gtests/mozpkix_gtest/pkixcheck_ParseValidity_tests.cpp
author Kevin Jacobs <kjacobs@mozilla.com>
Tue, 27 Aug 2019 14:45:43 +0000
changeset 15273 24b0fc7002039af07f6976d46ee7e186970c5cdb
parent 14907 403437c461fdd08f7a3a9dc7eba3c66e8c0c5ab9
permissions -rw-r--r--
Bug 1485533 - Close gaps in taskcluster SSL testing. r=mt This patch increases SSL testing on taskcluster, specifically, running an additional 395 tests on each SSL cycle (more for FIPS targets), and adding a new 'stress' cycle. Notable changes: 1) This patch removes SSL stress tests from the default `NSS_SSL_RUN` list in all.sh and ssl.sh. If stress tests are needed, this variable must be set to include. 2) The "normal_normal" case is added to `NSS_SSL_TESTS` for all targets. FIPS targets also run "normal_fips", "fips_normal", and "fips_fips". 3) `--enable-libpkix` is now set for all taskcluster "build.sh" builds in order to support a number of OCSP tests that were previously not run. Differential Revision: https://phabricator.services.mozilla.com/D43283

/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
/* vim: set ts=8 sts=2 et sw=2 tw=80: */
/* This code is made available to you under your choice of the following sets
 * of licensing terms:
 */
/* This Source Code Form is subject to the terms of the Mozilla Public
 * License, v. 2.0. If a copy of the MPL was not distributed with this
 * file, You can obtain one at http://mozilla.org/MPL/2.0/.
 */
/* Copyright 2014 Mozilla Contributors
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 *     http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

#include "pkixgtest.h"

#include "mozpkix/pkixcheck.h"

using namespace mozilla::pkix;
using namespace mozilla::pkix::test;

#define OLDER_UTCTIME \
  0x17, 13,                               /* tag, length */ \
  '9', '9', '0', '1', '0', '1',           /* (19)99-01-01 */ \
  '0', '0', '0', '0', '0', '0', 'Z'       /* 00:00:00Z */

#define NEWER_UTCTIME \
  0x17, 13,                               /* tag, length */ \
  '2', '1', '0', '1', '0', '1',           /* 2021-01-01 */ \
  '0', '0', '0', '0', '0', '0', 'Z'       /* 00:00:00Z */

static const Time FUTURE_TIME(YMDHMS(2025, 12, 31, 12, 23, 56));

class pkixcheck_ParseValidity : public ::testing::Test { };

TEST_F(pkixcheck_ParseValidity, BothEmptyNull)
{
  static const uint8_t DER[] = {
    0x17/*UTCTime*/, 0/*length*/,
    0x17/*UTCTime*/, 0/*length*/,
  };
  static const Input validity(DER);
  ASSERT_EQ(Result::ERROR_INVALID_DER_TIME, ParseValidity(validity));
}

TEST_F(pkixcheck_ParseValidity, NotBeforeEmptyNull)
{
  static const uint8_t DER[] = {
    0x17/*UTCTime*/, 0x00/*length*/,
    NEWER_UTCTIME
  };
  static const Input validity(DER);
  ASSERT_EQ(Result::ERROR_INVALID_DER_TIME, ParseValidity(validity));
}

TEST_F(pkixcheck_ParseValidity, NotAfterEmptyNull)
{
  static const uint8_t DER[] = {
    NEWER_UTCTIME,
    0x17/*UTCTime*/, 0x00/*length*/,
  };
  static const Input validity(DER);
  ASSERT_EQ(Result::ERROR_INVALID_DER_TIME, ParseValidity(validity));
}

TEST_F(pkixcheck_ParseValidity, InvalidNotAfterBeforeNotBefore)
{
  static const uint8_t DER[] = {
    NEWER_UTCTIME,
    OLDER_UTCTIME,
  };
  static const Input validity(DER);
  ASSERT_EQ(Result::ERROR_INVALID_DER_TIME, ParseValidity(validity));
}