X509V2AttributeCertificateGenerator.cs 6.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207
  1. #if !BESTHTTP_DISABLE_ALTERNATE_SSL && (!UNITY_WEBGL || UNITY_EDITOR)
  2. #pragma warning disable
  3. using System;
  4. using System.Collections;
  5. using System.IO;
  6. using BestHTTP.SecureProtocol.Org.BouncyCastle.Asn1;
  7. using BestHTTP.SecureProtocol.Org.BouncyCastle.Asn1.X509;
  8. using BestHTTP.SecureProtocol.Org.BouncyCastle.Crypto;
  9. using BestHTTP.SecureProtocol.Org.BouncyCastle.Crypto.Operators;
  10. using BestHTTP.SecureProtocol.Org.BouncyCastle.Math;
  11. using BestHTTP.SecureProtocol.Org.BouncyCastle.Security;
  12. using BestHTTP.SecureProtocol.Org.BouncyCastle.Security.Certificates;
  13. using BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities;
  14. namespace BestHTTP.SecureProtocol.Org.BouncyCastle.X509
  15. {
  16. /// <remarks>Class to produce an X.509 Version 2 AttributeCertificate.</remarks>
  17. public class X509V2AttributeCertificateGenerator
  18. {
  19. private readonly X509ExtensionsGenerator extGenerator = new X509ExtensionsGenerator();
  20. private V2AttributeCertificateInfoGenerator acInfoGen;
  21. private DerObjectIdentifier sigOID;
  22. private AlgorithmIdentifier sigAlgId;
  23. private string signatureAlgorithm;
  24. public X509V2AttributeCertificateGenerator()
  25. {
  26. acInfoGen = new V2AttributeCertificateInfoGenerator();
  27. }
  28. /// <summary>Reset the generator</summary>
  29. public void Reset()
  30. {
  31. acInfoGen = new V2AttributeCertificateInfoGenerator();
  32. extGenerator.Reset();
  33. }
  34. /// <summary>Set the Holder of this Attribute Certificate.</summary>
  35. public void SetHolder(
  36. AttributeCertificateHolder holder)
  37. {
  38. acInfoGen.SetHolder(holder.holder);
  39. }
  40. /// <summary>Set the issuer.</summary>
  41. public void SetIssuer(
  42. AttributeCertificateIssuer issuer)
  43. {
  44. acInfoGen.SetIssuer(AttCertIssuer.GetInstance(issuer.form));
  45. }
  46. /// <summary>Set the serial number for the certificate.</summary>
  47. public void SetSerialNumber(
  48. BigInteger serialNumber)
  49. {
  50. acInfoGen.SetSerialNumber(new DerInteger(serialNumber));
  51. }
  52. public void SetNotBefore(
  53. DateTime date)
  54. {
  55. acInfoGen.SetStartDate(new DerGeneralizedTime(date));
  56. }
  57. public void SetNotAfter(
  58. DateTime date)
  59. {
  60. acInfoGen.SetEndDate(new DerGeneralizedTime(date));
  61. }
  62. /// <summary>
  63. /// Set the signature algorithm. This can be either a name or an OID, names
  64. /// are treated as case insensitive.
  65. /// </summary>
  66. /// <param name="signatureAlgorithm">The algorithm name.</param>
  67. public void SetSignatureAlgorithm(
  68. string signatureAlgorithm)
  69. {
  70. this.signatureAlgorithm = signatureAlgorithm;
  71. try
  72. {
  73. sigOID = X509Utilities.GetAlgorithmOid(signatureAlgorithm);
  74. }
  75. catch (Exception)
  76. {
  77. throw new ArgumentException("Unknown signature type requested");
  78. }
  79. sigAlgId = X509Utilities.GetSigAlgID(sigOID, signatureAlgorithm);
  80. acInfoGen.SetSignature(sigAlgId);
  81. }
  82. /// <summary>Add an attribute.</summary>
  83. public void AddAttribute(
  84. X509Attribute attribute)
  85. {
  86. acInfoGen.AddAttribute(AttributeX509.GetInstance(attribute.ToAsn1Object()));
  87. }
  88. public void SetIssuerUniqueId(
  89. bool[] iui)
  90. {
  91. // TODO convert bool array to bit string
  92. //acInfoGen.SetIssuerUniqueID(iui);
  93. throw BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.CreateNotImplementedException("SetIssuerUniqueId()");
  94. }
  95. /// <summary>Add a given extension field for the standard extensions tag.</summary>
  96. public void AddExtension(
  97. string oid,
  98. bool critical,
  99. Asn1Encodable extensionValue)
  100. {
  101. extGenerator.AddExtension(new DerObjectIdentifier(oid), critical, extensionValue);
  102. }
  103. /// <summary>
  104. /// Add a given extension field for the standard extensions tag.
  105. /// The value parameter becomes the contents of the octet string associated
  106. /// with the extension.
  107. /// </summary>
  108. public void AddExtension(
  109. string oid,
  110. bool critical,
  111. byte[] extensionValue)
  112. {
  113. extGenerator.AddExtension(new DerObjectIdentifier(oid), critical, extensionValue);
  114. }
  115. /// <summary>
  116. /// Generate an X509 certificate, based on the current issuer and subject.
  117. /// </summary>
  118. public IX509AttributeCertificate Generate(
  119. AsymmetricKeyParameter privateKey)
  120. {
  121. return Generate(privateKey, null);
  122. }
  123. /// <summary>
  124. /// Generate an X509 certificate, based on the current issuer and subject,
  125. /// using the supplied source of randomness, if required.
  126. /// </summary>
  127. public IX509AttributeCertificate Generate(
  128. AsymmetricKeyParameter privateKey,
  129. SecureRandom random)
  130. {
  131. return Generate(new Asn1SignatureFactory(signatureAlgorithm, privateKey, random));
  132. }
  133. /// <summary>
  134. /// Generate a new X.509 Attribute Certificate using the passed in SignatureCalculator.
  135. /// </summary>
  136. /// <param name="signatureCalculatorFactory">A signature calculator factory with the necessary algorithm details.</param>
  137. /// <returns>An IX509AttributeCertificate.</returns>
  138. public IX509AttributeCertificate Generate(ISignatureFactory signatureCalculatorFactory)
  139. {
  140. if (!extGenerator.IsEmpty)
  141. {
  142. acInfoGen.SetExtensions(extGenerator.Generate());
  143. }
  144. AlgorithmIdentifier sigAlgID = (AlgorithmIdentifier)signatureCalculatorFactory.AlgorithmDetails;
  145. acInfoGen.SetSignature(sigAlgID);
  146. AttributeCertificateInfo acInfo = acInfoGen.GenerateAttributeCertificateInfo();
  147. byte[] encoded = acInfo.GetDerEncoded();
  148. IStreamCalculator streamCalculator = signatureCalculatorFactory.CreateCalculator();
  149. streamCalculator.Stream.Write(encoded, 0, encoded.Length);
  150. BestHTTP.SecureProtocol.Org.BouncyCastle.Utilities.Platform.Dispose(streamCalculator.Stream);
  151. try
  152. {
  153. DerBitString signatureValue = new DerBitString(((IBlockResult)streamCalculator.GetResult()).Collect());
  154. return new X509V2AttributeCertificate(new AttributeCertificate(acInfo, sigAlgID, signatureValue));
  155. }
  156. catch (Exception e)
  157. {
  158. // TODO
  159. // throw new ExtCertificateEncodingException("constructed invalid certificate", e);
  160. throw new CertificateEncodingException("constructed invalid certificate", e);
  161. }
  162. }
  163. /// <summary>
  164. /// Allows enumeration of the signature names supported by the generator.
  165. /// </summary>
  166. public IEnumerable SignatureAlgNames
  167. {
  168. get { return X509Utilities.GetAlgNames(); }
  169. }
  170. }
  171. }
  172. #pragma warning restore
  173. #endif