RsaTest.php 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337
  1. <?php
  2. /**
  3. * Zend Framework
  4. *
  5. * LICENSE
  6. *
  7. * This source file is subject to the new BSD license that is bundled
  8. * with this package in the file LICENSE.txt.
  9. * It is also available through the world-wide-web at this URL:
  10. * http://framework.zend.com/license/new-bsd
  11. * If you did not receive a copy of the license and are unable to
  12. * obtain it through the world-wide-web, please send an email
  13. * to license@zend.com so we can send you a copy immediately.
  14. *
  15. * @category Zend
  16. * @package Zend_Crypt
  17. * @subpackage UnitTests
  18. * @copyright Copyright (c) 2005-2010 Zend Technologies USA Inc. (http://www.zend.com)
  19. * @license http://framework.zend.com/license/new-bsd New BSD License
  20. * @version $Id$
  21. */
  22. require_once 'Zend/Crypt/Rsa.php';
  23. require_once 'PHPUnit/Framework/TestCase.php';
  24. /**
  25. * @category Zend
  26. * @package Zend_Crypt
  27. * @subpackage UnitTests
  28. * @copyright Copyright (c) 2005-2010 Zend Technologies USA Inc. (http://www.zend.com)
  29. * @license http://framework.zend.com/license/new-bsd New BSD License
  30. * @group Zend_Crypt
  31. */
  32. class Zend_Crypt_RsaTest extends PHPUnit_Framework_TestCase
  33. {
  34. protected $_testPemString = null;
  35. protected $_testPemPath = null;
  36. public function setUp()
  37. {
  38. try {
  39. $rsaObject = new Zend_Crypt_Rsa();
  40. } catch (Zend_Crypt_Rsa_Exception $e) {
  41. if (strpos($e->getMessage(), 'requires openssl extention') !== false) {
  42. $this->markTestSkipped($e->getMessage());
  43. } else {
  44. throw $e;
  45. }
  46. }
  47. $this->_testPemString = <<<RSAKEY
  48. -----BEGIN RSA PRIVATE KEY-----
  49. MIIBOgIBAAJBANDiE2+Xi/WnO+s120NiiJhNyIButVu6zxqlVzz0wy2j4kQVUC4Z
  50. RZD80IY+4wIiX2YxKBZKGnd2TtPkcJ/ljkUCAwEAAQJAL151ZeMKHEU2c1qdRKS9
  51. sTxCcc2pVwoAGVzRccNX16tfmCf8FjxuM3WmLdsPxYoHrwb1LFNxiNk1MXrxjH3R
  52. 6QIhAPB7edmcjH4bhMaJBztcbNE1VRCEi/bisAwiPPMq9/2nAiEA3lyc5+f6DEIJ
  53. h1y6BWkdVULDSM+jpi1XiV/DevxuijMCIQCAEPGqHsF+4v7Jj+3HAgh9PU6otj2n
  54. Y79nJtCYmvhoHwIgNDePaS4inApN7omp7WdXyhPZhBmulnGDYvEoGJN66d0CIHra
  55. I2SvDkQ5CmrzkW5qPaE2oO7BSqAhRZxiYpZFb5CI
  56. -----END RSA PRIVATE KEY-----
  57. RSAKEY;
  58. $this->_testPemStringPublic = <<<RSAKEY
  59. -----BEGIN PUBLIC KEY-----
  60. MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDiE2+Xi/WnO+s120NiiJhNyIButVu6
  61. zxqlVzz0wy2j4kQVUC4ZRZD80IY+4wIiX2YxKBZKGnd2TtPkcJ/ljkUCAwEAAQ==
  62. -----END PUBLIC KEY-----
  63. RSAKEY;
  64. $this->_testCertificateString = <<<CERT
  65. -----BEGIN CERTIFICATE-----
  66. MIIC6TCCApOgAwIBAgIBADANBgkqhkiG9w0BAQQFADCBhzELMAkGA1UEBhMCSUUx
  67. DzANBgNVBAgTBkR1YmxpbjEPMA0GA1UEBxMGRHVibGluMQ4wDAYDVQQKEwVHcm91
  68. cDERMA8GA1UECxMIU3ViZ3JvdXAxEzARBgNVBAMTCkpvZSBCbG9nZ3MxHjAcBgkq
  69. hkiG9w0BCQEWD2pvZUBleGFtcGxlLmNvbTAeFw0wODA2MTMwOTQ4NDlaFw0xMTA2
  70. MTMwOTQ4NDlaMIGHMQswCQYDVQQGEwJJRTEPMA0GA1UECBMGRHVibGluMQ8wDQYD
  71. VQQHEwZEdWJsaW4xDjAMBgNVBAoTBUdyb3VwMREwDwYDVQQLEwhTdWJncm91cDET
  72. MBEGA1UEAxMKSm9lIEJsb2dnczEeMBwGCSqGSIb3DQEJARYPam9lQGV4YW1wbGUu
  73. Y29tMFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDiE2+Xi/WnO+s120NiiJhNyIBu
  74. tVu6zxqlVzz0wy2j4kQVUC4ZRZD80IY+4wIiX2YxKBZKGnd2TtPkcJ/ljkUCAwEA
  75. AaOB5zCB5DAdBgNVHQ4EFgQUxpguR0f4g+502IxAp3aMZvJ6asMwgbQGA1UdIwSB
  76. rDCBqYAUxpguR0f4g+502IxAp3aMZvJ6asOhgY2kgYowgYcxCzAJBgNVBAYTAklF
  77. MQ8wDQYDVQQIEwZEdWJsaW4xDzANBgNVBAcTBkR1YmxpbjEOMAwGA1UEChMFR3Jv
  78. dXAxETAPBgNVBAsTCFN1Ymdyb3VwMRMwEQYDVQQDEwpKb2UgQmxvZ2dzMR4wHAYJ
  79. KoZIhvcNAQkBFg9qb2VAZXhhbXBsZS5jb22CAQAwDAYDVR0TBAUwAwEB/zANBgkq
  80. hkiG9w0BAQQFAANBAE4M7ZXJTDLHEFguGaP5g64lbmLmLtYX22ZaNY891FmxhtKm
  81. l9Nwj3KnPKFdqzJchujP2TLNwSYoQnxgyoMxdho=
  82. -----END CERTIFICATE-----
  83. CERT;
  84. $this->_testPemPath = dirname(__FILE__) . '/_files/test.pem';
  85. $this->_testCertificatePath = dirname(__FILE__) . '/_files/test.cert';
  86. }
  87. public function testConstructorSetsPemString()
  88. {
  89. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  90. $this->assertEquals($this->_testPemString, $rsa->getPemString());
  91. }
  92. public function testConstructorSetsPemPath()
  93. {
  94. $rsa = new Zend_Crypt_Rsa(array('pemPath'=>$this->_testPemPath));
  95. $this->assertEquals($this->_testPemPath, $rsa->getPemPath());
  96. }
  97. public function testSetPemPathLoadsPemString()
  98. {
  99. $rsa = new Zend_Crypt_Rsa(array('pemPath'=>$this->_testPemPath));
  100. $this->assertEquals($this->_testPemString, $rsa->getPemString());
  101. }
  102. public function testConstructorSetsCertificateString()
  103. {
  104. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  105. $this->assertEquals($this->_testCertificateString, $rsa->getCertificateString());
  106. }
  107. public function testConstructorSetsCertificatePath()
  108. {
  109. $rsa = new Zend_Crypt_Rsa(array('certificatePath'=>$this->_testCertificatePath));
  110. $this->assertEquals($this->_testCertificatePath, $rsa->getCertificatePath());
  111. }
  112. public function testSetCertificatePathLoadsCertificateString()
  113. {
  114. $rsa = new Zend_Crypt_Rsa(array('certificatePath'=>$this->_testCertificatePath));
  115. $this->assertEquals($this->_testCertificateString, $rsa->getCertificateString());
  116. }
  117. public function testConstructorSetsHashOption()
  118. {
  119. $rsa = new Zend_Crypt_Rsa(array('hashAlgorithm'=>'md2'));
  120. $this->assertEquals(OPENSSL_ALGO_MD2, $rsa->getHashAlgorithm());
  121. }
  122. public function testSetPemStringParsesPemForPrivateKey()
  123. {
  124. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  125. $this->assertType('Zend_Crypt_Rsa_Key_Private', $rsa->getPrivateKey());
  126. }
  127. public function testSetPemStringParsesPemForPublicKey()
  128. {
  129. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  130. $this->assertType('Zend_Crypt_Rsa_Key_Public', $rsa->getPublicKey());
  131. }
  132. public function testSetCertificateStringParsesCertificateForNullPrivateKey()
  133. {
  134. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  135. $this->assertEquals(null, $rsa->getPrivateKey());
  136. }
  137. public function testSetCertificateStringParsesCertificateForPublicKey()
  138. {
  139. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  140. $this->assertType('Zend_Crypt_Rsa_Key_Public', $rsa->getPublicKey());
  141. }
  142. public function testSignGeneratesExpectedBinarySignature()
  143. {
  144. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  145. $signature = $rsa->sign('1234567890');
  146. $this->assertEquals(
  147. 'sMHpp3u6DNecIm5RIkDD3xyKaH6qqP8roUWDs215iOGHehfK1ypqwoETKNP7NaksGS2C1Up813ixlGXkipPVbQ==',
  148. base64_encode($signature));
  149. }
  150. public function testSignGeneratesExpectedBinarySignatureUsingExternalKey()
  151. {
  152. $privateKey = new Zend_Crypt_Rsa_Key_Private($this->_testPemString);
  153. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  154. $signature = $rsa->sign('1234567890', $privateKey);
  155. $this->assertEquals(
  156. 'sMHpp3u6DNecIm5RIkDD3xyKaH6qqP8roUWDs215iOGHehfK1ypqwoETKNP7NaksGS2C1Up813ixlGXkipPVbQ==',
  157. base64_encode($signature));
  158. }
  159. public function testSignGeneratesExpectedBase64Signature()
  160. {
  161. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  162. $signature = $rsa->sign('1234567890', null, Zend_Crypt_Rsa::BASE64);
  163. $this->assertEquals(
  164. 'sMHpp3u6DNecIm5RIkDD3xyKaH6qqP8roUWDs215iOGHehfK1ypqwoETKNP7NaksGS2C1Up813ixlGXkipPVbQ==',
  165. $signature);
  166. }
  167. public function testVerifyVerifiesBinarySignatures()
  168. {
  169. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  170. $signature = $rsa->sign('1234567890');
  171. $result = $rsa->verifySignature('1234567890', $signature);
  172. $this->assertEquals(1, $result);
  173. }
  174. public function testVerifyVerifiesBinarySignaturesUsingCertificate()
  175. {
  176. $privateKey = new Zend_Crypt_Rsa_Key_Private($this->_testPemString);
  177. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  178. $signature = $rsa->sign('1234567890', $privateKey);
  179. $result = $rsa->verifySignature('1234567890', $signature);
  180. $this->assertEquals(1, $result);
  181. }
  182. public function testVerifyVerifiesBase64Signatures()
  183. {
  184. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  185. $signature = $rsa->sign('1234567890', null, Zend_Crypt_Rsa::BASE64);
  186. $result = $rsa->verifySignature('1234567890', $signature, Zend_Crypt_Rsa::BASE64);
  187. $this->assertEquals(1, $result);
  188. }
  189. public function testEncryptionUsingPublicKeyEncryption()
  190. {
  191. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  192. $encrypted = $rsa->encrypt('1234567890', $rsa->getPublicKey());
  193. $this->assertEquals(
  194. '1234567890',
  195. $rsa->decrypt($encrypted, $rsa->getPrivateKey())
  196. );
  197. }
  198. public function testEncryptionUsingPublicKeyBase64Encryption()
  199. {
  200. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  201. $encrypted = $rsa->encrypt('1234567890', $rsa->getPublicKey(), Zend_Crypt_Rsa::BASE64);
  202. $this->assertEquals(
  203. '1234567890',
  204. $rsa->decrypt($encrypted, $rsa->getPrivateKey(), Zend_Crypt_Rsa::BASE64)
  205. );
  206. }
  207. public function testBase64EncryptionUsingCertificatePublicKeyEncryption()
  208. {
  209. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  210. $encrypted = $rsa->encrypt('1234567890', $rsa->getPublicKey(), Zend_Crypt_Rsa::BASE64);
  211. $rsa2 = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  212. $this->assertEquals(
  213. '1234567890',
  214. $rsa->decrypt($encrypted, $rsa2->getPrivateKey(), Zend_Crypt_Rsa::BASE64)
  215. );
  216. }
  217. public function testEncryptionUsingPrivateKeyEncryption()
  218. {
  219. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  220. $encrypted = $rsa->encrypt('1234567890', $rsa->getPrivateKey());
  221. $this->assertEquals(
  222. '1234567890',
  223. $rsa->decrypt($encrypted, $rsa->getPublicKey())
  224. );
  225. }
  226. public function testEncryptionUsingPrivateKeyBase64Encryption()
  227. {
  228. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  229. $encrypted = $rsa->encrypt('1234567890', $rsa->getPrivateKey(), Zend_Crypt_Rsa::BASE64);
  230. $this->assertEquals(
  231. '1234567890',
  232. $rsa->decrypt($encrypted, $rsa->getPublicKey(), Zend_Crypt_Rsa::BASE64)
  233. );
  234. }
  235. public function testKeyGenerationCreatesArrayObjectResult()
  236. {
  237. $rsa = new Zend_Crypt_Rsa;
  238. $keys = $rsa->generateKeys(array('private_key_bits'=>512));
  239. $this->assertType('ArrayObject', $keys);
  240. }
  241. public function testKeyGenerationCreatesPrivateKeyInArrayObject()
  242. {
  243. $rsa = new Zend_Crypt_Rsa;
  244. $keys = $rsa->generateKeys(array('private_key_bits'=>512));
  245. $this->assertType('Zend_Crypt_Rsa_Key_Private', $keys->privateKey);
  246. }
  247. public function testKeyGenerationCreatesPublicKeyInArrayObject()
  248. {
  249. $rsa = new Zend_Crypt_Rsa;
  250. $keys = $rsa->generateKeys(array('privateKeyBits'=>512));
  251. $this->assertType('Zend_Crypt_Rsa_Key_Public', $keys->publicKey);
  252. }
  253. public function testKeyGenerationCreatesPassphrasedPrivateKey()
  254. {
  255. $rsa = new Zend_Crypt_Rsa;
  256. $config = array(
  257. 'privateKeyBits' => 512,
  258. 'passPhrase' => '0987654321'
  259. );
  260. $keys = $rsa->generateKeys($config);
  261. try {
  262. $rsa = new Zend_Crypt_Rsa(array(
  263. 'passPhrase'=>'1234567890',
  264. 'pemString'=>$keys->privateKey->toString()
  265. ));
  266. $this->fail('Expected exception not thrown');
  267. } catch (Zend_Crypt_Exception $e) {
  268. }
  269. }
  270. public function testConstructorLoadsPassphrasedKeys()
  271. {
  272. $rsa = new Zend_Crypt_Rsa;
  273. $config = array(
  274. 'privateKeyBits' => 512,
  275. 'passPhrase' => '0987654321'
  276. );
  277. $keys = $rsa->generateKeys($config);
  278. try {
  279. $rsa = new Zend_Crypt_Rsa(array(
  280. 'passPhrase'=>'0987654321',
  281. 'pemString'=>$keys->privateKey->toString()
  282. ));
  283. } catch (Zend_Crypt_Exception $e) {
  284. $this->fail('Passphrase loading failed of a private key');
  285. }
  286. }
  287. /**
  288. * @group ZF-8846
  289. */
  290. public function testLoadsPublicKeyFromPEMWithoutPrivateKeyAndThrowsNoException()
  291. {
  292. $rsa = new Zend_Crypt_Rsa;
  293. $rsa->setPemString($this->_testPemStringPublic);
  294. }
  295. }