xref: /aosp_15_r20/system/security/ondevice-signing/tests/SigningUtilsTest.cpp (revision e1997b9af69e3155ead6e072d106a0077849ffba)
1*e1997b9aSAndroid Build Coastguard Worker /*
2*e1997b9aSAndroid Build Coastguard Worker  * Copyright (C) 2021 The Android Open Source Project
3*e1997b9aSAndroid Build Coastguard Worker  *
4*e1997b9aSAndroid Build Coastguard Worker  * Licensed under the Apache License, Version 2.0 (the "License");
5*e1997b9aSAndroid Build Coastguard Worker  * you may not use this file except in compliance with the License.
6*e1997b9aSAndroid Build Coastguard Worker  * You may obtain a copy of the License at
7*e1997b9aSAndroid Build Coastguard Worker  *
8*e1997b9aSAndroid Build Coastguard Worker  *      http://www.apache.org/licenses/LICENSE-2.0
9*e1997b9aSAndroid Build Coastguard Worker  *
10*e1997b9aSAndroid Build Coastguard Worker  * Unless required by applicable law or agreed to in writing, software
11*e1997b9aSAndroid Build Coastguard Worker  * distributed under the License is distributed on an "AS IS" BASIS,
12*e1997b9aSAndroid Build Coastguard Worker  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13*e1997b9aSAndroid Build Coastguard Worker  * See the License for the specific language governing permissions and
14*e1997b9aSAndroid Build Coastguard Worker  * limitations under the License.
15*e1997b9aSAndroid Build Coastguard Worker  */
16*e1997b9aSAndroid Build Coastguard Worker 
17*e1997b9aSAndroid Build Coastguard Worker #include <android-base/file.h>
18*e1997b9aSAndroid Build Coastguard Worker #include <gtest/gtest.h>
19*e1997b9aSAndroid Build Coastguard Worker 
20*e1997b9aSAndroid Build Coastguard Worker #include "CertUtils.h"
21*e1997b9aSAndroid Build Coastguard Worker #include "VerityUtils.h"
22*e1997b9aSAndroid Build Coastguard Worker 
23*e1997b9aSAndroid Build Coastguard Worker // These files were created using the following commands:
24*e1997b9aSAndroid Build Coastguard Worker // openssl genrsa -out SigningUtils.pem 4096
25*e1997b9aSAndroid Build Coastguard Worker // openssl req -new -x509 -key SigningUtils.pem -out SigningUtils.cert.pem
26*e1997b9aSAndroid Build Coastguard Worker // openssl x509 -in SigningUtils.cert.pem -out SigningUtils.cert.der -outform DER
27*e1997b9aSAndroid Build Coastguard Worker // head -c 4096 </dev/urandom >test_file
28*e1997b9aSAndroid Build Coastguard Worker // openssl dgst -sign SigningUtils.pem -keyform PEM -sha256 -out test_file.sig -binary test_file
29*e1997b9aSAndroid Build Coastguard Worker const std::string kTestCert = "SigningUtils.cert.der";
30*e1997b9aSAndroid Build Coastguard Worker const std::string kTestFile = "test_file";
31*e1997b9aSAndroid Build Coastguard Worker const std::string kTestFileSignature = "test_file.sig";
32*e1997b9aSAndroid Build Coastguard Worker 
TEST(SigningUtilsTest,CheckVerifySignature)33*e1997b9aSAndroid Build Coastguard Worker TEST(SigningUtilsTest, CheckVerifySignature) {
34*e1997b9aSAndroid Build Coastguard Worker     std::string signature;
35*e1997b9aSAndroid Build Coastguard Worker     std::string sigFile = android::base::GetExecutableDirectory() + "/" + kTestFileSignature;
36*e1997b9aSAndroid Build Coastguard Worker     ASSERT_TRUE(android::base::ReadFileToString(sigFile, &signature));
37*e1997b9aSAndroid Build Coastguard Worker 
38*e1997b9aSAndroid Build Coastguard Worker     std::string data;
39*e1997b9aSAndroid Build Coastguard Worker     std::string testFile = android::base::GetExecutableDirectory() + "/" + kTestFile;
40*e1997b9aSAndroid Build Coastguard Worker     ASSERT_TRUE(android::base::ReadFileToString(testFile, &data));
41*e1997b9aSAndroid Build Coastguard Worker 
42*e1997b9aSAndroid Build Coastguard Worker     std::string testCert = android::base::GetExecutableDirectory() + "/" + kTestCert;
43*e1997b9aSAndroid Build Coastguard Worker     auto trustedKey = extractPublicKeyFromX509(testCert.c_str());
44*e1997b9aSAndroid Build Coastguard Worker     ASSERT_TRUE(trustedKey.ok());
45*e1997b9aSAndroid Build Coastguard Worker 
46*e1997b9aSAndroid Build Coastguard Worker     auto result = verifySignature(data, signature, *trustedKey);
47*e1997b9aSAndroid Build Coastguard Worker     ASSERT_TRUE(result.ok());
48*e1997b9aSAndroid Build Coastguard Worker }
49