blob: 2317479136c78f11c7e17f5e71b6d7e1690cdd20 [file] [log] [blame]
Yingdi Yu202a2e92015-07-12 16:49:25 -07001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
Davide Pesaventoa84f4642017-08-23 16:14:51 -04002/*
Laqin Fan0fe72ea2019-05-22 16:42:59 -05003 * Copyright (c) 2013-2019 Regents of the University of California.
Yingdi Yu202a2e92015-07-12 16:49:25 -07004 *
5 * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
6 *
7 * ndn-cxx library is free software: you can redistribute it and/or modify it under the
8 * terms of the GNU Lesser General Public License as published by the Free Software
9 * Foundation, either version 3 of the License, or (at your option) any later version.
10 *
11 * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License and GNU Lesser
16 * General Public License along with ndn-cxx, e.g., in COPYING.md file. If not, see
17 * <http://www.gnu.org/licenses/>.
18 *
19 * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
20 */
21
Davide Pesavento7e780642018-11-24 15:51:34 -050022#include "ndn-cxx/security/transform/private-key.hpp"
Davide Pesaventof45fa212017-09-14 17:23:56 -040023
Davide Pesavento7e780642018-11-24 15:51:34 -050024#include "ndn-cxx/encoding/buffer-stream.hpp"
Laqin Fan0fe72ea2019-05-22 16:42:59 -050025#include "ndn-cxx/security/impl/openssl.hpp"
Davide Pesavento7e780642018-11-24 15:51:34 -050026#include "ndn-cxx/security/key-params.hpp"
Laqin Fan0fe72ea2019-05-22 16:42:59 -050027#include "ndn-cxx/security/transform/base64-decode.hpp"
28#include "ndn-cxx/security/transform/bool-sink.hpp"
29#include "ndn-cxx/security/transform/buffer-source.hpp"
30#include "ndn-cxx/security/transform/public-key.hpp"
31#include "ndn-cxx/security/transform/signer-filter.hpp"
32#include "ndn-cxx/security/transform/stream-sink.hpp"
33#include "ndn-cxx/security/transform/verifier-filter.hpp"
Yingdi Yu202a2e92015-07-12 16:49:25 -070034
Davide Pesavento7e780642018-11-24 15:51:34 -050035#include "tests/boost-test.hpp"
36
Luca Keidel941fd8c2017-07-24 15:21:22 +020037#include <boost/mpl/vector.hpp>
Davide Pesaventoa84f4642017-08-23 16:14:51 -040038
39#include <sstream>
Yingdi Yu202a2e92015-07-12 16:49:25 -070040
41namespace ndn {
42namespace security {
43namespace transform {
44namespace tests {
45
46BOOST_AUTO_TEST_SUITE(Security)
47BOOST_AUTO_TEST_SUITE(Transform)
48BOOST_AUTO_TEST_SUITE(TestPrivateKey)
49
Davide Pesavento1bac1112019-06-13 21:48:46 -040050BOOST_AUTO_TEST_CASE(Empty)
51{
52 // test invoking member functions on an empty (default-constructed) PrivateKey
53 PrivateKey sKey;
54 BOOST_CHECK_EQUAL(sKey.getKeyType(), KeyType::NONE);
55 BOOST_CHECK_EQUAL(sKey.getKeySize(), 0);
laqinfan56a812d2019-06-03 15:33:58 -050056 BOOST_CHECK_THROW(sKey.getKeyDigest(DigestAlgorithm::SHA256), PrivateKey::Error);
Davide Pesavento1bac1112019-06-13 21:48:46 -040057 BOOST_CHECK_THROW(sKey.derivePublicKey(), PrivateKey::Error);
58 const uint8_t theAnswer = 42;
59 BOOST_CHECK_THROW(sKey.decrypt(&theAnswer, sizeof(theAnswer)), PrivateKey::Error);
60 std::ostringstream os;
61 BOOST_CHECK_THROW(sKey.savePkcs1(os), PrivateKey::Error);
62 std::string passwd("password");
63 BOOST_CHECK_THROW(sKey.savePkcs8(os, passwd.data(), passwd.size()), PrivateKey::Error);
64}
65
laqinfan56a812d2019-06-03 15:33:58 -050066BOOST_AUTO_TEST_CASE(KeyDigest)
67{
68 const Buffer buf(16);
69 PrivateKey sKey;
70 sKey.loadRaw(KeyType::HMAC, buf.data(), buf.size());
71 auto digest = sKey.getKeyDigest(DigestAlgorithm::SHA256);
72
73 const uint8_t expected[] = {
74 0x37, 0x47, 0x08, 0xff, 0xf7, 0x71, 0x9d, 0xd5, 0x97, 0x9e, 0xc8, 0x75, 0xd5, 0x6c, 0xd2, 0x28,
75 0x6f, 0x6d, 0x3c, 0xf7, 0xec, 0x31, 0x7a, 0x3b, 0x25, 0x63, 0x2a, 0xab, 0x28, 0xec, 0x37, 0xbb,
76 };
77 BOOST_CHECK_EQUAL_COLLECTIONS(digest->begin(), digest->end(),
78 expected, expected + sizeof(expected));
79}
80
laqinfan48f97242019-06-03 15:33:58 -050081BOOST_AUTO_TEST_CASE(LoadRaw)
82{
83 const Buffer buf(32);
84 PrivateKey sKey;
85 sKey.loadRaw(KeyType::HMAC, buf.data(), buf.size());
86 BOOST_CHECK_EQUAL(sKey.getKeyType(), KeyType::HMAC);
87 BOOST_CHECK_EQUAL(sKey.getKeySize(), 256);
88
89 PrivateKey sKey2;
90 BOOST_CHECK_THROW(sKey2.loadRaw(KeyType::NONE, buf.data(), buf.size()), std::invalid_argument);
91 BOOST_CHECK_THROW(sKey2.loadRaw(KeyType::RSA, buf.data(), buf.size()), std::invalid_argument);
92 BOOST_CHECK_THROW(sKey2.loadRaw(KeyType::EC, buf.data(), buf.size()), std::invalid_argument);
93 BOOST_CHECK_THROW(sKey2.loadRaw(KeyType::AES, buf.data(), buf.size()), std::invalid_argument);
94}
95
Davide Pesaventof45fa212017-09-14 17:23:56 -040096struct RsaKeyTestData
Yingdi Yu202a2e92015-07-12 16:49:25 -070097{
Davide Pesavento1bac1112019-06-13 21:48:46 -040098 const size_t keySize = 2048;
Davide Pesaventof45fa212017-09-14 17:23:56 -040099 const std::string privateKeyPkcs1 =
Yingdi Yu202a2e92015-07-12 16:49:25 -0700100 "MIIEpAIBAAKCAQEAw0WM1/WhAxyLtEqsiAJgWDZWuzkYpeYVdeeZcqRZzzfRgBQT\n"
101 "sNozS5t4HnwTZhwwXbH7k3QN0kRTV826Xobws3iigohnM9yTK+KKiayPhIAm/+5H\n"
102 "GT6SgFJhYhqo1/upWdueojil6RP4/AgavHhopxlAVbk6G9VdVnlQcQ5Zv0OcGi73\n"
103 "c+EnYD/YgURYGSngUi/Ynsh779p2U69/te9gZwIL5PuE9BiO6I39cL9z7EK1SfZh\n"
104 "OWvDe/qH7YhD/BHwcWit8FjRww1glwRVTJsA9rH58ynaAix0tcR/nBMRLUX+e3rU\n"
105 "RHg6UbSjJbdb9qmKM1fTGHKUzL/5pMG6uBU0ywIDAQABAoIBADQkckOIl4IZMUTn\n"
106 "W8LFv6xOdkJwMKC8G6bsPRFbyY+HvC2TLt7epSvfS+f4AcYWaOPcDu2E49vt2sNr\n"
107 "cASly8hgwiRRAB3dHH9vcsboiTo8bi2RFvMqvjv9w3tK2yMxVDtmZamzrrnaV3YV\n"
108 "Q+5nyKo2F/PMDjQ4eUAKDOzjhBuKHsZBTFnA1MFNI+UKj5X4Yp64DFmKlxTX/U2b\n"
109 "wzVywo5hzx2Uhw51jmoLls4YUvMJXD0wW5ZtYRuPogXvXb/of9ef/20/wU11WFKg\n"
110 "Xb4gfR8zUXaXS1sXcnVm3+24vIs9dApUwykuoyjOqxWqcHRec2QT2FxVGkFEraze\n"
111 "CPa4rMECgYEA5Y8CywomIcTgerFGFCeMHJr8nQGqY2V/owFb3k9maczPnC9p4a9R\n"
112 "c5szLxA9FMYFxurQZMBWSEG2JS1HR2mnjigx8UKjYML/A+rvvjZOMe4M6Sy2ggh4\n"
113 "SkLZKpWTzjTe07ByM/j5v/SjNZhWAG7sw4/LmPGRQkwJv+KZhGojuOkCgYEA2cOF\n"
114 "T6cJRv6kvzTz9S0COZOVm+euJh/BXp7oAsAmbNfOpckPMzqHXy8/wpdKl6AAcB57\n"
115 "OuztlNfV1D7qvbz7JuRlYwQ0cEfBgbZPcz1p18HHDXhwn57ZPb8G33Yh9Omg0HNA\n"
116 "Imb4LsVuSqxA6NwSj7cpRekgTedrhLFPJ+Ydb5MCgYEAsM3Q7OjILcIg0t6uht9e\n"
117 "vrlwTsz1mtCV2co2I6crzdj9HeI2vqf1KAElDt6G7PUHhglcr/yjd8uEqmWRPKNX\n"
118 "ddnnfVZB10jYeP/93pac6z/Zmc3iU4yKeUe7U10ZFf0KkiiYDQd59CpLef/2XScS\n"
119 "HB0oRofnxRQjfjLc4muNT+ECgYEAlcDk06MOOTly+F8lCc1bA1dgAmgwFd2usDBd\n"
120 "Y07a3e0HGnGLN3Kfl7C5i0tZq64HvxLnMd2vgLVxQlXGPpdQrC1TH+XLXg+qnlZO\n"
121 "ivSH7i0/gx75bHvj75eH1XK65V8pDVDEoSPottllAIs21CxLw3N1ObOZWJm2EfmR\n"
122 "cuHICmsCgYAtFJ1idqMoHxES3mlRpf2JxyQudP3SCm2WpGmqVzhRYInqeatY5sUd\n"
123 "lPLHm/p77RT7EyxQHTlwn8FJPuM/4ZH1rQd/vB+Y8qAtYJCexDMsbvLW+Js+VOvk\n"
124 "jweEC0nrcL31j9mF0vz5E6tfRu4hhJ6L4yfWs0gSejskeVB/w8QY4g==\n";
Davide Pesaventof45fa212017-09-14 17:23:56 -0400125 const std::string privateKeyPkcs8 =
Yingdi Yu202a2e92015-07-12 16:49:25 -0700126 "MIIFCzA9BgkqhkiG9w0BBQ0wMDAbBgkqhkiG9w0BBQwwDgQIOKYJXvB6p8kCAggA\n"
127 "MBEGBSsOAwIHBAiQgMK8kQXTyASCBMjeNiKYYw5/yHgs9BfSGrpqvV0LkkgMQNUW\n"
128 "R4ZY8fuNjZynd+PxDuw2pyrv1Yv3jc+tupwUehZEzYOnGd53wQAuLO+Z0TBgRFN7\n"
129 "Lhk+AxlT7hu0xaB3ZpJ/uvWpgEJHsq/aB/GYgyzXcQo2AiqzERVpMCWJVmE1L977\n"
130 "CHwJmLm5mxclVLYp1UK5lkIBFu/M4nPavmNmYNUU1LOrXRo56TlJ2kUp8gQyQI1P\n"
131 "VPxi4chmlsr/OnQ2d1eZN+euFm0CS+yP+LFgI9ZqdyH1w+J43SXdHDzauVcZp7oa\n"
132 "Kw24OrhHfolLAnQIECXEJYeT7tZmhC4O9V6B18PFVyxWnEU4eFNpFE8kYSmm8Um2\n"
133 "buvDKI71q43hm23moYT9uIM1f4M8UkoOliJGrlf4xgEcmDuokEX01PdOq1gc4nvG\n"
134 "0DCwDI9cOsyn8cxhk9UVtFgzuG/seuznxIv1F5H0hzYOyloStXxRisJES0kgByBt\n"
135 "FFTfyoFKRrmCjRIygwVKUSkSDR0DlQS5ZLvQyIswnSQFwxAHqfvoSL4dB9UAIAQ+\n"
136 "ALVF1maaHgptbL6Ifqf0GFCv0hdNCVNDNCdy8R+S6nEYE+YdYSIdT1L88KD5PjU3\n"
137 "YY/CMnxhTncMaT4acPO1UUYuSGRZ/JL6E0ihoqIU+bqUgLSHNzhPySPfN9uqN61Y\n"
138 "HFBtxeEPWKU0f/JPkRBMmZdMI1/OVmA3QHSRBydI+CQN8no2gZRFoVbHTkG8IMpE\n"
139 "1fiDJpwFkpzIv/JPiTSE7DeBH5NJk1bgu7TcuZfa4unyAqss0UuLnXzS06TppkUj\n"
140 "QGft0g8VPW56eli6B4xrSzzuvAdbrxsVfxdmtHPyYxLb3/UG1g4x/H/yULhx7x9P\n"
141 "iI6cw6JUE+8bwJV2ZIlHXXHO+wUp/gCFJ6MHo9wkR1QvnHP2ClJAzBm9OvYnUx2Y\n"
142 "SX0HxEowW8BkhxOF184LEmxeua0yyZUqCdrYmErp7x9EY/LhD1zBwH8OGRa0qzmR\n"
143 "VKxAPKihkb9OgxcUKbvKePx3k2cQ7fbCUspGPm4Kn1zwMgRAZ4fz/o8Lnwc8MSY3\n"
144 "lPWnmLTFu420SRH2g9N0o/r195hiZ5cc+KfF4pwZWKbEbKFk/UfXA9vmOi7BBtDJ\n"
145 "RWshOINhzMU6Ij3KuaEpHni1HoHjw0SQ97ow2x/aB8k2QC28tbsa49lD2KKJku6b\n"
146 "2Or89adwFKqMgS2IXfXMXs/iG5EFLYN6r8e40Dn5f1vJfRLJl03XByIfT2n92pw3\n"
147 "fP7muOIKLUsEKjOrmn94NwMlfeW13oQHEH2KjPOWFS/tyJHDdVU+of4COH5yg59a\n"
148 "TZqFkOTGeliE1O+6sfF9fRuVxFUF3D8Hpr0JIjdc6+3RgIlGsXc8BwiSjDSI2XW+\n"
149 "vo75/2zPU9t8OeXEIJk2CQGyqLwUJ6dyi/yDRrvZAgjrUvbpcxydnBAHrLbLUGXJ\n"
150 "aEHH2tjEtnTqVyTchr1yHoupcFOCkA0dAA66XqwcssQxJiMGrWTpCbgd9mrTXQaZ\n"
151 "U7afFN1jpO78tgBQUUpImXdHLLsqdN5tefqjileZGZ9x3/C6TNAfDwYJdsicNNn5\n"
152 "y+JVsbltfLWlJxb9teb3dtQiFlJ7ofprLJnJVqI/Js8lozY+KaxV2vtbZkcD4dM=\n";
Davide Pesaventof45fa212017-09-14 17:23:56 -0400153 const std::string publicKeyPkcs8 =
Yingdi Yu202a2e92015-07-12 16:49:25 -0700154 "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw0WM1/WhAxyLtEqsiAJg\n"
155 "WDZWuzkYpeYVdeeZcqRZzzfRgBQTsNozS5t4HnwTZhwwXbH7k3QN0kRTV826Xobw\n"
156 "s3iigohnM9yTK+KKiayPhIAm/+5HGT6SgFJhYhqo1/upWdueojil6RP4/AgavHho\n"
157 "pxlAVbk6G9VdVnlQcQ5Zv0OcGi73c+EnYD/YgURYGSngUi/Ynsh779p2U69/te9g\n"
158 "ZwIL5PuE9BiO6I39cL9z7EK1SfZhOWvDe/qH7YhD/BHwcWit8FjRww1glwRVTJsA\n"
159 "9rH58ynaAix0tcR/nBMRLUX+e3rURHg6UbSjJbdb9qmKM1fTGHKUzL/5pMG6uBU0\n"
160 "ywIDAQAB\n";
Yingdi Yu202a2e92015-07-12 16:49:25 -0700161};
162
Davide Pesaventof45fa212017-09-14 17:23:56 -0400163struct EcKeyTestData
Yingdi Yu202a2e92015-07-12 16:49:25 -0700164{
Davide Pesavento1bac1112019-06-13 21:48:46 -0400165 const size_t keySize = 256;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400166 const std::string privateKeyPkcs1 =
Yingdi Yu202a2e92015-07-12 16:49:25 -0700167 "MIIBaAIBAQQgRxwcbzK9RV6AHYFsDcykI86o3M/a1KlJn0z8PcLMBZOggfowgfcC\n"
168 "AQEwLAYHKoZIzj0BAQIhAP////8AAAABAAAAAAAAAAAAAAAA////////////////\n"
169 "MFsEIP////8AAAABAAAAAAAAAAAAAAAA///////////////8BCBaxjXYqjqT57Pr\n"
170 "vVV2mIa8ZR0GsMxTsPY7zjw+J9JgSwMVAMSdNgiG5wSTamZ44ROdJreBn36QBEEE\n"
171 "axfR8uEsQkf4vOblY6RA8ncDfYEt6zOg9KE5RdiYwpZP40Li/hp/m47n60p8D54W\n"
172 "K84zV2sxXs7LtkBoN79R9QIhAP////8AAAAA//////////+85vqtpxeehPO5ysL8\n"
173 "YyVRAgEBoUQDQgAEaG4WJuDAt0QkEM4t29KDUdzkQlMPGrqWzkWhgt9OGnwc6O7A\n"
174 "ZLPSrDyhwyrKS7XLRXml5DisQ93RvByll32y8A==\n";
Davide Pesaventof45fa212017-09-14 17:23:56 -0400175 const std::string privateKeyPkcs8 =
Yingdi Yu202a2e92015-07-12 16:49:25 -0700176 "MIIBwzA9BgkqhkiG9w0BBQ0wMDAbBgkqhkiG9w0BBQwwDgQIVHkBzLGtDvICAggA\n"
177 "MBEGBSsOAwIHBAhk6g9eI3toNwSCAYDd+LWPDBTrKV7vUyxTvDbpUd0eXfh73DKA\n"
178 "MHkdHuVmhpmpBbsF9XvaFuL8J/1xi1Yl2XGw8j3WyrprD2YEhl/+zKjNbdTDJmNO\n"
179 "SlomuwWb5AVCJ9reT94zIXKCnexUcyBFS7ep+P4dwuef0VjzprjfmnAZHrP+u594\n"
180 "ELHpKwi0ZpQLtcJjjud13bn43vbXb+aU7jmPV5lU2XP8TxaQJiYIibNEh1Y3TZGr\n"
181 "akJormYvhaYbiZkKLHQ9AvQMEjhoIW5WCB3q+tKZUKTzcQpjNnf9FOTeKN3jk3Kd\n"
182 "2OmibPZcbMJdgCD/nRVn1cBo7Hjn3IMjgtszQHtEUphOQiAkOJUnKmy9MTYqtcNN\n"
183 "6cuFItbu4QvbVwailgdUjOYwIJCmIxExlPV0ohS24pFGsO03Yn7W8rBB9VWENYmG\n"
184 "HkZIbGsHv7O9Wy7fv+FJgZkjeti0807IsNXSJl8LUK0ZIhAR7OU8uONWMsbHdQnk\n"
185 "q1HB1ZKa52ugACl7g/DF9b7CoSAjFeE=\n";
Davide Pesaventof45fa212017-09-14 17:23:56 -0400186 const std::string publicKeyPkcs8 =
Yingdi Yu202a2e92015-07-12 16:49:25 -0700187 "MIIBSzCCAQMGByqGSM49AgEwgfcCAQEwLAYHKoZIzj0BAQIhAP////8AAAABAAAA\n"
188 "AAAAAAAAAAAA////////////////MFsEIP////8AAAABAAAAAAAAAAAAAAAA////\n"
189 "///////////8BCBaxjXYqjqT57PrvVV2mIa8ZR0GsMxTsPY7zjw+J9JgSwMVAMSd\n"
190 "NgiG5wSTamZ44ROdJreBn36QBEEEaxfR8uEsQkf4vOblY6RA8ncDfYEt6zOg9KE5\n"
191 "RdiYwpZP40Li/hp/m47n60p8D54WK84zV2sxXs7LtkBoN79R9QIhAP////8AAAAA\n"
192 "//////////+85vqtpxeehPO5ysL8YyVRAgEBA0IABGhuFibgwLdEJBDOLdvSg1Hc\n"
193 "5EJTDxq6ls5FoYLfThp8HOjuwGSz0qw8ocMqyku1y0V5peQ4rEPd0bwcpZd9svA=\n";
Yingdi Yu202a2e92015-07-12 16:49:25 -0700194};
195
Luca Keidel941fd8c2017-07-24 15:21:22 +0200196using KeyTestDataSets = boost::mpl::vector<RsaKeyTestData, EcKeyTestData>;
Yingdi Yu202a2e92015-07-12 16:49:25 -0700197
Luca Keidel941fd8c2017-07-24 15:21:22 +0200198static void
Yingdi Yu202a2e92015-07-12 16:49:25 -0700199checkPkcs8Encoding(ConstBufferPtr encoding, const std::string& password, ConstBufferPtr pkcs1)
200{
201 PrivateKey sKey;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500202 sKey.loadPkcs8(encoding->data(), encoding->size(), password.data(), password.size());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700203 OBufferStream os;
Luca Keidel941fd8c2017-07-24 15:21:22 +0200204 sKey.savePkcs1(os);
Luca Keidel941fd8c2017-07-24 15:21:22 +0200205 BOOST_CHECK_EQUAL_COLLECTIONS(pkcs1->begin(), pkcs1->end(),
Davide Pesaventof45fa212017-09-14 17:23:56 -0400206 os.buf()->begin(), os.buf()->end());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700207}
208
Luca Keidel941fd8c2017-07-24 15:21:22 +0200209static void
Yingdi Yu202a2e92015-07-12 16:49:25 -0700210checkPkcs8Base64Encoding(ConstBufferPtr encoding, const std::string& password, ConstBufferPtr pkcs1)
211{
212 OBufferStream os;
213 bufferSource(*encoding) >> base64Decode() >> streamSink(os);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700214 checkPkcs8Encoding(os.buf(), password, pkcs1);
215}
216
217BOOST_AUTO_TEST_CASE_TEMPLATE(SaveLoad, T, KeyTestDataSets)
218{
219 T dataSet;
220
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500221 const uint8_t* sKeyPkcs1Base64 = reinterpret_cast<const uint8_t*>(dataSet.privateKeyPkcs1.data());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700222 size_t sKeyPkcs1Base64Len = dataSet.privateKeyPkcs1.size();
Yingdi Yu202a2e92015-07-12 16:49:25 -0700223 OBufferStream os;
224 bufferSource(sKeyPkcs1Base64, sKeyPkcs1Base64Len) >> base64Decode() >> streamSink(os);
225 ConstBufferPtr sKeyPkcs1Buf = os.buf();
Davide Pesavento5d0b0102017-10-07 13:43:16 -0400226 const uint8_t* sKeyPkcs1 = sKeyPkcs1Buf->data();
Yingdi Yu202a2e92015-07-12 16:49:25 -0700227 size_t sKeyPkcs1Len = sKeyPkcs1Buf->size();
228
Luca Keidel941fd8c2017-07-24 15:21:22 +0200229 // load key in base64-encoded pkcs1 format
Yingdi Yu202a2e92015-07-12 16:49:25 -0700230 PrivateKey sKey;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400231 BOOST_CHECK_NO_THROW(sKey.loadPkcs1Base64(sKeyPkcs1Base64, sKeyPkcs1Base64Len));
Davide Pesavento1bac1112019-06-13 21:48:46 -0400232 BOOST_CHECK_EQUAL(sKey.getKeySize(), dataSet.keySize);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700233
234 std::stringstream ss2(dataSet.privateKeyPkcs1);
235 PrivateKey sKey2;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400236 BOOST_CHECK_NO_THROW(sKey2.loadPkcs1Base64(ss2));
Yingdi Yu202a2e92015-07-12 16:49:25 -0700237
238 // load key in pkcs1 format
239 PrivateKey sKey3;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400240 BOOST_CHECK_NO_THROW(sKey3.loadPkcs1(sKeyPkcs1, sKeyPkcs1Len));
Davide Pesavento1bac1112019-06-13 21:48:46 -0400241 BOOST_CHECK_EQUAL(sKey3.getKeySize(), dataSet.keySize);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700242
243 std::stringstream ss4;
244 ss4.write(reinterpret_cast<const char*>(sKeyPkcs1), sKeyPkcs1Len);
245 PrivateKey sKey4;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400246 BOOST_CHECK_NO_THROW(sKey4.loadPkcs1(ss4));
Yingdi Yu202a2e92015-07-12 16:49:25 -0700247
Luca Keidel941fd8c2017-07-24 15:21:22 +0200248 // save key in base64-encoded pkcs1 format
Yingdi Yu202a2e92015-07-12 16:49:25 -0700249 OBufferStream os2;
250 BOOST_REQUIRE_NO_THROW(sKey.savePkcs1Base64(os2));
Yingdi Yu202a2e92015-07-12 16:49:25 -0700251 BOOST_CHECK_EQUAL_COLLECTIONS(sKeyPkcs1Base64, sKeyPkcs1Base64 + sKeyPkcs1Base64Len,
Davide Pesaventof45fa212017-09-14 17:23:56 -0400252 os2.buf()->begin(), os2.buf()->end());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700253
254 // save key in pkcs1 format
255 OBufferStream os3;
256 BOOST_REQUIRE_NO_THROW(sKey.savePkcs1(os3));
Yingdi Yu202a2e92015-07-12 16:49:25 -0700257 BOOST_CHECK_EQUAL_COLLECTIONS(sKeyPkcs1, sKeyPkcs1 + sKeyPkcs1Len,
Davide Pesaventof45fa212017-09-14 17:23:56 -0400258 os3.buf()->begin(), os3.buf()->end());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700259
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500260 const uint8_t* sKeyPkcs8Base64 = reinterpret_cast<const uint8_t*>(dataSet.privateKeyPkcs8.data());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700261 size_t sKeyPkcs8Base64Len = dataSet.privateKeyPkcs8.size();
Yingdi Yu202a2e92015-07-12 16:49:25 -0700262 OBufferStream os4;
263 bufferSource(sKeyPkcs8Base64, sKeyPkcs8Base64Len) >> base64Decode() >> streamSink(os4);
Davide Pesavento5d0b0102017-10-07 13:43:16 -0400264 const uint8_t* sKeyPkcs8 = os4.buf()->data();
Davide Pesaventof45fa212017-09-14 17:23:56 -0400265 size_t sKeyPkcs8Len = os4.buf()->size();
Yingdi Yu202a2e92015-07-12 16:49:25 -0700266
267 std::string password("password");
268 std::string wrongpw("wrongpw");
Luca Keidel941fd8c2017-07-24 15:21:22 +0200269 auto pwCallback = [&password] (char* buf, size_t size, int) -> int {
270 BOOST_REQUIRE_LE(password.size(), size);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700271 std::copy(password.begin(), password.end(), buf);
Luca Keidel941fd8c2017-07-24 15:21:22 +0200272 return static_cast<int>(password.size());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700273 };
274
Luca Keidel941fd8c2017-07-24 15:21:22 +0200275 // load key in base64-encoded pkcs8 format
Yingdi Yu202a2e92015-07-12 16:49:25 -0700276 PrivateKey sKey5;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400277 BOOST_CHECK_NO_THROW(sKey5.loadPkcs8Base64(sKeyPkcs8Base64, sKeyPkcs8Base64Len,
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500278 password.data(), password.size()));
Davide Pesavento1bac1112019-06-13 21:48:46 -0400279 BOOST_CHECK_EQUAL(sKey5.getKeySize(), dataSet.keySize);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700280
281 PrivateKey sKey6;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400282 BOOST_CHECK_NO_THROW(sKey6.loadPkcs8Base64(sKeyPkcs8Base64, sKeyPkcs8Base64Len, pwCallback));
Yingdi Yu202a2e92015-07-12 16:49:25 -0700283
284 std::stringstream ss7(dataSet.privateKeyPkcs8);
285 PrivateKey sKey7;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500286 BOOST_CHECK_NO_THROW(sKey7.loadPkcs8Base64(ss7, password.data(), password.size()));
Yingdi Yu202a2e92015-07-12 16:49:25 -0700287
288 std::stringstream ss8(dataSet.privateKeyPkcs8);
289 PrivateKey sKey8;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400290 BOOST_CHECK_NO_THROW(sKey8.loadPkcs8Base64(ss8, pwCallback));
Yingdi Yu202a2e92015-07-12 16:49:25 -0700291
292 // load key in pkcs8 format
293 PrivateKey sKey9;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500294 BOOST_CHECK_NO_THROW(sKey9.loadPkcs8(sKeyPkcs8, sKeyPkcs8Len, password.data(), password.size()));
Davide Pesavento1bac1112019-06-13 21:48:46 -0400295 BOOST_CHECK_EQUAL(sKey9.getKeySize(), dataSet.keySize);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700296
297 PrivateKey sKey10;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400298 BOOST_CHECK_NO_THROW(sKey10.loadPkcs8(sKeyPkcs8, sKeyPkcs8Len, pwCallback));
Yingdi Yu202a2e92015-07-12 16:49:25 -0700299
300 std::stringstream ss11;
301 ss11.write(reinterpret_cast<const char*>(sKeyPkcs8), sKeyPkcs8Len);
302 PrivateKey sKey11;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500303 BOOST_CHECK_NO_THROW(sKey11.loadPkcs8(ss11, password.data(), password.size()));
Yingdi Yu202a2e92015-07-12 16:49:25 -0700304
305 std::stringstream ss12;
306 ss12.write(reinterpret_cast<const char*>(sKeyPkcs8), sKeyPkcs8Len);
307 PrivateKey sKey12;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400308 BOOST_CHECK_NO_THROW(sKey12.loadPkcs8(ss12, pwCallback));
Yingdi Yu202a2e92015-07-12 16:49:25 -0700309
Davide Pesaventof45fa212017-09-14 17:23:56 -0400310 // load key using wrong password, Error is expected
Yingdi Yu202a2e92015-07-12 16:49:25 -0700311 PrivateKey sKey13;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500312 BOOST_CHECK_THROW(sKey13.loadPkcs8Base64(sKeyPkcs8Base64, sKeyPkcs8Base64Len, wrongpw.data(), wrongpw.size()),
Luca Keidel941fd8c2017-07-24 15:21:22 +0200313 PrivateKey::Error);
Davide Pesavento1bac1112019-06-13 21:48:46 -0400314 BOOST_CHECK_EQUAL(sKey13.getKeyType(), KeyType::NONE);
315 BOOST_CHECK_EQUAL(sKey13.getKeySize(), 0);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700316
Luca Keidel941fd8c2017-07-24 15:21:22 +0200317 // save key in base64-encoded pkcs8 format
Yingdi Yu202a2e92015-07-12 16:49:25 -0700318 OBufferStream os14;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500319 BOOST_REQUIRE_NO_THROW(sKey.savePkcs8Base64(os14, password.data(), password.size()));
Davide Pesaventof45fa212017-09-14 17:23:56 -0400320 checkPkcs8Base64Encoding(os14.buf(), password, sKeyPkcs1Buf);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700321
322 OBufferStream os15;
323 BOOST_REQUIRE_NO_THROW(sKey.savePkcs8Base64(os15, pwCallback));
Davide Pesaventof45fa212017-09-14 17:23:56 -0400324 checkPkcs8Base64Encoding(os15.buf(), password, sKeyPkcs1Buf);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700325
326 // save key in pkcs8 format
327 OBufferStream os16;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500328 BOOST_REQUIRE_NO_THROW(sKey.savePkcs8(os16, password.data(), password.size()));
Davide Pesaventof45fa212017-09-14 17:23:56 -0400329 checkPkcs8Encoding(os16.buf(), password, sKeyPkcs1Buf);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700330
331 OBufferStream os17;
332 BOOST_REQUIRE_NO_THROW(sKey.savePkcs8(os17, pwCallback));
Davide Pesaventof45fa212017-09-14 17:23:56 -0400333 checkPkcs8Encoding(os17.buf(), password, sKeyPkcs1Buf);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700334}
335
336BOOST_AUTO_TEST_CASE_TEMPLATE(DerivePublicKey, T, KeyTestDataSets)
337{
338 T dataSet;
339
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500340 const uint8_t* sKeyPkcs1Base64 = reinterpret_cast<const uint8_t*>(dataSet.privateKeyPkcs1.data());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700341 size_t sKeyPkcs1Base64Len = dataSet.privateKeyPkcs1.size();
Yingdi Yu202a2e92015-07-12 16:49:25 -0700342 PrivateKey sKey;
Davide Pesaventof45fa212017-09-14 17:23:56 -0400343 sKey.loadPkcs1Base64(sKeyPkcs1Base64, sKeyPkcs1Base64Len);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700344
345 // derive public key and compare
Davide Pesaventof45fa212017-09-14 17:23:56 -0400346 ConstBufferPtr pKeyBits = sKey.derivePublicKey();
Yingdi Yu202a2e92015-07-12 16:49:25 -0700347 OBufferStream os;
348 bufferSource(dataSet.publicKeyPkcs8) >> base64Decode() >> streamSink(os);
349 BOOST_CHECK_EQUAL_COLLECTIONS(pKeyBits->begin(), pKeyBits->end(),
350 os.buf()->begin(), os.buf()->end());
351}
352
353BOOST_AUTO_TEST_CASE(RsaDecryption)
354{
355 RsaKeyTestData dataSet;
356
357 PrivateKey sKey;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500358 sKey.loadPkcs1Base64(reinterpret_cast<const uint8_t*>(dataSet.privateKeyPkcs1.data()),
Yingdi Yu202a2e92015-07-12 16:49:25 -0700359 dataSet.privateKeyPkcs1.size());
Davide Pesavento06f1bdf2017-09-16 18:59:15 -0400360 BOOST_CHECK_EQUAL(sKey.getKeyType(), KeyType::RSA);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700361
Davide Pesaventof45fa212017-09-14 17:23:56 -0400362 const uint8_t plainText[] = {0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07};
Yingdi Yu202a2e92015-07-12 16:49:25 -0700363
364 const std::string cipherTextBase64 =
365 "i2XNpZ2JbLa4JmBTdDrGmsd4/0C+p+BSCpW3MuPBNe5uChQ0eRO1dvjTnEqwSECY\n"
366 "38en9JZwcyb0It/TSFNXHlq+Z1ZpffnjIJxQR9HcgwvwQJh6WRH0vu38tvGkGuNv\n"
367 "60Rdn85hqSy1CikmXCeWXL9yCqeqcP21R94G/T3FuA+c1FtFko8KOzCwvrTXMO6n\n"
368 "5PNsqlLXabSGr+jz4EwOsSCgPkiDf9U6tXoSPRA2/YvqFQdaiUXIVlomESvaqqZ8\n"
369 "FxPs2BON0lobM8gT+xdzbRKofp+rNjNK+5uWyeOnXJwzCszh17cdJl2BH1dZwaVD\n"
370 "PmTiSdeDQXZ94U5boDQ4Aw==\n";
Yingdi Yu202a2e92015-07-12 16:49:25 -0700371 OBufferStream os;
372 bufferSource(cipherTextBase64) >> base64Decode() >> streamSink(os);
373
Davide Pesavento5d0b0102017-10-07 13:43:16 -0400374 auto decrypted = sKey.decrypt(os.buf()->data(), os.buf()->size());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700375 BOOST_CHECK_EQUAL_COLLECTIONS(plainText, plainText + sizeof(plainText),
Davide Pesaventof45fa212017-09-14 17:23:56 -0400376 decrypted->begin(), decrypted->end());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700377}
378
Davide Pesaventof45fa212017-09-14 17:23:56 -0400379BOOST_AUTO_TEST_CASE(RsaEncryptDecrypt)
Yingdi Yu202a2e92015-07-12 16:49:25 -0700380{
381 RsaKeyTestData dataSet;
382
383 PublicKey pKey;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500384 pKey.loadPkcs8Base64(reinterpret_cast<const uint8_t*>(dataSet.publicKeyPkcs8.data()),
Yingdi Yu202a2e92015-07-12 16:49:25 -0700385 dataSet.publicKeyPkcs8.size());
Davide Pesavento06f1bdf2017-09-16 18:59:15 -0400386 BOOST_CHECK_EQUAL(pKey.getKeyType(), KeyType::RSA);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700387
388 PrivateKey sKey;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500389 sKey.loadPkcs1Base64(reinterpret_cast<const uint8_t*>(dataSet.privateKeyPkcs1.data()),
Yingdi Yu202a2e92015-07-12 16:49:25 -0700390 dataSet.privateKeyPkcs1.size());
Davide Pesavento06f1bdf2017-09-16 18:59:15 -0400391 BOOST_CHECK_EQUAL(sKey.getKeyType(), KeyType::RSA);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700392
Davide Pesaventof45fa212017-09-14 17:23:56 -0400393 const uint8_t plainText[] = {0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07};
Yingdi Yu202a2e92015-07-12 16:49:25 -0700394
Davide Pesaventof45fa212017-09-14 17:23:56 -0400395 auto cipherText = pKey.encrypt(plainText, sizeof(plainText));
Davide Pesavento5d0b0102017-10-07 13:43:16 -0400396 auto decrypted = sKey.decrypt(cipherText->data(), cipherText->size());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700397 BOOST_CHECK_EQUAL_COLLECTIONS(plainText, plainText + sizeof(plainText),
Davide Pesaventof45fa212017-09-14 17:23:56 -0400398 decrypted->begin(), decrypted->end());
399}
400
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500401BOOST_AUTO_TEST_CASE(UnsupportedDecryption)
Davide Pesaventof45fa212017-09-14 17:23:56 -0400402{
Davide Pesaventof45fa212017-09-14 17:23:56 -0400403 OBufferStream os;
404 bufferSource("Y2lhbyFob2xhIWhlbGxvIQ==") >> base64Decode() >> streamSink(os);
405
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500406 auto ecKey = generatePrivateKey(EcKeyParams());
407 BOOST_CHECK_THROW(ecKey->decrypt(os.buf()->data(), os.buf()->size()), PrivateKey::Error);
408
409 auto hmacKey = generatePrivateKey(HmacKeyParams());
410 BOOST_CHECK_THROW(hmacKey->decrypt(os.buf()->data(), os.buf()->size()), PrivateKey::Error);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700411}
412
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500413struct RsaKeyGenParams
Yingdi Yu202a2e92015-07-12 16:49:25 -0700414{
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500415 using Params = RsaKeyParams;
416 using hasPublicKey = std::true_type;
417 using canSavePkcs1 = std::true_type;
418};
419
420struct EcKeyGenParams
421{
422 using Params = EcKeyParams;
423 using hasPublicKey = std::true_type;
424 using canSavePkcs1 = std::true_type;
425};
426
427struct HmacKeyGenParams
428{
429 using Params = HmacKeyParams;
430 using hasPublicKey = std::false_type;
431 using canSavePkcs1 = std::false_type;
432};
433
434using KeyGenParams = boost::mpl::vector<RsaKeyGenParams,
435 EcKeyGenParams,
436 HmacKeyGenParams>;
437
438BOOST_AUTO_TEST_CASE_TEMPLATE(GenerateKey, T, KeyGenParams)
439{
Davide Pesavento1bac1112019-06-13 21:48:46 -0400440 typename T::Params params;
441 auto sKey = generatePrivateKey(params);
442 BOOST_CHECK_EQUAL(sKey->getKeyType(), params.getKeyType());
443 BOOST_CHECK_EQUAL(sKey->getKeySize(), params.getKeySize());
Yingdi Yu202a2e92015-07-12 16:49:25 -0700444
Luca Keidel941fd8c2017-07-24 15:21:22 +0200445 const uint8_t data[] = {0x01, 0x02, 0x03, 0x04};
Yingdi Yub263f152015-07-12 16:50:13 -0700446 OBufferStream os;
447 BOOST_REQUIRE_NO_THROW(bufferSource(data, sizeof(data)) >>
448 signerFilter(DigestAlgorithm::SHA256, *sKey) >>
449 streamSink(os));
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500450 auto sig = os.buf();
Yingdi Yub263f152015-07-12 16:50:13 -0700451
Yingdi Yub263f152015-07-12 16:50:13 -0700452 bool result = false;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500453 if (typename T::hasPublicKey()) {
454 auto pKeyBits = sKey->derivePublicKey();
455 PublicKey pKey;
456 pKey.loadPkcs8(pKeyBits->data(), pKeyBits->size());
457 BOOST_CHECK_NO_THROW(bufferSource(data, sizeof(data)) >>
Davide Pesavento5d0b0102017-10-07 13:43:16 -0400458 verifierFilter(DigestAlgorithm::SHA256, pKey, sig->data(), sig->size()) >>
Yingdi Yub263f152015-07-12 16:50:13 -0700459 boolSink(result));
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500460 }
461 else {
462#if OPENSSL_VERSION_NUMBER >= 0x1010100fL
463 BOOST_CHECK_THROW(sKey->derivePublicKey(), PrivateKey::Error);
464#endif
465 BOOST_CHECK_NO_THROW(bufferSource(data, sizeof(data)) >>
466 verifierFilter(DigestAlgorithm::SHA256, *sKey, sig->data(), sig->size()) >>
467 boolSink(result));
468 }
Yingdi Yub263f152015-07-12 16:50:13 -0700469 BOOST_CHECK(result);
470
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500471 if (typename T::canSavePkcs1()) {
Davide Pesavento1bac1112019-06-13 21:48:46 -0400472 auto sKey2 = generatePrivateKey(params);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700473
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500474 OBufferStream os1;
475 sKey->savePkcs1(os1);
476 OBufferStream os2;
477 sKey2->savePkcs1(os2);
Yingdi Yu202a2e92015-07-12 16:49:25 -0700478
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500479 BOOST_CHECK(*os1.buf() != *os2.buf());
480 }
481 else {
482#if OPENSSL_VERSION_NUMBER >= 0x1010100fL
483 OBufferStream os1;
484 BOOST_CHECK_THROW(sKey->savePkcs1(os1), PrivateKey::Error);
485#endif
486 }
Yingdi Yu202a2e92015-07-12 16:49:25 -0700487}
488
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500489BOOST_AUTO_TEST_CASE(GenerateKeyUnsupportedType)
Davide Pesaventof45fa212017-09-14 17:23:56 -0400490{
491 BOOST_CHECK_THROW(generatePrivateKey(AesKeyParams()), std::invalid_argument);
492}
493
Yingdi Yu202a2e92015-07-12 16:49:25 -0700494BOOST_AUTO_TEST_SUITE_END() // TestPrivateKey
495BOOST_AUTO_TEST_SUITE_END() // Transform
496BOOST_AUTO_TEST_SUITE_END() // Security
497
498} // namespace tests
499} // namespace transform
500} // namespace security
501} // namespace ndn