blob: 99d716ba609fa00deea7fa2821555bc982bce275 [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/x509_crt.h"
3#include "mbedtls/x509_crl.h"
4#include "mbedtls/x509_csr.h"
5#include "mbedtls/pem.h"
6#include "mbedtls/oid.h"
7#include "mbedtls/base64.h"
Paul Bakkerb63b0af2011-01-13 17:54:59 +00008
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +02009int verify_none( void *data, mbedtls_x509_crt *crt, int certificate_depth, uint32_t *flags )
Paul Bakkerb63b0af2011-01-13 17:54:59 +000010{
Paul Bakker5a624082011-01-18 16:31:52 +000011 ((void) data);
12 ((void) crt);
13 ((void) certificate_depth);
Manuel Pégourié-Gonnarde6028c92015-04-20 12:19:02 +010014 *flags |= MBEDTLS_X509_BADCERT_OTHER;
Paul Bakkerddf26b42013-09-18 13:46:23 +020015
Paul Bakker915275b2012-09-28 07:10:55 +000016 return 0;
Paul Bakkerb63b0af2011-01-13 17:54:59 +000017}
18
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +020019int verify_all( void *data, mbedtls_x509_crt *crt, int certificate_depth, uint32_t *flags )
Paul Bakkerb63b0af2011-01-13 17:54:59 +000020{
Paul Bakker5a624082011-01-18 16:31:52 +000021 ((void) data);
22 ((void) crt);
23 ((void) certificate_depth);
Paul Bakker915275b2012-09-28 07:10:55 +000024 *flags = 0;
Paul Bakker5a624082011-01-18 16:31:52 +000025
Paul Bakkerb63b0af2011-01-13 17:54:59 +000026 return 0;
27}
28
Manuel Pégourié-Gonnard560fea32015-09-01 11:59:24 +020029#if defined(MBEDTLS_X509_CRT_PARSE_C)
30typedef struct {
31 char buf[512];
32 char *p;
33} verify_print_context;
34
35void verify_print_init( verify_print_context *ctx )
36{
37 memset( ctx, 0, sizeof( verify_print_context ) );
38 ctx->p = ctx->buf;
39}
40
41int verify_print( void *data, mbedtls_x509_crt *crt, int certificate_depth, uint32_t *flags )
42{
43 int ret;
44 verify_print_context *ctx = (verify_print_context *) data;
45 char *p = ctx->p;
46 size_t n = ctx->buf + sizeof( ctx->buf ) - ctx->p;
47 ((void) flags);
48
49 ret = mbedtls_snprintf( p, n, "depth %d - serial ", certificate_depth );
50 MBEDTLS_X509_SAFE_SNPRINTF;
51
52 ret = mbedtls_x509_serial_gets( p, n, &crt->serial );
53 MBEDTLS_X509_SAFE_SNPRINTF;
54
55 ret = mbedtls_snprintf( p, n, " - subject " );
56 MBEDTLS_X509_SAFE_SNPRINTF;
57
58 ret = mbedtls_x509_dn_gets( p, n, &crt->subject );
59 MBEDTLS_X509_SAFE_SNPRINTF;
60
61 ret = mbedtls_snprintf( p, n, "\n" );
62 MBEDTLS_X509_SAFE_SNPRINTF;
63
64 ctx->p = p;
65
66 return( 0 );
67}
68#endif /* MBEDTLS_X509_CRT_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +020069/* END_HEADER */
Paul Bakker37940d9f2009-07-10 22:38:58 +000070
Paul Bakker33b43f12013-08-20 11:48:36 +020071/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020072 * depends_on:MBEDTLS_BIGNUM_C
Paul Bakker33b43f12013-08-20 11:48:36 +020073 * END_DEPENDENCIES
74 */
Paul Bakker5690efc2011-05-26 13:16:06 +000075
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020076/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +020077void x509_cert_info( char *crt_file, char *result_str )
Paul Bakker37940d9f2009-07-10 22:38:58 +000078{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020079 mbedtls_x509_crt crt;
Paul Bakker37940d9f2009-07-10 22:38:58 +000080 char buf[2000];
Paul Bakker69998dd2009-07-11 19:15:20 +000081 int res;
Paul Bakker37940d9f2009-07-10 22:38:58 +000082
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020083 mbedtls_x509_crt_init( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +000084 memset( buf, 0, 2000 );
85
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020086 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
87 res = mbedtls_x509_crt_info( buf, 2000, "", &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +000088
89 TEST_ASSERT( res != -1 );
90 TEST_ASSERT( res != -2 );
91
Paul Bakker33b43f12013-08-20 11:48:36 +020092 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +020093
94exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020095 mbedtls_x509_crt_free( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +000096}
Paul Bakker33b43f12013-08-20 11:48:36 +020097/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +000098
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020099/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRL_PARSE_C */
100void mbedtls_x509_crl_info( char *crl_file, char *result_str )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000101{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200102 mbedtls_x509_crl crl;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000103 char buf[2000];
Paul Bakker69998dd2009-07-11 19:15:20 +0000104 int res;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000105
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200106 mbedtls_x509_crl_init( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000107 memset( buf, 0, 2000 );
108
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200109 TEST_ASSERT( mbedtls_x509_crl_parse_file( &crl, crl_file ) == 0 );
110 res = mbedtls_x509_crl_info( buf, 2000, "", &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000111
112 TEST_ASSERT( res != -1 );
113 TEST_ASSERT( res != -2 );
114
Paul Bakker33b43f12013-08-20 11:48:36 +0200115 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200116
117exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200118 mbedtls_x509_crl_free( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000119}
Paul Bakker33b43f12013-08-20 11:48:36 +0200120/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000121
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200122/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CSR_PARSE_C */
123void mbedtls_x509_csr_info( char *csr_file, char *result_str )
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100124{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200125 mbedtls_x509_csr csr;
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100126 char buf[2000];
127 int res;
128
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200129 mbedtls_x509_csr_init( &csr );
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100130 memset( buf, 0, 2000 );
131
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200132 TEST_ASSERT( mbedtls_x509_csr_parse_file( &csr, csr_file ) == 0 );
133 res = mbedtls_x509_csr_info( buf, 2000, "", &csr );
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100134
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100135 TEST_ASSERT( res != -1 );
136 TEST_ASSERT( res != -2 );
137
138 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200139
140exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200141 mbedtls_x509_csr_free( &csr );
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100142}
143/* END_CASE */
144
Manuel Pégourié-Gonnardb5f48ad2015-04-20 10:38:13 +0100145/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C */
146void x509_verify_info( int flags, char *prefix, char *result_str )
147{
148 char buf[2000];
149 int res;
150
151 memset( buf, 0, sizeof( buf ) );
152
153 res = mbedtls_x509_crt_verify_info( buf, sizeof( buf ), prefix, flags );
154
155 TEST_ASSERT( res >= 0 );
156
157 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
158}
159/* END_CASE */
160
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200161/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_CRL_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +0200162void x509_verify( char *crt_file, char *ca_file, char *crl_file,
163 char *cn_name_str, int result, int flags_result,
164 char *verify_callback )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000165{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200166 mbedtls_x509_crt crt;
167 mbedtls_x509_crt ca;
168 mbedtls_x509_crl crl;
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +0200169 uint32_t flags = 0;
Paul Bakker69998dd2009-07-11 19:15:20 +0000170 int res;
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +0200171 int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *) = NULL;
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200172 char * cn_name = NULL;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000173
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200174 mbedtls_x509_crt_init( &crt );
175 mbedtls_x509_crt_init( &ca );
176 mbedtls_x509_crl_init( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000177
Paul Bakker33b43f12013-08-20 11:48:36 +0200178 if( strcmp( cn_name_str, "NULL" ) != 0 )
179 cn_name = cn_name_str;
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200180
Paul Bakker33b43f12013-08-20 11:48:36 +0200181 if( strcmp( verify_callback, "NULL" ) == 0 )
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200182 f_vrfy = NULL;
Paul Bakker33b43f12013-08-20 11:48:36 +0200183 else if( strcmp( verify_callback, "verify_none" ) == 0 )
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200184 f_vrfy = verify_none;
Paul Bakker33b43f12013-08-20 11:48:36 +0200185 else if( strcmp( verify_callback, "verify_all" ) == 0 )
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200186 f_vrfy = verify_all;
187 else
188 TEST_ASSERT( "No known verify callback selected" == 0 );
189
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200190 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
191 TEST_ASSERT( mbedtls_x509_crt_parse_file( &ca, ca_file ) == 0 );
192 TEST_ASSERT( mbedtls_x509_crl_parse_file( &crl, crl_file ) == 0 );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000193
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200194 res = mbedtls_x509_crt_verify( &crt, &ca, &crl, cn_name, &flags, f_vrfy, NULL );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000195
Paul Bakkerbd51b262014-07-10 15:26:12 +0200196 TEST_ASSERT( res == ( result ) );
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +0200197 TEST_ASSERT( flags == (uint32_t)( flags_result ) );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200198
199exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200200 mbedtls_x509_crt_free( &crt );
201 mbedtls_x509_crt_free( &ca );
202 mbedtls_x509_crl_free( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000203}
Paul Bakker33b43f12013-08-20 11:48:36 +0200204/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000205
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200206/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnard560fea32015-09-01 11:59:24 +0200207void x509_verify_callback( char *crt_file, char *ca_file,
208 int exp_ret, char *exp_vrfy_out )
209{
210 int ret;
211 mbedtls_x509_crt crt;
212 mbedtls_x509_crt ca;
213 uint32_t flags = 0;
214 verify_print_context vrfy_ctx;
215
216 mbedtls_x509_crt_init( &crt );
217 mbedtls_x509_crt_init( &ca );
218 verify_print_init( &vrfy_ctx );
219
220 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
221 TEST_ASSERT( mbedtls_x509_crt_parse_file( &ca, ca_file ) == 0 );
222
223 ret = mbedtls_x509_crt_verify( &crt, &ca, NULL, NULL, &flags,
224 verify_print, &vrfy_ctx );
225
226 TEST_ASSERT( ret == exp_ret );
227 TEST_ASSERT( strcmp( vrfy_ctx.buf, exp_vrfy_out ) == 0 );
228
229exit:
230 mbedtls_x509_crt_free( &crt );
231 mbedtls_x509_crt_free( &ca );
232}
233/* END_CASE */
234
235/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200236void mbedtls_x509_dn_gets( char *crt_file, char *entity, char *result_str )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000237{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200238 mbedtls_x509_crt crt;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000239 char buf[2000];
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200240 int res = 0;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000241
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200242 mbedtls_x509_crt_init( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000243 memset( buf, 0, 2000 );
244
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200245 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Paul Bakker33b43f12013-08-20 11:48:36 +0200246 if( strcmp( entity, "subject" ) == 0 )
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200247 res = mbedtls_x509_dn_gets( buf, 2000, &crt.subject );
Paul Bakker33b43f12013-08-20 11:48:36 +0200248 else if( strcmp( entity, "issuer" ) == 0 )
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200249 res = mbedtls_x509_dn_gets( buf, 2000, &crt.issuer );
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200250 else
251 TEST_ASSERT( "Unknown entity" == 0 );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000252
253 TEST_ASSERT( res != -1 );
254 TEST_ASSERT( res != -2 );
255
Paul Bakker33b43f12013-08-20 11:48:36 +0200256 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200257
258exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200259 mbedtls_x509_crt_free( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000260}
Paul Bakker33b43f12013-08-20 11:48:36 +0200261/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000262
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200263/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100264void mbedtls_x509_time_is_past( char *crt_file, char *entity, int result )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000265{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200266 mbedtls_x509_crt crt;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000267
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200268 mbedtls_x509_crt_init( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000269
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200270 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200271
Paul Bakker33b43f12013-08-20 11:48:36 +0200272 if( strcmp( entity, "valid_from" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100273 TEST_ASSERT( mbedtls_x509_time_is_past( &crt.valid_from ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +0200274 else if( strcmp( entity, "valid_to" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100275 TEST_ASSERT( mbedtls_x509_time_is_past( &crt.valid_to ) == result );
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200276 else
277 TEST_ASSERT( "Unknown entity" == 0 );
Paul Bakkerb08e6842012-02-11 18:43:20 +0000278
Paul Bakkerbd51b262014-07-10 15:26:12 +0200279exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200280 mbedtls_x509_crt_free( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000281}
Paul Bakker33b43f12013-08-20 11:48:36 +0200282/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000283
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200284/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100285void mbedtls_x509_time_is_future( char *crt_file, char *entity, int result )
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100286{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200287 mbedtls_x509_crt crt;
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100288
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200289 mbedtls_x509_crt_init( &crt );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100290
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200291 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100292
293 if( strcmp( entity, "valid_from" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100294 TEST_ASSERT( mbedtls_x509_time_is_future( &crt.valid_from ) == result );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100295 else if( strcmp( entity, "valid_to" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100296 TEST_ASSERT( mbedtls_x509_time_is_future( &crt.valid_to ) == result );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100297 else
298 TEST_ASSERT( "Unknown entity" == 0 );
299
Paul Bakkerbd51b262014-07-10 15:26:12 +0200300exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200301 mbedtls_x509_crt_free( &crt );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100302}
303/* END_CASE */
304
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200305/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_FS_IO */
Paul Bakker5a5fa922014-09-26 14:53:04 +0200306void x509parse_crt_file( char *crt_file, int result )
307{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200308 mbedtls_x509_crt crt;
Paul Bakker5a5fa922014-09-26 14:53:04 +0200309
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200310 mbedtls_x509_crt_init( &crt );
Paul Bakker5a5fa922014-09-26 14:53:04 +0200311
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200312 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == result );
Paul Bakker5a5fa922014-09-26 14:53:04 +0200313
314exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200315 mbedtls_x509_crt_free( &crt );
Paul Bakker5a5fa922014-09-26 14:53:04 +0200316}
317/* END_CASE */
318
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200319/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +0200320void x509parse_crt( char *crt_data, char *result_str, int result )
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000321{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200322 mbedtls_x509_crt crt;
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000323 unsigned char buf[2000];
324 unsigned char output[2000];
325 int data_len, res;
326
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200327 mbedtls_x509_crt_init( &crt );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000328 memset( buf, 0, 2000 );
329 memset( output, 0, 2000 );
330
Paul Bakker33b43f12013-08-20 11:48:36 +0200331 data_len = unhexify( buf, crt_data );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000332
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200333 TEST_ASSERT( mbedtls_x509_crt_parse( &crt, buf, data_len ) == ( result ) );
Paul Bakker33b43f12013-08-20 11:48:36 +0200334 if( ( result ) == 0 )
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000335 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200336 res = mbedtls_x509_crt_info( (char *) output, 2000, "", &crt );
Paul Bakker33b43f12013-08-20 11:48:36 +0200337
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000338 TEST_ASSERT( res != -1 );
339 TEST_ASSERT( res != -2 );
340
Paul Bakker33b43f12013-08-20 11:48:36 +0200341 TEST_ASSERT( strcmp( (char *) output, result_str ) == 0 );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000342 }
Paul Bakkerb08e6842012-02-11 18:43:20 +0000343
Paul Bakkerbd51b262014-07-10 15:26:12 +0200344exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200345 mbedtls_x509_crt_free( &crt );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000346}
Paul Bakker33b43f12013-08-20 11:48:36 +0200347/* END_CASE */
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000348
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200349/* BEGIN_CASE depends_on:MBEDTLS_X509_CRL_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +0200350void x509parse_crl( char *crl_data, char *result_str, int result )
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000351{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200352 mbedtls_x509_crl crl;
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000353 unsigned char buf[2000];
354 unsigned char output[2000];
355 int data_len, res;
356
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200357 mbedtls_x509_crl_init( &crl );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000358 memset( buf, 0, 2000 );
359 memset( output, 0, 2000 );
360
Paul Bakker33b43f12013-08-20 11:48:36 +0200361 data_len = unhexify( buf, crl_data );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000362
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200363 TEST_ASSERT( mbedtls_x509_crl_parse( &crl, buf, data_len ) == ( result ) );
Paul Bakker33b43f12013-08-20 11:48:36 +0200364 if( ( result ) == 0 )
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000365 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200366 res = mbedtls_x509_crl_info( (char *) output, 2000, "", &crl );
Paul Bakker33b43f12013-08-20 11:48:36 +0200367
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000368 TEST_ASSERT( res != -1 );
369 TEST_ASSERT( res != -2 );
370
Paul Bakker33b43f12013-08-20 11:48:36 +0200371 TEST_ASSERT( strcmp( (char *) output, result_str ) == 0 );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000372 }
Paul Bakkerb08e6842012-02-11 18:43:20 +0000373
Paul Bakkerbd51b262014-07-10 15:26:12 +0200374exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200375 mbedtls_x509_crl_free( &crl );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000376}
Paul Bakker33b43f12013-08-20 11:48:36 +0200377/* END_CASE */
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000378
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200379/* BEGIN_CASE depends_on:MBEDTLS_X509_CSR_PARSE_C */
380void mbedtls_x509_csr_parse( char *csr_der_hex, char *ref_out, int ref_ret )
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200381{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200382 mbedtls_x509_csr csr;
Paul Bakkerbd51b262014-07-10 15:26:12 +0200383 unsigned char *csr_der = NULL;
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200384 char my_out[1000];
385 size_t csr_der_len;
386 int my_ret;
387
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200388 mbedtls_x509_csr_init( &csr );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200389 memset( my_out, 0, sizeof( my_out ) );
390 csr_der = unhexify_alloc( csr_der_hex, &csr_der_len );
391
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200392 my_ret = mbedtls_x509_csr_parse_der( &csr, csr_der, csr_der_len );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200393 TEST_ASSERT( my_ret == ref_ret );
394
395 if( ref_ret == 0 )
396 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200397 size_t my_out_len = mbedtls_x509_csr_info( my_out, sizeof( my_out ), "", &csr );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200398 TEST_ASSERT( my_out_len == strlen( ref_out ) );
399 TEST_ASSERT( strcmp( my_out, ref_out ) == 0 );
400 }
401
Paul Bakkerbd51b262014-07-10 15:26:12 +0200402exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200403 mbedtls_x509_csr_free( &csr );
404 mbedtls_free( csr_der );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200405}
406/* END_CASE */
407
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200408/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
409void mbedtls_x509_crt_parse_path( char *crt_path, int ret, int nb_crt )
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100410{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200411 mbedtls_x509_crt chain, *cur;
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100412 int i;
413
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200414 mbedtls_x509_crt_init( &chain );
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100415
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200416 TEST_ASSERT( mbedtls_x509_crt_parse_path( &chain, crt_path ) == ret );
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100417
418 /* Check how many certs we got */
419 for( i = 0, cur = &chain; cur != NULL; cur = cur->next )
420 if( cur->raw.p != NULL )
421 i++;
422
423 TEST_ASSERT( i == nb_crt );
424
Paul Bakkerbd51b262014-07-10 15:26:12 +0200425exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200426 mbedtls_x509_crt_free( &chain );
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100427}
428/* END_CASE */
429
Janos Follath822b2c32015-10-11 10:25:22 +0200430/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
431void mbedtls_x509_crt_verify_chain( char *chain_paths, char *trusted_ca, int ret )
432{
433 char* act;
434 uint32_t flags;
435 int res;
436 mbedtls_x509_crt trusted, chain;
437
438 mbedtls_x509_crt_init( &chain );
439 mbedtls_x509_crt_init( &trusted );
440
441 while( (act = strsep( &chain_paths, " " )) )
442 TEST_ASSERT( mbedtls_x509_crt_parse_file( &chain, act ) == 0 );
443 TEST_ASSERT( mbedtls_x509_crt_parse_file( &trusted, trusted_ca ) == 0 );
444
445 res = mbedtls_x509_crt_verify( &chain, &trusted, NULL, NULL, &flags, NULL, NULL );
446
447 TEST_ASSERT( ret == res );
448
449exit:
450 mbedtls_x509_crt_free( &trusted );
451 mbedtls_x509_crt_free( &chain );
452}
453/* END_CASE */
454
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200455/* BEGIN_CASE depends_on:MBEDTLS_X509_USE_C */
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100456void x509_oid_desc( char *oid_str, char *ref_desc )
457{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200458 mbedtls_x509_buf oid;
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000459 const char *desc = NULL;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100460 unsigned char buf[20];
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000461 int ret;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100462
463 memset( buf, 0, sizeof buf );
464
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200465 oid.tag = MBEDTLS_ASN1_OID;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100466 oid.len = unhexify( buf, oid_str );
467 oid.p = buf;
468
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200469 ret = mbedtls_oid_get_extended_key_usage( &oid, &desc );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100470
471 if( strcmp( ref_desc, "notfound" ) == 0 )
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000472 {
473 TEST_ASSERT( ret != 0 );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100474 TEST_ASSERT( desc == NULL );
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000475 }
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100476 else
477 {
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000478 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100479 TEST_ASSERT( desc != NULL );
480 TEST_ASSERT( strcmp( desc, ref_desc ) == 0 );
481 }
482}
483/* END_CASE */
484
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200485/* BEGIN_CASE depends_on:MBEDTLS_X509_USE_C */
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100486void x509_oid_numstr( char *oid_str, char *numstr, int blen, int ret )
487{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200488 mbedtls_x509_buf oid;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100489 unsigned char oid_buf[20];
490 char num_buf[100];
491
492 memset( oid_buf, 0x00, sizeof oid_buf );
493 memset( num_buf, 0x2a, sizeof num_buf );
494
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200495 oid.tag = MBEDTLS_ASN1_OID;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100496 oid.len = unhexify( oid_buf, oid_str );
497 oid.p = oid_buf;
498
499 TEST_ASSERT( (size_t) blen <= sizeof num_buf );
500
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200501 TEST_ASSERT( mbedtls_oid_get_numeric_string( num_buf, blen, &oid ) == ret );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100502
503 if( ret >= 0 )
504 {
505 TEST_ASSERT( num_buf[ret] == 0 );
506 TEST_ASSERT( strcmp( num_buf, numstr ) == 0 );
507 }
508}
509/* END_CASE */
510
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200511/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_CHECK_KEY_USAGE */
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200512void x509_check_key_usage( char *crt_file, int usage, int ret )
513{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200514 mbedtls_x509_crt crt;
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200515
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200516 mbedtls_x509_crt_init( &crt );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200517
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200518 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200519
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200520 TEST_ASSERT( mbedtls_x509_crt_check_key_usage( &crt, usage ) == ret );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200521
Paul Bakkerbd51b262014-07-10 15:26:12 +0200522exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200523 mbedtls_x509_crt_free( &crt );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200524}
525/* END_CASE */
526
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200527/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_CHECK_EXTENDED_KEY_USAGE */
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200528void x509_check_extended_key_usage( char *crt_file, char *usage_hex, int ret )
529{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200530 mbedtls_x509_crt crt;
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200531 char oid[50];
532 size_t len;
533
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200534 mbedtls_x509_crt_init( &crt );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200535
536 len = unhexify( (unsigned char *) oid, usage_hex );
537
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200538 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200539
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200540 TEST_ASSERT( mbedtls_x509_crt_check_extended_key_usage( &crt, oid, len ) == ret );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200541
Paul Bakkerbd51b262014-07-10 15:26:12 +0200542exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200543 mbedtls_x509_crt_free( &crt );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200544}
545/* END_CASE */
546
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200547/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_RSASSA_PSS_SUPPORT */
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200548void x509_parse_rsassa_pss_params( char *hex_params, int params_tag,
549 int ref_msg_md, int ref_mgf_md,
550 int ref_salt_len, int ref_ret )
551{
552 int my_ret;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200553 mbedtls_x509_buf params;
554 mbedtls_md_type_t my_msg_md, my_mgf_md;
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200555 int my_salt_len;
556
557 params.p = unhexify_alloc( hex_params, &params.len );
558 params.tag = params_tag;
559
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200560 my_ret = mbedtls_x509_get_rsassa_pss_params( &params, &my_msg_md, &my_mgf_md,
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200561 &my_salt_len );
562
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200563 TEST_ASSERT( my_ret == ref_ret );
564
565 if( ref_ret == 0 )
566 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200567 TEST_ASSERT( my_msg_md == (mbedtls_md_type_t) ref_msg_md );
568 TEST_ASSERT( my_mgf_md == (mbedtls_md_type_t) ref_mgf_md );
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200569 TEST_ASSERT( my_salt_len == ref_salt_len );
570 }
571
Paul Bakkerbd51b262014-07-10 15:26:12 +0200572exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200573 mbedtls_free( params.p );
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200574}
575/* END_CASE */
576
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200577/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_SELF_TEST */
Paul Bakker33b43f12013-08-20 11:48:36 +0200578void x509_selftest()
Paul Bakker37940d9f2009-07-10 22:38:58 +0000579{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200580 TEST_ASSERT( mbedtls_x509_self_test( 0 ) == 0 );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000581}
Paul Bakker33b43f12013-08-20 11:48:36 +0200582/* END_CASE */