Add tests for RSA key hashing, chain-model validity, and PEM explanatory text - #199
Merged
Merged
Conversation
…natory text Add TRsaKeyParametersTest: the key hash code must fold in both the modulus and the exponent, so keys differing in either field hash differently and equal keys hash equally. Add TValidityModelTest: TPkixCertPathValidator honours the validation date under both the shell model (every certificate checked against the date) and the chain model (each CA checked at the time its subordinate was issued, via the subordinate NotBefore or the end-entity dateOfCertGen extension). Add TPemReaderTest.TestExplanatoryTextAroundObjects: the reader ignores explanatory text before the first object, between objects, and after the last, and does not mistake dashes in that text for a boundary (RFC 7468 sec. 5.2), through both the low-level and the OpenSSL-level readers.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds regression test coverage for three existing behaviours that were previously
unguarded. No production code changes: in each case the library already behaves
correctly, so these lock in the contract.
What's covered
RSA key parameter hashing (
TRsaKeyParametersTest, new)TRsaKeyParameters.GetHashCodemust fold in both the modulus and the exponent.Three cases:
Uses real RSA test-vector moduli, since
TRsaKeyParametersvalidates its modulus.Certification-path validity models (
TValidityModelTest, new)TPkixCertPathValidatorhonoursPkixParameters.Dateunder both validity models:PkixValidityModel): every certificate is checked against thevalidation date (a chain passes inside the end-entity window and fails before or
after it).
ChainValidityModel): only the end-entity is checked against thedate; each CA is checked at the time its subordinate was issued, so an intermediate
that has since expired still validates.
dateOfCertGen: the ISIS-MTTid-isismtt-at-dateOfCertGenextension(1.3.36.8.3.1) overrides the subordinate
NotBeforewhen timing the issuer's check.PEM explanatory text (
TPemReaderTest.TestExplanatoryTextAroundObjects, new method)Per RFC 7468 sec. 5.2, tools such as
openssl pkcs7 -print_certssurround each objectwith explanatory text. The reader must ignore it before the first
BEGIN, betweenobjects, and after the final
END, and must not mistake dashes inside that text for aboundary. Exercised through both the low-level
TPemReaderand the OpenSSL-levelTOpenSslPemReader. Input lives in a new fixture (Data/Pem/Reader/ExplanatoryText.txt)loaded via
TPemReaderVectors, matching the existing PEM tests.