[MTCs] update some tests to draft-plants-04 There were some tests that only tested the draft-davidben-08 path. Update them to plants-04. Since this CL is in preparation for removing support for the old draft entirely, it just updates the tests in-place rather than adding tests for both drafts. Change-Id: I94688573b989d4cefb524ef05c585decc731f6bc Bug: 520071497 Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/101127 Reviewed-by: David Benjamin <davidben@google.com> Commit-Queue: Matt Mueller <mattm@google.com>
diff --git a/pki/testdata/verify_unittest/mtc-config.json b/pki/testdata/verify_unittest/mtc-config.json index 2676874..c612a41 100644 --- a/pki/testdata/verify_unittest/mtc-config.json +++ b/pki/testdata/verify_unittest/mtc-config.json
@@ -1,9 +1,17 @@ { - "Version": "davidben-09", - "LogID": "32473.1", + "Version": "plants-04", + "ID": "32473.1", + "LogNumber": 1, + "Cosigners": [ + { + "CosignerID": "32473.1", + "SignatureAlgorithm": "mldsa44", + "PrivateKey": "MDQCAQAwCwYJYIZIAWUDBAMRBCKAIAABAgMEBQYHCAkKCwwNDg8QERITFBUWFxgZGhscHR4f" + } + ], "Entries": [ { - "Repeat": 8, + "Repeat": 9, "Subject": { "CommonName": "Filler certificates" },
diff --git a/pki/testdata/verify_unittest/mtc-leaf-b.pem b/pki/testdata/verify_unittest/mtc-leaf-b.pem index d181b18..d4a24a0 100644 --- a/pki/testdata/verify_unittest/mtc-leaf-b.pem +++ b/pki/testdata/verify_unittest/mtc-leaf-b.pem
@@ -1,11 +1,11 @@ -----BEGIN CERTIFICATE----- -MIIBjjCCAQWgAwIBAgIBCjAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEEAYLaSy8B -DAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVowADBZMBMG -ByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3clHe7DPNI -wH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBTMA4GA1Ud -DwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREBAf8EHzAd -ggliLmV4YW1wbGWCECouYmxhaC5iLmV4YW1wbGUwDAYKKwYBBAGC2ksvAAN1AAAA -AAAAAAAIAAAAAAAAABAAYEU5Qbm6XiITuPIIBG/EvPYLIl1JMzJKZ3atLHkoGOAb -x676xK7Ke7qP8w1tdF+k1wUIIjlmGT+aB2KOSOic0Wi/qlGnfqNJMluHRIvrrYnS -pSqKdlven8bsZWqgWDrP9AAA +MIIBkjCCAQugAwIBAgIHAQAAAAAACjAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEE +AYLaSy8BDAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVow +ADBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3c +lHe7DPNIwH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBT +MA4GA1UdDwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREB +Af8EHzAdggliLmV4YW1wbGWCECouYmxhaC5iLmV4YW1wbGUwDAYKKwYBBAGC2ksv +AANzAAAAAAAAAAAIAAAAAAAQAGADaPHAKcaptKHsp2da08Jy9WW6UzQlKWYJzfoe +RF0xIroyFtUgaA17H43oFPqWjefi50C8MzpB4A2KCRc7aTM83ScxvAWiKwAhfSqv +1pSIs3Xz5Krj9hXQd89+xOW/D1YAAA== -----END CERTIFICATE-----
diff --git a/pki/testdata/verify_unittest/mtc-leaf-bitflip.pem b/pki/testdata/verify_unittest/mtc-leaf-bitflip.pem index 70d152e..8c4a1b2 100644 --- a/pki/testdata/verify_unittest/mtc-leaf-bitflip.pem +++ b/pki/testdata/verify_unittest/mtc-leaf-bitflip.pem
@@ -1,11 +1,11 @@ -----BEGIN CERTIFICATE----- -MIIBjjCCAQWgAwIBAgIBCTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEEAYLaSy8B -DAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVowADBZMBMG -ByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3clHe7DPNI -wH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBTMA4GA1Ud -DwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREBAf8EHzAd -gglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksvAAN1AAAA -AAAAAAAIAAAAAAAAAA0AYGbmiKnfNXzM/834NuaRq4i0xGTzYV6nx8s8iUliZgki -gQcBu21ak6gq40RFYQpnPL0juf88bIJsdUymRTaKOe9FOUG5ul4iE7jyCARvxLz2 -CyJdSTMySmd2rSx5KBjgGwAA +MIIBkjCCAQugAwIBAgIHAQAAAAAACTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEE +AYLaSy8BDAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVow +ADBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3c +lHe7DPNIwH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBT +MA4GA1UdDwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREB +Af8EHzAdgglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksv +AANzAAAAAAAAAAAIAAAAAAANAGAEgK6gczm8d8gKP5tFa2nRAk0ir2AEjDporD5o +5huNWOraA53zncs3yWFVfBw1C95pfVJB5EMmJ/EMPEwtZLFTA2jxwCnGqbSh7Kdn +WtPCcvVlulM0JSlmCc36HkRdMSIAAA== -----END CERTIFICATE-----
diff --git a/pki/testdata/verify_unittest/mtc-leaf-c.pem b/pki/testdata/verify_unittest/mtc-leaf-c.pem index f40f175..eb0ab6c 100644 --- a/pki/testdata/verify_unittest/mtc-leaf-c.pem +++ b/pki/testdata/verify_unittest/mtc-leaf-c.pem
@@ -1,10 +1,11 @@ -----BEGIN CERTIFICATE----- -MIIBezCB86ADAgECAgETMAwGCisGAQQBgtpLLwAwGTEXMBUGCisGAQQBgtpLLwEM -BzMyNDczLjEwHhcNMjAwMTAxMDAwMDAwWhcNMzAxMjMxMjM1OTU5WjAAMFkwEwYH -KoZIzj0CAQYIKoZIzj0DAQcDQgAEyxiC16lts+SOL87OwHhGDzK9/dyUd7sM80jA -f53VL+AV38HoHKpmA7LJoYLf4yVhcVleNcxufsAfcPueTLX0VqNDMEEwDgYDVR0P -AQH/BAQDAgeAMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMBMBcGA1UdEQEB/wQNMAuC -CWMuZXhhbXBsZTAMBgorBgEEAYLaSy8AA3UAAAAAAAAAABAAAAAAAAAAGABgRTlB -ubpeIhO48ggEb8S89gsiXUkzMkpndq0seSgY4BvkaISclDjMOiHjWnQVjQwcga3E -eAlic9H5ARHDCvYTFkg9lSfzzvEVi2O7/esSu2PyEF9BBZ0x5YD/8oihdjQoAAA= +MIIBfzCB+aADAgECAgcBAAAAAAATMAwGCisGAQQBgtpLLwAwGTEXMBUGCisGAQQB +gtpLLwEMBzMyNDczLjEwHhcNMjAwMTAxMDAwMDAwWhcNMzAxMjMxMjM1OTU5WjAA +MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEyxiC16lts+SOL87OwHhGDzK9/dyU +d7sM80jAf53VL+AV38HoHKpmA7LJoYLf4yVhcVleNcxufsAfcPueTLX0VqNDMEEw +DgYDVR0PAQH/BAQDAgeAMBYGA1UdJQEB/wQMMAoGCCsGAQUFBwMBMBcGA1UdEQEB +/wQNMAuCCWMuZXhhbXBsZTAMBgorBgEEAYLaSy8AA3MAAAAAAAAAABAAAAAAABgA +YANo8cApxqm0oeynZ1rTwnL1ZbpTNCUpZgnN+h5EXTEi3n7BWV1YiEcwgdTB75Vw +9NF6ulTPsnQ68LkiqN63NEY2B38j4kagiB9RFst03akiQJqUQgnVr7Zz6gG5Cq8J +tgAA -----END CERTIFICATE-----
diff --git a/pki/testdata/verify_unittest/mtc-leaf-unused-bit.pem b/pki/testdata/verify_unittest/mtc-leaf-unused-bit.pem index 91612bb..ea4a145 100644 --- a/pki/testdata/verify_unittest/mtc-leaf-unused-bit.pem +++ b/pki/testdata/verify_unittest/mtc-leaf-unused-bit.pem
@@ -1,11 +1,11 @@ -----BEGIN CERTIFICATE----- -MIIBjjCCAQWgAwIBAgIBCTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEEAYLaSy8B -DAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVowADBZMBMG -ByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3clHe7DPNI -wH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBTMA4GA1Ud -DwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREBAf8EHzAd -gglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksvAAN1AQAA -AAAAAAAIAAAAAAAAAA0AYGfmiKnfNXzM/834NuaRq4i0xGTzYV6nx8s8iUliZgki -gQcBu21ak6gq40RFYQpnPL0juf88bIJsdUymRTaKOe9FOUG5ul4iE7jyCARvxLz2 -CyJdSTMySmd2rSx5KBjgGwAA +MIIBkjCCAQugAwIBAgIHAQAAAAAACTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEE +AYLaSy8BDAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVow +ADBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3c +lHe7DPNIwH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBT +MA4GA1UdDwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREB +Af8EHzAdgglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksv +AANzAQAAAAAAAAAIAAAAAAANAGAFgK6gczm8d8gKP5tFa2nRAk0ir2AEjDporD5o +5huNWOraA53zncs3yWFVfBw1C95pfVJB5EMmJ/EMPEwtZLFTA2jxwCnGqbSh7Kdn +WtPCcvVlulM0JSlmCc36HkRdMSIAAA== -----END CERTIFICATE-----
diff --git a/pki/testdata/verify_unittest/mtc-leaf.pem b/pki/testdata/verify_unittest/mtc-leaf.pem index d9ce153..790b812 100644 --- a/pki/testdata/verify_unittest/mtc-leaf.pem +++ b/pki/testdata/verify_unittest/mtc-leaf.pem
@@ -1,11 +1,11 @@ -----BEGIN CERTIFICATE----- -MIIBjjCCAQWgAwIBAgIBCTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEEAYLaSy8B -DAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVowADBZMBMG -ByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3clHe7DPNI -wH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBTMA4GA1Ud -DwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREBAf8EHzAd -gglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksvAAN1AAAA -AAAAAAAIAAAAAAAAAA0AYGfmiKnfNXzM/834NuaRq4i0xGTzYV6nx8s8iUliZgki -gQcBu21ak6gq40RFYQpnPL0juf88bIJsdUymRTaKOe9FOUG5ul4iE7jyCARvxLz2 -CyJdSTMySmd2rSx5KBjgGwAA +MIIBkjCCAQugAwIBAgIHAQAAAAAACTAMBgorBgEEAYLaSy8AMBkxFzAVBgorBgEE +AYLaSy8BDAczMjQ3My4xMB4XDTIwMDEwMTAwMDAwMFoXDTMwMTIzMTIzNTk1OVow +ADBZMBMGByqGSM49AgEGCCqGSM49AwEHA0IABMsYgtepbbPkji/OzsB4Rg8yvf3c +lHe7DPNIwH+d1S/gFd/B6ByqZgOyyaGC3+MlYXFZXjXMbn7AH3D7nky19FajVTBT +MA4GA1UdDwEB/wQEAwIHgDAWBgNVHSUBAf8EDDAKBggrBgEFBQcDATApBgNVHREB +Af8EHzAdgglhLmV4YW1wbGWCECouYmxhaC5hLmV4YW1wbGUwDAYKKwYBBAGC2ksv +AANzAAAAAAAAAAAIAAAAAAANAGAFgK6gczm8d8gKP5tFa2nRAk0ir2AEjDporD5o +5huNWOraA53zncs3yWFVfBw1C95pfVJB5EMmJ/EMPEwtZLFTA2jxwCnGqbSh7Kdn +WtPCcvVlulM0JSlmCc36HkRdMSIAAA== -----END CERTIFICATE-----
diff --git a/pki/testdata/verify_unittest/readme-mtc-certs.md b/pki/testdata/verify_unittest/readme-mtc-certs.md index a8ebb6e..1113176 100644 --- a/pki/testdata/verify_unittest/readme-mtc-certs.md +++ b/pki/testdata/verify_unittest/readme-mtc-certs.md
@@ -13,7 +13,7 @@ ## Instructions - Run - `go run github.com/ietf-plants-wg/merkle-tree-certs/demo@b0c83104918f10e8c813783f77434143eab4ef97 -config=mtc-config.json` + `go run github.com/ietf-plants-wg/merkle-tree-certs/demo@9029a99bcfa4e91b8b8e9ba646ac386a6e1c208f -config=mtc-config.json -out=out` - copy/move the following output files: - `out/cert_9_0.pem` to `mtc-leaf.pem` - `out/cert_9_1.pem` to `mtc-leaf-bitflip.pem` @@ -23,4 +23,4 @@ - edit `VerifyMTCTest::SetUp` to set the trusted subtrees to the ones output by the above command. - remove other artifacts created by the merkle-tree-certs/demo tool (e.g. - `rm -r out`). \ No newline at end of file + `rm -r out`).
diff --git a/pki/trust_store_collection_unittest.cc b/pki/trust_store_collection_unittest.cc index 8c82349..3902ba9 100644 --- a/pki/trust_store_collection_unittest.cc +++ b/pki/trust_store_collection_unittest.cc
@@ -214,21 +214,21 @@ // Create modified versions of `mtc_leaf_` with different issuers. These // don't need to be able to verify, we just need certs with different // issuers to test the issuer lookup in GetTrustedMTCIssuerOf. - constexpr char kLogId2Str[] = "32473.2"; - mtc_leaf2_ = ModifyLeafWithIssuerLogId(kLogId2Str); + constexpr char kCaId2Str[] = "32473.2"; + mtc_leaf2_ = ModifyLeafWithIssuerCaId(kCaId2Str); ASSERT_TRUE(mtc_leaf2_); - constexpr char kLogId3Str[] = "32473.3"; - mtc_leaf3_ = ModifyLeafWithIssuerLogId(kLogId3Str); + constexpr char kCaId3Str[] = "32473.3"; + mtc_leaf3_ = ModifyLeafWithIssuerCaId(kCaId3Str); ASSERT_TRUE(mtc_leaf3_); } - std::shared_ptr<const ParsedCertificate> ModifyLeafWithIssuerLogId( - std::string_view new_log_id) { - // The log_id encoded in the issuer name of mtc-leaf.pem. - constexpr std::string_view log_id_str = "32473.1"; + std::shared_ptr<const ParsedCertificate> ModifyLeafWithIssuerCaId( + std::string_view new_ca_id) { + // The ca_id encoded in the issuer name of mtc-leaf.pem. + constexpr std::string_view ca_id_str = "32473.1"; - if (new_log_id.size() != log_id_str.size()) { + if (new_ca_id.size() != ca_id_str.size()) { ADD_FAILURE() << "invalid replacement string"; return nullptr; } @@ -236,15 +236,15 @@ std::vector<uint8_t> leaf_der2(mtc_leaf_->der_cert().begin(), mtc_leaf_->der_cert().end()); - // find the log_id_str in leaf_der2 and replace the bytes with - // new log id. - auto it = std::search(leaf_der2.begin(), leaf_der2.end(), - log_id_str.begin(), log_id_str.end()); + // find the ca_id_str in leaf_der2 and replace the bytes with + // new CA id. + auto it = std::search(leaf_der2.begin(), leaf_der2.end(), ca_id_str.begin(), + ca_id_str.end()); if (it == leaf_der2.end()) { - ADD_FAILURE() << "log id not found"; + ADD_FAILURE() << "CA id not found"; return nullptr; } - std::copy(new_log_id.begin(), new_log_id.end(), it); + std::copy(new_ca_id.begin(), new_ca_id.end(), it); CertErrors errors; std::shared_ptr<const ParsedCertificate> mtc_leaf2 = @@ -268,17 +268,22 @@ } TEST_F(TrustStoreCollectionMtcTest, MtcTwoStores) { - constexpr uint8_t kLogid1[] = {0x81, 0xfd, 0x59, 0x01}; - constexpr uint8_t kLogid2[] = {0x81, 0xfd, 0x59, 0x02}; - constexpr uint8_t kLogid3[] = {0x81, 0xfd, 0x59, 0x03}; + constexpr uint8_t kCaId1[] = {0x81, 0xfd, 0x59, 0x01}; + constexpr uint8_t kCaId2[] = {0x81, 0xfd, 0x59, 0x02}; + constexpr uint8_t kCaId3[] = {0x81, 0xfd, 0x59, 0x03}; - Span<const TrustedSubtree> trusted_subtrees; - std::shared_ptr<const MTCAnchor> mtc_anchor1 = - std::make_shared<MTCAnchor>(MakeSpan(kLogid1), trusted_subtrees); - std::shared_ptr<const MTCAnchor> mtc_anchor2 = - std::make_shared<MTCAnchor>(MakeSpan(kLogid2), trusted_subtrees); - std::shared_ptr<const MTCAnchor> mtc_anchor3 = - std::make_shared<MTCAnchor>(MakeSpan(kLogid3), trusted_subtrees); + std::map<uint16_t, std::vector<TrustedSubtree>> trusted_subtrees; + // The ca_key doesn't need to be valid for this test. + UniquePtr<CRYPTO_BUFFER> ca_spki(CRYPTO_BUFFER_new({}, 0, nullptr)); + auto mtc_anchor1 = std::make_shared<MTCAnchor>( + MakeSpan(kCaId1), SignatureAlgorithm::kMldsa44, UpRef(ca_spki), + trusted_subtrees); + auto mtc_anchor2 = std::make_shared<MTCAnchor>( + MakeSpan(kCaId2), SignatureAlgorithm::kMldsa44, UpRef(ca_spki), + trusted_subtrees); + auto mtc_anchor3 = std::make_shared<MTCAnchor>( + MakeSpan(kCaId3), SignatureAlgorithm::kMldsa44, UpRef(ca_spki), + trusted_subtrees); TrustStoreCollection collection; TrustStoreInMemory in_memory1;
diff --git a/pki/trust_store_in_memory_unittest.cc b/pki/trust_store_in_memory_unittest.cc index 962bb51..0aea227 100644 --- a/pki/trust_store_in_memory_unittest.cc +++ b/pki/trust_store_in_memory_unittest.cc
@@ -131,14 +131,15 @@ EXPECT_TRUE(in_memory.IsEmpty()); // After adding an MTC root, it is no longer empty: - static const uint8_t kValidLogId[] = {42}; // relative OID of 42 - TrustedSubtree a; - a.range = Subtree{0, 4}; - std::vector<TrustedSubtree> valid_subtrees = {a}; - std::shared_ptr<MTCAnchor> valid_anchor = - std::make_shared<MTCAnchor>(kValidLogId, MakeSpan(valid_subtrees)); - EXPECT_TRUE(valid_anchor->IsValid()); - EXPECT_TRUE(in_memory.AddMTCTrustAnchor(valid_anchor)); + static const uint8_t kMtcCaId[] = {42}; // relative OID of 42 + // The ca_key doesn't need to be valid for this test. + UniquePtr<CRYPTO_BUFFER> ca_spki(CRYPTO_BUFFER_new({}, 0, nullptr)); + std::map<uint16_t, std::vector<TrustedSubtree>> trusted_subtrees; + auto mtc_anchor = std::make_shared<MTCAnchor>( + MakeSpan(kMtcCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki), + trusted_subtrees); + EXPECT_TRUE(mtc_anchor->IsValid()); + EXPECT_TRUE(in_memory.AddMTCTrustAnchor(mtc_anchor)); EXPECT_FALSE(in_memory.IsEmpty()); // It is empty again after a call to Clear: @@ -150,45 +151,52 @@ TrustStoreInMemory in_memory; // AddMTCTrustAnchor should fail if the MTCAnchor is invalid. - static const uint8_t kValidLogId[] = {42}; // relative OID of 42 + static const uint8_t kValidCaId[] = {42}; // relative OID of 42 TrustedSubtree a; a.range = Subtree{0, 4}; TrustedSubtree b; b.range = Subtree{0, 6}; TrustedSubtree c; c.range = Subtree{8, 9}; - std::vector<TrustedSubtree> valid_subtrees = {a, b, c}; - std::shared_ptr<MTCAnchor> valid_anchor = - std::make_shared<MTCAnchor>(kValidLogId, MakeSpan(valid_subtrees)); + std::map<uint16_t, std::vector<TrustedSubtree>> valid_subtrees; + valid_subtrees[1] = {a, b, c}; + // The ca_key doesn't need to be valid for this test. + UniquePtr<CRYPTO_BUFFER> ca_spki(CRYPTO_BUFFER_new({}, 0, nullptr)); + std::shared_ptr<MTCAnchor> valid_anchor = std::make_shared<MTCAnchor>( + kValidCaId, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), valid_subtrees); EXPECT_TRUE(valid_anchor->IsValid()); - EXPECT_EQ(valid_anchor->log_id(), kValidLogId); + EXPECT_EQ(valid_anchor->ca_id(), kValidCaId); EXPECT_TRUE(in_memory.AddMTCTrustAnchor(valid_anchor)); { - // Attempting to add another MTCTrustAnchor with the same Log ID should fail + // Attempting to add another MTCTrustAnchor with the same CA ID should fail TrustedSubtree d; d.range = Subtree{16, 17}; - std::vector<TrustedSubtree> subtrees = {d}; - std::shared_ptr<MTCAnchor> anchor = - std::make_shared<MTCAnchor>(kValidLogId, MakeSpan(subtrees)); + std::map<uint16_t, std::vector<TrustedSubtree>> subtrees; + subtrees[1] = {d}; + std::shared_ptr<MTCAnchor> anchor = std::make_shared<MTCAnchor>( + kValidCaId, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), subtrees); EXPECT_TRUE(anchor->IsValid()); EXPECT_FALSE(in_memory.AddMTCTrustAnchor(anchor)); } { - static const uint8_t kInvalidLogId[] = { + static const uint8_t kInvalidCaId[] = { 255}; // The high bit is set, indicating this relative OID has more // bytes, but there are no more bytes. std::shared_ptr<MTCAnchor> invalid_anchor = - std::make_shared<MTCAnchor>(kInvalidLogId, MakeSpan(valid_subtrees)); + std::make_shared<MTCAnchor>(kInvalidCaId, SignatureAlgorithm::kMldsa44, + UpRef(ca_spki), valid_subtrees); EXPECT_FALSE(invalid_anchor->IsValid()); EXPECT_FALSE(in_memory.AddMTCTrustAnchor(invalid_anchor)); } { - std::vector<TrustedSubtree> invalid_subtrees = {b, a, c}; + std::map<uint16_t, std::vector<TrustedSubtree>> invalid_subtrees; + invalid_subtrees[1] = {b, a, c}; std::shared_ptr<MTCAnchor> invalid_anchor = - std::make_shared<MTCAnchor>(kValidLogId, MakeSpan(invalid_subtrees)); + std::make_shared<MTCAnchor>(kValidCaId, SignatureAlgorithm::kMldsa44, + UpRef(ca_spki), invalid_subtrees); EXPECT_FALSE(invalid_anchor->IsValid()); EXPECT_FALSE(in_memory.AddMTCTrustAnchor(invalid_anchor)); } @@ -196,9 +204,11 @@ { TrustedSubtree subtree; subtree.range = Subtree{4, 9}; - std::vector<TrustedSubtree> invalid_subtrees = {subtree}; + std::map<uint16_t, std::vector<TrustedSubtree>> invalid_subtrees; + invalid_subtrees[1] = {subtree}; std::shared_ptr<MTCAnchor> invalid_anchor = - std::make_shared<MTCAnchor>(kValidLogId, MakeSpan(invalid_subtrees)); + std::make_shared<MTCAnchor>(kValidCaId, SignatureAlgorithm::kMldsa44, + UpRef(ca_spki), invalid_subtrees); EXPECT_FALSE(invalid_anchor->IsValid()); EXPECT_FALSE(in_memory.AddMTCTrustAnchor(invalid_anchor)); } @@ -208,17 +218,20 @@ TrustStoreInMemory in_memory1; TrustStoreInMemory in_memory2; - static const uint8_t kValidLogId1[] = {42}; // relative OID of 42 - static const uint8_t kValidLogId2[] = {43}; // relative OID of 43 - std::vector<TrustedSubtree> subtrees; - std::shared_ptr<MTCAnchor> anchor1 = - std::make_shared<MTCAnchor>(kValidLogId1, MakeSpan(subtrees)); - std::shared_ptr<MTCAnchor> anchor1_dup = - std::make_shared<MTCAnchor>(kValidLogId1, MakeSpan(subtrees)); - std::shared_ptr<MTCAnchor> anchor2 = - std::make_shared<MTCAnchor>(kValidLogId2, MakeSpan(subtrees)); - std::shared_ptr<MTCAnchor> anchor2_dup = - std::make_shared<MTCAnchor>(kValidLogId2, MakeSpan(subtrees)); + static const uint8_t kValidCaId1[] = {42}; // relative OID of 42 + static const uint8_t kValidCaId2[] = {43}; // relative OID of 43 + std::map<uint16_t, std::vector<TrustedSubtree>> subtrees; + // The ca_key doesn't need to be valid for this test. + UniquePtr<CRYPTO_BUFFER> ca_spki(CRYPTO_BUFFER_new({}, 0, nullptr)); + + std::shared_ptr<MTCAnchor> anchor1 = std::make_shared<MTCAnchor>( + kValidCaId1, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), subtrees); + std::shared_ptr<MTCAnchor> anchor1_dup = std::make_shared<MTCAnchor>( + kValidCaId1, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), subtrees); + std::shared_ptr<MTCAnchor> anchor2 = std::make_shared<MTCAnchor>( + kValidCaId2, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), subtrees); + std::shared_ptr<MTCAnchor> anchor2_dup = std::make_shared<MTCAnchor>( + kValidCaId2, SignatureAlgorithm::kMldsa44, UpRef(ca_spki), subtrees); ASSERT_TRUE(in_memory1.AddMTCTrustAnchor(anchor1)); ASSERT_TRUE(in_memory2.AddMTCTrustAnchor(anchor2));
diff --git a/pki/verify_unittest.cc b/pki/verify_unittest.cc index 31205a3..b959c7d 100644 --- a/pki/verify_unittest.cc +++ b/pki/verify_unittest.cc
@@ -21,6 +21,7 @@ #include <gmock/gmock.h> #include <gtest/gtest.h> +#include <openssl/bytestring.h> #include <openssl/pki/verify.h> #include <openssl/pki/verify_error.h> #include <openssl/pool.h> @@ -179,11 +180,40 @@ ASSERT_TRUE(CertificateVerify(opts, &error)) << error.DiagnosticString(); } +namespace { +UniquePtr<CRYPTO_BUFFER> ExportPublicKeyFromSeed(Span<const uint8_t> seed) { + UniquePtr<EVP_PKEY> pkey(EVP_PKEY_from_private_seed( + EVP_pkey_ml_dsa_44(), seed.data(), seed.size())); + if (!pkey) { + return nullptr; + } + + ScopedCBB cbb; + if (!CBB_init(cbb.get(), 0) || + !EVP_marshal_public_key(cbb.get(), pkey.get())) { + return nullptr; + } + return UniquePtr<CRYPTO_BUFFER>( + CRYPTO_BUFFER_new(CBB_data(cbb.get()), CBB_len(cbb.get()), nullptr)); +} +} // namespace + +// TODO(crbug.com/452986180): These MTC tests only test the landmark relative +// path, the standalone MTC tests all ended up in path_builder_unittest. Should +// probably have at least one or two standalone tests that go through this +// interface. class VerifyMTCTest : public ::testing::Test { public: VerifyMTCTest() = default; void SetUp() override { + static constexpr uint8_t kCaPrivateKeySeed[] = { + 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, + 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, + 0x16, 0x17, 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f}; + ca_spki_ = ExportPublicKeyFromSeed(kCaPrivateKeySeed); + ASSERT_TRUE(ca_spki_); + ASSERT_TRUE(ReadTestCertPem("mtc-leaf.pem", &generic_cert_)); ASSERT_TRUE(ReadTestCertPem("mtc-leaf-bitflip.pem", &bitflip_cert_)); ASSERT_TRUE(ReadTestCertPem("mtc-leaf-unused-bit.pem", &unused_bit_cert_)); @@ -191,13 +221,13 @@ ASSERT_TRUE(ReadTestCertPem("mtc-leaf-c.pem", &leaf_c_)); ASSERT_TRUE( - CreateTrustedSubtree("Rrynt7BBSfI4WMZ1u1+XOJSNaWnYOdUDjn7VbdF+kQY=", 8, + CreateTrustedSubtree("+g71+77yhXVIT2NWwsHWnTz8TFyJ6yT9TLDGOW+Vi6k=", 8, 13, &generic_cert_subtree_)); ASSERT_TRUE( - CreateTrustedSubtree("S92aoQXoNnSPJ37X1zY5InskJPTpzUs6LRr3TOwInvo=", 8, + CreateTrustedSubtree("sj2WUzCsih+fREf46unoF/8kyGr6tEpL/hlzn9D9994=", 8, 16, &leaf_b_subtree_)); ASSERT_TRUE( - CreateTrustedSubtree("FxyVwc4letskl3WVKXWqlPBvUZsl5NiD5sW7Wr50k+4=", 16, + CreateTrustedSubtree("bGiRKKU8PI5RTxSYgzL2nGvnUE4d/l09y6JaLCbqgy8=", 16, 24, &leaf_c_subtree_)); } @@ -248,6 +278,8 @@ } protected: + UniquePtr<CRYPTO_BUFFER> ca_spki_; + std::string generic_cert_; std::string bitflip_cert_; std::string unused_bit_cert_; @@ -262,19 +294,22 @@ // Subtree for `leaf_c_` which does not overlap with any other subtrees. TrustedSubtree leaf_c_subtree_; - // Relative OID encoding of 32473.1, the log ID used for the MTC Anchor that + // Relative OID encoding of 32473.1, the CA ID used for the MTC Anchor that // issued the test MTCs in this test fixture. - static constexpr uint8_t kAnchorLogId[] = {0x81, 0xfd, 0x59, 0x01}; - static constexpr uint8_t kAnchorLogIdBitflip[] = {0x81, 0xfd, 0x59, 0x00}; + static constexpr uint8_t kCaId[] = {0x81, 0xfd, 0x59, 0x01}; + static constexpr uint8_t kCaBitflipId[] = {0x81, 0xfd, 0x59, 0x00}; + // The test certs for this test all use log number 1. + static constexpr uint16_t kLogNumber = 1; }; TEST_F(VerifyMTCTest, SignaturelessMTC) { // Configure the trust store to trust the MTC anchor with the landmark subtree // for `generic_cert_`. std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore(); - std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_}; - auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId), - MakeSpan(trusted_subtrees)); + std::map<uint16_t, std::vector<TrustedSubtree>> subtrees; + subtrees[kLogNumber] = {generic_cert_subtree_}; + auto mtc_anchor = std::make_shared<MTCAnchor>( + MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees); ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor)); CertificateVerifyOptions opts; @@ -301,9 +336,10 @@ std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore(); trust_store->trust_store->AddCertificate(CertFromString(generic_cert_), CertificateTrust::ForDistrusted()); - std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_}; - auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId), - MakeSpan(trusted_subtrees)); + std::map<uint16_t, std::vector<TrustedSubtree>> subtrees; + subtrees[kLogNumber] = {generic_cert_subtree_}; + auto mtc_anchor = std::make_shared<MTCAnchor>( + MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees); ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor)); CertificateVerifyOptions opts; @@ -315,9 +351,10 @@ TEST_F(VerifyMTCTest, WrongProof) { std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore(); - std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_}; - auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId), - MakeSpan(trusted_subtrees)); + std::map<uint16_t, std::vector<TrustedSubtree>> subtrees; + subtrees[kLogNumber] = {generic_cert_subtree_}; + auto mtc_anchor = std::make_shared<MTCAnchor>( + MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees); ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor)); CertificateVerifyOptions opts; @@ -330,9 +367,10 @@ TEST_F(VerifyMTCTest, UnusedBit) { std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore(); - std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_}; - auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId), - MakeSpan(trusted_subtrees)); + std::map<uint16_t, std::vector<TrustedSubtree>> subtrees; + subtrees[kLogNumber] = {generic_cert_subtree_}; + auto mtc_anchor = std::make_shared<MTCAnchor>( + MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees); ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor)); CertificateVerifyOptions opts; @@ -343,14 +381,16 @@ VerifyError::StatusCode::CERTIFICATE_INVALID_SIGNATURE); } -TEST_F(VerifyMTCTest, WrongLogID) { - // Trust the correct subtree for `generic_cert_` but with the wrong log ID. +TEST_F(VerifyMTCTest, WrongCaId) { + // Trust the correct subtree for `generic_cert_` but with the wrong CA ID. // Verifying the cert should fail because even though the proof evaluates to a // valid hash, the hash is for the wrong issuer. std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore(); - std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_}; - auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogIdBitflip), - MakeSpan(trusted_subtrees)); + std::map<uint16_t, std::vector<TrustedSubtree>> subtrees; + subtrees[kLogNumber] = {generic_cert_subtree_}; + auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kCaBitflipId), + SignatureAlgorithm::kMldsa44, + UpRef(ca_spki_), subtrees); ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor)); CertificateVerifyOptions opts; @@ -364,9 +404,10 @@ // Configure the trust store to trust the MTC anchor with the landmark subtree // for `generic_cert_`. std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore(); - std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_}; - auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId), - MakeSpan(trusted_subtrees)); + std::map<uint16_t, std::vector<TrustedSubtree>> subtrees; + subtrees[kLogNumber] = {generic_cert_subtree_}; + auto mtc_anchor = std::make_shared<MTCAnchor>( + MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees); ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor)); CertificateVerifyOptions opts; @@ -402,10 +443,11 @@ // wrong hash. Configure the trust store to trust the MTC anchor with the // landmark subtree for `generic_cert_`. std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore(); - std::vector<TrustedSubtree> trusted_subtrees = {generic_cert_subtree_}; - trusted_subtrees[0].hash[0] ^= 1; - auto mtc_anchor = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId), - MakeSpan(trusted_subtrees)); + std::map<uint16_t, std::vector<TrustedSubtree>> subtrees; + subtrees[kLogNumber] = {generic_cert_subtree_}; + subtrees[kLogNumber][0].hash[0] ^= 1; + auto mtc_anchor = std::make_shared<MTCAnchor>( + MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees); ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor)); CertificateVerifyOptions opts; @@ -420,13 +462,17 @@ // generic_cert_ and leaf_b_ have proofs to subtree ranges with the same start // but different ends. Check that CertificateVerify only succeeds if the trust // store has the right MTCAnchor. - std::vector<TrustedSubtree> trusted_subtrees_a = {generic_cert_subtree_}; - std::vector<TrustedSubtree> trusted_subtrees_b = {leaf_b_subtree_}; + std::map<uint16_t, std::vector<TrustedSubtree>> trusted_subtrees_a; + trusted_subtrees_a[kLogNumber] = {generic_cert_subtree_}; + std::map<uint16_t, std::vector<TrustedSubtree>> trusted_subtrees_b; + trusted_subtrees_b[kLogNumber] = {leaf_b_subtree_}; - auto mtc_anchor_a = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId), - MakeSpan(trusted_subtrees_a)); - auto mtc_anchor_b = std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId), - MakeSpan(trusted_subtrees_b)); + auto mtc_anchor_a = + std::make_shared<MTCAnchor>(MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, + UpRef(ca_spki_), trusted_subtrees_a); + auto mtc_anchor_b = + std::make_shared<MTCAnchor>(MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, + UpRef(ca_spki_), trusted_subtrees_b); std::unique_ptr<VerifyTrustStore> trust_store_a = EmptyTrustStore(); ASSERT_TRUE(trust_store_a->trust_store->AddMTCTrustAnchor(mtc_anchor_a)); @@ -462,10 +508,11 @@ } TEST_F(VerifyMTCTest, MultipleSubtrees) { - std::vector<TrustedSubtree> subtrees = {generic_cert_subtree_, - leaf_b_subtree_, leaf_c_subtree_}; - auto mtc_anchor = - std::make_shared<MTCAnchor>(MakeSpan(kAnchorLogId), MakeSpan(subtrees)); + std::map<uint16_t, std::vector<TrustedSubtree>> subtrees; + subtrees[kLogNumber] = {generic_cert_subtree_, leaf_b_subtree_, + leaf_c_subtree_}; + auto mtc_anchor = std::make_shared<MTCAnchor>( + MakeSpan(kCaId), SignatureAlgorithm::kMldsa44, UpRef(ca_spki_), subtrees); std::unique_ptr<VerifyTrustStore> trust_store = EmptyTrustStore(); ASSERT_TRUE(trust_store->trust_store->AddMTCTrustAnchor(mtc_anchor));