diff options
Diffstat (limited to 'src/regress/lib/libcrypto')
| -rw-r--r-- | src/regress/lib/libcrypto/Makefile | 3 | ||||
| -rw-r--r-- | src/regress/lib/libcrypto/curve25519/Makefile | 9 | ||||
| -rw-r--r-- | src/regress/lib/libcrypto/curve25519/x25519test.c | 139 |
3 files changed, 150 insertions, 1 deletions
diff --git a/src/regress/lib/libcrypto/Makefile b/src/regress/lib/libcrypto/Makefile index dc11c60e92..595d1094da 100644 --- a/src/regress/lib/libcrypto/Makefile +++ b/src/regress/lib/libcrypto/Makefile | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | # $OpenBSD: Makefile,v 1.24 2016/11/04 19:45:12 jsing Exp $ | 1 | # $OpenBSD: Makefile,v 1.25 2016/11/05 15:09:02 jsing Exp $ |
| 2 | 2 | ||
| 3 | SUBDIR= \ | 3 | SUBDIR= \ |
| 4 | aead \ | 4 | aead \ |
| @@ -11,6 +11,7 @@ SUBDIR= \ | |||
| 11 | cast \ | 11 | cast \ |
| 12 | chacha \ | 12 | chacha \ |
| 13 | cts128 \ | 13 | cts128 \ |
| 14 | curve25519 \ | ||
| 14 | des \ | 15 | des \ |
| 15 | dh \ | 16 | dh \ |
| 16 | dsa \ | 17 | dsa \ |
diff --git a/src/regress/lib/libcrypto/curve25519/Makefile b/src/regress/lib/libcrypto/curve25519/Makefile new file mode 100644 index 0000000000..1bc4965670 --- /dev/null +++ b/src/regress/lib/libcrypto/curve25519/Makefile | |||
| @@ -0,0 +1,9 @@ | |||
| 1 | # $OpenBSD: Makefile,v 1.1 2016/11/05 15:09:02 jsing Exp $ | ||
| 2 | |||
| 3 | PROG= x25519test | ||
| 4 | LDADD= -lcrypto | ||
| 5 | DPADD= ${LIBCRYPTO} | ||
| 6 | WARNINGS= Yes | ||
| 7 | CFLAGS+= -DLIBRESSL_INTERNAL -Werror | ||
| 8 | |||
| 9 | .include <bsd.regress.mk> | ||
diff --git a/src/regress/lib/libcrypto/curve25519/x25519test.c b/src/regress/lib/libcrypto/curve25519/x25519test.c new file mode 100644 index 0000000000..ae6e296a3d --- /dev/null +++ b/src/regress/lib/libcrypto/curve25519/x25519test.c | |||
| @@ -0,0 +1,139 @@ | |||
| 1 | /* | ||
| 2 | * Copyright (c) 2015, Google Inc. | ||
| 3 | * | ||
| 4 | * Permission to use, copy, modify, and/or distribute this software for any | ||
| 5 | * purpose with or without fee is hereby granted, provided that the above | ||
| 6 | * copyright notice and this permission notice appear in all copies. | ||
| 7 | * | ||
| 8 | * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES | ||
| 9 | * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF | ||
| 10 | * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY | ||
| 11 | * SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES | ||
| 12 | * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION | ||
| 13 | * OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN | ||
| 14 | * CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. | ||
| 15 | */ | ||
| 16 | |||
| 17 | #include <stdint.h> | ||
| 18 | #include <stdio.h> | ||
| 19 | #include <string.h> | ||
| 20 | |||
| 21 | #include <openssl/curve25519.h> | ||
| 22 | |||
| 23 | static int | ||
| 24 | x25519_test(void) | ||
| 25 | { | ||
| 26 | /* Taken from https://tools.ietf.org/html/rfc7748#section-5.2 */ | ||
| 27 | static const uint8_t kScalar1[32] = { | ||
| 28 | 0xa5, 0x46, 0xe3, 0x6b, 0xf0, 0x52, 0x7c, 0x9d, | ||
| 29 | 0x3b, 0x16, 0x15, 0x4b, 0x82, 0x46, 0x5e, 0xdd, | ||
| 30 | 0x62, 0x14, 0x4c, 0x0a, 0xc1, 0xfc, 0x5a, 0x18, | ||
| 31 | 0x50, 0x6a, 0x22, 0x44, 0xba, 0x44, 0x9a, 0xc4, | ||
| 32 | }; | ||
| 33 | static const uint8_t kPoint1[32] = { | ||
| 34 | 0xe6, 0xdb, 0x68, 0x67, 0x58, 0x30, 0x30, 0xdb, | ||
| 35 | 0x35, 0x94, 0xc1, 0xa4, 0x24, 0xb1, 0x5f, 0x7c, | ||
| 36 | 0x72, 0x66, 0x24, 0xec, 0x26, 0xb3, 0x35, 0x3b, | ||
| 37 | 0x10, 0xa9, 0x03, 0xa6, 0xd0, 0xab, 0x1c, 0x4c, | ||
| 38 | }; | ||
| 39 | static const uint8_t kExpected1[32] = { | ||
| 40 | 0xc3, 0xda, 0x55, 0x37, 0x9d, 0xe9, 0xc6, 0x90, | ||
| 41 | 0x8e, 0x94, 0xea, 0x4d, 0xf2, 0x8d, 0x08, 0x4f, | ||
| 42 | 0x32, 0xec, 0xcf, 0x03, 0x49, 0x1c, 0x71, 0xf7, | ||
| 43 | 0x54, 0xb4, 0x07, 0x55, 0x77, 0xa2, 0x85, 0x52, | ||
| 44 | }; | ||
| 45 | static const uint8_t kScalar2[32] = { | ||
| 46 | 0x4b, 0x66, 0xe9, 0xd4, 0xd1, 0xb4, 0x67, 0x3c, | ||
| 47 | 0x5a, 0xd2, 0x26, 0x91, 0x95, 0x7d, 0x6a, 0xf5, | ||
| 48 | 0xc1, 0x1b, 0x64, 0x21, 0xe0, 0xea, 0x01, 0xd4, | ||
| 49 | 0x2c, 0xa4, 0x16, 0x9e, 0x79, 0x18, 0xba, 0x0d, | ||
| 50 | }; | ||
| 51 | static const uint8_t kPoint2[32] = { | ||
| 52 | 0xe5, 0x21, 0x0f, 0x12, 0x78, 0x68, 0x11, 0xd3, | ||
| 53 | 0xf4, 0xb7, 0x95, 0x9d, 0x05, 0x38, 0xae, 0x2c, | ||
| 54 | 0x31, 0xdb, 0xe7, 0x10, 0x6f, 0xc0, 0x3c, 0x3e, | ||
| 55 | 0xfc, 0x4c, 0xd5, 0x49, 0xc7, 0x15, 0xa4, 0x93, | ||
| 56 | }; | ||
| 57 | static const uint8_t kExpected2[32] = { | ||
| 58 | 0x95, 0xcb, 0xde, 0x94, 0x76, 0xe8, 0x90, 0x7d, | ||
| 59 | 0x7a, 0xad, 0xe4, 0x5c, 0xb4, 0xb8, 0x73, 0xf8, | ||
| 60 | 0x8b, 0x59, 0x5a, 0x68, 0x79, 0x9f, 0xa1, 0x52, | ||
| 61 | 0xe6, 0xf8, 0xf7, 0x64, 0x7a, 0xac, 0x79, 0x57, | ||
| 62 | }; | ||
| 63 | |||
| 64 | uint8_t out[32]; | ||
| 65 | |||
| 66 | X25519(out, kScalar1, kPoint1); | ||
| 67 | if (memcmp(kExpected1, out, sizeof(out)) != 0) { | ||
| 68 | fprintf(stderr, "X25519 test one failed.\n"); | ||
| 69 | return 0; | ||
| 70 | } | ||
| 71 | |||
| 72 | X25519(out, kScalar2, kPoint2); | ||
| 73 | if (memcmp(kExpected2, out, sizeof(out)) != 0) { | ||
| 74 | fprintf(stderr, "X25519 test two failed.\n"); | ||
| 75 | return 0; | ||
| 76 | } | ||
| 77 | |||
| 78 | return 1; | ||
| 79 | } | ||
| 80 | |||
| 81 | static int | ||
| 82 | x25519_iterated_test(void) | ||
| 83 | { | ||
| 84 | /* Taken from https://tools.ietf.org/html/rfc7748#section-5.2 */ | ||
| 85 | static const uint8_t kExpected[32] = { | ||
| 86 | 0x68, 0x4c, 0xf5, 0x9b, 0xa8, 0x33, 0x09, 0x55, | ||
| 87 | 0x28, 0x00, 0xef, 0x56, 0x6f, 0x2f, 0x4d, 0x3c, | ||
| 88 | 0x1c, 0x38, 0x87, 0xc4, 0x93, 0x60, 0xe3, 0x87, | ||
| 89 | 0x5f, 0x2e, 0xb9, 0x4d, 0x99, 0x53, 0x2c, 0x51, | ||
| 90 | }; | ||
| 91 | |||
| 92 | uint8_t scalar[32] = {9}, point[32] = {9}, out[32]; | ||
| 93 | unsigned i; | ||
| 94 | |||
| 95 | for (i = 0; i < 1000; i++) { | ||
| 96 | X25519(out, scalar, point); | ||
| 97 | memcpy(point, scalar, sizeof(point)); | ||
| 98 | memcpy(scalar, out, sizeof(scalar)); | ||
| 99 | } | ||
| 100 | |||
| 101 | if (memcmp(kExpected, scalar, sizeof(kExpected)) != 0) { | ||
| 102 | fprintf(stderr, "Iterated X25519 test failed\n"); | ||
| 103 | return 0; | ||
| 104 | } | ||
| 105 | |||
| 106 | return 1; | ||
| 107 | } | ||
| 108 | |||
| 109 | static int | ||
| 110 | x25519_small_order_test(void) | ||
| 111 | { | ||
| 112 | static const uint8_t kSmallOrderPoint[32] = { | ||
| 113 | 0xe0, 0xeb, 0x7a, 0x7c, 0x3b, 0x41, 0xb8, 0xae, | ||
| 114 | 0x16, 0x56, 0xe3, 0xfa, 0xf1, 0x9f, 0xc4, 0x6a, | ||
| 115 | 0xda, 0x09, 0x8d, 0xeb, 0x9c, 0x32, 0xb1, 0xfd, | ||
| 116 | 0x86, 0x62, 0x05, 0x16, 0x5f, 0x49, 0xb8, 0x00, | ||
| 117 | }; | ||
| 118 | |||
| 119 | uint8_t out[32], private_key[32]; | ||
| 120 | |||
| 121 | memset(private_key, 0x11, sizeof(private_key)); | ||
| 122 | if (X25519(out, private_key, kSmallOrderPoint)) { | ||
| 123 | fprintf(stderr, "X25519 returned success with a small-order input.\n"); | ||
| 124 | return 0; | ||
| 125 | } | ||
| 126 | |||
| 127 | return 1; | ||
| 128 | } | ||
| 129 | |||
| 130 | int | ||
| 131 | main(int argc, char **argv) { | ||
| 132 | if (!x25519_test() || | ||
| 133 | !x25519_iterated_test() || | ||
| 134 | !x25519_small_order_test()) | ||
| 135 | return 1; | ||
| 136 | |||
| 137 | printf("PASS\n"); | ||
| 138 | return 0; | ||
| 139 | } | ||
