You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
86 lines
2.3 KiB
86 lines
2.3 KiB
package cms_test
|
|
|
|
import (
|
|
"crypto/elliptic"
|
|
"crypto/sha1"
|
|
"errors"
|
|
"testing"
|
|
|
|
"g.activething.com/go/DateKeys/internal/cms"
|
|
"g.activething.com/go/DateKeys/internal/cms/cmstest"
|
|
"g.activething.com/go/DateKeys/internal/der"
|
|
)
|
|
|
|
// The keys and the certificates of the tests of the reader, made once: an
|
|
// RSA key takes time to generate. The certificates are made field by field,
|
|
// with the profile of spec §29.10, and are valid from 2020 to 2040.
|
|
var (
|
|
ecKey = cmstest.ECKey(elliptic.P256())
|
|
ecKey2 = cmstest.ECKey(elliptic.P256())
|
|
rsaKey = cmstest.RSAKey(2048)
|
|
|
|
ana = cmstest.NewCert(cmstest.CertSpec{CN: "Ana López"}, ecKey)
|
|
luis = cmstest.NewCert(cmstest.CertSpec{CN: "Luis Gómez"}, rsaKey)
|
|
tsa = cmstest.NewCert(cmstest.CertSpec{CN: "TSA de prueba"}, ecKey2)
|
|
)
|
|
|
|
// path joins paths of cmstest.Edit.
|
|
func path(parts ...any) []int {
|
|
var out []int
|
|
for _, p := range parts {
|
|
switch x := p.(type) {
|
|
case int:
|
|
out = append(out, x)
|
|
case []int:
|
|
out = append(out, x...)
|
|
}
|
|
}
|
|
return out
|
|
}
|
|
|
|
// firstSignerInfo is the path of the first SignerInfo of a signature.
|
|
func firstSignerInfo(b []byte) []int { return path(cmstest.SignerInfosPath(b), 0) }
|
|
|
|
// wantForm checks that the signature b breaks the profile (F1).
|
|
func wantForm(t *testing.T, name string, b []byte) {
|
|
t.Helper()
|
|
if _, err := cms.ParseSignature(b); !errors.Is(err, cms.ErrForm) {
|
|
t.Errorf("%s: %v, want a form error", name, err)
|
|
}
|
|
}
|
|
|
|
// signerOf parses the signature b, which must meet the profile, and returns
|
|
// its only SignerInfo.
|
|
func signerOf(t *testing.T, name string, b []byte) *cms.SignerInfo {
|
|
t.Helper()
|
|
sd, err := cms.ParseSignature(b)
|
|
if err != nil || len(sd.Signers) != 1 {
|
|
t.Fatalf("%s: %v", name, err)
|
|
}
|
|
return sd.Signers[0]
|
|
}
|
|
|
|
// resultOf is the result of the only SignerInfo of the signature b over msg.
|
|
func resultOf(t *testing.T, name string, b []byte) cms.Result {
|
|
t.Helper()
|
|
return signerOf(t, name, b).Check(msg)
|
|
}
|
|
|
|
func isForm(err error) bool { return errors.Is(err, cms.ErrForm) }
|
|
|
|
func isAlgorithm(err error) bool { return errors.Is(err, cms.ErrAlgorithm) }
|
|
|
|
// contentOf returns the content octets of the DER element b.
|
|
func contentOf(b []byte) []byte {
|
|
c, err := der.Content(b)
|
|
if err != nil {
|
|
panic(err)
|
|
}
|
|
return c
|
|
}
|
|
|
|
func sha1Sum(b []byte) []byte {
|
|
s := sha1.Sum(b)
|
|
return s[:]
|
|
}
|