From db25f3e3e0fd18000f65ea5104ce61585413fb46 Mon Sep 17 00:00:00 2001 From: "shoney.arickathil" Date: Wed, 9 Sep 2026 04:45:33 +0200 Subject: [PATCH] feat(crypto): private-key DER parsing (rv2 9 phase G3a) - wo_pkey_parse: PKCS#8 PrivateKeyInfo (wrapping PKCS#1/SEC1), bare PKCS#1 RSAPrivateKey, and bare SEC1 ECPrivateKey -> RSA (n,d) or the EC P-256 32-byte scalar. Reuses the X.509 DER reader; spans point into the buffer - KAT: all three formats parse, and the extracted key signs a hash our verify accepts (RSA-PSS + ECDSA); garbage rejected. test_crypto 130, ASan/UBSan clean Co-Authored-By: Claude Opus 4.8 (cherry picked from commit 819d67226a94c4cd5a765ec403e57466c64f1e65) --- runtime/src/crypto.c | 70 +++++++++ runtime/src/crypto.h | 6 + runtime/test/pkey_vectors.h | 292 ++++++++++++++++++++++++++++++++++++ runtime/test/test_crypto.c | 32 ++++ 4 files changed, 400 insertions(+) create mode 100644 runtime/test/pkey_vectors.h diff --git a/runtime/src/crypto.c b/runtime/src/crypto.c index 24f3529..8c29331 100644 --- a/runtime/src/crypto.c +++ b/runtime/src/crypto.c @@ -1864,6 +1864,76 @@ int wo_x509_eku_serverauth_ok(const uint8_t *cert_der, size_t cert_len) { return 0; /* present, no serverAuth */ } +/* ---- private-key parsing (rv2 9 phase G3) -------------------------------- + * Parse a DER private key โ€” PKCS#8 (PrivateKeyInfo wrapping PKCS#1/SEC1), + * bare PKCS#1 RSAPrivateKey, or bare SEC1 ECPrivateKey โ€” into the material the + * signers need: RSA (n, d) or the EC P-256 32-byte scalar. Spans point into + * der_buf (the caller keeps it). */ + +/* Read RSAPrivateKey fields after its version: modulus, publicExponent (skip), + * privateExponent. Leading zero sign-bytes are stripped. */ +static int pkey_rsa_after_version(der *s, const uint8_t **n, size_t *nlen, + const uint8_t **d, size_t *dlen) { + const uint8_t *np, *ep, *dp; size_t nl, el, dl; + if (der_tlv(s, &np, &nl) != 0x02) return -1; /* modulus */ + if (der_tlv(s, &ep, &el) != 0x02) return -1; /* publicExponent */ + if (der_tlv(s, &dp, &dl) != 0x02) return -1; /* privateExponent */ + (void)ep; (void)el; + while (nl > 1 && np[0] == 0) { np++; nl--; } + while (dl > 1 && dp[0] == 0) { dp++; dl--; } + *n = np; *nlen = nl; *d = dp; *dlen = dl; + return 0; +} +/* Read the SEC1 ECPrivateKey 32-byte scalar (the OCTET STRING after version). */ +static int pkey_ec_after_version(der *s, const uint8_t **ec_d) { + const uint8_t *p; size_t l; + if (der_tlv(s, &p, &l) != 0x04 || l != 32) return -1; + *ec_d = p; + return 0; +} + +int wo_pkey_parse(const uint8_t *der_buf, size_t len, int *key_alg, + const uint8_t **rsa_n, size_t *rsa_nlen, + const uint8_t **rsa_d, size_t *rsa_dlen, const uint8_t **ec_d) { + *key_alg = 0; + der top = { der_buf, der_buf + len }, seq; + if (der_into(&top, 0x30, &seq) < 0) return -1; + const uint8_t *vp; size_t vl; + if (der_tlv(&seq, &vp, &vl) != 0x02) return -1; /* version INTEGER */ + if (seq.p >= seq.end) return -1; + uint8_t next = *seq.p; + if (next == 0x30) { /* PKCS#8 PrivateKeyInfo */ + der alg; + if (der_into(&seq, 0x30, &alg) < 0) return -1; + const uint8_t *oid; size_t oidl; + if (der_tlv(&alg, &oid, &oidl) != 0x06) return -1; + const uint8_t *pk; size_t pkl; + if (der_tlv(&seq, &pk, &pkl) != 0x04) return -1; /* privateKey OCTET STRING */ + der inner = { pk, pk + pkl }, iseq; + if (der_into(&inner, 0x30, &iseq) < 0) return -1; + const uint8_t *iv2; size_t il2; + if (der_tlv(&iseq, &iv2, &il2) != 0x02) return -1; /* inner version */ + if (oid_eq(oid, oidl, OID_RSA_ENC, sizeof OID_RSA_ENC)) { + if (pkey_rsa_after_version(&iseq, rsa_n, rsa_nlen, rsa_d, rsa_dlen) != 0) return -1; + *key_alg = WO_X509_KEY_RSA; return 0; + } + if (oid_eq(oid, oidl, OID_EC_PUBKEY, sizeof OID_EC_PUBKEY)) { + if (pkey_ec_after_version(&iseq, ec_d) != 0) return -1; + *key_alg = WO_X509_KEY_EC_P256; return 0; + } + return -1; + } + if (next == 0x02) { /* bare PKCS#1 RSAPrivateKey */ + if (pkey_rsa_after_version(&seq, rsa_n, rsa_nlen, rsa_d, rsa_dlen) != 0) return -1; + *key_alg = WO_X509_KEY_RSA; return 0; + } + if (next == 0x04) { /* bare SEC1 ECPrivateKey */ + if (pkey_ec_after_version(&seq, ec_d) != 0) return -1; + *key_alg = WO_X509_KEY_EC_P256; return 0; + } + return -1; +} + /* Case-insensitive match of a presented dNSName pattern against a hostname, * with a single left-most "*" wildcard (RFC 6125 ยง6.4.3): "*.example.com" * matches one label, never a bare "example.com" or a dotted sub-label. */ diff --git a/runtime/src/crypto.h b/runtime/src/crypto.h index 9d9061b..291c0ee 100644 --- a/runtime/src/crypto.h +++ b/runtime/src/crypto.h @@ -106,6 +106,12 @@ int wo_x509_basic_constraints(const uint8_t *cert_der, size_t cert_len, /* Extended Key Usage: 1 if usable as a TLS server cert (EKU absent, or lists * serverAuth / anyExtendedKeyUsage), 0 otherwise. (rv2 9 F3c decision 6) */ int wo_x509_eku_serverauth_ok(const uint8_t *cert_der, size_t cert_len); +/* Parse a DER private key (PKCS#8 / PKCS#1 RSAPrivateKey / SEC1 ECPrivateKey) + * into RSA (n,d) or an EC P-256 32-byte scalar. Spans point into der_buf. + * *key_alg gets 1 (RSA) or 2 (EC P-256). 0 ok, -1 malformed/unsupported. */ +int wo_pkey_parse(const uint8_t *der_buf, size_t len, int *key_alg, + const uint8_t **rsa_n, size_t *rsa_nlen, + const uint8_t **rsa_d, size_t *rsa_dlen, const uint8_t **ec_d); int wo_builtin_crypto(wo_vm *vm, uint64_t *R, uint32_t ins, const char **msg); diff --git a/runtime/test/pkey_vectors.h b/runtime/test/pkey_vectors.h new file mode 100644 index 0000000..6d8036a --- /dev/null +++ b/runtime/test/pkey_vectors.h @@ -0,0 +1,292 @@ +/* Private-key DER vectors: RSA (PKCS#8 + PKCS#1), EC P-256 (PKCS#8 + SEC1), + * plus the matching public keys for a sign->verify round-trip. */ +static const unsigned char pk_rsa_pk8[] = { + 0x30,0x82,0x04,0xbd,0x02,0x01,0x00,0x30,0x0d,0x06,0x09,0x2a, + 0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x01,0x05,0x00,0x04,0x82, + 0x04,0xa7,0x30,0x82,0x04,0xa3,0x02,0x01,0x00,0x02,0x82,0x01, + 0x01,0x00,0xb8,0x41,0xd1,0x7c,0xa3,0x79,0x4e,0xd2,0x3c,0x83, + 0x06,0x85,0x87,0xec,0xf4,0x2a,0xbd,0x48,0x54,0x82,0xb4,0x75, + 0xa5,0x71,0x73,0x7f,0xaf,0x3b,0xd9,0x45,0x0b,0xf5,0x50,0x76, + 0x7c,0x83,0xc9,0x07,0xcc,0xe6,0x19,0xdb,0x1b,0x83,0xf8,0xc8, + 0xc2,0xcc,0x09,0xd7,0x99,0xb9,0x30,0x98,0x7e,0xbf,0xb8,0xec, + 0x76,0x0a,0x6c,0x41,0x88,0x17,0x9f,0xed,0xac,0x39,0x06,0xfd, + 0x5f,0xbd,0x97,0x41,0x47,0x4f,0x62,0xf5,0x74,0x6f,0xd2,0x5e, + 0x54,0x7f,0xfe,0x17,0xb8,0x44,0x18,0x2c,0x56,0x07,0x63,0x35, + 0x68,0x4e,0x12,0x9d,0x68,0xc9,0x76,0xce,0x4f,0x44,0x02,0xeb, + 0xf1,0x41,0xc0,0xab,0x34,0xf4,0x48,0xc8,0x55,0xd8,0xa9,0xd4, + 0x84,0xe2,0x64,0x4b,0xac,0x4e,0xf0,0x88,0x7b,0xab,0xf4,0xdc, + 0xa1,0x11,0xe9,0xc2,0x86,0xff,0x40,0xd8,0x83,0xfe,0x86,0x04, + 0x0d,0xe2,0x52,0x27,0xef,0x14,0xad,0xdc,0x90,0x4d,0x8a,0x8a, + 0xcc,0xda,0x60,0x32,0x96,0x3e,0x60,0x84,0x10,0xcd,0x5d,0x91, + 0x85,0x6c,0x75,0x74,0xdc,0xb1,0xf3,0xed,0x92,0x9d,0x1e,0xf2, + 0xa7,0x65,0x72,0x00,0x7d,0x51,0x66,0x8f,0xc5,0x2b,0x26,0xf8, + 0x9f,0xb6,0x42,0xba,0x5a,0x01,0x9e,0xdd,0xe9,0x61,0x24,0x60, + 0xbf,0x13,0x09,0xbf,0xea,0x05,0x28,0xe3,0x7f,0x09,0x54,0x4f, + 0x6d,0x9b,0x40,0xc3,0x7f,0x5c,0x90,0x03,0xa2,0xeb,0xa8,0x66, + 0x36,0xac,0x2e,0x6d,0xac,0x32,0xc5,0xf5,0xc5,0xb5,0xf2,0xbd, + 0x80,0x4c,0x82,0x93,0xa3,0x6d,0x3a,0x91,0xda,0x38,0x47,0xf8, + 0xe6,0x5d,0xf4,0x48,0xfb,0xcb,0x02,0x03,0x01,0x00,0x01,0x02, + 0x82,0x01,0x00,0x03,0x9a,0xb6,0x00,0x5c,0x2a,0x49,0x52,0x6f, + 0x80,0x98,0xa6,0x10,0x0c,0xa0,0x92,0x1d,0x75,0xc6,0xc1,0x6f, + 0xca,0x45,0x5c,0x3c,0xc8,0x28,0xa3,0x61,0x12,0xaa,0xb3,0x37, + 0xc9,0xb9,0x91,0xd2,0x62,0xe6,0xad,0x31,0xa0,0x49,0x9f,0x81, + 0x44,0x5c,0x1b,0x25,0xae,0x24,0x01,0xad,0x63,0xae,0x47,0x0d, + 0xd5,0x02,0x52,0x1d,0xe0,0x02,0x4b,0x84,0x03,0x60,0x35,0x15, + 0x5f,0xeb,0x79,0x87,0xf5,0xec,0xf1,0x2e,0x9c,0x62,0x94,0xb5, + 0x66,0xc6,0xfc,0x61,0xfa,0x10,0xce,0xb4,0x32,0x59,0xd4,0x77, + 0x2a,0x5a,0x49,0xfc,0xaf,0x3b,0x97,0x85,0x4d,0x6f,0xdb,0x82, + 0xbb,0x1e,0xd3,0x0c,0x73,0xcc,0xeb,0x62,0x69,0x18,0xd4,0xce, + 0x2d,0xac,0x13,0xc9,0xa6,0x79,0x4e,0x6a,0x02,0x21,0x79,0x29, + 0x0c,0x6f,0x93,0x95,0x70,0x07,0x1a,0x99,0xc5,0x92,0x71,0x46, + 0xc6,0xb5,0x40,0xff,0xa2,0x4c,0x8b,0x5a,0x81,0x7d,0x8f,0xfd, + 0xbb,0xfb,0xa3,0xd5,0x9b,0xd5,0x63,0x70,0xb6,0xae,0xf0,0x36, + 0x0a,0x1c,0xac,0x7e,0x4c,0x32,0x8c,0x9f,0xf3,0x30,0x4f,0x15, + 0x3a,0x8c,0x8c,0x6b,0xe1,0xf0,0xb4,0xb5,0x75,0x94,0x53,0x9d, + 0x02,0x42,0xd8,0x32,0xea,0x1e,0x0f,0x18,0x07,0x91,0x6d,0x66, + 0xa4,0xaf,0xda,0xc2,0xe4,0x3d,0x7b,0x85,0x1e,0x0d,0x06,0x3b, + 0xee,0xe5,0x1e,0x9a,0xdd,0xa9,0xa8,0x1b,0x1a,0x1b,0x3c,0x9c, + 0x64,0x2b,0xd5,0x0e,0x47,0xfe,0x51,0x96,0x8e,0x07,0xdb,0x50, + 0xe3,0x33,0x1d,0x04,0x71,0x19,0xf7,0xb8,0x6a,0x61,0x38,0x1a, + 0xdd,0x35,0x3d,0xa8,0x36,0x79,0x01,0x02,0x81,0x81,0x00,0xfe, + 0x7b,0x24,0xea,0x19,0x33,0xb7,0x4b,0x75,0x29,0x4b,0xae,0x17, + 0x7a,0x39,0xf1,0x11,0xec,0x5a,0xba,0x91,0x0f,0x81,0x66,0x6a, + 0xb7,0xc4,0x2b,0x70,0x72,0x2a,0xe3,0x81,0x47,0x5e,0x4c,0xf0, + 0x34,0x3d,0x28,0x7d,0x77,0x88,0x0d,0x6a,0x01,0x35,0x81,0xa8, + 0x77,0x66,0xe0,0x25,0x1d,0xec,0xab,0x48,0x46,0xb8,0x04,0x98, + 0x3d,0x3a,0xbc,0x0d,0xee,0x55,0xe0,0xd0,0x1b,0x72,0x46,0xbd, + 0xe5,0x02,0x8c,0xa5,0xb7,0xcd,0x2f,0xe4,0xa1,0xc4,0xa9,0x94, + 0x8b,0x07,0x32,0x31,0xa2,0x8e,0x45,0x16,0x77,0xa0,0xb4,0xc5, + 0x56,0x49,0xce,0x6a,0x9b,0x88,0x41,0x22,0xa7,0xa2,0xe2,0xa8, + 0x2e,0xfb,0x1f,0x26,0x24,0x7d,0x92,0x23,0x8d,0x8d,0xb6,0x05, + 0x52,0x44,0x8f,0xba,0xe2,0x19,0x41,0x02,0x81,0x81,0x00,0xb9, + 0x5b,0x5e,0x99,0x08,0xf2,0x8c,0x15,0x11,0x8a,0x6f,0x42,0x35, + 0xd4,0x81,0x54,0x84,0xaa,0x92,0x06,0x6e,0xe7,0x67,0x44,0xb7, + 0xfd,0xe4,0x60,0x68,0xd4,0x30,0x64,0x6f,0xc9,0x58,0xdc,0xe3, + 0x1d,0xa3,0x9a,0x0a,0x39,0x11,0x62,0x24,0x84,0xdf,0xa6,0x23, + 0x7c,0x18,0x63,0xaa,0xaa,0x88,0xee,0x5f,0x53,0x7a,0x57,0x6a, + 0x03,0xb5,0xf5,0x76,0x3b,0x3f,0x64,0xaf,0x13,0xa5,0xa2,0xf9, + 0x09,0x6a,0x5d,0x1b,0x25,0x31,0x3f,0xc7,0xbc,0xb5,0x20,0x0e, + 0x9e,0x3f,0xc5,0x51,0x5f,0x23,0xdb,0xd0,0xf7,0xc5,0xc3,0xf0, + 0xe2,0x5a,0x0c,0xde,0x5e,0x99,0xd7,0xe7,0x46,0x77,0x39,0x62, + 0x04,0x56,0x01,0xea,0xfc,0xd8,0x36,0x78,0x71,0xcd,0x02,0xd7, + 0xc1,0x5e,0x89,0xa4,0x02,0x66,0x0b,0x02,0x81,0x81,0x00,0xaf, + 0xae,0xdc,0x21,0x31,0x1c,0xde,0xe1,0x9d,0x14,0xd1,0x46,0x72, + 0xb6,0xd2,0xe1,0x76,0x7a,0x31,0x78,0xb3,0x44,0x7d,0x14,0xf3, + 0x7f,0xc2,0x52,0x2a,0xe2,0xe6,0x71,0x01,0x82,0xff,0xbb,0x25, + 0xe9,0x2a,0x7f,0x95,0x7e,0xbb,0xd2,0x66,0xe8,0x46,0xc4,0x28, + 0x45,0xa6,0x23,0xff,0xfb,0xd4,0xb3,0xba,0xc5,0xf7,0xac,0x54, + 0x5d,0x90,0xfa,0xda,0xb3,0x3b,0x5e,0x64,0xcd,0x4d,0xeb,0x40, + 0x95,0xa5,0x58,0xeb,0xdf,0x24,0x2c,0x78,0x2e,0xa5,0xd2,0x5c, + 0xd6,0x4e,0x35,0x7c,0xc6,0xb8,0x69,0x41,0xc5,0x7c,0x90,0xcf, + 0xdb,0x6e,0x40,0xae,0xa0,0x89,0x44,0x4e,0x64,0x64,0xb3,0x0d, + 0x60,0xc1,0xc5,0x13,0x54,0x05,0xcc,0xa9,0xf6,0xc3,0x6a,0x71, + 0xea,0x05,0xa3,0x24,0x65,0x8b,0x01,0x02,0x81,0x80,0x5d,0x6e, + 0xa4,0x29,0x89,0xec,0x11,0x16,0x91,0xa7,0xf1,0x5b,0x33,0x9d, + 0x31,0xaf,0xf3,0xcb,0xb3,0x1d,0xd1,0x0b,0x8d,0xef,0x82,0xbb, + 0x55,0x42,0x0f,0xb5,0x5d,0xcb,0x52,0xd9,0xf0,0x94,0x2f,0x5b, + 0x82,0x5b,0x24,0x6a,0x0d,0xcc,0x25,0xd2,0x60,0x95,0xf3,0x6f, + 0x1b,0x30,0x2a,0x18,0x1a,0x3b,0xe6,0x0b,0x43,0x31,0x0a,0xfc, + 0x61,0xdd,0x20,0x42,0xcf,0x3a,0xa6,0x51,0xc5,0xfd,0x77,0x80, + 0xfa,0x7f,0x82,0x2e,0x66,0x3b,0xdb,0x27,0xd1,0x39,0x1e,0x85, + 0x40,0x69,0xeb,0x11,0x85,0x16,0xc9,0xa8,0x0b,0xa5,0x30,0x28, + 0x38,0xf2,0x21,0xa9,0x17,0xed,0x4f,0xe4,0x22,0x36,0xe7,0xa4, + 0x7d,0xe2,0x2b,0x9c,0x56,0x34,0x66,0xd4,0x1e,0x5e,0x1f,0x79, + 0x96,0x78,0xd5,0x16,0x6c,0x6f,0x02,0x81,0x80,0x1e,0x75,0x6f, + 0x1b,0x4d,0x0a,0x7c,0x56,0xc5,0xaf,0x4e,0xf7,0x6c,0xfd,0xaf, + 0xe2,0x7a,0x57,0x54,0x3b,0xa0,0xda,0xba,0x09,0xc9,0x1a,0x59, + 0x78,0xd6,0x26,0x31,0xac,0x52,0x56,0x5a,0x1a,0x88,0x9d,0x50, + 0x1e,0xbe,0xce,0xda,0xf1,0x70,0x0b,0x4c,0x9d,0x2f,0xa0,0x3f, + 0xcd,0x41,0x6c,0xb2,0x46,0xcf,0x65,0xca,0x16,0x75,0xab,0x98, + 0x2a,0xc8,0x16,0x1d,0x83,0x59,0x5d,0xb8,0xed,0x9a,0x74,0xfc, + 0x5d,0x89,0xda,0x7e,0x0f,0xc3,0x5a,0x1b,0xb5,0xab,0x70,0x29, + 0x4f,0x4d,0x29,0x40,0xe8,0xd9,0xf7,0x55,0x7e,0x05,0x91,0xf0, + 0x21,0x4c,0x4e,0x27,0x16,0x28,0x24,0xf2,0x23,0x38,0x77,0xa4, + 0x3a,0x49,0x29,0xd1,0x15,0x22,0xd4,0x7c,0xc1,0x06,0x25,0x34, + 0x44,0xd1,0x61,0xf8,0x4d, +}; + +static const unsigned char pk_rsa_pk1[] = { + 0x30,0x82,0x04,0xa3,0x02,0x01,0x00,0x02,0x82,0x01,0x01,0x00, + 0xb8,0x41,0xd1,0x7c,0xa3,0x79,0x4e,0xd2,0x3c,0x83,0x06,0x85, + 0x87,0xec,0xf4,0x2a,0xbd,0x48,0x54,0x82,0xb4,0x75,0xa5,0x71, + 0x73,0x7f,0xaf,0x3b,0xd9,0x45,0x0b,0xf5,0x50,0x76,0x7c,0x83, + 0xc9,0x07,0xcc,0xe6,0x19,0xdb,0x1b,0x83,0xf8,0xc8,0xc2,0xcc, + 0x09,0xd7,0x99,0xb9,0x30,0x98,0x7e,0xbf,0xb8,0xec,0x76,0x0a, + 0x6c,0x41,0x88,0x17,0x9f,0xed,0xac,0x39,0x06,0xfd,0x5f,0xbd, + 0x97,0x41,0x47,0x4f,0x62,0xf5,0x74,0x6f,0xd2,0x5e,0x54,0x7f, + 0xfe,0x17,0xb8,0x44,0x18,0x2c,0x56,0x07,0x63,0x35,0x68,0x4e, + 0x12,0x9d,0x68,0xc9,0x76,0xce,0x4f,0x44,0x02,0xeb,0xf1,0x41, + 0xc0,0xab,0x34,0xf4,0x48,0xc8,0x55,0xd8,0xa9,0xd4,0x84,0xe2, + 0x64,0x4b,0xac,0x4e,0xf0,0x88,0x7b,0xab,0xf4,0xdc,0xa1,0x11, + 0xe9,0xc2,0x86,0xff,0x40,0xd8,0x83,0xfe,0x86,0x04,0x0d,0xe2, + 0x52,0x27,0xef,0x14,0xad,0xdc,0x90,0x4d,0x8a,0x8a,0xcc,0xda, + 0x60,0x32,0x96,0x3e,0x60,0x84,0x10,0xcd,0x5d,0x91,0x85,0x6c, + 0x75,0x74,0xdc,0xb1,0xf3,0xed,0x92,0x9d,0x1e,0xf2,0xa7,0x65, + 0x72,0x00,0x7d,0x51,0x66,0x8f,0xc5,0x2b,0x26,0xf8,0x9f,0xb6, + 0x42,0xba,0x5a,0x01,0x9e,0xdd,0xe9,0x61,0x24,0x60,0xbf,0x13, + 0x09,0xbf,0xea,0x05,0x28,0xe3,0x7f,0x09,0x54,0x4f,0x6d,0x9b, + 0x40,0xc3,0x7f,0x5c,0x90,0x03,0xa2,0xeb,0xa8,0x66,0x36,0xac, + 0x2e,0x6d,0xac,0x32,0xc5,0xf5,0xc5,0xb5,0xf2,0xbd,0x80,0x4c, + 0x82,0x93,0xa3,0x6d,0x3a,0x91,0xda,0x38,0x47,0xf8,0xe6,0x5d, + 0xf4,0x48,0xfb,0xcb,0x02,0x03,0x01,0x00,0x01,0x02,0x82,0x01, + 0x00,0x03,0x9a,0xb6,0x00,0x5c,0x2a,0x49,0x52,0x6f,0x80,0x98, + 0xa6,0x10,0x0c,0xa0,0x92,0x1d,0x75,0xc6,0xc1,0x6f,0xca,0x45, + 0x5c,0x3c,0xc8,0x28,0xa3,0x61,0x12,0xaa,0xb3,0x37,0xc9,0xb9, + 0x91,0xd2,0x62,0xe6,0xad,0x31,0xa0,0x49,0x9f,0x81,0x44,0x5c, + 0x1b,0x25,0xae,0x24,0x01,0xad,0x63,0xae,0x47,0x0d,0xd5,0x02, + 0x52,0x1d,0xe0,0x02,0x4b,0x84,0x03,0x60,0x35,0x15,0x5f,0xeb, + 0x79,0x87,0xf5,0xec,0xf1,0x2e,0x9c,0x62,0x94,0xb5,0x66,0xc6, + 0xfc,0x61,0xfa,0x10,0xce,0xb4,0x32,0x59,0xd4,0x77,0x2a,0x5a, + 0x49,0xfc,0xaf,0x3b,0x97,0x85,0x4d,0x6f,0xdb,0x82,0xbb,0x1e, + 0xd3,0x0c,0x73,0xcc,0xeb,0x62,0x69,0x18,0xd4,0xce,0x2d,0xac, + 0x13,0xc9,0xa6,0x79,0x4e,0x6a,0x02,0x21,0x79,0x29,0x0c,0x6f, + 0x93,0x95,0x70,0x07,0x1a,0x99,0xc5,0x92,0x71,0x46,0xc6,0xb5, + 0x40,0xff,0xa2,0x4c,0x8b,0x5a,0x81,0x7d,0x8f,0xfd,0xbb,0xfb, + 0xa3,0xd5,0x9b,0xd5,0x63,0x70,0xb6,0xae,0xf0,0x36,0x0a,0x1c, + 0xac,0x7e,0x4c,0x32,0x8c,0x9f,0xf3,0x30,0x4f,0x15,0x3a,0x8c, + 0x8c,0x6b,0xe1,0xf0,0xb4,0xb5,0x75,0x94,0x53,0x9d,0x02,0x42, + 0xd8,0x32,0xea,0x1e,0x0f,0x18,0x07,0x91,0x6d,0x66,0xa4,0xaf, + 0xda,0xc2,0xe4,0x3d,0x7b,0x85,0x1e,0x0d,0x06,0x3b,0xee,0xe5, + 0x1e,0x9a,0xdd,0xa9,0xa8,0x1b,0x1a,0x1b,0x3c,0x9c,0x64,0x2b, + 0xd5,0x0e,0x47,0xfe,0x51,0x96,0x8e,0x07,0xdb,0x50,0xe3,0x33, + 0x1d,0x04,0x71,0x19,0xf7,0xb8,0x6a,0x61,0x38,0x1a,0xdd,0x35, + 0x3d,0xa8,0x36,0x79,0x01,0x02,0x81,0x81,0x00,0xfe,0x7b,0x24, + 0xea,0x19,0x33,0xb7,0x4b,0x75,0x29,0x4b,0xae,0x17,0x7a,0x39, + 0xf1,0x11,0xec,0x5a,0xba,0x91,0x0f,0x81,0x66,0x6a,0xb7,0xc4, + 0x2b,0x70,0x72,0x2a,0xe3,0x81,0x47,0x5e,0x4c,0xf0,0x34,0x3d, + 0x28,0x7d,0x77,0x88,0x0d,0x6a,0x01,0x35,0x81,0xa8,0x77,0x66, + 0xe0,0x25,0x1d,0xec,0xab,0x48,0x46,0xb8,0x04,0x98,0x3d,0x3a, + 0xbc,0x0d,0xee,0x55,0xe0,0xd0,0x1b,0x72,0x46,0xbd,0xe5,0x02, + 0x8c,0xa5,0xb7,0xcd,0x2f,0xe4,0xa1,0xc4,0xa9,0x94,0x8b,0x07, + 0x32,0x31,0xa2,0x8e,0x45,0x16,0x77,0xa0,0xb4,0xc5,0x56,0x49, + 0xce,0x6a,0x9b,0x88,0x41,0x22,0xa7,0xa2,0xe2,0xa8,0x2e,0xfb, + 0x1f,0x26,0x24,0x7d,0x92,0x23,0x8d,0x8d,0xb6,0x05,0x52,0x44, + 0x8f,0xba,0xe2,0x19,0x41,0x02,0x81,0x81,0x00,0xb9,0x5b,0x5e, + 0x99,0x08,0xf2,0x8c,0x15,0x11,0x8a,0x6f,0x42,0x35,0xd4,0x81, + 0x54,0x84,0xaa,0x92,0x06,0x6e,0xe7,0x67,0x44,0xb7,0xfd,0xe4, + 0x60,0x68,0xd4,0x30,0x64,0x6f,0xc9,0x58,0xdc,0xe3,0x1d,0xa3, + 0x9a,0x0a,0x39,0x11,0x62,0x24,0x84,0xdf,0xa6,0x23,0x7c,0x18, + 0x63,0xaa,0xaa,0x88,0xee,0x5f,0x53,0x7a,0x57,0x6a,0x03,0xb5, + 0xf5,0x76,0x3b,0x3f,0x64,0xaf,0x13,0xa5,0xa2,0xf9,0x09,0x6a, + 0x5d,0x1b,0x25,0x31,0x3f,0xc7,0xbc,0xb5,0x20,0x0e,0x9e,0x3f, + 0xc5,0x51,0x5f,0x23,0xdb,0xd0,0xf7,0xc5,0xc3,0xf0,0xe2,0x5a, + 0x0c,0xde,0x5e,0x99,0xd7,0xe7,0x46,0x77,0x39,0x62,0x04,0x56, + 0x01,0xea,0xfc,0xd8,0x36,0x78,0x71,0xcd,0x02,0xd7,0xc1,0x5e, + 0x89,0xa4,0x02,0x66,0x0b,0x02,0x81,0x81,0x00,0xaf,0xae,0xdc, + 0x21,0x31,0x1c,0xde,0xe1,0x9d,0x14,0xd1,0x46,0x72,0xb6,0xd2, + 0xe1,0x76,0x7a,0x31,0x78,0xb3,0x44,0x7d,0x14,0xf3,0x7f,0xc2, + 0x52,0x2a,0xe2,0xe6,0x71,0x01,0x82,0xff,0xbb,0x25,0xe9,0x2a, + 0x7f,0x95,0x7e,0xbb,0xd2,0x66,0xe8,0x46,0xc4,0x28,0x45,0xa6, + 0x23,0xff,0xfb,0xd4,0xb3,0xba,0xc5,0xf7,0xac,0x54,0x5d,0x90, + 0xfa,0xda,0xb3,0x3b,0x5e,0x64,0xcd,0x4d,0xeb,0x40,0x95,0xa5, + 0x58,0xeb,0xdf,0x24,0x2c,0x78,0x2e,0xa5,0xd2,0x5c,0xd6,0x4e, + 0x35,0x7c,0xc6,0xb8,0x69,0x41,0xc5,0x7c,0x90,0xcf,0xdb,0x6e, + 0x40,0xae,0xa0,0x89,0x44,0x4e,0x64,0x64,0xb3,0x0d,0x60,0xc1, + 0xc5,0x13,0x54,0x05,0xcc,0xa9,0xf6,0xc3,0x6a,0x71,0xea,0x05, + 0xa3,0x24,0x65,0x8b,0x01,0x02,0x81,0x80,0x5d,0x6e,0xa4,0x29, + 0x89,0xec,0x11,0x16,0x91,0xa7,0xf1,0x5b,0x33,0x9d,0x31,0xaf, + 0xf3,0xcb,0xb3,0x1d,0xd1,0x0b,0x8d,0xef,0x82,0xbb,0x55,0x42, + 0x0f,0xb5,0x5d,0xcb,0x52,0xd9,0xf0,0x94,0x2f,0x5b,0x82,0x5b, + 0x24,0x6a,0x0d,0xcc,0x25,0xd2,0x60,0x95,0xf3,0x6f,0x1b,0x30, + 0x2a,0x18,0x1a,0x3b,0xe6,0x0b,0x43,0x31,0x0a,0xfc,0x61,0xdd, + 0x20,0x42,0xcf,0x3a,0xa6,0x51,0xc5,0xfd,0x77,0x80,0xfa,0x7f, + 0x82,0x2e,0x66,0x3b,0xdb,0x27,0xd1,0x39,0x1e,0x85,0x40,0x69, + 0xeb,0x11,0x85,0x16,0xc9,0xa8,0x0b,0xa5,0x30,0x28,0x38,0xf2, + 0x21,0xa9,0x17,0xed,0x4f,0xe4,0x22,0x36,0xe7,0xa4,0x7d,0xe2, + 0x2b,0x9c,0x56,0x34,0x66,0xd4,0x1e,0x5e,0x1f,0x79,0x96,0x78, + 0xd5,0x16,0x6c,0x6f,0x02,0x81,0x80,0x1e,0x75,0x6f,0x1b,0x4d, + 0x0a,0x7c,0x56,0xc5,0xaf,0x4e,0xf7,0x6c,0xfd,0xaf,0xe2,0x7a, + 0x57,0x54,0x3b,0xa0,0xda,0xba,0x09,0xc9,0x1a,0x59,0x78,0xd6, + 0x26,0x31,0xac,0x52,0x56,0x5a,0x1a,0x88,0x9d,0x50,0x1e,0xbe, + 0xce,0xda,0xf1,0x70,0x0b,0x4c,0x9d,0x2f,0xa0,0x3f,0xcd,0x41, + 0x6c,0xb2,0x46,0xcf,0x65,0xca,0x16,0x75,0xab,0x98,0x2a,0xc8, + 0x16,0x1d,0x83,0x59,0x5d,0xb8,0xed,0x9a,0x74,0xfc,0x5d,0x89, + 0xda,0x7e,0x0f,0xc3,0x5a,0x1b,0xb5,0xab,0x70,0x29,0x4f,0x4d, + 0x29,0x40,0xe8,0xd9,0xf7,0x55,0x7e,0x05,0x91,0xf0,0x21,0x4c, + 0x4e,0x27,0x16,0x28,0x24,0xf2,0x23,0x38,0x77,0xa4,0x3a,0x49, + 0x29,0xd1,0x15,0x22,0xd4,0x7c,0xc1,0x06,0x25,0x34,0x44,0xd1, + 0x61,0xf8,0x4d, +}; + +static const unsigned char pk_rsa_n[] = { + 0xb8,0x41,0xd1,0x7c,0xa3,0x79,0x4e,0xd2,0x3c,0x83,0x06,0x85, + 0x87,0xec,0xf4,0x2a,0xbd,0x48,0x54,0x82,0xb4,0x75,0xa5,0x71, + 0x73,0x7f,0xaf,0x3b,0xd9,0x45,0x0b,0xf5,0x50,0x76,0x7c,0x83, + 0xc9,0x07,0xcc,0xe6,0x19,0xdb,0x1b,0x83,0xf8,0xc8,0xc2,0xcc, + 0x09,0xd7,0x99,0xb9,0x30,0x98,0x7e,0xbf,0xb8,0xec,0x76,0x0a, + 0x6c,0x41,0x88,0x17,0x9f,0xed,0xac,0x39,0x06,0xfd,0x5f,0xbd, + 0x97,0x41,0x47,0x4f,0x62,0xf5,0x74,0x6f,0xd2,0x5e,0x54,0x7f, + 0xfe,0x17,0xb8,0x44,0x18,0x2c,0x56,0x07,0x63,0x35,0x68,0x4e, + 0x12,0x9d,0x68,0xc9,0x76,0xce,0x4f,0x44,0x02,0xeb,0xf1,0x41, + 0xc0,0xab,0x34,0xf4,0x48,0xc8,0x55,0xd8,0xa9,0xd4,0x84,0xe2, + 0x64,0x4b,0xac,0x4e,0xf0,0x88,0x7b,0xab,0xf4,0xdc,0xa1,0x11, + 0xe9,0xc2,0x86,0xff,0x40,0xd8,0x83,0xfe,0x86,0x04,0x0d,0xe2, + 0x52,0x27,0xef,0x14,0xad,0xdc,0x90,0x4d,0x8a,0x8a,0xcc,0xda, + 0x60,0x32,0x96,0x3e,0x60,0x84,0x10,0xcd,0x5d,0x91,0x85,0x6c, + 0x75,0x74,0xdc,0xb1,0xf3,0xed,0x92,0x9d,0x1e,0xf2,0xa7,0x65, + 0x72,0x00,0x7d,0x51,0x66,0x8f,0xc5,0x2b,0x26,0xf8,0x9f,0xb6, + 0x42,0xba,0x5a,0x01,0x9e,0xdd,0xe9,0x61,0x24,0x60,0xbf,0x13, + 0x09,0xbf,0xea,0x05,0x28,0xe3,0x7f,0x09,0x54,0x4f,0x6d,0x9b, + 0x40,0xc3,0x7f,0x5c,0x90,0x03,0xa2,0xeb,0xa8,0x66,0x36,0xac, + 0x2e,0x6d,0xac,0x32,0xc5,0xf5,0xc5,0xb5,0xf2,0xbd,0x80,0x4c, + 0x82,0x93,0xa3,0x6d,0x3a,0x91,0xda,0x38,0x47,0xf8,0xe6,0x5d, + 0xf4,0x48,0xfb,0xcb, +}; + +static const unsigned char pk_rsa_e[] = { + 0x01,0x00,0x01, +}; + +static const unsigned char pk_ec_pk8[] = { + 0x30,0x81,0x87,0x02,0x01,0x00,0x30,0x13,0x06,0x07,0x2a,0x86, + 0x48,0xce,0x3d,0x02,0x01,0x06,0x08,0x2a,0x86,0x48,0xce,0x3d, + 0x03,0x01,0x07,0x04,0x6d,0x30,0x6b,0x02,0x01,0x01,0x04,0x20, + 0x6d,0x8d,0x45,0xbc,0xe7,0x8c,0x09,0x8d,0xcb,0x3c,0xf5,0x92, + 0x87,0xfc,0xae,0x28,0x1d,0x9c,0x5b,0x4b,0x9a,0xd1,0xd8,0x6b, + 0xc4,0x17,0xae,0xd3,0x1e,0xfb,0xf3,0xb8,0xa1,0x44,0x03,0x42, + 0x00,0x04,0xf8,0xaa,0xbc,0xff,0x4a,0xb5,0x9a,0x51,0x14,0x13, + 0xa9,0xc6,0x93,0x24,0x32,0x1f,0xd1,0x0c,0xe6,0xcd,0xe8,0xd0, + 0x91,0x2f,0xa8,0xab,0x8b,0xd4,0x7e,0xa6,0x43,0xf6,0x76,0x37, + 0x43,0x66,0xda,0xc9,0x60,0x6d,0x45,0x7d,0x90,0x43,0x12,0x71, + 0xc9,0x99,0xce,0x5a,0xf1,0x7e,0x7c,0xbc,0x77,0xaf,0x0a,0xdc, + 0x37,0x60,0x32,0x97,0xb1,0xc2, +}; + +static const unsigned char pk_ec_sec1[] = { + 0x30,0x77,0x02,0x01,0x01,0x04,0x20,0x6d,0x8d,0x45,0xbc,0xe7, + 0x8c,0x09,0x8d,0xcb,0x3c,0xf5,0x92,0x87,0xfc,0xae,0x28,0x1d, + 0x9c,0x5b,0x4b,0x9a,0xd1,0xd8,0x6b,0xc4,0x17,0xae,0xd3,0x1e, + 0xfb,0xf3,0xb8,0xa0,0x0a,0x06,0x08,0x2a,0x86,0x48,0xce,0x3d, + 0x03,0x01,0x07,0xa1,0x44,0x03,0x42,0x00,0x04,0xf8,0xaa,0xbc, + 0xff,0x4a,0xb5,0x9a,0x51,0x14,0x13,0xa9,0xc6,0x93,0x24,0x32, + 0x1f,0xd1,0x0c,0xe6,0xcd,0xe8,0xd0,0x91,0x2f,0xa8,0xab,0x8b, + 0xd4,0x7e,0xa6,0x43,0xf6,0x76,0x37,0x43,0x66,0xda,0xc9,0x60, + 0x6d,0x45,0x7d,0x90,0x43,0x12,0x71,0xc9,0x99,0xce,0x5a,0xf1, + 0x7e,0x7c,0xbc,0x77,0xaf,0x0a,0xdc,0x37,0x60,0x32,0x97,0xb1, + 0xc2, +}; + +static const unsigned char pk_ec_qx[] = { + 0xf8,0xaa,0xbc,0xff,0x4a,0xb5,0x9a,0x51,0x14,0x13,0xa9,0xc6, + 0x93,0x24,0x32,0x1f,0xd1,0x0c,0xe6,0xcd,0xe8,0xd0,0x91,0x2f, + 0xa8,0xab,0x8b,0xd4,0x7e,0xa6,0x43,0xf6, +}; + +static const unsigned char pk_ec_qy[] = { + 0x76,0x37,0x43,0x66,0xda,0xc9,0x60,0x6d,0x45,0x7d,0x90,0x43, + 0x12,0x71,0xc9,0x99,0xce,0x5a,0xf1,0x7e,0x7c,0xbc,0x77,0xaf, + 0x0a,0xdc,0x37,0x60,0x32,0x97,0xb1,0xc2, +}; + +static const unsigned char pk_salt[] = { + 0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a, + 0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a, + 0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a,0x5a, +}; + +static const unsigned char pk_hash[] = { + 0x64,0x65,0x66,0x67,0x68,0x69,0x6a,0x6b,0x6c,0x6d,0x6e,0x6f, + 0x70,0x71,0x72,0x73,0x74,0x75,0x76,0x77,0x78,0x79,0x7a,0x7b, + 0x7c,0x7d,0x7e,0x7f,0x80,0x81,0x82,0x83, +}; + diff --git a/runtime/test/test_crypto.c b/runtime/test/test_crypto.c index 06b3fea..f086413 100644 --- a/runtime/test/test_crypto.c +++ b/runtime/test/test_crypto.c @@ -10,6 +10,7 @@ #include "x509_vectors.h" #include "rsa_sign_vectors.h" #include "ecdsa_sign_vectors.h" +#include "pkey_vectors.h" static void hex(const uint8_t *d, size_t n, char *out) { static const char *h = "0123456789abcdef"; @@ -492,5 +493,36 @@ int main(void) { T_CHECK(memcmp(r, r2, 32) == 0 && memcmp(s, s2, 32) == 0); } + /* Private-key parsing (rv2 9 phase G3) โ€” all three DER formats parse, and + * the extracted key signs a hash our verify accepts. */ + { + int ka; const uint8_t *n, *d, *ecd; size_t nl, dl; + uint8_t sig[256], r[32], s[32]; + /* RSA PKCS#8 */ + T_CHECK(wo_pkey_parse(pk_rsa_pk8, sizeof pk_rsa_pk8, &ka, &n, &nl, &d, &dl, &ecd) == 0); + T_CHECK(ka == 1); + T_CHECK(wo_rsa_pss_sha256_sign(pk_rsa_n, sizeof pk_rsa_n, d, dl, pk_hash, + pk_salt, sizeof pk_salt, sig) == 0); + T_CHECK(wo_rsa_pss_sha256_verify(pk_rsa_n, sizeof pk_rsa_n, pk_rsa_e, + sizeof pk_rsa_e, sig, 256, pk_hash, 32) == 1); + /* RSA PKCS#1 (bare) yields the same modulus + a working d */ + const uint8_t *n1, *d1; size_t nl1, dl1; + T_CHECK(wo_pkey_parse(pk_rsa_pk1, sizeof pk_rsa_pk1, &ka, &n1, &nl1, &d1, &dl1, &ecd) == 0); + T_CHECK(ka == 1 && nl1 == sizeof pk_rsa_n && memcmp(n1, pk_rsa_n, nl1) == 0); + /* EC PKCS#8 */ + T_CHECK(wo_pkey_parse(pk_ec_pk8, sizeof pk_ec_pk8, &ka, &n, &nl, &d, &dl, &ecd) == 0); + T_CHECK(ka == 2); + T_CHECK(wo_ecdsa_p256_sha256_sign(ecd, pk_hash, r, s) == 0); + T_CHECK(wo_ecdsa_p256_sha256_verify(pk_ec_qx, pk_ec_qy, r, s, pk_hash) == 1); + /* EC SEC1 (bare) parses to the same working scalar */ + const uint8_t *ecd2; + T_CHECK(wo_pkey_parse(pk_ec_sec1, sizeof pk_ec_sec1, &ka, &n, &nl, &d, &dl, &ecd2) == 0); + T_CHECK(ka == 2); + T_CHECK(wo_ecdsa_p256_sha256_sign(ecd2, pk_hash, r, s) == 0); + T_CHECK(wo_ecdsa_p256_sha256_verify(pk_ec_qx, pk_ec_qy, r, s, pk_hash) == 1); + /* garbage rejected */ + T_CHECK(wo_pkey_parse(pk_hash, sizeof pk_hash, &ka, &n, &nl, &d, &dl, &ecd) == -1); + } + return t_report("test_crypto"); }