aboutsummaryrefslogtreecommitdiff
path: root/unit_tests.py
diff options
context:
space:
mode:
authorRob Austein <sra@hactrn.net>2015-09-21 23:22:33 -0400
committerRob Austein <sra@hactrn.net>2015-09-21 23:22:33 -0400
commit95474a873859bb8a0991ef3973f0340f30025ce2 (patch)
tree0e2cbea5194385130edf533f94c9c5887c5c0de5 /unit_tests.py
parent9e25e0d01cd58380e115e995e558c61013350f04 (diff)
More key unit tests.
Diffstat (limited to 'unit_tests.py')
-rw-r--r--unit_tests.py111
1 files changed, 102 insertions, 9 deletions
diff --git a/unit_tests.py b/unit_tests.py
index b38e4ac..b82a479 100644
--- a/unit_tests.py
+++ b/unit_tests.py
@@ -118,18 +118,18 @@ class TestKeys(unittest.TestCase):
p11.C_Login(self.session, CKU_USER, user_pin)
def tearDown(self):
+ for handle in p11.Find(self.session):
+ p11.C_DestroyObject(self.session, handle)
p11.C_CloseAllSessions(only_slot)
del self.session
- def assertIsKeypair(self, public_key, private_key = None):
- if isinstance(public_key, tuple) and private_key is None:
- public_key, private_key = public_key
- self.assertIsInstance(public_key, (int, long))
- self.assertIsInstance(private_key, (int, long))
- # Could do something clever here like use C_GetAttributeValue() to
- # examine the objects. Maybe later.
+ def assertIsKeypair(self, public_handle, private_handle = None):
+ if isinstance(public_handle, tuple) and private_handle is None:
+ public_handle, private_handle = public_handle
+ self.assertEqual(p11.C_GetAttributeValue(self.session, public_handle, CKA_CLASS)[CKA_CLASS], CKO_PUBLIC_KEY)
+ self.assertEqual(p11.C_GetAttributeValue(self.session, private_handle, CKA_CLASS)[CKA_CLASS], CKO_PRIVATE_KEY)
- def test_keygen_ec_p256(self):
+ def test_keygen_token_vs_session(self):
self.assertIsKeypair(
p11.C_GenerateKeyPair(self.session, CKM_EC_KEY_PAIR_GEN, CKA_TOKEN = False,
CKA_ID = "EC-P256", CKA_EC_PARAMS = self.oid_p256,
@@ -150,7 +150,7 @@ class TestKeys(unittest.TestCase):
CKA_SIGN = True, CKA_VERIFY = True))
def test_gen_sign_verify_ecdsa_p256_sha256(self):
- public_key, private_key = p11.C_GenerateKeyPair(self.session, CKM_EC_KEY_PAIR_GEN, CKA_TOKEN = False,
+ public_key, private_key = p11.C_GenerateKeyPair(self.session, CKM_EC_KEY_PAIR_GEN,
CKA_ID = "EC-P256", CKA_EC_PARAMS = self.oid_p256,
CKA_SIGN = True, CKA_VERIFY = True)
self.assertIsKeypair(public_key, private_key)
@@ -161,6 +161,99 @@ class TestKeys(unittest.TestCase):
p11.C_VerifyInit(self.session, CKM_ECDSA_SHA256, public_key)
p11.C_Verify(self.session, hamster, sig)
+ @unittest.skip("SHA-384 not available in current build")
+ def test_gen_sign_verify_ecdsa_p384_sha384(self):
+ public_key, private_key = p11.C_GenerateKeyPair(self.session, CKM_EC_KEY_PAIR_GEN,
+ CKA_ID = "EC-P384", CKA_EC_PARAMS = self.oid_p384,
+ CKA_SIGN = True, CKA_VERIFY = True)
+ self.assertIsKeypair(public_key, private_key)
+ hamster = "Your mother was a hamster"
+ p11.C_SignInit(self.session, CKM_ECDSA_SHA384, private_key)
+ sig = p11.C_Sign(self.session, hamster)
+ self.assertIsInstance(sig, str)
+ p11.C_VerifyInit(self.session, CKM_ECDSA_SHA384, public_key)
+ p11.C_Verify(self.session, hamster, sig)
+
+ @unittest.skip("SHA-512 not available in current build")
+ def test_gen_sign_verify_ecdsa_p521_sha512(self):
+ public_key, private_key = p11.C_GenerateKeyPair(self.session, CKM_EC_KEY_PAIR_GEN,
+ CKA_ID = "EC-P521", CKA_EC_PARAMS = self.oid_p521,
+ CKA_SIGN = True, CKA_VERIFY = True)
+ self.assertIsKeypair(public_key, private_key)
+ hamster = "Your mother was a hamster"
+ p11.C_SignInit(self.session, CKM_ECDSA_SHA512, private_key)
+ sig = p11.C_Sign(self.session, hamster)
+ self.assertIsInstance(sig, str)
+ p11.C_VerifyInit(self.session, CKM_ECDSA_SHA512, public_key)
+ p11.C_Verify(self.session, hamster, sig)
+
+ def test_gen_rsa_1024(self):
+ self.assertIsKeypair(
+ p11.C_GenerateKeyPair(self.session, CKM_RSA_PKCS_KEY_PAIR_GEN, CKA_MODULUS_BITS = 1024,
+ CKA_ID = "RSA-1024", CKA_SIGN = True, CKA_VERIFY = True))
+
+ @unittest.skip("RSA key generation is still painfully slow")
+ def test_gen_rsa_2048(self):
+ self.assertIsKeypair(
+ p11.C_GenerateKeyPair(self.session, CKM_RSA_PKCS_KEY_PAIR_GEN, CKA_MODULUS_BITS = 2048,
+ CKA_ID = "RSA-1024", CKA_SIGN = True, CKA_VERIFY = True))
+
+ @staticmethod
+ def _build_ecpoint(x, y):
+ bytes_per_coordinate = (max(x.bit_length(), y.bit_length()) + 15) / 16
+ value = chr(0x04) + ("%0*x%0*x" % (bytes_per_coordinate, x, bytes_per_coordinate, y)).decode("hex")
+ if len(value) < 128:
+ length = chr(len(value))
+ else:
+ n = len(value).bit_length()
+ length = chr((n + 7) / 8) + ("%0*x" % ((n + 15) / 16, len(value))).decode("hex")
+ tag = chr(0x04)
+ return tag + length + value
+
+ def test_canned_ecdsa_p256_verify(self):
+ Q = self._build_ecpoint(0x8101ece47464a6ead70cf69a6e2bd3d88691a3262d22cba4f7635eaff26680a8,
+ 0xd8a12ba61d599235f67d9cb4d58f1783d3ca43e78f0a5abaa624079936c0c3a9)
+ H = "7c3e883ddc8bd688f96eac5e9324222c8f30f9d6bb59e9c5f020bd39ba2b8377".decode("hex")
+ r = "7214bc9647160bbd39ff2f80533f5dc6ddd70ddf86bb815661e805d5d4e6f27c".decode("hex")
+ s = "7d1ff961980f961bdaa3233b6209f4013317d3e3f9e1493592dbeaa1af2bc367".decode("hex")
+ handle = p11.C_CreateObject(
+ session = self.session,
+ CKA_CLASS = CKO_PUBLIC_KEY,
+ CKA_KEY_TYPE = CKK_EC,
+ CKA_LABEL = "EC-P-256 test case from \"Suite B Implementer's Guide to FIPS 186-3\"",
+ CKA_ID = "EC-P-256",
+ CKA_VERIFY = True,
+ CKA_ENCRYPT = False,
+ CKA_WRAP = False,
+ CKA_TOKEN = False,
+ CKA_EC_POINT = Q,
+ CKA_EC_PARAMS = self.oid_p256)
+ p11.C_VerifyInit(self.session, CKM_ECDSA, handle)
+ p11.C_Verify(self.session, H, r + s)
+
+ def test_canned_ecdsa_p384_verify(self):
+ Q = self._build_ecpoint(0x1fbac8eebd0cbf35640b39efe0808dd774debff20a2a329e91713baf7d7f3c3e81546d883730bee7e48678f857b02ca0,
+ 0xeb213103bd68ce343365a8a4c3d4555fa385f5330203bdd76ffad1f3affb95751c132007e1b240353cb0a4cf1693bdf9)
+ H = "b9210c9d7e20897ab86597266a9d5077e8db1b06f7220ed6ee75bd8b45db37891f8ba5550304004159f4453dc5b3f5a1".decode("hex")
+ r = "a0c27ec893092dea1e1bd2ccfed3cf945c8134ed0c9f81311a0f4a05942db8dbed8dd59f267471d5462aa14fe72de856".decode("hex")
+ s = "20ab3f45b74f10b6e11f96a2c8eb694d206b9dda86d3c7e331c26b22c987b7537726577667adadf168ebbe803794a402".decode("hex")
+ handle = p11.C_CreateObject(
+ session = self.session,
+ CKA_CLASS = CKO_PUBLIC_KEY,
+ CKA_KEY_TYPE = CKK_EC,
+ CKA_LABEL = "EC-P-384 test case from \"Suite B Implementer's Guide to FIPS 186-3\"",
+ CKA_ID = "EC-P-384",
+ CKA_VERIFY = True,
+ CKA_ENCRYPT = False,
+ CKA_WRAP = False,
+ CKA_TOKEN = False,
+ CKA_EC_POINT = Q,
+ CKA_EC_PARAMS = self.oid_p384)
+ p11.C_VerifyInit(self.session, CKM_ECDSA, handle)
+ p11.C_Verify(self.session, H, r + s)
+
+
+
def setUpModule():
global p11