test_rfc4490.py 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274
  1. #
  2. # This file is part of pyasn1-modules software.
  3. #
  4. # Copyright (c) 2019, Vigil Security, LLC
  5. # License: http://snmplabs.com/pyasn1/license.html
  6. #
  7. import sys
  8. import unittest
  9. from pyasn1.type import univ
  10. from pyasn1.codec.der.decoder import decode as der_decoder
  11. from pyasn1.codec.der.encoder import encode as der_encoder
  12. from pyasn1_modules import pem
  13. from pyasn1_modules import rfc5652
  14. from pyasn1_modules import rfc5280
  15. from pyasn1_modules import rfc4357
  16. from pyasn1_modules import rfc4490
  17. class SignedTestCase(unittest.TestCase):
  18. signed_pem_text = """\
  19. MIIBKAYJKoZIhvcNAQcCoIIBGTCCARUCAQExDDAKBgYqhQMCAgkFADAbBgkqhkiG
  20. 9w0BBwGgDgQMc2FtcGxlIHRleHQKMYHkMIHhAgEBMIGBMG0xHzAdBgNVBAMMFkdv
  21. c3RSMzQxMC0yMDAxIGV4YW1wbGUxEjAQBgNVBAoMCUNyeXB0b1BybzELMAkGA1UE
  22. BhMCUlUxKTAnBgkqhkiG9w0BCQEWGkdvc3RSMzQxMC0yMDAxQGV4YW1wbGUuY29t
  23. AhAr9cYewhG9F8fc1GJmtC4hMAoGBiqFAwICCQUAMAoGBiqFAwICEwUABEDAw0LZ
  24. P4/+JRERiHe/icPbg0IE1iD5aCqZ9v4wO+T0yPjVtNr74caRZzQfvKZ6DRJ7/RAl
  25. xlHbjbL0jHF+7XKp
  26. """
  27. def setUp(self):
  28. self.asn1Spec = rfc5652.ContentInfo()
  29. def testDerCodec(self):
  30. substrate = pem.readBase64fromText(self.signed_pem_text)
  31. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  32. self.assertFalse(rest)
  33. self.assertTrue(asn1Object.prettyPrint())
  34. self.assertEqual(substrate, der_encoder(asn1Object))
  35. self.assertEqual(rfc5652.id_signedData, asn1Object['contentType'])
  36. sd, rest = der_decoder(
  37. asn1Object['content'], asn1Spec=rfc5652.SignedData())
  38. self.assertFalse(rest)
  39. self.assertTrue(sd.prettyPrint())
  40. self.assertEqual(asn1Object['content'], der_encoder(sd))
  41. encoded_null = der_encoder(univ.Null(""))
  42. si = sd['signerInfos'][0]
  43. self.assertEqual(rfc4357.id_GostR3411_94, si['digestAlgorithm']['algorithm'])
  44. self.assertEqual(encoded_null, si['digestAlgorithm']['parameters'])
  45. self.assertEqual(rfc4357.id_GostR3410_2001, si['signatureAlgorithm']['algorithm'])
  46. self.assertEqual(encoded_null, si['signatureAlgorithm']['parameters'])
  47. sig = rfc4490.GostR3410_2001_Signature()
  48. sig = si['signature']
  49. self.assertEqual(64, len(sig))
  50. def testOpenTypes(self):
  51. substrate = pem.readBase64fromText(self.signed_pem_text)
  52. asn1Object, rest = der_decoder(
  53. substrate, asn1Spec=self.asn1Spec, decodeOpenTypes=True)
  54. self.assertFalse(rest)
  55. self.assertTrue(asn1Object.prettyPrint())
  56. self.assertEqual(substrate, der_encoder(asn1Object))
  57. self.assertEqual(rfc5652.id_signedData, asn1Object['contentType'])
  58. si = asn1Object['content']['signerInfos'][0]
  59. self.assertEqual(rfc4357.id_GostR3411_94, si['digestAlgorithm']['algorithm'])
  60. self.assertEqual(univ.Null(""), si['digestAlgorithm']['parameters'])
  61. self.assertEqual(rfc4357.id_GostR3410_2001, si['signatureAlgorithm']['algorithm'])
  62. self.assertEqual(univ.Null(""), si['signatureAlgorithm']['parameters'])
  63. sig = rfc4490.GostR3410_2001_Signature()
  64. sig = si['signature']
  65. self.assertEqual(64, len(sig))
  66. class KeyAgreeTestCase(unittest.TestCase):
  67. keyagree_pem_text = """\
  68. MIIBpAYJKoZIhvcNAQcDoIIBlTCCAZECAQIxggFQoYIBTAIBA6BloWMwHAYGKoUD
  69. AgITMBIGByqFAwICJAAGByqFAwICHgEDQwAEQLNVOfRngZcrpcTZhB8n+4HtCDLm
  70. mtTyAHi4/4Nk6tIdsHg8ff4DwfQG5DvMFrnF9vYZNxwXuKCqx9GhlLOlNiChCgQI
  71. L/D20YZLMoowHgYGKoUDAgJgMBQGByqFAwICDQAwCQYHKoUDAgIfATCBszCBsDCB
  72. gTBtMR8wHQYDVQQDDBZHb3N0UjM0MTAtMjAwMSBleGFtcGxlMRIwEAYDVQQKDAlD
  73. cnlwdG9Qcm8xCzAJBgNVBAYTAlJVMSkwJwYJKoZIhvcNAQkBFhpHb3N0UjM0MTAt
  74. MjAwMUBleGFtcGxlLmNvbQIQK/XGHsIRvRfH3NRiZrQuIQQqMCgEIBajHOfOTukN
  75. 8ex0aQRoHsefOu24Ox8dSn75pdnLGdXoBAST/YZ+MDgGCSqGSIb3DQEHATAdBgYq
  76. hQMCAhUwEwQItzXhegc1oh0GByqFAwICHwGADDmxivS/qeJlJbZVyQ==
  77. """
  78. def setUp(self):
  79. self.asn1Spec = rfc5652.ContentInfo()
  80. def testDerCodec(self):
  81. substrate = pem.readBase64fromText(self.keyagree_pem_text)
  82. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  83. self.assertFalse(rest)
  84. self.assertTrue(asn1Object.prettyPrint())
  85. self.assertEqual(substrate, der_encoder(asn1Object))
  86. self.assertEqual(rfc5652.id_envelopedData, asn1Object['contentType'])
  87. ed, rest = der_decoder(
  88. asn1Object['content'], asn1Spec=rfc5652.EnvelopedData())
  89. self.assertFalse(rest)
  90. self.assertTrue(ed.prettyPrint())
  91. self.assertEqual(asn1Object['content'], der_encoder(ed))
  92. ri = ed['recipientInfos'][0]
  93. alg1 = ri['kari']['originator']['originatorKey']['algorithm']
  94. self.assertEqual(rfc4357.id_GostR3410_2001, alg1['algorithm'])
  95. param1, rest = der_decoder(
  96. alg1['parameters'],
  97. asn1Spec=rfc4357.GostR3410_2001_PublicKeyParameters())
  98. self.assertFalse(rest)
  99. self.assertTrue(param1.prettyPrint())
  100. self.assertEqual(alg1['parameters'], der_encoder(param1))
  101. self.assertEqual(rfc4357.id_GostR3410_2001_CryptoPro_XchA_ParamSet, param1['publicKeyParamSet'])
  102. self.assertEqual(rfc4357.id_GostR3411_94_CryptoProParamSet, param1['digestParamSet'])
  103. self.assertEqual(8, len(ri['kari']['ukm']))
  104. alg2 = ri['kari']['keyEncryptionAlgorithm']
  105. self.assertEqual(rfc4490.id_GostR3410_2001_CryptoPro_ESDH, alg2['algorithm'])
  106. param2, rest = der_decoder(
  107. alg2['parameters'], asn1Spec=rfc4357.AlgorithmIdentifier())
  108. self.assertFalse(rest)
  109. self.assertTrue(param2.prettyPrint())
  110. self.assertEqual(alg2['parameters'], der_encoder(param2))
  111. self.assertEqual(rfc4490.id_Gost28147_89_None_KeyWrap, param2['algorithm'])
  112. kwa_p, rest = der_decoder(
  113. param2['parameters'], asn1Spec=rfc4490.Gost28147_89_KeyWrapParameters())
  114. self.assertFalse(rest)
  115. self.assertTrue(kwa_p.prettyPrint())
  116. self.assertEqual(param2['parameters'], der_encoder(kwa_p))
  117. self.assertEqual(rfc4357.id_Gost28147_89_CryptoPro_A_ParamSet, kwa_p['encryptionParamSet'])
  118. alg3 = ed['encryptedContentInfo']['contentEncryptionAlgorithm']
  119. self.assertEqual(rfc4357.id_Gost28147_89, alg3['algorithm'])
  120. param3, rest = der_decoder(alg3['parameters'], asn1Spec=rfc4357.Gost28147_89_Parameters())
  121. self.assertFalse(rest)
  122. self.assertTrue(param3.prettyPrint())
  123. self.assertEqual(alg3['parameters'], der_encoder(param3))
  124. self.assertEqual(8, len(param3['iv']))
  125. self.assertEqual(rfc4357.id_Gost28147_89_CryptoPro_A_ParamSet, param3['encryptionParamSet'])
  126. def testOpenTypes(self):
  127. openTypeMap = {
  128. rfc4357.id_GostR3410_2001: rfc4357.GostR3410_2001_PublicKeyParameters(),
  129. rfc4357.id_Gost28147_89: rfc4357.Gost28147_89_Parameters(),
  130. rfc4490.id_GostR3410_2001_CryptoPro_ESDH: rfc5280.AlgorithmIdentifier(),
  131. }
  132. substrate = pem.readBase64fromText(self.keyagree_pem_text)
  133. asn1Object, rest = der_decoder(
  134. substrate, asn1Spec=self.asn1Spec,
  135. openTypes=openTypeMap, decodeOpenTypes=True)
  136. self.assertFalse(rest)
  137. self.assertTrue(asn1Object.prettyPrint())
  138. self.assertEqual(substrate, der_encoder(asn1Object))
  139. self.assertEqual(rfc5652.id_envelopedData, asn1Object['contentType'])
  140. ri = asn1Object['content']['recipientInfos'][0]
  141. alg1 = ri['kari']['originator']['originatorKey']['algorithm']
  142. self.assertEqual(rfc4357.id_GostR3410_2001, alg1['algorithm'])
  143. param1 = alg1['parameters']
  144. self.assertEqual(rfc4357.id_GostR3410_2001_CryptoPro_XchA_ParamSet, param1['publicKeyParamSet'])
  145. self.assertEqual(rfc4357.id_GostR3411_94_CryptoProParamSet, param1['digestParamSet'])
  146. self.assertEqual(8, len(ri['kari']['ukm']))
  147. alg2 = ri['kari']['keyEncryptionAlgorithm']
  148. self.assertEqual(rfc4490.id_GostR3410_2001_CryptoPro_ESDH, alg2['algorithm'])
  149. param2 = alg2['parameters']
  150. self.assertEqual(rfc4490.id_Gost28147_89_None_KeyWrap, param2['algorithm'])
  151. kwa_p = param2['parameters']
  152. self.assertEqual(rfc4357.id_Gost28147_89_CryptoPro_A_ParamSet, kwa_p['encryptionParamSet'])
  153. alg3 = asn1Object['content']['encryptedContentInfo']['contentEncryptionAlgorithm']
  154. self.assertEqual(rfc4357.id_Gost28147_89, alg3['algorithm'])
  155. param3 = alg3['parameters']
  156. self.assertEqual(8, len(param3['iv']))
  157. self.assertEqual(rfc4357.id_Gost28147_89_CryptoPro_A_ParamSet, param3['encryptionParamSet'])
  158. class KeyTransportTestCase(unittest.TestCase):
  159. keytrans_pem_text = """\
  160. MIIBpwYJKoZIhvcNAQcDoIIBmDCCAZQCAQAxggFTMIIBTwIBADCBgTBtMR8wHQYD
  161. VQQDDBZHb3N0UjM0MTAtMjAwMSBleGFtcGxlMRIwEAYDVQQKDAlDcnlwdG9Qcm8x
  162. CzAJBgNVBAYTAlJVMSkwJwYJKoZIhvcNAQkBFhpHb3N0UjM0MTAtMjAwMUBleGFt
  163. cGxlLmNvbQIQK/XGHsIRvRfH3NRiZrQuITAcBgYqhQMCAhMwEgYHKoUDAgIkAAYH
  164. KoUDAgIeAQSBpzCBpDAoBCBqL6ghBpVon5/kR6qey2EVK35BYLxdjfv1PSgbGJr5
  165. dQQENm2Yt6B4BgcqhQMCAh8BoGMwHAYGKoUDAgITMBIGByqFAwICJAAGByqFAwIC
  166. HgEDQwAEQE0rLzOQ5tyj3VUqzd/g7/sx93N+Tv+/eImKK8PNMZQESw5gSJYf28dd
  167. Em/askCKd7W96vLsNMsjn5uL3Z4SwPYECJeV4ywrrSsMMDgGCSqGSIb3DQEHATAd
  168. BgYqhQMCAhUwEwQIvBCLHwv/NCkGByqFAwICHwGADKqOch3uT7Mu4w+hNw==
  169. """
  170. def setUp(self):
  171. self.asn1Spec = rfc5652.ContentInfo()
  172. def testDerCodec(self):
  173. substrate = pem.readBase64fromText(self.keytrans_pem_text)
  174. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  175. self.assertFalse(rest)
  176. self.assertTrue(asn1Object.prettyPrint())
  177. self.assertEqual(substrate, der_encoder(asn1Object))
  178. self.assertEqual(rfc5652.id_envelopedData, asn1Object['contentType'])
  179. ed, rest = der_decoder(
  180. asn1Object['content'], asn1Spec=rfc5652.EnvelopedData())
  181. self.assertFalse(rest)
  182. self.assertTrue(ed.prettyPrint())
  183. self.assertEqual(asn1Object['content'], der_encoder(ed))
  184. ri = ed['recipientInfos'][0]
  185. alg1 = ri['ktri']['keyEncryptionAlgorithm']
  186. self.assertEqual(rfc4357.id_GostR3410_2001, alg1['algorithm'])
  187. param1, rest = der_decoder(
  188. alg1['parameters'], asn1Spec=rfc4357.GostR3410_2001_PublicKeyParameters())
  189. self.assertFalse(rest)
  190. self.assertTrue(param1.prettyPrint())
  191. self.assertEqual(alg1['parameters'], der_encoder(param1))
  192. self.assertEqual(rfc4357.id_GostR3410_2001_CryptoPro_XchA_ParamSet, param1['publicKeyParamSet'])
  193. self.assertEqual(rfc4357.id_GostR3411_94_CryptoProParamSet, param1['digestParamSet'])
  194. alg2 = ed['encryptedContentInfo']['contentEncryptionAlgorithm']
  195. self.assertEqual(rfc4357.id_Gost28147_89, alg2['algorithm'])
  196. param2, rest = der_decoder(
  197. alg2['parameters'], asn1Spec=rfc4357.Gost28147_89_Parameters())
  198. self.assertFalse(rest)
  199. self.assertTrue(param2.prettyPrint())
  200. self.assertEqual(alg2['parameters'], der_encoder(param2))
  201. self.assertEqual(8, len(param2['iv']))
  202. self.assertEqual(rfc4357.id_Gost28147_89_CryptoPro_A_ParamSet, param2['encryptionParamSet'])
  203. def testOpenTypes(self):
  204. openTypeMap = {
  205. rfc4357.id_GostR3410_2001: rfc4357.GostR3410_2001_PublicKeyParameters(),
  206. rfc4357.id_Gost28147_89: rfc4357.Gost28147_89_Parameters(),
  207. }
  208. substrate = pem.readBase64fromText(self.keytrans_pem_text)
  209. asn1Object, rest = der_decoder(
  210. substrate, asn1Spec=self.asn1Spec,
  211. openTypes=openTypeMap, decodeOpenTypes=True)
  212. self.assertFalse(rest)
  213. self.assertTrue(asn1Object.prettyPrint())
  214. self.assertEqual(substrate, der_encoder(asn1Object))
  215. ri = asn1Object['content']['recipientInfos'][0]
  216. alg1 = ri['ktri']['keyEncryptionAlgorithm']
  217. self.assertEqual(rfc4357.id_GostR3410_2001, alg1['algorithm'])
  218. param1 = alg1['parameters']
  219. self.assertEqual(rfc4357.id_GostR3410_2001_CryptoPro_XchA_ParamSet, param1['publicKeyParamSet'])
  220. self.assertEqual(rfc4357.id_GostR3411_94_CryptoProParamSet, param1['digestParamSet'])
  221. alg2 = asn1Object['content']['encryptedContentInfo']['contentEncryptionAlgorithm']
  222. self.assertEqual(rfc4357.id_Gost28147_89, alg2['algorithm'])
  223. param2 = alg2['parameters']
  224. self.assertEqual(8, len(param2['iv']))
  225. self.assertEqual(rfc4357.id_Gost28147_89_CryptoPro_A_ParamSet, param2['encryptionParamSet'])
  226. suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__])
  227. if __name__ == '__main__':
  228. result = unittest.TextTestRunner(verbosity=2).run(suite)
  229. sys.exit(not result.wasSuccessful())