]>
Commit | Line | Data |
---|---|---|
3dbc5156 | 1 | /* |
33388b44 | 2 | * Copyright 2007-2020 The OpenSSL Project Authors. All Rights Reserved. |
3dbc5156 DDO |
3 | * Copyright Nokia 2007-2019 |
4 | * Copyright Siemens AG 2015-2019 | |
5 | * | |
6 | * Licensed under the Apache License 2.0 (the "License"). You may not use | |
7 | * this file except in compliance with the License. You can obtain a copy | |
8 | * in the file LICENSE in the source distribution or at | |
9 | * https://www.openssl.org/source/license.html | |
10 | */ | |
11 | ||
12 | #include "cmp_testlib.h" | |
13 | ||
852c2ed2 RS |
14 | DEFINE_STACK_OF(OSSL_CMP_CERTRESPONSE) |
15 | ||
5a7734cd | 16 | static const char *newkey_f; |
3dbc5156 DDO |
17 | static const char *server_cert_f; |
18 | static const char *pkcs10_f; | |
19 | ||
20 | typedef struct test_fixture { | |
21 | const char *test_case_name; | |
22 | OSSL_CMP_CTX *cmp_ctx; | |
23 | /* for msg create tests */ | |
24 | int bodytype; | |
25 | int err_code; | |
26 | /* for certConf */ | |
27 | int fail_info; | |
28 | /* for protection tests */ | |
29 | OSSL_CMP_MSG *msg; | |
30 | int expected; | |
31 | /* for error and response messages */ | |
32 | OSSL_CMP_PKISI *si; | |
33 | } CMP_MSG_TEST_FIXTURE; | |
34 | ||
5a7734cd DDO |
35 | static OPENSSL_CTX *libctx = NULL; |
36 | static OSSL_PROVIDER *default_null_provider = NULL, *provider = NULL; | |
37 | ||
38 | /* TODO(3.0) Clean this up - See issue #12680 */ | |
39 | static X509 *X509_dup_with_libctx(const X509 *cert) | |
40 | { | |
41 | X509 *dup = X509_dup(cert); | |
42 | ||
43 | if (dup != NULL) | |
44 | x509_set0_libctx(dup, libctx, NULL); | |
45 | return dup; | |
46 | } | |
47 | ||
3dbc5156 DDO |
48 | static unsigned char ref[CMP_TEST_REFVALUE_LENGTH]; |
49 | ||
50 | static void tear_down(CMP_MSG_TEST_FIXTURE *fixture) | |
51 | { | |
52 | OSSL_CMP_CTX_free(fixture->cmp_ctx); | |
53 | OSSL_CMP_MSG_free(fixture->msg); | |
54 | OSSL_CMP_PKISI_free(fixture->si); | |
55 | OPENSSL_free(fixture); | |
56 | } | |
57 | ||
58 | #define SET_OPT_UNPROTECTED_SEND(ctx, val) \ | |
59 | OSSL_CMP_CTX_set_option((ctx), OSSL_CMP_OPT_UNPROTECTED_SEND, (val)) | |
60 | static CMP_MSG_TEST_FIXTURE *set_up(const char *const test_case_name) | |
61 | { | |
62 | CMP_MSG_TEST_FIXTURE *fixture; | |
63 | ||
64 | if (!TEST_ptr(fixture = OPENSSL_zalloc(sizeof(*fixture)))) | |
65 | return NULL; | |
66 | fixture->test_case_name = test_case_name; | |
67 | ||
5a7734cd | 68 | if (!TEST_ptr(fixture->cmp_ctx = OSSL_CMP_CTX_new(libctx, NULL)) |
3dbc5156 DDO |
69 | || !TEST_true(SET_OPT_UNPROTECTED_SEND(fixture->cmp_ctx, 1)) |
70 | || !TEST_true(OSSL_CMP_CTX_set1_referenceValue(fixture->cmp_ctx, | |
71 | ref, sizeof(ref)))) { | |
72 | tear_down(fixture); | |
73 | return NULL; | |
74 | } | |
75 | return fixture; | |
76 | } | |
77 | ||
78 | static EVP_PKEY *newkey = NULL; | |
79 | static X509 *cert = NULL; | |
80 | ||
81 | #define EXECUTE_MSG_CREATION_TEST(expr) \ | |
82 | do { \ | |
83 | OSSL_CMP_MSG *msg = NULL; \ | |
84 | int good = fixture->expected != 0 ? \ | |
85 | TEST_ptr(msg = (expr)) && TEST_true(valid_asn1_encoding(msg)) : \ | |
86 | TEST_ptr_null(msg = (expr)); \ | |
87 | \ | |
88 | OSSL_CMP_MSG_free(msg); \ | |
89 | return good; \ | |
90 | } while (0) | |
91 | ||
92 | /*- | |
93 | * The following tests call a cmp message creation function. | |
94 | * if fixture->expected != 0: | |
95 | * returns 1 if the message is created and syntactically correct. | |
96 | * if fixture->expected == 0 | |
97 | * returns 1 if message creation returns NULL | |
98 | */ | |
99 | static int execute_certreq_create_test(CMP_MSG_TEST_FIXTURE *fixture) | |
100 | { | |
299e0f1e | 101 | EXECUTE_MSG_CREATION_TEST(ossl_cmp_certreq_new(fixture->cmp_ctx, |
3dbc5156 | 102 | fixture->bodytype, |
299e0f1e | 103 | NULL)); |
3dbc5156 DDO |
104 | } |
105 | ||
106 | static int execute_errormsg_create_test(CMP_MSG_TEST_FIXTURE *fixture) | |
107 | { | |
108 | EXECUTE_MSG_CREATION_TEST(ossl_cmp_error_new(fixture->cmp_ctx, fixture->si, | |
109 | fixture->err_code, | |
62dcd2aa | 110 | "details", 0)); |
3dbc5156 DDO |
111 | } |
112 | ||
113 | static int execute_rr_create_test(CMP_MSG_TEST_FIXTURE *fixture) | |
114 | { | |
115 | EXECUTE_MSG_CREATION_TEST(ossl_cmp_rr_new(fixture->cmp_ctx)); | |
116 | } | |
117 | ||
118 | static int execute_certconf_create_test(CMP_MSG_TEST_FIXTURE *fixture) | |
119 | { | |
120 | EXECUTE_MSG_CREATION_TEST(ossl_cmp_certConf_new | |
121 | (fixture->cmp_ctx, fixture->fail_info, NULL)); | |
122 | } | |
123 | ||
124 | static int execute_genm_create_test(CMP_MSG_TEST_FIXTURE *fixture) | |
125 | { | |
126 | EXECUTE_MSG_CREATION_TEST(ossl_cmp_genm_new(fixture->cmp_ctx)); | |
127 | } | |
128 | ||
129 | static int execute_pollreq_create_test(CMP_MSG_TEST_FIXTURE *fixture) | |
130 | { | |
131 | EXECUTE_MSG_CREATION_TEST(ossl_cmp_pollReq_new(fixture->cmp_ctx, 4711)); | |
132 | } | |
133 | ||
134 | static int execute_pkimessage_create_test(CMP_MSG_TEST_FIXTURE *fixture) | |
135 | { | |
136 | EXECUTE_MSG_CREATION_TEST(ossl_cmp_msg_create | |
137 | (fixture->cmp_ctx, fixture->bodytype)); | |
138 | } | |
139 | ||
235595c4 | 140 | static int set1_newPkey(OSSL_CMP_CTX *ctx, EVP_PKEY *pkey) |
3dbc5156 DDO |
141 | { |
142 | if (!EVP_PKEY_up_ref(pkey)) | |
143 | return 0; | |
144 | ||
145 | if (!OSSL_CMP_CTX_set0_newPkey(ctx, 1, pkey)) { | |
146 | EVP_PKEY_free(pkey); | |
147 | return 0; | |
148 | } | |
149 | return 1; | |
150 | } | |
151 | ||
152 | static int test_cmp_create_ir_protection_set(void) | |
153 | { | |
06cee80a | 154 | OSSL_CMP_CTX *ctx; |
3dbc5156 DDO |
155 | unsigned char secret[16]; |
156 | ||
06cee80a DDO |
157 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); |
158 | ||
159 | ctx = fixture->cmp_ctx; | |
3dbc5156 | 160 | fixture->bodytype = OSSL_CMP_PKIBODY_IR; |
bce58e7f | 161 | fixture->err_code = -1; |
3dbc5156 | 162 | fixture->expected = 1; |
5a7734cd | 163 | if (!TEST_int_eq(1, RAND_bytes_ex(libctx, secret, sizeof(secret))) |
3dbc5156 DDO |
164 | || !TEST_true(SET_OPT_UNPROTECTED_SEND(ctx, 0)) |
165 | || !TEST_true(set1_newPkey(ctx, newkey)) | |
166 | || !TEST_true(OSSL_CMP_CTX_set1_secretValue(ctx, secret, | |
167 | sizeof(secret)))) { | |
168 | tear_down(fixture); | |
169 | fixture = NULL; | |
170 | } | |
171 | EXECUTE_TEST(execute_certreq_create_test, tear_down); | |
172 | return result; | |
173 | } | |
174 | ||
175 | static int test_cmp_create_ir_protection_fails(void) | |
176 | { | |
177 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
178 | fixture->bodytype = OSSL_CMP_PKIBODY_IR; | |
bce58e7f | 179 | fixture->err_code = -1; |
3dbc5156 DDO |
180 | fixture->expected = 0; |
181 | if (!TEST_true(OSSL_CMP_CTX_set1_pkey(fixture->cmp_ctx, newkey)) | |
182 | || !TEST_true(SET_OPT_UNPROTECTED_SEND(fixture->cmp_ctx, 0)) | |
7e765f46 | 183 | /* newkey used by default for signing does not match cert: */ |
63f1883d | 184 | || !TEST_true(OSSL_CMP_CTX_set1_cert(fixture->cmp_ctx, cert))) { |
3dbc5156 DDO |
185 | tear_down(fixture); |
186 | fixture = NULL; | |
187 | } | |
188 | EXECUTE_TEST(execute_certreq_create_test, tear_down); | |
189 | return result; | |
190 | } | |
191 | ||
192 | static int test_cmp_create_cr_without_key(void) | |
193 | { | |
194 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
195 | fixture->bodytype = OSSL_CMP_PKIBODY_CR; | |
bce58e7f | 196 | fixture->err_code = -1; |
3dbc5156 DDO |
197 | fixture->expected = 0; |
198 | EXECUTE_TEST(execute_certreq_create_test, tear_down); | |
199 | return result; | |
200 | } | |
201 | ||
202 | static int test_cmp_create_cr(void) | |
203 | { | |
204 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
205 | fixture->bodytype = OSSL_CMP_PKIBODY_CR; | |
bce58e7f | 206 | fixture->err_code = -1; |
3dbc5156 DDO |
207 | fixture->expected = 1; |
208 | if (!TEST_true(set1_newPkey(fixture->cmp_ctx, newkey))) { | |
209 | tear_down(fixture); | |
210 | fixture = NULL; | |
211 | } | |
212 | EXECUTE_TEST(execute_certreq_create_test, tear_down); | |
213 | return result; | |
214 | } | |
215 | ||
216 | static int test_cmp_create_certreq_with_invalid_bodytype(void) | |
217 | { | |
218 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
219 | fixture->bodytype = OSSL_CMP_PKIBODY_RR; | |
bce58e7f | 220 | fixture->err_code = -1; |
3dbc5156 DDO |
221 | fixture->expected = 0; |
222 | if (!TEST_true(set1_newPkey(fixture->cmp_ctx, newkey))) { | |
223 | tear_down(fixture); | |
224 | fixture = NULL; | |
225 | } | |
226 | EXECUTE_TEST(execute_certreq_create_test, tear_down); | |
227 | return result; | |
228 | } | |
229 | ||
230 | static int test_cmp_create_p10cr(void) | |
231 | { | |
06cee80a | 232 | OSSL_CMP_CTX *ctx; |
3dbc5156 DDO |
233 | X509_REQ *p10cr = NULL; |
234 | ||
06cee80a DDO |
235 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); |
236 | ctx = fixture->cmp_ctx; | |
3dbc5156 | 237 | fixture->bodytype = OSSL_CMP_PKIBODY_P10CR; |
299e0f1e | 238 | fixture->err_code = CMP_R_ERROR_CREATING_CERTREQ; |
3dbc5156 DDO |
239 | fixture->expected = 1; |
240 | if (!TEST_ptr(p10cr = load_csr(pkcs10_f)) | |
241 | || !TEST_true(set1_newPkey(ctx, newkey)) | |
242 | || !TEST_true(OSSL_CMP_CTX_set1_p10CSR(ctx, p10cr))) { | |
243 | tear_down(fixture); | |
244 | fixture = NULL; | |
245 | } | |
246 | X509_REQ_free(p10cr); | |
247 | EXECUTE_TEST(execute_certreq_create_test, tear_down); | |
248 | return result; | |
249 | } | |
250 | ||
251 | static int test_cmp_create_p10cr_null(void) | |
252 | { | |
253 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
254 | fixture->bodytype = OSSL_CMP_PKIBODY_P10CR; | |
299e0f1e | 255 | fixture->err_code = CMP_R_ERROR_CREATING_CERTREQ; |
3dbc5156 DDO |
256 | fixture->expected = 0; |
257 | if (!TEST_true(set1_newPkey(fixture->cmp_ctx, newkey))) { | |
258 | tear_down(fixture); | |
259 | fixture = NULL; | |
260 | } | |
261 | EXECUTE_TEST(execute_certreq_create_test, tear_down); | |
262 | return result; | |
263 | } | |
264 | ||
265 | static int test_cmp_create_kur(void) | |
266 | { | |
267 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
268 | fixture->bodytype = OSSL_CMP_PKIBODY_KUR; | |
bce58e7f | 269 | fixture->err_code = -1; |
3dbc5156 DDO |
270 | fixture->expected = 1; |
271 | if (!TEST_true(set1_newPkey(fixture->cmp_ctx, newkey)) | |
272 | || !TEST_true(OSSL_CMP_CTX_set1_oldCert(fixture->cmp_ctx, cert))) { | |
273 | tear_down(fixture); | |
274 | fixture = NULL; | |
275 | } | |
276 | EXECUTE_TEST(execute_certreq_create_test, tear_down); | |
277 | return result; | |
278 | } | |
279 | ||
280 | static int test_cmp_create_kur_without_oldcert(void) | |
281 | { | |
282 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
283 | fixture->bodytype = OSSL_CMP_PKIBODY_KUR; | |
bce58e7f | 284 | fixture->err_code = -1; |
3dbc5156 DDO |
285 | fixture->expected = 0; |
286 | if (!TEST_true(set1_newPkey(fixture->cmp_ctx, newkey))) { | |
287 | tear_down(fixture); | |
288 | fixture = NULL; | |
289 | } | |
290 | EXECUTE_TEST(execute_certreq_create_test, tear_down); | |
291 | return result; | |
292 | } | |
293 | ||
294 | static int test_cmp_create_certconf(void) | |
295 | { | |
296 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
297 | fixture->fail_info = 0; | |
298 | fixture->expected = 1; | |
299 | if (!TEST_true(ossl_cmp_ctx_set0_newCert(fixture->cmp_ctx, | |
5a7734cd | 300 | X509_dup_with_libctx(cert)))) { |
3dbc5156 DDO |
301 | tear_down(fixture); |
302 | fixture = NULL; | |
303 | } | |
304 | EXECUTE_TEST(execute_certconf_create_test, tear_down); | |
305 | return result; | |
306 | } | |
307 | ||
308 | static int test_cmp_create_certconf_badAlg(void) | |
309 | { | |
310 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
311 | fixture->fail_info = 1 << OSSL_CMP_PKIFAILUREINFO_badAlg; | |
312 | fixture->expected = 1; | |
313 | if (!TEST_true(ossl_cmp_ctx_set0_newCert(fixture->cmp_ctx, | |
5a7734cd | 314 | X509_dup_with_libctx(cert)))) { |
3dbc5156 DDO |
315 | tear_down(fixture); |
316 | fixture = NULL; | |
317 | } | |
318 | EXECUTE_TEST(execute_certconf_create_test, tear_down); | |
319 | return result; | |
320 | } | |
321 | ||
322 | static int test_cmp_create_certconf_fail_info_max(void) | |
323 | { | |
324 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
325 | fixture->fail_info = 1 << OSSL_CMP_PKIFAILUREINFO_MAX; | |
326 | fixture->expected = 1; | |
327 | if (!TEST_true(ossl_cmp_ctx_set0_newCert(fixture->cmp_ctx, | |
5a7734cd | 328 | X509_dup_with_libctx(cert)))) { |
3dbc5156 DDO |
329 | tear_down(fixture); |
330 | fixture = NULL; | |
331 | } | |
332 | EXECUTE_TEST(execute_certconf_create_test, tear_down); | |
333 | return result; | |
334 | } | |
335 | ||
336 | static int test_cmp_create_error_msg(void) | |
337 | { | |
338 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
62dcd2aa | 339 | fixture->si = OSSL_CMP_STATUSINFO_new(OSSL_CMP_PKISTATUS_rejection, |
3dbc5156 DDO |
340 | OSSL_CMP_PKIFAILUREINFO_systemFailure, |
341 | NULL); | |
342 | fixture->err_code = -1; | |
235595c4 | 343 | fixture->expected = 1; /* expected: message creation is successful */ |
3dbc5156 DDO |
344 | if (!TEST_true(set1_newPkey(fixture->cmp_ctx, newkey))) { |
345 | tear_down(fixture); | |
346 | fixture = NULL; | |
347 | } | |
348 | EXECUTE_TEST(execute_errormsg_create_test, tear_down); | |
349 | return result; | |
350 | } | |
351 | ||
352 | ||
353 | static int test_cmp_create_pollreq(void) | |
354 | { | |
355 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
356 | fixture->expected = 1; | |
357 | EXECUTE_TEST(execute_pollreq_create_test, tear_down); | |
358 | return result; | |
359 | } | |
360 | ||
361 | static int test_cmp_create_rr(void) | |
362 | { | |
363 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
364 | fixture->expected = 1; | |
365 | if (!TEST_true(OSSL_CMP_CTX_set1_oldCert(fixture->cmp_ctx, cert))) { | |
366 | tear_down(fixture); | |
367 | fixture = NULL; | |
368 | } | |
369 | EXECUTE_TEST(execute_rr_create_test, tear_down); | |
370 | return result; | |
371 | } | |
372 | ||
373 | static int test_cmp_create_genm(void) | |
374 | { | |
375 | OSSL_CMP_ITAV *iv = NULL; | |
376 | ||
377 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
378 | fixture->expected = 1; | |
379 | iv = OSSL_CMP_ITAV_create(OBJ_nid2obj(NID_id_it_implicitConfirm), NULL); | |
7e765f46 | 380 | if (!TEST_ptr(iv) |
3dbc5156 DDO |
381 | || !TEST_true(OSSL_CMP_CTX_push0_genm_ITAV(fixture->cmp_ctx, iv))) { |
382 | OSSL_CMP_ITAV_free(iv); | |
383 | tear_down(fixture); | |
384 | fixture = NULL; | |
385 | } | |
386 | ||
387 | EXECUTE_TEST(execute_genm_create_test, tear_down); | |
388 | return result; | |
389 | } | |
390 | ||
391 | static int execute_certrep_create(CMP_MSG_TEST_FIXTURE *fixture) | |
392 | { | |
6d1f50b5 | 393 | OSSL_CMP_CTX *ctx = fixture->cmp_ctx; |
3dbc5156 DDO |
394 | OSSL_CMP_CERTREPMESSAGE *crepmsg = OSSL_CMP_CERTREPMESSAGE_new(); |
395 | OSSL_CMP_CERTRESPONSE *read_cresp, *cresp = OSSL_CMP_CERTRESPONSE_new(); | |
396 | EVP_PKEY *privkey; | |
397 | X509 *certfromresp = NULL; | |
398 | int res = 0; | |
399 | ||
400 | if (crepmsg == NULL || cresp == NULL) | |
401 | goto err; | |
402 | if (!ASN1_INTEGER_set(cresp->certReqId, 99)) | |
403 | goto err; | |
404 | if ((cresp->certifiedKeyPair = OSSL_CMP_CERTIFIEDKEYPAIR_new()) == NULL) | |
405 | goto err; | |
406 | cresp->certifiedKeyPair->certOrEncCert->type = | |
407 | OSSL_CMP_CERTORENCCERT_CERTIFICATE; | |
408 | if ((cresp->certifiedKeyPair->certOrEncCert->value.certificate = | |
5a7734cd | 409 | X509_dup_with_libctx(cert)) == NULL |
3dbc5156 DDO |
410 | || !sk_OSSL_CMP_CERTRESPONSE_push(crepmsg->response, cresp)) |
411 | goto err; | |
412 | cresp = NULL; | |
413 | read_cresp = ossl_cmp_certrepmessage_get0_certresponse(crepmsg, 99); | |
414 | if (!TEST_ptr(read_cresp)) | |
415 | goto err; | |
416 | if (!TEST_ptr_null(ossl_cmp_certrepmessage_get0_certresponse(crepmsg, 88))) | |
417 | goto err; | |
6d1f50b5 DDO |
418 | privkey = OSSL_CMP_CTX_get0_newPkey(ctx, 1); /* may be NULL */ |
419 | certfromresp = ossl_cmp_certresponse_get1_cert(read_cresp, ctx, privkey); | |
3dbc5156 DDO |
420 | if (certfromresp == NULL || !TEST_int_eq(X509_cmp(cert, certfromresp), 0)) |
421 | goto err; | |
422 | ||
423 | res = 1; | |
424 | err: | |
425 | X509_free(certfromresp); | |
426 | OSSL_CMP_CERTRESPONSE_free(cresp); | |
427 | OSSL_CMP_CERTREPMESSAGE_free(crepmsg); | |
428 | return res; | |
429 | } | |
430 | ||
431 | static int test_cmp_create_certrep(void) | |
432 | { | |
433 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
434 | EXECUTE_TEST(execute_certrep_create, tear_down); | |
435 | return result; | |
436 | } | |
437 | ||
438 | ||
439 | static int execute_rp_create(CMP_MSG_TEST_FIXTURE *fixture) | |
440 | { | |
62dcd2aa | 441 | OSSL_CMP_PKISI *si = OSSL_CMP_STATUSINFO_new(33, 44, "a text"); |
3dbc5156 DDO |
442 | X509_NAME *issuer = X509_NAME_new(); |
443 | ASN1_INTEGER *serial = ASN1_INTEGER_new(); | |
444 | OSSL_CRMF_CERTID *cid = NULL; | |
445 | OSSL_CMP_MSG *rpmsg = NULL; | |
446 | int res = 0; | |
447 | ||
448 | if (si == NULL || issuer == NULL || serial == NULL) | |
449 | goto err; | |
450 | ||
451 | if (!X509_NAME_add_entry_by_txt(issuer, "CN", MBSTRING_ASC, | |
235595c4 | 452 | (unsigned char *)"The Issuer", -1, -1, 0) |
3dbc5156 DDO |
453 | || !ASN1_INTEGER_set(serial, 99) |
454 | || (cid = OSSL_CRMF_CERTID_gen(issuer, serial)) == NULL | |
455 | || (rpmsg = ossl_cmp_rp_new(fixture->cmp_ctx, si, cid, 1)) == NULL) | |
456 | goto err; | |
457 | ||
458 | if (!TEST_ptr(ossl_cmp_revrepcontent_get_CertId(rpmsg->body->value.rp, 0))) | |
459 | goto err; | |
460 | ||
62dcd2aa | 461 | if (!TEST_ptr(ossl_cmp_revrepcontent_get_pkisi(rpmsg->body->value.rp, 0))) |
3dbc5156 DDO |
462 | goto err; |
463 | ||
464 | res = 1; | |
465 | err: | |
466 | ASN1_INTEGER_free(serial); | |
467 | X509_NAME_free(issuer); | |
468 | OSSL_CRMF_CERTID_free(cid); | |
469 | OSSL_CMP_PKISI_free(si); | |
470 | OSSL_CMP_MSG_free(rpmsg); | |
471 | return res; | |
472 | } | |
473 | ||
474 | static int test_cmp_create_rp(void) | |
475 | { | |
476 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
477 | EXECUTE_TEST(execute_rp_create, tear_down); | |
478 | return result; | |
479 | } | |
480 | ||
481 | static int execute_pollrep_create(CMP_MSG_TEST_FIXTURE *fixture) | |
482 | { | |
483 | OSSL_CMP_MSG *pollrep; | |
484 | int res = 0; | |
485 | ||
486 | pollrep = ossl_cmp_pollRep_new(fixture->cmp_ctx, 77, 2000); | |
487 | if (!TEST_ptr(pollrep)) | |
488 | return 0; | |
235595c4 DDO |
489 | if (!TEST_ptr(ossl_cmp_pollrepcontent_get0_pollrep(pollrep->body-> |
490 | value.pollRep, 77))) | |
3dbc5156 | 491 | goto err; |
235595c4 DDO |
492 | if (!TEST_ptr_null(ossl_cmp_pollrepcontent_get0_pollrep(pollrep->body-> |
493 | value.pollRep, 88))) | |
3dbc5156 DDO |
494 | goto err; |
495 | ||
496 | res = 1; | |
497 | err: | |
498 | OSSL_CMP_MSG_free(pollrep); | |
499 | return res; | |
500 | } | |
501 | ||
502 | static int test_cmp_create_pollrep(void) | |
503 | { | |
504 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
505 | EXECUTE_TEST(execute_pollrep_create, tear_down); | |
506 | return result; | |
507 | } | |
508 | ||
509 | static int test_cmp_pkimessage_create(int bodytype) | |
510 | { | |
511 | X509_REQ *p10cr = NULL; | |
512 | ||
513 | SETUP_TEST_FIXTURE(CMP_MSG_TEST_FIXTURE, set_up); | |
514 | ||
515 | switch (fixture->bodytype = bodytype) { | |
516 | case OSSL_CMP_PKIBODY_P10CR: | |
517 | fixture->expected = 1; | |
518 | if (!TEST_true(OSSL_CMP_CTX_set1_p10CSR(fixture->cmp_ctx, | |
519 | p10cr = load_csr(pkcs10_f)))) { | |
520 | tear_down(fixture); | |
521 | fixture = NULL; | |
522 | } | |
523 | X509_REQ_free(p10cr); | |
524 | break; | |
525 | case OSSL_CMP_PKIBODY_IR: | |
526 | case OSSL_CMP_PKIBODY_IP: | |
527 | case OSSL_CMP_PKIBODY_CR: | |
528 | case OSSL_CMP_PKIBODY_CP: | |
529 | case OSSL_CMP_PKIBODY_KUR: | |
530 | case OSSL_CMP_PKIBODY_KUP: | |
531 | case OSSL_CMP_PKIBODY_RR: | |
532 | case OSSL_CMP_PKIBODY_RP: | |
533 | case OSSL_CMP_PKIBODY_PKICONF: | |
534 | case OSSL_CMP_PKIBODY_GENM: | |
535 | case OSSL_CMP_PKIBODY_GENP: | |
536 | case OSSL_CMP_PKIBODY_ERROR: | |
537 | case OSSL_CMP_PKIBODY_CERTCONF: | |
538 | case OSSL_CMP_PKIBODY_POLLREQ: | |
539 | case OSSL_CMP_PKIBODY_POLLREP: | |
540 | fixture->expected = 1; | |
541 | break; | |
542 | default: | |
543 | fixture->expected = 0; | |
544 | break; | |
545 | } | |
546 | ||
547 | EXECUTE_TEST(execute_pkimessage_create_test, tear_down); | |
548 | return result; | |
549 | } | |
550 | ||
551 | void cleanup_tests(void) | |
552 | { | |
553 | EVP_PKEY_free(newkey); | |
554 | X509_free(cert); | |
5a7734cd | 555 | OPENSSL_CTX_free(libctx); |
3dbc5156 DDO |
556 | } |
557 | ||
5a7734cd DDO |
558 | #define USAGE "new.key server.crt pkcs10.der module_name [module_conf_file]\n" |
559 | OPT_TEST_DECLARE_USAGE(USAGE) | |
560 | ||
3dbc5156 DDO |
561 | int setup_tests(void) |
562 | { | |
8d242823 MC |
563 | if (!test_skip_common_options()) { |
564 | TEST_error("Error parsing test options\n"); | |
565 | return 0; | |
566 | } | |
567 | ||
5a7734cd DDO |
568 | if (!TEST_ptr(newkey_f = test_get_argument(0)) |
569 | || !TEST_ptr(server_cert_f = test_get_argument(1)) | |
570 | || !TEST_ptr(pkcs10_f = test_get_argument(2))) { | |
571 | TEST_error("usage: cmp_msg_test %s", USAGE); | |
3dbc5156 DDO |
572 | return 0; |
573 | } | |
574 | ||
5a7734cd DDO |
575 | if (!test_get_libctx(&libctx, &default_null_provider, &provider, 3, USAGE)) |
576 | return 0; | |
577 | ||
9afa0748 | 578 | if (!TEST_ptr(newkey = load_pem_key(newkey_f, libctx)) |
5a7734cd DDO |
579 | || !TEST_ptr(cert = load_pem_cert(server_cert_f, libctx)) |
580 | || !TEST_int_eq(1, RAND_bytes_ex(libctx, ref, sizeof(ref)))) { | |
3dbc5156 DDO |
581 | cleanup_tests(); |
582 | return 0; | |
583 | } | |
584 | ||
585 | /* Message creation tests */ | |
586 | ADD_TEST(test_cmp_create_certreq_with_invalid_bodytype); | |
587 | ADD_TEST(test_cmp_create_ir_protection_fails); | |
588 | ADD_TEST(test_cmp_create_ir_protection_set); | |
589 | ADD_TEST(test_cmp_create_error_msg); | |
590 | ADD_TEST(test_cmp_create_certconf); | |
591 | ADD_TEST(test_cmp_create_certconf_badAlg); | |
592 | ADD_TEST(test_cmp_create_certconf_fail_info_max); | |
593 | ADD_TEST(test_cmp_create_kur); | |
594 | ADD_TEST(test_cmp_create_kur_without_oldcert); | |
595 | ADD_TEST(test_cmp_create_cr); | |
596 | ADD_TEST(test_cmp_create_cr_without_key); | |
597 | ADD_TEST(test_cmp_create_p10cr); | |
598 | ADD_TEST(test_cmp_create_p10cr_null); | |
599 | ADD_TEST(test_cmp_create_pollreq); | |
600 | ADD_TEST(test_cmp_create_rr); | |
601 | ADD_TEST(test_cmp_create_rp); | |
602 | ADD_TEST(test_cmp_create_genm); | |
603 | ADD_TEST(test_cmp_create_certrep); | |
604 | ADD_TEST(test_cmp_create_pollrep); | |
605 | ADD_ALL_TESTS_NOSUBTEST(test_cmp_pkimessage_create, | |
606 | OSSL_CMP_PKIBODY_POLLREP + 1); | |
607 | return 1; | |
608 | } |