1 /* -*- Mode: C; indent-tabs-mode: t; c-basic-offset: 8; tab-width: 8 -*- */
2 /* test-dh.c: Test egg-dh.c
3 
4    Copyright (C) 2009 Stefan Walter
5 
6    The Gnome Keyring Library is free software; you can redistribute it and/or
7    modify it under the terms of the GNU Library General Public License as
8    published by the Free Software Foundation; either version 2 of the
9    License, or (at your option) any later version.
10 
11    The Gnome Keyring Library is distributed in the hope that it will be useful,
12    but WITHOUT ANY WARRANTY; without even the implied warranty of
13    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
14    Library General Public License for more details.
15 
16    You should have received a copy of the GNU Library General Public
17    License along with the Gnome Library; see the file COPYING.LIB.  If not,
18    write to the Free Software Foundation, Inc., 59 Temple Place - Suite 330,
19    Boston, MA 02111-1307, USA.
20 
21    Author: Stef Walter <stef@memberwebs.com>
22 */
23 
24 #include "config.h"
25 
26 #include "egg-dh.h"
27 #include "egg-libgcrypt.h"
28 #include "egg-secure-memory.h"
29 #include "egg-testing.h"
30 
SYSTEM_HOSTNAME(AGENT_REQUEST * request,AGENT_RESULT * result)31 #include <glib.h>
32 #include <gcrypt.h>
33 
34 #include <stdlib.h>
35 #include <stdio.h>
36 #include <string.h>
37 
38 EGG_SECURE_DEFINE_GLIB_GLOBALS ();
39 
40 static void
41 test_dh_perform (void)
42 {
43 	gcry_mpi_t p, g;
44 	gcry_mpi_t x1, X1;
45 	gcry_mpi_t x2, X2;
46 	gpointer k1, k2;
47 	gboolean ret;
48 	gsize n1, n2;
49 
50 	if (g_test_quick ())
51 		return;
52 
53 	/* Load up the parameters */
54 	if (!egg_dh_default_params ("ietf-ike-grp-modp-768", &p, &g))
55 		g_assert_not_reached ();
56 
57 	/* Generate secrets */
58 	ret = egg_dh_gen_pair (p, g, 0, &X1, &x1);
59 	g_assert (ret);
60 	ret = egg_dh_gen_pair (p, g, 0, &X2, &x2);
61 	g_assert (ret);
62 
63 	/* Calculate keys */
64 	k1 = egg_dh_gen_secret (X2, x1, p, &n1);
65 	g_assert (k1);
66 	k2 = egg_dh_gen_secret (X1, x2, p, &n2);
67 	g_assert (k2);
68 
69 	/* Keys must be the same */
70 	egg_assert_cmpsize (n1, ==, n2);
71 	g_assert (memcmp (k1, k2, n1) == 0);
72 
73 	gcry_mpi_release (p);
74 	gcry_mpi_release (g);
75 	gcry_mpi_release (x1);
76 	gcry_mpi_release (X1);
77 	egg_secure_free (k1);
78 	gcry_mpi_release (x2);
79 	gcry_mpi_release (X2);
80 	egg_secure_free (k2);
81 }
82 
83 static void
84 test_dh_short_pair (void)
85 {
86 	gcry_mpi_t p, g;
87 	gcry_mpi_t x1, X1;
88 	gboolean ret;
89 
90 	if (g_test_quick ())
91 		return;
92 
93 	/* Load up the parameters */
94 	ret = egg_dh_default_params ("ietf-ike-grp-modp-1024", &p, &g);
95 	g_assert (ret);
96 	g_assert_cmpuint (gcry_mpi_get_nbits (p), ==, 1024);
97 
98 	/* Generate secrets */
99 	ret = egg_dh_gen_pair (p, g, 512, &X1, &x1);
100 	g_assert (ret);
101 	g_assert_cmpuint (gcry_mpi_get_nbits (x1), <=, 512);
102 
103 	gcry_mpi_release (p);
104 	gcry_mpi_release (g);
105 	gcry_mpi_release (x1);
106 	gcry_mpi_release (X1);
107 }
108 
109 static void
110 check_dh_default (const gchar *name, guint bits)
111 {
112 	gboolean ret;
113 	gcry_mpi_t p, g, check;
114 	gconstpointer prime, base;
115 	gsize n_prime, n_base;
116 	gcry_error_t gcry;
117 
118 	ret = egg_dh_default_params (name, &p, &g);
119 	g_assert (ret);
120 	g_assert_cmpint (gcry_mpi_get_nbits (p), ==, bits);
121 	g_assert_cmpint (gcry_mpi_get_nbits (g), <, gcry_mpi_get_nbits (p));
122 
123 	ret = egg_dh_default_params_raw (name, &prime, &n_prime, &base, &n_base);
124 	g_assert (ret);
125 	g_assert (prime != NULL);
126 	egg_assert_cmpsize (n_prime, >, 0);
127 	g_assert (base != NULL);
128 	egg_assert_cmpsize (n_base, >, 0);
129 
130 	gcry = gcry_mpi_scan (&check, GCRYMPI_FMT_USG, prime, n_prime, NULL);
131 	g_assert (gcry == 0);
132 	g_assert (gcry_mpi_cmp (check, p) == 0);
133 	gcry_mpi_release (check);
134 
135 	gcry = gcry_mpi_scan (&check, GCRYMPI_FMT_USG, base, n_base, NULL);
136 	g_assert (gcry == 0);
137 	g_assert (gcry_mpi_cmp (check, g) == 0);
138 	gcry_mpi_release (check);
139 
140 	gcry_mpi_release (p);
141 	gcry_mpi_release (g);
142 }
143 
144 static void
145 test_dh_default_768 (void)
146 {
147 	check_dh_default ("ietf-ike-grp-modp-768", 768);
148 }
149 
150 static void
151 test_dh_default_1024 (void)
152 {
153 	check_dh_default ("ietf-ike-grp-modp-1024", 1024);
154 }
155 
156 static void
157 test_dh_default_1536 (void)
158 {
159 	check_dh_default ("ietf-ike-grp-modp-1536", 1536);
160 }
161 
162 static void
163 test_dh_default_2048 (void)
164 {
165 	check_dh_default ("ietf-ike-grp-modp-2048", 2048);
166 }
167 
168 static void
169 test_dh_default_3072 (void)
170 {
171 	check_dh_default ("ietf-ike-grp-modp-3072", 3072);
172 }
173 
174 static void
175 test_dh_default_4096 (void)
176 {
177 	check_dh_default ("ietf-ike-grp-modp-4096", 4096);
178 }
179 
180 static void
181 test_dh_default_8192 (void)
182 {
183 	check_dh_default ("ietf-ike-grp-modp-8192", 8192);
184 }
185 
186 static void
187 test_dh_default_bad (void)
188 {
189 	gboolean ret;
190 	gcry_mpi_t p, g;
191 
192 	ret = egg_dh_default_params ("bad-name", &p, &g);
193 	g_assert (!ret);
194 }
195 
196 int
197 main (int argc, char **argv)
198 {
199 	g_test_init (&argc, &argv, NULL);
200 
201 	egg_libgcrypt_initialize ();
202 
203 	g_test_add_func ("/dh/perform", test_dh_perform);
204 	g_test_add_func ("/dh/short-pair", test_dh_short_pair);
205 	g_test_add_func ("/dh/default-768", test_dh_default_768);
206 	g_test_add_func ("/dh/default-1024", test_dh_default_1024);
207 	g_test_add_func ("/dh/default-1536", test_dh_default_1536);
208 	g_test_add_func ("/dh/default-2048", test_dh_default_2048);
209 	g_test_add_func ("/dh/default-3072", test_dh_default_3072);
210 	g_test_add_func ("/dh/default-4096", test_dh_default_4096);
211 	g_test_add_func ("/dh/default-8192", test_dh_default_8192);
212 	g_test_add_func ("/dh/default-bad", test_dh_default_bad);
213 
214 	return g_test_run ();
215 }
216