@@ -3,12 +3,14 @@ const common = require('../common');
33if ( ! common . hasCrypto )
44 common . skip ( 'missing crypto' ) ;
55
6- const { hasOpenSSL3 } = require ( '../common/crypto' ) ;
6+ const { hasOpenSSL , hasFIPS } = require ( '../common/crypto' ) ;
77const assert = require ( 'assert' ) ;
88const util = require ( 'util' ) ;
99const crypto = require ( 'crypto' ) ;
1010const fixtures = require ( '../common/fixtures' ) ;
1111
12+ const fips3 = hasFIPS ( 3 ) ;
13+
1214function test (
1315 publicFixture ,
1416 privateFixture ,
@@ -65,6 +67,17 @@ function test(
6567 }
6668}
6769
70+ function testSignFailure ( privateFixture , algorithm , options , code , message ) {
71+ const key = { key : fixtures . readKey ( privateFixture ) , ...options } ;
72+ const data = Buffer . from ( 'Hello world' ) ;
73+ assert . throws ( ( ) => crypto . sign ( algorithm , data , key ) , { code } ) ;
74+ crypto . sign ( algorithm , data , key , common . mustCall ( ( err ) => {
75+ // Async crypto jobs in v24 preserve the OpenSSL message without a code.
76+ assert . strictEqual ( err ?. name , 'Error' ) ;
77+ assert . strictEqual ( err . message , message ) ;
78+ } ) ) ;
79+ }
80+
6881// RSA w/ default padding
6982test ( 'rsa_public.pem' , 'rsa_private.pem' , 'sha256' , true ) ;
7083test ( 'rsa_public.pem' , 'rsa_private.pem' , 'sha256' , true ,
@@ -94,14 +107,20 @@ if (!process.features.openssl_is_boringssl) {
94107 test ( 'ed448_public.pem' , 'ed448_private.pem' , undefined , true ) ;
95108
96109 // ECDSA w/ der signature encoding
97- test ( 'ec_secp256k1_public.pem' , 'ec_secp256k1_private.pem' , 'sha384' ,
98- false ) ;
99- test ( 'ec_secp256k1_public.pem' , 'ec_secp256k1_private.pem' , 'sha384' ,
100- false , { dsaEncoding : 'der' } ) ;
101-
102- // ECDSA w/ ieee-p1363 signature encoding
103- test ( 'ec_secp256k1_public.pem' , 'ec_secp256k1_private.pem' , 'sha384' , false ,
104- { dsaEncoding : 'ieee-p1363' } ) ;
110+ if ( fips3 ) {
111+ testSignFailure ( 'ec_secp256k1_private.pem' , 'sha384' , { } ,
112+ 'ERR_OSSL_EVP_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE' ,
113+ 'error:03000096:digital envelope routines::operation not supported for this keytype' ) ;
114+ } else {
115+ test ( 'ec_secp256k1_public.pem' , 'ec_secp256k1_private.pem' , 'sha384' ,
116+ false ) ;
117+ test ( 'ec_secp256k1_public.pem' , 'ec_secp256k1_private.pem' , 'sha384' ,
118+ false , { dsaEncoding : 'der' } ) ;
119+
120+ // ECDSA w/ ieee-p1363 signature encoding
121+ test ( 'ec_secp256k1_public.pem' , 'ec_secp256k1_private.pem' , 'sha384' , false ,
122+ { dsaEncoding : 'ieee-p1363' } ) ;
123+ }
105124
106125 // DSA w/ der signature encoding
107126 test ( 'dsa_public.pem' , 'dsa_private.pem' , 'sha256' ,
@@ -156,7 +175,7 @@ MCowBQYDK2VuAyEA6pwGRbadNQAI/tYN8+/p/0/hbsdHfOEGr1ADiLVk/Gc=
156175 const signature = crypto . randomBytes ( 16 ) ;
157176
158177 let expected = / n o d e f a u l t d i g e s t / ;
159- if ( hasOpenSSL3 || process . features . openssl_is_boringssl ) {
178+ if ( hasOpenSSL ( 3 ) || process . features . openssl_is_boringssl ) {
160179 expected = / o p e r a t i o n [ \s _ ] n o t [ \s _ ] s u p p o r t e d [ \s _ ] f o r [ \s _ ] t h i s [ \s _ ] k e y t y p e / i;
161180 }
162181
@@ -167,11 +186,21 @@ MCowBQYDK2VuAyEA6pwGRbadNQAI/tYN8+/p/0/hbsdHfOEGr1ADiLVk/Gc=
167186}
168187
169188{
170- const { privateKey } = crypto . generateKeyPairSync ( 'rsa' , {
171- modulusLength : 512
172- } ) ;
173- crypto . sign ( 'sha512' , 'message' , privateKey , common . mustCall ( ( err ) => {
174- assert . ok ( err ) ;
175- assert . match ( err . message , / d i g e s t [ \s _ ] t o o [ \s _ ] b i g [ \s _ ] f o r [ \s _ ] r s a [ \s _ ] k e y / i) ;
176- } ) ) ;
189+ if ( fips3 ) {
190+ crypto . generateKeyPair ( 'rsa' , { modulusLength : 512 } ,
191+ common . mustCall ( ( err ) => {
192+ assert . strictEqual ( err ?. name , 'Error' ) ;
193+ assert . strictEqual (
194+ err . message , 'error:020000AE:rsa routines::invalid modulus' ) ;
195+ } ) ) ;
196+ } else {
197+ const { privateKey } = crypto . generateKeyPairSync ( 'rsa' , {
198+ modulusLength : 512
199+ } ) ;
200+ crypto . sign ( 'sha512' , 'message' , privateKey , common . mustCall ( ( err ) => {
201+ assert . ok ( err ) ;
202+ assert . match (
203+ err . message , / d i g e s t [ \s _ ] t o o [ \s _ ] b i g [ \s _ ] f o r [ \s _ ] r s a [ \s _ ] k e y / i) ;
204+ } ) ) ;
205+ }
177206}
0 commit comments