blob: 4f659bee6a96f92edcd6792e5815b70f59ae3162 [file] [log] [blame]
Yingdi Yub263f152015-07-12 16:50:13 -07001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
Davide Pesavento6158f472017-08-11 18:55:09 -04002/*
Davide Pesavento47ce2ee2023-05-09 01:33:33 -04003 * Copyright (c) 2013-2023 Regents of the University of California.
Yingdi Yub263f152015-07-12 16:50:13 -07004 *
5 * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
6 *
7 * ndn-cxx library is free software: you can redistribute it and/or modify it under the
8 * terms of the GNU Lesser General Public License as published by the Free Software
9 * Foundation, either version 3 of the License, or (at your option) any later version.
10 *
11 * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License and GNU Lesser
16 * General Public License along with ndn-cxx, e.g., in COPYING.md file. If not, see
17 * <http://www.gnu.org/licenses/>.
18 *
19 * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
20 */
21
Davide Pesavento7e780642018-11-24 15:51:34 -050022#include "ndn-cxx/security/transform/verifier-filter.hpp"
Yingdi Yub263f152015-07-12 16:50:13 -070023
Davide Pesavento7e780642018-11-24 15:51:34 -050024#include "ndn-cxx/encoding/buffer-stream.hpp"
Laqin Fan0fe72ea2019-05-22 16:42:59 -050025#include "ndn-cxx/security/key-params.hpp"
Davide Pesavento7e780642018-11-24 15:51:34 -050026#include "ndn-cxx/security/transform/base64-decode.hpp"
27#include "ndn-cxx/security/transform/bool-sink.hpp"
28#include "ndn-cxx/security/transform/buffer-source.hpp"
29#include "ndn-cxx/security/transform/private-key.hpp"
30#include "ndn-cxx/security/transform/public-key.hpp"
31#include "ndn-cxx/security/transform/signer-filter.hpp"
32#include "ndn-cxx/security/transform/stream-sink.hpp"
Yingdi Yub263f152015-07-12 16:50:13 -070033
Davide Pesavento7e780642018-11-24 15:51:34 -050034#include "tests/boost-test.hpp"
Yingdi Yub263f152015-07-12 16:50:13 -070035
Davide Pesavento80d671f2022-06-08 04:04:52 -040036#include <openssl/opensslv.h>
37
Davide Pesavento47ce2ee2023-05-09 01:33:33 -040038namespace ndn::tests {
39
40using namespace ndn::security::transform;
Yingdi Yub263f152015-07-12 16:50:13 -070041
42BOOST_AUTO_TEST_SUITE(Security)
43BOOST_AUTO_TEST_SUITE(Transform)
44BOOST_AUTO_TEST_SUITE(TestVerifierFilter)
45
Laqin Fan0fe72ea2019-05-22 16:42:59 -050046const uint8_t DATA[] = {0x01, 0x02, 0x03, 0x04};
47
Yingdi Yub263f152015-07-12 16:50:13 -070048BOOST_AUTO_TEST_CASE(Rsa)
49{
Davide Pesavento6158f472017-08-11 18:55:09 -040050 const std::string publicKeyPkcs8 =
Yingdi Yub263f152015-07-12 16:50:13 -070051 "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw0WM1/WhAxyLtEqsiAJg\n"
52 "WDZWuzkYpeYVdeeZcqRZzzfRgBQTsNozS5t4HnwTZhwwXbH7k3QN0kRTV826Xobw\n"
53 "s3iigohnM9yTK+KKiayPhIAm/+5HGT6SgFJhYhqo1/upWdueojil6RP4/AgavHho\n"
54 "pxlAVbk6G9VdVnlQcQ5Zv0OcGi73c+EnYD/YgURYGSngUi/Ynsh779p2U69/te9g\n"
55 "ZwIL5PuE9BiO6I39cL9z7EK1SfZhOWvDe/qH7YhD/BHwcWit8FjRww1glwRVTJsA\n"
56 "9rH58ynaAix0tcR/nBMRLUX+e3rURHg6UbSjJbdb9qmKM1fTGHKUzL/5pMG6uBU0\n"
57 "ywIDAQAB\n";
Davide Pesavento6158f472017-08-11 18:55:09 -040058 const std::string privateKeyPkcs1 =
Yingdi Yub263f152015-07-12 16:50:13 -070059 "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDDRYzX9aEDHIu0\n"
60 "SqyIAmBYNla7ORil5hV155lypFnPN9GAFBOw2jNLm3gefBNmHDBdsfuTdA3SRFNX\n"
61 "zbpehvCzeKKCiGcz3JMr4oqJrI+EgCb/7kcZPpKAUmFiGqjX+6lZ256iOKXpE/j8\n"
62 "CBq8eGinGUBVuTob1V1WeVBxDlm/Q5waLvdz4SdgP9iBRFgZKeBSL9ieyHvv2nZT\n"
63 "r3+172BnAgvk+4T0GI7ojf1wv3PsQrVJ9mE5a8N7+oftiEP8EfBxaK3wWNHDDWCX\n"
64 "BFVMmwD2sfnzKdoCLHS1xH+cExEtRf57etREeDpRtKMlt1v2qYozV9MYcpTMv/mk\n"
65 "wbq4FTTLAgMBAAECggEANCRyQ4iXghkxROdbwsW/rE52QnAwoLwbpuw9EVvJj4e8\n"
66 "LZMu3t6lK99L5/gBxhZo49wO7YTj2+3aw2twBKXLyGDCJFEAHd0cf29yxuiJOjxu\n"
67 "LZEW8yq+O/3De0rbIzFUO2ZlqbOuudpXdhVD7mfIqjYX88wONDh5QAoM7OOEG4oe\n"
68 "xkFMWcDUwU0j5QqPlfhinrgMWYqXFNf9TZvDNXLCjmHPHZSHDnWOaguWzhhS8wlc\n"
69 "PTBblm1hG4+iBe9dv+h/15//bT/BTXVYUqBdviB9HzNRdpdLWxdydWbf7bi8iz10\n"
70 "ClTDKS6jKM6rFapwdF5zZBPYXFUaQUStrN4I9riswQKBgQDljwLLCiYhxOB6sUYU\n"
71 "J4wcmvydAapjZX+jAVveT2ZpzM+cL2nhr1FzmzMvED0UxgXG6tBkwFZIQbYlLUdH\n"
72 "aaeOKDHxQqNgwv8D6u++Nk4x7gzpLLaCCHhKQtkqlZPONN7TsHIz+Pm/9KM1mFYA\n"
73 "buzDj8uY8ZFCTAm/4pmEaiO46QKBgQDZw4VPpwlG/qS/NPP1LQI5k5Wb564mH8Fe\n"
74 "nugCwCZs186lyQ8zOodfLz/Cl0qXoABwHns67O2U19XUPuq9vPsm5GVjBDRwR8GB\n"
75 "tk9zPWnXwccNeHCfntk9vwbfdiH06aDQc0AiZvguxW5KrEDo3BKPtylF6SBN52uE\n"
76 "sU8n5h1vkwKBgQCwzdDs6MgtwiDS3q6G316+uXBOzPWa0JXZyjYjpyvN2P0d4ja+\n"
77 "p/UoASUO3obs9QeGCVyv/KN3y4SqZZE8o1d12ed9VkHXSNh4//3elpzrP9mZzeJT\n"
78 "jIp5R7tTXRkV/QqSKJgNB3n0Kkt5//ZdJxIcHShGh+fFFCN+Mtzia41P4QKBgQCV\n"
79 "wOTTow45OXL4XyUJzVsDV2ACaDAV3a6wMF1jTtrd7QcacYs3cp+XsLmLS1mrrge/\n"
80 "Eucx3a+AtXFCVcY+l1CsLVMf5cteD6qeVk6K9IfuLT+DHvlse+Pvl4fVcrrlXykN\n"
81 "UMShI+i22WUAizbULEvDc3U5s5lYmbYR+ZFy4cgKawKBgC0UnWJ2oygfERLeaVGl\n"
82 "/YnHJC50/dIKbZakaapXOFFgiep5q1jmxR2U8seb+nvtFPsTLFAdOXCfwUk+4z/h\n"
83 "kfWtB3+8H5jyoC1gkJ7EMyxu8tb4mz5U6+SPB4QLSetwvfWP2YXS/PkTq19G7iGE\n"
84 "novjJ9azSBJ6OyR5UH/DxBji\n";
Yingdi Yub263f152015-07-12 16:50:13 -070085
86 OBufferStream os1;
87 bufferSource(publicKeyPkcs8) >> base64Decode() >> streamSink(os1);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -040088 auto pubKey = os1.buf();
Yingdi Yub263f152015-07-12 16:50:13 -070089
90 PublicKey pKey;
Davide Pesavento765abc92021-12-27 00:44:04 -050091 pKey.loadPkcs8(*pubKey);
Davide Pesavento6158f472017-08-11 18:55:09 -040092
93 PrivateKey sKey;
Davide Pesavento765abc92021-12-27 00:44:04 -050094 sKey.loadPkcs1Base64({reinterpret_cast<const uint8_t*>(privateKeyPkcs1.data()),
95 privateKeyPkcs1.size()});
Davide Pesavento6158f472017-08-11 18:55:09 -040096
97 OBufferStream os2;
Davide Pesavento765abc92021-12-27 00:44:04 -050098 bufferSource(DATA) >> signerFilter(DigestAlgorithm::SHA256, sKey) >> streamSink(os2);
Davide Pesavento6158f472017-08-11 18:55:09 -040099 auto sig = os2.buf();
100
Davide Pesavento35c63792022-01-17 02:06:03 -0500101 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::NONE, pKey, *sig), Error);
102 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, sKey, *sig), Error);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400103
Davide Pesavento6158f472017-08-11 18:55:09 -0400104 bool result = false;
Davide Pesavento765abc92021-12-27 00:44:04 -0500105 bufferSource(DATA) >>
Davide Pesavento35c63792022-01-17 02:06:03 -0500106 verifierFilter(DigestAlgorithm::SHA256, pKey, *sig) >>
Davide Pesavento6158f472017-08-11 18:55:09 -0400107 boolSink(result);
Yingdi Yub263f152015-07-12 16:50:13 -0700108
109 BOOST_CHECK_EQUAL(result, true);
110}
111
112BOOST_AUTO_TEST_CASE(Ecdsa)
113{
Davide Pesavento6158f472017-08-11 18:55:09 -0400114 const std::string privateKeyPkcs1 =
Yingdi Yub263f152015-07-12 16:50:13 -0700115 "MIIBeQIBADCCAQMGByqGSM49AgEwgfcCAQEwLAYHKoZIzj0BAQIhAP////8AAAAB\n"
116 "AAAAAAAAAAAAAAAA////////////////MFsEIP////8AAAABAAAAAAAAAAAAAAAA\n"
117 "///////////////8BCBaxjXYqjqT57PrvVV2mIa8ZR0GsMxTsPY7zjw+J9JgSwMV\n"
118 "AMSdNgiG5wSTamZ44ROdJreBn36QBEEEaxfR8uEsQkf4vOblY6RA8ncDfYEt6zOg\n"
119 "9KE5RdiYwpZP40Li/hp/m47n60p8D54WK84zV2sxXs7LtkBoN79R9QIhAP////8A\n"
120 "AAAA//////////+85vqtpxeehPO5ysL8YyVRAgEBBG0wawIBAQQgRxwcbzK9RV6A\n"
121 "HYFsDcykI86o3M/a1KlJn0z8PcLMBZOhRANCAARobhYm4MC3RCQQzi3b0oNR3ORC\n"
122 "Uw8aupbORaGC304afBzo7sBks9KsPKHDKspLtctFeaXkOKxD3dG8HKWXfbLw\n";
Davide Pesavento6158f472017-08-11 18:55:09 -0400123 const std::string publicKeyPkcs8 =
Yingdi Yub263f152015-07-12 16:50:13 -0700124 "MIIBSzCCAQMGByqGSM49AgEwgfcCAQEwLAYHKoZIzj0BAQIhAP////8AAAABAAAA\n"
125 "AAAAAAAAAAAA////////////////MFsEIP////8AAAABAAAAAAAAAAAAAAAA////\n"
126 "///////////8BCBaxjXYqjqT57PrvVV2mIa8ZR0GsMxTsPY7zjw+J9JgSwMVAMSd\n"
127 "NgiG5wSTamZ44ROdJreBn36QBEEEaxfR8uEsQkf4vOblY6RA8ncDfYEt6zOg9KE5\n"
128 "RdiYwpZP40Li/hp/m47n60p8D54WK84zV2sxXs7LtkBoN79R9QIhAP////8AAAAA\n"
129 "//////////+85vqtpxeehPO5ysL8YyVRAgEBA0IABGhuFibgwLdEJBDOLdvSg1Hc\n"
130 "5EJTDxq6ls5FoYLfThp8HOjuwGSz0qw8ocMqyku1y0V5peQ4rEPd0bwcpZd9svA=\n";
Yingdi Yub263f152015-07-12 16:50:13 -0700131
132 OBufferStream os1;
133 bufferSource(publicKeyPkcs8) >> base64Decode() >> streamSink(os1);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400134 auto pubKey = os1.buf();
Yingdi Yub263f152015-07-12 16:50:13 -0700135
136 PublicKey pKey;
Davide Pesavento765abc92021-12-27 00:44:04 -0500137 pKey.loadPkcs8(*pubKey);
Davide Pesavento6158f472017-08-11 18:55:09 -0400138
139 PrivateKey sKey;
Davide Pesavento765abc92021-12-27 00:44:04 -0500140 sKey.loadPkcs1Base64({reinterpret_cast<const uint8_t*>(privateKeyPkcs1.data()),
141 privateKeyPkcs1.size()});
Davide Pesavento6158f472017-08-11 18:55:09 -0400142
143 OBufferStream os2;
Davide Pesavento765abc92021-12-27 00:44:04 -0500144 bufferSource(DATA) >> signerFilter(DigestAlgorithm::SHA256, sKey) >> streamSink(os2);
Davide Pesavento6158f472017-08-11 18:55:09 -0400145 auto sig = os2.buf();
146
Davide Pesavento35c63792022-01-17 02:06:03 -0500147 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::NONE, pKey, *sig), Error);
148 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, sKey, *sig), Error);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400149
Davide Pesavento6158f472017-08-11 18:55:09 -0400150 bool result = false;
Davide Pesavento765abc92021-12-27 00:44:04 -0500151 bufferSource(DATA) >>
Davide Pesavento35c63792022-01-17 02:06:03 -0500152 verifierFilter(DigestAlgorithm::SHA256, pKey, *sig) >>
Davide Pesavento6158f472017-08-11 18:55:09 -0400153 boolSink(result);
Yingdi Yub263f152015-07-12 16:50:13 -0700154
155 BOOST_CHECK_EQUAL(result, true);
156}
157
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500158BOOST_AUTO_TEST_CASE(Hmac)
159{
160 auto sKey = generatePrivateKey(HmacKeyParams());
161
162 OBufferStream os;
Davide Pesavento765abc92021-12-27 00:44:04 -0500163 bufferSource(DATA) >> signerFilter(DigestAlgorithm::SHA256, *sKey) >> streamSink(os);
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500164 auto sig = os.buf();
165
Davide Pesavento35c63792022-01-17 02:06:03 -0500166 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::NONE, *sKey, *sig), Error);
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500167
168 bool result = false;
Davide Pesavento765abc92021-12-27 00:44:04 -0500169 bufferSource(DATA) >>
Davide Pesavento35c63792022-01-17 02:06:03 -0500170 verifierFilter(DigestAlgorithm::SHA256, *sKey, *sig) >>
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500171 boolSink(result);
172
173 BOOST_CHECK_EQUAL(result, true);
174}
175
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400176BOOST_AUTO_TEST_CASE(InvalidKey)
177{
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500178 PublicKey pubKey;
Davide Pesavento35c63792022-01-17 02:06:03 -0500179 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, pubKey, {}), Error);
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500180 PrivateKey privKey;
Davide Pesavento35c63792022-01-17 02:06:03 -0500181 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, privKey, {}), Error);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400182}
183
Yingdi Yub263f152015-07-12 16:50:13 -0700184BOOST_AUTO_TEST_SUITE_END() // TestVerifierFilter
185BOOST_AUTO_TEST_SUITE_END() // Transform
186BOOST_AUTO_TEST_SUITE_END() // Security
187
Davide Pesavento47ce2ee2023-05-09 01:33:33 -0400188} // namespace ndn::tests