1*844a3294Stb /* $OpenBSD: cmstest.c,v 1.8 2024/03/29 06:42:42 tb Exp $ */
220706fe4Sjsing /*
320706fe4Sjsing * Copyright (c) 2019 Joel Sing <jsing@openbsd.org>
420706fe4Sjsing *
520706fe4Sjsing * Permission to use, copy, modify, and distribute this software for any
620706fe4Sjsing * purpose with or without fee is hereby granted, provided that the above
720706fe4Sjsing * copyright notice and this permission notice appear in all copies.
820706fe4Sjsing *
920706fe4Sjsing * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
1020706fe4Sjsing * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
1120706fe4Sjsing * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
1220706fe4Sjsing * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
1320706fe4Sjsing * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
1420706fe4Sjsing * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
1520706fe4Sjsing * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
1620706fe4Sjsing */
1720706fe4Sjsing
1820706fe4Sjsing #include <err.h>
1920706fe4Sjsing #include <string.h>
2020706fe4Sjsing
2120706fe4Sjsing #include <openssl/bio.h>
2220706fe4Sjsing #include <openssl/err.h>
2320706fe4Sjsing #include <openssl/pem.h>
2420706fe4Sjsing #include <openssl/x509.h>
2520706fe4Sjsing
2620706fe4Sjsing #include <openssl/cms.h>
2720706fe4Sjsing
2820706fe4Sjsing static int verbose = 0;
2920706fe4Sjsing
3020706fe4Sjsing static const char cms_msg[] = "Hello CMS!\r\n";
3120706fe4Sjsing
327eb1d99aStb static const char cms_ca_1[] =
33cba7e0c8Sjsing "-----BEGIN CERTIFICATE-----\n"
34cba7e0c8Sjsing "MIICqDCCAZACCQD8ebR8e4kdvjANBgkqhkiG9w0BAQsFADAWMRQwEgYDVQQDDAtU\n"
35cba7e0c8Sjsing "ZXN0IENNUyBDQTAeFw0xOTA1MTExNTUzNTNaFw0yOTA1MDgxNTUzNTNaMBYxFDAS\n"
36cba7e0c8Sjsing "BgNVBAMMC1Rlc3QgQ01TIENBMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC\n"
37cba7e0c8Sjsing "AQEAoIiW3POGYfhY0BEgG8mIwouOI917M72jsuUE57ccjEXLWseItLb7r9vkiwW/\n"
38cba7e0c8Sjsing "FYbz0UYkJW1JgpZmWaTGOgZGxj+WTzxh1aq7OHyJb6Pxwp9wGrGJu+BEqOZN/bi/\n"
39cba7e0c8Sjsing "aQ1l8x7DxVJkFeI1+4QKDfmGYfWoVzQLgamO3u0vxz3Vi/XzX01ZomcZUYYx0lIq\n"
40cba7e0c8Sjsing "hxAO665HoPUmecqYdLPquJNxdfiy37ieLJOmIsKZJtMcCZAxqhcCwE7I0196Ng3P\n"
41cba7e0c8Sjsing "fK9Sl7BCyTBszb2YC2qOleuI2Wjg/7o1+hugopUkjxz0RGFu5s3K9PhCLwpqylXg\n"
42cba7e0c8Sjsing "IXe9Vwi38gKawD3yjtDBRDNmIwIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQAvsvtc\n"
43cba7e0c8Sjsing "cO0Eo0F6MvB0bjBIMHBkKyWcmD2c5gVFhbHyRD+XBVXNdn5CcBba2amm0VgShBpM\n"
44cba7e0c8Sjsing "4e1rOtIH/Hf6nB3c/EjZvd16ryoTCTvzayac7sD2Y8IxF1JIAKvjFbu+LmzM/F5f\n"
45cba7e0c8Sjsing "x3/WdY1qs5W7lO46i8xmSUAP88gohWP4cyVUAITNrh/RSOFaWUd5i1/vZ+iEexLI\n"
46cba7e0c8Sjsing "rQWsweJleOxvA8SrXm2gAkqRWEncsxOrsX/MsPl7iJoebLhWbS3cOHhutWrfhdlC\n"
47cba7e0c8Sjsing "2uT6K7SA9rn6qqmvI6mLkHJQpqq++Py2UTDo1u8VKa3ieYNUN070kgxpYiVBGs3L\n"
48cba7e0c8Sjsing "aaACIcEs48gnTRWc\n"
49cba7e0c8Sjsing "-----END CERTIFICATE-----\n";
50cba7e0c8Sjsing
517eb1d99aStb static const char cms_cert_1[] =
5220706fe4Sjsing "-----BEGIN CERTIFICATE-----\n"
5320706fe4Sjsing "MIICpDCCAYwCAQMwDQYJKoZIhvcNAQEFBQAwFjEUMBIGA1UEAwwLVGVzdCBDTVMg\n"
5420706fe4Sjsing "Q0EwHhcNMTkwNTExMTU1MzU0WhcNMjkwNTA4MTU1MzU0WjAaMRgwFgYDVQQDDA9U\n"
5520706fe4Sjsing "ZXN0IENNUyBDZXJ0IDEwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDD\n"
5620706fe4Sjsing "MLSuy+tc0AwfrlszgHJ3z7UEpJSn5mcKxquFnEC5DtchgQJ+cj5VFvB9A9G98ykQ\n"
5720706fe4Sjsing "0IrHXNUTbS2yvf8ac1PlocuA8ggeDK4gPHCe097j0nUphhT0VzhwwFfP6Uo6VaR8\n"
5820706fe4Sjsing "B7Qb3zFTz64bN66V89etZ5NQJKMdrh4oOh5nfxLKvCcTK+9U4ZrgeGVdVXmL6HJp\n"
5920706fe4Sjsing "3m9CPobCBsC8DgI+zF/tg4GjDoVCJd6Tv5MRAmKiBrzTGglVeknkgiyIZ9C7gXU/\n"
6020706fe4Sjsing "7NMUihmLlt+80zr+nL0P+MA924WV4fZJi1wtf6Eioalq6n/9i93nBRCeu8bEOBrT\n"
6120706fe4Sjsing "pAre2oBEoULIJu7Ubx79AgMBAAEwDQYJKoZIhvcNAQEFBQADggEBADnLc6ZzApHq\n"
6220706fe4Sjsing "Z8l4zrFKAG/O/oULPMRTA8/zXNQ60BMV10hVtTCxVNq59d48wEljuUOGLfM91rhj\n"
6320706fe4Sjsing "gId8AOlsQbfRZE94DxlcaaAXaEjbkVSke56yfdLd4NqkIWrXGrFlbepj4b4ORAHh\n"
6420706fe4Sjsing "85kPwDEDnpMgQ63LqNX3gru3xf2AGIa1Fck2ISkVafqW5TH0Y6dCeGGFTtnH/QUT\n"
6520706fe4Sjsing "ofTm8uQ2vG9ERn+C1ooqJ2dyAckXFdmCcpor26vO/ZssMEKSee38ZNWR/01LEkOG\n"
6620706fe4Sjsing "G0+AL7E1mJdlVOtp3DDFN0hoNY7PbVuuzT+mrAwGLhCp2jnf68iNdrIuDdIE6yvi\n"
6720706fe4Sjsing "6WWvmmz+rC0=\n"
6820706fe4Sjsing "-----END CERTIFICATE-----\n";
6920706fe4Sjsing
707eb1d99aStb static const char cms_key_1[] =
7120706fe4Sjsing "-----BEGIN PRIVATE KEY-----\n"
7220706fe4Sjsing "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQDDMLSuy+tc0Awf\n"
7320706fe4Sjsing "rlszgHJ3z7UEpJSn5mcKxquFnEC5DtchgQJ+cj5VFvB9A9G98ykQ0IrHXNUTbS2y\n"
7420706fe4Sjsing "vf8ac1PlocuA8ggeDK4gPHCe097j0nUphhT0VzhwwFfP6Uo6VaR8B7Qb3zFTz64b\n"
7520706fe4Sjsing "N66V89etZ5NQJKMdrh4oOh5nfxLKvCcTK+9U4ZrgeGVdVXmL6HJp3m9CPobCBsC8\n"
7620706fe4Sjsing "DgI+zF/tg4GjDoVCJd6Tv5MRAmKiBrzTGglVeknkgiyIZ9C7gXU/7NMUihmLlt+8\n"
7720706fe4Sjsing "0zr+nL0P+MA924WV4fZJi1wtf6Eioalq6n/9i93nBRCeu8bEOBrTpAre2oBEoULI\n"
7820706fe4Sjsing "Ju7Ubx79AgMBAAECggEAD4XkGLKm+S6iiDJ5llL0x4qBPulH2UJ9l2HNakbO7ui7\n"
7920706fe4Sjsing "OzLjW+MCCgpU/dw75ftcnLW5E7nSSEU6iSiLDTN2zKBdatfUxW8EuhOUcU0wQLYQ\n"
8020706fe4Sjsing "E0lSiUwWdQEW+rX27US6XBLQxBav+ZZeplN7UvmdgXDnSkxfnJCoXVKh8GEuwWip\n"
8120706fe4Sjsing "sM/Lwg8MSZK0o5qFVXtPp7kreB8CWlVyPYW5rDYy3k02R1t9k6WSdO2foPXe9rdZ\n"
8220706fe4Sjsing "iiThkALcHdBcFF0NHrIkAgMdtcAxkDIwO2kOnGJQKDXu+txbzPYodMU0Z6eVnlIu\n"
8320706fe4Sjsing "jh9ZjnZKBJgX6YVLVPRBwQXHXeGAnvMNm2WXH7SCAQKBgQDmMxvspc3K6HOqMoik\n"
8420706fe4Sjsing "59Rq1gXIuaGH0uSMSiUMTkr4laJbh9WgZ6JTAfIPuhj1xKGfDK7LF9VjPQ104SgL\n"
8520706fe4Sjsing "dCA1pV6nsuGS3j3vBnaMfmO7yr3yON+p/WDpKOgqC51Z3/pT8reJtMnyowQuDeYe\n"
8620706fe4Sjsing "UVRVyeXA11nve0SSc97US4AtXQKBgQDZERtgs6ejiUJQXuflu9HDczEZ/pHfPI1y\n"
8720706fe4Sjsing "+RU0tvI4860OTjerVJA2YBeOBLa9Y3hblvNpOU0SoVeMAGQLblEznJAl1nbaWqVY\n"
8820706fe4Sjsing "kPgvtQcTOL/awEB90JklvSRqR82WJchMOHMG5SeqrpUx3Dg+cPH6nId0e8UCt3/U\n"
8920706fe4Sjsing "W/u/5hP+IQKBgQDfReEmxaZ10MIm6P6p24Wm3dEcYBfxEjbEb0HBzspek1u3JWep\n"
9020706fe4Sjsing "PfsuQavTXy/IaKBOENIUgBhjOZssqxnZChgXkD7frtulRNOTW5RuLkRzp3BWWJ1v\n"
9120706fe4Sjsing "VifB3gBYj41d16UH+VnVQbnCEiUCuk5hR4bh8oJaaUV8xvW6ipItHNHErQKBgGoe\n"
9220706fe4Sjsing "2uuj6UkiSbFRNL4z3JFZN6AlvNsOl3imHZ/v8Ou29dwQkVbJuNdckydzVoOwpZ7h\n"
9320706fe4Sjsing "ZY8D3JJHHq3rYv3TqQ86c56MAv8tYbiy5yMrtZHIJMOlSeI4oSa6GZt8Dx5gylO5\n"
9420706fe4Sjsing "JUMxtPrU70u5BiZAwYxsCi0AdYimfXAsqB9hNFUBAoGBAJPT7Xsr7NIkrbv+aYXj\n"
9520706fe4Sjsing "rVVJ1qokUEKT6H1GmFXO3Fkw3kjPKS8VZloKOB7OiBC+AwMEQIflArCZ+PJdnVNO\n"
9620706fe4Sjsing "48ntHnaeaZk8rKXsYdJsqMKgIxZYZuCIazZz9WHeYxn5vkH76Q3DrfqrneJ3HSU/\n"
9720706fe4Sjsing "pFtLoXoGoVXRjAtpNvX7fh/G\n"
9820706fe4Sjsing "-----END PRIVATE KEY-----\n";
9920706fe4Sjsing
100*844a3294Stb const char cms_ca_2[] =
101*844a3294Stb "-----BEGIN CERTIFICATE-----\n"
102*844a3294Stb "MIIBvTCCAW+gAwIBAgIQHioe49U1R3LcahmTCOUmoTAFBgMrZXAwXTEUMBIGA1UE\n"
103*844a3294Stb "ChMLQ01TIFRlc3QgQ0ExHTAbBgNVBAsMFGNtc3Rlc3RAbGlicmVzc2wub3JnMSYw\n"
104*844a3294Stb "JAYDVQQDDB1DTVMgVGVzdCBjbXN0ZXN0QGxpYnJlc3NsLm9yZzAeFw0yMzEwMDkw\n"
105*844a3294Stb "OTAzNDhaFw0zMzEwMDkwOTAzNDhaMF0xFDASBgNVBAoTC0NNUyBUZXN0IENBMR0w\n"
106*844a3294Stb "GwYDVQQLDBRjbXN0ZXN0QGxpYnJlc3NsLm9yZzEmMCQGA1UEAwwdQ01TIFRlc3Qg\n"
107*844a3294Stb "Y21zdGVzdEBsaWJyZXNzbC5vcmcwKjAFBgMrZXADIQAYj6pY7cN0DnwmsYHVDLqJ\n"
108*844a3294Stb "7/Futy5p4QJDKA/FSZ6+6KNFMEMwDgYDVR0PAQH/BAQDAgIEMBIGA1UdEwEB/wQI\n"
109*844a3294Stb "MAYBAf8CAQAwHQYDVR0OBBYEFE7G7c7O2Vj79+Q786M7ssMd/lflMAUGAytlcANB\n"
110*844a3294Stb "AOk+RHgs8D82saBM1nQMgIwEsNhYwbj3HhrRFDezYcnZeorBgiZTV3uQd2EndFdU\n"
111*844a3294Stb "hcs4OYMCRorxqpUXX6EMtwQ=\n"
112*844a3294Stb "-----END CERTIFICATE-----\n";
113*844a3294Stb
114*844a3294Stb const char cms_cert_2[] =
115*844a3294Stb "-----BEGIN CERTIFICATE-----\n"
116*844a3294Stb "MIIB5DCCAZagAwIBAgIQevuGe7FBHIc2pnQ4b4dsIzAFBgMrZXAwXTEUMBIGA1UE\n"
117*844a3294Stb "ChMLQ01TIFRlc3QgQ0ExHTAbBgNVBAsMFGNtc3Rlc3RAbGlicmVzc2wub3JnMSYw\n"
118*844a3294Stb "JAYDVQQDDB1DTVMgVGVzdCBjbXN0ZXN0QGxpYnJlc3NsLm9yZzAeFw0yMzEwMDkw\n"
119*844a3294Stb "OTAzNDhaFw0zMzEwMDkwOTAzNDhaMD4xHTAbBgNVBAoTFENNUyB0ZXN0IGNlcnRp\n"
120*844a3294Stb "ZmljYXRlMR0wGwYDVQQLDBRjbXN0ZXN0QGxpYnJlc3NsLm9yZzAqMAUGAytlcAMh\n"
121*844a3294Stb "AFH47Z54SuXMN+i5CCvMVUZJZzSYsDcRY+lPtc+J8h2ko4GKMIGHMA4GA1UdDwEB\n"
122*844a3294Stb "/wQEAwIFoDAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwQwHwYDVR0jBBgw\n"
123*844a3294Stb "FoAUTsbtzs7ZWPv35Dvzozuywx3+V+UwNQYDVR0RBC4wLIIUY21zdGVzdC5saWJy\n"
124*844a3294Stb "ZXNzbC5vcmeBFGNtc3Rlc3RAbGlicmVzc2wub3JnMAUGAytlcANBAAEqYppowFjF\n"
125*844a3294Stb "fTZhNM3cIyFfmQthJV/+krEE2VTSoKgCokll+fXz1K9P+R3asgrVDoHjnBtvksIE\n"
126*844a3294Stb "wup36c05XQA=\n"
127*844a3294Stb "-----END CERTIFICATE-----\n";
128*844a3294Stb
129*844a3294Stb const char cms_key_2[] =
130*844a3294Stb "-----BEGIN PRIVATE KEY-----\n"
131*844a3294Stb "MC4CAQAwBQYDK2VwBCIEIO88YApnGRDewzSwtxAnBvhlTPz9MjSz51mEpE2oi+9g\n"
132*844a3294Stb "-----END PRIVATE KEY-----\n";
133*844a3294Stb
13420706fe4Sjsing static void
hexdump(const unsigned char * buf,size_t len)13520706fe4Sjsing hexdump(const unsigned char *buf, size_t len)
13620706fe4Sjsing {
13720706fe4Sjsing size_t i;
13820706fe4Sjsing
13920706fe4Sjsing for (i = 1; i <= len; i++)
14020706fe4Sjsing fprintf(stderr, " 0x%02x,%s", buf[i - 1], i % 8 ? "" : "\n");
14120706fe4Sjsing if (len % 8 != 0)
14220706fe4Sjsing fprintf(stderr, "\n");
14320706fe4Sjsing }
14420706fe4Sjsing
14520706fe4Sjsing static int
test_cms_encrypt_decrypt(void)1468e87f5b5Stb test_cms_encrypt_decrypt(void)
14720706fe4Sjsing {
14820706fe4Sjsing STACK_OF(X509) *certs = NULL;
14920706fe4Sjsing CMS_ContentInfo *ci = NULL;
15020706fe4Sjsing EVP_PKEY *pkey = NULL;
15120706fe4Sjsing BIO *bio_mem = NULL;
152cba7e0c8Sjsing BIO *bio_out = NULL;
15320706fe4Sjsing X509 *cert = NULL;
15420706fe4Sjsing size_t len;
155167f52f3Stb long mem_len;
15620706fe4Sjsing char *p;
15720706fe4Sjsing int failed = 1;
15820706fe4Sjsing
15920706fe4Sjsing if ((bio_out = BIO_new_fp(stdout, BIO_NOCLOSE)) == NULL)
16020706fe4Sjsing errx(1, "failed to create BIO");
16120706fe4Sjsing
16220706fe4Sjsing if ((certs = sk_X509_new_null()) == NULL)
16320706fe4Sjsing errx(1, "failed to create certs");
16420706fe4Sjsing if ((bio_mem = BIO_new_mem_buf(cms_cert_1, -1)) == NULL)
16520706fe4Sjsing errx(1, "failed to create BIO for cert");
16620706fe4Sjsing if ((cert = PEM_read_bio_X509(bio_mem, NULL, NULL, NULL)) == NULL)
16720706fe4Sjsing errx(1, "failed to read cert");
16820706fe4Sjsing if (!sk_X509_push(certs, cert))
16920706fe4Sjsing errx(1, "failed to push cert");
17020706fe4Sjsing
17120706fe4Sjsing BIO_free(bio_mem);
17220706fe4Sjsing if ((bio_mem = BIO_new_mem_buf(cms_key_1, -1)) == NULL)
17320706fe4Sjsing errx(1, "failed to create BIO for key");
17420706fe4Sjsing if ((pkey = PEM_read_bio_PrivateKey(bio_mem, NULL, NULL, NULL)) == NULL)
17520706fe4Sjsing errx(1, "failed to read key");
17620706fe4Sjsing
17720706fe4Sjsing BIO_free(bio_mem);
17820706fe4Sjsing if ((bio_mem = BIO_new_mem_buf(cms_msg, -1)) == NULL)
17920706fe4Sjsing errx(1, "failed to create BIO for message");
18020706fe4Sjsing
18120706fe4Sjsing if ((ci = CMS_encrypt(certs, bio_mem, EVP_aes_256_cbc(), 0)) == NULL) {
18220706fe4Sjsing fprintf(stderr, "FAIL: CMS_encrypt returned NULL\n");
18320706fe4Sjsing ERR_print_errors_fp(stderr);
18420706fe4Sjsing goto failure;
18520706fe4Sjsing }
18620706fe4Sjsing
18720706fe4Sjsing if (verbose) {
18820706fe4Sjsing if (!CMS_ContentInfo_print_ctx(bio_out, ci, 0, NULL))
18920706fe4Sjsing errx(1, "failed to print CMS ContentInfo");
19020706fe4Sjsing if (!PEM_write_bio_CMS(bio_out, ci))
19120706fe4Sjsing errx(1, "failed to print CMS PEM");
19220706fe4Sjsing }
19320706fe4Sjsing
19420706fe4Sjsing BIO_free(bio_mem);
19520706fe4Sjsing if ((bio_mem = BIO_new(BIO_s_mem())) == NULL)
19620706fe4Sjsing errx(1, "failed to create BIO for message");
19720706fe4Sjsing
19820706fe4Sjsing if (!CMS_decrypt(ci, pkey, cert, NULL, bio_mem, 0)) {
19920706fe4Sjsing fprintf(stderr, "FAIL: CMS_decrypt failed\n");
20020706fe4Sjsing ERR_print_errors_fp(stderr);
20120706fe4Sjsing goto failure;
20220706fe4Sjsing }
20320706fe4Sjsing
204167f52f3Stb if ((mem_len = BIO_get_mem_data(bio_mem, &p)) <= 0) {
205167f52f3Stb fprintf(stderr, "FAIL: BIO_get_mem_data returned %ld\n",
206167f52f3Stb mem_len);
207167f52f3Stb goto failure;
208167f52f3Stb }
209167f52f3Stb if ((len = strlen(cms_msg)) != (size_t)mem_len) {
210167f52f3Stb fprintf(stderr, "FAIL: CMS decrypt returned %ld bytes, "
211167f52f3Stb "want %zu bytes\n", mem_len, len);
21220706fe4Sjsing fprintf(stderr, "Got CMS data:\n");
213167f52f3Stb hexdump(p, mem_len);
21420706fe4Sjsing fprintf(stderr, "Want CMS data:\n");
215167f52f3Stb hexdump(cms_msg, len);
21620706fe4Sjsing goto failure;
21720706fe4Sjsing }
21820706fe4Sjsing if (memcmp(p, cms_msg, len) != 0) {
21920706fe4Sjsing fprintf(stderr, "FAIL: CMS decrypt message differs");
22020706fe4Sjsing fprintf(stderr, "Got CMS data:\n");
221167f52f3Stb hexdump(p, mem_len);
22220706fe4Sjsing fprintf(stderr, "Want CMS data:\n");
223167f52f3Stb hexdump(cms_msg, len);
22420706fe4Sjsing goto failure;
22520706fe4Sjsing }
22620706fe4Sjsing
22720706fe4Sjsing failed = 0;
22820706fe4Sjsing
22920706fe4Sjsing failure:
23020706fe4Sjsing BIO_free(bio_mem);
231cba7e0c8Sjsing BIO_free(bio_out);
23220706fe4Sjsing CMS_ContentInfo_free(ci);
23320706fe4Sjsing EVP_PKEY_free(pkey);
23420706fe4Sjsing sk_X509_free(certs);
23520706fe4Sjsing X509_free(cert);
23620706fe4Sjsing
23720706fe4Sjsing return failed;
23820706fe4Sjsing }
23920706fe4Sjsing
240cba7e0c8Sjsing static int
test_cms_sign_verify(const char * ca_pem,const char * cert_pem,const char * key_pem)241*844a3294Stb test_cms_sign_verify(const char *ca_pem, const char *cert_pem,
242*844a3294Stb const char *key_pem)
243cba7e0c8Sjsing {
244cba7e0c8Sjsing STACK_OF(X509) *certs = NULL;
245cba7e0c8Sjsing CMS_ContentInfo *ci = NULL;
246cba7e0c8Sjsing X509_STORE *store = NULL;
247cba7e0c8Sjsing EVP_PKEY *pkey = NULL;
248cba7e0c8Sjsing BIO *bio_mem = NULL;
249cba7e0c8Sjsing BIO *bio_out = NULL;
250cba7e0c8Sjsing X509 *cert = NULL;
251cba7e0c8Sjsing X509 *ca = NULL;
252cba7e0c8Sjsing size_t len;
253167f52f3Stb long mem_len;
254cba7e0c8Sjsing char *p;
255cba7e0c8Sjsing int failed = 1;
256cba7e0c8Sjsing
257cba7e0c8Sjsing if ((bio_out = BIO_new_fp(stdout, BIO_NOCLOSE)) == NULL)
258cba7e0c8Sjsing errx(1, "failed to create BIO");
259cba7e0c8Sjsing
260cba7e0c8Sjsing if ((certs = sk_X509_new_null()) == NULL)
261cba7e0c8Sjsing errx(1, "failed to create certs");
262*844a3294Stb if ((bio_mem = BIO_new_mem_buf(cert_pem, -1)) == NULL)
263cba7e0c8Sjsing errx(1, "failed to create BIO for cert");
264cba7e0c8Sjsing if ((cert = PEM_read_bio_X509(bio_mem, NULL, NULL, NULL)) == NULL)
265cba7e0c8Sjsing errx(1, "failed to read cert");
266cba7e0c8Sjsing if (!sk_X509_push(certs, cert))
267cba7e0c8Sjsing errx(1, "failed to push cert");
268cba7e0c8Sjsing
269cba7e0c8Sjsing BIO_free(bio_mem);
270*844a3294Stb if ((bio_mem = BIO_new_mem_buf(ca_pem, -1)) == NULL)
271cba7e0c8Sjsing errx(1, "failed to create BIO for cert");
272cba7e0c8Sjsing if ((ca = PEM_read_bio_X509(bio_mem, NULL, NULL, NULL)) == NULL)
273cba7e0c8Sjsing errx(1, "failed to read cert");
274cba7e0c8Sjsing if ((store = X509_STORE_new()) == NULL)
275cba7e0c8Sjsing errx(1, "failed to create X509 store");
276cba7e0c8Sjsing if (!X509_STORE_add_cert(store, ca))
277cba7e0c8Sjsing errx(1, "failed to add cert to store");
278cba7e0c8Sjsing
279cba7e0c8Sjsing BIO_free(bio_mem);
280*844a3294Stb if ((bio_mem = BIO_new_mem_buf(key_pem, -1)) == NULL)
281cba7e0c8Sjsing errx(1, "failed to create BIO for key");
282cba7e0c8Sjsing if ((pkey = PEM_read_bio_PrivateKey(bio_mem, NULL, NULL, NULL)) == NULL)
283cba7e0c8Sjsing errx(1, "failed to read key");
284cba7e0c8Sjsing
285cba7e0c8Sjsing BIO_free(bio_mem);
286cba7e0c8Sjsing if ((bio_mem = BIO_new_mem_buf(cms_msg, -1)) == NULL)
287cba7e0c8Sjsing errx(1, "failed to create BIO for message");
288cba7e0c8Sjsing
289cba7e0c8Sjsing if ((ci = CMS_sign(cert, pkey, NULL, bio_mem, 0)) == NULL) {
290cba7e0c8Sjsing fprintf(stderr, "FAIL: CMS sign failed\n");
291cba7e0c8Sjsing ERR_print_errors_fp(stderr);
292cba7e0c8Sjsing goto failure;
293cba7e0c8Sjsing }
294cba7e0c8Sjsing
295cba7e0c8Sjsing if (verbose) {
296cba7e0c8Sjsing if (!CMS_ContentInfo_print_ctx(bio_out, ci, 0, NULL))
297cba7e0c8Sjsing errx(1, "failed to print CMS ContentInfo");
298cba7e0c8Sjsing if (!PEM_write_bio_CMS(bio_out, ci))
299cba7e0c8Sjsing errx(1, "failed to print CMS PEM");
300cba7e0c8Sjsing }
301cba7e0c8Sjsing
302cba7e0c8Sjsing BIO_free(bio_mem);
303cba7e0c8Sjsing if ((bio_mem = BIO_new(BIO_s_mem())) == NULL)
304cba7e0c8Sjsing errx(1, "failed to create BIO for message");
305cba7e0c8Sjsing
306cba7e0c8Sjsing if (!CMS_verify(ci, certs, store, NULL, bio_mem, 0)) {
307cba7e0c8Sjsing fprintf(stderr, "FAIL: CMS_verify failed\n");
308cba7e0c8Sjsing ERR_print_errors_fp(stderr);
309cba7e0c8Sjsing goto failure;
310cba7e0c8Sjsing }
311cba7e0c8Sjsing
312167f52f3Stb if ((mem_len = BIO_get_mem_data(bio_mem, &p)) <= 0) {
313167f52f3Stb fprintf(stderr, "FAIL: BIO_get_mem_data returned %ld\n",
314167f52f3Stb mem_len);
315167f52f3Stb goto failure;
316167f52f3Stb }
317167f52f3Stb if ((len = strlen(cms_msg)) != (size_t)mem_len) {
318167f52f3Stb fprintf(stderr, "FAIL: CMS verify returned %ld bytes, "
319167f52f3Stb "want %zu bytes\n", mem_len, len);
320cba7e0c8Sjsing fprintf(stderr, "Got CMS data:\n");
321167f52f3Stb hexdump(p, mem_len);
322cba7e0c8Sjsing fprintf(stderr, "Want CMS data:\n");
323167f52f3Stb hexdump(cms_msg, len);
324cba7e0c8Sjsing goto failure;
325cba7e0c8Sjsing }
326cba7e0c8Sjsing if (memcmp(p, cms_msg, len) != 0) {
327cba7e0c8Sjsing fprintf(stderr, "FAIL: CMS verify message differs");
328cba7e0c8Sjsing fprintf(stderr, "Got CMS data:\n");
329167f52f3Stb hexdump(p, mem_len);
330cba7e0c8Sjsing fprintf(stderr, "Want CMS data:\n");
331167f52f3Stb hexdump(cms_msg, len);
332cba7e0c8Sjsing goto failure;
333cba7e0c8Sjsing }
334cba7e0c8Sjsing
335cba7e0c8Sjsing failed = 0;
336cba7e0c8Sjsing
337cba7e0c8Sjsing failure:
338cba7e0c8Sjsing BIO_free(bio_mem);
339cba7e0c8Sjsing BIO_free(bio_out);
340cba7e0c8Sjsing CMS_ContentInfo_free(ci);
341cba7e0c8Sjsing EVP_PKEY_free(pkey);
342cba7e0c8Sjsing sk_X509_free(certs);
343cba7e0c8Sjsing X509_free(cert);
344cba7e0c8Sjsing X509_STORE_free(store);
345403d8dc1Stb X509_free(ca);
346cba7e0c8Sjsing
347cba7e0c8Sjsing return failed;
348cba7e0c8Sjsing }
349cba7e0c8Sjsing
35020706fe4Sjsing int
main(int argc,char ** argv)35120706fe4Sjsing main(int argc, char **argv)
35220706fe4Sjsing {
35320706fe4Sjsing int failed = 0;
35420706fe4Sjsing
35520706fe4Sjsing ERR_load_crypto_strings();
35620706fe4Sjsing
35720706fe4Sjsing failed |= test_cms_encrypt_decrypt();
358*844a3294Stb failed |= test_cms_sign_verify(cms_ca_1, cms_cert_1, cms_key_1);
359*844a3294Stb failed |= test_cms_sign_verify(cms_ca_2, cms_cert_2, cms_key_2);
36020706fe4Sjsing
36120706fe4Sjsing return failed;
36220706fe4Sjsing }
363