|
Packit Service |
3749ba |
/*
|
|
Packit Service |
3749ba |
* Copyright (c) 2011, Collabora Ltd.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* Redistribution and use in source and binary forms, with or without
|
|
Packit Service |
3749ba |
* modification, are permitted provided that the following conditions
|
|
Packit Service |
3749ba |
* are met:
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* * Redistributions of source code must retain the above
|
|
Packit Service |
3749ba |
* copyright notice, this list of conditions and the
|
|
Packit Service |
3749ba |
* following disclaimer.
|
|
Packit Service |
3749ba |
* * Redistributions in binary form must reproduce the
|
|
Packit Service |
3749ba |
* above copyright notice, this list of conditions and
|
|
Packit Service |
3749ba |
* the following disclaimer in the documentation and/or
|
|
Packit Service |
3749ba |
* other materials provided with the distribution.
|
|
Packit Service |
3749ba |
* * The names of contributors to this software may not be
|
|
Packit Service |
3749ba |
* used to endorse or promote products derived from this
|
|
Packit Service |
3749ba |
* software without specific prior written permission.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
|
Packit Service |
3749ba |
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
|
Packit Service |
3749ba |
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
|
Packit Service |
3749ba |
* FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
|
Packit Service |
3749ba |
* COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
|
|
Packit Service |
3749ba |
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
|
|
Packit Service |
3749ba |
* BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
|
|
Packit Service |
3749ba |
* OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
|
|
Packit Service |
3749ba |
* AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
|
|
Packit Service |
3749ba |
* OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
|
|
Packit Service |
3749ba |
* THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH
|
|
Packit Service |
3749ba |
* DAMAGE.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* Author: Stef Walter <stefw@collabora.co.uk>
|
|
Packit Service |
3749ba |
*/
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#define P11_KIT_DISABLE_DEPRECATED
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "config.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "test-trust.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "attrs.h"
|
|
Packit Service |
3749ba |
#include "compat.h"
|
|
Packit Service |
3749ba |
#include "debug.h"
|
|
Packit Service |
3749ba |
#include "dict.h"
|
|
Packit Service |
3749ba |
#include "extract.h"
|
|
Packit Service |
3749ba |
#include "message.h"
|
|
Packit Service |
3749ba |
#include "mock.h"
|
|
Packit Service |
3749ba |
#include "pkcs11.h"
|
|
Packit Service |
3749ba |
#include "pkcs11x.h"
|
|
Packit Service |
3749ba |
#include "oid.h"
|
|
Packit Service |
3749ba |
#include "test.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include <stdlib.h>
|
|
Packit Service |
3749ba |
#include <string.h>
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_file_name_for_label (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE label = { CKA_LABEL, "The Label!", 10 };
|
|
Packit Service |
3749ba |
p11_enumerate ex;
|
|
Packit Service |
3749ba |
char *name;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_init (&ex);
|
|
Packit Service |
3749ba |
ex.flags |= P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
ex.attrs = p11_attrs_build (NULL, &label, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
name = p11_enumerate_filename (&ex);
|
|
Packit Service |
3749ba |
assert_str_eq ("The_Label_", name);
|
|
Packit Service |
3749ba |
free (name);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_cleanup (&ex);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_file_name_for_class (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
p11_enumerate ex;
|
|
Packit Service |
3749ba |
char *name;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_init (&ex);
|
|
Packit Service |
3749ba |
ex.flags |= P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
ex.klass = CKO_CERTIFICATE;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
name = p11_enumerate_filename (&ex);
|
|
Packit Service |
3749ba |
assert_str_eq ("certificate", name);
|
|
Packit Service |
3749ba |
free (name);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
ex.klass = CKO_DATA;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
name = p11_enumerate_filename (&ex);
|
|
Packit Service |
3749ba |
assert_str_eq ("unknown", name);
|
|
Packit Service |
3749ba |
free (name);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_cleanup (&ex);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_comment_for_label (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE label = { CKA_LABEL, "The Label!", 10 };
|
|
Packit Service |
3749ba |
p11_enumerate ex;
|
|
Packit Service |
3749ba |
char *comment;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_init (&ex);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
ex.flags = P11_EXTRACT_COMMENT | P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
ex.attrs = p11_attrs_build (NULL, &label, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
comment = p11_enumerate_comment (&ex, true);
|
|
Packit Service |
3749ba |
assert_str_eq ("# The Label!\n", comment);
|
|
Packit Service |
3749ba |
free (comment);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
comment = p11_enumerate_comment (&ex, false);
|
|
Packit Service |
3749ba |
assert_str_eq ("\n# The Label!\n", comment);
|
|
Packit Service |
3749ba |
free (comment);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_cleanup (&ex);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_comment_not_enabled (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE label = { CKA_LABEL, "The Label!", 10 };
|
|
Packit Service |
3749ba |
p11_enumerate ex;
|
|
Packit Service |
3749ba |
char *comment;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_init (&ex);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
ex.flags |= P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
ex.attrs = p11_attrs_build (NULL, &label, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
comment = p11_enumerate_comment (&ex, true);
|
|
Packit Service |
3749ba |
assert_ptr_eq (NULL, comment);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
comment = p11_enumerate_comment (&ex, false);
|
|
Packit Service |
3749ba |
assert_ptr_eq (NULL, comment);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_cleanup (&ex);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
struct {
|
|
Packit Service |
3749ba |
CK_FUNCTION_LIST module;
|
|
Packit Service |
3749ba |
CK_FUNCTION_LIST_PTR modules[2];
|
|
Packit Service |
3749ba |
p11_enumerate ex;
|
|
Packit Service |
3749ba |
} test;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
setup (void *unused)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_reset ();
|
|
Packit Service |
3749ba |
memcpy (&test.module, &mock_module, sizeof (CK_FUNCTION_LIST));
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = test.module.C_Initialize (NULL);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_init (&test.ex);
|
|
Packit Service |
3749ba |
test.ex.flags |= P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/* Prefill the modules */
|
|
Packit Service |
3749ba |
test.modules[0] = &test.module;
|
|
Packit Service |
3749ba |
test.modules[1] = NULL;
|
|
Packit Service |
3749ba |
test.ex.modules = test.modules;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
teardown (void *unused)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/* Don't free the modules */
|
|
Packit Service |
3749ba |
test.ex.modules = NULL;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_cleanup (&test.ex);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = test.module.C_Finalize (NULL);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_OBJECT_CLASS certificate_class = CKO_CERTIFICATE;
|
|
Packit Service |
3749ba |
static CK_OBJECT_CLASS public_key_class = CKO_PUBLIC_KEY;
|
|
Packit Service |
3749ba |
static CK_OBJECT_CLASS extension_class = CKO_X_CERTIFICATE_EXTENSION;
|
|
Packit Service |
3749ba |
static CK_CERTIFICATE_TYPE x509_type = CKC_X_509;
|
|
Packit Service |
3749ba |
static CK_BBOOL truev = CK_TRUE;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_ATTRIBUTE cacert3_trusted[] = {
|
|
Packit Service |
3749ba |
{ CKA_VALUE, (void *)test_cacert3_ca_der, sizeof (test_cacert3_ca_der) },
|
|
Packit Service |
3749ba |
{ CKA_CLASS, &certificate_class, sizeof (certificate_class) },
|
|
Packit Service |
3749ba |
{ CKA_CERTIFICATE_TYPE, &x509_type, sizeof (x509_type) },
|
|
Packit Service |
3749ba |
{ CKA_LABEL, "Cacert3 Here", 11 },
|
|
Packit Service |
3749ba |
{ CKA_SUBJECT, (void *)test_cacert3_ca_subject, sizeof (test_cacert3_ca_subject) },
|
|
Packit Service |
3749ba |
{ CKA_ISSUER, (void *)test_cacert3_ca_issuer, sizeof (test_cacert3_ca_issuer) },
|
|
Packit Service |
3749ba |
{ CKA_SERIAL_NUMBER, (void *)test_cacert3_ca_serial, sizeof (test_cacert3_ca_serial) },
|
|
Packit Service |
3749ba |
{ CKA_PUBLIC_KEY_INFO, (void *)test_cacert3_ca_public_key, sizeof (test_cacert3_ca_public_key) },
|
|
Packit Service |
3749ba |
{ CKA_TRUSTED, &truev, sizeof (truev) },
|
|
Packit Service |
3749ba |
{ CKA_ID, "ID1", 3 },
|
|
Packit Service |
3749ba |
{ CKA_INVALID },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_ATTRIBUTE cacert3_distrusted[] = {
|
|
Packit Service |
3749ba |
{ CKA_VALUE, (void *)test_cacert3_ca_der, sizeof (test_cacert3_ca_der) },
|
|
Packit Service |
3749ba |
{ CKA_CLASS, &certificate_class, sizeof (certificate_class) },
|
|
Packit Service |
3749ba |
{ CKA_CERTIFICATE_TYPE, &x509_type, sizeof (x509_type) },
|
|
Packit Service |
3749ba |
{ CKA_LABEL, "Another CaCert", 11 },
|
|
Packit Service |
3749ba |
{ CKA_SUBJECT, (void *)test_cacert3_ca_subject, sizeof (test_cacert3_ca_subject) },
|
|
Packit Service |
3749ba |
{ CKA_ISSUER, (void *)test_cacert3_ca_issuer, sizeof (test_cacert3_ca_issuer) },
|
|
Packit Service |
3749ba |
{ CKA_SERIAL_NUMBER, (void *)test_cacert3_ca_serial, sizeof (test_cacert3_ca_serial) },
|
|
Packit Service |
3749ba |
{ CKA_X_DISTRUSTED, &truev, sizeof (truev) },
|
|
Packit Service |
3749ba |
{ CKA_INVALID },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_ATTRIBUTE cacert3_distrusted_by_key[] = {
|
|
Packit Service |
3749ba |
{ CKA_CLASS, &public_key_class, sizeof (public_key_class) },
|
|
Packit Service |
3749ba |
{ CKA_PUBLIC_KEY_INFO, (void *)test_cacert3_ca_public_key, sizeof (test_cacert3_ca_public_key) },
|
|
Packit Service |
3749ba |
{ CKA_X_DISTRUSTED, &truev, sizeof (truev) },
|
|
Packit Service |
3749ba |
{ CKA_INVALID },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_ATTRIBUTE certificate_filter[] = {
|
|
Packit Service |
3749ba |
{ CKA_CLASS, &certificate_class, sizeof (certificate_class) },
|
|
Packit Service |
3749ba |
{ CKA_INVALID },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_ATTRIBUTE extension_eku_server_client[] = {
|
|
Packit Service |
3749ba |
{ CKA_CLASS, &extension_class, sizeof (extension_class) },
|
|
Packit Service |
3749ba |
{ CKA_ID, "ID1", 3 },
|
|
Packit Service |
3749ba |
{ CKA_OBJECT_ID, (void *)P11_OID_EXTENDED_KEY_USAGE, sizeof (P11_OID_EXTENDED_KEY_USAGE) },
|
|
Packit Service |
3749ba |
{ CKA_VALUE, "\x30\x1d\x06\x03\x55\x1d\x25\x04\x16\x30\x14\x06\x08\x2b\x06\x01\x05\x05\x07\x03\x01\x06\x08\x2b\x06\x01\x05\x05\x07\x03\x02", 31 },
|
|
Packit Service |
3749ba |
{ CKA_PUBLIC_KEY_INFO, (void *)test_cacert3_ca_public_key, sizeof (test_cacert3_ca_public_key) },
|
|
Packit Service |
3749ba |
{ CKA_INVALID },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_ATTRIBUTE extension_eku_invalid[] = {
|
|
Packit Service |
3749ba |
{ CKA_CLASS, &extension_class, sizeof (extension_class) },
|
|
Packit Service |
3749ba |
{ CKA_ID, "ID1", 3 },
|
|
Packit Service |
3749ba |
{ CKA_OBJECT_ID, (void *)P11_OID_EXTENDED_KEY_USAGE, sizeof (P11_OID_EXTENDED_KEY_USAGE) },
|
|
Packit Service |
3749ba |
{ CKA_PUBLIC_KEY_INFO, (void *)test_cacert3_ca_public_key, sizeof (test_cacert3_ca_public_key) },
|
|
Packit Service |
3749ba |
{ CKA_VALUE, "\x30\x0e\x06\x03\x55\x1d\x25\x04\x07\x69\x6e\x76\x61\x6c\x69\x64", 16 },
|
|
Packit Service |
3749ba |
{ CKA_INVALID },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_ATTRIBUTE extension_eku_any[] = {
|
|
Packit Service |
3749ba |
{ CKA_CLASS, &extension_class, sizeof (extension_class) },
|
|
Packit Service |
3749ba |
{ CKA_ID, "ID1", 3 },
|
|
Packit Service |
3749ba |
{ CKA_OBJECT_ID, (void *)P11_OID_EXTENDED_KEY_USAGE, sizeof (P11_OID_EXTENDED_KEY_USAGE) },
|
|
Packit Service |
3749ba |
{ CKA_PUBLIC_KEY_INFO, (void *)test_cacert3_ca_public_key, sizeof (test_cacert3_ca_public_key) },
|
|
Packit Service |
3749ba |
/* anyExtendedKeyUsage ('2 5 29 37 0') and
|
|
Packit Service |
3749ba |
* Microsoft Smart Card Logon ('1 3 6 1 4 1 311 20 2 2') */
|
|
Packit Service |
3749ba |
{ CKA_VALUE, "\x30\x1b\x06\x03\x55\x1d\x25\x04\x14\x30\x12\x06\x04\x55\x1d\x25\x00\x06\x0a\x2b\x06\x01\x04\x01\x82\x37\x14\x02\x02", 29 },
|
|
Packit Service |
3749ba |
{ CKA_INVALID },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_info_simple_certificate (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
void *value;
|
|
Packit Service |
3749ba |
size_t length;
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
assert_ptr_not_null (test.ex.asn1_defs);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, extension_eku_server_client);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (test.ex.iter, certificate_filter, 1);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
assert_num_eq (CKO_CERTIFICATE, test.ex.klass);
|
|
Packit Service |
3749ba |
assert_ptr_not_null (test.ex.attrs);
|
|
Packit Service |
3749ba |
value = p11_attrs_find_value (test.ex.attrs, CKA_VALUE, &length);
|
|
Packit Service |
3749ba |
assert_ptr_not_null (value);
|
|
Packit Service |
3749ba |
assert (memcmp (value, test_cacert3_ca_der, length) == 0);
|
|
Packit Service |
3749ba |
assert_ptr_not_null (test.ex.cert_der);
|
|
Packit Service |
3749ba |
assert (memcmp (test.ex.cert_der, test_cacert3_ca_der, test.ex.cert_len) == 0);
|
|
Packit Service |
3749ba |
assert_ptr_not_null (test.ex.cert_asn);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_info_limit_purposes (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, extension_eku_server_client);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/* This should not match the above, with the attached certificate ext */
|
|
Packit Service |
3749ba |
assert_ptr_eq (NULL, test.ex.limit_to_purposes);
|
|
Packit Service |
3749ba |
p11_enumerate_opt_purpose (&test.ex, "1.1.1");
|
|
Packit Service |
3749ba |
assert_ptr_not_null (test.ex.limit_to_purposes);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (test.ex.iter, certificate_filter, 1);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_info_invalid_purposes (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, extension_eku_invalid);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (test.ex.iter, certificate_filter, 1);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_be_quiet ();
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/* No results due to invalid purpose on certificate */
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_be_loud ();
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_info_skip_non_certificate (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_message_quiet ();
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
assert_num_eq (CKO_CERTIFICATE, test.ex.klass);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_message_loud ();
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_limit_to_purpose_match (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, extension_eku_server_client);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_opt_purpose (&test.ex, P11_OID_SERVER_AUTH_STR);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_message_quiet ();
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_message_loud ();
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_limit_to_purpose_no_match (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, extension_eku_server_client);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_opt_purpose (&test.ex, "3.3.3.3");
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_message_quiet ();
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_message_loud ();
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_limit_to_purpose_match_any (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, extension_eku_any);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_opt_purpose (&test.ex, P11_OID_SERVER_AUTH_STR);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_message_quiet ();
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_message_loud ();
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_duplicate_extract (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE certificate = { CKA_CLASS, &certificate_class, sizeof (certificate_class) };
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_distrusted);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (test.ex.iter, &certificate, 1);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_duplicate_distrusted (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE certificate = { CKA_CLASS, &certificate_class, sizeof (certificate_class) };
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE attrs[] = {
|
|
Packit Service |
3749ba |
{ CKA_X_DISTRUSTED, NULL, 0 },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
CK_BBOOL val;
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_distrusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
test.ex.flags = P11_ENUMERATE_COLLAPSE | P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (test.ex.iter, &certificate, 1);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_load_attributes (test.ex.iter, attrs, 1);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
assert (p11_attrs_findn_bool (attrs, 1, CKA_X_DISTRUSTED, &val));
|
|
Packit Service |
3749ba |
assert_num_eq (val, CK_TRUE);
|
|
Packit Service |
3749ba |
free (attrs[0].pValue);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_trusted_match (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE certificate = { CKA_CLASS, &certificate_class, sizeof (certificate_class) };
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_distrusted);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
test.ex.flags = P11_ENUMERATE_ANCHORS | P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (test.ex.iter, &certificate, 1);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_distrust_match (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE certificate = { CKA_CLASS, &certificate_class, sizeof (certificate_class) };
|
|
Packit Service |
3749ba |
CK_BBOOL boolv;
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_distrusted);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
test.ex.flags = P11_ENUMERATE_BLACKLIST | P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (test.ex.iter, &certificate, 1);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (!p11_attrs_find_bool (test.ex.attrs, CKA_X_DISTRUSTED, &boolv))
|
|
Packit Service |
3749ba |
boolv = CK_FALSE;
|
|
Packit Service |
3749ba |
assert_num_eq (CK_TRUE, boolv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_override_by_issuer_serial (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE certificate = { CKA_CLASS, &certificate_class, sizeof (certificate_class) };
|
|
Packit Service |
3749ba |
CK_BBOOL distrusted = CK_FALSE;
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_distrusted);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
test.ex.flags = P11_ENUMERATE_ANCHORS | P11_ENUMERATE_BLACKLIST | P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (test.ex.iter, &certificate, 1);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_OK, rv);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
assert (p11_attrs_find_bool (test.ex.attrs, CKA_X_DISTRUSTED, &distrusted));
|
|
Packit Service |
3749ba |
assert_num_eq (CK_TRUE, distrusted);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static void
|
|
Packit Service |
3749ba |
test_override_by_public_key (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE certificate = { CKA_CLASS, &certificate_class, sizeof (certificate_class) };
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_trusted);
|
|
Packit Service |
3749ba |
mock_module_add_object (MOCK_SLOT_ONE_ID, cacert3_distrusted_by_key);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
test.ex.flags = P11_ENUMERATE_ANCHORS | P11_ENUMERATE_BLACKLIST | P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (test.ex.iter, &certificate, 1);
|
|
Packit Service |
3749ba |
p11_enumerate_ready (&test.ex, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/* No results returned, because distrust is not a cert */
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_next (test.ex.iter);
|
|
Packit Service |
3749ba |
assert_num_eq (CKR_CANCEL, rv);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
int
|
|
Packit Service |
3749ba |
main (int argc,
|
|
Packit Service |
3749ba |
char *argv[])
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
mock_module_init ();
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_test (test_file_name_for_label, "/extract/test_file_name_for_label");
|
|
Packit Service |
3749ba |
p11_test (test_file_name_for_class, "/extract/test_file_name_for_class");
|
|
Packit Service |
3749ba |
p11_test (test_comment_for_label, "/extract/test_comment_for_label");
|
|
Packit Service |
3749ba |
p11_test (test_comment_not_enabled, "/extract/test_comment_not_enabled");
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_fixture (setup, teardown);
|
|
Packit Service |
3749ba |
p11_test (test_info_simple_certificate, "/extract/test_info_simple_certificate");
|
|
Packit Service |
3749ba |
p11_test (test_info_limit_purposes, "/extract/test_info_limit_purposes");
|
|
Packit Service |
3749ba |
p11_test (test_info_invalid_purposes, "/extract/test_info_invalid_purposes");
|
|
Packit Service |
3749ba |
p11_test (test_info_skip_non_certificate, "/extract/test_info_skip_non_certificate");
|
|
Packit Service |
3749ba |
p11_test (test_limit_to_purpose_match, "/extract/test_limit_to_purpose_match");
|
|
Packit Service |
3749ba |
p11_test (test_limit_to_purpose_no_match, "/extract/test_limit_to_purpose_no_match");
|
|
Packit Service |
3749ba |
p11_test (test_limit_to_purpose_match_any, "/extract/test_limit_to_purpose_no_match_any");
|
|
Packit Service |
3749ba |
p11_test (test_duplicate_extract, "/extract/test_duplicate_extract");
|
|
Packit Service |
3749ba |
p11_test (test_duplicate_distrusted, "/extract/test-duplicate-distrusted");
|
|
Packit Service |
3749ba |
p11_test (test_trusted_match, "/extract/test_trusted_match");
|
|
Packit Service |
3749ba |
p11_test (test_distrust_match, "/extract/test_distrust_match");
|
|
Packit Service |
3749ba |
p11_test (test_override_by_issuer_serial, "/extract/override-by-issuer-and-serial");
|
|
Packit Service |
3749ba |
p11_test (test_override_by_public_key, "/extract/override-by-public-key");
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return p11_test_run (argc, argv);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "enumerate.c"
|