test_rfc6960.py 6.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176
  1. #
  2. # This file is part of pyasn1-modules software.
  3. #
  4. # Created by Russ Housley
  5. # Copyright (c) 2019, Vigil Security, LLC
  6. # License: http://snmplabs.com/pyasn1/license.html
  7. #
  8. import sys
  9. import unittest
  10. from pyasn1.codec.der.decoder import decode as der_decoder
  11. from pyasn1.codec.der.encoder import encode as der_encoder
  12. from pyasn1.type import univ
  13. from pyasn1_modules import pem
  14. from pyasn1_modules import rfc5280
  15. from pyasn1_modules import rfc4055
  16. from pyasn1_modules import rfc6960
  17. class OCSPRequestTestCase(unittest.TestCase):
  18. ocsp_req_pem_text = """\
  19. MGowaDBBMD8wPTAJBgUrDgMCGgUABBS3ZrMV9C5Dko03aH13cEZeppg3wgQUkqR1LKSevoFE63n8
  20. isWVpesQdXMCBDXe9M+iIzAhMB8GCSsGAQUFBzABAgQSBBBjdJOiIW9EKJGELNNf/rdA
  21. """
  22. def setUp(self):
  23. self.asn1Spec = rfc6960.OCSPRequest()
  24. def testDerCodec(self):
  25. substrate = pem.readBase64fromText(self.ocsp_req_pem_text)
  26. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  27. self.assertFalse(rest)
  28. self.assertTrue(asn1Object.prettyPrint())
  29. self.assertEqual(substrate, der_encoder(asn1Object))
  30. self.assertEqual(0, asn1Object['tbsRequest']['version'])
  31. count = 0
  32. for extn in asn1Object['tbsRequest']['requestExtensions']:
  33. self.assertIn(extn['extnID'], rfc5280.certificateExtensionsMap)
  34. ev, rest = der_decoder(
  35. extn['extnValue'],
  36. asn1Spec=rfc5280.certificateExtensionsMap[extn['extnID']])
  37. self.assertFalse(rest)
  38. self.assertTrue(ev.prettyPrint())
  39. self.assertEqual(extn['extnValue'], der_encoder(ev))
  40. count += 1
  41. self.assertEqual(1, count)
  42. def testOpenTypes(self):
  43. substrate = pem.readBase64fromText(self.ocsp_req_pem_text)
  44. asn1Object, rest = der_decoder(
  45. substrate, asn1Spec=self.asn1Spec, decodeOpenTypes=True)
  46. self.assertFalse(rest)
  47. self.assertTrue(asn1Object.prettyPrint())
  48. self.assertEqual(substrate, der_encoder(asn1Object))
  49. self.assertEqual(0, asn1Object['tbsRequest']['version'])
  50. for req in asn1Object['tbsRequest']['requestList']:
  51. ha = req['reqCert']['hashAlgorithm']
  52. self.assertEqual(rfc4055.id_sha1, ha['algorithm'])
  53. self.assertEqual(univ.Null(""), ha['parameters'])
  54. class OCSPResponseTestCase(unittest.TestCase):
  55. ocsp_resp_pem_text = """\
  56. MIIEvQoBAKCCBLYwggSyBgkrBgEFBQcwAQEEggSjMIIEnzCCAQ+hgYAwfjELMAkGA1UEBhMCQVUx
  57. EzARBgNVBAgTClNvbWUtU3RhdGUxITAfBgNVBAoTGEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDEV
  58. MBMGA1UEAxMMc25tcGxhYnMuY29tMSAwHgYJKoZIhvcNAQkBFhFpbmZvQHNubXBsYWJzLmNvbRgP
  59. MjAxMjA0MTExNDA5MjJaMFQwUjA9MAkGBSsOAwIaBQAEFLdmsxX0LkOSjTdofXdwRl6mmDfCBBSS
  60. pHUspJ6+gUTrefyKxZWl6xB1cwIENd70z4IAGA8yMDEyMDQxMTE0MDkyMlqhIzAhMB8GCSsGAQUF
  61. BzABAgQSBBBjdJOiIW9EKJGELNNf/rdAMA0GCSqGSIb3DQEBBQUAA4GBADk7oRiCy4ew1u0N52QL
  62. RFpW+tdb0NfkV2Xyu+HChKiTThZPr9ZXalIgkJ1w3BAnzhbB0JX/zq7Pf8yEz/OrQ4GGH7HyD3Vg
  63. PkMu+J6I3A2An+bUQo99AmCbZ5/tSHtDYQMQt3iNbv1fk0yvDmh7UdKuXUNSyJdHeg27dMNy4k8A
  64. oIIC9TCCAvEwggLtMIICVqADAgECAgEBMA0GCSqGSIb3DQEBBQUAMH4xCzAJBgNVBAYTAkFVMRMw
  65. EQYDVQQIEwpTb21lLVN0YXRlMSEwHwYDVQQKExhJbnRlcm5ldCBXaWRnaXRzIFB0eSBMdGQxFTAT
  66. BgNVBAMTDHNubXBsYWJzLmNvbTEgMB4GCSqGSIb3DQEJARYRaW5mb0Bzbm1wbGFicy5jb20wHhcN
  67. MTIwNDExMTMyNTM1WhcNMTMwNDExMTMyNTM1WjB+MQswCQYDVQQGEwJBVTETMBEGA1UECBMKU29t
  68. ZS1TdGF0ZTEhMB8GA1UEChMYSW50ZXJuZXQgV2lkZ2l0cyBQdHkgTHRkMRUwEwYDVQQDEwxzbm1w
  69. bGFicy5jb20xIDAeBgkqhkiG9w0BCQEWEWluZm9Ac25tcGxhYnMuY29tMIGfMA0GCSqGSIb3DQEB
  70. AQUAA4GNADCBiQKBgQDDDU5HOnNV8I2CojxB8ilIWRHYQuaAjnjrETMOprouDHFXnwWqQo/I3m0b
  71. XYmocrh9kDefb+cgc7+eJKvAvBqrqXRnU38DmQU/zhypCftGGfP8xjuBZ1n23lR3hplN1yYA0J2X
  72. SgBaAg6e8OsKf1vcX8Es09rDo8mQpt4G2zR56wIDAQABo3sweTAJBgNVHRMEAjAAMCwGCWCGSAGG
  73. +EIBDQQfFh1PcGVuU1NMIEdlbmVyYXRlZCBDZXJ0aWZpY2F0ZTAdBgNVHQ4EFgQU8Ys2dpJFLMHl
  74. yY57D4BNmlqnEcYwHwYDVR0jBBgwFoAU8Ys2dpJFLMHlyY57D4BNmlqnEcYwDQYJKoZIhvcNAQEF
  75. BQADgYEAWR0uFJVlQId6hVpUbgXFTpywtNitNXFiYYkRRv77McSJqLCa/c1wnuLmqcFcuRUK0oN6
  76. 8ZJDP2HDDKe8MCZ8+sx+CF54eM8VCgN9uQ9XyE7x9XrXDd3Uw9RJVaWSIezkNKNeBE0lDM2jUjC4
  77. HAESdf7nebz1wtqAOXE1jWF/y8g=
  78. """
  79. def setUp(self):
  80. self.asn1Spec = rfc6960.OCSPResponse()
  81. def testDerCodec(self):
  82. substrate = pem.readBase64fromText(self.ocsp_resp_pem_text)
  83. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  84. self.assertFalse(rest)
  85. self.assertTrue(asn1Object.prettyPrint())
  86. self.assertEqual(substrate, der_encoder(asn1Object))
  87. self.assertEqual(0, asn1Object['responseStatus'])
  88. rb = asn1Object['responseBytes']
  89. self.assertIn(rb['responseType'], rfc6960.ocspResponseMap)
  90. resp, rest = der_decoder(
  91. rb['response'], asn1Spec=rfc6960.ocspResponseMap[rb['responseType']])
  92. self.assertFalse(rest)
  93. self.assertTrue(resp.prettyPrint())
  94. self.assertEqual(rb['response'], der_encoder(resp))
  95. self.assertEqual(0, resp['tbsResponseData']['version'])
  96. count = 0
  97. for extn in resp['tbsResponseData']['responseExtensions']:
  98. self.assertIn(extn['extnID'], rfc5280.certificateExtensionsMap)
  99. ev, rest = der_decoder(
  100. extn['extnValue'],
  101. asn1Spec=rfc5280.certificateExtensionsMap[extn['extnID']])
  102. self.assertFalse(rest)
  103. self.assertTrue(ev.prettyPrint())
  104. self.assertEqual(extn['extnValue'], der_encoder(ev))
  105. count += 1
  106. self.assertEqual(1, count)
  107. def testOpenTypes(self):
  108. substrate = pem.readBase64fromText(self.ocsp_resp_pem_text)
  109. asn1Object, rest = der_decoder(
  110. substrate, asn1Spec=self.asn1Spec, decodeOpenTypes=True)
  111. self.assertFalse(rest)
  112. self.assertTrue(asn1Object.prettyPrint())
  113. self.assertEqual(substrate, der_encoder(asn1Object))
  114. self.assertEqual(0, asn1Object['responseStatus'])
  115. rb = asn1Object['responseBytes']
  116. self.assertIn(rb['responseType'], rfc6960.ocspResponseMap)
  117. resp, rest = der_decoder(
  118. rb['response'],
  119. asn1Spec=rfc6960.ocspResponseMap[rb['responseType']],
  120. decodeOpenTypes=True)
  121. self.assertFalse(rest)
  122. self.assertTrue(resp.prettyPrint())
  123. self.assertEqual(rb['response'], der_encoder(resp))
  124. self.assertEqual(0, resp['tbsResponseData']['version'])
  125. for rdn in resp['tbsResponseData']['responderID']['byName']['rdnSequence']:
  126. for attr in rdn:
  127. if attr['type'] == rfc5280.id_emailAddress:
  128. self.assertEqual('info@snmplabs.com', attr['value'])
  129. for r in resp['tbsResponseData']['responses']:
  130. ha = r['certID']['hashAlgorithm']
  131. self.assertEqual(rfc4055.id_sha1, ha['algorithm'])
  132. self.assertEqual(univ.Null(""), ha['parameters'])
  133. suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__])
  134. if __name__ == '__main__':
  135. result = unittest.TextTestRunner(verbosity=2).run(suite)
  136. sys.exit(not result.wasSuccessful())