test_rfc4043.py 4.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118
  1. #
  2. # This file is part of pyasn1-modules software.
  3. #
  4. # Created by Russ Housley
  5. # Copyright (c) 2019, Vigil Security, LLC
  6. # License: http://snmplabs.com/pyasn1/license.html
  7. #
  8. import sys
  9. import unittest
  10. from pyasn1.codec.der.decoder import decode as der_decoder
  11. from pyasn1.codec.der.encoder import encode as der_encoder
  12. from pyasn1.type import univ
  13. from pyasn1_modules import pem
  14. from pyasn1_modules import rfc5280
  15. from pyasn1_modules import rfc4043
  16. class PermIdCertTestCase(unittest.TestCase):
  17. cert_pem_text = """\
  18. MIIDDTCCApOgAwIBAgIJAKWzVCgbsG5HMAoGCCqGSM49BAMDMD8xCzAJBgNVBAYT
  19. AlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwIQm9n
  20. dXMgQ0EwHhcNMTkxMTEwMDA0MDIyWhcNMjAxMTA5MDA0MDIyWjBNMQswCQYDVQQG
  21. EwJVUzELMAkGA1UECBMCVkExEDAOBgNVBAcTB0hlcm5kb24xEDAOBgNVBAoTB0V4
  22. YW1wbGUxDTALBgNVBAMTBEdhaWwwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAQBoktg
  23. /68xL+uEQaWBoHyOjw8EMLeMEng3R2H7yiEzTGoaMJgPOKvSfzB2P0paHYPL+B5y
  24. Gc0CK5EHRujMl9ljH+Wydpk57rKBLo1ZzpWUS6anLGIkWs1sOakcgGGr7hGjggFL
  25. MIIBRzAdBgNVHQ4EFgQU1pCNZuMzfEaJ9GGhH7RKy6Mvz+cwbwYDVR0jBGgwZoAU
  26. 8jXbNATapVXyvWkDmbBi7OIVCMGhQ6RBMD8xCzAJBgNVBAYTAlVTMQswCQYDVQQI
  27. DAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwIQm9ndXMgQ0GCCQDokdYG
  28. kU/O8jAPBgNVHRMBAf8EBTADAQH/MAsGA1UdDwQEAwIBhjBCBglghkgBhvhCAQ0E
  29. NRYzVGhpcyBjZXJ0aWZpY2F0ZSBjYW5ub3QgYmUgdHJ1c3RlZCBmb3IgYW55IHB1
  30. cnBvc2UuMFMGA1UdEQRMMEqgNgYIKwYBBQUHCAOgKjAoDBs4MjYyMDgtNDE3MDI4
  31. LTU0ODE5NS0yMTUyMzMGCSsGAQQBgaxgMIEQZ2FpbEBleGFtcGxlLmNvbTAKBggq
  32. hkjOPQQDAwNoADBlAjBT+36Y/LPaGSu+61P7kR97M8jAjtH5DtUwrWR02ChshvYJ
  33. x0bpZq3PJaO0WlBgFicCMQCf+67wSvjxxtjI/OAg4t8NQIJW1LcehSXizlPDc772
  34. /FC5OiUAxO+iFaSVMeDFsCo=
  35. """
  36. def setUp(self):
  37. self.asn1Spec = rfc5280.Certificate()
  38. def testDerCodec(self):
  39. substrate = pem.readBase64fromText(self.cert_pem_text)
  40. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  41. self.assertFalse(rest)
  42. self.assertTrue(asn1Object.prettyPrint())
  43. self.assertEqual(substrate, der_encoder(asn1Object))
  44. perm_id_oid = rfc4043.id_on_permanentIdentifier
  45. assigner_oid = univ.ObjectIdentifier('1.3.6.1.4.1.22112.48')
  46. permanent_identifier_found = False
  47. for extn in asn1Object['tbsCertificate']['extensions']:
  48. if extn['extnID'] == rfc5280.id_ce_subjectAltName:
  49. extnValue, rest = der_decoder(
  50. extn['extnValue'], asn1Spec=rfc5280.SubjectAltName())
  51. self.assertFalse(rest)
  52. self.assertTrue(extnValue.prettyPrint())
  53. self.assertEqual(extn['extnValue'], der_encoder(extnValue))
  54. for gn in extnValue:
  55. if gn['otherName'].hasValue():
  56. self.assertEqual(perm_id_oid, gn['otherName']['type-id'])
  57. onValue, rest = der_decoder(
  58. gn['otherName']['value'],
  59. asn1Spec=rfc4043.PermanentIdentifier())
  60. self.assertFalse(rest)
  61. self.assertTrue(onValue.prettyPrint())
  62. self.assertEqual(gn['otherName']['value'], der_encoder(onValue))
  63. self.assertEqual(assigner_oid, onValue['assigner'])
  64. permanent_identifier_found = True
  65. self.assertTrue(permanent_identifier_found)
  66. def testOpenTypes(self):
  67. substrate = pem.readBase64fromText(self.cert_pem_text)
  68. asn1Object, rest = der_decoder(
  69. substrate, asn1Spec=self.asn1Spec, decodeOpenTypes=True)
  70. self.assertFalse(rest)
  71. self.assertTrue(asn1Object.prettyPrint())
  72. self.assertEqual(substrate, der_encoder(asn1Object))
  73. perm_id_oid = rfc4043.id_on_permanentIdentifier
  74. assigner_oid = univ.ObjectIdentifier('1.3.6.1.4.1.22112.48')
  75. permanent_identifier_found = False
  76. for extn in asn1Object['tbsCertificate']['extensions']:
  77. if extn['extnID'] == rfc5280.id_ce_subjectAltName:
  78. extnValue, rest = der_decoder(
  79. extn['extnValue'], asn1Spec=rfc5280.SubjectAltName(),
  80. decodeOpenTypes=True)
  81. self.assertFalse(rest)
  82. self.assertTrue(extnValue.prettyPrint())
  83. self.assertEqual(extn['extnValue'], der_encoder(extnValue))
  84. for gn in extnValue:
  85. if gn['otherName'].hasValue():
  86. on = gn['otherName']
  87. self.assertEqual(perm_id_oid, on['type-id'])
  88. self.assertEqual(assigner_oid, on['value']['assigner'])
  89. permanent_identifier_found = True
  90. self.assertTrue(permanent_identifier_found)
  91. suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__])
  92. if __name__ == '__main__':
  93. result = unittest.TextTestRunner(verbosity=2).run(suite)
  94. sys.exit(not result.wasSuccessful())