test_importKey.py 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345
  1. # -*- coding: utf-8 -*-
  2. #
  3. # SelfTest/PublicKey/test_importKey.py: Self-test for importing RSA keys
  4. #
  5. # ===================================================================
  6. # The contents of this file are dedicated to the public domain. To
  7. # the extent that dedication to the public domain is not available,
  8. # everyone is granted a worldwide, perpetual, royalty-free,
  9. # non-exclusive license to exercise all rights associated with the
  10. # contents of this file for any purpose whatsoever.
  11. # No rights are reserved.
  12. #
  13. # THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
  14. # EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
  15. # MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
  16. # NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
  17. # BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
  18. # ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
  19. # CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
  20. # SOFTWARE.
  21. # ===================================================================
  22. from __future__ import nested_scopes
  23. __revision__ = "$Id$"
  24. import unittest
  25. from Crypto.PublicKey import RSA
  26. from Crypto.SelfTest.st_common import *
  27. from Crypto.Util.py3compat import *
  28. from Crypto.Util.number import inverse
  29. from Crypto.Util import asn1
  30. def der2pem(der, text='PUBLIC'):
  31. import binascii
  32. chunks = [ binascii.b2a_base64(der[i:i+48]) for i in range(0, len(der), 48) ]
  33. pem = b('-----BEGIN %s KEY-----\n' % text)
  34. pem += b('').join(chunks)
  35. pem += b('-----END %s KEY-----' % text)
  36. return pem
  37. class ImportKeyTests(unittest.TestCase):
  38. # 512-bit RSA key generated with openssl
  39. rsaKeyPEM = u'''-----BEGIN RSA PRIVATE KEY-----
  40. MIIBOwIBAAJBAL8eJ5AKoIsjURpcEoGubZMxLD7+kT+TLr7UkvEtFrRhDDKMtuII
  41. q19FrL4pUIMymPMSLBn3hJLe30Dw48GQM4UCAwEAAQJACUSDEp8RTe32ftq8IwG8
  42. Wojl5mAd1wFiIOrZ/Uv8b963WJOJiuQcVN29vxU5+My9GPZ7RA3hrDBEAoHUDPrI
  43. OQIhAPIPLz4dphiD9imAkivY31Rc5AfHJiQRA7XixTcjEkojAiEAyh/pJHks/Mlr
  44. +rdPNEpotBjfV4M4BkgGAA/ipcmaAjcCIQCHvhwwKVBLzzTscT2HeUdEeBMoiXXK
  45. JACAr3sJQJGxIQIgarRp+m1WSKV1MciwMaTOnbU7wxFs9DP1pva76lYBzgUCIQC9
  46. n0CnZCJ6IZYqSt0H5N7+Q+2Ro64nuwV/OSQfM6sBwQ==
  47. -----END RSA PRIVATE KEY-----'''
  48. # As above, but this is actually an unencrypted PKCS#8 key
  49. rsaKeyPEM8 = u'''-----BEGIN PRIVATE KEY-----
  50. MIIBVQIBADANBgkqhkiG9w0BAQEFAASCAT8wggE7AgEAAkEAvx4nkAqgiyNRGlwS
  51. ga5tkzEsPv6RP5MuvtSS8S0WtGEMMoy24girX0WsvilQgzKY8xIsGfeEkt7fQPDj
  52. wZAzhQIDAQABAkAJRIMSnxFN7fZ+2rwjAbxaiOXmYB3XAWIg6tn9S/xv3rdYk4mK
  53. 5BxU3b2/FTn4zL0Y9ntEDeGsMEQCgdQM+sg5AiEA8g8vPh2mGIP2KYCSK9jfVFzk
  54. B8cmJBEDteLFNyMSSiMCIQDKH+kkeSz8yWv6t080Smi0GN9XgzgGSAYAD+KlyZoC
  55. NwIhAIe+HDApUEvPNOxxPYd5R0R4EyiJdcokAICvewlAkbEhAiBqtGn6bVZIpXUx
  56. yLAxpM6dtTvDEWz0M/Wm9rvqVgHOBQIhAL2fQKdkInohlipK3Qfk3v5D7ZGjrie7
  57. BX85JB8zqwHB
  58. -----END PRIVATE KEY-----'''
  59. # The same RSA private key as in rsaKeyPEM, but now encrypted
  60. rsaKeyEncryptedPEM=(
  61. # With DES and passphrase 'test'
  62. ('test', u'''-----BEGIN RSA PRIVATE KEY-----
  63. Proc-Type: 4,ENCRYPTED
  64. DEK-Info: DES-CBC,AF8F9A40BD2FA2FC
  65. Ckl9ex1kaVEWhYC2QBmfaF+YPiR4NFkRXA7nj3dcnuFEzBnY5XULupqQpQI3qbfA
  66. u8GYS7+b3toWWiHZivHbAAUBPDIZG9hKDyB9Sq2VMARGsX1yW1zhNvZLIiVJzUHs
  67. C6NxQ1IJWOXzTew/xM2I26kPwHIvadq+/VaT8gLQdjdH0jOiVNaevjWnLgrn1mLP
  68. BCNRMdcexozWtAFNNqSzfW58MJL2OdMi21ED184EFytIc1BlB+FZiGZduwKGuaKy
  69. 9bMbdb/1PSvsSzPsqW7KSSrTw6MgJAFJg6lzIYvR5F4poTVBxwBX3+EyEmShiaNY
  70. IRX3TgQI0IjrVuLmvlZKbGWP18FXj7I7k9tSsNOOzllTTdq3ny5vgM3A+ynfAaxp
  71. dysKznQ6P+IoqML1WxAID4aGRMWka+uArOJ148Rbj9s=
  72. -----END RSA PRIVATE KEY-----''',
  73. "\xAF\x8F\x9A\x40\xBD\x2F\xA2\xFC"),
  74. # With Triple-DES and passphrase 'rocking'
  75. ('rocking', u'''-----BEGIN RSA PRIVATE KEY-----
  76. Proc-Type: 4,ENCRYPTED
  77. DEK-Info: DES-EDE3-CBC,C05D6C07F7FC02F6
  78. w4lwQrXaVoTTJ0GgwY566htTA2/t1YlimhxkxYt9AEeCcidS5M0Wq9ClPiPz9O7F
  79. m6K5QpM1rxo1RUE/ZyI85gglRNPdNwkeTOqit+kum7nN73AToX17+irVmOA4Z9E+
  80. 4O07t91GxGMcjUSIFk0ucwEU4jgxRvYscbvOMvNbuZszGdVNzBTVddnShKCsy9i7
  81. nJbPlXeEKYi/OkRgO4PtfqqWQu5GIEFVUf9ev1QV7AvC+kyWTR1wWYnHX265jU5c
  82. sopxQQtP8XEHIJEdd5/p1oieRcWTCNyY8EkslxDSsrf0OtZp6mZH9N+KU47cgQtt
  83. 9qGORmlWnsIoFFKcDohbtOaWBTKhkj5h6OkLjFjfU/sBeV1c+7wDT3dAy5tawXjG
  84. YSxC7qDQIT/RECvV3+oQKEcmpEujn45wAnkTi12BH30=
  85. -----END RSA PRIVATE KEY-----''',
  86. "\xC0\x5D\x6C\x07\xF7\xFC\x02\xF6"),
  87. )
  88. rsaPublicKeyPEM = u'''-----BEGIN PUBLIC KEY-----
  89. MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAL8eJ5AKoIsjURpcEoGubZMxLD7+kT+T
  90. Lr7UkvEtFrRhDDKMtuIIq19FrL4pUIMymPMSLBn3hJLe30Dw48GQM4UCAwEAAQ==
  91. -----END PUBLIC KEY-----'''
  92. # Obtained using 'ssh-keygen -i -m PKCS8 -f rsaPublicKeyPEM'
  93. rsaPublicKeyOpenSSH = '''ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAAQQC/HieQCqCLI1EaXBKBrm2TMSw+/pE/ky6+1JLxLRa0YQwyjLbiCKtfRay+KVCDMpjzEiwZ94SS3t9A8OPBkDOF comment\n'''
  94. # The private key, in PKCS#1 format encoded with DER
  95. rsaKeyDER = a2b_hex(
  96. '''3082013b020100024100bf1e27900aa08b23511a5c1281ae6d93312c3efe
  97. 913f932ebed492f12d16b4610c328cb6e208ab5f45acbe2950833298f312
  98. 2c19f78492dedf40f0e3c190338502030100010240094483129f114dedf6
  99. 7edabc2301bc5a88e5e6601dd7016220ead9fd4bfc6fdeb75893898ae41c
  100. 54ddbdbf1539f8ccbd18f67b440de1ac30440281d40cfac839022100f20f
  101. 2f3e1da61883f62980922bd8df545ce407c726241103b5e2c53723124a23
  102. 022100ca1fe924792cfcc96bfab74f344a68b418df578338064806000fe2
  103. a5c99a023702210087be1c3029504bcf34ec713d877947447813288975ca
  104. 240080af7b094091b12102206ab469fa6d5648a57531c8b031a4ce9db53b
  105. c3116cf433f5a6f6bbea5601ce05022100bd9f40a764227a21962a4add07
  106. e4defe43ed91a3ae27bb057f39241f33ab01c1
  107. '''.replace(" ",""))
  108. # The private key, in unencrypted PKCS#8 format encoded with DER
  109. rsaKeyDER8 = a2b_hex(
  110. '''30820155020100300d06092a864886f70d01010105000482013f3082013
  111. b020100024100bf1e27900aa08b23511a5c1281ae6d93312c3efe913f932
  112. ebed492f12d16b4610c328cb6e208ab5f45acbe2950833298f3122c19f78
  113. 492dedf40f0e3c190338502030100010240094483129f114dedf67edabc2
  114. 301bc5a88e5e6601dd7016220ead9fd4bfc6fdeb75893898ae41c54ddbdb
  115. f1539f8ccbd18f67b440de1ac30440281d40cfac839022100f20f2f3e1da
  116. 61883f62980922bd8df545ce407c726241103b5e2c53723124a23022100c
  117. a1fe924792cfcc96bfab74f344a68b418df578338064806000fe2a5c99a0
  118. 23702210087be1c3029504bcf34ec713d877947447813288975ca240080a
  119. f7b094091b12102206ab469fa6d5648a57531c8b031a4ce9db53bc3116cf
  120. 433f5a6f6bbea5601ce05022100bd9f40a764227a21962a4add07e4defe4
  121. 3ed91a3ae27bb057f39241f33ab01c1
  122. '''.replace(" ",""))
  123. rsaPublicKeyDER = a2b_hex(
  124. '''305c300d06092a864886f70d0101010500034b003048024100bf1e27900a
  125. a08b23511a5c1281ae6d93312c3efe913f932ebed492f12d16b4610c328c
  126. b6e208ab5f45acbe2950833298f3122c19f78492dedf40f0e3c190338502
  127. 03010001
  128. '''.replace(" ",""))
  129. n = long('BF 1E 27 90 0A A0 8B 23 51 1A 5C 12 81 AE 6D 93 31 2C 3E FE 91 3F 93 2E BE D4 92 F1 2D 16 B4 61 0C 32 8C B6 E2 08 AB 5F 45 AC BE 29 50 83 32 98 F3 12 2C 19 F7 84 92 DE DF 40 F0 E3 C1 90 33 85'.replace(" ",""),16)
  130. e = 65537L
  131. d = long('09 44 83 12 9F 11 4D ED F6 7E DA BC 23 01 BC 5A 88 E5 E6 60 1D D7 01 62 20 EA D9 FD 4B FC 6F DE B7 58 93 89 8A E4 1C 54 DD BD BF 15 39 F8 CC BD 18 F6 7B 44 0D E1 AC 30 44 02 81 D4 0C FA C8 39'.replace(" ",""),16)
  132. p = long('00 F2 0F 2F 3E 1D A6 18 83 F6 29 80 92 2B D8 DF 54 5C E4 07 C7 26 24 11 03 B5 E2 C5 37 23 12 4A 23'.replace(" ",""),16)
  133. q = long('00 CA 1F E9 24 79 2C FC C9 6B FA B7 4F 34 4A 68 B4 18 DF 57 83 38 06 48 06 00 0F E2 A5 C9 9A 02 37'.replace(" ",""),16)
  134. # This is q^{-1} mod p). fastmath and slowmath use pInv (p^{-1}
  135. # mod q) instead!
  136. qInv = long('00 BD 9F 40 A7 64 22 7A 21 96 2A 4A DD 07 E4 DE FE 43 ED 91 A3 AE 27 BB 05 7F 39 24 1F 33 AB 01 C1'.replace(" ",""),16)
  137. pInv = inverse(p,q)
  138. def testImportKey1(self):
  139. """Verify import of RSAPrivateKey DER SEQUENCE"""
  140. key = self.rsa.importKey(self.rsaKeyDER)
  141. self.failUnless(key.has_private())
  142. self.assertEqual(key.n, self.n)
  143. self.assertEqual(key.e, self.e)
  144. self.assertEqual(key.d, self.d)
  145. self.assertEqual(key.p, self.p)
  146. self.assertEqual(key.q, self.q)
  147. def testImportKey2(self):
  148. """Verify import of SubjectPublicKeyInfo DER SEQUENCE"""
  149. key = self.rsa.importKey(self.rsaPublicKeyDER)
  150. self.failIf(key.has_private())
  151. self.assertEqual(key.n, self.n)
  152. self.assertEqual(key.e, self.e)
  153. def testImportKey3unicode(self):
  154. """Verify import of RSAPrivateKey DER SEQUENCE, encoded with PEM as unicode"""
  155. key = RSA.importKey(self.rsaKeyPEM)
  156. self.assertEqual(key.has_private(),True) # assert_
  157. self.assertEqual(key.n, self.n)
  158. self.assertEqual(key.e, self.e)
  159. self.assertEqual(key.d, self.d)
  160. self.assertEqual(key.p, self.p)
  161. self.assertEqual(key.q, self.q)
  162. def testImportKey3bytes(self):
  163. """Verify import of RSAPrivateKey DER SEQUENCE, encoded with PEM as byte string"""
  164. key = RSA.importKey(b(self.rsaKeyPEM))
  165. self.assertEqual(key.has_private(),True) # assert_
  166. self.assertEqual(key.n, self.n)
  167. self.assertEqual(key.e, self.e)
  168. self.assertEqual(key.d, self.d)
  169. self.assertEqual(key.p, self.p)
  170. self.assertEqual(key.q, self.q)
  171. def testImportKey4unicode(self):
  172. """Verify import of RSAPrivateKey DER SEQUENCE, encoded with PEM as unicode"""
  173. key = RSA.importKey(self.rsaPublicKeyPEM)
  174. self.assertEqual(key.has_private(),False) # failIf
  175. self.assertEqual(key.n, self.n)
  176. self.assertEqual(key.e, self.e)
  177. def testImportKey4bytes(self):
  178. """Verify import of SubjectPublicKeyInfo DER SEQUENCE, encoded with PEM as byte string"""
  179. key = RSA.importKey(b(self.rsaPublicKeyPEM))
  180. self.assertEqual(key.has_private(),False) # failIf
  181. self.assertEqual(key.n, self.n)
  182. self.assertEqual(key.e, self.e)
  183. def testImportKey5(self):
  184. """Verifies that the imported key is still a valid RSA pair"""
  185. key = RSA.importKey(self.rsaKeyPEM)
  186. idem = key.encrypt(key.decrypt(b("Test")),0)
  187. self.assertEqual(idem[0],b("Test"))
  188. def testImportKey6(self):
  189. """Verifies that the imported key is still a valid RSA pair"""
  190. key = RSA.importKey(self.rsaKeyDER)
  191. idem = key.encrypt(key.decrypt(b("Test")),0)
  192. self.assertEqual(idem[0],b("Test"))
  193. def testImportKey7(self):
  194. """Verify import of OpenSSH public key"""
  195. key = self.rsa.importKey(self.rsaPublicKeyOpenSSH)
  196. self.assertEqual(key.n, self.n)
  197. self.assertEqual(key.e, self.e)
  198. def testImportKey8(self):
  199. """Verify import of encrypted PrivateKeyInfo DER SEQUENCE"""
  200. for t in self.rsaKeyEncryptedPEM:
  201. key = self.rsa.importKey(t[1], t[0])
  202. self.failUnless(key.has_private())
  203. self.assertEqual(key.n, self.n)
  204. self.assertEqual(key.e, self.e)
  205. self.assertEqual(key.d, self.d)
  206. self.assertEqual(key.p, self.p)
  207. self.assertEqual(key.q, self.q)
  208. def testImportKey9(self):
  209. """Verify import of unencrypted PrivateKeyInfo DER SEQUENCE"""
  210. key = self.rsa.importKey(self.rsaKeyDER8)
  211. self.failUnless(key.has_private())
  212. self.assertEqual(key.n, self.n)
  213. self.assertEqual(key.e, self.e)
  214. self.assertEqual(key.d, self.d)
  215. self.assertEqual(key.p, self.p)
  216. self.assertEqual(key.q, self.q)
  217. def testImportKey10(self):
  218. """Verify import of unencrypted PrivateKeyInfo DER SEQUENCE, encoded with PEM"""
  219. key = self.rsa.importKey(self.rsaKeyPEM8)
  220. self.failUnless(key.has_private())
  221. self.assertEqual(key.n, self.n)
  222. self.assertEqual(key.e, self.e)
  223. self.assertEqual(key.d, self.d)
  224. self.assertEqual(key.p, self.p)
  225. self.assertEqual(key.q, self.q)
  226. def testImportKey11(self):
  227. """Verify import of RSAPublicKey DER SEQUENCE"""
  228. der = asn1.DerSequence([17, 3]).encode()
  229. key = self.rsa.importKey(der)
  230. self.assertEqual(key.n, 17)
  231. self.assertEqual(key.e, 3)
  232. def testImportKey12(self):
  233. """Verify import of RSAPublicKey DER SEQUENCE, encoded with PEM"""
  234. der = asn1.DerSequence([17, 3]).encode()
  235. pem = der2pem(der)
  236. key = self.rsa.importKey(pem)
  237. self.assertEqual(key.n, 17)
  238. self.assertEqual(key.e, 3)
  239. ###
  240. def testExportKey1(self):
  241. key = self.rsa.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  242. derKey = key.exportKey("DER")
  243. self.assertEqual(derKey, self.rsaKeyDER)
  244. def testExportKey2(self):
  245. key = self.rsa.construct([self.n, self.e])
  246. derKey = key.exportKey("DER")
  247. self.assertEqual(derKey, self.rsaPublicKeyDER)
  248. def testExportKey3(self):
  249. key = self.rsa.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  250. pemKey = key.exportKey("PEM")
  251. self.assertEqual(pemKey, b(self.rsaKeyPEM))
  252. def testExportKey4(self):
  253. key = self.rsa.construct([self.n, self.e])
  254. pemKey = key.exportKey("PEM")
  255. self.assertEqual(pemKey, b(self.rsaPublicKeyPEM))
  256. def testExportKey5(self):
  257. key = self.rsa.construct([self.n, self.e])
  258. openssh_1 = key.exportKey("OpenSSH").split()
  259. openssh_2 = self.rsaPublicKeyOpenSSH.split()
  260. self.assertEqual(openssh_1[0], openssh_2[0])
  261. self.assertEqual(openssh_1[1], openssh_2[1])
  262. def testExportKey4(self):
  263. key = self.rsa.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  264. # Tuple with index #1 is encrypted with 3DES
  265. t = map(b,self.rsaKeyEncryptedPEM[1])
  266. # Force the salt being used when exporting
  267. key._randfunc = lambda N: (t[2]*divmod(N+len(t[2]),len(t[2]))[0])[:N]
  268. pemKey = key.exportKey("PEM", t[0])
  269. self.assertEqual(pemKey, t[1])
  270. def testExportKey5(self):
  271. key = self.rsa.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  272. derKey = key.exportKey("DER", pkcs=8)
  273. self.assertEqual(derKey, self.rsaKeyDER8)
  274. def testExportKey6(self):
  275. key = self.rsa.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  276. pemKey = key.exportKey("PEM", pkcs=8)
  277. self.assertEqual(pemKey, b(self.rsaKeyPEM8))
  278. class ImportKeyTestsSlow(ImportKeyTests):
  279. def setUp(self):
  280. self.rsa = RSA.RSAImplementation(use_fast_math=0)
  281. class ImportKeyTestsFast(ImportKeyTests):
  282. def setUp(self):
  283. self.rsa = RSA.RSAImplementation(use_fast_math=1)
  284. if __name__ == '__main__':
  285. unittest.main()
  286. def get_tests(config={}):
  287. tests = []
  288. try:
  289. from Crypto.PublicKey import _fastmath
  290. tests += list_test_cases(ImportKeyTestsFast)
  291. except ImportError:
  292. pass
  293. tests += list_test_cases(ImportKeyTestsSlow)
  294. return tests
  295. if __name__ == '__main__':
  296. suite = lambda: unittest.TestSuite(get_tests())
  297. unittest.main(defaultTest='suite')
  298. # vim:set ts=4 sw=4 sts=4 expandtab: