RsaTest.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363
  1. <?php
  2. /**
  3. * Zend Framework
  4. *
  5. * LICENSE
  6. *
  7. * This source file is subject to the new BSD license that is bundled
  8. * with this package in the file LICENSE.txt.
  9. * It is also available through the world-wide-web at this URL:
  10. * http://framework.zend.com/license/new-bsd
  11. * If you did not receive a copy of the license and are unable to
  12. * obtain it through the world-wide-web, please send an email
  13. * to license@zend.com so we can send you a copy immediately.
  14. *
  15. * @category Zend
  16. * @package Zend_Crypt
  17. * @subpackage UnitTests
  18. * @copyright Copyright (c) 2005-2012 Zend Technologies USA Inc. (http://www.zend.com)
  19. * @license http://framework.zend.com/license/new-bsd New BSD License
  20. * @version $Id$
  21. */
  22. require_once 'Zend/Crypt/Rsa.php';
  23. /**
  24. * @category Zend
  25. * @package Zend_Crypt
  26. * @subpackage UnitTests
  27. * @copyright Copyright (c) 2005-2012 Zend Technologies USA Inc. (http://www.zend.com)
  28. * @license http://framework.zend.com/license/new-bsd New BSD License
  29. * @group Zend_Crypt
  30. */
  31. class Zend_Crypt_RsaTest extends PHPUnit_Framework_TestCase
  32. {
  33. protected $_testPemString = null;
  34. protected $_testPemPath = null;
  35. public function setUp()
  36. {
  37. if (!extension_loaded('openssl')) {
  38. $this->markTestSkipped('Zend_Crypt_Rsa requires openssl extension to be loaded.');
  39. }
  40. $this->_testPemString = <<<RSAKEY
  41. -----BEGIN RSA PRIVATE KEY-----
  42. MIIBOgIBAAJBANDiE2+Xi/WnO+s120NiiJhNyIButVu6zxqlVzz0wy2j4kQVUC4Z
  43. RZD80IY+4wIiX2YxKBZKGnd2TtPkcJ/ljkUCAwEAAQJAL151ZeMKHEU2c1qdRKS9
  44. sTxCcc2pVwoAGVzRccNX16tfmCf8FjxuM3WmLdsPxYoHrwb1LFNxiNk1MXrxjH3R
  45. 6QIhAPB7edmcjH4bhMaJBztcbNE1VRCEi/bisAwiPPMq9/2nAiEA3lyc5+f6DEIJ
  46. h1y6BWkdVULDSM+jpi1XiV/DevxuijMCIQCAEPGqHsF+4v7Jj+3HAgh9PU6otj2n
  47. Y79nJtCYmvhoHwIgNDePaS4inApN7omp7WdXyhPZhBmulnGDYvEoGJN66d0CIHra
  48. I2SvDkQ5CmrzkW5qPaE2oO7BSqAhRZxiYpZFb5CI
  49. -----END RSA PRIVATE KEY-----
  50. RSAKEY;
  51. $this->_testPemStringPublic = <<<RSAKEY
  52. -----BEGIN PUBLIC KEY-----
  53. MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDiE2+Xi/WnO+s120NiiJhNyIButVu6
  54. zxqlVzz0wy2j4kQVUC4ZRZD80IY+4wIiX2YxKBZKGnd2TtPkcJ/ljkUCAwEAAQ==
  55. -----END PUBLIC KEY-----
  56. RSAKEY;
  57. $this->_testCertificateString = <<<CERT
  58. -----BEGIN CERTIFICATE-----
  59. MIIC6TCCApOgAwIBAgIBADANBgkqhkiG9w0BAQQFADCBhzELMAkGA1UEBhMCSUUx
  60. DzANBgNVBAgTBkR1YmxpbjEPMA0GA1UEBxMGRHVibGluMQ4wDAYDVQQKEwVHcm91
  61. cDERMA8GA1UECxMIU3ViZ3JvdXAxEzARBgNVBAMTCkpvZSBCbG9nZ3MxHjAcBgkq
  62. hkiG9w0BCQEWD2pvZUBleGFtcGxlLmNvbTAeFw0wODA2MTMwOTQ4NDlaFw0xMTA2
  63. MTMwOTQ4NDlaMIGHMQswCQYDVQQGEwJJRTEPMA0GA1UECBMGRHVibGluMQ8wDQYD
  64. VQQHEwZEdWJsaW4xDjAMBgNVBAoTBUdyb3VwMREwDwYDVQQLEwhTdWJncm91cDET
  65. MBEGA1UEAxMKSm9lIEJsb2dnczEeMBwGCSqGSIb3DQEJARYPam9lQGV4YW1wbGUu
  66. Y29tMFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDiE2+Xi/WnO+s120NiiJhNyIBu
  67. tVu6zxqlVzz0wy2j4kQVUC4ZRZD80IY+4wIiX2YxKBZKGnd2TtPkcJ/ljkUCAwEA
  68. AaOB5zCB5DAdBgNVHQ4EFgQUxpguR0f4g+502IxAp3aMZvJ6asMwgbQGA1UdIwSB
  69. rDCBqYAUxpguR0f4g+502IxAp3aMZvJ6asOhgY2kgYowgYcxCzAJBgNVBAYTAklF
  70. MQ8wDQYDVQQIEwZEdWJsaW4xDzANBgNVBAcTBkR1YmxpbjEOMAwGA1UEChMFR3Jv
  71. dXAxETAPBgNVBAsTCFN1Ymdyb3VwMRMwEQYDVQQDEwpKb2UgQmxvZ2dzMR4wHAYJ
  72. KoZIhvcNAQkBFg9qb2VAZXhhbXBsZS5jb22CAQAwDAYDVR0TBAUwAwEB/zANBgkq
  73. hkiG9w0BAQQFAANBAE4M7ZXJTDLHEFguGaP5g64lbmLmLtYX22ZaNY891FmxhtKm
  74. l9Nwj3KnPKFdqzJchujP2TLNwSYoQnxgyoMxdho=
  75. -----END CERTIFICATE-----
  76. CERT;
  77. $this->_testPemPath = dirname(__FILE__) . '/_files/test.pem';
  78. $this->_testCertificatePath = dirname(__FILE__) . '/_files/test.cert';
  79. }
  80. public function testConstructorSetsPemString()
  81. {
  82. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  83. $this->assertEquals($this->_testPemString, $rsa->getPemString());
  84. }
  85. public function testConstructorSetsPemPath()
  86. {
  87. $rsa = new Zend_Crypt_Rsa(array('pemPath'=>$this->_testPemPath));
  88. $this->assertEquals($this->_testPemPath, $rsa->getPemPath());
  89. }
  90. public function testSetPemPathLoadsPemString()
  91. {
  92. $rsa = new Zend_Crypt_Rsa(array('pemPath'=>$this->_testPemPath));
  93. $this->assertEquals($this->_testPemString, $rsa->getPemString());
  94. }
  95. public function testConstructorSetsCertificateString()
  96. {
  97. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  98. $this->assertEquals($this->_testCertificateString, $rsa->getCertificateString());
  99. }
  100. public function testConstructorSetsCertificatePath()
  101. {
  102. $rsa = new Zend_Crypt_Rsa(array('certificatePath'=>$this->_testCertificatePath));
  103. $this->assertEquals($this->_testCertificatePath, $rsa->getCertificatePath());
  104. }
  105. public function testSetCertificatePathLoadsCertificateString()
  106. {
  107. $rsa = new Zend_Crypt_Rsa(array('certificatePath'=>$this->_testCertificatePath));
  108. $this->assertEquals($this->_testCertificateString, $rsa->getCertificateString());
  109. }
  110. public function testConstructorSetsHashOption()
  111. {
  112. if (!defined('OPENSSL_ALGO_MD2')) {
  113. $this->markTestSkipped('The OPENSSL_ALGO_MD2 constant is not defined in this PHP instance.');
  114. }
  115. $rsa = new Zend_Crypt_Rsa(array('hashAlgorithm'=>'md2'));
  116. $this->assertEquals(OPENSSL_ALGO_MD2, $rsa->getHashAlgorithm());
  117. }
  118. public function testSetPemStringParsesPemForPrivateKey()
  119. {
  120. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  121. $this->assertTrue($rsa->getPrivateKey() instanceof Zend_Crypt_Rsa_Key_Private);
  122. }
  123. public function testSetPemStringParsesPemForPublicKey()
  124. {
  125. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  126. $this->assertTrue($rsa->getPublicKey() instanceof Zend_Crypt_Rsa_Key_Public);
  127. }
  128. public function testSetCertificateStringParsesCertificateForNullPrivateKey()
  129. {
  130. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  131. $this->assertEquals(null, $rsa->getPrivateKey());
  132. }
  133. public function testSetCertificateStringParsesCertificateForPublicKey()
  134. {
  135. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  136. $this->assertTrue($rsa->getPublicKey() instanceof Zend_Crypt_Rsa_Key_Public);
  137. }
  138. public function testSignGeneratesExpectedBinarySignature()
  139. {
  140. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  141. $signature = $rsa->sign('1234567890');
  142. $this->assertEquals(
  143. 'sMHpp3u6DNecIm5RIkDD3xyKaH6qqP8roUWDs215iOGHehfK1ypqwoETKNP7NaksGS2C1Up813ixlGXkipPVbQ==',
  144. base64_encode($signature));
  145. }
  146. public function testSignGeneratesExpectedBinarySignatureUsingExternalKey()
  147. {
  148. $privateKey = new Zend_Crypt_Rsa_Key_Private($this->_testPemString);
  149. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  150. $signature = $rsa->sign('1234567890', $privateKey);
  151. $this->assertEquals(
  152. 'sMHpp3u6DNecIm5RIkDD3xyKaH6qqP8roUWDs215iOGHehfK1ypqwoETKNP7NaksGS2C1Up813ixlGXkipPVbQ==',
  153. base64_encode($signature));
  154. }
  155. public function testSignGeneratesExpectedBase64Signature()
  156. {
  157. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  158. $signature = $rsa->sign('1234567890', null, Zend_Crypt_Rsa::BASE64);
  159. $this->assertEquals(
  160. 'sMHpp3u6DNecIm5RIkDD3xyKaH6qqP8roUWDs215iOGHehfK1ypqwoETKNP7NaksGS2C1Up813ixlGXkipPVbQ==',
  161. $signature);
  162. }
  163. public function testVerifyVerifiesBinarySignatures()
  164. {
  165. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  166. $signature = $rsa->sign('1234567890');
  167. $result = $rsa->verifySignature('1234567890', $signature);
  168. $this->assertEquals(1, $result);
  169. }
  170. public function testVerifyVerifiesBinarySignaturesUsingCertificate()
  171. {
  172. $privateKey = new Zend_Crypt_Rsa_Key_Private($this->_testPemString);
  173. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  174. $signature = $rsa->sign('1234567890', $privateKey);
  175. $result = $rsa->verifySignature('1234567890', $signature);
  176. $this->assertEquals(1, $result);
  177. }
  178. public function testVerifyVerifiesBase64Signatures()
  179. {
  180. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  181. $signature = $rsa->sign('1234567890', null, Zend_Crypt_Rsa::BASE64);
  182. $result = $rsa->verifySignature('1234567890', $signature, Zend_Crypt_Rsa::BASE64);
  183. $this->assertEquals(1, $result);
  184. }
  185. public function testEncryptionUsingPublicKeyEncryption()
  186. {
  187. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  188. $encrypted = $rsa->encrypt('1234567890', $rsa->getPublicKey());
  189. $this->assertEquals(
  190. '1234567890',
  191. $rsa->decrypt($encrypted, $rsa->getPrivateKey())
  192. );
  193. }
  194. public function testEncryptionUsingPublicKeyBase64Encryption()
  195. {
  196. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  197. $encrypted = $rsa->encrypt('1234567890', $rsa->getPublicKey(), Zend_Crypt_Rsa::BASE64);
  198. $this->assertEquals(
  199. '1234567890',
  200. $rsa->decrypt($encrypted, $rsa->getPrivateKey(), Zend_Crypt_Rsa::BASE64)
  201. );
  202. }
  203. public function testBase64EncryptionUsingCertificatePublicKeyEncryption()
  204. {
  205. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  206. $encrypted = $rsa->encrypt('1234567890', $rsa->getPublicKey(), Zend_Crypt_Rsa::BASE64);
  207. $rsa2 = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  208. $this->assertEquals(
  209. '1234567890',
  210. $rsa->decrypt($encrypted, $rsa2->getPrivateKey(), Zend_Crypt_Rsa::BASE64)
  211. );
  212. }
  213. public function testEncryptionUsingPrivateKeyEncryption()
  214. {
  215. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  216. $encrypted = $rsa->encrypt('1234567890', $rsa->getPrivateKey());
  217. $this->assertEquals(
  218. '1234567890',
  219. $rsa->decrypt($encrypted, $rsa->getPublicKey())
  220. );
  221. }
  222. public function testEncryptionUsingPrivateKeyBase64Encryption()
  223. {
  224. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  225. $encrypted = $rsa->encrypt('1234567890', $rsa->getPrivateKey(), Zend_Crypt_Rsa::BASE64);
  226. $this->assertEquals(
  227. '1234567890',
  228. $rsa->decrypt($encrypted, $rsa->getPublicKey(), Zend_Crypt_Rsa::BASE64)
  229. );
  230. }
  231. public function testKeyGenerationCreatesArrayObjectResult()
  232. {
  233. $rsa = new Zend_Crypt_Rsa;
  234. // check to see if openssl.cnf can be found by trying to generate a key
  235. $test = openssl_pkey_new();
  236. if (!$test) {
  237. $this->markTestSkipped('Cannot generate a private key with openssl_pkey_new()');
  238. }
  239. $keys = $rsa->generateKeys(array('private_key_bits'=>512));
  240. $this->assertTrue($keys instanceof ArrayObject);
  241. }
  242. public function testKeyGenerationCreatesPrivateKeyInArrayObject()
  243. {
  244. $rsa = new Zend_Crypt_Rsa;
  245. // check to see if openssl.cnf can be found by trying to generate a key
  246. $test = openssl_pkey_new();
  247. if (!$test) {
  248. $this->markTestSkipped('Cannot generate a private key with openssl_pkey_new()');
  249. }
  250. $keys = $rsa->generateKeys(array('private_key_bits'=>512));
  251. $this->assertTrue($keys->privateKey instanceof Zend_Crypt_Rsa_Key_Private);
  252. }
  253. public function testKeyGenerationCreatesPublicKeyInArrayObject()
  254. {
  255. $rsa = new Zend_Crypt_Rsa;
  256. // check to see if openssl.cnf can be found by trying to generate a key
  257. $test = openssl_pkey_new();
  258. if (!$test) {
  259. $this->markTestSkipped('Cannot generate a private key with openssl_pkey_new()');
  260. }
  261. $keys = $rsa->generateKeys(array('privateKeyBits'=>512));
  262. $this->assertTrue($keys->publicKey instanceof Zend_Crypt_Rsa_Key_Public);
  263. }
  264. public function testKeyGenerationCreatesPassphrasedPrivateKey()
  265. {
  266. $rsa = new Zend_Crypt_Rsa;
  267. // check to see if openssl.cnf can be found by trying to generate a key
  268. $test = openssl_pkey_new();
  269. if (!$test) {
  270. $this->markTestSkipped('Cannot generate a private key with openssl_pkey_new()');
  271. }
  272. $config = array(
  273. 'privateKeyBits' => 512,
  274. 'passPhrase' => '0987654321'
  275. );
  276. $keys = $rsa->generateKeys($config);
  277. try {
  278. $rsa = new Zend_Crypt_Rsa(array(
  279. 'passPhrase'=>'1234567890',
  280. 'pemString'=>$keys->privateKey->toString()
  281. ));
  282. $this->fail('Expected exception not thrown');
  283. } catch (Zend_Crypt_Exception $e) {
  284. }
  285. }
  286. public function testConstructorLoadsPassphrasedKeys()
  287. {
  288. $rsa = new Zend_Crypt_Rsa;
  289. // check to see if openssl.cnf can be found by trying to generate a key
  290. $test = openssl_pkey_new();
  291. if (!$test) {
  292. $this->markTestSkipped('Cannot generate a private key with openssl_pkey_new()');
  293. }
  294. $config = array(
  295. 'privateKeyBits' => 512,
  296. 'passPhrase' => '0987654321'
  297. );
  298. $keys = $rsa->generateKeys($config);
  299. try {
  300. $rsa = new Zend_Crypt_Rsa(array(
  301. 'passPhrase'=>'0987654321',
  302. 'pemString'=>$keys->privateKey->toString()
  303. ));
  304. } catch (Zend_Crypt_Exception $e) {
  305. $this->fail('Passphrase loading failed of a private key');
  306. }
  307. }
  308. /**
  309. * @group ZF-8846
  310. */
  311. public function testLoadsPublicKeyFromPEMWithoutPrivateKeyAndThrowsNoException()
  312. {
  313. $rsa = new Zend_Crypt_Rsa;
  314. $rsa->setPemString($this->_testPemStringPublic);
  315. }
  316. }