blob: ef986b1234a57b7ac8591c52df63702c7a0509bb [file] [log] [blame]
Yingdi Yub263f152015-07-12 16:50:13 -07001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
Davide Pesavento6158f472017-08-11 18:55:09 -04002/*
Davide Pesavento35c63792022-01-17 02:06:03 -05003 * Copyright (c) 2013-2022 Regents of the University of California.
Yingdi Yub263f152015-07-12 16:50:13 -07004 *
5 * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
6 *
7 * ndn-cxx library is free software: you can redistribute it and/or modify it under the
8 * terms of the GNU Lesser General Public License as published by the Free Software
9 * Foundation, either version 3 of the License, or (at your option) any later version.
10 *
11 * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License and GNU Lesser
16 * General Public License along with ndn-cxx, e.g., in COPYING.md file. If not, see
17 * <http://www.gnu.org/licenses/>.
18 *
19 * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
20 */
21
Davide Pesavento7e780642018-11-24 15:51:34 -050022#include "ndn-cxx/security/transform/verifier-filter.hpp"
Yingdi Yub263f152015-07-12 16:50:13 -070023
Davide Pesavento7e780642018-11-24 15:51:34 -050024#include "ndn-cxx/encoding/buffer-stream.hpp"
Laqin Fan0fe72ea2019-05-22 16:42:59 -050025#include "ndn-cxx/security/key-params.hpp"
Davide Pesavento7e780642018-11-24 15:51:34 -050026#include "ndn-cxx/security/transform/base64-decode.hpp"
27#include "ndn-cxx/security/transform/bool-sink.hpp"
28#include "ndn-cxx/security/transform/buffer-source.hpp"
29#include "ndn-cxx/security/transform/private-key.hpp"
30#include "ndn-cxx/security/transform/public-key.hpp"
31#include "ndn-cxx/security/transform/signer-filter.hpp"
32#include "ndn-cxx/security/transform/stream-sink.hpp"
Yingdi Yub263f152015-07-12 16:50:13 -070033
Davide Pesavento7e780642018-11-24 15:51:34 -050034#include "tests/boost-test.hpp"
Yingdi Yub263f152015-07-12 16:50:13 -070035
Davide Pesavento80d671f2022-06-08 04:04:52 -040036#include <openssl/opensslv.h>
37
Yingdi Yub263f152015-07-12 16:50:13 -070038namespace ndn {
39namespace security {
40namespace transform {
41namespace tests {
42
43BOOST_AUTO_TEST_SUITE(Security)
44BOOST_AUTO_TEST_SUITE(Transform)
45BOOST_AUTO_TEST_SUITE(TestVerifierFilter)
46
Laqin Fan0fe72ea2019-05-22 16:42:59 -050047const uint8_t DATA[] = {0x01, 0x02, 0x03, 0x04};
48
Yingdi Yub263f152015-07-12 16:50:13 -070049BOOST_AUTO_TEST_CASE(Rsa)
50{
Davide Pesavento6158f472017-08-11 18:55:09 -040051 const std::string publicKeyPkcs8 =
Yingdi Yub263f152015-07-12 16:50:13 -070052 "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw0WM1/WhAxyLtEqsiAJg\n"
53 "WDZWuzkYpeYVdeeZcqRZzzfRgBQTsNozS5t4HnwTZhwwXbH7k3QN0kRTV826Xobw\n"
54 "s3iigohnM9yTK+KKiayPhIAm/+5HGT6SgFJhYhqo1/upWdueojil6RP4/AgavHho\n"
55 "pxlAVbk6G9VdVnlQcQ5Zv0OcGi73c+EnYD/YgURYGSngUi/Ynsh779p2U69/te9g\n"
56 "ZwIL5PuE9BiO6I39cL9z7EK1SfZhOWvDe/qH7YhD/BHwcWit8FjRww1glwRVTJsA\n"
57 "9rH58ynaAix0tcR/nBMRLUX+e3rURHg6UbSjJbdb9qmKM1fTGHKUzL/5pMG6uBU0\n"
58 "ywIDAQAB\n";
Davide Pesavento6158f472017-08-11 18:55:09 -040059 const std::string privateKeyPkcs1 =
Yingdi Yub263f152015-07-12 16:50:13 -070060 "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDDRYzX9aEDHIu0\n"
61 "SqyIAmBYNla7ORil5hV155lypFnPN9GAFBOw2jNLm3gefBNmHDBdsfuTdA3SRFNX\n"
62 "zbpehvCzeKKCiGcz3JMr4oqJrI+EgCb/7kcZPpKAUmFiGqjX+6lZ256iOKXpE/j8\n"
63 "CBq8eGinGUBVuTob1V1WeVBxDlm/Q5waLvdz4SdgP9iBRFgZKeBSL9ieyHvv2nZT\n"
64 "r3+172BnAgvk+4T0GI7ojf1wv3PsQrVJ9mE5a8N7+oftiEP8EfBxaK3wWNHDDWCX\n"
65 "BFVMmwD2sfnzKdoCLHS1xH+cExEtRf57etREeDpRtKMlt1v2qYozV9MYcpTMv/mk\n"
66 "wbq4FTTLAgMBAAECggEANCRyQ4iXghkxROdbwsW/rE52QnAwoLwbpuw9EVvJj4e8\n"
67 "LZMu3t6lK99L5/gBxhZo49wO7YTj2+3aw2twBKXLyGDCJFEAHd0cf29yxuiJOjxu\n"
68 "LZEW8yq+O/3De0rbIzFUO2ZlqbOuudpXdhVD7mfIqjYX88wONDh5QAoM7OOEG4oe\n"
69 "xkFMWcDUwU0j5QqPlfhinrgMWYqXFNf9TZvDNXLCjmHPHZSHDnWOaguWzhhS8wlc\n"
70 "PTBblm1hG4+iBe9dv+h/15//bT/BTXVYUqBdviB9HzNRdpdLWxdydWbf7bi8iz10\n"
71 "ClTDKS6jKM6rFapwdF5zZBPYXFUaQUStrN4I9riswQKBgQDljwLLCiYhxOB6sUYU\n"
72 "J4wcmvydAapjZX+jAVveT2ZpzM+cL2nhr1FzmzMvED0UxgXG6tBkwFZIQbYlLUdH\n"
73 "aaeOKDHxQqNgwv8D6u++Nk4x7gzpLLaCCHhKQtkqlZPONN7TsHIz+Pm/9KM1mFYA\n"
74 "buzDj8uY8ZFCTAm/4pmEaiO46QKBgQDZw4VPpwlG/qS/NPP1LQI5k5Wb564mH8Fe\n"
75 "nugCwCZs186lyQ8zOodfLz/Cl0qXoABwHns67O2U19XUPuq9vPsm5GVjBDRwR8GB\n"
76 "tk9zPWnXwccNeHCfntk9vwbfdiH06aDQc0AiZvguxW5KrEDo3BKPtylF6SBN52uE\n"
77 "sU8n5h1vkwKBgQCwzdDs6MgtwiDS3q6G316+uXBOzPWa0JXZyjYjpyvN2P0d4ja+\n"
78 "p/UoASUO3obs9QeGCVyv/KN3y4SqZZE8o1d12ed9VkHXSNh4//3elpzrP9mZzeJT\n"
79 "jIp5R7tTXRkV/QqSKJgNB3n0Kkt5//ZdJxIcHShGh+fFFCN+Mtzia41P4QKBgQCV\n"
80 "wOTTow45OXL4XyUJzVsDV2ACaDAV3a6wMF1jTtrd7QcacYs3cp+XsLmLS1mrrge/\n"
81 "Eucx3a+AtXFCVcY+l1CsLVMf5cteD6qeVk6K9IfuLT+DHvlse+Pvl4fVcrrlXykN\n"
82 "UMShI+i22WUAizbULEvDc3U5s5lYmbYR+ZFy4cgKawKBgC0UnWJ2oygfERLeaVGl\n"
83 "/YnHJC50/dIKbZakaapXOFFgiep5q1jmxR2U8seb+nvtFPsTLFAdOXCfwUk+4z/h\n"
84 "kfWtB3+8H5jyoC1gkJ7EMyxu8tb4mz5U6+SPB4QLSetwvfWP2YXS/PkTq19G7iGE\n"
85 "novjJ9azSBJ6OyR5UH/DxBji\n";
Yingdi Yub263f152015-07-12 16:50:13 -070086
87 OBufferStream os1;
88 bufferSource(publicKeyPkcs8) >> base64Decode() >> streamSink(os1);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -040089 auto pubKey = os1.buf();
Yingdi Yub263f152015-07-12 16:50:13 -070090
91 PublicKey pKey;
Davide Pesavento765abc92021-12-27 00:44:04 -050092 pKey.loadPkcs8(*pubKey);
Davide Pesavento6158f472017-08-11 18:55:09 -040093
94 PrivateKey sKey;
Davide Pesavento765abc92021-12-27 00:44:04 -050095 sKey.loadPkcs1Base64({reinterpret_cast<const uint8_t*>(privateKeyPkcs1.data()),
96 privateKeyPkcs1.size()});
Davide Pesavento6158f472017-08-11 18:55:09 -040097
98 OBufferStream os2;
Davide Pesavento765abc92021-12-27 00:44:04 -050099 bufferSource(DATA) >> signerFilter(DigestAlgorithm::SHA256, sKey) >> streamSink(os2);
Davide Pesavento6158f472017-08-11 18:55:09 -0400100 auto sig = os2.buf();
101
Davide Pesavento35c63792022-01-17 02:06:03 -0500102 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::NONE, pKey, *sig), Error);
103 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, sKey, *sig), Error);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400104
Davide Pesavento6158f472017-08-11 18:55:09 -0400105 bool result = false;
Davide Pesavento765abc92021-12-27 00:44:04 -0500106 bufferSource(DATA) >>
Davide Pesavento35c63792022-01-17 02:06:03 -0500107 verifierFilter(DigestAlgorithm::SHA256, pKey, *sig) >>
Davide Pesavento6158f472017-08-11 18:55:09 -0400108 boolSink(result);
Yingdi Yub263f152015-07-12 16:50:13 -0700109
110 BOOST_CHECK_EQUAL(result, true);
111}
112
113BOOST_AUTO_TEST_CASE(Ecdsa)
114{
Davide Pesavento6158f472017-08-11 18:55:09 -0400115 const std::string privateKeyPkcs1 =
Yingdi Yub263f152015-07-12 16:50:13 -0700116 "MIIBeQIBADCCAQMGByqGSM49AgEwgfcCAQEwLAYHKoZIzj0BAQIhAP////8AAAAB\n"
117 "AAAAAAAAAAAAAAAA////////////////MFsEIP////8AAAABAAAAAAAAAAAAAAAA\n"
118 "///////////////8BCBaxjXYqjqT57PrvVV2mIa8ZR0GsMxTsPY7zjw+J9JgSwMV\n"
119 "AMSdNgiG5wSTamZ44ROdJreBn36QBEEEaxfR8uEsQkf4vOblY6RA8ncDfYEt6zOg\n"
120 "9KE5RdiYwpZP40Li/hp/m47n60p8D54WK84zV2sxXs7LtkBoN79R9QIhAP////8A\n"
121 "AAAA//////////+85vqtpxeehPO5ysL8YyVRAgEBBG0wawIBAQQgRxwcbzK9RV6A\n"
122 "HYFsDcykI86o3M/a1KlJn0z8PcLMBZOhRANCAARobhYm4MC3RCQQzi3b0oNR3ORC\n"
123 "Uw8aupbORaGC304afBzo7sBks9KsPKHDKspLtctFeaXkOKxD3dG8HKWXfbLw\n";
Davide Pesavento6158f472017-08-11 18:55:09 -0400124 const std::string publicKeyPkcs8 =
Yingdi Yub263f152015-07-12 16:50:13 -0700125 "MIIBSzCCAQMGByqGSM49AgEwgfcCAQEwLAYHKoZIzj0BAQIhAP////8AAAABAAAA\n"
126 "AAAAAAAAAAAA////////////////MFsEIP////8AAAABAAAAAAAAAAAAAAAA////\n"
127 "///////////8BCBaxjXYqjqT57PrvVV2mIa8ZR0GsMxTsPY7zjw+J9JgSwMVAMSd\n"
128 "NgiG5wSTamZ44ROdJreBn36QBEEEaxfR8uEsQkf4vOblY6RA8ncDfYEt6zOg9KE5\n"
129 "RdiYwpZP40Li/hp/m47n60p8D54WK84zV2sxXs7LtkBoN79R9QIhAP////8AAAAA\n"
130 "//////////+85vqtpxeehPO5ysL8YyVRAgEBA0IABGhuFibgwLdEJBDOLdvSg1Hc\n"
131 "5EJTDxq6ls5FoYLfThp8HOjuwGSz0qw8ocMqyku1y0V5peQ4rEPd0bwcpZd9svA=\n";
Yingdi Yub263f152015-07-12 16:50:13 -0700132
133 OBufferStream os1;
134 bufferSource(publicKeyPkcs8) >> base64Decode() >> streamSink(os1);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400135 auto pubKey = os1.buf();
Yingdi Yub263f152015-07-12 16:50:13 -0700136
137 PublicKey pKey;
Davide Pesavento765abc92021-12-27 00:44:04 -0500138 pKey.loadPkcs8(*pubKey);
Davide Pesavento6158f472017-08-11 18:55:09 -0400139
140 PrivateKey sKey;
Davide Pesavento765abc92021-12-27 00:44:04 -0500141 sKey.loadPkcs1Base64({reinterpret_cast<const uint8_t*>(privateKeyPkcs1.data()),
142 privateKeyPkcs1.size()});
Davide Pesavento6158f472017-08-11 18:55:09 -0400143
144 OBufferStream os2;
Davide Pesavento765abc92021-12-27 00:44:04 -0500145 bufferSource(DATA) >> signerFilter(DigestAlgorithm::SHA256, sKey) >> streamSink(os2);
Davide Pesavento6158f472017-08-11 18:55:09 -0400146 auto sig = os2.buf();
147
Davide Pesavento35c63792022-01-17 02:06:03 -0500148 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::NONE, pKey, *sig), Error);
149 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, sKey, *sig), Error);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400150
Davide Pesavento6158f472017-08-11 18:55:09 -0400151 bool result = false;
Davide Pesavento765abc92021-12-27 00:44:04 -0500152 bufferSource(DATA) >>
Davide Pesavento35c63792022-01-17 02:06:03 -0500153 verifierFilter(DigestAlgorithm::SHA256, pKey, *sig) >>
Davide Pesavento6158f472017-08-11 18:55:09 -0400154 boolSink(result);
Yingdi Yub263f152015-07-12 16:50:13 -0700155
156 BOOST_CHECK_EQUAL(result, true);
157}
158
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500159BOOST_AUTO_TEST_CASE(Hmac)
160{
161 auto sKey = generatePrivateKey(HmacKeyParams());
162
163 OBufferStream os;
Davide Pesavento765abc92021-12-27 00:44:04 -0500164 bufferSource(DATA) >> signerFilter(DigestAlgorithm::SHA256, *sKey) >> streamSink(os);
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500165 auto sig = os.buf();
166
Davide Pesavento35c63792022-01-17 02:06:03 -0500167 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::NONE, *sKey, *sig), Error);
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500168
Davide Pesavento94dfcf12021-09-26 14:18:45 -0400169#if OPENSSL_VERSION_NUMBER < 0x30000000L // FIXME #5154
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500170 bool result = false;
Davide Pesavento765abc92021-12-27 00:44:04 -0500171 bufferSource(DATA) >>
Davide Pesavento35c63792022-01-17 02:06:03 -0500172 verifierFilter(DigestAlgorithm::SHA256, *sKey, *sig) >>
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500173 boolSink(result);
174
175 BOOST_CHECK_EQUAL(result, true);
Davide Pesavento94dfcf12021-09-26 14:18:45 -0400176#endif
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500177}
178
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400179BOOST_AUTO_TEST_CASE(InvalidKey)
180{
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500181 PublicKey pubKey;
Davide Pesavento35c63792022-01-17 02:06:03 -0500182 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, pubKey, {}), Error);
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500183 PrivateKey privKey;
Davide Pesavento35c63792022-01-17 02:06:03 -0500184 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, privKey, {}), Error);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400185}
186
Yingdi Yub263f152015-07-12 16:50:13 -0700187BOOST_AUTO_TEST_SUITE_END() // TestVerifierFilter
188BOOST_AUTO_TEST_SUITE_END() // Transform
189BOOST_AUTO_TEST_SUITE_END() // Security
190
191} // namespace tests
192} // namespace transform
193} // namespace security
194} // namespace ndn