Changes from v1 to v2: CPT – a tool for testing the certificate validation

Changes in the markdown source of the article: removed text, added text.

---
title: "CPT – a tool for testing the certificate validation"
type: blog
author: Falko Strenzke
date: 2018-04-17
---

The certification path validation, or short, the certificate validation, is the process of
verifying that an X.509 certificate is valid and thus the public key contained in it may be
trusted and used for cryptographic purposes. This operation is for instance embedded into
the TLS handshake, but also into many more applications and protocols.

This rather complex operation is specified in the [RFC
5280](https://tools.ietf.org/html/rfc5280) and is highly error prone as countless
vulnerability reports have demonstrated in the past (see for instance the ["Frankencerts"
project](http://www.cs.columbia.edu/~suman/docs/frankencert.pdf)).

For this reason the [German Federal Office for Information Security
(BSI)](https://www.bsi.bund.de) contracted out a project to [MTG AG](http://www.mtg.de) and
cryptosource, the subject of which was the assurance of the correctness of implementations
of the certificate validation in cryptographic libraries and applications. The results of
this project are now available on the [BSI
website.](https://www.bsi.bund.de/DE/Themen/Kryptografie_Kryptotechnologie/Kryptografie/CPT/cpt_node.html)

website.](https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Kryptografie/Certification-Path-Validation-Test-Tool/certification-path-validation-test-tool_node.html)

As the main task of the project, we created a test specification and a new test tool that
verifies this operation. The test specification consists of a set of positive and negative
test cases, systematically covering all aspects of RFC 5280 and other application specific
RFCs. The test specification, which is in the form of XML files, defines for each test case
a set of certificates and revocation lists as well as the information whether the
certificate validation using this test data should pass or not. The [CPT basis
tool](https://github.com/MTG-AG/cpt/) parses the XML test case specifications and generates
the test data. Furthermore, different tools for [testing applications, especially
TLS](https://github.com/MTG-AG/cpt-add-test-tools), and [cryptography
libraries](https://github.com/MTG-AG/cpt-native-lib-test) have been created. These tools
execute tests based on the test data generated by the CPT basis tool for different types of
test subjects.

As the final part of the project, the tests were applied to ten different cryptography
libraries and applications. The results are summarized in [this
report](https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/CPT/CPT_Tool_Test-Report_Findings.html;jsessionid=5CE415456F37F6D3E777CD9C74C8D6A0.1_cid360).

report](https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/CPT/CPT_Tool_Test-Report_Findings.html).

## useful links

-   the CPT main page:
    <https://www.bsi.bund.de/DE/Themen/Kryptografie_Kryptotechnologie/Kryptografie/CPT/cpt_node.html>
<https://www.bsi.bund.de/EN/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Kryptografie/Certification-Path-Validation-Test-Tool/certification-path-validation-test-tool_node.html>
-   Press Release of the BSI (German only):
    <https://www.bsi.bund.de/DE/Presse/Pressemitteilungen/Presse2018/pruef_tool_zertifikatsketten_10042018.html>
only), April 10, 2018: no longer available online
-   CPT basis tool on github: <https://github.com/MTG-AG/cpt/>
-   additional CPT tools for testing TLS and IPsec applications:
    <https://github.com/MTG-AG/cpt-add-test-tools>
-   an additional CPT tool for testing of C/C++ cryptographic libraries:
    <https://github.com/MTG-AG/cpt-native-lib-test>
-   report on found vulnerabilities:
    [Report_CPT_findings.pdf](https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/CPT/CPT_Tool_Test-Report_Findings.html;jsessionid=5CE415456F37F6D3E777CD9C74C8D6A0.1_cid360)
[Report_CPT_findings.pdf](https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/CPT/CPT_Tool_Test-Report_Findings.html)
-   [Slides](static/slides/ruhrsec_2018.pdf) of the talk about the CPT and the vulnerabilities
    discovered in the test subjects given at RuhrSec, Bochum, May 2018