test_rfc7508.py 5.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134
  1. #
  2. # This file is part of pyasn1-modules software.
  3. #
  4. # Created by Russ Housley
  5. # Copyright (c) 2019, Vigil Security, LLC
  6. # License: http://snmplabs.com/pyasn1/license.html
  7. #
  8. import sys
  9. import unittest
  10. from pyasn1.codec.der.decoder import decode as der_decoder
  11. from pyasn1.codec.der.encoder import encode as der_encoder
  12. from pyasn1_modules import pem
  13. from pyasn1_modules import rfc5652
  14. from pyasn1_modules import rfc7508
  15. class SignedMessageTestCase(unittest.TestCase):
  16. signed_message_pem_text = """\
  17. MIIE/AYJKoZIhvcNAQcCoIIE7TCCBOkCAQExDTALBglghkgBZQMEAgIwUQYJKoZI
  18. hvcNAQcBoEQEQkNvbnRlbnQtVHlwZTogdGV4dC9wbGFpbg0KDQpXYXRzb24sIGNv
  19. bWUgaGVyZSAtIEkgd2FudCB0byBzZWUgeW91LqCCAnwwggJ4MIIB/qADAgECAgkA
  20. pbNUKBuwbjswCgYIKoZIzj0EAwMwPzELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAlZB
  21. MRAwDgYDVQQHDAdIZXJuZG9uMREwDwYDVQQKDAhCb2d1cyBDQTAeFw0xOTA1Mjkx
  22. NDQ1NDFaFw0yMDA1MjgxNDQ1NDFaMHAxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJW
  23. QTEQMA4GA1UEBxMHSGVybmRvbjEQMA4GA1UEChMHRXhhbXBsZTEOMAwGA1UEAxMF
  24. QWxpY2UxIDAeBgkqhkiG9w0BCQEWEWFsaWNlQGV4YW1wbGUuY29tMHYwEAYHKoZI
  25. zj0CAQYFK4EEACIDYgAE+M2fBy/sRA6V1pKFqecRTE8+LuAHtZxes1wmJZrBBg+b
  26. z7uYZfYQxI3dVB0YCSD6Mt3yXFlnmfBRwoqyArbjIBYrDbHBv2k8Csg2DhQ7qs/w
  27. to8hMKoFgkcscqIbiV7Zo4GUMIGRMAsGA1UdDwQEAwIHgDBCBglghkgBhvhCAQ0E
  28. NRYzVGhpcyBjZXJ0aWZpY2F0ZSBjYW5ub3QgYmUgdHJ1c3RlZCBmb3IgYW55IHB1
  29. cnBvc2UuMB0GA1UdDgQWBBTEuloOPnrjPIGw9AKqaLsW4JYONTAfBgNVHSMEGDAW
  30. gBTyNds0BNqlVfK9aQOZsGLs4hUIwTAKBggqhkjOPQQDAwNoADBlAjBjuR/RNbgL
  31. 3kRhmn+PJTeKaL9sh/oQgHOYTgLmSnv3+NDCkhfKuMNoo/tHrkmihYgCMQC94Mae
  32. rDIrQpi0IDh+v0QSAv9rMife8tClafXWtDwwL8MS7oAh0ymT446Uizxx3PUxggIA
  33. MIIB/AIBATBMMD8xCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwH
  34. SGVybmRvbjERMA8GA1UECgwIQm9ndXMgQ0ECCQCls1QoG7BuOzALBglghkgBZQME
  35. AgKgggElMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8X
  36. DTE5MDUyOTE4MjMxOVowKAYJKoZIhvcNAQk0MRswGTALBglghkgBZQMEAgKhCgYI
  37. KoZIzj0EAwMwMQYLKoZIhvcNAQkQAjcxIjEgCgEBMBswGRoERnJvbQwRYWxpY2VA
  38. ZXhhbXBsZS5jb20wPwYJKoZIhvcNAQkEMTIEMLbkIqT9gmce1Peqxm1E9OiwuY1R
  39. WHHGVufwmjb6XKzj4goQ5tryN5uJN9NM+ZkmbDBNBgsqhkiG9w0BCRACATE+MDwE
  40. IMdPIQ9kJ1cI9Q6HkRCzbXWdD331uAUCL3MMFXP4KFOjgAEBMBUwE4ERYWxpY2VA
  41. ZXhhbXBsZS5jb20wCgYIKoZIzj0EAwMEZzBlAjEAuZ8SebvwMRvLPn9+s3VHFUNU
  42. bEtkkWCao1uNm5TOzphK0NbxzOsD854aC5ReKPSDAjAm1U0siLQw5p4qzGwyxDw9
  43. 5AI5J8Mvy+icNubmfsd4ofvxdaECdhr4rvsSMwbOsFk=
  44. """
  45. def setUp(self):
  46. self.asn1Spec = rfc5652.ContentInfo()
  47. def testDerCodec(self):
  48. substrate = pem.readBase64fromText(self.signed_message_pem_text)
  49. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  50. self.assertFalse(rest)
  51. self.assertTrue(asn1Object.prettyPrint())
  52. self.assertEqual(substrate, der_encoder(asn1Object))
  53. secure_header_field_attr_found = False
  54. self.assertEqual(rfc5652.id_signedData, asn1Object['contentType'])
  55. sd, rest = der_decoder(
  56. asn1Object['content'], asn1Spec=rfc5652.SignedData())
  57. for sa in sd['signerInfos'][0]['signedAttrs']:
  58. sat = sa['attrType']
  59. sav0 = sa['attrValues'][0]
  60. if sat == rfc7508.id_aa_secureHeaderFieldsIdentifier:
  61. self.assertIn(sat, rfc5652.cmsAttributesMap)
  62. sav, rest = der_decoder(
  63. sav0, asn1Spec=rfc5652.cmsAttributesMap[sat])
  64. self.assertFalse(rest)
  65. self.assertTrue(sav.prettyPrint())
  66. self.assertEqual(sav0, der_encoder(sav))
  67. from_field = rfc7508.HeaderFieldName('From')
  68. alice_email = rfc7508.HeaderFieldValue('alice@example.com')
  69. for shf in sav['secHeaderFields']:
  70. if shf['field-Name'] == from_field:
  71. self.assertEqual(alice_email, shf['field-Value'])
  72. secure_header_field_attr_found = True
  73. self.assertTrue(secure_header_field_attr_found)
  74. def testOpenTypes(self):
  75. substrate = pem.readBase64fromText(self.signed_message_pem_text)
  76. asn1Object, rest = der_decoder(
  77. substrate, asn1Spec=self.asn1Spec, decodeOpenTypes=True)
  78. self.assertFalse(rest)
  79. self.assertTrue(asn1Object.prettyPrint())
  80. self.assertEqual(substrate, der_encoder(asn1Object))
  81. self.assertIn(asn1Object['contentType'], rfc5652.cmsContentTypesMap)
  82. self.assertEqual(asn1Object['contentType'], rfc5652.id_signedData)
  83. sd = asn1Object['content']
  84. self.assertEqual(
  85. rfc5652.CMSVersion().subtype(value='v1'), sd['version'])
  86. ect = sd['encapContentInfo']['eContentType']
  87. self.assertIn(ect, rfc5652.cmsContentTypesMap)
  88. self.assertEqual(rfc5652.id_data, ect)
  89. for sa in sd['signerInfos'][0]['signedAttrs']:
  90. if sa['attrType'] == rfc7508.id_aa_secureHeaderFieldsIdentifier:
  91. self.assertIn(sa['attrType'], rfc5652.cmsAttributesMap)
  92. secure_header_field_attr_found = False
  93. for sa in sd['signerInfos'][0]['signedAttrs']:
  94. if sa['attrType'] == rfc7508.id_aa_secureHeaderFieldsIdentifier:
  95. self.assertIn(sa['attrType'], rfc5652.cmsAttributesMap)
  96. from_field = rfc7508.HeaderFieldName('From')
  97. alice_email = rfc7508.HeaderFieldValue('alice@example.com')
  98. for shf in sa['attrValues'][0]['secHeaderFields']:
  99. if shf['field-Name'] == from_field:
  100. self.assertEqual(alice_email, shf['field-Value'])
  101. secure_header_field_attr_found = True
  102. self.assertTrue(secure_header_field_attr_found)
  103. suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__])
  104. if __name__ == '__main__':
  105. result = unittest.TextTestRunner(verbosity=2).run(suite)
  106. sys.exit(not result.wasSuccessful())