test_suite_rsa.function 78 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865
  1. /* BEGIN_HEADER */
  2. #include "mbedtls/rsa.h"
  3. #include "mbedtls/rsa_internal.h"
  4. #include "mbedtls/md2.h"
  5. #include "mbedtls/md4.h"
  6. #include "mbedtls/md5.h"
  7. #include "mbedtls/sha1.h"
  8. #include "mbedtls/sha256.h"
  9. #include "mbedtls/sha512.h"
  10. #include "mbedtls/entropy.h"
  11. #include "mbedtls/ctr_drbg.h"
  12. /* END_HEADER */
  13. /* BEGIN_DEPENDENCIES
  14. * depends_on:MBEDTLS_RSA_C:MBEDTLS_BIGNUM_C:MBEDTLS_GENPRIME
  15. * END_DEPENDENCIES
  16. */
  17. /* BEGIN_CASE depends_on:MBEDTLS_CHECK_PARAMS:!MBEDTLS_PARAM_FAILED_ALT */
  18. void rsa_invalid_param( )
  19. {
  20. mbedtls_rsa_context ctx;
  21. const int valid_padding = MBEDTLS_RSA_PKCS_V21;
  22. const int invalid_padding = 42;
  23. const int valid_mode = MBEDTLS_RSA_PRIVATE;
  24. const int invalid_mode = 42;
  25. unsigned char buf[42] = { 0 };
  26. size_t olen;
  27. TEST_INVALID_PARAM( mbedtls_rsa_init( NULL, valid_padding, 0 ) );
  28. TEST_INVALID_PARAM( mbedtls_rsa_init( &ctx, invalid_padding, 0 ) );
  29. TEST_VALID_PARAM( mbedtls_rsa_free( NULL ) );
  30. /* No more variants because only the first argument must be non-NULL. */
  31. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  32. mbedtls_rsa_import( NULL, NULL, NULL,
  33. NULL, NULL, NULL ) );
  34. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  35. mbedtls_rsa_import_raw( NULL,
  36. NULL, 0,
  37. NULL, 0,
  38. NULL, 0,
  39. NULL, 0,
  40. NULL, 0 ) );
  41. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  42. mbedtls_rsa_complete( NULL ) );
  43. /* No more variants because only the first argument must be non-NULL. */
  44. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  45. mbedtls_rsa_export( NULL, NULL, NULL,
  46. NULL, NULL, NULL ) );
  47. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  48. mbedtls_rsa_export_raw( NULL,
  49. NULL, 0,
  50. NULL, 0,
  51. NULL, 0,
  52. NULL, 0,
  53. NULL, 0 ) );
  54. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  55. mbedtls_rsa_export_crt( NULL, NULL, NULL, NULL ) );
  56. TEST_INVALID_PARAM( mbedtls_rsa_set_padding( NULL,
  57. valid_padding, 0 ) );
  58. TEST_INVALID_PARAM( mbedtls_rsa_set_padding( &ctx,
  59. invalid_padding, 0 ) );
  60. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  61. mbedtls_rsa_gen_key( NULL,
  62. mbedtls_test_rnd_std_rand,
  63. NULL, 0, 0 ) );
  64. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  65. mbedtls_rsa_gen_key( &ctx, NULL,
  66. NULL, 0, 0 ) );
  67. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  68. mbedtls_rsa_check_pubkey( NULL ) );
  69. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  70. mbedtls_rsa_check_privkey( NULL ) );
  71. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  72. mbedtls_rsa_check_pub_priv( NULL, &ctx ) );
  73. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  74. mbedtls_rsa_check_pub_priv( &ctx, NULL ) );
  75. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  76. mbedtls_rsa_public( NULL, buf, buf ) );
  77. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  78. mbedtls_rsa_public( &ctx, NULL, buf ) );
  79. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  80. mbedtls_rsa_public( &ctx, buf, NULL ) );
  81. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  82. mbedtls_rsa_private( NULL, NULL, NULL,
  83. buf, buf ) );
  84. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  85. mbedtls_rsa_private( &ctx, NULL, NULL,
  86. NULL, buf ) );
  87. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  88. mbedtls_rsa_private( &ctx, NULL, NULL,
  89. buf, NULL ) );
  90. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  91. mbedtls_rsa_pkcs1_encrypt( NULL, NULL, NULL,
  92. valid_mode,
  93. sizeof( buf ), buf,
  94. buf ) );
  95. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  96. mbedtls_rsa_pkcs1_encrypt( &ctx, NULL, NULL,
  97. invalid_mode,
  98. sizeof( buf ), buf,
  99. buf ) );
  100. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  101. mbedtls_rsa_pkcs1_encrypt( &ctx, NULL, NULL,
  102. valid_mode,
  103. sizeof( buf ), NULL,
  104. buf ) );
  105. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  106. mbedtls_rsa_pkcs1_encrypt( &ctx, NULL, NULL,
  107. valid_mode,
  108. sizeof( buf ), buf,
  109. NULL ) );
  110. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  111. mbedtls_rsa_rsaes_pkcs1_v15_encrypt( NULL, NULL,
  112. NULL,
  113. valid_mode,
  114. sizeof( buf ), buf,
  115. buf ) );
  116. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  117. mbedtls_rsa_rsaes_pkcs1_v15_encrypt( &ctx, NULL,
  118. NULL,
  119. invalid_mode,
  120. sizeof( buf ), buf,
  121. buf ) );
  122. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  123. mbedtls_rsa_rsaes_pkcs1_v15_encrypt( &ctx, NULL,
  124. NULL,
  125. valid_mode,
  126. sizeof( buf ), NULL,
  127. buf ) );
  128. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  129. mbedtls_rsa_rsaes_pkcs1_v15_encrypt( &ctx, NULL,
  130. NULL,
  131. valid_mode,
  132. sizeof( buf ), buf,
  133. NULL ) );
  134. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  135. mbedtls_rsa_rsaes_oaep_encrypt( NULL, NULL, NULL,
  136. valid_mode,
  137. buf, sizeof( buf ),
  138. sizeof( buf ), buf,
  139. buf ) );
  140. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  141. mbedtls_rsa_rsaes_oaep_encrypt( &ctx, NULL, NULL,
  142. invalid_mode,
  143. buf, sizeof( buf ),
  144. sizeof( buf ), buf,
  145. buf ) );
  146. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  147. mbedtls_rsa_rsaes_oaep_encrypt( &ctx, NULL, NULL,
  148. valid_mode,
  149. NULL, sizeof( buf ),
  150. sizeof( buf ), buf,
  151. buf ) );
  152. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  153. mbedtls_rsa_rsaes_oaep_encrypt( &ctx, NULL, NULL,
  154. valid_mode,
  155. buf, sizeof( buf ),
  156. sizeof( buf ), NULL,
  157. buf ) );
  158. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  159. mbedtls_rsa_rsaes_oaep_encrypt( &ctx, NULL, NULL,
  160. valid_mode,
  161. buf, sizeof( buf ),
  162. sizeof( buf ), buf,
  163. NULL ) );
  164. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  165. mbedtls_rsa_pkcs1_decrypt( NULL, NULL, NULL,
  166. valid_mode, &olen,
  167. buf, buf, 42 ) );
  168. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  169. mbedtls_rsa_pkcs1_decrypt( &ctx, NULL, NULL,
  170. invalid_mode, &olen,
  171. buf, buf, 42 ) );
  172. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  173. mbedtls_rsa_pkcs1_decrypt( &ctx, NULL, NULL,
  174. valid_mode, NULL,
  175. buf, buf, 42 ) );
  176. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  177. mbedtls_rsa_pkcs1_decrypt( &ctx, NULL, NULL,
  178. valid_mode, &olen,
  179. NULL, buf, 42 ) );
  180. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  181. mbedtls_rsa_pkcs1_decrypt( &ctx, NULL, NULL,
  182. valid_mode, &olen,
  183. buf, NULL, 42 ) );
  184. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  185. mbedtls_rsa_rsaes_pkcs1_v15_decrypt( NULL, NULL,
  186. NULL,
  187. valid_mode, &olen,
  188. buf, buf, 42 ) );
  189. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  190. mbedtls_rsa_rsaes_pkcs1_v15_decrypt( &ctx, NULL,
  191. NULL,
  192. invalid_mode, &olen,
  193. buf, buf, 42 ) );
  194. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  195. mbedtls_rsa_rsaes_pkcs1_v15_decrypt( &ctx, NULL,
  196. NULL,
  197. valid_mode, NULL,
  198. buf, buf, 42 ) );
  199. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  200. mbedtls_rsa_rsaes_pkcs1_v15_decrypt( &ctx, NULL,
  201. NULL,
  202. valid_mode, &olen,
  203. NULL, buf, 42 ) );
  204. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  205. mbedtls_rsa_rsaes_pkcs1_v15_decrypt( &ctx, NULL,
  206. NULL,
  207. valid_mode, &olen,
  208. buf, NULL, 42 ) );
  209. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  210. mbedtls_rsa_rsaes_oaep_decrypt( NULL, NULL, NULL,
  211. valid_mode,
  212. buf, sizeof( buf ),
  213. &olen,
  214. buf, buf, 42 ) );
  215. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  216. mbedtls_rsa_rsaes_oaep_decrypt( &ctx, NULL, NULL,
  217. invalid_mode,
  218. buf, sizeof( buf ),
  219. &olen,
  220. buf, buf, 42 ) );
  221. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  222. mbedtls_rsa_rsaes_oaep_decrypt( &ctx, NULL, NULL,
  223. valid_mode,
  224. NULL, sizeof( buf ),
  225. NULL,
  226. buf, buf, 42 ) );
  227. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  228. mbedtls_rsa_rsaes_oaep_decrypt( &ctx, NULL, NULL,
  229. valid_mode,
  230. buf, sizeof( buf ),
  231. &olen,
  232. NULL, buf, 42 ) );
  233. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  234. mbedtls_rsa_rsaes_oaep_decrypt( &ctx, NULL, NULL,
  235. valid_mode,
  236. buf, sizeof( buf ),
  237. &olen,
  238. buf, NULL, 42 ) );
  239. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  240. mbedtls_rsa_pkcs1_sign( NULL, NULL, NULL,
  241. valid_mode,
  242. 0, sizeof( buf ), buf,
  243. buf ) );
  244. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  245. mbedtls_rsa_pkcs1_sign( &ctx, NULL, NULL,
  246. invalid_mode,
  247. 0, sizeof( buf ), buf,
  248. buf ) );
  249. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  250. mbedtls_rsa_pkcs1_sign( &ctx, NULL, NULL,
  251. valid_mode,
  252. 0, sizeof( buf ), NULL,
  253. buf ) );
  254. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  255. mbedtls_rsa_pkcs1_sign( &ctx, NULL, NULL,
  256. valid_mode,
  257. 0, sizeof( buf ), buf,
  258. NULL ) );
  259. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  260. mbedtls_rsa_pkcs1_sign( &ctx, NULL, NULL,
  261. valid_mode,
  262. MBEDTLS_MD_SHA1,
  263. 0, NULL,
  264. buf ) );
  265. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  266. mbedtls_rsa_rsassa_pkcs1_v15_sign( NULL, NULL, NULL,
  267. valid_mode,
  268. 0, sizeof( buf ), buf,
  269. buf ) );
  270. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  271. mbedtls_rsa_rsassa_pkcs1_v15_sign( &ctx, NULL, NULL,
  272. invalid_mode,
  273. 0, sizeof( buf ), buf,
  274. buf ) );
  275. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  276. mbedtls_rsa_rsassa_pkcs1_v15_sign( &ctx, NULL, NULL,
  277. valid_mode,
  278. 0, sizeof( buf ), NULL,
  279. buf ) );
  280. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  281. mbedtls_rsa_rsassa_pkcs1_v15_sign( &ctx, NULL, NULL,
  282. valid_mode,
  283. 0, sizeof( buf ), buf,
  284. NULL ) );
  285. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  286. mbedtls_rsa_rsassa_pkcs1_v15_sign( &ctx, NULL, NULL,
  287. valid_mode,
  288. MBEDTLS_MD_SHA1,
  289. 0, NULL,
  290. buf ) );
  291. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  292. mbedtls_rsa_rsassa_pss_sign( NULL, NULL, NULL,
  293. valid_mode,
  294. 0, sizeof( buf ), buf,
  295. buf ) );
  296. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  297. mbedtls_rsa_rsassa_pss_sign( &ctx, NULL, NULL,
  298. invalid_mode,
  299. 0, sizeof( buf ), buf,
  300. buf ) );
  301. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  302. mbedtls_rsa_rsassa_pss_sign( &ctx, NULL, NULL,
  303. valid_mode,
  304. 0, sizeof( buf ), NULL,
  305. buf ) );
  306. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  307. mbedtls_rsa_rsassa_pss_sign( &ctx, NULL, NULL,
  308. valid_mode,
  309. 0, sizeof( buf ), buf,
  310. NULL ) );
  311. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  312. mbedtls_rsa_rsassa_pss_sign( &ctx, NULL, NULL,
  313. valid_mode,
  314. MBEDTLS_MD_SHA1,
  315. 0, NULL,
  316. buf ) );
  317. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  318. mbedtls_rsa_rsassa_pss_sign_ext( NULL, NULL, NULL,
  319. 0, sizeof( buf ), buf,
  320. MBEDTLS_RSA_SALT_LEN_ANY,
  321. buf ) );
  322. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  323. mbedtls_rsa_rsassa_pss_sign_ext( &ctx, NULL, NULL,
  324. 0, sizeof( buf ), NULL,
  325. MBEDTLS_RSA_SALT_LEN_ANY,
  326. buf ) );
  327. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  328. mbedtls_rsa_rsassa_pss_sign_ext( &ctx, NULL, NULL,
  329. 0, sizeof( buf ), buf,
  330. MBEDTLS_RSA_SALT_LEN_ANY,
  331. NULL ) );
  332. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  333. mbedtls_rsa_rsassa_pss_sign_ext( &ctx, NULL, NULL,
  334. MBEDTLS_MD_SHA1,
  335. 0, NULL,
  336. MBEDTLS_RSA_SALT_LEN_ANY,
  337. buf ) );
  338. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  339. mbedtls_rsa_pkcs1_verify( NULL, NULL, NULL,
  340. valid_mode,
  341. 0, sizeof( buf ), buf,
  342. buf ) );
  343. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  344. mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL,
  345. invalid_mode,
  346. 0, sizeof( buf ), buf,
  347. buf ) );
  348. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  349. mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL,
  350. valid_mode,
  351. 0, sizeof( buf ), NULL,
  352. buf ) );
  353. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  354. mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL,
  355. valid_mode,
  356. 0, sizeof( buf ), buf,
  357. NULL ) );
  358. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  359. mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL,
  360. valid_mode,
  361. MBEDTLS_MD_SHA1, 0, NULL,
  362. buf ) );
  363. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  364. mbedtls_rsa_rsassa_pkcs1_v15_verify( NULL, NULL,
  365. NULL,
  366. valid_mode,
  367. 0, sizeof( buf ), buf,
  368. buf ) );
  369. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  370. mbedtls_rsa_rsassa_pkcs1_v15_verify( &ctx, NULL,
  371. NULL,
  372. invalid_mode,
  373. 0, sizeof( buf ), buf,
  374. buf ) );
  375. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  376. mbedtls_rsa_rsassa_pkcs1_v15_verify( &ctx, NULL,
  377. NULL,
  378. valid_mode,
  379. 0, sizeof( buf ),
  380. NULL, buf ) );
  381. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  382. mbedtls_rsa_rsassa_pkcs1_v15_verify( &ctx, NULL,
  383. NULL,
  384. valid_mode,
  385. 0, sizeof( buf ), buf,
  386. NULL ) );
  387. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  388. mbedtls_rsa_rsassa_pkcs1_v15_verify( &ctx, NULL,
  389. NULL,
  390. valid_mode,
  391. MBEDTLS_MD_SHA1,
  392. 0, NULL,
  393. buf ) );
  394. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  395. mbedtls_rsa_rsassa_pss_verify( NULL, NULL, NULL,
  396. valid_mode,
  397. 0, sizeof( buf ),
  398. buf, buf ) );
  399. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  400. mbedtls_rsa_rsassa_pss_verify( &ctx, NULL, NULL,
  401. invalid_mode,
  402. 0, sizeof( buf ),
  403. buf, buf ) );
  404. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  405. mbedtls_rsa_rsassa_pss_verify( &ctx, NULL, NULL,
  406. valid_mode,
  407. 0, sizeof( buf ),
  408. NULL, buf ) );
  409. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  410. mbedtls_rsa_rsassa_pss_verify( &ctx, NULL, NULL,
  411. valid_mode,
  412. 0, sizeof( buf ),
  413. buf, NULL ) );
  414. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  415. mbedtls_rsa_rsassa_pss_verify( &ctx, NULL, NULL,
  416. valid_mode,
  417. MBEDTLS_MD_SHA1,
  418. 0, NULL,
  419. buf ) );
  420. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  421. mbedtls_rsa_rsassa_pss_verify_ext( NULL, NULL, NULL,
  422. valid_mode,
  423. 0, sizeof( buf ),
  424. buf,
  425. 0, 0,
  426. buf ) );
  427. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  428. mbedtls_rsa_rsassa_pss_verify_ext( &ctx, NULL, NULL,
  429. invalid_mode,
  430. 0, sizeof( buf ),
  431. buf,
  432. 0, 0,
  433. buf ) );
  434. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  435. mbedtls_rsa_rsassa_pss_verify_ext( &ctx, NULL, NULL,
  436. valid_mode,
  437. 0, sizeof( buf ),
  438. NULL, 0, 0,
  439. buf ) );
  440. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  441. mbedtls_rsa_rsassa_pss_verify_ext( &ctx, NULL, NULL,
  442. valid_mode,
  443. 0, sizeof( buf ),
  444. buf, 0, 0,
  445. NULL ) );
  446. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  447. mbedtls_rsa_rsassa_pss_verify_ext( &ctx, NULL, NULL,
  448. valid_mode,
  449. MBEDTLS_MD_SHA1,
  450. 0, NULL,
  451. 0, 0,
  452. buf ) );
  453. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  454. mbedtls_rsa_copy( NULL, &ctx ) );
  455. TEST_INVALID_PARAM_RET( MBEDTLS_ERR_RSA_BAD_INPUT_DATA,
  456. mbedtls_rsa_copy( &ctx, NULL ) );
  457. exit:
  458. return;
  459. }
  460. /* END_CASE */
  461. /* BEGIN_CASE */
  462. void rsa_init_free( int reinit )
  463. {
  464. mbedtls_rsa_context ctx;
  465. /* Double free is not explicitly documented to work, but we rely on it
  466. * even inside the library so that you can call mbedtls_rsa_free()
  467. * unconditionally on an error path without checking whether it has
  468. * already been called in the success path. */
  469. mbedtls_rsa_init( &ctx, 0, 0 );
  470. mbedtls_rsa_free( &ctx );
  471. if( reinit )
  472. mbedtls_rsa_init( &ctx, 0, 0 );
  473. mbedtls_rsa_free( &ctx );
  474. /* This test case always succeeds, functionally speaking. A plausible
  475. * bug might trigger an invalid pointer dereference or a memory leak. */
  476. goto exit;
  477. }
  478. /* END_CASE */
  479. /* BEGIN_CASE */
  480. void mbedtls_rsa_pkcs1_sign( data_t * message_str, int padding_mode,
  481. int digest, int mod, int radix_P, char * input_P,
  482. int radix_Q, char * input_Q, int radix_N,
  483. char * input_N, int radix_E, char * input_E,
  484. data_t * result_str, int result )
  485. {
  486. unsigned char hash_result[MBEDTLS_MD_MAX_SIZE];
  487. unsigned char output[256];
  488. mbedtls_rsa_context ctx;
  489. mbedtls_mpi N, P, Q, E;
  490. mbedtls_test_rnd_pseudo_info rnd_info;
  491. mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
  492. mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
  493. mbedtls_rsa_init( &ctx, padding_mode, 0 );
  494. memset( hash_result, 0x00, sizeof( hash_result ) );
  495. memset( output, 0x00, sizeof( output ) );
  496. memset( &rnd_info, 0, sizeof( mbedtls_test_rnd_pseudo_info ) );
  497. TEST_ASSERT( mbedtls_test_read_mpi( &P, radix_P, input_P ) == 0 );
  498. TEST_ASSERT( mbedtls_test_read_mpi( &Q, radix_Q, input_Q ) == 0 );
  499. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  500. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  501. TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
  502. TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( mod / 8 ) );
  503. TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
  504. TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
  505. if( mbedtls_md_info_from_type( digest ) != NULL )
  506. TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( digest ), message_str->x, message_str->len, hash_result ) == 0 );
  507. TEST_ASSERT( mbedtls_rsa_pkcs1_sign( &ctx, &mbedtls_test_rnd_pseudo_rand,
  508. &rnd_info, MBEDTLS_RSA_PRIVATE, digest,
  509. 0, hash_result, output ) == result );
  510. if( result == 0 )
  511. {
  512. TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
  513. ctx.len, result_str->len ) == 0 );
  514. }
  515. exit:
  516. mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
  517. mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
  518. mbedtls_rsa_free( &ctx );
  519. }
  520. /* END_CASE */
  521. /* BEGIN_CASE */
  522. void mbedtls_rsa_pkcs1_verify( data_t * message_str, int padding_mode,
  523. int digest, int mod, int radix_N,
  524. char * input_N, int radix_E, char * input_E,
  525. data_t * result_str, int result )
  526. {
  527. unsigned char hash_result[MBEDTLS_MD_MAX_SIZE];
  528. mbedtls_rsa_context ctx;
  529. mbedtls_mpi N, E;
  530. mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
  531. mbedtls_rsa_init( &ctx, padding_mode, 0 );
  532. memset( hash_result, 0x00, sizeof( hash_result ) );
  533. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  534. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  535. TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
  536. TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( mod / 8 ) );
  537. TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
  538. if( mbedtls_md_info_from_type( digest ) != NULL )
  539. TEST_ASSERT( mbedtls_md( mbedtls_md_info_from_type( digest ), message_str->x, message_str->len, hash_result ) == 0 );
  540. TEST_ASSERT( mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC, digest, 0, hash_result, result_str->x ) == result );
  541. exit:
  542. mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
  543. mbedtls_rsa_free( &ctx );
  544. }
  545. /* END_CASE */
  546. /* BEGIN_CASE */
  547. void rsa_pkcs1_sign_raw( data_t * hash_result,
  548. int padding_mode, int mod, int radix_P,
  549. char * input_P, int radix_Q, char * input_Q,
  550. int radix_N, char * input_N, int radix_E,
  551. char * input_E, data_t * result_str )
  552. {
  553. unsigned char output[256];
  554. mbedtls_rsa_context ctx;
  555. mbedtls_mpi N, P, Q, E;
  556. mbedtls_test_rnd_pseudo_info rnd_info;
  557. mbedtls_rsa_init( &ctx, padding_mode, 0 );
  558. mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
  559. mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
  560. memset( output, 0x00, sizeof( output ) );
  561. memset( &rnd_info, 0, sizeof( mbedtls_test_rnd_pseudo_info ) );
  562. TEST_ASSERT( mbedtls_test_read_mpi( &P, radix_P, input_P ) == 0 );
  563. TEST_ASSERT( mbedtls_test_read_mpi( &Q, radix_Q, input_Q ) == 0 );
  564. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  565. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  566. TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
  567. TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( mod / 8 ) );
  568. TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
  569. TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
  570. TEST_ASSERT( mbedtls_rsa_pkcs1_sign( &ctx, &mbedtls_test_rnd_pseudo_rand,
  571. &rnd_info, MBEDTLS_RSA_PRIVATE,
  572. MBEDTLS_MD_NONE, hash_result->len,
  573. hash_result->x, output ) == 0 );
  574. TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
  575. ctx.len, result_str->len ) == 0 );
  576. #if defined(MBEDTLS_PKCS1_V15)
  577. /* For PKCS#1 v1.5, there is an alternative way to generate signatures */
  578. if( padding_mode == MBEDTLS_RSA_PKCS_V15 )
  579. {
  580. int res;
  581. memset( output, 0x00, sizeof( output) );
  582. res = mbedtls_rsa_rsaes_pkcs1_v15_encrypt( &ctx,
  583. &mbedtls_test_rnd_pseudo_rand, &rnd_info,
  584. MBEDTLS_RSA_PRIVATE, hash_result->len,
  585. hash_result->x, output );
  586. #if !defined(MBEDTLS_RSA_ALT)
  587. TEST_ASSERT( res == 0 );
  588. #else
  589. TEST_ASSERT( ( res == 0 ) ||
  590. ( res == MBEDTLS_ERR_RSA_UNSUPPORTED_OPERATION ) );
  591. #endif
  592. if( res == 0 )
  593. {
  594. TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
  595. ctx.len,
  596. result_str->len ) == 0 );
  597. }
  598. }
  599. #endif /* MBEDTLS_PKCS1_V15 */
  600. exit:
  601. mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
  602. mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
  603. mbedtls_rsa_free( &ctx );
  604. }
  605. /* END_CASE */
  606. /* BEGIN_CASE */
  607. void rsa_pkcs1_verify_raw( data_t * hash_result,
  608. int padding_mode, int mod, int radix_N,
  609. char * input_N, int radix_E, char * input_E,
  610. data_t * result_str, int correct )
  611. {
  612. unsigned char output[256];
  613. mbedtls_rsa_context ctx;
  614. mbedtls_mpi N, E;
  615. mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
  616. mbedtls_rsa_init( &ctx, padding_mode, 0 );
  617. memset( output, 0x00, sizeof( output ) );
  618. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  619. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  620. TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
  621. TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( mod / 8 ) );
  622. TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
  623. TEST_ASSERT( mbedtls_rsa_pkcs1_verify( &ctx, NULL, NULL, MBEDTLS_RSA_PUBLIC, MBEDTLS_MD_NONE, hash_result->len, hash_result->x, result_str->x ) == correct );
  624. #if defined(MBEDTLS_PKCS1_V15)
  625. /* For PKCS#1 v1.5, there is an alternative way to verify signatures */
  626. if( padding_mode == MBEDTLS_RSA_PKCS_V15 )
  627. {
  628. int res;
  629. int ok;
  630. size_t olen;
  631. res = mbedtls_rsa_rsaes_pkcs1_v15_decrypt( &ctx,
  632. NULL, NULL, MBEDTLS_RSA_PUBLIC,
  633. &olen, result_str->x, output, sizeof( output ) );
  634. #if !defined(MBEDTLS_RSA_ALT)
  635. TEST_ASSERT( res == 0 );
  636. #else
  637. TEST_ASSERT( ( res == 0 ) ||
  638. ( res == MBEDTLS_ERR_RSA_UNSUPPORTED_OPERATION ) );
  639. #endif
  640. if( res == 0 )
  641. {
  642. ok = olen == hash_result->len && memcmp( output, hash_result->x, olen ) == 0;
  643. if( correct == 0 )
  644. TEST_ASSERT( ok == 1 );
  645. else
  646. TEST_ASSERT( ok == 0 );
  647. }
  648. }
  649. #endif /* MBEDTLS_PKCS1_V15 */
  650. exit:
  651. mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
  652. mbedtls_rsa_free( &ctx );
  653. }
  654. /* END_CASE */
  655. /* BEGIN_CASE */
  656. void mbedtls_rsa_pkcs1_encrypt( data_t * message_str, int padding_mode,
  657. int mod, int radix_N, char * input_N,
  658. int radix_E, char * input_E,
  659. data_t * result_str, int result )
  660. {
  661. unsigned char output[256];
  662. mbedtls_rsa_context ctx;
  663. mbedtls_test_rnd_pseudo_info rnd_info;
  664. mbedtls_mpi N, E;
  665. mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
  666. memset( &rnd_info, 0, sizeof( mbedtls_test_rnd_pseudo_info ) );
  667. mbedtls_rsa_init( &ctx, padding_mode, 0 );
  668. memset( output, 0x00, sizeof( output ) );
  669. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  670. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  671. TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
  672. TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( mod / 8 ) );
  673. TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
  674. TEST_ASSERT( mbedtls_rsa_pkcs1_encrypt( &ctx,
  675. &mbedtls_test_rnd_pseudo_rand,
  676. &rnd_info, MBEDTLS_RSA_PUBLIC,
  677. message_str->len, message_str->x,
  678. output ) == result );
  679. if( result == 0 )
  680. {
  681. TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
  682. ctx.len, result_str->len ) == 0 );
  683. }
  684. exit:
  685. mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
  686. mbedtls_rsa_free( &ctx );
  687. }
  688. /* END_CASE */
  689. /* BEGIN_CASE */
  690. void rsa_pkcs1_encrypt_bad_rng( data_t * message_str, int padding_mode,
  691. int mod, int radix_N, char * input_N,
  692. int radix_E, char * input_E,
  693. data_t * result_str, int result )
  694. {
  695. unsigned char output[256];
  696. mbedtls_rsa_context ctx;
  697. mbedtls_mpi N, E;
  698. mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
  699. mbedtls_rsa_init( &ctx, padding_mode, 0 );
  700. memset( output, 0x00, sizeof( output ) );
  701. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  702. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  703. TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
  704. TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( mod / 8 ) );
  705. TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
  706. TEST_ASSERT( mbedtls_rsa_pkcs1_encrypt( &ctx, &mbedtls_test_rnd_zero_rand,
  707. NULL, MBEDTLS_RSA_PUBLIC,
  708. message_str->len, message_str->x,
  709. output ) == result );
  710. if( result == 0 )
  711. {
  712. TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
  713. ctx.len, result_str->len ) == 0 );
  714. }
  715. exit:
  716. mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
  717. mbedtls_rsa_free( &ctx );
  718. }
  719. /* END_CASE */
  720. /* BEGIN_CASE */
  721. void mbedtls_rsa_pkcs1_decrypt( data_t * message_str, int padding_mode,
  722. int mod, int radix_P, char * input_P,
  723. int radix_Q, char * input_Q, int radix_N,
  724. char * input_N, int radix_E, char * input_E,
  725. int max_output, data_t * result_str,
  726. int result )
  727. {
  728. unsigned char output[32];
  729. mbedtls_rsa_context ctx;
  730. size_t output_len;
  731. mbedtls_test_rnd_pseudo_info rnd_info;
  732. mbedtls_mpi N, P, Q, E;
  733. mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
  734. mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
  735. mbedtls_rsa_init( &ctx, padding_mode, 0 );
  736. memset( output, 0x00, sizeof( output ) );
  737. memset( &rnd_info, 0, sizeof( mbedtls_test_rnd_pseudo_info ) );
  738. TEST_ASSERT( mbedtls_test_read_mpi( &P, radix_P, input_P ) == 0 );
  739. TEST_ASSERT( mbedtls_test_read_mpi( &Q, radix_Q, input_Q ) == 0 );
  740. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  741. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  742. TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
  743. TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( mod / 8 ) );
  744. TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
  745. TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
  746. output_len = 0;
  747. TEST_ASSERT( mbedtls_rsa_pkcs1_decrypt( &ctx, mbedtls_test_rnd_pseudo_rand,
  748. &rnd_info, MBEDTLS_RSA_PRIVATE,
  749. &output_len, message_str->x, output,
  750. max_output ) == result );
  751. if( result == 0 )
  752. {
  753. TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
  754. output_len,
  755. result_str->len ) == 0 );
  756. }
  757. exit:
  758. mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
  759. mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
  760. mbedtls_rsa_free( &ctx );
  761. }
  762. /* END_CASE */
  763. /* BEGIN_CASE */
  764. void mbedtls_rsa_public( data_t * message_str, int mod, int radix_N,
  765. char * input_N, int radix_E, char * input_E,
  766. data_t * result_str, int result )
  767. {
  768. unsigned char output[256];
  769. mbedtls_rsa_context ctx, ctx2; /* Also test mbedtls_rsa_copy() while at it */
  770. mbedtls_mpi N, E;
  771. mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
  772. mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V15, 0 );
  773. mbedtls_rsa_init( &ctx2, MBEDTLS_RSA_PKCS_V15, 0 );
  774. memset( output, 0x00, sizeof( output ) );
  775. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  776. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  777. TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
  778. /* Check test data consistency */
  779. TEST_ASSERT( message_str->len == (size_t) ( mod / 8 ) );
  780. TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( mod / 8 ) );
  781. TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == 0 );
  782. TEST_ASSERT( mbedtls_rsa_public( &ctx, message_str->x, output ) == result );
  783. if( result == 0 )
  784. {
  785. TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
  786. ctx.len, result_str->len ) == 0 );
  787. }
  788. /* And now with the copy */
  789. TEST_ASSERT( mbedtls_rsa_copy( &ctx2, &ctx ) == 0 );
  790. /* clear the original to be sure */
  791. mbedtls_rsa_free( &ctx );
  792. TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx2 ) == 0 );
  793. memset( output, 0x00, sizeof( output ) );
  794. TEST_ASSERT( mbedtls_rsa_public( &ctx2, message_str->x, output ) == result );
  795. if( result == 0 )
  796. {
  797. TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
  798. ctx.len, result_str->len ) == 0 );
  799. }
  800. exit:
  801. mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
  802. mbedtls_rsa_free( &ctx );
  803. mbedtls_rsa_free( &ctx2 );
  804. }
  805. /* END_CASE */
  806. /* BEGIN_CASE */
  807. void mbedtls_rsa_private( data_t * message_str, int mod, int radix_P,
  808. char * input_P, int radix_Q, char * input_Q,
  809. int radix_N, char * input_N, int radix_E,
  810. char * input_E, data_t * result_str,
  811. int result )
  812. {
  813. unsigned char output[256];
  814. mbedtls_rsa_context ctx, ctx2; /* Also test mbedtls_rsa_copy() while at it */
  815. mbedtls_mpi N, P, Q, E;
  816. mbedtls_test_rnd_pseudo_info rnd_info;
  817. int i;
  818. mbedtls_mpi_init( &N ); mbedtls_mpi_init( &P );
  819. mbedtls_mpi_init( &Q ); mbedtls_mpi_init( &E );
  820. mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V15, 0 );
  821. mbedtls_rsa_init( &ctx2, MBEDTLS_RSA_PKCS_V15, 0 );
  822. memset( &rnd_info, 0, sizeof( mbedtls_test_rnd_pseudo_info ) );
  823. TEST_ASSERT( mbedtls_test_read_mpi( &P, radix_P, input_P ) == 0 );
  824. TEST_ASSERT( mbedtls_test_read_mpi( &Q, radix_Q, input_Q ) == 0 );
  825. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  826. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  827. TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, &P, &Q, NULL, &E ) == 0 );
  828. /* Check test data consistency */
  829. TEST_ASSERT( message_str->len == (size_t) ( mod / 8 ) );
  830. TEST_ASSERT( mbedtls_rsa_get_len( &ctx ) == (size_t) ( mod / 8 ) );
  831. TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
  832. TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
  833. /* repeat three times to test updating of blinding values */
  834. for( i = 0; i < 3; i++ )
  835. {
  836. memset( output, 0x00, sizeof( output ) );
  837. TEST_ASSERT( mbedtls_rsa_private( &ctx, mbedtls_test_rnd_pseudo_rand,
  838. &rnd_info, message_str->x,
  839. output ) == result );
  840. if( result == 0 )
  841. {
  842. TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
  843. ctx.len,
  844. result_str->len ) == 0 );
  845. }
  846. }
  847. /* And now one more time with the copy */
  848. TEST_ASSERT( mbedtls_rsa_copy( &ctx2, &ctx ) == 0 );
  849. /* clear the original to be sure */
  850. mbedtls_rsa_free( &ctx );
  851. TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx2 ) == 0 );
  852. memset( output, 0x00, sizeof( output ) );
  853. TEST_ASSERT( mbedtls_rsa_private( &ctx2, mbedtls_test_rnd_pseudo_rand,
  854. &rnd_info, message_str->x,
  855. output ) == result );
  856. if( result == 0 )
  857. {
  858. TEST_ASSERT( mbedtls_test_hexcmp( output, result_str->x,
  859. ctx2.len,
  860. result_str->len ) == 0 );
  861. }
  862. exit:
  863. mbedtls_mpi_free( &N ); mbedtls_mpi_free( &P );
  864. mbedtls_mpi_free( &Q ); mbedtls_mpi_free( &E );
  865. mbedtls_rsa_free( &ctx ); mbedtls_rsa_free( &ctx2 );
  866. }
  867. /* END_CASE */
  868. /* BEGIN_CASE */
  869. void rsa_check_privkey_null( )
  870. {
  871. mbedtls_rsa_context ctx;
  872. memset( &ctx, 0x00, sizeof( mbedtls_rsa_context ) );
  873. TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == MBEDTLS_ERR_RSA_KEY_CHECK_FAILED );
  874. }
  875. /* END_CASE */
  876. /* BEGIN_CASE */
  877. void mbedtls_rsa_check_pubkey( int radix_N, char * input_N, int radix_E,
  878. char * input_E, int result )
  879. {
  880. mbedtls_rsa_context ctx;
  881. mbedtls_mpi N, E;
  882. mbedtls_mpi_init( &N ); mbedtls_mpi_init( &E );
  883. mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V15, 0 );
  884. if( strlen( input_N ) )
  885. {
  886. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  887. }
  888. if( strlen( input_E ) )
  889. {
  890. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  891. }
  892. TEST_ASSERT( mbedtls_rsa_import( &ctx, &N, NULL, NULL, NULL, &E ) == 0 );
  893. TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == result );
  894. exit:
  895. mbedtls_mpi_free( &N ); mbedtls_mpi_free( &E );
  896. mbedtls_rsa_free( &ctx );
  897. }
  898. /* END_CASE */
  899. /* BEGIN_CASE */
  900. void mbedtls_rsa_check_privkey( int mod, int radix_P, char * input_P,
  901. int radix_Q, char * input_Q, int radix_N,
  902. char * input_N, int radix_E, char * input_E,
  903. int radix_D, char * input_D, int radix_DP,
  904. char * input_DP, int radix_DQ,
  905. char * input_DQ, int radix_QP,
  906. char * input_QP, int result )
  907. {
  908. mbedtls_rsa_context ctx;
  909. mbedtls_rsa_init( &ctx, MBEDTLS_RSA_PKCS_V15, 0 );
  910. ctx.len = mod / 8;
  911. if( strlen( input_P ) )
  912. {
  913. TEST_ASSERT( mbedtls_test_read_mpi( &ctx.P, radix_P, input_P ) == 0 );
  914. }
  915. if( strlen( input_Q ) )
  916. {
  917. TEST_ASSERT( mbedtls_test_read_mpi( &ctx.Q, radix_Q, input_Q ) == 0 );
  918. }
  919. if( strlen( input_N ) )
  920. {
  921. TEST_ASSERT( mbedtls_test_read_mpi( &ctx.N, radix_N, input_N ) == 0 );
  922. }
  923. if( strlen( input_E ) )
  924. {
  925. TEST_ASSERT( mbedtls_test_read_mpi( &ctx.E, radix_E, input_E ) == 0 );
  926. }
  927. if( strlen( input_D ) )
  928. {
  929. TEST_ASSERT( mbedtls_test_read_mpi( &ctx.D, radix_D, input_D ) == 0 );
  930. }
  931. #if !defined(MBEDTLS_RSA_NO_CRT)
  932. if( strlen( input_DP ) )
  933. {
  934. TEST_ASSERT( mbedtls_test_read_mpi( &ctx.DP, radix_DP, input_DP ) == 0 );
  935. }
  936. if( strlen( input_DQ ) )
  937. {
  938. TEST_ASSERT( mbedtls_test_read_mpi( &ctx.DQ, radix_DQ, input_DQ ) == 0 );
  939. }
  940. if( strlen( input_QP ) )
  941. {
  942. TEST_ASSERT( mbedtls_test_read_mpi( &ctx.QP, radix_QP, input_QP ) == 0 );
  943. }
  944. #else
  945. ((void) radix_DP); ((void) input_DP);
  946. ((void) radix_DQ); ((void) input_DQ);
  947. ((void) radix_QP); ((void) input_QP);
  948. #endif
  949. TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == result );
  950. exit:
  951. mbedtls_rsa_free( &ctx );
  952. }
  953. /* END_CASE */
  954. /* BEGIN_CASE */
  955. void rsa_check_pubpriv( int mod, int radix_Npub, char * input_Npub,
  956. int radix_Epub, char * input_Epub, int radix_P,
  957. char * input_P, int radix_Q, char * input_Q,
  958. int radix_N, char * input_N, int radix_E,
  959. char * input_E, int radix_D, char * input_D,
  960. int radix_DP, char * input_DP, int radix_DQ,
  961. char * input_DQ, int radix_QP, char * input_QP,
  962. int result )
  963. {
  964. mbedtls_rsa_context pub, prv;
  965. mbedtls_rsa_init( &pub, MBEDTLS_RSA_PKCS_V15, 0 );
  966. mbedtls_rsa_init( &prv, MBEDTLS_RSA_PKCS_V15, 0 );
  967. pub.len = mod / 8;
  968. prv.len = mod / 8;
  969. if( strlen( input_Npub ) )
  970. {
  971. TEST_ASSERT( mbedtls_test_read_mpi( &pub.N, radix_Npub, input_Npub ) == 0 );
  972. }
  973. if( strlen( input_Epub ) )
  974. {
  975. TEST_ASSERT( mbedtls_test_read_mpi( &pub.E, radix_Epub, input_Epub ) == 0 );
  976. }
  977. if( strlen( input_P ) )
  978. {
  979. TEST_ASSERT( mbedtls_test_read_mpi( &prv.P, radix_P, input_P ) == 0 );
  980. }
  981. if( strlen( input_Q ) )
  982. {
  983. TEST_ASSERT( mbedtls_test_read_mpi( &prv.Q, radix_Q, input_Q ) == 0 );
  984. }
  985. if( strlen( input_N ) )
  986. {
  987. TEST_ASSERT( mbedtls_test_read_mpi( &prv.N, radix_N, input_N ) == 0 );
  988. }
  989. if( strlen( input_E ) )
  990. {
  991. TEST_ASSERT( mbedtls_test_read_mpi( &prv.E, radix_E, input_E ) == 0 );
  992. }
  993. if( strlen( input_D ) )
  994. {
  995. TEST_ASSERT( mbedtls_test_read_mpi( &prv.D, radix_D, input_D ) == 0 );
  996. }
  997. #if !defined(MBEDTLS_RSA_NO_CRT)
  998. if( strlen( input_DP ) )
  999. {
  1000. TEST_ASSERT( mbedtls_test_read_mpi( &prv.DP, radix_DP, input_DP ) == 0 );
  1001. }
  1002. if( strlen( input_DQ ) )
  1003. {
  1004. TEST_ASSERT( mbedtls_test_read_mpi( &prv.DQ, radix_DQ, input_DQ ) == 0 );
  1005. }
  1006. if( strlen( input_QP ) )
  1007. {
  1008. TEST_ASSERT( mbedtls_test_read_mpi( &prv.QP, radix_QP, input_QP ) == 0 );
  1009. }
  1010. #else
  1011. ((void) radix_DP); ((void) input_DP);
  1012. ((void) radix_DQ); ((void) input_DQ);
  1013. ((void) radix_QP); ((void) input_QP);
  1014. #endif
  1015. TEST_ASSERT( mbedtls_rsa_check_pub_priv( &pub, &prv ) == result );
  1016. exit:
  1017. mbedtls_rsa_free( &pub );
  1018. mbedtls_rsa_free( &prv );
  1019. }
  1020. /* END_CASE */
  1021. /* BEGIN_CASE depends_on:MBEDTLS_CTR_DRBG_C:MBEDTLS_ENTROPY_C:ENTROPY_HAVE_STRONG */
  1022. void mbedtls_rsa_gen_key( int nrbits, int exponent, int result)
  1023. {
  1024. mbedtls_rsa_context ctx;
  1025. mbedtls_entropy_context entropy;
  1026. mbedtls_ctr_drbg_context ctr_drbg;
  1027. const char *pers = "test_suite_rsa";
  1028. mbedtls_ctr_drbg_init( &ctr_drbg );
  1029. mbedtls_entropy_init( &entropy );
  1030. mbedtls_rsa_init ( &ctx, 0, 0 );
  1031. TEST_ASSERT( mbedtls_ctr_drbg_seed( &ctr_drbg, mbedtls_entropy_func,
  1032. &entropy, (const unsigned char *) pers,
  1033. strlen( pers ) ) == 0 );
  1034. TEST_ASSERT( mbedtls_rsa_gen_key( &ctx, mbedtls_ctr_drbg_random, &ctr_drbg, nrbits, exponent ) == result );
  1035. if( result == 0 )
  1036. {
  1037. TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == 0 );
  1038. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &ctx.P, &ctx.Q ) > 0 );
  1039. }
  1040. exit:
  1041. mbedtls_rsa_free( &ctx );
  1042. mbedtls_ctr_drbg_free( &ctr_drbg );
  1043. mbedtls_entropy_free( &entropy );
  1044. }
  1045. /* END_CASE */
  1046. /* BEGIN_CASE depends_on:MBEDTLS_CTR_DRBG_C:MBEDTLS_ENTROPY_C */
  1047. void mbedtls_rsa_deduce_primes( int radix_N, char *input_N,
  1048. int radix_D, char *input_D,
  1049. int radix_E, char *input_E,
  1050. int radix_P, char *output_P,
  1051. int radix_Q, char *output_Q,
  1052. int corrupt, int result )
  1053. {
  1054. mbedtls_mpi N, P, Pp, Q, Qp, D, E;
  1055. mbedtls_mpi_init( &N );
  1056. mbedtls_mpi_init( &P ); mbedtls_mpi_init( &Q );
  1057. mbedtls_mpi_init( &Pp ); mbedtls_mpi_init( &Qp );
  1058. mbedtls_mpi_init( &D ); mbedtls_mpi_init( &E );
  1059. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  1060. TEST_ASSERT( mbedtls_test_read_mpi( &D, radix_D, input_D ) == 0 );
  1061. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  1062. TEST_ASSERT( mbedtls_test_read_mpi( &Qp, radix_P, output_P ) == 0 );
  1063. TEST_ASSERT( mbedtls_test_read_mpi( &Pp, radix_Q, output_Q ) == 0 );
  1064. if( corrupt )
  1065. TEST_ASSERT( mbedtls_mpi_add_int( &D, &D, 2 ) == 0 );
  1066. /* Try to deduce P, Q from N, D, E only. */
  1067. TEST_ASSERT( mbedtls_rsa_deduce_primes( &N, &D, &E, &P, &Q ) == result );
  1068. if( !corrupt )
  1069. {
  1070. /* Check if (P,Q) = (Pp, Qp) or (P,Q) = (Qp, Pp) */
  1071. TEST_ASSERT( ( mbedtls_mpi_cmp_mpi( &P, &Pp ) == 0 && mbedtls_mpi_cmp_mpi( &Q, &Qp ) == 0 ) ||
  1072. ( mbedtls_mpi_cmp_mpi( &P, &Qp ) == 0 && mbedtls_mpi_cmp_mpi( &Q, &Pp ) == 0 ) );
  1073. }
  1074. exit:
  1075. mbedtls_mpi_free( &N );
  1076. mbedtls_mpi_free( &P ); mbedtls_mpi_free( &Q );
  1077. mbedtls_mpi_free( &Pp ); mbedtls_mpi_free( &Qp );
  1078. mbedtls_mpi_free( &D ); mbedtls_mpi_free( &E );
  1079. }
  1080. /* END_CASE */
  1081. /* BEGIN_CASE */
  1082. void mbedtls_rsa_deduce_private_exponent( int radix_P, char *input_P,
  1083. int radix_Q, char *input_Q,
  1084. int radix_E, char *input_E,
  1085. int radix_D, char *output_D,
  1086. int corrupt, int result )
  1087. {
  1088. mbedtls_mpi P, Q, D, Dp, E, R, Rp;
  1089. mbedtls_mpi_init( &P ); mbedtls_mpi_init( &Q );
  1090. mbedtls_mpi_init( &D ); mbedtls_mpi_init( &Dp );
  1091. mbedtls_mpi_init( &E );
  1092. mbedtls_mpi_init( &R ); mbedtls_mpi_init( &Rp );
  1093. TEST_ASSERT( mbedtls_test_read_mpi( &P, radix_P, input_P ) == 0 );
  1094. TEST_ASSERT( mbedtls_test_read_mpi( &Q, radix_Q, input_Q ) == 0 );
  1095. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  1096. TEST_ASSERT( mbedtls_test_read_mpi( &Dp, radix_D, output_D ) == 0 );
  1097. if( corrupt )
  1098. {
  1099. /* Make E even */
  1100. TEST_ASSERT( mbedtls_mpi_set_bit( &E, 0, 0 ) == 0 );
  1101. }
  1102. /* Try to deduce D from N, P, Q, E. */
  1103. TEST_ASSERT( mbedtls_rsa_deduce_private_exponent( &P, &Q,
  1104. &E, &D ) == result );
  1105. if( !corrupt )
  1106. {
  1107. /*
  1108. * Check that D and Dp agree modulo LCM(P-1, Q-1).
  1109. */
  1110. /* Replace P,Q by P-1, Q-1 */
  1111. TEST_ASSERT( mbedtls_mpi_sub_int( &P, &P, 1 ) == 0 );
  1112. TEST_ASSERT( mbedtls_mpi_sub_int( &Q, &Q, 1 ) == 0 );
  1113. /* Check D == Dp modulo P-1 */
  1114. TEST_ASSERT( mbedtls_mpi_mod_mpi( &R, &D, &P ) == 0 );
  1115. TEST_ASSERT( mbedtls_mpi_mod_mpi( &Rp, &Dp, &P ) == 0 );
  1116. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R, &Rp ) == 0 );
  1117. /* Check D == Dp modulo Q-1 */
  1118. TEST_ASSERT( mbedtls_mpi_mod_mpi( &R, &D, &Q ) == 0 );
  1119. TEST_ASSERT( mbedtls_mpi_mod_mpi( &Rp, &Dp, &Q ) == 0 );
  1120. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &R, &Rp ) == 0 );
  1121. }
  1122. exit:
  1123. mbedtls_mpi_free( &P ); mbedtls_mpi_free( &Q );
  1124. mbedtls_mpi_free( &D ); mbedtls_mpi_free( &Dp );
  1125. mbedtls_mpi_free( &E );
  1126. mbedtls_mpi_free( &R ); mbedtls_mpi_free( &Rp );
  1127. }
  1128. /* END_CASE */
  1129. /* BEGIN_CASE depends_on:MBEDTLS_CTR_DRBG_C:MBEDTLS_ENTROPY_C:ENTROPY_HAVE_STRONG */
  1130. void mbedtls_rsa_import( int radix_N, char *input_N,
  1131. int radix_P, char *input_P,
  1132. int radix_Q, char *input_Q,
  1133. int radix_D, char *input_D,
  1134. int radix_E, char *input_E,
  1135. int successive,
  1136. int is_priv,
  1137. int res_check,
  1138. int res_complete )
  1139. {
  1140. mbedtls_mpi N, P, Q, D, E;
  1141. mbedtls_rsa_context ctx;
  1142. /* Buffers used for encryption-decryption test */
  1143. unsigned char *buf_orig = NULL;
  1144. unsigned char *buf_enc = NULL;
  1145. unsigned char *buf_dec = NULL;
  1146. mbedtls_entropy_context entropy;
  1147. mbedtls_ctr_drbg_context ctr_drbg;
  1148. const char *pers = "test_suite_rsa";
  1149. const int have_N = ( strlen( input_N ) > 0 );
  1150. const int have_P = ( strlen( input_P ) > 0 );
  1151. const int have_Q = ( strlen( input_Q ) > 0 );
  1152. const int have_D = ( strlen( input_D ) > 0 );
  1153. const int have_E = ( strlen( input_E ) > 0 );
  1154. mbedtls_ctr_drbg_init( &ctr_drbg );
  1155. mbedtls_entropy_init( &entropy );
  1156. mbedtls_rsa_init( &ctx, 0, 0 );
  1157. mbedtls_mpi_init( &N );
  1158. mbedtls_mpi_init( &P ); mbedtls_mpi_init( &Q );
  1159. mbedtls_mpi_init( &D ); mbedtls_mpi_init( &E );
  1160. TEST_ASSERT( mbedtls_ctr_drbg_seed( &ctr_drbg, mbedtls_entropy_func, &entropy,
  1161. (const unsigned char *) pers, strlen( pers ) ) == 0 );
  1162. if( have_N )
  1163. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  1164. if( have_P )
  1165. TEST_ASSERT( mbedtls_test_read_mpi( &P, radix_P, input_P ) == 0 );
  1166. if( have_Q )
  1167. TEST_ASSERT( mbedtls_test_read_mpi( &Q, radix_Q, input_Q ) == 0 );
  1168. if( have_D )
  1169. TEST_ASSERT( mbedtls_test_read_mpi( &D, radix_D, input_D ) == 0 );
  1170. if( have_E )
  1171. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  1172. if( !successive )
  1173. {
  1174. TEST_ASSERT( mbedtls_rsa_import( &ctx,
  1175. have_N ? &N : NULL,
  1176. have_P ? &P : NULL,
  1177. have_Q ? &Q : NULL,
  1178. have_D ? &D : NULL,
  1179. have_E ? &E : NULL ) == 0 );
  1180. }
  1181. else
  1182. {
  1183. /* Import N, P, Q, D, E separately.
  1184. * This should make no functional difference. */
  1185. TEST_ASSERT( mbedtls_rsa_import( &ctx,
  1186. have_N ? &N : NULL,
  1187. NULL, NULL, NULL, NULL ) == 0 );
  1188. TEST_ASSERT( mbedtls_rsa_import( &ctx,
  1189. NULL,
  1190. have_P ? &P : NULL,
  1191. NULL, NULL, NULL ) == 0 );
  1192. TEST_ASSERT( mbedtls_rsa_import( &ctx,
  1193. NULL, NULL,
  1194. have_Q ? &Q : NULL,
  1195. NULL, NULL ) == 0 );
  1196. TEST_ASSERT( mbedtls_rsa_import( &ctx,
  1197. NULL, NULL, NULL,
  1198. have_D ? &D : NULL,
  1199. NULL ) == 0 );
  1200. TEST_ASSERT( mbedtls_rsa_import( &ctx,
  1201. NULL, NULL, NULL, NULL,
  1202. have_E ? &E : NULL ) == 0 );
  1203. }
  1204. TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == res_complete );
  1205. /* On expected success, perform some public and private
  1206. * key operations to check if the key is working properly. */
  1207. if( res_complete == 0 )
  1208. {
  1209. if( is_priv )
  1210. TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == res_check );
  1211. else
  1212. TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == res_check );
  1213. if( res_check != 0 )
  1214. goto exit;
  1215. buf_orig = mbedtls_calloc( 1, mbedtls_rsa_get_len( &ctx ) );
  1216. buf_enc = mbedtls_calloc( 1, mbedtls_rsa_get_len( &ctx ) );
  1217. buf_dec = mbedtls_calloc( 1, mbedtls_rsa_get_len( &ctx ) );
  1218. if( buf_orig == NULL || buf_enc == NULL || buf_dec == NULL )
  1219. goto exit;
  1220. TEST_ASSERT( mbedtls_ctr_drbg_random( &ctr_drbg,
  1221. buf_orig, mbedtls_rsa_get_len( &ctx ) ) == 0 );
  1222. /* Make sure the number we're generating is smaller than the modulus */
  1223. buf_orig[0] = 0x00;
  1224. TEST_ASSERT( mbedtls_rsa_public( &ctx, buf_orig, buf_enc ) == 0 );
  1225. if( is_priv )
  1226. {
  1227. TEST_ASSERT( mbedtls_rsa_private( &ctx, mbedtls_ctr_drbg_random,
  1228. &ctr_drbg, buf_enc,
  1229. buf_dec ) == 0 );
  1230. TEST_ASSERT( memcmp( buf_orig, buf_dec,
  1231. mbedtls_rsa_get_len( &ctx ) ) == 0 );
  1232. }
  1233. }
  1234. exit:
  1235. mbedtls_free( buf_orig );
  1236. mbedtls_free( buf_enc );
  1237. mbedtls_free( buf_dec );
  1238. mbedtls_rsa_free( &ctx );
  1239. mbedtls_ctr_drbg_free( &ctr_drbg );
  1240. mbedtls_entropy_free( &entropy );
  1241. mbedtls_mpi_free( &N );
  1242. mbedtls_mpi_free( &P ); mbedtls_mpi_free( &Q );
  1243. mbedtls_mpi_free( &D ); mbedtls_mpi_free( &E );
  1244. }
  1245. /* END_CASE */
  1246. /* BEGIN_CASE */
  1247. void mbedtls_rsa_export( int radix_N, char *input_N,
  1248. int radix_P, char *input_P,
  1249. int radix_Q, char *input_Q,
  1250. int radix_D, char *input_D,
  1251. int radix_E, char *input_E,
  1252. int is_priv,
  1253. int successive )
  1254. {
  1255. /* Original MPI's with which we set up the RSA context */
  1256. mbedtls_mpi N, P, Q, D, E;
  1257. /* Exported MPI's */
  1258. mbedtls_mpi Ne, Pe, Qe, De, Ee;
  1259. const int have_N = ( strlen( input_N ) > 0 );
  1260. const int have_P = ( strlen( input_P ) > 0 );
  1261. const int have_Q = ( strlen( input_Q ) > 0 );
  1262. const int have_D = ( strlen( input_D ) > 0 );
  1263. const int have_E = ( strlen( input_E ) > 0 );
  1264. mbedtls_rsa_context ctx;
  1265. mbedtls_rsa_init( &ctx, 0, 0 );
  1266. mbedtls_mpi_init( &N );
  1267. mbedtls_mpi_init( &P ); mbedtls_mpi_init( &Q );
  1268. mbedtls_mpi_init( &D ); mbedtls_mpi_init( &E );
  1269. mbedtls_mpi_init( &Ne );
  1270. mbedtls_mpi_init( &Pe ); mbedtls_mpi_init( &Qe );
  1271. mbedtls_mpi_init( &De ); mbedtls_mpi_init( &Ee );
  1272. /* Setup RSA context */
  1273. if( have_N )
  1274. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  1275. if( have_P )
  1276. TEST_ASSERT( mbedtls_test_read_mpi( &P, radix_P, input_P ) == 0 );
  1277. if( have_Q )
  1278. TEST_ASSERT( mbedtls_test_read_mpi( &Q, radix_Q, input_Q ) == 0 );
  1279. if( have_D )
  1280. TEST_ASSERT( mbedtls_test_read_mpi( &D, radix_D, input_D ) == 0 );
  1281. if( have_E )
  1282. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  1283. TEST_ASSERT( mbedtls_rsa_import( &ctx,
  1284. strlen( input_N ) ? &N : NULL,
  1285. strlen( input_P ) ? &P : NULL,
  1286. strlen( input_Q ) ? &Q : NULL,
  1287. strlen( input_D ) ? &D : NULL,
  1288. strlen( input_E ) ? &E : NULL ) == 0 );
  1289. TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
  1290. /*
  1291. * Export parameters and compare to original ones.
  1292. */
  1293. /* N and E must always be present. */
  1294. if( !successive )
  1295. {
  1296. TEST_ASSERT( mbedtls_rsa_export( &ctx, &Ne, NULL, NULL, NULL, &Ee ) == 0 );
  1297. }
  1298. else
  1299. {
  1300. TEST_ASSERT( mbedtls_rsa_export( &ctx, &Ne, NULL, NULL, NULL, NULL ) == 0 );
  1301. TEST_ASSERT( mbedtls_rsa_export( &ctx, NULL, NULL, NULL, NULL, &Ee ) == 0 );
  1302. }
  1303. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &N, &Ne ) == 0 );
  1304. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &E, &Ee ) == 0 );
  1305. /* If we were providing enough information to setup a complete private context,
  1306. * we expect to be able to export all core parameters. */
  1307. if( is_priv )
  1308. {
  1309. if( !successive )
  1310. {
  1311. TEST_ASSERT( mbedtls_rsa_export( &ctx, NULL, &Pe, &Qe,
  1312. &De, NULL ) == 0 );
  1313. }
  1314. else
  1315. {
  1316. TEST_ASSERT( mbedtls_rsa_export( &ctx, NULL, &Pe, NULL,
  1317. NULL, NULL ) == 0 );
  1318. TEST_ASSERT( mbedtls_rsa_export( &ctx, NULL, NULL, &Qe,
  1319. NULL, NULL ) == 0 );
  1320. TEST_ASSERT( mbedtls_rsa_export( &ctx, NULL, NULL, NULL,
  1321. &De, NULL ) == 0 );
  1322. }
  1323. if( have_P )
  1324. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &P, &Pe ) == 0 );
  1325. if( have_Q )
  1326. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &Q, &Qe ) == 0 );
  1327. if( have_D )
  1328. TEST_ASSERT( mbedtls_mpi_cmp_mpi( &D, &De ) == 0 );
  1329. /* While at it, perform a sanity check */
  1330. TEST_ASSERT( mbedtls_rsa_validate_params( &Ne, &Pe, &Qe, &De, &Ee,
  1331. NULL, NULL ) == 0 );
  1332. }
  1333. exit:
  1334. mbedtls_rsa_free( &ctx );
  1335. mbedtls_mpi_free( &N );
  1336. mbedtls_mpi_free( &P ); mbedtls_mpi_free( &Q );
  1337. mbedtls_mpi_free( &D ); mbedtls_mpi_free( &E );
  1338. mbedtls_mpi_free( &Ne );
  1339. mbedtls_mpi_free( &Pe ); mbedtls_mpi_free( &Qe );
  1340. mbedtls_mpi_free( &De ); mbedtls_mpi_free( &Ee );
  1341. }
  1342. /* END_CASE */
  1343. /* BEGIN_CASE depends_on:MBEDTLS_ENTROPY_C:ENTROPY_HAVE_STRONG:MBEDTLS_ENTROPY_C:MBEDTLS_CTR_DRBG_C */
  1344. void mbedtls_rsa_validate_params( int radix_N, char *input_N,
  1345. int radix_P, char *input_P,
  1346. int radix_Q, char *input_Q,
  1347. int radix_D, char *input_D,
  1348. int radix_E, char *input_E,
  1349. int prng, int result )
  1350. {
  1351. /* Original MPI's with which we set up the RSA context */
  1352. mbedtls_mpi N, P, Q, D, E;
  1353. const int have_N = ( strlen( input_N ) > 0 );
  1354. const int have_P = ( strlen( input_P ) > 0 );
  1355. const int have_Q = ( strlen( input_Q ) > 0 );
  1356. const int have_D = ( strlen( input_D ) > 0 );
  1357. const int have_E = ( strlen( input_E ) > 0 );
  1358. mbedtls_entropy_context entropy;
  1359. mbedtls_ctr_drbg_context ctr_drbg;
  1360. const char *pers = "test_suite_rsa";
  1361. mbedtls_mpi_init( &N );
  1362. mbedtls_mpi_init( &P ); mbedtls_mpi_init( &Q );
  1363. mbedtls_mpi_init( &D ); mbedtls_mpi_init( &E );
  1364. mbedtls_ctr_drbg_init( &ctr_drbg );
  1365. mbedtls_entropy_init( &entropy );
  1366. TEST_ASSERT( mbedtls_ctr_drbg_seed( &ctr_drbg, mbedtls_entropy_func,
  1367. &entropy, (const unsigned char *) pers,
  1368. strlen( pers ) ) == 0 );
  1369. if( have_N )
  1370. TEST_ASSERT( mbedtls_test_read_mpi( &N, radix_N, input_N ) == 0 );
  1371. if( have_P )
  1372. TEST_ASSERT( mbedtls_test_read_mpi( &P, radix_P, input_P ) == 0 );
  1373. if( have_Q )
  1374. TEST_ASSERT( mbedtls_test_read_mpi( &Q, radix_Q, input_Q ) == 0 );
  1375. if( have_D )
  1376. TEST_ASSERT( mbedtls_test_read_mpi( &D, radix_D, input_D ) == 0 );
  1377. if( have_E )
  1378. TEST_ASSERT( mbedtls_test_read_mpi( &E, radix_E, input_E ) == 0 );
  1379. TEST_ASSERT( mbedtls_rsa_validate_params( have_N ? &N : NULL,
  1380. have_P ? &P : NULL,
  1381. have_Q ? &Q : NULL,
  1382. have_D ? &D : NULL,
  1383. have_E ? &E : NULL,
  1384. prng ? mbedtls_ctr_drbg_random : NULL,
  1385. prng ? &ctr_drbg : NULL ) == result );
  1386. exit:
  1387. mbedtls_ctr_drbg_free( &ctr_drbg );
  1388. mbedtls_entropy_free( &entropy );
  1389. mbedtls_mpi_free( &N );
  1390. mbedtls_mpi_free( &P ); mbedtls_mpi_free( &Q );
  1391. mbedtls_mpi_free( &D ); mbedtls_mpi_free( &E );
  1392. }
  1393. /* END_CASE */
  1394. /* BEGIN_CASE depends_on:MBEDTLS_CTR_DRBG_C:MBEDTLS_ENTROPY_C */
  1395. void mbedtls_rsa_export_raw( data_t *input_N, data_t *input_P,
  1396. data_t *input_Q, data_t *input_D,
  1397. data_t *input_E, int is_priv,
  1398. int successive )
  1399. {
  1400. /* Exported buffers */
  1401. unsigned char bufNe[256];
  1402. unsigned char bufPe[128];
  1403. unsigned char bufQe[128];
  1404. unsigned char bufDe[256];
  1405. unsigned char bufEe[1];
  1406. mbedtls_rsa_context ctx;
  1407. mbedtls_rsa_init( &ctx, 0, 0 );
  1408. /* Setup RSA context */
  1409. TEST_ASSERT( mbedtls_rsa_import_raw( &ctx,
  1410. input_N->len ? input_N->x : NULL, input_N->len,
  1411. input_P->len ? input_P->x : NULL, input_P->len,
  1412. input_Q->len ? input_Q->x : NULL, input_Q->len,
  1413. input_D->len ? input_D->x : NULL, input_D->len,
  1414. input_E->len ? input_E->x : NULL, input_E->len ) == 0 );
  1415. TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == 0 );
  1416. /*
  1417. * Export parameters and compare to original ones.
  1418. */
  1419. /* N and E must always be present. */
  1420. if( !successive )
  1421. {
  1422. TEST_ASSERT( mbedtls_rsa_export_raw( &ctx, bufNe, input_N->len,
  1423. NULL, 0, NULL, 0, NULL, 0,
  1424. bufEe, input_E->len ) == 0 );
  1425. }
  1426. else
  1427. {
  1428. TEST_ASSERT( mbedtls_rsa_export_raw( &ctx, bufNe, input_N->len,
  1429. NULL, 0, NULL, 0, NULL, 0,
  1430. NULL, 0 ) == 0 );
  1431. TEST_ASSERT( mbedtls_rsa_export_raw( &ctx, NULL, 0,
  1432. NULL, 0, NULL, 0, NULL, 0,
  1433. bufEe, input_E->len ) == 0 );
  1434. }
  1435. TEST_ASSERT( memcmp( input_N->x, bufNe, input_N->len ) == 0 );
  1436. TEST_ASSERT( memcmp( input_E->x, bufEe, input_E->len ) == 0 );
  1437. /* If we were providing enough information to setup a complete private context,
  1438. * we expect to be able to export all core parameters. */
  1439. if( is_priv )
  1440. {
  1441. if( !successive )
  1442. {
  1443. TEST_ASSERT( mbedtls_rsa_export_raw( &ctx, NULL, 0,
  1444. bufPe, input_P->len ? input_P->len : sizeof( bufPe ),
  1445. bufQe, input_Q->len ? input_Q->len : sizeof( bufQe ),
  1446. bufDe, input_D->len ? input_D->len : sizeof( bufDe ),
  1447. NULL, 0 ) == 0 );
  1448. }
  1449. else
  1450. {
  1451. TEST_ASSERT( mbedtls_rsa_export_raw( &ctx, NULL, 0,
  1452. bufPe, input_P->len ? input_P->len : sizeof( bufPe ),
  1453. NULL, 0, NULL, 0,
  1454. NULL, 0 ) == 0 );
  1455. TEST_ASSERT( mbedtls_rsa_export_raw( &ctx, NULL, 0, NULL, 0,
  1456. bufQe, input_Q->len ? input_Q->len : sizeof( bufQe ),
  1457. NULL, 0, NULL, 0 ) == 0 );
  1458. TEST_ASSERT( mbedtls_rsa_export_raw( &ctx, NULL, 0, NULL, 0, NULL, 0,
  1459. bufDe, input_D->len ? input_D->len : sizeof( bufDe ),
  1460. NULL, 0 ) == 0 );
  1461. }
  1462. if( input_P->len )
  1463. TEST_ASSERT( memcmp( input_P->x, bufPe, input_P->len ) == 0 );
  1464. if( input_Q->len )
  1465. TEST_ASSERT( memcmp( input_Q->x, bufQe, input_Q->len ) == 0 );
  1466. if( input_D->len )
  1467. TEST_ASSERT( memcmp( input_D->x, bufDe, input_D->len ) == 0 );
  1468. }
  1469. exit:
  1470. mbedtls_rsa_free( &ctx );
  1471. }
  1472. /* END_CASE */
  1473. /* BEGIN_CASE depends_on:MBEDTLS_CTR_DRBG_C:MBEDTLS_ENTROPY_C:ENTROPY_HAVE_STRONG */
  1474. void mbedtls_rsa_import_raw( data_t *input_N,
  1475. data_t *input_P, data_t *input_Q,
  1476. data_t *input_D, data_t *input_E,
  1477. int successive,
  1478. int is_priv,
  1479. int res_check,
  1480. int res_complete )
  1481. {
  1482. /* Buffers used for encryption-decryption test */
  1483. unsigned char *buf_orig = NULL;
  1484. unsigned char *buf_enc = NULL;
  1485. unsigned char *buf_dec = NULL;
  1486. mbedtls_rsa_context ctx;
  1487. mbedtls_entropy_context entropy;
  1488. mbedtls_ctr_drbg_context ctr_drbg;
  1489. const char *pers = "test_suite_rsa";
  1490. mbedtls_ctr_drbg_init( &ctr_drbg );
  1491. mbedtls_entropy_init( &entropy );
  1492. mbedtls_rsa_init( &ctx, 0, 0 );
  1493. TEST_ASSERT( mbedtls_ctr_drbg_seed( &ctr_drbg, mbedtls_entropy_func,
  1494. &entropy, (const unsigned char *) pers,
  1495. strlen( pers ) ) == 0 );
  1496. if( !successive )
  1497. {
  1498. TEST_ASSERT( mbedtls_rsa_import_raw( &ctx,
  1499. ( input_N->len > 0 ) ? input_N->x : NULL, input_N->len,
  1500. ( input_P->len > 0 ) ? input_P->x : NULL, input_P->len,
  1501. ( input_Q->len > 0 ) ? input_Q->x : NULL, input_Q->len,
  1502. ( input_D->len > 0 ) ? input_D->x : NULL, input_D->len,
  1503. ( input_E->len > 0 ) ? input_E->x : NULL, input_E->len ) == 0 );
  1504. }
  1505. else
  1506. {
  1507. /* Import N, P, Q, D, E separately.
  1508. * This should make no functional difference. */
  1509. TEST_ASSERT( mbedtls_rsa_import_raw( &ctx,
  1510. ( input_N->len > 0 ) ? input_N->x : NULL, input_N->len,
  1511. NULL, 0, NULL, 0, NULL, 0, NULL, 0 ) == 0 );
  1512. TEST_ASSERT( mbedtls_rsa_import_raw( &ctx,
  1513. NULL, 0,
  1514. ( input_P->len > 0 ) ? input_P->x : NULL, input_P->len,
  1515. NULL, 0, NULL, 0, NULL, 0 ) == 0 );
  1516. TEST_ASSERT( mbedtls_rsa_import_raw( &ctx,
  1517. NULL, 0, NULL, 0,
  1518. ( input_Q->len > 0 ) ? input_Q->x : NULL, input_Q->len,
  1519. NULL, 0, NULL, 0 ) == 0 );
  1520. TEST_ASSERT( mbedtls_rsa_import_raw( &ctx,
  1521. NULL, 0, NULL, 0, NULL, 0,
  1522. ( input_D->len > 0 ) ? input_D->x : NULL, input_D->len,
  1523. NULL, 0 ) == 0 );
  1524. TEST_ASSERT( mbedtls_rsa_import_raw( &ctx,
  1525. NULL, 0, NULL, 0, NULL, 0, NULL, 0,
  1526. ( input_E->len > 0 ) ? input_E->x : NULL, input_E->len ) == 0 );
  1527. }
  1528. TEST_ASSERT( mbedtls_rsa_complete( &ctx ) == res_complete );
  1529. /* On expected success, perform some public and private
  1530. * key operations to check if the key is working properly. */
  1531. if( res_complete == 0 )
  1532. {
  1533. if( is_priv )
  1534. TEST_ASSERT( mbedtls_rsa_check_privkey( &ctx ) == res_check );
  1535. else
  1536. TEST_ASSERT( mbedtls_rsa_check_pubkey( &ctx ) == res_check );
  1537. if( res_check != 0 )
  1538. goto exit;
  1539. buf_orig = mbedtls_calloc( 1, mbedtls_rsa_get_len( &ctx ) );
  1540. buf_enc = mbedtls_calloc( 1, mbedtls_rsa_get_len( &ctx ) );
  1541. buf_dec = mbedtls_calloc( 1, mbedtls_rsa_get_len( &ctx ) );
  1542. if( buf_orig == NULL || buf_enc == NULL || buf_dec == NULL )
  1543. goto exit;
  1544. TEST_ASSERT( mbedtls_ctr_drbg_random( &ctr_drbg,
  1545. buf_orig, mbedtls_rsa_get_len( &ctx ) ) == 0 );
  1546. /* Make sure the number we're generating is smaller than the modulus */
  1547. buf_orig[0] = 0x00;
  1548. TEST_ASSERT( mbedtls_rsa_public( &ctx, buf_orig, buf_enc ) == 0 );
  1549. if( is_priv )
  1550. {
  1551. TEST_ASSERT( mbedtls_rsa_private( &ctx, mbedtls_ctr_drbg_random,
  1552. &ctr_drbg, buf_enc,
  1553. buf_dec ) == 0 );
  1554. TEST_ASSERT( memcmp( buf_orig, buf_dec,
  1555. mbedtls_rsa_get_len( &ctx ) ) == 0 );
  1556. }
  1557. }
  1558. exit:
  1559. mbedtls_free( buf_orig );
  1560. mbedtls_free( buf_enc );
  1561. mbedtls_free( buf_dec );
  1562. mbedtls_rsa_free( &ctx );
  1563. mbedtls_ctr_drbg_free( &ctr_drbg );
  1564. mbedtls_entropy_free( &entropy );
  1565. }
  1566. /* END_CASE */
  1567. /* BEGIN_CASE depends_on:MBEDTLS_SELF_TEST */
  1568. void rsa_selftest( )
  1569. {
  1570. TEST_ASSERT( mbedtls_rsa_self_test( 1 ) == 0 );
  1571. }
  1572. /* END_CASE */