Update profile name config and test vector gen The desire is to have examples of an "android.16" profile implementation. This was accomplished by making header files that declare the profile name and including those header files into the configuration header. Adding "android.16" as a profile name necessitates some changes in the python script that generates the test vectors Bug: 378813154 Change-Id: I22310586aa61202c73737ee63643ef71cf2912cd Reviewed-on: https://pigweed-review.googlesource.com/c/open-dice/+/253672 Reviewed-by: Alice Wang <aliceywang@google.com> Lint: Lint 🤖 <android-build-ayeaye@system.gserviceaccount.com> Reviewed-by: Darren Krahn <dkrahn@google.com> Commit-Queue: Alice Wang <aliceywang@google.com>
diff --git a/BUILD.gn b/BUILD.gn index 2e21c22..568ffe6 100644 --- a/BUILD.gn +++ b/BUILD.gn
@@ -55,6 +55,18 @@ all_dependent_configs = [ ":standalone_ops_config" ] } +config("android_profile") { + include_dirs = [ "//include/dice/config/android" ] +} + +config("example_profile") { + include_dirs = [ "//include/dice/config/example" ] +} + +config("default_profile") { + include_dirs = [ "//include/dice/config/default" ] +} + config("boringssl_ed25519_ops_config") { include_dirs = [ "//include/dice/config/boringssl_ed25519" ] } @@ -85,7 +97,10 @@ "src/utils.c", ] deps = [ "//third_party/boringssl:crypto" ] - all_dependent_configs = [ ":boringssl_ed25519_ops_config" ] + all_dependent_configs = [ + ":boringssl_ed25519_ops_config", + ":default_profile", + ] } pw_static_library("dice_with_boringssl_p256_ops") { @@ -102,7 +117,10 @@ "src/utils.c", ] deps = [ "//third_party/boringssl:crypto" ] - all_dependent_configs = [ ":boringssl_ecdsa_p256_ops_config" ] + all_dependent_configs = [ + ":boringssl_ecdsa_p256_ops_config", + ":example_profile", + ] } pw_static_library("dice_with_boringssl_p384_ops") { @@ -119,7 +137,10 @@ "src/utils.c", ] deps = [ "//third_party/boringssl:crypto" ] - all_dependent_configs = [ ":boringssl_ecdsa_p384_ops_config" ] + all_dependent_configs = [ + ":boringssl_ecdsa_p384_ops_config", + ":example_profile", + ] } config("mbedtls_ops_config") { @@ -159,7 +180,10 @@ ":cbor_writer", "//third_party/boringssl:crypto", ] - all_dependent_configs = [ ":boringssl_ed25519_ops_config" ] + all_dependent_configs = [ + ":boringssl_ed25519_ops_config", + ":android_profile", + ] } pw_static_library("boringssl_ecdsa_utils") { @@ -190,7 +214,10 @@ ":cbor_writer", "//third_party/boringssl:crypto", ] - all_dependent_configs = [ ":boringssl_ecdsa_p256_ops_config" ] + all_dependent_configs = [ + ":boringssl_ecdsa_p256_ops_config", + ":example_profile", + ] } pw_static_library("dice_with_cbor_p384_cert") { @@ -211,7 +238,10 @@ ":cbor_writer", "//third_party/boringssl:crypto", ] - all_dependent_configs = [ ":boringssl_ecdsa_p384_ops_config" ] + all_dependent_configs = [ + ":boringssl_ecdsa_p384_ops_config", + ":example_profile", + ] } pw_static_library("dice_with_cbor_multialg") { @@ -232,7 +262,10 @@ ":cbor_writer", "//third_party/boringssl:crypto", ] - all_dependent_configs = [ ":boringssl_multialg_ops_config" ] + all_dependent_configs = [ + ":boringssl_multialg_ops_config", + ":android_profile", + ] } pw_static_library("dice_with_cbor_template_ed25519_cert") { @@ -249,7 +282,10 @@ "src/utils.c", ] deps = [ "//third_party/boringssl:crypto" ] - all_dependent_configs = [ ":boringssl_ed25519_ops_config" ] + all_dependent_configs = [ + ":boringssl_ed25519_ops_config", + ":default_profile", + ] } pw_static_library("dice_with_x509_template_cert") { @@ -266,7 +302,10 @@ "src/utils.c", ] deps = [ "//third_party/boringssl:crypto" ] - all_dependent_configs = [ ":boringssl_ed25519_ops_config" ] + all_dependent_configs = [ + ":boringssl_ed25519_ops_config", + ":default_profile", + ] } pw_source_set("fuzzer") {
diff --git a/generate_test_values.py b/generate_test_values.py index 41be12f..a3cb853 100644 --- a/generate_test_values.py +++ b/generate_test_values.py
@@ -122,8 +122,7 @@ )[:-3] -def _generate_c(name): - """Generates C declarations from dumps identified by |name|.""" +def _generate_attest_and_seal(name): content = "" attest_cdi_data = _read_file("_attest_cdi_%s.bin" % name) content += _generate_array( @@ -133,34 +132,44 @@ content += _generate_array( "kExpectedCdiSeal_%s" % _to_camel_case(name), seal_cdi_data ) - for cert_type in ("X509", "CBOR"): - for key_type in ("Ed25519", "P256", "P384"): - var_name = "kExpected%s%sCert_%s" % ( - _to_camel_case(cert_type), - _to_camel_case(key_type), - _to_camel_case(name), - ) - cert_data = _read_file( - "_%s_%s_cert_%s.cert" % (cert_type, key_type, name) - ) - if cert_type == "X509" and key_type != "P384": - content += ( - "// $ openssl x509 -inform DER -noout -text -certopt " - "ext_parse\n" - ) - content += _generate_cert_comment(cert_data) - content += _generate_array(var_name, cert_data) return content +def _generate_cert(name, cert_type, key_type): + content = "" + var_name = "kExpected%s%sCert_%s" % ( + _to_camel_case(cert_type), + _to_camel_case(key_type), + _to_camel_case(name), + ) + cert_data = _read_file("_%s_%s_cert_%s.cert" % (cert_type, key_type, name)) + if cert_type == "X509" and key_type != "P384": + content += ( + "// $ openssl x509 -inform DER -noout -text -certopt " "ext_parse\n" + ) + content += _generate_cert_comment(cert_data) + content += _generate_array(var_name, cert_data) + return content + + +def _generate_certs(name, cert_type): + """Generates C declarations from dumps identified by |name|.""" + return "".join( + _generate_cert(name, cert_type, key_type) + for key_type in ("Ed25519", "P256", "P384") + ) + + def main(argv): if len(argv) > 1: raise app.UsageError("Too many command-line arguments.") content = _FILE_HEADER - content += _generate_c("zero_input") - content += _generate_c("hash_only_input") - content += _generate_c("descriptor_input") + for name in ("zero_input", "hash_only_input", "descriptor_input"): + content += _generate_attest_and_seal(name) + content += _generate_certs(name, "X509") + content += _generate_certs(name, "CBOR") + content += _generate_certs("android_" + name, "CBOR") content += _FILE_FOOTER subprocess.run( ["clang-format", "--style=file"], input=content.encode(), check=True
diff --git a/include/dice/config/android/dice/profile_name.h b/include/dice/config/android/dice/profile_name.h new file mode 100644 index 0000000..d5ba6c4 --- /dev/null +++ b/include/dice/config/android/dice/profile_name.h
@@ -0,0 +1,20 @@ +// Copyright 2024 Google LLC +// +// Licensed under the Apache License, Version 2.0 (the "License"); you may not +// use this file except in compliance with the License. You may obtain a copy of +// the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, WITHOUT +// WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the +// License for the specific language governing permissions and limitations under +// the License. + +#ifndef DICE_CONFIG_ANDROID_DICE_PROFILE_NAME_H_ +#define DICE_CONFIG_ANDROID_DICE_PROFILE_NAME_H_ + +#define DICE_PROFILE_NAME "android.16" + +#endif // DICE_CONFIG_ANDROID_DICE_PROFILE_NAME_H_
diff --git a/include/dice/config/boringssl_ecdsa_p256/dice/config.h b/include/dice/config/boringssl_ecdsa_p256/dice/config.h index 7e390d5..69ac4b8 100644 --- a/include/dice/config/boringssl_ecdsa_p256/dice/config.h +++ b/include/dice/config/boringssl_ecdsa_p256/dice/config.h
@@ -21,4 +21,4 @@ #define DICE_PRIVATE_KEY_BUFFER_SIZE 32 #define DICE_SIGNATURE_BUFFER_SIZE 64 -#endif // DICE_CONFIG_BORINGSSL_ECDSA_P256_DICE_DICE_CONFIG_H_ +#endif // DICE_CONFIG_BORINGSSL_ECDSA_P256_DICE_CONFIG_H_
diff --git a/include/dice/config/boringssl_ecdsa_p384/dice/config.h b/include/dice/config/boringssl_ecdsa_p384/dice/config.h index 48ff621..0a60dac 100644 --- a/include/dice/config/boringssl_ecdsa_p384/dice/config.h +++ b/include/dice/config/boringssl_ecdsa_p384/dice/config.h
@@ -21,4 +21,4 @@ #define DICE_PRIVATE_KEY_BUFFER_SIZE 48 #define DICE_SIGNATURE_BUFFER_SIZE 96 -#endif // DICE_CONFIG_BORINGSSL_ECDSA_P384_DICE_DICE_CONFIG_H_ +#endif // DICE_CONFIG_BORINGSSL_ECDSA_P384_DICE_CONFIG_H_
diff --git a/include/dice/config/boringssl_ed25519/dice/config.h b/include/dice/config/boringssl_ed25519/dice/config.h index 79d1eab..e2158f8 100644 --- a/include/dice/config/boringssl_ed25519/dice/config.h +++ b/include/dice/config/boringssl_ed25519/dice/config.h
@@ -21,4 +21,4 @@ #define DICE_PRIVATE_KEY_BUFFER_SIZE 64 #define DICE_SIGNATURE_BUFFER_SIZE 64 -#endif // DICE_CONFIG_BORINGSSL_ED25519_DICE_DICE_CONFIG_H_ +#endif // DICE_CONFIG_BORINGSSL_ED25519_DICE_CONFIG_H_
diff --git a/include/dice/config/boringssl_multialg/dice/config.h b/include/dice/config/boringssl_multialg/dice/config.h index 1158a1b..91fe667 100644 --- a/include/dice/config/boringssl_multialg/dice/config.h +++ b/include/dice/config/boringssl_multialg/dice/config.h
@@ -64,4 +64,4 @@ } // extern "C" #endif -#endif // DICE_CONFIG_BORINGSSL_MULTIALG_DICE_DICE_CONFIG_H_ +#endif // DICE_CONFIG_BORINGSSL_MULTIALG_DICE_CONFIG_H_
diff --git a/include/dice/config/default/dice/profile_name.h b/include/dice/config/default/dice/profile_name.h new file mode 100644 index 0000000..dcecef5 --- /dev/null +++ b/include/dice/config/default/dice/profile_name.h
@@ -0,0 +1,20 @@ +// Copyright 2024 Google LLC +// +// Licensed under the Apache License, Version 2.0 (the "License"); you may not +// use this file except in compliance with the License. You may obtain a copy of +// the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, WITHOUT +// WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the +// License for the specific language governing permissions and limitations under +// the License. + +#ifndef DICE_CONFIG_DEFAULT_DICE_PROFILE_NAME_H_ +#define DICE_CONFIG_DEFAULT_DICE_PROFILE_NAME_H_ + +#define DICE_PROFILE_NAME NULL + +#endif // DICE_CONFIG_DEFAULT_PROFILE_NAME_H_
diff --git a/include/dice/config/example/dice/profile_name.h b/include/dice/config/example/dice/profile_name.h new file mode 100644 index 0000000..f1f5c3f --- /dev/null +++ b/include/dice/config/example/dice/profile_name.h
@@ -0,0 +1,20 @@ +// Copyright 2024 Google LLC +// +// Licensed under the Apache License, Version 2.0 (the "License"); you may not +// use this file except in compliance with the License. You may obtain a copy of +// the License at +// +// https://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, WITHOUT +// WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the +// License for the specific language governing permissions and limitations under +// the License. + +#ifndef DICE_CONFIG_EXAMPLE_DICE_PROFILE_NAME_H_ +#define DICE_CONFIG_EXAMPLE_DICE_PROFILE_NAME_H_ + +#define DICE_PROFILE_NAME "opendice.example" + +#endif // DICE_CONFIG_EXAMPLE_DICE_PROFILE_NAME_H_
diff --git a/include/dice/known_test_values.h b/include/dice/known_test_values.h index 3bf61cb..ac60cd9 100644 --- a/include/dice/known_test_values.h +++ b/include/dice/known_test_values.h
@@ -40,11 +40,11 @@ // Serial Number: // 67:c2:2a:88:59:06:2b:98:68:18:e8:e7:2b:0b:cd:9f:59:34:9c:89 // Signature Algorithm: ED25519 -// Issuer: serialNumber = 7a06eee41b789f4863d86b8778b1a201a6fedd56 +// Issuer: serialNumber=7a06eee41b789f4863d86b8778b1a201a6fedd56 // Validity // Not Before: Mar 22 23:59:59 2018 GMT // Not After : Dec 31 23:59:59 9999 GMT -// Subject: serialNumber = 67c22a8859062b986818e8e72b0bcd9f59349c89 +// Subject: serialNumber=67c22a8859062b986818e8e72b0bcd9f59349c89 // Subject Public Key Info: // Public Key Algorithm: ED25519 // ED25519 Public-Key: @@ -153,11 +153,11 @@ // Serial Number: // 7c:7d:c0:a3:c1:e7:8d:4e:68:bc:c1:a2:32:9e:f9:1c:a8:12:44:91 // Signature Algorithm: ecdsa-with-SHA512 -// Issuer: serialNumber = 4c514d88db0f81d57beb96177e3d7ea4aa581e66 +// Issuer: serialNumber=4c514d88db0f81d57beb96177e3d7ea4aa581e66 // Validity // Not Before: Mar 22 23:59:59 2018 GMT // Not After : Dec 31 23:59:59 9999 GMT -// Subject: serialNumber = 7c7dc0a3c1e78d4e68bcc1a2329ef91ca8124491 +// Subject: serialNumber=7c7dc0a3c1e78d4e68bcc1a2329ef91ca8124491 // Subject Public Key Info: // Public Key Algorithm: id-ecPublicKey // Public-Key: (256 bit) @@ -314,8 +314,8 @@ 0x21, 0xec, 0xa3, 0xd3, 0x89, 0x7a, 0x24, 0x4d, 0xcb, 0xe1, 0x1a, 0x0f, 0x9a, 0xb7, 0x9f, 0x67, 0x09, 0x3f, 0xee, 0x56, 0x0f}; -constexpr uint8_t kExpectedCborP256Cert_ZeroInput[503] = { - 0x84, 0x43, 0xa1, 0x01, 0x26, 0xa0, 0x59, 0x01, 0xac, 0xa9, 0x01, 0x78, +constexpr uint8_t kExpectedCborP256Cert_ZeroInput[498] = { + 0x84, 0x43, 0xa1, 0x01, 0x26, 0xa0, 0x59, 0x01, 0xa7, 0xa9, 0x01, 0x78, 0x28, 0x36, 0x37, 0x32, 0x64, 0x30, 0x30, 0x35, 0x33, 0x61, 0x65, 0x34, 0x35, 0x31, 0x33, 0x66, 0x62, 0x62, 0x33, 0x62, 0x61, 0x63, 0x38, 0x32, 0x30, 0x39, 0x64, 0x61, 0x65, 0x62, 0x33, 0x65, 0x38, 0x38, 0x39, 0x37, @@ -349,17 +349,17 @@ 0xeb, 0x40, 0x19, 0xab, 0x55, 0xc6, 0x6b, 0xc8, 0x8b, 0xb8, 0xb4, 0x69, 0xad, 0x7e, 0xe8, 0x58, 0x9e, 0x07, 0xd2, 0xf8, 0xbc, 0x88, 0x8e, 0xb3, 0x11, 0xc2, 0xdf, 0x97, 0x3b, 0x1b, 0x4a, 0x3a, 0x00, 0x47, 0x44, 0x58, - 0x41, 0x20, 0x3a, 0x00, 0x47, 0x44, 0x59, 0x75, 0x6f, 0x70, 0x65, 0x6e, + 0x41, 0x20, 0x3a, 0x00, 0x47, 0x44, 0x59, 0x70, 0x6f, 0x70, 0x65, 0x6e, 0x64, 0x69, 0x63, 0x65, 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, - 0x2e, 0x70, 0x32, 0x35, 0x36, 0x58, 0x40, 0x63, 0xb5, 0x32, 0x12, 0x4a, - 0x18, 0xf5, 0xa8, 0xf0, 0x67, 0x3e, 0x76, 0x46, 0xa5, 0xb6, 0xb8, 0xbf, - 0xfe, 0xa2, 0xeb, 0x6f, 0x4d, 0x5f, 0x18, 0x69, 0x03, 0xc6, 0x31, 0xce, - 0xeb, 0xae, 0xcd, 0xca, 0x93, 0x31, 0x51, 0x51, 0xcf, 0x05, 0xb6, 0x7e, - 0x87, 0x91, 0xd0, 0x5b, 0x88, 0xf5, 0xe3, 0x93, 0xf7, 0xba, 0xd5, 0xd7, - 0x07, 0xe3, 0xe6, 0x3f, 0xcb, 0xf6, 0x24, 0xd2, 0xf6, 0xc1, 0x5c}; + 0x58, 0x40, 0xd3, 0x15, 0x5f, 0x22, 0x51, 0x2d, 0x68, 0xa7, 0x9f, 0x09, + 0xff, 0x9f, 0x00, 0xd8, 0x52, 0xaa, 0x85, 0xbb, 0xdb, 0xb9, 0xb6, 0x57, + 0x2f, 0xc3, 0xbf, 0xd8, 0xe0, 0x59, 0xb9, 0x98, 0xc1, 0x88, 0x23, 0x42, + 0x35, 0x21, 0x75, 0xb1, 0xc9, 0xb4, 0x85, 0x45, 0x8d, 0x00, 0xa3, 0x31, + 0x75, 0x14, 0xc2, 0x0f, 0xdd, 0xa7, 0x34, 0xe7, 0xc8, 0x9b, 0x2c, 0x62, + 0x8b, 0xab, 0x74, 0xb3, 0x5f, 0x4e}; -constexpr uint8_t kExpectedCborP384Cert_ZeroInput[569] = { - 0x84, 0x44, 0xa1, 0x01, 0x38, 0x22, 0xa0, 0x59, 0x01, 0xcd, 0xa9, 0x01, +constexpr uint8_t kExpectedCborP384Cert_ZeroInput[564] = { + 0x84, 0x44, 0xa1, 0x01, 0x38, 0x22, 0xa0, 0x59, 0x01, 0xc8, 0xa9, 0x01, 0x78, 0x28, 0x30, 0x34, 0x63, 0x32, 0x36, 0x35, 0x66, 0x65, 0x30, 0x36, 0x66, 0x66, 0x32, 0x33, 0x30, 0x65, 0x33, 0x39, 0x62, 0x36, 0x33, 0x32, 0x32, 0x65, 0x65, 0x61, 0x39, 0x65, 0x30, 0x31, 0x30, 0x37, 0x31, 0x31, @@ -396,17 +396,149 @@ 0xfc, 0xe0, 0x3c, 0xdc, 0x5d, 0x1b, 0x58, 0x16, 0x69, 0xdd, 0x44, 0x24, 0x67, 0xbf, 0x21, 0xd7, 0x47, 0xf3, 0x13, 0xd1, 0x47, 0x6c, 0x4b, 0xd3, 0x05, 0xb5, 0x29, 0xa0, 0xf1, 0x3a, 0x00, 0x47, 0x44, 0x58, 0x41, 0x20, - 0x3a, 0x00, 0x47, 0x44, 0x59, 0x75, 0x6f, 0x70, 0x65, 0x6e, 0x64, 0x69, - 0x63, 0x65, 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x70, - 0x33, 0x38, 0x34, 0x58, 0x60, 0x15, 0x22, 0x2f, 0x02, 0xdd, 0x28, 0x07, - 0x9a, 0x90, 0xcf, 0xae, 0x29, 0x76, 0x81, 0x14, 0xc3, 0xf2, 0x06, 0x13, - 0x01, 0xe1, 0x5f, 0x6e, 0xb1, 0x1d, 0x1f, 0x7a, 0xcd, 0x3f, 0xf5, 0xf9, - 0x87, 0x4d, 0x78, 0x6e, 0xa5, 0xff, 0x86, 0xb2, 0x1e, 0x0c, 0x8b, 0xd2, - 0x26, 0x20, 0x02, 0xe1, 0x65, 0x8b, 0x91, 0x8f, 0x29, 0x97, 0xdb, 0x4b, - 0x05, 0xa7, 0xe3, 0xc7, 0x97, 0x8e, 0x42, 0xe5, 0xbe, 0x44, 0xdd, 0xff, - 0xed, 0xf9, 0x70, 0xa3, 0xec, 0x64, 0xe4, 0xb9, 0x1d, 0x2b, 0xe0, 0xe9, - 0x29, 0xa3, 0x1d, 0xf5, 0x79, 0xd0, 0x1c, 0x3a, 0x26, 0xbc, 0xb2, 0xf9, - 0xd9, 0xcd, 0x59, 0xd9, 0xc1}; + 0x3a, 0x00, 0x47, 0x44, 0x59, 0x70, 0x6f, 0x70, 0x65, 0x6e, 0x64, 0x69, + 0x63, 0x65, 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x58, 0x60, + 0x23, 0x4b, 0xe9, 0xd7, 0xe7, 0x48, 0x93, 0x86, 0xef, 0x67, 0x5f, 0x99, + 0x3f, 0xd2, 0x5e, 0xa4, 0x01, 0x89, 0x7c, 0xf2, 0xa0, 0x1c, 0xe3, 0x1a, + 0x4b, 0x8c, 0xb8, 0xfb, 0xf9, 0x27, 0x3d, 0xa2, 0x33, 0x29, 0xed, 0x13, + 0x94, 0x79, 0xb4, 0x75, 0x48, 0x9c, 0xa5, 0x0c, 0x96, 0x93, 0xad, 0x70, + 0x11, 0x74, 0xd0, 0x00, 0x4c, 0xcb, 0xa3, 0xfa, 0xed, 0x13, 0xfa, 0xc3, + 0x86, 0xfd, 0x39, 0x19, 0xf9, 0x6e, 0xaf, 0x46, 0x45, 0x4d, 0x4e, 0x67, + 0x78, 0x60, 0xb5, 0xc7, 0x85, 0x10, 0xa4, 0xe9, 0xfe, 0x18, 0x2a, 0x3e, + 0x68, 0xe0, 0x91, 0x09, 0x22, 0x06, 0xfa, 0x2c, 0x2f, 0x14, 0xfd, 0x0a}; + +constexpr uint8_t kExpectedCborEd25519Cert_AndroidZeroInput[457] = { + 0x84, 0x43, 0xa1, 0x01, 0x27, 0xa0, 0x59, 0x01, 0x7e, 0xa9, 0x01, 0x78, + 0x28, 0x37, 0x61, 0x30, 0x36, 0x65, 0x65, 0x65, 0x34, 0x31, 0x62, 0x37, + 0x38, 0x39, 0x66, 0x34, 0x38, 0x36, 0x33, 0x64, 0x38, 0x36, 0x62, 0x38, + 0x37, 0x37, 0x38, 0x62, 0x31, 0x61, 0x32, 0x30, 0x31, 0x61, 0x36, 0x66, + 0x65, 0x64, 0x64, 0x35, 0x36, 0x02, 0x78, 0x28, 0x36, 0x37, 0x63, 0x32, + 0x32, 0x61, 0x38, 0x38, 0x35, 0x39, 0x30, 0x36, 0x32, 0x62, 0x39, 0x38, + 0x36, 0x38, 0x31, 0x38, 0x65, 0x38, 0x65, 0x37, 0x32, 0x62, 0x30, 0x62, + 0x63, 0x64, 0x39, 0x66, 0x35, 0x39, 0x33, 0x34, 0x39, 0x63, 0x38, 0x39, + 0x3a, 0x00, 0x47, 0x44, 0x50, 0x58, 0x40, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x3a, + 0x00, 0x47, 0x44, 0x53, 0x58, 0x40, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x3a, 0x00, + 0x47, 0x44, 0x54, 0x58, 0x40, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x3a, 0x00, 0x47, + 0x44, 0x56, 0x41, 0x00, 0x3a, 0x00, 0x47, 0x44, 0x57, 0x58, 0x2d, 0xa5, + 0x01, 0x01, 0x03, 0x27, 0x04, 0x81, 0x02, 0x20, 0x06, 0x21, 0x58, 0x20, + 0x0d, 0x14, 0xe5, 0xde, 0x29, 0x2e, 0xb1, 0xc8, 0xb3, 0x1b, 0xea, 0xe4, + 0x3a, 0xb5, 0x5d, 0x8e, 0x9d, 0xc0, 0x14, 0xb7, 0x3e, 0xaa, 0x83, 0xb9, + 0x25, 0xa0, 0x78, 0x8c, 0xc6, 0x2e, 0x5c, 0x8d, 0x3a, 0x00, 0x47, 0x44, + 0x58, 0x41, 0x20, 0x3a, 0x00, 0x47, 0x44, 0x59, 0x6a, 0x61, 0x6e, 0x64, + 0x72, 0x6f, 0x69, 0x64, 0x2e, 0x31, 0x36, 0x58, 0x40, 0xb8, 0x4d, 0x72, + 0x36, 0x1a, 0xb8, 0x5b, 0x53, 0x0c, 0x8a, 0x4b, 0xe2, 0xa8, 0x49, 0xe8, + 0xc0, 0x3d, 0x36, 0x1c, 0x6e, 0x7d, 0x21, 0x72, 0x9a, 0x7b, 0x8f, 0x1b, + 0x7b, 0x49, 0x7d, 0x6e, 0xe6, 0x71, 0x2c, 0x19, 0x4f, 0x1b, 0x97, 0x1d, + 0x19, 0xf5, 0xb2, 0xd5, 0x3e, 0x8a, 0x8c, 0x47, 0x14, 0xbb, 0x19, 0xfb, + 0x32, 0xaa, 0x42, 0x40, 0xaf, 0x66, 0x13, 0xa1, 0x9a, 0x6d, 0xd2, 0xe8, + 0x01}; + +constexpr uint8_t kExpectedCborP256Cert_AndroidZeroInput[492] = { + 0x84, 0x43, 0xa1, 0x01, 0x26, 0xa0, 0x59, 0x01, 0xa1, 0xa9, 0x01, 0x78, + 0x28, 0x36, 0x37, 0x32, 0x64, 0x30, 0x30, 0x35, 0x33, 0x61, 0x65, 0x34, + 0x35, 0x31, 0x33, 0x66, 0x62, 0x62, 0x33, 0x62, 0x61, 0x63, 0x38, 0x32, + 0x30, 0x39, 0x64, 0x61, 0x65, 0x62, 0x33, 0x65, 0x38, 0x38, 0x39, 0x37, + 0x36, 0x38, 0x31, 0x63, 0x64, 0x02, 0x78, 0x28, 0x32, 0x65, 0x37, 0x35, + 0x62, 0x36, 0x65, 0x37, 0x32, 0x33, 0x30, 0x63, 0x32, 0x30, 0x66, 0x32, + 0x39, 0x36, 0x30, 0x62, 0x64, 0x65, 0x34, 0x61, 0x63, 0x66, 0x31, 0x32, + 0x38, 0x38, 0x64, 0x34, 0x61, 0x62, 0x36, 0x36, 0x35, 0x62, 0x39, 0x62, + 0x3a, 0x00, 0x47, 0x44, 0x50, 0x58, 0x40, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x3a, + 0x00, 0x47, 0x44, 0x53, 0x58, 0x40, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x3a, 0x00, + 0x47, 0x44, 0x54, 0x58, 0x40, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x3a, 0x00, 0x47, + 0x44, 0x56, 0x41, 0x00, 0x3a, 0x00, 0x47, 0x44, 0x57, 0x58, 0x50, 0xa6, + 0x01, 0x02, 0x03, 0x26, 0x04, 0x81, 0x02, 0x20, 0x01, 0x21, 0x58, 0x20, + 0x4f, 0x3b, 0x4e, 0x82, 0xc4, 0x5a, 0xda, 0x08, 0x45, 0x89, 0xc2, 0x19, + 0x7b, 0xaf, 0x1f, 0x37, 0x6e, 0xac, 0x40, 0xe1, 0xfd, 0x49, 0xb0, 0x24, + 0x06, 0x02, 0xae, 0xc2, 0x69, 0x54, 0x1c, 0x6b, 0x22, 0x58, 0x20, 0xe7, + 0xeb, 0x40, 0x19, 0xab, 0x55, 0xc6, 0x6b, 0xc8, 0x8b, 0xb8, 0xb4, 0x69, + 0xad, 0x7e, 0xe8, 0x58, 0x9e, 0x07, 0xd2, 0xf8, 0xbc, 0x88, 0x8e, 0xb3, + 0x11, 0xc2, 0xdf, 0x97, 0x3b, 0x1b, 0x4a, 0x3a, 0x00, 0x47, 0x44, 0x58, + 0x41, 0x20, 0x3a, 0x00, 0x47, 0x44, 0x59, 0x6a, 0x61, 0x6e, 0x64, 0x72, + 0x6f, 0x69, 0x64, 0x2e, 0x31, 0x36, 0x58, 0x40, 0x4c, 0x70, 0x48, 0xd1, + 0x17, 0x4e, 0x6e, 0xdc, 0xab, 0x70, 0x4b, 0xc5, 0x62, 0x4d, 0x8b, 0x57, + 0xd1, 0xcb, 0x46, 0xbb, 0x06, 0xaa, 0xd2, 0xa7, 0x83, 0xf9, 0xad, 0x20, + 0x69, 0x43, 0x01, 0x7e, 0x1e, 0xd5, 0xfb, 0xb9, 0x32, 0x0b, 0xf0, 0x8f, + 0x65, 0x96, 0xbf, 0x4b, 0x1e, 0x10, 0x13, 0x6d, 0xce, 0x72, 0x76, 0x5e, + 0x97, 0x5d, 0x11, 0xcb, 0x00, 0xea, 0x51, 0x53, 0x4f, 0xdf, 0xea, 0x98}; + +constexpr uint8_t kExpectedCborP384Cert_AndroidZeroInput[558] = { + 0x84, 0x44, 0xa1, 0x01, 0x38, 0x22, 0xa0, 0x59, 0x01, 0xc2, 0xa9, 0x01, + 0x78, 0x28, 0x30, 0x34, 0x63, 0x32, 0x36, 0x35, 0x66, 0x65, 0x30, 0x36, + 0x66, 0x66, 0x32, 0x33, 0x30, 0x65, 0x33, 0x39, 0x62, 0x36, 0x33, 0x32, + 0x32, 0x65, 0x65, 0x61, 0x39, 0x65, 0x30, 0x31, 0x30, 0x37, 0x31, 0x31, + 0x66, 0x62, 0x36, 0x36, 0x62, 0x34, 0x02, 0x78, 0x28, 0x34, 0x30, 0x63, + 0x62, 0x34, 0x66, 0x30, 0x36, 0x34, 0x61, 0x36, 0x38, 0x64, 0x34, 0x30, + 0x37, 0x61, 0x30, 0x62, 0x33, 0x39, 0x30, 0x61, 0x62, 0x63, 0x63, 0x30, + 0x35, 0x61, 0x33, 0x34, 0x62, 0x66, 0x63, 0x38, 0x61, 0x66, 0x33, 0x33, + 0x66, 0x3a, 0x00, 0x47, 0x44, 0x50, 0x58, 0x40, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x3a, 0x00, 0x47, 0x44, 0x53, 0x58, 0x40, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x3a, + 0x00, 0x47, 0x44, 0x54, 0x58, 0x40, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, + 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x3a, 0x00, + 0x47, 0x44, 0x56, 0x41, 0x00, 0x3a, 0x00, 0x47, 0x44, 0x57, 0x58, 0x71, + 0xa6, 0x01, 0x02, 0x03, 0x38, 0x22, 0x04, 0x81, 0x02, 0x20, 0x02, 0x21, + 0x58, 0x30, 0x77, 0x19, 0x6b, 0xa5, 0x84, 0xeb, 0x79, 0x46, 0xd2, 0xfb, + 0xb0, 0xd5, 0xc8, 0x31, 0xc7, 0xad, 0x91, 0x37, 0x5e, 0x11, 0x28, 0xdb, + 0x23, 0x8c, 0xc1, 0xc6, 0x7f, 0xae, 0x5e, 0x07, 0x10, 0x95, 0x5b, 0x17, + 0xb5, 0xd5, 0x08, 0x12, 0x31, 0x06, 0xba, 0x31, 0x31, 0x10, 0x43, 0x71, + 0x51, 0xde, 0x22, 0x58, 0x30, 0x03, 0x25, 0xa9, 0x76, 0x29, 0x67, 0x9d, + 0x6b, 0xa9, 0x01, 0xb1, 0x22, 0xa0, 0x4b, 0xee, 0xf7, 0xb3, 0xe1, 0x52, + 0xfc, 0xe0, 0x3c, 0xdc, 0x5d, 0x1b, 0x58, 0x16, 0x69, 0xdd, 0x44, 0x24, + 0x67, 0xbf, 0x21, 0xd7, 0x47, 0xf3, 0x13, 0xd1, 0x47, 0x6c, 0x4b, 0xd3, + 0x05, 0xb5, 0x29, 0xa0, 0xf1, 0x3a, 0x00, 0x47, 0x44, 0x58, 0x41, 0x20, + 0x3a, 0x00, 0x47, 0x44, 0x59, 0x6a, 0x61, 0x6e, 0x64, 0x72, 0x6f, 0x69, + 0x64, 0x2e, 0x31, 0x36, 0x58, 0x60, 0xfd, 0x2a, 0x30, 0x69, 0xfa, 0x08, + 0xb7, 0x6f, 0x8e, 0xda, 0x48, 0xc7, 0x40, 0x8c, 0xdd, 0x7d, 0x92, 0x2f, + 0x48, 0x89, 0x45, 0xf5, 0xe0, 0xc8, 0x8f, 0xd4, 0xf4, 0x4a, 0x4d, 0x9d, + 0x7f, 0x0c, 0x2c, 0x93, 0x6e, 0x0a, 0xaa, 0x20, 0x19, 0x58, 0xc1, 0xd2, + 0x72, 0x31, 0x96, 0xf9, 0x4a, 0xea, 0xd3, 0xf2, 0xb4, 0xe0, 0x11, 0x8d, + 0x92, 0xce, 0x4d, 0x45, 0x95, 0xd1, 0xc9, 0x8c, 0xc5, 0xfc, 0xc4, 0xea, + 0x4f, 0x4a, 0x9c, 0x37, 0x68, 0x42, 0xeb, 0xf5, 0xe7, 0x49, 0x15, 0xd2, + 0x44, 0x8a, 0xd0, 0xe6, 0x14, 0xa5, 0xf2, 0x0b, 0x33, 0xdc, 0x9a, 0x80, + 0x84, 0x30, 0x5f, 0xcc, 0xd6, 0x6f}; constexpr uint8_t kExpectedCdiAttest_HashOnlyInput[32] = { 0x08, 0x4e, 0xf4, 0x06, 0xc6, 0x9b, 0xa7, 0x4b, 0x1e, 0x24, 0xd0, @@ -425,11 +557,11 @@ // Serial Number: // 0d:04:0e:2f:46:00:52:a5:31:1c:1b:91:db:f9:b4:40:83:32:ec:29 // Signature Algorithm: ED25519 -// Issuer: serialNumber = 475708eb3b426f386cfce8f3baf5439046278dfa +// Issuer: serialNumber=475708eb3b426f386cfce8f3baf5439046278dfa // Validity // Not Before: Mar 22 23:59:59 2018 GMT // Not After : Dec 31 23:59:59 9999 GMT -// Subject: serialNumber = 0d040e2f460052a5311c1b91dbf9b4408332ec29 +// Subject: serialNumber=0d040e2f460052a5311c1b91dbf9b4408332ec29 // Subject Public Key Info: // Public Key Algorithm: ED25519 // ED25519 Public-Key: @@ -538,11 +670,11 @@ // Serial Number: // 68:49:58:d9:ae:a7:2e:bf:7c:06:af:20:03:b6:44:47:82:4a:62:71 // Signature Algorithm: ecdsa-with-SHA512 -// Issuer: serialNumber = 1be5687933db3d9cd5fca729e81d6685465a7bf1 +// Issuer: serialNumber=1be5687933db3d9cd5fca729e81d6685465a7bf1 // Validity // Not Before: Mar 22 23:59:59 2018 GMT // Not After : Dec 31 23:59:59 9999 GMT -// Subject: serialNumber = 684958d9aea72ebf7c06af2003b64447824a6271 +// Subject: serialNumber=684958d9aea72ebf7c06af2003b64447824a6271 // Subject Public Key Info: // Public Key Algorithm: id-ecPublicKey // Public-Key: (256 bit) @@ -699,8 +831,8 @@ 0xb6, 0x71, 0xc7, 0x76, 0x64, 0x25, 0xfb, 0x03, 0xcf, 0xd6, 0x6f, 0x2f, 0x9a, 0x15, 0xc8, 0xad, 0x47, 0x9a, 0xf3, 0x16, 0x01}; -constexpr uint8_t kExpectedCborP256Cert_HashOnlyInput[503] = { - 0x84, 0x43, 0xa1, 0x01, 0x26, 0xa0, 0x59, 0x01, 0xac, 0xa9, 0x01, 0x78, +constexpr uint8_t kExpectedCborP256Cert_HashOnlyInput[498] = { + 0x84, 0x43, 0xa1, 0x01, 0x26, 0xa0, 0x59, 0x01, 0xa7, 0xa9, 0x01, 0x78, 0x28, 0x34, 0x38, 0x36, 0x30, 0x33, 0x63, 0x30, 0x30, 0x35, 0x32, 0x63, 0x31, 0x63, 0x61, 0x63, 0x37, 0x33, 0x63, 0x61, 0x65, 0x33, 0x36, 0x63, 0x33, 0x62, 0x64, 0x65, 0x63, 0x37, 0x63, 0x36, 0x31, 0x33, 0x39, 0x38, @@ -734,17 +866,17 @@ 0x1a, 0x19, 0xea, 0x10, 0x7e, 0xa9, 0x38, 0xf4, 0x45, 0x33, 0xc1, 0x66, 0x5b, 0xbc, 0xfc, 0x0a, 0x6e, 0x98, 0x99, 0x72, 0x88, 0xc1, 0xad, 0x0e, 0x15, 0xc2, 0x85, 0x77, 0x75, 0x00, 0x0b, 0x3a, 0x00, 0x47, 0x44, 0x58, - 0x41, 0x20, 0x3a, 0x00, 0x47, 0x44, 0x59, 0x75, 0x6f, 0x70, 0x65, 0x6e, + 0x41, 0x20, 0x3a, 0x00, 0x47, 0x44, 0x59, 0x70, 0x6f, 0x70, 0x65, 0x6e, 0x64, 0x69, 0x63, 0x65, 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, - 0x2e, 0x70, 0x32, 0x35, 0x36, 0x58, 0x40, 0x9f, 0xc7, 0x0a, 0x63, 0x96, - 0x61, 0xc1, 0x7a, 0x55, 0x52, 0x76, 0x30, 0xc7, 0xe1, 0xb9, 0x92, 0x21, - 0x43, 0x7e, 0x46, 0xf1, 0x45, 0xba, 0xf3, 0xb5, 0x99, 0xe7, 0x8b, 0x64, - 0x58, 0x1d, 0x5c, 0x49, 0xc7, 0x9e, 0x1d, 0xb2, 0x0c, 0xb1, 0xd3, 0x81, - 0x43, 0x6a, 0x2d, 0x13, 0xcb, 0xf8, 0x45, 0x1d, 0xe7, 0x76, 0xed, 0xba, - 0x1a, 0x09, 0x28, 0xe6, 0xd0, 0x23, 0x81, 0x9e, 0xd8, 0xb9, 0x8f}; + 0x58, 0x40, 0x14, 0x5a, 0x40, 0x93, 0x86, 0x46, 0xde, 0xb8, 0xb8, 0xef, + 0xb2, 0x52, 0x34, 0x48, 0xb1, 0x2e, 0x0b, 0x30, 0xa9, 0x58, 0x32, 0x96, + 0xfd, 0x5a, 0xdc, 0xfd, 0xfb, 0xf3, 0xf7, 0x70, 0x02, 0xc0, 0x21, 0xd5, + 0xaa, 0xc4, 0xac, 0x7c, 0xed, 0xf0, 0x3e, 0x7f, 0x61, 0x64, 0x62, 0xe7, + 0x3c, 0x0f, 0x55, 0x86, 0x99, 0x05, 0xf0, 0xb2, 0x61, 0x35, 0x43, 0x94, + 0x47, 0x45, 0xa6, 0x14, 0xa7, 0x9a}; -constexpr uint8_t kExpectedCborP384Cert_HashOnlyInput[569] = { - 0x84, 0x44, 0xa1, 0x01, 0x38, 0x22, 0xa0, 0x59, 0x01, 0xcd, 0xa9, 0x01, +constexpr uint8_t kExpectedCborP384Cert_HashOnlyInput[564] = { + 0x84, 0x44, 0xa1, 0x01, 0x38, 0x22, 0xa0, 0x59, 0x01, 0xc8, 0xa9, 0x01, 0x78, 0x28, 0x35, 0x64, 0x38, 0x62, 0x36, 0x62, 0x65, 0x37, 0x63, 0x65, 0x33, 0x65, 0x64, 0x65, 0x36, 0x61, 0x32, 0x34, 0x31, 0x38, 0x30, 0x31, 0x34, 0x35, 0x32, 0x33, 0x65, 0x36, 0x63, 0x39, 0x64, 0x63, 0x38, 0x37, @@ -781,17 +913,149 @@ 0x5c, 0x90, 0xfb, 0x4b, 0x6d, 0x96, 0x42, 0x77, 0xe2, 0xf6, 0x58, 0x3d, 0x37, 0xa7, 0x3d, 0x2e, 0xca, 0xd1, 0x2c, 0xa4, 0xd4, 0xa7, 0xaf, 0x25, 0xc3, 0xb2, 0xe7, 0x34, 0xf5, 0x3a, 0x00, 0x47, 0x44, 0x58, 0x41, 0x20, - 0x3a, 0x00, 0x47, 0x44, 0x59, 0x75, 0x6f, 0x70, 0x65, 0x6e, 0x64, 0x69, - 0x63, 0x65, 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x70, - 0x33, 0x38, 0x34, 0x58, 0x60, 0x88, 0xa1, 0x0e, 0xbc, 0x51, 0xfb, 0x22, - 0x0c, 0x05, 0x67, 0x56, 0x39, 0x8c, 0xdb, 0x8e, 0x3f, 0x1b, 0x2c, 0x8c, - 0x67, 0x49, 0x85, 0xc3, 0x9b, 0x33, 0x0f, 0x2b, 0x5e, 0x99, 0x65, 0x0d, - 0x7b, 0xa4, 0x8e, 0xcd, 0x4a, 0xd0, 0x3c, 0x81, 0x9d, 0x34, 0xc5, 0x0a, - 0x4f, 0xab, 0xeb, 0xc8, 0xe6, 0xb9, 0x2e, 0x09, 0x64, 0xdc, 0xa1, 0xc5, - 0x19, 0x1a, 0xf2, 0x1c, 0xc2, 0xc7, 0x02, 0xb3, 0x93, 0xac, 0x8c, 0x61, - 0x7d, 0x4d, 0xcf, 0xc3, 0x1b, 0x06, 0x0e, 0x7f, 0x03, 0x71, 0x79, 0x21, - 0x4c, 0x46, 0xd5, 0x77, 0xe9, 0xd2, 0x5e, 0xa8, 0xe4, 0x71, 0xfc, 0x6d, - 0xa1, 0xf6, 0x12, 0xab, 0x40}; + 0x3a, 0x00, 0x47, 0x44, 0x59, 0x70, 0x6f, 0x70, 0x65, 0x6e, 0x64, 0x69, + 0x63, 0x65, 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x58, 0x60, + 0xfd, 0x0c, 0x1c, 0x0b, 0xe0, 0x6b, 0xf0, 0x10, 0x4b, 0x59, 0x55, 0xe8, + 0xd0, 0x52, 0x80, 0x8c, 0xb6, 0xef, 0x21, 0x8c, 0xae, 0x98, 0x68, 0x86, + 0xa4, 0xb8, 0x15, 0x9c, 0xc1, 0x08, 0x3f, 0x2b, 0xd8, 0x77, 0xab, 0x09, + 0x16, 0xa9, 0x51, 0x2f, 0x6c, 0xb6, 0x08, 0xb9, 0xd3, 0x3c, 0xbf, 0x3d, + 0xe6, 0x6d, 0xf2, 0x0c, 0x72, 0xd5, 0x41, 0x19, 0xeb, 0xc8, 0x56, 0x08, + 0x10, 0xaf, 0x3f, 0x98, 0xcb, 0x01, 0xb5, 0xcc, 0xc6, 0x91, 0x53, 0xfd, + 0x52, 0x1d, 0x93, 0x89, 0x81, 0xa9, 0xe0, 0xd2, 0x90, 0x83, 0x70, 0xe4, + 0x41, 0xe1, 0x5f, 0x6f, 0x6d, 0x21, 0x3e, 0x5d, 0x3b, 0x2a, 0xdb, 0x01}; + +constexpr uint8_t kExpectedCborEd25519Cert_AndroidHashOnlyInput[457] = { + 0x84, 0x43, 0xa1, 0x01, 0x27, 0xa0, 0x59, 0x01, 0x7e, 0xa9, 0x01, 0x78, + 0x28, 0x34, 0x37, 0x35, 0x37, 0x30, 0x38, 0x65, 0x62, 0x33, 0x62, 0x34, + 0x32, 0x36, 0x66, 0x33, 0x38, 0x36, 0x63, 0x66, 0x63, 0x65, 0x38, 0x66, + 0x33, 0x62, 0x61, 0x66, 0x35, 0x34, 0x33, 0x39, 0x30, 0x34, 0x36, 0x32, + 0x37, 0x38, 0x64, 0x66, 0x61, 0x02, 0x78, 0x28, 0x30, 0x64, 0x30, 0x34, + 0x30, 0x65, 0x32, 0x66, 0x34, 0x36, 0x30, 0x30, 0x35, 0x32, 0x61, 0x35, + 0x33, 0x31, 0x31, 0x63, 0x31, 0x62, 0x39, 0x31, 0x64, 0x62, 0x66, 0x39, + 0x62, 0x34, 0x34, 0x30, 0x38, 0x33, 0x33, 0x32, 0x65, 0x63, 0x32, 0x39, + 0x3a, 0x00, 0x47, 0x44, 0x50, 0x58, 0x40, 0xb7, 0xd4, 0x0c, 0xcb, 0x22, + 0x5b, 0xa5, 0x78, 0x8f, 0x98, 0xff, 0x9e, 0x86, 0x93, 0x75, 0xf6, 0x90, + 0xac, 0x50, 0xcf, 0x9e, 0xbd, 0x0a, 0xfe, 0xb1, 0xd9, 0xc2, 0x4e, 0x52, + 0x19, 0xe4, 0xde, 0x29, 0xe5, 0x61, 0xf3, 0xf9, 0x29, 0xe8, 0x40, 0x87, + 0x7a, 0xdd, 0x17, 0x48, 0x05, 0x89, 0x7e, 0x2b, 0xcb, 0x54, 0x79, 0xcc, + 0x66, 0xf1, 0xb3, 0x13, 0x29, 0x0c, 0x68, 0x96, 0xb2, 0xbb, 0x8f, 0x3a, + 0x00, 0x47, 0x44, 0x53, 0x58, 0x40, 0xcf, 0x99, 0x7b, 0xea, 0x2e, 0x2c, + 0x86, 0xa0, 0x7b, 0x52, 0x09, 0xc8, 0xb5, 0x3c, 0x41, 0x12, 0x29, 0x28, + 0x1a, 0x82, 0x0d, 0x49, 0x9c, 0x95, 0xcb, 0x0b, 0x1b, 0x31, 0x1a, 0x01, + 0x9c, 0xf2, 0x66, 0x1a, 0xd9, 0xb5, 0xce, 0x52, 0x59, 0xcb, 0xf4, 0x81, + 0x9b, 0x21, 0xaf, 0x32, 0x5d, 0x07, 0xa0, 0x1e, 0x91, 0x59, 0x6f, 0x06, + 0x55, 0x10, 0x8e, 0x2e, 0x08, 0x88, 0x52, 0x28, 0x86, 0x7f, 0x3a, 0x00, + 0x47, 0x44, 0x54, 0x58, 0x40, 0x22, 0x52, 0x60, 0x17, 0xef, 0x2c, 0xa1, + 0xf6, 0xcb, 0xed, 0x39, 0xd5, 0xe2, 0xaa, 0x65, 0x20, 0xfb, 0xad, 0x82, + 0x93, 0xe5, 0x78, 0x23, 0x22, 0x97, 0xc1, 0x6e, 0x6a, 0x4e, 0x36, 0xd7, + 0x6a, 0x61, 0x39, 0x08, 0x21, 0xd4, 0xfe, 0x92, 0x5f, 0x36, 0x2d, 0xeb, + 0x5d, 0xbb, 0x32, 0x8b, 0xe3, 0x94, 0x4f, 0xbe, 0x1b, 0x21, 0xf9, 0xcc, + 0x23, 0x73, 0x41, 0xb6, 0xb9, 0xb6, 0x98, 0xd0, 0xbc, 0x3a, 0x00, 0x47, + 0x44, 0x56, 0x41, 0x00, 0x3a, 0x00, 0x47, 0x44, 0x57, 0x58, 0x2d, 0xa5, + 0x01, 0x01, 0x03, 0x27, 0x04, 0x81, 0x02, 0x20, 0x06, 0x21, 0x58, 0x20, + 0x5a, 0x39, 0x49, 0x67, 0x8c, 0xd3, 0x0e, 0x88, 0xab, 0x1c, 0xdd, 0xf7, + 0x15, 0x55, 0xd5, 0xbf, 0xd3, 0xf0, 0xb8, 0x47, 0x25, 0xa9, 0x58, 0xe1, + 0xb9, 0xda, 0x4e, 0xb5, 0xf1, 0x38, 0x9a, 0x5a, 0x3a, 0x00, 0x47, 0x44, + 0x58, 0x41, 0x20, 0x3a, 0x00, 0x47, 0x44, 0x59, 0x6a, 0x61, 0x6e, 0x64, + 0x72, 0x6f, 0x69, 0x64, 0x2e, 0x31, 0x36, 0x58, 0x40, 0x03, 0x7f, 0xf0, + 0xfd, 0x3a, 0xdb, 0xbd, 0x38, 0x37, 0x0c, 0x73, 0x4a, 0xb7, 0xbf, 0x24, + 0x8e, 0x66, 0xd7, 0xf5, 0xb9, 0x41, 0x8d, 0x31, 0x52, 0x20, 0xce, 0xbb, + 0x29, 0xe3, 0xd5, 0x1a, 0xe2, 0xa7, 0x10, 0xb1, 0xc4, 0xdf, 0x86, 0x41, + 0xe5, 0xc8, 0x84, 0x9b, 0x3b, 0xf2, 0x76, 0xe9, 0x6c, 0x3d, 0x00, 0x49, + 0xe5, 0xd2, 0x15, 0xc0, 0x0b, 0x40, 0x62, 0x1c, 0xc6, 0x00, 0x07, 0x94, + 0x02}; + +constexpr uint8_t kExpectedCborP256Cert_AndroidHashOnlyInput[492] = { + 0x84, 0x43, 0xa1, 0x01, 0x26, 0xa0, 0x59, 0x01, 0xa1, 0xa9, 0x01, 0x78, + 0x28, 0x34, 0x38, 0x36, 0x30, 0x33, 0x63, 0x30, 0x30, 0x35, 0x32, 0x63, + 0x31, 0x63, 0x61, 0x63, 0x37, 0x33, 0x63, 0x61, 0x65, 0x33, 0x36, 0x63, + 0x33, 0x62, 0x64, 0x65, 0x63, 0x37, 0x63, 0x36, 0x31, 0x33, 0x39, 0x38, + 0x38, 0x35, 0x63, 0x39, 0x64, 0x02, 0x78, 0x28, 0x37, 0x63, 0x32, 0x30, + 0x30, 0x61, 0x35, 0x35, 0x65, 0x66, 0x65, 0x37, 0x31, 0x31, 0x32, 0x65, + 0x63, 0x61, 0x34, 0x65, 0x30, 0x32, 0x36, 0x64, 0x37, 0x30, 0x32, 0x63, + 0x36, 0x34, 0x65, 0x39, 0x65, 0x32, 0x39, 0x63, 0x64, 0x33, 0x65, 0x39, + 0x3a, 0x00, 0x47, 0x44, 0x50, 0x58, 0x40, 0xb7, 0xd4, 0x0c, 0xcb, 0x22, + 0x5b, 0xa5, 0x78, 0x8f, 0x98, 0xff, 0x9e, 0x86, 0x93, 0x75, 0xf6, 0x90, + 0xac, 0x50, 0xcf, 0x9e, 0xbd, 0x0a, 0xfe, 0xb1, 0xd9, 0xc2, 0x4e, 0x52, + 0x19, 0xe4, 0xde, 0x29, 0xe5, 0x61, 0xf3, 0xf9, 0x29, 0xe8, 0x40, 0x87, + 0x7a, 0xdd, 0x17, 0x48, 0x05, 0x89, 0x7e, 0x2b, 0xcb, 0x54, 0x79, 0xcc, + 0x66, 0xf1, 0xb3, 0x13, 0x29, 0x0c, 0x68, 0x96, 0xb2, 0xbb, 0x8f, 0x3a, + 0x00, 0x47, 0x44, 0x53, 0x58, 0x40, 0xcf, 0x99, 0x7b, 0xea, 0x2e, 0x2c, + 0x86, 0xa0, 0x7b, 0x52, 0x09, 0xc8, 0xb5, 0x3c, 0x41, 0x12, 0x29, 0x28, + 0x1a, 0x82, 0x0d, 0x49, 0x9c, 0x95, 0xcb, 0x0b, 0x1b, 0x31, 0x1a, 0x01, + 0x9c, 0xf2, 0x66, 0x1a, 0xd9, 0xb5, 0xce, 0x52, 0x59, 0xcb, 0xf4, 0x81, + 0x9b, 0x21, 0xaf, 0x32, 0x5d, 0x07, 0xa0, 0x1e, 0x91, 0x59, 0x6f, 0x06, + 0x55, 0x10, 0x8e, 0x2e, 0x08, 0x88, 0x52, 0x28, 0x86, 0x7f, 0x3a, 0x00, + 0x47, 0x44, 0x54, 0x58, 0x40, 0x22, 0x52, 0x60, 0x17, 0xef, 0x2c, 0xa1, + 0xf6, 0xcb, 0xed, 0x39, 0xd5, 0xe2, 0xaa, 0x65, 0x20, 0xfb, 0xad, 0x82, + 0x93, 0xe5, 0x78, 0x23, 0x22, 0x97, 0xc1, 0x6e, 0x6a, 0x4e, 0x36, 0xd7, + 0x6a, 0x61, 0x39, 0x08, 0x21, 0xd4, 0xfe, 0x92, 0x5f, 0x36, 0x2d, 0xeb, + 0x5d, 0xbb, 0x32, 0x8b, 0xe3, 0x94, 0x4f, 0xbe, 0x1b, 0x21, 0xf9, 0xcc, + 0x23, 0x73, 0x41, 0xb6, 0xb9, 0xb6, 0x98, 0xd0, 0xbc, 0x3a, 0x00, 0x47, + 0x44, 0x56, 0x41, 0x00, 0x3a, 0x00, 0x47, 0x44, 0x57, 0x58, 0x50, 0xa6, + 0x01, 0x02, 0x03, 0x26, 0x04, 0x81, 0x02, 0x20, 0x01, 0x21, 0x58, 0x20, + 0xfe, 0x9d, 0xb2, 0xf9, 0x28, 0x09, 0xc3, 0x04, 0x12, 0x85, 0xdc, 0xd3, + 0x70, 0x6f, 0x22, 0x1c, 0x72, 0xb6, 0xc4, 0x4f, 0xde, 0x93, 0xee, 0xfd, + 0xfb, 0x6d, 0x57, 0x18, 0xfc, 0x8f, 0x6f, 0x0b, 0x22, 0x58, 0x20, 0x09, + 0x1a, 0x19, 0xea, 0x10, 0x7e, 0xa9, 0x38, 0xf4, 0x45, 0x33, 0xc1, 0x66, + 0x5b, 0xbc, 0xfc, 0x0a, 0x6e, 0x98, 0x99, 0x72, 0x88, 0xc1, 0xad, 0x0e, + 0x15, 0xc2, 0x85, 0x77, 0x75, 0x00, 0x0b, 0x3a, 0x00, 0x47, 0x44, 0x58, + 0x41, 0x20, 0x3a, 0x00, 0x47, 0x44, 0x59, 0x6a, 0x61, 0x6e, 0x64, 0x72, + 0x6f, 0x69, 0x64, 0x2e, 0x31, 0x36, 0x58, 0x40, 0x49, 0x27, 0xce, 0x6e, + 0xea, 0x70, 0x68, 0x4c, 0xbc, 0xac, 0xc7, 0xab, 0x07, 0xe2, 0x7a, 0x30, + 0x4d, 0x1b, 0x84, 0xe5, 0xe6, 0x18, 0xe1, 0xe1, 0x76, 0xa7, 0x58, 0xd0, + 0x74, 0xef, 0x82, 0x81, 0x96, 0x73, 0x8b, 0x77, 0x2c, 0xe2, 0x27, 0x4a, + 0xc2, 0x4f, 0x90, 0x20, 0xd2, 0x5d, 0xf5, 0x8d, 0xb0, 0x5d, 0x87, 0xb4, + 0xbd, 0x75, 0x44, 0x14, 0x30, 0xb8, 0x31, 0x10, 0x18, 0x27, 0x45, 0xcb}; + +constexpr uint8_t kExpectedCborP384Cert_AndroidHashOnlyInput[558] = { + 0x84, 0x44, 0xa1, 0x01, 0x38, 0x22, 0xa0, 0x59, 0x01, 0xc2, 0xa9, 0x01, + 0x78, 0x28, 0x35, 0x64, 0x38, 0x62, 0x36, 0x62, 0x65, 0x37, 0x63, 0x65, + 0x33, 0x65, 0x64, 0x65, 0x36, 0x61, 0x32, 0x34, 0x31, 0x38, 0x30, 0x31, + 0x34, 0x35, 0x32, 0x33, 0x65, 0x36, 0x63, 0x39, 0x64, 0x63, 0x38, 0x37, + 0x65, 0x39, 0x38, 0x63, 0x63, 0x36, 0x02, 0x78, 0x28, 0x36, 0x35, 0x61, + 0x63, 0x35, 0x39, 0x36, 0x61, 0x62, 0x39, 0x39, 0x34, 0x30, 0x33, 0x61, + 0x38, 0x63, 0x37, 0x30, 0x32, 0x37, 0x35, 0x62, 0x31, 0x34, 0x62, 0x30, + 0x32, 0x33, 0x37, 0x33, 0x66, 0x66, 0x31, 0x34, 0x33, 0x66, 0x39, 0x31, + 0x65, 0x3a, 0x00, 0x47, 0x44, 0x50, 0x58, 0x40, 0xb7, 0xd4, 0x0c, 0xcb, + 0x22, 0x5b, 0xa5, 0x78, 0x8f, 0x98, 0xff, 0x9e, 0x86, 0x93, 0x75, 0xf6, + 0x90, 0xac, 0x50, 0xcf, 0x9e, 0xbd, 0x0a, 0xfe, 0xb1, 0xd9, 0xc2, 0x4e, + 0x52, 0x19, 0xe4, 0xde, 0x29, 0xe5, 0x61, 0xf3, 0xf9, 0x29, 0xe8, 0x40, + 0x87, 0x7a, 0xdd, 0x17, 0x48, 0x05, 0x89, 0x7e, 0x2b, 0xcb, 0x54, 0x79, + 0xcc, 0x66, 0xf1, 0xb3, 0x13, 0x29, 0x0c, 0x68, 0x96, 0xb2, 0xbb, 0x8f, + 0x3a, 0x00, 0x47, 0x44, 0x53, 0x58, 0x40, 0xcf, 0x99, 0x7b, 0xea, 0x2e, + 0x2c, 0x86, 0xa0, 0x7b, 0x52, 0x09, 0xc8, 0xb5, 0x3c, 0x41, 0x12, 0x29, + 0x28, 0x1a, 0x82, 0x0d, 0x49, 0x9c, 0x95, 0xcb, 0x0b, 0x1b, 0x31, 0x1a, + 0x01, 0x9c, 0xf2, 0x66, 0x1a, 0xd9, 0xb5, 0xce, 0x52, 0x59, 0xcb, 0xf4, + 0x81, 0x9b, 0x21, 0xaf, 0x32, 0x5d, 0x07, 0xa0, 0x1e, 0x91, 0x59, 0x6f, + 0x06, 0x55, 0x10, 0x8e, 0x2e, 0x08, 0x88, 0x52, 0x28, 0x86, 0x7f, 0x3a, + 0x00, 0x47, 0x44, 0x54, 0x58, 0x40, 0x22, 0x52, 0x60, 0x17, 0xef, 0x2c, + 0xa1, 0xf6, 0xcb, 0xed, 0x39, 0xd5, 0xe2, 0xaa, 0x65, 0x20, 0xfb, 0xad, + 0x82, 0x93, 0xe5, 0x78, 0x23, 0x22, 0x97, 0xc1, 0x6e, 0x6a, 0x4e, 0x36, + 0xd7, 0x6a, 0x61, 0x39, 0x08, 0x21, 0xd4, 0xfe, 0x92, 0x5f, 0x36, 0x2d, + 0xeb, 0x5d, 0xbb, 0x32, 0x8b, 0xe3, 0x94, 0x4f, 0xbe, 0x1b, 0x21, 0xf9, + 0xcc, 0x23, 0x73, 0x41, 0xb6, 0xb9, 0xb6, 0x98, 0xd0, 0xbc, 0x3a, 0x00, + 0x47, 0x44, 0x56, 0x41, 0x00, 0x3a, 0x00, 0x47, 0x44, 0x57, 0x58, 0x71, + 0xa6, 0x01, 0x02, 0x03, 0x38, 0x22, 0x04, 0x81, 0x02, 0x20, 0x02, 0x21, + 0x58, 0x30, 0x32, 0x81, 0xad, 0x61, 0x1e, 0x50, 0x96, 0x2b, 0x5e, 0xda, + 0xff, 0xee, 0x14, 0xa6, 0x44, 0x3d, 0xd9, 0xd1, 0x34, 0xf6, 0x64, 0xb7, + 0x61, 0x58, 0xf4, 0x9a, 0x58, 0xdb, 0xef, 0xa8, 0x87, 0x13, 0x26, 0x08, + 0x1b, 0xc7, 0xdd, 0xc5, 0x5b, 0x73, 0x42, 0xd6, 0x29, 0x87, 0x3f, 0x85, + 0xd0, 0xe4, 0x22, 0x58, 0x30, 0x60, 0x85, 0xd8, 0x42, 0x29, 0x1b, 0xc6, + 0xd9, 0xf6, 0x2f, 0x3a, 0xce, 0xa0, 0xb9, 0x40, 0xb8, 0x18, 0xde, 0xc2, + 0x5c, 0x90, 0xfb, 0x4b, 0x6d, 0x96, 0x42, 0x77, 0xe2, 0xf6, 0x58, 0x3d, + 0x37, 0xa7, 0x3d, 0x2e, 0xca, 0xd1, 0x2c, 0xa4, 0xd4, 0xa7, 0xaf, 0x25, + 0xc3, 0xb2, 0xe7, 0x34, 0xf5, 0x3a, 0x00, 0x47, 0x44, 0x58, 0x41, 0x20, + 0x3a, 0x00, 0x47, 0x44, 0x59, 0x6a, 0x61, 0x6e, 0x64, 0x72, 0x6f, 0x69, + 0x64, 0x2e, 0x31, 0x36, 0x58, 0x60, 0x29, 0x98, 0x94, 0x32, 0x0a, 0xf9, + 0xe6, 0x31, 0x9a, 0xb5, 0xd8, 0x87, 0x9a, 0x3d, 0xa4, 0xda, 0x2b, 0xa8, + 0x8b, 0x0b, 0x6f, 0x41, 0xf0, 0x01, 0xd1, 0xbf, 0xaa, 0xfa, 0x15, 0xee, + 0xc6, 0x3d, 0x5f, 0xdd, 0x8c, 0x52, 0x7e, 0x25, 0xda, 0x41, 0xc6, 0x1a, + 0xd9, 0xfb, 0xc1, 0x80, 0xcc, 0x09, 0xd0, 0x95, 0xba, 0xb3, 0x16, 0xc2, + 0xcc, 0xc5, 0x9f, 0x9e, 0xa9, 0x31, 0x4e, 0xa8, 0xfd, 0x0f, 0xf2, 0x92, + 0x4a, 0xae, 0x09, 0x47, 0xc1, 0xf2, 0x10, 0x8c, 0x68, 0x3a, 0xc6, 0xce, + 0x0a, 0x64, 0x64, 0x72, 0x3a, 0x60, 0x28, 0x90, 0x48, 0xbc, 0x90, 0x85, + 0x77, 0x5b, 0x42, 0x33, 0x87, 0xdd}; constexpr uint8_t kExpectedCdiAttest_DescriptorInput[32] = { 0x20, 0xd5, 0x0c, 0x68, 0x5a, 0xd9, 0xe2, 0xdf, 0x77, 0x60, 0x78, @@ -810,11 +1074,11 @@ // Serial Number: // 52:1f:03:5c:21:e3:2f:16:74:1c:1e:ae:6b:de:d9:3c:e3:21:e0:df // Signature Algorithm: ED25519 -// Issuer: serialNumber = 475708eb3b426f386cfce8f3baf5439046278dfa +// Issuer: serialNumber=475708eb3b426f386cfce8f3baf5439046278dfa // Validity // Not Before: Mar 22 23:59:59 2018 GMT // Not After : Dec 31 23:59:59 9999 GMT -// Subject: serialNumber = 521f035c21e32f16741c1eae6bded93ce321e0df +// Subject: serialNumber=521f035c21e32f16741c1eae6bded93ce321e0df // Subject Public Key Info: // Public Key Algorithm: ED25519 // ED25519 Public-Key: @@ -962,11 +1226,11 @@ // Serial Number: // 2c:0d:e9:55:c4:fa:08:2c:2c:3a:0b:40:66:59:af:a1:c1:c0:84:6c // Signature Algorithm: ecdsa-with-SHA512 -// Issuer: serialNumber = 1be5687933db3d9cd5fca729e81d6685465a7bf1 +// Issuer: serialNumber=1be5687933db3d9cd5fca729e81d6685465a7bf1 // Validity // Not Before: Mar 22 23:59:59 2018 GMT // Not After : Dec 31 23:59:59 9999 GMT -// Subject: serialNumber = 2c0de955c4fa082c2c3a0b406659afa1c1c0846c +// Subject: serialNumber=2c0de955c4fa082c2c3a0b406659afa1c1c0846c // Subject Public Key Info: // Public Key Algorithm: id-ecPublicKey // Public-Key: (256 bit) @@ -1123,66 +1387,10 @@ constexpr uint8_t kExpectedX509P384Cert_DescriptorInput[0] = {}; -constexpr uint8_t kExpectedCborEd25519Cert_DescriptorInput[667] = { - 0x84, 0x43, 0xa1, 0x01, 0x27, 0xa0, 0x59, 0x02, 0x50, 0xab, 0x01, 0x78, - 0x28, 0x34, 0x37, 0x35, 0x37, 0x30, 0x38, 0x65, 0x62, 0x33, 0x62, 0x34, - 0x32, 0x36, 0x66, 0x33, 0x38, 0x36, 0x63, 0x66, 0x63, 0x65, 0x38, 0x66, - 0x33, 0x62, 0x61, 0x66, 0x35, 0x34, 0x33, 0x39, 0x30, 0x34, 0x36, 0x32, - 0x37, 0x38, 0x64, 0x66, 0x61, 0x02, 0x78, 0x28, 0x35, 0x32, 0x31, 0x66, - 0x30, 0x33, 0x35, 0x63, 0x32, 0x31, 0x65, 0x33, 0x32, 0x66, 0x31, 0x36, - 0x37, 0x34, 0x31, 0x63, 0x31, 0x65, 0x61, 0x65, 0x36, 0x62, 0x64, 0x65, - 0x64, 0x39, 0x33, 0x63, 0x65, 0x33, 0x32, 0x31, 0x65, 0x30, 0x64, 0x66, - 0x3a, 0x00, 0x47, 0x44, 0x50, 0x58, 0x40, 0xb7, 0xd4, 0x0c, 0xcb, 0x22, - 0x5b, 0xa5, 0x78, 0x8f, 0x98, 0xff, 0x9e, 0x86, 0x93, 0x75, 0xf6, 0x90, - 0xac, 0x50, 0xcf, 0x9e, 0xbd, 0x0a, 0xfe, 0xb1, 0xd9, 0xc2, 0x4e, 0x52, - 0x19, 0xe4, 0xde, 0x29, 0xe5, 0x61, 0xf3, 0xf9, 0x29, 0xe8, 0x40, 0x87, - 0x7a, 0xdd, 0x17, 0x48, 0x05, 0x89, 0x7e, 0x2b, 0xcb, 0x54, 0x79, 0xcc, - 0x66, 0xf1, 0xb3, 0x13, 0x29, 0x0c, 0x68, 0x96, 0xb2, 0xbb, 0x8f, 0x3a, - 0x00, 0x47, 0x44, 0x51, 0x58, 0x64, 0x6c, 0x46, 0x01, 0x33, 0x26, 0x73, - 0x4b, 0x22, 0x65, 0xfd, 0xfa, 0x58, 0xd7, 0x57, 0x3e, 0x95, 0x59, 0xe0, - 0x3a, 0xc3, 0xb9, 0xf7, 0xc8, 0x0e, 0x98, 0x80, 0x8c, 0xf5, 0xc4, 0xb8, - 0xaf, 0xe3, 0x16, 0x84, 0x25, 0xa5, 0x35, 0x5d, 0x17, 0x72, 0x56, 0x8f, - 0x8e, 0xec, 0x2f, 0x5a, 0x74, 0x60, 0x77, 0x2a, 0x6e, 0x90, 0xc0, 0x4e, - 0x9f, 0x87, 0x6b, 0xf4, 0x8d, 0x9c, 0x66, 0xe3, 0x0b, 0xd2, 0x10, 0x35, - 0x21, 0xa8, 0x1d, 0xa2, 0x31, 0x17, 0xe7, 0x0c, 0xdf, 0x18, 0xf7, 0x94, - 0xe4, 0xd1, 0xca, 0x32, 0x7d, 0xf2, 0x63, 0x23, 0x1d, 0xbc, 0x84, 0x74, - 0x61, 0xdb, 0x87, 0xf2, 0xab, 0x72, 0xad, 0xaf, 0x08, 0xf8, 0x3a, 0x00, - 0x47, 0x44, 0x53, 0x58, 0x28, 0x1b, 0x40, 0xc1, 0xa9, 0x77, 0x60, 0xeb, - 0xc3, 0x67, 0xf0, 0x5f, 0x6a, 0xe1, 0x5e, 0x20, 0xc2, 0x51, 0x68, 0x4d, - 0x82, 0x48, 0x8b, 0x03, 0x32, 0x16, 0x79, 0x88, 0x14, 0x37, 0x78, 0x7f, - 0x16, 0x9a, 0x06, 0xfd, 0xc0, 0x8a, 0x15, 0x80, 0x62, 0x3a, 0x00, 0x47, - 0x44, 0x52, 0x58, 0x40, 0x45, 0x00, 0xe9, 0x5c, 0xbd, 0x00, 0x57, 0x04, - 0x55, 0x87, 0x6c, 0xbd, 0x2f, 0xea, 0x41, 0x9c, 0x66, 0x42, 0x51, 0x41, - 0xbb, 0x44, 0xed, 0x0e, 0xe9, 0x66, 0xcf, 0xd5, 0x10, 0x73, 0x0d, 0x4b, - 0x48, 0xe4, 0x7a, 0x53, 0x35, 0x01, 0x0e, 0x6d, 0x15, 0x55, 0xc5, 0xb7, - 0xd2, 0xd5, 0x36, 0xb6, 0xbc, 0x7e, 0xb0, 0xf3, 0x3d, 0xe6, 0x19, 0x78, - 0x62, 0xeb, 0x02, 0x57, 0x39, 0x56, 0x73, 0x4f, 0x3a, 0x00, 0x47, 0x44, - 0x54, 0x58, 0x40, 0x22, 0x52, 0x60, 0x17, 0xef, 0x2c, 0xa1, 0xf6, 0xcb, - 0xed, 0x39, 0xd5, 0xe2, 0xaa, 0x65, 0x20, 0xfb, 0xad, 0x82, 0x93, 0xe5, - 0x78, 0x23, 0x22, 0x97, 0xc1, 0x6e, 0x6a, 0x4e, 0x36, 0xd7, 0x6a, 0x61, - 0x39, 0x08, 0x21, 0xd4, 0xfe, 0x92, 0x5f, 0x36, 0x2d, 0xeb, 0x5d, 0xbb, - 0x32, 0x8b, 0xe3, 0x94, 0x4f, 0xbe, 0x1b, 0x21, 0xf9, 0xcc, 0x23, 0x73, - 0x41, 0xb6, 0xb9, 0xb6, 0x98, 0xd0, 0xbc, 0x3a, 0x00, 0x47, 0x44, 0x55, - 0x58, 0x41, 0x92, 0xd6, 0x97, 0xb3, 0x83, 0xdf, 0xe7, 0x8c, 0xc7, 0xbc, - 0x4a, 0xfc, 0xea, 0x76, 0xc0, 0x53, 0x66, 0xbd, 0x2c, 0x1e, 0x10, 0x31, - 0x90, 0x80, 0x11, 0x2d, 0x08, 0x4d, 0x7c, 0x39, 0x76, 0xdc, 0x73, 0xe7, - 0x1c, 0x16, 0x62, 0xd5, 0x59, 0xd7, 0x49, 0x2b, 0x6a, 0xa2, 0x36, 0x67, - 0x57, 0xd1, 0xf2, 0xf9, 0xaf, 0x13, 0xd7, 0xa3, 0xe4, 0xd3, 0x39, 0x5b, - 0x02, 0x78, 0xb1, 0xe0, 0x09, 0x70, 0xa2, 0x3a, 0x00, 0x47, 0x44, 0x56, - 0x41, 0x00, 0x3a, 0x00, 0x47, 0x44, 0x57, 0x58, 0x2d, 0xa5, 0x01, 0x01, - 0x03, 0x27, 0x04, 0x81, 0x02, 0x20, 0x06, 0x21, 0x58, 0x20, 0x93, 0x7f, - 0xd9, 0xc0, 0x4d, 0xc6, 0xbb, 0x2e, 0x1d, 0x11, 0x62, 0xcd, 0x5c, 0x76, - 0x94, 0xc7, 0xdb, 0x02, 0x54, 0x0c, 0x85, 0x01, 0x3a, 0x01, 0xab, 0x37, - 0xfa, 0xce, 0xf9, 0x6e, 0x62, 0x20, 0x3a, 0x00, 0x47, 0x44, 0x58, 0x41, - 0x20, 0x58, 0x40, 0xf6, 0x01, 0x7a, 0xc0, 0xf7, 0x8b, 0xb4, 0xf9, 0xbf, - 0x60, 0x98, 0x5b, 0xc5, 0x64, 0x15, 0x4f, 0xa3, 0x0d, 0x19, 0x3a, 0x5f, - 0xb2, 0x46, 0x0c, 0xc8, 0xfc, 0x40, 0x47, 0xa5, 0x87, 0xef, 0xd2, 0xdb, - 0xbd, 0x35, 0xb6, 0x87, 0x99, 0x22, 0xe1, 0x3f, 0x37, 0xe3, 0x71, 0x28, - 0x5a, 0xfa, 0xca, 0xcd, 0x5d, 0x44, 0x58, 0x45, 0xdf, 0xbb, 0x3d, 0x08, - 0x88, 0x9b, 0x0c, 0x3b, 0x06, 0x7c, 0x0e}; +constexpr uint8_t kExpectedCborEd25519Cert_DescriptorInput[0] = {}; -constexpr uint8_t kExpectedCborP256Cert_DescriptorInput[729] = { - 0x84, 0x43, 0xa1, 0x01, 0x26, 0xa0, 0x59, 0x02, 0x8e, 0xac, 0x01, 0x78, +constexpr uint8_t kExpectedCborP256Cert_DescriptorInput[724] = { + 0x84, 0x43, 0xa1, 0x01, 0x26, 0xa0, 0x59, 0x02, 0x89, 0xac, 0x01, 0x78, 0x28, 0x34, 0x38, 0x36, 0x30, 0x33, 0x63, 0x30, 0x30, 0x35, 0x32, 0x63, 0x31, 0x63, 0x61, 0x63, 0x37, 0x33, 0x63, 0x61, 0x65, 0x33, 0x36, 0x63, 0x33, 0x62, 0x64, 0x65, 0x63, 0x37, 0x63, 0x36, 0x31, 0x33, 0x39, 0x38, @@ -1235,17 +1443,17 @@ 0x8c, 0x72, 0xde, 0xf7, 0xaf, 0x2d, 0xc6, 0x23, 0x00, 0xb1, 0x2b, 0x4e, 0x1c, 0xf3, 0xaf, 0x67, 0xf0, 0x9b, 0x88, 0x40, 0x79, 0x3b, 0x09, 0x78, 0x30, 0x51, 0x65, 0x38, 0x61, 0x3a, 0x00, 0x47, 0x44, 0x58, 0x41, 0x20, - 0x3a, 0x00, 0x47, 0x44, 0x59, 0x75, 0x6f, 0x70, 0x65, 0x6e, 0x64, 0x69, - 0x63, 0x65, 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x70, - 0x32, 0x35, 0x36, 0x58, 0x40, 0x5e, 0x90, 0x5d, 0x5b, 0x1e, 0xfc, 0xda, - 0xab, 0x8d, 0x52, 0xb0, 0xb4, 0xa3, 0xb9, 0xb1, 0x7e, 0x36, 0x20, 0x7f, - 0x2e, 0x4b, 0x2c, 0x86, 0x77, 0x1f, 0xf2, 0x7d, 0x5a, 0x18, 0xfb, 0x15, - 0x7b, 0x3a, 0x0a, 0xdc, 0x0a, 0x1e, 0xcb, 0xfa, 0x72, 0xac, 0x30, 0xb1, - 0x1c, 0x4b, 0xd8, 0x28, 0x70, 0x43, 0x73, 0x91, 0xe5, 0x6b, 0xab, 0xd1, - 0x55, 0xc7, 0x0c, 0xed, 0x32, 0x9b, 0xa0, 0x5e, 0x26}; + 0x3a, 0x00, 0x47, 0x44, 0x59, 0x70, 0x6f, 0x70, 0x65, 0x6e, 0x64, 0x69, + 0x63, 0x65, 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x58, 0x40, + 0x86, 0x4d, 0x64, 0xeb, 0x1d, 0x7e, 0x9a, 0x1d, 0x80, 0x5b, 0x46, 0xb3, + 0xfc, 0x21, 0x4d, 0xdf, 0x6a, 0x0d, 0x4e, 0xa5, 0x27, 0x1f, 0x56, 0xdf, + 0x2f, 0xc2, 0x08, 0x9d, 0x29, 0x4d, 0x88, 0x63, 0x64, 0x50, 0xb0, 0x7f, + 0x7e, 0x59, 0x22, 0xff, 0x9d, 0x9a, 0x44, 0x31, 0x69, 0xdf, 0xed, 0x9b, + 0x42, 0x46, 0xf7, 0xf2, 0xc9, 0x76, 0xfa, 0x44, 0x3e, 0x10, 0xb2, 0xe3, + 0xd3, 0x45, 0xb4, 0x74}; -constexpr uint8_t kExpectedCborP384Cert_DescriptorInput[795] = { - 0x84, 0x44, 0xa1, 0x01, 0x38, 0x22, 0xa0, 0x59, 0x02, 0xaf, 0xac, 0x01, +constexpr uint8_t kExpectedCborP384Cert_DescriptorInput[790] = { + 0x84, 0x44, 0xa1, 0x01, 0x38, 0x22, 0xa0, 0x59, 0x02, 0xaa, 0xac, 0x01, 0x78, 0x28, 0x35, 0x64, 0x38, 0x62, 0x36, 0x62, 0x65, 0x37, 0x63, 0x65, 0x33, 0x65, 0x64, 0x65, 0x36, 0x61, 0x32, 0x34, 0x31, 0x38, 0x30, 0x31, 0x34, 0x35, 0x32, 0x33, 0x65, 0x36, 0x63, 0x39, 0x64, 0x63, 0x38, 0x37, @@ -1301,17 +1509,205 @@ 0xb2, 0xc1, 0xc6, 0x6f, 0xb4, 0x16, 0xa4, 0x78, 0x76, 0x73, 0x6f, 0xcb, 0xf5, 0x7d, 0x26, 0xc2, 0x37, 0xe9, 0x58, 0x98, 0xeb, 0xef, 0x11, 0x7c, 0x8d, 0x1d, 0x4b, 0x3a, 0x00, 0x47, 0x44, 0x58, 0x41, 0x20, 0x3a, 0x00, - 0x47, 0x44, 0x59, 0x75, 0x6f, 0x70, 0x65, 0x6e, 0x64, 0x69, 0x63, 0x65, - 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x70, 0x33, 0x38, - 0x34, 0x58, 0x60, 0x5b, 0xe4, 0xf7, 0x39, 0x88, 0x09, 0x93, 0x73, 0x57, - 0x5d, 0xb9, 0xb1, 0xb9, 0x39, 0xa8, 0x45, 0x8c, 0xba, 0x07, 0x11, 0x9d, - 0xda, 0x23, 0x3c, 0x56, 0x82, 0x04, 0x81, 0xcb, 0x61, 0xb0, 0x1c, 0xe5, - 0xbe, 0x3b, 0xa1, 0x77, 0x44, 0xa3, 0xe0, 0x18, 0x11, 0x78, 0x9e, 0xc4, - 0x2c, 0x3f, 0xb6, 0x60, 0xa6, 0x3b, 0xe3, 0x74, 0x4d, 0xcc, 0x3a, 0x99, - 0x22, 0x66, 0x1b, 0x09, 0xb8, 0x1c, 0x81, 0x32, 0x57, 0x66, 0xde, 0xa2, - 0x76, 0x50, 0xa1, 0xee, 0xb3, 0x95, 0x60, 0x82, 0x40, 0x29, 0x30, 0x8b, - 0x19, 0x33, 0x90, 0x54, 0x47, 0xd1, 0x38, 0x25, 0xb8, 0x28, 0xe9, 0xc5, - 0x9d, 0x9a, 0x3e}; + 0x47, 0x44, 0x59, 0x70, 0x6f, 0x70, 0x65, 0x6e, 0x64, 0x69, 0x63, 0x65, + 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x58, 0x60, 0x28, 0x92, + 0x97, 0x4c, 0x88, 0xb1, 0xf1, 0xbe, 0x75, 0xda, 0xd7, 0x97, 0x0a, 0x6c, + 0xaf, 0xb0, 0x38, 0x7e, 0xb6, 0x88, 0x84, 0x2c, 0xf1, 0xda, 0xe7, 0xfc, + 0xf4, 0x24, 0x68, 0x65, 0xcb, 0xb7, 0x60, 0x81, 0x72, 0xc0, 0xb6, 0xed, + 0x6a, 0x00, 0xa5, 0xf8, 0xbf, 0x80, 0x40, 0x11, 0xbd, 0x36, 0xdc, 0x3d, + 0x9e, 0x67, 0x84, 0x82, 0xcf, 0xa5, 0xd1, 0x23, 0xc6, 0x29, 0xbd, 0x11, + 0xb5, 0x06, 0x36, 0x88, 0x0e, 0x3f, 0x66, 0xb1, 0xaa, 0x74, 0x13, 0xfa, + 0x67, 0x8a, 0xb9, 0x64, 0x7d, 0x98, 0x14, 0x5a, 0x29, 0x1c, 0x7b, 0xe8, + 0x70, 0x8e, 0xae, 0x35, 0x12, 0xc5, 0x21, 0xe2, 0x81, 0x1c}; + +constexpr uint8_t kExpectedCborEd25519Cert_AndroidDescriptorInput[683] = { + 0x84, 0x43, 0xa1, 0x01, 0x27, 0xa0, 0x59, 0x02, 0x60, 0xac, 0x01, 0x78, + 0x28, 0x34, 0x37, 0x35, 0x37, 0x30, 0x38, 0x65, 0x62, 0x33, 0x62, 0x34, + 0x32, 0x36, 0x66, 0x33, 0x38, 0x36, 0x63, 0x66, 0x63, 0x65, 0x38, 0x66, + 0x33, 0x62, 0x61, 0x66, 0x35, 0x34, 0x33, 0x39, 0x30, 0x34, 0x36, 0x32, + 0x37, 0x38, 0x64, 0x66, 0x61, 0x02, 0x78, 0x28, 0x35, 0x32, 0x31, 0x66, + 0x30, 0x33, 0x35, 0x63, 0x32, 0x31, 0x65, 0x33, 0x32, 0x66, 0x31, 0x36, + 0x37, 0x34, 0x31, 0x63, 0x31, 0x65, 0x61, 0x65, 0x36, 0x62, 0x64, 0x65, + 0x64, 0x39, 0x33, 0x63, 0x65, 0x33, 0x32, 0x31, 0x65, 0x30, 0x64, 0x66, + 0x3a, 0x00, 0x47, 0x44, 0x50, 0x58, 0x40, 0xb7, 0xd4, 0x0c, 0xcb, 0x22, + 0x5b, 0xa5, 0x78, 0x8f, 0x98, 0xff, 0x9e, 0x86, 0x93, 0x75, 0xf6, 0x90, + 0xac, 0x50, 0xcf, 0x9e, 0xbd, 0x0a, 0xfe, 0xb1, 0xd9, 0xc2, 0x4e, 0x52, + 0x19, 0xe4, 0xde, 0x29, 0xe5, 0x61, 0xf3, 0xf9, 0x29, 0xe8, 0x40, 0x87, + 0x7a, 0xdd, 0x17, 0x48, 0x05, 0x89, 0x7e, 0x2b, 0xcb, 0x54, 0x79, 0xcc, + 0x66, 0xf1, 0xb3, 0x13, 0x29, 0x0c, 0x68, 0x96, 0xb2, 0xbb, 0x8f, 0x3a, + 0x00, 0x47, 0x44, 0x51, 0x58, 0x64, 0x6c, 0x46, 0x01, 0x33, 0x26, 0x73, + 0x4b, 0x22, 0x65, 0xfd, 0xfa, 0x58, 0xd7, 0x57, 0x3e, 0x95, 0x59, 0xe0, + 0x3a, 0xc3, 0xb9, 0xf7, 0xc8, 0x0e, 0x98, 0x80, 0x8c, 0xf5, 0xc4, 0xb8, + 0xaf, 0xe3, 0x16, 0x84, 0x25, 0xa5, 0x35, 0x5d, 0x17, 0x72, 0x56, 0x8f, + 0x8e, 0xec, 0x2f, 0x5a, 0x74, 0x60, 0x77, 0x2a, 0x6e, 0x90, 0xc0, 0x4e, + 0x9f, 0x87, 0x6b, 0xf4, 0x8d, 0x9c, 0x66, 0xe3, 0x0b, 0xd2, 0x10, 0x35, + 0x21, 0xa8, 0x1d, 0xa2, 0x31, 0x17, 0xe7, 0x0c, 0xdf, 0x18, 0xf7, 0x94, + 0xe4, 0xd1, 0xca, 0x32, 0x7d, 0xf2, 0x63, 0x23, 0x1d, 0xbc, 0x84, 0x74, + 0x61, 0xdb, 0x87, 0xf2, 0xab, 0x72, 0xad, 0xaf, 0x08, 0xf8, 0x3a, 0x00, + 0x47, 0x44, 0x53, 0x58, 0x28, 0x1b, 0x40, 0xc1, 0xa9, 0x77, 0x60, 0xeb, + 0xc3, 0x67, 0xf0, 0x5f, 0x6a, 0xe1, 0x5e, 0x20, 0xc2, 0x51, 0x68, 0x4d, + 0x82, 0x48, 0x8b, 0x03, 0x32, 0x16, 0x79, 0x88, 0x14, 0x37, 0x78, 0x7f, + 0x16, 0x9a, 0x06, 0xfd, 0xc0, 0x8a, 0x15, 0x80, 0x62, 0x3a, 0x00, 0x47, + 0x44, 0x52, 0x58, 0x40, 0x45, 0x00, 0xe9, 0x5c, 0xbd, 0x00, 0x57, 0x04, + 0x55, 0x87, 0x6c, 0xbd, 0x2f, 0xea, 0x41, 0x9c, 0x66, 0x42, 0x51, 0x41, + 0xbb, 0x44, 0xed, 0x0e, 0xe9, 0x66, 0xcf, 0xd5, 0x10, 0x73, 0x0d, 0x4b, + 0x48, 0xe4, 0x7a, 0x53, 0x35, 0x01, 0x0e, 0x6d, 0x15, 0x55, 0xc5, 0xb7, + 0xd2, 0xd5, 0x36, 0xb6, 0xbc, 0x7e, 0xb0, 0xf3, 0x3d, 0xe6, 0x19, 0x78, + 0x62, 0xeb, 0x02, 0x57, 0x39, 0x56, 0x73, 0x4f, 0x3a, 0x00, 0x47, 0x44, + 0x54, 0x58, 0x40, 0x22, 0x52, 0x60, 0x17, 0xef, 0x2c, 0xa1, 0xf6, 0xcb, + 0xed, 0x39, 0xd5, 0xe2, 0xaa, 0x65, 0x20, 0xfb, 0xad, 0x82, 0x93, 0xe5, + 0x78, 0x23, 0x22, 0x97, 0xc1, 0x6e, 0x6a, 0x4e, 0x36, 0xd7, 0x6a, 0x61, + 0x39, 0x08, 0x21, 0xd4, 0xfe, 0x92, 0x5f, 0x36, 0x2d, 0xeb, 0x5d, 0xbb, + 0x32, 0x8b, 0xe3, 0x94, 0x4f, 0xbe, 0x1b, 0x21, 0xf9, 0xcc, 0x23, 0x73, + 0x41, 0xb6, 0xb9, 0xb6, 0x98, 0xd0, 0xbc, 0x3a, 0x00, 0x47, 0x44, 0x55, + 0x58, 0x41, 0x92, 0xd6, 0x97, 0xb3, 0x83, 0xdf, 0xe7, 0x8c, 0xc7, 0xbc, + 0x4a, 0xfc, 0xea, 0x76, 0xc0, 0x53, 0x66, 0xbd, 0x2c, 0x1e, 0x10, 0x31, + 0x90, 0x80, 0x11, 0x2d, 0x08, 0x4d, 0x7c, 0x39, 0x76, 0xdc, 0x73, 0xe7, + 0x1c, 0x16, 0x62, 0xd5, 0x59, 0xd7, 0x49, 0x2b, 0x6a, 0xa2, 0x36, 0x67, + 0x57, 0xd1, 0xf2, 0xf9, 0xaf, 0x13, 0xd7, 0xa3, 0xe4, 0xd3, 0x39, 0x5b, + 0x02, 0x78, 0xb1, 0xe0, 0x09, 0x70, 0xa2, 0x3a, 0x00, 0x47, 0x44, 0x56, + 0x41, 0x00, 0x3a, 0x00, 0x47, 0x44, 0x57, 0x58, 0x2d, 0xa5, 0x01, 0x01, + 0x03, 0x27, 0x04, 0x81, 0x02, 0x20, 0x06, 0x21, 0x58, 0x20, 0x93, 0x7f, + 0xd9, 0xc0, 0x4d, 0xc6, 0xbb, 0x2e, 0x1d, 0x11, 0x62, 0xcd, 0x5c, 0x76, + 0x94, 0xc7, 0xdb, 0x02, 0x54, 0x0c, 0x85, 0x01, 0x3a, 0x01, 0xab, 0x37, + 0xfa, 0xce, 0xf9, 0x6e, 0x62, 0x20, 0x3a, 0x00, 0x47, 0x44, 0x58, 0x41, + 0x20, 0x3a, 0x00, 0x47, 0x44, 0x59, 0x6a, 0x61, 0x6e, 0x64, 0x72, 0x6f, + 0x69, 0x64, 0x2e, 0x31, 0x36, 0x58, 0x40, 0xbf, 0xea, 0x43, 0x83, 0x56, + 0xfe, 0x0b, 0x0b, 0xc4, 0xc9, 0xe9, 0x4b, 0x06, 0x68, 0xcd, 0x43, 0x2f, + 0xaf, 0x36, 0x7a, 0xcf, 0x78, 0x1a, 0x39, 0x01, 0x05, 0xfe, 0xd1, 0xd8, + 0x4a, 0xe2, 0x4e, 0x0c, 0xd4, 0xdb, 0x71, 0x0b, 0xd1, 0x13, 0x2d, 0x6e, + 0x65, 0x70, 0x81, 0x34, 0x8d, 0x51, 0x33, 0xa2, 0xaf, 0xfb, 0xc7, 0x7f, + 0x46, 0x5a, 0xce, 0xfe, 0x4b, 0x45, 0x81, 0xd6, 0x1e, 0x74, 0x08}; + +constexpr uint8_t kExpectedCborP256Cert_AndroidDescriptorInput[718] = { + 0x84, 0x43, 0xa1, 0x01, 0x26, 0xa0, 0x59, 0x02, 0x83, 0xac, 0x01, 0x78, + 0x28, 0x34, 0x38, 0x36, 0x30, 0x33, 0x63, 0x30, 0x30, 0x35, 0x32, 0x63, + 0x31, 0x63, 0x61, 0x63, 0x37, 0x33, 0x63, 0x61, 0x65, 0x33, 0x36, 0x63, + 0x33, 0x62, 0x64, 0x65, 0x63, 0x37, 0x63, 0x36, 0x31, 0x33, 0x39, 0x38, + 0x38, 0x35, 0x63, 0x39, 0x64, 0x02, 0x78, 0x28, 0x35, 0x61, 0x30, 0x34, + 0x65, 0x39, 0x65, 0x63, 0x66, 0x31, 0x39, 0x61, 0x64, 0x33, 0x64, 0x35, + 0x32, 0x36, 0x36, 0x38, 0x62, 0x38, 0x32, 0x61, 0x36, 0x30, 0x38, 0x31, + 0x66, 0x30, 0x33, 0x66, 0x64, 0x62, 0x32, 0x39, 0x66, 0x38, 0x36, 0x34, + 0x3a, 0x00, 0x47, 0x44, 0x50, 0x58, 0x40, 0xb7, 0xd4, 0x0c, 0xcb, 0x22, + 0x5b, 0xa5, 0x78, 0x8f, 0x98, 0xff, 0x9e, 0x86, 0x93, 0x75, 0xf6, 0x90, + 0xac, 0x50, 0xcf, 0x9e, 0xbd, 0x0a, 0xfe, 0xb1, 0xd9, 0xc2, 0x4e, 0x52, + 0x19, 0xe4, 0xde, 0x29, 0xe5, 0x61, 0xf3, 0xf9, 0x29, 0xe8, 0x40, 0x87, + 0x7a, 0xdd, 0x17, 0x48, 0x05, 0x89, 0x7e, 0x2b, 0xcb, 0x54, 0x79, 0xcc, + 0x66, 0xf1, 0xb3, 0x13, 0x29, 0x0c, 0x68, 0x96, 0xb2, 0xbb, 0x8f, 0x3a, + 0x00, 0x47, 0x44, 0x51, 0x58, 0x64, 0x6c, 0x46, 0x01, 0x33, 0x26, 0x73, + 0x4b, 0x22, 0x65, 0xfd, 0xfa, 0x58, 0xd7, 0x57, 0x3e, 0x95, 0x59, 0xe0, + 0x3a, 0xc3, 0xb9, 0xf7, 0xc8, 0x0e, 0x98, 0x80, 0x8c, 0xf5, 0xc4, 0xb8, + 0xaf, 0xe3, 0x16, 0x84, 0x25, 0xa5, 0x35, 0x5d, 0x17, 0x72, 0x56, 0x8f, + 0x8e, 0xec, 0x2f, 0x5a, 0x74, 0x60, 0x77, 0x2a, 0x6e, 0x90, 0xc0, 0x4e, + 0x9f, 0x87, 0x6b, 0xf4, 0x8d, 0x9c, 0x66, 0xe3, 0x0b, 0xd2, 0x10, 0x35, + 0x21, 0xa8, 0x1d, 0xa2, 0x31, 0x17, 0xe7, 0x0c, 0xdf, 0x18, 0xf7, 0x94, + 0xe4, 0xd1, 0xca, 0x32, 0x7d, 0xf2, 0x63, 0x23, 0x1d, 0xbc, 0x84, 0x74, + 0x61, 0xdb, 0x87, 0xf2, 0xab, 0x72, 0xad, 0xaf, 0x08, 0xf8, 0x3a, 0x00, + 0x47, 0x44, 0x53, 0x58, 0x28, 0x1b, 0x40, 0xc1, 0xa9, 0x77, 0x60, 0xeb, + 0xc3, 0x67, 0xf0, 0x5f, 0x6a, 0xe1, 0x5e, 0x20, 0xc2, 0x51, 0x68, 0x4d, + 0x82, 0x48, 0x8b, 0x03, 0x32, 0x16, 0x79, 0x88, 0x14, 0x37, 0x78, 0x7f, + 0x16, 0x9a, 0x06, 0xfd, 0xc0, 0x8a, 0x15, 0x80, 0x62, 0x3a, 0x00, 0x47, + 0x44, 0x52, 0x58, 0x40, 0x45, 0x00, 0xe9, 0x5c, 0xbd, 0x00, 0x57, 0x04, + 0x55, 0x87, 0x6c, 0xbd, 0x2f, 0xea, 0x41, 0x9c, 0x66, 0x42, 0x51, 0x41, + 0xbb, 0x44, 0xed, 0x0e, 0xe9, 0x66, 0xcf, 0xd5, 0x10, 0x73, 0x0d, 0x4b, + 0x48, 0xe4, 0x7a, 0x53, 0x35, 0x01, 0x0e, 0x6d, 0x15, 0x55, 0xc5, 0xb7, + 0xd2, 0xd5, 0x36, 0xb6, 0xbc, 0x7e, 0xb0, 0xf3, 0x3d, 0xe6, 0x19, 0x78, + 0x62, 0xeb, 0x02, 0x57, 0x39, 0x56, 0x73, 0x4f, 0x3a, 0x00, 0x47, 0x44, + 0x54, 0x58, 0x40, 0x22, 0x52, 0x60, 0x17, 0xef, 0x2c, 0xa1, 0xf6, 0xcb, + 0xed, 0x39, 0xd5, 0xe2, 0xaa, 0x65, 0x20, 0xfb, 0xad, 0x82, 0x93, 0xe5, + 0x78, 0x23, 0x22, 0x97, 0xc1, 0x6e, 0x6a, 0x4e, 0x36, 0xd7, 0x6a, 0x61, + 0x39, 0x08, 0x21, 0xd4, 0xfe, 0x92, 0x5f, 0x36, 0x2d, 0xeb, 0x5d, 0xbb, + 0x32, 0x8b, 0xe3, 0x94, 0x4f, 0xbe, 0x1b, 0x21, 0xf9, 0xcc, 0x23, 0x73, + 0x41, 0xb6, 0xb9, 0xb6, 0x98, 0xd0, 0xbc, 0x3a, 0x00, 0x47, 0x44, 0x55, + 0x58, 0x41, 0x92, 0xd6, 0x97, 0xb3, 0x83, 0xdf, 0xe7, 0x8c, 0xc7, 0xbc, + 0x4a, 0xfc, 0xea, 0x76, 0xc0, 0x53, 0x66, 0xbd, 0x2c, 0x1e, 0x10, 0x31, + 0x90, 0x80, 0x11, 0x2d, 0x08, 0x4d, 0x7c, 0x39, 0x76, 0xdc, 0x73, 0xe7, + 0x1c, 0x16, 0x62, 0xd5, 0x59, 0xd7, 0x49, 0x2b, 0x6a, 0xa2, 0x36, 0x67, + 0x57, 0xd1, 0xf2, 0xf9, 0xaf, 0x13, 0xd7, 0xa3, 0xe4, 0xd3, 0x39, 0x5b, + 0x02, 0x78, 0xb1, 0xe0, 0x09, 0x70, 0xa2, 0x3a, 0x00, 0x47, 0x44, 0x56, + 0x41, 0x00, 0x3a, 0x00, 0x47, 0x44, 0x57, 0x58, 0x50, 0xa6, 0x01, 0x02, + 0x03, 0x26, 0x04, 0x81, 0x02, 0x20, 0x01, 0x21, 0x58, 0x20, 0x6d, 0x1e, + 0xdd, 0x35, 0x38, 0x70, 0xc2, 0x8a, 0x01, 0xdf, 0x80, 0xb1, 0xa5, 0xae, + 0x85, 0x4b, 0x7a, 0x12, 0xdd, 0x11, 0xf6, 0x97, 0x27, 0x44, 0x9b, 0x27, + 0xf3, 0x87, 0x97, 0xb3, 0xe7, 0x36, 0x22, 0x58, 0x20, 0xe6, 0x42, 0x87, + 0x8c, 0x72, 0xde, 0xf7, 0xaf, 0x2d, 0xc6, 0x23, 0x00, 0xb1, 0x2b, 0x4e, + 0x1c, 0xf3, 0xaf, 0x67, 0xf0, 0x9b, 0x88, 0x40, 0x79, 0x3b, 0x09, 0x78, + 0x30, 0x51, 0x65, 0x38, 0x61, 0x3a, 0x00, 0x47, 0x44, 0x58, 0x41, 0x20, + 0x3a, 0x00, 0x47, 0x44, 0x59, 0x6a, 0x61, 0x6e, 0x64, 0x72, 0x6f, 0x69, + 0x64, 0x2e, 0x31, 0x36, 0x58, 0x40, 0x6f, 0xa6, 0x44, 0x07, 0x57, 0x7e, + 0xe3, 0xf1, 0x8b, 0xfb, 0x82, 0xbc, 0x87, 0xaf, 0x9e, 0x0d, 0xff, 0x9b, + 0xa1, 0x06, 0xfe, 0x56, 0x82, 0x6a, 0xa2, 0x24, 0x49, 0x25, 0x32, 0x20, + 0xfd, 0x97, 0xaa, 0x1d, 0x28, 0xc6, 0xd6, 0x3c, 0x86, 0x06, 0x07, 0x70, + 0xf5, 0x0b, 0x8f, 0x80, 0x73, 0x1a, 0xe0, 0x60, 0x72, 0x24, 0x3e, 0xe1, + 0xfd, 0x0c, 0x6b, 0x14, 0xc5, 0x38, 0x42, 0x39, 0x0c, 0x90}; + +constexpr uint8_t kExpectedCborP384Cert_AndroidDescriptorInput[784] = { + 0x84, 0x44, 0xa1, 0x01, 0x38, 0x22, 0xa0, 0x59, 0x02, 0xa4, 0xac, 0x01, + 0x78, 0x28, 0x35, 0x64, 0x38, 0x62, 0x36, 0x62, 0x65, 0x37, 0x63, 0x65, + 0x33, 0x65, 0x64, 0x65, 0x36, 0x61, 0x32, 0x34, 0x31, 0x38, 0x30, 0x31, + 0x34, 0x35, 0x32, 0x33, 0x65, 0x36, 0x63, 0x39, 0x64, 0x63, 0x38, 0x37, + 0x65, 0x39, 0x38, 0x63, 0x63, 0x36, 0x02, 0x78, 0x28, 0x36, 0x66, 0x31, + 0x33, 0x39, 0x63, 0x37, 0x62, 0x32, 0x62, 0x31, 0x36, 0x61, 0x63, 0x38, + 0x31, 0x30, 0x32, 0x34, 0x64, 0x35, 0x37, 0x34, 0x39, 0x36, 0x62, 0x31, + 0x62, 0x37, 0x61, 0x31, 0x33, 0x66, 0x64, 0x33, 0x65, 0x38, 0x30, 0x37, + 0x66, 0x3a, 0x00, 0x47, 0x44, 0x50, 0x58, 0x40, 0xb7, 0xd4, 0x0c, 0xcb, + 0x22, 0x5b, 0xa5, 0x78, 0x8f, 0x98, 0xff, 0x9e, 0x86, 0x93, 0x75, 0xf6, + 0x90, 0xac, 0x50, 0xcf, 0x9e, 0xbd, 0x0a, 0xfe, 0xb1, 0xd9, 0xc2, 0x4e, + 0x52, 0x19, 0xe4, 0xde, 0x29, 0xe5, 0x61, 0xf3, 0xf9, 0x29, 0xe8, 0x40, + 0x87, 0x7a, 0xdd, 0x17, 0x48, 0x05, 0x89, 0x7e, 0x2b, 0xcb, 0x54, 0x79, + 0xcc, 0x66, 0xf1, 0xb3, 0x13, 0x29, 0x0c, 0x68, 0x96, 0xb2, 0xbb, 0x8f, + 0x3a, 0x00, 0x47, 0x44, 0x51, 0x58, 0x64, 0x6c, 0x46, 0x01, 0x33, 0x26, + 0x73, 0x4b, 0x22, 0x65, 0xfd, 0xfa, 0x58, 0xd7, 0x57, 0x3e, 0x95, 0x59, + 0xe0, 0x3a, 0xc3, 0xb9, 0xf7, 0xc8, 0x0e, 0x98, 0x80, 0x8c, 0xf5, 0xc4, + 0xb8, 0xaf, 0xe3, 0x16, 0x84, 0x25, 0xa5, 0x35, 0x5d, 0x17, 0x72, 0x56, + 0x8f, 0x8e, 0xec, 0x2f, 0x5a, 0x74, 0x60, 0x77, 0x2a, 0x6e, 0x90, 0xc0, + 0x4e, 0x9f, 0x87, 0x6b, 0xf4, 0x8d, 0x9c, 0x66, 0xe3, 0x0b, 0xd2, 0x10, + 0x35, 0x21, 0xa8, 0x1d, 0xa2, 0x31, 0x17, 0xe7, 0x0c, 0xdf, 0x18, 0xf7, + 0x94, 0xe4, 0xd1, 0xca, 0x32, 0x7d, 0xf2, 0x63, 0x23, 0x1d, 0xbc, 0x84, + 0x74, 0x61, 0xdb, 0x87, 0xf2, 0xab, 0x72, 0xad, 0xaf, 0x08, 0xf8, 0x3a, + 0x00, 0x47, 0x44, 0x53, 0x58, 0x28, 0x1b, 0x40, 0xc1, 0xa9, 0x77, 0x60, + 0xeb, 0xc3, 0x67, 0xf0, 0x5f, 0x6a, 0xe1, 0x5e, 0x20, 0xc2, 0x51, 0x68, + 0x4d, 0x82, 0x48, 0x8b, 0x03, 0x32, 0x16, 0x79, 0x88, 0x14, 0x37, 0x78, + 0x7f, 0x16, 0x9a, 0x06, 0xfd, 0xc0, 0x8a, 0x15, 0x80, 0x62, 0x3a, 0x00, + 0x47, 0x44, 0x52, 0x58, 0x40, 0x45, 0x00, 0xe9, 0x5c, 0xbd, 0x00, 0x57, + 0x04, 0x55, 0x87, 0x6c, 0xbd, 0x2f, 0xea, 0x41, 0x9c, 0x66, 0x42, 0x51, + 0x41, 0xbb, 0x44, 0xed, 0x0e, 0xe9, 0x66, 0xcf, 0xd5, 0x10, 0x73, 0x0d, + 0x4b, 0x48, 0xe4, 0x7a, 0x53, 0x35, 0x01, 0x0e, 0x6d, 0x15, 0x55, 0xc5, + 0xb7, 0xd2, 0xd5, 0x36, 0xb6, 0xbc, 0x7e, 0xb0, 0xf3, 0x3d, 0xe6, 0x19, + 0x78, 0x62, 0xeb, 0x02, 0x57, 0x39, 0x56, 0x73, 0x4f, 0x3a, 0x00, 0x47, + 0x44, 0x54, 0x58, 0x40, 0x22, 0x52, 0x60, 0x17, 0xef, 0x2c, 0xa1, 0xf6, + 0xcb, 0xed, 0x39, 0xd5, 0xe2, 0xaa, 0x65, 0x20, 0xfb, 0xad, 0x82, 0x93, + 0xe5, 0x78, 0x23, 0x22, 0x97, 0xc1, 0x6e, 0x6a, 0x4e, 0x36, 0xd7, 0x6a, + 0x61, 0x39, 0x08, 0x21, 0xd4, 0xfe, 0x92, 0x5f, 0x36, 0x2d, 0xeb, 0x5d, + 0xbb, 0x32, 0x8b, 0xe3, 0x94, 0x4f, 0xbe, 0x1b, 0x21, 0xf9, 0xcc, 0x23, + 0x73, 0x41, 0xb6, 0xb9, 0xb6, 0x98, 0xd0, 0xbc, 0x3a, 0x00, 0x47, 0x44, + 0x55, 0x58, 0x41, 0x92, 0xd6, 0x97, 0xb3, 0x83, 0xdf, 0xe7, 0x8c, 0xc7, + 0xbc, 0x4a, 0xfc, 0xea, 0x76, 0xc0, 0x53, 0x66, 0xbd, 0x2c, 0x1e, 0x10, + 0x31, 0x90, 0x80, 0x11, 0x2d, 0x08, 0x4d, 0x7c, 0x39, 0x76, 0xdc, 0x73, + 0xe7, 0x1c, 0x16, 0x62, 0xd5, 0x59, 0xd7, 0x49, 0x2b, 0x6a, 0xa2, 0x36, + 0x67, 0x57, 0xd1, 0xf2, 0xf9, 0xaf, 0x13, 0xd7, 0xa3, 0xe4, 0xd3, 0x39, + 0x5b, 0x02, 0x78, 0xb1, 0xe0, 0x09, 0x70, 0xa2, 0x3a, 0x00, 0x47, 0x44, + 0x56, 0x41, 0x00, 0x3a, 0x00, 0x47, 0x44, 0x57, 0x58, 0x71, 0xa6, 0x01, + 0x02, 0x03, 0x38, 0x22, 0x04, 0x81, 0x02, 0x20, 0x02, 0x21, 0x58, 0x30, + 0xb4, 0x02, 0x19, 0x48, 0xca, 0xdd, 0x23, 0x4b, 0x92, 0x91, 0x22, 0x8d, + 0xa8, 0x80, 0x85, 0xc0, 0xf9, 0x23, 0xe4, 0x89, 0xbd, 0x91, 0x8d, 0xf3, + 0x8f, 0xa3, 0x73, 0x60, 0x70, 0x19, 0xc6, 0x33, 0x76, 0xbf, 0xd4, 0x60, + 0xfa, 0xdc, 0xde, 0x46, 0x58, 0x51, 0x13, 0x1d, 0x73, 0x81, 0x79, 0xff, + 0x22, 0x58, 0x30, 0x39, 0x79, 0x1b, 0x49, 0x6a, 0xcf, 0x37, 0x8f, 0xf4, + 0x1a, 0xc2, 0x29, 0xb5, 0x80, 0x2f, 0x7b, 0x2b, 0x0a, 0x27, 0x96, 0xb3, + 0xb2, 0xc1, 0xc6, 0x6f, 0xb4, 0x16, 0xa4, 0x78, 0x76, 0x73, 0x6f, 0xcb, + 0xf5, 0x7d, 0x26, 0xc2, 0x37, 0xe9, 0x58, 0x98, 0xeb, 0xef, 0x11, 0x7c, + 0x8d, 0x1d, 0x4b, 0x3a, 0x00, 0x47, 0x44, 0x58, 0x41, 0x20, 0x3a, 0x00, + 0x47, 0x44, 0x59, 0x6a, 0x61, 0x6e, 0x64, 0x72, 0x6f, 0x69, 0x64, 0x2e, + 0x31, 0x36, 0x58, 0x60, 0x7f, 0x81, 0xa3, 0x5b, 0xf5, 0x5c, 0x9f, 0x82, + 0x4b, 0x0a, 0x63, 0x57, 0xed, 0x66, 0x8e, 0x66, 0x23, 0x85, 0x98, 0x7e, + 0xe0, 0x74, 0x92, 0x96, 0x3a, 0xac, 0x92, 0xf7, 0x3f, 0x34, 0x58, 0x13, + 0x5e, 0x00, 0xb4, 0x5c, 0x08, 0xc6, 0xfa, 0x07, 0xa0, 0x18, 0x82, 0x5f, + 0x56, 0xdb, 0x6b, 0xc1, 0x5b, 0xf8, 0x3b, 0x20, 0x14, 0xec, 0x55, 0x0b, + 0x9b, 0xfe, 0xbf, 0xe1, 0xf3, 0xc4, 0x27, 0xd8, 0x35, 0x6c, 0xad, 0x43, + 0x46, 0x59, 0x65, 0xb3, 0x7e, 0x22, 0x93, 0xfe, 0xbd, 0x37, 0xe5, 0xa2, + 0x76, 0x13, 0x9b, 0xa0, 0x65, 0x06, 0xa9, 0x01, 0x7a, 0x49, 0x58, 0x4c, + 0xef, 0x13, 0x84, 0xf3}; } // namespace test } // namespace dice
diff --git a/include/dice/types.h b/include/dice/types.h index 3f004df..7c36d1c 100644 --- a/include/dice/types.h +++ b/include/dice/types.h
@@ -45,8 +45,6 @@ // Parameters related to the DICE key operations. // // Fields: -// profile_name: Name of the profile. NULL if not specified. The pointer -// should point to a valid static string or NULL. // public_key_size: Actual size of the public key. // signature_size: Actual size of the signature. // cose_key_type: Key type that is represented as the 'kty' member of the @@ -54,7 +52,6 @@ // cose_key_algorithm: COSE algorithm identifier for the key. // cose_key_curve: COSE curve identifier for the key. typedef struct DiceKeyParam_ { - const char* profile_name; size_t public_key_size; size_t signature_size; int64_t cose_key_type;
diff --git a/src/boringssl_cert_op.c b/src/boringssl_cert_op.c index 21ce297..79ce6d3 100644 --- a/src/boringssl_cert_op.c +++ b/src/boringssl_cert_op.c
@@ -21,6 +21,7 @@ #include "dice/dice.h" #include "dice/ops.h" +#include "dice/profile_name.h" #include "dice/utils.h" #include "openssl/asn1.h" #include "openssl/asn1t.h" @@ -310,8 +311,7 @@ return result; } -static DiceResult GetDiceExtensionData(const char* profile_name, - const DiceInputValues* input_values, +static DiceResult GetDiceExtensionData(const DiceInputValues* input_values, size_t buffer_size, uint8_t* buffer, size_t* actual_size) { DiceResult result = kDiceResultOk; @@ -431,14 +431,14 @@ } // Encode profile name. - if (profile_name) { + if (DICE_PROFILE_NAME) { asn1->profile_name = ASN1_UTF8STRING_new(); if (!asn1->profile_name) { result = kDiceResultPlatformError; goto out; } - if (!ASN1_STRING_set(asn1->profile_name, profile_name, - strlen(profile_name))) { + if (!ASN1_STRING_set(asn1->profile_name, DICE_PROFILE_NAME, + strlen(DICE_PROFILE_NAME))) { result = kDiceResultPlatformError; goto out; } @@ -458,8 +458,7 @@ return result; } -static DiceResult AddDiceExtension(const char* profile_name, - const DiceInputValues* input_values, +static DiceResult AddDiceExtension(const DiceInputValues* input_values, X509* x509) { const char* kDiceExtensionOid = "1.3.6.1.4.1.11129.2.1.24"; @@ -471,7 +470,7 @@ uint8_t extension_buffer[DICE_MAX_EXTENSION_SIZE]; size_t extension_size = 0; DiceResult result = - GetDiceExtensionData(profile_name, input_values, sizeof(extension_buffer), + GetDiceExtensionData(input_values, sizeof(extension_buffer), extension_buffer, &extension_size); if (result != kDiceResultOk) { goto out; @@ -589,7 +588,7 @@ if (result != kDiceResultOk) { goto out; } - result = AddDiceExtension(key_param.profile_name, input_values, x509); + result = AddDiceExtension(input_values, x509); if (result != kDiceResultOk) { goto out; }
diff --git a/src/boringssl_ed25519_ops.c b/src/boringssl_ed25519_ops.c index 7d94bff..f646ac6 100644 --- a/src/boringssl_ed25519_ops.c +++ b/src/boringssl_ed25519_ops.c
@@ -34,14 +34,11 @@ #error "Ed25519 needs 64 bytes to store the signature." #endif -#define DICE_PROFILE_NAME NULL - DiceResult DiceGetKeyParam(void* context_not_used, DicePrincipal principal_not_used, DiceKeyParam* key_param) { (void)context_not_used; (void)principal_not_used; - key_param->profile_name = DICE_PROFILE_NAME; key_param->public_key_size = DICE_PUBLIC_KEY_BUFFER_SIZE; key_param->signature_size = DICE_SIGNATURE_BUFFER_SIZE;
diff --git a/src/boringssl_multialg_ops.c b/src/boringssl_multialg_ops.c index 745329e..2ac1a09 100644 --- a/src/boringssl_multialg_ops.c +++ b/src/boringssl_multialg_ops.c
@@ -37,10 +37,6 @@ #error "Multialg needs 96 bytes to store the signature (P-384)" #endif -#define DICE_PROFILE_NAME_ED25519 NULL -#define DICE_PROFILE_NAME_P256 "opendice.example.p256" -#define DICE_PROFILE_NAME_P384 "opendice.example.p384" - DiceResult DiceGetKeyParam(void* context, DicePrincipal principal, DiceKeyParam* key_param) { DiceKeyAlgorithm alg; @@ -50,7 +46,6 @@ } switch (alg) { case kDiceKeyAlgorithmEd25519: - key_param->profile_name = DICE_PROFILE_NAME_ED25519; key_param->public_key_size = 32; key_param->signature_size = 64; @@ -59,7 +54,6 @@ key_param->cose_key_curve = kCoseCrvEd25519; return kDiceResultOk; case kDiceKeyAlgorithmP256: - key_param->profile_name = DICE_PROFILE_NAME_P256; key_param->public_key_size = 64; key_param->signature_size = 64; @@ -68,7 +62,6 @@ key_param->cose_key_curve = kCoseCrvP256; return kDiceResultOk; case kDiceKeyAlgorithmP384: - key_param->profile_name = DICE_PROFILE_NAME_P384; key_param->public_key_size = 96; key_param->signature_size = 96;
diff --git a/src/boringssl_p256_ops.c b/src/boringssl_p256_ops.c index a39f3b8..621eafe 100644 --- a/src/boringssl_p256_ops.c +++ b/src/boringssl_p256_ops.c
@@ -35,14 +35,11 @@ #error "P-256 needs 64 bytes to store the signature." #endif -#define DICE_PROFILE_NAME "opendice.example.p256" - DiceResult DiceGetKeyParam(void* context_not_used, DicePrincipal principal_not_used, DiceKeyParam* key_param) { (void)context_not_used; (void)principal_not_used; - key_param->profile_name = DICE_PROFILE_NAME; key_param->public_key_size = DICE_PUBLIC_KEY_BUFFER_SIZE; key_param->signature_size = DICE_SIGNATURE_BUFFER_SIZE;
diff --git a/src/boringssl_p384_ops.c b/src/boringssl_p384_ops.c index 9ff53c9..0a340db 100644 --- a/src/boringssl_p384_ops.c +++ b/src/boringssl_p384_ops.c
@@ -35,14 +35,11 @@ #error "P-384 needs 96 bytes to store the signature." #endif -#define DICE_PROFILE_NAME "opendice.example.p384" - DiceResult DiceGetKeyParam(void* context_not_used, DicePrincipal principal_not_used, DiceKeyParam* key_param) { (void)context_not_used; (void)principal_not_used; - key_param->profile_name = DICE_PROFILE_NAME; key_param->public_key_size = DICE_PUBLIC_KEY_BUFFER_SIZE; key_param->signature_size = DICE_SIGNATURE_BUFFER_SIZE;
diff --git a/src/cbor_cert_op.c b/src/cbor_cert_op.c index 49664e3..da0ba94 100644 --- a/src/cbor_cert_op.c +++ b/src/cbor_cert_op.c
@@ -25,6 +25,7 @@ #include "dice/dice.h" #include "dice/ops.h" #include "dice/ops/trait/cose.h" +#include "dice/profile_name.h" #include "dice/utils.h" // Max size of COSE_Key encoding. @@ -226,7 +227,7 @@ if (result != kDiceResultOk) { return result; } - if (key_param.profile_name) { + if (DICE_PROFILE_NAME) { map_pairs += 1; } @@ -292,9 +293,9 @@ CborWriteInt(kKeyUsageLabel, &out); CborWriteBstr(/*data_size=*/1, &key_usage, &out); // Add the profile name - if (key_param.profile_name) { + if (DICE_PROFILE_NAME) { CborWriteInt(kProfileNameLabel, &out); - CborWriteTstr(key_param.profile_name, &out); + CborWriteTstr(DICE_PROFILE_NAME, &out); } *encoded_size = CborOutSize(&out); if (CborOutOverflowed(&out)) {
diff --git a/src/cbor_cert_op_test.cc b/src/cbor_cert_op_test.cc index db7545f..e01c3dc 100644 --- a/src/cbor_cert_op_test.cc +++ b/src/cbor_cert_op_test.cc
@@ -44,15 +44,16 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_Ed25519, "zero_input", next_state); + DumpState(CertificateType_Cbor, KeyType_Ed25519, "android_zero_input", + next_state); // Both CDI values and the certificate should be deterministic. EXPECT_EQ(0, memcmp(next_state.cdi_attest, dice::test::kExpectedCdiAttest_ZeroInput, DICE_CDI_SIZE)); EXPECT_EQ(0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_ZeroInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_ZeroInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_AndroidZeroInput), next_state.certificate_size); - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborEd25519Cert_ZeroInput, + EXPECT_EQ(0, memcmp(dice::test::kExpectedCborEd25519Cert_AndroidZeroInput, next_state.certificate, next_state.certificate_size)); } @@ -60,15 +61,15 @@ DiceStateForTest current_state = {}; DiceStateForTest next_state = {}; DiceInputValues input_values = {}; - ASSERT_LE(sizeof(dice::test::kExpectedCborEd25519Cert_ZeroInput) / 2, + ASSERT_LE(sizeof(dice::test::kExpectedCborEd25519Cert_AndroidZeroInput) / 2, sizeof(next_state.certificate)); DiceResult result = DiceMainFlow( NULL, current_state.cdi_attest, current_state.cdi_seal, &input_values, - sizeof(dice::test::kExpectedCborEd25519Cert_ZeroInput) / 2, + sizeof(dice::test::kExpectedCborEd25519Cert_AndroidZeroInput) / 2, next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultBufferTooSmall, result); - EXPECT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_ZeroInput), + EXPECT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_AndroidZeroInput), next_state.certificate_size); } @@ -90,7 +91,7 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_Ed25519, "hash_only_input", + DumpState(CertificateType_Cbor, KeyType_Ed25519, "android_hash_only_input", next_state); // Both CDI values and the certificate should be deterministic. EXPECT_EQ( @@ -99,9 +100,9 @@ EXPECT_EQ( 0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_HashOnlyInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_HashOnlyInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_AndroidHashOnlyInput), next_state.certificate_size); - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborEd25519Cert_HashOnlyInput, + EXPECT_EQ(0, memcmp(dice::test::kExpectedCborEd25519Cert_AndroidHashOnlyInput, next_state.certificate, next_state.certificate_size)); } @@ -139,7 +140,7 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_Ed25519, "descriptor_input", + DumpState(CertificateType_Cbor, KeyType_Ed25519, "android_descriptor_input", next_state); // Both CDI values and the certificate should be deterministic. EXPECT_EQ( @@ -148,10 +149,11 @@ EXPECT_EQ( 0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_DescriptorInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_DescriptorInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_AndroidDescriptorInput), next_state.certificate_size); - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborEd25519Cert_DescriptorInput, - next_state.certificate, next_state.certificate_size)); + EXPECT_EQ(0, + memcmp(dice::test::kExpectedCborEd25519Cert_AndroidDescriptorInput, + next_state.certificate, next_state.certificate_size)); } TEST(DiceOpsTest, NonZeroMode) {
diff --git a/src/cbor_multialg_op_test.cc b/src/cbor_multialg_op_test.cc index 8e8eadd..ee3ba42 100644 --- a/src/cbor_multialg_op_test.cc +++ b/src/cbor_multialg_op_test.cc
@@ -57,7 +57,8 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_Ed25519, "zero_input", next_state); + DumpState(CertificateType_Cbor, KeyType_Ed25519, "android_zero_input", + next_state); // The CDI values should be deterministic. ASSERT_EQ(sizeof(next_state.cdi_attest), sizeof(dice::test::kExpectedCdiAttest_ZeroInput)); @@ -67,9 +68,9 @@ sizeof(dice::test::kExpectedCdiSeal_ZeroInput)); EXPECT_EQ(0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_ZeroInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_ZeroInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_AndroidZeroInput), next_state.certificate_size); - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborEd25519Cert_ZeroInput, + EXPECT_EQ(0, memcmp(dice::test::kExpectedCborEd25519Cert_AndroidZeroInput, next_state.certificate, next_state.certificate_size)); } @@ -84,7 +85,8 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_P256, "zero_input", next_state); + DumpState(CertificateType_Cbor, KeyType_P256, "android_zero_input", + next_state); // The CDI values should be deterministic. ASSERT_EQ(sizeof(next_state.cdi_attest), sizeof(dice::test::kExpectedCdiAttest_ZeroInput)); @@ -94,12 +96,12 @@ sizeof(dice::test::kExpectedCdiSeal_ZeroInput)); EXPECT_EQ(0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_ZeroInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborP256Cert_ZeroInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborP256Cert_AndroidZeroInput), next_state.certificate_size); // Comparing everything except for the signature, since ECDSA signatures are // not deterministic constexpr size_t signature_size = 64; - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP256Cert_ZeroInput, + EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP256Cert_AndroidZeroInput, next_state.certificate, next_state.certificate_size - signature_size)); } @@ -115,7 +117,8 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_P384, "zero_input", next_state); + DumpState(CertificateType_Cbor, KeyType_P384, "android_zero_input", + next_state); // The CDI values should be deterministic. ASSERT_EQ(sizeof(next_state.cdi_attest), sizeof(dice::test::kExpectedCdiAttest_ZeroInput)); @@ -125,12 +128,12 @@ sizeof(dice::test::kExpectedCdiSeal_ZeroInput)); EXPECT_EQ(0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_ZeroInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborP384Cert_ZeroInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborP384Cert_AndroidZeroInput), next_state.certificate_size); // Comparing everything except for the signature, since ECDSA signatures are // not deterministic constexpr size_t signature_size = 96; - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP384Cert_ZeroInput, + EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP384Cert_AndroidZeroInput, next_state.certificate, next_state.certificate_size - signature_size)); } @@ -155,7 +158,7 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_Ed25519, "hash_only_input", + DumpState(CertificateType_Cbor, KeyType_Ed25519, "android_hash_only_input", next_state); ASSERT_EQ(sizeof(next_state.cdi_attest), sizeof(dice::test::kExpectedCdiAttest_HashOnlyInput)); @@ -167,9 +170,9 @@ EXPECT_EQ( 0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_HashOnlyInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_HashOnlyInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_AndroidHashOnlyInput), next_state.certificate_size); - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborEd25519Cert_HashOnlyInput, + EXPECT_EQ(0, memcmp(dice::test::kExpectedCborEd25519Cert_AndroidHashOnlyInput, next_state.certificate, next_state.certificate_size)); } @@ -193,7 +196,8 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_P256, "hash_only_input", next_state); + DumpState(CertificateType_Cbor, KeyType_P256, "android_hash_only_input", + next_state); ASSERT_EQ(sizeof(next_state.cdi_attest), sizeof(dice::test::kExpectedCdiAttest_HashOnlyInput)); EXPECT_EQ( @@ -204,10 +208,10 @@ EXPECT_EQ( 0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_HashOnlyInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborP256Cert_HashOnlyInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborP256Cert_AndroidHashOnlyInput), next_state.certificate_size); constexpr size_t signature_size = 64; - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP256Cert_HashOnlyInput, + EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP256Cert_AndroidHashOnlyInput, next_state.certificate, next_state.certificate_size - signature_size)); } @@ -232,7 +236,8 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_P384, "hash_only_input", next_state); + DumpState(CertificateType_Cbor, KeyType_P384, "android_hash_only_input", + next_state); ASSERT_EQ(sizeof(next_state.cdi_attest), sizeof(dice::test::kExpectedCdiAttest_HashOnlyInput)); EXPECT_EQ( @@ -243,10 +248,10 @@ EXPECT_EQ( 0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_HashOnlyInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborP384Cert_HashOnlyInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborP384Cert_AndroidHashOnlyInput), next_state.certificate_size); constexpr size_t signature_size = 96; - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP384Cert_HashOnlyInput, + EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP384Cert_AndroidHashOnlyInput, next_state.certificate, next_state.certificate_size - signature_size)); } @@ -287,7 +292,7 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_Ed25519, "descriptor_input", + DumpState(CertificateType_Cbor, KeyType_Ed25519, "android_descriptor_input", next_state); // Both CDI values and the certificate should be deterministic. EXPECT_EQ( @@ -296,10 +301,11 @@ EXPECT_EQ( 0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_DescriptorInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_DescriptorInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborEd25519Cert_AndroidDescriptorInput), next_state.certificate_size); - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborEd25519Cert_DescriptorInput, - next_state.certificate, next_state.certificate_size)); + EXPECT_EQ(0, + memcmp(dice::test::kExpectedCborEd25519Cert_AndroidDescriptorInput, + next_state.certificate, next_state.certificate_size)); } TEST(DiceOpsTest, P256KnownAnswerDescriptorInput) { @@ -338,7 +344,8 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_P256, "descriptor_input", next_state); + DumpState(CertificateType_Cbor, KeyType_P256, "android_descriptor_input", + next_state); // Both CDI values and the certificate should be deterministic. EXPECT_EQ( 0, memcmp(next_state.cdi_attest, @@ -346,10 +353,10 @@ EXPECT_EQ( 0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_DescriptorInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborP256Cert_DescriptorInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborP256Cert_AndroidDescriptorInput), next_state.certificate_size); constexpr size_t signature_size = 64; - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP256Cert_DescriptorInput, + EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP256Cert_AndroidDescriptorInput, next_state.certificate, next_state.certificate_size - signature_size)); } @@ -390,7 +397,8 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); - DumpState(CertificateType_Cbor, KeyType_P384, "descriptor_input", next_state); + DumpState(CertificateType_Cbor, KeyType_P384, "android_descriptor_input", + next_state); // Both CDI values and the certificate should be deterministic. EXPECT_EQ( 0, memcmp(next_state.cdi_attest, @@ -398,10 +406,10 @@ EXPECT_EQ( 0, memcmp(next_state.cdi_seal, dice::test::kExpectedCdiSeal_DescriptorInput, DICE_CDI_SIZE)); - ASSERT_EQ(sizeof(dice::test::kExpectedCborP384Cert_DescriptorInput), + ASSERT_EQ(sizeof(dice::test::kExpectedCborP384Cert_AndroidDescriptorInput), next_state.certificate_size); constexpr size_t signature_size = 96; - EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP384Cert_DescriptorInput, + EXPECT_EQ(0, memcmp(dice::test::kExpectedCborP384Cert_AndroidDescriptorInput, next_state.certificate, next_state.certificate_size - signature_size)); }
diff --git a/src/template_cbor_cert_op.c b/src/template_cbor_cert_op.c index 3492505..cd1ea76 100644 --- a/src/template_cbor_cert_op.c +++ b/src/template_cbor_cert_op.c
@@ -40,6 +40,7 @@ #include "dice/dice.h" #include "dice/ops.h" +#include "dice/profile_name.h" #include "dice/utils.h" #if DICE_PUBLIC_KEY_BUFFER_SIZE != 32 @@ -173,7 +174,7 @@ // Variable length descriptors are not supported. if (input_values->code_descriptor_size > 0 || input_values->config_type != kDiceConfigTypeInline || - input_values->authority_descriptor_size > 0 || key_param.profile_name) { + input_values->authority_descriptor_size > 0 || DICE_PROFILE_NAME) { return kDiceResultInvalidInput; }
diff --git a/src/template_cbor_cert_op_test.cc b/src/template_cbor_cert_op_test.cc index c2d0700..37dcb86 100644 --- a/src/template_cbor_cert_op_test.cc +++ b/src/template_cbor_cert_op_test.cc
@@ -41,6 +41,7 @@ sizeof(next_state.certificate), next_state.certificate, &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); + DumpState(CertificateType_Cbor, KeyType_Ed25519, "zero_input", next_state); // Both CDI values and the certificate should be deterministic. EXPECT_EQ(0, memcmp(next_state.cdi_attest, dice::test::kExpectedCdiAttest_ZeroInput, DICE_CDI_SIZE)); @@ -71,6 +72,8 @@ &next_state.certificate_size, next_state.cdi_attest, next_state.cdi_seal); EXPECT_EQ(kDiceResultOk, result); // Both CDI values and the certificate should be deterministic. + DumpState(CertificateType_Cbor, KeyType_Ed25519, "hash_only_input", + next_state); EXPECT_EQ( 0, memcmp(next_state.cdi_attest, dice::test::kExpectedCdiAttest_HashOnlyInput, DICE_CDI_SIZE));
diff --git a/src/template_cert_op.c b/src/template_cert_op.c index cc9f553..19dd7d1 100644 --- a/src/template_cert_op.c +++ b/src/template_cert_op.c
@@ -35,6 +35,7 @@ #include "dice/dice.h" #include "dice/ops.h" +#include "dice/profile_name.h" #include "dice/utils.h" #include "openssl/curve25519.h" #include "openssl/is_boringssl.h" @@ -183,7 +184,7 @@ // Variable length descriptors are not supported. if (input_values->code_descriptor_size > 0 || input_values->config_type != kDiceConfigTypeInline || - input_values->authority_descriptor_size > 0 || key_param.profile_name) { + input_values->authority_descriptor_size > 0 || DICE_PROFILE_NAME) { return kDiceResultInvalidInput; }