cms.dart ports internal/cms of datekeys-go at c531e93, with its order of
checks and its texts: parseCert reads a certificate field by field with
the profile of spec v0.12 §29.10, with the holder from givenName and
surname before the commonName and the issuer from organizationName when
there is no commonName with text; parseSignature reads a detached
SignedData, its certificates, OCSP responses, signers, signed and
unsigned attributes, and SignerInfo.check gives valid, invalid or not
verifiable with the closed table of algorithms, a key of another scheme
invalid; parseToken reads an RFC 3161 token and its TSTInfo field by
field, form errors before algorithm errors, and Token.check verifies it
over a subject. Object identifiers are compared by their bytes, and a
SET OF may repeat an element.
The tests run every case of the vectors on the VM, the fixtures
format3_signed_cms and format3_sealed included, and the part that
cms_vectors.g.dart holds compiled to JavaScript.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
nist_curves.dart reads an uncompressed point as Go's
ecdsa.ParseUncompressedPublicKey does, and computes u1 G + u2 Q in
Jacobian coordinates with Shamir's trick, the infinity included.
ecdsa.dart is VerifyASN1: the encoding as cryptobyte reads it, r and s
in [1, n - 1] and never reduced, s above n/2 accepted, the hash cut to
the bits of the order. rsa.dart is VerifyPKCS1v15, which rebuilds the
encoding and compares it whole, and VerifyPSS with a salt of the length
of the hash, with the bytes before emLen that must be zero; and the
hashes of the table, SHA-256, SHA-384 and SHA-512 of package:crypto.
All on BigInt, exact on the VM and compiled to JavaScript, and not
constant-time: a verification sees public values only. The curve
constants are those that the vectors record from Go.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>