test_rfc3770.py 3.6 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394
  1. #
  2. # This file is part of pyasn1-modules software.
  3. #
  4. # Created by Russ Housley
  5. # Copyright (c) 2019, Vigil Security, LLC
  6. # License: http://snmplabs.com/pyasn1/license.html
  7. #
  8. import sys
  9. import unittest
  10. from pyasn1.codec.der.decoder import decode as der_decoder
  11. from pyasn1.codec.der.encoder import encode as der_encoder
  12. from pyasn1_modules import pem
  13. from pyasn1_modules import rfc5480
  14. from pyasn1_modules import rfc5280
  15. from pyasn1_modules import rfc3770
  16. class CertificateTestCase(unittest.TestCase):
  17. cert_pem_text = """\
  18. MIICqzCCAjCgAwIBAgIJAKWzVCgbsG4/MAoGCCqGSM49BAMDMD8xCzAJBgNVBAYT
  19. AlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwIQm9n
  20. dXMgQ0EwHhcNMTkwNzE5MTk0MjQ3WhcNMjAwNzE4MTk0MjQ3WjBjMQswCQYDVQQG
  21. EwJVUzELMAkGA1UECBMCVkExEDAOBgNVBAcTB0hlcm5kb24xGzAZBgNVBAoTElZp
  22. Z2lsIFNlY3VyaXR5IExMQzEYMBYGA1UEAxMPZWFwLmV4YW1wbGUuY29tMHYwEAYH
  23. KoZIzj0CAQYFK4EEACIDYgAEMMbnIp2BUbuyMgH9HhNHrh7VBy7ql2lBjGRSsefR
  24. Wa7+vCWs4uviW6On4eem5YoP9/UdO7DaIL+/J9/3DJHERI17oFxn+YWiE4JwXofy
  25. QwfSu3cncVNMqpiDjEkUGGvBo4HTMIHQMAsGA1UdDwQEAwIHgDBCBglghkgBhvhC
  26. AQ0ENRYzVGhpcyBjZXJ0aWZpY2F0ZSBjYW5ub3QgYmUgdHJ1c3RlZCBmb3IgYW55
  27. IHB1cnBvc2UuMB0GA1UdDgQWBBSDjPGr7M742rsE4oQGwBvGvllZ+zAfBgNVHSME
  28. GDAWgBTyNds0BNqlVfK9aQOZsGLs4hUIwTAeBggrBgEFBQcBDQQSMBAEB0V4YW1w
  29. bGUEBUJvZ3VzMB0GA1UdJQQWMBQGCCsGAQUFBwMOBggrBgEFBQcDDTAKBggqhkjO
  30. PQQDAwNpADBmAjEAmCPZnnlUQOKlcOIIOgFrRCkOqO0ESs+dobYwAc2rFCBtQyP7
  31. C3N00xkX8WZZpiAZAjEAi1Z5+nGbJg5eJTc8fwudutN/HNwJEIS6mHds9kfcy26x
  32. DAlVlhox680Jxy5J8Pkx
  33. """
  34. def setUp(self):
  35. self.asn1Spec = rfc5280.Certificate()
  36. def testDerCodec(self):
  37. substrate = pem.readBase64fromText(self.cert_pem_text)
  38. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  39. self.assertFalse(rest)
  40. self.assertTrue(asn1Object.prettyPrint())
  41. self.assertEqual(substrate, der_encoder(asn1Object))
  42. def testOpenTypes(self):
  43. substrate = pem.readBase64fromText(self.cert_pem_text)
  44. asn1Object, rest = der_decoder(
  45. substrate, asn1Spec=self.asn1Spec, decodeOpenTypes=True)
  46. self.assertFalse(rest)
  47. self.assertTrue(asn1Object.prettyPrint())
  48. self.assertEqual(substrate, der_encoder(asn1Object))
  49. sig_alg = asn1Object['tbsCertificate']['signature']
  50. self.assertEqual(rfc5480.ecdsa_with_SHA384, sig_alg['algorithm'])
  51. self.assertFalse(sig_alg['parameters'].hasValue())
  52. spki_alg = asn1Object['tbsCertificate']['subjectPublicKeyInfo']['algorithm']
  53. self.assertEqual(rfc5480.id_ecPublicKey, spki_alg['algorithm'])
  54. self.assertEqual(
  55. rfc5480.secp384r1, spki_alg['parameters']['namedCurve'])
  56. extn_list = []
  57. for extn in asn1Object['tbsCertificate']['extensions']:
  58. extn_list.append(extn['extnID'])
  59. if extn['extnID'] in rfc5280.certificateExtensionsMap.keys():
  60. extnValue, rest = der_decoder(
  61. extn['extnValue'],
  62. asn1Spec=rfc5280.certificateExtensionsMap[extn['extnID']])
  63. self.assertEqual(extn['extnValue'], der_encoder(extnValue))
  64. if extn['extnID'] == rfc3770.id_pe_wlanSSID:
  65. self.assertIn(b'Example', extnValue)
  66. if extn['extnID'] == rfc5280.id_ce_extKeyUsage:
  67. self.assertIn(rfc3770.id_kp_eapOverLAN, extnValue)
  68. self.assertIn(rfc3770.id_kp_eapOverPPP, extnValue)
  69. self.assertIn(rfc3770.id_pe_wlanSSID, extn_list)
  70. self.assertIn(rfc5280.id_ce_extKeyUsage, extn_list)
  71. suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__])
  72. if __name__ == '__main__':
  73. unittest.TextTestRunner(verbosity=2).run(suite)