blob: 63fd03e8089eec8bd71832f273e107872fe76184 [file] [log] [blame]
Yingdi Yub263f152015-07-12 16:50:13 -07001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
Davide Pesavento6158f472017-08-11 18:55:09 -04002/*
Davide Pesavento94dfcf12021-09-26 14:18:45 -04003 * Copyright (c) 2013-2021 Regents of the University of California.
Yingdi Yub263f152015-07-12 16:50:13 -07004 *
5 * This file is part of ndn-cxx library (NDN C++ library with eXperimental eXtensions).
6 *
7 * ndn-cxx library is free software: you can redistribute it and/or modify it under the
8 * terms of the GNU Lesser General Public License as published by the Free Software
9 * Foundation, either version 3 of the License, or (at your option) any later version.
10 *
11 * ndn-cxx library is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU Lesser General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License and GNU Lesser
16 * General Public License along with ndn-cxx, e.g., in COPYING.md file. If not, see
17 * <http://www.gnu.org/licenses/>.
18 *
19 * See AUTHORS.md for complete list of ndn-cxx authors and contributors.
20 */
21
Davide Pesavento7e780642018-11-24 15:51:34 -050022#include "ndn-cxx/security/transform/verifier-filter.hpp"
Yingdi Yub263f152015-07-12 16:50:13 -070023
Davide Pesavento7e780642018-11-24 15:51:34 -050024#include "ndn-cxx/encoding/buffer-stream.hpp"
Davide Pesavento94dfcf12021-09-26 14:18:45 -040025#include "ndn-cxx/security/impl/openssl.hpp"
Laqin Fan0fe72ea2019-05-22 16:42:59 -050026#include "ndn-cxx/security/key-params.hpp"
Davide Pesavento7e780642018-11-24 15:51:34 -050027#include "ndn-cxx/security/transform/base64-decode.hpp"
28#include "ndn-cxx/security/transform/bool-sink.hpp"
29#include "ndn-cxx/security/transform/buffer-source.hpp"
30#include "ndn-cxx/security/transform/private-key.hpp"
31#include "ndn-cxx/security/transform/public-key.hpp"
32#include "ndn-cxx/security/transform/signer-filter.hpp"
33#include "ndn-cxx/security/transform/stream-sink.hpp"
Yingdi Yub263f152015-07-12 16:50:13 -070034
Davide Pesavento7e780642018-11-24 15:51:34 -050035#include "tests/boost-test.hpp"
Yingdi Yub263f152015-07-12 16:50:13 -070036
37namespace ndn {
38namespace security {
39namespace transform {
40namespace tests {
41
42BOOST_AUTO_TEST_SUITE(Security)
43BOOST_AUTO_TEST_SUITE(Transform)
44BOOST_AUTO_TEST_SUITE(TestVerifierFilter)
45
Laqin Fan0fe72ea2019-05-22 16:42:59 -050046const uint8_t DATA[] = {0x01, 0x02, 0x03, 0x04};
47
Yingdi Yub263f152015-07-12 16:50:13 -070048BOOST_AUTO_TEST_CASE(Rsa)
49{
Davide Pesavento6158f472017-08-11 18:55:09 -040050 const std::string publicKeyPkcs8 =
Yingdi Yub263f152015-07-12 16:50:13 -070051 "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAw0WM1/WhAxyLtEqsiAJg\n"
52 "WDZWuzkYpeYVdeeZcqRZzzfRgBQTsNozS5t4HnwTZhwwXbH7k3QN0kRTV826Xobw\n"
53 "s3iigohnM9yTK+KKiayPhIAm/+5HGT6SgFJhYhqo1/upWdueojil6RP4/AgavHho\n"
54 "pxlAVbk6G9VdVnlQcQ5Zv0OcGi73c+EnYD/YgURYGSngUi/Ynsh779p2U69/te9g\n"
55 "ZwIL5PuE9BiO6I39cL9z7EK1SfZhOWvDe/qH7YhD/BHwcWit8FjRww1glwRVTJsA\n"
56 "9rH58ynaAix0tcR/nBMRLUX+e3rURHg6UbSjJbdb9qmKM1fTGHKUzL/5pMG6uBU0\n"
57 "ywIDAQAB\n";
Davide Pesavento6158f472017-08-11 18:55:09 -040058 const std::string privateKeyPkcs1 =
Yingdi Yub263f152015-07-12 16:50:13 -070059 "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDDRYzX9aEDHIu0\n"
60 "SqyIAmBYNla7ORil5hV155lypFnPN9GAFBOw2jNLm3gefBNmHDBdsfuTdA3SRFNX\n"
61 "zbpehvCzeKKCiGcz3JMr4oqJrI+EgCb/7kcZPpKAUmFiGqjX+6lZ256iOKXpE/j8\n"
62 "CBq8eGinGUBVuTob1V1WeVBxDlm/Q5waLvdz4SdgP9iBRFgZKeBSL9ieyHvv2nZT\n"
63 "r3+172BnAgvk+4T0GI7ojf1wv3PsQrVJ9mE5a8N7+oftiEP8EfBxaK3wWNHDDWCX\n"
64 "BFVMmwD2sfnzKdoCLHS1xH+cExEtRf57etREeDpRtKMlt1v2qYozV9MYcpTMv/mk\n"
65 "wbq4FTTLAgMBAAECggEANCRyQ4iXghkxROdbwsW/rE52QnAwoLwbpuw9EVvJj4e8\n"
66 "LZMu3t6lK99L5/gBxhZo49wO7YTj2+3aw2twBKXLyGDCJFEAHd0cf29yxuiJOjxu\n"
67 "LZEW8yq+O/3De0rbIzFUO2ZlqbOuudpXdhVD7mfIqjYX88wONDh5QAoM7OOEG4oe\n"
68 "xkFMWcDUwU0j5QqPlfhinrgMWYqXFNf9TZvDNXLCjmHPHZSHDnWOaguWzhhS8wlc\n"
69 "PTBblm1hG4+iBe9dv+h/15//bT/BTXVYUqBdviB9HzNRdpdLWxdydWbf7bi8iz10\n"
70 "ClTDKS6jKM6rFapwdF5zZBPYXFUaQUStrN4I9riswQKBgQDljwLLCiYhxOB6sUYU\n"
71 "J4wcmvydAapjZX+jAVveT2ZpzM+cL2nhr1FzmzMvED0UxgXG6tBkwFZIQbYlLUdH\n"
72 "aaeOKDHxQqNgwv8D6u++Nk4x7gzpLLaCCHhKQtkqlZPONN7TsHIz+Pm/9KM1mFYA\n"
73 "buzDj8uY8ZFCTAm/4pmEaiO46QKBgQDZw4VPpwlG/qS/NPP1LQI5k5Wb564mH8Fe\n"
74 "nugCwCZs186lyQ8zOodfLz/Cl0qXoABwHns67O2U19XUPuq9vPsm5GVjBDRwR8GB\n"
75 "tk9zPWnXwccNeHCfntk9vwbfdiH06aDQc0AiZvguxW5KrEDo3BKPtylF6SBN52uE\n"
76 "sU8n5h1vkwKBgQCwzdDs6MgtwiDS3q6G316+uXBOzPWa0JXZyjYjpyvN2P0d4ja+\n"
77 "p/UoASUO3obs9QeGCVyv/KN3y4SqZZE8o1d12ed9VkHXSNh4//3elpzrP9mZzeJT\n"
78 "jIp5R7tTXRkV/QqSKJgNB3n0Kkt5//ZdJxIcHShGh+fFFCN+Mtzia41P4QKBgQCV\n"
79 "wOTTow45OXL4XyUJzVsDV2ACaDAV3a6wMF1jTtrd7QcacYs3cp+XsLmLS1mrrge/\n"
80 "Eucx3a+AtXFCVcY+l1CsLVMf5cteD6qeVk6K9IfuLT+DHvlse+Pvl4fVcrrlXykN\n"
81 "UMShI+i22WUAizbULEvDc3U5s5lYmbYR+ZFy4cgKawKBgC0UnWJ2oygfERLeaVGl\n"
82 "/YnHJC50/dIKbZakaapXOFFgiep5q1jmxR2U8seb+nvtFPsTLFAdOXCfwUk+4z/h\n"
83 "kfWtB3+8H5jyoC1gkJ7EMyxu8tb4mz5U6+SPB4QLSetwvfWP2YXS/PkTq19G7iGE\n"
84 "novjJ9azSBJ6OyR5UH/DxBji\n";
Yingdi Yub263f152015-07-12 16:50:13 -070085
86 OBufferStream os1;
87 bufferSource(publicKeyPkcs8) >> base64Decode() >> streamSink(os1);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -040088 auto pubKey = os1.buf();
Yingdi Yub263f152015-07-12 16:50:13 -070089
90 PublicKey pKey;
Davide Pesavento5d0b0102017-10-07 13:43:16 -040091 pKey.loadPkcs8(pubKey->data(), pubKey->size());
Davide Pesavento6158f472017-08-11 18:55:09 -040092
93 PrivateKey sKey;
94 sKey.loadPkcs1Base64(reinterpret_cast<const uint8_t*>(privateKeyPkcs1.data()), privateKeyPkcs1.size());
95
96 OBufferStream os2;
Laqin Fan0fe72ea2019-05-22 16:42:59 -050097 bufferSource(DATA, sizeof(DATA)) >> signerFilter(DigestAlgorithm::SHA256, sKey) >> streamSink(os2);
Davide Pesavento6158f472017-08-11 18:55:09 -040098 auto sig = os2.buf();
99
Davide Pesavento5d0b0102017-10-07 13:43:16 -0400100 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::NONE, pKey, sig->data(), sig->size()), Error);
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500101 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, sKey, sig->data(), sig->size()), Error);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400102
Davide Pesavento6158f472017-08-11 18:55:09 -0400103 bool result = false;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500104 bufferSource(DATA, sizeof(DATA)) >>
Davide Pesavento5d0b0102017-10-07 13:43:16 -0400105 verifierFilter(DigestAlgorithm::SHA256, pKey, sig->data(), sig->size()) >>
Davide Pesavento6158f472017-08-11 18:55:09 -0400106 boolSink(result);
Yingdi Yub263f152015-07-12 16:50:13 -0700107
108 BOOST_CHECK_EQUAL(result, true);
109}
110
111BOOST_AUTO_TEST_CASE(Ecdsa)
112{
Davide Pesavento6158f472017-08-11 18:55:09 -0400113 const std::string privateKeyPkcs1 =
Yingdi Yub263f152015-07-12 16:50:13 -0700114 "MIIBeQIBADCCAQMGByqGSM49AgEwgfcCAQEwLAYHKoZIzj0BAQIhAP////8AAAAB\n"
115 "AAAAAAAAAAAAAAAA////////////////MFsEIP////8AAAABAAAAAAAAAAAAAAAA\n"
116 "///////////////8BCBaxjXYqjqT57PrvVV2mIa8ZR0GsMxTsPY7zjw+J9JgSwMV\n"
117 "AMSdNgiG5wSTamZ44ROdJreBn36QBEEEaxfR8uEsQkf4vOblY6RA8ncDfYEt6zOg\n"
118 "9KE5RdiYwpZP40Li/hp/m47n60p8D54WK84zV2sxXs7LtkBoN79R9QIhAP////8A\n"
119 "AAAA//////////+85vqtpxeehPO5ysL8YyVRAgEBBG0wawIBAQQgRxwcbzK9RV6A\n"
120 "HYFsDcykI86o3M/a1KlJn0z8PcLMBZOhRANCAARobhYm4MC3RCQQzi3b0oNR3ORC\n"
121 "Uw8aupbORaGC304afBzo7sBks9KsPKHDKspLtctFeaXkOKxD3dG8HKWXfbLw\n";
Davide Pesavento6158f472017-08-11 18:55:09 -0400122 const std::string publicKeyPkcs8 =
Yingdi Yub263f152015-07-12 16:50:13 -0700123 "MIIBSzCCAQMGByqGSM49AgEwgfcCAQEwLAYHKoZIzj0BAQIhAP////8AAAABAAAA\n"
124 "AAAAAAAAAAAA////////////////MFsEIP////8AAAABAAAAAAAAAAAAAAAA////\n"
125 "///////////8BCBaxjXYqjqT57PrvVV2mIa8ZR0GsMxTsPY7zjw+J9JgSwMVAMSd\n"
126 "NgiG5wSTamZ44ROdJreBn36QBEEEaxfR8uEsQkf4vOblY6RA8ncDfYEt6zOg9KE5\n"
127 "RdiYwpZP40Li/hp/m47n60p8D54WK84zV2sxXs7LtkBoN79R9QIhAP////8AAAAA\n"
128 "//////////+85vqtpxeehPO5ysL8YyVRAgEBA0IABGhuFibgwLdEJBDOLdvSg1Hc\n"
129 "5EJTDxq6ls5FoYLfThp8HOjuwGSz0qw8ocMqyku1y0V5peQ4rEPd0bwcpZd9svA=\n";
Yingdi Yub263f152015-07-12 16:50:13 -0700130
131 OBufferStream os1;
132 bufferSource(publicKeyPkcs8) >> base64Decode() >> streamSink(os1);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400133 auto pubKey = os1.buf();
Yingdi Yub263f152015-07-12 16:50:13 -0700134
135 PublicKey pKey;
Davide Pesavento5d0b0102017-10-07 13:43:16 -0400136 pKey.loadPkcs8(pubKey->data(), pubKey->size());
Davide Pesavento6158f472017-08-11 18:55:09 -0400137
138 PrivateKey sKey;
139 sKey.loadPkcs1Base64(reinterpret_cast<const uint8_t*>(privateKeyPkcs1.data()), privateKeyPkcs1.size());
140
141 OBufferStream os2;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500142 bufferSource(DATA, sizeof(DATA)) >> signerFilter(DigestAlgorithm::SHA256, sKey) >> streamSink(os2);
Davide Pesavento6158f472017-08-11 18:55:09 -0400143 auto sig = os2.buf();
144
Davide Pesavento5d0b0102017-10-07 13:43:16 -0400145 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::NONE, pKey, sig->data(), sig->size()), Error);
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500146 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, sKey, sig->data(), sig->size()), Error);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400147
Davide Pesavento6158f472017-08-11 18:55:09 -0400148 bool result = false;
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500149 bufferSource(DATA, sizeof(DATA)) >>
Davide Pesavento5d0b0102017-10-07 13:43:16 -0400150 verifierFilter(DigestAlgorithm::SHA256, pKey, sig->data(), sig->size()) >>
Davide Pesavento6158f472017-08-11 18:55:09 -0400151 boolSink(result);
Yingdi Yub263f152015-07-12 16:50:13 -0700152
153 BOOST_CHECK_EQUAL(result, true);
154}
155
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500156BOOST_AUTO_TEST_CASE(Hmac)
157{
158 auto sKey = generatePrivateKey(HmacKeyParams());
159
160 OBufferStream os;
161 bufferSource(DATA, sizeof(DATA)) >> signerFilter(DigestAlgorithm::SHA256, *sKey) >> streamSink(os);
162 auto sig = os.buf();
163
164 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::NONE, *sKey, sig->data(), sig->size()), Error);
165
Davide Pesavento94dfcf12021-09-26 14:18:45 -0400166#if OPENSSL_VERSION_NUMBER < 0x30000000L // FIXME #5154
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500167 bool result = false;
168 bufferSource(DATA, sizeof(DATA)) >>
169 verifierFilter(DigestAlgorithm::SHA256, *sKey, sig->data(), sig->size()) >>
170 boolSink(result);
171
172 BOOST_CHECK_EQUAL(result, true);
Davide Pesavento94dfcf12021-09-26 14:18:45 -0400173#endif
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500174}
175
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400176BOOST_AUTO_TEST_CASE(InvalidKey)
177{
Laqin Fan0fe72ea2019-05-22 16:42:59 -0500178 PublicKey pubKey;
179 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, pubKey, nullptr, 0), Error);
180 PrivateKey privKey;
181 BOOST_CHECK_THROW(VerifierFilter(DigestAlgorithm::SHA256, privKey, nullptr, 0), Error);
Davide Pesavento8a14b9b2017-09-17 01:26:06 -0400182}
183
Yingdi Yub263f152015-07-12 16:50:13 -0700184BOOST_AUTO_TEST_SUITE_END() // TestVerifierFilter
185BOOST_AUTO_TEST_SUITE_END() // Transform
186BOOST_AUTO_TEST_SUITE_END() // Security
187
188} // namespace tests
189} // namespace transform
190} // namespace security
191} // namespace ndn