|
9 | 9 | X509Certificate,
|
10 | 10 | createPrivateKey,
|
11 | 11 | generateKeyPairSync,
|
| 12 | + createSign, |
12 | 13 | } = require('crypto');
|
13 | 14 |
|
14 | 15 | const {
|
@@ -190,14 +191,57 @@ const der = Buffer.from(
|
190 | 191 | {
|
191 | 192 | // https://github.com/nodejs/node/issues/45377
|
192 | 193 | // https://github.com/nodejs/node/issues/45485
|
193 |
| - // Confirm failures of X509Certificate:verify() and X509Certificate:CheckPrivateKey() |
| 194 | + // Confirm failures of |
| 195 | + // X509Certificate:verify() |
| 196 | + // X509Certificate:CheckPrivateKey() |
| 197 | + // X509Certificate:CheckCA() |
| 198 | + // X509Certificate:CheckIssued() |
| 199 | + // X509Certificate:ToLegacy() |
194 | 200 | // do not affect other functions that use OpenSSL.
|
195 | 201 | // Subsequent calls to e.g. createPrivateKey should not throw.
|
196 | 202 | const keyPair = generateKeyPairSync('ed25519');
|
197 | 203 | assert(!x509.verify(keyPair.publicKey));
|
198 | 204 | createPrivateKey(key);
|
199 | 205 | assert(!x509.checkPrivateKey(keyPair.privateKey));
|
200 | 206 | createPrivateKey(key);
|
| 207 | + const certPem = ` |
| 208 | +-----BEGIN CERTIFICATE----- |
| 209 | +MIID6zCCAtOgAwIBAgIUTUREAaNcNL0zPkxAlMX0GJtJ/FcwDQYJKoZIhvcNAQEN |
| 210 | +BQAwgYkxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMREwDwYDVQQH |
| 211 | +DAhDYXJsc2JhZDEPMA0GA1UECgwGVmlhc2F0MR0wGwYDVQQLDBRWaWFzYXQgU2Vj |
| 212 | +dXJlIE1vYmlsZTEiMCAGA1UEAwwZSGFja2VyT25lIHJlcG9ydCAjMTgwODU5NjAi |
| 213 | +GA8yMDIyMTIxNjAwMDAwMFoYDzIwMjMxMjE1MjM1OTU5WjCBiTELMAkGA1UEBhMC |
| 214 | +VVMxEzARBgNVBAgMCkNhbGlmb3JuaWExETAPBgNVBAcMCENhcmxzYmFkMQ8wDQYD |
| 215 | +VQQKDAZWaWFzYXQxHTAbBgNVBAsMFFZpYXNhdCBTZWN1cmUgTW9iaWxlMSIwIAYD |
| 216 | +VQQDDBlIYWNrZXJPbmUgcmVwb3J0ICMxODA4NTk2MIIBIjANBgkqhkiG9w0BAQEF |
| 217 | +AAOCAQ8AMIIBCgKCAQEA6I7RBPm4E/9rIrCHV5lfsHI/yYzXtACJmoyP8OMkjbeB |
| 218 | +h21oSJJF9FEnbivk6bYaHZIPasa+lSAydRM2rbbmfhF+jQoWYCIbV2ztrbFR70S1 |
| 219 | +wAuJrlYYm+8u+1HUru5UBZWUr/p1gFtv3QjpA8+43iwE4pXytTBKPXFo1f5iZwGI |
| 220 | +D5Bz6DohT7Tyb8cpQ1uMCMCT0EJJ4n8wUrvfBgwBO94O4qlhs9vYgnDKepJDjptc |
| 221 | +uSuEpvHALO8+EYkQ7nkM4Xzl/WK1yFtxxE93Jvd1OvViDGVrRVfsq+xYTKknGLX0 |
| 222 | +QIeoDDnIr0OjlYPd/cqyEgMcFyFxwDSzSc1esxdCpQIDAQABo0UwQzAdBgNVHQ4E |
| 223 | +FgQUurygsEKdtQk0T+sjM0gEURdveRUwEgYDVR0TAQH/BAgwBgEB/wIB/zAOBgNV |
| 224 | +HQ8BAf8EBAMCB4AwDQYJKoZIhvcNAQENBQADggEBAH7mIIXiQsQ4/QGNNFOQzTgP |
| 225 | +/bUbMSZJsY5TPAvS9rF9yQVzs4dJZnQk5kEb/qrDQSe27oP0L0hfFm1wTGy+aKfa |
| 226 | +BVGHdRmmvHtDUPLA9URCFShqKuS+GXp+6zt7dyZPRrPmiZaciiCMPHOnx59xSdPm |
| 227 | +AZG8cD3fmK2ThC4FAMyvRb0qeobka3s22xTQ2kjwJO5gykTkZ+BR6SzRHQTjYMuT |
| 228 | +iry9Bu8Kvbzu3r5n+/bmNz+xRNmEeehgT2qsHjA5b2YBVTr9MdN9Ro3H3saA3upr |
| 229 | +oans248kpal88CGqsN2so/wZKxVnpiXlPHMdiNL7hRSUqlHkUi07FrP2Htg8kjI= |
| 230 | +-----END CERTIFICATE-----`.trim(); |
| 231 | + const c = new X509Certificate(certPem); |
| 232 | + assert(!c.ca); |
| 233 | + const signer = createSign('SHA256'); |
| 234 | + assert(signer.sign(key, 'hex')); |
| 235 | + |
| 236 | + const c1 = new X509Certificate(certPem); |
| 237 | + assert(!c1.checkIssued(c1)); |
| 238 | + const signer1 = createSign('SHA256'); |
| 239 | + assert(signer1.sign(key, 'hex')); |
| 240 | + |
| 241 | + const c2 = new X509Certificate(certPem); |
| 242 | + assert(c2.toLegacyObject()); |
| 243 | + const signer2 = createSign('SHA256'); |
| 244 | + assert(signer2.sign(key, 'hex')); |
201 | 245 | }
|
202 | 246 |
|
203 | 247 | // X509Certificate can be cloned via MessageChannel/MessagePort
|
|
0 commit comments