push 52d6b63ba2f2d4f9b02b6b922d27bff05a60596f
[wine/hacks.git] / dlls / crypt32 / tests / cert.c
blob685a5643555ff71e4b9df0f3dcbb8630798fe1d8
1 /*
2 * crypt32 cert functions tests
4 * Copyright 2005-2006 Juan Lang
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 2.1 of the License, or (at your option) any later version.
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, write to the Free Software
18 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
21 #include <assert.h>
22 #include <stdio.h>
23 #include <stdarg.h>
24 #include <windef.h>
25 #include <winbase.h>
26 #include <winreg.h>
27 #include <winerror.h>
28 #include <wincrypt.h>
30 #include "wine/test.h"
32 static BOOL (WINAPI *pCertAddStoreToCollection)(HCERTSTORE,HCERTSTORE,DWORD,DWORD);
33 static PCCERT_CONTEXT (WINAPI *pCertCreateSelfSignCertificate)(HCRYPTPROV_OR_NCRYPT_KEY_HANDLE,PCERT_NAME_BLOB,DWORD,PCRYPT_KEY_PROV_INFO,PCRYPT_ALGORITHM_IDENTIFIER,PSYSTEMTIME,PSYSTEMTIME,PCERT_EXTENSIONS);
34 static BOOL (WINAPI *pCertGetValidUsages)(DWORD,PCCERT_CONTEXT*,int*,LPSTR*,DWORD*);
35 static BOOL (WINAPI *pCryptAcquireCertificatePrivateKey)(PCCERT_CONTEXT,DWORD,void*,HCRYPTPROV_OR_NCRYPT_KEY_HANDLE*,DWORD*,BOOL*);
36 static BOOL (WINAPI *pCryptEncodeObjectEx)(DWORD,LPCSTR,const void*,DWORD,PCRYPT_ENCODE_PARA,void*,DWORD*);
37 static BOOL (WINAPI * pCryptVerifyCertificateSignatureEx)
38 (HCRYPTPROV, DWORD, DWORD, void *, DWORD, void *, DWORD, void *);
40 static BOOL (WINAPI * pCryptAcquireContextA)
41 (HCRYPTPROV *, LPCSTR, LPCSTR, DWORD, DWORD);
43 static void init_function_pointers(void)
45 HMODULE hCrypt32 = GetModuleHandleA("crypt32.dll");
46 HMODULE hAdvapi32 = GetModuleHandleA("advapi32.dll");
48 #define GET_PROC(dll, func) \
49 p ## func = (void *)GetProcAddress(dll, #func); \
50 if(!p ## func) \
51 trace("GetProcAddress(%s) failed\n", #func);
53 GET_PROC(hCrypt32, CertAddStoreToCollection)
54 GET_PROC(hCrypt32, CertCreateSelfSignCertificate)
55 GET_PROC(hCrypt32, CertGetValidUsages)
56 GET_PROC(hCrypt32, CryptAcquireCertificatePrivateKey)
57 GET_PROC(hCrypt32, CryptEncodeObjectEx)
58 GET_PROC(hCrypt32, CryptVerifyCertificateSignatureEx)
60 GET_PROC(hAdvapi32, CryptAcquireContextA)
62 #undef GET_PROC
65 static BYTE subjectName[] = { 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06,
66 0x03, 0x55, 0x04, 0x03, 0x13, 0x0a, 0x4a, 0x75, 0x61, 0x6e, 0x20, 0x4c, 0x61,
67 0x6e, 0x67, 0x00 };
68 static BYTE serialNum[] = { 1 };
69 static const BYTE bigCert[] = { 0x30, 0x7a, 0x02, 0x01, 0x01, 0x30, 0x02, 0x06,
70 0x00, 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13,
71 0x0a, 0x4a, 0x75, 0x61, 0x6e, 0x20, 0x4c, 0x61, 0x6e, 0x67, 0x00, 0x30, 0x22,
72 0x18, 0x0f, 0x31, 0x36, 0x30, 0x31, 0x30, 0x31, 0x30, 0x31, 0x30, 0x30, 0x30,
73 0x30, 0x30, 0x30, 0x5a, 0x18, 0x0f, 0x31, 0x36, 0x30, 0x31, 0x30, 0x31, 0x30,
74 0x31, 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x30, 0x15, 0x31, 0x13, 0x30,
75 0x11, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x0a, 0x4a, 0x75, 0x61, 0x6e, 0x20,
76 0x4c, 0x61, 0x6e, 0x67, 0x00, 0x30, 0x07, 0x30, 0x02, 0x06, 0x00, 0x03, 0x01,
77 0x00, 0xa3, 0x16, 0x30, 0x14, 0x30, 0x12, 0x06, 0x03, 0x55, 0x1d, 0x13, 0x01,
78 0x01, 0xff, 0x04, 0x08, 0x30, 0x06, 0x01, 0x01, 0xff, 0x02, 0x01, 0x01 };
79 static BYTE bigCertHash[] = { 0x6e, 0x30, 0x90, 0x71, 0x5f, 0xd9, 0x23,
80 0x56, 0xeb, 0xae, 0x25, 0x40, 0xe6, 0x22, 0xda, 0x19, 0x26, 0x02, 0xa6, 0x08 };
82 static const BYTE bigCertWithDifferentSubject[] = { 0x30, 0x7a, 0x02, 0x01, 0x02,
83 0x30, 0x02, 0x06, 0x00, 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55,
84 0x04, 0x03, 0x13, 0x0a, 0x4a, 0x75, 0x61, 0x6e, 0x20, 0x4c, 0x61, 0x6e, 0x67,
85 0x00, 0x30, 0x22, 0x18, 0x0f, 0x31, 0x36, 0x30, 0x31, 0x30, 0x31, 0x30, 0x31,
86 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x18, 0x0f, 0x31, 0x36, 0x30, 0x31,
87 0x30, 0x31, 0x30, 0x31, 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x30, 0x15,
88 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x0a, 0x41, 0x6c,
89 0x65, 0x78, 0x20, 0x4c, 0x61, 0x6e, 0x67, 0x00, 0x30, 0x07, 0x30, 0x02, 0x06,
90 0x00, 0x03, 0x01, 0x00, 0xa3, 0x16, 0x30, 0x14, 0x30, 0x12, 0x06, 0x03, 0x55,
91 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04, 0x08, 0x30, 0x06, 0x01, 0x01, 0xff, 0x02,
92 0x01, 0x01 };
93 static const BYTE bigCertWithDifferentIssuer[] = { 0x30, 0x7a, 0x02, 0x01,
94 0x01, 0x30, 0x02, 0x06, 0x00, 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03,
95 0x55, 0x04, 0x03, 0x13, 0x0a, 0x41, 0x6c, 0x65, 0x78, 0x20, 0x4c, 0x61, 0x6e,
96 0x67, 0x00, 0x30, 0x22, 0x18, 0x0f, 0x31, 0x36, 0x30, 0x31, 0x30, 0x31, 0x30,
97 0x31, 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x18, 0x0f, 0x31, 0x36, 0x30,
98 0x31, 0x30, 0x31, 0x30, 0x31, 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x30,
99 0x15, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x0a, 0x4a,
100 0x75, 0x61, 0x6e, 0x20, 0x4c, 0x61, 0x6e, 0x67, 0x00, 0x30, 0x07, 0x30, 0x02,
101 0x06, 0x00, 0x03, 0x01, 0x00, 0xa3, 0x16, 0x30, 0x14, 0x30, 0x12, 0x06, 0x03,
102 0x55, 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04, 0x08, 0x30, 0x06, 0x01, 0x01, 0xff,
103 0x02, 0x01, 0x01 };
105 static BYTE subjectName2[] = { 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06,
106 0x03, 0x55, 0x04, 0x03, 0x13, 0x0a, 0x41, 0x6c, 0x65, 0x78, 0x20, 0x4c, 0x61,
107 0x6e, 0x67, 0x00 };
108 static const BYTE bigCert2[] = { 0x30, 0x7a, 0x02, 0x01, 0x01, 0x30, 0x02, 0x06,
109 0x00, 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13,
110 0x0a, 0x41, 0x6c, 0x65, 0x78, 0x20, 0x4c, 0x61, 0x6e, 0x67, 0x00, 0x30, 0x22,
111 0x18, 0x0f, 0x31, 0x36, 0x30, 0x31, 0x30, 0x31, 0x30, 0x31, 0x30, 0x30, 0x30,
112 0x30, 0x30, 0x30, 0x5a, 0x18, 0x0f, 0x31, 0x36, 0x30, 0x31, 0x30, 0x31, 0x30,
113 0x31, 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x30, 0x15, 0x31, 0x13, 0x30,
114 0x11, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x0a, 0x41, 0x6c, 0x65, 0x78, 0x20,
115 0x4c, 0x61, 0x6e, 0x67, 0x00, 0x30, 0x07, 0x30, 0x02, 0x06, 0x00, 0x03, 0x01,
116 0x00, 0xa3, 0x16, 0x30, 0x14, 0x30, 0x12, 0x06, 0x03, 0x55, 0x1d, 0x13, 0x01,
117 0x01, 0xff, 0x04, 0x08, 0x30, 0x06, 0x01, 0x01, 0xff, 0x02, 0x01, 0x01 };
118 static const BYTE bigCert2WithDifferentSerial[] = { 0x30, 0x7a, 0x02, 0x01,
119 0x02, 0x30, 0x02, 0x06, 0x00, 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03,
120 0x55, 0x04, 0x03, 0x13, 0x0a, 0x41, 0x6c, 0x65, 0x78, 0x20, 0x4c, 0x61, 0x6e,
121 0x67, 0x00, 0x30, 0x22, 0x18, 0x0f, 0x31, 0x36, 0x30, 0x31, 0x30, 0x31, 0x30,
122 0x31, 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x18, 0x0f, 0x31, 0x36, 0x30,
123 0x31, 0x30, 0x31, 0x30, 0x31, 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x30,
124 0x15, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x0a, 0x41,
125 0x6c, 0x65, 0x78, 0x20, 0x4c, 0x61, 0x6e, 0x67, 0x00, 0x30, 0x07, 0x30, 0x02,
126 0x06, 0x00, 0x03, 0x01, 0x00, 0xa3, 0x16, 0x30, 0x14, 0x30, 0x12, 0x06, 0x03,
127 0x55, 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04, 0x08, 0x30, 0x06, 0x01, 0x01, 0xff,
128 0x02, 0x01, 0x01 };
129 static BYTE bigCert2Hash[] = { 0x4a, 0x7f, 0x32, 0x1f, 0xcf, 0x3b, 0xc0,
130 0x87, 0x48, 0x2b, 0xa1, 0x86, 0x54, 0x18, 0xe4, 0x3a, 0x0e, 0x53, 0x7e, 0x2b };
132 static const BYTE certWithUsage[] = { 0x30, 0x81, 0x93, 0x02, 0x01, 0x01, 0x30,
133 0x02, 0x06, 0x00, 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04,
134 0x03, 0x13, 0x0a, 0x4a, 0x75, 0x61, 0x6e, 0x20, 0x4c, 0x61, 0x6e, 0x67, 0x00,
135 0x30, 0x22, 0x18, 0x0f, 0x31, 0x36, 0x30, 0x31, 0x30, 0x31, 0x30, 0x31, 0x30,
136 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x18, 0x0f, 0x31, 0x36, 0x30, 0x31, 0x30,
137 0x31, 0x30, 0x31, 0x30, 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x30, 0x15, 0x31,
138 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x0a, 0x4a, 0x75, 0x61,
139 0x6e, 0x20, 0x4c, 0x61, 0x6e, 0x67, 0x00, 0x30, 0x07, 0x30, 0x02, 0x06, 0x00,
140 0x03, 0x01, 0x00, 0xa3, 0x2f, 0x30, 0x2d, 0x30, 0x2b, 0x06, 0x03, 0x55, 0x1d,
141 0x25, 0x01, 0x01, 0xff, 0x04, 0x21, 0x30, 0x1f, 0x06, 0x08, 0x2b, 0x06, 0x01,
142 0x05, 0x05, 0x07, 0x03, 0x03, 0x06, 0x08, 0x2b, 0x06, 0x01, 0x05, 0x05, 0x07,
143 0x03, 0x02, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x01 };
145 static void testAddCert(void)
147 HCERTSTORE store;
148 HCERTSTORE collection;
149 PCCERT_CONTEXT context;
150 PCCERT_CONTEXT copyContext;
151 BOOL ret;
153 store = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0,
154 CERT_STORE_CREATE_NEW_FLAG, NULL);
155 ok(store != NULL, "CertOpenStore failed: %d\n", GetLastError());
156 if (!store)
157 return;
159 /* Weird--bad add disposition leads to an access violation in Windows.
160 * Both tests crash on some win9x boxes.
162 if (0)
164 ret = CertAddEncodedCertificateToStore(0, X509_ASN_ENCODING, bigCert,
165 sizeof(bigCert), 0, NULL);
166 ok(!ret && (GetLastError() == STATUS_ACCESS_VIOLATION ||
167 GetLastError() == E_INVALIDARG),
168 "Expected STATUS_ACCESS_VIOLATION or E_INVALIDARG, got %08x\n",
169 GetLastError());
170 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
171 bigCert, sizeof(bigCert), 0, NULL);
172 ok(!ret && (GetLastError() == STATUS_ACCESS_VIOLATION ||
173 GetLastError() == E_INVALIDARG),
174 "Expected STATUS_ACCESS_VIOLATION or E_INVALIDARG, got %08x\n",
175 GetLastError());
178 /* Weird--can add a cert to the NULL store (does this have special
179 * meaning?)
181 context = NULL;
182 ret = CertAddEncodedCertificateToStore(0, X509_ASN_ENCODING, bigCert,
183 sizeof(bigCert), CERT_STORE_ADD_ALWAYS, &context);
184 ok(ret || broken(GetLastError() == OSS_DATA_ERROR /* win98 */),
185 "CertAddEncodedCertificateToStore failed: %08x\n", GetLastError());
186 if (context)
187 CertFreeCertificateContext(context);
188 if (!ret && GetLastError() == OSS_DATA_ERROR)
190 skip("bigCert can't be decoded, skipping tests\n");
191 return;
194 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
195 bigCert, sizeof(bigCert), CERT_STORE_ADD_ALWAYS, NULL);
196 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
197 GetLastError());
198 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
199 bigCert2, sizeof(bigCert2), CERT_STORE_ADD_NEW, NULL);
200 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
201 GetLastError());
202 /* This has the same name as bigCert, so finding isn't done by name */
203 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
204 certWithUsage, sizeof(certWithUsage), CERT_STORE_ADD_NEW, &context);
205 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
206 GetLastError());
207 ok(context != NULL, "Expected a context\n");
208 if (context)
210 CRYPT_DATA_BLOB hash = { sizeof(bigCert2Hash), bigCert2Hash };
212 /* Duplicate (AddRef) the context so we can still use it after
213 * deleting it from the store.
215 CertDuplicateCertificateContext(context);
216 CertDeleteCertificateFromStore(context);
217 /* Set the same hash as bigCert2, and try to readd it */
218 ret = CertSetCertificateContextProperty(context, CERT_HASH_PROP_ID,
219 0, &hash);
220 ok(ret, "CertSetCertificateContextProperty failed: %08x\n",
221 GetLastError());
222 ret = CertAddCertificateContextToStore(store, context,
223 CERT_STORE_ADD_NEW, NULL);
224 /* The failure is a bit odd (CRYPT_E_ASN1_BADTAG), so just check
225 * that it fails.
227 ok(!ret, "Expected failure\n");
228 CertFreeCertificateContext(context);
230 context = CertCreateCertificateContext(X509_ASN_ENCODING, bigCert2,
231 sizeof(bigCert2));
232 ok(context != NULL, "Expected a context\n");
233 if (context)
235 /* Try to readd bigCert2 to the store */
236 ret = CertAddCertificateContextToStore(store, context,
237 CERT_STORE_ADD_NEW, NULL);
238 ok(!ret && GetLastError() == CRYPT_E_EXISTS,
239 "Expected CRYPT_E_EXISTS, got %08x\n", GetLastError());
240 CertFreeCertificateContext(context);
243 /* Adding a cert with the same issuer name and serial number (but
244 * different subject) as an existing cert succeeds.
246 context = NULL;
247 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
248 bigCert2WithDifferentSerial, sizeof(bigCert2WithDifferentSerial),
249 CERT_STORE_ADD_NEW, &context);
250 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
251 GetLastError());
252 if (context)
253 CertDeleteCertificateFromStore(context);
255 /* Adding a cert with the same subject name and serial number (but
256 * different issuer) as an existing cert succeeds.
258 context = NULL;
259 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
260 bigCertWithDifferentSubject, sizeof(bigCertWithDifferentSubject),
261 CERT_STORE_ADD_NEW, &context);
262 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
263 GetLastError());
264 if (context)
265 CertDeleteCertificateFromStore(context);
267 /* Adding a cert with the same issuer name and serial number (but
268 * different otherwise) as an existing cert succeeds.
270 context = NULL;
271 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
272 bigCertWithDifferentIssuer, sizeof(bigCertWithDifferentIssuer),
273 CERT_STORE_ADD_NEW, &context);
274 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
275 GetLastError());
276 if (context)
277 CertDeleteCertificateFromStore(context);
279 collection = CertOpenStore(CERT_STORE_PROV_COLLECTION, 0, 0,
280 CERT_STORE_CREATE_NEW_FLAG, NULL);
281 ok(collection != NULL, "CertOpenStore failed: %08x\n", GetLastError());
282 if (collection && pCertAddStoreToCollection)
284 /* Add store to the collection, but disable updates */
285 pCertAddStoreToCollection(collection, store, 0, 0);
287 context = CertCreateCertificateContext(X509_ASN_ENCODING, bigCert2,
288 sizeof(bigCert2));
289 ok(context != NULL, "Expected a context\n");
290 if (context)
292 /* Try to readd bigCert2 to the collection */
293 ret = CertAddCertificateContextToStore(collection, context,
294 CERT_STORE_ADD_NEW, NULL);
295 ok(!ret && GetLastError() == CRYPT_E_EXISTS,
296 "Expected CRYPT_E_EXISTS, got %08x\n", GetLastError());
297 /* Replacing an existing certificate context is allowed, even
298 * though updates to the collection aren't..
300 ret = CertAddCertificateContextToStore(collection, context,
301 CERT_STORE_ADD_REPLACE_EXISTING, NULL);
302 ok(ret, "CertAddCertificateContextToStore failed: %08x\n",
303 GetLastError());
304 /* use the existing certificate and ask for a copy of the context*/
305 copyContext = NULL;
306 ret = CertAddCertificateContextToStore(collection, context,
307 CERT_STORE_ADD_USE_EXISTING, &copyContext);
308 ok(ret, "CertAddCertificateContextToStore failed: %08x\n",
309 GetLastError());
310 ok(copyContext != NULL, "Expected on output a non NULL copyContext\n");
311 if (copyContext)
312 CertFreeCertificateContext(copyContext);
313 /* but adding a new certificate isn't allowed. */
314 ret = CertAddCertificateContextToStore(collection, context,
315 CERT_STORE_ADD_ALWAYS, NULL);
316 ok(!ret && GetLastError() == E_ACCESSDENIED,
317 "Expected E_ACCESSDENIED, got %08x\n", GetLastError());
318 CertFreeCertificateContext(context);
321 CertCloseStore(collection, 0);
324 CertCloseStore(store, 0);
327 static void checkHash(const BYTE *data, DWORD dataLen, ALG_ID algID,
328 PCCERT_CONTEXT context, DWORD propID)
330 BYTE hash[20] = { 0 }, hashProperty[20];
331 BOOL ret;
332 DWORD size;
333 DWORD dwSizeWithNull;
335 memset(hash, 0, sizeof(hash));
336 memset(hashProperty, 0, sizeof(hashProperty));
337 size = sizeof(hash);
338 ret = CryptHashCertificate(0, algID, 0, data, dataLen, hash, &size);
339 ok(ret, "CryptHashCertificate failed: %08x\n", GetLastError());
340 ret = CertGetCertificateContextProperty(context, propID, NULL,
341 &dwSizeWithNull);
342 ok(ret, "algID %08x, propID %d: CertGetCertificateContextProperty failed: %08x\n",
343 algID, propID, GetLastError());
344 ret = CertGetCertificateContextProperty(context, propID, hashProperty,
345 &size);
346 ok(ret, "CertGetCertificateContextProperty failed: %08x\n",
347 GetLastError());
348 ok(!memcmp(hash, hashProperty, size), "Unexpected hash for property %d\n",
349 propID);
350 ok(size == dwSizeWithNull, "Unexpected length of hash for property: received %d instead of %d\n",
351 dwSizeWithNull,size);
354 static CHAR cspNameA[] = "WineCryptTemp";
355 static WCHAR cspNameW[] = { 'W','i','n','e','C','r','y','p','t','T','e','m','p',0 };
356 static const BYTE v1CertWithPubKey[] = {
357 0x30,0x81,0x95,0x02,0x01,0x01,0x30,0x02,0x06,0x00,0x30,0x15,0x31,0x13,0x30,
358 0x11,0x06,0x03,0x55,0x04,0x03,0x13,0x0a,0x4a,0x75,0x61,0x6e,0x20,0x4c,0x61,
359 0x6e,0x67,0x00,0x30,0x22,0x18,0x0f,0x31,0x36,0x30,0x31,0x30,0x31,0x30,0x31,
360 0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x18,0x0f,0x31,0x36,0x30,0x31,0x30,0x31,
361 0x30,0x31,0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x30,0x15,0x31,0x13,0x30,0x11,
362 0x06,0x03,0x55,0x04,0x03,0x13,0x0a,0x4a,0x75,0x61,0x6e,0x20,0x4c,0x61,0x6e,
363 0x67,0x00,0x30,0x22,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,
364 0x01,0x01,0x05,0x00,0x03,0x11,0x00,0x00,0x01,0x02,0x03,0x04,0x05,0x06,0x07,
365 0x08,0x09,0x0a,0x0b,0x0c,0x0d,0x0e,0x0f,0xa3,0x16,0x30,0x14,0x30,0x12,0x06,
366 0x03,0x55,0x1d,0x13,0x01,0x01,0xff,0x04,0x08,0x30,0x06,0x01,0x01,0xff,0x02,
367 0x01,0x01 };
368 static const BYTE v1CertWithSubjectKeyId[] = {
369 0x30,0x7b,0x02,0x01,0x01,0x30,0x02,0x06,0x00,0x30,0x15,0x31,0x13,0x30,0x11,
370 0x06,0x03,0x55,0x04,0x03,0x13,0x0a,0x4a,0x75,0x61,0x6e,0x20,0x4c,0x61,0x6e,
371 0x67,0x00,0x30,0x22,0x18,0x0f,0x31,0x36,0x30,0x31,0x30,0x31,0x30,0x31,0x30,
372 0x30,0x30,0x30,0x30,0x30,0x5a,0x18,0x0f,0x31,0x36,0x30,0x31,0x30,0x31,0x30,
373 0x31,0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x30,0x15,0x31,0x13,0x30,0x11,0x06,
374 0x03,0x55,0x04,0x03,0x13,0x0a,0x4a,0x75,0x61,0x6e,0x20,0x4c,0x61,0x6e,0x67,
375 0x00,0x30,0x07,0x30,0x02,0x06,0x00,0x03,0x01,0x00,0xa3,0x17,0x30,0x15,0x30,
376 0x13,0x06,0x03,0x55,0x1d,0x0e,0x04,0x0c,0x04,0x0a,0x4a,0x75,0x61,0x6e,0x20,
377 0x4c,0x61,0x6e,0x67,0x00 };
378 static const BYTE subjectKeyId[] = {
379 0x4a,0x75,0x61,0x6e,0x20,0x4c,0x61,0x6e,0x67,0x00 };
380 static const BYTE selfSignedCert[] = {
381 0x30, 0x82, 0x01, 0x1f, 0x30, 0x81, 0xce, 0xa0, 0x03, 0x02, 0x01, 0x02, 0x02,
382 0x10, 0xeb, 0x0d, 0x57, 0x2a, 0x9c, 0x09, 0xba, 0xa4, 0x4a, 0xb7, 0x25, 0x49,
383 0xd9, 0x3e, 0xb5, 0x73, 0x30, 0x09, 0x06, 0x05, 0x2b, 0x0e, 0x03, 0x02, 0x1d,
384 0x05, 0x00, 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x03,
385 0x13, 0x0a, 0x4a, 0x75, 0x61, 0x6e, 0x20, 0x4c, 0x61, 0x6e, 0x67, 0x00, 0x30,
386 0x1e, 0x17, 0x0d, 0x30, 0x36, 0x30, 0x36, 0x32, 0x39, 0x30, 0x35, 0x30, 0x30,
387 0x34, 0x36, 0x5a, 0x17, 0x0d, 0x30, 0x37, 0x30, 0x36, 0x32, 0x39, 0x31, 0x31,
388 0x30, 0x30, 0x34, 0x36, 0x5a, 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06, 0x03,
389 0x55, 0x04, 0x03, 0x13, 0x0a, 0x4a, 0x75, 0x61, 0x6e, 0x20, 0x4c, 0x61, 0x6e,
390 0x67, 0x00, 0x30, 0x5c, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7,
391 0x0d, 0x01, 0x01, 0x01, 0x05, 0x00, 0x03, 0x4b, 0x00, 0x30, 0x48, 0x02, 0x41,
392 0x00, 0xe2, 0x54, 0x3a, 0xa7, 0x83, 0xb1, 0x27, 0x14, 0x3e, 0x59, 0xbb, 0xb4,
393 0x53, 0xe6, 0x1f, 0xe7, 0x5d, 0xf1, 0x21, 0x68, 0xad, 0x85, 0x53, 0xdb, 0x6b,
394 0x1e, 0xeb, 0x65, 0x97, 0x03, 0x86, 0x60, 0xde, 0xf3, 0x6c, 0x38, 0x75, 0xe0,
395 0x4c, 0x61, 0xbb, 0xbc, 0x62, 0x17, 0xa9, 0xcd, 0x79, 0x3f, 0x21, 0x4e, 0x96,
396 0xcb, 0x0e, 0xdc, 0x61, 0x94, 0x30, 0x18, 0x10, 0x6b, 0xd0, 0x1c, 0x10, 0x79,
397 0x02, 0x03, 0x01, 0x00, 0x01, 0x30, 0x09, 0x06, 0x05, 0x2b, 0x0e, 0x03, 0x02,
398 0x1d, 0x05, 0x00, 0x03, 0x41, 0x00, 0x25, 0x90, 0x53, 0x34, 0xd9, 0x56, 0x41,
399 0x5e, 0xdb, 0x7e, 0x01, 0x36, 0xec, 0x27, 0x61, 0x5e, 0xb7, 0x4d, 0x90, 0x66,
400 0xa2, 0xe1, 0x9d, 0x58, 0x76, 0xd4, 0x9c, 0xba, 0x2c, 0x84, 0xc6, 0x83, 0x7a,
401 0x22, 0x0d, 0x03, 0x69, 0x32, 0x1a, 0x6d, 0xcb, 0x0c, 0x15, 0xb3, 0x6b, 0xc7,
402 0x0a, 0x8c, 0xb4, 0x5c, 0x34, 0x78, 0xe0, 0x3c, 0x9c, 0xe9, 0xf3, 0x30, 0x9f,
403 0xa8, 0x76, 0x57, 0x92, 0x36 };
404 static const BYTE selfSignedSignatureHash[] = { 0x07,0x5a,0x3e,0xfd,0x0d,0xf6,
405 0x88,0xeb,0x00,0x64,0xbd,0xc9,0xd6,0xea,0x0a,0x7c,0xcc,0x24,0xdb,0x5d };
407 static void testCertProperties(void)
409 PCCERT_CONTEXT context = CertCreateCertificateContext(X509_ASN_ENCODING,
410 bigCert, sizeof(bigCert));
411 DWORD propID, numProps, access, size;
412 BOOL ret;
413 BYTE hash[20] = { 0 }, hashProperty[20];
414 CRYPT_DATA_BLOB blob;
415 CERT_KEY_CONTEXT keyContext;
417 ok(context != NULL || broken(GetLastError() == OSS_DATA_ERROR /* win98 */),
418 "CertCreateCertificateContext failed: %08x\n", GetLastError());
419 if (!context)
420 return;
422 /* This crashes
423 propID = CertEnumCertificateContextProperties(NULL, 0);
426 propID = 0;
427 numProps = 0;
428 do {
429 propID = CertEnumCertificateContextProperties(context, propID);
430 if (propID)
431 numProps++;
432 } while (propID != 0);
433 ok(numProps == 0, "Expected 0 properties, got %d\n", numProps);
435 /* Tests with a NULL cert context. Prop ID 0 fails.. */
436 ret = CertSetCertificateContextProperty(NULL, 0, 0, NULL);
437 ok(!ret && GetLastError() == E_INVALIDARG,
438 "Expected E_INVALIDARG, got %08x\n", GetLastError());
439 /* while this just crashes.
440 ret = CertSetCertificateContextProperty(NULL,
441 CERT_KEY_PROV_HANDLE_PROP_ID, 0, NULL);
444 ret = CertSetCertificateContextProperty(context, 0, 0, NULL);
445 ok(!ret && GetLastError() == E_INVALIDARG,
446 "Expected E_INVALIDARG, got %08x\n", GetLastError());
447 /* Can't set the cert property directly, this crashes.
448 ret = CertSetCertificateContextProperty(context,
449 CERT_CERT_PROP_ID, 0, bigCert2);
452 /* These all crash.
453 ret = CertGetCertificateContextProperty(context,
454 CERT_ACCESS_STATE_PROP_ID, 0, NULL);
455 ret = CertGetCertificateContextProperty(context, CERT_HASH_PROP_ID,
456 NULL, NULL);
457 ret = CertGetCertificateContextProperty(context, CERT_HASH_PROP_ID,
458 hashProperty, NULL);
460 /* A missing prop */
461 size = 0;
462 ret = CertGetCertificateContextProperty(context,
463 CERT_KEY_PROV_INFO_PROP_ID, NULL, &size);
464 ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
465 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
466 /* And, an implicit property */
467 size = sizeof(access);
468 ret = CertGetCertificateContextProperty(context,
469 CERT_ACCESS_STATE_PROP_ID, &access, &size);
470 ok(ret, "CertGetCertificateContextProperty failed: %08x\n",
471 GetLastError());
472 ok(!(access & CERT_ACCESS_STATE_WRITE_PERSIST_FLAG),
473 "Didn't expect a persisted cert\n");
474 /* Trying to set this "read only" property crashes.
475 access |= CERT_ACCESS_STATE_WRITE_PERSIST_FLAG;
476 ret = CertSetCertificateContextProperty(context,
477 CERT_ACCESS_STATE_PROP_ID, 0, &access);
480 /* Can I set the hash to an invalid hash? */
481 blob.pbData = hash;
482 blob.cbData = sizeof(hash);
483 ret = CertSetCertificateContextProperty(context, CERT_HASH_PROP_ID, 0,
484 &blob);
485 ok(ret, "CertSetCertificateContextProperty failed: %08x\n",
486 GetLastError());
487 size = sizeof(hashProperty);
488 ret = CertGetCertificateContextProperty(context, CERT_HASH_PROP_ID,
489 hashProperty, &size);
490 ok(!memcmp(hashProperty, hash, sizeof(hash)), "Unexpected hash\n");
491 /* Delete the (bogus) hash, and get the real one */
492 ret = CertSetCertificateContextProperty(context, CERT_HASH_PROP_ID, 0,
493 NULL);
494 ok(ret, "CertSetCertificateContextProperty failed: %08x\n",
495 GetLastError());
496 checkHash(bigCert, sizeof(bigCert), CALG_SHA1, context,
497 CERT_HASH_PROP_ID);
499 /* Now that the hash property is set, we should get one property when
500 * enumerating.
502 propID = 0;
503 numProps = 0;
504 do {
505 propID = CertEnumCertificateContextProperties(context, propID);
506 if (propID)
507 numProps++;
508 } while (propID != 0);
509 ok(numProps == 1, "Expected 1 properties, got %d\n", numProps);
511 /* Check a few other implicit properties */
512 checkHash(bigCert, sizeof(bigCert), CALG_MD5, context,
513 CERT_MD5_HASH_PROP_ID);
515 /* Getting the signature hash fails with this bogus certificate */
516 size = 0;
517 ret = CertGetCertificateContextProperty(context,
518 CERT_SIGNATURE_HASH_PROP_ID, NULL, &size);
519 ok(!ret &&
520 (GetLastError() == CRYPT_E_ASN1_BADTAG ||
521 GetLastError() == CRYPT_E_NOT_FOUND ||
522 GetLastError() == OSS_DATA_ERROR), /* win9x */
523 "Expected CRYPT_E_ASN1_BADTAG, got %08x\n", GetLastError());
525 /* Test key contexts and handles and such */
526 size = 0;
527 ret = CertGetCertificateContextProperty(context, CERT_KEY_CONTEXT_PROP_ID,
528 NULL, &size);
529 ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
530 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
531 size = sizeof(CERT_KEY_CONTEXT);
532 ret = CertGetCertificateContextProperty(context, CERT_KEY_CONTEXT_PROP_ID,
533 NULL, &size);
534 ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
535 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
536 ret = CertGetCertificateContextProperty(context, CERT_KEY_CONTEXT_PROP_ID,
537 &keyContext, &size);
538 ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
539 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
540 /* Key context with an invalid size */
541 keyContext.cbSize = 0;
542 ret = CertSetCertificateContextProperty(context, CERT_KEY_CONTEXT_PROP_ID,
543 0, &keyContext);
544 ok(!ret && GetLastError() == E_INVALIDARG,
545 "Expected E_INVALIDARG, got %08x\n", GetLastError());
546 size = sizeof(keyContext);
547 ret = CertGetCertificateContextProperty(context, CERT_KEY_CONTEXT_PROP_ID,
548 &keyContext, &size);
549 ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
550 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
551 keyContext.cbSize = sizeof(keyContext);
552 keyContext.hCryptProv = 0;
553 keyContext.dwKeySpec = AT_SIGNATURE;
554 ret = CertSetCertificateContextProperty(context, CERT_KEY_CONTEXT_PROP_ID,
555 0, &keyContext);
556 ok(ret, "CertSetCertificateContextProperty failed: %08x\n", GetLastError());
557 /* Now that that's set, the key prov handle property is also gettable.
559 size = sizeof(keyContext.hCryptProv);
560 ret = CertGetCertificateContextProperty(context,
561 CERT_KEY_PROV_HANDLE_PROP_ID, &keyContext.hCryptProv, &size);
562 ok(ret, "Expected to get the CERT_KEY_PROV_HANDLE_PROP_ID, got %08x\n",
563 GetLastError());
564 /* Remove the key prov handle property.. */
565 ret = CertSetCertificateContextProperty(context,
566 CERT_KEY_PROV_HANDLE_PROP_ID, 0, NULL);
567 ok(ret, "CertSetCertificateContextProperty failed: %08x\n",
568 GetLastError());
569 /* and the key context's CSP is set to NULL. */
570 size = sizeof(keyContext);
571 ret = CertGetCertificateContextProperty(context,
572 CERT_KEY_CONTEXT_PROP_ID, &keyContext, &size);
573 ok(ret, "CertGetCertificateContextProperty failed: %08x\n",
574 GetLastError());
575 ok(keyContext.hCryptProv == 0, "Expected no hCryptProv\n");
577 /* According to MSDN the subject key id can be stored as a property,
578 * as a subject key extension, or as the SHA1 hash of the public key,
579 * but this cert has none of them:
581 ret = CertGetCertificateContextProperty(context,
582 CERT_KEY_IDENTIFIER_PROP_ID, NULL, &size);
583 ok(!ret && GetLastError() == ERROR_INVALID_DATA,
584 "Expected ERROR_INVALID_DATA, got %08x\n", GetLastError());
585 CertFreeCertificateContext(context);
586 /* This cert does have a public key, but its subject key identifier still
587 * isn't available: */
588 context = CertCreateCertificateContext(X509_ASN_ENCODING,
589 v1CertWithPubKey, sizeof(v1CertWithPubKey));
590 ret = CertGetCertificateContextProperty(context,
591 CERT_KEY_IDENTIFIER_PROP_ID, NULL, &size);
592 ok(!ret && GetLastError() == ERROR_INVALID_DATA,
593 "Expected ERROR_INVALID_DATA, got %08x\n", GetLastError());
594 CertFreeCertificateContext(context);
595 /* This cert with a subject key extension can have its key identifier
596 * property retrieved:
598 context = CertCreateCertificateContext(X509_ASN_ENCODING,
599 v1CertWithSubjectKeyId, sizeof(v1CertWithSubjectKeyId));
600 ret = CertGetCertificateContextProperty(context,
601 CERT_KEY_IDENTIFIER_PROP_ID, NULL, &size);
602 ok(ret, "CertGetCertificateContextProperty failed: %08x\n", GetLastError());
603 if (ret)
605 LPBYTE buf = HeapAlloc(GetProcessHeap(), 0, size);
607 if (buf)
609 ret = CertGetCertificateContextProperty(context,
610 CERT_KEY_IDENTIFIER_PROP_ID, buf, &size);
611 ok(ret, "CertGetCertificateContextProperty failed: %08x\n",
612 GetLastError());
613 ok(!memcmp(buf, subjectKeyId, size), "Unexpected subject key id\n");
614 HeapFree(GetProcessHeap(), 0, buf);
617 CertFreeCertificateContext(context);
619 context = CertCreateCertificateContext(X509_ASN_ENCODING,
620 selfSignedCert, sizeof(selfSignedCert));
621 /* Getting the signature hash of a valid (self-signed) cert succeeds */
622 size = 0;
623 ret = CertGetCertificateContextProperty(context,
624 CERT_SIGNATURE_HASH_PROP_ID, NULL, &size);
625 ok(ret, "CertGetCertificateContextProperty failed: %08x\n", GetLastError());
626 ok(size == sizeof(selfSignedSignatureHash), "unexpected size %d\n", size);
627 ret = CertGetCertificateContextProperty(context,
628 CERT_SIGNATURE_HASH_PROP_ID, hashProperty, &size);
629 if (ret)
630 ok(!memcmp(hashProperty, selfSignedSignatureHash, size),
631 "unexpected value\n");
632 CertFreeCertificateContext(context);
635 static void testDupCert(void)
637 HCERTSTORE store;
638 PCCERT_CONTEXT context, dupContext;
639 BOOL ret;
641 store = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0,
642 CERT_STORE_CREATE_NEW_FLAG, NULL);
643 ok(store != NULL, "CertOpenStore failed: %d\n", GetLastError());
644 if (!store)
645 return;
647 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
648 bigCert, sizeof(bigCert), CERT_STORE_ADD_ALWAYS, &context);
649 ok(ret || broken(GetLastError() == OSS_DATA_ERROR /* win98 */),
650 "CertAddEncodedCertificateToStore failed: %08x\n", GetLastError());
651 if (!ret && GetLastError() == OSS_DATA_ERROR)
653 skip("bigCert can't be decoded, skipping tests\n");
654 return;
656 ok(context != NULL, "Expected a valid cert context\n");
657 if (context)
659 ok(context->cbCertEncoded == sizeof(bigCert),
660 "Wrong cert size %d\n", context->cbCertEncoded);
661 ok(!memcmp(context->pbCertEncoded, bigCert, sizeof(bigCert)),
662 "Unexpected encoded cert in context\n");
663 ok(context->hCertStore == store, "Unexpected store\n");
665 dupContext = CertDuplicateCertificateContext(context);
666 ok(dupContext != NULL, "Expected valid duplicate\n");
667 /* Not only is it a duplicate, it's identical: the address is the
668 * same.
670 ok(dupContext == context, "Expected identical context addresses\n");
671 CertFreeCertificateContext(dupContext);
672 CertFreeCertificateContext(context);
674 CertCloseStore(store, 0);
676 SetLastError(0xdeadbeef);
677 context = CertDuplicateCertificateContext(NULL);
678 ok(context == NULL, "Expected context to be NULL\n");
681 static BYTE subjectName3[] = { 0x30, 0x15, 0x31, 0x13, 0x30, 0x11, 0x06,
682 0x03, 0x55, 0x04, 0x03, 0x13, 0x0a, 0x52, 0x6f, 0x62, 0x20, 0x20, 0x4c, 0x61,
683 0x6e, 0x67, 0x00 };
684 static const BYTE iTunesCert0[] = {
685 0x30,0x82,0x03,0xc4,0x30,0x82,0x03,0x2d,0xa0,0x03,0x02,0x01,0x02,0x02,0x10,
686 0x47,0xbf,0x19,0x95,0xdf,0x8d,0x52,0x46,0x43,0xf7,0xdb,0x6d,0x48,0x0d,0x31,
687 0xa4,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x05,0x05,
688 0x00,0x30,0x81,0x8b,0x31,0x0b,0x30,0x09,0x06,0x03,0x55,0x04,0x06,0x13,0x02,
689 0x5a,0x41,0x31,0x15,0x30,0x13,0x06,0x03,0x55,0x04,0x08,0x13,0x0c,0x57,0x65,
690 0x73,0x74,0x65,0x72,0x6e,0x20,0x43,0x61,0x70,0x65,0x31,0x14,0x30,0x12,0x06,
691 0x03,0x55,0x04,0x07,0x13,0x0b,0x44,0x75,0x72,0x62,0x61,0x6e,0x76,0x69,0x6c,
692 0x6c,0x65,0x31,0x0f,0x30,0x0d,0x06,0x03,0x55,0x04,0x0a,0x13,0x06,0x54,0x68,
693 0x61,0x77,0x74,0x65,0x31,0x1d,0x30,0x1b,0x06,0x03,0x55,0x04,0x0b,0x13,0x14,
694 0x54,0x68,0x61,0x77,0x74,0x65,0x20,0x43,0x65,0x72,0x74,0x69,0x66,0x69,0x63,
695 0x61,0x74,0x69,0x6f,0x6e,0x31,0x1f,0x30,0x1d,0x06,0x03,0x55,0x04,0x03,0x13,
696 0x16,0x54,0x68,0x61,0x77,0x74,0x65,0x20,0x54,0x69,0x6d,0x65,0x73,0x74,0x61,
697 0x6d,0x70,0x69,0x6e,0x67,0x20,0x43,0x41,0x30,0x1e,0x17,0x0d,0x30,0x33,0x31,
698 0x32,0x30,0x34,0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x17,0x0d,0x31,0x33,0x31,
699 0x32,0x30,0x33,0x32,0x33,0x35,0x39,0x35,0x39,0x5a,0x30,0x53,0x31,0x0b,0x30,
700 0x09,0x06,0x03,0x55,0x04,0x06,0x13,0x02,0x55,0x53,0x31,0x17,0x30,0x15,0x06,
701 0x03,0x55,0x04,0x0a,0x13,0x0e,0x56,0x65,0x72,0x69,0x53,0x69,0x67,0x6e,0x2c,
702 0x20,0x49,0x6e,0x63,0x2e,0x31,0x2b,0x30,0x29,0x06,0x03,0x55,0x04,0x03,0x13,
703 0x22,0x56,0x65,0x72,0x69,0x53,0x69,0x67,0x6e,0x20,0x54,0x69,0x6d,0x65,0x20,
704 0x53,0x74,0x61,0x6d,0x70,0x69,0x6e,0x67,0x20,0x53,0x65,0x72,0x76,0x69,0x63,
705 0x65,0x73,0x20,0x43,0x41,0x30,0x82,0x01,0x22,0x30,0x0d,0x06,0x09,0x2a,0x86,
706 0x48,0x86,0xf7,0x0d,0x01,0x01,0x01,0x05,0x00,0x03,0x82,0x01,0x0f,0x00,0x30,
707 0x82,0x01,0x0a,0x02,0x82,0x01,0x01,0x00,0xa9,0xca,0xb2,0xa4,0xcc,0xcd,0x20,
708 0xaf,0x0a,0x7d,0x89,0xac,0x87,0x75,0xf0,0xb4,0x4e,0xf1,0xdf,0xc1,0x0f,0xbf,
709 0x67,0x61,0xbd,0xa3,0x64,0x1c,0xda,0xbb,0xf9,0xca,0x33,0xab,0x84,0x30,0x89,
710 0x58,0x7e,0x8c,0xdb,0x6b,0xdd,0x36,0x9e,0x0f,0xbf,0xd1,0xec,0x78,0xf2,0x77,
711 0xa6,0x7e,0x6f,0x3c,0xbf,0x93,0xaf,0x0d,0xba,0x68,0xf4,0x6c,0x94,0xca,0xbd,
712 0x52,0x2d,0xab,0x48,0x3d,0xf5,0xb6,0xd5,0x5d,0x5f,0x1b,0x02,0x9f,0xfa,0x2f,
713 0x6b,0x1e,0xa4,0xf7,0xa3,0x9a,0xa6,0x1a,0xc8,0x02,0xe1,0x7f,0x4c,0x52,0xe3,
714 0x0e,0x60,0xec,0x40,0x1c,0x7e,0xb9,0x0d,0xde,0x3f,0xc7,0xb4,0xdf,0x87,0xbd,
715 0x5f,0x7a,0x6a,0x31,0x2e,0x03,0x99,0x81,0x13,0xa8,0x47,0x20,0xce,0x31,0x73,
716 0x0d,0x57,0x2d,0xcd,0x78,0x34,0x33,0x95,0x12,0x99,0x12,0xb9,0xde,0x68,0x2f,
717 0xaa,0xe6,0xe3,0xc2,0x8a,0x8c,0x2a,0xc3,0x8b,0x21,0x87,0x66,0xbd,0x83,0x58,
718 0x57,0x6f,0x75,0xbf,0x3c,0xaa,0x26,0x87,0x5d,0xca,0x10,0x15,0x3c,0x9f,0x84,
719 0xea,0x54,0xc1,0x0a,0x6e,0xc4,0xfe,0xc5,0x4a,0xdd,0xb9,0x07,0x11,0x97,0x22,
720 0x7c,0xdb,0x3e,0x27,0xd1,0x1e,0x78,0xec,0x9f,0x31,0xc9,0xf1,0xe6,0x22,0x19,
721 0xdb,0xc4,0xb3,0x47,0x43,0x9a,0x1a,0x5f,0xa0,0x1e,0x90,0xe4,0x5e,0xf5,0xee,
722 0x7c,0xf1,0x7d,0xab,0x62,0x01,0x8f,0xf5,0x4d,0x0b,0xde,0xd0,0x22,0x56,0xa8,
723 0x95,0xcd,0xae,0x88,0x76,0xae,0xee,0xba,0x0d,0xf3,0xe4,0x4d,0xd9,0xa0,0xfb,
724 0x68,0xa0,0xae,0x14,0x3b,0xb3,0x87,0xc1,0xbb,0x02,0x03,0x01,0x00,0x01,0xa3,
725 0x81,0xdb,0x30,0x81,0xd8,0x30,0x34,0x06,0x08,0x2b,0x06,0x01,0x05,0x05,0x07,
726 0x01,0x01,0x04,0x28,0x30,0x26,0x30,0x24,0x06,0x08,0x2b,0x06,0x01,0x05,0x05,
727 0x07,0x30,0x01,0x86,0x18,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x6f,0x63,0x73,
728 0x70,0x2e,0x76,0x65,0x72,0x69,0x73,0x69,0x67,0x6e,0x2e,0x63,0x6f,0x6d,0x30,
729 0x12,0x06,0x03,0x55,0x1d,0x13,0x01,0x01,0xff,0x04,0x08,0x30,0x06,0x01,0x01,
730 0xff,0x02,0x01,0x00,0x30,0x41,0x06,0x03,0x55,0x1d,0x1f,0x04,0x3a,0x30,0x38,
731 0x30,0x36,0xa0,0x34,0xa0,0x32,0x86,0x30,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,
732 0x63,0x72,0x6c,0x2e,0x76,0x65,0x72,0x69,0x73,0x69,0x67,0x6e,0x2e,0x63,0x6f,
733 0x6d,0x2f,0x54,0x68,0x61,0x77,0x74,0x65,0x54,0x69,0x6d,0x65,0x73,0x74,0x61,
734 0x6d,0x70,0x69,0x6e,0x67,0x43,0x41,0x2e,0x63,0x72,0x6c,0x30,0x13,0x06,0x03,
735 0x55,0x1d,0x25,0x04,0x0c,0x30,0x0a,0x06,0x08,0x2b,0x06,0x01,0x05,0x05,0x07,
736 0x03,0x08,0x30,0x0e,0x06,0x03,0x55,0x1d,0x0f,0x01,0x01,0xff,0x04,0x04,0x03,
737 0x02,0x01,0x06,0x30,0x24,0x06,0x03,0x55,0x1d,0x11,0x04,0x1d,0x30,0x1b,0xa4,
738 0x19,0x30,0x17,0x31,0x15,0x30,0x13,0x06,0x03,0x55,0x04,0x03,0x13,0x0c,0x54,
739 0x53,0x41,0x32,0x30,0x34,0x38,0x2d,0x31,0x2d,0x35,0x33,0x30,0x0d,0x06,0x09,
740 0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x05,0x05,0x00,0x03,0x81,0x81,0x00,
741 0x4a,0x6b,0xf9,0xea,0x58,0xc2,0x44,0x1c,0x31,0x89,0x79,0x99,0x2b,0x96,0xbf,
742 0x82,0xac,0x01,0xd6,0x1c,0x4c,0xcd,0xb0,0x8a,0x58,0x6e,0xdf,0x08,0x29,0xa3,
743 0x5e,0xc8,0xca,0x93,0x13,0xe7,0x04,0x52,0x0d,0xef,0x47,0x27,0x2f,0x00,0x38,
744 0xb0,0xe4,0xc9,0x93,0x4e,0x9a,0xd4,0x22,0x62,0x15,0xf7,0x3f,0x37,0x21,0x4f,
745 0x70,0x31,0x80,0xf1,0x8b,0x38,0x87,0xb3,0xe8,0xe8,0x97,0x00,0xfe,0xcf,0x55,
746 0x96,0x4e,0x24,0xd2,0xa9,0x27,0x4e,0x7a,0xae,0xb7,0x61,0x41,0xf3,0x2a,0xce,
747 0xe7,0xc9,0xd9,0x5e,0xdd,0xbb,0x2b,0x85,0x3e,0xb5,0x9d,0xb5,0xd9,0xe1,0x57,
748 0xff,0xbe,0xb4,0xc5,0x7e,0xf5,0xcf,0x0c,0x9e,0xf0,0x97,0xfe,0x2b,0xd3,0x3b,
749 0x52,0x1b,0x1b,0x38,0x27,0xf7,0x3f,0x4a };
750 static const BYTE iTunesCert1[] = {
751 0x30,0x82,0x03,0xff,0x30,0x82,0x02,0xe7,0xa0,0x03,0x02,0x01,0x02,0x02,0x10,
752 0x0d,0xe9,0x2b,0xf0,0xd4,0xd8,0x29,0x88,0x18,0x32,0x05,0x09,0x5e,0x9a,0x76,
753 0x88,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x05,0x05,
754 0x00,0x30,0x53,0x31,0x0b,0x30,0x09,0x06,0x03,0x55,0x04,0x06,0x13,0x02,0x55,
755 0x53,0x31,0x17,0x30,0x15,0x06,0x03,0x55,0x04,0x0a,0x13,0x0e,0x56,0x65,0x72,
756 0x69,0x53,0x69,0x67,0x6e,0x2c,0x20,0x49,0x6e,0x63,0x2e,0x31,0x2b,0x30,0x29,
757 0x06,0x03,0x55,0x04,0x03,0x13,0x22,0x56,0x65,0x72,0x69,0x53,0x69,0x67,0x6e,
758 0x20,0x54,0x69,0x6d,0x65,0x20,0x53,0x74,0x61,0x6d,0x70,0x69,0x6e,0x67,0x20,
759 0x53,0x65,0x72,0x76,0x69,0x63,0x65,0x73,0x20,0x43,0x41,0x30,0x1e,0x17,0x0d,
760 0x30,0x33,0x31,0x32,0x30,0x34,0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x17,0x0d,
761 0x30,0x38,0x31,0x32,0x30,0x33,0x32,0x33,0x35,0x39,0x35,0x39,0x5a,0x30,0x57,
762 0x31,0x0b,0x30,0x09,0x06,0x03,0x55,0x04,0x06,0x13,0x02,0x55,0x53,0x31,0x17,
763 0x30,0x15,0x06,0x03,0x55,0x04,0x0a,0x13,0x0e,0x56,0x65,0x72,0x69,0x53,0x69,
764 0x67,0x6e,0x2c,0x20,0x49,0x6e,0x63,0x2e,0x31,0x2f,0x30,0x2d,0x06,0x03,0x55,
765 0x04,0x03,0x13,0x26,0x56,0x65,0x72,0x69,0x53,0x69,0x67,0x6e,0x20,0x54,0x69,
766 0x6d,0x65,0x20,0x53,0x74,0x61,0x6d,0x70,0x69,0x6e,0x67,0x20,0x53,0x65,0x72,
767 0x76,0x69,0x63,0x65,0x73,0x20,0x53,0x69,0x67,0x6e,0x65,0x72,0x30,0x82,0x01,
768 0x22,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x01,0x05,
769 0x00,0x03,0x82,0x01,0x0f,0x00,0x30,0x82,0x01,0x0a,0x02,0x82,0x01,0x01,0x00,
770 0xb2,0x50,0x28,0x48,0xdd,0xd3,0x68,0x7a,0x84,0x18,0x44,0x66,0x75,0x5d,0x7e,
771 0xc4,0xb8,0x9f,0x63,0x26,0xff,0x3d,0x43,0x9c,0x7c,0x11,0x38,0x10,0x25,0x55,
772 0x73,0xd9,0x75,0x27,0x69,0xfd,0x4e,0xb9,0x20,0x5c,0xd3,0x0a,0xf9,0xa0,0x1b,
773 0x2a,0xed,0x55,0x56,0x21,0x61,0xd8,0x1e,0xdb,0xe4,0xbc,0x33,0x6b,0xc7,0xef,
774 0xdd,0xa3,0x37,0x65,0x8e,0x1b,0x93,0x0c,0xb6,0x53,0x1e,0x5c,0x7c,0x66,0x35,
775 0x5f,0x05,0x8a,0x45,0xfe,0x76,0x4e,0xdf,0x53,0x80,0xa2,0x81,0x20,0x9d,0xae,
776 0x88,0x5c,0xa2,0x08,0xf7,0xe5,0x30,0xf9,0xee,0x22,0x37,0x4c,0x42,0x0a,0xce,
777 0xdf,0xc6,0x1f,0xc4,0xd6,0x55,0xe9,0x81,0x3f,0xb5,0x52,0xa3,0x2c,0xaa,0x01,
778 0x7a,0xf2,0xa2,0xaa,0x8d,0x35,0xfe,0x9f,0xe6,0x5d,0x6a,0x05,0x9f,0x3d,0x6b,
779 0xe3,0xbf,0x96,0xc0,0xfe,0xcc,0x60,0xf9,0x40,0xe7,0x07,0xa0,0x44,0xeb,0x81,
780 0x51,0x6e,0xa5,0x2a,0xf2,0xb6,0x8a,0x10,0x28,0xed,0x8f,0xdc,0x06,0xa0,0x86,
781 0x50,0x9a,0x7b,0x4a,0x08,0x0d,0x30,0x1d,0xca,0x10,0x9e,0x6b,0xf7,0xe9,0x58,
782 0xae,0x04,0xa9,0x40,0x99,0xb2,0x28,0xe8,0x8f,0x16,0xac,0x3c,0xe3,0x53,0x6f,
783 0x4b,0xd3,0x35,0x9d,0xb5,0x6f,0x64,0x1d,0xb3,0x96,0x2c,0xbb,0x3d,0xe7,0x79,
784 0xeb,0x6d,0x7a,0xf9,0x16,0xe6,0x26,0xad,0xaf,0xef,0x99,0x53,0xb7,0x40,0x2c,
785 0x95,0xb8,0x79,0xaa,0xfe,0xd4,0x52,0xab,0x29,0x74,0x7e,0x42,0xec,0x39,0x1e,
786 0xa2,0x6a,0x16,0xe6,0x59,0xbb,0x24,0x68,0xd8,0x00,0x80,0x43,0x10,0x87,0x80,
787 0x6b,0x02,0x03,0x01,0x00,0x01,0xa3,0x81,0xca,0x30,0x81,0xc7,0x30,0x34,0x06,
788 0x08,0x2b,0x06,0x01,0x05,0x05,0x07,0x01,0x01,0x04,0x28,0x30,0x26,0x30,0x24,
789 0x06,0x08,0x2b,0x06,0x01,0x05,0x05,0x07,0x30,0x01,0x86,0x18,0x68,0x74,0x74,
790 0x70,0x3a,0x2f,0x2f,0x6f,0x63,0x73,0x70,0x2e,0x76,0x65,0x72,0x69,0x73,0x69,
791 0x67,0x6e,0x2e,0x63,0x6f,0x6d,0x30,0x0c,0x06,0x03,0x55,0x1d,0x13,0x01,0x01,
792 0xff,0x04,0x02,0x30,0x00,0x30,0x33,0x06,0x03,0x55,0x1d,0x1f,0x04,0x2c,0x30,
793 0x2a,0x30,0x28,0xa0,0x26,0xa0,0x24,0x86,0x22,0x68,0x74,0x74,0x70,0x3a,0x2f,
794 0x2f,0x63,0x72,0x6c,0x2e,0x76,0x65,0x72,0x69,0x73,0x69,0x67,0x6e,0x2e,0x63,
795 0x6f,0x6d,0x2f,0x74,0x73,0x73,0x2d,0x63,0x61,0x2e,0x63,0x72,0x6c,0x30,0x16,
796 0x06,0x03,0x55,0x1d,0x25,0x01,0x01,0xff,0x04,0x0c,0x30,0x0a,0x06,0x08,0x2b,
797 0x06,0x01,0x05,0x05,0x07,0x03,0x08,0x30,0x0e,0x06,0x03,0x55,0x1d,0x0f,0x01,
798 0x01,0xff,0x04,0x04,0x03,0x02,0x06,0xc0,0x30,0x24,0x06,0x03,0x55,0x1d,0x11,
799 0x04,0x1d,0x30,0x1b,0xa4,0x19,0x30,0x17,0x31,0x15,0x30,0x13,0x06,0x03,0x55,
800 0x04,0x03,0x13,0x0c,0x54,0x53,0x41,0x32,0x30,0x34,0x38,0x2d,0x31,0x2d,0x35,
801 0x34,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x05,0x05,
802 0x00,0x03,0x82,0x01,0x01,0x00,0x87,0x78,0x70,0xda,0x4e,0x52,0x01,0x20,0x5b,
803 0xe0,0x79,0xc9,0x82,0x30,0xc4,0xfd,0xb9,0x19,0x96,0xbd,0x91,0x00,0xc3,0xbd,
804 0xcd,0xcd,0xc6,0xf4,0x0e,0xd8,0xff,0xf9,0x4d,0xc0,0x33,0x62,0x30,0x11,0xc5,
805 0xf5,0x74,0x1b,0xd4,0x92,0xde,0x5f,0x9c,0x20,0x13,0xb1,0x7c,0x45,0xbe,0x50,
806 0xcd,0x83,0xe7,0x80,0x17,0x83,0xa7,0x27,0x93,0x67,0x13,0x46,0xfb,0xca,0xb8,
807 0x98,0x41,0x03,0xcc,0x9b,0x51,0x5b,0x05,0x8b,0x7f,0xa8,0x6f,0xf3,0x1b,0x50,
808 0x1b,0x24,0x2e,0xf2,0x69,0x8d,0x6c,0x22,0xf7,0xbb,0xca,0x16,0x95,0xed,0x0c,
809 0x74,0xc0,0x68,0x77,0xd9,0xeb,0x99,0x62,0x87,0xc1,0x73,0x90,0xf8,0x89,0x74,
810 0x7a,0x23,0xab,0xa3,0x98,0x7b,0x97,0xb1,0xf7,0x8f,0x29,0x71,0x4d,0x2e,0x75,
811 0x1b,0x48,0x41,0xda,0xf0,0xb5,0x0d,0x20,0x54,0xd6,0x77,0xa0,0x97,0x82,0x63,
812 0x69,0xfd,0x09,0xcf,0x8a,0xf0,0x75,0xbb,0x09,0x9b,0xd9,0xf9,0x11,0x55,0x26,
813 0x9a,0x61,0x32,0xbe,0x7a,0x02,0xb0,0x7b,0x86,0xbe,0xa2,0xc3,0x8b,0x22,0x2c,
814 0x78,0xd1,0x35,0x76,0xbc,0x92,0x73,0x5c,0xf9,0xb9,0xe6,0x4c,0x15,0x0a,0x23,
815 0xcc,0xe4,0xd2,0xd4,0x34,0x2e,0x49,0x40,0x15,0x3c,0x0f,0x60,0x7a,0x24,0xc6,
816 0xa5,0x66,0xef,0x96,0xcf,0x70,0xeb,0x3e,0xe7,0xf4,0x0d,0x7e,0xdc,0xd1,0x7c,
817 0xa3,0x76,0x71,0x69,0xc1,0x9c,0x4f,0x47,0x30,0x35,0x21,0xb1,0xa2,0xaf,0x1a,
818 0x62,0x3c,0x2b,0xd9,0x8e,0xaa,0x2a,0x07,0x7b,0xd8,0x18,0xb3,0x5c,0x7b,0xe2,
819 0x9d,0xa5,0x6f,0xfe,0x3c,0x89,0xad };
820 static const BYTE iTunesCert2[] = {
821 0x30,0x82,0x04,0xbf,0x30,0x82,0x04,0x28,0xa0,0x03,0x02,0x01,0x02,0x02,0x10,
822 0x41,0x91,0xa1,0x5a,0x39,0x78,0xdf,0xcf,0x49,0x65,0x66,0x38,0x1d,0x4c,0x75,
823 0xc2,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x05,0x05,
824 0x00,0x30,0x5f,0x31,0x0b,0x30,0x09,0x06,0x03,0x55,0x04,0x06,0x13,0x02,0x55,
825 0x53,0x31,0x17,0x30,0x15,0x06,0x03,0x55,0x04,0x0a,0x13,0x0e,0x56,0x65,0x72,
826 0x69,0x53,0x69,0x67,0x6e,0x2c,0x20,0x49,0x6e,0x63,0x2e,0x31,0x37,0x30,0x35,
827 0x06,0x03,0x55,0x04,0x0b,0x13,0x2e,0x43,0x6c,0x61,0x73,0x73,0x20,0x33,0x20,
828 0x50,0x75,0x62,0x6c,0x69,0x63,0x20,0x50,0x72,0x69,0x6d,0x61,0x72,0x79,0x20,
829 0x43,0x65,0x72,0x74,0x69,0x66,0x69,0x63,0x61,0x74,0x69,0x6f,0x6e,0x20,0x41,
830 0x75,0x74,0x68,0x6f,0x72,0x69,0x74,0x79,0x30,0x1e,0x17,0x0d,0x30,0x34,0x30,
831 0x37,0x31,0x36,0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x17,0x0d,0x31,0x34,0x30,
832 0x37,0x31,0x35,0x32,0x33,0x35,0x39,0x35,0x39,0x5a,0x30,0x81,0xb4,0x31,0x0b,
833 0x30,0x09,0x06,0x03,0x55,0x04,0x06,0x13,0x02,0x55,0x53,0x31,0x17,0x30,0x15,
834 0x06,0x03,0x55,0x04,0x0a,0x13,0x0e,0x56,0x65,0x72,0x69,0x53,0x69,0x67,0x6e,
835 0x2c,0x20,0x49,0x6e,0x63,0x2e,0x31,0x1f,0x30,0x1d,0x06,0x03,0x55,0x04,0x0b,
836 0x13,0x16,0x56,0x65,0x72,0x69,0x53,0x69,0x67,0x6e,0x20,0x54,0x72,0x75,0x73,
837 0x74,0x20,0x4e,0x65,0x74,0x77,0x6f,0x72,0x6b,0x31,0x3b,0x30,0x39,0x06,0x03,
838 0x55,0x04,0x0b,0x13,0x32,0x54,0x65,0x72,0x6d,0x73,0x20,0x6f,0x66,0x20,0x75,
839 0x73,0x65,0x20,0x61,0x74,0x20,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x77,
840 0x77,0x77,0x2e,0x76,0x65,0x72,0x69,0x73,0x69,0x67,0x6e,0x2e,0x63,0x6f,0x6d,
841 0x2f,0x72,0x70,0x61,0x20,0x28,0x63,0x29,0x30,0x34,0x31,0x2e,0x30,0x2c,0x06,
842 0x03,0x55,0x04,0x03,0x13,0x25,0x56,0x65,0x72,0x69,0x53,0x69,0x67,0x6e,0x20,
843 0x43,0x6c,0x61,0x73,0x73,0x20,0x33,0x20,0x43,0x6f,0x64,0x65,0x20,0x53,0x69,
844 0x67,0x6e,0x69,0x6e,0x67,0x20,0x32,0x30,0x30,0x34,0x20,0x43,0x41,0x30,0x82,
845 0x01,0x22,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x01,
846 0x05,0x00,0x03,0x82,0x01,0x0f,0x00,0x30,0x82,0x01,0x0a,0x02,0x82,0x01,0x01,
847 0x00,0xbe,0xbc,0xee,0xbc,0x7e,0xef,0x83,0xeb,0xe0,0x37,0x4f,0xfb,0x03,0x10,
848 0x38,0xbe,0x08,0xd2,0x8c,0x7d,0x9d,0xfa,0x92,0x7f,0x19,0x0c,0xc2,0x6b,0xee,
849 0x42,0x52,0x8c,0xde,0xd3,0x1c,0x48,0x13,0x25,0xea,0xc1,0x63,0x7a,0xf9,0x51,
850 0x65,0xee,0xd3,0xaa,0x3b,0xf5,0xf0,0x94,0x9c,0x2b,0xfb,0xf2,0x66,0xd4,0x24,
851 0xda,0xf7,0xf5,0x9f,0x6e,0x19,0x39,0x36,0xbc,0xd0,0xa3,0x76,0x08,0x1e,0x22,
852 0x27,0x24,0x6c,0x38,0x91,0x27,0xe2,0x84,0x49,0xae,0x1b,0x8a,0xa1,0xfd,0x25,
853 0x82,0x2c,0x10,0x30,0xe8,0x71,0xab,0x28,0xe8,0x77,0x4a,0x51,0xf1,0xec,0xcd,
854 0xf8,0xf0,0x54,0xd4,0x6f,0xc0,0xe3,0x6d,0x0a,0x8f,0xd9,0xd8,0x64,0x8d,0x63,
855 0xb2,0x2d,0x4e,0x27,0xf6,0x85,0x0e,0xfe,0x6d,0xe3,0x29,0x99,0xe2,0x85,0x47,
856 0x7c,0x2d,0x86,0x7f,0xe8,0x57,0x8f,0xad,0x67,0xc2,0x33,0x32,0x91,0x13,0x20,
857 0xfc,0xa9,0x23,0x14,0x9a,0x6d,0xc2,0x84,0x4b,0x76,0x68,0x04,0xd5,0x71,0x2c,
858 0x5d,0x21,0xfa,0x88,0x0d,0x26,0xfd,0x1f,0x2d,0x91,0x2b,0xe7,0x01,0x55,0x4d,
859 0xf2,0x6d,0x35,0x28,0x82,0xdf,0xd9,0x6b,0x5c,0xb6,0xd6,0xd9,0xaa,0x81,0xfd,
860 0x5f,0xcd,0x83,0xba,0x63,0x9d,0xd0,0x22,0xfc,0xa9,0x3b,0x42,0x69,0xb2,0x8e,
861 0x3a,0xb5,0xbc,0xb4,0x9e,0x0f,0x5e,0xc4,0xea,0x2c,0x82,0x8b,0x28,0xfd,0x53,
862 0x08,0x96,0xdd,0xb5,0x01,0x20,0xd1,0xf9,0xa5,0x18,0xe7,0xc0,0xee,0x51,0x70,
863 0x37,0xe1,0xb6,0x05,0x48,0x52,0x48,0x6f,0x38,0xea,0xc3,0xe8,0x6c,0x7b,0x44,
864 0x84,0xbb,0x02,0x03,0x01,0x00,0x01,0xa3,0x82,0x01,0xa0,0x30,0x82,0x01,0x9c,
865 0x30,0x12,0x06,0x03,0x55,0x1d,0x13,0x01,0x01,0xff,0x04,0x08,0x30,0x06,0x01,
866 0x01,0xff,0x02,0x01,0x00,0x30,0x44,0x06,0x03,0x55,0x1d,0x20,0x04,0x3d,0x30,
867 0x3b,0x30,0x39,0x06,0x0b,0x60,0x86,0x48,0x01,0x86,0xf8,0x45,0x01,0x07,0x17,
868 0x03,0x30,0x2a,0x30,0x28,0x06,0x08,0x2b,0x06,0x01,0x05,0x05,0x07,0x02,0x01,
869 0x16,0x1c,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x76,
870 0x65,0x72,0x69,0x73,0x69,0x67,0x6e,0x2e,0x63,0x6f,0x6d,0x2f,0x72,0x70,0x61,
871 0x30,0x31,0x06,0x03,0x55,0x1d,0x1f,0x04,0x2a,0x30,0x28,0x30,0x26,0xa0,0x24,
872 0xa0,0x22,0x86,0x20,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x63,0x72,0x6c,0x2e,
873 0x76,0x65,0x72,0x69,0x73,0x69,0x67,0x6e,0x2e,0x63,0x6f,0x6d,0x2f,0x70,0x63,
874 0x61,0x33,0x2e,0x63,0x72,0x6c,0x30,0x1d,0x06,0x03,0x55,0x1d,0x25,0x04,0x16,
875 0x30,0x14,0x06,0x08,0x2b,0x06,0x01,0x05,0x05,0x07,0x03,0x02,0x06,0x08,0x2b,
876 0x06,0x01,0x05,0x05,0x07,0x03,0x03,0x30,0x0e,0x06,0x03,0x55,0x1d,0x0f,0x01,
877 0x01,0xff,0x04,0x04,0x03,0x02,0x01,0x06,0x30,0x11,0x06,0x09,0x60,0x86,0x48,
878 0x01,0x86,0xf8,0x42,0x01,0x01,0x04,0x04,0x03,0x02,0x00,0x01,0x30,0x29,0x06,
879 0x03,0x55,0x1d,0x11,0x04,0x22,0x30,0x20,0xa4,0x1e,0x30,0x1c,0x31,0x1a,0x30,
880 0x18,0x06,0x03,0x55,0x04,0x03,0x13,0x11,0x43,0x6c,0x61,0x73,0x73,0x33,0x43,
881 0x41,0x32,0x30,0x34,0x38,0x2d,0x31,0x2d,0x34,0x33,0x30,0x1d,0x06,0x03,0x55,
882 0x1d,0x0e,0x04,0x16,0x04,0x14,0x08,0xf5,0x51,0xe8,0xfb,0xfe,0x3d,0x3d,0x64,
883 0x36,0x7c,0x68,0xcf,0x5b,0x78,0xa8,0xdf,0xb9,0xc5,0x37,0x30,0x81,0x80,0x06,
884 0x03,0x55,0x1d,0x23,0x04,0x79,0x30,0x77,0xa1,0x63,0xa4,0x61,0x30,0x5f,0x31,
885 0x0b,0x30,0x09,0x06,0x03,0x55,0x04,0x06,0x13,0x02,0x55,0x53,0x31,0x17,0x30,
886 0x15,0x06,0x03,0x55,0x04,0x0a,0x13,0x0e,0x56,0x65,0x72,0x69,0x53,0x69,0x67,
887 0x6e,0x2c,0x20,0x49,0x6e,0x63,0x2e,0x31,0x37,0x30,0x35,0x06,0x03,0x55,0x04,
888 0x0b,0x13,0x2e,0x43,0x6c,0x61,0x73,0x73,0x20,0x33,0x20,0x50,0x75,0x62,0x6c,
889 0x69,0x63,0x20,0x50,0x72,0x69,0x6d,0x61,0x72,0x79,0x20,0x43,0x65,0x72,0x74,
890 0x69,0x66,0x69,0x63,0x61,0x74,0x69,0x6f,0x6e,0x20,0x41,0x75,0x74,0x68,0x6f,
891 0x72,0x69,0x74,0x79,0x82,0x10,0x70,0xba,0xe4,0x1d,0x10,0xd9,0x29,0x34,0xb6,
892 0x38,0xca,0x7b,0x03,0xcc,0xba,0xbf,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,
893 0xf7,0x0d,0x01,0x01,0x05,0x05,0x00,0x03,0x81,0x81,0x00,0xae,0x3a,0x17,0xb8,
894 0x4a,0x7b,0x55,0xfa,0x64,0x55,0xec,0x40,0xa4,0xed,0x49,0x41,0x90,0x99,0x9c,
895 0x89,0xbc,0xaf,0x2e,0x1d,0xca,0x78,0x23,0xf9,0x1c,0x19,0x0f,0x7f,0xeb,0x68,
896 0xbc,0x32,0xd9,0x88,0x38,0xde,0xdc,0x3f,0xd3,0x89,0xb4,0x3f,0xb1,0x82,0x96,
897 0xf1,0xa4,0x5a,0xba,0xed,0x2e,0x26,0xd3,0xde,0x7c,0x01,0x6e,0x00,0x0a,0x00,
898 0xa4,0x06,0x92,0x11,0x48,0x09,0x40,0xf9,0x1c,0x18,0x79,0x67,0x23,0x24,0xe0,
899 0xbb,0xd5,0xe1,0x50,0xae,0x1b,0xf5,0x0e,0xdd,0xe0,0x2e,0x81,0xcd,0x80,0xa3,
900 0x6c,0x52,0x4f,0x91,0x75,0x55,0x8a,0xba,0x22,0xf2,0xd2,0xea,0x41,0x75,0x88,
901 0x2f,0x63,0x55,0x7d,0x1e,0x54,0x5a,0x95,0x59,0xca,0xd9,0x34,0x81,0xc0,0x5f,
902 0x5e,0xf6,0x7a,0xb5 };
903 static const BYTE iTunesCert3[] = {
904 0x30,0x82,0x04,0xf1,0x30,0x82,0x03,0xd9,0xa0,0x03,0x02,0x01,0x02,0x02,0x10,
905 0x0f,0x1a,0xa0,0xe0,0x9b,0x9b,0x61,0xa6,0xb6,0xfe,0x40,0xd2,0xdf,0x6a,0xf6,
906 0x8d,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x05,0x05,
907 0x00,0x30,0x81,0xb4,0x31,0x0b,0x30,0x09,0x06,0x03,0x55,0x04,0x06,0x13,0x02,
908 0x55,0x53,0x31,0x17,0x30,0x15,0x06,0x03,0x55,0x04,0x0a,0x13,0x0e,0x56,0x65,
909 0x72,0x69,0x53,0x69,0x67,0x6e,0x2c,0x20,0x49,0x6e,0x63,0x2e,0x31,0x1f,0x30,
910 0x1d,0x06,0x03,0x55,0x04,0x0b,0x13,0x16,0x56,0x65,0x72,0x69,0x53,0x69,0x67,
911 0x6e,0x20,0x54,0x72,0x75,0x73,0x74,0x20,0x4e,0x65,0x74,0x77,0x6f,0x72,0x6b,
912 0x31,0x3b,0x30,0x39,0x06,0x03,0x55,0x04,0x0b,0x13,0x32,0x54,0x65,0x72,0x6d,
913 0x73,0x20,0x6f,0x66,0x20,0x75,0x73,0x65,0x20,0x61,0x74,0x20,0x68,0x74,0x74,
914 0x70,0x73,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x76,0x65,0x72,0x69,0x73,0x69,
915 0x67,0x6e,0x2e,0x63,0x6f,0x6d,0x2f,0x72,0x70,0x61,0x20,0x28,0x63,0x29,0x30,
916 0x34,0x31,0x2e,0x30,0x2c,0x06,0x03,0x55,0x04,0x03,0x13,0x25,0x56,0x65,0x72,
917 0x69,0x53,0x69,0x67,0x6e,0x20,0x43,0x6c,0x61,0x73,0x73,0x20,0x33,0x20,0x43,
918 0x6f,0x64,0x65,0x20,0x53,0x69,0x67,0x6e,0x69,0x6e,0x67,0x20,0x32,0x30,0x30,
919 0x34,0x20,0x43,0x41,0x30,0x1e,0x17,0x0d,0x30,0x36,0x30,0x31,0x31,0x37,0x30,
920 0x30,0x30,0x30,0x30,0x30,0x5a,0x17,0x0d,0x30,0x38,0x30,0x31,0x32,0x32,0x32,
921 0x33,0x35,0x39,0x35,0x39,0x5a,0x30,0x81,0xb4,0x31,0x0b,0x30,0x09,0x06,0x03,
922 0x55,0x04,0x06,0x13,0x02,0x55,0x53,0x31,0x13,0x30,0x11,0x06,0x03,0x55,0x04,
923 0x08,0x13,0x0a,0x43,0x61,0x6c,0x69,0x66,0x6f,0x72,0x6e,0x69,0x61,0x31,0x12,
924 0x30,0x10,0x06,0x03,0x55,0x04,0x07,0x13,0x09,0x43,0x75,0x70,0x65,0x72,0x74,
925 0x69,0x6e,0x6f,0x31,0x1d,0x30,0x1b,0x06,0x03,0x55,0x04,0x0a,0x14,0x14,0x41,
926 0x70,0x70,0x6c,0x65,0x20,0x43,0x6f,0x6d,0x70,0x75,0x74,0x65,0x72,0x2c,0x20,
927 0x49,0x6e,0x63,0x2e,0x31,0x3e,0x30,0x3c,0x06,0x03,0x55,0x04,0x0b,0x13,0x35,
928 0x44,0x69,0x67,0x69,0x74,0x61,0x6c,0x20,0x49,0x44,0x20,0x43,0x6c,0x61,0x73,
929 0x73,0x20,0x33,0x20,0x2d,0x20,0x4d,0x69,0x63,0x72,0x6f,0x73,0x6f,0x66,0x74,
930 0x20,0x53,0x6f,0x66,0x74,0x77,0x61,0x72,0x65,0x20,0x56,0x61,0x6c,0x69,0x64,
931 0x61,0x74,0x69,0x6f,0x6e,0x20,0x76,0x32,0x31,0x1d,0x30,0x1b,0x06,0x03,0x55,
932 0x04,0x03,0x14,0x14,0x41,0x70,0x70,0x6c,0x65,0x20,0x43,0x6f,0x6d,0x70,0x75,
933 0x74,0x65,0x72,0x2c,0x20,0x49,0x6e,0x63,0x2e,0x30,0x81,0x9f,0x30,0x0d,0x06,
934 0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x01,0x05,0x00,0x03,0x81,0x8d,
935 0x00,0x30,0x81,0x89,0x02,0x81,0x81,0x00,0xd3,0xab,0x3b,0x7f,0xec,0x48,0x84,
936 0xce,0xa8,0x1a,0x12,0xf3,0x3c,0x87,0xcb,0x24,0x58,0x96,0x02,0x87,0x66,0x49,
937 0xeb,0x89,0xee,0x79,0x44,0x70,0x8d,0xe7,0xd4,0x1f,0x30,0x92,0xc0,0x9c,0x35,
938 0x78,0xc0,0xaf,0x1c,0xb6,0x28,0xd3,0xe0,0xe0,0x9d,0xd3,0x49,0x76,0x73,0x57,
939 0x19,0x4d,0x8d,0x70,0x85,0x64,0x4d,0x1d,0xc6,0x02,0x3e,0xe5,0x2c,0x66,0x07,
940 0xd2,0x27,0x4b,0xd6,0xc8,0x3c,0x93,0xb6,0x15,0x0c,0xde,0x5b,0xd7,0x93,0xdd,
941 0xbe,0x85,0x62,0x34,0x17,0x8a,0x05,0x60,0xf0,0x8a,0x1c,0x5a,0x40,0x21,0x8d,
942 0x51,0x6c,0xb0,0x62,0xd8,0xb5,0xd4,0xf9,0xb1,0xd0,0x58,0x7a,0x7a,0x82,0x55,
943 0xb3,0xf9,0x53,0x71,0xde,0xd2,0xc9,0x37,0x8c,0xf6,0x5a,0x1f,0x2d,0xcd,0x7c,
944 0x67,0x02,0x03,0x01,0x00,0x01,0xa3,0x82,0x01,0x7f,0x30,0x82,0x01,0x7b,0x30,
945 0x09,0x06,0x03,0x55,0x1d,0x13,0x04,0x02,0x30,0x00,0x30,0x0e,0x06,0x03,0x55,
946 0x1d,0x0f,0x01,0x01,0xff,0x04,0x04,0x03,0x02,0x07,0x80,0x30,0x40,0x06,0x03,
947 0x55,0x1d,0x1f,0x04,0x39,0x30,0x37,0x30,0x35,0xa0,0x33,0xa0,0x31,0x86,0x2f,
948 0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x43,0x53,0x43,0x33,0x2d,0x32,0x30,0x30,
949 0x34,0x2d,0x63,0x72,0x6c,0x2e,0x76,0x65,0x72,0x69,0x73,0x69,0x67,0x6e,0x2e,
950 0x63,0x6f,0x6d,0x2f,0x43,0x53,0x43,0x33,0x2d,0x32,0x30,0x30,0x34,0x2e,0x63,
951 0x72,0x6c,0x30,0x44,0x06,0x03,0x55,0x1d,0x20,0x04,0x3d,0x30,0x3b,0x30,0x39,
952 0x06,0x0b,0x60,0x86,0x48,0x01,0x86,0xf8,0x45,0x01,0x07,0x17,0x03,0x30,0x2a,
953 0x30,0x28,0x06,0x08,0x2b,0x06,0x01,0x05,0x05,0x07,0x02,0x01,0x16,0x1c,0x68,
954 0x74,0x74,0x70,0x73,0x3a,0x2f,0x2f,0x77,0x77,0x77,0x2e,0x76,0x65,0x72,0x69,
955 0x73,0x69,0x67,0x6e,0x2e,0x63,0x6f,0x6d,0x2f,0x72,0x70,0x61,0x30,0x13,0x06,
956 0x03,0x55,0x1d,0x25,0x04,0x0c,0x30,0x0a,0x06,0x08,0x2b,0x06,0x01,0x05,0x05,
957 0x07,0x03,0x03,0x30,0x75,0x06,0x08,0x2b,0x06,0x01,0x05,0x05,0x07,0x01,0x01,
958 0x04,0x69,0x30,0x67,0x30,0x24,0x06,0x08,0x2b,0x06,0x01,0x05,0x05,0x07,0x30,
959 0x01,0x86,0x18,0x68,0x74,0x74,0x70,0x3a,0x2f,0x2f,0x6f,0x63,0x73,0x70,0x2e,
960 0x76,0x65,0x72,0x69,0x73,0x69,0x67,0x6e,0x2e,0x63,0x6f,0x6d,0x30,0x3f,0x06,
961 0x08,0x2b,0x06,0x01,0x05,0x05,0x07,0x30,0x02,0x86,0x33,0x68,0x74,0x74,0x70,
962 0x3a,0x2f,0x2f,0x43,0x53,0x43,0x33,0x2d,0x32,0x30,0x30,0x34,0x2d,0x61,0x69,
963 0x61,0x2e,0x76,0x65,0x72,0x69,0x73,0x69,0x67,0x6e,0x2e,0x63,0x6f,0x6d,0x2f,
964 0x43,0x53,0x43,0x33,0x2d,0x32,0x30,0x30,0x34,0x2d,0x61,0x69,0x61,0x2e,0x63,
965 0x65,0x72,0x30,0x1f,0x06,0x03,0x55,0x1d,0x23,0x04,0x18,0x30,0x16,0x80,0x14,
966 0x08,0xf5,0x51,0xe8,0xfb,0xfe,0x3d,0x3d,0x64,0x36,0x7c,0x68,0xcf,0x5b,0x78,
967 0xa8,0xdf,0xb9,0xc5,0x37,0x30,0x11,0x06,0x09,0x60,0x86,0x48,0x01,0x86,0xf8,
968 0x42,0x01,0x01,0x04,0x04,0x03,0x02,0x04,0x10,0x30,0x16,0x06,0x0a,0x2b,0x06,
969 0x01,0x04,0x01,0x82,0x37,0x02,0x01,0x1b,0x04,0x08,0x30,0x06,0x01,0x01,0x00,
970 0x01,0x01,0xff,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,
971 0x05,0x05,0x00,0x03,0x82,0x01,0x01,0x00,0x6a,0xa6,0x06,0xd0,0x33,0x18,0x64,
972 0xe2,0x69,0x82,0xee,0x6e,0x36,0x9e,0x9d,0x9a,0x0e,0x18,0xa8,0xac,0x9d,0x10,
973 0xed,0x01,0x3c,0xb9,0x61,0x04,0x62,0xf3,0x85,0x8f,0xcc,0x4f,0x2c,0x66,0x35,
974 0x54,0x25,0x45,0x8d,0x95,0x1c,0xd2,0x33,0xbe,0x2e,0xdd,0x7f,0x74,0xaf,0x03,
975 0x7b,0x86,0x63,0xb0,0xc9,0xe6,0xbd,0xc7,0x8e,0xde,0x03,0x18,0x98,0x82,0xc3,
976 0xbb,0xf8,0x15,0x99,0x1a,0xa9,0xdd,0xb9,0x5d,0xb9,0xbd,0x53,0x95,0x25,0x76,
977 0xfb,0x5c,0x53,0x90,0xea,0x01,0x0a,0xa0,0xb1,0xbf,0x09,0x1b,0x97,0x8f,0x40,
978 0xfa,0x85,0x12,0x74,0x01,0xdb,0xf6,0xdb,0x09,0xd6,0x5f,0x4f,0xd7,0x17,0xb4,
979 0xbf,0x9e,0x2f,0x86,0x52,0x5d,0x70,0x24,0x52,0x32,0x1e,0xa5,0x1d,0x39,0x8b,
980 0x66,0xf6,0xba,0x9b,0x69,0x8e,0x12,0x60,0xdb,0xb6,0xcf,0xe6,0x0d,0xd6,0x1c,
981 0x8f,0xd4,0x5b,0x4b,0x00,0xde,0x21,0x93,0xfb,0x6e,0xc7,0x3d,0xb4,0x66,0x0d,
982 0x29,0x0c,0x4e,0xe9,0x3f,0x94,0xd6,0xd6,0xdc,0xec,0xf8,0x53,0x3b,0x62,0xd5,
983 0x97,0x50,0x53,0x84,0x17,0xfe,0xe2,0xed,0x4c,0x23,0x0a,0x49,0xce,0x5b,0xe9,
984 0x70,0x31,0xc1,0x04,0x02,0x02,0x6c,0xb8,0x52,0xcd,0xc7,0x4e,0x70,0xb4,0x13,
985 0xd7,0xe0,0x92,0xba,0x44,0x1a,0x10,0x4c,0x6e,0x45,0xc6,0x86,0x04,0xc6,0x64,
986 0xd3,0x9c,0x6e,0xc1,0x9c,0xac,0x74,0x3d,0x77,0x06,0x5e,0x28,0x28,0x5c,0xf5,
987 0xe0,0x9c,0x19,0xd8,0xba,0x74,0x81,0x2d,0x67,0x77,0x93,0x8d,0xbf,0xd2,0x52,
988 0x00,0xe6,0xa5,0x38,0x4e,0x2e,0x73,0x66,0x7a };
989 static BYTE iTunesIssuer[] = {
990 0x30,0x81,0xb4,0x31,0x0b,0x30,0x09,0x06,0x03,0x55,0x04,0x06,
991 0x13,0x02,0x55,0x53,0x31,0x17,0x30,0x15,0x06,0x03,0x55,0x04,
992 0x0a,0x13,0x0e,0x56,0x65,0x72,0x69,0x53,0x69,0x67,0x6e,0x2c,
993 0x20,0x49,0x6e,0x63,0x2e,0x31,0x1f,0x30,0x1d,0x06,0x03,0x55,
994 0x04,0x0b,0x13,0x16,0x56,0x65,0x72,0x69,0x53,0x69,0x67,0x6e,
995 0x20,0x54,0x72,0x75,0x73,0x74,0x20,0x4e,0x65,0x74,0x77,0x6f,
996 0x72,0x6b,0x31,0x3b,0x30,0x39,0x06,0x03,0x55,0x04,0x0b,0x13,
997 0x32,0x54,0x65,0x72,0x6d,0x73,0x20,0x6f,0x66,0x20,0x75,0x73,
998 0x65,0x20,0x61,0x74,0x20,0x68,0x74,0x74,0x70,0x73,0x3a,0x2f,
999 0x2f,0x77,0x77,0x77,0x2e,0x76,0x65,0x72,0x69,0x73,0x69,0x67,
1000 0x6e,0x2e,0x63,0x6f,0x6d,0x2f,0x72,0x70,0x61,0x20,0x28,0x63,
1001 0x29,0x30,0x34,0x31,0x2e,0x30,0x2c,0x06,0x03,0x55,0x04,0x03,
1002 0x13,0x25,0x56,0x65,0x72,0x69,0x53,0x69,0x67,0x6e,0x20,0x43,
1003 0x6c,0x61,0x73,0x73,0x20,0x33,0x20,0x43,0x6f,0x64,0x65,0x20,
1004 0x53,0x69,0x67,0x6e,0x69,0x6e,0x67,0x20,0x32,0x30,0x30,0x34,
1005 0x20,0x43,0x41 };
1006 static BYTE iTunesSerialNum[] = {
1007 0x8d,0xf6,0x6a,0xdf,0xd2,0x40,0xfe,0xb6,0xa6,0x61,0x9b,0x9b,
1008 0xe0,0xa0,0x1a,0x0f };
1010 static void testFindCert(void)
1012 HCERTSTORE store;
1013 PCCERT_CONTEXT context = NULL, subject;
1014 BOOL ret;
1015 CERT_INFO certInfo = { 0 };
1016 CRYPT_HASH_BLOB blob;
1017 BYTE otherSerialNumber[] = { 2 };
1018 DWORD count;
1019 static const WCHAR juan[] = { 'j','u','a','n',0 };
1020 static const WCHAR lang[] = { 'L','A','N','G',0 };
1021 static const WCHAR malcolm[] = { 'm','a','l','c','o','l','m',0 };
1023 store = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0,
1024 CERT_STORE_CREATE_NEW_FLAG, NULL);
1025 ok(store != NULL, "CertOpenStore failed: %d\n", GetLastError());
1026 if (!store)
1027 return;
1029 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1030 bigCert, sizeof(bigCert), CERT_STORE_ADD_NEW, NULL);
1031 ok(ret || broken(GetLastError() == OSS_DATA_ERROR /* win98 */),
1032 "CertAddEncodedCertificateToStore failed: %08x\n", GetLastError());
1033 if (!ret && GetLastError() == OSS_DATA_ERROR)
1035 skip("bigCert can't be decoded, skipping tests\n");
1036 return;
1038 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1039 bigCert2, sizeof(bigCert2), CERT_STORE_ADD_NEW, NULL);
1040 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
1041 GetLastError());
1042 /* This has the same name as bigCert */
1043 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1044 certWithUsage, sizeof(certWithUsage), CERT_STORE_ADD_NEW, NULL);
1045 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
1046 GetLastError());
1048 /* Crashes
1049 context = CertFindCertificateInStore(NULL, 0, 0, 0, NULL, NULL);
1052 /* Check first cert's there, by issuer */
1053 certInfo.Subject.pbData = subjectName;
1054 certInfo.Subject.cbData = sizeof(subjectName);
1055 certInfo.SerialNumber.pbData = serialNum;
1056 certInfo.SerialNumber.cbData = sizeof(serialNum);
1057 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1058 CERT_FIND_ISSUER_NAME, &certInfo.Subject, NULL);
1059 ok(context != NULL, "CertFindCertificateInStore failed: %08x\n",
1060 GetLastError());
1061 if (context)
1063 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1064 CERT_FIND_ISSUER_NAME, &certInfo.Subject, context);
1065 ok(context != NULL, "Expected more than one cert\n");
1066 if (context)
1068 context = CertFindCertificateInStore(store, X509_ASN_ENCODING,
1069 0, CERT_FIND_ISSUER_NAME, &certInfo.Subject, context);
1070 ok(context == NULL, "Expected precisely two certs\n");
1074 /* Check second cert's there as well, by subject name */
1075 certInfo.Subject.pbData = subjectName2;
1076 certInfo.Subject.cbData = sizeof(subjectName2);
1077 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1078 CERT_FIND_SUBJECT_NAME, &certInfo.Subject, NULL);
1079 ok(context != NULL, "CertFindCertificateInStore failed: %08x\n",
1080 GetLastError());
1081 if (context)
1083 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1084 CERT_FIND_SUBJECT_NAME, &certInfo.Subject, context);
1085 ok(context == NULL, "Expected one cert only\n");
1088 /* Strange but true: searching for the subject cert requires you to set
1089 * the issuer, not the subject
1091 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1092 CERT_FIND_SUBJECT_CERT, &certInfo.Subject, NULL);
1093 ok(context == NULL, "Expected no certificate\n");
1094 certInfo.Subject.pbData = NULL;
1095 certInfo.Subject.cbData = 0;
1096 certInfo.Issuer.pbData = subjectName2;
1097 certInfo.Issuer.cbData = sizeof(subjectName2);
1098 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1099 CERT_FIND_SUBJECT_CERT, &certInfo, NULL);
1100 ok(context != NULL, "CertFindCertificateInStore failed: %08x\n",
1101 GetLastError());
1102 if (context)
1104 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1105 CERT_FIND_SUBJECT_CERT, &certInfo.Subject, context);
1106 ok(context == NULL, "Expected one cert only\n");
1108 /* A non-matching serial number will not match. */
1109 certInfo.SerialNumber.pbData = otherSerialNumber;
1110 certInfo.SerialNumber.cbData = sizeof(otherSerialNumber);
1111 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1112 CERT_FIND_SUBJECT_CERT, &certInfo, NULL);
1113 ok(context == NULL, "Expected no match\n");
1114 /* No serial number will not match */
1115 certInfo.SerialNumber.cbData = 0;
1116 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1117 CERT_FIND_SUBJECT_CERT, &certInfo, NULL);
1118 ok(context == NULL, "Expected no match\n");
1119 /* A serial number still won't match if the name doesn't */
1120 certInfo.SerialNumber.pbData = serialNum;
1121 certInfo.SerialNumber.cbData = sizeof(serialNum);
1122 certInfo.Issuer.pbData = subjectName3;
1123 certInfo.Issuer.cbData = sizeof(subjectName3);
1124 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1125 CERT_FIND_SUBJECT_CERT, &certInfo, NULL);
1126 ok(context == NULL, "Expected no match\n");
1128 /* The nice thing about hashes, they're unique */
1129 blob.pbData = bigCertHash;
1130 blob.cbData = sizeof(bigCertHash);
1131 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1132 CERT_FIND_SHA1_HASH, &blob, NULL);
1133 ok(context != NULL, "CertFindCertificateInStore failed: %08x\n",
1134 GetLastError());
1135 if (context)
1137 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1138 CERT_FIND_SHA1_HASH, &certInfo.Subject, context);
1139 ok(context == NULL, "Expected one cert only\n");
1142 /* Searching for NULL string matches any context. */
1143 count = 0;
1144 context = NULL;
1145 do {
1146 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1147 CERT_FIND_ISSUER_STR, NULL, context);
1148 if (context)
1149 count++;
1150 } while (context);
1151 ok(count == 3, "expected 3 contexts\n");
1152 count = 0;
1153 context = NULL;
1154 do {
1155 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1156 CERT_FIND_ISSUER_STR, juan, context);
1157 if (context)
1158 count++;
1159 } while (context);
1160 ok(count == 2, "expected 2 contexts\n");
1161 count = 0;
1162 context = NULL;
1163 do {
1164 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1165 CERT_FIND_ISSUER_STR, lang, context);
1166 if (context)
1167 count++;
1168 } while (context);
1169 ok(count == 3, "expected 3 contexts\n");
1170 SetLastError(0xdeadbeef);
1171 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1172 CERT_FIND_ISSUER_STR, malcolm, NULL);
1173 ok(!context, "expected no certs\n");
1174 ok(GetLastError() == CRYPT_E_NOT_FOUND,
1175 "expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
1177 CertCloseStore(store, 0);
1179 /* Another subject cert search, using iTunes's certs */
1180 store = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0,
1181 CERT_STORE_CREATE_NEW_FLAG, NULL);
1182 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1183 iTunesCert0, sizeof(iTunesCert0), CERT_STORE_ADD_NEW, NULL);
1184 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
1185 GetLastError());
1186 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1187 iTunesCert1, sizeof(iTunesCert1), CERT_STORE_ADD_NEW, NULL);
1188 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
1189 GetLastError());
1190 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1191 iTunesCert2, sizeof(iTunesCert2), CERT_STORE_ADD_NEW, NULL);
1192 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
1193 GetLastError());
1194 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1195 iTunesCert3, sizeof(iTunesCert3), CERT_STORE_ADD_NEW, &subject);
1196 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
1197 GetLastError());
1199 /* The certInfo's issuer does not match any subject, but the serial
1200 * number does match a cert whose issuer matches certInfo's issuer.
1201 * This yields a match.
1203 certInfo.SerialNumber.cbData = sizeof(iTunesSerialNum);
1204 certInfo.SerialNumber.pbData = iTunesSerialNum;
1205 certInfo.Issuer.cbData = sizeof(iTunesIssuer);
1206 certInfo.Issuer.pbData = iTunesIssuer;
1207 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1208 CERT_FIND_SUBJECT_CERT, &certInfo, NULL);
1209 ok(context != NULL, "Expected a match\n");
1210 if (context)
1212 ret = CertCompareCertificateName(context->dwCertEncodingType,
1213 &certInfo.Issuer, &context->pCertInfo->Subject);
1214 ok(!ret, "Expected subject name not to match\n");
1215 ret = CertCompareCertificateName(context->dwCertEncodingType,
1216 &certInfo.Issuer, &context->pCertInfo->Issuer);
1217 ok(ret, "Expected issuer name to match\n");
1218 ret = CertCompareIntegerBlob(&certInfo.SerialNumber,
1219 &context->pCertInfo->SerialNumber);
1220 ok(ret, "Expected serial number to match\n");
1221 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1222 CERT_FIND_SUBJECT_CERT, &certInfo, context);
1223 ok(context == NULL, "Expected one cert only\n");
1226 context = CertFindCertificateInStore(store, X509_ASN_ENCODING, 0,
1227 CERT_FIND_ISSUER_OF, subject, NULL);
1228 ok(context != NULL, "Expected an issuer\n");
1229 if (context)
1231 PCCERT_CONTEXT none = CertFindCertificateInStore(store,
1232 X509_ASN_ENCODING, 0, CERT_FIND_ISSUER_OF, context, NULL);
1234 ok(!none, "Expected no parent of issuer\n");
1235 CertFreeCertificateContext(context);
1237 CertFreeCertificateContext(subject);
1238 CertCloseStore(store, 0);
1241 static void testGetSubjectCert(void)
1243 HCERTSTORE store;
1244 PCCERT_CONTEXT context1, context2;
1245 CERT_INFO info = { 0 };
1246 BOOL ret;
1248 store = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0,
1249 CERT_STORE_CREATE_NEW_FLAG, NULL);
1250 ok(store != NULL, "CertOpenStore failed: %d\n", GetLastError());
1251 if (!store)
1252 return;
1254 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1255 bigCert, sizeof(bigCert), CERT_STORE_ADD_ALWAYS, NULL);
1256 ok(ret || broken(GetLastError() == OSS_DATA_ERROR /* win98 */),
1257 "CertAddEncodedCertificateToStore failed: %08x\n", GetLastError());
1258 if (!ret && GetLastError() == OSS_DATA_ERROR)
1260 skip("bigCert can't be decoded, skipping tests\n");
1261 return;
1263 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1264 bigCert2, sizeof(bigCert2), CERT_STORE_ADD_NEW, &context1);
1265 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
1266 GetLastError());
1267 ok(context1 != NULL, "Expected a context\n");
1268 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1269 certWithUsage, sizeof(certWithUsage), CERT_STORE_ADD_NEW, NULL);
1270 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
1271 GetLastError());
1273 context2 = CertGetSubjectCertificateFromStore(store, X509_ASN_ENCODING,
1274 NULL);
1275 ok(!context2 && GetLastError() == E_INVALIDARG,
1276 "Expected E_INVALIDARG, got %08x\n", GetLastError());
1277 context2 = CertGetSubjectCertificateFromStore(store, X509_ASN_ENCODING,
1278 &info);
1279 ok(!context2 && GetLastError() == CRYPT_E_NOT_FOUND,
1280 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
1281 info.SerialNumber.cbData = sizeof(serialNum);
1282 info.SerialNumber.pbData = serialNum;
1283 context2 = CertGetSubjectCertificateFromStore(store, X509_ASN_ENCODING,
1284 &info);
1285 ok(!context2 && GetLastError() == CRYPT_E_NOT_FOUND,
1286 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
1287 info.Issuer.cbData = sizeof(subjectName2);
1288 info.Issuer.pbData = subjectName2;
1289 context2 = CertGetSubjectCertificateFromStore(store, X509_ASN_ENCODING,
1290 &info);
1291 ok(context2 != NULL,
1292 "CertGetSubjectCertificateFromStore failed: %08x\n", GetLastError());
1293 /* Not only should this find a context, but it should be the same
1294 * (same address) as context1.
1296 ok(context1 == context2, "Expected identical context addresses\n");
1297 CertFreeCertificateContext(context2);
1299 CertFreeCertificateContext(context1);
1300 CertCloseStore(store, 0);
1303 /* This expires in 1970 or so */
1304 static const BYTE expiredCert[] = { 0x30, 0x82, 0x01, 0x33, 0x30, 0x81, 0xe2,
1305 0xa0, 0x03, 0x02, 0x01, 0x02, 0x02, 0x10, 0xc4, 0xd7, 0x7f, 0x0e, 0x6f, 0xa6,
1306 0x8c, 0xaa, 0x47, 0x47, 0x40, 0xe7, 0xb7, 0x0b, 0x4a, 0x7f, 0x30, 0x09, 0x06,
1307 0x05, 0x2b, 0x0e, 0x03, 0x02, 0x1d, 0x05, 0x00, 0x30, 0x1f, 0x31, 0x1d, 0x30,
1308 0x1b, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x14, 0x61, 0x72, 0x69, 0x63, 0x40,
1309 0x63, 0x6f, 0x64, 0x65, 0x77, 0x65, 0x61, 0x76, 0x65, 0x72, 0x73, 0x2e, 0x63,
1310 0x6f, 0x6d, 0x30, 0x1e, 0x17, 0x0d, 0x36, 0x39, 0x30, 0x31, 0x30, 0x31, 0x30,
1311 0x30, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x17, 0x0d, 0x37, 0x30, 0x30, 0x31, 0x30,
1312 0x31, 0x30, 0x36, 0x30, 0x30, 0x30, 0x30, 0x5a, 0x30, 0x1f, 0x31, 0x1d, 0x30,
1313 0x1b, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x14, 0x61, 0x72, 0x69, 0x63, 0x40,
1314 0x63, 0x6f, 0x64, 0x65, 0x77, 0x65, 0x61, 0x76, 0x65, 0x72, 0x73, 0x2e, 0x63,
1315 0x6f, 0x6d, 0x30, 0x5c, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7,
1316 0x0d, 0x01, 0x01, 0x01, 0x05, 0x00, 0x03, 0x4b, 0x00, 0x30, 0x48, 0x02, 0x41,
1317 0x00, 0xa1, 0xaf, 0x4a, 0xea, 0xa7, 0x83, 0x57, 0xc0, 0x37, 0x33, 0x7e, 0x29,
1318 0x5e, 0x0d, 0xfc, 0x44, 0x74, 0x3a, 0x1d, 0xc3, 0x1b, 0x1d, 0x96, 0xed, 0x4e,
1319 0xf4, 0x1b, 0x98, 0xec, 0x69, 0x1b, 0x04, 0xea, 0x25, 0xcf, 0xb3, 0x2a, 0xf5,
1320 0xd9, 0x22, 0xd9, 0x8d, 0x08, 0x39, 0x81, 0xc6, 0xe0, 0x4f, 0x12, 0x37, 0x2a,
1321 0x3f, 0x80, 0xa6, 0x6c, 0x67, 0x43, 0x3a, 0xdd, 0x95, 0x0c, 0xbb, 0x2f, 0x6b,
1322 0x02, 0x03, 0x01, 0x00, 0x01, 0x30, 0x09, 0x06, 0x05, 0x2b, 0x0e, 0x03, 0x02,
1323 0x1d, 0x05, 0x00, 0x03, 0x41, 0x00, 0x8f, 0xa2, 0x5b, 0xd6, 0xdf, 0x34, 0xd0,
1324 0xa2, 0xa7, 0x47, 0xf1, 0x13, 0x79, 0xd3, 0xf3, 0x39, 0xbd, 0x4e, 0x2b, 0xa3,
1325 0xf4, 0x63, 0x37, 0xac, 0x5a, 0x0c, 0x5e, 0x4d, 0x0d, 0x54, 0x87, 0x4f, 0x31,
1326 0xfb, 0xa0, 0xce, 0x8f, 0x9a, 0x2f, 0x4d, 0x48, 0xc6, 0x84, 0x8d, 0xf5, 0x70,
1327 0x74, 0x17, 0xa5, 0xf3, 0x66, 0x47, 0x06, 0xd6, 0x64, 0x45, 0xbc, 0x52, 0xef,
1328 0x49, 0xe5, 0xf9, 0x65, 0xf3 };
1330 /* This expires in 2036 or so */
1331 static const BYTE childOfExpired[] = { 0x30, 0x81, 0xcc, 0x30, 0x78, 0xa0,
1332 0x03, 0x02, 0x01, 0x02, 0x02, 0x01, 0x01, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86,
1333 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x05, 0x05, 0x00, 0x30, 0x1f, 0x31, 0x1d,
1334 0x30, 0x1b, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x14, 0x61, 0x72, 0x69, 0x63,
1335 0x40, 0x63, 0x6f, 0x64, 0x65, 0x77, 0x65, 0x61, 0x76, 0x65, 0x72, 0x73, 0x2e,
1336 0x63, 0x6f, 0x6d, 0x30, 0x1e, 0x17, 0x0d, 0x30, 0x36, 0x30, 0x35, 0x30, 0x35,
1337 0x31, 0x37, 0x31, 0x32, 0x34, 0x39, 0x5a, 0x17, 0x0d, 0x33, 0x36, 0x30, 0x35,
1338 0x30, 0x35, 0x31, 0x37, 0x31, 0x32, 0x34, 0x39, 0x5a, 0x30, 0x15, 0x31, 0x13,
1339 0x30, 0x11, 0x06, 0x03, 0x55, 0x04, 0x03, 0x13, 0x0a, 0x4a, 0x75, 0x61, 0x6e,
1340 0x20, 0x4c, 0x61, 0x6e, 0x67, 0x00, 0x30, 0x07, 0x30, 0x02, 0x06, 0x00, 0x03,
1341 0x01, 0x00, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01,
1342 0x01, 0x05, 0x05, 0x00, 0x03, 0x41, 0x00, 0x20, 0x3b, 0xdb, 0x4d, 0x67, 0x50,
1343 0xec, 0x73, 0x9d, 0xf9, 0x85, 0x5d, 0x18, 0xe9, 0xb4, 0x98, 0xe3, 0x31, 0xb7,
1344 0x03, 0x0b, 0xc0, 0x39, 0x93, 0x56, 0x81, 0x0a, 0xfc, 0x78, 0xa8, 0x29, 0x42,
1345 0x5f, 0x69, 0xfb, 0xbc, 0x5b, 0xf2, 0xa6, 0x2a, 0xbe, 0x91, 0x2c, 0xfc, 0x89,
1346 0x69, 0x15, 0x18, 0x58, 0xe5, 0x02, 0x75, 0xf7, 0x2a, 0xb6, 0xa9, 0xfb, 0x47,
1347 0x6a, 0x6e, 0x0a, 0x9b, 0xe9, 0xdc };
1348 /* chain10_0 -+
1349 * +-> chain7_1
1350 * chain10_1 -+
1351 * A chain with two issuers, only one of whose dates is valid.
1353 static const BYTE chain10_0[] = {
1354 0x30,0x82,0x01,0x9b,0x30,0x82,0x01,0x08,0xa0,0x03,0x02,0x01,0x02,0x02,0x10,
1355 0x4a,0x30,0x3a,0x42,0xa2,0x5a,0xb3,0x93,0x4d,0x94,0x06,0xad,0x6d,0x1c,0x34,
1356 0xe6,0x30,0x09,0x06,0x05,0x2b,0x0e,0x03,0x02,0x1d,0x05,0x00,0x30,0x10,0x31,
1357 0x0e,0x30,0x0c,0x06,0x03,0x55,0x04,0x03,0x13,0x05,0x43,0x65,0x72,0x74,0x31,
1358 0x30,0x1e,0x17,0x0d,0x30,0x36,0x30,0x31,0x30,0x31,0x30,0x30,0x30,0x30,0x30,
1359 0x30,0x5a,0x17,0x0d,0x30,0x36,0x31,0x32,0x33,0x31,0x32,0x33,0x35,0x39,0x35,
1360 0x39,0x5a,0x30,0x10,0x31,0x0e,0x30,0x0c,0x06,0x03,0x55,0x04,0x03,0x13,0x05,
1361 0x43,0x65,0x72,0x74,0x31,0x30,0x81,0x9f,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,
1362 0x86,0xf7,0x0d,0x01,0x01,0x01,0x05,0x00,0x03,0x81,0x8d,0x00,0x30,0x81,0x89,
1363 0x02,0x81,0x81,0x00,0xad,0x7e,0xca,0xf3,0xe5,0x99,0xc2,0x2a,0xca,0x50,0x82,
1364 0x7c,0x2d,0xa4,0x81,0xcd,0x0d,0x0d,0x86,0xd7,0xd8,0xb2,0xde,0xc5,0xc3,0x34,
1365 0x9e,0x07,0x78,0x08,0x11,0x12,0x2d,0x21,0x0a,0x09,0x07,0x14,0x03,0x7a,0xe7,
1366 0x3b,0x58,0xf1,0xde,0x3e,0x01,0x25,0x93,0xab,0x8f,0xce,0x1f,0xc1,0x33,0x91,
1367 0xfe,0x59,0xb9,0x3b,0x9e,0x95,0x12,0x89,0x8e,0xc3,0x4b,0x98,0x1b,0x99,0xc5,
1368 0x07,0xe2,0xdf,0x15,0x4c,0x39,0x76,0x06,0xad,0xdb,0x16,0x06,0x49,0xba,0xcd,
1369 0x0f,0x07,0xd6,0xea,0x27,0xa6,0xfe,0x3d,0x88,0xe5,0x97,0x45,0x72,0xb6,0x1c,
1370 0xc0,0x1c,0xb1,0xa2,0x89,0xe8,0x37,0x9e,0xf6,0x2a,0xcf,0xd5,0x1f,0x2f,0x35,
1371 0x5e,0x8f,0x3a,0x9c,0x61,0xb1,0xf1,0x6c,0xff,0x8c,0xb2,0x2f,0x02,0x03,0x01,
1372 0x00,0x01,0x30,0x09,0x06,0x05,0x2b,0x0e,0x03,0x02,0x1d,0x05,0x00,0x03,0x81,
1373 0x81,0x00,0x85,0x6e,0x35,0x2f,0x2c,0x51,0x4f,0xd6,0x2a,0xe4,0x9e,0xd0,0x4b,
1374 0xe6,0x90,0xfd,0xf7,0x20,0xad,0x76,0x3f,0x93,0xea,0x7f,0x0d,0x1f,0xb3,0x8e,
1375 0xfd,0xe0,0xe1,0xd6,0xd7,0x9c,0x7d,0x46,0x6b,0x15,0x5c,0xe6,0xc9,0x62,0x3b,
1376 0x70,0x4a,0x4b,0xb2,0x82,0xe3,0x55,0x0c,0xc4,0x90,0x44,0x06,0x6c,0x86,0x1c,
1377 0x6d,0x47,0x12,0xda,0x33,0x95,0x5d,0x98,0x43,0xcb,0x7c,0xfa,0x2b,0xee,0xc4,
1378 0x2d,0xc8,0x95,0x33,0x89,0x08,0x3f,0x9f,0x87,0xea,0x20,0x04,0xaf,0x58,0x4b,
1379 0x9d,0xc0,0x7c,0x0a,0x1b,0x05,0x31,0x3b,0xbb,0x13,0x58,0x2e,0x3f,0x61,0x6b,
1380 0x10,0xb4,0xeb,0xb9,0x1a,0x30,0xfd,0xea,0xca,0x29,0x99,0x5f,0x42,0x2b,0x00,
1381 0xb0,0x08,0xc3,0xf0,0xb6,0xd6,0x6b,0xf9,0x35,0x95 };
1382 static const BYTE chain10_1[] = {
1383 0x30,0x82,0x01,0x9b,0x30,0x82,0x01,0x08,0xa0,0x03,0x02,0x01,0x02,0x02,0x10,
1384 0xbf,0x99,0x4f,0x14,0x03,0x77,0x44,0xb8,0x49,0x02,0x70,0xa1,0xb8,0x9c,0xa7,
1385 0x24,0x30,0x09,0x06,0x05,0x2b,0x0e,0x03,0x02,0x1d,0x05,0x00,0x30,0x10,0x31,
1386 0x0e,0x30,0x0c,0x06,0x03,0x55,0x04,0x03,0x13,0x05,0x43,0x65,0x72,0x74,0x31,
1387 0x30,0x1e,0x17,0x0d,0x30,0x37,0x30,0x31,0x30,0x31,0x30,0x30,0x30,0x30,0x30,
1388 0x30,0x5a,0x17,0x0d,0x30,0x37,0x31,0x32,0x33,0x31,0x32,0x33,0x35,0x39,0x35,
1389 0x39,0x5a,0x30,0x10,0x31,0x0e,0x30,0x0c,0x06,0x03,0x55,0x04,0x03,0x13,0x05,
1390 0x43,0x65,0x72,0x74,0x31,0x30,0x81,0x9f,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,
1391 0x86,0xf7,0x0d,0x01,0x01,0x01,0x05,0x00,0x03,0x81,0x8d,0x00,0x30,0x81,0x89,
1392 0x02,0x81,0x81,0x00,0xad,0x7e,0xca,0xf3,0xe5,0x99,0xc2,0x2a,0xca,0x50,0x82,
1393 0x7c,0x2d,0xa4,0x81,0xcd,0x0d,0x0d,0x86,0xd7,0xd8,0xb2,0xde,0xc5,0xc3,0x34,
1394 0x9e,0x07,0x78,0x08,0x11,0x12,0x2d,0x21,0x0a,0x09,0x07,0x14,0x03,0x7a,0xe7,
1395 0x3b,0x58,0xf1,0xde,0x3e,0x01,0x25,0x93,0xab,0x8f,0xce,0x1f,0xc1,0x33,0x91,
1396 0xfe,0x59,0xb9,0x3b,0x9e,0x95,0x12,0x89,0x8e,0xc3,0x4b,0x98,0x1b,0x99,0xc5,
1397 0x07,0xe2,0xdf,0x15,0x4c,0x39,0x76,0x06,0xad,0xdb,0x16,0x06,0x49,0xba,0xcd,
1398 0x0f,0x07,0xd6,0xea,0x27,0xa6,0xfe,0x3d,0x88,0xe5,0x97,0x45,0x72,0xb6,0x1c,
1399 0xc0,0x1c,0xb1,0xa2,0x89,0xe8,0x37,0x9e,0xf6,0x2a,0xcf,0xd5,0x1f,0x2f,0x35,
1400 0x5e,0x8f,0x3a,0x9c,0x61,0xb1,0xf1,0x6c,0xff,0x8c,0xb2,0x2f,0x02,0x03,0x01,
1401 0x00,0x01,0x30,0x09,0x06,0x05,0x2b,0x0e,0x03,0x02,0x1d,0x05,0x00,0x03,0x81,
1402 0x81,0x00,0xa8,0xec,0x8c,0x34,0xe7,0x2c,0xdf,0x75,0x87,0xc4,0xf7,0xda,0x71,
1403 0x72,0x29,0xb2,0x48,0xa8,0x2a,0xec,0x7b,0x7d,0x19,0xb9,0x5f,0x1d,0xd9,0x91,
1404 0x2b,0xc4,0x28,0x7e,0xd6,0xb5,0x91,0x69,0xa5,0x8a,0x1a,0x1f,0x97,0x98,0x46,
1405 0x9d,0xdf,0x12,0xf6,0x45,0x62,0xad,0x60,0xb6,0xba,0xb0,0xfd,0xf5,0x9f,0xc6,
1406 0x98,0x05,0x4f,0x4d,0x48,0xdc,0xee,0x69,0xbe,0xb8,0xc4,0xc4,0xd7,0x1b,0xb1,
1407 0x1f,0x64,0xd6,0x45,0xa7,0xdb,0xb3,0x87,0x63,0x0f,0x54,0xe1,0x3a,0x6b,0x57,
1408 0x36,0xd7,0x68,0x65,0xcf,0xda,0x57,0x8d,0xcd,0x84,0x75,0x47,0x26,0x2c,0xef,
1409 0x1e,0x8f,0xc7,0x3b,0xee,0x5d,0x03,0xa6,0xdf,0x3a,0x20,0xb2,0xcc,0xc9,0x09,
1410 0x2c,0xfe,0x2b,0x79,0xb0,0xca,0x2c,0x9a,0x81,0x6b };
1411 static const BYTE chain7_1[] = {
1412 0x30,0x82,0x01,0x93,0x30,0x81,0xfd,0xa0,0x03,0x02,0x01,0x02,0x02,0x01,0x01,
1413 0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x05,0x05,0x00,
1414 0x30,0x10,0x31,0x0e,0x30,0x0c,0x06,0x03,0x55,0x04,0x03,0x13,0x05,0x43,0x65,
1415 0x72,0x74,0x31,0x30,0x1e,0x17,0x0d,0x30,0x37,0x30,0x31,0x30,0x31,0x30,0x30,
1416 0x30,0x30,0x30,0x30,0x5a,0x17,0x0d,0x30,0x37,0x31,0x32,0x33,0x31,0x32,0x33,
1417 0x35,0x39,0x35,0x39,0x5a,0x30,0x10,0x31,0x0e,0x30,0x0c,0x06,0x03,0x55,0x04,
1418 0x03,0x13,0x05,0x43,0x65,0x72,0x74,0x32,0x30,0x81,0x9f,0x30,0x0d,0x06,0x09,
1419 0x2a,0x86,0x48,0x86,0xf7,0x0d,0x01,0x01,0x01,0x05,0x00,0x03,0x81,0x8d,0x00,
1420 0x30,0x81,0x89,0x02,0x81,0x81,0x00,0xb8,0x52,0xda,0xc5,0x4b,0x3f,0xe5,0x33,
1421 0x0e,0x67,0x5f,0x48,0x21,0xdc,0x7e,0xef,0x37,0x33,0xba,0xff,0xb4,0xc6,0xdc,
1422 0xb6,0x17,0x8e,0x20,0x55,0x07,0x12,0xd2,0x7b,0x3c,0xce,0x30,0xc5,0xa7,0x48,
1423 0x9f,0x6e,0xfe,0xb8,0xbe,0xdb,0x9f,0x9b,0x17,0x60,0x16,0xde,0xc6,0x8b,0x47,
1424 0xd1,0x57,0x71,0x3c,0x93,0xfc,0xbd,0xec,0x44,0x32,0x3b,0xb9,0xcf,0x6b,0x05,
1425 0x72,0xa7,0x87,0x8e,0x7e,0xd4,0x9a,0x87,0x1c,0x2f,0xb7,0x82,0x40,0xfc,0x6a,
1426 0x80,0x83,0x68,0x28,0xce,0x84,0xf4,0x0b,0x2e,0x44,0xcb,0x53,0xac,0x85,0x85,
1427 0xb5,0x46,0x36,0x98,0x3c,0x10,0x02,0xaa,0x02,0xbc,0x8b,0xa2,0x23,0xb2,0xd3,
1428 0x51,0x9a,0x22,0x4a,0xe3,0xaa,0x4e,0x7c,0xda,0x38,0xcf,0x49,0x98,0x72,0xa3,
1429 0x02,0x03,0x01,0x00,0x01,0x30,0x0d,0x06,0x09,0x2a,0x86,0x48,0x86,0xf7,0x0d,
1430 0x01,0x01,0x05,0x05,0x00,0x03,0x81,0x81,0x00,0x9f,0x69,0xfd,0x26,0xd5,0x4b,
1431 0xe0,0xab,0x12,0x21,0xb9,0xfc,0xf7,0xe0,0x0c,0x09,0x94,0xad,0x27,0xd7,0x9d,
1432 0xa3,0xcc,0x46,0x2a,0x25,0x9a,0x24,0xa7,0x31,0x58,0x78,0xf5,0xfc,0x30,0xe1,
1433 0x6d,0xfd,0x59,0xab,0xbe,0x69,0xa0,0xea,0xe3,0x7d,0x7a,0x7b,0xe5,0x85,0xeb,
1434 0x86,0x6a,0x84,0x3c,0x96,0x01,0x1a,0x70,0xa7,0xb8,0xcb,0xf2,0x11,0xe7,0x52,
1435 0x9c,0x58,0x2d,0xac,0x63,0xce,0x72,0x4b,0xad,0x62,0xa8,0x1d,0x75,0x96,0xe2,
1436 0x27,0xf5,0x6f,0xba,0x91,0xf8,0xf1,0xb0,0xbf,0x90,0x24,0x6d,0xba,0x5d,0xd7,
1437 0x39,0x63,0x3b,0x7c,0x04,0x5d,0x89,0x9d,0x1c,0xf2,0xf7,0xcc,0xdf,0x6e,0x8a,
1438 0x43,0xa9,0xdd,0x86,0x05,0xa2,0xf3,0x22,0x2d,0x1e,0x70,0xa1,0x59,0xd7,0xa5,
1439 0x94,0x7d };
1441 static void testGetIssuerCert(void)
1443 BOOL ret;
1444 PCCERT_CONTEXT parent, child, cert1, cert2;
1445 DWORD flags = 0xffffffff;
1446 HCERTSTORE store = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0,
1447 CERT_STORE_CREATE_NEW_FLAG, NULL);
1449 ok(store != NULL, "CertOpenStore failed: %08x\n", GetLastError());
1451 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1452 expiredCert, sizeof(expiredCert), CERT_STORE_ADD_ALWAYS, NULL);
1453 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
1454 GetLastError());
1456 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1457 childOfExpired, sizeof(childOfExpired), CERT_STORE_ADD_ALWAYS, &child);
1458 ok(ret, "CertAddEncodedCertificateToStore failed: %08x\n",
1459 GetLastError());
1461 /* These crash:
1462 parent = CertGetIssuerCertificateFromStore(NULL, NULL, NULL, NULL);
1463 parent = CertGetIssuerCertificateFromStore(store, NULL, NULL, NULL);
1465 parent = CertGetIssuerCertificateFromStore(NULL, NULL, NULL, &flags);
1466 ok(!parent && GetLastError() == E_INVALIDARG,
1467 "Expected E_INVALIDARG, got %08x\n", GetLastError());
1468 parent = CertGetIssuerCertificateFromStore(store, NULL, NULL, &flags);
1469 ok(!parent && GetLastError() == E_INVALIDARG,
1470 "Expected E_INVALIDARG, got %08x\n", GetLastError());
1471 parent = CertGetIssuerCertificateFromStore(store, child, NULL, &flags);
1472 ok(!parent && GetLastError() == E_INVALIDARG,
1473 "Expected E_INVALIDARG, got %08x\n", GetLastError());
1474 /* Confusing: the caller cannot set either of the
1475 * CERT_STORE_NO_*_FLAGs, as these are not checks,
1476 * they're results:
1478 flags = CERT_STORE_NO_CRL_FLAG | CERT_STORE_NO_ISSUER_FLAG;
1479 parent = CertGetIssuerCertificateFromStore(store, child, NULL, &flags);
1480 ok(!parent && GetLastError() == E_INVALIDARG,
1481 "Expected E_INVALIDARG, got %08x\n", GetLastError());
1482 /* Perform no checks */
1483 flags = 0;
1484 parent = CertGetIssuerCertificateFromStore(store, child, NULL, &flags);
1485 ok(parent != NULL, "CertGetIssuerCertificateFromStore failed: %08x\n",
1486 GetLastError());
1487 if (parent)
1488 CertFreeCertificateContext(parent);
1489 /* Check revocation and signature only */
1490 flags = CERT_STORE_REVOCATION_FLAG | CERT_STORE_SIGNATURE_FLAG;
1491 parent = CertGetIssuerCertificateFromStore(store, child, NULL, &flags);
1492 ok(parent != NULL, "CertGetIssuerCertificateFromStore failed: %08x\n",
1493 GetLastError());
1494 /* Confusing: CERT_STORE_REVOCATION_FLAG succeeds when there is no CRL by
1495 * setting CERT_STORE_NO_CRL_FLAG.
1497 ok(flags == (CERT_STORE_REVOCATION_FLAG | CERT_STORE_NO_CRL_FLAG),
1498 "Expected CERT_STORE_REVOCATION_FLAG | CERT_STORE_NO_CRL_FLAG, got %08x\n",
1499 flags);
1500 if (parent)
1501 CertFreeCertificateContext(parent);
1502 /* Checking time validity is not productive, because while most Windows
1503 * versions return 0 (time valid) because the child is not expired,
1504 * Windows 2003 SP1 returns that it is expired. Thus the range of
1505 * possibilities is covered, and a test verifies nothing.
1508 CertFreeCertificateContext(child);
1509 CertCloseStore(store, 0);
1511 flags = 0;
1512 store = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0,
1513 CERT_STORE_CREATE_NEW_FLAG, NULL);
1514 /* With only the child certificate, no issuer will be found */
1515 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1516 chain7_1, sizeof(chain7_1), CERT_STORE_ADD_ALWAYS, &child);
1517 parent = CertGetIssuerCertificateFromStore(store, child, NULL, &flags);
1518 ok(parent == NULL, "Expected no issuer\n");
1519 /* Adding an issuer allows one (and only one) issuer to be found */
1520 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1521 chain10_1, sizeof(chain10_1), CERT_STORE_ADD_ALWAYS, &cert1);
1522 parent = CertGetIssuerCertificateFromStore(store, child, NULL, &flags);
1523 ok(parent == cert1, "Expected cert1 to be the issuer\n");
1524 parent = CertGetIssuerCertificateFromStore(store, child, parent, &flags);
1525 ok(parent == NULL, "Expected only one issuer\n");
1526 /* Adding a second issuer allows two issuers to be found - and the second
1527 * issuer is found before the first, implying certs are added to the head
1528 * of a list.
1530 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1531 chain10_0, sizeof(chain10_0), CERT_STORE_ADD_ALWAYS, &cert2);
1532 parent = CertGetIssuerCertificateFromStore(store, child, NULL, &flags);
1533 ok(parent == cert2, "Expected cert2 to be the first issuer\n");
1534 parent = CertGetIssuerCertificateFromStore(store, child, parent, &flags);
1535 ok(parent == cert1, "Expected cert1 to be the second issuer\n");
1536 parent = CertGetIssuerCertificateFromStore(store, child, parent, &flags);
1537 ok(parent == NULL, "Expected no more than two issuers\n");
1538 CertFreeCertificateContext(child);
1539 CertFreeCertificateContext(cert1);
1540 CertFreeCertificateContext(cert2);
1541 CertCloseStore(store, 0);
1543 /* Repeat the test, reversing the order in which issuers are added,
1544 * to show it's order-dependent.
1546 store = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0,
1547 CERT_STORE_CREATE_NEW_FLAG, NULL);
1548 /* With only the child certificate, no issuer will be found */
1549 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1550 chain7_1, sizeof(chain7_1), CERT_STORE_ADD_ALWAYS, &child);
1551 parent = CertGetIssuerCertificateFromStore(store, child, NULL, &flags);
1552 ok(parent == NULL, "Expected no issuer\n");
1553 /* Adding an issuer allows one (and only one) issuer to be found */
1554 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1555 chain10_0, sizeof(chain10_0), CERT_STORE_ADD_ALWAYS, &cert1);
1556 parent = CertGetIssuerCertificateFromStore(store, child, NULL, &flags);
1557 ok(parent == cert1, "Expected cert1 to be the issuer\n");
1558 parent = CertGetIssuerCertificateFromStore(store, child, parent, &flags);
1559 ok(parent == NULL, "Expected only one issuer\n");
1560 /* Adding a second issuer allows two issuers to be found - and the second
1561 * issuer is found before the first, implying certs are added to the head
1562 * of a list.
1564 ret = CertAddEncodedCertificateToStore(store, X509_ASN_ENCODING,
1565 chain10_1, sizeof(chain10_1), CERT_STORE_ADD_ALWAYS, &cert2);
1566 parent = CertGetIssuerCertificateFromStore(store, child, NULL, &flags);
1567 ok(parent == cert2, "Expected cert2 to be the first issuer\n");
1568 parent = CertGetIssuerCertificateFromStore(store, child, parent, &flags);
1569 ok(parent == cert1, "Expected cert1 to be the second issuer\n");
1570 parent = CertGetIssuerCertificateFromStore(store, child, parent, &flags);
1571 ok(parent == NULL, "Expected no more than two issuers\n");
1572 CertFreeCertificateContext(child);
1573 CertFreeCertificateContext(cert1);
1574 CertFreeCertificateContext(cert2);
1575 CertCloseStore(store, 0);
1578 static void testCryptHashCert(void)
1580 static const BYTE emptyHash[] = { 0xda, 0x39, 0xa3, 0xee, 0x5e, 0x6b, 0x4b,
1581 0x0d, 0x32, 0x55, 0xbf, 0xef, 0x95, 0x60, 0x18, 0x90, 0xaf, 0xd8, 0x07,
1582 0x09 };
1583 static const BYTE knownHash[] = { 0xae, 0x9d, 0xbf, 0x6d, 0xf5, 0x46, 0xee,
1584 0x8b, 0xc5, 0x7a, 0x13, 0xba, 0xc2, 0xb1, 0x04, 0xf2, 0xbf, 0x52, 0xa8,
1585 0xa2 };
1586 static const BYTE toHash[] = "abcdefghijklmnopqrstuvwxyz0123456789.,;!?:";
1587 BOOL ret;
1588 BYTE hash[20];
1589 DWORD hashLen = sizeof(hash);
1591 /* NULL buffer and nonzero length crashes
1592 ret = CryptHashCertificate(0, 0, 0, NULL, size, hash, &hashLen);
1593 empty hash length also crashes
1594 ret = CryptHashCertificate(0, 0, 0, buf, size, hash, NULL);
1596 /* Test empty hash */
1597 ret = CryptHashCertificate(0, 0, 0, toHash, sizeof(toHash), NULL,
1598 &hashLen);
1599 ok(ret, "CryptHashCertificate failed: %08x\n", GetLastError());
1600 ok(hashLen == sizeof(hash), "Got unexpected size of hash %d\n", hashLen);
1601 /* Test with empty buffer */
1602 ret = CryptHashCertificate(0, 0, 0, NULL, 0, hash, &hashLen);
1603 ok(ret, "CryptHashCertificate failed: %08x\n", GetLastError());
1604 ok(!memcmp(hash, emptyHash, sizeof(emptyHash)),
1605 "Unexpected hash of nothing\n");
1606 /* Test a known value */
1607 ret = CryptHashCertificate(0, 0, 0, toHash, sizeof(toHash), hash,
1608 &hashLen);
1609 ok(ret, "CryptHashCertificate failed: %08x\n", GetLastError());
1610 ok(!memcmp(hash, knownHash, sizeof(knownHash)), "Unexpected hash\n");
1613 static void verifySig(HCRYPTPROV csp, const BYTE *toSign, size_t toSignLen,
1614 const BYTE *sig, unsigned int sigLen)
1616 HCRYPTHASH hash;
1617 BOOL ret = CryptCreateHash(csp, CALG_SHA1, 0, 0, &hash);
1619 ok(ret, "CryptCreateHash failed: %08x\n", GetLastError());
1620 if (ret)
1622 BYTE mySig[64];
1623 DWORD mySigSize = sizeof(mySig);
1625 ret = CryptHashData(hash, toSign, toSignLen, 0);
1626 ok(ret, "CryptHashData failed: %08x\n", GetLastError());
1627 /* use the A variant so the test can run on Win9x */
1628 ret = CryptSignHashA(hash, AT_SIGNATURE, NULL, 0, mySig, &mySigSize);
1629 ok(ret, "CryptSignHash failed: %08x\n", GetLastError());
1630 if (ret)
1632 ok(mySigSize == sigLen, "Expected sig length %d, got %d\n",
1633 sigLen, mySigSize);
1634 ok(!memcmp(mySig, sig, sigLen), "Unexpected signature\n");
1636 CryptDestroyHash(hash);
1640 /* Tests signing the certificate described by toBeSigned with the CSP passed in,
1641 * using the algorithm with OID sigOID. The CSP is assumed to be empty, and a
1642 * keyset named AT_SIGNATURE will be added to it. The signing key will be
1643 * stored in *key, and the signature will be stored in sig. sigLen should be
1644 * at least 64 bytes.
1646 static void testSignCert(HCRYPTPROV csp, const CRYPT_DATA_BLOB *toBeSigned,
1647 LPCSTR sigOID, HCRYPTKEY *key, BYTE *sig, DWORD *sigLen)
1649 BOOL ret;
1650 DWORD size = 0;
1651 CRYPT_ALGORITHM_IDENTIFIER algoID = { NULL, { 0, NULL } };
1653 /* These all crash
1654 ret = CryptSignCertificate(0, 0, 0, NULL, 0, NULL, NULL, NULL, NULL);
1655 ret = CryptSignCertificate(0, 0, 0, NULL, 0, NULL, NULL, NULL, &size);
1656 ret = CryptSignCertificate(0, 0, 0, toBeSigned->pbData, toBeSigned->cbData,
1657 NULL, NULL, NULL, &size);
1659 ret = CryptSignCertificate(0, 0, 0, toBeSigned->pbData, toBeSigned->cbData,
1660 &algoID, NULL, NULL, &size);
1661 ok(!ret && GetLastError() == NTE_BAD_ALGID,
1662 "Expected NTE_BAD_ALGID, got %08x\n", GetLastError());
1663 algoID.pszObjId = (LPSTR)sigOID;
1664 ret = CryptSignCertificate(0, 0, 0, toBeSigned->pbData, toBeSigned->cbData,
1665 &algoID, NULL, NULL, &size);
1666 ok(!ret &&
1667 (GetLastError() == ERROR_INVALID_PARAMETER || GetLastError() == NTE_BAD_ALGID),
1668 "Expected ERROR_INVALID_PARAMETER or NTE_BAD_ALGID, got %08x\n",
1669 GetLastError());
1670 ret = CryptSignCertificate(0, AT_SIGNATURE, 0, toBeSigned->pbData,
1671 toBeSigned->cbData, &algoID, NULL, NULL, &size);
1672 ok(!ret &&
1673 (GetLastError() == ERROR_INVALID_PARAMETER || GetLastError() == NTE_BAD_ALGID),
1674 "Expected ERROR_INVALID_PARAMETER or NTE_BAD_ALGID, got %08x\n",
1675 GetLastError());
1677 /* No keys exist in the new CSP yet.. */
1678 ret = CryptSignCertificate(csp, AT_SIGNATURE, 0, toBeSigned->pbData,
1679 toBeSigned->cbData, &algoID, NULL, NULL, &size);
1680 ok(!ret && (GetLastError() == NTE_BAD_KEYSET || GetLastError() ==
1681 NTE_NO_KEY), "Expected NTE_BAD_KEYSET or NTE_NO_KEY, got %08x\n",
1682 GetLastError());
1683 ret = CryptGenKey(csp, AT_SIGNATURE, 0, key);
1684 ok(ret, "CryptGenKey failed: %08x\n", GetLastError());
1685 if (ret)
1687 ret = CryptSignCertificate(csp, AT_SIGNATURE, 0, toBeSigned->pbData,
1688 toBeSigned->cbData, &algoID, NULL, NULL, &size);
1689 ok(ret, "CryptSignCertificate failed: %08x\n", GetLastError());
1690 ok(size <= *sigLen, "Expected size <= %d, got %d\n", *sigLen, size);
1691 if (ret)
1693 ret = CryptSignCertificate(csp, AT_SIGNATURE, 0, toBeSigned->pbData,
1694 toBeSigned->cbData, &algoID, NULL, sig, &size);
1695 ok(ret, "CryptSignCertificate failed: %08x\n", GetLastError());
1696 if (ret)
1698 *sigLen = size;
1699 verifySig(csp, toBeSigned->pbData, toBeSigned->cbData, sig,
1700 size);
1706 static void testVerifyCertSig(HCRYPTPROV csp, const CRYPT_DATA_BLOB *toBeSigned,
1707 LPCSTR sigOID, const BYTE *sig, DWORD sigLen)
1709 CERT_SIGNED_CONTENT_INFO info;
1710 LPBYTE cert = NULL;
1711 DWORD size = 0;
1712 BOOL ret;
1714 if (!pCryptVerifyCertificateSignatureEx)
1716 win_skip("no CryptVerifyCertificateSignatureEx support\n");
1717 return;
1719 if (!pCryptEncodeObjectEx)
1721 win_skip("no CryptEncodeObjectEx support\n");
1722 return;
1724 ret = pCryptVerifyCertificateSignatureEx(0, 0, 0, NULL, 0, NULL, 0, NULL);
1725 ok(!ret && GetLastError() == E_INVALIDARG,
1726 "Expected E_INVALIDARG, got %08x\n", GetLastError());
1727 ret = pCryptVerifyCertificateSignatureEx(csp, 0, 0, NULL, 0, NULL, 0, NULL);
1728 ok(!ret && GetLastError() == E_INVALIDARG,
1729 "Expected E_INVALIDARG, got %08x\n", GetLastError());
1730 ret = pCryptVerifyCertificateSignatureEx(csp, X509_ASN_ENCODING, 0, NULL, 0,
1731 NULL, 0, NULL);
1732 ok(!ret && GetLastError() == E_INVALIDARG,
1733 "Expected E_INVALIDARG, got %08x\n", GetLastError());
1734 /* This crashes
1735 ret = pCryptVerifyCertificateSignatureEx(csp, X509_ASN_ENCODING,
1736 CRYPT_VERIFY_CERT_SIGN_SUBJECT_BLOB, NULL, 0, NULL, 0, NULL);
1738 info.ToBeSigned.cbData = toBeSigned->cbData;
1739 info.ToBeSigned.pbData = toBeSigned->pbData;
1740 info.SignatureAlgorithm.pszObjId = (LPSTR)sigOID;
1741 info.SignatureAlgorithm.Parameters.cbData = 0;
1742 info.Signature.cbData = sigLen;
1743 info.Signature.pbData = (BYTE *)sig;
1744 info.Signature.cUnusedBits = 0;
1745 ret = pCryptEncodeObjectEx(X509_ASN_ENCODING, X509_CERT, &info,
1746 CRYPT_ENCODE_ALLOC_FLAG, NULL, &cert, &size);
1747 ok(ret, "CryptEncodeObjectEx failed: %08x\n", GetLastError());
1748 if (cert)
1750 CRYPT_DATA_BLOB certBlob = { 0, NULL };
1751 PCERT_PUBLIC_KEY_INFO pubKeyInfo = NULL;
1753 ret = pCryptVerifyCertificateSignatureEx(csp, X509_ASN_ENCODING,
1754 CRYPT_VERIFY_CERT_SIGN_SUBJECT_BLOB, &certBlob, 0, NULL, 0, NULL);
1755 ok(!ret && GetLastError() == CRYPT_E_ASN1_EOD,
1756 "Expected CRYPT_E_ASN1_EOD, got %08x\n", GetLastError());
1757 certBlob.cbData = 1;
1758 certBlob.pbData = (void *)0xdeadbeef;
1759 ret = pCryptVerifyCertificateSignatureEx(csp, X509_ASN_ENCODING,
1760 CRYPT_VERIFY_CERT_SIGN_SUBJECT_BLOB, &certBlob, 0, NULL, 0, NULL);
1761 ok(!ret && (GetLastError() == STATUS_ACCESS_VIOLATION ||
1762 GetLastError() == CRYPT_E_ASN1_EOD /* Win9x */ ||
1763 GetLastError() == CRYPT_E_ASN1_BADTAG /* Win98 */),
1764 "Expected STATUS_ACCESS_VIOLATION, CRYPT_E_ASN1_EOD, OR CRYPT_E_ASN1_BADTAG, got %08x\n",
1765 GetLastError());
1767 certBlob.cbData = size;
1768 certBlob.pbData = cert;
1769 ret = pCryptVerifyCertificateSignatureEx(csp, X509_ASN_ENCODING,
1770 CRYPT_VERIFY_CERT_SIGN_SUBJECT_BLOB, &certBlob, 0, NULL, 0, NULL);
1771 ok(!ret && GetLastError() == E_INVALIDARG,
1772 "Expected E_INVALIDARG, got %08x\n", GetLastError());
1773 ret = pCryptVerifyCertificateSignatureEx(csp, X509_ASN_ENCODING,
1774 CRYPT_VERIFY_CERT_SIGN_SUBJECT_BLOB, &certBlob,
1775 CRYPT_VERIFY_CERT_SIGN_ISSUER_NULL, NULL, 0, NULL);
1776 ok(!ret && GetLastError() == E_INVALIDARG,
1777 "Expected E_INVALIDARG, got %08x\n", GetLastError());
1778 /* This crashes
1779 ret = pCryptVerifyCertificateSignatureEx(csp, X509_ASN_ENCODING,
1780 CRYPT_VERIFY_CERT_SIGN_SUBJECT_BLOB, &certBlob,
1781 CRYPT_VERIFY_CERT_SIGN_ISSUER_PUBKEY, NULL, 0, NULL);
1783 CryptExportPublicKeyInfoEx(csp, AT_SIGNATURE, X509_ASN_ENCODING,
1784 (LPSTR)sigOID, 0, NULL, NULL, &size);
1785 pubKeyInfo = HeapAlloc(GetProcessHeap(), 0, size);
1786 if (pubKeyInfo)
1788 ret = CryptExportPublicKeyInfoEx(csp, AT_SIGNATURE,
1789 X509_ASN_ENCODING, (LPSTR)sigOID, 0, NULL, pubKeyInfo, &size);
1790 ok(ret, "CryptExportKey failed: %08x\n", GetLastError());
1791 if (ret)
1793 ret = pCryptVerifyCertificateSignatureEx(csp, X509_ASN_ENCODING,
1794 CRYPT_VERIFY_CERT_SIGN_SUBJECT_BLOB, &certBlob,
1795 CRYPT_VERIFY_CERT_SIGN_ISSUER_PUBKEY, pubKeyInfo, 0, NULL);
1796 ok(ret, "CryptVerifyCertificateSignatureEx failed: %08x\n",
1797 GetLastError());
1799 HeapFree(GetProcessHeap(), 0, pubKeyInfo);
1801 LocalFree(cert);
1805 static BYTE emptyCert[] = { 0x30, 0x00 };
1807 static void testCertSigs(void)
1809 HCRYPTPROV csp;
1810 CRYPT_DATA_BLOB toBeSigned = { sizeof(emptyCert), emptyCert };
1811 BOOL ret;
1812 HCRYPTKEY key;
1813 BYTE sig[64];
1814 DWORD sigSize = sizeof(sig);
1816 /* Just in case a previous run failed, delete this thing */
1817 pCryptAcquireContextA(&csp, cspNameA, MS_DEF_PROV_A, PROV_RSA_FULL,
1818 CRYPT_DELETEKEYSET);
1819 ret = pCryptAcquireContextA(&csp, cspNameA, MS_DEF_PROV_A, PROV_RSA_FULL,
1820 CRYPT_NEWKEYSET);
1821 ok(ret, "CryptAcquireContext failed: %08x\n", GetLastError());
1823 testSignCert(csp, &toBeSigned, szOID_RSA_SHA1RSA, &key, sig, &sigSize);
1824 testVerifyCertSig(csp, &toBeSigned, szOID_RSA_SHA1RSA, sig, sigSize);
1826 CryptDestroyKey(key);
1827 CryptReleaseContext(csp, 0);
1828 ret = pCryptAcquireContextA(&csp, cspNameA, MS_DEF_PROV_A, PROV_RSA_FULL,
1829 CRYPT_DELETEKEYSET);
1832 static const BYTE md5SignedEmptyCert[] = {
1833 0x30,0x56,0x30,0x33,0x02,0x00,0x30,0x02,0x06,0x00,0x30,0x22,0x18,0x0f,0x31,0x36,
1834 0x30,0x31,0x30,0x31,0x30,0x31,0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x18,0x0f,0x31,
1835 0x36,0x30,0x31,0x30,0x31,0x30,0x31,0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x30,0x07,
1836 0x30,0x02,0x06,0x00,0x03,0x01,0x00,0x30,0x0c,0x06,0x08,0x2a,0x86,0x48,0x86,0xf7,
1837 0x0d,0x02,0x05,0x05,0x00,0x03,0x11,0x00,0xfb,0x0f,0x66,0x82,0x66,0xd9,0xe5,0xf8,
1838 0xd8,0xa2,0x55,0x2b,0xe1,0xa5,0xd9,0x04 };
1839 static const BYTE md5SignedEmptyCertNoNull[] = {
1840 0x30,0x54,0x30,0x33,0x02,0x00,0x30,0x02,0x06,0x00,0x30,0x22,0x18,0x0f,0x31,0x36,
1841 0x30,0x31,0x30,0x31,0x30,0x31,0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x18,0x0f,0x31,
1842 0x36,0x30,0x31,0x30,0x31,0x30,0x31,0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x30,0x07,
1843 0x30,0x02,0x06,0x00,0x03,0x01,0x00,0x30,0x0a,0x06,0x08,0x2a,0x86,0x48,0x86,0xf7,
1844 0x0d,0x02,0x05,0x03,0x11,0x00,0x04,0xd9,0xa5,0xe1,0x2b,0x55,0xa2,0xd8,0xf8,0xe5,
1845 0xd9,0x66,0x82,0x66,0x0f,0xfb };
1847 static void testSignAndEncodeCert(void)
1849 static char oid_rsa_md5rsa[] = szOID_RSA_MD5RSA;
1850 static char oid_rsa_md5[] = szOID_RSA_MD5;
1851 BOOL ret;
1852 DWORD size;
1853 CRYPT_ALGORITHM_IDENTIFIER algID = { 0 };
1854 CERT_INFO info = { 0 };
1856 /* Crash
1857 ret = CryptSignAndEncodeCertificate(0, 0, 0, NULL, NULL, NULL, NULL, NULL,
1858 NULL);
1859 ret = CryptSignAndEncodeCertificate(0, 0, 0, NULL, NULL, NULL, NULL, NULL,
1860 &size);
1862 ret = CryptSignAndEncodeCertificate(0, 0, 0, NULL, NULL, &algID, NULL, NULL,
1863 &size);
1864 ok(!ret && GetLastError() == ERROR_FILE_NOT_FOUND,
1865 "Expected ERROR_FILE_NOT_FOUND, got %08x\n", GetLastError());
1866 ret = CryptSignAndEncodeCertificate(0, 0, X509_ASN_ENCODING, NULL, NULL,
1867 &algID, NULL, NULL, &size);
1868 ok(!ret && GetLastError() == ERROR_FILE_NOT_FOUND,
1869 "Expected ERROR_FILE_NOT_FOUND, got %08x\n", GetLastError());
1870 ret = CryptSignAndEncodeCertificate(0, 0, 0, X509_CERT_TO_BE_SIGNED, NULL,
1871 &algID, NULL, NULL, &size);
1872 ok(!ret && GetLastError() == ERROR_FILE_NOT_FOUND,
1873 "Expected ERROR_FILE_NOT_FOUND, got %08x\n", GetLastError());
1874 /* Crashes on some win9x boxes */
1875 if (0)
1877 ret = CryptSignAndEncodeCertificate(0, 0, X509_ASN_ENCODING,
1878 X509_CERT_TO_BE_SIGNED, NULL, &algID, NULL, NULL, &size);
1879 ok(!ret && GetLastError() == STATUS_ACCESS_VIOLATION,
1880 "Expected STATUS_ACCESS_VIOLATION, got %08x\n", GetLastError());
1882 /* Crashes
1883 ret = CryptSignAndEncodeCertificate(0, 0, X509_ASN_ENCODING,
1884 X509_CERT_TO_BE_SIGNED, &info, NULL, NULL, NULL, &size);
1886 ret = CryptSignAndEncodeCertificate(0, 0, X509_ASN_ENCODING,
1887 X509_CERT_TO_BE_SIGNED, &info, &algID, NULL, NULL, &size);
1888 ok(!ret &&
1889 (GetLastError() == NTE_BAD_ALGID ||
1890 GetLastError() == OSS_BAD_PTR), /* win9x */
1891 "Expected NTE_BAD_ALGID, got %08x\n", GetLastError());
1892 algID.pszObjId = oid_rsa_md5rsa;
1893 ret = CryptSignAndEncodeCertificate(0, 0, X509_ASN_ENCODING,
1894 X509_CERT_TO_BE_SIGNED, &info, &algID, NULL, NULL, &size);
1895 ok(!ret &&
1896 (GetLastError() == ERROR_INVALID_PARAMETER ||
1897 GetLastError() == NTE_BAD_ALGID ||
1898 GetLastError() == OSS_BAD_PTR), /* Win9x */
1899 "Expected ERROR_INVALID_PARAMETER or NTE_BAD_ALGID, got %08x\n",
1900 GetLastError());
1901 algID.pszObjId = oid_rsa_md5;
1902 ret = CryptSignAndEncodeCertificate(0, 0, X509_ASN_ENCODING,
1903 X509_CERT_TO_BE_SIGNED, &info, &algID, NULL, NULL, &size);
1904 /* oid_rsa_md5 not present in some win2k */
1905 if (ret)
1907 LPBYTE buf = HeapAlloc(GetProcessHeap(), 0, size);
1909 if (buf)
1911 ret = CryptSignAndEncodeCertificate(0, 0, X509_ASN_ENCODING,
1912 X509_CERT_TO_BE_SIGNED, &info, &algID, NULL, buf, &size);
1913 ok(ret, "CryptSignAndEncodeCertificate failed: %08x\n",
1914 GetLastError());
1915 /* Tricky: because the NULL parameters may either be omitted or
1916 * included as an asn.1-encoded NULL (0x05,0x00), two different
1917 * values are allowed.
1919 ok(size == sizeof(md5SignedEmptyCert) ||
1920 size == sizeof(md5SignedEmptyCertNoNull), "Unexpected size %d\n",
1921 size);
1922 if (size == sizeof(md5SignedEmptyCert))
1923 ok(!memcmp(buf, md5SignedEmptyCert, size),
1924 "Unexpected value\n");
1925 else if (size == sizeof(md5SignedEmptyCertNoNull))
1926 ok(!memcmp(buf, md5SignedEmptyCertNoNull, size),
1927 "Unexpected value\n");
1928 HeapFree(GetProcessHeap(), 0, buf);
1933 static void testCreateSelfSignCert(void)
1935 PCCERT_CONTEXT context;
1936 CERT_NAME_BLOB name = { sizeof(subjectName), subjectName };
1937 HCRYPTPROV csp;
1938 BOOL ret;
1939 HCRYPTKEY key;
1940 CRYPT_KEY_PROV_INFO info;
1942 if (!pCertCreateSelfSignCertificate)
1944 win_skip("CertCreateSelfSignCertificate() is not available\n");
1945 return;
1948 /* This crashes:
1949 context = pCertCreateSelfSignCertificate(0, NULL, 0, NULL, NULL, NULL, NULL,
1950 NULL);
1951 * Calling this with no first parameter creates a new key container, which
1952 * lasts beyond the test, so I don't test that. Nb: the generated key
1953 * name is a GUID.
1954 context = pCertCreateSelfSignCertificate(0, &name, 0, NULL, NULL, NULL, NULL,
1955 NULL);
1958 /* Acquire a CSP */
1959 pCryptAcquireContextA(&csp, cspNameA, MS_DEF_PROV_A, PROV_RSA_FULL,
1960 CRYPT_DELETEKEYSET);
1961 ret = pCryptAcquireContextA(&csp, cspNameA, MS_DEF_PROV_A, PROV_RSA_FULL,
1962 CRYPT_NEWKEYSET);
1963 ok(ret, "CryptAcquireContext failed: %08x\n", GetLastError());
1965 context = pCertCreateSelfSignCertificate(csp, &name, 0, NULL, NULL, NULL,
1966 NULL, NULL);
1967 ok(!context && GetLastError() == NTE_NO_KEY,
1968 "Expected NTE_NO_KEY, got %08x\n", GetLastError());
1969 ret = CryptGenKey(csp, AT_SIGNATURE, 0, &key);
1970 ok(ret, "CryptGenKey failed: %08x\n", GetLastError());
1971 if (ret)
1973 context = pCertCreateSelfSignCertificate(csp, &name, 0, NULL, NULL, NULL,
1974 NULL, NULL);
1975 ok(context != NULL, "CertCreateSelfSignCertificate failed: %08x\n",
1976 GetLastError());
1977 if (context)
1979 DWORD size = 0;
1980 PCRYPT_KEY_PROV_INFO info;
1982 /* The context must have a key provider info property */
1983 ret = CertGetCertificateContextProperty(context,
1984 CERT_KEY_PROV_INFO_PROP_ID, NULL, &size);
1985 ok(ret && size, "Expected non-zero key provider info\n");
1986 if (size)
1988 info = HeapAlloc(GetProcessHeap(), 0, size);
1989 if (info)
1991 ret = CertGetCertificateContextProperty(context,
1992 CERT_KEY_PROV_INFO_PROP_ID, info, &size);
1993 ok(ret, "CertGetCertificateContextProperty failed: %08x\n",
1994 GetLastError());
1995 if (ret)
1997 /* Sanity-check the key provider */
1998 ok(!lstrcmpW(info->pwszContainerName, cspNameW),
1999 "Unexpected key container\n");
2000 ok(!lstrcmpW(info->pwszProvName, MS_DEF_PROV_W),
2001 "Unexpected provider\n");
2002 ok(info->dwKeySpec == AT_SIGNATURE,
2003 "Expected AT_SIGNATURE, got %d\n", info->dwKeySpec);
2005 HeapFree(GetProcessHeap(), 0, info);
2009 CertFreeCertificateContext(context);
2012 CryptDestroyKey(key);
2015 CryptReleaseContext(csp, 0);
2016 ret = pCryptAcquireContextA(&csp, cspNameA, MS_DEF_PROV_A, PROV_RSA_FULL,
2017 CRYPT_DELETEKEYSET);
2019 /* do the same test with AT_KEYEXCHANGE and key info*/
2020 memset(&info,0,sizeof(info));
2021 info.dwProvType = PROV_RSA_FULL;
2022 info.dwKeySpec = AT_KEYEXCHANGE;
2023 info.pwszProvName = (LPWSTR) MS_DEF_PROV_W;
2024 info.pwszContainerName = cspNameW;
2025 context = pCertCreateSelfSignCertificate(0, &name, 0, &info, NULL, NULL,
2026 NULL, NULL);
2027 ok(context != NULL, "CertCreateSelfSignCertificate failed: %08x\n",
2028 GetLastError());
2029 if (context)
2031 DWORD size = 0;
2032 PCRYPT_KEY_PROV_INFO info;
2034 /* The context must have a key provider info property */
2035 ret = CertGetCertificateContextProperty(context,
2036 CERT_KEY_PROV_INFO_PROP_ID, NULL, &size);
2037 ok(ret && size, "Expected non-zero key provider info\n");
2038 if (size)
2040 info = HeapAlloc(GetProcessHeap(), 0, size);
2041 if (info)
2043 ret = CertGetCertificateContextProperty(context,
2044 CERT_KEY_PROV_INFO_PROP_ID, info, &size);
2045 ok(ret, "CertGetCertificateContextProperty failed: %08x\n",
2046 GetLastError());
2047 if (ret)
2049 /* Sanity-check the key provider */
2050 ok(!lstrcmpW(info->pwszContainerName, cspNameW),
2051 "Unexpected key container\n");
2052 ok(!lstrcmpW(info->pwszProvName, MS_DEF_PROV_W),
2053 "Unexpected provider\n");
2054 ok(info->dwKeySpec == AT_KEYEXCHANGE,
2055 "Expected AT_KEYEXCHANGE, got %d\n", info->dwKeySpec);
2057 HeapFree(GetProcessHeap(), 0, info);
2061 CertFreeCertificateContext(context);
2064 pCryptAcquireContextA(&csp, cspNameA, MS_DEF_PROV_A, PROV_RSA_FULL,
2065 CRYPT_DELETEKEYSET);
2068 static const LPCSTR keyUsages[] = { szOID_PKIX_KP_CODE_SIGNING,
2069 szOID_PKIX_KP_CLIENT_AUTH, szOID_RSA_RSA };
2071 static void testKeyUsage(void)
2073 BOOL ret;
2074 PCCERT_CONTEXT context;
2075 DWORD size;
2077 /* Test base cases */
2078 ret = CertGetEnhancedKeyUsage(NULL, 0, NULL, NULL);
2079 ok(!ret && GetLastError() == ERROR_INVALID_PARAMETER,
2080 "Expected ERROR_INVALID_PARAMETER, got %08x\n", GetLastError());
2081 size = 1;
2082 ret = CertGetEnhancedKeyUsage(NULL, 0, NULL, &size);
2083 ok(!ret && GetLastError() == ERROR_INVALID_PARAMETER,
2084 "Expected ERROR_INVALID_PARAMETER, got %08x\n", GetLastError());
2085 size = 0;
2086 ret = CertGetEnhancedKeyUsage(NULL, 0, NULL, &size);
2087 ok(!ret && GetLastError() == ERROR_INVALID_PARAMETER,
2088 "Expected ERROR_INVALID_PARAMETER, got %08x\n", GetLastError());
2089 /* These crash
2090 ret = CertSetEnhancedKeyUsage(NULL, NULL);
2091 usage.cUsageIdentifier = 0;
2092 ret = CertSetEnhancedKeyUsage(NULL, &usage);
2094 /* Test with a cert with no enhanced key usage extension */
2095 context = CertCreateCertificateContext(X509_ASN_ENCODING, bigCert,
2096 sizeof(bigCert));
2097 ok(context != NULL, "CertCreateCertificateContext failed: %08x\n",
2098 GetLastError());
2099 if (context)
2101 static const char oid[] = "1.2.3.4";
2102 BYTE buf[sizeof(CERT_ENHKEY_USAGE) + 2 * (sizeof(LPSTR) + sizeof(oid))];
2103 PCERT_ENHKEY_USAGE pUsage = (PCERT_ENHKEY_USAGE)buf;
2105 ret = CertGetEnhancedKeyUsage(context, 0, NULL, NULL);
2106 ok(!ret && GetLastError() == ERROR_INVALID_PARAMETER,
2107 "Expected ERROR_INVALID_PARAMETER, got %08x\n", GetLastError());
2108 size = 1;
2109 ret = CertGetEnhancedKeyUsage(context, 0, NULL, &size);
2110 if (ret)
2112 /* Windows 2000, ME, or later: even though it succeeded, we expect
2113 * CRYPT_E_NOT_FOUND, which indicates there is no enhanced key
2114 * usage set for this cert (which implies it's valid for all uses.)
2116 ok(GetLastError() == CRYPT_E_NOT_FOUND,
2117 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
2118 ok(size == sizeof(CERT_ENHKEY_USAGE), "Wrong size %d\n", size);
2119 ret = CertGetEnhancedKeyUsage(context, 0, pUsage, &size);
2120 ok(ret, "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2121 ok(pUsage->cUsageIdentifier == 0, "Expected 0 usages, got %d\n",
2122 pUsage->cUsageIdentifier);
2124 else
2126 /* Windows NT, 95, or 98: it fails, and the last error is
2127 * CRYPT_E_NOT_FOUND.
2129 ok(GetLastError() == CRYPT_E_NOT_FOUND,
2130 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
2132 /* I can add a usage identifier when no key usage has been set */
2133 ret = CertAddEnhancedKeyUsageIdentifier(context, oid);
2134 ok(ret, "CertAddEnhancedKeyUsageIdentifier failed: %08x\n",
2135 GetLastError());
2136 size = sizeof(buf);
2137 ret = CertGetEnhancedKeyUsage(context,
2138 CERT_FIND_PROP_ONLY_ENHKEY_USAGE_FLAG, pUsage, &size);
2139 ok(ret && GetLastError() == 0,
2140 "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2141 ok(pUsage->cUsageIdentifier == 1, "Expected 1 usage, got %d\n",
2142 pUsage->cUsageIdentifier);
2143 if (pUsage->cUsageIdentifier)
2144 ok(!strcmp(pUsage->rgpszUsageIdentifier[0], oid),
2145 "Expected %s, got %s\n", oid, pUsage->rgpszUsageIdentifier[0]);
2146 /* Now set an empty key usage */
2147 pUsage->cUsageIdentifier = 0;
2148 ret = CertSetEnhancedKeyUsage(context, pUsage);
2149 ok(ret, "CertSetEnhancedKeyUsage failed: %08x\n", GetLastError());
2150 /* Shouldn't find it in the cert */
2151 size = sizeof(buf);
2152 ret = CertGetEnhancedKeyUsage(context,
2153 CERT_FIND_EXT_ONLY_ENHKEY_USAGE_FLAG, pUsage, &size);
2154 ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
2155 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
2156 /* Should find it as an extended property */
2157 ret = CertGetEnhancedKeyUsage(context,
2158 CERT_FIND_PROP_ONLY_ENHKEY_USAGE_FLAG, pUsage, &size);
2159 ok(ret && GetLastError() == 0,
2160 "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2161 ok(pUsage->cUsageIdentifier == 0, "Expected 0 usages, got %d\n",
2162 pUsage->cUsageIdentifier);
2163 /* Should find it as either */
2164 ret = CertGetEnhancedKeyUsage(context, 0, pUsage, &size);
2165 ok(ret && GetLastError() == 0,
2166 "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2167 ok(pUsage->cUsageIdentifier == 0, "Expected 0 usages, got %d\n",
2168 pUsage->cUsageIdentifier);
2169 /* Add a usage identifier */
2170 ret = CertAddEnhancedKeyUsageIdentifier(context, oid);
2171 ok(ret, "CertAddEnhancedKeyUsageIdentifier failed: %08x\n",
2172 GetLastError());
2173 size = sizeof(buf);
2174 ret = CertGetEnhancedKeyUsage(context, 0, pUsage, &size);
2175 ok(ret && GetLastError() == 0,
2176 "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2177 ok(pUsage->cUsageIdentifier == 1, "Expected 1 identifier, got %d\n",
2178 pUsage->cUsageIdentifier);
2179 if (pUsage->cUsageIdentifier)
2180 ok(!strcmp(pUsage->rgpszUsageIdentifier[0], oid),
2181 "Expected %s, got %s\n", oid, pUsage->rgpszUsageIdentifier[0]);
2182 /* Re-adding the same usage identifier succeeds, though it only adds
2183 * a duplicate usage identifier on versions prior to Vista
2185 ret = CertAddEnhancedKeyUsageIdentifier(context, oid);
2186 ok(ret, "CertAddEnhancedKeyUsageIdentifier failed: %08x\n",
2187 GetLastError());
2188 size = sizeof(buf);
2189 ret = CertGetEnhancedKeyUsage(context, 0, pUsage, &size);
2190 ok(ret && GetLastError() == 0,
2191 "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2192 ok(pUsage->cUsageIdentifier == 1 || pUsage->cUsageIdentifier == 2,
2193 "Expected 1 or 2 identifiers, got %d\n", pUsage->cUsageIdentifier);
2194 if (pUsage->cUsageIdentifier)
2195 ok(!strcmp(pUsage->rgpszUsageIdentifier[0], oid),
2196 "Expected %s, got %s\n", oid, pUsage->rgpszUsageIdentifier[0]);
2197 if (pUsage->cUsageIdentifier >= 2)
2198 ok(!strcmp(pUsage->rgpszUsageIdentifier[1], oid),
2199 "Expected %s, got %s\n", oid, pUsage->rgpszUsageIdentifier[1]);
2200 /* Now set a NULL extended property--this deletes the property. */
2201 ret = CertSetEnhancedKeyUsage(context, NULL);
2202 ok(ret, "CertSetEnhancedKeyUsage failed: %08x\n", GetLastError());
2203 SetLastError(0xbaadcafe);
2204 size = sizeof(buf);
2205 ret = CertGetEnhancedKeyUsage(context, 0, pUsage, &size);
2206 ok(GetLastError() == CRYPT_E_NOT_FOUND,
2207 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
2209 CertFreeCertificateContext(context);
2211 /* Now test with a cert with an enhanced key usage extension */
2212 context = CertCreateCertificateContext(X509_ASN_ENCODING, certWithUsage,
2213 sizeof(certWithUsage));
2214 ok(context != NULL, "CertCreateCertificateContext failed: %08x\n",
2215 GetLastError());
2216 if (context)
2218 LPBYTE buf = NULL;
2219 DWORD bufSize = 0, i;
2221 /* The size may depend on what flags are used to query it, so I
2222 * realloc the buffer for each test.
2224 ret = CertGetEnhancedKeyUsage(context,
2225 CERT_FIND_EXT_ONLY_ENHKEY_USAGE_FLAG, NULL, &bufSize);
2226 ok(ret, "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2227 buf = HeapAlloc(GetProcessHeap(), 0, bufSize);
2228 if (buf)
2230 PCERT_ENHKEY_USAGE pUsage = (PCERT_ENHKEY_USAGE)buf;
2232 /* Should find it in the cert */
2233 size = bufSize;
2234 ret = CertGetEnhancedKeyUsage(context,
2235 CERT_FIND_EXT_ONLY_ENHKEY_USAGE_FLAG, pUsage, &size);
2236 ok(ret && GetLastError() == 0,
2237 "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2238 ok(pUsage->cUsageIdentifier == 3, "Expected 3 usages, got %d\n",
2239 pUsage->cUsageIdentifier);
2240 for (i = 0; i < pUsage->cUsageIdentifier; i++)
2241 ok(!strcmp(pUsage->rgpszUsageIdentifier[i], keyUsages[i]),
2242 "Expected %s, got %s\n", keyUsages[i],
2243 pUsage->rgpszUsageIdentifier[i]);
2244 HeapFree(GetProcessHeap(), 0, buf);
2246 ret = CertGetEnhancedKeyUsage(context, 0, NULL, &bufSize);
2247 ok(ret, "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2248 buf = HeapAlloc(GetProcessHeap(), 0, bufSize);
2249 if (buf)
2251 PCERT_ENHKEY_USAGE pUsage = (PCERT_ENHKEY_USAGE)buf;
2253 /* Should find it as either */
2254 size = bufSize;
2255 ret = CertGetEnhancedKeyUsage(context, 0, pUsage, &size);
2256 /* In Windows, GetLastError returns CRYPT_E_NOT_FOUND not found
2257 * here, even though the return is successful and the usage id
2258 * count is positive. I don't enforce that here.
2260 ok(ret,
2261 "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2262 ok(pUsage->cUsageIdentifier == 3, "Expected 3 usages, got %d\n",
2263 pUsage->cUsageIdentifier);
2264 for (i = 0; i < pUsage->cUsageIdentifier; i++)
2265 ok(!strcmp(pUsage->rgpszUsageIdentifier[i], keyUsages[i]),
2266 "Expected %s, got %s\n", keyUsages[i],
2267 pUsage->rgpszUsageIdentifier[i]);
2268 HeapFree(GetProcessHeap(), 0, buf);
2270 /* Shouldn't find it as an extended property */
2271 ret = CertGetEnhancedKeyUsage(context,
2272 CERT_FIND_PROP_ONLY_ENHKEY_USAGE_FLAG, NULL, &size);
2273 ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
2274 "Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
2275 /* Adding a usage identifier overrides the cert's usage!? */
2276 ret = CertAddEnhancedKeyUsageIdentifier(context, szOID_RSA_RSA);
2277 ok(ret, "CertAddEnhancedKeyUsageIdentifier failed: %08x\n",
2278 GetLastError());
2279 ret = CertGetEnhancedKeyUsage(context, 0, NULL, &bufSize);
2280 ok(ret, "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2281 buf = HeapAlloc(GetProcessHeap(), 0, bufSize);
2282 if (buf)
2284 PCERT_ENHKEY_USAGE pUsage = (PCERT_ENHKEY_USAGE)buf;
2286 /* Should find it as either */
2287 size = bufSize;
2288 ret = CertGetEnhancedKeyUsage(context, 0, pUsage, &size);
2289 ok(ret,
2290 "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2291 ok(pUsage->cUsageIdentifier == 1, "Expected 1 usage, got %d\n",
2292 pUsage->cUsageIdentifier);
2293 ok(!strcmp(pUsage->rgpszUsageIdentifier[0], szOID_RSA_RSA),
2294 "Expected %s, got %s\n", szOID_RSA_RSA,
2295 pUsage->rgpszUsageIdentifier[0]);
2296 HeapFree(GetProcessHeap(), 0, buf);
2298 /* But querying the cert directly returns its usage */
2299 ret = CertGetEnhancedKeyUsage(context,
2300 CERT_FIND_EXT_ONLY_ENHKEY_USAGE_FLAG, NULL, &bufSize);
2301 ok(ret, "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2302 buf = HeapAlloc(GetProcessHeap(), 0, bufSize);
2303 if (buf)
2305 PCERT_ENHKEY_USAGE pUsage = (PCERT_ENHKEY_USAGE)buf;
2307 size = bufSize;
2308 ret = CertGetEnhancedKeyUsage(context,
2309 CERT_FIND_EXT_ONLY_ENHKEY_USAGE_FLAG, pUsage, &size);
2310 ok(ret,
2311 "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2312 ok(pUsage->cUsageIdentifier == 3, "Expected 3 usages, got %d\n",
2313 pUsage->cUsageIdentifier);
2314 for (i = 0; i < pUsage->cUsageIdentifier; i++)
2315 ok(!strcmp(pUsage->rgpszUsageIdentifier[i], keyUsages[i]),
2316 "Expected %s, got %s\n", keyUsages[i],
2317 pUsage->rgpszUsageIdentifier[i]);
2318 HeapFree(GetProcessHeap(), 0, buf);
2320 /* And removing the only usage identifier in the extended property
2321 * results in the cert's key usage being found.
2323 ret = CertRemoveEnhancedKeyUsageIdentifier(context, szOID_RSA_RSA);
2324 ok(ret, "CertRemoveEnhancedKeyUsage failed: %08x\n", GetLastError());
2325 ret = CertGetEnhancedKeyUsage(context, 0, NULL, &bufSize);
2326 ok(ret, "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2327 buf = HeapAlloc(GetProcessHeap(), 0, bufSize);
2328 if (buf)
2330 PCERT_ENHKEY_USAGE pUsage = (PCERT_ENHKEY_USAGE)buf;
2332 /* Should find it as either */
2333 size = bufSize;
2334 ret = CertGetEnhancedKeyUsage(context, 0, pUsage, &size);
2335 ok(ret,
2336 "CertGetEnhancedKeyUsage failed: %08x\n", GetLastError());
2337 ok(pUsage->cUsageIdentifier == 3, "Expected 3 usages, got %d\n",
2338 pUsage->cUsageIdentifier);
2339 for (i = 0; i < pUsage->cUsageIdentifier; i++)
2340 ok(!strcmp(pUsage->rgpszUsageIdentifier[i], keyUsages[i]),
2341 "Expected %s, got %s\n", keyUsages[i],
2342 pUsage->rgpszUsageIdentifier[i]);
2343 HeapFree(GetProcessHeap(), 0, buf);
2346 CertFreeCertificateContext(context);
2350 static const BYTE cert2WithUsage[] = {
2351 0x30,0x81,0x89,0x02,0x01,0x01,0x30,0x02,0x06,0x00,0x30,0x15,0x31,0x13,0x30,
2352 0x11,0x06,0x03,0x55,0x04,0x03,0x13,0x0a,0x4a,0x75,0x61,0x6e,0x20,0x4c,0x61,
2353 0x6e,0x67,0x00,0x30,0x22,0x18,0x0f,0x31,0x36,0x30,0x31,0x30,0x31,0x30,0x31,
2354 0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x18,0x0f,0x31,0x36,0x30,0x31,0x30,0x31,
2355 0x30,0x31,0x30,0x30,0x30,0x30,0x30,0x30,0x5a,0x30,0x15,0x31,0x13,0x30,0x11,
2356 0x06,0x03,0x55,0x04,0x03,0x13,0x0a,0x4a,0x75,0x61,0x6e,0x20,0x4c,0x61,0x6e,
2357 0x67,0x00,0x30,0x07,0x30,0x02,0x06,0x00,0x03,0x01,0x00,0xa3,0x25,0x30,0x23,
2358 0x30,0x21,0x06,0x03,0x55,0x1d,0x25,0x01,0x01,0xff,0x04,0x17,0x30,0x15,0x06,
2359 0x08,0x2b,0x06,0x01,0x05,0x05,0x07,0x03,0x02,0x06,0x09,0x2a,0x86,0x48,0x86,
2360 0xf7,0x0d,0x01,0x01,0x01 };
2362 static void testGetValidUsages(void)
2364 static const LPCSTR expectedOIDs[] = {
2365 "1.3.6.1.5.5.7.3.3",
2366 "1.3.6.1.5.5.7.3.2",
2367 "1.2.840.113549.1.1.1",
2369 static const LPCSTR expectedOIDs2[] = {
2370 "1.3.6.1.5.5.7.3.2",
2371 "1.2.840.113549.1.1.1",
2373 BOOL ret;
2374 int numOIDs;
2375 DWORD size;
2376 LPSTR *oids = NULL;
2377 PCCERT_CONTEXT contexts[3];
2379 if (!pCertGetValidUsages)
2381 win_skip("CertGetValidUsages() is not available\n");
2382 return;
2385 /* Crash
2386 ret = pCertGetValidUsages(0, NULL, NULL, NULL, NULL);
2387 ret = pCertGetValidUsages(0, NULL, NULL, NULL, &size);
2389 contexts[0] = NULL;
2390 numOIDs = size = 0xdeadbeef;
2391 SetLastError(0xdeadbeef);
2392 ret = pCertGetValidUsages(1, &contexts[0], &numOIDs, NULL, &size);
2393 ok(ret, "CertGetValidUsages failed: %d\n", GetLastError());
2394 ok(numOIDs == -1, "Expected -1, got %d\n", numOIDs);
2395 ok(size == 0, "Expected size 0, got %d\n", size);
2396 contexts[0] = CertCreateCertificateContext(X509_ASN_ENCODING, bigCert,
2397 sizeof(bigCert));
2398 contexts[1] = CertCreateCertificateContext(X509_ASN_ENCODING, certWithUsage,
2399 sizeof(certWithUsage));
2400 contexts[2] = CertCreateCertificateContext(X509_ASN_ENCODING,
2401 cert2WithUsage, sizeof(cert2WithUsage));
2402 numOIDs = size = 0xdeadbeef;
2403 ret = pCertGetValidUsages(0, NULL, &numOIDs, NULL, &size);
2404 ok(ret, "CertGetValidUsages failed: %08x\n", GetLastError());
2405 ok(numOIDs == -1, "Expected -1, got %d\n", numOIDs);
2406 ok(size == 0, "Expected size 0, got %d\n", size);
2407 numOIDs = size = 0xdeadbeef;
2408 ret = pCertGetValidUsages(1, contexts, &numOIDs, NULL, &size);
2409 ok(ret, "CertGetValidUsages failed: %08x\n", GetLastError());
2410 ok(numOIDs == -1, "Expected -1, got %d\n", numOIDs);
2411 ok(size == 0, "Expected size 0, got %d\n", size);
2412 ret = pCertGetValidUsages(1, &contexts[1], &numOIDs, NULL, &size);
2413 ok(ret, "CertGetValidUsages failed: %08x\n", GetLastError());
2414 ok(numOIDs == 3, "Expected 3, got %d\n", numOIDs);
2415 ok(size, "Expected non-zero size\n");
2416 oids = HeapAlloc(GetProcessHeap(), 0, size);
2417 if (oids)
2419 int i;
2420 DWORD smallSize = 1;
2422 SetLastError(0xdeadbeef);
2423 ret = pCertGetValidUsages(1, &contexts[1], &numOIDs, oids, &smallSize);
2424 ok(!ret && GetLastError() == ERROR_MORE_DATA,
2425 "Expected ERROR_MORE_DATA, got %d\n", GetLastError());
2426 ret = pCertGetValidUsages(1, &contexts[1], &numOIDs, oids, &size);
2427 ok(ret, "CertGetValidUsages failed: %08x\n", GetLastError());
2428 for (i = 0; i < numOIDs; i++)
2429 ok(!lstrcmpA(oids[i], expectedOIDs[i]), "unexpected OID %s\n",
2430 oids[i]);
2431 HeapFree(GetProcessHeap(), 0, oids);
2433 numOIDs = size = 0xdeadbeef;
2434 /* Oddly enough, this crashes when the number of contexts is not 1:
2435 ret = pCertGetValidUsages(2, contexts, &numOIDs, NULL, &size);
2436 * but setting size to 0 allows it to succeed:
2438 size = 0;
2439 ret = pCertGetValidUsages(2, contexts, &numOIDs, NULL, &size);
2440 ok(ret, "CertGetValidUsages failed: %08x\n", GetLastError());
2441 ok(numOIDs == 3, "Expected 3, got %d\n", numOIDs);
2442 ok(size, "Expected non-zero size\n");
2443 oids = HeapAlloc(GetProcessHeap(), 0, size);
2444 if (oids)
2446 int i;
2448 ret = pCertGetValidUsages(1, &contexts[1], &numOIDs, oids, &size);
2449 ok(ret, "CertGetValidUsages failed: %08x\n", GetLastError());
2450 for (i = 0; i < numOIDs; i++)
2451 ok(!lstrcmpA(oids[i], expectedOIDs[i]), "unexpected OID %s\n",
2452 oids[i]);
2453 HeapFree(GetProcessHeap(), 0, oids);
2455 numOIDs = 0xdeadbeef;
2456 size = 0;
2457 ret = pCertGetValidUsages(1, &contexts[2], &numOIDs, NULL, &size);
2458 ok(ret, "CertGetValidUsages failed: %08x\n", GetLastError());
2459 ok(numOIDs == 2, "Expected 2, got %d\n", numOIDs);
2460 ok(size, "Expected non-zero size\n");
2461 oids = HeapAlloc(GetProcessHeap(), 0, size);
2462 if (oids)
2464 int i;
2466 ret = pCertGetValidUsages(1, &contexts[2], &numOIDs, oids, &size);
2467 ok(ret, "CertGetValidUsages failed: %08x\n", GetLastError());
2468 for (i = 0; i < numOIDs; i++)
2469 ok(!lstrcmpA(oids[i], expectedOIDs2[i]), "unexpected OID %s\n",
2470 oids[i]);
2471 HeapFree(GetProcessHeap(), 0, oids);
2473 numOIDs = 0xdeadbeef;
2474 size = 0;
2475 ret = pCertGetValidUsages(3, contexts, &numOIDs, NULL, &size);
2476 ok(ret, "CertGetValidUsages failed: %08x\n", GetLastError());
2477 ok(numOIDs == 2, "Expected 2, got %d\n", numOIDs);
2478 ok(size, "Expected non-zero size\n");
2479 oids = HeapAlloc(GetProcessHeap(), 0, size);
2480 if (oids)
2482 int i;
2484 ret = pCertGetValidUsages(3, contexts, &numOIDs, oids, &size);
2485 ok(ret, "CertGetValidUsages failed: %08x\n", GetLastError());
2486 for (i = 0; i < numOIDs; i++)
2487 ok(!lstrcmpA(oids[i], expectedOIDs2[i]), "unexpected OID %s\n",
2488 oids[i]);
2489 HeapFree(GetProcessHeap(), 0, oids);
2491 CertFreeCertificateContext(contexts[0]);
2492 CertFreeCertificateContext(contexts[1]);
2493 CertFreeCertificateContext(contexts[2]);
2496 static void testCompareCertName(void)
2498 static BYTE bogus[] = { 1, 2, 3, 4 };
2499 static BYTE bogusPrime[] = { 0, 1, 2, 3, 4 };
2500 static BYTE emptyPrime[] = { 0x30, 0x00, 0x01 };
2501 BOOL ret;
2502 CERT_NAME_BLOB blob1, blob2;
2504 /* crashes
2505 ret = CertCompareCertificateName(0, NULL, NULL);
2507 /* An empty name checks against itself.. */
2508 blob1.pbData = emptyCert;
2509 blob1.cbData = sizeof(emptyCert);
2510 ret = CertCompareCertificateName(0, &blob1, &blob1);
2511 ok(ret, "CertCompareCertificateName failed: %08x\n", GetLastError());
2512 /* It doesn't have to be a valid encoded name.. */
2513 blob1.pbData = bogus;
2514 blob1.cbData = sizeof(bogus);
2515 ret = CertCompareCertificateName(0, &blob1, &blob1);
2516 ok(ret, "CertCompareCertificateName failed: %08x\n", GetLastError());
2517 /* Leading zeroes matter.. */
2518 blob2.pbData = bogusPrime;
2519 blob2.cbData = sizeof(bogusPrime);
2520 ret = CertCompareCertificateName(0, &blob1, &blob2);
2521 ok(!ret, "Expected failure\n");
2522 /* As do trailing extra bytes. */
2523 blob2.pbData = emptyPrime;
2524 blob2.cbData = sizeof(emptyPrime);
2525 ret = CertCompareCertificateName(0, &blob1, &blob2);
2526 ok(!ret, "Expected failure\n");
2529 static BYTE int1[] = { 0x88, 0xff, 0xff, 0xff };
2530 static BYTE int2[] = { 0x88, 0xff };
2531 static BYTE int3[] = { 0x23, 0xff };
2532 static BYTE int4[] = { 0x7f, 0x00 };
2533 static BYTE int5[] = { 0x7f };
2534 static BYTE int6[] = { 0x80, 0x00, 0x00, 0x00 };
2535 static BYTE int7[] = { 0x80, 0x00 };
2537 static struct IntBlobTest
2539 CRYPT_INTEGER_BLOB blob1;
2540 CRYPT_INTEGER_BLOB blob2;
2541 BOOL areEqual;
2542 } intBlobs[] = {
2543 { { sizeof(int1), int1 }, { sizeof(int2), int2 }, TRUE },
2544 { { sizeof(int3), int3 }, { sizeof(int3), int3 }, TRUE },
2545 { { sizeof(int4), int4 }, { sizeof(int5), int5 }, TRUE },
2546 { { sizeof(int6), int6 }, { sizeof(int7), int7 }, TRUE },
2547 { { sizeof(int1), int1 }, { sizeof(int7), int7 }, FALSE },
2550 static void testCompareIntegerBlob(void)
2552 DWORD i;
2553 BOOL ret;
2555 for (i = 0; i < sizeof(intBlobs) / sizeof(intBlobs[0]); i++)
2557 ret = CertCompareIntegerBlob(&intBlobs[i].blob1, &intBlobs[i].blob2);
2558 ok(ret == intBlobs[i].areEqual,
2559 "%d: expected blobs %s compare\n", i, intBlobs[i].areEqual ?
2560 "to" : "not to");
2564 static void testComparePublicKeyInfo(void)
2566 BOOL ret;
2567 CERT_PUBLIC_KEY_INFO info1 = { { 0 } }, info2 = { { 0 } };
2568 static CHAR oid_rsa_rsa[] = szOID_RSA_RSA;
2569 static CHAR oid_rsa_sha1rsa[] = szOID_RSA_SHA1RSA;
2570 static CHAR oid_x957_dsa[] = szOID_X957_DSA;
2571 static BYTE bits1[] = { 1, 0 };
2572 static BYTE bits2[] = { 0 };
2573 static BYTE bits3[] = { 1 };
2574 static BYTE bits4[] = { 0x30,8, 2,1,0x81, 2,3,1,0,1 };
2575 static BYTE bits5[] = { 0x30,9, 2,2,0,0x81, 2,3,1,0,1 };
2576 static BYTE bits6[] = { 0x30,9, 2,2,0,0x82, 2,3,1,0,1 };
2578 /* crashes
2579 ret = CertComparePublicKeyInfo(0, NULL, NULL);
2581 /* Empty public keys compare */
2582 ret = CertComparePublicKeyInfo(0, &info1, &info2);
2583 ok(ret, "CertComparePublicKeyInfo failed: %08x\n", GetLastError());
2584 /* Different OIDs appear to compare */
2585 info1.Algorithm.pszObjId = oid_rsa_rsa;
2586 info2.Algorithm.pszObjId = oid_rsa_sha1rsa;
2587 ret = CertComparePublicKeyInfo(0, &info1, &info2);
2588 ok(ret, "CertComparePublicKeyInfo failed: %08x\n", GetLastError());
2589 info2.Algorithm.pszObjId = oid_x957_dsa;
2590 ret = CertComparePublicKeyInfo(0, &info1, &info2);
2591 ok(ret, "CertComparePublicKeyInfo failed: %08x\n", GetLastError());
2592 info1.PublicKey.cbData = sizeof(bits1);
2593 info1.PublicKey.pbData = bits1;
2594 info1.PublicKey.cUnusedBits = 0;
2595 info2.PublicKey.cbData = sizeof(bits1);
2596 info2.PublicKey.pbData = bits1;
2597 info2.PublicKey.cUnusedBits = 0;
2598 ret = CertComparePublicKeyInfo(0, &info1, &info2);
2599 ok(ret, "CertComparePublicKeyInfo failed: %08x\n", GetLastError());
2600 info2.Algorithm.pszObjId = oid_rsa_rsa;
2601 info1.PublicKey.cbData = sizeof(bits4);
2602 info1.PublicKey.pbData = bits4;
2603 info1.PublicKey.cUnusedBits = 0;
2604 info2.PublicKey.cbData = sizeof(bits5);
2605 info2.PublicKey.pbData = bits5;
2606 info2.PublicKey.cUnusedBits = 0;
2607 ret = CertComparePublicKeyInfo(0, &info1, &info2);
2608 ok(!ret, "CertComparePublicKeyInfo: as raw binary: keys should be unequal\n");
2609 ret = CertComparePublicKeyInfo(X509_ASN_ENCODING, &info1, &info2);
2610 ok(ret ||
2611 broken(!ret), /* win9x */
2612 "CertComparePublicKeyInfo: as ASN.1 encoded: keys should be equal\n");
2613 info1.PublicKey.cUnusedBits = 1;
2614 info2.PublicKey.cUnusedBits = 5;
2615 ret = CertComparePublicKeyInfo(X509_ASN_ENCODING, &info1, &info2);
2616 ok(ret ||
2617 broken(!ret), /* win9x */
2618 "CertComparePublicKeyInfo: ASN.1 encoding should ignore cUnusedBits\n");
2619 info1.PublicKey.cUnusedBits = 0;
2620 info2.PublicKey.cUnusedBits = 0;
2621 info1.PublicKey.cbData--; /* kill one byte, make ASN.1 encoded data invalid */
2622 ret = CertComparePublicKeyInfo(X509_ASN_ENCODING, &info1, &info2);
2623 ok(!ret, "CertComparePublicKeyInfo: comparing bad ASN.1 encoded key should fail\n");
2624 /* Even though they compare in their used bits, these do not compare */
2625 info1.PublicKey.cbData = sizeof(bits2);
2626 info1.PublicKey.pbData = bits2;
2627 info1.PublicKey.cUnusedBits = 0;
2628 info2.PublicKey.cbData = sizeof(bits3);
2629 info2.PublicKey.pbData = bits3;
2630 info2.PublicKey.cUnusedBits = 1;
2631 ret = CertComparePublicKeyInfo(0, &info1, &info2);
2632 /* Simple (non-comparing) case */
2633 ok(!ret, "Expected keys not to compare\n");
2634 info2.PublicKey.cbData = sizeof(bits1);
2635 info2.PublicKey.pbData = bits1;
2636 info2.PublicKey.cUnusedBits = 0;
2637 ret = CertComparePublicKeyInfo(0, &info1, &info2);
2638 ok(!ret, "Expected keys not to compare\n");
2639 /* ASN.1 encoded non-comparing case */
2640 info1.PublicKey.cbData = sizeof(bits5);
2641 info1.PublicKey.pbData = bits5;
2642 info1.PublicKey.cUnusedBits = 0;
2643 info2.PublicKey.cbData = sizeof(bits6);
2644 info2.PublicKey.pbData = bits6;
2645 info2.PublicKey.cUnusedBits = 0;
2646 ret = CertComparePublicKeyInfo(X509_ASN_ENCODING, &info1, &info2);
2647 ok(!ret, "CertComparePublicKeyInfo: different keys should be unequal\n");
2650 static void testHashPublicKeyInfo(void)
2652 BOOL ret;
2653 CERT_PUBLIC_KEY_INFO info = { { 0 } };
2654 DWORD len;
2656 /* Crash
2657 ret = CryptHashPublicKeyInfo(0, 0, 0, 0, NULL, NULL, NULL);
2658 ret = CryptHashPublicKeyInfo(0, 0, 0, 0, &info, NULL, NULL);
2660 ret = CryptHashPublicKeyInfo(0, 0, 0, 0, NULL, NULL, &len);
2661 ok(!ret && GetLastError() == ERROR_FILE_NOT_FOUND,
2662 "Expected ERROR_FILE_NOT_FOUND, got %08x\n", GetLastError());
2663 /* Crashes on some win9x boxes */
2664 if (0)
2666 ret = CryptHashPublicKeyInfo(0, 0, 0, X509_ASN_ENCODING, NULL, NULL, &len);
2667 ok(!ret && GetLastError() == STATUS_ACCESS_VIOLATION,
2668 "Expected STATUS_ACCESS_VIOLATION, got %08x\n", GetLastError());
2670 ret = CryptHashPublicKeyInfo(0, 0, 0, X509_ASN_ENCODING, &info, NULL, &len);
2671 ok(ret ||
2672 broken(!ret), /* win9x */
2673 "CryptHashPublicKeyInfo failed: %08x\n", GetLastError());
2674 if (ret)
2676 ok(len == 16, "Expected hash size 16, got %d\n", len);
2677 if (len == 16)
2679 static const BYTE emptyHash[] = { 0xb8,0x51,0x3a,0x31,0x0e,0x9f,0x40,
2680 0x36,0x9c,0x92,0x45,0x1b,0x9d,0xc8,0xf9,0xf6 };
2681 BYTE buf[16];
2683 ret = CryptHashPublicKeyInfo(0, 0, 0, X509_ASN_ENCODING, &info, buf,
2684 &len);
2685 ok(ret, "CryptHashPublicKeyInfo failed: %08x\n", GetLastError());
2686 ok(!memcmp(buf, emptyHash, len), "Unexpected hash\n");
2691 static const BYTE md5SignedEmptyCertHash[] = { 0xfb,0x0f,0x66,0x82,0x66,0xd9,
2692 0xe5,0xf8,0xd8,0xa2,0x55,0x2b,0xe1,0xa5,0xd9,0x04 };
2694 static void testHashToBeSigned(void)
2696 BOOL ret;
2697 DWORD size;
2698 BYTE hash[16];
2700 /* Crash */
2701 if (0)
2703 ret = CryptHashToBeSigned(0, 0, NULL, 0, NULL, NULL);
2705 SetLastError(0xdeadbeef);
2706 ret = CryptHashToBeSigned(0, 0, NULL, 0, NULL, &size);
2707 ok(!ret && GetLastError() == ERROR_FILE_NOT_FOUND,
2708 "expected ERROR_FILE_NOT_FOUND, got %d\n", GetLastError());
2709 SetLastError(0xdeadbeef);
2710 ret = CryptHashToBeSigned(0, X509_ASN_ENCODING, NULL, 0, NULL, &size);
2711 ok(!ret &&
2712 (GetLastError() == CRYPT_E_ASN1_EOD ||
2713 GetLastError() == OSS_BAD_ARG), /* win9x */
2714 "expected CRYPT_E_ASN1_EOD, got %08x\n", GetLastError());
2715 /* Can't sign anything: has to be asn.1 encoded, at least */
2716 SetLastError(0xdeadbeef);
2717 ret = CryptHashToBeSigned(0, X509_ASN_ENCODING, int1, sizeof(int1),
2718 NULL, &size);
2719 ok(!ret &&
2720 (GetLastError() == CRYPT_E_ASN1_BADTAG ||
2721 GetLastError() == OSS_MORE_INPUT), /* win9x */
2722 "expected CRYPT_E_ASN1_BADTAG, got %08x\n", GetLastError());
2723 /* Can't be empty, either */
2724 SetLastError(0xdeadbeef);
2725 ret = CryptHashToBeSigned(0, X509_ASN_ENCODING, emptyCert,
2726 sizeof(emptyCert), NULL, &size);
2727 ok(!ret &&
2728 (GetLastError() == CRYPT_E_ASN1_CORRUPT ||
2729 GetLastError() == OSS_DATA_ERROR), /* win9x */
2730 "expected CRYPT_E_ASN1_CORRUPT, got %08x\n", GetLastError());
2731 /* Signing a cert works */
2732 ret = CryptHashToBeSigned(0, X509_ASN_ENCODING, md5SignedEmptyCert,
2733 sizeof(md5SignedEmptyCert), NULL, &size);
2734 ok(ret ||
2735 broken(!ret), /* win9x */
2736 "CryptHashToBeSigned failed: %08x\n", GetLastError());
2737 if (ret)
2739 ok(size == sizeof(md5SignedEmptyCertHash), "unexpected size %d\n", size);
2742 ret = CryptHashToBeSigned(0, X509_ASN_ENCODING, md5SignedEmptyCert,
2743 sizeof(md5SignedEmptyCert), hash, &size);
2744 ok(!memcmp(hash, md5SignedEmptyCertHash, size), "unexpected value\n");
2747 static void testCompareCert(void)
2749 CERT_INFO info1 = { 0 }, info2 = { 0 };
2750 BOOL ret;
2752 /* Crashes
2753 ret = CertCompareCertificate(X509_ASN_ENCODING, NULL, NULL);
2756 /* Certs with the same issuer and serial number are equal, even if they
2757 * differ in other respects (like subject).
2759 info1.SerialNumber.pbData = serialNum;
2760 info1.SerialNumber.cbData = sizeof(serialNum);
2761 info1.Issuer.pbData = subjectName;
2762 info1.Issuer.cbData = sizeof(subjectName);
2763 info1.Subject.pbData = subjectName2;
2764 info1.Subject.cbData = sizeof(subjectName2);
2765 info2.SerialNumber.pbData = serialNum;
2766 info2.SerialNumber.cbData = sizeof(serialNum);
2767 info2.Issuer.pbData = subjectName;
2768 info2.Issuer.cbData = sizeof(subjectName);
2769 info2.Subject.pbData = subjectName;
2770 info2.Subject.cbData = sizeof(subjectName);
2771 ret = CertCompareCertificate(X509_ASN_ENCODING, &info1, &info2);
2772 ok(ret, "Expected certs to be equal\n");
2774 info2.Issuer.pbData = subjectName2;
2775 info2.Issuer.cbData = sizeof(subjectName2);
2776 ret = CertCompareCertificate(X509_ASN_ENCODING, &info1, &info2);
2777 ok(!ret, "Expected certs not to be equal\n");
2780 static void testVerifySubjectCert(void)
2782 BOOL ret;
2783 DWORD flags;
2784 PCCERT_CONTEXT context1, context2;
2786 /* Crashes
2787 ret = CertVerifySubjectCertificateContext(NULL, NULL, NULL);
2789 flags = 0;
2790 ret = CertVerifySubjectCertificateContext(NULL, NULL, &flags);
2791 ok(ret, "CertVerifySubjectCertificateContext failed; %08x\n",
2792 GetLastError());
2793 flags = CERT_STORE_NO_CRL_FLAG;
2794 ret = CertVerifySubjectCertificateContext(NULL, NULL, &flags);
2795 ok(!ret && GetLastError() == E_INVALIDARG,
2796 "Expected E_INVALIDARG, got %08x\n", GetLastError());
2798 flags = 0;
2799 context1 = CertCreateCertificateContext(X509_ASN_ENCODING, bigCert,
2800 sizeof(bigCert));
2801 ret = CertVerifySubjectCertificateContext(NULL, context1, &flags);
2802 ok(ret, "CertVerifySubjectCertificateContext failed; %08x\n",
2803 GetLastError());
2804 ret = CertVerifySubjectCertificateContext(context1, NULL, &flags);
2805 ok(ret, "CertVerifySubjectCertificateContext failed; %08x\n",
2806 GetLastError());
2807 ret = CertVerifySubjectCertificateContext(context1, context1, &flags);
2808 ok(ret, "CertVerifySubjectCertificateContext failed; %08x\n",
2809 GetLastError());
2811 context2 = CertCreateCertificateContext(X509_ASN_ENCODING,
2812 bigCertWithDifferentSubject, sizeof(bigCertWithDifferentSubject));
2813 SetLastError(0xdeadbeef);
2814 ret = CertVerifySubjectCertificateContext(context1, context2, &flags);
2815 ok(ret, "CertVerifySubjectCertificateContext failed; %08x\n",
2816 GetLastError());
2817 flags = CERT_STORE_REVOCATION_FLAG;
2818 ret = CertVerifySubjectCertificateContext(context1, context2, &flags);
2819 ok(ret, "CertVerifySubjectCertificateContext failed; %08x\n",
2820 GetLastError());
2821 ok(flags == (CERT_STORE_REVOCATION_FLAG | CERT_STORE_NO_CRL_FLAG),
2822 "Expected CERT_STORE_REVOCATION_FLAG | CERT_STORE_NO_CRL_FLAG, got %08x\n",
2823 flags);
2824 flags = CERT_STORE_SIGNATURE_FLAG;
2825 ret = CertVerifySubjectCertificateContext(context1, context2, &flags);
2826 ok(ret, "CertVerifySubjectCertificateContext failed; %08x\n",
2827 GetLastError());
2828 ok(flags == CERT_STORE_SIGNATURE_FLAG,
2829 "Expected CERT_STORE_SIGNATURE_FLAG, got %08x\n", flags);
2830 CertFreeCertificateContext(context2);
2832 CertFreeCertificateContext(context1);
2835 static void testVerifyRevocation(void)
2837 BOOL ret;
2838 CERT_REVOCATION_STATUS status = { 0 };
2839 PCCERT_CONTEXT cert = CertCreateCertificateContext(X509_ASN_ENCODING,
2840 bigCert, sizeof(bigCert));
2842 /* Crash
2843 ret = CertVerifyRevocation(0, 0, 0, NULL, 0, NULL, NULL);
2845 SetLastError(0xdeadbeef);
2846 ret = CertVerifyRevocation(0, 0, 0, NULL, 0, NULL, &status);
2847 ok(!ret && GetLastError() == E_INVALIDARG,
2848 "Expected E_INVALIDARG, got %08x\n", GetLastError());
2849 status.cbSize = sizeof(status);
2850 ret = CertVerifyRevocation(0, 0, 0, NULL, 0, NULL, &status);
2851 ok(ret, "CertVerifyRevocation failed: %08x\n", GetLastError());
2852 ret = CertVerifyRevocation(0, 2, 0, NULL, 0, NULL, &status);
2853 ok(ret, "CertVerifyRevocation failed: %08x\n", GetLastError());
2854 ret = CertVerifyRevocation(2, 0, 0, NULL, 0, NULL, &status);
2855 ok(ret, "CertVerifyRevocation failed: %08x\n", GetLastError());
2856 SetLastError(0xdeadbeef);
2857 ret = CertVerifyRevocation(0, 0, 1, (void **)&cert, 0, NULL, &status);
2858 ok(!ret && GetLastError() == CRYPT_E_NO_REVOCATION_DLL,
2859 "Expected CRYPT_E_NO_REVOCATION_DLL, got %08x\n", GetLastError());
2860 SetLastError(0xdeadbeef);
2861 ret = CertVerifyRevocation(0, 2, 1, (void **)&cert, 0, NULL, &status);
2862 ok(!ret && GetLastError() == CRYPT_E_NO_REVOCATION_DLL,
2863 "Expected CRYPT_E_NO_REVOCATION_DLL, got %08x\n", GetLastError());
2865 CertFreeCertificateContext(cert);
2868 static BYTE privKey[] = {
2869 0x07, 0x02, 0x00, 0x00, 0x00, 0x24, 0x00, 0x00, 0x52, 0x53, 0x41, 0x32, 0x00,
2870 0x02, 0x00, 0x00, 0x01, 0x00, 0x01, 0x00, 0x79, 0x10, 0x1c, 0xd0, 0x6b, 0x10,
2871 0x18, 0x30, 0x94, 0x61, 0xdc, 0x0e, 0xcb, 0x96, 0x4e, 0x21, 0x3f, 0x79, 0xcd,
2872 0xa9, 0x17, 0x62, 0xbc, 0xbb, 0x61, 0x4c, 0xe0, 0x75, 0x38, 0x6c, 0xf3, 0xde,
2873 0x60, 0x86, 0x03, 0x97, 0x65, 0xeb, 0x1e, 0x6b, 0xdb, 0x53, 0x85, 0xad, 0x68,
2874 0x21, 0xf1, 0x5d, 0xe7, 0x1f, 0xe6, 0x53, 0xb4, 0xbb, 0x59, 0x3e, 0x14, 0x27,
2875 0xb1, 0x83, 0xa7, 0x3a, 0x54, 0xe2, 0x8f, 0x65, 0x8e, 0x6a, 0x4a, 0xcf, 0x3b,
2876 0x1f, 0x65, 0xff, 0xfe, 0xf1, 0x31, 0x3a, 0x37, 0x7a, 0x8b, 0xcb, 0xc6, 0xd4,
2877 0x98, 0x50, 0x36, 0x67, 0xe4, 0xa1, 0xe8, 0x7e, 0x8a, 0xc5, 0x23, 0xf2, 0x77,
2878 0xf5, 0x37, 0x61, 0x49, 0x72, 0x59, 0xe8, 0x3d, 0xf7, 0x60, 0xb2, 0x77, 0xca,
2879 0x78, 0x54, 0x6d, 0x65, 0x9e, 0x03, 0x97, 0x1b, 0x61, 0xbd, 0x0c, 0xd8, 0x06,
2880 0x63, 0xe2, 0xc5, 0x48, 0xef, 0xb3, 0xe2, 0x6e, 0x98, 0x7d, 0xbd, 0x4e, 0x72,
2881 0x91, 0xdb, 0x31, 0x57, 0xe3, 0x65, 0x3a, 0x49, 0xca, 0xec, 0xd2, 0x02, 0x4e,
2882 0x22, 0x7e, 0x72, 0x8e, 0xf9, 0x79, 0x84, 0x82, 0xdf, 0x7b, 0x92, 0x2d, 0xaf,
2883 0xc9, 0xe4, 0x33, 0xef, 0x89, 0x5c, 0x66, 0x99, 0xd8, 0x80, 0x81, 0x47, 0x2b,
2884 0xb1, 0x66, 0x02, 0x84, 0x59, 0x7b, 0xc3, 0xbe, 0x98, 0x45, 0x4a, 0x3d, 0xdd,
2885 0xea, 0x2b, 0xdf, 0x4e, 0xb4, 0x24, 0x6b, 0xec, 0xe7, 0xd9, 0x0c, 0x45, 0xb8,
2886 0xbe, 0xca, 0x69, 0x37, 0x92, 0x4c, 0x38, 0x6b, 0x96, 0x6d, 0xcd, 0x86, 0x67,
2887 0x5c, 0xea, 0x54, 0x94, 0xa4, 0xca, 0xa4, 0x02, 0xa5, 0x21, 0x4d, 0xae, 0x40,
2888 0x8f, 0x9d, 0x51, 0x83, 0xf2, 0x3f, 0x33, 0xc1, 0x72, 0xb4, 0x1d, 0x94, 0x6e,
2889 0x7d, 0xe4, 0x27, 0x3f, 0xea, 0xff, 0xe5, 0x9b, 0xa7, 0x5e, 0x55, 0x8e, 0x0d,
2890 0x69, 0x1c, 0x7a, 0xff, 0x81, 0x9d, 0x53, 0x52, 0x97, 0x9a, 0x76, 0x79, 0xda,
2891 0x93, 0x32, 0x16, 0xec, 0x69, 0x51, 0x1a, 0x4e, 0xc3, 0xf1, 0x72, 0x80, 0x78,
2892 0x5e, 0x66, 0x4a, 0x8d, 0x85, 0x2f, 0x3f, 0xb2, 0xa7 };
2894 static const BYTE exportedPublicKeyBlob[] = {
2895 0x06,0x02,0x00,0x00,0x00,0xa4,0x00,0x00,0x52,0x53,0x41,0x31,0x00,0x02,0x00,0x00,
2896 0x01,0x00,0x01,0x00,0x79,0x10,0x1c,0xd0,0x6b,0x10,0x18,0x30,0x94,0x61,0xdc,0x0e,
2897 0xcb,0x96,0x4e,0x21,0x3f,0x79,0xcd,0xa9,0x17,0x62,0xbc,0xbb,0x61,0x4c,0xe0,0x75,
2898 0x38,0x6c,0xf3,0xde,0x60,0x86,0x03,0x97,0x65,0xeb,0x1e,0x6b,0xdb,0x53,0x85,0xad,
2899 0x68,0x21,0xf1,0x5d,0xe7,0x1f,0xe6,0x53,0xb4,0xbb,0x59,0x3e,0x14,0x27,0xb1,0x83,
2900 0xa7,0x3a,0x54,0xe2 };
2902 static const BYTE asnEncodedPublicKey[] = {
2903 0x30,0x48,0x02,0x41,0x00,0xe2,0x54,0x3a,0xa7,0x83,0xb1,0x27,0x14,0x3e,0x59,0xbb,
2904 0xb4,0x53,0xe6,0x1f,0xe7,0x5d,0xf1,0x21,0x68,0xad,0x85,0x53,0xdb,0x6b,0x1e,0xeb,
2905 0x65,0x97,0x03,0x86,0x60,0xde,0xf3,0x6c,0x38,0x75,0xe0,0x4c,0x61,0xbb,0xbc,0x62,
2906 0x17,0xa9,0xcd,0x79,0x3f,0x21,0x4e,0x96,0xcb,0x0e,0xdc,0x61,0x94,0x30,0x18,0x10,
2907 0x6b,0xd0,0x1c,0x10,0x79,0x02,0x03,0x01,0x00,0x01 };
2909 static void testAcquireCertPrivateKey(void)
2911 BOOL ret;
2912 PCCERT_CONTEXT cert;
2913 HCRYPTPROV csp;
2914 DWORD size, keySpec;
2915 BOOL callerFree;
2916 CRYPT_KEY_PROV_INFO keyProvInfo;
2917 HCRYPTKEY key;
2918 WCHAR ms_def_prov_w[MAX_PATH];
2920 if (!pCryptAcquireCertificatePrivateKey)
2922 win_skip("CryptAcquireCertificatePrivateKey() is not available\n");
2923 return;
2926 lstrcpyW(ms_def_prov_w, MS_DEF_PROV_W);
2928 keyProvInfo.pwszContainerName = cspNameW;
2929 keyProvInfo.pwszProvName = ms_def_prov_w;
2930 keyProvInfo.dwProvType = PROV_RSA_FULL;
2931 keyProvInfo.dwFlags = 0;
2932 keyProvInfo.cProvParam = 0;
2933 keyProvInfo.rgProvParam = NULL;
2934 keyProvInfo.dwKeySpec = AT_SIGNATURE;
2936 pCryptAcquireContextA(NULL, cspNameA, MS_DEF_PROV_A, PROV_RSA_FULL,
2937 CRYPT_DELETEKEYSET);
2939 cert = CertCreateCertificateContext(X509_ASN_ENCODING, selfSignedCert,
2940 sizeof(selfSignedCert));
2942 /* Crash
2943 ret = pCryptAcquireCertificatePrivateKey(NULL, 0, NULL, NULL, NULL, NULL);
2944 ret = pCryptAcquireCertificatePrivateKey(NULL, 0, NULL, NULL, NULL,
2945 &callerFree);
2946 ret = pCryptAcquireCertificatePrivateKey(NULL, 0, NULL, NULL, &keySpec,
2947 NULL);
2948 ret = pCryptAcquireCertificatePrivateKey(NULL, 0, NULL, &csp, NULL, NULL);
2949 ret = pCryptAcquireCertificatePrivateKey(NULL, 0, NULL, &csp, &keySpec,
2950 &callerFree);
2951 ret = pCryptAcquireCertificatePrivateKey(cert, 0, NULL, NULL, NULL, NULL);
2954 /* Missing private key */
2955 ret = pCryptAcquireCertificatePrivateKey(cert, 0, NULL, &csp, NULL, NULL);
2956 ok(!ret && GetLastError() == CRYPT_E_NO_KEY_PROPERTY,
2957 "Expected CRYPT_E_NO_KEY_PROPERTY, got %08x\n", GetLastError());
2958 ret = pCryptAcquireCertificatePrivateKey(cert, 0, NULL, &csp, &keySpec,
2959 &callerFree);
2960 ok(!ret && GetLastError() == CRYPT_E_NO_KEY_PROPERTY,
2961 "Expected CRYPT_E_NO_KEY_PROPERTY, got %08x\n", GetLastError());
2962 CertSetCertificateContextProperty(cert, CERT_KEY_PROV_INFO_PROP_ID, 0,
2963 &keyProvInfo);
2964 ret = pCryptAcquireCertificatePrivateKey(cert, 0, NULL, &csp, &keySpec,
2965 &callerFree);
2966 ok(!ret && GetLastError() == CRYPT_E_NO_KEY_PROPERTY,
2967 "Expected CRYPT_E_NO_KEY_PROPERTY, got %08x\n", GetLastError());
2969 pCryptAcquireContextA(&csp, cspNameA, MS_DEF_PROV_A, PROV_RSA_FULL,
2970 CRYPT_NEWKEYSET);
2971 ret = CryptImportKey(csp, privKey, sizeof(privKey), 0, 0, &key);
2972 ok(ret, "CryptImportKey failed: %08x\n", GetLastError());
2973 if (ret)
2975 HCRYPTPROV certCSP;
2976 DWORD size;
2977 CERT_KEY_CONTEXT keyContext;
2979 /* Don't cache provider */
2980 ret = pCryptAcquireCertificatePrivateKey(cert, 0, NULL, &certCSP,
2981 &keySpec, &callerFree);
2982 ok(ret ||
2983 broken(!ret), /* win95 */
2984 "CryptAcquireCertificatePrivateKey failed: %08x\n",
2985 GetLastError());
2986 if (ret)
2988 ok(callerFree, "Expected callerFree to be TRUE\n");
2989 CryptReleaseContext(certCSP, 0);
2992 ret = pCryptAcquireCertificatePrivateKey(cert, 0, NULL, &certCSP,
2993 NULL, NULL);
2994 ok(ret ||
2995 broken(!ret), /* win95 */
2996 "CryptAcquireCertificatePrivateKey failed: %08x\n",
2997 GetLastError());
2998 CryptReleaseContext(certCSP, 0);
3000 /* Use the key prov info's caching (there shouldn't be any) */
3001 ret = pCryptAcquireCertificatePrivateKey(cert,
3002 CRYPT_ACQUIRE_USE_PROV_INFO_FLAG, NULL, &certCSP, &keySpec,
3003 &callerFree);
3004 ok(ret ||
3005 broken(!ret), /* win95 */
3006 "CryptAcquireCertificatePrivateKey failed: %08x\n",
3007 GetLastError());
3008 if (ret)
3010 ok(callerFree, "Expected callerFree to be TRUE\n");
3011 CryptReleaseContext(certCSP, 0);
3014 /* Cache it (and check that it's cached) */
3015 ret = pCryptAcquireCertificatePrivateKey(cert,
3016 CRYPT_ACQUIRE_CACHE_FLAG, NULL, &certCSP, &keySpec, &callerFree);
3017 ok(ret ||
3018 broken(!ret), /* win95 */
3019 "CryptAcquireCertificatePrivateKey failed: %08x\n",
3020 GetLastError());
3021 ok(!callerFree, "Expected callerFree to be FALSE\n");
3022 size = sizeof(keyContext);
3023 ret = CertGetCertificateContextProperty(cert, CERT_KEY_CONTEXT_PROP_ID,
3024 &keyContext, &size);
3025 ok(ret ||
3026 broken(!ret), /* win95 */
3027 "CertGetCertificateContextProperty failed: %08x\n",
3028 GetLastError());
3030 /* Remove the cached provider */
3031 CryptReleaseContext(keyContext.hCryptProv, 0);
3032 CertSetCertificateContextProperty(cert, CERT_KEY_CONTEXT_PROP_ID, 0,
3033 NULL);
3034 /* Allow caching via the key prov info */
3035 keyProvInfo.dwFlags = CERT_SET_KEY_CONTEXT_PROP_ID;
3036 CertSetCertificateContextProperty(cert, CERT_KEY_PROV_INFO_PROP_ID, 0,
3037 &keyProvInfo);
3038 /* Now use the key prov info's caching */
3039 ret = pCryptAcquireCertificatePrivateKey(cert,
3040 CRYPT_ACQUIRE_USE_PROV_INFO_FLAG, NULL, &certCSP, &keySpec,
3041 &callerFree);
3042 ok(ret ||
3043 broken(!ret), /* win95 */
3044 "CryptAcquireCertificatePrivateKey failed: %08x\n",
3045 GetLastError());
3046 ok(!callerFree, "Expected callerFree to be FALSE\n");
3047 size = sizeof(keyContext);
3048 ret = CertGetCertificateContextProperty(cert, CERT_KEY_CONTEXT_PROP_ID,
3049 &keyContext, &size);
3050 ok(ret ||
3051 broken(!ret), /* win95 */
3052 "CertGetCertificateContextProperty failed: %08x\n",
3053 GetLastError());
3054 CryptReleaseContext(certCSP, 0);
3056 CryptDestroyKey(key);
3059 /* Some sanity-checking on public key exporting */
3060 ret = CryptImportPublicKeyInfo(csp, X509_ASN_ENCODING,
3061 &cert->pCertInfo->SubjectPublicKeyInfo, &key);
3062 ok(ret, "CryptImportPublicKeyInfo failed: %08x\n", GetLastError());
3063 if (ret)
3065 ret = CryptExportKey(key, 0, PUBLICKEYBLOB, 0, NULL, &size);
3066 ok(ret, "CryptExportKey failed: %08x\n", GetLastError());
3067 if (ret)
3069 LPBYTE buf = HeapAlloc(GetProcessHeap(), 0, size), encodedKey;
3071 ret = CryptExportKey(key, 0, PUBLICKEYBLOB, 0, buf, &size);
3072 ok(ret, "CryptExportKey failed: %08x\n", GetLastError());
3073 ok(size == sizeof(exportedPublicKeyBlob), "Unexpected size %d\n",
3074 size);
3075 ok(!memcmp(buf, exportedPublicKeyBlob, size), "Unexpected value\n");
3076 ret = pCryptEncodeObjectEx(X509_ASN_ENCODING, RSA_CSP_PUBLICKEYBLOB,
3077 buf, CRYPT_ENCODE_ALLOC_FLAG, NULL, &encodedKey, &size);
3078 ok(ret, "CryptEncodeObjectEx failed: %08x\n", GetLastError());
3079 if (ret)
3081 ok(size == sizeof(asnEncodedPublicKey), "Unexpected size %d\n",
3082 size);
3083 ok(!memcmp(encodedKey, asnEncodedPublicKey, size),
3084 "Unexpected value\n");
3085 LocalFree(encodedKey);
3087 HeapFree(GetProcessHeap(), 0, buf);
3089 CryptDestroyKey(key);
3091 ret = CryptExportPublicKeyInfoEx(csp, AT_SIGNATURE, X509_ASN_ENCODING,
3092 NULL, 0, NULL, NULL, &size);
3093 ok(ret, "CryptExportPublicKeyInfoEx failed: %08x\n", GetLastError());
3094 if (ret)
3096 PCERT_PUBLIC_KEY_INFO info = HeapAlloc(GetProcessHeap(), 0, size);
3098 ret = CryptExportPublicKeyInfoEx(csp, AT_SIGNATURE, X509_ASN_ENCODING,
3099 NULL, 0, NULL, info, &size);
3100 ok(ret, "CryptExportPublicKeyInfoEx failed: %08x\n", GetLastError());
3101 if (ret)
3103 ok(info->PublicKey.cbData == sizeof(asnEncodedPublicKey),
3104 "Unexpected size %d\n", info->PublicKey.cbData);
3105 ok(!memcmp(info->PublicKey.pbData, asnEncodedPublicKey,
3106 info->PublicKey.cbData), "Unexpected value\n");
3108 HeapFree(GetProcessHeap(), 0, info);
3111 CryptReleaseContext(csp, 0);
3112 pCryptAcquireContextA(&csp, cspNameA, MS_DEF_PROV_A, PROV_RSA_FULL,
3113 CRYPT_DELETEKEYSET);
3115 CertFreeCertificateContext(cert);
3118 static void testGetPublicKeyLength(void)
3120 static char oid_rsa_rsa[] = szOID_RSA_RSA;
3121 static char oid_rsa_dh[] = szOID_RSA_DH;
3122 static char bogusOID[] = "1.2.3";
3123 DWORD ret;
3124 CERT_PUBLIC_KEY_INFO info = { { 0 } };
3125 BYTE bogusKey[] = { 1, 2, 3, 4, 5, 6, 7, 8 };
3126 BYTE key[] = { 0x30,0x0f,0x02,0x08,0x00,0x01,0x02,0x03,0x04,0x05,0x06,0x07,
3127 0x02,0x03,0x01,0x00,0x01 };
3129 /* Crashes
3130 ret = CertGetPublicKeyLength(0, NULL);
3132 /* With an empty public key info */
3133 SetLastError(0xdeadbeef);
3134 ret = CertGetPublicKeyLength(0, &info);
3135 ok(ret == 0 && GetLastError() == ERROR_FILE_NOT_FOUND,
3136 "Expected length 0 and ERROR_FILE_NOT_FOUND, got length %d, %08x\n",
3137 ret, GetLastError());
3138 SetLastError(0xdeadbeef);
3139 ret = CertGetPublicKeyLength(X509_ASN_ENCODING, &info);
3140 ok(ret == 0 &&
3141 (GetLastError() == CRYPT_E_ASN1_EOD ||
3142 GetLastError() == OSS_BAD_ARG), /* win9x */
3143 "Expected length 0 and CRYPT_E_ASN1_EOD, got length %d, %08x\n",
3144 ret, GetLastError());
3145 /* With a nearly-empty public key info */
3146 info.Algorithm.pszObjId = oid_rsa_rsa;
3147 SetLastError(0xdeadbeef);
3148 ret = CertGetPublicKeyLength(0, &info);
3149 ok(ret == 0 && GetLastError() == ERROR_FILE_NOT_FOUND,
3150 "Expected length 0 and ERROR_FILE_NOT_FOUND, got length %d, %08x\n",
3151 ret, GetLastError());
3152 SetLastError(0xdeadbeef);
3153 ret = CertGetPublicKeyLength(X509_ASN_ENCODING, &info);
3154 ok(ret == 0 &&
3155 (GetLastError() == CRYPT_E_ASN1_EOD ||
3156 GetLastError() == OSS_BAD_ARG), /* win9x */
3157 "Expected length 0 and CRYPT_E_ASN1_EOD, got length %d, %08x\n",
3158 ret, GetLastError());
3159 /* With a bogus key */
3160 info.PublicKey.cbData = sizeof(bogusKey);
3161 info.PublicKey.pbData = bogusKey;
3162 SetLastError(0xdeadbeef);
3163 ret = CertGetPublicKeyLength(0, &info);
3164 ok(ret == 0 && GetLastError() == ERROR_FILE_NOT_FOUND,
3165 "Expected length 0 and ERROR_FILE_NOT_FOUND, got length %d, %08x\n",
3166 ret, GetLastError());
3167 SetLastError(0xdeadbeef);
3168 ret = CertGetPublicKeyLength(X509_ASN_ENCODING, &info);
3169 ok(ret == 0 &&
3170 (GetLastError() == CRYPT_E_ASN1_BADTAG ||
3171 GetLastError() == OSS_PDU_MISMATCH), /* win9x */
3172 "Expected length 0 and CRYPT_E_ASN1_BADTAGTAG, got length %d, %08x\n",
3173 ret, GetLastError());
3174 /* With a believable RSA key but a bogus OID */
3175 info.Algorithm.pszObjId = bogusOID;
3176 info.PublicKey.cbData = sizeof(key);
3177 info.PublicKey.pbData = key;
3178 SetLastError(0xdeadbeef);
3179 ret = CertGetPublicKeyLength(0, &info);
3180 ok(ret == 0 && GetLastError() == ERROR_FILE_NOT_FOUND,
3181 "Expected length 0 and ERROR_FILE_NOT_FOUND, got length %d, %08x\n",
3182 ret, GetLastError());
3183 SetLastError(0xdeadbeef);
3184 ret = CertGetPublicKeyLength(X509_ASN_ENCODING, &info);
3185 ok(ret == 56 || broken(ret == 0 && GetLastError() == NTE_BAD_LEN) /* Win7 */,
3186 "Expected length 56, got %d\n", ret);
3187 /* An RSA key with the DH OID */
3188 info.Algorithm.pszObjId = oid_rsa_dh;
3189 SetLastError(0xdeadbeef);
3190 ret = CertGetPublicKeyLength(X509_ASN_ENCODING, &info);
3191 ok(ret == 0 &&
3192 (GetLastError() == CRYPT_E_ASN1_BADTAG ||
3193 GetLastError() == E_INVALIDARG), /* win9x */
3194 "Expected length 0 and CRYPT_E_ASN1_BADTAG, got length %d, %08x\n",
3195 ret, GetLastError());
3196 /* With the RSA OID */
3197 info.Algorithm.pszObjId = oid_rsa_rsa;
3198 SetLastError(0xdeadbeef);
3199 ret = CertGetPublicKeyLength(X509_ASN_ENCODING, &info);
3200 ok(ret == 56 || broken(ret == 0 && GetLastError() == NTE_BAD_LEN) /* Win7 */,
3201 "Expected length 56, got %d\n", ret);
3202 /* With the RSA OID and a message encoding */
3203 info.Algorithm.pszObjId = oid_rsa_rsa;
3204 SetLastError(0xdeadbeef);
3205 ret = CertGetPublicKeyLength(X509_ASN_ENCODING | PKCS_7_ASN_ENCODING, &info);
3206 ok(ret == 56 || broken(ret == 0 && GetLastError() == NTE_BAD_LEN) /* Win7 */,
3207 "Expected length 56, got %d\n", ret);
3210 START_TEST(cert)
3212 init_function_pointers();
3214 testAddCert();
3215 testCertProperties();
3216 testDupCert();
3217 testFindCert();
3218 testGetSubjectCert();
3219 testGetIssuerCert();
3221 testCryptHashCert();
3222 testCertSigs();
3223 testSignAndEncodeCert();
3224 testCreateSelfSignCert();
3225 testKeyUsage();
3226 testGetValidUsages();
3227 testCompareCertName();
3228 testCompareIntegerBlob();
3229 testComparePublicKeyInfo();
3230 testHashPublicKeyInfo();
3231 testHashToBeSigned();
3232 testCompareCert();
3233 testVerifySubjectCert();
3234 testVerifyRevocation();
3235 testAcquireCertPrivateKey();
3236 testGetPublicKeyLength();