v0.10
main
v0.5.0
v0.4.0
v0.3.0
v0.2.0
v0.1.0
${ noResults }
3 Commits (96614d5e792b7936af9c70666537166774207b1d)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
95329eef4a |
Follow the draft v0.12: testdata at 601e6d2, the reader of certificates, the texts of the verdicts
testdata is synced with the head of the branch v0.12 of datekeys-go
(601e6d2); SPEC_VERSION stays 0.11 until the author approves the draft.
- CMS as Go reads it at the draft v0.12 (review of 2 October, T2, T6 to T8
and the TypeScript side of E7 to E9):
- the certificate field by field with the profile of section 29.10, its
errors in CertificateError with the texts of Go; one that breaks it
decides nothing unless a SignerInfo names it, and two copies are one;
- the text of a name only from UTF8String, PrintableString, IA5String,
TeletexString in ASCII and BMPString without surrogates, never from an
attribute that appears twice; the holder by givenName and surname
before the commonName, the issuer by its commonName or its
organizationName;
- object identifiers by the bytes of their DER; a SET OF may repeat an
element; RSA with NULL parameters and an odd modulus; a key of another
scheme than its algorithm is invalid; a messageImprint of another
length is S3; the crls of a token decide nothing;
- DER: UTCTime and GeneralizedTime in their X.690 forms with a date that
exists, the restricted string types as primitive, the accuracy as
minimal INTEGERs. The test of cms.test.ts that compared a function
with itself has an expected value of its own.
- The verdicts in the texts of the draft: names between « and », shown
with at most 64 code points and no two spaces in a row, or their SHA-256;
in F6 the authority of each seal and the warning that nobody checks who
issued it; foreign signers in Spanish; times with their fraction.
- security.json in its context with lines, and the 135 cases of
security_cms.json, compared field by field, lines included.
- The 218 cases of mutations.json, with the texts of capsule.Open
regenerated by scripts/mutation-go-texts.go, and ibe-vectors.json with
the fixtures format3_note, format3_unsigned and the new
format3_seal_unsupported; its frozen values do not change.
- note.json, run with checkNoteData, publicNote and unusableNote.
- inspect reads the public note on demand, only for a header with one, so
that the Unicode tables never load with /inspect; the view of inspect
-json gives public_note and public_note_unusable, as Go.
A Go/TypeScript differential of 63,623 security areas, made from the
vectors, edited element by element and signed afresh with varied
certificates, tokens and authorities, gave no difference in verdicts,
results or lines; the code before this change differed in 13,296 of the
first 42,986.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
4 days ago |
|
|
06e992fa74 |
CMS as Go reads it: the issuer by its Name, uncompressed keys, the BOM, linear readers
Fixes T1, T3, T13 and the CMS part of T5 of the review of the session of 1 and 2 October (docs, spec_v0.11/revision_sesion_1_2_octubre.md): - securitycms.ts: an issuer that breaks the rules of the declared author shows the SHA-256 of the DER of its Name, Go's sha256.Sum256(RawIssuer), and no longer that of the certificate (cms.certIssuerHash). - cms.ts: an ECDSA key counts only with its point uncompressed, 0x04 and the two coordinates, the only form that Go's x509.ParsePKIXPublicKey reads: a compressed one makes a signer not verifiable (F5) and a seal S1. - cms.ts: a UTF8String and the times of a certificate and of a token keep a leading U+FEFF, as Go reads the bytes: such a name shows the hash, and such a time breaks the profile (F1, S2). - cms.ts: oidOf and intOf take time linear in the length of the element. An arc of up to seven digits accumulates in a number, a longer one and every INTEGER are read whole from hexadecimal, never by a shift per byte, which took some 700 ms for 60 KB; attributes of one type are appended, not copied. - security.ts: evaluateSecurity never throws. A fault while it evaluates the signature gives F1, one while it evaluates the seal S2, each apart, and one while it decodes the area X, as the Go reference will from v0.12. - Tests: securitycms.test.ts and security.failure.test.ts are new. cms.test.ts now refuses a second content-type and two signature-time- stamps for the rule of the count, with every SET OF in DER order, and der.test.ts tests the depth at its boundary. cmsbuild.ts makes names, validities and compressed points of its own. capsule.EvaluateSecurityIn of the Go reference at spec-v0.11 gives the same verdicts, signer lines and Spanish lines on 25 areas made with cmsbuild.ts: issuers with ESC, U+202E, empty, of 300 bytes or with a leading U+FEFF; names and times with a leading U+FEFF; and compressed keys on P-256, P-384 and P-521, as signers and as authorities of a seal. HEAD gave other ones in 19 of them. npm run verify passes. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
1 week ago |
|
|
92b4d196eb |
The signature with certificates and the time seal in the library: alg 2, RFC 3161
der.ts checks DER byte by byte. cms.ts reads the CMS signature and the RFC 3161 token of spec v0.11 29.10 and 29.11 with the closed table of algorithms: RSA PKCS 1 and PSS with BigInt, ECDSA with the arithmetic of @noble/curves, no new package. securitycms.ts gives F1, F2, F5 and F6 with the signers named, and S1 to S5 with the authority of a valid seal. evaluateSecurity returns them with their detail, and verdictLines writes the lines of F6 and S4. The 22 cases of security_cms.json and the fixtures format3_signed_cms and format3_sealed give the verdicts, the signers and the seal of the Go reference. testing/cmsbuild.ts builds signatures and tokens with WebCrypto for the hostile cases ported from the Go tests, and the pending mechanism of the first sync is gone. npm run verify passes. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
1 week ago |