/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
/* vim: set ts=2 et sw=2 tw=80: */
/* This Source Code Form is subject to the terms of the Mozilla Public
* License , v . 2 . 0 . If a copy of the MPL was not distributed with this file ,
* You can obtain one at http://mozilla.org/MPL/2.0/. */
#include "cert.h"
#include "certdb.h"
#include "nss.h"
#include "pk11pub.h"
#include "secoid.h"
#include "secpkcs7.h"
#include "gtest/gtest.h"
#include "nss_scoped_ptrs.h"
namespace nss_test {
// This is an invalid PKCS7 message. Among other things, it contains some
// unknown hash OIDs. This should fail to parse, but it should be safe to try.
static const uint8_t p7_with_unknown_hashes[] = {
0 x30,
0 x4d,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x07,
0 x02,
0 xa0,
0 x40,
0 x30,
0 x3e,
0 x02,
0 x01,
0 x20,
0 x31,
0 x27,
0 x30,
0 x0b,
0 x06,
0 x09,
0 x60,
0 x86,
0 x48,
0 x01,
0 x65,
0 x03,
0 x04,
0 x02,
0 x05,
0 x30,
0 x0b,
0 x06,
0 x09,
0 x60,
0 x86,
0 x48,
0 x01,
0 x65,
0 x03,
0 x04,
0 x02,
0 x05,
0 x30,
0 x0b,
0 x06,
0 x09,
0 x60,
0 x86,
0 x48,
0 x01,
0 x65,
0 x03,
0 x04,
0 x02,
0 x04,
0 x30,
0 x10,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x07,
0 x01,
0 xa0,
0 x03,
0 x04,
0 x01,
0 x00};
// This is an invalid PKCS7 message. It contains multiple hash OIDs (that's not
// what makes it invalid). When it fails to parse, the associated digest data
// structures should be freed correctly.
static const uint8_t p7_with_multiple_hashes[] = {
0 x30,
0 x4d,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x07,
0 x02,
0 xa0,
0 x40,
0 x30,
0 x3e,
0 x02,
0 x01,
0 x20,
0 x31,
0 x27,
0 x30,
0 x0b,
0 x06,
0 x09,
0 x60,
0 x86,
0 x48,
0 x01,
0 x65,
0 x03,
0 x04,
0 x02,
0 x03,
0 x30,
0 x0b,
0 x06,
0 x09,
0 x60,
0 x86,
0 x48,
0 x01,
0 x65,
0 x03,
0 x04,
0 x02,
0 x02,
0 x30,
0 x0b,
0 x06,
0 x09,
0 x60,
0 x86,
0 x48,
0 x01,
0 x65,
0 x03,
0 x04,
0 x02,
0 x04,
0 x30,
0 x10,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x07,
0 x01,
0 xa0,
0 x03,
0 x04,
0 x01,
0 x00};
// Valid PKCS7 SignedData with digestAlgorithms = [unknown_oid, sha-256],
// content "hi", and empty signerInfos. Tests that digests stay aligned with
// digestAlgorithms when unrecognized algorithms are present.
static const uint8_t p7_mixed_digest_algs[] = {
0 x30,
0 x3f,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x07,
0 x02,
0 xa0,
0 x32,
0 x30,
0 x30,
0 x02,
0 x01,
0 x01,
0 x31,
0 x16,
0 x30,
0 x05,
0 x06,
0 x03,
0 x2b,
0 x06,
0 x01,
0 x30,
0 x0d,
0 x06,
0 x09,
0 x60,
0 x86,
0 x48,
0 x01,
0 x65,
0 x03,
0 x04,
0 x02,
0 x01,
0 x05,
0 x00,
0 x30,
0 x11,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x07,
0 x01,
0 xa0,
0 x04,
0 x04,
0 x02,
0 x68,
0 x69,
0 x31,
0 x00};
// Valid PKCS7 SignedData with digestAlgorithms = [unknown_oid (1.3.6.1),
// sha-256], content "test", a self-signed P-256 certificate, and a single
// signerInfo with an ECDSA-SHA256 signature (no authenticated attributes).
// This allows exercising the full sec_pkcs7_verify_signature code path with
// misaligned digest indices.
//
// To regenerate: python3 generate_p7_verify_blob.py (in this directory).
// The script uses the `cryptography` library to create a fresh P-256 key,
// self-signed cert, and valid PKCS7 SignedData with the unknown OID injected
// into digestAlgorithms.
static const uint8_t p7_signed_mixed_algs[] = {
0 x30,
0 x82,
0 x02,
0 x10,
0 x06,
0 x09,
0 x2A,
0 x86,
0 x48,
0 x86,
0 xF7,
0 x0D,
0 x01,
0 x07,
0 x02,
0 xA0,
0 x82,
0 x02,
0 x01,
0 x30,
0 x82,
0 x01,
0 xFD,
0 x02,
0 x01,
0 x01,
0 x31,
0 x16,
0 x30,
0 x05,
0 x06,
0 x03,
0 x2B,
0 x06,
0 x01,
0 x30,
0 x0D,
0 x06,
0 x09,
0 x60,
0 x86,
0 x48,
0 x01,
0 x65,
0 x03,
0 x04,
0 x02,
0 x01,
0 x05,
0 x00,
0 x30,
0 x13,
0 x06,
0 x09,
0 x2A,
0 x86,
0 x48,
0 x86,
0 xF7,
0 x0D,
0 x01,
0 x07,
0 x01,
0 xA0,
0 x06,
0 x04,
0 x04,
0 x74,
0 x65,
0 x73,
0 x74,
0 xA0,
0 x82,
0 x01,
0 x2E,
0 x30,
0 x82,
0 x01,
0 x2A,
0 x30,
0 x81,
0 xD0,
0 xA0,
0 x03,
0 x02,
0 x01,
0 x02,
0 x02,
0 x14,
0 x18,
0 xE7,
0 x5C,
0 x43,
0 xA6,
0 x74,
0 x20,
0 x0F,
0 x82,
0 x72,
0 x27,
0 x14,
0 x1B,
0 xC8,
0 xDC,
0 x4B,
0 x29,
0 x9D,
0 x8D,
0 x82,
0 x30,
0 x0A,
0 x06,
0 x08,
0 x2A,
0 x86,
0 x48,
0 xCE,
0 x3D,
0 x04,
0 x03,
0 x02,
0 x30,
0 x15,
0 x31,
0 x13,
0 x30,
0 x11,
0 x06,
0 x03,
0 x55,
0 x04,
0 x03,
0 x0C,
0 x0A,
0 x50,
0 x4B,
0 x43,
0 x53,
0 x37,
0 x20,
0 x54,
0 x65,
0 x73,
0 x74,
0 x30,
0 x1E,
0 x17,
0 x0D,
0 x32,
0 x35,
0 x30,
0 x31,
0 x30,
0 x31,
0 x30,
0 x30,
0 x30,
0 x30,
0 x30,
0 x30,
0 x5A,
0 x17,
0 x0D,
0 x33,
0 x35,
0 x30,
0 x31,
0 x30,
0 x31,
0 x30,
0 x30,
0 x30,
0 x30,
0 x30,
0 x30,
0 x5A,
0 x30,
0 x15,
0 x31,
0 x13,
0 x30,
0 x11,
0 x06,
0 x03,
0 x55,
0 x04,
0 x03,
0 x0C,
0 x0A,
0 x50,
0 x4B,
0 x43,
0 x53,
0 x37,
0 x20,
0 x54,
0 x65,
0 x73,
0 x74,
0 x30,
0 x59,
0 x30,
0 x13,
0 x06,
0 x07,
0 x2A,
0 x86,
0 x48,
0 xCE,
0 x3D,
0 x02,
0 x01,
0 x06,
0 x08,
0 x2A,
0 x86,
0 x48,
0 xCE,
0 x3D,
0 x03,
0 x01,
0 x07,
0 x03,
0 x42,
0 x00,
0 x04,
0 xED,
0 xC5,
0 xFB,
0 x1A,
0 xC1,
0 x6F,
0 x2F,
0 xA8,
0 x90,
0 xD1,
0 xBA,
0 x46,
0 x6C,
0 xDD,
0 xA0,
0 xB0,
0 x97,
0 xA5,
0 x86,
0 xD5,
0 xBE,
0 x9B,
0 x2B,
0 xC4,
0 x9C,
0 x8F,
0 x1A,
0 x16,
0 x8A,
0 x05,
0 xA6,
0 xB8,
0 x8E,
0 x99,
0 xCD,
0 x59,
0 xCD,
0 x4D,
0 x72,
0 x45,
0 x11,
0 x42,
0 xAA,
0 x4F,
0 xF2,
0 x03,
0 xED,
0 xC9,
0 x6C,
0 x27,
0 xA5,
0 xB5,
0 x95,
0 x5E,
0 x11,
0 xFD,
0 x1B,
0 x27,
0 x3A,
0 x17,
0 x31,
0 xDB,
0 xBD,
0 x95,
0 x30,
0 x0A,
0 x06,
0 x08,
0 x2A,
0 x86,
0 x48,
0 xCE,
0 x3D,
0 x04,
0 x03,
0 x02,
0 x03,
0 x49,
0 x00,
0 x30,
0 x46,
0 x02,
0 x21,
0 x00,
0 x8D,
0 xFE,
0 x8F,
0 x1A,
0 x46,
0 x36,
0 x9E,
0 x58,
0 x2A,
0 x22,
0 x81,
0 x3B,
0 x0F,
0 xEC,
0 xAD,
0 x38,
0 x7C,
0 xC5,
0 xB1,
0 xC8,
0 xFF,
0 x28,
0 xD0,
0 x23,
0 xB9,
0 x10,
0 xF9,
0 xFE,
0 x41,
0 x8B,
0 x63,
0 x85,
0 x02,
0 x21,
0 x00,
0 xFC,
0 x29,
0 x07,
0 x9A,
0 x62,
0 xA5,
0 x6E,
0 x8F,
0 xEB,
0 xC9,
0 x4B,
0 x80,
0 xD7,
0 xD9,
0 x80,
0 xDD,
0 xE0,
0 xB4,
0 x6D,
0 x98,
0 x53,
0 x5E,
0 x9D,
0 x57,
0 x64,
0 xFA,
0 x51,
0 xEE,
0 xF9,
0 xC8,
0 x9C,
0 xC4,
0 x31,
0 x81,
0 x98,
0 x30,
0 x81,
0 x95,
0 x02,
0 x01,
0 x01,
0 x30,
0 x2D,
0 x30,
0 x15,
0 x31,
0 x13,
0 x30,
0 x11,
0 x06,
0 x03,
0 x55,
0 x04,
0 x03,
0 x0C,
0 x0A,
0 x50,
0 x4B,
0 x43,
0 x53,
0 x37,
0 x20,
0 x54,
0 x65,
0 x73,
0 x74,
0 x02,
0 x14,
0 x18,
0 xE7,
0 x5C,
0 x43,
0 xA6,
0 x74,
0 x20,
0 x0F,
0 x82,
0 x72,
0 x27,
0 x14,
0 x1B,
0 xC8,
0 xDC,
0 x4B,
0 x29,
0 x9D,
0 x8D,
0 x82,
0 x30,
0 x0D,
0 x06,
0 x09,
0 x60,
0 x86,
0 x48,
0 x01,
0 x65,
0 x03,
0 x04,
0 x02,
0 x01,
0 x05,
0 x00,
0 x30,
0 x09,
0 x06,
0 x07,
0 x2A,
0 x86,
0 x48,
0 xCE,
0 x3D,
0 x02,
0 x01,
0 x04,
0 x47,
0 x30,
0 x45,
0 x02,
0 x20,
0 x5A,
0 x2B,
0 x0E,
0 xD2,
0 x2F,
0 x24,
0 x75,
0 xB8,
0 x18,
0 xF5,
0 x8D,
0 x1D,
0 x5E,
0 x7E,
0 x81,
0 x48,
0 x55,
0 x47,
0 x35,
0 xFF,
0 xB0,
0 xFA,
0 x6E,
0 x8C,
0 x0F,
0 xE5,
0 xC7,
0 x1A,
0 x2B,
0 xCF,
0 x5B,
0 xE0,
0 x02,
0 x21,
0 x00,
0 xA0,
0 x13,
0 x3F,
0 xF7,
0 xF3,
0 x98,
0 x86,
0 xD5,
0 x17,
0 xE9,
0 x23,
0 x5B,
0 xD2,
0 x41,
0 xC7,
0 xD2,
0 x20,
0 xD5,
0 x91,
0 xDC,
0 x7E,
0 xC8,
0 x6E,
0 x43,
0 xBA,
0 xC4,
0 x5F,
0 x9A,
0 xFA,
0 xE9,
0 xC5,
0 x0A};
// Certificate DER extracted from p7_signed_mixed_algs (CN=PKCS7 Test,
// self-signed P-256). Used to trust the cert before signature verification.
static const uint8_t p7_test_cert_der[] = {
0 x30,
0 x82,
0 x01,
0 x2A,
0 x30,
0 x81,
0 xD0,
0 xA0,
0 x03,
0 x02,
0 x01,
0 x02,
0 x02,
0 x14,
0 x18,
0 xE7,
0 x5C,
0 x43,
0 xA6,
0 x74,
0 x20,
0 x0F,
0 x82,
0 x72,
0 x27,
0 x14,
0 x1B,
0 xC8,
0 xDC,
0 x4B,
0 x29,
0 x9D,
0 x8D,
0 x82,
0 x30,
0 x0A,
0 x06,
0 x08,
0 x2A,
0 x86,
0 x48,
0 xCE,
0 x3D,
0 x04,
0 x03,
0 x02,
0 x30,
0 x15,
0 x31,
0 x13,
0 x30,
0 x11,
0 x06,
0 x03,
0 x55,
0 x04,
0 x03,
0 x0C,
0 x0A,
0 x50,
0 x4B,
0 x43,
0 x53,
0 x37,
0 x20,
0 x54,
0 x65,
0 x73,
0 x74,
0 x30,
0 x1E,
0 x17,
0 x0D,
0 x32,
0 x35,
0 x30,
0 x31,
0 x30,
0 x31,
0 x30,
0 x30,
0 x30,
0 x30,
0 x30,
0 x30,
0 x5A,
0 x17,
0 x0D,
0 x33,
0 x35,
0 x30,
0 x31,
0 x30,
0 x31,
0 x30,
0 x30,
0 x30,
0 x30,
0 x30,
0 x30,
0 x5A,
0 x30,
0 x15,
0 x31,
0 x13,
0 x30,
0 x11,
0 x06,
0 x03,
0 x55,
0 x04,
0 x03,
0 x0C,
0 x0A,
0 x50,
0 x4B,
0 x43,
0 x53,
0 x37,
0 x20,
0 x54,
0 x65,
0 x73,
0 x74,
0 x30,
0 x59,
0 x30,
0 x13,
0 x06,
0 x07,
0 x2A,
0 x86,
0 x48,
0 xCE,
0 x3D,
0 x02,
0 x01,
0 x06,
0 x08,
0 x2A,
0 x86,
0 x48,
0 xCE,
0 x3D,
0 x03,
0 x01,
0 x07,
0 x03,
0 x42,
0 x00,
0 x04,
0 xED,
0 xC5,
0 xFB,
0 x1A,
0 xC1,
0 x6F,
0 x2F,
0 xA8,
0 x90,
0 xD1,
0 xBA,
0 x46,
0 x6C,
0 xDD,
0 xA0,
0 xB0,
0 x97,
0 xA5,
0 x86,
0 xD5,
0 xBE,
0 x9B,
0 x2B,
0 xC4,
0 x9C,
0 x8F,
0 x1A,
0 x16,
0 x8A,
0 x05,
0 xA6,
0 xB8,
0 x8E,
0 x99,
0 xCD,
0 x59,
0 xCD,
0 x4D,
0 x72,
0 x45,
0 x11,
0 x42,
0 xAA,
0 x4F,
0 xF2,
0 x03,
0 xED,
0 xC9,
0 x6C,
0 x27,
0 xA5,
0 xB5,
0 x95,
0 x5E,
0 x11,
0 xFD,
0 x1B,
0 x27,
0 x3A,
0 x17,
0 x31,
0 xDB,
0 xBD,
0 x95,
0 x30,
0 x0A,
0 x06,
0 x08,
0 x2A,
0 x86,
0 x48,
0 xCE,
0 x3D,
0 x04,
0 x03,
0 x02,
0 x03,
0 x49,
0 x00,
0 x30,
0 x46,
0 x02,
0 x21,
0 x00,
0 x8D,
0 xFE,
0 x8F,
0 x1A,
0 x46,
0 x36,
0 x9E,
0 x58,
0 x2A,
0 x22,
0 x81,
0 x3B,
0 x0F,
0 xEC,
0 xAD,
0 x38,
0 x7C,
0 xC5,
0 xB1,
0 xC8,
0 xFF,
0 x28,
0 xD0,
0 x23,
0 xB9,
0 x10,
0 xF9,
0 xFE,
0 x41,
0 x8B,
0 x63,
0 x85,
0 x02,
0 x21,
0 x00,
0 xFC,
0 x29,
0 x07,
0 x9A,
0 x62,
0 xA5,
0 x6E,
0 x8F,
0 xEB,
0 xC9,
0 x4B,
0 x80,
0 xD7,
0 xD9,
0 x80,
0 xDD,
0 xE0,
0 xB4,
0 x6D,
0 x98,
0 x53,
0 x5E,
0 x9D,
0 x57,
0 x64,
0 xFA,
0 x51,
0 xEE,
0 xF9,
0 xC8,
0 x9C,
0 xC4};
class P7ImportTest : public ::testing::Test {};
TEST_F(P7ImportTest, DigestsAlignWithDigestAlgorithms) {
ScopedSEC_PKCS7DecoderContext dcx(SEC_PKCS7DecoderStart(
nullptr, nullptr, nullptr, nullptr, nullptr, nullptr, nullptr));
ASSERT_TRUE(dcx);
SECStatus rv = SEC_PKCS7DecoderUpdate(
dcx.get(), reinterpret_cast<
const char *>(p7_mixed_digest_algs),
sizeof (p7_mixed_digest_algs));
ASSERT_EQ(SECSuccess, rv);
SEC_PKCS7ContentInfo *cinfo = SEC_PKCS7DecoderFinish(dcx.release());
ASSERT_TRUE(cinfo);
ASSERT_EQ(SEC_OID_PKCS7_SIGNED_DATA, SEC_PKCS7ContentType(cinfo));
SEC_PKCS7SignedData *sigd = cinfo->content.signedData;
ASSERT_TRUE(sigd);
ASSERT_TRUE(sigd->digestAlgorithms);
ASSERT_TRUE(sigd->digestAlgorithms[
0 ]);
ASSERT_TRUE(sigd->digestAlgorithms[
1 ]);
ASSERT_TRUE(sigd->digests);
// digests[0] corresponds to the unknown algorithm — should be NULL.
EXPECT_EQ(nullptr, sigd->digests[
0 ]);
// digests[1] corresponds to SHA-256 — should be non-NULL.
EXPECT_NE(nullptr, sigd->digests[
1 ]);
SEC_PKCS7DestroyContentInfo(cinfo);
}
// Verify that the digest for a recognized algorithm can be found by index
// even when an unrecognized algorithm occupies an earlier slot. This
// replicates the lookup logic in sec_pkcs7_verify_signature.
TEST_F(P7ImportTest, DigestLookupSkipsUnrecognizedAlgorithm) {
ScopedSEC_PKCS7DecoderContext dcx(SEC_PKCS7DecoderStart(
nullptr, nullptr, nullptr, nullptr, nullptr, nullptr, nullptr));
ASSERT_TRUE(dcx);
SECStatus rv = SEC_PKCS7DecoderUpdate(
dcx.get(), reinterpret_cast<
const char *>(p7_mixed_digest_algs),
sizeof (p7_mixed_digest_algs));
ASSERT_EQ(SECSuccess, rv);
SEC_PKCS7ContentInfo *cinfo = SEC_PKCS7DecoderFinish(dcx.release());
ASSERT_TRUE(cinfo);
SEC_PKCS7SignedData *sigd = cinfo->content.signedData;
ASSERT_TRUE(sigd);
SECAlgorithmID **digestalgs = sigd->digestAlgorithms;
SECItem **digests = sigd->digests;
ASSERT_TRUE(digestalgs);
ASSERT_TRUE(digests);
// digests[0] is NULL (unknown algorithm), but digests is non-NULL.
// The early-out in sec_pkcs7_verify_signature must not treat this as
// "no digests available".
EXPECT_EQ(nullptr, digests[
0 ]);
// Replicate the verification lookup: find SHA-256 in digestAlgorithms,
// then access digests at the same index.
int i;
for (i =
0 ; digestalgs[i] != NULL; i++) {
if (SECOID_FindOIDTag(&digestalgs[i]->algorithm) == SEC_OID_SHA256)
break ;
}
ASSERT_NE(nullptr, digestalgs[i]) <<
"SHA-256 not found in digestAlgorithms" ;
EXPECT_NE(nullptr, digests[i])
<<
"digests[" << i <<
"] is NULL despite SHA-256 being recognized" ;
SEC_PKCS7DestroyContentInfo(cinfo);
}
// End-to-end verification of a signed PKCS7 message whose digestAlgorithms
// contains an unrecognized OID before the signer's SHA-256. This exercises
// sec_pkcs7_verify_signature including the index-based digest lookup.
TEST_F(P7ImportTest, VerifySignatureWithMixedDigestAlgorithms) {
CERTCertDBHandle *certdb = CERT_GetDefaultCertDB();
ASSERT_TRUE(certdb);
// Import the test cert and trust it for object signing so that
// CERT_VerifyCert succeeds inside sec_pkcs7_verify_signature.
SECItem certDER = {siBuffer,
const_cast <uint8_t *>(p7_test_cert_der),
sizeof (p7_test_cert_der)};
ScopedCERTCertificate cert(
CERT_NewTempCertificate(certdb, &certDER, nullptr, PR_TRUE, PR_TRUE));
ASSERT_TRUE(cert);
CERTCertTrust trust;
memset(&trust,
0 ,
sizeof (trust));
trust.emailFlags = CERTDB_TERMINAL_RECORD | CERTDB_TRUSTED | CERTDB_VALID_CA |
CERTDB_TRUSTED_CA;
ASSERT_EQ(SECSuccess, CERT_ChangeCertTrust(certdb, cert.get(), &trust));
// Decode the PKCS7 message.
ScopedSEC_PKCS7DecoderContext dcx(SEC_PKCS7DecoderStart(
nullptr, nullptr, nullptr, nullptr, nullptr, nullptr, nullptr));
ASSERT_TRUE(dcx);
SECStatus rv = SEC_PKCS7DecoderUpdate(
dcx.get(), reinterpret_cast<
const char *>(p7_signed_mixed_algs),
sizeof (p7_signed_mixed_algs));
ASSERT_EQ(SECSuccess, rv);
SEC_PKCS7ContentInfo *cinfo = SEC_PKCS7DecoderFinish(dcx.release());
ASSERT_TRUE(cinfo);
ASSERT_EQ(SEC_OID_PKCS7_SIGNED_DATA, SEC_PKCS7ContentType(cinfo));
// Verify the signature. This reaches sec_pkcs7_verify_signature and
// exercises the digest lookup at the index matching the signer's algorithm.
PRBool valid =
SEC_PKCS7VerifySignature(cinfo, certUsageEmailSigner, PR_FALSE);
EXPECT_TRUE(valid) <<
"Signature verification failed; error="
<< PORT_GetError();
SEC_PKCS7DestroyContentInfo(cinfo);
}
TEST_F(P7ImportTest, FailSafeWithUnknownHashes) {
ScopedSEC_PKCS7DecoderContext dcx(SEC_PKCS7DecoderStart(
nullptr, nullptr, nullptr, nullptr, nullptr, nullptr, nullptr));
ASSERT_TRUE(dcx);
SECStatus rv = SEC_PKCS7DecoderUpdate(
dcx.get(), reinterpret_cast<
const char *>(p7_with_unknown_hashes),
sizeof (p7_with_unknown_hashes));
ASSERT_EQ(SECFailure, rv);
}
TEST_F(P7ImportTest, NoLeakWithMultipleHashes) {
ScopedSEC_PKCS7DecoderContext dcx(SEC_PKCS7DecoderStart(
nullptr, nullptr, nullptr, nullptr, nullptr, nullptr, nullptr));
ASSERT_TRUE(dcx);
SECStatus rv = SEC_PKCS7DecoderUpdate(
dcx.get(), reinterpret_cast<
const char *>(p7_with_multiple_hashes),
sizeof (p7_with_multiple_hashes));
ASSERT_EQ(SECFailure, rv);
}
// RSA-2048 private key (PKCS #8, unencrypted DER) that matches kTestCert.
static const uint8_t kTestRsaKey[] = {
0 x30,
0 x82,
0 x04,
0 xbe,
0 x02,
0 x01,
0 x00,
0 x30,
0 x0d,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x01,
0 x01,
0 x05,
0 x00,
0 x04,
0 x82,
0 x04,
0 xa8,
0 x30,
0 x82,
0 x04,
0 xa4,
0 x02,
0 x01,
0 x00,
0 x02,
0 x82,
0 x01,
0 x01,
0 x00,
0 xc5,
0 x2a,
0 xdb,
0 x86,
0 xb0,
0 x2a,
0 x4d,
0 xe0,
0 x52,
0 xb0,
0 x4a,
0 x29,
0 xe2,
0 xe0,
0 xb4,
0 xcc,
0 xf8,
0 x0c,
0 x00,
0 xcd,
0 x0d,
0 x7e,
0 xcc,
0 xb1,
0 xd3,
0 xc8,
0 xa2,
0 x0d,
0 x43,
0 x6d,
0 x06,
0 x07,
0 x22,
0 x49,
0 xec,
0 x86,
0 x21,
0 x85,
0 x68,
0 xf7,
0 x6e,
0 x48,
0 xa3,
0 xe8,
0 x5b,
0 x54,
0 x4d,
0 x0c,
0 x5b,
0 xfb,
0 x80,
0 x07,
0 x10,
0 xab,
0 xe4,
0 xda,
0 x3e,
0 xd6,
0 xec,
0 x08,
0 x3e,
0 x25,
0 x2c,
0 x08,
0 x07,
0 x78,
0 xbf,
0 x1d,
0 x84,
0 xeb,
0 x46,
0 x58,
0 xb1,
0 x29,
0 x9c,
0 x38,
0 xdd,
0 x5f,
0 x48,
0 x78,
0 x5f,
0 x02,
0 xaa,
0 x8f,
0 x4b,
0 x93,
0 xd3,
0 x03,
0 x83,
0 xb6,
0 x68,
0 xa3,
0 xfe,
0 x07,
0 xfc,
0 x67,
0 x8c,
0 xdd,
0 x4f,
0 x86,
0 x88,
0 x80,
0 xfe,
0 xa3,
0 xbf,
0 xc6,
0 x79,
0 x20,
0 xed,
0 xcf,
0 x5f,
0 x2a,
0 x65,
0 xcd,
0 x3c,
0 xf8,
0 x2d,
0 x97,
0 x1b,
0 x63,
0 x0e,
0 xad,
0 x79,
0 xc6,
0 x74,
0 x1d,
0 x66,
0 xcd,
0 x11,
0 xdc,
0 x15,
0 xd0,
0 x46,
0 x0f,
0 xf0,
0 x3b,
0 x70,
0 xca,
0 x69,
0 x74,
0 x70,
0 x87,
0 x8f,
0 xd1,
0 xfe,
0 x3c,
0 xdd,
0 xbc,
0 x34,
0 xb2,
0 xee,
0 x74,
0 xd7,
0 xfe,
0 x10,
0 xbe,
0 x40,
0 xf4,
0 x52,
0 x8f,
0 x77,
0 xbf,
0 xbf,
0 x03,
0 xa7,
0 x36,
0 x62,
0 x96,
0 x10,
0 x4e,
0 x4e,
0 x6a,
0 x1a,
0 x5a,
0 xea,
0 x89,
0 x04,
0 x5b,
0 x3e,
0 x37,
0 x4f,
0 x61,
0 x65,
0 x33,
0 xbe,
0 xa5,
0 x4f,
0 x19,
0 x20,
0 x51,
0 x02,
0 x0b,
0 x59,
0 x12,
0 xcf,
0 x48,
0 xc3,
0 x79,
0 x09,
0 xe8,
0 xc2,
0 x0e,
0 x5d,
0 xec,
0 xbe,
0 x8e,
0 xc9,
0 xf7,
0 xf2,
0 xf5,
0 x4a,
0 xae,
0 x16,
0 xb0,
0 xee,
0 xc8,
0 x5b,
0 x20,
0 x37,
0 xe5,
0 x29,
0 x4f,
0 x15,
0 x40,
0 x5f,
0 x1f,
0 x14,
0 x05,
0 x5c,
0 xb6,
0 x8a,
0 x5d,
0 x44,
0 x45,
0 xb4,
0 x96,
0 x51,
0 xeb,
0 x2b,
0 xa6,
0 xac,
0 xc9,
0 xa1,
0 xbe,
0 xa1,
0 xcf,
0 x53,
0 x9e,
0 x21,
0 xdd,
0 x01,
0 x08,
0 xfc,
0 x05,
0 xfc,
0 x0d,
0 x02,
0 x03,
0 x01,
0 x00,
0 x01,
0 x02,
0 x82,
0 x01,
0 x00,
0 x10,
0 xc9,
0 x4f,
0 xa6,
0 xb8,
0 x49,
0 x91,
0 xc1,
0 xc9,
0 xd3,
0 x1f,
0 xd7,
0 xfb,
0 x17,
0 x48,
0 x82,
0 xb4,
0 x3c,
0 xf4,
0 x0b,
0 x2b,
0 xdd,
0 x4c,
0 xce,
0 x23,
0 x0a,
0 xcf,
0 x89,
0 x33,
0 x8c,
0 x0d,
0 x04,
0 x54,
0 x78,
0 xae,
0 x13,
0 x7e,
0 xb7,
0 xc8,
0 xb2,
0 x5a,
0 xdd,
0 xad,
0 x09,
0 x73,
0 xa5,
0 x1f,
0 x68,
0 xda,
0 xf7,
0 xf4,
0 x49,
0 x7b,
0 x08,
0 xe2,
0 x28,
0 xc1,
0 x4a,
0 xde,
0 x63,
0 x96,
0 x99,
0 x91,
0 x95,
0 xc9,
0 x6a,
0 x65,
0 x53,
0 x12,
0 x65,
0 xa4,
0 x37,
0 xee,
0 xe0,
0 x17,
0 xb5,
0 xdb,
0 xb0,
0 x68,
0 xba,
0 x1e,
0 xd4,
0 xaf,
0 x9d,
0 x6d,
0 x96,
0 x28,
0 xa9,
0 x56,
0 xf0,
0 x69,
0 x18,
0 xf5,
0 x35,
0 x76,
0 xd9,
0 x80,
0 xc1,
0 x0d,
0 x81,
0 x40,
0 x63,
0 xed,
0 xca,
0 x16,
0 x8c,
0 xc3,
0 x9e,
0 xa3,
0 x15,
0 xe7,
0 x08,
0 x9e,
0 xb6,
0 xdf,
0 x91,
0 xa8,
0 x48,
0 x02,
0 x2e,
0 x92,
0 x7f,
0 x00,
0 x81,
0 x7d,
0 xe7,
0 x4c,
0 x40,
0 xd3,
0 xad,
0 xa8,
0 x50,
0 xa0,
0 x88,
0 x4f,
0 x01,
0 x20,
0 x8e,
0 x97,
0 xe3,
0 x82,
0 x42,
0 xa5,
0 x41,
0 x11,
0 xbe,
0 x94,
0 x3e,
0 x8b,
0 x37,
0 x36,
0 xfa,
0 x62,
0 x0c,
0 x7a,
0 x28,
0 x05,
0 x0f,
0 x8e,
0 x6f,
0 x93,
0 x60,
0 xea,
0 x03,
0 x63,
0 x6e,
0 xb0,
0 xfb,
0 xf2,
0 x4d,
0 x1a,
0 x4a,
0 x56,
0 xd8,
0 x51,
0 x8e,
0 xc5,
0 x3a,
0 x42,
0 x26,
0 x35,
0 x0b,
0 x05,
0 x70,
0 xe8,
0 x4e,
0 x2c,
0 xe6,
0 x4e,
0 x42,
0 x5c,
0 x9e,
0 x82,
0 x19,
0 x71,
0 x8d,
0 xc5,
0 xba,
0 xe1,
0 x86,
0 x1b,
0 x5a,
0 x6b,
0 xfe,
0 x4a,
0 x79,
0 xa9,
0 x84,
0 x47,
0 x8f,
0 xe4,
0 x03,
0 xfd,
0 x41,
0 x6c,
0 x51,
0 x60,
0 x9a,
0 xd8,
0 x43,
0 x33,
0 xf4,
0 xbb,
0 xb1,
0 x51,
0 xc6,
0 xdd,
0 x45,
0 x26,
0 x46,
0 x86,
0 x0f,
0 xde,
0 x2e,
0 x2c,
0 x6a,
0 xd2,
0 x2b,
0 x5e,
0 x3f,
0 x5e,
0 xe8,
0 x76,
0 xc8,
0 x70,
0 xc8,
0 x19,
0 x85,
0 xd2,
0 x3e,
0 x78,
0 x4b,
0 xa7,
0 x8a,
0 x1e,
0 x9d,
0 x02,
0 x81,
0 x81,
0 x00,
0 xf0,
0 xd5,
0 xab,
0 x7f,
0 x10,
0 x62,
0 xcc,
0 x0b,
0 xcb,
0 x01,
0 xd8,
0 xfd,
0 x73,
0 x30,
0 xe6,
0 xb5,
0 xe2,
0 x8d,
0 x30,
0 xdf,
0 x31,
0 x6d,
0 x80,
0 x7e,
0 x4b,
0 x01,
0 xa9,
0 x08,
0 x00,
0 x4f,
0 xfc,
0 x1c,
0 x40,
0 x33,
0 x4d,
0 x8a,
0 x6b,
0 xc5,
0 x4a,
0 x7a,
0 x72,
0 x43,
0 x1b,
0 x99,
0 x4d,
0 x8f,
0 xc7,
0 xb6,
0 x5d,
0 xb5,
0 x45,
0 x6f,
0 xe2,
0 x56,
0 x25,
0 x91,
0 xdf,
0 x25,
0 x04,
0 x9a,
0 x97,
0 x95,
0 xab,
0 x95,
0 x2e,
0 x63,
0 x0b,
0 x9d,
0 x95,
0 xe4,
0 xb2,
0 x94,
0 xf8,
0 xd4,
0 xe7,
0 xbe,
0 x71,
0 x1f,
0 xae,
0 xb6,
0 xe3,
0 x57,
0 xe0,
0 x20,
0 x40,
0 xd7,
0 xa8,
0 x3f,
0 x53,
0 x80,
0 x93,
0 x6c,
0 xca,
0 x7c,
0 xfc,
0 x46,
0 x7e,
0 x91,
0 x2d,
0 x82,
0 x52,
0 xfd,
0 x99,
0 xd8,
0 x6a,
0 x8a,
0 x6b,
0 x5e,
0 x6a,
0 x94,
0 xd5,
0 xa9,
0 xca,
0 x55,
0 x6f,
0 x37,
0 xae,
0 xaf,
0 x9d,
0 x36,
0 x8d,
0 x8b,
0 xda,
0 x2f,
0 x7c,
0 x60,
0 x6f,
0 xb3,
0 x02,
0 x81,
0 x81,
0 x00,
0 xd1,
0 x95,
0 x42,
0 x11,
0 x0f,
0 x56,
0 x91,
0 xf1,
0 x9b,
0 x2e,
0 xb8,
0 x77,
0 xde,
0 xaa,
0 xef,
0 x79,
0 x3b,
0 x29,
0 x4e,
0 x53,
0 xea,
0 x37,
0 x4d,
0 xfc,
0 xbe,
0 x50,
0 x76,
0 xfb,
0 x95,
0 x76,
0 xec,
0 x65,
0 xe3,
0 xb3,
0 xa7,
0 x47,
0 x27,
0 xdc,
0 xbd,
0 xff,
0 xc9,
0 x00,
0 x54,
0 x03,
0 x5a,
0 xbf,
0 xd4,
0 xb2,
0 xed,
0 x32,
0 x4d,
0 xd9,
0 xf3,
0 xf8,
0 x18,
0 x12,
0 x2b,
0 xa4,
0 xf0,
0 xbe,
0 x97,
0 x81,
0 x61,
0 x67,
0 x09,
0 xf9,
0 xc9,
0 x3d,
0 xad,
0 x8e,
0 x9f,
0 xfc,
0 xe4,
0 xae,
0 xcf,
0 x1c,
0 x76,
0 xc2,
0 x71,
0 x19,
0 x95,
0 xa3,
0 xf3,
0 x60,
0 x56,
0 xf4,
0 x32,
0 x53,
0 x85,
0 x5b,
0 x8b,
0 xc8,
0 xba,
0 x76,
0 x89,
0 x13,
0 x71,
0 x1d,
0 xd3,
0 x9b,
0 xba,
0 x39,
0 xd1,
0 x97,
0 xb2,
0 x49,
0 x94,
0 xc0,
0 xfb,
0 xed,
0 xd8,
0 x93,
0 xa8,
0 x44,
0 xec,
0 x74,
0 xc5,
0 x30,
0 x08,
0 x3a,
0 xa8,
0 x4a,
0 xdb,
0 x4b,
0 x1b,
0 x74,
0 x05,
0 x3f,
0 x02,
0 x81,
0 x80,
0 x6b,
0 x52,
0 x7c,
0 x93,
0 x2a,
0 x25,
0 x2c,
0 xd2,
0 xd0,
0 x8b,
0 xa9,
0 x3c,
0 x00,
0 xda,
0 x38,
0 xe5,
0 xb2,
0 xe8,
0 xc2,
0 x6f,
0 xa3,
0 xe2,
0 x2d,
0 x51,
0 x9a,
0 x71,
0 x49,
0 xf7,
0 x23,
0 xd4,
0 x80,
0 xff,
0 xc1,
0 xe8,
0 x5a,
0 xd4,
0 xa5,
0 x84,
0 x0c,
0 xd5,
0 x96,
0 x17,
0 xab,
0 xb3,
0 xdc,
0 x69,
0 x87,
0 x51,
0 x10,
0 x5f,
0 x58,
0 x6b,
0 x2c,
0 x8c,
0 xc1,
0 x3f,
0 x49,
0 x16,
0 x80,
0 xff,
0 xb7,
0 x2f,
0 x5e,
0 x80,
0 x23,
0 x64,
0 xc5,
0 xe7,
0 x5a,
0 xc5,
0 xc8,
0 x83,
0 x34,
0 x84,
0 x04,
0 x25,
0 xcc,
0 xd9,
0 x96,
0 x8d,
0 x2f,
0 xb0,
0 x98,
0 x53,
0 x27,
0 x32,
0 x33,
0 x6a,
0 xcc,
0 xf6,
0 x4e,
0 x3c,
0 x3b,
0 xdc,
0 x08,
0 xbc,
0 x0d,
0 x68,
0 xfa,
0 xc3,
0 xc9,
0 xe1,
0 xf3,
0 x6e,
0 x0a,
0 xc4,
0 x56,
0 x66,
0 x83,
0 xce,
0 x81,
0 x8c,
0 xa1,
0 x7b,
0 x03,
0 x0d,
0 xe8,
0 x4d,
0 xa0,
0 x1c,
0 x90,
0 x65,
0 x53,
0 x3c,
0 xb8,
0 x0b,
0 x6d,
0 x9b,
0 x02,
0 x81,
0 x81,
0 x00,
0 xa5,
0 xc0,
0 x8c,
0 xc2,
0 x9f,
0 x45,
0 xd1,
0 x20,
0 xaa,
0 xa1,
0 x55,
0 xa4,
0 xff,
0 xc6,
0 x62,
0 xa4,
0 x97,
0 x64,
0 x80,
0 x9d,
0 x1f,
0 x34,
0 x64,
0 x0a,
0 x4a,
0 x9d,
0 xaa,
0 xac,
0 x28,
0 x36,
0 x28,
0 x9a,
0 x20,
0 x6e,
0 x7a,
0 x12,
0 x6d,
0 x75,
0 x48,
0 x12,
0 xde,
0 x6d,
0 xd3,
0 x03,
0 xe0,
0 x26,
0 xac,
0 xda,
0 x61,
0 x7b,
0 x92,
0 x54,
0 x98,
0 x7d,
0 x92,
0 xd3,
0 xf4,
0 x0e,
0 x7b,
0 x93,
0 xd0,
0 x90,
0 xb3,
0 x6e,
0 xe1,
0 x55,
0 xda,
0 x91,
0 x5c,
0 x0c,
0 xdb,
0 x7d,
0 x0f,
0 x83,
0 x2d,
0 x2b,
0 x8e,
0 xc5,
0 x12,
0 xdb,
0 xb0,
0 x1c,
0 x3d,
0 x23,
0 xe9,
0 x41,
0 x31,
0 xf8,
0 x1a,
0 x15,
0 x1f,
0 xc5,
0 x3d,
0 xaa,
0 xf7,
0 x98,
0 x17,
0 xb3,
0 x06,
0 x23,
0 x38,
0 x31,
0 xf8,
0 x10,
0 x28,
0 x21,
0 xc7,
0 x72,
0 xa5,
0 x0c,
0 x23,
0 x68,
0 x0c,
0 x01,
0 x8e,
0 x9c,
0 x7f,
0 x43,
0 x10,
0 x8f,
0 x0b,
0 x80,
0 x40,
0 x54,
0 xf3,
0 x3e,
0 x5b,
0 xd3,
0 x02,
0 x81,
0 x81,
0 x00,
0 x80,
0 x1f,
0 x1f,
0 x58,
0 x4f,
0 xe0,
0 xc0,
0 x88,
0 xe4,
0 x06,
0 x4a,
0 x0a,
0 x65,
0 x87,
0 xb0,
0 xd2,
0 x30,
0 x96,
0 x8d,
0 xaf,
0 x88,
0 x65,
0 x37,
0 x72,
0 x5b,
0 x75,
0 xd8,
0 xeb,
0 x1a,
0 x20,
0 x96,
0 x61,
0 xa7,
0 x40,
0 xcc,
0 xdb,
0 xe3,
0 xe3,
0 x58,
0 x9c,
0 xcb,
0 x37,
0 x78,
0 xd4,
0 x36,
0 x01,
0 xaa,
0 xeb,
0 x2f,
0 x53,
0 xc1,
0 x16,
0 x80,
0 xf2,
0 x36,
0 x17,
0 x4e,
0 x5c,
0 xa9,
0 x3c,
0 xd7,
0 x14,
0 x1f,
0 x6d,
0 xa3,
0 xbf,
0 x81,
0 x3d,
0 x69,
0 xbd,
0 xc7,
0 xa9,
0 xc6,
0 x22,
0 x21,
0 x58,
0 x67,
0 x01,
0 x76,
0 xec,
0 x7b,
0 x82,
0 x14,
0 xb2,
0 xff,
0 xae,
0 x04,
0 x7b,
0 x18,
0 x6c,
0 x78,
0 xd0,
0 x1f,
0 x15,
0 x13,
0 x7b,
0 x76,
0 x89,
0 x9f,
0 xec,
0 xd0,
0 x43,
0 x3f,
0 x59,
0 x33,
0 x8b,
0 x68,
0 x55,
0 xdd,
0 xb2,
0 x36,
0 x20,
0 x67,
0 x20,
0 x4b,
0 x3b,
0 x30,
0 x42,
0 xdd,
0 x7d,
0 xbc,
0 x8c,
0 x58,
0 x8f,
0 x17,
0 x46,
0 xa0,
0 x85,
};
// Self-signed RSA-2048 certificate, CN=PKCS7 Test, serial 5e0a3d...
static const uint8_t kTestCert[] = {
0 x30,
0 x82,
0 x03,
0 x0a,
0 x30,
0 x82,
0 x01,
0 xf2,
0 xa0,
0 x03,
0 x02,
0 x01,
0 x02,
0 x02,
0 x13,
0 x5e,
0 x0a,
0 x3d,
0 x63,
0 xe7,
0 xc3,
0 xfe,
0 x17,
0 x6c,
0 x21,
0 x8d,
0 x2e,
0 x9e,
0 xc7,
0 xbf,
0 xa3,
0 xa0,
0 xa0,
0 x88,
0 x30,
0 x0d,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x01,
0 x0b,
0 x05,
0 x00,
0 x30,
0 x15,
0 x31,
0 x13,
0 x30,
0 x11,
0 x06,
0 x03,
0 x55,
0 x04,
0 x03,
0 x0c,
0 x0a,
0 x50,
0 x4b,
0 x43,
0 x53,
0 x37,
0 x20,
0 x54,
0 x65,
0 x73,
0 x74,
0 x30,
0 x1e,
0 x17,
0 x0d,
0 x32,
0 x36,
0 x30,
0 x34,
0 x30,
0 x38,
0 x31,
0 x37,
0 x31,
0 x39,
0 x33,
0 x35,
0 x5a,
0 x17,
0 x0d,
0 x33,
0 x36,
0 x30,
0 x34,
0 x30,
0 x35,
0 x31,
0 x37,
0 x31,
0 x39,
0 x33,
0 x35,
0 x5a,
0 x30,
0 x15,
0 x31,
0 x13,
0 x30,
0 x11,
0 x06,
0 x03,
0 x55,
0 x04,
0 x03,
0 x0c,
0 x0a,
0 x50,
0 x4b,
0 x43,
0 x53,
0 x37,
0 x20,
0 x54,
0 x65,
0 x73,
0 x74,
0 x30,
0 x82,
0 x01,
0 x22,
0 x30,
0 x0d,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x01,
0 x01,
0 x05,
0 x00,
0 x03,
0 x82,
0 x01,
0 x0f,
0 x00,
0 x30,
0 x82,
0 x01,
0 x0a,
0 x02,
0 x82,
0 x01,
0 x01,
0 x00,
0 xc5,
0 x2a,
0 xdb,
0 x86,
0 xb0,
0 x2a,
0 x4d,
0 xe0,
0 x52,
0 xb0,
0 x4a,
0 x29,
0 xe2,
0 xe0,
0 xb4,
0 xcc,
0 xf8,
0 x0c,
0 x00,
0 xcd,
0 x0d,
0 x7e,
0 xcc,
0 xb1,
0 xd3,
0 xc8,
0 xa2,
0 x0d,
0 x43,
0 x6d,
0 x06,
0 x07,
0 x22,
0 x49,
0 xec,
0 x86,
0 x21,
0 x85,
0 x68,
0 xf7,
0 x6e,
0 x48,
0 xa3,
0 xe8,
0 x5b,
0 x54,
0 x4d,
0 x0c,
0 x5b,
0 xfb,
0 x80,
0 x07,
0 x10,
0 xab,
0 xe4,
0 xda,
0 x3e,
0 xd6,
0 xec,
0 x08,
0 x3e,
0 x25,
0 x2c,
0 x08,
0 x07,
0 x78,
0 xbf,
0 x1d,
0 x84,
0 xeb,
0 x46,
0 x58,
0 xb1,
0 x29,
0 x9c,
0 x38,
0 xdd,
0 x5f,
0 x48,
0 x78,
0 x5f,
0 x02,
0 xaa,
0 x8f,
0 x4b,
0 x93,
0 xd3,
0 x03,
0 x83,
0 xb6,
0 x68,
0 xa3,
0 xfe,
0 x07,
0 xfc,
0 x67,
0 x8c,
0 xdd,
0 x4f,
0 x86,
0 x88,
0 x80,
0 xfe,
0 xa3,
0 xbf,
0 xc6,
0 x79,
0 x20,
0 xed,
0 xcf,
0 x5f,
0 x2a,
0 x65,
0 xcd,
0 x3c,
0 xf8,
0 x2d,
0 x97,
0 x1b,
0 x63,
0 x0e,
0 xad,
0 x79,
0 xc6,
0 x74,
0 x1d,
0 x66,
0 xcd,
0 x11,
0 xdc,
0 x15,
0 xd0,
0 x46,
0 x0f,
0 xf0,
0 x3b,
0 x70,
0 xca,
0 x69,
0 x74,
0 x70,
0 x87,
0 x8f,
0 xd1,
0 xfe,
0 x3c,
0 xdd,
0 xbc,
0 x34,
0 xb2,
0 xee,
0 x74,
0 xd7,
0 xfe,
0 x10,
0 xbe,
0 x40,
0 xf4,
0 x52,
0 x8f,
0 x77,
0 xbf,
0 xbf,
0 x03,
0 xa7,
0 x36,
0 x62,
0 x96,
0 x10,
0 x4e,
0 x4e,
0 x6a,
0 x1a,
0 x5a,
0 xea,
0 x89,
0 x04,
0 x5b,
0 x3e,
0 x37,
0 x4f,
0 x61,
0 x65,
0 x33,
0 xbe,
0 xa5,
0 x4f,
0 x19,
0 x20,
0 x51,
0 x02,
0 x0b,
0 x59,
0 x12,
0 xcf,
0 x48,
0 xc3,
0 x79,
0 x09,
0 xe8,
0 xc2,
0 x0e,
0 x5d,
0 xec,
0 xbe,
0 x8e,
0 xc9,
0 xf7,
0 xf2,
0 xf5,
0 x4a,
0 xae,
0 x16,
0 xb0,
0 xee,
0 xc8,
0 x5b,
0 x20,
0 x37,
0 xe5,
0 x29,
0 x4f,
0 x15,
0 x40,
0 x5f,
0 x1f,
0 x14,
0 x05,
0 x5c,
0 xb6,
0 x8a,
0 x5d,
0 x44,
0 x45,
0 xb4,
0 x96,
0 x51,
0 xeb,
0 x2b,
0 xa6,
0 xac,
0 xc9,
0 xa1,
0 xbe,
0 xa1,
0 xcf,
0 x53,
0 x9e,
0 x21,
0 xdd,
0 x01,
0 x08,
0 xfc,
0 x05,
0 xfc,
0 x0d,
0 x02,
0 x03,
0 x01,
0 x00,
0 x01,
0 xa3,
0 x53,
0 x30,
0 x51,
0 x30,
0 x1d,
0 x06,
0 x03,
0 x55,
0 x1d,
0 x0e,
0 x04,
0 x16,
0 x04,
0 x14,
0 xad,
0 x27,
0 x48,
0 x83,
0 xbb,
0 xa1,
0 x29,
0 x5c,
0 x0d,
0 xf6,
0 xaf,
0 x20,
0 x06,
0 x72,
0 x27,
0 xe8,
0 x75,
0 x41,
0 x4e,
0 x7c,
0 x30,
0 x1f,
0 x06,
0 x03,
0 x55,
0 x1d,
0 x23,
0 x04,
0 x18,
0 x30,
0 x16,
0 x80,
0 x14,
0 xad,
0 x27,
0 x48,
0 x83,
0 xbb,
0 xa1,
0 x29,
0 x5c,
0 x0d,
0 xf6,
0 xaf,
0 x20,
0 x06,
0 x72,
0 x27,
0 xe8,
0 x75,
0 x41,
0 x4e,
0 x7c,
0 x30,
0 x0f,
0 x06,
0 x03,
0 x55,
0 x1d,
0 x13,
0 x01,
0 x01,
0 xff,
0 x04,
0 x05,
0 x30,
0 x03,
0 x01,
0 x01,
0 xff,
0 x30,
0 x0d,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x01,
0 x0b,
0 x05,
0 x00,
0 x03,
0 x82,
0 x01,
0 x01,
0 x00,
0 x7a,
0 xbd,
0 x2f,
0 x03,
0 x1a,
0 xfb,
0 x56,
0 x6b,
0 x1b,
0 x20,
0 x37,
0 x15,
0 x31,
0 x1b,
0 xd9,
0 x25,
0 xb9,
0 x22,
0 x2e,
0 xc7,
0 x98,
0 x8a,
0 x30,
0 x5c,
0 x9f,
0 xe2,
0 x28,
0 x63,
0 x1b,
0 xc9,
0 x42,
0 x42,
0 xfe,
0 xd0,
0 x2e,
0 x97,
0 xef,
0 xb6,
0 x0b,
0 x83,
0 x9d,
0 x14,
0 x60,
0 xa4,
0 xf1,
0 x1c,
0 x3e,
0 x76,
0 x3f,
0 x20,
0 xf6,
0 x03,
0 x8c,
0 x4e,
0 x8f,
0 x8d,
0 xa7,
0 xca,
0 xc2,
0 x43,
0 x71,
0 xbd,
0 xc7,
0 x35,
0 x28,
0 x9d,
0 x32,
0 xec,
0 x09,
0 x8e,
0 x9d,
0 x10,
0 xa0,
0 xf3,
0 x78,
0 x61,
0 x57,
0 x2c,
0 xc6,
0 x49,
0 x82,
0 x98,
0 x97,
0 x67,
0 xed,
0 x36,
0 xbe,
0 x5e,
0 xa2,
0 x50,
0 xb8,
0 xc9,
0 x83,
0 x2b,
0 xe0,
0 xe6,
0 xfb,
0 xb7,
0 xf9,
0 x30,
0 x6b,
0 xa7,
0 x18,
0 xdf,
0 x6d,
0 xf7,
0 x00,
0 x30,
0 x13,
0 x12,
0 x25,
0 xe5,
0 xcd,
0 x14,
0 x5c,
0 xd3,
0 xbe,
0 x4f,
0 x96,
0 x19,
0 x28,
0 xc0,
0 xa6,
0 xe8,
0 x1f,
0 xe6,
0 x00,
0 x87,
0 x92,
0 xff,
0 x57,
0 xb9,
0 x51,
0 x0e,
0 x2c,
0 xfd,
0 x64,
0 x80,
0 xf7,
0 xd0,
0 x94,
0 xc3,
0 x26,
0 x66,
0 x74,
0 xe3,
0 xdc,
0 xba,
0 x09,
0 x8e,
0 x84,
0 x48,
0 x43,
0 x68,
0 x46,
0 x74,
0 x6f,
0 xcf,
0 x17,
0 x2e,
0 xca,
0 x49,
0 x54,
0 xb9,
0 xa3,
0 xce,
0 x4f,
0 x77,
0 xfc,
0 x1f,
0 x81,
0 x04,
0 x6c,
0 xdb,
0 x33,
0 x6d,
0 xab,
0 xb9,
0 xf7,
0 x8a,
0 x83,
0 x67,
0 x73,
0 x35,
0 x13,
0 x8f,
0 x6f,
0 xa9,
0 xa8,
0 xb7,
0 x97,
0 x31,
0 xcb,
0 x7a,
0 xda,
0 x8c,
0 xd0,
0 xf6,
0 x5a,
0 xd1,
0 x4b,
0 x4f,
0 x23,
0 x69,
0 x88,
0 xef,
0 x49,
0 xe2,
0 xcc,
0 x81,
0 xef,
0 x1c,
0 xdf,
0 x73,
0 x73,
0 xa4,
0 xcb,
0 x5b,
0 x60,
0 x28,
0 x43,
0 xb0,
0 x4d,
0 x8c,
0 x4a,
0 xfd,
0 x2f,
0 xaa,
0 xb9,
0 x41,
0 xa8,
0 xc4,
0 x70,
0 xd2,
0 x25,
0 x49,
0 x16,
0 xfe,
0 xeb,
0 x9c,
0 x21,
0 x32,
0 x7a,
0 x2c,
0 x7b,
0 x76,
0 x1e,
0 x72,
0 xb6,
0 xca,
0 xf4,
0 xdb,
0 x82,
0 x68,
0 x5a,
0 x2e,
};
static PRBool DecryptionAllowed(SECAlgorithmID *
/*alg*/,
PK11SymKey *
/*key*/) {
return PR_TRUE;
}
// Test fixture that imports kTestRsaKey + kTestCert into the internal NSS slot.
class P7EnvelopedDataTest : public ::testing::Test {
protected :
void SetUp() override {
ScopedPK11SlotInfo slot(PK11_GetInternalKeySlot());
ASSERT_NE(nullptr, slot.get());
SECItem key_item = {siBuffer,
const_cast <uint8_t *>(kTestRsaKey),
sizeof (kTestRsaKey)};
ASSERT_EQ(SECSuccess, PK11_ImportDERPrivateKeyInfo(
slot.get(), &key_item, nullptr, nullptr, PR_TRUE,
PR_FALSE, KU_ALL, nullptr));
// Decode the certificate DER into a CERTCertificate, then import it
// permanently into the slot so the PKCS7 decoder can find the key.
SECItem cert_item = {siBuffer,
const_cast <uint8_t *>(kTestCert),
sizeof (kTestCert)};
ScopedCERTCertificate cert(CERT_NewTempCertificate(
CERT_GetDefaultCertDB(), &cert_item, nullptr, PR_FALSE, PR_TRUE));
ASSERT_NE(nullptr, cert.get());
char cert_nick[] =
"p7-test-cert" ;
ASSERT_EQ(SECSuccess,
PK11_ImportCert(slot.get(), cert.get(), CK_INVALID_HANDLE,
cert_nick, PR_FALSE));
// Mark as an email-user cert so pk11_FindCertObjectByRecipient's
// CERTDB_USER trust check passes.
CERTCertTrust trust = {
0 , CERTDB_USER,
0 };
ASSERT_EQ(SECSuccess, CERT_ChangeCertTrust(nullptr, cert.get(), &trust));
}
};
// bug 2029783: when no content callback is provided,
// sec_pkcs7_decoder_work_data accumulates decrypted output in
// envelopedData->encContentInfo.plainContent. Test that reallocation of the
// internal buffer is handled correctly across multiple calls to
// SEC_PKCS7DecoderUpdate.
TEST_F(P7EnvelopedDataTest, MultiChunkDecryptPlaintextCorrect) {
// Split the 451-byte DER so that the first call delivers 25 bytes of
// ciphertext and the second delivers the remaining 31.
const unsigned int splitOffset =
420 ;
// EnvelopedData (DES-EDE3-CBC, RSA-v1.5 key wrap) for kTestCert.
// Plaintext: "plaintext: hello world from pkcs7 enveloped data test\n" (54 B)
// The [0 PRIMITIVE] ciphertext element begins at byte 395, length 56.
const uint8_t envelopedData[] = {
0 x30,
0 x82,
0 x01,
0 xbf,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x07,
0 x03,
0 xa0,
0 x82,
0 x01,
0 xb0,
0 x30,
0 x82,
0 x01,
0 xac,
0 x02,
0 x01,
0 x00,
0 x31,
0 x82,
0 x01,
0 x48,
0 x30,
0 x82,
0 x01,
0 x44,
0 x02,
0 x01,
0 x00,
0 x30,
0 x2c,
0 x30,
0 x15,
0 x31,
0 x13,
0 x30,
0 x11,
0 x06,
0 x03,
0 x55,
0 x04,
0 x03,
0 x0c,
0 x0a,
0 x50,
0 x4b,
0 x43,
0 x53,
0 x37,
0 x20,
0 x54,
0 x65,
0 x73,
0 x74,
0 x02,
0 x13,
0 x5e,
0 x0a,
0 x3d,
0 x63,
0 xe7,
0 xc3,
0 xfe,
0 x17,
0 x6c,
0 x21,
0 x8d,
0 x2e,
0 x9e,
0 xc7,
0 xbf,
0 xa3,
0 xa0,
0 xa0,
0 x88,
0 x30,
0 x0d,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x01,
0 x01,
0 x05,
0 x00,
0 x04,
0 x82,
0 x01,
0 x00,
0 xbb,
0 x9c,
0 xd7,
0 xb3,
0 x8e,
0 x15,
0 x03,
0 x60,
0 x25,
0 xfb,
0 x15,
0 x62,
0 x88,
0 x9b,
0 xdd,
0 xa6,
0 x1a,
0 xc6,
0 xf8,
0 x36,
0 x9e,
0 x65,
0 xd7,
0 x25,
0 xcf,
0 x38,
0 xe4,
0 xe0,
0 x14,
0 x8c,
0 x25,
0 x12,
0 x41,
0 xf9,
0 xad,
0 x9a,
0 x5a,
0 x07,
0 xb8,
0 x56,
0 xfe,
0 xf2,
0 x5f,
0 x53,
0 x78,
0 x64,
0 xe7,
0 xc1,
0 x23,
0 x42,
0 x7b,
0 x1c,
0 x8f,
0 x42,
0 x0b,
0 xa6,
0 x33,
0 x9a,
0 x26,
0 xb6,
0 x41,
0 xbc,
0 xd6,
0 x30,
0 x66,
0 x2e,
0 x93,
0 x17,
0 xb1,
0 x1c,
0 x9d,
0 x44,
0 xf7,
0 x33,
0 xab,
0 xa5,
0 x5c,
0 xf1,
0 xf6,
0 x5c,
0 x79,
0 x44,
0 x17,
0 x80,
0 xf1,
0 xa9,
0 x79,
0 x4f,
0 x22,
0 x83,
0 x29,
0 x7a,
0 xd6,
0 x5f,
0 x8b,
0 x3f,
0 xfa,
0 xb3,
0 xce,
0 xae,
0 xa9,
0 xdf,
0 xa1,
0 xd9,
0 xbd,
0 x1c,
0 xab,
0 xde,
0 x87,
0 x8d,
0 x00,
0 xb5,
0 x97,
0 x5e,
0 xe5,
0 xd9,
0 xc1,
0 xc2,
0 x28,
0 xbb,
0 x16,
0 x70,
0 x01,
0 xea,
0 x73,
0 x68,
0 x86,
0 x66,
0 x4a,
0 x10,
0 x65,
0 x27,
0 x57,
0 xec,
0 x16,
0 xdc,
0 x0d,
0 xfa,
0 x19,
0 x96,
0 x3f,
0 x01,
0 x27,
0 x54,
0 x75,
0 x3f,
0 xfa,
0 xf6,
0 x76,
0 x0d,
0 x18,
0 x03,
0 x5b,
0 x2c,
0 xd4,
0 xcb,
0 x41,
0 xdc,
0 x34,
0 xb7,
0 xed,
0 x2a,
0 x16,
0 x85,
0 xa3,
0 xfb,
0 x0b,
0 xd2,
0 x22,
0 x2e,
0 x8d,
0 xf4,
0 xf9,
0 x21,
0 x52,
0 xa6,
0 x68,
0 xeb,
0 xdb,
0 xb2,
0 xc2,
0 x94,
0 xfe,
0 xb9,
0 xbf,
0 xcf,
0 x04,
0 x26,
0 x73,
0 x29,
0 xbf,
0 x06,
0 xf9,
0 xd9,
0 xfb,
0 x3d,
0 x0d,
0 x03,
0 x49,
0 x39,
0 xc6,
0 x63,
0 x70,
0 x58,
0 x30,
0 x79,
0 x54,
0 x01,
0 x85,
0 x3b,
0 x72,
0 xb9,
0 xc2,
0 x28,
0 x4d,
0 x86,
0 xe1,
0 x02,
0 x92,
0 xb3,
0 x65,
0 x56,
0 xb2,
0 x24,
0 xf3,
0 xda,
0 x90,
0 x9a,
0 xf3,
0 x28,
0 xcb,
0 x8e,
0 x1c,
0 x4d,
0 x96,
0 x08,
0 x81,
0 x2c,
0 xbd,
0 x8b,
0 x8e,
0 xca,
0 xa0,
0 x10,
0 x4f,
0 x1a,
0 xdf,
0 xe7,
0 xf4,
0 x2d,
0 xf8,
0 x53,
0 x24,
0 xd9,
0 x0e,
0 x2e,
0 x30,
0 x5b,
0 x06,
0 x09,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x01,
0 x07,
0 x01,
0 x30,
0 x14,
0 x06,
0 x08,
0 x2a,
0 x86,
0 x48,
0 x86,
0 xf7,
0 x0d,
0 x03,
0 x07,
0 x04,
0 x08,
0 xed,
0 x29,
0 x04,
0 x3e,
0 x0f,
0 xbb,
0 x12,
0 x7c,
0 x80,
0 x38,
0 xc5,
0 xd0,
0 x1a,
0 x1e,
0 xbe,
0 xaa,
0 x15,
0 xb8,
0 xe7,
0 xb7,
0 xe6,
0 xac,
0 x29,
0 xfe,
0 x50,
0 x34,
0 xa4,
0 x47,
0 x93,
0 xe3,
0 xa5,
0 x96,
0 x78,
0 x50,
0 xf9,
0 xa5,
0 x8c,
0 xed,
0 x0e,
0 xa9,
0 xe3,
0 x6b,
0 x61,
0 xf2,
0 x7d,
0 x1a,
0 x07,
0 x4d,
0 xf6,
0 x12,
0 xaf,
0 x9b,
0 xde,
0 xfd,
0 xb9,
0 xaf,
0 xac,
0 xb6,
0 x8d,
0 xfc,
0 x0e,
0 x01,
0 x63,
0 x64,
0 xf5,
0 x57,
};
// Expected decrypted content (55 bytes, CRLF line ending, no NUL terminator).
// DES-EDE3-CBC pads to a multiple of 8: 55 bytes + 1 pad byte = 56 bytes
// ciphertext, so the PKCS#7 pad value is 0x01.
const uint8_t kExpectedPlaintext[] = {
'p' ,
'l' ,
'a' ,
'i' ,
'n' ,
't' ,
'e' ,
'x' ,
't' ,
':' ,
' ' ,
'h' ,
'e' ,
'l' ,
'l' ,
'o' ,
' ' ,
'w' ,
'o' ,
'r' ,
'l' ,
'd' ,
' ' ,
'f' ,
'r' ,
'o' ,
'm' ,
' ' ,
'p' ,
'k' ,
'c' ,
's' ,
'7' ,
' ' ,
'e' ,
'n' ,
'v' ,
'e' ,
'l' ,
'o' ,
'p' ,
'e' ,
'd' ,
' ' ,
'd' ,
'a' ,
't' ,
'a' ,
' ' ,
't' ,
'e' ,
's' ,
't' ,
'\r' ,
'\n' ,
};
ScopedSEC_PKCS7DecoderContext dcx(
SEC_PKCS7DecoderStart(nullptr, nullptr,
// no content callback
nullptr, nullptr,
// no password callback
nullptr, nullptr,
// no key callback
DecryptionAllowed));
ASSERT_TRUE(dcx);
ASSERT_EQ(SECSuccess,
SEC_PKCS7DecoderUpdate(
dcx.get(), reinterpret_cast<
const char *>(envelopedData),
splitOffset));
ASSERT_EQ(SECSuccess,
SEC_PKCS7DecoderUpdate(
dcx.get(),
reinterpret_cast<
const char *>(envelopedData) + splitOffset,
sizeof (envelopedData) - splitOffset));
// SEC_PKCS7DecoderFinish takes ownership of dcx; release() prevents the
// ScopedSEC_PKCS7DecoderContext destructor from calling Finish a second time.
ScopedSEC_PKCS7ContentInfo cinfo(SEC_PKCS7DecoderFinish(dcx.release()));
ASSERT_NE(nullptr, cinfo);
ASSERT_EQ(SEC_OID_PKCS7_ENVELOPED_DATA, SEC_PKCS7ContentType(cinfo.get()));
const SECItem *plain =
&cinfo.get()->content.envelopedData->encContentInfo.plainContent;
ASSERT_EQ(
sizeof (kExpectedPlaintext), plain->len);
EXPECT_EQ(
0 , memcmp(plain->data, kExpectedPlaintext,
sizeof (kExpectedPlaintext)));
}
}
// namespace nss_test
Messung V0.5 in Prozent C=93 H=98 G=95
¤ Dauer der Verarbeitung: 0.20 Sekunden
¤
*© Formatika GbR, Deutschland