|
1 | | -package org.bouncycastle.pqc.jcajce.provider.test; |
| 1 | +package org.bouncycastle.jcajce.provider.test; |
2 | 2 |
|
3 | 3 | import java.security.AlgorithmParameters; |
4 | 4 | import java.security.KeyPair; |
5 | 5 | import java.security.KeyPairGenerator; |
6 | 6 | import java.security.ProviderException; |
7 | 7 | import java.security.Security; |
8 | 8 | import java.security.Signature; |
| 9 | +import java.security.spec.MGF1ParameterSpec; |
| 10 | +import java.security.spec.PSSParameterSpec; |
9 | 11 |
|
10 | 12 | import junit.framework.TestCase; |
11 | 13 | import org.bouncycastle.jcajce.spec.ContextParameterSpec; |
@@ -219,6 +221,62 @@ public void testResetContext() |
219 | 221 | assertTrue(verifier.verify(s)); |
220 | 222 | } |
221 | 223 |
|
| 224 | + /** |
| 225 | + * getParameters() caches the AlgorithmParameters it builds, so a context set after it has been |
| 226 | + * asked for once has to clear that cache rather than go on reporting the previous context. |
| 227 | + * <p> |
| 228 | + * testResetContext above only asks after the second setParameter, so the cache is never |
| 229 | + * populated with the first context there and a stale one would go unnoticed. |
| 230 | + * </p> |
| 231 | + */ |
| 232 | + public void testGetParametersNotStaleAfterReset() |
| 233 | + throws Exception |
| 234 | + { |
| 235 | + byte[] second = Strings.toByteArray("second context"); |
| 236 | + |
| 237 | + KeyPair kp = KeyPairGenerator.getInstance("ML-DSA-65", "BC").generateKeyPair(); |
| 238 | + |
| 239 | + Signature sig = Signature.getInstance("ML-DSA", "BC"); |
| 240 | + |
| 241 | + sig.setParameter(new ContextParameterSpec(CONTEXT)); |
| 242 | + sig.initSign(kp.getPrivate()); |
| 243 | + |
| 244 | + assertTrue(Arrays.areEqual(CONTEXT, |
| 245 | + sig.getParameters().getParameterSpec(ContextParameterSpec.class).getContext())); |
| 246 | + |
| 247 | + sig.setParameter(new ContextParameterSpec(second)); |
| 248 | + |
| 249 | + assertTrue("getParameters() still reported the previous context", Arrays.areEqual(second, |
| 250 | + sig.getParameters().getParameterSpec(ContextParameterSpec.class).getContext())); |
| 251 | + } |
| 252 | + |
| 253 | + /** |
| 254 | + * The RSASSA-PSS services cache getParameters() the same way, so the same question is asked of |
| 255 | + * the sibling path this class's contract is modelled on. |
| 256 | + */ |
| 257 | + public void testPssGetParametersNotStaleAfterReset() |
| 258 | + throws Exception |
| 259 | + { |
| 260 | + KeyPairGenerator kpg = KeyPairGenerator.getInstance("RSA", "BC"); |
| 261 | + |
| 262 | + kpg.initialize(2048); |
| 263 | + |
| 264 | + KeyPair kp = kpg.generateKeyPair(); |
| 265 | + |
| 266 | + Signature sig = Signature.getInstance("SHA256withRSAandMGF1", "BC"); |
| 267 | + |
| 268 | + sig.initSign(kp.getPrivate()); |
| 269 | + sig.setParameter(new PSSParameterSpec("SHA-256", "MGF1", MGF1ParameterSpec.SHA256, 32, 1)); |
| 270 | + |
| 271 | + assertEquals(32, |
| 272 | + ((PSSParameterSpec)sig.getParameters().getParameterSpec(PSSParameterSpec.class)).getSaltLength()); |
| 273 | + |
| 274 | + sig.setParameter(new PSSParameterSpec("SHA-256", "MGF1", MGF1ParameterSpec.SHA256, 20, 1)); |
| 275 | + |
| 276 | + assertEquals("getParameters() still reported the previous salt length", 20, |
| 277 | + ((PSSParameterSpec)sig.getParameters().getParameterSpec(PSSParameterSpec.class)).getSaltLength()); |
| 278 | + } |
| 279 | + |
222 | 280 | public void testSetParameterMidUpdateStillRejected() |
223 | 281 | throws Exception |
224 | 282 | { |
|
0 commit comments