CryptoUtilTest.kt (5349B)
1 /* 2 * This file is part of LibEuFin. 3 * Copyright (C) 2024 Taler Systems S.A. 4 5 * LibEuFin is free software; you can redistribute it and/or modify 6 * it under the terms of the GNU Affero General Public License as 7 * published by the Free Software Foundation; either version 3, or 8 * (at your option) any later version. 9 10 * LibEuFin is distributed in the hope that it will be useful, but 11 * WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY 12 * or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Affero General 13 * Public License for more details. 14 15 * You should have received a copy of the GNU Affero General Public 16 * License along with LibEuFin; see the file COPYING. If not, see 17 * <http://www.gnu.org/licenses/> 18 */ 19 20 import org.junit.Test 21 import tech.libeufin.common.crypto.CryptoUtil 22 import tech.libeufin.common.crypto.PasswordHashCheck 23 import tech.libeufin.common.crypto.PwCrypto 24 import tech.libeufin.common.decodeUpHex 25 import tech.libeufin.common.encodeBase64 26 import tech.libeufin.common.encodeHex 27 import tech.libeufin.common.encodeUpHex 28 import kotlin.test.assertEquals 29 import kotlin.test.assertTrue 30 31 class CryptoUtilTest { 32 33 @Test 34 fun loadFromModulusAndExponent() { 35 val public = CryptoUtil.genRSAPublic(1024) 36 val pub2 = CryptoUtil.RSAPublicFromComponents( 37 public.modulus.toByteArray(), 38 public.publicExponent.toByteArray() 39 ) 40 assertEquals(public, pub2) 41 } 42 43 @Test 44 fun testCryptoUtilBasics() { 45 val (private, public) = CryptoUtil.genRSAPair(1024) 46 assertEquals(private, CryptoUtil.loadRSAPrivate(private.encoded)) 47 assertEquals(public, CryptoUtil.loadRSAPublic(public.encoded)) 48 } 49 50 @Test 51 fun testEbicsE002() { 52 val data = "Hello, World!".toByteArray() 53 val (private, public) = CryptoUtil.genRSAPair(1024) 54 val (txKey, encryptedKey) = CryptoUtil.genEbicsE002Key(public) 55 val enc = CryptoUtil.encryptEbicsE002(txKey, data.inputStream()) 56 val txKey2 = CryptoUtil.decryptEbicsE002Key(private, encryptedKey) 57 val dec = CryptoUtil.decryptEbicsE002(txKey2, enc).readBytes() 58 assertTrue(data.contentEquals(dec)) 59 } 60 61 @Test 62 fun testEbicsA006() { 63 val (private, public) = CryptoUtil.genRSAPair(1024) 64 val data = "Hello, World".toByteArray(Charsets.UTF_8) 65 val sig = CryptoUtil.signEbicsA006(data, private) 66 assertTrue(CryptoUtil.verifyEbicsA006(sig, data, public)) 67 } 68 69 @Test 70 fun testEbicsPublicKeyHashing() { 71 val exponentStr = "01 00 01".replace(" ", "") 72 val moduloStrtrimIndent().replace(" ", "").replace("\n", "") 90 val expectedHashStr = """ 91 72 71 D5 83 B4 24 A6 DA 0B 7B 22 24 3B E2 B8 8C 92 6E A6 0F 9F 76 11 FD 18 BE 2C E8 8B 21 03 A9 41 93 """.trimIndent() 94 95 val expectedHash = expectedHashStr.replace(" ", "").replace("\n", "") 96 97 val pub = CryptoUtil.RSAPublicFromComponents(moduloStr.decodeUpHex(), exponentStr.decodeUpHex()) 98 99 println("echoed pub exp: ${pub.publicExponent.encodeHex()}") 100 println("echoed pub mod: ${pub.modulus.encodeHex()}") 101 102 val pubHash = CryptoUtil.getEbicsPublicKeyHash(pub) 103 104 println("our pubHash: ${pubHash.encodeUpHex()}") 105 println("expected pubHash: ${expectedHash}") 106 107 assertEquals(expectedHash, pubHash.encodeUpHex()) 108 } 109 110 @Test 111 fun passwordHashing() { 112 val password = "myinsecurepw" 113 val pwCrypto = PwCrypto.Bcrypt(cost = 4) 114 // Check roundtrip 115 val hash = pwCrypto.hashpw(password) 116 assertEquals(pwCrypto.checkpw(password, hash), PasswordHashCheck(true, false)) 117 assertEquals(pwCrypto.checkpw("other", hash), PasswordHashCheck(false, false)) 118 119 // Check outdated algorithm 120 val pwh = CryptoUtil.hashStringSHA256(password).encodeBase64() 121 val outdatedHash = "sha256\$$pwh" 122 assertEquals(pwCrypto.checkpw(password, outdatedHash), PasswordHashCheck(true, true)) 123 assertEquals(pwCrypto.checkpw("other", outdatedHash), PasswordHashCheck(false, true)) 124 125 // Check outdated options 126 val betterCrypto = pwCrypto.copy(cost = 5) 127 assertEquals(betterCrypto.checkpw(password, hash), PasswordHashCheck(true, true)) 128 assertEquals(betterCrypto.checkpw("other", hash), PasswordHashCheck(false, true)) 129 } 130 }