Skip to content

Add tests for RSA key hashing, chain-model validity, and PEM explanatory text - #199

Merged
Xor-el merged 1 commit into
masterfrom
tests/hashcode-pem-validitymodel-guards
Sep 7, 2026
Merged

Xor-el merged 1 commit into
masterfrom
tests/hashcode-pem-validitymodel-guards

Conversation

@Xor-el

@Xor-el Xor-el commented Sep 7, 2026

Copy link
Copy Markdown
Owner

Summary

Adds regression test coverage for three existing behaviours that were previously
unguarded. No production code changes: in each case the library already behaves
correctly, so these lock in the contract.

What's covered

RSA key parameter hashing (TRsaKeyParametersTest, new)

TRsaKeyParameters.GetHashCode must fold in both the modulus and the exponent.
Three cases:

  • keys differing only in the exponent hash differently (and are unequal)
  • keys differing only in the modulus hash differently (and are unequal)
  • equal keys hash equally

Uses real RSA test-vector moduli, since TRsaKeyParameters validates its modulus.

Certification-path validity models (TValidityModelTest, new)

TPkixCertPathValidator honours PkixParameters.Date under both validity models:

  • Shell model (PkixValidityModel): every certificate is checked against the
    validation date (a chain passes inside the end-entity window and fails before or
    after it).
  • Chain model (ChainValidityModel): only the end-entity is checked against the
    date; each CA is checked at the time its subordinate was issued, so an intermediate
    that has since expired still validates.
  • dateOfCertGen: the ISIS-MTT id-isismtt-at-dateOfCertGen extension
    (1.3.36.8.3.1) overrides the subordinate NotBefore when timing the issuer's check.

PEM explanatory text (TPemReaderTest.TestExplanatoryTextAroundObjects, new method)

Per RFC 7468 sec. 5.2, tools such as openssl pkcs7 -print_certs surround each object
with explanatory text. The reader must ignore it before the first BEGIN, between
objects, and after the final END, and must not mistake dashes inside that text for a
boundary. Exercised through both the low-level TPemReader and the OpenSSL-level
TOpenSslPemReader. Input lives in a new fixture (Data/Pem/Reader/ExplanatoryText.txt)
loaded via TPemReaderVectors, matching the existing PEM tests.

…natory text

Add TRsaKeyParametersTest: the key hash code must fold in both the modulus and the
exponent, so keys differing in either field hash differently and equal keys hash
equally.

Add TValidityModelTest: TPkixCertPathValidator honours the validation date under both
the shell model (every certificate checked against the date) and the chain model (each
CA checked at the time its subordinate was issued, via the subordinate NotBefore or the
end-entity dateOfCertGen extension).

Add TPemReaderTest.TestExplanatoryTextAroundObjects: the reader ignores explanatory text
before the first object, between objects, and after the last, and does not mistake dashes
in that text for a boundary (RFC 7468 sec. 5.2), through both the low-level and the
OpenSSL-level readers.
@Xor-el
Xor-el merged commit 8e2f024 into master Sep 7, 2026
42 checks passed
@Xor-el
Xor-el deleted the tests/hashcode-pem-validitymodel-guards branch September 7, 2026 13:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant