Browse Source

Add RSA-4096 and EC-P256 key types, parameterize all tests

- Add RSA_4096 and EC_P256 alongside RSA_2048 and EC_P384
- Parameterize encrypted key tests (RSA-only, EC encrypted keys
  are a pre-existing PemSslCredentials limitation)
- 14 test scenarios total

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
pull/15205/head
Sergey Matvienko 7 months ago
parent
commit
561a8597aa
  1. 23
      application/src/test/java/org/thingsboard/server/service/edge/rpc/EdgeGrpcSslTest.java

23
application/src/test/java/org/thingsboard/server/service/edge/rpc/EdgeGrpcSslTest.java

@ -77,6 +77,8 @@ class EdgeGrpcSslTest {
enum KeyType { enum KeyType {
RSA_2048("RSA", 2048, null, "SHA256withRSA"), RSA_2048("RSA", 2048, null, "SHA256withRSA"),
RSA_4096("RSA", 4096, null, "SHA256withRSA"),
EC_P256("EC", 256, "secp256r1", "SHA256withECDSA"),
EC_P384("EC", 384, "secp384r1", "SHA384withECDSA"); EC_P384("EC", 384, "secp384r1", "SHA384withECDSA");
final String algorithm; final String algorithm;
@ -144,10 +146,14 @@ class EdgeGrpcSslTest {
assertTlsConnectivity(cert); assertTlsConnectivity(cert);
} }
@Test // RSA-only: BouncyCastle writes encrypted EC keys in traditional PEM format (BEGIN EC PRIVATE KEY),
void encryptedPrivateKey() throws Exception { // which after decryption produces a PEMKeyPair without public key info — causing PemSslCredentials
KeyPair kp = KeyType.RSA_2048.generateKeyPair(); // to fail with "Cannot invoke SubjectPublicKeyInfo.getEncoded() because getPublicKeyInfo() is null".
X509Certificate cert = generateSelfSignedCert(kp, KeyType.RSA_2048.sigAlg); @ParameterizedTest(name = "encryptedPrivateKey_{0}")
@EnumSource(value = KeyType.class, names = {"RSA_2048", "RSA_4096"})
void encryptedPrivateKey(KeyType keyType) throws Exception {
KeyPair kp = keyType.generateKeyPair();
X509Certificate cert = generateSelfSignedCert(kp, keyType.sigAlg);
String password = "test-password"; String password = "test-password";
Path combinedFile = writeTempPemEncrypted("enc-combined", password, cert, kp.getPrivate()); Path combinedFile = writeTempPemEncrypted("enc-combined", password, cert, kp.getPrivate());
@ -156,10 +162,11 @@ class EdgeGrpcSslTest {
assertTlsConnectivity(cert); assertTlsConnectivity(cert);
} }
@Test @ParameterizedTest(name = "combinedPemWithoutKey_{0}")
void combinedPemWithoutKey_throwsException() throws Exception { @EnumSource(KeyType.class)
KeyPair kp = KeyType.RSA_2048.generateKeyPair(); void combinedPemWithoutKey_throwsException(KeyType keyType) throws Exception {
X509Certificate cert = generateSelfSignedCert(kp, KeyType.RSA_2048.sigAlg); KeyPair kp = keyType.generateKeyPair();
X509Certificate cert = generateSelfSignedCert(kp, keyType.sigAlg);
Path certOnlyFile = writeTempPem("cert-only", cert); Path certOnlyFile = writeTempPem("cert-only", cert);

Loading…
Cancel
Save