blob: a6781903d15b1e6ca01ed070c7456bf6bac8c609 [file] [log] [blame]
package keys
import (
func mkkey() security.PublicKey {
s, err := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
if err != nil {
return security.NewECDSAPublicKey(&s.PublicKey)
func TestTrustedKeys(t *testing.T) {
k1 := mkkey()
k2 := mkkey()
test := func(name string, k1Trust, k2Trust TrustLevel) error {
var errs []string
t1 := LevelOfTrust(k1, name)
t2 := LevelOfTrust(k2, name)
if t1 != k1Trust {
errs = append(errs, fmt.Sprintf("Got %v want %v for LevelOfTrust(k1, %v)", t1, k1Trust, name))
if t2 != k2Trust {
errs = append(errs, fmt.Sprintf("Got %v want %v for LevelOfTrust(k2, %v)", t2, k2Trust, name))
switch len(errs) {
case 0:
return nil
case 1:
return errors.New(errs[0])
return errors.New(strings.Join(errs, ". "))
// Initially, everything is unregistered
if err := test("foo", Unknown, Unknown); err != nil {
// k1 will be trusted for "foo" after Trust is called.
Trust(k1, "foo")
if err := test("foo", Trusted, Mistrusted); err != nil {
// multiple keys can be trusted for the same name
Trust(k2, "foo")
if err := test("foo", Trusted, Trusted); err != nil {
// Trust so far is only for "foo", not "bar"
if err := test("bar", Unknown, Unknown); err != nil {
Trust(k2, "bar")
if err := test("bar", Mistrusted, Trusted); err != nil {