test_rfc5916.py 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107
  1. #
  2. # This file is part of pyasn1-modules software.
  3. #
  4. # Created by Russ Housley
  5. # Copyright (c) 2019, Vigil Security, LLC
  6. # License: http://snmplabs.com/pyasn1/license.html
  7. #
  8. import sys
  9. import unittest
  10. from pyasn1.codec.der.decoder import decode as der_decoder
  11. from pyasn1.codec.der.encoder import encode as der_encoder
  12. from pyasn1.type import univ
  13. from pyasn1_modules import pem
  14. from pyasn1_modules import rfc5280
  15. from pyasn1_modules import rfc5916
  16. class DeviceCertTestCase(unittest.TestCase):
  17. cert_pem_text = """\
  18. MIICpzCCAiygAwIBAgIJAKWzVCgbsG5FMAoGCCqGSM49BAMDMD8xCzAJBgNVBAYT
  19. AlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwIQm9n
  20. dXMgQ0EwHhcNMTkxMDMxMTQwMDE1WhcNMjAxMDMwMTQwMDE1WjB4MQswCQYDVQQG
  21. EwJVUzELMAkGA1UECBMCVkExEDAOBgNVBAcTB0hlcm5kb24xEDAOBgNVBAoTB0V4
  22. YW1wbGUxGjAYBgNVBAsTEURldmljZSBPcGVyYXRpb25zMRwwGgYDVQQDExNleDEy
  23. MzQ1LmV4YW1wbGUuY29tMHYwEAYHKoZIzj0CAQYFK4EEACIDYgAE7Lje3glS2qYl
  24. 5x6N9TOlD4CbnzfFeJQfbDaCa3vexEiwE0apuAP+4L5fqOsYeZC970iNW+z3PdUs
  25. GzkKDC2cCVy8nIxQ3mWhNQDvavT3iz5OGSwa1GjSXRFbGn2x9QjNo4G6MIG3MEIG
  26. CWCGSAGG+EIBDQQ1FjNUaGlzIGNlcnRpZmljYXRlIGNhbm5vdCBiZSB0cnVzdGVk
  27. IGZvciBhbnkgcHVycG9zZS4wHQYDVR0OBBYEFPTQN1kXEM5Rd4hNvQL5HyA+o2No
  28. MB8GA1UdIwQYMBaAFPI12zQE2qVV8r1pA5mwYuziFQjBMAsGA1UdDwQEAwIHgDAk
  29. BgNVHQkEHTAbMBkGCWCGSAFlAgEFRTEMBgorBgEEAYGsYDAYMAoGCCqGSM49BAMD
  30. A2kAMGYCMQCt6AceOEIwXFKFHIV8+wTK/vgs7ZYSA6jhXUpzNtzZw1xh9NxVUhmx
  31. pogu5Q9Vp28CMQC5YVF8dShC1tk9YImRftiVl8C6pbj//1K/+MwmR6nRk/WU+hKl
  32. +Qsc5Goi6At471s=
  33. """
  34. def setUp(self):
  35. self.asn1Spec = rfc5280.Certificate()
  36. def testDerCodec(self):
  37. substrate = pem.readBase64fromText(self.cert_pem_text)
  38. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  39. self.assertFalse(rest)
  40. self.assertTrue(asn1Object.prettyPrint())
  41. self.assertEqual(substrate, der_encoder(asn1Object))
  42. found_dev_owner = False
  43. der_dev_own_oid = der_encoder(univ.ObjectIdentifier('1.3.6.1.4.1.22112.48.24'))
  44. for extn in asn1Object['tbsCertificate']['extensions']:
  45. if extn['extnID'] == rfc5280.id_ce_subjectDirectoryAttributes:
  46. self.assertIn(extn['extnID'], rfc5280.certificateExtensionsMap)
  47. ev, rest = der_decoder(
  48. extn['extnValue'],
  49. asn1Spec=rfc5280.certificateExtensionsMap[extn['extnID']])
  50. self.assertFalse(rest)
  51. self.assertTrue(ev.prettyPrint())
  52. self.assertEqual(extn['extnValue'], der_encoder(ev))
  53. for attr in ev:
  54. if attr['type'] == rfc5916.id_deviceOwner:
  55. self.assertEqual(der_dev_own_oid, attr['values'][0])
  56. found_dev_owner = True
  57. self.assertTrue(found_dev_owner)
  58. def testOpenTypes(self):
  59. substrate = pem.readBase64fromText(self.cert_pem_text)
  60. asn1Object, rest = der_decoder(substrate,
  61. asn1Spec=self.asn1Spec,
  62. decodeOpenTypes=True)
  63. self.assertFalse(rest)
  64. self.assertTrue(asn1Object.prettyPrint())
  65. self.assertEqual(substrate, der_encoder(asn1Object))
  66. found_dev_owner = False
  67. dev_own_oid = univ.ObjectIdentifier('1.3.6.1.4.1.22112.48.24')
  68. for extn in asn1Object['tbsCertificate']['extensions']:
  69. if extn['extnID'] == rfc5280.id_ce_subjectDirectoryAttributes:
  70. self.assertIn(extn['extnID'], rfc5280.certificateExtensionsMap)
  71. ev, rest = der_decoder(
  72. extn['extnValue'],
  73. asn1Spec=rfc5280.certificateExtensionsMap[extn['extnID']],
  74. decodeOpenTypes=True)
  75. self.assertFalse(rest)
  76. self.assertTrue(ev.prettyPrint())
  77. self.assertEqual(extn['extnValue'], der_encoder(ev))
  78. for attr in ev:
  79. if attr['type'] == rfc5916.id_deviceOwner:
  80. self.assertEqual(dev_own_oid, attr['values'][0])
  81. found_dev_owner = True
  82. self.assertTrue(found_dev_owner)
  83. suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__])
  84. if __name__ == '__main__':
  85. result = unittest.TextTestRunner(verbosity=2).run(suite)
  86. sys.exit(not result.wasSuccessful())