Adding a Required Attribute to a Signature

Viewed 36

I'm trying to add id-aa-signingCertificate to the required attributes, described the structures according to the rfc2634 standard


/*
SigningCertificate ::=  SEQUENCE {
       certs        SEQUENCE OF ESSCertID,
       policies     SEQUENCE OF PolicyInformation OPTIONAL
   }
ESSCertID ::=  SEQUENCE {
        certHash                 Hash,
        issuerSerial             IssuerSerial OPTIONAL
   }
   Hash ::= OCTET STRING -- SHA1 hash of entire certificate
   IssuerSerial ::= SEQUENCE {
        issuer                   GeneralNames,
        serialNumber             CertificateSerialNumber
   }
*/
type SignerCertificate struct {
    SigningCertificate SigningCertificate `asn1:"sequence"`
}

type SigningCertificate struct {
    ESSCertID       ESSCertID       `asn1:"sequence"`
    IssuerAndSerial issuerAndSerial `asn1:"optional"`
}

type ESSCertID struct {
    Hash []byte `asn1:"explicit,tag:16"`
}

When the attribute is added, the function works successfully, but the certificate is not parsed during verification. Probably the structure is not correctly described?

h := sha1.New()
    h.Write(cert.Raw)
    b := h.Sum(nil)
    ias, err := cert2issuerAndSerial(cert)
    if err != nil {
        return err
    }

    ss := SignerCertificate{
        SigningCertificate: SigningCertificate{
            ESSCertID: ESSCertID{
                Hash: b},
            IssuerAndSerial: ias},
    }

    attrs.Add(oidAttributeContentType, sd.sd.ContentInfo.ContentType)
    attrs.Add(oidAttributeMessageDigest, sd.messageDigest)
    attrs.Add(oidAttributeSigningTime, time.Now().UTC())
    attrs.Add(oidSigningCert, ss) // if you remove it, the certificate is recognized
0 Answers
Related