Blame tests/x509sign-verify-common.h

Packit aea12f
#ifndef GNUTLS_TESTS_X509SIGN_VERIFY_COMMON_H
Packit aea12f
#define GNUTLS_TESTS_X509SIGN_VERIFY_COMMON_H
Packit aea12f
Packit aea12f
static void tls_log_func(int level, const char *str)
Packit aea12f
{
Packit aea12f
	fprintf(stderr, "<%d> %s", level, str);
Packit aea12f
}
Packit aea12f
Packit aea12f
/* sha1 hash of "hello" string */
Packit aea12f
const gnutls_datum_t sha1_data = {
Packit aea12f
	(void *)
Packit aea12f
	    "\xaa\xf4\xc6\x1d\xdc\xc5\xe8\xa2\xda\xbe"
Packit aea12f
	    "\xde\x0f\x3b\x48\x2c\xd9\xae\xa9\x43\x4d",
Packit aea12f
	20
Packit aea12f
};
Packit aea12f
Packit aea12f
/* sha1 hash of "hello" string */
Packit aea12f
const gnutls_datum_t sha256_data = {
Packit aea12f
	(void *)
Packit aea12f
	    "\x2c\xf2\x4d\xba\x5f\xb0\xa3\x0e\x26\xe8"
Packit aea12f
	    "\x3b\x2a\xc5\xb9\xe2\x9e\x1b\x16\x1e\x5c"
Packit aea12f
	    "\x1f\xa7\x42\x5e\x73\x04\x33\x62\x93\x8b"
Packit aea12f
	    "\x98\x24",
Packit aea12f
	32
Packit aea12f
};
Packit aea12f
Packit aea12f
/* gost r 34.11-94 hash of "hello" string */
Packit aea12f
const gnutls_datum_t gostr94_data = {
Packit aea12f
	(void *)
Packit aea12f
	    "\x92\xea\x6d\xdb\xaf\x40\x02\x0d\xf3\x65"
Packit aea12f
	    "\x1f\x27\x8f\xd7\x15\x12\x17\xa2\x4a\xa8"
Packit aea12f
	    "\xd2\x2e\xbd\x25\x19\xcf\xd4\xd8\x9e\x64"
Packit aea12f
	    "\x50\xea",
Packit aea12f
	32
Packit aea12f
};
Packit aea12f
Packit aea12f
/* Streebog-256 hash of "hello" string */
Packit aea12f
const gnutls_datum_t streebog256_data = {
Packit aea12f
	(void *)
Packit aea12f
	    "\x3f\xb0\x70\x0a\x41\xce\x6e\x41\x41\x3b"
Packit aea12f
	    "\xa7\x64\xf9\x8b\xf2\x13\x5b\xa6\xde\xd5"
Packit aea12f
	    "\x16\xbe\xa2\xfa\xe8\x42\x9c\xc5\xbd\xd4"
Packit aea12f
	    "\x6d\x6d",
Packit aea12f
	32
Packit aea12f
};
Packit aea12f
Packit aea12f
/* Streebog-512 hash of "hello" string */
Packit aea12f
const gnutls_datum_t streebog512_data = {
Packit aea12f
	(void *)
Packit aea12f
	    "\x8d\xf4\x14\x26\x09\x66\xbe\xb7\xb3\x4d"
Packit aea12f
	    "\x92\x07\x63\x07\x9e\x15\xdf\x1f\x63\x29"
Packit aea12f
	    "\x7e\xb3\xdd\x43\x11\xe8\xb5\x85\xd4\xbf"
Packit aea12f
	    "\x2f\x59\x23\x21\x4f\x1d\xfe\xd3\xfd\xee"
Packit aea12f
	    "\x4a\xaf\x01\x83\x30\xa1\x2a\xcd\xe0\xef"
Packit aea12f
	    "\xcc\x33\x8e\xb5\x29\x22\xf3\xe5\x71\x21"
Packit aea12f
	    "\x2d\x42\xc8\xde",
Packit aea12f
	64
Packit aea12f
};
Packit aea12f
Packit aea12f
const gnutls_datum_t invalid_hash_data = {
Packit aea12f
	(void *)
Packit aea12f
	    "\xaa\xf4\xc6\x1d\xdc\xca\xe8\xa2\xda\xbe"
Packit aea12f
	    "\xde\x0f\x3b\x48\x2c\xb9\xae\xa9\x43\x4d",
Packit aea12f
	20
Packit aea12f
};
Packit aea12f
Packit aea12f
const gnutls_datum_t raw_data = {
Packit aea12f
	(void *)"hello",
Packit aea12f
	5
Packit aea12f
};
Packit aea12f
Packit aea12f
Packit aea12f
static void print_keys(gnutls_privkey_t privkey, gnutls_pubkey_t pubkey)
Packit aea12f
{
Packit aea12f
	gnutls_x509_privkey_t xkey;
Packit aea12f
	gnutls_datum_t out;
Packit aea12f
	int ret = gnutls_privkey_export_x509(privkey, &xkey);
Packit aea12f
Packit aea12f
	if (ret < 0)
Packit aea12f
		fail("error in privkey export\n");
Packit aea12f
Packit aea12f
	ret = gnutls_x509_privkey_export2(xkey, GNUTLS_X509_FMT_PEM, &out;;
Packit aea12f
	if (ret < 0)
Packit aea12f
		fail("error in privkey export\n");
Packit aea12f
Packit aea12f
	fprintf(stderr, "%s\n", out.data);
Packit aea12f
	gnutls_free(out.data);
Packit aea12f
Packit aea12f
	ret = gnutls_pubkey_export2(pubkey, GNUTLS_X509_FMT_PEM, &out;;
Packit aea12f
	if (ret < 0)
Packit aea12f
		fail("error in pubkey export\n");
Packit aea12f
Packit aea12f
	fprintf(stderr, "%s\n", out.data);
Packit aea12f
	gnutls_free(out.data);
Packit aea12f
Packit aea12f
	gnutls_x509_privkey_deinit(xkey);
Packit aea12f
}
Packit aea12f
Packit aea12f
#define ERR fail("Failure at: %s (%s-%s) (iter: %d)\n", gnutls_sign_get_name(sign_algo), gnutls_pk_get_name(pk), gnutls_digest_get_name(hash), j);
Packit aea12f
static
Packit aea12f
void test_sig(gnutls_pk_algorithm_t pk, unsigned hash, unsigned bits)
Packit aea12f
{
Packit aea12f
	gnutls_pubkey_t pubkey;
Packit aea12f
	gnutls_privkey_t privkey;
Packit aea12f
	gnutls_sign_algorithm_t sign_algo;
Packit aea12f
	gnutls_datum_t signature;
Packit aea12f
	const gnutls_datum_t *hash_data;
Packit aea12f
	int ret;
Packit aea12f
	unsigned j;
Packit aea12f
	unsigned vflags = 0;
Packit aea12f
Packit aea12f
	if (hash == GNUTLS_DIG_SHA1) {
Packit aea12f
		hash_data = &sha1_data;
Packit aea12f
		vflags |= GNUTLS_VERIFY_ALLOW_SIGN_WITH_SHA1;
Packit aea12f
	} else if (hash == GNUTLS_DIG_SHA256)
Packit aea12f
		hash_data = &sha256_data;
Packit aea12f
	else if (hash == GNUTLS_DIG_GOSTR_94)
Packit aea12f
		hash_data = &gostr94_data;
Packit aea12f
	else if (hash == GNUTLS_DIG_STREEBOG_256)
Packit aea12f
		hash_data = &streebog256_data;
Packit aea12f
	else if (hash == GNUTLS_DIG_STREEBOG_512)
Packit aea12f
		hash_data = &streebog512_data;
Packit aea12f
	else
Packit aea12f
		abort();
Packit aea12f
Packit aea12f
	sign_algo =
Packit aea12f
	    gnutls_pk_to_sign(pk, hash);
Packit aea12f
Packit aea12f
	for (j = 0; j < 100; j++) {
Packit aea12f
		ret = gnutls_pubkey_init(&pubkey);
Packit aea12f
		if (ret < 0)
Packit aea12f
			ERR;
Packit aea12f
Packit aea12f
		ret = gnutls_privkey_init(&privkey);
Packit aea12f
		if (ret < 0)
Packit aea12f
			ERR;
Packit aea12f
Packit aea12f
		ret = gnutls_privkey_generate(privkey, pk, bits, 0);
Packit aea12f
		if (ret < 0)
Packit aea12f
			ERR;
Packit aea12f
Packit aea12f
		ret =
Packit aea12f
		    gnutls_privkey_sign_hash(privkey, hash,
Packit aea12f
					     0, hash_data,
Packit aea12f
					     &signature);
Packit aea12f
		if (ret < 0)
Packit aea12f
			ERR;
Packit aea12f
Packit aea12f
		ret = gnutls_pubkey_import_privkey(pubkey, privkey, GNUTLS_KEY_DIGITAL_SIGNATURE, 0);
Packit aea12f
		if (ret < 0)
Packit aea12f
			ERR;
Packit aea12f
Packit aea12f
		ret =
Packit aea12f
		    gnutls_pubkey_verify_hash2(pubkey,
Packit aea12f
						sign_algo, vflags,
Packit aea12f
						hash_data, &signature);
Packit aea12f
		if (ret < 0) {
Packit aea12f
			print_keys(privkey, pubkey);
Packit aea12f
			ERR;
Packit aea12f
		}
Packit aea12f
Packit aea12f
		/* should fail */
Packit aea12f
		ret =
Packit aea12f
		    gnutls_pubkey_verify_hash2(pubkey,
Packit aea12f
						sign_algo, vflags,
Packit aea12f
						&invalid_hash_data,
Packit aea12f
						&signature);
Packit aea12f
		if (ret != GNUTLS_E_PK_SIG_VERIFY_FAILED) {
Packit aea12f
			print_keys(privkey, pubkey);
Packit aea12f
			ERR;
Packit aea12f
		}
Packit aea12f
Packit aea12f
		sign_algo =
Packit aea12f
		    gnutls_pk_to_sign(gnutls_pubkey_get_pk_algorithm
Packit aea12f
				      (pubkey, NULL), hash);
Packit aea12f
Packit aea12f
		ret =
Packit aea12f
		    gnutls_pubkey_verify_hash2(pubkey, sign_algo, vflags,
Packit aea12f
						hash_data, &signature);
Packit aea12f
		if (ret < 0)
Packit aea12f
			ERR;
Packit aea12f
Packit aea12f
		/* should fail */
Packit aea12f
		ret =
Packit aea12f
		    gnutls_pubkey_verify_hash2(pubkey, sign_algo, vflags,
Packit aea12f
						&invalid_hash_data,
Packit aea12f
						&signature);
Packit aea12f
		if (ret != GNUTLS_E_PK_SIG_VERIFY_FAILED) {
Packit aea12f
			print_keys(privkey, pubkey);
Packit aea12f
			ERR;
Packit aea12f
		}
Packit aea12f
Packit aea12f
		/* test the raw interface */
Packit aea12f
		gnutls_free(signature.data);
Packit aea12f
		signature.data = NULL;
Packit aea12f
Packit aea12f
		if (pk == GNUTLS_PK_RSA) {
Packit aea12f
			ret =
Packit aea12f
			    gnutls_privkey_sign_hash(privkey,
Packit aea12f
						     hash,
Packit aea12f
						     GNUTLS_PRIVKEY_SIGN_FLAG_TLS1_RSA,
Packit aea12f
						     hash_data,
Packit aea12f
						     &signature);
Packit aea12f
			if (ret < 0)
Packit aea12f
				ERR;
Packit aea12f
Packit aea12f
			sign_algo =
Packit aea12f
			    gnutls_pk_to_sign
Packit aea12f
			    (gnutls_pubkey_get_pk_algorithm
Packit aea12f
			     (pubkey, NULL), hash);
Packit aea12f
Packit aea12f
			ret =
Packit aea12f
			    gnutls_pubkey_verify_hash2(pubkey,
Packit aea12f
							sign_algo,
Packit aea12f
							vflags|GNUTLS_PUBKEY_VERIFY_FLAG_TLS1_RSA,
Packit aea12f
							hash_data,
Packit aea12f
							&signature);
Packit aea12f
			if (ret < 0) {
Packit aea12f
				print_keys(privkey, pubkey);
Packit aea12f
				ERR;
Packit aea12f
			}
Packit aea12f
Packit aea12f
		}
Packit aea12f
		gnutls_free(signature.data);
Packit aea12f
		gnutls_privkey_deinit(privkey);
Packit aea12f
		gnutls_pubkey_deinit(pubkey);
Packit aea12f
	}
Packit aea12f
}
Packit aea12f
Packit aea12f
#endif /* GNUTLS_TESTS_X509SIGN_VERIFY_COMMON_H */