summaryrefslogtreecommitdiff
path: root/CryptoPkg/Test/UnitTest/Library/BaseCryptLib/Pkcs7EncryptTestCert.h
AgeCommit message (Collapse)AuthorFilesLines
2026-08-28CryptoPkg: Add Pkcs7Decrypt APIDoug Cook1-64/+354
Add support for a Pkcs7Decrypt API, mirroring the Pkcs7Encrypt API. I expect that the primary use of Pkcs7Decrypt would be for testing the Pkcs7Encrypt API, but maybe somebody will need it for real work someday. Signed-off-by: Doug Cook <dcook@microsoft.com> Committed-by: Doug Flick <dougflick@microsoft.com>
2026-08-28CryptoPkg: Add Pkcs7Encrypt smoke testsDoug Flick1-0/+77
These don't actually decrypt anything, so calling them "unit tests" was a stretch. They're smoke tests: build an envelopedData ContentInfo for a recipient cert, then walk the DER and check the shape looks right (id-envelopedData, CMSVersion, the right number of RecipientInfo entries, the expected content-encryption OID). Covered: * AES-128/192/256-CBC happy paths. * Two recipients, just to confirm the SET grows. * The parameter-validation contract from BaseCryptLib.h (NULL stack/InData/output pointers, bogus CipherNid, bogus Flags). The DER walker is hand-rolled in the test file so we don't have to pull OpenSSL or mbedtls headers into a unit test that has to compile against both. It catches obvious shape regressions but won't notice if the CEK, IV, or PKCS#7 padding are wrong - a real round-trip needs a Pkcs7Decrypt API we don't have yet. Signed-off-by: Doug Flick <dougflick@microsoft.com>