]> Cypherpunks repositories - gostls13.git/commit
crypto/internal/fips: add SHA2,SHA3,HMAC ACVP tests
authorDaniel McCarney <daniel@binaryparadox.net>
Wed, 25 Sep 2024 19:58:32 +0000 (15:58 -0400)
committerFilippo Valsorda <filippo@golang.org>
Mon, 28 Oct 2024 15:01:02 +0000 (15:01 +0000)
commite738f06a12cf00b0333462bef0057d611ff42fee
tree4da934e2869c43f51a3822bc02153d962be6e14c
parentf0b51a2099446d3835c8d54edef8300c0f081116
crypto/internal/fips: add SHA2,SHA3,HMAC ACVP tests

Adds a new crypto/internal/fips test binary that operates as both a unit
test fetching/driving the BoringSSL acvptool, and an acvptool module
wraper when invoked by the unit test. Initial support for testing the
SHA2 and SHA3 family of digests, and the HMAC family of MACs is
included.

Test vectors and expected answers are maintained in a separate repo,
`github.com/cpu/go-acvp` and fetched through the module proxy as part of
the test process.

The BSSL acvptool "lowers" the NIST ACVP server JSON test vectors into
a simpler stdin/stdout protocol that can be implemented by a module
wrapper. The tool will fork our acvpwrapper binary, request the
supported configuration, and then provide test cases over stdin,
expecting results to be returned on stdout.

See "Testing other FIPS modules" from the BoringSSL ACVP.md
documentation for a more detailed description of the protocol used
between the acvptool and module wrappers.

Updates #69642
Updates #69536

Change-Id: I6b568c67f2a71144fbf31db467c6fd25710457f5
Reviewed-on: https://go-review.googlesource.com/c/go/+/615816
Reviewed-by: Michael Pratt <mpratt@google.com>
LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com>
Reviewed-by: Filippo Valsorda <filippo@golang.org>
Reviewed-by: Dmitri Shuralyov <dmitshur@google.com>
src/crypto/internal/fips/acvp_capabilities.json [new file with mode: 0644]
src/crypto/internal/fips/acvp_test.config.json [new file with mode: 0644]
src/crypto/internal/fips/acvp_test.go [new file with mode: 0644]