Home | History | Annotate | Line # | Download | only in test
cms-examples.pl revision 1.1
      1  1.1  christos # test/cms-examples.pl
      2  1.1  christos # Written by Dr Stephen N Henson (steve (at] openssl.org) for the OpenSSL
      3  1.1  christos # project.
      4  1.1  christos #
      5  1.1  christos # ====================================================================
      6  1.1  christos # Copyright (c) 2008 The OpenSSL Project.  All rights reserved.
      7  1.1  christos #
      8  1.1  christos # Redistribution and use in source and binary forms, with or without
      9  1.1  christos # modification, are permitted provided that the following conditions
     10  1.1  christos # are met:
     11  1.1  christos #
     12  1.1  christos # 1. Redistributions of source code must retain the above copyright
     13  1.1  christos #    notice, this list of conditions and the following disclaimer.
     14  1.1  christos #
     15  1.1  christos # 2. Redistributions in binary form must reproduce the above copyright
     16  1.1  christos #    notice, this list of conditions and the following disclaimer in
     17  1.1  christos #    the documentation and/or other materials provided with the
     18  1.1  christos #    distribution.
     19  1.1  christos #
     20  1.1  christos # 3. All advertising materials mentioning features or use of this
     21  1.1  christos #    software must display the following acknowledgment:
     22  1.1  christos #    "This product includes software developed by the OpenSSL Project
     23  1.1  christos #    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
     24  1.1  christos #
     25  1.1  christos # 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
     26  1.1  christos #    endorse or promote products derived from this software without
     27  1.1  christos #    prior written permission. For written permission, please contact
     28  1.1  christos #    licensing (at] OpenSSL.org.
     29  1.1  christos #
     30  1.1  christos # 5. Products derived from this software may not be called "OpenSSL"
     31  1.1  christos #    nor may "OpenSSL" appear in their names without prior written
     32  1.1  christos #    permission of the OpenSSL Project.
     33  1.1  christos #
     34  1.1  christos # 6. Redistributions of any form whatsoever must retain the following
     35  1.1  christos #    acknowledgment:
     36  1.1  christos #    "This product includes software developed by the OpenSSL Project
     37  1.1  christos #    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
     38  1.1  christos #
     39  1.1  christos # THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
     40  1.1  christos # EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     41  1.1  christos # IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
     42  1.1  christos # PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
     43  1.1  christos # ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
     44  1.1  christos # SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
     45  1.1  christos # NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
     46  1.1  christos # LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     47  1.1  christos # HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
     48  1.1  christos # STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
     49  1.1  christos # ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
     50  1.1  christos # OF THE POSSIBILITY OF SUCH DAMAGE.
     51  1.1  christos # ====================================================================
     52  1.1  christos 
     53  1.1  christos # Perl script to run tests against S/MIME examples in RFC4134
     54  1.1  christos # Assumes RFC is in current directory and called "rfc4134.txt"
     55  1.1  christos 
     56  1.1  christos use MIME::Base64;
     57  1.1  christos 
     58  1.1  christos my $badttest = 0;
     59  1.1  christos my $verbose  = 1;
     60  1.1  christos 
     61  1.1  christos my $cmscmd;
     62  1.1  christos my $exdir  = "./";
     63  1.1  christos my $exfile = "./rfc4134.txt";
     64  1.1  christos 
     65  1.1  christos if (-f "../apps/openssl")
     66  1.1  christos 	{
     67  1.1  christos 	$cmscmd = "../util/shlib_wrap.sh ../apps/openssl cms";
     68  1.1  christos 	}
     69  1.1  christos elsif (-f "..\\out32dll\\openssl.exe")
     70  1.1  christos 	{
     71  1.1  christos 	$cmscmd = "..\\out32dll\\openssl.exe cms";
     72  1.1  christos 	}
     73  1.1  christos elsif (-f "..\\out32\\openssl.exe")
     74  1.1  christos 	{
     75  1.1  christos 	$cmscmd = "..\\out32\\openssl.exe cms";
     76  1.1  christos 	}
     77  1.1  christos 
     78  1.1  christos my @test_list = (
     79  1.1  christos     [ "3.1.bin"  => "dataout" ],
     80  1.1  christos     [ "3.2.bin"  => "encode, dataout" ],
     81  1.1  christos     [ "4.1.bin"  => "encode, verifyder, cont, dss" ],
     82  1.1  christos     [ "4.2.bin"  => "encode, verifyder, cont, rsa" ],
     83  1.1  christos     [ "4.3.bin"  => "encode, verifyder, cont_extern, dss" ],
     84  1.1  christos     [ "4.4.bin"  => "encode, verifyder, cont, dss" ],
     85  1.1  christos     [ "4.5.bin"  => "verifyder, cont, rsa" ],
     86  1.1  christos     [ "4.6.bin"  => "encode, verifyder, cont, dss" ],
     87  1.1  christos     [ "4.7.bin"  => "encode, verifyder, cont, dss" ],
     88  1.1  christos     [ "4.8.eml"  => "verifymime, dss" ],
     89  1.1  christos     [ "4.9.eml"  => "verifymime, dss" ],
     90  1.1  christos     [ "4.10.bin" => "encode, verifyder, cont, dss" ],
     91  1.1  christos     [ "4.11.bin" => "encode, certsout" ],
     92  1.1  christos     [ "5.1.bin"  => "encode, envelopeder, cont" ],
     93  1.1  christos     [ "5.2.bin"  => "encode, envelopeder, cont" ],
     94  1.1  christos     [ "5.3.eml"  => "envelopemime, cont" ],
     95  1.1  christos     [ "6.0.bin"  => "encode, digest, cont" ],
     96  1.1  christos     [ "7.1.bin"  => "encode, encrypted, cont" ],
     97  1.1  christos     [ "7.2.bin"  => "encode, encrypted, cont" ]
     98  1.1  christos );
     99  1.1  christos 
    100  1.1  christos # Extract examples from RFC4134 text.
    101  1.1  christos # Base64 decode all examples, certificates and
    102  1.1  christos # private keys are converted to PEM format.
    103  1.1  christos 
    104  1.1  christos my ( $filename, $data );
    105  1.1  christos 
    106  1.1  christos my @cleanup = ( "cms.out", "cms.err", "tmp.der", "tmp.txt" );
    107  1.1  christos 
    108  1.1  christos $data = "";
    109  1.1  christos 
    110  1.1  christos open( IN, $exfile ) || die "Can't Open RFC examples file $exfile";
    111  1.1  christos 
    112  1.1  christos while (<IN>) {
    113  1.1  christos     next unless (/^\|/);
    114  1.1  christos     s/^\|//;
    115  1.1  christos     next if (/^\*/);
    116  1.1  christos     if (/^>(.*)$/) {
    117  1.1  christos         $filename = $1;
    118  1.1  christos         next;
    119  1.1  christos     }
    120  1.1  christos     if (/^</) {
    121  1.1  christos         $filename = "$exdir/$filename";
    122  1.1  christos         if ( $filename =~ /\.bin$/ || $filename =~ /\.eml$/ ) {
    123  1.1  christos             $data = decode_base64($data);
    124  1.1  christos             open OUT, ">$filename";
    125  1.1  christos             binmode OUT;
    126  1.1  christos             print OUT $data;
    127  1.1  christos             close OUT;
    128  1.1  christos             push @cleanup, $filename;
    129  1.1  christos         }
    130  1.1  christos         elsif ( $filename =~ /\.cer$/ ) {
    131  1.1  christos             write_pem( $filename, "CERTIFICATE", $data );
    132  1.1  christos         }
    133  1.1  christos         elsif ( $filename =~ /\.pri$/ ) {
    134  1.1  christos             write_pem( $filename, "PRIVATE KEY", $data );
    135  1.1  christos         }
    136  1.1  christos         $data     = "";
    137  1.1  christos         $filename = "";
    138  1.1  christos     }
    139  1.1  christos     else {
    140  1.1  christos         $data .= $_;
    141  1.1  christos     }
    142  1.1  christos 
    143  1.1  christos }
    144  1.1  christos 
    145  1.1  christos my $secretkey =
    146  1.1  christos   "73:7c:79:1f:25:ea:d0:e0:46:29:25:43:52:f7:dc:62:91:e5:cb:26:91:7a:da:32";
    147  1.1  christos 
    148  1.1  christos foreach (@test_list) {
    149  1.1  christos     my ( $file, $tlist ) = @$_;
    150  1.1  christos     print "Example file $file:\n";
    151  1.1  christos     if ( $tlist =~ /encode/ ) {
    152  1.1  christos         run_reencode_test( $exdir, $file );
    153  1.1  christos     }
    154  1.1  christos     if ( $tlist =~ /certsout/ ) {
    155  1.1  christos         run_certsout_test( $exdir, $file );
    156  1.1  christos     }
    157  1.1  christos     if ( $tlist =~ /dataout/ ) {
    158  1.1  christos         run_dataout_test( $exdir, $file );
    159  1.1  christos     }
    160  1.1  christos     if ( $tlist =~ /verify/ ) {
    161  1.1  christos         run_verify_test( $exdir, $tlist, $file );
    162  1.1  christos     }
    163  1.1  christos     if ( $tlist =~ /digest/ ) {
    164  1.1  christos         run_digest_test( $exdir, $tlist, $file );
    165  1.1  christos     }
    166  1.1  christos     if ( $tlist =~ /encrypted/ ) {
    167  1.1  christos         run_encrypted_test( $exdir, $tlist, $file, $secretkey );
    168  1.1  christos     }
    169  1.1  christos     if ( $tlist =~ /envelope/ ) {
    170  1.1  christos         run_envelope_test( $exdir, $tlist, $file );
    171  1.1  christos     }
    172  1.1  christos 
    173  1.1  christos }
    174  1.1  christos 
    175  1.1  christos foreach (@cleanup) {
    176  1.1  christos     unlink $_;
    177  1.1  christos }
    178  1.1  christos 
    179  1.1  christos if ($badtest) {
    180  1.1  christos     print "\n$badtest TESTS FAILED!!\n";
    181  1.1  christos }
    182  1.1  christos else {
    183  1.1  christos     print "\n***All tests successful***\n";
    184  1.1  christos }
    185  1.1  christos 
    186  1.1  christos sub write_pem {
    187  1.1  christos     my ( $filename, $str, $data ) = @_;
    188  1.1  christos 
    189  1.1  christos     $filename =~ s/\.[^.]*$/.pem/;
    190  1.1  christos 
    191  1.1  christos     push @cleanup, $filename;
    192  1.1  christos 
    193  1.1  christos     open OUT, ">$filename";
    194  1.1  christos 
    195  1.1  christos     print OUT "-----BEGIN $str-----\n";
    196  1.1  christos     print OUT $data;
    197  1.1  christos     print OUT "-----END $str-----\n";
    198  1.1  christos 
    199  1.1  christos     close OUT;
    200  1.1  christos }
    201  1.1  christos 
    202  1.1  christos sub run_reencode_test {
    203  1.1  christos     my ( $cmsdir, $tfile ) = @_;
    204  1.1  christos     unlink "tmp.der";
    205  1.1  christos 
    206  1.1  christos     system( "$cmscmd -cmsout -inform DER -outform DER"
    207  1.1  christos           . " -in $cmsdir/$tfile -out tmp.der" );
    208  1.1  christos 
    209  1.1  christos     if ($?) {
    210  1.1  christos         print "\tReencode command FAILED!!\n";
    211  1.1  christos         $badtest++;
    212  1.1  christos     }
    213  1.1  christos     elsif ( !cmp_files( "$cmsdir/$tfile", "tmp.der" ) ) {
    214  1.1  christos         print "\tReencode FAILED!!\n";
    215  1.1  christos         $badtest++;
    216  1.1  christos     }
    217  1.1  christos     else {
    218  1.1  christos         print "\tReencode passed\n" if $verbose;
    219  1.1  christos     }
    220  1.1  christos }
    221  1.1  christos 
    222  1.1  christos sub run_certsout_test {
    223  1.1  christos     my ( $cmsdir, $tfile ) = @_;
    224  1.1  christos     unlink "tmp.der";
    225  1.1  christos     unlink "tmp.pem";
    226  1.1  christos 
    227  1.1  christos     system( "$cmscmd -cmsout -inform DER -certsout tmp.pem"
    228  1.1  christos           . " -in $cmsdir/$tfile -out tmp.der" );
    229  1.1  christos 
    230  1.1  christos     if ($?) {
    231  1.1  christos         print "\tCertificate output command FAILED!!\n";
    232  1.1  christos         $badtest++;
    233  1.1  christos     }
    234  1.1  christos     else {
    235  1.1  christos         print "\tCertificate output passed\n" if $verbose;
    236  1.1  christos     }
    237  1.1  christos }
    238  1.1  christos 
    239  1.1  christos sub run_dataout_test {
    240  1.1  christos     my ( $cmsdir, $tfile ) = @_;
    241  1.1  christos     unlink "tmp.txt";
    242  1.1  christos 
    243  1.1  christos     system(
    244  1.1  christos         "$cmscmd -data_out -inform DER" . " -in $cmsdir/$tfile -out tmp.txt" );
    245  1.1  christos 
    246  1.1  christos     if ($?) {
    247  1.1  christos         print "\tDataout command FAILED!!\n";
    248  1.1  christos         $badtest++;
    249  1.1  christos     }
    250  1.1  christos     elsif ( !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) ) {
    251  1.1  christos         print "\tDataout compare FAILED!!\n";
    252  1.1  christos         $badtest++;
    253  1.1  christos     }
    254  1.1  christos     else {
    255  1.1  christos         print "\tDataout passed\n" if $verbose;
    256  1.1  christos     }
    257  1.1  christos }
    258  1.1  christos 
    259  1.1  christos sub run_verify_test {
    260  1.1  christos     my ( $cmsdir, $tlist, $tfile ) = @_;
    261  1.1  christos     unlink "tmp.txt";
    262  1.1  christos 
    263  1.1  christos     $form   = "DER"                     if $tlist =~ /verifyder/;
    264  1.1  christos     $form   = "SMIME"                   if $tlist =~ /verifymime/;
    265  1.1  christos     $cafile = "$cmsdir/CarlDSSSelf.pem" if $tlist =~ /dss/;
    266  1.1  christos     $cafile = "$cmsdir/CarlRSASelf.pem" if $tlist =~ /rsa/;
    267  1.1  christos 
    268  1.1  christos     $cmd =
    269  1.1  christos         "$cmscmd -verify -inform $form"
    270  1.1  christos       . " -CAfile $cafile"
    271  1.1  christos       . " -in $cmsdir/$tfile -out tmp.txt";
    272  1.1  christos 
    273  1.1  christos     $cmd .= " -content $cmsdir/ExContent.bin" if $tlist =~ /cont_extern/;
    274  1.1  christos 
    275  1.1  christos     system("$cmd 2>cms.err 1>cms.out");
    276  1.1  christos 
    277  1.1  christos     if ($?) {
    278  1.1  christos         print "\tVerify command FAILED!!\n";
    279  1.1  christos         $badtest++;
    280  1.1  christos     }
    281  1.1  christos     elsif ( $tlist =~ /cont/
    282  1.1  christos         && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
    283  1.1  christos     {
    284  1.1  christos         print "\tVerify content compare FAILED!!\n";
    285  1.1  christos         $badtest++;
    286  1.1  christos     }
    287  1.1  christos     else {
    288  1.1  christos         print "\tVerify passed\n" if $verbose;
    289  1.1  christos     }
    290  1.1  christos }
    291  1.1  christos 
    292  1.1  christos sub run_envelope_test {
    293  1.1  christos     my ( $cmsdir, $tlist, $tfile ) = @_;
    294  1.1  christos     unlink "tmp.txt";
    295  1.1  christos 
    296  1.1  christos     $form = "DER"   if $tlist =~ /envelopeder/;
    297  1.1  christos     $form = "SMIME" if $tlist =~ /envelopemime/;
    298  1.1  christos 
    299  1.1  christos     $cmd =
    300  1.1  christos         "$cmscmd -decrypt -inform $form"
    301  1.1  christos       . " -recip $cmsdir/BobRSASignByCarl.pem"
    302  1.1  christos       . " -inkey $cmsdir/BobPrivRSAEncrypt.pem"
    303  1.1  christos       . " -in $cmsdir/$tfile -out tmp.txt";
    304  1.1  christos 
    305  1.1  christos     system("$cmd 2>cms.err 1>cms.out");
    306  1.1  christos 
    307  1.1  christos     if ($?) {
    308  1.1  christos         print "\tDecrypt command FAILED!!\n";
    309  1.1  christos         $badtest++;
    310  1.1  christos     }
    311  1.1  christos     elsif ( $tlist =~ /cont/
    312  1.1  christos         && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
    313  1.1  christos     {
    314  1.1  christos         print "\tDecrypt content compare FAILED!!\n";
    315  1.1  christos         $badtest++;
    316  1.1  christos     }
    317  1.1  christos     else {
    318  1.1  christos         print "\tDecrypt passed\n" if $verbose;
    319  1.1  christos     }
    320  1.1  christos }
    321  1.1  christos 
    322  1.1  christos sub run_digest_test {
    323  1.1  christos     my ( $cmsdir, $tlist, $tfile ) = @_;
    324  1.1  christos     unlink "tmp.txt";
    325  1.1  christos 
    326  1.1  christos     my $cmd =
    327  1.1  christos       "$cmscmd -digest_verify -inform DER" . " -in $cmsdir/$tfile -out tmp.txt";
    328  1.1  christos 
    329  1.1  christos     system("$cmd 2>cms.err 1>cms.out");
    330  1.1  christos 
    331  1.1  christos     if ($?) {
    332  1.1  christos         print "\tDigest verify command FAILED!!\n";
    333  1.1  christos         $badtest++;
    334  1.1  christos     }
    335  1.1  christos     elsif ( $tlist =~ /cont/
    336  1.1  christos         && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
    337  1.1  christos     {
    338  1.1  christos         print "\tDigest verify content compare FAILED!!\n";
    339  1.1  christos         $badtest++;
    340  1.1  christos     }
    341  1.1  christos     else {
    342  1.1  christos         print "\tDigest verify passed\n" if $verbose;
    343  1.1  christos     }
    344  1.1  christos }
    345  1.1  christos 
    346  1.1  christos sub run_encrypted_test {
    347  1.1  christos     my ( $cmsdir, $tlist, $tfile, $key ) = @_;
    348  1.1  christos     unlink "tmp.txt";
    349  1.1  christos 
    350  1.1  christos     system( "$cmscmd -EncryptedData_decrypt -inform DER"
    351  1.1  christos           . " -secretkey $key"
    352  1.1  christos           . " -in $cmsdir/$tfile -out tmp.txt" );
    353  1.1  christos 
    354  1.1  christos     if ($?) {
    355  1.1  christos         print "\tEncrypted Data command FAILED!!\n";
    356  1.1  christos         $badtest++;
    357  1.1  christos     }
    358  1.1  christos     elsif ( $tlist =~ /cont/
    359  1.1  christos         && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
    360  1.1  christos     {
    361  1.1  christos         print "\tEncrypted Data content compare FAILED!!\n";
    362  1.1  christos         $badtest++;
    363  1.1  christos     }
    364  1.1  christos     else {
    365  1.1  christos         print "\tEncryptedData verify passed\n" if $verbose;
    366  1.1  christos     }
    367  1.1  christos }
    368  1.1  christos 
    369  1.1  christos sub cmp_files {
    370  1.1  christos     my ( $f1, $f2 ) = @_;
    371  1.1  christos     my ( $fp1, $fp2 );
    372  1.1  christos 
    373  1.1  christos     my ( $rd1, $rd2 );
    374  1.1  christos 
    375  1.1  christos     if ( !open( $fp1, "<$f1" ) ) {
    376  1.1  christos         print STDERR "Can't Open file $f1\n";
    377  1.1  christos         return 0;
    378  1.1  christos     }
    379  1.1  christos 
    380  1.1  christos     if ( !open( $fp2, "<$f2" ) ) {
    381  1.1  christos         print STDERR "Can't Open file $f2\n";
    382  1.1  christos         return 0;
    383  1.1  christos     }
    384  1.1  christos 
    385  1.1  christos     binmode $fp1;
    386  1.1  christos     binmode $fp2;
    387  1.1  christos 
    388  1.1  christos     my $ret = 0;
    389  1.1  christos 
    390  1.1  christos     for ( ; ; ) {
    391  1.1  christos         $n1 = sysread $fp1, $rd1, 4096;
    392  1.1  christos         $n2 = sysread $fp2, $rd2, 4096;
    393  1.1  christos         last if ( $n1 != $n2 );
    394  1.1  christos         last if ( $rd1 ne $rd2 );
    395  1.1  christos 
    396  1.1  christos         if ( $n1 == 0 ) {
    397  1.1  christos             $ret = 1;
    398  1.1  christos             last;
    399  1.1  christos         }
    400  1.1  christos 
    401  1.1  christos     }
    402  1.1  christos 
    403  1.1  christos     close $fp1;
    404  1.1  christos     close $fp2;
    405  1.1  christos 
    406  1.1  christos     return $ret;
    407  1.1  christos 
    408  1.1  christos }
    409  1.1  christos 
    410