package main import ( "crypto/elliptic" "crypto/sha256" "time" "g.activething.com/go/DateKeys/capsule" "g.activething.com/go/DateKeys/internal/cms/cmstest" "g.activething.com/go/DateKeys/internal/testkit" ) // The fixtures with certificates (spec v0.11, §29.10, §29.11) are signed by // test certificates made when the fixture is generated, so their bytes are // random and, like those of the other fixtures, frozen once written. The // private keys are not kept: a reader only verifies. var ( certFrom = time.Date(2020, 1, 1, 0, 0, 0, 0, time.UTC) certTo = time.Date(2040, 1, 1, 0, 0, 0, 0, time.UTC) ) func sum256(b []byte) [32]byte { return sha256.Sum256(b) } // certSigner is a CMSSigner that signs as a signing application would, and // seals each signature with the authority tsa at the writing time. type certSigner struct { signers []cmstest.Signer tsa cmstest.Signer when time.Time } func (c *certSigner) Signers() (out [][32]byte) { for _, s := range c.signers { out = append(out, sum256(s.Cert.Raw)) } return out } func (c *certSigner) Sign(message []byte) ([]byte, error) { return cmstest.Signature(message, cmstest.Options{Token: func(sig []byte) []byte { return cmstest.Token(sig, c.when, cmstest.TokenOptions{Accuracy: time.Second}, c.tsa) }}, c.signers...), nil } // tokenSealer asks the authority tsa for the token over SEAL_SUBJECT. type tokenSealer struct { tsa cmstest.Signer when time.Time } func (s tokenSealer) Seal(subject [32]byte) ([]byte, error) { return cmstest.Token(subject[:], s.when, cmstest.TokenOptions{Accuracy: time.Second}, s.tsa), nil } // configureCMS makes the capsule be signed by two certificates, an ECDSA one // and an RSA one, each sealed by a time-stamping authority: verdict F6. func configureCMS(o *capsule.EncryptOptions) error { ana := cmstest.NewECDSA("Ana López", elliptic.P256(), certFrom, certTo) luis := cmstest.NewRSA("Luis Gómez", 2048, certFrom, certTo) tsa := cmstest.NewECDSA("Autoridad de Sellado de prueba", elliptic.P256(), certFrom, certTo) o.CMSSigner = &certSigner{signers: []cmstest.Signer{ana, luis}, tsa: tsa, when: testkit.Genesis()} return nil } // configureSeal makes the capsule carry a seal of seal_type 2 over the // signature of alg 1 that its spec gives a key for: verdicts F4 and S4. func configureSeal(o *capsule.EncryptOptions) error { tsa := cmstest.NewECDSA("Autoridad de Sellado de prueba", elliptic.P256(), certFrom, certTo) o.Sealer = tokenSealer{tsa: tsa, when: testkit.Genesis()} return nil }