1 module passwd.sha_test; 2 3 @safe: 4 5 import std.algorithm; 6 import std.range; 7 import std.utf : byCodeUnit; 8 9 import passwd; 10 import passwd.exception; 11 import passwd.sha; 12 import passwd.test; 13 14 unittest 15 { 16 auto salt = SHA256Crypt.genSalt(2000); 17 standardTests!SHA256Crypt(salt); 18 assertThrown!ValueException("hunter2".crypt("$5$unknownparam=foo$salt")); 19 } 20 21 unittest 22 { 23 auto salt = SHA512Crypt.genSalt(2000); 24 standardTests!SHA512Crypt(salt); 25 assertThrown!ValueException("hunter2".crypt("$6$unknownparam=foo$salt")); 26 } 27 28 version (unittest) 29 { 30 bool testCase(string password, string salt, string ex_crypt) 31 { 32 auto result = crypt(password, salt); 33 return result == ex_crypt; 34 } 35 } 36 37 // SHA256 test vectors 38 unittest 39 { 40 // https://openwall.info/wiki/john/sample-hashes 41 assert ("password".canCryptTo("$5$MnfsQ4iN$ZMTppKN16y/tIsUYs/obHlhdP.Os80yXhTurpBMUbA5")); 42 assert ("rasmuslerdorf".canCryptTo("$5$rounds=5000$usesomesillystri$KqJWpanXZHKq2BOB43TSaYhEWsQ1Lr5QNyPCDH/Tp.6")); 43 44 // https://akkadia.org/drepper/SHA-crypt.txt 45 assert (testCase("Hello world!", "$5$saltstring", "$5$saltstring$5B8vYYiY.CVt1RlTTf8KbXBH3hsxY/GNooZaBBGWEc5")); 46 assert (testCase("Hello world!", "$5$rounds=10000$saltstringsaltstring", "$5$rounds=10000$saltstringsaltst$3xv.VbSHBb41AL9AvLeujZkZRBAwqFMz2.opqey6IcA")); 47 assert (testCase("This is just a test", "$5$rounds=5000$toolongsaltstring", "$5$rounds=5000$toolongsaltstrin$Un/5jzAHMgOGZ5.mWJpuVolil07guHPvOW8mGRcvxa5")); 48 assert (testCase("a very much longer text to encrypt. This one even stretches over morethan one line.", "$5$rounds=1400$anotherlongsaltstring", "$5$rounds=1400$anotherlongsalts$Rx.j8H.h8HjEDGomFU8bDkXm3XIUnzyxf12oP84Bnq1")); 49 assert (testCase("we have a short salt string but not a short password", "$5$rounds=77777$short", "$5$rounds=77777$short$JiO1O3ZpDAxGJeaDIuqCoEFysAe1mZNJRs3pw0KQRd/")); 50 assert (testCase("a short string", "$5$rounds=123456$asaltof16chars..", "$5$rounds=123456$asaltof16chars..$gP3VQ/6X7UUEW3HkBn2w1/Ptq2jxPyzV/cZKmF/wJvD")); 51 assert (testCase("the minimum number is still observed", "$5$rounds=10$roundstoolow", "$5$rounds=1000$roundstoolow$yfvwcWrQ8l/K0DAWyuPMDNHpIVlTQebY9l/gL972bIC")); 52 } 53 54 // SHA512 test vectors 55 unittest 56 { 57 // https://openwall.info/wiki/john/sample-hashes 58 assert ("password".canCryptTo("$6$zWwwXKNj$gLAOoZCjcr8p/.VgV/FkGC3NX7BsXys3KHYePfuIGMNjY83dVxugPYlxVg/evpcVEJLT/rSwZcDMlVVf/bhf.1")); 59 assert ("rasmuslerdorf".canCryptTo("$6$rounds=5000$usesomesillystri$D4IrlXatmP7rx3P3InaxBeoomnAihCKRVQP22JZ6EY47Wc6BkroIuUUBOov1i.S5KPgErtP/EN5mcO.ChWQW21")); 60 61 // https://akkadia.org/drepper/SHA-crypt.txt 62 assert (testCase("Hello world!", "$6$saltstring", "$6$saltstring$svn8UoSVapNtMuq1ukKS4tPQd8iKwSMHWjl/O817G3uBnIFNjnQJuesI68u4OTLiBFdcbYEdFCoEOfaS35inz1")); 63 assert (testCase("Hello world!", "$6$rounds=10000$saltstringsaltstring", "$6$rounds=10000$saltstringsaltst$OW1/O6BYHV6BcXZu8QVeXbDWra3Oeqh0sbHbbMCVNSnCM/UrjmM0Dp8vOuZeHBy/YTBmSK6H9qs/y3RnOaw5v.")); 64 assert (testCase("This is just a test", "$6$rounds=5000$toolongsaltstring", "$6$rounds=5000$toolongsaltstrin$lQ8jolhgVRVhY4b5pZKaysCLi0QBxGoNeKQzQ3glMhwllF7oGDZxUhx1yxdYcz/e1JSbq3y6JMxxl8audkUEm0")); 65 assert (testCase("a very much longer text to encrypt. This one even stretches over morethan one line.", "$6$rounds=1400$anotherlongsaltstring", "$6$rounds=1400$anotherlongsalts$POfYwTEok97VWcjxIiSOjiykti.o/pQs.wPvMxQ6Fm7I6IoYN3CmLs66x9t0oSwbtEW7o7UmJEiDwGqd8p4ur1")); 66 assert (testCase("we have a short salt string but not a short password", "$6$rounds=77777$short", "$6$rounds=77777$short$WuQyW2YR.hBNpjjRhpYD/ifIw05xdfeEyQoMxIXbkvr0gge1a1x3yRULJ5CCaUeOxFmtlcGZelFl5CxtgfiAc0")); 67 assert (testCase("a short string", "$6$rounds=123456$asaltof16chars..", "$6$rounds=123456$asaltof16chars..$BtCwjqMJGx5hrJhZywWvt0RLE8uZ4oPwcelCjmw2kSYu.Ec6ycULevoBK25fs2xXgMNrCzIMVcgEJAstJeonj1")); 68 assert (testCase("the minimum number is still observed", "$6$rounds=10$roundstoolow", "$6$rounds=1000$roundstoolow$kUMsbe306n21p9R.FRkW3IGn.S9NPN0x50YhH1xhLsPuWGsUSklZt58jaTfF4ZEQpyUNGc0dqbpBYYBaHHrsX.")); 69 }