RsaTest.php 14 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369
  1. <?php
  2. /**
  3. * Zend Framework
  4. *
  5. * LICENSE
  6. *
  7. * This source file is subject to the new BSD license that is bundled
  8. * with this package in the file LICENSE.txt.
  9. * It is also available through the world-wide-web at this URL:
  10. * http://framework.zend.com/license/new-bsd
  11. * If you did not receive a copy of the license and are unable to
  12. * obtain it through the world-wide-web, please send an email
  13. * to license@zend.com so we can send you a copy immediately.
  14. *
  15. * @category Zend
  16. * @package Zend_Crypt
  17. * @subpackage UnitTests
  18. * @copyright Copyright (c) 2005-2012 Zend Technologies USA Inc. (http://www.zend.com)
  19. * @license http://framework.zend.com/license/new-bsd New BSD License
  20. * @version $Id$
  21. */
  22. require_once 'Zend/Crypt/Rsa.php';
  23. /**
  24. * @category Zend
  25. * @package Zend_Crypt
  26. * @subpackage UnitTests
  27. * @copyright Copyright (c) 2005-2012 Zend Technologies USA Inc. (http://www.zend.com)
  28. * @license http://framework.zend.com/license/new-bsd New BSD License
  29. * @group Zend_Crypt
  30. */
  31. class Zend_Crypt_RsaTest extends PHPUnit_Framework_TestCase
  32. {
  33. protected $_testPemString = null;
  34. protected $_testPemPath = null;
  35. public function setUp()
  36. {
  37. try {
  38. $rsaObject = new Zend_Crypt_Rsa();
  39. } catch (Zend_Crypt_Rsa_Exception $e) {
  40. if (strpos($e->getMessage(), 'requires openssl extension') !== false) {
  41. $this->markTestSkipped($e->getMessage());
  42. } else {
  43. throw $e;
  44. }
  45. }
  46. $this->_testPemString = <<<RSAKEY
  47. -----BEGIN RSA PRIVATE KEY-----
  48. MIIBOgIBAAJBANDiE2+Xi/WnO+s120NiiJhNyIButVu6zxqlVzz0wy2j4kQVUC4Z
  49. RZD80IY+4wIiX2YxKBZKGnd2TtPkcJ/ljkUCAwEAAQJAL151ZeMKHEU2c1qdRKS9
  50. sTxCcc2pVwoAGVzRccNX16tfmCf8FjxuM3WmLdsPxYoHrwb1LFNxiNk1MXrxjH3R
  51. 6QIhAPB7edmcjH4bhMaJBztcbNE1VRCEi/bisAwiPPMq9/2nAiEA3lyc5+f6DEIJ
  52. h1y6BWkdVULDSM+jpi1XiV/DevxuijMCIQCAEPGqHsF+4v7Jj+3HAgh9PU6otj2n
  53. Y79nJtCYmvhoHwIgNDePaS4inApN7omp7WdXyhPZhBmulnGDYvEoGJN66d0CIHra
  54. I2SvDkQ5CmrzkW5qPaE2oO7BSqAhRZxiYpZFb5CI
  55. -----END RSA PRIVATE KEY-----
  56. RSAKEY;
  57. $this->_testPemStringPublic = <<<RSAKEY
  58. -----BEGIN PUBLIC KEY-----
  59. MFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDiE2+Xi/WnO+s120NiiJhNyIButVu6
  60. zxqlVzz0wy2j4kQVUC4ZRZD80IY+4wIiX2YxKBZKGnd2TtPkcJ/ljkUCAwEAAQ==
  61. -----END PUBLIC KEY-----
  62. RSAKEY;
  63. $this->_testCertificateString = <<<CERT
  64. -----BEGIN CERTIFICATE-----
  65. MIIC6TCCApOgAwIBAgIBADANBgkqhkiG9w0BAQQFADCBhzELMAkGA1UEBhMCSUUx
  66. DzANBgNVBAgTBkR1YmxpbjEPMA0GA1UEBxMGRHVibGluMQ4wDAYDVQQKEwVHcm91
  67. cDERMA8GA1UECxMIU3ViZ3JvdXAxEzARBgNVBAMTCkpvZSBCbG9nZ3MxHjAcBgkq
  68. hkiG9w0BCQEWD2pvZUBleGFtcGxlLmNvbTAeFw0wODA2MTMwOTQ4NDlaFw0xMTA2
  69. MTMwOTQ4NDlaMIGHMQswCQYDVQQGEwJJRTEPMA0GA1UECBMGRHVibGluMQ8wDQYD
  70. VQQHEwZEdWJsaW4xDjAMBgNVBAoTBUdyb3VwMREwDwYDVQQLEwhTdWJncm91cDET
  71. MBEGA1UEAxMKSm9lIEJsb2dnczEeMBwGCSqGSIb3DQEJARYPam9lQGV4YW1wbGUu
  72. Y29tMFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBANDiE2+Xi/WnO+s120NiiJhNyIBu
  73. tVu6zxqlVzz0wy2j4kQVUC4ZRZD80IY+4wIiX2YxKBZKGnd2TtPkcJ/ljkUCAwEA
  74. AaOB5zCB5DAdBgNVHQ4EFgQUxpguR0f4g+502IxAp3aMZvJ6asMwgbQGA1UdIwSB
  75. rDCBqYAUxpguR0f4g+502IxAp3aMZvJ6asOhgY2kgYowgYcxCzAJBgNVBAYTAklF
  76. MQ8wDQYDVQQIEwZEdWJsaW4xDzANBgNVBAcTBkR1YmxpbjEOMAwGA1UEChMFR3Jv
  77. dXAxETAPBgNVBAsTCFN1Ymdyb3VwMRMwEQYDVQQDEwpKb2UgQmxvZ2dzMR4wHAYJ
  78. KoZIhvcNAQkBFg9qb2VAZXhhbXBsZS5jb22CAQAwDAYDVR0TBAUwAwEB/zANBgkq
  79. hkiG9w0BAQQFAANBAE4M7ZXJTDLHEFguGaP5g64lbmLmLtYX22ZaNY891FmxhtKm
  80. l9Nwj3KnPKFdqzJchujP2TLNwSYoQnxgyoMxdho=
  81. -----END CERTIFICATE-----
  82. CERT;
  83. $this->_testPemPath = dirname(__FILE__) . '/_files/test.pem';
  84. $this->_testCertificatePath = dirname(__FILE__) . '/_files/test.cert';
  85. }
  86. public function testConstructorSetsPemString()
  87. {
  88. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  89. $this->assertEquals($this->_testPemString, $rsa->getPemString());
  90. }
  91. public function testConstructorSetsPemPath()
  92. {
  93. $rsa = new Zend_Crypt_Rsa(array('pemPath'=>$this->_testPemPath));
  94. $this->assertEquals($this->_testPemPath, $rsa->getPemPath());
  95. }
  96. public function testSetPemPathLoadsPemString()
  97. {
  98. $rsa = new Zend_Crypt_Rsa(array('pemPath'=>$this->_testPemPath));
  99. $this->assertEquals($this->_testPemString, $rsa->getPemString());
  100. }
  101. public function testConstructorSetsCertificateString()
  102. {
  103. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  104. $this->assertEquals($this->_testCertificateString, $rsa->getCertificateString());
  105. }
  106. public function testConstructorSetsCertificatePath()
  107. {
  108. $rsa = new Zend_Crypt_Rsa(array('certificatePath'=>$this->_testCertificatePath));
  109. $this->assertEquals($this->_testCertificatePath, $rsa->getCertificatePath());
  110. }
  111. public function testSetCertificatePathLoadsCertificateString()
  112. {
  113. $rsa = new Zend_Crypt_Rsa(array('certificatePath'=>$this->_testCertificatePath));
  114. $this->assertEquals($this->_testCertificateString, $rsa->getCertificateString());
  115. }
  116. public function testConstructorSetsHashOption()
  117. {
  118. if (!defined('OPENSSL_ALGO_MD2')) {
  119. $this->markTestSkipped('The OPENSSL_ALGO_MD2 constant is not defined in this PHP instance.');
  120. }
  121. $rsa = new Zend_Crypt_Rsa(array('hashAlgorithm'=>'md2'));
  122. $this->assertEquals(OPENSSL_ALGO_MD2, $rsa->getHashAlgorithm());
  123. }
  124. public function testSetPemStringParsesPemForPrivateKey()
  125. {
  126. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  127. $this->assertType('Zend_Crypt_Rsa_Key_Private', $rsa->getPrivateKey());
  128. }
  129. public function testSetPemStringParsesPemForPublicKey()
  130. {
  131. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  132. $this->assertType('Zend_Crypt_Rsa_Key_Public', $rsa->getPublicKey());
  133. }
  134. public function testSetCertificateStringParsesCertificateForNullPrivateKey()
  135. {
  136. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  137. $this->assertEquals(null, $rsa->getPrivateKey());
  138. }
  139. public function testSetCertificateStringParsesCertificateForPublicKey()
  140. {
  141. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  142. $this->assertType('Zend_Crypt_Rsa_Key_Public', $rsa->getPublicKey());
  143. }
  144. public function testSignGeneratesExpectedBinarySignature()
  145. {
  146. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  147. $signature = $rsa->sign('1234567890');
  148. $this->assertEquals(
  149. 'sMHpp3u6DNecIm5RIkDD3xyKaH6qqP8roUWDs215iOGHehfK1ypqwoETKNP7NaksGS2C1Up813ixlGXkipPVbQ==',
  150. base64_encode($signature));
  151. }
  152. public function testSignGeneratesExpectedBinarySignatureUsingExternalKey()
  153. {
  154. $privateKey = new Zend_Crypt_Rsa_Key_Private($this->_testPemString);
  155. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  156. $signature = $rsa->sign('1234567890', $privateKey);
  157. $this->assertEquals(
  158. 'sMHpp3u6DNecIm5RIkDD3xyKaH6qqP8roUWDs215iOGHehfK1ypqwoETKNP7NaksGS2C1Up813ixlGXkipPVbQ==',
  159. base64_encode($signature));
  160. }
  161. public function testSignGeneratesExpectedBase64Signature()
  162. {
  163. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  164. $signature = $rsa->sign('1234567890', null, Zend_Crypt_Rsa::BASE64);
  165. $this->assertEquals(
  166. 'sMHpp3u6DNecIm5RIkDD3xyKaH6qqP8roUWDs215iOGHehfK1ypqwoETKNP7NaksGS2C1Up813ixlGXkipPVbQ==',
  167. $signature);
  168. }
  169. public function testVerifyVerifiesBinarySignatures()
  170. {
  171. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  172. $signature = $rsa->sign('1234567890');
  173. $result = $rsa->verifySignature('1234567890', $signature);
  174. $this->assertEquals(1, $result);
  175. }
  176. public function testVerifyVerifiesBinarySignaturesUsingCertificate()
  177. {
  178. $privateKey = new Zend_Crypt_Rsa_Key_Private($this->_testPemString);
  179. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  180. $signature = $rsa->sign('1234567890', $privateKey);
  181. $result = $rsa->verifySignature('1234567890', $signature);
  182. $this->assertEquals(1, $result);
  183. }
  184. public function testVerifyVerifiesBase64Signatures()
  185. {
  186. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  187. $signature = $rsa->sign('1234567890', null, Zend_Crypt_Rsa::BASE64);
  188. $result = $rsa->verifySignature('1234567890', $signature, Zend_Crypt_Rsa::BASE64);
  189. $this->assertEquals(1, $result);
  190. }
  191. public function testEncryptionUsingPublicKeyEncryption()
  192. {
  193. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  194. $encrypted = $rsa->encrypt('1234567890', $rsa->getPublicKey());
  195. $this->assertEquals(
  196. '1234567890',
  197. $rsa->decrypt($encrypted, $rsa->getPrivateKey())
  198. );
  199. }
  200. public function testEncryptionUsingPublicKeyBase64Encryption()
  201. {
  202. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  203. $encrypted = $rsa->encrypt('1234567890', $rsa->getPublicKey(), Zend_Crypt_Rsa::BASE64);
  204. $this->assertEquals(
  205. '1234567890',
  206. $rsa->decrypt($encrypted, $rsa->getPrivateKey(), Zend_Crypt_Rsa::BASE64)
  207. );
  208. }
  209. public function testBase64EncryptionUsingCertificatePublicKeyEncryption()
  210. {
  211. $rsa = new Zend_Crypt_Rsa(array('certificateString'=>$this->_testCertificateString));
  212. $encrypted = $rsa->encrypt('1234567890', $rsa->getPublicKey(), Zend_Crypt_Rsa::BASE64);
  213. $rsa2 = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  214. $this->assertEquals(
  215. '1234567890',
  216. $rsa->decrypt($encrypted, $rsa2->getPrivateKey(), Zend_Crypt_Rsa::BASE64)
  217. );
  218. }
  219. public function testEncryptionUsingPrivateKeyEncryption()
  220. {
  221. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  222. $encrypted = $rsa->encrypt('1234567890', $rsa->getPrivateKey());
  223. $this->assertEquals(
  224. '1234567890',
  225. $rsa->decrypt($encrypted, $rsa->getPublicKey())
  226. );
  227. }
  228. public function testEncryptionUsingPrivateKeyBase64Encryption()
  229. {
  230. $rsa = new Zend_Crypt_Rsa(array('pemString'=>$this->_testPemString));
  231. $encrypted = $rsa->encrypt('1234567890', $rsa->getPrivateKey(), Zend_Crypt_Rsa::BASE64);
  232. $this->assertEquals(
  233. '1234567890',
  234. $rsa->decrypt($encrypted, $rsa->getPublicKey(), Zend_Crypt_Rsa::BASE64)
  235. );
  236. }
  237. public function testKeyGenerationCreatesArrayObjectResult()
  238. {
  239. $rsa = new Zend_Crypt_Rsa;
  240. // check to see if openssl.cnf can be found by trying to generate a key
  241. $test = openssl_pkey_new();
  242. if (!$test) {
  243. $this->markTestSkipped('Cannot generate a private key with openssl_pkey_new()');
  244. }
  245. $keys = $rsa->generateKeys(array('private_key_bits'=>512));
  246. $this->assertType('ArrayObject', $keys);
  247. }
  248. public function testKeyGenerationCreatesPrivateKeyInArrayObject()
  249. {
  250. $rsa = new Zend_Crypt_Rsa;
  251. // check to see if openssl.cnf can be found by trying to generate a key
  252. $test = openssl_pkey_new();
  253. if (!$test) {
  254. $this->markTestSkipped('Cannot generate a private key with openssl_pkey_new()');
  255. }
  256. $keys = $rsa->generateKeys(array('private_key_bits'=>512));
  257. $this->assertType('Zend_Crypt_Rsa_Key_Private', $keys->privateKey);
  258. }
  259. public function testKeyGenerationCreatesPublicKeyInArrayObject()
  260. {
  261. $rsa = new Zend_Crypt_Rsa;
  262. // check to see if openssl.cnf can be found by trying to generate a key
  263. $test = openssl_pkey_new();
  264. if (!$test) {
  265. $this->markTestSkipped('Cannot generate a private key with openssl_pkey_new()');
  266. }
  267. $keys = $rsa->generateKeys(array('privateKeyBits'=>512));
  268. $this->assertType('Zend_Crypt_Rsa_Key_Public', $keys->publicKey);
  269. }
  270. public function testKeyGenerationCreatesPassphrasedPrivateKey()
  271. {
  272. $rsa = new Zend_Crypt_Rsa;
  273. // check to see if openssl.cnf can be found by trying to generate a key
  274. $test = openssl_pkey_new();
  275. if (!$test) {
  276. $this->markTestSkipped('Cannot generate a private key with openssl_pkey_new()');
  277. }
  278. $config = array(
  279. 'privateKeyBits' => 512,
  280. 'passPhrase' => '0987654321'
  281. );
  282. $keys = $rsa->generateKeys($config);
  283. try {
  284. $rsa = new Zend_Crypt_Rsa(array(
  285. 'passPhrase'=>'1234567890',
  286. 'pemString'=>$keys->privateKey->toString()
  287. ));
  288. $this->fail('Expected exception not thrown');
  289. } catch (Zend_Crypt_Exception $e) {
  290. }
  291. }
  292. public function testConstructorLoadsPassphrasedKeys()
  293. {
  294. $rsa = new Zend_Crypt_Rsa;
  295. // check to see if openssl.cnf can be found by trying to generate a key
  296. $test = openssl_pkey_new();
  297. if (!$test) {
  298. $this->markTestSkipped('Cannot generate a private key with openssl_pkey_new()');
  299. }
  300. $config = array(
  301. 'privateKeyBits' => 512,
  302. 'passPhrase' => '0987654321'
  303. );
  304. $keys = $rsa->generateKeys($config);
  305. try {
  306. $rsa = new Zend_Crypt_Rsa(array(
  307. 'passPhrase'=>'0987654321',
  308. 'pemString'=>$keys->privateKey->toString()
  309. ));
  310. } catch (Zend_Crypt_Exception $e) {
  311. $this->fail('Passphrase loading failed of a private key');
  312. }
  313. }
  314. /**
  315. * @group ZF-8846
  316. */
  317. public function testLoadsPublicKeyFromPEMWithoutPrivateKeyAndThrowsNoException()
  318. {
  319. $rsa = new Zend_Crypt_Rsa;
  320. $rsa->setPemString($this->_testPemStringPublic);
  321. }
  322. }