<feed xmlns='http://www.w3.org/2005/Atom'>
<title>Tianocore/edk2.git/CryptoPkg/Test/UnitTest/Library/BaseCryptLib/Pkcs7EncryptTests.c, branch master</title>
<subtitle>EDK II (mirror)</subtitle>
<id>https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/Tianocore/edk2.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/'/>
<updated>2026-08-28T12:37:18+00:00</updated>
<entry>
<title>CryptoPkg: Add Pkcs7Decrypt API</title>
<updated>2026-08-28T12:37:18+00:00</updated>
<author>
<name>Doug Cook</name>
<email>dcook@microsoft.com</email>
</author>
<published>2026-07-27T23:15:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=5337420d7c59b446a4ec9f1348bc75e47de8299d'/>
<id>urn:sha1:5337420d7c59b446a4ec9f1348bc75e47de8299d</id>
<content type='text'>
Add support for a Pkcs7Decrypt API, mirroring the Pkcs7Encrypt API.

I expect that the primary use of Pkcs7Decrypt would be for testing the
Pkcs7Encrypt API, but maybe somebody will need it for real work someday.

Signed-off-by: Doug Cook &lt;dcook@microsoft.com&gt;
Committed-by: Doug Flick &lt;dougflick@microsoft.com&gt;
</content>
</entry>
<entry>
<title>CryptoPkg: Add Pkcs7Encrypt smoke tests</title>
<updated>2026-08-28T12:37:18+00:00</updated>
<author>
<name>Doug Flick</name>
<email>dougflick@microsoft.com</email>
</author>
<published>2026-06-03T22:08:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/Tianocore/edk2.git/commit/?id=07a37d45eef9972b7fc3deb761d5c24527a17387'/>
<id>urn:sha1:07a37d45eef9972b7fc3deb761d5c24527a17387</id>
<content type='text'>
These don't actually decrypt anything, so calling them "unit tests"
was a stretch. They're smoke tests: build an envelopedData ContentInfo
for a recipient cert, then walk the DER and check the shape looks
right (id-envelopedData, CMSVersion, the right number of
RecipientInfo entries, the expected content-encryption OID).

Covered:

  * AES-128/192/256-CBC happy paths.
  * Two recipients, just to confirm the SET grows.
  * The parameter-validation contract from BaseCryptLib.h
    (NULL stack/InData/output pointers, bogus CipherNid, bogus Flags).

The DER walker is hand-rolled in the test file so we don't have to
pull OpenSSL or mbedtls headers into a unit test that has to compile
against both. It catches obvious shape regressions but won't notice
if the CEK, IV, or PKCS#7 padding are wrong - a real round-trip needs
a Pkcs7Decrypt API we don't have yet.

Signed-off-by: Doug Flick &lt;dougflick@microsoft.com&gt;
</content>
</entry>
</feed>
