Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 1 | /* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */ |
Davide Pesavento | a84f464 | 2017-08-23 16:14:51 -0400 | [diff] [blame] | 2 | /* |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 3 | * Copyright (c) 2013-2022 Regents of the University of California. |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 4 | * |
| 5 | * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions). |
| 6 | * |
| 7 | * ndn-cxx library is free software: you can redistribute it and/or modify it under the |
| 8 | * terms of the GNU Lesser General Public License as published by the Free Software |
| 9 | * Foundation, either version 3 of the License, or (at your option) any later version. |
| 10 | * |
| 11 | * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY |
| 12 | * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A |
| 13 | * PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details. |
| 14 | * |
| 15 | * You should have received copies of the GNU General Public License and GNU Lesser |
| 16 | * General Public License along with ndn-cxx, e.g., in COPYING.md file. If not, see |
| 17 | * <http://www.gnu.org/licenses/>. |
| 18 | * |
| 19 | * See AUTHORS.md for complete list of ndn-cxx authors and contributors. |
| 20 | */ |
| 21 | |
Davide Pesavento | 7e78064 | 2018-11-24 15:51:34 -0500 | [diff] [blame] | 22 | #include "ndn-cxx/security/transform/private-key.hpp" |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 23 | |
Davide Pesavento | 7e78064 | 2018-11-24 15:51:34 -0500 | [diff] [blame] | 24 | #include "ndn-cxx/encoding/buffer-stream.hpp" |
| 25 | #include "ndn-cxx/security/key-params.hpp" |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 26 | #include "ndn-cxx/security/transform/base64-decode.hpp" |
| 27 | #include "ndn-cxx/security/transform/bool-sink.hpp" |
| 28 | #include "ndn-cxx/security/transform/buffer-source.hpp" |
| 29 | #include "ndn-cxx/security/transform/public-key.hpp" |
| 30 | #include "ndn-cxx/security/transform/signer-filter.hpp" |
| 31 | #include "ndn-cxx/security/transform/stream-sink.hpp" |
| 32 | #include "ndn-cxx/security/transform/verifier-filter.hpp" |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 33 | #include "ndn-cxx/util/string-helper.hpp" |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 34 | |
Davide Pesavento | 7e78064 | 2018-11-24 15:51:34 -0500 | [diff] [blame] | 35 | #include "tests/boost-test.hpp" |
| 36 | |
Davide Pesavento | 80d671f | 2022-06-08 04:04:52 -0400 | [diff] [blame] | 37 | #include <openssl/opensslv.h> |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 38 | #include <boost/mpl/vector.hpp> |
Davide Pesavento | a84f464 | 2017-08-23 16:14:51 -0400 | [diff] [blame] | 39 | #include <sstream> |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 40 | |
| 41 | namespace ndn { |
| 42 | namespace security { |
| 43 | namespace transform { |
| 44 | namespace tests { |
| 45 | |
| 46 | BOOST_AUTO_TEST_SUITE(Security) |
| 47 | BOOST_AUTO_TEST_SUITE(Transform) |
| 48 | BOOST_AUTO_TEST_SUITE(TestPrivateKey) |
| 49 | |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 50 | BOOST_AUTO_TEST_CASE(Empty) |
| 51 | { |
| 52 | // test invoking member functions on an empty (default-constructed) PrivateKey |
| 53 | PrivateKey sKey; |
| 54 | BOOST_CHECK_EQUAL(sKey.getKeyType(), KeyType::NONE); |
| 55 | BOOST_CHECK_EQUAL(sKey.getKeySize(), 0); |
laqinfan | 56a812d | 2019-06-03 15:33:58 -0500 | [diff] [blame] | 56 | BOOST_CHECK_THROW(sKey.getKeyDigest(DigestAlgorithm::SHA256), PrivateKey::Error); |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 57 | BOOST_CHECK_THROW(sKey.derivePublicKey(), PrivateKey::Error); |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 58 | BOOST_CHECK_THROW(sKey.decrypt({}), PrivateKey::Error); |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 59 | std::ostringstream os; |
| 60 | BOOST_CHECK_THROW(sKey.savePkcs1(os), PrivateKey::Error); |
| 61 | std::string passwd("password"); |
| 62 | BOOST_CHECK_THROW(sKey.savePkcs8(os, passwd.data(), passwd.size()), PrivateKey::Error); |
| 63 | } |
| 64 | |
Davide Pesavento | 94dfcf1 | 2021-09-26 14:18:45 -0400 | [diff] [blame] | 65 | #if OPENSSL_VERSION_NUMBER < 0x30000000L // FIXME #5154 |
laqinfan | 56a812d | 2019-06-03 15:33:58 -0500 | [diff] [blame] | 66 | BOOST_AUTO_TEST_CASE(KeyDigest) |
| 67 | { |
| 68 | const Buffer buf(16); |
| 69 | PrivateKey sKey; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 70 | sKey.loadRaw(KeyType::HMAC, buf); |
laqinfan | 56a812d | 2019-06-03 15:33:58 -0500 | [diff] [blame] | 71 | auto digest = sKey.getKeyDigest(DigestAlgorithm::SHA256); |
| 72 | |
| 73 | const uint8_t expected[] = { |
| 74 | 0x37, 0x47, 0x08, 0xff, 0xf7, 0x71, 0x9d, 0xd5, 0x97, 0x9e, 0xc8, 0x75, 0xd5, 0x6c, 0xd2, 0x28, |
| 75 | 0x6f, 0x6d, 0x3c, 0xf7, 0xec, 0x31, 0x7a, 0x3b, 0x25, 0x63, 0x2a, 0xab, 0x28, 0xec, 0x37, 0xbb, |
| 76 | }; |
| 77 | BOOST_CHECK_EQUAL_COLLECTIONS(digest->begin(), digest->end(), |
| 78 | expected, expected + sizeof(expected)); |
| 79 | } |
Davide Pesavento | 94dfcf1 | 2021-09-26 14:18:45 -0400 | [diff] [blame] | 80 | #endif |
laqinfan | 56a812d | 2019-06-03 15:33:58 -0500 | [diff] [blame] | 81 | |
laqinfan | 48f9724 | 2019-06-03 15:33:58 -0500 | [diff] [blame] | 82 | BOOST_AUTO_TEST_CASE(LoadRaw) |
| 83 | { |
| 84 | const Buffer buf(32); |
| 85 | PrivateKey sKey; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 86 | sKey.loadRaw(KeyType::HMAC, buf); |
Davide Pesavento | 94dfcf1 | 2021-09-26 14:18:45 -0400 | [diff] [blame] | 87 | #if OPENSSL_VERSION_NUMBER < 0x30000000L // FIXME #5154 |
laqinfan | 48f9724 | 2019-06-03 15:33:58 -0500 | [diff] [blame] | 88 | BOOST_CHECK_EQUAL(sKey.getKeyType(), KeyType::HMAC); |
| 89 | BOOST_CHECK_EQUAL(sKey.getKeySize(), 256); |
Davide Pesavento | 94dfcf1 | 2021-09-26 14:18:45 -0400 | [diff] [blame] | 90 | #endif |
laqinfan | 48f9724 | 2019-06-03 15:33:58 -0500 | [diff] [blame] | 91 | |
| 92 | PrivateKey sKey2; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 93 | BOOST_CHECK_THROW(sKey2.loadRaw(KeyType::NONE, buf), std::invalid_argument); |
| 94 | BOOST_CHECK_THROW(sKey2.loadRaw(KeyType::RSA, buf), std::invalid_argument); |
| 95 | BOOST_CHECK_THROW(sKey2.loadRaw(KeyType::EC, buf), std::invalid_argument); |
| 96 | BOOST_CHECK_THROW(sKey2.loadRaw(KeyType::AES, buf), std::invalid_argument); |
laqinfan | 48f9724 | 2019-06-03 15:33:58 -0500 | [diff] [blame] | 97 | } |
| 98 | |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 99 | struct RsaKey_DesEncrypted |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 100 | { |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 101 | const size_t keySize = 2048; |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 102 | const std::string privateKeyPkcs1 = |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 103 | R"PEM(MIIEpAIBAAKCAQEAw0WM1/WhAxyLtEqsiAJgWDZWuzkYpeYVdeeZcqRZzzfRgBQT |
| 104 | sNozS5t4HnwTZhwwXbH7k3QN0kRTV826Xobws3iigohnM9yTK+KKiayPhIAm/+5H |
| 105 | GT6SgFJhYhqo1/upWdueojil6RP4/AgavHhopxlAVbk6G9VdVnlQcQ5Zv0OcGi73 |
| 106 | c+EnYD/YgURYGSngUi/Ynsh779p2U69/te9gZwIL5PuE9BiO6I39cL9z7EK1SfZh |
| 107 | OWvDe/qH7YhD/BHwcWit8FjRww1glwRVTJsA9rH58ynaAix0tcR/nBMRLUX+e3rU |
| 108 | RHg6UbSjJbdb9qmKM1fTGHKUzL/5pMG6uBU0ywIDAQABAoIBADQkckOIl4IZMUTn |
| 109 | W8LFv6xOdkJwMKC8G6bsPRFbyY+HvC2TLt7epSvfS+f4AcYWaOPcDu2E49vt2sNr |
| 110 | cASly8hgwiRRAB3dHH9vcsboiTo8bi2RFvMqvjv9w3tK2yMxVDtmZamzrrnaV3YV |
| 111 | Q+5nyKo2F/PMDjQ4eUAKDOzjhBuKHsZBTFnA1MFNI+UKj5X4Yp64DFmKlxTX/U2b |
| 112 | wzVywo5hzx2Uhw51jmoLls4YUvMJXD0wW5ZtYRuPogXvXb/of9ef/20/wU11WFKg |
| 113 | Xb4gfR8zUXaXS1sXcnVm3+24vIs9dApUwykuoyjOqxWqcHRec2QT2FxVGkFEraze |
| 114 | CPa4rMECgYEA5Y8CywomIcTgerFGFCeMHJr8nQGqY2V/owFb3k9maczPnC9p4a9R |
| 115 | c5szLxA9FMYFxurQZMBWSEG2JS1HR2mnjigx8UKjYML/A+rvvjZOMe4M6Sy2ggh4 |
| 116 | SkLZKpWTzjTe07ByM/j5v/SjNZhWAG7sw4/LmPGRQkwJv+KZhGojuOkCgYEA2cOF |
| 117 | T6cJRv6kvzTz9S0COZOVm+euJh/BXp7oAsAmbNfOpckPMzqHXy8/wpdKl6AAcB57 |
| 118 | OuztlNfV1D7qvbz7JuRlYwQ0cEfBgbZPcz1p18HHDXhwn57ZPb8G33Yh9Omg0HNA |
| 119 | Imb4LsVuSqxA6NwSj7cpRekgTedrhLFPJ+Ydb5MCgYEAsM3Q7OjILcIg0t6uht9e |
| 120 | vrlwTsz1mtCV2co2I6crzdj9HeI2vqf1KAElDt6G7PUHhglcr/yjd8uEqmWRPKNX |
| 121 | ddnnfVZB10jYeP/93pac6z/Zmc3iU4yKeUe7U10ZFf0KkiiYDQd59CpLef/2XScS |
| 122 | HB0oRofnxRQjfjLc4muNT+ECgYEAlcDk06MOOTly+F8lCc1bA1dgAmgwFd2usDBd |
| 123 | Y07a3e0HGnGLN3Kfl7C5i0tZq64HvxLnMd2vgLVxQlXGPpdQrC1TH+XLXg+qnlZO |
| 124 | ivSH7i0/gx75bHvj75eH1XK65V8pDVDEoSPottllAIs21CxLw3N1ObOZWJm2EfmR |
| 125 | cuHICmsCgYAtFJ1idqMoHxES3mlRpf2JxyQudP3SCm2WpGmqVzhRYInqeatY5sUd |
| 126 | lPLHm/p77RT7EyxQHTlwn8FJPuM/4ZH1rQd/vB+Y8qAtYJCexDMsbvLW+Js+VOvk |
| 127 | jweEC0nrcL31j9mF0vz5E6tfRu4hhJ6L4yfWs0gSejskeVB/w8QY4g== |
| 128 | )PEM"; |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 129 | const std::string privateKeyPkcs8 = |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 130 | R"PEM(MIIFCzA9BgkqhkiG9w0BBQ0wMDAbBgkqhkiG9w0BBQwwDgQIOKYJXvB6p8kCAggA |
| 131 | MBEGBSsOAwIHBAiQgMK8kQXTyASCBMjeNiKYYw5/yHgs9BfSGrpqvV0LkkgMQNUW |
| 132 | R4ZY8fuNjZynd+PxDuw2pyrv1Yv3jc+tupwUehZEzYOnGd53wQAuLO+Z0TBgRFN7 |
| 133 | Lhk+AxlT7hu0xaB3ZpJ/uvWpgEJHsq/aB/GYgyzXcQo2AiqzERVpMCWJVmE1L977 |
| 134 | CHwJmLm5mxclVLYp1UK5lkIBFu/M4nPavmNmYNUU1LOrXRo56TlJ2kUp8gQyQI1P |
| 135 | VPxi4chmlsr/OnQ2d1eZN+euFm0CS+yP+LFgI9ZqdyH1w+J43SXdHDzauVcZp7oa |
| 136 | Kw24OrhHfolLAnQIECXEJYeT7tZmhC4O9V6B18PFVyxWnEU4eFNpFE8kYSmm8Um2 |
| 137 | buvDKI71q43hm23moYT9uIM1f4M8UkoOliJGrlf4xgEcmDuokEX01PdOq1gc4nvG |
| 138 | 0DCwDI9cOsyn8cxhk9UVtFgzuG/seuznxIv1F5H0hzYOyloStXxRisJES0kgByBt |
| 139 | FFTfyoFKRrmCjRIygwVKUSkSDR0DlQS5ZLvQyIswnSQFwxAHqfvoSL4dB9UAIAQ+ |
| 140 | ALVF1maaHgptbL6Ifqf0GFCv0hdNCVNDNCdy8R+S6nEYE+YdYSIdT1L88KD5PjU3 |
| 141 | YY/CMnxhTncMaT4acPO1UUYuSGRZ/JL6E0ihoqIU+bqUgLSHNzhPySPfN9uqN61Y |
| 142 | HFBtxeEPWKU0f/JPkRBMmZdMI1/OVmA3QHSRBydI+CQN8no2gZRFoVbHTkG8IMpE |
| 143 | 1fiDJpwFkpzIv/JPiTSE7DeBH5NJk1bgu7TcuZfa4unyAqss0UuLnXzS06TppkUj |
| 144 | QGft0g8VPW56eli6B4xrSzzuvAdbrxsVfxdmtHPyYxLb3/UG1g4x/H/yULhx7x9P |
| 145 | iI6cw6JUE+8bwJV2ZIlHXXHO+wUp/gCFJ6MHo9wkR1QvnHP2ClJAzBm9OvYnUx2Y |
| 146 | SX0HxEowW8BkhxOF184LEmxeua0yyZUqCdrYmErp7x9EY/LhD1zBwH8OGRa0qzmR |
| 147 | VKxAPKihkb9OgxcUKbvKePx3k2cQ7fbCUspGPm4Kn1zwMgRAZ4fz/o8Lnwc8MSY3 |
| 148 | lPWnmLTFu420SRH2g9N0o/r195hiZ5cc+KfF4pwZWKbEbKFk/UfXA9vmOi7BBtDJ |
| 149 | RWshOINhzMU6Ij3KuaEpHni1HoHjw0SQ97ow2x/aB8k2QC28tbsa49lD2KKJku6b |
| 150 | 2Or89adwFKqMgS2IXfXMXs/iG5EFLYN6r8e40Dn5f1vJfRLJl03XByIfT2n92pw3 |
| 151 | fP7muOIKLUsEKjOrmn94NwMlfeW13oQHEH2KjPOWFS/tyJHDdVU+of4COH5yg59a |
| 152 | TZqFkOTGeliE1O+6sfF9fRuVxFUF3D8Hpr0JIjdc6+3RgIlGsXc8BwiSjDSI2XW+ |
| 153 | vo75/2zPU9t8OeXEIJk2CQGyqLwUJ6dyi/yDRrvZAgjrUvbpcxydnBAHrLbLUGXJ |
| 154 | aEHH2tjEtnTqVyTchr1yHoupcFOCkA0dAA66XqwcssQxJiMGrWTpCbgd9mrTXQaZ |
| 155 | U7afFN1jpO78tgBQUUpImXdHLLsqdN5tefqjileZGZ9x3/C6TNAfDwYJdsicNNn5 |
| 156 | y+JVsbltfLWlJxb9teb3dtQiFlJ7ofprLJnJVqI/Js8lozY+KaxV2vtbZkcD4dM= |
| 157 | )PEM"; |
| 158 | const std::string publicKey = |
| 159 | R"PEM(MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw0WM1/WhAxyLtEqsiAJg |
| 160 | WDZWuzkYpeYVdeeZcqRZzzfRgBQTsNozS5t4HnwTZhwwXbH7k3QN0kRTV826Xobw |
| 161 | s3iigohnM9yTK+KKiayPhIAm/+5HGT6SgFJhYhqo1/upWdueojil6RP4/AgavHho |
| 162 | pxlAVbk6G9VdVnlQcQ5Zv0OcGi73c+EnYD/YgURYGSngUi/Ynsh779p2U69/te9g |
| 163 | ZwIL5PuE9BiO6I39cL9z7EK1SfZhOWvDe/qH7YhD/BHwcWit8FjRww1glwRVTJsA |
| 164 | 9rH58ynaAix0tcR/nBMRLUX+e3rURHg6UbSjJbdb9qmKM1fTGHKUzL/5pMG6uBU0 |
| 165 | ywIDAQAB |
| 166 | )PEM"; |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 167 | }; |
| 168 | |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 169 | struct RsaKey_Aes256Encrypted |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 170 | { |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 171 | // Generated with OpenSSL 3.0.0 |
| 172 | // openssl genpkey -quiet -algorithm RSA -pkeyopt rsa_keygen_bits:2048 -outform PEM -out key.pem |
| 173 | // openssl pkcs8 -in key.pem -nocrypt -traditional -outform PEM -out pvt1.pem |
| 174 | // openssl pkcs8 -in key.pem -topk8 -v2 aes256 -passout pass:password -outform PEM -out pvt8.pem |
| 175 | // openssl pkey -in key.pem -pubout -outform PEM -out pub.pem |
| 176 | |
| 177 | const size_t keySize = 2048; |
| 178 | const std::string privateKeyPkcs1 = |
| 179 | R"PEM(MIIEowIBAAKCAQEAzEKtiRrzvhwGDMpsUlKMd7Veo9+lvLpttdX/ETo2exU36HqV |
| 180 | 6zSM7LnpfqId7zug+l+VGwPd+oJOzROSCAoUcP3C3m9CkfqT97H9g2zdfwXqJnMQ |
| 181 | tnpAGngXOTF6RSBDVqo+jfeRw3c+MCXDZ0cHd49uv+CnWks6Sj+gowppdsQfvQRr |
| 182 | 2incnwqht3JuaiTytxNrk6DjpoNTHyZJ53SY6DibGSk6aDFWMJcfvTZ6EuUbcepP |
| 183 | 7HRwABn4Ctj1FTx3hDPe4sIrBFrbfP7yDQ9NxYh1baxXcCjWfCS43qUjrtcQFVkK |
| 184 | vE3uucmw1rf0C0Wy7dDvF2n1v+WLAEPSgJnumwIDAQABAoIBAEdNgWGKkIqNIsmF |
| 185 | QhHssg85t2tSL3t1wsWGic8cOJd3vTgAzuO3yPf8IBeuBPAVqyirhBPVokAIC/UH |
| 186 | v2LiDeexlbxrL1xhEhUVw48Eyj9Es8uvQCbK/ySeRlEXRfzqecc/j62kPfRzZDiP |
| 187 | fipHv8ILRlhh1lmtSBBSLMOtZ0pnJUmrNIOaFlJa56t0G3a+4C1u2swOtoCOWtyR |
| 188 | o7NAHiCcZNbnFQQSLyfDj3Sqnsaxke41A+gtrSeeUHkqnP0rxdmqChdyU36Yszi2 |
| 189 | nB+yUXJT7Iw5GD+/vVUoby1/FVCRbh8zNfXvozC3llUSmsn3CBzVLoI+uwD5/zSz |
| 190 | +zMZ1x0CgYEA1o/cuEnALy+FXYbyrdV2R+ecy6t2/3WFDmK7+7klFFHcPBbmh/nL |
| 191 | OIjFPHVYUcyv2qW6JnCYqCutPOJ97JGvyScriNdg047UPGHaFaPZY/4rTXLm6tzN |
| 192 | I6E5eTRLkaFDVb96zYevxLjf88Lceocp2g8vR88kHqKe//0K8sBw+n0CgYEA87WA |
| 193 | CJOzmBdeWN7GbfA9rqxQq8qsFMaG+mJ5sE1MQHW5j/Hzsj6xi5qS9Uy8D9qlQiSV |
| 194 | nA/frqNBjaXiagVIqvfKvkkOFqRFIkVfGIJcYJk3tzi3tgdcHJ0B0LNCg/xHtjuZ |
| 195 | 9KiuBNlDfkhsV6d7g/YQ0Sf/ghWmSGyOtVEtQPcCgYEAs5wYK1jpfVZtcN5/lc8k |
| 196 | RYr4MXJmmfB5opI6RL028eyYzOBquJb9bGTpnvOoLEmJSCIFUxpcYCK30UjUGs3V |
| 197 | 9jBI/DM3hcGBns5W7liLqW3iN+IgtaiCPPpAj1qci9sP797rYNPd6nLMXlTXleZB |
| 198 | vZ2KebVHyjFdonLj0FQR/00CgYBSbXLuc7ZsnIrGmCKZEIZsS8/FKvlk1XjVuvTZ |
| 199 | kmtV6ftnGjiIcvft9cv6t4dr/VGju2f2rs/C62jClfasUTkwyjqCfYcMVWcknj35 |
| 200 | ti20Zl4X1FEeegLHkrsIcXjv1yYSFrqNq3egIDPZxHkQdI8sJM+vTk33G4dwO3dR |
| 201 | EDG0JQKBgBeZhFw4R4MgCYUjNecw+k6AcU5J1JZ+KCJpSBv6J9ilQhkM0PeGLEab |
| 202 | TsurvpoIdAlqojgMnNf98gBahz+zjyLJEB+SPU6AGsahkQZ8wRY1a7ua/SjHPbCk |
| 203 | I3CkY6wqJK8vcjQkUQhE+5y1ZBIhQpH22eHyM4WMLaTFsL9yMvzY |
| 204 | )PEM"; |
| 205 | const std::string privateKeyPkcs8 = |
| 206 | R"PEM(MIIFLTBXBgkqhkiG9w0BBQ0wSjApBgkqhkiG9w0BBQwwHAQIc3ZMcKTZDhcCAggA |
| 207 | MAwGCCqGSIb3DQIJBQAwHQYJYIZIAWUDBAEqBBA1/62RtDr/mX2ZuI3Nq9tTBIIE |
| 208 | 0ITRsiXopz4ox+k3ltt64vwQDLrKhm3uoz9lb885mD/wDkRU+02a3Kq+LjhExawM |
| 209 | Po8VVIbMjyXa3c2eYlmPOUXuXyMz8zi1NyDD1ypZTcVQxIT1ZZK+qsTlIy9Q2MIt |
| 210 | PU/Xg/nPCCJn7FBjkjqpGa942SVnvAbBLk342y8XozHmdbKYDVvNRjkYd6zUpR/n |
| 211 | 5EG1AHBHNFySbtJSg5/6HU5sX6pM7LNAiTT3i0r8LcCWijHofhmUbCfrg+DdgW5+ |
| 212 | ttmsTo/HZCjSSsHtd6xqxdOJyfvFIV1BvVKFP5X6OK8cnHtk/0SuNt2OROjvbOtU |
| 213 | JqSGkzV6MukagrMVtTu9BuXGNz8ee1zVglArEwHw13MihI9a/lGD/AujwjU9CdOd |
| 214 | jH6l2Ibp1MrSn52injoY9i6VmFSTktOrTrIzkGVevHcHkyZBqN3mwQRL3M16t0Bp |
| 215 | RJl01z5b7UYoSDO/w4BOtf6NK/zWix1+GHDnz9fplsaebiDF3YFOq6+p+1/14zPg |
| 216 | cfMkqgco6AGijPimhCQhMVnuWoBKcwIHCs6+sp02lI5HsVl3Lke4586w3qqOU9QY |
| 217 | L8iJFlLax/Sm9MVM/usWUaolXY6BElqkqhd3Z7KJoCazWos2oxVHkutKArNYf9XI |
| 218 | DV309jwBSnBDzmgDpXk7VZWFswxJIc8I1z5759wh370NJ06HeGCLvgBuLp6Dkq2c |
| 219 | hNqR32HWN7wjVqX2hB7X7RPjwX4a/z2oih/fQFc5WuIHfKWTviWcVq8jhIxocLqz |
| 220 | dSGWVvj6j0LoDh7s26iCXe6hb5N5khWHI6Dh7ZFC27aSejljyNqB+KEblIHvTPjS |
| 221 | WgGF14QTwDL6L4tpwtxoPG+QFnoHhM2ORkvwFkmQRmfSKeBfTapiRDLPQvlfIzTI |
| 222 | 6Ie3l9gA4H14HqffawdwfP1fS/lOlLFH7SyO59tSjtVC3ErLMhHD+1R+Q3X1w/lF |
| 223 | jUZ2vwvE+86ikhxZvQCVOiCGXqry9qZfm67cuXD/tolAv5pV2qFDxHAEe5QqUYSv |
| 224 | bJTgo6zin1XByu3jlQPblcEeJ33iRcQDqh96GgMnJstsGuUjBREVjbNZ30YZYeVg |
| 225 | +L/h9otyO92Nq0knADHeixy9JZ2ATRMoTAT4XydSN9lHOh+K5pC3kf9pke2NCJyr |
| 226 | r/w9VQnQiIkxZ+THFshHHJxZZLlLwYWWr894rKftyZB+nDidNZfXr6K8VWoCAwh4 |
| 227 | XwV6109KeHx86Kim9KQPn5RYVFdoxt2dO5O9vcXWtcNciIEi4MPyUM+oHwWrKTLX |
| 228 | EQsVu5gaz8vFt3lg0+Ctf8vAIA1/FxXEZ/BTAiV96lvRcUbXU2AdL+rNU2rtpqxH |
| 229 | h9L3r6IEN9WVIkNH5Q4CqSS9z+BxIPj76dA1MXK1nb8OJ9Y+BMPhktMz9M+KcVpD |
| 230 | 1rXebv+/9Tw0lKLcNL50AglJOP+IRL0hHh62xtXs+FP5KocBs1kVAJORrS6wiy22 |
| 231 | DGwcVmgTvWsPHzIf3IEa7DEjhClnU6alxKxCEmzPtm29upYXL9o3y7CMwidvCYpD |
| 232 | zFU2pIKA85YpjUYL25MiCyJPODc3VoW9l+rBqPu6bVWZXsfgsD4lcdFaJbPqcVby |
| 233 | PEe2dEUjhwpYgjbjOO7geMe+VeShipZJ63yFsNaPWzcz |
| 234 | )PEM"; |
| 235 | const std::string publicKey = |
| 236 | R"PEM(MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAzEKtiRrzvhwGDMpsUlKM |
| 237 | d7Veo9+lvLpttdX/ETo2exU36HqV6zSM7LnpfqId7zug+l+VGwPd+oJOzROSCAoU |
| 238 | cP3C3m9CkfqT97H9g2zdfwXqJnMQtnpAGngXOTF6RSBDVqo+jfeRw3c+MCXDZ0cH |
| 239 | d49uv+CnWks6Sj+gowppdsQfvQRr2incnwqht3JuaiTytxNrk6DjpoNTHyZJ53SY |
| 240 | 6DibGSk6aDFWMJcfvTZ6EuUbcepP7HRwABn4Ctj1FTx3hDPe4sIrBFrbfP7yDQ9N |
| 241 | xYh1baxXcCjWfCS43qUjrtcQFVkKvE3uucmw1rf0C0Wy7dDvF2n1v+WLAEPSgJnu |
| 242 | mwIDAQAB |
| 243 | )PEM"; |
| 244 | }; |
| 245 | |
| 246 | struct EcKeySpecifiedCurve_DesEncrypted |
| 247 | { |
| 248 | // EC keys are generated in "namedCurve" format only. However, old keys in "specifiedCurve" |
| 249 | // format are still accepted. See https://redmine.named-data.net/issues/5037 |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 250 | |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 251 | const size_t keySize = 256; |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 252 | const std::string privateKeyPkcs1 = |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 253 | R"PEM(MIIBaAIBAQQgRxwcbzK9RV6AHYFsDcykI86o3M/a1KlJn0z8PcLMBZOggfowgfcC |
| 254 | AQEwLAYHKoZIzj0BAQIhAP////8AAAABAAAAAAAAAAAAAAAA//////////////// |
| 255 | MFsEIP////8AAAABAAAAAAAAAAAAAAAA///////////////8BCBaxjXYqjqT57Pr |
| 256 | vVV2mIa8ZR0GsMxTsPY7zjw+J9JgSwMVAMSdNgiG5wSTamZ44ROdJreBn36QBEEE |
| 257 | axfR8uEsQkf4vOblY6RA8ncDfYEt6zOg9KE5RdiYwpZP40Li/hp/m47n60p8D54W |
| 258 | K84zV2sxXs7LtkBoN79R9QIhAP////8AAAAA//////////+85vqtpxeehPO5ysL8 |
| 259 | YyVRAgEBoUQDQgAEaG4WJuDAt0QkEM4t29KDUdzkQlMPGrqWzkWhgt9OGnwc6O7A |
| 260 | ZLPSrDyhwyrKS7XLRXml5DisQ93RvByll32y8A== |
| 261 | )PEM"; |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 262 | const std::string privateKeyPkcs8 = |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 263 | R"PEM(MIIBwzA9BgkqhkiG9w0BBQ0wMDAbBgkqhkiG9w0BBQwwDgQIVHkBzLGtDvICAggA |
| 264 | MBEGBSsOAwIHBAhk6g9eI3toNwSCAYDd+LWPDBTrKV7vUyxTvDbpUd0eXfh73DKA |
| 265 | MHkdHuVmhpmpBbsF9XvaFuL8J/1xi1Yl2XGw8j3WyrprD2YEhl/+zKjNbdTDJmNO |
| 266 | SlomuwWb5AVCJ9reT94zIXKCnexUcyBFS7ep+P4dwuef0VjzprjfmnAZHrP+u594 |
| 267 | ELHpKwi0ZpQLtcJjjud13bn43vbXb+aU7jmPV5lU2XP8TxaQJiYIibNEh1Y3TZGr |
| 268 | akJormYvhaYbiZkKLHQ9AvQMEjhoIW5WCB3q+tKZUKTzcQpjNnf9FOTeKN3jk3Kd |
| 269 | 2OmibPZcbMJdgCD/nRVn1cBo7Hjn3IMjgtszQHtEUphOQiAkOJUnKmy9MTYqtcNN |
| 270 | 6cuFItbu4QvbVwailgdUjOYwIJCmIxExlPV0ohS24pFGsO03Yn7W8rBB9VWENYmG |
| 271 | HkZIbGsHv7O9Wy7fv+FJgZkjeti0807IsNXSJl8LUK0ZIhAR7OU8uONWMsbHdQnk |
| 272 | q1HB1ZKa52ugACl7g/DF9b7CoSAjFeE= |
| 273 | )PEM"; |
| 274 | const std::string publicKey = |
| 275 | R"PEM(MIIBSzCCAQMGByqGSM49AgEwgfcCAQEwLAYHKoZIzj0BAQIhAP////8AAAABAAAA |
| 276 | AAAAAAAAAAAA////////////////MFsEIP////8AAAABAAAAAAAAAAAAAAAA//// |
| 277 | ///////////8BCBaxjXYqjqT57PrvVV2mIa8ZR0GsMxTsPY7zjw+J9JgSwMVAMSd |
| 278 | NgiG5wSTamZ44ROdJreBn36QBEEEaxfR8uEsQkf4vOblY6RA8ncDfYEt6zOg9KE5 |
| 279 | RdiYwpZP40Li/hp/m47n60p8D54WK84zV2sxXs7LtkBoN79R9QIhAP////8AAAAA |
| 280 | //////////+85vqtpxeehPO5ysL8YyVRAgEBA0IABGhuFibgwLdEJBDOLdvSg1Hc |
| 281 | 5EJTDxq6ls5FoYLfThp8HOjuwGSz0qw8ocMqyku1y0V5peQ4rEPd0bwcpZd9svA= |
| 282 | )PEM"; |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 283 | }; |
| 284 | |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 285 | struct EcKeyNamedCurve_DesEncrypted |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 286 | { |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 287 | // Generated with older (1.0.x?) OpenSSL |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 288 | // openssl ecparam -name secp384r1 -genkey -out pvt1.pem |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 289 | // openssl pkcs8 -in pvt1.pem -topk8 -passout pass:password -outform PEM -out pvt8.pem |
| 290 | // openssl ec -in pvt1.pem -pubout -outform PEM -out pub.pem |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 291 | |
| 292 | const size_t keySize = 384; |
| 293 | const std::string privateKeyPkcs1 = |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 294 | R"PEM(MIGkAgEBBDCUsb7NymksCkQAjdLMjUilWhOEyeYmGi79sX1RbsmfnoF/8SesKBhO |
| 295 | or+TZ8g8/8igBwYFK4EEACKhZANiAARWGplLOGdQiXRFQcd0VLPeTt0zXEj5zvSv |
| 296 | aHx9MrzBy57wgz10wTAiR561wuLtFAYxmqL9Ikrzx/BaEg0+v2zQ05NCzMNN8v2c |
| 297 | 7/FzOhD7fmZrlJsT6Q2aHGExW0Rj3GE= |
| 298 | )PEM"; |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 299 | const std::string privateKeyPkcs8 = |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 300 | R"PEM(MIHgMBsGCSqGSIb3DQEFAzAOBAjniUjwJfWsMQICCAAEgcCakGTKa49csaPpmtzi |
| 301 | 5sTJw+AH8ajUqcDbtp2pJP/Ni6M1p9fai9hOKPElf9uJuYh/S80FAU6WQmZBAxL4 |
| 302 | bF598ncLPogpGvz21wLuSc1xnbD829zAsMmh0XZvMZpBWX2g0NnZJx7GOraskTSh |
| 303 | 7qGu70B+uKzw+JxIzgBEeMcoBUg8mTEht5zghfLGYkQp6BpTPdpU64udpPAKzFNs |
| 304 | 5X+BzBnT5Yy49/Lp4uYIji8qwJFF3VqTn8RFKunFYDDejRU= |
| 305 | )PEM"; |
| 306 | const std::string publicKey = |
| 307 | R"PEM(MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEVhqZSzhnUIl0RUHHdFSz3k7dM1xI+c70 |
| 308 | r2h8fTK8wcue8IM9dMEwIkeetcLi7RQGMZqi/SJK88fwWhINPr9s0NOTQszDTfL9 |
| 309 | nO/xczoQ+35ma5SbE+kNmhxhMVtEY9xh |
| 310 | )PEM"; |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 311 | }; |
| 312 | |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 313 | struct EcKeyNamedCurve_Aes256Encrypted |
| 314 | { |
| 315 | // Generated with OpenSSL 3.0.0 |
| 316 | // openssl genpkey -quiet -algorithm EC -pkeyopt ec_paramgen_curve:P-384 |
| 317 | // -pkeyopt ec_param_enc:named_curve -outform PEM -out key.pem |
| 318 | // openssl pkcs8 -in key.pem -nocrypt -traditional -outform PEM -out pvt1.pem |
| 319 | // openssl pkcs8 -in key.pem -topk8 -v2 aes256 -passout pass:password -outform PEM -out pvt8.pem |
| 320 | // openssl pkey -in key.pem -pubout -outform PEM -out pub.pem |
| 321 | |
| 322 | const size_t keySize = 384; |
| 323 | const std::string privateKeyPkcs1 = |
| 324 | R"PEM(MIGkAgEBBDAa5I6hfwcDZ8Hzn6/ZU3jV/Fp6jZP+tgUHSdMcfRS3iLOY296KdcXd |
| 325 | xISVHU3g+XygBwYFK4EEACKhZANiAAQh3xGTxgMFXwoRNBCrnzawZnoQUojZ1Qe5 |
| 326 | 3VrR+9ECawVf2sPklX+Lw1pE1TG5q+YepM8imRclRbXLBSGPF6f+qJCiFWR71XS2 |
| 327 | CX2kW/AZOGluxYrVMe22ns5TY2o50G8= |
| 328 | )PEM"; |
| 329 | const std::string privateKeyPkcs8 = |
| 330 | R"PEM(MIIBHDBXBgkqhkiG9w0BBQ0wSjApBgkqhkiG9w0BBQwwHAQIy4A7Il3JRNQCAggA |
| 331 | MAwGCCqGSIb3DQIJBQAwHQYJYIZIAWUDBAEqBBBPYOn/2qSDBlKhZ6+ckre8BIHA |
| 332 | jXwlDh+OX+1VayCWohXUooxZPfgKmIVkxhNrQzn0DV/FW9WbiXC72vss75/o5O2H |
| 333 | o4EuIOxnbxIM5HhsrdDY5g8Abkk5gKYt+eVJQn1EPAR+PU9T8OUKyQr9rO0Pvsu8 |
| 334 | 9h5V9+WFHNnNBTN3pqIV5cU25oVX7tqeZKs+5I4QIaq4hzPj+k15dLFaaq5XejZH |
| 335 | KjMKNdKbfz4TEs7u1W9YyrD3Z8/RgzLwVRjJqqOKeoJF4b1lOqOd5rWb4Oa06alr |
| 336 | )PEM"; |
| 337 | const std::string publicKey = |
| 338 | R"PEM(MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEId8Rk8YDBV8KETQQq582sGZ6EFKI2dUH |
| 339 | ud1a0fvRAmsFX9rD5JV/i8NaRNUxuavmHqTPIpkXJUW1ywUhjxen/qiQohVke9V0 |
| 340 | tgl9pFvwGThpbsWK1THttp7OU2NqOdBv |
| 341 | )PEM"; |
| 342 | }; |
| 343 | |
| 344 | struct EcKeyNamedCurve_Des3Encrypted |
| 345 | { |
| 346 | // Generated with OpenSSL 3.0.0 |
| 347 | // openssl genpkey -quiet -algorithm EC -pkeyopt ec_paramgen_curve:P-256 |
| 348 | // -pkeyopt ec_param_enc:named_curve -outform PEM -out key.pem |
| 349 | // openssl pkcs8 -in key.pem -nocrypt -traditional -outform PEM -out pvt1.pem |
| 350 | // openssl pkcs8 -in key.pem -topk8 -v2 des3 -passout pass:password -outform PEM -out pvt8.pem |
| 351 | // openssl pkey -in key.pem -pubout -outform PEM -out pub.pem |
| 352 | |
| 353 | const size_t keySize = 256; |
| 354 | const std::string privateKeyPkcs1 = |
| 355 | R"PEM(MHcCAQEEIEbb/pnOVzkIZP4jrpZQCxl2OTJVQD7rHBJxxv8Aa215oAoGCCqGSM49 |
| 356 | AwEHoUQDQgAEvSFhYwmFe17QAj0xhumERNJFf5MTkAegdE+db4ojchAbcDLRcnzY |
| 357 | +TUx5pTBqdBg+STMK7h36ZUn+KcMeizMRA== |
| 358 | )PEM"; |
| 359 | const std::string privateKeyPkcs8 = |
| 360 | R"PEM(MIHjME4GCSqGSIb3DQEFDTBBMCkGCSqGSIb3DQEFDDAcBAj2rY09BeCZGgICCAAw |
| 361 | DAYIKoZIhvcNAgkFADAUBggqhkiG9w0DBwQI6CIHMAz7K7AEgZBzyr8QcH1OWEqc |
| 362 | ByPy4Vlze9D0izD7/NIxUeauHILqXMjU6Z057oYZ14Nm+DpbyJWu16gjZ2N+M2GH |
| 363 | 4bH8gS6JUGhqtSbQ1Oo5lmjPXphefZp0tarv19Hp8S1VKmcVoj65kxfn5x0GKepg |
| 364 | fhXlMB2uQHvNoujU9PyeTZhwjAPQ6vHgFonbPPaL/f256NqMmnA= |
| 365 | )PEM"; |
| 366 | const std::string publicKey = |
| 367 | R"PEM(MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEvSFhYwmFe17QAj0xhumERNJFf5MT |
| 368 | kAegdE+db4ojchAbcDLRcnzY+TUx5pTBqdBg+STMK7h36ZUn+KcMeizMRA== |
| 369 | )PEM"; |
| 370 | }; |
| 371 | |
| 372 | using KeyTestDataSets = boost::mpl::vector< |
| 373 | #if OPENSSL_VERSION_NUMBER < 0x30000000L |
| 374 | // DES-encrypted keys |
| 375 | // .privateKeyPkcs8 uses either the PBES1 or PBES2 encryption scheme with DES-CBC-Pad (see RFC 8018) |
| 376 | // This is no longer supported out-of-the-box by OpenSSL 3.0 and later |
| 377 | RsaKey_DesEncrypted, |
| 378 | EcKeySpecifiedCurve_DesEncrypted, |
| 379 | EcKeyNamedCurve_DesEncrypted, |
| 380 | #endif |
| 381 | // AES-encrypted keys |
| 382 | // .privateKeyPkcs8 uses the PBES2 encryption scheme with AES-CBC-Pad (see RFC 8018) |
| 383 | // This works with all supported versions of OpenSSL |
| 384 | RsaKey_Aes256Encrypted, |
| 385 | EcKeyNamedCurve_Aes256Encrypted, |
| 386 | // 3DES-encrypted keys |
| 387 | // .privateKeyPkcs8 uses the PBES2 encryption scheme with DES-EDE3-CBC-Pad (see RFC 8018) |
| 388 | // This works with all supported versions of OpenSSL |
| 389 | EcKeyNamedCurve_Des3Encrypted |
| 390 | >; |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 391 | |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 392 | static void |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 393 | checkPkcs8Encoding(const ConstBufferPtr& encoding, |
| 394 | const std::string& password, |
| 395 | const ConstBufferPtr& pkcs1) |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 396 | { |
| 397 | PrivateKey sKey; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 398 | sKey.loadPkcs8(*encoding, password.data(), password.size()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 399 | OBufferStream os; |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 400 | sKey.savePkcs1(os); |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 401 | BOOST_CHECK_EQUAL_COLLECTIONS(pkcs1->begin(), pkcs1->end(), |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 402 | os.buf()->begin(), os.buf()->end()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 403 | } |
| 404 | |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 405 | static void |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 406 | checkPkcs8Base64Encoding(const ConstBufferPtr& encoding, |
| 407 | const std::string& password, |
| 408 | const ConstBufferPtr& pkcs1) |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 409 | { |
| 410 | OBufferStream os; |
| 411 | bufferSource(*encoding) >> base64Decode() >> streamSink(os); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 412 | checkPkcs8Encoding(os.buf(), password, pkcs1); |
| 413 | } |
| 414 | |
| 415 | BOOST_AUTO_TEST_CASE_TEMPLATE(SaveLoad, T, KeyTestDataSets) |
| 416 | { |
| 417 | T dataSet; |
| 418 | |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 419 | auto sKeyPkcs1Base64 = make_span(reinterpret_cast<const uint8_t*>(dataSet.privateKeyPkcs1.data()), |
| 420 | dataSet.privateKeyPkcs1.size()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 421 | OBufferStream os; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 422 | bufferSource(sKeyPkcs1Base64) >> base64Decode() >> streamSink(os); |
| 423 | auto sKeyPkcs1 = os.buf(); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 424 | |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 425 | // load key in base64-encoded pkcs1 format |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 426 | PrivateKey sKey; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 427 | BOOST_CHECK_NO_THROW(sKey.loadPkcs1Base64(sKeyPkcs1Base64)); |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 428 | BOOST_CHECK_EQUAL(sKey.getKeySize(), dataSet.keySize); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 429 | |
| 430 | std::stringstream ss2(dataSet.privateKeyPkcs1); |
| 431 | PrivateKey sKey2; |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 432 | BOOST_CHECK_NO_THROW(sKey2.loadPkcs1Base64(ss2)); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 433 | |
| 434 | // load key in pkcs1 format |
| 435 | PrivateKey sKey3; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 436 | BOOST_CHECK_NO_THROW(sKey3.loadPkcs1(*sKeyPkcs1)); |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 437 | BOOST_CHECK_EQUAL(sKey3.getKeySize(), dataSet.keySize); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 438 | |
| 439 | std::stringstream ss4; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 440 | ss4.write(reinterpret_cast<const char*>(sKeyPkcs1->data()), sKeyPkcs1->size()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 441 | PrivateKey sKey4; |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 442 | BOOST_CHECK_NO_THROW(sKey4.loadPkcs1(ss4)); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 443 | |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 444 | // save key in base64-encoded pkcs1 format |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 445 | OBufferStream os2; |
| 446 | BOOST_REQUIRE_NO_THROW(sKey.savePkcs1Base64(os2)); |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 447 | BOOST_CHECK_EQUAL_COLLECTIONS(sKeyPkcs1Base64.begin(), sKeyPkcs1Base64.end(), |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 448 | os2.buf()->begin(), os2.buf()->end()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 449 | |
| 450 | // save key in pkcs1 format |
| 451 | OBufferStream os3; |
| 452 | BOOST_REQUIRE_NO_THROW(sKey.savePkcs1(os3)); |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 453 | BOOST_CHECK_EQUAL_COLLECTIONS(sKeyPkcs1->begin(), sKeyPkcs1->end(), |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 454 | os3.buf()->begin(), os3.buf()->end()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 455 | |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 456 | auto sKeyPkcs8Base64 = make_span(reinterpret_cast<const uint8_t*>(dataSet.privateKeyPkcs8.data()), |
| 457 | dataSet.privateKeyPkcs8.size()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 458 | OBufferStream os4; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 459 | bufferSource(sKeyPkcs8Base64) >> base64Decode() >> streamSink(os4); |
| 460 | auto sKeyPkcs8 = os4.buf(); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 461 | |
| 462 | std::string password("password"); |
| 463 | std::string wrongpw("wrongpw"); |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 464 | auto pwCallback = [&password] (char* buf, size_t size, int) -> int { |
| 465 | BOOST_REQUIRE_LE(password.size(), size); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 466 | std::copy(password.begin(), password.end(), buf); |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 467 | return static_cast<int>(password.size()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 468 | }; |
| 469 | |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 470 | // load key in base64-encoded pkcs8 format |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 471 | PrivateKey sKey5; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 472 | BOOST_CHECK_NO_THROW(sKey5.loadPkcs8Base64(sKeyPkcs8Base64, password.data(), password.size())); |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 473 | BOOST_CHECK_EQUAL(sKey5.getKeySize(), dataSet.keySize); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 474 | |
| 475 | PrivateKey sKey6; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 476 | BOOST_CHECK_NO_THROW(sKey6.loadPkcs8Base64(sKeyPkcs8Base64, pwCallback)); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 477 | |
| 478 | std::stringstream ss7(dataSet.privateKeyPkcs8); |
| 479 | PrivateKey sKey7; |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 480 | BOOST_CHECK_NO_THROW(sKey7.loadPkcs8Base64(ss7, password.data(), password.size())); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 481 | |
| 482 | std::stringstream ss8(dataSet.privateKeyPkcs8); |
| 483 | PrivateKey sKey8; |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 484 | BOOST_CHECK_NO_THROW(sKey8.loadPkcs8Base64(ss8, pwCallback)); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 485 | |
| 486 | // load key in pkcs8 format |
| 487 | PrivateKey sKey9; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 488 | BOOST_CHECK_NO_THROW(sKey9.loadPkcs8(*sKeyPkcs8, password.data(), password.size())); |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 489 | BOOST_CHECK_EQUAL(sKey9.getKeySize(), dataSet.keySize); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 490 | |
| 491 | PrivateKey sKey10; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 492 | BOOST_CHECK_NO_THROW(sKey10.loadPkcs8(*sKeyPkcs8, pwCallback)); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 493 | |
| 494 | std::stringstream ss11; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 495 | ss11.write(reinterpret_cast<const char*>(sKeyPkcs8->data()), sKeyPkcs8->size()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 496 | PrivateKey sKey11; |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 497 | BOOST_CHECK_NO_THROW(sKey11.loadPkcs8(ss11, password.data(), password.size())); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 498 | |
| 499 | std::stringstream ss12; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 500 | ss12.write(reinterpret_cast<const char*>(sKeyPkcs8->data()), sKeyPkcs8->size()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 501 | PrivateKey sKey12; |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 502 | BOOST_CHECK_NO_THROW(sKey12.loadPkcs8(ss12, pwCallback)); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 503 | |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 504 | // load key using wrong password, Error is expected |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 505 | PrivateKey sKey13; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 506 | BOOST_CHECK_THROW(sKey13.loadPkcs8Base64(sKeyPkcs8Base64, wrongpw.data(), wrongpw.size()), |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 507 | PrivateKey::Error); |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 508 | BOOST_CHECK_EQUAL(sKey13.getKeyType(), KeyType::NONE); |
| 509 | BOOST_CHECK_EQUAL(sKey13.getKeySize(), 0); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 510 | |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 511 | // save key in base64-encoded pkcs8 format |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 512 | OBufferStream os14; |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 513 | BOOST_REQUIRE_NO_THROW(sKey.savePkcs8Base64(os14, password.data(), password.size())); |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 514 | checkPkcs8Base64Encoding(os14.buf(), password, sKeyPkcs1); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 515 | |
| 516 | OBufferStream os15; |
| 517 | BOOST_REQUIRE_NO_THROW(sKey.savePkcs8Base64(os15, pwCallback)); |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 518 | checkPkcs8Base64Encoding(os15.buf(), password, sKeyPkcs1); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 519 | |
| 520 | // save key in pkcs8 format |
| 521 | OBufferStream os16; |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 522 | BOOST_REQUIRE_NO_THROW(sKey.savePkcs8(os16, password.data(), password.size())); |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 523 | checkPkcs8Encoding(os16.buf(), password, sKeyPkcs1); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 524 | |
| 525 | OBufferStream os17; |
| 526 | BOOST_REQUIRE_NO_THROW(sKey.savePkcs8(os17, pwCallback)); |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 527 | checkPkcs8Encoding(os17.buf(), password, sKeyPkcs1); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 528 | } |
| 529 | |
| 530 | BOOST_AUTO_TEST_CASE_TEMPLATE(DerivePublicKey, T, KeyTestDataSets) |
| 531 | { |
| 532 | T dataSet; |
| 533 | |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 534 | auto sKeyPkcs1Base64 = make_span(reinterpret_cast<const uint8_t*>(dataSet.privateKeyPkcs1.data()), |
| 535 | dataSet.privateKeyPkcs1.size()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 536 | PrivateKey sKey; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 537 | sKey.loadPkcs1Base64(sKeyPkcs1Base64); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 538 | |
| 539 | // derive public key and compare |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 540 | ConstBufferPtr pKeyBits = sKey.derivePublicKey(); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 541 | OBufferStream os; |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 542 | bufferSource(dataSet.publicKey) >> base64Decode() >> streamSink(os); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 543 | BOOST_CHECK_EQUAL_COLLECTIONS(pKeyBits->begin(), pKeyBits->end(), |
| 544 | os.buf()->begin(), os.buf()->end()); |
| 545 | } |
| 546 | |
| 547 | BOOST_AUTO_TEST_CASE(RsaDecryption) |
| 548 | { |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 549 | RsaKey_Aes256Encrypted dataSet; |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 550 | |
| 551 | PrivateKey sKey; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 552 | sKey.loadPkcs1Base64({reinterpret_cast<const uint8_t*>(dataSet.privateKeyPkcs1.data()), |
| 553 | dataSet.privateKeyPkcs1.size()}); |
Davide Pesavento | 06f1bdf | 2017-09-16 18:59:15 -0400 | [diff] [blame] | 554 | BOOST_CHECK_EQUAL(sKey.getKeyType(), KeyType::RSA); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 555 | |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 556 | const uint8_t plaintext[] = {0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07}; |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 557 | |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 558 | // Ciphertext generated with OpenSSL 3.0.0 |
| 559 | // printf ... | openssl pkeyutl -encrypt -inkey pub.pem -pubin -pkeyopt rsa_padding_mode:oaep | base64 |
| 560 | const std::string ciphertext = |
| 561 | R"BASE64(BgVqf6yKhMytCeL6+/oEoyx9rahh2+a1iU0D17RgfX6Q/3eNEcC2xY5QomjI7k/no8yiTZbXT9R4 |
| 562 | REE6ic0DjFSbFwJjC/P0/oTSQyUNn4xNO+aK0MGnyeN34A8c3bZfLuo2DU496SQF0B9I5SS3gEA9 |
| 563 | rqdIAdbWoOCKi1EX5SXtAOPTsj5PHHH+UM52bxOrUPvGSl9tRaz5S6hVf2haSoio4nnG3/bA6pdb |
| 564 | hHjyHHA/oi1PlFRIe0EO2/riAdqdIW3eOqZGP5t5QAMmiP178A9YQdbSavTgBSuE20T01U82Ln+L |
| 565 | pNk+PE/mmM20iNBo8C9cAJVUju6T4DCNZk7H5Q== |
| 566 | )BASE64"; |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 567 | OBufferStream os; |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 568 | bufferSource(ciphertext) >> base64Decode() >> streamSink(os); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 569 | |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 570 | auto decrypted = sKey.decrypt(*os.buf()); |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 571 | BOOST_CHECK_EQUAL_COLLECTIONS(plaintext, plaintext + sizeof(plaintext), |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 572 | decrypted->begin(), decrypted->end()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 573 | } |
| 574 | |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 575 | BOOST_AUTO_TEST_CASE(RsaEncryptDecrypt) |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 576 | { |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 577 | RsaKey_Aes256Encrypted dataSet; |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 578 | |
| 579 | PublicKey pKey; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 580 | pKey.loadPkcs8Base64({reinterpret_cast<const uint8_t*>(dataSet.publicKey.data()), |
| 581 | dataSet.publicKey.size()}); |
Davide Pesavento | 06f1bdf | 2017-09-16 18:59:15 -0400 | [diff] [blame] | 582 | BOOST_CHECK_EQUAL(pKey.getKeyType(), KeyType::RSA); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 583 | |
| 584 | PrivateKey sKey; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 585 | sKey.loadPkcs1Base64({reinterpret_cast<const uint8_t*>(dataSet.privateKeyPkcs1.data()), |
| 586 | dataSet.privateKeyPkcs1.size()}); |
Davide Pesavento | 06f1bdf | 2017-09-16 18:59:15 -0400 | [diff] [blame] | 587 | BOOST_CHECK_EQUAL(sKey.getKeyType(), KeyType::RSA); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 588 | |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 589 | const uint8_t plaintext[] = {0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07}; |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 590 | |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 591 | auto ciphertext = pKey.encrypt(plaintext); |
| 592 | auto decrypted = sKey.decrypt(*ciphertext); |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 593 | BOOST_CHECK_EQUAL_COLLECTIONS(plaintext, plaintext + sizeof(plaintext), |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 594 | decrypted->begin(), decrypted->end()); |
| 595 | } |
| 596 | |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 597 | BOOST_AUTO_TEST_CASE(UnsupportedDecryption) |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 598 | { |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 599 | OBufferStream os; |
| 600 | bufferSource("Y2lhbyFob2xhIWhlbGxvIQ==") >> base64Decode() >> streamSink(os); |
| 601 | |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 602 | auto ecKey = generatePrivateKey(EcKeyParams()); |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 603 | BOOST_CHECK_THROW(ecKey->decrypt(*os.buf()), PrivateKey::Error); |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 604 | |
| 605 | auto hmacKey = generatePrivateKey(HmacKeyParams()); |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 606 | BOOST_CHECK_THROW(hmacKey->decrypt(*os.buf()), PrivateKey::Error); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 607 | } |
| 608 | |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 609 | class RsaKeyGenParams |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 610 | { |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 611 | public: |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 612 | using Params = RsaKeyParams; |
| 613 | using hasPublicKey = std::true_type; |
| 614 | using canSavePkcs1 = std::true_type; |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 615 | |
| 616 | static void |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 617 | checkPublicKey(const Buffer&) |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 618 | { |
| 619 | } |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 620 | }; |
| 621 | |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 622 | class EcKeyGenParams |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 623 | { |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 624 | public: |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 625 | using Params = EcKeyParams; |
| 626 | using hasPublicKey = std::true_type; |
| 627 | using canSavePkcs1 = std::true_type; |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 628 | |
| 629 | static void |
| 630 | checkPublicKey(const Buffer& bits) |
| 631 | { |
| 632 | // EC key generation should use named curve format. See https://redmine.named-data.net/issues/5037 |
| 633 | // OBJECT IDENTIFIER 1.2.840.10045.3.1.7 prime256v1 (ANSI X9.62 named elliptic curve) |
| 634 | const uint8_t oid[] = {0x06, 0x08, 0x2A, 0x86, 0x48, 0xCE, 0x3D, 0x03, 0x01, 0x07}; |
| 635 | BOOST_CHECK_MESSAGE(std::search(bits.begin(), bits.end(), oid, oid + sizeof(oid)) != bits.end(), |
| 636 | "OID not found in " << toHex(bits)); |
| 637 | } |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 638 | }; |
| 639 | |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 640 | class HmacKeyGenParams |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 641 | { |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 642 | public: |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 643 | using Params = HmacKeyParams; |
| 644 | using hasPublicKey = std::false_type; |
| 645 | using canSavePkcs1 = std::false_type; |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 646 | |
| 647 | static void |
Davide Pesavento | ea9e43e | 2021-09-20 00:45:03 -0400 | [diff] [blame] | 648 | checkPublicKey(const Buffer&) |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 649 | { |
| 650 | } |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 651 | }; |
| 652 | |
Davide Pesavento | 94dfcf1 | 2021-09-26 14:18:45 -0400 | [diff] [blame] | 653 | using KeyGenParams = boost::mpl::vector< |
| 654 | #if OPENSSL_VERSION_NUMBER < 0x30000000L // FIXME #5154 |
| 655 | HmacKeyGenParams, |
| 656 | #endif |
| 657 | RsaKeyGenParams, |
| 658 | EcKeyGenParams |
| 659 | >; |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 660 | |
| 661 | BOOST_AUTO_TEST_CASE_TEMPLATE(GenerateKey, T, KeyGenParams) |
| 662 | { |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 663 | typename T::Params params; |
| 664 | auto sKey = generatePrivateKey(params); |
| 665 | BOOST_CHECK_EQUAL(sKey->getKeyType(), params.getKeyType()); |
| 666 | BOOST_CHECK_EQUAL(sKey->getKeySize(), params.getKeySize()); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 667 | |
Luca Keidel | 941fd8c | 2017-07-24 15:21:22 +0200 | [diff] [blame] | 668 | const uint8_t data[] = {0x01, 0x02, 0x03, 0x04}; |
Yingdi Yu | b263f15 | 2015-07-12 16:50:13 -0700 | [diff] [blame] | 669 | OBufferStream os; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 670 | BOOST_REQUIRE_NO_THROW(bufferSource(data) >> |
Yingdi Yu | b263f15 | 2015-07-12 16:50:13 -0700 | [diff] [blame] | 671 | signerFilter(DigestAlgorithm::SHA256, *sKey) >> |
| 672 | streamSink(os)); |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 673 | auto sig = os.buf(); |
Yingdi Yu | b263f15 | 2015-07-12 16:50:13 -0700 | [diff] [blame] | 674 | |
Yingdi Yu | b263f15 | 2015-07-12 16:50:13 -0700 | [diff] [blame] | 675 | bool result = false; |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 676 | if (typename T::hasPublicKey()) { |
| 677 | auto pKeyBits = sKey->derivePublicKey(); |
Junxiao Shi | fbb6990 | 2020-04-24 08:39:18 +0000 | [diff] [blame] | 678 | BOOST_REQUIRE(pKeyBits != nullptr); |
| 679 | T::checkPublicKey(*pKeyBits); |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 680 | PublicKey pKey; |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 681 | pKey.loadPkcs8(*pKeyBits); |
| 682 | BOOST_CHECK_NO_THROW(bufferSource(data) >> |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 683 | verifierFilter(DigestAlgorithm::SHA256, pKey, *sig) >> |
Yingdi Yu | b263f15 | 2015-07-12 16:50:13 -0700 | [diff] [blame] | 684 | boolSink(result)); |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 685 | } |
| 686 | else { |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 687 | BOOST_CHECK_THROW(sKey->derivePublicKey(), PrivateKey::Error); |
Davide Pesavento | 765abc9 | 2021-12-27 00:44:04 -0500 | [diff] [blame] | 688 | BOOST_CHECK_NO_THROW(bufferSource(data) >> |
Davide Pesavento | 35c6379 | 2022-01-17 02:06:03 -0500 | [diff] [blame] | 689 | verifierFilter(DigestAlgorithm::SHA256, *sKey, *sig) >> |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 690 | boolSink(result)); |
| 691 | } |
Yingdi Yu | b263f15 | 2015-07-12 16:50:13 -0700 | [diff] [blame] | 692 | BOOST_CHECK(result); |
| 693 | |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 694 | if (typename T::canSavePkcs1()) { |
Davide Pesavento | 1bac111 | 2019-06-13 21:48:46 -0400 | [diff] [blame] | 695 | auto sKey2 = generatePrivateKey(params); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 696 | |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 697 | OBufferStream os1; |
| 698 | sKey->savePkcs1(os1); |
| 699 | OBufferStream os2; |
| 700 | sKey2->savePkcs1(os2); |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 701 | |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 702 | BOOST_CHECK(*os1.buf() != *os2.buf()); |
| 703 | } |
| 704 | else { |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 705 | OBufferStream os1; |
| 706 | BOOST_CHECK_THROW(sKey->savePkcs1(os1), PrivateKey::Error); |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 707 | } |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 708 | } |
| 709 | |
Laqin Fan | 0fe72ea | 2019-05-22 16:42:59 -0500 | [diff] [blame] | 710 | BOOST_AUTO_TEST_CASE(GenerateKeyUnsupportedType) |
Davide Pesavento | f45fa21 | 2017-09-14 17:23:56 -0400 | [diff] [blame] | 711 | { |
| 712 | BOOST_CHECK_THROW(generatePrivateKey(AesKeyParams()), std::invalid_argument); |
| 713 | } |
| 714 | |
Yingdi Yu | 202a2e9 | 2015-07-12 16:49:25 -0700 | [diff] [blame] | 715 | BOOST_AUTO_TEST_SUITE_END() // TestPrivateKey |
| 716 | BOOST_AUTO_TEST_SUITE_END() // Transform |
| 717 | BOOST_AUTO_TEST_SUITE_END() // Security |
| 718 | |
| 719 | } // namespace tests |
| 720 | } // namespace transform |
| 721 | } // namespace security |
| 722 | } // namespace ndn |