update main-with-bazel from master branch
This commit is contained in:
+1
-1
@@ -171,13 +171,13 @@ crypto_headers = [
|
||||
"src/include/openssl/evp.h",
|
||||
"src/include/openssl/evp_errors.h",
|
||||
"src/include/openssl/ex_data.h",
|
||||
"src/include/openssl/experimental/kyber.h",
|
||||
"src/include/openssl/hkdf.h",
|
||||
"src/include/openssl/hmac.h",
|
||||
"src/include/openssl/hpke.h",
|
||||
"src/include/openssl/hrss.h",
|
||||
"src/include/openssl/is_boringssl.h",
|
||||
"src/include/openssl/kdf.h",
|
||||
"src/include/openssl/kyber.h",
|
||||
"src/include/openssl/lhash.h",
|
||||
"src/include/openssl/md4.h",
|
||||
"src/include/openssl/md5.h",
|
||||
|
||||
+1
-1
@@ -405,13 +405,13 @@
|
||||
"src/include/openssl/evp.h",
|
||||
"src/include/openssl/evp_errors.h",
|
||||
"src/include/openssl/ex_data.h",
|
||||
"src/include/openssl/experimental/kyber.h",
|
||||
"src/include/openssl/hkdf.h",
|
||||
"src/include/openssl/hmac.h",
|
||||
"src/include/openssl/hpke.h",
|
||||
"src/include/openssl/hrss.h",
|
||||
"src/include/openssl/is_boringssl.h",
|
||||
"src/include/openssl/kdf.h",
|
||||
"src/include/openssl/kyber.h",
|
||||
"src/include/openssl/lhash.h",
|
||||
"src/include/openssl/md4.h",
|
||||
"src/include/openssl/md5.h",
|
||||
|
||||
@@ -16,6 +16,9 @@ OpenSSL's legacy ASN.1, X.509, and PEM implementation. If possible, avoid using
|
||||
them. These are left largely unmodified from upstream and are retained only for
|
||||
compatibility with existing OpenSSL consumers.
|
||||
|
||||
Experimental public APIs are found in `include/openssl/experimental`. Use of
|
||||
these will likely be incompatible with changes in the near future as they are
|
||||
finalized.
|
||||
|
||||
## Forward declarations
|
||||
|
||||
|
||||
@@ -813,10 +813,7 @@ TEST_P(BIOPairTest, TestPair) {
|
||||
// A closed write end may not be written to.
|
||||
EXPECT_EQ(0u, BIO_ctrl_get_write_guarantee(bio1));
|
||||
EXPECT_EQ(-1, BIO_write(bio1, "_____", 5));
|
||||
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_BIO, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(BIO_R_BROKEN_PIPE, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_get_error(), ERR_LIB_BIO, BIO_R_BROKEN_PIPE));
|
||||
|
||||
// The other end is still functional.
|
||||
EXPECT_EQ(5, BIO_write(bio2, "12345", 5));
|
||||
|
||||
@@ -381,7 +381,7 @@ TEST_P(PerAEADTest, TestVectorScatterGather) {
|
||||
|
||||
// Skip decryption for AEADs that don't implement open_gather().
|
||||
if (!ret) {
|
||||
int err = ERR_peek_error();
|
||||
uint32_t err = ERR_peek_error();
|
||||
if (ERR_GET_LIB(err) == ERR_LIB_CIPHER &&
|
||||
ERR_GET_REASON(err) == CIPHER_R_CTRL_NOT_IMPLEMENTED) {
|
||||
t->SkipCurrent();
|
||||
@@ -709,10 +709,10 @@ TEST_P(PerAEADTest, InvalidNonceLength) {
|
||||
nonce.data(), nonce.size(), nullptr /* in */,
|
||||
0, kZeros /* ad */, ad_len));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_CIPHER, ERR_GET_LIB(err));
|
||||
// TODO(davidben): Merge these errors. https://crbug.com/boringssl/129.
|
||||
if (ERR_GET_REASON(err) != CIPHER_R_UNSUPPORTED_NONCE_SIZE) {
|
||||
EXPECT_EQ(CIPHER_R_INVALID_NONCE_SIZE, ERR_GET_REASON(err));
|
||||
if (!ErrorEquals(err, ERR_LIB_CIPHER, CIPHER_R_UNSUPPORTED_NONCE_SIZE)) {
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(err, ERR_LIB_CIPHER, CIPHER_R_INVALID_NONCE_SIZE));
|
||||
}
|
||||
|
||||
ctx.Reset();
|
||||
@@ -723,9 +723,9 @@ TEST_P(PerAEADTest, InvalidNonceLength) {
|
||||
nonce.data(), nonce.size(), kZeros /* in */,
|
||||
sizeof(kZeros), kZeros /* ad */, ad_len));
|
||||
err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_CIPHER, ERR_GET_LIB(err));
|
||||
if (ERR_GET_REASON(err) != CIPHER_R_UNSUPPORTED_NONCE_SIZE) {
|
||||
EXPECT_EQ(CIPHER_R_INVALID_NONCE_SIZE, ERR_GET_REASON(err));
|
||||
if (!ErrorEquals(err, ERR_LIB_CIPHER, CIPHER_R_UNSUPPORTED_NONCE_SIZE)) {
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(err, ERR_LIB_CIPHER, CIPHER_R_INVALID_NONCE_SIZE));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -267,9 +267,8 @@ TEST(DSATest, InvalidGroup) {
|
||||
static const uint8_t kDigest[32] = {0};
|
||||
EXPECT_FALSE(
|
||||
DSA_sign(0, kDigest, sizeof(kDigest), sig.data(), &sig_len, dsa.get()));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_DSA, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(DSA_R_INVALID_PARAMETERS, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_DSA, DSA_R_INVALID_PARAMETERS));
|
||||
}
|
||||
|
||||
// Signing and verifying should cleanly fail when the DSA object is empty.
|
||||
|
||||
@@ -812,7 +812,8 @@ TEST(EVPExtraTest, MarshalEmptyPublicKey) {
|
||||
bssl::ScopedCBB cbb;
|
||||
EXPECT_FALSE(EVP_marshal_public_key(cbb.get(), empty.get()))
|
||||
<< "Marshalled empty public key.";
|
||||
EXPECT_EQ(EVP_R_UNSUPPORTED_ALGORITHM, ERR_GET_REASON(ERR_peek_last_error()));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_peek_last_error(), ERR_LIB_EVP,
|
||||
EVP_R_UNSUPPORTED_ALGORITHM));
|
||||
}
|
||||
|
||||
TEST(EVPExtraTest, d2i_PrivateKey) {
|
||||
@@ -890,16 +891,14 @@ TEST(EVPExtraTest, Ed25519) {
|
||||
// Passing too small of a buffer is noticed.
|
||||
len = 31;
|
||||
EXPECT_FALSE(EVP_PKEY_get_raw_public_key(pubkey.get(), buf, &len));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_EVP, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(EVP_R_BUFFER_TOO_SMALL, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_EVP, EVP_R_BUFFER_TOO_SMALL));
|
||||
ERR_clear_error();
|
||||
|
||||
// There is no private key.
|
||||
EXPECT_FALSE(EVP_PKEY_get_raw_private_key(pubkey.get(), nullptr, &len));
|
||||
err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_EVP, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(EVP_R_NOT_A_PRIVATE_KEY, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_EVP, EVP_R_NOT_A_PRIVATE_KEY));
|
||||
ERR_clear_error();
|
||||
|
||||
// The public key must encode properly.
|
||||
@@ -915,9 +914,8 @@ TEST(EVPExtraTest, Ed25519) {
|
||||
// The public key must gracefully fail to encode as a private key.
|
||||
ASSERT_TRUE(CBB_init(cbb.get(), 0));
|
||||
EXPECT_FALSE(EVP_marshal_private_key(cbb.get(), pubkey.get()));
|
||||
err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_EVP, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(EVP_R_NOT_A_PRIVATE_KEY, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_EVP, EVP_R_NOT_A_PRIVATE_KEY));
|
||||
ERR_clear_error();
|
||||
cbb.Reset();
|
||||
|
||||
@@ -940,9 +938,8 @@ TEST(EVPExtraTest, Ed25519) {
|
||||
// Passing too small of a buffer is noticed.
|
||||
len = 31;
|
||||
EXPECT_FALSE(EVP_PKEY_get_raw_private_key(privkey.get(), buf, &len));
|
||||
err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_EVP, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(EVP_R_BUFFER_TOO_SMALL, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_EVP, EVP_R_BUFFER_TOO_SMALL));
|
||||
ERR_clear_error();
|
||||
// The public key must be extractable.
|
||||
len = 32;
|
||||
@@ -995,9 +992,8 @@ TEST(EVPExtraTest, Ed25519) {
|
||||
EVP_DigestSignInit(ctx.get(), nullptr, nullptr, nullptr, privkey.get()));
|
||||
len = 31;
|
||||
EXPECT_FALSE(EVP_DigestSign(ctx.get(), buf, &len, nullptr /* msg */, 0));
|
||||
err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_EVP, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(EVP_R_BUFFER_TOO_SMALL, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_EVP, EVP_R_BUFFER_TOO_SMALL));
|
||||
ERR_clear_error();
|
||||
}
|
||||
|
||||
|
||||
@@ -69,9 +69,8 @@ TEST(ScryptTest, MemoryLimit) {
|
||||
reinterpret_cast<const uint8_t *>(kSalt),
|
||||
strlen(kSalt), 1048576 /* N */, 8 /* r */,
|
||||
1 /* p */, 0 /* max_mem */, key, sizeof(key)));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_EVP, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(EVP_R_MEMORY_LIMIT_EXCEEDED, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_EVP, EVP_R_MEMORY_LIMIT_EXCEEDED));
|
||||
}
|
||||
|
||||
TEST(ScryptTest, InvalidParameters) {
|
||||
|
||||
@@ -884,9 +884,7 @@ static void TestNotModSquare(BIGNUMFileTest *t, BN_CTX *ctx) {
|
||||
EXPECT_FALSE(BN_mod_sqrt(ret.get(), not_mod_square.get(), p.get(), ctx))
|
||||
<< "BN_mod_sqrt unexpectedly succeeded.";
|
||||
|
||||
uint32_t err = ERR_peek_error();
|
||||
EXPECT_EQ(ERR_LIB_BN, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(BN_R_NOT_A_SQUARE, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_peek_error(), ERR_LIB_BN, BN_R_NOT_A_SQUARE));
|
||||
ERR_clear_error();
|
||||
}
|
||||
|
||||
|
||||
@@ -657,7 +657,8 @@ TEST_P(AEADServiceIndicatorTest, EVP_AEAD) {
|
||||
encrypt_output.size(), nonce.data(), nonce.size(),
|
||||
kPlaintext, sizeof(kPlaintext), nullptr, 0)));
|
||||
EXPECT_EQ(approved, FIPSStatus::NOT_APPROVED);
|
||||
EXPECT_EQ(ERR_GET_REASON(ERR_get_error()), CIPHER_R_INVALID_NONCE);
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_CIPHER, CIPHER_R_INVALID_NONCE));
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -554,9 +554,8 @@ TEST(HPKETest, SetupSenderBufferTooSmall) {
|
||||
sender_ctx.get(), enc, &enc_len, sizeof(enc),
|
||||
EVP_hpke_x25519_hkdf_sha256(), EVP_hpke_hkdf_sha256(),
|
||||
EVP_hpke_aes_128_gcm(), public_key_r, sizeof(public_key_r), nullptr, 0));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_EVP, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(EVP_R_INVALID_BUFFER_SIZE, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_EVP, EVP_R_INVALID_BUFFER_SIZE));
|
||||
ERR_clear_error();
|
||||
}
|
||||
|
||||
@@ -587,9 +586,8 @@ TEST(HPKETest, SetupRecipientWrongLengthEnc) {
|
||||
ASSERT_FALSE(EVP_HPKE_CTX_setup_recipient(
|
||||
recipient_ctx.get(), key.get(), EVP_hpke_hkdf_sha256(),
|
||||
EVP_hpke_aes_128_gcm(), bogus_enc, sizeof(bogus_enc), nullptr, 0));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_EVP, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(EVP_R_INVALID_PEER_KEY, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_EVP, EVP_R_INVALID_PEER_KEY));
|
||||
ERR_clear_error();
|
||||
}
|
||||
|
||||
@@ -603,9 +601,8 @@ TEST(HPKETest, SetupSenderWrongLengthPeerPublicValue) {
|
||||
EVP_hpke_x25519_hkdf_sha256(), EVP_hpke_hkdf_sha256(),
|
||||
EVP_hpke_aes_128_gcm(), bogus_public_key_r, sizeof(bogus_public_key_r),
|
||||
nullptr, 0));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_EVP, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(EVP_R_INVALID_PEER_KEY, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_EVP, EVP_R_INVALID_PEER_KEY));
|
||||
ERR_clear_error();
|
||||
}
|
||||
|
||||
|
||||
@@ -16,7 +16,7 @@
|
||||
#define OPENSSL_HEADER_CRYPTO_KYBER_INTERNAL_H
|
||||
|
||||
#include <openssl/base.h>
|
||||
#include <openssl/kyber.h>
|
||||
#include <openssl/experimental/kyber.h>
|
||||
|
||||
#if defined(__cplusplus)
|
||||
extern "C" {
|
||||
|
||||
@@ -12,7 +12,7 @@
|
||||
* OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
|
||||
* CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
|
||||
|
||||
#include <openssl/kyber.h>
|
||||
#include <openssl/experimental/kyber.h>
|
||||
|
||||
#include <assert.h>
|
||||
#include <stdlib.h>
|
||||
|
||||
@@ -20,7 +20,7 @@
|
||||
|
||||
#include <openssl/bytestring.h>
|
||||
#include <openssl/ctrdrbg.h>
|
||||
#include <openssl/kyber.h>
|
||||
#include <openssl/experimental/kyber.h>
|
||||
|
||||
#include "../test/file_test.h"
|
||||
#include "../test/test_util.h"
|
||||
|
||||
@@ -20,6 +20,8 @@
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/rsa.h>
|
||||
|
||||
#include "../test/test_util.h"
|
||||
|
||||
|
||||
// Test that implausible ciphers, notably an IV-less RC4, aren't allowed in PEM.
|
||||
// This is a regression test for https://github.com/openssl/openssl/issues/6347,
|
||||
@@ -39,7 +41,6 @@ TEST(PEMTest, NoRC4) {
|
||||
bssl::UniquePtr<RSA> rsa(PEM_read_bio_RSAPublicKey(
|
||||
bio.get(), nullptr, nullptr, const_cast<char *>("password")));
|
||||
EXPECT_FALSE(rsa);
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_PEM, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(PEM_R_UNSUPPORTED_ENCRYPTION, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_PEM, PEM_R_UNSUPPORTED_ENCRYPTION));
|
||||
}
|
||||
|
||||
@@ -712,9 +712,8 @@ TEST(RSATest, GenerateSmallKey) {
|
||||
ASSERT_TRUE(BN_set_word(e.get(), RSA_F4));
|
||||
|
||||
EXPECT_FALSE(RSA_generate_key_ex(rsa.get(), 255, e.get(), nullptr));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_RSA, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(RSA_R_KEY_SIZE_TOO_SMALL, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_RSA, RSA_R_KEY_SIZE_TOO_SMALL));
|
||||
}
|
||||
|
||||
// Attempting to generate an funny RSA key length should round down.
|
||||
@@ -1175,17 +1174,13 @@ TEST(RSATest, MissingParameters) {
|
||||
std::vector<uint8_t> out(RSA_size(sample.get()));
|
||||
EXPECT_FALSE(RSA_sign(NID_sha256, kZeros, sizeof(kZeros), out.data(), &len_u,
|
||||
rsa.get()));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_RSA, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(RSA_R_VALUE_MISSING, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_get_error(), ERR_LIB_RSA, RSA_R_VALUE_MISSING));
|
||||
|
||||
size_t len;
|
||||
EXPECT_FALSE(RSA_decrypt(rsa.get(), &len, out.data(), out.size(),
|
||||
kOAEPCiphertext1, sizeof(kOAEPCiphertext1),
|
||||
RSA_PKCS1_OAEP_PADDING));
|
||||
err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_RSA, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(RSA_R_VALUE_MISSING, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_get_error(), ERR_LIB_RSA, RSA_R_VALUE_MISSING));
|
||||
|
||||
// A private key without e cannot perform public key operations.
|
||||
rsa.reset(RSA_new_private_key_no_e(RSA_get0_n(sample.get()),
|
||||
@@ -1194,15 +1189,11 @@ TEST(RSATest, MissingParameters) {
|
||||
|
||||
EXPECT_FALSE(RSA_verify(NID_sha256, kZeros, sizeof(kZeros), sig.data(),
|
||||
sig.size(), rsa.get()));
|
||||
err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_RSA, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(RSA_R_VALUE_MISSING, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_get_error(), ERR_LIB_RSA, RSA_R_VALUE_MISSING));
|
||||
|
||||
EXPECT_FALSE(RSA_encrypt(rsa.get(), &len, out.data(), out.size(), kPlaintext,
|
||||
sizeof(kPlaintext), RSA_PKCS1_OAEP_PADDING));
|
||||
err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_RSA, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(RSA_R_VALUE_MISSING, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_get_error(), ERR_LIB_RSA, RSA_R_VALUE_MISSING));
|
||||
}
|
||||
|
||||
TEST(RSATest, Negative) {
|
||||
|
||||
@@ -16,6 +16,8 @@
|
||||
|
||||
#include <ostream>
|
||||
|
||||
#include <openssl/err.h>
|
||||
|
||||
#include "../internal.h"
|
||||
|
||||
|
||||
@@ -67,3 +69,16 @@ std::string EncodeHex(bssl::Span<const uint8_t> in) {
|
||||
return ret;
|
||||
}
|
||||
|
||||
testing::AssertionResult ErrorEquals(uint32_t err, int lib, int reason) {
|
||||
if (ERR_GET_LIB(err) == lib && ERR_GET_REASON(err) == reason) {
|
||||
return testing::AssertionSuccess();
|
||||
}
|
||||
|
||||
char buf[128], expected[128];
|
||||
return testing::AssertionFailure()
|
||||
<< "Got \"" << ERR_error_string_n(err, buf, sizeof(buf))
|
||||
<< "\", wanted \""
|
||||
<< ERR_error_string_n(ERR_PACK(lib, reason), expected,
|
||||
sizeof(expected))
|
||||
<< "\"";
|
||||
}
|
||||
|
||||
@@ -24,6 +24,8 @@
|
||||
#include <string>
|
||||
#include <vector>
|
||||
|
||||
#include <gtest/gtest.h>
|
||||
|
||||
#include <openssl/span.h>
|
||||
|
||||
#include "../internal.h"
|
||||
@@ -67,5 +69,9 @@ bool DecodeHex(std::vector<uint8_t> *out, const std::string &in);
|
||||
// EncodeHex returns |in| encoded in hexadecimal.
|
||||
std::string EncodeHex(bssl::Span<const uint8_t> in);
|
||||
|
||||
// ErrorEquals asserts that |err| is an error with library |lib| and reason
|
||||
// |reason|.
|
||||
testing::AssertionResult ErrorEquals(uint32_t err, int lib, int reason);
|
||||
|
||||
|
||||
#endif // OPENSSL_HEADER_CRYPTO_TEST_TEST_UTIL_H
|
||||
|
||||
+12
-17
@@ -72,6 +72,7 @@ typedef struct lookup_dir_hashes_st {
|
||||
} BY_DIR_HASH;
|
||||
|
||||
typedef struct lookup_dir_entry_st {
|
||||
CRYPTO_MUTEX lock;
|
||||
char *dir;
|
||||
int dir_type;
|
||||
STACK_OF(BY_DIR_HASH) *hashes;
|
||||
@@ -156,6 +157,7 @@ static int by_dir_hash_cmp(const BY_DIR_HASH *const *a,
|
||||
|
||||
static void by_dir_entry_free(BY_DIR_ENTRY *ent) {
|
||||
if (ent != NULL) {
|
||||
CRYPTO_MUTEX_cleanup(&ent->lock);
|
||||
OPENSSL_free(ent->dir);
|
||||
sk_BY_DIR_HASH_pop_free(ent->hashes, by_dir_hash_free);
|
||||
OPENSSL_free(ent);
|
||||
@@ -215,15 +217,12 @@ static int add_cert_dir(BY_DIR *ctx, const char *dir, int type) {
|
||||
if (!ent) {
|
||||
return 0;
|
||||
}
|
||||
CRYPTO_MUTEX_init(&ent->lock);
|
||||
ent->dir_type = type;
|
||||
ent->hashes = sk_BY_DIR_HASH_new(by_dir_hash_cmp);
|
||||
ent->dir = OPENSSL_malloc(len + 1);
|
||||
if (!ent->dir || !ent->hashes) {
|
||||
by_dir_entry_free(ent);
|
||||
return 0;
|
||||
}
|
||||
OPENSSL_strlcpy(ent->dir, ss, len + 1);
|
||||
if (!sk_BY_DIR_ENTRY_push(ctx->dirs, ent)) {
|
||||
ent->dir = OPENSSL_strndup(ss, len);
|
||||
if (ent->dir == NULL || ent->hashes == NULL ||
|
||||
!sk_BY_DIR_ENTRY_push(ctx->dirs, ent)) {
|
||||
by_dir_entry_free(ent);
|
||||
return 0;
|
||||
}
|
||||
@@ -232,10 +231,6 @@ static int add_cert_dir(BY_DIR *ctx, const char *dir, int type) {
|
||||
return 1;
|
||||
}
|
||||
|
||||
// g_ent_hashes_lock protects the |hashes| member of all |BY_DIR_ENTRY|
|
||||
// objects.
|
||||
static CRYPTO_MUTEX g_ent_hashes_lock = CRYPTO_MUTEX_INIT;
|
||||
|
||||
static int get_cert_by_subject(X509_LOOKUP *xl, int type, X509_NAME *name,
|
||||
X509_OBJECT *ret) {
|
||||
union {
|
||||
@@ -300,7 +295,7 @@ static int get_cert_by_subject(X509_LOOKUP *xl, int type, X509_NAME *name,
|
||||
}
|
||||
if (type == X509_LU_CRL && ent->hashes) {
|
||||
htmp.hash = h;
|
||||
CRYPTO_MUTEX_lock_read(&g_ent_hashes_lock);
|
||||
CRYPTO_MUTEX_lock_read(&ent->lock);
|
||||
if (sk_BY_DIR_HASH_find(ent->hashes, &idx, &htmp)) {
|
||||
hent = sk_BY_DIR_HASH_value(ent->hashes, idx);
|
||||
k = hent->suffix;
|
||||
@@ -308,7 +303,7 @@ static int get_cert_by_subject(X509_LOOKUP *xl, int type, X509_NAME *name,
|
||||
hent = NULL;
|
||||
k = 0;
|
||||
}
|
||||
CRYPTO_MUTEX_unlock_read(&g_ent_hashes_lock);
|
||||
CRYPTO_MUTEX_unlock_read(&ent->lock);
|
||||
} else {
|
||||
k = 0;
|
||||
hent = NULL;
|
||||
@@ -341,7 +336,7 @@ static int get_cert_by_subject(X509_LOOKUP *xl, int type, X509_NAME *name,
|
||||
// If a CRL, update the last file suffix added for this
|
||||
|
||||
if (type == X509_LU_CRL) {
|
||||
CRYPTO_MUTEX_lock_write(&g_ent_hashes_lock);
|
||||
CRYPTO_MUTEX_lock_write(&ent->lock);
|
||||
// Look for entry again in case another thread added an entry
|
||||
// first.
|
||||
if (!hent) {
|
||||
@@ -354,14 +349,14 @@ static int get_cert_by_subject(X509_LOOKUP *xl, int type, X509_NAME *name,
|
||||
if (!hent) {
|
||||
hent = OPENSSL_malloc(sizeof(BY_DIR_HASH));
|
||||
if (hent == NULL) {
|
||||
CRYPTO_MUTEX_unlock_write(&g_ent_hashes_lock);
|
||||
CRYPTO_MUTEX_unlock_write(&ent->lock);
|
||||
ok = 0;
|
||||
goto finish;
|
||||
}
|
||||
hent->hash = h;
|
||||
hent->suffix = k;
|
||||
if (!sk_BY_DIR_HASH_push(ent->hashes, hent)) {
|
||||
CRYPTO_MUTEX_unlock_write(&g_ent_hashes_lock);
|
||||
CRYPTO_MUTEX_unlock_write(&ent->lock);
|
||||
OPENSSL_free(hent);
|
||||
ok = 0;
|
||||
goto finish;
|
||||
@@ -371,7 +366,7 @@ static int get_cert_by_subject(X509_LOOKUP *xl, int type, X509_NAME *name,
|
||||
hent->suffix = k;
|
||||
}
|
||||
|
||||
CRYPTO_MUTEX_unlock_write(&g_ent_hashes_lock);
|
||||
CRYPTO_MUTEX_unlock_write(&ent->lock);
|
||||
}
|
||||
|
||||
if (tmp != NULL) {
|
||||
|
||||
@@ -2062,9 +2062,8 @@ TEST(X509Test, TestEd25519BadParameters) {
|
||||
|
||||
ASSERT_FALSE(X509_verify(cert.get(), pkey.get()));
|
||||
|
||||
uint32_t err = ERR_get_error();
|
||||
ASSERT_EQ(ERR_LIB_X509, ERR_GET_LIB(err));
|
||||
ASSERT_EQ(X509_R_INVALID_PARAMETER, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_X509, X509_R_INVALID_PARAMETER));
|
||||
ERR_clear_error();
|
||||
}
|
||||
|
||||
@@ -2909,9 +2908,8 @@ TEST(X509Test, MismatchAlgorithms) {
|
||||
ASSERT_TRUE(pkey);
|
||||
|
||||
EXPECT_FALSE(X509_verify(cert.get(), pkey.get()));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_X509, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(X509_R_SIGNATURE_ALGORITHM_MISMATCH, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_get_error(), ERR_LIB_X509,
|
||||
X509_R_SIGNATURE_ALGORITHM_MISMATCH));
|
||||
}
|
||||
|
||||
TEST(X509Test, PEMX509Info) {
|
||||
@@ -3044,9 +3042,8 @@ TEST(X509Test, ReadBIOEmpty) {
|
||||
// certificates.
|
||||
bssl::UniquePtr<X509> x509(d2i_X509_bio(bio.get(), nullptr));
|
||||
EXPECT_FALSE(x509);
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_ASN1, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(ASN1_R_HEADER_TOO_LONG, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_ASN1, ASN1_R_HEADER_TOO_LONG));
|
||||
}
|
||||
|
||||
TEST(X509Test, ReadBIOOneByte) {
|
||||
@@ -3058,9 +3055,8 @@ TEST(X509Test, ReadBIOOneByte) {
|
||||
// to signal EOF.
|
||||
bssl::UniquePtr<X509> x509(d2i_X509_bio(bio.get(), nullptr));
|
||||
EXPECT_FALSE(x509);
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_ASN1, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(ASN1_R_NOT_ENOUGH_DATA, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_ASN1, ASN1_R_NOT_ENOUGH_DATA));
|
||||
}
|
||||
|
||||
TEST(X509Test, PartialBIOReturn) {
|
||||
@@ -3773,9 +3769,8 @@ TEST(X509Test, AlgorithmParameters) {
|
||||
cert = CertFromPEM(kP256InvalidParam);
|
||||
ASSERT_TRUE(cert);
|
||||
EXPECT_FALSE(X509_verify(cert.get(), key.get()));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_X509, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(X509_R_INVALID_PARAMETER, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_X509, X509_R_INVALID_PARAMETER));
|
||||
|
||||
// RSA parameters should be NULL, but we accept omitted ones.
|
||||
key = PrivateKeyFromPEM(kRSAKey);
|
||||
@@ -3792,9 +3787,8 @@ TEST(X509Test, AlgorithmParameters) {
|
||||
cert = CertFromPEM(kRSAInvalidParam);
|
||||
ASSERT_TRUE(cert);
|
||||
EXPECT_FALSE(X509_verify(cert.get(), key.get()));
|
||||
err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_X509, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(X509_R_INVALID_PARAMETER, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_X509, X509_R_INVALID_PARAMETER));
|
||||
}
|
||||
|
||||
TEST(X509Test, GeneralName) {
|
||||
|
||||
+28
-10
@@ -848,15 +848,22 @@ OPENSSL_EXPORT void SSL_CTX_set0_buffer_pool(SSL_CTX *ctx,
|
||||
// the wire) but does not include the leaf. Both client and server certificates
|
||||
// use these functions.
|
||||
//
|
||||
// Prefer to configure the certificate before the private key. If configured in
|
||||
// the other order, inconsistent private keys will be silently dropped, rather
|
||||
// than return an error. Additionally, overwriting a previously-configured
|
||||
// certificate and key pair only works if the certificate is configured first.
|
||||
//
|
||||
// Certificates and keys may be configured before the handshake or dynamically
|
||||
// in the early callback and certificate callback.
|
||||
|
||||
// SSL_CTX_use_certificate sets |ctx|'s leaf certificate to |x509|. It returns
|
||||
// one on success and zero on failure.
|
||||
// one on success and zero on failure. If |ctx| has a private key which is
|
||||
// inconsistent with |x509|, the private key is silently dropped.
|
||||
OPENSSL_EXPORT int SSL_CTX_use_certificate(SSL_CTX *ctx, X509 *x509);
|
||||
|
||||
// SSL_use_certificate sets |ssl|'s leaf certificate to |x509|. It returns one
|
||||
// on success and zero on failure.
|
||||
// on success and zero on failure. If |ssl| has a private key which is
|
||||
// inconsistent with |x509|, the private key is silently dropped.
|
||||
OPENSSL_EXPORT int SSL_use_certificate(SSL *ssl, X509 *x509);
|
||||
|
||||
// SSL_CTX_use_PrivateKey sets |ctx|'s private key to |pkey|. It returns one on
|
||||
@@ -990,14 +997,6 @@ SSL_get0_peer_delegation_algorithms(const SSL *ssl,
|
||||
// chain of |ssl|.
|
||||
OPENSSL_EXPORT void SSL_certs_clear(SSL *ssl);
|
||||
|
||||
// SSL_CTX_check_private_key returns one if the certificate and private key
|
||||
// configured in |ctx| are consistent and zero otherwise.
|
||||
OPENSSL_EXPORT int SSL_CTX_check_private_key(const SSL_CTX *ctx);
|
||||
|
||||
// SSL_check_private_key returns one if the certificate and private key
|
||||
// configured in |ssl| are consistent and zero otherwise.
|
||||
OPENSSL_EXPORT int SSL_check_private_key(const SSL *ssl);
|
||||
|
||||
// SSL_CTX_get0_certificate returns |ctx|'s leaf certificate.
|
||||
OPENSSL_EXPORT X509 *SSL_CTX_get0_certificate(const SSL_CTX *ctx);
|
||||
|
||||
@@ -5317,6 +5316,25 @@ OPENSSL_EXPORT int SSL_set1_curves_list(SSL *ssl, const char *curves);
|
||||
// returns this value, but we define this constant for compatibility.
|
||||
#define TLSEXT_nid_unknown 0x1000000
|
||||
|
||||
// SSL_CTX_check_private_key returns one if |ctx| has both a certificate and
|
||||
// private key, and zero otherwise.
|
||||
//
|
||||
// This function does not check consistency because the library checks when the
|
||||
// certificate and key are individually configured. However, if the private key
|
||||
// is configured before the certificate, inconsistent private keys are silently
|
||||
// dropped. Some callers are inadvertently relying on this function to detect
|
||||
// when this happens.
|
||||
//
|
||||
// Instead, callers should configure the certificate first, then the private
|
||||
// key, checking for errors in each. This function is then unnecessary.
|
||||
OPENSSL_EXPORT int SSL_CTX_check_private_key(const SSL_CTX *ctx);
|
||||
|
||||
// SSL_check_private_key returns one if |ssl| has both a certificate and private
|
||||
// key, and zero otherwise.
|
||||
//
|
||||
// See discussion in |SSL_CTX_check_private_key|.
|
||||
OPENSSL_EXPORT int SSL_check_private_key(const SSL *ssl);
|
||||
|
||||
|
||||
// Compliance policy configurations
|
||||
//
|
||||
|
||||
@@ -3202,7 +3202,6 @@ bool ssl_is_key_type_supported(int key_type);
|
||||
// message on the error queue.
|
||||
bool ssl_compare_public_and_private_key(const EVP_PKEY *pubkey,
|
||||
const EVP_PKEY *privkey);
|
||||
bool ssl_cert_check_private_key(const CERT *cert, const EVP_PKEY *privkey);
|
||||
bool ssl_get_new_session(SSL_HANDSHAKE *hs);
|
||||
bool ssl_encrypt_ticket(SSL_HANDSHAKE *hs, CBB *out,
|
||||
const SSL_SESSION *session);
|
||||
|
||||
@@ -493,30 +493,6 @@ bool ssl_compare_public_and_private_key(const EVP_PKEY *pubkey,
|
||||
return false;
|
||||
}
|
||||
|
||||
bool ssl_cert_check_private_key(const CERT *cert, const EVP_PKEY *privkey) {
|
||||
if (privkey == nullptr) {
|
||||
OPENSSL_PUT_ERROR(SSL, SSL_R_NO_PRIVATE_KEY_ASSIGNED);
|
||||
return false;
|
||||
}
|
||||
|
||||
if (cert->chain == nullptr ||
|
||||
sk_CRYPTO_BUFFER_value(cert->chain.get(), 0) == nullptr) {
|
||||
OPENSSL_PUT_ERROR(SSL, SSL_R_NO_CERTIFICATE_ASSIGNED);
|
||||
return false;
|
||||
}
|
||||
|
||||
CBS cert_cbs;
|
||||
CRYPTO_BUFFER_init_CBS(sk_CRYPTO_BUFFER_value(cert->chain.get(), 0),
|
||||
&cert_cbs);
|
||||
UniquePtr<EVP_PKEY> pubkey = ssl_cert_parse_pubkey(&cert_cbs);
|
||||
if (!pubkey) {
|
||||
OPENSSL_PUT_ERROR(X509, X509_R_UNKNOWN_KEY_TYPE);
|
||||
return false;
|
||||
}
|
||||
|
||||
return ssl_compare_public_and_private_key(pubkey.get(), privkey);
|
||||
}
|
||||
|
||||
bool ssl_cert_check_key_usage(const CBS *in, enum ssl_key_usage_t bit) {
|
||||
CBS buf = *in;
|
||||
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
#include <openssl/curve25519.h>
|
||||
#include <openssl/ec.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/kyber.h>
|
||||
#include <openssl/experimental/kyber.h>
|
||||
#include <openssl/hrss.h>
|
||||
#include <openssl/mem.h>
|
||||
#include <openssl/nid.h>
|
||||
|
||||
+23
-4
@@ -1724,17 +1724,36 @@ int SSL_has_pending(const SSL *ssl) {
|
||||
return SSL_pending(ssl) != 0 || !ssl->s3->read_buffer.empty();
|
||||
}
|
||||
|
||||
static bool has_cert_and_key(const CERT *cert) {
|
||||
// TODO(davidben): If |cert->key_method| is set, that should be fine too.
|
||||
if (cert->privatekey == nullptr) {
|
||||
OPENSSL_PUT_ERROR(SSL, SSL_R_NO_PRIVATE_KEY_ASSIGNED);
|
||||
return false;
|
||||
}
|
||||
|
||||
if (cert->chain == nullptr ||
|
||||
sk_CRYPTO_BUFFER_value(cert->chain.get(), 0) == nullptr) {
|
||||
OPENSSL_PUT_ERROR(SSL, SSL_R_NO_CERTIFICATE_ASSIGNED);
|
||||
return false;
|
||||
}
|
||||
|
||||
return true;
|
||||
}
|
||||
|
||||
int SSL_CTX_check_private_key(const SSL_CTX *ctx) {
|
||||
return ssl_cert_check_private_key(ctx->cert.get(),
|
||||
ctx->cert->privatekey.get());
|
||||
// There is no need to actually check consistency because inconsistent values
|
||||
// can never be configured.
|
||||
return has_cert_and_key(ctx->cert.get());
|
||||
}
|
||||
|
||||
int SSL_check_private_key(const SSL *ssl) {
|
||||
if (!ssl->config) {
|
||||
return 0;
|
||||
}
|
||||
return ssl_cert_check_private_key(ssl->config->cert.get(),
|
||||
ssl->config->cert->privatekey.get());
|
||||
|
||||
// There is no need to actually check consistency because inconsistent values
|
||||
// can never be configured.
|
||||
return has_cert_and_key(ssl->config->cert.get());
|
||||
}
|
||||
|
||||
long SSL_get_default_timeout(const SSL *ssl) {
|
||||
|
||||
+15
-5
@@ -83,11 +83,21 @@ static bool ssl_set_pkey(CERT *cert, EVP_PKEY *pkey) {
|
||||
return false;
|
||||
}
|
||||
|
||||
if (cert->chain != nullptr &&
|
||||
sk_CRYPTO_BUFFER_value(cert->chain.get(), 0) != nullptr &&
|
||||
// Sanity-check that the private key and the certificate match.
|
||||
!ssl_cert_check_private_key(cert, pkey)) {
|
||||
return false;
|
||||
// If the leaf certificate has been configured, check it matches.
|
||||
const CRYPTO_BUFFER *leaf = cert->chain != nullptr
|
||||
? sk_CRYPTO_BUFFER_value(cert->chain.get(), 0)
|
||||
: nullptr;
|
||||
if (leaf != nullptr) {
|
||||
CBS cert_cbs;
|
||||
CRYPTO_BUFFER_init_CBS(leaf, &cert_cbs);
|
||||
UniquePtr<EVP_PKEY> pubkey = ssl_cert_parse_pubkey(&cert_cbs);
|
||||
if (!pubkey) {
|
||||
OPENSSL_PUT_ERROR(X509, X509_R_UNKNOWN_KEY_TYPE);
|
||||
return false;
|
||||
}
|
||||
if (!ssl_compare_public_and_private_key(pubkey.get(), pkey)) {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
cert->privatekey = UpRef(pkey);
|
||||
|
||||
+88
-18
@@ -3021,9 +3021,8 @@ TEST(SSLTest, WriteAfterWrongVersionOnEarlyData) {
|
||||
// The client processes the ServerHello and fails.
|
||||
EXPECT_EQ(-1, SSL_do_handshake(client.get()));
|
||||
EXPECT_EQ(SSL_ERROR_SSL, SSL_get_error(client.get(), -1));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_SSL, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(SSL_R_WRONG_VERSION_ON_EARLY_DATA, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_get_error(), ERR_LIB_SSL,
|
||||
SSL_R_WRONG_VERSION_ON_EARLY_DATA));
|
||||
|
||||
// The client should have written an alert to the transport.
|
||||
const uint8_t *unused;
|
||||
@@ -3035,9 +3034,8 @@ TEST(SSLTest, WriteAfterWrongVersionOnEarlyData) {
|
||||
// Writing should fail, with the same error as the handshake.
|
||||
EXPECT_EQ(-1, SSL_write(client.get(), "a", 1));
|
||||
EXPECT_EQ(SSL_ERROR_SSL, SSL_get_error(client.get(), -1));
|
||||
err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_SSL, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(SSL_R_WRONG_VERSION_ON_EARLY_DATA, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_get_error(), ERR_LIB_SSL,
|
||||
SSL_R_WRONG_VERSION_ON_EARLY_DATA));
|
||||
|
||||
// Nothing should be written to the transport.
|
||||
ASSERT_TRUE(BIO_mem_contents(mem.get(), &unused, &len));
|
||||
@@ -4556,6 +4554,82 @@ TEST(SSLTest, SetChainAndKeyMismatch) {
|
||||
ERR_clear_error();
|
||||
}
|
||||
|
||||
TEST(SSLTest, CertThenKeyMismatch) {
|
||||
bssl::UniquePtr<SSL_CTX> ctx(SSL_CTX_new(TLS_method()));
|
||||
ASSERT_TRUE(ctx);
|
||||
|
||||
bssl::UniquePtr<EVP_PKEY> key = GetTestKey();
|
||||
ASSERT_TRUE(key);
|
||||
bssl::UniquePtr<X509> leaf = GetChainTestCertificate();
|
||||
ASSERT_TRUE(leaf);
|
||||
|
||||
// There is no key or certificate, so |SSL_CTX_check_private_key| fails.
|
||||
EXPECT_FALSE(SSL_CTX_check_private_key(ctx.get()));
|
||||
|
||||
// With only a certificate, |SSL_CTX_check_private_key| still fails.
|
||||
ASSERT_TRUE(SSL_CTX_use_certificate(ctx.get(), leaf.get()));
|
||||
EXPECT_FALSE(SSL_CTX_check_private_key(ctx.get()));
|
||||
|
||||
// The private key does not match the certificate, so it should fail.
|
||||
EXPECT_FALSE(SSL_CTX_use_PrivateKey(ctx.get(), key.get()));
|
||||
|
||||
// Checking the private key fails, but this is really because there is still
|
||||
// no private key.
|
||||
EXPECT_FALSE(SSL_CTX_check_private_key(ctx.get()));
|
||||
EXPECT_EQ(nullptr, SSL_CTX_get0_privatekey(ctx.get()));
|
||||
}
|
||||
|
||||
TEST(SSLTest, KeyThenCertMismatch) {
|
||||
bssl::UniquePtr<SSL_CTX> ctx(SSL_CTX_new(TLS_method()));
|
||||
ASSERT_TRUE(ctx);
|
||||
|
||||
bssl::UniquePtr<EVP_PKEY> key = GetTestKey();
|
||||
ASSERT_TRUE(key);
|
||||
bssl::UniquePtr<X509> leaf = GetChainTestCertificate();
|
||||
ASSERT_TRUE(leaf);
|
||||
|
||||
// There is no key or certificate, so |SSL_CTX_check_private_key| fails.
|
||||
EXPECT_FALSE(SSL_CTX_check_private_key(ctx.get()));
|
||||
|
||||
// With only a key, |SSL_CTX_check_private_key| still fails.
|
||||
ASSERT_TRUE(SSL_CTX_use_PrivateKey(ctx.get(), key.get()));
|
||||
EXPECT_FALSE(SSL_CTX_check_private_key(ctx.get()));
|
||||
|
||||
// If configuring a certificate that doesn't match the key, configuration
|
||||
// actually succeeds. We just silently drop the private key.
|
||||
ASSERT_TRUE(SSL_CTX_use_certificate(ctx.get(), leaf.get()));
|
||||
EXPECT_EQ(nullptr, SSL_CTX_get0_privatekey(ctx.get()));
|
||||
|
||||
// Some callers configure the private key, then the certificate, and then
|
||||
// expect |SSL_CTX_check_private_key| to check consistency. It does, but only
|
||||
// by way of noticing there is no private key. The actual consistency check
|
||||
// happened in |SSL_CTX_use_certificate|.
|
||||
EXPECT_FALSE(SSL_CTX_check_private_key(ctx.get()));
|
||||
}
|
||||
|
||||
TEST(SSLTest, OverrideCertAndKey) {
|
||||
// It is possible to override an existing certificate by configuring
|
||||
// certificate, then key, due to |SSL_CTX_use_certificate|'s above silent
|
||||
// dropping behavior.
|
||||
bssl::UniquePtr<SSL_CTX> ctx(SSL_CTX_new(TLS_method()));
|
||||
ASSERT_TRUE(ctx);
|
||||
|
||||
bssl::UniquePtr<EVP_PKEY> key = GetTestKey();
|
||||
ASSERT_TRUE(key);
|
||||
bssl::UniquePtr<X509> leaf = GetTestCertificate();
|
||||
ASSERT_TRUE(leaf);
|
||||
bssl::UniquePtr<EVP_PKEY> key2 = GetChainTestKey();
|
||||
ASSERT_TRUE(key2);
|
||||
bssl::UniquePtr<X509> leaf2 = GetChainTestCertificate();
|
||||
ASSERT_TRUE(leaf2);
|
||||
|
||||
ASSERT_TRUE(SSL_CTX_use_certificate(ctx.get(), leaf.get()));
|
||||
ASSERT_TRUE(SSL_CTX_use_PrivateKey(ctx.get(), key.get()));
|
||||
|
||||
ASSERT_TRUE(SSL_CTX_use_certificate(ctx.get(), leaf2.get()));
|
||||
ASSERT_TRUE(SSL_CTX_use_PrivateKey(ctx.get(), key2.get()));
|
||||
}
|
||||
|
||||
TEST(SSLTest, SetChainAndKeyCtx) {
|
||||
bssl::UniquePtr<SSL_CTX> client_ctx(SSL_CTX_new(TLS_with_buffers_method()));
|
||||
ASSERT_TRUE(client_ctx);
|
||||
@@ -5114,9 +5188,8 @@ TEST(SSLTest, NoCiphersAvailable) {
|
||||
int ret = SSL_do_handshake(ssl.get());
|
||||
EXPECT_EQ(-1, ret);
|
||||
EXPECT_EQ(SSL_ERROR_SSL, SSL_get_error(ssl.get(), ret));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_SSL, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(SSL_R_NO_CIPHERS_AVAILABLE, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_SSL, SSL_R_NO_CIPHERS_AVAILABLE));
|
||||
}
|
||||
|
||||
TEST_P(SSLVersionTest, SessionVersion) {
|
||||
@@ -7101,9 +7174,8 @@ TEST_F(QUICMethodTest, ExcessProvidedData) {
|
||||
// EncryptedExtensions on key change.
|
||||
ASSERT_EQ(SSL_do_handshake(client_.get()), -1);
|
||||
ASSERT_EQ(SSL_get_error(client_.get(), -1), SSL_ERROR_SSL);
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_GET_LIB(err), ERR_LIB_SSL);
|
||||
EXPECT_EQ(ERR_GET_REASON(err), SSL_R_EXCESS_HANDSHAKE_DATA);
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_SSL, SSL_R_EXCESS_HANDSHAKE_DATA));
|
||||
|
||||
// The client sends an alert in response to this. The alert is sent at
|
||||
// handshake level because we install write secrets before read secrets and
|
||||
@@ -7552,9 +7624,8 @@ TEST_P(SSLVersionTest, DoubleSSLError) {
|
||||
// The client handshake should terminate on a certificate verification
|
||||
// error.
|
||||
EXPECT_EQ(SSL_ERROR_SSL, client_err);
|
||||
uint32_t err = ERR_peek_error();
|
||||
EXPECT_EQ(ERR_LIB_SSL, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(SSL_R_CERTIFICATE_VERIFY_FAILED, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(ErrorEquals(ERR_peek_error(), ERR_LIB_SSL,
|
||||
SSL_R_CERTIFICATE_VERIFY_FAILED));
|
||||
break;
|
||||
}
|
||||
|
||||
@@ -7830,9 +7901,8 @@ TEST(SSLTest, WriteWhileExplicitRenegotiate) {
|
||||
// We never renegotiate as a server.
|
||||
ASSERT_EQ(-1, SSL_read(server.get(), buf, sizeof(buf)));
|
||||
ASSERT_EQ(SSL_ERROR_SSL, SSL_get_error(server.get(), -1));
|
||||
uint32_t err = ERR_get_error();
|
||||
EXPECT_EQ(ERR_LIB_SSL, ERR_GET_LIB(err));
|
||||
EXPECT_EQ(SSL_R_NO_RENEGOTIATION, ERR_GET_REASON(err));
|
||||
EXPECT_TRUE(
|
||||
ErrorEquals(ERR_get_error(), ERR_LIB_SSL, SSL_R_NO_RENEGOTIATION));
|
||||
}
|
||||
|
||||
TEST(SSLTest, ConnectionPropertiesDuringRenegotiate) {
|
||||
|
||||
+1
-1
@@ -38,8 +38,8 @@
|
||||
#include <openssl/ecdsa.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/evp.h>
|
||||
#include <openssl/experimental/kyber.h>
|
||||
#include <openssl/hrss.h>
|
||||
#include <openssl/kyber.h>
|
||||
#include <openssl/mem.h>
|
||||
#include <openssl/nid.h>
|
||||
#include <openssl/rand.h>
|
||||
|
||||
+5
-1
@@ -36,7 +36,6 @@
|
||||
"include/openssl/engine.h",
|
||||
"include/openssl/hkdf.h",
|
||||
"include/openssl/hmac.h",
|
||||
"include/openssl/kyber.h",
|
||||
"include/openssl/md5.h",
|
||||
"include/openssl/rc4.h",
|
||||
"include/openssl/rsa.h",
|
||||
@@ -60,6 +59,11 @@
|
||||
"include/openssl/conf.h",
|
||||
"include/openssl/x509.h"
|
||||
]
|
||||
},{
|
||||
"Name": "Experimental primitives. Will be removed and replaced when standardized!",
|
||||
"Headers": [
|
||||
"include/openssl/experimental/kyber.h"
|
||||
]
|
||||
},{
|
||||
"Name": "SSL implementation",
|
||||
"Headers": [
|
||||
|
||||
Reference in New Issue
Block a user