v0.16
main
v0.15
v0.14
v0.13
v0.12
v0.11
v0.10
v0.9
v0.8.2
spec-v0.16
spec-v0.15
spec-v0.14
spec-v0.13
spec-v0.12
spec-v0.11
spec-v0.10
spec-v0.9
spec-v0.8.2
${ noResults }
5 Commits (spec-v0.14)
| Author | SHA1 | Message | Date |
|---|---|---|---|
|
|
4ce4d59c8d |
Tests of the CMS reader: certificates field by field, every check, fuzzing
The builder of the tests, cmstest: - NewCert writes a certificate from the DER of its tbsCertificate, field by field: names of any string type with any bytes (UTF8String, PrintableString with an underscore or an at sign, IA5String, TeletexString, BMPString of odd length or with a surrogate, VisibleString, NumericString), an attribute twice or none, no version, times with a fraction, an extension twice, a compressed EC key, an even modulus, and any signature. A Signer made so serves Signature and Token. - Options for the version of a SignerInfo, the hashAlgorithm and the certHash of an ESSCertIDv2, a signatureAlgorithm other than the one of the key, a certificate twice, two content-type attributes, an attribute with an arc of 2^31, a SignerInfo twice, BER, signerInfos out of order, two signature-time-stamp attributes, and edits of the SignedData and of each SignerInfo. - Token options for any accuracy, a genTime of free text, ordering FALSE, a field after the last, an imprint of any length, no message-digest, a CRL in crls and the certificate of the authority twice. - Edits of the DER after signing: Edit, Retag, Withdraw (a SignerInfo removed), WithoutTimeStamp (a CAdES-T removed), Merge (a co-signature) and Indefinite. The tests of internal/cms and internal/der fail for each check of cms.go, cert.go, verify.go and der.go. A mutation run, which replaces each leaf of each condition by false and by true, one at a time, kills every mutant that is not equivalent to the code it mutates. FuzzParseSignature, FuzzParseToken, FuzzParseCert and FuzzDERCheck, seeded with security_cms.json and with what cmstest builds: no panic, what Check accepts Split reads, and the parsers fail only with ErrForm or ErrAlgorithm. capsule: the case of a seal outside the validity of the certificate gave an invalid seal; it now tests a certificate that expired before a valid seal (out of validity) apart from an authority that was not valid at its time (invalid seal). SIGNERS out of order, empty, too long, with 31 bytes or with a hash twice are F1 beside a CMS signature that is valid for the AUTHOR_MESSAGE of those SIGNERS, and the names of certificates show as spec v0.12 §29.7 says. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
6 days ago |
|
|
b06ab4ffa2 |
DER: the restricted string types are DER, a NumericString among them
der.Check refused the universal types 7, 18, 21, 25 and 27 (ObjectDescriptor, NumericString, VideotexString, GraphicString and GeneralString), which DER writes primitive with their content as it is (X.690 10.2). A certificate whose name holds one of them, as the INN of a Russian certificate or the countryCode3n of X.520, made the whole CMS signature F1, and a token S2, while spec v0.12 §29.10 asks for DER and reads the name with its profile: any value, which is no text when it is not of the five string types. Such a certificate now meets the profile; its value shows as no text. REAL, RELATIVE-OID, TIME and the reserved tags stay refused: their DER has rules of its own, and no certificate, signature or token uses them. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
6 days ago |
|
|
839e1173e0 |
CMS reader: its own certificate profile, identifiers by their bytes
Fixes of the review of the session of 1 and 2 October in internal/cms and internal/der: - Object identifiers are compared by the bytes of their DER: an arc of 2^31 or more no longer makes an attribute that decides nothing fail the signature (F1), and an algorithm with one is outside the table (F5, S1), as spec v0.11 says. - A SET OF may repeat an element, as X.690 allows: a TSA that sends its certificate twice no longer gives S2. Two copies of a certificate are one. - Certificates are read with a profile of their own instead of encoding/asn1 and crypto/x509, field by field, so that a second implementation can read them the same: version 3, the fields in order, names of non-empty SETs, times of validity in DER without a fraction, extensions without repetition, and the text of a name only from UTF8String, PrintableString, IA5String, TeletexString in ASCII and BMPString without surrogates, nothing removed from it. A certificate that breaks the profile decides nothing unless a SignerInfo names it. The holder is givenName and surname before commonName, which in the certificates of the FNMT carries the NIF; the issuer is its commonName or its organizationName. - The key: RSA with NULL parameters, exactly a modulus and an exponent, the modulus odd; EC only uncompressed on P-256, P-384 and P-521. - A key of another scheme than its algorithm is invalid (F2) and not outside the table (F5), as step 3 of 29.10 says; a messageImprint of another length is S3; the crls of a token decide nothing. - DER: UTCTime and GeneralizedTime in their forms of X.690, a date that exists, and the millis and micros of accuracy as minimal INTEGERs. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> |
6 days ago |
|
|
b0bda15d20 |
Review fixes: the CMS reader, the area after the signature, and the issuer on screen
The TSTInfo is read field by field in DER, with accuracy from zero and millis and micros from 1 to 999, genTime in UTC with Z, no default written and nothing after the last field. The ContentInfo and the SignerInfo must be SEQUENCEs, a SignerInfo version must match its sid, an attribute needs a value and is counted by attribute and not by value, a signing-certificate beside the v2 decides nothing, PSS parameters come in order without the trailer, and der.Check refuses the end of contents and the universal tags the profile does not use. The writer signs before L is fixed: write asks prepare for the final L, so the area grows to 64 KiB only when what was signed does not fit and LargeArea allows it, and nobody signs twice for it. Typed nils are nil, the exclusions are checked before a file is read, Encrypt refuses the signing options, and EvaluateSecurityIn gives X if a parser panics. The issuer of a certificate is filtered like its holder. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
6 days ago |
|
|
55a261c792 |
Signature plan, alg 2 begun: a strict DER check and the CMS and RFC 3161 reader
internal/der checks that bytes are one element of DER. internal/cms reads the detached CMS signature of spec v0.11 29.10 and the RFC 3161 token of 29.11, in the order of the spec, with the closed table of algorithms (RSA PKCS 1 and PSS of 2048 to 4096 bits, ECDSA on P-256, P-384 and P-521, SHA-2), with the standard library only. A certificate is read with encoding/asn1, so that a key of a curve Go lacks makes a signature "not verifiable" and not malformed. internal/cms/cmstest builds them for tests. Not wired into capsule yet. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
6 days ago |