AWS-Signature-V4
view release on metacpan or search on metacpan
t/security.t view on Meta::CPAN
};
subtest 'secrets of the x509 key are not kept around' => sub {
my $dir = File::Temp::tempdir(CLEANUP => 1);
system(qq{openssl genpkey -algorithm EC -pkeyopt ec_paramgen_curve:P-256 }
. qq{-aes256 -pass pass:TopSecretPass -out $dir/k.pem 2>/dev/null}) == 0
or skip_all 'openssl needed';
system(qq{openssl req -new -x509 -key $dir/k.pem -passin pass:TopSecretPass }
. qq{-subj /CN=t -days 1 -out $dir/c.pem 2>/dev/null}) == 0
or skip_all 'openssl needed';
my $pem = do { local (@ARGV, $/) = "$dir/k.pem"; <> };
my $s = AWS::Signature::V4->new(service => 'rolesanywhere', region => 'r',
x509 => {key_type => 'ECDSA', certificate_file => "$dir/c.pem",
private_key => $pem, private_key_password => 'TopSecretPass'});
ok !exists $s->x509->{private_key}, 'no key text in ->x509';
ok !exists $s->x509->{private_key_password}, 'no password in ->x509';
my $dump = dump_of($s);
unlike $dump, qr/TopSecretPass/, 'no password in a dump';
unlike $dump, qr/ENCRYPTED PRIVATE KEY/, 'no key text in a dump';
like $s->sign(method => 'GET', url => 'https://h/', time => 0)->{signature},
qr/\A[0-9a-f]+\z/, 'signing still works';
( run in 1.834 second using v1.01-cache-2.11-cpan-64eb572602a )