public class OpenSSHKeyParsingTests extends SimpleTest
NOT-A-SECRET: openssh test vector. Every private key in this file is a deliberately published test fixture. Each was generated for this test suite with no passphrase and has never protected anything; they exist so the parser can be exercised against real ssh-keygen output. Automated secret scanners flag them, and that is a false positive - there is nothing here to rotate or report.
All of them carry the comment "bc-test-vector". A new vector should be generated the same way, with ssh-keygen -C bc-test-vector, so that no user name or host name of whoever produced it is carried in the key's comment field, where it is invisible in the source but recoverable by anyone who decodes the blob (github #2376).
SimpleTest.TestExceptionOperation| Constructor and Description |
|---|
OpenSSHKeyParsingTests() |
| Modifier and Type | Method and Description |
|---|---|
java.lang.String |
getName() |
static void |
main(java.lang.String[] args) |
void |
performTest() |
void |
testDSA() |
void |
testECDSA_curvesFromSSHKeyGen() |
void |
testECDSA() |
void |
testECDSAEncodeOpenSSHFormat()
github #2240 - ensure encodePrivateKey for ECDSA emits the openssh-key-v1
envelope (not the raw RFC 5915 ECPrivateKey SEQUENCE) so the output is
compatible with OpenSSH and JSCH.
|
void |
testED25519() |
void |
testEncryptedKeyRoundsBounded()
The bcrypt round count is read from the key's own kdfoptions and drives the KDF before
anything about the key has been verified, so it has to be bounded: a round costs several
milliseconds and the wire format allows up to 2^31-1 of them, which is CPU-months from a
key file of a few hundred bytes.
|
void |
testEncryptedKeys()
github #1733 - decryption of passphrase-protected openssh-key-v1 keys across the
OpenSSH cipher suite (bcrypt KDF).
|
void |
testFailures() |
void |
testRSA() |
public static void main(java.lang.String[] args)
public void testDSA()
throws java.lang.Exception
java.lang.Exceptionpublic void testECDSA_curvesFromSSHKeyGen()
throws java.lang.Exception
java.lang.Exceptionpublic void testECDSA()
throws java.lang.Exception
java.lang.Exceptionpublic void testED25519()
throws java.lang.Exception
java.lang.Exceptionpublic void testFailures()
throws java.lang.Exception
java.lang.Exceptionpublic void testEncryptedKeys()
throws java.lang.Exception
java.lang.Exceptionpublic void testEncryptedKeyRoundsBounded()
throws java.lang.Exception
The fixture below is a normal ssh-keygen key at its default of 16 rounds, so the cap is lowered under it rather than a hostile key being hand-built - the same approach as BCFKSStoreTest.shouldRejectExcessiveMacKdfCost.
java.lang.Exceptionpublic java.lang.String getName()
getName in interface TestgetName in class SimpleTestpublic void performTest()
throws java.lang.Exception
performTest in class SimpleTestjava.lang.Exceptionpublic void testECDSAEncodeOpenSSHFormat()
throws java.lang.Exception
java.lang.Exceptionpublic void testRSA()
throws java.lang.Exception
java.lang.Exception