You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
DateKeys/internal/testkit/genfixtures/cmsfix.go

72 lines
2.5 KiB

package main
import (
"crypto/elliptic"
"crypto/sha256"
"time"
"g.activething.com/go/DateKeys/capsule"
"g.activething.com/go/DateKeys/internal/cms/cmstest"
"g.activething.com/go/DateKeys/internal/testkit"
)
// The fixtures with certificates (spec v0.11, §29.10, §29.11) are signed by
// test certificates made when the fixture is generated, so their bytes are
// random and, like those of the other fixtures, frozen once written. The
// private keys are not kept: a reader only verifies.
var (
certFrom = time.Date(2020, 1, 1, 0, 0, 0, 0, time.UTC)
certTo = time.Date(2040, 1, 1, 0, 0, 0, 0, time.UTC)
)
func sum256(b []byte) [32]byte { return sha256.Sum256(b) }
// certSigner is a CMSSigner that signs as a signing application would, and
// seals each signature with the authority tsa at the writing time.
type certSigner struct {
signers []cmstest.Signer
tsa cmstest.Signer
when time.Time
}
func (c *certSigner) Signers() (out [][32]byte) {
for _, s := range c.signers {
out = append(out, sum256(s.Cert.Raw))
}
return out
}
func (c *certSigner) Sign(message []byte) ([]byte, error) {
return cmstest.Signature(message, cmstest.Options{Token: func(sig []byte) []byte {
return cmstest.Token(sig, c.when, cmstest.TokenOptions{Accuracy: time.Second}, c.tsa)
}}, c.signers...), nil
}
// tokenSealer asks the authority tsa for the token over SEAL_SUBJECT.
type tokenSealer struct {
tsa cmstest.Signer
when time.Time
}
func (s tokenSealer) Seal(subject [32]byte) ([]byte, error) {
return cmstest.Token(subject[:], s.when, cmstest.TokenOptions{Accuracy: time.Second}, s.tsa), nil
}
// configureCMS makes the capsule be signed by two certificates, an ECDSA one
// and an RSA one, each sealed by a time-stamping authority: verdict F6.
func configureCMS(o *capsule.EncryptOptions) error {
ana := cmstest.NewECDSA("Ana López", elliptic.P256(), certFrom, certTo)
luis := cmstest.NewRSA("Luis Gómez", 2048, certFrom, certTo)
tsa := cmstest.NewECDSA("Autoridad de Sellado de prueba", elliptic.P256(), certFrom, certTo)
o.CMSSigner = &certSigner{signers: []cmstest.Signer{ana, luis}, tsa: tsa, when: testkit.Genesis()}
return nil
}
// configureSeal makes the capsule carry a seal of seal_type 2 over the
// signature of alg 1 that its spec gives a key for: verdicts F4 and S4.
func configureSeal(o *capsule.EncryptOptions) error {
tsa := cmstest.NewECDSA("Autoridad de Sellado de prueba", elliptic.P256(), certFrom, certTo)
o.Sealer = tokenSealer{tsa: tsa, when: testkit.Genesis()}
return nil
}

Powered by TurnKey Linux.