Fixes T1, T3, T13 and the CMS part of T5 of the review of the session of
1 and 2 October (docs, spec_v0.11/revision_sesion_1_2_octubre.md):
- securitycms.ts: an issuer that breaks the rules of the declared author
shows the SHA-256 of the DER of its Name, Go's sha256.Sum256(RawIssuer),
and no longer that of the certificate (cms.certIssuerHash).
- cms.ts: an ECDSA key counts only with its point uncompressed, 0x04 and
the two coordinates, the only form that Go's x509.ParsePKIXPublicKey
reads: a compressed one makes a signer not verifiable (F5) and a seal S1.
- cms.ts: a UTF8String and the times of a certificate and of a token keep a
leading U+FEFF, as Go reads the bytes: such a name shows the hash, and
such a time breaks the profile (F1, S2).
- cms.ts: oidOf and intOf take time linear in the length of the element.
An arc of up to seven digits accumulates in a number, a longer one and
every INTEGER are read whole from hexadecimal, never by a shift per byte,
which took some 700 ms for 60 KB; attributes of one type are appended,
not copied.
- security.ts: evaluateSecurity never throws. A fault while it evaluates
the signature gives F1, one while it evaluates the seal S2, each apart,
and one while it decodes the area X, as the Go reference will from v0.12.
- Tests: securitycms.test.ts and security.failure.test.ts are new.
cms.test.ts now refuses a second content-type and two signature-time-
stamps for the rule of the count, with every SET OF in DER order, and
der.test.ts tests the depth at its boundary. cmsbuild.ts makes names,
validities and compressed points of its own.
capsule.EvaluateSecurityIn of the Go reference at spec-v0.11 gives the same
verdicts, signer lines and Spanish lines on 25 areas made with cmsbuild.ts:
issuers with ESC, U+202E, empty, of 300 bytes or with a leading U+FEFF;
names and times with a leading U+FEFF; and compressed keys on P-256, P-384
and P-521, as signers and as authorities of a seal. HEAD gave other ones in
19 of them. npm run verify passes.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
der.ts checks DER byte by byte. cms.ts reads the CMS signature and the RFC
3161 token of spec v0.11 29.10 and 29.11 with the closed table of
algorithms: RSA PKCS 1 and PSS with BigInt, ECDSA with the arithmetic of
@noble/curves, no new package. securitycms.ts gives F1, F2, F5 and F6 with
the signers named, and S1 to S5 with the authority of a valid seal.
evaluateSecurity returns them with their detail, and verdictLines writes the
lines of F6 and S4. The 22 cases of security_cms.json and the fixtures
format3_signed_cms and format3_sealed give the verdicts, the signers and the
seal of the Go reference. testing/cmsbuild.ts builds signatures and tokens
with WebCrypto for the hostile cases ported from the Go tests, and the
pending mechanism of the first sync is gone. npm run verify passes.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>