1 module passwd.sha_test;
2 
3 @safe:
4 
5 import std.algorithm;
6 import std.range;
7 import std.utf : byCodeUnit;
8 
9 import passwd;
10 import passwd.exception;
11 import passwd.sha;
12 import passwd.test;
13 
14 unittest
15 {
16 	auto salt = SHA256Crypt.genSalt(2000);
17 	standardTests!SHA256Crypt(salt);
18 	assertThrown!ValueException("hunter2".crypt("$5$unknownparam=foo$salt"));
19 }
20 
21 unittest
22 {
23 	auto salt = SHA512Crypt.genSalt(2000);
24 	standardTests!SHA512Crypt(salt);
25 	assertThrown!ValueException("hunter2".crypt("$6$unknownparam=foo$salt"));
26 }
27 
28 version (unittest)
29 {
30 	bool testCase(string password, string salt, string ex_crypt)
31 	{
32 		auto result = crypt(password, salt);
33 		return result == ex_crypt;
34 	}
35 }
36 
37 // SHA256 test vectors
38 unittest
39 {
40 	// https://openwall.info/wiki/john/sample-hashes
41 	assert ("password".canCryptTo("$5$MnfsQ4iN$ZMTppKN16y/tIsUYs/obHlhdP.Os80yXhTurpBMUbA5"));
42 	assert ("rasmuslerdorf".canCryptTo("$5$rounds=5000$usesomesillystri$KqJWpanXZHKq2BOB43TSaYhEWsQ1Lr5QNyPCDH/Tp.6"));
43 
44 	// https://akkadia.org/drepper/SHA-crypt.txt
45 	assert (testCase("Hello world!", "$5$saltstring", "$5$saltstring$5B8vYYiY.CVt1RlTTf8KbXBH3hsxY/GNooZaBBGWEc5"));
46 	assert (testCase("Hello world!", "$5$rounds=10000$saltstringsaltstring", "$5$rounds=10000$saltstringsaltst$3xv.VbSHBb41AL9AvLeujZkZRBAwqFMz2.opqey6IcA"));
47 	assert (testCase("This is just a test", "$5$rounds=5000$toolongsaltstring", "$5$rounds=5000$toolongsaltstrin$Un/5jzAHMgOGZ5.mWJpuVolil07guHPvOW8mGRcvxa5"));
48 	assert (testCase("a very much longer text to encrypt.  This one even stretches over morethan one line.", "$5$rounds=1400$anotherlongsaltstring", "$5$rounds=1400$anotherlongsalts$Rx.j8H.h8HjEDGomFU8bDkXm3XIUnzyxf12oP84Bnq1"));
49 	assert (testCase("we have a short salt string but not a short password", "$5$rounds=77777$short", "$5$rounds=77777$short$JiO1O3ZpDAxGJeaDIuqCoEFysAe1mZNJRs3pw0KQRd/"));
50 	assert (testCase("a short string", "$5$rounds=123456$asaltof16chars..", "$5$rounds=123456$asaltof16chars..$gP3VQ/6X7UUEW3HkBn2w1/Ptq2jxPyzV/cZKmF/wJvD"));
51 	assert (testCase("the minimum number is still observed", "$5$rounds=10$roundstoolow", "$5$rounds=1000$roundstoolow$yfvwcWrQ8l/K0DAWyuPMDNHpIVlTQebY9l/gL972bIC"));
52 }
53 
54 // SHA512 test vectors
55 unittest
56 {
57 	// https://openwall.info/wiki/john/sample-hashes
58 	assert ("password".canCryptTo("$6$zWwwXKNj$gLAOoZCjcr8p/.VgV/FkGC3NX7BsXys3KHYePfuIGMNjY83dVxugPYlxVg/evpcVEJLT/rSwZcDMlVVf/bhf.1"));
59 	assert ("rasmuslerdorf".canCryptTo("$6$rounds=5000$usesomesillystri$D4IrlXatmP7rx3P3InaxBeoomnAihCKRVQP22JZ6EY47Wc6BkroIuUUBOov1i.S5KPgErtP/EN5mcO.ChWQW21"));
60 
61 	// https://akkadia.org/drepper/SHA-crypt.txt
62 	assert (testCase("Hello world!", "$6$saltstring", "$6$saltstring$svn8UoSVapNtMuq1ukKS4tPQd8iKwSMHWjl/O817G3uBnIFNjnQJuesI68u4OTLiBFdcbYEdFCoEOfaS35inz1"));
63 	assert (testCase("Hello world!", "$6$rounds=10000$saltstringsaltstring", "$6$rounds=10000$saltstringsaltst$OW1/O6BYHV6BcXZu8QVeXbDWra3Oeqh0sbHbbMCVNSnCM/UrjmM0Dp8vOuZeHBy/YTBmSK6H9qs/y3RnOaw5v."));
64 	assert (testCase("This is just a test", "$6$rounds=5000$toolongsaltstring", "$6$rounds=5000$toolongsaltstrin$lQ8jolhgVRVhY4b5pZKaysCLi0QBxGoNeKQzQ3glMhwllF7oGDZxUhx1yxdYcz/e1JSbq3y6JMxxl8audkUEm0"));
65 	assert (testCase("a very much longer text to encrypt.  This one even stretches over morethan one line.", "$6$rounds=1400$anotherlongsaltstring", "$6$rounds=1400$anotherlongsalts$POfYwTEok97VWcjxIiSOjiykti.o/pQs.wPvMxQ6Fm7I6IoYN3CmLs66x9t0oSwbtEW7o7UmJEiDwGqd8p4ur1"));
66 	assert (testCase("we have a short salt string but not a short password", "$6$rounds=77777$short", "$6$rounds=77777$short$WuQyW2YR.hBNpjjRhpYD/ifIw05xdfeEyQoMxIXbkvr0gge1a1x3yRULJ5CCaUeOxFmtlcGZelFl5CxtgfiAc0"));
67 	assert (testCase("a short string", "$6$rounds=123456$asaltof16chars..", "$6$rounds=123456$asaltof16chars..$BtCwjqMJGx5hrJhZywWvt0RLE8uZ4oPwcelCjmw2kSYu.Ec6ycULevoBK25fs2xXgMNrCzIMVcgEJAstJeonj1"));
68 	assert (testCase("the minimum number is still observed", "$6$rounds=10$roundstoolow", "$6$rounds=1000$roundstoolow$kUMsbe306n21p9R.FRkW3IGn.S9NPN0x50YhH1xhLsPuWGsUSklZt58jaTfF4ZEQpyUNGc0dqbpBYYBaHHrsX."));
69 }