2 * Copyright (c) 2013-2014 Apple Inc. All Rights Reserved.
4 * @APPLE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
21 * @APPLE_LICENSE_HEADER_END@
25 #include <Security/SecBase.h>
26 #include <Security/SecItem.h>
27 #include <Security/SecKey.h>
28 #include "keychain/SecureObjectSync/SOSPeerInfoDER.h"
29 #include "keychain/SecureObjectSync/SOSCircle.h"
30 #include <Security/SecureObjectSync/SOSPeerInfo.h>
31 #include "keychain/SecureObjectSync/SOSInternal.h"
33 #include <utilities/SecCFWrappers.h>
35 #include <CoreFoundation/CoreFoundation.h>
40 #include "SOSCircle_regressions.h"
42 #include "SOSRegressionUtilities.h"
46 typedef struct piStuff_t
{
48 SecKeyRef octagonSigningKey
;
49 SecKeyRef octagonEncryptionKey
;
50 SOSFullPeerInfoRef fpi
;
52 SOSPeerInfoRef resignation_ticket
;
55 static piStuff
*makeSimplePeer(char *name
) {
56 piStuff
*pi
= malloc(sizeof(piStuff
));
59 pi
->signingKey
= NULL
;
60 CFStringRef cfName
= CFStringCreateWithCString(kCFAllocatorDefault
, name
, kCFStringEncodingMacRoman
);
61 pi
->fpi
= SOSCreateFullPeerInfoFromName(cfName
, &pi
->signingKey
, &pi
->octagonSigningKey
, &pi
->octagonEncryptionKey
, NULL
);
62 CFReleaseSafe(cfName
);
63 pi
->pi
= SOSFullPeerInfoGetPeerInfo(pi
->fpi
);
64 pi
->resignation_ticket
= SOSPeerInfoCreateRetirementTicket(kCFAllocatorDefault
, pi
->signingKey
, pi
->pi
, NULL
);
68 static void freeSimplePeer(piStuff
*pi
)
70 CFReleaseSafe(pi
->fpi
);
71 CFReleaseSafe(pi
->signingKey
);
72 CFReleaseSafe(pi
->octagonSigningKey
);
73 CFReleaseSafe(pi
->octagonEncryptionKey
);
74 CFReleaseSafe(pi
->resignation_ticket
);
78 static inline bool retire_me(piStuff
*pi
, size_t seconds
) {
79 return SOSPeerInfoRetireRetirementTicket(seconds
, pi
->resignation_ticket
);
83 static inline bool chkBasicTicket(piStuff
*pi
) {
84 return CFEqual(SOSPeerInfoInspectRetirementTicket(pi
->resignation_ticket
, NULL
), SOSPeerInfoGetPeerID(pi
->pi
));
87 static bool in_between_time(CFDateRef before
, piStuff
*pi
, CFDateRef after
) {
88 CFDateRef during
= SOSPeerInfoGetRetirementDate(pi
->resignation_ticket
);
89 CFTimeInterval time1
= CFDateGetTimeIntervalSinceDate(before
, during
);
90 CFTimeInterval time2
= CFDateGetTimeIntervalSinceDate(during
, after
);
91 CFReleaseNull(during
);
92 if(time1
>= 0.0) return false;
93 if(time2
>= 0.0) return false;
97 static bool PeerInfoRoundTrip(SOSPeerInfoRef pi
) {
99 size_t size
= SOSPeerInfoGetDEREncodedSize(pi
, NULL
);
100 uint8_t buffer
[size
];
101 const uint8_t *buffer_p
= SOSPeerInfoEncodeToDER(pi
, NULL
, buffer
, buffer
+ sizeof(buffer
));
102 ok(buffer_p
!= NULL
, "encode");
103 if(buffer_p
== NULL
) return false;
104 SOSPeerInfoRef pi2
= SOSPeerInfoCreateFromDER(NULL
, NULL
, &buffer_p
, buffer
+ sizeof(buffer
));
105 ok(pi2
!= NULL
, "decode");
106 if(!pi2
) return false;
107 ok(CFEqual(pi
, pi2
), "Decode matches");
108 if(CFEqual(pi
, pi2
)) retval
= true;
113 static void tests(void)
115 CFDateRef before_time
= CFDateCreate(NULL
, CFAbsoluteTimeGetCurrent());
117 piStuff
*iPhone
= makeSimplePeer("iPhone");
118 piStuff
*iPad
= makeSimplePeer("iPad");
119 piStuff
*iMac
= makeSimplePeer("iMac");
120 piStuff
*iDrone
= makeSimplePeer("iDrone");
122 CFDateRef after_time
= CFDateCreate(NULL
, CFAbsoluteTimeGetCurrent());
124 ok(in_between_time(before_time
, iPhone
, after_time
), "retirement date recorded correctly");
125 CFReleaseSafe(before_time
);
126 CFReleaseSafe(after_time
);
127 ok(chkBasicTicket(iPhone
), "peer ID's Match");
128 ok(chkBasicTicket(iPad
), "peer ID's Match");
129 ok(chkBasicTicket(iMac
), "peer ID's Match");
130 ok(chkBasicTicket(iDrone
), "peer ID's Match");
132 // ok(miss_signature(iDrone, iPad), "signature failure detected");
134 ok(!retire_me(iPhone
, 10000), "ticket still valid");
136 ok(retire_me(iPhone
, 1), "ticket not valid");
138 CFDateRef retdate
= SOSPeerInfoGetRetirementDate(iPhone
->resignation_ticket
);
139 ok(retdate
!= NULL
, "got retirement date %@", retdate
);
140 CFReleaseSafe(retdate
);
142 ok(PeerInfoRoundTrip(iPhone
->resignation_ticket
), "retirement ticket safely DERs");
144 CFDateRef appdate
= NULL
;
145 ok((appdate
= SOSPeerInfoGetApplicationDate(iPhone
->resignation_ticket
)) != NULL
, "got application date %@", appdate
);
146 CFReleaseSafe(appdate
);
149 freeSimplePeer(iPhone
);
150 freeSimplePeer(iPad
);
151 freeSimplePeer(iMac
);
152 freeSimplePeer(iDrone
);
157 int sc_130_resignationticket(int argc
, char *const *argv
)