blob: 13692656ff3c1e83724a2096c8cd046a47ab859c [file] [log] [blame]
[email protected]e54d0af2012-03-03 01:07:151// Copyright (c) 2012 The Chromium Authors. All rights reserved.
[email protected]c81d9dcc2010-03-17 00:51:442// Use of this source code is governed by a BSD-style license that can be
3// found in the LICENSE file.
4
[email protected]6e7845ae2013-03-29 21:48:115#ifndef NET_TEST_CERT_TEST_UTIL_H_
6#define NET_TEST_CERT_TEST_UTIL_H_
[email protected]c81d9dcc2010-03-17 00:51:447
[email protected]32765f82010-12-16 00:01:378#include <string>
9
[email protected]3b63f8f42011-03-28 01:54:1510#include "base/memory/ref_counted.h"
[email protected]6e7845ae2013-03-29 21:48:1111#include "net/cert/x509_cert_types.h"
12#include "net/cert/x509_certificate.h"
eromance65aff2017-02-04 00:05:3213#include "testing/gtest/include/gtest/gtest.h"
[email protected]c81d9dcc2010-03-17 00:51:4414
davidben71f35ff2015-04-17 20:54:4815#if defined(USE_NSS_CERTS)
[email protected]83e1ae32014-07-18 10:57:0716// From <pk11pub.h>
17typedef struct PK11SlotInfoStr PK11SlotInfo;
Matt Mueller947a0b82017-08-18 01:43:1618
19#include "net/cert/scoped_nss_types.h"
[email protected]83e1ae32014-07-18 10:57:0720#endif
21
[email protected]a3ef4832013-02-02 05:12:3322namespace base {
[email protected]864b1362010-08-19 03:49:3823class FilePath;
[email protected]a3ef4832013-02-02 05:12:3324}
[email protected]864b1362010-08-19 03:49:3825
[email protected]c81d9dcc2010-03-17 00:51:4426namespace net {
27
[email protected]7d015e42012-03-14 16:15:1228class EVRootCAMetadata;
29
davidben71f35ff2015-04-17 20:54:4830#if defined(USE_NSS_CERTS)
davidben85bad9e2015-05-11 20:20:1031// Imports a private key from file |key_filename| in |dir| into |slot|. The file
32// must contain a PKCS#8 PrivateKeyInfo in DER encoding. Returns true on success
33// and false on failure.
34bool ImportSensitiveKeyFromFile(const base::FilePath& dir,
35 const std::string& key_filename,
36 PK11SlotInfo* slot);
[email protected]cc9b29fb2014-08-02 11:52:2637
Matt Mueller947a0b82017-08-18 01:43:1638ScopedCERTCertificate ImportClientCertToSlot(
39 const scoped_refptr<X509Certificate>& cert,
40 PK11SlotInfo* slot);
[email protected]cc9b29fb2014-08-02 11:52:2641
42scoped_refptr<X509Certificate> ImportClientCertAndKeyFromFile(
43 const base::FilePath& dir,
44 const std::string& cert_filename,
45 const std::string& key_filename,
Matt Mueller947a0b82017-08-18 01:43:1646 PK11SlotInfo* slot,
47 ScopedCERTCertificate* nss_cert);
48scoped_refptr<X509Certificate> ImportClientCertAndKeyFromFile(
49 const base::FilePath& dir,
50 const std::string& cert_filename,
51 const std::string& key_filename,
[email protected]cc9b29fb2014-08-02 11:52:2652 PK11SlotInfo* slot);
[email protected]83e1ae32014-07-18 10:57:0753#endif
54
55// Imports all of the certificates in |cert_file|, a file in |certs_dir|, into a
56// CertificateList.
[email protected]a3ef4832013-02-02 05:12:3357CertificateList CreateCertificateListFromFile(const base::FilePath& certs_dir,
[email protected]e54d0af2012-03-03 01:07:1558 const std::string& cert_file,
59 int format);
60
eromance65aff2017-02-04 00:05:3261// Imports all the certificates given a list of filenames, and assigns the
62// result to |*certs|. The filenames are relative to the test certificates
63// directory.
64::testing::AssertionResult LoadCertificateFiles(
65 const std::vector<std::string>& cert_filenames,
66 CertificateList* certs);
67
[email protected]1f11d6f2013-11-24 22:33:0068// Imports all of the certificates in |cert_file|, a file in |certs_dir|, into
69// a new X509Certificate. The first certificate in the chain will be used for
70// the returned cert, with any additional certificates configured as
71// intermediate certificates.
72scoped_refptr<X509Certificate> CreateCertificateChainFromFile(
73 const base::FilePath& certs_dir,
74 const std::string& cert_file,
75 int format);
76
77// Imports a single certificate from |cert_file|.
[email protected]42fdb452012-11-01 12:44:4078// |certs_dir| represents the test certificates directory. |cert_file| is the
[email protected]32765f82010-12-16 00:01:3779// name of the certificate file. If cert_file contains multiple certificates,
80// the first certificate found will be returned.
[email protected]a3ef4832013-02-02 05:12:3381scoped_refptr<X509Certificate> ImportCertFromFile(const base::FilePath& certs_dir,
[email protected]32765f82010-12-16 00:01:3782 const std::string& cert_file);
[email protected]c81d9dcc2010-03-17 00:51:4483
[email protected]7d015e42012-03-14 16:15:1284// ScopedTestEVPolicy causes certificates marked with |policy|, issued from a
85// root with the given fingerprint, to be treated as EV. |policy| is expressed
86// as a string of dotted numbers: i.e. "1.2.3.4".
87// This should only be used in unittests as adding a CA twice causes a CHECK
88// failure.
89class ScopedTestEVPolicy {
90 public:
91 ScopedTestEVPolicy(EVRootCAMetadata* ev_root_ca_metadata,
[email protected]ede03212012-09-07 12:52:2692 const SHA1HashValue& fingerprint,
[email protected]7d015e42012-03-14 16:15:1293 const char* policy);
94 ~ScopedTestEVPolicy();
95
96 private:
[email protected]ede03212012-09-07 12:52:2697 SHA1HashValue fingerprint_;
[email protected]7d015e42012-03-14 16:15:1298 EVRootCAMetadata* const ev_root_ca_metadata_;
99};
100
[email protected]c81d9dcc2010-03-17 00:51:44101} // namespace net
102
[email protected]6e7845ae2013-03-29 21:48:11103#endif // NET_TEST_CERT_TEST_UTIL_H_