3 test_description='S/MIME signature verification and decryption'
4 . $(dirname "$0")/test-lib.sh || exit 1
6 test_require_external_prereq openssl
7 test_require_external_prereq gpgsm
9 FINGERPRINT=$(openssl x509 -fingerprint -in "$NOTMUCH_SRCDIR/test/smime/key+cert.pem" -noout | sed -e 's/^.*=//' -e s/://g)
13 test_begin_subtest "emacs delivery of S/MIME signed message"
16 "test signed message 001" \
17 "This is a test signed message." \
18 "(mml-secure-message-sign \"smime\")"'
20 test_begin_subtest "emacs delivery of S/MIME encrypted + signed message"
21 # Hard code the MML to avoid several interactive questions
24 "test encrypted message 001" \
25 "<#secure method=smime mode=signencrypt>\nThis is a test encrypted message.\n"'
27 test_begin_subtest "Signature verification (openssl)"
28 notmuch show --format=raw subject:"test signed message 001" |\
29 openssl smime -verify -CAfile $NOTMUCH_SRCDIR/test/smime/test.crt 2>OUTPUT
31 Verification successful
33 test_expect_equal_file EXPECTED OUTPUT
35 test_begin_subtest "signature verification (notmuch CLI)"
36 output=$(notmuch show --format=json --verify subject:"test signed message 001" \
37 | notmuch_json_show_sanitize \
38 | sed -e 's|"created": [-1234567890]*|"created": 946728000|g' \
39 -e 's|"expires": [-1234567890]*|"expires": 424242424|g' )
40 expected='[[[{"id": "XXXXX",
43 "filename": ["YYYYY"],
44 "timestamp": 946728000,
45 "date_relative": "2000-01-01",
46 "tags": ["inbox","signed"],
47 "crypto": {"signed": {"status": [{"fingerprint": "'$FINGERPRINT'", "status": "good","userid": "CN=Notmuch Test Suite","expires": 424242424, "created": 946728000}]}},
48 "headers": {"Subject": "test signed message 001",
49 "From": "Notmuch Test Suite <test_suite@notmuchmail.org>",
50 "To": "test_suite@notmuchmail.org",
51 "Date": "Sat, 01 Jan 2000 12:00:00 +0000"},
53 "sigstatus": [{"fingerprint": "'$FINGERPRINT'",
55 "userid": "CN=Notmuch Test Suite",
57 "created": 946728000}],
58 "content-type": "multipart/signed",
60 "content-type": "text/plain",
61 "content": "This is a test signed message.\n"},
63 "content-disposition": "attachment",
64 "content-length": "NONZERO",
65 "content-transfer-encoding": "base64",
66 "content-type": "application/pkcs7-signature",
67 "filename": "smime.p7s"}]}]},
69 test_expect_equal_json \
73 test_begin_subtest "Decryption and signature verification (openssl)"
74 notmuch show --format=raw subject:"test encrypted message 001" |\
75 openssl smime -decrypt -recip $NOTMUCH_SRCDIR/test/smime/key+cert.pem |\
76 openssl smime -verify -CAfile $NOTMUCH_SRCDIR/test/smime/test.crt 2>OUTPUT
78 Verification successful
80 test_expect_equal_file EXPECTED OUTPUT
82 test_begin_subtest "Decryption (notmuch CLI)"
83 test_subtest_known_broken
84 notmuch show --decrypt=true subject:"test encrypted message 001" |\
85 grep "^This is a" > OUTPUT
87 This is a test encrypted message.
89 test_expect_equal_file EXPECTED OUTPUT