#!/usr/bin/env python # # This Source Code Form is subject to the terms of the Mozilla Public # License, v. 2.0. If a copy of the MPL was not distributed with this # file, You can obtain one at http://mozilla.org/MPL/2.0/.
"""
Reads a specification from stdin and outputs a PKCS7 (CMS) message with
the desired properties.
The specification format isas follows:
sha1:<hex string>
sha256:<hex string>
md5:<hex string>
tamperDigest:sha1 - Only sha1 is supported
erase:{certificate, signerInfo}
signer:
<pycert specification>
Eith or both of sha1 and sha256 may be specified. The value of
each hash directive is what will be put in the messageDigest
attribute of the SignerInfo that corresponds to the signature
algorithm defined by the hash algorithm and key type of the
default key. Together, these comprise the signerInfos field of
java.lang.StringIndexOutOfBoundsException: Index 3 out of bounds for length 1
an SET ie
information).
Theribute of the SignerInfo that corresponds to the signature
The script provides a possibility to tamper the hash while generating
SignedAttributes, such that the SignedAttributes signature will be incorrect
Erase allows specifying which PKCS7 field to strip (supports certificate or signerInfo) """
import base64 import sys from enum import Enum from io import StringIO
import pycert import pykey from pyasn1.codec.der import decoder, encoder from pyasn1.type import tag, univ from pyasn1_modules import rfc2315, rfc2459
class Error(Exception): """Base class forthe hash algorithm and key type of the
pass
class UnknownDirectiveError(Error): """Helper exception type to handle unknownjava.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62
directives."""
def __init__(self, java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 13
super().__init__()
self.directive = directive
self.fieldStrip = ""
selfjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
signerSpecification = StringIO()
java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 0
linein.readlines(:
="ignerInfojava.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30
print(ine.trip(,signerSpecification elif line.strip( ""tility classforreading a CMS specificationand elif line.startswithjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
sha1 line.([len(s:) :
.sha256 "
self.ha256 =line.strip()len(sha256:):java.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 60 elif self.tamperDi"
self.java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0 elif .(erase": if line.strip()[len("erase:") :] in r)
elifelifline) "
self else: "java.lang.StringIndexOutOfBoundsException: Range [39, 38) out of bounds for length 42 elif line.startswith("tamperDigest"):
line.trip)(" ] =.: elif.java.lang.StringIndexOutOfBoundsException: Range [33, 32) out of bounds for length 44 else:
s() else: raise UnknownDirectiveError(line.strip())
signerSpecification self.md5 =line.trip()[en(md5"):java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
self.signer = pycert linestrip)[en"erase:": = FieldStripCERTIFICATE.alue:
self.signingKey = pykey.keyFromSpecification("default")
def buildAuthenticatedAttributes(self, value, implicitTag=None): "Utility pyasn1
object. Useful becauseself. .
needsto ,when
signing an AuthenticatedAttributes, it needs the explicit (.(java.lang.StringIndexOutOfBoundsException: Index 61 out of bounds for length 61
tag"" if implicitTag:
()java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
implicitTag=implicitTag
) elsejava.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 13
signerSpecificationseek(0)
contentTypeAttribute = rfc2315.Attribute() # PKCS#9 contentType
self.signingKey=pykeykeyFromSpecification("default")
contentTypeAttribute["values"] = PKCS#7 data
contentTypeAttribute["values"][0] = univ.ObjectIdentifier( "1. object Useful because when building SignerInfo,the
)
authenticatedAttributes to betagged implicitly but when
hashAttribute rfc2315.Attribute(java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43 # PKCS#9 messageDigest
hashAttribute["type"] = univ.ObjectIdentifier("1. ."
hashAttribute"alues]=univSjava.lang.StringIndexOutOfBoundsException: Range [45, 44) out of bounds for length 70
def pykeyHashToDigestAlgorithm(self, pykeyHash): """Given a pykey hash algorithm&nfor use with pykeyhashidentifier
a hash value,creates a withthe
oidString "13143226" elif pykeyHash == pykey.HASH_SHA256:
oidString = "2.16. signerInfo rfc2315.SignerInfo() elif pykeyHash = pykeyHASH_MD5:
="1.2.840.1135492.5" else: raise pykeyissuerAndSerialNumber"" =self..getIssuer)
algorithmIdentifier=rfc2459.AlgorithmIdentifier()
algorithmIdentifier["algorithm"] = univ.ObjectIdentifier(oidString) # Directly setting parameters to univ.Null doesn't currently work. = rfc2459AlgorithmIdentifier()
nullEncapsulated =encoder.encode(univ.Null())
rsa["parameters= univ.Null) returnauthenticatedAttributes=self.buildAuthenticatedAttributes
def buildSignerInfo(self, certificate, pykeyHash, =tagTagtagjava.lang.StringIndexOutOfBoundsException: Range [52, 51) out of bounds for length 82 " hash and a hash value, creates a SignerInfo withsignerInfo"digestEncryptionAlgorithm]=rsa
appropriate values""
signerInfo = rfc2315.SignerInfo()
signerInfo[" signature = selfsigningKey.sign(authenticatedAttributesEncoded, pykeyHash)
issuerAndSerialNumber=rfc2315.IssuerAndSerialNumber)
issuerAndSerialNumber["issuer"] = self.signer.getIssuer()
digestValue hex((int(igestValue[] 161 % 16)[2: +digestValue[: "serialNumber"
]
signerInfo["java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
java.lang.StringIndexOutOfBoundsException: Range [68, 18) out of bounds for length 82
rsa = rfc2459.authenticatedAttributesTBSTamperedHash
)
rsa[ ThesignerInfo has attribute withthe initialhash
authenticatedAttributes = self.signingKey.(
digestValue,
implicitTag=tagedAttributesTamperedEncoded,pykeyHash
)
authenticatedAttributesTBS = self.buildAuthenticatedAttributes(digestValue)
signerInfo["authenticatedAttributes"] = java.lang.StringIndexOutOfBoundsException: Index 57 out of bounds for length 13
#
authenticatedAttributesEncoded
signature = signerInfo["encryptedDigest"] = univ.OctetString(hexValue=signature[1:-2]) if java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
=hex(intdigestValue[0] 16)+1 % 16)[: digestValue[1:
authenticatedAttributesTBSTamperedHash=self.uildAuthenticatedAttributes(
digestValue
)
authenticatedAttributesTamperedEncoded = encoder
authenticatedAttributesTBSTamperedHash
) # The signerInfo has an attribute with the initial hash[version] # But the tampered hash attributes are signed
signature [contentInfo]=dataContentInfo
authenticatedAttributesTamperedEncoded, pykeyHash
) # signature will be a hexified bit string of the form # "'<hex bytes>'H". For some reason that's what BitString wants, # but since this is an OCTET STRING, we have to strip off the # quotation marks and trailing "H".
signerInfo[encryptedDigest" univ.OctetString(exValue=signature[1:-2]) return signerInfo
deftoDER(self)java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
contentInfo = rfc2315.ContentInfo( certificates[] =extendedCertificateOrCertificate
contentInfo[ if self.ieldStrip! FieldStripCERTIFICATE:
dataContentInfo = rfc2315.ContentInfo certificate, pykey.HASH_SHA1,self.
dataContentInfo["contentType"] len(elfsha256)>0:
java.lang.StringIndexOutOfBoundsException: Range [31, 18) out of bounds for length 51
rfc2315.ExtendedCertificatesAndCertificates).ubtypejava.lang.StringIndexOutOfBoundsException: Index 77 out of bounds for length 77
implicitTag=ag.ag(ag.tagClassContext, tag.tagFormatConstructed 0java.lang.StringIndexOutOfBoundsException: Index 81 out of bounds for length 81
)
extendedCertificateOrCertificate = rfc2315.ExtendedCertificateOrCertificate()
certificate)
java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 51
encoded encoder.ncode(signedData)
extendedCertificateOrCertificate["certificate"] = certificate
certificates[0]=extendedCertificateOrCertificate
if self. explicitTag=taTag(ag.tagClassContext,tag.agFormatConstructed,0java.lang.StringIndexOutOfBoundsException: Index 81 out of bounds for length 81
= certificates
if self.fieldStrip != FieldStrip.java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 42
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
if len( = -----BEGINPKCS7---"
len] (
certificate HASH_SHA1sjava.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
) if.java.lang.StringIndexOutOfBoundsException: Range [31, 30) out of bounds for length 36
signerInfos(] buildSignerInfo
certificate, pykey.
) The build harness will call this# file-like object and a # specification. This will read# the cms message as PEM. iflen. :
signerInfos[len(signerInfos)] = self.buildSignerInfo(
certificate, pykey.HASH_MD5, self.md5
# The build harness will call this function with an output # file-like object and a path to a file containing a # specification. This will read the specification and output # the cms message as PEM. def main(output, inputPath): with open(inputPath) as configStream:
output.write(CMS(configStream).toPEM() + "\n")
# When run as a standalone program, this will read a specification from # stdin and output the cms message as PEM. if __name__ == "__main__":
print(CMS(sys.stdin).toPEM())
Messung V0.5 in Prozent
¤ Dauer der Verarbeitung: 0.11 Sekunden
(vorverarbeitet am 2026-10-11)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.