x509-validation 1.6.8 → 1.6.9
raw patch · 4 files changed
+15/−50 lines, 4 filesdep ~x509PVP ok
version bump matches the API change (PVP)
Dependency ranges changed: x509
API changes (from Hackage documentation)
+ Data.X509.Validation: SignatureFailed :: SignatureFailure -> SignatureVerification
+ Data.X509.Validation: SignaturePass :: SignatureVerification
+ Data.X509.Validation: data SignatureVerification
+ Data.X509.Validation: verifySignature :: SignatureALG -> PubKey -> ByteString -> ByteString -> SignatureVerification
+ Data.X509.Validation: verifySignedSignature :: (Show a, Eq a, ASN1Object a) => SignedExact a -> PubKey -> SignatureVerification
Files
- Data/X509/Validation.hs +2/−0
- Data/X509/Validation/Signature.hs +8/−41
- Tests/Certificate.hs +4/−8
- x509-validation.cabal +1/−1
Data/X509/Validation.hs view
@@ -27,6 +27,8 @@ , getFingerprint -- * Cache , module Data.X509.Validation.Cache+ -- * Signature verification+ , module Data.X509.Validation.Signature ) where import Control.Applicative
Data/X509/Validation/Signature.hs view
@@ -18,15 +18,12 @@ import qualified Crypto.PubKey.RSA.PSS as PSS import qualified Crypto.PubKey.DSA as DSA import qualified Crypto.PubKey.ECC.Types as ECC-import qualified Crypto.PubKey.ECC.Prim as ECC import qualified Crypto.PubKey.ECC.ECDSA as ECDSA import Crypto.Hash-import Crypto.Number.Serialize (os2ip) import Data.ByteString (ByteString)-import qualified Data.ByteString as B import Data.X509-import Data.List (find)+import Data.X509.EC import Data.ASN1.Types import Data.ASN1.Encoding import Data.ASN1.BinaryEncoding@@ -126,48 +123,18 @@ verifyECDSA :: HashALG -> PubKeyEC -> Maybe (ByteString -> ByteString -> Bool) verifyECDSA hashALG key =- case key of- PubKeyEC_Named curveName pub -> verifyCurve curveName pub- PubKeyEC_Prime {} ->- case find matchPrimeCurve $ enumFrom $ toEnum 0 of- Nothing -> Nothing- Just curveName -> verifyCurve curveName (pubkeyEC_pub key)+ ecPubKeyCurveName key >>= verifyCurve (pubkeyEC_pub key) where- matchPrimeCurve c =- case ECC.getCurveByName c of- ECC.CurveFP (ECC.CurvePrime p cc) ->- ECC.ecc_a cc == pubkeyEC_a key &&- ECC.ecc_b cc == pubkeyEC_b key &&- ECC.ecc_n cc == pubkeyEC_order key &&- p == pubkeyEC_prime key- _ -> False-- verifyCurve curveName pub = Just $ \msg sigBS ->+ verifyCurve pub curveName = Just $ \msg sigBS -> case decodeASN1' BER sigBS of Left _ -> False Right [Start Sequence,IntVal r,IntVal s,End Sequence] ->- case unserializePoint (ECC.getCurveByName curveName) pub of- Nothing -> False- Just pubkey -> (ecdsaVerify hashALG) pubkey (ECDSA.Signature r s) msg+ let curve = ECC.getCurveByName curveName+ in case unserializePoint curve pub of+ Nothing -> False+ Just p -> let pubkey = ECDSA.PublicKey curve p+ in (ecdsaVerify hashALG) pubkey (ECDSA.Signature r s) msg Right _ -> False-- unserializePoint curve (SerializedPoint bs) =- case B.uncons bs of- Nothing -> Nothing- Just (ptFormat, input) ->- case ptFormat of- 4 -> if B.length input /= 2 * bytes- then Nothing- else- let (x, y) = B.splitAt bytes input- p = ECC.Point (os2ip x) (os2ip y)- in if ECC.isPointValid curve p- then Just $ ECDSA.PublicKey curve p- else Nothing- -- 2 and 3 for compressed format.- _ -> Nothing- where bits = ECC.curveSizeBits curve- bytes = (bits + 7) `div` 8 ecdsaVerify HashMD2 = ECDSA.verify MD2 ecdsaVerify HashMD5 = ECDSA.verify MD5
Tests/Certificate.hs view
@@ -29,12 +29,11 @@ import Control.Applicative import Crypto.Hash.Algorithms-import Crypto.Number.Generate import Crypto.Number.Serialize import qualified Crypto.PubKey.DSA as DSA import qualified Crypto.PubKey.ECC.ECDSA as ECDSA-import qualified Crypto.PubKey.ECC.Prim as ECC+import qualified Crypto.PubKey.ECC.Generate as ECC import qualified Crypto.PubKey.ECC.Types as ECC import qualified Crypto.PubKey.RSA as RSA import qualified Crypto.PubKey.RSA.PKCS15 as RSA@@ -110,12 +109,9 @@ let y = DSA.calculatePublic params x return (alg, DSA.PublicKey params y, DSA.PrivateKey params x) generateKeys alg@(AlgEC name _) = do- d <- generateBetween 1 (n - 1)- let p = ECC.pointBaseMul curve d- return (alg, ECDSA.PublicKey curve p, ECDSA.PrivateKey curve d)- where- curve = ECC.getCurveByName name- n = ECC.ecc_n . ECC.common_curve $ curve+ let curve = ECC.getCurveByName name+ (pub, priv) <- ECC.generate curve+ return (alg, pub, priv) generateRSAKeys :: Alg RSA.PublicKey RSA.PrivateKey -> Int
x509-validation.cabal view
@@ -1,5 +1,5 @@ Name: x509-validation-version: 1.6.8+version: 1.6.9 Description: X.509 Certificate and CRL validation License: BSD3 License-file: LICENSE