san_list san_mail;
168 mbedtls_x509_san_list san_dn;
Przemek Stekiel8e83d3a2023-02-14 12:01:16 +0100169 mbedtls_x509_san_list *san_list = NULL;
Andrzej Kurek34ccd8d2023-07-07 06:32:17 -0400170 mbedtls_asn1_named_data *ext_san_dirname = NULL;
171
172 const char san_ip_name[] = { 0x7f, 0x00, 0x00, 0x01 }; // 127.0.0.1
Przemek Stekiel8e83d3a2023-02-14 12:01:16 +0100173 const char *san_dns_name = "example.com";
Andrzej Kurek34ccd8d2023-07-07 06:32:17 -0400174 const char *san_dn_name = "C=UK,O=Mbed TLS,CN=Mbed TLS directoryName SAN";
175 const char *san_mail_name = "mail@example.com";
176 const char *san_uri_name = "http://pki.example.com";
177
178 san_mail.node.type = MBEDTLS_X509_SAN_RFC822_NAME;
179 san_mail.node.san.unstructured_name.p = (unsigned char *) san_mail_name;
180 san_mail.node.san.unstructured_name.len = strlen(san_mail_name);
181 san_mail.next = NULL;
182
183 san_dns.node.type = MBEDTLS_X509_SAN_DNS_NAME;
184 san_dns.node.san.unstructured_name.p = (unsigned char *) san_dns_name;
185 san_dns.node.san.unstructured_name.len = strlen(san_dns_name);
186 san_dns.next = &san_mail;
187
188 san_dn.node.type = MBEDTLS_X509_SAN_DIRECTORY_NAME;
189 TEST_ASSERT(mbedtls_x509_string_to_names(&ext_san_dirname,
190 san_dn_name) == 0);
191 san_dn.node.san.directory_name = *ext_san_dirname;
192 san_dn.next = &san_dns;
193
194 san_ip.node.type = MBEDTLS_X509_SAN_IP_ADDRESS;
195 san_ip.node.san.unstructured_name.p = (unsigned char *) san_ip_name;
196 san_ip.node.san.unstructured_name.len = sizeof(san_ip_name);
197 san_ip.next = &san_dn;
Przemek Stekiel8e83d3a2023-02-14 12:01:16 +0100198
199 san_uri.node.type = MBEDTLS_X509_SAN_UNIFORM_RESOURCE_IDENTIFIER;
Przemek Stekiel5a49d3c2023-02-24 13:12:55 +0100200 san_uri.node.san.unstructured_name.p = (unsigned char *) san_uri_name;
201 san_uri.node.san.unstructured_name.len = strlen(san_uri_name);
Andrzej Kurek34ccd8d2023-07-07 06:32:17 -0400202 san_uri.next = &san_ip;
203
204 san_list = &san_uri;
Paul Bakker6d620502012-02-16 14:09:13 +0000205
Gilles Peskine449bd832023-01-11 14:50:10 +0100206 memset(&rnd_info, 0x2a, sizeof(mbedtls_test_rnd_pseudo_info));
Manuel Pégourié-Gonnardee731792013-09-11 22:48:40 +0200207
Gilles Peskine449bd832023-01-11 14:50:10 +0100208 mbedtls_x509write_csr_init(&req);
Gilles Peskine449bd832023-01-11 14:50:10 +0100209 mbedtls_pk_init(&key);
valerio32f2ac92023-04-20 11:59:52 +0200210 MD_OR_USE_PSA_INIT();
211
Gilles Peskine449bd832023-01-11 14:50:10 +0100212 TEST_ASSERT(mbedtls_pk_parse_keyfile(&key, key_file, NULL,
213 mbedtls_test_rnd_std_rand, NULL) == 0);
Paul Bakker6d620502012-02-16 14:09:13 +0000214
Gilles Peskine449bd832023-01-11 14:50:10 +0100215 mbedtls_x509write_csr_set_md_alg(&req, md_type);
216 mbedtls_x509write_csr_set_key(&req, &key);
217 TEST_ASSERT(mbedtls_x509write_csr_set_subject_name(&req, subject_name) == 0);
218 if (set_key_usage != 0) {
219 TEST_ASSERT(mbedtls_x509write_csr_set_key_usage(&req, key_usage) == 0);
220 }
221 if (set_cert_type != 0) {
222 TEST_ASSERT(mbedtls_x509write_csr_set_ns_cert_type(&req, cert_type) == 0);
223 }
224 if (set_extension != 0) {
225 TEST_ASSERT(csr_set_extended_key_usage(&req, MBEDTLS_OID_SERVER_AUTH,
226 MBEDTLS_OID_SIZE(MBEDTLS_OID_SERVER_AUTH)) == 0);
Przemek Stekiel8e83d3a2023-02-14 12:01:16 +0100227
228 TEST_ASSERT(mbedtls_x509write_csr_set_subject_alternative_name(&req, san_list) == 0);
Gilles Peskine449bd832023-01-11 14:50:10 +0100229 }
Paul Bakker8eabfc12013-08-25 10:18:25 +0200230
Gilles Peskine449bd832023-01-11 14:50:10 +0100231 ret = mbedtls_x509write_csr_pem(&req, buf, sizeof(buf),
232 mbedtls_test_rnd_pseudo_rand, &rnd_info);
233 TEST_ASSERT(ret == 0);
Paul Bakker6d620502012-02-16 14:09:13 +0000234
Gilles Peskine449bd832023-01-11 14:50:10 +0100235 pem_len = strlen((char *) buf);
Paul Bakker6d620502012-02-16 14:09:13 +0000236
Gilles Peskine449bd832023-01-11 14:50:10 +0100237 for (buf_index = pem_len; buf_index < sizeof(buf); ++buf_index) {
238 TEST_ASSERT(buf[buf_index] == 0);
Paul Elliott557b8d62020-11-19 09:46:56 +0000239 }
240
Neil Armstrong5b320382022-02-21 17:22:10 +0100241#if defined(MBEDTLS_USE_PSA_CRYPTO)
242 // When using PSA crypto, RNG isn't controllable, so cert_req_check_file can't be used
Gilles Peskine449bd832023-01-11 14:50:10 +0100243 (void) cert_req_check_file;
Neil Armstrong5b320382022-02-21 17:22:10 +0100244 buf[pem_len] = '\0';
Gilles Peskine449bd832023-01-11 14:50:10 +0100245 TEST_ASSERT(x509_crt_verifycsr(buf, pem_len + 1) == 0);
Neil Armstrong5b320382022-02-21 17:22:10 +0100246#else
Gilles Peskine449bd832023-01-11 14:50:10 +0100247 f = fopen(cert_req_check_file, "r");
248 TEST_ASSERT(f != NULL);
249 olen = fread(check_buf, 1, sizeof(check_buf), f);
250 fclose(f);
Paul Bakker6d620502012-02-16 14:09:13 +0000251
Gilles Peskine449bd832023-01-11 14:50:10 +0100252 TEST_ASSERT(olen >= pem_len - 1);
253 TEST_ASSERT(memcmp(buf, check_buf, pem_len - 1) == 0);
Neil Armstrongc23d2e32022-03-18 15:31:59 +0100254#endif /* MBEDTLS_USE_PSA_CRYPTO */
Paul Bakker58ef6ec2013-01-03 11:33:48 +0100255
Gilles Peskine449bd832023-01-11 14:50:10 +0100256 der_len = mbedtls_x509write_csr_der(&req, buf, sizeof(buf),
257 mbedtls_test_rnd_pseudo_rand,
258 &rnd_info);
259 TEST_ASSERT(der_len >= 0);
Andres AGe0af9952016-09-07 11:09:44 +0100260
Gilles Peskine449bd832023-01-11 14:50:10 +0100261 if (der_len == 0) {
Andres AGe0af9952016-09-07 11:09:44 +0100262 goto exit;
Gilles Peskine449bd832023-01-11 14:50:10 +0100263 }
Andres AGe0af9952016-09-07 11:09:44 +0100264
Neil Armstrong5b320382022-02-21 17:22:10 +0100265#if defined(MBEDTLS_USE_PSA_CRYPTO)
266 // When using PSA crypto, RNG isn't controllable, result length isn't
267 // deterministic over multiple runs, removing a single byte isn't enough to
268 // go into the MBEDTLS_ERR_ASN1_BUF_TOO_SMALL error case
269 der_len /= 2;
270#else
271 der_len -= 1;
272#endif
Gilles Peskine449bd832023-01-11 14:50:10 +0100273 ret = mbedtls_x509write_csr_der(&req, buf, (size_t) (der_len),
274 mbedtls_test_rnd_pseudo_rand, &rnd_info);
275 TEST_ASSERT(ret == MBEDTLS_ERR_ASN1_BUF_TOO_SMALL);
Andres AGe0af9952016-09-07 11:09:44 +0100276
Paul Bakkerbd51b262014-07-10 15:26:12 +0200277exit:
Andrzej Kurekbdb41dd2023-07-10 08:09:50 -0400278 mbedtls_asn1_free_named_data_list(&ext_san_dirname);
Gilles Peskine449bd832023-01-11 14:50:10 +0100279 mbedtls_x509write_csr_free(&req);
280 mbedtls_pk_free(&key);
Manuel Pégourié-Gonnard33a13022023-03-17 14:02:49 +0100281 MD_OR_USE_PSA_DONE();
Paul Bakker6d620502012-02-16 14:09:13 +0000282}
Paul Bakker33b43f12013-08-20 11:48:36 +0200283/* END_CASE */
Paul Bakker2397cf32013-09-08 15:58:15 +0200284
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500285/* BEGIN_CASE depends_on:MBEDTLS_PEM_WRITE_C:MBEDTLS_X509_CSR_WRITE_C:MBEDTLS_USE_PSA_CRYPTO */
Gilles Peskine449bd832023-01-11 14:50:10 +0100286void x509_csr_check_opaque(char *key_file, int md_type, int key_usage,
287 int cert_type)
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500288{
289 mbedtls_pk_context key;
Paul Elliott09a8f4d2024-10-25 12:41:28 +0100290 mbedtls_pk_init(&key);
291
Ronald Cron5425a212020-08-04 14:58:35 +0200292 mbedtls_svc_key_id_t key_id = MBEDTLS_SVC_KEY_ID_INIT;
Valerio Setti1fa2f6e2024-02-27 08:11:25 +0100293 psa_key_attributes_t key_attr = PSA_KEY_ATTRIBUTES_INIT;
Paul Elliott09a8f4d2024-10-25 12:41:28 +0100294
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500295 mbedtls_x509write_csr req;
Paul Elliott09a8f4d2024-10-25 12:41:28 +0100296 mbedtls_x509write_csr_init(&req);
297
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500298 unsigned char buf[4096];
299 int ret;
300 size_t pem_len = 0;
301 const char *subject_name = "C=NL,O=PolarSSL,CN=PolarSSL Server 1";
Ronald Cron351f0ee2020-06-10 12:12:18 +0200302 mbedtls_test_rnd_pseudo_info rnd_info;
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500303
Valerio Setti569c1712023-04-19 14:53:36 +0200304 MD_OR_USE_PSA_INIT();
305
Gilles Peskine449bd832023-01-11 14:50:10 +0100306 memset(&rnd_info, 0x2a, sizeof(mbedtls_test_rnd_pseudo_info));
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500307
Gilles Peskine449bd832023-01-11 14:50:10 +0100308 TEST_ASSERT(mbedtls_pk_parse_keyfile(&key, key_file, NULL,
309 mbedtls_test_rnd_std_rand, NULL) == 0);
Neil Armstrong95974972022-04-22 13:57:44 +0200310
Valerio Setti1fa2f6e2024-02-27 08:11:25 +0100311 /* Turn the PK context into an opaque one. */
312 TEST_EQUAL(mbedtls_pk_get_psa_attributes(&key, PSA_KEY_USAGE_SIGN_HASH, &key_attr), 0);
313 TEST_EQUAL(mbedtls_pk_import_into_psa(&key, &key_attr, &key_id), 0);
314 mbedtls_pk_free(&key);
315 mbedtls_pk_init(&key);
316 TEST_EQUAL(mbedtls_pk_setup_opaque(&key, key_id), 0);
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500317
Gilles Peskine449bd832023-01-11 14:50:10 +0100318 mbedtls_x509write_csr_set_md_alg(&req, md_type);
319 mbedtls_x509write_csr_set_key(&req, &key);
320 TEST_ASSERT(mbedtls_x509write_csr_set_subject_name(&req, subject_name) == 0);
321 if (key_usage != 0) {
322 TEST_ASSERT(mbedtls_x509write_csr_set_key_usage(&req, key_usage) == 0);
323 }
324 if (cert_type != 0) {
325 TEST_ASSERT(mbedtls_x509write_csr_set_ns_cert_type(&req, cert_type) == 0);
326 }
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500327
Gilles Peskine449bd832023-01-11 14:50:10 +0100328 ret = mbedtls_x509write_csr_pem(&req, buf, sizeof(buf) - 1,
329 mbedtls_test_rnd_pseudo_rand, &rnd_info);
Ronald Cron6c5bd7f2020-06-10 14:08:26 +0200330
Gilles Peskine449bd832023-01-11 14:50:10 +0100331 TEST_ASSERT(ret == 0);
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500332
Gilles Peskine449bd832023-01-11 14:50:10 +0100333 pem_len = strlen((char *) buf);
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500334 buf[pem_len] = '\0';
Gilles Peskine449bd832023-01-11 14:50:10 +0100335 TEST_ASSERT(x509_crt_verifycsr(buf, pem_len + 1) == 0);
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500336
Manuel Pégourié-Gonnardfeb03962020-08-20 09:59:33 +0200337
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500338exit:
Gilles Peskine449bd832023-01-11 14:50:10 +0100339 mbedtls_x509write_csr_free(&req);
340 mbedtls_pk_free(&key);
341 psa_destroy_key(key_id);
Valerio Setti569c1712023-04-19 14:53:36 +0200342 MD_OR_USE_PSA_DONE();
Andrzej Kurek5f7bad32018-11-19 10:12:37 -0500343}
344/* END_CASE */
345
Manuel Pégourié-Gonnarda9464892023-03-17 12:08:50 +0100346/* BEGIN_CASE depends_on:MBEDTLS_PEM_WRITE_C:MBEDTLS_X509_CRT_WRITE_C:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_MD_CAN_SHA1 */
Gilles Peskine449bd832023-01-11 14:50:10 +0100347void x509_crt_check(char *subject_key_file, char *subject_pwd,
348 char *subject_name, char *issuer_key_file,
349 char *issuer_pwd, char *issuer_name,
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100350 data_t *serial_arg, char *not_before, char *not_after,
Gilles Peskine449bd832023-01-11 14:50:10 +0100351 int md_type, int key_usage, int set_key_usage,
352 char *ext_key_usage,
353 int cert_type, int set_cert_type, int auth_ident,
354 int ver, char *cert_check_file, int pk_wrap, int is_ca,
Andrzej Kurek76c96622023-04-04 06:57:08 -0400355 char *cert_verify_file, int set_subjectAltNames)
Paul Bakker2397cf32013-09-08 15:58:15 +0200356{
Hanno Becker418a6222017-09-14 07:51:28 +0100357 mbedtls_pk_context subject_key, issuer_key, issuer_key_alt;
358 mbedtls_pk_context *key = &issuer_key;
359
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200360 mbedtls_x509write_cert crt;
Andres AGe0af9952016-09-07 11:09:44 +0100361 unsigned char buf[4096];
Paul Bakker2397cf32013-09-08 15:58:15 +0200362 unsigned char check_buf[5000];
Werner Lewisacd01e52022-05-10 12:23:13 +0100363 unsigned char *p, *end;
364 unsigned char tag, sz;
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100365#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
366 mbedtls_mpi serial_mpi;
367#endif
Werner Lewisacd01e52022-05-10 12:23:13 +0100368 int ret, before_tag, after_tag;
Paul Elliott557b8d62020-11-19 09:46:56 +0000369 size_t olen = 0, pem_len = 0, buf_index = 0;
Andres AGe0af9952016-09-07 11:09:44 +0100370 int der_len = -1;
Paul Bakker2397cf32013-09-08 15:58:15 +0200371 FILE *f;
Ronald Cron351f0ee2020-06-10 12:12:18 +0200372 mbedtls_test_rnd_pseudo_info rnd_info;
Neil Armstrong98f899c2022-03-16 17:42:42 +0100373#if defined(MBEDTLS_USE_PSA_CRYPTO)
374 mbedtls_svc_key_id_t key_id = MBEDTLS_SVC_KEY_ID_INIT;
Valerio Setti1fa2f6e2024-02-27 08:11:25 +0100375 psa_key_attributes_t key_attr = PSA_KEY_ATTRIBUTES_INIT;
Neil Armstrong98f899c2022-03-16 17:42:42 +0100376#endif
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100377 mbedtls_pk_type_t issuer_key_type;
Andrzej Kurek76c96622023-04-04 06:57:08 -0400378 mbedtls_x509_san_list san_ip;
379 mbedtls_x509_san_list san_dns;
380 mbedtls_x509_san_list san_uri;
381 mbedtls_x509_san_list san_mail;
382 mbedtls_x509_san_list san_dn;
383 mbedtls_asn1_named_data *ext_san_dirname = NULL;
384 const char san_ip_name[] = { 0x01, 0x02, 0x03, 0x04 };
385 const char *san_dns_name = "example.com";
386 const char *san_dn_name = "C=UK,O=Mbed TLS,CN=SubjectAltName test";
387 const char *san_mail_name = "mail@example.com";
388 const char *san_uri_name = "http://pki.example.com";
389 mbedtls_x509_san_list *san_list = NULL;
390
391 if (set_subjectAltNames) {
392 san_mail.node.type = MBEDTLS_X509_SAN_RFC822_NAME;
393 san_mail.node.san.unstructured_name.p = (unsigned char *) san_mail_name;
Andrzej Kurek13c43f62023-04-04 10:43:38 -0400394 san_mail.node.san.unstructured_name.len = strlen(san_mail_name);
Andrzej Kurek76c96622023-04-04 06:57:08 -0400395 san_mail.next = NULL;
396
397 san_dns.node.type = MBEDTLS_X509_SAN_DNS_NAME;
398 san_dns.node.san.unstructured_name.p = (unsigned char *) san_dns_name;
399 san_dns.node.san.unstructured_name.len = strlen(san_dns_name);
400 san_dns.next = &san_mail;
401
402 san_dn.node.type = MBEDTLS_X509_SAN_DIRECTORY_NAME;
403 TEST_ASSERT(mbedtls_x509_string_to_names(&ext_san_dirname,
404 san_dn_name) == 0);
405 san_dn.node.san.directory_name = *ext_san_dirname;
406 san_dn.next = &san_dns;
407
408 san_ip.node.type = MBEDTLS_X509_SAN_IP_ADDRESS;
409 san_ip.node.san.unstructured_name.p = (unsigned char *) san_ip_name;
410 san_ip.node.san.unstructured_name.len = sizeof(san_ip_name);
411 san_ip.next = &san_dn;
412
413 san_uri.node.type = MBEDTLS_X509_SAN_UNIFORM_RESOURCE_IDENTIFIER;
414 san_uri.node.san.unstructured_name.p = (unsigned char *) san_uri_name;
415 san_uri.node.san.unstructured_name.len = strlen(san_uri_name);
416 san_uri.next = &san_ip;
417
418 san_list = &san_uri;
419 }
Paul Bakker2397cf32013-09-08 15:58:15 +0200420
Gilles Peskine449bd832023-01-11 14:50:10 +0100421 memset(&rnd_info, 0x2a, sizeof(mbedtls_test_rnd_pseudo_info));
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100422#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
423 mbedtls_mpi_init(&serial_mpi);
424#endif
Hanno Becker418a6222017-09-14 07:51:28 +0100425
Gilles Peskine449bd832023-01-11 14:50:10 +0100426 mbedtls_pk_init(&subject_key);
427 mbedtls_pk_init(&issuer_key);
428 mbedtls_pk_init(&issuer_key_alt);
Gilles Peskine449bd832023-01-11 14:50:10 +0100429 mbedtls_x509write_crt_init(&crt);
valerio32f2ac92023-04-20 11:59:52 +0200430 MD_OR_USE_PSA_INIT();
Paul Bakker2397cf32013-09-08 15:58:15 +0200431
Gilles Peskine449bd832023-01-11 14:50:10 +0100432 TEST_ASSERT(mbedtls_pk_parse_keyfile(&subject_key, subject_key_file,
433 subject_pwd, mbedtls_test_rnd_std_rand, NULL) == 0);
Hanno Becker418a6222017-09-14 07:51:28 +0100434
Gilles Peskine449bd832023-01-11 14:50:10 +0100435 TEST_ASSERT(mbedtls_pk_parse_keyfile(&issuer_key, issuer_key_file,
436 issuer_pwd, mbedtls_test_rnd_std_rand, NULL) == 0);
Hanno Becker418a6222017-09-14 07:51:28 +0100437
Gilles Peskine449bd832023-01-11 14:50:10 +0100438 issuer_key_type = mbedtls_pk_get_type(&issuer_key);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100439
Dave Rodgmandc3b1542023-01-20 11:39:00 +0000440#if defined(MBEDTLS_RSA_C) && defined(MBEDTLS_PK_RSA_ALT_SUPPORT)
Hanno Becker418a6222017-09-14 07:51:28 +0100441 /* For RSA PK contexts, create a copy as an alternative RSA context. */
Gilles Peskine449bd832023-01-11 14:50:10 +0100442 if (pk_wrap == 1 && issuer_key_type == MBEDTLS_PK_RSA) {
443 TEST_ASSERT(mbedtls_pk_setup_rsa_alt(&issuer_key_alt,
444 mbedtls_pk_rsa(issuer_key),
445 mbedtls_rsa_decrypt_func,
446 mbedtls_rsa_sign_func,
447 mbedtls_rsa_key_len_func) == 0);
Hanno Becker418a6222017-09-14 07:51:28 +0100448
449 key = &issuer_key_alt;
450 }
Manuel Pégourié-Gonnard147b28e2018-03-12 15:26:59 +0100451#endif
Hanno Becker418a6222017-09-14 07:51:28 +0100452
Neil Armstrong98f899c2022-03-16 17:42:42 +0100453#if defined(MBEDTLS_USE_PSA_CRYPTO)
Valerio Setti1fa2f6e2024-02-27 08:11:25 +0100454 /* Turn the issuer PK context into an opaque one. */
Gilles Peskine449bd832023-01-11 14:50:10 +0100455 if (pk_wrap == 2) {
Valerio Setti1fa2f6e2024-02-27 08:11:25 +0100456 TEST_EQUAL(mbedtls_pk_get_psa_attributes(&issuer_key, PSA_KEY_USAGE_SIGN_HASH,
457 &key_attr), 0);
458 TEST_EQUAL(mbedtls_pk_import_into_psa(&issuer_key, &key_attr, &key_id), 0);
459 mbedtls_pk_free(&issuer_key);
460 mbedtls_pk_init(&issuer_key);
461 TEST_EQUAL(mbedtls_pk_setup_opaque(&issuer_key, key_id), 0);
Neil Armstrong98f899c2022-03-16 17:42:42 +0100462 }
463#endif /* MBEDTLS_USE_PSA_CRYPTO */
464
Gilles Peskine449bd832023-01-11 14:50:10 +0100465 if (pk_wrap == 2) {
466 TEST_ASSERT(mbedtls_pk_get_type(&issuer_key) == MBEDTLS_PK_OPAQUE);
467 }
Neil Armstrong98f899c2022-03-16 17:42:42 +0100468
Gilles Peskine449bd832023-01-11 14:50:10 +0100469 if (ver != -1) {
470 mbedtls_x509write_crt_set_version(&crt, ver);
471 }
Hanno Becker418a6222017-09-14 07:51:28 +0100472
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100473#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100474 TEST_ASSERT(mbedtls_mpi_read_binary(&serial_mpi, serial_arg->x,
475 serial_arg->len) == 0);
476 TEST_ASSERT(mbedtls_x509write_crt_set_serial(&crt, &serial_mpi) == 0);
Valerio Settida0afcc2023-01-05 16:46:59 +0100477#else
Valerio Settiaf4815c2023-01-26 17:43:09 +0100478 TEST_ASSERT(mbedtls_x509write_crt_set_serial_raw(&crt, serial_arg->x,
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100479 serial_arg->len) == 0);
Valerio Settida0afcc2023-01-05 16:46:59 +0100480#endif
Gilles Peskine449bd832023-01-11 14:50:10 +0100481 TEST_ASSERT(mbedtls_x509write_crt_set_validity(&crt, not_before,
482 not_after) == 0);
483 mbedtls_x509write_crt_set_md_alg(&crt, md_type);
484 TEST_ASSERT(mbedtls_x509write_crt_set_issuer_name(&crt, issuer_name) == 0);
485 TEST_ASSERT(mbedtls_x509write_crt_set_subject_name(&crt, subject_name) == 0);
486 mbedtls_x509write_crt_set_subject_key(&crt, &subject_key);
Hanno Becker418a6222017-09-14 07:51:28 +0100487
Gilles Peskine449bd832023-01-11 14:50:10 +0100488 mbedtls_x509write_crt_set_issuer_key(&crt, key);
Paul Bakker2397cf32013-09-08 15:58:15 +0200489
Gilles Peskine449bd832023-01-11 14:50:10 +0100490 if (crt.version >= MBEDTLS_X509_CRT_VERSION_3) {
Darren Krahn9c134ce2021-01-13 22:04:45 -0800491 /* For the CA case, a path length of -1 means unlimited. */
Gilles Peskine449bd832023-01-11 14:50:10 +0100492 TEST_ASSERT(mbedtls_x509write_crt_set_basic_constraints(&crt, is_ca,
493 (is_ca ? -1 : 0)) == 0);
494 TEST_ASSERT(mbedtls_x509write_crt_set_subject_key_identifier(&crt) == 0);
495 if (auth_ident) {
496 TEST_ASSERT(mbedtls_x509write_crt_set_authority_key_identifier(&crt) == 0);
497 }
498 if (set_key_usage != 0) {
499 TEST_ASSERT(mbedtls_x509write_crt_set_key_usage(&crt, key_usage) == 0);
500 }
501 if (set_cert_type != 0) {
502 TEST_ASSERT(mbedtls_x509write_crt_set_ns_cert_type(&crt, cert_type) == 0);
503 }
504 if (strcmp(ext_key_usage, "NULL") != 0) {
Dave Rodgmanec9f6b42022-07-27 14:34:58 +0100505 mbedtls_asn1_sequence exts[2];
Gilles Peskine449bd832023-01-11 14:50:10 +0100506 memset(exts, 0, sizeof(exts));
Dave Rodgman5f3f0d02022-08-11 14:38:26 +0100507
508#define SET_OID(x, oid) \
509 do { \
510 x.len = MBEDTLS_OID_SIZE(oid); \
Gilles Peskine449bd832023-01-11 14:50:10 +0100511 x.p = (unsigned char *) oid; \
Dave Rodgman5f3f0d02022-08-11 14:38:26 +0100512 x.tag = MBEDTLS_ASN1_OID; \
Dave Rodgmane2b772d2022-08-11 16:04:13 +0100513 } \
Gilles Peskine449bd832023-01-11 14:50:10 +0100514 while (0)
Dave Rodgman5f3f0d02022-08-11 14:38:26 +0100515
Gilles Peskine449bd832023-01-11 14:50:10 +0100516 if (strcmp(ext_key_usage, "serverAuth") == 0) {
517 SET_OID(exts[0].buf, MBEDTLS_OID_SERVER_AUTH);
518 } else if (strcmp(ext_key_usage, "codeSigning,timeStamping") == 0) {
519 SET_OID(exts[0].buf, MBEDTLS_OID_CODE_SIGNING);
Dave Rodgman5f3f0d02022-08-11 14:38:26 +0100520 exts[0].next = &exts[1];
Gilles Peskine449bd832023-01-11 14:50:10 +0100521 SET_OID(exts[1].buf, MBEDTLS_OID_TIME_STAMPING);
Nicholas Wilsonca841d32015-11-13 14:22:36 +0000522 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100523 TEST_ASSERT(mbedtls_x509write_crt_set_ext_key_usage(&crt, exts) == 0);
Nicholas Wilsonca841d32015-11-13 14:22:36 +0000524 }
Manuel Pégourié-Gonnard6c1a73e2014-03-28 14:03:22 +0100525 }
Paul Bakker2397cf32013-09-08 15:58:15 +0200526
Andrzej Kurek76c96622023-04-04 06:57:08 -0400527 if (set_subjectAltNames) {
528 TEST_ASSERT(mbedtls_x509write_crt_set_subject_alternative_name(&crt, san_list) == 0);
529 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100530 ret = mbedtls_x509write_crt_pem(&crt, buf, sizeof(buf),
531 mbedtls_test_rnd_pseudo_rand, &rnd_info);
532 TEST_ASSERT(ret == 0);
Paul Bakker2397cf32013-09-08 15:58:15 +0200533
Gilles Peskine449bd832023-01-11 14:50:10 +0100534 pem_len = strlen((char *) buf);
Paul Bakker2397cf32013-09-08 15:58:15 +0200535
Paul Elliott557b8d62020-11-19 09:46:56 +0000536 // check that the rest of the buffer remains clear
Gilles Peskine449bd832023-01-11 14:50:10 +0100537 for (buf_index = pem_len; buf_index < sizeof(buf); ++buf_index) {
538 TEST_ASSERT(buf[buf_index] == 0);
Paul Elliott557b8d62020-11-19 09:46:56 +0000539 }
540
Gilles Peskine449bd832023-01-11 14:50:10 +0100541 if (issuer_key_type != MBEDTLS_PK_RSA) {
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100542 mbedtls_x509_crt crt_parse, trusted;
543 uint32_t flags;
Paul Bakker2397cf32013-09-08 15:58:15 +0200544
Gilles Peskine449bd832023-01-11 14:50:10 +0100545 mbedtls_x509_crt_init(&crt_parse);
546 mbedtls_x509_crt_init(&trusted);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100547
Gilles Peskine449bd832023-01-11 14:50:10 +0100548 TEST_ASSERT(mbedtls_x509_crt_parse_file(&trusted,
549 cert_verify_file) == 0);
550 TEST_ASSERT(mbedtls_x509_crt_parse(&crt_parse,
551 buf, sizeof(buf)) == 0);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100552
Gilles Peskine449bd832023-01-11 14:50:10 +0100553 ret = mbedtls_x509_crt_verify(&crt_parse, &trusted, NULL, NULL, &flags,
554 NULL, NULL);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100555
Gilles Peskine449bd832023-01-11 14:50:10 +0100556 mbedtls_x509_crt_free(&crt_parse);
557 mbedtls_x509_crt_free(&trusted);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100558
Gilles Peskine449bd832023-01-11 14:50:10 +0100559 TEST_EQUAL(flags, 0);
560 TEST_EQUAL(ret, 0);
561 } else if (*cert_check_file != '\0') {
562 f = fopen(cert_check_file, "r");
563 TEST_ASSERT(f != NULL);
564 olen = fread(check_buf, 1, sizeof(check_buf), f);
565 fclose(f);
566 TEST_ASSERT(olen < sizeof(check_buf));
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100567
Gilles Peskine449bd832023-01-11 14:50:10 +0100568 TEST_EQUAL(olen, pem_len);
569 TEST_ASSERT(olen >= pem_len - 1);
570 TEST_ASSERT(memcmp(buf, check_buf, pem_len - 1) == 0);
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100571 }
Paul Bakker2397cf32013-09-08 15:58:15 +0200572
Gilles Peskine449bd832023-01-11 14:50:10 +0100573 der_len = mbedtls_x509write_crt_der(&crt, buf, sizeof(buf),
574 mbedtls_test_rnd_pseudo_rand,
575 &rnd_info);
576 TEST_ASSERT(der_len >= 0);
Andres AGe0af9952016-09-07 11:09:44 +0100577
Gilles Peskine449bd832023-01-11 14:50:10 +0100578 if (der_len == 0) {
Andres AGe0af9952016-09-07 11:09:44 +0100579 goto exit;
Gilles Peskine449bd832023-01-11 14:50:10 +0100580 }
Andres AGe0af9952016-09-07 11:09:44 +0100581
Werner Lewisacd01e52022-05-10 12:23:13 +0100582 // Not testing against file, check date format
Gilles Peskine449bd832023-01-11 14:50:10 +0100583 if (*cert_check_file == '\0') {
Werner Lewisacd01e52022-05-10 12:23:13 +0100584 // UTC tag if before 2050, 2 digits less for year
Gilles Peskine449bd832023-01-11 14:50:10 +0100585 if (not_before[0] == '2' && (not_before[1] > '0' || not_before[2] > '4')) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100586 before_tag = MBEDTLS_ASN1_GENERALIZED_TIME;
Gilles Peskine449bd832023-01-11 14:50:10 +0100587 } else {
Werner Lewisacd01e52022-05-10 12:23:13 +0100588 before_tag = MBEDTLS_ASN1_UTC_TIME;
589 not_before += 2;
590 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100591 if (not_after[0] == '2' && (not_after[1] > '0' || not_after[2] > '4')) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100592 after_tag = MBEDTLS_ASN1_GENERALIZED_TIME;
Gilles Peskine449bd832023-01-11 14:50:10 +0100593 } else {
Werner Lewisacd01e52022-05-10 12:23:13 +0100594 after_tag = MBEDTLS_ASN1_UTC_TIME;
595 not_after += 2;
596 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100597 end = buf + sizeof(buf);
598 for (p = end - der_len; p < end;) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100599 tag = *p++;
600 sz = *p++;
Gilles Peskine449bd832023-01-11 14:50:10 +0100601 if (tag == MBEDTLS_ASN1_UTC_TIME || tag == MBEDTLS_ASN1_GENERALIZED_TIME) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100602 // Check correct tag and time written
Gilles Peskine449bd832023-01-11 14:50:10 +0100603 TEST_ASSERT(before_tag == tag);
604 TEST_ASSERT(memcmp(p, not_before, sz - 1) == 0);
Werner Lewisacd01e52022-05-10 12:23:13 +0100605 p += sz;
606 tag = *p++;
607 sz = *p++;
Gilles Peskine449bd832023-01-11 14:50:10 +0100608 TEST_ASSERT(after_tag == tag);
609 TEST_ASSERT(memcmp(p, not_after, sz - 1) == 0);
Werner Lewisacd01e52022-05-10 12:23:13 +0100610 break;
611 }
612 // Increment if long form ASN1 length
Gilles Peskine449bd832023-01-11 14:50:10 +0100613 if (sz & 0x80) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100614 p += sz & 0x0F;
Gilles Peskine449bd832023-01-11 14:50:10 +0100615 }
616 if (tag != (MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE)) {
Werner Lewisacd01e52022-05-10 12:23:13 +0100617 p += sz;
Gilles Peskine449bd832023-01-11 14:50:10 +0100618 }
Werner Lewisacd01e52022-05-10 12:23:13 +0100619 }
Gilles Peskine449bd832023-01-11 14:50:10 +0100620 TEST_ASSERT(p < end);
Werner Lewisacd01e52022-05-10 12:23:13 +0100621 }
622
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100623#if defined(MBEDTLS_USE_PSA_CRYPTO)
Neil Armstronge6ed23c2022-04-22 09:44:04 +0200624 // When using PSA crypto, RNG isn't controllable, result length isn't
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100625 // deterministic over multiple runs, removing a single byte isn't enough to
626 // go into the MBEDTLS_ERR_ASN1_BUF_TOO_SMALL error case
Gilles Peskine449bd832023-01-11 14:50:10 +0100627 if (issuer_key_type != MBEDTLS_PK_RSA) {
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100628 der_len /= 2;
Gilles Peskine449bd832023-01-11 14:50:10 +0100629 } else
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100630#endif
Gilles Peskine449bd832023-01-11 14:50:10 +0100631 der_len -= 1;
Neil Armstrong6ce6dd92022-03-17 09:38:50 +0100632
Gilles Peskine449bd832023-01-11 14:50:10 +0100633 ret = mbedtls_x509write_crt_der(&crt, buf, (size_t) (der_len),
634 mbedtls_test_rnd_pseudo_rand, &rnd_info);
635 TEST_ASSERT(ret == MBEDTLS_ERR_ASN1_BUF_TOO_SMALL);
Andres AGe0af9952016-09-07 11:09:44 +0100636
Paul Bakkerbd51b262014-07-10 15:26:12 +0200637exit:
Andrzej Kurek5da1d752023-04-05 08:30:59 -0400638 mbedtls_asn1_free_named_data_list(&ext_san_dirname);
Gilles Peskine449bd832023-01-11 14:50:10 +0100639 mbedtls_x509write_crt_free(&crt);
640 mbedtls_pk_free(&issuer_key_alt);
641 mbedtls_pk_free(&subject_key);
642 mbedtls_pk_free(&issuer_key);
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100643#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
644 mbedtls_mpi_free(&serial_mpi);
645#endif
Neil Armstrong98f899c2022-03-16 17:42:42 +0100646#if defined(MBEDTLS_USE_PSA_CRYPTO)
Gilles Peskine449bd832023-01-11 14:50:10 +0100647 psa_destroy_key(key_id);
Neil Armstrong98f899c2022-03-16 17:42:42 +0100648#endif
Manuel Pégourié-Gonnard33a13022023-03-17 14:02:49 +0100649 MD_OR_USE_PSA_DONE();
Paul Bakker2397cf32013-09-08 15:58:15 +0200650}
651/* END_CASE */
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200652
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100653/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_WRITE_C */
654void x509_set_serial_check()
655{
656 mbedtls_x509write_cert ctx;
657 uint8_t invalid_serial[MBEDTLS_X509_RFC5280_MAX_SERIAL_LEN + 1];
658
David Horstmanne04a97a2023-12-08 18:27:48 +0000659#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
660 mbedtls_mpi serial_mpi;
661 mbedtls_mpi_init(&serial_mpi);
662#endif
663
Valerio Setti569c1712023-04-19 14:53:36 +0200664 USE_PSA_INIT();
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100665 memset(invalid_serial, 0x01, sizeof(invalid_serial));
666
Valerio Settiea19d2d2023-01-09 17:21:17 +0100667#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100668 TEST_EQUAL(mbedtls_mpi_read_binary(&serial_mpi, invalid_serial,
669 sizeof(invalid_serial)), 0);
670 TEST_EQUAL(mbedtls_x509write_crt_set_serial(&ctx, &serial_mpi),
671 MBEDTLS_ERR_X509_BAD_INPUT_DATA);
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100672#endif
673
Valerio Settiaf4815c2023-01-26 17:43:09 +0100674 TEST_EQUAL(mbedtls_x509write_crt_set_serial_raw(&ctx, invalid_serial,
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100675 sizeof(invalid_serial)),
676 MBEDTLS_ERR_X509_BAD_INPUT_DATA);
677
Valerio Settia87f8392023-01-26 18:00:50 +0100678exit:
679#if defined(MBEDTLS_TEST_DEPRECATED) && defined(MBEDTLS_BIGNUM_C)
680 mbedtls_mpi_free(&serial_mpi);
681#else
682 ;
683#endif
Valerio Setti569c1712023-04-19 14:53:36 +0200684 USE_PSA_DONE();
Valerio Settiaad8dbd2023-01-09 17:20:25 +0100685}
686/* END_CASE */
687
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200688/* BEGIN_CASE depends_on:MBEDTLS_X509_CREATE_C:MBEDTLS_X509_USE_C */
Gilles Peskinec94500b2023-09-21 18:01:05 +0200689void mbedtls_x509_string_to_names(char *name, char *parsed_name,
690 int result, int may_fail)
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200691{
692 int ret;
693 size_t len = 0;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200694 mbedtls_asn1_named_data *names = NULL;
Gilles Peskine21e46b32023-10-17 16:35:20 +0200695 mbedtls_x509_name parsed;
696 memset(&parsed, 0, sizeof(parsed));
697 mbedtls_x509_name *parsed_cur = NULL;
698 mbedtls_x509_name *parsed_prv = NULL;
Gilles Peskinef2574202023-10-18 17:39:48 +0200699 unsigned char buf[1024] = { 0 };
700 unsigned char out[1024] = { 0 };
Gilles Peskine21e46b32023-10-17 16:35:20 +0200701 unsigned char *c = buf + sizeof(buf);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200702
Valerio Setti569c1712023-04-19 14:53:36 +0200703 USE_PSA_INIT();
704
Gilles Peskine449bd832023-01-11 14:50:10 +0100705 ret = mbedtls_x509_string_to_names(&names, name);
Gilles Peskine1c7223b2023-09-21 14:02:05 +0200706 TEST_EQUAL(ret, result);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200707
Gilles Peskine449bd832023-01-11 14:50:10 +0100708 if (ret != 0) {
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200709 goto exit;
Gilles Peskine449bd832023-01-11 14:50:10 +0100710 }
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200711
Gilles Peskine449bd832023-01-11 14:50:10 +0100712 ret = mbedtls_x509_write_names(&c, buf, names);
Gilles Peskine1c7223b2023-09-21 14:02:05 +0200713 TEST_LE_S(1, ret);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200714
Gilles Peskine1c7223b2023-09-21 14:02:05 +0200715 TEST_EQUAL(mbedtls_asn1_get_tag(&c, buf + sizeof(buf), &len,
Gilles Peskineaa01a032023-09-21 15:57:30 +0200716 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE), 0);
Gilles Peskinec94500b2023-09-21 18:01:05 +0200717 ret = mbedtls_x509_get_name(&c, buf + sizeof(buf), &parsed);
718 if ((may_fail & MAY_FAIL_GET_NAME) && ret < 0) {
719 /* Validation inconsistency between mbedtls_x509_string_to_names() and
720 * mbedtls_x509_get_name(). Accept it for now. */
721 goto exit;
722 }
723 TEST_EQUAL(ret, 0);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200724
Gilles Peskine449bd832023-01-11 14:50:10 +0100725 ret = mbedtls_x509_dn_gets((char *) out, sizeof(out), &parsed);
Gilles Peskinec94500b2023-09-21 18:01:05 +0200726 if ((may_fail & MAY_FAIL_DN_GETS) && ret < 0) {
727 /* Validation inconsistency between mbedtls_x509_string_to_names() and
728 * mbedtls_x509_dn_gets(). Accept it for now. */
729 goto exit;
730 }
Gilles Peskine1c7223b2023-09-21 14:02:05 +0200731 TEST_LE_S(1, ret);
Gilles Peskine449bd832023-01-11 14:50:10 +0100732 TEST_ASSERT(strcmp((char *) out, parsed_name) == 0);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200733
Manuel Pégourié-Gonnardf9ac5e72025-05-05 18:25:26 +0200734 /* Check that calling a 2nd time with the same param (now non-NULL)
735 * returns an error as expected. */
736 ret = mbedtls_x509_string_to_names(&names, name);
737 TEST_EQUAL(ret, MBEDTLS_ERR_X509_BAD_INPUT_DATA);
738
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200739exit:
Gilles Peskine449bd832023-01-11 14:50:10 +0100740 mbedtls_asn1_free_named_data_list(&names);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200741
742 parsed_cur = parsed.next;
Gilles Peskine449bd832023-01-11 14:50:10 +0100743 while (parsed_cur != 0) {
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200744 parsed_prv = parsed_cur;
745 parsed_cur = parsed_cur->next;
Gilles Peskine449bd832023-01-11 14:50:10 +0100746 mbedtls_free(parsed_prv);
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200747 }
Valerio Setti569c1712023-04-19 14:53:36 +0200748 USE_PSA_DONE();
Paul Bakker8dcb2d72014-08-08 12:22:30 +0200749}
750/* END_CASE */
Jonathan Winzig2bd2b782024-01-09 15:19:42 +0100751
Jonathan Winzig315c3ca2024-01-09 18:31:11 +0100752/* BEGIN_CASE depends_on:MBEDTLS_X509_CSR_WRITE_C */
Jonathan Winzig6c9779f2024-01-09 17:47:10 +0100753void x509_set_extension_length_check()
Jonathan Winzig2bd2b782024-01-09 15:19:42 +0100754{
755 int ret = 0;
756
757 mbedtls_x509write_csr ctx;
758 mbedtls_x509write_csr_init(&ctx);
759
760 unsigned char buf[EXT_KEY_USAGE_TMP_BUF_MAX_LENGTH] = { 0 };
761 unsigned char *p = buf + sizeof(buf);
762
763 ret = mbedtls_x509_set_extension(&(ctx.MBEDTLS_PRIVATE(extensions)),
764 MBEDTLS_OID_EXTENDED_KEY_USAGE,
765 MBEDTLS_OID_SIZE(MBEDTLS_OID_EXTENDED_KEY_USAGE),
766 0,
767 p,
Jonathan Winzig6c9779f2024-01-09 17:47:10 +0100768 SIZE_MAX);
769 TEST_ASSERT(MBEDTLS_ERR_X509_BAD_INPUT_DATA == ret);
Jonathan Winzig2bd2b782024-01-09 15:19:42 +0100770}
771/* END_CASE */