Class: Saro::Dat::DatSignature
- Inherits:
-
Object
- Object
- Saro::Dat::DatSignature
- Defined in:
- lib/saro/dat/signature.rb
Instance Attribute Summary collapse
-
#algorithm ⇒ Object
readonly
Returns the value of attribute algorithm.
-
#signing_key ⇒ Object
readonly
Returns the value of attribute signing_key.
-
#verifying_key ⇒ Object
readonly
Returns the value of attribute verifying_key.
Class Method Summary collapse
Instance Method Summary collapse
- #exports(verify_only = false) ⇒ Object
-
#initialize(algorithm, signing_key, verifying_key, config = nil) ⇒ DatSignature
constructor
A new instance of DatSignature.
- #pair ⇒ Object
- #sign(body) ⇒ Object
- #signable ⇒ Object
- #support_verify_only ⇒ Object
-
#verify(body, signature) ⇒ Object
Verifies a raw (already decoded) signature.
-
#verify_base64(body, signature_base64) ⇒ Object
Verifies a base64url-encoded signature.
Constructor Details
#initialize(algorithm, signing_key, verifying_key, config = nil) ⇒ DatSignature
Returns a new instance of DatSignature.
40 41 42 43 44 45 |
# File 'lib/saro/dat/signature.rb', line 40 def initialize(algorithm, signing_key, , config = nil) @algorithm = algorithm @signing_key = signing_key @verifying_key = @config = config || Saro::Dat.get_signature_config(algorithm) end |
Instance Attribute Details
#algorithm ⇒ Object (readonly)
Returns the value of attribute algorithm.
38 39 40 |
# File 'lib/saro/dat/signature.rb', line 38 def algorithm @algorithm end |
#signing_key ⇒ Object (readonly)
Returns the value of attribute signing_key.
38 39 40 |
# File 'lib/saro/dat/signature.rb', line 38 def signing_key @signing_key end |
#verifying_key ⇒ Object (readonly)
Returns the value of attribute verifying_key.
38 39 40 |
# File 'lib/saro/dat/signature.rb', line 38 def @verifying_key end |
Class Method Details
.generate(algorithm) ⇒ Object
98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 |
# File 'lib/saro/dat/signature.rb', line 98 def self.generate(algorithm) config = Saro::Dat.get_signature_config(algorithm) if config[:name] == "HMAC" key = OpenSSL::Random.random_bytes(config[:hmac_len]) new(algorithm, key, key, config) else key = OpenSSL::PKey::EC.generate(config[:curve]) begin key.check_key rescue OpenSSL::PKey::PKeyError, OpenSSL::PKey::ECError => e raise Saro::Dat::Error.new(Saro::Dat::ErrorCode::INTERNAL_UNKNOWN, "generated ecdsa key pair is invalid: #{e.}", cause: e) end new(algorithm, key, key, config) end end |
.imports(algorithm, base64_str) ⇒ Object
114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 |
# File 'lib/saro/dat/signature.rb', line 114 def self.imports(algorithm, base64_str) config = Saro::Dat.get_signature_config(algorithm) bytes_data = Saro::Dat::Util.decode_base64_url(base64_str) if config[:name] == "HMAC" if bytes_data.bytesize != config[:hmac_len] raise Saro::Dat::Error.new(Saro::Dat::ErrorCode::KEY_INVALID, "hmac key must be #{config[:hmac_len]} bytes, got #{bytes_data.bytesize}") end new(algorithm, bytes_data, bytes_data, config) else private_len = config[:private_len] public_len = config[:public_len] signing_key = nil = nil if bytes_data.bytesize == private_len + public_len private_bytes = bytes_data[0, private_len] public_bytes = bytes_data[private_len, public_len] d_value = OpenSSL::BN.new(private_bytes, 2) signing_key = create_ec_key(config[:curve], d_value, public_bytes) = signing_key elsif bytes_data.bytesize == public_len = create_ec_key(config[:curve], nil, bytes_data) else raise Saro::Dat::Error.new(Saro::Dat::ErrorCode::KEY_INVALID, "ecdsa key length matches neither private+public nor public") end new(algorithm, signing_key, , config) end end |
Instance Method Details
#exports(verify_only = false) ⇒ Object
147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 |
# File 'lib/saro/dat/signature.rb', line 147 def exports(verify_only = false) if verify_only && !support_verify_only raise Saro::Dat::Error.new(Saro::Dat::ErrorCode::KEY_VERIFY_ONLY_UNSUPPORTED, @algorithm.to_s) end if @config[:name] == "HMAC" Saro::Dat::Util.encode_base64_url_str(@verifying_key) else if verify_only || !@signing_key&.private_key public_bytes = @verifying_key.public_key.to_octet_string(:uncompressed) Saro::Dat::Util.encode_base64_url_str(public_bytes) else d_value = @signing_key.private_key curve_size = (@signing_key.group.degree + 7) / 8 d_bytes = d_value.to_s(2).rjust(curve_size, "\x00".b) public_bytes = @verifying_key.public_key.to_octet_string(:uncompressed) Saro::Dat::Util.encode_base64_url_str(d_bytes + public_bytes) end end end |
#pair ⇒ Object
242 243 244 |
# File 'lib/saro/dat/signature.rb', line 242 def pair @config[:name] == "ECDSA" end |
#sign(body) ⇒ Object
169 170 171 172 173 174 175 176 177 178 179 180 |
# File 'lib/saro/dat/signature.rb', line 169 def sign(body) raise Saro::Dat::Error.new(Saro::Dat::ErrorCode::SIG_KEY_MISSING, "this key is verify-only") unless @signing_key body = normalize_body(body) raise Saro::Dat::Error.new(Saro::Dat::ErrorCode::CONFIG_ARGUMENT_INVALID, "body to sign is empty") if body.nil? || body.empty? if @config[:name] == "HMAC" OpenSSL::HMAC.digest(@config[:hash], @signing_key, body) else signature_der = @signing_key.dsa_sign_asn1(OpenSSL::Digest.digest(@config[:hash], body)) der_to_raw_signature(signature_der) end end |
#signable ⇒ Object
238 239 240 |
# File 'lib/saro/dat/signature.rb', line 238 def signable !@signing_key.nil? end |
#support_verify_only ⇒ Object
246 247 248 |
# File 'lib/saro/dat/signature.rb', line 246 def support_verify_only @config[:name] == "ECDSA" end |
#verify(body, signature) ⇒ Object
Verifies a raw (already decoded) signature. Use #verify_base64 for a base64url-encoded signature: the branch used to be picked from the string's encoding tag, so a raw signature that merely carried a UTF-8 tag was silently run through the base64 decoder.
186 187 188 |
# File 'lib/saro/dat/signature.rb', line 186 def verify(body, signature) verify_bytes(body, signature) end |
#verify_base64(body, signature_base64) ⇒ Object
Verifies a base64url-encoded signature.
191 192 193 194 195 196 197 198 |
# File 'lib/saro/dat/signature.rb', line 191 def verify_base64(body, signature_base64) sig_bytes = begin Saro::Dat::Util.decode_base64_url(signature_base64) rescue Saro::Dat::Error => e raise Saro::Dat::Error.new(Saro::Dat::ErrorCode::SIG_MALFORMED, "signature is not base64url", cause: e) end verify_bytes(body, sig_bytes) end |