summaryrefslogtreecommitdiffstats
path: root/security/nss/cmd/libpkix/pkix_pl/pki/test_nameconstraints.c
blob: 636ba3ead3cacbdf2fbbff02953f85bb98ae2709 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
/* This Source Code Form is subject to the terms of the Mozilla Public
 * License, v. 2.0. If a copy of the MPL was not distributed with this
 * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
/*
 * test_nameconstraints.c
 *
 * Test CERT Name Constraints Type
 *
 */

#include "testutil.h"
#include "testutil_nss.h"

static void *plContext = NULL;

static char *
catDirName(char *platform, char *dir, void *plContext)
{
    char *pathName = NULL;
    PKIX_UInt32 dirLen;
    PKIX_UInt32 platformLen;

    PKIX_TEST_STD_VARS();

    dirLen = PL_strlen(dir);
    platformLen = PL_strlen(platform);

    PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_Malloc(platformLen +
                                                 dirLen +
                                                 2,
                                             (void **)&pathName, plContext));

    PL_strcpy(pathName, platform);
    PL_strcat(pathName, "/");
    PL_strcat(pathName, dir);

cleanup:

    PKIX_TEST_RETURN();

    return (pathName);
}

static void
testNameConstraints(char *dataDir)
{
    char *goodPname = "nameConstraintsDN5CACert.crt";
    PKIX_PL_Cert *goodCert = NULL;
    PKIX_PL_CertNameConstraints *goodNC = NULL;
    char *expectedAscii =
        "[\n"
        "\t\tPermitted Name:  (OU=permittedSubtree1,"
        "O=Test Certificates,C=US)\n"
        "\t\tExcluded Name:   (OU=excludedSubtree1,"
        "OU=permittedSubtree1,O=Test Certificates,C=US)\n"
        "\t]\n";

    PKIX_TEST_STD_VARS();

    subTest("PKIX_PL_CertNameConstraints");

    goodCert = createCert(dataDir, goodPname, plContext);

    subTest("PKIX_PL_Cert_GetNameConstraints");

    PKIX_TEST_EXPECT_NO_ERROR(PKIX_PL_Cert_GetNameConstraints(goodCert, &goodNC, plContext));

    testToStringHelper((PKIX_PL_Object *)goodNC, expectedAscii, plContext);

cleanup:

    PKIX_TEST_DECREF_AC(goodNC);
    PKIX_TEST_DECREF_AC(goodCert);

    PKIX_TEST_RETURN();
}

static void
printUsage(void)
{
    (void)printf("\nUSAGE:\ttest_nameconstraints <test-purpose>"
                 " <data-dir> <platform-prefix>\n\n");
}

/* Functional tests for CRL public functions */

int
test_nameconstraints(int argc, char *argv[])
{
    PKIX_UInt32 actualMinorVersion;
    PKIX_UInt32 j = 0;
    char *platformDir = NULL;
    char *dataDir = NULL;
    char *combinedDir = NULL;

    /* Note XXX serialnumber and reasoncode need debug */

    PKIX_TEST_STD_VARS();

    startTests("NameConstraints");

    PKIX_TEST_EXPECT_NO_ERROR(
        PKIX_PL_NssContext_Create(0, PKIX_FALSE, NULL, &plContext));

    if (argc < 3 + j) {
        printUsage();
        return (0);
    }

    dataDir = argv[2 + j];
    platformDir = argv[3 + j];
    combinedDir = catDirName(platformDir, dataDir, plContext);

    testNameConstraints(combinedDir);

cleanup:

    pkixTestErrorResult = PKIX_PL_Free(combinedDir, plContext);

    PKIX_Shutdown(plContext);

    PKIX_TEST_RETURN();

    endTests("NameConstraints");

    return (0);
}