2021-10-07 15:48:52 +02:00
|
|
|
// SPDX-FileCopyrightText: 2021 Paul Schaub <vanitasvitae@fsfe.org>
|
|
|
|
//
|
|
|
|
// SPDX-License-Identifier: Apache-2.0
|
|
|
|
|
2021-01-22 20:03:20 +01:00
|
|
|
package org.pgpainless.key.protection;
|
|
|
|
|
|
|
|
import static org.junit.jupiter.api.Assertions.assertEquals;
|
|
|
|
import static org.junit.jupiter.api.Assertions.assertNotNull;
|
|
|
|
import static org.junit.jupiter.api.Assertions.assertNull;
|
|
|
|
import static org.junit.jupiter.api.Assertions.assertThrows;
|
|
|
|
|
|
|
|
import java.io.IOException;
|
|
|
|
import java.security.InvalidAlgorithmParameterException;
|
|
|
|
import java.security.NoSuchAlgorithmException;
|
|
|
|
import java.util.Iterator;
|
|
|
|
import java.util.Map;
|
|
|
|
import java.util.Random;
|
|
|
|
import java.util.concurrent.ConcurrentHashMap;
|
|
|
|
import javax.annotation.Nullable;
|
|
|
|
|
|
|
|
import org.bouncycastle.openpgp.PGPException;
|
|
|
|
import org.bouncycastle.openpgp.PGPSecretKey;
|
|
|
|
import org.bouncycastle.openpgp.PGPSecretKeyRing;
|
|
|
|
import org.bouncycastle.openpgp.operator.PBESecretKeyDecryptor;
|
|
|
|
import org.junit.jupiter.api.Test;
|
2021-02-25 23:27:08 +01:00
|
|
|
import org.junit.jupiter.params.ParameterizedTest;
|
2021-12-14 15:47:53 +01:00
|
|
|
import org.junit.jupiter.params.provider.ArgumentsSource;
|
2021-01-22 20:03:20 +01:00
|
|
|
import org.pgpainless.PGPainless;
|
2021-02-25 23:27:08 +01:00
|
|
|
import org.pgpainless.implementation.ImplementationFactory;
|
2021-01-22 20:03:20 +01:00
|
|
|
import org.pgpainless.key.TestKeys;
|
|
|
|
import org.pgpainless.key.protection.passphrase_provider.SecretKeyPassphraseProvider;
|
|
|
|
import org.pgpainless.util.Passphrase;
|
2021-12-14 15:47:53 +01:00
|
|
|
import org.pgpainless.util.TestImplementationFactoryProvider;
|
2021-01-22 20:03:20 +01:00
|
|
|
|
|
|
|
public class SecretKeyRingProtectorTest {
|
|
|
|
|
2021-02-25 23:27:08 +01:00
|
|
|
@ParameterizedTest
|
2021-12-14 15:47:53 +01:00
|
|
|
@ArgumentsSource(TestImplementationFactoryProvider.class)
|
2021-11-20 20:19:22 +01:00
|
|
|
public void testUnlockAllKeysWithSamePassword(ImplementationFactory implementationFactory)
|
|
|
|
throws IOException, PGPException, InvalidAlgorithmParameterException, NoSuchAlgorithmException {
|
2021-02-25 23:27:08 +01:00
|
|
|
ImplementationFactory.setFactoryImplementation(implementationFactory);
|
|
|
|
|
2021-01-22 20:03:20 +01:00
|
|
|
PGPSecretKeyRing secretKeys = TestKeys.getCryptieSecretKeyRing();
|
2021-11-20 20:19:22 +01:00
|
|
|
SecretKeyRingProtector protector =
|
|
|
|
SecretKeyRingProtector.unlockEachKeyWith(TestKeys.CRYPTIE_PASSPHRASE, secretKeys);
|
2021-01-22 20:03:20 +01:00
|
|
|
for (PGPSecretKey secretKey : secretKeys) {
|
|
|
|
PBESecretKeyDecryptor decryptor = protector.getDecryptor(secretKey.getKeyID());
|
|
|
|
assertNotNull(decryptor);
|
|
|
|
secretKey.extractPrivateKey(decryptor);
|
|
|
|
}
|
|
|
|
PGPSecretKeyRing unrelatedKeys = PGPainless.generateKeyRing().simpleEcKeyRing("unrelated",
|
|
|
|
"SecurePassword");
|
|
|
|
for (PGPSecretKey unrelatedKey : unrelatedKeys) {
|
|
|
|
PBESecretKeyDecryptor decryptor = protector.getDecryptor(unrelatedKey.getKeyID());
|
|
|
|
assertNull(decryptor);
|
2021-11-20 20:19:22 +01:00
|
|
|
assertThrows(PGPException.class,
|
|
|
|
() -> unrelatedKey.extractPrivateKey(protector.getDecryptor(unrelatedKey.getKeyID())));
|
2021-01-22 20:03:20 +01:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
@Test
|
|
|
|
public void testUnprotectedKeys() throws PGPException {
|
|
|
|
Random random = new Random();
|
|
|
|
SecretKeyRingProtector protector = SecretKeyRingProtector.unprotectedKeys();
|
|
|
|
for (int i = 0; i < 10; i++) {
|
|
|
|
Long keyId = random.nextLong();
|
|
|
|
assertNull(protector.getEncryptor(keyId));
|
|
|
|
assertNull(protector.getDecryptor(keyId));
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-02-25 23:27:08 +01:00
|
|
|
@ParameterizedTest
|
2021-12-14 15:47:53 +01:00
|
|
|
@ArgumentsSource(TestImplementationFactoryProvider.class)
|
2021-11-20 20:19:22 +01:00
|
|
|
public void testUnlockSingleKeyWithPassphrase(ImplementationFactory implementationFactory)
|
|
|
|
throws IOException, PGPException {
|
2021-02-25 23:27:08 +01:00
|
|
|
ImplementationFactory.setFactoryImplementation(implementationFactory);
|
|
|
|
|
2021-01-22 20:03:20 +01:00
|
|
|
PGPSecretKeyRing secretKeys = TestKeys.getCryptieSecretKeyRing();
|
|
|
|
Iterator<PGPSecretKey> iterator = secretKeys.iterator();
|
|
|
|
PGPSecretKey secretKey = iterator.next();
|
|
|
|
PGPSecretKey subKey = iterator.next();
|
|
|
|
|
2021-11-20 20:19:22 +01:00
|
|
|
SecretKeyRingProtector protector =
|
|
|
|
SecretKeyRingProtector.unlockSingleKeyWith(TestKeys.CRYPTIE_PASSPHRASE, secretKey);
|
2021-01-22 20:03:20 +01:00
|
|
|
assertNotNull(protector.getDecryptor(secretKey.getKeyID()));
|
|
|
|
assertNotNull(protector.getEncryptor(secretKey.getKeyID()));
|
|
|
|
assertNull(protector.getEncryptor(subKey.getKeyID()));
|
|
|
|
assertNull(protector.getDecryptor(subKey.getKeyID()));
|
|
|
|
}
|
|
|
|
|
|
|
|
@Test
|
|
|
|
public void testFromPassphraseMap() {
|
|
|
|
Map<Long, Passphrase> passphraseMap = new ConcurrentHashMap<>();
|
|
|
|
passphraseMap.put(1L, Passphrase.emptyPassphrase());
|
2021-11-20 20:19:22 +01:00
|
|
|
CachingSecretKeyRingProtector protector =
|
|
|
|
(CachingSecretKeyRingProtector) SecretKeyRingProtector.fromPassphraseMap(passphraseMap);
|
2021-01-22 20:03:20 +01:00
|
|
|
|
|
|
|
assertNotNull(protector.getPassphraseFor(1L));
|
|
|
|
assertNull(protector.getPassphraseFor(5L));
|
|
|
|
|
|
|
|
protector.addPassphrase(5L, Passphrase.fromPassword("pa55w0rd"));
|
|
|
|
protector.forgetPassphrase(1L);
|
|
|
|
|
|
|
|
assertNull(protector.getPassphraseFor(1L));
|
|
|
|
assertNotNull(protector.getPassphraseFor(5L));
|
|
|
|
}
|
|
|
|
|
|
|
|
@Test
|
|
|
|
public void testMissingPassphraseCallback() {
|
|
|
|
Map<Long, Passphrase> passphraseMap = new ConcurrentHashMap<>();
|
|
|
|
passphraseMap.put(1L, Passphrase.emptyPassphrase());
|
2021-05-14 18:55:26 +02:00
|
|
|
CachingSecretKeyRingProtector protector = new CachingSecretKeyRingProtector(passphraseMap,
|
2021-01-22 20:03:20 +01:00
|
|
|
KeyRingProtectionSettings.secureDefaultSettings(), new SecretKeyPassphraseProvider() {
|
|
|
|
@Nullable
|
|
|
|
@Override
|
|
|
|
public Passphrase getPassphraseFor(Long keyId) {
|
|
|
|
return Passphrase.fromPassword("missingP455w0rd");
|
|
|
|
}
|
2021-09-15 16:33:03 +02:00
|
|
|
|
|
|
|
@Override
|
|
|
|
public boolean hasPassphrase(Long keyId) {
|
|
|
|
return true;
|
|
|
|
}
|
2021-01-22 20:03:20 +01:00
|
|
|
});
|
|
|
|
|
|
|
|
assertEquals(Passphrase.emptyPassphrase(), protector.getPassphraseFor(1L));
|
|
|
|
assertEquals(Passphrase.fromPassword("missingP455w0rd"), protector.getPassphraseFor(3L));
|
|
|
|
}
|
|
|
|
}
|