I'm trying to add id-aa-signingCertificate to the required attributes, described the structures according to the rfc2634 standard
/*
SigningCertificate ::= SEQUENCE {
certs SEQUENCE OF ESSCertID,
policies SEQUENCE OF PolicyInformation OPTIONAL
}
ESSCertID ::= SEQUENCE {
certHash Hash,
issuerSerial IssuerSerial OPTIONAL
}
Hash ::= OCTET STRING -- SHA1 hash of entire certificate
IssuerSerial ::= SEQUENCE {
issuer GeneralNames,
serialNumber CertificateSerialNumber
}
*/
type SignerCertificate struct {
SigningCertificate SigningCertificate `asn1:"sequence"`
}
type SigningCertificate struct {
ESSCertID ESSCertID `asn1:"sequence"`
IssuerAndSerial issuerAndSerial `asn1:"optional"`
}
type ESSCertID struct {
Hash []byte `asn1:"explicit,tag:16"`
}
When the attribute is added, the function works successfully, but the certificate is not parsed during verification. Probably the structure is not correctly described?
h := sha1.New()
h.Write(cert.Raw)
b := h.Sum(nil)
ias, err := cert2issuerAndSerial(cert)
if err != nil {
return err
}
ss := SignerCertificate{
SigningCertificate: SigningCertificate{
ESSCertID: ESSCertID{
Hash: b},
IssuerAndSerial: ias},
}
attrs.Add(oidAttributeContentType, sd.sd.ContentInfo.ContentType)
attrs.Add(oidAttributeMessageDigest, sd.messageDigest)
attrs.Add(oidAttributeSigningTime, time.Now().UTC())
attrs.Add(oidSigningCert, ss) // if you remove it, the certificate is recognized