CmsSignerTest.cs 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294
  1. //
  2. // CmsSignerTest.cs - NUnit tests for CmsSigner
  3. //
  4. // Author:
  5. // Sebastien Pouliot <[email protected]>
  6. //
  7. // (C) 2003 Motus Technologies Inc. (http://www.motus.com)
  8. // Copyright (C) 2004 Novell, Inc (http://www.novell.com)
  9. //
  10. // Permission is hereby granted, free of charge, to any person obtaining
  11. // a copy of this software and associated documentation files (the
  12. // "Software"), to deal in the Software without restriction, including
  13. // without limitation the rights to use, copy, modify, merge, publish,
  14. // distribute, sublicense, and/or sell copies of the Software, and to
  15. // permit persons to whom the Software is furnished to do so, subject to
  16. // the following conditions:
  17. //
  18. // The above copyright notice and this permission notice shall be
  19. // included in all copies or substantial portions of the Software.
  20. //
  21. // THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
  22. // EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
  23. // MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
  24. // NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE
  25. // LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
  26. // OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
  27. // WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
  28. //
  29. using NUnit.Framework;
  30. using System;
  31. using System.Collections;
  32. using System.Security.Cryptography;
  33. using System.Security.Cryptography.Pkcs;
  34. using System.Security.Cryptography.X509Certificates;
  35. namespace MonoTests.System.Security.Cryptography.Pkcs {
  36. [TestFixture]
  37. public class CmsSignerTest {
  38. static byte[] asnNull = { 0x05, 0x00 };
  39. static string sha1Oid = "1.3.14.3.2.26";
  40. static string sha1Name = "sha1";
  41. static string rsaOid = "1.2.840.113549.1.1.1";
  42. static string rsaName = "RSA";
  43. [Test]
  44. public void ConstructorEmpty ()
  45. {
  46. CmsSigner ps = new CmsSigner ();
  47. // default properties
  48. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  49. Assert.IsNull (ps.Certificate, "Certificate");
  50. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  51. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  52. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  53. Assert.AreEqual (SubjectIdentifierType.IssuerAndSerialNumber, ps.SignerIdentifierType, "SignerIdentifierType");
  54. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  55. }
  56. [Test]
  57. public void ConstructorIssuerAndSerialNumber ()
  58. {
  59. CmsSigner ps = new CmsSigner (SubjectIdentifierType.IssuerAndSerialNumber);
  60. // default properties
  61. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  62. Assert.IsNull (ps.Certificate, "Certificate");
  63. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  64. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  65. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  66. Assert.AreEqual (SubjectIdentifierType.IssuerAndSerialNumber, ps.SignerIdentifierType, "SignerIdentifierType");
  67. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  68. }
  69. [Test]
  70. public void ConstructorSubjectKeyIdentifier ()
  71. {
  72. CmsSigner ps = new CmsSigner (SubjectIdentifierType.SubjectKeyIdentifier);
  73. // default properties
  74. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  75. Assert.IsNull (ps.Certificate, "Certificate");
  76. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  77. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  78. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  79. Assert.AreEqual (SubjectIdentifierType.SubjectKeyIdentifier, ps.SignerIdentifierType, "SignerIdentifierType");
  80. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  81. }
  82. [Test]
  83. public void ConstructorUnknown ()
  84. {
  85. CmsSigner ps = new CmsSigner (SubjectIdentifierType.Unknown);
  86. // default properties
  87. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  88. Assert.IsNull (ps.Certificate, "Certificate");
  89. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  90. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  91. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  92. // Unknown is converted to IssuerAndSerialNumber
  93. Assert.AreEqual (SubjectIdentifierType.IssuerAndSerialNumber, ps.SignerIdentifierType, "SignerIdentifierType");
  94. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  95. }
  96. // TODO: return valid x509 certifiate with private key
  97. private X509Certificate2 GetValidCertificateWithPrivateKey ()
  98. {
  99. X509Certificate2 x509 = new X509Certificate2 ();
  100. return x509;
  101. }
  102. [Test]
  103. public void ConstructorX509CertificateEx ()
  104. {
  105. X509Certificate2 x509 = GetValidCertificateWithPrivateKey ();
  106. CmsSigner ps = new CmsSigner (x509);
  107. // default properties
  108. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  109. Assert.IsNotNull (ps.Certificate, "Certificate");
  110. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  111. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  112. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  113. Assert.AreEqual (SubjectIdentifierType.IssuerAndSerialNumber, ps.SignerIdentifierType, "SignerIdentifierType");
  114. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  115. }
  116. [Test]
  117. public void ConstructorX509CertificateExEmpty ()
  118. {
  119. X509Certificate2 x509 = new X509Certificate2 (); // empty
  120. CmsSigner ps = new CmsSigner (x509);
  121. // default properties
  122. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  123. Assert.IsNotNull (ps.Certificate, "Certificate");
  124. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  125. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  126. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  127. Assert.AreEqual (SubjectIdentifierType.IssuerAndSerialNumber, ps.SignerIdentifierType, "SignerIdentifierType");
  128. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  129. }
  130. [Test]
  131. //BUG [ExpectedException (typeof (ArgumentNullException))]
  132. public void ConstructorX509CertificateExNull ()
  133. {
  134. X509Certificate2 x509 = null;
  135. CmsSigner ps = new CmsSigner (x509);
  136. // default properties
  137. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  138. Assert.IsNull (ps.Certificate, "Certificate");
  139. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  140. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  141. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  142. Assert.AreEqual (SubjectIdentifierType.IssuerAndSerialNumber, ps.SignerIdentifierType, "SignerIdentifierType");
  143. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  144. }
  145. [Test]
  146. public void ConstructorIssuerAndSerialNumberX509CertificateEx ()
  147. {
  148. X509Certificate2 x509 = GetValidCertificateWithPrivateKey ();
  149. CmsSigner ps = new CmsSigner (SubjectIdentifierType.IssuerAndSerialNumber, x509);
  150. // default properties
  151. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  152. Assert.IsNotNull (ps.Certificate, "Certificate");
  153. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  154. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  155. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  156. Assert.AreEqual (SubjectIdentifierType.IssuerAndSerialNumber, ps.SignerIdentifierType, "SignerIdentifierType");
  157. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  158. }
  159. [Test]
  160. public void ConstructorSubjectKeyIdentifierX509CertificateEx ()
  161. {
  162. X509Certificate2 x509 = GetValidCertificateWithPrivateKey ();
  163. CmsSigner ps = new CmsSigner (SubjectIdentifierType.SubjectKeyIdentifier, x509);
  164. // default properties
  165. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  166. Assert.IsNotNull (ps.Certificate, "Certificate");
  167. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  168. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  169. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  170. Assert.AreEqual (SubjectIdentifierType.SubjectKeyIdentifier, ps.SignerIdentifierType, "SignerIdentifierType");
  171. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  172. }
  173. [Test]
  174. public void ConstructorUnknownX509CertificateEx ()
  175. {
  176. X509Certificate2 x509 = GetValidCertificateWithPrivateKey ();
  177. CmsSigner ps = new CmsSigner (SubjectIdentifierType.Unknown, x509);
  178. // default properties
  179. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  180. Assert.IsNotNull (ps.Certificate, "Certificate");
  181. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  182. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  183. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  184. // Unknown is converted to IssuerAndSerialNumber
  185. Assert.AreEqual (SubjectIdentifierType.IssuerAndSerialNumber, ps.SignerIdentifierType, "SignerIdentifierType");
  186. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  187. }
  188. [Test]
  189. //BUG [ExpectedException (typeof (ArgumentNullException))]
  190. public void ConstructorIssuerAndSerialNumberX509CertificateExNull ()
  191. {
  192. CmsSigner ps = new CmsSigner (SubjectIdentifierType.IssuerAndSerialNumber, null);
  193. // default properties
  194. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes");
  195. Assert.IsNull (ps.Certificate, "Certificate");
  196. Assert.AreEqual (sha1Name, ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  197. Assert.AreEqual (sha1Oid, ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  198. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "IncludeOption");
  199. Assert.AreEqual (SubjectIdentifierType.IssuerAndSerialNumber, ps.SignerIdentifierType, "SignerIdentifierType");
  200. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes");
  201. }
  202. [Test]
  203. public void SignedAttributes ()
  204. {
  205. CmsSigner ps = new CmsSigner ();
  206. Assert.AreEqual (0, ps.SignedAttributes.Count, "SignedAttributes=0");
  207. ps.SignedAttributes.Add (new Pkcs9DocumentDescription ("mono"));
  208. Assert.AreEqual (1, ps.SignedAttributes.Count, "SignedAttributes=1");
  209. }
  210. [Test]
  211. public void Certificate ()
  212. {
  213. CmsSigner ps = new CmsSigner ();
  214. Assert.IsNull (ps.Certificate, "Certificate=default(null)");
  215. ps.Certificate = GetValidCertificateWithPrivateKey ();
  216. Assert.IsNotNull (ps.Certificate, "Certificate!=null");
  217. ps.Certificate = null;
  218. Assert.IsNull (ps.Certificate, "Certificate=null");
  219. }
  220. [Test]
  221. public void Digest ()
  222. {
  223. CmsSigner ps = new CmsSigner ();
  224. ps.DigestAlgorithm = new Oid ("1.2.840.113549.2.5");
  225. Assert.AreEqual ("md5", ps.DigestAlgorithm.FriendlyName, "DigestAlgorithm.FriendlyName");
  226. Assert.AreEqual ("1.2.840.113549.2.5", ps.DigestAlgorithm.Value, "DigestAlgorithm.Value");
  227. ps.DigestAlgorithm = null;
  228. Assert.IsNull (ps.DigestAlgorithm, "DigestAlgorithm=null");
  229. }
  230. [Test]
  231. public void IncludeOption ()
  232. {
  233. CmsSigner ps = new CmsSigner ();
  234. ps.IncludeOption = X509IncludeOption.EndCertOnly;
  235. Assert.AreEqual (X509IncludeOption.EndCertOnly, ps.IncludeOption, "EndCertOnly");
  236. ps.IncludeOption = X509IncludeOption.ExcludeRoot;
  237. Assert.AreEqual (X509IncludeOption.ExcludeRoot, ps.IncludeOption, "ExcludeRoot");
  238. ps.IncludeOption = X509IncludeOption.None;
  239. Assert.AreEqual (X509IncludeOption.None, ps.IncludeOption, "None");
  240. ps.IncludeOption = X509IncludeOption.WholeChain;
  241. Assert.AreEqual (X509IncludeOption.WholeChain, ps.IncludeOption, "WholeChain");
  242. }
  243. [Test]
  244. public void SubjectIdentifierTypeProperty ()
  245. {
  246. CmsSigner ps = new CmsSigner ();
  247. ps.SignerIdentifierType = SubjectIdentifierType.IssuerAndSerialNumber;
  248. Assert.AreEqual (SubjectIdentifierType.IssuerAndSerialNumber, ps.SignerIdentifierType, "IssuerAndSerialNumber");
  249. ps.SignerIdentifierType = SubjectIdentifierType.SubjectKeyIdentifier;
  250. Assert.AreEqual (SubjectIdentifierType.SubjectKeyIdentifier, ps.SignerIdentifierType, "SubjectKeyIdentifier");
  251. }
  252. [Test]
  253. [ExpectedException (typeof (ArgumentException))]
  254. public void SubjectIdentifierTypeUnknown ()
  255. {
  256. CmsSigner ps = new CmsSigner ();
  257. ps.SignerIdentifierType = SubjectIdentifierType.Unknown;
  258. }
  259. [Test]
  260. public void UnauthenticatedAttributes ()
  261. {
  262. CmsSigner ps = new CmsSigner ();
  263. Assert.AreEqual (0, ps.UnsignedAttributes.Count, "UnsignedAttributes=0");
  264. ps.UnsignedAttributes.Add (new Pkcs9DocumentDescription ("mono"));
  265. Assert.AreEqual (1, ps.UnsignedAttributes.Count, "UnsignedAttributes=1");
  266. }
  267. }
  268. }