self_test_data.inc 50 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286
  1. /*
  2. * Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the Apache License 2.0 (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. /* Macros to build Self test data */
  10. #define ITM(x) x, sizeof(x)
  11. #define ITM_STR(x) x, (sizeof(x) - 1)
  12. #define ST_KAT_PARAM_END() { "", 0, NULL, 0 }
  13. #define ST_KAT_PARAM_BIGNUM(name, data) \
  14. { name, OSSL_PARAM_UNSIGNED_INTEGER, ITM(data) }
  15. #define ST_KAT_PARAM_OCTET(name, data) \
  16. { name, OSSL_PARAM_OCTET_STRING, ITM(data) }
  17. #define ST_KAT_PARAM_UTF8STRING(name, data) \
  18. { name, OSSL_PARAM_UTF8_STRING, ITM_STR(data) }
  19. /* used to store raw parameters for keys and algorithms */
  20. typedef struct st_kat_param_st {
  21. const char *name; /* an OSSL_PARAM name */
  22. size_t type; /* the type associated with the data */
  23. const void *data; /* unsigned char [], or char [] depending on the type */
  24. size_t data_len; /* the length of the data */
  25. } ST_KAT_PARAM;
  26. typedef struct st_kat_st {
  27. const char *desc;
  28. const char *algorithm;
  29. const unsigned char *pt;
  30. size_t pt_len;
  31. const unsigned char *expected;
  32. size_t expected_len;
  33. } ST_KAT;
  34. typedef ST_KAT ST_KAT_DIGEST;
  35. typedef struct st_kat_cipher_st {
  36. ST_KAT base;
  37. const unsigned char *key;
  38. size_t key_len;
  39. const unsigned char *iv;
  40. size_t iv_len;
  41. const unsigned char *aad;
  42. size_t aad_len;
  43. const unsigned char *tag;
  44. size_t tag_len;
  45. } ST_KAT_CIPHER;
  46. typedef struct st_kat_kdf_st {
  47. const char *desc;
  48. const char *algorithm;
  49. const ST_KAT_PARAM *params;
  50. const unsigned char *expected;
  51. size_t expected_len;
  52. } ST_KAT_KDF;
  53. typedef struct st_kat_drbg_st {
  54. const char *desc;
  55. const char *algorithm;
  56. const char *param_name;
  57. char *param_value;
  58. const unsigned char *entropyin;
  59. size_t entropyinlen;
  60. const unsigned char *nonce;
  61. size_t noncelen;
  62. const unsigned char *persstr;
  63. size_t persstrlen;
  64. const unsigned char *entropyinpr1;
  65. size_t entropyinpr1len;
  66. const unsigned char *entropyinpr2;
  67. size_t entropyinpr2len;
  68. const unsigned char *entropyaddin1;
  69. size_t entropyaddin1len;
  70. const unsigned char *entropyaddin2;
  71. size_t entropyaddin2len;
  72. const unsigned char *expected;
  73. size_t expectedlen;
  74. } ST_KAT_DRBG;
  75. typedef struct st_kat_kas_st {
  76. const char *desc;
  77. const char *algorithm;
  78. const ST_KAT_PARAM *key_group;
  79. const ST_KAT_PARAM *key_host_data;
  80. const ST_KAT_PARAM *key_peer_data;
  81. const unsigned char *expected;
  82. size_t expected_len;
  83. } ST_KAT_KAS;
  84. typedef struct st_kat_sign_st {
  85. const char *desc;
  86. const char *algorithm;
  87. const char *mdalgorithm;
  88. const ST_KAT_PARAM *key;
  89. const unsigned char *sig_expected; /* Set to NULL if this value changes */
  90. size_t sig_expected_len;
  91. } ST_KAT_SIGN;
  92. typedef struct st_kat_asym_cipher_st {
  93. const char *desc;
  94. const char *algorithm;
  95. int encrypt;
  96. const ST_KAT_PARAM *key;
  97. const ST_KAT_PARAM *postinit;
  98. const unsigned char *in;
  99. size_t in_len;
  100. const unsigned char *expected;
  101. size_t expected_len;
  102. } ST_KAT_ASYM_CIPHER;
  103. /*- DIGEST TEST DATA */
  104. static const unsigned char sha1_pt[] = "abc";
  105. static const unsigned char sha1_digest[] = {
  106. 0xA9, 0x99, 0x3E, 0x36, 0x47, 0x06, 0x81, 0x6A, 0xBA, 0x3E, 0x25, 0x71,
  107. 0x78, 0x50, 0xC2, 0x6C, 0x9C, 0xD0, 0xD8, 0x9D
  108. };
  109. static const unsigned char sha512_pt[] = "abc";
  110. static const unsigned char sha512_digest[] = {
  111. 0xDD, 0xAF, 0x35, 0xA1, 0x93, 0x61, 0x7A, 0xBA, 0xCC, 0x41, 0x73, 0x49,
  112. 0xAE, 0x20, 0x41, 0x31, 0x12, 0xE6, 0xFA, 0x4E, 0x89, 0xA9, 0x7E, 0xA2,
  113. 0x0A, 0x9E, 0xEE, 0xE6, 0x4B, 0x55, 0xD3, 0x9A, 0x21, 0x92, 0x99, 0x2A,
  114. 0x27, 0x4F, 0xC1, 0xA8, 0x36, 0xBA, 0x3C, 0x23, 0xA3, 0xFE, 0xEB, 0xBD,
  115. 0x45, 0x4D, 0x44, 0x23, 0x64, 0x3C, 0xE8, 0x0E, 0x2A, 0x9A, 0xC9, 0x4F,
  116. 0xA5, 0x4C, 0xA4, 0x9F
  117. };
  118. static const unsigned char sha3_256_pt[] = { 0xe7, 0x37, 0x21, 0x05 };
  119. static const unsigned char sha3_256_digest[] = {
  120. 0x3a, 0x42, 0xb6, 0x8a, 0xb0, 0x79, 0xf2, 0x8c, 0x4c, 0xa3, 0xc7, 0x52,
  121. 0x29, 0x6f, 0x27, 0x90, 0x06, 0xc4, 0xfe, 0x78, 0xb1, 0xeb, 0x79, 0xd9,
  122. 0x89, 0x77, 0x7f, 0x05, 0x1e, 0x40, 0x46, 0xae
  123. };
  124. static const ST_KAT_DIGEST st_kat_digest_tests[] =
  125. {
  126. {
  127. OSSL_SELF_TEST_DESC_MD_SHA1,
  128. "SHA1",
  129. ITM_STR(sha1_pt),
  130. ITM(sha1_digest),
  131. },
  132. {
  133. OSSL_SELF_TEST_DESC_MD_SHA2,
  134. "SHA512",
  135. ITM_STR(sha512_pt),
  136. ITM(sha512_digest),
  137. },
  138. {
  139. OSSL_SELF_TEST_DESC_MD_SHA3,
  140. "SHA3-256",
  141. ITM(sha3_256_pt),
  142. ITM(sha3_256_digest),
  143. },
  144. };
  145. /*- CIPHER TEST DATA */
  146. /* DES3 test data */
  147. static const unsigned char des_ede3_cbc_pt[] = {
  148. 0x6B, 0xC1, 0xBE, 0xE2, 0x2E, 0x40, 0x9F, 0x96,
  149. 0xE9, 0x3D, 0x7E, 0x11, 0x73, 0x93, 0x17, 0x2A,
  150. 0xAE, 0x2D, 0x8A, 0x57, 0x1E, 0x03, 0xAC, 0x9C,
  151. 0x9E, 0xB7, 0x6F, 0xAC, 0x45, 0xAF, 0x8E, 0x51
  152. };
  153. static const unsigned char des_ede3_cbc_key[] = {
  154. 0x01, 0x23, 0x45, 0x67, 0x89, 0xAB, 0xCD, 0xEF,
  155. 0x23, 0x45, 0x67, 0x89, 0xAB, 0xCD, 0xEF, 0x01,
  156. 0x45, 0x67, 0x89, 0xAB, 0xCD, 0xEF, 0x01, 0x23
  157. };
  158. static const unsigned char des_ede3_cbc_iv[] = {
  159. 0xF6, 0x9F, 0x24, 0x45, 0xDF, 0x4F, 0x9B, 0x17
  160. };
  161. static const unsigned char des_ede3_cbc_ct[] = {
  162. 0x20, 0x79, 0xC3, 0xD5, 0x3A, 0xA7, 0x63, 0xE1,
  163. 0x93, 0xB7, 0x9E, 0x25, 0x69, 0xAB, 0x52, 0x62,
  164. 0x51, 0x65, 0x70, 0x48, 0x1F, 0x25, 0xB5, 0x0F,
  165. 0x73, 0xC0, 0xBD, 0xA8, 0x5C, 0x8E, 0x0D, 0xA7
  166. };
  167. /* AES-256 GCM test data */
  168. static const unsigned char aes_256_gcm_key[] = {
  169. 0x92, 0xe1, 0x1d, 0xcd, 0xaa, 0x86, 0x6f, 0x5c,
  170. 0xe7, 0x90, 0xfd, 0x24, 0x50, 0x1f, 0x92, 0x50,
  171. 0x9a, 0xac, 0xf4, 0xcb, 0x8b, 0x13, 0x39, 0xd5,
  172. 0x0c, 0x9c, 0x12, 0x40, 0x93, 0x5d, 0xd0, 0x8b
  173. };
  174. static const unsigned char aes_256_gcm_iv[] = {
  175. 0xac, 0x93, 0xa1, 0xa6, 0x14, 0x52, 0x99, 0xbd,
  176. 0xe9, 0x02, 0xf2, 0x1a
  177. };
  178. static const unsigned char aes_256_gcm_pt[] = {
  179. 0x2d, 0x71, 0xbc, 0xfa, 0x91, 0x4e, 0x4a, 0xc0,
  180. 0x45, 0xb2, 0xaa, 0x60, 0x95, 0x5f, 0xad, 0x24
  181. };
  182. static const unsigned char aes_256_gcm_aad[] = {
  183. 0x1e, 0x08, 0x89, 0x01, 0x6f, 0x67, 0x60, 0x1c,
  184. 0x8e, 0xbe, 0xa4, 0x94, 0x3b, 0xc2, 0x3a, 0xd6
  185. };
  186. static const unsigned char aes_256_gcm_ct[] = {
  187. 0x89, 0x95, 0xae, 0x2e, 0x6d, 0xf3, 0xdb, 0xf9,
  188. 0x6f, 0xac, 0x7b, 0x71, 0x37, 0xba, 0xe6, 0x7f
  189. };
  190. static const unsigned char aes_256_gcm_tag[] = {
  191. 0xec, 0xa5, 0xaa, 0x77, 0xd5, 0x1d, 0x4a, 0x0a,
  192. 0x14, 0xd9, 0xc5, 0x1e, 0x1d, 0xa4, 0x74, 0xab
  193. };
  194. static const ST_KAT_CIPHER st_kat_cipher_tests[] = {
  195. #ifndef OPENSSL_NO_DES
  196. {
  197. {
  198. OSSL_SELF_TEST_DESC_CIPHER_TDES,
  199. "DES-EDE3-CBC",
  200. ITM(des_ede3_cbc_pt),
  201. ITM(des_ede3_cbc_ct)
  202. },
  203. ITM(des_ede3_cbc_key),
  204. ITM(des_ede3_cbc_iv),
  205. },
  206. #endif
  207. {
  208. {
  209. OSSL_SELF_TEST_DESC_CIPHER_AES_GCM,
  210. "AES-256-GCM",
  211. ITM(aes_256_gcm_pt),
  212. ITM(aes_256_gcm_ct),
  213. },
  214. ITM(aes_256_gcm_key),
  215. ITM(aes_256_gcm_iv),
  216. ITM(aes_256_gcm_aad),
  217. ITM(aes_256_gcm_tag)
  218. }
  219. };
  220. static const char hkdf_digest[] = "SHA256";
  221. static const unsigned char hkdf_secret[] = { 's', 'e', 'c', 'r', 'e', 't' };
  222. static const unsigned char hkdf_salt[] = { 's', 'a', 'l', 't' };
  223. static const unsigned char hkdf_info[] = { 'l', 'a', 'b', 'e', 'l' };
  224. static const ST_KAT_PARAM hkdf_params[] = {
  225. ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, hkdf_digest),
  226. ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_KEY, hkdf_secret),
  227. ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_SALT, hkdf_salt),
  228. ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_INFO, hkdf_info),
  229. ST_KAT_PARAM_END()
  230. };
  231. static const unsigned char hkdf_expected[] = {
  232. 0x2a, 0xc4, 0x36, 0x9f, 0x52, 0x59, 0x96, 0xf8,
  233. 0xde, 0x13
  234. };
  235. static const char sskdf_digest[] = "SHA224";
  236. static const unsigned char sskdf_secret[] = {
  237. 0x6d, 0xbd, 0xc2, 0x3f, 0x04, 0x54, 0x88, 0xe4,
  238. 0x06, 0x27, 0x57, 0xb0, 0x6b, 0x9e, 0xba, 0xe1,
  239. 0x83, 0xfc, 0x5a, 0x59, 0x46, 0xd8, 0x0d, 0xb9,
  240. 0x3f, 0xec, 0x6f, 0x62, 0xec, 0x07, 0xe3, 0x72,
  241. 0x7f, 0x01, 0x26, 0xae, 0xd1, 0x2c, 0xe4, 0xb2,
  242. 0x62, 0xf4, 0x7d, 0x48, 0xd5, 0x42, 0x87, 0xf8,
  243. 0x1d, 0x47, 0x4c, 0x7c, 0x3b, 0x18, 0x50, 0xe9
  244. };
  245. static const unsigned char sskdf_otherinfo[] = {
  246. 0xa1, 0xb2, 0xc3, 0xd4, 0xe5, 0x43, 0x41, 0x56,
  247. 0x53, 0x69, 0x64, 0x3c, 0x83, 0x2e, 0x98, 0x49,
  248. 0xdc, 0xdb, 0xa7, 0x1e, 0x9a, 0x31, 0x39, 0xe6,
  249. 0x06, 0xe0, 0x95, 0xde, 0x3c, 0x26, 0x4a, 0x66,
  250. 0xe9, 0x8a, 0x16, 0x58, 0x54, 0xcd, 0x07, 0x98,
  251. 0x9b, 0x1e, 0xe0, 0xec, 0x3f, 0x8d, 0xbe
  252. };
  253. static const unsigned char sskdf_expected[] = {
  254. 0xa4, 0x62, 0xde, 0x16, 0xa8, 0x9d, 0xe8, 0x46,
  255. 0x6e, 0xf5, 0x46, 0x0b, 0x47, 0xb8
  256. };
  257. static const ST_KAT_PARAM sskdf_params[] = {
  258. ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, sskdf_digest),
  259. ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_KEY, sskdf_secret),
  260. ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_INFO, sskdf_otherinfo),
  261. ST_KAT_PARAM_END()
  262. };
  263. static const ST_KAT_KDF st_kat_kdf_tests[] =
  264. {
  265. {
  266. OSSL_SELF_TEST_DESC_KDF_HKDF,
  267. OSSL_KDF_NAME_HKDF,
  268. hkdf_params,
  269. ITM(hkdf_expected)
  270. },
  271. {
  272. OSSL_SELF_TEST_DESC_KDF_SSKDF,
  273. OSSL_KDF_NAME_SSKDF,
  274. sskdf_params,
  275. ITM(sskdf_expected)
  276. }
  277. };
  278. /*-
  279. * DRBG test vectors are a small subset of
  280. * https://csrc.nist.rip/groups/STM/cavp/documents/drbg/drbgtestvectors.zip
  281. * Using the folder drbgvectors_pr_true
  282. * Generated for CAVS 14.3.
  283. */
  284. /*
  285. * Hash_DRBG.rsp
  286. *
  287. * [SHA-256]
  288. * [PredictionResistance = True]
  289. * [EntropyInputLen = 256]
  290. * [NonceLen = 128]
  291. * [PersonalizationStringLen = 256]
  292. * [AdditionalInputLen = 256]
  293. * [ReturnedBitsLen = 1024]
  294. *
  295. * COUNT = 14
  296. */
  297. static const unsigned char drbg_hash_sha256_pr_entropyin[] = {
  298. 0x06, 0x6d, 0xc8, 0xce, 0x75, 0xb2, 0x89, 0x66, 0xa6, 0x85, 0x16, 0x3f,
  299. 0xe2, 0xa4, 0xd4, 0x27, 0xfb, 0xdb, 0x61, 0x66, 0x50, 0x61, 0x6b, 0xa2,
  300. 0x82, 0xfc, 0x33, 0x2b, 0x4e, 0x6f, 0x12, 0x20
  301. };
  302. static const unsigned char drbg_hash_sha256_pr_nonce[] = {
  303. 0x55, 0x9f, 0x7c, 0x64, 0x89, 0x70, 0x83, 0xec, 0x2d, 0x73, 0x70, 0xd9,
  304. 0xf0, 0xe5, 0x07, 0x1f
  305. };
  306. static const unsigned char drbg_hash_sha256_pr_persstr[] = {
  307. 0x88, 0x6f, 0x54, 0x9a, 0xad, 0x1a, 0xc6, 0x3d, 0x18, 0xcb, 0xcc, 0x66,
  308. 0x85, 0xda, 0xa2, 0xc2, 0xf7, 0x9e, 0xb0, 0x89, 0x4c, 0xb4, 0xae, 0xf1,
  309. 0xac, 0x54, 0x4f, 0xce, 0x57, 0xf1, 0x5e, 0x11
  310. };
  311. static const unsigned char drbg_hash_sha256_pr_entropyinpr0[] = {
  312. 0xff, 0x80, 0xb7, 0xd2, 0x6a, 0x05, 0xbc, 0x8a, 0x7a, 0xbe, 0x53, 0x28,
  313. 0x6b, 0x0e, 0xeb, 0x73, 0x3b, 0x71, 0x5a, 0x20, 0x5b, 0xfa, 0x4f, 0xf6,
  314. 0x37, 0x03, 0xde, 0xad, 0xb6, 0xea, 0x0e, 0xf4
  315. };
  316. static const unsigned char drbg_hash_sha256_pr_entropyinpr1[] = {
  317. 0xc7, 0x38, 0x32, 0x53, 0x46, 0x81, 0xed, 0xe3, 0x7e, 0x03, 0x84, 0x6d,
  318. 0x3c, 0x84, 0x17, 0x67, 0x29, 0x7d, 0x24, 0x6c, 0x68, 0x92, 0x41, 0xd2,
  319. 0xe7, 0x75, 0xbe, 0x7e, 0xc9, 0x96, 0x29, 0x3d
  320. };
  321. static const unsigned char drbg_hash_sha256_pr_addin0[] = {
  322. 0xb7, 0x21, 0x5f, 0x14, 0xac, 0x7b, 0xaf, 0xd0, 0xa9, 0x17, 0x72, 0xba,
  323. 0x22, 0xf7, 0x19, 0xaf, 0xbd, 0x20, 0xb3, 0x11, 0x63, 0x6c, 0x2b, 0x1e,
  324. 0x83, 0xe4, 0xa8, 0x23, 0x35, 0x3f, 0xc6, 0xea
  325. };
  326. static const unsigned char drbg_hash_sha256_pr_addin1[] = {
  327. 0xce, 0xd3, 0x1f, 0x7e, 0x0d, 0xae, 0x5b, 0xb5, 0xc0, 0x43, 0xe2, 0x46,
  328. 0xb2, 0x94, 0x73, 0xe2, 0xfd, 0x39, 0x51, 0x2e, 0xad, 0x45, 0x69, 0xee,
  329. 0xe3, 0xe3, 0x80, 0x33, 0x14, 0xab, 0xa7, 0xa3
  330. };
  331. static const unsigned char drbg_hash_sha256_pr_expected[] = {
  332. 0x60, 0xc2, 0x34, 0xcf, 0xaf, 0xb4, 0x68, 0x03, 0x3b, 0xf1, 0x95, 0xe5,
  333. 0x78, 0xce, 0x26, 0x6e, 0x14, 0x65, 0x32, 0x6a, 0x96, 0xa9, 0xe0, 0x3f,
  334. 0x8b, 0x89, 0x36, 0x70, 0xef, 0x62, 0x75, 0x4d, 0x5e, 0x80, 0xd5, 0x53,
  335. 0xa1, 0xf8, 0x49, 0x50, 0x20, 0x8b, 0x93, 0x43, 0x07, 0x9f, 0x2e, 0xf8,
  336. 0x56, 0xe9, 0xc5, 0x70, 0x61, 0x85, 0x97, 0xb5, 0xdc, 0x82, 0xa2, 0xda,
  337. 0xea, 0xa3, 0xfd, 0x9b, 0x2f, 0xd2, 0xa0, 0xd7, 0x1b, 0xc6, 0x29, 0x35,
  338. 0xcc, 0xb8, 0x3d, 0xa0, 0x67, 0x98, 0x05, 0xa0, 0xe3, 0x1e, 0xfe, 0xe4,
  339. 0xf0, 0xe5, 0x13, 0xb0, 0x83, 0x17, 0xfa, 0xca, 0x93, 0x5e, 0x38, 0x29,
  340. 0x48, 0xd2, 0x72, 0xdb, 0x76, 0x3e, 0x6d, 0xf3, 0x25, 0x10, 0xff, 0x1b,
  341. 0x99, 0xff, 0xf8, 0xc6, 0x0e, 0xb0, 0xdd, 0x29, 0x2e, 0xbc, 0xbb, 0xc8,
  342. 0x0a, 0x01, 0x6e, 0xd3, 0xb0, 0x0e, 0x4e, 0xab
  343. };
  344. /*
  345. * CTR_DRBG.rsp
  346. *
  347. * [AES-128 use df]
  348. * [PredictionResistance = True]
  349. * [EntropyInputLen = 128]
  350. * [NonceLen = 64]
  351. * [PersonalizationStringLen = 128]
  352. * [AdditionalInputLen = 128]
  353. * [ReturnedBitsLen = 512]
  354. *
  355. * COUNT = 0
  356. */
  357. static const unsigned char drbg_ctr_aes128_pr_df_entropyin[] = {
  358. 0x92, 0x89, 0x8f, 0x31, 0xfa, 0x1c, 0xff, 0x6d, 0x18, 0x2f, 0x26, 0x06,
  359. 0x43, 0xdf, 0xf8, 0x18
  360. };
  361. static const unsigned char drbg_ctr_aes128_pr_df_nonce[] = {
  362. 0xc2, 0xa4, 0xd9, 0x72, 0xc3, 0xb9, 0xb6, 0x97
  363. };
  364. static const unsigned char drbg_ctr_aes128_pr_df_persstr[] = {
  365. 0xea, 0x65, 0xee, 0x60, 0x26, 0x4e, 0x7e, 0xb6, 0x0e, 0x82, 0x68, 0xc4,
  366. 0x37, 0x3c, 0x5c, 0x0b
  367. };
  368. static const unsigned char drbg_ctr_aes128_pr_df_entropyinpr0[] = {
  369. 0x20, 0x72, 0x8a, 0x06, 0xf8, 0x6f, 0x8d, 0xd4, 0x41, 0xe2, 0x72, 0xb7,
  370. 0xc4, 0x2c, 0xe8, 0x10
  371. };
  372. static const unsigned char drbg_ctr_aes128_pr_df_entropyinpr1[] = {
  373. 0x3d, 0xb0, 0xf0, 0x94, 0xf3, 0x05, 0x50, 0x33, 0x17, 0x86, 0x3e, 0x22,
  374. 0x08, 0xf7, 0xa5, 0x01
  375. };
  376. static const unsigned char drbg_ctr_aes128_pr_df_addin0[] = {
  377. 0x1a, 0x40, 0xfa, 0xe3, 0xcc, 0x6c, 0x7c, 0xa0, 0xf8, 0xda, 0xba, 0x59,
  378. 0x23, 0x6d, 0xad, 0x1d
  379. };
  380. static const unsigned char drbg_ctr_aes128_pr_df_addin1[] = {
  381. 0x9f, 0x72, 0x76, 0x6c, 0xc7, 0x46, 0xe5, 0xed, 0x2e, 0x53, 0x20, 0x12,
  382. 0xbc, 0x59, 0x31, 0x8c
  383. };
  384. static const unsigned char drbg_ctr_aes128_pr_df_expected[] = {
  385. 0x5a, 0x35, 0x39, 0x87, 0x0f, 0x4d, 0x22, 0xa4, 0x09, 0x24, 0xee, 0x71,
  386. 0xc9, 0x6f, 0xac, 0x72, 0x0a, 0xd6, 0xf0, 0x88, 0x82, 0xd0, 0x83, 0x28,
  387. 0x73, 0xec, 0x3f, 0x93, 0xd8, 0xab, 0x45, 0x23, 0xf0, 0x7e, 0xac, 0x45,
  388. 0x14, 0x5e, 0x93, 0x9f, 0xb1, 0xd6, 0x76, 0x43, 0x3d, 0xb6, 0xe8, 0x08,
  389. 0x88, 0xf6, 0xda, 0x89, 0x08, 0x77, 0x42, 0xfe, 0x1a, 0xf4, 0x3f, 0xc4,
  390. 0x23, 0xc5, 0x1f, 0x68
  391. };
  392. /*
  393. * HMAC_DRBG.rsp
  394. *
  395. * [SHA-1]
  396. * [PredictionResistance = True]
  397. * [EntropyInputLen = 128]
  398. * [NonceLen = 64]
  399. * [PersonalizationStringLen = 128]
  400. * [AdditionalInputLen = 128]
  401. * [ReturnedBitsLen = 640]
  402. *
  403. * COUNT = 0
  404. */
  405. static const unsigned char drbg_hmac_sha1_pr_entropyin[] = {
  406. 0x68, 0x0f, 0xac, 0xe9, 0x0d, 0x7b, 0xca, 0x21, 0xd4, 0xa0, 0xed, 0xb7,
  407. 0x79, 0x9e, 0xe5, 0xd8
  408. };
  409. static const unsigned char drbg_hmac_sha1_pr_nonce[] = {
  410. 0xb7, 0xbe, 0x9e, 0xed, 0xdd, 0x0e, 0x3b, 0x4b
  411. };
  412. static const unsigned char drbg_hmac_sha1_pr_persstr[] = {
  413. 0xf5, 0x8c, 0x40, 0xae, 0x70, 0xf7, 0xa5, 0x56, 0x48, 0xa9, 0x31, 0xa0,
  414. 0xa9, 0x31, 0x3d, 0xd7
  415. };
  416. static const unsigned char drbg_hmac_sha1_pr_entropyinpr0[] = {
  417. 0x7c, 0xaf, 0xe2, 0x31, 0x63, 0x0a, 0xa9, 0x5a, 0x74, 0x2c, 0x4e, 0x5f,
  418. 0x5f, 0x22, 0xc6, 0xa4
  419. };
  420. static const unsigned char drbg_hmac_sha1_pr_entropyinpr1[] = {
  421. 0x1c, 0x0d, 0x77, 0x92, 0x89, 0x88, 0x27, 0x94, 0x8a, 0x58, 0x9f, 0x82,
  422. 0x2d, 0x1a, 0xf7, 0xa6
  423. };
  424. static const unsigned char drbg_hmac_sha1_pr_addin0[] = {
  425. 0xdc, 0x36, 0x63, 0xf0, 0x62, 0x78, 0x9c, 0xd1, 0x5c, 0xbb, 0x20, 0xc3,
  426. 0xc1, 0x8c, 0xd9, 0xd7
  427. };
  428. static const unsigned char drbg_hmac_sha1_pr_addin1[] = {
  429. 0xfe, 0x85, 0xb0, 0xab, 0x14, 0xc6, 0x96, 0xe6, 0x9c, 0x24, 0xe7, 0xb5,
  430. 0xa1, 0x37, 0x12, 0x0c
  431. };
  432. static const unsigned char drbg_hmac_sha1_pr_expected[] = {
  433. 0x68, 0x00, 0x4b, 0x3a, 0x28, 0xf7, 0xf0, 0x1c, 0xf9, 0xe9, 0xb5, 0x71,
  434. 0x20, 0x79, 0xef, 0x80, 0x87, 0x1b, 0x08, 0xb9, 0xa9, 0x1b, 0xcd, 0x2b,
  435. 0x9f, 0x09, 0x4d, 0xa4, 0x84, 0x80, 0xb3, 0x4c, 0xaf, 0xd5, 0x59, 0x6b,
  436. 0x0c, 0x0a, 0x48, 0xe1, 0x48, 0xda, 0xbc, 0x6f, 0x77, 0xb8, 0xff, 0xaf,
  437. 0x18, 0x70, 0x28, 0xe1, 0x04, 0x13, 0x7a, 0x4f, 0xeb, 0x1c, 0x72, 0xb0,
  438. 0xc4, 0x4f, 0xe8, 0xb1, 0xaf, 0xab, 0xa5, 0xbc, 0xfd, 0x86, 0x67, 0xf2,
  439. 0xf5, 0x5b, 0x46, 0x06, 0x63, 0x2e, 0x3c, 0xbc
  440. };
  441. static const ST_KAT_DRBG st_kat_drbg_tests[] =
  442. {
  443. {
  444. OSSL_SELF_TEST_DESC_DRBG_HASH,
  445. "HASH-DRBG", "digest", "SHA256",
  446. ITM(drbg_hash_sha256_pr_entropyin),
  447. ITM(drbg_hash_sha256_pr_nonce),
  448. ITM(drbg_hash_sha256_pr_persstr),
  449. ITM(drbg_hash_sha256_pr_entropyinpr0),
  450. ITM(drbg_hash_sha256_pr_entropyinpr1),
  451. ITM(drbg_hash_sha256_pr_addin0),
  452. ITM(drbg_hash_sha256_pr_addin1),
  453. ITM(drbg_hash_sha256_pr_expected)
  454. },
  455. {
  456. OSSL_SELF_TEST_DESC_DRBG_CTR,
  457. "CTR-DRBG", "cipher", "AES-128-CTR",
  458. ITM(drbg_ctr_aes128_pr_df_entropyin),
  459. ITM(drbg_ctr_aes128_pr_df_nonce),
  460. ITM(drbg_ctr_aes128_pr_df_persstr),
  461. ITM(drbg_ctr_aes128_pr_df_entropyinpr0),
  462. ITM(drbg_ctr_aes128_pr_df_entropyinpr1),
  463. ITM(drbg_ctr_aes128_pr_df_addin0),
  464. ITM(drbg_ctr_aes128_pr_df_addin1),
  465. ITM(drbg_ctr_aes128_pr_df_expected)
  466. },
  467. {
  468. OSSL_SELF_TEST_DESC_DRBG_HMAC,
  469. "HMAC-DRBG", "digest", "SHA1",
  470. ITM(drbg_hmac_sha1_pr_entropyin),
  471. ITM(drbg_hmac_sha1_pr_nonce),
  472. ITM(drbg_hmac_sha1_pr_persstr),
  473. ITM(drbg_hmac_sha1_pr_entropyinpr0),
  474. ITM(drbg_hmac_sha1_pr_entropyinpr1),
  475. ITM(drbg_hmac_sha1_pr_addin0),
  476. ITM(drbg_hmac_sha1_pr_addin1),
  477. ITM(drbg_hmac_sha1_pr_expected)
  478. }
  479. };
  480. /* KEY EXCHANGE TEST DATA */
  481. #ifndef OPENSSL_NO_DH
  482. /* DH KAT */
  483. static const unsigned char dh_p[] = {
  484. 0xdc, 0xca, 0x15, 0x11, 0xb2, 0x31, 0x32, 0x25,
  485. 0xf5, 0x21, 0x16, 0xe1, 0x54, 0x27, 0x89, 0xe0,
  486. 0x01, 0xf0, 0x42, 0x5b, 0xcc, 0xc7, 0xf3, 0x66,
  487. 0xf7, 0x40, 0x64, 0x07, 0xf1, 0xc9, 0xfa, 0x8b,
  488. 0xe6, 0x10, 0xf1, 0x77, 0x8b, 0xb1, 0x70, 0xbe,
  489. 0x39, 0xdb, 0xb7, 0x6f, 0x85, 0xbf, 0x24, 0xce,
  490. 0x68, 0x80, 0xad, 0xb7, 0x62, 0x9f, 0x7c, 0x6d,
  491. 0x01, 0x5e, 0x61, 0xd4, 0x3f, 0xa3, 0xee, 0x4d,
  492. 0xe1, 0x85, 0xf2, 0xcf, 0xd0, 0x41, 0xff, 0xde,
  493. 0x9d, 0x41, 0x84, 0x07, 0xe1, 0x51, 0x38, 0xbb,
  494. 0x02, 0x1d, 0xae, 0xb3, 0x5f, 0x76, 0x2d, 0x17,
  495. 0x82, 0xac, 0xc6, 0x58, 0xd3, 0x2b, 0xd4, 0xb0,
  496. 0x23, 0x2c, 0x92, 0x7d, 0xd3, 0x8f, 0xa0, 0x97,
  497. 0xb3, 0xd1, 0x85, 0x9f, 0xa8, 0xac, 0xaf, 0xb9,
  498. 0x8f, 0x06, 0x66, 0x08, 0xfc, 0x64, 0x4e, 0xc7,
  499. 0xdd, 0xb6, 0xf0, 0x85, 0x99, 0xf9, 0x2a, 0xc1,
  500. 0xb5, 0x98, 0x25, 0xda, 0x84, 0x32, 0x07, 0x7d,
  501. 0xef, 0x69, 0x56, 0x46, 0x06, 0x3c, 0x20, 0x82,
  502. 0x3c, 0x95, 0x07, 0xab, 0x6f, 0x01, 0x76, 0xd4,
  503. 0x73, 0x0d, 0x99, 0x0d, 0xbb, 0xe6, 0x36, 0x1c,
  504. 0xd8, 0xb2, 0xb9, 0x4d, 0x3d, 0x2f, 0x32, 0x9b,
  505. 0x82, 0x09, 0x9b, 0xd6, 0x61, 0xf4, 0x29, 0x50,
  506. 0xf4, 0x03, 0xdf, 0x3e, 0xde, 0x62, 0xa3, 0x31,
  507. 0x88, 0xb0, 0x27, 0x98, 0xba, 0x82, 0x3f, 0x44,
  508. 0xb9, 0x46, 0xfe, 0x9d, 0xf6, 0x77, 0xa0, 0xc5,
  509. 0xa1, 0x23, 0x8e, 0xaa, 0x97, 0xb7, 0x0f, 0x80,
  510. 0xda, 0x8c, 0xac, 0x88, 0xe0, 0x92, 0xb1, 0x12,
  511. 0x70, 0x60, 0xff, 0xbf, 0x45, 0x57, 0x99, 0x94,
  512. 0x01, 0x1d, 0xc2, 0xfa, 0xa5, 0xe7, 0xf6, 0xc7,
  513. 0x62, 0x45, 0xe1, 0xcc, 0x31, 0x22, 0x31, 0xc1,
  514. 0x7d, 0x1c, 0xa6, 0xb1, 0x90, 0x07, 0xef, 0x0d,
  515. 0xb9, 0x9f, 0x9c, 0xb6, 0x0e, 0x1d, 0x5f, 0x69
  516. };
  517. static const unsigned char dh_q[] = {
  518. 0x89, 0x8b, 0x22, 0x67, 0x17, 0xef, 0x03, 0x9e,
  519. 0x60, 0x3e, 0x82, 0xe5, 0xc7, 0xaf, 0xe4, 0x83,
  520. 0x74, 0xac, 0x5f, 0x62, 0x5c, 0x54, 0xf1, 0xea,
  521. 0x11, 0xac, 0xb5, 0x7d
  522. };
  523. static const unsigned char dh_g[] = {
  524. 0x5e, 0xf7, 0xb8, 0x8f, 0x2d, 0xf6, 0x01, 0x39,
  525. 0x35, 0x1d, 0xfb, 0xfe, 0x12, 0x66, 0x80, 0x5f,
  526. 0xdf, 0x35, 0x6c, 0xdf, 0xd1, 0x3a, 0x4d, 0xa0,
  527. 0x05, 0x0c, 0x7e, 0xde, 0x24, 0x6d, 0xf5, 0x9f,
  528. 0x6a, 0xbf, 0x96, 0xad, 0xe5, 0xf2, 0xb2, 0x8f,
  529. 0xfe, 0x88, 0xd6, 0xbc, 0xe7, 0xf7, 0x89, 0x4a,
  530. 0x3d, 0x53, 0x5f, 0xc8, 0x21, 0x26, 0xdd, 0xd4,
  531. 0x24, 0x87, 0x2e, 0x16, 0xb8, 0x38, 0xdf, 0x8c,
  532. 0x51, 0xe9, 0x01, 0x6f, 0x88, 0x9c, 0x7c, 0x20,
  533. 0x3e, 0x98, 0xa8, 0xb6, 0x31, 0xf9, 0xc7, 0x25,
  534. 0x63, 0xd3, 0x8a, 0x49, 0x58, 0x9a, 0x07, 0x53,
  535. 0xd3, 0x58, 0xe7, 0x83, 0x31, 0x8c, 0xef, 0xd9,
  536. 0x67, 0x7c, 0x7b, 0x2d, 0xbb, 0x77, 0xd6, 0xdc,
  537. 0xe2, 0xa1, 0x96, 0x37, 0x95, 0xca, 0x64, 0xb9,
  538. 0x2d, 0x1c, 0x9a, 0xac, 0x6d, 0x0e, 0x8d, 0x43,
  539. 0x1d, 0xe5, 0xe5, 0x00, 0x60, 0xdf, 0xf7, 0x86,
  540. 0x89, 0xc9, 0xec, 0xa1, 0xc1, 0x24, 0x8c, 0x16,
  541. 0xed, 0x09, 0xc7, 0xad, 0x41, 0x2a, 0x17, 0x40,
  542. 0x6d, 0x2b, 0x52, 0x5a, 0xa1, 0xca, 0xbb, 0x23,
  543. 0x7b, 0x97, 0x34, 0xec, 0x7b, 0x8c, 0xe3, 0xfa,
  544. 0xe0, 0x2f, 0x29, 0xc5, 0xef, 0xed, 0x30, 0xd6,
  545. 0x91, 0x87, 0xda, 0x10, 0x9c, 0x2c, 0x9f, 0xe2,
  546. 0xaa, 0xdb, 0xb0, 0xc2, 0x2a, 0xf5, 0x4c, 0x61,
  547. 0x66, 0x55, 0x00, 0x0c, 0x43, 0x1c, 0x6b, 0x4a,
  548. 0x37, 0x97, 0x63, 0xb0, 0xa9, 0x16, 0x58, 0xef,
  549. 0xc8, 0x4e, 0x8b, 0x06, 0x35, 0x8c, 0x8b, 0x4f,
  550. 0x21, 0x37, 0x10, 0xfd, 0x10, 0x17, 0x2c, 0xf3,
  551. 0x9b, 0x83, 0x0c, 0x2d, 0xd8, 0x4a, 0x0c, 0x8a,
  552. 0xb8, 0x25, 0x16, 0xec, 0xab, 0x99, 0x5f, 0xa4,
  553. 0x21, 0x5e, 0x02, 0x3e, 0x4e, 0xcf, 0x80, 0x74,
  554. 0xc3, 0x9d, 0x6c, 0x88, 0xb7, 0x0d, 0x1e, 0xe4,
  555. 0xe9, 0x6f, 0xdc, 0x20, 0xea, 0x11, 0x5c, 0x32
  556. };
  557. static const unsigned char dh_priv[] = {
  558. 0x14, 0x33, 0xe0, 0xb5, 0xa9, 0x17, 0xb6, 0x0a,
  559. 0x30, 0x23, 0xf2, 0xf8, 0xaa, 0x2c, 0x2d, 0x70,
  560. 0xd2, 0x96, 0x8a, 0xba, 0x9a, 0xea, 0xc8, 0x15,
  561. 0x40, 0xb8, 0xfc, 0xe6
  562. };
  563. static const unsigned char dh_pub[] = {
  564. 0x95, 0xdd, 0x33, 0x8d, 0x29, 0xe5, 0x71, 0x04,
  565. 0x92, 0xb9, 0x18, 0x31, 0x7b, 0x72, 0xa3, 0x69,
  566. 0x36, 0xe1, 0x95, 0x1a, 0x2e, 0xe5, 0xa5, 0x59,
  567. 0x16, 0x99, 0xc0, 0x48, 0x6d, 0x0d, 0x4f, 0x9b,
  568. 0xdd, 0x6d, 0x5a, 0x3f, 0x6b, 0x98, 0x89, 0x0c,
  569. 0x62, 0xb3, 0x76, 0x52, 0xd3, 0x6e, 0x71, 0x21,
  570. 0x11, 0xe6, 0x8a, 0x73, 0x55, 0x37, 0x25, 0x06,
  571. 0x99, 0xef, 0xe3, 0x30, 0x53, 0x73, 0x91, 0xfb,
  572. 0xc2, 0xc5, 0x48, 0xbc, 0x5a, 0xc3, 0xe5, 0xb2,
  573. 0x33, 0x86, 0xc3, 0xee, 0xf5, 0xeb, 0x43, 0xc0,
  574. 0x99, 0xd7, 0x0a, 0x52, 0x02, 0x68, 0x7e, 0x83,
  575. 0x96, 0x42, 0x48, 0xfc, 0xa9, 0x1f, 0x40, 0x90,
  576. 0x8e, 0x8f, 0xb3, 0x31, 0x93, 0x15, 0xf6, 0xd2,
  577. 0x60, 0x6d, 0x7f, 0x7c, 0xd5, 0x2c, 0xc6, 0xe7,
  578. 0xc5, 0x84, 0x3a, 0xfb, 0x22, 0x51, 0x9c, 0xf0,
  579. 0xf0, 0xf9, 0xd3, 0xa0, 0xa4, 0xe8, 0xc8, 0x88,
  580. 0x99, 0xef, 0xed, 0xe7, 0x36, 0x43, 0x51, 0xfb,
  581. 0x6a, 0x36, 0x3e, 0xe7, 0x17, 0xe5, 0x44, 0x5a,
  582. 0xda, 0xb4, 0xc9, 0x31, 0xa6, 0x48, 0x39, 0x97,
  583. 0xb8, 0x7d, 0xad, 0x83, 0x67, 0x7e, 0x4d, 0x1d,
  584. 0x3a, 0x77, 0x75, 0xe0, 0xf6, 0xd0, 0x0f, 0xdf,
  585. 0x73, 0xc7, 0xad, 0x80, 0x1e, 0x66, 0x5a, 0x0e,
  586. 0x5a, 0x79, 0x6d, 0x0a, 0x03, 0x80, 0xa1, 0x9f,
  587. 0xa1, 0x82, 0xef, 0xc8, 0xa0, 0x4f, 0x5e, 0x4d,
  588. 0xb9, 0x0d, 0x1a, 0x86, 0x37, 0xf9, 0x5d, 0xb1,
  589. 0x64, 0x36, 0xbd, 0xc8, 0xf3, 0xfc, 0x09, 0x6c,
  590. 0x4f, 0xf7, 0xf2, 0x34, 0xbe, 0x8f, 0xef, 0x47,
  591. 0x9a, 0xc4, 0xb0, 0xdc, 0x4b, 0x77, 0x26, 0x3e,
  592. 0x07, 0xd9, 0x95, 0x9d, 0xe0, 0xf1, 0xbf, 0x3f,
  593. 0x0a, 0xe3, 0xd9, 0xd5, 0x0e, 0x4b, 0x89, 0xc9,
  594. 0x9e, 0x3e, 0xa1, 0x21, 0x73, 0x43, 0xdd, 0x8c,
  595. 0x65, 0x81, 0xac, 0xc4, 0x95, 0x9c, 0x91, 0xd3
  596. };
  597. static const unsigned char dh_peer_pub[] = {
  598. 0x1f, 0xc1, 0xda, 0x34, 0x1d, 0x1a, 0x84, 0x6a,
  599. 0x96, 0xb7, 0xbe, 0x24, 0x34, 0x0f, 0x87, 0x7d,
  600. 0xd0, 0x10, 0xaa, 0x03, 0x56, 0xd5, 0xad, 0x58,
  601. 0xaa, 0xe9, 0xc7, 0xb0, 0x8f, 0x74, 0x9a, 0x32,
  602. 0x23, 0x51, 0x10, 0xb5, 0xd8, 0x8e, 0xb5, 0xdb,
  603. 0xfa, 0x97, 0x8d, 0x27, 0xec, 0xc5, 0x30, 0xf0,
  604. 0x2d, 0x31, 0x14, 0x00, 0x5b, 0x64, 0xb1, 0xc0,
  605. 0xe0, 0x24, 0xcb, 0x8a, 0xe2, 0x16, 0x98, 0xbc,
  606. 0xa9, 0xe6, 0x0d, 0x42, 0x80, 0x86, 0x22, 0xf1,
  607. 0x81, 0xc5, 0x6e, 0x1d, 0xe7, 0xa9, 0x6e, 0x6e,
  608. 0xfe, 0xe9, 0xd6, 0x65, 0x67, 0xe9, 0x1b, 0x97,
  609. 0x70, 0x42, 0xc7, 0xe3, 0xd0, 0x44, 0x8f, 0x05,
  610. 0xfb, 0x77, 0xf5, 0x22, 0xb9, 0xbf, 0xc8, 0xd3,
  611. 0x3c, 0xc3, 0xc3, 0x1e, 0xd3, 0xb3, 0x1f, 0x0f,
  612. 0xec, 0xb6, 0xdb, 0x4f, 0x6e, 0xa3, 0x11, 0xe7,
  613. 0x7a, 0xfd, 0xbc, 0xd4, 0x7a, 0xee, 0x1b, 0xb1,
  614. 0x50, 0xf2, 0x16, 0x87, 0x35, 0x78, 0xfb, 0x96,
  615. 0x46, 0x8e, 0x8f, 0x9f, 0x3d, 0xe8, 0xef, 0xbf,
  616. 0xce, 0x75, 0x62, 0x4b, 0x1d, 0xf0, 0x53, 0x22,
  617. 0xa3, 0x4f, 0x14, 0x63, 0xe8, 0x39, 0xe8, 0x98,
  618. 0x4c, 0x4a, 0xd0, 0xa9, 0x6e, 0x1a, 0xc8, 0x42,
  619. 0xe5, 0x31, 0x8c, 0xc2, 0x3c, 0x06, 0x2a, 0x8c,
  620. 0xa1, 0x71, 0xb8, 0xd5, 0x75, 0x98, 0x0d, 0xde,
  621. 0x7f, 0xc5, 0x6f, 0x15, 0x36, 0x52, 0x38, 0x20,
  622. 0xd4, 0x31, 0x92, 0xbf, 0xd5, 0x1e, 0x8e, 0x22,
  623. 0x89, 0x78, 0xac, 0xa5, 0xb9, 0x44, 0x72, 0xf3,
  624. 0x39, 0xca, 0xeb, 0x99, 0x31, 0xb4, 0x2b, 0xe3,
  625. 0x01, 0x26, 0x8b, 0xc9, 0x97, 0x89, 0xc9, 0xb2,
  626. 0x55, 0x71, 0xc3, 0xc0, 0xe4, 0xcb, 0x3f, 0x00,
  627. 0x7f, 0x1a, 0x51, 0x1c, 0xbb, 0x53, 0xc8, 0x51,
  628. 0x9c, 0xdd, 0x13, 0x02, 0xab, 0xca, 0x6c, 0x0f,
  629. 0x34, 0xf9, 0x67, 0x39, 0xf1, 0x7f, 0xf4, 0x8b
  630. };
  631. static const unsigned char dh_secret_expected[] = {
  632. 0x08, 0xff, 0x33, 0xbb, 0x2e, 0xcf, 0xf4, 0x9a,
  633. 0x7d, 0x4a, 0x79, 0x12, 0xae, 0xb1, 0xbb, 0x6a,
  634. 0xb5, 0x11, 0x64, 0x1b, 0x4a, 0x76, 0x77, 0x0c,
  635. 0x8c, 0xc1, 0xbc, 0xc2, 0x33, 0x34, 0x3d, 0xfe,
  636. 0x70, 0x0d, 0x11, 0x81, 0x3d, 0x2c, 0x9e, 0xd2,
  637. 0x3b, 0x21, 0x1c, 0xa9, 0xe8, 0x78, 0x69, 0x21,
  638. 0xed, 0xca, 0x28, 0x3c, 0x68, 0xb1, 0x61, 0x53,
  639. 0xfa, 0x01, 0xe9, 0x1a, 0xb8, 0x2c, 0x90, 0xdd,
  640. 0xab, 0x4a, 0x95, 0x81, 0x67, 0x70, 0xa9, 0x87,
  641. 0x10, 0xe1, 0x4c, 0x92, 0xab, 0x83, 0xb6, 0xe4,
  642. 0x6e, 0x1e, 0x42, 0x6e, 0xe8, 0x52, 0x43, 0x0d,
  643. 0x61, 0x87, 0xda, 0xa3, 0x72, 0x0a, 0x6b, 0xcd,
  644. 0x73, 0x23, 0x5c, 0x6b, 0x0f, 0x94, 0x1f, 0x33,
  645. 0x64, 0xf5, 0x04, 0x20, 0x55, 0x1a, 0x4b, 0xfe,
  646. 0xaf, 0xe2, 0xbc, 0x43, 0x85, 0x05, 0xa5, 0x9a,
  647. 0x4a, 0x40, 0xda, 0xca, 0x7a, 0x89, 0x5a, 0x73,
  648. 0xdb, 0x57, 0x5c, 0x74, 0xc1, 0x3a, 0x23, 0xad,
  649. 0x88, 0x32, 0x95, 0x7d, 0x58, 0x2d, 0x38, 0xf0,
  650. 0xa6, 0x16, 0x5f, 0xb0, 0xd7, 0xe9, 0xb8, 0x79,
  651. 0x9e, 0x42, 0xfd, 0x32, 0x20, 0xe3, 0x32, 0xe9,
  652. 0x81, 0x85, 0xa0, 0xc9, 0x42, 0x97, 0x57, 0xb2,
  653. 0xd0, 0xd0, 0x2c, 0x17, 0xdb, 0xaa, 0x1f, 0xf6,
  654. 0xed, 0x93, 0xd7, 0xe7, 0x3e, 0x24, 0x1e, 0xae,
  655. 0xd9, 0x0c, 0xaf, 0x39, 0x4d, 0x2b, 0xc6, 0x57,
  656. 0x0f, 0x18, 0xc8, 0x1f, 0x2b, 0xe5, 0xd0, 0x1a,
  657. 0x2c, 0xa9, 0x9f, 0xf1, 0x42, 0xb5, 0xd9, 0x63,
  658. 0xf9, 0xf5, 0x00, 0x32, 0x5e, 0x75, 0x56, 0xf9,
  659. 0x58, 0x49, 0xb3, 0xff, 0xc7, 0x47, 0x94, 0x86,
  660. 0xbe, 0x1d, 0x45, 0x96, 0xa3, 0x10, 0x6b, 0xd5,
  661. 0xcb, 0x4f, 0x61, 0xc5, 0x7e, 0xc5, 0xf1, 0x00,
  662. 0xfb, 0x7a, 0x0c, 0x82, 0xa1, 0x0b, 0x82, 0x52,
  663. 0x6a, 0x97, 0xd1, 0xd9, 0x7d, 0x98, 0xea, 0xf6
  664. };
  665. static const ST_KAT_PARAM dh_group[] = {
  666. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_FFC_P, dh_p),
  667. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_FFC_Q, dh_q),
  668. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_FFC_G, dh_g),
  669. ST_KAT_PARAM_END()
  670. };
  671. /* The host's private key */
  672. static const ST_KAT_PARAM dh_host_key[] = {
  673. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_PUB_KEY, dh_pub),
  674. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_PRIV_KEY, dh_priv),
  675. ST_KAT_PARAM_END()
  676. };
  677. /* The peer's public key */
  678. static const ST_KAT_PARAM dh_peer_key[] = {
  679. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_PUB_KEY, dh_peer_pub),
  680. ST_KAT_PARAM_END()
  681. };
  682. #endif /* OPENSSL_NO_DH */
  683. #ifndef OPENSSL_NO_EC
  684. static const char ecdh_curve_name[] = "prime256v1";
  685. static const unsigned char ecdh_privd[] = {
  686. 0x33, 0xd0, 0x43, 0x83, 0xa9, 0x89, 0x56, 0x03,
  687. 0xd2, 0xd7, 0xfe, 0x6b, 0x01, 0x6f, 0xe4, 0x59,
  688. 0xcc, 0x0d, 0x9a, 0x24, 0x6c, 0x86, 0x1b, 0x2e,
  689. 0xdc, 0x4b, 0x4d, 0x35, 0x43, 0xe1, 0x1b, 0xad
  690. };
  691. static const unsigned char ecdh_pub[] = {
  692. 0x04,
  693. 0x1b, 0x93, 0x67, 0x55, 0x1c, 0x55, 0x9f, 0x63,
  694. 0xd1, 0x22, 0xa4, 0xd8, 0xd1, 0x0a, 0x60, 0x6d,
  695. 0x02, 0xa5, 0x77, 0x57, 0xc8, 0xa3, 0x47, 0x73,
  696. 0x3a, 0x6a, 0x08, 0x28, 0x39, 0xbd, 0xc9, 0xd2,
  697. 0x80, 0xec, 0xe9, 0xa7, 0x08, 0x29, 0x71, 0x2f,
  698. 0xc9, 0x56, 0x82, 0xee, 0x9a, 0x85, 0x0f, 0x6d,
  699. 0x7f, 0x59, 0x5f, 0x8c, 0xd1, 0x96, 0x0b, 0xdf,
  700. 0x29, 0x3e, 0x49, 0x07, 0x88, 0x3f, 0x9a, 0x29
  701. };
  702. static const unsigned char ecdh_peer_pub[] = {
  703. 0x04,
  704. 0x1f, 0x72, 0xbd, 0x2a, 0x3e, 0xeb, 0x6c, 0x76,
  705. 0xe5, 0x5d, 0x69, 0x75, 0x24, 0xbf, 0x2f, 0x5b,
  706. 0x96, 0xb2, 0x91, 0x62, 0x06, 0x35, 0xcc, 0xb2,
  707. 0x4b, 0x31, 0x1b, 0x0c, 0x6f, 0x06, 0x9f, 0x86,
  708. 0xcf, 0xc8, 0xac, 0xd5, 0x4f, 0x4d, 0x77, 0xf3,
  709. 0x70, 0x4a, 0x8f, 0x04, 0x9a, 0xb1, 0x03, 0xc7,
  710. 0xeb, 0xd5, 0x94, 0x78, 0x61, 0xab, 0x78, 0x0c,
  711. 0x4a, 0x2d, 0x6b, 0xf3, 0x2f, 0x2e, 0x4a, 0xbc
  712. };
  713. static const ST_KAT_PARAM ecdh_group[] = {
  714. ST_KAT_PARAM_UTF8STRING(OSSL_PKEY_PARAM_GROUP_NAME, ecdh_curve_name),
  715. ST_KAT_PARAM_END()
  716. };
  717. static const ST_KAT_PARAM ecdh_host_key[] = {
  718. ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_PUB_KEY, ecdh_pub),
  719. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_PRIV_KEY, ecdh_privd),
  720. ST_KAT_PARAM_END()
  721. };
  722. static const ST_KAT_PARAM ecdh_peer_key[] = {
  723. ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_PUB_KEY, ecdh_peer_pub),
  724. ST_KAT_PARAM_END()
  725. };
  726. static const unsigned char ecdh_secret_expected[] = {
  727. 0x45, 0x2a, 0x2f, 0x0d, 0x24, 0xe6, 0x8d, 0xd0,
  728. 0xda, 0x59, 0x7b, 0x0c, 0xec, 0x9b, 0x4c, 0x38,
  729. 0x41, 0xdd, 0xce, 0xb3, 0xcc, 0xf1, 0x90, 0x8e,
  730. 0x30, 0xdb, 0x5b, 0x5f, 0x97, 0xea, 0xe0, 0xc2
  731. };
  732. #endif /* OPENSSL_NO_EC */
  733. static const ST_KAT_KAS st_kat_kas_tests[] =
  734. {
  735. #ifndef OPENSSL_NO_DH
  736. {
  737. OSSL_SELF_TEST_DESC_KA_DH,
  738. "DH",
  739. dh_group,
  740. dh_host_key,
  741. dh_peer_key,
  742. ITM(dh_secret_expected)
  743. },
  744. #endif /* OPENSSL_NO_DH */
  745. #ifndef OPENSSL_NO_EC
  746. {
  747. OSSL_SELF_TEST_DESC_KA_ECDH,
  748. "EC",
  749. ecdh_group,
  750. ecdh_host_key,
  751. ecdh_peer_key,
  752. ITM(ecdh_secret_expected)
  753. },
  754. #endif /* OPENSSL_NO_EC */
  755. };
  756. #if !defined(OPENSSL_NO_RSA)
  757. /* RSA key data */
  758. static const unsigned char rsa_n[] = {
  759. 0xDB, 0x10, 0x1A, 0xC2, 0xA3, 0xF1, 0xDC, 0xFF,
  760. 0x13, 0x6B, 0xED, 0x44, 0xDF, 0xF0, 0x02, 0x6D,
  761. 0x13, 0xC7, 0x88, 0xDA, 0x70, 0x6B, 0x54, 0xF1,
  762. 0xE8, 0x27, 0xDC, 0xC3, 0x0F, 0x99, 0x6A, 0xFA,
  763. 0xC6, 0x67, 0xFF, 0x1D, 0x1E, 0x3C, 0x1D, 0xC1,
  764. 0xB5, 0x5F, 0x6C, 0xC0, 0xB2, 0x07, 0x3A, 0x6D,
  765. 0x41, 0xE4, 0x25, 0x99, 0xAC, 0xFC, 0xD2, 0x0F,
  766. 0x02, 0xD3, 0xD1, 0x54, 0x06, 0x1A, 0x51, 0x77,
  767. 0xBD, 0xB6, 0xBF, 0xEA, 0xA7, 0x5C, 0x06, 0xA9,
  768. 0x5D, 0x69, 0x84, 0x45, 0xD7, 0xF5, 0x05, 0xBA,
  769. 0x47, 0xF0, 0x1B, 0xD7, 0x2B, 0x24, 0xEC, 0xCB,
  770. 0x9B, 0x1B, 0x10, 0x8D, 0x81, 0xA0, 0xBE, 0xB1,
  771. 0x8C, 0x33, 0xE4, 0x36, 0xB8, 0x43, 0xEB, 0x19,
  772. 0x2A, 0x81, 0x8D, 0xDE, 0x81, 0x0A, 0x99, 0x48,
  773. 0xB6, 0xF6, 0xBC, 0xCD, 0x49, 0x34, 0x3A, 0x8F,
  774. 0x26, 0x94, 0xE3, 0x28, 0x82, 0x1A, 0x7C, 0x8F,
  775. 0x59, 0x9F, 0x45, 0xE8, 0x5D, 0x1A, 0x45, 0x76,
  776. 0x04, 0x56, 0x05, 0xA1, 0xD0, 0x1B, 0x8C, 0x77,
  777. 0x6D, 0xAF, 0x53, 0xFA, 0x71, 0xE2, 0x67, 0xE0,
  778. 0x9A, 0xFE, 0x03, 0xA9, 0x85, 0xD2, 0xC9, 0xAA,
  779. 0xBA, 0x2A, 0xBC, 0xF4, 0xA0, 0x08, 0xF5, 0x13,
  780. 0x98, 0x13, 0x5D, 0xF0, 0xD9, 0x33, 0x34, 0x2A,
  781. 0x61, 0xC3, 0x89, 0x55, 0xF0, 0xAE, 0x1A, 0x9C,
  782. 0x22, 0xEE, 0x19, 0x05, 0x8D, 0x32, 0xFE, 0xEC,
  783. 0x9C, 0x84, 0xBA, 0xB7, 0xF9, 0x6C, 0x3A, 0x4F,
  784. 0x07, 0xFC, 0x45, 0xEB, 0x12, 0xE5, 0x7B, 0xFD,
  785. 0x55, 0xE6, 0x29, 0x69, 0xD1, 0xC2, 0xE8, 0xB9,
  786. 0x78, 0x59, 0xF6, 0x79, 0x10, 0xC6, 0x4E, 0xEB,
  787. 0x6A, 0x5E, 0xB9, 0x9A, 0xC7, 0xC4, 0x5B, 0x63,
  788. 0xDA, 0xA3, 0x3F, 0x5E, 0x92, 0x7A, 0x81, 0x5E,
  789. 0xD6, 0xB0, 0xE2, 0x62, 0x8F, 0x74, 0x26, 0xC2,
  790. 0x0C, 0xD3, 0x9A, 0x17, 0x47, 0xE6, 0x8E, 0xAB
  791. };
  792. static const unsigned char rsa_e[] = { 0x01, 0x00, 0x01 };
  793. static const unsigned char rsa_d[] = {
  794. 0x52, 0x41, 0xF4, 0xDA, 0x7B, 0xB7, 0x59, 0x55,
  795. 0xCA, 0xD4, 0x2F, 0x0F, 0x3A, 0xCB, 0xA4, 0x0D,
  796. 0x93, 0x6C, 0xCC, 0x9D, 0xC1, 0xB2, 0xFB, 0xFD,
  797. 0xAE, 0x40, 0x31, 0xAC, 0x69, 0x52, 0x21, 0x92,
  798. 0xB3, 0x27, 0xDF, 0xEA, 0xEE, 0x2C, 0x82, 0xBB,
  799. 0xF7, 0x40, 0x32, 0xD5, 0x14, 0xC4, 0x94, 0x12,
  800. 0xEC, 0xB8, 0x1F, 0xCA, 0x59, 0xE3, 0xC1, 0x78,
  801. 0xF3, 0x85, 0xD8, 0x47, 0xA5, 0xD7, 0x02, 0x1A,
  802. 0x65, 0x79, 0x97, 0x0D, 0x24, 0xF4, 0xF0, 0x67,
  803. 0x6E, 0x75, 0x2D, 0xBF, 0x10, 0x3D, 0xA8, 0x7D,
  804. 0xEF, 0x7F, 0x60, 0xE4, 0xE6, 0x05, 0x82, 0x89,
  805. 0x5D, 0xDF, 0xC6, 0xD2, 0x6C, 0x07, 0x91, 0x33,
  806. 0x98, 0x42, 0xF0, 0x02, 0x00, 0x25, 0x38, 0xC5,
  807. 0x85, 0x69, 0x8A, 0x7D, 0x2F, 0x95, 0x6C, 0x43,
  808. 0x9A, 0xB8, 0x81, 0xE2, 0xD0, 0x07, 0x35, 0xAA,
  809. 0x05, 0x41, 0xC9, 0x1E, 0xAF, 0xE4, 0x04, 0x3B,
  810. 0x19, 0xB8, 0x73, 0xA2, 0xAC, 0x4B, 0x1E, 0x66,
  811. 0x48, 0xD8, 0x72, 0x1F, 0xAC, 0xF6, 0xCB, 0xBC,
  812. 0x90, 0x09, 0xCA, 0xEC, 0x0C, 0xDC, 0xF9, 0x2C,
  813. 0xD7, 0xEB, 0xAE, 0xA3, 0xA4, 0x47, 0xD7, 0x33,
  814. 0x2F, 0x8A, 0xCA, 0xBC, 0x5E, 0xF0, 0x77, 0xE4,
  815. 0x97, 0x98, 0x97, 0xC7, 0x10, 0x91, 0x7D, 0x2A,
  816. 0xA6, 0xFF, 0x46, 0x83, 0x97, 0xDE, 0xE9, 0xE2,
  817. 0x17, 0x03, 0x06, 0x14, 0xE2, 0xD7, 0xB1, 0x1D,
  818. 0x77, 0xAF, 0x51, 0x27, 0x5B, 0x5E, 0x69, 0xB8,
  819. 0x81, 0xE6, 0x11, 0xC5, 0x43, 0x23, 0x81, 0x04,
  820. 0x62, 0xFF, 0xE9, 0x46, 0xB8, 0xD8, 0x44, 0xDB,
  821. 0xA5, 0xCC, 0x31, 0x54, 0x34, 0xCE, 0x3E, 0x82,
  822. 0xD6, 0xBF, 0x7A, 0x0B, 0x64, 0x21, 0x6D, 0x88,
  823. 0x7E, 0x5B, 0x45, 0x12, 0x1E, 0x63, 0x8D, 0x49,
  824. 0xA7, 0x1D, 0xD9, 0x1E, 0x06, 0xCD, 0xE8, 0xBA,
  825. 0x2C, 0x8C, 0x69, 0x32, 0xEA, 0xBE, 0x60, 0x71
  826. };
  827. static const unsigned char rsa_p[] = {
  828. 0xFA, 0xAC, 0xE1, 0x37, 0x5E, 0x32, 0x11, 0x34,
  829. 0xC6, 0x72, 0x58, 0x2D, 0x91, 0x06, 0x3E, 0x77,
  830. 0xE7, 0x11, 0x21, 0xCD, 0x4A, 0xF8, 0xA4, 0x3F,
  831. 0x0F, 0xEF, 0x31, 0xE3, 0xF3, 0x55, 0xA0, 0xB9,
  832. 0xAC, 0xB6, 0xCB, 0xBB, 0x41, 0xD0, 0x32, 0x81,
  833. 0x9A, 0x8F, 0x7A, 0x99, 0x30, 0x77, 0x6C, 0x68,
  834. 0x27, 0xE2, 0x96, 0xB5, 0x72, 0xC9, 0xC3, 0xD4,
  835. 0x42, 0xAA, 0xAA, 0xCA, 0x95, 0x8F, 0xFF, 0xC9,
  836. 0x9B, 0x52, 0x34, 0x30, 0x1D, 0xCF, 0xFE, 0xCF,
  837. 0x3C, 0x56, 0x68, 0x6E, 0xEF, 0xE7, 0x6C, 0xD7,
  838. 0xFB, 0x99, 0xF5, 0x4A, 0xA5, 0x21, 0x1F, 0x2B,
  839. 0xEA, 0x93, 0xE8, 0x98, 0x26, 0xC4, 0x6E, 0x42,
  840. 0x21, 0x5E, 0xA0, 0xA1, 0x2A, 0x58, 0x35, 0xBB,
  841. 0x10, 0xE7, 0xBA, 0x27, 0x0A, 0x3B, 0xB3, 0xAF,
  842. 0xE2, 0x75, 0x36, 0x04, 0xAC, 0x56, 0xA0, 0xAB,
  843. 0x52, 0xDE, 0xCE, 0xDD, 0x2C, 0x28, 0x77, 0x03
  844. };
  845. static const unsigned char rsa_q[] = {
  846. 0xDF, 0xB7, 0x52, 0xB6, 0xD7, 0xC0, 0xE2, 0x96,
  847. 0xE7, 0xC9, 0xFE, 0x5D, 0x71, 0x5A, 0xC4, 0x40,
  848. 0x96, 0x2F, 0xE5, 0x87, 0xEA, 0xF3, 0xA5, 0x77,
  849. 0x11, 0x67, 0x3C, 0x8D, 0x56, 0x08, 0xA7, 0xB5,
  850. 0x67, 0xFA, 0x37, 0xA8, 0xB8, 0xCF, 0x61, 0xE8,
  851. 0x63, 0xD8, 0x38, 0x06, 0x21, 0x2B, 0x92, 0x09,
  852. 0xA6, 0x39, 0x3A, 0xEA, 0xA8, 0xB4, 0x45, 0x4B,
  853. 0x36, 0x10, 0x4C, 0xE4, 0x00, 0x66, 0x71, 0x65,
  854. 0xF8, 0x0B, 0x94, 0x59, 0x4F, 0x8C, 0xFD, 0xD5,
  855. 0x34, 0xA2, 0xE7, 0x62, 0x84, 0x0A, 0xA7, 0xBB,
  856. 0xDB, 0xD9, 0x8A, 0xCD, 0x05, 0xE1, 0xCC, 0x57,
  857. 0x7B, 0xF1, 0xF1, 0x1F, 0x11, 0x9D, 0xBA, 0x3E,
  858. 0x45, 0x18, 0x99, 0x1B, 0x41, 0x64, 0x43, 0xEE,
  859. 0x97, 0x5D, 0x77, 0x13, 0x5B, 0x74, 0x69, 0x73,
  860. 0x87, 0x95, 0x05, 0x07, 0xBE, 0x45, 0x07, 0x17,
  861. 0x7E, 0x4A, 0x69, 0x22, 0xF3, 0xDB, 0x05, 0x39
  862. };
  863. static const unsigned char rsa_dp[] = {
  864. 0x5E, 0xD8, 0xDC, 0xDA, 0x53, 0x44, 0xC4, 0x67,
  865. 0xE0, 0x92, 0x51, 0x34, 0xE4, 0x83, 0xA5, 0x4D,
  866. 0x3E, 0xDB, 0xA7, 0x9B, 0x82, 0xBB, 0x73, 0x81,
  867. 0xFC, 0xE8, 0x77, 0x4B, 0x15, 0xBE, 0x17, 0x73,
  868. 0x49, 0x9B, 0x5C, 0x98, 0xBC, 0xBD, 0x26, 0xEF,
  869. 0x0C, 0xE9, 0x2E, 0xED, 0x19, 0x7E, 0x86, 0x41,
  870. 0x1E, 0x9E, 0x48, 0x81, 0xDD, 0x2D, 0xE4, 0x6F,
  871. 0xC2, 0xCD, 0xCA, 0x93, 0x9E, 0x65, 0x7E, 0xD5,
  872. 0xEC, 0x73, 0xFD, 0x15, 0x1B, 0xA2, 0xA0, 0x7A,
  873. 0x0F, 0x0D, 0x6E, 0xB4, 0x53, 0x07, 0x90, 0x92,
  874. 0x64, 0x3B, 0x8B, 0xA9, 0x33, 0xB3, 0xC5, 0x94,
  875. 0x9B, 0x4C, 0x5D, 0x9C, 0x7C, 0x46, 0xA4, 0xA5,
  876. 0x56, 0xF4, 0xF3, 0xF8, 0x27, 0x0A, 0x7B, 0x42,
  877. 0x0D, 0x92, 0x70, 0x47, 0xE7, 0x42, 0x51, 0xA9,
  878. 0xC2, 0x18, 0xB1, 0x58, 0xB1, 0x50, 0x91, 0xB8,
  879. 0x61, 0x41, 0xB6, 0xA9, 0xCE, 0xD4, 0x7C, 0xBB
  880. };
  881. static const unsigned char rsa_dq[] = {
  882. 0x54, 0x09, 0x1F, 0x0F, 0x03, 0xD8, 0xB6, 0xC5,
  883. 0x0C, 0xE8, 0xB9, 0x9E, 0x0C, 0x38, 0x96, 0x43,
  884. 0xD4, 0xA6, 0xC5, 0x47, 0xDB, 0x20, 0x0E, 0xE5,
  885. 0xBD, 0x29, 0xD4, 0x7B, 0x1A, 0xF8, 0x41, 0x57,
  886. 0x49, 0x69, 0x9A, 0x82, 0xCC, 0x79, 0x4A, 0x43,
  887. 0xEB, 0x4D, 0x8B, 0x2D, 0xF2, 0x43, 0xD5, 0xA5,
  888. 0xBE, 0x44, 0xFD, 0x36, 0xAC, 0x8C, 0x9B, 0x02,
  889. 0xF7, 0x9A, 0x03, 0xE8, 0x19, 0xA6, 0x61, 0xAE,
  890. 0x76, 0x10, 0x93, 0x77, 0x41, 0x04, 0xAB, 0x4C,
  891. 0xED, 0x6A, 0xCC, 0x14, 0x1B, 0x99, 0x8D, 0x0C,
  892. 0x6A, 0x37, 0x3B, 0x86, 0x6C, 0x51, 0x37, 0x5B,
  893. 0x1D, 0x79, 0xF2, 0xA3, 0x43, 0x10, 0xC6, 0xA7,
  894. 0x21, 0x79, 0x6D, 0xF9, 0xE9, 0x04, 0x6A, 0xE8,
  895. 0x32, 0xFF, 0xAE, 0xFD, 0x1C, 0x7B, 0x8C, 0x29,
  896. 0x13, 0xA3, 0x0C, 0xB2, 0xAD, 0xEC, 0x6C, 0x0F,
  897. 0x8D, 0x27, 0x12, 0x7B, 0x48, 0xB2, 0xDB, 0x31
  898. };
  899. static const unsigned char rsa_qInv[] = {
  900. 0x8D, 0x1B, 0x05, 0xCA, 0x24, 0x1F, 0x0C, 0x53,
  901. 0x19, 0x52, 0x74, 0x63, 0x21, 0xFA, 0x78, 0x46,
  902. 0x79, 0xAF, 0x5C, 0xDE, 0x30, 0xA4, 0x6C, 0x20,
  903. 0x38, 0xE6, 0x97, 0x39, 0xB8, 0x7A, 0x70, 0x0D,
  904. 0x8B, 0x6C, 0x6D, 0x13, 0x74, 0xD5, 0x1C, 0xDE,
  905. 0xA9, 0xF4, 0x60, 0x37, 0xFE, 0x68, 0x77, 0x5E,
  906. 0x0B, 0x4E, 0x5E, 0x03, 0x31, 0x30, 0xDF, 0xD6,
  907. 0xAE, 0x85, 0xD0, 0x81, 0xBB, 0x61, 0xC7, 0xB1,
  908. 0x04, 0x5A, 0xC4, 0x6D, 0x56, 0x1C, 0xD9, 0x64,
  909. 0xE7, 0x85, 0x7F, 0x88, 0x91, 0xC9, 0x60, 0x28,
  910. 0x05, 0xE2, 0xC6, 0x24, 0x8F, 0xDD, 0x61, 0x64,
  911. 0xD8, 0x09, 0xDE, 0x7E, 0xD3, 0x4A, 0x61, 0x1A,
  912. 0xD3, 0x73, 0x58, 0x4B, 0xD8, 0xA0, 0x54, 0x25,
  913. 0x48, 0x83, 0x6F, 0x82, 0x6C, 0xAF, 0x36, 0x51,
  914. 0x2A, 0x5D, 0x14, 0x2F, 0x41, 0x25, 0x00, 0xDD,
  915. 0xF8, 0xF3, 0x95, 0xFE, 0x31, 0x25, 0x50, 0x12
  916. };
  917. static const ST_KAT_PARAM rsa_crt_key[] = {
  918. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_N, rsa_n),
  919. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_E, rsa_e),
  920. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_D, rsa_d),
  921. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_FACTOR, rsa_p),
  922. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_FACTOR, rsa_q),
  923. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_EXPONENT, rsa_dp),
  924. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_EXPONENT, rsa_dq),
  925. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_COEFFICIENT, rsa_qInv),
  926. ST_KAT_PARAM_END()
  927. };
  928. static const ST_KAT_PARAM rsa_pub_key[] = {
  929. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_N, rsa_n),
  930. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_E, rsa_e),
  931. ST_KAT_PARAM_END()
  932. };
  933. static const ST_KAT_PARAM rsa_priv_key[] = {
  934. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_N, rsa_n),
  935. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_E, rsa_e),
  936. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_RSA_D, rsa_d),
  937. ST_KAT_PARAM_END()
  938. };
  939. static const ST_KAT_PARAM rsa_enc_params[] = {
  940. ST_KAT_PARAM_UTF8STRING(OSSL_ASYM_CIPHER_PARAM_PAD_MODE,
  941. OSSL_PKEY_RSA_PAD_MODE_NONE),
  942. ST_KAT_PARAM_END()
  943. };
  944. static const unsigned char rsa_expected_sig[256] = {
  945. 0xad, 0xbe, 0x2a, 0xaf, 0x16, 0x85, 0xc5, 0x00,
  946. 0x91, 0x3e, 0xd0, 0x49, 0xfb, 0x3a, 0x81, 0xb9,
  947. 0x6c, 0x28, 0xbc, 0xbf, 0xea, 0x96, 0x5f, 0xe4,
  948. 0x9f, 0x99, 0xf7, 0x18, 0x8c, 0xec, 0x60, 0x28,
  949. 0xeb, 0x29, 0x02, 0x49, 0xfc, 0xda, 0xd7, 0x78,
  950. 0x68, 0xf8, 0xe1, 0xe9, 0x4d, 0x20, 0x6d, 0x32,
  951. 0xa6, 0xde, 0xfc, 0xe4, 0xda, 0xcc, 0x6c, 0x75,
  952. 0x36, 0x6b, 0xff, 0x5a, 0xac, 0x01, 0xa8, 0xc2,
  953. 0xa9, 0xe6, 0x8b, 0x18, 0x3e, 0xec, 0xea, 0x4c,
  954. 0x4a, 0x9e, 0x00, 0x09, 0xd1, 0x8a, 0x69, 0x1b,
  955. 0x8b, 0xd9, 0xad, 0x37, 0xe5, 0x7c, 0xff, 0x7d,
  956. 0x59, 0x56, 0x3e, 0xa0, 0xc6, 0x32, 0xd8, 0x35,
  957. 0x2f, 0xff, 0xfb, 0x05, 0x02, 0xcd, 0xd7, 0x19,
  958. 0xb9, 0x00, 0x86, 0x2a, 0xcf, 0xaa, 0x78, 0x16,
  959. 0x4b, 0xf1, 0xa7, 0x59, 0xef, 0x7d, 0xe8, 0x74,
  960. 0x23, 0x5c, 0xb2, 0xd4, 0x8a, 0x99, 0xa5, 0xbc,
  961. 0xfa, 0x63, 0xd8, 0xf7, 0xbd, 0xc6, 0x00, 0x13,
  962. 0x06, 0x02, 0x9a, 0xd4, 0xa7, 0xb4, 0x3d, 0x61,
  963. 0xab, 0xf1, 0xc2, 0x95, 0x59, 0x9b, 0x3d, 0x67,
  964. 0x1f, 0xde, 0x57, 0xb6, 0xb6, 0x9f, 0xb0, 0x87,
  965. 0xd6, 0x51, 0xd5, 0x3e, 0x00, 0xe2, 0xc9, 0xa0,
  966. 0x03, 0x66, 0xbc, 0x01, 0xb3, 0x8e, 0xfa, 0xf1,
  967. 0x15, 0xeb, 0x26, 0xf1, 0x5d, 0x81, 0x90, 0xb4,
  968. 0x1c, 0x00, 0x7c, 0x83, 0x4a, 0xa5, 0xde, 0x64,
  969. 0xae, 0xea, 0x6c, 0x43, 0xc3, 0x20, 0x77, 0x77,
  970. 0x42, 0x12, 0x24, 0xf5, 0xe3, 0x70, 0xdd, 0x59,
  971. 0x48, 0x9c, 0xef, 0xd4, 0x8a, 0x3c, 0x29, 0x6a,
  972. 0x0c, 0x9c, 0xf2, 0x13, 0xa4, 0x1c, 0x2f, 0x49,
  973. 0xcd, 0xb4, 0xaa, 0x28, 0x40, 0x34, 0xc6, 0x75,
  974. 0xba, 0x30, 0xe6, 0xd8, 0x5b, 0x2f, 0x08, 0xd0,
  975. 0x29, 0xa5, 0x39, 0xfb, 0x6e, 0x3b, 0x0f, 0x52,
  976. 0x2c, 0x68, 0xf0, 0x37, 0xa9, 0xd2, 0x56, 0xd6
  977. };
  978. static const unsigned char rsa_asym_plaintext_encrypt[256] = {
  979. 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08,
  980. 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10,
  981. };
  982. static const unsigned char rsa_asym_expected_encrypt[256] = {
  983. 0x54, 0xac, 0x23, 0x96, 0x1d, 0x82, 0x5d, 0x8b,
  984. 0x8f, 0x36, 0x33, 0xd0, 0xf4, 0x02, 0xa2, 0x61,
  985. 0xb1, 0x13, 0xd4, 0x4a, 0x46, 0x06, 0x37, 0x3c,
  986. 0xbf, 0x40, 0x05, 0x3c, 0xc6, 0x3b, 0x64, 0xdc,
  987. 0x22, 0x22, 0xaf, 0x36, 0x79, 0x62, 0x45, 0xf0,
  988. 0x97, 0x82, 0x22, 0x44, 0x86, 0x4a, 0x7c, 0xfa,
  989. 0xac, 0x03, 0x21, 0x84, 0x3f, 0x31, 0xad, 0x2a,
  990. 0xa4, 0x6e, 0x7a, 0xc5, 0x93, 0xf3, 0x0f, 0xfc,
  991. 0xf1, 0x62, 0xce, 0x82, 0x12, 0x45, 0xc9, 0x35,
  992. 0xb0, 0x7a, 0xcd, 0x99, 0x8c, 0x91, 0x6b, 0x5a,
  993. 0xd3, 0x46, 0xdb, 0xf9, 0x9e, 0x52, 0x49, 0xbd,
  994. 0x1e, 0xe8, 0xda, 0xac, 0x61, 0x47, 0xc2, 0xda,
  995. 0xfc, 0x1e, 0xfb, 0x74, 0xd7, 0xd6, 0xc1, 0x18,
  996. 0x86, 0x3e, 0x20, 0x9c, 0x7a, 0xe1, 0x04, 0xb7,
  997. 0x38, 0x43, 0xb1, 0x4e, 0xa0, 0xd8, 0xc1, 0x39,
  998. 0x4d, 0xe1, 0xd3, 0xb0, 0xb3, 0xf1, 0x82, 0x87,
  999. 0x1f, 0x74, 0xb5, 0x69, 0xfd, 0x33, 0xd6, 0x21,
  1000. 0x7c, 0x61, 0x60, 0x28, 0xca, 0x70, 0xdb, 0xa0,
  1001. 0xbb, 0xc8, 0x73, 0xa9, 0x82, 0xf8, 0x6b, 0xd8,
  1002. 0xf0, 0xc9, 0x7b, 0x20, 0xdf, 0x9d, 0xfb, 0x8c,
  1003. 0xd4, 0xa2, 0x89, 0xe1, 0x9b, 0x04, 0xad, 0xaa,
  1004. 0x11, 0x6c, 0x8f, 0xce, 0x83, 0x29, 0x56, 0x69,
  1005. 0xbb, 0x00, 0x3b, 0xef, 0xca, 0x2d, 0xcd, 0x52,
  1006. 0xc8, 0xf1, 0xb3, 0x9b, 0xb4, 0x4f, 0x6d, 0x9c,
  1007. 0x3d, 0x69, 0xcc, 0x6d, 0x1f, 0x38, 0x4d, 0xe6,
  1008. 0xbb, 0x0c, 0x87, 0xdc, 0x5f, 0xa9, 0x24, 0x93,
  1009. 0x03, 0x46, 0xa2, 0x33, 0x6c, 0xf4, 0xd8, 0x5d,
  1010. 0x68, 0xf3, 0xd3, 0xe0, 0xf2, 0x30, 0xdb, 0xf5,
  1011. 0x4f, 0x0f, 0xad, 0xc7, 0xd0, 0xaa, 0x47, 0xd9,
  1012. 0x9f, 0x85, 0x1b, 0x2e, 0x6c, 0x3c, 0x57, 0x04,
  1013. 0x29, 0xf4, 0xf5, 0x66, 0x7d, 0x93, 0x4a, 0xaa,
  1014. 0x05, 0x52, 0x55, 0xc1, 0xc6, 0x06, 0x90, 0xab,
  1015. };
  1016. #endif /* OPENSSL_NO_RSA */
  1017. #ifndef OPENSSL_NO_EC
  1018. /* ECDSA key data */
  1019. static const char ecd_curve_name[] = "secp224r1";
  1020. static const unsigned char ecd_priv[] = {
  1021. 0x98, 0x1f, 0xb5, 0xf1, 0xfc, 0x87, 0x1d, 0x7d,
  1022. 0xde, 0x1e, 0x01, 0x64, 0x09, 0x9b, 0xe7, 0x1b,
  1023. 0x9f, 0xad, 0x63, 0xdd, 0x33, 0x01, 0xd1, 0x50,
  1024. 0x80, 0x93, 0x50, 0x30
  1025. };
  1026. static const unsigned char ecd_pub[] = {
  1027. 0x04, 0x95, 0x47, 0x99, 0x44, 0x29, 0x8f, 0x51,
  1028. 0x39, 0xe2, 0x53, 0xec, 0x79, 0xb0, 0x4d, 0xde,
  1029. 0x87, 0x1a, 0x76, 0x54, 0xd5, 0x96, 0xb8, 0x7a,
  1030. 0x6d, 0xf4, 0x1c, 0x2c, 0x87, 0x91, 0x5f, 0xd5,
  1031. 0x31, 0xdd, 0x24, 0xe5, 0x78, 0xd9, 0x08, 0x24,
  1032. 0x8a, 0x49, 0x99, 0xec, 0x55, 0xf2, 0x82, 0xb3,
  1033. 0xc4, 0xb7, 0x33, 0x68, 0xe4, 0x24, 0xa9, 0x12,
  1034. 0x82
  1035. };
  1036. static const ST_KAT_PARAM ecdsa_key[] = {
  1037. ST_KAT_PARAM_UTF8STRING(OSSL_PKEY_PARAM_GROUP_NAME, ecd_curve_name),
  1038. ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_PUB_KEY, ecd_pub),
  1039. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_PRIV_KEY, ecd_priv),
  1040. ST_KAT_PARAM_END()
  1041. };
  1042. #endif /* OPENSSL_NO_EC */
  1043. #ifndef OPENSSL_NO_DSA
  1044. /* dsa 2048 */
  1045. static const unsigned char dsa_p[] = {
  1046. 0xa2, 0x9b, 0x88, 0x72, 0xce, 0x8b, 0x84, 0x23,
  1047. 0xb7, 0xd5, 0xd2, 0x1d, 0x4b, 0x02, 0xf5, 0x7e,
  1048. 0x03, 0xe9, 0xe6, 0xb8, 0xa2, 0x58, 0xdc, 0x16,
  1049. 0x61, 0x1b, 0xa0, 0x98, 0xab, 0x54, 0x34, 0x15,
  1050. 0xe4, 0x15, 0xf1, 0x56, 0x99, 0x7a, 0x3e, 0xe2,
  1051. 0x36, 0x65, 0x8f, 0xa0, 0x93, 0x26, 0x0d, 0xe3,
  1052. 0xad, 0x42, 0x2e, 0x05, 0xe0, 0x46, 0xf9, 0xec,
  1053. 0x29, 0x16, 0x1a, 0x37, 0x5f, 0x0e, 0xb4, 0xef,
  1054. 0xfc, 0xef, 0x58, 0x28, 0x5c, 0x5d, 0x39, 0xed,
  1055. 0x42, 0x5d, 0x7a, 0x62, 0xca, 0x12, 0x89, 0x6c,
  1056. 0x4a, 0x92, 0xcb, 0x19, 0x46, 0xf2, 0x95, 0x2a,
  1057. 0x48, 0x13, 0x3f, 0x07, 0xda, 0x36, 0x4d, 0x1b,
  1058. 0xdf, 0x6b, 0x0f, 0x71, 0x39, 0x98, 0x3e, 0x69,
  1059. 0x3c, 0x80, 0x05, 0x9b, 0x0e, 0xac, 0xd1, 0x47,
  1060. 0x9b, 0xa9, 0xf2, 0x85, 0x77, 0x54, 0xed, 0xe7,
  1061. 0x5f, 0x11, 0x2b, 0x07, 0xeb, 0xbf, 0x35, 0x34,
  1062. 0x8b, 0xbf, 0x3e, 0x01, 0xe0, 0x2f, 0x2d, 0x47,
  1063. 0x3d, 0xe3, 0x94, 0x53, 0xf9, 0x9d, 0xd2, 0x36,
  1064. 0x75, 0x41, 0xca, 0xca, 0x3b, 0xa0, 0x11, 0x66,
  1065. 0x34, 0x3d, 0x7b, 0x5b, 0x58, 0xa3, 0x7b, 0xd1,
  1066. 0xb7, 0x52, 0x1d, 0xb2, 0xf1, 0x3b, 0x86, 0x70,
  1067. 0x71, 0x32, 0xfe, 0x09, 0xf4, 0xcd, 0x09, 0xdc,
  1068. 0x16, 0x18, 0xfa, 0x34, 0x01, 0xeb, 0xf9, 0xcc,
  1069. 0x7b, 0x19, 0xfa, 0x94, 0xaa, 0x47, 0x20, 0x88,
  1070. 0x13, 0x3d, 0x6c, 0xb2, 0xd3, 0x5c, 0x11, 0x79,
  1071. 0xc8, 0xc8, 0xff, 0x36, 0x87, 0x58, 0xd5, 0x07,
  1072. 0xd9, 0xf9, 0xa1, 0x7d, 0x46, 0xc1, 0x10, 0xfe,
  1073. 0x31, 0x44, 0xce, 0x9b, 0x02, 0x2b, 0x42, 0xe4,
  1074. 0x19, 0xeb, 0x4f, 0x53, 0x88, 0x61, 0x3b, 0xfc,
  1075. 0x3e, 0x26, 0x24, 0x1a, 0x43, 0x2e, 0x87, 0x06,
  1076. 0xbc, 0x58, 0xef, 0x76, 0x11, 0x72, 0x78, 0xde,
  1077. 0xab, 0x6c, 0xf6, 0x92, 0x61, 0x82, 0x91, 0xb7
  1078. };
  1079. static const unsigned char dsa_q[] = {
  1080. 0xa3, 0xbf, 0xd9, 0xab, 0x78, 0x84, 0x79, 0x4e,
  1081. 0x38, 0x34, 0x50, 0xd5, 0x89, 0x1d, 0xc1, 0x8b,
  1082. 0x65, 0x15, 0x7b, 0xdc, 0xfc, 0xda, 0xc5, 0x15,
  1083. 0x18, 0x90, 0x28, 0x67
  1084. };
  1085. static const unsigned char dsa_g[] = {
  1086. 0x68, 0x19, 0x27, 0x88, 0x69, 0xc7, 0xfd, 0x3d,
  1087. 0x2d, 0x7b, 0x77, 0xf7, 0x7e, 0x81, 0x50, 0xd9,
  1088. 0xad, 0x43, 0x3b, 0xea, 0x3b, 0xa8, 0x5e, 0xfc,
  1089. 0x80, 0x41, 0x5a, 0xa3, 0x54, 0x5f, 0x78, 0xf7,
  1090. 0x22, 0x96, 0xf0, 0x6c, 0xb1, 0x9c, 0xed, 0xa0,
  1091. 0x6c, 0x94, 0xb0, 0x55, 0x1c, 0xfe, 0x6e, 0x6f,
  1092. 0x86, 0x3e, 0x31, 0xd1, 0xde, 0x6e, 0xed, 0x7d,
  1093. 0xab, 0x8b, 0x0c, 0x9d, 0xf2, 0x31, 0xe0, 0x84,
  1094. 0x34, 0xd1, 0x18, 0x4f, 0x91, 0xd0, 0x33, 0x69,
  1095. 0x6b, 0xb3, 0x82, 0xf8, 0x45, 0x5e, 0x98, 0x88,
  1096. 0xf5, 0xd3, 0x1d, 0x47, 0x84, 0xec, 0x40, 0x12,
  1097. 0x02, 0x46, 0xf4, 0xbe, 0xa6, 0x17, 0x94, 0xbb,
  1098. 0xa5, 0x86, 0x6f, 0x09, 0x74, 0x64, 0x63, 0xbd,
  1099. 0xf8, 0xe9, 0xe1, 0x08, 0xcd, 0x95, 0x29, 0xc3,
  1100. 0xd0, 0xf6, 0xdf, 0x80, 0x31, 0x6e, 0x2e, 0x70,
  1101. 0xaa, 0xeb, 0x1b, 0x26, 0xcd, 0xb8, 0xad, 0x97,
  1102. 0xbc, 0x3d, 0x28, 0x7e, 0x0b, 0x8d, 0x61, 0x6c,
  1103. 0x42, 0xe6, 0x5b, 0x87, 0xdb, 0x20, 0xde, 0xb7,
  1104. 0x00, 0x5b, 0xc4, 0x16, 0x74, 0x7a, 0x64, 0x70,
  1105. 0x14, 0x7a, 0x68, 0xa7, 0x82, 0x03, 0x88, 0xeb,
  1106. 0xf4, 0x4d, 0x52, 0xe0, 0x62, 0x8a, 0xf9, 0xcf,
  1107. 0x1b, 0x71, 0x66, 0xd0, 0x34, 0x65, 0xf3, 0x5a,
  1108. 0xcc, 0x31, 0xb6, 0x11, 0x0c, 0x43, 0xda, 0xbc,
  1109. 0x7c, 0x5d, 0x59, 0x1e, 0x67, 0x1e, 0xaf, 0x7c,
  1110. 0x25, 0x2c, 0x1c, 0x14, 0x53, 0x36, 0xa1, 0xa4,
  1111. 0xdd, 0xf1, 0x32, 0x44, 0xd5, 0x5e, 0x83, 0x56,
  1112. 0x80, 0xca, 0xb2, 0x53, 0x3b, 0x82, 0xdf, 0x2e,
  1113. 0xfe, 0x55, 0xec, 0x18, 0xc1, 0xe6, 0xcd, 0x00,
  1114. 0x7b, 0xb0, 0x89, 0x75, 0x8b, 0xb1, 0x7c, 0x2c,
  1115. 0xbe, 0x14, 0x44, 0x1b, 0xd0, 0x93, 0xae, 0x66,
  1116. 0xe5, 0x97, 0x6d, 0x53, 0x73, 0x3f, 0x4f, 0xa3,
  1117. 0x26, 0x97, 0x01, 0xd3, 0x1d, 0x23, 0xd4, 0x67
  1118. };
  1119. static const unsigned char dsa_pub[] = {
  1120. 0xa0, 0x12, 0xb3, 0xb1, 0x70, 0xb3, 0x07, 0x22,
  1121. 0x79, 0x57, 0xb7, 0xca, 0x20, 0x61, 0xa8, 0x16,
  1122. 0xac, 0x7a, 0x2b, 0x3d, 0x9a, 0xe9, 0x95, 0xa5,
  1123. 0x11, 0x9c, 0x38, 0x5b, 0x60, 0x3b, 0xf6, 0xf6,
  1124. 0xc5, 0xde, 0x4d, 0xc5, 0xec, 0xb5, 0xdf, 0xa4,
  1125. 0xa4, 0x1c, 0x68, 0x66, 0x2e, 0xb2, 0x5b, 0x63,
  1126. 0x8b, 0x7e, 0x26, 0x20, 0xba, 0x89, 0x8d, 0x07,
  1127. 0xda, 0x6c, 0x49, 0x91, 0xe7, 0x6c, 0xc0, 0xec,
  1128. 0xd1, 0xad, 0x34, 0x21, 0x07, 0x70, 0x67, 0xe4,
  1129. 0x7c, 0x18, 0xf5, 0x8a, 0x92, 0xa7, 0x2a, 0xd4,
  1130. 0x31, 0x99, 0xec, 0xb7, 0xbd, 0x84, 0xe7, 0xd3,
  1131. 0xaf, 0xb9, 0x01, 0x9f, 0x0e, 0x9d, 0xd0, 0xfb,
  1132. 0xaa, 0x48, 0x73, 0x00, 0xb1, 0x30, 0x81, 0xe3,
  1133. 0x3c, 0x90, 0x28, 0x76, 0x43, 0x6f, 0x7b, 0x03,
  1134. 0xc3, 0x45, 0x52, 0x84, 0x81, 0xd3, 0x62, 0x81,
  1135. 0x5e, 0x24, 0xfe, 0x59, 0xda, 0xc5, 0xac, 0x34,
  1136. 0x66, 0x0d, 0x4c, 0x8a, 0x76, 0xcb, 0x99, 0xa7,
  1137. 0xc7, 0xde, 0x93, 0xeb, 0x95, 0x6c, 0xd6, 0xbc,
  1138. 0x88, 0xe5, 0x8d, 0x90, 0x10, 0x34, 0x94, 0x4a,
  1139. 0x09, 0x4b, 0x01, 0x80, 0x3a, 0x43, 0xc6, 0x72,
  1140. 0xb9, 0x68, 0x8c, 0x0e, 0x01, 0xd8, 0xf4, 0xfc,
  1141. 0x91, 0xc6, 0x2a, 0x3f, 0x88, 0x02, 0x1f, 0x7b,
  1142. 0xd6, 0xa6, 0x51, 0xb1, 0xa8, 0x8f, 0x43, 0xaa,
  1143. 0x4e, 0xf2, 0x76, 0x53, 0xd1, 0x2b, 0xf8, 0xb7,
  1144. 0x09, 0x9f, 0xdf, 0x6b, 0x46, 0x10, 0x82, 0xf8,
  1145. 0xe9, 0x39, 0x10, 0x7b, 0xfd, 0x2f, 0x72, 0x10,
  1146. 0x08, 0x7d, 0x32, 0x6c, 0x37, 0x52, 0x00, 0xf1,
  1147. 0xf5, 0x1e, 0x7e, 0x74, 0xa3, 0x41, 0x31, 0x90,
  1148. 0x1b, 0xcd, 0x08, 0x63, 0x52, 0x1f, 0xf8, 0xd6,
  1149. 0x76, 0xc4, 0x85, 0x81, 0x86, 0x87, 0x36, 0xc5,
  1150. 0xe5, 0x1b, 0x16, 0xa4, 0xe3, 0x92, 0x15, 0xea,
  1151. 0x0b, 0x17, 0xc4, 0x73, 0x59, 0x74, 0xc5, 0x16
  1152. };
  1153. static const unsigned char dsa_priv[] = {
  1154. 0x6c, 0xca, 0xee, 0xf6, 0xd7, 0x3b, 0x4e, 0x80,
  1155. 0xf1, 0x1c, 0x17, 0xb8, 0xe9, 0x62, 0x7c, 0x03,
  1156. 0x66, 0x35, 0xba, 0xc3, 0x94, 0x23, 0x50, 0x5e,
  1157. 0x40, 0x7e, 0x5c, 0xb7
  1158. };
  1159. static const ST_KAT_PARAM dsa_key[] = {
  1160. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_FFC_P, dsa_p),
  1161. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_FFC_Q, dsa_q),
  1162. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_FFC_G, dsa_g),
  1163. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_PUB_KEY, dsa_pub),
  1164. ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_PRIV_KEY, dsa_priv),
  1165. ST_KAT_PARAM_END()
  1166. };
  1167. #endif /* OPENSSL_NO_DSA */
  1168. static const ST_KAT_SIGN st_kat_sign_tests[] = {
  1169. #ifndef OPENSSL_NO_RSA
  1170. {
  1171. OSSL_SELF_TEST_DESC_SIGN_RSA,
  1172. "RSA",
  1173. "SHA-256",
  1174. rsa_crt_key,
  1175. ITM(rsa_expected_sig)
  1176. },
  1177. #endif /* OPENSSL_NO_RSA */
  1178. #ifndef OPENSSL_NO_EC
  1179. {
  1180. OSSL_SELF_TEST_DESC_SIGN_ECDSA,
  1181. "EC",
  1182. "SHA-256",
  1183. ecdsa_key,
  1184. /*
  1185. * The ECDSA signature changes each time due to it using a random k.
  1186. * So there is no expected KAT for this case.
  1187. */
  1188. },
  1189. #endif /* OPENSSL_NO_EC */
  1190. #ifndef OPENSSL_NO_DSA
  1191. {
  1192. OSSL_SELF_TEST_DESC_SIGN_DSA,
  1193. "DSA",
  1194. "SHA-256",
  1195. dsa_key,
  1196. /*
  1197. * The DSA signature changes each time due to it using a random k.
  1198. * So there is no expected KAT for this case.
  1199. */
  1200. },
  1201. #endif /* OPENSSL_NO_DSA */
  1202. };
  1203. static const ST_KAT_ASYM_CIPHER st_kat_asym_cipher_tests[] = {
  1204. #ifndef OPENSSL_NO_RSA
  1205. {
  1206. OSSL_SELF_TEST_DESC_ASYM_RSA_ENC,
  1207. "RSA",
  1208. 1,
  1209. rsa_pub_key,
  1210. rsa_enc_params,
  1211. ITM(rsa_asym_plaintext_encrypt),
  1212. ITM(rsa_asym_expected_encrypt),
  1213. },
  1214. {
  1215. OSSL_SELF_TEST_DESC_ASYM_RSA_DEC,
  1216. "RSA",
  1217. 0,
  1218. rsa_priv_key,
  1219. rsa_enc_params,
  1220. ITM(rsa_asym_expected_encrypt),
  1221. ITM(rsa_asym_plaintext_encrypt),
  1222. },
  1223. {
  1224. OSSL_SELF_TEST_DESC_ASYM_RSA_DEC,
  1225. "RSA",
  1226. 0,
  1227. rsa_crt_key,
  1228. rsa_enc_params,
  1229. ITM(rsa_asym_expected_encrypt),
  1230. ITM(rsa_asym_plaintext_encrypt),
  1231. },
  1232. #endif /* OPENSSL_NO_RSA */
  1233. };