test_rfc5035.py 8.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192
  1. #
  2. # This file is part of pyasn1-modules software.
  3. #
  4. # Created by Russ Housley
  5. # Copyright (c) 2019, Vigil Security, LLC
  6. # License: http://snmplabs.com/pyasn1/license.html
  7. #
  8. import sys
  9. import unittest
  10. from pyasn1.codec.der.decoder import decode as der_decoder
  11. from pyasn1.codec.der.encoder import encode as der_encoder
  12. from pyasn1_modules import pem
  13. from pyasn1_modules import rfc5652
  14. from pyasn1_modules import rfc5035
  15. class SignedMessageTestCase(unittest.TestCase):
  16. signed_message_pem_text = """\
  17. MIIFzAYJKoZIhvcNAQcCoIIFvTCCBbkCAQExDTALBglghkgBZQMEAgIwUQYJKoZI
  18. hvcNAQcBoEQEQkNvbnRlbnQtVHlwZTogdGV4dC9wbGFpbg0KDQpXYXRzb24sIGNv
  19. bWUgaGVyZSAtIEkgd2FudCB0byBzZWUgeW91LqCCAnwwggJ4MIIB/qADAgECAgkA
  20. pbNUKBuwbjswCgYIKoZIzj0EAwMwPzELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAlZB
  21. MRAwDgYDVQQHDAdIZXJuZG9uMREwDwYDVQQKDAhCb2d1cyBDQTAeFw0xOTA1Mjkx
  22. NDQ1NDFaFw0yMDA1MjgxNDQ1NDFaMHAxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJW
  23. QTEQMA4GA1UEBxMHSGVybmRvbjEQMA4GA1UEChMHRXhhbXBsZTEOMAwGA1UEAxMF
  24. QWxpY2UxIDAeBgkqhkiG9w0BCQEWEWFsaWNlQGV4YW1wbGUuY29tMHYwEAYHKoZI
  25. zj0CAQYFK4EEACIDYgAE+M2fBy/sRA6V1pKFqecRTE8+LuAHtZxes1wmJZrBBg+b
  26. z7uYZfYQxI3dVB0YCSD6Mt3yXFlnmfBRwoqyArbjIBYrDbHBv2k8Csg2DhQ7qs/w
  27. to8hMKoFgkcscqIbiV7Zo4GUMIGRMAsGA1UdDwQEAwIHgDBCBglghkgBhvhCAQ0E
  28. NRYzVGhpcyBjZXJ0aWZpY2F0ZSBjYW5ub3QgYmUgdHJ1c3RlZCBmb3IgYW55IHB1
  29. cnBvc2UuMB0GA1UdDgQWBBTEuloOPnrjPIGw9AKqaLsW4JYONTAfBgNVHSMEGDAW
  30. gBTyNds0BNqlVfK9aQOZsGLs4hUIwTAKBggqhkjOPQQDAwNoADBlAjBjuR/RNbgL
  31. 3kRhmn+PJTeKaL9sh/oQgHOYTgLmSnv3+NDCkhfKuMNoo/tHrkmihYgCMQC94Mae
  32. rDIrQpi0IDh+v0QSAv9rMife8tClafXWtDwwL8MS7oAh0ymT446Uizxx3PUxggLQ
  33. MIICzAIBATBMMD8xCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwH
  34. SGVybmRvbjERMA8GA1UECgwIQm9ndXMgQ0ECCQCls1QoG7BuOzALBglghkgBZQME
  35. AgKgggH1MBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8X
  36. DTE5MDUyOTE4MjMxOVowJQYLKoZIhvcNAQkQAgcxFgQUAbWZQYhLO5wtUgsOCGtT
  37. 4V3aNhUwLwYLKoZIhvcNAQkQAgQxIDAeDBFXYXRzb24sIGNvbWUgaGVyZQYJKoZI
  38. hvcNAQcBMDUGCyqGSIb3DQEJEAICMSYxJAIBAQYKKwYBBAGBrGABARMTQm9hZ3Vz
  39. IFByaXZhY3kgTWFyazA/BgkqhkiG9w0BCQQxMgQwtuQipP2CZx7U96rGbUT06LC5
  40. jVFYccZW5/CaNvpcrOPiChDm2vI3m4k300z5mSZsME0GCyqGSIb3DQEJEAIBMT4w
  41. PAQgx08hD2QnVwj1DoeRELNtdZ0PffW4BQIvcwwVc/goU6OAAQEwFTATgRFhbGlj
  42. ZUBleGFtcGxlLmNvbTCBmwYLKoZIhvcNAQkQAi8xgYswgYgwdjB0BCACcp04gyM2
  43. dTDg+0ydCwlucr6Mg8Wd3J3c9V+iLHsnZzBQMEOkQTA/MQswCQYDVQQGEwJVUzEL
  44. MAkGA1UECAwCVkExEDAOBgNVBAcMB0hlcm5kb24xETAPBgNVBAoMCEJvZ3VzIENB
  45. AgkApbNUKBuwbjswDjAMBgorBgEEAYGsYAEBMAoGCCqGSM49BAMDBGcwZQIxAO3K
  46. D9YjFTKE3p383VVw/ol79WTVoMea4H1+7xn+3E1XO4oyb7qwQz0KmsGfdqWptgIw
  47. T9yMtRLN5ZDU14y+Phzq9NKpSw/x5KyXoUKjCMc3Ru6dIW+CgcRQees+dhnvuD5U
  48. """
  49. def setUp(self):
  50. self.asn1Spec = rfc5652.ContentInfo()
  51. def testDerCodec(self):
  52. substrate = pem.readBase64fromText(self.signed_message_pem_text)
  53. asn1Object, rest = der_decoder (substrate, asn1Spec=self.asn1Spec)
  54. self.assertFalse(rest)
  55. self.assertTrue(asn1Object.prettyPrint())
  56. self.assertEqual(substrate, der_encoder(asn1Object))
  57. self.assertEqual(rfc5652.id_signedData, asn1Object['contentType'])
  58. sd, rest = der_decoder(asn1Object['content'], asn1Spec=rfc5652.SignedData())
  59. self.assertFalse(rest)
  60. self.assertTrue(sd.prettyPrint())
  61. self.assertEqual(asn1Object['content'], der_encoder(sd))
  62. for sa in sd['signerInfos'][0]['signedAttrs']:
  63. sat = sa['attrType']
  64. sav0 = sa['attrValues'][0]
  65. if sat in rfc5652.cmsAttributesMap.keys():
  66. sav, rest = der_decoder(sav0, asn1Spec=rfc5652.cmsAttributesMap[sat])
  67. self.assertFalse(rest)
  68. self.assertTrue(sav.prettyPrint())
  69. self.assertEqual(sav0, der_encoder(sav))
  70. class SignedReceiptTestCase(unittest.TestCase):
  71. signed_receipt_pem_text = """\
  72. MIIE3gYJKoZIhvcNAQcCoIIEzzCCBMsCAQMxDTALBglghkgBZQMEAgEwga4GCyqGSIb3DQEJ
  73. EAEBoIGeBIGbMIGYAgEBBgkqhkiG9w0BBwEEIMdPIQ9kJ1cI9Q6HkRCzbXWdD331uAUCL3MM
  74. FXP4KFOjBGYwZAIwOLV5WCbYjy5HLHE69IqXQQHVDJQzmo18WwkFrEYH3EMsvpXEIGqsFTFN
  75. 6NV4VBe9AjA5fGOCP5IhI32YqmGfs+zDlqZyb2xSX6Gr/IfCIm0angfOI39g7lAZDyivjh5H
  76. /oSgggJ3MIICczCCAfqgAwIBAgIJAKWzVCgbsG48MAoGCCqGSM49BAMDMD8xCzAJBgNVBAYT
  77. AlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwHSGVybmRvbjERMA8GA1UECgwIQm9ndXMgQ0Ew
  78. HhcNMTkwNTI5MTkyMDEzWhcNMjAwNTI4MTkyMDEzWjBsMQswCQYDVQQGEwJVUzELMAkGA1UE
  79. CBMCVkExEDAOBgNVBAcTB0hlcm5kb24xEDAOBgNVBAoTB0V4YW1wbGUxDDAKBgNVBAMTA0Jv
  80. YjEeMBwGCSqGSIb3DQEJARYPYm9iQGV4YW1wbGUuY29tMHYwEAYHKoZIzj0CAQYFK4EEACID
  81. YgAEMaRiVS8WvN8Ycmpfq75jBbOMUukNfXAg6AL0JJBXtIFAuIJcZVlkLn/xbywkcMLHK/O+
  82. w9RWUQa2Cjw+h8b/1Cl+gIpqLtE558bD5PfM2aYpJ/YE6yZ9nBfTQs7z1TH5o4GUMIGRMAsG
  83. A1UdDwQEAwIHgDBCBglghkgBhvhCAQ0ENRYzVGhpcyBjZXJ0aWZpY2F0ZSBjYW5ub3QgYmUg
  84. dHJ1c3RlZCBmb3IgYW55IHB1cnBvc2UuMB0GA1UdDgQWBBTKa2Zy3iybV3+YjuLDKtNmjsIa
  85. pTAfBgNVHSMEGDAWgBTyNds0BNqlVfK9aQOZsGLs4hUIwTAKBggqhkjOPQQDAwNnADBkAjAV
  86. boS6OfEYQomLDi2RUkd71hzwwiQZztbxNbosahIzjR8ZQaHhjdjJlrP/T6aXBwsCMDfRweYz
  87. 3Ce4E4wPfoqQnvqpM7ZlfhstjQQGOsWAtIIfqW/l+TgCO8ux3XLV6fj36zGCAYkwggGFAgEB
  88. MEwwPzELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAlZBMRAwDgYDVQQHDAdIZXJuZG9uMREwDwYD
  89. VQQKDAhCb2d1cyBDQQIJAKWzVCgbsG48MAsGCWCGSAFlAwQCAaCBrjAaBgkqhkiG9w0BCQMx
  90. DQYLKoZIhvcNAQkQAQEwHAYJKoZIhvcNAQkFMQ8XDTE5MDUyOTE5MzU1NVowLwYJKoZIhvcN
  91. AQkEMSIEIGb9Hm2kCnM0CYNpZU4Uj7dN0AzOieIn9sDqZMcIcZrEMEEGCyqGSIb3DQEJEAIF
  92. MTIEMBZzeHVja7fQ62ywyh8rtKzBP1WJooMdZ+8c6pRqfIESYIU5bQnH99OPA51QCwdOdjAK
  93. BggqhkjOPQQDAgRoMGYCMQDZiT22xgab6RFMAPvN4fhWwzx017EzttD4VaYrpbolropBdPJ6
  94. jIXiZQgCwxbGTCwCMQClaQ9K+L5LTeuW50ZKSIbmBZQ5dxjtnK3OlS7hYRi6U0JKZmWbbuS8
  95. vFIgX7eIkd8=
  96. """
  97. def setUp(self):
  98. self.asn1Spec = rfc5652.ContentInfo()
  99. def testDerCodec(self):
  100. substrate = pem.readBase64fromText(self.signed_receipt_pem_text)
  101. asn1Object, rest = der_decoder(substrate, asn1Spec=self.asn1Spec)
  102. self.assertFalse(rest)
  103. self.assertTrue(asn1Object.prettyPrint())
  104. self.assertEqual(substrate, der_encoder(asn1Object))
  105. self.assertEqual(rfc5652.id_signedData, asn1Object['contentType'])
  106. sd, rest = der_decoder(
  107. asn1Object['content'], asn1Spec=rfc5652.SignedData())
  108. self.assertFalse(rest)
  109. self.assertTrue(sd.prettyPrint())
  110. self.assertEqual(asn1Object['content'], der_encoder(sd))
  111. self.assertEqual(
  112. rfc5035.id_ct_receipt, sd['encapContentInfo']['eContentType'])
  113. receipt, rest = der_decoder(
  114. sd['encapContentInfo']['eContent'], asn1Spec=rfc5035.Receipt())
  115. self.assertFalse(rest)
  116. self.assertTrue(receipt.prettyPrint())
  117. self.assertEqual(
  118. sd['encapContentInfo']['eContent'], der_encoder(receipt))
  119. for sa in sd['signerInfos'][0]['signedAttrs']:
  120. sat = sa['attrType']
  121. sav0 = sa['attrValues'][0]
  122. if sat in rfc5652.cmsAttributesMap.keys():
  123. sav, rest = der_decoder(
  124. sav0, asn1Spec=rfc5652.cmsAttributesMap[sat])
  125. self.assertFalse(rest)
  126. self.assertTrue(sav.prettyPrint())
  127. self.assertEqual(sav0, der_encoder(sav))
  128. def testOpenTypes(self):
  129. substrate = pem.readBase64fromText(self.signed_receipt_pem_text)
  130. asn1Object, rest = der_decoder(
  131. substrate, asn1Spec=self.asn1Spec, decodeOpenTypes=True)
  132. self.assertFalse(rest)
  133. self.assertTrue(asn1Object.prettyPrint())
  134. self.assertEqual(substrate, der_encoder(asn1Object))
  135. self.assertIn(asn1Object['contentType'], rfc5652.cmsContentTypesMap)
  136. self.assertEqual(rfc5652.id_signedData, asn1Object['contentType'])
  137. sd = asn1Object['content']
  138. self.assertEqual(
  139. rfc5652.CMSVersion().subtype(value='v3'), sd['version'])
  140. self.assertIn(
  141. sd['encapContentInfo']['eContentType'], rfc5652.cmsContentTypesMap)
  142. self.assertEqual(
  143. rfc5035.id_ct_receipt, sd['encapContentInfo']['eContentType'])
  144. for sa in sd['signerInfos'][0]['signedAttrs']:
  145. self.assertIn(sa['attrType'], rfc5652.cmsAttributesMap)
  146. if sa['attrType'] == rfc5035.id_aa_msgSigDigest:
  147. self.assertIn(
  148. '0x167378', sa['attrValues'][0].prettyPrint()[:10])
  149. # Since receipt is inside an OCTET STRING, decodeOpenTypes=True cannot
  150. # automatically decode it
  151. receipt, rest = der_decoder(
  152. sd['encapContentInfo']['eContent'],
  153. asn1Spec=rfc5652.cmsContentTypesMap[sd['encapContentInfo']['eContentType']])
  154. self.assertEqual(1, receipt['version'])
  155. suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__])
  156. if __name__ == '__main__':
  157. result = unittest.TextTestRunner(verbosity=2).run(suite)
  158. sys.exit(not result.wasSuccessful())