|
|
20746d |
From c33a8fe36d340447641d4dc623c98d2bf9a2d650 Mon Sep 17 00:00:00 2001
|
|
|
20746d |
From: Fraser Tweedale <ftweedal@redhat.com>
|
|
|
20746d |
Date: Thu, 24 Aug 2017 13:37:36 +1000
|
|
|
20746d |
Subject: [PATCH] MS cert template: add tests
|
|
|
20746d |
|
|
|
20746d |
Part of: https://pagure.io/certmonger/issue/78
|
|
|
20746d |
---
|
|
|
20746d |
tests/038-ms-v2-template/expected.out | 19 ++++++++++
|
|
|
20746d |
tests/038-ms-v2-template/extract-extdata.py | 29 ++++++++++++++++
|
|
|
20746d |
tests/038-ms-v2-template/run.sh | 54 +++++++++++++++++++++++++++++
|
|
|
20746d |
tests/Makefile.am | 8 +++--
|
|
|
20746d |
4 files changed, 108 insertions(+), 2 deletions(-)
|
|
|
20746d |
create mode 100644 tests/038-ms-v2-template/expected.out
|
|
|
20746d |
create mode 100755 tests/038-ms-v2-template/extract-extdata.py
|
|
|
20746d |
create mode 100755 tests/038-ms-v2-template/run.sh
|
|
|
20746d |
|
|
|
20746d |
diff --git a/tests/038-ms-v2-template/expected.out b/tests/038-ms-v2-template/expected.out
|
|
|
20746d |
new file mode 100644
|
|
|
20746d |
index 0000000..7338a5f
|
|
|
20746d |
--- /dev/null
|
|
|
20746d |
+++ b/tests/038-ms-v2-template/expected.out
|
|
|
20746d |
@@ -0,0 +1,19 @@
|
|
|
20746d |
+[key]
|
|
|
20746d |
+OK.
|
|
|
20746d |
+[csr : bogus oid]
|
|
|
20746d |
+extension not present
|
|
|
20746d |
+[csr : bogus major version]
|
|
|
20746d |
+extension not present
|
|
|
20746d |
+[csr : missing major version]
|
|
|
20746d |
+extension not present
|
|
|
20746d |
+[csr : too many parts]
|
|
|
20746d |
+extension not present
|
|
|
20746d |
+[csr : oid, major version]
|
|
|
20746d |
+ 0:d=0 hl=2 l= 8 cons: SEQUENCE
|
|
|
20746d |
+ 2:d=1 hl=2 l= 3 prim: OBJECT :1.2.3.4
|
|
|
20746d |
+ 7:d=1 hl=2 l= 1 prim: INTEGER :2A
|
|
|
20746d |
+[csr : oid, major version, minor version]
|
|
|
20746d |
+ 0:d=0 hl=2 l= 11 cons: SEQUENCE
|
|
|
20746d |
+ 2:d=1 hl=2 l= 3 prim: OBJECT :1.2.3.4
|
|
|
20746d |
+ 7:d=1 hl=2 l= 1 prim: INTEGER :2A
|
|
|
20746d |
+ 10:d=1 hl=2 l= 1 prim: INTEGER :11
|
|
|
20746d |
diff --git a/tests/038-ms-v2-template/extract-extdata.py b/tests/038-ms-v2-template/extract-extdata.py
|
|
|
20746d |
new file mode 100755
|
|
|
20746d |
index 0000000..cd96f99
|
|
|
20746d |
--- /dev/null
|
|
|
20746d |
+++ b/tests/038-ms-v2-template/extract-extdata.py
|
|
|
20746d |
@@ -0,0 +1,29 @@
|
|
|
20746d |
+#!/bin/python2
|
|
|
20746d |
+
|
|
|
20746d |
+# Given `openssl asn1parse` output of a CSR, look for the V2 Template
|
|
|
20746d |
+# extension and output its data if found. Nonzero exit status if
|
|
|
20746d |
+# not found.
|
|
|
20746d |
+
|
|
|
20746d |
+import binascii
|
|
|
20746d |
+import re
|
|
|
20746d |
+import sys
|
|
|
20746d |
+
|
|
|
20746d |
+STATE_SEARCH, STATE_FOUND, STATE_DONE = range(3)
|
|
|
20746d |
+
|
|
|
20746d |
+state = STATE_SEARCH
|
|
|
20746d |
+
|
|
|
20746d |
+for line in sys.stdin:
|
|
|
20746d |
+ if state == STATE_SEARCH and ':1.3.6.1.4.1.311.21.7' in line:
|
|
|
20746d |
+ state = STATE_FOUND
|
|
|
20746d |
+ continue
|
|
|
20746d |
+
|
|
|
20746d |
+ # look for first OCTET STRING once we're in STATE_FOUND
|
|
|
20746d |
+ #
|
|
|
20746d |
+ if state == STATE_FOUND and 'OCTET STRING' in line:
|
|
|
20746d |
+ result = re.search(r'\[HEX DUMP\]:(\w*)', line)
|
|
|
20746d |
+ sys.stdout.write(binascii.unhexlify(result.group(1)))
|
|
|
20746d |
+ state = STATE_DONE
|
|
|
20746d |
+ break
|
|
|
20746d |
+
|
|
|
20746d |
+if state != STATE_DONE:
|
|
|
20746d |
+ sys.exit(1)
|
|
|
20746d |
diff --git a/tests/038-ms-v2-template/run.sh b/tests/038-ms-v2-template/run.sh
|
|
|
20746d |
new file mode 100755
|
|
|
20746d |
index 0000000..0eeb7f9
|
|
|
20746d |
--- /dev/null
|
|
|
20746d |
+++ b/tests/038-ms-v2-template/run.sh
|
|
|
20746d |
@@ -0,0 +1,54 @@
|
|
|
20746d |
+#!/bin/bash -e
|
|
|
20746d |
+
|
|
|
20746d |
+srcdir=$PWD
|
|
|
20746d |
+cd $tmpdir
|
|
|
20746d |
+
|
|
|
20746d |
+mkconfig() {
|
|
|
20746d |
+ cat > request <<- EOF
|
|
|
20746d |
+ key_storage_type=FILE
|
|
|
20746d |
+ key_storage_location=$tmpdir/key
|
|
|
20746d |
+ cert_storage_type=FILE
|
|
|
20746d |
+ cert_storage_location=$tmpdir/cert
|
|
|
20746d |
+ template_subject=CN=MS V2 Certificate Template test
|
|
|
20746d |
+ EOF
|
|
|
20746d |
+}
|
|
|
20746d |
+
|
|
|
20746d |
+echo "[key]"
|
|
|
20746d |
+mkconfig
|
|
|
20746d |
+$toolsdir/keygen request
|
|
|
20746d |
+
|
|
|
20746d |
+echo "[csr : bogus oid]"
|
|
|
20746d |
+mkconfig
|
|
|
20746d |
+echo "template_certificate_template=NotAnOid:42" >> request
|
|
|
20746d |
+$toolsdir/csrgen request | openssl asn1parse \
|
|
|
20746d |
+ | $srcdir/extract-extdata.py || echo "extension not present"
|
|
|
20746d |
+
|
|
|
20746d |
+echo "[csr : bogus major version]"
|
|
|
20746d |
+mkconfig
|
|
|
20746d |
+echo "template_certificate_template=1.2.3.4:wat" >> request
|
|
|
20746d |
+$toolsdir/csrgen request | openssl asn1parse \
|
|
|
20746d |
+ | $srcdir/extract-extdata.py || echo "extension not present"
|
|
|
20746d |
+
|
|
|
20746d |
+echo "[csr : missing major version]"
|
|
|
20746d |
+mkconfig
|
|
|
20746d |
+echo "template_certificate_template=1.2.3.4" >> request
|
|
|
20746d |
+$toolsdir/csrgen request | openssl asn1parse \
|
|
|
20746d |
+ | $srcdir/extract-extdata.py || echo "extension not present"
|
|
|
20746d |
+
|
|
|
20746d |
+echo "[csr : too many parts]"
|
|
|
20746d |
+mkconfig
|
|
|
20746d |
+echo "template_certificate_template=1.2.3.4:1:1:1" >> request
|
|
|
20746d |
+$toolsdir/csrgen request | openssl asn1parse \
|
|
|
20746d |
+ | $srcdir/extract-extdata.py || echo "extension not present"
|
|
|
20746d |
+
|
|
|
20746d |
+echo "[csr : oid, major version]"
|
|
|
20746d |
+mkconfig
|
|
|
20746d |
+echo "template_certificate_template=1.2.3.4:42" >> request
|
|
|
20746d |
+$toolsdir/csrgen request | openssl asn1parse \
|
|
|
20746d |
+ | $srcdir/extract-extdata.py | openssl asn1parse -inform DER
|
|
|
20746d |
+
|
|
|
20746d |
+echo "[csr : oid, major version, minor version]"
|
|
|
20746d |
+mkconfig
|
|
|
20746d |
+echo "template_certificate_template=1.2.3.4:42:17" >> request
|
|
|
20746d |
+$toolsdir/csrgen request | openssl asn1parse \
|
|
|
20746d |
+ | $srcdir/extract-extdata.py | openssl asn1parse -inform DER
|
|
|
20746d |
diff --git a/tests/Makefile.am b/tests/Makefile.am
|
|
|
20746d |
index bbcd06e..562b027 100644
|
|
|
20746d |
--- a/tests/Makefile.am
|
|
|
20746d |
+++ b/tests/Makefile.am
|
|
|
20746d |
@@ -148,7 +148,10 @@ EXTRA_DIST = \
|
|
|
20746d |
036-getcert/expected.out \
|
|
|
20746d |
036-getcert/run.sh \
|
|
|
20746d |
037-rekey2/expected.out \
|
|
|
20746d |
- 037-rekey2/run.sh
|
|
|
20746d |
+ 037-rekey2/run.sh \
|
|
|
20746d |
+ 038-ms-v2-template/expected.out \
|
|
|
20746d |
+ 038-ms-v2-template/extract-extdata.py \
|
|
|
20746d |
+ 038-ms-v2-template/run.sh
|
|
|
20746d |
|
|
|
20746d |
subdirs = \
|
|
|
20746d |
001-keyiread \
|
|
|
20746d |
@@ -189,7 +192,8 @@ subdirs = \
|
|
|
20746d |
034-perms \
|
|
|
20746d |
035-json \
|
|
|
20746d |
036-getcert \
|
|
|
20746d |
- 037-rekey2
|
|
|
20746d |
+ 037-rekey2 \
|
|
|
20746d |
+ 038-ms-v2-template
|
|
|
20746d |
|
|
|
20746d |
if HAVE_DBM_NSSDB
|
|
|
20746d |
subdirs += \
|
|
|
20746d |
--
|
|
|
20746d |
2.14.4
|
|
|
20746d |
|