Blame nss/cmd/libpkix/pkix/top/test_buildchain_partialchain.c

Packit 40b132
/* This Source Code Form is subject to the terms of the Mozilla Public
Packit 40b132
 * License, v. 2.0. If a copy of the MPL was not distributed with this
Packit 40b132
 * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
Packit 40b132
/*
Packit 40b132
 * test_buildchain_partialchain.c
Packit 40b132
 *
Packit 40b132
 * Test BuildChain function
Packit 40b132
 *
Packit 40b132
 */
Packit 40b132
Packit 40b132
#define debuggingWithoutRevocation
Packit 40b132
Packit 40b132
#include "testutil.h"
Packit 40b132
#include "testutil_nss.h"
Packit 40b132
Packit 40b132
#define LDAP_PORT 389
Packit 40b132
static PKIX_Boolean usebind = PKIX_FALSE;
Packit 40b132
static PKIX_Boolean useLDAP = PKIX_FALSE;
Packit 40b132
static char buf[PR_NETDB_BUF_SIZE];
Packit 40b132
static char *serverName = NULL;
Packit 40b132
static char *sepPtr = NULL;
Packit 40b132
static PRNetAddr netAddr;
Packit 40b132
static PRHostEnt hostent;
Packit 40b132
static PKIX_UInt32 portNum = 0;
Packit 40b132
static PRIntn hostenum = 0;
Packit 40b132
static PRStatus prstatus = PR_FAILURE;
Packit 40b132
static void *ipaddr = NULL;
Packit 40b132
Packit 40b132
Packit 40b132
static void *plContext = NULL;
Packit 40b132
Packit 40b132
static void printUsage(void) {
Packit 40b132
    (void) printf("\nUSAGE:\ttest_buildchain [-arenas] [usebind] "
Packit 40b132
        "servername[:port] <testName> [ENE|EE]\n"
Packit 40b132
        "\t <certStoreDirectory> <targetCert>"
Packit 40b132
        " <intermediate Certs...> <trustedCert>\n\n");
Packit 40b132
    (void) printf
Packit 40b132
        ("Builds a chain of certificates from <targetCert> to <trustedCert>\n"
Packit 40b132
        "using the certs and CRLs in <certStoreDirectory>. "
Packit 40b132
        "servername[:port] gives\n"
Packit 40b132
        "the address of an LDAP server. If port is not"
Packit 40b132
        " specified, port 389 is used. \"-\" means no LDAP server.\n"
Packit 40b132
        "If ENE is specified, then an Error is Not Expected. "
Packit 40b132
        "EE indicates an Error is Expected.\n");
Packit 40b132
}
Packit 40b132
Packit 40b132
static PKIX_Error *
Packit 40b132
createLdapCertStore(
Packit 40b132
        char *hostname,
Packit 40b132
        PRIntervalTime timeout,
Packit 40b132
        PKIX_CertStore **pLdapCertStore,
Packit 40b132
        void* plContext)
Packit 40b132
{
Packit 40b132
        PRIntn backlog = 0;
Packit 40b132
Packit 40b132
        char *bindname = "";
Packit 40b132
        char *auth = "";
Packit 40b132
Packit 40b132
        LDAPBindAPI bindAPI;
Packit 40b132
        LDAPBindAPI *bindPtr = NULL;
Packit 40b132
        PKIX_PL_LdapDefaultClient *ldapClient = NULL;
Packit 40b132
        PKIX_CertStore *ldapCertStore = NULL;
Packit 40b132
Packit 40b132
        PKIX_TEST_STD_VARS();
Packit 40b132
Packit 40b132
        if (usebind) {
Packit 40b132
                bindPtr = &bindAPI;
Packit 40b132
                bindAPI.selector = SIMPLE_AUTH;
Packit 40b132
                bindAPI.chooser.simple.bindName = bindname;
Packit 40b132
                bindAPI.chooser.simple.authentication = auth;
Packit 40b132
        }
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_LdapDefaultClient_CreateByName
Packit 40b132
                (hostname, timeout, bindPtr, &ldapClient, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_LdapCertStore_Create
Packit 40b132
                ((PKIX_PL_LdapClient *)ldapClient,
Packit 40b132
                &ldapCertStore,
Packit 40b132
                plContext));
Packit 40b132
Packit 40b132
        *pLdapCertStore = ldapCertStore;
Packit 40b132
cleanup:
Packit 40b132
Packit 40b132
        PKIX_TEST_DECREF_AC(ldapClient);
Packit 40b132
Packit 40b132
        PKIX_TEST_RETURN();
Packit 40b132
Packit 40b132
        return (pkixTestErrorResult);
Packit 40b132
Packit 40b132
}
Packit 40b132
Packit 40b132
/* Test with all Certs in the partial list, no leaf */
Packit 40b132
static PKIX_Error *
Packit 40b132
testWithNoLeaf(
Packit 40b132
        PKIX_PL_Cert *trustedCert,
Packit 40b132
        PKIX_List *listOfCerts,
Packit 40b132
        PKIX_PL_Cert *targetCert,
Packit 40b132
        PKIX_List *certStores,
Packit 40b132
        PKIX_Boolean testValid,
Packit 40b132
        void* plContext)
Packit 40b132
{
Packit 40b132
        PKIX_UInt32 numCerts = 0;
Packit 40b132
        PKIX_UInt32 i = 0;
Packit 40b132
        PKIX_TrustAnchor *anchor = NULL;
Packit 40b132
        PKIX_List *anchors = NULL;
Packit 40b132
        PKIX_List *hintCerts = NULL;
Packit 40b132
        PKIX_List *revCheckers = NULL;
Packit 40b132
        PKIX_List *certs = NULL;
Packit 40b132
        PKIX_PL_Cert *cert = NULL;
Packit 40b132
        PKIX_ProcessingParams *procParams = NULL;
Packit 40b132
        PKIX_ComCertSelParams *certSelParams = NULL;
Packit 40b132
        PKIX_CertSelector *certSelector = NULL;
Packit 40b132
        PKIX_PL_PublicKey *trustedPubKey = NULL;
Packit 40b132
        PKIX_RevocationChecker *revChecker = NULL;
Packit 40b132
        PKIX_BuildResult *buildResult = NULL;
Packit 40b132
        PRPollDesc *pollDesc = NULL;
Packit 40b132
        void *state = NULL;
Packit 40b132
        char *asciiResult = NULL;
Packit 40b132
Packit 40b132
        PKIX_TEST_STD_VARS();
Packit 40b132
Packit 40b132
        /* create processing params with list of trust anchors */
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_TrustAnchor_CreateWithCert
Packit 40b132
                (trustedCert, &anchor, plContext));
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_Create(&anchors, plContext));
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_AppendItem
Packit 40b132
                (anchors, (PKIX_PL_Object *)anchor, plContext));
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_Create
Packit 40b132
                (anchors, &procParams, plContext));
Packit 40b132
Packit 40b132
        /* create CertSelector with no target certificate in params */
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ComCertSelParams_Create
Packit 40b132
                (&certSelParams, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_CertSelector_Create
Packit 40b132
                (NULL, NULL, &certSelector, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_CertSelector_SetCommonCertSelectorParams
Packit 40b132
                (certSelector, certSelParams, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetTargetCertConstraints
Packit 40b132
                (procParams, certSelector, plContext));
Packit 40b132
Packit 40b132
        /* create hintCerts */
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_Object_Duplicate
Packit 40b132
                ((PKIX_PL_Object *)listOfCerts,
Packit 40b132
                (PKIX_PL_Object **)&hintCerts,
Packit 40b132
                plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetHintCerts
Packit 40b132
                (procParams, hintCerts, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetCertStores
Packit 40b132
                (procParams, certStores, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_Create(&revCheckers, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_Cert_GetSubjectPublicKey
Packit 40b132
                (trustedCert, &trustedPubKey, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_GetLength
Packit 40b132
                (listOfCerts, &numCerts, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(pkix_DefaultRevChecker_Initialize
Packit 40b132
                (certStores,
Packit 40b132
                NULL, /* testDate, may be NULL */
Packit 40b132
                trustedPubKey,
Packit 40b132
                numCerts,
Packit 40b132
                &revChecker,
Packit 40b132
                plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_AppendItem
Packit 40b132
                (revCheckers, (PKIX_PL_Object *)revChecker, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetRevocationCheckers
Packit 40b132
                (procParams, revCheckers, plContext));
Packit 40b132
Packit 40b132
#ifdef debuggingWithoutRevocation
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetRevocationEnabled
Packit 40b132
                (procParams, PKIX_FALSE, plContext));
Packit 40b132
#endif
Packit 40b132
Packit 40b132
        /* build cert chain using processing params and return buildResult */
Packit 40b132
Packit 40b132
        pkixTestErrorResult = PKIX_BuildChain
Packit 40b132
                (procParams,
Packit 40b132
                (void **)&pollDesc,
Packit 40b132
                &state,
Packit 40b132
                &buildResult,
Packit 40b132
                NULL,
Packit 40b132
                plContext);
Packit 40b132
Packit 40b132
        while (pollDesc != NULL) {
Packit 40b132
Packit 40b132
                if (PR_Poll(pollDesc, 1, 0) < 0) {
Packit 40b132
                        testError("PR_Poll failed");
Packit 40b132
                }
Packit 40b132
Packit 40b132
                pkixTestErrorResult = PKIX_BuildChain
Packit 40b132
                        (procParams,
Packit 40b132
                        (void **)&pollDesc,
Packit 40b132
                        &state,
Packit 40b132
                        &buildResult,
Packit 40b132
                        NULL,
Packit 40b132
                        plContext);
Packit 40b132
        }
Packit 40b132
Packit 40b132
        if (pkixTestErrorResult) {
Packit 40b132
                if (testValid == PKIX_FALSE) { /* EE */
Packit 40b132
                        (void) printf("EXPECTED ERROR RECEIVED!\n");
Packit 40b132
                } else { /* ENE */
Packit 40b132
                        testError("UNEXPECTED ERROR RECEIVED");
Packit 40b132
                }
Packit 40b132
                PKIX_TEST_DECREF_BC(pkixTestErrorResult);
Packit 40b132
                goto cleanup;
Packit 40b132
        }
Packit 40b132
Packit 40b132
        if (testValid == PKIX_TRUE) { /* ENE */
Packit 40b132
                (void) printf("EXPECTED NON-ERROR RECEIVED!\n");
Packit 40b132
        } else { /* EE */
Packit 40b132
                (void) printf("UNEXPECTED NON-ERROR RECEIVED!\n");
Packit 40b132
        }
Packit 40b132
Packit 40b132
        if (buildResult) {
Packit 40b132
Packit 40b132
                PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                        (PKIX_BuildResult_GetCertChain
Packit 40b132
                        (buildResult, &certs, plContext));
Packit 40b132
Packit 40b132
                PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                        (PKIX_List_GetLength(certs, &numCerts, plContext));
Packit 40b132
Packit 40b132
                printf("\n");
Packit 40b132
Packit 40b132
                for (i = 0; i < numCerts; i++) {
Packit 40b132
                        PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                                (PKIX_List_GetItem
Packit 40b132
                                (certs,
Packit 40b132
                                i,
Packit 40b132
                                (PKIX_PL_Object**)&cert,
Packit 40b132
                                plContext));
Packit 40b132
Packit 40b132
                        asciiResult = PKIX_Cert2ASCII(cert);
Packit 40b132
Packit 40b132
                        printf("CERT[%d]:\n%s\n", i, asciiResult);
Packit 40b132
Packit 40b132
                        /* PKIX_Cert2ASCII used PKIX_PL_Malloc(...,,NULL) */
Packit 40b132
                        PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                                (PKIX_PL_Free(asciiResult, NULL));
Packit 40b132
                        asciiResult = NULL;
Packit 40b132
Packit 40b132
                        PKIX_TEST_DECREF_BC(cert);
Packit 40b132
                }
Packit 40b132
        }
Packit 40b132
Packit 40b132
cleanup:
Packit 40b132
        PKIX_PL_Free(asciiResult, NULL);
Packit 40b132
Packit 40b132
        PKIX_TEST_DECREF_AC(state);
Packit 40b132
        PKIX_TEST_DECREF_AC(buildResult);
Packit 40b132
        PKIX_TEST_DECREF_AC(procParams);
Packit 40b132
        PKIX_TEST_DECREF_AC(revCheckers);
Packit 40b132
        PKIX_TEST_DECREF_AC(revChecker);
Packit 40b132
        PKIX_TEST_DECREF_AC(certSelParams);
Packit 40b132
        PKIX_TEST_DECREF_AC(certSelector);
Packit 40b132
        PKIX_TEST_DECREF_AC(anchors);
Packit 40b132
        PKIX_TEST_DECREF_AC(anchor);
Packit 40b132
        PKIX_TEST_DECREF_AC(hintCerts);
Packit 40b132
        PKIX_TEST_DECREF_AC(trustedPubKey);
Packit 40b132
        PKIX_TEST_DECREF_AC(certs);
Packit 40b132
        PKIX_TEST_DECREF_AC(cert);
Packit 40b132
        PKIX_TEST_RETURN();
Packit 40b132
Packit 40b132
        return (pkixTestErrorResult);
Packit 40b132
Packit 40b132
}
Packit 40b132
Packit 40b132
/* Test with all Certs in the partial list, leaf duplicates the first one */
Packit 40b132
static PKIX_Error *
Packit 40b132
testWithDuplicateLeaf(
Packit 40b132
        PKIX_PL_Cert *trustedCert,
Packit 40b132
        PKIX_List *listOfCerts,
Packit 40b132
        PKIX_PL_Cert *targetCert,
Packit 40b132
        PKIX_List *certStores,
Packit 40b132
        PKIX_Boolean testValid,
Packit 40b132
        void* plContext)
Packit 40b132
{
Packit 40b132
        PKIX_UInt32 numCerts = 0;
Packit 40b132
        PKIX_UInt32 i = 0;
Packit 40b132
        PKIX_TrustAnchor *anchor = NULL;
Packit 40b132
        PKIX_List *anchors = NULL;
Packit 40b132
        PKIX_List *hintCerts = NULL;
Packit 40b132
        PKIX_List *revCheckers = NULL;
Packit 40b132
        PKIX_List *certs = NULL;
Packit 40b132
        PKIX_PL_Cert *cert = NULL;
Packit 40b132
        PKIX_ProcessingParams *procParams = NULL;
Packit 40b132
        PKIX_ComCertSelParams *certSelParams = NULL;
Packit 40b132
        PKIX_CertSelector *certSelector = NULL;
Packit 40b132
        PKIX_PL_PublicKey *trustedPubKey = NULL;
Packit 40b132
        PKIX_RevocationChecker *revChecker = NULL;
Packit 40b132
        PKIX_BuildResult *buildResult = NULL;
Packit 40b132
        PRPollDesc *pollDesc = NULL;
Packit 40b132
        void *state = NULL;
Packit 40b132
        char *asciiResult = NULL;
Packit 40b132
Packit 40b132
        PKIX_TEST_STD_VARS();
Packit 40b132
Packit 40b132
        /* create processing params with list of trust anchors */
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_TrustAnchor_CreateWithCert
Packit 40b132
                (trustedCert, &anchor, plContext));
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_Create(&anchors, plContext));
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_AppendItem
Packit 40b132
                (anchors, (PKIX_PL_Object *)anchor, plContext));
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_Create
Packit 40b132
                (anchors, &procParams, plContext));
Packit 40b132
Packit 40b132
        /* create CertSelector with target certificate in params */
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ComCertSelParams_Create
Packit 40b132
                (&certSelParams, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ComCertSelParams_SetCertificate
Packit 40b132
                (certSelParams, targetCert, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_CertSelector_Create
Packit 40b132
                (NULL, NULL, &certSelector, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_CertSelector_SetCommonCertSelectorParams
Packit 40b132
                (certSelector, certSelParams, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetTargetCertConstraints
Packit 40b132
                (procParams, certSelector, plContext));
Packit 40b132
Packit 40b132
        /* create hintCerts */
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_Object_Duplicate
Packit 40b132
                ((PKIX_PL_Object *)listOfCerts,
Packit 40b132
                (PKIX_PL_Object **)&hintCerts,
Packit 40b132
                plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetHintCerts
Packit 40b132
                (procParams, hintCerts, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetCertStores
Packit 40b132
                (procParams, certStores, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_Create(&revCheckers, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_Cert_GetSubjectPublicKey
Packit 40b132
                (trustedCert, &trustedPubKey, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_GetLength
Packit 40b132
                (listOfCerts, &numCerts, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(pkix_DefaultRevChecker_Initialize
Packit 40b132
                (certStores,
Packit 40b132
                NULL, /* testDate, may be NULL */
Packit 40b132
                trustedPubKey,
Packit 40b132
                numCerts,
Packit 40b132
                &revChecker,
Packit 40b132
                plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_AppendItem
Packit 40b132
                (revCheckers, (PKIX_PL_Object *)revChecker, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetRevocationCheckers
Packit 40b132
                (procParams, revCheckers, plContext));
Packit 40b132
Packit 40b132
#ifdef debuggingWithoutRevocation
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetRevocationEnabled
Packit 40b132
                (procParams, PKIX_FALSE, plContext));
Packit 40b132
#endif
Packit 40b132
Packit 40b132
        /* build cert chain using processing params and return buildResult */
Packit 40b132
Packit 40b132
        pkixTestErrorResult = PKIX_BuildChain
Packit 40b132
                (procParams,
Packit 40b132
                (void **)&pollDesc,
Packit 40b132
                &state,
Packit 40b132
                &buildResult,
Packit 40b132
                NULL,
Packit 40b132
                plContext);
Packit 40b132
Packit 40b132
        while (pollDesc != NULL) {
Packit 40b132
Packit 40b132
                if (PR_Poll(pollDesc, 1, 0) < 0) {
Packit 40b132
                        testError("PR_Poll failed");
Packit 40b132
                }
Packit 40b132
Packit 40b132
                pkixTestErrorResult = PKIX_BuildChain
Packit 40b132
                        (procParams,
Packit 40b132
                        (void **)&pollDesc,
Packit 40b132
                        &state,
Packit 40b132
                        &buildResult,
Packit 40b132
                        NULL,
Packit 40b132
                        plContext);
Packit 40b132
        }
Packit 40b132
Packit 40b132
        if (pkixTestErrorResult) {
Packit 40b132
                if (testValid == PKIX_FALSE) { /* EE */
Packit 40b132
                        (void) printf("EXPECTED ERROR RECEIVED!\n");
Packit 40b132
                } else { /* ENE */
Packit 40b132
                        testError("UNEXPECTED ERROR RECEIVED");
Packit 40b132
                }
Packit 40b132
                PKIX_TEST_DECREF_BC(pkixTestErrorResult);
Packit 40b132
                goto cleanup;
Packit 40b132
        }
Packit 40b132
Packit 40b132
        if (testValid == PKIX_TRUE) { /* ENE */
Packit 40b132
                (void) printf("EXPECTED NON-ERROR RECEIVED!\n");
Packit 40b132
        } else { /* EE */
Packit 40b132
                (void) printf("UNEXPECTED NON-ERROR RECEIVED!\n");
Packit 40b132
        }
Packit 40b132
Packit 40b132
        if (buildResult) {
Packit 40b132
Packit 40b132
                PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                        (PKIX_BuildResult_GetCertChain
Packit 40b132
                        (buildResult, &certs, plContext));
Packit 40b132
Packit 40b132
                PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                        (PKIX_List_GetLength(certs, &numCerts, plContext));
Packit 40b132
Packit 40b132
                printf("\n");
Packit 40b132
Packit 40b132
                for (i = 0; i < numCerts; i++) {
Packit 40b132
                        PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                                (PKIX_List_GetItem
Packit 40b132
                                (certs,
Packit 40b132
                                i,
Packit 40b132
                                (PKIX_PL_Object**)&cert,
Packit 40b132
                                plContext));
Packit 40b132
Packit 40b132
                        asciiResult = PKIX_Cert2ASCII(cert);
Packit 40b132
Packit 40b132
                        printf("CERT[%d]:\n%s\n", i, asciiResult);
Packit 40b132
Packit 40b132
                        /* PKIX_Cert2ASCII used PKIX_PL_Malloc(...,,NULL) */
Packit 40b132
                        PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                                (PKIX_PL_Free(asciiResult, NULL));
Packit 40b132
                        asciiResult = NULL;
Packit 40b132
Packit 40b132
                        PKIX_TEST_DECREF_BC(cert);
Packit 40b132
                }
Packit 40b132
        }
Packit 40b132
Packit 40b132
cleanup:
Packit 40b132
        PKIX_PL_Free(asciiResult, NULL);
Packit 40b132
Packit 40b132
        PKIX_TEST_DECREF_AC(state);
Packit 40b132
        PKIX_TEST_DECREF_AC(buildResult);
Packit 40b132
        PKIX_TEST_DECREF_AC(procParams);
Packit 40b132
        PKIX_TEST_DECREF_AC(revCheckers);
Packit 40b132
        PKIX_TEST_DECREF_AC(revChecker);
Packit 40b132
        PKIX_TEST_DECREF_AC(certSelParams);
Packit 40b132
        PKIX_TEST_DECREF_AC(certSelector);
Packit 40b132
        PKIX_TEST_DECREF_AC(anchors);
Packit 40b132
        PKIX_TEST_DECREF_AC(anchor);
Packit 40b132
        PKIX_TEST_DECREF_AC(hintCerts);
Packit 40b132
        PKIX_TEST_DECREF_AC(trustedPubKey);
Packit 40b132
        PKIX_TEST_DECREF_AC(certs);
Packit 40b132
        PKIX_TEST_DECREF_AC(cert);
Packit 40b132
        PKIX_TEST_RETURN();
Packit 40b132
Packit 40b132
        return (pkixTestErrorResult);
Packit 40b132
Packit 40b132
}
Packit 40b132
Packit 40b132
/* Test with all Certs except the leaf in the partial list */
Packit 40b132
static PKIX_Error *
Packit 40b132
testWithLeafAndChain(
Packit 40b132
        PKIX_PL_Cert *trustedCert,
Packit 40b132
        PKIX_List *listOfCerts,
Packit 40b132
        PKIX_PL_Cert *targetCert,
Packit 40b132
        PKIX_List *certStores,
Packit 40b132
        PKIX_Boolean testValid,
Packit 40b132
        void* plContext)
Packit 40b132
{
Packit 40b132
        PKIX_UInt32 numCerts = 0;
Packit 40b132
        PKIX_UInt32 i = 0;
Packit 40b132
        PKIX_TrustAnchor *anchor = NULL;
Packit 40b132
        PKIX_List *anchors = NULL;
Packit 40b132
        PKIX_List *hintCerts = NULL;
Packit 40b132
        PKIX_List *revCheckers = NULL;
Packit 40b132
        PKIX_List *certs = NULL;
Packit 40b132
        PKIX_PL_Cert *cert = NULL;
Packit 40b132
        PKIX_ProcessingParams *procParams = NULL;
Packit 40b132
        PKIX_ComCertSelParams *certSelParams = NULL;
Packit 40b132
        PKIX_CertSelector *certSelector = NULL;
Packit 40b132
        PKIX_PL_PublicKey *trustedPubKey = NULL;
Packit 40b132
        PKIX_RevocationChecker *revChecker = NULL;
Packit 40b132
        PKIX_BuildResult *buildResult = NULL;
Packit 40b132
        PRPollDesc *pollDesc = NULL;
Packit 40b132
        void *state = NULL;
Packit 40b132
        char *asciiResult = NULL;
Packit 40b132
Packit 40b132
        PKIX_TEST_STD_VARS();
Packit 40b132
Packit 40b132
        /* create processing params with list of trust anchors */
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_TrustAnchor_CreateWithCert
Packit 40b132
                (trustedCert, &anchor, plContext));
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_Create(&anchors, plContext));
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_AppendItem
Packit 40b132
                (anchors, (PKIX_PL_Object *)anchor, plContext));
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_Create
Packit 40b132
                (anchors, &procParams, plContext));
Packit 40b132
Packit 40b132
        /* create CertSelector with target certificate in params */
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ComCertSelParams_Create
Packit 40b132
                (&certSelParams, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ComCertSelParams_SetCertificate
Packit 40b132
                (certSelParams, targetCert, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_CertSelector_Create
Packit 40b132
                (NULL, NULL, &certSelector, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_CertSelector_SetCommonCertSelectorParams
Packit 40b132
                (certSelector, certSelParams, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetTargetCertConstraints
Packit 40b132
                (procParams, certSelector, plContext));
Packit 40b132
Packit 40b132
        /* create hintCerts */
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_Object_Duplicate
Packit 40b132
                ((PKIX_PL_Object *)listOfCerts,
Packit 40b132
                (PKIX_PL_Object **)&hintCerts,
Packit 40b132
                plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_DeleteItem
Packit 40b132
                (hintCerts, 0, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetHintCerts
Packit 40b132
                (procParams, hintCerts, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetCertStores
Packit 40b132
                (procParams, certStores, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_Create(&revCheckers, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_Cert_GetSubjectPublicKey
Packit 40b132
                (trustedCert, &trustedPubKey, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_GetLength
Packit 40b132
                (listOfCerts, &numCerts, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(pkix_DefaultRevChecker_Initialize
Packit 40b132
                (certStores,
Packit 40b132
                NULL, /* testDate, may be NULL */
Packit 40b132
                trustedPubKey,
Packit 40b132
                numCerts,
Packit 40b132
                &revChecker,
Packit 40b132
                plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_AppendItem
Packit 40b132
                (revCheckers, (PKIX_PL_Object *)revChecker, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetRevocationCheckers
Packit 40b132
                (procParams, revCheckers, plContext));
Packit 40b132
Packit 40b132
#ifdef debuggingWithoutRevocation
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_ProcessingParams_SetRevocationEnabled
Packit 40b132
                (procParams, PKIX_FALSE, plContext));
Packit 40b132
#endif
Packit 40b132
Packit 40b132
        /* build cert chain using processing params and return buildResult */
Packit 40b132
Packit 40b132
        pkixTestErrorResult = PKIX_BuildChain
Packit 40b132
                (procParams,
Packit 40b132
                (void **)&pollDesc,
Packit 40b132
                &state,
Packit 40b132
                &buildResult,
Packit 40b132
                NULL,
Packit 40b132
                plContext);
Packit 40b132
Packit 40b132
        while (pollDesc != NULL) {
Packit 40b132
Packit 40b132
                if (PR_Poll(pollDesc, 1, 0) < 0) {
Packit 40b132
                        testError("PR_Poll failed");
Packit 40b132
                }
Packit 40b132
Packit 40b132
                pkixTestErrorResult = PKIX_BuildChain
Packit 40b132
                        (procParams,
Packit 40b132
                        (void **)&pollDesc,
Packit 40b132
                        &state,
Packit 40b132
                        &buildResult,
Packit 40b132
                        NULL,
Packit 40b132
                        plContext);
Packit 40b132
        }
Packit 40b132
Packit 40b132
        if (pkixTestErrorResult) {
Packit 40b132
                if (testValid == PKIX_FALSE) { /* EE */
Packit 40b132
                        (void) printf("EXPECTED ERROR RECEIVED!\n");
Packit 40b132
                } else { /* ENE */
Packit 40b132
                        testError("UNEXPECTED ERROR RECEIVED");
Packit 40b132
                }
Packit 40b132
                PKIX_TEST_DECREF_BC(pkixTestErrorResult);
Packit 40b132
                goto cleanup;
Packit 40b132
        }
Packit 40b132
Packit 40b132
        if (testValid == PKIX_TRUE) { /* ENE */
Packit 40b132
                (void) printf("EXPECTED NON-ERROR RECEIVED!\n");
Packit 40b132
        } else { /* EE */
Packit 40b132
                (void) printf("UNEXPECTED NON-ERROR RECEIVED!\n");
Packit 40b132
        }
Packit 40b132
Packit 40b132
        if (buildResult) {
Packit 40b132
Packit 40b132
                PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                        (PKIX_BuildResult_GetCertChain
Packit 40b132
                        (buildResult, &certs, plContext));
Packit 40b132
Packit 40b132
                PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                        (PKIX_List_GetLength(certs, &numCerts, plContext));
Packit 40b132
Packit 40b132
                printf("\n");
Packit 40b132
Packit 40b132
                for (i = 0; i < numCerts; i++) {
Packit 40b132
                        PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                                (PKIX_List_GetItem
Packit 40b132
                                (certs,
Packit 40b132
                                i,
Packit 40b132
                                (PKIX_PL_Object**)&cert,
Packit 40b132
                                plContext));
Packit 40b132
Packit 40b132
                        asciiResult = PKIX_Cert2ASCII(cert);
Packit 40b132
Packit 40b132
                        printf("CERT[%d]:\n%s\n", i, asciiResult);
Packit 40b132
Packit 40b132
                        /* PKIX_Cert2ASCII used PKIX_PL_Malloc(...,,NULL) */
Packit 40b132
                        PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                                (PKIX_PL_Free(asciiResult, NULL));
Packit 40b132
                        asciiResult = NULL;
Packit 40b132
Packit 40b132
                        PKIX_TEST_DECREF_BC(cert);
Packit 40b132
                }
Packit 40b132
        }
Packit 40b132
Packit 40b132
cleanup:
Packit 40b132
Packit 40b132
        PKIX_TEST_DECREF_AC(state);
Packit 40b132
        PKIX_TEST_DECREF_AC(buildResult);
Packit 40b132
        PKIX_TEST_DECREF_AC(procParams);
Packit 40b132
        PKIX_TEST_DECREF_AC(revCheckers);
Packit 40b132
        PKIX_TEST_DECREF_AC(revChecker);
Packit 40b132
        PKIX_TEST_DECREF_AC(certSelParams);
Packit 40b132
        PKIX_TEST_DECREF_AC(certSelector);
Packit 40b132
        PKIX_TEST_DECREF_AC(anchors);
Packit 40b132
        PKIX_TEST_DECREF_AC(anchor);
Packit 40b132
        PKIX_TEST_DECREF_AC(hintCerts);
Packit 40b132
        PKIX_TEST_DECREF_AC(trustedPubKey);
Packit 40b132
        PKIX_TEST_DECREF_AC(certs);
Packit 40b132
        PKIX_TEST_DECREF_AC(cert);
Packit 40b132
Packit 40b132
        PKIX_TEST_RETURN();
Packit 40b132
Packit 40b132
        return (pkixTestErrorResult);
Packit 40b132
Packit 40b132
}
Packit 40b132
Packit 40b132
int test_buildchain_partialchain(int argc, char *argv[])
Packit 40b132
{
Packit 40b132
        PKIX_UInt32 actualMinorVersion = 0;
Packit 40b132
        PKIX_UInt32 j = 0;
Packit 40b132
        PKIX_UInt32 k = 0;
Packit 40b132
        PKIX_Boolean ene = PKIX_TRUE; /* expect no error */
Packit 40b132
        PKIX_List *listOfCerts = NULL;
Packit 40b132
        PKIX_List *certStores = NULL;
Packit 40b132
        PKIX_PL_Cert *dirCert = NULL;
Packit 40b132
        PKIX_PL_Cert *trusted = NULL;
Packit 40b132
        PKIX_PL_Cert *target = NULL;
Packit 40b132
        PKIX_CertStore *ldapCertStore = NULL;
Packit 40b132
        PKIX_CertStore *certStore = NULL;
Packit 40b132
        PKIX_PL_String *dirNameString = NULL;
Packit 40b132
        char *dirName = NULL;
Packit 40b132
Packit 40b132
        PRIntervalTime timeout = PR_INTERVAL_NO_TIMEOUT; /* blocking */
Packit 40b132
        /* PRIntervalTime timeout = PR_INTERVAL_NO_WAIT; =0 for non-blocking */
Packit 40b132
Packit 40b132
        PKIX_TEST_STD_VARS();
Packit 40b132
Packit 40b132
        if (argc < 5) {
Packit 40b132
                printUsage();
Packit 40b132
                return (0);
Packit 40b132
        }
Packit 40b132
Packit 40b132
        startTests("BuildChain");
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(
Packit 40b132
            PKIX_PL_NssContext_Create(0, PKIX_FALSE, NULL, &plContext));
Packit 40b132
Packit 40b132
        /*
Packit 40b132
         * arguments:
Packit 40b132
         * [optional] -arenas
Packit 40b132
         * [optional] usebind
Packit 40b132
         *            servername or servername:port ( - for no server)
Packit 40b132
         *            testname
Packit 40b132
         *            EE or ENE
Packit 40b132
         *            cert directory
Packit 40b132
         *            target cert (end entity)
Packit 40b132
         *            intermediate certs
Packit 40b132
         *            trust anchor
Packit 40b132
         */
Packit 40b132
Packit 40b132
        /* optional argument "usebind" for Ldap CertStore */
Packit 40b132
        if (argv[j + 1]) {
Packit 40b132
                if (PORT_Strcmp(argv[j + 1], "usebind") == 0) {
Packit 40b132
                        usebind = PKIX_TRUE;
Packit 40b132
                        j++;
Packit 40b132
                }
Packit 40b132
        }
Packit 40b132
Packit 40b132
        if (PORT_Strcmp(argv[++j], "-") == 0) {
Packit 40b132
                useLDAP = PKIX_FALSE;
Packit 40b132
        } else {
Packit 40b132
                serverName = argv[j];
Packit 40b132
                useLDAP = PKIX_TRUE;
Packit 40b132
        }
Packit 40b132
Packit 40b132
        subTest(argv[++j]);
Packit 40b132
Packit 40b132
        /* ENE = expect no error; EE = expect error */
Packit 40b132
        if (PORT_Strcmp(argv[++j], "ENE") == 0) {
Packit 40b132
                ene = PKIX_TRUE;
Packit 40b132
        } else if (PORT_Strcmp(argv[j], "EE") == 0) {
Packit 40b132
                ene = PKIX_FALSE;
Packit 40b132
        } else {
Packit 40b132
                printUsage();
Packit 40b132
                return (0);
Packit 40b132
        }
Packit 40b132
Packit 40b132
        dirName = argv[++j];
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_Create(&listOfCerts, plContext));
Packit 40b132
Packit 40b132
        for (k = ++j; k < ((PKIX_UInt32)argc); k++) {
Packit 40b132
Packit 40b132
                dirCert = createCert(dirName, argv[k], plContext);
Packit 40b132
Packit 40b132
                if (k == ((PKIX_UInt32)(argc - 1))) {
Packit 40b132
                        PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_Object_IncRef
Packit 40b132
                                ((PKIX_PL_Object *)dirCert, plContext));
Packit 40b132
                        trusted = dirCert;
Packit 40b132
                } else {
Packit 40b132
Packit 40b132
                        PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                                (PKIX_List_AppendItem
Packit 40b132
                                (listOfCerts,
Packit 40b132
                                (PKIX_PL_Object *)dirCert,
Packit 40b132
                                plContext));
Packit 40b132
Packit 40b132
                        if (k == j) {
Packit 40b132
                                PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_Object_IncRef
Packit 40b132
                                        ((PKIX_PL_Object *)dirCert, plContext));
Packit 40b132
                                target = dirCert;
Packit 40b132
                        }
Packit 40b132
                }
Packit 40b132
Packit 40b132
                PKIX_TEST_DECREF_BC(dirCert);
Packit 40b132
        }
Packit 40b132
Packit 40b132
        /* create CertStores */
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_String_Create
Packit 40b132
                (PKIX_ESCASCII, dirName, 0, &dirNameString, plContext));
Packit 40b132
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(PKIX_List_Create(&certStores, plContext));
Packit 40b132
Packit 40b132
        if (useLDAP == PKIX_TRUE) {
Packit 40b132
                PKIX_TEST_EXPECT_NO_ERROR(createLdapCertStore
Packit 40b132
                        (serverName, timeout, &ldapCertStore, plContext));
Packit 40b132
Packit 40b132
                PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                        (PKIX_List_AppendItem
Packit 40b132
                        (certStores,
Packit 40b132
                        (PKIX_PL_Object *)ldapCertStore,
Packit 40b132
                        plContext));
Packit 40b132
        } else {
Packit 40b132
                PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                        (PKIX_PL_CollectionCertStore_Create
Packit 40b132
                        (dirNameString, &certStore, plContext));
Packit 40b132
                PKIX_TEST_EXPECT_NO_ERROR
Packit 40b132
                        (PKIX_List_AppendItem
Packit 40b132
                        (certStores, (PKIX_PL_Object *)certStore, plContext));
Packit 40b132
        }
Packit 40b132
Packit 40b132
        subTest("testWithNoLeaf");
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(testWithNoLeaf
Packit 40b132
                (trusted, listOfCerts, target, certStores, ene, plContext));
Packit 40b132
Packit 40b132
        subTest("testWithDuplicateLeaf");
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(testWithDuplicateLeaf
Packit 40b132
                (trusted, listOfCerts, target, certStores, ene, plContext));
Packit 40b132
Packit 40b132
        subTest("testWithLeafAndChain");
Packit 40b132
        PKIX_TEST_EXPECT_NO_ERROR(testWithLeafAndChain
Packit 40b132
                (trusted, listOfCerts, target, certStores, ene, plContext));
Packit 40b132
Packit 40b132
cleanup:
Packit 40b132
Packit 40b132
        PKIX_TEST_DECREF_AC(listOfCerts);
Packit 40b132
        PKIX_TEST_DECREF_AC(certStores);
Packit 40b132
        PKIX_TEST_DECREF_AC(ldapCertStore);
Packit 40b132
        PKIX_TEST_DECREF_AC(certStore);
Packit 40b132
        PKIX_TEST_DECREF_AC(dirNameString);
Packit 40b132
        PKIX_TEST_DECREF_AC(trusted);
Packit 40b132
        PKIX_TEST_DECREF_AC(target);
Packit 40b132
Packit 40b132
        PKIX_TEST_RETURN();
Packit 40b132
Packit 40b132
        PKIX_Shutdown(plContext);
Packit 40b132
Packit 40b132
        endTests("BuildChain");
Packit 40b132
Packit 40b132
        return (0);
Packit 40b132
Packit 40b132
}