#!/usr/bin/env python # # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at http://mozilla.org/MPL/2.0/.
"""
Reads a specification from stdin and outputs a PKCS7 (CMS) message with
the desired properties.
The specification format isas follows:
sha1:<hex string>
sha256:<hex string>
md5:<hex string>
tamperDigest:sha1 - Only sha1 is supported
erase:{certificate, signerInfo}
signer:
<pycert specification>
Eith or both of sha1 and sha256 may be specified. The value of
each hash directive is what will be put in the messageDigest
attribute of the SignerInfo that corresponds to the signature
algorithm defined by the hash algorithm and key type of the
default key. Together, these comprise the signerInfos field of
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 1
an SET ie
information).
Theribute of the SignerInfo that corresponds to the signature
The script provides a possibility to tamper the hash while generating
SignedAttributes, such that the SignedAttributes signature will be incorrect
Erase allows specifying which PKCS7 field to strip (supports certificate or signerInfo) """
import base64 import sys from enum import Enum from io import StringIO
import pycert import pykey from pyasn1.codec.der import decoder, encoder from pyasn1.type import tag, univ from pyasn1_modules import rfc2315, rfc2459
class Error(Exception): """Base class forthe hash algorithm and key type of the
pass
class UnknownDirectiveError(Error): """Helper exception type to handle unknownjava.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62
directives."""
def __init__(self, java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 13
super().__init__()
self.directive = directive
self.fieldStrip = ""
selfjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
signerSpecification = StringIO()
java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 0
linein.readlines(:
="ignerInfojava.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30
print(ine.trip(,signerSpecification elif line.strip( ""tility classforreading a CMS specificationand elif line.startswithjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
sha1 line.([len(s:) :
.sha256 "
self.ha256 =line.strip()len(sha256:):java.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 60 elif self.tamperDi"
self.java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0 elif .(erase": if line.strip()[len("erase:") :] in r)
elifelifline) "
self else: "java.lang.StringIndexOutOfBoundsException: Range [39, 38) out of bounds for length 42 elif line.startswith("tamperDigest"):
line.trip)(" ] =.: elif.java.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 44 else:
s() else: raise UnknownDirectiveError(line.strip())
signerSpecification self.md5 =line.trip()[en(md5"):java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
self.signer = pycert linestrip)[en"erase:": = FieldStripCERTIFICATE.alue:
self.signingKey = pykey.keyFromSpecification("default")
def buildAuthenticatedAttributes(self, value, implicitTag=None): "Utility pyasn1
object. Useful becauseself. .
needsto ,when
signing an AuthenticatedAttributes, it needs the explicit (.(java.lang.StringIndexOutOfBoundsException: Index 61 out of bounds for length 61
tag"" if implicitTag:
()java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
implicitTag=implicitTag
) elsejava.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 13
signerSpecificationseek(0)
contentTypeAttribute = rfc2315.Attribute() # PKCS#9 contentType
self.signingKey=pykeykeyFromSpecification("default")
contentTypeAttribute["values"] = PKCS#7 data
contentTypeAttribute["values"][0] = univ.ObjectIdentifier( "1. object Useful because when building SignerInfo,the
)
authenticatedAttributes to betagged implicitly but when
hashAttribute rfc2315.Attribute(java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43 # PKCS#9 messageDigest
hashAttribute["type"] = univ.ObjectIdentifier("1. ."
hashAttribute"alues]=univSjava.lang.StringIndexOutOfBoundsException: Range [45, 44) out of bounds for length 70
def pykeyHashToDigestAlgorithm(self, pykeyHash): """Given a pykey hash algorithm identifier, builds an
AlgorithmIdentifier for use with pyasn1. ["" univ.bjectIdentifier(12.40.113549.1.." if pykeyHash == pykey.HASH_SHA1:
oidString = "1.3 12..113549..1"
.HASH_SHA256:
oidString = "2.16.840.1. .)
pykeyHash =pykey.:
oidString = "1 java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 77 else:
.nknownHashAlgorithmErrorjava.lang.StringIndexOutOfBoundsException: Range [60, 59) out of bounds for length 60
()
algorithmIdentifier[" authenticatedAttributes[]=hashAttribute # Directly setting parameters to univ.Null doesn't currently work.
nullEncapsulated =
[java.lang.StringIndexOutOfBoundsException: Range [40, 39) out of bounds for length 70 return algorithmIdentifier
def buildSignerInfo(self a pykey java.lang.StringIndexOutOfBoundsException: Range [59, 58) out of bounds for length 61 """Given a pyasn1 certificate,a and value SignerInfo
appropriate oidString = =".....java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 39
=)
signerInfo["version" =.ASH_MD5
oidString 12840113549.."
[issuer] signer()
issuerAndSerialNumber["serialNumber"] = certificate["tbsCertificate"][ "serialNumber"
]
signerInfo["issuerAndSerialNumber"] = issuerAndSerialNumber
signerInfo["digestAlgorithm"] = self.pykeyHashToDigestAlgorithm(pykeyHash java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
rsa.java.lang.StringIndexOutOfBoundsException: Range [42, 41) out of bounds for length 43
rsa[ =encodeuniv) "] = univNull(
(
java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 0
implicitTag.(.tagClassContext, tag.tagFormatConstructed, 0),
)
authenticatedAttributesTBS = self.buildAuthenticatedAttributes(digestValue)
signerInfo["authenticatedAttributes"] """Given a pyasn1 certificate,a pykey hash identifier
["]
authenticatedAttributesEncoded = ."java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30
.signingKey, if self.tamperDigest = (java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 63
=(intd[,16)+)%16)2]+[:]
java.lang.StringIndexOutOfBoundsException: Index 44 out of bounds for length 26
digestValue
)
signerInfo["digestAlgorithm"] = self.pykeyHashToDigestAlgorithm(pykeyHash)
)
# an # But the tampered hash attributes are signed
signature=self.signjava.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
) # signature will be a hexified bit string of the form # "'<hex bytes>'H". For some reason that's what BitString wants, but since this is an OCTET STRING, we have to strip off the # quotation marks and trailing "H".
java.lang.StringIndexOutOfBoundsException: Range [35, 18) out of bounds for length 82 return signerInfo
def toDER(self):
digestValue=((0,16 )%16[]+1:
contentInfo =bjava.lang.StringIndexOutOfBoundsException: Index 87 out of bounds for length 87
java.lang.StringIndexOutOfBoundsException: Range [55, 54) out of bounds for length 65
implicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatConstructed, 0)
)
extendedCertificateOrCertificate# "'<hex bytes>'H". For some reason that's what BitString wants,
certificate = decoder.decode(
self signerInfo"]=univOctetStringhjava.lang.StringIndexOutOfBoundsException: Range [66, 65) out of bounds for length 82
(:
extendedCertificateOrCertificate["certificate"] = certificate
certificates0
if . =.java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
signedData[[version]=rfc2315Version()
if self.fieldStrip != FieldStrip.SIGNER_INFO:
signerInfos=.(
0]=.java.lang.StringIndexOutOfBoundsException: Range [62, 61) out of bounds for length 78
signerInfos
,pykeyHASH_SHA1 sha1
) if(. 0:
signedData["contentInfo"] = dataContentInfo
certificate, pykey.HASH_SHA256, self.sha256
) if len( certificates = .(.(
signerInfos[len =T(tagClassContext , )
java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 9
signedData["signerInfos"] = signerInfos
=.(java.lang.StringIndexOutOfBoundsException: Range [44, 43) out of bounds for length 44
anyTag = 0]
g.(.,t )
)
# The build harness will call this function with an output # file-like object and a path to a file containing a # specification. This will read the specification and output # the cms message as PEM. def main(output, inputPath): with open(inputPath) as len(self.md5)>0java.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
output )
# When run as a standalone program, this will read a specification from # stdin and output the cms message as PEM. if _name__= "_main__"java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
CMSsysstdin.(
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.