2
0

PrivateKeyAuthenticationTests.cs 7.0 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164
  1. using Renci.SshNet.IntegrationTests.Common;
  2. using Renci.SshNet.TestTools.OpenSSH;
  3. namespace Renci.SshNet.IntegrationTests
  4. {
  5. [TestClass]
  6. public class PrivateKeyAuthenticationTests : TestBase
  7. {
  8. private IConnectionInfoFactory _connectionInfoFactory;
  9. private RemoteSshdConfig _remoteSshdConfig;
  10. [TestInitialize]
  11. public void SetUp()
  12. {
  13. _connectionInfoFactory = new LinuxVMConnectionFactory(SshServerHostName, SshServerPort);
  14. _remoteSshdConfig = new RemoteSshd(new LinuxAdminConnectionFactory(SshServerHostName, SshServerPort)).OpenConfig();
  15. }
  16. [TestCleanup]
  17. public void TearDown()
  18. {
  19. _remoteSshdConfig?.Reset();
  20. }
  21. [TestMethod]
  22. public void SshRsa()
  23. {
  24. DoTest(PublicKeyAlgorithm.SshRsa, "Data.Key.RSA.txt");
  25. }
  26. [TestMethod]
  27. public void SshRsaSha256()
  28. {
  29. DoTest(PublicKeyAlgorithm.RsaSha2256, "Data.Key.RSA.txt");
  30. }
  31. [TestMethod]
  32. public void SshRsaSha512()
  33. {
  34. DoTest(PublicKeyAlgorithm.RsaSha2512, "Data.Key.RSA.txt");
  35. }
  36. [TestMethod]
  37. public void Ecdsa256()
  38. {
  39. DoTest(PublicKeyAlgorithm.EcdsaSha2Nistp256, "Data.Key.ECDSA.Encrypted.txt", "12345");
  40. }
  41. [TestMethod]
  42. public void Ecdsa384()
  43. {
  44. DoTest(PublicKeyAlgorithm.EcdsaSha2Nistp384, "Data.Key.OPENSSH.ECDSA384.Encrypted.txt", "12345");
  45. }
  46. [TestMethod]
  47. public void Ecdsa521()
  48. {
  49. DoTest(PublicKeyAlgorithm.EcdsaSha2Nistp521, "Data.Key.OPENSSH.ECDSA521.Encrypted.txt", "12345");
  50. }
  51. [TestMethod]
  52. public void Ed25519()
  53. {
  54. DoTest(PublicKeyAlgorithm.SshEd25519, "Data.Key.OPENSSH.ED25519.Encrypted.txt", "12345");
  55. }
  56. // The private keys used for the certificate tests below should stay out of authorized_keys for a proper test.
  57. [TestMethod]
  58. public void SshRsaCertificate()
  59. {
  60. // ssh-keygen -L -f Key.OPENSSH.RSA.Encrypted.Aes.192.CTR-cert.pub
  61. // Type: ssh-rsa-cert-v01@openssh.com user certificate
  62. // Public key: RSA-CERT SHA256:MMIzDVhQHqU9SAZ8p3x2wo6JpXixCWO/7qf6h0l8DJA
  63. // Signing CA: RSA SHA256:NqLEgdYti0XjUkYjGyQv2Ddy1O5v2NZDZFRtlfESLIA (using rsa-sha2-512)
  64. // And we will authenticate (sign) with ssh-rsa (SHA-1)
  65. DoTest(PublicKeyAlgorithm.SshRsaCertV01OpenSSH, "Data.Key.OPENSSH.RSA.Encrypted.Aes.192.CTR.txt", "12345", "Data.Key.OPENSSH.RSA.Encrypted.Aes.192.CTR-cert.pub");
  66. }
  67. [TestMethod]
  68. public void SshRsaSha256Certificate()
  69. {
  70. // As above, but we will authenticate (sign) with rsa-sha2-256
  71. DoTest(PublicKeyAlgorithm.SshRsaCertV01OpenSSH, "Data.Key.OPENSSH.RSA.Encrypted.Aes.192.CTR.txt", "12345", "Data.Key.OPENSSH.RSA.Encrypted.Aes.192.CTR-cert.pub");
  72. }
  73. [TestMethod]
  74. public void Ecdsa256Certificate()
  75. {
  76. // ssh-keygen -L -f Key.OPENSSH.ECDSA.Encrypted.Aes.128.CTR-cert.pub
  77. // Type: ecdsa-sha2-nistp256-cert-v01@openssh.com user certificate
  78. // Public key: ECDSA-CERT SHA256:ufAaMwjTmKrjvt4CQiLPal1/HrmB2D7oL+H2lh/Om8c
  79. // Signing CA: RSA SHA256:NqLEgdYti0XjUkYjGyQv2Ddy1O5v2NZDZFRtlfESLIA (using rsa-sha2-512)
  80. DoTest(PublicKeyAlgorithm.EcdsaSha2Nistp256CertV01OpenSSH, "Data.Key.OPENSSH.ECDSA.Encrypted.Aes.128.CTR.txt", "12345", "Data.Key.OPENSSH.ECDSA.Encrypted.Aes.128.CTR-cert.pub");
  81. }
  82. [TestMethod]
  83. public void Ecdsa384Certificate()
  84. {
  85. // ssh-keygen -L -f Key.OPENSSH.ECDSA384.Encrypted.Aes.256.GCM-cert.pub
  86. // Type: ecdsa-sha2-nistp384-cert-v01@openssh.com user certificate
  87. // Public key: ECDSA-CERT SHA256:wy4X47uddqD8nggcsGHG7Rcs0qcnh4r6NrdBGdh/8us
  88. // Signing CA: RSA SHA256:NqLEgdYti0XjUkYjGyQv2Ddy1O5v2NZDZFRtlfESLIA (using rsa-sha2-256)
  89. DoTest(PublicKeyAlgorithm.EcdsaSha2Nistp384CertV01OpenSSH, "Data.Key.OPENSSH.ECDSA384.Encrypted.Aes.256.GCM.txt", "12345", "Data.Key.OPENSSH.ECDSA384.Encrypted.Aes.256.GCM-cert.pub");
  90. }
  91. [TestMethod]
  92. public void Ecdsa521Certificate()
  93. {
  94. // ssh-keygen -L -f Key.OPENSSH.ECDSA521.Encrypted.Aes.192.CBC-cert.pub
  95. // Type: ecdsa-sha2-nistp521-cert-v01@openssh.com user certificate
  96. // Public key: ECDSA-CERT SHA256:U3wBX0sSPYxso31gi1QPz7O+1eMOTb0LoOSOjWRwyYE
  97. // Signing CA: ECDSA SHA256:r/t6I+bZQzN5BhSuntFSHDHlrnNHVM2lAo6gbvynG/4 (using ecdsa-sha2-nistp256)
  98. DoTest(PublicKeyAlgorithm.EcdsaSha2Nistp521CertV01OpenSSH, "Data.Key.OPENSSH.ECDSA521.Encrypted.Aes.192.CBC.txt", "12345", "Data.Key.OPENSSH.ECDSA521.Encrypted.Aes.192.CBC-cert.pub");
  99. }
  100. [TestMethod]
  101. public void Ed25519Certificate()
  102. {
  103. // ssh-keygen -L -f Key.OPENSSH.ED25519.Encrypted.ChaCha20.Poly1305-cert.pub
  104. // Type: ssh-ed25519-cert-v01@openssh.com user certificate
  105. // Public key: ED25519-CERT SHA256:gwO3eBcuPqChqg9B/kHsQo1/bYTAjaEZCanA7hqSuEg
  106. // Signing CA: ECDSA SHA256:r/t6I+bZQzN5BhSuntFSHDHlrnNHVM2lAo6gbvynG/4 (using ecdsa-sha2-nistp256)
  107. DoTest(PublicKeyAlgorithm.SshEd25519CertV01OpenSSH, "Data.Key.OPENSSH.ED25519.Encrypted.ChaCha20.Poly1305.txt", "12345", "Data.Key.OPENSSH.ED25519.Encrypted.ChaCha20.Poly1305-cert.pub");
  108. }
  109. private void DoTest(PublicKeyAlgorithm publicKeyAlgorithm, string keyResource, string passPhrase = null, string certificateResource = null)
  110. {
  111. _remoteSshdConfig.ClearPublicKeyAcceptedAlgorithms()
  112. .AddPublicKeyAcceptedAlgorithm(publicKeyAlgorithm)
  113. .Update()
  114. .Restart();
  115. var connectionInfo = _connectionInfoFactory.Create(CreatePrivateKeyAuthenticationMethod(keyResource, passPhrase, certificateResource));
  116. using (var client = new SshClient(connectionInfo))
  117. {
  118. client.Connect();
  119. }
  120. }
  121. private static PrivateKeyAuthenticationMethod CreatePrivateKeyAuthenticationMethod(string keyResource, string passPhrase, string certificateResource)
  122. {
  123. PrivateKeyFile privateKey;
  124. using (var keyStream = GetData(keyResource))
  125. {
  126. if (certificateResource is not null)
  127. {
  128. using (var certificateStream = GetData(certificateResource))
  129. {
  130. privateKey = new PrivateKeyFile(keyStream, passPhrase, certificateStream);
  131. }
  132. }
  133. else
  134. {
  135. privateKey = new PrivateKeyFile(keyStream, passPhrase);
  136. }
  137. }
  138. return new PrivateKeyAuthenticationMethod(Users.Regular.UserName, privateKey);
  139. }
  140. }
  141. }