|
These don't actually decrypt anything, so calling them "unit tests"
was a stretch. They're smoke tests: build an envelopedData ContentInfo
for a recipient cert, then walk the DER and check the shape looks
right (id-envelopedData, CMSVersion, the right number of
RecipientInfo entries, the expected content-encryption OID).
Covered:
* AES-128/192/256-CBC happy paths.
* Two recipients, just to confirm the SET grows.
* The parameter-validation contract from BaseCryptLib.h
(NULL stack/InData/output pointers, bogus CipherNid, bogus Flags).
The DER walker is hand-rolled in the test file so we don't have to
pull OpenSSL or mbedtls headers into a unit test that has to compile
against both. It catches obvious shape regressions but won't notice
if the CEK, IV, or PKCS#7 padding are wrong - a real round-trip needs
a Pkcs7Decrypt API we don't have yet.
Signed-off-by: Doug Flick <dougflick@microsoft.com>
|