DefaultKeyResolverTests.cs 12 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276
  1. // Copyright (c) .NET Foundation. All rights reserved.
  2. // Licensed under the Apache License, Version 2.0. See License.txt in the project root for license information.
  3. using System;
  4. using System.Collections.Generic;
  5. using System.Globalization;
  6. using Microsoft.AspNetCore.DataProtection.AuthenticatedEncryption;
  7. using Microsoft.AspNetCore.DataProtection.KeyManagement.Internal;
  8. using Moq;
  9. using Xunit;
  10. namespace Microsoft.AspNetCore.DataProtection.KeyManagement
  11. {
  12. public class DefaultKeyResolverTests
  13. {
  14. [Fact]
  15. public void ResolveDefaultKeyPolicy_EmptyKeyRing_ReturnsNullDefaultKey()
  16. {
  17. // Arrange
  18. var resolver = CreateDefaultKeyResolver();
  19. // Act
  20. var resolution = resolver.ResolveDefaultKeyPolicy(DateTimeOffset.Now, new IKey[0]);
  21. // Assert
  22. Assert.Null(resolution.DefaultKey);
  23. Assert.True(resolution.ShouldGenerateNewKey);
  24. }
  25. [Fact]
  26. public void ResolveDefaultKeyPolicy_ValidExistingKey_ReturnsExistingKey()
  27. {
  28. // Arrange
  29. var resolver = CreateDefaultKeyResolver();
  30. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  31. var key2 = CreateKey("2016-03-01 00:00:00Z", "2017-03-01 00:00:00Z");
  32. // Act
  33. var resolution = resolver.ResolveDefaultKeyPolicy("2016-02-20 23:59:00Z", key1, key2);
  34. // Assert
  35. Assert.Same(key1, resolution.DefaultKey);
  36. Assert.False(resolution.ShouldGenerateNewKey);
  37. }
  38. [Fact]
  39. public void ResolveDefaultKeyPolicy_ValidExistingKey_AllowsForClockSkew_KeysStraddleSkewLine_ReturnsExistingKey()
  40. {
  41. // Arrange
  42. var resolver = CreateDefaultKeyResolver();
  43. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  44. var key2 = CreateKey("2016-03-01 00:00:00Z", "2017-03-01 00:00:00Z");
  45. // Act
  46. var resolution = resolver.ResolveDefaultKeyPolicy("2016-02-29 23:59:00Z", key1, key2);
  47. // Assert
  48. Assert.Same(key2, resolution.DefaultKey);
  49. Assert.False(resolution.ShouldGenerateNewKey);
  50. }
  51. [Fact]
  52. public void ResolveDefaultKeyPolicy_ValidExistingKey_AllowsForClockSkew_AllKeysInFuture_ReturnsExistingKey()
  53. {
  54. // Arrange
  55. var resolver = CreateDefaultKeyResolver();
  56. var key1 = CreateKey("2016-03-01 00:00:00Z", "2017-03-01 00:00:00Z");
  57. // Act
  58. var resolution = resolver.ResolveDefaultKeyPolicy("2016-02-29 23:59:00Z", key1);
  59. // Assert
  60. Assert.Same(key1, resolution.DefaultKey);
  61. Assert.False(resolution.ShouldGenerateNewKey);
  62. }
  63. [Fact]
  64. public void ResolveDefaultKeyPolicy_ValidExistingKey_NoSuccessor_ReturnsExistingKey_SignalsGenerateNewKey()
  65. {
  66. // Arrange
  67. var resolver = CreateDefaultKeyResolver();
  68. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  69. // Act
  70. var resolution = resolver.ResolveDefaultKeyPolicy("2016-02-29 23:59:00Z", key1);
  71. // Assert
  72. Assert.Same(key1, resolution.DefaultKey);
  73. Assert.True(resolution.ShouldGenerateNewKey);
  74. }
  75. [Fact]
  76. public void ResolveDefaultKeyPolicy_ValidExistingKey_NoLegitimateSuccessor_ReturnsExistingKey_SignalsGenerateNewKey()
  77. {
  78. // Arrange
  79. var resolver = CreateDefaultKeyResolver();
  80. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  81. var key2 = CreateKey("2016-03-01 00:00:00Z", "2017-03-01 00:00:00Z", isRevoked: true);
  82. var key3 = CreateKey("2016-03-01 00:00:00Z", "2016-03-02 00:00:00Z"); // key expires too soon
  83. // Act
  84. var resolution = resolver.ResolveDefaultKeyPolicy("2016-02-29 23:50:00Z", key1, key2, key3);
  85. // Assert
  86. Assert.Same(key1, resolution.DefaultKey);
  87. Assert.True(resolution.ShouldGenerateNewKey);
  88. }
  89. [Fact]
  90. public void ResolveDefaultKeyPolicy_MostRecentKeyIsInvalid_BecauseOfRevocation_ReturnsNull()
  91. {
  92. // Arrange
  93. var resolver = CreateDefaultKeyResolver();
  94. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  95. var key2 = CreateKey("2015-03-02 00:00:00Z", "2016-03-01 00:00:00Z", isRevoked: true);
  96. // Act
  97. var resolution = resolver.ResolveDefaultKeyPolicy("2015-04-01 00:00:00Z", key1, key2);
  98. // Assert
  99. Assert.Null(resolution.DefaultKey);
  100. Assert.True(resolution.ShouldGenerateNewKey);
  101. }
  102. [Fact]
  103. public void ResolveDefaultKeyPolicy_MostRecentKeyIsInvalid_BecauseOfFailureToDecipher_ReturnsNull()
  104. {
  105. // Arrange
  106. var resolver = CreateDefaultKeyResolver();
  107. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  108. var key2 = CreateKey("2015-03-02 00:00:00Z", "2016-03-01 00:00:00Z", createEncryptorInstanceThrows: true);
  109. // Act
  110. var resolution = resolver.ResolveDefaultKeyPolicy("2015-04-01 00:00:00Z", key1, key2);
  111. // Assert
  112. Assert.Null(resolution.DefaultKey);
  113. Assert.True(resolution.ShouldGenerateNewKey);
  114. }
  115. [Fact]
  116. public void ResolveDefaultKeyPolicy_FutureKeyIsValidAndWithinClockSkew_ReturnsFutureKey()
  117. {
  118. // Arrange
  119. var resolver = CreateDefaultKeyResolver();
  120. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  121. // Act
  122. var resolution = resolver.ResolveDefaultKeyPolicy("2015-02-28 23:53:00Z", key1);
  123. // Assert
  124. Assert.Same(key1, resolution.DefaultKey);
  125. Assert.False(resolution.ShouldGenerateNewKey);
  126. }
  127. [Fact]
  128. public void ResolveDefaultKeyPolicy_FutureKeyIsValidButNotWithinClockSkew_ReturnsNull()
  129. {
  130. // Arrange
  131. var resolver = CreateDefaultKeyResolver();
  132. var key1 = CreateKey("2015-03-01 00:00:00Z", "2016-03-01 00:00:00Z");
  133. // Act
  134. var resolution = resolver.ResolveDefaultKeyPolicy("2015-02-28 23:00:00Z", key1);
  135. // Assert
  136. Assert.Null(resolution.DefaultKey);
  137. Assert.True(resolution.ShouldGenerateNewKey);
  138. }
  139. [Fact]
  140. public void ResolveDefaultKeyPolicy_IgnoresExpiredOrRevokedFutureKeys()
  141. {
  142. // Arrange
  143. var resolver = CreateDefaultKeyResolver();
  144. var key1 = CreateKey("2015-03-01 00:00:00Z", "2014-03-01 00:00:00Z"); // expiration before activation should never occur
  145. var key2 = CreateKey("2015-03-01 00:01:00Z", "2015-04-01 00:00:00Z", isRevoked: true);
  146. var key3 = CreateKey("2015-03-01 00:02:00Z", "2015-04-01 00:00:00Z");
  147. // Act
  148. var resolution = resolver.ResolveDefaultKeyPolicy("2015-02-28 23:59:00Z", key1, key2, key3);
  149. // Assert
  150. Assert.Same(key3, resolution.DefaultKey);
  151. Assert.False(resolution.ShouldGenerateNewKey);
  152. }
  153. [Fact]
  154. public void ResolveDefaultKeyPolicy_FallbackKey_SelectsLatestBeforePriorPropagationWindow_IgnoresRevokedKeys()
  155. {
  156. // Arrange
  157. var resolver = CreateDefaultKeyResolver();
  158. var key1 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-01 00:00:00Z");
  159. var key2 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-02 00:00:00Z");
  160. var key3 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-03 00:00:00Z", isRevoked: true);
  161. var key4 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-04 00:00:00Z");
  162. // Act
  163. var resolution = resolver.ResolveDefaultKeyPolicy("2000-01-05 00:00:00Z", key1, key2, key3, key4);
  164. // Assert
  165. Assert.Same(key2, resolution.FallbackKey);
  166. Assert.True(resolution.ShouldGenerateNewKey);
  167. }
  168. [Fact]
  169. public void ResolveDefaultKeyPolicy_FallbackKey_SelectsLatestBeforePriorPropagationWindow_IgnoresFailures()
  170. {
  171. // Arrange
  172. var resolver = CreateDefaultKeyResolver();
  173. var key1 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-01 00:00:00Z");
  174. var key2 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-02 00:00:00Z");
  175. var key3 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-03 00:00:00Z", createEncryptorInstanceThrows: true);
  176. var key4 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-04 00:00:00Z");
  177. // Act
  178. var resolution = resolver.ResolveDefaultKeyPolicy("2000-01-05 00:00:00Z", key1, key2, key3, key4);
  179. // Assert
  180. Assert.Same(key2, resolution.FallbackKey);
  181. Assert.True(resolution.ShouldGenerateNewKey);
  182. }
  183. [Fact]
  184. public void ResolveDefaultKeyPolicy_FallbackKey_NoNonRevokedKeysBeforePriorPropagationWindow_SelectsEarliestNonRevokedKey()
  185. {
  186. // Arrange
  187. var resolver = CreateDefaultKeyResolver();
  188. var key1 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-03 00:00:00Z", isRevoked: true);
  189. var key2 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-04 00:00:00Z");
  190. var key3 = CreateKey("2010-01-01 00:00:00Z", "2010-01-01 00:00:00Z", creationDate: "2000-01-05 00:00:00Z");
  191. // Act
  192. var resolution = resolver.ResolveDefaultKeyPolicy("2000-01-05 00:00:00Z", key1, key2, key3);
  193. // Assert
  194. Assert.Same(key2, resolution.FallbackKey);
  195. Assert.True(resolution.ShouldGenerateNewKey);
  196. }
  197. private static IDefaultKeyResolver CreateDefaultKeyResolver()
  198. {
  199. return new DefaultKeyResolver(
  200. keyPropagationWindow: TimeSpan.FromDays(2),
  201. maxServerToServerClockSkew: TimeSpan.FromMinutes(7),
  202. services: null);
  203. }
  204. private static IKey CreateKey(string activationDate, string expirationDate, string creationDate = null, bool isRevoked = false, bool createEncryptorInstanceThrows = false)
  205. {
  206. var mockKey = new Mock<IKey>();
  207. mockKey.Setup(o => o.KeyId).Returns(Guid.NewGuid());
  208. mockKey.Setup(o => o.CreationDate).Returns((creationDate != null) ? DateTimeOffset.ParseExact(creationDate, "u", CultureInfo.InvariantCulture) : DateTimeOffset.MinValue);
  209. mockKey.Setup(o => o.ActivationDate).Returns(DateTimeOffset.ParseExact(activationDate, "u", CultureInfo.InvariantCulture));
  210. mockKey.Setup(o => o.ExpirationDate).Returns(DateTimeOffset.ParseExact(expirationDate, "u", CultureInfo.InvariantCulture));
  211. mockKey.Setup(o => o.IsRevoked).Returns(isRevoked);
  212. if (createEncryptorInstanceThrows)
  213. {
  214. mockKey.Setup(o => o.CreateEncryptorInstance()).Throws(new Exception("This method fails."));
  215. }
  216. else
  217. {
  218. mockKey.Setup(o => o.CreateEncryptorInstance()).Returns(new Mock<IAuthenticatedEncryptor>().Object);
  219. }
  220. return mockKey.Object;
  221. }
  222. }
  223. internal static class DefaultKeyResolverExtensions
  224. {
  225. public static DefaultKeyResolution ResolveDefaultKeyPolicy(this IDefaultKeyResolver resolver, string now, params IKey[] allKeys)
  226. {
  227. return resolver.ResolveDefaultKeyPolicy(DateTimeOffset.ParseExact(now, "u", CultureInfo.InvariantCulture), (IEnumerable<IKey>)allKeys);
  228. }
  229. }
  230. }