test_rfc6211.py 4.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122
  1. #
  2. # This file is part of pyasn1-modules software.
  3. #
  4. # Created by Russ Housley
  5. # Copyright (c) 2019, Vigil Security, LLC
  6. # License: http://snmplabs.com/pyasn1/license.html
  7. #
  8. import sys
  9. import unittest
  10. from pyasn1.type import univ
  11. from pyasn1.codec.der.decoder import decode as der_decoder
  12. from pyasn1.codec.der.encoder import encode as der_encoder
  13. from pyasn1_modules import pem
  14. from pyasn1_modules import rfc5652
  15. from pyasn1_modules import rfc6211
  16. class SignedMessageTestCase(unittest.TestCase):
  17. signed_message_pem_text = """\
  18. MIIEyAYJKoZIhvcNAQcCoIIEuTCCBLUCAQExDTALBglghkgBZQMEAgIwUQYJKoZI
  19. hvcNAQcBoEQEQkNvbnRlbnQtVHlwZTogdGV4dC9wbGFpbg0KDQpXYXRzb24sIGNv
  20. bWUgaGVyZSAtIEkgd2FudCB0byBzZWUgeW91LqCCAnwwggJ4MIIB/qADAgECAgkA
  21. pbNUKBuwbjswCgYIKoZIzj0EAwMwPzELMAkGA1UEBhMCVVMxCzAJBgNVBAgMAlZB
  22. MRAwDgYDVQQHDAdIZXJuZG9uMREwDwYDVQQKDAhCb2d1cyBDQTAeFw0xOTA1Mjkx
  23. NDQ1NDFaFw0yMDA1MjgxNDQ1NDFaMHAxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJW
  24. QTEQMA4GA1UEBxMHSGVybmRvbjEQMA4GA1UEChMHRXhhbXBsZTEOMAwGA1UEAxMF
  25. QWxpY2UxIDAeBgkqhkiG9w0BCQEWEWFsaWNlQGV4YW1wbGUuY29tMHYwEAYHKoZI
  26. zj0CAQYFK4EEACIDYgAE+M2fBy/sRA6V1pKFqecRTE8+LuAHtZxes1wmJZrBBg+b
  27. z7uYZfYQxI3dVB0YCSD6Mt3yXFlnmfBRwoqyArbjIBYrDbHBv2k8Csg2DhQ7qs/w
  28. to8hMKoFgkcscqIbiV7Zo4GUMIGRMAsGA1UdDwQEAwIHgDBCBglghkgBhvhCAQ0E
  29. NRYzVGhpcyBjZXJ0aWZpY2F0ZSBjYW5ub3QgYmUgdHJ1c3RlZCBmb3IgYW55IHB1
  30. cnBvc2UuMB0GA1UdDgQWBBTEuloOPnrjPIGw9AKqaLsW4JYONTAfBgNVHSMEGDAW
  31. gBTyNds0BNqlVfK9aQOZsGLs4hUIwTAKBggqhkjOPQQDAwNoADBlAjBjuR/RNbgL
  32. 3kRhmn+PJTeKaL9sh/oQgHOYTgLmSnv3+NDCkhfKuMNoo/tHrkmihYgCMQC94Mae
  33. rDIrQpi0IDh+v0QSAv9rMife8tClafXWtDwwL8MS7oAh0ymT446Uizxx3PUxggHM
  34. MIIByAIBATBMMD8xCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJWQTEQMA4GA1UEBwwH
  35. SGVybmRvbjERMA8GA1UECgwIQm9ndXMgQ0ECCQCls1QoG7BuOzALBglghkgBZQME
  36. AgKggfIwGAYJKoZIhvcNAQkDMQsGCSqGSIb3DQEHATAcBgkqhkiG9w0BCQUxDxcN
  37. MTkwNTI5MTgyMzE5WjAoBgkqhkiG9w0BCTQxGzAZMAsGCWCGSAFlAwQCAqEKBggq
  38. hkjOPQQDAzA/BgkqhkiG9w0BCQQxMgQwtuQipP2CZx7U96rGbUT06LC5jVFYccZW
  39. 5/CaNvpcrOPiChDm2vI3m4k300z5mSZsME0GCyqGSIb3DQEJEAIBMT4wPAQgx08h
  40. D2QnVwj1DoeRELNtdZ0PffW4BQIvcwwVc/goU6OAAQEwFTATgRFhbGljZUBleGFt
  41. cGxlLmNvbTAKBggqhkjOPQQDAwRnMGUCMQChIMyN1nTN+LLQcYJuhWT297vSKMDK
  42. fIUedSwWYrcSnSa1pq2s3Wue+pNBfecEjYECMGrUNu1UpWdafEJulP9Vz76qOPMa
  43. 5V/AnTEV5zkmzRle8sffN+nQ+SGkoos5zpI1kA==
  44. """
  45. def setUp(self):
  46. self.asn1Spec = rfc5652.ContentInfo()
  47. def testDerCodec(self):
  48. substrate = pem.readBase64fromText(self.signed_message_pem_text)
  49. asn1Object, rest = der_decoder (substrate, asn1Spec=self.asn1Spec)
  50. self.assertFalse(rest)
  51. self.assertTrue(asn1Object.prettyPrint())
  52. self.assertEqual(substrate, der_encoder(asn1Object))
  53. self.assertEqual(rfc5652.id_signedData, asn1Object['contentType'])
  54. sd, rest = der_decoder(
  55. asn1Object['content'], asn1Spec=rfc5652.SignedData())
  56. self.assertFalse(rest)
  57. self.assertTrue(sd.prettyPrint())
  58. self.assertEqual(asn1Object['content'], der_encoder(sd))
  59. for sa in sd['signerInfos'][0]['signedAttrs']:
  60. sat = sa['attrType']
  61. sav0 = sa['attrValues'][0]
  62. if sat in rfc6211.id_aa_cmsAlgorithmProtect:
  63. sav, rest = der_decoder(
  64. sav0, asn1Spec=rfc6211.CMSAlgorithmProtection())
  65. self.assertFalse(rest)
  66. self.assertTrue(sav.prettyPrint())
  67. self.assertEqual(sav0, der_encoder(sav))
  68. def testOpenTypes(self):
  69. substrate = pem.readBase64fromText(self.signed_message_pem_text)
  70. asn1Object, rest = der_decoder(
  71. substrate, asn1Spec=self.asn1Spec, decodeOpenTypes=True)
  72. self.assertFalse(rest)
  73. self.assertTrue(asn1Object.prettyPrint())
  74. self.assertEqual(substrate, der_encoder(asn1Object))
  75. self.assertIn(asn1Object['contentType'], rfc5652.cmsContentTypesMap)
  76. self.assertEqual(rfc5652.id_signedData, asn1Object['contentType'])
  77. sd = asn1Object['content']
  78. self.assertEqual(
  79. rfc5652.CMSVersion().subtype(value='v1'), sd['version'])
  80. ect = sd['encapContentInfo']['eContentType']
  81. self.assertIn(ect, rfc5652.cmsContentTypesMap)
  82. self.assertEqual(rfc5652.id_data, ect)
  83. for sa in sd['signerInfos'][0]['signedAttrs']:
  84. if sa['attrType'] == rfc6211.id_aa_cmsAlgorithmProtect:
  85. self.assertIn(sa['attrType'], rfc5652.cmsAttributesMap)
  86. sav0 = sa['attrValues'][0]
  87. digest_oid = univ.ObjectIdentifier('2.16.840.1.101.3.4.2.2')
  88. sig_oid = univ.ObjectIdentifier('1.2.840.10045.4.3.3')
  89. self.assertEqual(
  90. digest_oid, sav0['digestAlgorithm']['algorithm'])
  91. self.assertEqual(
  92. sig_oid, sav0['signatureAlgorithm']['algorithm'])
  93. suite = unittest.TestLoader().loadTestsFromModule(sys.modules[__name__])
  94. if __name__ == '__main__':
  95. result = unittest.TextTestRunner(verbosity=2).run(suite)
  96. sys.exit(not result.wasSuccessful())