blob: 95fc287be048fda8f75b479501c6813f20b9b9e3 [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/x509_crt.h"
3#include "mbedtls/x509_crl.h"
4#include "mbedtls/x509_csr.h"
5#include "mbedtls/pem.h"
6#include "mbedtls/oid.h"
7#include "mbedtls/base64.h"
Paul Bakkerb63b0af2011-01-13 17:54:59 +00008
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +02009int verify_none( void *data, mbedtls_x509_crt *crt, int certificate_depth, uint32_t *flags )
Paul Bakkerb63b0af2011-01-13 17:54:59 +000010{
Paul Bakker5a624082011-01-18 16:31:52 +000011 ((void) data);
12 ((void) crt);
13 ((void) certificate_depth);
Manuel Pégourié-Gonnarde6028c92015-04-20 12:19:02 +010014 *flags |= MBEDTLS_X509_BADCERT_OTHER;
Paul Bakkerddf26b42013-09-18 13:46:23 +020015
Paul Bakker915275b2012-09-28 07:10:55 +000016 return 0;
Paul Bakkerb63b0af2011-01-13 17:54:59 +000017}
18
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +020019int verify_all( void *data, mbedtls_x509_crt *crt, int certificate_depth, uint32_t *flags )
Paul Bakkerb63b0af2011-01-13 17:54:59 +000020{
Paul Bakker5a624082011-01-18 16:31:52 +000021 ((void) data);
22 ((void) crt);
23 ((void) certificate_depth);
Paul Bakker915275b2012-09-28 07:10:55 +000024 *flags = 0;
Paul Bakker5a624082011-01-18 16:31:52 +000025
Paul Bakkerb63b0af2011-01-13 17:54:59 +000026 return 0;
27}
28
Manuel Pégourié-Gonnard560fea32015-09-01 11:59:24 +020029#if defined(MBEDTLS_X509_CRT_PARSE_C)
30typedef struct {
31 char buf[512];
32 char *p;
33} verify_print_context;
34
35void verify_print_init( verify_print_context *ctx )
36{
37 memset( ctx, 0, sizeof( verify_print_context ) );
38 ctx->p = ctx->buf;
39}
40
41int verify_print( void *data, mbedtls_x509_crt *crt, int certificate_depth, uint32_t *flags )
42{
43 int ret;
44 verify_print_context *ctx = (verify_print_context *) data;
45 char *p = ctx->p;
46 size_t n = ctx->buf + sizeof( ctx->buf ) - ctx->p;
47 ((void) flags);
48
49 ret = mbedtls_snprintf( p, n, "depth %d - serial ", certificate_depth );
50 MBEDTLS_X509_SAFE_SNPRINTF;
51
52 ret = mbedtls_x509_serial_gets( p, n, &crt->serial );
53 MBEDTLS_X509_SAFE_SNPRINTF;
54
55 ret = mbedtls_snprintf( p, n, " - subject " );
56 MBEDTLS_X509_SAFE_SNPRINTF;
57
58 ret = mbedtls_x509_dn_gets( p, n, &crt->subject );
59 MBEDTLS_X509_SAFE_SNPRINTF;
60
61 ret = mbedtls_snprintf( p, n, "\n" );
62 MBEDTLS_X509_SAFE_SNPRINTF;
63
64 ctx->p = p;
65
66 return( 0 );
67}
68#endif /* MBEDTLS_X509_CRT_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +020069/* END_HEADER */
Paul Bakker37940d9f2009-07-10 22:38:58 +000070
Paul Bakker33b43f12013-08-20 11:48:36 +020071/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020072 * depends_on:MBEDTLS_BIGNUM_C
Paul Bakker33b43f12013-08-20 11:48:36 +020073 * END_DEPENDENCIES
74 */
Paul Bakker5690efc2011-05-26 13:16:06 +000075
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020076/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +020077void x509_cert_info( char *crt_file, char *result_str )
Paul Bakker37940d9f2009-07-10 22:38:58 +000078{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020079 mbedtls_x509_crt crt;
Paul Bakker37940d9f2009-07-10 22:38:58 +000080 char buf[2000];
Paul Bakker69998dd2009-07-11 19:15:20 +000081 int res;
Paul Bakker37940d9f2009-07-10 22:38:58 +000082
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020083 mbedtls_x509_crt_init( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +000084 memset( buf, 0, 2000 );
85
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020086 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
87 res = mbedtls_x509_crt_info( buf, 2000, "", &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +000088
89 TEST_ASSERT( res != -1 );
90 TEST_ASSERT( res != -2 );
91
Paul Bakker33b43f12013-08-20 11:48:36 +020092 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +020093
94exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020095 mbedtls_x509_crt_free( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +000096}
Paul Bakker33b43f12013-08-20 11:48:36 +020097/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +000098
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020099/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRL_PARSE_C */
100void mbedtls_x509_crl_info( char *crl_file, char *result_str )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000101{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200102 mbedtls_x509_crl crl;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000103 char buf[2000];
Paul Bakker69998dd2009-07-11 19:15:20 +0000104 int res;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000105
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200106 mbedtls_x509_crl_init( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000107 memset( buf, 0, 2000 );
108
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200109 TEST_ASSERT( mbedtls_x509_crl_parse_file( &crl, crl_file ) == 0 );
110 res = mbedtls_x509_crl_info( buf, 2000, "", &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000111
112 TEST_ASSERT( res != -1 );
113 TEST_ASSERT( res != -2 );
114
Paul Bakker33b43f12013-08-20 11:48:36 +0200115 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200116
117exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200118 mbedtls_x509_crl_free( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000119}
Paul Bakker33b43f12013-08-20 11:48:36 +0200120/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000121
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200122/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CSR_PARSE_C */
123void mbedtls_x509_csr_info( char *csr_file, char *result_str )
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100124{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200125 mbedtls_x509_csr csr;
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100126 char buf[2000];
127 int res;
128
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200129 mbedtls_x509_csr_init( &csr );
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100130 memset( buf, 0, 2000 );
131
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200132 TEST_ASSERT( mbedtls_x509_csr_parse_file( &csr, csr_file ) == 0 );
133 res = mbedtls_x509_csr_info( buf, 2000, "", &csr );
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100134
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100135 TEST_ASSERT( res != -1 );
136 TEST_ASSERT( res != -2 );
137
138 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200139
140exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200141 mbedtls_x509_csr_free( &csr );
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100142}
143/* END_CASE */
144
Manuel Pégourié-Gonnardb5f48ad2015-04-20 10:38:13 +0100145/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C */
146void x509_verify_info( int flags, char *prefix, char *result_str )
147{
148 char buf[2000];
149 int res;
150
151 memset( buf, 0, sizeof( buf ) );
152
153 res = mbedtls_x509_crt_verify_info( buf, sizeof( buf ), prefix, flags );
154
155 TEST_ASSERT( res >= 0 );
156
157 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
158}
159/* END_CASE */
160
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200161/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_CRL_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +0200162void x509_verify( char *crt_file, char *ca_file, char *crl_file,
163 char *cn_name_str, int result, int flags_result,
164 char *verify_callback )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000165{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200166 mbedtls_x509_crt crt;
167 mbedtls_x509_crt ca;
168 mbedtls_x509_crl crl;
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +0200169 uint32_t flags = 0;
Paul Bakker69998dd2009-07-11 19:15:20 +0000170 int res;
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +0200171 int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *) = NULL;
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200172 char * cn_name = NULL;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000173
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200174 mbedtls_x509_crt_init( &crt );
175 mbedtls_x509_crt_init( &ca );
176 mbedtls_x509_crl_init( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000177
Paul Bakker33b43f12013-08-20 11:48:36 +0200178 if( strcmp( cn_name_str, "NULL" ) != 0 )
179 cn_name = cn_name_str;
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200180
Paul Bakker33b43f12013-08-20 11:48:36 +0200181 if( strcmp( verify_callback, "NULL" ) == 0 )
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200182 f_vrfy = NULL;
Paul Bakker33b43f12013-08-20 11:48:36 +0200183 else if( strcmp( verify_callback, "verify_none" ) == 0 )
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200184 f_vrfy = verify_none;
Paul Bakker33b43f12013-08-20 11:48:36 +0200185 else if( strcmp( verify_callback, "verify_all" ) == 0 )
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200186 f_vrfy = verify_all;
187 else
188 TEST_ASSERT( "No known verify callback selected" == 0 );
189
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200190 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
191 TEST_ASSERT( mbedtls_x509_crt_parse_file( &ca, ca_file ) == 0 );
192 TEST_ASSERT( mbedtls_x509_crl_parse_file( &crl, crl_file ) == 0 );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000193
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200194 res = mbedtls_x509_crt_verify( &crt, &ca, &crl, cn_name, &flags, f_vrfy, NULL );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000195
Paul Bakkerbd51b262014-07-10 15:26:12 +0200196 TEST_ASSERT( res == ( result ) );
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +0200197 TEST_ASSERT( flags == (uint32_t)( flags_result ) );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200198
199exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200200 mbedtls_x509_crt_free( &crt );
201 mbedtls_x509_crt_free( &ca );
202 mbedtls_x509_crl_free( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000203}
Paul Bakker33b43f12013-08-20 11:48:36 +0200204/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000205
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200206/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnard560fea32015-09-01 11:59:24 +0200207void x509_verify_callback( char *crt_file, char *ca_file,
208 int exp_ret, char *exp_vrfy_out )
209{
210 int ret;
211 mbedtls_x509_crt crt;
212 mbedtls_x509_crt ca;
213 uint32_t flags = 0;
214 verify_print_context vrfy_ctx;
215
216 mbedtls_x509_crt_init( &crt );
217 mbedtls_x509_crt_init( &ca );
218 verify_print_init( &vrfy_ctx );
219
220 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
221 TEST_ASSERT( mbedtls_x509_crt_parse_file( &ca, ca_file ) == 0 );
222
223 ret = mbedtls_x509_crt_verify( &crt, &ca, NULL, NULL, &flags,
224 verify_print, &vrfy_ctx );
225
226 TEST_ASSERT( ret == exp_ret );
227 TEST_ASSERT( strcmp( vrfy_ctx.buf, exp_vrfy_out ) == 0 );
228
229exit:
230 mbedtls_x509_crt_free( &crt );
231 mbedtls_x509_crt_free( &ca );
232}
233/* END_CASE */
234
235/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200236void mbedtls_x509_dn_gets( char *crt_file, char *entity, char *result_str )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000237{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200238 mbedtls_x509_crt crt;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000239 char buf[2000];
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200240 int res = 0;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000241
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200242 mbedtls_x509_crt_init( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000243 memset( buf, 0, 2000 );
244
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200245 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Paul Bakker33b43f12013-08-20 11:48:36 +0200246 if( strcmp( entity, "subject" ) == 0 )
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200247 res = mbedtls_x509_dn_gets( buf, 2000, &crt.subject );
Paul Bakker33b43f12013-08-20 11:48:36 +0200248 else if( strcmp( entity, "issuer" ) == 0 )
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200249 res = mbedtls_x509_dn_gets( buf, 2000, &crt.issuer );
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200250 else
251 TEST_ASSERT( "Unknown entity" == 0 );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000252
253 TEST_ASSERT( res != -1 );
254 TEST_ASSERT( res != -2 );
255
Paul Bakker33b43f12013-08-20 11:48:36 +0200256 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200257
258exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200259 mbedtls_x509_crt_free( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000260}
Paul Bakker33b43f12013-08-20 11:48:36 +0200261/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000262
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200263/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100264void mbedtls_x509_time_is_past( char *crt_file, char *entity, int result )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000265{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200266 mbedtls_x509_crt crt;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000267
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200268 mbedtls_x509_crt_init( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000269
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200270 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200271
Paul Bakker33b43f12013-08-20 11:48:36 +0200272 if( strcmp( entity, "valid_from" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100273 TEST_ASSERT( mbedtls_x509_time_is_past( &crt.valid_from ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +0200274 else if( strcmp( entity, "valid_to" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100275 TEST_ASSERT( mbedtls_x509_time_is_past( &crt.valid_to ) == result );
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200276 else
277 TEST_ASSERT( "Unknown entity" == 0 );
Paul Bakkerb08e6842012-02-11 18:43:20 +0000278
Paul Bakkerbd51b262014-07-10 15:26:12 +0200279exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200280 mbedtls_x509_crt_free( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000281}
Paul Bakker33b43f12013-08-20 11:48:36 +0200282/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000283
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200284/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100285void mbedtls_x509_time_is_future( char *crt_file, char *entity, int result )
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100286{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200287 mbedtls_x509_crt crt;
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100288
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200289 mbedtls_x509_crt_init( &crt );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100290
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200291 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100292
293 if( strcmp( entity, "valid_from" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100294 TEST_ASSERT( mbedtls_x509_time_is_future( &crt.valid_from ) == result );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100295 else if( strcmp( entity, "valid_to" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100296 TEST_ASSERT( mbedtls_x509_time_is_future( &crt.valid_to ) == result );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100297 else
298 TEST_ASSERT( "Unknown entity" == 0 );
299
Paul Bakkerbd51b262014-07-10 15:26:12 +0200300exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200301 mbedtls_x509_crt_free( &crt );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100302}
303/* END_CASE */
304
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200305/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_FS_IO */
Paul Bakker5a5fa922014-09-26 14:53:04 +0200306void x509parse_crt_file( char *crt_file, int result )
307{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200308 mbedtls_x509_crt crt;
Paul Bakker5a5fa922014-09-26 14:53:04 +0200309
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200310 mbedtls_x509_crt_init( &crt );
Paul Bakker5a5fa922014-09-26 14:53:04 +0200311
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200312 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == result );
Paul Bakker5a5fa922014-09-26 14:53:04 +0200313
314exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200315 mbedtls_x509_crt_free( &crt );
Paul Bakker5a5fa922014-09-26 14:53:04 +0200316}
317/* END_CASE */
318
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200319/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +0200320void x509parse_crt( char *crt_data, char *result_str, int result )
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000321{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200322 mbedtls_x509_crt crt;
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000323 unsigned char buf[2000];
324 unsigned char output[2000];
325 int data_len, res;
326
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200327 mbedtls_x509_crt_init( &crt );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000328 memset( buf, 0, 2000 );
329 memset( output, 0, 2000 );
330
Paul Bakker33b43f12013-08-20 11:48:36 +0200331 data_len = unhexify( buf, crt_data );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000332
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200333 TEST_ASSERT( mbedtls_x509_crt_parse( &crt, buf, data_len ) == ( result ) );
Paul Bakker33b43f12013-08-20 11:48:36 +0200334 if( ( result ) == 0 )
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000335 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200336 res = mbedtls_x509_crt_info( (char *) output, 2000, "", &crt );
Paul Bakker33b43f12013-08-20 11:48:36 +0200337
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000338 TEST_ASSERT( res != -1 );
339 TEST_ASSERT( res != -2 );
340
Paul Bakker33b43f12013-08-20 11:48:36 +0200341 TEST_ASSERT( strcmp( (char *) output, result_str ) == 0 );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000342 }
Paul Bakkerb08e6842012-02-11 18:43:20 +0000343
Paul Bakkerbd51b262014-07-10 15:26:12 +0200344exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200345 mbedtls_x509_crt_free( &crt );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000346}
Paul Bakker33b43f12013-08-20 11:48:36 +0200347/* END_CASE */
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000348
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200349/* BEGIN_CASE depends_on:MBEDTLS_X509_CRL_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +0200350void x509parse_crl( char *crl_data, char *result_str, int result )
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000351{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200352 mbedtls_x509_crl crl;
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000353 unsigned char buf[2000];
354 unsigned char output[2000];
355 int data_len, res;
356
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200357 mbedtls_x509_crl_init( &crl );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000358 memset( buf, 0, 2000 );
359 memset( output, 0, 2000 );
360
Paul Bakker33b43f12013-08-20 11:48:36 +0200361 data_len = unhexify( buf, crl_data );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000362
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200363 TEST_ASSERT( mbedtls_x509_crl_parse( &crl, buf, data_len ) == ( result ) );
Paul Bakker33b43f12013-08-20 11:48:36 +0200364 if( ( result ) == 0 )
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000365 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200366 res = mbedtls_x509_crl_info( (char *) output, 2000, "", &crl );
Paul Bakker33b43f12013-08-20 11:48:36 +0200367
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000368 TEST_ASSERT( res != -1 );
369 TEST_ASSERT( res != -2 );
370
Paul Bakker33b43f12013-08-20 11:48:36 +0200371 TEST_ASSERT( strcmp( (char *) output, result_str ) == 0 );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000372 }
Paul Bakkerb08e6842012-02-11 18:43:20 +0000373
Paul Bakkerbd51b262014-07-10 15:26:12 +0200374exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200375 mbedtls_x509_crl_free( &crl );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000376}
Paul Bakker33b43f12013-08-20 11:48:36 +0200377/* END_CASE */
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000378
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200379/* BEGIN_CASE depends_on:MBEDTLS_X509_CSR_PARSE_C */
380void mbedtls_x509_csr_parse( char *csr_der_hex, char *ref_out, int ref_ret )
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200381{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200382 mbedtls_x509_csr csr;
Paul Bakkerbd51b262014-07-10 15:26:12 +0200383 unsigned char *csr_der = NULL;
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200384 char my_out[1000];
385 size_t csr_der_len;
386 int my_ret;
387
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200388 mbedtls_x509_csr_init( &csr );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200389 memset( my_out, 0, sizeof( my_out ) );
390 csr_der = unhexify_alloc( csr_der_hex, &csr_der_len );
391
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200392 my_ret = mbedtls_x509_csr_parse_der( &csr, csr_der, csr_der_len );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200393 TEST_ASSERT( my_ret == ref_ret );
394
395 if( ref_ret == 0 )
396 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200397 size_t my_out_len = mbedtls_x509_csr_info( my_out, sizeof( my_out ), "", &csr );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200398 TEST_ASSERT( my_out_len == strlen( ref_out ) );
399 TEST_ASSERT( strcmp( my_out, ref_out ) == 0 );
400 }
401
Paul Bakkerbd51b262014-07-10 15:26:12 +0200402exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200403 mbedtls_x509_csr_free( &csr );
404 mbedtls_free( csr_der );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200405}
406/* END_CASE */
407
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200408/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
409void mbedtls_x509_crt_parse_path( char *crt_path, int ret, int nb_crt )
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100410{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200411 mbedtls_x509_crt chain, *cur;
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100412 int i;
413
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200414 mbedtls_x509_crt_init( &chain );
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100415
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200416 TEST_ASSERT( mbedtls_x509_crt_parse_path( &chain, crt_path ) == ret );
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100417
418 /* Check how many certs we got */
419 for( i = 0, cur = &chain; cur != NULL; cur = cur->next )
420 if( cur->raw.p != NULL )
421 i++;
422
423 TEST_ASSERT( i == nb_crt );
424
Paul Bakkerbd51b262014-07-10 15:26:12 +0200425exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200426 mbedtls_x509_crt_free( &chain );
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100427}
428/* END_CASE */
429
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200430/* BEGIN_CASE depends_on:MBEDTLS_X509_USE_C */
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100431void x509_oid_desc( char *oid_str, char *ref_desc )
432{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200433 mbedtls_x509_buf oid;
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000434 const char *desc = NULL;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100435 unsigned char buf[20];
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000436 int ret;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100437
438 memset( buf, 0, sizeof buf );
439
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200440 oid.tag = MBEDTLS_ASN1_OID;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100441 oid.len = unhexify( buf, oid_str );
442 oid.p = buf;
443
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200444 ret = mbedtls_oid_get_extended_key_usage( &oid, &desc );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100445
446 if( strcmp( ref_desc, "notfound" ) == 0 )
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000447 {
448 TEST_ASSERT( ret != 0 );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100449 TEST_ASSERT( desc == NULL );
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000450 }
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100451 else
452 {
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000453 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100454 TEST_ASSERT( desc != NULL );
455 TEST_ASSERT( strcmp( desc, ref_desc ) == 0 );
456 }
457}
458/* END_CASE */
459
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200460/* BEGIN_CASE depends_on:MBEDTLS_X509_USE_C */
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100461void x509_oid_numstr( char *oid_str, char *numstr, int blen, int ret )
462{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200463 mbedtls_x509_buf oid;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100464 unsigned char oid_buf[20];
465 char num_buf[100];
466
467 memset( oid_buf, 0x00, sizeof oid_buf );
468 memset( num_buf, 0x2a, sizeof num_buf );
469
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200470 oid.tag = MBEDTLS_ASN1_OID;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100471 oid.len = unhexify( oid_buf, oid_str );
472 oid.p = oid_buf;
473
474 TEST_ASSERT( (size_t) blen <= sizeof num_buf );
475
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200476 TEST_ASSERT( mbedtls_oid_get_numeric_string( num_buf, blen, &oid ) == ret );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100477
478 if( ret >= 0 )
479 {
480 TEST_ASSERT( num_buf[ret] == 0 );
481 TEST_ASSERT( strcmp( num_buf, numstr ) == 0 );
482 }
483}
484/* END_CASE */
485
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200486/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_CHECK_KEY_USAGE */
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200487void x509_check_key_usage( char *crt_file, int usage, int ret )
488{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200489 mbedtls_x509_crt crt;
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200490
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200491 mbedtls_x509_crt_init( &crt );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200492
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200493 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200494
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200495 TEST_ASSERT( mbedtls_x509_crt_check_key_usage( &crt, usage ) == ret );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200496
Paul Bakkerbd51b262014-07-10 15:26:12 +0200497exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200498 mbedtls_x509_crt_free( &crt );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200499}
500/* END_CASE */
501
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200502/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_CHECK_EXTENDED_KEY_USAGE */
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200503void x509_check_extended_key_usage( char *crt_file, char *usage_hex, int ret )
504{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200505 mbedtls_x509_crt crt;
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200506 char oid[50];
507 size_t len;
508
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200509 mbedtls_x509_crt_init( &crt );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200510
511 len = unhexify( (unsigned char *) oid, usage_hex );
512
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200513 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200514
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200515 TEST_ASSERT( mbedtls_x509_crt_check_extended_key_usage( &crt, oid, len ) == ret );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200516
Paul Bakkerbd51b262014-07-10 15:26:12 +0200517exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200518 mbedtls_x509_crt_free( &crt );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200519}
520/* END_CASE */
521
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200522/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_RSASSA_PSS_SUPPORT */
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200523void x509_parse_rsassa_pss_params( char *hex_params, int params_tag,
524 int ref_msg_md, int ref_mgf_md,
525 int ref_salt_len, int ref_ret )
526{
527 int my_ret;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200528 mbedtls_x509_buf params;
529 mbedtls_md_type_t my_msg_md, my_mgf_md;
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200530 int my_salt_len;
531
532 params.p = unhexify_alloc( hex_params, &params.len );
533 params.tag = params_tag;
534
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200535 my_ret = mbedtls_x509_get_rsassa_pss_params( &params, &my_msg_md, &my_mgf_md,
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200536 &my_salt_len );
537
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200538 TEST_ASSERT( my_ret == ref_ret );
539
540 if( ref_ret == 0 )
541 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200542 TEST_ASSERT( my_msg_md == (mbedtls_md_type_t) ref_msg_md );
543 TEST_ASSERT( my_mgf_md == (mbedtls_md_type_t) ref_mgf_md );
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200544 TEST_ASSERT( my_salt_len == ref_salt_len );
545 }
546
Paul Bakkerbd51b262014-07-10 15:26:12 +0200547exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200548 mbedtls_free( params.p );
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200549}
550/* END_CASE */
551
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200552/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_SELF_TEST */
Paul Bakker33b43f12013-08-20 11:48:36 +0200553void x509_selftest()
Paul Bakker37940d9f2009-07-10 22:38:58 +0000554{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200555 TEST_ASSERT( mbedtls_x509_self_test( 0 ) == 0 );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000556}
Paul Bakker33b43f12013-08-20 11:48:36 +0200557/* END_CASE */