blob: 688009d1ec98936139a07a00252fbbb0b33b0846 [file] [log] [blame]
Paul Bakker33b43f12013-08-20 11:48:36 +02001/* BEGIN_HEADER */
Manuel Pégourié-Gonnard7f809972015-03-09 17:05:11 +00002#include "mbedtls/x509_crt.h"
3#include "mbedtls/x509_crl.h"
4#include "mbedtls/x509_csr.h"
5#include "mbedtls/pem.h"
6#include "mbedtls/oid.h"
7#include "mbedtls/base64.h"
Paul Bakkerb63b0af2011-01-13 17:54:59 +00008
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +02009int verify_none( void *data, mbedtls_x509_crt *crt, int certificate_depth, uint32_t *flags )
Paul Bakkerb63b0af2011-01-13 17:54:59 +000010{
Paul Bakker5a624082011-01-18 16:31:52 +000011 ((void) data);
12 ((void) crt);
13 ((void) certificate_depth);
Manuel Pégourié-Gonnarde6028c92015-04-20 12:19:02 +010014 *flags |= MBEDTLS_X509_BADCERT_OTHER;
Paul Bakkerddf26b42013-09-18 13:46:23 +020015
Paul Bakker915275b2012-09-28 07:10:55 +000016 return 0;
Paul Bakkerb63b0af2011-01-13 17:54:59 +000017}
18
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +020019int verify_all( void *data, mbedtls_x509_crt *crt, int certificate_depth, uint32_t *flags )
Paul Bakkerb63b0af2011-01-13 17:54:59 +000020{
Paul Bakker5a624082011-01-18 16:31:52 +000021 ((void) data);
22 ((void) crt);
23 ((void) certificate_depth);
Paul Bakker915275b2012-09-28 07:10:55 +000024 *flags = 0;
Paul Bakker5a624082011-01-18 16:31:52 +000025
Paul Bakkerb63b0af2011-01-13 17:54:59 +000026 return 0;
27}
28
Manuel Pégourié-Gonnard560fea32015-09-01 11:59:24 +020029#if defined(MBEDTLS_X509_CRT_PARSE_C)
30typedef struct {
31 char buf[512];
32 char *p;
33} verify_print_context;
34
35void verify_print_init( verify_print_context *ctx )
36{
37 memset( ctx, 0, sizeof( verify_print_context ) );
38 ctx->p = ctx->buf;
39}
40
41int verify_print( void *data, mbedtls_x509_crt *crt, int certificate_depth, uint32_t *flags )
42{
43 int ret;
44 verify_print_context *ctx = (verify_print_context *) data;
45 char *p = ctx->p;
46 size_t n = ctx->buf + sizeof( ctx->buf ) - ctx->p;
47 ((void) flags);
48
49 ret = mbedtls_snprintf( p, n, "depth %d - serial ", certificate_depth );
50 MBEDTLS_X509_SAFE_SNPRINTF;
51
52 ret = mbedtls_x509_serial_gets( p, n, &crt->serial );
53 MBEDTLS_X509_SAFE_SNPRINTF;
54
55 ret = mbedtls_snprintf( p, n, " - subject " );
56 MBEDTLS_X509_SAFE_SNPRINTF;
57
58 ret = mbedtls_x509_dn_gets( p, n, &crt->subject );
59 MBEDTLS_X509_SAFE_SNPRINTF;
60
61 ret = mbedtls_snprintf( p, n, "\n" );
62 MBEDTLS_X509_SAFE_SNPRINTF;
63
64 ctx->p = p;
65
66 return( 0 );
67}
68#endif /* MBEDTLS_X509_CRT_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +020069/* END_HEADER */
Paul Bakker37940d9f2009-07-10 22:38:58 +000070
Paul Bakker33b43f12013-08-20 11:48:36 +020071/* BEGIN_DEPENDENCIES
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020072 * depends_on:MBEDTLS_BIGNUM_C
Paul Bakker33b43f12013-08-20 11:48:36 +020073 * END_DEPENDENCIES
74 */
Paul Bakker5690efc2011-05-26 13:16:06 +000075
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020076/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +020077void x509_cert_info( char *crt_file, char *result_str )
Paul Bakker37940d9f2009-07-10 22:38:58 +000078{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020079 mbedtls_x509_crt crt;
Paul Bakker37940d9f2009-07-10 22:38:58 +000080 char buf[2000];
Paul Bakker69998dd2009-07-11 19:15:20 +000081 int res;
Paul Bakker37940d9f2009-07-10 22:38:58 +000082
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020083 mbedtls_x509_crt_init( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +000084 memset( buf, 0, 2000 );
85
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020086 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
87 res = mbedtls_x509_crt_info( buf, 2000, "", &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +000088
89 TEST_ASSERT( res != -1 );
90 TEST_ASSERT( res != -2 );
91
Paul Bakker33b43f12013-08-20 11:48:36 +020092 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +020093
94exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020095 mbedtls_x509_crt_free( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +000096}
Paul Bakker33b43f12013-08-20 11:48:36 +020097/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +000098
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020099/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRL_PARSE_C */
100void mbedtls_x509_crl_info( char *crl_file, char *result_str )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000101{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200102 mbedtls_x509_crl crl;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000103 char buf[2000];
Paul Bakker69998dd2009-07-11 19:15:20 +0000104 int res;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000105
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200106 mbedtls_x509_crl_init( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000107 memset( buf, 0, 2000 );
108
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200109 TEST_ASSERT( mbedtls_x509_crl_parse_file( &crl, crl_file ) == 0 );
110 res = mbedtls_x509_crl_info( buf, 2000, "", &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000111
112 TEST_ASSERT( res != -1 );
113 TEST_ASSERT( res != -2 );
114
Paul Bakker33b43f12013-08-20 11:48:36 +0200115 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200116
117exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200118 mbedtls_x509_crl_free( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000119}
Paul Bakker33b43f12013-08-20 11:48:36 +0200120/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000121
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200122/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CSR_PARSE_C */
123void mbedtls_x509_csr_info( char *csr_file, char *result_str )
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100124{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200125 mbedtls_x509_csr csr;
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100126 char buf[2000];
127 int res;
128
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200129 mbedtls_x509_csr_init( &csr );
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100130 memset( buf, 0, 2000 );
131
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200132 TEST_ASSERT( mbedtls_x509_csr_parse_file( &csr, csr_file ) == 0 );
133 res = mbedtls_x509_csr_info( buf, 2000, "", &csr );
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100134
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100135 TEST_ASSERT( res != -1 );
136 TEST_ASSERT( res != -2 );
137
138 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200139
140exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200141 mbedtls_x509_csr_free( &csr );
Manuel Pégourié-Gonnard2a8d7fd2014-01-24 17:34:26 +0100142}
143/* END_CASE */
144
Manuel Pégourié-Gonnardb5f48ad2015-04-20 10:38:13 +0100145/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C */
146void x509_verify_info( int flags, char *prefix, char *result_str )
147{
148 char buf[2000];
149 int res;
150
151 memset( buf, 0, sizeof( buf ) );
152
153 res = mbedtls_x509_crt_verify_info( buf, sizeof( buf ), prefix, flags );
154
155 TEST_ASSERT( res >= 0 );
156
157 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
158}
159/* END_CASE */
160
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200161/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_CRL_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +0200162void x509_verify( char *crt_file, char *ca_file, char *crl_file,
163 char *cn_name_str, int result, int flags_result,
164 char *verify_callback )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000165{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200166 mbedtls_x509_crt crt;
167 mbedtls_x509_crt ca;
168 mbedtls_x509_crl crl;
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +0200169 uint32_t flags = 0;
Paul Bakker69998dd2009-07-11 19:15:20 +0000170 int res;
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +0200171 int (*f_vrfy)(void *, mbedtls_x509_crt *, int, uint32_t *) = NULL;
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200172 char * cn_name = NULL;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000173
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200174 mbedtls_x509_crt_init( &crt );
175 mbedtls_x509_crt_init( &ca );
176 mbedtls_x509_crl_init( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000177
Paul Bakker33b43f12013-08-20 11:48:36 +0200178 if( strcmp( cn_name_str, "NULL" ) != 0 )
179 cn_name = cn_name_str;
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200180
Paul Bakker33b43f12013-08-20 11:48:36 +0200181 if( strcmp( verify_callback, "NULL" ) == 0 )
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200182 f_vrfy = NULL;
Paul Bakker33b43f12013-08-20 11:48:36 +0200183 else if( strcmp( verify_callback, "verify_none" ) == 0 )
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200184 f_vrfy = verify_none;
Paul Bakker33b43f12013-08-20 11:48:36 +0200185 else if( strcmp( verify_callback, "verify_all" ) == 0 )
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200186 f_vrfy = verify_all;
187 else
188 TEST_ASSERT( "No known verify callback selected" == 0 );
189
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200190 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
191 TEST_ASSERT( mbedtls_x509_crt_parse_file( &ca, ca_file ) == 0 );
192 TEST_ASSERT( mbedtls_x509_crl_parse_file( &crl, crl_file ) == 0 );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000193
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200194 res = mbedtls_x509_crt_verify( &crt, &ca, &crl, cn_name, &flags, f_vrfy, NULL );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000195
Paul Bakkerbd51b262014-07-10 15:26:12 +0200196 TEST_ASSERT( res == ( result ) );
Manuel Pégourié-Gonnarde6ef16f2015-05-11 19:54:43 +0200197 TEST_ASSERT( flags == (uint32_t)( flags_result ) );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200198
199exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200200 mbedtls_x509_crt_free( &crt );
201 mbedtls_x509_crt_free( &ca );
202 mbedtls_x509_crl_free( &crl );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000203}
Paul Bakker33b43f12013-08-20 11:48:36 +0200204/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000205
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200206/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnard560fea32015-09-01 11:59:24 +0200207void x509_verify_callback( char *crt_file, char *ca_file,
208 int exp_ret, char *exp_vrfy_out )
209{
210 int ret;
211 mbedtls_x509_crt crt;
212 mbedtls_x509_crt ca;
213 uint32_t flags = 0;
214 verify_print_context vrfy_ctx;
215
216 mbedtls_x509_crt_init( &crt );
217 mbedtls_x509_crt_init( &ca );
218 verify_print_init( &vrfy_ctx );
219
220 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
221 TEST_ASSERT( mbedtls_x509_crt_parse_file( &ca, ca_file ) == 0 );
222
223 ret = mbedtls_x509_crt_verify( &crt, &ca, NULL, NULL, &flags,
224 verify_print, &vrfy_ctx );
225
226 TEST_ASSERT( ret == exp_ret );
227 TEST_ASSERT( strcmp( vrfy_ctx.buf, exp_vrfy_out ) == 0 );
228
229exit:
230 mbedtls_x509_crt_free( &crt );
231 mbedtls_x509_crt_free( &ca );
232}
233/* END_CASE */
234
235/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200236void mbedtls_x509_dn_gets( char *crt_file, char *entity, char *result_str )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000237{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200238 mbedtls_x509_crt crt;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000239 char buf[2000];
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200240 int res = 0;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000241
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200242 mbedtls_x509_crt_init( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000243 memset( buf, 0, 2000 );
244
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200245 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Paul Bakker33b43f12013-08-20 11:48:36 +0200246 if( strcmp( entity, "subject" ) == 0 )
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200247 res = mbedtls_x509_dn_gets( buf, 2000, &crt.subject );
Paul Bakker33b43f12013-08-20 11:48:36 +0200248 else if( strcmp( entity, "issuer" ) == 0 )
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200249 res = mbedtls_x509_dn_gets( buf, 2000, &crt.issuer );
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200250 else
251 TEST_ASSERT( "Unknown entity" == 0 );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000252
253 TEST_ASSERT( res != -1 );
254 TEST_ASSERT( res != -2 );
255
Paul Bakker33b43f12013-08-20 11:48:36 +0200256 TEST_ASSERT( strcmp( buf, result_str ) == 0 );
Paul Bakkerbd51b262014-07-10 15:26:12 +0200257
258exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200259 mbedtls_x509_crt_free( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000260}
Paul Bakker33b43f12013-08-20 11:48:36 +0200261/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000262
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200263/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100264void mbedtls_x509_time_is_past( char *crt_file, char *entity, int result )
Paul Bakker37940d9f2009-07-10 22:38:58 +0000265{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200266 mbedtls_x509_crt crt;
Paul Bakker37940d9f2009-07-10 22:38:58 +0000267
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200268 mbedtls_x509_crt_init( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000269
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200270 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200271
Paul Bakker33b43f12013-08-20 11:48:36 +0200272 if( strcmp( entity, "valid_from" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100273 TEST_ASSERT( mbedtls_x509_time_is_past( &crt.valid_from ) == result );
Paul Bakker33b43f12013-08-20 11:48:36 +0200274 else if( strcmp( entity, "valid_to" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100275 TEST_ASSERT( mbedtls_x509_time_is_past( &crt.valid_to ) == result );
Paul Bakkerdbd443d2013-08-16 13:38:47 +0200276 else
277 TEST_ASSERT( "Unknown entity" == 0 );
Paul Bakkerb08e6842012-02-11 18:43:20 +0000278
Paul Bakkerbd51b262014-07-10 15:26:12 +0200279exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200280 mbedtls_x509_crt_free( &crt );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000281}
Paul Bakker33b43f12013-08-20 11:48:36 +0200282/* END_CASE */
Paul Bakker37940d9f2009-07-10 22:38:58 +0000283
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200284/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100285void mbedtls_x509_time_is_future( char *crt_file, char *entity, int result )
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100286{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200287 mbedtls_x509_crt crt;
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100288
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200289 mbedtls_x509_crt_init( &crt );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100290
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200291 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100292
293 if( strcmp( entity, "valid_from" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100294 TEST_ASSERT( mbedtls_x509_time_is_future( &crt.valid_from ) == result );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100295 else if( strcmp( entity, "valid_to" ) == 0 )
Manuel Pégourié-Gonnardc730ed32015-06-02 10:38:50 +0100296 TEST_ASSERT( mbedtls_x509_time_is_future( &crt.valid_to ) == result );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100297 else
298 TEST_ASSERT( "Unknown entity" == 0 );
299
Paul Bakkerbd51b262014-07-10 15:26:12 +0200300exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200301 mbedtls_x509_crt_free( &crt );
Manuel Pégourié-Gonnard6304f782014-03-10 12:26:11 +0100302}
303/* END_CASE */
304
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200305/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_FS_IO */
Paul Bakker5a5fa922014-09-26 14:53:04 +0200306void x509parse_crt_file( char *crt_file, int result )
307{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200308 mbedtls_x509_crt crt;
Paul Bakker5a5fa922014-09-26 14:53:04 +0200309
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200310 mbedtls_x509_crt_init( &crt );
Paul Bakker5a5fa922014-09-26 14:53:04 +0200311
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200312 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == result );
Paul Bakker5a5fa922014-09-26 14:53:04 +0200313
314exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200315 mbedtls_x509_crt_free( &crt );
Paul Bakker5a5fa922014-09-26 14:53:04 +0200316}
317/* END_CASE */
318
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200319/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +0200320void x509parse_crt( char *crt_data, char *result_str, int result )
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000321{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200322 mbedtls_x509_crt crt;
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000323 unsigned char buf[2000];
324 unsigned char output[2000];
325 int data_len, res;
326
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200327 mbedtls_x509_crt_init( &crt );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000328 memset( buf, 0, 2000 );
329 memset( output, 0, 2000 );
330
Paul Bakker33b43f12013-08-20 11:48:36 +0200331 data_len = unhexify( buf, crt_data );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000332
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200333 TEST_ASSERT( mbedtls_x509_crt_parse( &crt, buf, data_len ) == ( result ) );
Paul Bakker33b43f12013-08-20 11:48:36 +0200334 if( ( result ) == 0 )
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000335 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200336 res = mbedtls_x509_crt_info( (char *) output, 2000, "", &crt );
Paul Bakker33b43f12013-08-20 11:48:36 +0200337
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000338 TEST_ASSERT( res != -1 );
339 TEST_ASSERT( res != -2 );
340
Paul Bakker33b43f12013-08-20 11:48:36 +0200341 TEST_ASSERT( strcmp( (char *) output, result_str ) == 0 );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000342 }
Paul Bakkerb08e6842012-02-11 18:43:20 +0000343
Paul Bakkerbd51b262014-07-10 15:26:12 +0200344exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200345 mbedtls_x509_crt_free( &crt );
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000346}
Paul Bakker33b43f12013-08-20 11:48:36 +0200347/* END_CASE */
Paul Bakkerb2c38f52009-07-19 19:36:15 +0000348
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200349/* BEGIN_CASE depends_on:MBEDTLS_X509_CRL_PARSE_C */
Paul Bakker33b43f12013-08-20 11:48:36 +0200350void x509parse_crl( char *crl_data, char *result_str, int result )
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000351{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200352 mbedtls_x509_crl crl;
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000353 unsigned char buf[2000];
354 unsigned char output[2000];
355 int data_len, res;
356
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200357 mbedtls_x509_crl_init( &crl );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000358 memset( buf, 0, 2000 );
359 memset( output, 0, 2000 );
360
Paul Bakker33b43f12013-08-20 11:48:36 +0200361 data_len = unhexify( buf, crl_data );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000362
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200363 TEST_ASSERT( mbedtls_x509_crl_parse( &crl, buf, data_len ) == ( result ) );
Paul Bakker33b43f12013-08-20 11:48:36 +0200364 if( ( result ) == 0 )
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000365 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200366 res = mbedtls_x509_crl_info( (char *) output, 2000, "", &crl );
Paul Bakker33b43f12013-08-20 11:48:36 +0200367
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000368 TEST_ASSERT( res != -1 );
369 TEST_ASSERT( res != -2 );
370
Paul Bakker33b43f12013-08-20 11:48:36 +0200371 TEST_ASSERT( strcmp( (char *) output, result_str ) == 0 );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000372 }
Paul Bakkerb08e6842012-02-11 18:43:20 +0000373
Paul Bakkerbd51b262014-07-10 15:26:12 +0200374exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200375 mbedtls_x509_crl_free( &crl );
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000376}
Paul Bakker33b43f12013-08-20 11:48:36 +0200377/* END_CASE */
Paul Bakker6b0fa4f2009-07-20 20:35:41 +0000378
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200379/* BEGIN_CASE depends_on:MBEDTLS_X509_CSR_PARSE_C */
380void mbedtls_x509_csr_parse( char *csr_der_hex, char *ref_out, int ref_ret )
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200381{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200382 mbedtls_x509_csr csr;
Paul Bakkerbd51b262014-07-10 15:26:12 +0200383 unsigned char *csr_der = NULL;
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200384 char my_out[1000];
385 size_t csr_der_len;
386 int my_ret;
387
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200388 mbedtls_x509_csr_init( &csr );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200389 memset( my_out, 0, sizeof( my_out ) );
390 csr_der = unhexify_alloc( csr_der_hex, &csr_der_len );
391
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200392 my_ret = mbedtls_x509_csr_parse_der( &csr, csr_der, csr_der_len );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200393 TEST_ASSERT( my_ret == ref_ret );
394
395 if( ref_ret == 0 )
396 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200397 size_t my_out_len = mbedtls_x509_csr_info( my_out, sizeof( my_out ), "", &csr );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200398 TEST_ASSERT( my_out_len == strlen( ref_out ) );
399 TEST_ASSERT( strcmp( my_out, ref_out ) == 0 );
400 }
401
Paul Bakkerbd51b262014-07-10 15:26:12 +0200402exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200403 mbedtls_x509_csr_free( &csr );
404 mbedtls_free( csr_der );
Manuel Pégourié-Gonnardd77cd5d2014-06-13 11:13:15 +0200405}
406/* END_CASE */
407
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200408/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
409void mbedtls_x509_crt_parse_path( char *crt_path, int ret, int nb_crt )
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100410{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200411 mbedtls_x509_crt chain, *cur;
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100412 int i;
413
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200414 mbedtls_x509_crt_init( &chain );
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100415
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200416 TEST_ASSERT( mbedtls_x509_crt_parse_path( &chain, crt_path ) == ret );
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100417
418 /* Check how many certs we got */
419 for( i = 0, cur = &chain; cur != NULL; cur = cur->next )
420 if( cur->raw.p != NULL )
421 i++;
422
423 TEST_ASSERT( i == nb_crt );
424
Paul Bakkerbd51b262014-07-10 15:26:12 +0200425exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200426 mbedtls_x509_crt_free( &chain );
Manuel Pégourié-Gonnardfbae2a12013-11-26 16:43:39 +0100427}
428/* END_CASE */
429
Janos Follath822b2c32015-10-11 10:25:22 +0200430/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C */
Janos Follathef4f2582015-10-11 16:17:27 +0200431void mbedtls_x509_crt_verify_chain( char *chain_paths, char *trusted_ca, int flags_result )
Janos Follath822b2c32015-10-11 10:25:22 +0200432{
433 char* act;
434 uint32_t flags;
Janos Follathef4f2582015-10-11 16:17:27 +0200435 int result, res;
Manuel Pégourié-Gonnarde670f902015-10-30 09:23:19 +0100436 mbedtls_x509_crt trusted, chain;
Janos Follath822b2c32015-10-11 10:25:22 +0200437
Janos Follathef4f2582015-10-11 16:17:27 +0200438 result= flags_result?MBEDTLS_ERR_X509_CERT_VERIFY_FAILED:0;
439
Janos Follath822b2c32015-10-11 10:25:22 +0200440 mbedtls_x509_crt_init( &chain );
441 mbedtls_x509_crt_init( &trusted );
442
Manuel Pégourié-Gonnarde670f902015-10-30 09:23:19 +0100443 while( (act = strsep( &chain_paths, " " )) )
444 TEST_ASSERT( mbedtls_x509_crt_parse_file( &chain, act ) == 0 );
445 TEST_ASSERT( mbedtls_x509_crt_parse_file( &trusted, trusted_ca ) == 0 );
Janos Follath822b2c32015-10-11 10:25:22 +0200446
447 res = mbedtls_x509_crt_verify( &chain, &trusted, NULL, NULL, &flags, NULL, NULL );
Janos Follathef4f2582015-10-11 16:17:27 +0200448
449 TEST_ASSERT( res == ( result ) );
450 TEST_ASSERT( flags == (uint32_t)( flags_result ) );
Janos Follath822b2c32015-10-11 10:25:22 +0200451
452exit:
453 mbedtls_x509_crt_free( &trusted );
454 mbedtls_x509_crt_free( &chain );
455}
456/* END_CASE */
457
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200458/* BEGIN_CASE depends_on:MBEDTLS_X509_USE_C */
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100459void x509_oid_desc( char *oid_str, char *ref_desc )
460{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200461 mbedtls_x509_buf oid;
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000462 const char *desc = NULL;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100463 unsigned char buf[20];
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000464 int ret;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100465
466 memset( buf, 0, sizeof buf );
467
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200468 oid.tag = MBEDTLS_ASN1_OID;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100469 oid.len = unhexify( buf, oid_str );
470 oid.p = buf;
471
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200472 ret = mbedtls_oid_get_extended_key_usage( &oid, &desc );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100473
474 if( strcmp( ref_desc, "notfound" ) == 0 )
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000475 {
476 TEST_ASSERT( ret != 0 );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100477 TEST_ASSERT( desc == NULL );
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000478 }
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100479 else
480 {
Manuel Pégourié-Gonnard48d3cef2015-03-20 18:14:26 +0000481 TEST_ASSERT( ret == 0 );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100482 TEST_ASSERT( desc != NULL );
483 TEST_ASSERT( strcmp( desc, ref_desc ) == 0 );
484 }
485}
486/* END_CASE */
487
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200488/* BEGIN_CASE depends_on:MBEDTLS_X509_USE_C */
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100489void x509_oid_numstr( char *oid_str, char *numstr, int blen, int ret )
490{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200491 mbedtls_x509_buf oid;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100492 unsigned char oid_buf[20];
493 char num_buf[100];
494
495 memset( oid_buf, 0x00, sizeof oid_buf );
496 memset( num_buf, 0x2a, sizeof num_buf );
497
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200498 oid.tag = MBEDTLS_ASN1_OID;
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100499 oid.len = unhexify( oid_buf, oid_str );
500 oid.p = oid_buf;
501
502 TEST_ASSERT( (size_t) blen <= sizeof num_buf );
503
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200504 TEST_ASSERT( mbedtls_oid_get_numeric_string( num_buf, blen, &oid ) == ret );
Manuel Pégourié-Gonnard7afdb882014-03-28 16:06:35 +0100505
506 if( ret >= 0 )
507 {
508 TEST_ASSERT( num_buf[ret] == 0 );
509 TEST_ASSERT( strcmp( num_buf, numstr ) == 0 );
510 }
511}
512/* END_CASE */
513
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200514/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_CHECK_KEY_USAGE */
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200515void x509_check_key_usage( char *crt_file, int usage, int ret )
516{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200517 mbedtls_x509_crt crt;
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200518
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200519 mbedtls_x509_crt_init( &crt );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200520
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200521 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200522
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200523 TEST_ASSERT( mbedtls_x509_crt_check_key_usage( &crt, usage ) == ret );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200524
Paul Bakkerbd51b262014-07-10 15:26:12 +0200525exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200526 mbedtls_x509_crt_free( &crt );
Manuel Pégourié-Gonnard603116c2014-04-09 09:50:03 +0200527}
528/* END_CASE */
529
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200530/* BEGIN_CASE depends_on:MBEDTLS_FS_IO:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_CHECK_EXTENDED_KEY_USAGE */
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200531void x509_check_extended_key_usage( char *crt_file, char *usage_hex, int ret )
532{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200533 mbedtls_x509_crt crt;
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200534 char oid[50];
535 size_t len;
536
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200537 mbedtls_x509_crt_init( &crt );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200538
539 len = unhexify( (unsigned char *) oid, usage_hex );
540
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200541 TEST_ASSERT( mbedtls_x509_crt_parse_file( &crt, crt_file ) == 0 );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200542
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200543 TEST_ASSERT( mbedtls_x509_crt_check_extended_key_usage( &crt, oid, len ) == ret );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200544
Paul Bakkerbd51b262014-07-10 15:26:12 +0200545exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200546 mbedtls_x509_crt_free( &crt );
Manuel Pégourié-Gonnard7afb8a02014-04-10 17:53:56 +0200547}
548/* END_CASE */
549
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200550/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_X509_RSASSA_PSS_SUPPORT */
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200551void x509_parse_rsassa_pss_params( char *hex_params, int params_tag,
552 int ref_msg_md, int ref_mgf_md,
553 int ref_salt_len, int ref_ret )
554{
555 int my_ret;
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200556 mbedtls_x509_buf params;
557 mbedtls_md_type_t my_msg_md, my_mgf_md;
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200558 int my_salt_len;
559
560 params.p = unhexify_alloc( hex_params, &params.len );
561 params.tag = params_tag;
562
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200563 my_ret = mbedtls_x509_get_rsassa_pss_params( &params, &my_msg_md, &my_mgf_md,
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200564 &my_salt_len );
565
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200566 TEST_ASSERT( my_ret == ref_ret );
567
568 if( ref_ret == 0 )
569 {
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200570 TEST_ASSERT( my_msg_md == (mbedtls_md_type_t) ref_msg_md );
571 TEST_ASSERT( my_mgf_md == (mbedtls_md_type_t) ref_mgf_md );
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200572 TEST_ASSERT( my_salt_len == ref_salt_len );
573 }
574
Paul Bakkerbd51b262014-07-10 15:26:12 +0200575exit:
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200576 mbedtls_free( params.p );
Manuel Pégourié-Gonnard85403692014-06-06 14:48:38 +0200577}
578/* END_CASE */
579
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200580/* BEGIN_CASE depends_on:MBEDTLS_X509_CRT_PARSE_C:MBEDTLS_SELF_TEST */
Paul Bakker33b43f12013-08-20 11:48:36 +0200581void x509_selftest()
Paul Bakker37940d9f2009-07-10 22:38:58 +0000582{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200583 TEST_ASSERT( mbedtls_x509_self_test( 0 ) == 0 );
Paul Bakker37940d9f2009-07-10 22:38:58 +0000584}
Paul Bakker33b43f12013-08-20 11:48:36 +0200585/* END_CASE */