17.12
This commit is contained in:
@@ -0,0 +1,65 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Copyright (c) 2005-2019, Ilya Etingof <etingof@gmail.com>
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
import base64
|
||||
import sys
|
||||
|
||||
stSpam, stHam, stDump = 0, 1, 2
|
||||
|
||||
|
||||
# The markers parameters is in form ('start1', 'stop1'), ('start2', 'stop2')...
|
||||
# Return is (marker-index, substrate)
|
||||
def readPemBlocksFromFile(fileObj, *markers):
|
||||
startMarkers = dict(map(lambda x: (x[1], x[0]),
|
||||
enumerate(map(lambda y: y[0], markers))))
|
||||
stopMarkers = dict(map(lambda x: (x[1], x[0]),
|
||||
enumerate(map(lambda y: y[1], markers))))
|
||||
idx = -1
|
||||
substrate = ''
|
||||
certLines = []
|
||||
state = stSpam
|
||||
while True:
|
||||
certLine = fileObj.readline()
|
||||
if not certLine:
|
||||
break
|
||||
certLine = certLine.strip()
|
||||
if state == stSpam:
|
||||
if certLine in startMarkers:
|
||||
certLines = []
|
||||
idx = startMarkers[certLine]
|
||||
state = stHam
|
||||
continue
|
||||
if state == stHam:
|
||||
if certLine in stopMarkers and stopMarkers[certLine] == idx:
|
||||
state = stDump
|
||||
else:
|
||||
certLines.append(certLine)
|
||||
if state == stDump:
|
||||
if sys.version_info[0] <= 2:
|
||||
substrate = ''.join([base64.b64decode(x) for x in certLines])
|
||||
else:
|
||||
substrate = ''.encode().join([base64.b64decode(x.encode()) for x in certLines])
|
||||
break
|
||||
return idx, substrate
|
||||
|
||||
|
||||
# Backward compatibility routine
|
||||
def readPemFromFile(fileObj,
|
||||
startMarker='-----BEGIN CERTIFICATE-----',
|
||||
endMarker='-----END CERTIFICATE-----'):
|
||||
idx, substrate = readPemBlocksFromFile(fileObj, (startMarker, endMarker))
|
||||
return substrate
|
||||
|
||||
|
||||
def readBase64fromText(text):
|
||||
if sys.version_info[0] <= 2:
|
||||
return base64.b64decode(text)
|
||||
else:
|
||||
return base64.b64decode(text.encode())
|
||||
|
||||
|
||||
def readBase64FromFile(fileObj):
|
||||
return readBase64fromText(fileObj.read())
|
||||
@@ -0,0 +1,22 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Copyright (c) 2005-2019, Ilya Etingof <etingof@gmail.com>
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# SNMPv2c message syntax
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# http://www.ietf.org/rfc/rfc1901.txt
|
||||
#
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import namedval
|
||||
from pyasn1.type import univ
|
||||
|
||||
|
||||
class Message(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('version', univ.Integer(namedValues=namedval.NamedValues(('version-2c', 1)))),
|
||||
namedtype.NamedType('community', univ.OctetString()),
|
||||
namedtype.NamedType('data', univ.Any())
|
||||
)
|
||||
@@ -0,0 +1,69 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Copyright (c) 2005-2019, Ilya Etingof <etingof@gmail.com>
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# PKCS#1 syntax
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# ftp://ftp.rsasecurity.com/pub/pkcs/pkcs-1/pkcs-1v2.asn
|
||||
#
|
||||
# Sample captures could be obtained with "openssl genrsa" command
|
||||
#
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules.rfc2459 import AlgorithmIdentifier
|
||||
|
||||
pkcs_1 = univ.ObjectIdentifier('1.2.840.113549.1.1')
|
||||
rsaEncryption = univ.ObjectIdentifier('1.2.840.113549.1.1.1')
|
||||
md2WithRSAEncryption = univ.ObjectIdentifier('1.2.840.113549.1.1.2')
|
||||
md4WithRSAEncryption = univ.ObjectIdentifier('1.2.840.113549.1.1.3')
|
||||
md5WithRSAEncryption = univ.ObjectIdentifier('1.2.840.113549.1.1.4')
|
||||
sha1WithRSAEncryption = univ.ObjectIdentifier('1.2.840.113549.1.1.5')
|
||||
rsaOAEPEncryptionSET = univ.ObjectIdentifier('1.2.840.113549.1.1.6')
|
||||
id_RSAES_OAEP = univ.ObjectIdentifier('1.2.840.113549.1.1.7')
|
||||
id_mgf1 = univ.ObjectIdentifier('1.2.840.113549.1.1.8')
|
||||
id_pSpecified = univ.ObjectIdentifier('1.2.840.113549.1.1.9')
|
||||
id_sha1 = univ.ObjectIdentifier('1.3.14.3.2.26')
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
|
||||
class Version(univ.Integer):
|
||||
pass
|
||||
|
||||
|
||||
class RSAPrivateKey(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('version', Version()),
|
||||
namedtype.NamedType('modulus', univ.Integer()),
|
||||
namedtype.NamedType('publicExponent', univ.Integer()),
|
||||
namedtype.NamedType('privateExponent', univ.Integer()),
|
||||
namedtype.NamedType('prime1', univ.Integer()),
|
||||
namedtype.NamedType('prime2', univ.Integer()),
|
||||
namedtype.NamedType('exponent1', univ.Integer()),
|
||||
namedtype.NamedType('exponent2', univ.Integer()),
|
||||
namedtype.NamedType('coefficient', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
class RSAPublicKey(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('modulus', univ.Integer()),
|
||||
namedtype.NamedType('publicExponent', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
# XXX defaults not set
|
||||
class RSAES_OAEP_params(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('hashFunc', AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.NamedType('maskGenFunc', AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1))),
|
||||
namedtype.NamedType('pSourceFunc', AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 2)))
|
||||
)
|
||||
@@ -0,0 +1,258 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Copyright (c) 2005-2019, Ilya Etingof <etingof@gmail.com>
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# X.509 certificate Request Message Format (CRMF) syntax
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# http://tools.ietf.org/html/rfc2511
|
||||
#
|
||||
# Sample captures could be obtained with OpenSSL
|
||||
#
|
||||
from pyasn1_modules import rfc2315
|
||||
from pyasn1_modules.rfc2459 import *
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
id_pkix = univ.ObjectIdentifier('1.3.6.1.5.5.7')
|
||||
id_pkip = univ.ObjectIdentifier('1.3.6.1.5.5.7.5')
|
||||
id_regCtrl = univ.ObjectIdentifier('1.3.6.1.5.5.7.5.1')
|
||||
id_regCtrl_regToken = univ.ObjectIdentifier('1.3.6.1.5.5.7.5.1.1')
|
||||
id_regCtrl_authenticator = univ.ObjectIdentifier('1.3.6.1.5.5.7.5.1.2')
|
||||
id_regCtrl_pkiPublicationInfo = univ.ObjectIdentifier('1.3.6.1.5.5.7.5.1.3')
|
||||
id_regCtrl_pkiArchiveOptions = univ.ObjectIdentifier('1.3.6.1.5.5.7.5.1.4')
|
||||
id_regCtrl_oldCertID = univ.ObjectIdentifier('1.3.6.1.5.5.7.5.1.5')
|
||||
id_regCtrl_protocolEncrKey = univ.ObjectIdentifier('1.3.6.1.5.5.7.5.1.6')
|
||||
id_regInfo = univ.ObjectIdentifier('1.3.6.1.5.5.7.5.2')
|
||||
id_regInfo_utf8Pairs = univ.ObjectIdentifier('1.3.6.1.5.5.7.5.2.1')
|
||||
id_regInfo_certReq = univ.ObjectIdentifier('1.3.6.1.5.5.7.5.2.2')
|
||||
|
||||
|
||||
# This should be in PKIX Certificate Extensions module
|
||||
|
||||
class GeneralName(univ.OctetString):
|
||||
pass
|
||||
|
||||
|
||||
# end of PKIX Certificate Extensions module
|
||||
|
||||
class UTF8Pairs(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
class ProtocolEncrKey(SubjectPublicKeyInfo):
|
||||
pass
|
||||
|
||||
|
||||
class CertId(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('issuer', GeneralName()),
|
||||
namedtype.NamedType('serialNumber', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
class OldCertId(CertId):
|
||||
pass
|
||||
|
||||
|
||||
class KeyGenParameters(univ.OctetString):
|
||||
pass
|
||||
|
||||
|
||||
class EncryptedValue(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('intendedAlg', AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.OptionalNamedType('symmAlg', AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1))),
|
||||
namedtype.OptionalNamedType('encSymmKey', univ.BitString().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 2))),
|
||||
namedtype.OptionalNamedType('keyAlg', AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 3))),
|
||||
namedtype.OptionalNamedType('valueHint', univ.OctetString().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 4))),
|
||||
namedtype.NamedType('encValue', univ.BitString())
|
||||
)
|
||||
|
||||
|
||||
class EncryptedKey(univ.Choice):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('encryptedValue', EncryptedValue()),
|
||||
namedtype.NamedType('envelopedData', rfc2315.EnvelopedData().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0)))
|
||||
)
|
||||
|
||||
|
||||
class PKIArchiveOptions(univ.Choice):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('encryptedPrivKey', EncryptedKey().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.NamedType('keyGenParameters', KeyGenParameters().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.NamedType('archiveRemGenPrivKey',
|
||||
univ.Boolean().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2)))
|
||||
)
|
||||
|
||||
|
||||
class SinglePubInfo(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('pubMethod', univ.Integer(
|
||||
namedValues=namedval.NamedValues(('dontCare', 0), ('x500', 1), ('web', 2), ('ldap', 3)))),
|
||||
namedtype.OptionalNamedType('pubLocation', GeneralName())
|
||||
)
|
||||
|
||||
|
||||
class PKIPublicationInfo(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('action',
|
||||
univ.Integer(namedValues=namedval.NamedValues(('dontPublish', 0), ('pleasePublish', 1)))),
|
||||
namedtype.OptionalNamedType('pubInfos', univ.SequenceOf(componentType=SinglePubInfo()).subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX)))
|
||||
)
|
||||
|
||||
|
||||
class Authenticator(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
class RegToken(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
class SubsequentMessage(univ.Integer):
|
||||
namedValues = namedval.NamedValues(
|
||||
('encrCert', 0),
|
||||
('challengeResp', 1)
|
||||
)
|
||||
|
||||
|
||||
class POPOPrivKey(univ.Choice):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('thisMessage',
|
||||
univ.BitString().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.NamedType('subsequentMessage', SubsequentMessage().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.NamedType('dhMAC',
|
||||
univ.BitString().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2)))
|
||||
)
|
||||
|
||||
|
||||
class PBMParameter(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('salt', univ.OctetString()),
|
||||
namedtype.NamedType('owf', AlgorithmIdentifier()),
|
||||
namedtype.NamedType('iterationCount', univ.Integer()),
|
||||
namedtype.NamedType('mac', AlgorithmIdentifier())
|
||||
)
|
||||
|
||||
|
||||
class PKMACValue(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('algId', AlgorithmIdentifier()),
|
||||
namedtype.NamedType('value', univ.BitString())
|
||||
)
|
||||
|
||||
|
||||
class POPOSigningKeyInput(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType(
|
||||
'authInfo', univ.Choice(
|
||||
componentType=namedtype.NamedTypes(
|
||||
namedtype.NamedType(
|
||||
'sender', GeneralName().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))
|
||||
),
|
||||
namedtype.NamedType('publicKeyMAC', PKMACValue())
|
||||
)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType('publicKey', SubjectPublicKeyInfo())
|
||||
)
|
||||
|
||||
|
||||
class POPOSigningKey(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('poposkInput', POPOSigningKeyInput().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.NamedType('algorithmIdentifier', AlgorithmIdentifier()),
|
||||
namedtype.NamedType('signature', univ.BitString())
|
||||
)
|
||||
|
||||
|
||||
class ProofOfPossession(univ.Choice):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('raVerified',
|
||||
univ.Null().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.NamedType('signature', POPOSigningKey().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1))),
|
||||
namedtype.NamedType('keyEncipherment', POPOPrivKey().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 2))),
|
||||
namedtype.NamedType('keyAgreement', POPOPrivKey().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 3)))
|
||||
)
|
||||
|
||||
|
||||
class Controls(univ.SequenceOf):
|
||||
componentType = AttributeTypeAndValue()
|
||||
sizeSpec = univ.SequenceOf.sizeSpec + constraint.ValueSizeConstraint(1, MAX)
|
||||
|
||||
|
||||
class OptionalValidity(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('notBefore',
|
||||
Time().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.OptionalNamedType('notAfter',
|
||||
Time().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1)))
|
||||
)
|
||||
|
||||
|
||||
class CertTemplate(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('version', Version().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.OptionalNamedType('serialNumber', univ.Integer().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.OptionalNamedType('signingAlg', AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 2))),
|
||||
namedtype.OptionalNamedType('issuer', Name().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 3))),
|
||||
namedtype.OptionalNamedType('validity', OptionalValidity().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 4))),
|
||||
namedtype.OptionalNamedType('subject', Name().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 5))),
|
||||
namedtype.OptionalNamedType('publicKey', SubjectPublicKeyInfo().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 6))),
|
||||
namedtype.OptionalNamedType('issuerUID', UniqueIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 7))),
|
||||
namedtype.OptionalNamedType('subjectUID', UniqueIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 8))),
|
||||
namedtype.OptionalNamedType('extensions', Extensions().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 9)))
|
||||
)
|
||||
|
||||
|
||||
class CertRequest(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certReqId', univ.Integer()),
|
||||
namedtype.NamedType('certTemplate', CertTemplate()),
|
||||
namedtype.OptionalNamedType('controls', Controls())
|
||||
)
|
||||
|
||||
|
||||
class CertReq(CertRequest):
|
||||
pass
|
||||
|
||||
|
||||
class CertReqMsg(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certReq', CertRequest()),
|
||||
namedtype.OptionalNamedType('pop', ProofOfPossession()),
|
||||
namedtype.OptionalNamedType('regInfo', univ.SequenceOf(componentType=AttributeTypeAndValue()).subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX)))
|
||||
)
|
||||
|
||||
|
||||
class CertReqMessages(univ.SequenceOf):
|
||||
componentType = CertReqMsg()
|
||||
sizeSpec = univ.SequenceOf.sizeSpec + constraint.ValueSizeConstraint(1, MAX)
|
||||
@@ -0,0 +1,75 @@
|
||||
# coding: utf-8
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Joel Johnson with asn1ate tool.
|
||||
# Modified by Russ Housley to add support for opentypes by importing
|
||||
# definitions from rfc5280 so that the same maps are used.
|
||||
#
|
||||
# Copyright (c) 2005-2019, Ilya Etingof <etingof@gmail.com>
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# PKCS #10: Certification Request Syntax Specification
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc2986.txt
|
||||
#
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc5280
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
|
||||
AttributeType = rfc5280.AttributeType
|
||||
|
||||
AttributeValue = rfc5280.AttributeValue
|
||||
|
||||
AttributeTypeAndValue = rfc5280.AttributeTypeAndValue
|
||||
|
||||
Attribute = rfc5280.Attribute
|
||||
|
||||
RelativeDistinguishedName = rfc5280.RelativeDistinguishedName
|
||||
|
||||
RDNSequence = rfc5280.RDNSequence
|
||||
|
||||
Name = rfc5280.Name
|
||||
|
||||
AlgorithmIdentifier = rfc5280.AlgorithmIdentifier
|
||||
|
||||
SubjectPublicKeyInfo = rfc5280.SubjectPublicKeyInfo
|
||||
|
||||
|
||||
class Attributes(univ.SetOf):
|
||||
pass
|
||||
|
||||
|
||||
Attributes.componentType = Attribute()
|
||||
|
||||
|
||||
class CertificationRequestInfo(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
CertificationRequestInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('version', univ.Integer()),
|
||||
namedtype.NamedType('subject', Name()),
|
||||
namedtype.NamedType('subjectPKInfo', SubjectPublicKeyInfo()),
|
||||
namedtype.NamedType('attributes',
|
||||
Attributes().subtype(implicitTag=tag.Tag(
|
||||
tag.tagClassContext, tag.tagFormatSimple, 0))
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
class CertificationRequest(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
CertificationRequest.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certificationRequestInfo', CertificationRequestInfo()),
|
||||
namedtype.NamedType('signatureAlgorithm', AlgorithmIdentifier()),
|
||||
namedtype.NamedType('signature', univ.BitString())
|
||||
)
|
||||
@@ -0,0 +1,142 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley with assistance from asn1ate v.0.6.0.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# Time-Stamp Protocol (TSP)
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc3161.txt
|
||||
#
|
||||
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import namedval
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
from pyasn1.type import useful
|
||||
|
||||
from pyasn1_modules import rfc4210
|
||||
from pyasn1_modules import rfc5280
|
||||
from pyasn1_modules import rfc5652
|
||||
|
||||
|
||||
Extensions = rfc5280.Extensions
|
||||
|
||||
AlgorithmIdentifier = rfc5280.AlgorithmIdentifier
|
||||
|
||||
GeneralName = rfc5280.GeneralName
|
||||
|
||||
ContentInfo = rfc5652.ContentInfo
|
||||
|
||||
PKIFreeText = rfc4210.PKIFreeText
|
||||
|
||||
|
||||
id_ct_TSTInfo = univ.ObjectIdentifier('1.2.840.113549.1.9.16.1.4')
|
||||
|
||||
|
||||
class Accuracy(univ.Sequence):
|
||||
pass
|
||||
|
||||
Accuracy.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('seconds', univ.Integer()),
|
||||
namedtype.OptionalNamedType('millis', univ.Integer().subtype(subtypeSpec=constraint.ValueRangeConstraint(1, 999)).subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.OptionalNamedType('micros', univ.Integer().subtype(subtypeSpec=constraint.ValueRangeConstraint(1, 999)).subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1)))
|
||||
)
|
||||
|
||||
|
||||
class MessageImprint(univ.Sequence):
|
||||
pass
|
||||
|
||||
MessageImprint.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('hashAlgorithm', AlgorithmIdentifier()),
|
||||
namedtype.NamedType('hashedMessage', univ.OctetString())
|
||||
)
|
||||
|
||||
|
||||
class PKIFailureInfo(univ.BitString):
|
||||
pass
|
||||
|
||||
PKIFailureInfo.namedValues = namedval.NamedValues(
|
||||
('badAlg', 0),
|
||||
('badRequest', 2),
|
||||
('badDataFormat', 5),
|
||||
('timeNotAvailable', 14),
|
||||
('unacceptedPolicy', 15),
|
||||
('unacceptedExtension', 16),
|
||||
('addInfoNotAvailable', 17),
|
||||
('systemFailure', 25)
|
||||
)
|
||||
|
||||
|
||||
class PKIStatus(univ.Integer):
|
||||
pass
|
||||
|
||||
PKIStatus.namedValues = namedval.NamedValues(
|
||||
('granted', 0),
|
||||
('grantedWithMods', 1),
|
||||
('rejection', 2),
|
||||
('waiting', 3),
|
||||
('revocationWarning', 4),
|
||||
('revocationNotification', 5)
|
||||
)
|
||||
|
||||
|
||||
class PKIStatusInfo(univ.Sequence):
|
||||
pass
|
||||
|
||||
PKIStatusInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('status', PKIStatus()),
|
||||
namedtype.OptionalNamedType('statusString', PKIFreeText()),
|
||||
namedtype.OptionalNamedType('failInfo', PKIFailureInfo())
|
||||
)
|
||||
|
||||
|
||||
class TSAPolicyId(univ.ObjectIdentifier):
|
||||
pass
|
||||
|
||||
|
||||
class TSTInfo(univ.Sequence):
|
||||
pass
|
||||
|
||||
TSTInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('version', univ.Integer(namedValues=namedval.NamedValues(('v1', 1)))),
|
||||
namedtype.NamedType('policy', TSAPolicyId()),
|
||||
namedtype.NamedType('messageImprint', MessageImprint()),
|
||||
namedtype.NamedType('serialNumber', univ.Integer()),
|
||||
namedtype.NamedType('genTime', useful.GeneralizedTime()),
|
||||
namedtype.OptionalNamedType('accuracy', Accuracy()),
|
||||
namedtype.DefaultedNamedType('ordering', univ.Boolean().subtype(value=0)),
|
||||
namedtype.OptionalNamedType('nonce', univ.Integer()),
|
||||
namedtype.OptionalNamedType('tsa', GeneralName().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.OptionalNamedType('extensions', Extensions().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1)))
|
||||
)
|
||||
|
||||
|
||||
class TimeStampReq(univ.Sequence):
|
||||
pass
|
||||
|
||||
TimeStampReq.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('version', univ.Integer(namedValues=namedval.NamedValues(('v1', 1)))),
|
||||
namedtype.NamedType('messageImprint', MessageImprint()),
|
||||
namedtype.OptionalNamedType('reqPolicy', TSAPolicyId()),
|
||||
namedtype.OptionalNamedType('nonce', univ.Integer()),
|
||||
namedtype.DefaultedNamedType('certReq', univ.Boolean().subtype(value=0)),
|
||||
namedtype.OptionalNamedType('extensions', Extensions().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0)))
|
||||
)
|
||||
|
||||
|
||||
class TimeStampToken(ContentInfo):
|
||||
pass
|
||||
|
||||
|
||||
class TimeStampResp(univ.Sequence):
|
||||
pass
|
||||
|
||||
TimeStampResp.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('status', PKIStatusInfo()),
|
||||
namedtype.OptionalNamedType('timeStampToken', TimeStampToken())
|
||||
)
|
||||
@@ -0,0 +1,233 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules.
|
||||
#
|
||||
# Copyright (c) 2017, Danielle Madeley <danielle@madeley.id.au>
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# Derived from RFC 3279
|
||||
#
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import namedval
|
||||
from pyasn1.type import univ
|
||||
|
||||
|
||||
def _OID(*components):
|
||||
output = []
|
||||
for x in tuple(components):
|
||||
if isinstance(x, univ.ObjectIdentifier):
|
||||
output.extend(list(x))
|
||||
else:
|
||||
output.append(int(x))
|
||||
|
||||
return univ.ObjectIdentifier(output)
|
||||
|
||||
|
||||
md2 = _OID(1, 2, 840, 113549, 2, 2)
|
||||
md5 = _OID(1, 2, 840, 113549, 2, 5)
|
||||
id_sha1 = _OID(1, 3, 14, 3, 2, 26)
|
||||
id_dsa = _OID(1, 2, 840, 10040, 4, 1)
|
||||
|
||||
|
||||
class DSAPublicKey(univ.Integer):
|
||||
pass
|
||||
|
||||
|
||||
class Dss_Parms(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('p', univ.Integer()),
|
||||
namedtype.NamedType('q', univ.Integer()),
|
||||
namedtype.NamedType('g', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
id_dsa_with_sha1 = _OID(1, 2, 840, 10040, 4, 3)
|
||||
|
||||
|
||||
class Dss_Sig_Value(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('r', univ.Integer()),
|
||||
namedtype.NamedType('s', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
pkcs_1 = _OID(1, 2, 840, 113549, 1, 1)
|
||||
rsaEncryption = _OID(pkcs_1, 1)
|
||||
md2WithRSAEncryption = _OID(pkcs_1, 2)
|
||||
md5WithRSAEncryption = _OID(pkcs_1, 4)
|
||||
sha1WithRSAEncryption = _OID(pkcs_1, 5)
|
||||
|
||||
|
||||
class RSAPublicKey(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('modulus', univ.Integer()),
|
||||
namedtype.NamedType('publicExponent', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
dhpublicnumber = _OID(1, 2, 840, 10046, 2, 1)
|
||||
|
||||
|
||||
class DHPublicKey(univ.Integer):
|
||||
pass
|
||||
|
||||
|
||||
class ValidationParms(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('seed', univ.BitString()),
|
||||
namedtype.NamedType('pgenCounter', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
class DomainParameters(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('p', univ.Integer()),
|
||||
namedtype.NamedType('g', univ.Integer()),
|
||||
namedtype.NamedType('q', univ.Integer()),
|
||||
namedtype.OptionalNamedType('j', univ.Integer()),
|
||||
namedtype.OptionalNamedType('validationParms', ValidationParms())
|
||||
)
|
||||
|
||||
|
||||
id_keyExchangeAlgorithm = _OID(2, 16, 840, 1, 101, 2, 1, 1, 22)
|
||||
|
||||
|
||||
class KEA_Parms_Id(univ.OctetString):
|
||||
pass
|
||||
|
||||
|
||||
ansi_X9_62 = _OID(1, 2, 840, 10045)
|
||||
|
||||
|
||||
class FieldID(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('fieldType', univ.ObjectIdentifier()),
|
||||
namedtype.NamedType('parameters', univ.Any())
|
||||
)
|
||||
|
||||
|
||||
id_ecSigType = _OID(ansi_X9_62, 4)
|
||||
ecdsa_with_SHA1 = _OID(id_ecSigType, 1)
|
||||
|
||||
|
||||
class ECDSA_Sig_Value(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('r', univ.Integer()),
|
||||
namedtype.NamedType('s', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
id_fieldType = _OID(ansi_X9_62, 1)
|
||||
prime_field = _OID(id_fieldType, 1)
|
||||
|
||||
|
||||
class Prime_p(univ.Integer):
|
||||
pass
|
||||
|
||||
|
||||
characteristic_two_field = _OID(id_fieldType, 2)
|
||||
|
||||
|
||||
class Characteristic_two(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('m', univ.Integer()),
|
||||
namedtype.NamedType('basis', univ.ObjectIdentifier()),
|
||||
namedtype.NamedType('parameters', univ.Any())
|
||||
)
|
||||
|
||||
|
||||
id_characteristic_two_basis = _OID(characteristic_two_field, 3)
|
||||
gnBasis = _OID(id_characteristic_two_basis, 1)
|
||||
tpBasis = _OID(id_characteristic_two_basis, 2)
|
||||
|
||||
|
||||
class Trinomial(univ.Integer):
|
||||
pass
|
||||
|
||||
|
||||
ppBasis = _OID(id_characteristic_two_basis, 3)
|
||||
|
||||
|
||||
class Pentanomial(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('k1', univ.Integer()),
|
||||
namedtype.NamedType('k2', univ.Integer()),
|
||||
namedtype.NamedType('k3', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
class FieldElement(univ.OctetString):
|
||||
pass
|
||||
|
||||
|
||||
class ECPoint(univ.OctetString):
|
||||
pass
|
||||
|
||||
|
||||
class Curve(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('a', FieldElement()),
|
||||
namedtype.NamedType('b', FieldElement()),
|
||||
namedtype.OptionalNamedType('seed', univ.BitString())
|
||||
)
|
||||
|
||||
|
||||
class ECPVer(univ.Integer):
|
||||
namedValues = namedval.NamedValues(
|
||||
('ecpVer1', 1)
|
||||
)
|
||||
|
||||
|
||||
class ECParameters(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('version', ECPVer()),
|
||||
namedtype.NamedType('fieldID', FieldID()),
|
||||
namedtype.NamedType('curve', Curve()),
|
||||
namedtype.NamedType('base', ECPoint()),
|
||||
namedtype.NamedType('order', univ.Integer()),
|
||||
namedtype.OptionalNamedType('cofactor', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
class EcpkParameters(univ.Choice):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('ecParameters', ECParameters()),
|
||||
namedtype.NamedType('namedCurve', univ.ObjectIdentifier()),
|
||||
namedtype.NamedType('implicitlyCA', univ.Null())
|
||||
)
|
||||
|
||||
|
||||
id_publicKeyType = _OID(ansi_X9_62, 2)
|
||||
id_ecPublicKey = _OID(id_publicKeyType, 1)
|
||||
|
||||
ellipticCurve = _OID(ansi_X9_62, 3)
|
||||
|
||||
c_TwoCurve = _OID(ellipticCurve, 0)
|
||||
c2pnb163v1 = _OID(c_TwoCurve, 1)
|
||||
c2pnb163v2 = _OID(c_TwoCurve, 2)
|
||||
c2pnb163v3 = _OID(c_TwoCurve, 3)
|
||||
c2pnb176w1 = _OID(c_TwoCurve, 4)
|
||||
c2tnb191v1 = _OID(c_TwoCurve, 5)
|
||||
c2tnb191v2 = _OID(c_TwoCurve, 6)
|
||||
c2tnb191v3 = _OID(c_TwoCurve, 7)
|
||||
c2onb191v4 = _OID(c_TwoCurve, 8)
|
||||
c2onb191v5 = _OID(c_TwoCurve, 9)
|
||||
c2pnb208w1 = _OID(c_TwoCurve, 10)
|
||||
c2tnb239v1 = _OID(c_TwoCurve, 11)
|
||||
c2tnb239v2 = _OID(c_TwoCurve, 12)
|
||||
c2tnb239v3 = _OID(c_TwoCurve, 13)
|
||||
c2onb239v4 = _OID(c_TwoCurve, 14)
|
||||
c2onb239v5 = _OID(c_TwoCurve, 15)
|
||||
c2pnb272w1 = _OID(c_TwoCurve, 16)
|
||||
c2pnb304w1 = _OID(c_TwoCurve, 17)
|
||||
c2tnb359v1 = _OID(c_TwoCurve, 18)
|
||||
c2pnb368w1 = _OID(c_TwoCurve, 19)
|
||||
c2tnb431r1 = _OID(c_TwoCurve, 20)
|
||||
|
||||
primeCurve = _OID(ellipticCurve, 1)
|
||||
prime192v1 = _OID(primeCurve, 1)
|
||||
prime192v2 = _OID(primeCurve, 2)
|
||||
prime192v3 = _OID(primeCurve, 3)
|
||||
prime239v1 = _OID(primeCurve, 4)
|
||||
prime239v2 = _OID(primeCurve, 5)
|
||||
prime239v3 = _OID(primeCurve, 6)
|
||||
prime256v1 = _OID(primeCurve, 7)
|
||||
@@ -0,0 +1,74 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# RSAES-OAEP Key Transport Algorithm in CMS
|
||||
#
|
||||
# Notice that all of the things needed in RFC 3560 are also defined
|
||||
# in RFC 4055. So, they are all pulled from the RFC 4055 module into
|
||||
# this one so that people looking a RFC 3560 can easily find them.
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc3560.txt
|
||||
#
|
||||
|
||||
from pyasn1_modules import rfc4055
|
||||
|
||||
id_sha1 = rfc4055.id_sha1
|
||||
|
||||
id_sha256 = rfc4055.id_sha256
|
||||
|
||||
id_sha384 = rfc4055.id_sha384
|
||||
|
||||
id_sha512 = rfc4055.id_sha512
|
||||
|
||||
id_mgf1 = rfc4055.id_mgf1
|
||||
|
||||
rsaEncryption = rfc4055.rsaEncryption
|
||||
|
||||
id_RSAES_OAEP = rfc4055.id_RSAES_OAEP
|
||||
|
||||
id_pSpecified = rfc4055.id_pSpecified
|
||||
|
||||
sha1Identifier = rfc4055.sha1Identifier
|
||||
|
||||
sha256Identifier = rfc4055.sha256Identifier
|
||||
|
||||
sha384Identifier = rfc4055.sha384Identifier
|
||||
|
||||
sha512Identifier = rfc4055.sha512Identifier
|
||||
|
||||
mgf1SHA1Identifier = rfc4055.mgf1SHA1Identifier
|
||||
|
||||
mgf1SHA256Identifier = rfc4055.mgf1SHA256Identifier
|
||||
|
||||
mgf1SHA384Identifier = rfc4055.mgf1SHA384Identifier
|
||||
|
||||
mgf1SHA512Identifier = rfc4055.mgf1SHA512Identifier
|
||||
|
||||
pSpecifiedEmptyIdentifier = rfc4055.pSpecifiedEmptyIdentifier
|
||||
|
||||
|
||||
class RSAES_OAEP_params(rfc4055.RSAES_OAEP_params):
|
||||
pass
|
||||
|
||||
|
||||
rSAES_OAEP_Default_Params = RSAES_OAEP_params()
|
||||
|
||||
rSAES_OAEP_Default_Identifier = rfc4055.rSAES_OAEP_Default_Identifier
|
||||
|
||||
rSAES_OAEP_SHA256_Params = rfc4055.rSAES_OAEP_SHA256_Params
|
||||
|
||||
rSAES_OAEP_SHA256_Identifier = rfc4055.rSAES_OAEP_SHA256_Identifier
|
||||
|
||||
rSAES_OAEP_SHA384_Params = rfc4055.rSAES_OAEP_SHA384_Params
|
||||
|
||||
rSAES_OAEP_SHA384_Identifier = rfc4055.rSAES_OAEP_SHA384_Identifier
|
||||
|
||||
rSAES_OAEP_SHA512_Params = rfc4055.rSAES_OAEP_SHA512_Params
|
||||
|
||||
rSAES_OAEP_SHA512_Identifier = rfc4055.rSAES_OAEP_SHA512_Identifier
|
||||
@@ -0,0 +1,204 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley with assistance from asn1ate v.0.6.0.
|
||||
# Modified by Russ Housley to add maps for use with opentypes.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# Logotypes in X.509 Certificates
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc3709.txt
|
||||
#
|
||||
|
||||
from pyasn1.type import char
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import namedval
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc5280
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
|
||||
class HashAlgAndValue(univ.Sequence):
|
||||
pass
|
||||
|
||||
HashAlgAndValue.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('hashAlg', rfc5280.AlgorithmIdentifier()),
|
||||
namedtype.NamedType('hashValue', univ.OctetString())
|
||||
)
|
||||
|
||||
|
||||
class LogotypeDetails(univ.Sequence):
|
||||
pass
|
||||
|
||||
LogotypeDetails.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('mediaType', char.IA5String()),
|
||||
namedtype.NamedType('logotypeHash', univ.SequenceOf(
|
||||
componentType=HashAlgAndValue()).subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX))),
|
||||
namedtype.NamedType('logotypeURI', univ.SequenceOf(
|
||||
componentType=char.IA5String()).subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX)))
|
||||
)
|
||||
|
||||
|
||||
class LogotypeAudioInfo(univ.Sequence):
|
||||
pass
|
||||
|
||||
LogotypeAudioInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('fileSize', univ.Integer()),
|
||||
namedtype.NamedType('playTime', univ.Integer()),
|
||||
namedtype.NamedType('channels', univ.Integer()),
|
||||
namedtype.OptionalNamedType('sampleRate', univ.Integer().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 3))),
|
||||
namedtype.OptionalNamedType('language', char.IA5String().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 4)))
|
||||
)
|
||||
|
||||
|
||||
class LogotypeAudio(univ.Sequence):
|
||||
pass
|
||||
|
||||
LogotypeAudio.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('audioDetails', LogotypeDetails()),
|
||||
namedtype.OptionalNamedType('audioInfo', LogotypeAudioInfo())
|
||||
)
|
||||
|
||||
|
||||
class LogotypeImageType(univ.Integer):
|
||||
pass
|
||||
|
||||
LogotypeImageType.namedValues = namedval.NamedValues(
|
||||
('grayScale', 0),
|
||||
('color', 1)
|
||||
)
|
||||
|
||||
|
||||
class LogotypeImageResolution(univ.Choice):
|
||||
pass
|
||||
|
||||
LogotypeImageResolution.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('numBits',
|
||||
univ.Integer().subtype(implicitTag=tag.Tag(
|
||||
tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.NamedType('tableSize',
|
||||
univ.Integer().subtype(implicitTag=tag.Tag(
|
||||
tag.tagClassContext, tag.tagFormatSimple, 2)))
|
||||
)
|
||||
|
||||
|
||||
class LogotypeImageInfo(univ.Sequence):
|
||||
pass
|
||||
|
||||
LogotypeImageInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.DefaultedNamedType('type', LogotypeImageType().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext,
|
||||
tag.tagFormatSimple, 0)).subtype(value='color')),
|
||||
namedtype.NamedType('fileSize', univ.Integer()),
|
||||
namedtype.NamedType('xSize', univ.Integer()),
|
||||
namedtype.NamedType('ySize', univ.Integer()),
|
||||
namedtype.OptionalNamedType('resolution', LogotypeImageResolution()),
|
||||
namedtype.OptionalNamedType('language', char.IA5String().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 4)))
|
||||
)
|
||||
|
||||
|
||||
class LogotypeImage(univ.Sequence):
|
||||
pass
|
||||
|
||||
LogotypeImage.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('imageDetails', LogotypeDetails()),
|
||||
namedtype.OptionalNamedType('imageInfo', LogotypeImageInfo())
|
||||
)
|
||||
|
||||
|
||||
class LogotypeData(univ.Sequence):
|
||||
pass
|
||||
|
||||
LogotypeData.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('image', univ.SequenceOf(
|
||||
componentType=LogotypeImage())),
|
||||
namedtype.OptionalNamedType('audio', univ.SequenceOf(
|
||||
componentType=LogotypeAudio()).subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext,
|
||||
tag.tagFormatSimple, 1)))
|
||||
)
|
||||
|
||||
|
||||
class LogotypeReference(univ.Sequence):
|
||||
pass
|
||||
|
||||
LogotypeReference.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('refStructHash', univ.SequenceOf(
|
||||
componentType=HashAlgAndValue()).subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX))),
|
||||
namedtype.NamedType('refStructURI', univ.SequenceOf(
|
||||
componentType=char.IA5String()).subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX)))
|
||||
)
|
||||
|
||||
|
||||
class LogotypeInfo(univ.Choice):
|
||||
pass
|
||||
|
||||
LogotypeInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('direct',
|
||||
LogotypeData().subtype(implicitTag=tag.Tag(tag.tagClassContext,
|
||||
tag.tagFormatConstructed, 0))),
|
||||
namedtype.NamedType('indirect', LogotypeReference().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext,
|
||||
tag.tagFormatConstructed, 1)))
|
||||
)
|
||||
|
||||
# Other logotype type and associated object identifiers
|
||||
|
||||
id_logo_background = univ.ObjectIdentifier('1.3.6.1.5.5.7.20.2')
|
||||
|
||||
id_logo_loyalty = univ.ObjectIdentifier('1.3.6.1.5.5.7.20.1')
|
||||
|
||||
|
||||
class OtherLogotypeInfo(univ.Sequence):
|
||||
pass
|
||||
|
||||
OtherLogotypeInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('logotypeType', univ.ObjectIdentifier()),
|
||||
namedtype.NamedType('info', LogotypeInfo())
|
||||
)
|
||||
|
||||
|
||||
# Logotype Certificate Extension
|
||||
|
||||
id_pe_logotype = univ.ObjectIdentifier('1.3.6.1.5.5.7.1.12')
|
||||
|
||||
|
||||
class LogotypeExtn(univ.Sequence):
|
||||
pass
|
||||
|
||||
LogotypeExtn.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('communityLogos', univ.SequenceOf(
|
||||
componentType=LogotypeInfo()).subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.OptionalNamedType('issuerLogo', LogotypeInfo().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1))),
|
||||
namedtype.OptionalNamedType('subjectLogo', LogotypeInfo().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 2))),
|
||||
namedtype.OptionalNamedType('otherLogos', univ.SequenceOf(
|
||||
componentType=OtherLogotypeInfo()).subtype(explicitTag=tag.Tag(
|
||||
tag.tagClassContext, tag.tagFormatSimple, 3)))
|
||||
)
|
||||
|
||||
|
||||
# Map of Certificate Extension OIDs to Extensions added to the
|
||||
# ones that are in rfc5280.py
|
||||
|
||||
_certificateExtensionsMapUpdate = {
|
||||
id_pe_logotype: LogotypeExtn(),
|
||||
}
|
||||
|
||||
rfc5280.certificateExtensionsMap.update(_certificateExtensionsMapUpdate)
|
||||
@@ -0,0 +1,258 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley with a very small amount of assistance from
|
||||
# asn1ate v.0.6.0.
|
||||
# Modified by Russ Housley to add maps for opentypes.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# Additional Algorithms and Identifiers for RSA Cryptography
|
||||
# for use in Certificates and CRLs
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc4055.txt
|
||||
#
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc5280
|
||||
|
||||
|
||||
def _OID(*components):
|
||||
output = []
|
||||
for x in tuple(components):
|
||||
if isinstance(x, univ.ObjectIdentifier):
|
||||
output.extend(list(x))
|
||||
else:
|
||||
output.append(int(x))
|
||||
return univ.ObjectIdentifier(output)
|
||||
|
||||
|
||||
id_sha1 = _OID(1, 3, 14, 3, 2, 26)
|
||||
|
||||
id_sha256 = _OID(2, 16, 840, 1, 101, 3, 4, 2, 1)
|
||||
|
||||
id_sha384 = _OID(2, 16, 840, 1, 101, 3, 4, 2, 2)
|
||||
|
||||
id_sha512 = _OID(2, 16, 840, 1, 101, 3, 4, 2, 3)
|
||||
|
||||
id_sha224 = _OID(2, 16, 840, 1, 101, 3, 4, 2, 4)
|
||||
|
||||
rsaEncryption = _OID(1, 2, 840, 113549, 1, 1, 1)
|
||||
|
||||
id_mgf1 = _OID(1, 2, 840, 113549, 1, 1, 8)
|
||||
|
||||
id_RSAES_OAEP = _OID(1, 2, 840, 113549, 1, 1, 7)
|
||||
|
||||
id_pSpecified = _OID(1, 2, 840, 113549, 1, 1, 9)
|
||||
|
||||
id_RSASSA_PSS = _OID(1, 2, 840, 113549, 1, 1, 10)
|
||||
|
||||
sha256WithRSAEncryption = _OID(1, 2, 840, 113549, 1, 1, 11)
|
||||
|
||||
sha384WithRSAEncryption = _OID(1, 2, 840, 113549, 1, 1, 12)
|
||||
|
||||
sha512WithRSAEncryption = _OID(1, 2, 840, 113549, 1, 1, 13)
|
||||
|
||||
sha224WithRSAEncryption = _OID(1, 2, 840, 113549, 1, 1, 14)
|
||||
|
||||
sha1Identifier = rfc5280.AlgorithmIdentifier()
|
||||
sha1Identifier['algorithm'] = id_sha1
|
||||
sha1Identifier['parameters'] = univ.Null("")
|
||||
|
||||
sha224Identifier = rfc5280.AlgorithmIdentifier()
|
||||
sha224Identifier['algorithm'] = id_sha224
|
||||
sha224Identifier['parameters'] = univ.Null("")
|
||||
|
||||
sha256Identifier = rfc5280.AlgorithmIdentifier()
|
||||
sha256Identifier['algorithm'] = id_sha256
|
||||
sha256Identifier['parameters'] = univ.Null("")
|
||||
|
||||
sha384Identifier = rfc5280.AlgorithmIdentifier()
|
||||
sha384Identifier['algorithm'] = id_sha384
|
||||
sha384Identifier['parameters'] = univ.Null("")
|
||||
|
||||
sha512Identifier = rfc5280.AlgorithmIdentifier()
|
||||
sha512Identifier['algorithm'] = id_sha512
|
||||
sha512Identifier['parameters'] = univ.Null("")
|
||||
|
||||
mgf1SHA1Identifier = rfc5280.AlgorithmIdentifier()
|
||||
mgf1SHA1Identifier['algorithm'] = id_mgf1
|
||||
mgf1SHA1Identifier['parameters'] = sha1Identifier
|
||||
|
||||
mgf1SHA224Identifier = rfc5280.AlgorithmIdentifier()
|
||||
mgf1SHA224Identifier['algorithm'] = id_mgf1
|
||||
mgf1SHA224Identifier['parameters'] = sha224Identifier
|
||||
|
||||
mgf1SHA256Identifier = rfc5280.AlgorithmIdentifier()
|
||||
mgf1SHA256Identifier['algorithm'] = id_mgf1
|
||||
mgf1SHA256Identifier['parameters'] = sha256Identifier
|
||||
|
||||
mgf1SHA384Identifier = rfc5280.AlgorithmIdentifier()
|
||||
mgf1SHA384Identifier['algorithm'] = id_mgf1
|
||||
mgf1SHA384Identifier['parameters'] = sha384Identifier
|
||||
|
||||
mgf1SHA512Identifier = rfc5280.AlgorithmIdentifier()
|
||||
mgf1SHA512Identifier['algorithm'] = id_mgf1
|
||||
mgf1SHA512Identifier['parameters'] = sha512Identifier
|
||||
|
||||
pSpecifiedEmptyIdentifier = rfc5280.AlgorithmIdentifier()
|
||||
pSpecifiedEmptyIdentifier['algorithm'] = id_pSpecified
|
||||
pSpecifiedEmptyIdentifier['parameters'] = univ.OctetString(value='')
|
||||
|
||||
|
||||
class RSAPublicKey(univ.Sequence):
|
||||
pass
|
||||
|
||||
RSAPublicKey.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('modulus', univ.Integer()),
|
||||
namedtype.NamedType('publicExponent', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
class HashAlgorithm(rfc5280.AlgorithmIdentifier):
|
||||
pass
|
||||
|
||||
|
||||
class MaskGenAlgorithm(rfc5280.AlgorithmIdentifier):
|
||||
pass
|
||||
|
||||
|
||||
class RSAES_OAEP_params(univ.Sequence):
|
||||
pass
|
||||
|
||||
RSAES_OAEP_params.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('hashFunc', rfc5280.AlgorithmIdentifier().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.OptionalNamedType('maskGenFunc', rfc5280.AlgorithmIdentifier().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1))),
|
||||
namedtype.OptionalNamedType('pSourceFunc', rfc5280.AlgorithmIdentifier().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 2)))
|
||||
)
|
||||
|
||||
rSAES_OAEP_Default_Params = RSAES_OAEP_params()
|
||||
|
||||
rSAES_OAEP_Default_Identifier = rfc5280.AlgorithmIdentifier()
|
||||
rSAES_OAEP_Default_Identifier['algorithm'] = id_RSAES_OAEP
|
||||
rSAES_OAEP_Default_Identifier['parameters'] = rSAES_OAEP_Default_Params
|
||||
|
||||
rSAES_OAEP_SHA224_Params = RSAES_OAEP_params()
|
||||
rSAES_OAEP_SHA224_Params['hashFunc'] = sha224Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0), cloneValueFlag=True)
|
||||
rSAES_OAEP_SHA224_Params['maskGenFunc'] = mgf1SHA224Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1), cloneValueFlag=True)
|
||||
|
||||
rSAES_OAEP_SHA224_Identifier = rfc5280.AlgorithmIdentifier()
|
||||
rSAES_OAEP_SHA224_Identifier['algorithm'] = id_RSAES_OAEP
|
||||
rSAES_OAEP_SHA224_Identifier['parameters'] = rSAES_OAEP_SHA224_Params
|
||||
|
||||
rSAES_OAEP_SHA256_Params = RSAES_OAEP_params()
|
||||
rSAES_OAEP_SHA256_Params['hashFunc'] = sha256Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0), cloneValueFlag=True)
|
||||
rSAES_OAEP_SHA256_Params['maskGenFunc'] = mgf1SHA256Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1), cloneValueFlag=True)
|
||||
|
||||
rSAES_OAEP_SHA256_Identifier = rfc5280.AlgorithmIdentifier()
|
||||
rSAES_OAEP_SHA256_Identifier['algorithm'] = id_RSAES_OAEP
|
||||
rSAES_OAEP_SHA256_Identifier['parameters'] = rSAES_OAEP_SHA256_Params
|
||||
|
||||
rSAES_OAEP_SHA384_Params = RSAES_OAEP_params()
|
||||
rSAES_OAEP_SHA384_Params['hashFunc'] = sha384Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0), cloneValueFlag=True)
|
||||
rSAES_OAEP_SHA384_Params['maskGenFunc'] = mgf1SHA384Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1), cloneValueFlag=True)
|
||||
|
||||
rSAES_OAEP_SHA384_Identifier = rfc5280.AlgorithmIdentifier()
|
||||
rSAES_OAEP_SHA384_Identifier['algorithm'] = id_RSAES_OAEP
|
||||
rSAES_OAEP_SHA384_Identifier['parameters'] = rSAES_OAEP_SHA384_Params
|
||||
|
||||
rSAES_OAEP_SHA512_Params = RSAES_OAEP_params()
|
||||
rSAES_OAEP_SHA512_Params['hashFunc'] = sha512Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0), cloneValueFlag=True)
|
||||
rSAES_OAEP_SHA512_Params['maskGenFunc'] = mgf1SHA512Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1), cloneValueFlag=True)
|
||||
|
||||
rSAES_OAEP_SHA512_Identifier = rfc5280.AlgorithmIdentifier()
|
||||
rSAES_OAEP_SHA512_Identifier['algorithm'] = id_RSAES_OAEP
|
||||
rSAES_OAEP_SHA512_Identifier['parameters'] = rSAES_OAEP_SHA512_Params
|
||||
|
||||
|
||||
class RSASSA_PSS_params(univ.Sequence):
|
||||
pass
|
||||
|
||||
RSASSA_PSS_params.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('hashAlgorithm', rfc5280.AlgorithmIdentifier().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.OptionalNamedType('maskGenAlgorithm', rfc5280.AlgorithmIdentifier().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1))),
|
||||
namedtype.DefaultedNamedType('saltLength', univ.Integer(value=20).subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2))),
|
||||
namedtype.DefaultedNamedType('trailerField', univ.Integer(value=1).subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 3)))
|
||||
)
|
||||
|
||||
rSASSA_PSS_Default_Params = RSASSA_PSS_params()
|
||||
|
||||
rSASSA_PSS_Default_Identifier = rfc5280.AlgorithmIdentifier()
|
||||
rSASSA_PSS_Default_Identifier['algorithm'] = id_RSASSA_PSS
|
||||
rSASSA_PSS_Default_Identifier['parameters'] = rSASSA_PSS_Default_Params
|
||||
|
||||
rSASSA_PSS_SHA224_Params = RSASSA_PSS_params()
|
||||
rSASSA_PSS_SHA224_Params['hashAlgorithm'] = sha224Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0), cloneValueFlag=True)
|
||||
rSASSA_PSS_SHA224_Params['maskGenAlgorithm'] = mgf1SHA224Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1), cloneValueFlag=True)
|
||||
|
||||
rSASSA_PSS_SHA224_Identifier = rfc5280.AlgorithmIdentifier()
|
||||
rSASSA_PSS_SHA224_Identifier['algorithm'] = id_RSASSA_PSS
|
||||
rSASSA_PSS_SHA224_Identifier['parameters'] = rSASSA_PSS_SHA224_Params
|
||||
|
||||
rSASSA_PSS_SHA256_Params = RSASSA_PSS_params()
|
||||
rSASSA_PSS_SHA256_Params['hashAlgorithm'] = sha256Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0), cloneValueFlag=True)
|
||||
rSASSA_PSS_SHA256_Params['maskGenAlgorithm'] = mgf1SHA256Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1), cloneValueFlag=True)
|
||||
|
||||
rSASSA_PSS_SHA256_Identifier = rfc5280.AlgorithmIdentifier()
|
||||
rSASSA_PSS_SHA256_Identifier['algorithm'] = id_RSASSA_PSS
|
||||
rSASSA_PSS_SHA256_Identifier['parameters'] = rSASSA_PSS_SHA256_Params
|
||||
|
||||
rSASSA_PSS_SHA384_Params = RSASSA_PSS_params()
|
||||
rSASSA_PSS_SHA384_Params['hashAlgorithm'] = sha384Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0), cloneValueFlag=True)
|
||||
rSASSA_PSS_SHA384_Params['maskGenAlgorithm'] = mgf1SHA384Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1), cloneValueFlag=True)
|
||||
|
||||
rSASSA_PSS_SHA384_Identifier = rfc5280.AlgorithmIdentifier()
|
||||
rSASSA_PSS_SHA384_Identifier['algorithm'] = id_RSASSA_PSS
|
||||
rSASSA_PSS_SHA384_Identifier['parameters'] = rSASSA_PSS_SHA384_Params
|
||||
|
||||
rSASSA_PSS_SHA512_Params = RSASSA_PSS_params()
|
||||
rSASSA_PSS_SHA512_Params['hashAlgorithm'] = sha512Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0), cloneValueFlag=True)
|
||||
rSASSA_PSS_SHA512_Params['maskGenAlgorithm'] = mgf1SHA512Identifier.subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1), cloneValueFlag=True)
|
||||
|
||||
rSASSA_PSS_SHA512_Identifier = rfc5280.AlgorithmIdentifier()
|
||||
rSASSA_PSS_SHA512_Identifier['algorithm'] = id_RSASSA_PSS
|
||||
rSASSA_PSS_SHA512_Identifier['parameters'] = rSASSA_PSS_SHA512_Params
|
||||
|
||||
|
||||
# Update the Algorithm Identifier map
|
||||
|
||||
_algorithmIdentifierMapUpdate = {
|
||||
id_sha1: univ.Null(),
|
||||
id_sha224: univ.Null(),
|
||||
id_sha256: univ.Null(),
|
||||
id_sha384: univ.Null(),
|
||||
id_sha512: univ.Null(),
|
||||
id_mgf1: rfc5280.AlgorithmIdentifier(),
|
||||
id_pSpecified: univ.OctetString(),
|
||||
id_RSAES_OAEP: RSAES_OAEP_params(),
|
||||
id_RSASSA_PSS: RSASSA_PSS_params(),
|
||||
}
|
||||
|
||||
rfc5280.algorithmIdentifierMap.update(_algorithmIdentifierMapUpdate)
|
||||
@@ -0,0 +1,59 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley with some assistance from asn1ate v.0.6.0.
|
||||
# Modified by Russ Housley to add a map for use with opentypes.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# Protecting Multiple Contents with the CMS
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc4073.txt
|
||||
#
|
||||
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc5652
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
|
||||
# Content Collection Content Type and Object Identifier
|
||||
|
||||
id_ct_contentCollection = univ.ObjectIdentifier('1.2.840.113549.1.9.16.1.19')
|
||||
|
||||
class ContentCollection(univ.SequenceOf):
|
||||
pass
|
||||
|
||||
ContentCollection.componentType = rfc5652.ContentInfo()
|
||||
ContentCollection.sizeSpec = constraint.ValueSizeConstraint(1, MAX)
|
||||
|
||||
|
||||
# Content With Attributes Content Type and Object Identifier
|
||||
|
||||
id_ct_contentWithAttrs = univ.ObjectIdentifier('1.2.840.113549.1.9.16.1.20')
|
||||
|
||||
class ContentWithAttributes(univ.Sequence):
|
||||
pass
|
||||
|
||||
ContentWithAttributes.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('content', rfc5652.ContentInfo()),
|
||||
namedtype.NamedType('attrs', univ.SequenceOf(
|
||||
componentType=rfc5652.Attribute()).subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX)))
|
||||
)
|
||||
|
||||
|
||||
# Map of Content Type OIDs to Content Types is added to the
|
||||
# ones that are in rfc5652.py
|
||||
|
||||
_cmsContentTypesMapUpdate = {
|
||||
id_ct_contentCollection: ContentCollection(),
|
||||
id_ct_contentWithAttrs: ContentWithAttributes(),
|
||||
}
|
||||
|
||||
rfc5652.cmsContentTypesMap.update(_cmsContentTypesMapUpdate)
|
||||
@@ -0,0 +1,803 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Copyright (c) 2005-2019, Ilya Etingof <etingof@gmail.com>
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# Certificate Management Protocol structures as per RFC4210
|
||||
#
|
||||
# Based on Alex Railean's work
|
||||
#
|
||||
from pyasn1.type import char
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import namedval
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
from pyasn1.type import useful
|
||||
|
||||
from pyasn1_modules import rfc2314
|
||||
from pyasn1_modules import rfc2459
|
||||
from pyasn1_modules import rfc2511
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
|
||||
class KeyIdentifier(univ.OctetString):
|
||||
pass
|
||||
|
||||
|
||||
class CMPCertificate(rfc2459.Certificate):
|
||||
pass
|
||||
|
||||
|
||||
class OOBCert(CMPCertificate):
|
||||
pass
|
||||
|
||||
|
||||
class CertAnnContent(CMPCertificate):
|
||||
pass
|
||||
|
||||
|
||||
class PKIFreeText(univ.SequenceOf):
|
||||
"""
|
||||
PKIFreeText ::= SEQUENCE SIZE (1..MAX) OF UTF8String
|
||||
"""
|
||||
componentType = char.UTF8String()
|
||||
sizeSpec = univ.SequenceOf.sizeSpec + constraint.ValueSizeConstraint(1, MAX)
|
||||
|
||||
|
||||
class PollRepContent(univ.SequenceOf):
|
||||
"""
|
||||
PollRepContent ::= SEQUENCE OF SEQUENCE {
|
||||
certReqId INTEGER,
|
||||
checkAfter INTEGER, -- time in seconds
|
||||
reason PKIFreeText OPTIONAL
|
||||
}
|
||||
"""
|
||||
|
||||
class CertReq(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certReqId', univ.Integer()),
|
||||
namedtype.NamedType('checkAfter', univ.Integer()),
|
||||
namedtype.OptionalNamedType('reason', PKIFreeText())
|
||||
)
|
||||
|
||||
componentType = CertReq()
|
||||
|
||||
|
||||
class PollReqContent(univ.SequenceOf):
|
||||
"""
|
||||
PollReqContent ::= SEQUENCE OF SEQUENCE {
|
||||
certReqId INTEGER
|
||||
}
|
||||
|
||||
"""
|
||||
|
||||
class CertReq(univ.Sequence):
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certReqId', univ.Integer())
|
||||
)
|
||||
|
||||
componentType = CertReq()
|
||||
|
||||
|
||||
class InfoTypeAndValue(univ.Sequence):
|
||||
"""
|
||||
InfoTypeAndValue ::= SEQUENCE {
|
||||
infoType OBJECT IDENTIFIER,
|
||||
infoValue ANY DEFINED BY infoType OPTIONAL
|
||||
}"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('infoType', univ.ObjectIdentifier()),
|
||||
namedtype.OptionalNamedType('infoValue', univ.Any())
|
||||
)
|
||||
|
||||
|
||||
class GenRepContent(univ.SequenceOf):
|
||||
componentType = InfoTypeAndValue()
|
||||
|
||||
|
||||
class GenMsgContent(univ.SequenceOf):
|
||||
componentType = InfoTypeAndValue()
|
||||
|
||||
|
||||
class PKIConfirmContent(univ.Null):
|
||||
pass
|
||||
|
||||
|
||||
class CRLAnnContent(univ.SequenceOf):
|
||||
componentType = rfc2459.CertificateList()
|
||||
|
||||
|
||||
class CAKeyUpdAnnContent(univ.Sequence):
|
||||
"""
|
||||
CAKeyUpdAnnContent ::= SEQUENCE {
|
||||
oldWithNew CMPCertificate,
|
||||
newWithOld CMPCertificate,
|
||||
newWithNew CMPCertificate
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('oldWithNew', CMPCertificate()),
|
||||
namedtype.NamedType('newWithOld', CMPCertificate()),
|
||||
namedtype.NamedType('newWithNew', CMPCertificate())
|
||||
)
|
||||
|
||||
|
||||
class RevDetails(univ.Sequence):
|
||||
"""
|
||||
RevDetails ::= SEQUENCE {
|
||||
certDetails CertTemplate,
|
||||
crlEntryDetails Extensions OPTIONAL
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certDetails', rfc2511.CertTemplate()),
|
||||
namedtype.OptionalNamedType('crlEntryDetails', rfc2459.Extensions())
|
||||
)
|
||||
|
||||
|
||||
class RevReqContent(univ.SequenceOf):
|
||||
componentType = RevDetails()
|
||||
|
||||
|
||||
class CertOrEncCert(univ.Choice):
|
||||
"""
|
||||
CertOrEncCert ::= CHOICE {
|
||||
certificate [0] CMPCertificate,
|
||||
encryptedCert [1] EncryptedValue
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certificate', CMPCertificate().subtype(explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.NamedType('encryptedCert', rfc2511.EncryptedValue().subtype(explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1)))
|
||||
)
|
||||
|
||||
|
||||
class CertifiedKeyPair(univ.Sequence):
|
||||
"""
|
||||
CertifiedKeyPair ::= SEQUENCE {
|
||||
certOrEncCert CertOrEncCert,
|
||||
privateKey [0] EncryptedValue OPTIONAL,
|
||||
publicationInfo [1] PKIPublicationInfo OPTIONAL
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certOrEncCert', CertOrEncCert()),
|
||||
namedtype.OptionalNamedType('privateKey', rfc2511.EncryptedValue().subtype(explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.OptionalNamedType('publicationInfo', rfc2511.PKIPublicationInfo().subtype(explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1)))
|
||||
)
|
||||
|
||||
|
||||
class POPODecKeyRespContent(univ.SequenceOf):
|
||||
componentType = univ.Integer()
|
||||
|
||||
|
||||
class Challenge(univ.Sequence):
|
||||
"""
|
||||
Challenge ::= SEQUENCE {
|
||||
owf AlgorithmIdentifier OPTIONAL,
|
||||
witness OCTET STRING,
|
||||
challenge OCTET STRING
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('owf', rfc2459.AlgorithmIdentifier()),
|
||||
namedtype.NamedType('witness', univ.OctetString()),
|
||||
namedtype.NamedType('challenge', univ.OctetString())
|
||||
)
|
||||
|
||||
|
||||
class PKIStatus(univ.Integer):
|
||||
"""
|
||||
PKIStatus ::= INTEGER {
|
||||
accepted (0),
|
||||
grantedWithMods (1),
|
||||
rejection (2),
|
||||
waiting (3),
|
||||
revocationWarning (4),
|
||||
revocationNotification (5),
|
||||
keyUpdateWarning (6)
|
||||
}
|
||||
"""
|
||||
namedValues = namedval.NamedValues(
|
||||
('accepted', 0),
|
||||
('grantedWithMods', 1),
|
||||
('rejection', 2),
|
||||
('waiting', 3),
|
||||
('revocationWarning', 4),
|
||||
('revocationNotification', 5),
|
||||
('keyUpdateWarning', 6)
|
||||
)
|
||||
|
||||
|
||||
class PKIFailureInfo(univ.BitString):
|
||||
"""
|
||||
PKIFailureInfo ::= BIT STRING {
|
||||
badAlg (0),
|
||||
badMessageCheck (1),
|
||||
badRequest (2),
|
||||
badTime (3),
|
||||
badCertId (4),
|
||||
badDataFormat (5),
|
||||
wrongAuthority (6),
|
||||
incorrectData (7),
|
||||
missingTimeStamp (8),
|
||||
badPOP (9),
|
||||
certRevoked (10),
|
||||
certConfirmed (11),
|
||||
wrongIntegrity (12),
|
||||
badRecipientNonce (13),
|
||||
timeNotAvailable (14),
|
||||
unacceptedPolicy (15),
|
||||
unacceptedExtension (16),
|
||||
addInfoNotAvailable (17),
|
||||
badSenderNonce (18),
|
||||
badCertTemplate (19),
|
||||
signerNotTrusted (20),
|
||||
transactionIdInUse (21),
|
||||
unsupportedVersion (22),
|
||||
notAuthorized (23),
|
||||
systemUnavail (24),
|
||||
systemFailure (25),
|
||||
duplicateCertReq (26)
|
||||
"""
|
||||
namedValues = namedval.NamedValues(
|
||||
('badAlg', 0),
|
||||
('badMessageCheck', 1),
|
||||
('badRequest', 2),
|
||||
('badTime', 3),
|
||||
('badCertId', 4),
|
||||
('badDataFormat', 5),
|
||||
('wrongAuthority', 6),
|
||||
('incorrectData', 7),
|
||||
('missingTimeStamp', 8),
|
||||
('badPOP', 9),
|
||||
('certRevoked', 10),
|
||||
('certConfirmed', 11),
|
||||
('wrongIntegrity', 12),
|
||||
('badRecipientNonce', 13),
|
||||
('timeNotAvailable', 14),
|
||||
('unacceptedPolicy', 15),
|
||||
('unacceptedExtension', 16),
|
||||
('addInfoNotAvailable', 17),
|
||||
('badSenderNonce', 18),
|
||||
('badCertTemplate', 19),
|
||||
('signerNotTrusted', 20),
|
||||
('transactionIdInUse', 21),
|
||||
('unsupportedVersion', 22),
|
||||
('notAuthorized', 23),
|
||||
('systemUnavail', 24),
|
||||
('systemFailure', 25),
|
||||
('duplicateCertReq', 26)
|
||||
)
|
||||
|
||||
|
||||
class PKIStatusInfo(univ.Sequence):
|
||||
"""
|
||||
PKIStatusInfo ::= SEQUENCE {
|
||||
status PKIStatus,
|
||||
statusString PKIFreeText OPTIONAL,
|
||||
failInfo PKIFailureInfo OPTIONAL
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('status', PKIStatus()),
|
||||
namedtype.OptionalNamedType('statusString', PKIFreeText()),
|
||||
namedtype.OptionalNamedType('failInfo', PKIFailureInfo())
|
||||
)
|
||||
|
||||
|
||||
class ErrorMsgContent(univ.Sequence):
|
||||
"""
|
||||
ErrorMsgContent ::= SEQUENCE {
|
||||
pKIStatusInfo PKIStatusInfo,
|
||||
errorCode INTEGER OPTIONAL,
|
||||
-- implementation-specific error codes
|
||||
errorDetails PKIFreeText OPTIONAL
|
||||
-- implementation-specific error details
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('pKIStatusInfo', PKIStatusInfo()),
|
||||
namedtype.OptionalNamedType('errorCode', univ.Integer()),
|
||||
namedtype.OptionalNamedType('errorDetails', PKIFreeText())
|
||||
)
|
||||
|
||||
|
||||
class CertStatus(univ.Sequence):
|
||||
"""
|
||||
CertStatus ::= SEQUENCE {
|
||||
certHash OCTET STRING,
|
||||
certReqId INTEGER,
|
||||
statusInfo PKIStatusInfo OPTIONAL
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certHash', univ.OctetString()),
|
||||
namedtype.NamedType('certReqId', univ.Integer()),
|
||||
namedtype.OptionalNamedType('statusInfo', PKIStatusInfo())
|
||||
)
|
||||
|
||||
|
||||
class CertConfirmContent(univ.SequenceOf):
|
||||
componentType = CertStatus()
|
||||
|
||||
|
||||
class RevAnnContent(univ.Sequence):
|
||||
"""
|
||||
RevAnnContent ::= SEQUENCE {
|
||||
status PKIStatus,
|
||||
certId CertId,
|
||||
willBeRevokedAt GeneralizedTime,
|
||||
badSinceDate GeneralizedTime,
|
||||
crlDetails Extensions OPTIONAL
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('status', PKIStatus()),
|
||||
namedtype.NamedType('certId', rfc2511.CertId()),
|
||||
namedtype.NamedType('willBeRevokedAt', useful.GeneralizedTime()),
|
||||
namedtype.NamedType('badSinceDate', useful.GeneralizedTime()),
|
||||
namedtype.OptionalNamedType('crlDetails', rfc2459.Extensions())
|
||||
)
|
||||
|
||||
|
||||
class RevRepContent(univ.Sequence):
|
||||
"""
|
||||
RevRepContent ::= SEQUENCE {
|
||||
status SEQUENCE SIZE (1..MAX) OF PKIStatusInfo,
|
||||
revCerts [0] SEQUENCE SIZE (1..MAX) OF CertId
|
||||
OPTIONAL,
|
||||
crls [1] SEQUENCE SIZE (1..MAX) OF CertificateList
|
||||
OPTIONAL
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType(
|
||||
'status', univ.SequenceOf(
|
||||
componentType=PKIStatusInfo(),
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX)
|
||||
)
|
||||
),
|
||||
namedtype.OptionalNamedType(
|
||||
'revCerts', univ.SequenceOf(componentType=rfc2511.CertId()).subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX),
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0)
|
||||
)
|
||||
),
|
||||
namedtype.OptionalNamedType(
|
||||
'crls', univ.SequenceOf(componentType=rfc2459.CertificateList()).subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX),
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1)
|
||||
)
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
class KeyRecRepContent(univ.Sequence):
|
||||
"""
|
||||
KeyRecRepContent ::= SEQUENCE {
|
||||
status PKIStatusInfo,
|
||||
newSigCert [0] CMPCertificate OPTIONAL,
|
||||
caCerts [1] SEQUENCE SIZE (1..MAX) OF
|
||||
CMPCertificate OPTIONAL,
|
||||
keyPairHist [2] SEQUENCE SIZE (1..MAX) OF
|
||||
CertifiedKeyPair OPTIONAL
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('status', PKIStatusInfo()),
|
||||
namedtype.OptionalNamedType(
|
||||
'newSigCert', CMPCertificate().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0)
|
||||
)
|
||||
),
|
||||
namedtype.OptionalNamedType(
|
||||
'caCerts', univ.SequenceOf(componentType=CMPCertificate()).subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1),
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX)
|
||||
)
|
||||
),
|
||||
namedtype.OptionalNamedType('keyPairHist', univ.SequenceOf(componentType=CertifiedKeyPair()).subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 2),
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX))
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
class CertResponse(univ.Sequence):
|
||||
"""
|
||||
CertResponse ::= SEQUENCE {
|
||||
certReqId INTEGER,
|
||||
status PKIStatusInfo,
|
||||
certifiedKeyPair CertifiedKeyPair OPTIONAL,
|
||||
rspInfo OCTET STRING OPTIONAL
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certReqId', univ.Integer()),
|
||||
namedtype.NamedType('status', PKIStatusInfo()),
|
||||
namedtype.OptionalNamedType('certifiedKeyPair', CertifiedKeyPair()),
|
||||
namedtype.OptionalNamedType('rspInfo', univ.OctetString())
|
||||
)
|
||||
|
||||
|
||||
class CertRepMessage(univ.Sequence):
|
||||
"""
|
||||
CertRepMessage ::= SEQUENCE {
|
||||
caPubs [1] SEQUENCE SIZE (1..MAX) OF CMPCertificate
|
||||
OPTIONAL,
|
||||
response SEQUENCE OF CertResponse
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType(
|
||||
'caPubs', univ.SequenceOf(
|
||||
componentType=CMPCertificate()
|
||||
).subtype(sizeSpec=constraint.ValueSizeConstraint(1, MAX),
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1))
|
||||
),
|
||||
namedtype.NamedType('response', univ.SequenceOf(componentType=CertResponse()))
|
||||
)
|
||||
|
||||
|
||||
class POPODecKeyChallContent(univ.SequenceOf):
|
||||
componentType = Challenge()
|
||||
|
||||
|
||||
class OOBCertHash(univ.Sequence):
|
||||
"""
|
||||
OOBCertHash ::= SEQUENCE {
|
||||
hashAlg [0] AlgorithmIdentifier OPTIONAL,
|
||||
certId [1] CertId OPTIONAL,
|
||||
hashVal BIT STRING
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType(
|
||||
'hashAlg', rfc2459.AlgorithmIdentifier().subtype(explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))
|
||||
),
|
||||
namedtype.OptionalNamedType(
|
||||
'certId', rfc2511.CertId().subtype(explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1))
|
||||
),
|
||||
namedtype.NamedType('hashVal', univ.BitString())
|
||||
)
|
||||
|
||||
|
||||
# pyasn1 does not naturally handle recursive definitions, thus this hack:
|
||||
# NestedMessageContent ::= PKIMessages
|
||||
class NestedMessageContent(univ.SequenceOf):
|
||||
"""
|
||||
NestedMessageContent ::= PKIMessages
|
||||
"""
|
||||
componentType = univ.Any()
|
||||
|
||||
|
||||
class DHBMParameter(univ.Sequence):
|
||||
"""
|
||||
DHBMParameter ::= SEQUENCE {
|
||||
owf AlgorithmIdentifier,
|
||||
-- AlgId for a One-Way Function (SHA-1 recommended)
|
||||
mac AlgorithmIdentifier
|
||||
-- the MAC AlgId (e.g., DES-MAC, Triple-DES-MAC [PKCS11],
|
||||
} -- or HMAC [RFC2104, RFC2202])
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('owf', rfc2459.AlgorithmIdentifier()),
|
||||
namedtype.NamedType('mac', rfc2459.AlgorithmIdentifier())
|
||||
)
|
||||
|
||||
|
||||
id_DHBasedMac = univ.ObjectIdentifier('1.2.840.113533.7.66.30')
|
||||
|
||||
|
||||
class PBMParameter(univ.Sequence):
|
||||
"""
|
||||
PBMParameter ::= SEQUENCE {
|
||||
salt OCTET STRING,
|
||||
owf AlgorithmIdentifier,
|
||||
iterationCount INTEGER,
|
||||
mac AlgorithmIdentifier
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType(
|
||||
'salt', univ.OctetString().subtype(subtypeSpec=constraint.ValueSizeConstraint(0, 128))
|
||||
),
|
||||
namedtype.NamedType('owf', rfc2459.AlgorithmIdentifier()),
|
||||
namedtype.NamedType('iterationCount', univ.Integer()),
|
||||
namedtype.NamedType('mac', rfc2459.AlgorithmIdentifier())
|
||||
)
|
||||
|
||||
|
||||
id_PasswordBasedMac = univ.ObjectIdentifier('1.2.840.113533.7.66.13')
|
||||
|
||||
|
||||
class PKIProtection(univ.BitString):
|
||||
pass
|
||||
|
||||
|
||||
# pyasn1 does not naturally handle recursive definitions, thus this hack:
|
||||
# NestedMessageContent ::= PKIMessages
|
||||
nestedMessageContent = NestedMessageContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 20))
|
||||
|
||||
|
||||
class PKIBody(univ.Choice):
|
||||
"""
|
||||
PKIBody ::= CHOICE { -- message-specific body elements
|
||||
ir [0] CertReqMessages, --Initialization Request
|
||||
ip [1] CertRepMessage, --Initialization Response
|
||||
cr [2] CertReqMessages, --Certification Request
|
||||
cp [3] CertRepMessage, --Certification Response
|
||||
p10cr [4] CertificationRequest, --imported from [PKCS10]
|
||||
popdecc [5] POPODecKeyChallContent, --pop Challenge
|
||||
popdecr [6] POPODecKeyRespContent, --pop Response
|
||||
kur [7] CertReqMessages, --Key Update Request
|
||||
kup [8] CertRepMessage, --Key Update Response
|
||||
krr [9] CertReqMessages, --Key Recovery Request
|
||||
krp [10] KeyRecRepContent, --Key Recovery Response
|
||||
rr [11] RevReqContent, --Revocation Request
|
||||
rp [12] RevRepContent, --Revocation Response
|
||||
ccr [13] CertReqMessages, --Cross-Cert. Request
|
||||
ccp [14] CertRepMessage, --Cross-Cert. Response
|
||||
ckuann [15] CAKeyUpdAnnContent, --CA Key Update Ann.
|
||||
cann [16] CertAnnContent, --Certificate Ann.
|
||||
rann [17] RevAnnContent, --Revocation Ann.
|
||||
crlann [18] CRLAnnContent, --CRL Announcement
|
||||
pkiconf [19] PKIConfirmContent, --Confirmation
|
||||
nested [20] NestedMessageContent, --Nested Message
|
||||
genm [21] GenMsgContent, --General Message
|
||||
genp [22] GenRepContent, --General Response
|
||||
error [23] ErrorMsgContent, --Error Message
|
||||
certConf [24] CertConfirmContent, --Certificate confirm
|
||||
pollReq [25] PollReqContent, --Polling request
|
||||
pollRep [26] PollRepContent --Polling response
|
||||
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType(
|
||||
'ir', rfc2511.CertReqMessages().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'ip', CertRepMessage().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'cr', rfc2511.CertReqMessages().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 2)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'cp', CertRepMessage().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 3)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'p10cr', rfc2314.CertificationRequest().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 4)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'popdecc', POPODecKeyChallContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 5)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'popdecr', POPODecKeyRespContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 6)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'kur', rfc2511.CertReqMessages().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 7)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'kup', CertRepMessage().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 8)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'krr', rfc2511.CertReqMessages().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 9)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'krp', KeyRecRepContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 10)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'rr', RevReqContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 11)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'rp', RevRepContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 12)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'ccr', rfc2511.CertReqMessages().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 13)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'ccp', CertRepMessage().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 14)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'ckuann', CAKeyUpdAnnContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 15)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'cann', CertAnnContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 16)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'rann', RevAnnContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 17)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'crlann', CRLAnnContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 18)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'pkiconf', PKIConfirmContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 19)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'nested', nestedMessageContent
|
||||
),
|
||||
# namedtype.NamedType('nested', NestedMessageContent().subtype(
|
||||
# explicitTag=tag.Tag(tag.tagClassContext,tag.tagFormatConstructed,20)
|
||||
# )
|
||||
# ),
|
||||
namedtype.NamedType(
|
||||
'genm', GenMsgContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 21)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'gen', GenRepContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 22)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'error', ErrorMsgContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 23)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'certConf', CertConfirmContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 24)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'pollReq', PollReqContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 25)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'pollRep', PollRepContent().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 26)
|
||||
)
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
class PKIHeader(univ.Sequence):
|
||||
"""
|
||||
PKIHeader ::= SEQUENCE {
|
||||
pvno INTEGER { cmp1999(1), cmp2000(2) },
|
||||
sender GeneralName,
|
||||
recipient GeneralName,
|
||||
messageTime [0] GeneralizedTime OPTIONAL,
|
||||
protectionAlg [1] AlgorithmIdentifier OPTIONAL,
|
||||
senderKID [2] KeyIdentifier OPTIONAL,
|
||||
recipKID [3] KeyIdentifier OPTIONAL,
|
||||
transactionID [4] OCTET STRING OPTIONAL,
|
||||
senderNonce [5] OCTET STRING OPTIONAL,
|
||||
recipNonce [6] OCTET STRING OPTIONAL,
|
||||
freeText [7] PKIFreeText OPTIONAL,
|
||||
generalInfo [8] SEQUENCE SIZE (1..MAX) OF
|
||||
InfoTypeAndValue OPTIONAL
|
||||
}
|
||||
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType(
|
||||
'pvno', univ.Integer(
|
||||
namedValues=namedval.NamedValues(('cmp1999', 1), ('cmp2000', 2))
|
||||
)
|
||||
),
|
||||
namedtype.NamedType('sender', rfc2459.GeneralName()),
|
||||
namedtype.NamedType('recipient', rfc2459.GeneralName()),
|
||||
namedtype.OptionalNamedType('messageTime', useful.GeneralizedTime().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.OptionalNamedType('protectionAlg', rfc2459.AlgorithmIdentifier().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1))),
|
||||
namedtype.OptionalNamedType('senderKID', rfc2459.KeyIdentifier().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2))),
|
||||
namedtype.OptionalNamedType('recipKID', rfc2459.KeyIdentifier().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 3))),
|
||||
namedtype.OptionalNamedType('transactionID', univ.OctetString().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 4))),
|
||||
namedtype.OptionalNamedType('senderNonce', univ.OctetString().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 5))),
|
||||
namedtype.OptionalNamedType('recipNonce', univ.OctetString().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 6))),
|
||||
namedtype.OptionalNamedType('freeText', PKIFreeText().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 7))),
|
||||
namedtype.OptionalNamedType('generalInfo',
|
||||
univ.SequenceOf(
|
||||
componentType=InfoTypeAndValue().subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX),
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 8)
|
||||
)
|
||||
)
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
class ProtectedPart(univ.Sequence):
|
||||
"""
|
||||
ProtectedPart ::= SEQUENCE {
|
||||
header PKIHeader,
|
||||
body PKIBody
|
||||
}
|
||||
"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('header', PKIHeader()),
|
||||
namedtype.NamedType('infoValue', PKIBody())
|
||||
)
|
||||
|
||||
|
||||
class PKIMessage(univ.Sequence):
|
||||
"""
|
||||
PKIMessage ::= SEQUENCE {
|
||||
header PKIHeader,
|
||||
body PKIBody,
|
||||
protection [0] PKIProtection OPTIONAL,
|
||||
extraCerts [1] SEQUENCE SIZE (1..MAX) OF CMPCertificate
|
||||
OPTIONAL
|
||||
}"""
|
||||
componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('header', PKIHeader()),
|
||||
namedtype.NamedType('body', PKIBody()),
|
||||
namedtype.OptionalNamedType('protection', PKIProtection().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.OptionalNamedType('extraCerts',
|
||||
univ.SequenceOf(
|
||||
componentType=CMPCertificate()
|
||||
).subtype(
|
||||
sizeSpec=constraint.ValueSizeConstraint(1, MAX),
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1)
|
||||
)
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
class PKIMessages(univ.SequenceOf):
|
||||
"""
|
||||
PKIMessages ::= SEQUENCE SIZE (1..MAX) OF PKIMessage
|
||||
"""
|
||||
componentType = PKIMessage()
|
||||
sizeSpec = univ.SequenceOf.sizeSpec + constraint.ValueSizeConstraint(1, MAX)
|
||||
|
||||
|
||||
# pyasn1 does not naturally handle recursive definitions, thus this hack:
|
||||
# NestedMessageContent ::= PKIMessages
|
||||
NestedMessageContent._componentType = PKIMessages()
|
||||
nestedMessageContent._componentType = PKIMessages()
|
||||
@@ -0,0 +1,396 @@
|
||||
# coding: utf-8
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Stanisław Pitucha with asn1ate tool.
|
||||
# Copyright (c) 2005-2019, Ilya Etingof <etingof@gmail.com>
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# Internet X.509 Public Key Infrastructure Certificate Request
|
||||
# Message Format (CRMF)
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# http://www.ietf.org/rfc/rfc4211.txt
|
||||
#
|
||||
from pyasn1.type import char
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import namedval
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc3280
|
||||
from pyasn1_modules import rfc3852
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
|
||||
def _buildOid(*components):
|
||||
output = []
|
||||
for x in tuple(components):
|
||||
if isinstance(x, univ.ObjectIdentifier):
|
||||
output.extend(list(x))
|
||||
else:
|
||||
output.append(int(x))
|
||||
|
||||
return univ.ObjectIdentifier(output)
|
||||
|
||||
|
||||
id_pkix = _buildOid(1, 3, 6, 1, 5, 5, 7)
|
||||
|
||||
id_pkip = _buildOid(id_pkix, 5)
|
||||
|
||||
id_regCtrl = _buildOid(id_pkip, 1)
|
||||
|
||||
|
||||
class SinglePubInfo(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
SinglePubInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('pubMethod', univ.Integer(
|
||||
namedValues=namedval.NamedValues(('dontCare', 0), ('x500', 1), ('web', 2), ('ldap', 3)))),
|
||||
namedtype.OptionalNamedType('pubLocation', rfc3280.GeneralName())
|
||||
)
|
||||
|
||||
|
||||
class UTF8Pairs(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
class PKMACValue(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
PKMACValue.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('algId', rfc3280.AlgorithmIdentifier()),
|
||||
namedtype.NamedType('value', univ.BitString())
|
||||
)
|
||||
|
||||
|
||||
class POPOSigningKeyInput(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
POPOSigningKeyInput.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType(
|
||||
'authInfo', univ.Choice(
|
||||
componentType=namedtype.NamedTypes(
|
||||
namedtype.NamedType(
|
||||
'sender', rfc3280.GeneralName().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))
|
||||
),
|
||||
namedtype.NamedType(
|
||||
'publicKeyMAC', PKMACValue()
|
||||
)
|
||||
)
|
||||
)
|
||||
),
|
||||
namedtype.NamedType('publicKey', rfc3280.SubjectPublicKeyInfo())
|
||||
)
|
||||
|
||||
|
||||
class POPOSigningKey(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
POPOSigningKey.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('poposkInput', POPOSigningKeyInput().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.NamedType('algorithmIdentifier', rfc3280.AlgorithmIdentifier()),
|
||||
namedtype.NamedType('signature', univ.BitString())
|
||||
)
|
||||
|
||||
|
||||
class Attributes(univ.SetOf):
|
||||
pass
|
||||
|
||||
|
||||
Attributes.componentType = rfc3280.Attribute()
|
||||
|
||||
|
||||
class PrivateKeyInfo(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
PrivateKeyInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('version', univ.Integer()),
|
||||
namedtype.NamedType('privateKeyAlgorithm', rfc3280.AlgorithmIdentifier()),
|
||||
namedtype.NamedType('privateKey', univ.OctetString()),
|
||||
namedtype.OptionalNamedType('attributes',
|
||||
Attributes().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0)))
|
||||
)
|
||||
|
||||
|
||||
class EncryptedValue(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
EncryptedValue.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('intendedAlg', rfc3280.AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.OptionalNamedType('symmAlg', rfc3280.AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.OptionalNamedType('encSymmKey', univ.BitString().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2))),
|
||||
namedtype.OptionalNamedType('keyAlg', rfc3280.AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 3))),
|
||||
namedtype.OptionalNamedType('valueHint', univ.OctetString().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 4))),
|
||||
namedtype.NamedType('encValue', univ.BitString())
|
||||
)
|
||||
|
||||
|
||||
class EncryptedKey(univ.Choice):
|
||||
pass
|
||||
|
||||
|
||||
EncryptedKey.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('encryptedValue', EncryptedValue()),
|
||||
namedtype.NamedType('envelopedData', rfc3852.EnvelopedData().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0)))
|
||||
)
|
||||
|
||||
|
||||
class KeyGenParameters(univ.OctetString):
|
||||
pass
|
||||
|
||||
|
||||
class PKIArchiveOptions(univ.Choice):
|
||||
pass
|
||||
|
||||
|
||||
PKIArchiveOptions.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('encryptedPrivKey',
|
||||
EncryptedKey().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.NamedType('keyGenParameters',
|
||||
KeyGenParameters().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.NamedType('archiveRemGenPrivKey',
|
||||
univ.Boolean().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2)))
|
||||
)
|
||||
|
||||
id_regCtrl_authenticator = _buildOid(id_regCtrl, 2)
|
||||
|
||||
id_regInfo = _buildOid(id_pkip, 2)
|
||||
|
||||
id_regInfo_certReq = _buildOid(id_regInfo, 2)
|
||||
|
||||
|
||||
class ProtocolEncrKey(rfc3280.SubjectPublicKeyInfo):
|
||||
pass
|
||||
|
||||
|
||||
class Authenticator(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
class SubsequentMessage(univ.Integer):
|
||||
pass
|
||||
|
||||
|
||||
SubsequentMessage.namedValues = namedval.NamedValues(
|
||||
('encrCert', 0),
|
||||
('challengeResp', 1)
|
||||
)
|
||||
|
||||
|
||||
class AttributeTypeAndValue(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
AttributeTypeAndValue.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('type', univ.ObjectIdentifier()),
|
||||
namedtype.NamedType('value', univ.Any())
|
||||
)
|
||||
|
||||
|
||||
class POPOPrivKey(univ.Choice):
|
||||
pass
|
||||
|
||||
|
||||
POPOPrivKey.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('thisMessage',
|
||||
univ.BitString().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.NamedType('subsequentMessage',
|
||||
SubsequentMessage().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.NamedType('dhMAC',
|
||||
univ.BitString().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2))),
|
||||
namedtype.NamedType('agreeMAC',
|
||||
PKMACValue().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 3))),
|
||||
namedtype.NamedType('encryptedKey', rfc3852.EnvelopedData().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 4)))
|
||||
)
|
||||
|
||||
|
||||
class ProofOfPossession(univ.Choice):
|
||||
pass
|
||||
|
||||
|
||||
ProofOfPossession.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('raVerified',
|
||||
univ.Null().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.NamedType('signature', POPOSigningKey().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1))),
|
||||
namedtype.NamedType('keyEncipherment',
|
||||
POPOPrivKey().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 2))),
|
||||
namedtype.NamedType('keyAgreement',
|
||||
POPOPrivKey().subtype(implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 3)))
|
||||
)
|
||||
|
||||
|
||||
class OptionalValidity(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
OptionalValidity.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('notBefore', rfc3280.Time().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.OptionalNamedType('notAfter', rfc3280.Time().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1)))
|
||||
)
|
||||
|
||||
|
||||
class CertTemplate(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
CertTemplate.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('version', rfc3280.Version().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.OptionalNamedType('serialNumber', univ.Integer().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.OptionalNamedType('signingAlg', rfc3280.AlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2))),
|
||||
namedtype.OptionalNamedType('issuer', rfc3280.Name().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 3))),
|
||||
namedtype.OptionalNamedType('validity', OptionalValidity().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 4))),
|
||||
namedtype.OptionalNamedType('subject', rfc3280.Name().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 5))),
|
||||
namedtype.OptionalNamedType('publicKey', rfc3280.SubjectPublicKeyInfo().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 6))),
|
||||
namedtype.OptionalNamedType('issuerUID', rfc3280.UniqueIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 7))),
|
||||
namedtype.OptionalNamedType('subjectUID', rfc3280.UniqueIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 8))),
|
||||
namedtype.OptionalNamedType('extensions', rfc3280.Extensions().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 9)))
|
||||
)
|
||||
|
||||
|
||||
class Controls(univ.SequenceOf):
|
||||
pass
|
||||
|
||||
|
||||
Controls.componentType = AttributeTypeAndValue()
|
||||
Controls.sizeSpec = constraint.ValueSizeConstraint(1, MAX)
|
||||
|
||||
|
||||
class CertRequest(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
CertRequest.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certReqId', univ.Integer()),
|
||||
namedtype.NamedType('certTemplate', CertTemplate()),
|
||||
namedtype.OptionalNamedType('controls', Controls())
|
||||
)
|
||||
|
||||
|
||||
class CertReqMsg(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
CertReqMsg.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certReq', CertRequest()),
|
||||
namedtype.OptionalNamedType('popo', ProofOfPossession()),
|
||||
namedtype.OptionalNamedType('regInfo', univ.SequenceOf(componentType=AttributeTypeAndValue()))
|
||||
)
|
||||
|
||||
|
||||
class CertReqMessages(univ.SequenceOf):
|
||||
pass
|
||||
|
||||
|
||||
CertReqMessages.componentType = CertReqMsg()
|
||||
CertReqMessages.sizeSpec = constraint.ValueSizeConstraint(1, MAX)
|
||||
|
||||
|
||||
class CertReq(CertRequest):
|
||||
pass
|
||||
|
||||
|
||||
id_regCtrl_pkiPublicationInfo = _buildOid(id_regCtrl, 3)
|
||||
|
||||
|
||||
class CertId(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
CertId.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('issuer', rfc3280.GeneralName()),
|
||||
namedtype.NamedType('serialNumber', univ.Integer())
|
||||
)
|
||||
|
||||
|
||||
class OldCertId(CertId):
|
||||
pass
|
||||
|
||||
|
||||
class PKIPublicationInfo(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
PKIPublicationInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('action',
|
||||
univ.Integer(namedValues=namedval.NamedValues(('dontPublish', 0), ('pleasePublish', 1)))),
|
||||
namedtype.OptionalNamedType('pubInfos', univ.SequenceOf(componentType=SinglePubInfo()))
|
||||
)
|
||||
|
||||
|
||||
class EncKeyWithID(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
EncKeyWithID.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('privateKey', PrivateKeyInfo()),
|
||||
namedtype.OptionalNamedType(
|
||||
'identifier', univ.Choice(
|
||||
componentType=namedtype.NamedTypes(
|
||||
namedtype.NamedType('string', char.UTF8String()),
|
||||
namedtype.NamedType('generalName', rfc3280.GeneralName())
|
||||
)
|
||||
)
|
||||
)
|
||||
)
|
||||
|
||||
id_regCtrl_protocolEncrKey = _buildOid(id_regCtrl, 6)
|
||||
|
||||
id_regCtrl_oldCertID = _buildOid(id_regCtrl, 5)
|
||||
|
||||
id_smime = _buildOid(1, 2, 840, 113549, 1, 9, 16)
|
||||
|
||||
|
||||
class PBMParameter(univ.Sequence):
|
||||
pass
|
||||
|
||||
|
||||
PBMParameter.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('salt', univ.OctetString()),
|
||||
namedtype.NamedType('owf', rfc3280.AlgorithmIdentifier()),
|
||||
namedtype.NamedType('iterationCount', univ.Integer()),
|
||||
namedtype.NamedType('mac', rfc3280.AlgorithmIdentifier())
|
||||
)
|
||||
|
||||
id_regCtrl_regToken = _buildOid(id_regCtrl, 1)
|
||||
|
||||
id_regCtrl_pkiArchiveOptions = _buildOid(id_regCtrl, 4)
|
||||
|
||||
id_regInfo_utf8Pairs = _buildOid(id_regInfo, 1)
|
||||
|
||||
id_ct = _buildOid(id_smime, 1)
|
||||
|
||||
id_ct_encKeyWithID = _buildOid(id_ct, 21)
|
||||
|
||||
|
||||
class RegToken(char.UTF8String):
|
||||
pass
|
||||
@@ -0,0 +1,199 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley with assistance from asn1ate v.0.6.0.
|
||||
# Modified by Russ Housley to add a map for use with opentypes.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# Update to Enhanced Security Services for S/MIME
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc5035.txt
|
||||
#
|
||||
|
||||
from pyasn1.codec.der.encoder import encode as der_encode
|
||||
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc2634
|
||||
from pyasn1_modules import rfc4055
|
||||
from pyasn1_modules import rfc5652
|
||||
from pyasn1_modules import rfc5280
|
||||
|
||||
ContentType = rfc5652.ContentType
|
||||
|
||||
IssuerAndSerialNumber = rfc5652.IssuerAndSerialNumber
|
||||
|
||||
SubjectKeyIdentifier = rfc5652.SubjectKeyIdentifier
|
||||
|
||||
AlgorithmIdentifier = rfc5280.AlgorithmIdentifier
|
||||
|
||||
PolicyInformation = rfc5280.PolicyInformation
|
||||
|
||||
GeneralNames = rfc5280.GeneralNames
|
||||
|
||||
CertificateSerialNumber = rfc5280.CertificateSerialNumber
|
||||
|
||||
|
||||
# Signing Certificate Attribute V1 and V2
|
||||
|
||||
id_aa_signingCertificate = rfc2634.id_aa_signingCertificate
|
||||
|
||||
id_aa_signingCertificateV2 = univ.ObjectIdentifier('1.2.840.113549.1.9.16.2.47')
|
||||
|
||||
Hash = rfc2634.Hash
|
||||
|
||||
IssuerSerial = rfc2634.IssuerSerial
|
||||
|
||||
ESSCertID = rfc2634.ESSCertID
|
||||
|
||||
SigningCertificate = rfc2634.SigningCertificate
|
||||
|
||||
|
||||
sha256AlgId = AlgorithmIdentifier()
|
||||
sha256AlgId['algorithm'] = rfc4055.id_sha256
|
||||
# A non-schema object for sha256AlgId['parameters'] as absent
|
||||
sha256AlgId['parameters'] = der_encode(univ.OctetString(''))
|
||||
|
||||
|
||||
class ESSCertIDv2(univ.Sequence):
|
||||
pass
|
||||
|
||||
ESSCertIDv2.componentType = namedtype.NamedTypes(
|
||||
namedtype.DefaultedNamedType('hashAlgorithm', sha256AlgId),
|
||||
namedtype.NamedType('certHash', Hash()),
|
||||
namedtype.OptionalNamedType('issuerSerial', IssuerSerial())
|
||||
)
|
||||
|
||||
|
||||
class SigningCertificateV2(univ.Sequence):
|
||||
pass
|
||||
|
||||
SigningCertificateV2.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certs', univ.SequenceOf(
|
||||
componentType=ESSCertIDv2())),
|
||||
namedtype.OptionalNamedType('policies', univ.SequenceOf(
|
||||
componentType=PolicyInformation()))
|
||||
)
|
||||
|
||||
|
||||
# Mail List Expansion History Attribute
|
||||
|
||||
id_aa_mlExpandHistory = rfc2634.id_aa_mlExpandHistory
|
||||
|
||||
ub_ml_expansion_history = rfc2634.ub_ml_expansion_history
|
||||
|
||||
EntityIdentifier = rfc2634.EntityIdentifier
|
||||
|
||||
MLReceiptPolicy = rfc2634.MLReceiptPolicy
|
||||
|
||||
MLData = rfc2634.MLData
|
||||
|
||||
MLExpansionHistory = rfc2634.MLExpansionHistory
|
||||
|
||||
|
||||
# ESS Security Label Attribute
|
||||
|
||||
id_aa_securityLabel = rfc2634.id_aa_securityLabel
|
||||
|
||||
ub_privacy_mark_length = rfc2634.ub_privacy_mark_length
|
||||
|
||||
ub_security_categories = rfc2634.ub_security_categories
|
||||
|
||||
ub_integer_options = rfc2634.ub_integer_options
|
||||
|
||||
ESSPrivacyMark = rfc2634.ESSPrivacyMark
|
||||
|
||||
SecurityClassification = rfc2634.SecurityClassification
|
||||
|
||||
SecurityPolicyIdentifier = rfc2634.SecurityPolicyIdentifier
|
||||
|
||||
SecurityCategory = rfc2634.SecurityCategory
|
||||
|
||||
SecurityCategories = rfc2634.SecurityCategories
|
||||
|
||||
ESSSecurityLabel = rfc2634.ESSSecurityLabel
|
||||
|
||||
|
||||
# Equivalent Labels Attribute
|
||||
|
||||
id_aa_equivalentLabels = rfc2634.id_aa_equivalentLabels
|
||||
|
||||
EquivalentLabels = rfc2634.EquivalentLabels
|
||||
|
||||
|
||||
# Content Identifier Attribute
|
||||
|
||||
id_aa_contentIdentifier = rfc2634.id_aa_contentIdentifier
|
||||
|
||||
ContentIdentifier = rfc2634.ContentIdentifier
|
||||
|
||||
|
||||
# Content Reference Attribute
|
||||
|
||||
id_aa_contentReference = rfc2634.id_aa_contentReference
|
||||
|
||||
ContentReference = rfc2634.ContentReference
|
||||
|
||||
|
||||
# Message Signature Digest Attribute
|
||||
|
||||
id_aa_msgSigDigest = rfc2634.id_aa_msgSigDigest
|
||||
|
||||
MsgSigDigest = rfc2634.MsgSigDigest
|
||||
|
||||
|
||||
# Content Hints Attribute
|
||||
|
||||
id_aa_contentHint = rfc2634.id_aa_contentHint
|
||||
|
||||
ContentHints = rfc2634.ContentHints
|
||||
|
||||
|
||||
# Receipt Request Attribute
|
||||
|
||||
AllOrFirstTier = rfc2634.AllOrFirstTier
|
||||
|
||||
ReceiptsFrom = rfc2634.ReceiptsFrom
|
||||
|
||||
id_aa_receiptRequest = rfc2634.id_aa_receiptRequest
|
||||
|
||||
ub_receiptsTo = rfc2634.ub_receiptsTo
|
||||
|
||||
ReceiptRequest = rfc2634.ReceiptRequest
|
||||
|
||||
|
||||
# Receipt Content Type
|
||||
|
||||
ESSVersion = rfc2634.ESSVersion
|
||||
|
||||
id_ct_receipt = rfc2634.id_ct_receipt
|
||||
|
||||
Receipt = rfc2634.Receipt
|
||||
|
||||
ub_receiptsTo = rfc2634.ub_receiptsTo
|
||||
|
||||
ReceiptRequest = rfc2634.ReceiptRequest
|
||||
|
||||
|
||||
# Map of Attribute Type to the Attribute structure is added to the
|
||||
# ones that are in rfc5652.py
|
||||
|
||||
_cmsAttributesMapUpdate = {
|
||||
id_aa_signingCertificateV2: SigningCertificateV2(),
|
||||
}
|
||||
|
||||
rfc5652.cmsAttributesMap.update(_cmsAttributesMapUpdate)
|
||||
|
||||
|
||||
# Map of Content Type OIDs to Content Types is added to the
|
||||
# ones that are in rfc5652.py
|
||||
|
||||
_cmsContentTypesMapUpdate = {
|
||||
id_ct_receipt: Receipt(),
|
||||
}
|
||||
|
||||
rfc5652.cmsContentTypesMap.update(_cmsContentTypesMapUpdate)
|
||||
@@ -0,0 +1,119 @@
|
||||
# This file is being contributed to pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley with assistance from asn1ate v.0.6.0.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# Trust Anchor Format
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc5914.txt
|
||||
|
||||
from pyasn1.type import char
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import namedval
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc5280
|
||||
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
Certificate = rfc5280.Certificate
|
||||
|
||||
Name = rfc5280.Name
|
||||
|
||||
Extensions = rfc5280.Extensions
|
||||
|
||||
SubjectPublicKeyInfo = rfc5280.SubjectPublicKeyInfo
|
||||
|
||||
TBSCertificate = rfc5280.TBSCertificate
|
||||
|
||||
CertificatePolicies = rfc5280.CertificatePolicies
|
||||
|
||||
KeyIdentifier = rfc5280.KeyIdentifier
|
||||
|
||||
NameConstraints = rfc5280.NameConstraints
|
||||
|
||||
|
||||
class CertPolicyFlags(univ.BitString):
|
||||
pass
|
||||
|
||||
CertPolicyFlags.namedValues = namedval.NamedValues(
|
||||
('inhibitPolicyMapping', 0),
|
||||
('requireExplicitPolicy', 1),
|
||||
('inhibitAnyPolicy', 2)
|
||||
)
|
||||
|
||||
|
||||
class CertPathControls(univ.Sequence):
|
||||
pass
|
||||
|
||||
CertPathControls.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('taName', Name()),
|
||||
namedtype.OptionalNamedType('certificate', Certificate().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.OptionalNamedType('policySet', CertificatePolicies().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.OptionalNamedType('policyFlags', CertPolicyFlags().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2))),
|
||||
namedtype.OptionalNamedType('nameConstr', NameConstraints().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 3))),
|
||||
namedtype.OptionalNamedType('pathLenConstraint', univ.Integer().subtype(
|
||||
subtypeSpec=constraint.ValueRangeConstraint(0, MAX)).subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 4)))
|
||||
)
|
||||
|
||||
|
||||
class TrustAnchorTitle(char.UTF8String):
|
||||
pass
|
||||
|
||||
TrustAnchorTitle.subtypeSpec = constraint.ValueSizeConstraint(1, 64)
|
||||
|
||||
|
||||
class TrustAnchorInfoVersion(univ.Integer):
|
||||
pass
|
||||
|
||||
TrustAnchorInfoVersion.namedValues = namedval.NamedValues(
|
||||
('v1', 1)
|
||||
)
|
||||
|
||||
|
||||
class TrustAnchorInfo(univ.Sequence):
|
||||
pass
|
||||
|
||||
TrustAnchorInfo.componentType = namedtype.NamedTypes(
|
||||
namedtype.DefaultedNamedType('version', TrustAnchorInfoVersion().subtype(value='v1')),
|
||||
namedtype.NamedType('pubKey', SubjectPublicKeyInfo()),
|
||||
namedtype.NamedType('keyId', KeyIdentifier()),
|
||||
namedtype.OptionalNamedType('taTitle', TrustAnchorTitle()),
|
||||
namedtype.OptionalNamedType('certPath', CertPathControls()),
|
||||
namedtype.OptionalNamedType('exts', Extensions().subtype(explicitTag=tag.Tag(
|
||||
tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.OptionalNamedType('taTitleLangTag', char.UTF8String().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2)))
|
||||
)
|
||||
|
||||
|
||||
class TrustAnchorChoice(univ.Choice):
|
||||
pass
|
||||
|
||||
TrustAnchorChoice.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('certificate', Certificate()),
|
||||
namedtype.NamedType('tbsCert', TBSCertificate().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.NamedType('taInfo', TrustAnchorInfo().subtype(
|
||||
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 2)))
|
||||
)
|
||||
|
||||
|
||||
id_ct_trustAnchorList = univ.ObjectIdentifier('1.2.840.113549.1.9.16.1.34')
|
||||
|
||||
class TrustAnchorList(univ.SequenceOf):
|
||||
pass
|
||||
|
||||
TrustAnchorList.componentType = TrustAnchorChoice()
|
||||
TrustAnchorList.subtypeSpec=constraint.ValueSizeConstraint(1, MAX)
|
||||
@@ -0,0 +1,45 @@
|
||||
# This file is being contributed to pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley.
|
||||
# Modified by Russ Housley to add a map for use with opentypes.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# BinaryTime: An Alternate Format for Representing Date and Time
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc6019.txt
|
||||
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc5652
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
|
||||
# BinaryTime: Represent date and time as an integer
|
||||
|
||||
class BinaryTime(univ.Integer):
|
||||
pass
|
||||
|
||||
BinaryTime.subtypeSpec = constraint.ValueRangeConstraint(0, MAX)
|
||||
|
||||
|
||||
# CMS Attribute for representing signing time in BinaryTime
|
||||
|
||||
id_aa_binarySigningTime = univ.ObjectIdentifier('1.2.840.113549.1.9.16.2.46')
|
||||
|
||||
class BinarySigningTime(BinaryTime):
|
||||
pass
|
||||
|
||||
|
||||
# Map of Attribute Type OIDs to Attributes ia added to the
|
||||
# ones that are in rfc5652.py
|
||||
|
||||
_cmsAttributesMapUpdate = {
|
||||
id_aa_binarySigningTime: BinarySigningTime(),
|
||||
}
|
||||
|
||||
rfc5652.cmsAttributesMap.update(_cmsAttributesMapUpdate)
|
||||
@@ -0,0 +1,469 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley with assistance from asn1ate v.0.6.0.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# CMS Symmetric Key Package Content Type
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc6031.txt
|
||||
#
|
||||
|
||||
from pyasn1.type import char
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import namedval
|
||||
from pyasn1.type import opentype
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
from pyasn1.type import useful
|
||||
|
||||
from pyasn1_modules import rfc5652
|
||||
from pyasn1_modules import rfc6019
|
||||
|
||||
|
||||
def _OID(*components):
|
||||
output = []
|
||||
for x in tuple(components):
|
||||
if isinstance(x, univ.ObjectIdentifier):
|
||||
output.extend(list(x))
|
||||
else:
|
||||
output.append(int(x))
|
||||
return univ.ObjectIdentifier(output)
|
||||
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
id_pskc = univ.ObjectIdentifier('1.2.840.113549.1.9.16.12')
|
||||
|
||||
|
||||
# Symmetric Key Package Attributes
|
||||
|
||||
id_pskc_manufacturer = _OID(id_pskc, 1)
|
||||
|
||||
class at_pskc_manufacturer(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_serialNo = _OID(id_pskc, 2)
|
||||
|
||||
class at_pskc_serialNo(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_model = _OID(id_pskc, 3)
|
||||
|
||||
class at_pskc_model(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_issueNo = _OID(id_pskc, 4)
|
||||
|
||||
class at_pskc_issueNo(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_deviceBinding = _OID(id_pskc, 5)
|
||||
|
||||
class at_pskc_deviceBinding(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_deviceStartDate = _OID(id_pskc, 6)
|
||||
|
||||
class at_pskc_deviceStartDate(useful.GeneralizedTime):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_deviceExpiryDate = _OID(id_pskc, 7)
|
||||
|
||||
class at_pskc_deviceExpiryDate(useful.GeneralizedTime):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_moduleId = _OID(id_pskc, 8)
|
||||
|
||||
class at_pskc_moduleId(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_deviceUserId = _OID(id_pskc, 26)
|
||||
|
||||
class at_pskc_deviceUserId(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
# Symmetric Key Attributes
|
||||
|
||||
id_pskc_keyId = _OID(id_pskc, 9)
|
||||
|
||||
class at_pskc_keyUserId(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_algorithm = _OID(id_pskc, 10)
|
||||
|
||||
class at_pskc_algorithm(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_issuer = _OID(id_pskc, 11)
|
||||
|
||||
class at_pskc_issuer(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_keyProfileId = _OID(id_pskc, 12)
|
||||
|
||||
class at_pskc_keyProfileId(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_keyReference = _OID(id_pskc, 13)
|
||||
|
||||
class at_pskc_keyReference(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_friendlyName = _OID(id_pskc, 14)
|
||||
|
||||
class FriendlyName(univ.Sequence):
|
||||
pass
|
||||
|
||||
FriendlyName.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('friendlyName', char.UTF8String()),
|
||||
namedtype.OptionalNamedType('friendlyNameLangTag', char.UTF8String())
|
||||
)
|
||||
|
||||
class at_pskc_friendlyName(FriendlyName):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_algorithmParameters = _OID(id_pskc, 15)
|
||||
|
||||
class Encoding(char.UTF8String):
|
||||
pass
|
||||
|
||||
Encoding.namedValues = namedval.NamedValues(
|
||||
('dec', "DECIMAL"),
|
||||
('hex', "HEXADECIMAL"),
|
||||
('alpha', "ALPHANUMERIC"),
|
||||
('b64', "BASE64"),
|
||||
('bin', "BINARY")
|
||||
)
|
||||
|
||||
Encoding.subtypeSpec = constraint.SingleValueConstraint(
|
||||
"DECIMAL", "HEXADECIMAL", "ALPHANUMERIC", "BASE64", "BINARY" )
|
||||
|
||||
class ChallengeFormat(univ.Sequence):
|
||||
pass
|
||||
|
||||
ChallengeFormat.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('encoding', Encoding()),
|
||||
namedtype.DefaultedNamedType('checkDigit',
|
||||
univ.Boolean().subtype(value=0)),
|
||||
namedtype.NamedType('min', univ.Integer().subtype(
|
||||
subtypeSpec=constraint.ValueRangeConstraint(0, MAX))),
|
||||
namedtype.NamedType('max', univ.Integer().subtype(
|
||||
subtypeSpec=constraint.ValueRangeConstraint(0, MAX)))
|
||||
)
|
||||
|
||||
class ResponseFormat(univ.Sequence):
|
||||
pass
|
||||
|
||||
ResponseFormat.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('encoding', Encoding()),
|
||||
namedtype.NamedType('length', univ.Integer().subtype(
|
||||
subtypeSpec=constraint.ValueRangeConstraint(0, MAX))),
|
||||
namedtype.DefaultedNamedType('checkDigit',
|
||||
univ.Boolean().subtype(value=0))
|
||||
)
|
||||
|
||||
class PSKCAlgorithmParameters(univ.Choice):
|
||||
pass
|
||||
|
||||
PSKCAlgorithmParameters.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('suite', char.UTF8String()),
|
||||
namedtype.NamedType('challengeFormat', ChallengeFormat().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.NamedType('responseFormat', ResponseFormat().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 1)))
|
||||
)
|
||||
|
||||
class at_pskc_algorithmParameters(PSKCAlgorithmParameters):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_counter = _OID(id_pskc, 16)
|
||||
|
||||
class at_pskc_counter(univ.Integer):
|
||||
pass
|
||||
|
||||
at_pskc_counter.subtypeSpec = constraint.ValueRangeConstraint(0, MAX)
|
||||
|
||||
|
||||
id_pskc_time = _OID(id_pskc, 17)
|
||||
|
||||
class at_pskc_time(rfc6019.BinaryTime):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_timeInterval = _OID(id_pskc, 18)
|
||||
|
||||
class at_pskc_timeInterval(univ.Integer):
|
||||
pass
|
||||
|
||||
at_pskc_timeInterval.subtypeSpec = constraint.ValueRangeConstraint(0, MAX)
|
||||
|
||||
|
||||
id_pskc_timeDrift = _OID(id_pskc, 19)
|
||||
|
||||
class at_pskc_timeDrift(univ.Integer):
|
||||
pass
|
||||
|
||||
at_pskc_timeDrift.subtypeSpec = constraint.ValueRangeConstraint(0, MAX)
|
||||
|
||||
|
||||
id_pskc_valueMAC = _OID(id_pskc, 20)
|
||||
|
||||
class ValueMac(univ.Sequence):
|
||||
pass
|
||||
|
||||
ValueMac.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('macAlgorithm', char.UTF8String()),
|
||||
namedtype.NamedType('mac', char.UTF8String())
|
||||
)
|
||||
|
||||
class at_pskc_valueMAC(ValueMac):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_keyUserId = _OID(id_pskc, 27)
|
||||
|
||||
class at_pskc_keyId(char.UTF8String):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_keyStartDate = _OID(id_pskc, 21)
|
||||
|
||||
class at_pskc_keyStartDate(useful.GeneralizedTime):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_keyExpiryDate = _OID(id_pskc, 22)
|
||||
|
||||
class at_pskc_keyExpiryDate(useful.GeneralizedTime):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_numberOfTransactions = _OID(id_pskc, 23)
|
||||
|
||||
class at_pskc_numberOfTransactions(univ.Integer):
|
||||
pass
|
||||
|
||||
at_pskc_numberOfTransactions.subtypeSpec = constraint.ValueRangeConstraint(0, MAX)
|
||||
|
||||
|
||||
id_pskc_keyUsages = _OID(id_pskc, 24)
|
||||
|
||||
class PSKCKeyUsage(char.UTF8String):
|
||||
pass
|
||||
|
||||
PSKCKeyUsage.namedValues = namedval.NamedValues(
|
||||
('otp', "OTP"),
|
||||
('cr', "CR"),
|
||||
('encrypt', "Encrypt"),
|
||||
('integrity', "Integrity"),
|
||||
('verify', "Verify"),
|
||||
('unlock', "Unlock"),
|
||||
('decrypt', "Decrypt"),
|
||||
('keywrap', "KeyWrap"),
|
||||
('unwrap', "Unwrap"),
|
||||
('derive', "Derive"),
|
||||
('generate', "Generate")
|
||||
)
|
||||
|
||||
PSKCKeyUsage.subtypeSpec = constraint.SingleValueConstraint(
|
||||
"OTP", "CR", "Encrypt", "Integrity", "Verify", "Unlock",
|
||||
"Decrypt", "KeyWrap", "Unwrap", "Derive", "Generate" )
|
||||
|
||||
class PSKCKeyUsages(univ.SequenceOf):
|
||||
pass
|
||||
|
||||
PSKCKeyUsages.componentType = PSKCKeyUsage()
|
||||
|
||||
class at_pskc_keyUsage(PSKCKeyUsages):
|
||||
pass
|
||||
|
||||
|
||||
id_pskc_pinPolicy = _OID(id_pskc, 25)
|
||||
|
||||
class PINUsageMode(char.UTF8String):
|
||||
pass
|
||||
|
||||
PINUsageMode.namedValues = namedval.NamedValues(
|
||||
("local", "Local"),
|
||||
("prepend", "Prepend"),
|
||||
("append", "Append"),
|
||||
("algorithmic", "Algorithmic")
|
||||
)
|
||||
|
||||
PINUsageMode.subtypeSpec = constraint.SingleValueConstraint(
|
||||
"Local", "Prepend", "Append", "Algorithmic" )
|
||||
|
||||
class PINPolicy(univ.Sequence):
|
||||
pass
|
||||
|
||||
PINPolicy.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('pinKeyId', char.UTF8String().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.NamedType('pinUsageMode', PINUsageMode().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.OptionalNamedType('maxFailedAttempts', univ.Integer().subtype(
|
||||
subtypeSpec=constraint.ValueRangeConstraint(0, MAX)).subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2))),
|
||||
namedtype.OptionalNamedType('minLength', univ.Integer().subtype(
|
||||
subtypeSpec=constraint.ValueRangeConstraint(0, MAX)).subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 3))),
|
||||
namedtype.OptionalNamedType('maxLength', univ.Integer().subtype(
|
||||
subtypeSpec=constraint.ValueRangeConstraint(0, MAX)).subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 4))),
|
||||
namedtype.OptionalNamedType('pinEncoding', Encoding().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 5)))
|
||||
)
|
||||
|
||||
class at_pskc_pinPolicy(PINPolicy):
|
||||
pass
|
||||
|
||||
|
||||
# Map of Symmetric Key Package Attribute OIDs to Attributes
|
||||
|
||||
sKeyPkgAttributesMap = {
|
||||
id_pskc_manufacturer: at_pskc_manufacturer(),
|
||||
id_pskc_serialNo: at_pskc_serialNo(),
|
||||
id_pskc_model: at_pskc_model(),
|
||||
id_pskc_issueNo: at_pskc_issueNo(),
|
||||
id_pskc_deviceBinding: at_pskc_deviceBinding(),
|
||||
id_pskc_deviceStartDate: at_pskc_deviceStartDate(),
|
||||
id_pskc_deviceExpiryDate: at_pskc_deviceExpiryDate(),
|
||||
id_pskc_moduleId: at_pskc_moduleId(),
|
||||
id_pskc_deviceUserId: at_pskc_deviceUserId(),
|
||||
}
|
||||
|
||||
|
||||
# Map of Symmetric Key Attribute OIDs to Attributes
|
||||
|
||||
sKeyAttributesMap = {
|
||||
id_pskc_keyId: at_pskc_keyId(),
|
||||
id_pskc_algorithm: at_pskc_algorithm(),
|
||||
id_pskc_issuer: at_pskc_issuer(),
|
||||
id_pskc_keyProfileId: at_pskc_keyProfileId(),
|
||||
id_pskc_keyReference: at_pskc_keyReference(),
|
||||
id_pskc_friendlyName: at_pskc_friendlyName(),
|
||||
id_pskc_algorithmParameters: at_pskc_algorithmParameters(),
|
||||
id_pskc_counter: at_pskc_counter(),
|
||||
id_pskc_time: at_pskc_time(),
|
||||
id_pskc_timeInterval: at_pskc_timeInterval(),
|
||||
id_pskc_timeDrift: at_pskc_timeDrift(),
|
||||
id_pskc_valueMAC: at_pskc_valueMAC(),
|
||||
id_pskc_keyUserId: at_pskc_keyUserId(),
|
||||
id_pskc_keyStartDate: at_pskc_keyStartDate(),
|
||||
id_pskc_keyExpiryDate: at_pskc_keyExpiryDate(),
|
||||
id_pskc_numberOfTransactions: at_pskc_numberOfTransactions(),
|
||||
id_pskc_keyUsages: at_pskc_keyUsage(),
|
||||
id_pskc_pinPolicy: at_pskc_pinPolicy(),
|
||||
}
|
||||
|
||||
|
||||
# This definition replaces Attribute() from rfc5652.py; it is the same except
|
||||
# that opentype is added with sKeyPkgAttributesMap and sKeyAttributesMap
|
||||
|
||||
class AttributeType(univ.ObjectIdentifier):
|
||||
pass
|
||||
|
||||
|
||||
class AttributeValue(univ.Any):
|
||||
pass
|
||||
|
||||
|
||||
class SKeyAttribute(univ.Sequence):
|
||||
pass
|
||||
|
||||
SKeyAttribute.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('attrType', AttributeType()),
|
||||
namedtype.NamedType('attrValues',
|
||||
univ.SetOf(componentType=AttributeValue()),
|
||||
openType=opentype.OpenType('attrType', sKeyAttributesMap)
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
class SKeyPkgAttribute(univ.Sequence):
|
||||
pass
|
||||
|
||||
SKeyPkgAttribute.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('attrType', AttributeType()),
|
||||
namedtype.NamedType('attrValues',
|
||||
univ.SetOf(componentType=AttributeValue()),
|
||||
openType=opentype.OpenType('attrType', sKeyPkgAttributesMap)
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
# Symmetric Key Package Content Type
|
||||
|
||||
id_ct_KP_sKeyPackage = univ.ObjectIdentifier('1.2.840.113549.1.9.16.1.25')
|
||||
|
||||
|
||||
class KeyPkgVersion(univ.Integer):
|
||||
pass
|
||||
|
||||
KeyPkgVersion.namedValues = namedval.NamedValues(
|
||||
('v1', 1)
|
||||
)
|
||||
|
||||
|
||||
class OneSymmetricKey(univ.Sequence):
|
||||
pass
|
||||
|
||||
OneSymmetricKey.componentType = namedtype.NamedTypes(
|
||||
namedtype.OptionalNamedType('sKeyAttrs',
|
||||
univ.SequenceOf(componentType=SKeyAttribute()).subtype(
|
||||
subtypeSpec=constraint.ValueSizeConstraint(1, MAX))),
|
||||
namedtype.OptionalNamedType('sKey', univ.OctetString())
|
||||
)
|
||||
|
||||
OneSymmetricKey.sizeSpec = univ.Sequence.sizeSpec + constraint.ValueSizeConstraint(1, 2)
|
||||
|
||||
|
||||
class SymmetricKeys(univ.SequenceOf):
|
||||
pass
|
||||
|
||||
SymmetricKeys.componentType = OneSymmetricKey()
|
||||
SymmetricKeys.subtypeSpec=constraint.ValueSizeConstraint(1, MAX)
|
||||
|
||||
|
||||
class SymmetricKeyPackage(univ.Sequence):
|
||||
pass
|
||||
|
||||
SymmetricKeyPackage.componentType = namedtype.NamedTypes(
|
||||
namedtype.DefaultedNamedType('version', KeyPkgVersion().subtype(value='v1')),
|
||||
namedtype.OptionalNamedType('sKeyPkgAttrs',
|
||||
univ.SequenceOf(componentType=SKeyPkgAttribute()).subtype(
|
||||
subtypeSpec=constraint.ValueSizeConstraint(1, MAX),
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.NamedType('sKeys', SymmetricKeys())
|
||||
)
|
||||
|
||||
|
||||
# Map of Content Type OIDs to Content Types are
|
||||
# added to the ones that are in rfc5652.py
|
||||
|
||||
_cmsContentTypesMapUpdate = {
|
||||
id_ct_KP_sKeyPackage: SymmetricKeyPackage(),
|
||||
}
|
||||
|
||||
rfc5652.cmsContentTypesMap.update(_cmsContentTypesMapUpdate)
|
||||
@@ -0,0 +1,72 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley with assistance from asn1ate v.0.6.0.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# CMS Algorithm Identifier Protection Attribute
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc6211.txt
|
||||
#
|
||||
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc5652
|
||||
|
||||
|
||||
# Imports from RFC 5652
|
||||
|
||||
DigestAlgorithmIdentifier = rfc5652.DigestAlgorithmIdentifier
|
||||
|
||||
MessageAuthenticationCodeAlgorithm = rfc5652.MessageAuthenticationCodeAlgorithm
|
||||
|
||||
SignatureAlgorithmIdentifier = rfc5652.SignatureAlgorithmIdentifier
|
||||
|
||||
|
||||
# CMS Algorithm Protection attribute
|
||||
|
||||
id_aa_cmsAlgorithmProtect = univ.ObjectIdentifier('1.2.840.113549.1.9.52')
|
||||
|
||||
|
||||
class CMSAlgorithmProtection(univ.Sequence):
|
||||
pass
|
||||
|
||||
CMSAlgorithmProtection.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('digestAlgorithm', DigestAlgorithmIdentifier()),
|
||||
namedtype.OptionalNamedType('signatureAlgorithm',
|
||||
SignatureAlgorithmIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),
|
||||
namedtype.OptionalNamedType('macAlgorithm',
|
||||
MessageAuthenticationCodeAlgorithm().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2)))
|
||||
)
|
||||
|
||||
CMSAlgorithmProtection.subtypeSpec = constraint.ConstraintsUnion(
|
||||
constraint.WithComponentsConstraint(
|
||||
('signatureAlgorithm', constraint.ComponentPresentConstraint()),
|
||||
('macAlgorithm', constraint.ComponentAbsentConstraint())),
|
||||
constraint.WithComponentsConstraint(
|
||||
('signatureAlgorithm', constraint.ComponentAbsentConstraint()),
|
||||
('macAlgorithm', constraint.ComponentPresentConstraint()))
|
||||
)
|
||||
|
||||
|
||||
aa_cmsAlgorithmProtection = rfc5652.Attribute()
|
||||
aa_cmsAlgorithmProtection['attrType'] = id_aa_cmsAlgorithmProtect
|
||||
aa_cmsAlgorithmProtection['attrValues'][0] = CMSAlgorithmProtection()
|
||||
|
||||
|
||||
# Map of Attribute Type OIDs to Attributes are
|
||||
# added to the ones that are in rfc5652.py
|
||||
|
||||
_cmsAttributesMapUpdate = {
|
||||
id_aa_cmsAlgorithmProtect: CMSAlgorithmProtection(),
|
||||
}
|
||||
|
||||
rfc5652.cmsAttributesMap.update(_cmsAttributesMapUpdate)
|
||||
@@ -0,0 +1,261 @@
|
||||
# This file is being contributed to of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley without assistance from the asn1ate tool.
|
||||
# Modified by Russ Housley to add support for opentypes.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# CMS Key Package Receipt and Error Content Types
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc7191.txt
|
||||
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import namedval
|
||||
from pyasn1.type import opentype
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc5280
|
||||
from pyasn1_modules import rfc5652
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
DistinguishedName = rfc5280.DistinguishedName
|
||||
|
||||
|
||||
# SingleAttribute is the same as Attribute in RFC 5652, except that the
|
||||
# attrValues SET must have one and only one member
|
||||
|
||||
class AttributeValue(univ.Any):
|
||||
pass
|
||||
|
||||
|
||||
class AttributeValues(univ.SetOf):
|
||||
pass
|
||||
|
||||
AttributeValues.componentType = AttributeValue()
|
||||
AttributeValues.sizeSpec = univ.Set.sizeSpec + constraint.ValueSizeConstraint(1, 1)
|
||||
|
||||
|
||||
class SingleAttribute(univ.Sequence):
|
||||
pass
|
||||
|
||||
SingleAttribute.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('attrType', univ.ObjectIdentifier()),
|
||||
namedtype.NamedType('attrValues', AttributeValues(),
|
||||
openType=opentype.OpenType('attrType', rfc5652.cmsAttributesMap)
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
# SIR Entity Name
|
||||
|
||||
class SIREntityNameType(univ.ObjectIdentifier):
|
||||
pass
|
||||
|
||||
|
||||
class SIREntityNameValue(univ.Any):
|
||||
pass
|
||||
|
||||
|
||||
class SIREntityName(univ.Sequence):
|
||||
pass
|
||||
|
||||
SIREntityName.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('sirenType', SIREntityNameType()),
|
||||
namedtype.NamedType('sirenValue', univ.OctetString())
|
||||
# CONTAINING the DER-encoded SIREntityNameValue
|
||||
)
|
||||
|
||||
|
||||
class SIREntityNames(univ.SequenceOf):
|
||||
pass
|
||||
|
||||
SIREntityNames.componentType = SIREntityName()
|
||||
SIREntityNames.sizeSpec=constraint.ValueSizeConstraint(1, MAX)
|
||||
|
||||
|
||||
id_dn = univ.ObjectIdentifier('2.16.840.1.101.2.1.16.0')
|
||||
|
||||
|
||||
class siren_dn(SIREntityName):
|
||||
def __init__(self):
|
||||
SIREntityName.__init__(self)
|
||||
self['sirenType'] = id_dn
|
||||
|
||||
|
||||
# Key Package Error CMS Content Type
|
||||
|
||||
class EnumeratedErrorCode(univ.Enumerated):
|
||||
pass
|
||||
|
||||
# Error codes with values <= 33 are aligned with RFC 5934
|
||||
EnumeratedErrorCode.namedValues = namedval.NamedValues(
|
||||
('decodeFailure', 1),
|
||||
('badContentInfo', 2),
|
||||
('badSignedData', 3),
|
||||
('badEncapContent', 4),
|
||||
('badCertificate', 5),
|
||||
('badSignerInfo', 6),
|
||||
('badSignedAttrs', 7),
|
||||
('badUnsignedAttrs', 8),
|
||||
('missingContent', 9),
|
||||
('noTrustAnchor', 10),
|
||||
('notAuthorized', 11),
|
||||
('badDigestAlgorithm', 12),
|
||||
('badSignatureAlgorithm', 13),
|
||||
('unsupportedKeySize', 14),
|
||||
('unsupportedParameters', 15),
|
||||
('signatureFailure', 16),
|
||||
('insufficientMemory', 17),
|
||||
('incorrectTarget', 23),
|
||||
('missingSignature', 29),
|
||||
('resourcesBusy', 30),
|
||||
('versionNumberMismatch', 31),
|
||||
('revokedCertificate', 33),
|
||||
('ambiguousDecrypt', 60),
|
||||
('noDecryptKey', 61),
|
||||
('badEncryptedData', 62),
|
||||
('badEnvelopedData', 63),
|
||||
('badAuthenticatedData', 64),
|
||||
('badAuthEnvelopedData', 65),
|
||||
('badKeyAgreeRecipientInfo', 66),
|
||||
('badKEKRecipientInfo', 67),
|
||||
('badEncryptContent', 68),
|
||||
('badEncryptAlgorithm', 69),
|
||||
('missingCiphertext', 70),
|
||||
('decryptFailure', 71),
|
||||
('badMACAlgorithm', 72),
|
||||
('badAuthAttrs', 73),
|
||||
('badUnauthAttrs', 74),
|
||||
('invalidMAC', 75),
|
||||
('mismatchedDigestAlg', 76),
|
||||
('missingCertificate', 77),
|
||||
('tooManySigners', 78),
|
||||
('missingSignedAttributes', 79),
|
||||
('derEncodingNotUsed', 80),
|
||||
('missingContentHints', 81),
|
||||
('invalidAttributeLocation', 82),
|
||||
('badMessageDigest', 83),
|
||||
('badKeyPackage', 84),
|
||||
('badAttributes', 85),
|
||||
('attributeComparisonFailure', 86),
|
||||
('unsupportedSymmetricKeyPackage', 87),
|
||||
('unsupportedAsymmetricKeyPackage', 88),
|
||||
('constraintViolation', 89),
|
||||
('ambiguousDefaultValue', 90),
|
||||
('noMatchingRecipientInfo', 91),
|
||||
('unsupportedKeyWrapAlgorithm', 92),
|
||||
('badKeyTransRecipientInfo', 93),
|
||||
('other', 127)
|
||||
)
|
||||
|
||||
|
||||
class ErrorCodeChoice(univ.Choice):
|
||||
pass
|
||||
|
||||
ErrorCodeChoice.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('enum', EnumeratedErrorCode()),
|
||||
namedtype.NamedType('oid', univ.ObjectIdentifier())
|
||||
)
|
||||
|
||||
|
||||
class KeyPkgID(univ.OctetString):
|
||||
pass
|
||||
|
||||
|
||||
class KeyPkgIdentifier(univ.Choice):
|
||||
pass
|
||||
|
||||
KeyPkgIdentifier.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('pkgID', KeyPkgID()),
|
||||
namedtype.NamedType('attribute', SingleAttribute())
|
||||
)
|
||||
|
||||
|
||||
class KeyPkgVersion(univ.Integer):
|
||||
pass
|
||||
|
||||
|
||||
KeyPkgVersion.namedValues = namedval.NamedValues(
|
||||
('v1', 1),
|
||||
('v2', 2)
|
||||
)
|
||||
|
||||
KeyPkgVersion.subtypeSpec = constraint.ValueRangeConstraint(1, 65535)
|
||||
|
||||
|
||||
id_ct_KP_keyPackageError = univ.ObjectIdentifier('2.16.840.1.101.2.1.2.78.6')
|
||||
|
||||
class KeyPackageError(univ.Sequence):
|
||||
pass
|
||||
|
||||
KeyPackageError.componentType = namedtype.NamedTypes(
|
||||
namedtype.DefaultedNamedType('version', KeyPkgVersion().subtype(value='v2')),
|
||||
namedtype.OptionalNamedType('errorOf', KeyPkgIdentifier().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0))),
|
||||
namedtype.NamedType('errorBy', SIREntityName()),
|
||||
namedtype.NamedType('errorCode', ErrorCodeChoice())
|
||||
)
|
||||
|
||||
|
||||
# Key Package Receipt CMS Content Type
|
||||
|
||||
id_ct_KP_keyPackageReceipt = univ.ObjectIdentifier('2.16.840.1.101.2.1.2.78.3')
|
||||
|
||||
class KeyPackageReceipt(univ.Sequence):
|
||||
pass
|
||||
|
||||
KeyPackageReceipt.componentType = namedtype.NamedTypes(
|
||||
namedtype.DefaultedNamedType('version', KeyPkgVersion().subtype(value='v2')),
|
||||
namedtype.NamedType('receiptOf', KeyPkgIdentifier()),
|
||||
namedtype.NamedType('receivedBy', SIREntityName())
|
||||
)
|
||||
|
||||
|
||||
# Key Package Receipt Request Attribute
|
||||
|
||||
class KeyPkgReceiptReq(univ.Sequence):
|
||||
pass
|
||||
|
||||
KeyPkgReceiptReq.componentType = namedtype.NamedTypes(
|
||||
namedtype.DefaultedNamedType('encryptReceipt', univ.Boolean().subtype(value=0)),
|
||||
namedtype.OptionalNamedType('receiptsFrom', SIREntityNames().subtype(
|
||||
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.NamedType('receiptsTo', SIREntityNames())
|
||||
)
|
||||
|
||||
|
||||
id_aa_KP_keyPkgIdAndReceiptReq = univ.ObjectIdentifier('2.16.840.1.101.2.1.5.65')
|
||||
|
||||
class KeyPkgIdentifierAndReceiptReq(univ.Sequence):
|
||||
pass
|
||||
|
||||
KeyPkgIdentifierAndReceiptReq.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('pkgID', KeyPkgID()),
|
||||
namedtype.OptionalNamedType('receiptReq', KeyPkgReceiptReq())
|
||||
)
|
||||
|
||||
|
||||
# Map of Attribute Type OIDs to Attributes are added to
|
||||
# the ones that are in rfc5652.py
|
||||
|
||||
_cmsAttributesMapUpdate = {
|
||||
id_aa_KP_keyPkgIdAndReceiptReq: KeyPkgIdentifierAndReceiptReq(),
|
||||
}
|
||||
|
||||
rfc5652.cmsAttributesMap.update(_cmsAttributesMapUpdate)
|
||||
|
||||
|
||||
# Map of CMC Content Type OIDs to CMC Content Types are added to
|
||||
# the ones that are in rfc5652.py
|
||||
|
||||
_cmsContentTypesMapUpdate = {
|
||||
id_ct_KP_keyPackageError: KeyPackageError(),
|
||||
id_ct_KP_keyPackageReceipt: KeyPackageReceipt(),
|
||||
}
|
||||
|
||||
rfc5652.cmsContentTypesMap.update(_cmsContentTypesMapUpdate)
|
||||
@@ -0,0 +1,32 @@
|
||||
# This file is being contributed to pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# IKEv2 Certificate Bundle
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc7296.txt
|
||||
|
||||
from pyasn1.type import namedtype
|
||||
from pyasn1.type import tag
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc5280
|
||||
|
||||
|
||||
class CertificateOrCRL(univ.Choice):
|
||||
pass
|
||||
|
||||
CertificateOrCRL.componentType = namedtype.NamedTypes(
|
||||
namedtype.NamedType('cert', rfc5280.Certificate().subtype(explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),
|
||||
namedtype.NamedType('crl', rfc5280.CertificateList().subtype(explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1)))
|
||||
)
|
||||
|
||||
|
||||
class CertificateBundle(univ.SequenceOf):
|
||||
pass
|
||||
|
||||
CertificateBundle.componentType = CertificateOrCRL()
|
||||
@@ -0,0 +1,20 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# BGPsec Router PKI Profile
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc8209.txt
|
||||
#
|
||||
|
||||
from pyasn1.type import univ
|
||||
|
||||
|
||||
id_kp = univ.ObjectIdentifier('1.3.6.1.5.5.7.3')
|
||||
|
||||
id_kp_bgpsec_router = id_kp + (30, )
|
||||
@@ -0,0 +1,52 @@
|
||||
#
|
||||
# This file is part of pyasn1-modules software.
|
||||
#
|
||||
# Created by Russ Housley with some assistance from asn1ate v.0.6.0.
|
||||
#
|
||||
# Copyright (c) 2019, Vigil Security, LLC
|
||||
# License: http://snmplabs.com/pyasn1/license.html
|
||||
#
|
||||
# Internationalized Email Addresses in X.509 Certificates
|
||||
#
|
||||
# ASN.1 source from:
|
||||
# https://www.rfc-editor.org/rfc/rfc8398.txt
|
||||
# https://www.rfc-editor.org/errata/eid5418
|
||||
#
|
||||
|
||||
from pyasn1.type import char
|
||||
from pyasn1.type import constraint
|
||||
from pyasn1.type import univ
|
||||
|
||||
from pyasn1_modules import rfc5280
|
||||
|
||||
MAX = float('inf')
|
||||
|
||||
|
||||
# SmtpUTF8Mailbox contains Mailbox as specified in Section 3.3 of RFC 6531
|
||||
|
||||
id_pkix = rfc5280.id_pkix
|
||||
|
||||
id_on = id_pkix + (8, )
|
||||
|
||||
id_on_SmtpUTF8Mailbox = id_on + (9, )
|
||||
|
||||
|
||||
class SmtpUTF8Mailbox(char.UTF8String):
|
||||
pass
|
||||
|
||||
SmtpUTF8Mailbox.subtypeSpec = constraint.ValueSizeConstraint(1, MAX)
|
||||
|
||||
|
||||
on_SmtpUTF8Mailbox = rfc5280.AnotherName()
|
||||
on_SmtpUTF8Mailbox['type-id'] = id_on_SmtpUTF8Mailbox
|
||||
on_SmtpUTF8Mailbox['value'] = SmtpUTF8Mailbox()
|
||||
|
||||
|
||||
# Map of Other Name OIDs to Other Name is added to the
|
||||
# ones that are in rfc5280.py
|
||||
|
||||
_anotherNameMapUpdate = {
|
||||
id_on_SmtpUTF8Mailbox: SmtpUTF8Mailbox(),
|
||||
}
|
||||
|
||||
rfc5280.anotherNameMap.update(_anotherNameMapUpdate)
|
||||
Reference in New Issue
Block a user