2 * Copyright 2017 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the OpenSSL license (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
10 /* Tests for X509 time functions */
15 #include <openssl/asn1.h>
16 #include <openssl/x509.h>
24 /* -1 if asn1_time <= cmp_time, 1 if asn1_time > cmp_time, 0 if error. */
30 /* 0 for check-only mode, 1 for set-string mode */
32 /* 0 for error, 1 if succeed */
35 * The following 2 fields are ignored if set_string field is set to '0'
36 * (in check only mode).
38 * But they can still be ignored explicitly in set-string mode by:
39 * setting -1 to expected_type and setting NULL to expected_string.
41 * It's useful in a case of set-string mode but the expected result
42 * is a 'parsing error'.
45 const char *expected_string;
49 * Actually, the "loose" mode has been tested in
50 * those time-compare-cases, so we may not test it again.
52 static TESTDATA_FORMAT x509_format_tests[] = {
55 /* good format, check only */
56 "20170217180105Z", 0, 1, -1, NULL,
59 /* not leap year, check only */
60 "20170229180105Z", 0, 0, -1, NULL,
63 /* leap year, check only */
64 "20160229180105Z", 0, 1, -1, NULL,
67 /* SS is missing, check only */
68 "201702171801Z", 0, 0, -1, NULL,
71 /* fractional seconds, check only */
72 "20170217180105.001Z", 0, 0, -1, NULL,
75 /* time zone, check only */
76 "20170217180105+0800", 0, 0, -1, NULL,
79 /* SS is missing, set string */
80 "201702171801Z", 1, 0, -1, NULL,
83 /* fractional seconds, set string */
84 "20170217180105.001Z", 1, 0, -1, NULL,
87 /* time zone, set string */
88 "20170217180105+0800", 1, 0, -1, NULL,
91 /* good format, check returned 'turned' string */
92 "20170217180154Z", 1, 1, V_ASN1_UTCTIME, "170217180154Z",
95 /* good format, check returned string */
96 "20510217180154Z", 1, 1, V_ASN1_GENERALIZEDTIME, "20510217180154Z",
99 /* good format but out of UTC range, check returned string */
100 "19230419180154Z", 1, 1, V_ASN1_GENERALIZEDTIME, "19230419180154Z",
104 /* SS is missing, check only */
105 "1702171801Z", 0, 0, -1, NULL,
108 /* not leap year, check only */
109 "050229180101Z", 0, 0, -1, NULL,
112 /* leap year, check only */
113 "040229180101Z", 0, 1, -1, NULL,
116 /* time zone, check only */
117 "170217180154+0800", 0, 0, -1, NULL,
120 /* SS is missing, set string */
121 "1702171801Z", 1, 0, -1, NULL,
124 /* time zone, set string */
125 "170217180154+0800", 1, 0, -1, NULL,
128 /* 2017, good format, check returned string */
129 "170217180154Z", 1, 1, V_ASN1_UTCTIME, "170217180154Z",
132 /* 1998, good format, check returned string */
133 "981223180154Z", 1, 1, V_ASN1_UTCTIME, "981223180154Z",
137 static TESTDATA x509_cmp_tests[] = {
139 "20170217180154Z", V_ASN1_GENERALIZEDTIME,
140 /* The same in seconds since epoch. */
144 "20170217180154Z", V_ASN1_GENERALIZEDTIME,
145 /* One second more. */
149 "20170217180154Z", V_ASN1_GENERALIZEDTIME,
150 /* One second less. */
153 /* Same as UTC time. */
155 "170217180154Z", V_ASN1_UTCTIME,
156 /* The same in seconds since epoch. */
160 "170217180154Z", V_ASN1_UTCTIME,
161 /* One second more. */
165 "170217180154Z", V_ASN1_UTCTIME,
166 /* One second less. */
169 /* UTCTime from the 20th century. */
171 "990217180154Z", V_ASN1_UTCTIME,
172 /* The same in seconds since epoch. */
176 "990217180154Z", V_ASN1_UTCTIME,
177 /* One second more. */
181 "990217180154Z", V_ASN1_UTCTIME,
182 /* One second less. */
185 /* Various invalid formats. */
188 "20170217180154", V_ASN1_GENERALIZEDTIME, 0, 0,
191 /* No trailing Z, UTCTime. */
192 "170217180154", V_ASN1_UTCTIME, 0, 0,
196 "201702171801Z", V_ASN1_GENERALIZEDTIME, 0, 0,
199 /* No seconds, UTCTime. */
200 "1702171801Z", V_ASN1_UTCTIME, 0, 0,
203 /* Fractional seconds. */
204 "20170217180154.001Z", V_ASN1_GENERALIZEDTIME, 0, 0,
207 /* Fractional seconds, UTCTime. */
208 "170217180154.001Z", V_ASN1_UTCTIME, 0, 0,
211 /* Timezone offset. */
212 "20170217180154+0100", V_ASN1_GENERALIZEDTIME, 0, 0,
215 /* Timezone offset, UTCTime. */
216 "170217180154+0100", V_ASN1_UTCTIME, 0, 0,
220 "2017021718015400Z", V_ASN1_GENERALIZEDTIME, 0, 0,
223 /* Extra digits, UTCTime. */
224 "17021718015400Z", V_ASN1_UTCTIME, 0, 0,
228 "2017021718015aZ", V_ASN1_GENERALIZEDTIME, 0, 0,
231 /* Non-digits, UTCTime. */
232 "17021718015aZ", V_ASN1_UTCTIME, 0, 0,
235 /* Trailing garbage. */
236 "20170217180154Zlongtrailinggarbage", V_ASN1_GENERALIZEDTIME, 0, 0,
239 /* Trailing garbage, UTCTime. */
240 "170217180154Zlongtrailinggarbage", V_ASN1_UTCTIME, 0, 0,
244 "20170217180154Z", V_ASN1_UTCTIME, 0, 0,
248 "170217180154Z", V_ASN1_GENERALIZEDTIME, 0, 0,
252 "20170217180154Z", V_ASN1_OCTET_STRING, 0, 0,
256 static int test_x509_cmp_time(int idx)
261 memset(&t, 0, sizeof(t));
262 t.type = x509_cmp_tests[idx].type;
263 t.data = (unsigned char*)(x509_cmp_tests[idx].data);
264 t.length = strlen(x509_cmp_tests[idx].data);
267 result = X509_cmp_time(&t, &x509_cmp_tests[idx].cmp_time);
268 if (!TEST_int_eq(result, x509_cmp_tests[idx].expected)) {
269 TEST_info("test_x509_cmp_time(%d) failed: expected %d, got %d\n",
270 idx, x509_cmp_tests[idx].expected, result);
276 static int test_x509_cmp_time_current()
278 time_t now = time(NULL);
279 /* Pick a day earlier and later, relative to any system clock. */
280 ASN1_TIME *asn1_before = NULL, *asn1_after = NULL;
281 int cmp_result, failed = 0;
283 asn1_before = ASN1_TIME_adj(NULL, now, -1, 0);
284 asn1_after = ASN1_TIME_adj(NULL, now, 1, 0);
286 cmp_result = X509_cmp_time(asn1_before, NULL);
287 if (!TEST_int_eq(cmp_result, -1))
290 cmp_result = X509_cmp_time(asn1_after, NULL);
291 if (!TEST_int_eq(cmp_result, 1))
294 ASN1_TIME_free(asn1_before);
295 ASN1_TIME_free(asn1_after);
300 static int test_x509_time(int idx)
305 if (x509_format_tests[idx].set_string) {
306 /* set-string mode */
309 TEST_info("test_x509_time(%d) failed: internal error\n", idx);
314 result = ASN1_TIME_set_string_X509(t, x509_format_tests[idx].data);
315 /* time string parsing result is always checked against what's expected */
316 if (!TEST_int_eq(result, x509_format_tests[idx].expected)) {
317 TEST_info("test_x509_time(%d) failed: expected %d, got %d\n",
318 idx, x509_format_tests[idx].expected, result);
322 /* if t is not NULL but expected_type is ignored(-1), it is an 'OK' case */
323 if (t != NULL && x509_format_tests[idx].expected_type != -1) {
324 if (!TEST_int_eq(t->type, x509_format_tests[idx].expected_type)) {
325 TEST_info("test_x509_time(%d) failed: expected_type %d, got %d\n",
326 idx, x509_format_tests[idx].expected_type, t->type);
331 /* if t is not NULL but expected_string is NULL, it is an 'OK' case too */
332 if (t != NULL && x509_format_tests[idx].expected_string) {
333 if (!TEST_str_eq((const char *)t->data,
334 x509_format_tests[idx].expected_string)) {
335 TEST_info("test_x509_time(%d) failed: expected_string %s, got %s\n",
336 idx, x509_format_tests[idx].expected_string, t->data);
348 void register_tests()
350 ADD_TEST(test_x509_cmp_time_current);
351 ADD_ALL_TESTS(test_x509_cmp_time, OSSL_NELEM(x509_cmp_tests));
352 ADD_ALL_TESTS(test_x509_time, OSSL_NELEM(x509_format_tests));