2
0

pkcs12_format_test.c 38 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053
  1. /*
  2. * Copyright 2020-2023 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the Apache License 2.0 (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. #include <stdio.h>
  10. #include <string.h>
  11. #include <stdlib.h>
  12. #include <openssl/pkcs12.h>
  13. #include <openssl/x509.h>
  14. #include <openssl/x509v3.h>
  15. #include <openssl/pem.h>
  16. #include "testutil.h"
  17. #include "helpers/pkcs12.h"
  18. static int default_libctx = 1;
  19. static OSSL_LIB_CTX *testctx = NULL;
  20. static OSSL_PROVIDER *nullprov = NULL;
  21. static OSSL_PROVIDER *deflprov = NULL;
  22. static OSSL_PROVIDER *lgcyprov = NULL;
  23. /* --------------------------------------------------------------------------
  24. * PKCS12 component test data
  25. */
  26. static const unsigned char CERT1[] =
  27. {
  28. 0x30, 0x82, 0x01, 0xed, 0x30, 0x82, 0x01, 0x56, 0xa0, 0x03, 0x02, 0x01, 0x02, 0x02, 0x09, 0x00,
  29. 0x8b, 0x4b, 0x5e, 0x6c, 0x03, 0x28, 0x4e, 0xe6, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86,
  30. 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x30, 0x19, 0x31, 0x17, 0x30, 0x15, 0x06, 0x03, 0x55,
  31. 0x04, 0x03, 0x0c, 0x0e, 0x50, 0x31, 0x32, 0x54, 0x65, 0x73, 0x74, 0x2d, 0x52, 0x6f, 0x6f, 0x74,
  32. 0x2d, 0x41, 0x30, 0x1e, 0x17, 0x0d, 0x31, 0x39, 0x30, 0x39, 0x33, 0x30, 0x30, 0x30, 0x34, 0x36,
  33. 0x35, 0x36, 0x5a, 0x17, 0x0d, 0x32, 0x39, 0x30, 0x39, 0x32, 0x37, 0x30, 0x30, 0x34, 0x36, 0x35,
  34. 0x36, 0x5a, 0x30, 0x1b, 0x31, 0x19, 0x30, 0x17, 0x06, 0x03, 0x55, 0x04, 0x03, 0x0c, 0x10, 0x50,
  35. 0x31, 0x32, 0x54, 0x65, 0x73, 0x74, 0x2d, 0x53, 0x65, 0x72, 0x76, 0x65, 0x72, 0x2d, 0x31, 0x30,
  36. 0x81, 0x9f, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x01, 0x05,
  37. 0x00, 0x03, 0x81, 0x8d, 0x00, 0x30, 0x81, 0x89, 0x02, 0x81, 0x81, 0x00, 0xbc, 0xdc, 0x6f, 0x8c,
  38. 0x7a, 0x2a, 0x4b, 0xea, 0x66, 0x66, 0x04, 0xa9, 0x05, 0x92, 0x53, 0xd7, 0x13, 0x3c, 0x49, 0xe1,
  39. 0xc8, 0xbb, 0xdf, 0x3d, 0xcb, 0x88, 0x31, 0x07, 0x20, 0x59, 0x93, 0x24, 0x7f, 0x7d, 0xc6, 0x84,
  40. 0x81, 0x16, 0x64, 0x4a, 0x52, 0xa6, 0x30, 0x44, 0xdc, 0x1a, 0x30, 0xde, 0xae, 0x29, 0x18, 0xcf,
  41. 0xc7, 0xf3, 0xcf, 0x0c, 0xb7, 0x8e, 0x2b, 0x1e, 0x21, 0x01, 0x0b, 0xfb, 0xe5, 0xe6, 0xcf, 0x2b,
  42. 0x84, 0xe1, 0x33, 0xf8, 0xba, 0x02, 0xfc, 0x30, 0xfa, 0xc4, 0x33, 0xc7, 0x37, 0xc6, 0x7f, 0x72,
  43. 0x31, 0x92, 0x1d, 0x8f, 0xa0, 0xfb, 0xe5, 0x4a, 0x08, 0x31, 0x78, 0x80, 0x9c, 0x23, 0xb4, 0xe9,
  44. 0x19, 0x56, 0x04, 0xfa, 0x0d, 0x07, 0x04, 0xb7, 0x43, 0xac, 0x4c, 0x49, 0x7c, 0xc2, 0xa1, 0x44,
  45. 0xc1, 0x48, 0x7d, 0x28, 0xe5, 0x23, 0x66, 0x07, 0x22, 0xd5, 0xf0, 0xf1, 0x02, 0x03, 0x01, 0x00,
  46. 0x01, 0xa3, 0x3b, 0x30, 0x39, 0x30, 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23, 0x04, 0x18, 0x30, 0x16,
  47. 0x80, 0x14, 0xdb, 0xbb, 0xb8, 0x92, 0x4e, 0x24, 0x0b, 0x1b, 0xbb, 0x78, 0x33, 0xf9, 0x01, 0x02,
  48. 0x23, 0x0d, 0x96, 0x18, 0x30, 0x47, 0x30, 0x09, 0x06, 0x03, 0x55, 0x1d, 0x13, 0x04, 0x02, 0x30,
  49. 0x00, 0x30, 0x0b, 0x06, 0x03, 0x55, 0x1d, 0x0f, 0x04, 0x04, 0x03, 0x02, 0x04, 0xf0, 0x30, 0x0d,
  50. 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03, 0x81, 0x81,
  51. 0x00, 0x1c, 0x13, 0xdc, 0x02, 0xf1, 0x44, 0x36, 0x65, 0xa9, 0xbe, 0x30, 0x1c, 0x66, 0x14, 0x20,
  52. 0x86, 0x5a, 0xa8, 0x69, 0x25, 0xf8, 0x1a, 0xb6, 0x9e, 0x5e, 0xe9, 0x89, 0xb8, 0x67, 0x70, 0x19,
  53. 0x87, 0x60, 0xeb, 0x4b, 0x11, 0x71, 0x85, 0xf8, 0xe9, 0xa7, 0x3e, 0x20, 0x42, 0xec, 0x43, 0x25,
  54. 0x01, 0x03, 0xe5, 0x4d, 0x83, 0x22, 0xf5, 0x8e, 0x3a, 0x1a, 0x1b, 0xd4, 0x1c, 0xda, 0x6b, 0x9d,
  55. 0x10, 0x1b, 0xee, 0x67, 0x4e, 0x1f, 0x69, 0xab, 0xbc, 0xaa, 0x62, 0x8e, 0x9e, 0xc6, 0xee, 0xd6,
  56. 0x09, 0xc0, 0xca, 0xe0, 0xaa, 0x9f, 0x07, 0xb2, 0xc2, 0xbb, 0x31, 0x96, 0xa2, 0x04, 0x62, 0xd3,
  57. 0x13, 0x32, 0x29, 0x67, 0x6e, 0xad, 0x2e, 0x0b, 0xea, 0x04, 0x7c, 0x8c, 0x5a, 0x5d, 0xac, 0x14,
  58. 0xaa, 0x61, 0x7f, 0x28, 0x6c, 0x2d, 0x64, 0x2d, 0xc3, 0xaf, 0x77, 0x52, 0x90, 0xb4, 0x37, 0xc0,
  59. 0x30,
  60. };
  61. static const unsigned char CERT2[] =
  62. {
  63. 0x30, 0x82, 0x01, 0xed, 0x30, 0x82, 0x01, 0x56, 0xa0, 0x03, 0x02, 0x01, 0x02, 0x02, 0x09, 0x00,
  64. 0x8b, 0x4b, 0x5e, 0x6c, 0x03, 0x28, 0x4e, 0xe7, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86,
  65. 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x30, 0x19, 0x31, 0x17, 0x30, 0x15, 0x06, 0x03, 0x55,
  66. 0x04, 0x03, 0x0c, 0x0e, 0x50, 0x31, 0x32, 0x54, 0x65, 0x73, 0x74, 0x2d, 0x52, 0x6f, 0x6f, 0x74,
  67. 0x2d, 0x41, 0x30, 0x1e, 0x17, 0x0d, 0x31, 0x39, 0x30, 0x39, 0x33, 0x30, 0x30, 0x30, 0x34, 0x36,
  68. 0x35, 0x36, 0x5a, 0x17, 0x0d, 0x32, 0x39, 0x30, 0x39, 0x32, 0x37, 0x30, 0x30, 0x34, 0x36, 0x35,
  69. 0x36, 0x5a, 0x30, 0x1b, 0x31, 0x19, 0x30, 0x17, 0x06, 0x03, 0x55, 0x04, 0x03, 0x0c, 0x10, 0x50,
  70. 0x31, 0x32, 0x54, 0x65, 0x73, 0x74, 0x2d, 0x43, 0x6c, 0x69, 0x65, 0x6e, 0x74, 0x2d, 0x31, 0x30,
  71. 0x81, 0x9f, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x01, 0x05,
  72. 0x00, 0x03, 0x81, 0x8d, 0x00, 0x30, 0x81, 0x89, 0x02, 0x81, 0x81, 0x00, 0xa8, 0x6e, 0x40, 0x86,
  73. 0x9f, 0x98, 0x59, 0xfb, 0x57, 0xbf, 0xc1, 0x55, 0x12, 0x38, 0xeb, 0xb3, 0x46, 0x34, 0xc9, 0x35,
  74. 0x4d, 0xfd, 0x03, 0xe9, 0x3a, 0x88, 0x9e, 0x97, 0x8f, 0xf4, 0xec, 0x36, 0x7b, 0x3f, 0xba, 0xb8,
  75. 0xa5, 0x96, 0x30, 0x03, 0xc5, 0xc6, 0xd9, 0xa8, 0x4e, 0xbc, 0x23, 0x51, 0xa1, 0x96, 0xd2, 0x03,
  76. 0x98, 0x73, 0xb6, 0x17, 0x9c, 0x77, 0xd4, 0x95, 0x1e, 0x1b, 0xb3, 0x1b, 0xc8, 0x71, 0xd1, 0x2e,
  77. 0x31, 0xc7, 0x6a, 0x75, 0x57, 0x08, 0x7f, 0xba, 0x70, 0x76, 0xf7, 0x67, 0xf4, 0x4e, 0xbe, 0xfc,
  78. 0x70, 0x61, 0x41, 0x07, 0x2b, 0x7c, 0x3c, 0x3b, 0xb3, 0xbc, 0xd5, 0xa8, 0xbd, 0x28, 0xd8, 0x49,
  79. 0xd3, 0xe1, 0x78, 0xc8, 0xc1, 0x42, 0x5e, 0x18, 0x36, 0xa8, 0x41, 0xf7, 0xc8, 0xaa, 0x35, 0xfe,
  80. 0x2d, 0xd1, 0xb4, 0xcc, 0x00, 0x67, 0xae, 0x79, 0xd3, 0x28, 0xd5, 0x5b, 0x02, 0x03, 0x01, 0x00,
  81. 0x01, 0xa3, 0x3b, 0x30, 0x39, 0x30, 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23, 0x04, 0x18, 0x30, 0x16,
  82. 0x80, 0x14, 0xdb, 0xbb, 0xb8, 0x92, 0x4e, 0x24, 0x0b, 0x1b, 0xbb, 0x78, 0x33, 0xf9, 0x01, 0x02,
  83. 0x23, 0x0d, 0x96, 0x18, 0x30, 0x47, 0x30, 0x09, 0x06, 0x03, 0x55, 0x1d, 0x13, 0x04, 0x02, 0x30,
  84. 0x00, 0x30, 0x0b, 0x06, 0x03, 0x55, 0x1d, 0x0f, 0x04, 0x04, 0x03, 0x02, 0x04, 0xf0, 0x30, 0x0d,
  85. 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03, 0x81, 0x81,
  86. 0x00, 0x3b, 0xa6, 0x73, 0xbe, 0xe0, 0x28, 0xed, 0x1f, 0x29, 0x78, 0x4c, 0xc0, 0x1f, 0xe9, 0x85,
  87. 0xc6, 0x8f, 0xe3, 0x87, 0x7c, 0xd9, 0xe7, 0x0a, 0x37, 0xe8, 0xaa, 0xb5, 0xd2, 0x7f, 0xf8, 0x90,
  88. 0x20, 0x80, 0x35, 0xa7, 0x79, 0x2b, 0x04, 0xa7, 0xbf, 0xe6, 0x7b, 0x58, 0xcb, 0xec, 0x0e, 0x58,
  89. 0xef, 0x2a, 0x70, 0x8a, 0x56, 0x8a, 0xcf, 0x6b, 0x7a, 0x74, 0x0c, 0xf4, 0x15, 0x37, 0x93, 0xcd,
  90. 0xe6, 0xb2, 0xa1, 0x83, 0x09, 0xdb, 0x9e, 0x4f, 0xff, 0x6a, 0x17, 0x4f, 0x33, 0xc9, 0xcc, 0x90,
  91. 0x2a, 0x67, 0xff, 0x16, 0x78, 0xa8, 0x2c, 0x10, 0xe0, 0x52, 0x8c, 0xe6, 0xe9, 0x90, 0x8d, 0xe0,
  92. 0x62, 0x04, 0x9a, 0x0f, 0x44, 0x01, 0x82, 0x14, 0x92, 0x44, 0x25, 0x69, 0x22, 0xb7, 0xb8, 0xc5,
  93. 0x94, 0x4c, 0x4b, 0x1c, 0x9b, 0x92, 0x60, 0x66, 0x90, 0x4e, 0xb9, 0xa8, 0x4c, 0x89, 0xbb, 0x0f,
  94. 0x0b,
  95. };
  96. static const unsigned char KEY1[] =
  97. {
  98. 0x30, 0x82, 0x02, 0x5d, 0x02, 0x01, 0x00, 0x02, 0x81, 0x81, 0x00, 0xbc, 0xdc, 0x6f, 0x8c, 0x7a,
  99. 0x2a, 0x4b, 0xea, 0x66, 0x66, 0x04, 0xa9, 0x05, 0x92, 0x53, 0xd7, 0x13, 0x3c, 0x49, 0xe1, 0xc8,
  100. 0xbb, 0xdf, 0x3d, 0xcb, 0x88, 0x31, 0x07, 0x20, 0x59, 0x93, 0x24, 0x7f, 0x7d, 0xc6, 0x84, 0x81,
  101. 0x16, 0x64, 0x4a, 0x52, 0xa6, 0x30, 0x44, 0xdc, 0x1a, 0x30, 0xde, 0xae, 0x29, 0x18, 0xcf, 0xc7,
  102. 0xf3, 0xcf, 0x0c, 0xb7, 0x8e, 0x2b, 0x1e, 0x21, 0x01, 0x0b, 0xfb, 0xe5, 0xe6, 0xcf, 0x2b, 0x84,
  103. 0xe1, 0x33, 0xf8, 0xba, 0x02, 0xfc, 0x30, 0xfa, 0xc4, 0x33, 0xc7, 0x37, 0xc6, 0x7f, 0x72, 0x31,
  104. 0x92, 0x1d, 0x8f, 0xa0, 0xfb, 0xe5, 0x4a, 0x08, 0x31, 0x78, 0x80, 0x9c, 0x23, 0xb4, 0xe9, 0x19,
  105. 0x56, 0x04, 0xfa, 0x0d, 0x07, 0x04, 0xb7, 0x43, 0xac, 0x4c, 0x49, 0x7c, 0xc2, 0xa1, 0x44, 0xc1,
  106. 0x48, 0x7d, 0x28, 0xe5, 0x23, 0x66, 0x07, 0x22, 0xd5, 0xf0, 0xf1, 0x02, 0x03, 0x01, 0x00, 0x01,
  107. 0x02, 0x81, 0x81, 0x00, 0xa5, 0x6d, 0xf9, 0x8f, 0xf5, 0x5a, 0xa3, 0x50, 0xd9, 0x0d, 0x37, 0xbb,
  108. 0xce, 0x13, 0x94, 0xb8, 0xea, 0x32, 0x7f, 0x0c, 0xf5, 0x46, 0x0b, 0x90, 0x17, 0x7e, 0x5e, 0x63,
  109. 0xbd, 0xa4, 0x78, 0xcd, 0x19, 0x97, 0xd4, 0x92, 0x30, 0x78, 0xaa, 0xb4, 0xa7, 0x9c, 0xc6, 0xdf,
  110. 0x2a, 0x65, 0x0e, 0xb5, 0x9f, 0x9c, 0x84, 0x0d, 0x4d, 0x3a, 0x74, 0xfc, 0xd0, 0xb4, 0x09, 0x74,
  111. 0xc4, 0xb8, 0x24, 0x03, 0xa8, 0xf0, 0xf8, 0x0d, 0x5c, 0x8e, 0xdf, 0x4b, 0xe1, 0x0a, 0x8f, 0x4f,
  112. 0xd5, 0xc7, 0x9b, 0x54, 0x55, 0x8f, 0x00, 0x5c, 0xea, 0x4c, 0x73, 0xf9, 0x1b, 0xbf, 0xb8, 0x93,
  113. 0x33, 0x20, 0xce, 0x45, 0xd9, 0x03, 0x02, 0xb2, 0x36, 0xc5, 0x0a, 0x30, 0x50, 0x78, 0x80, 0x66,
  114. 0x00, 0x22, 0x38, 0x86, 0xcf, 0x63, 0x4a, 0x5c, 0xbf, 0x2b, 0xd9, 0x6e, 0xe6, 0xf0, 0x39, 0xad,
  115. 0x12, 0x25, 0x41, 0xb9, 0x02, 0x41, 0x00, 0xf3, 0x7c, 0x07, 0x99, 0x64, 0x3a, 0x28, 0x8c, 0x8d,
  116. 0x05, 0xfe, 0x32, 0xb5, 0x4c, 0x8c, 0x6d, 0xde, 0x3d, 0x16, 0x08, 0xa0, 0x01, 0x61, 0x4f, 0x8e,
  117. 0xa0, 0xf7, 0x26, 0x26, 0xb5, 0x8e, 0xc0, 0x7a, 0xce, 0x86, 0x34, 0xde, 0xb8, 0xef, 0x86, 0x01,
  118. 0xbe, 0x24, 0xaa, 0x9b, 0x36, 0x93, 0x72, 0x9b, 0xf9, 0xc6, 0xcb, 0x76, 0x84, 0x67, 0x06, 0x06,
  119. 0x30, 0x50, 0xdf, 0x42, 0x17, 0xe0, 0xa7, 0x02, 0x41, 0x00, 0xc6, 0x91, 0xa0, 0x41, 0x34, 0x11,
  120. 0x67, 0x4b, 0x08, 0x0f, 0xda, 0xa7, 0x99, 0xec, 0x58, 0x11, 0xa5, 0x82, 0xdb, 0x50, 0xfe, 0x77,
  121. 0xe2, 0xd1, 0x53, 0x9c, 0x7d, 0xe8, 0xbf, 0xe7, 0x7c, 0xa9, 0x01, 0xb1, 0x87, 0xc3, 0x52, 0x79,
  122. 0x9e, 0x2c, 0xa7, 0x6f, 0x02, 0x37, 0x32, 0xef, 0x24, 0x31, 0x21, 0x0b, 0x86, 0x05, 0x32, 0x4a,
  123. 0x2e, 0x0b, 0x65, 0x05, 0xd3, 0xd6, 0x30, 0xb2, 0xfc, 0xa7, 0x02, 0x41, 0x00, 0xc2, 0xed, 0x31,
  124. 0xdc, 0x40, 0x9c, 0x3a, 0xe8, 0x42, 0xe2, 0x60, 0x5e, 0x52, 0x3c, 0xc5, 0x54, 0x14, 0x0e, 0x8d,
  125. 0x7c, 0x3c, 0x34, 0xbe, 0xa6, 0x05, 0x86, 0xa2, 0x36, 0x5d, 0xd9, 0x0e, 0x3e, 0xd4, 0x52, 0x50,
  126. 0xa9, 0x35, 0x01, 0x93, 0x68, 0x92, 0x2e, 0x9a, 0x86, 0x27, 0x1a, 0xab, 0x32, 0x9e, 0xe2, 0x79,
  127. 0x9f, 0x5b, 0xf3, 0xa5, 0xd2, 0xf1, 0xd3, 0x6e, 0x7b, 0x3e, 0x1b, 0x85, 0x93, 0x02, 0x40, 0x68,
  128. 0xb8, 0xb6, 0x7e, 0x8c, 0xba, 0x3c, 0xf2, 0x8a, 0x2e, 0xea, 0x4f, 0x07, 0xd3, 0x68, 0x62, 0xee,
  129. 0x1a, 0x04, 0x16, 0x44, 0x0d, 0xef, 0xf6, 0x1b, 0x95, 0x65, 0xa5, 0xd1, 0x47, 0x81, 0x2c, 0x14,
  130. 0xb3, 0x8e, 0xf9, 0x08, 0xcf, 0x11, 0x07, 0x55, 0xca, 0x2a, 0xad, 0xf7, 0xd3, 0xbd, 0x0f, 0x97,
  131. 0xf0, 0xde, 0xde, 0x70, 0xb6, 0x44, 0x70, 0x47, 0xf7, 0xf9, 0xcf, 0x75, 0x61, 0x7f, 0xf3, 0x02,
  132. 0x40, 0x38, 0x4a, 0x67, 0xaf, 0xae, 0xb6, 0xb2, 0x6a, 0x00, 0x25, 0x5a, 0xa4, 0x65, 0x20, 0xb1,
  133. 0x13, 0xbd, 0x83, 0xff, 0xb4, 0xbc, 0xf4, 0xdd, 0xa1, 0xbb, 0x1c, 0x96, 0x37, 0x35, 0xf4, 0xbf,
  134. 0xed, 0x4c, 0xed, 0x92, 0xe8, 0xac, 0xc9, 0xc1, 0xa5, 0xa3, 0x23, 0x66, 0x40, 0x8a, 0xa1, 0xe6,
  135. 0xe3, 0x95, 0xfe, 0xc4, 0x53, 0xf5, 0x7d, 0x6e, 0xca, 0x45, 0x42, 0xe4, 0xc2, 0x9f, 0xe5, 0x1e,
  136. 0xb5,
  137. };
  138. static const unsigned char KEY2[] =
  139. {
  140. 0x30, 0x82, 0x02, 0x5c, 0x02, 0x01, 0x00, 0x02, 0x81, 0x81, 0x00, 0xa8, 0x6e, 0x40, 0x86, 0x9f,
  141. 0x98, 0x59, 0xfb, 0x57, 0xbf, 0xc1, 0x55, 0x12, 0x38, 0xeb, 0xb3, 0x46, 0x34, 0xc9, 0x35, 0x4d,
  142. 0xfd, 0x03, 0xe9, 0x3a, 0x88, 0x9e, 0x97, 0x8f, 0xf4, 0xec, 0x36, 0x7b, 0x3f, 0xba, 0xb8, 0xa5,
  143. 0x96, 0x30, 0x03, 0xc5, 0xc6, 0xd9, 0xa8, 0x4e, 0xbc, 0x23, 0x51, 0xa1, 0x96, 0xd2, 0x03, 0x98,
  144. 0x73, 0xb6, 0x17, 0x9c, 0x77, 0xd4, 0x95, 0x1e, 0x1b, 0xb3, 0x1b, 0xc8, 0x71, 0xd1, 0x2e, 0x31,
  145. 0xc7, 0x6a, 0x75, 0x57, 0x08, 0x7f, 0xba, 0x70, 0x76, 0xf7, 0x67, 0xf4, 0x4e, 0xbe, 0xfc, 0x70,
  146. 0x61, 0x41, 0x07, 0x2b, 0x7c, 0x3c, 0x3b, 0xb3, 0xbc, 0xd5, 0xa8, 0xbd, 0x28, 0xd8, 0x49, 0xd3,
  147. 0xe1, 0x78, 0xc8, 0xc1, 0x42, 0x5e, 0x18, 0x36, 0xa8, 0x41, 0xf7, 0xc8, 0xaa, 0x35, 0xfe, 0x2d,
  148. 0xd1, 0xb4, 0xcc, 0x00, 0x67, 0xae, 0x79, 0xd3, 0x28, 0xd5, 0x5b, 0x02, 0x03, 0x01, 0x00, 0x01,
  149. 0x02, 0x81, 0x81, 0x00, 0xa6, 0x00, 0x83, 0xf8, 0x2b, 0x33, 0xac, 0xfb, 0xdb, 0xf0, 0x52, 0x4b,
  150. 0xd6, 0x39, 0xe3, 0x94, 0x3d, 0x8d, 0xa9, 0x01, 0xb0, 0x6b, 0xbe, 0x7f, 0x10, 0x01, 0xb6, 0xcd,
  151. 0x0a, 0x45, 0x0a, 0xca, 0x67, 0x8e, 0xd8, 0x29, 0x44, 0x8a, 0x51, 0xa8, 0x66, 0x35, 0x26, 0x30,
  152. 0x8b, 0xe9, 0x41, 0xa6, 0x22, 0xec, 0xd2, 0xf0, 0x58, 0x41, 0x33, 0x26, 0xf2, 0x3f, 0xe8, 0x75,
  153. 0x4f, 0xc7, 0x5d, 0x2e, 0x5a, 0xa8, 0x7a, 0xd2, 0xbf, 0x59, 0xa0, 0x86, 0x79, 0x0b, 0x92, 0x6c,
  154. 0x95, 0x5d, 0x87, 0x63, 0x5c, 0xd6, 0x1a, 0xc0, 0xf6, 0x7a, 0x15, 0x8d, 0xc7, 0x3c, 0xb6, 0x9e,
  155. 0xa6, 0x58, 0x46, 0x9b, 0xbf, 0x3e, 0x28, 0x8c, 0xdf, 0x1a, 0x87, 0xaa, 0x7e, 0xf5, 0xf2, 0xcb,
  156. 0x5e, 0x84, 0x2d, 0xf6, 0x82, 0x7e, 0x89, 0x4e, 0xf5, 0xe6, 0x3c, 0x92, 0x80, 0x1e, 0x98, 0x1c,
  157. 0x6a, 0x7b, 0x57, 0x01, 0x02, 0x41, 0x00, 0xdd, 0x60, 0x95, 0xd7, 0xa1, 0x9d, 0x0c, 0xa1, 0x84,
  158. 0xc5, 0x39, 0xca, 0x67, 0x4c, 0x1c, 0x06, 0x71, 0x5b, 0x5c, 0x2d, 0x8d, 0xce, 0xcd, 0xe2, 0x79,
  159. 0xc8, 0x33, 0xbe, 0x50, 0x37, 0x60, 0x9f, 0x3b, 0xb9, 0x59, 0x55, 0x22, 0x1f, 0xa5, 0x4b, 0x1d,
  160. 0xca, 0x38, 0xa0, 0xab, 0x87, 0x9c, 0x86, 0x0e, 0xdb, 0x1c, 0x4f, 0x4f, 0x07, 0xed, 0x18, 0x3f,
  161. 0x05, 0x3c, 0xec, 0x78, 0x11, 0xf6, 0x99, 0x02, 0x41, 0x00, 0xc2, 0xc5, 0xcf, 0xbe, 0x95, 0x91,
  162. 0xeb, 0xcf, 0x47, 0xf3, 0x33, 0x32, 0xc7, 0x7e, 0x93, 0x56, 0xf7, 0xd8, 0xf9, 0xd4, 0xb6, 0xd6,
  163. 0x20, 0xac, 0xba, 0x8a, 0x20, 0x19, 0x14, 0xab, 0xc5, 0x5d, 0xb2, 0x08, 0xcc, 0x77, 0x7c, 0x65,
  164. 0xa8, 0xdb, 0x66, 0x97, 0x36, 0x44, 0x2c, 0x63, 0xc0, 0x6a, 0x7e, 0xb0, 0x0b, 0x5c, 0x90, 0x12,
  165. 0x50, 0xb4, 0x36, 0x60, 0xc3, 0x1f, 0x22, 0x0c, 0xc8, 0x13, 0x02, 0x40, 0x33, 0xc8, 0x7e, 0x04,
  166. 0x7c, 0x97, 0x61, 0xf6, 0xfe, 0x39, 0xac, 0x34, 0xfe, 0x48, 0xbd, 0x5d, 0x7c, 0x72, 0xa4, 0x73,
  167. 0x3b, 0x72, 0x9e, 0x92, 0x55, 0x6e, 0x51, 0x3c, 0x39, 0x43, 0x5a, 0xe4, 0xa4, 0x71, 0xcc, 0xc5,
  168. 0xaf, 0x3f, 0xbb, 0xc8, 0x80, 0x65, 0x67, 0x2d, 0x9e, 0x32, 0x10, 0x99, 0x03, 0x2c, 0x99, 0xc8,
  169. 0xab, 0x71, 0xed, 0x31, 0xf8, 0xbb, 0xde, 0xee, 0x69, 0x7f, 0xba, 0x31, 0x02, 0x40, 0x7e, 0xbc,
  170. 0x60, 0x55, 0x4e, 0xd5, 0xc8, 0x6e, 0xf4, 0x0e, 0x57, 0xbe, 0x2e, 0xf9, 0x39, 0xbe, 0x59, 0x3f,
  171. 0xa2, 0x30, 0xbb, 0x57, 0xd1, 0xa3, 0x13, 0x2e, 0x55, 0x7c, 0x7c, 0x6a, 0xd8, 0xde, 0x02, 0xbe,
  172. 0x9e, 0xed, 0x10, 0xd0, 0xc5, 0x73, 0x1d, 0xea, 0x3e, 0xb1, 0x55, 0x81, 0x02, 0xef, 0x48, 0xc8,
  173. 0x1c, 0x5c, 0x7a, 0x92, 0xb0, 0x58, 0xd3, 0x19, 0x5b, 0x5d, 0xa2, 0xb6, 0x56, 0x69, 0x02, 0x40,
  174. 0x1e, 0x00, 0x6a, 0x9f, 0xba, 0xee, 0x46, 0x5a, 0xc5, 0xb5, 0x9f, 0x91, 0x33, 0xdd, 0xc9, 0x96,
  175. 0x75, 0xb7, 0x87, 0xcf, 0x18, 0x1c, 0xb7, 0xb9, 0x3f, 0x04, 0x10, 0xb8, 0x75, 0xa9, 0xb8, 0xa0,
  176. 0x31, 0x35, 0x03, 0x30, 0x89, 0xc8, 0x37, 0x68, 0x20, 0x30, 0x99, 0x39, 0x96, 0xd6, 0x2b, 0x3d,
  177. 0x5e, 0x45, 0x84, 0xf7, 0xd2, 0x61, 0x50, 0xc9, 0x50, 0xba, 0x8d, 0x08, 0xaa, 0xd0, 0x08, 0x1e,
  178. };
  179. static const PKCS12_ATTR ATTRS1[] = {
  180. { "friendlyName", "george" },
  181. { "localKeyID", "1234567890" },
  182. { "1.2.3.4.5", "MyCustomAttribute" },
  183. { NULL, NULL }
  184. };
  185. static const PKCS12_ATTR ATTRS2[] = {
  186. { "friendlyName", "janet" },
  187. { "localKeyID", "987654321" },
  188. { "1.2.3.5.8.13", "AnotherCustomAttribute" },
  189. { NULL, NULL }
  190. };
  191. static const PKCS12_ATTR ATTRS3[] = {
  192. { "friendlyName", "wildduk" },
  193. { "localKeyID", "1122334455" },
  194. { "oracle-jdk-trustedkeyusage", "anyExtendedKeyUsage" },
  195. { NULL, NULL }
  196. };
  197. static const PKCS12_ATTR ATTRS4[] = {
  198. { "friendlyName", "wildduk" },
  199. { "localKeyID", "1122334455" },
  200. { NULL, NULL }
  201. };
  202. static const PKCS12_ENC enc_default = {
  203. #ifndef OPENSSL_NO_DES
  204. NID_pbe_WithSHA1And3_Key_TripleDES_CBC,
  205. #else
  206. NID_aes_128_cbc,
  207. #endif
  208. "Password1",
  209. 1000
  210. };
  211. static const PKCS12_ENC mac_default = {
  212. NID_sha1,
  213. "Password1",
  214. 1000
  215. };
  216. static const int enc_nids_all[] = {
  217. /* NOTE: To use PBES2 we pass the desired cipher NID instead of NID_pbes2 */
  218. NID_aes_128_cbc,
  219. NID_aes_256_cbc,
  220. #ifndef OPENSSL_NO_DES
  221. NID_des_ede3_cbc,
  222. NID_des_cbc,
  223. #endif
  224. #ifndef OPENSSL_NO_RC5
  225. NID_rc5_cbc,
  226. #endif
  227. #ifndef OPENSSL_NO_RC4
  228. NID_rc4,
  229. #endif
  230. #ifndef OPENSSL_NO_RC2
  231. NID_rc2_cbc,
  232. #endif
  233. #ifndef OPENSSL_NO_MD2
  234. # ifndef OPENSSL_NO_DES
  235. NID_pbeWithMD2AndDES_CBC,
  236. # endif
  237. # ifndef OPENSSL_NO_RC2
  238. NID_pbeWithMD2AndRC2_CBC,
  239. # endif
  240. #endif
  241. #ifndef OPENSSL_NO_MD5
  242. # ifndef OPENSSL_NO_DES
  243. NID_pbeWithMD5AndDES_CBC,
  244. # endif
  245. # ifndef OPENSSL_NO_RC2
  246. NID_pbeWithMD5AndRC2_CBC,
  247. # endif
  248. #endif
  249. #ifndef OPENSSL_NO_DES
  250. NID_pbeWithSHA1AndDES_CBC,
  251. #endif
  252. #ifndef OPENSSL_NO_RC2
  253. NID_pbe_WithSHA1And128BitRC2_CBC,
  254. NID_pbe_WithSHA1And40BitRC2_CBC,
  255. NID_pbeWithSHA1AndRC2_CBC,
  256. #endif
  257. #ifndef OPENSSL_NO_RC4
  258. NID_pbe_WithSHA1And128BitRC4,
  259. NID_pbe_WithSHA1And40BitRC4,
  260. #endif
  261. #ifndef OPENSSL_NO_DES
  262. NID_pbe_WithSHA1And2_Key_TripleDES_CBC,
  263. NID_pbe_WithSHA1And3_Key_TripleDES_CBC,
  264. #endif
  265. };
  266. static const int enc_nids_no_legacy[] = {
  267. /* NOTE: To use PBES2 we pass the desired cipher NID instead of NID_pbes2 */
  268. NID_aes_128_cbc,
  269. NID_aes_256_cbc,
  270. #ifndef OPENSSL_NO_DES
  271. NID_des_ede3_cbc,
  272. NID_pbe_WithSHA1And2_Key_TripleDES_CBC,
  273. NID_pbe_WithSHA1And3_Key_TripleDES_CBC,
  274. #endif
  275. };
  276. static const int mac_nids[] = {
  277. NID_sha1,
  278. NID_md5,
  279. NID_sha256,
  280. NID_sha512,
  281. NID_sha3_256,
  282. NID_sha3_512
  283. };
  284. static const int iters[] = {
  285. 1,
  286. 1000
  287. };
  288. static const char *passwords[] = {
  289. "Password1",
  290. "",
  291. };
  292. /* --------------------------------------------------------------------------
  293. * Local functions
  294. */
  295. static int get_custom_oid(void)
  296. {
  297. static int sec_nid = -1;
  298. if (sec_nid != -1)
  299. return sec_nid;
  300. if (!TEST_true(OBJ_create("1.3.5.7.9", "CustomSecretOID", "My custom secret OID")))
  301. return -1;
  302. return sec_nid = OBJ_txt2nid("CustomSecretOID");
  303. }
  304. /* --------------------------------------------------------------------------
  305. * PKCS12 format tests
  306. */
  307. static int test_single_cert_no_attrs(void)
  308. {
  309. PKCS12_BUILDER *pb = new_pkcs12_builder("1cert.p12");
  310. /* Generate/encode */
  311. start_pkcs12(pb);
  312. start_contentinfo(pb);
  313. add_certbag(pb, CERT1, sizeof(CERT1), NULL);
  314. end_contentinfo(pb);
  315. end_pkcs12(pb);
  316. /* Read/decode */
  317. start_check_pkcs12(pb);
  318. start_check_contentinfo(pb);
  319. check_certbag(pb, CERT1, sizeof(CERT1), NULL);
  320. end_check_contentinfo(pb);
  321. end_check_pkcs12(pb);
  322. return end_pkcs12_builder(pb);
  323. }
  324. static int test_single_key(PKCS12_ENC *enc)
  325. {
  326. char fname[80];
  327. PKCS12_BUILDER *pb;
  328. sprintf(fname, "1key_ciph-%s_iter-%d.p12", OBJ_nid2sn(enc->nid), enc->iter);
  329. pb = new_pkcs12_builder(fname);
  330. /* Generate/encode */
  331. start_pkcs12(pb);
  332. start_contentinfo(pb);
  333. add_keybag(pb, KEY1, sizeof(KEY1), NULL, enc);
  334. end_contentinfo(pb);
  335. end_pkcs12(pb);
  336. /* Read/decode */
  337. start_check_pkcs12(pb);
  338. start_check_contentinfo(pb);
  339. check_keybag(pb, KEY1, sizeof(KEY1), NULL, enc);
  340. end_check_contentinfo(pb);
  341. end_check_pkcs12(pb);
  342. return end_pkcs12_builder(pb);
  343. }
  344. static int test_single_key_enc_alg(int z)
  345. {
  346. PKCS12_ENC enc;
  347. if (lgcyprov == NULL)
  348. enc.nid = enc_nids_no_legacy[z];
  349. else
  350. enc.nid = enc_nids_all[z];
  351. enc.pass = enc_default.pass;
  352. enc.iter = enc_default.iter;
  353. return test_single_key(&enc);
  354. }
  355. static int test_single_key_enc_pass(int z)
  356. {
  357. PKCS12_ENC enc;
  358. enc.nid = enc_default.nid;
  359. enc.pass = passwords[z];
  360. enc.iter = enc_default.iter;
  361. return test_single_key(&enc);
  362. }
  363. static int test_single_key_enc_iter(int z)
  364. {
  365. PKCS12_ENC enc;
  366. enc.nid = enc_default.nid;
  367. enc.pass = enc_default.pass;
  368. enc.iter = iters[z];
  369. return test_single_key(&enc);
  370. }
  371. static int test_single_key_with_attrs(void)
  372. {
  373. PKCS12_BUILDER *pb = new_pkcs12_builder("1keyattrs.p12");
  374. /* Generate/encode */
  375. start_pkcs12(pb);
  376. start_contentinfo(pb);
  377. add_keybag(pb, KEY1, sizeof(KEY1), ATTRS1, &enc_default);
  378. end_contentinfo(pb);
  379. end_pkcs12(pb);
  380. /* Read/decode */
  381. start_check_pkcs12(pb);
  382. start_check_contentinfo(pb);
  383. check_keybag(pb, KEY1, sizeof(KEY1), ATTRS1, &enc_default);
  384. end_check_contentinfo(pb);
  385. end_check_pkcs12(pb);
  386. return end_pkcs12_builder(pb);
  387. }
  388. static int test_single_cert_mac(PKCS12_ENC *mac)
  389. {
  390. char fname[80];
  391. PKCS12_BUILDER *pb;
  392. sprintf(fname, "1cert_mac-%s_iter-%d.p12", OBJ_nid2sn(mac->nid), mac->iter);
  393. pb = new_pkcs12_builder(fname);
  394. /* Generate/encode */
  395. start_pkcs12(pb);
  396. start_contentinfo(pb);
  397. add_certbag(pb, CERT1, sizeof(CERT1), NULL);
  398. end_contentinfo(pb);
  399. end_pkcs12_with_mac(pb, mac);
  400. /* Read/decode */
  401. start_check_pkcs12_with_mac(pb, mac);
  402. start_check_contentinfo(pb);
  403. check_certbag(pb, CERT1, sizeof(CERT1), NULL);
  404. end_check_contentinfo(pb);
  405. end_check_pkcs12(pb);
  406. return end_pkcs12_builder(pb);
  407. }
  408. static int test_single_cert_mac_alg(int z)
  409. {
  410. PKCS12_ENC mac;
  411. mac.nid = mac_nids[z];
  412. mac.pass = mac_default.pass;
  413. mac.iter = mac_default.iter;
  414. return test_single_cert_mac(&mac);
  415. }
  416. static int test_single_cert_mac_pass(int z)
  417. {
  418. PKCS12_ENC mac;
  419. mac.nid = mac_default.nid;
  420. mac.pass = passwords[z];
  421. mac.iter = mac_default.iter;
  422. return test_single_cert_mac(&mac);
  423. }
  424. static int test_single_cert_mac_iter(int z)
  425. {
  426. PKCS12_ENC mac;
  427. mac.nid = mac_default.nid;
  428. mac.pass = mac_default.pass;
  429. mac.iter = iters[z];
  430. return test_single_cert_mac(&mac);
  431. }
  432. static int test_cert_key_with_attrs_and_mac(void)
  433. {
  434. PKCS12_BUILDER *pb = new_pkcs12_builder("1cert1key.p12");
  435. /* Generate/encode */
  436. start_pkcs12(pb);
  437. start_contentinfo(pb);
  438. add_certbag(pb, CERT1, sizeof(CERT1), ATTRS1);
  439. add_keybag(pb, KEY1, sizeof(KEY1), ATTRS1, &enc_default);
  440. end_contentinfo(pb);
  441. end_pkcs12_with_mac(pb, &mac_default);
  442. /* Read/decode */
  443. start_check_pkcs12_with_mac(pb, &mac_default);
  444. start_check_contentinfo(pb);
  445. check_certbag(pb, CERT1, sizeof(CERT1), ATTRS1);
  446. check_keybag(pb, KEY1, sizeof(KEY1), ATTRS1, &enc_default);
  447. end_check_contentinfo(pb);
  448. end_check_pkcs12(pb);
  449. return end_pkcs12_builder(pb);
  450. }
  451. static int test_cert_key_encrypted_content(void)
  452. {
  453. PKCS12_BUILDER *pb = new_pkcs12_builder("1cert1key_enc.p12");
  454. /* Generate/encode */
  455. start_pkcs12(pb);
  456. start_contentinfo(pb);
  457. add_certbag(pb, CERT1, sizeof(CERT1), ATTRS1);
  458. add_keybag(pb, KEY1, sizeof(KEY1), ATTRS1, &enc_default);
  459. end_contentinfo_encrypted(pb, &enc_default);
  460. end_pkcs12_with_mac(pb, &mac_default);
  461. /* Read/decode */
  462. start_check_pkcs12_with_mac(pb, &mac_default);
  463. start_check_contentinfo_encrypted(pb, &enc_default);
  464. check_certbag(pb, CERT1, sizeof(CERT1), ATTRS1);
  465. check_keybag(pb, KEY1, sizeof(KEY1), ATTRS1, &enc_default);
  466. end_check_contentinfo(pb);
  467. end_check_pkcs12(pb);
  468. return end_pkcs12_builder(pb);
  469. }
  470. static int test_single_secret_encrypted_content(void)
  471. {
  472. PKCS12_BUILDER *pb = new_pkcs12_builder("1secret.p12");
  473. int custom_nid = get_custom_oid();
  474. /* Generate/encode */
  475. start_pkcs12(pb);
  476. start_contentinfo(pb);
  477. add_secretbag(pb, custom_nid, "VerySecretMessage", ATTRS1);
  478. end_contentinfo_encrypted(pb, &enc_default);
  479. end_pkcs12_with_mac(pb, &mac_default);
  480. /* Read/decode */
  481. start_check_pkcs12_with_mac(pb, &mac_default);
  482. start_check_contentinfo_encrypted(pb, &enc_default);
  483. check_secretbag(pb, custom_nid, "VerySecretMessage", ATTRS1);
  484. end_check_contentinfo(pb);
  485. end_check_pkcs12(pb);
  486. return end_pkcs12_builder(pb);
  487. }
  488. static int test_single_secret(PKCS12_ENC *enc)
  489. {
  490. int custom_nid;
  491. char fname[80];
  492. PKCS12_BUILDER *pb;
  493. sprintf(fname, "1secret_ciph-%s_iter-%d.p12", OBJ_nid2sn(enc->nid), enc->iter);
  494. pb = new_pkcs12_builder(fname);
  495. custom_nid = get_custom_oid();
  496. /* Generate/encode */
  497. start_pkcs12(pb);
  498. start_contentinfo(pb);
  499. add_secretbag(pb, custom_nid, "VerySecretMessage", ATTRS1);
  500. end_contentinfo_encrypted(pb, enc);
  501. end_pkcs12_with_mac(pb, &mac_default);
  502. /* Read/decode */
  503. start_check_pkcs12_with_mac(pb, &mac_default);
  504. start_check_contentinfo_encrypted(pb, enc);
  505. check_secretbag(pb, custom_nid, "VerySecretMessage", ATTRS1);
  506. end_check_contentinfo(pb);
  507. end_check_pkcs12(pb);
  508. return end_pkcs12_builder(pb);
  509. }
  510. static int test_single_secret_enc_alg(int z)
  511. {
  512. PKCS12_ENC enc;
  513. if (lgcyprov == NULL)
  514. enc.nid = enc_nids_no_legacy[z];
  515. else
  516. enc.nid = enc_nids_all[z];
  517. enc.pass = enc_default.pass;
  518. enc.iter = enc_default.iter;
  519. return test_single_secret(&enc);
  520. }
  521. static int test_multiple_contents(void)
  522. {
  523. PKCS12_BUILDER *pb = new_pkcs12_builder("multi_contents.p12");
  524. int custom_nid = get_custom_oid();
  525. /* Generate/encode */
  526. start_pkcs12(pb);
  527. start_contentinfo(pb);
  528. add_certbag(pb, CERT1, sizeof(CERT1), ATTRS1);
  529. add_certbag(pb, CERT2, sizeof(CERT2), ATTRS2);
  530. add_keybag(pb, KEY1, sizeof(KEY1), ATTRS1, &enc_default);
  531. add_keybag(pb, KEY2, sizeof(KEY2), ATTRS2, &enc_default);
  532. end_contentinfo(pb);
  533. start_contentinfo(pb);
  534. add_secretbag(pb, custom_nid, "VeryVerySecretMessage", ATTRS1);
  535. end_contentinfo_encrypted(pb, &enc_default);
  536. end_pkcs12_with_mac(pb, &mac_default);
  537. /* Read/decode */
  538. start_check_pkcs12_with_mac(pb, &mac_default);
  539. start_check_contentinfo(pb);
  540. check_certbag(pb, CERT1, sizeof(CERT1), ATTRS1);
  541. check_certbag(pb, CERT2, sizeof(CERT2), ATTRS2);
  542. check_keybag(pb, KEY1, sizeof(KEY1), ATTRS1, &enc_default);
  543. check_keybag(pb, KEY2, sizeof(KEY2), ATTRS2, &enc_default);
  544. end_check_contentinfo(pb);
  545. start_check_contentinfo_encrypted(pb, &enc_default);
  546. check_secretbag(pb, custom_nid, "VeryVerySecretMessage", ATTRS1);
  547. end_check_contentinfo(pb);
  548. end_check_pkcs12(pb);
  549. return end_pkcs12_builder(pb);
  550. }
  551. static int test_jdk_trusted_attr(void)
  552. {
  553. PKCS12_BUILDER *pb = new_pkcs12_builder("jdk_trusted.p12");
  554. /* Generate/encode */
  555. start_pkcs12(pb);
  556. start_contentinfo(pb);
  557. add_certbag(pb, CERT1, sizeof(CERT1), ATTRS3);
  558. end_contentinfo(pb);
  559. end_pkcs12_with_mac(pb, &mac_default);
  560. /* Read/decode */
  561. start_check_pkcs12_with_mac(pb, &mac_default);
  562. start_check_contentinfo(pb);
  563. check_certbag(pb, CERT1, sizeof(CERT1), ATTRS3);
  564. end_check_contentinfo(pb);
  565. end_check_pkcs12(pb);
  566. return end_pkcs12_builder(pb);
  567. }
  568. static int test_set0_attrs(void)
  569. {
  570. PKCS12_BUILDER *pb = new_pkcs12_builder("attrs.p12");
  571. PKCS12_SAFEBAG *bag = NULL;
  572. STACK_OF(X509_ATTRIBUTE) *attrs = NULL;
  573. X509_ATTRIBUTE *attr = NULL;
  574. start_pkcs12(pb);
  575. start_contentinfo(pb);
  576. /* Add cert and attrs (name/locakkey only) */
  577. add_certbag(pb, CERT1, sizeof(CERT1), ATTRS4);
  578. bag = sk_PKCS12_SAFEBAG_value(pb->bags, 0);
  579. attrs = (STACK_OF(X509_ATTRIBUTE)*)PKCS12_SAFEBAG_get0_attrs(bag);
  580. /* Create new attr, add to list and confirm return attrs is not NULL */
  581. attr = X509_ATTRIBUTE_create(NID_oracle_jdk_trustedkeyusage, V_ASN1_OBJECT, OBJ_txt2obj("anyExtendedKeyUsage", 0));
  582. X509at_add1_attr(&attrs, attr);
  583. PKCS12_SAFEBAG_set0_attrs(bag, attrs);
  584. attrs = (STACK_OF(X509_ATTRIBUTE)*)PKCS12_SAFEBAG_get0_attrs(bag);
  585. X509_ATTRIBUTE_free(attr);
  586. if(!TEST_ptr(attrs)) {
  587. goto err;
  588. }
  589. end_contentinfo(pb);
  590. end_pkcs12(pb);
  591. /* Read/decode */
  592. start_check_pkcs12(pb);
  593. start_check_contentinfo(pb);
  594. /* Use existing check functionality to confirm cert bag attrs identical to ATTRS3 */
  595. check_certbag(pb, CERT1, sizeof(CERT1), ATTRS3);
  596. end_check_contentinfo(pb);
  597. end_check_pkcs12(pb);
  598. return end_pkcs12_builder(pb);
  599. err:
  600. (void)end_pkcs12_builder(pb);
  601. return 0;
  602. }
  603. #ifndef OPENSSL_NO_DES
  604. static int pkcs12_create_test(void)
  605. {
  606. int ret = 0;
  607. EVP_PKEY *pkey = NULL;
  608. PKCS12 *p12 = NULL;
  609. const unsigned char *p;
  610. static const unsigned char rsa_key[] = {
  611. 0x30, 0x82, 0x02, 0x5d, 0x02, 0x01, 0x00, 0x02, 0x81, 0x81, 0x00, 0xbb,
  612. 0x24, 0x7a, 0x09, 0x7e, 0x0e, 0xb2, 0x37, 0x32, 0xcc, 0x39, 0x67, 0xad,
  613. 0xf1, 0x9e, 0x3d, 0x6b, 0x82, 0x83, 0xd1, 0xd0, 0xac, 0xa4, 0xc0, 0x18,
  614. 0xbe, 0x8d, 0x98, 0x00, 0xc0, 0x7b, 0xff, 0x07, 0x44, 0xc9, 0xca, 0x1c,
  615. 0xba, 0x36, 0xe1, 0x27, 0x69, 0xff, 0xb1, 0xe3, 0x8d, 0x8b, 0xee, 0x57,
  616. 0xa9, 0x3a, 0xaa, 0x16, 0x43, 0x39, 0x54, 0x19, 0x7c, 0xae, 0x69, 0x24,
  617. 0x14, 0xf6, 0x64, 0xff, 0xbc, 0x74, 0xc6, 0x67, 0x6c, 0x4c, 0xf1, 0x02,
  618. 0x49, 0x69, 0xc7, 0x2b, 0xe1, 0xe1, 0xa1, 0xa3, 0x43, 0x14, 0xf4, 0x77,
  619. 0x8f, 0xc8, 0xd0, 0x85, 0x5a, 0x35, 0x95, 0xac, 0x62, 0xa9, 0xc1, 0x21,
  620. 0x00, 0x77, 0xa0, 0x8b, 0x97, 0x30, 0xb4, 0x5a, 0x2c, 0xb8, 0x90, 0x2f,
  621. 0x48, 0xa0, 0x05, 0x28, 0x4b, 0xf2, 0x0f, 0x8d, 0xec, 0x8b, 0x4d, 0x03,
  622. 0x42, 0x75, 0xd6, 0xad, 0x81, 0xc0, 0x11, 0x02, 0x03, 0x01, 0x00, 0x01,
  623. 0x02, 0x81, 0x80, 0x00, 0xfc, 0xb9, 0x4a, 0x26, 0x07, 0x89, 0x51, 0x2b,
  624. 0x53, 0x72, 0x91, 0xe0, 0x18, 0x3e, 0xa6, 0x5e, 0x31, 0xef, 0x9c, 0x0c,
  625. 0x16, 0x24, 0x42, 0xd0, 0x28, 0x33, 0xf9, 0xfa, 0xd0, 0x3c, 0x54, 0x04,
  626. 0x06, 0xc0, 0x15, 0xf5, 0x1b, 0x9a, 0xb3, 0x24, 0x31, 0xab, 0x3c, 0x6b,
  627. 0x47, 0x43, 0xb0, 0xd2, 0xa9, 0xdc, 0x05, 0xe1, 0x81, 0x59, 0xb6, 0x04,
  628. 0xe9, 0x66, 0x61, 0xaa, 0xd7, 0x0b, 0x00, 0x8f, 0x3d, 0xe5, 0xbf, 0xa2,
  629. 0xf8, 0x5e, 0x25, 0x6c, 0x1e, 0x22, 0x0f, 0xb4, 0xfd, 0x41, 0xe2, 0x03,
  630. 0x31, 0x5f, 0xda, 0x20, 0xc5, 0xc0, 0xf3, 0x55, 0x0e, 0xe1, 0xc9, 0xec,
  631. 0xd7, 0x3e, 0x2a, 0x0c, 0x01, 0xca, 0x7b, 0x22, 0xcb, 0xac, 0xf4, 0x2b,
  632. 0x27, 0xf0, 0x78, 0x5f, 0xb5, 0xc2, 0xf9, 0xe8, 0x14, 0x5a, 0x6e, 0x7e,
  633. 0x86, 0xbd, 0x6a, 0x9b, 0x20, 0x0c, 0xba, 0xcc, 0x97, 0x20, 0x11, 0x02,
  634. 0x41, 0x00, 0xc9, 0x59, 0x9f, 0x29, 0x8a, 0x5b, 0x9f, 0xe3, 0x2a, 0xd8,
  635. 0x7e, 0xc2, 0x40, 0x9f, 0xa8, 0x45, 0xe5, 0x3e, 0x11, 0x8d, 0x3c, 0xed,
  636. 0x6e, 0xab, 0xce, 0xd0, 0x65, 0x46, 0xd8, 0xc7, 0x07, 0x63, 0xb5, 0x23,
  637. 0x34, 0xf4, 0x9f, 0x7e, 0x1c, 0xc7, 0xc7, 0xf9, 0x65, 0xd1, 0xf4, 0x04,
  638. 0x42, 0x38, 0xbe, 0x3a, 0x0c, 0x9d, 0x08, 0x25, 0xfc, 0xa3, 0x71, 0xd9,
  639. 0xae, 0x0c, 0x39, 0x61, 0xf4, 0x89, 0x02, 0x41, 0x00, 0xed, 0xef, 0xab,
  640. 0xa9, 0xd5, 0x39, 0x9c, 0xee, 0x59, 0x1b, 0xff, 0xcf, 0x48, 0x44, 0x1b,
  641. 0xb6, 0x32, 0xe7, 0x46, 0x24, 0xf3, 0x04, 0x7f, 0xde, 0x95, 0x08, 0x6d,
  642. 0x75, 0x9e, 0x67, 0x17, 0xba, 0x5c, 0xa4, 0xd4, 0xe2, 0xe2, 0x4d, 0x77,
  643. 0xce, 0xeb, 0x66, 0x29, 0xc5, 0x96, 0xe0, 0x62, 0xbb, 0xe5, 0xac, 0xdc,
  644. 0x44, 0x62, 0x54, 0x86, 0xed, 0x64, 0x0c, 0xce, 0xd0, 0x60, 0x03, 0x9d,
  645. 0x49, 0x02, 0x40, 0x54, 0xd9, 0x18, 0x72, 0x27, 0xe4, 0xbe, 0x76, 0xbb,
  646. 0x1a, 0x6a, 0x28, 0x2f, 0x95, 0x58, 0x12, 0xc4, 0x2c, 0xa8, 0xb6, 0xcc,
  647. 0xe2, 0xfd, 0x0d, 0x17, 0x64, 0xc8, 0x18, 0xd7, 0xc6, 0xdf, 0x3d, 0x4c,
  648. 0x1a, 0x9e, 0xf9, 0x2a, 0xb0, 0xb9, 0x2e, 0x12, 0xfd, 0xec, 0xc3, 0x51,
  649. 0xc1, 0xed, 0xa9, 0xfd, 0xb7, 0x76, 0x93, 0x41, 0xd8, 0xc8, 0x22, 0x94,
  650. 0x1a, 0x77, 0xf6, 0x9c, 0xc3, 0xc3, 0x89, 0x02, 0x41, 0x00, 0x8e, 0xf9,
  651. 0xa7, 0x08, 0xad, 0xb5, 0x2a, 0x04, 0xdb, 0x8d, 0x04, 0xa1, 0xb5, 0x06,
  652. 0x20, 0x34, 0xd2, 0xcf, 0xc0, 0x89, 0xb1, 0x72, 0x31, 0xb8, 0x39, 0x8b,
  653. 0xcf, 0xe2, 0x8e, 0xa5, 0xda, 0x4f, 0x45, 0x1e, 0x53, 0x42, 0x66, 0xc4,
  654. 0x30, 0x4b, 0x29, 0x8e, 0xc1, 0x69, 0x17, 0x29, 0x8c, 0x8a, 0xe6, 0x0f,
  655. 0x82, 0x68, 0xa1, 0x41, 0xb3, 0xb6, 0x70, 0x99, 0x75, 0xa9, 0x27, 0x18,
  656. 0xe4, 0xe9, 0x02, 0x41, 0x00, 0x89, 0xea, 0x6e, 0x6d, 0x70, 0xdf, 0x25,
  657. 0x5f, 0x18, 0x3f, 0x48, 0xda, 0x63, 0x10, 0x8b, 0xfe, 0xa8, 0x0c, 0x94,
  658. 0x0f, 0xde, 0x97, 0x56, 0x53, 0x89, 0x94, 0xe2, 0x1e, 0x2c, 0x74, 0x3c,
  659. 0x91, 0x81, 0x34, 0x0b, 0xa6, 0x40, 0xf8, 0xcb, 0x2a, 0x60, 0x8c, 0xe0,
  660. 0x02, 0xb7, 0x89, 0x93, 0xcf, 0x18, 0x9f, 0x49, 0x54, 0xfd, 0x7d, 0x3f,
  661. 0x9a, 0xef, 0xd4, 0xa4, 0x4f, 0xc1, 0x45, 0x99, 0x91,
  662. };
  663. p = rsa_key;
  664. if (!TEST_ptr(pkey = d2i_PrivateKey_ex(EVP_PKEY_RSA, NULL, &p,
  665. sizeof(rsa_key), NULL, NULL)))
  666. goto err;
  667. if (!TEST_int_eq(ERR_peek_error(), 0))
  668. goto err;
  669. p12 = PKCS12_create(NULL, NULL, pkey, NULL, NULL,
  670. NID_pbe_WithSHA1And3_Key_TripleDES_CBC,
  671. NID_pbe_WithSHA1And3_Key_TripleDES_CBC, 2, 1, 0);
  672. if (!TEST_ptr(p12))
  673. goto err;
  674. if (!TEST_int_eq(ERR_peek_error(), 0))
  675. goto err;
  676. ret = 1;
  677. err:
  678. PKCS12_free(p12);
  679. EVP_PKEY_free(pkey);
  680. return ret;
  681. }
  682. #endif
  683. static int pkcs12_recreate_test(void)
  684. {
  685. int ret = 0;
  686. X509 *cert = NULL;
  687. X509 *cert_parsed = NULL;
  688. EVP_PKEY *pkey = NULL;
  689. EVP_PKEY *pkey_parsed = NULL;
  690. PKCS12 *p12 = NULL;
  691. PKCS12 *p12_parsed = NULL;
  692. PKCS12 *p12_recreated = NULL;
  693. const unsigned char *cert_bytes = CERT1;
  694. const unsigned char *key_bytes = KEY1;
  695. BIO *bio = NULL;
  696. cert = d2i_X509(NULL, &cert_bytes, sizeof(CERT1));
  697. if (!TEST_ptr(cert))
  698. goto err;
  699. pkey = d2i_AutoPrivateKey(NULL, &key_bytes, sizeof(KEY1));
  700. if (!TEST_ptr(pkey))
  701. goto err;
  702. p12 = PKCS12_create("pass", NULL, pkey, cert, NULL, NID_aes_256_cbc,
  703. NID_aes_256_cbc, 2, 1, 0);
  704. if (!TEST_ptr(p12))
  705. goto err;
  706. if (!TEST_int_eq(ERR_peek_error(), 0))
  707. goto err;
  708. bio = BIO_new(BIO_s_mem());
  709. if (!TEST_ptr(bio))
  710. goto err;
  711. if (!TEST_int_eq(i2d_PKCS12_bio(bio, p12), 1))
  712. goto err;
  713. p12_parsed = PKCS12_init_ex(NID_pkcs7_data, testctx, NULL);
  714. if (!TEST_ptr(p12_parsed))
  715. goto err;
  716. p12_parsed = d2i_PKCS12_bio(bio, &p12_parsed);
  717. if (!TEST_ptr(p12_parsed))
  718. goto err;
  719. if (!TEST_int_eq(PKCS12_parse(p12_parsed, "pass", &pkey_parsed,
  720. &cert_parsed, NULL), 1))
  721. goto err;
  722. /* cert_parsed also contains auxiliary data */
  723. p12_recreated = PKCS12_create("new_pass", NULL, pkey_parsed, cert_parsed,
  724. NULL, NID_aes_256_cbc, NID_aes_256_cbc,
  725. 2, 1, 0);
  726. if (!TEST_ptr(p12_recreated))
  727. goto err;
  728. if (!TEST_int_eq(ERR_peek_error(), 0))
  729. goto err;
  730. ret = 1;
  731. err:
  732. BIO_free(bio);
  733. PKCS12_free(p12);
  734. PKCS12_free(p12_parsed);
  735. PKCS12_free(p12_recreated);
  736. EVP_PKEY_free(pkey);
  737. EVP_PKEY_free(pkey_parsed);
  738. X509_free(cert);
  739. X509_free(cert_parsed);
  740. return ret;
  741. }
  742. typedef enum OPTION_choice {
  743. OPT_ERR = -1,
  744. OPT_EOF = 0,
  745. OPT_WRITE,
  746. OPT_LEGACY,
  747. OPT_CONTEXT,
  748. OPT_TEST_ENUM
  749. } OPTION_CHOICE;
  750. const OPTIONS *test_get_options(void)
  751. {
  752. static const OPTIONS options[] = {
  753. OPT_TEST_OPTIONS_DEFAULT_USAGE,
  754. { "write", OPT_WRITE, '-', "Write PKCS12 objects to file" },
  755. { "legacy", OPT_LEGACY, '-', "Test the legacy APIs" },
  756. { "context", OPT_CONTEXT, '-', "Explicitly use a non-default library context" },
  757. { NULL }
  758. };
  759. return options;
  760. }
  761. int setup_tests(void)
  762. {
  763. OPTION_CHOICE o;
  764. while ((o = opt_next()) != OPT_EOF) {
  765. switch (o) {
  766. case OPT_WRITE:
  767. PKCS12_helper_set_write_files(1);
  768. break;
  769. case OPT_LEGACY:
  770. PKCS12_helper_set_legacy(1);
  771. break;
  772. case OPT_CONTEXT:
  773. default_libctx = 0;
  774. break;
  775. case OPT_TEST_CASES:
  776. break;
  777. default:
  778. return 0;
  779. }
  780. }
  781. if (!default_libctx) {
  782. testctx = OSSL_LIB_CTX_new();
  783. if (!TEST_ptr(testctx))
  784. return 0;
  785. nullprov = OSSL_PROVIDER_load(NULL, "null");
  786. if (!TEST_ptr(nullprov))
  787. return 0;
  788. }
  789. deflprov = OSSL_PROVIDER_load(testctx, "default");
  790. if (!TEST_ptr(deflprov))
  791. return 0;
  792. lgcyprov = OSSL_PROVIDER_load(testctx, "legacy");
  793. PKCS12_helper_set_libctx(testctx);
  794. /*
  795. * Verify that the default and fips providers in the default libctx are not
  796. * available if we are using a standalone context
  797. */
  798. if (!default_libctx) {
  799. if (!TEST_false(OSSL_PROVIDER_available(NULL, "default"))
  800. || !TEST_false(OSSL_PROVIDER_available(NULL, "fips")))
  801. return 0;
  802. }
  803. ADD_TEST(test_single_cert_no_attrs);
  804. if (lgcyprov == NULL) {
  805. ADD_ALL_TESTS(test_single_key_enc_alg, OSSL_NELEM(enc_nids_no_legacy));
  806. ADD_ALL_TESTS(test_single_secret_enc_alg, OSSL_NELEM(enc_nids_no_legacy));
  807. } else {
  808. ADD_ALL_TESTS(test_single_key_enc_alg, OSSL_NELEM(enc_nids_all));
  809. ADD_ALL_TESTS(test_single_secret_enc_alg, OSSL_NELEM(enc_nids_all));
  810. }
  811. #ifndef OPENSSL_NO_DES
  812. if (default_libctx)
  813. ADD_TEST(pkcs12_create_test);
  814. #endif
  815. if (default_libctx)
  816. ADD_TEST(pkcs12_recreate_test);
  817. ADD_ALL_TESTS(test_single_key_enc_pass, OSSL_NELEM(passwords));
  818. ADD_ALL_TESTS(test_single_key_enc_iter, OSSL_NELEM(iters));
  819. ADD_TEST(test_single_key_with_attrs);
  820. ADD_ALL_TESTS(test_single_cert_mac_alg, OSSL_NELEM(mac_nids));
  821. ADD_ALL_TESTS(test_single_cert_mac_pass, OSSL_NELEM(passwords));
  822. ADD_ALL_TESTS(test_single_cert_mac_iter, OSSL_NELEM(iters));
  823. ADD_TEST(test_cert_key_with_attrs_and_mac);
  824. ADD_TEST(test_cert_key_encrypted_content);
  825. ADD_TEST(test_single_secret_encrypted_content);
  826. ADD_TEST(test_multiple_contents);
  827. ADD_TEST(test_jdk_trusted_attr);
  828. ADD_TEST(test_set0_attrs);
  829. return 1;
  830. }
  831. void cleanup_tests(void)
  832. {
  833. OSSL_PROVIDER_unload(nullprov);
  834. OSSL_PROVIDER_unload(deflprov);
  835. OSSL_PROVIDER_unload(lgcyprov);
  836. OSSL_LIB_CTX_free(testctx);
  837. }