2016-04-22 19:21:51 +08:00
|
|
|
#! /usr/bin/env perl
|
2021-01-20 19:59:53 +08:00
|
|
|
# Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.
|
2016-04-22 19:21:51 +08:00
|
|
|
#
|
2018-12-06 20:05:25 +08:00
|
|
|
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
2016-04-22 19:21:51 +08:00
|
|
|
# this file except in compliance with the License. You can obtain a copy
|
|
|
|
# in the file LICENSE in the source distribution or at
|
|
|
|
# https://www.openssl.org/source/license.html
|
|
|
|
|
2015-04-18 02:13:58 +08:00
|
|
|
|
|
|
|
use strict;
|
|
|
|
use warnings;
|
|
|
|
|
|
|
|
use File::Spec;
|
2016-01-30 08:05:33 +08:00
|
|
|
use OpenSSL::Test qw/:DEFAULT srctop_file/;
|
2015-09-20 05:19:14 +08:00
|
|
|
use OpenSSL::Test::Utils;
|
2015-04-18 02:13:58 +08:00
|
|
|
|
|
|
|
setup("test_ec");
|
|
|
|
|
2021-01-20 19:59:53 +08:00
|
|
|
plan skip_all => 'EC is not supported in this build' if disabled('ec');
|
|
|
|
|
2022-07-01 22:35:44 +08:00
|
|
|
plan tests => 15;
|
|
|
|
|
|
|
|
my $no_fips = disabled('fips') || ($ENV{NO_FIPS} // 0);
|
2015-04-18 02:13:58 +08:00
|
|
|
|
2016-01-30 08:05:33 +08:00
|
|
|
require_ok(srctop_file('test','recipes','tconversion.pl'));
|
2015-04-18 02:13:58 +08:00
|
|
|
|
|
|
|
ok(run(test(["ectest"])), "running ectest");
|
|
|
|
|
2020-02-12 08:10:44 +08:00
|
|
|
# TODO: remove these when the 'ec' app is removed.
|
|
|
|
# Also consider moving this to the 20-25 test section because it is testing
|
|
|
|
# the command line tool in addition to the algorithm.
|
2021-01-20 19:59:53 +08:00
|
|
|
subtest 'EC conversions -- private key' => sub {
|
|
|
|
tconversion( -type => 'ec', -prefix => 'ec-priv',
|
|
|
|
-in => srctop_file("test","testec-p256.pem") );
|
|
|
|
};
|
|
|
|
subtest 'EC conversions -- private key PKCS#8' => sub {
|
|
|
|
tconversion( -type => 'ec', -prefix => 'ec-pkcs8',
|
|
|
|
-in => srctop_file("test","testec-p256.pem"),
|
|
|
|
-args => "pkey" );
|
|
|
|
};
|
|
|
|
subtest 'EC conversions -- public key' => sub {
|
|
|
|
tconversion( -type => 'ec', -prefix => 'ec-pub',
|
|
|
|
-in => srctop_file("test","testecpub-p256.pem"),
|
|
|
|
-args => [ "ec", "-pubin", "-pubout" ] );
|
|
|
|
};
|
2019-11-11 18:13:10 +08:00
|
|
|
|
2021-01-20 19:59:53 +08:00
|
|
|
subtest 'PKEY conversions -- private key' => sub {
|
|
|
|
tconversion( -type => 'pkey', -prefix => 'ec-pkey-priv',
|
|
|
|
-in => srctop_file("test","testec-p256.pem") );
|
|
|
|
};
|
|
|
|
subtest 'PKEY conversions -- private key PKCS#8' => sub {
|
|
|
|
tconversion( -type => 'pkey', -prefix => 'ec-pkey-pkcs8',
|
|
|
|
-in => srctop_file("test","testec-p256.pem"),
|
|
|
|
-args => "pkey" );
|
|
|
|
};
|
|
|
|
subtest 'PKEY conversions -- public key' => sub {
|
|
|
|
tconversion( -type => 'pkey', -prefix => 'ec-pkey-pub',
|
|
|
|
-in => srctop_file("test","testecpub-p256.pem"),
|
|
|
|
-args => [ "pkey", "-pubin", "-pubout" ] );
|
|
|
|
};
|
2019-11-11 18:13:10 +08:00
|
|
|
|
2021-01-20 19:59:53 +08:00
|
|
|
subtest 'Ed25519 conversions -- private key' => sub {
|
|
|
|
tconversion( -type => "pkey", -prefix => "ed25519-pkey-priv",
|
|
|
|
-in => srctop_file("test", "tested25519.pem") );
|
|
|
|
};
|
|
|
|
subtest 'Ed25519 conversions -- private key PKCS#8' => sub {
|
|
|
|
tconversion( -type => "pkey", -prefix => "ed25519-pkey-pkcs8",
|
|
|
|
-in => srctop_file("test", "tested25519.pem"),
|
|
|
|
-args => ["pkey"] );
|
|
|
|
};
|
|
|
|
subtest 'Ed25519 conversions -- public key' => sub {
|
|
|
|
tconversion( -type => "pkey", -prefix => "ed25519-pkey-pub",
|
|
|
|
-in => srctop_file("test", "tested25519pub.pem"),
|
|
|
|
-args => ["pkey", "-pubin", "-pubout"] );
|
|
|
|
};
|
|
|
|
subtest 'Ed448 conversions -- private key' => sub {
|
|
|
|
tconversion( -type => "pkey", -prefix => "ed448-pkey-priv",
|
|
|
|
-in => srctop_file("test", "tested448.pem") );
|
|
|
|
};
|
|
|
|
subtest 'Ed448 conversions -- private key PKCS#8' => sub {
|
|
|
|
tconversion( -type => "pkey", -prefix => "ed448-pkey-pkcs8",
|
|
|
|
-in => srctop_file("test", "tested448.pem"),
|
|
|
|
-args => ["pkey"] );
|
|
|
|
};
|
|
|
|
subtest 'Ed448 conversions -- public key' => sub {
|
|
|
|
tconversion( -type => "pkey", -prefix => "ed448-pkey-pub",
|
|
|
|
-in => srctop_file("test", "tested448pub.pem"),
|
|
|
|
-args => ["pkey", "-pubin", "-pubout"] );
|
|
|
|
};
|
2022-07-01 22:35:44 +08:00
|
|
|
|
|
|
|
subtest 'Check loading of fips and non-fips keys' => sub {
|
|
|
|
plan skip_all => "FIPS is disabled"
|
|
|
|
if $no_fips;
|
|
|
|
|
|
|
|
plan tests => 2;
|
|
|
|
|
|
|
|
my $fipsconf = srctop_file("test", "fips-and-base.cnf");
|
|
|
|
$ENV{OPENSSL_CONF} = $fipsconf;
|
|
|
|
|
|
|
|
ok(!run(app(['openssl', 'pkey',
|
|
|
|
'-check', '-in', srctop_file("test", "testec-p112r1.pem")])),
|
|
|
|
"Checking non-fips curve key fails in FIPS provider");
|
|
|
|
|
|
|
|
ok(run(app(['openssl', 'pkey',
|
|
|
|
'-provider', 'default',
|
|
|
|
'-propquery', '?fips!=yes',
|
|
|
|
'-check', '-in', srctop_file("test", "testec-p112r1.pem")])),
|
|
|
|
"Checking non-fips curve key succeeds with non-fips property query");
|
|
|
|
|
|
|
|
delete $ENV{OPENSSL_CONF};
|
|
|
|
}
|