The TSTInfo is read field by field in DER, with accuracy from zero and
millis and micros from 1 to 999, genTime in UTC with Z, no default written
and nothing after the last field. The ContentInfo and the SignerInfo must be
SEQUENCEs, a SignerInfo version must match its sid, an attribute needs a
value and is counted by attribute and not by value, a signing-certificate
beside the v2 decides nothing, PSS parameters come in order without the
trailer, and der.Check refuses the end of contents and the universal tags
the profile does not use.
The writer signs before L is fixed: write asks prepare for the final L, so
the area grows to 64 KiB only when what was signed does not fit and LargeArea
allows it, and nobody signs twice for it. Typed nils are nil, the exclusions
are checked before a file is read, Encrypt refuses the signing options, and
EvaluateSecurityIn gives X if a parser panics. The issuer of a certificate is
filtered like its holder.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
internal/der checks that bytes are one element of DER. internal/cms reads
the detached CMS signature of spec v0.11 29.10 and the RFC 3161 token of
29.11, in the order of the spec, with the closed table of algorithms (RSA
PKCS 1 and PSS of 2048 to 4096 bits, ECDSA on P-256, P-384 and P-521,
SHA-2), with the standard library only. A certificate is read with
encoding/asn1, so that a key of a curve Go lacks makes a signature "not
verifiable" and not malformed. internal/cms/cmstest builds them for tests.
Not wired into capsule yet.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>