1 package org.cacert.gigi.util;
3 import static org.hamcrest.CoreMatchers.*;
4 import static org.junit.Assert.*;
5 import static org.junit.Assume.*;
7 import java.io.IOException;
8 import java.security.GeneralSecurityException;
9 import java.util.Arrays;
11 import org.cacert.gigi.GigiApiException;
12 import org.cacert.gigi.dbObjects.Certificate;
13 import org.cacert.gigi.dbObjects.Certificate.CertificateStatus;
14 import org.cacert.gigi.dbObjects.CertificateProfile;
15 import org.cacert.gigi.dbObjects.Digest;
16 import org.cacert.gigi.dbObjects.Domain;
17 import org.cacert.gigi.dbObjects.Job;
18 import org.cacert.gigi.pages.account.certs.CertificateRequest;
19 import org.cacert.gigi.testUtils.ClientTest;
20 import org.junit.Test;
21 import org.junit.runner.RunWith;
22 import org.junit.runners.Parameterized;
23 import org.junit.runners.Parameterized.Parameter;
24 import org.junit.runners.Parameterized.Parameters;
26 @RunWith(Parameterized.class)
27 public class TestCAAValidation extends ClientTest {
29 @Parameters(name = "CAATest({0}) = {1}")
30 public static Iterable<Object[]> genParams() throws IOException {
33 String caa = (String) getTestProps().get("domain.CAAtest");
35 String[] parts = caa.split(" ");
36 Object[][] res = new Object[parts.length][];
37 for (int i = 0; i < res.length; i++) {
38 char firstChar = parts[i].charAt(0);
39 if (firstChar != '-' && firstChar != '+') {
40 throw new Error("malformed CAA test vector");
42 res[i] = new Object[] {
43 parts[i].substring(1), firstChar == '+'
46 return Arrays.<Object[]>asList(res);
53 public Boolean success;
56 public void testCAA() {
57 assertEquals(success, CAA.verifyDomainAccess(u, CertificateProfile.getByName("server"), domain));
61 public void testCAACert() throws GeneralSecurityException, IOException, GigiApiException, InterruptedException {
62 Domain d = new Domain(u, u, domain);
64 String csr = generatePEMCSR(generateKeypair(), "CN=test");
65 CertificateRequest cr = new CertificateRequest(new AuthorizationContext(u, u), csr);
67 cr.update("", Digest.SHA512.toString(), "server", null, null, "dns:" + domain + "\n");
68 } catch (GigiApiException e) {
69 assertThat(e.getMessage(), containsString("has been removed"));
74 Certificate draft = cr.draft();
75 Job j = draft.issue(null, "2y", u);
78 assertEquals(CertificateStatus.ISSUED, draft.getStatus());