Skip to content

Commit 2c109b2

Browse files
authored
Merge pull request #1092 from rhenium/ky/pkey-docs-avoid-public-key
pkey: avoid using {DH,DSA,RSA}#public_key in docs and tests
2 parents e324933 + 13d5616 commit 2c109b2

7 files changed

Lines changed: 49 additions & 30 deletions

File tree

‎ext/openssl/ossl.c‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -754,7 +754,7 @@ ossl_crypto_fixed_length_secure_compare(VALUE dummy, VALUE str1, VALUE str2)
754754
* cert.not_before = Time.now
755755
* cert.not_after = Time.now + 3600
756756
*
757-
* cert.public_key = key.public_key
757+
* cert.public_key = key
758758
* cert.subject = name
759759
*
760760
* === Certificate Extensions
@@ -836,7 +836,7 @@ ossl_crypto_fixed_length_secure_compare(VALUE dummy, VALUE str1, VALUE str2)
836836
* ca_cert.not_before = Time.now
837837
* ca_cert.not_after = Time.now + 86400
838838
*
839-
* ca_cert.public_key = ca_key.public_key
839+
* ca_cert.public_key = ca_key
840840
* ca_cert.subject = ca_name
841841
* ca_cert.issuer = ca_name
842842
*
@@ -878,7 +878,7 @@ ossl_crypto_fixed_length_secure_compare(VALUE dummy, VALUE str1, VALUE str2)
878878
* csr = OpenSSL::X509::Request.new
879879
* csr.version = 0
880880
* csr.subject = name
881-
* csr.public_key = key.public_key
881+
* csr.public_key = key
882882
* csr.sign key, OpenSSL::Digest.new('SHA1')
883883
*
884884
* A CSR is saved to disk and sent to the CA for signing.

‎ext/openssl/ossl_ns_spki.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -336,7 +336,7 @@ ossl_spki_verify(VALUE self, VALUE key)
336336
* key = OpenSSL::PKey::RSA.new 2048
337337
* spki = OpenSSL::Netscape::SPKI.new
338338
* spki.challenge = "RandomChallenge"
339-
* spki.public_key = key.public_key
339+
* spki.public_key = key
340340
* spki.sign(key, OpenSSL::Digest.new('SHA256'))
341341
* #send a request containing this to a server generating a certificate
342342
* === Verifying an SPKI request

‎ext/openssl/ossl_pkey.c‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1192,7 +1192,7 @@ ossl_pkey_compare(VALUE self, VALUE other)
11921192
* signature = pkey.sign("SHA256", data, signopts)
11931193
*
11941194
* # Creates a copy of the RSA key pkey, but without the private components
1195-
* pub_key = pkey.public_key
1195+
* pub_key = OpenSSL::PKey.read(pkey.public_to_der)
11961196
* puts pub_key.verify("SHA256", signature, data, signopts) # => true
11971197
*/
11981198
static VALUE
@@ -1350,7 +1350,7 @@ ossl_pkey_verify(int argc, VALUE *argv, VALUE self)
13501350
* signature = pkey.sign_raw("SHA256", hash, signopts)
13511351
*
13521352
* # Creates a copy of the RSA key pkey, but without the private components
1353-
* pub_key = pkey.public_key
1353+
* pub_key = OpenSSL::PKey.read(pkey.public_to_der)
13541354
* puts pub_key.verify_raw("SHA256", signature, hash, signopts) # => true
13551355
*/
13561356
static VALUE

‎ext/openssl/ossl_x509cert.c‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -922,7 +922,7 @@ Init_ossl_x509cert(void)
922922
* root_ca.serial = 1
923923
* root_ca.subject = OpenSSL::X509::Name.parse "/DC=org/DC=ruby-lang/CN=Ruby CA"
924924
* root_ca.issuer = root_ca.subject # root CA's are "self-signed"
925-
* root_ca.public_key = root_key.public_key
925+
* root_ca.public_key = root_key
926926
* root_ca.not_before = Time.now
927927
* root_ca.not_after = root_ca.not_before + 2 * 365 * 24 * 60 * 60 # 2 years validity
928928
* ef = OpenSSL::X509::ExtensionFactory.new
@@ -943,7 +943,7 @@ Init_ossl_x509cert(void)
943943
* cert.serial = 2
944944
* cert.subject = OpenSSL::X509::Name.parse "/DC=org/DC=ruby-lang/CN=Ruby certificate"
945945
* cert.issuer = root_ca.subject # root CA is the issuer
946-
* cert.public_key = key.public_key
946+
* cert.public_key = key
947947
* cert.not_before = Time.now
948948
* cert.not_after = cert.not_before + 1 * 365 * 24 * 60 * 60 # 1 years validity
949949
* ef = OpenSSL::X509::ExtensionFactory.new

‎test/openssl/test_ns_spki.rb‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -21,17 +21,17 @@ def test_build_data
2121
key2 = Fixtures.pkey("rsa-2")
2222
spki = OpenSSL::Netscape::SPKI.new
2323
spki.challenge = "RandomString"
24-
spki.public_key = key1.public_key
24+
spki.public_key = key1
2525
spki.sign(key1, OpenSSL::Digest.new('SHA256'))
26-
assert(spki.verify(spki.public_key))
27-
assert(spki.verify(key1.public_key))
28-
assert(!spki.verify(key2.public_key))
26+
assert_true(spki.verify(spki.public_key))
27+
assert_true(spki.verify(OpenSSL::PKey.read(key1.public_to_der)))
28+
assert_false(spki.verify(OpenSSL::PKey.read(key2.public_to_der)))
2929

3030
der = spki.to_der
3131
spki = OpenSSL::Netscape::SPKI.new(der)
3232
assert_equal("RandomString", spki.challenge)
33-
assert_equal(key1.public_key.to_der, spki.public_key.to_der)
34-
assert(spki.verify(spki.public_key))
33+
assert_equal(key1.public_to_der, spki.public_key.public_to_der)
34+
assert_true(spki.verify(spki.public_key))
3535
assert_not_nil(spki.to_text)
3636
end
3737

‎test/openssl/test_pkey_dsa.rb‎

Lines changed: 18 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -14,16 +14,15 @@ def test_private
1414
assert_equal true, key.private?
1515
key2 = OpenSSL::PKey::DSA.new(key.to_der)
1616
assert_equal true, key2.private?
17-
key3 = key.public_key
17+
key3 = OpenSSL::PKey::DSA.new(key.public_to_der)
1818
assert_equal false, key3.private?
19-
key4 = OpenSSL::PKey::DSA.new(key3.to_der)
20-
assert_equal false, key4.private?
2119
end
2220

2321
def test_new
24-
key = OpenSSL::PKey::DSA.new(2048)
25-
pem = key.public_key.to_pem
26-
OpenSSL::PKey::DSA.new pem
22+
key = OpenSSL::PKey::DSA.new(1024)
23+
assert_predicate(key, :private?)
24+
assert_equal(1024, key.p.num_bits)
25+
assert_equal(160, key.q.num_bits)
2726
end
2827

2928
def test_new_break
@@ -233,6 +232,19 @@ def test_params
233232
assert_nil(pubkey.params["priv_key"])
234233
end
235234

235+
def test_public_key
236+
key = Fixtures.pkey("dsa2048")
237+
pub = key.public_key
238+
assert_not_predicate(pub, :private?)
239+
assert_predicate(pub, :public?)
240+
assert_equal(key.p, pub.p)
241+
assert_equal(key.q, pub.q)
242+
assert_equal(key.g, pub.g)
243+
assert_equal(key.pub_key, pub.pub_key)
244+
assert_nil(pub.priv_key)
245+
assert_equal(key.public_to_der, pub.to_der)
246+
end
247+
236248
def test_dup
237249
key = Fixtures.pkey("dsa2048")
238250
key2 = key.dup

‎test/openssl/test_pkey_rsa.rb‎

Lines changed: 17 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -20,13 +20,9 @@ def test_private
2020
key2 = OpenSSL::PKey::RSA.new(key.to_der)
2121
assert_true(key2.private?)
2222

23-
# public key
24-
key3 = key.public_key
25-
assert_false(key3.private?)
26-
2723
# Generated by public key DER
28-
key4 = OpenSSL::PKey::RSA.new(key3.to_der)
29-
assert_false(key4.private?)
24+
key3 = OpenSSL::PKey::RSA.new(key.public_to_der)
25+
assert_false(key3.private?)
3026

3127
if !openssl?(3, 0, 0)
3228
# Generated by RSA#set_key
@@ -290,11 +286,11 @@ def test_export
290286

291287
# key has only n, e and d
292288
key.set_key(orig.n, orig.e, orig.d)
293-
assert_equal orig.public_key.export, key.export
289+
assert_equal pub.export, key.export
294290

295291
# key has only n, e, d, p and q
296292
key.set_factors(orig.p, orig.q)
297-
assert_equal orig.public_key.export, key.export
293+
assert_equal pub.export, key.export
298294

299295
# key has n, e, d, p, q, dmp1, dmq1 and iqmp
300296
key.set_crt_params(orig.dmp1, orig.dmq1, orig.iqmp)
@@ -315,11 +311,11 @@ def test_to_der
315311

316312
# key has only n, e and d
317313
key.set_key(orig.n, orig.e, orig.d)
318-
assert_equal orig.public_key.to_der, key.to_der
314+
assert_equal pub.to_der, key.to_der
319315

320316
# key has only n, e, d, p and q
321317
key.set_factors(orig.p, orig.q)
322-
assert_equal orig.public_key.to_der, key.to_der
318+
assert_equal pub.to_der, key.to_der
323319

324320
# key has n, e, d, p, q, dmp1, dmq1 and iqmp
325321
key.set_crt_params(orig.dmp1, orig.dmq1, orig.iqmp)
@@ -548,6 +544,17 @@ def test_get_param
548544
assert_equal(key.iqmp, key.get_param("rsa-coefficient1"))
549545
end
550546

547+
def test_public_key
548+
key = Fixtures.pkey("rsa-1")
549+
pub = key.public_key
550+
assert_not_predicate(pub, :private?)
551+
assert_predicate(pub, :public?)
552+
assert_equal(key.n, pub.n)
553+
assert_equal(key.e, pub.e)
554+
assert_nil(pub.d)
555+
assert_equal(key.public_to_der, pub.to_der)
556+
end
557+
551558
def test_dup
552559
key = Fixtures.pkey("rsa-1")
553560
key2 = key.dup

0 commit comments

Comments
 (0)