x509test.c 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398
  1. /*
  2. * Copyright 2014-2022 The GmSSL Project. All Rights Reserved.
  3. *
  4. * Licensed under the Apache License, Version 2.0 (the License); you may
  5. * not use this file except in compliance with the License.
  6. *
  7. * http://www.apache.org/licenses/LICENSE-2.0
  8. */
  9. #include <stdio.h>
  10. #include <string.h>
  11. #include <stdlib.h>
  12. #include <gmssl/oid.h>
  13. #include <gmssl/x509_alg.h>
  14. #include <gmssl/x509.h>
  15. #include <gmssl/rand.h>
  16. #include <gmssl/error.h>
  17. static int test_x509_version(void)
  18. {
  19. int tests[] = {
  20. X509_version_v1,
  21. X509_version_v2,
  22. X509_version_v3,
  23. -1,
  24. };
  25. uint8_t buf[256];
  26. uint8_t *p = buf;
  27. const uint8_t *cp = buf;
  28. size_t len = 0;
  29. int i;
  30. format_print(stderr, 0, 0, "Version\n");
  31. for (i = 0; i < sizeof(tests)/sizeof(tests[0]); i++) {
  32. if (x509_explicit_version_to_der(i, tests[i], &p, &len) < 0) {
  33. error_print();
  34. return -1;
  35. }
  36. format_bytes(stderr, 0, 4, "", buf, len);
  37. }
  38. for (i = 0; i < sizeof(tests)/sizeof(tests[0]); i++) {
  39. int ver;
  40. if (x509_explicit_version_from_der(i, &ver, &cp, &len) < 0
  41. || asn1_check(ver == tests[i]) != 1) {
  42. error_print();
  43. return -1;
  44. }
  45. format_print(stderr, 0, 4, "%s\n", x509_version_name(ver));
  46. }
  47. (void)asn1_length_is_zero(len);
  48. printf("%s() ok\n", __FUNCTION__);
  49. return 0;
  50. }
  51. static int test_x509_validity(void)
  52. {
  53. time_t not_before, not_before_;
  54. time_t not_after, not_after_;
  55. uint8_t buf[256];
  56. uint8_t *p = buf;
  57. const uint8_t *cp = buf;
  58. size_t len = 0;
  59. time(&not_before);
  60. format_print(stderr, 0, 0, "Validity\n");
  61. if (x509_validity_add_days(&not_after, not_before, 365) != 1
  62. || x509_validity_to_der(not_before, not_after, &p, &len) != 1) {
  63. error_print();
  64. return -1;
  65. }
  66. format_bytes(stderr, 0, 4, "", buf, len);
  67. if (x509_validity_from_der(&not_before_, &not_after_, &cp, &len) != 1
  68. || asn1_check(not_before == not_before_) != 1
  69. || asn1_check(not_after == not_after_) != 1
  70. || asn1_length_is_zero(len) != 1) {
  71. error_print();
  72. return 1;
  73. }
  74. printf("%s() ok\n", __FUNCTION__);
  75. return 0;
  76. }
  77. static int test_x509_attr_type_and_value(void)
  78. {
  79. int oid;
  80. int tag;
  81. const uint8_t *d;
  82. size_t dlen;
  83. uint8_t buf[256];
  84. uint8_t *p = buf;
  85. const uint8_t *cp = buf;
  86. size_t len = 0;
  87. format_print(stderr, 0, 0, "AttributeTypeAndValue\n");
  88. if (x509_attr_type_and_value_to_der(OID_at_locality_name, ASN1_TAG_PrintableString, (uint8_t *)"Haidian", strlen("Haidian"), &p, &len) != 1) {
  89. error_print();
  90. return -1;
  91. }
  92. format_bytes(stderr, 0, 4, "", buf, len);
  93. if (x509_attr_type_and_value_from_der(&oid, &tag, &d, &dlen, &cp, &len) != 1
  94. || asn1_check(oid == OID_at_locality_name) != 1
  95. || asn1_check(tag == ASN1_TAG_PrintableString) != 1
  96. || asn1_check(dlen == strlen("Haidian")) != 1
  97. || asn1_check(memcmp("Haidian", d, dlen) == 0) != 1
  98. || asn1_length_is_zero(len) != 1) {
  99. error_print();
  100. return -1;
  101. }
  102. format_print(stderr, 0, 4, "%s : %s ", x509_name_type_name(oid), asn1_tag_name(tag));
  103. format_string(stderr, 0, 0, "", d, dlen);
  104. printf("%s() ok\n", __FUNCTION__);
  105. return 0;
  106. }
  107. static int test_x509_rdn(void)
  108. {
  109. int oid;
  110. int tag;
  111. const uint8_t *d;
  112. size_t dlen;
  113. const uint8_t *more;
  114. size_t morelen;
  115. uint8_t buf[256];
  116. uint8_t *p = buf;
  117. const uint8_t *cp = buf;
  118. size_t len = 0;
  119. format_print(stderr, 0, 0, "RDN\n");
  120. if (x509_rdn_to_der(OID_at_locality_name, ASN1_TAG_PrintableString,
  121. (uint8_t *)"Haidian", strlen("Haidian"), NULL, 0, &p, &len) != 1) {
  122. error_print();
  123. return -1;
  124. }
  125. format_bytes(stderr, 0, 4, "", buf, len);
  126. if (x509_rdn_from_der(&oid, &tag, &d, &dlen, &more, &morelen, &cp, &len) != 1
  127. || asn1_check(oid == OID_at_locality_name) != 1
  128. || asn1_check(tag == ASN1_TAG_PrintableString) != 1
  129. || asn1_check(dlen == strlen("Haidian")) != 1
  130. || asn1_check(memcmp("Haidian", d, dlen) == 0) != 1
  131. || asn1_check(more == NULL) != 1
  132. || asn1_check(morelen == 0) != 1
  133. || asn1_length_is_zero(len) != 1) {
  134. error_print();
  135. return -1;
  136. }
  137. format_print(stderr, 0, 4, "%s : %s ", x509_name_type_name(oid), asn1_tag_name(tag));
  138. format_string(stderr, 0, 0, "", d, dlen);
  139. printf("%s() ok\n", __FUNCTION__);
  140. return 0;
  141. }
  142. static int test_x509_name(void)
  143. {
  144. int err = 0;
  145. uint8_t name[512];
  146. size_t namelen = 0;
  147. uint8_t buf[1024];
  148. const uint8_t *cp = buf;
  149. uint8_t *p = buf;
  150. size_t len = 0;
  151. if (x509_name_add_country_name(name, &namelen, sizeof(name), "CN") != 1
  152. || format_bytes(stderr, 0, 4, "", name, namelen) > 2
  153. || x509_name_add_locality_name(name, &namelen, sizeof(name), ASN1_TAG_PrintableString, (uint8_t *)"Haidian", strlen("Haidian")) != 1
  154. || format_bytes(stderr, 0, 4, "", name, namelen) > 2
  155. || x509_name_add_state_or_province_name(name, &namelen, sizeof(name), ASN1_TAG_PrintableString, (uint8_t *)"Beijing", strlen("Beijing")) != 1
  156. || format_bytes(stderr, 0, 4, "", name, namelen) > 2
  157. || x509_name_add_organization_name(name, &namelen, sizeof(name), ASN1_TAG_PrintableString, (uint8_t *)"PKU", strlen("PKU")) != 1
  158. || format_bytes(stderr, 0, 4, "", name, namelen) > 2
  159. || x509_name_add_organizational_unit_name(name, &namelen, sizeof(name), ASN1_TAG_PrintableString, (uint8_t *)"CS", strlen("CS")) != 1
  160. || format_bytes(stderr, 0, 4, "", name, namelen) > 2
  161. || x509_name_add_common_name(name, &namelen, sizeof(name), ASN1_TAG_PrintableString, (uint8_t *)"CA", strlen("CA")) != 1
  162. || format_bytes(stderr, 0, 4, "", name, namelen) > 2
  163. ) {
  164. error_print();
  165. return 1;
  166. }
  167. format_bytes(stdout, 0, 0, "der ", name, namelen);
  168. x509_name_print(stdout, 0, 0, "Name", name, namelen);
  169. return 0;
  170. }
  171. static int test_x509_public_key_info(void)
  172. {
  173. int err = 0;
  174. SM2_KEY sm2_key;
  175. SM2_KEY pub_key;
  176. uint8_t buf[256];
  177. const uint8_t *cp = buf;
  178. uint8_t *p = buf;
  179. size_t len = 0;
  180. const uint8_t *d;
  181. size_t dlen;
  182. if (sm2_key_generate(&sm2_key) != 1
  183. || x509_public_key_info_to_der(&sm2_key, &p, &len) != 1
  184. || asn1_sequence_from_der(&d, &dlen, &cp, &len) != 1
  185. || asn1_length_is_zero(len) != 1) {
  186. error_print();
  187. return 1;
  188. }
  189. x509_public_key_info_print(stdout, 0, 0, "PublicKeyInfo", d, dlen);
  190. if (sm2_key_generate(&sm2_key) != 1
  191. || x509_public_key_info_to_der(&sm2_key, &p, &len) != 1
  192. || x509_public_key_info_from_der(&pub_key, &cp, &len) != 1
  193. || asn1_length_is_zero(len) != 1) {
  194. error_print();
  195. return 1;
  196. }
  197. sm2_public_key_print(stdout, 0, 8, "ECPublicKey", &pub_key);
  198. printf("%s() ok\n", __FUNCTION__);
  199. return 0;
  200. }
  201. static int set_x509_name(uint8_t *name, size_t *namelen, size_t maxlen)
  202. {
  203. *namelen = 0;
  204. if (x509_name_add_country_name(name, namelen, maxlen, "CN") != 1
  205. || x509_name_add_locality_name(name, namelen, maxlen, ASN1_TAG_PrintableString, (uint8_t *)"Haidian", strlen("Haidian")) != 1
  206. || x509_name_add_state_or_province_name(name, namelen, maxlen, ASN1_TAG_PrintableString, (uint8_t *)"Beijing", strlen("Beijing")) != 1
  207. || x509_name_add_organization_name(name, namelen, maxlen, ASN1_TAG_PrintableString, (uint8_t *)"PKU", strlen("PKU")) != 1
  208. || x509_name_add_organizational_unit_name(name, namelen, maxlen, ASN1_TAG_PrintableString, (uint8_t *)"CS", strlen("CS")) != 1
  209. || x509_name_add_common_name(name, namelen, maxlen, ASN1_TAG_PrintableString, (uint8_t *)"CA", strlen("CA")) != 1) {
  210. error_print();
  211. return -1;
  212. }
  213. return 1;
  214. }
  215. static int test_x509_tbs_cert(void)
  216. {
  217. uint8_t serial[20] = { 0x01, 0x00 };
  218. uint8_t issuer[256];
  219. size_t issuer_len = 0;
  220. time_t not_before, not_after;
  221. uint8_t subject[256];
  222. size_t subject_len = 0;
  223. SM2_KEY sm2_key;
  224. uint8_t buf[1024] = {0};
  225. uint8_t *p = buf;
  226. const uint8_t *cp = buf;
  227. size_t len = 0;
  228. const uint8_t *d;
  229. size_t dlen;
  230. set_x509_name(issuer, &issuer_len, sizeof(issuer));
  231. time(&not_before);
  232. x509_validity_add_days(&not_after, not_before, 365);
  233. set_x509_name(subject, &subject_len, sizeof(subject));
  234. sm2_key_generate(&sm2_key);
  235. if (x509_tbs_cert_to_der(
  236. X509_version_v3,
  237. serial, sizeof(serial),
  238. OID_sm2sign_with_sm3,
  239. issuer, issuer_len,
  240. not_before, not_after,
  241. subject, subject_len,
  242. &sm2_key,
  243. NULL, 0,
  244. NULL, 0,
  245. NULL, 0,
  246. &p, &len) != 1) {
  247. error_print();
  248. return -1;
  249. }
  250. format_bytes(stderr, 0, 0, "tbs_cert", buf, len);
  251. if (asn1_sequence_from_der(&d, &dlen, &cp, &len) != 1
  252. || asn1_length_is_zero(len) != 1) {
  253. error_print();
  254. return -1;
  255. }
  256. x509_tbs_cert_print(stderr, 0, 4, "TBSCertificate", d, dlen);
  257. return 0;
  258. }
  259. static int test_x509_cert_get(const uint8_t *cert, size_t certlen)
  260. {
  261. const uint8_t *serial;
  262. size_t serial_len;
  263. const uint8_t *issuer;
  264. size_t issuer_len;
  265. const uint8_t *subject;
  266. size_t subject_len;
  267. SM2_KEY public_key;
  268. if (x509_cert_get_issuer_and_serial_number(cert, certlen, &issuer, &issuer_len, &serial, &serial_len) != 1
  269. || x509_cert_get_subject(cert, certlen, &subject, &subject_len) != 1
  270. || x509_cert_get_subject_public_key(cert, certlen, &public_key) != 1) {
  271. error_print();
  272. return -1;
  273. }
  274. format_bytes(stderr, 0, 4, "SerialNumber", serial, serial_len);
  275. x509_name_print(stderr, 0, 4, "Issuer", issuer, issuer_len);
  276. x509_name_print(stderr, 0, 4, "Subject", subject, subject_len);
  277. sm2_public_key_print(stderr, 0, 4, "SubjectPublicKey", &public_key);
  278. return 0;
  279. }
  280. static int test_x509_cert(void)
  281. {
  282. uint8_t serial[20] = { 0x01, 0x00 };
  283. uint8_t issuer[256];
  284. size_t issuer_len = 0;
  285. time_t not_before, not_after;
  286. uint8_t subject[256];
  287. size_t subject_len = 0;
  288. SM2_KEY sm2_key;
  289. uint8_t cert[1024] = {0};
  290. uint8_t *p = cert;
  291. const uint8_t *cp = cert;
  292. size_t certlen = 0;
  293. set_x509_name(issuer, &issuer_len, sizeof(issuer));
  294. time(&not_before);
  295. x509_validity_add_days(&not_after, not_before, 365);
  296. set_x509_name(subject, &subject_len, sizeof(subject));
  297. sm2_key_generate(&sm2_key);
  298. if (x509_cert_sign_to_der(
  299. X509_version_v3,
  300. serial, sizeof(serial),
  301. OID_sm2sign_with_sm3,
  302. issuer, issuer_len,
  303. not_before, not_after,
  304. subject, subject_len,
  305. &sm2_key,
  306. NULL, 0,
  307. NULL, 0,
  308. NULL, 0,
  309. &sm2_key, SM2_DEFAULT_ID, strlen(SM2_DEFAULT_ID),
  310. &p, &certlen) != 1) {
  311. error_print();
  312. return -1;
  313. }
  314. format_bytes(stderr, 0, 4, "cert", cert, certlen);
  315. x509_cert_print(stderr, 0, 4, "Certificate", cert, certlen);
  316. /*
  317. // TODO: use the same cert to verify?
  318. if (x509_cert_verify(cert, certlen, &sm2_key, SM2_DEFAULT_ID, strlen(SM2_DEFAULT_ID)) != 1) {
  319. error_print();
  320. return -1;
  321. }
  322. printf("x509_cert_verify() success\n");
  323. */
  324. test_x509_cert_get(cert, certlen);
  325. FILE *fp;
  326. if (!(fp = fopen("cert.pem", "w"))) {
  327. error_print();
  328. return -1;
  329. }
  330. x509_cert_to_pem(cert, certlen, fp);
  331. x509_cert_to_pem(cert, certlen, stderr);
  332. fclose(fp);
  333. if (!(fp = fopen("cert.pem", "r"))) {
  334. error_print();
  335. return -1;
  336. }
  337. memset(cert, 0, sizeof(cert));
  338. if (x509_cert_from_pem(cert, &certlen, sizeof(cert), fp) != 1) {
  339. error_print();
  340. return -1;
  341. }
  342. x509_cert_print(stderr, 0, 4, "Certificate", cert, certlen);
  343. return 0;
  344. }
  345. int main(void)
  346. {
  347. int err = 0;
  348. err += test_x509_version();
  349. err += test_x509_validity();
  350. err += test_x509_attr_type_and_value();
  351. err += test_x509_rdn();
  352. err += test_x509_name();
  353. err += test_x509_public_key_info();
  354. err += test_x509_tbs_cert();
  355. err += test_x509_cert();
  356. return err;
  357. }