xref: /freebsd/crypto/openssl/test/x509_acert_test.c (revision e7be843b4a162e68651d3911f0357ed464915629)
1*e7be843bSPierre Pronchery /*
2*e7be843bSPierre Pronchery  * Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.
3*e7be843bSPierre Pronchery  *
4*e7be843bSPierre Pronchery  * Licensed under the Apache License 2.0 (the "License").  You may not use
5*e7be843bSPierre Pronchery  * this file except in compliance with the License.  You can obtain a copy
6*e7be843bSPierre Pronchery  * in the file LICENSE in the source distribution or at
7*e7be843bSPierre Pronchery  * https://www.openssl.org/source/license.html
8*e7be843bSPierre Pronchery  */
9*e7be843bSPierre Pronchery 
10*e7be843bSPierre Pronchery #include <openssl/pem.h>
11*e7be843bSPierre Pronchery #include <openssl/rsa.h>
12*e7be843bSPierre Pronchery #include <openssl/x509_acert.h>
13*e7be843bSPierre Pronchery 
14*e7be843bSPierre Pronchery #include "testutil.h"
15*e7be843bSPierre Pronchery 
test_print_acert(int idx)16*e7be843bSPierre Pronchery static int test_print_acert(int idx)
17*e7be843bSPierre Pronchery {
18*e7be843bSPierre Pronchery     int ret = 0;
19*e7be843bSPierre Pronchery     const char *acert_file;
20*e7be843bSPierre Pronchery     X509_ACERT *acert = NULL;
21*e7be843bSPierre Pronchery     BIO *bp, *bout;
22*e7be843bSPierre Pronchery 
23*e7be843bSPierre Pronchery     if (!TEST_ptr(acert_file = test_get_argument(idx)))
24*e7be843bSPierre Pronchery         return 0;
25*e7be843bSPierre Pronchery 
26*e7be843bSPierre Pronchery     if (!TEST_ptr(bp = BIO_new_file(acert_file, "r")))
27*e7be843bSPierre Pronchery         return 0;
28*e7be843bSPierre Pronchery 
29*e7be843bSPierre Pronchery     if (!TEST_ptr(bout = BIO_new_fp(stderr, BIO_NOCLOSE)))
30*e7be843bSPierre Pronchery         goto err;
31*e7be843bSPierre Pronchery 
32*e7be843bSPierre Pronchery     if (!TEST_ptr(acert = PEM_read_bio_X509_ACERT(bp, NULL, NULL, NULL)))
33*e7be843bSPierre Pronchery         goto err;
34*e7be843bSPierre Pronchery 
35*e7be843bSPierre Pronchery     if (!TEST_int_eq(X509_ACERT_print(bout, acert), 1)) {
36*e7be843bSPierre Pronchery         goto err;
37*e7be843bSPierre Pronchery     }
38*e7be843bSPierre Pronchery 
39*e7be843bSPierre Pronchery     ret = 1;
40*e7be843bSPierre Pronchery 
41*e7be843bSPierre Pronchery err:
42*e7be843bSPierre Pronchery     BIO_free(bp);
43*e7be843bSPierre Pronchery     BIO_free(bout);
44*e7be843bSPierre Pronchery     X509_ACERT_free(acert);
45*e7be843bSPierre Pronchery     return ret;
46*e7be843bSPierre Pronchery }
47*e7be843bSPierre Pronchery 
test_acert_sign(void)48*e7be843bSPierre Pronchery static int test_acert_sign(void)
49*e7be843bSPierre Pronchery {
50*e7be843bSPierre Pronchery     int ret = 0;
51*e7be843bSPierre Pronchery     const char *acert_file;
52*e7be843bSPierre Pronchery     EVP_PKEY *pkey;
53*e7be843bSPierre Pronchery     BIO *bp = NULL;
54*e7be843bSPierre Pronchery     X509_ACERT *acert = NULL;
55*e7be843bSPierre Pronchery 
56*e7be843bSPierre Pronchery     if (!TEST_ptr(acert_file = test_get_argument(0)))
57*e7be843bSPierre Pronchery         return 0;
58*e7be843bSPierre Pronchery 
59*e7be843bSPierre Pronchery     if (!TEST_ptr(pkey = EVP_RSA_gen(2048)))
60*e7be843bSPierre Pronchery         return 0;
61*e7be843bSPierre Pronchery 
62*e7be843bSPierre Pronchery     if (!TEST_ptr(bp = BIO_new_file(acert_file, "r")))
63*e7be843bSPierre Pronchery         goto err;
64*e7be843bSPierre Pronchery 
65*e7be843bSPierre Pronchery     if (!TEST_ptr(acert = PEM_read_bio_X509_ACERT(bp, NULL, NULL, NULL)))
66*e7be843bSPierre Pronchery         goto err;
67*e7be843bSPierre Pronchery 
68*e7be843bSPierre Pronchery     if (!TEST_int_gt(X509_ACERT_sign(acert, pkey, EVP_sha256()), 0) ||
69*e7be843bSPierre Pronchery         !TEST_int_eq(X509_ACERT_verify(acert, pkey), 1))
70*e7be843bSPierre Pronchery         goto err;
71*e7be843bSPierre Pronchery 
72*e7be843bSPierre Pronchery     ret = 1;
73*e7be843bSPierre Pronchery 
74*e7be843bSPierre Pronchery err:
75*e7be843bSPierre Pronchery     BIO_free(bp);
76*e7be843bSPierre Pronchery     X509_ACERT_free(acert);
77*e7be843bSPierre Pronchery     EVP_PKEY_free(pkey);
78*e7be843bSPierre Pronchery     return ret;
79*e7be843bSPierre Pronchery }
80*e7be843bSPierre Pronchery 
81*e7be843bSPierre Pronchery /* IetfAttrSyntax structure with one value */
82*e7be843bSPierre Pronchery static const unsigned char attr_syntax_single[] = {
83*e7be843bSPierre Pronchery   0x30, 0x15, 0xa0, 0x09, 0x86, 0x07, 0x54, 0x65, 0x73, 0x74, 0x76, 0x61,
84*e7be843bSPierre Pronchery   0x6c, 0x30, 0x08, 0x0c, 0x06, 0x67, 0x72, 0x6f, 0x75, 0x70, 0x31
85*e7be843bSPierre Pronchery };
86*e7be843bSPierre Pronchery 
87*e7be843bSPierre Pronchery /* IetfAttrSyntax structure with multiple values of the same type */
88*e7be843bSPierre Pronchery static const unsigned char attr_syntax_multiple[] = {
89*e7be843bSPierre Pronchery   0x30, 0x1d, 0x30, 0x1b, 0x0c, 0x07, 0x67, 0x72, 0x6f, 0x75, 0x70, 0x20,
90*e7be843bSPierre Pronchery   0x31, 0x0c, 0x07, 0x67, 0x72, 0x6f, 0x75, 0x70, 0x20, 0x32, 0x0c, 0x07,
91*e7be843bSPierre Pronchery   0x67, 0x72, 0x6f, 0x75, 0x70, 0x20, 0x33
92*e7be843bSPierre Pronchery };
93*e7be843bSPierre Pronchery 
94*e7be843bSPierre Pronchery /* IetfAttrSyntax structure with multiple values of different types */
95*e7be843bSPierre Pronchery static const unsigned char attr_syntax_diff_type[] = {
96*e7be843bSPierre Pronchery   0x30, 0x11, 0x30, 0x0f, 0x04, 0x08, 0x64, 0x65, 0x61, 0x64, 0x63, 0x6f,
97*e7be843bSPierre Pronchery   0x64, 0x65, 0x0c, 0x03, 0x61, 0x61, 0x61
98*e7be843bSPierre Pronchery };
99*e7be843bSPierre Pronchery 
100*e7be843bSPierre Pronchery /* IetfAttrSyntax structure with an invalid/unsupported value type */
101*e7be843bSPierre Pronchery static const unsigned char attr_syntax_invalid_type[] = {
102*e7be843bSPierre Pronchery   0x30, 0x05, 0x30, 0x03, 0x02, 0x01, 0x0a
103*e7be843bSPierre Pronchery };
104*e7be843bSPierre Pronchery 
105*e7be843bSPierre Pronchery #define ADD_TEST_DATA(x, valid) {x, sizeof(x), valid}
106*e7be843bSPierre Pronchery 
107*e7be843bSPierre Pronchery struct ietf_type_test_data {
108*e7be843bSPierre Pronchery     const unsigned char *data;
109*e7be843bSPierre Pronchery     size_t len;
110*e7be843bSPierre Pronchery     int valid;
111*e7be843bSPierre Pronchery };
112*e7be843bSPierre Pronchery 
113*e7be843bSPierre Pronchery static const struct ietf_type_test_data ietf_syntax_tests[] = {
114*e7be843bSPierre Pronchery     ADD_TEST_DATA(attr_syntax_single, 1),
115*e7be843bSPierre Pronchery     ADD_TEST_DATA(attr_syntax_multiple, 1),
116*e7be843bSPierre Pronchery     ADD_TEST_DATA(attr_syntax_diff_type, 0),
117*e7be843bSPierre Pronchery     ADD_TEST_DATA(attr_syntax_invalid_type, 0),
118*e7be843bSPierre Pronchery };
119*e7be843bSPierre Pronchery 
test_object_group_attr(int idx)120*e7be843bSPierre Pronchery static int test_object_group_attr(int idx)
121*e7be843bSPierre Pronchery {
122*e7be843bSPierre Pronchery     int ret = 0;
123*e7be843bSPierre Pronchery     OSSL_IETF_ATTR_SYNTAX *ias = NULL;
124*e7be843bSPierre Pronchery     BIO *bout = NULL;
125*e7be843bSPierre Pronchery     const unsigned char *p;
126*e7be843bSPierre Pronchery     const struct ietf_type_test_data *test = &ietf_syntax_tests[idx];
127*e7be843bSPierre Pronchery 
128*e7be843bSPierre Pronchery     if (!TEST_ptr(bout = BIO_new_fp(stderr, BIO_NOCLOSE)))
129*e7be843bSPierre Pronchery         goto done;
130*e7be843bSPierre Pronchery 
131*e7be843bSPierre Pronchery     p = test->data;
132*e7be843bSPierre Pronchery 
133*e7be843bSPierre Pronchery     ias = d2i_OSSL_IETF_ATTR_SYNTAX(NULL, &p, test->len);
134*e7be843bSPierre Pronchery 
135*e7be843bSPierre Pronchery     if ((test->valid && !TEST_ptr(ias))
136*e7be843bSPierre Pronchery             || (!test->valid && !TEST_ptr_null(ias)))
137*e7be843bSPierre Pronchery         goto done;
138*e7be843bSPierre Pronchery 
139*e7be843bSPierre Pronchery     if (ias != NULL
140*e7be843bSPierre Pronchery             && !TEST_int_eq(OSSL_IETF_ATTR_SYNTAX_print(bout, ias, 4), 1)) {
141*e7be843bSPierre Pronchery         OSSL_IETF_ATTR_SYNTAX_free(ias);
142*e7be843bSPierre Pronchery         goto done;
143*e7be843bSPierre Pronchery     }
144*e7be843bSPierre Pronchery 
145*e7be843bSPierre Pronchery     ret = 1;
146*e7be843bSPierre Pronchery 
147*e7be843bSPierre Pronchery done:
148*e7be843bSPierre Pronchery     OSSL_IETF_ATTR_SYNTAX_free(ias);
149*e7be843bSPierre Pronchery     BIO_free(bout);
150*e7be843bSPierre Pronchery     return ret;
151*e7be843bSPierre Pronchery }
152*e7be843bSPierre Pronchery 
153*e7be843bSPierre Pronchery OPT_TEST_DECLARE_USAGE("[<attribute certs (PEM)>...]\n")
setup_tests(void)154*e7be843bSPierre Pronchery int setup_tests(void)
155*e7be843bSPierre Pronchery {
156*e7be843bSPierre Pronchery     int cnt;
157*e7be843bSPierre Pronchery 
158*e7be843bSPierre Pronchery     if (!test_skip_common_options()) {
159*e7be843bSPierre Pronchery         TEST_error("Error parsing test options\n");
160*e7be843bSPierre Pronchery         return 0;
161*e7be843bSPierre Pronchery     }
162*e7be843bSPierre Pronchery 
163*e7be843bSPierre Pronchery     cnt = test_get_argument_count();
164*e7be843bSPierre Pronchery     if (cnt < 1) {
165*e7be843bSPierre Pronchery         TEST_error("Must specify at least 1 attribute certificate file\n");
166*e7be843bSPierre Pronchery         return 0;
167*e7be843bSPierre Pronchery     }
168*e7be843bSPierre Pronchery 
169*e7be843bSPierre Pronchery     ADD_ALL_TESTS(test_print_acert, cnt);
170*e7be843bSPierre Pronchery     ADD_TEST(test_acert_sign);
171*e7be843bSPierre Pronchery     ADD_ALL_TESTS(test_object_group_attr, OSSL_NELEM(ietf_syntax_tests));
172*e7be843bSPierre Pronchery 
173*e7be843bSPierre Pronchery     return 1;
174*e7be843bSPierre Pronchery }
175