| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515 |
- using System;
- using System.Collections.Generic;
- using System.IO;
- using System.Linq;
- using Microsoft.VisualStudio.TestTools.UnitTesting;
- using Renci.SshNet.Common;
- using Renci.SshNet.Security;
- using Renci.SshNet.Tests.Common;
- namespace Renci.SshNet.Tests.Classes
- {
- /// <summary>
- /// old private key information/
- /// </summary>
- [TestClass]
- public class PrivateKeyFileTest : TestBase
- {
- #if NETFRAMEWORK
- private static readonly DateTimeOffset UnixEpoch = new(1970, 01, 01, 00, 00, 00, TimeSpan.Zero);
- #else
- private static readonly DateTimeOffset UnixEpoch = DateTimeOffset.UnixEpoch;
- #endif
- private string _temporaryFile;
- [TestInitialize]
- public void SetUp()
- {
- _temporaryFile = GetTempFileName();
- }
- [TestCleanup]
- public void TearDown()
- {
- if (_temporaryFile != null)
- {
- File.Delete(_temporaryFile);
- }
- }
- /// <summary>
- /// A test for <see cref="PrivateKeyFile(string)"/> ctor.
- ///</summary>
- [TestMethod]
- public void ConstructorWithFileNameShouldThrowArgumentNullExceptionWhenFileNameIsNull()
- {
- string fileName = null;
- try
- {
- _ = new PrivateKeyFile(fileName);
- Assert.Fail();
- }
- catch (ArgumentNullException ex)
- {
- Assert.IsNull(ex.InnerException);
- Assert.AreEqual("fileName", ex.ParamName);
- }
- }
- /// <summary>
- /// A test for <see cref="PrivateKeyFile(string, string)"/> ctor.
- ///</summary>
- [TestMethod]
- public void ConstructorWithFileNameAndPassphraseShouldThrowArgumentNullExceptionWhenFileNameIsNull()
- {
- string fileName = null;
- try
- {
- _ = new PrivateKeyFile(fileName, "12345");
- Assert.Fail();
- }
- catch (ArgumentNullException ex)
- {
- Assert.IsNull(ex.InnerException);
- Assert.AreEqual("fileName", ex.ParamName);
- }
- }
- [TestMethod]
- public void ConstructorWithPrivateKeyShouldThrowArgumentNullExceptionWhenPrivateKeyIsNull()
- {
- Stream privateKey = null;
- try
- {
- _ = new PrivateKeyFile(privateKey);
- Assert.Fail();
- }
- catch (ArgumentNullException ex)
- {
- Assert.IsNull(ex.InnerException);
- Assert.AreEqual("privateKey", ex.ParamName);
- }
- }
- [TestMethod]
- public void ConstructorWithPrivateKeyAndPassphraseShouldThrowArgumentNullExceptionWhenPrivateKeyIsNull()
- {
- Stream privateKey = null;
- try
- {
- _ = new PrivateKeyFile(privateKey, "12345");
- Assert.Fail();
- }
- catch (ArgumentNullException ex)
- {
- Assert.IsNull(ex.InnerException);
- Assert.AreEqual("privateKey", ex.ParamName);
- }
- }
- [TestMethod]
- public void ConstructorWithKeyShouldThrowArgumentNullExceptionWhenKeyIsNull()
- {
- Key key = null;
- try
- {
- _ = new PrivateKeyFile(key);
- Assert.Fail();
- }
- catch (ArgumentNullException ex)
- {
- Assert.IsNull(ex.InnerException);
- Assert.AreEqual("key", ex.ParamName);
- }
- }
- [TestMethod]
- public void Test_PrivateKey_SSH2_Encrypted_ShouldThrowSshExceptionWhenPassphraseIsWrong()
- {
- using (var stream = GetData("Key.SSH2.RSA.Encrypted.Des.CBC.12345.txt"))
- {
- try
- {
- _ = new PrivateKeyFile(stream, "34567");
- Assert.Fail();
- }
- catch (SshException ex)
- {
- Assert.IsInstanceOfType<SshException>(ex);
- Assert.IsNull(ex.InnerException);
- Assert.AreEqual("Invalid passphrase.", ex.Message);
- }
- }
- }
- [TestMethod]
- public void Test_PrivateKey_SSH2_Encrypted_ShouldThrowSshPassPhraseNullOrEmptyExceptionWhenPassphraseIsNull()
- {
- using (var stream = GetData("Key.SSH2.RSA.Encrypted.Des.CBC.12345.txt"))
- {
- try
- {
- _ = new PrivateKeyFile(stream, null);
- Assert.Fail();
- }
- catch (SshPassPhraseNullOrEmptyException ex)
- {
- Assert.IsInstanceOfType<SshPassPhraseNullOrEmptyException>(ex);
- Assert.IsNull(ex.InnerException);
- Assert.AreEqual("Private key is encrypted but passphrase is empty.", ex.Message);
- }
- }
- }
- [TestMethod]
- public void Test_PrivateKey_SSH2_Encrypted_ShouldThrowSshPassPhraseNullOrEmptyExceptionWhenPassphraseIsEmpty()
- {
- using (var stream = GetData("Key.SSH2.RSA.Encrypted.Des.CBC.12345.txt"))
- {
- try
- {
- _ = new PrivateKeyFile(stream, string.Empty);
- Assert.Fail();
- }
- catch (SshPassPhraseNullOrEmptyException ex)
- {
- Assert.IsInstanceOfType<SshPassPhraseNullOrEmptyException>(ex);
- Assert.IsNull(ex.InnerException);
- Assert.AreEqual("Private key is encrypted but passphrase is empty.", ex.Message);
- }
- }
- }
- /// <summary>
- ///A test for Dispose
- ///</summary>
- [TestMethod]
- public void DisposeTest()
- {
- using (var privateKeyStream = GetData("Key.RSA.txt"))
- {
- var target = new PrivateKeyFile(privateKeyStream);
- target.Dispose();
- }
- }
- /// <summary>
- /// A test for <see cref="PrivateKeyFile(string, string)"/> ctor.
- ///</summary>
- [TestMethod]
- public void ConstructorWithFileNameAndPassphrase()
- {
- using (var stream = GetData("Key.RSA.Encrypted.Aes.128.CBC.12345.txt"))
- {
- SaveStreamToFile(stream, _temporaryFile);
- }
- using (var fs = File.Open(_temporaryFile, FileMode.Open, FileAccess.Read, FileShare.Read))
- {
- var privateKeyFile = new PrivateKeyFile(_temporaryFile, "12345");
- TestRsaKeyFile(privateKeyFile);
- }
- }
- /// <summary>
- /// A test for <see cref="PrivateKeyFile(string, string)"/> ctor.
- ///</summary>
- [TestMethod]
- public void ConstructorWithFileNameAndPassphraseShouldThrowSshPassPhraseNullOrEmptyExceptionWhenNeededPassphraseIsEmpty()
- {
- var passphrase = string.Empty;
- using (var stream = GetData("Key.RSA.Encrypted.Aes.128.CBC.12345.txt"))
- {
- SaveStreamToFile(stream, _temporaryFile);
- }
- try
- {
- _ = new PrivateKeyFile(_temporaryFile, passphrase);
- Assert.Fail();
- }
- catch (SshPassPhraseNullOrEmptyException ex)
- {
- Assert.IsNull(ex.InnerException);
- Assert.AreEqual("Private key is encrypted but passphrase is empty.", ex.Message);
- }
- }
- /// <summary>
- /// A test for <see cref="PrivateKeyFile(string, string)"/> ctor.
- ///</summary>
- [TestMethod]
- public void ConstructorWithFileNameAndPassphraseShouldThrowSshPassPhraseNullOrEmptyExceptionWhenNeededPassphraseIsNull()
- {
- string passphrase = null;
- using (var stream = GetData("Key.RSA.Encrypted.Aes.128.CBC.12345.txt"))
- {
- SaveStreamToFile(stream, _temporaryFile);
- }
- try
- {
- _ = new PrivateKeyFile(_temporaryFile, passphrase);
- Assert.Fail();
- }
- catch (SshPassPhraseNullOrEmptyException ex)
- {
- Assert.IsNull(ex.InnerException);
- Assert.AreEqual("Private key is encrypted but passphrase is empty.", ex.Message);
- }
- }
- /// <summary>
- /// A test for <see cref="PrivateKeyFile(string)"/> ctor.
- ///</summary>
- [TestMethod]
- public void ConstructorWithFileName()
- {
- using (var stream = GetData("Key.RSA.Encrypted.Aes.128.CBC.12345.txt"))
- {
- SaveStreamToFile(stream, _temporaryFile);
- }
- var privateKeyFile = new PrivateKeyFile(_temporaryFile, "12345");
- TestRsaKeyFile(privateKeyFile);
- }
- [TestMethod]
- public void ConstructorWithFileNameShouldBeAbleToReadFileThatIsSharedForReadAccess()
- {
- using (var stream = GetData("Key.RSA.txt"))
- {
- SaveStreamToFile(stream, _temporaryFile);
- }
- using (var fs = File.Open(_temporaryFile, FileMode.Open, FileAccess.Read, FileShare.Read))
- {
- var privateKeyFile = new PrivateKeyFile(_temporaryFile);
- TestRsaKeyFile(privateKeyFile);
- }
- }
- [TestMethod]
- public void ConstructorWithFileNameAndPassPhraseShouldBeAbleToReadFileThatIsSharedForReadAccess()
- {
- using (var stream = GetData("Key.RSA.Encrypted.Aes.128.CBC.12345.txt"))
- {
- SaveStreamToFile(stream, _temporaryFile);
- }
- using (var fs = File.Open(_temporaryFile, FileMode.Open, FileAccess.Read, FileShare.Read))
- {
- var privateKeyFile = new PrivateKeyFile(_temporaryFile, "12345");
- TestRsaKeyFile(privateKeyFile);
- }
- }
- [TestMethod]
- [DataRow("Key.DSA.PKCS8.Encrypted.Aes.256.CBC.12345.txt", "12345", typeof(DsaKey))]
- [DataRow("Key.DSA.PKCS8.txt", null, typeof(DsaKey))]
- [DataRow("Key.DSA.txt", null, typeof(DsaKey))]
- [DataRow("Key.ECDSA.Encrypted.txt", "12345", typeof(EcdsaKey))]
- [DataRow("Key.ECDSA.PKCS8.Encrypted.Aes.256.CBC.12345.txt", "12345", typeof(EcdsaKey))]
- [DataRow("Key.ECDSA.PKCS8.txt", null, typeof(EcdsaKey))]
- [DataRow("Key.ECDSA.txt", null, typeof(EcdsaKey))]
- [DataRow("Key.ECDSA384.Encrypted.txt", "12345", typeof(EcdsaKey))]
- [DataRow("Key.ECDSA384.txt", null, typeof(EcdsaKey))]
- [DataRow("Key.ECDSA521.Encrypted.txt", "12345", typeof(EcdsaKey))]
- [DataRow("Key.ECDSA521.txt", null, typeof(EcdsaKey))]
- [DataRow("Key.OPENSSH.ECDSA.Encrypted.Aes.128.CTR.txt", "12345", typeof(EcdsaKey))]
- [DataRow("Key.OPENSSH.ECDSA.Encrypted.txt", "12345", typeof(EcdsaKey))]
- [DataRow("Key.OPENSSH.ECDSA.txt", null, typeof(EcdsaKey))]
- [DataRow("Key.OPENSSH.ECDSA384.Encrypted.Aes.256.GCM.txt", "12345", typeof(EcdsaKey))]
- [DataRow("Key.OPENSSH.ECDSA384.Encrypted.txt", "12345", typeof(EcdsaKey))]
- [DataRow("Key.OPENSSH.ECDSA384.txt", null, typeof(EcdsaKey))]
- [DataRow("Key.OPENSSH.ECDSA521.Encrypted.Aes.192.CBC.txt", "12345", typeof(EcdsaKey))]
- [DataRow("Key.OPENSSH.ECDSA521.Encrypted.txt", "12345", typeof(EcdsaKey))]
- [DataRow("Key.OPENSSH.ECDSA521.txt", null, typeof(EcdsaKey))]
- [DataRow("Key.OPENSSH.ED25519.Encrypted.3Des.CBC.txt", "12345", typeof(ED25519Key))]
- [DataRow("Key.OPENSSH.ED25519.Encrypted.Aes.128.CBC.txt", "12345", typeof(ED25519Key))]
- [DataRow("Key.OPENSSH.ED25519.Encrypted.Aes.128.GCM.txt", "12345", typeof(ED25519Key))]
- [DataRow("Key.OPENSSH.ED25519.Encrypted.Aes.256.CBC.txt", "12345", typeof(ED25519Key))]
- [DataRow("Key.OPENSSH.ED25519.Encrypted.Aes.256.CTR.txt", "12345", typeof(ED25519Key))]
- [DataRow("Key.OPENSSH.ED25519.Encrypted.ChaCha20.Poly1305.txt", "12345", typeof(ED25519Key))]
- [DataRow("Key.OPENSSH.ED25519.Encrypted.txt", "12345", typeof(ED25519Key))]
- [DataRow("Key.OPENSSH.ED25519.PKCS8.Encrypted.Aes.256.CBC.12345.txt", "12345", typeof(ED25519Key))]
- [DataRow("Key.OPENSSH.ED25519.PKCS8.txt", null, typeof(ED25519Key))]
- [DataRow("Key.OPENSSH.ED25519.txt", null, typeof(ED25519Key))]
- [DataRow("Key.OPENSSH.RSA.Encrypted.Aes.192.CTR.txt", "12345", typeof(RsaKey))]
- [DataRow("Key.OPENSSH.RSA.Encrypted.txt", "12345", typeof(RsaKey))]
- [DataRow("Key.OPENSSH.RSA.txt", null, typeof(RsaKey))]
- [DataRow("Key.RSA.Encrypted.Aes.128.CBC.12345.txt", "12345", typeof(RsaKey))]
- [DataRow("Key.RSA.Encrypted.Aes.192.CBC.12345.txt", "12345", typeof(RsaKey))]
- [DataRow("Key.RSA.Encrypted.Aes.256.CBC.12345.txt", "12345", typeof(RsaKey))]
- [DataRow("Key.RSA.Encrypted.Des.CBC.12345.txt", "12345", typeof(RsaKey))]
- [DataRow("Key.RSA.Encrypted.Des.Ede3.CBC.12345.txt", "12345", typeof(RsaKey))]
- [DataRow("Key.RSA.Encrypted.Des.Ede3.CFB.1234567890.txt", "1234567890", typeof(RsaKey))]
- [DataRow("Key.RSA.PKCS8.Encrypted.Aes.256.CBC.12345.txt", "12345", typeof(RsaKey))]
- [DataRow("Key.RSA.PKCS8.txt", null, typeof(RsaKey))]
- [DataRow("Key.RSA.txt", null, typeof(RsaKey))]
- [DataRow("Key.SSH2.DSA.Encrypted.Des.CBC.12345.txt", "12345", typeof(DsaKey))]
- [DataRow("Key.SSH2.DSA.txt", null, typeof(DsaKey))]
- [DataRow("Key.SSH2.RSA.Encrypted.Des.CBC.12345.txt", "12345", typeof(RsaKey))]
- [DataRow("Key.SSH2.RSA.txt", null, typeof(RsaKey))]
- public void Test_PrivateKey(string name, string passPhrase, Type expectedKeyType)
- {
- using (var stream = GetData(name))
- {
- var pkFile = new PrivateKeyFile(stream, passPhrase);
- Assert.IsInstanceOfType(pkFile.Key, expectedKeyType);
- if (expectedKeyType == typeof(RsaKey))
- {
- TestRsaKeyFile(pkFile);
- }
- }
- }
- [TestMethod]
- public void Test_Certificate_OPENSSH_RSA()
- {
- PrivateKeyFile pkFile;
- using (var privateKeyStream = GetData("Key.OPENSSH.RSA.txt"))
- using (var certificateStream = GetData("Key.OPENSSH.RSA-cert.pub"))
- {
- pkFile = new PrivateKeyFile(privateKeyStream, passPhrase: null, certificateStream);
- }
- Certificate cert = pkFile.Certificate;
- // ssh-keygen -L -f Key.OPENSSH.RSA-cert.pub
- Assert.AreEqual("ssh-rsa-cert-v01@openssh.com", cert.Name);
- Assert.IsInstanceOfType<RsaKey>(cert.Key);
- CollectionAssert.AreEqual(((RsaKey)pkFile.Key).Public, ((RsaKey)cert.Key).Public);
- Assert.AreEqual(0UL, cert.Serial);
- Assert.AreEqual(Certificate.CertificateType.User, cert.Type);
- Assert.AreEqual("rsa-cert-rsa", cert.KeyId);
- CollectionAssert.AreEqual(new string[] { "sshnet" }, cert.ValidPrincipals.ToList());
- Assert.AreEqual(0, cert.CriticalOptions.Count);
- Assert.IsTrue(cert.ValidAfter.EqualsExact(new DateTimeOffset(2024, 07, 17, 20, 50, 34, TimeSpan.Zero)));
- Assert.AreEqual(ulong.MaxValue, cert.ValidBeforeUnixSeconds);
- Assert.AreEqual(DateTimeOffset.MaxValue, cert.ValidBefore);
- CollectionAssert.AreEqual(new Dictionary<string, string>
- {
- ["permit-X11-forwarding"] = "",
- ["permit-agent-forwarding"] = "",
- ["permit-port-forwarding"] = "",
- ["permit-pty"] = "",
- ["permit-user-rc"] = "",
- }, new Dictionary<string, string>(cert.Extensions));
- Assert.AreEqual("NqLEgdYti0XjUkYjGyQv2Ddy1O5v2NZDZFRtlfESLIA", cert.CertificateAuthorityKeyFingerPrint);
- Assert.AreEqual(6, pkFile.HostKeyAlgorithms.Count);
- var algorithms = pkFile.HostKeyAlgorithms.ToList();
- Assert.AreEqual("rsa-sha2-512-cert-v01@openssh.com", algorithms[0].Name);
- Assert.AreEqual("rsa-sha2-256-cert-v01@openssh.com", algorithms[1].Name);
- Assert.AreEqual("ssh-rsa-cert-v01@openssh.com", algorithms[2].Name);
- Assert.AreEqual("ssh-rsa", algorithms[3].Name);
- Assert.AreEqual("rsa-sha2-512", algorithms[4].Name);
- Assert.AreEqual("rsa-sha2-256", algorithms[5].Name);
- }
- [TestMethod]
- public void Test_CertificateKeyMismatch()
- {
- using (var privateKey = GetData("Key.OPENSSH.RSA.txt"))
- using (var certificate = GetData("Key.OPENSSH.ECDSA521-cert.pub"))
- {
- Assert.ThrowsException<ArgumentException>(() => new PrivateKeyFile(privateKey, passPhrase: null, certificate));
- }
- }
- [TestMethod]
- public void Test_Certificate_OPENSSH_ECDSA()
- {
- PrivateKeyFile pkFile;
- using (var privateKeyStream = GetData("Key.OPENSSH.ECDSA521.txt"))
- using (var certificateStream = GetData("Key.OPENSSH.ECDSA521-cert.pub"))
- {
- pkFile = new PrivateKeyFile(privateKeyStream, passPhrase: null, certificateStream);
- }
- Certificate cert = pkFile.Certificate;
- // ssh-keygen -L -f Key.OPENSSH.ECDSA521-cert.pub
- Assert.AreEqual("ecdsa-sha2-nistp521-cert-v01@openssh.com", cert.Name);
- Assert.IsInstanceOfType<EcdsaKey>(cert.Key);
- CollectionAssert.AreEqual(((EcdsaKey)pkFile.Key).Public, ((EcdsaKey)cert.Key).Public);
- Assert.AreEqual(0UL, cert.Serial);
- Assert.AreEqual(Certificate.CertificateType.User, cert.Type);
- Assert.AreEqual("ecdsa521certEcdsa", cert.KeyId);
- CollectionAssert.AreEqual(new string[] { "sshnet" }, cert.ValidPrincipals.ToList());
- Assert.AreEqual(0, cert.CriticalOptions.Count);
- Assert.AreEqual(0UL, cert.ValidAfterUnixSeconds);
- Assert.IsTrue(cert.ValidAfter.EqualsExact(UnixEpoch));
- Assert.AreEqual(ulong.MaxValue, cert.ValidBeforeUnixSeconds);
- Assert.AreEqual(DateTimeOffset.MaxValue, cert.ValidBefore);
- CollectionAssert.AreEqual(new Dictionary<string, string>
- {
- ["permit-X11-forwarding"] = "",
- ["permit-agent-forwarding"] = "",
- ["permit-port-forwarding"] = "",
- ["permit-pty"] = "",
- ["permit-user-rc"] = "",
- }, new Dictionary<string, string>(cert.Extensions));
- Assert.AreEqual("r/t6I+bZQzN5BhSuntFSHDHlrnNHVM2lAo6gbvynG/4", cert.CertificateAuthorityKeyFingerPrint);
- Assert.AreEqual(2, pkFile.HostKeyAlgorithms.Count);
- var algorithms = pkFile.HostKeyAlgorithms.ToList();
- Assert.AreEqual("ecdsa-sha2-nistp521-cert-v01@openssh.com", algorithms[0].Name);
- Assert.AreEqual("ecdsa-sha2-nistp521", algorithms[1].Name);
- }
- private void SaveStreamToFile(Stream stream, string fileName)
- {
- var buffer = new byte[4000];
- using (var fs = new FileStream(fileName, FileMode.Create, FileAccess.Write))
- {
- var bytesRead = stream.Read(buffer, 0, buffer.Length);
- while (bytesRead > 0)
- {
- fs.Write(buffer, 0, bytesRead);
- bytesRead = stream.Read(buffer, 0, buffer.Length);
- }
- }
- }
- private string GetTempFileName()
- {
- var tempFile = Path.GetTempFileName();
- File.Delete(tempFile);
- return tempFile;
- }
- private static void TestRsaKeyFile(PrivateKeyFile rsaPrivateKeyFile)
- {
- Assert.IsNotNull(rsaPrivateKeyFile.HostKeyAlgorithms);
- Assert.AreEqual(3, rsaPrivateKeyFile.HostKeyAlgorithms.Count);
- var algorithms = rsaPrivateKeyFile.HostKeyAlgorithms.ToList();
- // ssh-rsa should be attempted first during authentication by default.
- // See https://github.com/sshnet/SSH.NET/issues/1233#issuecomment-1871196405
- Assert.AreEqual("ssh-rsa", algorithms[0].Name);
- Assert.AreEqual("rsa-sha2-512", algorithms[1].Name);
- Assert.AreEqual("rsa-sha2-256", algorithms[2].Name);
- }
- }
- }
|