mirror of
https://github.com/ApfelTeeSaft/reactos.git
synced 2026-08-26 19:33:31 +00:00
[CRYPTNET_WINETEST] Sync with Wine 10.0. CORE-20594
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
|
||||
add_executable(cryptnet_winetest cryptnet.c testlist.c)
|
||||
add_executable(cryptnet_winetest cryptnet.c)
|
||||
set_module_type(cryptnet_winetest win32cui)
|
||||
target_compile_definitions(cryptnet_winetest PRIVATE USE_WINE_TODOS)
|
||||
target_link_libraries(cryptnet_winetest winetestlib)
|
||||
add_importlibs(cryptnet_winetest cryptnet crypt32 msvcrt kernel32)
|
||||
add_rostests_file(TARGET cryptnet_winetest)
|
||||
|
||||
@@ -87,7 +87,7 @@ static const BYTE certWithAIAWithCAIssuers[] = {
|
||||
static void compareUrlArray(const CRYPT_URL_ARRAY *expected,
|
||||
const CRYPT_URL_ARRAY *got)
|
||||
{
|
||||
ok(expected->cUrl == got->cUrl, "Expected %d URLs, got %d\n",
|
||||
ok(expected->cUrl == got->cUrl, "Expected %ld URLs, got %ld\n",
|
||||
expected->cUrl, got->cUrl);
|
||||
if (expected->cUrl == got->cUrl)
|
||||
{
|
||||
@@ -95,15 +95,14 @@ static void compareUrlArray(const CRYPT_URL_ARRAY *expected,
|
||||
|
||||
for (i = 0; i < got->cUrl; i++)
|
||||
ok(!lstrcmpiW(expected->rgwszUrl[i], got->rgwszUrl[i]),
|
||||
"%d: unexpected URL\n", i);
|
||||
"%ld: unexpected URL\n", i);
|
||||
}
|
||||
}
|
||||
|
||||
static WCHAR url[] =
|
||||
{ 'h','t','t','p',':','/','/','w','i','n','e','h','q','.','o','r','g',0 };
|
||||
|
||||
static void test_getObjectUrl(void)
|
||||
{
|
||||
static WCHAR url[] = L"http://winehq.org";
|
||||
BOOL ret;
|
||||
DWORD urlArraySize = 0, infoSize = 0;
|
||||
PCCERT_CONTEXT cert;
|
||||
@@ -111,7 +110,7 @@ static void test_getObjectUrl(void)
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CryptGetObjectUrl(NULL, NULL, 0, NULL, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == ERROR_FILE_NOT_FOUND,
|
||||
"Expected ERROR_FILE_NOT_FOUND, got %d\n", GetLastError());
|
||||
"Expected ERROR_FILE_NOT_FOUND, got %ld\n", GetLastError());
|
||||
/* Crash
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_ISSUER, NULL, 0, NULL, NULL,
|
||||
NULL, NULL, NULL);
|
||||
@@ -127,7 +126,7 @@ static void test_getObjectUrl(void)
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_ISSUER, (void *)cert, 0, NULL,
|
||||
NULL, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
CertFreeCertificateContext(cert);
|
||||
|
||||
cert = CertCreateCertificateContext(X509_ASN_ENCODING,
|
||||
@@ -139,17 +138,17 @@ static void test_getObjectUrl(void)
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_ISSUER, (void *)cert, 0,
|
||||
NULL, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_ISSUER, (void *)cert,
|
||||
CRYPT_GET_URL_FROM_PROPERTY, NULL, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_ISSUER, (void *)cert,
|
||||
CRYPT_GET_URL_FROM_EXTENSION, NULL, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
/* It does have an issuing dist point extension, but that's not what
|
||||
* this is looking for (it wants a CRL dist points extension)
|
||||
*/
|
||||
@@ -157,19 +156,19 @@ static void test_getObjectUrl(void)
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_CRL_DIST_POINT,
|
||||
(void *)cert, 0, NULL, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_CRL_DIST_POINT,
|
||||
(void *)cert, CRYPT_GET_URL_FROM_PROPERTY, NULL, NULL, NULL, NULL,
|
||||
NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_CRL_DIST_POINT,
|
||||
(void *)cert, CRYPT_GET_URL_FROM_EXTENSION, NULL, NULL, NULL, NULL,
|
||||
NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
CertFreeCertificateContext(cert);
|
||||
}
|
||||
cert = CertCreateCertificateContext(X509_ASN_ENCODING,
|
||||
@@ -183,38 +182,38 @@ static void test_getObjectUrl(void)
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_ISSUER, (void *)cert, 0,
|
||||
NULL, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_ISSUER, (void *)cert,
|
||||
CRYPT_GET_URL_FROM_PROPERTY, NULL, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_ISSUER, (void *)cert,
|
||||
CRYPT_GET_URL_FROM_EXTENSION, NULL, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
/* It does have a CRL dist points extension */
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_CRL_DIST_POINT,
|
||||
(void *)cert, 0, NULL, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == E_INVALIDARG,
|
||||
"Expected E_INVALIDARG, got %08x\n", GetLastError());
|
||||
"Expected E_INVALIDARG, got %08lx\n", GetLastError());
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_CRL_DIST_POINT,
|
||||
(void *)cert, 0, NULL, NULL, NULL, &infoSize, NULL);
|
||||
ok(!ret && GetLastError() == E_INVALIDARG,
|
||||
"Expected E_INVALIDARG, got %08x\n", GetLastError());
|
||||
"Expected E_INVALIDARG, got %08lx\n", GetLastError());
|
||||
/* Can get it without specifying the location: */
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_CRL_DIST_POINT,
|
||||
(void *)cert, 0, NULL, &urlArraySize, NULL, NULL, NULL);
|
||||
ok(ret, "CryptGetObjectUrl failed: %08x\n", GetLastError());
|
||||
ok(ret, "CryptGetObjectUrl failed: %08lx\n", GetLastError());
|
||||
urlArray = HeapAlloc(GetProcessHeap(), 0, urlArraySize);
|
||||
if (urlArray)
|
||||
{
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_CRL_DIST_POINT,
|
||||
(void *)cert, 0, urlArray, &urlArraySize, NULL, NULL, NULL);
|
||||
ok(ret, "CryptGetObjectUrl failed: %08x\n", GetLastError());
|
||||
ok(ret, "CryptGetObjectUrl failed: %08lx\n", GetLastError());
|
||||
if (ret)
|
||||
{
|
||||
LPWSTR pUrl = url;
|
||||
@@ -228,14 +227,14 @@ static void test_getObjectUrl(void)
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_CRL_DIST_POINT,
|
||||
(void *)cert, CRYPT_GET_URL_FROM_EXTENSION, NULL, &urlArraySize, NULL,
|
||||
NULL, NULL);
|
||||
ok(ret, "CryptGetObjectUrl failed: %08x\n", GetLastError());
|
||||
ok(ret, "CryptGetObjectUrl failed: %08lx\n", GetLastError());
|
||||
urlArray = HeapAlloc(GetProcessHeap(), 0, urlArraySize);
|
||||
if (urlArray)
|
||||
{
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_CRL_DIST_POINT,
|
||||
(void *)cert, CRYPT_GET_URL_FROM_EXTENSION, urlArray,
|
||||
&urlArraySize, NULL, NULL, NULL);
|
||||
ok(ret, "CryptGetObjectUrl failed: %08x\n", GetLastError());
|
||||
ok(ret, "CryptGetObjectUrl failed: %08lx\n", GetLastError());
|
||||
if (ret)
|
||||
{
|
||||
LPWSTR pUrl = url;
|
||||
@@ -251,7 +250,7 @@ static void test_getObjectUrl(void)
|
||||
(void *)cert, CRYPT_GET_URL_FROM_PROPERTY, NULL, &urlArraySize, NULL,
|
||||
NULL, NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"Expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
CertFreeCertificateContext(cert);
|
||||
}
|
||||
cert = CertCreateCertificateContext(X509_ASN_ENCODING,
|
||||
@@ -265,7 +264,7 @@ static void test_getObjectUrl(void)
|
||||
*/
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_ISSUER,
|
||||
(void *)cert, 0, NULL, &urlArraySize, NULL, NULL, NULL);
|
||||
ok(ret, "CryptGetObjectUrl failed: %08x\n", GetLastError());
|
||||
ok(ret, "CryptGetObjectUrl failed: %08lx\n", GetLastError());
|
||||
if (ret)
|
||||
{
|
||||
urlArray = HeapAlloc(GetProcessHeap(), 0, urlArraySize);
|
||||
@@ -274,7 +273,7 @@ static void test_getObjectUrl(void)
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_ISSUER,
|
||||
(void *)cert, CRYPT_GET_URL_FROM_EXTENSION, urlArray,
|
||||
&urlArraySize, NULL, NULL, NULL);
|
||||
ok(ret, "CryptGetObjectUrl failed: %08x\n", GetLastError());
|
||||
ok(ret, "CryptGetObjectUrl failed: %08lx\n", GetLastError());
|
||||
if (ret)
|
||||
{
|
||||
LPWSTR pUrl = url;
|
||||
@@ -290,7 +289,7 @@ static void test_getObjectUrl(void)
|
||||
ret = CryptGetObjectUrl(URL_OID_CERTIFICATE_CRL_DIST_POINT,
|
||||
(void *)cert, 0, NULL, &urlArraySize, NULL, NULL, NULL);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NOT_FOUND,
|
||||
"expected CRYPT_E_NOT_FOUND, got %08x\n", GetLastError());
|
||||
"expected CRYPT_E_NOT_FOUND, got %08lx\n", GetLastError());
|
||||
CertFreeCertificateContext(cert);
|
||||
}
|
||||
}
|
||||
@@ -328,7 +327,7 @@ static void test_retrieveObjectByUrl(void)
|
||||
ret = CryptRetrieveObjectByUrlA(NULL, NULL, 0, 0, NULL, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && (GetLastError() == ERROR_INVALID_PARAMETER ||
|
||||
GetLastError() == E_INVALIDARG),
|
||||
"got 0x%x/%u (expected ERROR_INVALID_PARAMETER or E_INVALIDARG)\n",
|
||||
"got 0x%lx/%lu (expected ERROR_INVALID_PARAMETER or E_INVALIDARG)\n",
|
||||
GetLastError(), GetLastError());
|
||||
|
||||
make_tmp_file(tmpfile);
|
||||
@@ -343,21 +342,21 @@ static void test_retrieveObjectByUrl(void)
|
||||
win_skip("File URLs not supported\n");
|
||||
return;
|
||||
}
|
||||
ok(ret, "CryptRetrieveObjectByUrlA failed: %d\n", GetLastError());
|
||||
ok(ret, "CryptRetrieveObjectByUrlA failed: %ld\n", GetLastError());
|
||||
ok(pBlobArray && pBlobArray != (CRYPT_BLOB_ARRAY *)0xdeadbeef,
|
||||
"Expected a valid pointer\n");
|
||||
if (pBlobArray && pBlobArray != (CRYPT_BLOB_ARRAY *)0xdeadbeef)
|
||||
{
|
||||
ok(pBlobArray->cBlob == 1, "Expected 1 blob, got %d\n",
|
||||
ok(pBlobArray->cBlob == 1, "Expected 1 blob, got %ld\n",
|
||||
pBlobArray->cBlob);
|
||||
ok(pBlobArray->rgBlob[0].cbData == sizeof(certWithCRLDistPoint),
|
||||
"Unexpected size %d\n", pBlobArray->rgBlob[0].cbData);
|
||||
"Unexpected size %ld\n", pBlobArray->rgBlob[0].cbData);
|
||||
CryptMemFree(pBlobArray);
|
||||
}
|
||||
cert = (PCCERT_CONTEXT)0xdeadbeef;
|
||||
ret = CryptRetrieveObjectByUrlA(url, CONTEXT_OID_CERTIFICATE, 0, 0,
|
||||
(void **)&cert, NULL, NULL, NULL, NULL);
|
||||
ok(ret, "CryptRetrieveObjectByUrlA failed: %d\n", GetLastError());
|
||||
ok(ret, "CryptRetrieveObjectByUrlA failed: %ld\n", GetLastError());
|
||||
ok(cert && cert != (PCCERT_CONTEXT)0xdeadbeef, "Expected a cert\n");
|
||||
if (cert && cert != (PCCERT_CONTEXT)0xdeadbeef)
|
||||
CertFreeCertificateContext(cert);
|
||||
@@ -371,7 +370,7 @@ static void test_retrieveObjectByUrl(void)
|
||||
ok(!ret && (GetLastError() == CRYPT_E_NO_MATCH ||
|
||||
broken(GetLastError() == CRYPT_E_ASN1_BADTAG ||
|
||||
GetLastError() == OSS_DATA_ERROR)),
|
||||
"got 0x%x/%u (expected CRYPT_E_NO_MATCH)\n", GetLastError(), GetLastError());
|
||||
"got 0x%lx/%lu (expected CRYPT_E_NO_MATCH)\n", GetLastError(), GetLastError());
|
||||
|
||||
/* only newer versions of cryptnet do the cleanup */
|
||||
if(!ret && GetLastError() != CRYPT_E_ASN1_BADTAG &&
|
||||
@@ -384,7 +383,7 @@ static void test_retrieveObjectByUrl(void)
|
||||
store = (HCERTSTORE)0xdeadbeef;
|
||||
ret = CryptRetrieveObjectByUrlA(url, CONTEXT_OID_CAPI2_ANY, 0, 0,
|
||||
&store, NULL, NULL, NULL, NULL);
|
||||
ok(ret, "CryptRetrieveObjectByUrlA failed: %d\n", GetLastError());
|
||||
ok(ret, "CryptRetrieveObjectByUrlA failed: %ld\n", GetLastError());
|
||||
if (store && store != (HCERTSTORE)0xdeadbeef)
|
||||
{
|
||||
DWORD certs = 0;
|
||||
@@ -395,14 +394,14 @@ static void test_retrieveObjectByUrl(void)
|
||||
if (cert)
|
||||
certs++;
|
||||
} while (cert);
|
||||
ok(certs == 1, "Expected 1 cert, got %d\n", certs);
|
||||
ok(certs == 1, "Expected 1 cert, got %ld\n", certs);
|
||||
CertCloseStore(store, 0);
|
||||
}
|
||||
/* Are file URLs cached? */
|
||||
cert = (PCCERT_CONTEXT)0xdeadbeef;
|
||||
ret = CryptRetrieveObjectByUrlA(url, CONTEXT_OID_CERTIFICATE,
|
||||
CRYPT_CACHE_ONLY_RETRIEVAL, 0, (void **)&cert, NULL, NULL, NULL, NULL);
|
||||
ok(ret, "CryptRetrieveObjectByUrlA failed: %08x\n", GetLastError());
|
||||
ok(ret, "CryptRetrieveObjectByUrlA failed: %08lx\n", GetLastError());
|
||||
if (cert && cert != (PCCERT_CONTEXT)0xdeadbeef)
|
||||
CertFreeCertificateContext(cert);
|
||||
|
||||
@@ -411,7 +410,7 @@ static void test_retrieveObjectByUrl(void)
|
||||
(void **)&cert, NULL, NULL, NULL, &aux);
|
||||
/* w2k: failure with E_INVALIDARG */
|
||||
ok(ret || broken(GetLastError() == E_INVALIDARG),
|
||||
"got %u with 0x%x/%u (expected '!=0' or '0' with E_INVALIDARG)\n",
|
||||
"got %u with 0x%lx/%lu (expected '!=0' or '0' with E_INVALIDARG)\n",
|
||||
ret, GetLastError(), GetLastError());
|
||||
if (cert && cert != (PCCERT_CONTEXT)0xdeadbeef)
|
||||
CertFreeCertificateContext(cert);
|
||||
@@ -422,7 +421,7 @@ static void test_retrieveObjectByUrl(void)
|
||||
(void **)&cert, NULL, NULL, NULL, &aux);
|
||||
/* w2k: failure with E_INVALIDARG */
|
||||
ok(ret || broken(GetLastError() == E_INVALIDARG),
|
||||
"got %u with 0x%x/%u (expected '!=0' or '0' with E_INVALIDARG)\n",
|
||||
"got %u with 0x%lx/%lu (expected '!=0' or '0' with E_INVALIDARG)\n",
|
||||
ret, GetLastError(), GetLastError());
|
||||
if (!ret) {
|
||||
/* no more tests useful */
|
||||
@@ -435,7 +434,7 @@ static void test_retrieveObjectByUrl(void)
|
||||
aux.pLastSyncTime = &ft;
|
||||
ret = CryptRetrieveObjectByUrlA(url, CONTEXT_OID_CERTIFICATE, 0, 0,
|
||||
(void **)&cert, NULL, NULL, NULL, &aux);
|
||||
ok(ret, "CryptRetrieveObjectByUrlA failed: %08x\n", GetLastError());
|
||||
ok(ret, "CryptRetrieveObjectByUrlA failed: %08lx\n", GetLastError());
|
||||
CertFreeCertificateContext(cert);
|
||||
ok(ft.dwLowDateTime || ft.dwHighDateTime,
|
||||
"Expected last sync time to be set\n");
|
||||
@@ -446,7 +445,7 @@ static void test_retrieveObjectByUrl(void)
|
||||
CRYPT_CACHE_ONLY_RETRIEVAL, 0, (void **)&cert, NULL, NULL, NULL, NULL);
|
||||
ok(!ret && (GetLastError() == ERROR_FILE_NOT_FOUND ||
|
||||
GetLastError() == ERROR_PATH_NOT_FOUND),
|
||||
"Expected ERROR_FILE_NOT_FOUND or ERROR_PATH_NOT_FOUND, got %d\n",
|
||||
"Expected ERROR_FILE_NOT_FOUND or ERROR_PATH_NOT_FOUND, got %ld\n",
|
||||
GetLastError());
|
||||
}
|
||||
|
||||
@@ -594,200 +593,279 @@ static SYSTEMTIME may2007 = { 2007, 5, 2, 1, 0, 0, 0, 0 };
|
||||
|
||||
static void test_verifyRevocation(void)
|
||||
{
|
||||
HMODULE hCryptNet = GetModuleHandleA("cryptnet.dll");
|
||||
BOOL ret;
|
||||
CERT_REVOCATION_STATUS status = { sizeof(status), 0 };
|
||||
PCCERT_CONTEXT certs[2];
|
||||
CERT_REVOCATION_PARA revPara = { sizeof(revPara), 0 };
|
||||
CERT_REVOCATION_STATUS status;
|
||||
CERT_REVOCATION_PARA params = {sizeof(params)};
|
||||
const CERT_CONTEXT *certs[2];
|
||||
FILETIME time;
|
||||
BOOL ret;
|
||||
|
||||
pCertVerifyRevocation = (void *)GetProcAddress(GetModuleHandleA("cryptnet.dll"), "CertDllVerifyRevocation");
|
||||
|
||||
pCertVerifyRevocation = (void *)GetProcAddress(hCryptNet,
|
||||
"CertDllVerifyRevocation");
|
||||
if (!pCertVerifyRevocation)
|
||||
{
|
||||
win_skip("no CertDllVerifyRevocation\n");
|
||||
return;
|
||||
}
|
||||
if (0)
|
||||
{
|
||||
/* Crash */
|
||||
pCertVerifyRevocation(0, 0, 0, NULL, 0, NULL, NULL);
|
||||
}
|
||||
|
||||
SetLastError(0xdeadbeef);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(0, 0, 0, NULL, 0, NULL, &status);
|
||||
ok(!ret && GetLastError() == E_INVALIDARG,
|
||||
"expected E_INVALIDARG, got %08x\n", GetLastError());
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == E_INVALIDARG, "got error %#lx\n", GetLastError());
|
||||
todo_wine ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
todo_wine ok(status.dwError == E_INVALIDARG, "got error %#lx\n", status.dwError);
|
||||
todo_wine ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, 0, 0, NULL, 0, NULL,
|
||||
&status);
|
||||
ok(!ret && GetLastError() == E_INVALIDARG,
|
||||
"expected E_INVALIDARG, got %08x\n", GetLastError());
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, 0, 0, NULL, 0, NULL, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == E_INVALIDARG, "got error %#lx\n", GetLastError());
|
||||
todo_wine ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
todo_wine ok(status.dwError == E_INVALIDARG, "got error %#lx\n", status.dwError);
|
||||
todo_wine ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE, 0, NULL, 0,
|
||||
NULL, &status);
|
||||
ok(!ret && GetLastError() == E_INVALIDARG,
|
||||
"expected E_INVALIDARG, got %08x\n", GetLastError());
|
||||
certs[0] = CertCreateCertificateContext(X509_ASN_ENCODING, bigCert,
|
||||
sizeof(bigCert));
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE, 0, NULL, 0, NULL, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == E_INVALIDARG, "got error %#lx\n", GetLastError());
|
||||
todo_wine ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
todo_wine ok(status.dwError == E_INVALIDARG, "got error %#lx\n", status.dwError);
|
||||
todo_wine ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
certs[0] = CertCreateCertificateContext(X509_ASN_ENCODING, bigCert, sizeof(bigCert));
|
||||
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)certs, 0, NULL, &status);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", GetLastError());
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", status.dwError);
|
||||
ok(status.dwIndex == 0, "expected index 0, got %d\n", status.dwIndex);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE, 1, (void **)certs, 0, NULL, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
CertFreeCertificateContext(certs[0]);
|
||||
certs[0] = CertCreateCertificateContext(X509_ASN_ENCODING,
|
||||
rootWithKeySignAndCRLSign, sizeof(rootWithKeySignAndCRLSign));
|
||||
certs[1] = CertCreateCertificateContext(X509_ASN_ENCODING,
|
||||
revokedCert, sizeof(revokedCert));
|
||||
|
||||
certs[0] = CertCreateCertificateContext(X509_ASN_ENCODING, rootWithKeySignAndCRLSign, sizeof(rootWithKeySignAndCRLSign));
|
||||
certs[1] = CertCreateCertificateContext(X509_ASN_ENCODING, revokedCert, sizeof(revokedCert));
|
||||
|
||||
/* The root cert itself can't be checked for revocation */
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)certs, 0, NULL, &status);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", GetLastError());
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", status.dwError);
|
||||
ok(status.dwIndex == 0, "expected index 0, got %d\n", status.dwIndex);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE, 1, (void **)&certs[0], 0, NULL, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
/* Neither can the end cert */
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, NULL, &status);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", GetLastError());
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", status.dwError);
|
||||
ok(status.dwIndex == 0, "expected index 0, got %d\n", status.dwIndex);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE, 1, (void **)&certs[1], 0, NULL, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
/* Both certs together can't, either (they're not CRLs) */
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
2, (void **)certs, 0, NULL, &status);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", GetLastError());
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", status.dwError);
|
||||
ok(status.dwIndex == 0, "expected index 0, got %d\n", status.dwIndex);
|
||||
/* Now add a CRL to the hCrlStore */
|
||||
revPara.hCrlStore = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0,
|
||||
CERT_STORE_CREATE_NEW_FLAG, NULL);
|
||||
CertAddEncodedCRLToStore(revPara.hCrlStore, X509_ASN_ENCODING,
|
||||
rootSignedCRLWithBadAKI, sizeof(rootSignedCRLWithBadAKI),
|
||||
CERT_STORE_ADD_ALWAYS, NULL);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE, 2, (void **)certs, 0, NULL, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
/* Test with an invalid CRL */
|
||||
|
||||
params.hCrlStore = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0, CERT_STORE_CREATE_NEW_FLAG, NULL);
|
||||
ret = CertAddEncodedCRLToStore(params.hCrlStore, X509_ASN_ENCODING, rootSignedCRLWithBadAKI,
|
||||
sizeof(rootSignedCRLWithBadAKI), CERT_STORE_ADD_ALWAYS, NULL);
|
||||
ok(ret, "failed to add CRL, error %lu\n", GetLastError());
|
||||
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
2, (void **)certs, 0, &revPara, &status);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", GetLastError());
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", status.dwError);
|
||||
ok(status.dwIndex == 0, "expected index 0, got %d\n", status.dwIndex);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
2, (void **)certs, 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
/* Specifying CERT_VERIFY_REV_CHAIN_FLAG doesn't change things either */
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
2, (void **)certs, CERT_VERIFY_REV_CHAIN_FLAG, &revPara, &status);
|
||||
ok(!ret && GetLastError() == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", GetLastError());
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK,
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", status.dwError);
|
||||
ok(status.dwIndex == 0, "expected index 0, got %d\n", status.dwIndex);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
2, (void **)certs, CERT_VERIFY_REV_CHAIN_FLAG, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
/* Again, specifying the issuer cert: no change */
|
||||
revPara.pIssuerCert = certs[0];
|
||||
params.pIssuerCert = certs[0];
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, &revPara, &status);
|
||||
/* Win2k thinks the cert is revoked, and it is, except the CRL contains a
|
||||
* bad authority key ID extension and can't be matched with the issuer
|
||||
* cert, hence the revocation status should be unknown.
|
||||
*/
|
||||
if (!ret && GetLastError() == ERROR_FILE_NOT_FOUND)
|
||||
{
|
||||
win_skip("CERT_CONTEXT_REVOCATION_TYPE unsupported, skipping\n");
|
||||
return;
|
||||
}
|
||||
ok(!ret && (GetLastError() == CRYPT_E_NO_REVOCATION_CHECK ||
|
||||
broken(GetLastError() == CRYPT_E_REVOKED /* Win2k */)),
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", GetLastError());
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK ||
|
||||
broken(status.dwError == CRYPT_E_REVOKED /* Win2k */),
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", status.dwError);
|
||||
ok(status.dwIndex == 0, "expected index 0, got %d\n", status.dwIndex);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
/* Specifying the time to check: still no change */
|
||||
SystemTimeToFileTime(&oct2007, &time);
|
||||
revPara.pftTimeToUse = &time;
|
||||
params.pftTimeToUse = &time;
|
||||
|
||||
SetLastError(0xdeadbeef);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, &revPara, &status);
|
||||
ok(!ret, "Expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK ||
|
||||
broken(GetLastError() == CRYPT_E_REVOKED), /* W2K SP3/SP4 */
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", GetLastError());
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK ||
|
||||
broken(GetLastError() == CRYPT_E_REVOKED), /* W2K SP3/SP4 */
|
||||
"expected CRYPT_E_NO_REVOCATION_CHECK, got %08x\n", status.dwError);
|
||||
ok(status.dwIndex == 0, "expected index 0, got %d\n", status.dwIndex);
|
||||
CertCloseStore(revPara.hCrlStore, 0);
|
||||
1, (void **)&certs[1], 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
CertCloseStore(params.hCrlStore, 0);
|
||||
|
||||
/* Test again with a valid CRL. This time, the cert should be revoked when
|
||||
* the time is after the validity period of the CRL, or considered
|
||||
* "revocation offline" when the checked time precedes the validity
|
||||
* period of the CRL.
|
||||
*/
|
||||
revPara.hCrlStore = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0,
|
||||
CERT_STORE_CREATE_NEW_FLAG, NULL);
|
||||
ret = CertAddEncodedCRLToStore(revPara.hCrlStore, X509_ASN_ENCODING,
|
||||
rootSignedCRL, sizeof(rootSignedCRL), CERT_STORE_ADD_ALWAYS, NULL);
|
||||
ok(ret, "CertAddEncodedCRLToStore failed: %08x\n", GetLastError());
|
||||
revPara.pftTimeToUse = NULL;
|
||||
params.hCrlStore = CertOpenStore(CERT_STORE_PROV_MEMORY, 0, 0, CERT_STORE_CREATE_NEW_FLAG, NULL);
|
||||
ret = CertAddEncodedCRLToStore(params.hCrlStore, X509_ASN_ENCODING,
|
||||
rootSignedCRL, sizeof(rootSignedCRL), CERT_STORE_ADD_ALWAYS, NULL);
|
||||
ok(ret, "failed to add CRL, error %lu\n", GetLastError());
|
||||
|
||||
params.pftTimeToUse = NULL;
|
||||
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, &revPara, &status);
|
||||
ok(!ret && (GetLastError() == CRYPT_E_REVOKED ||
|
||||
broken(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK /* NT4 */)),
|
||||
"expected CRYPT_E_REVOKED, got %08x\n", GetLastError());
|
||||
revPara.pftTimeToUse = &time;
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_REVOKED, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_REVOKED, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
SystemTimeToFileTime(&oct2007, &time);
|
||||
params.pftTimeToUse = &time;
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, &revPara, &status);
|
||||
ok(!ret && (GetLastError() == CRYPT_E_REVOKED ||
|
||||
broken(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK /* NT4 */)),
|
||||
"expected CRYPT_E_REVOKED, got %08x\n", GetLastError());
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_REVOKED, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_REVOKED, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
SystemTimeToFileTime(&may2007, &time);
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, &revPara, &status);
|
||||
ok(!ret && (GetLastError() == CRYPT_E_REVOCATION_OFFLINE ||
|
||||
broken(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK /* NT4 */)),
|
||||
"expected CRYPT_E_REVOCATION_OFFLINE, got %08x\n", GetLastError());
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_REVOCATION_OFFLINE, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_REVOCATION_OFFLINE, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
CertFreeCertificateContext(certs[1]);
|
||||
|
||||
/* Test again with a valid CRL and an un-revoked cert. No matter the
|
||||
* time checked, it's reported as revocation offline.
|
||||
*/
|
||||
certs[1] = CertCreateCertificateContext(X509_ASN_ENCODING,
|
||||
unRevokedCert, sizeof(unRevokedCert));
|
||||
ok(certs[1] != NULL, "CertCreateCertificateContext failed: %08x\n",
|
||||
GetLastError());
|
||||
revPara.pftTimeToUse = NULL;
|
||||
certs[1] = CertCreateCertificateContext(X509_ASN_ENCODING, unRevokedCert, sizeof(unRevokedCert));
|
||||
|
||||
params.pftTimeToUse = NULL;
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, &revPara, &status);
|
||||
ok(!ret && (GetLastError() == CRYPT_E_REVOCATION_OFFLINE ||
|
||||
broken(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK /* NT4 */)),
|
||||
"expected CRYPT_E_REVOCATION_OFFLINE, got %08x\n", GetLastError());
|
||||
revPara.pftTimeToUse = &time;
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_REVOCATION_OFFLINE, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_REVOCATION_OFFLINE, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
SystemTimeToFileTime(&oct2007, &time);
|
||||
params.pftTimeToUse = &time;
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, &revPara, &status);
|
||||
ok(!ret && (GetLastError() == CRYPT_E_REVOCATION_OFFLINE ||
|
||||
broken(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK /* NT4 */)),
|
||||
"expected CRYPT_E_REVOCATION_OFFLINE, got %08x\n", GetLastError());
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_REVOCATION_OFFLINE, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_REVOCATION_OFFLINE, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
SystemTimeToFileTime(&may2007, &time);
|
||||
SetLastError(0xdeadbeef);
|
||||
ret = CertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, &revPara, &status);
|
||||
ok(!ret && (GetLastError() == CRYPT_E_REVOCATION_OFFLINE ||
|
||||
broken(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK /* NT4 */)),
|
||||
"expected CRYPT_E_REVOCATION_OFFLINE, got %08x\n", GetLastError());
|
||||
CertCloseStore(revPara.hCrlStore, 0);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_REVOCATION_OFFLINE, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_REVOCATION_OFFLINE, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
params.pftTimeToUse = NULL;
|
||||
|
||||
/* Test with the wrong encoding type. */
|
||||
SetLastError(0xdeadbeef);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(0, CERT_CONTEXT_REVOCATION_TYPE,
|
||||
1, (void **)&certs[1], 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
todo_wine ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
todo_wine ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
/* Test with the wrong context type. */
|
||||
SetLastError(0xdeadbeef);
|
||||
memset(&status, 0xcc, sizeof(status));
|
||||
status.cbSize = sizeof(status);
|
||||
ret = pCertVerifyRevocation(X509_ASN_ENCODING, 0xdeadbeef,
|
||||
1, (void **)&certs[1], 0, ¶ms, &status);
|
||||
ok(!ret, "expected failure\n");
|
||||
ok(GetLastError() == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", GetLastError());
|
||||
ok(!status.dwIndex, "got index %lu\n", status.dwIndex);
|
||||
ok(status.dwError == CRYPT_E_NO_REVOCATION_CHECK, "got error %#lx\n", status.dwError);
|
||||
ok(!status.dwReason, "got reason %lu\n", status.dwReason);
|
||||
|
||||
CertCloseStore(params.hCrlStore, 0);
|
||||
CertFreeCertificateContext(certs[1]);
|
||||
CertFreeCertificateContext(certs[0]);
|
||||
}
|
||||
|
||||
@@ -1,12 +0,0 @@
|
||||
/* Automatically generated file; DO NOT EDIT!! */
|
||||
|
||||
#define STANDALONE
|
||||
#include <wine/test.h>
|
||||
|
||||
extern void func_cryptnet(void);
|
||||
|
||||
const struct test winetest_testlist[] =
|
||||
{
|
||||
{ "cryptnet", func_cryptnet },
|
||||
{ 0, 0 }
|
||||
};
|
||||
Reference in New Issue
Block a user