2018-02-06 11:46:26 +01:00
|
|
|
/* This Source Code Form is subject to the terms of the Mozilla Public
|
|
|
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this file,
|
|
|
|
|
* You can obtain one at http://mozilla.org/MPL/2.0/. */
|
|
|
|
|
|
|
|
|
|
#include <memory>
|
|
|
|
|
#include "nss.h"
|
|
|
|
|
#include "pk11pub.h"
|
|
|
|
|
#include "sechash.h"
|
|
|
|
|
|
|
|
|
|
#include "cpputil.h"
|
|
|
|
|
#include "scoped_ptrs.h"
|
2018-02-23 11:04:39 +01:00
|
|
|
#include "databuffer.h"
|
2018-02-06 11:46:26 +01:00
|
|
|
|
|
|
|
|
#include "gtest/gtest.h"
|
|
|
|
|
|
|
|
|
|
namespace nss_test {
|
|
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
// For test vectors.
|
|
|
|
|
struct Pkcs11SignatureTestParams {
|
|
|
|
|
const DataBuffer pkcs8_;
|
|
|
|
|
const DataBuffer spki_;
|
|
|
|
|
const DataBuffer data_;
|
|
|
|
|
const DataBuffer signature_;
|
|
|
|
|
};
|
|
|
|
|
|
2018-02-06 11:46:26 +01:00
|
|
|
class Pk11SignatureTest : public ::testing::Test {
|
|
|
|
|
protected:
|
2018-08-14 07:52:35 +02:00
|
|
|
Pk11SignatureTest(CK_MECHANISM_TYPE mech, SECOidTag hash_oid)
|
|
|
|
|
: mechanism_(mech), hash_oid_(hash_oid) {}
|
2018-02-06 11:46:26 +01:00
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
virtual const SECItem* parameters() const { return nullptr; }
|
|
|
|
|
CK_MECHANISM_TYPE mechanism() const { return mechanism_; }
|
|
|
|
|
|
|
|
|
|
ScopedSECKEYPrivateKey ImportPrivateKey(const DataBuffer& pkcs8) {
|
2018-02-06 11:46:26 +01:00
|
|
|
ScopedPK11SlotInfo slot(PK11_GetInternalSlot());
|
|
|
|
|
if (!slot) {
|
2018-02-23 11:04:39 +01:00
|
|
|
ADD_FAILURE() << "No slot";
|
2018-02-06 11:46:26 +01:00
|
|
|
return nullptr;
|
|
|
|
|
}
|
|
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
SECItem pkcs8Item = {siBuffer, toUcharPtr(pkcs8.data()),
|
|
|
|
|
static_cast<unsigned int>(pkcs8.len())};
|
2018-02-06 11:46:26 +01:00
|
|
|
|
|
|
|
|
SECKEYPrivateKey* key = nullptr;
|
|
|
|
|
SECStatus rv = PK11_ImportDERPrivateKeyInfoAndReturnKey(
|
|
|
|
|
slot.get(), &pkcs8Item, nullptr, nullptr, false, false, KU_ALL, &key,
|
|
|
|
|
nullptr);
|
|
|
|
|
|
|
|
|
|
if (rv != SECSuccess) {
|
|
|
|
|
return nullptr;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return ScopedSECKEYPrivateKey(key);
|
|
|
|
|
}
|
|
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
ScopedSECKEYPublicKey ImportPublicKey(const DataBuffer& spki) {
|
|
|
|
|
SECItem spkiItem = {siBuffer, toUcharPtr(spki.data()),
|
|
|
|
|
static_cast<unsigned int>(spki.len())};
|
2018-02-06 11:46:26 +01:00
|
|
|
|
|
|
|
|
ScopedCERTSubjectPublicKeyInfo certSpki(
|
|
|
|
|
SECKEY_DecodeDERSubjectPublicKeyInfo(&spkiItem));
|
|
|
|
|
|
|
|
|
|
return ScopedSECKEYPublicKey(SECKEY_ExtractPublicKey(certSpki.get()));
|
|
|
|
|
}
|
|
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
bool ComputeHash(const DataBuffer& data, DataBuffer* hash) {
|
|
|
|
|
hash->Allocate(static_cast<size_t>(HASH_ResultLenByOidTag(hash_oid_)));
|
|
|
|
|
SECStatus rv =
|
|
|
|
|
PK11_HashBuf(hash_oid_, hash->data(), data.data(), data.len());
|
|
|
|
|
return rv == SECSuccess;
|
2018-02-06 11:46:26 +01:00
|
|
|
}
|
|
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
bool SignHashedData(ScopedSECKEYPrivateKey& privKey, const DataBuffer& hash,
|
|
|
|
|
DataBuffer* sig) {
|
|
|
|
|
SECItem hashItem = {siBuffer, toUcharPtr(hash.data()),
|
|
|
|
|
static_cast<unsigned int>(hash.len())};
|
|
|
|
|
int sigLen = PK11_SignatureLen(privKey.get());
|
|
|
|
|
EXPECT_LT(0, sigLen);
|
|
|
|
|
sig->Allocate(static_cast<size_t>(sigLen));
|
|
|
|
|
SECItem sigItem = {siBuffer, toUcharPtr(sig->data()),
|
|
|
|
|
static_cast<unsigned int>(sig->len())};
|
|
|
|
|
SECStatus rv = PK11_SignWithMechanism(privKey.get(), mechanism_,
|
|
|
|
|
parameters(), &sigItem, &hashItem);
|
|
|
|
|
return rv == SECSuccess;
|
2018-02-06 11:46:26 +01:00
|
|
|
}
|
|
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
bool ImportPrivateKeyAndSignHashedData(const DataBuffer& pkcs8,
|
|
|
|
|
const DataBuffer& data,
|
|
|
|
|
DataBuffer* sig) {
|
|
|
|
|
ScopedSECKEYPrivateKey privKey(ImportPrivateKey(pkcs8));
|
2018-02-06 11:46:26 +01:00
|
|
|
if (!privKey) {
|
2018-02-23 11:04:39 +01:00
|
|
|
return false;
|
2018-02-06 11:46:26 +01:00
|
|
|
}
|
|
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
DataBuffer hash;
|
|
|
|
|
if (!ComputeHash(data, &hash)) {
|
|
|
|
|
ADD_FAILURE() << "Failed to compute hash";
|
|
|
|
|
return false;
|
2018-02-06 11:46:26 +01:00
|
|
|
}
|
2018-02-23 11:04:39 +01:00
|
|
|
return SignHashedData(privKey, hash, sig);
|
2018-02-06 11:46:26 +01:00
|
|
|
}
|
|
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
void Verify(const Pkcs11SignatureTestParams& params, const DataBuffer& sig) {
|
|
|
|
|
ScopedSECKEYPublicKey pubKey(ImportPublicKey(params.spki_));
|
2018-02-06 11:46:26 +01:00
|
|
|
ASSERT_TRUE(pubKey);
|
|
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
DataBuffer hash;
|
|
|
|
|
ASSERT_TRUE(ComputeHash(params.data_, &hash));
|
2018-02-06 11:46:26 +01:00
|
|
|
|
|
|
|
|
// Verify.
|
2018-02-23 11:04:39 +01:00
|
|
|
SECItem hashItem = {siBuffer, toUcharPtr(hash.data()),
|
|
|
|
|
static_cast<unsigned int>(hash.len())};
|
|
|
|
|
SECItem sigItem = {siBuffer, toUcharPtr(sig.data()),
|
|
|
|
|
static_cast<unsigned int>(sig.len())};
|
2018-02-06 11:46:26 +01:00
|
|
|
SECStatus rv = PK11_VerifyWithMechanism(
|
2018-02-23 11:04:39 +01:00
|
|
|
pubKey.get(), mechanism_, parameters(), &sigItem, &hashItem, nullptr);
|
2018-02-06 11:46:26 +01:00
|
|
|
EXPECT_EQ(rv, SECSuccess);
|
|
|
|
|
}
|
|
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
void Verify(const Pkcs11SignatureTestParams& params) {
|
|
|
|
|
Verify(params, params.signature_);
|
2018-02-23 11:04:39 +01:00
|
|
|
}
|
2018-02-06 11:46:26 +01:00
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
void SignAndVerify(const Pkcs11SignatureTestParams& params) {
|
|
|
|
|
DataBuffer sig;
|
|
|
|
|
ASSERT_TRUE(
|
|
|
|
|
ImportPrivateKeyAndSignHashedData(params.pkcs8_, params.data_, &sig));
|
|
|
|
|
Verify(params, sig);
|
|
|
|
|
}
|
2018-04-25 21:33:33 +02:00
|
|
|
|
2018-02-23 11:04:39 +01:00
|
|
|
private:
|
|
|
|
|
CK_MECHANISM_TYPE mechanism_;
|
|
|
|
|
SECOidTag hash_oid_;
|
|
|
|
|
};
|
2018-04-25 21:33:33 +02:00
|
|
|
|
2018-02-06 11:46:26 +01:00
|
|
|
} // namespace nss_test
|