mirror of
https://github.com/ultravioletrs/cocos.git
synced 2026-08-07 07:14:50 +00:00
NOISSUE - Add FetchKbsToken RPC support, update protobuf generation, and include additional binaries in CI workflow. (#610)
CI / checkproto (push) Has been cancelled
CI / lint (push) Has been cancelled
CI / test (agent) (push) Has been cancelled
CI / test (cli) (push) Has been cancelled
CI / test (cmd) (push) Has been cancelled
CI / test (internal) (push) Has been cancelled
CI / test (manager, true) (push) Has been cancelled
CI / test (pkg) (push) Has been cancelled
CI / upload-coverage (push) Has been cancelled
CI / checkproto (push) Has been cancelled
CI / lint (push) Has been cancelled
CI / test (agent) (push) Has been cancelled
CI / test (cli) (push) Has been cancelled
CI / test (cmd) (push) Has been cancelled
CI / test (internal) (push) Has been cancelled
CI / test (manager, true) (push) Has been cancelled
CI / test (pkg) (push) Has been cancelled
CI / upload-coverage (push) Has been cancelled
* feat: add FetchKbsToken RPC support, update protobuf generation, and include additional binaries in CI workflow. Signed-off-by: Sammy Oina <sammyoina@gmail.com> * chore: update protoc version and add GetKbsToken mock method with updated kbsHTTPGet signature Signed-off-by: Sammy Oina <sammyoina@gmail.com> * test: inject mock attestation client into agentService for resource and KBS tests Signed-off-by: Sammy Oina <sammyoina@gmail.com> * test: update key derivation in tests to use Concat KDF instead of HKDF Signed-off-by: Sammy Oina <sammyoina@gmail.com> --------- Signed-off-by: Sammy Oina <sammyoina@gmail.com>
This commit is contained in:
committed by
GitHub
parent
cbf2a44c6a
commit
13f7e97d82
+27
-14
@@ -15,9 +15,31 @@ import (
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"golang.org/x/crypto/hkdf"
|
||||
)
|
||||
|
||||
// testConcatKDF derives a KEK using Concat KDF (NIST SP 800-56A), matching
|
||||
// the exact implementation in DecryptWithWrappedKey.
|
||||
func testConcatKDF(sharedSecret []byte) []byte {
|
||||
algStr := "ECDH-ES+A256KW"
|
||||
otherInfo := make([]byte, 0, 4+len(algStr)+4+4+4)
|
||||
algLen := uint32(len(algStr))
|
||||
otherInfo = append(otherInfo, byte(algLen>>24), byte(algLen>>16), byte(algLen>>8), byte(algLen))
|
||||
otherInfo = append(otherInfo, algStr...)
|
||||
otherInfo = append(otherInfo, 0, 0, 0, 0) // PartyUInfo
|
||||
otherInfo = append(otherInfo, 0, 0, 0, 0) // PartyVInfo
|
||||
otherInfo = append(otherInfo, 0, 0, 1, 0) // SuppPubInfo (256 bits BE)
|
||||
|
||||
counter := uint32(1)
|
||||
hashInput := make([]byte, 0, 4+len(sharedSecret)+len(otherInfo))
|
||||
hashInput = append(hashInput, byte(counter>>24), byte(counter>>16), byte(counter>>8), byte(counter))
|
||||
hashInput = append(hashInput, sharedSecret...)
|
||||
hashInput = append(hashInput, otherInfo...)
|
||||
|
||||
h := sha256.New()
|
||||
h.Write(hashInput)
|
||||
return h.Sum(nil)
|
||||
}
|
||||
|
||||
// testAESKeyWrap implements RFC 3394 AES Key Wrap for use in test setup.
|
||||
func testAESKeyWrap(kek, key []byte) ([]byte, error) {
|
||||
block, err := aes.NewCipher(kek)
|
||||
@@ -527,11 +549,8 @@ func TestDecryptWithWrappedKeyFullRoundTrip(t *testing.T) {
|
||||
sharedSecret, err := ephemeralKey.ECDH(recipientKey.PublicKey())
|
||||
require.NoError(t, err)
|
||||
|
||||
// Derive KEK using HKDF (same as in DecryptWithWrappedKey)
|
||||
kek := make([]byte, 32)
|
||||
kdf := hkdf.New(sha256.New, sharedSecret, nil, nil)
|
||||
_, err = kdf.Read(kek)
|
||||
require.NoError(t, err)
|
||||
// Derive KEK using Concat KDF (same as in DecryptWithWrappedKey)
|
||||
kek := testConcatKDF(sharedSecret)
|
||||
|
||||
// Generate random CEK (32 bytes)
|
||||
cek := make([]byte, 32)
|
||||
@@ -589,10 +608,7 @@ func TestDecryptWithWrappedKeyFullRoundTrip(t *testing.T) {
|
||||
sharedSecret, err := ephemeralKey.ECDH(recipientKey.PublicKey())
|
||||
require.NoError(t, err)
|
||||
|
||||
kek := make([]byte, 32)
|
||||
kdf := hkdf.New(sha256.New, sharedSecret, nil, nil)
|
||||
_, err = kdf.Read(kek)
|
||||
require.NoError(t, err)
|
||||
kek := testConcatKDF(sharedSecret)
|
||||
|
||||
cek := make([]byte, 16) // 16-byte CEK (AES-128)
|
||||
_, err = rand.Read(cek)
|
||||
@@ -650,10 +666,7 @@ func TestDecryptWithWrappedKeyFullRoundTrip(t *testing.T) {
|
||||
sharedSecret, err := ephemeralKey.ECDH(recipientKey.PublicKey())
|
||||
require.NoError(t, err)
|
||||
|
||||
kek := make([]byte, 32)
|
||||
kdf := hkdf.New(sha256.New, sharedSecret, nil, nil)
|
||||
_, err = kdf.Read(kek)
|
||||
require.NoError(t, err)
|
||||
kek := testConcatKDF(sharedSecret)
|
||||
|
||||
cek := make([]byte, 32)
|
||||
_, err = rand.Read(cek)
|
||||
|
||||
Reference in New Issue
Block a user