You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
72 lines
2.5 KiB
72 lines
2.5 KiB
package main
|
|
|
|
import (
|
|
"crypto/elliptic"
|
|
"crypto/sha256"
|
|
"time"
|
|
|
|
"g.activething.com/go/DateKeys/capsule"
|
|
"g.activething.com/go/DateKeys/internal/cms/cmstest"
|
|
"g.activething.com/go/DateKeys/internal/testkit"
|
|
)
|
|
|
|
// The fixtures with certificates (spec v0.11, §29.10, §29.11) are signed by
|
|
// test certificates made when the fixture is generated, so their bytes are
|
|
// random and, like those of the other fixtures, frozen once written. The
|
|
// private keys are not kept: a reader only verifies.
|
|
var (
|
|
certFrom = time.Date(2020, 1, 1, 0, 0, 0, 0, time.UTC)
|
|
certTo = time.Date(2040, 1, 1, 0, 0, 0, 0, time.UTC)
|
|
)
|
|
|
|
func sum256(b []byte) [32]byte { return sha256.Sum256(b) }
|
|
|
|
// certSigner is a CMSSigner that signs as a signing application would, and
|
|
// seals each signature with the authority tsa at the writing time.
|
|
type certSigner struct {
|
|
signers []cmstest.Signer
|
|
tsa cmstest.Signer
|
|
when time.Time
|
|
}
|
|
|
|
func (c *certSigner) Signers() (out [][32]byte) {
|
|
for _, s := range c.signers {
|
|
out = append(out, sum256(s.Cert.Raw))
|
|
}
|
|
return out
|
|
}
|
|
|
|
func (c *certSigner) Sign(message []byte) ([]byte, error) {
|
|
return cmstest.Signature(message, cmstest.Options{Token: func(sig []byte) []byte {
|
|
return cmstest.Token(sig, c.when, cmstest.TokenOptions{Accuracy: time.Second}, c.tsa)
|
|
}}, c.signers...), nil
|
|
}
|
|
|
|
// tokenSealer asks the authority tsa for the token over SEAL_SUBJECT.
|
|
type tokenSealer struct {
|
|
tsa cmstest.Signer
|
|
when time.Time
|
|
}
|
|
|
|
func (s tokenSealer) Seal(subject [32]byte) ([]byte, error) {
|
|
return cmstest.Token(subject[:], s.when, cmstest.TokenOptions{Accuracy: time.Second}, s.tsa), nil
|
|
}
|
|
|
|
// configureCMS makes the capsule be signed by two certificates, an ECDSA one
|
|
// and an RSA one, each sealed by a time-stamping authority: verdict F6.
|
|
func configureCMS(o *capsule.EncryptOptions) error {
|
|
ana := cmstest.NewECDSA("Ana López", elliptic.P256(), certFrom, certTo)
|
|
luis := cmstest.NewRSA("Luis Gómez", 2048, certFrom, certTo)
|
|
tsa := cmstest.NewECDSA("Autoridad de Sellado de prueba", elliptic.P256(), certFrom, certTo)
|
|
o.CMSSigner = &certSigner{signers: []cmstest.Signer{ana, luis}, tsa: tsa, when: testkit.Genesis()}
|
|
return nil
|
|
}
|
|
|
|
// configureSeal makes the capsule carry a seal of seal_type 2 over the
|
|
// signature of alg 1 that its spec gives a key for: verdicts F4 and S4.
|
|
func configureSeal(o *capsule.EncryptOptions) error {
|
|
tsa := cmstest.NewECDSA("Autoridad de Sellado de prueba", elliptic.P256(), certFrom, certTo)
|
|
o.Sealer = tokenSealer{tsa: tsa, when: testkit.Genesis()}
|
|
return nil
|
|
}
|