You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 

273 line
9.3 KiB

  1. /* Copyright (c) 2014, Google Inc.
  2. *
  3. * Permission to use, copy, modify, and/or distribute this software for any
  4. * purpose with or without fee is hereby granted, provided that the above
  5. * copyright notice and this permission notice appear in all copies.
  6. *
  7. * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
  8. * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
  9. * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
  10. * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
  11. * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
  12. * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
  13. * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
  14. #include <stdint.h>
  15. #include <stdio.h>
  16. #include <string.h>
  17. #include <memory>
  18. #include <openssl/crypto.h>
  19. #include <openssl/digest.h>
  20. #include <openssl/err.h>
  21. #include <openssl/md4.h>
  22. #include <openssl/md5.h>
  23. #include <openssl/nid.h>
  24. #include <openssl/sha.h>
  25. #include "../internal.h"
  26. struct MD {
  27. // name is the name of the digest.
  28. const char* name;
  29. // md_func is the digest to test.
  30. const EVP_MD *(*func)(void);
  31. // one_shot_func is the convenience one-shot version of the
  32. // digest.
  33. uint8_t *(*one_shot_func)(const uint8_t *, size_t, uint8_t *);
  34. };
  35. static const MD md4 = { "MD4", &EVP_md4, nullptr };
  36. static const MD md5 = { "MD5", &EVP_md5, &MD5 };
  37. static const MD sha1 = { "SHA1", &EVP_sha1, &SHA1 };
  38. static const MD sha224 = { "SHA224", &EVP_sha224, &SHA224 };
  39. static const MD sha256 = { "SHA256", &EVP_sha256, &SHA256 };
  40. static const MD sha384 = { "SHA384", &EVP_sha384, &SHA384 };
  41. static const MD sha512 = { "SHA512", &EVP_sha512, &SHA512 };
  42. static const MD md5_sha1 = { "MD5-SHA1", &EVP_md5_sha1, nullptr };
  43. struct TestVector {
  44. // md is the digest to test.
  45. const MD &md;
  46. // input is a NUL-terminated string to hash.
  47. const char *input;
  48. // repeat is the number of times to repeat input.
  49. size_t repeat;
  50. // expected_hex is the expected digest in hexadecimal.
  51. const char *expected_hex;
  52. };
  53. static const TestVector kTestVectors[] = {
  54. // MD4 tests, from RFC 1320. (crypto/md4 does not provide a
  55. // one-shot MD4 function.)
  56. { md4, "", 1, "31d6cfe0d16ae931b73c59d7e0c089c0" },
  57. { md4, "a", 1, "bde52cb31de33e46245e05fbdbd6fb24" },
  58. { md4, "abc", 1, "a448017aaf21d8525fc10ae87aa6729d" },
  59. { md4, "message digest", 1, "d9130a8164549fe818874806e1c7014b" },
  60. { md4, "abcdefghijklmnopqrstuvwxyz", 1,
  61. "d79e1c308aa5bbcdeea8ed63df412da9" },
  62. { md4,
  63. "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 1,
  64. "043f8582f241db351ce627e153e7f0e4" },
  65. { md4, "1234567890", 8, "e33b4ddc9c38f2199c3e7b164fcc0536" },
  66. // MD5 tests, from RFC 1321.
  67. { md5, "", 1, "d41d8cd98f00b204e9800998ecf8427e" },
  68. { md5, "a", 1, "0cc175b9c0f1b6a831c399e269772661" },
  69. { md5, "abc", 1, "900150983cd24fb0d6963f7d28e17f72" },
  70. { md5, "message digest", 1, "f96b697d7cb7938d525a2f31aaf161d0" },
  71. { md5, "abcdefghijklmnopqrstuvwxyz", 1,
  72. "c3fcd3d76192e4007dfb496cca67e13b" },
  73. { md5,
  74. "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789", 1,
  75. "d174ab98d277d9f5a5611c2c9f419d9f" },
  76. { md5, "1234567890", 8, "57edf4a22be3c955ac49da2e2107b67a" },
  77. // SHA-1 tests, from RFC 3174.
  78. { sha1, "abc", 1, "a9993e364706816aba3e25717850c26c9cd0d89d" },
  79. { sha1,
  80. "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq", 1,
  81. "84983e441c3bd26ebaae4aa1f95129e5e54670f1" },
  82. { sha1, "a", 1000000, "34aa973cd4c4daa4f61eeb2bdbad27316534016f" },
  83. { sha1,
  84. "0123456701234567012345670123456701234567012345670123456701234567", 10,
  85. "dea356a2cddd90c7a7ecedc5ebb563934f460452" },
  86. // SHA-224 tests, from RFC 3874.
  87. { sha224, "abc", 1,
  88. "23097d223405d8228642a477bda255b32aadbce4bda0b3f7e36c9da7" },
  89. { sha224,
  90. "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq", 1,
  91. "75388b16512776cc5dba5da1fd890150b0c6455cb4f58b1952522525" },
  92. { sha224,
  93. "a", 1000000,
  94. "20794655980c91d8bbb4c1ea97618a4bf03f42581948b2ee4ee7ad67" },
  95. // SHA-256 tests, from NIST.
  96. { sha256, "abc", 1,
  97. "ba7816bf8f01cfea414140de5dae2223b00361a396177a9cb410ff61f20015ad" },
  98. { sha256,
  99. "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq", 1,
  100. "248d6a61d20638b8e5c026930c3e6039a33ce45964ff2167f6ecedd419db06c1" },
  101. // SHA-384 tests, from NIST.
  102. { sha384, "abc", 1,
  103. "cb00753f45a35e8bb5a03d699ac65007272c32ab0eded1631a8b605a43ff5bed"
  104. "8086072ba1e7cc2358baeca134c825a7" },
  105. { sha384,
  106. "abcdefghbcdefghicdefghijdefghijkefghijklfghijklmghijklmn"
  107. "hijklmnoijklmnopjklmnopqklmnopqrlmnopqrsmnopqrstnopqrstu", 1,
  108. "09330c33f71147e83d192fc782cd1b4753111b173b3b05d22fa08086e3b0f712"
  109. "fcc7c71a557e2db966c3e9fa91746039" },
  110. // SHA-512 tests, from NIST.
  111. { sha512, "abc", 1,
  112. "ddaf35a193617abacc417349ae20413112e6fa4e89a97ea20a9eeee64b55d39a"
  113. "2192992a274fc1a836ba3c23a3feebbd454d4423643ce80e2a9ac94fa54ca49f" },
  114. { sha512,
  115. "abcdefghbcdefghicdefghijdefghijkefghijklfghijklmghijklmn"
  116. "hijklmnoijklmnopjklmnopqklmnopqrlmnopqrsmnopqrstnopqrstu", 1,
  117. "8e959b75dae313da8cf4f72814fc143f8f7779c6eb9f7fa17299aeadb6889018"
  118. "501d289e4900f7e4331b99dec4b5433ac7d329eeb6dd26545e96e55b874be909" },
  119. // MD5-SHA1 tests.
  120. { md5_sha1, "abc", 1,
  121. "900150983cd24fb0d6963f7d28e17f72a9993e364706816aba3e25717850c26c9cd0d89d" },
  122. };
  123. static bool CompareDigest(const TestVector *test,
  124. const uint8_t *digest,
  125. size_t digest_len) {
  126. static const char kHexTable[] = "0123456789abcdef";
  127. char digest_hex[2*EVP_MAX_MD_SIZE + 1];
  128. for (size_t i = 0; i < digest_len; i++) {
  129. digest_hex[2*i] = kHexTable[digest[i] >> 4];
  130. digest_hex[2*i + 1] = kHexTable[digest[i] & 0xf];
  131. }
  132. digest_hex[2*digest_len] = '\0';
  133. if (strcmp(digest_hex, test->expected_hex) != 0) {
  134. fprintf(stderr, "%s(\"%s\" * %d) = %s; want %s\n",
  135. test->md.name, test->input, (int)test->repeat,
  136. digest_hex, test->expected_hex);
  137. return false;
  138. }
  139. return true;
  140. }
  141. static int TestDigest(const TestVector *test) {
  142. bssl::ScopedEVP_MD_CTX ctx;
  143. // Test the input provided.
  144. if (!EVP_DigestInit_ex(ctx.get(), test->md.func(), NULL)) {
  145. fprintf(stderr, "EVP_DigestInit_ex failed\n");
  146. return false;
  147. }
  148. for (size_t i = 0; i < test->repeat; i++) {
  149. if (!EVP_DigestUpdate(ctx.get(), test->input, strlen(test->input))) {
  150. fprintf(stderr, "EVP_DigestUpdate failed\n");
  151. return false;
  152. }
  153. }
  154. std::unique_ptr<uint8_t[]> digest(new uint8_t[EVP_MD_size(test->md.func())]);
  155. unsigned digest_len;
  156. if (!EVP_DigestFinal_ex(ctx.get(), digest.get(), &digest_len)) {
  157. fprintf(stderr, "EVP_DigestFinal_ex failed\n");
  158. return false;
  159. }
  160. if (!CompareDigest(test, digest.get(), digest_len)) {
  161. return false;
  162. }
  163. // Test the input one character at a time.
  164. if (!EVP_DigestInit_ex(ctx.get(), test->md.func(), NULL)) {
  165. fprintf(stderr, "EVP_DigestInit_ex failed\n");
  166. return false;
  167. }
  168. if (!EVP_DigestUpdate(ctx.get(), NULL, 0)) {
  169. fprintf(stderr, "EVP_DigestUpdate failed\n");
  170. return false;
  171. }
  172. for (size_t i = 0; i < test->repeat; i++) {
  173. for (const char *p = test->input; *p; p++) {
  174. if (!EVP_DigestUpdate(ctx.get(), p, 1)) {
  175. fprintf(stderr, "EVP_DigestUpdate failed\n");
  176. return false;
  177. }
  178. }
  179. }
  180. if (!EVP_DigestFinal_ex(ctx.get(), digest.get(), &digest_len)) {
  181. fprintf(stderr, "EVP_DigestFinal_ex failed\n");
  182. return false;
  183. }
  184. if (digest_len != EVP_MD_size(test->md.func())) {
  185. fprintf(stderr, "EVP_MD_size output incorrect\n");
  186. return false;
  187. }
  188. if (!CompareDigest(test, digest.get(), digest_len)) {
  189. return false;
  190. }
  191. // Test the one-shot function.
  192. if (test->md.one_shot_func && test->repeat == 1) {
  193. uint8_t *out = test->md.one_shot_func((const uint8_t *)test->input,
  194. strlen(test->input), digest.get());
  195. if (out != digest.get()) {
  196. fprintf(stderr, "one_shot_func gave incorrect return\n");
  197. return false;
  198. }
  199. if (!CompareDigest(test, digest.get(), EVP_MD_size(test->md.func()))) {
  200. return false;
  201. }
  202. // Test the deprecated static buffer variant, until it's removed.
  203. out = test->md.one_shot_func((const uint8_t *)test->input,
  204. strlen(test->input), NULL);
  205. if (!CompareDigest(test, out, EVP_MD_size(test->md.func()))) {
  206. return false;
  207. }
  208. }
  209. return true;
  210. }
  211. static int TestGetters() {
  212. if (EVP_get_digestbyname("RSA-SHA512") != EVP_sha512() ||
  213. EVP_get_digestbyname("sha512WithRSAEncryption") != EVP_sha512() ||
  214. EVP_get_digestbyname("nonsense") != NULL ||
  215. EVP_get_digestbyname("SHA512") != EVP_sha512() ||
  216. EVP_get_digestbyname("sha512") != EVP_sha512()) {
  217. return false;
  218. }
  219. if (EVP_get_digestbynid(NID_sha512) != EVP_sha512() ||
  220. EVP_get_digestbynid(NID_sha512WithRSAEncryption) != NULL ||
  221. EVP_get_digestbynid(NID_undef) != NULL) {
  222. return false;
  223. }
  224. return true;
  225. }
  226. int main() {
  227. CRYPTO_library_init();
  228. for (size_t i = 0; i < OPENSSL_ARRAY_SIZE(kTestVectors); i++) {
  229. if (!TestDigest(&kTestVectors[i])) {
  230. fprintf(stderr, "Test %d failed\n", (int)i);
  231. return 1;
  232. }
  233. }
  234. if (!TestGetters()) {
  235. return 1;
  236. }
  237. printf("PASS\n");
  238. return 0;
  239. }