BcTlsCertificate.cs 3.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101
  1. #if !BESTHTTP_DISABLE_ALTERNATE_SSL && (!UNITY_WEBGL || UNITY_EDITOR)
  2. #pragma warning disable
  3. using System;
  4. using System.IO;
  5. using Best.HTTP.SecureProtocol.Org.BouncyCastle.Asn1;
  6. using Best.HTTP.SecureProtocol.Org.BouncyCastle.Asn1.X509;
  7. using Best.HTTP.SecureProtocol.Org.BouncyCastle.Math;
  8. using Best.HTTP.SecureProtocol.Org.BouncyCastle.Utilities;
  9. namespace Best.HTTP.SecureProtocol.Org.BouncyCastle.Tls.Crypto.Impl.BC
  10. {
  11. /// <summary>Implementation class for a single X.509 certificate based on the BC light-weight API.</summary>
  12. public class BcTlsCertificate
  13. : BcTlsRawKeyCertificate
  14. {
  15. /// <exception cref="IOException"/>
  16. public static BcTlsCertificate Convert(BcTlsCrypto crypto, TlsCertificate certificate)
  17. {
  18. if (certificate is BcTlsCertificate)
  19. return (BcTlsCertificate)certificate;
  20. return new BcTlsCertificate(crypto, certificate.GetEncoded());
  21. }
  22. /// <exception cref="IOException"/>
  23. public static X509CertificateStructure ParseCertificate(byte[] encoding)
  24. {
  25. try
  26. {
  27. Asn1Object asn1 = TlsUtilities.ReadAsn1Object(encoding);
  28. return X509CertificateStructure.GetInstance(asn1);
  29. }
  30. catch (Exception e)
  31. {
  32. throw new TlsFatalAlert(AlertDescription.bad_certificate, e);
  33. }
  34. }
  35. protected readonly X509CertificateStructure m_certificate;
  36. /// <exception cref="IOException"/>
  37. public BcTlsCertificate(BcTlsCrypto crypto, byte[] encoding)
  38. : this(crypto, ParseCertificate(encoding))
  39. {
  40. }
  41. public BcTlsCertificate(BcTlsCrypto crypto, X509CertificateStructure certificate)
  42. : base(crypto, certificate.SubjectPublicKeyInfo)
  43. {
  44. m_certificate = certificate;
  45. }
  46. public virtual X509CertificateStructure X509CertificateStructure => m_certificate;
  47. /// <exception cref="IOException"/>
  48. public override byte[] GetEncoded()
  49. {
  50. return m_certificate.GetEncoded(Asn1Encodable.Der);
  51. }
  52. /// <exception cref="IOException"/>
  53. public override byte[] GetExtension(DerObjectIdentifier extensionOid)
  54. {
  55. X509Extensions extensions = m_certificate.TbsCertificate.Extensions;
  56. if (extensions != null)
  57. {
  58. X509Extension extension = extensions.GetExtension(extensionOid);
  59. if (extension != null)
  60. {
  61. return Arrays.Clone(extension.Value.GetOctets());
  62. }
  63. }
  64. return null;
  65. }
  66. public override BigInteger SerialNumber => m_certificate.SerialNumber.Value;
  67. public override string SigAlgOid => m_certificate.SignatureAlgorithm.Algorithm.Id;
  68. public override Asn1Encodable GetSigAlgParams() => m_certificate.SignatureAlgorithm.Parameters;
  69. protected override bool SupportsKeyUsage(int keyUsageBits)
  70. {
  71. X509Extensions exts = m_certificate.TbsCertificate.Extensions;
  72. if (exts != null)
  73. {
  74. KeyUsage ku = KeyUsage.FromExtensions(exts);
  75. if (ku != null)
  76. {
  77. int bits = ku.GetBytes()[0] & 0xff;
  78. if ((bits & keyUsageBits) != keyUsageBits)
  79. return false;
  80. }
  81. }
  82. return true;
  83. }
  84. }
  85. }
  86. #pragma warning restore
  87. #endif