test_import_RSA.py 22 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505
  1. # -*- coding: utf-8 -*-
  2. #
  3. # SelfTest/PublicKey/test_importKey.py: Self-test for importing RSA keys
  4. #
  5. # ===================================================================
  6. # The contents of this file are dedicated to the public domain. To
  7. # the extent that dedication to the public domain is not available,
  8. # everyone is granted a worldwide, perpetual, royalty-free,
  9. # non-exclusive license to exercise all rights associated with the
  10. # contents of this file for any purpose whatsoever.
  11. # No rights are reserved.
  12. #
  13. # THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
  14. # EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
  15. # MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND
  16. # NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS
  17. # BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN
  18. # ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
  19. # CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
  20. # SOFTWARE.
  21. # ===================================================================
  22. import unittest
  23. import re
  24. from Cryptodome.PublicKey import RSA
  25. from Cryptodome.SelfTest.st_common import *
  26. from Cryptodome.Util.py3compat import *
  27. from Cryptodome.Util.number import inverse
  28. from Cryptodome.Util import asn1
  29. def der2pem(der, text='PUBLIC'):
  30. import binascii
  31. chunks = [ binascii.b2a_base64(der[i:i+48]) for i in range(0, len(der), 48) ]
  32. pem = b('-----BEGIN %s KEY-----\n' % text)
  33. pem += b('').join(chunks)
  34. pem += b('-----END %s KEY-----' % text)
  35. return pem
  36. class ImportKeyTests(unittest.TestCase):
  37. # 512-bit RSA key generated with openssl
  38. rsaKeyPEM = u'''-----BEGIN RSA PRIVATE KEY-----
  39. MIIBOwIBAAJBAL8eJ5AKoIsjURpcEoGubZMxLD7+kT+TLr7UkvEtFrRhDDKMtuII
  40. q19FrL4pUIMymPMSLBn3hJLe30Dw48GQM4UCAwEAAQJACUSDEp8RTe32ftq8IwG8
  41. Wojl5mAd1wFiIOrZ/Uv8b963WJOJiuQcVN29vxU5+My9GPZ7RA3hrDBEAoHUDPrI
  42. OQIhAPIPLz4dphiD9imAkivY31Rc5AfHJiQRA7XixTcjEkojAiEAyh/pJHks/Mlr
  43. +rdPNEpotBjfV4M4BkgGAA/ipcmaAjcCIQCHvhwwKVBLzzTscT2HeUdEeBMoiXXK
  44. JACAr3sJQJGxIQIgarRp+m1WSKV1MciwMaTOnbU7wxFs9DP1pva76lYBzgUCIQC9
  45. n0CnZCJ6IZYqSt0H5N7+Q+2Ro64nuwV/OSQfM6sBwQ==
  46. -----END RSA PRIVATE KEY-----'''
  47. # As above, but this is actually an unencrypted PKCS#8 key
  48. rsaKeyPEM8 = u'''-----BEGIN PRIVATE KEY-----
  49. MIIBVQIBADANBgkqhkiG9w0BAQEFAASCAT8wggE7AgEAAkEAvx4nkAqgiyNRGlwS
  50. ga5tkzEsPv6RP5MuvtSS8S0WtGEMMoy24girX0WsvilQgzKY8xIsGfeEkt7fQPDj
  51. wZAzhQIDAQABAkAJRIMSnxFN7fZ+2rwjAbxaiOXmYB3XAWIg6tn9S/xv3rdYk4mK
  52. 5BxU3b2/FTn4zL0Y9ntEDeGsMEQCgdQM+sg5AiEA8g8vPh2mGIP2KYCSK9jfVFzk
  53. B8cmJBEDteLFNyMSSiMCIQDKH+kkeSz8yWv6t080Smi0GN9XgzgGSAYAD+KlyZoC
  54. NwIhAIe+HDApUEvPNOxxPYd5R0R4EyiJdcokAICvewlAkbEhAiBqtGn6bVZIpXUx
  55. yLAxpM6dtTvDEWz0M/Wm9rvqVgHOBQIhAL2fQKdkInohlipK3Qfk3v5D7ZGjrie7
  56. BX85JB8zqwHB
  57. -----END PRIVATE KEY-----'''
  58. # The same RSA private key as in rsaKeyPEM, but now encrypted
  59. rsaKeyEncryptedPEM=(
  60. # PEM encryption
  61. # With DES and passphrase 'test'
  62. ('test', u'''-----BEGIN RSA PRIVATE KEY-----
  63. Proc-Type: 4,ENCRYPTED
  64. DEK-Info: DES-CBC,AF8F9A40BD2FA2FC
  65. Ckl9ex1kaVEWhYC2QBmfaF+YPiR4NFkRXA7nj3dcnuFEzBnY5XULupqQpQI3qbfA
  66. u8GYS7+b3toWWiHZivHbAAUBPDIZG9hKDyB9Sq2VMARGsX1yW1zhNvZLIiVJzUHs
  67. C6NxQ1IJWOXzTew/xM2I26kPwHIvadq+/VaT8gLQdjdH0jOiVNaevjWnLgrn1mLP
  68. BCNRMdcexozWtAFNNqSzfW58MJL2OdMi21ED184EFytIc1BlB+FZiGZduwKGuaKy
  69. 9bMbdb/1PSvsSzPsqW7KSSrTw6MgJAFJg6lzIYvR5F4poTVBxwBX3+EyEmShiaNY
  70. IRX3TgQI0IjrVuLmvlZKbGWP18FXj7I7k9tSsNOOzllTTdq3ny5vgM3A+ynfAaxp
  71. dysKznQ6P+IoqML1WxAID4aGRMWka+uArOJ148Rbj9s=
  72. -----END RSA PRIVATE KEY-----'''),
  73. # PKCS8 encryption
  74. ('winter', u'''-----BEGIN ENCRYPTED PRIVATE KEY-----
  75. MIIBpjBABgkqhkiG9w0BBQ0wMzAbBgkqhkiG9w0BBQwwDgQIeZIsbW3O+JcCAggA
  76. MBQGCCqGSIb3DQMHBAgSM2p0D8FilgSCAWBhFyP2tiGKVpGj3mO8qIBzinU60ApR
  77. 3unvP+N6j7LVgnV2lFGaXbJ6a1PbQXe+2D6DUyBLo8EMXrKKVLqOMGkFMHc0UaV6
  78. R6MmrsRDrbOqdpTuVRW+NVd5J9kQQh4xnfU/QrcPPt7vpJvSf4GzG0n666Ki50OV
  79. M/feuVlIiyGXY6UWdVDpcOV72cq02eNUs/1JWdh2uEBvA9fCL0c07RnMrdT+CbJQ
  80. NjJ7f8ULtp7xvR9O3Al/yJ4Wv3i4VxF1f3MCXzhlUD4I0ONlr0kJWgeQ80q/cWhw
  81. ntvgJwnCn2XR1h6LA8Wp+0ghDTsL2NhJpWd78zClGhyU4r3hqu1XDjoXa7YCXCix
  82. jCV15+ViDJzlNCwg+W6lRg18sSLkCT7alviIE0U5tHc6UPbbHwT5QqAxAABaP+nZ
  83. CGqJGyiwBzrKebjgSm/KRd4C91XqcsysyH2kKPfT51MLAoD4xelOURBP
  84. -----END ENCRYPTED PRIVATE KEY-----'''
  85. ),
  86. )
  87. rsaPublicKeyPEM = u'''-----BEGIN PUBLIC KEY-----
  88. MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBAL8eJ5AKoIsjURpcEoGubZMxLD7+kT+T
  89. Lr7UkvEtFrRhDDKMtuIIq19FrL4pUIMymPMSLBn3hJLe30Dw48GQM4UCAwEAAQ==
  90. -----END PUBLIC KEY-----'''
  91. # Obtained using 'ssh-keygen -i -m PKCS8 -f rsaPublicKeyPEM'
  92. rsaPublicKeyOpenSSH = b('''ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAAQQC/HieQCqCLI1EaXBKBrm2TMSw+/pE/ky6+1JLxLRa0YQwyjLbiCKtfRay+KVCDMpjzEiwZ94SS3t9A8OPBkDOF comment\n''')
  93. # The private key, in PKCS#1 format encoded with DER
  94. rsaKeyDER = a2b_hex(
  95. '''3082013b020100024100bf1e27900aa08b23511a5c1281ae6d93312c3efe
  96. 913f932ebed492f12d16b4610c328cb6e208ab5f45acbe2950833298f312
  97. 2c19f78492dedf40f0e3c190338502030100010240094483129f114dedf6
  98. 7edabc2301bc5a88e5e6601dd7016220ead9fd4bfc6fdeb75893898ae41c
  99. 54ddbdbf1539f8ccbd18f67b440de1ac30440281d40cfac839022100f20f
  100. 2f3e1da61883f62980922bd8df545ce407c726241103b5e2c53723124a23
  101. 022100ca1fe924792cfcc96bfab74f344a68b418df578338064806000fe2
  102. a5c99a023702210087be1c3029504bcf34ec713d877947447813288975ca
  103. 240080af7b094091b12102206ab469fa6d5648a57531c8b031a4ce9db53b
  104. c3116cf433f5a6f6bbea5601ce05022100bd9f40a764227a21962a4add07
  105. e4defe43ed91a3ae27bb057f39241f33ab01c1
  106. '''.replace(" ",""))
  107. # The private key, in unencrypted PKCS#8 format encoded with DER
  108. rsaKeyDER8 = a2b_hex(
  109. '''30820155020100300d06092a864886f70d01010105000482013f3082013
  110. b020100024100bf1e27900aa08b23511a5c1281ae6d93312c3efe913f932
  111. ebed492f12d16b4610c328cb6e208ab5f45acbe2950833298f3122c19f78
  112. 492dedf40f0e3c190338502030100010240094483129f114dedf67edabc2
  113. 301bc5a88e5e6601dd7016220ead9fd4bfc6fdeb75893898ae41c54ddbdb
  114. f1539f8ccbd18f67b440de1ac30440281d40cfac839022100f20f2f3e1da
  115. 61883f62980922bd8df545ce407c726241103b5e2c53723124a23022100c
  116. a1fe924792cfcc96bfab74f344a68b418df578338064806000fe2a5c99a0
  117. 23702210087be1c3029504bcf34ec713d877947447813288975ca240080a
  118. f7b094091b12102206ab469fa6d5648a57531c8b031a4ce9db53bc3116cf
  119. 433f5a6f6bbea5601ce05022100bd9f40a764227a21962a4add07e4defe4
  120. 3ed91a3ae27bb057f39241f33ab01c1
  121. '''.replace(" ",""))
  122. rsaPublicKeyDER = a2b_hex(
  123. '''305c300d06092a864886f70d0101010500034b003048024100bf1e27900a
  124. a08b23511a5c1281ae6d93312c3efe913f932ebed492f12d16b4610c328c
  125. b6e208ab5f45acbe2950833298f3122c19f78492dedf40f0e3c190338502
  126. 03010001
  127. '''.replace(" ",""))
  128. n = int('BF 1E 27 90 0A A0 8B 23 51 1A 5C 12 81 AE 6D 93 31 2C 3E FE 91 3F 93 2E BE D4 92 F1 2D 16 B4 61 0C 32 8C B6 E2 08 AB 5F 45 AC BE 29 50 83 32 98 F3 12 2C 19 F7 84 92 DE DF 40 F0 E3 C1 90 33 85'.replace(" ",""),16)
  129. e = 65537
  130. d = int('09 44 83 12 9F 11 4D ED F6 7E DA BC 23 01 BC 5A 88 E5 E6 60 1D D7 01 62 20 EA D9 FD 4B FC 6F DE B7 58 93 89 8A E4 1C 54 DD BD BF 15 39 F8 CC BD 18 F6 7B 44 0D E1 AC 30 44 02 81 D4 0C FA C8 39'.replace(" ",""),16)
  131. p = int('00 F2 0F 2F 3E 1D A6 18 83 F6 29 80 92 2B D8 DF 54 5C E4 07 C7 26 24 11 03 B5 E2 C5 37 23 12 4A 23'.replace(" ",""),16)
  132. q = int('00 CA 1F E9 24 79 2C FC C9 6B FA B7 4F 34 4A 68 B4 18 DF 57 83 38 06 48 06 00 0F E2 A5 C9 9A 02 37'.replace(" ",""),16)
  133. # This is q^{-1} mod p). fastmath and slowmath use pInv (p^{-1}
  134. # mod q) instead!
  135. qInv = int('00 BD 9F 40 A7 64 22 7A 21 96 2A 4A DD 07 E4 DE FE 43 ED 91 A3 AE 27 BB 05 7F 39 24 1F 33 AB 01 C1'.replace(" ",""),16)
  136. pInv = inverse(p,q)
  137. def testImportKey1(self):
  138. """Verify import of RSAPrivateKey DER SEQUENCE"""
  139. key = RSA.importKey(self.rsaKeyDER)
  140. self.failUnless(key.has_private())
  141. self.assertEqual(key.n, self.n)
  142. self.assertEqual(key.e, self.e)
  143. self.assertEqual(key.d, self.d)
  144. self.assertEqual(key.p, self.p)
  145. self.assertEqual(key.q, self.q)
  146. def testImportKey2(self):
  147. """Verify import of SubjectPublicKeyInfo DER SEQUENCE"""
  148. key = RSA.importKey(self.rsaPublicKeyDER)
  149. self.failIf(key.has_private())
  150. self.assertEqual(key.n, self.n)
  151. self.assertEqual(key.e, self.e)
  152. def testImportKey3unicode(self):
  153. """Verify import of RSAPrivateKey DER SEQUENCE, encoded with PEM as unicode"""
  154. key = RSA.importKey(self.rsaKeyPEM)
  155. self.assertEqual(key.has_private(),True) # assert_
  156. self.assertEqual(key.n, self.n)
  157. self.assertEqual(key.e, self.e)
  158. self.assertEqual(key.d, self.d)
  159. self.assertEqual(key.p, self.p)
  160. self.assertEqual(key.q, self.q)
  161. def testImportKey3bytes(self):
  162. """Verify import of RSAPrivateKey DER SEQUENCE, encoded with PEM as byte string"""
  163. key = RSA.importKey(b(self.rsaKeyPEM))
  164. self.assertEqual(key.has_private(),True) # assert_
  165. self.assertEqual(key.n, self.n)
  166. self.assertEqual(key.e, self.e)
  167. self.assertEqual(key.d, self.d)
  168. self.assertEqual(key.p, self.p)
  169. self.assertEqual(key.q, self.q)
  170. def testImportKey4unicode(self):
  171. """Verify import of RSAPrivateKey DER SEQUENCE, encoded with PEM as unicode"""
  172. key = RSA.importKey(self.rsaPublicKeyPEM)
  173. self.assertEqual(key.has_private(),False) # failIf
  174. self.assertEqual(key.n, self.n)
  175. self.assertEqual(key.e, self.e)
  176. def testImportKey4bytes(self):
  177. """Verify import of SubjectPublicKeyInfo DER SEQUENCE, encoded with PEM as byte string"""
  178. key = RSA.importKey(b(self.rsaPublicKeyPEM))
  179. self.assertEqual(key.has_private(),False) # failIf
  180. self.assertEqual(key.n, self.n)
  181. self.assertEqual(key.e, self.e)
  182. def testImportKey5(self):
  183. """Verifies that the imported key is still a valid RSA pair"""
  184. key = RSA.importKey(self.rsaKeyPEM)
  185. idem = key._encrypt(key._decrypt(89))
  186. self.assertEqual(idem, 89)
  187. def testImportKey6(self):
  188. """Verifies that the imported key is still a valid RSA pair"""
  189. key = RSA.importKey(self.rsaKeyDER)
  190. idem = key._encrypt(key._decrypt(65))
  191. self.assertEqual(idem, 65)
  192. def testImportKey7(self):
  193. """Verify import of OpenSSH public key"""
  194. key = RSA.importKey(self.rsaPublicKeyOpenSSH)
  195. self.assertEqual(key.n, self.n)
  196. self.assertEqual(key.e, self.e)
  197. def testImportKey8(self):
  198. """Verify import of encrypted PrivateKeyInfo DER SEQUENCE"""
  199. for t in self.rsaKeyEncryptedPEM:
  200. key = RSA.importKey(t[1], t[0])
  201. self.failUnless(key.has_private())
  202. self.assertEqual(key.n, self.n)
  203. self.assertEqual(key.e, self.e)
  204. self.assertEqual(key.d, self.d)
  205. self.assertEqual(key.p, self.p)
  206. self.assertEqual(key.q, self.q)
  207. def testImportKey9(self):
  208. """Verify import of unencrypted PrivateKeyInfo DER SEQUENCE"""
  209. key = RSA.importKey(self.rsaKeyDER8)
  210. self.failUnless(key.has_private())
  211. self.assertEqual(key.n, self.n)
  212. self.assertEqual(key.e, self.e)
  213. self.assertEqual(key.d, self.d)
  214. self.assertEqual(key.p, self.p)
  215. self.assertEqual(key.q, self.q)
  216. def testImportKey10(self):
  217. """Verify import of unencrypted PrivateKeyInfo DER SEQUENCE, encoded with PEM"""
  218. key = RSA.importKey(self.rsaKeyPEM8)
  219. self.failUnless(key.has_private())
  220. self.assertEqual(key.n, self.n)
  221. self.assertEqual(key.e, self.e)
  222. self.assertEqual(key.d, self.d)
  223. self.assertEqual(key.p, self.p)
  224. self.assertEqual(key.q, self.q)
  225. def testImportKey11(self):
  226. """Verify import of RSAPublicKey DER SEQUENCE"""
  227. der = asn1.DerSequence([17, 3]).encode()
  228. key = RSA.importKey(der)
  229. self.assertEqual(key.n, 17)
  230. self.assertEqual(key.e, 3)
  231. def testImportKey12(self):
  232. """Verify import of RSAPublicKey DER SEQUENCE, encoded with PEM"""
  233. der = asn1.DerSequence([17, 3]).encode()
  234. pem = der2pem(der)
  235. key = RSA.importKey(pem)
  236. self.assertEqual(key.n, 17)
  237. self.assertEqual(key.e, 3)
  238. def test_import_key_windows_cr_lf(self):
  239. pem_cr_lf = "\r\n".join(self.rsaKeyPEM.splitlines())
  240. key = RSA.importKey(pem_cr_lf)
  241. self.assertEqual(key.n, self.n)
  242. self.assertEqual(key.e, self.e)
  243. self.assertEqual(key.d, self.d)
  244. self.assertEqual(key.p, self.p)
  245. self.assertEqual(key.q, self.q)
  246. ###
  247. def testExportKey1(self):
  248. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  249. derKey = key.export_key("DER")
  250. self.assertEqual(derKey, self.rsaKeyDER)
  251. def testExportKey2(self):
  252. key = RSA.construct([self.n, self.e])
  253. derKey = key.export_key("DER")
  254. self.assertEqual(derKey, self.rsaPublicKeyDER)
  255. def testExportKey3(self):
  256. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  257. pemKey = key.export_key("PEM")
  258. self.assertEqual(pemKey, b(self.rsaKeyPEM))
  259. def testExportKey4(self):
  260. key = RSA.construct([self.n, self.e])
  261. pemKey = key.export_key("PEM")
  262. self.assertEqual(pemKey, b(self.rsaPublicKeyPEM))
  263. def testExportKey5(self):
  264. key = RSA.construct([self.n, self.e])
  265. openssh_1 = key.export_key("OpenSSH").split()
  266. openssh_2 = self.rsaPublicKeyOpenSSH.split()
  267. self.assertEqual(openssh_1[0], openssh_2[0])
  268. self.assertEqual(openssh_1[1], openssh_2[1])
  269. def testExportKey7(self):
  270. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  271. derKey = key.export_key("DER", pkcs=8)
  272. self.assertEqual(derKey, self.rsaKeyDER8)
  273. def testExportKey8(self):
  274. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  275. pemKey = key.export_key("PEM", pkcs=8)
  276. self.assertEqual(pemKey, b(self.rsaKeyPEM8))
  277. def testExportKey9(self):
  278. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  279. self.assertRaises(ValueError, key.export_key, "invalid-format")
  280. def testExportKey10(self):
  281. # Export and re-import the encrypted key. It must match.
  282. # PEM envelope, PKCS#1, old PEM encryption
  283. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  284. outkey = key.export_key('PEM', 'test')
  285. self.failUnless(tostr(outkey).find('4,ENCRYPTED')!=-1)
  286. self.failUnless(tostr(outkey).find('BEGIN RSA PRIVATE KEY')!=-1)
  287. inkey = RSA.importKey(outkey, 'test')
  288. self.assertEqual(key.n, inkey.n)
  289. self.assertEqual(key.e, inkey.e)
  290. self.assertEqual(key.d, inkey.d)
  291. def testExportKey11(self):
  292. # Export and re-import the encrypted key. It must match.
  293. # PEM envelope, PKCS#1, old PEM encryption
  294. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  295. outkey = key.export_key('PEM', 'test', pkcs=1)
  296. self.failUnless(tostr(outkey).find('4,ENCRYPTED')!=-1)
  297. self.failUnless(tostr(outkey).find('BEGIN RSA PRIVATE KEY')!=-1)
  298. inkey = RSA.importKey(outkey, 'test')
  299. self.assertEqual(key.n, inkey.n)
  300. self.assertEqual(key.e, inkey.e)
  301. self.assertEqual(key.d, inkey.d)
  302. def testExportKey12(self):
  303. # Export and re-import the encrypted key. It must match.
  304. # PEM envelope, PKCS#8, old PEM encryption
  305. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  306. outkey = key.export_key('PEM', 'test', pkcs=8)
  307. self.failUnless(tostr(outkey).find('4,ENCRYPTED')!=-1)
  308. self.failUnless(tostr(outkey).find('BEGIN PRIVATE KEY')!=-1)
  309. inkey = RSA.importKey(outkey, 'test')
  310. self.assertEqual(key.n, inkey.n)
  311. self.assertEqual(key.e, inkey.e)
  312. self.assertEqual(key.d, inkey.d)
  313. def testExportKey13(self):
  314. # Export and re-import the encrypted key. It must match.
  315. # PEM envelope, PKCS#8, PKCS#8 encryption
  316. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  317. outkey = key.export_key('PEM', 'test', pkcs=8,
  318. protection='PBKDF2WithHMAC-SHA1AndDES-EDE3-CBC')
  319. self.failUnless(tostr(outkey).find('4,ENCRYPTED')==-1)
  320. self.failUnless(tostr(outkey).find('BEGIN ENCRYPTED PRIVATE KEY')!=-1)
  321. inkey = RSA.importKey(outkey, 'test')
  322. self.assertEqual(key.n, inkey.n)
  323. self.assertEqual(key.e, inkey.e)
  324. self.assertEqual(key.d, inkey.d)
  325. def testExportKey14(self):
  326. # Export and re-import the encrypted key. It must match.
  327. # DER envelope, PKCS#8, PKCS#8 encryption
  328. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  329. outkey = key.export_key('DER', 'test', pkcs=8)
  330. inkey = RSA.importKey(outkey, 'test')
  331. self.assertEqual(key.n, inkey.n)
  332. self.assertEqual(key.e, inkey.e)
  333. self.assertEqual(key.d, inkey.d)
  334. def testExportKey15(self):
  335. # Verify that that error an condition is detected when trying to
  336. # use a password with DER encoding and PKCS#1.
  337. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  338. self.assertRaises(ValueError, key.export_key, 'DER', 'test', 1)
  339. def test_import_key(self):
  340. """Verify that import_key is an alias to importKey"""
  341. key = RSA.import_key(self.rsaPublicKeyDER)
  342. self.failIf(key.has_private())
  343. self.assertEqual(key.n, self.n)
  344. self.assertEqual(key.e, self.e)
  345. def test_exportKey(self):
  346. key = RSA.construct([self.n, self.e, self.d, self.p, self.q, self.pInv])
  347. self.assertEqual(key.export_key(), key.exportKey())
  348. class ImportKeyFromX509Cert(unittest.TestCase):
  349. def test_x509v1(self):
  350. # Sample V1 certificate with a 1024 bit RSA key
  351. x509_v1_cert = """
  352. -----BEGIN CERTIFICATE-----
  353. MIICOjCCAaMCAQEwDQYJKoZIhvcNAQEEBQAwfjENMAsGA1UEChMEQWNtZTELMAkG
  354. A1UECxMCUkQxHDAaBgkqhkiG9w0BCQEWDXNwYW1AYWNtZS5vcmcxEzARBgNVBAcT
  355. Ck1ldHJvcG9saXMxETAPBgNVBAgTCE5ldyBZb3JrMQswCQYDVQQGEwJVUzENMAsG
  356. A1UEAxMEdGVzdDAeFw0xNDA3MTExOTU3MjRaFw0xNzA0MDYxOTU3MjRaME0xCzAJ
  357. BgNVBAYTAlVTMREwDwYDVQQIEwhOZXcgWW9yazENMAsGA1UEChMEQWNtZTELMAkG
  358. A1UECxMCUkQxDzANBgNVBAMTBmxhdHZpYTCBnzANBgkqhkiG9w0BAQEFAAOBjQAw
  359. gYkCgYEAyG+kytdRj3TFbRmHDYp3TXugVQ81chew0qeOxZWOz80IjtWpgdOaCvKW
  360. NCuc8wUR9BWrEQW+39SaRMLiQfQtyFSQZijc3nsEBu/Lo4uWZ0W/FHDRVSvkJA/V
  361. Ex5NL5ikI+wbUeCV5KajGNDalZ8F1pk32+CBs8h1xNx5DyxuEHUCAwEAATANBgkq
  362. hkiG9w0BAQQFAAOBgQCVQF9Y//Q4Psy+umEM38pIlbZ2hxC5xNz/MbVPwuCkNcGn
  363. KYNpQJP+JyVTsPpO8RLZsAQDzRueMI3S7fbbwTzAflN0z19wvblvu93xkaBytVok
  364. 9VBAH28olVhy9b1MMeg2WOt5sUEQaFNPnwwsyiY9+HsRpvpRnPSQF+kyYVsshQ==
  365. -----END CERTIFICATE-----
  366. """.strip()
  367. # RSA public key as dumped by openssl
  368. exponent = 65537
  369. modulus_str = """
  370. 00:c8:6f:a4:ca:d7:51:8f:74:c5:6d:19:87:0d:8a:
  371. 77:4d:7b:a0:55:0f:35:72:17:b0:d2:a7:8e:c5:95:
  372. 8e:cf:cd:08:8e:d5:a9:81:d3:9a:0a:f2:96:34:2b:
  373. 9c:f3:05:11:f4:15:ab:11:05:be:df:d4:9a:44:c2:
  374. e2:41:f4:2d:c8:54:90:66:28:dc:de:7b:04:06:ef:
  375. cb:a3:8b:96:67:45:bf:14:70:d1:55:2b:e4:24:0f:
  376. d5:13:1e:4d:2f:98:a4:23:ec:1b:51:e0:95:e4:a6:
  377. a3:18:d0:da:95:9f:05:d6:99:37:db:e0:81:b3:c8:
  378. 75:c4:dc:79:0f:2c:6e:10:75
  379. """
  380. modulus = int(re.sub("[^0-9a-f]","", modulus_str), 16)
  381. key = RSA.importKey(x509_v1_cert)
  382. self.assertEqual(key.e, exponent)
  383. self.assertEqual(key.n, modulus)
  384. self.failIf(key.has_private())
  385. def test_x509v3(self):
  386. # Sample V3 certificate with a 1024 bit RSA key
  387. x509_v3_cert = """
  388. -----BEGIN CERTIFICATE-----
  389. MIIEcjCCAlqgAwIBAgIBATANBgkqhkiG9w0BAQsFADBhMQswCQYDVQQGEwJVUzEL
  390. MAkGA1UECAwCTUQxEjAQBgNVBAcMCUJhbHRpbW9yZTEQMA4GA1UEAwwHVGVzdCBD
  391. QTEfMB0GCSqGSIb3DQEJARYQdGVzdEBleGFtcGxlLmNvbTAeFw0xNDA3MTIwOTM1
  392. MTJaFw0xNzA0MDcwOTM1MTJaMEQxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJNRDES
  393. MBAGA1UEBwwJQmFsdGltb3JlMRQwEgYDVQQDDAtUZXN0IFNlcnZlcjCBnzANBgkq
  394. hkiG9w0BAQEFAAOBjQAwgYkCgYEA/S7GJV2OcFdyNMQ4K75KrYFtMEn3VnEFdPHa
  395. jyS37XlMxSh0oS4GeTGVUCJInl5Cpsv8WQdh03FfeOdvzp5IZ46OcjeOPiWnmjgl
  396. 2G5j7e2bDH7RSchGV+OD6Fb1Agvuu2/9iy8fdf3rPQ/7eAddzKUrzwacVbnW+tg2
  397. QtSXKRcCAwEAAaOB1TCB0jAdBgNVHQ4EFgQU/WwCX7FfWMIPDFfJ+I8a2COG+l8w
  398. HwYDVR0jBBgwFoAUa0hkif3RMaraiWtsOOZZlLu9wJwwCQYDVR0TBAIwADALBgNV
  399. HQ8EBAMCBeAwSgYDVR0RBEMwQYILZXhhbXBsZS5jb22CD3d3dy5leGFtcGxlLmNv
  400. bYIQbWFpbC5leGFtcGxlLmNvbYIPZnRwLmV4YW1wbGUuY29tMCwGCWCGSAGG+EIB
  401. DQQfFh1PcGVuU1NMIEdlbmVyYXRlZCBDZXJ0aWZpY2F0ZTANBgkqhkiG9w0BAQsF
  402. AAOCAgEAvO6xfdsGbnoK4My3eJthodTAjMjPwFVY133LH04QLcCv54TxKhtUg1fi
  403. PgdjVe1HpTytPBfXy2bSZbXAN0abZCtw1rYrnn7o1g2pN8iypVq3zVn0iMTzQzxs
  404. zEPO3bpR/UhNSf90PmCsS5rqZpAAnXSaAy1ClwHWk/0eG2pYkhE1m1ABVMN2lsAW
  405. e9WxGk6IFqaI9O37NYQwmEypMs4DC+ECJEvbPFiqi3n0gbXCZJJ6omDA5xJldaYK
  406. Oa7KR3s/qjBsu9UAiWpLBuFoSTHIF2aeRKRFmUdmzwo43eVPep65pY6eQ4AdL2RF
  407. rqEuINbGlzI5oQyYhu71IwB+iPZXaZZPlwjLgOsuad/p2hOgDb5WxUi8FnDPursQ
  408. ujfpIpmrOP/zpvvQWnwePI3lI+5n41kTBSbefXEdv6rXpHk3QRzB90uPxnXPdxSC
  409. 16ASA8bQT5an/1AgoE3k9CrcD2K0EmgaX0YI0HUhkyzbkg34EhpWJ6vvRUbRiNRo
  410. 9cIbt/ya9Y9u0Ja8GLXv6dwX0l0IdJMkL8KifXUFAVCujp1FBrr/gdmwQn8itANy
  411. +qbnWSxmOvtaY0zcaFAcONuHva0h51/WqXOMO1eb8PhR4HIIYU8p1oBwQp7dSni8
  412. THDi1F+GG5PsymMDj5cWK42f+QzjVw5PrVmFqqrrEoMlx8DWh5Y=
  413. -----END CERTIFICATE-----
  414. """.strip()
  415. # RSA public key as dumped by openssl
  416. exponent = 65537
  417. modulus_str = """
  418. 00:fd:2e:c6:25:5d:8e:70:57:72:34:c4:38:2b:be:
  419. 4a:ad:81:6d:30:49:f7:56:71:05:74:f1:da:8f:24:
  420. b7:ed:79:4c:c5:28:74:a1:2e:06:79:31:95:50:22:
  421. 48:9e:5e:42:a6:cb:fc:59:07:61:d3:71:5f:78:e7:
  422. 6f:ce:9e:48:67:8e:8e:72:37:8e:3e:25:a7:9a:38:
  423. 25:d8:6e:63:ed:ed:9b:0c:7e:d1:49:c8:46:57:e3:
  424. 83:e8:56:f5:02:0b:ee:bb:6f:fd:8b:2f:1f:75:fd:
  425. eb:3d:0f:fb:78:07:5d:cc:a5:2b:cf:06:9c:55:b9:
  426. d6:fa:d8:36:42:d4:97:29:17
  427. """
  428. modulus = int(re.sub("[^0-9a-f]","", modulus_str), 16)
  429. key = RSA.importKey(x509_v3_cert)
  430. self.assertEqual(key.e, exponent)
  431. self.assertEqual(key.n, modulus)
  432. self.failIf(key.has_private())
  433. if __name__ == '__main__':
  434. unittest.main()
  435. def get_tests(config={}):
  436. tests = []
  437. tests += list_test_cases(ImportKeyTests)
  438. tests += list_test_cases(ImportKeyFromX509Cert)
  439. return tests
  440. if __name__ == '__main__':
  441. suite = lambda: unittest.TestSuite(get_tests())
  442. unittest.main(defaultTest='suite')
  443. # vim:set ts=4 sw=4 sts=4 expandtab: