mbedtls/tests/data_files
Andrzej Kurek 3fd9297658 Guard from undefined behaviour in case of an INT_MAX max_pathlen
When parsing a certificate with the basic constraints extension
the max_pathlen that was read from it was incremented regardless
of its value. However, if the max_pathlen is equal to INT_MAX (which
is highly unlikely), an undefined behaviour would occur.
This commit adds a check to ensure that such value is not accepted
as valid. Relevant tests for INT_MAX and INT_MAX-1 are also introduced.
Certificates added in this commit were generated using the
test_suite_x509write, function test_x509_crt_check. Input data taken
from the "Certificate write check Server1 SHA1" test case, so the generated
files are like the "server1.crt", but with the "is_ca" field set to 1 and
max_pathlen as described by the file name.

Signed-off-by: Andrzej Kurek <andrzej.kurek@arm.com>
Signed-off-by: Piotr Nowicki <piotr.nowicki@arm.com>
2020-04-17 11:30:21 +02:00
..
dir-maxpath
dir1
dir2
dir3
dir4
.gitignore
bitstring-in-dn.pem Add test certificate for bitstring in DN 2015-03-27 13:11:33 +01:00
cert_example_multi.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
cert_example_multi_nocn.crt
cert_example_wildcard.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
cert_md2.crt Add MD[245] test CRTs to tree 2019-06-03 16:22:01 +01:00
cert_md4.crt Add MD[245] test CRTs to tree 2019-06-03 16:22:01 +01:00
cert_md5.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
cert_sha1.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
cert_sha224.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
cert_sha256.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
cert_sha384.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
cert_sha512.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
cert_v1_with_ext.crt
cli-rsa-sha1.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
cli-rsa-sha256.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
cli-rsa.key
cli.opensslconf
cli2.crt
cli2.key
crl-ec-sha1.pem
crl-ec-sha224.pem
crl-ec-sha256.pem
crl-ec-sha384.pem
crl-ec-sha512.pem
crl-future.pem
crl-idp.pem
crl-idpnc.pem
crl-malformed-trailing-spaces.pem
crl-rsa-pss-sha1-badsign.pem
crl-rsa-pss-sha1.pem
crl-rsa-pss-sha224.pem
crl-rsa-pss-sha256.pem
crl-rsa-pss-sha384.pem
crl-rsa-pss-sha512.pem
crl.pem Update soon to be expired crl 2019-07-10 16:58:56 +03:00
crl_cat_ec-rsa.pem
crl_cat_ecfut-rsa.pem Update soon to be expired crl 2019-07-10 16:58:56 +03:00
crl_cat_rsa-ec.pem
crl_cat_rsabadpem-ec.pem
crl_expired.pem
crl_md2.pem
crl_md4.pem
crl_md5.pem
crl_sha1.pem
crl_sha224.pem
crl_sha256.pem
crl_sha384.pem
crl_sha512.pem
crt_cat_rsaexp-ec.pem
dh.1000.pem
dh.optlen.pem
dhparams.pem
ec_224_prv.pem
ec_224_pub.pem
ec_256_long_prv.pem pk_write test cases with short/long private key 2018-09-04 11:16:42 +02:00
ec_256_prv.pem
ec_256_pub.pem
ec_384_prv.pem
ec_384_pub.pem
ec_521_prv.pem
ec_521_pub.pem
ec_521_short_prv.pem pk_write test cases with short/long private key 2018-09-04 11:16:42 +02:00
ec_bp256_prv.pem
ec_bp256_pub.pem
ec_bp384_prv.pem
ec_bp384_pub.pem
ec_bp512_prv.pem
ec_bp512_pub.pem
ec_prv.pk8.der
ec_prv.pk8.pem
ec_prv.pk8.pw.der Adapt test files to supported PKCS#8 modes 2013-07-08 17:32:26 +02:00
ec_prv.pk8.pw.pem
ec_prv.pk8nopub.der Fix parsing of PKCS#8 encoded Elliptic Curve keys. 2018-03-28 11:29:21 +02:00
ec_prv.pk8nopub.pem Fix parsing of PKCS#8 encoded Elliptic Curve keys. 2018-03-28 11:29:21 +02:00
ec_prv.pk8nopubparam.der Fix parsing of PKCS#8 encoded Elliptic Curve keys. 2018-03-28 11:29:21 +02:00
ec_prv.pk8nopubparam.pem Fix parsing of PKCS#8 encoded Elliptic Curve keys. 2018-03-28 11:29:21 +02:00
ec_prv.pk8param.der Fix parsing of PKCS#8 encoded Elliptic Curve keys. 2018-03-28 11:29:21 +02:00
ec_prv.pk8param.pem Fix parsing of PKCS#8 encoded Elliptic Curve keys. 2018-03-28 11:29:21 +02:00
ec_prv.sec1.der
ec_prv.sec1.pem
ec_prv.sec1.pw.pem
ec_prv.specdom.der
ec_pub.der
ec_pub.pem
enco-ca-prstr.pem Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
enco-cert-utf8str.pem Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
format_gen.key
format_gen.pub
format_pkcs12.fmt
format_rsa.key
hash_file_1
hash_file_2
hash_file_3
hash_file_4
hash_file_5
keyUsage.decipherOnly.crt
Makefile Fix CA encoding issue with gnutls-cli 2020-02-03 15:55:43 +01:00
mpi_10
mpi_too_big
passwd.psk
print_c.pl
Readme-x509.txt
rsa512.key
rsa521.key
rsa522.key
rsa528.key
rsa4096_prv.pem
rsa4096_pub.pem
rsa_pkcs1_1024_3des.pem
rsa_pkcs1_1024_aes128.pem
rsa_pkcs1_1024_aes192.pem
rsa_pkcs1_1024_aes256.pem
rsa_pkcs1_1024_clear.pem Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
rsa_pkcs1_1024_des.pem
rsa_pkcs1_2048_3des.pem
rsa_pkcs1_2048_aes128.pem
rsa_pkcs1_2048_aes192.pem
rsa_pkcs1_2048_aes256.pem
rsa_pkcs1_2048_clear.pem
rsa_pkcs1_2048_des.pem
rsa_pkcs1_4096_3des.pem
rsa_pkcs1_4096_aes128.pem
rsa_pkcs1_4096_aes192.pem
rsa_pkcs1_4096_aes256.pem
rsa_pkcs1_4096_clear.pem
rsa_pkcs1_4096_des.pem
rsa_pkcs8_pbe_sha1_1024_2des.der
rsa_pkcs8_pbe_sha1_1024_2des.pem
rsa_pkcs8_pbe_sha1_1024_3des.der
rsa_pkcs8_pbe_sha1_1024_3des.pem
rsa_pkcs8_pbe_sha1_1024_rc4_128.der
rsa_pkcs8_pbe_sha1_1024_rc4_128.pem
rsa_pkcs8_pbe_sha1_2048_2des.der
rsa_pkcs8_pbe_sha1_2048_2des.pem
rsa_pkcs8_pbe_sha1_2048_3des.der
rsa_pkcs8_pbe_sha1_2048_3des.pem
rsa_pkcs8_pbe_sha1_2048_rc4_128.der
rsa_pkcs8_pbe_sha1_2048_rc4_128.pem
rsa_pkcs8_pbe_sha1_4096_2des.der
rsa_pkcs8_pbe_sha1_4096_2des.pem
rsa_pkcs8_pbe_sha1_4096_3des.der
rsa_pkcs8_pbe_sha1_4096_3des.pem
rsa_pkcs8_pbe_sha1_4096_rc4_128.der
rsa_pkcs8_pbe_sha1_4096_rc4_128.pem
rsa_pkcs8_pbes2_pbkdf2_1024_3des.der
rsa_pkcs8_pbes2_pbkdf2_1024_3des.pem
rsa_pkcs8_pbes2_pbkdf2_1024_3des_sha224.der
rsa_pkcs8_pbes2_pbkdf2_1024_3des_sha224.pem
rsa_pkcs8_pbes2_pbkdf2_1024_3des_sha256.der
rsa_pkcs8_pbes2_pbkdf2_1024_3des_sha256.pem
rsa_pkcs8_pbes2_pbkdf2_1024_3des_sha384.der
rsa_pkcs8_pbes2_pbkdf2_1024_3des_sha384.pem
rsa_pkcs8_pbes2_pbkdf2_1024_3des_sha512.der
rsa_pkcs8_pbes2_pbkdf2_1024_3des_sha512.pem
rsa_pkcs8_pbes2_pbkdf2_1024_des.der
rsa_pkcs8_pbes2_pbkdf2_1024_des.pem
rsa_pkcs8_pbes2_pbkdf2_1024_des_sha224.der
rsa_pkcs8_pbes2_pbkdf2_1024_des_sha224.pem
rsa_pkcs8_pbes2_pbkdf2_1024_des_sha256.der data_files/pkcs8-v2: add keys generated with PRF != SHA1 2018-02-08 17:18:19 +08:00
rsa_pkcs8_pbes2_pbkdf2_1024_des_sha256.pem
rsa_pkcs8_pbes2_pbkdf2_1024_des_sha384.der data_files/pkcs8-v2: add keys generated with PRF != SHA1 2018-02-08 17:18:19 +08:00
rsa_pkcs8_pbes2_pbkdf2_1024_des_sha384.pem
rsa_pkcs8_pbes2_pbkdf2_1024_des_sha512.der
rsa_pkcs8_pbes2_pbkdf2_1024_des_sha512.pem
rsa_pkcs8_pbes2_pbkdf2_2048_3des.der
rsa_pkcs8_pbes2_pbkdf2_2048_3des.pem
rsa_pkcs8_pbes2_pbkdf2_2048_3des_sha224.der
rsa_pkcs8_pbes2_pbkdf2_2048_3des_sha224.pem
rsa_pkcs8_pbes2_pbkdf2_2048_3des_sha256.der
rsa_pkcs8_pbes2_pbkdf2_2048_3des_sha256.pem
rsa_pkcs8_pbes2_pbkdf2_2048_3des_sha384.der
rsa_pkcs8_pbes2_pbkdf2_2048_3des_sha384.pem
rsa_pkcs8_pbes2_pbkdf2_2048_3des_sha512.der
rsa_pkcs8_pbes2_pbkdf2_2048_3des_sha512.pem
rsa_pkcs8_pbes2_pbkdf2_2048_des.der
rsa_pkcs8_pbes2_pbkdf2_2048_des.pem
rsa_pkcs8_pbes2_pbkdf2_2048_des_sha224.der
rsa_pkcs8_pbes2_pbkdf2_2048_des_sha224.pem
rsa_pkcs8_pbes2_pbkdf2_2048_des_sha256.der
rsa_pkcs8_pbes2_pbkdf2_2048_des_sha256.pem
rsa_pkcs8_pbes2_pbkdf2_2048_des_sha384.der
rsa_pkcs8_pbes2_pbkdf2_2048_des_sha384.pem
rsa_pkcs8_pbes2_pbkdf2_2048_des_sha512.der
rsa_pkcs8_pbes2_pbkdf2_2048_des_sha512.pem
rsa_pkcs8_pbes2_pbkdf2_4096_3des.der
rsa_pkcs8_pbes2_pbkdf2_4096_3des.pem
rsa_pkcs8_pbes2_pbkdf2_4096_3des_sha224.der
rsa_pkcs8_pbes2_pbkdf2_4096_3des_sha224.pem
rsa_pkcs8_pbes2_pbkdf2_4096_3des_sha256.der
rsa_pkcs8_pbes2_pbkdf2_4096_3des_sha256.pem
rsa_pkcs8_pbes2_pbkdf2_4096_3des_sha384.der
rsa_pkcs8_pbes2_pbkdf2_4096_3des_sha384.pem
rsa_pkcs8_pbes2_pbkdf2_4096_3des_sha512.der
rsa_pkcs8_pbes2_pbkdf2_4096_3des_sha512.pem
rsa_pkcs8_pbes2_pbkdf2_4096_des.der
rsa_pkcs8_pbes2_pbkdf2_4096_des.pem
rsa_pkcs8_pbes2_pbkdf2_4096_des_sha224.der
rsa_pkcs8_pbes2_pbkdf2_4096_des_sha224.pem
rsa_pkcs8_pbes2_pbkdf2_4096_des_sha256.der
rsa_pkcs8_pbes2_pbkdf2_4096_des_sha256.pem
rsa_pkcs8_pbes2_pbkdf2_4096_des_sha384.der
rsa_pkcs8_pbes2_pbkdf2_4096_des_sha384.pem
rsa_pkcs8_pbes2_pbkdf2_4096_des_sha512.der
rsa_pkcs8_pbes2_pbkdf2_4096_des_sha512.pem
secp521r1_prv.der Add a test for signing content with a long ECDSA key 2019-06-10 11:48:38 +02:00
server1-ms.req.sha256 Add additional test case for alternative CSR headers 2018-12-05 23:23:28 +00:00
server1-nospace.crt
server1-v1.crt
server1.cert_type.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server1.cert_type.crt.openssl.v3_ext
server1.cert_type_noauthid.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server1.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server1.crt.openssl.v3_ext
server1.csr
server1.ext_ku.crt
server1.key
server1.key_usage.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server1.key_usage.crt.openssl.v3_ext
server1.key_usage_noauthid.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server1.noauthid.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server1.pubkey
server1.req.cert_type Add tests for (named) bitstring to suite_asn1write 2019-02-11 21:10:55 +00:00
server1.req.cert_type_empty Add tests for (named) bitstring to suite_asn1write 2019-02-11 21:10:55 +00:00
server1.req.key_usage Add tests for (named) bitstring to suite_asn1write 2019-02-11 21:10:55 +00:00
server1.req.key_usage_empty Add tests for (named) bitstring to suite_asn1write 2019-02-11 21:10:55 +00:00
server1.req.ku-ct Add tests for (named) bitstring to suite_asn1write 2019-02-11 21:10:55 +00:00
server1.req.md4
server1.req.md5
server1.req.sha1
server1.req.sha224
server1.req.sha256
server1.req.sha384
server1.req.sha512
server1.v1.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server1_ca.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server1_csr.opensslconf
server1_pathlen_int_max-1.crt Guard from undefined behaviour in case of an INT_MAX max_pathlen 2020-04-17 11:30:21 +02:00
server1_pathlen_int_max.crt Guard from undefined behaviour in case of an INT_MAX max_pathlen 2020-04-17 11:30:21 +02:00
server2-badsign.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server2-sha256.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server2-v1-chain.crt
server2-v1.crt
server2.crt Create certificates with correct string formatting 2019-07-10 17:23:06 +03:00
server2.key
server2.ku-ds.crt
server2.ku-ds_ke.crt
server2.ku-ka.crt
server2.ku-ke.crt
server3.crt
server3.key
server4.crt
server4.key
server5-badsign.crt
server5-der0.crt
server5-der1a.crt
server5-der1b.crt
server5-der2.crt
server5-der4.crt
server5-der8.crt
server5-der9.crt
server5-expired.crt
server5-future.crt
server5-selfsigned.crt
server5-sha1.crt
server5-sha224.crt
server5-sha384.crt
server5-sha512.crt
server5-ss-expired.crt
server5-ss-forgeca.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
server5.crt
server5.eku-cli.crt
server5.eku-cs.crt
server5.eku-cs_any.crt
server5.eku-srv.crt
server5.eku-srv_cli.crt
server5.key
server5.ku-ds.crt
server5.ku-ka.crt
server5.ku-ke.crt
server5.req.ku.sha1 Add tests for (named) bitstring to suite_asn1write 2019-02-11 21:10:55 +00:00
server5.req.sha1
server5.req.sha224
server5.req.sha256
server5.req.sha384
server5.req.sha512
server6-ss-child.crt
server6.crt
server6.key
server7-badsign.crt
server7-expired.crt
server7-future.crt
server7.crt
server7.key
server7_all_space.crt
server7_int-ca-exp.crt
server7_int-ca.crt
server7_int-ca_ca2.crt
server7_pem_space.crt
server7_spurious_int-ca.crt
server7_trailing_space.crt
server8.crt
server8.key
server8_int-ca2.crt
server9-bad-mgfhash.crt
server9-bad-saltlen.crt
server9-badsign.crt
server9-defaults.crt
server9-sha224.crt
server9-sha256.crt
server9-sha384.crt
server9-sha512.crt
server9-with-ca.crt
server9.crt
server9.key
server9.req.sha1
server9.req.sha224
server9.req.sha256
server9.req.sha384
server9.req.sha512
server10.key
server10_int3_int-ca2.crt
server10_int3_int-ca2_ca.crt
server10_int3_spurious_int-ca2.crt
test-ca-alt-good.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
test-ca-alt.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
test-ca-alt.csr Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
test-ca-alt.key Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
test-ca-good-alt.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
test-ca-sha1.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
test-ca-sha256.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
test-ca-v1.crt
test-ca.crt Create certificates with correct string formatting 2019-07-10 17:23:06 +03:00
test-ca.key
test-ca.opensslconf
test-ca.server1.db Update soon to be expired crl 2019-07-10 16:58:56 +03:00
test-ca.server1.opensslconf
test-ca2-expired.crt
test-ca2.crt
test-ca2.key
test-ca2.ku-crl.crt
test-ca2.ku-crt.crt
test-ca2.ku-crt_crl.crt
test-ca2.ku-ds.crt
test-ca2_cat-future-invalid.crt
test-ca2_cat-future-present.crt
test-ca2_cat-past-invalid.crt
test-ca2_cat-past-present.crt
test-ca2_cat-present-future.crt
test-ca2_cat-present-past.crt
test-ca_cat12.crt Create certificates with correct string formatting 2019-07-10 17:23:06 +03:00
test-ca_cat12u.crt Fix CA encoding issue with gnutls-cli 2020-02-03 15:55:43 +01:00
test-ca_cat21.crt Create certificates with correct string formatting 2019-07-10 17:23:06 +03:00
test-ca_printable.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
test-ca_uppercase.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
test-ca_utf8.crt Update certificates to expire in 2029 2019-07-10 17:23:06 +03:00
test-int-ca-exp.crt
test-int-ca.crt
test-int-ca.key
test-int-ca2.crt
test-int-ca2.key
test-int-ca3.crt
test-int-ca3.key