test_rfc7229.py 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293
  1. #
  2. # This file is part of pyasn1-modules software.
  3. #
  4. # Created by Russ Housley
  5. # Copyright (c) 2019, Vigil Security, LLC
  6. # License: http://snmplabs.com/pyasn1/license.html
  7. #
  8. import sys
  9. import unittest
  10. from pyasn1.codec.der.decoder import decode as der_decoder
  11. from pyasn1.codec.der.encoder import encode as der_encoder
  12. from pyasn1_modules import pem
  13. from pyasn1_modules import rfc5280
  14. from pyasn1_modules import rfc7229
  15. class CertificatePolicyTestCase(unittest.TestCase):
  16. pem_text = """\
  17. MIIDJDCCAqqgAwIBAgIJAKWzVCgbsG5AMAoGCCqGSM49BAMDMD8xCzAJBgNVBAYT
  18. AlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwIQm9n
  19. dXMgQ0EwHhcNMTkxMDEzMTkwNTUzWhcNMjAxMDEyMTkwNTUzWjBTMQswCQYDVQQG
  20. EwJVUzELMAkGA1UECBMCVkExEDAOBgNVBAcTB0hlcm5kb24xJTAjBgNVBAoTHFRF
  21. U1QgQ2VydGlmaWNhdGlvbiBBdXRob3JpdHkwdjAQBgcqhkjOPQIBBgUrgQQAIgNi
  22. AATwUXZUseiOaqWdrClDCMbp9YFAM87LTmFirygpzKDU9cfqSCg7zBDIphXCwMcS
  23. 9zVWDoStCbcvN0jw5CljHcffzpHYX91P88SZRJ1w4hawHjOsWxvM3AkYgZ5nfdlL
  24. 7EajggFcMIIBWDAdBgNVHQ4EFgQU8jXbNATapVXyvWkDmbBi7OIVCMEwbwYDVR0j
  25. BGgwZoAU8jXbNATapVXyvWkDmbBi7OIVCMGhQ6RBMD8xCzAJBgNVBAYTAlVTMQsw
  26. CQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwIQm9ndXMgQ0GC
  27. CQDokdYGkU/O8jAPBgNVHRMBAf8EBTADAQH/MAsGA1UdDwQEAwIBhjBCBglghkgB
  28. hvhCAQ0ENRYzVGhpcyBjZXJ0aWZpY2F0ZSBjYW5ub3QgYmUgdHJ1c3RlZCBmb3Ig
  29. YW55IHB1cnBvc2UuMCEGA1UdIAQaMBgwCgYIKwYBBQUHDQEwCgYIKwYBBQUHDQIw
  30. CgYDVR02BAMCAQIwNQYDVR0hBC4wLDAUBggrBgEFBQcNAQYIKwYBBQUHDQcwFAYI
  31. KwYBBQUHDQIGCCsGAQUFBw0IMAoGCCqGSM49BAMDA2gAMGUCMHaWskjS7MKQCMcn
  32. zEKFOV3LWK8pL57vrECJd8ywKdwBJUNw9HhvSKkfUwL6rjlLpQIxAL2QO3CNoZRP
  33. PZs8K3IjUA5+U73pA8lpaTOPscLY22WL9pAGmyVUyEJ8lM7E+r4iDg==
  34. """
  35. def setUp(self):
  36. self.asn1Spec = rfc5280.Certificate()
  37. def testDerCodec(self):
  38. test_oids = [
  39. rfc7229.id_TEST_certPolicyOne,
  40. rfc7229.id_TEST_certPolicyTwo,
  41. rfc7229.id_TEST_certPolicyThree,
  42. rfc7229.id_TEST_certPolicyFour,
  43. rfc7229.id_TEST_certPolicyFive,
  44. rfc7229.id_TEST_certPolicySix,
  45. rfc7229.id_TEST_certPolicySeven,
  46. rfc7229.id_TEST_certPolicyEight,
  47. ]
  48. substrate = pem.readBase64fromText(self.pem_text)
  49. asn1Object, rest = der_decoder(
  50. substrate, asn1Spec=self.asn1Spec)
  51. self.assertFalse(rest)
  52. self.assertTrue(asn1Object.prettyPrint())
  53. self.assertEqual(substrate, der_encoder(asn1Object))
  54. count = 0
  55. for extn in asn1Object['tbsCertificate']['extensions']:
  56. if extn['extnID'] in rfc5280.certificateExtensionsMap.keys():
  57. s = extn['extnValue']
  58. ev, rest = der_decoder(
  59. s, rfc5280.certificateExtensionsMap[extn['extnID']])
  60. self.assertFalse(rest)
  61. self.assertTrue(ev.prettyPrint())
  62. self.assertEqual(s, der_encoder(ev))
  63. if extn['extnID'] == rfc5280.id_ce_certificatePolicies:
  64. for pol in ev:
  65. if pol['policyIdentifier'] in test_oids:
  66. count += 1
  67. if extn['extnID'] == rfc5280.id_ce_policyMappings:
  68. for pmap in ev:
  69. if pmap['issuerDomainPolicy'] in test_oids:
  70. count += 1
  71. if pmap['subjectDomainPolicy'] in test_oids:
  72. count += 1
  73. self.assertEqual(6, count)
  74. suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__])
  75. if __name__ == '__main__':
  76. result = unittest.TextTestRunner(verbosity=2).run(suite)
  77. sys.exit(not result.wasSuccessful())