Repository navigation
Expand file tree
/
Copy pathsign_legacy_test.go
More file actions
79 lines (74 loc) · 1.96 KB
/
Copy pathsign_legacy_test.go
File metadata and controls
79 lines (74 loc) · 1.96 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
//go:build legacy
package pkcs7
import (
"bytes"
"crypto"
"crypto/x509"
"testing"
)
func TestLegacySign(t *testing.T) {
testLegacySign(t, []x509.SignatureAlgorithm{
x509.SHA1WithRSA,
x509.ECDSAWithSHA1,
}, true)
}
func TestLegacySignWithoutAttributes(t *testing.T) {
testLegacySign(t, []x509.SignatureAlgorithm{
x509.SHA1WithRSA,
x509.ECDSAWithSHA1,
}, false)
}
func testLegacySign(t *testing.T, signatureAlgorithms []x509.SignatureAlgorithm, withSignedAttributes bool) {
t.Helper()
content := []byte("legacy SHA-1 CMS signature")
for _, signatureAlgorithm := range signatureAlgorithms {
t.Run(signatureAlgorithm.String(), func(t *testing.T) {
certificate, err := createTestCertificate(signatureAlgorithm)
if err != nil {
t.Fatal(err)
}
digestOID, err := GetDigestOIDForSignatureAlgorithm(signatureAlgorithm)
if err != nil {
t.Fatal(err)
}
for _, detached := range []bool{false, true} {
signedData, err := NewSignedData(content)
if err != nil {
t.Fatal(err)
}
signedData.SetDigestAlgorithm(digestOID)
privateKey := (*certificate.PrivateKey).(crypto.Signer)
if withSignedAttributes {
err = signedData.AddSigner(certificate.Certificate, privateKey, SignerInfoConfig{})
} else {
err = signedData.SignWithoutAttr(certificate.Certificate, privateKey, SignerInfoConfig{})
}
if err != nil {
t.Fatal(err)
}
if detached {
signedData.Detach()
}
der, err := signedData.Finish()
if err != nil {
t.Fatal(err)
}
parsed, err := Parse(der)
if err != nil {
t.Fatal(err)
}
if detached {
parsed.Content = content
}
if !bytes.Equal(parsed.Content, content) {
t.Fatalf("content = %q, want %q", parsed.Content, content)
}
// Go 1.27 no longer permits SHA-1 certificate-chain validation,
// but low-level CMS signature verification remains supported.
if err := parsed.Verify(); err != nil {
t.Fatal(err)
}
}
})
}
}