test_rfc4683.py 4.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122
  1. #
  2. # This file is part of pyasn1-modules software.
  3. #
  4. # Created by Russ Housley
  5. # Copyright (c) 2019, Vigil Security, LLC
  6. # License: http://snmplabs.com/pyasn1/license.html
  7. #
  8. import sys
  9. import unittest
  10. from pyasn1.codec.der.decoder import decode as der_decoder
  11. from pyasn1.codec.der.encoder import encode as der_encoder
  12. from pyasn1.type import univ
  13. from pyasn1_modules import pem
  14. from pyasn1_modules import rfc5280
  15. from pyasn1_modules import rfc4683
  16. class SIMCertificateTestCase(unittest.TestCase):
  17. cert_pem_text = """\
  18. MIIDOzCCAsCgAwIBAgIJAKWzVCgbsG5KMAoGCCqGSM49BAMDMD8xCzAJBgNVBAYT
  19. AlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwIQm9n
  20. dXMgQ0EwHhcNMTkxMjExMjIzODUwWhcNMjAxMjEwMjIzODUwWjBOMQswCQYDVQQG
  21. EwJVUzELMAkGA1UECBMCVkExEDAOBgNVBAcTB0hlcm5kb24xEDAOBgNVBAoTB0V4
  22. YW1wbGUxDjAMBgNVBAMTBUhlbnJ5MHYwEAYHKoZIzj0CAQYFK4EEACIDYgAEZj80
  23. YyLeDb0arJY8ZxBUMMxPEMT9+5WFVBCC1dPpUn25MmEpb82Dz1inv3xmG6sFKIHj
  24. achlvkNGDXTUzZ1DdCF0O7gU5Z+YctwczGQVSt/2Ox0NWTiHLDpbpyoTyK0Bo4IB
  25. dzCCAXMwHQYDVR0OBBYEFOjxtcL2ucMoTjS5MNKKpdKzXtz/MG8GA1UdIwRoMGaA
  26. FPI12zQE2qVV8r1pA5mwYuziFQjBoUOkQTA/MQswCQYDVQQGEwJVUzELMAkGA1UE
  27. CAwCVkExEDAOBgNVBAcMB0hlcm5kb24xETAPBgNVBAoMCEJvZ3VzIENBggkA6JHW
  28. BpFPzvIwDwYDVR0TAQH/BAUwAwEB/zALBgNVHQ8EBAMCAYYwQgYJYIZIAYb4QgEN
  29. BDUWM1RoaXMgY2VydGlmaWNhdGUgY2Fubm90IGJlIHRydXN0ZWQgZm9yIGFueSBw
  30. dXJwb3NlLjB/BgNVHREEeDB2oGEGCCsGAQUFBwgGoFUwUzANBglghkgBZQMEAgEF
  31. AAQgnrmI6yL2lM5kmfLVn28A8PVIVgE2S7HEFtfLExhg7HsEIOaAn/Pq8hb4qn/K
  32. imN3uyZrjAv3Uspg0VYEcetJdHSCgRFoZW5yeUBleGFtcGxlLmNvbTAKBggqhkjO
  33. PQQDAwNpADBmAjEAiWhD493OGnqfdit6SRdBjn3N6HVaMxyVO0Lfosjf9+9FDWad
  34. rYt3o64YQqGz9NTMAjEAmahE0EMiu/TyzRDidlG2SxmY2aHg9hQO0t38i1jInJyi
  35. 9LjB81zHEL6noTgBZsan
  36. """
  37. def setUp(self):
  38. self.asn1Spec = rfc5280.Certificate()
  39. def testDerCodec(self):
  40. substrate = pem.readBase64fromText(self.cert_pem_text)
  41. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  42. self.assertFalse(rest)
  43. self.assertTrue(asn1Object.prettyPrint())
  44. self.assertEqual(substrate, der_encoder(asn1Object))
  45. found_PEPSI = False
  46. for extn in asn1Object['tbsCertificate']['extensions']:
  47. if extn['extnID'] == rfc5280.id_ce_subjectAltName:
  48. extnValue, rest = der_decoder(
  49. extn['extnValue'], asn1Spec=rfc5280.SubjectAltName())
  50. self.assertFalse(rest)
  51. self.assertTrue(extnValue.prettyPrint())
  52. self.assertEqual(extn['extnValue'], der_encoder(extnValue))
  53. for gn in extnValue:
  54. if gn['otherName'].hasValue():
  55. gn_on = gn['otherName']
  56. if gn_on['type-id'] == rfc4683.id_on_SIM:
  57. self.assertIn(
  58. gn_on['type-id'], rfc5280.anotherNameMap)
  59. spec = rfc5280.anotherNameMap[gn_on['type-id']]
  60. on, rest = der_decoder(
  61. gn_on['value'], asn1Spec=spec)
  62. self.assertFalse(rest)
  63. self.assertTrue(on.prettyPrint())
  64. self.assertEqual(gn_on['value'], der_encoder(on))
  65. self.assertEqual(
  66. 'e6809ff3ea', on['pEPSI'].prettyPrint()[2:12])
  67. found_PEPSI = True
  68. self.assertTrue(found_PEPSI)
  69. def testOpenTypes(self):
  70. substrate = pem.readBase64fromText(self.cert_pem_text)
  71. asn1Object, rest = der_decoder(
  72. substrate, asn1Spec=self.asn1Spec, decodeOpenTypes=True)
  73. self.assertFalse(rest)
  74. self.assertTrue(asn1Object.prettyPrint())
  75. self.assertEqual(substrate, der_encoder(asn1Object))
  76. found_PEPSI = False
  77. for extn in asn1Object['tbsCertificate']['extensions']:
  78. if extn['extnID'] == rfc5280.id_ce_subjectAltName:
  79. extnValue, rest = der_decoder(
  80. extn['extnValue'],
  81. asn1Spec=rfc5280.SubjectAltName(),
  82. decodeOpenTypes=True)
  83. self.assertFalse(rest)
  84. self.assertTrue(extnValue.prettyPrint())
  85. self.assertEqual(extn['extnValue'], der_encoder(extnValue))
  86. for gn in extnValue:
  87. if gn['otherName'].hasValue():
  88. pepsi = gn['otherName']['value']['pEPSI']
  89. self.assertEqual(
  90. 'e6809ff3ea', pepsi.prettyPrint()[2:12])
  91. found_PEPSI = True
  92. self.assertTrue(found_PEPSI)
  93. suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__])
  94. if __name__ == '__main__':
  95. result = unittest.TextTestRunner(verbosity=2).run(suite)
  96. sys.exit(not result.wasSuccessful())