]> git.ipfire.org Git - thirdparty/openssl.git/commitdiff
apps: test rsa -text option
authorJakub Zelenka <jakub.zelenka@openssl.foundation>
Tue, 14 Jul 2026 16:26:40 +0000 (18:26 +0200)
committerPauli <paul.dale@oracle.com>
Mon, 20 Jul 2026 23:32:12 +0000 (09:32 +1000)
The -text option of the rsa app was not exercised by any test. Add a
subtest that prints both a private and a public key in text form and,
after stripping the colon-separated hex formatting, verifies the printed
modulus and private exponent match the committed testrsa.pem keypair
rather than merely checking that the labels are present.

Assisted-by: Claude:claude-opus-4-8
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
(Merged from https://github.com/openssl/openssl/pull/31950)

test/recipes/15-test_rsa.t

index 3e60b23ef47d548a92a3ee5f7c66dd6acf979054..c7eafbfb1cee4e838b2421f0e4994fe16728f1d1 100644 (file)
@@ -17,7 +17,7 @@ use OpenSSL::Test::Utils;
 
 setup("test_rsa");
 
-plan tests => 16;
+plan tests => 17;
 
 require_ok(srctop_file('test', 'recipes', 'tconversion.pl'));
 
@@ -27,6 +27,53 @@ run_rsa_tests("pkey");
 
 run_rsa_tests("rsa");
 
+SKIP: {
+    skip "RSA is not supported in this build", 1 if disabled("rsa");
+
+    subtest "rsa -text prints the key in text form" => sub {
+        plan tests => 6;
+
+        # The modulus (n) and private exponent (d) of the committed
+        # testrsa.pem keypair.  -text prints them as colon-separated hex; we
+        # strip the formatting and compare against the known values so the
+        # actual key material, not just the labels, is verified.
+        my $modulus = "AADB7AA92E464F15711996166B4FF8BBE2301DFEE9D8B3596DC3"
+            . "C1A7DFCE7C87180170509FC84EFD17B5BB02CA5DD0A3228686B380CB746F"
+            . "3CAE4CDFC8AE5D3D";
+        my $priv_exp = "677727CDA1D733F6F119A479091D51AC3D6A1410157E840588E1"
+            . "FDB8F26031AA00BA84048AC3C755C64329C3AFE30120EBF4C89C02170671"
+            . "2282DAAF473BB2A1";
+
+        my @priv = run(app(['openssl', 'rsa', '-text', '-noout',
+                            '-in', srctop_file("test", "testrsa.pem")],
+                           stderr => undef),
+                       capture => 1);
+        chomp @priv;
+        my $priv_blob = uc join('', @priv);
+        $priv_blob =~ s/[^0-9A-F]//g;
+        ok(grep(/^Private-Key: \(512 bit, 2 primes\)$/, @priv),
+           "-text prints the private key header");
+        ok(index($priv_blob, $modulus) >= 0,
+           "-text prints the expected modulus for a private key");
+        ok(index($priv_blob, $priv_exp) >= 0,
+           "-text prints the expected private exponent");
+
+        my @pub = run(app(['openssl', 'rsa', '-pubin', '-text', '-noout',
+                           '-in', srctop_file("test", "testrsapub.pem")],
+                          stderr => undef),
+                      capture => 1);
+        chomp @pub;
+        my $pub_blob = uc join('', @pub);
+        $pub_blob =~ s/[^0-9A-F]//g;
+        ok(grep(/^Public-Key: \(512 bit\)$/, @pub),
+           "-text prints the public key header");
+        ok(index($pub_blob, $modulus) >= 0,
+           "-text prints the expected modulus for a public key");
+        ok(!grep(/privateExponent/, @pub),
+           "-text does not print a private exponent for a public key");
+    };
+}
+
 sub run_rsa_tests {
     my $cmd = shift;