Alex Stapleton | c5fffd3 | 2014-03-18 15:29:00 +0000 | [diff] [blame] | 1 | Test vectors |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 2 | ============ |
| 3 | |
| 4 | Testing the correctness of the primitives implemented in each ``cryptography`` |
Alex Stapleton | a39a319 | 2014-03-14 20:03:12 +0000 | [diff] [blame] | 5 | backend requires trusted test vectors. Where possible these vectors are |
| 6 | obtained from official sources such as `NIST`_ or `IETF`_ RFCs. When this is |
| 7 | not possible ``cryptography`` has chosen to create a set of custom vectors |
| 8 | using an official vector file as input to verify consistency between |
| 9 | implemented backends. |
| 10 | |
| 11 | Vectors are kept in the `cryptography_vectors` package rather than within our |
| 12 | main test suite. |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 13 | |
| 14 | Sources |
| 15 | ------- |
| 16 | |
Alex Stapleton | c5fffd3 | 2014-03-18 15:29:00 +0000 | [diff] [blame] | 17 | Asymmetric ciphers |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 18 | ~~~~~~~~~~~~~~~~~~ |
| 19 | |
Alex Stapleton | abec8a1 | 2014-02-22 16:33:24 +0000 | [diff] [blame] | 20 | * RSA PKCS #1 from the RSA FTP site (ftp://ftp.rsasecurity.com/pub/pkcs/pkcs-1/ |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 21 | and ftp://ftp.rsa.com/pub/rsalabs/tmp/). |
Paul Kehrer | 7f0039c | 2014-03-03 22:32:11 -0400 | [diff] [blame] | 22 | * RSA FIPS 186-2 and PKCS1 v1.5 vulnerability test vectors from `NIST CAVP`_. |
Alex Stapleton | 07c6a39 | 2014-04-02 11:05:30 +0100 | [diff] [blame] | 23 | * FIPS 186-2 and FIPS 186-3 DSA test vectors from `NIST CAVP`_. |
| 24 | * FIPS 186-2 and FIPS 186-3 ECDSA test vectors from `NIST CAVP`_. |
Alex Stapleton | 23fef0a | 2014-07-13 13:57:24 +0100 | [diff] [blame] | 25 | * DH and ECDH test vectors from `NIST CAVP`_. |
Alex Stapleton | 833a8ea | 2014-04-02 14:50:56 +0100 | [diff] [blame] | 26 | * Ed25519 test vectors from the `Ed25519 website_`. |
Alex Stapleton | e7da0ab | 2014-03-02 14:04:33 +0000 | [diff] [blame] | 27 | * OpenSSL PEM RSA serialization vectors from the `OpenSSL example key`_ and |
| 28 | `GnuTLS key parsing tests`_. |
| 29 | * OpenSSL PEM DSA serialization vectors from the `GnuTLS example keys`_. |
Alex Stapleton | abec8a1 | 2014-02-22 16:33:24 +0000 | [diff] [blame] | 30 | * PKCS #8 PEM serialization vectors from |
| 31 | |
Paul Kehrer | b525adf | 2014-09-29 15:18:23 -0500 | [diff] [blame] | 32 | * GnuTLS: `enc-rsa-pkcs8.pem`_, `enc2-rsa-pkcs8.pem`_, |
Alex Gaynor | 899c3ac | 2014-11-18 18:45:24 -0800 | [diff] [blame] | 33 | `unenc-rsa-pkcs8.pem`_, `pkcs12_s2k_pem.c`_. The contents of |
| 34 | `enc2-rsa-pkcs8.pem`_ was re-encrypted using a stronger PKCS#8 cipher. |
Alex Stapleton | abec8a1 | 2014-02-22 16:33:24 +0000 | [diff] [blame] | 35 | * `Botan's ECC private keys`_. |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 36 | |
Paul Kehrer | ebc2650 | 2014-11-26 19:18:56 -1000 | [diff] [blame] | 37 | Custom Asymmetric Vectors |
| 38 | ~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 39 | |
Paul Kehrer | 10831a0 | 2015-01-03 18:45:04 -0600 | [diff] [blame] | 40 | * ``asymmetric/PEM_Serialization/ec_private_key.pem`` and |
| 41 | ``asymmetric/DER_Serialization/ec_private_key.der`` - Contains an Elliptic |
Paul Kehrer | 0498d4c | 2015-01-01 22:29:12 -0600 | [diff] [blame] | 42 | Curve key generated by OpenSSL from the curve ``secp256r1``. |
Paul Kehrer | 10831a0 | 2015-01-03 18:45:04 -0600 | [diff] [blame] | 43 | * ``asymmetric/PEM_Serialization/ec_private_key_encrypted.pem`` and |
| 44 | ``asymmetric/DER_Serialization/ec_private_key_encrypted.der``- Contains the |
Paul Kehrer | 0498d4c | 2015-01-01 22:29:12 -0600 | [diff] [blame] | 45 | same Elliptic Curve key as ``ec_private_key.pem``, except that it is |
| 46 | encrypted with AES-128 with the password "123456". |
Paul Kehrer | 10831a0 | 2015-01-03 18:45:04 -0600 | [diff] [blame] | 47 | * ``asymmetric/PEM_Serialization/ec_public_key.pem`` and |
| 48 | ``asymmetric/DER_Serialization/ec_public_key.der``- Contains the public key |
Paul Kehrer | 0498d4c | 2015-01-01 22:29:12 -0600 | [diff] [blame] | 49 | corresponding to ``ec_private_key.pem``, generated using OpenSSL. |
| 50 | * ``asymmetric/PEM_Serialization/rsa_private_key.pem`` - Contains an RSA 2048 |
| 51 | bit key generated using OpenSSL, protected by the secret "123456" with DES3 |
| 52 | encryption. |
Paul Kehrer | 10831a0 | 2015-01-03 18:45:04 -0600 | [diff] [blame] | 53 | * ``asymmetric/PEM_Serialization/rsa_public_key.pem`` and |
| 54 | ``asymmetric/DER_Serialization/rsa_public_key.der``- Contains an RSA 2048 |
Paul Kehrer | 0498d4c | 2015-01-01 22:29:12 -0600 | [diff] [blame] | 55 | bit public generated using OpenSSL from ``rsa_private_key.pem``. |
| 56 | * ``asymmetric/PEM_Serialization/dsaparam.pem`` - Contains 2048-bit DSA |
| 57 | parameters generated using OpenSSL; contains no keys. |
| 58 | * ``asymmetric/PEM_Serialization/dsa_private_key.pem`` - Contains a DSA 2048 |
| 59 | bit key generated using OpenSSL from the parameters in ``dsaparam.pem``, |
| 60 | protected by the secret "123456" with DES3 encryption. |
Paul Kehrer | 10831a0 | 2015-01-03 18:45:04 -0600 | [diff] [blame] | 61 | * ``asymmetric/PEM_Serialization/dsa_public_key.pem`` and |
| 62 | ``asymmetric/DER_Serialization/dsa_public_key.der`` - Contains a DSA 2048 bit |
Paul Kehrer | 0498d4c | 2015-01-01 22:29:12 -0600 | [diff] [blame] | 63 | key generated using OpenSSL from ``dsa_private_key.pem``. |
Paul Kehrer | 4b8abc3 | 2015-01-06 14:46:15 +0000 | [diff] [blame] | 64 | * ``asymmetric/PKCS8/unenc-dsa-pkcs8.pem`` and |
Paul Kehrer | 10831a0 | 2015-01-03 18:45:04 -0600 | [diff] [blame] | 65 | ``asymmetric/DER_Serialization/unenc-dsa-pkcs8.der`` - Contains a DSA 1024 |
Paul Kehrer | a36661e | 2015-01-04 07:57:40 -0600 | [diff] [blame] | 66 | bit key generated using OpenSSL. |
Paul Kehrer | 4b8abc3 | 2015-01-06 14:46:15 +0000 | [diff] [blame] | 67 | * ``asymmetric/PKCS8/unenc-dsa-pkcs8.pub.pem`` and |
Paul Kehrer | 10831a0 | 2015-01-03 18:45:04 -0600 | [diff] [blame] | 68 | ``asymmetric/DER_Serialization/unenc-dsa-pkcs8.pub.der`` - Contains a DSA |
Paul Kehrer | a673dcc | 2015-01-03 23:26:01 -0600 | [diff] [blame] | 69 | 2048 bit public key generated using OpenSSL from ``unenc-dsa-pkcs8.pem``. |
Paul Kehrer | 10831a0 | 2015-01-03 18:45:04 -0600 | [diff] [blame] | 70 | * DER conversions of the `GnuTLS example keys`_ for DSA as well as the |
| 71 | `OpenSSL example key`_ for RSA. |
| 72 | * DER conversions of `enc-rsa-pkcs8.pem`_, `enc2-rsa-pkcs8.pem`_, and |
| 73 | `unenc-rsa-pkcs8.pem`_. |
Paul Kehrer | ebc2650 | 2014-11-26 19:18:56 -1000 | [diff] [blame] | 74 | |
| 75 | |
Paul Kehrer | bab4e39 | 2014-11-24 11:48:17 -1000 | [diff] [blame] | 76 | X.509 |
| 77 | ~~~~~ |
| 78 | |
| 79 | * PKITS test suite from `NIST PKI Testing`_. |
Paul Kehrer | ebc2650 | 2014-11-26 19:18:56 -1000 | [diff] [blame] | 80 | * ``v1_cert.pem`` from the OpenSSL source tree (`testx509.pem`_). |
| 81 | * ``ecdsa_root.pem`` - `DigiCert Global Root G3`_, a ``secp384r1`` ECDSA root |
| 82 | certificate. |
Paul Kehrer | b01622d | 2015-02-13 11:59:15 -0600 | [diff] [blame^] | 83 | * ``verisign-md2-root.pem`` - A legacy Verisign public root signed using the |
| 84 | MD2 algorithm. |
Paul Kehrer | ebc2650 | 2014-11-26 19:18:56 -1000 | [diff] [blame] | 85 | |
| 86 | Custom X.509 Vectors |
| 87 | ~~~~~~~~~~~~~~~~~~~~ |
| 88 | |
| 89 | * ``invalid_version.pem`` - Contains an RSA 2048 bit certificate with the |
| 90 | X.509 version field set to ``0x7``. |
| 91 | * ``post2000utctime.pem`` - Contains an RSA 2048 bit certificate with the |
| 92 | ``notBefore`` and ``notAfter`` fields encoded as post-2000 ``UTCTime``. |
Paul Kehrer | a850c61 | 2014-12-12 14:21:18 -0600 | [diff] [blame] | 93 | * ``dsa_selfsigned_ca.pem`` - Contains a DSA self-signed CA certificate |
| 94 | generated using OpenSSL. |
Paul Kehrer | d317bae | 2014-12-12 11:42:31 -0600 | [diff] [blame] | 95 | * ``ec_no_named_curve.pem`` - Contains an ECDSA certificate that does not have |
| 96 | an embedded OID defining the curve. |
Paul Kehrer | 2221720 | 2015-01-17 21:26:28 -0600 | [diff] [blame] | 97 | * ``all_supported_names.pem`` - An RSA 2048 bit certificate generated using |
| 98 | OpenSSL that contains a subject and issuer that have two of each supported |
| 99 | attribute type from :rfc:`5280`. |
Paul Kehrer | 1207d15 | 2015-01-17 21:31:42 -0600 | [diff] [blame] | 100 | * ``unsupported_subject_name.pem`` - An RSA 2048 bit self-signed CA certificate |
| 101 | generated using OpenSSL that contains the unsupported "initials" name. |
Paul Kehrer | 6392b4b | 2015-01-17 22:20:01 -0600 | [diff] [blame] | 102 | * ``utf8_common_name.pem`` - An RSA 2048 bit self-signed CA certificate |
| 103 | generated using OpenSSL that contains a UTF8String common name with the value |
| 104 | "We heart UTF8!â„¢". |
Paul Kehrer | bab4e39 | 2014-11-24 11:48:17 -1000 | [diff] [blame] | 105 | |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 106 | Hashes |
| 107 | ~~~~~~ |
| 108 | |
| 109 | * MD5 from :rfc:`1321`. |
| 110 | * RIPEMD160 from the `RIPEMD website`_. |
| 111 | * SHA1 from `NIST CAVP`_. |
| 112 | * SHA2 (224, 256, 384, 512) from `NIST CAVP`_. |
| 113 | * Whirlpool from the `Whirlpool website`_. |
| 114 | |
| 115 | HMAC |
| 116 | ~~~~ |
| 117 | |
| 118 | * HMAC-MD5 from :rfc:`2202`. |
| 119 | * HMAC-SHA1 from :rfc:`2202`. |
| 120 | * HMAC-RIPEMD160 from :rfc:`2286`. |
| 121 | * HMAC-SHA2 (224, 256, 384, 512) from :rfc:`4231`. |
| 122 | |
Alex Stapleton | c5fffd3 | 2014-03-18 15:29:00 +0000 | [diff] [blame] | 123 | Key derivation functions |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 124 | ~~~~~~~~~~~~~~~~~~~~~~~~ |
| 125 | |
| 126 | * HKDF (SHA1, SHA256) from :rfc:`5869`. |
| 127 | * PBKDF2 (HMAC-SHA1) from :rfc:`6070`. |
Alex Gaynor | 75e72ea | 2014-03-01 12:18:27 -0800 | [diff] [blame] | 128 | * scrypt from the `draft RFC`_. |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 129 | |
| 130 | Recipes |
| 131 | ~~~~~~~ |
| 132 | |
| 133 | * Fernet from its `specification repository`_. |
| 134 | |
Alex Stapleton | c5fffd3 | 2014-03-18 15:29:00 +0000 | [diff] [blame] | 135 | Symmetric ciphers |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 136 | ~~~~~~~~~~~~~~~~~ |
| 137 | |
Paul Kehrer | e547d8f | 2014-02-15 21:37:52 -0600 | [diff] [blame] | 138 | * AES (CBC, CFB, ECB, GCM, OFB) from `NIST CAVP`_. |
| 139 | * AES CTR from :rfc:`3686`. |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 140 | * 3DES (CBC, CFB, ECB, OFB) from `NIST CAVP`_. |
| 141 | * ARC4 from :rfc:`6229`. |
| 142 | * Blowfish (CBC, CFB, ECB, OFB) from `Bruce Schneier's vectors`_. |
| 143 | * Camellia (ECB) from NTT's `Camellia page`_ as linked by `CRYPTREC`_. |
| 144 | * Camellia (CBC, CFB, OFB) from `OpenSSL's test vectors`_. |
| 145 | * CAST5 (ECB) from :rfc:`2144`. |
Paul Kehrer | cf6ffb5 | 2014-02-12 16:17:04 -0600 | [diff] [blame] | 146 | * CAST5 (CBC, CFB, OFB) generated by this project. |
| 147 | See: :doc:`/development/custom-vectors/cast5` |
Paul Kehrer | b09622c | 2014-02-16 19:32:04 -0600 | [diff] [blame] | 148 | * IDEA (ECB) from the `NESSIE IDEA vectors`_ created by `NESSIE`_. |
| 149 | * IDEA (CBC, CFB, OFB) generated by this project. |
| 150 | See: :doc:`/development/custom-vectors/idea` |
Paul Kehrer | 1d0f973 | 2014-04-08 08:44:25 -0500 | [diff] [blame] | 151 | * SEED (ECB) from :rfc:`4269`. |
Paul Kehrer | f0e12ac | 2014-04-08 08:59:40 -0500 | [diff] [blame] | 152 | * SEED (CBC) from :rfc:`4196`. |
Paul Kehrer | 6d8f9b0 | 2014-04-08 09:17:02 -0500 | [diff] [blame] | 153 | * SEED (CFB, OFB) generated by this project. |
| 154 | See: :doc:`/development/custom-vectors/seed` |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 155 | |
Alex Stapleton | c5fffd3 | 2014-03-18 15:29:00 +0000 | [diff] [blame] | 156 | Two factor authentication |
Ayrx | 933dd68 | 2014-02-18 23:26:11 +0800 | [diff] [blame] | 157 | ~~~~~~~~~~~~~~~~~~~~~~~~~ |
| 158 | |
| 159 | * HOTP from :rfc:`4226` |
Alex Gaynor | 75e72ea | 2014-03-01 12:18:27 -0800 | [diff] [blame] | 160 | * TOTP from :rfc:`6238` (Note that an `errata`_ for the test vectors in RFC |
| 161 | 6238 exists) |
Ayrx | 933dd68 | 2014-02-18 23:26:11 +0800 | [diff] [blame] | 162 | |
Ayrx | 1d6b77b | 2014-04-10 23:11:03 +0800 | [diff] [blame] | 163 | CMAC |
| 164 | ~~~~ |
| 165 | |
Ayrx | fa52e6a | 2014-04-14 22:26:21 +0800 | [diff] [blame] | 166 | * AES-128, AES-192, AES-256, 3DES from `NIST SP-800-38B`_ |
Ayrx | 1d6b77b | 2014-04-10 23:11:03 +0800 | [diff] [blame] | 167 | |
Alex Stapleton | c5fffd3 | 2014-03-18 15:29:00 +0000 | [diff] [blame] | 168 | Creating test vectors |
Paul Kehrer | cf6ffb5 | 2014-02-12 16:17:04 -0600 | [diff] [blame] | 169 | --------------------- |
| 170 | |
| 171 | When official vectors are unavailable ``cryptography`` may choose to build |
Paul Kehrer | 9f7ad19 | 2014-09-24 21:54:39 -0500 | [diff] [blame] | 172 | its own using existing vectors as source material. |
michael-hart | 59f7219 | 2014-09-24 11:31:20 +0100 | [diff] [blame] | 173 | |
Paul Kehrer | ebc2650 | 2014-11-26 19:18:56 -1000 | [diff] [blame] | 174 | Custom Symmetric Vectors |
| 175 | ~~~~~~~~~~~~~~~~~~~~~~~~ |
Paul Kehrer | cf6ffb5 | 2014-02-12 16:17:04 -0600 | [diff] [blame] | 176 | |
| 177 | .. toctree:: |
| 178 | :maxdepth: 1 |
| 179 | |
| 180 | custom-vectors/cast5 |
Paul Kehrer | b09622c | 2014-02-16 19:32:04 -0600 | [diff] [blame] | 181 | custom-vectors/idea |
Paul Kehrer | 6d8f9b0 | 2014-04-08 09:17:02 -0500 | [diff] [blame] | 182 | custom-vectors/seed |
Paul Kehrer | cf6ffb5 | 2014-02-12 16:17:04 -0600 | [diff] [blame] | 183 | |
| 184 | If official test vectors appear in the future the custom generated vectors |
| 185 | should be discarded. |
| 186 | |
| 187 | Any vectors generated by this method must also be prefixed with the following |
| 188 | header format (substituting the correct information): |
| 189 | |
| 190 | .. code-block:: python |
| 191 | |
| 192 | # CAST5 CBC vectors built for https://github.com/pyca/cryptography |
| 193 | # Derived from the AESVS MMT test data for CBC |
| 194 | # Verified against the CommonCrypto and Go crypto packages |
| 195 | # Key Length : 128 |
| 196 | |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 197 | .. _`NIST`: http://www.nist.gov/ |
| 198 | .. _`IETF`: https://www.ietf.org/ |
| 199 | .. _`NIST CAVP`: http://csrc.nist.gov/groups/STM/cavp/ |
| 200 | .. _`Bruce Schneier's vectors`: https://www.schneier.com/code/vectors.txt |
| 201 | .. _`Camellia page`: http://info.isl.ntt.co.jp/crypt/eng/camellia/ |
| 202 | .. _`CRYPTREC`: http://www.cryptrec.go.jp |
| 203 | .. _`OpenSSL's test vectors`: https://github.com/openssl/openssl/blob/97cf1f6c2854a3a955fd7dd3a1f113deba00c9ef/crypto/evp/evptests.txt#L232 |
| 204 | .. _`RIPEMD website`: http://homes.esat.kuleuven.be/~bosselae/ripemd160.html |
| 205 | .. _`Whirlpool website`: http://www.larc.usp.br/~pbarreto/WhirlpoolPage.html |
Alex Gaynor | 75e72ea | 2014-03-01 12:18:27 -0800 | [diff] [blame] | 206 | .. _`draft RFC`: https://tools.ietf.org/html/draft-josefsson-scrypt-kdf-01 |
Paul Kehrer | 1681a69 | 2014-02-11 23:43:51 -0600 | [diff] [blame] | 207 | .. _`Specification repository`: https://github.com/fernet/spec |
Ayrx | 933dd68 | 2014-02-18 23:26:11 +0800 | [diff] [blame] | 208 | .. _`errata`: http://www.rfc-editor.org/errata_search.php?rfc=6238 |
Alex Stapleton | e7da0ab | 2014-03-02 14:04:33 +0000 | [diff] [blame] | 209 | .. _`OpenSSL example key`: http://git.openssl.org/gitweb/?p=openssl.git;a=blob;f=test/testrsa.pem;h=aad21067a8f7cb93a52a511eb9162fd83be39135;hb=66e8211c0b1347970096e04b18aa52567c325200 |
| 210 | .. _`GnuTLS key parsing tests`: https://gitorious.org/gnutls/gnutls/commit/f16ef39ef0303b02d7fa590a37820440c466ce8d |
michael-hart | 59f7219 | 2014-09-24 11:31:20 +0100 | [diff] [blame] | 211 | .. _`enc-rsa-pkcs8.pem`: https://gitorious.org/gnutls/gnutls/source/f8d943b38bf74eaaa11d396112daf43cb8aa82ae:tests/pkcs8-decode/encpkcs8.pem |
| 212 | .. _`enc2-rsa-pkcs8.pem`: https://gitorious.org/gnutls/gnutls/source/f8d943b38bf74eaaa11d396112daf43cb8aa82ae:tests/pkcs8-decode/enc2pkcs8.pem |
| 213 | .. _`unenc-rsa-pkcs8.pem`: https://gitorious.org/gnutls/gnutls/source/f8d943b38bf74eaaa11d396112daf43cb8aa82ae:tests/pkcs8-decode/unencpkcs8.pem |
Alex Stapleton | abec8a1 | 2014-02-22 16:33:24 +0000 | [diff] [blame] | 214 | .. _`pkcs12_s2k_pem.c`: https://gitorious.org/gnutls/gnutls/source/f8d943b38bf74eaaa11d396112daf43cb8aa82ae:tests/pkcs12_s2k_pem.c |
| 215 | .. _`Botan's ECC private keys`: https://github.com/randombit/botan/tree/4917f26a2b154e841cd27c1bcecdd41d2bdeb6ce/src/tests/data/ecc |
Alex Stapleton | e7da0ab | 2014-03-02 14:04:33 +0000 | [diff] [blame] | 216 | .. _`GnuTLS example keys`: https://gitorious.org/gnutls/gnutls/commit/ad2061deafdd7db78fd405f9d143b0a7c579da7b |
Paul Kehrer | b09622c | 2014-02-16 19:32:04 -0600 | [diff] [blame] | 217 | .. _`NESSIE IDEA vectors`: https://www.cosic.esat.kuleuven.be/nessie/testvectors/bc/idea/Idea-128-64.verified.test-vectors |
| 218 | .. _`NESSIE`: https://en.wikipedia.org/wiki/NESSIE |
Alex Stapleton | 833a8ea | 2014-04-02 14:50:56 +0100 | [diff] [blame] | 219 | .. _`Ed25519 website`: http://ed25519.cr.yp.to/software.html |
Ayrx | 40afce0 | 2014-04-13 19:17:52 +0800 | [diff] [blame] | 220 | .. _`NIST SP-800-38B`: http://csrc.nist.gov/publications/nistpubs/800-38B/Updated_CMAC_Examples.pdf |
Paul Kehrer | bab4e39 | 2014-11-24 11:48:17 -1000 | [diff] [blame] | 221 | .. _`NIST PKI Testing`: http://csrc.nist.gov/groups/ST/crypto_apps_infra/pki/pkitesting.html |
Paul Kehrer | ebc2650 | 2014-11-26 19:18:56 -1000 | [diff] [blame] | 222 | .. _`testx509.pem`: https://github.com/openssl/openssl/blob/master/test/testx509.pem |
| 223 | .. _`DigiCert Global Root G3`: http://cacerts.digicert.com/DigiCertGlobalRootG3.crt |