openssl/test
Simo Sorce 6922740fac Add SSKDF test vectors from RFC 8636
RFC 8636 defines the Pkinit Agility KDF, which turns out to be just a
standard SSKDF with the Info built out of the ASN.1 option of SP 800 56A
(See 5.8.2.1.2 of NIST SP 800-56A Rev. 3)

RFC 8636 Also defines test vectors, so let's add them in addition to the
tests from "non-official" test vectors.

Signed-off-by: Simo Sorce <simo@redhat.com>

Reviewed-by: Shane Lontis <shane.lontis@oracle.com>
Reviewed-by: Richard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/9957)
2019-09-23 09:10:11 -04:00
..
certs Add Restricted PSS certificate and key 2019-08-09 13:19:16 +01:00
ct
d2i-tests
ocsp-tests
ossl_shim Build: Change all _NO_INST to use attributes instead. 2019-01-22 12:35:39 +01:00
recipes Add SSKDF test vectors from RFC 8636 2019-09-23 09:10:11 -04:00
smime-certs Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
ssl-tests Add TLS tests for RSA-PSS Restricted certificates 2019-08-09 13:19:16 +01:00
testutil Extend tests of SSL_check_chain() 2019-08-09 17:29:39 +01:00
aborttest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
aesgcmtest.c Add EVP_CIPHER_CTX_tag_length() 2019-09-11 17:52:30 +10:00
afalgtest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
asn1_decode_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
asn1_dsa_internal_test.c Add simple ASN.1 utils for DSA signature DER. 2019-07-12 06:26:46 +10:00
asn1_encode_test.c fix truncation of integers on 32bit AIX 2019-03-11 14:45:18 +01:00
asn1_internal_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
asn1_string_table_test.c typo ANS1 -> ASN1 2018-12-11 20:57:31 +10:00
asn1_time_test.c Fix Typos 2019-07-02 14:22:29 +02:00
asynciotest.c Make the PACKET/WPACKET code available to both libcrypto and libssl 2019-07-12 06:26:46 +10:00
asynctest.c add an additional async notification communication method based on callback 2019-01-27 12:27:17 +00:00
bad_dtls_test.c Make the PACKET/WPACKET code available to both libcrypto and libssl 2019-07-12 06:26:46 +10:00
bftest.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
bio_callback_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
bio_enc_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
bio_memleak_test.c Fix and document BIO_FLAGS_NONCLEAR_RST behavior on memory BIO 2019-06-19 14:29:27 +02:00
bioprinttest.c fix truncation of integers on 32bit AIX 2019-03-11 14:45:18 +01:00
bn_internal_test.c removed BN_clear NULL checks 2019-03-20 09:17:42 +10:00
bn_rand_range.h Test of uniformity of BN_rand_range output. 2019-05-29 09:54:29 +10:00
bntest.c Remove tab characters from C source files. 2019-07-16 20:24:10 +10:00
bntests.pl Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
build.info Add fips module integrity check 2019-09-15 19:55:10 +10:00
CAss.cnf
CAssdh.cnf
CAssdsa.cnf
CAssrsa.cnf
casttest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
CAtsa.cnf
chacha_internal_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
cipher_overhead_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
cipherbytes_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
cipherlist_test.c Ignore cipher suites when setting cipher list 2019-02-14 13:54:56 +00:00
ciphername_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
clienthellotest.c Test SSL_set_ciphersuites 2019-08-15 14:33:06 +01:00
cms-examples.pl Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
cmsapitest.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
conf_include_test.c Fix Typos 2019-07-01 10:09:22 +02:00
constant_time_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
context_internal_test.c Instead of global data store it in an OPENSSL_CTX 2019-05-02 22:42:09 +01:00
crltest.c Fix a memory leak with di2_X509_CRL reuse 2019-01-31 19:10:57 +01:00
ct_test.c Extend tests of SSL_check_chain() 2019-08-09 17:29:39 +01:00
ctype_internal_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
curve448_internal_test.c Make the EC code available from inside the FIPS provider 2019-08-06 11:19:07 +01:00
d2i_test.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
danetest.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
danetest.in Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
danetest.pem
default-and-fips.cnf Add fips module integrity check 2019-09-15 19:55:10 +10:00
default-and-legacy.cnf test/recipes/30-test_evp.t: Modify to test with different providers 2019-07-26 18:14:41 +02:00
default.cnf test/recipes/30-test_evp.t: Modify to test with different providers 2019-07-26 18:14:41 +02:00
destest.c add missing const 2018-12-09 22:02:48 -05:00
dhtest.c Check the DH modulus bit length 2019-09-09 14:43:57 +02:00
drbg_cavs_data_ctr.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
drbg_cavs_data_hash.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
drbg_cavs_data_hmac.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
drbg_cavs_data.h Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
drbg_cavs_test.c Remove tab characters from C source files. 2019-07-16 20:24:10 +10:00
drbgtest.c drbg: ensure fork-safety without using a pthread_atfork handler 2019-09-11 11:22:18 +02:00
drbgtest.h Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
dsa_no_digest_size_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
dsatest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
dtls_mtu_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
dtlstest.c Fix Typos 2019-07-02 14:22:29 +02:00
dtlsv1listentest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
ec_internal_test.c [test] unit test for field_inv function pointer in EC_METHOD 2019-02-17 21:02:36 +02:00
ecdsatest.c EC only uses approved curves in FIPS mode. 2019-06-25 12:00:25 +10:00
ecdsatest.h [test] modernize ecdsatest and extend ECDSA sign KATs 2019-02-26 17:59:51 +02:00
ecstresstest.c Remove tab characters from C source files. 2019-07-16 20:24:10 +10:00
ectest.c [test] ECC: check the bounds for auto computing cofactor 2019-09-09 18:10:10 +03:00
enginetest.c test/enginetest.c: Make sure no config file is loaded 2019-07-19 20:18:34 +02:00
errtest.c Modernise the ERR functionality further (new functions and deprecations) 2019-09-12 17:59:52 +02:00
evp_extra_test.c Add fips module integrity check 2019-09-15 19:55:10 +10:00
evp_fetch_prov_test.c Add fips module integrity check 2019-09-15 19:55:10 +10:00
evp_kdf_test.c Update tests to (mostly) use KDF names 2019-09-11 10:22:49 +10:00
evp_pkey_dparams_test.c EC only uses approved curves in FIPS mode. 2019-06-25 12:00:25 +10:00
evp_test.c Modernise the ERR functionality further (new functions and deprecations) 2019-09-12 17:59:52 +02:00
evp_test.h Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
exdatatest.c Add CRYPTO_alloc_ex_data() 2019-02-16 00:29:20 +01:00
exptest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
fatalerrtest.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
fips.cnf Add fips module integrity check 2019-09-15 19:55:10 +10:00
generate_buildtest.pl Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
generate_ssl_tests.pl Rework the perl fallback functionality 2019-09-12 12:49:31 +02:00
gmdifftest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
gosttest.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
handshake_helper.c Fix end-point shared secret for DTLS/SCTP 2019-02-01 11:57:19 +00:00
handshake_helper.h Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
hmactest.c Cleaner disposal of ephemeral engine ids and names 2018-12-09 22:02:48 -05:00
ideatest.c add missing const in cast 2018-12-09 22:02:49 -05:00
igetest.c Deprecate AES_ige_encrypt() and AES_bi_ige_encrypt() 2019-04-12 14:22:41 +01:00
legacy.cnf test/recipes/30-test_evp.t: Modify to test with different providers 2019-07-26 18:14:41 +02:00
lhash_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
md2test.c Add a legacy provider and put MD2 in it 2019-04-09 10:24:43 +01:00
mdc2_internal_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
mdc2test.c Change provider params from int to size_t 2019-09-05 11:23:57 +10:00
memleaktest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
modes_internal_test.c Add Common shared code needed to move aes ciphers to providers 2019-07-16 09:46:14 +10:00
namemap_internal_test.c OSSL_NAMEMAP: make names case insensitive 2019-06-24 10:58:13 +02:00
ocspapitest.c OCSP: fix memory leak in OCSP_url_svcloc_new method. 2019-05-27 08:11:50 +10:00
ossl_test_endian.h Fix test builds. 2019-03-28 15:02:19 +10:00
P1ss.cnf
P2ss.cnf
p_test.c Rename provider and core get_param_types functions 2019-08-15 11:58:25 +02:00
packettest.c Make the PACKET/WPACKET code available to both libcrypto and libssl 2019-07-12 06:26:46 +10:00
param_build_test.c Add param builder free function. 2019-07-19 01:14:07 +10:00
params_api_test.c Change OSSL_PARAM return size to not be a pointer. 2019-06-24 14:43:55 +10:00
params_conversion_test.c Change OSSL_PARAM return size to not be a pointer. 2019-06-24 14:43:55 +10:00
params_test.c Fix Typos 2019-07-02 14:22:29 +02:00
pbelutest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
pemtest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
pkcs7-1.pem
pkcs7.pem
pkey_meth_kdf_test.c Added new EVP/KDF API. 2019-02-13 12:11:49 +01:00
pkey_meth_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
pkits-test.pl Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
poly1305_internal_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
property_test.c Modify ossl_method_store_add() to accept an OSSL_PROVIDER and check for it 2019-08-22 01:50:30 +02:00
provider_internal_test.c Load the config file by default 2019-08-01 09:59:20 +01:00
provider_internal_test.conf.in Add test for the provider configuration module 2019-04-03 11:42:48 +02:00
provider_test.c Change OSSL_PARAM return size to not be a pointer. 2019-06-24 14:43:55 +10:00
rc2test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
rc4test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
rc5test.c Change RC5_32_set_key to return an int type 2019-07-01 10:18:37 +01:00
rdrand_sanitytest.c Remove extern declarations of OPENSSL_ia32cap_P 2019-09-01 15:41:58 +02:00
README Update test/README 2019-06-20 17:16:50 +10:00
README.external Remove unnecessary trailing whitespace 2019-02-05 16:25:11 +01:00
README.ssltest.md
recordlentest.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
rsa_complex.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
rsa_mp_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
rsa_sp800_56b_test.c removed BN_clear NULL checks 2019-03-20 09:17:42 +10:00
rsa_test.c FIPS 186-4 RSA Generation & Validation 2019-03-12 12:00:52 +00:00
run_tests.pl Rework test/run_tests.pl to support selective verbosity and TAP copy 2019-09-12 14:38:00 +02:00
sanitytest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
secmemtest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
serverinfo2.pem
serverinfo.pem
servername_test.c Make the PACKET/WPACKET code available to both libcrypto and libssl 2019-07-12 06:26:46 +10:00
session.pem
shibboleth.pfx
shlibloadtest.c Introduce a no-pinshared option 2019-01-04 13:19:39 +00:00
siphash_internal_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
sm2_internal_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
sm4_internal_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
smcont.txt
sparse_array_test.c Fix BIO_printf format warnings 2019-07-30 20:41:30 +02:00
srptest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
ssl_cert_table_internal_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
ssl_test_ctx_test.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
ssl_test_ctx_test.conf
ssl_test_ctx.c Fix end-point shared secret for DTLS/SCTP 2019-02-01 11:57:19 +00:00
ssl_test_ctx.h Fix end-point shared secret for DTLS/SCTP 2019-02-01 11:57:19 +00:00
ssl_test.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
ssl_test.tmpl
sslapitest.c Fix no-ec 2019-08-29 11:07:30 +01:00
sslbuffertest.c Make the PACKET/WPACKET code available to both libcrypto and libssl 2019-07-12 06:26:46 +10:00
sslcorrupttest.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
ssltest_old.c Remove NextStep support 2019-07-01 13:32:46 -04:00
ssltestlib.c Fix Typos 2019-07-02 14:22:29 +02:00
ssltestlib.h Write a test for receiving a KeyUpdate (update requested) while writing 2019-06-03 11:51:14 +01:00
Sssdsa.cnf
Sssrsa.cnf
stack_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
sysdefault.cnf
sysdefaulttest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
test_test.c Fix --strict-warnings build 2019-08-18 21:45:16 +02:00
test.cnf
testcrl.pem
testdsa.pem
testdsapub.pem
testec-p256.pem
testecpub-p256.pem
testp7.pem
testreq2.pem
testrsa.pem
testrsapub.pem
testsid.pem
testutil.h Extend tests of SSL_check_chain() 2019-08-09 17:29:39 +01:00
testx509.pem
threadstest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
time_offset_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
tls13ccstest.c Make the PACKET/WPACKET code available to both libcrypto and libssl 2019-07-12 06:26:46 +10:00
tls13encryptiontest.c Collapse ssl3_state_st (s3) into ssl_st 2019-04-29 17:26:09 +01:00
tls13secretstest.c Fix Typos 2019-07-02 14:22:29 +02:00
uitest.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
Uss.cnf
v3-cert1.pem
v3-cert2.pem
v3ext.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
v3nametest.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
verify_extra_test.c Support SM2 certificate signing 2019-06-28 18:58:19 +08:00
versions.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
wpackettest.c Make the PACKET/WPACKET code available to both libcrypto and libssl 2019-07-12 06:26:46 +10:00
x509_check_cert_pkey_test.c Fix incorrect usage of a test case 2019-06-26 17:36:56 +08:00
x509_dup_cert_test.c Updated test command line parsing to support commmon commands 2019-02-11 15:31:51 +01:00
x509_internal_test.c Join the x509 and x509v3 directories 2019-05-29 09:32:50 +02:00
x509_time_test.c Following the license change, modify the boilerplates in test/ 2018-12-06 14:19:22 +01:00
x509aux.c constify *_dup() and *i2d_*() and related functions as far as possible, introducing DECLARE_ASN1_DUP_FUNCTION 2019-03-06 16:10:09 +00:00

How to add recipes
==================

For any test that you want to perform, you write a script located in
test/recipes/, named {nn}-test_{name}.t, where {nn} is a two digit number and
{name} is a unique name of your choice.

Please note that if a test involves a new testing executable, you will need to
do some additions in test/build.info. Please refer to the section "Changes to 
test/build.info" below.


Naming conventions
=================

A test executable is named test/{name}test.c

A test recipe is named test/recipes/{nn}-test_{name}.t, where {nn} is a two
digit number and {name} is a unique name of your choice.

The number {nn} is (somewhat loosely) grouped as follows:

00-04  sanity, internal and essential API tests
05-09  individual symmetric cipher algorithms
10-14  math (bignum)
15-19  individual asymmetric cipher algorithms
20-24  openssl commands (some otherwise not tested)
25-29  certificate forms, generation and verification
30-35  engine and evp
60-79  APIs
   70  PACKET layer
80-89  "larger" protocols (CA, CMS, OCSP, SSL, TSA)
90-98  misc
99     most time consuming tests [such as test_fuzz]


A recipe that just runs a test executable
=========================================

A script that just runs a program looks like this:

    #! /usr/bin/perl

    use OpenSSL::Test::Simple;

    simple_test("test_{name}", "{name}test", "{name}");

{name} is the unique name you have chosen for your test.

The second argument to `simple_test' is the test executable, and `simple_test'
expects it to be located in test/

For documentation on OpenSSL::Test::Simple, do
`perldoc util/perl/OpenSSL/Test/Simple.pm'.


A recipe that runs a more complex test
======================================

For more complex tests, you will need to read up on Test::More and
OpenSSL::Test.  Test::More is normally preinstalled, do `man Test::More' for
documentation.  For OpenSSL::Test, do `perldoc util/perl/OpenSSL/Test.pm'.

A script to start from could be this:

    #! /usr/bin/perl

    use strict;
    use warnings;
    use OpenSSL::Test;

    setup("test_{name}");

    plan tests => 2;                # The number of tests being performed

    ok(test1, "test1");
    ok(test2, "test1");

    sub test1
    {
        # test feature 1
    }

    sub test2
    {
        # test feature 2
    }


Changes to test/build.info
==========================

Whenever a new test involves a new test executable you need to do the
following (at all times, replace {NAME} and {name} with the name of your
test):

* add {name} to the list of programs under PROGRAMS_NO_INST

* create a three line description of how to build the test, you will have
to modify the include paths and source files if you don't want to use the
basic test framework:

    SOURCE[{name}]={name}.c
    INCLUDE[{name}]=.. ../include ../apps/include
    DEPEND[{name}]=../libcrypto libtestutil.a

Generic form of C test executables
==================================

    #include "testutil.h"

    static int my_test(void)
    {
        int testresult = 0;                 /* Assume the test will fail    */
        int observed;

        observed = function();              /* Call the code under test     */
        if (!TEST_int_eq(observed, 2))      /* Check the result is correct  */
            goto end;                       /* Exit on failure - optional   */

        testresult = 1;                     /* Mark the test case a success */
    end:
        cleanup();                          /* Any cleanup you require      */
        return testresult;
    }

    int setup_tests(void)
    {
        ADD_TEST(my_test);                  /* Add each test separately     */
        return 1;                           /* Indicate success             */
    }

You should use the TEST_xxx macros provided by testutil.h to test all failure
conditions.  These macros produce an error message in a standard format if the
condition is not met (and nothing if the condition is met).  Additional
information can be presented with the TEST_info macro that takes a printf
format string and arguments.  TEST_error is useful for complicated conditions,
it also takes a printf format string and argument.  In all cases the TEST_xxx
macros are guaranteed to evaluate their arguments exactly once.  This means
that expressions with side effects are allowed as parameters.  Thus,

    if (!TEST_ptr(ptr = OPENSSL_malloc(..)))

works fine and can be used in place of:

    ptr = OPENSSL_malloc(..);
    if (!TEST_ptr(ptr))

The former produces a more meaningful message on failure than the latter.