Home | History | Annotate | Line # | Download | only in test
cms-examples.pl revision 1.1.1.2.14.1
      1       1.1.1.2  christos #! /usr/bin/env perl
      2       1.1.1.2  christos # Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved.
      3           1.1  christos #
      4  1.1.1.2.14.1    martin # Licensed under the Apache License 2.0 (the "License").  You may not use
      5       1.1.1.2  christos # this file except in compliance with the License.  You can obtain a copy
      6       1.1.1.2  christos # in the file LICENSE in the source distribution or at
      7       1.1.1.2  christos # https://www.openssl.org/source/license.html
      8           1.1  christos 
      9           1.1  christos # Perl script to run tests against S/MIME examples in RFC4134
     10           1.1  christos # Assumes RFC is in current directory and called "rfc4134.txt"
     11           1.1  christos 
     12           1.1  christos use MIME::Base64;
     13           1.1  christos 
     14           1.1  christos my $badttest = 0;
     15           1.1  christos my $verbose  = 1;
     16           1.1  christos 
     17           1.1  christos my $cmscmd;
     18           1.1  christos my $exdir  = "./";
     19           1.1  christos my $exfile = "./rfc4134.txt";
     20           1.1  christos 
     21           1.1  christos if (-f "../apps/openssl")
     22           1.1  christos 	{
     23           1.1  christos 	$cmscmd = "../util/shlib_wrap.sh ../apps/openssl cms";
     24           1.1  christos 	}
     25           1.1  christos elsif (-f "..\\out32dll\\openssl.exe")
     26           1.1  christos 	{
     27           1.1  christos 	$cmscmd = "..\\out32dll\\openssl.exe cms";
     28           1.1  christos 	}
     29           1.1  christos elsif (-f "..\\out32\\openssl.exe")
     30           1.1  christos 	{
     31           1.1  christos 	$cmscmd = "..\\out32\\openssl.exe cms";
     32           1.1  christos 	}
     33           1.1  christos 
     34           1.1  christos my @test_list = (
     35           1.1  christos     [ "3.1.bin"  => "dataout" ],
     36           1.1  christos     [ "3.2.bin"  => "encode, dataout" ],
     37           1.1  christos     [ "4.1.bin"  => "encode, verifyder, cont, dss" ],
     38           1.1  christos     [ "4.2.bin"  => "encode, verifyder, cont, rsa" ],
     39           1.1  christos     [ "4.3.bin"  => "encode, verifyder, cont_extern, dss" ],
     40           1.1  christos     [ "4.4.bin"  => "encode, verifyder, cont, dss" ],
     41           1.1  christos     [ "4.5.bin"  => "verifyder, cont, rsa" ],
     42           1.1  christos     [ "4.6.bin"  => "encode, verifyder, cont, dss" ],
     43           1.1  christos     [ "4.7.bin"  => "encode, verifyder, cont, dss" ],
     44           1.1  christos     [ "4.8.eml"  => "verifymime, dss" ],
     45           1.1  christos     [ "4.9.eml"  => "verifymime, dss" ],
     46           1.1  christos     [ "4.10.bin" => "encode, verifyder, cont, dss" ],
     47           1.1  christos     [ "4.11.bin" => "encode, certsout" ],
     48           1.1  christos     [ "5.1.bin"  => "encode, envelopeder, cont" ],
     49           1.1  christos     [ "5.2.bin"  => "encode, envelopeder, cont" ],
     50           1.1  christos     [ "5.3.eml"  => "envelopemime, cont" ],
     51           1.1  christos     [ "6.0.bin"  => "encode, digest, cont" ],
     52           1.1  christos     [ "7.1.bin"  => "encode, encrypted, cont" ],
     53           1.1  christos     [ "7.2.bin"  => "encode, encrypted, cont" ]
     54           1.1  christos );
     55           1.1  christos 
     56           1.1  christos # Extract examples from RFC4134 text.
     57           1.1  christos # Base64 decode all examples, certificates and
     58           1.1  christos # private keys are converted to PEM format.
     59           1.1  christos 
     60           1.1  christos my ( $filename, $data );
     61           1.1  christos 
     62           1.1  christos my @cleanup = ( "cms.out", "cms.err", "tmp.der", "tmp.txt" );
     63           1.1  christos 
     64           1.1  christos $data = "";
     65           1.1  christos 
     66           1.1  christos open( IN, $exfile ) || die "Can't Open RFC examples file $exfile";
     67           1.1  christos 
     68           1.1  christos while (<IN>) {
     69           1.1  christos     next unless (/^\|/);
     70           1.1  christos     s/^\|//;
     71           1.1  christos     next if (/^\*/);
     72           1.1  christos     if (/^>(.*)$/) {
     73           1.1  christos         $filename = $1;
     74           1.1  christos         next;
     75           1.1  christos     }
     76           1.1  christos     if (/^</) {
     77           1.1  christos         $filename = "$exdir/$filename";
     78           1.1  christos         if ( $filename =~ /\.bin$/ || $filename =~ /\.eml$/ ) {
     79           1.1  christos             $data = decode_base64($data);
     80           1.1  christos             open OUT, ">$filename";
     81           1.1  christos             binmode OUT;
     82           1.1  christos             print OUT $data;
     83           1.1  christos             close OUT;
     84           1.1  christos             push @cleanup, $filename;
     85           1.1  christos         }
     86           1.1  christos         elsif ( $filename =~ /\.cer$/ ) {
     87           1.1  christos             write_pem( $filename, "CERTIFICATE", $data );
     88           1.1  christos         }
     89           1.1  christos         elsif ( $filename =~ /\.pri$/ ) {
     90           1.1  christos             write_pem( $filename, "PRIVATE KEY", $data );
     91           1.1  christos         }
     92           1.1  christos         $data     = "";
     93           1.1  christos         $filename = "";
     94           1.1  christos     }
     95           1.1  christos     else {
     96           1.1  christos         $data .= $_;
     97           1.1  christos     }
     98           1.1  christos 
     99           1.1  christos }
    100           1.1  christos 
    101           1.1  christos my $secretkey =
    102           1.1  christos   "73:7c:79:1f:25:ea:d0:e0:46:29:25:43:52:f7:dc:62:91:e5:cb:26:91:7a:da:32";
    103           1.1  christos 
    104           1.1  christos foreach (@test_list) {
    105           1.1  christos     my ( $file, $tlist ) = @$_;
    106           1.1  christos     print "Example file $file:\n";
    107           1.1  christos     if ( $tlist =~ /encode/ ) {
    108           1.1  christos         run_reencode_test( $exdir, $file );
    109           1.1  christos     }
    110           1.1  christos     if ( $tlist =~ /certsout/ ) {
    111           1.1  christos         run_certsout_test( $exdir, $file );
    112           1.1  christos     }
    113           1.1  christos     if ( $tlist =~ /dataout/ ) {
    114           1.1  christos         run_dataout_test( $exdir, $file );
    115           1.1  christos     }
    116           1.1  christos     if ( $tlist =~ /verify/ ) {
    117           1.1  christos         run_verify_test( $exdir, $tlist, $file );
    118           1.1  christos     }
    119           1.1  christos     if ( $tlist =~ /digest/ ) {
    120           1.1  christos         run_digest_test( $exdir, $tlist, $file );
    121           1.1  christos     }
    122           1.1  christos     if ( $tlist =~ /encrypted/ ) {
    123           1.1  christos         run_encrypted_test( $exdir, $tlist, $file, $secretkey );
    124           1.1  christos     }
    125           1.1  christos     if ( $tlist =~ /envelope/ ) {
    126           1.1  christos         run_envelope_test( $exdir, $tlist, $file );
    127           1.1  christos     }
    128           1.1  christos 
    129           1.1  christos }
    130           1.1  christos 
    131           1.1  christos foreach (@cleanup) {
    132           1.1  christos     unlink $_;
    133           1.1  christos }
    134           1.1  christos 
    135           1.1  christos if ($badtest) {
    136           1.1  christos     print "\n$badtest TESTS FAILED!!\n";
    137           1.1  christos }
    138           1.1  christos else {
    139           1.1  christos     print "\n***All tests successful***\n";
    140           1.1  christos }
    141           1.1  christos 
    142           1.1  christos sub write_pem {
    143           1.1  christos     my ( $filename, $str, $data ) = @_;
    144           1.1  christos 
    145           1.1  christos     $filename =~ s/\.[^.]*$/.pem/;
    146           1.1  christos 
    147           1.1  christos     push @cleanup, $filename;
    148           1.1  christos 
    149           1.1  christos     open OUT, ">$filename";
    150           1.1  christos 
    151           1.1  christos     print OUT "-----BEGIN $str-----\n";
    152           1.1  christos     print OUT $data;
    153           1.1  christos     print OUT "-----END $str-----\n";
    154           1.1  christos 
    155           1.1  christos     close OUT;
    156           1.1  christos }
    157           1.1  christos 
    158           1.1  christos sub run_reencode_test {
    159           1.1  christos     my ( $cmsdir, $tfile ) = @_;
    160           1.1  christos     unlink "tmp.der";
    161           1.1  christos 
    162           1.1  christos     system( "$cmscmd -cmsout -inform DER -outform DER"
    163           1.1  christos           . " -in $cmsdir/$tfile -out tmp.der" );
    164           1.1  christos 
    165           1.1  christos     if ($?) {
    166           1.1  christos         print "\tReencode command FAILED!!\n";
    167           1.1  christos         $badtest++;
    168           1.1  christos     }
    169           1.1  christos     elsif ( !cmp_files( "$cmsdir/$tfile", "tmp.der" ) ) {
    170           1.1  christos         print "\tReencode FAILED!!\n";
    171           1.1  christos         $badtest++;
    172           1.1  christos     }
    173           1.1  christos     else {
    174           1.1  christos         print "\tReencode passed\n" if $verbose;
    175           1.1  christos     }
    176           1.1  christos }
    177           1.1  christos 
    178           1.1  christos sub run_certsout_test {
    179           1.1  christos     my ( $cmsdir, $tfile ) = @_;
    180           1.1  christos     unlink "tmp.der";
    181           1.1  christos     unlink "tmp.pem";
    182           1.1  christos 
    183           1.1  christos     system( "$cmscmd -cmsout -inform DER -certsout tmp.pem"
    184           1.1  christos           . " -in $cmsdir/$tfile -out tmp.der" );
    185           1.1  christos 
    186           1.1  christos     if ($?) {
    187           1.1  christos         print "\tCertificate output command FAILED!!\n";
    188           1.1  christos         $badtest++;
    189           1.1  christos     }
    190           1.1  christos     else {
    191           1.1  christos         print "\tCertificate output passed\n" if $verbose;
    192           1.1  christos     }
    193           1.1  christos }
    194           1.1  christos 
    195           1.1  christos sub run_dataout_test {
    196           1.1  christos     my ( $cmsdir, $tfile ) = @_;
    197           1.1  christos     unlink "tmp.txt";
    198           1.1  christos 
    199           1.1  christos     system(
    200           1.1  christos         "$cmscmd -data_out -inform DER" . " -in $cmsdir/$tfile -out tmp.txt" );
    201           1.1  christos 
    202           1.1  christos     if ($?) {
    203           1.1  christos         print "\tDataout command FAILED!!\n";
    204           1.1  christos         $badtest++;
    205           1.1  christos     }
    206           1.1  christos     elsif ( !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) ) {
    207           1.1  christos         print "\tDataout compare FAILED!!\n";
    208           1.1  christos         $badtest++;
    209           1.1  christos     }
    210           1.1  christos     else {
    211           1.1  christos         print "\tDataout passed\n" if $verbose;
    212           1.1  christos     }
    213           1.1  christos }
    214           1.1  christos 
    215           1.1  christos sub run_verify_test {
    216           1.1  christos     my ( $cmsdir, $tlist, $tfile ) = @_;
    217           1.1  christos     unlink "tmp.txt";
    218           1.1  christos 
    219           1.1  christos     $form   = "DER"                     if $tlist =~ /verifyder/;
    220           1.1  christos     $form   = "SMIME"                   if $tlist =~ /verifymime/;
    221           1.1  christos     $cafile = "$cmsdir/CarlDSSSelf.pem" if $tlist =~ /dss/;
    222           1.1  christos     $cafile = "$cmsdir/CarlRSASelf.pem" if $tlist =~ /rsa/;
    223           1.1  christos 
    224           1.1  christos     $cmd =
    225           1.1  christos         "$cmscmd -verify -inform $form"
    226           1.1  christos       . " -CAfile $cafile"
    227           1.1  christos       . " -in $cmsdir/$tfile -out tmp.txt";
    228           1.1  christos 
    229           1.1  christos     $cmd .= " -content $cmsdir/ExContent.bin" if $tlist =~ /cont_extern/;
    230           1.1  christos 
    231           1.1  christos     system("$cmd 2>cms.err 1>cms.out");
    232           1.1  christos 
    233           1.1  christos     if ($?) {
    234           1.1  christos         print "\tVerify command FAILED!!\n";
    235           1.1  christos         $badtest++;
    236           1.1  christos     }
    237           1.1  christos     elsif ( $tlist =~ /cont/
    238           1.1  christos         && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
    239           1.1  christos     {
    240           1.1  christos         print "\tVerify content compare FAILED!!\n";
    241           1.1  christos         $badtest++;
    242           1.1  christos     }
    243           1.1  christos     else {
    244           1.1  christos         print "\tVerify passed\n" if $verbose;
    245           1.1  christos     }
    246           1.1  christos }
    247           1.1  christos 
    248           1.1  christos sub run_envelope_test {
    249           1.1  christos     my ( $cmsdir, $tlist, $tfile ) = @_;
    250           1.1  christos     unlink "tmp.txt";
    251           1.1  christos 
    252           1.1  christos     $form = "DER"   if $tlist =~ /envelopeder/;
    253           1.1  christos     $form = "SMIME" if $tlist =~ /envelopemime/;
    254           1.1  christos 
    255           1.1  christos     $cmd =
    256           1.1  christos         "$cmscmd -decrypt -inform $form"
    257           1.1  christos       . " -recip $cmsdir/BobRSASignByCarl.pem"
    258           1.1  christos       . " -inkey $cmsdir/BobPrivRSAEncrypt.pem"
    259           1.1  christos       . " -in $cmsdir/$tfile -out tmp.txt";
    260           1.1  christos 
    261           1.1  christos     system("$cmd 2>cms.err 1>cms.out");
    262           1.1  christos 
    263           1.1  christos     if ($?) {
    264           1.1  christos         print "\tDecrypt command FAILED!!\n";
    265           1.1  christos         $badtest++;
    266           1.1  christos     }
    267           1.1  christos     elsif ( $tlist =~ /cont/
    268           1.1  christos         && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
    269           1.1  christos     {
    270           1.1  christos         print "\tDecrypt content compare FAILED!!\n";
    271           1.1  christos         $badtest++;
    272           1.1  christos     }
    273           1.1  christos     else {
    274           1.1  christos         print "\tDecrypt passed\n" if $verbose;
    275           1.1  christos     }
    276           1.1  christos }
    277           1.1  christos 
    278           1.1  christos sub run_digest_test {
    279           1.1  christos     my ( $cmsdir, $tlist, $tfile ) = @_;
    280           1.1  christos     unlink "tmp.txt";
    281           1.1  christos 
    282           1.1  christos     my $cmd =
    283           1.1  christos       "$cmscmd -digest_verify -inform DER" . " -in $cmsdir/$tfile -out tmp.txt";
    284           1.1  christos 
    285           1.1  christos     system("$cmd 2>cms.err 1>cms.out");
    286           1.1  christos 
    287           1.1  christos     if ($?) {
    288           1.1  christos         print "\tDigest verify command FAILED!!\n";
    289           1.1  christos         $badtest++;
    290           1.1  christos     }
    291           1.1  christos     elsif ( $tlist =~ /cont/
    292           1.1  christos         && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
    293           1.1  christos     {
    294           1.1  christos         print "\tDigest verify content compare FAILED!!\n";
    295           1.1  christos         $badtest++;
    296           1.1  christos     }
    297           1.1  christos     else {
    298           1.1  christos         print "\tDigest verify passed\n" if $verbose;
    299           1.1  christos     }
    300           1.1  christos }
    301           1.1  christos 
    302           1.1  christos sub run_encrypted_test {
    303           1.1  christos     my ( $cmsdir, $tlist, $tfile, $key ) = @_;
    304           1.1  christos     unlink "tmp.txt";
    305           1.1  christos 
    306           1.1  christos     system( "$cmscmd -EncryptedData_decrypt -inform DER"
    307           1.1  christos           . " -secretkey $key"
    308           1.1  christos           . " -in $cmsdir/$tfile -out tmp.txt" );
    309           1.1  christos 
    310           1.1  christos     if ($?) {
    311           1.1  christos         print "\tEncrypted Data command FAILED!!\n";
    312           1.1  christos         $badtest++;
    313           1.1  christos     }
    314           1.1  christos     elsif ( $tlist =~ /cont/
    315           1.1  christos         && !cmp_files( "$cmsdir/ExContent.bin", "tmp.txt" ) )
    316           1.1  christos     {
    317           1.1  christos         print "\tEncrypted Data content compare FAILED!!\n";
    318           1.1  christos         $badtest++;
    319           1.1  christos     }
    320           1.1  christos     else {
    321           1.1  christos         print "\tEncryptedData verify passed\n" if $verbose;
    322           1.1  christos     }
    323           1.1  christos }
    324           1.1  christos 
    325           1.1  christos sub cmp_files {
    326           1.1  christos     my ( $f1, $f2 ) = @_;
    327           1.1  christos     my ( $fp1, $fp2 );
    328           1.1  christos 
    329           1.1  christos     my ( $rd1, $rd2 );
    330           1.1  christos 
    331           1.1  christos     if ( !open( $fp1, "<$f1" ) ) {
    332           1.1  christos         print STDERR "Can't Open file $f1\n";
    333           1.1  christos         return 0;
    334           1.1  christos     }
    335           1.1  christos 
    336           1.1  christos     if ( !open( $fp2, "<$f2" ) ) {
    337           1.1  christos         print STDERR "Can't Open file $f2\n";
    338           1.1  christos         return 0;
    339           1.1  christos     }
    340           1.1  christos 
    341           1.1  christos     binmode $fp1;
    342           1.1  christos     binmode $fp2;
    343           1.1  christos 
    344           1.1  christos     my $ret = 0;
    345           1.1  christos 
    346           1.1  christos     for ( ; ; ) {
    347           1.1  christos         $n1 = sysread $fp1, $rd1, 4096;
    348           1.1  christos         $n2 = sysread $fp2, $rd2, 4096;
    349           1.1  christos         last if ( $n1 != $n2 );
    350           1.1  christos         last if ( $rd1 ne $rd2 );
    351           1.1  christos 
    352           1.1  christos         if ( $n1 == 0 ) {
    353           1.1  christos             $ret = 1;
    354           1.1  christos             last;
    355           1.1  christos         }
    356           1.1  christos 
    357           1.1  christos     }
    358           1.1  christos 
    359           1.1  christos     close $fp1;
    360           1.1  christos     close $fp2;
    361           1.1  christos 
    362           1.1  christos     return $ret;
    363           1.1  christos 
    364           1.1  christos }
    365           1.1  christos 
    366