index.es.js 756 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152515351545155515651575158515951605161516251635164516551665167516851695170517151725173517451755176517751785179518051815182518351845185518651875188518951905191519251935194519551965197519851995200520152025203520452055206520752085209521052115212521352145215521652175218521952205221522252235224522552265227522852295230523152325233523452355236523752385239524052415242524352445245524652475248524952505251525252535254525552565257525852595260526152625263526452655266526752685269527052715272527352745275527652775278527952805281528252835284528552865287528852895290529152925293529452955296529752985299530053015302530353045305530653075308530953105311531253135314531553165317531853195320532153225323532453255326532753285329533053315332533353345335533653375338533953405341534253435344534553465347534853495350535153525353535453555356535753585359536053615362536353645365536653675368536953705371537253735374537553765377537853795380538153825383538453855386538753885389539053915392539353945395539653975398539954005401540254035404540554065407540854095410541154125413541454155416541754185419542054215422542354245425542654275428542954305431543254335434543554365437543854395440544154425443544454455446544754485449545054515452545354545455545654575458545954605461546254635464546554665467546854695470547154725473547454755476547754785479548054815482548354845485548654875488548954905491549254935494549554965497549854995500550155025503550455055506550755085509551055115512551355145515551655175518551955205521552255235524552555265527552855295530553155325533553455355536553755385539554055415542554355445545554655475548554955505551555255535554555555565557555855595560556155625563556455655566556755685569557055715572557355745575557655775578557955805581558255835584558555865587558855895590559155925593559455955596559755985599560056015602560356045605560656075608560956105611561256135614561556165617561856195620562156225623562456255626562756285629563056315632563356345635563656375638563956405641564256435644564556465647564856495650565156525653565456555656565756585659566056615662566356645665566656675668566956705671567256735674567556765677567856795680568156825683568456855686568756885689569056915692569356945695569656975698569957005701570257035704570557065707570857095710571157125713571457155716571757185719572057215722572357245725572657275728572957305731573257335734573557365737573857395740574157425743574457455746574757485749575057515752575357545755575657575758575957605761576257635764576557665767576857695770577157725773577457755776577757785779578057815782578357845785578657875788578957905791579257935794579557965797579857995800580158025803580458055806580758085809581058115812581358145815581658175818581958205821582258235824582558265827582858295830583158325833583458355836583758385839584058415842584358445845584658475848584958505851585258535854585558565857585858595860586158625863586458655866586758685869587058715872587358745875587658775878587958805881588258835884588558865887588858895890589158925893589458955896589758985899590059015902590359045905590659075908590959105911591259135914591559165917591859195920592159225923592459255926592759285929593059315932593359345935593659375938593959405941594259435944594559465947594859495950595159525953595459555956595759585959596059615962596359645965596659675968596959705971597259735974597559765977597859795980598159825983598459855986598759885989599059915992599359945995599659975998599960006001600260036004600560066007600860096010601160126013601460156016601760186019602060216022602360246025602660276028602960306031603260336034603560366037603860396040604160426043604460456046604760486049605060516052605360546055605660576058605960606061606260636064606560666067606860696070607160726073607460756076607760786079608060816082608360846085608660876088608960906091609260936094609560966097609860996100610161026103610461056106610761086109611061116112611361146115611661176118611961206121612261236124612561266127612861296130613161326133613461356136613761386139614061416142614361446145614661476148614961506151615261536154615561566157615861596160616161626163616461656166616761686169617061716172617361746175617661776178617961806181618261836184618561866187618861896190619161926193619461956196619761986199620062016202620362046205620662076208620962106211621262136214621562166217621862196220622162226223622462256226622762286229623062316232623362346235623662376238623962406241624262436244624562466247624862496250625162526253625462556256625762586259626062616262626362646265626662676268626962706271627262736274627562766277627862796280628162826283628462856286628762886289629062916292629362946295629662976298629963006301630263036304630563066307630863096310631163126313631463156316631763186319632063216322632363246325632663276328632963306331633263336334633563366337633863396340634163426343634463456346634763486349635063516352635363546355635663576358635963606361636263636364636563666367636863696370637163726373637463756376637763786379638063816382638363846385638663876388638963906391639263936394639563966397639863996400640164026403640464056406640764086409641064116412641364146415641664176418641964206421642264236424642564266427642864296430643164326433643464356436643764386439644064416442644364446445644664476448644964506451645264536454645564566457645864596460646164626463646464656466646764686469647064716472647364746475647664776478647964806481648264836484648564866487648864896490649164926493649464956496649764986499650065016502650365046505650665076508650965106511651265136514651565166517651865196520652165226523652465256526652765286529653065316532653365346535653665376538653965406541654265436544654565466547654865496550655165526553655465556556655765586559656065616562656365646565656665676568656965706571657265736574657565766577657865796580658165826583658465856586658765886589659065916592659365946595659665976598659966006601660266036604660566066607660866096610661166126613661466156616661766186619662066216622662366246625662666276628662966306631663266336634663566366637663866396640664166426643664466456646664766486649665066516652665366546655665666576658665966606661666266636664666566666667666866696670667166726673667466756676667766786679668066816682668366846685668666876688668966906691669266936694669566966697669866996700670167026703670467056706670767086709671067116712671367146715671667176718671967206721672267236724672567266727672867296730673167326733673467356736673767386739674067416742674367446745674667476748674967506751675267536754675567566757675867596760676167626763676467656766676767686769677067716772677367746775677667776778677967806781678267836784678567866787678867896790679167926793679467956796679767986799680068016802680368046805680668076808680968106811681268136814681568166817681868196820682168226823682468256826682768286829683068316832683368346835683668376838683968406841684268436844684568466847684868496850685168526853685468556856685768586859686068616862686368646865686668676868686968706871687268736874687568766877687868796880688168826883688468856886688768886889689068916892689368946895689668976898689969006901690269036904690569066907690869096910691169126913691469156916691769186919692069216922692369246925692669276928692969306931693269336934693569366937693869396940694169426943694469456946694769486949695069516952695369546955695669576958695969606961696269636964696569666967696869696970697169726973697469756976697769786979698069816982698369846985698669876988698969906991699269936994699569966997699869997000700170027003700470057006700770087009701070117012701370147015701670177018701970207021702270237024702570267027702870297030703170327033703470357036703770387039704070417042704370447045704670477048704970507051705270537054705570567057705870597060706170627063706470657066706770687069707070717072707370747075707670777078707970807081708270837084708570867087708870897090709170927093709470957096709770987099710071017102710371047105710671077108710971107111711271137114711571167117711871197120712171227123712471257126712771287129713071317132713371347135713671377138713971407141714271437144714571467147714871497150715171527153715471557156715771587159716071617162716371647165716671677168716971707171717271737174717571767177717871797180718171827183718471857186718771887189719071917192719371947195719671977198719972007201720272037204720572067207720872097210721172127213721472157216721772187219722072217222722372247225722672277228722972307231723272337234723572367237723872397240724172427243724472457246724772487249725072517252725372547255725672577258725972607261726272637264726572667267726872697270727172727273727472757276727772787279728072817282728372847285728672877288728972907291729272937294729572967297729872997300730173027303730473057306730773087309731073117312731373147315731673177318731973207321732273237324732573267327732873297330733173327333733473357336733773387339734073417342734373447345734673477348734973507351735273537354735573567357735873597360736173627363736473657366736773687369737073717372737373747375737673777378737973807381738273837384738573867387738873897390739173927393739473957396739773987399740074017402740374047405740674077408740974107411741274137414741574167417741874197420742174227423742474257426742774287429743074317432743374347435743674377438743974407441744274437444744574467447744874497450745174527453745474557456745774587459746074617462746374647465746674677468746974707471747274737474747574767477747874797480748174827483748474857486748774887489749074917492749374947495749674977498749975007501750275037504750575067507750875097510751175127513751475157516751775187519752075217522752375247525752675277528752975307531753275337534753575367537753875397540754175427543754475457546754775487549755075517552755375547555755675577558755975607561756275637564756575667567756875697570757175727573757475757576757775787579758075817582758375847585758675877588758975907591759275937594759575967597759875997600760176027603760476057606760776087609761076117612761376147615761676177618761976207621762276237624762576267627762876297630763176327633763476357636763776387639764076417642764376447645764676477648764976507651765276537654765576567657765876597660766176627663766476657666766776687669767076717672767376747675767676777678767976807681768276837684768576867687768876897690769176927693769476957696769776987699770077017702770377047705770677077708770977107711771277137714771577167717771877197720772177227723772477257726772777287729773077317732773377347735773677377738773977407741774277437744774577467747774877497750775177527753775477557756775777587759776077617762776377647765776677677768776977707771777277737774777577767777777877797780778177827783778477857786778777887789779077917792779377947795779677977798779978007801780278037804780578067807780878097810781178127813781478157816781778187819782078217822782378247825782678277828782978307831783278337834783578367837783878397840784178427843784478457846784778487849785078517852785378547855785678577858785978607861786278637864786578667867786878697870787178727873787478757876787778787879788078817882788378847885788678877888788978907891789278937894789578967897789878997900790179027903790479057906790779087909791079117912791379147915791679177918791979207921792279237924792579267927792879297930793179327933793479357936793779387939794079417942794379447945794679477948794979507951795279537954795579567957795879597960796179627963796479657966796779687969797079717972797379747975797679777978797979807981798279837984798579867987798879897990799179927993799479957996799779987999800080018002800380048005800680078008800980108011801280138014801580168017801880198020802180228023802480258026802780288029803080318032803380348035803680378038803980408041804280438044804580468047804880498050805180528053805480558056805780588059806080618062806380648065806680678068806980708071807280738074807580768077807880798080808180828083808480858086808780888089809080918092809380948095809680978098809981008101810281038104810581068107810881098110811181128113811481158116811781188119812081218122812381248125812681278128812981308131813281338134813581368137813881398140814181428143814481458146814781488149815081518152815381548155815681578158815981608161816281638164816581668167816881698170817181728173817481758176817781788179818081818182818381848185818681878188818981908191819281938194819581968197819881998200820182028203820482058206820782088209821082118212821382148215821682178218821982208221822282238224822582268227822882298230823182328233823482358236823782388239824082418242824382448245824682478248824982508251825282538254825582568257825882598260826182628263826482658266826782688269827082718272827382748275827682778278827982808281828282838284828582868287828882898290829182928293829482958296829782988299830083018302830383048305830683078308830983108311831283138314831583168317831883198320832183228323832483258326832783288329833083318332833383348335833683378338833983408341834283438344834583468347834883498350835183528353835483558356835783588359836083618362836383648365836683678368836983708371837283738374837583768377837883798380838183828383838483858386838783888389839083918392839383948395839683978398839984008401840284038404840584068407840884098410841184128413841484158416841784188419842084218422842384248425842684278428842984308431843284338434843584368437843884398440844184428443844484458446844784488449845084518452845384548455845684578458845984608461846284638464846584668467846884698470847184728473847484758476847784788479848084818482848384848485848684878488848984908491849284938494849584968497849884998500850185028503850485058506850785088509851085118512851385148515851685178518851985208521852285238524852585268527852885298530853185328533853485358536853785388539854085418542854385448545854685478548854985508551855285538554855585568557855885598560856185628563856485658566856785688569857085718572857385748575857685778578857985808581858285838584858585868587858885898590859185928593859485958596859785988599860086018602860386048605860686078608860986108611861286138614861586168617861886198620862186228623862486258626862786288629863086318632863386348635863686378638863986408641864286438644864586468647864886498650865186528653865486558656865786588659866086618662866386648665866686678668866986708671867286738674867586768677867886798680868186828683868486858686868786888689869086918692869386948695869686978698869987008701870287038704870587068707870887098710871187128713871487158716871787188719872087218722872387248725872687278728872987308731873287338734873587368737873887398740874187428743874487458746874787488749875087518752875387548755875687578758875987608761876287638764876587668767876887698770877187728773877487758776877787788779878087818782878387848785878687878788878987908791879287938794879587968797879887998800880188028803880488058806880788088809881088118812881388148815881688178818881988208821882288238824882588268827882888298830883188328833883488358836883788388839884088418842884388448845884688478848884988508851885288538854885588568857885888598860886188628863886488658866886788688869887088718872887388748875887688778878887988808881888288838884888588868887888888898890889188928893889488958896889788988899890089018902890389048905890689078908890989108911891289138914891589168917891889198920892189228923892489258926892789288929893089318932893389348935893689378938893989408941894289438944894589468947894889498950895189528953895489558956895789588959896089618962896389648965896689678968896989708971897289738974897589768977897889798980898189828983898489858986898789888989899089918992899389948995899689978998899990009001900290039004900590069007900890099010901190129013901490159016901790189019902090219022902390249025902690279028902990309031903290339034903590369037903890399040904190429043904490459046904790489049905090519052905390549055905690579058905990609061906290639064906590669067906890699070907190729073907490759076907790789079908090819082908390849085908690879088908990909091909290939094909590969097909890999100910191029103910491059106910791089109911091119112911391149115911691179118911991209121912291239124912591269127912891299130913191329133913491359136913791389139914091419142914391449145914691479148914991509151915291539154915591569157915891599160916191629163916491659166916791689169917091719172917391749175917691779178917991809181918291839184918591869187918891899190919191929193919491959196919791989199920092019202920392049205920692079208920992109211921292139214921592169217921892199220922192229223922492259226922792289229923092319232923392349235923692379238923992409241924292439244924592469247924892499250925192529253925492559256925792589259926092619262926392649265926692679268926992709271927292739274927592769277927892799280928192829283928492859286928792889289929092919292929392949295929692979298929993009301930293039304930593069307930893099310931193129313931493159316931793189319932093219322932393249325932693279328932993309331933293339334933593369337933893399340934193429343934493459346934793489349935093519352935393549355935693579358935993609361936293639364936593669367936893699370937193729373937493759376937793789379938093819382938393849385938693879388938993909391939293939394939593969397939893999400940194029403940494059406940794089409941094119412941394149415941694179418941994209421942294239424942594269427942894299430943194329433943494359436943794389439944094419442944394449445944694479448944994509451945294539454945594569457945894599460946194629463946494659466946794689469947094719472947394749475947694779478947994809481948294839484948594869487948894899490949194929493949494959496949794989499950095019502950395049505950695079508950995109511951295139514951595169517951895199520952195229523952495259526952795289529953095319532953395349535953695379538953995409541954295439544954595469547954895499550955195529553955495559556955795589559956095619562956395649565956695679568956995709571957295739574957595769577957895799580958195829583958495859586958795889589959095919592959395949595959695979598959996009601960296039604960596069607960896099610961196129613961496159616961796189619962096219622962396249625962696279628962996309631963296339634963596369637963896399640964196429643964496459646964796489649965096519652965396549655965696579658965996609661966296639664966596669667966896699670967196729673967496759676967796789679968096819682968396849685968696879688968996909691969296939694969596969697969896999700970197029703970497059706970797089709971097119712971397149715971697179718971997209721972297239724972597269727972897299730973197329733973497359736973797389739974097419742974397449745974697479748974997509751975297539754975597569757975897599760976197629763976497659766976797689769977097719772977397749775977697779778977997809781978297839784978597869787978897899790979197929793979497959796979797989799980098019802980398049805980698079808980998109811981298139814981598169817981898199820982198229823982498259826982798289829983098319832983398349835983698379838983998409841984298439844984598469847984898499850985198529853985498559856985798589859986098619862986398649865986698679868986998709871987298739874987598769877987898799880988198829883988498859886988798889889989098919892989398949895989698979898989999009901990299039904990599069907990899099910991199129913991499159916991799189919992099219922992399249925992699279928992999309931993299339934993599369937993899399940994199429943994499459946994799489949995099519952995399549955995699579958995999609961996299639964996599669967996899699970997199729973997499759976997799789979998099819982998399849985998699879988998999909991999299939994999599969997999899991000010001100021000310004100051000610007100081000910010100111001210013100141001510016100171001810019100201002110022100231002410025100261002710028100291003010031100321003310034100351003610037100381003910040100411004210043100441004510046100471004810049100501005110052100531005410055100561005710058100591006010061100621006310064100651006610067100681006910070100711007210073100741007510076100771007810079100801008110082100831008410085100861008710088100891009010091100921009310094100951009610097100981009910100101011010210103101041010510106101071010810109101101011110112101131011410115101161011710118101191012010121101221012310124101251012610127101281012910130101311013210133101341013510136101371013810139101401014110142101431014410145101461014710148101491015010151101521015310154101551015610157101581015910160101611016210163101641016510166101671016810169101701017110172101731017410175101761017710178101791018010181101821018310184101851018610187101881018910190101911019210193101941019510196101971019810199102001020110202102031020410205102061020710208102091021010211102121021310214102151021610217102181021910220102211022210223102241022510226102271022810229102301023110232102331023410235102361023710238102391024010241102421024310244102451024610247102481024910250102511025210253102541025510256102571025810259102601026110262102631026410265102661026710268102691027010271102721027310274102751027610277102781027910280102811028210283102841028510286102871028810289102901029110292102931029410295102961029710298102991030010301103021030310304103051030610307103081030910310103111031210313103141031510316103171031810319103201032110322103231032410325103261032710328103291033010331103321033310334103351033610337103381033910340103411034210343103441034510346103471034810349103501035110352103531035410355103561035710358103591036010361103621036310364103651036610367103681036910370103711037210373103741037510376103771037810379103801038110382103831038410385103861038710388103891039010391103921039310394103951039610397103981039910400104011040210403104041040510406104071040810409104101041110412104131041410415104161041710418104191042010421104221042310424104251042610427104281042910430104311043210433104341043510436104371043810439104401044110442104431044410445104461044710448104491045010451104521045310454104551045610457104581045910460104611046210463104641046510466104671046810469104701047110472104731047410475104761047710478104791048010481104821048310484104851048610487104881048910490104911049210493104941049510496104971049810499105001050110502105031050410505105061050710508105091051010511105121051310514105151051610517105181051910520105211052210523105241052510526105271052810529105301053110532105331053410535105361053710538105391054010541105421054310544105451054610547105481054910550105511055210553105541055510556105571055810559105601056110562105631056410565105661056710568105691057010571105721057310574105751057610577105781057910580105811058210583105841058510586105871058810589105901059110592105931059410595105961059710598105991060010601106021060310604106051060610607106081060910610106111061210613106141061510616106171061810619106201062110622106231062410625106261062710628106291063010631106321063310634106351063610637106381063910640106411064210643106441064510646106471064810649106501065110652106531065410655106561065710658106591066010661106621066310664106651066610667106681066910670106711067210673106741067510676106771067810679106801068110682106831068410685106861068710688106891069010691106921069310694106951069610697106981069910700107011070210703107041070510706107071070810709107101071110712107131071410715107161071710718107191072010721107221072310724107251072610727107281072910730107311073210733107341073510736107371073810739107401074110742107431074410745107461074710748107491075010751107521075310754107551075610757107581075910760107611076210763107641076510766107671076810769107701077110772107731077410775107761077710778107791078010781107821078310784107851078610787107881078910790107911079210793107941079510796107971079810799108001080110802108031080410805108061080710808108091081010811108121081310814108151081610817108181081910820108211082210823108241082510826108271082810829108301083110832108331083410835108361083710838108391084010841108421084310844108451084610847108481084910850108511085210853108541085510856108571085810859108601086110862108631086410865108661086710868108691087010871108721087310874108751087610877108781087910880108811088210883108841088510886108871088810889108901089110892108931089410895108961089710898108991090010901109021090310904109051090610907109081090910910109111091210913109141091510916109171091810919109201092110922109231092410925109261092710928109291093010931109321093310934109351093610937109381093910940109411094210943109441094510946109471094810949109501095110952109531095410955109561095710958109591096010961109621096310964109651096610967109681096910970109711097210973109741097510976109771097810979109801098110982109831098410985109861098710988109891099010991109921099310994109951099610997109981099911000110011100211003110041100511006110071100811009110101101111012110131101411015110161101711018110191102011021110221102311024110251102611027110281102911030110311103211033110341103511036110371103811039110401104111042110431104411045110461104711048110491105011051110521105311054110551105611057110581105911060110611106211063110641106511066110671106811069110701107111072110731107411075110761107711078110791108011081110821108311084110851108611087110881108911090110911109211093110941109511096110971109811099111001110111102111031110411105111061110711108111091111011111111121111311114111151111611117111181111911120111211112211123111241112511126111271112811129111301113111132111331113411135111361113711138111391114011141111421114311144111451114611147111481114911150111511115211153111541115511156111571115811159111601116111162111631116411165111661116711168111691117011171111721117311174111751117611177111781117911180111811118211183111841118511186111871118811189111901119111192111931119411195111961119711198111991120011201112021120311204112051120611207112081120911210112111121211213112141121511216112171121811219112201122111222112231122411225112261122711228112291123011231112321123311234112351123611237112381123911240112411124211243112441124511246112471124811249112501125111252112531125411255112561125711258112591126011261112621126311264112651126611267112681126911270112711127211273112741127511276112771127811279112801128111282112831128411285112861128711288112891129011291112921129311294112951129611297112981129911300113011130211303113041130511306113071130811309113101131111312113131131411315113161131711318113191132011321113221132311324113251132611327113281132911330113311133211333113341133511336113371133811339113401134111342113431134411345113461134711348113491135011351113521135311354113551135611357113581135911360113611136211363113641136511366113671136811369113701137111372113731137411375113761137711378113791138011381113821138311384113851138611387113881138911390113911139211393113941139511396113971139811399114001140111402114031140411405114061140711408114091141011411114121141311414114151141611417114181141911420114211142211423114241142511426114271142811429114301143111432114331143411435114361143711438114391144011441114421144311444114451144611447114481144911450114511145211453114541145511456114571145811459114601146111462114631146411465114661146711468114691147011471114721147311474114751147611477114781147911480114811148211483114841148511486114871148811489114901149111492114931149411495114961149711498114991150011501115021150311504115051150611507115081150911510115111151211513115141151511516115171151811519115201152111522115231152411525115261152711528115291153011531115321153311534115351153611537115381153911540115411154211543115441154511546115471154811549115501155111552115531155411555115561155711558115591156011561115621156311564115651156611567115681156911570115711157211573115741157511576115771157811579115801158111582115831158411585115861158711588115891159011591115921159311594115951159611597115981159911600116011160211603116041160511606116071160811609116101161111612116131161411615116161161711618116191162011621116221162311624116251162611627116281162911630116311163211633116341163511636116371163811639116401164111642116431164411645116461164711648116491165011651116521165311654116551165611657116581165911660116611166211663116641166511666116671166811669116701167111672116731167411675116761167711678116791168011681116821168311684116851168611687116881168911690116911169211693116941169511696116971169811699117001170111702117031170411705117061170711708117091171011711117121171311714117151171611717117181171911720117211172211723117241172511726117271172811729117301173111732117331173411735117361173711738117391174011741117421174311744117451174611747117481174911750117511175211753117541175511756117571175811759117601176111762117631176411765117661176711768117691177011771117721177311774117751177611777117781177911780117811178211783117841178511786117871178811789117901179111792117931179411795117961179711798117991180011801118021180311804118051180611807118081180911810118111181211813118141181511816118171181811819118201182111822118231182411825118261182711828118291183011831118321183311834118351183611837118381183911840118411184211843118441184511846118471184811849118501185111852118531185411855118561185711858118591186011861118621186311864118651186611867118681186911870118711187211873118741187511876118771187811879118801188111882118831188411885118861188711888118891189011891118921189311894118951189611897118981189911900119011190211903119041190511906119071190811909119101191111912119131191411915119161191711918119191192011921119221192311924119251192611927119281192911930119311193211933119341193511936119371193811939119401194111942119431194411945119461194711948119491195011951119521195311954119551195611957119581195911960119611196211963119641196511966119671196811969119701197111972119731197411975119761197711978119791198011981119821198311984119851198611987119881198911990119911199211993119941199511996119971199811999120001200112002120031200412005120061200712008120091201012011120121201312014120151201612017120181201912020120211202212023120241202512026120271202812029120301203112032120331203412035120361203712038120391204012041120421204312044120451204612047120481204912050120511205212053120541205512056120571205812059120601206112062120631206412065120661206712068120691207012071120721207312074120751207612077120781207912080120811208212083120841208512086120871208812089120901209112092120931209412095120961209712098120991210012101121021210312104121051210612107121081210912110121111211212113121141211512116121171211812119121201212112122121231212412125121261212712128121291213012131121321213312134121351213612137121381213912140121411214212143121441214512146121471214812149121501215112152121531215412155121561215712158121591216012161121621216312164121651216612167121681216912170121711217212173121741217512176121771217812179121801218112182121831218412185121861218712188121891219012191121921219312194121951219612197121981219912200122011220212203122041220512206122071220812209122101221112212122131221412215122161221712218122191222012221122221222312224122251222612227122281222912230122311223212233122341223512236122371223812239122401224112242122431224412245122461224712248122491225012251122521225312254122551225612257122581225912260122611226212263122641226512266122671226812269122701227112272122731227412275122761227712278122791228012281122821228312284122851228612287122881228912290122911229212293122941229512296122971229812299123001230112302123031230412305123061230712308123091231012311123121231312314123151231612317123181231912320123211232212323123241232512326123271232812329123301233112332123331233412335123361233712338123391234012341123421234312344123451234612347123481234912350123511235212353123541235512356123571235812359123601236112362123631236412365123661236712368123691237012371123721237312374123751237612377123781237912380123811238212383123841238512386123871238812389123901239112392123931239412395123961239712398123991240012401124021240312404124051240612407124081240912410124111241212413124141241512416124171241812419124201242112422124231242412425124261242712428124291243012431124321243312434124351243612437124381243912440124411244212443124441244512446124471244812449124501245112452124531245412455124561245712458124591246012461124621246312464124651246612467124681246912470124711247212473124741247512476124771247812479124801248112482124831248412485124861248712488124891249012491124921249312494124951249612497124981249912500125011250212503125041250512506125071250812509125101251112512125131251412515125161251712518125191252012521125221252312524125251252612527125281252912530125311253212533125341253512536125371253812539125401254112542125431254412545125461254712548125491255012551125521255312554125551255612557125581255912560125611256212563125641256512566125671256812569125701257112572125731257412575125761257712578125791258012581125821258312584125851258612587125881258912590125911259212593125941259512596125971259812599126001260112602126031260412605126061260712608126091261012611126121261312614126151261612617126181261912620126211262212623126241262512626126271262812629126301263112632126331263412635126361263712638126391264012641126421264312644126451264612647126481264912650126511265212653126541265512656126571265812659126601266112662126631266412665126661266712668126691267012671126721267312674126751267612677126781267912680126811268212683126841268512686126871268812689126901269112692126931269412695126961269712698126991270012701127021270312704127051270612707127081270912710127111271212713127141271512716127171271812719127201272112722127231272412725127261272712728127291273012731127321273312734127351273612737127381273912740127411274212743127441274512746127471274812749127501275112752127531275412755127561275712758127591276012761127621276312764127651276612767127681276912770127711277212773127741277512776127771277812779127801278112782127831278412785127861278712788127891279012791127921279312794127951279612797127981279912800128011280212803128041280512806128071280812809128101281112812128131281412815128161281712818128191282012821128221282312824128251282612827128281282912830128311283212833128341283512836128371283812839128401284112842128431284412845128461284712848128491285012851128521285312854128551285612857128581285912860128611286212863128641286512866128671286812869128701287112872128731287412875128761287712878128791288012881128821288312884128851288612887128881288912890128911289212893128941289512896128971289812899129001290112902129031290412905129061290712908129091291012911129121291312914129151291612917129181291912920129211292212923129241292512926129271292812929129301293112932129331293412935129361293712938129391294012941129421294312944129451294612947129481294912950129511295212953129541295512956129571295812959129601296112962129631296412965129661296712968129691297012971129721297312974129751297612977129781297912980129811298212983129841298512986129871298812989129901299112992129931299412995129961299712998129991300013001130021300313004130051300613007130081300913010130111301213013130141301513016130171301813019130201302113022130231302413025130261302713028130291303013031130321303313034130351303613037130381303913040130411304213043130441304513046130471304813049130501305113052130531305413055130561305713058130591306013061130621306313064130651306613067130681306913070130711307213073130741307513076130771307813079130801308113082130831308413085130861308713088130891309013091130921309313094130951309613097130981309913100131011310213103131041310513106131071310813109131101311113112131131311413115131161311713118131191312013121131221312313124131251312613127131281312913130131311313213133131341313513136131371313813139131401314113142131431314413145131461314713148131491315013151131521315313154131551315613157131581315913160131611316213163131641316513166131671316813169131701317113172131731317413175131761317713178131791318013181131821318313184131851318613187131881318913190131911319213193131941319513196131971319813199132001320113202132031320413205132061320713208132091321013211132121321313214132151321613217132181321913220132211322213223132241322513226132271322813229132301323113232132331323413235132361323713238132391324013241132421324313244132451324613247132481324913250132511325213253132541325513256132571325813259132601326113262132631326413265132661326713268132691327013271132721327313274132751327613277132781327913280132811328213283132841328513286132871328813289132901329113292132931329413295132961329713298132991330013301133021330313304133051330613307133081330913310133111331213313133141331513316133171331813319133201332113322133231332413325133261332713328133291333013331133321333313334133351333613337133381333913340133411334213343133441334513346133471334813349133501335113352133531335413355133561335713358133591336013361133621336313364133651336613367133681336913370133711337213373133741337513376133771337813379133801338113382133831338413385133861338713388133891339013391133921339313394133951339613397133981339913400134011340213403134041340513406134071340813409134101341113412134131341413415134161341713418134191342013421134221342313424134251342613427134281342913430134311343213433134341343513436134371343813439134401344113442134431344413445134461344713448134491345013451134521345313454134551345613457134581345913460134611346213463134641346513466134671346813469134701347113472134731347413475134761347713478134791348013481134821348313484134851348613487134881348913490134911349213493134941349513496134971349813499135001350113502135031350413505135061350713508135091351013511135121351313514135151351613517135181351913520135211352213523135241352513526135271352813529135301353113532135331353413535135361353713538135391354013541135421354313544135451354613547135481354913550135511355213553135541355513556135571355813559135601356113562135631356413565135661356713568135691357013571135721357313574135751357613577135781357913580135811358213583135841358513586135871358813589135901359113592135931359413595135961359713598135991360013601136021360313604136051360613607136081360913610136111361213613136141361513616136171361813619136201362113622136231362413625136261362713628136291363013631136321363313634136351363613637136381363913640136411364213643136441364513646136471364813649136501365113652136531365413655136561365713658136591366013661136621366313664136651366613667136681366913670136711367213673136741367513676136771367813679136801368113682136831368413685136861368713688136891369013691136921369313694136951369613697136981369913700137011370213703137041370513706137071370813709137101371113712137131371413715137161371713718137191372013721137221372313724137251372613727137281372913730137311373213733137341373513736137371373813739137401374113742137431374413745137461374713748137491375013751137521375313754137551375613757137581375913760137611376213763137641376513766137671376813769137701377113772137731377413775137761377713778137791378013781137821378313784137851378613787137881378913790137911379213793137941379513796137971379813799138001380113802138031380413805138061380713808138091381013811138121381313814138151381613817138181381913820138211382213823138241382513826138271382813829138301383113832138331383413835138361383713838138391384013841138421384313844138451384613847138481384913850138511385213853138541385513856138571385813859138601386113862138631386413865138661386713868138691387013871138721387313874138751387613877138781387913880138811388213883138841388513886138871388813889138901389113892138931389413895138961389713898138991390013901139021390313904139051390613907139081390913910139111391213913139141391513916139171391813919139201392113922139231392413925139261392713928139291393013931139321393313934139351393613937139381393913940139411394213943139441394513946139471394813949139501395113952139531395413955139561395713958139591396013961139621396313964139651396613967139681396913970139711397213973139741397513976139771397813979139801398113982139831398413985139861398713988139891399013991139921399313994139951399613997139981399914000140011400214003140041400514006140071400814009140101401114012140131401414015140161401714018140191402014021140221402314024140251402614027140281402914030140311403214033140341403514036140371403814039140401404114042140431404414045140461404714048140491405014051140521405314054140551405614057140581405914060140611406214063140641406514066140671406814069140701407114072140731407414075140761407714078140791408014081140821408314084140851408614087140881408914090140911409214093140941409514096140971409814099141001410114102141031410414105141061410714108141091411014111141121411314114141151411614117141181411914120141211412214123141241412514126141271412814129141301413114132141331413414135141361413714138141391414014141141421414314144141451414614147141481414914150141511415214153141541415514156141571415814159141601416114162141631416414165141661416714168141691417014171141721417314174141751417614177141781417914180141811418214183141841418514186141871418814189141901419114192141931419414195141961419714198141991420014201142021420314204142051420614207142081420914210142111421214213142141421514216142171421814219142201422114222142231422414225142261422714228142291423014231142321423314234142351423614237142381423914240142411424214243142441424514246142471424814249142501425114252142531425414255142561425714258142591426014261142621426314264142651426614267142681426914270142711427214273142741427514276142771427814279142801428114282142831428414285142861428714288142891429014291142921429314294142951429614297142981429914300143011430214303143041430514306143071430814309143101431114312143131431414315143161431714318143191432014321143221432314324143251432614327143281432914330143311433214333143341433514336143371433814339143401434114342143431434414345143461434714348143491435014351143521435314354143551435614357143581435914360143611436214363143641436514366143671436814369143701437114372143731437414375143761437714378143791438014381143821438314384143851438614387143881438914390143911439214393143941439514396143971439814399144001440114402144031440414405144061440714408144091441014411144121441314414144151441614417144181441914420144211442214423144241442514426144271442814429144301443114432144331443414435144361443714438144391444014441144421444314444144451444614447144481444914450144511445214453144541445514456144571445814459144601446114462144631446414465144661446714468144691447014471144721447314474144751447614477144781447914480144811448214483144841448514486144871448814489144901449114492144931449414495144961449714498144991450014501145021450314504145051450614507145081450914510145111451214513145141451514516145171451814519145201452114522145231452414525145261452714528145291453014531145321453314534145351453614537145381453914540145411454214543145441454514546145471454814549145501455114552145531455414555145561455714558145591456014561145621456314564145651456614567145681456914570145711457214573145741457514576145771457814579145801458114582145831458414585145861458714588145891459014591145921459314594145951459614597145981459914600146011460214603146041460514606146071460814609146101461114612146131461414615146161461714618146191462014621146221462314624146251462614627146281462914630146311463214633146341463514636146371463814639146401464114642146431464414645146461464714648146491465014651146521465314654146551465614657146581465914660146611466214663146641466514666146671466814669146701467114672146731467414675146761467714678146791468014681146821468314684146851468614687146881468914690146911469214693146941469514696146971469814699147001470114702147031470414705147061470714708147091471014711147121471314714147151471614717147181471914720147211472214723147241472514726147271472814729147301473114732147331473414735147361473714738147391474014741147421474314744147451474614747147481474914750147511475214753147541475514756147571475814759147601476114762147631476414765147661476714768147691477014771147721477314774147751477614777147781477914780147811478214783147841478514786147871478814789147901479114792147931479414795147961479714798147991480014801148021480314804148051480614807148081480914810148111481214813148141481514816148171481814819148201482114822148231482414825148261482714828148291483014831148321483314834148351483614837148381483914840148411484214843148441484514846148471484814849148501485114852148531485414855148561485714858148591486014861148621486314864148651486614867148681486914870148711487214873148741487514876148771487814879148801488114882148831488414885148861488714888148891489014891148921489314894148951489614897148981489914900149011490214903149041490514906149071490814909149101491114912149131491414915149161491714918149191492014921149221492314924149251492614927149281492914930149311493214933149341493514936149371493814939149401494114942149431494414945149461494714948149491495014951149521495314954149551495614957149581495914960149611496214963149641496514966149671496814969149701497114972149731497414975149761497714978149791498014981149821498314984149851498614987149881498914990149911499214993149941499514996149971499814999150001500115002150031500415005150061500715008150091501015011150121501315014150151501615017150181501915020150211502215023150241502515026150271502815029150301503115032150331503415035150361503715038150391504015041150421504315044150451504615047150481504915050150511505215053150541505515056150571505815059150601506115062150631506415065150661506715068150691507015071150721507315074150751507615077150781507915080150811508215083150841508515086150871508815089150901509115092150931509415095150961509715098150991510015101151021510315104151051510615107151081510915110151111511215113151141511515116151171511815119151201512115122151231512415125151261512715128151291513015131151321513315134151351513615137151381513915140151411514215143151441514515146151471514815149151501515115152151531515415155151561515715158151591516015161151621516315164151651516615167151681516915170151711517215173151741517515176151771517815179151801518115182151831518415185151861518715188151891519015191151921519315194151951519615197151981519915200152011520215203152041520515206152071520815209152101521115212152131521415215152161521715218152191522015221152221522315224152251522615227152281522915230152311523215233152341523515236152371523815239152401524115242152431524415245152461524715248152491525015251152521525315254152551525615257152581525915260152611526215263152641526515266152671526815269152701527115272152731527415275152761527715278152791528015281152821528315284152851528615287152881528915290152911529215293152941529515296152971529815299153001530115302153031530415305153061530715308153091531015311153121531315314153151531615317153181531915320153211532215323153241532515326153271532815329153301533115332153331533415335153361533715338153391534015341153421534315344153451534615347153481534915350153511535215353153541535515356153571535815359153601536115362153631536415365153661536715368153691537015371153721537315374153751537615377153781537915380153811538215383153841538515386153871538815389153901539115392153931539415395153961539715398153991540015401154021540315404154051540615407154081540915410154111541215413154141541515416154171541815419154201542115422154231542415425154261542715428154291543015431154321543315434154351543615437154381543915440154411544215443154441544515446154471544815449154501545115452154531545415455154561545715458154591546015461154621546315464154651546615467154681546915470154711547215473154741547515476154771547815479154801548115482154831548415485154861548715488154891549015491154921549315494154951549615497154981549915500155011550215503155041550515506155071550815509155101551115512155131551415515155161551715518155191552015521155221552315524155251552615527155281552915530155311553215533155341553515536155371553815539155401554115542155431554415545155461554715548155491555015551155521555315554155551555615557155581555915560155611556215563155641556515566155671556815569155701557115572155731557415575155761557715578155791558015581155821558315584155851558615587155881558915590155911559215593155941559515596155971559815599156001560115602156031560415605156061560715608156091561015611156121561315614156151561615617156181561915620156211562215623156241562515626156271562815629156301563115632156331563415635156361563715638156391564015641156421564315644156451564615647156481564915650156511565215653156541565515656156571565815659156601566115662156631566415665156661566715668156691567015671156721567315674156751567615677156781567915680156811568215683156841568515686156871568815689156901569115692156931569415695156961569715698156991570015701157021570315704157051570615707157081570915710157111571215713157141571515716157171571815719157201572115722157231572415725157261572715728157291573015731157321573315734157351573615737157381573915740157411574215743157441574515746157471574815749157501575115752157531575415755157561575715758157591576015761157621576315764157651576615767157681576915770157711577215773157741577515776157771577815779157801578115782157831578415785157861578715788157891579015791157921579315794157951579615797157981579915800158011580215803158041580515806158071580815809158101581115812158131581415815158161581715818158191582015821158221582315824158251582615827158281582915830158311583215833158341583515836158371583815839158401584115842158431584415845158461584715848158491585015851158521585315854158551585615857158581585915860158611586215863158641586515866158671586815869158701587115872158731587415875158761587715878158791588015881158821588315884158851588615887158881588915890158911589215893158941589515896158971589815899159001590115902159031590415905159061590715908159091591015911159121591315914159151591615917159181591915920159211592215923159241592515926159271592815929159301593115932159331593415935159361593715938159391594015941159421594315944159451594615947159481594915950159511595215953159541595515956159571595815959159601596115962159631596415965159661596715968159691597015971159721597315974159751597615977159781597915980159811598215983159841598515986159871598815989159901599115992159931599415995159961599715998159991600016001160021600316004160051600616007160081600916010160111601216013160141601516016160171601816019160201602116022160231602416025160261602716028160291603016031160321603316034160351603616037160381603916040160411604216043160441604516046160471604816049160501605116052160531605416055160561605716058160591606016061160621606316064160651606616067160681606916070160711607216073160741607516076160771607816079160801608116082160831608416085160861608716088160891609016091160921609316094160951609616097160981609916100161011610216103161041610516106161071610816109161101611116112161131611416115161161611716118161191612016121161221612316124161251612616127161281612916130161311613216133161341613516136161371613816139161401614116142161431614416145161461614716148161491615016151161521615316154161551615616157161581615916160161611616216163161641616516166161671616816169161701617116172161731617416175161761617716178161791618016181161821618316184161851618616187161881618916190161911619216193161941619516196161971619816199162001620116202162031620416205162061620716208162091621016211162121621316214162151621616217162181621916220162211622216223162241622516226162271622816229162301623116232162331623416235162361623716238162391624016241162421624316244162451624616247162481624916250162511625216253162541625516256162571625816259162601626116262162631626416265162661626716268162691627016271162721627316274162751627616277162781627916280162811628216283162841628516286162871628816289162901629116292162931629416295162961629716298162991630016301163021630316304163051630616307163081630916310163111631216313163141631516316163171631816319163201632116322163231632416325163261632716328163291633016331163321633316334163351633616337163381633916340163411634216343163441634516346163471634816349163501635116352163531635416355163561635716358163591636016361163621636316364163651636616367163681636916370163711637216373163741637516376163771637816379163801638116382163831638416385163861638716388163891639016391163921639316394163951639616397163981639916400164011640216403164041640516406164071640816409164101641116412164131641416415164161641716418164191642016421164221642316424164251642616427164281642916430164311643216433164341643516436164371643816439164401644116442164431644416445164461644716448164491645016451164521645316454164551645616457164581645916460164611646216463164641646516466164671646816469164701647116472164731647416475164761647716478164791648016481164821648316484164851648616487164881648916490164911649216493164941649516496164971649816499165001650116502165031650416505165061650716508165091651016511165121651316514165151651616517165181651916520165211652216523165241652516526165271652816529165301653116532165331653416535165361653716538165391654016541165421654316544165451654616547165481654916550165511655216553165541655516556165571655816559165601656116562165631656416565165661656716568165691657016571165721657316574165751657616577165781657916580165811658216583165841658516586165871658816589165901659116592165931659416595165961659716598165991660016601166021660316604166051660616607166081660916610166111661216613166141661516616166171661816619166201662116622166231662416625166261662716628166291663016631166321663316634166351663616637166381663916640166411664216643166441664516646166471664816649166501665116652166531665416655166561665716658166591666016661166621666316664166651666616667166681666916670166711667216673166741667516676166771667816679166801668116682166831668416685166861668716688166891669016691166921669316694166951669616697166981669916700167011670216703167041670516706167071670816709167101671116712167131671416715167161671716718167191672016721167221672316724167251672616727167281672916730167311673216733167341673516736167371673816739167401674116742167431674416745167461674716748167491675016751167521675316754167551675616757167581675916760167611676216763167641676516766167671676816769167701677116772167731677416775167761677716778167791678016781167821678316784167851678616787167881678916790167911679216793167941679516796167971679816799168001680116802168031680416805168061680716808168091681016811168121681316814168151681616817168181681916820168211682216823168241682516826168271682816829168301683116832168331683416835168361683716838168391684016841168421684316844168451684616847168481684916850168511685216853168541685516856168571685816859168601686116862168631686416865168661686716868168691687016871168721687316874168751687616877168781687916880168811688216883168841688516886168871688816889168901689116892168931689416895168961689716898168991690016901169021690316904169051690616907169081690916910169111691216913169141691516916169171691816919169201692116922169231692416925169261692716928169291693016931169321693316934169351693616937169381693916940169411694216943169441694516946169471694816949169501695116952169531695416955169561695716958169591696016961169621696316964169651696616967169681696916970169711697216973169741697516976169771697816979169801698116982169831698416985169861698716988169891699016991169921699316994169951699616997169981699917000170011700217003170041700517006170071700817009170101701117012170131701417015170161701717018170191702017021170221702317024170251702617027170281702917030170311703217033170341703517036170371703817039170401704117042170431704417045170461704717048170491705017051170521705317054170551705617057170581705917060170611706217063170641706517066170671706817069170701707117072170731707417075170761707717078170791708017081170821708317084170851708617087170881708917090170911709217093170941709517096170971709817099171001710117102171031710417105171061710717108171091711017111171121711317114171151711617117171181711917120171211712217123171241712517126171271712817129171301713117132171331713417135171361713717138171391714017141171421714317144171451714617147171481714917150171511715217153171541715517156171571715817159171601716117162171631716417165171661716717168171691717017171171721717317174171751717617177171781717917180171811718217183171841718517186171871718817189171901719117192171931719417195171961719717198171991720017201172021720317204172051720617207172081720917210172111721217213172141721517216172171721817219172201722117222172231722417225172261722717228172291723017231172321723317234172351723617237172381723917240172411724217243172441724517246172471724817249172501725117252172531725417255172561725717258172591726017261172621726317264172651726617267172681726917270172711727217273172741727517276172771727817279172801728117282172831728417285172861728717288172891729017291172921729317294172951729617297172981729917300173011730217303173041730517306173071730817309173101731117312173131731417315173161731717318173191732017321173221732317324173251732617327173281732917330173311733217333173341733517336173371733817339173401734117342173431734417345173461734717348173491735017351173521735317354173551735617357173581735917360173611736217363173641736517366173671736817369173701737117372173731737417375173761737717378173791738017381173821738317384173851738617387173881738917390173911739217393173941739517396173971739817399174001740117402174031740417405174061740717408174091741017411174121741317414174151741617417174181741917420174211742217423174241742517426174271742817429174301743117432174331743417435174361743717438174391744017441174421744317444174451744617447174481744917450174511745217453174541745517456174571745817459174601746117462174631746417465174661746717468174691747017471174721747317474174751747617477174781747917480174811748217483174841748517486174871748817489174901749117492174931749417495174961749717498174991750017501175021750317504175051750617507175081750917510175111751217513175141751517516175171751817519175201752117522175231752417525175261752717528175291753017531175321753317534175351753617537175381753917540175411754217543175441754517546175471754817549175501755117552175531755417555175561755717558175591756017561175621756317564175651756617567175681756917570175711757217573175741757517576175771757817579175801758117582175831758417585175861758717588175891759017591175921759317594175951759617597175981759917600176011760217603176041760517606176071760817609176101761117612176131761417615176161761717618176191762017621176221762317624176251762617627176281762917630176311763217633176341763517636176371763817639176401764117642176431764417645176461764717648176491765017651176521765317654176551765617657176581765917660176611766217663176641766517666176671766817669176701767117672176731767417675176761767717678176791768017681176821768317684176851768617687176881768917690176911769217693176941769517696176971769817699177001770117702177031770417705177061770717708177091771017711177121771317714177151771617717177181771917720177211772217723177241772517726177271772817729177301773117732177331773417735177361773717738177391774017741177421774317744177451774617747177481774917750177511775217753177541775517756177571775817759177601776117762177631776417765177661776717768177691777017771177721777317774177751777617777177781777917780177811778217783177841778517786177871778817789177901779117792177931779417795177961779717798177991780017801178021780317804178051780617807178081780917810178111781217813178141781517816178171781817819178201782117822178231782417825178261782717828178291783017831178321783317834178351783617837178381783917840178411784217843178441784517846178471784817849178501785117852178531785417855178561785717858178591786017861178621786317864178651786617867178681786917870178711787217873178741787517876178771787817879178801788117882178831788417885178861788717888178891789017891178921789317894178951789617897178981789917900179011790217903179041790517906179071790817909179101791117912179131791417915179161791717918179191792017921179221792317924179251792617927179281792917930179311793217933179341793517936179371793817939179401794117942179431794417945179461794717948179491795017951179521795317954179551795617957179581795917960179611796217963179641796517966179671796817969179701797117972179731797417975179761797717978179791798017981179821798317984179851798617987179881798917990179911799217993179941799517996179971799817999180001800118002180031800418005180061800718008180091801018011180121801318014180151801618017180181801918020180211802218023180241802518026180271802818029180301803118032180331803418035180361803718038180391804018041180421804318044180451804618047180481804918050180511805218053180541805518056180571805818059180601806118062180631806418065180661806718068180691807018071180721807318074180751807618077180781807918080180811808218083180841808518086180871808818089180901809118092180931809418095180961809718098180991810018101181021810318104181051810618107181081810918110181111811218113181141811518116181171811818119181201812118122181231812418125181261812718128181291813018131181321813318134181351813618137181381813918140181411814218143181441814518146181471814818149181501815118152181531815418155181561815718158181591816018161181621816318164181651816618167181681816918170181711817218173181741817518176181771817818179181801818118182181831818418185181861818718188181891819018191181921819318194181951819618197181981819918200182011820218203182041820518206182071820818209182101821118212182131821418215182161821718218182191822018221182221822318224182251822618227182281822918230182311823218233182341823518236182371823818239182401824118242182431824418245182461824718248182491825018251182521825318254182551825618257182581825918260182611826218263182641826518266182671826818269182701827118272182731827418275182761827718278182791828018281182821828318284182851828618287182881828918290182911829218293182941829518296182971829818299183001830118302183031830418305183061830718308183091831018311183121831318314183151831618317183181831918320183211832218323183241832518326183271832818329183301833118332183331833418335183361833718338183391834018341183421834318344183451834618347183481834918350183511835218353183541835518356183571835818359183601836118362183631836418365183661836718368183691837018371183721837318374183751837618377183781837918380183811838218383183841838518386183871838818389183901839118392183931839418395183961839718398183991840018401184021840318404184051840618407184081840918410184111841218413184141841518416184171841818419184201842118422184231842418425184261842718428184291843018431184321843318434184351843618437184381843918440184411844218443184441844518446184471844818449184501845118452184531845418455184561845718458184591846018461184621846318464184651846618467184681846918470184711847218473184741847518476184771847818479184801848118482184831848418485184861848718488184891849018491184921849318494184951849618497184981849918500185011850218503185041850518506185071850818509185101851118512185131851418515185161851718518185191852018521185221852318524185251852618527185281852918530185311853218533185341853518536185371853818539185401854118542185431854418545185461854718548185491855018551185521855318554185551855618557185581855918560185611856218563185641856518566185671856818569185701857118572185731857418575185761857718578185791858018581185821858318584185851858618587185881858918590185911859218593185941859518596185971859818599186001860118602186031860418605186061860718608186091861018611186121861318614186151861618617186181861918620186211862218623186241862518626186271862818629186301863118632186331863418635186361863718638186391864018641186421864318644186451864618647186481864918650186511865218653186541865518656186571865818659186601866118662186631866418665186661866718668186691867018671186721867318674186751867618677186781867918680186811868218683186841868518686186871868818689186901869118692186931869418695186961869718698186991870018701187021870318704187051870618707187081870918710187111871218713187141871518716187171871818719187201872118722187231872418725187261872718728187291873018731187321873318734187351873618737187381873918740187411874218743187441874518746187471874818749187501875118752187531875418755187561875718758187591876018761187621876318764187651876618767187681876918770187711877218773187741877518776187771877818779187801878118782187831878418785187861878718788187891879018791187921879318794187951879618797187981879918800188011880218803188041880518806188071880818809188101881118812188131881418815188161881718818188191882018821188221882318824188251882618827188281882918830188311883218833188341883518836188371883818839188401884118842188431884418845188461884718848188491885018851188521885318854188551885618857188581885918860188611886218863188641886518866188671886818869188701887118872188731887418875188761887718878188791888018881188821888318884188851888618887188881888918890188911889218893188941889518896188971889818899189001890118902189031890418905189061890718908189091891018911189121891318914189151891618917189181891918920189211892218923189241892518926189271892818929189301893118932189331893418935189361893718938189391894018941189421894318944189451894618947189481894918950189511895218953189541895518956189571895818959189601896118962189631896418965189661896718968189691897018971189721897318974189751897618977189781897918980189811898218983189841898518986189871898818989189901899118992189931899418995189961899718998189991900019001190021900319004190051900619007190081900919010190111901219013190141901519016190171901819019190201902119022190231902419025190261902719028190291903019031190321903319034190351903619037190381903919040190411904219043190441904519046190471904819049190501905119052190531905419055190561905719058190591906019061190621906319064190651906619067190681906919070190711907219073190741907519076190771907819079190801908119082190831908419085190861908719088190891909019091190921909319094190951909619097190981909919100191011910219103191041910519106191071910819109191101911119112191131911419115
  1. /*!
  2. * Copyright (c) 2014, GlobalSign
  3. * Copyright (c) 2015-2019, Peculiar Ventures
  4. * All rights reserved.
  5. *
  6. * Author 2014-2019, Yury Strozhevsky
  7. *
  8. * Redistribution and use in source and binary forms, with or without modification,
  9. * are permitted provided that the following conditions are met:
  10. *
  11. * * Redistributions of source code must retain the above copyright notice, this
  12. * list of conditions and the following disclaimer.
  13. *
  14. * * Redistributions in binary form must reproduce the above copyright notice, this
  15. * list of conditions and the following disclaimer in the documentation and/or
  16. * other materials provided with the distribution.
  17. *
  18. * * Neither the name of the {organization} nor the names of its
  19. * contributors may be used to endorse or promote products derived from
  20. * this software without specific prior written permission.
  21. *
  22. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND
  23. * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
  24. * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
  25. * DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR
  26. * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
  27. * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  28. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON
  29. * ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
  30. * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
  31. * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  32. *
  33. */
  34. import * as asn1js from 'asn1js';
  35. import * as pvtsutils from 'pvtsutils';
  36. import { BufferSourceConverter } from 'pvtsutils';
  37. import * as pvutils from 'pvutils';
  38. import * as bs from 'bytestreamjs';
  39. import { sha1 } from '@noble/hashes/sha1';
  40. import { sha512, sha384, sha256 } from '@noble/hashes/sha2';
  41. const EMPTY_BUFFER = new ArrayBuffer(0);
  42. const EMPTY_STRING = "";
  43. class ArgumentError extends TypeError {
  44. constructor() {
  45. super(...arguments);
  46. this.name = ArgumentError.NAME;
  47. }
  48. static isType(value, type) {
  49. if (typeof type === "string") {
  50. if (type === "Array" && Array.isArray(value)) {
  51. return true;
  52. }
  53. else if (type === "ArrayBuffer" && value instanceof ArrayBuffer) {
  54. return true;
  55. }
  56. else if (type === "ArrayBufferView" && ArrayBuffer.isView(value)) {
  57. return true;
  58. }
  59. else if (typeof value === type) {
  60. return true;
  61. }
  62. }
  63. else if (value instanceof type) {
  64. return true;
  65. }
  66. return false;
  67. }
  68. static assert(value, name, ...types) {
  69. for (const type of types) {
  70. if (this.isType(value, type)) {
  71. return;
  72. }
  73. }
  74. const typeNames = types.map(o => o instanceof Function && "name" in o ? o.name : `${o}`);
  75. throw new ArgumentError(`Parameter '${name}' is not of type ${typeNames.length > 1 ? `(${typeNames.join(" or ")})` : typeNames[0]}`);
  76. }
  77. }
  78. ArgumentError.NAME = "ArgumentError";
  79. class ParameterError extends TypeError {
  80. static assert(...args) {
  81. let target = null;
  82. let params;
  83. let fields;
  84. if (typeof args[0] === "string") {
  85. target = args[0];
  86. params = args[1];
  87. fields = args.slice(2);
  88. }
  89. else {
  90. params = args[0];
  91. fields = args.slice(1);
  92. }
  93. ArgumentError.assert(params, "parameters", "object");
  94. for (const field of fields) {
  95. const value = params[field];
  96. if (value === undefined || value === null) {
  97. throw new ParameterError(field, target);
  98. }
  99. }
  100. }
  101. static assertEmpty(value, name, target) {
  102. if (value === undefined || value === null) {
  103. throw new ParameterError(name, target);
  104. }
  105. }
  106. constructor(field, target = null, message) {
  107. super();
  108. this.name = ParameterError.NAME;
  109. this.field = field;
  110. if (target) {
  111. this.target = target;
  112. }
  113. if (message) {
  114. this.message = message;
  115. }
  116. else {
  117. this.message = `Absent mandatory parameter '${field}' ${target ? ` in '${target}'` : EMPTY_STRING}`;
  118. }
  119. }
  120. }
  121. ParameterError.NAME = "ParameterError";
  122. class AsnError extends Error {
  123. static assertSchema(asn1, target) {
  124. if (!asn1.verified) {
  125. throw new Error(`Object's schema was not verified against input data for ${target}`);
  126. }
  127. }
  128. static assert(asn, target) {
  129. if (asn.offset === -1) {
  130. throw new AsnError(`Error during parsing of ASN.1 data. Data is not correct for '${target}'.`);
  131. }
  132. }
  133. constructor(message) {
  134. super(message);
  135. this.name = "AsnError";
  136. }
  137. }
  138. class PkiObject {
  139. static blockName() {
  140. return this.CLASS_NAME;
  141. }
  142. static fromBER(raw) {
  143. const asn1 = asn1js.fromBER(raw);
  144. AsnError.assert(asn1, this.name);
  145. try {
  146. return new this({ schema: asn1.result });
  147. }
  148. catch (e) {
  149. throw new AsnError(`Cannot create '${this.CLASS_NAME}' from ASN.1 object`);
  150. }
  151. }
  152. static defaultValues(memberName) {
  153. throw new Error(`Invalid member name for ${this.CLASS_NAME} class: ${memberName}`);
  154. }
  155. static schema(parameters = {}) {
  156. throw new Error(`Method '${this.CLASS_NAME}.schema' should be overridden`);
  157. }
  158. get className() {
  159. return this.constructor.CLASS_NAME;
  160. }
  161. toString(encoding = "hex") {
  162. let schema;
  163. try {
  164. schema = this.toSchema();
  165. }
  166. catch {
  167. schema = this.toSchema(true);
  168. }
  169. return pvtsutils.Convert.ToString(schema.toBER(), encoding);
  170. }
  171. }
  172. PkiObject.CLASS_NAME = "PkiObject";
  173. function stringPrep(inputString) {
  174. let isSpace = false;
  175. let cutResult = EMPTY_STRING;
  176. const result = inputString.trim();
  177. for (let i = 0; i < result.length; i++) {
  178. if (result.charCodeAt(i) === 32) {
  179. if (isSpace === false)
  180. isSpace = true;
  181. }
  182. else {
  183. if (isSpace) {
  184. cutResult += " ";
  185. isSpace = false;
  186. }
  187. cutResult += result[i];
  188. }
  189. }
  190. return cutResult.toLowerCase();
  191. }
  192. const TYPE$5 = "type";
  193. const VALUE$6 = "value";
  194. class AttributeTypeAndValue extends PkiObject {
  195. constructor(parameters = {}) {
  196. super();
  197. this.type = pvutils.getParametersValue(parameters, TYPE$5, AttributeTypeAndValue.defaultValues(TYPE$5));
  198. this.value = pvutils.getParametersValue(parameters, VALUE$6, AttributeTypeAndValue.defaultValues(VALUE$6));
  199. if (parameters.schema) {
  200. this.fromSchema(parameters.schema);
  201. }
  202. }
  203. static defaultValues(memberName) {
  204. switch (memberName) {
  205. case TYPE$5:
  206. return EMPTY_STRING;
  207. case VALUE$6:
  208. return {};
  209. default:
  210. return super.defaultValues(memberName);
  211. }
  212. }
  213. static schema(parameters = {}) {
  214. const names = pvutils.getParametersValue(parameters, "names", {});
  215. return (new asn1js.Sequence({
  216. name: (names.blockName || EMPTY_STRING),
  217. value: [
  218. new asn1js.ObjectIdentifier({ name: (names.type || EMPTY_STRING) }),
  219. new asn1js.Any({ name: (names.value || EMPTY_STRING) })
  220. ]
  221. }));
  222. }
  223. fromSchema(schema) {
  224. pvutils.clearProps(schema, [
  225. TYPE$5,
  226. "typeValue"
  227. ]);
  228. const asn1 = asn1js.compareSchema(schema, schema, AttributeTypeAndValue.schema({
  229. names: {
  230. type: TYPE$5,
  231. value: "typeValue"
  232. }
  233. }));
  234. AsnError.assertSchema(asn1, this.className);
  235. this.type = asn1.result.type.valueBlock.toString();
  236. this.value = asn1.result.typeValue;
  237. }
  238. toSchema() {
  239. return (new asn1js.Sequence({
  240. value: [
  241. new asn1js.ObjectIdentifier({ value: this.type }),
  242. this.value
  243. ]
  244. }));
  245. }
  246. toJSON() {
  247. const _object = {
  248. type: this.type
  249. };
  250. if (Object.keys(this.value).length !== 0) {
  251. _object.value = (this.value).toJSON();
  252. }
  253. else {
  254. _object.value = this.value;
  255. }
  256. return _object;
  257. }
  258. isEqual(compareTo) {
  259. const stringBlockNames = [
  260. asn1js.Utf8String.blockName(),
  261. asn1js.BmpString.blockName(),
  262. asn1js.UniversalString.blockName(),
  263. asn1js.NumericString.blockName(),
  264. asn1js.PrintableString.blockName(),
  265. asn1js.TeletexString.blockName(),
  266. asn1js.VideotexString.blockName(),
  267. asn1js.IA5String.blockName(),
  268. asn1js.GraphicString.blockName(),
  269. asn1js.VisibleString.blockName(),
  270. asn1js.GeneralString.blockName(),
  271. asn1js.CharacterString.blockName()
  272. ];
  273. if (compareTo instanceof ArrayBuffer) {
  274. return pvtsutils.BufferSourceConverter.isEqual(this.value.valueBeforeDecodeView, compareTo);
  275. }
  276. if (compareTo.constructor.blockName() === AttributeTypeAndValue.blockName()) {
  277. if (this.type !== compareTo.type)
  278. return false;
  279. const isStringPair = [false, false];
  280. const thisName = this.value.constructor.blockName();
  281. for (const name of stringBlockNames) {
  282. if (thisName === name) {
  283. isStringPair[0] = true;
  284. }
  285. if (compareTo.value.constructor.blockName() === name) {
  286. isStringPair[1] = true;
  287. }
  288. }
  289. if (isStringPair[0] !== isStringPair[1]) {
  290. return false;
  291. }
  292. const isString = (isStringPair[0] && isStringPair[1]);
  293. if (isString) {
  294. const value1 = stringPrep(this.value.valueBlock.value);
  295. const value2 = stringPrep(compareTo.value.valueBlock.value);
  296. if (value1.localeCompare(value2) !== 0)
  297. return false;
  298. }
  299. else {
  300. if (!pvtsutils.BufferSourceConverter.isEqual(this.value.valueBeforeDecodeView, compareTo.value.valueBeforeDecodeView))
  301. return false;
  302. }
  303. return true;
  304. }
  305. return false;
  306. }
  307. }
  308. AttributeTypeAndValue.CLASS_NAME = "AttributeTypeAndValue";
  309. const TYPE_AND_VALUES = "typesAndValues";
  310. const VALUE_BEFORE_DECODE = "valueBeforeDecode";
  311. const RDN = "RDN";
  312. class RelativeDistinguishedNames extends PkiObject {
  313. constructor(parameters = {}) {
  314. super();
  315. this.typesAndValues = pvutils.getParametersValue(parameters, TYPE_AND_VALUES, RelativeDistinguishedNames.defaultValues(TYPE_AND_VALUES));
  316. this.valueBeforeDecode = pvutils.getParametersValue(parameters, VALUE_BEFORE_DECODE, RelativeDistinguishedNames.defaultValues(VALUE_BEFORE_DECODE));
  317. if (parameters.schema) {
  318. this.fromSchema(parameters.schema);
  319. }
  320. }
  321. static defaultValues(memberName) {
  322. switch (memberName) {
  323. case TYPE_AND_VALUES:
  324. return [];
  325. case VALUE_BEFORE_DECODE:
  326. return EMPTY_BUFFER;
  327. default:
  328. return super.defaultValues(memberName);
  329. }
  330. }
  331. static compareWithDefault(memberName, memberValue) {
  332. switch (memberName) {
  333. case TYPE_AND_VALUES:
  334. return (memberValue.length === 0);
  335. case VALUE_BEFORE_DECODE:
  336. return (memberValue.byteLength === 0);
  337. default:
  338. return super.defaultValues(memberName);
  339. }
  340. }
  341. static schema(parameters = {}) {
  342. const names = pvutils.getParametersValue(parameters, "names", {});
  343. return (new asn1js.Sequence({
  344. name: (names.blockName || EMPTY_STRING),
  345. value: [
  346. new asn1js.Repeated({
  347. name: (names.repeatedSequence || EMPTY_STRING),
  348. value: new asn1js.Set({
  349. value: [
  350. new asn1js.Repeated({
  351. name: (names.repeatedSet || EMPTY_STRING),
  352. value: AttributeTypeAndValue.schema(names.typeAndValue || {})
  353. })
  354. ]
  355. })
  356. })
  357. ]
  358. }));
  359. }
  360. fromSchema(schema) {
  361. pvutils.clearProps(schema, [
  362. RDN,
  363. TYPE_AND_VALUES
  364. ]);
  365. const asn1 = asn1js.compareSchema(schema, schema, RelativeDistinguishedNames.schema({
  366. names: {
  367. blockName: RDN,
  368. repeatedSet: TYPE_AND_VALUES
  369. }
  370. }));
  371. AsnError.assertSchema(asn1, this.className);
  372. if (TYPE_AND_VALUES in asn1.result) {
  373. this.typesAndValues = Array.from(asn1.result.typesAndValues, element => new AttributeTypeAndValue({ schema: element }));
  374. }
  375. this.valueBeforeDecode = asn1.result.RDN.valueBeforeDecodeView.slice().buffer;
  376. }
  377. toSchema() {
  378. if (this.valueBeforeDecode.byteLength === 0) {
  379. return (new asn1js.Sequence({
  380. value: [new asn1js.Set({
  381. value: Array.from(this.typesAndValues, o => o.toSchema())
  382. })]
  383. }));
  384. }
  385. const asn1 = asn1js.fromBER(this.valueBeforeDecode);
  386. AsnError.assert(asn1, "RelativeDistinguishedNames");
  387. if (!(asn1.result instanceof asn1js.Sequence)) {
  388. throw new Error("ASN.1 result should be SEQUENCE");
  389. }
  390. return asn1.result;
  391. }
  392. toJSON() {
  393. return {
  394. typesAndValues: Array.from(this.typesAndValues, o => o.toJSON())
  395. };
  396. }
  397. isEqual(compareTo) {
  398. if (compareTo instanceof RelativeDistinguishedNames) {
  399. if (this.typesAndValues.length !== compareTo.typesAndValues.length)
  400. return false;
  401. for (const [index, typeAndValue] of this.typesAndValues.entries()) {
  402. if (typeAndValue.isEqual(compareTo.typesAndValues[index]) === false)
  403. return false;
  404. }
  405. return true;
  406. }
  407. if (compareTo instanceof ArrayBuffer) {
  408. return pvutils.isEqualBuffer(this.valueBeforeDecode, compareTo);
  409. }
  410. return false;
  411. }
  412. }
  413. RelativeDistinguishedNames.CLASS_NAME = "RelativeDistinguishedNames";
  414. const TYPE$4 = "type";
  415. const VALUE$5 = "value";
  416. function builtInStandardAttributes(parameters = {}, optional = false) {
  417. const names = pvutils.getParametersValue(parameters, "names", {});
  418. return (new asn1js.Sequence({
  419. optional,
  420. value: [
  421. new asn1js.Constructed({
  422. optional: true,
  423. idBlock: {
  424. tagClass: 2,
  425. tagNumber: 1
  426. },
  427. name: (names.country_name || EMPTY_STRING),
  428. value: [
  429. new asn1js.Choice({
  430. value: [
  431. new asn1js.NumericString(),
  432. new asn1js.PrintableString()
  433. ]
  434. })
  435. ]
  436. }),
  437. new asn1js.Constructed({
  438. optional: true,
  439. idBlock: {
  440. tagClass: 2,
  441. tagNumber: 2
  442. },
  443. name: (names.administration_domain_name || EMPTY_STRING),
  444. value: [
  445. new asn1js.Choice({
  446. value: [
  447. new asn1js.NumericString(),
  448. new asn1js.PrintableString()
  449. ]
  450. })
  451. ]
  452. }),
  453. new asn1js.Primitive({
  454. optional: true,
  455. idBlock: {
  456. tagClass: 3,
  457. tagNumber: 0
  458. },
  459. name: (names.network_address || EMPTY_STRING),
  460. isHexOnly: true
  461. }),
  462. new asn1js.Primitive({
  463. optional: true,
  464. idBlock: {
  465. tagClass: 3,
  466. tagNumber: 1
  467. },
  468. name: (names.terminal_identifier || EMPTY_STRING),
  469. isHexOnly: true
  470. }),
  471. new asn1js.Constructed({
  472. optional: true,
  473. idBlock: {
  474. tagClass: 3,
  475. tagNumber: 2
  476. },
  477. name: (names.private_domain_name || EMPTY_STRING),
  478. value: [
  479. new asn1js.Choice({
  480. value: [
  481. new asn1js.NumericString(),
  482. new asn1js.PrintableString()
  483. ]
  484. })
  485. ]
  486. }),
  487. new asn1js.Primitive({
  488. optional: true,
  489. idBlock: {
  490. tagClass: 3,
  491. tagNumber: 3
  492. },
  493. name: (names.organization_name || EMPTY_STRING),
  494. isHexOnly: true
  495. }),
  496. new asn1js.Primitive({
  497. optional: true,
  498. name: (names.numeric_user_identifier || EMPTY_STRING),
  499. idBlock: {
  500. tagClass: 3,
  501. tagNumber: 4
  502. },
  503. isHexOnly: true
  504. }),
  505. new asn1js.Constructed({
  506. optional: true,
  507. name: (names.personal_name || EMPTY_STRING),
  508. idBlock: {
  509. tagClass: 3,
  510. tagNumber: 5
  511. },
  512. value: [
  513. new asn1js.Primitive({
  514. idBlock: {
  515. tagClass: 3,
  516. tagNumber: 0
  517. },
  518. isHexOnly: true
  519. }),
  520. new asn1js.Primitive({
  521. optional: true,
  522. idBlock: {
  523. tagClass: 3,
  524. tagNumber: 1
  525. },
  526. isHexOnly: true
  527. }),
  528. new asn1js.Primitive({
  529. optional: true,
  530. idBlock: {
  531. tagClass: 3,
  532. tagNumber: 2
  533. },
  534. isHexOnly: true
  535. }),
  536. new asn1js.Primitive({
  537. optional: true,
  538. idBlock: {
  539. tagClass: 3,
  540. tagNumber: 3
  541. },
  542. isHexOnly: true
  543. })
  544. ]
  545. }),
  546. new asn1js.Constructed({
  547. optional: true,
  548. name: (names.organizational_unit_names || EMPTY_STRING),
  549. idBlock: {
  550. tagClass: 3,
  551. tagNumber: 6
  552. },
  553. value: [
  554. new asn1js.Repeated({
  555. value: new asn1js.PrintableString()
  556. })
  557. ]
  558. })
  559. ]
  560. }));
  561. }
  562. function builtInDomainDefinedAttributes(optional = false) {
  563. return (new asn1js.Sequence({
  564. optional,
  565. value: [
  566. new asn1js.PrintableString(),
  567. new asn1js.PrintableString()
  568. ]
  569. }));
  570. }
  571. function extensionAttributes(optional = false) {
  572. return (new asn1js.Set({
  573. optional,
  574. value: [
  575. new asn1js.Primitive({
  576. optional: true,
  577. idBlock: {
  578. tagClass: 3,
  579. tagNumber: 0
  580. },
  581. isHexOnly: true
  582. }),
  583. new asn1js.Constructed({
  584. optional: true,
  585. idBlock: {
  586. tagClass: 3,
  587. tagNumber: 1
  588. },
  589. value: [new asn1js.Any()]
  590. })
  591. ]
  592. }));
  593. }
  594. class GeneralName extends PkiObject {
  595. constructor(parameters = {}) {
  596. super();
  597. this.type = pvutils.getParametersValue(parameters, TYPE$4, GeneralName.defaultValues(TYPE$4));
  598. this.value = pvutils.getParametersValue(parameters, VALUE$5, GeneralName.defaultValues(VALUE$5));
  599. if (parameters.schema) {
  600. this.fromSchema(parameters.schema);
  601. }
  602. }
  603. static defaultValues(memberName) {
  604. switch (memberName) {
  605. case TYPE$4:
  606. return 9;
  607. case VALUE$5:
  608. return {};
  609. default:
  610. return super.defaultValues(memberName);
  611. }
  612. }
  613. static compareWithDefault(memberName, memberValue) {
  614. switch (memberName) {
  615. case TYPE$4:
  616. return (memberValue === GeneralName.defaultValues(memberName));
  617. case VALUE$5:
  618. return (Object.keys(memberValue).length === 0);
  619. default:
  620. return super.defaultValues(memberName);
  621. }
  622. }
  623. static schema(parameters = {}) {
  624. const names = pvutils.getParametersValue(parameters, "names", {});
  625. return (new asn1js.Choice({
  626. value: [
  627. new asn1js.Constructed({
  628. idBlock: {
  629. tagClass: 3,
  630. tagNumber: 0
  631. },
  632. name: (names.blockName || EMPTY_STRING),
  633. value: [
  634. new asn1js.ObjectIdentifier(),
  635. new asn1js.Constructed({
  636. idBlock: {
  637. tagClass: 3,
  638. tagNumber: 0
  639. },
  640. value: [new asn1js.Any()]
  641. })
  642. ]
  643. }),
  644. new asn1js.Primitive({
  645. name: (names.blockName || EMPTY_STRING),
  646. idBlock: {
  647. tagClass: 3,
  648. tagNumber: 1
  649. }
  650. }),
  651. new asn1js.Primitive({
  652. name: (names.blockName || EMPTY_STRING),
  653. idBlock: {
  654. tagClass: 3,
  655. tagNumber: 2
  656. }
  657. }),
  658. new asn1js.Constructed({
  659. idBlock: {
  660. tagClass: 3,
  661. tagNumber: 3
  662. },
  663. name: (names.blockName || EMPTY_STRING),
  664. value: [
  665. builtInStandardAttributes((names.builtInStandardAttributes || {}), false),
  666. builtInDomainDefinedAttributes(true),
  667. extensionAttributes(true)
  668. ]
  669. }),
  670. new asn1js.Constructed({
  671. idBlock: {
  672. tagClass: 3,
  673. tagNumber: 4
  674. },
  675. name: (names.blockName || EMPTY_STRING),
  676. value: [RelativeDistinguishedNames.schema(names.directoryName || {})]
  677. }),
  678. new asn1js.Constructed({
  679. idBlock: {
  680. tagClass: 3,
  681. tagNumber: 5
  682. },
  683. name: (names.blockName || EMPTY_STRING),
  684. value: [
  685. new asn1js.Constructed({
  686. optional: true,
  687. idBlock: {
  688. tagClass: 3,
  689. tagNumber: 0
  690. },
  691. value: [
  692. new asn1js.Choice({
  693. value: [
  694. new asn1js.TeletexString(),
  695. new asn1js.PrintableString(),
  696. new asn1js.UniversalString(),
  697. new asn1js.Utf8String(),
  698. new asn1js.BmpString()
  699. ]
  700. })
  701. ]
  702. }),
  703. new asn1js.Constructed({
  704. idBlock: {
  705. tagClass: 3,
  706. tagNumber: 1
  707. },
  708. value: [
  709. new asn1js.Choice({
  710. value: [
  711. new asn1js.TeletexString(),
  712. new asn1js.PrintableString(),
  713. new asn1js.UniversalString(),
  714. new asn1js.Utf8String(),
  715. new asn1js.BmpString()
  716. ]
  717. })
  718. ]
  719. })
  720. ]
  721. }),
  722. new asn1js.Primitive({
  723. name: (names.blockName || EMPTY_STRING),
  724. idBlock: {
  725. tagClass: 3,
  726. tagNumber: 6
  727. }
  728. }),
  729. new asn1js.Primitive({
  730. name: (names.blockName || EMPTY_STRING),
  731. idBlock: {
  732. tagClass: 3,
  733. tagNumber: 7
  734. }
  735. }),
  736. new asn1js.Primitive({
  737. name: (names.blockName || EMPTY_STRING),
  738. idBlock: {
  739. tagClass: 3,
  740. tagNumber: 8
  741. }
  742. })
  743. ]
  744. }));
  745. }
  746. fromSchema(schema) {
  747. pvutils.clearProps(schema, [
  748. "blockName",
  749. "otherName",
  750. "rfc822Name",
  751. "dNSName",
  752. "x400Address",
  753. "directoryName",
  754. "ediPartyName",
  755. "uniformResourceIdentifier",
  756. "iPAddress",
  757. "registeredID"
  758. ]);
  759. const asn1 = asn1js.compareSchema(schema, schema, GeneralName.schema({
  760. names: {
  761. blockName: "blockName",
  762. otherName: "otherName",
  763. rfc822Name: "rfc822Name",
  764. dNSName: "dNSName",
  765. x400Address: "x400Address",
  766. directoryName: {
  767. names: {
  768. blockName: "directoryName"
  769. }
  770. },
  771. ediPartyName: "ediPartyName",
  772. uniformResourceIdentifier: "uniformResourceIdentifier",
  773. iPAddress: "iPAddress",
  774. registeredID: "registeredID"
  775. }
  776. }));
  777. AsnError.assertSchema(asn1, this.className);
  778. this.type = asn1.result.blockName.idBlock.tagNumber;
  779. switch (this.type) {
  780. case 0:
  781. this.value = asn1.result.blockName;
  782. break;
  783. case 1:
  784. case 2:
  785. case 6:
  786. {
  787. const value = asn1.result.blockName;
  788. value.idBlock.tagClass = 1;
  789. value.idBlock.tagNumber = 22;
  790. const valueBER = value.toBER(false);
  791. const asnValue = asn1js.fromBER(valueBER);
  792. AsnError.assert(asnValue, "GeneralName value");
  793. this.value = asnValue.result.valueBlock.value;
  794. }
  795. break;
  796. case 3:
  797. this.value = asn1.result.blockName;
  798. break;
  799. case 4:
  800. this.value = new RelativeDistinguishedNames({ schema: asn1.result.directoryName });
  801. break;
  802. case 5:
  803. this.value = asn1.result.ediPartyName;
  804. break;
  805. case 7:
  806. this.value = new asn1js.OctetString({ valueHex: asn1.result.blockName.valueBlock.valueHex });
  807. break;
  808. case 8:
  809. {
  810. const value = asn1.result.blockName;
  811. value.idBlock.tagClass = 1;
  812. value.idBlock.tagNumber = 6;
  813. const valueBER = value.toBER(false);
  814. const asnValue = asn1js.fromBER(valueBER);
  815. AsnError.assert(asnValue, "GeneralName registeredID");
  816. this.value = asnValue.result.valueBlock.toString();
  817. }
  818. break;
  819. }
  820. }
  821. toSchema() {
  822. switch (this.type) {
  823. case 0:
  824. case 3:
  825. case 5:
  826. return new asn1js.Constructed({
  827. idBlock: {
  828. tagClass: 3,
  829. tagNumber: this.type
  830. },
  831. value: [
  832. this.value
  833. ]
  834. });
  835. case 1:
  836. case 2:
  837. case 6:
  838. {
  839. const value = new asn1js.IA5String({ value: this.value });
  840. value.idBlock.tagClass = 3;
  841. value.idBlock.tagNumber = this.type;
  842. return value;
  843. }
  844. case 4:
  845. return new asn1js.Constructed({
  846. idBlock: {
  847. tagClass: 3,
  848. tagNumber: 4
  849. },
  850. value: [this.value.toSchema()]
  851. });
  852. case 7:
  853. {
  854. const value = this.value;
  855. value.idBlock.tagClass = 3;
  856. value.idBlock.tagNumber = this.type;
  857. return value;
  858. }
  859. case 8:
  860. {
  861. const value = new asn1js.ObjectIdentifier({ value: this.value });
  862. value.idBlock.tagClass = 3;
  863. value.idBlock.tagNumber = this.type;
  864. return value;
  865. }
  866. default:
  867. return GeneralName.schema();
  868. }
  869. }
  870. toJSON() {
  871. const _object = {
  872. type: this.type,
  873. value: EMPTY_STRING
  874. };
  875. if ((typeof this.value) === "string")
  876. _object.value = this.value;
  877. else {
  878. try {
  879. _object.value = this.value.toJSON();
  880. }
  881. catch {
  882. }
  883. }
  884. return _object;
  885. }
  886. }
  887. GeneralName.CLASS_NAME = "GeneralName";
  888. const ACCESS_METHOD = "accessMethod";
  889. const ACCESS_LOCATION = "accessLocation";
  890. const CLEAR_PROPS$1v = [
  891. ACCESS_METHOD,
  892. ACCESS_LOCATION,
  893. ];
  894. class AccessDescription extends PkiObject {
  895. constructor(parameters = {}) {
  896. super();
  897. this.accessMethod = pvutils.getParametersValue(parameters, ACCESS_METHOD, AccessDescription.defaultValues(ACCESS_METHOD));
  898. this.accessLocation = pvutils.getParametersValue(parameters, ACCESS_LOCATION, AccessDescription.defaultValues(ACCESS_LOCATION));
  899. if (parameters.schema) {
  900. this.fromSchema(parameters.schema);
  901. }
  902. }
  903. static defaultValues(memberName) {
  904. switch (memberName) {
  905. case ACCESS_METHOD:
  906. return EMPTY_STRING;
  907. case ACCESS_LOCATION:
  908. return new GeneralName();
  909. default:
  910. return super.defaultValues(memberName);
  911. }
  912. }
  913. static schema(parameters = {}) {
  914. const names = pvutils.getParametersValue(parameters, "names", {});
  915. return (new asn1js.Sequence({
  916. name: (names.blockName || EMPTY_STRING),
  917. value: [
  918. new asn1js.ObjectIdentifier({ name: (names.accessMethod || EMPTY_STRING) }),
  919. GeneralName.schema(names.accessLocation || {})
  920. ]
  921. }));
  922. }
  923. fromSchema(schema) {
  924. pvutils.clearProps(schema, CLEAR_PROPS$1v);
  925. const asn1 = asn1js.compareSchema(schema, schema, AccessDescription.schema({
  926. names: {
  927. accessMethod: ACCESS_METHOD,
  928. accessLocation: {
  929. names: {
  930. blockName: ACCESS_LOCATION
  931. }
  932. }
  933. }
  934. }));
  935. AsnError.assertSchema(asn1, this.className);
  936. this.accessMethod = asn1.result.accessMethod.valueBlock.toString();
  937. this.accessLocation = new GeneralName({ schema: asn1.result.accessLocation });
  938. }
  939. toSchema() {
  940. return (new asn1js.Sequence({
  941. value: [
  942. new asn1js.ObjectIdentifier({ value: this.accessMethod }),
  943. this.accessLocation.toSchema()
  944. ]
  945. }));
  946. }
  947. toJSON() {
  948. return {
  949. accessMethod: this.accessMethod,
  950. accessLocation: this.accessLocation.toJSON()
  951. };
  952. }
  953. }
  954. AccessDescription.CLASS_NAME = "AccessDescription";
  955. const SECONDS = "seconds";
  956. const MILLIS = "millis";
  957. const MICROS = "micros";
  958. class Accuracy extends PkiObject {
  959. constructor(parameters = {}) {
  960. super();
  961. if (SECONDS in parameters) {
  962. this.seconds = pvutils.getParametersValue(parameters, SECONDS, Accuracy.defaultValues(SECONDS));
  963. }
  964. if (MILLIS in parameters) {
  965. this.millis = pvutils.getParametersValue(parameters, MILLIS, Accuracy.defaultValues(MILLIS));
  966. }
  967. if (MICROS in parameters) {
  968. this.micros = pvutils.getParametersValue(parameters, MICROS, Accuracy.defaultValues(MICROS));
  969. }
  970. if (parameters.schema) {
  971. this.fromSchema(parameters.schema);
  972. }
  973. }
  974. static defaultValues(memberName) {
  975. switch (memberName) {
  976. case SECONDS:
  977. case MILLIS:
  978. case MICROS:
  979. return 0;
  980. default:
  981. return super.defaultValues(memberName);
  982. }
  983. }
  984. static compareWithDefault(memberName, memberValue) {
  985. switch (memberName) {
  986. case SECONDS:
  987. case MILLIS:
  988. case MICROS:
  989. return (memberValue === Accuracy.defaultValues(memberName));
  990. default:
  991. return super.defaultValues(memberName);
  992. }
  993. }
  994. static schema(parameters = {}) {
  995. const names = pvutils.getParametersValue(parameters, "names", {});
  996. return (new asn1js.Sequence({
  997. name: (names.blockName || EMPTY_STRING),
  998. optional: true,
  999. value: [
  1000. new asn1js.Integer({
  1001. optional: true,
  1002. name: (names.seconds || EMPTY_STRING)
  1003. }),
  1004. new asn1js.Primitive({
  1005. name: (names.millis || EMPTY_STRING),
  1006. optional: true,
  1007. idBlock: {
  1008. tagClass: 3,
  1009. tagNumber: 0
  1010. }
  1011. }),
  1012. new asn1js.Primitive({
  1013. name: (names.micros || EMPTY_STRING),
  1014. optional: true,
  1015. idBlock: {
  1016. tagClass: 3,
  1017. tagNumber: 1
  1018. }
  1019. })
  1020. ]
  1021. }));
  1022. }
  1023. fromSchema(schema) {
  1024. pvutils.clearProps(schema, [
  1025. SECONDS,
  1026. MILLIS,
  1027. MICROS,
  1028. ]);
  1029. const asn1 = asn1js.compareSchema(schema, schema, Accuracy.schema({
  1030. names: {
  1031. seconds: SECONDS,
  1032. millis: MILLIS,
  1033. micros: MICROS,
  1034. }
  1035. }));
  1036. AsnError.assertSchema(asn1, this.className);
  1037. if ("seconds" in asn1.result) {
  1038. this.seconds = asn1.result.seconds.valueBlock.valueDec;
  1039. }
  1040. if ("millis" in asn1.result) {
  1041. const intMillis = new asn1js.Integer({ valueHex: asn1.result.millis.valueBlock.valueHex });
  1042. this.millis = intMillis.valueBlock.valueDec;
  1043. }
  1044. if ("micros" in asn1.result) {
  1045. const intMicros = new asn1js.Integer({ valueHex: asn1.result.micros.valueBlock.valueHex });
  1046. this.micros = intMicros.valueBlock.valueDec;
  1047. }
  1048. }
  1049. toSchema() {
  1050. const outputArray = [];
  1051. if (this.seconds !== undefined)
  1052. outputArray.push(new asn1js.Integer({ value: this.seconds }));
  1053. if (this.millis !== undefined) {
  1054. const intMillis = new asn1js.Integer({ value: this.millis });
  1055. outputArray.push(new asn1js.Primitive({
  1056. idBlock: {
  1057. tagClass: 3,
  1058. tagNumber: 0
  1059. },
  1060. valueHex: intMillis.valueBlock.valueHexView
  1061. }));
  1062. }
  1063. if (this.micros !== undefined) {
  1064. const intMicros = new asn1js.Integer({ value: this.micros });
  1065. outputArray.push(new asn1js.Primitive({
  1066. idBlock: {
  1067. tagClass: 3,
  1068. tagNumber: 1
  1069. },
  1070. valueHex: intMicros.valueBlock.valueHexView
  1071. }));
  1072. }
  1073. return (new asn1js.Sequence({
  1074. value: outputArray
  1075. }));
  1076. }
  1077. toJSON() {
  1078. const _object = {};
  1079. if (this.seconds !== undefined)
  1080. _object.seconds = this.seconds;
  1081. if (this.millis !== undefined)
  1082. _object.millis = this.millis;
  1083. if (this.micros !== undefined)
  1084. _object.micros = this.micros;
  1085. return _object;
  1086. }
  1087. }
  1088. Accuracy.CLASS_NAME = "Accuracy";
  1089. const ALGORITHM_ID = "algorithmId";
  1090. const ALGORITHM_PARAMS = "algorithmParams";
  1091. const ALGORITHM$2 = "algorithm";
  1092. const PARAMS = "params";
  1093. const CLEAR_PROPS$1u = [
  1094. ALGORITHM$2,
  1095. PARAMS
  1096. ];
  1097. class AlgorithmIdentifier extends PkiObject {
  1098. constructor(parameters = {}) {
  1099. super();
  1100. this.algorithmId = pvutils.getParametersValue(parameters, ALGORITHM_ID, AlgorithmIdentifier.defaultValues(ALGORITHM_ID));
  1101. if (ALGORITHM_PARAMS in parameters) {
  1102. this.algorithmParams = pvutils.getParametersValue(parameters, ALGORITHM_PARAMS, AlgorithmIdentifier.defaultValues(ALGORITHM_PARAMS));
  1103. }
  1104. if (parameters.schema) {
  1105. this.fromSchema(parameters.schema);
  1106. }
  1107. }
  1108. static defaultValues(memberName) {
  1109. switch (memberName) {
  1110. case ALGORITHM_ID:
  1111. return EMPTY_STRING;
  1112. case ALGORITHM_PARAMS:
  1113. return new asn1js.Any();
  1114. default:
  1115. return super.defaultValues(memberName);
  1116. }
  1117. }
  1118. static compareWithDefault(memberName, memberValue) {
  1119. switch (memberName) {
  1120. case ALGORITHM_ID:
  1121. return (memberValue === EMPTY_STRING);
  1122. case ALGORITHM_PARAMS:
  1123. return (memberValue instanceof asn1js.Any);
  1124. default:
  1125. return super.defaultValues(memberName);
  1126. }
  1127. }
  1128. static schema(parameters = {}) {
  1129. const names = pvutils.getParametersValue(parameters, "names", {});
  1130. return (new asn1js.Sequence({
  1131. name: (names.blockName || EMPTY_STRING),
  1132. optional: (names.optional || false),
  1133. value: [
  1134. new asn1js.ObjectIdentifier({ name: (names.algorithmIdentifier || EMPTY_STRING) }),
  1135. new asn1js.Any({ name: (names.algorithmParams || EMPTY_STRING), optional: true })
  1136. ]
  1137. }));
  1138. }
  1139. fromSchema(schema) {
  1140. pvutils.clearProps(schema, CLEAR_PROPS$1u);
  1141. const asn1 = asn1js.compareSchema(schema, schema, AlgorithmIdentifier.schema({
  1142. names: {
  1143. algorithmIdentifier: ALGORITHM$2,
  1144. algorithmParams: PARAMS
  1145. }
  1146. }));
  1147. AsnError.assertSchema(asn1, this.className);
  1148. this.algorithmId = asn1.result.algorithm.valueBlock.toString();
  1149. if (PARAMS in asn1.result) {
  1150. this.algorithmParams = asn1.result.params;
  1151. }
  1152. }
  1153. toSchema() {
  1154. const outputArray = [];
  1155. outputArray.push(new asn1js.ObjectIdentifier({ value: this.algorithmId }));
  1156. if (this.algorithmParams && !(this.algorithmParams instanceof asn1js.Any)) {
  1157. outputArray.push(this.algorithmParams);
  1158. }
  1159. return (new asn1js.Sequence({
  1160. value: outputArray
  1161. }));
  1162. }
  1163. toJSON() {
  1164. const object = {
  1165. algorithmId: this.algorithmId
  1166. };
  1167. if (this.algorithmParams && !(this.algorithmParams instanceof asn1js.Any)) {
  1168. object.algorithmParams = this.algorithmParams.toJSON();
  1169. }
  1170. return object;
  1171. }
  1172. isEqual(algorithmIdentifier) {
  1173. if (!(algorithmIdentifier instanceof AlgorithmIdentifier)) {
  1174. return false;
  1175. }
  1176. if (this.algorithmId !== algorithmIdentifier.algorithmId) {
  1177. return false;
  1178. }
  1179. if (this.algorithmParams) {
  1180. if (algorithmIdentifier.algorithmParams) {
  1181. return JSON.stringify(this.algorithmParams) === JSON.stringify(algorithmIdentifier.algorithmParams);
  1182. }
  1183. return false;
  1184. }
  1185. if (algorithmIdentifier.algorithmParams) {
  1186. return false;
  1187. }
  1188. return true;
  1189. }
  1190. }
  1191. AlgorithmIdentifier.CLASS_NAME = "AlgorithmIdentifier";
  1192. const ALT_NAMES = "altNames";
  1193. const CLEAR_PROPS$1t = [
  1194. ALT_NAMES
  1195. ];
  1196. class AltName extends PkiObject {
  1197. constructor(parameters = {}) {
  1198. super();
  1199. this.altNames = pvutils.getParametersValue(parameters, ALT_NAMES, AltName.defaultValues(ALT_NAMES));
  1200. if (parameters.schema) {
  1201. this.fromSchema(parameters.schema);
  1202. }
  1203. }
  1204. static defaultValues(memberName) {
  1205. switch (memberName) {
  1206. case ALT_NAMES:
  1207. return [];
  1208. default:
  1209. return super.defaultValues(memberName);
  1210. }
  1211. }
  1212. static schema(parameters = {}) {
  1213. const names = pvutils.getParametersValue(parameters, "names", {});
  1214. return (new asn1js.Sequence({
  1215. name: (names.blockName || EMPTY_STRING),
  1216. value: [
  1217. new asn1js.Repeated({
  1218. name: (names.altNames || EMPTY_STRING),
  1219. value: GeneralName.schema()
  1220. })
  1221. ]
  1222. }));
  1223. }
  1224. fromSchema(schema) {
  1225. pvutils.clearProps(schema, CLEAR_PROPS$1t);
  1226. const asn1 = asn1js.compareSchema(schema, schema, AltName.schema({
  1227. names: {
  1228. altNames: ALT_NAMES
  1229. }
  1230. }));
  1231. AsnError.assertSchema(asn1, this.className);
  1232. if (ALT_NAMES in asn1.result) {
  1233. this.altNames = Array.from(asn1.result.altNames, element => new GeneralName({ schema: element }));
  1234. }
  1235. }
  1236. toSchema() {
  1237. return (new asn1js.Sequence({
  1238. value: Array.from(this.altNames, o => o.toSchema())
  1239. }));
  1240. }
  1241. toJSON() {
  1242. return {
  1243. altNames: Array.from(this.altNames, o => o.toJSON())
  1244. };
  1245. }
  1246. }
  1247. AltName.CLASS_NAME = "AltName";
  1248. const TYPE$3 = "type";
  1249. const VALUES$1 = "values";
  1250. const CLEAR_PROPS$1s = [
  1251. TYPE$3,
  1252. VALUES$1
  1253. ];
  1254. class Attribute extends PkiObject {
  1255. constructor(parameters = {}) {
  1256. super();
  1257. this.type = pvutils.getParametersValue(parameters, TYPE$3, Attribute.defaultValues(TYPE$3));
  1258. this.values = pvutils.getParametersValue(parameters, VALUES$1, Attribute.defaultValues(VALUES$1));
  1259. if (parameters.schema) {
  1260. this.fromSchema(parameters.schema);
  1261. }
  1262. }
  1263. static defaultValues(memberName) {
  1264. switch (memberName) {
  1265. case TYPE$3:
  1266. return EMPTY_STRING;
  1267. case VALUES$1:
  1268. return [];
  1269. default:
  1270. return super.defaultValues(memberName);
  1271. }
  1272. }
  1273. static compareWithDefault(memberName, memberValue) {
  1274. switch (memberName) {
  1275. case TYPE$3:
  1276. return (memberValue === EMPTY_STRING);
  1277. case VALUES$1:
  1278. return (memberValue.length === 0);
  1279. default:
  1280. return super.defaultValues(memberName);
  1281. }
  1282. }
  1283. static schema(parameters = {}) {
  1284. const names = pvutils.getParametersValue(parameters, "names", {});
  1285. return (new asn1js.Sequence({
  1286. name: (names.blockName || EMPTY_STRING),
  1287. value: [
  1288. new asn1js.ObjectIdentifier({ name: (names.type || EMPTY_STRING) }),
  1289. new asn1js.Set({
  1290. name: (names.setName || EMPTY_STRING),
  1291. value: [
  1292. new asn1js.Repeated({
  1293. name: (names.values || EMPTY_STRING),
  1294. value: new asn1js.Any()
  1295. })
  1296. ]
  1297. })
  1298. ]
  1299. }));
  1300. }
  1301. fromSchema(schema) {
  1302. pvutils.clearProps(schema, CLEAR_PROPS$1s);
  1303. const asn1 = asn1js.compareSchema(schema, schema, Attribute.schema({
  1304. names: {
  1305. type: TYPE$3,
  1306. values: VALUES$1
  1307. }
  1308. }));
  1309. AsnError.assertSchema(asn1, this.className);
  1310. this.type = asn1.result.type.valueBlock.toString();
  1311. this.values = asn1.result.values;
  1312. }
  1313. toSchema() {
  1314. return (new asn1js.Sequence({
  1315. value: [
  1316. new asn1js.ObjectIdentifier({ value: this.type }),
  1317. new asn1js.Set({
  1318. value: this.values
  1319. })
  1320. ]
  1321. }));
  1322. }
  1323. toJSON() {
  1324. return {
  1325. type: this.type,
  1326. values: Array.from(this.values, o => o.toJSON())
  1327. };
  1328. }
  1329. }
  1330. Attribute.CLASS_NAME = "Attribute";
  1331. const NOT_BEFORE_TIME = "notBeforeTime";
  1332. const NOT_AFTER_TIME = "notAfterTime";
  1333. const CLEAR_PROPS$1r = [
  1334. NOT_BEFORE_TIME,
  1335. NOT_AFTER_TIME,
  1336. ];
  1337. class AttCertValidityPeriod extends PkiObject {
  1338. constructor(parameters = {}) {
  1339. super();
  1340. this.notBeforeTime = pvutils.getParametersValue(parameters, NOT_BEFORE_TIME, AttCertValidityPeriod.defaultValues(NOT_BEFORE_TIME));
  1341. this.notAfterTime = pvutils.getParametersValue(parameters, NOT_AFTER_TIME, AttCertValidityPeriod.defaultValues(NOT_AFTER_TIME));
  1342. if (parameters.schema) {
  1343. this.fromSchema(parameters.schema);
  1344. }
  1345. }
  1346. static defaultValues(memberName) {
  1347. switch (memberName) {
  1348. case NOT_BEFORE_TIME:
  1349. case NOT_AFTER_TIME:
  1350. return new Date(0, 0, 0);
  1351. default:
  1352. return super.defaultValues(memberName);
  1353. }
  1354. }
  1355. static schema(parameters = {}) {
  1356. const names = pvutils.getParametersValue(parameters, "names", {});
  1357. return (new asn1js.Sequence({
  1358. name: (names.blockName || EMPTY_STRING),
  1359. value: [
  1360. new asn1js.GeneralizedTime({ name: (names.notBeforeTime || EMPTY_STRING) }),
  1361. new asn1js.GeneralizedTime({ name: (names.notAfterTime || EMPTY_STRING) })
  1362. ]
  1363. }));
  1364. }
  1365. fromSchema(schema) {
  1366. pvutils.clearProps(schema, CLEAR_PROPS$1r);
  1367. const asn1 = asn1js.compareSchema(schema, schema, AttCertValidityPeriod.schema({
  1368. names: {
  1369. notBeforeTime: NOT_BEFORE_TIME,
  1370. notAfterTime: NOT_AFTER_TIME
  1371. }
  1372. }));
  1373. AsnError.assertSchema(asn1, this.className);
  1374. this.notBeforeTime = asn1.result.notBeforeTime.toDate();
  1375. this.notAfterTime = asn1.result.notAfterTime.toDate();
  1376. }
  1377. toSchema() {
  1378. return (new asn1js.Sequence({
  1379. value: [
  1380. new asn1js.GeneralizedTime({ valueDate: this.notBeforeTime }),
  1381. new asn1js.GeneralizedTime({ valueDate: this.notAfterTime }),
  1382. ]
  1383. }));
  1384. }
  1385. toJSON() {
  1386. return {
  1387. notBeforeTime: this.notBeforeTime,
  1388. notAfterTime: this.notAfterTime
  1389. };
  1390. }
  1391. }
  1392. AttCertValidityPeriod.CLASS_NAME = "AttCertValidityPeriod";
  1393. const NAMES = "names";
  1394. const GENERAL_NAMES = "generalNames";
  1395. class GeneralNames extends PkiObject {
  1396. constructor(parameters = {}) {
  1397. super();
  1398. this.names = pvutils.getParametersValue(parameters, NAMES, GeneralNames.defaultValues(NAMES));
  1399. if (parameters.schema) {
  1400. this.fromSchema(parameters.schema);
  1401. }
  1402. }
  1403. static defaultValues(memberName) {
  1404. switch (memberName) {
  1405. case "names":
  1406. return [];
  1407. default:
  1408. return super.defaultValues(memberName);
  1409. }
  1410. }
  1411. static schema(parameters = {}, optional = false) {
  1412. const names = pvutils.getParametersValue(parameters, NAMES, {});
  1413. return (new asn1js.Sequence({
  1414. optional,
  1415. name: (names.blockName || EMPTY_STRING),
  1416. value: [
  1417. new asn1js.Repeated({
  1418. name: (names.generalNames || EMPTY_STRING),
  1419. value: GeneralName.schema()
  1420. })
  1421. ]
  1422. }));
  1423. }
  1424. fromSchema(schema) {
  1425. pvutils.clearProps(schema, [
  1426. NAMES,
  1427. GENERAL_NAMES
  1428. ]);
  1429. const asn1 = asn1js.compareSchema(schema, schema, GeneralNames.schema({
  1430. names: {
  1431. blockName: NAMES,
  1432. generalNames: GENERAL_NAMES
  1433. }
  1434. }));
  1435. AsnError.assertSchema(asn1, this.className);
  1436. this.names = Array.from(asn1.result.generalNames, element => new GeneralName({ schema: element }));
  1437. }
  1438. toSchema() {
  1439. return (new asn1js.Sequence({
  1440. value: Array.from(this.names, o => o.toSchema())
  1441. }));
  1442. }
  1443. toJSON() {
  1444. return {
  1445. names: Array.from(this.names, o => o.toJSON())
  1446. };
  1447. }
  1448. }
  1449. GeneralNames.CLASS_NAME = "GeneralNames";
  1450. const id_SubjectDirectoryAttributes = "2.5.29.9";
  1451. const id_SubjectKeyIdentifier = "2.5.29.14";
  1452. const id_KeyUsage = "2.5.29.15";
  1453. const id_PrivateKeyUsagePeriod = "2.5.29.16";
  1454. const id_SubjectAltName = "2.5.29.17";
  1455. const id_IssuerAltName = "2.5.29.18";
  1456. const id_BasicConstraints = "2.5.29.19";
  1457. const id_CRLNumber = "2.5.29.20";
  1458. const id_BaseCRLNumber = "2.5.29.27";
  1459. const id_CRLReason = "2.5.29.21";
  1460. const id_InvalidityDate = "2.5.29.24";
  1461. const id_IssuingDistributionPoint = "2.5.29.28";
  1462. const id_CertificateIssuer = "2.5.29.29";
  1463. const id_NameConstraints = "2.5.29.30";
  1464. const id_CRLDistributionPoints = "2.5.29.31";
  1465. const id_FreshestCRL = "2.5.29.46";
  1466. const id_CertificatePolicies = "2.5.29.32";
  1467. const id_AnyPolicy = "2.5.29.32.0";
  1468. const id_MicrosoftAppPolicies = "1.3.6.1.4.1.311.21.10";
  1469. const id_PolicyMappings = "2.5.29.33";
  1470. const id_AuthorityKeyIdentifier = "2.5.29.35";
  1471. const id_PolicyConstraints = "2.5.29.36";
  1472. const id_ExtKeyUsage = "2.5.29.37";
  1473. const id_InhibitAnyPolicy = "2.5.29.54";
  1474. const id_AuthorityInfoAccess = "1.3.6.1.5.5.7.1.1";
  1475. const id_SubjectInfoAccess = "1.3.6.1.5.5.7.1.11";
  1476. const id_SignedCertificateTimestampList = "1.3.6.1.4.1.11129.2.4.2";
  1477. const id_MicrosoftCertTemplateV1 = "1.3.6.1.4.1.311.20.2";
  1478. const id_MicrosoftPrevCaCertHash = "1.3.6.1.4.1.311.21.2";
  1479. const id_MicrosoftCertTemplateV2 = "1.3.6.1.4.1.311.21.7";
  1480. const id_MicrosoftCaVersion = "1.3.6.1.4.1.311.21.1";
  1481. const id_QCStatements = "1.3.6.1.5.5.7.1.3";
  1482. const id_ContentType_Data = "1.2.840.113549.1.7.1";
  1483. const id_ContentType_SignedData = "1.2.840.113549.1.7.2";
  1484. const id_ContentType_EnvelopedData = "1.2.840.113549.1.7.3";
  1485. const id_ContentType_EncryptedData = "1.2.840.113549.1.7.6";
  1486. const id_eContentType_TSTInfo = "1.2.840.113549.1.9.16.1.4";
  1487. const id_CertBag_X509Certificate = "1.2.840.113549.1.9.22.1";
  1488. const id_CertBag_SDSICertificate = "1.2.840.113549.1.9.22.2";
  1489. const id_CertBag_AttributeCertificate = "1.2.840.113549.1.9.22.3";
  1490. const id_CRLBag_X509CRL = "1.2.840.113549.1.9.23.1";
  1491. const id_pkix = "1.3.6.1.5.5.7";
  1492. const id_ad = `${id_pkix}.48`;
  1493. const id_PKIX_OCSP_Basic = `${id_ad}.1.1`;
  1494. const id_ad_caIssuers = `${id_ad}.2`;
  1495. const id_ad_ocsp = `${id_ad}.1`;
  1496. const id_sha1 = "1.3.14.3.2.26";
  1497. const id_sha256 = "2.16.840.1.101.3.4.2.1";
  1498. const id_sha384 = "2.16.840.1.101.3.4.2.2";
  1499. const id_sha512 = "2.16.840.1.101.3.4.2.3";
  1500. const KEY_IDENTIFIER$1 = "keyIdentifier";
  1501. const AUTHORITY_CERT_ISSUER = "authorityCertIssuer";
  1502. const AUTHORITY_CERT_SERIAL_NUMBER = "authorityCertSerialNumber";
  1503. const CLEAR_PROPS$1q = [
  1504. KEY_IDENTIFIER$1,
  1505. AUTHORITY_CERT_ISSUER,
  1506. AUTHORITY_CERT_SERIAL_NUMBER,
  1507. ];
  1508. class AuthorityKeyIdentifier extends PkiObject {
  1509. constructor(parameters = {}) {
  1510. super();
  1511. if (KEY_IDENTIFIER$1 in parameters) {
  1512. this.keyIdentifier = pvutils.getParametersValue(parameters, KEY_IDENTIFIER$1, AuthorityKeyIdentifier.defaultValues(KEY_IDENTIFIER$1));
  1513. }
  1514. if (AUTHORITY_CERT_ISSUER in parameters) {
  1515. this.authorityCertIssuer = pvutils.getParametersValue(parameters, AUTHORITY_CERT_ISSUER, AuthorityKeyIdentifier.defaultValues(AUTHORITY_CERT_ISSUER));
  1516. }
  1517. if (AUTHORITY_CERT_SERIAL_NUMBER in parameters) {
  1518. this.authorityCertSerialNumber = pvutils.getParametersValue(parameters, AUTHORITY_CERT_SERIAL_NUMBER, AuthorityKeyIdentifier.defaultValues(AUTHORITY_CERT_SERIAL_NUMBER));
  1519. }
  1520. if (parameters.schema) {
  1521. this.fromSchema(parameters.schema);
  1522. }
  1523. }
  1524. static defaultValues(memberName) {
  1525. switch (memberName) {
  1526. case KEY_IDENTIFIER$1:
  1527. return new asn1js.OctetString();
  1528. case AUTHORITY_CERT_ISSUER:
  1529. return [];
  1530. case AUTHORITY_CERT_SERIAL_NUMBER:
  1531. return new asn1js.Integer();
  1532. default:
  1533. return super.defaultValues(memberName);
  1534. }
  1535. }
  1536. static schema(parameters = {}) {
  1537. const names = pvutils.getParametersValue(parameters, "names", {});
  1538. return (new asn1js.Sequence({
  1539. name: (names.blockName || EMPTY_STRING),
  1540. value: [
  1541. new asn1js.Primitive({
  1542. name: (names.keyIdentifier || EMPTY_STRING),
  1543. optional: true,
  1544. idBlock: {
  1545. tagClass: 3,
  1546. tagNumber: 0
  1547. }
  1548. }),
  1549. new asn1js.Constructed({
  1550. optional: true,
  1551. idBlock: {
  1552. tagClass: 3,
  1553. tagNumber: 1
  1554. },
  1555. value: [
  1556. new asn1js.Repeated({
  1557. name: (names.authorityCertIssuer || EMPTY_STRING),
  1558. value: GeneralName.schema()
  1559. })
  1560. ]
  1561. }),
  1562. new asn1js.Primitive({
  1563. name: (names.authorityCertSerialNumber || EMPTY_STRING),
  1564. optional: true,
  1565. idBlock: {
  1566. tagClass: 3,
  1567. tagNumber: 2
  1568. }
  1569. })
  1570. ]
  1571. }));
  1572. }
  1573. fromSchema(schema) {
  1574. pvutils.clearProps(schema, CLEAR_PROPS$1q);
  1575. const asn1 = asn1js.compareSchema(schema, schema, AuthorityKeyIdentifier.schema({
  1576. names: {
  1577. keyIdentifier: KEY_IDENTIFIER$1,
  1578. authorityCertIssuer: AUTHORITY_CERT_ISSUER,
  1579. authorityCertSerialNumber: AUTHORITY_CERT_SERIAL_NUMBER
  1580. }
  1581. }));
  1582. AsnError.assertSchema(asn1, this.className);
  1583. if (KEY_IDENTIFIER$1 in asn1.result)
  1584. this.keyIdentifier = new asn1js.OctetString({ valueHex: asn1.result.keyIdentifier.valueBlock.valueHex });
  1585. if (AUTHORITY_CERT_ISSUER in asn1.result)
  1586. this.authorityCertIssuer = Array.from(asn1.result.authorityCertIssuer, o => new GeneralName({ schema: o }));
  1587. if (AUTHORITY_CERT_SERIAL_NUMBER in asn1.result)
  1588. this.authorityCertSerialNumber = new asn1js.Integer({ valueHex: asn1.result.authorityCertSerialNumber.valueBlock.valueHex });
  1589. }
  1590. toSchema() {
  1591. const outputArray = [];
  1592. if (this.keyIdentifier) {
  1593. outputArray.push(new asn1js.Primitive({
  1594. idBlock: {
  1595. tagClass: 3,
  1596. tagNumber: 0
  1597. },
  1598. valueHex: this.keyIdentifier.valueBlock.valueHexView
  1599. }));
  1600. }
  1601. if (this.authorityCertIssuer) {
  1602. outputArray.push(new asn1js.Constructed({
  1603. idBlock: {
  1604. tagClass: 3,
  1605. tagNumber: 1
  1606. },
  1607. value: Array.from(this.authorityCertIssuer, o => o.toSchema())
  1608. }));
  1609. }
  1610. if (this.authorityCertSerialNumber) {
  1611. outputArray.push(new asn1js.Primitive({
  1612. idBlock: {
  1613. tagClass: 3,
  1614. tagNumber: 2
  1615. },
  1616. valueHex: this.authorityCertSerialNumber.valueBlock.valueHexView
  1617. }));
  1618. }
  1619. return (new asn1js.Sequence({
  1620. value: outputArray
  1621. }));
  1622. }
  1623. toJSON() {
  1624. const object = {};
  1625. if (this.keyIdentifier) {
  1626. object.keyIdentifier = this.keyIdentifier.toJSON();
  1627. }
  1628. if (this.authorityCertIssuer) {
  1629. object.authorityCertIssuer = Array.from(this.authorityCertIssuer, o => o.toJSON());
  1630. }
  1631. if (this.authorityCertSerialNumber) {
  1632. object.authorityCertSerialNumber = this.authorityCertSerialNumber.toJSON();
  1633. }
  1634. return object;
  1635. }
  1636. }
  1637. AuthorityKeyIdentifier.CLASS_NAME = "AuthorityKeyIdentifier";
  1638. const PATH_LENGTH_CONSTRAINT = "pathLenConstraint";
  1639. const CA = "cA";
  1640. class BasicConstraints extends PkiObject {
  1641. constructor(parameters = {}) {
  1642. super();
  1643. this.cA = pvutils.getParametersValue(parameters, CA, false);
  1644. if (PATH_LENGTH_CONSTRAINT in parameters) {
  1645. this.pathLenConstraint = pvutils.getParametersValue(parameters, PATH_LENGTH_CONSTRAINT, 0);
  1646. }
  1647. if (parameters.schema) {
  1648. this.fromSchema(parameters.schema);
  1649. }
  1650. }
  1651. static defaultValues(memberName) {
  1652. switch (memberName) {
  1653. case CA:
  1654. return false;
  1655. default:
  1656. return super.defaultValues(memberName);
  1657. }
  1658. }
  1659. static schema(parameters = {}) {
  1660. const names = pvutils.getParametersValue(parameters, "names", {});
  1661. return (new asn1js.Sequence({
  1662. name: (names.blockName || EMPTY_STRING),
  1663. value: [
  1664. new asn1js.Boolean({
  1665. optional: true,
  1666. name: (names.cA || EMPTY_STRING)
  1667. }),
  1668. new asn1js.Integer({
  1669. optional: true,
  1670. name: (names.pathLenConstraint || EMPTY_STRING)
  1671. })
  1672. ]
  1673. }));
  1674. }
  1675. fromSchema(schema) {
  1676. pvutils.clearProps(schema, [
  1677. CA,
  1678. PATH_LENGTH_CONSTRAINT
  1679. ]);
  1680. const asn1 = asn1js.compareSchema(schema, schema, BasicConstraints.schema({
  1681. names: {
  1682. cA: CA,
  1683. pathLenConstraint: PATH_LENGTH_CONSTRAINT
  1684. }
  1685. }));
  1686. AsnError.assertSchema(asn1, this.className);
  1687. if (CA in asn1.result) {
  1688. this.cA = asn1.result.cA.valueBlock.value;
  1689. }
  1690. if (PATH_LENGTH_CONSTRAINT in asn1.result) {
  1691. if (asn1.result.pathLenConstraint.valueBlock.isHexOnly) {
  1692. this.pathLenConstraint = asn1.result.pathLenConstraint;
  1693. }
  1694. else {
  1695. this.pathLenConstraint = asn1.result.pathLenConstraint.valueBlock.valueDec;
  1696. }
  1697. }
  1698. }
  1699. toSchema() {
  1700. const outputArray = [];
  1701. if (this.cA !== BasicConstraints.defaultValues(CA))
  1702. outputArray.push(new asn1js.Boolean({ value: this.cA }));
  1703. if (PATH_LENGTH_CONSTRAINT in this) {
  1704. if (this.pathLenConstraint instanceof asn1js.Integer) {
  1705. outputArray.push(this.pathLenConstraint);
  1706. }
  1707. else {
  1708. outputArray.push(new asn1js.Integer({ value: this.pathLenConstraint }));
  1709. }
  1710. }
  1711. return (new asn1js.Sequence({
  1712. value: outputArray
  1713. }));
  1714. }
  1715. toJSON() {
  1716. const object = {};
  1717. if (this.cA !== BasicConstraints.defaultValues(CA)) {
  1718. object.cA = this.cA;
  1719. }
  1720. if (PATH_LENGTH_CONSTRAINT in this) {
  1721. if (this.pathLenConstraint instanceof asn1js.Integer) {
  1722. object.pathLenConstraint = this.pathLenConstraint.toJSON();
  1723. }
  1724. else {
  1725. object.pathLenConstraint = this.pathLenConstraint;
  1726. }
  1727. }
  1728. return object;
  1729. }
  1730. }
  1731. BasicConstraints.CLASS_NAME = "BasicConstraints";
  1732. const CERTIFICATE_INDEX = "certificateIndex";
  1733. const KEY_INDEX = "keyIndex";
  1734. class CAVersion extends PkiObject {
  1735. constructor(parameters = {}) {
  1736. super();
  1737. this.certificateIndex = pvutils.getParametersValue(parameters, CERTIFICATE_INDEX, CAVersion.defaultValues(CERTIFICATE_INDEX));
  1738. this.keyIndex = pvutils.getParametersValue(parameters, KEY_INDEX, CAVersion.defaultValues(KEY_INDEX));
  1739. if (parameters.schema) {
  1740. this.fromSchema(parameters.schema);
  1741. }
  1742. }
  1743. static defaultValues(memberName) {
  1744. switch (memberName) {
  1745. case CERTIFICATE_INDEX:
  1746. case KEY_INDEX:
  1747. return 0;
  1748. default:
  1749. return super.defaultValues(memberName);
  1750. }
  1751. }
  1752. static schema() {
  1753. return (new asn1js.Integer());
  1754. }
  1755. fromSchema(schema) {
  1756. if (schema.constructor.blockName() !== asn1js.Integer.blockName()) {
  1757. throw new Error("Object's schema was not verified against input data for CAVersion");
  1758. }
  1759. let value = schema.valueBlock.valueHex.slice(0);
  1760. const valueView = new Uint8Array(value);
  1761. switch (true) {
  1762. case (value.byteLength < 4):
  1763. {
  1764. const tempValue = new ArrayBuffer(4);
  1765. const tempValueView = new Uint8Array(tempValue);
  1766. tempValueView.set(valueView, 4 - value.byteLength);
  1767. value = tempValue.slice(0);
  1768. }
  1769. break;
  1770. case (value.byteLength > 4):
  1771. {
  1772. const tempValue = new ArrayBuffer(4);
  1773. const tempValueView = new Uint8Array(tempValue);
  1774. tempValueView.set(valueView.slice(0, 4));
  1775. value = tempValue.slice(0);
  1776. }
  1777. break;
  1778. }
  1779. const keyIndexBuffer = value.slice(0, 2);
  1780. const keyIndexView8 = new Uint8Array(keyIndexBuffer);
  1781. let temp = keyIndexView8[0];
  1782. keyIndexView8[0] = keyIndexView8[1];
  1783. keyIndexView8[1] = temp;
  1784. const keyIndexView16 = new Uint16Array(keyIndexBuffer);
  1785. this.keyIndex = keyIndexView16[0];
  1786. const certificateIndexBuffer = value.slice(2);
  1787. const certificateIndexView8 = new Uint8Array(certificateIndexBuffer);
  1788. temp = certificateIndexView8[0];
  1789. certificateIndexView8[0] = certificateIndexView8[1];
  1790. certificateIndexView8[1] = temp;
  1791. const certificateIndexView16 = new Uint16Array(certificateIndexBuffer);
  1792. this.certificateIndex = certificateIndexView16[0];
  1793. }
  1794. toSchema() {
  1795. const certificateIndexBuffer = new ArrayBuffer(2);
  1796. const certificateIndexView = new Uint16Array(certificateIndexBuffer);
  1797. certificateIndexView[0] = this.certificateIndex;
  1798. const certificateIndexView8 = new Uint8Array(certificateIndexBuffer);
  1799. let temp = certificateIndexView8[0];
  1800. certificateIndexView8[0] = certificateIndexView8[1];
  1801. certificateIndexView8[1] = temp;
  1802. const keyIndexBuffer = new ArrayBuffer(2);
  1803. const keyIndexView = new Uint16Array(keyIndexBuffer);
  1804. keyIndexView[0] = this.keyIndex;
  1805. const keyIndexView8 = new Uint8Array(keyIndexBuffer);
  1806. temp = keyIndexView8[0];
  1807. keyIndexView8[0] = keyIndexView8[1];
  1808. keyIndexView8[1] = temp;
  1809. return (new asn1js.Integer({
  1810. valueHex: pvutils.utilConcatBuf(keyIndexBuffer, certificateIndexBuffer)
  1811. }));
  1812. }
  1813. toJSON() {
  1814. return {
  1815. certificateIndex: this.certificateIndex,
  1816. keyIndex: this.keyIndex
  1817. };
  1818. }
  1819. }
  1820. CAVersion.CLASS_NAME = "CAVersion";
  1821. const POLICY_QUALIFIER_ID = "policyQualifierId";
  1822. const QUALIFIER = "qualifier";
  1823. const CLEAR_PROPS$1p = [
  1824. POLICY_QUALIFIER_ID,
  1825. QUALIFIER
  1826. ];
  1827. class PolicyQualifierInfo extends PkiObject {
  1828. constructor(parameters = {}) {
  1829. super();
  1830. this.policyQualifierId = pvutils.getParametersValue(parameters, POLICY_QUALIFIER_ID, PolicyQualifierInfo.defaultValues(POLICY_QUALIFIER_ID));
  1831. this.qualifier = pvutils.getParametersValue(parameters, QUALIFIER, PolicyQualifierInfo.defaultValues(QUALIFIER));
  1832. if (parameters.schema) {
  1833. this.fromSchema(parameters.schema);
  1834. }
  1835. }
  1836. static defaultValues(memberName) {
  1837. switch (memberName) {
  1838. case POLICY_QUALIFIER_ID:
  1839. return EMPTY_STRING;
  1840. case QUALIFIER:
  1841. return new asn1js.Any();
  1842. default:
  1843. return super.defaultValues(memberName);
  1844. }
  1845. }
  1846. static schema(parameters = {}) {
  1847. const names = pvutils.getParametersValue(parameters, "names", {});
  1848. return (new asn1js.Sequence({
  1849. name: (names.blockName || EMPTY_STRING),
  1850. value: [
  1851. new asn1js.ObjectIdentifier({ name: (names.policyQualifierId || EMPTY_STRING) }),
  1852. new asn1js.Any({ name: (names.qualifier || EMPTY_STRING) })
  1853. ]
  1854. }));
  1855. }
  1856. fromSchema(schema) {
  1857. pvutils.clearProps(schema, CLEAR_PROPS$1p);
  1858. const asn1 = asn1js.compareSchema(schema, schema, PolicyQualifierInfo.schema({
  1859. names: {
  1860. policyQualifierId: POLICY_QUALIFIER_ID,
  1861. qualifier: QUALIFIER
  1862. }
  1863. }));
  1864. AsnError.assertSchema(asn1, this.className);
  1865. this.policyQualifierId = asn1.result.policyQualifierId.valueBlock.toString();
  1866. this.qualifier = asn1.result.qualifier;
  1867. }
  1868. toSchema() {
  1869. return (new asn1js.Sequence({
  1870. value: [
  1871. new asn1js.ObjectIdentifier({ value: this.policyQualifierId }),
  1872. this.qualifier
  1873. ]
  1874. }));
  1875. }
  1876. toJSON() {
  1877. return {
  1878. policyQualifierId: this.policyQualifierId,
  1879. qualifier: this.qualifier.toJSON()
  1880. };
  1881. }
  1882. }
  1883. PolicyQualifierInfo.CLASS_NAME = "PolicyQualifierInfo";
  1884. const POLICY_IDENTIFIER = "policyIdentifier";
  1885. const POLICY_QUALIFIERS = "policyQualifiers";
  1886. const CLEAR_PROPS$1o = [
  1887. POLICY_IDENTIFIER,
  1888. POLICY_QUALIFIERS
  1889. ];
  1890. class PolicyInformation extends PkiObject {
  1891. constructor(parameters = {}) {
  1892. super();
  1893. this.policyIdentifier = pvutils.getParametersValue(parameters, POLICY_IDENTIFIER, PolicyInformation.defaultValues(POLICY_IDENTIFIER));
  1894. if (POLICY_QUALIFIERS in parameters) {
  1895. this.policyQualifiers = pvutils.getParametersValue(parameters, POLICY_QUALIFIERS, PolicyInformation.defaultValues(POLICY_QUALIFIERS));
  1896. }
  1897. if (parameters.schema) {
  1898. this.fromSchema(parameters.schema);
  1899. }
  1900. }
  1901. static defaultValues(memberName) {
  1902. switch (memberName) {
  1903. case POLICY_IDENTIFIER:
  1904. return EMPTY_STRING;
  1905. case POLICY_QUALIFIERS:
  1906. return [];
  1907. default:
  1908. return super.defaultValues(memberName);
  1909. }
  1910. }
  1911. static schema(parameters = {}) {
  1912. const names = pvutils.getParametersValue(parameters, "names", {});
  1913. return (new asn1js.Sequence({
  1914. name: (names.blockName || EMPTY_STRING),
  1915. value: [
  1916. new asn1js.ObjectIdentifier({ name: (names.policyIdentifier || EMPTY_STRING) }),
  1917. new asn1js.Sequence({
  1918. optional: true,
  1919. value: [
  1920. new asn1js.Repeated({
  1921. name: (names.policyQualifiers || EMPTY_STRING),
  1922. value: PolicyQualifierInfo.schema()
  1923. })
  1924. ]
  1925. })
  1926. ]
  1927. }));
  1928. }
  1929. fromSchema(schema) {
  1930. pvutils.clearProps(schema, CLEAR_PROPS$1o);
  1931. const asn1 = asn1js.compareSchema(schema, schema, PolicyInformation.schema({
  1932. names: {
  1933. policyIdentifier: POLICY_IDENTIFIER,
  1934. policyQualifiers: POLICY_QUALIFIERS
  1935. }
  1936. }));
  1937. AsnError.assertSchema(asn1, this.className);
  1938. this.policyIdentifier = asn1.result.policyIdentifier.valueBlock.toString();
  1939. if (POLICY_QUALIFIERS in asn1.result) {
  1940. this.policyQualifiers = Array.from(asn1.result.policyQualifiers, element => new PolicyQualifierInfo({ schema: element }));
  1941. }
  1942. }
  1943. toSchema() {
  1944. const outputArray = [];
  1945. outputArray.push(new asn1js.ObjectIdentifier({ value: this.policyIdentifier }));
  1946. if (this.policyQualifiers) {
  1947. outputArray.push(new asn1js.Sequence({
  1948. value: Array.from(this.policyQualifiers, o => o.toSchema())
  1949. }));
  1950. }
  1951. return (new asn1js.Sequence({
  1952. value: outputArray
  1953. }));
  1954. }
  1955. toJSON() {
  1956. const res = {
  1957. policyIdentifier: this.policyIdentifier
  1958. };
  1959. if (this.policyQualifiers)
  1960. res.policyQualifiers = Array.from(this.policyQualifiers, o => o.toJSON());
  1961. return res;
  1962. }
  1963. }
  1964. PolicyInformation.CLASS_NAME = "PolicyInformation";
  1965. const CERTIFICATE_POLICIES = "certificatePolicies";
  1966. const CLEAR_PROPS$1n = [
  1967. CERTIFICATE_POLICIES,
  1968. ];
  1969. class CertificatePolicies extends PkiObject {
  1970. constructor(parameters = {}) {
  1971. super();
  1972. this.certificatePolicies = pvutils.getParametersValue(parameters, CERTIFICATE_POLICIES, CertificatePolicies.defaultValues(CERTIFICATE_POLICIES));
  1973. if (parameters.schema) {
  1974. this.fromSchema(parameters.schema);
  1975. }
  1976. }
  1977. static defaultValues(memberName) {
  1978. switch (memberName) {
  1979. case CERTIFICATE_POLICIES:
  1980. return [];
  1981. default:
  1982. return super.defaultValues(memberName);
  1983. }
  1984. }
  1985. static schema(parameters = {}) {
  1986. const names = pvutils.getParametersValue(parameters, "names", {});
  1987. return (new asn1js.Sequence({
  1988. name: (names.blockName || EMPTY_STRING),
  1989. value: [
  1990. new asn1js.Repeated({
  1991. name: (names.certificatePolicies || EMPTY_STRING),
  1992. value: PolicyInformation.schema()
  1993. })
  1994. ]
  1995. }));
  1996. }
  1997. fromSchema(schema) {
  1998. pvutils.clearProps(schema, CLEAR_PROPS$1n);
  1999. const asn1 = asn1js.compareSchema(schema, schema, CertificatePolicies.schema({
  2000. names: {
  2001. certificatePolicies: CERTIFICATE_POLICIES
  2002. }
  2003. }));
  2004. AsnError.assertSchema(asn1, this.className);
  2005. this.certificatePolicies = Array.from(asn1.result.certificatePolicies, element => new PolicyInformation({ schema: element }));
  2006. }
  2007. toSchema() {
  2008. return (new asn1js.Sequence({
  2009. value: Array.from(this.certificatePolicies, o => o.toSchema())
  2010. }));
  2011. }
  2012. toJSON() {
  2013. return {
  2014. certificatePolicies: Array.from(this.certificatePolicies, o => o.toJSON())
  2015. };
  2016. }
  2017. }
  2018. CertificatePolicies.CLASS_NAME = "CertificatePolicies";
  2019. const TEMPLATE_ID = "templateID";
  2020. const TEMPLATE_MAJOR_VERSION = "templateMajorVersion";
  2021. const TEMPLATE_MINOR_VERSION = "templateMinorVersion";
  2022. const CLEAR_PROPS$1m = [
  2023. TEMPLATE_ID,
  2024. TEMPLATE_MAJOR_VERSION,
  2025. TEMPLATE_MINOR_VERSION
  2026. ];
  2027. class CertificateTemplate extends PkiObject {
  2028. constructor(parameters = {}) {
  2029. super();
  2030. this.templateID = pvutils.getParametersValue(parameters, TEMPLATE_ID, CertificateTemplate.defaultValues(TEMPLATE_ID));
  2031. if (TEMPLATE_MAJOR_VERSION in parameters) {
  2032. this.templateMajorVersion = pvutils.getParametersValue(parameters, TEMPLATE_MAJOR_VERSION, CertificateTemplate.defaultValues(TEMPLATE_MAJOR_VERSION));
  2033. }
  2034. if (TEMPLATE_MINOR_VERSION in parameters) {
  2035. this.templateMinorVersion = pvutils.getParametersValue(parameters, TEMPLATE_MINOR_VERSION, CertificateTemplate.defaultValues(TEMPLATE_MINOR_VERSION));
  2036. }
  2037. if (parameters.schema) {
  2038. this.fromSchema(parameters.schema);
  2039. }
  2040. }
  2041. static defaultValues(memberName) {
  2042. switch (memberName) {
  2043. case TEMPLATE_ID:
  2044. return EMPTY_STRING;
  2045. case TEMPLATE_MAJOR_VERSION:
  2046. case TEMPLATE_MINOR_VERSION:
  2047. return 0;
  2048. default:
  2049. return super.defaultValues(memberName);
  2050. }
  2051. }
  2052. static schema(parameters = {}) {
  2053. const names = pvutils.getParametersValue(parameters, "names", {});
  2054. return (new asn1js.Sequence({
  2055. name: (names.blockName || EMPTY_STRING),
  2056. value: [
  2057. new asn1js.ObjectIdentifier({ name: (names.templateID || EMPTY_STRING) }),
  2058. new asn1js.Integer({
  2059. name: (names.templateMajorVersion || EMPTY_STRING),
  2060. optional: true
  2061. }),
  2062. new asn1js.Integer({
  2063. name: (names.templateMinorVersion || EMPTY_STRING),
  2064. optional: true
  2065. }),
  2066. ]
  2067. }));
  2068. }
  2069. fromSchema(schema) {
  2070. pvutils.clearProps(schema, CLEAR_PROPS$1m);
  2071. const asn1 = asn1js.compareSchema(schema, schema, CertificateTemplate.schema({
  2072. names: {
  2073. templateID: TEMPLATE_ID,
  2074. templateMajorVersion: TEMPLATE_MAJOR_VERSION,
  2075. templateMinorVersion: TEMPLATE_MINOR_VERSION
  2076. }
  2077. }));
  2078. AsnError.assertSchema(asn1, this.className);
  2079. this.templateID = asn1.result.templateID.valueBlock.toString();
  2080. if (TEMPLATE_MAJOR_VERSION in asn1.result) {
  2081. this.templateMajorVersion = asn1.result.templateMajorVersion.valueBlock.valueDec;
  2082. }
  2083. if (TEMPLATE_MINOR_VERSION in asn1.result) {
  2084. this.templateMinorVersion = asn1.result.templateMinorVersion.valueBlock.valueDec;
  2085. }
  2086. }
  2087. toSchema() {
  2088. const outputArray = [];
  2089. outputArray.push(new asn1js.ObjectIdentifier({ value: this.templateID }));
  2090. if (TEMPLATE_MAJOR_VERSION in this) {
  2091. outputArray.push(new asn1js.Integer({ value: this.templateMajorVersion }));
  2092. }
  2093. if (TEMPLATE_MINOR_VERSION in this) {
  2094. outputArray.push(new asn1js.Integer({ value: this.templateMinorVersion }));
  2095. }
  2096. return (new asn1js.Sequence({
  2097. value: outputArray
  2098. }));
  2099. }
  2100. toJSON() {
  2101. const res = {
  2102. templateID: this.templateID
  2103. };
  2104. if (TEMPLATE_MAJOR_VERSION in this)
  2105. res.templateMajorVersion = this.templateMajorVersion;
  2106. if (TEMPLATE_MINOR_VERSION in this)
  2107. res.templateMinorVersion = this.templateMinorVersion;
  2108. return res;
  2109. }
  2110. }
  2111. const DISTRIBUTION_POINT$1 = "distributionPoint";
  2112. const DISTRIBUTION_POINT_NAMES$1 = "distributionPointNames";
  2113. const REASONS = "reasons";
  2114. const CRL_ISSUER = "cRLIssuer";
  2115. const CRL_ISSUER_NAMES = "cRLIssuerNames";
  2116. const CLEAR_PROPS$1l = [
  2117. DISTRIBUTION_POINT$1,
  2118. DISTRIBUTION_POINT_NAMES$1,
  2119. REASONS,
  2120. CRL_ISSUER,
  2121. CRL_ISSUER_NAMES,
  2122. ];
  2123. class DistributionPoint extends PkiObject {
  2124. constructor(parameters = {}) {
  2125. super();
  2126. if (DISTRIBUTION_POINT$1 in parameters) {
  2127. this.distributionPoint = pvutils.getParametersValue(parameters, DISTRIBUTION_POINT$1, DistributionPoint.defaultValues(DISTRIBUTION_POINT$1));
  2128. }
  2129. if (REASONS in parameters) {
  2130. this.reasons = pvutils.getParametersValue(parameters, REASONS, DistributionPoint.defaultValues(REASONS));
  2131. }
  2132. if (CRL_ISSUER in parameters) {
  2133. this.cRLIssuer = pvutils.getParametersValue(parameters, CRL_ISSUER, DistributionPoint.defaultValues(CRL_ISSUER));
  2134. }
  2135. if (parameters.schema) {
  2136. this.fromSchema(parameters.schema);
  2137. }
  2138. }
  2139. static defaultValues(memberName) {
  2140. switch (memberName) {
  2141. case DISTRIBUTION_POINT$1:
  2142. return [];
  2143. case REASONS:
  2144. return new asn1js.BitString();
  2145. case CRL_ISSUER:
  2146. return [];
  2147. default:
  2148. return super.defaultValues(memberName);
  2149. }
  2150. }
  2151. static schema(parameters = {}) {
  2152. const names = pvutils.getParametersValue(parameters, "names", {});
  2153. return (new asn1js.Sequence({
  2154. name: (names.blockName || EMPTY_STRING),
  2155. value: [
  2156. new asn1js.Constructed({
  2157. optional: true,
  2158. idBlock: {
  2159. tagClass: 3,
  2160. tagNumber: 0
  2161. },
  2162. value: [
  2163. new asn1js.Choice({
  2164. value: [
  2165. new asn1js.Constructed({
  2166. name: (names.distributionPoint || EMPTY_STRING),
  2167. optional: true,
  2168. idBlock: {
  2169. tagClass: 3,
  2170. tagNumber: 0
  2171. },
  2172. value: [
  2173. new asn1js.Repeated({
  2174. name: (names.distributionPointNames || EMPTY_STRING),
  2175. value: GeneralName.schema()
  2176. })
  2177. ]
  2178. }),
  2179. new asn1js.Constructed({
  2180. name: (names.distributionPoint || EMPTY_STRING),
  2181. optional: true,
  2182. idBlock: {
  2183. tagClass: 3,
  2184. tagNumber: 1
  2185. },
  2186. value: RelativeDistinguishedNames.schema().valueBlock.value
  2187. })
  2188. ]
  2189. })
  2190. ]
  2191. }),
  2192. new asn1js.Primitive({
  2193. name: (names.reasons || EMPTY_STRING),
  2194. optional: true,
  2195. idBlock: {
  2196. tagClass: 3,
  2197. tagNumber: 1
  2198. }
  2199. }),
  2200. new asn1js.Constructed({
  2201. name: (names.cRLIssuer || EMPTY_STRING),
  2202. optional: true,
  2203. idBlock: {
  2204. tagClass: 3,
  2205. tagNumber: 2
  2206. },
  2207. value: [
  2208. new asn1js.Repeated({
  2209. name: (names.cRLIssuerNames || EMPTY_STRING),
  2210. value: GeneralName.schema()
  2211. })
  2212. ]
  2213. })
  2214. ]
  2215. }));
  2216. }
  2217. fromSchema(schema) {
  2218. pvutils.clearProps(schema, CLEAR_PROPS$1l);
  2219. const asn1 = asn1js.compareSchema(schema, schema, DistributionPoint.schema({
  2220. names: {
  2221. distributionPoint: DISTRIBUTION_POINT$1,
  2222. distributionPointNames: DISTRIBUTION_POINT_NAMES$1,
  2223. reasons: REASONS,
  2224. cRLIssuer: CRL_ISSUER,
  2225. cRLIssuerNames: CRL_ISSUER_NAMES
  2226. }
  2227. }));
  2228. AsnError.assertSchema(asn1, this.className);
  2229. if (DISTRIBUTION_POINT$1 in asn1.result) {
  2230. if (asn1.result.distributionPoint.idBlock.tagNumber === 0) {
  2231. this.distributionPoint = Array.from(asn1.result.distributionPointNames, element => new GeneralName({ schema: element }));
  2232. }
  2233. if (asn1.result.distributionPoint.idBlock.tagNumber === 1) {
  2234. this.distributionPoint = new RelativeDistinguishedNames({
  2235. schema: new asn1js.Sequence({
  2236. value: asn1.result.distributionPoint.valueBlock.value
  2237. })
  2238. });
  2239. }
  2240. }
  2241. if (REASONS in asn1.result) {
  2242. this.reasons = new asn1js.BitString({ valueHex: asn1.result.reasons.valueBlock.valueHex });
  2243. }
  2244. if (CRL_ISSUER in asn1.result) {
  2245. this.cRLIssuer = Array.from(asn1.result.cRLIssuerNames, element => new GeneralName({ schema: element }));
  2246. }
  2247. }
  2248. toSchema() {
  2249. const outputArray = [];
  2250. if (this.distributionPoint) {
  2251. let internalValue;
  2252. if (this.distributionPoint instanceof Array) {
  2253. internalValue = new asn1js.Constructed({
  2254. idBlock: {
  2255. tagClass: 3,
  2256. tagNumber: 0
  2257. },
  2258. value: Array.from(this.distributionPoint, o => o.toSchema())
  2259. });
  2260. }
  2261. else {
  2262. internalValue = new asn1js.Constructed({
  2263. idBlock: {
  2264. tagClass: 3,
  2265. tagNumber: 1
  2266. },
  2267. value: [this.distributionPoint.toSchema()]
  2268. });
  2269. }
  2270. outputArray.push(new asn1js.Constructed({
  2271. idBlock: {
  2272. tagClass: 3,
  2273. tagNumber: 0
  2274. },
  2275. value: [internalValue]
  2276. }));
  2277. }
  2278. if (this.reasons) {
  2279. outputArray.push(new asn1js.Primitive({
  2280. idBlock: {
  2281. tagClass: 3,
  2282. tagNumber: 1
  2283. },
  2284. valueHex: this.reasons.valueBlock.valueHexView
  2285. }));
  2286. }
  2287. if (this.cRLIssuer) {
  2288. outputArray.push(new asn1js.Constructed({
  2289. idBlock: {
  2290. tagClass: 3,
  2291. tagNumber: 2
  2292. },
  2293. value: Array.from(this.cRLIssuer, o => o.toSchema())
  2294. }));
  2295. }
  2296. return (new asn1js.Sequence({
  2297. value: outputArray
  2298. }));
  2299. }
  2300. toJSON() {
  2301. const object = {};
  2302. if (this.distributionPoint) {
  2303. if (this.distributionPoint instanceof Array) {
  2304. object.distributionPoint = Array.from(this.distributionPoint, o => o.toJSON());
  2305. }
  2306. else {
  2307. object.distributionPoint = this.distributionPoint.toJSON();
  2308. }
  2309. }
  2310. if (this.reasons) {
  2311. object.reasons = this.reasons.toJSON();
  2312. }
  2313. if (this.cRLIssuer) {
  2314. object.cRLIssuer = Array.from(this.cRLIssuer, o => o.toJSON());
  2315. }
  2316. return object;
  2317. }
  2318. }
  2319. DistributionPoint.CLASS_NAME = "DistributionPoint";
  2320. const DISTRIBUTION_POINTS = "distributionPoints";
  2321. const CLEAR_PROPS$1k = [
  2322. DISTRIBUTION_POINTS
  2323. ];
  2324. class CRLDistributionPoints extends PkiObject {
  2325. constructor(parameters = {}) {
  2326. super();
  2327. this.distributionPoints = pvutils.getParametersValue(parameters, DISTRIBUTION_POINTS, CRLDistributionPoints.defaultValues(DISTRIBUTION_POINTS));
  2328. if (parameters.schema) {
  2329. this.fromSchema(parameters.schema);
  2330. }
  2331. }
  2332. static defaultValues(memberName) {
  2333. switch (memberName) {
  2334. case DISTRIBUTION_POINTS:
  2335. return [];
  2336. default:
  2337. return super.defaultValues(memberName);
  2338. }
  2339. }
  2340. static schema(parameters = {}) {
  2341. const names = pvutils.getParametersValue(parameters, "names", {});
  2342. return (new asn1js.Sequence({
  2343. name: (names.blockName || EMPTY_STRING),
  2344. value: [
  2345. new asn1js.Repeated({
  2346. name: (names.distributionPoints || EMPTY_STRING),
  2347. value: DistributionPoint.schema()
  2348. })
  2349. ]
  2350. }));
  2351. }
  2352. fromSchema(schema) {
  2353. pvutils.clearProps(schema, CLEAR_PROPS$1k);
  2354. const asn1 = asn1js.compareSchema(schema, schema, CRLDistributionPoints.schema({
  2355. names: {
  2356. distributionPoints: DISTRIBUTION_POINTS
  2357. }
  2358. }));
  2359. AsnError.assertSchema(asn1, this.className);
  2360. this.distributionPoints = Array.from(asn1.result.distributionPoints, element => new DistributionPoint({ schema: element }));
  2361. }
  2362. toSchema() {
  2363. return (new asn1js.Sequence({
  2364. value: Array.from(this.distributionPoints, o => o.toSchema())
  2365. }));
  2366. }
  2367. toJSON() {
  2368. return {
  2369. distributionPoints: Array.from(this.distributionPoints, o => o.toJSON())
  2370. };
  2371. }
  2372. }
  2373. CRLDistributionPoints.CLASS_NAME = "CRLDistributionPoints";
  2374. const KEY_PURPOSES = "keyPurposes";
  2375. const CLEAR_PROPS$1j = [
  2376. KEY_PURPOSES,
  2377. ];
  2378. class ExtKeyUsage extends PkiObject {
  2379. constructor(parameters = {}) {
  2380. super();
  2381. this.keyPurposes = pvutils.getParametersValue(parameters, KEY_PURPOSES, ExtKeyUsage.defaultValues(KEY_PURPOSES));
  2382. if (parameters.schema) {
  2383. this.fromSchema(parameters.schema);
  2384. }
  2385. }
  2386. static defaultValues(memberName) {
  2387. switch (memberName) {
  2388. case KEY_PURPOSES:
  2389. return [];
  2390. default:
  2391. return super.defaultValues(memberName);
  2392. }
  2393. }
  2394. static schema(parameters = {}) {
  2395. const names = pvutils.getParametersValue(parameters, "names", {});
  2396. return (new asn1js.Sequence({
  2397. name: (names.blockName || EMPTY_STRING),
  2398. value: [
  2399. new asn1js.Repeated({
  2400. name: (names.keyPurposes || EMPTY_STRING),
  2401. value: new asn1js.ObjectIdentifier()
  2402. })
  2403. ]
  2404. }));
  2405. }
  2406. fromSchema(schema) {
  2407. pvutils.clearProps(schema, CLEAR_PROPS$1j);
  2408. const asn1 = asn1js.compareSchema(schema, schema, ExtKeyUsage.schema({
  2409. names: {
  2410. keyPurposes: KEY_PURPOSES
  2411. }
  2412. }));
  2413. AsnError.assertSchema(asn1, this.className);
  2414. this.keyPurposes = Array.from(asn1.result.keyPurposes, (element) => element.valueBlock.toString());
  2415. }
  2416. toSchema() {
  2417. return (new asn1js.Sequence({
  2418. value: Array.from(this.keyPurposes, element => new asn1js.ObjectIdentifier({ value: element }))
  2419. }));
  2420. }
  2421. toJSON() {
  2422. return {
  2423. keyPurposes: Array.from(this.keyPurposes)
  2424. };
  2425. }
  2426. }
  2427. ExtKeyUsage.CLASS_NAME = "ExtKeyUsage";
  2428. const ACCESS_DESCRIPTIONS = "accessDescriptions";
  2429. class InfoAccess extends PkiObject {
  2430. constructor(parameters = {}) {
  2431. super();
  2432. this.accessDescriptions = pvutils.getParametersValue(parameters, ACCESS_DESCRIPTIONS, InfoAccess.defaultValues(ACCESS_DESCRIPTIONS));
  2433. if (parameters.schema) {
  2434. this.fromSchema(parameters.schema);
  2435. }
  2436. }
  2437. static defaultValues(memberName) {
  2438. switch (memberName) {
  2439. case ACCESS_DESCRIPTIONS:
  2440. return [];
  2441. default:
  2442. return super.defaultValues(memberName);
  2443. }
  2444. }
  2445. static schema(parameters = {}) {
  2446. const names = pvutils.getParametersValue(parameters, "names", {});
  2447. return (new asn1js.Sequence({
  2448. name: (names.blockName || EMPTY_STRING),
  2449. value: [
  2450. new asn1js.Repeated({
  2451. name: (names.accessDescriptions || EMPTY_STRING),
  2452. value: AccessDescription.schema()
  2453. })
  2454. ]
  2455. }));
  2456. }
  2457. fromSchema(schema) {
  2458. pvutils.clearProps(schema, [
  2459. ACCESS_DESCRIPTIONS
  2460. ]);
  2461. const asn1 = asn1js.compareSchema(schema, schema, InfoAccess.schema({
  2462. names: {
  2463. accessDescriptions: ACCESS_DESCRIPTIONS
  2464. }
  2465. }));
  2466. AsnError.assertSchema(asn1, this.className);
  2467. this.accessDescriptions = Array.from(asn1.result.accessDescriptions, element => new AccessDescription({ schema: element }));
  2468. }
  2469. toSchema() {
  2470. return (new asn1js.Sequence({
  2471. value: Array.from(this.accessDescriptions, o => o.toSchema())
  2472. }));
  2473. }
  2474. toJSON() {
  2475. return {
  2476. accessDescriptions: Array.from(this.accessDescriptions, o => o.toJSON())
  2477. };
  2478. }
  2479. }
  2480. InfoAccess.CLASS_NAME = "InfoAccess";
  2481. const DISTRIBUTION_POINT = "distributionPoint";
  2482. const DISTRIBUTION_POINT_NAMES = "distributionPointNames";
  2483. const ONLY_CONTAINS_USER_CERTS = "onlyContainsUserCerts";
  2484. const ONLY_CONTAINS_CA_CERTS = "onlyContainsCACerts";
  2485. const ONLY_SOME_REASON = "onlySomeReasons";
  2486. const INDIRECT_CRL = "indirectCRL";
  2487. const ONLY_CONTAINS_ATTRIBUTE_CERTS = "onlyContainsAttributeCerts";
  2488. const CLEAR_PROPS$1i = [
  2489. DISTRIBUTION_POINT,
  2490. DISTRIBUTION_POINT_NAMES,
  2491. ONLY_CONTAINS_USER_CERTS,
  2492. ONLY_CONTAINS_CA_CERTS,
  2493. ONLY_SOME_REASON,
  2494. INDIRECT_CRL,
  2495. ONLY_CONTAINS_ATTRIBUTE_CERTS,
  2496. ];
  2497. class IssuingDistributionPoint extends PkiObject {
  2498. constructor(parameters = {}) {
  2499. super();
  2500. if (DISTRIBUTION_POINT in parameters) {
  2501. this.distributionPoint = pvutils.getParametersValue(parameters, DISTRIBUTION_POINT, IssuingDistributionPoint.defaultValues(DISTRIBUTION_POINT));
  2502. }
  2503. this.onlyContainsUserCerts = pvutils.getParametersValue(parameters, ONLY_CONTAINS_USER_CERTS, IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_USER_CERTS));
  2504. this.onlyContainsCACerts = pvutils.getParametersValue(parameters, ONLY_CONTAINS_CA_CERTS, IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_CA_CERTS));
  2505. if (ONLY_SOME_REASON in parameters) {
  2506. this.onlySomeReasons = pvutils.getParametersValue(parameters, ONLY_SOME_REASON, IssuingDistributionPoint.defaultValues(ONLY_SOME_REASON));
  2507. }
  2508. this.indirectCRL = pvutils.getParametersValue(parameters, INDIRECT_CRL, IssuingDistributionPoint.defaultValues(INDIRECT_CRL));
  2509. this.onlyContainsAttributeCerts = pvutils.getParametersValue(parameters, ONLY_CONTAINS_ATTRIBUTE_CERTS, IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_ATTRIBUTE_CERTS));
  2510. if (parameters.schema) {
  2511. this.fromSchema(parameters.schema);
  2512. }
  2513. }
  2514. static defaultValues(memberName) {
  2515. switch (memberName) {
  2516. case DISTRIBUTION_POINT:
  2517. return [];
  2518. case ONLY_CONTAINS_USER_CERTS:
  2519. return false;
  2520. case ONLY_CONTAINS_CA_CERTS:
  2521. return false;
  2522. case ONLY_SOME_REASON:
  2523. return 0;
  2524. case INDIRECT_CRL:
  2525. return false;
  2526. case ONLY_CONTAINS_ATTRIBUTE_CERTS:
  2527. return false;
  2528. default:
  2529. return super.defaultValues(memberName);
  2530. }
  2531. }
  2532. static schema(parameters = {}) {
  2533. const names = pvutils.getParametersValue(parameters, "names", {});
  2534. return (new asn1js.Sequence({
  2535. name: (names.blockName || EMPTY_STRING),
  2536. value: [
  2537. new asn1js.Constructed({
  2538. optional: true,
  2539. idBlock: {
  2540. tagClass: 3,
  2541. tagNumber: 0
  2542. },
  2543. value: [
  2544. new asn1js.Choice({
  2545. value: [
  2546. new asn1js.Constructed({
  2547. name: (names.distributionPoint || EMPTY_STRING),
  2548. idBlock: {
  2549. tagClass: 3,
  2550. tagNumber: 0
  2551. },
  2552. value: [
  2553. new asn1js.Repeated({
  2554. name: (names.distributionPointNames || EMPTY_STRING),
  2555. value: GeneralName.schema()
  2556. })
  2557. ]
  2558. }),
  2559. new asn1js.Constructed({
  2560. name: (names.distributionPoint || EMPTY_STRING),
  2561. idBlock: {
  2562. tagClass: 3,
  2563. tagNumber: 1
  2564. },
  2565. value: RelativeDistinguishedNames.schema().valueBlock.value
  2566. })
  2567. ]
  2568. })
  2569. ]
  2570. }),
  2571. new asn1js.Primitive({
  2572. name: (names.onlyContainsUserCerts || EMPTY_STRING),
  2573. optional: true,
  2574. idBlock: {
  2575. tagClass: 3,
  2576. tagNumber: 1
  2577. }
  2578. }),
  2579. new asn1js.Primitive({
  2580. name: (names.onlyContainsCACerts || EMPTY_STRING),
  2581. optional: true,
  2582. idBlock: {
  2583. tagClass: 3,
  2584. tagNumber: 2
  2585. }
  2586. }),
  2587. new asn1js.Primitive({
  2588. name: (names.onlySomeReasons || EMPTY_STRING),
  2589. optional: true,
  2590. idBlock: {
  2591. tagClass: 3,
  2592. tagNumber: 3
  2593. }
  2594. }),
  2595. new asn1js.Primitive({
  2596. name: (names.indirectCRL || EMPTY_STRING),
  2597. optional: true,
  2598. idBlock: {
  2599. tagClass: 3,
  2600. tagNumber: 4
  2601. }
  2602. }),
  2603. new asn1js.Primitive({
  2604. name: (names.onlyContainsAttributeCerts || EMPTY_STRING),
  2605. optional: true,
  2606. idBlock: {
  2607. tagClass: 3,
  2608. tagNumber: 5
  2609. }
  2610. })
  2611. ]
  2612. }));
  2613. }
  2614. fromSchema(schema) {
  2615. pvutils.clearProps(schema, CLEAR_PROPS$1i);
  2616. const asn1 = asn1js.compareSchema(schema, schema, IssuingDistributionPoint.schema({
  2617. names: {
  2618. distributionPoint: DISTRIBUTION_POINT,
  2619. distributionPointNames: DISTRIBUTION_POINT_NAMES,
  2620. onlyContainsUserCerts: ONLY_CONTAINS_USER_CERTS,
  2621. onlyContainsCACerts: ONLY_CONTAINS_CA_CERTS,
  2622. onlySomeReasons: ONLY_SOME_REASON,
  2623. indirectCRL: INDIRECT_CRL,
  2624. onlyContainsAttributeCerts: ONLY_CONTAINS_ATTRIBUTE_CERTS
  2625. }
  2626. }));
  2627. AsnError.assertSchema(asn1, this.className);
  2628. if (DISTRIBUTION_POINT in asn1.result) {
  2629. switch (true) {
  2630. case (asn1.result.distributionPoint.idBlock.tagNumber === 0):
  2631. this.distributionPoint = Array.from(asn1.result.distributionPointNames, element => new GeneralName({ schema: element }));
  2632. break;
  2633. case (asn1.result.distributionPoint.idBlock.tagNumber === 1):
  2634. {
  2635. this.distributionPoint = new RelativeDistinguishedNames({
  2636. schema: new asn1js.Sequence({
  2637. value: asn1.result.distributionPoint.valueBlock.value
  2638. })
  2639. });
  2640. }
  2641. break;
  2642. default:
  2643. throw new Error("Unknown tagNumber for distributionPoint: {$asn1.result.distributionPoint.idBlock.tagNumber}");
  2644. }
  2645. }
  2646. if (ONLY_CONTAINS_USER_CERTS in asn1.result) {
  2647. const view = new Uint8Array(asn1.result.onlyContainsUserCerts.valueBlock.valueHex);
  2648. this.onlyContainsUserCerts = (view[0] !== 0x00);
  2649. }
  2650. if (ONLY_CONTAINS_CA_CERTS in asn1.result) {
  2651. const view = new Uint8Array(asn1.result.onlyContainsCACerts.valueBlock.valueHex);
  2652. this.onlyContainsCACerts = (view[0] !== 0x00);
  2653. }
  2654. if (ONLY_SOME_REASON in asn1.result) {
  2655. const view = new Uint8Array(asn1.result.onlySomeReasons.valueBlock.valueHex);
  2656. this.onlySomeReasons = view[0];
  2657. }
  2658. if (INDIRECT_CRL in asn1.result) {
  2659. const view = new Uint8Array(asn1.result.indirectCRL.valueBlock.valueHex);
  2660. this.indirectCRL = (view[0] !== 0x00);
  2661. }
  2662. if (ONLY_CONTAINS_ATTRIBUTE_CERTS in asn1.result) {
  2663. const view = new Uint8Array(asn1.result.onlyContainsAttributeCerts.valueBlock.valueHex);
  2664. this.onlyContainsAttributeCerts = (view[0] !== 0x00);
  2665. }
  2666. }
  2667. toSchema() {
  2668. const outputArray = [];
  2669. if (this.distributionPoint) {
  2670. let value;
  2671. if (this.distributionPoint instanceof Array) {
  2672. value = new asn1js.Constructed({
  2673. idBlock: {
  2674. tagClass: 3,
  2675. tagNumber: 0
  2676. },
  2677. value: Array.from(this.distributionPoint, o => o.toSchema())
  2678. });
  2679. }
  2680. else {
  2681. value = this.distributionPoint.toSchema();
  2682. value.idBlock.tagClass = 3;
  2683. value.idBlock.tagNumber = 1;
  2684. }
  2685. outputArray.push(new asn1js.Constructed({
  2686. idBlock: {
  2687. tagClass: 3,
  2688. tagNumber: 0
  2689. },
  2690. value: [value]
  2691. }));
  2692. }
  2693. if (this.onlyContainsUserCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_USER_CERTS)) {
  2694. outputArray.push(new asn1js.Primitive({
  2695. idBlock: {
  2696. tagClass: 3,
  2697. tagNumber: 1
  2698. },
  2699. valueHex: (new Uint8Array([0xFF])).buffer
  2700. }));
  2701. }
  2702. if (this.onlyContainsCACerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_CA_CERTS)) {
  2703. outputArray.push(new asn1js.Primitive({
  2704. idBlock: {
  2705. tagClass: 3,
  2706. tagNumber: 2
  2707. },
  2708. valueHex: (new Uint8Array([0xFF])).buffer
  2709. }));
  2710. }
  2711. if (this.onlySomeReasons !== undefined) {
  2712. const buffer = new ArrayBuffer(1);
  2713. const view = new Uint8Array(buffer);
  2714. view[0] = this.onlySomeReasons;
  2715. outputArray.push(new asn1js.Primitive({
  2716. idBlock: {
  2717. tagClass: 3,
  2718. tagNumber: 3
  2719. },
  2720. valueHex: buffer
  2721. }));
  2722. }
  2723. if (this.indirectCRL !== IssuingDistributionPoint.defaultValues(INDIRECT_CRL)) {
  2724. outputArray.push(new asn1js.Primitive({
  2725. idBlock: {
  2726. tagClass: 3,
  2727. tagNumber: 4
  2728. },
  2729. valueHex: (new Uint8Array([0xFF])).buffer
  2730. }));
  2731. }
  2732. if (this.onlyContainsAttributeCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_ATTRIBUTE_CERTS)) {
  2733. outputArray.push(new asn1js.Primitive({
  2734. idBlock: {
  2735. tagClass: 3,
  2736. tagNumber: 5
  2737. },
  2738. valueHex: (new Uint8Array([0xFF])).buffer
  2739. }));
  2740. }
  2741. return (new asn1js.Sequence({
  2742. value: outputArray
  2743. }));
  2744. }
  2745. toJSON() {
  2746. const obj = {};
  2747. if (this.distributionPoint) {
  2748. if (this.distributionPoint instanceof Array) {
  2749. obj.distributionPoint = Array.from(this.distributionPoint, o => o.toJSON());
  2750. }
  2751. else {
  2752. obj.distributionPoint = this.distributionPoint.toJSON();
  2753. }
  2754. }
  2755. if (this.onlyContainsUserCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_USER_CERTS)) {
  2756. obj.onlyContainsUserCerts = this.onlyContainsUserCerts;
  2757. }
  2758. if (this.onlyContainsCACerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_CA_CERTS)) {
  2759. obj.onlyContainsCACerts = this.onlyContainsCACerts;
  2760. }
  2761. if (ONLY_SOME_REASON in this) {
  2762. obj.onlySomeReasons = this.onlySomeReasons;
  2763. }
  2764. if (this.indirectCRL !== IssuingDistributionPoint.defaultValues(INDIRECT_CRL)) {
  2765. obj.indirectCRL = this.indirectCRL;
  2766. }
  2767. if (this.onlyContainsAttributeCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_ATTRIBUTE_CERTS)) {
  2768. obj.onlyContainsAttributeCerts = this.onlyContainsAttributeCerts;
  2769. }
  2770. return obj;
  2771. }
  2772. }
  2773. IssuingDistributionPoint.CLASS_NAME = "IssuingDistributionPoint";
  2774. const BASE = "base";
  2775. const MINIMUM = "minimum";
  2776. const MAXIMUM = "maximum";
  2777. const CLEAR_PROPS$1h = [
  2778. BASE,
  2779. MINIMUM,
  2780. MAXIMUM
  2781. ];
  2782. class GeneralSubtree extends PkiObject {
  2783. constructor(parameters = {}) {
  2784. super();
  2785. this.base = pvutils.getParametersValue(parameters, BASE, GeneralSubtree.defaultValues(BASE));
  2786. this.minimum = pvutils.getParametersValue(parameters, MINIMUM, GeneralSubtree.defaultValues(MINIMUM));
  2787. if (MAXIMUM in parameters) {
  2788. this.maximum = pvutils.getParametersValue(parameters, MAXIMUM, GeneralSubtree.defaultValues(MAXIMUM));
  2789. }
  2790. if (parameters.schema) {
  2791. this.fromSchema(parameters.schema);
  2792. }
  2793. }
  2794. static defaultValues(memberName) {
  2795. switch (memberName) {
  2796. case BASE:
  2797. return new GeneralName();
  2798. case MINIMUM:
  2799. return 0;
  2800. case MAXIMUM:
  2801. return 0;
  2802. default:
  2803. return super.defaultValues(memberName);
  2804. }
  2805. }
  2806. static schema(parameters = {}) {
  2807. const names = pvutils.getParametersValue(parameters, "names", {});
  2808. return (new asn1js.Sequence({
  2809. name: (names.blockName || EMPTY_STRING),
  2810. value: [
  2811. GeneralName.schema(names.base || {}),
  2812. new asn1js.Constructed({
  2813. optional: true,
  2814. idBlock: {
  2815. tagClass: 3,
  2816. tagNumber: 0
  2817. },
  2818. value: [new asn1js.Integer({ name: (names.minimum || EMPTY_STRING) })]
  2819. }),
  2820. new asn1js.Constructed({
  2821. optional: true,
  2822. idBlock: {
  2823. tagClass: 3,
  2824. tagNumber: 1
  2825. },
  2826. value: [new asn1js.Integer({ name: (names.maximum || EMPTY_STRING) })]
  2827. })
  2828. ]
  2829. }));
  2830. }
  2831. fromSchema(schema) {
  2832. pvutils.clearProps(schema, CLEAR_PROPS$1h);
  2833. const asn1 = asn1js.compareSchema(schema, schema, GeneralSubtree.schema({
  2834. names: {
  2835. base: {
  2836. names: {
  2837. blockName: BASE
  2838. }
  2839. },
  2840. minimum: MINIMUM,
  2841. maximum: MAXIMUM
  2842. }
  2843. }));
  2844. AsnError.assertSchema(asn1, this.className);
  2845. this.base = new GeneralName({ schema: asn1.result.base });
  2846. if (MINIMUM in asn1.result) {
  2847. if (asn1.result.minimum.valueBlock.isHexOnly)
  2848. this.minimum = asn1.result.minimum;
  2849. else
  2850. this.minimum = asn1.result.minimum.valueBlock.valueDec;
  2851. }
  2852. if (MAXIMUM in asn1.result) {
  2853. if (asn1.result.maximum.valueBlock.isHexOnly)
  2854. this.maximum = asn1.result.maximum;
  2855. else
  2856. this.maximum = asn1.result.maximum.valueBlock.valueDec;
  2857. }
  2858. }
  2859. toSchema() {
  2860. const outputArray = [];
  2861. outputArray.push(this.base.toSchema());
  2862. if (this.minimum !== 0) {
  2863. let valueMinimum = 0;
  2864. if (this.minimum instanceof asn1js.Integer) {
  2865. valueMinimum = this.minimum;
  2866. }
  2867. else {
  2868. valueMinimum = new asn1js.Integer({ value: this.minimum });
  2869. }
  2870. outputArray.push(new asn1js.Constructed({
  2871. optional: true,
  2872. idBlock: {
  2873. tagClass: 3,
  2874. tagNumber: 0
  2875. },
  2876. value: [valueMinimum]
  2877. }));
  2878. }
  2879. if (MAXIMUM in this) {
  2880. let valueMaximum = 0;
  2881. if (this.maximum instanceof asn1js.Integer) {
  2882. valueMaximum = this.maximum;
  2883. }
  2884. else {
  2885. valueMaximum = new asn1js.Integer({ value: this.maximum });
  2886. }
  2887. outputArray.push(new asn1js.Constructed({
  2888. optional: true,
  2889. idBlock: {
  2890. tagClass: 3,
  2891. tagNumber: 1
  2892. },
  2893. value: [valueMaximum]
  2894. }));
  2895. }
  2896. return (new asn1js.Sequence({
  2897. value: outputArray
  2898. }));
  2899. }
  2900. toJSON() {
  2901. const res = {
  2902. base: this.base.toJSON()
  2903. };
  2904. if (this.minimum !== 0) {
  2905. if (typeof this.minimum === "number") {
  2906. res.minimum = this.minimum;
  2907. }
  2908. else {
  2909. res.minimum = this.minimum.toJSON();
  2910. }
  2911. }
  2912. if (this.maximum !== undefined) {
  2913. if (typeof this.maximum === "number") {
  2914. res.maximum = this.maximum;
  2915. }
  2916. else {
  2917. res.maximum = this.maximum.toJSON();
  2918. }
  2919. }
  2920. return res;
  2921. }
  2922. }
  2923. GeneralSubtree.CLASS_NAME = "GeneralSubtree";
  2924. const PERMITTED_SUBTREES = "permittedSubtrees";
  2925. const EXCLUDED_SUBTREES = "excludedSubtrees";
  2926. const CLEAR_PROPS$1g = [
  2927. PERMITTED_SUBTREES,
  2928. EXCLUDED_SUBTREES
  2929. ];
  2930. class NameConstraints extends PkiObject {
  2931. constructor(parameters = {}) {
  2932. super();
  2933. if (PERMITTED_SUBTREES in parameters) {
  2934. this.permittedSubtrees = pvutils.getParametersValue(parameters, PERMITTED_SUBTREES, NameConstraints.defaultValues(PERMITTED_SUBTREES));
  2935. }
  2936. if (EXCLUDED_SUBTREES in parameters) {
  2937. this.excludedSubtrees = pvutils.getParametersValue(parameters, EXCLUDED_SUBTREES, NameConstraints.defaultValues(EXCLUDED_SUBTREES));
  2938. }
  2939. if (parameters.schema) {
  2940. this.fromSchema(parameters.schema);
  2941. }
  2942. }
  2943. static defaultValues(memberName) {
  2944. switch (memberName) {
  2945. case PERMITTED_SUBTREES:
  2946. case EXCLUDED_SUBTREES:
  2947. return [];
  2948. default:
  2949. return super.defaultValues(memberName);
  2950. }
  2951. }
  2952. static schema(parameters = {}) {
  2953. const names = pvutils.getParametersValue(parameters, "names", {});
  2954. return (new asn1js.Sequence({
  2955. name: (names.blockName || EMPTY_STRING),
  2956. value: [
  2957. new asn1js.Constructed({
  2958. optional: true,
  2959. idBlock: {
  2960. tagClass: 3,
  2961. tagNumber: 0
  2962. },
  2963. value: [
  2964. new asn1js.Repeated({
  2965. name: (names.permittedSubtrees || EMPTY_STRING),
  2966. value: GeneralSubtree.schema()
  2967. })
  2968. ]
  2969. }),
  2970. new asn1js.Constructed({
  2971. optional: true,
  2972. idBlock: {
  2973. tagClass: 3,
  2974. tagNumber: 1
  2975. },
  2976. value: [
  2977. new asn1js.Repeated({
  2978. name: (names.excludedSubtrees || EMPTY_STRING),
  2979. value: GeneralSubtree.schema()
  2980. })
  2981. ]
  2982. })
  2983. ]
  2984. }));
  2985. }
  2986. fromSchema(schema) {
  2987. pvutils.clearProps(schema, CLEAR_PROPS$1g);
  2988. const asn1 = asn1js.compareSchema(schema, schema, NameConstraints.schema({
  2989. names: {
  2990. permittedSubtrees: PERMITTED_SUBTREES,
  2991. excludedSubtrees: EXCLUDED_SUBTREES
  2992. }
  2993. }));
  2994. AsnError.assertSchema(asn1, this.className);
  2995. if (PERMITTED_SUBTREES in asn1.result)
  2996. this.permittedSubtrees = Array.from(asn1.result.permittedSubtrees, element => new GeneralSubtree({ schema: element }));
  2997. if (EXCLUDED_SUBTREES in asn1.result)
  2998. this.excludedSubtrees = Array.from(asn1.result.excludedSubtrees, element => new GeneralSubtree({ schema: element }));
  2999. }
  3000. toSchema() {
  3001. const outputArray = [];
  3002. if (this.permittedSubtrees) {
  3003. outputArray.push(new asn1js.Constructed({
  3004. idBlock: {
  3005. tagClass: 3,
  3006. tagNumber: 0
  3007. },
  3008. value: Array.from(this.permittedSubtrees, o => o.toSchema())
  3009. }));
  3010. }
  3011. if (this.excludedSubtrees) {
  3012. outputArray.push(new asn1js.Constructed({
  3013. idBlock: {
  3014. tagClass: 3,
  3015. tagNumber: 1
  3016. },
  3017. value: Array.from(this.excludedSubtrees, o => o.toSchema())
  3018. }));
  3019. }
  3020. return (new asn1js.Sequence({
  3021. value: outputArray
  3022. }));
  3023. }
  3024. toJSON() {
  3025. const object = {};
  3026. if (this.permittedSubtrees) {
  3027. object.permittedSubtrees = Array.from(this.permittedSubtrees, o => o.toJSON());
  3028. }
  3029. if (this.excludedSubtrees) {
  3030. object.excludedSubtrees = Array.from(this.excludedSubtrees, o => o.toJSON());
  3031. }
  3032. return object;
  3033. }
  3034. }
  3035. NameConstraints.CLASS_NAME = "NameConstraints";
  3036. const REQUIRE_EXPLICIT_POLICY = "requireExplicitPolicy";
  3037. const INHIBIT_POLICY_MAPPING = "inhibitPolicyMapping";
  3038. const CLEAR_PROPS$1f = [
  3039. REQUIRE_EXPLICIT_POLICY,
  3040. INHIBIT_POLICY_MAPPING,
  3041. ];
  3042. class PolicyConstraints extends PkiObject {
  3043. constructor(parameters = {}) {
  3044. super();
  3045. if (REQUIRE_EXPLICIT_POLICY in parameters) {
  3046. this.requireExplicitPolicy = pvutils.getParametersValue(parameters, REQUIRE_EXPLICIT_POLICY, PolicyConstraints.defaultValues(REQUIRE_EXPLICIT_POLICY));
  3047. }
  3048. if (INHIBIT_POLICY_MAPPING in parameters) {
  3049. this.inhibitPolicyMapping = pvutils.getParametersValue(parameters, INHIBIT_POLICY_MAPPING, PolicyConstraints.defaultValues(INHIBIT_POLICY_MAPPING));
  3050. }
  3051. if (parameters.schema) {
  3052. this.fromSchema(parameters.schema);
  3053. }
  3054. }
  3055. static defaultValues(memberName) {
  3056. switch (memberName) {
  3057. case REQUIRE_EXPLICIT_POLICY:
  3058. return 0;
  3059. case INHIBIT_POLICY_MAPPING:
  3060. return 0;
  3061. default:
  3062. return super.defaultValues(memberName);
  3063. }
  3064. }
  3065. static schema(parameters = {}) {
  3066. const names = pvutils.getParametersValue(parameters, "names", {});
  3067. return (new asn1js.Sequence({
  3068. name: (names.blockName || EMPTY_STRING),
  3069. value: [
  3070. new asn1js.Primitive({
  3071. name: (names.requireExplicitPolicy || EMPTY_STRING),
  3072. optional: true,
  3073. idBlock: {
  3074. tagClass: 3,
  3075. tagNumber: 0
  3076. }
  3077. }),
  3078. new asn1js.Primitive({
  3079. name: (names.inhibitPolicyMapping || EMPTY_STRING),
  3080. optional: true,
  3081. idBlock: {
  3082. tagClass: 3,
  3083. tagNumber: 1
  3084. }
  3085. })
  3086. ]
  3087. }));
  3088. }
  3089. fromSchema(schema) {
  3090. pvutils.clearProps(schema, CLEAR_PROPS$1f);
  3091. const asn1 = asn1js.compareSchema(schema, schema, PolicyConstraints.schema({
  3092. names: {
  3093. requireExplicitPolicy: REQUIRE_EXPLICIT_POLICY,
  3094. inhibitPolicyMapping: INHIBIT_POLICY_MAPPING
  3095. }
  3096. }));
  3097. AsnError.assertSchema(asn1, this.className);
  3098. if (REQUIRE_EXPLICIT_POLICY in asn1.result) {
  3099. const field1 = asn1.result.requireExplicitPolicy;
  3100. field1.idBlock.tagClass = 1;
  3101. field1.idBlock.tagNumber = 2;
  3102. const ber1 = field1.toBER(false);
  3103. const int1 = asn1js.fromBER(ber1);
  3104. AsnError.assert(int1, "Integer");
  3105. this.requireExplicitPolicy = int1.result.valueBlock.valueDec;
  3106. }
  3107. if (INHIBIT_POLICY_MAPPING in asn1.result) {
  3108. const field2 = asn1.result.inhibitPolicyMapping;
  3109. field2.idBlock.tagClass = 1;
  3110. field2.idBlock.tagNumber = 2;
  3111. const ber2 = field2.toBER(false);
  3112. const int2 = asn1js.fromBER(ber2);
  3113. AsnError.assert(int2, "Integer");
  3114. this.inhibitPolicyMapping = int2.result.valueBlock.valueDec;
  3115. }
  3116. }
  3117. toSchema() {
  3118. const outputArray = [];
  3119. if (REQUIRE_EXPLICIT_POLICY in this) {
  3120. const int1 = new asn1js.Integer({ value: this.requireExplicitPolicy });
  3121. int1.idBlock.tagClass = 3;
  3122. int1.idBlock.tagNumber = 0;
  3123. outputArray.push(int1);
  3124. }
  3125. if (INHIBIT_POLICY_MAPPING in this) {
  3126. const int2 = new asn1js.Integer({ value: this.inhibitPolicyMapping });
  3127. int2.idBlock.tagClass = 3;
  3128. int2.idBlock.tagNumber = 1;
  3129. outputArray.push(int2);
  3130. }
  3131. return (new asn1js.Sequence({
  3132. value: outputArray
  3133. }));
  3134. }
  3135. toJSON() {
  3136. const res = {};
  3137. if (REQUIRE_EXPLICIT_POLICY in this) {
  3138. res.requireExplicitPolicy = this.requireExplicitPolicy;
  3139. }
  3140. if (INHIBIT_POLICY_MAPPING in this) {
  3141. res.inhibitPolicyMapping = this.inhibitPolicyMapping;
  3142. }
  3143. return res;
  3144. }
  3145. }
  3146. PolicyConstraints.CLASS_NAME = "PolicyConstraints";
  3147. const ISSUER_DOMAIN_POLICY = "issuerDomainPolicy";
  3148. const SUBJECT_DOMAIN_POLICY = "subjectDomainPolicy";
  3149. const CLEAR_PROPS$1e = [
  3150. ISSUER_DOMAIN_POLICY,
  3151. SUBJECT_DOMAIN_POLICY
  3152. ];
  3153. class PolicyMapping extends PkiObject {
  3154. constructor(parameters = {}) {
  3155. super();
  3156. this.issuerDomainPolicy = pvutils.getParametersValue(parameters, ISSUER_DOMAIN_POLICY, PolicyMapping.defaultValues(ISSUER_DOMAIN_POLICY));
  3157. this.subjectDomainPolicy = pvutils.getParametersValue(parameters, SUBJECT_DOMAIN_POLICY, PolicyMapping.defaultValues(SUBJECT_DOMAIN_POLICY));
  3158. if (parameters.schema) {
  3159. this.fromSchema(parameters.schema);
  3160. }
  3161. }
  3162. static defaultValues(memberName) {
  3163. switch (memberName) {
  3164. case ISSUER_DOMAIN_POLICY:
  3165. return EMPTY_STRING;
  3166. case SUBJECT_DOMAIN_POLICY:
  3167. return EMPTY_STRING;
  3168. default:
  3169. return super.defaultValues(memberName);
  3170. }
  3171. }
  3172. static schema(parameters = {}) {
  3173. const names = pvutils.getParametersValue(parameters, "names", {});
  3174. return (new asn1js.Sequence({
  3175. name: (names.blockName || EMPTY_STRING),
  3176. value: [
  3177. new asn1js.ObjectIdentifier({ name: (names.issuerDomainPolicy || EMPTY_STRING) }),
  3178. new asn1js.ObjectIdentifier({ name: (names.subjectDomainPolicy || EMPTY_STRING) })
  3179. ]
  3180. }));
  3181. }
  3182. fromSchema(schema) {
  3183. pvutils.clearProps(schema, CLEAR_PROPS$1e);
  3184. const asn1 = asn1js.compareSchema(schema, schema, PolicyMapping.schema({
  3185. names: {
  3186. issuerDomainPolicy: ISSUER_DOMAIN_POLICY,
  3187. subjectDomainPolicy: SUBJECT_DOMAIN_POLICY
  3188. }
  3189. }));
  3190. AsnError.assertSchema(asn1, this.className);
  3191. this.issuerDomainPolicy = asn1.result.issuerDomainPolicy.valueBlock.toString();
  3192. this.subjectDomainPolicy = asn1.result.subjectDomainPolicy.valueBlock.toString();
  3193. }
  3194. toSchema() {
  3195. return (new asn1js.Sequence({
  3196. value: [
  3197. new asn1js.ObjectIdentifier({ value: this.issuerDomainPolicy }),
  3198. new asn1js.ObjectIdentifier({ value: this.subjectDomainPolicy })
  3199. ]
  3200. }));
  3201. }
  3202. toJSON() {
  3203. return {
  3204. issuerDomainPolicy: this.issuerDomainPolicy,
  3205. subjectDomainPolicy: this.subjectDomainPolicy
  3206. };
  3207. }
  3208. }
  3209. PolicyMapping.CLASS_NAME = "PolicyMapping";
  3210. const MAPPINGS = "mappings";
  3211. const CLEAR_PROPS$1d = [
  3212. MAPPINGS,
  3213. ];
  3214. class PolicyMappings extends PkiObject {
  3215. constructor(parameters = {}) {
  3216. super();
  3217. this.mappings = pvutils.getParametersValue(parameters, MAPPINGS, PolicyMappings.defaultValues(MAPPINGS));
  3218. if (parameters.schema) {
  3219. this.fromSchema(parameters.schema);
  3220. }
  3221. }
  3222. static defaultValues(memberName) {
  3223. switch (memberName) {
  3224. case MAPPINGS:
  3225. return [];
  3226. default:
  3227. return super.defaultValues(memberName);
  3228. }
  3229. }
  3230. static schema(parameters = {}) {
  3231. const names = pvutils.getParametersValue(parameters, "names", {});
  3232. return (new asn1js.Sequence({
  3233. name: (names.blockName || EMPTY_STRING),
  3234. value: [
  3235. new asn1js.Repeated({
  3236. name: (names.mappings || EMPTY_STRING),
  3237. value: PolicyMapping.schema()
  3238. })
  3239. ]
  3240. }));
  3241. }
  3242. fromSchema(schema) {
  3243. pvutils.clearProps(schema, CLEAR_PROPS$1d);
  3244. const asn1 = asn1js.compareSchema(schema, schema, PolicyMappings.schema({
  3245. names: {
  3246. mappings: MAPPINGS
  3247. }
  3248. }));
  3249. AsnError.assertSchema(asn1, this.className);
  3250. this.mappings = Array.from(asn1.result.mappings, element => new PolicyMapping({ schema: element }));
  3251. }
  3252. toSchema() {
  3253. return (new asn1js.Sequence({
  3254. value: Array.from(this.mappings, o => o.toSchema())
  3255. }));
  3256. }
  3257. toJSON() {
  3258. return {
  3259. mappings: Array.from(this.mappings, o => o.toJSON())
  3260. };
  3261. }
  3262. }
  3263. PolicyMappings.CLASS_NAME = "PolicyMappings";
  3264. const NOT_BEFORE$1 = "notBefore";
  3265. const NOT_AFTER$1 = "notAfter";
  3266. const CLEAR_PROPS$1c = [
  3267. NOT_BEFORE$1,
  3268. NOT_AFTER$1
  3269. ];
  3270. class PrivateKeyUsagePeriod extends PkiObject {
  3271. constructor(parameters = {}) {
  3272. super();
  3273. if (NOT_BEFORE$1 in parameters) {
  3274. this.notBefore = pvutils.getParametersValue(parameters, NOT_BEFORE$1, PrivateKeyUsagePeriod.defaultValues(NOT_BEFORE$1));
  3275. }
  3276. if (NOT_AFTER$1 in parameters) {
  3277. this.notAfter = pvutils.getParametersValue(parameters, NOT_AFTER$1, PrivateKeyUsagePeriod.defaultValues(NOT_AFTER$1));
  3278. }
  3279. if (parameters.schema) {
  3280. this.fromSchema(parameters.schema);
  3281. }
  3282. }
  3283. static defaultValues(memberName) {
  3284. switch (memberName) {
  3285. case NOT_BEFORE$1:
  3286. return new Date();
  3287. case NOT_AFTER$1:
  3288. return new Date();
  3289. default:
  3290. return super.defaultValues(memberName);
  3291. }
  3292. }
  3293. static schema(parameters = {}) {
  3294. const names = pvutils.getParametersValue(parameters, "names", {});
  3295. return (new asn1js.Sequence({
  3296. name: (names.blockName || EMPTY_STRING),
  3297. value: [
  3298. new asn1js.Primitive({
  3299. name: (names.notBefore || EMPTY_STRING),
  3300. optional: true,
  3301. idBlock: {
  3302. tagClass: 3,
  3303. tagNumber: 0
  3304. }
  3305. }),
  3306. new asn1js.Primitive({
  3307. name: (names.notAfter || EMPTY_STRING),
  3308. optional: true,
  3309. idBlock: {
  3310. tagClass: 3,
  3311. tagNumber: 1
  3312. }
  3313. })
  3314. ]
  3315. }));
  3316. }
  3317. fromSchema(schema) {
  3318. pvutils.clearProps(schema, CLEAR_PROPS$1c);
  3319. const asn1 = asn1js.compareSchema(schema, schema, PrivateKeyUsagePeriod.schema({
  3320. names: {
  3321. notBefore: NOT_BEFORE$1,
  3322. notAfter: NOT_AFTER$1
  3323. }
  3324. }));
  3325. AsnError.assertSchema(asn1, this.className);
  3326. if (NOT_BEFORE$1 in asn1.result) {
  3327. const localNotBefore = new asn1js.GeneralizedTime();
  3328. localNotBefore.fromBuffer(asn1.result.notBefore.valueBlock.valueHex);
  3329. this.notBefore = localNotBefore.toDate();
  3330. }
  3331. if (NOT_AFTER$1 in asn1.result) {
  3332. const localNotAfter = new asn1js.GeneralizedTime({ valueHex: asn1.result.notAfter.valueBlock.valueHex });
  3333. localNotAfter.fromBuffer(asn1.result.notAfter.valueBlock.valueHex);
  3334. this.notAfter = localNotAfter.toDate();
  3335. }
  3336. }
  3337. toSchema() {
  3338. const outputArray = [];
  3339. if (NOT_BEFORE$1 in this) {
  3340. outputArray.push(new asn1js.Primitive({
  3341. idBlock: {
  3342. tagClass: 3,
  3343. tagNumber: 0
  3344. },
  3345. valueHex: (new asn1js.GeneralizedTime({ valueDate: this.notBefore })).valueBlock.valueHexView
  3346. }));
  3347. }
  3348. if (NOT_AFTER$1 in this) {
  3349. outputArray.push(new asn1js.Primitive({
  3350. idBlock: {
  3351. tagClass: 3,
  3352. tagNumber: 1
  3353. },
  3354. valueHex: (new asn1js.GeneralizedTime({ valueDate: this.notAfter })).valueBlock.valueHexView
  3355. }));
  3356. }
  3357. return (new asn1js.Sequence({
  3358. value: outputArray
  3359. }));
  3360. }
  3361. toJSON() {
  3362. const res = {};
  3363. if (this.notBefore) {
  3364. res.notBefore = this.notBefore;
  3365. }
  3366. if (this.notAfter) {
  3367. res.notAfter = this.notAfter;
  3368. }
  3369. return res;
  3370. }
  3371. }
  3372. PrivateKeyUsagePeriod.CLASS_NAME = "PrivateKeyUsagePeriod";
  3373. const ID = "id";
  3374. const TYPE$2 = "type";
  3375. const VALUES = "values";
  3376. const QC_STATEMENT_CLEAR_PROPS = [
  3377. ID,
  3378. TYPE$2
  3379. ];
  3380. const QC_STATEMENTS_CLEAR_PROPS = [
  3381. VALUES
  3382. ];
  3383. class QCStatement extends PkiObject {
  3384. constructor(parameters = {}) {
  3385. super();
  3386. this.id = pvutils.getParametersValue(parameters, ID, QCStatement.defaultValues(ID));
  3387. if (TYPE$2 in parameters) {
  3388. this.type = pvutils.getParametersValue(parameters, TYPE$2, QCStatement.defaultValues(TYPE$2));
  3389. }
  3390. if (parameters.schema) {
  3391. this.fromSchema(parameters.schema);
  3392. }
  3393. }
  3394. static defaultValues(memberName) {
  3395. switch (memberName) {
  3396. case ID:
  3397. return EMPTY_STRING;
  3398. case TYPE$2:
  3399. return new asn1js.Null();
  3400. default:
  3401. return super.defaultValues(memberName);
  3402. }
  3403. }
  3404. static compareWithDefault(memberName, memberValue) {
  3405. switch (memberName) {
  3406. case ID:
  3407. return (memberValue === EMPTY_STRING);
  3408. case TYPE$2:
  3409. return (memberValue instanceof asn1js.Null);
  3410. default:
  3411. return super.defaultValues(memberName);
  3412. }
  3413. }
  3414. static schema(parameters = {}) {
  3415. const names = pvutils.getParametersValue(parameters, "names", {});
  3416. return (new asn1js.Sequence({
  3417. name: (names.blockName || EMPTY_STRING),
  3418. value: [
  3419. new asn1js.ObjectIdentifier({ name: (names.id || EMPTY_STRING) }),
  3420. new asn1js.Any({
  3421. name: (names.type || EMPTY_STRING),
  3422. optional: true
  3423. })
  3424. ]
  3425. }));
  3426. }
  3427. fromSchema(schema) {
  3428. pvutils.clearProps(schema, QC_STATEMENT_CLEAR_PROPS);
  3429. const asn1 = asn1js.compareSchema(schema, schema, QCStatement.schema({
  3430. names: {
  3431. id: ID,
  3432. type: TYPE$2
  3433. }
  3434. }));
  3435. AsnError.assertSchema(asn1, this.className);
  3436. this.id = asn1.result.id.valueBlock.toString();
  3437. if (TYPE$2 in asn1.result)
  3438. this.type = asn1.result.type;
  3439. }
  3440. toSchema() {
  3441. const value = [
  3442. new asn1js.ObjectIdentifier({ value: this.id })
  3443. ];
  3444. if (TYPE$2 in this)
  3445. value.push(this.type);
  3446. return (new asn1js.Sequence({
  3447. value,
  3448. }));
  3449. }
  3450. toJSON() {
  3451. const object = {
  3452. id: this.id
  3453. };
  3454. if (this.type) {
  3455. object.type = this.type.toJSON();
  3456. }
  3457. return object;
  3458. }
  3459. }
  3460. QCStatement.CLASS_NAME = "QCStatement";
  3461. class QCStatements extends PkiObject {
  3462. constructor(parameters = {}) {
  3463. super();
  3464. this.values = pvutils.getParametersValue(parameters, VALUES, QCStatements.defaultValues(VALUES));
  3465. if (parameters.schema) {
  3466. this.fromSchema(parameters.schema);
  3467. }
  3468. }
  3469. static defaultValues(memberName) {
  3470. switch (memberName) {
  3471. case VALUES:
  3472. return [];
  3473. default:
  3474. return super.defaultValues(memberName);
  3475. }
  3476. }
  3477. static compareWithDefault(memberName, memberValue) {
  3478. switch (memberName) {
  3479. case VALUES:
  3480. return (memberValue.length === 0);
  3481. default:
  3482. return super.defaultValues(memberName);
  3483. }
  3484. }
  3485. static schema(parameters = {}) {
  3486. const names = pvutils.getParametersValue(parameters, "names", {});
  3487. return (new asn1js.Sequence({
  3488. name: (names.blockName || EMPTY_STRING),
  3489. value: [
  3490. new asn1js.Repeated({
  3491. name: (names.values || EMPTY_STRING),
  3492. value: QCStatement.schema(names.value || {})
  3493. }),
  3494. ]
  3495. }));
  3496. }
  3497. fromSchema(schema) {
  3498. pvutils.clearProps(schema, QC_STATEMENTS_CLEAR_PROPS);
  3499. const asn1 = asn1js.compareSchema(schema, schema, QCStatements.schema({
  3500. names: {
  3501. values: VALUES
  3502. }
  3503. }));
  3504. AsnError.assertSchema(asn1, this.className);
  3505. this.values = Array.from(asn1.result.values, element => new QCStatement({ schema: element }));
  3506. }
  3507. toSchema() {
  3508. return (new asn1js.Sequence({
  3509. value: Array.from(this.values, o => o.toSchema())
  3510. }));
  3511. }
  3512. toJSON() {
  3513. return {
  3514. values: Array.from(this.values, o => o.toJSON())
  3515. };
  3516. }
  3517. }
  3518. QCStatements.CLASS_NAME = "QCStatements";
  3519. var _a;
  3520. class ECNamedCurves {
  3521. static register(name, id, size) {
  3522. this.namedCurves[name.toLowerCase()] = this.namedCurves[id] = { name, id, size };
  3523. }
  3524. static find(nameOrId) {
  3525. return this.namedCurves[nameOrId.toLowerCase()] || null;
  3526. }
  3527. }
  3528. _a = ECNamedCurves;
  3529. ECNamedCurves.namedCurves = {};
  3530. (() => {
  3531. _a.register("P-256", "1.2.840.10045.3.1.7", 32);
  3532. _a.register("P-384", "1.3.132.0.34", 48);
  3533. _a.register("P-521", "1.3.132.0.35", 66);
  3534. _a.register("brainpoolP256r1", "1.3.36.3.3.2.8.1.1.7", 32);
  3535. _a.register("brainpoolP384r1", "1.3.36.3.3.2.8.1.1.11", 48);
  3536. _a.register("brainpoolP512r1", "1.3.36.3.3.2.8.1.1.13", 64);
  3537. })();
  3538. const X = "x";
  3539. const Y = "y";
  3540. const NAMED_CURVE$1 = "namedCurve";
  3541. class ECPublicKey extends PkiObject {
  3542. constructor(parameters = {}) {
  3543. super();
  3544. this.x = pvutils.getParametersValue(parameters, X, ECPublicKey.defaultValues(X));
  3545. this.y = pvutils.getParametersValue(parameters, Y, ECPublicKey.defaultValues(Y));
  3546. this.namedCurve = pvutils.getParametersValue(parameters, NAMED_CURVE$1, ECPublicKey.defaultValues(NAMED_CURVE$1));
  3547. if (parameters.json) {
  3548. this.fromJSON(parameters.json);
  3549. }
  3550. if (parameters.schema) {
  3551. this.fromSchema(parameters.schema);
  3552. }
  3553. }
  3554. static defaultValues(memberName) {
  3555. switch (memberName) {
  3556. case X:
  3557. case Y:
  3558. return EMPTY_BUFFER;
  3559. case NAMED_CURVE$1:
  3560. return EMPTY_STRING;
  3561. default:
  3562. return super.defaultValues(memberName);
  3563. }
  3564. }
  3565. static compareWithDefault(memberName, memberValue) {
  3566. switch (memberName) {
  3567. case X:
  3568. case Y:
  3569. return memberValue instanceof ArrayBuffer &&
  3570. (pvutils.isEqualBuffer(memberValue, ECPublicKey.defaultValues(memberName)));
  3571. case NAMED_CURVE$1:
  3572. return typeof memberValue === "string" &&
  3573. memberValue === ECPublicKey.defaultValues(memberName);
  3574. default:
  3575. return super.defaultValues(memberName);
  3576. }
  3577. }
  3578. static schema() {
  3579. return new asn1js.RawData();
  3580. }
  3581. fromSchema(schema1) {
  3582. const view = BufferSourceConverter.toUint8Array(schema1);
  3583. if (view[0] !== 0x04) {
  3584. throw new Error("Object's schema was not verified against input data for ECPublicKey");
  3585. }
  3586. const namedCurve = ECNamedCurves.find(this.namedCurve);
  3587. if (!namedCurve) {
  3588. throw new Error(`Incorrect curve OID: ${this.namedCurve}`);
  3589. }
  3590. const coordinateLength = namedCurve.size;
  3591. if (view.byteLength !== (coordinateLength * 2 + 1)) {
  3592. throw new Error("Object's schema was not verified against input data for ECPublicKey");
  3593. }
  3594. this.namedCurve = namedCurve.name;
  3595. this.x = view.slice(1, coordinateLength + 1).buffer;
  3596. this.y = view.slice(1 + coordinateLength, coordinateLength * 2 + 1).buffer;
  3597. }
  3598. toSchema() {
  3599. return new asn1js.RawData({
  3600. data: pvutils.utilConcatBuf((new Uint8Array([0x04])).buffer, this.x, this.y)
  3601. });
  3602. }
  3603. toJSON() {
  3604. const namedCurve = ECNamedCurves.find(this.namedCurve);
  3605. return {
  3606. crv: namedCurve ? namedCurve.name : this.namedCurve,
  3607. x: pvutils.toBase64(pvutils.arrayBufferToString(this.x), true, true, false),
  3608. y: pvutils.toBase64(pvutils.arrayBufferToString(this.y), true, true, false)
  3609. };
  3610. }
  3611. fromJSON(json) {
  3612. ParameterError.assert("json", json, "crv", "x", "y");
  3613. let coordinateLength = 0;
  3614. const namedCurve = ECNamedCurves.find(json.crv);
  3615. if (namedCurve) {
  3616. this.namedCurve = namedCurve.id;
  3617. coordinateLength = namedCurve.size;
  3618. }
  3619. const xConvertBuffer = pvutils.stringToArrayBuffer(pvutils.fromBase64(json.x, true));
  3620. if (xConvertBuffer.byteLength < coordinateLength) {
  3621. this.x = new ArrayBuffer(coordinateLength);
  3622. const view = new Uint8Array(this.x);
  3623. const convertBufferView = new Uint8Array(xConvertBuffer);
  3624. view.set(convertBufferView, 1);
  3625. }
  3626. else {
  3627. this.x = xConvertBuffer.slice(0, coordinateLength);
  3628. }
  3629. const yConvertBuffer = pvutils.stringToArrayBuffer(pvutils.fromBase64(json.y, true));
  3630. if (yConvertBuffer.byteLength < coordinateLength) {
  3631. this.y = new ArrayBuffer(coordinateLength);
  3632. const view = new Uint8Array(this.y);
  3633. const convertBufferView = new Uint8Array(yConvertBuffer);
  3634. view.set(convertBufferView, 1);
  3635. }
  3636. else {
  3637. this.y = yConvertBuffer.slice(0, coordinateLength);
  3638. }
  3639. }
  3640. }
  3641. ECPublicKey.CLASS_NAME = "ECPublicKey";
  3642. const MODULUS$1 = "modulus";
  3643. const PUBLIC_EXPONENT$1 = "publicExponent";
  3644. const CLEAR_PROPS$1b = [MODULUS$1, PUBLIC_EXPONENT$1];
  3645. class RSAPublicKey extends PkiObject {
  3646. constructor(parameters = {}) {
  3647. super();
  3648. this.modulus = pvutils.getParametersValue(parameters, MODULUS$1, RSAPublicKey.defaultValues(MODULUS$1));
  3649. this.publicExponent = pvutils.getParametersValue(parameters, PUBLIC_EXPONENT$1, RSAPublicKey.defaultValues(PUBLIC_EXPONENT$1));
  3650. if (parameters.json) {
  3651. this.fromJSON(parameters.json);
  3652. }
  3653. if (parameters.schema) {
  3654. this.fromSchema(parameters.schema);
  3655. }
  3656. }
  3657. static defaultValues(memberName) {
  3658. switch (memberName) {
  3659. case MODULUS$1:
  3660. return new asn1js.Integer();
  3661. case PUBLIC_EXPONENT$1:
  3662. return new asn1js.Integer();
  3663. default:
  3664. return super.defaultValues(memberName);
  3665. }
  3666. }
  3667. static schema(parameters = {}) {
  3668. const names = pvutils.getParametersValue(parameters, "names", {});
  3669. return (new asn1js.Sequence({
  3670. name: (names.blockName || EMPTY_STRING),
  3671. value: [
  3672. new asn1js.Integer({ name: (names.modulus || EMPTY_STRING) }),
  3673. new asn1js.Integer({ name: (names.publicExponent || EMPTY_STRING) })
  3674. ]
  3675. }));
  3676. }
  3677. fromSchema(schema) {
  3678. pvutils.clearProps(schema, CLEAR_PROPS$1b);
  3679. const asn1 = asn1js.compareSchema(schema, schema, RSAPublicKey.schema({
  3680. names: {
  3681. modulus: MODULUS$1,
  3682. publicExponent: PUBLIC_EXPONENT$1
  3683. }
  3684. }));
  3685. AsnError.assertSchema(asn1, this.className);
  3686. this.modulus = asn1.result.modulus.convertFromDER(256);
  3687. this.publicExponent = asn1.result.publicExponent;
  3688. }
  3689. toSchema() {
  3690. return (new asn1js.Sequence({
  3691. value: [
  3692. this.modulus.convertToDER(),
  3693. this.publicExponent
  3694. ]
  3695. }));
  3696. }
  3697. toJSON() {
  3698. return {
  3699. n: pvtsutils.Convert.ToBase64Url(this.modulus.valueBlock.valueHexView),
  3700. e: pvtsutils.Convert.ToBase64Url(this.publicExponent.valueBlock.valueHexView),
  3701. };
  3702. }
  3703. fromJSON(json) {
  3704. ParameterError.assert("json", json, "n", "e");
  3705. const array = pvutils.stringToArrayBuffer(pvutils.fromBase64(json.n, true));
  3706. this.modulus = new asn1js.Integer({ valueHex: array.slice(0, Math.pow(2, pvutils.nearestPowerOf2(array.byteLength))) });
  3707. this.publicExponent = new asn1js.Integer({ valueHex: pvutils.stringToArrayBuffer(pvutils.fromBase64(json.e, true)).slice(0, 3) });
  3708. }
  3709. }
  3710. RSAPublicKey.CLASS_NAME = "RSAPublicKey";
  3711. const ALGORITHM$1 = "algorithm";
  3712. const SUBJECT_PUBLIC_KEY = "subjectPublicKey";
  3713. const CLEAR_PROPS$1a = [ALGORITHM$1, SUBJECT_PUBLIC_KEY];
  3714. class PublicKeyInfo extends PkiObject {
  3715. get parsedKey() {
  3716. if (this._parsedKey === undefined) {
  3717. switch (this.algorithm.algorithmId) {
  3718. case "1.2.840.10045.2.1":
  3719. if ("algorithmParams" in this.algorithm) {
  3720. if (this.algorithm.algorithmParams.constructor.blockName() === asn1js.ObjectIdentifier.blockName()) {
  3721. try {
  3722. this._parsedKey = new ECPublicKey({
  3723. namedCurve: this.algorithm.algorithmParams.valueBlock.toString(),
  3724. schema: this.subjectPublicKey.valueBlock.valueHexView
  3725. });
  3726. }
  3727. catch {
  3728. }
  3729. }
  3730. }
  3731. break;
  3732. case "1.2.840.113549.1.1.1":
  3733. case "1.2.840.113549.1.1.10":
  3734. {
  3735. const publicKeyASN1 = asn1js.fromBER(this.subjectPublicKey.valueBlock.valueHexView);
  3736. if (publicKeyASN1.offset !== -1) {
  3737. try {
  3738. this._parsedKey = new RSAPublicKey({ schema: publicKeyASN1.result });
  3739. }
  3740. catch {
  3741. }
  3742. }
  3743. }
  3744. break;
  3745. }
  3746. this._parsedKey || (this._parsedKey = null);
  3747. }
  3748. return this._parsedKey || undefined;
  3749. }
  3750. set parsedKey(value) {
  3751. this._parsedKey = value;
  3752. }
  3753. constructor(parameters = {}) {
  3754. super();
  3755. this.algorithm = pvutils.getParametersValue(parameters, ALGORITHM$1, PublicKeyInfo.defaultValues(ALGORITHM$1));
  3756. this.subjectPublicKey = pvutils.getParametersValue(parameters, SUBJECT_PUBLIC_KEY, PublicKeyInfo.defaultValues(SUBJECT_PUBLIC_KEY));
  3757. const parsedKey = pvutils.getParametersValue(parameters, "parsedKey", null);
  3758. if (parsedKey) {
  3759. this.parsedKey = parsedKey;
  3760. }
  3761. if (parameters.json) {
  3762. this.fromJSON(parameters.json);
  3763. }
  3764. if (parameters.schema) {
  3765. this.fromSchema(parameters.schema);
  3766. }
  3767. }
  3768. static defaultValues(memberName) {
  3769. switch (memberName) {
  3770. case ALGORITHM$1:
  3771. return new AlgorithmIdentifier();
  3772. case SUBJECT_PUBLIC_KEY:
  3773. return new asn1js.BitString();
  3774. default:
  3775. return super.defaultValues(memberName);
  3776. }
  3777. }
  3778. static schema(parameters = {}) {
  3779. const names = pvutils.getParametersValue(parameters, "names", {});
  3780. return (new asn1js.Sequence({
  3781. name: (names.blockName || EMPTY_STRING),
  3782. value: [
  3783. AlgorithmIdentifier.schema(names.algorithm || {}),
  3784. new asn1js.BitString({ name: (names.subjectPublicKey || EMPTY_STRING) })
  3785. ]
  3786. }));
  3787. }
  3788. fromSchema(schema) {
  3789. pvutils.clearProps(schema, CLEAR_PROPS$1a);
  3790. const asn1 = asn1js.compareSchema(schema, schema, PublicKeyInfo.schema({
  3791. names: {
  3792. algorithm: {
  3793. names: {
  3794. blockName: ALGORITHM$1
  3795. }
  3796. },
  3797. subjectPublicKey: SUBJECT_PUBLIC_KEY
  3798. }
  3799. }));
  3800. AsnError.assertSchema(asn1, this.className);
  3801. this.algorithm = new AlgorithmIdentifier({ schema: asn1.result.algorithm });
  3802. this.subjectPublicKey = asn1.result.subjectPublicKey;
  3803. }
  3804. toSchema() {
  3805. return (new asn1js.Sequence({
  3806. value: [
  3807. this.algorithm.toSchema(),
  3808. this.subjectPublicKey
  3809. ]
  3810. }));
  3811. }
  3812. toJSON() {
  3813. if (!this.parsedKey) {
  3814. return {
  3815. algorithm: this.algorithm.toJSON(),
  3816. subjectPublicKey: this.subjectPublicKey.toJSON(),
  3817. };
  3818. }
  3819. const jwk = {};
  3820. switch (this.algorithm.algorithmId) {
  3821. case "1.2.840.10045.2.1":
  3822. jwk.kty = "EC";
  3823. break;
  3824. case "1.2.840.113549.1.1.1":
  3825. case "1.2.840.113549.1.1.10":
  3826. jwk.kty = "RSA";
  3827. break;
  3828. }
  3829. const publicKeyJWK = this.parsedKey.toJSON();
  3830. Object.assign(jwk, publicKeyJWK);
  3831. return jwk;
  3832. }
  3833. fromJSON(json) {
  3834. if ("kty" in json) {
  3835. switch (json.kty.toUpperCase()) {
  3836. case "EC":
  3837. this.parsedKey = new ECPublicKey({ json });
  3838. this.algorithm = new AlgorithmIdentifier({
  3839. algorithmId: "1.2.840.10045.2.1",
  3840. algorithmParams: new asn1js.ObjectIdentifier({ value: this.parsedKey.namedCurve })
  3841. });
  3842. break;
  3843. case "RSA":
  3844. this.parsedKey = new RSAPublicKey({ json });
  3845. this.algorithm = new AlgorithmIdentifier({
  3846. algorithmId: "1.2.840.113549.1.1.1",
  3847. algorithmParams: new asn1js.Null()
  3848. });
  3849. break;
  3850. default:
  3851. throw new Error(`Invalid value for "kty" parameter: ${json.kty}`);
  3852. }
  3853. this.subjectPublicKey = new asn1js.BitString({ valueHex: this.parsedKey.toSchema().toBER(false) });
  3854. }
  3855. }
  3856. async importKey(publicKey, crypto = getCrypto(true)) {
  3857. try {
  3858. if (!publicKey) {
  3859. throw new Error("Need to provide publicKey input parameter");
  3860. }
  3861. const exportedKey = await crypto.exportKey("spki", publicKey);
  3862. const asn1 = asn1js.fromBER(exportedKey);
  3863. try {
  3864. this.fromSchema(asn1.result);
  3865. }
  3866. catch {
  3867. throw new Error("Error during initializing object from schema");
  3868. }
  3869. }
  3870. catch (e) {
  3871. const message = e instanceof Error ? e.message : `${e}`;
  3872. throw new Error(`Error during exporting public key: ${message}`);
  3873. }
  3874. }
  3875. }
  3876. PublicKeyInfo.CLASS_NAME = "PublicKeyInfo";
  3877. const VERSION$l = "version";
  3878. const PRIVATE_KEY$1 = "privateKey";
  3879. const NAMED_CURVE = "namedCurve";
  3880. const PUBLIC_KEY$1 = "publicKey";
  3881. const CLEAR_PROPS$19 = [
  3882. VERSION$l,
  3883. PRIVATE_KEY$1,
  3884. NAMED_CURVE,
  3885. PUBLIC_KEY$1
  3886. ];
  3887. class ECPrivateKey extends PkiObject {
  3888. constructor(parameters = {}) {
  3889. super();
  3890. this.version = pvutils.getParametersValue(parameters, VERSION$l, ECPrivateKey.defaultValues(VERSION$l));
  3891. this.privateKey = pvutils.getParametersValue(parameters, PRIVATE_KEY$1, ECPrivateKey.defaultValues(PRIVATE_KEY$1));
  3892. if (NAMED_CURVE in parameters) {
  3893. this.namedCurve = pvutils.getParametersValue(parameters, NAMED_CURVE, ECPrivateKey.defaultValues(NAMED_CURVE));
  3894. }
  3895. if (PUBLIC_KEY$1 in parameters) {
  3896. this.publicKey = pvutils.getParametersValue(parameters, PUBLIC_KEY$1, ECPrivateKey.defaultValues(PUBLIC_KEY$1));
  3897. }
  3898. if (parameters.json) {
  3899. this.fromJSON(parameters.json);
  3900. }
  3901. if (parameters.schema) {
  3902. this.fromSchema(parameters.schema);
  3903. }
  3904. }
  3905. static defaultValues(memberName) {
  3906. switch (memberName) {
  3907. case VERSION$l:
  3908. return 1;
  3909. case PRIVATE_KEY$1:
  3910. return new asn1js.OctetString();
  3911. case NAMED_CURVE:
  3912. return EMPTY_STRING;
  3913. case PUBLIC_KEY$1:
  3914. return new ECPublicKey();
  3915. default:
  3916. return super.defaultValues(memberName);
  3917. }
  3918. }
  3919. static compareWithDefault(memberName, memberValue) {
  3920. switch (memberName) {
  3921. case VERSION$l:
  3922. return (memberValue === ECPrivateKey.defaultValues(memberName));
  3923. case PRIVATE_KEY$1:
  3924. return (memberValue.isEqual(ECPrivateKey.defaultValues(memberName)));
  3925. case NAMED_CURVE:
  3926. return (memberValue === EMPTY_STRING);
  3927. case PUBLIC_KEY$1:
  3928. return ((ECPublicKey.compareWithDefault(NAMED_CURVE, memberValue.namedCurve)) &&
  3929. (ECPublicKey.compareWithDefault("x", memberValue.x)) &&
  3930. (ECPublicKey.compareWithDefault("y", memberValue.y)));
  3931. default:
  3932. return super.defaultValues(memberName);
  3933. }
  3934. }
  3935. static schema(parameters = {}) {
  3936. const names = pvutils.getParametersValue(parameters, "names", {});
  3937. return (new asn1js.Sequence({
  3938. name: (names.blockName || EMPTY_STRING),
  3939. value: [
  3940. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  3941. new asn1js.OctetString({ name: (names.privateKey || EMPTY_STRING) }),
  3942. new asn1js.Constructed({
  3943. optional: true,
  3944. idBlock: {
  3945. tagClass: 3,
  3946. tagNumber: 0
  3947. },
  3948. value: [
  3949. new asn1js.ObjectIdentifier({ name: (names.namedCurve || EMPTY_STRING) })
  3950. ]
  3951. }),
  3952. new asn1js.Constructed({
  3953. optional: true,
  3954. idBlock: {
  3955. tagClass: 3,
  3956. tagNumber: 1
  3957. },
  3958. value: [
  3959. new asn1js.BitString({ name: (names.publicKey || EMPTY_STRING) })
  3960. ]
  3961. })
  3962. ]
  3963. }));
  3964. }
  3965. fromSchema(schema) {
  3966. pvutils.clearProps(schema, CLEAR_PROPS$19);
  3967. const asn1 = asn1js.compareSchema(schema, schema, ECPrivateKey.schema({
  3968. names: {
  3969. version: VERSION$l,
  3970. privateKey: PRIVATE_KEY$1,
  3971. namedCurve: NAMED_CURVE,
  3972. publicKey: PUBLIC_KEY$1
  3973. }
  3974. }));
  3975. AsnError.assertSchema(asn1, this.className);
  3976. this.version = asn1.result.version.valueBlock.valueDec;
  3977. this.privateKey = asn1.result.privateKey;
  3978. if (NAMED_CURVE in asn1.result) {
  3979. this.namedCurve = asn1.result.namedCurve.valueBlock.toString();
  3980. }
  3981. if (PUBLIC_KEY$1 in asn1.result) {
  3982. const publicKeyData = { schema: asn1.result.publicKey.valueBlock.valueHex };
  3983. if (NAMED_CURVE in this) {
  3984. publicKeyData.namedCurve = this.namedCurve;
  3985. }
  3986. this.publicKey = new ECPublicKey(publicKeyData);
  3987. }
  3988. }
  3989. toSchema() {
  3990. const outputArray = [
  3991. new asn1js.Integer({ value: this.version }),
  3992. this.privateKey
  3993. ];
  3994. if (this.namedCurve) {
  3995. outputArray.push(new asn1js.Constructed({
  3996. idBlock: {
  3997. tagClass: 3,
  3998. tagNumber: 0
  3999. },
  4000. value: [
  4001. new asn1js.ObjectIdentifier({ value: this.namedCurve })
  4002. ]
  4003. }));
  4004. }
  4005. if (this.publicKey) {
  4006. outputArray.push(new asn1js.Constructed({
  4007. idBlock: {
  4008. tagClass: 3,
  4009. tagNumber: 1
  4010. },
  4011. value: [
  4012. new asn1js.BitString({ valueHex: this.publicKey.toSchema().toBER(false) })
  4013. ]
  4014. }));
  4015. }
  4016. return new asn1js.Sequence({
  4017. value: outputArray
  4018. });
  4019. }
  4020. toJSON() {
  4021. if (!this.namedCurve || ECPrivateKey.compareWithDefault(NAMED_CURVE, this.namedCurve)) {
  4022. throw new Error("Not enough information for making JSON: absent \"namedCurve\" value");
  4023. }
  4024. const curve = ECNamedCurves.find(this.namedCurve);
  4025. const privateKeyJSON = {
  4026. crv: curve ? curve.name : this.namedCurve,
  4027. d: pvtsutils.Convert.ToBase64Url(this.privateKey.valueBlock.valueHexView),
  4028. };
  4029. if (this.publicKey) {
  4030. const publicKeyJSON = this.publicKey.toJSON();
  4031. privateKeyJSON.x = publicKeyJSON.x;
  4032. privateKeyJSON.y = publicKeyJSON.y;
  4033. }
  4034. return privateKeyJSON;
  4035. }
  4036. fromJSON(json) {
  4037. ParameterError.assert("json", json, "crv", "d");
  4038. let coordinateLength = 0;
  4039. const curve = ECNamedCurves.find(json.crv);
  4040. if (curve) {
  4041. this.namedCurve = curve.id;
  4042. coordinateLength = curve.size;
  4043. }
  4044. const convertBuffer = pvtsutils.Convert.FromBase64Url(json.d);
  4045. if (convertBuffer.byteLength < coordinateLength) {
  4046. const buffer = new ArrayBuffer(coordinateLength);
  4047. const view = new Uint8Array(buffer);
  4048. const convertBufferView = new Uint8Array(convertBuffer);
  4049. view.set(convertBufferView, 1);
  4050. this.privateKey = new asn1js.OctetString({ valueHex: buffer });
  4051. }
  4052. else {
  4053. this.privateKey = new asn1js.OctetString({ valueHex: convertBuffer.slice(0, coordinateLength) });
  4054. }
  4055. if (json.x && json.y) {
  4056. this.publicKey = new ECPublicKey({ json });
  4057. }
  4058. }
  4059. }
  4060. ECPrivateKey.CLASS_NAME = "ECPrivateKey";
  4061. const PRIME = "prime";
  4062. const EXPONENT = "exponent";
  4063. const COEFFICIENT$1 = "coefficient";
  4064. const CLEAR_PROPS$18 = [
  4065. PRIME,
  4066. EXPONENT,
  4067. COEFFICIENT$1,
  4068. ];
  4069. class OtherPrimeInfo extends PkiObject {
  4070. constructor(parameters = {}) {
  4071. super();
  4072. this.prime = pvutils.getParametersValue(parameters, PRIME, OtherPrimeInfo.defaultValues(PRIME));
  4073. this.exponent = pvutils.getParametersValue(parameters, EXPONENT, OtherPrimeInfo.defaultValues(EXPONENT));
  4074. this.coefficient = pvutils.getParametersValue(parameters, COEFFICIENT$1, OtherPrimeInfo.defaultValues(COEFFICIENT$1));
  4075. if (parameters.json) {
  4076. this.fromJSON(parameters.json);
  4077. }
  4078. if (parameters.schema) {
  4079. this.fromSchema(parameters.schema);
  4080. }
  4081. }
  4082. static defaultValues(memberName) {
  4083. switch (memberName) {
  4084. case PRIME:
  4085. return new asn1js.Integer();
  4086. case EXPONENT:
  4087. return new asn1js.Integer();
  4088. case COEFFICIENT$1:
  4089. return new asn1js.Integer();
  4090. default:
  4091. return super.defaultValues(memberName);
  4092. }
  4093. }
  4094. static schema(parameters = {}) {
  4095. const names = pvutils.getParametersValue(parameters, "names", {});
  4096. return (new asn1js.Sequence({
  4097. name: (names.blockName || EMPTY_STRING),
  4098. value: [
  4099. new asn1js.Integer({ name: (names.prime || EMPTY_STRING) }),
  4100. new asn1js.Integer({ name: (names.exponent || EMPTY_STRING) }),
  4101. new asn1js.Integer({ name: (names.coefficient || EMPTY_STRING) })
  4102. ]
  4103. }));
  4104. }
  4105. fromSchema(schema) {
  4106. pvutils.clearProps(schema, CLEAR_PROPS$18);
  4107. const asn1 = asn1js.compareSchema(schema, schema, OtherPrimeInfo.schema({
  4108. names: {
  4109. prime: PRIME,
  4110. exponent: EXPONENT,
  4111. coefficient: COEFFICIENT$1
  4112. }
  4113. }));
  4114. AsnError.assertSchema(asn1, this.className);
  4115. this.prime = asn1.result.prime.convertFromDER();
  4116. this.exponent = asn1.result.exponent.convertFromDER();
  4117. this.coefficient = asn1.result.coefficient.convertFromDER();
  4118. }
  4119. toSchema() {
  4120. return (new asn1js.Sequence({
  4121. value: [
  4122. this.prime.convertToDER(),
  4123. this.exponent.convertToDER(),
  4124. this.coefficient.convertToDER()
  4125. ]
  4126. }));
  4127. }
  4128. toJSON() {
  4129. return {
  4130. r: pvtsutils.Convert.ToBase64Url(this.prime.valueBlock.valueHexView),
  4131. d: pvtsutils.Convert.ToBase64Url(this.exponent.valueBlock.valueHexView),
  4132. t: pvtsutils.Convert.ToBase64Url(this.coefficient.valueBlock.valueHexView),
  4133. };
  4134. }
  4135. fromJSON(json) {
  4136. ParameterError.assert("json", json, "r", "d", "r");
  4137. this.prime = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.r) });
  4138. this.exponent = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.d) });
  4139. this.coefficient = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.t) });
  4140. }
  4141. }
  4142. OtherPrimeInfo.CLASS_NAME = "OtherPrimeInfo";
  4143. const VERSION$k = "version";
  4144. const MODULUS = "modulus";
  4145. const PUBLIC_EXPONENT = "publicExponent";
  4146. const PRIVATE_EXPONENT = "privateExponent";
  4147. const PRIME1 = "prime1";
  4148. const PRIME2 = "prime2";
  4149. const EXPONENT1 = "exponent1";
  4150. const EXPONENT2 = "exponent2";
  4151. const COEFFICIENT = "coefficient";
  4152. const OTHER_PRIME_INFOS = "otherPrimeInfos";
  4153. const CLEAR_PROPS$17 = [
  4154. VERSION$k,
  4155. MODULUS,
  4156. PUBLIC_EXPONENT,
  4157. PRIVATE_EXPONENT,
  4158. PRIME1,
  4159. PRIME2,
  4160. EXPONENT1,
  4161. EXPONENT2,
  4162. COEFFICIENT,
  4163. OTHER_PRIME_INFOS
  4164. ];
  4165. class RSAPrivateKey extends PkiObject {
  4166. constructor(parameters = {}) {
  4167. super();
  4168. this.version = pvutils.getParametersValue(parameters, VERSION$k, RSAPrivateKey.defaultValues(VERSION$k));
  4169. this.modulus = pvutils.getParametersValue(parameters, MODULUS, RSAPrivateKey.defaultValues(MODULUS));
  4170. this.publicExponent = pvutils.getParametersValue(parameters, PUBLIC_EXPONENT, RSAPrivateKey.defaultValues(PUBLIC_EXPONENT));
  4171. this.privateExponent = pvutils.getParametersValue(parameters, PRIVATE_EXPONENT, RSAPrivateKey.defaultValues(PRIVATE_EXPONENT));
  4172. this.prime1 = pvutils.getParametersValue(parameters, PRIME1, RSAPrivateKey.defaultValues(PRIME1));
  4173. this.prime2 = pvutils.getParametersValue(parameters, PRIME2, RSAPrivateKey.defaultValues(PRIME2));
  4174. this.exponent1 = pvutils.getParametersValue(parameters, EXPONENT1, RSAPrivateKey.defaultValues(EXPONENT1));
  4175. this.exponent2 = pvutils.getParametersValue(parameters, EXPONENT2, RSAPrivateKey.defaultValues(EXPONENT2));
  4176. this.coefficient = pvutils.getParametersValue(parameters, COEFFICIENT, RSAPrivateKey.defaultValues(COEFFICIENT));
  4177. if (OTHER_PRIME_INFOS in parameters) {
  4178. this.otherPrimeInfos = pvutils.getParametersValue(parameters, OTHER_PRIME_INFOS, RSAPrivateKey.defaultValues(OTHER_PRIME_INFOS));
  4179. }
  4180. if (parameters.json) {
  4181. this.fromJSON(parameters.json);
  4182. }
  4183. if (parameters.schema) {
  4184. this.fromSchema(parameters.schema);
  4185. }
  4186. }
  4187. static defaultValues(memberName) {
  4188. switch (memberName) {
  4189. case VERSION$k:
  4190. return 0;
  4191. case MODULUS:
  4192. return new asn1js.Integer();
  4193. case PUBLIC_EXPONENT:
  4194. return new asn1js.Integer();
  4195. case PRIVATE_EXPONENT:
  4196. return new asn1js.Integer();
  4197. case PRIME1:
  4198. return new asn1js.Integer();
  4199. case PRIME2:
  4200. return new asn1js.Integer();
  4201. case EXPONENT1:
  4202. return new asn1js.Integer();
  4203. case EXPONENT2:
  4204. return new asn1js.Integer();
  4205. case COEFFICIENT:
  4206. return new asn1js.Integer();
  4207. case OTHER_PRIME_INFOS:
  4208. return [];
  4209. default:
  4210. return super.defaultValues(memberName);
  4211. }
  4212. }
  4213. static schema(parameters = {}) {
  4214. const names = pvutils.getParametersValue(parameters, "names", {});
  4215. return (new asn1js.Sequence({
  4216. name: (names.blockName || EMPTY_STRING),
  4217. value: [
  4218. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  4219. new asn1js.Integer({ name: (names.modulus || EMPTY_STRING) }),
  4220. new asn1js.Integer({ name: (names.publicExponent || EMPTY_STRING) }),
  4221. new asn1js.Integer({ name: (names.privateExponent || EMPTY_STRING) }),
  4222. new asn1js.Integer({ name: (names.prime1 || EMPTY_STRING) }),
  4223. new asn1js.Integer({ name: (names.prime2 || EMPTY_STRING) }),
  4224. new asn1js.Integer({ name: (names.exponent1 || EMPTY_STRING) }),
  4225. new asn1js.Integer({ name: (names.exponent2 || EMPTY_STRING) }),
  4226. new asn1js.Integer({ name: (names.coefficient || EMPTY_STRING) }),
  4227. new asn1js.Sequence({
  4228. optional: true,
  4229. value: [
  4230. new asn1js.Repeated({
  4231. name: (names.otherPrimeInfosName || EMPTY_STRING),
  4232. value: OtherPrimeInfo.schema(names.otherPrimeInfo || {})
  4233. })
  4234. ]
  4235. })
  4236. ]
  4237. }));
  4238. }
  4239. fromSchema(schema) {
  4240. pvutils.clearProps(schema, CLEAR_PROPS$17);
  4241. const asn1 = asn1js.compareSchema(schema, schema, RSAPrivateKey.schema({
  4242. names: {
  4243. version: VERSION$k,
  4244. modulus: MODULUS,
  4245. publicExponent: PUBLIC_EXPONENT,
  4246. privateExponent: PRIVATE_EXPONENT,
  4247. prime1: PRIME1,
  4248. prime2: PRIME2,
  4249. exponent1: EXPONENT1,
  4250. exponent2: EXPONENT2,
  4251. coefficient: COEFFICIENT,
  4252. otherPrimeInfo: {
  4253. names: {
  4254. blockName: OTHER_PRIME_INFOS
  4255. }
  4256. }
  4257. }
  4258. }));
  4259. AsnError.assertSchema(asn1, this.className);
  4260. this.version = asn1.result.version.valueBlock.valueDec;
  4261. this.modulus = asn1.result.modulus.convertFromDER(256);
  4262. this.publicExponent = asn1.result.publicExponent;
  4263. this.privateExponent = asn1.result.privateExponent.convertFromDER(256);
  4264. this.prime1 = asn1.result.prime1.convertFromDER(128);
  4265. this.prime2 = asn1.result.prime2.convertFromDER(128);
  4266. this.exponent1 = asn1.result.exponent1.convertFromDER(128);
  4267. this.exponent2 = asn1.result.exponent2.convertFromDER(128);
  4268. this.coefficient = asn1.result.coefficient.convertFromDER(128);
  4269. if (OTHER_PRIME_INFOS in asn1.result)
  4270. this.otherPrimeInfos = Array.from(asn1.result.otherPrimeInfos, element => new OtherPrimeInfo({ schema: element }));
  4271. }
  4272. toSchema() {
  4273. const outputArray = [];
  4274. outputArray.push(new asn1js.Integer({ value: this.version }));
  4275. outputArray.push(this.modulus.convertToDER());
  4276. outputArray.push(this.publicExponent);
  4277. outputArray.push(this.privateExponent.convertToDER());
  4278. outputArray.push(this.prime1.convertToDER());
  4279. outputArray.push(this.prime2.convertToDER());
  4280. outputArray.push(this.exponent1.convertToDER());
  4281. outputArray.push(this.exponent2.convertToDER());
  4282. outputArray.push(this.coefficient.convertToDER());
  4283. if (this.otherPrimeInfos) {
  4284. outputArray.push(new asn1js.Sequence({
  4285. value: Array.from(this.otherPrimeInfos, o => o.toSchema())
  4286. }));
  4287. }
  4288. return (new asn1js.Sequence({
  4289. value: outputArray
  4290. }));
  4291. }
  4292. toJSON() {
  4293. const jwk = {
  4294. n: pvtsutils.Convert.ToBase64Url(this.modulus.valueBlock.valueHexView),
  4295. e: pvtsutils.Convert.ToBase64Url(this.publicExponent.valueBlock.valueHexView),
  4296. d: pvtsutils.Convert.ToBase64Url(this.privateExponent.valueBlock.valueHexView),
  4297. p: pvtsutils.Convert.ToBase64Url(this.prime1.valueBlock.valueHexView),
  4298. q: pvtsutils.Convert.ToBase64Url(this.prime2.valueBlock.valueHexView),
  4299. dp: pvtsutils.Convert.ToBase64Url(this.exponent1.valueBlock.valueHexView),
  4300. dq: pvtsutils.Convert.ToBase64Url(this.exponent2.valueBlock.valueHexView),
  4301. qi: pvtsutils.Convert.ToBase64Url(this.coefficient.valueBlock.valueHexView),
  4302. };
  4303. if (this.otherPrimeInfos) {
  4304. jwk.oth = Array.from(this.otherPrimeInfos, o => o.toJSON());
  4305. }
  4306. return jwk;
  4307. }
  4308. fromJSON(json) {
  4309. ParameterError.assert("json", json, "n", "e", "d", "p", "q", "dp", "dq", "qi");
  4310. this.modulus = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.n) });
  4311. this.publicExponent = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.e) });
  4312. this.privateExponent = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.d) });
  4313. this.prime1 = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.p) });
  4314. this.prime2 = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.q) });
  4315. this.exponent1 = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.dp) });
  4316. this.exponent2 = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.dq) });
  4317. this.coefficient = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.qi) });
  4318. if (json.oth) {
  4319. this.otherPrimeInfos = Array.from(json.oth, (element) => new OtherPrimeInfo({ json: element }));
  4320. }
  4321. }
  4322. }
  4323. RSAPrivateKey.CLASS_NAME = "RSAPrivateKey";
  4324. const VERSION$j = "version";
  4325. const PRIVATE_KEY_ALGORITHM = "privateKeyAlgorithm";
  4326. const PRIVATE_KEY = "privateKey";
  4327. const ATTRIBUTES$5 = "attributes";
  4328. const PARSED_KEY = "parsedKey";
  4329. const CLEAR_PROPS$16 = [
  4330. VERSION$j,
  4331. PRIVATE_KEY_ALGORITHM,
  4332. PRIVATE_KEY,
  4333. ATTRIBUTES$5
  4334. ];
  4335. class PrivateKeyInfo extends PkiObject {
  4336. constructor(parameters = {}) {
  4337. super();
  4338. this.version = pvutils.getParametersValue(parameters, VERSION$j, PrivateKeyInfo.defaultValues(VERSION$j));
  4339. this.privateKeyAlgorithm = pvutils.getParametersValue(parameters, PRIVATE_KEY_ALGORITHM, PrivateKeyInfo.defaultValues(PRIVATE_KEY_ALGORITHM));
  4340. this.privateKey = pvutils.getParametersValue(parameters, PRIVATE_KEY, PrivateKeyInfo.defaultValues(PRIVATE_KEY));
  4341. if (ATTRIBUTES$5 in parameters) {
  4342. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES$5, PrivateKeyInfo.defaultValues(ATTRIBUTES$5));
  4343. }
  4344. if (PARSED_KEY in parameters) {
  4345. this.parsedKey = pvutils.getParametersValue(parameters, PARSED_KEY, PrivateKeyInfo.defaultValues(PARSED_KEY));
  4346. }
  4347. if (parameters.json) {
  4348. this.fromJSON(parameters.json);
  4349. }
  4350. if (parameters.schema) {
  4351. this.fromSchema(parameters.schema);
  4352. }
  4353. }
  4354. static defaultValues(memberName) {
  4355. switch (memberName) {
  4356. case VERSION$j:
  4357. return 0;
  4358. case PRIVATE_KEY_ALGORITHM:
  4359. return new AlgorithmIdentifier();
  4360. case PRIVATE_KEY:
  4361. return new asn1js.OctetString();
  4362. case ATTRIBUTES$5:
  4363. return [];
  4364. case PARSED_KEY:
  4365. return {};
  4366. default:
  4367. return super.defaultValues(memberName);
  4368. }
  4369. }
  4370. static schema(parameters = {}) {
  4371. const names = pvutils.getParametersValue(parameters, "names", {});
  4372. return (new asn1js.Sequence({
  4373. name: (names.blockName || EMPTY_STRING),
  4374. value: [
  4375. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  4376. AlgorithmIdentifier.schema(names.privateKeyAlgorithm || {}),
  4377. new asn1js.OctetString({ name: (names.privateKey || EMPTY_STRING) }),
  4378. new asn1js.Constructed({
  4379. optional: true,
  4380. idBlock: {
  4381. tagClass: 3,
  4382. tagNumber: 0
  4383. },
  4384. value: [
  4385. new asn1js.Repeated({
  4386. name: (names.attributes || EMPTY_STRING),
  4387. value: Attribute.schema()
  4388. })
  4389. ]
  4390. })
  4391. ]
  4392. }));
  4393. }
  4394. fromSchema(schema) {
  4395. pvutils.clearProps(schema, CLEAR_PROPS$16);
  4396. const asn1 = asn1js.compareSchema(schema, schema, PrivateKeyInfo.schema({
  4397. names: {
  4398. version: VERSION$j,
  4399. privateKeyAlgorithm: {
  4400. names: {
  4401. blockName: PRIVATE_KEY_ALGORITHM
  4402. }
  4403. },
  4404. privateKey: PRIVATE_KEY,
  4405. attributes: ATTRIBUTES$5
  4406. }
  4407. }));
  4408. AsnError.assertSchema(asn1, this.className);
  4409. this.version = asn1.result.version.valueBlock.valueDec;
  4410. this.privateKeyAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.privateKeyAlgorithm });
  4411. this.privateKey = asn1.result.privateKey;
  4412. if (ATTRIBUTES$5 in asn1.result)
  4413. this.attributes = Array.from(asn1.result.attributes, element => new Attribute({ schema: element }));
  4414. switch (this.privateKeyAlgorithm.algorithmId) {
  4415. case "1.2.840.113549.1.1.1":
  4416. {
  4417. const privateKeyASN1 = asn1js.fromBER(this.privateKey.valueBlock.valueHexView);
  4418. if (privateKeyASN1.offset !== -1)
  4419. this.parsedKey = new RSAPrivateKey({ schema: privateKeyASN1.result });
  4420. }
  4421. break;
  4422. case "1.2.840.10045.2.1":
  4423. if ("algorithmParams" in this.privateKeyAlgorithm) {
  4424. if (this.privateKeyAlgorithm.algorithmParams instanceof asn1js.ObjectIdentifier) {
  4425. const privateKeyASN1 = asn1js.fromBER(this.privateKey.valueBlock.valueHexView);
  4426. if (privateKeyASN1.offset !== -1) {
  4427. this.parsedKey = new ECPrivateKey({
  4428. namedCurve: this.privateKeyAlgorithm.algorithmParams.valueBlock.toString(),
  4429. schema: privateKeyASN1.result
  4430. });
  4431. }
  4432. }
  4433. }
  4434. break;
  4435. }
  4436. }
  4437. toSchema() {
  4438. const outputArray = [
  4439. new asn1js.Integer({ value: this.version }),
  4440. this.privateKeyAlgorithm.toSchema(),
  4441. this.privateKey
  4442. ];
  4443. if (this.attributes) {
  4444. outputArray.push(new asn1js.Constructed({
  4445. optional: true,
  4446. idBlock: {
  4447. tagClass: 3,
  4448. tagNumber: 0
  4449. },
  4450. value: Array.from(this.attributes, o => o.toSchema())
  4451. }));
  4452. }
  4453. return (new asn1js.Sequence({
  4454. value: outputArray
  4455. }));
  4456. }
  4457. toJSON() {
  4458. if (!this.parsedKey) {
  4459. const object = {
  4460. version: this.version,
  4461. privateKeyAlgorithm: this.privateKeyAlgorithm.toJSON(),
  4462. privateKey: this.privateKey.toJSON(),
  4463. };
  4464. if (this.attributes) {
  4465. object.attributes = Array.from(this.attributes, o => o.toJSON());
  4466. }
  4467. return object;
  4468. }
  4469. const jwk = {};
  4470. switch (this.privateKeyAlgorithm.algorithmId) {
  4471. case "1.2.840.10045.2.1":
  4472. jwk.kty = "EC";
  4473. break;
  4474. case "1.2.840.113549.1.1.1":
  4475. jwk.kty = "RSA";
  4476. break;
  4477. }
  4478. const publicKeyJWK = this.parsedKey.toJSON();
  4479. Object.assign(jwk, publicKeyJWK);
  4480. return jwk;
  4481. }
  4482. fromJSON(json) {
  4483. if ("kty" in json) {
  4484. switch (json.kty.toUpperCase()) {
  4485. case "EC":
  4486. this.parsedKey = new ECPrivateKey({ json });
  4487. this.privateKeyAlgorithm = new AlgorithmIdentifier({
  4488. algorithmId: "1.2.840.10045.2.1",
  4489. algorithmParams: new asn1js.ObjectIdentifier({ value: this.parsedKey.namedCurve })
  4490. });
  4491. break;
  4492. case "RSA":
  4493. this.parsedKey = new RSAPrivateKey({ json });
  4494. this.privateKeyAlgorithm = new AlgorithmIdentifier({
  4495. algorithmId: "1.2.840.113549.1.1.1",
  4496. algorithmParams: new asn1js.Null()
  4497. });
  4498. break;
  4499. default:
  4500. throw new Error(`Invalid value for "kty" parameter: ${json.kty}`);
  4501. }
  4502. this.privateKey = new asn1js.OctetString({ valueHex: this.parsedKey.toSchema().toBER(false) });
  4503. }
  4504. }
  4505. }
  4506. PrivateKeyInfo.CLASS_NAME = "PrivateKeyInfo";
  4507. const CONTENT_TYPE$1 = "contentType";
  4508. const CONTENT_ENCRYPTION_ALGORITHM = "contentEncryptionAlgorithm";
  4509. const ENCRYPTED_CONTENT = "encryptedContent";
  4510. const CLEAR_PROPS$15 = [
  4511. CONTENT_TYPE$1,
  4512. CONTENT_ENCRYPTION_ALGORITHM,
  4513. ENCRYPTED_CONTENT,
  4514. ];
  4515. const PIECE_SIZE = 1024;
  4516. class EncryptedContentInfo extends PkiObject {
  4517. constructor(parameters = {}) {
  4518. super();
  4519. this.contentType = pvutils.getParametersValue(parameters, CONTENT_TYPE$1, EncryptedContentInfo.defaultValues(CONTENT_TYPE$1));
  4520. this.contentEncryptionAlgorithm = pvutils.getParametersValue(parameters, CONTENT_ENCRYPTION_ALGORITHM, EncryptedContentInfo.defaultValues(CONTENT_ENCRYPTION_ALGORITHM));
  4521. if (ENCRYPTED_CONTENT in parameters && parameters.encryptedContent) {
  4522. this.encryptedContent = parameters.encryptedContent;
  4523. if ((this.encryptedContent.idBlock.tagClass === 1) &&
  4524. (this.encryptedContent.idBlock.tagNumber === 4)) {
  4525. if (this.encryptedContent.idBlock.isConstructed === false && !parameters.disableSplit) {
  4526. const constrString = new asn1js.OctetString({
  4527. idBlock: { isConstructed: true },
  4528. isConstructed: true
  4529. });
  4530. let offset = 0;
  4531. const valueHex = this.encryptedContent.valueBlock.valueHexView.slice().buffer;
  4532. let length = valueHex.byteLength;
  4533. while (length > 0) {
  4534. const pieceView = new Uint8Array(valueHex, offset, ((offset + PIECE_SIZE) > valueHex.byteLength) ? (valueHex.byteLength - offset) : PIECE_SIZE);
  4535. const _array = new ArrayBuffer(pieceView.length);
  4536. const _view = new Uint8Array(_array);
  4537. for (let i = 0; i < _view.length; i++)
  4538. _view[i] = pieceView[i];
  4539. constrString.valueBlock.value.push(new asn1js.OctetString({ valueHex: _array }));
  4540. length -= pieceView.length;
  4541. offset += pieceView.length;
  4542. }
  4543. this.encryptedContent = constrString;
  4544. }
  4545. }
  4546. }
  4547. if (parameters.schema) {
  4548. this.fromSchema(parameters.schema);
  4549. }
  4550. }
  4551. static defaultValues(memberName) {
  4552. switch (memberName) {
  4553. case CONTENT_TYPE$1:
  4554. return EMPTY_STRING;
  4555. case CONTENT_ENCRYPTION_ALGORITHM:
  4556. return new AlgorithmIdentifier();
  4557. case ENCRYPTED_CONTENT:
  4558. return new asn1js.OctetString();
  4559. default:
  4560. return super.defaultValues(memberName);
  4561. }
  4562. }
  4563. static compareWithDefault(memberName, memberValue) {
  4564. switch (memberName) {
  4565. case CONTENT_TYPE$1:
  4566. return (memberValue === EMPTY_STRING);
  4567. case CONTENT_ENCRYPTION_ALGORITHM:
  4568. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  4569. case ENCRYPTED_CONTENT:
  4570. return (memberValue.isEqual(EncryptedContentInfo.defaultValues(ENCRYPTED_CONTENT)));
  4571. default:
  4572. return super.defaultValues(memberName);
  4573. }
  4574. }
  4575. static schema(parameters = {}) {
  4576. const names = pvutils.getParametersValue(parameters, "names", {});
  4577. return (new asn1js.Sequence({
  4578. name: (names.blockName || EMPTY_STRING),
  4579. value: [
  4580. new asn1js.ObjectIdentifier({ name: (names.contentType || EMPTY_STRING) }),
  4581. AlgorithmIdentifier.schema(names.contentEncryptionAlgorithm || {}),
  4582. new asn1js.Choice({
  4583. value: [
  4584. new asn1js.Constructed({
  4585. name: (names.encryptedContent || EMPTY_STRING),
  4586. idBlock: {
  4587. tagClass: 3,
  4588. tagNumber: 0
  4589. },
  4590. value: [
  4591. new asn1js.Repeated({
  4592. value: new asn1js.OctetString()
  4593. })
  4594. ]
  4595. }),
  4596. new asn1js.Primitive({
  4597. name: (names.encryptedContent || EMPTY_STRING),
  4598. idBlock: {
  4599. tagClass: 3,
  4600. tagNumber: 0
  4601. }
  4602. })
  4603. ]
  4604. })
  4605. ]
  4606. }));
  4607. }
  4608. fromSchema(schema) {
  4609. pvutils.clearProps(schema, CLEAR_PROPS$15);
  4610. const asn1 = asn1js.compareSchema(schema, schema, EncryptedContentInfo.schema({
  4611. names: {
  4612. contentType: CONTENT_TYPE$1,
  4613. contentEncryptionAlgorithm: {
  4614. names: {
  4615. blockName: CONTENT_ENCRYPTION_ALGORITHM
  4616. }
  4617. },
  4618. encryptedContent: ENCRYPTED_CONTENT
  4619. }
  4620. }));
  4621. AsnError.assertSchema(asn1, this.className);
  4622. this.contentType = asn1.result.contentType.valueBlock.toString();
  4623. this.contentEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.contentEncryptionAlgorithm });
  4624. if (ENCRYPTED_CONTENT in asn1.result) {
  4625. this.encryptedContent = asn1.result.encryptedContent;
  4626. this.encryptedContent.idBlock.tagClass = 1;
  4627. this.encryptedContent.idBlock.tagNumber = 4;
  4628. }
  4629. }
  4630. toSchema() {
  4631. const sequenceLengthBlock = {
  4632. isIndefiniteForm: false
  4633. };
  4634. const outputArray = [];
  4635. outputArray.push(new asn1js.ObjectIdentifier({ value: this.contentType }));
  4636. outputArray.push(this.contentEncryptionAlgorithm.toSchema());
  4637. if (this.encryptedContent) {
  4638. sequenceLengthBlock.isIndefiniteForm = this.encryptedContent.idBlock.isConstructed;
  4639. const encryptedValue = this.encryptedContent;
  4640. encryptedValue.idBlock.tagClass = 3;
  4641. encryptedValue.idBlock.tagNumber = 0;
  4642. encryptedValue.lenBlock.isIndefiniteForm = this.encryptedContent.idBlock.isConstructed;
  4643. outputArray.push(encryptedValue);
  4644. }
  4645. return (new asn1js.Sequence({
  4646. lenBlock: sequenceLengthBlock,
  4647. value: outputArray
  4648. }));
  4649. }
  4650. toJSON() {
  4651. const res = {
  4652. contentType: this.contentType,
  4653. contentEncryptionAlgorithm: this.contentEncryptionAlgorithm.toJSON()
  4654. };
  4655. if (this.encryptedContent) {
  4656. res.encryptedContent = this.encryptedContent.toJSON();
  4657. }
  4658. return res;
  4659. }
  4660. getEncryptedContent() {
  4661. if (!this.encryptedContent) {
  4662. throw new Error("Parameter 'encryptedContent' is undefined");
  4663. }
  4664. return asn1js.OctetString.prototype.getValue.call(this.encryptedContent);
  4665. }
  4666. }
  4667. EncryptedContentInfo.CLASS_NAME = "EncryptedContentInfo";
  4668. const HASH_ALGORITHM$4 = "hashAlgorithm";
  4669. const MASK_GEN_ALGORITHM$1 = "maskGenAlgorithm";
  4670. const SALT_LENGTH = "saltLength";
  4671. const TRAILER_FIELD = "trailerField";
  4672. const CLEAR_PROPS$14 = [
  4673. HASH_ALGORITHM$4,
  4674. MASK_GEN_ALGORITHM$1,
  4675. SALT_LENGTH,
  4676. TRAILER_FIELD
  4677. ];
  4678. class RSASSAPSSParams extends PkiObject {
  4679. constructor(parameters = {}) {
  4680. super();
  4681. this.hashAlgorithm = pvutils.getParametersValue(parameters, HASH_ALGORITHM$4, RSASSAPSSParams.defaultValues(HASH_ALGORITHM$4));
  4682. this.maskGenAlgorithm = pvutils.getParametersValue(parameters, MASK_GEN_ALGORITHM$1, RSASSAPSSParams.defaultValues(MASK_GEN_ALGORITHM$1));
  4683. this.saltLength = pvutils.getParametersValue(parameters, SALT_LENGTH, RSASSAPSSParams.defaultValues(SALT_LENGTH));
  4684. this.trailerField = pvutils.getParametersValue(parameters, TRAILER_FIELD, RSASSAPSSParams.defaultValues(TRAILER_FIELD));
  4685. if (parameters.schema) {
  4686. this.fromSchema(parameters.schema);
  4687. }
  4688. }
  4689. static defaultValues(memberName) {
  4690. switch (memberName) {
  4691. case HASH_ALGORITHM$4:
  4692. return new AlgorithmIdentifier({
  4693. algorithmId: "1.3.14.3.2.26",
  4694. algorithmParams: new asn1js.Null()
  4695. });
  4696. case MASK_GEN_ALGORITHM$1:
  4697. return new AlgorithmIdentifier({
  4698. algorithmId: "1.2.840.113549.1.1.8",
  4699. algorithmParams: (new AlgorithmIdentifier({
  4700. algorithmId: "1.3.14.3.2.26",
  4701. algorithmParams: new asn1js.Null()
  4702. })).toSchema()
  4703. });
  4704. case SALT_LENGTH:
  4705. return 20;
  4706. case TRAILER_FIELD:
  4707. return 1;
  4708. default:
  4709. return super.defaultValues(memberName);
  4710. }
  4711. }
  4712. static schema(parameters = {}) {
  4713. const names = pvutils.getParametersValue(parameters, "names", {});
  4714. return (new asn1js.Sequence({
  4715. name: (names.blockName || EMPTY_STRING),
  4716. value: [
  4717. new asn1js.Constructed({
  4718. idBlock: {
  4719. tagClass: 3,
  4720. tagNumber: 0
  4721. },
  4722. optional: true,
  4723. value: [AlgorithmIdentifier.schema(names.hashAlgorithm || {})]
  4724. }),
  4725. new asn1js.Constructed({
  4726. idBlock: {
  4727. tagClass: 3,
  4728. tagNumber: 1
  4729. },
  4730. optional: true,
  4731. value: [AlgorithmIdentifier.schema(names.maskGenAlgorithm || {})]
  4732. }),
  4733. new asn1js.Constructed({
  4734. idBlock: {
  4735. tagClass: 3,
  4736. tagNumber: 2
  4737. },
  4738. optional: true,
  4739. value: [new asn1js.Integer({ name: (names.saltLength || EMPTY_STRING) })]
  4740. }),
  4741. new asn1js.Constructed({
  4742. idBlock: {
  4743. tagClass: 3,
  4744. tagNumber: 3
  4745. },
  4746. optional: true,
  4747. value: [new asn1js.Integer({ name: (names.trailerField || EMPTY_STRING) })]
  4748. })
  4749. ]
  4750. }));
  4751. }
  4752. fromSchema(schema) {
  4753. pvutils.clearProps(schema, CLEAR_PROPS$14);
  4754. const asn1 = asn1js.compareSchema(schema, schema, RSASSAPSSParams.schema({
  4755. names: {
  4756. hashAlgorithm: {
  4757. names: {
  4758. blockName: HASH_ALGORITHM$4
  4759. }
  4760. },
  4761. maskGenAlgorithm: {
  4762. names: {
  4763. blockName: MASK_GEN_ALGORITHM$1
  4764. }
  4765. },
  4766. saltLength: SALT_LENGTH,
  4767. trailerField: TRAILER_FIELD
  4768. }
  4769. }));
  4770. AsnError.assertSchema(asn1, this.className);
  4771. if (HASH_ALGORITHM$4 in asn1.result)
  4772. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  4773. if (MASK_GEN_ALGORITHM$1 in asn1.result)
  4774. this.maskGenAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.maskGenAlgorithm });
  4775. if (SALT_LENGTH in asn1.result)
  4776. this.saltLength = asn1.result.saltLength.valueBlock.valueDec;
  4777. if (TRAILER_FIELD in asn1.result)
  4778. this.trailerField = asn1.result.trailerField.valueBlock.valueDec;
  4779. }
  4780. toSchema() {
  4781. const outputArray = [];
  4782. if (!this.hashAlgorithm.isEqual(RSASSAPSSParams.defaultValues(HASH_ALGORITHM$4))) {
  4783. outputArray.push(new asn1js.Constructed({
  4784. idBlock: {
  4785. tagClass: 3,
  4786. tagNumber: 0
  4787. },
  4788. value: [this.hashAlgorithm.toSchema()]
  4789. }));
  4790. }
  4791. if (!this.maskGenAlgorithm.isEqual(RSASSAPSSParams.defaultValues(MASK_GEN_ALGORITHM$1))) {
  4792. outputArray.push(new asn1js.Constructed({
  4793. idBlock: {
  4794. tagClass: 3,
  4795. tagNumber: 1
  4796. },
  4797. value: [this.maskGenAlgorithm.toSchema()]
  4798. }));
  4799. }
  4800. if (this.saltLength !== RSASSAPSSParams.defaultValues(SALT_LENGTH)) {
  4801. outputArray.push(new asn1js.Constructed({
  4802. idBlock: {
  4803. tagClass: 3,
  4804. tagNumber: 2
  4805. },
  4806. value: [new asn1js.Integer({ value: this.saltLength })]
  4807. }));
  4808. }
  4809. if (this.trailerField !== RSASSAPSSParams.defaultValues(TRAILER_FIELD)) {
  4810. outputArray.push(new asn1js.Constructed({
  4811. idBlock: {
  4812. tagClass: 3,
  4813. tagNumber: 3
  4814. },
  4815. value: [new asn1js.Integer({ value: this.trailerField })]
  4816. }));
  4817. }
  4818. return (new asn1js.Sequence({
  4819. value: outputArray
  4820. }));
  4821. }
  4822. toJSON() {
  4823. const res = {};
  4824. if (!this.hashAlgorithm.isEqual(RSASSAPSSParams.defaultValues(HASH_ALGORITHM$4))) {
  4825. res.hashAlgorithm = this.hashAlgorithm.toJSON();
  4826. }
  4827. if (!this.maskGenAlgorithm.isEqual(RSASSAPSSParams.defaultValues(MASK_GEN_ALGORITHM$1))) {
  4828. res.maskGenAlgorithm = this.maskGenAlgorithm.toJSON();
  4829. }
  4830. if (this.saltLength !== RSASSAPSSParams.defaultValues(SALT_LENGTH)) {
  4831. res.saltLength = this.saltLength;
  4832. }
  4833. if (this.trailerField !== RSASSAPSSParams.defaultValues(TRAILER_FIELD)) {
  4834. res.trailerField = this.trailerField;
  4835. }
  4836. return res;
  4837. }
  4838. }
  4839. RSASSAPSSParams.CLASS_NAME = "RSASSAPSSParams";
  4840. const SALT = "salt";
  4841. const ITERATION_COUNT = "iterationCount";
  4842. const KEY_LENGTH = "keyLength";
  4843. const PRF = "prf";
  4844. const CLEAR_PROPS$13 = [
  4845. SALT,
  4846. ITERATION_COUNT,
  4847. KEY_LENGTH,
  4848. PRF
  4849. ];
  4850. class PBKDF2Params extends PkiObject {
  4851. constructor(parameters = {}) {
  4852. super();
  4853. this.salt = pvutils.getParametersValue(parameters, SALT, PBKDF2Params.defaultValues(SALT));
  4854. this.iterationCount = pvutils.getParametersValue(parameters, ITERATION_COUNT, PBKDF2Params.defaultValues(ITERATION_COUNT));
  4855. if (KEY_LENGTH in parameters) {
  4856. this.keyLength = pvutils.getParametersValue(parameters, KEY_LENGTH, PBKDF2Params.defaultValues(KEY_LENGTH));
  4857. }
  4858. if (PRF in parameters) {
  4859. this.prf = pvutils.getParametersValue(parameters, PRF, PBKDF2Params.defaultValues(PRF));
  4860. }
  4861. if (parameters.schema) {
  4862. this.fromSchema(parameters.schema);
  4863. }
  4864. }
  4865. static defaultValues(memberName) {
  4866. switch (memberName) {
  4867. case SALT:
  4868. return {};
  4869. case ITERATION_COUNT:
  4870. return (-1);
  4871. case KEY_LENGTH:
  4872. return 0;
  4873. case PRF:
  4874. return new AlgorithmIdentifier({
  4875. algorithmId: "1.3.14.3.2.26",
  4876. algorithmParams: new asn1js.Null()
  4877. });
  4878. default:
  4879. return super.defaultValues(memberName);
  4880. }
  4881. }
  4882. static schema(parameters = {}) {
  4883. const names = pvutils.getParametersValue(parameters, "names", {});
  4884. return (new asn1js.Sequence({
  4885. name: (names.blockName || EMPTY_STRING),
  4886. value: [
  4887. new asn1js.Choice({
  4888. value: [
  4889. new asn1js.OctetString({ name: (names.saltPrimitive || EMPTY_STRING) }),
  4890. AlgorithmIdentifier.schema(names.saltConstructed || {})
  4891. ]
  4892. }),
  4893. new asn1js.Integer({ name: (names.iterationCount || EMPTY_STRING) }),
  4894. new asn1js.Integer({
  4895. name: (names.keyLength || EMPTY_STRING),
  4896. optional: true
  4897. }),
  4898. AlgorithmIdentifier.schema(names.prf || {
  4899. names: {
  4900. optional: true
  4901. }
  4902. })
  4903. ]
  4904. }));
  4905. }
  4906. fromSchema(schema) {
  4907. pvutils.clearProps(schema, CLEAR_PROPS$13);
  4908. const asn1 = asn1js.compareSchema(schema, schema, PBKDF2Params.schema({
  4909. names: {
  4910. saltPrimitive: SALT,
  4911. saltConstructed: {
  4912. names: {
  4913. blockName: SALT
  4914. }
  4915. },
  4916. iterationCount: ITERATION_COUNT,
  4917. keyLength: KEY_LENGTH,
  4918. prf: {
  4919. names: {
  4920. blockName: PRF,
  4921. optional: true
  4922. }
  4923. }
  4924. }
  4925. }));
  4926. AsnError.assertSchema(asn1, this.className);
  4927. this.salt = asn1.result.salt;
  4928. this.iterationCount = asn1.result.iterationCount.valueBlock.valueDec;
  4929. if (KEY_LENGTH in asn1.result)
  4930. this.keyLength = asn1.result.keyLength.valueBlock.valueDec;
  4931. if (PRF in asn1.result)
  4932. this.prf = new AlgorithmIdentifier({ schema: asn1.result.prf });
  4933. }
  4934. toSchema() {
  4935. const outputArray = [];
  4936. outputArray.push(this.salt);
  4937. outputArray.push(new asn1js.Integer({ value: this.iterationCount }));
  4938. if (KEY_LENGTH in this) {
  4939. if (PBKDF2Params.defaultValues(KEY_LENGTH) !== this.keyLength)
  4940. outputArray.push(new asn1js.Integer({ value: this.keyLength }));
  4941. }
  4942. if (this.prf) {
  4943. if (PBKDF2Params.defaultValues(PRF).isEqual(this.prf) === false)
  4944. outputArray.push(this.prf.toSchema());
  4945. }
  4946. return (new asn1js.Sequence({
  4947. value: outputArray
  4948. }));
  4949. }
  4950. toJSON() {
  4951. const res = {
  4952. salt: this.salt.toJSON(),
  4953. iterationCount: this.iterationCount
  4954. };
  4955. if (KEY_LENGTH in this) {
  4956. if (PBKDF2Params.defaultValues(KEY_LENGTH) !== this.keyLength)
  4957. res.keyLength = this.keyLength;
  4958. }
  4959. if (this.prf) {
  4960. if (PBKDF2Params.defaultValues(PRF).isEqual(this.prf) === false)
  4961. res.prf = this.prf.toJSON();
  4962. }
  4963. return res;
  4964. }
  4965. }
  4966. PBKDF2Params.CLASS_NAME = "PBKDF2Params";
  4967. const KEY_DERIVATION_FUNC = "keyDerivationFunc";
  4968. const ENCRYPTION_SCHEME = "encryptionScheme";
  4969. const CLEAR_PROPS$12 = [
  4970. KEY_DERIVATION_FUNC,
  4971. ENCRYPTION_SCHEME
  4972. ];
  4973. class PBES2Params extends PkiObject {
  4974. constructor(parameters = {}) {
  4975. super();
  4976. this.keyDerivationFunc = pvutils.getParametersValue(parameters, KEY_DERIVATION_FUNC, PBES2Params.defaultValues(KEY_DERIVATION_FUNC));
  4977. this.encryptionScheme = pvutils.getParametersValue(parameters, ENCRYPTION_SCHEME, PBES2Params.defaultValues(ENCRYPTION_SCHEME));
  4978. if (parameters.schema) {
  4979. this.fromSchema(parameters.schema);
  4980. }
  4981. }
  4982. static defaultValues(memberName) {
  4983. switch (memberName) {
  4984. case KEY_DERIVATION_FUNC:
  4985. return new AlgorithmIdentifier();
  4986. case ENCRYPTION_SCHEME:
  4987. return new AlgorithmIdentifier();
  4988. default:
  4989. return super.defaultValues(memberName);
  4990. }
  4991. }
  4992. static schema(parameters = {}) {
  4993. const names = pvutils.getParametersValue(parameters, "names", {});
  4994. return (new asn1js.Sequence({
  4995. name: (names.blockName || EMPTY_STRING),
  4996. value: [
  4997. AlgorithmIdentifier.schema(names.keyDerivationFunc || {}),
  4998. AlgorithmIdentifier.schema(names.encryptionScheme || {})
  4999. ]
  5000. }));
  5001. }
  5002. fromSchema(schema) {
  5003. pvutils.clearProps(schema, CLEAR_PROPS$12);
  5004. const asn1 = asn1js.compareSchema(schema, schema, PBES2Params.schema({
  5005. names: {
  5006. keyDerivationFunc: {
  5007. names: {
  5008. blockName: KEY_DERIVATION_FUNC
  5009. }
  5010. },
  5011. encryptionScheme: {
  5012. names: {
  5013. blockName: ENCRYPTION_SCHEME
  5014. }
  5015. }
  5016. }
  5017. }));
  5018. AsnError.assertSchema(asn1, this.className);
  5019. this.keyDerivationFunc = new AlgorithmIdentifier({ schema: asn1.result.keyDerivationFunc });
  5020. this.encryptionScheme = new AlgorithmIdentifier({ schema: asn1.result.encryptionScheme });
  5021. }
  5022. toSchema() {
  5023. return (new asn1js.Sequence({
  5024. value: [
  5025. this.keyDerivationFunc.toSchema(),
  5026. this.encryptionScheme.toSchema()
  5027. ]
  5028. }));
  5029. }
  5030. toJSON() {
  5031. return {
  5032. keyDerivationFunc: this.keyDerivationFunc.toJSON(),
  5033. encryptionScheme: this.encryptionScheme.toJSON()
  5034. };
  5035. }
  5036. }
  5037. PBES2Params.CLASS_NAME = "PBES2Params";
  5038. class AbstractCryptoEngine {
  5039. constructor(parameters) {
  5040. this.crypto = parameters.crypto;
  5041. this.subtle = "webkitSubtle" in parameters.crypto
  5042. ? parameters.crypto.webkitSubtle
  5043. : parameters.crypto.subtle;
  5044. this.name = pvutils.getParametersValue(parameters, "name", EMPTY_STRING);
  5045. }
  5046. async encrypt(...args) {
  5047. return this.subtle.encrypt(...args);
  5048. }
  5049. async decrypt(...args) {
  5050. return this.subtle.decrypt(...args);
  5051. }
  5052. sign(...args) {
  5053. return this.subtle.sign(...args);
  5054. }
  5055. async verify(...args) {
  5056. return this.subtle.verify(...args);
  5057. }
  5058. async digest(...args) {
  5059. return this.subtle.digest(...args);
  5060. }
  5061. async generateKey(...args) {
  5062. return this.subtle.generateKey(...args);
  5063. }
  5064. async deriveKey(...args) {
  5065. return this.subtle.deriveKey(...args);
  5066. }
  5067. async deriveBits(...args) {
  5068. return this.subtle.deriveBits(...args);
  5069. }
  5070. async wrapKey(...args) {
  5071. return this.subtle.wrapKey(...args);
  5072. }
  5073. async unwrapKey(...args) {
  5074. return this.subtle.unwrapKey(...args);
  5075. }
  5076. exportKey(...args) {
  5077. return this.subtle.exportKey(...args);
  5078. }
  5079. importKey(...args) {
  5080. return this.subtle.importKey(...args);
  5081. }
  5082. getRandomValues(array) {
  5083. if (array === null) {
  5084. throw new Error("Argument \"array\" must not be null");
  5085. }
  5086. return this.crypto.getRandomValues(array);
  5087. }
  5088. }
  5089. async function makePKCS12B2Key(hashAlgorithm, keyLength, password, salt, iterationCount) {
  5090. let u;
  5091. let v;
  5092. let md;
  5093. switch (hashAlgorithm.toUpperCase()) {
  5094. case "SHA-1":
  5095. u = 20;
  5096. v = 64;
  5097. md = sha1;
  5098. break;
  5099. case "SHA-256":
  5100. u = 32;
  5101. v = 64;
  5102. md = sha256;
  5103. break;
  5104. case "SHA-384":
  5105. u = 48;
  5106. v = 128;
  5107. md = sha384;
  5108. break;
  5109. case "SHA-512":
  5110. u = 64;
  5111. v = 128;
  5112. md = sha512;
  5113. break;
  5114. default:
  5115. throw new Error("Unsupported hashing algorithm");
  5116. }
  5117. const originalPassword = new Uint8Array(password);
  5118. let decodedPassword = new TextDecoder().decode(password);
  5119. const encodedPassword = new TextEncoder().encode(decodedPassword);
  5120. if (encodedPassword.some((byte, i) => byte !== originalPassword[i])) {
  5121. decodedPassword = String.fromCharCode(...originalPassword);
  5122. }
  5123. const passwordTransformed = new Uint8Array(decodedPassword.length * 2 + 2);
  5124. const passwordView = new DataView(passwordTransformed.buffer);
  5125. for (let i = 0; i < decodedPassword.length; i++) {
  5126. passwordView.setUint16(i * 2, decodedPassword.charCodeAt(i), false);
  5127. }
  5128. passwordView.setUint16(decodedPassword.length * 2, 0, false);
  5129. const D = new Uint8Array(v).fill(3);
  5130. const saltView = new Uint8Array(salt);
  5131. const S = new Uint8Array(v * Math.ceil(saltView.length / v)).map((_, i) => saltView[i % saltView.length]);
  5132. const P = new Uint8Array(v * Math.ceil(passwordTransformed.length / v)).map((_, i) => passwordTransformed[i % passwordTransformed.length]);
  5133. let I = new Uint8Array(S.length + P.length);
  5134. I.set(S);
  5135. I.set(P, S.length);
  5136. const c = Math.ceil((keyLength >> 3) / u);
  5137. const result = [];
  5138. for (let i = 0; i < c; i++) {
  5139. let A = new Uint8Array(D.length + I.length);
  5140. A.set(D);
  5141. A.set(I, D.length);
  5142. for (let j = 0; j < iterationCount; j++) {
  5143. A = md(A);
  5144. }
  5145. const B = new Uint8Array(v).map((_, i) => A[i % A.length]);
  5146. const k = Math.ceil(saltView.length / v) + Math.ceil(passwordTransformed.length / v);
  5147. const iRound = [];
  5148. for (let j = 0; j < k; j++) {
  5149. const chunk = Array.from(I.slice(j * v, (j + 1) * v));
  5150. let x = 0x1ff;
  5151. for (let l = B.length - 1; l >= 0; l--) {
  5152. x >>= 8;
  5153. x += B[l] + (chunk[l] || 0);
  5154. chunk[l] = x & 0xff;
  5155. }
  5156. iRound.push(...chunk);
  5157. }
  5158. I = new Uint8Array(iRound);
  5159. result.push(...A);
  5160. }
  5161. return new Uint8Array(result.slice(0, keyLength >> 3)).buffer;
  5162. }
  5163. function prepareAlgorithm(data) {
  5164. const res = typeof data === "string"
  5165. ? { name: data }
  5166. : data;
  5167. if ("hash" in res) {
  5168. return {
  5169. ...res,
  5170. hash: prepareAlgorithm(res.hash)
  5171. };
  5172. }
  5173. return res;
  5174. }
  5175. class CryptoEngine extends AbstractCryptoEngine {
  5176. async importKey(format, keyData, algorithm, extractable, keyUsages) {
  5177. var _a, _b, _c, _d, _e, _f;
  5178. let jwk = {};
  5179. const alg = prepareAlgorithm(algorithm);
  5180. switch (format.toLowerCase()) {
  5181. case "raw":
  5182. return this.subtle.importKey("raw", keyData, algorithm, extractable, keyUsages);
  5183. case "spki":
  5184. {
  5185. const asn1 = asn1js.fromBER(pvtsutils.BufferSourceConverter.toArrayBuffer(keyData));
  5186. AsnError.assert(asn1, "keyData");
  5187. const publicKeyInfo = new PublicKeyInfo();
  5188. try {
  5189. publicKeyInfo.fromSchema(asn1.result);
  5190. }
  5191. catch {
  5192. throw new ArgumentError("Incorrect keyData");
  5193. }
  5194. switch (alg.name.toUpperCase()) {
  5195. case "RSA-PSS":
  5196. {
  5197. keyUsages = ["verify"];
  5198. jwk.kty = "RSA";
  5199. jwk.ext = extractable;
  5200. jwk.key_ops = keyUsages;
  5201. if (!["1.2.840.113549.1.1.1", "1.2.840.113549.1.1.10"].includes(publicKeyInfo.algorithm.algorithmId))
  5202. throw new Error(`Incorrect public key algorithm: ${publicKeyInfo.algorithm.algorithmId}`);
  5203. if (!alg.hash) {
  5204. throw new ParameterError("hash", "algorithm.hash", "Incorrect hash algorithm: Hash algorithm is missed");
  5205. }
  5206. switch (alg.hash.name.toUpperCase()) {
  5207. case "SHA-1":
  5208. jwk.alg = "PS1";
  5209. break;
  5210. case "SHA-256":
  5211. jwk.alg = "PS256";
  5212. break;
  5213. case "SHA-384":
  5214. jwk.alg = "PS384";
  5215. break;
  5216. case "SHA-512":
  5217. jwk.alg = "PS512";
  5218. break;
  5219. default:
  5220. throw new Error(`Incorrect hash algorithm: ${alg.hash.name.toUpperCase()}`);
  5221. }
  5222. const rsaPssPublicKeyJSON = publicKeyInfo.toJSON();
  5223. Object.assign(jwk, rsaPssPublicKeyJSON);
  5224. }
  5225. break;
  5226. case "RSASSA-PKCS1-V1_5":
  5227. {
  5228. keyUsages = ["verify"];
  5229. jwk.kty = "RSA";
  5230. jwk.ext = extractable;
  5231. jwk.key_ops = keyUsages;
  5232. if (publicKeyInfo.algorithm.algorithmId !== "1.2.840.113549.1.1.1")
  5233. throw new Error(`Incorrect public key algorithm: ${publicKeyInfo.algorithm.algorithmId}`);
  5234. if (!alg.hash) {
  5235. throw new ParameterError("hash", "algorithm.hash", "Incorrect hash algorithm: Hash algorithm is missed");
  5236. }
  5237. switch (alg.hash.name.toUpperCase()) {
  5238. case "SHA-1":
  5239. jwk.alg = "RS1";
  5240. break;
  5241. case "SHA-256":
  5242. jwk.alg = "RS256";
  5243. break;
  5244. case "SHA-384":
  5245. jwk.alg = "RS384";
  5246. break;
  5247. case "SHA-512":
  5248. jwk.alg = "RS512";
  5249. break;
  5250. default:
  5251. throw new Error(`Incorrect hash algorithm: ${alg.hash.name.toUpperCase()}`);
  5252. }
  5253. const rsaPublicKeyJSON = publicKeyInfo.toJSON();
  5254. Object.assign(jwk, rsaPublicKeyJSON);
  5255. }
  5256. break;
  5257. case "ECDSA":
  5258. keyUsages = ["verify"];
  5259. case "ECDH":
  5260. {
  5261. jwk = {
  5262. kty: "EC",
  5263. ext: extractable,
  5264. key_ops: keyUsages
  5265. };
  5266. if (publicKeyInfo.algorithm.algorithmId !== "1.2.840.10045.2.1") {
  5267. throw new Error(`Incorrect public key algorithm: ${publicKeyInfo.algorithm.algorithmId}`);
  5268. }
  5269. const publicKeyJSON = publicKeyInfo.toJSON();
  5270. Object.assign(jwk, publicKeyJSON);
  5271. }
  5272. break;
  5273. case "RSA-OAEP":
  5274. {
  5275. jwk.kty = "RSA";
  5276. jwk.ext = extractable;
  5277. jwk.key_ops = keyUsages;
  5278. if (this.name.toLowerCase() === "safari")
  5279. jwk.alg = "RSA-OAEP";
  5280. else {
  5281. if (!alg.hash) {
  5282. throw new ParameterError("hash", "algorithm.hash", "Incorrect hash algorithm: Hash algorithm is missed");
  5283. }
  5284. switch (alg.hash.name.toUpperCase()) {
  5285. case "SHA-1":
  5286. jwk.alg = "RSA-OAEP";
  5287. break;
  5288. case "SHA-256":
  5289. jwk.alg = "RSA-OAEP-256";
  5290. break;
  5291. case "SHA-384":
  5292. jwk.alg = "RSA-OAEP-384";
  5293. break;
  5294. case "SHA-512":
  5295. jwk.alg = "RSA-OAEP-512";
  5296. break;
  5297. default:
  5298. throw new Error(`Incorrect hash algorithm: ${alg.hash.name.toUpperCase()}`);
  5299. }
  5300. }
  5301. const publicKeyJSON = publicKeyInfo.toJSON();
  5302. Object.assign(jwk, publicKeyJSON);
  5303. }
  5304. break;
  5305. case "RSAES-PKCS1-V1_5":
  5306. {
  5307. jwk.kty = "RSA";
  5308. jwk.ext = extractable;
  5309. jwk.key_ops = keyUsages;
  5310. jwk.alg = "PS1";
  5311. const publicKeyJSON = publicKeyInfo.toJSON();
  5312. Object.assign(jwk, publicKeyJSON);
  5313. }
  5314. break;
  5315. default:
  5316. throw new Error(`Incorrect algorithm name: ${alg.name.toUpperCase()}`);
  5317. }
  5318. }
  5319. break;
  5320. case "pkcs8":
  5321. {
  5322. const privateKeyInfo = new PrivateKeyInfo();
  5323. const asn1 = asn1js.fromBER(pvtsutils.BufferSourceConverter.toArrayBuffer(keyData));
  5324. AsnError.assert(asn1, "keyData");
  5325. try {
  5326. privateKeyInfo.fromSchema(asn1.result);
  5327. }
  5328. catch {
  5329. throw new Error("Incorrect keyData");
  5330. }
  5331. if (!privateKeyInfo.parsedKey)
  5332. throw new Error("Incorrect keyData");
  5333. switch (alg.name.toUpperCase()) {
  5334. case "RSA-PSS":
  5335. {
  5336. switch ((_a = alg.hash) === null || _a === void 0 ? void 0 : _a.name.toUpperCase()) {
  5337. case "SHA-1":
  5338. jwk.alg = "PS1";
  5339. break;
  5340. case "SHA-256":
  5341. jwk.alg = "PS256";
  5342. break;
  5343. case "SHA-384":
  5344. jwk.alg = "PS384";
  5345. break;
  5346. case "SHA-512":
  5347. jwk.alg = "PS512";
  5348. break;
  5349. default:
  5350. throw new Error(`Incorrect hash algorithm: ${(_b = alg.hash) === null || _b === void 0 ? void 0 : _b.name.toUpperCase()}`);
  5351. }
  5352. }
  5353. case "RSASSA-PKCS1-V1_5":
  5354. {
  5355. keyUsages = ["sign"];
  5356. jwk.kty = "RSA";
  5357. jwk.ext = extractable;
  5358. jwk.key_ops = keyUsages;
  5359. if (privateKeyInfo.privateKeyAlgorithm.algorithmId !== "1.2.840.113549.1.1.1")
  5360. throw new Error(`Incorrect private key algorithm: ${privateKeyInfo.privateKeyAlgorithm.algorithmId}`);
  5361. if (("alg" in jwk) === false) {
  5362. switch ((_c = alg.hash) === null || _c === void 0 ? void 0 : _c.name.toUpperCase()) {
  5363. case "SHA-1":
  5364. jwk.alg = "RS1";
  5365. break;
  5366. case "SHA-256":
  5367. jwk.alg = "RS256";
  5368. break;
  5369. case "SHA-384":
  5370. jwk.alg = "RS384";
  5371. break;
  5372. case "SHA-512":
  5373. jwk.alg = "RS512";
  5374. break;
  5375. default:
  5376. throw new Error(`Incorrect hash algorithm: ${(_d = alg.hash) === null || _d === void 0 ? void 0 : _d.name.toUpperCase()}`);
  5377. }
  5378. }
  5379. const privateKeyJSON = privateKeyInfo.toJSON();
  5380. Object.assign(jwk, privateKeyJSON);
  5381. }
  5382. break;
  5383. case "ECDSA":
  5384. keyUsages = ["sign"];
  5385. case "ECDH":
  5386. {
  5387. jwk = {
  5388. kty: "EC",
  5389. ext: extractable,
  5390. key_ops: keyUsages
  5391. };
  5392. if (privateKeyInfo.privateKeyAlgorithm.algorithmId !== "1.2.840.10045.2.1")
  5393. throw new Error(`Incorrect algorithm: ${privateKeyInfo.privateKeyAlgorithm.algorithmId}`);
  5394. const privateKeyJSON = privateKeyInfo.toJSON();
  5395. Object.assign(jwk, privateKeyJSON);
  5396. }
  5397. break;
  5398. case "RSA-OAEP":
  5399. {
  5400. jwk.kty = "RSA";
  5401. jwk.ext = extractable;
  5402. jwk.key_ops = keyUsages;
  5403. if (this.name.toLowerCase() === "safari")
  5404. jwk.alg = "RSA-OAEP";
  5405. else {
  5406. switch ((_e = alg.hash) === null || _e === void 0 ? void 0 : _e.name.toUpperCase()) {
  5407. case "SHA-1":
  5408. jwk.alg = "RSA-OAEP";
  5409. break;
  5410. case "SHA-256":
  5411. jwk.alg = "RSA-OAEP-256";
  5412. break;
  5413. case "SHA-384":
  5414. jwk.alg = "RSA-OAEP-384";
  5415. break;
  5416. case "SHA-512":
  5417. jwk.alg = "RSA-OAEP-512";
  5418. break;
  5419. default:
  5420. throw new Error(`Incorrect hash algorithm: ${(_f = alg.hash) === null || _f === void 0 ? void 0 : _f.name.toUpperCase()}`);
  5421. }
  5422. }
  5423. const privateKeyJSON = privateKeyInfo.toJSON();
  5424. Object.assign(jwk, privateKeyJSON);
  5425. }
  5426. break;
  5427. case "RSAES-PKCS1-V1_5":
  5428. {
  5429. keyUsages = ["decrypt"];
  5430. jwk.kty = "RSA";
  5431. jwk.ext = extractable;
  5432. jwk.key_ops = keyUsages;
  5433. jwk.alg = "PS1";
  5434. const privateKeyJSON = privateKeyInfo.toJSON();
  5435. Object.assign(jwk, privateKeyJSON);
  5436. }
  5437. break;
  5438. default:
  5439. throw new Error(`Incorrect algorithm name: ${alg.name.toUpperCase()}`);
  5440. }
  5441. }
  5442. break;
  5443. case "jwk":
  5444. jwk = keyData;
  5445. break;
  5446. default:
  5447. throw new Error(`Incorrect format: ${format}`);
  5448. }
  5449. if (this.name.toLowerCase() === "safari") {
  5450. try {
  5451. return this.subtle.importKey("jwk", pvutils.stringToArrayBuffer(JSON.stringify(jwk)), algorithm, extractable, keyUsages);
  5452. }
  5453. catch {
  5454. return this.subtle.importKey("jwk", jwk, algorithm, extractable, keyUsages);
  5455. }
  5456. }
  5457. return this.subtle.importKey("jwk", jwk, algorithm, extractable, keyUsages);
  5458. }
  5459. async exportKey(format, key) {
  5460. let jwk = await this.subtle.exportKey("jwk", key);
  5461. if (this.name.toLowerCase() === "safari") {
  5462. if (jwk instanceof ArrayBuffer) {
  5463. jwk = JSON.parse(pvutils.arrayBufferToString(jwk));
  5464. }
  5465. }
  5466. switch (format.toLowerCase()) {
  5467. case "raw":
  5468. return this.subtle.exportKey("raw", key);
  5469. case "spki": {
  5470. const publicKeyInfo = new PublicKeyInfo();
  5471. try {
  5472. publicKeyInfo.fromJSON(jwk);
  5473. }
  5474. catch {
  5475. throw new Error("Incorrect key data");
  5476. }
  5477. return publicKeyInfo.toSchema().toBER(false);
  5478. }
  5479. case "pkcs8": {
  5480. const privateKeyInfo = new PrivateKeyInfo();
  5481. try {
  5482. privateKeyInfo.fromJSON(jwk);
  5483. }
  5484. catch {
  5485. throw new Error("Incorrect key data");
  5486. }
  5487. return privateKeyInfo.toSchema().toBER(false);
  5488. }
  5489. case "jwk":
  5490. return jwk;
  5491. default:
  5492. throw new Error(`Incorrect format: ${format}`);
  5493. }
  5494. }
  5495. async convert(inputFormat, outputFormat, keyData, algorithm, extractable, keyUsages) {
  5496. if (inputFormat.toLowerCase() === outputFormat.toLowerCase()) {
  5497. return keyData;
  5498. }
  5499. const key = await this.importKey(inputFormat, keyData, algorithm, extractable, keyUsages);
  5500. return this.exportKey(outputFormat, key);
  5501. }
  5502. getAlgorithmByOID(oid, safety = false, target) {
  5503. switch (oid) {
  5504. case "1.2.840.113549.1.1.1":
  5505. return {
  5506. name: "RSAES-PKCS1-v1_5"
  5507. };
  5508. case "1.2.840.113549.1.1.5":
  5509. return {
  5510. name: "RSASSA-PKCS1-v1_5",
  5511. hash: {
  5512. name: "SHA-1"
  5513. }
  5514. };
  5515. case "1.2.840.113549.1.1.11":
  5516. return {
  5517. name: "RSASSA-PKCS1-v1_5",
  5518. hash: {
  5519. name: "SHA-256"
  5520. }
  5521. };
  5522. case "1.2.840.113549.1.1.12":
  5523. return {
  5524. name: "RSASSA-PKCS1-v1_5",
  5525. hash: {
  5526. name: "SHA-384"
  5527. }
  5528. };
  5529. case "1.2.840.113549.1.1.13":
  5530. return {
  5531. name: "RSASSA-PKCS1-v1_5",
  5532. hash: {
  5533. name: "SHA-512"
  5534. }
  5535. };
  5536. case "1.2.840.113549.1.1.10":
  5537. return {
  5538. name: "RSA-PSS"
  5539. };
  5540. case "1.2.840.113549.1.1.7":
  5541. return {
  5542. name: "RSA-OAEP"
  5543. };
  5544. case "1.2.840.10045.2.1":
  5545. case "1.2.840.10045.4.1":
  5546. return {
  5547. name: "ECDSA",
  5548. hash: {
  5549. name: "SHA-1"
  5550. }
  5551. };
  5552. case "1.2.840.10045.4.3.2":
  5553. return {
  5554. name: "ECDSA",
  5555. hash: {
  5556. name: "SHA-256"
  5557. }
  5558. };
  5559. case "1.2.840.10045.4.3.3":
  5560. return {
  5561. name: "ECDSA",
  5562. hash: {
  5563. name: "SHA-384"
  5564. }
  5565. };
  5566. case "1.2.840.10045.4.3.4":
  5567. return {
  5568. name: "ECDSA",
  5569. hash: {
  5570. name: "SHA-512"
  5571. }
  5572. };
  5573. case "1.3.133.16.840.63.0.2":
  5574. return {
  5575. name: "ECDH",
  5576. kdf: "SHA-1"
  5577. };
  5578. case "1.3.132.1.11.1":
  5579. return {
  5580. name: "ECDH",
  5581. kdf: "SHA-256"
  5582. };
  5583. case "1.3.132.1.11.2":
  5584. return {
  5585. name: "ECDH",
  5586. kdf: "SHA-384"
  5587. };
  5588. case "1.3.132.1.11.3":
  5589. return {
  5590. name: "ECDH",
  5591. kdf: "SHA-512"
  5592. };
  5593. case "2.16.840.1.101.3.4.1.2":
  5594. return {
  5595. name: "AES-CBC",
  5596. length: 128
  5597. };
  5598. case "2.16.840.1.101.3.4.1.22":
  5599. return {
  5600. name: "AES-CBC",
  5601. length: 192
  5602. };
  5603. case "2.16.840.1.101.3.4.1.42":
  5604. return {
  5605. name: "AES-CBC",
  5606. length: 256
  5607. };
  5608. case "2.16.840.1.101.3.4.1.6":
  5609. return {
  5610. name: "AES-GCM",
  5611. length: 128
  5612. };
  5613. case "2.16.840.1.101.3.4.1.26":
  5614. return {
  5615. name: "AES-GCM",
  5616. length: 192
  5617. };
  5618. case "2.16.840.1.101.3.4.1.46":
  5619. return {
  5620. name: "AES-GCM",
  5621. length: 256
  5622. };
  5623. case "2.16.840.1.101.3.4.1.4":
  5624. return {
  5625. name: "AES-CFB",
  5626. length: 128
  5627. };
  5628. case "2.16.840.1.101.3.4.1.24":
  5629. return {
  5630. name: "AES-CFB",
  5631. length: 192
  5632. };
  5633. case "2.16.840.1.101.3.4.1.44":
  5634. return {
  5635. name: "AES-CFB",
  5636. length: 256
  5637. };
  5638. case "2.16.840.1.101.3.4.1.5":
  5639. return {
  5640. name: "AES-KW",
  5641. length: 128
  5642. };
  5643. case "2.16.840.1.101.3.4.1.25":
  5644. return {
  5645. name: "AES-KW",
  5646. length: 192
  5647. };
  5648. case "2.16.840.1.101.3.4.1.45":
  5649. return {
  5650. name: "AES-KW",
  5651. length: 256
  5652. };
  5653. case "1.2.840.113549.2.7":
  5654. return {
  5655. name: "HMAC",
  5656. hash: {
  5657. name: "SHA-1"
  5658. }
  5659. };
  5660. case "1.2.840.113549.2.9":
  5661. return {
  5662. name: "HMAC",
  5663. hash: {
  5664. name: "SHA-256"
  5665. }
  5666. };
  5667. case "1.2.840.113549.2.10":
  5668. return {
  5669. name: "HMAC",
  5670. hash: {
  5671. name: "SHA-384"
  5672. }
  5673. };
  5674. case "1.2.840.113549.2.11":
  5675. return {
  5676. name: "HMAC",
  5677. hash: {
  5678. name: "SHA-512"
  5679. }
  5680. };
  5681. case "1.2.840.113549.1.9.16.3.5":
  5682. return {
  5683. name: "DH"
  5684. };
  5685. case "1.3.14.3.2.26":
  5686. return {
  5687. name: "SHA-1"
  5688. };
  5689. case "2.16.840.1.101.3.4.2.1":
  5690. return {
  5691. name: "SHA-256"
  5692. };
  5693. case "2.16.840.1.101.3.4.2.2":
  5694. return {
  5695. name: "SHA-384"
  5696. };
  5697. case "2.16.840.1.101.3.4.2.3":
  5698. return {
  5699. name: "SHA-512"
  5700. };
  5701. case "1.2.840.113549.1.5.12":
  5702. return {
  5703. name: "PBKDF2"
  5704. };
  5705. case "1.2.840.10045.3.1.7":
  5706. return {
  5707. name: "P-256"
  5708. };
  5709. case "1.3.132.0.34":
  5710. return {
  5711. name: "P-384"
  5712. };
  5713. case "1.3.132.0.35":
  5714. return {
  5715. name: "P-521"
  5716. };
  5717. }
  5718. if (safety) {
  5719. throw new Error(`Unsupported algorithm identifier ${target ? `for ${target} ` : EMPTY_STRING}: ${oid}`);
  5720. }
  5721. return {};
  5722. }
  5723. getOIDByAlgorithm(algorithm, safety = false, target) {
  5724. let result = EMPTY_STRING;
  5725. switch (algorithm.name.toUpperCase()) {
  5726. case "RSAES-PKCS1-V1_5":
  5727. result = "1.2.840.113549.1.1.1";
  5728. break;
  5729. case "RSASSA-PKCS1-V1_5":
  5730. switch (algorithm.hash.name.toUpperCase()) {
  5731. case "SHA-1":
  5732. result = "1.2.840.113549.1.1.5";
  5733. break;
  5734. case "SHA-256":
  5735. result = "1.2.840.113549.1.1.11";
  5736. break;
  5737. case "SHA-384":
  5738. result = "1.2.840.113549.1.1.12";
  5739. break;
  5740. case "SHA-512":
  5741. result = "1.2.840.113549.1.1.13";
  5742. break;
  5743. }
  5744. break;
  5745. case "RSA-PSS":
  5746. result = "1.2.840.113549.1.1.10";
  5747. break;
  5748. case "RSA-OAEP":
  5749. result = "1.2.840.113549.1.1.7";
  5750. break;
  5751. case "ECDSA":
  5752. switch (algorithm.hash.name.toUpperCase()) {
  5753. case "SHA-1":
  5754. result = "1.2.840.10045.4.1";
  5755. break;
  5756. case "SHA-256":
  5757. result = "1.2.840.10045.4.3.2";
  5758. break;
  5759. case "SHA-384":
  5760. result = "1.2.840.10045.4.3.3";
  5761. break;
  5762. case "SHA-512":
  5763. result = "1.2.840.10045.4.3.4";
  5764. break;
  5765. }
  5766. break;
  5767. case "ECDH":
  5768. switch (algorithm.kdf.toUpperCase()) {
  5769. case "SHA-1":
  5770. result = "1.3.133.16.840.63.0.2";
  5771. break;
  5772. case "SHA-256":
  5773. result = "1.3.132.1.11.1";
  5774. break;
  5775. case "SHA-384":
  5776. result = "1.3.132.1.11.2";
  5777. break;
  5778. case "SHA-512":
  5779. result = "1.3.132.1.11.3";
  5780. break;
  5781. }
  5782. break;
  5783. case "AES-CTR":
  5784. break;
  5785. case "AES-CBC":
  5786. switch (algorithm.length) {
  5787. case 128:
  5788. result = "2.16.840.1.101.3.4.1.2";
  5789. break;
  5790. case 192:
  5791. result = "2.16.840.1.101.3.4.1.22";
  5792. break;
  5793. case 256:
  5794. result = "2.16.840.1.101.3.4.1.42";
  5795. break;
  5796. }
  5797. break;
  5798. case "AES-CMAC":
  5799. break;
  5800. case "AES-GCM":
  5801. switch (algorithm.length) {
  5802. case 128:
  5803. result = "2.16.840.1.101.3.4.1.6";
  5804. break;
  5805. case 192:
  5806. result = "2.16.840.1.101.3.4.1.26";
  5807. break;
  5808. case 256:
  5809. result = "2.16.840.1.101.3.4.1.46";
  5810. break;
  5811. }
  5812. break;
  5813. case "AES-CFB":
  5814. switch (algorithm.length) {
  5815. case 128:
  5816. result = "2.16.840.1.101.3.4.1.4";
  5817. break;
  5818. case 192:
  5819. result = "2.16.840.1.101.3.4.1.24";
  5820. break;
  5821. case 256:
  5822. result = "2.16.840.1.101.3.4.1.44";
  5823. break;
  5824. }
  5825. break;
  5826. case "AES-KW":
  5827. switch (algorithm.length) {
  5828. case 128:
  5829. result = "2.16.840.1.101.3.4.1.5";
  5830. break;
  5831. case 192:
  5832. result = "2.16.840.1.101.3.4.1.25";
  5833. break;
  5834. case 256:
  5835. result = "2.16.840.1.101.3.4.1.45";
  5836. break;
  5837. }
  5838. break;
  5839. case "HMAC":
  5840. switch (algorithm.hash.name.toUpperCase()) {
  5841. case "SHA-1":
  5842. result = "1.2.840.113549.2.7";
  5843. break;
  5844. case "SHA-256":
  5845. result = "1.2.840.113549.2.9";
  5846. break;
  5847. case "SHA-384":
  5848. result = "1.2.840.113549.2.10";
  5849. break;
  5850. case "SHA-512":
  5851. result = "1.2.840.113549.2.11";
  5852. break;
  5853. }
  5854. break;
  5855. case "DH":
  5856. result = "1.2.840.113549.1.9.16.3.5";
  5857. break;
  5858. case "SHA-1":
  5859. result = "1.3.14.3.2.26";
  5860. break;
  5861. case "SHA-256":
  5862. result = "2.16.840.1.101.3.4.2.1";
  5863. break;
  5864. case "SHA-384":
  5865. result = "2.16.840.1.101.3.4.2.2";
  5866. break;
  5867. case "SHA-512":
  5868. result = "2.16.840.1.101.3.4.2.3";
  5869. break;
  5870. case "CONCAT":
  5871. break;
  5872. case "HKDF":
  5873. break;
  5874. case "PBKDF2":
  5875. result = "1.2.840.113549.1.5.12";
  5876. break;
  5877. case "P-256":
  5878. result = "1.2.840.10045.3.1.7";
  5879. break;
  5880. case "P-384":
  5881. result = "1.3.132.0.34";
  5882. break;
  5883. case "P-521":
  5884. result = "1.3.132.0.35";
  5885. break;
  5886. }
  5887. if (!result && safety) {
  5888. throw new Error(`Unsupported algorithm ${target ? `for ${target} ` : EMPTY_STRING}: ${algorithm.name}`);
  5889. }
  5890. return result;
  5891. }
  5892. getAlgorithmParameters(algorithmName, operation) {
  5893. let result = {
  5894. algorithm: {},
  5895. usages: []
  5896. };
  5897. switch (algorithmName.toUpperCase()) {
  5898. case "RSAES-PKCS1-V1_5":
  5899. case "RSASSA-PKCS1-V1_5":
  5900. switch (operation.toLowerCase()) {
  5901. case "generatekey":
  5902. result = {
  5903. algorithm: {
  5904. name: "RSASSA-PKCS1-v1_5",
  5905. modulusLength: 2048,
  5906. publicExponent: new Uint8Array([0x01, 0x00, 0x01]),
  5907. hash: {
  5908. name: "SHA-256"
  5909. }
  5910. },
  5911. usages: ["sign", "verify"]
  5912. };
  5913. break;
  5914. case "verify":
  5915. case "sign":
  5916. case "importkey":
  5917. result = {
  5918. algorithm: {
  5919. name: "RSASSA-PKCS1-v1_5",
  5920. hash: {
  5921. name: "SHA-256"
  5922. }
  5923. },
  5924. usages: ["verify"]
  5925. };
  5926. break;
  5927. case "exportkey":
  5928. default:
  5929. return {
  5930. algorithm: {
  5931. name: "RSASSA-PKCS1-v1_5"
  5932. },
  5933. usages: []
  5934. };
  5935. }
  5936. break;
  5937. case "RSA-PSS":
  5938. switch (operation.toLowerCase()) {
  5939. case "sign":
  5940. case "verify":
  5941. result = {
  5942. algorithm: {
  5943. name: "RSA-PSS",
  5944. hash: {
  5945. name: "SHA-1"
  5946. },
  5947. saltLength: 20
  5948. },
  5949. usages: ["sign", "verify"]
  5950. };
  5951. break;
  5952. case "generatekey":
  5953. result = {
  5954. algorithm: {
  5955. name: "RSA-PSS",
  5956. modulusLength: 2048,
  5957. publicExponent: new Uint8Array([0x01, 0x00, 0x01]),
  5958. hash: {
  5959. name: "SHA-1"
  5960. }
  5961. },
  5962. usages: ["sign", "verify"]
  5963. };
  5964. break;
  5965. case "importkey":
  5966. result = {
  5967. algorithm: {
  5968. name: "RSA-PSS",
  5969. hash: {
  5970. name: "SHA-1"
  5971. }
  5972. },
  5973. usages: ["verify"]
  5974. };
  5975. break;
  5976. case "exportkey":
  5977. default:
  5978. return {
  5979. algorithm: {
  5980. name: "RSA-PSS"
  5981. },
  5982. usages: []
  5983. };
  5984. }
  5985. break;
  5986. case "RSA-OAEP":
  5987. switch (operation.toLowerCase()) {
  5988. case "encrypt":
  5989. case "decrypt":
  5990. result = {
  5991. algorithm: {
  5992. name: "RSA-OAEP"
  5993. },
  5994. usages: ["encrypt", "decrypt"]
  5995. };
  5996. break;
  5997. case "generatekey":
  5998. result = {
  5999. algorithm: {
  6000. name: "RSA-OAEP",
  6001. modulusLength: 2048,
  6002. publicExponent: new Uint8Array([0x01, 0x00, 0x01]),
  6003. hash: {
  6004. name: "SHA-256"
  6005. }
  6006. },
  6007. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6008. };
  6009. break;
  6010. case "importkey":
  6011. result = {
  6012. algorithm: {
  6013. name: "RSA-OAEP",
  6014. hash: {
  6015. name: "SHA-256"
  6016. }
  6017. },
  6018. usages: ["encrypt"]
  6019. };
  6020. break;
  6021. case "exportkey":
  6022. default:
  6023. return {
  6024. algorithm: {
  6025. name: "RSA-OAEP"
  6026. },
  6027. usages: []
  6028. };
  6029. }
  6030. break;
  6031. case "ECDSA":
  6032. switch (operation.toLowerCase()) {
  6033. case "generatekey":
  6034. result = {
  6035. algorithm: {
  6036. name: "ECDSA",
  6037. namedCurve: "P-256"
  6038. },
  6039. usages: ["sign", "verify"]
  6040. };
  6041. break;
  6042. case "importkey":
  6043. result = {
  6044. algorithm: {
  6045. name: "ECDSA",
  6046. namedCurve: "P-256"
  6047. },
  6048. usages: ["verify"]
  6049. };
  6050. break;
  6051. case "verify":
  6052. case "sign":
  6053. result = {
  6054. algorithm: {
  6055. name: "ECDSA",
  6056. hash: {
  6057. name: "SHA-256"
  6058. }
  6059. },
  6060. usages: ["sign"]
  6061. };
  6062. break;
  6063. default:
  6064. return {
  6065. algorithm: {
  6066. name: "ECDSA"
  6067. },
  6068. usages: []
  6069. };
  6070. }
  6071. break;
  6072. case "ECDH":
  6073. switch (operation.toLowerCase()) {
  6074. case "exportkey":
  6075. case "importkey":
  6076. case "generatekey":
  6077. result = {
  6078. algorithm: {
  6079. name: "ECDH",
  6080. namedCurve: "P-256"
  6081. },
  6082. usages: ["deriveKey", "deriveBits"]
  6083. };
  6084. break;
  6085. case "derivekey":
  6086. case "derivebits":
  6087. result = {
  6088. algorithm: {
  6089. name: "ECDH",
  6090. namedCurve: "P-256",
  6091. public: []
  6092. },
  6093. usages: ["encrypt", "decrypt"]
  6094. };
  6095. break;
  6096. default:
  6097. return {
  6098. algorithm: {
  6099. name: "ECDH"
  6100. },
  6101. usages: []
  6102. };
  6103. }
  6104. break;
  6105. case "AES-CTR":
  6106. switch (operation.toLowerCase()) {
  6107. case "importkey":
  6108. case "exportkey":
  6109. case "generatekey":
  6110. result = {
  6111. algorithm: {
  6112. name: "AES-CTR",
  6113. length: 256
  6114. },
  6115. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6116. };
  6117. break;
  6118. case "decrypt":
  6119. case "encrypt":
  6120. result = {
  6121. algorithm: {
  6122. name: "AES-CTR",
  6123. counter: new Uint8Array(16),
  6124. length: 10
  6125. },
  6126. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6127. };
  6128. break;
  6129. default:
  6130. return {
  6131. algorithm: {
  6132. name: "AES-CTR"
  6133. },
  6134. usages: []
  6135. };
  6136. }
  6137. break;
  6138. case "AES-CBC":
  6139. switch (operation.toLowerCase()) {
  6140. case "importkey":
  6141. case "exportkey":
  6142. case "generatekey":
  6143. result = {
  6144. algorithm: {
  6145. name: "AES-CBC",
  6146. length: 256
  6147. },
  6148. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6149. };
  6150. break;
  6151. case "decrypt":
  6152. case "encrypt":
  6153. result = {
  6154. algorithm: {
  6155. name: "AES-CBC",
  6156. iv: this.getRandomValues(new Uint8Array(16))
  6157. },
  6158. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6159. };
  6160. break;
  6161. default:
  6162. return {
  6163. algorithm: {
  6164. name: "AES-CBC"
  6165. },
  6166. usages: []
  6167. };
  6168. }
  6169. break;
  6170. case "AES-GCM":
  6171. switch (operation.toLowerCase()) {
  6172. case "importkey":
  6173. case "exportkey":
  6174. case "generatekey":
  6175. result = {
  6176. algorithm: {
  6177. name: "AES-GCM",
  6178. length: 256
  6179. },
  6180. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6181. };
  6182. break;
  6183. case "decrypt":
  6184. case "encrypt":
  6185. result = {
  6186. algorithm: {
  6187. name: "AES-GCM",
  6188. iv: this.getRandomValues(new Uint8Array(16))
  6189. },
  6190. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6191. };
  6192. break;
  6193. default:
  6194. return {
  6195. algorithm: {
  6196. name: "AES-GCM"
  6197. },
  6198. usages: []
  6199. };
  6200. }
  6201. break;
  6202. case "AES-KW":
  6203. switch (operation.toLowerCase()) {
  6204. case "importkey":
  6205. case "exportkey":
  6206. case "generatekey":
  6207. case "wrapkey":
  6208. case "unwrapkey":
  6209. result = {
  6210. algorithm: {
  6211. name: "AES-KW",
  6212. length: 256
  6213. },
  6214. usages: ["wrapKey", "unwrapKey"]
  6215. };
  6216. break;
  6217. default:
  6218. return {
  6219. algorithm: {
  6220. name: "AES-KW"
  6221. },
  6222. usages: []
  6223. };
  6224. }
  6225. break;
  6226. case "HMAC":
  6227. switch (operation.toLowerCase()) {
  6228. case "sign":
  6229. case "verify":
  6230. result = {
  6231. algorithm: {
  6232. name: "HMAC"
  6233. },
  6234. usages: ["sign", "verify"]
  6235. };
  6236. break;
  6237. case "importkey":
  6238. case "exportkey":
  6239. case "generatekey":
  6240. result = {
  6241. algorithm: {
  6242. name: "HMAC",
  6243. length: 32,
  6244. hash: {
  6245. name: "SHA-256"
  6246. }
  6247. },
  6248. usages: ["sign", "verify"]
  6249. };
  6250. break;
  6251. default:
  6252. return {
  6253. algorithm: {
  6254. name: "HMAC"
  6255. },
  6256. usages: []
  6257. };
  6258. }
  6259. break;
  6260. case "HKDF":
  6261. switch (operation.toLowerCase()) {
  6262. case "derivekey":
  6263. result = {
  6264. algorithm: {
  6265. name: "HKDF",
  6266. hash: "SHA-256",
  6267. salt: new Uint8Array([]),
  6268. info: new Uint8Array([])
  6269. },
  6270. usages: ["encrypt", "decrypt"]
  6271. };
  6272. break;
  6273. default:
  6274. return {
  6275. algorithm: {
  6276. name: "HKDF"
  6277. },
  6278. usages: []
  6279. };
  6280. }
  6281. break;
  6282. case "PBKDF2":
  6283. switch (operation.toLowerCase()) {
  6284. case "derivekey":
  6285. result = {
  6286. algorithm: {
  6287. name: "PBKDF2",
  6288. hash: { name: "SHA-256" },
  6289. salt: new Uint8Array([]),
  6290. iterations: 10000
  6291. },
  6292. usages: ["encrypt", "decrypt"]
  6293. };
  6294. break;
  6295. default:
  6296. return {
  6297. algorithm: {
  6298. name: "PBKDF2"
  6299. },
  6300. usages: []
  6301. };
  6302. }
  6303. break;
  6304. }
  6305. return result;
  6306. }
  6307. getHashAlgorithm(signatureAlgorithm) {
  6308. let result = EMPTY_STRING;
  6309. switch (signatureAlgorithm.algorithmId) {
  6310. case "1.2.840.10045.4.1":
  6311. case "1.2.840.113549.1.1.5":
  6312. result = "SHA-1";
  6313. break;
  6314. case "1.2.840.10045.4.3.2":
  6315. case "1.2.840.113549.1.1.11":
  6316. result = "SHA-256";
  6317. break;
  6318. case "1.2.840.10045.4.3.3":
  6319. case "1.2.840.113549.1.1.12":
  6320. result = "SHA-384";
  6321. break;
  6322. case "1.2.840.10045.4.3.4":
  6323. case "1.2.840.113549.1.1.13":
  6324. result = "SHA-512";
  6325. break;
  6326. case "1.2.840.113549.1.1.10":
  6327. {
  6328. try {
  6329. const params = new RSASSAPSSParams({ schema: signatureAlgorithm.algorithmParams });
  6330. if (params.hashAlgorithm) {
  6331. const algorithm = this.getAlgorithmByOID(params.hashAlgorithm.algorithmId);
  6332. if ("name" in algorithm) {
  6333. result = algorithm.name;
  6334. }
  6335. else {
  6336. return EMPTY_STRING;
  6337. }
  6338. }
  6339. else
  6340. result = "SHA-1";
  6341. }
  6342. catch {
  6343. }
  6344. }
  6345. break;
  6346. }
  6347. return result;
  6348. }
  6349. async encryptEncryptedContentInfo(parameters) {
  6350. ParameterError.assert(parameters, "password", "contentEncryptionAlgorithm", "hmacHashAlgorithm", "iterationCount", "contentToEncrypt", "contentToEncrypt", "contentType");
  6351. const contentEncryptionOID = this.getOIDByAlgorithm(parameters.contentEncryptionAlgorithm, true, "contentEncryptionAlgorithm");
  6352. const pbkdf2OID = this.getOIDByAlgorithm({
  6353. name: "PBKDF2"
  6354. }, true, "PBKDF2");
  6355. const hmacOID = this.getOIDByAlgorithm({
  6356. name: "HMAC",
  6357. hash: {
  6358. name: parameters.hmacHashAlgorithm
  6359. }
  6360. }, true, "hmacHashAlgorithm");
  6361. const ivBuffer = new ArrayBuffer(16);
  6362. const ivView = new Uint8Array(ivBuffer);
  6363. this.getRandomValues(ivView);
  6364. const saltBuffer = new ArrayBuffer(64);
  6365. const saltView = new Uint8Array(saltBuffer);
  6366. this.getRandomValues(saltView);
  6367. const contentView = new Uint8Array(parameters.contentToEncrypt);
  6368. const pbkdf2Params = new PBKDF2Params({
  6369. salt: new asn1js.OctetString({ valueHex: saltBuffer }),
  6370. iterationCount: parameters.iterationCount,
  6371. prf: new AlgorithmIdentifier({
  6372. algorithmId: hmacOID,
  6373. algorithmParams: new asn1js.Null()
  6374. })
  6375. });
  6376. const passwordView = new Uint8Array(parameters.password);
  6377. const pbkdfKey = await this.importKey("raw", passwordView, "PBKDF2", false, ["deriveKey"]);
  6378. const derivedKey = await this.deriveKey({
  6379. name: "PBKDF2",
  6380. hash: {
  6381. name: parameters.hmacHashAlgorithm
  6382. },
  6383. salt: saltView,
  6384. iterations: parameters.iterationCount
  6385. }, pbkdfKey, parameters.contentEncryptionAlgorithm, false, ["encrypt"]);
  6386. const encryptedData = await this.encrypt({
  6387. name: parameters.contentEncryptionAlgorithm.name,
  6388. iv: ivView
  6389. }, derivedKey, contentView);
  6390. const pbes2Parameters = new PBES2Params({
  6391. keyDerivationFunc: new AlgorithmIdentifier({
  6392. algorithmId: pbkdf2OID,
  6393. algorithmParams: pbkdf2Params.toSchema()
  6394. }),
  6395. encryptionScheme: new AlgorithmIdentifier({
  6396. algorithmId: contentEncryptionOID,
  6397. algorithmParams: new asn1js.OctetString({ valueHex: ivBuffer })
  6398. })
  6399. });
  6400. return new EncryptedContentInfo({
  6401. contentType: parameters.contentType,
  6402. contentEncryptionAlgorithm: new AlgorithmIdentifier({
  6403. algorithmId: "1.2.840.113549.1.5.13",
  6404. algorithmParams: pbes2Parameters.toSchema()
  6405. }),
  6406. encryptedContent: new asn1js.OctetString({ valueHex: encryptedData })
  6407. });
  6408. }
  6409. async decryptEncryptedContentInfo(parameters) {
  6410. ParameterError.assert(parameters, "password", "encryptedContentInfo");
  6411. if (parameters.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId !== "1.2.840.113549.1.5.13")
  6412. throw new Error(`Unknown "contentEncryptionAlgorithm": ${parameters.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId}`);
  6413. let pbes2Parameters;
  6414. try {
  6415. pbes2Parameters = new PBES2Params({ schema: parameters.encryptedContentInfo.contentEncryptionAlgorithm.algorithmParams });
  6416. }
  6417. catch {
  6418. throw new Error("Incorrectly encoded \"pbes2Parameters\"");
  6419. }
  6420. let pbkdf2Params;
  6421. try {
  6422. pbkdf2Params = new PBKDF2Params({ schema: pbes2Parameters.keyDerivationFunc.algorithmParams });
  6423. }
  6424. catch {
  6425. throw new Error("Incorrectly encoded \"pbkdf2Params\"");
  6426. }
  6427. const contentEncryptionAlgorithm = this.getAlgorithmByOID(pbes2Parameters.encryptionScheme.algorithmId, true);
  6428. const ivBuffer = pbes2Parameters.encryptionScheme.algorithmParams.valueBlock.valueHex;
  6429. const ivView = new Uint8Array(ivBuffer);
  6430. const saltBuffer = pbkdf2Params.salt.valueBlock.valueHex;
  6431. const saltView = new Uint8Array(saltBuffer);
  6432. const iterationCount = pbkdf2Params.iterationCount;
  6433. let hmacHashAlgorithm = "SHA-1";
  6434. if (pbkdf2Params.prf) {
  6435. const algorithm = this.getAlgorithmByOID(pbkdf2Params.prf.algorithmId, true);
  6436. hmacHashAlgorithm = algorithm.hash.name;
  6437. }
  6438. const pbkdfKey = await this.importKey("raw", parameters.password, "PBKDF2", false, ["deriveKey"]);
  6439. const result = await this.deriveKey({
  6440. name: "PBKDF2",
  6441. hash: {
  6442. name: hmacHashAlgorithm
  6443. },
  6444. salt: saltView,
  6445. iterations: iterationCount
  6446. }, pbkdfKey, contentEncryptionAlgorithm, false, ["decrypt"]);
  6447. const dataBuffer = parameters.encryptedContentInfo.getEncryptedContent();
  6448. return this.decrypt({
  6449. name: contentEncryptionAlgorithm.name,
  6450. iv: ivView
  6451. }, result, dataBuffer);
  6452. }
  6453. async stampDataWithPassword(parameters) {
  6454. if ((parameters instanceof Object) === false)
  6455. throw new Error("Parameters must have type \"Object\"");
  6456. ParameterError.assert(parameters, "password", "hashAlgorithm", "iterationCount", "salt", "contentToStamp");
  6457. let length;
  6458. switch (parameters.hashAlgorithm.toLowerCase()) {
  6459. case "sha-1":
  6460. length = 160;
  6461. break;
  6462. case "sha-256":
  6463. length = 256;
  6464. break;
  6465. case "sha-384":
  6466. length = 384;
  6467. break;
  6468. case "sha-512":
  6469. length = 512;
  6470. break;
  6471. default:
  6472. throw new Error(`Incorrect "parameters.hashAlgorithm" parameter: ${parameters.hashAlgorithm}`);
  6473. }
  6474. const hmacAlgorithm = {
  6475. name: "HMAC",
  6476. length,
  6477. hash: {
  6478. name: parameters.hashAlgorithm
  6479. }
  6480. };
  6481. const pkcsKey = await makePKCS12B2Key(parameters.hashAlgorithm, length, parameters.password, parameters.salt, parameters.iterationCount);
  6482. const hmacKey = await this.importKey("raw", new Uint8Array(pkcsKey), hmacAlgorithm, false, ["sign"]);
  6483. return this.sign(hmacAlgorithm, hmacKey, new Uint8Array(parameters.contentToStamp));
  6484. }
  6485. async verifyDataStampedWithPassword(parameters) {
  6486. ParameterError.assert(parameters, "password", "hashAlgorithm", "salt", "iterationCount", "contentToVerify", "signatureToVerify");
  6487. let length = 0;
  6488. switch (parameters.hashAlgorithm.toLowerCase()) {
  6489. case "sha-1":
  6490. length = 160;
  6491. break;
  6492. case "sha-256":
  6493. length = 256;
  6494. break;
  6495. case "sha-384":
  6496. length = 384;
  6497. break;
  6498. case "sha-512":
  6499. length = 512;
  6500. break;
  6501. default:
  6502. throw new Error(`Incorrect "parameters.hashAlgorithm" parameter: ${parameters.hashAlgorithm}`);
  6503. }
  6504. const hmacAlgorithm = {
  6505. name: "HMAC",
  6506. length,
  6507. hash: {
  6508. name: parameters.hashAlgorithm
  6509. }
  6510. };
  6511. const pkcsKey = await makePKCS12B2Key(parameters.hashAlgorithm, length, parameters.password, parameters.salt, parameters.iterationCount);
  6512. const hmacKey = await this.importKey("raw", new Uint8Array(pkcsKey), hmacAlgorithm, false, ["verify"]);
  6513. return this.verify(hmacAlgorithm, hmacKey, new Uint8Array(parameters.signatureToVerify), new Uint8Array(parameters.contentToVerify));
  6514. }
  6515. async getSignatureParameters(privateKey, hashAlgorithm = "SHA-1") {
  6516. this.getOIDByAlgorithm({ name: hashAlgorithm }, true, "hashAlgorithm");
  6517. const signatureAlgorithm = new AlgorithmIdentifier();
  6518. const parameters = this.getAlgorithmParameters(privateKey.algorithm.name, "sign");
  6519. if (!Object.keys(parameters.algorithm).length) {
  6520. throw new Error("Parameter 'algorithm' is empty");
  6521. }
  6522. const algorithm = parameters.algorithm;
  6523. if ("hash" in privateKey.algorithm && privateKey.algorithm.hash && privateKey.algorithm.hash.name) {
  6524. algorithm.hash.name = privateKey.algorithm.hash.name;
  6525. }
  6526. else {
  6527. algorithm.hash.name = hashAlgorithm;
  6528. }
  6529. switch (privateKey.algorithm.name.toUpperCase()) {
  6530. case "RSASSA-PKCS1-V1_5":
  6531. case "ECDSA":
  6532. signatureAlgorithm.algorithmId = this.getOIDByAlgorithm(algorithm, true);
  6533. break;
  6534. case "RSA-PSS":
  6535. {
  6536. switch (algorithm.hash.name.toUpperCase()) {
  6537. case "SHA-256":
  6538. algorithm.saltLength = 32;
  6539. break;
  6540. case "SHA-384":
  6541. algorithm.saltLength = 48;
  6542. break;
  6543. case "SHA-512":
  6544. algorithm.saltLength = 64;
  6545. break;
  6546. }
  6547. const paramsObject = {};
  6548. if (algorithm.hash.name.toUpperCase() !== "SHA-1") {
  6549. const hashAlgorithmOID = this.getOIDByAlgorithm({ name: algorithm.hash.name }, true, "hashAlgorithm");
  6550. paramsObject.hashAlgorithm = new AlgorithmIdentifier({
  6551. algorithmId: hashAlgorithmOID,
  6552. algorithmParams: new asn1js.Null()
  6553. });
  6554. paramsObject.maskGenAlgorithm = new AlgorithmIdentifier({
  6555. algorithmId: "1.2.840.113549.1.1.8",
  6556. algorithmParams: paramsObject.hashAlgorithm.toSchema()
  6557. });
  6558. }
  6559. if (algorithm.saltLength !== 20)
  6560. paramsObject.saltLength = algorithm.saltLength;
  6561. const pssParameters = new RSASSAPSSParams(paramsObject);
  6562. signatureAlgorithm.algorithmId = "1.2.840.113549.1.1.10";
  6563. signatureAlgorithm.algorithmParams = pssParameters.toSchema();
  6564. }
  6565. break;
  6566. default:
  6567. throw new Error(`Unsupported signature algorithm: ${privateKey.algorithm.name}`);
  6568. }
  6569. return {
  6570. signatureAlgorithm,
  6571. parameters
  6572. };
  6573. }
  6574. async signWithPrivateKey(data, privateKey, parameters) {
  6575. const signature = await this.sign(parameters.algorithm, privateKey, data);
  6576. if (parameters.algorithm.name === "ECDSA") {
  6577. return createCMSECDSASignature(signature);
  6578. }
  6579. return signature;
  6580. }
  6581. fillPublicKeyParameters(publicKeyInfo, signatureAlgorithm) {
  6582. const parameters = {};
  6583. const shaAlgorithm = this.getHashAlgorithm(signatureAlgorithm);
  6584. if (shaAlgorithm === EMPTY_STRING)
  6585. throw new Error(`Unsupported signature algorithm: ${signatureAlgorithm.algorithmId}`);
  6586. let algorithmId;
  6587. if (signatureAlgorithm.algorithmId === "1.2.840.113549.1.1.10")
  6588. algorithmId = signatureAlgorithm.algorithmId;
  6589. else
  6590. algorithmId = publicKeyInfo.algorithm.algorithmId;
  6591. const algorithmObject = this.getAlgorithmByOID(algorithmId, true);
  6592. parameters.algorithm = this.getAlgorithmParameters(algorithmObject.name, "importKey");
  6593. if ("hash" in parameters.algorithm.algorithm)
  6594. parameters.algorithm.algorithm.hash.name = shaAlgorithm;
  6595. if (algorithmObject.name === "ECDSA") {
  6596. const publicKeyAlgorithm = publicKeyInfo.algorithm;
  6597. if (!publicKeyAlgorithm.algorithmParams) {
  6598. throw new Error("Algorithm parameters for ECDSA public key are missed");
  6599. }
  6600. const publicKeyAlgorithmParams = publicKeyAlgorithm.algorithmParams;
  6601. if ("idBlock" in publicKeyAlgorithm.algorithmParams) {
  6602. if (!((publicKeyAlgorithmParams.idBlock.tagClass === 1) && (publicKeyAlgorithmParams.idBlock.tagNumber === 6))) {
  6603. throw new Error("Incorrect type for ECDSA public key parameters");
  6604. }
  6605. }
  6606. const curveObject = this.getAlgorithmByOID(publicKeyAlgorithmParams.valueBlock.toString(), true);
  6607. parameters.algorithm.algorithm.namedCurve = curveObject.name;
  6608. }
  6609. return parameters;
  6610. }
  6611. async getPublicKey(publicKeyInfo, signatureAlgorithm, parameters) {
  6612. if (!parameters) {
  6613. parameters = this.fillPublicKeyParameters(publicKeyInfo, signatureAlgorithm);
  6614. }
  6615. const publicKeyInfoBuffer = publicKeyInfo.toSchema().toBER(false);
  6616. return this.importKey("spki", publicKeyInfoBuffer, parameters.algorithm.algorithm, true, parameters.algorithm.usages);
  6617. }
  6618. async verifyWithPublicKey(data, signature, publicKeyInfo, signatureAlgorithm, shaAlgorithm) {
  6619. let publicKey;
  6620. if (!shaAlgorithm) {
  6621. shaAlgorithm = this.getHashAlgorithm(signatureAlgorithm);
  6622. if (!shaAlgorithm)
  6623. throw new Error(`Unsupported signature algorithm: ${signatureAlgorithm.algorithmId}`);
  6624. publicKey = await this.getPublicKey(publicKeyInfo, signatureAlgorithm);
  6625. }
  6626. else {
  6627. const parameters = {};
  6628. let algorithmId;
  6629. if (signatureAlgorithm.algorithmId === "1.2.840.113549.1.1.10")
  6630. algorithmId = signatureAlgorithm.algorithmId;
  6631. else
  6632. algorithmId = publicKeyInfo.algorithm.algorithmId;
  6633. const algorithmObject = this.getAlgorithmByOID(algorithmId, true);
  6634. parameters.algorithm = this.getAlgorithmParameters(algorithmObject.name, "importKey");
  6635. if ("hash" in parameters.algorithm.algorithm)
  6636. parameters.algorithm.algorithm.hash.name = shaAlgorithm;
  6637. if (algorithmObject.name === "ECDSA") {
  6638. let algorithmParamsChecked = false;
  6639. if (("algorithmParams" in publicKeyInfo.algorithm) === true) {
  6640. if ("idBlock" in publicKeyInfo.algorithm.algorithmParams) {
  6641. if ((publicKeyInfo.algorithm.algorithmParams.idBlock.tagClass === 1) && (publicKeyInfo.algorithm.algorithmParams.idBlock.tagNumber === 6))
  6642. algorithmParamsChecked = true;
  6643. }
  6644. }
  6645. if (algorithmParamsChecked === false) {
  6646. throw new Error("Incorrect type for ECDSA public key parameters");
  6647. }
  6648. const curveObject = this.getAlgorithmByOID(publicKeyInfo.algorithm.algorithmParams.valueBlock.toString(), true);
  6649. parameters.algorithm.algorithm.namedCurve = curveObject.name;
  6650. }
  6651. publicKey = await this.getPublicKey(publicKeyInfo, null, parameters);
  6652. }
  6653. const algorithm = this.getAlgorithmParameters(publicKey.algorithm.name, "verify");
  6654. if ("hash" in algorithm.algorithm)
  6655. algorithm.algorithm.hash.name = shaAlgorithm;
  6656. let signatureValue = signature.valueBlock.valueHexView;
  6657. if (publicKey.algorithm.name === "ECDSA") {
  6658. const namedCurve = ECNamedCurves.find(publicKey.algorithm.namedCurve);
  6659. if (!namedCurve) {
  6660. throw new Error("Unsupported named curve in use");
  6661. }
  6662. const asn1 = asn1js.fromBER(signatureValue);
  6663. AsnError.assert(asn1, "Signature value");
  6664. signatureValue = createECDSASignatureFromCMS(asn1.result, namedCurve.size);
  6665. }
  6666. if (publicKey.algorithm.name === "RSA-PSS") {
  6667. const pssParameters = new RSASSAPSSParams({ schema: signatureAlgorithm.algorithmParams });
  6668. if ("saltLength" in pssParameters)
  6669. algorithm.algorithm.saltLength = pssParameters.saltLength;
  6670. else
  6671. algorithm.algorithm.saltLength = 20;
  6672. let hashAlgo = "SHA-1";
  6673. if ("hashAlgorithm" in pssParameters) {
  6674. const hashAlgorithm = this.getAlgorithmByOID(pssParameters.hashAlgorithm.algorithmId, true);
  6675. hashAlgo = hashAlgorithm.name;
  6676. }
  6677. algorithm.algorithm.hash.name = hashAlgo;
  6678. }
  6679. return this.verify(algorithm.algorithm, publicKey, signatureValue, data);
  6680. }
  6681. }
  6682. let engine = {
  6683. name: "none",
  6684. crypto: null,
  6685. };
  6686. function isCryptoEngine(engine) {
  6687. return engine
  6688. && typeof engine === "object"
  6689. && "crypto" in engine
  6690. ? true
  6691. : false;
  6692. }
  6693. function setEngine(name, ...args) {
  6694. let crypto = null;
  6695. if (args.length < 2) {
  6696. if (args.length) {
  6697. crypto = args[0];
  6698. }
  6699. else {
  6700. crypto = typeof self !== "undefined" && self.crypto ? new CryptoEngine({ name: "browser", crypto: self.crypto }) : null;
  6701. }
  6702. }
  6703. else {
  6704. const cryptoArg = args[0];
  6705. const subtleArg = args[1];
  6706. if (isCryptoEngine(subtleArg)) {
  6707. crypto = subtleArg;
  6708. }
  6709. else if (isCryptoEngine(cryptoArg)) {
  6710. crypto = cryptoArg;
  6711. }
  6712. else if ("subtle" in cryptoArg && "getRandomValues" in cryptoArg) {
  6713. crypto = new CryptoEngine({
  6714. crypto: cryptoArg,
  6715. });
  6716. }
  6717. }
  6718. if ((typeof process !== "undefined") && ("pid" in process) && (typeof global !== "undefined") && (typeof window === "undefined")) {
  6719. if (typeof global[process.pid] === "undefined") {
  6720. global[process.pid] = {};
  6721. }
  6722. else {
  6723. if (typeof global[process.pid] !== "object") {
  6724. throw new Error(`Name global.${process.pid} already exists and it is not an object`);
  6725. }
  6726. }
  6727. if (typeof global[process.pid].pkijs === "undefined") {
  6728. global[process.pid].pkijs = {};
  6729. }
  6730. else {
  6731. if (typeof global[process.pid].pkijs !== "object") {
  6732. throw new Error(`Name global.${process.pid}.pkijs already exists and it is not an object`);
  6733. }
  6734. }
  6735. global[process.pid].pkijs.engine = {
  6736. name: name,
  6737. crypto,
  6738. };
  6739. }
  6740. else {
  6741. engine = {
  6742. name: name,
  6743. crypto,
  6744. };
  6745. }
  6746. }
  6747. function getEngine() {
  6748. if ((typeof process !== "undefined") && ("pid" in process) && (typeof global !== "undefined") && (typeof window === "undefined")) {
  6749. let _engine;
  6750. try {
  6751. _engine = global[process.pid].pkijs.engine;
  6752. }
  6753. catch {
  6754. throw new Error("Please call 'setEngine' before call to 'getEngine'");
  6755. }
  6756. return _engine;
  6757. }
  6758. return engine;
  6759. }
  6760. function getCrypto(safety = false) {
  6761. const _engine = getEngine();
  6762. if (!_engine.crypto && safety) {
  6763. throw new Error("Unable to create WebCrypto object");
  6764. }
  6765. return _engine.crypto;
  6766. }
  6767. function getRandomValues(view) {
  6768. return getCrypto(true).getRandomValues(view);
  6769. }
  6770. function getOIDByAlgorithm(algorithm, safety, target) {
  6771. return getCrypto(true).getOIDByAlgorithm(algorithm, safety, target);
  6772. }
  6773. function getAlgorithmParameters(algorithmName, operation) {
  6774. return getCrypto(true).getAlgorithmParameters(algorithmName, operation);
  6775. }
  6776. function createCMSECDSASignature(signatureBuffer) {
  6777. if ((signatureBuffer.byteLength % 2) !== 0)
  6778. return EMPTY_BUFFER;
  6779. const length = signatureBuffer.byteLength / 2;
  6780. const rBuffer = new ArrayBuffer(length);
  6781. const rView = new Uint8Array(rBuffer);
  6782. rView.set(new Uint8Array(signatureBuffer, 0, length));
  6783. const rInteger = new asn1js.Integer({ valueHex: rBuffer });
  6784. const sBuffer = new ArrayBuffer(length);
  6785. const sView = new Uint8Array(sBuffer);
  6786. sView.set(new Uint8Array(signatureBuffer, length, length));
  6787. const sInteger = new asn1js.Integer({ valueHex: sBuffer });
  6788. return (new asn1js.Sequence({
  6789. value: [
  6790. rInteger.convertToDER(),
  6791. sInteger.convertToDER()
  6792. ]
  6793. })).toBER(false);
  6794. }
  6795. function createECDSASignatureFromCMS(cmsSignature, pointSize) {
  6796. if (!(cmsSignature instanceof asn1js.Sequence
  6797. && cmsSignature.valueBlock.value.length === 2
  6798. && cmsSignature.valueBlock.value[0] instanceof asn1js.Integer
  6799. && cmsSignature.valueBlock.value[1] instanceof asn1js.Integer))
  6800. return EMPTY_BUFFER;
  6801. const rValueView = cmsSignature.valueBlock.value[0].convertFromDER().valueBlock.valueHexView;
  6802. const sValueView = cmsSignature.valueBlock.value[1].convertFromDER().valueBlock.valueHexView;
  6803. const res = new Uint8Array(pointSize * 2);
  6804. res.set(rValueView, pointSize - rValueView.byteLength);
  6805. res.set(sValueView, (2 * pointSize) - sValueView.byteLength);
  6806. return res.buffer;
  6807. }
  6808. function getAlgorithmByOID(oid, safety = false, target) {
  6809. return getCrypto(true).getAlgorithmByOID(oid, safety, target);
  6810. }
  6811. function getHashAlgorithm(signatureAlgorithm) {
  6812. return getCrypto(true).getHashAlgorithm(signatureAlgorithm);
  6813. }
  6814. async function kdfWithCounter(hashFunction, zBuffer, Counter, SharedInfo, crypto) {
  6815. switch (hashFunction.toUpperCase()) {
  6816. case "SHA-1":
  6817. case "SHA-256":
  6818. case "SHA-384":
  6819. case "SHA-512":
  6820. break;
  6821. default:
  6822. throw new ArgumentError(`Unknown hash function: ${hashFunction}`);
  6823. }
  6824. ArgumentError.assert(zBuffer, "zBuffer", "ArrayBuffer");
  6825. if (zBuffer.byteLength === 0)
  6826. throw new ArgumentError("'zBuffer' has zero length, error");
  6827. ArgumentError.assert(SharedInfo, "SharedInfo", "ArrayBuffer");
  6828. if (Counter > 255)
  6829. throw new ArgumentError("Please set 'Counter' argument to value less or equal to 255");
  6830. const counterBuffer = new ArrayBuffer(4);
  6831. const counterView = new Uint8Array(counterBuffer);
  6832. counterView[0] = 0x00;
  6833. counterView[1] = 0x00;
  6834. counterView[2] = 0x00;
  6835. counterView[3] = Counter;
  6836. let combinedBuffer = EMPTY_BUFFER;
  6837. combinedBuffer = pvutils.utilConcatBuf(combinedBuffer, zBuffer);
  6838. combinedBuffer = pvutils.utilConcatBuf(combinedBuffer, counterBuffer);
  6839. combinedBuffer = pvutils.utilConcatBuf(combinedBuffer, SharedInfo);
  6840. const result = await crypto.digest({ name: hashFunction }, combinedBuffer);
  6841. return {
  6842. counter: Counter,
  6843. result
  6844. };
  6845. }
  6846. async function kdf(hashFunction, Zbuffer, keydatalen, SharedInfo, crypto = getCrypto(true)) {
  6847. let hashLength = 0;
  6848. let maxCounter = 1;
  6849. switch (hashFunction.toUpperCase()) {
  6850. case "SHA-1":
  6851. hashLength = 160;
  6852. break;
  6853. case "SHA-256":
  6854. hashLength = 256;
  6855. break;
  6856. case "SHA-384":
  6857. hashLength = 384;
  6858. break;
  6859. case "SHA-512":
  6860. hashLength = 512;
  6861. break;
  6862. default:
  6863. throw new ArgumentError(`Unknown hash function: ${hashFunction}`);
  6864. }
  6865. ArgumentError.assert(Zbuffer, "Zbuffer", "ArrayBuffer");
  6866. if (Zbuffer.byteLength === 0)
  6867. throw new ArgumentError("'Zbuffer' has zero length, error");
  6868. ArgumentError.assert(SharedInfo, "SharedInfo", "ArrayBuffer");
  6869. const quotient = keydatalen / hashLength;
  6870. if (Math.floor(quotient) > 0) {
  6871. maxCounter = Math.floor(quotient);
  6872. if ((quotient - maxCounter) > 0)
  6873. maxCounter++;
  6874. }
  6875. const incomingResult = [];
  6876. for (let i = 1; i <= maxCounter; i++)
  6877. incomingResult.push(await kdfWithCounter(hashFunction, Zbuffer, i, SharedInfo, crypto));
  6878. let combinedBuffer = EMPTY_BUFFER;
  6879. let currentCounter = 1;
  6880. let found = true;
  6881. while (found) {
  6882. found = false;
  6883. for (const result of incomingResult) {
  6884. if (result.counter === currentCounter) {
  6885. combinedBuffer = pvutils.utilConcatBuf(combinedBuffer, result.result);
  6886. found = true;
  6887. break;
  6888. }
  6889. }
  6890. currentCounter++;
  6891. }
  6892. keydatalen >>= 3;
  6893. if (combinedBuffer.byteLength > keydatalen) {
  6894. const newBuffer = new ArrayBuffer(keydatalen);
  6895. const newView = new Uint8Array(newBuffer);
  6896. const combinedView = new Uint8Array(combinedBuffer);
  6897. for (let i = 0; i < keydatalen; i++)
  6898. newView[i] = combinedView[i];
  6899. return newBuffer;
  6900. }
  6901. return combinedBuffer;
  6902. }
  6903. const VERSION$i = "version";
  6904. const LOG_ID = "logID";
  6905. const EXTENSIONS$6 = "extensions";
  6906. const TIMESTAMP = "timestamp";
  6907. const HASH_ALGORITHM$3 = "hashAlgorithm";
  6908. const SIGNATURE_ALGORITHM$8 = "signatureAlgorithm";
  6909. const SIGNATURE$7 = "signature";
  6910. const NONE = "none";
  6911. const MD5 = "md5";
  6912. const SHA1 = "sha1";
  6913. const SHA224 = "sha224";
  6914. const SHA256 = "sha256";
  6915. const SHA384 = "sha384";
  6916. const SHA512 = "sha512";
  6917. const ANONYMOUS = "anonymous";
  6918. const RSA = "rsa";
  6919. const DSA = "dsa";
  6920. const ECDSA = "ecdsa";
  6921. class SignedCertificateTimestamp extends PkiObject {
  6922. constructor(parameters = {}) {
  6923. super();
  6924. this.version = pvutils.getParametersValue(parameters, VERSION$i, SignedCertificateTimestamp.defaultValues(VERSION$i));
  6925. this.logID = pvutils.getParametersValue(parameters, LOG_ID, SignedCertificateTimestamp.defaultValues(LOG_ID));
  6926. this.timestamp = pvutils.getParametersValue(parameters, TIMESTAMP, SignedCertificateTimestamp.defaultValues(TIMESTAMP));
  6927. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$6, SignedCertificateTimestamp.defaultValues(EXTENSIONS$6));
  6928. this.hashAlgorithm = pvutils.getParametersValue(parameters, HASH_ALGORITHM$3, SignedCertificateTimestamp.defaultValues(HASH_ALGORITHM$3));
  6929. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$8, SignedCertificateTimestamp.defaultValues(SIGNATURE_ALGORITHM$8));
  6930. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$7, SignedCertificateTimestamp.defaultValues(SIGNATURE$7));
  6931. if ("stream" in parameters && parameters.stream) {
  6932. this.fromStream(parameters.stream);
  6933. }
  6934. if (parameters.schema) {
  6935. this.fromSchema(parameters.schema);
  6936. }
  6937. }
  6938. static defaultValues(memberName) {
  6939. switch (memberName) {
  6940. case VERSION$i:
  6941. return 0;
  6942. case LOG_ID:
  6943. case EXTENSIONS$6:
  6944. return EMPTY_BUFFER;
  6945. case TIMESTAMP:
  6946. return new Date(0);
  6947. case HASH_ALGORITHM$3:
  6948. case SIGNATURE_ALGORITHM$8:
  6949. return EMPTY_STRING;
  6950. case SIGNATURE$7:
  6951. return EMPTY_BUFFER;
  6952. default:
  6953. return super.defaultValues(memberName);
  6954. }
  6955. }
  6956. fromSchema(schema) {
  6957. if ((schema instanceof asn1js.RawData) === false)
  6958. throw new Error("Object's schema was not verified against input data for SignedCertificateTimestamp");
  6959. const seqStream = new bs.SeqStream({
  6960. stream: new bs.ByteStream({
  6961. buffer: schema.data
  6962. })
  6963. });
  6964. this.fromStream(seqStream);
  6965. }
  6966. fromStream(stream) {
  6967. const blockLength = stream.getUint16();
  6968. this.version = (stream.getBlock(1))[0];
  6969. if (this.version === 0) {
  6970. this.logID = (new Uint8Array(stream.getBlock(32))).buffer.slice(0);
  6971. this.timestamp = new Date(pvutils.utilFromBase(new Uint8Array(stream.getBlock(8)), 8));
  6972. const extensionsLength = stream.getUint16();
  6973. this.extensions = (new Uint8Array(stream.getBlock(extensionsLength))).buffer.slice(0);
  6974. switch ((stream.getBlock(1))[0]) {
  6975. case 0:
  6976. this.hashAlgorithm = NONE;
  6977. break;
  6978. case 1:
  6979. this.hashAlgorithm = MD5;
  6980. break;
  6981. case 2:
  6982. this.hashAlgorithm = SHA1;
  6983. break;
  6984. case 3:
  6985. this.hashAlgorithm = SHA224;
  6986. break;
  6987. case 4:
  6988. this.hashAlgorithm = SHA256;
  6989. break;
  6990. case 5:
  6991. this.hashAlgorithm = SHA384;
  6992. break;
  6993. case 6:
  6994. this.hashAlgorithm = SHA512;
  6995. break;
  6996. default:
  6997. throw new Error("Object's stream was not correct for SignedCertificateTimestamp");
  6998. }
  6999. switch ((stream.getBlock(1))[0]) {
  7000. case 0:
  7001. this.signatureAlgorithm = ANONYMOUS;
  7002. break;
  7003. case 1:
  7004. this.signatureAlgorithm = RSA;
  7005. break;
  7006. case 2:
  7007. this.signatureAlgorithm = DSA;
  7008. break;
  7009. case 3:
  7010. this.signatureAlgorithm = ECDSA;
  7011. break;
  7012. default:
  7013. throw new Error("Object's stream was not correct for SignedCertificateTimestamp");
  7014. }
  7015. const signatureLength = stream.getUint16();
  7016. this.signature = new Uint8Array(stream.getBlock(signatureLength)).buffer.slice(0);
  7017. if (blockLength !== (47 + extensionsLength + signatureLength)) {
  7018. throw new Error("Object's stream was not correct for SignedCertificateTimestamp");
  7019. }
  7020. }
  7021. }
  7022. toSchema() {
  7023. const stream = this.toStream();
  7024. return new asn1js.RawData({ data: stream.stream.buffer });
  7025. }
  7026. toStream() {
  7027. const stream = new bs.SeqStream();
  7028. stream.appendUint16(47 + this.extensions.byteLength + this.signature.byteLength);
  7029. stream.appendChar(this.version);
  7030. stream.appendView(new Uint8Array(this.logID));
  7031. const timeBuffer = new ArrayBuffer(8);
  7032. const timeView = new Uint8Array(timeBuffer);
  7033. const baseArray = pvutils.utilToBase(this.timestamp.valueOf(), 8);
  7034. timeView.set(new Uint8Array(baseArray), 8 - baseArray.byteLength);
  7035. stream.appendView(timeView);
  7036. stream.appendUint16(this.extensions.byteLength);
  7037. if (this.extensions.byteLength)
  7038. stream.appendView(new Uint8Array(this.extensions));
  7039. let _hashAlgorithm;
  7040. switch (this.hashAlgorithm.toLowerCase()) {
  7041. case NONE:
  7042. _hashAlgorithm = 0;
  7043. break;
  7044. case MD5:
  7045. _hashAlgorithm = 1;
  7046. break;
  7047. case SHA1:
  7048. _hashAlgorithm = 2;
  7049. break;
  7050. case SHA224:
  7051. _hashAlgorithm = 3;
  7052. break;
  7053. case SHA256:
  7054. _hashAlgorithm = 4;
  7055. break;
  7056. case SHA384:
  7057. _hashAlgorithm = 5;
  7058. break;
  7059. case SHA512:
  7060. _hashAlgorithm = 6;
  7061. break;
  7062. default:
  7063. throw new Error(`Incorrect data for hashAlgorithm: ${this.hashAlgorithm}`);
  7064. }
  7065. stream.appendChar(_hashAlgorithm);
  7066. let _signatureAlgorithm;
  7067. switch (this.signatureAlgorithm.toLowerCase()) {
  7068. case ANONYMOUS:
  7069. _signatureAlgorithm = 0;
  7070. break;
  7071. case RSA:
  7072. _signatureAlgorithm = 1;
  7073. break;
  7074. case DSA:
  7075. _signatureAlgorithm = 2;
  7076. break;
  7077. case ECDSA:
  7078. _signatureAlgorithm = 3;
  7079. break;
  7080. default:
  7081. throw new Error(`Incorrect data for signatureAlgorithm: ${this.signatureAlgorithm}`);
  7082. }
  7083. stream.appendChar(_signatureAlgorithm);
  7084. stream.appendUint16(this.signature.byteLength);
  7085. stream.appendView(new Uint8Array(this.signature));
  7086. return stream;
  7087. }
  7088. toJSON() {
  7089. return {
  7090. version: this.version,
  7091. logID: pvutils.bufferToHexCodes(this.logID),
  7092. timestamp: this.timestamp,
  7093. extensions: pvutils.bufferToHexCodes(this.extensions),
  7094. hashAlgorithm: this.hashAlgorithm,
  7095. signatureAlgorithm: this.signatureAlgorithm,
  7096. signature: pvutils.bufferToHexCodes(this.signature),
  7097. };
  7098. }
  7099. async verify(logs, data, dataType = 0, crypto = getCrypto(true)) {
  7100. const logId = pvutils.toBase64(pvutils.arrayBufferToString(this.logID));
  7101. let publicKeyBase64 = null;
  7102. const stream = new bs.SeqStream();
  7103. for (const log of logs) {
  7104. if (log.log_id === logId) {
  7105. publicKeyBase64 = log.key;
  7106. break;
  7107. }
  7108. }
  7109. if (!publicKeyBase64) {
  7110. throw new Error(`Public key not found for CT with logId: ${logId}`);
  7111. }
  7112. const pki = pvutils.stringToArrayBuffer(pvutils.fromBase64(publicKeyBase64));
  7113. const publicKeyInfo = PublicKeyInfo.fromBER(pki);
  7114. stream.appendChar(0x00);
  7115. stream.appendChar(0x00);
  7116. const timeBuffer = new ArrayBuffer(8);
  7117. const timeView = new Uint8Array(timeBuffer);
  7118. const baseArray = pvutils.utilToBase(this.timestamp.valueOf(), 8);
  7119. timeView.set(new Uint8Array(baseArray), 8 - baseArray.byteLength);
  7120. stream.appendView(timeView);
  7121. stream.appendUint16(dataType);
  7122. if (dataType === 0)
  7123. stream.appendUint24(data.byteLength);
  7124. stream.appendView(new Uint8Array(data));
  7125. stream.appendUint16(this.extensions.byteLength);
  7126. if (this.extensions.byteLength !== 0)
  7127. stream.appendView(new Uint8Array(this.extensions));
  7128. return crypto.verifyWithPublicKey(stream.buffer.slice(0, stream.length), new asn1js.OctetString({ valueHex: this.signature }), publicKeyInfo, { algorithmId: EMPTY_STRING }, "SHA-256");
  7129. }
  7130. }
  7131. SignedCertificateTimestamp.CLASS_NAME = "SignedCertificateTimestamp";
  7132. async function verifySCTsForCertificate(certificate, issuerCertificate, logs, index = (-1), crypto = getCrypto(true)) {
  7133. let parsedValue = null;
  7134. const stream = new bs.SeqStream();
  7135. if (certificate.extensions) {
  7136. for (let i = certificate.extensions.length - 1; i >= 0; i--) {
  7137. switch (certificate.extensions[i].extnID) {
  7138. case id_SignedCertificateTimestampList:
  7139. {
  7140. parsedValue = certificate.extensions[i].parsedValue;
  7141. if (!parsedValue || parsedValue.timestamps.length === 0)
  7142. throw new Error("Nothing to verify in the certificate");
  7143. certificate.extensions.splice(i, 1);
  7144. }
  7145. break;
  7146. }
  7147. }
  7148. }
  7149. if (parsedValue === null)
  7150. throw new Error("No SignedCertificateTimestampList extension in the specified certificate");
  7151. const tbs = certificate.encodeTBS().toBER();
  7152. const issuerId = await crypto.digest({ name: "SHA-256" }, new Uint8Array(issuerCertificate.subjectPublicKeyInfo.toSchema().toBER(false)));
  7153. stream.appendView(new Uint8Array(issuerId));
  7154. stream.appendUint24(tbs.byteLength);
  7155. stream.appendView(new Uint8Array(tbs));
  7156. const preCert = stream.stream.slice(0, stream.length);
  7157. if (index === (-1)) {
  7158. const verifyArray = [];
  7159. for (const timestamp of parsedValue.timestamps) {
  7160. const verifyResult = await timestamp.verify(logs, preCert.buffer, 1, crypto);
  7161. verifyArray.push(verifyResult);
  7162. }
  7163. return verifyArray;
  7164. }
  7165. if (index >= parsedValue.timestamps.length)
  7166. index = (parsedValue.timestamps.length - 1);
  7167. return [await parsedValue.timestamps[index].verify(logs, preCert.buffer, 1, crypto)];
  7168. }
  7169. const TIMESTAMPS = "timestamps";
  7170. class SignedCertificateTimestampList extends PkiObject {
  7171. constructor(parameters = {}) {
  7172. super();
  7173. this.timestamps = pvutils.getParametersValue(parameters, TIMESTAMPS, SignedCertificateTimestampList.defaultValues(TIMESTAMPS));
  7174. if (parameters.schema) {
  7175. this.fromSchema(parameters.schema);
  7176. }
  7177. }
  7178. static defaultValues(memberName) {
  7179. switch (memberName) {
  7180. case TIMESTAMPS:
  7181. return [];
  7182. default:
  7183. return super.defaultValues(memberName);
  7184. }
  7185. }
  7186. static compareWithDefault(memberName, memberValue) {
  7187. switch (memberName) {
  7188. case TIMESTAMPS:
  7189. return (memberValue.length === 0);
  7190. default:
  7191. return super.defaultValues(memberName);
  7192. }
  7193. }
  7194. static schema(parameters = {}) {
  7195. var _a;
  7196. const names = pvutils.getParametersValue(parameters, "names", {});
  7197. (_a = names.optional) !== null && _a !== void 0 ? _a : (names.optional = false);
  7198. return (new asn1js.OctetString({
  7199. name: (names.blockName || "SignedCertificateTimestampList"),
  7200. optional: names.optional
  7201. }));
  7202. }
  7203. fromSchema(schema) {
  7204. if ((schema instanceof asn1js.OctetString) === false) {
  7205. throw new Error("Object's schema was not verified against input data for SignedCertificateTimestampList");
  7206. }
  7207. const seqStream = new bs.SeqStream({
  7208. stream: new bs.ByteStream({
  7209. buffer: schema.valueBlock.valueHex
  7210. })
  7211. });
  7212. const dataLength = seqStream.getUint16();
  7213. if (dataLength !== seqStream.length) {
  7214. throw new Error("Object's schema was not verified against input data for SignedCertificateTimestampList");
  7215. }
  7216. while (seqStream.length) {
  7217. this.timestamps.push(new SignedCertificateTimestamp({ stream: seqStream }));
  7218. }
  7219. }
  7220. toSchema() {
  7221. const stream = new bs.SeqStream();
  7222. let overallLength = 0;
  7223. const timestampsData = [];
  7224. for (const timestamp of this.timestamps) {
  7225. const timestampStream = timestamp.toStream();
  7226. timestampsData.push(timestampStream);
  7227. overallLength += timestampStream.stream.buffer.byteLength;
  7228. }
  7229. stream.appendUint16(overallLength);
  7230. for (const timestamp of timestampsData) {
  7231. stream.appendView(timestamp.stream.view);
  7232. }
  7233. return new asn1js.OctetString({ valueHex: stream.stream.buffer.slice(0) });
  7234. }
  7235. toJSON() {
  7236. return {
  7237. timestamps: Array.from(this.timestamps, o => o.toJSON())
  7238. };
  7239. }
  7240. }
  7241. SignedCertificateTimestampList.CLASS_NAME = "SignedCertificateTimestampList";
  7242. const ATTRIBUTES$4 = "attributes";
  7243. const CLEAR_PROPS$11 = [
  7244. ATTRIBUTES$4
  7245. ];
  7246. class SubjectDirectoryAttributes extends PkiObject {
  7247. constructor(parameters = {}) {
  7248. super();
  7249. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES$4, SubjectDirectoryAttributes.defaultValues(ATTRIBUTES$4));
  7250. if (parameters.schema) {
  7251. this.fromSchema(parameters.schema);
  7252. }
  7253. }
  7254. static defaultValues(memberName) {
  7255. switch (memberName) {
  7256. case ATTRIBUTES$4:
  7257. return [];
  7258. default:
  7259. return super.defaultValues(memberName);
  7260. }
  7261. }
  7262. static schema(parameters = {}) {
  7263. const names = pvutils.getParametersValue(parameters, "names", {});
  7264. return (new asn1js.Sequence({
  7265. name: (names.blockName || EMPTY_STRING),
  7266. value: [
  7267. new asn1js.Repeated({
  7268. name: (names.attributes || EMPTY_STRING),
  7269. value: Attribute.schema()
  7270. })
  7271. ]
  7272. }));
  7273. }
  7274. fromSchema(schema) {
  7275. pvutils.clearProps(schema, CLEAR_PROPS$11);
  7276. const asn1 = asn1js.compareSchema(schema, schema, SubjectDirectoryAttributes.schema({
  7277. names: {
  7278. attributes: ATTRIBUTES$4
  7279. }
  7280. }));
  7281. AsnError.assertSchema(asn1, this.className);
  7282. this.attributes = Array.from(asn1.result.attributes, element => new Attribute({ schema: element }));
  7283. }
  7284. toSchema() {
  7285. return (new asn1js.Sequence({
  7286. value: Array.from(this.attributes, o => o.toSchema())
  7287. }));
  7288. }
  7289. toJSON() {
  7290. return {
  7291. attributes: Array.from(this.attributes, o => o.toJSON())
  7292. };
  7293. }
  7294. }
  7295. SubjectDirectoryAttributes.CLASS_NAME = "SubjectDirectoryAttributes";
  7296. class ExtensionValueFactory {
  7297. static getItems() {
  7298. if (!this.types) {
  7299. this.types = {};
  7300. ExtensionValueFactory.register(id_SubjectAltName, "SubjectAltName", AltName);
  7301. ExtensionValueFactory.register(id_IssuerAltName, "IssuerAltName", AltName);
  7302. ExtensionValueFactory.register(id_AuthorityKeyIdentifier, "AuthorityKeyIdentifier", AuthorityKeyIdentifier);
  7303. ExtensionValueFactory.register(id_BasicConstraints, "BasicConstraints", BasicConstraints);
  7304. ExtensionValueFactory.register(id_MicrosoftCaVersion, "MicrosoftCaVersion", CAVersion);
  7305. ExtensionValueFactory.register(id_CertificatePolicies, "CertificatePolicies", CertificatePolicies);
  7306. ExtensionValueFactory.register(id_MicrosoftAppPolicies, "CertificatePoliciesMicrosoft", CertificatePolicies);
  7307. ExtensionValueFactory.register(id_MicrosoftCertTemplateV2, "MicrosoftCertTemplateV2", CertificateTemplate);
  7308. ExtensionValueFactory.register(id_CRLDistributionPoints, "CRLDistributionPoints", CRLDistributionPoints);
  7309. ExtensionValueFactory.register(id_FreshestCRL, "FreshestCRL", CRLDistributionPoints);
  7310. ExtensionValueFactory.register(id_ExtKeyUsage, "ExtKeyUsage", ExtKeyUsage);
  7311. ExtensionValueFactory.register(id_CertificateIssuer, "CertificateIssuer", GeneralNames);
  7312. ExtensionValueFactory.register(id_AuthorityInfoAccess, "AuthorityInfoAccess", InfoAccess);
  7313. ExtensionValueFactory.register(id_SubjectInfoAccess, "SubjectInfoAccess", InfoAccess);
  7314. ExtensionValueFactory.register(id_IssuingDistributionPoint, "IssuingDistributionPoint", IssuingDistributionPoint);
  7315. ExtensionValueFactory.register(id_NameConstraints, "NameConstraints", NameConstraints);
  7316. ExtensionValueFactory.register(id_PolicyConstraints, "PolicyConstraints", PolicyConstraints);
  7317. ExtensionValueFactory.register(id_PolicyMappings, "PolicyMappings", PolicyMappings);
  7318. ExtensionValueFactory.register(id_PrivateKeyUsagePeriod, "PrivateKeyUsagePeriod", PrivateKeyUsagePeriod);
  7319. ExtensionValueFactory.register(id_QCStatements, "QCStatements", QCStatements);
  7320. ExtensionValueFactory.register(id_SignedCertificateTimestampList, "SignedCertificateTimestampList", SignedCertificateTimestampList);
  7321. ExtensionValueFactory.register(id_SubjectDirectoryAttributes, "SubjectDirectoryAttributes", SubjectDirectoryAttributes);
  7322. }
  7323. return this.types;
  7324. }
  7325. static fromBER(id, raw) {
  7326. const asn1 = asn1js.fromBER(raw);
  7327. if (asn1.offset === -1) {
  7328. return null;
  7329. }
  7330. const item = this.find(id);
  7331. if (item) {
  7332. try {
  7333. return new item.type({ schema: asn1.result });
  7334. }
  7335. catch {
  7336. const res = new item.type();
  7337. res.parsingError = `Incorrectly formatted value of extension ${item.name} (${id})`;
  7338. return res;
  7339. }
  7340. }
  7341. return asn1.result;
  7342. }
  7343. static find(id) {
  7344. const types = this.getItems();
  7345. return types[id] || null;
  7346. }
  7347. static register(id, name, type) {
  7348. this.getItems()[id] = { name, type };
  7349. }
  7350. }
  7351. const EXTN_ID = "extnID";
  7352. const CRITICAL = "critical";
  7353. const EXTN_VALUE = "extnValue";
  7354. const PARSED_VALUE$5 = "parsedValue";
  7355. const CLEAR_PROPS$10 = [
  7356. EXTN_ID,
  7357. CRITICAL,
  7358. EXTN_VALUE
  7359. ];
  7360. class Extension extends PkiObject {
  7361. get parsedValue() {
  7362. if (this._parsedValue === undefined) {
  7363. const parsedValue = ExtensionValueFactory.fromBER(this.extnID, this.extnValue.valueBlock.valueHexView);
  7364. this._parsedValue = parsedValue;
  7365. }
  7366. return this._parsedValue || undefined;
  7367. }
  7368. set parsedValue(value) {
  7369. this._parsedValue = value;
  7370. }
  7371. constructor(parameters = {}) {
  7372. super();
  7373. this.extnID = pvutils.getParametersValue(parameters, EXTN_ID, Extension.defaultValues(EXTN_ID));
  7374. this.critical = pvutils.getParametersValue(parameters, CRITICAL, Extension.defaultValues(CRITICAL));
  7375. if (EXTN_VALUE in parameters) {
  7376. this.extnValue = new asn1js.OctetString({ valueHex: parameters.extnValue });
  7377. }
  7378. else {
  7379. this.extnValue = Extension.defaultValues(EXTN_VALUE);
  7380. }
  7381. if (PARSED_VALUE$5 in parameters) {
  7382. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE$5, Extension.defaultValues(PARSED_VALUE$5));
  7383. }
  7384. if (parameters.schema) {
  7385. this.fromSchema(parameters.schema);
  7386. }
  7387. }
  7388. static defaultValues(memberName) {
  7389. switch (memberName) {
  7390. case EXTN_ID:
  7391. return EMPTY_STRING;
  7392. case CRITICAL:
  7393. return false;
  7394. case EXTN_VALUE:
  7395. return new asn1js.OctetString();
  7396. case PARSED_VALUE$5:
  7397. return {};
  7398. default:
  7399. return super.defaultValues(memberName);
  7400. }
  7401. }
  7402. static schema(parameters = {}) {
  7403. const names = pvutils.getParametersValue(parameters, "names", {});
  7404. return (new asn1js.Sequence({
  7405. name: (names.blockName || EMPTY_STRING),
  7406. value: [
  7407. new asn1js.ObjectIdentifier({ name: (names.extnID || EMPTY_STRING) }),
  7408. new asn1js.Boolean({
  7409. name: (names.critical || EMPTY_STRING),
  7410. optional: true
  7411. }),
  7412. new asn1js.OctetString({ name: (names.extnValue || EMPTY_STRING) })
  7413. ]
  7414. }));
  7415. }
  7416. fromSchema(schema) {
  7417. pvutils.clearProps(schema, CLEAR_PROPS$10);
  7418. const asn1 = asn1js.compareSchema(schema, schema, Extension.schema({
  7419. names: {
  7420. extnID: EXTN_ID,
  7421. critical: CRITICAL,
  7422. extnValue: EXTN_VALUE
  7423. }
  7424. }));
  7425. AsnError.assertSchema(asn1, this.className);
  7426. this.extnID = asn1.result.extnID.valueBlock.toString();
  7427. if (CRITICAL in asn1.result) {
  7428. this.critical = asn1.result.critical.valueBlock.value;
  7429. }
  7430. this.extnValue = asn1.result.extnValue;
  7431. }
  7432. toSchema() {
  7433. const outputArray = [];
  7434. outputArray.push(new asn1js.ObjectIdentifier({ value: this.extnID }));
  7435. if (this.critical !== Extension.defaultValues(CRITICAL)) {
  7436. outputArray.push(new asn1js.Boolean({ value: this.critical }));
  7437. }
  7438. outputArray.push(this.extnValue);
  7439. return (new asn1js.Sequence({
  7440. value: outputArray
  7441. }));
  7442. }
  7443. toJSON() {
  7444. const object = {
  7445. extnID: this.extnID,
  7446. extnValue: this.extnValue.toJSON(),
  7447. };
  7448. if (this.critical !== Extension.defaultValues(CRITICAL)) {
  7449. object.critical = this.critical;
  7450. }
  7451. if (this.parsedValue && this.parsedValue.toJSON) {
  7452. object.parsedValue = this.parsedValue.toJSON();
  7453. }
  7454. return object;
  7455. }
  7456. }
  7457. Extension.CLASS_NAME = "Extension";
  7458. const EXTENSIONS$5 = "extensions";
  7459. const CLEAR_PROPS$$ = [
  7460. EXTENSIONS$5,
  7461. ];
  7462. class Extensions extends PkiObject {
  7463. constructor(parameters = {}) {
  7464. super();
  7465. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$5, Extensions.defaultValues(EXTENSIONS$5));
  7466. if (parameters.schema) {
  7467. this.fromSchema(parameters.schema);
  7468. }
  7469. }
  7470. static defaultValues(memberName) {
  7471. switch (memberName) {
  7472. case EXTENSIONS$5:
  7473. return [];
  7474. default:
  7475. return super.defaultValues(memberName);
  7476. }
  7477. }
  7478. static schema(parameters = {}, optional = false) {
  7479. const names = pvutils.getParametersValue(parameters, "names", {});
  7480. return (new asn1js.Sequence({
  7481. optional,
  7482. name: (names.blockName || EMPTY_STRING),
  7483. value: [
  7484. new asn1js.Repeated({
  7485. name: (names.extensions || EMPTY_STRING),
  7486. value: Extension.schema(names.extension || {})
  7487. })
  7488. ]
  7489. }));
  7490. }
  7491. fromSchema(schema) {
  7492. pvutils.clearProps(schema, CLEAR_PROPS$$);
  7493. const asn1 = asn1js.compareSchema(schema, schema, Extensions.schema({
  7494. names: {
  7495. extensions: EXTENSIONS$5
  7496. }
  7497. }));
  7498. AsnError.assertSchema(asn1, this.className);
  7499. this.extensions = Array.from(asn1.result.extensions, element => new Extension({ schema: element }));
  7500. }
  7501. toSchema() {
  7502. return (new asn1js.Sequence({
  7503. value: Array.from(this.extensions, o => o.toSchema())
  7504. }));
  7505. }
  7506. toJSON() {
  7507. return {
  7508. extensions: this.extensions.map(o => o.toJSON())
  7509. };
  7510. }
  7511. }
  7512. Extensions.CLASS_NAME = "Extensions";
  7513. const ISSUER$5 = "issuer";
  7514. const SERIAL_NUMBER$6 = "serialNumber";
  7515. const ISSUER_UID = "issuerUID";
  7516. const CLEAR_PROPS$_ = [
  7517. ISSUER$5,
  7518. SERIAL_NUMBER$6,
  7519. ISSUER_UID,
  7520. ];
  7521. class IssuerSerial extends PkiObject {
  7522. constructor(parameters = {}) {
  7523. super();
  7524. this.issuer = pvutils.getParametersValue(parameters, ISSUER$5, IssuerSerial.defaultValues(ISSUER$5));
  7525. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$6, IssuerSerial.defaultValues(SERIAL_NUMBER$6));
  7526. if (ISSUER_UID in parameters) {
  7527. this.issuerUID = pvutils.getParametersValue(parameters, ISSUER_UID, IssuerSerial.defaultValues(ISSUER_UID));
  7528. }
  7529. if (parameters.schema) {
  7530. this.fromSchema(parameters.schema);
  7531. }
  7532. }
  7533. static defaultValues(memberName) {
  7534. switch (memberName) {
  7535. case ISSUER$5:
  7536. return new GeneralNames();
  7537. case SERIAL_NUMBER$6:
  7538. return new asn1js.Integer();
  7539. case ISSUER_UID:
  7540. return new asn1js.BitString();
  7541. default:
  7542. return super.defaultValues(memberName);
  7543. }
  7544. }
  7545. static schema(parameters = {}) {
  7546. const names = pvutils.getParametersValue(parameters, "names", {});
  7547. return (new asn1js.Sequence({
  7548. name: (names.blockName || EMPTY_STRING),
  7549. value: [
  7550. GeneralNames.schema(names.issuer || {}),
  7551. new asn1js.Integer({ name: (names.serialNumber || EMPTY_STRING) }),
  7552. new asn1js.BitString({
  7553. optional: true,
  7554. name: (names.issuerUID || EMPTY_STRING)
  7555. })
  7556. ]
  7557. }));
  7558. }
  7559. fromSchema(schema) {
  7560. pvutils.clearProps(schema, CLEAR_PROPS$_);
  7561. const asn1 = asn1js.compareSchema(schema, schema, IssuerSerial.schema({
  7562. names: {
  7563. issuer: {
  7564. names: {
  7565. blockName: ISSUER$5
  7566. }
  7567. },
  7568. serialNumber: SERIAL_NUMBER$6,
  7569. issuerUID: ISSUER_UID
  7570. }
  7571. }));
  7572. AsnError.assertSchema(asn1, this.className);
  7573. this.issuer = new GeneralNames({ schema: asn1.result.issuer });
  7574. this.serialNumber = asn1.result.serialNumber;
  7575. if (ISSUER_UID in asn1.result)
  7576. this.issuerUID = asn1.result.issuerUID;
  7577. }
  7578. toSchema() {
  7579. const result = new asn1js.Sequence({
  7580. value: [
  7581. this.issuer.toSchema(),
  7582. this.serialNumber
  7583. ]
  7584. });
  7585. if (this.issuerUID) {
  7586. result.valueBlock.value.push(this.issuerUID);
  7587. }
  7588. return result;
  7589. }
  7590. toJSON() {
  7591. const result = {
  7592. issuer: this.issuer.toJSON(),
  7593. serialNumber: this.serialNumber.toJSON()
  7594. };
  7595. if (this.issuerUID) {
  7596. result.issuerUID = this.issuerUID.toJSON();
  7597. }
  7598. return result;
  7599. }
  7600. }
  7601. IssuerSerial.CLASS_NAME = "IssuerSerial";
  7602. const VERSION$h = "version";
  7603. const BASE_CERTIFICATE_ID$2 = "baseCertificateID";
  7604. const SUBJECT_NAME = "subjectName";
  7605. const ISSUER$4 = "issuer";
  7606. const SIGNATURE$6 = "signature";
  7607. const SERIAL_NUMBER$5 = "serialNumber";
  7608. const ATTR_CERT_VALIDITY_PERIOD$1 = "attrCertValidityPeriod";
  7609. const ATTRIBUTES$3 = "attributes";
  7610. const ISSUER_UNIQUE_ID$2 = "issuerUniqueID";
  7611. const EXTENSIONS$4 = "extensions";
  7612. const CLEAR_PROPS$Z = [
  7613. VERSION$h,
  7614. BASE_CERTIFICATE_ID$2,
  7615. SUBJECT_NAME,
  7616. ISSUER$4,
  7617. SIGNATURE$6,
  7618. SERIAL_NUMBER$5,
  7619. ATTR_CERT_VALIDITY_PERIOD$1,
  7620. ATTRIBUTES$3,
  7621. ISSUER_UNIQUE_ID$2,
  7622. EXTENSIONS$4,
  7623. ];
  7624. class AttributeCertificateInfoV1 extends PkiObject {
  7625. constructor(parameters = {}) {
  7626. super();
  7627. this.version = pvutils.getParametersValue(parameters, VERSION$h, AttributeCertificateInfoV1.defaultValues(VERSION$h));
  7628. if (BASE_CERTIFICATE_ID$2 in parameters) {
  7629. this.baseCertificateID = pvutils.getParametersValue(parameters, BASE_CERTIFICATE_ID$2, AttributeCertificateInfoV1.defaultValues(BASE_CERTIFICATE_ID$2));
  7630. }
  7631. if (SUBJECT_NAME in parameters) {
  7632. this.subjectName = pvutils.getParametersValue(parameters, SUBJECT_NAME, AttributeCertificateInfoV1.defaultValues(SUBJECT_NAME));
  7633. }
  7634. this.issuer = pvutils.getParametersValue(parameters, ISSUER$4, AttributeCertificateInfoV1.defaultValues(ISSUER$4));
  7635. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$6, AttributeCertificateInfoV1.defaultValues(SIGNATURE$6));
  7636. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$5, AttributeCertificateInfoV1.defaultValues(SERIAL_NUMBER$5));
  7637. this.attrCertValidityPeriod = pvutils.getParametersValue(parameters, ATTR_CERT_VALIDITY_PERIOD$1, AttributeCertificateInfoV1.defaultValues(ATTR_CERT_VALIDITY_PERIOD$1));
  7638. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES$3, AttributeCertificateInfoV1.defaultValues(ATTRIBUTES$3));
  7639. if (ISSUER_UNIQUE_ID$2 in parameters)
  7640. this.issuerUniqueID = pvutils.getParametersValue(parameters, ISSUER_UNIQUE_ID$2, AttributeCertificateInfoV1.defaultValues(ISSUER_UNIQUE_ID$2));
  7641. if (EXTENSIONS$4 in parameters) {
  7642. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$4, AttributeCertificateInfoV1.defaultValues(EXTENSIONS$4));
  7643. }
  7644. if (parameters.schema) {
  7645. this.fromSchema(parameters.schema);
  7646. }
  7647. }
  7648. static defaultValues(memberName) {
  7649. switch (memberName) {
  7650. case VERSION$h:
  7651. return 0;
  7652. case BASE_CERTIFICATE_ID$2:
  7653. return new IssuerSerial();
  7654. case SUBJECT_NAME:
  7655. return new GeneralNames();
  7656. case ISSUER$4:
  7657. return new GeneralNames();
  7658. case SIGNATURE$6:
  7659. return new AlgorithmIdentifier();
  7660. case SERIAL_NUMBER$5:
  7661. return new asn1js.Integer();
  7662. case ATTR_CERT_VALIDITY_PERIOD$1:
  7663. return new AttCertValidityPeriod();
  7664. case ATTRIBUTES$3:
  7665. return [];
  7666. case ISSUER_UNIQUE_ID$2:
  7667. return new asn1js.BitString();
  7668. case EXTENSIONS$4:
  7669. return new Extensions();
  7670. default:
  7671. return super.defaultValues(memberName);
  7672. }
  7673. }
  7674. static schema(parameters = {}) {
  7675. const names = pvutils.getParametersValue(parameters, "names", {});
  7676. return (new asn1js.Sequence({
  7677. name: (names.blockName || EMPTY_STRING),
  7678. value: [
  7679. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  7680. new asn1js.Choice({
  7681. value: [
  7682. new asn1js.Constructed({
  7683. name: (names.baseCertificateID || EMPTY_STRING),
  7684. idBlock: {
  7685. tagClass: 3,
  7686. tagNumber: 0
  7687. },
  7688. value: IssuerSerial.schema().valueBlock.value
  7689. }),
  7690. new asn1js.Constructed({
  7691. name: (names.subjectName || EMPTY_STRING),
  7692. idBlock: {
  7693. tagClass: 3,
  7694. tagNumber: 1
  7695. },
  7696. value: GeneralNames.schema().valueBlock.value
  7697. }),
  7698. ]
  7699. }),
  7700. GeneralNames.schema({
  7701. names: {
  7702. blockName: (names.issuer || EMPTY_STRING)
  7703. }
  7704. }),
  7705. AlgorithmIdentifier.schema(names.signature || {}),
  7706. new asn1js.Integer({ name: (names.serialNumber || EMPTY_STRING) }),
  7707. AttCertValidityPeriod.schema(names.attrCertValidityPeriod || {}),
  7708. new asn1js.Sequence({
  7709. name: (names.attributes || EMPTY_STRING),
  7710. value: [
  7711. new asn1js.Repeated({
  7712. value: Attribute.schema()
  7713. })
  7714. ]
  7715. }),
  7716. new asn1js.BitString({
  7717. optional: true,
  7718. name: (names.issuerUniqueID || EMPTY_STRING)
  7719. }),
  7720. Extensions.schema(names.extensions || {}, true)
  7721. ]
  7722. }));
  7723. }
  7724. fromSchema(schema) {
  7725. pvutils.clearProps(schema, CLEAR_PROPS$Z);
  7726. const asn1 = asn1js.compareSchema(schema, schema, AttributeCertificateInfoV1.schema({
  7727. names: {
  7728. version: VERSION$h,
  7729. baseCertificateID: BASE_CERTIFICATE_ID$2,
  7730. subjectName: SUBJECT_NAME,
  7731. issuer: ISSUER$4,
  7732. signature: {
  7733. names: {
  7734. blockName: SIGNATURE$6
  7735. }
  7736. },
  7737. serialNumber: SERIAL_NUMBER$5,
  7738. attrCertValidityPeriod: {
  7739. names: {
  7740. blockName: ATTR_CERT_VALIDITY_PERIOD$1
  7741. }
  7742. },
  7743. attributes: ATTRIBUTES$3,
  7744. issuerUniqueID: ISSUER_UNIQUE_ID$2,
  7745. extensions: {
  7746. names: {
  7747. blockName: EXTENSIONS$4
  7748. }
  7749. }
  7750. }
  7751. }));
  7752. AsnError.assertSchema(asn1, this.className);
  7753. this.version = asn1.result.version.valueBlock.valueDec;
  7754. if (BASE_CERTIFICATE_ID$2 in asn1.result) {
  7755. this.baseCertificateID = new IssuerSerial({
  7756. schema: new asn1js.Sequence({
  7757. value: asn1.result.baseCertificateID.valueBlock.value
  7758. })
  7759. });
  7760. }
  7761. if (SUBJECT_NAME in asn1.result) {
  7762. this.subjectName = new GeneralNames({
  7763. schema: new asn1js.Sequence({
  7764. value: asn1.result.subjectName.valueBlock.value
  7765. })
  7766. });
  7767. }
  7768. this.issuer = asn1.result.issuer;
  7769. this.signature = new AlgorithmIdentifier({ schema: asn1.result.signature });
  7770. this.serialNumber = asn1.result.serialNumber;
  7771. this.attrCertValidityPeriod = new AttCertValidityPeriod({ schema: asn1.result.attrCertValidityPeriod });
  7772. this.attributes = Array.from(asn1.result.attributes.valueBlock.value, element => new Attribute({ schema: element }));
  7773. if (ISSUER_UNIQUE_ID$2 in asn1.result) {
  7774. this.issuerUniqueID = asn1.result.issuerUniqueID;
  7775. }
  7776. if (EXTENSIONS$4 in asn1.result) {
  7777. this.extensions = new Extensions({ schema: asn1.result.extensions });
  7778. }
  7779. }
  7780. toSchema() {
  7781. const result = new asn1js.Sequence({
  7782. value: [new asn1js.Integer({ value: this.version })]
  7783. });
  7784. if (this.baseCertificateID) {
  7785. result.valueBlock.value.push(new asn1js.Constructed({
  7786. idBlock: {
  7787. tagClass: 3,
  7788. tagNumber: 0
  7789. },
  7790. value: this.baseCertificateID.toSchema().valueBlock.value
  7791. }));
  7792. }
  7793. if (this.subjectName) {
  7794. result.valueBlock.value.push(new asn1js.Constructed({
  7795. idBlock: {
  7796. tagClass: 3,
  7797. tagNumber: 1
  7798. },
  7799. value: this.subjectName.toSchema().valueBlock.value
  7800. }));
  7801. }
  7802. result.valueBlock.value.push(this.issuer.toSchema());
  7803. result.valueBlock.value.push(this.signature.toSchema());
  7804. result.valueBlock.value.push(this.serialNumber);
  7805. result.valueBlock.value.push(this.attrCertValidityPeriod.toSchema());
  7806. result.valueBlock.value.push(new asn1js.Sequence({
  7807. value: Array.from(this.attributes, o => o.toSchema())
  7808. }));
  7809. if (this.issuerUniqueID) {
  7810. result.valueBlock.value.push(this.issuerUniqueID);
  7811. }
  7812. if (this.extensions) {
  7813. result.valueBlock.value.push(this.extensions.toSchema());
  7814. }
  7815. return result;
  7816. }
  7817. toJSON() {
  7818. const result = {
  7819. version: this.version
  7820. };
  7821. if (this.baseCertificateID) {
  7822. result.baseCertificateID = this.baseCertificateID.toJSON();
  7823. }
  7824. if (this.subjectName) {
  7825. result.subjectName = this.subjectName.toJSON();
  7826. }
  7827. result.issuer = this.issuer.toJSON();
  7828. result.signature = this.signature.toJSON();
  7829. result.serialNumber = this.serialNumber.toJSON();
  7830. result.attrCertValidityPeriod = this.attrCertValidityPeriod.toJSON();
  7831. result.attributes = Array.from(this.attributes, o => o.toJSON());
  7832. if (this.issuerUniqueID) {
  7833. result.issuerUniqueID = this.issuerUniqueID.toJSON();
  7834. }
  7835. if (this.extensions) {
  7836. result.extensions = this.extensions.toJSON();
  7837. }
  7838. return result;
  7839. }
  7840. }
  7841. AttributeCertificateInfoV1.CLASS_NAME = "AttributeCertificateInfoV1";
  7842. const ACINFO$1 = "acinfo";
  7843. const SIGNATURE_ALGORITHM$7 = "signatureAlgorithm";
  7844. const SIGNATURE_VALUE$4 = "signatureValue";
  7845. const CLEAR_PROPS$Y = [
  7846. ACINFO$1,
  7847. SIGNATURE_VALUE$4,
  7848. SIGNATURE_ALGORITHM$7
  7849. ];
  7850. class AttributeCertificateV1 extends PkiObject {
  7851. constructor(parameters = {}) {
  7852. super();
  7853. this.acinfo = pvutils.getParametersValue(parameters, ACINFO$1, AttributeCertificateV1.defaultValues(ACINFO$1));
  7854. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$7, AttributeCertificateV1.defaultValues(SIGNATURE_ALGORITHM$7));
  7855. this.signatureValue = pvutils.getParametersValue(parameters, SIGNATURE_VALUE$4, AttributeCertificateV1.defaultValues(SIGNATURE_VALUE$4));
  7856. if (parameters.schema) {
  7857. this.fromSchema(parameters.schema);
  7858. }
  7859. }
  7860. static defaultValues(memberName) {
  7861. switch (memberName) {
  7862. case ACINFO$1:
  7863. return new AttributeCertificateInfoV1();
  7864. case SIGNATURE_ALGORITHM$7:
  7865. return new AlgorithmIdentifier();
  7866. case SIGNATURE_VALUE$4:
  7867. return new asn1js.BitString();
  7868. default:
  7869. return super.defaultValues(memberName);
  7870. }
  7871. }
  7872. static schema(parameters = {}) {
  7873. const names = pvutils.getParametersValue(parameters, "names", {});
  7874. return (new asn1js.Sequence({
  7875. name: (names.blockName || EMPTY_STRING),
  7876. value: [
  7877. AttributeCertificateInfoV1.schema(names.acinfo || {}),
  7878. AlgorithmIdentifier.schema(names.signatureAlgorithm || {}),
  7879. new asn1js.BitString({ name: (names.signatureValue || EMPTY_STRING) })
  7880. ]
  7881. }));
  7882. }
  7883. fromSchema(schema) {
  7884. pvutils.clearProps(schema, CLEAR_PROPS$Y);
  7885. const asn1 = asn1js.compareSchema(schema, schema, AttributeCertificateV1.schema({
  7886. names: {
  7887. acinfo: {
  7888. names: {
  7889. blockName: ACINFO$1
  7890. }
  7891. },
  7892. signatureAlgorithm: {
  7893. names: {
  7894. blockName: SIGNATURE_ALGORITHM$7
  7895. }
  7896. },
  7897. signatureValue: SIGNATURE_VALUE$4
  7898. }
  7899. }));
  7900. AsnError.assertSchema(asn1, this.className);
  7901. this.acinfo = new AttributeCertificateInfoV1({ schema: asn1.result.acinfo });
  7902. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  7903. this.signatureValue = asn1.result.signatureValue;
  7904. }
  7905. toSchema() {
  7906. return (new asn1js.Sequence({
  7907. value: [
  7908. this.acinfo.toSchema(),
  7909. this.signatureAlgorithm.toSchema(),
  7910. this.signatureValue
  7911. ]
  7912. }));
  7913. }
  7914. toJSON() {
  7915. return {
  7916. acinfo: this.acinfo.toJSON(),
  7917. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  7918. signatureValue: this.signatureValue.toJSON(),
  7919. };
  7920. }
  7921. }
  7922. AttributeCertificateV1.CLASS_NAME = "AttributeCertificateV1";
  7923. const DIGESTED_OBJECT_TYPE = "digestedObjectType";
  7924. const OTHER_OBJECT_TYPE_ID = "otherObjectTypeID";
  7925. const DIGEST_ALGORITHM$2 = "digestAlgorithm";
  7926. const OBJECT_DIGEST = "objectDigest";
  7927. const CLEAR_PROPS$X = [
  7928. DIGESTED_OBJECT_TYPE,
  7929. OTHER_OBJECT_TYPE_ID,
  7930. DIGEST_ALGORITHM$2,
  7931. OBJECT_DIGEST,
  7932. ];
  7933. class ObjectDigestInfo extends PkiObject {
  7934. constructor(parameters = {}) {
  7935. super();
  7936. this.digestedObjectType = pvutils.getParametersValue(parameters, DIGESTED_OBJECT_TYPE, ObjectDigestInfo.defaultValues(DIGESTED_OBJECT_TYPE));
  7937. if (OTHER_OBJECT_TYPE_ID in parameters) {
  7938. this.otherObjectTypeID = pvutils.getParametersValue(parameters, OTHER_OBJECT_TYPE_ID, ObjectDigestInfo.defaultValues(OTHER_OBJECT_TYPE_ID));
  7939. }
  7940. this.digestAlgorithm = pvutils.getParametersValue(parameters, DIGEST_ALGORITHM$2, ObjectDigestInfo.defaultValues(DIGEST_ALGORITHM$2));
  7941. this.objectDigest = pvutils.getParametersValue(parameters, OBJECT_DIGEST, ObjectDigestInfo.defaultValues(OBJECT_DIGEST));
  7942. if (parameters.schema) {
  7943. this.fromSchema(parameters.schema);
  7944. }
  7945. }
  7946. static defaultValues(memberName) {
  7947. switch (memberName) {
  7948. case DIGESTED_OBJECT_TYPE:
  7949. return new asn1js.Enumerated();
  7950. case OTHER_OBJECT_TYPE_ID:
  7951. return new asn1js.ObjectIdentifier();
  7952. case DIGEST_ALGORITHM$2:
  7953. return new AlgorithmIdentifier();
  7954. case OBJECT_DIGEST:
  7955. return new asn1js.BitString();
  7956. default:
  7957. return super.defaultValues(memberName);
  7958. }
  7959. }
  7960. static schema(parameters = {}) {
  7961. const names = pvutils.getParametersValue(parameters, "names", {});
  7962. return (new asn1js.Sequence({
  7963. name: (names.blockName || EMPTY_STRING),
  7964. value: [
  7965. new asn1js.Enumerated({ name: (names.digestedObjectType || EMPTY_STRING) }),
  7966. new asn1js.ObjectIdentifier({
  7967. optional: true,
  7968. name: (names.otherObjectTypeID || EMPTY_STRING)
  7969. }),
  7970. AlgorithmIdentifier.schema(names.digestAlgorithm || {}),
  7971. new asn1js.BitString({ name: (names.objectDigest || EMPTY_STRING) }),
  7972. ]
  7973. }));
  7974. }
  7975. fromSchema(schema) {
  7976. pvutils.clearProps(schema, CLEAR_PROPS$X);
  7977. const asn1 = asn1js.compareSchema(schema, schema, ObjectDigestInfo.schema({
  7978. names: {
  7979. digestedObjectType: DIGESTED_OBJECT_TYPE,
  7980. otherObjectTypeID: OTHER_OBJECT_TYPE_ID,
  7981. digestAlgorithm: {
  7982. names: {
  7983. blockName: DIGEST_ALGORITHM$2
  7984. }
  7985. },
  7986. objectDigest: OBJECT_DIGEST
  7987. }
  7988. }));
  7989. AsnError.assertSchema(asn1, this.className);
  7990. this.digestedObjectType = asn1.result.digestedObjectType;
  7991. if (OTHER_OBJECT_TYPE_ID in asn1.result) {
  7992. this.otherObjectTypeID = asn1.result.otherObjectTypeID;
  7993. }
  7994. this.digestAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.digestAlgorithm });
  7995. this.objectDigest = asn1.result.objectDigest;
  7996. }
  7997. toSchema() {
  7998. const result = new asn1js.Sequence({
  7999. value: [this.digestedObjectType]
  8000. });
  8001. if (this.otherObjectTypeID) {
  8002. result.valueBlock.value.push(this.otherObjectTypeID);
  8003. }
  8004. result.valueBlock.value.push(this.digestAlgorithm.toSchema());
  8005. result.valueBlock.value.push(this.objectDigest);
  8006. return result;
  8007. }
  8008. toJSON() {
  8009. const result = {
  8010. digestedObjectType: this.digestedObjectType.toJSON(),
  8011. digestAlgorithm: this.digestAlgorithm.toJSON(),
  8012. objectDigest: this.objectDigest.toJSON(),
  8013. };
  8014. if (this.otherObjectTypeID) {
  8015. result.otherObjectTypeID = this.otherObjectTypeID.toJSON();
  8016. }
  8017. return result;
  8018. }
  8019. }
  8020. ObjectDigestInfo.CLASS_NAME = "ObjectDigestInfo";
  8021. const ISSUER_NAME = "issuerName";
  8022. const BASE_CERTIFICATE_ID$1 = "baseCertificateID";
  8023. const OBJECT_DIGEST_INFO$1 = "objectDigestInfo";
  8024. const CLEAR_PROPS$W = [
  8025. ISSUER_NAME,
  8026. BASE_CERTIFICATE_ID$1,
  8027. OBJECT_DIGEST_INFO$1
  8028. ];
  8029. class V2Form extends PkiObject {
  8030. constructor(parameters = {}) {
  8031. super();
  8032. if (ISSUER_NAME in parameters) {
  8033. this.issuerName = pvutils.getParametersValue(parameters, ISSUER_NAME, V2Form.defaultValues(ISSUER_NAME));
  8034. }
  8035. if (BASE_CERTIFICATE_ID$1 in parameters) {
  8036. this.baseCertificateID = pvutils.getParametersValue(parameters, BASE_CERTIFICATE_ID$1, V2Form.defaultValues(BASE_CERTIFICATE_ID$1));
  8037. }
  8038. if (OBJECT_DIGEST_INFO$1 in parameters) {
  8039. this.objectDigestInfo = pvutils.getParametersValue(parameters, OBJECT_DIGEST_INFO$1, V2Form.defaultValues(OBJECT_DIGEST_INFO$1));
  8040. }
  8041. if (parameters.schema) {
  8042. this.fromSchema(parameters.schema);
  8043. }
  8044. }
  8045. static defaultValues(memberName) {
  8046. switch (memberName) {
  8047. case ISSUER_NAME:
  8048. return new GeneralNames();
  8049. case BASE_CERTIFICATE_ID$1:
  8050. return new IssuerSerial();
  8051. case OBJECT_DIGEST_INFO$1:
  8052. return new ObjectDigestInfo();
  8053. default:
  8054. return super.defaultValues(memberName);
  8055. }
  8056. }
  8057. static schema(parameters = {}) {
  8058. const names = pvutils.getParametersValue(parameters, "names", {});
  8059. return (new asn1js.Sequence({
  8060. name: (names.blockName || EMPTY_STRING),
  8061. value: [
  8062. GeneralNames.schema({
  8063. names: {
  8064. blockName: names.issuerName
  8065. }
  8066. }, true),
  8067. new asn1js.Constructed({
  8068. optional: true,
  8069. name: (names.baseCertificateID || EMPTY_STRING),
  8070. idBlock: {
  8071. tagClass: 3,
  8072. tagNumber: 0
  8073. },
  8074. value: IssuerSerial.schema().valueBlock.value
  8075. }),
  8076. new asn1js.Constructed({
  8077. optional: true,
  8078. name: (names.objectDigestInfo || EMPTY_STRING),
  8079. idBlock: {
  8080. tagClass: 3,
  8081. tagNumber: 1
  8082. },
  8083. value: ObjectDigestInfo.schema().valueBlock.value
  8084. })
  8085. ]
  8086. }));
  8087. }
  8088. fromSchema(schema) {
  8089. pvutils.clearProps(schema, CLEAR_PROPS$W);
  8090. const asn1 = asn1js.compareSchema(schema, schema, V2Form.schema({
  8091. names: {
  8092. issuerName: ISSUER_NAME,
  8093. baseCertificateID: BASE_CERTIFICATE_ID$1,
  8094. objectDigestInfo: OBJECT_DIGEST_INFO$1
  8095. }
  8096. }));
  8097. AsnError.assertSchema(asn1, this.className);
  8098. if (ISSUER_NAME in asn1.result)
  8099. this.issuerName = new GeneralNames({ schema: asn1.result.issuerName });
  8100. if (BASE_CERTIFICATE_ID$1 in asn1.result) {
  8101. this.baseCertificateID = new IssuerSerial({
  8102. schema: new asn1js.Sequence({
  8103. value: asn1.result.baseCertificateID.valueBlock.value
  8104. })
  8105. });
  8106. }
  8107. if (OBJECT_DIGEST_INFO$1 in asn1.result) {
  8108. this.objectDigestInfo = new ObjectDigestInfo({
  8109. schema: new asn1js.Sequence({
  8110. value: asn1.result.objectDigestInfo.valueBlock.value
  8111. })
  8112. });
  8113. }
  8114. }
  8115. toSchema() {
  8116. const result = new asn1js.Sequence();
  8117. if (this.issuerName)
  8118. result.valueBlock.value.push(this.issuerName.toSchema());
  8119. if (this.baseCertificateID) {
  8120. result.valueBlock.value.push(new asn1js.Constructed({
  8121. idBlock: {
  8122. tagClass: 3,
  8123. tagNumber: 0
  8124. },
  8125. value: this.baseCertificateID.toSchema().valueBlock.value
  8126. }));
  8127. }
  8128. if (this.objectDigestInfo) {
  8129. result.valueBlock.value.push(new asn1js.Constructed({
  8130. idBlock: {
  8131. tagClass: 3,
  8132. tagNumber: 1
  8133. },
  8134. value: this.objectDigestInfo.toSchema().valueBlock.value
  8135. }));
  8136. }
  8137. return result;
  8138. }
  8139. toJSON() {
  8140. const result = {};
  8141. if (this.issuerName) {
  8142. result.issuerName = this.issuerName.toJSON();
  8143. }
  8144. if (this.baseCertificateID) {
  8145. result.baseCertificateID = this.baseCertificateID.toJSON();
  8146. }
  8147. if (this.objectDigestInfo) {
  8148. result.objectDigestInfo = this.objectDigestInfo.toJSON();
  8149. }
  8150. return result;
  8151. }
  8152. }
  8153. V2Form.CLASS_NAME = "V2Form";
  8154. const BASE_CERTIFICATE_ID = "baseCertificateID";
  8155. const ENTITY_NAME = "entityName";
  8156. const OBJECT_DIGEST_INFO = "objectDigestInfo";
  8157. const CLEAR_PROPS$V = [
  8158. BASE_CERTIFICATE_ID,
  8159. ENTITY_NAME,
  8160. OBJECT_DIGEST_INFO
  8161. ];
  8162. class Holder extends PkiObject {
  8163. constructor(parameters = {}) {
  8164. super();
  8165. if (BASE_CERTIFICATE_ID in parameters) {
  8166. this.baseCertificateID = pvutils.getParametersValue(parameters, BASE_CERTIFICATE_ID, Holder.defaultValues(BASE_CERTIFICATE_ID));
  8167. }
  8168. if (ENTITY_NAME in parameters) {
  8169. this.entityName = pvutils.getParametersValue(parameters, ENTITY_NAME, Holder.defaultValues(ENTITY_NAME));
  8170. }
  8171. if (OBJECT_DIGEST_INFO in parameters) {
  8172. this.objectDigestInfo = pvutils.getParametersValue(parameters, OBJECT_DIGEST_INFO, Holder.defaultValues(OBJECT_DIGEST_INFO));
  8173. }
  8174. if (parameters.schema) {
  8175. this.fromSchema(parameters.schema);
  8176. }
  8177. }
  8178. static defaultValues(memberName) {
  8179. switch (memberName) {
  8180. case BASE_CERTIFICATE_ID:
  8181. return new IssuerSerial();
  8182. case ENTITY_NAME:
  8183. return new GeneralNames();
  8184. case OBJECT_DIGEST_INFO:
  8185. return new ObjectDigestInfo();
  8186. default:
  8187. return super.defaultValues(memberName);
  8188. }
  8189. }
  8190. static schema(parameters = {}) {
  8191. const names = pvutils.getParametersValue(parameters, "names", {});
  8192. return (new asn1js.Sequence({
  8193. name: (names.blockName || EMPTY_STRING),
  8194. value: [
  8195. new asn1js.Constructed({
  8196. optional: true,
  8197. name: (names.baseCertificateID || EMPTY_STRING),
  8198. idBlock: {
  8199. tagClass: 3,
  8200. tagNumber: 0
  8201. },
  8202. value: IssuerSerial.schema().valueBlock.value
  8203. }),
  8204. new asn1js.Constructed({
  8205. optional: true,
  8206. name: (names.entityName || EMPTY_STRING),
  8207. idBlock: {
  8208. tagClass: 3,
  8209. tagNumber: 1
  8210. },
  8211. value: GeneralNames.schema().valueBlock.value
  8212. }),
  8213. new asn1js.Constructed({
  8214. optional: true,
  8215. name: (names.objectDigestInfo || EMPTY_STRING),
  8216. idBlock: {
  8217. tagClass: 3,
  8218. tagNumber: 2
  8219. },
  8220. value: ObjectDigestInfo.schema().valueBlock.value
  8221. })
  8222. ]
  8223. }));
  8224. }
  8225. fromSchema(schema) {
  8226. pvutils.clearProps(schema, CLEAR_PROPS$V);
  8227. const asn1 = asn1js.compareSchema(schema, schema, Holder.schema({
  8228. names: {
  8229. baseCertificateID: BASE_CERTIFICATE_ID,
  8230. entityName: ENTITY_NAME,
  8231. objectDigestInfo: OBJECT_DIGEST_INFO
  8232. }
  8233. }));
  8234. AsnError.assertSchema(asn1, this.className);
  8235. if (BASE_CERTIFICATE_ID in asn1.result) {
  8236. this.baseCertificateID = new IssuerSerial({
  8237. schema: new asn1js.Sequence({
  8238. value: asn1.result.baseCertificateID.valueBlock.value
  8239. })
  8240. });
  8241. }
  8242. if (ENTITY_NAME in asn1.result) {
  8243. this.entityName = new GeneralNames({
  8244. schema: new asn1js.Sequence({
  8245. value: asn1.result.entityName.valueBlock.value
  8246. })
  8247. });
  8248. }
  8249. if (OBJECT_DIGEST_INFO in asn1.result) {
  8250. this.objectDigestInfo = new ObjectDigestInfo({
  8251. schema: new asn1js.Sequence({
  8252. value: asn1.result.objectDigestInfo.valueBlock.value
  8253. })
  8254. });
  8255. }
  8256. }
  8257. toSchema() {
  8258. const result = new asn1js.Sequence();
  8259. if (this.baseCertificateID) {
  8260. result.valueBlock.value.push(new asn1js.Constructed({
  8261. idBlock: {
  8262. tagClass: 3,
  8263. tagNumber: 0
  8264. },
  8265. value: this.baseCertificateID.toSchema().valueBlock.value
  8266. }));
  8267. }
  8268. if (this.entityName) {
  8269. result.valueBlock.value.push(new asn1js.Constructed({
  8270. idBlock: {
  8271. tagClass: 3,
  8272. tagNumber: 1
  8273. },
  8274. value: this.entityName.toSchema().valueBlock.value
  8275. }));
  8276. }
  8277. if (this.objectDigestInfo) {
  8278. result.valueBlock.value.push(new asn1js.Constructed({
  8279. idBlock: {
  8280. tagClass: 3,
  8281. tagNumber: 2
  8282. },
  8283. value: this.objectDigestInfo.toSchema().valueBlock.value
  8284. }));
  8285. }
  8286. return result;
  8287. }
  8288. toJSON() {
  8289. const result = {};
  8290. if (this.baseCertificateID) {
  8291. result.baseCertificateID = this.baseCertificateID.toJSON();
  8292. }
  8293. if (this.entityName) {
  8294. result.entityName = this.entityName.toJSON();
  8295. }
  8296. if (this.objectDigestInfo) {
  8297. result.objectDigestInfo = this.objectDigestInfo.toJSON();
  8298. }
  8299. return result;
  8300. }
  8301. }
  8302. Holder.CLASS_NAME = "Holder";
  8303. const VERSION$g = "version";
  8304. const HOLDER = "holder";
  8305. const ISSUER$3 = "issuer";
  8306. const SIGNATURE$5 = "signature";
  8307. const SERIAL_NUMBER$4 = "serialNumber";
  8308. const ATTR_CERT_VALIDITY_PERIOD = "attrCertValidityPeriod";
  8309. const ATTRIBUTES$2 = "attributes";
  8310. const ISSUER_UNIQUE_ID$1 = "issuerUniqueID";
  8311. const EXTENSIONS$3 = "extensions";
  8312. const CLEAR_PROPS$U = [
  8313. VERSION$g,
  8314. HOLDER,
  8315. ISSUER$3,
  8316. SIGNATURE$5,
  8317. SERIAL_NUMBER$4,
  8318. ATTR_CERT_VALIDITY_PERIOD,
  8319. ATTRIBUTES$2,
  8320. ISSUER_UNIQUE_ID$1,
  8321. EXTENSIONS$3
  8322. ];
  8323. class AttributeCertificateInfoV2 extends PkiObject {
  8324. constructor(parameters = {}) {
  8325. super();
  8326. this.version = pvutils.getParametersValue(parameters, VERSION$g, AttributeCertificateInfoV2.defaultValues(VERSION$g));
  8327. this.holder = pvutils.getParametersValue(parameters, HOLDER, AttributeCertificateInfoV2.defaultValues(HOLDER));
  8328. this.issuer = pvutils.getParametersValue(parameters, ISSUER$3, AttributeCertificateInfoV2.defaultValues(ISSUER$3));
  8329. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$5, AttributeCertificateInfoV2.defaultValues(SIGNATURE$5));
  8330. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$4, AttributeCertificateInfoV2.defaultValues(SERIAL_NUMBER$4));
  8331. this.attrCertValidityPeriod = pvutils.getParametersValue(parameters, ATTR_CERT_VALIDITY_PERIOD, AttributeCertificateInfoV2.defaultValues(ATTR_CERT_VALIDITY_PERIOD));
  8332. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES$2, AttributeCertificateInfoV2.defaultValues(ATTRIBUTES$2));
  8333. if (ISSUER_UNIQUE_ID$1 in parameters) {
  8334. this.issuerUniqueID = pvutils.getParametersValue(parameters, ISSUER_UNIQUE_ID$1, AttributeCertificateInfoV2.defaultValues(ISSUER_UNIQUE_ID$1));
  8335. }
  8336. if (EXTENSIONS$3 in parameters) {
  8337. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$3, AttributeCertificateInfoV2.defaultValues(EXTENSIONS$3));
  8338. }
  8339. if (parameters.schema) {
  8340. this.fromSchema(parameters.schema);
  8341. }
  8342. }
  8343. static defaultValues(memberName) {
  8344. switch (memberName) {
  8345. case VERSION$g:
  8346. return 1;
  8347. case HOLDER:
  8348. return new Holder();
  8349. case ISSUER$3:
  8350. return {};
  8351. case SIGNATURE$5:
  8352. return new AlgorithmIdentifier();
  8353. case SERIAL_NUMBER$4:
  8354. return new asn1js.Integer();
  8355. case ATTR_CERT_VALIDITY_PERIOD:
  8356. return new AttCertValidityPeriod();
  8357. case ATTRIBUTES$2:
  8358. return [];
  8359. case ISSUER_UNIQUE_ID$1:
  8360. return new asn1js.BitString();
  8361. case EXTENSIONS$3:
  8362. return new Extensions();
  8363. default:
  8364. return super.defaultValues(memberName);
  8365. }
  8366. }
  8367. static schema(parameters = {}) {
  8368. const names = pvutils.getParametersValue(parameters, "names", {});
  8369. return (new asn1js.Sequence({
  8370. name: (names.blockName || EMPTY_STRING),
  8371. value: [
  8372. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  8373. Holder.schema(names.holder || {}),
  8374. new asn1js.Choice({
  8375. value: [
  8376. GeneralNames.schema({
  8377. names: {
  8378. blockName: (names.issuer || EMPTY_STRING)
  8379. }
  8380. }),
  8381. new asn1js.Constructed({
  8382. name: (names.issuer || EMPTY_STRING),
  8383. idBlock: {
  8384. tagClass: 3,
  8385. tagNumber: 0
  8386. },
  8387. value: V2Form.schema().valueBlock.value
  8388. })
  8389. ]
  8390. }),
  8391. AlgorithmIdentifier.schema(names.signature || {}),
  8392. new asn1js.Integer({ name: (names.serialNumber || EMPTY_STRING) }),
  8393. AttCertValidityPeriod.schema(names.attrCertValidityPeriod || {}),
  8394. new asn1js.Sequence({
  8395. name: (names.attributes || EMPTY_STRING),
  8396. value: [
  8397. new asn1js.Repeated({
  8398. value: Attribute.schema()
  8399. })
  8400. ]
  8401. }),
  8402. new asn1js.BitString({
  8403. optional: true,
  8404. name: (names.issuerUniqueID || EMPTY_STRING)
  8405. }),
  8406. Extensions.schema(names.extensions || {}, true)
  8407. ]
  8408. }));
  8409. }
  8410. fromSchema(schema) {
  8411. pvutils.clearProps(schema, CLEAR_PROPS$U);
  8412. const asn1 = asn1js.compareSchema(schema, schema, AttributeCertificateInfoV2.schema({
  8413. names: {
  8414. version: VERSION$g,
  8415. holder: {
  8416. names: {
  8417. blockName: HOLDER
  8418. }
  8419. },
  8420. issuer: ISSUER$3,
  8421. signature: {
  8422. names: {
  8423. blockName: SIGNATURE$5
  8424. }
  8425. },
  8426. serialNumber: SERIAL_NUMBER$4,
  8427. attrCertValidityPeriod: {
  8428. names: {
  8429. blockName: ATTR_CERT_VALIDITY_PERIOD
  8430. }
  8431. },
  8432. attributes: ATTRIBUTES$2,
  8433. issuerUniqueID: ISSUER_UNIQUE_ID$1,
  8434. extensions: {
  8435. names: {
  8436. blockName: EXTENSIONS$3
  8437. }
  8438. }
  8439. }
  8440. }));
  8441. AsnError.assertSchema(asn1, this.className);
  8442. this.version = asn1.result.version.valueBlock.valueDec;
  8443. this.holder = new Holder({ schema: asn1.result.holder });
  8444. switch (asn1.result.issuer.idBlock.tagClass) {
  8445. case 3:
  8446. this.issuer = new V2Form({
  8447. schema: new asn1js.Sequence({
  8448. value: asn1.result.issuer.valueBlock.value
  8449. })
  8450. });
  8451. break;
  8452. case 1:
  8453. default:
  8454. throw new Error("Incorrect value for 'issuer' in AttributeCertificateInfoV2");
  8455. }
  8456. this.signature = new AlgorithmIdentifier({ schema: asn1.result.signature });
  8457. this.serialNumber = asn1.result.serialNumber;
  8458. this.attrCertValidityPeriod = new AttCertValidityPeriod({ schema: asn1.result.attrCertValidityPeriod });
  8459. this.attributes = Array.from(asn1.result.attributes.valueBlock.value, element => new Attribute({ schema: element }));
  8460. if (ISSUER_UNIQUE_ID$1 in asn1.result) {
  8461. this.issuerUniqueID = asn1.result.issuerUniqueID;
  8462. }
  8463. if (EXTENSIONS$3 in asn1.result) {
  8464. this.extensions = new Extensions({ schema: asn1.result.extensions });
  8465. }
  8466. }
  8467. toSchema() {
  8468. const result = new asn1js.Sequence({
  8469. value: [
  8470. new asn1js.Integer({ value: this.version }),
  8471. this.holder.toSchema(),
  8472. new asn1js.Constructed({
  8473. idBlock: {
  8474. tagClass: 3,
  8475. tagNumber: 0
  8476. },
  8477. value: this.issuer.toSchema().valueBlock.value
  8478. }),
  8479. this.signature.toSchema(),
  8480. this.serialNumber,
  8481. this.attrCertValidityPeriod.toSchema(),
  8482. new asn1js.Sequence({
  8483. value: Array.from(this.attributes, o => o.toSchema())
  8484. })
  8485. ]
  8486. });
  8487. if (this.issuerUniqueID) {
  8488. result.valueBlock.value.push(this.issuerUniqueID);
  8489. }
  8490. if (this.extensions) {
  8491. result.valueBlock.value.push(this.extensions.toSchema());
  8492. }
  8493. return result;
  8494. }
  8495. toJSON() {
  8496. const result = {
  8497. version: this.version,
  8498. holder: this.holder.toJSON(),
  8499. issuer: this.issuer.toJSON(),
  8500. signature: this.signature.toJSON(),
  8501. serialNumber: this.serialNumber.toJSON(),
  8502. attrCertValidityPeriod: this.attrCertValidityPeriod.toJSON(),
  8503. attributes: Array.from(this.attributes, o => o.toJSON())
  8504. };
  8505. if (this.issuerUniqueID) {
  8506. result.issuerUniqueID = this.issuerUniqueID.toJSON();
  8507. }
  8508. if (this.extensions) {
  8509. result.extensions = this.extensions.toJSON();
  8510. }
  8511. return result;
  8512. }
  8513. }
  8514. AttributeCertificateInfoV2.CLASS_NAME = "AttributeCertificateInfoV2";
  8515. const ACINFO = "acinfo";
  8516. const SIGNATURE_ALGORITHM$6 = "signatureAlgorithm";
  8517. const SIGNATURE_VALUE$3 = "signatureValue";
  8518. const CLEAR_PROPS$T = [
  8519. ACINFO,
  8520. SIGNATURE_ALGORITHM$6,
  8521. SIGNATURE_VALUE$3,
  8522. ];
  8523. class AttributeCertificateV2 extends PkiObject {
  8524. constructor(parameters = {}) {
  8525. super();
  8526. this.acinfo = pvutils.getParametersValue(parameters, ACINFO, AttributeCertificateV2.defaultValues(ACINFO));
  8527. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$6, AttributeCertificateV2.defaultValues(SIGNATURE_ALGORITHM$6));
  8528. this.signatureValue = pvutils.getParametersValue(parameters, SIGNATURE_VALUE$3, AttributeCertificateV2.defaultValues(SIGNATURE_VALUE$3));
  8529. if (parameters.schema) {
  8530. this.fromSchema(parameters.schema);
  8531. }
  8532. }
  8533. static defaultValues(memberName) {
  8534. switch (memberName) {
  8535. case ACINFO:
  8536. return new AttributeCertificateInfoV2();
  8537. case SIGNATURE_ALGORITHM$6:
  8538. return new AlgorithmIdentifier();
  8539. case SIGNATURE_VALUE$3:
  8540. return new asn1js.BitString();
  8541. default:
  8542. return super.defaultValues(memberName);
  8543. }
  8544. }
  8545. static schema(parameters = {}) {
  8546. const names = pvutils.getParametersValue(parameters, "names", {});
  8547. return (new asn1js.Sequence({
  8548. name: (names.blockName || EMPTY_STRING),
  8549. value: [
  8550. AttributeCertificateInfoV2.schema(names.acinfo || {}),
  8551. AlgorithmIdentifier.schema(names.signatureAlgorithm || {}),
  8552. new asn1js.BitString({ name: (names.signatureValue || EMPTY_STRING) })
  8553. ]
  8554. }));
  8555. }
  8556. fromSchema(schema) {
  8557. pvutils.clearProps(schema, CLEAR_PROPS$T);
  8558. const asn1 = asn1js.compareSchema(schema, schema, AttributeCertificateV2.schema({
  8559. names: {
  8560. acinfo: {
  8561. names: {
  8562. blockName: ACINFO
  8563. }
  8564. },
  8565. signatureAlgorithm: {
  8566. names: {
  8567. blockName: SIGNATURE_ALGORITHM$6
  8568. }
  8569. },
  8570. signatureValue: SIGNATURE_VALUE$3
  8571. }
  8572. }));
  8573. AsnError.assertSchema(asn1, this.className);
  8574. this.acinfo = new AttributeCertificateInfoV2({ schema: asn1.result.acinfo });
  8575. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  8576. this.signatureValue = asn1.result.signatureValue;
  8577. }
  8578. toSchema() {
  8579. return (new asn1js.Sequence({
  8580. value: [
  8581. this.acinfo.toSchema(),
  8582. this.signatureAlgorithm.toSchema(),
  8583. this.signatureValue
  8584. ]
  8585. }));
  8586. }
  8587. toJSON() {
  8588. return {
  8589. acinfo: this.acinfo.toJSON(),
  8590. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  8591. signatureValue: this.signatureValue.toJSON(),
  8592. };
  8593. }
  8594. }
  8595. AttributeCertificateV2.CLASS_NAME = "AttributeCertificateV2";
  8596. const CONTENT_TYPE = "contentType";
  8597. const CONTENT = "content";
  8598. const CLEAR_PROPS$S = [CONTENT_TYPE, CONTENT];
  8599. class ContentInfo extends PkiObject {
  8600. constructor(parameters = {}) {
  8601. super();
  8602. this.contentType = pvutils.getParametersValue(parameters, CONTENT_TYPE, ContentInfo.defaultValues(CONTENT_TYPE));
  8603. this.content = pvutils.getParametersValue(parameters, CONTENT, ContentInfo.defaultValues(CONTENT));
  8604. if (parameters.schema) {
  8605. this.fromSchema(parameters.schema);
  8606. }
  8607. }
  8608. static defaultValues(memberName) {
  8609. switch (memberName) {
  8610. case CONTENT_TYPE:
  8611. return EMPTY_STRING;
  8612. case CONTENT:
  8613. return new asn1js.Any();
  8614. default:
  8615. return super.defaultValues(memberName);
  8616. }
  8617. }
  8618. static compareWithDefault(memberName, memberValue) {
  8619. switch (memberName) {
  8620. case CONTENT_TYPE:
  8621. return (typeof memberValue === "string" &&
  8622. memberValue === this.defaultValues(CONTENT_TYPE));
  8623. case CONTENT:
  8624. return (memberValue instanceof asn1js.Any);
  8625. default:
  8626. return super.defaultValues(memberName);
  8627. }
  8628. }
  8629. static schema(parameters = {}) {
  8630. const names = pvutils.getParametersValue(parameters, "names", {});
  8631. if (("optional" in names) === false) {
  8632. names.optional = false;
  8633. }
  8634. return (new asn1js.Sequence({
  8635. name: (names.blockName || "ContentInfo"),
  8636. optional: names.optional,
  8637. value: [
  8638. new asn1js.ObjectIdentifier({ name: (names.contentType || CONTENT_TYPE) }),
  8639. new asn1js.Constructed({
  8640. idBlock: {
  8641. tagClass: 3,
  8642. tagNumber: 0
  8643. },
  8644. value: [new asn1js.Any({ name: (names.content || CONTENT) })]
  8645. })
  8646. ]
  8647. }));
  8648. }
  8649. fromSchema(schema) {
  8650. pvutils.clearProps(schema, CLEAR_PROPS$S);
  8651. const asn1 = asn1js.compareSchema(schema, schema, ContentInfo.schema());
  8652. AsnError.assertSchema(asn1, this.className);
  8653. this.contentType = asn1.result.contentType.valueBlock.toString();
  8654. this.content = asn1.result.content;
  8655. }
  8656. toSchema() {
  8657. return (new asn1js.Sequence({
  8658. value: [
  8659. new asn1js.ObjectIdentifier({ value: this.contentType }),
  8660. new asn1js.Constructed({
  8661. idBlock: {
  8662. tagClass: 3,
  8663. tagNumber: 0
  8664. },
  8665. value: [this.content]
  8666. })
  8667. ]
  8668. }));
  8669. }
  8670. toJSON() {
  8671. const object = {
  8672. contentType: this.contentType
  8673. };
  8674. if (!(this.content instanceof asn1js.Any)) {
  8675. object.content = this.content.toJSON();
  8676. }
  8677. return object;
  8678. }
  8679. }
  8680. ContentInfo.CLASS_NAME = "ContentInfo";
  8681. ContentInfo.DATA = id_ContentType_Data;
  8682. ContentInfo.SIGNED_DATA = id_ContentType_SignedData;
  8683. ContentInfo.ENVELOPED_DATA = id_ContentType_EnvelopedData;
  8684. ContentInfo.ENCRYPTED_DATA = id_ContentType_EncryptedData;
  8685. const TYPE$1 = "type";
  8686. const VALUE$4 = "value";
  8687. const UTC_TIME_NAME = "utcTimeName";
  8688. const GENERAL_TIME_NAME = "generalTimeName";
  8689. const CLEAR_PROPS$R = [UTC_TIME_NAME, GENERAL_TIME_NAME];
  8690. var TimeType;
  8691. (function (TimeType) {
  8692. TimeType[TimeType["UTCTime"] = 0] = "UTCTime";
  8693. TimeType[TimeType["GeneralizedTime"] = 1] = "GeneralizedTime";
  8694. TimeType[TimeType["empty"] = 2] = "empty";
  8695. })(TimeType || (TimeType = {}));
  8696. class Time extends PkiObject {
  8697. constructor(parameters = {}) {
  8698. super();
  8699. this.type = pvutils.getParametersValue(parameters, TYPE$1, Time.defaultValues(TYPE$1));
  8700. this.value = pvutils.getParametersValue(parameters, VALUE$4, Time.defaultValues(VALUE$4));
  8701. if (parameters.schema) {
  8702. this.fromSchema(parameters.schema);
  8703. }
  8704. }
  8705. static defaultValues(memberName) {
  8706. switch (memberName) {
  8707. case TYPE$1:
  8708. return 0;
  8709. case VALUE$4:
  8710. return new Date(0, 0, 0);
  8711. default:
  8712. return super.defaultValues(memberName);
  8713. }
  8714. }
  8715. static schema(parameters = {}, optional = false) {
  8716. const names = pvutils.getParametersValue(parameters, "names", {});
  8717. return (new asn1js.Choice({
  8718. optional,
  8719. value: [
  8720. new asn1js.UTCTime({ name: (names.utcTimeName || EMPTY_STRING) }),
  8721. new asn1js.GeneralizedTime({ name: (names.generalTimeName || EMPTY_STRING) })
  8722. ]
  8723. }));
  8724. }
  8725. fromSchema(schema) {
  8726. pvutils.clearProps(schema, CLEAR_PROPS$R);
  8727. const asn1 = asn1js.compareSchema(schema, schema, Time.schema({
  8728. names: {
  8729. utcTimeName: UTC_TIME_NAME,
  8730. generalTimeName: GENERAL_TIME_NAME
  8731. }
  8732. }));
  8733. AsnError.assertSchema(asn1, this.className);
  8734. if (UTC_TIME_NAME in asn1.result) {
  8735. this.type = 0;
  8736. this.value = asn1.result.utcTimeName.toDate();
  8737. }
  8738. if (GENERAL_TIME_NAME in asn1.result) {
  8739. this.type = 1;
  8740. this.value = asn1.result.generalTimeName.toDate();
  8741. }
  8742. }
  8743. toSchema() {
  8744. if (this.type === 0) {
  8745. return new asn1js.UTCTime({ valueDate: this.value });
  8746. }
  8747. else if (this.type === 1) {
  8748. return new asn1js.GeneralizedTime({ valueDate: this.value });
  8749. }
  8750. return {};
  8751. }
  8752. toJSON() {
  8753. return {
  8754. type: this.type,
  8755. value: this.value
  8756. };
  8757. }
  8758. }
  8759. Time.CLASS_NAME = "Time";
  8760. const TBS$4 = "tbs";
  8761. const VERSION$f = "version";
  8762. const SERIAL_NUMBER$3 = "serialNumber";
  8763. const SIGNATURE$4 = "signature";
  8764. const ISSUER$2 = "issuer";
  8765. const NOT_BEFORE = "notBefore";
  8766. const NOT_AFTER = "notAfter";
  8767. const SUBJECT$1 = "subject";
  8768. const SUBJECT_PUBLIC_KEY_INFO = "subjectPublicKeyInfo";
  8769. const ISSUER_UNIQUE_ID = "issuerUniqueID";
  8770. const SUBJECT_UNIQUE_ID = "subjectUniqueID";
  8771. const EXTENSIONS$2 = "extensions";
  8772. const SIGNATURE_ALGORITHM$5 = "signatureAlgorithm";
  8773. const SIGNATURE_VALUE$2 = "signatureValue";
  8774. const TBS_CERTIFICATE = "tbsCertificate";
  8775. const TBS_CERTIFICATE_VERSION = `${TBS_CERTIFICATE}.${VERSION$f}`;
  8776. const TBS_CERTIFICATE_SERIAL_NUMBER = `${TBS_CERTIFICATE}.${SERIAL_NUMBER$3}`;
  8777. const TBS_CERTIFICATE_SIGNATURE = `${TBS_CERTIFICATE}.${SIGNATURE$4}`;
  8778. const TBS_CERTIFICATE_ISSUER = `${TBS_CERTIFICATE}.${ISSUER$2}`;
  8779. const TBS_CERTIFICATE_NOT_BEFORE = `${TBS_CERTIFICATE}.${NOT_BEFORE}`;
  8780. const TBS_CERTIFICATE_NOT_AFTER = `${TBS_CERTIFICATE}.${NOT_AFTER}`;
  8781. const TBS_CERTIFICATE_SUBJECT = `${TBS_CERTIFICATE}.${SUBJECT$1}`;
  8782. const TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY = `${TBS_CERTIFICATE}.${SUBJECT_PUBLIC_KEY_INFO}`;
  8783. const TBS_CERTIFICATE_ISSUER_UNIQUE_ID = `${TBS_CERTIFICATE}.${ISSUER_UNIQUE_ID}`;
  8784. const TBS_CERTIFICATE_SUBJECT_UNIQUE_ID = `${TBS_CERTIFICATE}.${SUBJECT_UNIQUE_ID}`;
  8785. const TBS_CERTIFICATE_EXTENSIONS = `${TBS_CERTIFICATE}.${EXTENSIONS$2}`;
  8786. const CLEAR_PROPS$Q = [
  8787. TBS_CERTIFICATE,
  8788. TBS_CERTIFICATE_VERSION,
  8789. TBS_CERTIFICATE_SERIAL_NUMBER,
  8790. TBS_CERTIFICATE_SIGNATURE,
  8791. TBS_CERTIFICATE_ISSUER,
  8792. TBS_CERTIFICATE_NOT_BEFORE,
  8793. TBS_CERTIFICATE_NOT_AFTER,
  8794. TBS_CERTIFICATE_SUBJECT,
  8795. TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY,
  8796. TBS_CERTIFICATE_ISSUER_UNIQUE_ID,
  8797. TBS_CERTIFICATE_SUBJECT_UNIQUE_ID,
  8798. TBS_CERTIFICATE_EXTENSIONS,
  8799. SIGNATURE_ALGORITHM$5,
  8800. SIGNATURE_VALUE$2
  8801. ];
  8802. function tbsCertificate(parameters = {}) {
  8803. const names = pvutils.getParametersValue(parameters, "names", {});
  8804. return (new asn1js.Sequence({
  8805. name: (names.blockName || TBS_CERTIFICATE),
  8806. value: [
  8807. new asn1js.Constructed({
  8808. optional: true,
  8809. idBlock: {
  8810. tagClass: 3,
  8811. tagNumber: 0
  8812. },
  8813. value: [
  8814. new asn1js.Integer({ name: (names.tbsCertificateVersion || TBS_CERTIFICATE_VERSION) })
  8815. ]
  8816. }),
  8817. new asn1js.Integer({ name: (names.tbsCertificateSerialNumber || TBS_CERTIFICATE_SERIAL_NUMBER) }),
  8818. AlgorithmIdentifier.schema(names.signature || {
  8819. names: {
  8820. blockName: TBS_CERTIFICATE_SIGNATURE
  8821. }
  8822. }),
  8823. RelativeDistinguishedNames.schema(names.issuer || {
  8824. names: {
  8825. blockName: TBS_CERTIFICATE_ISSUER
  8826. }
  8827. }),
  8828. new asn1js.Sequence({
  8829. name: (names.tbsCertificateValidity || "tbsCertificate.validity"),
  8830. value: [
  8831. Time.schema(names.notBefore || {
  8832. names: {
  8833. utcTimeName: TBS_CERTIFICATE_NOT_BEFORE,
  8834. generalTimeName: TBS_CERTIFICATE_NOT_BEFORE
  8835. }
  8836. }),
  8837. Time.schema(names.notAfter || {
  8838. names: {
  8839. utcTimeName: TBS_CERTIFICATE_NOT_AFTER,
  8840. generalTimeName: TBS_CERTIFICATE_NOT_AFTER
  8841. }
  8842. })
  8843. ]
  8844. }),
  8845. RelativeDistinguishedNames.schema(names.subject || {
  8846. names: {
  8847. blockName: TBS_CERTIFICATE_SUBJECT
  8848. }
  8849. }),
  8850. PublicKeyInfo.schema(names.subjectPublicKeyInfo || {
  8851. names: {
  8852. blockName: TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY
  8853. }
  8854. }),
  8855. new asn1js.Primitive({
  8856. name: (names.tbsCertificateIssuerUniqueID || TBS_CERTIFICATE_ISSUER_UNIQUE_ID),
  8857. optional: true,
  8858. idBlock: {
  8859. tagClass: 3,
  8860. tagNumber: 1
  8861. }
  8862. }),
  8863. new asn1js.Primitive({
  8864. name: (names.tbsCertificateSubjectUniqueID || TBS_CERTIFICATE_SUBJECT_UNIQUE_ID),
  8865. optional: true,
  8866. idBlock: {
  8867. tagClass: 3,
  8868. tagNumber: 2
  8869. }
  8870. }),
  8871. new asn1js.Constructed({
  8872. optional: true,
  8873. idBlock: {
  8874. tagClass: 3,
  8875. tagNumber: 3
  8876. },
  8877. value: [Extensions.schema(names.extensions || {
  8878. names: {
  8879. blockName: TBS_CERTIFICATE_EXTENSIONS
  8880. }
  8881. })]
  8882. })
  8883. ]
  8884. }));
  8885. }
  8886. class Certificate extends PkiObject {
  8887. get tbs() {
  8888. return pvtsutils.BufferSourceConverter.toArrayBuffer(this.tbsView);
  8889. }
  8890. set tbs(value) {
  8891. this.tbsView = new Uint8Array(value);
  8892. }
  8893. constructor(parameters = {}) {
  8894. super();
  8895. this.tbsView = new Uint8Array(pvutils.getParametersValue(parameters, TBS$4, Certificate.defaultValues(TBS$4)));
  8896. this.version = pvutils.getParametersValue(parameters, VERSION$f, Certificate.defaultValues(VERSION$f));
  8897. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$3, Certificate.defaultValues(SERIAL_NUMBER$3));
  8898. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$4, Certificate.defaultValues(SIGNATURE$4));
  8899. this.issuer = pvutils.getParametersValue(parameters, ISSUER$2, Certificate.defaultValues(ISSUER$2));
  8900. this.notBefore = pvutils.getParametersValue(parameters, NOT_BEFORE, Certificate.defaultValues(NOT_BEFORE));
  8901. this.notAfter = pvutils.getParametersValue(parameters, NOT_AFTER, Certificate.defaultValues(NOT_AFTER));
  8902. this.subject = pvutils.getParametersValue(parameters, SUBJECT$1, Certificate.defaultValues(SUBJECT$1));
  8903. this.subjectPublicKeyInfo = pvutils.getParametersValue(parameters, SUBJECT_PUBLIC_KEY_INFO, Certificate.defaultValues(SUBJECT_PUBLIC_KEY_INFO));
  8904. if (ISSUER_UNIQUE_ID in parameters) {
  8905. this.issuerUniqueID = pvutils.getParametersValue(parameters, ISSUER_UNIQUE_ID, Certificate.defaultValues(ISSUER_UNIQUE_ID));
  8906. }
  8907. if (SUBJECT_UNIQUE_ID in parameters) {
  8908. this.subjectUniqueID = pvutils.getParametersValue(parameters, SUBJECT_UNIQUE_ID, Certificate.defaultValues(SUBJECT_UNIQUE_ID));
  8909. }
  8910. if (EXTENSIONS$2 in parameters) {
  8911. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$2, Certificate.defaultValues(EXTENSIONS$2));
  8912. }
  8913. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$5, Certificate.defaultValues(SIGNATURE_ALGORITHM$5));
  8914. this.signatureValue = pvutils.getParametersValue(parameters, SIGNATURE_VALUE$2, Certificate.defaultValues(SIGNATURE_VALUE$2));
  8915. if (parameters.schema) {
  8916. this.fromSchema(parameters.schema);
  8917. }
  8918. }
  8919. static defaultValues(memberName) {
  8920. switch (memberName) {
  8921. case TBS$4:
  8922. return EMPTY_BUFFER;
  8923. case VERSION$f:
  8924. return 0;
  8925. case SERIAL_NUMBER$3:
  8926. return new asn1js.Integer();
  8927. case SIGNATURE$4:
  8928. return new AlgorithmIdentifier();
  8929. case ISSUER$2:
  8930. return new RelativeDistinguishedNames();
  8931. case NOT_BEFORE:
  8932. return new Time();
  8933. case NOT_AFTER:
  8934. return new Time();
  8935. case SUBJECT$1:
  8936. return new RelativeDistinguishedNames();
  8937. case SUBJECT_PUBLIC_KEY_INFO:
  8938. return new PublicKeyInfo();
  8939. case ISSUER_UNIQUE_ID:
  8940. return EMPTY_BUFFER;
  8941. case SUBJECT_UNIQUE_ID:
  8942. return EMPTY_BUFFER;
  8943. case EXTENSIONS$2:
  8944. return [];
  8945. case SIGNATURE_ALGORITHM$5:
  8946. return new AlgorithmIdentifier();
  8947. case SIGNATURE_VALUE$2:
  8948. return new asn1js.BitString();
  8949. default:
  8950. return super.defaultValues(memberName);
  8951. }
  8952. }
  8953. static schema(parameters = {}) {
  8954. const names = pvutils.getParametersValue(parameters, "names", {});
  8955. return (new asn1js.Sequence({
  8956. name: (names.blockName || EMPTY_STRING),
  8957. value: [
  8958. tbsCertificate(names.tbsCertificate),
  8959. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  8960. names: {
  8961. blockName: SIGNATURE_ALGORITHM$5
  8962. }
  8963. }),
  8964. new asn1js.BitString({ name: (names.signatureValue || SIGNATURE_VALUE$2) })
  8965. ]
  8966. }));
  8967. }
  8968. fromSchema(schema) {
  8969. pvutils.clearProps(schema, CLEAR_PROPS$Q);
  8970. const asn1 = asn1js.compareSchema(schema, schema, Certificate.schema({
  8971. names: {
  8972. tbsCertificate: {
  8973. names: {
  8974. extensions: {
  8975. names: {
  8976. extensions: TBS_CERTIFICATE_EXTENSIONS
  8977. }
  8978. }
  8979. }
  8980. }
  8981. }
  8982. }));
  8983. AsnError.assertSchema(asn1, this.className);
  8984. this.tbsView = asn1.result.tbsCertificate.valueBeforeDecodeView;
  8985. if (TBS_CERTIFICATE_VERSION in asn1.result)
  8986. this.version = asn1.result[TBS_CERTIFICATE_VERSION].valueBlock.valueDec;
  8987. this.serialNumber = asn1.result[TBS_CERTIFICATE_SERIAL_NUMBER];
  8988. this.signature = new AlgorithmIdentifier({ schema: asn1.result[TBS_CERTIFICATE_SIGNATURE] });
  8989. this.issuer = new RelativeDistinguishedNames({ schema: asn1.result[TBS_CERTIFICATE_ISSUER] });
  8990. this.notBefore = new Time({ schema: asn1.result[TBS_CERTIFICATE_NOT_BEFORE] });
  8991. this.notAfter = new Time({ schema: asn1.result[TBS_CERTIFICATE_NOT_AFTER] });
  8992. this.subject = new RelativeDistinguishedNames({ schema: asn1.result[TBS_CERTIFICATE_SUBJECT] });
  8993. this.subjectPublicKeyInfo = new PublicKeyInfo({ schema: asn1.result[TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY] });
  8994. if (TBS_CERTIFICATE_ISSUER_UNIQUE_ID in asn1.result)
  8995. this.issuerUniqueID = asn1.result[TBS_CERTIFICATE_ISSUER_UNIQUE_ID].valueBlock.valueHex;
  8996. if (TBS_CERTIFICATE_SUBJECT_UNIQUE_ID in asn1.result)
  8997. this.subjectUniqueID = asn1.result[TBS_CERTIFICATE_SUBJECT_UNIQUE_ID].valueBlock.valueHex;
  8998. if (TBS_CERTIFICATE_EXTENSIONS in asn1.result)
  8999. this.extensions = Array.from(asn1.result[TBS_CERTIFICATE_EXTENSIONS], element => new Extension({ schema: element }));
  9000. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  9001. this.signatureValue = asn1.result.signatureValue;
  9002. }
  9003. encodeTBS() {
  9004. const outputArray = [];
  9005. if ((VERSION$f in this) && (this.version !== Certificate.defaultValues(VERSION$f))) {
  9006. outputArray.push(new asn1js.Constructed({
  9007. optional: true,
  9008. idBlock: {
  9009. tagClass: 3,
  9010. tagNumber: 0
  9011. },
  9012. value: [
  9013. new asn1js.Integer({ value: this.version })
  9014. ]
  9015. }));
  9016. }
  9017. outputArray.push(this.serialNumber);
  9018. outputArray.push(this.signature.toSchema());
  9019. outputArray.push(this.issuer.toSchema());
  9020. outputArray.push(new asn1js.Sequence({
  9021. value: [
  9022. this.notBefore.toSchema(),
  9023. this.notAfter.toSchema()
  9024. ]
  9025. }));
  9026. outputArray.push(this.subject.toSchema());
  9027. outputArray.push(this.subjectPublicKeyInfo.toSchema());
  9028. if (this.issuerUniqueID) {
  9029. outputArray.push(new asn1js.Primitive({
  9030. optional: true,
  9031. idBlock: {
  9032. tagClass: 3,
  9033. tagNumber: 1
  9034. },
  9035. valueHex: this.issuerUniqueID
  9036. }));
  9037. }
  9038. if (this.subjectUniqueID) {
  9039. outputArray.push(new asn1js.Primitive({
  9040. optional: true,
  9041. idBlock: {
  9042. tagClass: 3,
  9043. tagNumber: 2
  9044. },
  9045. valueHex: this.subjectUniqueID
  9046. }));
  9047. }
  9048. if (this.extensions) {
  9049. outputArray.push(new asn1js.Constructed({
  9050. optional: true,
  9051. idBlock: {
  9052. tagClass: 3,
  9053. tagNumber: 3
  9054. },
  9055. value: [new asn1js.Sequence({
  9056. value: Array.from(this.extensions, o => o.toSchema())
  9057. })]
  9058. }));
  9059. }
  9060. return (new asn1js.Sequence({
  9061. value: outputArray
  9062. }));
  9063. }
  9064. toSchema(encodeFlag = false) {
  9065. let tbsSchema;
  9066. if (encodeFlag === false) {
  9067. if (!this.tbsView.byteLength) {
  9068. return Certificate.schema().value[0];
  9069. }
  9070. const asn1 = asn1js.fromBER(this.tbsView);
  9071. AsnError.assert(asn1, "TBS Certificate");
  9072. tbsSchema = asn1.result;
  9073. }
  9074. else {
  9075. tbsSchema = this.encodeTBS();
  9076. }
  9077. return (new asn1js.Sequence({
  9078. value: [
  9079. tbsSchema,
  9080. this.signatureAlgorithm.toSchema(),
  9081. this.signatureValue
  9082. ]
  9083. }));
  9084. }
  9085. toJSON() {
  9086. const res = {
  9087. tbs: pvtsutils.Convert.ToHex(this.tbsView),
  9088. version: this.version,
  9089. serialNumber: this.serialNumber.toJSON(),
  9090. signature: this.signature.toJSON(),
  9091. issuer: this.issuer.toJSON(),
  9092. notBefore: this.notBefore.toJSON(),
  9093. notAfter: this.notAfter.toJSON(),
  9094. subject: this.subject.toJSON(),
  9095. subjectPublicKeyInfo: this.subjectPublicKeyInfo.toJSON(),
  9096. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  9097. signatureValue: this.signatureValue.toJSON(),
  9098. };
  9099. if ((VERSION$f in this) && (this.version !== Certificate.defaultValues(VERSION$f))) {
  9100. res.version = this.version;
  9101. }
  9102. if (this.issuerUniqueID) {
  9103. res.issuerUniqueID = pvtsutils.Convert.ToHex(this.issuerUniqueID);
  9104. }
  9105. if (this.subjectUniqueID) {
  9106. res.subjectUniqueID = pvtsutils.Convert.ToHex(this.subjectUniqueID);
  9107. }
  9108. if (this.extensions) {
  9109. res.extensions = Array.from(this.extensions, o => o.toJSON());
  9110. }
  9111. return res;
  9112. }
  9113. async getPublicKey(parameters, crypto = getCrypto(true)) {
  9114. return crypto.getPublicKey(this.subjectPublicKeyInfo, this.signatureAlgorithm, parameters);
  9115. }
  9116. async getKeyHash(hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  9117. return crypto.digest({ name: hashAlgorithm }, this.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView);
  9118. }
  9119. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  9120. if (!privateKey) {
  9121. throw new Error("Need to provide a private key for signing");
  9122. }
  9123. const signatureParameters = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  9124. const parameters = signatureParameters.parameters;
  9125. this.signature = signatureParameters.signatureAlgorithm;
  9126. this.signatureAlgorithm = signatureParameters.signatureAlgorithm;
  9127. this.tbsView = new Uint8Array(this.encodeTBS().toBER());
  9128. const signature = await crypto.signWithPrivateKey(this.tbsView, privateKey, parameters);
  9129. this.signatureValue = new asn1js.BitString({ valueHex: signature });
  9130. }
  9131. async verify(issuerCertificate, crypto = getCrypto(true)) {
  9132. let subjectPublicKeyInfo;
  9133. if (issuerCertificate) {
  9134. subjectPublicKeyInfo = issuerCertificate.subjectPublicKeyInfo;
  9135. }
  9136. else if (this.issuer.isEqual(this.subject)) {
  9137. subjectPublicKeyInfo = this.subjectPublicKeyInfo;
  9138. }
  9139. if (!(subjectPublicKeyInfo instanceof PublicKeyInfo)) {
  9140. throw new Error("Please provide issuer certificate as a parameter");
  9141. }
  9142. return crypto.verifyWithPublicKey(this.tbsView, this.signatureValue, subjectPublicKeyInfo, this.signatureAlgorithm);
  9143. }
  9144. }
  9145. Certificate.CLASS_NAME = "Certificate";
  9146. function checkCA(cert, signerCert = null) {
  9147. if (signerCert && cert.issuer.isEqual(signerCert.issuer) && cert.serialNumber.isEqual(signerCert.serialNumber)) {
  9148. return null;
  9149. }
  9150. let isCA = false;
  9151. if (cert.extensions) {
  9152. for (const extension of cert.extensions) {
  9153. if (extension.extnID === id_BasicConstraints && extension.parsedValue instanceof BasicConstraints) {
  9154. if (extension.parsedValue.cA) {
  9155. isCA = true;
  9156. break;
  9157. }
  9158. }
  9159. }
  9160. }
  9161. if (isCA) {
  9162. return cert;
  9163. }
  9164. return null;
  9165. }
  9166. const CERT_ID$1 = "certId";
  9167. const CERT_VALUE = "certValue";
  9168. const PARSED_VALUE$4 = "parsedValue";
  9169. const CLEAR_PROPS$P = [
  9170. CERT_ID$1,
  9171. CERT_VALUE
  9172. ];
  9173. class CertBag extends PkiObject {
  9174. constructor(parameters = {}) {
  9175. super();
  9176. this.certId = pvutils.getParametersValue(parameters, CERT_ID$1, CertBag.defaultValues(CERT_ID$1));
  9177. this.certValue = pvutils.getParametersValue(parameters, CERT_VALUE, CertBag.defaultValues(CERT_VALUE));
  9178. if (PARSED_VALUE$4 in parameters) {
  9179. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE$4, CertBag.defaultValues(PARSED_VALUE$4));
  9180. }
  9181. if (parameters.schema) {
  9182. this.fromSchema(parameters.schema);
  9183. }
  9184. }
  9185. static defaultValues(memberName) {
  9186. switch (memberName) {
  9187. case CERT_ID$1:
  9188. return EMPTY_STRING;
  9189. case CERT_VALUE:
  9190. return (new asn1js.Any());
  9191. case PARSED_VALUE$4:
  9192. return {};
  9193. default:
  9194. return super.defaultValues(memberName);
  9195. }
  9196. }
  9197. static compareWithDefault(memberName, memberValue) {
  9198. switch (memberName) {
  9199. case CERT_ID$1:
  9200. return (memberValue === EMPTY_STRING);
  9201. case CERT_VALUE:
  9202. return (memberValue instanceof asn1js.Any);
  9203. case PARSED_VALUE$4:
  9204. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  9205. default:
  9206. return super.defaultValues(memberName);
  9207. }
  9208. }
  9209. static schema(parameters = {}) {
  9210. const names = pvutils.getParametersValue(parameters, "names", {});
  9211. return (new asn1js.Sequence({
  9212. name: (names.blockName || EMPTY_STRING),
  9213. value: [
  9214. new asn1js.ObjectIdentifier({ name: (names.id || "id") }),
  9215. new asn1js.Constructed({
  9216. idBlock: {
  9217. tagClass: 3,
  9218. tagNumber: 0
  9219. },
  9220. value: [new asn1js.Any({ name: (names.value || "value") })]
  9221. })
  9222. ]
  9223. }));
  9224. }
  9225. fromSchema(schema) {
  9226. pvutils.clearProps(schema, CLEAR_PROPS$P);
  9227. const asn1 = asn1js.compareSchema(schema, schema, CertBag.schema({
  9228. names: {
  9229. id: CERT_ID$1,
  9230. value: CERT_VALUE
  9231. }
  9232. }));
  9233. AsnError.assertSchema(asn1, this.className);
  9234. this.certId = asn1.result.certId.valueBlock.toString();
  9235. this.certValue = asn1.result.certValue;
  9236. const certValueHex = this.certValue.valueBlock.valueHexView;
  9237. switch (this.certId) {
  9238. case id_CertBag_X509Certificate:
  9239. {
  9240. try {
  9241. this.parsedValue = Certificate.fromBER(certValueHex);
  9242. }
  9243. catch {
  9244. AttributeCertificateV2.fromBER(certValueHex);
  9245. }
  9246. }
  9247. break;
  9248. case id_CertBag_AttributeCertificate:
  9249. {
  9250. this.parsedValue = AttributeCertificateV2.fromBER(certValueHex);
  9251. }
  9252. break;
  9253. case id_CertBag_SDSICertificate:
  9254. default:
  9255. throw new Error(`Incorrect CERT_ID value in CertBag: ${this.certId}`);
  9256. }
  9257. }
  9258. toSchema() {
  9259. if (PARSED_VALUE$4 in this) {
  9260. if ("acinfo" in this.parsedValue) {
  9261. this.certId = id_CertBag_AttributeCertificate;
  9262. }
  9263. else {
  9264. this.certId = id_CertBag_X509Certificate;
  9265. }
  9266. this.certValue = new asn1js.OctetString({ valueHex: this.parsedValue.toSchema().toBER(false) });
  9267. }
  9268. return (new asn1js.Sequence({
  9269. value: [
  9270. new asn1js.ObjectIdentifier({ value: this.certId }),
  9271. new asn1js.Constructed({
  9272. idBlock: {
  9273. tagClass: 3,
  9274. tagNumber: 0
  9275. },
  9276. value: [(("toSchema" in this.certValue) ? this.certValue.toSchema() : this.certValue)]
  9277. })
  9278. ]
  9279. }));
  9280. }
  9281. toJSON() {
  9282. return {
  9283. certId: this.certId,
  9284. certValue: this.certValue.toJSON()
  9285. };
  9286. }
  9287. }
  9288. CertBag.CLASS_NAME = "CertBag";
  9289. const USER_CERTIFICATE = "userCertificate";
  9290. const REVOCATION_DATE = "revocationDate";
  9291. const CRL_ENTRY_EXTENSIONS = "crlEntryExtensions";
  9292. const CLEAR_PROPS$O = [
  9293. USER_CERTIFICATE,
  9294. REVOCATION_DATE,
  9295. CRL_ENTRY_EXTENSIONS
  9296. ];
  9297. class RevokedCertificate extends PkiObject {
  9298. constructor(parameters = {}) {
  9299. super();
  9300. this.userCertificate = pvutils.getParametersValue(parameters, USER_CERTIFICATE, RevokedCertificate.defaultValues(USER_CERTIFICATE));
  9301. this.revocationDate = pvutils.getParametersValue(parameters, REVOCATION_DATE, RevokedCertificate.defaultValues(REVOCATION_DATE));
  9302. if (CRL_ENTRY_EXTENSIONS in parameters) {
  9303. this.crlEntryExtensions = pvutils.getParametersValue(parameters, CRL_ENTRY_EXTENSIONS, RevokedCertificate.defaultValues(CRL_ENTRY_EXTENSIONS));
  9304. }
  9305. if (parameters.schema) {
  9306. this.fromSchema(parameters.schema);
  9307. }
  9308. }
  9309. static defaultValues(memberName) {
  9310. switch (memberName) {
  9311. case USER_CERTIFICATE:
  9312. return new asn1js.Integer();
  9313. case REVOCATION_DATE:
  9314. return new Time();
  9315. case CRL_ENTRY_EXTENSIONS:
  9316. return new Extensions();
  9317. default:
  9318. return super.defaultValues(memberName);
  9319. }
  9320. }
  9321. static schema(parameters = {}) {
  9322. const names = pvutils.getParametersValue(parameters, "names", {});
  9323. return new asn1js.Sequence({
  9324. name: (names.blockName || EMPTY_STRING),
  9325. value: [
  9326. new asn1js.Integer({ name: (names.userCertificate || USER_CERTIFICATE) }),
  9327. Time.schema({
  9328. names: {
  9329. utcTimeName: (names.revocationDate || REVOCATION_DATE),
  9330. generalTimeName: (names.revocationDate || REVOCATION_DATE)
  9331. }
  9332. }),
  9333. Extensions.schema({
  9334. names: {
  9335. blockName: (names.crlEntryExtensions || CRL_ENTRY_EXTENSIONS)
  9336. }
  9337. }, true)
  9338. ]
  9339. });
  9340. }
  9341. fromSchema(schema) {
  9342. pvutils.clearProps(schema, CLEAR_PROPS$O);
  9343. const asn1 = asn1js.compareSchema(schema, schema, RevokedCertificate.schema());
  9344. AsnError.assertSchema(asn1, this.className);
  9345. this.userCertificate = asn1.result.userCertificate;
  9346. this.revocationDate = new Time({ schema: asn1.result.revocationDate });
  9347. if (CRL_ENTRY_EXTENSIONS in asn1.result) {
  9348. this.crlEntryExtensions = new Extensions({ schema: asn1.result.crlEntryExtensions });
  9349. }
  9350. }
  9351. toSchema() {
  9352. const outputArray = [
  9353. this.userCertificate,
  9354. this.revocationDate.toSchema()
  9355. ];
  9356. if (this.crlEntryExtensions) {
  9357. outputArray.push(this.crlEntryExtensions.toSchema());
  9358. }
  9359. return (new asn1js.Sequence({
  9360. value: outputArray
  9361. }));
  9362. }
  9363. toJSON() {
  9364. const res = {
  9365. userCertificate: this.userCertificate.toJSON(),
  9366. revocationDate: this.revocationDate.toJSON(),
  9367. };
  9368. if (this.crlEntryExtensions) {
  9369. res.crlEntryExtensions = this.crlEntryExtensions.toJSON();
  9370. }
  9371. return res;
  9372. }
  9373. }
  9374. RevokedCertificate.CLASS_NAME = "RevokedCertificate";
  9375. const TBS$3 = "tbs";
  9376. const VERSION$e = "version";
  9377. const SIGNATURE$3 = "signature";
  9378. const ISSUER$1 = "issuer";
  9379. const THIS_UPDATE$1 = "thisUpdate";
  9380. const NEXT_UPDATE$1 = "nextUpdate";
  9381. const REVOKED_CERTIFICATES = "revokedCertificates";
  9382. const CRL_EXTENSIONS = "crlExtensions";
  9383. const SIGNATURE_ALGORITHM$4 = "signatureAlgorithm";
  9384. const SIGNATURE_VALUE$1 = "signatureValue";
  9385. const TBS_CERT_LIST = "tbsCertList";
  9386. const TBS_CERT_LIST_VERSION = `${TBS_CERT_LIST}.version`;
  9387. const TBS_CERT_LIST_SIGNATURE = `${TBS_CERT_LIST}.signature`;
  9388. const TBS_CERT_LIST_ISSUER = `${TBS_CERT_LIST}.issuer`;
  9389. const TBS_CERT_LIST_THIS_UPDATE = `${TBS_CERT_LIST}.thisUpdate`;
  9390. const TBS_CERT_LIST_NEXT_UPDATE = `${TBS_CERT_LIST}.nextUpdate`;
  9391. const TBS_CERT_LIST_REVOKED_CERTIFICATES = `${TBS_CERT_LIST}.revokedCertificates`;
  9392. const TBS_CERT_LIST_EXTENSIONS = `${TBS_CERT_LIST}.extensions`;
  9393. const CLEAR_PROPS$N = [
  9394. TBS_CERT_LIST,
  9395. TBS_CERT_LIST_VERSION,
  9396. TBS_CERT_LIST_SIGNATURE,
  9397. TBS_CERT_LIST_ISSUER,
  9398. TBS_CERT_LIST_THIS_UPDATE,
  9399. TBS_CERT_LIST_NEXT_UPDATE,
  9400. TBS_CERT_LIST_REVOKED_CERTIFICATES,
  9401. TBS_CERT_LIST_EXTENSIONS,
  9402. SIGNATURE_ALGORITHM$4,
  9403. SIGNATURE_VALUE$1
  9404. ];
  9405. function tbsCertList(parameters = {}) {
  9406. const names = pvutils.getParametersValue(parameters, "names", {});
  9407. return (new asn1js.Sequence({
  9408. name: (names.blockName || TBS_CERT_LIST),
  9409. value: [
  9410. new asn1js.Integer({
  9411. optional: true,
  9412. name: (names.tbsCertListVersion || TBS_CERT_LIST_VERSION),
  9413. value: 2
  9414. }),
  9415. AlgorithmIdentifier.schema(names.signature || {
  9416. names: {
  9417. blockName: TBS_CERT_LIST_SIGNATURE
  9418. }
  9419. }),
  9420. RelativeDistinguishedNames.schema(names.issuer || {
  9421. names: {
  9422. blockName: TBS_CERT_LIST_ISSUER
  9423. }
  9424. }),
  9425. Time.schema(names.tbsCertListThisUpdate || {
  9426. names: {
  9427. utcTimeName: TBS_CERT_LIST_THIS_UPDATE,
  9428. generalTimeName: TBS_CERT_LIST_THIS_UPDATE
  9429. }
  9430. }),
  9431. Time.schema(names.tbsCertListNextUpdate || {
  9432. names: {
  9433. utcTimeName: TBS_CERT_LIST_NEXT_UPDATE,
  9434. generalTimeName: TBS_CERT_LIST_NEXT_UPDATE
  9435. }
  9436. }, true),
  9437. new asn1js.Sequence({
  9438. optional: true,
  9439. value: [
  9440. new asn1js.Repeated({
  9441. name: (names.tbsCertListRevokedCertificates || TBS_CERT_LIST_REVOKED_CERTIFICATES),
  9442. value: new asn1js.Sequence({
  9443. value: [
  9444. new asn1js.Integer(),
  9445. Time.schema(),
  9446. Extensions.schema({}, true)
  9447. ]
  9448. })
  9449. })
  9450. ]
  9451. }),
  9452. new asn1js.Constructed({
  9453. optional: true,
  9454. idBlock: {
  9455. tagClass: 3,
  9456. tagNumber: 0
  9457. },
  9458. value: [Extensions.schema(names.crlExtensions || {
  9459. names: {
  9460. blockName: TBS_CERT_LIST_EXTENSIONS
  9461. }
  9462. })]
  9463. })
  9464. ]
  9465. }));
  9466. }
  9467. const WELL_KNOWN_EXTENSIONS = [
  9468. id_AuthorityKeyIdentifier,
  9469. id_IssuerAltName,
  9470. id_CRLNumber,
  9471. id_BaseCRLNumber,
  9472. id_IssuingDistributionPoint,
  9473. id_FreshestCRL,
  9474. id_AuthorityInfoAccess,
  9475. id_CRLReason,
  9476. id_InvalidityDate,
  9477. id_CertificateIssuer,
  9478. ];
  9479. class CertificateRevocationList extends PkiObject {
  9480. get tbs() {
  9481. return pvtsutils.BufferSourceConverter.toArrayBuffer(this.tbsView);
  9482. }
  9483. set tbs(value) {
  9484. this.tbsView = new Uint8Array(value);
  9485. }
  9486. constructor(parameters = {}) {
  9487. super();
  9488. this.tbsView = new Uint8Array(pvutils.getParametersValue(parameters, TBS$3, CertificateRevocationList.defaultValues(TBS$3)));
  9489. this.version = pvutils.getParametersValue(parameters, VERSION$e, CertificateRevocationList.defaultValues(VERSION$e));
  9490. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$3, CertificateRevocationList.defaultValues(SIGNATURE$3));
  9491. this.issuer = pvutils.getParametersValue(parameters, ISSUER$1, CertificateRevocationList.defaultValues(ISSUER$1));
  9492. this.thisUpdate = pvutils.getParametersValue(parameters, THIS_UPDATE$1, CertificateRevocationList.defaultValues(THIS_UPDATE$1));
  9493. if (NEXT_UPDATE$1 in parameters) {
  9494. this.nextUpdate = pvutils.getParametersValue(parameters, NEXT_UPDATE$1, CertificateRevocationList.defaultValues(NEXT_UPDATE$1));
  9495. }
  9496. if (REVOKED_CERTIFICATES in parameters) {
  9497. this.revokedCertificates = pvutils.getParametersValue(parameters, REVOKED_CERTIFICATES, CertificateRevocationList.defaultValues(REVOKED_CERTIFICATES));
  9498. }
  9499. if (CRL_EXTENSIONS in parameters) {
  9500. this.crlExtensions = pvutils.getParametersValue(parameters, CRL_EXTENSIONS, CertificateRevocationList.defaultValues(CRL_EXTENSIONS));
  9501. }
  9502. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$4, CertificateRevocationList.defaultValues(SIGNATURE_ALGORITHM$4));
  9503. this.signatureValue = pvutils.getParametersValue(parameters, SIGNATURE_VALUE$1, CertificateRevocationList.defaultValues(SIGNATURE_VALUE$1));
  9504. if (parameters.schema) {
  9505. this.fromSchema(parameters.schema);
  9506. }
  9507. }
  9508. static defaultValues(memberName) {
  9509. switch (memberName) {
  9510. case TBS$3:
  9511. return EMPTY_BUFFER;
  9512. case VERSION$e:
  9513. return 0;
  9514. case SIGNATURE$3:
  9515. return new AlgorithmIdentifier();
  9516. case ISSUER$1:
  9517. return new RelativeDistinguishedNames();
  9518. case THIS_UPDATE$1:
  9519. return new Time();
  9520. case NEXT_UPDATE$1:
  9521. return new Time();
  9522. case REVOKED_CERTIFICATES:
  9523. return [];
  9524. case CRL_EXTENSIONS:
  9525. return new Extensions();
  9526. case SIGNATURE_ALGORITHM$4:
  9527. return new AlgorithmIdentifier();
  9528. case SIGNATURE_VALUE$1:
  9529. return new asn1js.BitString();
  9530. default:
  9531. return super.defaultValues(memberName);
  9532. }
  9533. }
  9534. static schema(parameters = {}) {
  9535. const names = pvutils.getParametersValue(parameters, "names", {});
  9536. return (new asn1js.Sequence({
  9537. name: (names.blockName || "CertificateList"),
  9538. value: [
  9539. tbsCertList(parameters),
  9540. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  9541. names: {
  9542. blockName: SIGNATURE_ALGORITHM$4
  9543. }
  9544. }),
  9545. new asn1js.BitString({ name: (names.signatureValue || SIGNATURE_VALUE$1) })
  9546. ]
  9547. }));
  9548. }
  9549. fromSchema(schema) {
  9550. pvutils.clearProps(schema, CLEAR_PROPS$N);
  9551. const asn1 = asn1js.compareSchema(schema, schema, CertificateRevocationList.schema());
  9552. AsnError.assertSchema(asn1, this.className);
  9553. this.tbsView = asn1.result.tbsCertList.valueBeforeDecodeView;
  9554. if (TBS_CERT_LIST_VERSION in asn1.result) {
  9555. this.version = asn1.result[TBS_CERT_LIST_VERSION].valueBlock.valueDec;
  9556. }
  9557. this.signature = new AlgorithmIdentifier({ schema: asn1.result[TBS_CERT_LIST_SIGNATURE] });
  9558. this.issuer = new RelativeDistinguishedNames({ schema: asn1.result[TBS_CERT_LIST_ISSUER] });
  9559. this.thisUpdate = new Time({ schema: asn1.result[TBS_CERT_LIST_THIS_UPDATE] });
  9560. if (TBS_CERT_LIST_NEXT_UPDATE in asn1.result) {
  9561. this.nextUpdate = new Time({ schema: asn1.result[TBS_CERT_LIST_NEXT_UPDATE] });
  9562. }
  9563. if (TBS_CERT_LIST_REVOKED_CERTIFICATES in asn1.result) {
  9564. this.revokedCertificates = Array.from(asn1.result[TBS_CERT_LIST_REVOKED_CERTIFICATES], element => new RevokedCertificate({ schema: element }));
  9565. }
  9566. if (TBS_CERT_LIST_EXTENSIONS in asn1.result) {
  9567. this.crlExtensions = new Extensions({ schema: asn1.result[TBS_CERT_LIST_EXTENSIONS] });
  9568. }
  9569. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  9570. this.signatureValue = asn1.result.signatureValue;
  9571. }
  9572. encodeTBS() {
  9573. const outputArray = [];
  9574. if (this.version !== CertificateRevocationList.defaultValues(VERSION$e)) {
  9575. outputArray.push(new asn1js.Integer({ value: this.version }));
  9576. }
  9577. outputArray.push(this.signature.toSchema());
  9578. outputArray.push(this.issuer.toSchema());
  9579. outputArray.push(this.thisUpdate.toSchema());
  9580. if (this.nextUpdate) {
  9581. outputArray.push(this.nextUpdate.toSchema());
  9582. }
  9583. if (this.revokedCertificates) {
  9584. outputArray.push(new asn1js.Sequence({
  9585. value: Array.from(this.revokedCertificates, o => o.toSchema())
  9586. }));
  9587. }
  9588. if (this.crlExtensions) {
  9589. outputArray.push(new asn1js.Constructed({
  9590. optional: true,
  9591. idBlock: {
  9592. tagClass: 3,
  9593. tagNumber: 0
  9594. },
  9595. value: [
  9596. this.crlExtensions.toSchema()
  9597. ]
  9598. }));
  9599. }
  9600. return (new asn1js.Sequence({
  9601. value: outputArray
  9602. }));
  9603. }
  9604. toSchema(encodeFlag = false) {
  9605. let tbsSchema;
  9606. if (!encodeFlag) {
  9607. if (!this.tbsView.byteLength) {
  9608. return CertificateRevocationList.schema();
  9609. }
  9610. const asn1 = asn1js.fromBER(this.tbsView);
  9611. AsnError.assert(asn1, "TBS Certificate Revocation List");
  9612. tbsSchema = asn1.result;
  9613. }
  9614. else {
  9615. tbsSchema = this.encodeTBS();
  9616. }
  9617. return (new asn1js.Sequence({
  9618. value: [
  9619. tbsSchema,
  9620. this.signatureAlgorithm.toSchema(),
  9621. this.signatureValue
  9622. ]
  9623. }));
  9624. }
  9625. toJSON() {
  9626. const res = {
  9627. tbs: pvtsutils.Convert.ToHex(this.tbsView),
  9628. version: this.version,
  9629. signature: this.signature.toJSON(),
  9630. issuer: this.issuer.toJSON(),
  9631. thisUpdate: this.thisUpdate.toJSON(),
  9632. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  9633. signatureValue: this.signatureValue.toJSON()
  9634. };
  9635. if (this.version !== CertificateRevocationList.defaultValues(VERSION$e))
  9636. res.version = this.version;
  9637. if (this.nextUpdate) {
  9638. res.nextUpdate = this.nextUpdate.toJSON();
  9639. }
  9640. if (this.revokedCertificates) {
  9641. res.revokedCertificates = Array.from(this.revokedCertificates, o => o.toJSON());
  9642. }
  9643. if (this.crlExtensions) {
  9644. res.crlExtensions = this.crlExtensions.toJSON();
  9645. }
  9646. return res;
  9647. }
  9648. isCertificateRevoked(certificate) {
  9649. if (!this.issuer.isEqual(certificate.issuer)) {
  9650. return false;
  9651. }
  9652. if (!this.revokedCertificates) {
  9653. return false;
  9654. }
  9655. for (const revokedCertificate of this.revokedCertificates) {
  9656. if (revokedCertificate.userCertificate.isEqual(certificate.serialNumber)) {
  9657. return true;
  9658. }
  9659. }
  9660. return false;
  9661. }
  9662. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  9663. if (!privateKey) {
  9664. throw new Error("Need to provide a private key for signing");
  9665. }
  9666. const signatureParameters = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  9667. const { parameters } = signatureParameters;
  9668. this.signature = signatureParameters.signatureAlgorithm;
  9669. this.signatureAlgorithm = signatureParameters.signatureAlgorithm;
  9670. this.tbsView = new Uint8Array(this.encodeTBS().toBER());
  9671. const signature = await crypto.signWithPrivateKey(this.tbsView, privateKey, parameters);
  9672. this.signatureValue = new asn1js.BitString({ valueHex: signature });
  9673. }
  9674. async verify(parameters = {}, crypto = getCrypto(true)) {
  9675. let subjectPublicKeyInfo;
  9676. if (parameters.issuerCertificate) {
  9677. subjectPublicKeyInfo = parameters.issuerCertificate.subjectPublicKeyInfo;
  9678. if (!this.issuer.isEqual(parameters.issuerCertificate.subject)) {
  9679. return false;
  9680. }
  9681. }
  9682. if (parameters.publicKeyInfo) {
  9683. subjectPublicKeyInfo = parameters.publicKeyInfo;
  9684. }
  9685. if (!subjectPublicKeyInfo) {
  9686. throw new Error("Issuer's certificate must be provided as an input parameter");
  9687. }
  9688. if (this.crlExtensions) {
  9689. for (const extension of this.crlExtensions.extensions) {
  9690. if (extension.critical) {
  9691. if (!WELL_KNOWN_EXTENSIONS.includes(extension.extnID))
  9692. return false;
  9693. }
  9694. }
  9695. }
  9696. return crypto.verifyWithPublicKey(this.tbsView, this.signatureValue, subjectPublicKeyInfo, this.signatureAlgorithm);
  9697. }
  9698. }
  9699. CertificateRevocationList.CLASS_NAME = "CertificateRevocationList";
  9700. const CRL_ID = "crlId";
  9701. const CRL_VALUE = "crlValue";
  9702. const PARSED_VALUE$3 = "parsedValue";
  9703. const CLEAR_PROPS$M = [
  9704. CRL_ID,
  9705. CRL_VALUE,
  9706. ];
  9707. class CRLBag extends PkiObject {
  9708. constructor(parameters = {}) {
  9709. super();
  9710. this.crlId = pvutils.getParametersValue(parameters, CRL_ID, CRLBag.defaultValues(CRL_ID));
  9711. this.crlValue = pvutils.getParametersValue(parameters, CRL_VALUE, CRLBag.defaultValues(CRL_VALUE));
  9712. if (PARSED_VALUE$3 in parameters) {
  9713. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE$3, CRLBag.defaultValues(PARSED_VALUE$3));
  9714. }
  9715. if (parameters.schema) {
  9716. this.fromSchema(parameters.schema);
  9717. }
  9718. }
  9719. static defaultValues(memberName) {
  9720. switch (memberName) {
  9721. case CRL_ID:
  9722. return EMPTY_STRING;
  9723. case CRL_VALUE:
  9724. return (new asn1js.Any());
  9725. case PARSED_VALUE$3:
  9726. return {};
  9727. default:
  9728. return super.defaultValues(memberName);
  9729. }
  9730. }
  9731. static compareWithDefault(memberName, memberValue) {
  9732. switch (memberName) {
  9733. case CRL_ID:
  9734. return (memberValue === EMPTY_STRING);
  9735. case CRL_VALUE:
  9736. return (memberValue instanceof asn1js.Any);
  9737. case PARSED_VALUE$3:
  9738. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  9739. default:
  9740. return super.defaultValues(memberName);
  9741. }
  9742. }
  9743. static schema(parameters = {}) {
  9744. const names = pvutils.getParametersValue(parameters, "names", {});
  9745. return (new asn1js.Sequence({
  9746. name: (names.blockName || EMPTY_STRING),
  9747. value: [
  9748. new asn1js.ObjectIdentifier({ name: (names.id || "id") }),
  9749. new asn1js.Constructed({
  9750. idBlock: {
  9751. tagClass: 3,
  9752. tagNumber: 0
  9753. },
  9754. value: [new asn1js.Any({ name: (names.value || "value") })]
  9755. })
  9756. ]
  9757. }));
  9758. }
  9759. fromSchema(schema) {
  9760. pvutils.clearProps(schema, CLEAR_PROPS$M);
  9761. const asn1 = asn1js.compareSchema(schema, schema, CRLBag.schema({
  9762. names: {
  9763. id: CRL_ID,
  9764. value: CRL_VALUE
  9765. }
  9766. }));
  9767. AsnError.assertSchema(asn1, this.className);
  9768. this.crlId = asn1.result.crlId.valueBlock.toString();
  9769. this.crlValue = asn1.result.crlValue;
  9770. switch (this.crlId) {
  9771. case id_CRLBag_X509CRL:
  9772. {
  9773. this.parsedValue = CertificateRevocationList.fromBER(this.certValue.valueBlock.valueHex);
  9774. }
  9775. break;
  9776. default:
  9777. throw new Error(`Incorrect CRL_ID value in CRLBag: ${this.crlId}`);
  9778. }
  9779. }
  9780. toSchema() {
  9781. if (this.parsedValue) {
  9782. this.crlId = id_CRLBag_X509CRL;
  9783. this.crlValue = new asn1js.OctetString({ valueHex: this.parsedValue.toSchema().toBER(false) });
  9784. }
  9785. return (new asn1js.Sequence({
  9786. value: [
  9787. new asn1js.ObjectIdentifier({ value: this.crlId }),
  9788. new asn1js.Constructed({
  9789. idBlock: {
  9790. tagClass: 3,
  9791. tagNumber: 0
  9792. },
  9793. value: [this.crlValue.toSchema()]
  9794. })
  9795. ]
  9796. }));
  9797. }
  9798. toJSON() {
  9799. return {
  9800. crlId: this.crlId,
  9801. crlValue: this.crlValue.toJSON()
  9802. };
  9803. }
  9804. }
  9805. CRLBag.CLASS_NAME = "CRLBag";
  9806. const VERSION$d = "version";
  9807. const ENCRYPTED_CONTENT_INFO$1 = "encryptedContentInfo";
  9808. const UNPROTECTED_ATTRS$1 = "unprotectedAttrs";
  9809. const CLEAR_PROPS$L = [
  9810. VERSION$d,
  9811. ENCRYPTED_CONTENT_INFO$1,
  9812. UNPROTECTED_ATTRS$1,
  9813. ];
  9814. class EncryptedData extends PkiObject {
  9815. constructor(parameters = {}) {
  9816. super();
  9817. this.version = pvutils.getParametersValue(parameters, VERSION$d, EncryptedData.defaultValues(VERSION$d));
  9818. this.encryptedContentInfo = pvutils.getParametersValue(parameters, ENCRYPTED_CONTENT_INFO$1, EncryptedData.defaultValues(ENCRYPTED_CONTENT_INFO$1));
  9819. if (UNPROTECTED_ATTRS$1 in parameters) {
  9820. this.unprotectedAttrs = pvutils.getParametersValue(parameters, UNPROTECTED_ATTRS$1, EncryptedData.defaultValues(UNPROTECTED_ATTRS$1));
  9821. }
  9822. if (parameters.schema) {
  9823. this.fromSchema(parameters.schema);
  9824. }
  9825. }
  9826. static defaultValues(memberName) {
  9827. switch (memberName) {
  9828. case VERSION$d:
  9829. return 0;
  9830. case ENCRYPTED_CONTENT_INFO$1:
  9831. return new EncryptedContentInfo();
  9832. case UNPROTECTED_ATTRS$1:
  9833. return [];
  9834. default:
  9835. return super.defaultValues(memberName);
  9836. }
  9837. }
  9838. static compareWithDefault(memberName, memberValue) {
  9839. switch (memberName) {
  9840. case VERSION$d:
  9841. return (memberValue === 0);
  9842. case ENCRYPTED_CONTENT_INFO$1:
  9843. return ((EncryptedContentInfo.compareWithDefault("contentType", memberValue.contentType)) &&
  9844. (EncryptedContentInfo.compareWithDefault("contentEncryptionAlgorithm", memberValue.contentEncryptionAlgorithm)) &&
  9845. (EncryptedContentInfo.compareWithDefault("encryptedContent", memberValue.encryptedContent)));
  9846. case UNPROTECTED_ATTRS$1:
  9847. return (memberValue.length === 0);
  9848. default:
  9849. return super.defaultValues(memberName);
  9850. }
  9851. }
  9852. static schema(parameters = {}) {
  9853. const names = pvutils.getParametersValue(parameters, "names", {});
  9854. return (new asn1js.Sequence({
  9855. name: (names.blockName || EMPTY_STRING),
  9856. value: [
  9857. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  9858. EncryptedContentInfo.schema(names.encryptedContentInfo || {}),
  9859. new asn1js.Constructed({
  9860. optional: true,
  9861. idBlock: {
  9862. tagClass: 3,
  9863. tagNumber: 1
  9864. },
  9865. value: [
  9866. new asn1js.Repeated({
  9867. name: (names.unprotectedAttrs || EMPTY_STRING),
  9868. value: Attribute.schema()
  9869. })
  9870. ]
  9871. })
  9872. ]
  9873. }));
  9874. }
  9875. fromSchema(schema) {
  9876. pvutils.clearProps(schema, CLEAR_PROPS$L);
  9877. const asn1 = asn1js.compareSchema(schema, schema, EncryptedData.schema({
  9878. names: {
  9879. version: VERSION$d,
  9880. encryptedContentInfo: {
  9881. names: {
  9882. blockName: ENCRYPTED_CONTENT_INFO$1
  9883. }
  9884. },
  9885. unprotectedAttrs: UNPROTECTED_ATTRS$1
  9886. }
  9887. }));
  9888. AsnError.assertSchema(asn1, this.className);
  9889. this.version = asn1.result.version.valueBlock.valueDec;
  9890. this.encryptedContentInfo = new EncryptedContentInfo({ schema: asn1.result.encryptedContentInfo });
  9891. if (UNPROTECTED_ATTRS$1 in asn1.result)
  9892. this.unprotectedAttrs = Array.from(asn1.result.unprotectedAttrs, element => new Attribute({ schema: element }));
  9893. }
  9894. toSchema() {
  9895. const outputArray = [];
  9896. outputArray.push(new asn1js.Integer({ value: this.version }));
  9897. outputArray.push(this.encryptedContentInfo.toSchema());
  9898. if (this.unprotectedAttrs) {
  9899. outputArray.push(new asn1js.Constructed({
  9900. optional: true,
  9901. idBlock: {
  9902. tagClass: 3,
  9903. tagNumber: 1
  9904. },
  9905. value: Array.from(this.unprotectedAttrs, o => o.toSchema())
  9906. }));
  9907. }
  9908. return (new asn1js.Sequence({
  9909. value: outputArray
  9910. }));
  9911. }
  9912. toJSON() {
  9913. const res = {
  9914. version: this.version,
  9915. encryptedContentInfo: this.encryptedContentInfo.toJSON()
  9916. };
  9917. if (this.unprotectedAttrs)
  9918. res.unprotectedAttrs = Array.from(this.unprotectedAttrs, o => o.toJSON());
  9919. return res;
  9920. }
  9921. async encrypt(parameters, crypto = getCrypto(true)) {
  9922. ArgumentError.assert(parameters, "parameters", "object");
  9923. const encryptParams = {
  9924. ...parameters,
  9925. contentType: "1.2.840.113549.1.7.1",
  9926. };
  9927. this.encryptedContentInfo = await crypto.encryptEncryptedContentInfo(encryptParams);
  9928. }
  9929. async decrypt(parameters, crypto = getCrypto(true)) {
  9930. ArgumentError.assert(parameters, "parameters", "object");
  9931. const decryptParams = {
  9932. ...parameters,
  9933. encryptedContentInfo: this.encryptedContentInfo,
  9934. };
  9935. return crypto.decryptEncryptedContentInfo(decryptParams);
  9936. }
  9937. }
  9938. EncryptedData.CLASS_NAME = "EncryptedData";
  9939. const ENCRYPTION_ALGORITHM = "encryptionAlgorithm";
  9940. const ENCRYPTED_DATA = "encryptedData";
  9941. const PARSED_VALUE$2 = "parsedValue";
  9942. const CLEAR_PROPS$K = [
  9943. ENCRYPTION_ALGORITHM,
  9944. ENCRYPTED_DATA,
  9945. ];
  9946. class PKCS8ShroudedKeyBag extends PkiObject {
  9947. constructor(parameters = {}) {
  9948. super();
  9949. this.encryptionAlgorithm = pvutils.getParametersValue(parameters, ENCRYPTION_ALGORITHM, PKCS8ShroudedKeyBag.defaultValues(ENCRYPTION_ALGORITHM));
  9950. this.encryptedData = pvutils.getParametersValue(parameters, ENCRYPTED_DATA, PKCS8ShroudedKeyBag.defaultValues(ENCRYPTED_DATA));
  9951. if (PARSED_VALUE$2 in parameters) {
  9952. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE$2, PKCS8ShroudedKeyBag.defaultValues(PARSED_VALUE$2));
  9953. }
  9954. if (parameters.schema) {
  9955. this.fromSchema(parameters.schema);
  9956. }
  9957. }
  9958. static defaultValues(memberName) {
  9959. switch (memberName) {
  9960. case ENCRYPTION_ALGORITHM:
  9961. return (new AlgorithmIdentifier());
  9962. case ENCRYPTED_DATA:
  9963. return (new asn1js.OctetString());
  9964. case PARSED_VALUE$2:
  9965. return {};
  9966. default:
  9967. return super.defaultValues(memberName);
  9968. }
  9969. }
  9970. static compareWithDefault(memberName, memberValue) {
  9971. switch (memberName) {
  9972. case ENCRYPTION_ALGORITHM:
  9973. return ((AlgorithmIdentifier.compareWithDefault("algorithmId", memberValue.algorithmId)) &&
  9974. (("algorithmParams" in memberValue) === false));
  9975. case ENCRYPTED_DATA:
  9976. return (memberValue.isEqual(PKCS8ShroudedKeyBag.defaultValues(memberName)));
  9977. case PARSED_VALUE$2:
  9978. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  9979. default:
  9980. return super.defaultValues(memberName);
  9981. }
  9982. }
  9983. static schema(parameters = {}) {
  9984. const names = pvutils.getParametersValue(parameters, "names", {});
  9985. return (new asn1js.Sequence({
  9986. name: (names.blockName || EMPTY_STRING),
  9987. value: [
  9988. AlgorithmIdentifier.schema(names.encryptionAlgorithm || {
  9989. names: {
  9990. blockName: ENCRYPTION_ALGORITHM
  9991. }
  9992. }),
  9993. new asn1js.Choice({
  9994. value: [
  9995. new asn1js.OctetString({ name: (names.encryptedData || ENCRYPTED_DATA) }),
  9996. new asn1js.OctetString({
  9997. idBlock: {
  9998. isConstructed: true
  9999. },
  10000. name: (names.encryptedData || ENCRYPTED_DATA)
  10001. })
  10002. ]
  10003. })
  10004. ]
  10005. }));
  10006. }
  10007. fromSchema(schema) {
  10008. pvutils.clearProps(schema, CLEAR_PROPS$K);
  10009. const asn1 = asn1js.compareSchema(schema, schema, PKCS8ShroudedKeyBag.schema({
  10010. names: {
  10011. encryptionAlgorithm: {
  10012. names: {
  10013. blockName: ENCRYPTION_ALGORITHM
  10014. }
  10015. },
  10016. encryptedData: ENCRYPTED_DATA
  10017. }
  10018. }));
  10019. AsnError.assertSchema(asn1, this.className);
  10020. this.encryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.encryptionAlgorithm });
  10021. this.encryptedData = asn1.result.encryptedData;
  10022. }
  10023. toSchema() {
  10024. return (new asn1js.Sequence({
  10025. value: [
  10026. this.encryptionAlgorithm.toSchema(),
  10027. this.encryptedData
  10028. ]
  10029. }));
  10030. }
  10031. toJSON() {
  10032. return {
  10033. encryptionAlgorithm: this.encryptionAlgorithm.toJSON(),
  10034. encryptedData: this.encryptedData.toJSON(),
  10035. };
  10036. }
  10037. async parseInternalValues(parameters, crypto = getCrypto(true)) {
  10038. const cmsEncrypted = new EncryptedData({
  10039. encryptedContentInfo: new EncryptedContentInfo({
  10040. contentEncryptionAlgorithm: this.encryptionAlgorithm,
  10041. encryptedContent: this.encryptedData
  10042. })
  10043. });
  10044. const decryptedData = await cmsEncrypted.decrypt(parameters, crypto);
  10045. this.parsedValue = PrivateKeyInfo.fromBER(decryptedData);
  10046. }
  10047. async makeInternalValues(parameters, crypto = getCrypto(true)) {
  10048. if (!this.parsedValue) {
  10049. throw new Error("Please initialize \"parsedValue\" first");
  10050. }
  10051. const cmsEncrypted = new EncryptedData();
  10052. const encryptParams = {
  10053. ...parameters,
  10054. contentToEncrypt: this.parsedValue.toSchema().toBER(false),
  10055. };
  10056. await cmsEncrypted.encrypt(encryptParams, crypto);
  10057. if (!cmsEncrypted.encryptedContentInfo.encryptedContent) {
  10058. throw new Error("The filed `encryptedContent` in EncryptedContentInfo is empty");
  10059. }
  10060. this.encryptionAlgorithm = cmsEncrypted.encryptedContentInfo.contentEncryptionAlgorithm;
  10061. this.encryptedData = cmsEncrypted.encryptedContentInfo.encryptedContent;
  10062. }
  10063. }
  10064. PKCS8ShroudedKeyBag.CLASS_NAME = "PKCS8ShroudedKeyBag";
  10065. const SECRET_TYPE_ID = "secretTypeId";
  10066. const SECRET_VALUE = "secretValue";
  10067. const CLEAR_PROPS$J = [
  10068. SECRET_TYPE_ID,
  10069. SECRET_VALUE,
  10070. ];
  10071. class SecretBag extends PkiObject {
  10072. constructor(parameters = {}) {
  10073. super();
  10074. this.secretTypeId = pvutils.getParametersValue(parameters, SECRET_TYPE_ID, SecretBag.defaultValues(SECRET_TYPE_ID));
  10075. this.secretValue = pvutils.getParametersValue(parameters, SECRET_VALUE, SecretBag.defaultValues(SECRET_VALUE));
  10076. if (parameters.schema) {
  10077. this.fromSchema(parameters.schema);
  10078. }
  10079. }
  10080. static defaultValues(memberName) {
  10081. switch (memberName) {
  10082. case SECRET_TYPE_ID:
  10083. return EMPTY_STRING;
  10084. case SECRET_VALUE:
  10085. return (new asn1js.Any());
  10086. default:
  10087. return super.defaultValues(memberName);
  10088. }
  10089. }
  10090. static compareWithDefault(memberName, memberValue) {
  10091. switch (memberName) {
  10092. case SECRET_TYPE_ID:
  10093. return (memberValue === EMPTY_STRING);
  10094. case SECRET_VALUE:
  10095. return (memberValue instanceof asn1js.Any);
  10096. default:
  10097. return super.defaultValues(memberName);
  10098. }
  10099. }
  10100. static schema(parameters = {}) {
  10101. const names = pvutils.getParametersValue(parameters, "names", {});
  10102. return (new asn1js.Sequence({
  10103. name: (names.blockName || EMPTY_STRING),
  10104. value: [
  10105. new asn1js.ObjectIdentifier({ name: (names.id || "id") }),
  10106. new asn1js.Constructed({
  10107. idBlock: {
  10108. tagClass: 3,
  10109. tagNumber: 0
  10110. },
  10111. value: [new asn1js.Any({ name: (names.value || "value") })]
  10112. })
  10113. ]
  10114. }));
  10115. }
  10116. fromSchema(schema) {
  10117. pvutils.clearProps(schema, CLEAR_PROPS$J);
  10118. const asn1 = asn1js.compareSchema(schema, schema, SecretBag.schema({
  10119. names: {
  10120. id: SECRET_TYPE_ID,
  10121. value: SECRET_VALUE
  10122. }
  10123. }));
  10124. AsnError.assertSchema(asn1, this.className);
  10125. this.secretTypeId = asn1.result.secretTypeId.valueBlock.toString();
  10126. this.secretValue = asn1.result.secretValue;
  10127. }
  10128. toSchema() {
  10129. return (new asn1js.Sequence({
  10130. value: [
  10131. new asn1js.ObjectIdentifier({ value: this.secretTypeId }),
  10132. new asn1js.Constructed({
  10133. idBlock: {
  10134. tagClass: 3,
  10135. tagNumber: 0
  10136. },
  10137. value: [this.secretValue.toSchema()]
  10138. })
  10139. ]
  10140. }));
  10141. }
  10142. toJSON() {
  10143. return {
  10144. secretTypeId: this.secretTypeId,
  10145. secretValue: this.secretValue.toJSON()
  10146. };
  10147. }
  10148. }
  10149. SecretBag.CLASS_NAME = "SecretBag";
  10150. class SafeBagValueFactory {
  10151. static getItems() {
  10152. if (!this.items) {
  10153. this.items = {};
  10154. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.1", PrivateKeyInfo);
  10155. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.2", PKCS8ShroudedKeyBag);
  10156. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.3", CertBag);
  10157. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.4", CRLBag);
  10158. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.5", SecretBag);
  10159. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.6", SafeContents);
  10160. }
  10161. return this.items;
  10162. }
  10163. static register(id, type) {
  10164. this.getItems()[id] = type;
  10165. }
  10166. static find(id) {
  10167. return this.getItems()[id] || null;
  10168. }
  10169. }
  10170. const BAG_ID = "bagId";
  10171. const BAG_VALUE = "bagValue";
  10172. const BAG_ATTRIBUTES = "bagAttributes";
  10173. const CLEAR_PROPS$I = [
  10174. BAG_ID,
  10175. BAG_VALUE,
  10176. BAG_ATTRIBUTES
  10177. ];
  10178. class SafeBag extends PkiObject {
  10179. constructor(parameters = {}) {
  10180. super();
  10181. this.bagId = pvutils.getParametersValue(parameters, BAG_ID, SafeBag.defaultValues(BAG_ID));
  10182. this.bagValue = pvutils.getParametersValue(parameters, BAG_VALUE, SafeBag.defaultValues(BAG_VALUE));
  10183. if (BAG_ATTRIBUTES in parameters) {
  10184. this.bagAttributes = pvutils.getParametersValue(parameters, BAG_ATTRIBUTES, SafeBag.defaultValues(BAG_ATTRIBUTES));
  10185. }
  10186. if (parameters.schema) {
  10187. this.fromSchema(parameters.schema);
  10188. }
  10189. }
  10190. static defaultValues(memberName) {
  10191. switch (memberName) {
  10192. case BAG_ID:
  10193. return EMPTY_STRING;
  10194. case BAG_VALUE:
  10195. return (new asn1js.Any());
  10196. case BAG_ATTRIBUTES:
  10197. return [];
  10198. default:
  10199. return super.defaultValues(memberName);
  10200. }
  10201. }
  10202. static compareWithDefault(memberName, memberValue) {
  10203. switch (memberName) {
  10204. case BAG_ID:
  10205. return (memberValue === EMPTY_STRING);
  10206. case BAG_VALUE:
  10207. return (memberValue instanceof asn1js.Any);
  10208. case BAG_ATTRIBUTES:
  10209. return (memberValue.length === 0);
  10210. default:
  10211. return super.defaultValues(memberName);
  10212. }
  10213. }
  10214. static schema(parameters = {}) {
  10215. const names = pvutils.getParametersValue(parameters, "names", {});
  10216. return (new asn1js.Sequence({
  10217. name: (names.blockName || EMPTY_STRING),
  10218. value: [
  10219. new asn1js.ObjectIdentifier({ name: (names.bagId || BAG_ID) }),
  10220. new asn1js.Constructed({
  10221. idBlock: {
  10222. tagClass: 3,
  10223. tagNumber: 0
  10224. },
  10225. value: [new asn1js.Any({ name: (names.bagValue || BAG_VALUE) })]
  10226. }),
  10227. new asn1js.Set({
  10228. optional: true,
  10229. value: [
  10230. new asn1js.Repeated({
  10231. name: (names.bagAttributes || BAG_ATTRIBUTES),
  10232. value: Attribute.schema()
  10233. })
  10234. ]
  10235. })
  10236. ]
  10237. }));
  10238. }
  10239. fromSchema(schema) {
  10240. pvutils.clearProps(schema, CLEAR_PROPS$I);
  10241. const asn1 = asn1js.compareSchema(schema, schema, SafeBag.schema({
  10242. names: {
  10243. bagId: BAG_ID,
  10244. bagValue: BAG_VALUE,
  10245. bagAttributes: BAG_ATTRIBUTES
  10246. }
  10247. }));
  10248. AsnError.assertSchema(asn1, this.className);
  10249. this.bagId = asn1.result.bagId.valueBlock.toString();
  10250. const bagType = SafeBagValueFactory.find(this.bagId);
  10251. if (!bagType) {
  10252. throw new Error(`Invalid BAG_ID for SafeBag: ${this.bagId}`);
  10253. }
  10254. this.bagValue = new bagType({ schema: asn1.result.bagValue });
  10255. if (BAG_ATTRIBUTES in asn1.result) {
  10256. this.bagAttributes = Array.from(asn1.result.bagAttributes, element => new Attribute({ schema: element }));
  10257. }
  10258. }
  10259. toSchema() {
  10260. const outputArray = [
  10261. new asn1js.ObjectIdentifier({ value: this.bagId }),
  10262. new asn1js.Constructed({
  10263. idBlock: {
  10264. tagClass: 3,
  10265. tagNumber: 0
  10266. },
  10267. value: [this.bagValue.toSchema()]
  10268. })
  10269. ];
  10270. if (this.bagAttributes) {
  10271. outputArray.push(new asn1js.Set({
  10272. value: Array.from(this.bagAttributes, o => o.toSchema())
  10273. }));
  10274. }
  10275. return (new asn1js.Sequence({
  10276. value: outputArray
  10277. }));
  10278. }
  10279. toJSON() {
  10280. const output = {
  10281. bagId: this.bagId,
  10282. bagValue: this.bagValue.toJSON()
  10283. };
  10284. if (this.bagAttributes) {
  10285. output.bagAttributes = Array.from(this.bagAttributes, o => o.toJSON());
  10286. }
  10287. return output;
  10288. }
  10289. }
  10290. SafeBag.CLASS_NAME = "SafeBag";
  10291. const SAFE_BUGS = "safeBags";
  10292. class SafeContents extends PkiObject {
  10293. constructor(parameters = {}) {
  10294. super();
  10295. this.safeBags = pvutils.getParametersValue(parameters, SAFE_BUGS, SafeContents.defaultValues(SAFE_BUGS));
  10296. if (parameters.schema) {
  10297. this.fromSchema(parameters.schema);
  10298. }
  10299. }
  10300. static defaultValues(memberName) {
  10301. switch (memberName) {
  10302. case SAFE_BUGS:
  10303. return [];
  10304. default:
  10305. return super.defaultValues(memberName);
  10306. }
  10307. }
  10308. static compareWithDefault(memberName, memberValue) {
  10309. switch (memberName) {
  10310. case SAFE_BUGS:
  10311. return (memberValue.length === 0);
  10312. default:
  10313. return super.defaultValues(memberName);
  10314. }
  10315. }
  10316. static schema(parameters = {}) {
  10317. const names = pvutils.getParametersValue(parameters, "names", {});
  10318. return (new asn1js.Sequence({
  10319. name: (names.blockName || EMPTY_STRING),
  10320. value: [
  10321. new asn1js.Repeated({
  10322. name: (names.safeBags || EMPTY_STRING),
  10323. value: SafeBag.schema()
  10324. })
  10325. ]
  10326. }));
  10327. }
  10328. fromSchema(schema) {
  10329. pvutils.clearProps(schema, [
  10330. SAFE_BUGS
  10331. ]);
  10332. const asn1 = asn1js.compareSchema(schema, schema, SafeContents.schema({
  10333. names: {
  10334. safeBags: SAFE_BUGS
  10335. }
  10336. }));
  10337. AsnError.assertSchema(asn1, this.className);
  10338. this.safeBags = Array.from(asn1.result.safeBags, element => new SafeBag({ schema: element }));
  10339. }
  10340. toSchema() {
  10341. return (new asn1js.Sequence({
  10342. value: Array.from(this.safeBags, o => o.toSchema())
  10343. }));
  10344. }
  10345. toJSON() {
  10346. return {
  10347. safeBags: Array.from(this.safeBags, o => o.toJSON())
  10348. };
  10349. }
  10350. }
  10351. SafeContents.CLASS_NAME = "SafeContents";
  10352. const OTHER_CERT_FORMAT = "otherCertFormat";
  10353. const OTHER_CERT = "otherCert";
  10354. const CLEAR_PROPS$H = [
  10355. OTHER_CERT_FORMAT,
  10356. OTHER_CERT
  10357. ];
  10358. class OtherCertificateFormat extends PkiObject {
  10359. constructor(parameters = {}) {
  10360. super();
  10361. this.otherCertFormat = pvutils.getParametersValue(parameters, OTHER_CERT_FORMAT, OtherCertificateFormat.defaultValues(OTHER_CERT_FORMAT));
  10362. this.otherCert = pvutils.getParametersValue(parameters, OTHER_CERT, OtherCertificateFormat.defaultValues(OTHER_CERT));
  10363. if (parameters.schema) {
  10364. this.fromSchema(parameters.schema);
  10365. }
  10366. }
  10367. static defaultValues(memberName) {
  10368. switch (memberName) {
  10369. case OTHER_CERT_FORMAT:
  10370. return EMPTY_STRING;
  10371. case OTHER_CERT:
  10372. return new asn1js.Any();
  10373. default:
  10374. return super.defaultValues(memberName);
  10375. }
  10376. }
  10377. static schema(parameters = {}) {
  10378. const names = pvutils.getParametersValue(parameters, "names", {});
  10379. return (new asn1js.Sequence({
  10380. name: (names.blockName || EMPTY_STRING),
  10381. value: [
  10382. new asn1js.ObjectIdentifier({ name: (names.otherCertFormat || OTHER_CERT_FORMAT) }),
  10383. new asn1js.Any({ name: (names.otherCert || OTHER_CERT) })
  10384. ]
  10385. }));
  10386. }
  10387. fromSchema(schema) {
  10388. pvutils.clearProps(schema, CLEAR_PROPS$H);
  10389. const asn1 = asn1js.compareSchema(schema, schema, OtherCertificateFormat.schema());
  10390. AsnError.assertSchema(asn1, this.className);
  10391. this.otherCertFormat = asn1.result.otherCertFormat.valueBlock.toString();
  10392. this.otherCert = asn1.result.otherCert;
  10393. }
  10394. toSchema() {
  10395. return (new asn1js.Sequence({
  10396. value: [
  10397. new asn1js.ObjectIdentifier({ value: this.otherCertFormat }),
  10398. this.otherCert
  10399. ]
  10400. }));
  10401. }
  10402. toJSON() {
  10403. const res = {
  10404. otherCertFormat: this.otherCertFormat
  10405. };
  10406. if (!(this.otherCert instanceof asn1js.Any)) {
  10407. res.otherCert = this.otherCert.toJSON();
  10408. }
  10409. return res;
  10410. }
  10411. }
  10412. const CERTIFICATES$1 = "certificates";
  10413. const CLEAR_PROPS$G = [
  10414. CERTIFICATES$1,
  10415. ];
  10416. class CertificateSet extends PkiObject {
  10417. constructor(parameters = {}) {
  10418. super();
  10419. this.certificates = pvutils.getParametersValue(parameters, CERTIFICATES$1, CertificateSet.defaultValues(CERTIFICATES$1));
  10420. if (parameters.schema) {
  10421. this.fromSchema(parameters.schema);
  10422. }
  10423. }
  10424. static defaultValues(memberName) {
  10425. switch (memberName) {
  10426. case CERTIFICATES$1:
  10427. return [];
  10428. default:
  10429. return super.defaultValues(memberName);
  10430. }
  10431. }
  10432. static schema(parameters = {}) {
  10433. const names = pvutils.getParametersValue(parameters, "names", {});
  10434. return (new asn1js.Set({
  10435. name: (names.blockName || EMPTY_STRING),
  10436. value: [
  10437. new asn1js.Repeated({
  10438. name: (names.certificates || CERTIFICATES$1),
  10439. value: new asn1js.Choice({
  10440. value: [
  10441. Certificate.schema(),
  10442. new asn1js.Constructed({
  10443. idBlock: {
  10444. tagClass: 3,
  10445. tagNumber: 0
  10446. },
  10447. value: [
  10448. new asn1js.Any()
  10449. ]
  10450. }),
  10451. new asn1js.Constructed({
  10452. idBlock: {
  10453. tagClass: 3,
  10454. tagNumber: 1
  10455. },
  10456. value: [
  10457. new asn1js.Sequence
  10458. ]
  10459. }),
  10460. new asn1js.Constructed({
  10461. idBlock: {
  10462. tagClass: 3,
  10463. tagNumber: 2
  10464. },
  10465. value: AttributeCertificateV2.schema().valueBlock.value
  10466. }),
  10467. new asn1js.Constructed({
  10468. idBlock: {
  10469. tagClass: 3,
  10470. tagNumber: 3
  10471. },
  10472. value: OtherCertificateFormat.schema().valueBlock.value
  10473. })
  10474. ]
  10475. })
  10476. })
  10477. ]
  10478. }));
  10479. }
  10480. fromSchema(schema) {
  10481. pvutils.clearProps(schema, CLEAR_PROPS$G);
  10482. const asn1 = asn1js.compareSchema(schema, schema, CertificateSet.schema());
  10483. AsnError.assertSchema(asn1, this.className);
  10484. this.certificates = Array.from(asn1.result.certificates || [], (element) => {
  10485. const initialTagNumber = element.idBlock.tagNumber;
  10486. if (element.idBlock.tagClass === 1)
  10487. return new Certificate({ schema: element });
  10488. const elementSequence = new asn1js.Sequence({
  10489. value: element.valueBlock.value
  10490. });
  10491. switch (initialTagNumber) {
  10492. case 1:
  10493. if (elementSequence.valueBlock.value[0].valueBlock.value[0].valueBlock.valueDec === 1) {
  10494. return new AttributeCertificateV2({ schema: elementSequence });
  10495. }
  10496. else {
  10497. return new AttributeCertificateV1({ schema: elementSequence });
  10498. }
  10499. case 2:
  10500. return new AttributeCertificateV2({ schema: elementSequence });
  10501. case 3:
  10502. return new OtherCertificateFormat({ schema: elementSequence });
  10503. }
  10504. return element;
  10505. });
  10506. }
  10507. toSchema() {
  10508. return (new asn1js.Set({
  10509. value: Array.from(this.certificates, element => {
  10510. switch (true) {
  10511. case (element instanceof Certificate):
  10512. return element.toSchema();
  10513. case (element instanceof AttributeCertificateV1):
  10514. return new asn1js.Constructed({
  10515. idBlock: {
  10516. tagClass: 3,
  10517. tagNumber: 1
  10518. },
  10519. value: element.toSchema().valueBlock.value
  10520. });
  10521. case (element instanceof AttributeCertificateV2):
  10522. return new asn1js.Constructed({
  10523. idBlock: {
  10524. tagClass: 3,
  10525. tagNumber: 2
  10526. },
  10527. value: element.toSchema().valueBlock.value
  10528. });
  10529. case (element instanceof OtherCertificateFormat):
  10530. return new asn1js.Constructed({
  10531. idBlock: {
  10532. tagClass: 3,
  10533. tagNumber: 3
  10534. },
  10535. value: element.toSchema().valueBlock.value
  10536. });
  10537. }
  10538. return element.toSchema();
  10539. })
  10540. }));
  10541. }
  10542. toJSON() {
  10543. return {
  10544. certificates: Array.from(this.certificates, o => o.toJSON())
  10545. };
  10546. }
  10547. }
  10548. CertificateSet.CLASS_NAME = "CertificateSet";
  10549. const OTHER_REV_INFO_FORMAT = "otherRevInfoFormat";
  10550. const OTHER_REV_INFO = "otherRevInfo";
  10551. const CLEAR_PROPS$F = [
  10552. OTHER_REV_INFO_FORMAT,
  10553. OTHER_REV_INFO
  10554. ];
  10555. class OtherRevocationInfoFormat extends PkiObject {
  10556. constructor(parameters = {}) {
  10557. super();
  10558. this.otherRevInfoFormat = pvutils.getParametersValue(parameters, OTHER_REV_INFO_FORMAT, OtherRevocationInfoFormat.defaultValues(OTHER_REV_INFO_FORMAT));
  10559. this.otherRevInfo = pvutils.getParametersValue(parameters, OTHER_REV_INFO, OtherRevocationInfoFormat.defaultValues(OTHER_REV_INFO));
  10560. if (parameters.schema) {
  10561. this.fromSchema(parameters.schema);
  10562. }
  10563. }
  10564. static defaultValues(memberName) {
  10565. switch (memberName) {
  10566. case OTHER_REV_INFO_FORMAT:
  10567. return EMPTY_STRING;
  10568. case OTHER_REV_INFO:
  10569. return new asn1js.Any();
  10570. default:
  10571. return super.defaultValues(memberName);
  10572. }
  10573. }
  10574. static schema(parameters = {}) {
  10575. const names = pvutils.getParametersValue(parameters, "names", {});
  10576. return (new asn1js.Sequence({
  10577. name: (names.blockName || EMPTY_STRING),
  10578. value: [
  10579. new asn1js.ObjectIdentifier({ name: (names.otherRevInfoFormat || OTHER_REV_INFO_FORMAT) }),
  10580. new asn1js.Any({ name: (names.otherRevInfo || OTHER_REV_INFO) })
  10581. ]
  10582. }));
  10583. }
  10584. fromSchema(schema) {
  10585. pvutils.clearProps(schema, CLEAR_PROPS$F);
  10586. const asn1 = asn1js.compareSchema(schema, schema, OtherRevocationInfoFormat.schema());
  10587. AsnError.assertSchema(asn1, this.className);
  10588. this.otherRevInfoFormat = asn1.result.otherRevInfoFormat.valueBlock.toString();
  10589. this.otherRevInfo = asn1.result.otherRevInfo;
  10590. }
  10591. toSchema() {
  10592. return (new asn1js.Sequence({
  10593. value: [
  10594. new asn1js.ObjectIdentifier({ value: this.otherRevInfoFormat }),
  10595. this.otherRevInfo
  10596. ]
  10597. }));
  10598. }
  10599. toJSON() {
  10600. const res = {
  10601. otherRevInfoFormat: this.otherRevInfoFormat
  10602. };
  10603. if (!(this.otherRevInfo instanceof asn1js.Any)) {
  10604. res.otherRevInfo = this.otherRevInfo.toJSON();
  10605. }
  10606. return res;
  10607. }
  10608. }
  10609. OtherRevocationInfoFormat.CLASS_NAME = "OtherRevocationInfoFormat";
  10610. const CRLS$3 = "crls";
  10611. const OTHER_REVOCATION_INFOS = "otherRevocationInfos";
  10612. const CLEAR_PROPS$E = [
  10613. CRLS$3
  10614. ];
  10615. class RevocationInfoChoices extends PkiObject {
  10616. constructor(parameters = {}) {
  10617. super();
  10618. this.crls = pvutils.getParametersValue(parameters, CRLS$3, RevocationInfoChoices.defaultValues(CRLS$3));
  10619. this.otherRevocationInfos = pvutils.getParametersValue(parameters, OTHER_REVOCATION_INFOS, RevocationInfoChoices.defaultValues(OTHER_REVOCATION_INFOS));
  10620. if (parameters.schema) {
  10621. this.fromSchema(parameters.schema);
  10622. }
  10623. }
  10624. static defaultValues(memberName) {
  10625. switch (memberName) {
  10626. case CRLS$3:
  10627. return [];
  10628. case OTHER_REVOCATION_INFOS:
  10629. return [];
  10630. default:
  10631. return super.defaultValues(memberName);
  10632. }
  10633. }
  10634. static schema(parameters = {}) {
  10635. const names = pvutils.getParametersValue(parameters, "names", {});
  10636. return (new asn1js.Set({
  10637. name: (names.blockName || EMPTY_STRING),
  10638. value: [
  10639. new asn1js.Repeated({
  10640. name: (names.crls || EMPTY_STRING),
  10641. value: new asn1js.Choice({
  10642. value: [
  10643. CertificateRevocationList.schema(),
  10644. new asn1js.Constructed({
  10645. idBlock: {
  10646. tagClass: 3,
  10647. tagNumber: 1
  10648. },
  10649. value: [
  10650. new asn1js.ObjectIdentifier(),
  10651. new asn1js.Any()
  10652. ]
  10653. })
  10654. ]
  10655. })
  10656. })
  10657. ]
  10658. }));
  10659. }
  10660. fromSchema(schema) {
  10661. pvutils.clearProps(schema, CLEAR_PROPS$E);
  10662. const asn1 = asn1js.compareSchema(schema, schema, RevocationInfoChoices.schema({
  10663. names: {
  10664. crls: CRLS$3
  10665. }
  10666. }));
  10667. AsnError.assertSchema(asn1, this.className);
  10668. if (asn1.result.crls) {
  10669. for (const element of asn1.result.crls) {
  10670. if (element.idBlock.tagClass === 1)
  10671. this.crls.push(new CertificateRevocationList({ schema: element }));
  10672. else
  10673. this.otherRevocationInfos.push(new OtherRevocationInfoFormat({ schema: element }));
  10674. }
  10675. }
  10676. }
  10677. toSchema() {
  10678. const outputArray = [];
  10679. outputArray.push(...Array.from(this.crls, o => o.toSchema()));
  10680. outputArray.push(...Array.from(this.otherRevocationInfos, element => {
  10681. const schema = element.toSchema();
  10682. schema.idBlock.tagClass = 3;
  10683. schema.idBlock.tagNumber = 1;
  10684. return schema;
  10685. }));
  10686. return (new asn1js.Set({
  10687. value: outputArray
  10688. }));
  10689. }
  10690. toJSON() {
  10691. return {
  10692. crls: Array.from(this.crls, o => o.toJSON()),
  10693. otherRevocationInfos: Array.from(this.otherRevocationInfos, o => o.toJSON())
  10694. };
  10695. }
  10696. }
  10697. RevocationInfoChoices.CLASS_NAME = "RevocationInfoChoices";
  10698. const CERTS$3 = "certs";
  10699. const CRLS$2 = "crls";
  10700. const CLEAR_PROPS$D = [
  10701. CERTS$3,
  10702. CRLS$2,
  10703. ];
  10704. class OriginatorInfo extends PkiObject {
  10705. constructor(parameters = {}) {
  10706. super();
  10707. this.crls = pvutils.getParametersValue(parameters, CRLS$2, OriginatorInfo.defaultValues(CRLS$2));
  10708. if (parameters.schema) {
  10709. this.fromSchema(parameters.schema);
  10710. }
  10711. }
  10712. static defaultValues(memberName) {
  10713. switch (memberName) {
  10714. case CERTS$3:
  10715. return new CertificateSet();
  10716. case CRLS$2:
  10717. return new RevocationInfoChoices();
  10718. default:
  10719. return super.defaultValues(memberName);
  10720. }
  10721. }
  10722. static compareWithDefault(memberName, memberValue) {
  10723. switch (memberName) {
  10724. case CERTS$3:
  10725. return (memberValue.certificates.length === 0);
  10726. case CRLS$2:
  10727. return ((memberValue.crls.length === 0) && (memberValue.otherRevocationInfos.length === 0));
  10728. default:
  10729. return super.defaultValues(memberName);
  10730. }
  10731. }
  10732. static schema(parameters = {}) {
  10733. const names = pvutils.getParametersValue(parameters, "names", {});
  10734. return (new asn1js.Sequence({
  10735. name: (names.blockName || EMPTY_STRING),
  10736. value: [
  10737. new asn1js.Constructed({
  10738. name: (names.certs || EMPTY_STRING),
  10739. optional: true,
  10740. idBlock: {
  10741. tagClass: 3,
  10742. tagNumber: 0
  10743. },
  10744. value: CertificateSet.schema().valueBlock.value
  10745. }),
  10746. new asn1js.Constructed({
  10747. name: (names.crls || EMPTY_STRING),
  10748. optional: true,
  10749. idBlock: {
  10750. tagClass: 3,
  10751. tagNumber: 1
  10752. },
  10753. value: RevocationInfoChoices.schema().valueBlock.value
  10754. })
  10755. ]
  10756. }));
  10757. }
  10758. fromSchema(schema) {
  10759. pvutils.clearProps(schema, CLEAR_PROPS$D);
  10760. const asn1 = asn1js.compareSchema(schema, schema, OriginatorInfo.schema({
  10761. names: {
  10762. certs: CERTS$3,
  10763. crls: CRLS$2
  10764. }
  10765. }));
  10766. AsnError.assertSchema(asn1, this.className);
  10767. if (CERTS$3 in asn1.result) {
  10768. this.certs = new CertificateSet({
  10769. schema: new asn1js.Set({
  10770. value: asn1.result.certs.valueBlock.value
  10771. })
  10772. });
  10773. }
  10774. if (CRLS$2 in asn1.result) {
  10775. this.crls = new RevocationInfoChoices({
  10776. schema: new asn1js.Set({
  10777. value: asn1.result.crls.valueBlock.value
  10778. })
  10779. });
  10780. }
  10781. }
  10782. toSchema() {
  10783. const sequenceValue = [];
  10784. if (this.certs) {
  10785. sequenceValue.push(new asn1js.Constructed({
  10786. idBlock: {
  10787. tagClass: 3,
  10788. tagNumber: 0
  10789. },
  10790. value: this.certs.toSchema().valueBlock.value
  10791. }));
  10792. }
  10793. if (this.crls) {
  10794. sequenceValue.push(new asn1js.Constructed({
  10795. idBlock: {
  10796. tagClass: 3,
  10797. tagNumber: 1
  10798. },
  10799. value: this.crls.toSchema().valueBlock.value
  10800. }));
  10801. }
  10802. return (new asn1js.Sequence({
  10803. value: sequenceValue
  10804. }));
  10805. }
  10806. toJSON() {
  10807. const res = {};
  10808. if (this.certs) {
  10809. res.certs = this.certs.toJSON();
  10810. }
  10811. if (this.crls) {
  10812. res.crls = this.crls.toJSON();
  10813. }
  10814. return res;
  10815. }
  10816. }
  10817. OriginatorInfo.CLASS_NAME = "OriginatorInfo";
  10818. const ISSUER = "issuer";
  10819. const SERIAL_NUMBER$2 = "serialNumber";
  10820. const CLEAR_PROPS$C = [
  10821. ISSUER,
  10822. SERIAL_NUMBER$2,
  10823. ];
  10824. class IssuerAndSerialNumber extends PkiObject {
  10825. constructor(parameters = {}) {
  10826. super();
  10827. this.issuer = pvutils.getParametersValue(parameters, ISSUER, IssuerAndSerialNumber.defaultValues(ISSUER));
  10828. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$2, IssuerAndSerialNumber.defaultValues(SERIAL_NUMBER$2));
  10829. if (parameters.schema) {
  10830. this.fromSchema(parameters.schema);
  10831. }
  10832. }
  10833. static defaultValues(memberName) {
  10834. switch (memberName) {
  10835. case ISSUER:
  10836. return new RelativeDistinguishedNames();
  10837. case SERIAL_NUMBER$2:
  10838. return new asn1js.Integer();
  10839. default:
  10840. return super.defaultValues(memberName);
  10841. }
  10842. }
  10843. static schema(parameters = {}) {
  10844. const names = pvutils.getParametersValue(parameters, "names", {});
  10845. return (new asn1js.Sequence({
  10846. name: (names.blockName || EMPTY_STRING),
  10847. value: [
  10848. RelativeDistinguishedNames.schema(names.issuer || {}),
  10849. new asn1js.Integer({ name: (names.serialNumber || EMPTY_STRING) })
  10850. ]
  10851. }));
  10852. }
  10853. fromSchema(schema) {
  10854. pvutils.clearProps(schema, CLEAR_PROPS$C);
  10855. const asn1 = asn1js.compareSchema(schema, schema, IssuerAndSerialNumber.schema({
  10856. names: {
  10857. issuer: {
  10858. names: {
  10859. blockName: ISSUER
  10860. }
  10861. },
  10862. serialNumber: SERIAL_NUMBER$2
  10863. }
  10864. }));
  10865. AsnError.assertSchema(asn1, this.className);
  10866. this.issuer = new RelativeDistinguishedNames({ schema: asn1.result.issuer });
  10867. this.serialNumber = asn1.result.serialNumber;
  10868. }
  10869. toSchema() {
  10870. return (new asn1js.Sequence({
  10871. value: [
  10872. this.issuer.toSchema(),
  10873. this.serialNumber
  10874. ]
  10875. }));
  10876. }
  10877. toJSON() {
  10878. return {
  10879. issuer: this.issuer.toJSON(),
  10880. serialNumber: this.serialNumber.toJSON(),
  10881. };
  10882. }
  10883. }
  10884. IssuerAndSerialNumber.CLASS_NAME = "IssuerAndSerialNumber";
  10885. const VARIANT$3 = "variant";
  10886. const VALUE$3 = "value";
  10887. const CLEAR_PROPS$B = [
  10888. "blockName"
  10889. ];
  10890. class RecipientIdentifier extends PkiObject {
  10891. constructor(parameters = {}) {
  10892. super();
  10893. this.variant = pvutils.getParametersValue(parameters, VARIANT$3, RecipientIdentifier.defaultValues(VARIANT$3));
  10894. if (VALUE$3 in parameters) {
  10895. this.value = pvutils.getParametersValue(parameters, VALUE$3, RecipientIdentifier.defaultValues(VALUE$3));
  10896. }
  10897. if (parameters.schema) {
  10898. this.fromSchema(parameters.schema);
  10899. }
  10900. }
  10901. static defaultValues(memberName) {
  10902. switch (memberName) {
  10903. case VARIANT$3:
  10904. return (-1);
  10905. case VALUE$3:
  10906. return {};
  10907. default:
  10908. return super.defaultValues(memberName);
  10909. }
  10910. }
  10911. static compareWithDefault(memberName, memberValue) {
  10912. switch (memberName) {
  10913. case VARIANT$3:
  10914. return (memberValue === (-1));
  10915. case VALUE$3:
  10916. return (Object.keys(memberValue).length === 0);
  10917. default:
  10918. return super.defaultValues(memberName);
  10919. }
  10920. }
  10921. static schema(parameters = {}) {
  10922. const names = pvutils.getParametersValue(parameters, "names", {});
  10923. return (new asn1js.Choice({
  10924. value: [
  10925. IssuerAndSerialNumber.schema({
  10926. names: {
  10927. blockName: (names.blockName || EMPTY_STRING)
  10928. }
  10929. }),
  10930. new asn1js.Primitive({
  10931. name: (names.blockName || EMPTY_STRING),
  10932. idBlock: {
  10933. tagClass: 3,
  10934. tagNumber: 0
  10935. }
  10936. })
  10937. ]
  10938. }));
  10939. }
  10940. fromSchema(schema) {
  10941. pvutils.clearProps(schema, CLEAR_PROPS$B);
  10942. const asn1 = asn1js.compareSchema(schema, schema, RecipientIdentifier.schema({
  10943. names: {
  10944. blockName: "blockName"
  10945. }
  10946. }));
  10947. AsnError.assertSchema(asn1, this.className);
  10948. if (asn1.result.blockName.idBlock.tagClass === 1) {
  10949. this.variant = 1;
  10950. this.value = new IssuerAndSerialNumber({ schema: asn1.result.blockName });
  10951. }
  10952. else {
  10953. this.variant = 2;
  10954. this.value = new asn1js.OctetString({ valueHex: asn1.result.blockName.valueBlock.valueHex });
  10955. }
  10956. }
  10957. toSchema() {
  10958. switch (this.variant) {
  10959. case 1:
  10960. if (!(this.value instanceof IssuerAndSerialNumber)) {
  10961. throw new Error("Incorrect type of RecipientIdentifier.value. It should be IssuerAndSerialNumber.");
  10962. }
  10963. return this.value.toSchema();
  10964. case 2:
  10965. if (!(this.value instanceof asn1js.OctetString)) {
  10966. throw new Error("Incorrect type of RecipientIdentifier.value. It should be ASN.1 OctetString.");
  10967. }
  10968. return new asn1js.Primitive({
  10969. idBlock: {
  10970. tagClass: 3,
  10971. tagNumber: 0
  10972. },
  10973. valueHex: this.value.valueBlock.valueHexView
  10974. });
  10975. default:
  10976. return new asn1js.Any();
  10977. }
  10978. }
  10979. toJSON() {
  10980. const res = {
  10981. variant: this.variant
  10982. };
  10983. if ((this.variant === 1 || this.variant === 2) && this.value) {
  10984. res.value = this.value.toJSON();
  10985. }
  10986. return res;
  10987. }
  10988. }
  10989. RecipientIdentifier.CLASS_NAME = "RecipientIdentifier";
  10990. const VERSION$c = "version";
  10991. const RID$1 = "rid";
  10992. const KEY_ENCRYPTION_ALGORITHM$3 = "keyEncryptionAlgorithm";
  10993. const ENCRYPTED_KEY$3 = "encryptedKey";
  10994. const RECIPIENT_CERTIFICATE$1 = "recipientCertificate";
  10995. const CLEAR_PROPS$A = [
  10996. VERSION$c,
  10997. RID$1,
  10998. KEY_ENCRYPTION_ALGORITHM$3,
  10999. ENCRYPTED_KEY$3,
  11000. ];
  11001. class KeyTransRecipientInfo extends PkiObject {
  11002. constructor(parameters = {}) {
  11003. super();
  11004. this.version = pvutils.getParametersValue(parameters, VERSION$c, KeyTransRecipientInfo.defaultValues(VERSION$c));
  11005. this.rid = pvutils.getParametersValue(parameters, RID$1, KeyTransRecipientInfo.defaultValues(RID$1));
  11006. this.keyEncryptionAlgorithm = pvutils.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM$3, KeyTransRecipientInfo.defaultValues(KEY_ENCRYPTION_ALGORITHM$3));
  11007. this.encryptedKey = pvutils.getParametersValue(parameters, ENCRYPTED_KEY$3, KeyTransRecipientInfo.defaultValues(ENCRYPTED_KEY$3));
  11008. this.recipientCertificate = pvutils.getParametersValue(parameters, RECIPIENT_CERTIFICATE$1, KeyTransRecipientInfo.defaultValues(RECIPIENT_CERTIFICATE$1));
  11009. if (parameters.schema) {
  11010. this.fromSchema(parameters.schema);
  11011. }
  11012. }
  11013. static defaultValues(memberName) {
  11014. switch (memberName) {
  11015. case VERSION$c:
  11016. return (-1);
  11017. case RID$1:
  11018. return {};
  11019. case KEY_ENCRYPTION_ALGORITHM$3:
  11020. return new AlgorithmIdentifier();
  11021. case ENCRYPTED_KEY$3:
  11022. return new asn1js.OctetString();
  11023. case RECIPIENT_CERTIFICATE$1:
  11024. return new Certificate();
  11025. default:
  11026. return super.defaultValues(memberName);
  11027. }
  11028. }
  11029. static compareWithDefault(memberName, memberValue) {
  11030. switch (memberName) {
  11031. case VERSION$c:
  11032. return (memberValue === KeyTransRecipientInfo.defaultValues(VERSION$c));
  11033. case RID$1:
  11034. return (Object.keys(memberValue).length === 0);
  11035. case KEY_ENCRYPTION_ALGORITHM$3:
  11036. case ENCRYPTED_KEY$3:
  11037. return memberValue.isEqual(KeyTransRecipientInfo.defaultValues(memberName));
  11038. case RECIPIENT_CERTIFICATE$1:
  11039. return false;
  11040. default:
  11041. return super.defaultValues(memberName);
  11042. }
  11043. }
  11044. static schema(parameters = {}) {
  11045. const names = pvutils.getParametersValue(parameters, "names", {});
  11046. return (new asn1js.Sequence({
  11047. name: (names.blockName || EMPTY_STRING),
  11048. value: [
  11049. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  11050. RecipientIdentifier.schema(names.rid || {}),
  11051. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  11052. new asn1js.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  11053. ]
  11054. }));
  11055. }
  11056. fromSchema(schema) {
  11057. pvutils.clearProps(schema, CLEAR_PROPS$A);
  11058. const asn1 = asn1js.compareSchema(schema, schema, KeyTransRecipientInfo.schema({
  11059. names: {
  11060. version: VERSION$c,
  11061. rid: {
  11062. names: {
  11063. blockName: RID$1
  11064. }
  11065. },
  11066. keyEncryptionAlgorithm: {
  11067. names: {
  11068. blockName: KEY_ENCRYPTION_ALGORITHM$3
  11069. }
  11070. },
  11071. encryptedKey: ENCRYPTED_KEY$3
  11072. }
  11073. }));
  11074. AsnError.assertSchema(asn1, this.className);
  11075. this.version = asn1.result.version.valueBlock.valueDec;
  11076. if (asn1.result.rid.idBlock.tagClass === 3) {
  11077. this.rid = new asn1js.OctetString({ valueHex: asn1.result.rid.valueBlock.valueHex });
  11078. }
  11079. else {
  11080. this.rid = new IssuerAndSerialNumber({ schema: asn1.result.rid });
  11081. }
  11082. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  11083. this.encryptedKey = asn1.result.encryptedKey;
  11084. }
  11085. toSchema() {
  11086. const outputArray = [];
  11087. if (this.rid instanceof IssuerAndSerialNumber) {
  11088. this.version = 0;
  11089. outputArray.push(new asn1js.Integer({ value: this.version }));
  11090. outputArray.push(this.rid.toSchema());
  11091. }
  11092. else {
  11093. this.version = 2;
  11094. outputArray.push(new asn1js.Integer({ value: this.version }));
  11095. outputArray.push(new asn1js.Primitive({
  11096. idBlock: {
  11097. tagClass: 3,
  11098. tagNumber: 0
  11099. },
  11100. valueHex: this.rid.valueBlock.valueHexView
  11101. }));
  11102. }
  11103. outputArray.push(this.keyEncryptionAlgorithm.toSchema());
  11104. outputArray.push(this.encryptedKey);
  11105. return (new asn1js.Sequence({
  11106. value: outputArray
  11107. }));
  11108. }
  11109. toJSON() {
  11110. return {
  11111. version: this.version,
  11112. rid: this.rid.toJSON(),
  11113. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  11114. encryptedKey: this.encryptedKey.toJSON(),
  11115. };
  11116. }
  11117. }
  11118. KeyTransRecipientInfo.CLASS_NAME = "KeyTransRecipientInfo";
  11119. const ALGORITHM = "algorithm";
  11120. const PUBLIC_KEY = "publicKey";
  11121. const CLEAR_PROPS$z = [
  11122. ALGORITHM,
  11123. PUBLIC_KEY
  11124. ];
  11125. class OriginatorPublicKey extends PkiObject {
  11126. constructor(parameters = {}) {
  11127. super();
  11128. this.algorithm = pvutils.getParametersValue(parameters, ALGORITHM, OriginatorPublicKey.defaultValues(ALGORITHM));
  11129. this.publicKey = pvutils.getParametersValue(parameters, PUBLIC_KEY, OriginatorPublicKey.defaultValues(PUBLIC_KEY));
  11130. if (parameters.schema) {
  11131. this.fromSchema(parameters.schema);
  11132. }
  11133. }
  11134. static defaultValues(memberName) {
  11135. switch (memberName) {
  11136. case ALGORITHM:
  11137. return new AlgorithmIdentifier();
  11138. case PUBLIC_KEY:
  11139. return new asn1js.BitString();
  11140. default:
  11141. return super.defaultValues(memberName);
  11142. }
  11143. }
  11144. static compareWithDefault(memberName, memberValue) {
  11145. switch (memberName) {
  11146. case ALGORITHM:
  11147. case PUBLIC_KEY:
  11148. return (memberValue.isEqual(OriginatorPublicKey.defaultValues(memberName)));
  11149. default:
  11150. return super.defaultValues(memberName);
  11151. }
  11152. }
  11153. static schema(parameters = {}) {
  11154. const names = pvutils.getParametersValue(parameters, "names", {});
  11155. return (new asn1js.Sequence({
  11156. name: (names.blockName || EMPTY_STRING),
  11157. value: [
  11158. AlgorithmIdentifier.schema(names.algorithm || {}),
  11159. new asn1js.BitString({ name: (names.publicKey || EMPTY_STRING) })
  11160. ]
  11161. }));
  11162. }
  11163. fromSchema(schema) {
  11164. pvutils.clearProps(schema, CLEAR_PROPS$z);
  11165. const asn1 = asn1js.compareSchema(schema, schema, OriginatorPublicKey.schema({
  11166. names: {
  11167. algorithm: {
  11168. names: {
  11169. blockName: ALGORITHM
  11170. }
  11171. },
  11172. publicKey: PUBLIC_KEY
  11173. }
  11174. }));
  11175. AsnError.assertSchema(asn1, this.className);
  11176. this.algorithm = new AlgorithmIdentifier({ schema: asn1.result.algorithm });
  11177. this.publicKey = asn1.result.publicKey;
  11178. }
  11179. toSchema() {
  11180. return (new asn1js.Sequence({
  11181. value: [
  11182. this.algorithm.toSchema(),
  11183. this.publicKey
  11184. ]
  11185. }));
  11186. }
  11187. toJSON() {
  11188. return {
  11189. algorithm: this.algorithm.toJSON(),
  11190. publicKey: this.publicKey.toJSON(),
  11191. };
  11192. }
  11193. }
  11194. OriginatorPublicKey.CLASS_NAME = "OriginatorPublicKey";
  11195. const VARIANT$2 = "variant";
  11196. const VALUE$2 = "value";
  11197. const CLEAR_PROPS$y = [
  11198. "blockName",
  11199. ];
  11200. class OriginatorIdentifierOrKey extends PkiObject {
  11201. constructor(parameters = {}) {
  11202. super();
  11203. this.variant = pvutils.getParametersValue(parameters, VARIANT$2, OriginatorIdentifierOrKey.defaultValues(VARIANT$2));
  11204. if (VALUE$2 in parameters) {
  11205. this.value = pvutils.getParametersValue(parameters, VALUE$2, OriginatorIdentifierOrKey.defaultValues(VALUE$2));
  11206. }
  11207. if (parameters.schema) {
  11208. this.fromSchema(parameters.schema);
  11209. }
  11210. }
  11211. static defaultValues(memberName) {
  11212. switch (memberName) {
  11213. case VARIANT$2:
  11214. return (-1);
  11215. case VALUE$2:
  11216. return {};
  11217. default:
  11218. return super.defaultValues(memberName);
  11219. }
  11220. }
  11221. static compareWithDefault(memberName, memberValue) {
  11222. switch (memberName) {
  11223. case VARIANT$2:
  11224. return (memberValue === (-1));
  11225. case VALUE$2:
  11226. return (Object.keys(memberValue).length === 0);
  11227. default:
  11228. return super.defaultValues(memberName);
  11229. }
  11230. }
  11231. static schema(parameters = {}) {
  11232. const names = pvutils.getParametersValue(parameters, "names", {});
  11233. return (new asn1js.Choice({
  11234. value: [
  11235. IssuerAndSerialNumber.schema({
  11236. names: {
  11237. blockName: (names.blockName || EMPTY_STRING)
  11238. }
  11239. }),
  11240. new asn1js.Primitive({
  11241. idBlock: {
  11242. tagClass: 3,
  11243. tagNumber: 0
  11244. },
  11245. name: (names.blockName || EMPTY_STRING)
  11246. }),
  11247. new asn1js.Constructed({
  11248. idBlock: {
  11249. tagClass: 3,
  11250. tagNumber: 1
  11251. },
  11252. name: (names.blockName || EMPTY_STRING),
  11253. value: OriginatorPublicKey.schema().valueBlock.value
  11254. })
  11255. ]
  11256. }));
  11257. }
  11258. fromSchema(schema) {
  11259. pvutils.clearProps(schema, CLEAR_PROPS$y);
  11260. const asn1 = asn1js.compareSchema(schema, schema, OriginatorIdentifierOrKey.schema({
  11261. names: {
  11262. blockName: "blockName"
  11263. }
  11264. }));
  11265. AsnError.assertSchema(asn1, this.className);
  11266. if (asn1.result.blockName.idBlock.tagClass === 1) {
  11267. this.variant = 1;
  11268. this.value = new IssuerAndSerialNumber({ schema: asn1.result.blockName });
  11269. }
  11270. else {
  11271. if (asn1.result.blockName.idBlock.tagNumber === 0) {
  11272. asn1.result.blockName.idBlock.tagClass = 1;
  11273. asn1.result.blockName.idBlock.tagNumber = 4;
  11274. this.variant = 2;
  11275. this.value = asn1.result.blockName;
  11276. }
  11277. else {
  11278. this.variant = 3;
  11279. this.value = new OriginatorPublicKey({
  11280. schema: new asn1js.Sequence({
  11281. value: asn1.result.blockName.valueBlock.value
  11282. })
  11283. });
  11284. }
  11285. }
  11286. }
  11287. toSchema() {
  11288. switch (this.variant) {
  11289. case 1:
  11290. return this.value.toSchema();
  11291. case 2:
  11292. this.value.idBlock.tagClass = 3;
  11293. this.value.idBlock.tagNumber = 0;
  11294. return this.value;
  11295. case 3:
  11296. {
  11297. const _schema = this.value.toSchema();
  11298. _schema.idBlock.tagClass = 3;
  11299. _schema.idBlock.tagNumber = 1;
  11300. return _schema;
  11301. }
  11302. default:
  11303. return new asn1js.Any();
  11304. }
  11305. }
  11306. toJSON() {
  11307. const res = {
  11308. variant: this.variant
  11309. };
  11310. if ((this.variant === 1) || (this.variant === 2) || (this.variant === 3)) {
  11311. res.value = this.value.toJSON();
  11312. }
  11313. return res;
  11314. }
  11315. }
  11316. OriginatorIdentifierOrKey.CLASS_NAME = "OriginatorIdentifierOrKey";
  11317. const KEY_ATTR_ID = "keyAttrId";
  11318. const KEY_ATTR = "keyAttr";
  11319. const CLEAR_PROPS$x = [
  11320. KEY_ATTR_ID,
  11321. KEY_ATTR,
  11322. ];
  11323. class OtherKeyAttribute extends PkiObject {
  11324. constructor(parameters = {}) {
  11325. super();
  11326. this.keyAttrId = pvutils.getParametersValue(parameters, KEY_ATTR_ID, OtherKeyAttribute.defaultValues(KEY_ATTR_ID));
  11327. if (KEY_ATTR in parameters) {
  11328. this.keyAttr = pvutils.getParametersValue(parameters, KEY_ATTR, OtherKeyAttribute.defaultValues(KEY_ATTR));
  11329. }
  11330. if (parameters.schema) {
  11331. this.fromSchema(parameters.schema);
  11332. }
  11333. }
  11334. static defaultValues(memberName) {
  11335. switch (memberName) {
  11336. case KEY_ATTR_ID:
  11337. return EMPTY_STRING;
  11338. case KEY_ATTR:
  11339. return {};
  11340. default:
  11341. return super.defaultValues(memberName);
  11342. }
  11343. }
  11344. static compareWithDefault(memberName, memberValue) {
  11345. switch (memberName) {
  11346. case KEY_ATTR_ID:
  11347. return (typeof memberValue === "string" && memberValue === EMPTY_STRING);
  11348. case KEY_ATTR:
  11349. return (Object.keys(memberValue).length === 0);
  11350. default:
  11351. return super.defaultValues(memberName);
  11352. }
  11353. }
  11354. static schema(parameters = {}) {
  11355. const names = pvutils.getParametersValue(parameters, "names", {});
  11356. return (new asn1js.Sequence({
  11357. optional: (names.optional || true),
  11358. name: (names.blockName || EMPTY_STRING),
  11359. value: [
  11360. new asn1js.ObjectIdentifier({ name: (names.keyAttrId || EMPTY_STRING) }),
  11361. new asn1js.Any({
  11362. optional: true,
  11363. name: (names.keyAttr || EMPTY_STRING)
  11364. })
  11365. ]
  11366. }));
  11367. }
  11368. fromSchema(schema) {
  11369. pvutils.clearProps(schema, CLEAR_PROPS$x);
  11370. const asn1 = asn1js.compareSchema(schema, schema, OtherKeyAttribute.schema({
  11371. names: {
  11372. keyAttrId: KEY_ATTR_ID,
  11373. keyAttr: KEY_ATTR
  11374. }
  11375. }));
  11376. AsnError.assertSchema(asn1, this.className);
  11377. this.keyAttrId = asn1.result.keyAttrId.valueBlock.toString();
  11378. if (KEY_ATTR in asn1.result) {
  11379. this.keyAttr = asn1.result.keyAttr;
  11380. }
  11381. }
  11382. toSchema() {
  11383. const outputArray = [];
  11384. outputArray.push(new asn1js.ObjectIdentifier({ value: this.keyAttrId }));
  11385. if (KEY_ATTR in this) {
  11386. outputArray.push(this.keyAttr);
  11387. }
  11388. return (new asn1js.Sequence({
  11389. value: outputArray,
  11390. }));
  11391. }
  11392. toJSON() {
  11393. const res = {
  11394. keyAttrId: this.keyAttrId
  11395. };
  11396. if (KEY_ATTR in this) {
  11397. res.keyAttr = this.keyAttr.toJSON();
  11398. }
  11399. return res;
  11400. }
  11401. }
  11402. OtherKeyAttribute.CLASS_NAME = "OtherKeyAttribute";
  11403. const SUBJECT_KEY_IDENTIFIER = "subjectKeyIdentifier";
  11404. const DATE$1 = "date";
  11405. const OTHER$1 = "other";
  11406. const CLEAR_PROPS$w = [
  11407. SUBJECT_KEY_IDENTIFIER,
  11408. DATE$1,
  11409. OTHER$1,
  11410. ];
  11411. class RecipientKeyIdentifier extends PkiObject {
  11412. constructor(parameters = {}) {
  11413. super();
  11414. this.subjectKeyIdentifier = pvutils.getParametersValue(parameters, SUBJECT_KEY_IDENTIFIER, RecipientKeyIdentifier.defaultValues(SUBJECT_KEY_IDENTIFIER));
  11415. if (DATE$1 in parameters) {
  11416. this.date = pvutils.getParametersValue(parameters, DATE$1, RecipientKeyIdentifier.defaultValues(DATE$1));
  11417. }
  11418. if (OTHER$1 in parameters) {
  11419. this.other = pvutils.getParametersValue(parameters, OTHER$1, RecipientKeyIdentifier.defaultValues(OTHER$1));
  11420. }
  11421. if (parameters.schema) {
  11422. this.fromSchema(parameters.schema);
  11423. }
  11424. }
  11425. static defaultValues(memberName) {
  11426. switch (memberName) {
  11427. case SUBJECT_KEY_IDENTIFIER:
  11428. return new asn1js.OctetString();
  11429. case DATE$1:
  11430. return new asn1js.GeneralizedTime();
  11431. case OTHER$1:
  11432. return new OtherKeyAttribute();
  11433. default:
  11434. return super.defaultValues(memberName);
  11435. }
  11436. }
  11437. static compareWithDefault(memberName, memberValue) {
  11438. switch (memberName) {
  11439. case SUBJECT_KEY_IDENTIFIER:
  11440. return (memberValue.isEqual(RecipientKeyIdentifier.defaultValues(SUBJECT_KEY_IDENTIFIER)));
  11441. case DATE$1:
  11442. return ((memberValue.year === 0) &&
  11443. (memberValue.month === 0) &&
  11444. (memberValue.day === 0) &&
  11445. (memberValue.hour === 0) &&
  11446. (memberValue.minute === 0) &&
  11447. (memberValue.second === 0) &&
  11448. (memberValue.millisecond === 0));
  11449. case OTHER$1:
  11450. return ((memberValue.keyAttrId === EMPTY_STRING) && (("keyAttr" in memberValue) === false));
  11451. default:
  11452. return super.defaultValues(memberName);
  11453. }
  11454. }
  11455. static schema(parameters = {}) {
  11456. const names = pvutils.getParametersValue(parameters, "names", {});
  11457. return (new asn1js.Sequence({
  11458. name: (names.blockName || EMPTY_STRING),
  11459. value: [
  11460. new asn1js.OctetString({ name: (names.subjectKeyIdentifier || EMPTY_STRING) }),
  11461. new asn1js.GeneralizedTime({
  11462. optional: true,
  11463. name: (names.date || EMPTY_STRING)
  11464. }),
  11465. OtherKeyAttribute.schema(names.other || {})
  11466. ]
  11467. }));
  11468. }
  11469. fromSchema(schema) {
  11470. pvutils.clearProps(schema, CLEAR_PROPS$w);
  11471. const asn1 = asn1js.compareSchema(schema, schema, RecipientKeyIdentifier.schema({
  11472. names: {
  11473. subjectKeyIdentifier: SUBJECT_KEY_IDENTIFIER,
  11474. date: DATE$1,
  11475. other: {
  11476. names: {
  11477. blockName: OTHER$1
  11478. }
  11479. }
  11480. }
  11481. }));
  11482. AsnError.assertSchema(asn1, this.className);
  11483. this.subjectKeyIdentifier = asn1.result.subjectKeyIdentifier;
  11484. if (DATE$1 in asn1.result)
  11485. this.date = asn1.result.date;
  11486. if (OTHER$1 in asn1.result)
  11487. this.other = new OtherKeyAttribute({ schema: asn1.result.other });
  11488. }
  11489. toSchema() {
  11490. const outputArray = [];
  11491. outputArray.push(this.subjectKeyIdentifier);
  11492. if (this.date) {
  11493. outputArray.push(this.date);
  11494. }
  11495. if (this.other) {
  11496. outputArray.push(this.other.toSchema());
  11497. }
  11498. return (new asn1js.Sequence({
  11499. value: outputArray
  11500. }));
  11501. }
  11502. toJSON() {
  11503. const res = {
  11504. subjectKeyIdentifier: this.subjectKeyIdentifier.toJSON()
  11505. };
  11506. if (this.date) {
  11507. res.date = this.date.toJSON();
  11508. }
  11509. if (this.other) {
  11510. res.other = this.other.toJSON();
  11511. }
  11512. return res;
  11513. }
  11514. }
  11515. RecipientKeyIdentifier.CLASS_NAME = "RecipientKeyIdentifier";
  11516. const VARIANT$1 = "variant";
  11517. const VALUE$1 = "value";
  11518. const CLEAR_PROPS$v = [
  11519. "blockName",
  11520. ];
  11521. class KeyAgreeRecipientIdentifier extends PkiObject {
  11522. constructor(parameters = {}) {
  11523. super();
  11524. this.variant = pvutils.getParametersValue(parameters, VARIANT$1, KeyAgreeRecipientIdentifier.defaultValues(VARIANT$1));
  11525. this.value = pvutils.getParametersValue(parameters, VALUE$1, KeyAgreeRecipientIdentifier.defaultValues(VALUE$1));
  11526. if (parameters.schema) {
  11527. this.fromSchema(parameters.schema);
  11528. }
  11529. }
  11530. static defaultValues(memberName) {
  11531. switch (memberName) {
  11532. case VARIANT$1:
  11533. return (-1);
  11534. case VALUE$1:
  11535. return {};
  11536. default:
  11537. return super.defaultValues(memberName);
  11538. }
  11539. }
  11540. static compareWithDefault(memberName, memberValue) {
  11541. switch (memberName) {
  11542. case VARIANT$1:
  11543. return (memberValue === (-1));
  11544. case VALUE$1:
  11545. return (Object.keys(memberValue).length === 0);
  11546. default:
  11547. return super.defaultValues(memberName);
  11548. }
  11549. }
  11550. static schema(parameters = {}) {
  11551. const names = pvutils.getParametersValue(parameters, "names", {});
  11552. return (new asn1js.Choice({
  11553. value: [
  11554. IssuerAndSerialNumber.schema(names.issuerAndSerialNumber || {
  11555. names: {
  11556. blockName: (names.blockName || EMPTY_STRING)
  11557. }
  11558. }),
  11559. new asn1js.Constructed({
  11560. name: (names.blockName || EMPTY_STRING),
  11561. idBlock: {
  11562. tagClass: 3,
  11563. tagNumber: 0
  11564. },
  11565. value: RecipientKeyIdentifier.schema(names.rKeyId || {
  11566. names: {
  11567. blockName: (names.blockName || EMPTY_STRING)
  11568. }
  11569. }).valueBlock.value
  11570. })
  11571. ]
  11572. }));
  11573. }
  11574. fromSchema(schema) {
  11575. pvutils.clearProps(schema, CLEAR_PROPS$v);
  11576. const asn1 = asn1js.compareSchema(schema, schema, KeyAgreeRecipientIdentifier.schema({
  11577. names: {
  11578. blockName: "blockName"
  11579. }
  11580. }));
  11581. AsnError.assertSchema(asn1, this.className);
  11582. if (asn1.result.blockName.idBlock.tagClass === 1) {
  11583. this.variant = 1;
  11584. this.value = new IssuerAndSerialNumber({ schema: asn1.result.blockName });
  11585. }
  11586. else {
  11587. this.variant = 2;
  11588. this.value = new RecipientKeyIdentifier({
  11589. schema: new asn1js.Sequence({
  11590. value: asn1.result.blockName.valueBlock.value
  11591. })
  11592. });
  11593. }
  11594. }
  11595. toSchema() {
  11596. switch (this.variant) {
  11597. case 1:
  11598. return this.value.toSchema();
  11599. case 2:
  11600. return new asn1js.Constructed({
  11601. idBlock: {
  11602. tagClass: 3,
  11603. tagNumber: 0
  11604. },
  11605. value: this.value.toSchema().valueBlock.value
  11606. });
  11607. default:
  11608. return new asn1js.Any();
  11609. }
  11610. }
  11611. toJSON() {
  11612. const res = {
  11613. variant: this.variant,
  11614. };
  11615. if ((this.variant === 1) || (this.variant === 2)) {
  11616. res.value = this.value.toJSON();
  11617. }
  11618. return res;
  11619. }
  11620. }
  11621. KeyAgreeRecipientIdentifier.CLASS_NAME = "KeyAgreeRecipientIdentifier";
  11622. const RID = "rid";
  11623. const ENCRYPTED_KEY$2 = "encryptedKey";
  11624. const CLEAR_PROPS$u = [
  11625. RID,
  11626. ENCRYPTED_KEY$2,
  11627. ];
  11628. class RecipientEncryptedKey extends PkiObject {
  11629. constructor(parameters = {}) {
  11630. super();
  11631. this.rid = pvutils.getParametersValue(parameters, RID, RecipientEncryptedKey.defaultValues(RID));
  11632. this.encryptedKey = pvutils.getParametersValue(parameters, ENCRYPTED_KEY$2, RecipientEncryptedKey.defaultValues(ENCRYPTED_KEY$2));
  11633. if (parameters.schema) {
  11634. this.fromSchema(parameters.schema);
  11635. }
  11636. }
  11637. static defaultValues(memberName) {
  11638. switch (memberName) {
  11639. case RID:
  11640. return new KeyAgreeRecipientIdentifier();
  11641. case ENCRYPTED_KEY$2:
  11642. return new asn1js.OctetString();
  11643. default:
  11644. return super.defaultValues(memberName);
  11645. }
  11646. }
  11647. static compareWithDefault(memberName, memberValue) {
  11648. switch (memberName) {
  11649. case RID:
  11650. return ((memberValue.variant === (-1)) && (("value" in memberValue) === false));
  11651. case ENCRYPTED_KEY$2:
  11652. return (memberValue.isEqual(RecipientEncryptedKey.defaultValues(ENCRYPTED_KEY$2)));
  11653. default:
  11654. return super.defaultValues(memberName);
  11655. }
  11656. }
  11657. static schema(parameters = {}) {
  11658. const names = pvutils.getParametersValue(parameters, "names", {});
  11659. return (new asn1js.Sequence({
  11660. name: (names.blockName || EMPTY_STRING),
  11661. value: [
  11662. KeyAgreeRecipientIdentifier.schema(names.rid || {}),
  11663. new asn1js.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  11664. ]
  11665. }));
  11666. }
  11667. fromSchema(schema) {
  11668. pvutils.clearProps(schema, CLEAR_PROPS$u);
  11669. const asn1 = asn1js.compareSchema(schema, schema, RecipientEncryptedKey.schema({
  11670. names: {
  11671. rid: {
  11672. names: {
  11673. blockName: RID
  11674. }
  11675. },
  11676. encryptedKey: ENCRYPTED_KEY$2
  11677. }
  11678. }));
  11679. AsnError.assertSchema(asn1, this.className);
  11680. this.rid = new KeyAgreeRecipientIdentifier({ schema: asn1.result.rid });
  11681. this.encryptedKey = asn1.result.encryptedKey;
  11682. }
  11683. toSchema() {
  11684. return (new asn1js.Sequence({
  11685. value: [
  11686. this.rid.toSchema(),
  11687. this.encryptedKey
  11688. ]
  11689. }));
  11690. }
  11691. toJSON() {
  11692. return {
  11693. rid: this.rid.toJSON(),
  11694. encryptedKey: this.encryptedKey.toJSON(),
  11695. };
  11696. }
  11697. }
  11698. RecipientEncryptedKey.CLASS_NAME = "RecipientEncryptedKey";
  11699. const ENCRYPTED_KEYS = "encryptedKeys";
  11700. const RECIPIENT_ENCRYPTED_KEYS = "RecipientEncryptedKeys";
  11701. const CLEAR_PROPS$t = [
  11702. RECIPIENT_ENCRYPTED_KEYS,
  11703. ];
  11704. class RecipientEncryptedKeys extends PkiObject {
  11705. constructor(parameters = {}) {
  11706. super();
  11707. this.encryptedKeys = pvutils.getParametersValue(parameters, ENCRYPTED_KEYS, RecipientEncryptedKeys.defaultValues(ENCRYPTED_KEYS));
  11708. if (parameters.schema) {
  11709. this.fromSchema(parameters.schema);
  11710. }
  11711. }
  11712. static defaultValues(memberName) {
  11713. switch (memberName) {
  11714. case ENCRYPTED_KEYS:
  11715. return [];
  11716. default:
  11717. return super.defaultValues(memberName);
  11718. }
  11719. }
  11720. static compareWithDefault(memberName, memberValue) {
  11721. switch (memberName) {
  11722. case ENCRYPTED_KEYS:
  11723. return (memberValue.length === 0);
  11724. default:
  11725. return super.defaultValues(memberName);
  11726. }
  11727. }
  11728. static schema(parameters = {}) {
  11729. const names = pvutils.getParametersValue(parameters, "names", {});
  11730. return (new asn1js.Sequence({
  11731. name: (names.blockName || EMPTY_STRING),
  11732. value: [
  11733. new asn1js.Repeated({
  11734. name: (names.RecipientEncryptedKeys || EMPTY_STRING),
  11735. value: RecipientEncryptedKey.schema()
  11736. })
  11737. ]
  11738. }));
  11739. }
  11740. fromSchema(schema) {
  11741. pvutils.clearProps(schema, CLEAR_PROPS$t);
  11742. const asn1 = asn1js.compareSchema(schema, schema, RecipientEncryptedKeys.schema({
  11743. names: {
  11744. RecipientEncryptedKeys: RECIPIENT_ENCRYPTED_KEYS
  11745. }
  11746. }));
  11747. AsnError.assertSchema(asn1, this.className);
  11748. this.encryptedKeys = Array.from(asn1.result.RecipientEncryptedKeys, element => new RecipientEncryptedKey({ schema: element }));
  11749. }
  11750. toSchema() {
  11751. return (new asn1js.Sequence({
  11752. value: Array.from(this.encryptedKeys, o => o.toSchema())
  11753. }));
  11754. }
  11755. toJSON() {
  11756. return {
  11757. encryptedKeys: Array.from(this.encryptedKeys, o => o.toJSON())
  11758. };
  11759. }
  11760. }
  11761. RecipientEncryptedKeys.CLASS_NAME = "RecipientEncryptedKeys";
  11762. const VERSION$b = "version";
  11763. const ORIGINATOR = "originator";
  11764. const UKM = "ukm";
  11765. const KEY_ENCRYPTION_ALGORITHM$2 = "keyEncryptionAlgorithm";
  11766. const RECIPIENT_ENCRYPTED_KEY = "recipientEncryptedKeys";
  11767. const RECIPIENT_CERTIFICATE = "recipientCertificate";
  11768. const RECIPIENT_PUBLIC_KEY = "recipientPublicKey";
  11769. const CLEAR_PROPS$s = [
  11770. VERSION$b,
  11771. ORIGINATOR,
  11772. UKM,
  11773. KEY_ENCRYPTION_ALGORITHM$2,
  11774. RECIPIENT_ENCRYPTED_KEY,
  11775. ];
  11776. class KeyAgreeRecipientInfo extends PkiObject {
  11777. constructor(parameters = {}) {
  11778. super();
  11779. this.version = pvutils.getParametersValue(parameters, VERSION$b, KeyAgreeRecipientInfo.defaultValues(VERSION$b));
  11780. this.originator = pvutils.getParametersValue(parameters, ORIGINATOR, KeyAgreeRecipientInfo.defaultValues(ORIGINATOR));
  11781. if (UKM in parameters) {
  11782. this.ukm = pvutils.getParametersValue(parameters, UKM, KeyAgreeRecipientInfo.defaultValues(UKM));
  11783. }
  11784. this.keyEncryptionAlgorithm = pvutils.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM$2, KeyAgreeRecipientInfo.defaultValues(KEY_ENCRYPTION_ALGORITHM$2));
  11785. this.recipientEncryptedKeys = pvutils.getParametersValue(parameters, RECIPIENT_ENCRYPTED_KEY, KeyAgreeRecipientInfo.defaultValues(RECIPIENT_ENCRYPTED_KEY));
  11786. this.recipientCertificate = pvutils.getParametersValue(parameters, RECIPIENT_CERTIFICATE, KeyAgreeRecipientInfo.defaultValues(RECIPIENT_CERTIFICATE));
  11787. this.recipientPublicKey = pvutils.getParametersValue(parameters, RECIPIENT_PUBLIC_KEY, KeyAgreeRecipientInfo.defaultValues(RECIPIENT_PUBLIC_KEY));
  11788. if (parameters.schema) {
  11789. this.fromSchema(parameters.schema);
  11790. }
  11791. }
  11792. static defaultValues(memberName) {
  11793. switch (memberName) {
  11794. case VERSION$b:
  11795. return 0;
  11796. case ORIGINATOR:
  11797. return new OriginatorIdentifierOrKey();
  11798. case UKM:
  11799. return new asn1js.OctetString();
  11800. case KEY_ENCRYPTION_ALGORITHM$2:
  11801. return new AlgorithmIdentifier();
  11802. case RECIPIENT_ENCRYPTED_KEY:
  11803. return new RecipientEncryptedKeys();
  11804. case RECIPIENT_CERTIFICATE:
  11805. return new Certificate();
  11806. case RECIPIENT_PUBLIC_KEY:
  11807. return null;
  11808. default:
  11809. return super.defaultValues(memberName);
  11810. }
  11811. }
  11812. static compareWithDefault(memberName, memberValue) {
  11813. switch (memberName) {
  11814. case VERSION$b:
  11815. return (memberValue === 0);
  11816. case ORIGINATOR:
  11817. return ((memberValue.variant === (-1)) && (("value" in memberValue) === false));
  11818. case UKM:
  11819. return (memberValue.isEqual(KeyAgreeRecipientInfo.defaultValues(UKM)));
  11820. case KEY_ENCRYPTION_ALGORITHM$2:
  11821. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  11822. case RECIPIENT_ENCRYPTED_KEY:
  11823. return (memberValue.encryptedKeys.length === 0);
  11824. case RECIPIENT_CERTIFICATE:
  11825. return false;
  11826. case RECIPIENT_PUBLIC_KEY:
  11827. return false;
  11828. default:
  11829. return super.defaultValues(memberName);
  11830. }
  11831. }
  11832. static schema(parameters = {}) {
  11833. const names = pvutils.getParametersValue(parameters, "names", {});
  11834. return (new asn1js.Sequence({
  11835. name: names.blockName || EMPTY_STRING,
  11836. value: [
  11837. new asn1js.Integer({ name: names.version || EMPTY_STRING }),
  11838. new asn1js.Constructed({
  11839. idBlock: {
  11840. tagClass: 3,
  11841. tagNumber: 0
  11842. },
  11843. value: [
  11844. OriginatorIdentifierOrKey.schema(names.originator || {})
  11845. ]
  11846. }),
  11847. new asn1js.Constructed({
  11848. optional: true,
  11849. idBlock: {
  11850. tagClass: 3,
  11851. tagNumber: 1
  11852. },
  11853. value: [new asn1js.OctetString({ name: names.ukm || EMPTY_STRING })]
  11854. }),
  11855. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  11856. RecipientEncryptedKeys.schema(names.recipientEncryptedKeys || {})
  11857. ]
  11858. }));
  11859. }
  11860. fromSchema(schema) {
  11861. pvutils.clearProps(schema, CLEAR_PROPS$s);
  11862. const asn1 = asn1js.compareSchema(schema, schema, KeyAgreeRecipientInfo.schema({
  11863. names: {
  11864. version: VERSION$b,
  11865. originator: {
  11866. names: {
  11867. blockName: ORIGINATOR
  11868. }
  11869. },
  11870. ukm: UKM,
  11871. keyEncryptionAlgorithm: {
  11872. names: {
  11873. blockName: KEY_ENCRYPTION_ALGORITHM$2
  11874. }
  11875. },
  11876. recipientEncryptedKeys: {
  11877. names: {
  11878. blockName: RECIPIENT_ENCRYPTED_KEY
  11879. }
  11880. }
  11881. }
  11882. }));
  11883. AsnError.assertSchema(asn1, this.className);
  11884. this.version = asn1.result.version.valueBlock.valueDec;
  11885. this.originator = new OriginatorIdentifierOrKey({ schema: asn1.result.originator });
  11886. if (UKM in asn1.result)
  11887. this.ukm = asn1.result.ukm;
  11888. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  11889. this.recipientEncryptedKeys = new RecipientEncryptedKeys({ schema: asn1.result.recipientEncryptedKeys });
  11890. }
  11891. toSchema() {
  11892. const outputArray = [];
  11893. outputArray.push(new asn1js.Integer({ value: this.version }));
  11894. outputArray.push(new asn1js.Constructed({
  11895. idBlock: {
  11896. tagClass: 3,
  11897. tagNumber: 0
  11898. },
  11899. value: [this.originator.toSchema()]
  11900. }));
  11901. if (this.ukm) {
  11902. outputArray.push(new asn1js.Constructed({
  11903. optional: true,
  11904. idBlock: {
  11905. tagClass: 3,
  11906. tagNumber: 1
  11907. },
  11908. value: [this.ukm]
  11909. }));
  11910. }
  11911. outputArray.push(this.keyEncryptionAlgorithm.toSchema());
  11912. outputArray.push(this.recipientEncryptedKeys.toSchema());
  11913. return (new asn1js.Sequence({
  11914. value: outputArray
  11915. }));
  11916. }
  11917. toJSON() {
  11918. const res = {
  11919. version: this.version,
  11920. originator: this.originator.toJSON(),
  11921. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  11922. recipientEncryptedKeys: this.recipientEncryptedKeys.toJSON(),
  11923. };
  11924. if (this.ukm) {
  11925. res.ukm = this.ukm.toJSON();
  11926. }
  11927. return res;
  11928. }
  11929. }
  11930. KeyAgreeRecipientInfo.CLASS_NAME = "KeyAgreeRecipientInfo";
  11931. const KEY_IDENTIFIER = "keyIdentifier";
  11932. const DATE = "date";
  11933. const OTHER = "other";
  11934. const CLEAR_PROPS$r = [
  11935. KEY_IDENTIFIER,
  11936. DATE,
  11937. OTHER,
  11938. ];
  11939. class KEKIdentifier extends PkiObject {
  11940. constructor(parameters = {}) {
  11941. super();
  11942. this.keyIdentifier = pvutils.getParametersValue(parameters, KEY_IDENTIFIER, KEKIdentifier.defaultValues(KEY_IDENTIFIER));
  11943. if (DATE in parameters) {
  11944. this.date = pvutils.getParametersValue(parameters, DATE, KEKIdentifier.defaultValues(DATE));
  11945. }
  11946. if (OTHER in parameters) {
  11947. this.other = pvutils.getParametersValue(parameters, OTHER, KEKIdentifier.defaultValues(OTHER));
  11948. }
  11949. if (parameters.schema) {
  11950. this.fromSchema(parameters.schema);
  11951. }
  11952. }
  11953. static defaultValues(memberName) {
  11954. switch (memberName) {
  11955. case KEY_IDENTIFIER:
  11956. return new asn1js.OctetString();
  11957. case DATE:
  11958. return new asn1js.GeneralizedTime();
  11959. case OTHER:
  11960. return new OtherKeyAttribute();
  11961. default:
  11962. return super.defaultValues(memberName);
  11963. }
  11964. }
  11965. static compareWithDefault(memberName, memberValue) {
  11966. switch (memberName) {
  11967. case KEY_IDENTIFIER:
  11968. return (memberValue.isEqual(KEKIdentifier.defaultValues(KEY_IDENTIFIER)));
  11969. case DATE:
  11970. return ((memberValue.year === 0) &&
  11971. (memberValue.month === 0) &&
  11972. (memberValue.day === 0) &&
  11973. (memberValue.hour === 0) &&
  11974. (memberValue.minute === 0) &&
  11975. (memberValue.second === 0) &&
  11976. (memberValue.millisecond === 0));
  11977. case OTHER:
  11978. return ((memberValue.compareWithDefault("keyAttrId", memberValue.keyAttrId)) &&
  11979. (("keyAttr" in memberValue) === false));
  11980. default:
  11981. return super.defaultValues(memberName);
  11982. }
  11983. }
  11984. static schema(parameters = {}) {
  11985. const names = pvutils.getParametersValue(parameters, "names", {});
  11986. return (new asn1js.Sequence({
  11987. name: (names.blockName || EMPTY_STRING),
  11988. value: [
  11989. new asn1js.OctetString({ name: (names.keyIdentifier || EMPTY_STRING) }),
  11990. new asn1js.GeneralizedTime({
  11991. optional: true,
  11992. name: (names.date || EMPTY_STRING)
  11993. }),
  11994. OtherKeyAttribute.schema(names.other || {})
  11995. ]
  11996. }));
  11997. }
  11998. fromSchema(schema) {
  11999. pvutils.clearProps(schema, CLEAR_PROPS$r);
  12000. const asn1 = asn1js.compareSchema(schema, schema, KEKIdentifier.schema({
  12001. names: {
  12002. keyIdentifier: KEY_IDENTIFIER,
  12003. date: DATE,
  12004. other: {
  12005. names: {
  12006. blockName: OTHER
  12007. }
  12008. }
  12009. }
  12010. }));
  12011. AsnError.assertSchema(asn1, this.className);
  12012. this.keyIdentifier = asn1.result.keyIdentifier;
  12013. if (DATE in asn1.result)
  12014. this.date = asn1.result.date;
  12015. if (OTHER in asn1.result)
  12016. this.other = new OtherKeyAttribute({ schema: asn1.result.other });
  12017. }
  12018. toSchema() {
  12019. const outputArray = [];
  12020. outputArray.push(this.keyIdentifier);
  12021. if (this.date) {
  12022. outputArray.push(this.date);
  12023. }
  12024. if (this.other) {
  12025. outputArray.push(this.other.toSchema());
  12026. }
  12027. return (new asn1js.Sequence({
  12028. value: outputArray
  12029. }));
  12030. }
  12031. toJSON() {
  12032. const res = {
  12033. keyIdentifier: this.keyIdentifier.toJSON()
  12034. };
  12035. if (this.date) {
  12036. res.date = this.date;
  12037. }
  12038. if (this.other) {
  12039. res.other = this.other.toJSON();
  12040. }
  12041. return res;
  12042. }
  12043. }
  12044. KEKIdentifier.CLASS_NAME = "KEKIdentifier";
  12045. const VERSION$a = "version";
  12046. const KEK_ID = "kekid";
  12047. const KEY_ENCRYPTION_ALGORITHM$1 = "keyEncryptionAlgorithm";
  12048. const ENCRYPTED_KEY$1 = "encryptedKey";
  12049. const PER_DEFINED_KEK = "preDefinedKEK";
  12050. const CLEAR_PROPS$q = [
  12051. VERSION$a,
  12052. KEK_ID,
  12053. KEY_ENCRYPTION_ALGORITHM$1,
  12054. ENCRYPTED_KEY$1,
  12055. ];
  12056. class KEKRecipientInfo extends PkiObject {
  12057. constructor(parameters = {}) {
  12058. super();
  12059. this.version = pvutils.getParametersValue(parameters, VERSION$a, KEKRecipientInfo.defaultValues(VERSION$a));
  12060. this.kekid = pvutils.getParametersValue(parameters, KEK_ID, KEKRecipientInfo.defaultValues(KEK_ID));
  12061. this.keyEncryptionAlgorithm = pvutils.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM$1, KEKRecipientInfo.defaultValues(KEY_ENCRYPTION_ALGORITHM$1));
  12062. this.encryptedKey = pvutils.getParametersValue(parameters, ENCRYPTED_KEY$1, KEKRecipientInfo.defaultValues(ENCRYPTED_KEY$1));
  12063. this.preDefinedKEK = pvutils.getParametersValue(parameters, PER_DEFINED_KEK, KEKRecipientInfo.defaultValues(PER_DEFINED_KEK));
  12064. if (parameters.schema) {
  12065. this.fromSchema(parameters.schema);
  12066. }
  12067. }
  12068. static defaultValues(memberName) {
  12069. switch (memberName) {
  12070. case VERSION$a:
  12071. return 0;
  12072. case KEK_ID:
  12073. return new KEKIdentifier();
  12074. case KEY_ENCRYPTION_ALGORITHM$1:
  12075. return new AlgorithmIdentifier();
  12076. case ENCRYPTED_KEY$1:
  12077. return new asn1js.OctetString();
  12078. case PER_DEFINED_KEK:
  12079. return EMPTY_BUFFER;
  12080. default:
  12081. return super.defaultValues(memberName);
  12082. }
  12083. }
  12084. static compareWithDefault(memberName, memberValue) {
  12085. switch (memberName) {
  12086. case "KEKRecipientInfo":
  12087. return (memberValue === KEKRecipientInfo.defaultValues(VERSION$a));
  12088. case KEK_ID:
  12089. return ((memberValue.compareWithDefault("keyIdentifier", memberValue.keyIdentifier)) &&
  12090. (("date" in memberValue) === false) &&
  12091. (("other" in memberValue) === false));
  12092. case KEY_ENCRYPTION_ALGORITHM$1:
  12093. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  12094. case ENCRYPTED_KEY$1:
  12095. return (memberValue.isEqual(KEKRecipientInfo.defaultValues(ENCRYPTED_KEY$1)));
  12096. case PER_DEFINED_KEK:
  12097. return (memberValue.byteLength === 0);
  12098. default:
  12099. return super.defaultValues(memberName);
  12100. }
  12101. }
  12102. static schema(parameters = {}) {
  12103. const names = pvutils.getParametersValue(parameters, "names", {});
  12104. return (new asn1js.Sequence({
  12105. name: (names.blockName || EMPTY_STRING),
  12106. value: [
  12107. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  12108. KEKIdentifier.schema(names.kekid || {}),
  12109. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  12110. new asn1js.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  12111. ]
  12112. }));
  12113. }
  12114. fromSchema(schema) {
  12115. pvutils.clearProps(schema, CLEAR_PROPS$q);
  12116. const asn1 = asn1js.compareSchema(schema, schema, KEKRecipientInfo.schema({
  12117. names: {
  12118. version: VERSION$a,
  12119. kekid: {
  12120. names: {
  12121. blockName: KEK_ID
  12122. }
  12123. },
  12124. keyEncryptionAlgorithm: {
  12125. names: {
  12126. blockName: KEY_ENCRYPTION_ALGORITHM$1
  12127. }
  12128. },
  12129. encryptedKey: ENCRYPTED_KEY$1
  12130. }
  12131. }));
  12132. AsnError.assertSchema(asn1, this.className);
  12133. this.version = asn1.result.version.valueBlock.valueDec;
  12134. this.kekid = new KEKIdentifier({ schema: asn1.result.kekid });
  12135. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  12136. this.encryptedKey = asn1.result.encryptedKey;
  12137. }
  12138. toSchema() {
  12139. return (new asn1js.Sequence({
  12140. value: [
  12141. new asn1js.Integer({ value: this.version }),
  12142. this.kekid.toSchema(),
  12143. this.keyEncryptionAlgorithm.toSchema(),
  12144. this.encryptedKey
  12145. ]
  12146. }));
  12147. }
  12148. toJSON() {
  12149. return {
  12150. version: this.version,
  12151. kekid: this.kekid.toJSON(),
  12152. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  12153. encryptedKey: this.encryptedKey.toJSON(),
  12154. };
  12155. }
  12156. }
  12157. KEKRecipientInfo.CLASS_NAME = "KEKRecipientInfo";
  12158. const VERSION$9 = "version";
  12159. const KEY_DERIVATION_ALGORITHM = "keyDerivationAlgorithm";
  12160. const KEY_ENCRYPTION_ALGORITHM = "keyEncryptionAlgorithm";
  12161. const ENCRYPTED_KEY = "encryptedKey";
  12162. const PASSWORD = "password";
  12163. const CLEAR_PROPS$p = [
  12164. VERSION$9,
  12165. KEY_DERIVATION_ALGORITHM,
  12166. KEY_ENCRYPTION_ALGORITHM,
  12167. ENCRYPTED_KEY
  12168. ];
  12169. class PasswordRecipientinfo extends PkiObject {
  12170. constructor(parameters = {}) {
  12171. super();
  12172. this.version = pvutils.getParametersValue(parameters, VERSION$9, PasswordRecipientinfo.defaultValues(VERSION$9));
  12173. if (KEY_DERIVATION_ALGORITHM in parameters) {
  12174. this.keyDerivationAlgorithm = pvutils.getParametersValue(parameters, KEY_DERIVATION_ALGORITHM, PasswordRecipientinfo.defaultValues(KEY_DERIVATION_ALGORITHM));
  12175. }
  12176. this.keyEncryptionAlgorithm = pvutils.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM, PasswordRecipientinfo.defaultValues(KEY_ENCRYPTION_ALGORITHM));
  12177. this.encryptedKey = pvutils.getParametersValue(parameters, ENCRYPTED_KEY, PasswordRecipientinfo.defaultValues(ENCRYPTED_KEY));
  12178. this.password = pvutils.getParametersValue(parameters, PASSWORD, PasswordRecipientinfo.defaultValues(PASSWORD));
  12179. if (parameters.schema) {
  12180. this.fromSchema(parameters.schema);
  12181. }
  12182. }
  12183. static defaultValues(memberName) {
  12184. switch (memberName) {
  12185. case VERSION$9:
  12186. return (-1);
  12187. case KEY_DERIVATION_ALGORITHM:
  12188. return new AlgorithmIdentifier();
  12189. case KEY_ENCRYPTION_ALGORITHM:
  12190. return new AlgorithmIdentifier();
  12191. case ENCRYPTED_KEY:
  12192. return new asn1js.OctetString();
  12193. case PASSWORD:
  12194. return EMPTY_BUFFER;
  12195. default:
  12196. return super.defaultValues(memberName);
  12197. }
  12198. }
  12199. static compareWithDefault(memberName, memberValue) {
  12200. switch (memberName) {
  12201. case VERSION$9:
  12202. return (memberValue === (-1));
  12203. case KEY_DERIVATION_ALGORITHM:
  12204. case KEY_ENCRYPTION_ALGORITHM:
  12205. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  12206. case ENCRYPTED_KEY:
  12207. return (memberValue.isEqual(PasswordRecipientinfo.defaultValues(ENCRYPTED_KEY)));
  12208. case PASSWORD:
  12209. return (memberValue.byteLength === 0);
  12210. default:
  12211. return super.defaultValues(memberName);
  12212. }
  12213. }
  12214. static schema(parameters = {}) {
  12215. const names = pvutils.getParametersValue(parameters, "names", {});
  12216. return (new asn1js.Sequence({
  12217. name: (names.blockName || EMPTY_STRING),
  12218. value: [
  12219. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  12220. new asn1js.Constructed({
  12221. name: (names.keyDerivationAlgorithm || EMPTY_STRING),
  12222. optional: true,
  12223. idBlock: {
  12224. tagClass: 3,
  12225. tagNumber: 0
  12226. },
  12227. value: AlgorithmIdentifier.schema().valueBlock.value
  12228. }),
  12229. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  12230. new asn1js.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  12231. ]
  12232. }));
  12233. }
  12234. fromSchema(schema) {
  12235. pvutils.clearProps(schema, CLEAR_PROPS$p);
  12236. const asn1 = asn1js.compareSchema(schema, schema, PasswordRecipientinfo.schema({
  12237. names: {
  12238. version: VERSION$9,
  12239. keyDerivationAlgorithm: KEY_DERIVATION_ALGORITHM,
  12240. keyEncryptionAlgorithm: {
  12241. names: {
  12242. blockName: KEY_ENCRYPTION_ALGORITHM
  12243. }
  12244. },
  12245. encryptedKey: ENCRYPTED_KEY
  12246. }
  12247. }));
  12248. AsnError.assertSchema(asn1, this.className);
  12249. this.version = asn1.result.version.valueBlock.valueDec;
  12250. if (KEY_DERIVATION_ALGORITHM in asn1.result) {
  12251. this.keyDerivationAlgorithm = new AlgorithmIdentifier({
  12252. schema: new asn1js.Sequence({
  12253. value: asn1.result.keyDerivationAlgorithm.valueBlock.value
  12254. })
  12255. });
  12256. }
  12257. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  12258. this.encryptedKey = asn1.result.encryptedKey;
  12259. }
  12260. toSchema() {
  12261. const outputArray = [];
  12262. outputArray.push(new asn1js.Integer({ value: this.version }));
  12263. if (this.keyDerivationAlgorithm) {
  12264. outputArray.push(new asn1js.Constructed({
  12265. idBlock: {
  12266. tagClass: 3,
  12267. tagNumber: 0
  12268. },
  12269. value: this.keyDerivationAlgorithm.toSchema().valueBlock.value
  12270. }));
  12271. }
  12272. outputArray.push(this.keyEncryptionAlgorithm.toSchema());
  12273. outputArray.push(this.encryptedKey);
  12274. return (new asn1js.Sequence({
  12275. value: outputArray
  12276. }));
  12277. }
  12278. toJSON() {
  12279. const res = {
  12280. version: this.version,
  12281. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  12282. encryptedKey: this.encryptedKey.toJSON(),
  12283. };
  12284. if (this.keyDerivationAlgorithm) {
  12285. res.keyDerivationAlgorithm = this.keyDerivationAlgorithm.toJSON();
  12286. }
  12287. return res;
  12288. }
  12289. }
  12290. PasswordRecipientinfo.CLASS_NAME = "PasswordRecipientInfo";
  12291. const ORI_TYPE = "oriType";
  12292. const ORI_VALUE = "oriValue";
  12293. const CLEAR_PROPS$o = [
  12294. ORI_TYPE,
  12295. ORI_VALUE
  12296. ];
  12297. class OtherRecipientInfo extends PkiObject {
  12298. constructor(parameters = {}) {
  12299. super();
  12300. this.oriType = pvutils.getParametersValue(parameters, ORI_TYPE, OtherRecipientInfo.defaultValues(ORI_TYPE));
  12301. this.oriValue = pvutils.getParametersValue(parameters, ORI_VALUE, OtherRecipientInfo.defaultValues(ORI_VALUE));
  12302. if (parameters.schema) {
  12303. this.fromSchema(parameters.schema);
  12304. }
  12305. }
  12306. static defaultValues(memberName) {
  12307. switch (memberName) {
  12308. case ORI_TYPE:
  12309. return EMPTY_STRING;
  12310. case ORI_VALUE:
  12311. return {};
  12312. default:
  12313. return super.defaultValues(memberName);
  12314. }
  12315. }
  12316. static compareWithDefault(memberName, memberValue) {
  12317. switch (memberName) {
  12318. case ORI_TYPE:
  12319. return (memberValue === EMPTY_STRING);
  12320. case ORI_VALUE:
  12321. return (Object.keys(memberValue).length === 0);
  12322. default:
  12323. return super.defaultValues(memberName);
  12324. }
  12325. }
  12326. static schema(parameters = {}) {
  12327. const names = pvutils.getParametersValue(parameters, "names", {});
  12328. return (new asn1js.Sequence({
  12329. name: (names.blockName || EMPTY_STRING),
  12330. value: [
  12331. new asn1js.ObjectIdentifier({ name: (names.oriType || EMPTY_STRING) }),
  12332. new asn1js.Any({ name: (names.oriValue || EMPTY_STRING) })
  12333. ]
  12334. }));
  12335. }
  12336. fromSchema(schema) {
  12337. pvutils.clearProps(schema, CLEAR_PROPS$o);
  12338. const asn1 = asn1js.compareSchema(schema, schema, OtherRecipientInfo.schema({
  12339. names: {
  12340. oriType: ORI_TYPE,
  12341. oriValue: ORI_VALUE
  12342. }
  12343. }));
  12344. AsnError.assertSchema(asn1, this.className);
  12345. this.oriType = asn1.result.oriType.valueBlock.toString();
  12346. this.oriValue = asn1.result.oriValue;
  12347. }
  12348. toSchema() {
  12349. return (new asn1js.Sequence({
  12350. value: [
  12351. new asn1js.ObjectIdentifier({ value: this.oriType }),
  12352. this.oriValue
  12353. ]
  12354. }));
  12355. }
  12356. toJSON() {
  12357. const res = {
  12358. oriType: this.oriType
  12359. };
  12360. if (!OtherRecipientInfo.compareWithDefault(ORI_VALUE, this.oriValue)) {
  12361. res.oriValue = this.oriValue.toJSON();
  12362. }
  12363. return res;
  12364. }
  12365. }
  12366. OtherRecipientInfo.CLASS_NAME = "OtherRecipientInfo";
  12367. const VARIANT = "variant";
  12368. const VALUE = "value";
  12369. const CLEAR_PROPS$n = [
  12370. "blockName"
  12371. ];
  12372. class RecipientInfo extends PkiObject {
  12373. constructor(parameters = {}) {
  12374. super();
  12375. this.variant = pvutils.getParametersValue(parameters, VARIANT, RecipientInfo.defaultValues(VARIANT));
  12376. if (VALUE in parameters) {
  12377. this.value = pvutils.getParametersValue(parameters, VALUE, RecipientInfo.defaultValues(VALUE));
  12378. }
  12379. if (parameters.schema) {
  12380. this.fromSchema(parameters.schema);
  12381. }
  12382. }
  12383. static defaultValues(memberName) {
  12384. switch (memberName) {
  12385. case VARIANT:
  12386. return (-1);
  12387. case VALUE:
  12388. return {};
  12389. default:
  12390. return super.defaultValues(memberName);
  12391. }
  12392. }
  12393. static compareWithDefault(memberName, memberValue) {
  12394. switch (memberName) {
  12395. case VARIANT:
  12396. return (memberValue === RecipientInfo.defaultValues(memberName));
  12397. case VALUE:
  12398. return (Object.keys(memberValue).length === 0);
  12399. default:
  12400. return super.defaultValues(memberName);
  12401. }
  12402. }
  12403. static schema(parameters = {}) {
  12404. const names = pvutils.getParametersValue(parameters, "names", {});
  12405. return (new asn1js.Choice({
  12406. value: [
  12407. KeyTransRecipientInfo.schema({
  12408. names: {
  12409. blockName: (names.blockName || EMPTY_STRING)
  12410. }
  12411. }),
  12412. new asn1js.Constructed({
  12413. name: (names.blockName || EMPTY_STRING),
  12414. idBlock: {
  12415. tagClass: 3,
  12416. tagNumber: 1
  12417. },
  12418. value: KeyAgreeRecipientInfo.schema().valueBlock.value
  12419. }),
  12420. new asn1js.Constructed({
  12421. name: (names.blockName || EMPTY_STRING),
  12422. idBlock: {
  12423. tagClass: 3,
  12424. tagNumber: 2
  12425. },
  12426. value: KEKRecipientInfo.schema().valueBlock.value
  12427. }),
  12428. new asn1js.Constructed({
  12429. name: (names.blockName || EMPTY_STRING),
  12430. idBlock: {
  12431. tagClass: 3,
  12432. tagNumber: 3
  12433. },
  12434. value: PasswordRecipientinfo.schema().valueBlock.value
  12435. }),
  12436. new asn1js.Constructed({
  12437. name: (names.blockName || EMPTY_STRING),
  12438. idBlock: {
  12439. tagClass: 3,
  12440. tagNumber: 4
  12441. },
  12442. value: OtherRecipientInfo.schema().valueBlock.value
  12443. })
  12444. ]
  12445. }));
  12446. }
  12447. fromSchema(schema) {
  12448. pvutils.clearProps(schema, CLEAR_PROPS$n);
  12449. const asn1 = asn1js.compareSchema(schema, schema, RecipientInfo.schema({
  12450. names: {
  12451. blockName: "blockName"
  12452. }
  12453. }));
  12454. AsnError.assertSchema(asn1, this.className);
  12455. if (asn1.result.blockName.idBlock.tagClass === 1) {
  12456. this.variant = 1;
  12457. this.value = new KeyTransRecipientInfo({ schema: asn1.result.blockName });
  12458. }
  12459. else {
  12460. const blockSequence = new asn1js.Sequence({
  12461. value: asn1.result.blockName.valueBlock.value
  12462. });
  12463. switch (asn1.result.blockName.idBlock.tagNumber) {
  12464. case 1:
  12465. this.variant = 2;
  12466. this.value = new KeyAgreeRecipientInfo({ schema: blockSequence });
  12467. break;
  12468. case 2:
  12469. this.variant = 3;
  12470. this.value = new KEKRecipientInfo({ schema: blockSequence });
  12471. break;
  12472. case 3:
  12473. this.variant = 4;
  12474. this.value = new PasswordRecipientinfo({ schema: blockSequence });
  12475. break;
  12476. case 4:
  12477. this.variant = 5;
  12478. this.value = new OtherRecipientInfo({ schema: blockSequence });
  12479. break;
  12480. default:
  12481. throw new Error("Incorrect structure of RecipientInfo block");
  12482. }
  12483. }
  12484. }
  12485. toSchema() {
  12486. ParameterError.assertEmpty(this.value, "value", "RecipientInfo");
  12487. const _schema = this.value.toSchema();
  12488. switch (this.variant) {
  12489. case 1:
  12490. return _schema;
  12491. case 2:
  12492. case 3:
  12493. case 4:
  12494. _schema.idBlock.tagClass = 3;
  12495. _schema.idBlock.tagNumber = (this.variant - 1);
  12496. return _schema;
  12497. default:
  12498. return new asn1js.Any();
  12499. }
  12500. }
  12501. toJSON() {
  12502. const res = {
  12503. variant: this.variant
  12504. };
  12505. if (this.value && (this.variant >= 1) && (this.variant <= 4)) {
  12506. res.value = this.value.toJSON();
  12507. }
  12508. return res;
  12509. }
  12510. }
  12511. RecipientInfo.CLASS_NAME = "RecipientInfo";
  12512. const HASH_ALGORITHM$2 = "hashAlgorithm";
  12513. const MASK_GEN_ALGORITHM = "maskGenAlgorithm";
  12514. const P_SOURCE_ALGORITHM = "pSourceAlgorithm";
  12515. const CLEAR_PROPS$m = [
  12516. HASH_ALGORITHM$2,
  12517. MASK_GEN_ALGORITHM,
  12518. P_SOURCE_ALGORITHM
  12519. ];
  12520. class RSAESOAEPParams extends PkiObject {
  12521. constructor(parameters = {}) {
  12522. super();
  12523. this.hashAlgorithm = pvutils.getParametersValue(parameters, HASH_ALGORITHM$2, RSAESOAEPParams.defaultValues(HASH_ALGORITHM$2));
  12524. this.maskGenAlgorithm = pvutils.getParametersValue(parameters, MASK_GEN_ALGORITHM, RSAESOAEPParams.defaultValues(MASK_GEN_ALGORITHM));
  12525. this.pSourceAlgorithm = pvutils.getParametersValue(parameters, P_SOURCE_ALGORITHM, RSAESOAEPParams.defaultValues(P_SOURCE_ALGORITHM));
  12526. if (parameters.schema) {
  12527. this.fromSchema(parameters.schema);
  12528. }
  12529. }
  12530. static defaultValues(memberName) {
  12531. switch (memberName) {
  12532. case HASH_ALGORITHM$2:
  12533. return new AlgorithmIdentifier({
  12534. algorithmId: "1.3.14.3.2.26",
  12535. algorithmParams: new asn1js.Null()
  12536. });
  12537. case MASK_GEN_ALGORITHM:
  12538. return new AlgorithmIdentifier({
  12539. algorithmId: "1.2.840.113549.1.1.8",
  12540. algorithmParams: (new AlgorithmIdentifier({
  12541. algorithmId: "1.3.14.3.2.26",
  12542. algorithmParams: new asn1js.Null()
  12543. })).toSchema()
  12544. });
  12545. case P_SOURCE_ALGORITHM:
  12546. return new AlgorithmIdentifier({
  12547. algorithmId: "1.2.840.113549.1.1.9",
  12548. algorithmParams: new asn1js.OctetString({ valueHex: (new Uint8Array([0xda, 0x39, 0xa3, 0xee, 0x5e, 0x6b, 0x4b, 0x0d, 0x32, 0x55, 0xbf, 0xef, 0x95, 0x60, 0x18, 0x90, 0xaf, 0xd8, 0x07, 0x09])).buffer })
  12549. });
  12550. default:
  12551. return super.defaultValues(memberName);
  12552. }
  12553. }
  12554. static schema(parameters = {}) {
  12555. const names = pvutils.getParametersValue(parameters, "names", {});
  12556. return (new asn1js.Sequence({
  12557. name: (names.blockName || EMPTY_STRING),
  12558. value: [
  12559. new asn1js.Constructed({
  12560. idBlock: {
  12561. tagClass: 3,
  12562. tagNumber: 0
  12563. },
  12564. optional: true,
  12565. value: [AlgorithmIdentifier.schema(names.hashAlgorithm || {})]
  12566. }),
  12567. new asn1js.Constructed({
  12568. idBlock: {
  12569. tagClass: 3,
  12570. tagNumber: 1
  12571. },
  12572. optional: true,
  12573. value: [AlgorithmIdentifier.schema(names.maskGenAlgorithm || {})]
  12574. }),
  12575. new asn1js.Constructed({
  12576. idBlock: {
  12577. tagClass: 3,
  12578. tagNumber: 2
  12579. },
  12580. optional: true,
  12581. value: [AlgorithmIdentifier.schema(names.pSourceAlgorithm || {})]
  12582. })
  12583. ]
  12584. }));
  12585. }
  12586. fromSchema(schema) {
  12587. pvutils.clearProps(schema, CLEAR_PROPS$m);
  12588. const asn1 = asn1js.compareSchema(schema, schema, RSAESOAEPParams.schema({
  12589. names: {
  12590. hashAlgorithm: {
  12591. names: {
  12592. blockName: HASH_ALGORITHM$2
  12593. }
  12594. },
  12595. maskGenAlgorithm: {
  12596. names: {
  12597. blockName: MASK_GEN_ALGORITHM
  12598. }
  12599. },
  12600. pSourceAlgorithm: {
  12601. names: {
  12602. blockName: P_SOURCE_ALGORITHM
  12603. }
  12604. }
  12605. }
  12606. }));
  12607. AsnError.assertSchema(asn1, this.className);
  12608. if (HASH_ALGORITHM$2 in asn1.result)
  12609. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  12610. if (MASK_GEN_ALGORITHM in asn1.result)
  12611. this.maskGenAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.maskGenAlgorithm });
  12612. if (P_SOURCE_ALGORITHM in asn1.result)
  12613. this.pSourceAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.pSourceAlgorithm });
  12614. }
  12615. toSchema() {
  12616. const outputArray = [];
  12617. if (!this.hashAlgorithm.isEqual(RSAESOAEPParams.defaultValues(HASH_ALGORITHM$2))) {
  12618. outputArray.push(new asn1js.Constructed({
  12619. idBlock: {
  12620. tagClass: 3,
  12621. tagNumber: 0
  12622. },
  12623. value: [this.hashAlgorithm.toSchema()]
  12624. }));
  12625. }
  12626. if (!this.maskGenAlgorithm.isEqual(RSAESOAEPParams.defaultValues(MASK_GEN_ALGORITHM))) {
  12627. outputArray.push(new asn1js.Constructed({
  12628. idBlock: {
  12629. tagClass: 3,
  12630. tagNumber: 1
  12631. },
  12632. value: [this.maskGenAlgorithm.toSchema()]
  12633. }));
  12634. }
  12635. if (!this.pSourceAlgorithm.isEqual(RSAESOAEPParams.defaultValues(P_SOURCE_ALGORITHM))) {
  12636. outputArray.push(new asn1js.Constructed({
  12637. idBlock: {
  12638. tagClass: 3,
  12639. tagNumber: 2
  12640. },
  12641. value: [this.pSourceAlgorithm.toSchema()]
  12642. }));
  12643. }
  12644. return (new asn1js.Sequence({
  12645. value: outputArray
  12646. }));
  12647. }
  12648. toJSON() {
  12649. const res = {};
  12650. if (!this.hashAlgorithm.isEqual(RSAESOAEPParams.defaultValues(HASH_ALGORITHM$2))) {
  12651. res.hashAlgorithm = this.hashAlgorithm.toJSON();
  12652. }
  12653. if (!this.maskGenAlgorithm.isEqual(RSAESOAEPParams.defaultValues(MASK_GEN_ALGORITHM))) {
  12654. res.maskGenAlgorithm = this.maskGenAlgorithm.toJSON();
  12655. }
  12656. if (!this.pSourceAlgorithm.isEqual(RSAESOAEPParams.defaultValues(P_SOURCE_ALGORITHM))) {
  12657. res.pSourceAlgorithm = this.pSourceAlgorithm.toJSON();
  12658. }
  12659. return res;
  12660. }
  12661. }
  12662. RSAESOAEPParams.CLASS_NAME = "RSAESOAEPParams";
  12663. const KEY_INFO = "keyInfo";
  12664. const ENTITY_U_INFO = "entityUInfo";
  12665. const SUPP_PUB_INFO = "suppPubInfo";
  12666. const CLEAR_PROPS$l = [
  12667. KEY_INFO,
  12668. ENTITY_U_INFO,
  12669. SUPP_PUB_INFO
  12670. ];
  12671. class ECCCMSSharedInfo extends PkiObject {
  12672. constructor(parameters = {}) {
  12673. super();
  12674. this.keyInfo = pvutils.getParametersValue(parameters, KEY_INFO, ECCCMSSharedInfo.defaultValues(KEY_INFO));
  12675. if (ENTITY_U_INFO in parameters) {
  12676. this.entityUInfo = pvutils.getParametersValue(parameters, ENTITY_U_INFO, ECCCMSSharedInfo.defaultValues(ENTITY_U_INFO));
  12677. }
  12678. this.suppPubInfo = pvutils.getParametersValue(parameters, SUPP_PUB_INFO, ECCCMSSharedInfo.defaultValues(SUPP_PUB_INFO));
  12679. if (parameters.schema) {
  12680. this.fromSchema(parameters.schema);
  12681. }
  12682. }
  12683. static defaultValues(memberName) {
  12684. switch (memberName) {
  12685. case KEY_INFO:
  12686. return new AlgorithmIdentifier();
  12687. case ENTITY_U_INFO:
  12688. return new asn1js.OctetString();
  12689. case SUPP_PUB_INFO:
  12690. return new asn1js.OctetString();
  12691. default:
  12692. return super.defaultValues(memberName);
  12693. }
  12694. }
  12695. static compareWithDefault(memberName, memberValue) {
  12696. switch (memberName) {
  12697. case KEY_INFO:
  12698. case ENTITY_U_INFO:
  12699. case SUPP_PUB_INFO:
  12700. return (memberValue.isEqual(ECCCMSSharedInfo.defaultValues(memberName)));
  12701. default:
  12702. return super.defaultValues(memberName);
  12703. }
  12704. }
  12705. static schema(parameters = {}) {
  12706. const names = pvutils.getParametersValue(parameters, "names", {});
  12707. return (new asn1js.Sequence({
  12708. name: (names.blockName || EMPTY_STRING),
  12709. value: [
  12710. AlgorithmIdentifier.schema(names.keyInfo || {}),
  12711. new asn1js.Constructed({
  12712. name: (names.entityUInfo || EMPTY_STRING),
  12713. idBlock: {
  12714. tagClass: 3,
  12715. tagNumber: 0
  12716. },
  12717. optional: true,
  12718. value: [new asn1js.OctetString()]
  12719. }),
  12720. new asn1js.Constructed({
  12721. name: (names.suppPubInfo || EMPTY_STRING),
  12722. idBlock: {
  12723. tagClass: 3,
  12724. tagNumber: 2
  12725. },
  12726. value: [new asn1js.OctetString()]
  12727. })
  12728. ]
  12729. }));
  12730. }
  12731. fromSchema(schema) {
  12732. pvutils.clearProps(schema, CLEAR_PROPS$l);
  12733. const asn1 = asn1js.compareSchema(schema, schema, ECCCMSSharedInfo.schema({
  12734. names: {
  12735. keyInfo: {
  12736. names: {
  12737. blockName: KEY_INFO
  12738. }
  12739. },
  12740. entityUInfo: ENTITY_U_INFO,
  12741. suppPubInfo: SUPP_PUB_INFO
  12742. }
  12743. }));
  12744. AsnError.assertSchema(asn1, this.className);
  12745. this.keyInfo = new AlgorithmIdentifier({ schema: asn1.result.keyInfo });
  12746. if (ENTITY_U_INFO in asn1.result)
  12747. this.entityUInfo = asn1.result.entityUInfo.valueBlock.value[0];
  12748. this.suppPubInfo = asn1.result.suppPubInfo.valueBlock.value[0];
  12749. }
  12750. toSchema() {
  12751. const outputArray = [];
  12752. outputArray.push(this.keyInfo.toSchema());
  12753. if (this.entityUInfo) {
  12754. outputArray.push(new asn1js.Constructed({
  12755. idBlock: {
  12756. tagClass: 3,
  12757. tagNumber: 0
  12758. },
  12759. value: [this.entityUInfo]
  12760. }));
  12761. }
  12762. outputArray.push(new asn1js.Constructed({
  12763. idBlock: {
  12764. tagClass: 3,
  12765. tagNumber: 2
  12766. },
  12767. value: [this.suppPubInfo]
  12768. }));
  12769. return new asn1js.Sequence({
  12770. value: outputArray
  12771. });
  12772. }
  12773. toJSON() {
  12774. const res = {
  12775. keyInfo: this.keyInfo.toJSON(),
  12776. suppPubInfo: this.suppPubInfo.toJSON(),
  12777. };
  12778. if (this.entityUInfo) {
  12779. res.entityUInfo = this.entityUInfo.toJSON();
  12780. }
  12781. return res;
  12782. }
  12783. }
  12784. ECCCMSSharedInfo.CLASS_NAME = "ECCCMSSharedInfo";
  12785. const VERSION$8 = "version";
  12786. const ORIGINATOR_INFO = "originatorInfo";
  12787. const RECIPIENT_INFOS = "recipientInfos";
  12788. const ENCRYPTED_CONTENT_INFO = "encryptedContentInfo";
  12789. const UNPROTECTED_ATTRS = "unprotectedAttrs";
  12790. const CLEAR_PROPS$k = [
  12791. VERSION$8,
  12792. ORIGINATOR_INFO,
  12793. RECIPIENT_INFOS,
  12794. ENCRYPTED_CONTENT_INFO,
  12795. UNPROTECTED_ATTRS
  12796. ];
  12797. const defaultEncryptionParams = {
  12798. kdfAlgorithm: "SHA-512",
  12799. kekEncryptionLength: 256
  12800. };
  12801. const curveLengthByName = {
  12802. "P-256": 256,
  12803. "P-384": 384,
  12804. "P-521": 528
  12805. };
  12806. class EnvelopedData extends PkiObject {
  12807. constructor(parameters = {}) {
  12808. super();
  12809. this.version = pvutils.getParametersValue(parameters, VERSION$8, EnvelopedData.defaultValues(VERSION$8));
  12810. if (ORIGINATOR_INFO in parameters) {
  12811. this.originatorInfo = pvutils.getParametersValue(parameters, ORIGINATOR_INFO, EnvelopedData.defaultValues(ORIGINATOR_INFO));
  12812. }
  12813. this.recipientInfos = pvutils.getParametersValue(parameters, RECIPIENT_INFOS, EnvelopedData.defaultValues(RECIPIENT_INFOS));
  12814. this.encryptedContentInfo = pvutils.getParametersValue(parameters, ENCRYPTED_CONTENT_INFO, EnvelopedData.defaultValues(ENCRYPTED_CONTENT_INFO));
  12815. if (UNPROTECTED_ATTRS in parameters) {
  12816. this.unprotectedAttrs = pvutils.getParametersValue(parameters, UNPROTECTED_ATTRS, EnvelopedData.defaultValues(UNPROTECTED_ATTRS));
  12817. }
  12818. this.policy = {
  12819. disableSplit: !!parameters.disableSplit,
  12820. };
  12821. if (parameters.schema) {
  12822. this.fromSchema(parameters.schema);
  12823. }
  12824. }
  12825. static defaultValues(memberName) {
  12826. switch (memberName) {
  12827. case VERSION$8:
  12828. return 0;
  12829. case ORIGINATOR_INFO:
  12830. return new OriginatorInfo();
  12831. case RECIPIENT_INFOS:
  12832. return [];
  12833. case ENCRYPTED_CONTENT_INFO:
  12834. return new EncryptedContentInfo();
  12835. case UNPROTECTED_ATTRS:
  12836. return [];
  12837. default:
  12838. return super.defaultValues(memberName);
  12839. }
  12840. }
  12841. static compareWithDefault(memberName, memberValue) {
  12842. switch (memberName) {
  12843. case VERSION$8:
  12844. return (memberValue === EnvelopedData.defaultValues(memberName));
  12845. case ORIGINATOR_INFO:
  12846. return ((memberValue.certs.certificates.length === 0) && (memberValue.crls.crls.length === 0));
  12847. case RECIPIENT_INFOS:
  12848. case UNPROTECTED_ATTRS:
  12849. return (memberValue.length === 0);
  12850. case ENCRYPTED_CONTENT_INFO:
  12851. return ((EncryptedContentInfo.compareWithDefault("contentType", memberValue.contentType)) &&
  12852. (EncryptedContentInfo.compareWithDefault("contentEncryptionAlgorithm", memberValue.contentEncryptionAlgorithm) &&
  12853. (EncryptedContentInfo.compareWithDefault("encryptedContent", memberValue.encryptedContent))));
  12854. default:
  12855. return super.defaultValues(memberName);
  12856. }
  12857. }
  12858. static schema(parameters = {}) {
  12859. const names = pvutils.getParametersValue(parameters, "names", {});
  12860. return (new asn1js.Sequence({
  12861. name: (names.blockName || EMPTY_STRING),
  12862. value: [
  12863. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  12864. new asn1js.Constructed({
  12865. name: (names.originatorInfo || EMPTY_STRING),
  12866. optional: true,
  12867. idBlock: {
  12868. tagClass: 3,
  12869. tagNumber: 0
  12870. },
  12871. value: OriginatorInfo.schema().valueBlock.value
  12872. }),
  12873. new asn1js.Set({
  12874. value: [
  12875. new asn1js.Repeated({
  12876. name: (names.recipientInfos || EMPTY_STRING),
  12877. value: RecipientInfo.schema()
  12878. })
  12879. ]
  12880. }),
  12881. EncryptedContentInfo.schema(names.encryptedContentInfo || {}),
  12882. new asn1js.Constructed({
  12883. optional: true,
  12884. idBlock: {
  12885. tagClass: 3,
  12886. tagNumber: 1
  12887. },
  12888. value: [
  12889. new asn1js.Repeated({
  12890. name: (names.unprotectedAttrs || EMPTY_STRING),
  12891. value: Attribute.schema()
  12892. })
  12893. ]
  12894. })
  12895. ]
  12896. }));
  12897. }
  12898. fromSchema(schema) {
  12899. pvutils.clearProps(schema, CLEAR_PROPS$k);
  12900. const asn1 = asn1js.compareSchema(schema, schema, EnvelopedData.schema({
  12901. names: {
  12902. version: VERSION$8,
  12903. originatorInfo: ORIGINATOR_INFO,
  12904. recipientInfos: RECIPIENT_INFOS,
  12905. encryptedContentInfo: {
  12906. names: {
  12907. blockName: ENCRYPTED_CONTENT_INFO
  12908. }
  12909. },
  12910. unprotectedAttrs: UNPROTECTED_ATTRS
  12911. }
  12912. }));
  12913. AsnError.assertSchema(asn1, this.className);
  12914. this.version = asn1.result.version.valueBlock.valueDec;
  12915. if (ORIGINATOR_INFO in asn1.result) {
  12916. this.originatorInfo = new OriginatorInfo({
  12917. schema: new asn1js.Sequence({
  12918. value: asn1.result.originatorInfo.valueBlock.value
  12919. })
  12920. });
  12921. }
  12922. this.recipientInfos = Array.from(asn1.result.recipientInfos, o => new RecipientInfo({ schema: o }));
  12923. this.encryptedContentInfo = new EncryptedContentInfo({ schema: asn1.result.encryptedContentInfo });
  12924. if (UNPROTECTED_ATTRS in asn1.result)
  12925. this.unprotectedAttrs = Array.from(asn1.result.unprotectedAttrs, o => new Attribute({ schema: o }));
  12926. }
  12927. toSchema() {
  12928. const outputArray = [];
  12929. outputArray.push(new asn1js.Integer({ value: this.version }));
  12930. if (this.originatorInfo) {
  12931. outputArray.push(new asn1js.Constructed({
  12932. optional: true,
  12933. idBlock: {
  12934. tagClass: 3,
  12935. tagNumber: 0
  12936. },
  12937. value: this.originatorInfo.toSchema().valueBlock.value
  12938. }));
  12939. }
  12940. outputArray.push(new asn1js.Set({
  12941. value: Array.from(this.recipientInfos, o => o.toSchema())
  12942. }));
  12943. outputArray.push(this.encryptedContentInfo.toSchema());
  12944. if (this.unprotectedAttrs) {
  12945. outputArray.push(new asn1js.Constructed({
  12946. optional: true,
  12947. idBlock: {
  12948. tagClass: 3,
  12949. tagNumber: 1
  12950. },
  12951. value: Array.from(this.unprotectedAttrs, o => o.toSchema())
  12952. }));
  12953. }
  12954. return (new asn1js.Sequence({
  12955. value: outputArray
  12956. }));
  12957. }
  12958. toJSON() {
  12959. const res = {
  12960. version: this.version,
  12961. recipientInfos: Array.from(this.recipientInfos, o => o.toJSON()),
  12962. encryptedContentInfo: this.encryptedContentInfo.toJSON(),
  12963. };
  12964. if (this.originatorInfo)
  12965. res.originatorInfo = this.originatorInfo.toJSON();
  12966. if (this.unprotectedAttrs)
  12967. res.unprotectedAttrs = Array.from(this.unprotectedAttrs, o => o.toJSON());
  12968. return res;
  12969. }
  12970. addRecipientByCertificate(certificate, parameters, variant, crypto = getCrypto(true)) {
  12971. const encryptionParameters = Object.assign({ useOAEP: true, oaepHashAlgorithm: "SHA-512" }, defaultEncryptionParams, parameters || {});
  12972. if (certificate.subjectPublicKeyInfo.algorithm.algorithmId.indexOf("1.2.840.113549") !== (-1))
  12973. variant = 1;
  12974. else {
  12975. if (certificate.subjectPublicKeyInfo.algorithm.algorithmId.indexOf("1.2.840.10045") !== (-1))
  12976. variant = 2;
  12977. else
  12978. throw new Error(`Unknown type of certificate's public key: ${certificate.subjectPublicKeyInfo.algorithm.algorithmId}`);
  12979. }
  12980. switch (variant) {
  12981. case 1:
  12982. {
  12983. let algorithmId;
  12984. let algorithmParams;
  12985. if (encryptionParameters.useOAEP === true) {
  12986. algorithmId = crypto.getOIDByAlgorithm({
  12987. name: "RSA-OAEP"
  12988. }, true, "keyEncryptionAlgorithm");
  12989. const hashOID = crypto.getOIDByAlgorithm({
  12990. name: encryptionParameters.oaepHashAlgorithm
  12991. }, true, "RSAES-OAEP-params");
  12992. const hashAlgorithm = new AlgorithmIdentifier({
  12993. algorithmId: hashOID,
  12994. algorithmParams: new asn1js.Null()
  12995. });
  12996. const rsaOAEPParams = new RSAESOAEPParams({
  12997. hashAlgorithm,
  12998. maskGenAlgorithm: new AlgorithmIdentifier({
  12999. algorithmId: "1.2.840.113549.1.1.8",
  13000. algorithmParams: hashAlgorithm.toSchema()
  13001. })
  13002. });
  13003. algorithmParams = rsaOAEPParams.toSchema();
  13004. }
  13005. else {
  13006. algorithmId = crypto.getOIDByAlgorithm({
  13007. name: "RSAES-PKCS1-v1_5"
  13008. });
  13009. if (algorithmId === EMPTY_STRING)
  13010. throw new Error("Can not find OID for RSAES-PKCS1-v1_5");
  13011. algorithmParams = new asn1js.Null();
  13012. }
  13013. const keyInfo = new KeyTransRecipientInfo({
  13014. version: 0,
  13015. rid: new IssuerAndSerialNumber({
  13016. issuer: certificate.issuer,
  13017. serialNumber: certificate.serialNumber
  13018. }),
  13019. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13020. algorithmId,
  13021. algorithmParams
  13022. }),
  13023. recipientCertificate: certificate,
  13024. });
  13025. this.recipientInfos.push(new RecipientInfo({
  13026. variant: 1,
  13027. value: keyInfo
  13028. }));
  13029. }
  13030. break;
  13031. case 2:
  13032. {
  13033. const recipientIdentifier = new KeyAgreeRecipientIdentifier({
  13034. variant: 1,
  13035. value: new IssuerAndSerialNumber({
  13036. issuer: certificate.issuer,
  13037. serialNumber: certificate.serialNumber
  13038. })
  13039. });
  13040. this._addKeyAgreeRecipientInfo(recipientIdentifier, encryptionParameters, { recipientCertificate: certificate }, crypto);
  13041. }
  13042. break;
  13043. default:
  13044. throw new Error(`Unknown "variant" value: ${variant}`);
  13045. }
  13046. return true;
  13047. }
  13048. addRecipientByPreDefinedData(preDefinedData, parameters = {}, variant, crypto = getCrypto(true)) {
  13049. ArgumentError.assert(preDefinedData, "preDefinedData", "ArrayBuffer");
  13050. if (!preDefinedData.byteLength) {
  13051. throw new Error("Pre-defined data could have zero length");
  13052. }
  13053. if (!parameters.keyIdentifier) {
  13054. const keyIdentifierBuffer = new ArrayBuffer(16);
  13055. const keyIdentifierView = new Uint8Array(keyIdentifierBuffer);
  13056. crypto.getRandomValues(keyIdentifierView);
  13057. parameters.keyIdentifier = keyIdentifierBuffer;
  13058. }
  13059. if (!parameters.hmacHashAlgorithm)
  13060. parameters.hmacHashAlgorithm = "SHA-512";
  13061. if (parameters.iterationCount === undefined) {
  13062. parameters.iterationCount = 2048;
  13063. }
  13064. if (!parameters.keyEncryptionAlgorithm) {
  13065. parameters.keyEncryptionAlgorithm = {
  13066. name: "AES-KW",
  13067. length: 256
  13068. };
  13069. }
  13070. if (!parameters.keyEncryptionAlgorithmParams)
  13071. parameters.keyEncryptionAlgorithmParams = new asn1js.Null();
  13072. switch (variant) {
  13073. case 1:
  13074. {
  13075. const kekOID = crypto.getOIDByAlgorithm(parameters.keyEncryptionAlgorithm, true, "keyEncryptionAlgorithm");
  13076. const keyInfo = new KEKRecipientInfo({
  13077. version: 4,
  13078. kekid: new KEKIdentifier({
  13079. keyIdentifier: new asn1js.OctetString({ valueHex: parameters.keyIdentifier })
  13080. }),
  13081. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13082. algorithmId: kekOID,
  13083. algorithmParams: parameters.keyEncryptionAlgorithmParams
  13084. }),
  13085. preDefinedKEK: preDefinedData
  13086. });
  13087. this.recipientInfos.push(new RecipientInfo({
  13088. variant: 3,
  13089. value: keyInfo
  13090. }));
  13091. }
  13092. break;
  13093. case 2:
  13094. {
  13095. const pbkdf2OID = crypto.getOIDByAlgorithm({ name: "PBKDF2" }, true, "keyDerivationAlgorithm");
  13096. const saltBuffer = new ArrayBuffer(64);
  13097. const saltView = new Uint8Array(saltBuffer);
  13098. crypto.getRandomValues(saltView);
  13099. const hmacOID = crypto.getOIDByAlgorithm({
  13100. name: "HMAC",
  13101. hash: {
  13102. name: parameters.hmacHashAlgorithm
  13103. }
  13104. }, true, "hmacHashAlgorithm");
  13105. const pbkdf2Params = new PBKDF2Params({
  13106. salt: new asn1js.OctetString({ valueHex: saltBuffer }),
  13107. iterationCount: parameters.iterationCount,
  13108. prf: new AlgorithmIdentifier({
  13109. algorithmId: hmacOID,
  13110. algorithmParams: new asn1js.Null()
  13111. })
  13112. });
  13113. const kekOID = crypto.getOIDByAlgorithm(parameters.keyEncryptionAlgorithm, true, "keyEncryptionAlgorithm");
  13114. const keyInfo = new PasswordRecipientinfo({
  13115. version: 0,
  13116. keyDerivationAlgorithm: new AlgorithmIdentifier({
  13117. algorithmId: pbkdf2OID,
  13118. algorithmParams: pbkdf2Params.toSchema()
  13119. }),
  13120. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13121. algorithmId: kekOID,
  13122. algorithmParams: parameters.keyEncryptionAlgorithmParams
  13123. }),
  13124. password: preDefinedData
  13125. });
  13126. this.recipientInfos.push(new RecipientInfo({
  13127. variant: 4,
  13128. value: keyInfo
  13129. }));
  13130. }
  13131. break;
  13132. default:
  13133. throw new Error(`Unknown value for "variant": ${variant}`);
  13134. }
  13135. }
  13136. addRecipientByKeyIdentifier(key, keyId, parameters, crypto = getCrypto(true)) {
  13137. const encryptionParameters = Object.assign({}, defaultEncryptionParams, parameters || {});
  13138. const recipientIdentifier = new KeyAgreeRecipientIdentifier({
  13139. variant: 2,
  13140. value: new RecipientKeyIdentifier({
  13141. subjectKeyIdentifier: new asn1js.OctetString({ valueHex: keyId }),
  13142. })
  13143. });
  13144. this._addKeyAgreeRecipientInfo(recipientIdentifier, encryptionParameters, { recipientPublicKey: key }, crypto);
  13145. }
  13146. _addKeyAgreeRecipientInfo(recipientIdentifier, encryptionParameters, extraRecipientInfoParams, crypto = getCrypto(true)) {
  13147. const encryptedKey = new RecipientEncryptedKey({
  13148. rid: recipientIdentifier
  13149. });
  13150. const aesKWoid = crypto.getOIDByAlgorithm({
  13151. name: "AES-KW",
  13152. length: encryptionParameters.kekEncryptionLength
  13153. }, true, "keyEncryptionAlgorithm");
  13154. const aesKW = new AlgorithmIdentifier({
  13155. algorithmId: aesKWoid,
  13156. });
  13157. const ecdhOID = crypto.getOIDByAlgorithm({
  13158. name: "ECDH",
  13159. kdf: encryptionParameters.kdfAlgorithm
  13160. }, true, "KeyAgreeRecipientInfo");
  13161. const ukmBuffer = new ArrayBuffer(64);
  13162. const ukmView = new Uint8Array(ukmBuffer);
  13163. crypto.getRandomValues(ukmView);
  13164. const recipientInfoParams = {
  13165. version: 3,
  13166. ukm: new asn1js.OctetString({ valueHex: ukmBuffer }),
  13167. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13168. algorithmId: ecdhOID,
  13169. algorithmParams: aesKW.toSchema()
  13170. }),
  13171. recipientEncryptedKeys: new RecipientEncryptedKeys({
  13172. encryptedKeys: [encryptedKey]
  13173. })
  13174. };
  13175. const keyInfo = new KeyAgreeRecipientInfo(Object.assign(recipientInfoParams, extraRecipientInfoParams));
  13176. this.recipientInfos.push(new RecipientInfo({
  13177. variant: 2,
  13178. value: keyInfo
  13179. }));
  13180. }
  13181. async encrypt(contentEncryptionAlgorithm, contentToEncrypt, crypto = getCrypto(true)) {
  13182. const ivBuffer = new ArrayBuffer(16);
  13183. const ivView = new Uint8Array(ivBuffer);
  13184. crypto.getRandomValues(ivView);
  13185. const contentView = new Uint8Array(contentToEncrypt);
  13186. const contentEncryptionOID = crypto.getOIDByAlgorithm(contentEncryptionAlgorithm, true, "contentEncryptionAlgorithm");
  13187. const sessionKey = await crypto.generateKey(contentEncryptionAlgorithm, true, ["encrypt"]);
  13188. const encryptedContent = await crypto.encrypt({
  13189. name: contentEncryptionAlgorithm.name,
  13190. iv: ivView
  13191. }, sessionKey, contentView);
  13192. const exportedSessionKey = await crypto.exportKey("raw", sessionKey);
  13193. this.version = 2;
  13194. this.encryptedContentInfo = new EncryptedContentInfo({
  13195. disableSplit: this.policy.disableSplit,
  13196. contentType: "1.2.840.113549.1.7.1",
  13197. contentEncryptionAlgorithm: new AlgorithmIdentifier({
  13198. algorithmId: contentEncryptionOID,
  13199. algorithmParams: new asn1js.OctetString({ valueHex: ivBuffer })
  13200. }),
  13201. encryptedContent: new asn1js.OctetString({ valueHex: encryptedContent })
  13202. });
  13203. const SubKeyAgreeRecipientInfo = async (index) => {
  13204. const recipientInfo = this.recipientInfos[index].value;
  13205. let recipientCurve;
  13206. let recipientPublicKey;
  13207. if (recipientInfo.recipientPublicKey) {
  13208. recipientCurve = recipientInfo.recipientPublicKey.algorithm.namedCurve;
  13209. recipientPublicKey = recipientInfo.recipientPublicKey;
  13210. }
  13211. else if (recipientInfo.recipientCertificate) {
  13212. const curveObject = recipientInfo.recipientCertificate.subjectPublicKeyInfo.algorithm.algorithmParams;
  13213. if (curveObject.constructor.blockName() !== asn1js.ObjectIdentifier.blockName())
  13214. throw new Error(`Incorrect "recipientCertificate" for index ${index}`);
  13215. const curveOID = curveObject.valueBlock.toString();
  13216. switch (curveOID) {
  13217. case "1.2.840.10045.3.1.7":
  13218. recipientCurve = "P-256";
  13219. break;
  13220. case "1.3.132.0.34":
  13221. recipientCurve = "P-384";
  13222. break;
  13223. case "1.3.132.0.35":
  13224. recipientCurve = "P-521";
  13225. break;
  13226. default:
  13227. throw new Error(`Incorrect curve OID for index ${index}`);
  13228. }
  13229. recipientPublicKey = await recipientInfo.recipientCertificate.getPublicKey({
  13230. algorithm: {
  13231. algorithm: {
  13232. name: "ECDH",
  13233. namedCurve: recipientCurve
  13234. },
  13235. usages: []
  13236. }
  13237. }, crypto);
  13238. }
  13239. else {
  13240. throw new Error("Unsupported RecipientInfo");
  13241. }
  13242. const recipientCurveLength = curveLengthByName[recipientCurve];
  13243. const ecdhKeys = await crypto.generateKey({ name: "ECDH", namedCurve: recipientCurve }, true, ["deriveBits"]);
  13244. const exportedECDHPublicKey = await crypto.exportKey("spki", ecdhKeys.publicKey);
  13245. const derivedBits = await crypto.deriveBits({
  13246. name: "ECDH",
  13247. public: recipientPublicKey
  13248. }, ecdhKeys.privateKey, recipientCurveLength);
  13249. const aesKWAlgorithm = new AlgorithmIdentifier({ schema: recipientInfo.keyEncryptionAlgorithm.algorithmParams });
  13250. const kwAlgorithm = crypto.getAlgorithmByOID(aesKWAlgorithm.algorithmId, true, "aesKWAlgorithm");
  13251. let kwLength = kwAlgorithm.length;
  13252. const kwLengthBuffer = new ArrayBuffer(4);
  13253. const kwLengthView = new Uint8Array(kwLengthBuffer);
  13254. for (let j = 3; j >= 0; j--) {
  13255. kwLengthView[j] = kwLength;
  13256. kwLength >>= 8;
  13257. }
  13258. const eccInfo = new ECCCMSSharedInfo({
  13259. keyInfo: new AlgorithmIdentifier({
  13260. algorithmId: aesKWAlgorithm.algorithmId
  13261. }),
  13262. entityUInfo: recipientInfo.ukm,
  13263. suppPubInfo: new asn1js.OctetString({ valueHex: kwLengthBuffer })
  13264. });
  13265. const encodedInfo = eccInfo.toSchema().toBER(false);
  13266. const ecdhAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "ecdhAlgorithm");
  13267. const derivedKeyRaw = await kdf(ecdhAlgorithm.kdf, derivedBits, kwAlgorithm.length, encodedInfo, crypto);
  13268. const awsKW = await crypto.importKey("raw", derivedKeyRaw, { name: "AES-KW" }, true, ["wrapKey"]);
  13269. const wrappedKey = await crypto.wrapKey("raw", sessionKey, awsKW, { name: "AES-KW" });
  13270. const originator = new OriginatorIdentifierOrKey();
  13271. originator.variant = 3;
  13272. originator.value = OriginatorPublicKey.fromBER(exportedECDHPublicKey);
  13273. recipientInfo.originator = originator;
  13274. recipientInfo.recipientEncryptedKeys.encryptedKeys[0].encryptedKey = new asn1js.OctetString({ valueHex: wrappedKey });
  13275. return { ecdhPrivateKey: ecdhKeys.privateKey };
  13276. };
  13277. const SubKeyTransRecipientInfo = async (index) => {
  13278. const recipientInfo = this.recipientInfos[index].value;
  13279. const algorithmParameters = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "keyEncryptionAlgorithm");
  13280. if (algorithmParameters.name === "RSA-OAEP") {
  13281. const schema = recipientInfo.keyEncryptionAlgorithm.algorithmParams;
  13282. const rsaOAEPParams = new RSAESOAEPParams({ schema });
  13283. algorithmParameters.hash = crypto.getAlgorithmByOID(rsaOAEPParams.hashAlgorithm.algorithmId);
  13284. if (("name" in algorithmParameters.hash) === false)
  13285. throw new Error(`Incorrect OID for hash algorithm: ${rsaOAEPParams.hashAlgorithm.algorithmId}`);
  13286. }
  13287. try {
  13288. const publicKey = await recipientInfo.recipientCertificate.getPublicKey({
  13289. algorithm: {
  13290. algorithm: algorithmParameters,
  13291. usages: ["encrypt", "wrapKey"]
  13292. }
  13293. }, crypto);
  13294. const encryptedKey = await crypto.encrypt(publicKey.algorithm, publicKey, exportedSessionKey);
  13295. recipientInfo.encryptedKey = new asn1js.OctetString({ valueHex: encryptedKey });
  13296. }
  13297. catch {
  13298. }
  13299. };
  13300. const SubKEKRecipientInfo = async (index) => {
  13301. const recipientInfo = this.recipientInfos[index].value;
  13302. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "kekAlgorithm");
  13303. const kekKey = await crypto.importKey("raw", new Uint8Array(recipientInfo.preDefinedKEK), kekAlgorithm, true, ["wrapKey"]);
  13304. const wrappedKey = await crypto.wrapKey("raw", sessionKey, kekKey, kekAlgorithm);
  13305. recipientInfo.encryptedKey = new asn1js.OctetString({ valueHex: wrappedKey });
  13306. };
  13307. const SubPasswordRecipientinfo = async (index) => {
  13308. const recipientInfo = this.recipientInfos[index].value;
  13309. let pbkdf2Params;
  13310. if (!recipientInfo.keyDerivationAlgorithm)
  13311. throw new Error("Please append encoded \"keyDerivationAlgorithm\"");
  13312. if (!recipientInfo.keyDerivationAlgorithm.algorithmParams)
  13313. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13314. try {
  13315. pbkdf2Params = new PBKDF2Params({ schema: recipientInfo.keyDerivationAlgorithm.algorithmParams });
  13316. }
  13317. catch {
  13318. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13319. }
  13320. const passwordView = new Uint8Array(recipientInfo.password);
  13321. const derivationKey = await crypto.importKey("raw", passwordView, "PBKDF2", false, ["deriveKey"]);
  13322. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "kekAlgorithm");
  13323. let hmacHashAlgorithm = "SHA-1";
  13324. if (pbkdf2Params.prf) {
  13325. const prfAlgorithm = crypto.getAlgorithmByOID(pbkdf2Params.prf.algorithmId, true, "prfAlgorithm");
  13326. hmacHashAlgorithm = prfAlgorithm.hash.name;
  13327. }
  13328. const saltView = new Uint8Array(pbkdf2Params.salt.valueBlock.valueHex);
  13329. const iterations = pbkdf2Params.iterationCount;
  13330. const derivedKey = await crypto.deriveKey({
  13331. name: "PBKDF2",
  13332. hash: {
  13333. name: hmacHashAlgorithm
  13334. },
  13335. salt: saltView,
  13336. iterations
  13337. }, derivationKey, kekAlgorithm, true, ["wrapKey"]);
  13338. const wrappedKey = await crypto.wrapKey("raw", sessionKey, derivedKey, kekAlgorithm);
  13339. recipientInfo.encryptedKey = new asn1js.OctetString({ valueHex: wrappedKey });
  13340. };
  13341. const res = [];
  13342. for (let i = 0; i < this.recipientInfos.length; i++) {
  13343. switch (this.recipientInfos[i].variant) {
  13344. case 1:
  13345. res.push(await SubKeyTransRecipientInfo(i));
  13346. break;
  13347. case 2:
  13348. res.push(await SubKeyAgreeRecipientInfo(i));
  13349. break;
  13350. case 3:
  13351. res.push(await SubKEKRecipientInfo(i));
  13352. break;
  13353. case 4:
  13354. res.push(await SubPasswordRecipientinfo(i));
  13355. break;
  13356. default:
  13357. throw new Error(`Unknown recipient type in array with index ${i}`);
  13358. }
  13359. }
  13360. return res;
  13361. }
  13362. async decrypt(recipientIndex, parameters, crypto = getCrypto(true)) {
  13363. const decryptionParameters = parameters || {};
  13364. if ((recipientIndex + 1) > this.recipientInfos.length) {
  13365. throw new Error(`Maximum value for "index" is: ${this.recipientInfos.length - 1}`);
  13366. }
  13367. const SubKeyAgreeRecipientInfo = async (index) => {
  13368. const recipientInfo = this.recipientInfos[index].value;
  13369. let curveOID;
  13370. let recipientCurve;
  13371. let recipientCurveLength;
  13372. const originator = recipientInfo.originator;
  13373. if (decryptionParameters.recipientCertificate) {
  13374. const curveObject = decryptionParameters.recipientCertificate.subjectPublicKeyInfo.algorithm.algorithmParams;
  13375. if (curveObject.constructor.blockName() !== asn1js.ObjectIdentifier.blockName()) {
  13376. throw new Error(`Incorrect "recipientCertificate" for index ${index}`);
  13377. }
  13378. curveOID = curveObject.valueBlock.toString();
  13379. }
  13380. else if (originator.value.algorithm.algorithmParams) {
  13381. const curveObject = originator.value.algorithm.algorithmParams;
  13382. if (curveObject.constructor.blockName() !== asn1js.ObjectIdentifier.blockName()) {
  13383. throw new Error(`Incorrect originator for index ${index}`);
  13384. }
  13385. curveOID = curveObject.valueBlock.toString();
  13386. }
  13387. else {
  13388. throw new Error("Parameter \"recipientCertificate\" is mandatory for \"KeyAgreeRecipientInfo\" if algorithm params are missing from originator");
  13389. }
  13390. if (!decryptionParameters.recipientPrivateKey)
  13391. throw new Error("Parameter \"recipientPrivateKey\" is mandatory for \"KeyAgreeRecipientInfo\"");
  13392. switch (curveOID) {
  13393. case "1.2.840.10045.3.1.7":
  13394. recipientCurve = "P-256";
  13395. recipientCurveLength = 256;
  13396. break;
  13397. case "1.3.132.0.34":
  13398. recipientCurve = "P-384";
  13399. recipientCurveLength = 384;
  13400. break;
  13401. case "1.3.132.0.35":
  13402. recipientCurve = "P-521";
  13403. recipientCurveLength = 528;
  13404. break;
  13405. default:
  13406. throw new Error(`Incorrect curve OID for index ${index}`);
  13407. }
  13408. let ecdhPrivateKey;
  13409. let keyCrypto = crypto;
  13410. if (BufferSourceConverter.isBufferSource(decryptionParameters.recipientPrivateKey)) {
  13411. ecdhPrivateKey = await crypto.importKey("pkcs8", decryptionParameters.recipientPrivateKey, {
  13412. name: "ECDH",
  13413. namedCurve: recipientCurve
  13414. }, true, ["deriveBits"]);
  13415. }
  13416. else {
  13417. ecdhPrivateKey = decryptionParameters.recipientPrivateKey;
  13418. if ("crypto" in decryptionParameters && decryptionParameters.crypto) {
  13419. keyCrypto = decryptionParameters.crypto.subtle;
  13420. }
  13421. }
  13422. if (("algorithmParams" in originator.value.algorithm) === false)
  13423. originator.value.algorithm.algorithmParams = new asn1js.ObjectIdentifier({ value: curveOID });
  13424. const buffer = originator.value.toSchema().toBER(false);
  13425. const ecdhPublicKey = await crypto.importKey("spki", buffer, {
  13426. name: "ECDH",
  13427. namedCurve: recipientCurve
  13428. }, true, []);
  13429. const sharedSecret = await keyCrypto.deriveBits({
  13430. name: "ECDH",
  13431. public: ecdhPublicKey
  13432. }, ecdhPrivateKey, recipientCurveLength);
  13433. async function applyKDF(includeAlgorithmParams) {
  13434. includeAlgorithmParams = includeAlgorithmParams || false;
  13435. const aesKWAlgorithm = new AlgorithmIdentifier({ schema: recipientInfo.keyEncryptionAlgorithm.algorithmParams });
  13436. const kwAlgorithm = crypto.getAlgorithmByOID(aesKWAlgorithm.algorithmId, true, "kwAlgorithm");
  13437. let kwLength = kwAlgorithm.length;
  13438. const kwLengthBuffer = new ArrayBuffer(4);
  13439. const kwLengthView = new Uint8Array(kwLengthBuffer);
  13440. for (let j = 3; j >= 0; j--) {
  13441. kwLengthView[j] = kwLength;
  13442. kwLength >>= 8;
  13443. }
  13444. const keyInfoAlgorithm = {
  13445. algorithmId: aesKWAlgorithm.algorithmId
  13446. };
  13447. if (includeAlgorithmParams) {
  13448. keyInfoAlgorithm.algorithmParams = new asn1js.Null();
  13449. }
  13450. const eccInfo = new ECCCMSSharedInfo({
  13451. keyInfo: new AlgorithmIdentifier(keyInfoAlgorithm),
  13452. entityUInfo: recipientInfo.ukm,
  13453. suppPubInfo: new asn1js.OctetString({ valueHex: kwLengthBuffer })
  13454. });
  13455. const encodedInfo = eccInfo.toSchema().toBER(false);
  13456. const ecdhAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "ecdhAlgorithm");
  13457. if (!ecdhAlgorithm.name) {
  13458. throw new Error(`Incorrect OID for key encryption algorithm: ${recipientInfo.keyEncryptionAlgorithm.algorithmId}`);
  13459. }
  13460. return kdf(ecdhAlgorithm.kdf, sharedSecret, kwAlgorithm.length, encodedInfo, crypto);
  13461. }
  13462. const kdfResult = await applyKDF();
  13463. const importAesKwKey = async (kdfResult) => {
  13464. return crypto.importKey("raw", kdfResult, { name: "AES-KW" }, true, ["unwrapKey"]);
  13465. };
  13466. const aesKwKey = await importAesKwKey(kdfResult);
  13467. const unwrapSessionKey = async (aesKwKey) => {
  13468. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13469. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13470. return crypto.unwrapKey("raw", recipientInfo.recipientEncryptedKeys.encryptedKeys[0].encryptedKey.valueBlock.valueHexView, aesKwKey, { name: "AES-KW" }, contentEncryptionAlgorithm, true, ["decrypt"]);
  13471. };
  13472. try {
  13473. return await unwrapSessionKey(aesKwKey);
  13474. }
  13475. catch {
  13476. const kdfResult = await applyKDF(true);
  13477. const aesKwKey = await importAesKwKey(kdfResult);
  13478. return unwrapSessionKey(aesKwKey);
  13479. }
  13480. };
  13481. const SubKeyTransRecipientInfo = async (index) => {
  13482. const recipientInfo = this.recipientInfos[index].value;
  13483. if (!decryptionParameters.recipientPrivateKey) {
  13484. throw new Error("Parameter \"recipientPrivateKey\" is mandatory for \"KeyTransRecipientInfo\"");
  13485. }
  13486. const algorithmParameters = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "keyEncryptionAlgorithm");
  13487. if (algorithmParameters.name === "RSA-OAEP") {
  13488. const schema = recipientInfo.keyEncryptionAlgorithm.algorithmParams;
  13489. const rsaOAEPParams = new RSAESOAEPParams({ schema });
  13490. algorithmParameters.hash = crypto.getAlgorithmByOID(rsaOAEPParams.hashAlgorithm.algorithmId);
  13491. if (("name" in algorithmParameters.hash) === false)
  13492. throw new Error(`Incorrect OID for hash algorithm: ${rsaOAEPParams.hashAlgorithm.algorithmId}`);
  13493. }
  13494. let privateKey;
  13495. let keyCrypto = crypto;
  13496. if (BufferSourceConverter.isBufferSource(decryptionParameters.recipientPrivateKey)) {
  13497. privateKey = await crypto.importKey("pkcs8", decryptionParameters.recipientPrivateKey, algorithmParameters, true, ["decrypt"]);
  13498. }
  13499. else {
  13500. privateKey = decryptionParameters.recipientPrivateKey;
  13501. if ("crypto" in decryptionParameters && decryptionParameters.crypto) {
  13502. keyCrypto = decryptionParameters.crypto.subtle;
  13503. }
  13504. }
  13505. const sessionKey = await keyCrypto.decrypt(privateKey.algorithm, privateKey, recipientInfo.encryptedKey.valueBlock.valueHexView);
  13506. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13507. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13508. if (("name" in contentEncryptionAlgorithm) === false)
  13509. throw new Error(`Incorrect "contentEncryptionAlgorithm": ${algorithmId}`);
  13510. return crypto.importKey("raw", sessionKey, contentEncryptionAlgorithm, true, ["decrypt"]);
  13511. };
  13512. const SubKEKRecipientInfo = async (index) => {
  13513. const recipientInfo = this.recipientInfos[index].value;
  13514. if (!decryptionParameters.preDefinedData)
  13515. throw new Error("Parameter \"preDefinedData\" is mandatory for \"KEKRecipientInfo\"");
  13516. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "kekAlgorithm");
  13517. const importedKey = await crypto.importKey("raw", decryptionParameters.preDefinedData, kekAlgorithm, true, ["unwrapKey"]);
  13518. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13519. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13520. if (!contentEncryptionAlgorithm.name) {
  13521. throw new Error(`Incorrect "contentEncryptionAlgorithm": ${algorithmId}`);
  13522. }
  13523. return crypto.unwrapKey("raw", recipientInfo.encryptedKey.valueBlock.valueHexView, importedKey, kekAlgorithm, contentEncryptionAlgorithm, true, ["decrypt"]);
  13524. };
  13525. const SubPasswordRecipientinfo = async (index) => {
  13526. const recipientInfo = this.recipientInfos[index].value;
  13527. let pbkdf2Params;
  13528. if (!decryptionParameters.preDefinedData) {
  13529. throw new Error("Parameter \"preDefinedData\" is mandatory for \"KEKRecipientInfo\"");
  13530. }
  13531. if (!recipientInfo.keyDerivationAlgorithm) {
  13532. throw new Error("Please append encoded \"keyDerivationAlgorithm\"");
  13533. }
  13534. if (!recipientInfo.keyDerivationAlgorithm.algorithmParams) {
  13535. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13536. }
  13537. try {
  13538. pbkdf2Params = new PBKDF2Params({ schema: recipientInfo.keyDerivationAlgorithm.algorithmParams });
  13539. }
  13540. catch {
  13541. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13542. }
  13543. const pbkdf2Key = await crypto.importKey("raw", decryptionParameters.preDefinedData, "PBKDF2", false, ["deriveKey"]);
  13544. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "keyEncryptionAlgorithm");
  13545. const hmacHashAlgorithm = pbkdf2Params.prf
  13546. ? crypto.getAlgorithmByOID(pbkdf2Params.prf.algorithmId, true, "prfAlgorithm").hash.name
  13547. : "SHA-1";
  13548. const saltView = new Uint8Array(pbkdf2Params.salt.valueBlock.valueHex);
  13549. const iterations = pbkdf2Params.iterationCount;
  13550. const kekKey = await crypto.deriveKey({
  13551. name: "PBKDF2",
  13552. hash: {
  13553. name: hmacHashAlgorithm
  13554. },
  13555. salt: saltView,
  13556. iterations
  13557. }, pbkdf2Key, kekAlgorithm, true, ["unwrapKey"]);
  13558. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13559. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13560. return crypto.unwrapKey("raw", recipientInfo.encryptedKey.valueBlock.valueHexView, kekKey, kekAlgorithm, contentEncryptionAlgorithm, true, ["decrypt"]);
  13561. };
  13562. let unwrappedKey;
  13563. switch (this.recipientInfos[recipientIndex].variant) {
  13564. case 1:
  13565. unwrappedKey = await SubKeyTransRecipientInfo(recipientIndex);
  13566. break;
  13567. case 2:
  13568. unwrappedKey = await SubKeyAgreeRecipientInfo(recipientIndex);
  13569. break;
  13570. case 3:
  13571. unwrappedKey = await SubKEKRecipientInfo(recipientIndex);
  13572. break;
  13573. case 4:
  13574. unwrappedKey = await SubPasswordRecipientinfo(recipientIndex);
  13575. break;
  13576. default:
  13577. throw new Error(`Unknown recipient type in array with index ${recipientIndex}`);
  13578. }
  13579. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13580. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13581. const ivBuffer = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmParams.valueBlock.valueHex;
  13582. const ivView = new Uint8Array(ivBuffer);
  13583. if (!this.encryptedContentInfo.encryptedContent) {
  13584. throw new Error("Required property `encryptedContent` is empty");
  13585. }
  13586. const dataBuffer = this.encryptedContentInfo.getEncryptedContent();
  13587. return crypto.decrypt({
  13588. name: contentEncryptionAlgorithm.name,
  13589. iv: ivView
  13590. }, unwrappedKey, dataBuffer);
  13591. }
  13592. }
  13593. EnvelopedData.CLASS_NAME = "EnvelopedData";
  13594. const SAFE_CONTENTS = "safeContents";
  13595. const PARSED_VALUE$1 = "parsedValue";
  13596. const CONTENT_INFOS = "contentInfos";
  13597. class AuthenticatedSafe extends PkiObject {
  13598. constructor(parameters = {}) {
  13599. super();
  13600. this.safeContents = pvutils.getParametersValue(parameters, SAFE_CONTENTS, AuthenticatedSafe.defaultValues(SAFE_CONTENTS));
  13601. if (PARSED_VALUE$1 in parameters) {
  13602. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE$1, AuthenticatedSafe.defaultValues(PARSED_VALUE$1));
  13603. }
  13604. if (parameters.schema) {
  13605. this.fromSchema(parameters.schema);
  13606. }
  13607. }
  13608. static defaultValues(memberName) {
  13609. switch (memberName) {
  13610. case SAFE_CONTENTS:
  13611. return [];
  13612. case PARSED_VALUE$1:
  13613. return {};
  13614. default:
  13615. return super.defaultValues(memberName);
  13616. }
  13617. }
  13618. static compareWithDefault(memberName, memberValue) {
  13619. switch (memberName) {
  13620. case SAFE_CONTENTS:
  13621. return (memberValue.length === 0);
  13622. case PARSED_VALUE$1:
  13623. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  13624. default:
  13625. return super.defaultValues(memberName);
  13626. }
  13627. }
  13628. static schema(parameters = {}) {
  13629. const names = pvutils.getParametersValue(parameters, "names", {});
  13630. return (new asn1js.Sequence({
  13631. name: (names.blockName || EMPTY_STRING),
  13632. value: [
  13633. new asn1js.Repeated({
  13634. name: (names.contentInfos || EMPTY_STRING),
  13635. value: ContentInfo.schema()
  13636. })
  13637. ]
  13638. }));
  13639. }
  13640. fromSchema(schema) {
  13641. pvutils.clearProps(schema, [
  13642. CONTENT_INFOS
  13643. ]);
  13644. const asn1 = asn1js.compareSchema(schema, schema, AuthenticatedSafe.schema({
  13645. names: {
  13646. contentInfos: CONTENT_INFOS
  13647. }
  13648. }));
  13649. AsnError.assertSchema(asn1, this.className);
  13650. this.safeContents = Array.from(asn1.result.contentInfos, element => new ContentInfo({ schema: element }));
  13651. }
  13652. toSchema() {
  13653. return (new asn1js.Sequence({
  13654. value: Array.from(this.safeContents, o => o.toSchema())
  13655. }));
  13656. }
  13657. toJSON() {
  13658. return {
  13659. safeContents: Array.from(this.safeContents, o => o.toJSON())
  13660. };
  13661. }
  13662. async parseInternalValues(parameters, crypto = getCrypto(true)) {
  13663. ParameterError.assert(parameters, SAFE_CONTENTS);
  13664. ArgumentError.assert(parameters.safeContents, SAFE_CONTENTS, "Array");
  13665. if (parameters.safeContents.length !== this.safeContents.length) {
  13666. throw new ArgumentError("Length of \"parameters.safeContents\" must be equal to \"this.safeContents.length\"");
  13667. }
  13668. this.parsedValue = {
  13669. safeContents: [],
  13670. };
  13671. for (const [index, content] of this.safeContents.entries()) {
  13672. const safeContent = parameters.safeContents[index];
  13673. const errorTarget = `parameters.safeContents[${index}]`;
  13674. switch (content.contentType) {
  13675. case id_ContentType_Data:
  13676. {
  13677. ArgumentError.assert(content.content, "this.safeContents[j].content", asn1js.OctetString);
  13678. const authSafeContent = content.content.getValue();
  13679. this.parsedValue.safeContents.push({
  13680. privacyMode: 0,
  13681. value: SafeContents.fromBER(authSafeContent)
  13682. });
  13683. }
  13684. break;
  13685. case id_ContentType_EnvelopedData:
  13686. {
  13687. const cmsEnveloped = new EnvelopedData({ schema: content.content });
  13688. ParameterError.assert(errorTarget, safeContent, "recipientCertificate", "recipientKey");
  13689. const envelopedData = safeContent;
  13690. const recipientCertificate = envelopedData.recipientCertificate;
  13691. const recipientKey = envelopedData.recipientKey;
  13692. const decrypted = await cmsEnveloped.decrypt(0, {
  13693. recipientCertificate,
  13694. recipientPrivateKey: recipientKey
  13695. }, crypto);
  13696. this.parsedValue.safeContents.push({
  13697. privacyMode: 2,
  13698. value: SafeContents.fromBER(decrypted),
  13699. });
  13700. }
  13701. break;
  13702. case id_ContentType_EncryptedData:
  13703. {
  13704. const cmsEncrypted = new EncryptedData({ schema: content.content });
  13705. ParameterError.assert(errorTarget, safeContent, "password");
  13706. const password = safeContent.password;
  13707. const decrypted = await cmsEncrypted.decrypt({
  13708. password
  13709. }, crypto);
  13710. this.parsedValue.safeContents.push({
  13711. privacyMode: 1,
  13712. value: SafeContents.fromBER(decrypted),
  13713. });
  13714. }
  13715. break;
  13716. default:
  13717. throw new Error(`Unknown "contentType" for AuthenticatedSafe: " ${content.contentType}`);
  13718. }
  13719. }
  13720. }
  13721. async makeInternalValues(parameters, crypto = getCrypto(true)) {
  13722. if (!(this.parsedValue)) {
  13723. throw new Error("Please run \"parseValues\" first or add \"parsedValue\" manually");
  13724. }
  13725. ArgumentError.assert(this.parsedValue, "this.parsedValue", "object");
  13726. ArgumentError.assert(this.parsedValue.safeContents, "this.parsedValue.safeContents", "Array");
  13727. ArgumentError.assert(parameters, "parameters", "object");
  13728. ParameterError.assert(parameters, "safeContents");
  13729. ArgumentError.assert(parameters.safeContents, "parameters.safeContents", "Array");
  13730. if (parameters.safeContents.length !== this.parsedValue.safeContents.length) {
  13731. throw new ArgumentError("Length of \"parameters.safeContents\" must be equal to \"this.parsedValue.safeContents\"");
  13732. }
  13733. this.safeContents = [];
  13734. for (const [index, content] of this.parsedValue.safeContents.entries()) {
  13735. ParameterError.assert("content", content, "privacyMode", "value");
  13736. ArgumentError.assert(content.value, "content.value", SafeContents);
  13737. switch (content.privacyMode) {
  13738. case 0:
  13739. {
  13740. const contentBuffer = content.value.toSchema().toBER(false);
  13741. this.safeContents.push(new ContentInfo({
  13742. contentType: "1.2.840.113549.1.7.1",
  13743. content: new asn1js.OctetString({ valueHex: contentBuffer })
  13744. }));
  13745. }
  13746. break;
  13747. case 1:
  13748. {
  13749. const cmsEncrypted = new EncryptedData();
  13750. const currentParameters = parameters.safeContents[index];
  13751. currentParameters.contentToEncrypt = content.value.toSchema().toBER(false);
  13752. await cmsEncrypted.encrypt(currentParameters, crypto);
  13753. this.safeContents.push(new ContentInfo({
  13754. contentType: "1.2.840.113549.1.7.6",
  13755. content: cmsEncrypted.toSchema()
  13756. }));
  13757. }
  13758. break;
  13759. case 2:
  13760. {
  13761. const cmsEnveloped = new EnvelopedData();
  13762. const contentToEncrypt = content.value.toSchema().toBER(false);
  13763. const safeContent = parameters.safeContents[index];
  13764. ParameterError.assert(`parameters.safeContents[${index}]`, safeContent, "encryptingCertificate", "encryptionAlgorithm");
  13765. switch (true) {
  13766. case (safeContent.encryptionAlgorithm.name.toLowerCase() === "aes-cbc"):
  13767. case (safeContent.encryptionAlgorithm.name.toLowerCase() === "aes-gcm"):
  13768. break;
  13769. default:
  13770. throw new Error(`Incorrect parameter "encryptionAlgorithm" in "parameters.safeContents[i]": ${safeContent.encryptionAlgorithm}`);
  13771. }
  13772. switch (true) {
  13773. case (safeContent.encryptionAlgorithm.length === 128):
  13774. case (safeContent.encryptionAlgorithm.length === 192):
  13775. case (safeContent.encryptionAlgorithm.length === 256):
  13776. break;
  13777. default:
  13778. throw new Error(`Incorrect parameter "encryptionAlgorithm.length" in "parameters.safeContents[i]": ${safeContent.encryptionAlgorithm.length}`);
  13779. }
  13780. const encryptionAlgorithm = safeContent.encryptionAlgorithm;
  13781. cmsEnveloped.addRecipientByCertificate(safeContent.encryptingCertificate, {}, undefined, crypto);
  13782. await cmsEnveloped.encrypt(encryptionAlgorithm, contentToEncrypt, crypto);
  13783. this.safeContents.push(new ContentInfo({
  13784. contentType: "1.2.840.113549.1.7.3",
  13785. content: cmsEnveloped.toSchema()
  13786. }));
  13787. }
  13788. break;
  13789. default:
  13790. throw new Error(`Incorrect value for "content.privacyMode": ${content.privacyMode}`);
  13791. }
  13792. }
  13793. return this;
  13794. }
  13795. }
  13796. AuthenticatedSafe.CLASS_NAME = "AuthenticatedSafe";
  13797. const HASH_ALGORITHM$1 = "hashAlgorithm";
  13798. const ISSUER_NAME_HASH = "issuerNameHash";
  13799. const ISSUER_KEY_HASH = "issuerKeyHash";
  13800. const SERIAL_NUMBER$1 = "serialNumber";
  13801. const CLEAR_PROPS$j = [
  13802. HASH_ALGORITHM$1,
  13803. ISSUER_NAME_HASH,
  13804. ISSUER_KEY_HASH,
  13805. SERIAL_NUMBER$1,
  13806. ];
  13807. class CertID extends PkiObject {
  13808. static async create(certificate, parameters, crypto = getCrypto(true)) {
  13809. const certID = new CertID();
  13810. await certID.createForCertificate(certificate, parameters, crypto);
  13811. return certID;
  13812. }
  13813. constructor(parameters = {}) {
  13814. super();
  13815. this.hashAlgorithm = pvutils.getParametersValue(parameters, HASH_ALGORITHM$1, CertID.defaultValues(HASH_ALGORITHM$1));
  13816. this.issuerNameHash = pvutils.getParametersValue(parameters, ISSUER_NAME_HASH, CertID.defaultValues(ISSUER_NAME_HASH));
  13817. this.issuerKeyHash = pvutils.getParametersValue(parameters, ISSUER_KEY_HASH, CertID.defaultValues(ISSUER_KEY_HASH));
  13818. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$1, CertID.defaultValues(SERIAL_NUMBER$1));
  13819. if (parameters.schema) {
  13820. this.fromSchema(parameters.schema);
  13821. }
  13822. }
  13823. static defaultValues(memberName) {
  13824. switch (memberName) {
  13825. case HASH_ALGORITHM$1:
  13826. return new AlgorithmIdentifier();
  13827. case ISSUER_NAME_HASH:
  13828. case ISSUER_KEY_HASH:
  13829. return new asn1js.OctetString();
  13830. case SERIAL_NUMBER$1:
  13831. return new asn1js.Integer();
  13832. default:
  13833. return super.defaultValues(memberName);
  13834. }
  13835. }
  13836. static compareWithDefault(memberName, memberValue) {
  13837. switch (memberName) {
  13838. case HASH_ALGORITHM$1:
  13839. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  13840. case ISSUER_NAME_HASH:
  13841. case ISSUER_KEY_HASH:
  13842. case SERIAL_NUMBER$1:
  13843. return (memberValue.isEqual(CertID.defaultValues(SERIAL_NUMBER$1)));
  13844. default:
  13845. return super.defaultValues(memberName);
  13846. }
  13847. }
  13848. static schema(parameters = {}) {
  13849. const names = pvutils.getParametersValue(parameters, "names", {});
  13850. return (new asn1js.Sequence({
  13851. name: (names.blockName || EMPTY_STRING),
  13852. value: [
  13853. AlgorithmIdentifier.schema(names.hashAlgorithmObject || {
  13854. names: {
  13855. blockName: (names.hashAlgorithm || EMPTY_STRING)
  13856. }
  13857. }),
  13858. new asn1js.OctetString({ name: (names.issuerNameHash || EMPTY_STRING) }),
  13859. new asn1js.OctetString({ name: (names.issuerKeyHash || EMPTY_STRING) }),
  13860. new asn1js.Integer({ name: (names.serialNumber || EMPTY_STRING) })
  13861. ]
  13862. }));
  13863. }
  13864. fromSchema(schema) {
  13865. pvutils.clearProps(schema, CLEAR_PROPS$j);
  13866. const asn1 = asn1js.compareSchema(schema, schema, CertID.schema({
  13867. names: {
  13868. hashAlgorithm: HASH_ALGORITHM$1,
  13869. issuerNameHash: ISSUER_NAME_HASH,
  13870. issuerKeyHash: ISSUER_KEY_HASH,
  13871. serialNumber: SERIAL_NUMBER$1
  13872. }
  13873. }));
  13874. AsnError.assertSchema(asn1, this.className);
  13875. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  13876. this.issuerNameHash = asn1.result.issuerNameHash;
  13877. this.issuerKeyHash = asn1.result.issuerKeyHash;
  13878. this.serialNumber = asn1.result.serialNumber;
  13879. }
  13880. toSchema() {
  13881. return (new asn1js.Sequence({
  13882. value: [
  13883. this.hashAlgorithm.toSchema(),
  13884. this.issuerNameHash,
  13885. this.issuerKeyHash,
  13886. this.serialNumber
  13887. ]
  13888. }));
  13889. }
  13890. toJSON() {
  13891. return {
  13892. hashAlgorithm: this.hashAlgorithm.toJSON(),
  13893. issuerNameHash: this.issuerNameHash.toJSON(),
  13894. issuerKeyHash: this.issuerKeyHash.toJSON(),
  13895. serialNumber: this.serialNumber.toJSON(),
  13896. };
  13897. }
  13898. isEqual(certificateID) {
  13899. if (this.hashAlgorithm.algorithmId !== certificateID.hashAlgorithm.algorithmId) {
  13900. return false;
  13901. }
  13902. if (!pvtsutils.BufferSourceConverter.isEqual(this.issuerNameHash.valueBlock.valueHexView, certificateID.issuerNameHash.valueBlock.valueHexView)) {
  13903. return false;
  13904. }
  13905. if (!pvtsutils.BufferSourceConverter.isEqual(this.issuerKeyHash.valueBlock.valueHexView, certificateID.issuerKeyHash.valueBlock.valueHexView)) {
  13906. return false;
  13907. }
  13908. if (!this.serialNumber.isEqual(certificateID.serialNumber)) {
  13909. return false;
  13910. }
  13911. return true;
  13912. }
  13913. async createForCertificate(certificate, parameters, crypto = getCrypto(true)) {
  13914. ParameterError.assert(parameters, HASH_ALGORITHM$1, "issuerCertificate");
  13915. const hashOID = crypto.getOIDByAlgorithm({ name: parameters.hashAlgorithm }, true, "hashAlgorithm");
  13916. this.hashAlgorithm = new AlgorithmIdentifier({
  13917. algorithmId: hashOID,
  13918. algorithmParams: new asn1js.Null()
  13919. });
  13920. const issuerCertificate = parameters.issuerCertificate;
  13921. this.serialNumber = certificate.serialNumber;
  13922. const hashIssuerName = await crypto.digest({ name: parameters.hashAlgorithm }, issuerCertificate.subject.toSchema().toBER(false));
  13923. this.issuerNameHash = new asn1js.OctetString({ valueHex: hashIssuerName });
  13924. const issuerKeyBuffer = issuerCertificate.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView;
  13925. const hashIssuerKey = await crypto.digest({ name: parameters.hashAlgorithm }, issuerKeyBuffer);
  13926. this.issuerKeyHash = new asn1js.OctetString({ valueHex: hashIssuerKey });
  13927. }
  13928. }
  13929. CertID.CLASS_NAME = "CertID";
  13930. const CERT_ID = "certID";
  13931. const CERT_STATUS = "certStatus";
  13932. const THIS_UPDATE = "thisUpdate";
  13933. const NEXT_UPDATE = "nextUpdate";
  13934. const SINGLE_EXTENSIONS = "singleExtensions";
  13935. const CLEAR_PROPS$i = [
  13936. CERT_ID,
  13937. CERT_STATUS,
  13938. THIS_UPDATE,
  13939. NEXT_UPDATE,
  13940. SINGLE_EXTENSIONS,
  13941. ];
  13942. class SingleResponse extends PkiObject {
  13943. constructor(parameters = {}) {
  13944. super();
  13945. this.certID = pvutils.getParametersValue(parameters, CERT_ID, SingleResponse.defaultValues(CERT_ID));
  13946. this.certStatus = pvutils.getParametersValue(parameters, CERT_STATUS, SingleResponse.defaultValues(CERT_STATUS));
  13947. this.thisUpdate = pvutils.getParametersValue(parameters, THIS_UPDATE, SingleResponse.defaultValues(THIS_UPDATE));
  13948. if (NEXT_UPDATE in parameters) {
  13949. this.nextUpdate = pvutils.getParametersValue(parameters, NEXT_UPDATE, SingleResponse.defaultValues(NEXT_UPDATE));
  13950. }
  13951. if (SINGLE_EXTENSIONS in parameters) {
  13952. this.singleExtensions = pvutils.getParametersValue(parameters, SINGLE_EXTENSIONS, SingleResponse.defaultValues(SINGLE_EXTENSIONS));
  13953. }
  13954. if (parameters.schema) {
  13955. this.fromSchema(parameters.schema);
  13956. }
  13957. }
  13958. static defaultValues(memberName) {
  13959. switch (memberName) {
  13960. case CERT_ID:
  13961. return new CertID();
  13962. case CERT_STATUS:
  13963. return {};
  13964. case THIS_UPDATE:
  13965. case NEXT_UPDATE:
  13966. return new Date(0, 0, 0);
  13967. case SINGLE_EXTENSIONS:
  13968. return [];
  13969. default:
  13970. return super.defaultValues(memberName);
  13971. }
  13972. }
  13973. static compareWithDefault(memberName, memberValue) {
  13974. switch (memberName) {
  13975. case CERT_ID:
  13976. return ((CertID.compareWithDefault("hashAlgorithm", memberValue.hashAlgorithm)) &&
  13977. (CertID.compareWithDefault("issuerNameHash", memberValue.issuerNameHash)) &&
  13978. (CertID.compareWithDefault("issuerKeyHash", memberValue.issuerKeyHash)) &&
  13979. (CertID.compareWithDefault("serialNumber", memberValue.serialNumber)));
  13980. case CERT_STATUS:
  13981. return (Object.keys(memberValue).length === 0);
  13982. case THIS_UPDATE:
  13983. case NEXT_UPDATE:
  13984. return (memberValue === SingleResponse.defaultValues(memberName));
  13985. default:
  13986. return super.defaultValues(memberName);
  13987. }
  13988. }
  13989. static schema(parameters = {}) {
  13990. const names = pvutils.getParametersValue(parameters, "names", {});
  13991. return (new asn1js.Sequence({
  13992. name: (names.blockName || EMPTY_STRING),
  13993. value: [
  13994. CertID.schema(names.certID || {}),
  13995. new asn1js.Choice({
  13996. value: [
  13997. new asn1js.Primitive({
  13998. name: (names.certStatus || EMPTY_STRING),
  13999. idBlock: {
  14000. tagClass: 3,
  14001. tagNumber: 0
  14002. },
  14003. }),
  14004. new asn1js.Constructed({
  14005. name: (names.certStatus || EMPTY_STRING),
  14006. idBlock: {
  14007. tagClass: 3,
  14008. tagNumber: 1
  14009. },
  14010. value: [
  14011. new asn1js.GeneralizedTime(),
  14012. new asn1js.Constructed({
  14013. optional: true,
  14014. idBlock: {
  14015. tagClass: 3,
  14016. tagNumber: 0
  14017. },
  14018. value: [new asn1js.Enumerated()]
  14019. })
  14020. ]
  14021. }),
  14022. new asn1js.Primitive({
  14023. name: (names.certStatus || EMPTY_STRING),
  14024. idBlock: {
  14025. tagClass: 3,
  14026. tagNumber: 2
  14027. },
  14028. lenBlock: { length: 1 }
  14029. })
  14030. ]
  14031. }),
  14032. new asn1js.GeneralizedTime({ name: (names.thisUpdate || EMPTY_STRING) }),
  14033. new asn1js.Constructed({
  14034. optional: true,
  14035. idBlock: {
  14036. tagClass: 3,
  14037. tagNumber: 0
  14038. },
  14039. value: [new asn1js.GeneralizedTime({ name: (names.nextUpdate || EMPTY_STRING) })]
  14040. }),
  14041. new asn1js.Constructed({
  14042. optional: true,
  14043. idBlock: {
  14044. tagClass: 3,
  14045. tagNumber: 1
  14046. },
  14047. value: [Extensions.schema(names.singleExtensions || {})]
  14048. })
  14049. ]
  14050. }));
  14051. }
  14052. fromSchema(schema) {
  14053. pvutils.clearProps(schema, CLEAR_PROPS$i);
  14054. const asn1 = asn1js.compareSchema(schema, schema, SingleResponse.schema({
  14055. names: {
  14056. certID: {
  14057. names: {
  14058. blockName: CERT_ID
  14059. }
  14060. },
  14061. certStatus: CERT_STATUS,
  14062. thisUpdate: THIS_UPDATE,
  14063. nextUpdate: NEXT_UPDATE,
  14064. singleExtensions: {
  14065. names: {
  14066. blockName: SINGLE_EXTENSIONS
  14067. }
  14068. }
  14069. }
  14070. }));
  14071. AsnError.assertSchema(asn1, this.className);
  14072. this.certID = new CertID({ schema: asn1.result.certID });
  14073. this.certStatus = asn1.result.certStatus;
  14074. this.thisUpdate = asn1.result.thisUpdate.toDate();
  14075. if (NEXT_UPDATE in asn1.result)
  14076. this.nextUpdate = asn1.result.nextUpdate.toDate();
  14077. if (SINGLE_EXTENSIONS in asn1.result)
  14078. this.singleExtensions = Array.from(asn1.result.singleExtensions.valueBlock.value, element => new Extension({ schema: element }));
  14079. }
  14080. toSchema() {
  14081. const outputArray = [];
  14082. outputArray.push(this.certID.toSchema());
  14083. outputArray.push(this.certStatus);
  14084. outputArray.push(new asn1js.GeneralizedTime({ valueDate: this.thisUpdate }));
  14085. if (this.nextUpdate) {
  14086. outputArray.push(new asn1js.Constructed({
  14087. idBlock: {
  14088. tagClass: 3,
  14089. tagNumber: 0
  14090. },
  14091. value: [new asn1js.GeneralizedTime({ valueDate: this.nextUpdate })]
  14092. }));
  14093. }
  14094. if (this.singleExtensions) {
  14095. outputArray.push(new asn1js.Constructed({
  14096. idBlock: {
  14097. tagClass: 3,
  14098. tagNumber: 1
  14099. },
  14100. value: [new asn1js.Sequence({ value: Array.from(this.singleExtensions, o => o.toSchema()) })]
  14101. }));
  14102. }
  14103. return (new asn1js.Sequence({
  14104. value: outputArray
  14105. }));
  14106. }
  14107. toJSON() {
  14108. const res = {
  14109. certID: this.certID.toJSON(),
  14110. certStatus: this.certStatus.toJSON(),
  14111. thisUpdate: this.thisUpdate
  14112. };
  14113. if (this.nextUpdate) {
  14114. res.nextUpdate = this.nextUpdate;
  14115. }
  14116. if (this.singleExtensions) {
  14117. res.singleExtensions = Array.from(this.singleExtensions, o => o.toJSON());
  14118. }
  14119. return res;
  14120. }
  14121. }
  14122. SingleResponse.CLASS_NAME = "SingleResponse";
  14123. const TBS$2 = "tbs";
  14124. const VERSION$7 = "version";
  14125. const RESPONDER_ID = "responderID";
  14126. const PRODUCED_AT = "producedAt";
  14127. const RESPONSES = "responses";
  14128. const RESPONSE_EXTENSIONS = "responseExtensions";
  14129. const RESPONSE_DATA = "ResponseData";
  14130. const RESPONSE_DATA_VERSION = `${RESPONSE_DATA}.${VERSION$7}`;
  14131. const RESPONSE_DATA_RESPONDER_ID = `${RESPONSE_DATA}.${RESPONDER_ID}`;
  14132. const RESPONSE_DATA_PRODUCED_AT = `${RESPONSE_DATA}.${PRODUCED_AT}`;
  14133. const RESPONSE_DATA_RESPONSES = `${RESPONSE_DATA}.${RESPONSES}`;
  14134. const RESPONSE_DATA_RESPONSE_EXTENSIONS = `${RESPONSE_DATA}.${RESPONSE_EXTENSIONS}`;
  14135. const CLEAR_PROPS$h = [
  14136. RESPONSE_DATA,
  14137. RESPONSE_DATA_VERSION,
  14138. RESPONSE_DATA_RESPONDER_ID,
  14139. RESPONSE_DATA_PRODUCED_AT,
  14140. RESPONSE_DATA_RESPONSES,
  14141. RESPONSE_DATA_RESPONSE_EXTENSIONS
  14142. ];
  14143. class ResponseData extends PkiObject {
  14144. get tbs() {
  14145. return pvtsutils.BufferSourceConverter.toArrayBuffer(this.tbsView);
  14146. }
  14147. set tbs(value) {
  14148. this.tbsView = new Uint8Array(value);
  14149. }
  14150. constructor(parameters = {}) {
  14151. super();
  14152. this.tbsView = new Uint8Array(pvutils.getParametersValue(parameters, TBS$2, ResponseData.defaultValues(TBS$2)));
  14153. if (VERSION$7 in parameters) {
  14154. this.version = pvutils.getParametersValue(parameters, VERSION$7, ResponseData.defaultValues(VERSION$7));
  14155. }
  14156. this.responderID = pvutils.getParametersValue(parameters, RESPONDER_ID, ResponseData.defaultValues(RESPONDER_ID));
  14157. this.producedAt = pvutils.getParametersValue(parameters, PRODUCED_AT, ResponseData.defaultValues(PRODUCED_AT));
  14158. this.responses = pvutils.getParametersValue(parameters, RESPONSES, ResponseData.defaultValues(RESPONSES));
  14159. if (RESPONSE_EXTENSIONS in parameters) {
  14160. this.responseExtensions = pvutils.getParametersValue(parameters, RESPONSE_EXTENSIONS, ResponseData.defaultValues(RESPONSE_EXTENSIONS));
  14161. }
  14162. if (parameters.schema) {
  14163. this.fromSchema(parameters.schema);
  14164. }
  14165. }
  14166. static defaultValues(memberName) {
  14167. switch (memberName) {
  14168. case VERSION$7:
  14169. return 0;
  14170. case TBS$2:
  14171. return EMPTY_BUFFER;
  14172. case RESPONDER_ID:
  14173. return {};
  14174. case PRODUCED_AT:
  14175. return new Date(0, 0, 0);
  14176. case RESPONSES:
  14177. case RESPONSE_EXTENSIONS:
  14178. return [];
  14179. default:
  14180. return super.defaultValues(memberName);
  14181. }
  14182. }
  14183. static compareWithDefault(memberName, memberValue) {
  14184. switch (memberName) {
  14185. case TBS$2:
  14186. return (memberValue.byteLength === 0);
  14187. case RESPONDER_ID:
  14188. return (Object.keys(memberValue).length === 0);
  14189. case PRODUCED_AT:
  14190. return (memberValue === ResponseData.defaultValues(memberName));
  14191. case RESPONSES:
  14192. case RESPONSE_EXTENSIONS:
  14193. return (memberValue.length === 0);
  14194. default:
  14195. return super.defaultValues(memberName);
  14196. }
  14197. }
  14198. static schema(parameters = {}) {
  14199. const names = pvutils.getParametersValue(parameters, "names", {});
  14200. return (new asn1js.Sequence({
  14201. name: (names.blockName || RESPONSE_DATA),
  14202. value: [
  14203. new asn1js.Constructed({
  14204. optional: true,
  14205. idBlock: {
  14206. tagClass: 3,
  14207. tagNumber: 0
  14208. },
  14209. value: [new asn1js.Integer({ name: (names.version || RESPONSE_DATA_VERSION) })]
  14210. }),
  14211. new asn1js.Choice({
  14212. value: [
  14213. new asn1js.Constructed({
  14214. name: (names.responderID || RESPONSE_DATA_RESPONDER_ID),
  14215. idBlock: {
  14216. tagClass: 3,
  14217. tagNumber: 1
  14218. },
  14219. value: [RelativeDistinguishedNames.schema(names.ResponseDataByName || {
  14220. names: {
  14221. blockName: "ResponseData.byName"
  14222. }
  14223. })]
  14224. }),
  14225. new asn1js.Constructed({
  14226. name: (names.responderID || RESPONSE_DATA_RESPONDER_ID),
  14227. idBlock: {
  14228. tagClass: 3,
  14229. tagNumber: 2
  14230. },
  14231. value: [new asn1js.OctetString({ name: (names.ResponseDataByKey || "ResponseData.byKey") })]
  14232. })
  14233. ]
  14234. }),
  14235. new asn1js.GeneralizedTime({ name: (names.producedAt || RESPONSE_DATA_PRODUCED_AT) }),
  14236. new asn1js.Sequence({
  14237. value: [
  14238. new asn1js.Repeated({
  14239. name: RESPONSE_DATA_RESPONSES,
  14240. value: SingleResponse.schema(names.response || {})
  14241. })
  14242. ]
  14243. }),
  14244. new asn1js.Constructed({
  14245. optional: true,
  14246. idBlock: {
  14247. tagClass: 3,
  14248. tagNumber: 1
  14249. },
  14250. value: [Extensions.schema(names.extensions || {
  14251. names: {
  14252. blockName: RESPONSE_DATA_RESPONSE_EXTENSIONS
  14253. }
  14254. })]
  14255. })
  14256. ]
  14257. }));
  14258. }
  14259. fromSchema(schema) {
  14260. pvutils.clearProps(schema, CLEAR_PROPS$h);
  14261. const asn1 = asn1js.compareSchema(schema, schema, ResponseData.schema());
  14262. AsnError.assertSchema(asn1, this.className);
  14263. this.tbsView = asn1.result.ResponseData.valueBeforeDecodeView;
  14264. if (RESPONSE_DATA_VERSION in asn1.result)
  14265. this.version = asn1.result[RESPONSE_DATA_VERSION].valueBlock.valueDec;
  14266. if (asn1.result[RESPONSE_DATA_RESPONDER_ID].idBlock.tagNumber === 1)
  14267. this.responderID = new RelativeDistinguishedNames({ schema: asn1.result[RESPONSE_DATA_RESPONDER_ID].valueBlock.value[0] });
  14268. else
  14269. this.responderID = asn1.result[RESPONSE_DATA_RESPONDER_ID].valueBlock.value[0];
  14270. this.producedAt = asn1.result[RESPONSE_DATA_PRODUCED_AT].toDate();
  14271. this.responses = Array.from(asn1.result[RESPONSE_DATA_RESPONSES], element => new SingleResponse({ schema: element }));
  14272. if (RESPONSE_DATA_RESPONSE_EXTENSIONS in asn1.result)
  14273. this.responseExtensions = Array.from(asn1.result[RESPONSE_DATA_RESPONSE_EXTENSIONS].valueBlock.value, element => new Extension({ schema: element }));
  14274. }
  14275. toSchema(encodeFlag = false) {
  14276. let tbsSchema;
  14277. if (encodeFlag === false) {
  14278. if (!this.tbsView.byteLength) {
  14279. return ResponseData.schema();
  14280. }
  14281. const asn1 = asn1js.fromBER(this.tbsView);
  14282. AsnError.assert(asn1, "TBS Response Data");
  14283. tbsSchema = asn1.result;
  14284. }
  14285. else {
  14286. const outputArray = [];
  14287. if (VERSION$7 in this) {
  14288. outputArray.push(new asn1js.Constructed({
  14289. idBlock: {
  14290. tagClass: 3,
  14291. tagNumber: 0
  14292. },
  14293. value: [new asn1js.Integer({ value: this.version })]
  14294. }));
  14295. }
  14296. if (this.responderID instanceof RelativeDistinguishedNames) {
  14297. outputArray.push(new asn1js.Constructed({
  14298. idBlock: {
  14299. tagClass: 3,
  14300. tagNumber: 1
  14301. },
  14302. value: [this.responderID.toSchema()]
  14303. }));
  14304. }
  14305. else {
  14306. outputArray.push(new asn1js.Constructed({
  14307. idBlock: {
  14308. tagClass: 3,
  14309. tagNumber: 2
  14310. },
  14311. value: [this.responderID]
  14312. }));
  14313. }
  14314. outputArray.push(new asn1js.GeneralizedTime({ valueDate: this.producedAt }));
  14315. outputArray.push(new asn1js.Sequence({
  14316. value: Array.from(this.responses, o => o.toSchema())
  14317. }));
  14318. if (this.responseExtensions) {
  14319. outputArray.push(new asn1js.Constructed({
  14320. idBlock: {
  14321. tagClass: 3,
  14322. tagNumber: 1
  14323. },
  14324. value: [new asn1js.Sequence({
  14325. value: Array.from(this.responseExtensions, o => o.toSchema())
  14326. })]
  14327. }));
  14328. }
  14329. tbsSchema = new asn1js.Sequence({
  14330. value: outputArray
  14331. });
  14332. }
  14333. return tbsSchema;
  14334. }
  14335. toJSON() {
  14336. const res = {};
  14337. if (VERSION$7 in this) {
  14338. res.version = this.version;
  14339. }
  14340. if (this.responderID) {
  14341. res.responderID = this.responderID;
  14342. }
  14343. if (this.producedAt) {
  14344. res.producedAt = this.producedAt;
  14345. }
  14346. if (this.responses) {
  14347. res.responses = Array.from(this.responses, o => o.toJSON());
  14348. }
  14349. if (this.responseExtensions) {
  14350. res.responseExtensions = Array.from(this.responseExtensions, o => o.toJSON());
  14351. }
  14352. return res;
  14353. }
  14354. }
  14355. ResponseData.CLASS_NAME = "ResponseData";
  14356. const TRUSTED_CERTS = "trustedCerts";
  14357. const CERTS$2 = "certs";
  14358. const CRLS$1 = "crls";
  14359. const OCSPS$1 = "ocsps";
  14360. const CHECK_DATE = "checkDate";
  14361. const FIND_ORIGIN = "findOrigin";
  14362. const FIND_ISSUER = "findIssuer";
  14363. var ChainValidationCode;
  14364. (function (ChainValidationCode) {
  14365. ChainValidationCode[ChainValidationCode["unknown"] = -1] = "unknown";
  14366. ChainValidationCode[ChainValidationCode["success"] = 0] = "success";
  14367. ChainValidationCode[ChainValidationCode["noRevocation"] = 11] = "noRevocation";
  14368. ChainValidationCode[ChainValidationCode["noPath"] = 60] = "noPath";
  14369. ChainValidationCode[ChainValidationCode["noValidPath"] = 97] = "noValidPath";
  14370. })(ChainValidationCode || (ChainValidationCode = {}));
  14371. class ChainValidationError extends Error {
  14372. constructor(code, message) {
  14373. super(message);
  14374. this.name = ChainValidationError.NAME;
  14375. this.code = code;
  14376. this.message = message;
  14377. }
  14378. }
  14379. ChainValidationError.NAME = "ChainValidationError";
  14380. function isTrusted(cert, trustedList) {
  14381. for (let i = 0; i < trustedList.length; i++) {
  14382. if (pvtsutils.BufferSourceConverter.isEqual(cert.tbsView, trustedList[i].tbsView)) {
  14383. return true;
  14384. }
  14385. }
  14386. return false;
  14387. }
  14388. class CertificateChainValidationEngine {
  14389. constructor(parameters = {}) {
  14390. this.trustedCerts = pvutils.getParametersValue(parameters, TRUSTED_CERTS, this.defaultValues(TRUSTED_CERTS));
  14391. this.certs = pvutils.getParametersValue(parameters, CERTS$2, this.defaultValues(CERTS$2));
  14392. this.crls = pvutils.getParametersValue(parameters, CRLS$1, this.defaultValues(CRLS$1));
  14393. this.ocsps = pvutils.getParametersValue(parameters, OCSPS$1, this.defaultValues(OCSPS$1));
  14394. this.checkDate = pvutils.getParametersValue(parameters, CHECK_DATE, this.defaultValues(CHECK_DATE));
  14395. this.findOrigin = pvutils.getParametersValue(parameters, FIND_ORIGIN, this.defaultValues(FIND_ORIGIN));
  14396. this.findIssuer = pvutils.getParametersValue(parameters, FIND_ISSUER, this.defaultValues(FIND_ISSUER));
  14397. }
  14398. static defaultFindOrigin(certificate, validationEngine) {
  14399. if (certificate.tbsView.byteLength === 0) {
  14400. certificate.tbsView = new Uint8Array(certificate.encodeTBS().toBER());
  14401. }
  14402. for (const localCert of validationEngine.certs) {
  14403. if (localCert.tbsView.byteLength === 0) {
  14404. localCert.tbsView = new Uint8Array(localCert.encodeTBS().toBER());
  14405. }
  14406. if (pvtsutils.BufferSourceConverter.isEqual(certificate.tbsView, localCert.tbsView))
  14407. return "Intermediate Certificates";
  14408. }
  14409. for (const trustedCert of validationEngine.trustedCerts) {
  14410. if (trustedCert.tbsView.byteLength === 0)
  14411. trustedCert.tbsView = new Uint8Array(trustedCert.encodeTBS().toBER());
  14412. if (pvtsutils.BufferSourceConverter.isEqual(certificate.tbsView, trustedCert.tbsView))
  14413. return "Trusted Certificates";
  14414. }
  14415. return "Unknown";
  14416. }
  14417. async defaultFindIssuer(certificate, validationEngine, crypto = getCrypto(true)) {
  14418. const result = [];
  14419. let keyIdentifier = null;
  14420. let authorityCertIssuer = null;
  14421. let authorityCertSerialNumber = null;
  14422. if (certificate.subject.isEqual(certificate.issuer)) {
  14423. try {
  14424. const verificationResult = await certificate.verify(undefined, crypto);
  14425. if (verificationResult) {
  14426. return [certificate];
  14427. }
  14428. }
  14429. catch {
  14430. }
  14431. }
  14432. if (certificate.extensions) {
  14433. for (const extension of certificate.extensions) {
  14434. if (extension.extnID === id_AuthorityKeyIdentifier && extension.parsedValue instanceof AuthorityKeyIdentifier) {
  14435. if (extension.parsedValue.keyIdentifier) {
  14436. keyIdentifier = extension.parsedValue.keyIdentifier;
  14437. }
  14438. else {
  14439. if (extension.parsedValue.authorityCertIssuer) {
  14440. authorityCertIssuer = extension.parsedValue.authorityCertIssuer;
  14441. }
  14442. if (extension.parsedValue.authorityCertSerialNumber) {
  14443. authorityCertSerialNumber = extension.parsedValue.authorityCertSerialNumber;
  14444. }
  14445. }
  14446. break;
  14447. }
  14448. }
  14449. }
  14450. function checkCertificate(possibleIssuer) {
  14451. if (keyIdentifier !== null) {
  14452. if (possibleIssuer.extensions) {
  14453. let extensionFound = false;
  14454. for (const extension of possibleIssuer.extensions) {
  14455. if (extension.extnID === id_SubjectKeyIdentifier && extension.parsedValue) {
  14456. extensionFound = true;
  14457. if (pvtsutils.BufferSourceConverter.isEqual(extension.parsedValue.valueBlock.valueHex, keyIdentifier.valueBlock.valueHexView)) {
  14458. result.push(possibleIssuer);
  14459. }
  14460. break;
  14461. }
  14462. }
  14463. if (extensionFound) {
  14464. return;
  14465. }
  14466. }
  14467. }
  14468. let authorityCertSerialNumberEqual = false;
  14469. if (authorityCertSerialNumber !== null)
  14470. authorityCertSerialNumberEqual = possibleIssuer.serialNumber.isEqual(authorityCertSerialNumber);
  14471. if (authorityCertIssuer !== null) {
  14472. if (possibleIssuer.subject.isEqual(authorityCertIssuer)) {
  14473. if (authorityCertSerialNumberEqual)
  14474. result.push(possibleIssuer);
  14475. }
  14476. }
  14477. else {
  14478. if (certificate.issuer.isEqual(possibleIssuer.subject))
  14479. result.push(possibleIssuer);
  14480. }
  14481. }
  14482. for (const trustedCert of validationEngine.trustedCerts) {
  14483. checkCertificate(trustedCert);
  14484. }
  14485. for (const intermediateCert of validationEngine.certs) {
  14486. checkCertificate(intermediateCert);
  14487. }
  14488. for (let i = result.length - 1; i >= 0; i--) {
  14489. try {
  14490. const verificationResult = await certificate.verify(result[i], crypto);
  14491. if (verificationResult === false)
  14492. result.splice(i, 1);
  14493. }
  14494. catch {
  14495. result.splice(i, 1);
  14496. }
  14497. }
  14498. return result;
  14499. }
  14500. defaultValues(memberName) {
  14501. switch (memberName) {
  14502. case TRUSTED_CERTS:
  14503. return [];
  14504. case CERTS$2:
  14505. return [];
  14506. case CRLS$1:
  14507. return [];
  14508. case OCSPS$1:
  14509. return [];
  14510. case CHECK_DATE:
  14511. return new Date();
  14512. case FIND_ORIGIN:
  14513. return CertificateChainValidationEngine.defaultFindOrigin;
  14514. case FIND_ISSUER:
  14515. return this.defaultFindIssuer;
  14516. default:
  14517. throw new Error(`Invalid member name for CertificateChainValidationEngine class: ${memberName}`);
  14518. }
  14519. }
  14520. async sort(passedWhenNotRevValues = false, crypto = getCrypto(true)) {
  14521. const localCerts = [];
  14522. const buildPath = async (certificate, crypto) => {
  14523. const result = [];
  14524. function checkUnique(array) {
  14525. let unique = true;
  14526. for (let i = 0; i < array.length; i++) {
  14527. for (let j = 0; j < array.length; j++) {
  14528. if (j === i)
  14529. continue;
  14530. if (array[i] === array[j]) {
  14531. unique = false;
  14532. break;
  14533. }
  14534. }
  14535. if (!unique)
  14536. break;
  14537. }
  14538. return unique;
  14539. }
  14540. if (isTrusted(certificate, this.trustedCerts)) {
  14541. return [[certificate]];
  14542. }
  14543. const findIssuerResult = await this.findIssuer(certificate, this, crypto);
  14544. if (findIssuerResult.length === 0) {
  14545. throw new Error("No valid certificate paths found");
  14546. }
  14547. for (let i = 0; i < findIssuerResult.length; i++) {
  14548. if (pvtsutils.BufferSourceConverter.isEqual(findIssuerResult[i].tbsView, certificate.tbsView)) {
  14549. result.push([findIssuerResult[i]]);
  14550. continue;
  14551. }
  14552. const buildPathResult = await buildPath(findIssuerResult[i], crypto);
  14553. for (let j = 0; j < buildPathResult.length; j++) {
  14554. const copy = buildPathResult[j].slice();
  14555. copy.splice(0, 0, findIssuerResult[i]);
  14556. if (checkUnique(copy))
  14557. result.push(copy);
  14558. else
  14559. result.push(buildPathResult[j]);
  14560. }
  14561. }
  14562. return result;
  14563. };
  14564. const findCRL = async (certificate) => {
  14565. const issuerCertificates = [];
  14566. const crls = [];
  14567. const crlsAndCertificates = [];
  14568. issuerCertificates.push(...localCerts.filter(element => certificate.issuer.isEqual(element.subject)));
  14569. if (issuerCertificates.length === 0) {
  14570. return {
  14571. status: 1,
  14572. statusMessage: "No certificate's issuers"
  14573. };
  14574. }
  14575. crls.push(...this.crls.filter(o => o.issuer.isEqual(certificate.issuer)));
  14576. if (crls.length === 0) {
  14577. return {
  14578. status: 2,
  14579. statusMessage: "No CRLs for specific certificate issuer"
  14580. };
  14581. }
  14582. for (let i = 0; i < crls.length; i++) {
  14583. const crl = crls[i];
  14584. if (crl.nextUpdate && crl.nextUpdate.value < this.checkDate) {
  14585. continue;
  14586. }
  14587. for (let j = 0; j < issuerCertificates.length; j++) {
  14588. try {
  14589. const result = await crls[i].verify({ issuerCertificate: issuerCertificates[j] }, crypto);
  14590. if (result) {
  14591. crlsAndCertificates.push({
  14592. crl: crls[i],
  14593. certificate: issuerCertificates[j]
  14594. });
  14595. break;
  14596. }
  14597. }
  14598. catch {
  14599. }
  14600. }
  14601. }
  14602. if (crlsAndCertificates.length) {
  14603. return {
  14604. status: 0,
  14605. statusMessage: EMPTY_STRING,
  14606. result: crlsAndCertificates
  14607. };
  14608. }
  14609. return {
  14610. status: 3,
  14611. statusMessage: "No valid CRLs found"
  14612. };
  14613. };
  14614. const findOCSP = async (certificate, issuerCertificate) => {
  14615. const hashAlgorithm = crypto.getAlgorithmByOID(certificate.signatureAlgorithm.algorithmId);
  14616. if (!hashAlgorithm.name) {
  14617. return 1;
  14618. }
  14619. if (!hashAlgorithm.hash) {
  14620. return 1;
  14621. }
  14622. for (let i = 0; i < this.ocsps.length; i++) {
  14623. const ocsp = this.ocsps[i];
  14624. const result = await ocsp.getCertificateStatus(certificate, issuerCertificate, crypto);
  14625. if (result.isForCertificate) {
  14626. if (result.status === 0)
  14627. return 0;
  14628. return 1;
  14629. }
  14630. }
  14631. return 2;
  14632. };
  14633. async function checkForCA(certificate, needToCheckCRL = false) {
  14634. let isCA = false;
  14635. let mustBeCA = false;
  14636. let keyUsagePresent = false;
  14637. let cRLSign = false;
  14638. if (certificate.extensions) {
  14639. for (let j = 0; j < certificate.extensions.length; j++) {
  14640. const extension = certificate.extensions[j];
  14641. if (extension.critical && !extension.parsedValue) {
  14642. return {
  14643. result: false,
  14644. resultCode: 6,
  14645. resultMessage: `Unable to parse critical certificate extension: ${extension.extnID}`
  14646. };
  14647. }
  14648. if (extension.extnID === id_KeyUsage) {
  14649. keyUsagePresent = true;
  14650. const view = new Uint8Array(extension.parsedValue.valueBlock.valueHex);
  14651. if ((view[0] & 0x04) === 0x04)
  14652. mustBeCA = true;
  14653. if ((view[0] & 0x02) === 0x02)
  14654. cRLSign = true;
  14655. }
  14656. if (extension.extnID === id_BasicConstraints) {
  14657. if ("cA" in extension.parsedValue) {
  14658. if (extension.parsedValue.cA === true)
  14659. isCA = true;
  14660. }
  14661. }
  14662. }
  14663. if ((mustBeCA === true) && (isCA === false)) {
  14664. return {
  14665. result: false,
  14666. resultCode: 3,
  14667. resultMessage: "Unable to build certificate chain - using \"keyCertSign\" flag set without BasicConstraints"
  14668. };
  14669. }
  14670. if ((keyUsagePresent === true) && (isCA === true) && (mustBeCA === false)) {
  14671. return {
  14672. result: false,
  14673. resultCode: 4,
  14674. resultMessage: "Unable to build certificate chain - \"keyCertSign\" flag was not set"
  14675. };
  14676. }
  14677. if ((isCA === true) && (keyUsagePresent === true) && ((needToCheckCRL) && (cRLSign === false))) {
  14678. return {
  14679. result: false,
  14680. resultCode: 5,
  14681. resultMessage: "Unable to build certificate chain - intermediate certificate must have \"cRLSign\" key usage flag"
  14682. };
  14683. }
  14684. }
  14685. if (isCA === false) {
  14686. return {
  14687. result: false,
  14688. resultCode: 7,
  14689. resultMessage: "Unable to build certificate chain - more than one possible end-user certificate"
  14690. };
  14691. }
  14692. return {
  14693. result: true,
  14694. resultCode: 0,
  14695. resultMessage: EMPTY_STRING
  14696. };
  14697. }
  14698. const basicCheck = async (path, checkDate) => {
  14699. for (let i = 0; i < path.length; i++) {
  14700. if ((path[i].notBefore.value > checkDate) ||
  14701. (path[i].notAfter.value < checkDate)) {
  14702. return {
  14703. result: false,
  14704. resultCode: 8,
  14705. resultMessage: "The certificate is either not yet valid or expired"
  14706. };
  14707. }
  14708. }
  14709. if (path.length < 2) {
  14710. return {
  14711. result: false,
  14712. resultCode: 9,
  14713. resultMessage: "Too short certificate path"
  14714. };
  14715. }
  14716. for (let i = (path.length - 2); i >= 0; i--) {
  14717. if (path[i].issuer.isEqual(path[i].subject) === false) {
  14718. if (path[i].issuer.isEqual(path[i + 1].subject) === false) {
  14719. return {
  14720. result: false,
  14721. resultCode: 10,
  14722. resultMessage: "Incorrect name chaining"
  14723. };
  14724. }
  14725. }
  14726. }
  14727. if ((this.crls.length !== 0) || (this.ocsps.length !== 0)) {
  14728. for (let i = 0; i < (path.length - 1); i++) {
  14729. let ocspResult = 2;
  14730. let crlResult = {
  14731. status: 0,
  14732. statusMessage: EMPTY_STRING
  14733. };
  14734. if (this.ocsps.length !== 0) {
  14735. ocspResult = await findOCSP(path[i], path[i + 1]);
  14736. switch (ocspResult) {
  14737. case 0:
  14738. continue;
  14739. case 1:
  14740. return {
  14741. result: false,
  14742. resultCode: 12,
  14743. resultMessage: "One of certificates was revoked via OCSP response"
  14744. };
  14745. }
  14746. }
  14747. if (this.crls.length !== 0) {
  14748. crlResult = await findCRL(path[i]);
  14749. if (crlResult.status === 0 && crlResult.result) {
  14750. for (let j = 0; j < crlResult.result.length; j++) {
  14751. const isCertificateRevoked = crlResult.result[j].crl.isCertificateRevoked(path[i]);
  14752. if (isCertificateRevoked) {
  14753. return {
  14754. result: false,
  14755. resultCode: 12,
  14756. resultMessage: "One of certificates had been revoked"
  14757. };
  14758. }
  14759. const isCertificateCA = await checkForCA(crlResult.result[j].certificate, true);
  14760. if (isCertificateCA.result === false) {
  14761. return {
  14762. result: false,
  14763. resultCode: 13,
  14764. resultMessage: "CRL issuer certificate is not a CA certificate or does not have crlSign flag"
  14765. };
  14766. }
  14767. }
  14768. }
  14769. else {
  14770. if (passedWhenNotRevValues === false) {
  14771. throw new ChainValidationError(ChainValidationCode.noRevocation, `No revocation values found for one of certificates: ${crlResult.statusMessage}`);
  14772. }
  14773. }
  14774. }
  14775. else {
  14776. if (ocspResult === 2) {
  14777. return {
  14778. result: false,
  14779. resultCode: 11,
  14780. resultMessage: "No revocation values found for one of certificates"
  14781. };
  14782. }
  14783. }
  14784. if ((ocspResult === 2) && (crlResult.status === 2) && passedWhenNotRevValues) {
  14785. const issuerCertificate = path[i + 1];
  14786. let extensionFound = false;
  14787. if (issuerCertificate.extensions) {
  14788. for (const extension of issuerCertificate.extensions) {
  14789. switch (extension.extnID) {
  14790. case id_CRLDistributionPoints:
  14791. case id_FreshestCRL:
  14792. case id_AuthorityInfoAccess:
  14793. extensionFound = true;
  14794. break;
  14795. }
  14796. }
  14797. }
  14798. if (extensionFound) {
  14799. throw new ChainValidationError(ChainValidationCode.noRevocation, `No revocation values found for one of certificates: ${crlResult.statusMessage}`);
  14800. }
  14801. }
  14802. }
  14803. }
  14804. for (const [i, cert] of path.entries()) {
  14805. if (!i) {
  14806. continue;
  14807. }
  14808. const result = await checkForCA(cert);
  14809. if (!result.result) {
  14810. return {
  14811. result: false,
  14812. resultCode: 14,
  14813. resultMessage: "One of intermediate certificates is not a CA certificate"
  14814. };
  14815. }
  14816. }
  14817. return {
  14818. result: true
  14819. };
  14820. };
  14821. localCerts.push(...this.trustedCerts);
  14822. localCerts.push(...this.certs);
  14823. for (let i = 0; i < localCerts.length; i++) {
  14824. for (let j = 0; j < localCerts.length; j++) {
  14825. if (i === j)
  14826. continue;
  14827. if (pvtsutils.BufferSourceConverter.isEqual(localCerts[i].tbsView, localCerts[j].tbsView)) {
  14828. localCerts.splice(j, 1);
  14829. i = 0;
  14830. break;
  14831. }
  14832. }
  14833. }
  14834. const leafCert = localCerts[localCerts.length - 1];
  14835. let result;
  14836. const certificatePath = [leafCert];
  14837. result = await buildPath(leafCert, crypto);
  14838. if (result.length === 0) {
  14839. throw new ChainValidationError(ChainValidationCode.noPath, "Unable to find certificate path");
  14840. }
  14841. for (let i = result.length - 1; i >= 0; i--) {
  14842. let found = false;
  14843. for (let j = 0; j < (result[i]).length; j++) {
  14844. const certificate = (result[i])[j];
  14845. for (let k = 0; k < this.trustedCerts.length; k++) {
  14846. if (pvtsutils.BufferSourceConverter.isEqual(certificate.tbsView, this.trustedCerts[k].tbsView)) {
  14847. found = true;
  14848. break;
  14849. }
  14850. }
  14851. if (found)
  14852. break;
  14853. }
  14854. if (!found) {
  14855. result.splice(i, 1);
  14856. }
  14857. }
  14858. if (result.length === 0) {
  14859. throw new ChainValidationError(ChainValidationCode.noValidPath, "No valid certificate paths found");
  14860. }
  14861. let shortestLength = result[0].length;
  14862. let shortestIndex = 0;
  14863. for (let i = 0; i < result.length; i++) {
  14864. if (result[i].length < shortestLength) {
  14865. shortestLength = result[i].length;
  14866. shortestIndex = i;
  14867. }
  14868. }
  14869. for (let i = 0; i < result[shortestIndex].length; i++)
  14870. certificatePath.push((result[shortestIndex])[i]);
  14871. result = await basicCheck(certificatePath, this.checkDate);
  14872. if (result.result === false)
  14873. throw result;
  14874. return certificatePath;
  14875. }
  14876. async verify(parameters = {}, crypto = getCrypto(true)) {
  14877. function compareDNSName(name, constraint) {
  14878. const namePrepared = stringPrep(name);
  14879. const constraintPrepared = stringPrep(constraint);
  14880. const nameSplitted = namePrepared.split(".");
  14881. const constraintSplitted = constraintPrepared.split(".");
  14882. const nameLen = nameSplitted.length;
  14883. const constrLen = constraintSplitted.length;
  14884. if ((nameLen === 0) || (constrLen === 0) || (nameLen < constrLen)) {
  14885. return false;
  14886. }
  14887. for (let i = 0; i < nameLen; i++) {
  14888. if (nameSplitted[i].length === 0) {
  14889. return false;
  14890. }
  14891. }
  14892. for (let i = 0; i < constrLen; i++) {
  14893. if (constraintSplitted[i].length === 0) {
  14894. if (i === 0) {
  14895. if (constrLen === 1) {
  14896. return false;
  14897. }
  14898. continue;
  14899. }
  14900. return false;
  14901. }
  14902. }
  14903. for (let i = 0; i < constrLen; i++) {
  14904. if (constraintSplitted[constrLen - 1 - i].length === 0) {
  14905. continue;
  14906. }
  14907. if (nameSplitted[nameLen - 1 - i].localeCompare(constraintSplitted[constrLen - 1 - i]) !== 0) {
  14908. return false;
  14909. }
  14910. }
  14911. return true;
  14912. }
  14913. function compareRFC822Name(name, constraint) {
  14914. const namePrepared = stringPrep(name);
  14915. const constraintPrepared = stringPrep(constraint);
  14916. const nameSplitted = namePrepared.split("@");
  14917. const constraintSplitted = constraintPrepared.split("@");
  14918. if ((nameSplitted.length === 0) || (constraintSplitted.length === 0) || (nameSplitted.length < constraintSplitted.length))
  14919. return false;
  14920. if (constraintSplitted.length === 1) {
  14921. const result = compareDNSName(nameSplitted[1], constraintSplitted[0]);
  14922. if (result) {
  14923. const ns = nameSplitted[1].split(".");
  14924. const cs = constraintSplitted[0].split(".");
  14925. if (cs[0].length === 0)
  14926. return true;
  14927. return ns.length === cs.length;
  14928. }
  14929. return false;
  14930. }
  14931. return (namePrepared.localeCompare(constraintPrepared) === 0);
  14932. }
  14933. function compareUniformResourceIdentifier(name, constraint) {
  14934. let namePrepared = stringPrep(name);
  14935. const constraintPrepared = stringPrep(constraint);
  14936. const ns = namePrepared.split("/");
  14937. const cs = constraintPrepared.split("/");
  14938. if (cs.length > 1)
  14939. return false;
  14940. if (ns.length > 1) {
  14941. for (let i = 0; i < ns.length; i++) {
  14942. if ((ns[i].length > 0) && (ns[i].charAt(ns[i].length - 1) !== ":")) {
  14943. const nsPort = ns[i].split(":");
  14944. namePrepared = nsPort[0];
  14945. break;
  14946. }
  14947. }
  14948. }
  14949. const result = compareDNSName(namePrepared, constraintPrepared);
  14950. if (result) {
  14951. const nameSplitted = namePrepared.split(".");
  14952. const constraintSplitted = constraintPrepared.split(".");
  14953. if (constraintSplitted[0].length === 0)
  14954. return true;
  14955. return nameSplitted.length === constraintSplitted.length;
  14956. }
  14957. return false;
  14958. }
  14959. function compareIPAddress(name, constraint) {
  14960. const nameView = name.valueBlock.valueHexView;
  14961. const constraintView = constraint.valueBlock.valueHexView;
  14962. if ((nameView.length === 4) && (constraintView.length === 8)) {
  14963. for (let i = 0; i < 4; i++) {
  14964. if ((nameView[i] ^ constraintView[i]) & constraintView[i + 4])
  14965. return false;
  14966. }
  14967. return true;
  14968. }
  14969. if ((nameView.length === 16) && (constraintView.length === 32)) {
  14970. for (let i = 0; i < 16; i++) {
  14971. if ((nameView[i] ^ constraintView[i]) & constraintView[i + 16])
  14972. return false;
  14973. }
  14974. return true;
  14975. }
  14976. return false;
  14977. }
  14978. function compareDirectoryName(name, constraint) {
  14979. if ((name.typesAndValues.length === 0) || (constraint.typesAndValues.length === 0))
  14980. return true;
  14981. if (name.typesAndValues.length < constraint.typesAndValues.length)
  14982. return false;
  14983. let result = true;
  14984. let nameStart = 0;
  14985. for (let i = 0; i < constraint.typesAndValues.length; i++) {
  14986. let localResult = false;
  14987. for (let j = nameStart; j < name.typesAndValues.length; j++) {
  14988. localResult = name.typesAndValues[j].isEqual(constraint.typesAndValues[i]);
  14989. if (name.typesAndValues[j].type === constraint.typesAndValues[i].type)
  14990. result = result && localResult;
  14991. if (localResult === true) {
  14992. if ((nameStart === 0) || (nameStart === j)) {
  14993. nameStart = j + 1;
  14994. break;
  14995. }
  14996. else
  14997. return false;
  14998. }
  14999. }
  15000. if (localResult === false)
  15001. return false;
  15002. }
  15003. return (nameStart === 0) ? false : result;
  15004. }
  15005. try {
  15006. if (this.certs.length === 0)
  15007. throw new Error("Empty certificate array");
  15008. const passedWhenNotRevValues = parameters.passedWhenNotRevValues || false;
  15009. const initialPolicySet = parameters.initialPolicySet || [id_AnyPolicy];
  15010. const initialExplicitPolicy = parameters.initialExplicitPolicy || false;
  15011. const initialPolicyMappingInhibit = parameters.initialPolicyMappingInhibit || false;
  15012. const initialInhibitPolicy = parameters.initialInhibitPolicy || false;
  15013. const initialPermittedSubtreesSet = parameters.initialPermittedSubtreesSet || [];
  15014. const initialExcludedSubtreesSet = parameters.initialExcludedSubtreesSet || [];
  15015. const initialRequiredNameForms = parameters.initialRequiredNameForms || [];
  15016. let explicitPolicyIndicator = initialExplicitPolicy;
  15017. let policyMappingInhibitIndicator = initialPolicyMappingInhibit;
  15018. let inhibitAnyPolicyIndicator = initialInhibitPolicy;
  15019. const pendingConstraints = [
  15020. false,
  15021. false,
  15022. false,
  15023. ];
  15024. let explicitPolicyPending = 0;
  15025. let policyMappingInhibitPending = 0;
  15026. let inhibitAnyPolicyPending = 0;
  15027. let permittedSubtrees = initialPermittedSubtreesSet;
  15028. let excludedSubtrees = initialExcludedSubtreesSet;
  15029. const requiredNameForms = initialRequiredNameForms;
  15030. let pathDepth = 1;
  15031. this.certs = await this.sort(passedWhenNotRevValues, crypto);
  15032. const allPolicies = [];
  15033. allPolicies.push(id_AnyPolicy);
  15034. const policiesAndCerts = [];
  15035. const anyPolicyArray = new Array(this.certs.length - 1);
  15036. for (let ii = 0; ii < (this.certs.length - 1); ii++)
  15037. anyPolicyArray[ii] = true;
  15038. policiesAndCerts.push(anyPolicyArray);
  15039. const policyMappings = new Array(this.certs.length - 1);
  15040. const certPolicies = new Array(this.certs.length - 1);
  15041. let explicitPolicyStart = (explicitPolicyIndicator) ? (this.certs.length - 1) : (-1);
  15042. for (let i = (this.certs.length - 2); i >= 0; i--, pathDepth++) {
  15043. const cert = this.certs[i];
  15044. if (cert.extensions) {
  15045. for (let j = 0; j < cert.extensions.length; j++) {
  15046. const extension = cert.extensions[j];
  15047. if (extension.extnID === id_CertificatePolicies) {
  15048. certPolicies[i] = extension.parsedValue;
  15049. for (let s = 0; s < allPolicies.length; s++) {
  15050. if (allPolicies[s] === id_AnyPolicy) {
  15051. delete (policiesAndCerts[s])[i];
  15052. break;
  15053. }
  15054. }
  15055. for (let k = 0; k < extension.parsedValue.certificatePolicies.length; k++) {
  15056. let policyIndex = (-1);
  15057. const policyId = extension.parsedValue.certificatePolicies[k].policyIdentifier;
  15058. for (let s = 0; s < allPolicies.length; s++) {
  15059. if (policyId === allPolicies[s]) {
  15060. policyIndex = s;
  15061. break;
  15062. }
  15063. }
  15064. if (policyIndex === (-1)) {
  15065. allPolicies.push(policyId);
  15066. const certArray = new Array(this.certs.length - 1);
  15067. certArray[i] = true;
  15068. policiesAndCerts.push(certArray);
  15069. }
  15070. else
  15071. (policiesAndCerts[policyIndex])[i] = true;
  15072. }
  15073. }
  15074. if (extension.extnID === id_PolicyMappings) {
  15075. if (policyMappingInhibitIndicator) {
  15076. return {
  15077. result: false,
  15078. resultCode: 98,
  15079. resultMessage: "Policy mapping prohibited"
  15080. };
  15081. }
  15082. policyMappings[i] = extension.parsedValue;
  15083. }
  15084. if (extension.extnID === id_PolicyConstraints) {
  15085. if (explicitPolicyIndicator === false) {
  15086. if (extension.parsedValue.requireExplicitPolicy === 0) {
  15087. explicitPolicyIndicator = true;
  15088. explicitPolicyStart = i;
  15089. }
  15090. else {
  15091. if (pendingConstraints[0] === false) {
  15092. pendingConstraints[0] = true;
  15093. explicitPolicyPending = extension.parsedValue.requireExplicitPolicy;
  15094. }
  15095. else
  15096. explicitPolicyPending = (explicitPolicyPending > extension.parsedValue.requireExplicitPolicy) ? extension.parsedValue.requireExplicitPolicy : explicitPolicyPending;
  15097. }
  15098. if (extension.parsedValue.inhibitPolicyMapping === 0)
  15099. policyMappingInhibitIndicator = true;
  15100. else {
  15101. if (pendingConstraints[1] === false) {
  15102. pendingConstraints[1] = true;
  15103. policyMappingInhibitPending = extension.parsedValue.inhibitPolicyMapping + 1;
  15104. }
  15105. else
  15106. policyMappingInhibitPending = (policyMappingInhibitPending > (extension.parsedValue.inhibitPolicyMapping + 1)) ? (extension.parsedValue.inhibitPolicyMapping + 1) : policyMappingInhibitPending;
  15107. }
  15108. }
  15109. }
  15110. if (extension.extnID === id_InhibitAnyPolicy) {
  15111. if (inhibitAnyPolicyIndicator === false) {
  15112. if (extension.parsedValue.valueBlock.valueDec === 0)
  15113. inhibitAnyPolicyIndicator = true;
  15114. else {
  15115. if (pendingConstraints[2] === false) {
  15116. pendingConstraints[2] = true;
  15117. inhibitAnyPolicyPending = extension.parsedValue.valueBlock.valueDec;
  15118. }
  15119. else
  15120. inhibitAnyPolicyPending = (inhibitAnyPolicyPending > extension.parsedValue.valueBlock.valueDec) ? extension.parsedValue.valueBlock.valueDec : inhibitAnyPolicyPending;
  15121. }
  15122. }
  15123. }
  15124. }
  15125. if (inhibitAnyPolicyIndicator === true) {
  15126. let policyIndex = (-1);
  15127. for (let searchAnyPolicy = 0; searchAnyPolicy < allPolicies.length; searchAnyPolicy++) {
  15128. if (allPolicies[searchAnyPolicy] === id_AnyPolicy) {
  15129. policyIndex = searchAnyPolicy;
  15130. break;
  15131. }
  15132. }
  15133. if (policyIndex !== (-1))
  15134. delete (policiesAndCerts[0])[i];
  15135. }
  15136. if (explicitPolicyIndicator === false) {
  15137. if (pendingConstraints[0] === true) {
  15138. explicitPolicyPending--;
  15139. if (explicitPolicyPending === 0) {
  15140. explicitPolicyIndicator = true;
  15141. explicitPolicyStart = i;
  15142. pendingConstraints[0] = false;
  15143. }
  15144. }
  15145. }
  15146. if (policyMappingInhibitIndicator === false) {
  15147. if (pendingConstraints[1] === true) {
  15148. policyMappingInhibitPending--;
  15149. if (policyMappingInhibitPending === 0) {
  15150. policyMappingInhibitIndicator = true;
  15151. pendingConstraints[1] = false;
  15152. }
  15153. }
  15154. }
  15155. if (inhibitAnyPolicyIndicator === false) {
  15156. if (pendingConstraints[2] === true) {
  15157. inhibitAnyPolicyPending--;
  15158. if (inhibitAnyPolicyPending === 0) {
  15159. inhibitAnyPolicyIndicator = true;
  15160. pendingConstraints[2] = false;
  15161. }
  15162. }
  15163. }
  15164. }
  15165. }
  15166. for (let i = 0; i < (this.certs.length - 1); i++) {
  15167. if ((i < (this.certs.length - 2)) && (typeof policyMappings[i + 1] !== "undefined")) {
  15168. for (let k = 0; k < policyMappings[i + 1].mappings.length; k++) {
  15169. if ((policyMappings[i + 1].mappings[k].issuerDomainPolicy === id_AnyPolicy) || (policyMappings[i + 1].mappings[k].subjectDomainPolicy === id_AnyPolicy)) {
  15170. return {
  15171. result: false,
  15172. resultCode: 99,
  15173. resultMessage: "The \"anyPolicy\" should not be a part of policy mapping scheme"
  15174. };
  15175. }
  15176. let issuerDomainPolicyIndex = (-1);
  15177. let subjectDomainPolicyIndex = (-1);
  15178. for (let n = 0; n < allPolicies.length; n++) {
  15179. if (allPolicies[n] === policyMappings[i + 1].mappings[k].issuerDomainPolicy)
  15180. issuerDomainPolicyIndex = n;
  15181. if (allPolicies[n] === policyMappings[i + 1].mappings[k].subjectDomainPolicy)
  15182. subjectDomainPolicyIndex = n;
  15183. }
  15184. if (typeof (policiesAndCerts[issuerDomainPolicyIndex])[i] !== "undefined")
  15185. delete (policiesAndCerts[issuerDomainPolicyIndex])[i];
  15186. for (let j = 0; j < certPolicies[i].certificatePolicies.length; j++) {
  15187. if (policyMappings[i + 1].mappings[k].subjectDomainPolicy === certPolicies[i].certificatePolicies[j].policyIdentifier) {
  15188. if ((issuerDomainPolicyIndex !== (-1)) && (subjectDomainPolicyIndex !== (-1))) {
  15189. for (let m = 0; m <= i; m++) {
  15190. if (typeof (policiesAndCerts[subjectDomainPolicyIndex])[m] !== "undefined") {
  15191. (policiesAndCerts[issuerDomainPolicyIndex])[m] = true;
  15192. delete (policiesAndCerts[subjectDomainPolicyIndex])[m];
  15193. }
  15194. }
  15195. }
  15196. }
  15197. }
  15198. }
  15199. }
  15200. }
  15201. for (let i = 0; i < allPolicies.length; i++) {
  15202. if (allPolicies[i] === id_AnyPolicy) {
  15203. for (let j = 0; j < explicitPolicyStart; j++)
  15204. delete (policiesAndCerts[i])[j];
  15205. }
  15206. }
  15207. const authConstrPolicies = [];
  15208. for (let i = 0; i < policiesAndCerts.length; i++) {
  15209. let found = true;
  15210. for (let j = 0; j < (this.certs.length - 1); j++) {
  15211. let anyPolicyFound = false;
  15212. if ((j < explicitPolicyStart) && (allPolicies[i] === id_AnyPolicy) && (allPolicies.length > 1)) {
  15213. found = false;
  15214. break;
  15215. }
  15216. if (typeof (policiesAndCerts[i])[j] === "undefined") {
  15217. if (j >= explicitPolicyStart) {
  15218. for (let k = 0; k < allPolicies.length; k++) {
  15219. if (allPolicies[k] === id_AnyPolicy) {
  15220. if ((policiesAndCerts[k])[j] === true)
  15221. anyPolicyFound = true;
  15222. break;
  15223. }
  15224. }
  15225. }
  15226. if (!anyPolicyFound) {
  15227. found = false;
  15228. break;
  15229. }
  15230. }
  15231. }
  15232. if (found === true)
  15233. authConstrPolicies.push(allPolicies[i]);
  15234. }
  15235. let userConstrPolicies = [];
  15236. if ((initialPolicySet.length === 1) && (initialPolicySet[0] === id_AnyPolicy) && (explicitPolicyIndicator === false))
  15237. userConstrPolicies = initialPolicySet;
  15238. else {
  15239. if ((authConstrPolicies.length === 1) && (authConstrPolicies[0] === id_AnyPolicy))
  15240. userConstrPolicies = initialPolicySet;
  15241. else {
  15242. for (let i = 0; i < authConstrPolicies.length; i++) {
  15243. for (let j = 0; j < initialPolicySet.length; j++) {
  15244. if ((initialPolicySet[j] === authConstrPolicies[i]) || (initialPolicySet[j] === id_AnyPolicy)) {
  15245. userConstrPolicies.push(authConstrPolicies[i]);
  15246. break;
  15247. }
  15248. }
  15249. }
  15250. }
  15251. }
  15252. const policyResult = {
  15253. result: (userConstrPolicies.length > 0),
  15254. resultCode: 0,
  15255. resultMessage: (userConstrPolicies.length > 0) ? EMPTY_STRING : "Zero \"userConstrPolicies\" array, no intersections with \"authConstrPolicies\"",
  15256. authConstrPolicies,
  15257. userConstrPolicies,
  15258. explicitPolicyIndicator,
  15259. policyMappings,
  15260. certificatePath: this.certs
  15261. };
  15262. if (userConstrPolicies.length === 0)
  15263. return policyResult;
  15264. if (policyResult.result === false)
  15265. return policyResult;
  15266. pathDepth = 1;
  15267. for (let i = (this.certs.length - 2); i >= 0; i--, pathDepth++) {
  15268. const cert = this.certs[i];
  15269. let subjectAltNames = [];
  15270. let certPermittedSubtrees = [];
  15271. let certExcludedSubtrees = [];
  15272. if (cert.extensions) {
  15273. for (let j = 0; j < cert.extensions.length; j++) {
  15274. const extension = cert.extensions[j];
  15275. if (extension.extnID === id_NameConstraints) {
  15276. if ("permittedSubtrees" in extension.parsedValue)
  15277. certPermittedSubtrees = certPermittedSubtrees.concat(extension.parsedValue.permittedSubtrees);
  15278. if ("excludedSubtrees" in extension.parsedValue)
  15279. certExcludedSubtrees = certExcludedSubtrees.concat(extension.parsedValue.excludedSubtrees);
  15280. }
  15281. if (extension.extnID === id_SubjectAltName)
  15282. subjectAltNames = subjectAltNames.concat(extension.parsedValue.altNames);
  15283. }
  15284. }
  15285. let formFound = (requiredNameForms.length <= 0);
  15286. for (let j = 0; j < requiredNameForms.length; j++) {
  15287. switch (requiredNameForms[j].base.type) {
  15288. case 4:
  15289. {
  15290. if (requiredNameForms[j].base.value.typesAndValues.length !== cert.subject.typesAndValues.length)
  15291. continue;
  15292. formFound = true;
  15293. for (let k = 0; k < cert.subject.typesAndValues.length; k++) {
  15294. if (cert.subject.typesAndValues[k].type !== requiredNameForms[j].base.value.typesAndValues[k].type) {
  15295. formFound = false;
  15296. break;
  15297. }
  15298. }
  15299. if (formFound === true)
  15300. break;
  15301. }
  15302. break;
  15303. default:
  15304. }
  15305. }
  15306. if (formFound === false) {
  15307. policyResult.result = false;
  15308. policyResult.resultCode = 21;
  15309. policyResult.resultMessage = "No necessary name form found";
  15310. throw policyResult;
  15311. }
  15312. const constrGroups = [
  15313. [],
  15314. [],
  15315. [],
  15316. [],
  15317. [],
  15318. ];
  15319. for (let j = 0; j < permittedSubtrees.length; j++) {
  15320. switch (permittedSubtrees[j].base.type) {
  15321. case 1:
  15322. constrGroups[0].push(permittedSubtrees[j]);
  15323. break;
  15324. case 2:
  15325. constrGroups[1].push(permittedSubtrees[j]);
  15326. break;
  15327. case 4:
  15328. constrGroups[2].push(permittedSubtrees[j]);
  15329. break;
  15330. case 6:
  15331. constrGroups[3].push(permittedSubtrees[j]);
  15332. break;
  15333. case 7:
  15334. constrGroups[4].push(permittedSubtrees[j]);
  15335. break;
  15336. default:
  15337. }
  15338. }
  15339. for (let p = 0; p < 5; p++) {
  15340. let groupPermitted = false;
  15341. let valueExists = false;
  15342. const group = constrGroups[p];
  15343. for (let j = 0; j < group.length; j++) {
  15344. switch (p) {
  15345. case 0:
  15346. if (subjectAltNames.length > 0) {
  15347. for (let k = 0; k < subjectAltNames.length; k++) {
  15348. if (subjectAltNames[k].type === 1) {
  15349. valueExists = true;
  15350. groupPermitted = groupPermitted || compareRFC822Name(subjectAltNames[k].value, group[j].base.value);
  15351. }
  15352. }
  15353. }
  15354. else {
  15355. for (let k = 0; k < cert.subject.typesAndValues.length; k++) {
  15356. if ((cert.subject.typesAndValues[k].type === "1.2.840.113549.1.9.1") ||
  15357. (cert.subject.typesAndValues[k].type === "0.9.2342.19200300.100.1.3")) {
  15358. valueExists = true;
  15359. groupPermitted = groupPermitted || compareRFC822Name(cert.subject.typesAndValues[k].value.valueBlock.value, group[j].base.value);
  15360. }
  15361. }
  15362. }
  15363. break;
  15364. case 1:
  15365. if (subjectAltNames.length > 0) {
  15366. for (let k = 0; k < subjectAltNames.length; k++) {
  15367. if (subjectAltNames[k].type === 2) {
  15368. valueExists = true;
  15369. groupPermitted = groupPermitted || compareDNSName(subjectAltNames[k].value, group[j].base.value);
  15370. }
  15371. }
  15372. }
  15373. break;
  15374. case 2:
  15375. valueExists = true;
  15376. groupPermitted = compareDirectoryName(cert.subject, group[j].base.value);
  15377. break;
  15378. case 3:
  15379. if (subjectAltNames.length > 0) {
  15380. for (let k = 0; k < subjectAltNames.length; k++) {
  15381. if (subjectAltNames[k].type === 6) {
  15382. valueExists = true;
  15383. groupPermitted = groupPermitted || compareUniformResourceIdentifier(subjectAltNames[k].value, group[j].base.value);
  15384. }
  15385. }
  15386. }
  15387. break;
  15388. case 4:
  15389. if (subjectAltNames.length > 0) {
  15390. for (let k = 0; k < subjectAltNames.length; k++) {
  15391. if (subjectAltNames[k].type === 7) {
  15392. valueExists = true;
  15393. groupPermitted = groupPermitted || compareIPAddress(subjectAltNames[k].value, group[j].base.value);
  15394. }
  15395. }
  15396. }
  15397. break;
  15398. default:
  15399. }
  15400. if (groupPermitted)
  15401. break;
  15402. }
  15403. if ((groupPermitted === false) && (group.length > 0) && valueExists) {
  15404. policyResult.result = false;
  15405. policyResult.resultCode = 41;
  15406. policyResult.resultMessage = "Failed to meet \"permitted sub-trees\" name constraint";
  15407. throw policyResult;
  15408. }
  15409. }
  15410. let excluded = false;
  15411. for (let j = 0; j < excludedSubtrees.length; j++) {
  15412. switch (excludedSubtrees[j].base.type) {
  15413. case 1:
  15414. if (subjectAltNames.length >= 0) {
  15415. for (let k = 0; k < subjectAltNames.length; k++) {
  15416. if (subjectAltNames[k].type === 1)
  15417. excluded = excluded || compareRFC822Name(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15418. }
  15419. }
  15420. else {
  15421. for (let k = 0; k < cert.subject.typesAndValues.length; k++) {
  15422. if ((cert.subject.typesAndValues[k].type === "1.2.840.113549.1.9.1") ||
  15423. (cert.subject.typesAndValues[k].type === "0.9.2342.19200300.100.1.3"))
  15424. excluded = excluded || compareRFC822Name(cert.subject.typesAndValues[k].value.valueBlock.value, excludedSubtrees[j].base.value);
  15425. }
  15426. }
  15427. break;
  15428. case 2:
  15429. if (subjectAltNames.length > 0) {
  15430. for (let k = 0; k < subjectAltNames.length; k++) {
  15431. if (subjectAltNames[k].type === 2)
  15432. excluded = excluded || compareDNSName(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15433. }
  15434. }
  15435. break;
  15436. case 4:
  15437. excluded = excluded || compareDirectoryName(cert.subject, excludedSubtrees[j].base.value);
  15438. break;
  15439. case 6:
  15440. if (subjectAltNames.length > 0) {
  15441. for (let k = 0; k < subjectAltNames.length; k++) {
  15442. if (subjectAltNames[k].type === 6)
  15443. excluded = excluded || compareUniformResourceIdentifier(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15444. }
  15445. }
  15446. break;
  15447. case 7:
  15448. if (subjectAltNames.length > 0) {
  15449. for (let k = 0; k < subjectAltNames.length; k++) {
  15450. if (subjectAltNames[k].type === 7)
  15451. excluded = excluded || compareIPAddress(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15452. }
  15453. }
  15454. break;
  15455. default:
  15456. }
  15457. if (excluded)
  15458. break;
  15459. }
  15460. if (excluded === true) {
  15461. policyResult.result = false;
  15462. policyResult.resultCode = 42;
  15463. policyResult.resultMessage = "Failed to meet \"excluded sub-trees\" name constraint";
  15464. throw policyResult;
  15465. }
  15466. permittedSubtrees = permittedSubtrees.concat(certPermittedSubtrees);
  15467. excludedSubtrees = excludedSubtrees.concat(certExcludedSubtrees);
  15468. }
  15469. return policyResult;
  15470. }
  15471. catch (error) {
  15472. if (error instanceof Error) {
  15473. if (error instanceof ChainValidationError) {
  15474. return {
  15475. result: false,
  15476. resultCode: error.code,
  15477. resultMessage: error.message,
  15478. error: error,
  15479. };
  15480. }
  15481. return {
  15482. result: false,
  15483. resultCode: ChainValidationCode.unknown,
  15484. resultMessage: error.message,
  15485. error: error,
  15486. };
  15487. }
  15488. if (error && typeof error === "object" && "resultMessage" in error) {
  15489. return error;
  15490. }
  15491. return {
  15492. result: false,
  15493. resultCode: -1,
  15494. resultMessage: `${error}`,
  15495. };
  15496. }
  15497. }
  15498. }
  15499. const TBS_RESPONSE_DATA = "tbsResponseData";
  15500. const SIGNATURE_ALGORITHM$3 = "signatureAlgorithm";
  15501. const SIGNATURE$2 = "signature";
  15502. const CERTS$1 = "certs";
  15503. const BASIC_OCSP_RESPONSE = "BasicOCSPResponse";
  15504. const BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA = `${BASIC_OCSP_RESPONSE}.${TBS_RESPONSE_DATA}`;
  15505. const BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM = `${BASIC_OCSP_RESPONSE}.${SIGNATURE_ALGORITHM$3}`;
  15506. const BASIC_OCSP_RESPONSE_SIGNATURE = `${BASIC_OCSP_RESPONSE}.${SIGNATURE$2}`;
  15507. const BASIC_OCSP_RESPONSE_CERTS = `${BASIC_OCSP_RESPONSE}.${CERTS$1}`;
  15508. const CLEAR_PROPS$g = [
  15509. BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA,
  15510. BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM,
  15511. BASIC_OCSP_RESPONSE_SIGNATURE,
  15512. BASIC_OCSP_RESPONSE_CERTS
  15513. ];
  15514. class BasicOCSPResponse extends PkiObject {
  15515. constructor(parameters = {}) {
  15516. super();
  15517. this.tbsResponseData = pvutils.getParametersValue(parameters, TBS_RESPONSE_DATA, BasicOCSPResponse.defaultValues(TBS_RESPONSE_DATA));
  15518. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$3, BasicOCSPResponse.defaultValues(SIGNATURE_ALGORITHM$3));
  15519. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$2, BasicOCSPResponse.defaultValues(SIGNATURE$2));
  15520. if (CERTS$1 in parameters) {
  15521. this.certs = pvutils.getParametersValue(parameters, CERTS$1, BasicOCSPResponse.defaultValues(CERTS$1));
  15522. }
  15523. if (parameters.schema) {
  15524. this.fromSchema(parameters.schema);
  15525. }
  15526. }
  15527. static defaultValues(memberName) {
  15528. switch (memberName) {
  15529. case TBS_RESPONSE_DATA:
  15530. return new ResponseData();
  15531. case SIGNATURE_ALGORITHM$3:
  15532. return new AlgorithmIdentifier();
  15533. case SIGNATURE$2:
  15534. return new asn1js.BitString();
  15535. case CERTS$1:
  15536. return [];
  15537. default:
  15538. return super.defaultValues(memberName);
  15539. }
  15540. }
  15541. static compareWithDefault(memberName, memberValue) {
  15542. switch (memberName) {
  15543. case "type":
  15544. {
  15545. let comparisonResult = ((ResponseData.compareWithDefault("tbs", memberValue.tbs)) &&
  15546. (ResponseData.compareWithDefault("responderID", memberValue.responderID)) &&
  15547. (ResponseData.compareWithDefault("producedAt", memberValue.producedAt)) &&
  15548. (ResponseData.compareWithDefault("responses", memberValue.responses)));
  15549. if ("responseExtensions" in memberValue)
  15550. comparisonResult = comparisonResult && (ResponseData.compareWithDefault("responseExtensions", memberValue.responseExtensions));
  15551. return comparisonResult;
  15552. }
  15553. case SIGNATURE_ALGORITHM$3:
  15554. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  15555. case SIGNATURE$2:
  15556. return (memberValue.isEqual(BasicOCSPResponse.defaultValues(memberName)));
  15557. case CERTS$1:
  15558. return (memberValue.length === 0);
  15559. default:
  15560. return super.defaultValues(memberName);
  15561. }
  15562. }
  15563. static schema(parameters = {}) {
  15564. const names = pvutils.getParametersValue(parameters, "names", {});
  15565. return (new asn1js.Sequence({
  15566. name: (names.blockName || BASIC_OCSP_RESPONSE),
  15567. value: [
  15568. ResponseData.schema(names.tbsResponseData || {
  15569. names: {
  15570. blockName: BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA
  15571. }
  15572. }),
  15573. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  15574. names: {
  15575. blockName: BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM
  15576. }
  15577. }),
  15578. new asn1js.BitString({ name: (names.signature || BASIC_OCSP_RESPONSE_SIGNATURE) }),
  15579. new asn1js.Constructed({
  15580. optional: true,
  15581. idBlock: {
  15582. tagClass: 3,
  15583. tagNumber: 0
  15584. },
  15585. value: [
  15586. new asn1js.Sequence({
  15587. value: [new asn1js.Repeated({
  15588. name: BASIC_OCSP_RESPONSE_CERTS,
  15589. value: Certificate.schema(names.certs || {})
  15590. })]
  15591. })
  15592. ]
  15593. })
  15594. ]
  15595. }));
  15596. }
  15597. fromSchema(schema) {
  15598. pvutils.clearProps(schema, CLEAR_PROPS$g);
  15599. const asn1 = asn1js.compareSchema(schema, schema, BasicOCSPResponse.schema());
  15600. AsnError.assertSchema(asn1, this.className);
  15601. this.tbsResponseData = new ResponseData({ schema: asn1.result[BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA] });
  15602. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result[BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM] });
  15603. this.signature = asn1.result[BASIC_OCSP_RESPONSE_SIGNATURE];
  15604. if (BASIC_OCSP_RESPONSE_CERTS in asn1.result) {
  15605. this.certs = Array.from(asn1.result[BASIC_OCSP_RESPONSE_CERTS], element => new Certificate({ schema: element }));
  15606. }
  15607. }
  15608. toSchema() {
  15609. const outputArray = [];
  15610. outputArray.push(this.tbsResponseData.toSchema());
  15611. outputArray.push(this.signatureAlgorithm.toSchema());
  15612. outputArray.push(this.signature);
  15613. if (this.certs) {
  15614. outputArray.push(new asn1js.Constructed({
  15615. idBlock: {
  15616. tagClass: 3,
  15617. tagNumber: 0
  15618. },
  15619. value: [
  15620. new asn1js.Sequence({
  15621. value: Array.from(this.certs, o => o.toSchema())
  15622. })
  15623. ]
  15624. }));
  15625. }
  15626. return (new asn1js.Sequence({
  15627. value: outputArray
  15628. }));
  15629. }
  15630. toJSON() {
  15631. const res = {
  15632. tbsResponseData: this.tbsResponseData.toJSON(),
  15633. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  15634. signature: this.signature.toJSON(),
  15635. };
  15636. if (this.certs) {
  15637. res.certs = Array.from(this.certs, o => o.toJSON());
  15638. }
  15639. return res;
  15640. }
  15641. async getCertificateStatus(certificate, issuerCertificate, crypto = getCrypto(true)) {
  15642. const result = {
  15643. isForCertificate: false,
  15644. status: 2
  15645. };
  15646. const hashesObject = {};
  15647. const certIDs = [];
  15648. for (const response of this.tbsResponseData.responses) {
  15649. const hashAlgorithm = crypto.getAlgorithmByOID(response.certID.hashAlgorithm.algorithmId, true, "CertID.hashAlgorithm");
  15650. if (!hashesObject[hashAlgorithm.name]) {
  15651. hashesObject[hashAlgorithm.name] = 1;
  15652. const certID = new CertID();
  15653. certIDs.push(certID);
  15654. await certID.createForCertificate(certificate, {
  15655. hashAlgorithm: hashAlgorithm.name,
  15656. issuerCertificate
  15657. }, crypto);
  15658. }
  15659. }
  15660. for (const response of this.tbsResponseData.responses) {
  15661. for (const id of certIDs) {
  15662. if (response.certID.isEqual(id)) {
  15663. result.isForCertificate = true;
  15664. try {
  15665. switch (response.certStatus.idBlock.isConstructed) {
  15666. case true:
  15667. if (response.certStatus.idBlock.tagNumber === 1)
  15668. result.status = 1;
  15669. break;
  15670. case false:
  15671. switch (response.certStatus.idBlock.tagNumber) {
  15672. case 0:
  15673. result.status = 0;
  15674. break;
  15675. case 2:
  15676. result.status = 2;
  15677. break;
  15678. default:
  15679. }
  15680. break;
  15681. default:
  15682. }
  15683. }
  15684. catch {
  15685. }
  15686. return result;
  15687. }
  15688. }
  15689. }
  15690. return result;
  15691. }
  15692. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  15693. if (!privateKey) {
  15694. throw new Error("Need to provide a private key for signing");
  15695. }
  15696. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  15697. const algorithm = signatureParams.parameters.algorithm;
  15698. if (!("name" in algorithm)) {
  15699. throw new Error("Empty algorithm");
  15700. }
  15701. this.signatureAlgorithm = signatureParams.signatureAlgorithm;
  15702. this.tbsResponseData.tbsView = new Uint8Array(this.tbsResponseData.toSchema(true).toBER());
  15703. const signature = await crypto.signWithPrivateKey(this.tbsResponseData.tbsView, privateKey, { algorithm });
  15704. this.signature = new asn1js.BitString({ valueHex: signature });
  15705. }
  15706. async verify(params = {}, crypto = getCrypto(true)) {
  15707. let signerCert = null;
  15708. let certIndex = -1;
  15709. const trustedCerts = params.trustedCerts || [];
  15710. if (!this.certs) {
  15711. throw new Error("No certificates attached to the BasicOCSPResponse");
  15712. }
  15713. switch (true) {
  15714. case (this.tbsResponseData.responderID instanceof RelativeDistinguishedNames):
  15715. for (const [index, certificate] of this.certs.entries()) {
  15716. if (certificate.subject.isEqual(this.tbsResponseData.responderID)) {
  15717. certIndex = index;
  15718. break;
  15719. }
  15720. }
  15721. break;
  15722. case (this.tbsResponseData.responderID instanceof asn1js.OctetString):
  15723. for (const [index, cert] of this.certs.entries()) {
  15724. const hash = await crypto.digest({ name: "sha-1" }, cert.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView);
  15725. if (pvutils.isEqualBuffer(hash, this.tbsResponseData.responderID.valueBlock.valueHex)) {
  15726. certIndex = index;
  15727. break;
  15728. }
  15729. }
  15730. break;
  15731. default:
  15732. throw new Error("Wrong value for responderID");
  15733. }
  15734. if (certIndex === (-1))
  15735. throw new Error("Correct certificate was not found in OCSP response");
  15736. signerCert = this.certs[certIndex];
  15737. const additionalCerts = [signerCert];
  15738. for (const cert of this.certs) {
  15739. const caCert = await checkCA(cert, signerCert);
  15740. if (caCert) {
  15741. additionalCerts.push(caCert);
  15742. }
  15743. }
  15744. const certChain = new CertificateChainValidationEngine({
  15745. certs: additionalCerts,
  15746. trustedCerts,
  15747. });
  15748. const verificationResult = await certChain.verify({}, crypto);
  15749. if (!verificationResult.result) {
  15750. throw new Error("Validation of signer's certificate failed");
  15751. }
  15752. return crypto.verifyWithPublicKey(this.tbsResponseData.tbsView, this.signature, this.certs[certIndex].subjectPublicKeyInfo, this.signatureAlgorithm);
  15753. }
  15754. }
  15755. BasicOCSPResponse.CLASS_NAME = "BasicOCSPResponse";
  15756. const TBS$1 = "tbs";
  15757. const VERSION$6 = "version";
  15758. const SUBJECT = "subject";
  15759. const SPKI = "subjectPublicKeyInfo";
  15760. const ATTRIBUTES$1 = "attributes";
  15761. const SIGNATURE_ALGORITHM$2 = "signatureAlgorithm";
  15762. const SIGNATURE_VALUE = "signatureValue";
  15763. const CSR_INFO = "CertificationRequestInfo";
  15764. const CSR_INFO_VERSION = `${CSR_INFO}.version`;
  15765. const CSR_INFO_SUBJECT = `${CSR_INFO}.subject`;
  15766. const CSR_INFO_SPKI = `${CSR_INFO}.subjectPublicKeyInfo`;
  15767. const CSR_INFO_ATTRS = `${CSR_INFO}.attributes`;
  15768. const CLEAR_PROPS$f = [
  15769. CSR_INFO,
  15770. CSR_INFO_VERSION,
  15771. CSR_INFO_SUBJECT,
  15772. CSR_INFO_SPKI,
  15773. CSR_INFO_ATTRS,
  15774. SIGNATURE_ALGORITHM$2,
  15775. SIGNATURE_VALUE
  15776. ];
  15777. function CertificationRequestInfo(parameters = {}) {
  15778. const names = pvutils.getParametersValue(parameters, "names", {});
  15779. return (new asn1js.Sequence({
  15780. name: (names.CertificationRequestInfo || CSR_INFO),
  15781. value: [
  15782. new asn1js.Integer({ name: (names.CertificationRequestInfoVersion || CSR_INFO_VERSION) }),
  15783. RelativeDistinguishedNames.schema(names.subject || {
  15784. names: {
  15785. blockName: CSR_INFO_SUBJECT
  15786. }
  15787. }),
  15788. PublicKeyInfo.schema({
  15789. names: {
  15790. blockName: CSR_INFO_SPKI
  15791. }
  15792. }),
  15793. new asn1js.Constructed({
  15794. optional: true,
  15795. idBlock: {
  15796. tagClass: 3,
  15797. tagNumber: 0
  15798. },
  15799. value: [
  15800. new asn1js.Repeated({
  15801. optional: true,
  15802. name: (names.CertificationRequestInfoAttributes || CSR_INFO_ATTRS),
  15803. value: Attribute.schema(names.attributes || {})
  15804. })
  15805. ]
  15806. })
  15807. ]
  15808. }));
  15809. }
  15810. class CertificationRequest extends PkiObject {
  15811. get tbs() {
  15812. return pvtsutils.BufferSourceConverter.toArrayBuffer(this.tbsView);
  15813. }
  15814. set tbs(value) {
  15815. this.tbsView = new Uint8Array(value);
  15816. }
  15817. constructor(parameters = {}) {
  15818. super();
  15819. this.tbsView = new Uint8Array(pvutils.getParametersValue(parameters, TBS$1, CertificationRequest.defaultValues(TBS$1)));
  15820. this.version = pvutils.getParametersValue(parameters, VERSION$6, CertificationRequest.defaultValues(VERSION$6));
  15821. this.subject = pvutils.getParametersValue(parameters, SUBJECT, CertificationRequest.defaultValues(SUBJECT));
  15822. this.subjectPublicKeyInfo = pvutils.getParametersValue(parameters, SPKI, CertificationRequest.defaultValues(SPKI));
  15823. if (ATTRIBUTES$1 in parameters) {
  15824. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES$1, CertificationRequest.defaultValues(ATTRIBUTES$1));
  15825. }
  15826. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$2, CertificationRequest.defaultValues(SIGNATURE_ALGORITHM$2));
  15827. this.signatureValue = pvutils.getParametersValue(parameters, SIGNATURE_VALUE, CertificationRequest.defaultValues(SIGNATURE_VALUE));
  15828. if (parameters.schema) {
  15829. this.fromSchema(parameters.schema);
  15830. }
  15831. }
  15832. static defaultValues(memberName) {
  15833. switch (memberName) {
  15834. case TBS$1:
  15835. return EMPTY_BUFFER;
  15836. case VERSION$6:
  15837. return 0;
  15838. case SUBJECT:
  15839. return new RelativeDistinguishedNames();
  15840. case SPKI:
  15841. return new PublicKeyInfo();
  15842. case ATTRIBUTES$1:
  15843. return [];
  15844. case SIGNATURE_ALGORITHM$2:
  15845. return new AlgorithmIdentifier();
  15846. case SIGNATURE_VALUE:
  15847. return new asn1js.BitString();
  15848. default:
  15849. return super.defaultValues(memberName);
  15850. }
  15851. }
  15852. static schema(parameters = {}) {
  15853. const names = pvutils.getParametersValue(parameters, "names", {});
  15854. return (new asn1js.Sequence({
  15855. value: [
  15856. CertificationRequestInfo(names.certificationRequestInfo || {}),
  15857. new asn1js.Sequence({
  15858. name: (names.signatureAlgorithm || SIGNATURE_ALGORITHM$2),
  15859. value: [
  15860. new asn1js.ObjectIdentifier(),
  15861. new asn1js.Any({ optional: true })
  15862. ]
  15863. }),
  15864. new asn1js.BitString({ name: (names.signatureValue || SIGNATURE_VALUE) })
  15865. ]
  15866. }));
  15867. }
  15868. fromSchema(schema) {
  15869. pvutils.clearProps(schema, CLEAR_PROPS$f);
  15870. const asn1 = asn1js.compareSchema(schema, schema, CertificationRequest.schema());
  15871. AsnError.assertSchema(asn1, this.className);
  15872. this.tbsView = asn1.result.CertificationRequestInfo.valueBeforeDecodeView;
  15873. this.version = asn1.result[CSR_INFO_VERSION].valueBlock.valueDec;
  15874. this.subject = new RelativeDistinguishedNames({ schema: asn1.result[CSR_INFO_SUBJECT] });
  15875. this.subjectPublicKeyInfo = new PublicKeyInfo({ schema: asn1.result[CSR_INFO_SPKI] });
  15876. if (CSR_INFO_ATTRS in asn1.result) {
  15877. this.attributes = Array.from(asn1.result[CSR_INFO_ATTRS], element => new Attribute({ schema: element }));
  15878. }
  15879. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  15880. this.signatureValue = asn1.result.signatureValue;
  15881. }
  15882. encodeTBS() {
  15883. const outputArray = [
  15884. new asn1js.Integer({ value: this.version }),
  15885. this.subject.toSchema(),
  15886. this.subjectPublicKeyInfo.toSchema()
  15887. ];
  15888. if (ATTRIBUTES$1 in this) {
  15889. outputArray.push(new asn1js.Constructed({
  15890. idBlock: {
  15891. tagClass: 3,
  15892. tagNumber: 0
  15893. },
  15894. value: Array.from(this.attributes || [], o => o.toSchema())
  15895. }));
  15896. }
  15897. return (new asn1js.Sequence({
  15898. value: outputArray
  15899. }));
  15900. }
  15901. toSchema(encodeFlag = false) {
  15902. let tbsSchema;
  15903. if (encodeFlag === false) {
  15904. if (this.tbsView.byteLength === 0) {
  15905. return CertificationRequest.schema();
  15906. }
  15907. const asn1 = asn1js.fromBER(this.tbsView);
  15908. AsnError.assert(asn1, "PKCS#10 Certificate Request");
  15909. tbsSchema = asn1.result;
  15910. }
  15911. else {
  15912. tbsSchema = this.encodeTBS();
  15913. }
  15914. return (new asn1js.Sequence({
  15915. value: [
  15916. tbsSchema,
  15917. this.signatureAlgorithm.toSchema(),
  15918. this.signatureValue
  15919. ]
  15920. }));
  15921. }
  15922. toJSON() {
  15923. const object = {
  15924. tbs: pvtsutils.Convert.ToHex(this.tbsView),
  15925. version: this.version,
  15926. subject: this.subject.toJSON(),
  15927. subjectPublicKeyInfo: this.subjectPublicKeyInfo.toJSON(),
  15928. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  15929. signatureValue: this.signatureValue.toJSON(),
  15930. };
  15931. if (ATTRIBUTES$1 in this) {
  15932. object.attributes = Array.from(this.attributes || [], o => o.toJSON());
  15933. }
  15934. return object;
  15935. }
  15936. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  15937. if (!privateKey) {
  15938. throw new Error("Need to provide a private key for signing");
  15939. }
  15940. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  15941. const parameters = signatureParams.parameters;
  15942. this.signatureAlgorithm = signatureParams.signatureAlgorithm;
  15943. this.tbsView = new Uint8Array(this.encodeTBS().toBER());
  15944. const signature = await crypto.signWithPrivateKey(this.tbsView, privateKey, parameters);
  15945. this.signatureValue = new asn1js.BitString({ valueHex: signature });
  15946. }
  15947. async verify(crypto = getCrypto(true)) {
  15948. return crypto.verifyWithPublicKey(this.tbsView, this.signatureValue, this.subjectPublicKeyInfo, this.signatureAlgorithm);
  15949. }
  15950. async getPublicKey(parameters, crypto = getCrypto(true)) {
  15951. return crypto.getPublicKey(this.subjectPublicKeyInfo, this.signatureAlgorithm, parameters);
  15952. }
  15953. }
  15954. CertificationRequest.CLASS_NAME = "CertificationRequest";
  15955. const DIGEST_ALGORITHM$1 = "digestAlgorithm";
  15956. const DIGEST = "digest";
  15957. const CLEAR_PROPS$e = [
  15958. DIGEST_ALGORITHM$1,
  15959. DIGEST
  15960. ];
  15961. class DigestInfo extends PkiObject {
  15962. constructor(parameters = {}) {
  15963. super();
  15964. this.digestAlgorithm = pvutils.getParametersValue(parameters, DIGEST_ALGORITHM$1, DigestInfo.defaultValues(DIGEST_ALGORITHM$1));
  15965. this.digest = pvutils.getParametersValue(parameters, DIGEST, DigestInfo.defaultValues(DIGEST));
  15966. if (parameters.schema) {
  15967. this.fromSchema(parameters.schema);
  15968. }
  15969. }
  15970. static defaultValues(memberName) {
  15971. switch (memberName) {
  15972. case DIGEST_ALGORITHM$1:
  15973. return new AlgorithmIdentifier();
  15974. case DIGEST:
  15975. return new asn1js.OctetString();
  15976. default:
  15977. return super.defaultValues(memberName);
  15978. }
  15979. }
  15980. static compareWithDefault(memberName, memberValue) {
  15981. switch (memberName) {
  15982. case DIGEST_ALGORITHM$1:
  15983. return ((AlgorithmIdentifier.compareWithDefault("algorithmId", memberValue.algorithmId)) &&
  15984. (("algorithmParams" in memberValue) === false));
  15985. case DIGEST:
  15986. return (memberValue.isEqual(DigestInfo.defaultValues(memberName)));
  15987. default:
  15988. return super.defaultValues(memberName);
  15989. }
  15990. }
  15991. static schema(parameters = {}) {
  15992. const names = pvutils.getParametersValue(parameters, "names", {});
  15993. return (new asn1js.Sequence({
  15994. name: (names.blockName || EMPTY_STRING),
  15995. value: [
  15996. AlgorithmIdentifier.schema(names.digestAlgorithm || {
  15997. names: {
  15998. blockName: DIGEST_ALGORITHM$1
  15999. }
  16000. }),
  16001. new asn1js.OctetString({ name: (names.digest || DIGEST) })
  16002. ]
  16003. }));
  16004. }
  16005. fromSchema(schema) {
  16006. pvutils.clearProps(schema, CLEAR_PROPS$e);
  16007. const asn1 = asn1js.compareSchema(schema, schema, DigestInfo.schema({
  16008. names: {
  16009. digestAlgorithm: {
  16010. names: {
  16011. blockName: DIGEST_ALGORITHM$1
  16012. }
  16013. },
  16014. digest: DIGEST
  16015. }
  16016. }));
  16017. AsnError.assertSchema(asn1, this.className);
  16018. this.digestAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.digestAlgorithm });
  16019. this.digest = asn1.result.digest;
  16020. }
  16021. toSchema() {
  16022. return (new asn1js.Sequence({
  16023. value: [
  16024. this.digestAlgorithm.toSchema(),
  16025. this.digest
  16026. ]
  16027. }));
  16028. }
  16029. toJSON() {
  16030. return {
  16031. digestAlgorithm: this.digestAlgorithm.toJSON(),
  16032. digest: this.digest.toJSON(),
  16033. };
  16034. }
  16035. }
  16036. DigestInfo.CLASS_NAME = "DigestInfo";
  16037. const E_CONTENT_TYPE = "eContentType";
  16038. const E_CONTENT = "eContent";
  16039. const CLEAR_PROPS$d = [
  16040. E_CONTENT_TYPE,
  16041. E_CONTENT,
  16042. ];
  16043. class EncapsulatedContentInfo extends PkiObject {
  16044. constructor(parameters = {}) {
  16045. super();
  16046. this.eContentType = pvutils.getParametersValue(parameters, E_CONTENT_TYPE, EncapsulatedContentInfo.defaultValues(E_CONTENT_TYPE));
  16047. if (E_CONTENT in parameters) {
  16048. this.eContent = pvutils.getParametersValue(parameters, E_CONTENT, EncapsulatedContentInfo.defaultValues(E_CONTENT));
  16049. if ((this.eContent.idBlock.tagClass === 1) &&
  16050. (this.eContent.idBlock.tagNumber === 4)) {
  16051. if (this.eContent.idBlock.isConstructed === false) {
  16052. const constrString = new asn1js.OctetString({
  16053. idBlock: { isConstructed: true },
  16054. isConstructed: true
  16055. });
  16056. let offset = 0;
  16057. const viewHex = this.eContent.valueBlock.valueHexView.slice().buffer;
  16058. let length = viewHex.byteLength;
  16059. while (length > 0) {
  16060. const pieceView = new Uint8Array(viewHex, offset, ((offset + 65536) > viewHex.byteLength) ? (viewHex.byteLength - offset) : 65536);
  16061. const _array = new ArrayBuffer(pieceView.length);
  16062. const _view = new Uint8Array(_array);
  16063. for (let i = 0; i < _view.length; i++) {
  16064. _view[i] = pieceView[i];
  16065. }
  16066. constrString.valueBlock.value.push(new asn1js.OctetString({ valueHex: _array }));
  16067. length -= pieceView.length;
  16068. offset += pieceView.length;
  16069. }
  16070. this.eContent = constrString;
  16071. }
  16072. }
  16073. }
  16074. if (parameters.schema) {
  16075. this.fromSchema(parameters.schema);
  16076. }
  16077. }
  16078. static defaultValues(memberName) {
  16079. switch (memberName) {
  16080. case E_CONTENT_TYPE:
  16081. return EMPTY_STRING;
  16082. case E_CONTENT:
  16083. return new asn1js.OctetString();
  16084. default:
  16085. return super.defaultValues(memberName);
  16086. }
  16087. }
  16088. static compareWithDefault(memberName, memberValue) {
  16089. switch (memberName) {
  16090. case E_CONTENT_TYPE:
  16091. return (memberValue === EMPTY_STRING);
  16092. case E_CONTENT:
  16093. {
  16094. if ((memberValue.idBlock.tagClass === 1) && (memberValue.idBlock.tagNumber === 4))
  16095. return (memberValue.isEqual(EncapsulatedContentInfo.defaultValues(E_CONTENT)));
  16096. return false;
  16097. }
  16098. default:
  16099. return super.defaultValues(memberName);
  16100. }
  16101. }
  16102. static schema(parameters = {}) {
  16103. const names = pvutils.getParametersValue(parameters, "names", {});
  16104. return (new asn1js.Sequence({
  16105. name: (names.blockName || EMPTY_STRING),
  16106. value: [
  16107. new asn1js.ObjectIdentifier({ name: (names.eContentType || EMPTY_STRING) }),
  16108. new asn1js.Constructed({
  16109. optional: true,
  16110. idBlock: {
  16111. tagClass: 3,
  16112. tagNumber: 0
  16113. },
  16114. value: [
  16115. new asn1js.Any({ name: (names.eContent || EMPTY_STRING) })
  16116. ]
  16117. })
  16118. ]
  16119. }));
  16120. }
  16121. fromSchema(schema) {
  16122. pvutils.clearProps(schema, CLEAR_PROPS$d);
  16123. const asn1 = asn1js.compareSchema(schema, schema, EncapsulatedContentInfo.schema({
  16124. names: {
  16125. eContentType: E_CONTENT_TYPE,
  16126. eContent: E_CONTENT
  16127. }
  16128. }));
  16129. AsnError.assertSchema(asn1, this.className);
  16130. this.eContentType = asn1.result.eContentType.valueBlock.toString();
  16131. if (E_CONTENT in asn1.result)
  16132. this.eContent = asn1.result.eContent;
  16133. }
  16134. toSchema() {
  16135. const outputArray = [];
  16136. outputArray.push(new asn1js.ObjectIdentifier({ value: this.eContentType }));
  16137. if (this.eContent) {
  16138. if (EncapsulatedContentInfo.compareWithDefault(E_CONTENT, this.eContent) === false) {
  16139. outputArray.push(new asn1js.Constructed({
  16140. optional: true,
  16141. idBlock: {
  16142. tagClass: 3,
  16143. tagNumber: 0
  16144. },
  16145. value: [this.eContent]
  16146. }));
  16147. }
  16148. }
  16149. return (new asn1js.Sequence({
  16150. value: outputArray
  16151. }));
  16152. }
  16153. toJSON() {
  16154. const res = {
  16155. eContentType: this.eContentType
  16156. };
  16157. if (this.eContent && EncapsulatedContentInfo.compareWithDefault(E_CONTENT, this.eContent) === false) {
  16158. res.eContent = this.eContent.toJSON();
  16159. }
  16160. return res;
  16161. }
  16162. }
  16163. EncapsulatedContentInfo.CLASS_NAME = "EncapsulatedContentInfo";
  16164. class KeyBag extends PrivateKeyInfo {
  16165. constructor(parameters = {}) {
  16166. super(parameters);
  16167. }
  16168. }
  16169. const MAC = "mac";
  16170. const MAC_SALT = "macSalt";
  16171. const ITERATIONS = "iterations";
  16172. const CLEAR_PROPS$c = [
  16173. MAC,
  16174. MAC_SALT,
  16175. ITERATIONS
  16176. ];
  16177. class MacData extends PkiObject {
  16178. constructor(parameters = {}) {
  16179. super();
  16180. this.mac = pvutils.getParametersValue(parameters, MAC, MacData.defaultValues(MAC));
  16181. this.macSalt = pvutils.getParametersValue(parameters, MAC_SALT, MacData.defaultValues(MAC_SALT));
  16182. if (ITERATIONS in parameters) {
  16183. this.iterations = pvutils.getParametersValue(parameters, ITERATIONS, MacData.defaultValues(ITERATIONS));
  16184. }
  16185. if (parameters.schema) {
  16186. this.fromSchema(parameters.schema);
  16187. }
  16188. }
  16189. static defaultValues(memberName) {
  16190. switch (memberName) {
  16191. case MAC:
  16192. return new DigestInfo();
  16193. case MAC_SALT:
  16194. return new asn1js.OctetString();
  16195. case ITERATIONS:
  16196. return 1;
  16197. default:
  16198. return super.defaultValues(memberName);
  16199. }
  16200. }
  16201. static compareWithDefault(memberName, memberValue) {
  16202. switch (memberName) {
  16203. case MAC:
  16204. return ((DigestInfo.compareWithDefault("digestAlgorithm", memberValue.digestAlgorithm)) &&
  16205. (DigestInfo.compareWithDefault("digest", memberValue.digest)));
  16206. case MAC_SALT:
  16207. return (memberValue.isEqual(MacData.defaultValues(memberName)));
  16208. case ITERATIONS:
  16209. return (memberValue === MacData.defaultValues(memberName));
  16210. default:
  16211. return super.defaultValues(memberName);
  16212. }
  16213. }
  16214. static schema(parameters = {}) {
  16215. const names = pvutils.getParametersValue(parameters, "names", {});
  16216. return (new asn1js.Sequence({
  16217. name: (names.blockName || EMPTY_STRING),
  16218. optional: (names.optional || true),
  16219. value: [
  16220. DigestInfo.schema(names.mac || {
  16221. names: {
  16222. blockName: MAC
  16223. }
  16224. }),
  16225. new asn1js.OctetString({ name: (names.macSalt || MAC_SALT) }),
  16226. new asn1js.Integer({
  16227. optional: true,
  16228. name: (names.iterations || ITERATIONS)
  16229. })
  16230. ]
  16231. }));
  16232. }
  16233. fromSchema(schema) {
  16234. pvutils.clearProps(schema, CLEAR_PROPS$c);
  16235. const asn1 = asn1js.compareSchema(schema, schema, MacData.schema({
  16236. names: {
  16237. mac: {
  16238. names: {
  16239. blockName: MAC
  16240. }
  16241. },
  16242. macSalt: MAC_SALT,
  16243. iterations: ITERATIONS
  16244. }
  16245. }));
  16246. AsnError.assertSchema(asn1, this.className);
  16247. this.mac = new DigestInfo({ schema: asn1.result.mac });
  16248. this.macSalt = asn1.result.macSalt;
  16249. if (ITERATIONS in asn1.result)
  16250. this.iterations = asn1.result.iterations.valueBlock.valueDec;
  16251. }
  16252. toSchema() {
  16253. const outputArray = [
  16254. this.mac.toSchema(),
  16255. this.macSalt
  16256. ];
  16257. if (this.iterations !== undefined) {
  16258. outputArray.push(new asn1js.Integer({ value: this.iterations }));
  16259. }
  16260. return (new asn1js.Sequence({
  16261. value: outputArray
  16262. }));
  16263. }
  16264. toJSON() {
  16265. const res = {
  16266. mac: this.mac.toJSON(),
  16267. macSalt: this.macSalt.toJSON(),
  16268. };
  16269. if (this.iterations !== undefined) {
  16270. res.iterations = this.iterations;
  16271. }
  16272. return res;
  16273. }
  16274. }
  16275. MacData.CLASS_NAME = "MacData";
  16276. const HASH_ALGORITHM = "hashAlgorithm";
  16277. const HASHED_MESSAGE = "hashedMessage";
  16278. const CLEAR_PROPS$b = [
  16279. HASH_ALGORITHM,
  16280. HASHED_MESSAGE,
  16281. ];
  16282. class MessageImprint extends PkiObject {
  16283. static async create(hashAlgorithm, message, crypto = getCrypto(true)) {
  16284. const hashAlgorithmOID = crypto.getOIDByAlgorithm({ name: hashAlgorithm }, true, "hashAlgorithm");
  16285. const hashedMessage = await crypto.digest(hashAlgorithm, message);
  16286. const res = new MessageImprint({
  16287. hashAlgorithm: new AlgorithmIdentifier({
  16288. algorithmId: hashAlgorithmOID,
  16289. algorithmParams: new asn1js.Null(),
  16290. }),
  16291. hashedMessage: new asn1js.OctetString({ valueHex: hashedMessage })
  16292. });
  16293. return res;
  16294. }
  16295. constructor(parameters = {}) {
  16296. super();
  16297. this.hashAlgorithm = pvutils.getParametersValue(parameters, HASH_ALGORITHM, MessageImprint.defaultValues(HASH_ALGORITHM));
  16298. this.hashedMessage = pvutils.getParametersValue(parameters, HASHED_MESSAGE, MessageImprint.defaultValues(HASHED_MESSAGE));
  16299. if (parameters.schema) {
  16300. this.fromSchema(parameters.schema);
  16301. }
  16302. }
  16303. static defaultValues(memberName) {
  16304. switch (memberName) {
  16305. case HASH_ALGORITHM:
  16306. return new AlgorithmIdentifier();
  16307. case HASHED_MESSAGE:
  16308. return new asn1js.OctetString();
  16309. default:
  16310. return super.defaultValues(memberName);
  16311. }
  16312. }
  16313. static compareWithDefault(memberName, memberValue) {
  16314. switch (memberName) {
  16315. case HASH_ALGORITHM:
  16316. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  16317. case HASHED_MESSAGE:
  16318. return (memberValue.isEqual(MessageImprint.defaultValues(memberName)) === 0);
  16319. default:
  16320. return super.defaultValues(memberName);
  16321. }
  16322. }
  16323. static schema(parameters = {}) {
  16324. const names = pvutils.getParametersValue(parameters, "names", {});
  16325. return (new asn1js.Sequence({
  16326. name: (names.blockName || EMPTY_STRING),
  16327. value: [
  16328. AlgorithmIdentifier.schema(names.hashAlgorithm || {}),
  16329. new asn1js.OctetString({ name: (names.hashedMessage || EMPTY_STRING) })
  16330. ]
  16331. }));
  16332. }
  16333. fromSchema(schema) {
  16334. pvutils.clearProps(schema, CLEAR_PROPS$b);
  16335. const asn1 = asn1js.compareSchema(schema, schema, MessageImprint.schema({
  16336. names: {
  16337. hashAlgorithm: {
  16338. names: {
  16339. blockName: HASH_ALGORITHM
  16340. }
  16341. },
  16342. hashedMessage: HASHED_MESSAGE
  16343. }
  16344. }));
  16345. AsnError.assertSchema(asn1, this.className);
  16346. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  16347. this.hashedMessage = asn1.result.hashedMessage;
  16348. }
  16349. toSchema() {
  16350. return (new asn1js.Sequence({
  16351. value: [
  16352. this.hashAlgorithm.toSchema(),
  16353. this.hashedMessage
  16354. ]
  16355. }));
  16356. }
  16357. toJSON() {
  16358. return {
  16359. hashAlgorithm: this.hashAlgorithm.toJSON(),
  16360. hashedMessage: this.hashedMessage.toJSON(),
  16361. };
  16362. }
  16363. }
  16364. MessageImprint.CLASS_NAME = "MessageImprint";
  16365. const REQ_CERT = "reqCert";
  16366. const SINGLE_REQUEST_EXTENSIONS = "singleRequestExtensions";
  16367. const CLEAR_PROPS$a = [
  16368. REQ_CERT,
  16369. SINGLE_REQUEST_EXTENSIONS,
  16370. ];
  16371. class Request extends PkiObject {
  16372. constructor(parameters = {}) {
  16373. super();
  16374. this.reqCert = pvutils.getParametersValue(parameters, REQ_CERT, Request.defaultValues(REQ_CERT));
  16375. if (SINGLE_REQUEST_EXTENSIONS in parameters) {
  16376. this.singleRequestExtensions = pvutils.getParametersValue(parameters, SINGLE_REQUEST_EXTENSIONS, Request.defaultValues(SINGLE_REQUEST_EXTENSIONS));
  16377. }
  16378. if (parameters.schema) {
  16379. this.fromSchema(parameters.schema);
  16380. }
  16381. }
  16382. static defaultValues(memberName) {
  16383. switch (memberName) {
  16384. case REQ_CERT:
  16385. return new CertID();
  16386. case SINGLE_REQUEST_EXTENSIONS:
  16387. return [];
  16388. default:
  16389. return super.defaultValues(memberName);
  16390. }
  16391. }
  16392. static compareWithDefault(memberName, memberValue) {
  16393. switch (memberName) {
  16394. case REQ_CERT:
  16395. return (memberValue.isEqual(Request.defaultValues(memberName)));
  16396. case SINGLE_REQUEST_EXTENSIONS:
  16397. return (memberValue.length === 0);
  16398. default:
  16399. return super.defaultValues(memberName);
  16400. }
  16401. }
  16402. static schema(parameters = {}) {
  16403. const names = pvutils.getParametersValue(parameters, "names", {});
  16404. return (new asn1js.Sequence({
  16405. name: (names.blockName || EMPTY_STRING),
  16406. value: [
  16407. CertID.schema(names.reqCert || {}),
  16408. new asn1js.Constructed({
  16409. optional: true,
  16410. idBlock: {
  16411. tagClass: 3,
  16412. tagNumber: 0
  16413. },
  16414. value: [Extensions.schema(names.extensions || {
  16415. names: {
  16416. blockName: (names.singleRequestExtensions || EMPTY_STRING)
  16417. }
  16418. })]
  16419. })
  16420. ]
  16421. }));
  16422. }
  16423. fromSchema(schema) {
  16424. pvutils.clearProps(schema, CLEAR_PROPS$a);
  16425. const asn1 = asn1js.compareSchema(schema, schema, Request.schema({
  16426. names: {
  16427. reqCert: {
  16428. names: {
  16429. blockName: REQ_CERT
  16430. }
  16431. },
  16432. extensions: {
  16433. names: {
  16434. blockName: SINGLE_REQUEST_EXTENSIONS
  16435. }
  16436. }
  16437. }
  16438. }));
  16439. AsnError.assertSchema(asn1, this.className);
  16440. this.reqCert = new CertID({ schema: asn1.result.reqCert });
  16441. if (SINGLE_REQUEST_EXTENSIONS in asn1.result) {
  16442. this.singleRequestExtensions = Array.from(asn1.result.singleRequestExtensions.valueBlock.value, element => new Extension({ schema: element }));
  16443. }
  16444. }
  16445. toSchema() {
  16446. const outputArray = [];
  16447. outputArray.push(this.reqCert.toSchema());
  16448. if (this.singleRequestExtensions) {
  16449. outputArray.push(new asn1js.Constructed({
  16450. optional: true,
  16451. idBlock: {
  16452. tagClass: 3,
  16453. tagNumber: 0
  16454. },
  16455. value: [
  16456. new asn1js.Sequence({
  16457. value: Array.from(this.singleRequestExtensions, o => o.toSchema())
  16458. })
  16459. ]
  16460. }));
  16461. }
  16462. return (new asn1js.Sequence({
  16463. value: outputArray
  16464. }));
  16465. }
  16466. toJSON() {
  16467. const res = {
  16468. reqCert: this.reqCert.toJSON()
  16469. };
  16470. if (this.singleRequestExtensions) {
  16471. res.singleRequestExtensions = Array.from(this.singleRequestExtensions, o => o.toJSON());
  16472. }
  16473. return res;
  16474. }
  16475. }
  16476. Request.CLASS_NAME = "Request";
  16477. const TBS = "tbs";
  16478. const VERSION$5 = "version";
  16479. const REQUESTOR_NAME = "requestorName";
  16480. const REQUEST_LIST = "requestList";
  16481. const REQUEST_EXTENSIONS = "requestExtensions";
  16482. const TBS_REQUEST$1 = "TBSRequest";
  16483. const TBS_REQUEST_VERSION = `${TBS_REQUEST$1}.${VERSION$5}`;
  16484. const TBS_REQUEST_REQUESTOR_NAME = `${TBS_REQUEST$1}.${REQUESTOR_NAME}`;
  16485. const TBS_REQUEST_REQUESTS = `${TBS_REQUEST$1}.requests`;
  16486. const TBS_REQUEST_REQUEST_EXTENSIONS = `${TBS_REQUEST$1}.${REQUEST_EXTENSIONS}`;
  16487. const CLEAR_PROPS$9 = [
  16488. TBS_REQUEST$1,
  16489. TBS_REQUEST_VERSION,
  16490. TBS_REQUEST_REQUESTOR_NAME,
  16491. TBS_REQUEST_REQUESTS,
  16492. TBS_REQUEST_REQUEST_EXTENSIONS
  16493. ];
  16494. class TBSRequest extends PkiObject {
  16495. get tbs() {
  16496. return pvtsutils.BufferSourceConverter.toArrayBuffer(this.tbsView);
  16497. }
  16498. set tbs(value) {
  16499. this.tbsView = new Uint8Array(value);
  16500. }
  16501. constructor(parameters = {}) {
  16502. super();
  16503. this.tbsView = new Uint8Array(pvutils.getParametersValue(parameters, TBS, TBSRequest.defaultValues(TBS)));
  16504. if (VERSION$5 in parameters) {
  16505. this.version = pvutils.getParametersValue(parameters, VERSION$5, TBSRequest.defaultValues(VERSION$5));
  16506. }
  16507. if (REQUESTOR_NAME in parameters) {
  16508. this.requestorName = pvutils.getParametersValue(parameters, REQUESTOR_NAME, TBSRequest.defaultValues(REQUESTOR_NAME));
  16509. }
  16510. this.requestList = pvutils.getParametersValue(parameters, REQUEST_LIST, TBSRequest.defaultValues(REQUEST_LIST));
  16511. if (REQUEST_EXTENSIONS in parameters) {
  16512. this.requestExtensions = pvutils.getParametersValue(parameters, REQUEST_EXTENSIONS, TBSRequest.defaultValues(REQUEST_EXTENSIONS));
  16513. }
  16514. if (parameters.schema) {
  16515. this.fromSchema(parameters.schema);
  16516. }
  16517. }
  16518. static defaultValues(memberName) {
  16519. switch (memberName) {
  16520. case TBS:
  16521. return EMPTY_BUFFER;
  16522. case VERSION$5:
  16523. return 0;
  16524. case REQUESTOR_NAME:
  16525. return new GeneralName();
  16526. case REQUEST_LIST:
  16527. case REQUEST_EXTENSIONS:
  16528. return [];
  16529. default:
  16530. return super.defaultValues(memberName);
  16531. }
  16532. }
  16533. static compareWithDefault(memberName, memberValue) {
  16534. switch (memberName) {
  16535. case TBS:
  16536. return (memberValue.byteLength === 0);
  16537. case VERSION$5:
  16538. return (memberValue === TBSRequest.defaultValues(memberName));
  16539. case REQUESTOR_NAME:
  16540. return ((memberValue.type === GeneralName.defaultValues("type")) && (Object.keys(memberValue.value).length === 0));
  16541. case REQUEST_LIST:
  16542. case REQUEST_EXTENSIONS:
  16543. return (memberValue.length === 0);
  16544. default:
  16545. return super.defaultValues(memberName);
  16546. }
  16547. }
  16548. static schema(parameters = {}) {
  16549. const names = pvutils.getParametersValue(parameters, "names", {});
  16550. return (new asn1js.Sequence({
  16551. name: (names.blockName || TBS_REQUEST$1),
  16552. value: [
  16553. new asn1js.Constructed({
  16554. optional: true,
  16555. idBlock: {
  16556. tagClass: 3,
  16557. tagNumber: 0
  16558. },
  16559. value: [new asn1js.Integer({ name: (names.TBSRequestVersion || TBS_REQUEST_VERSION) })]
  16560. }),
  16561. new asn1js.Constructed({
  16562. optional: true,
  16563. idBlock: {
  16564. tagClass: 3,
  16565. tagNumber: 1
  16566. },
  16567. value: [GeneralName.schema(names.requestorName || {
  16568. names: {
  16569. blockName: TBS_REQUEST_REQUESTOR_NAME
  16570. }
  16571. })]
  16572. }),
  16573. new asn1js.Sequence({
  16574. name: (names.requestList || "TBSRequest.requestList"),
  16575. value: [
  16576. new asn1js.Repeated({
  16577. name: (names.requests || TBS_REQUEST_REQUESTS),
  16578. value: Request.schema(names.requestNames || {})
  16579. })
  16580. ]
  16581. }),
  16582. new asn1js.Constructed({
  16583. optional: true,
  16584. idBlock: {
  16585. tagClass: 3,
  16586. tagNumber: 2
  16587. },
  16588. value: [Extensions.schema(names.extensions || {
  16589. names: {
  16590. blockName: (names.requestExtensions || TBS_REQUEST_REQUEST_EXTENSIONS)
  16591. }
  16592. })]
  16593. })
  16594. ]
  16595. }));
  16596. }
  16597. fromSchema(schema) {
  16598. pvutils.clearProps(schema, CLEAR_PROPS$9);
  16599. const asn1 = asn1js.compareSchema(schema, schema, TBSRequest.schema());
  16600. AsnError.assertSchema(asn1, this.className);
  16601. this.tbsView = asn1.result.TBSRequest.valueBeforeDecodeView;
  16602. if (TBS_REQUEST_VERSION in asn1.result)
  16603. this.version = asn1.result[TBS_REQUEST_VERSION].valueBlock.valueDec;
  16604. if (TBS_REQUEST_REQUESTOR_NAME in asn1.result)
  16605. this.requestorName = new GeneralName({ schema: asn1.result[TBS_REQUEST_REQUESTOR_NAME] });
  16606. this.requestList = Array.from(asn1.result[TBS_REQUEST_REQUESTS], element => new Request({ schema: element }));
  16607. if (TBS_REQUEST_REQUEST_EXTENSIONS in asn1.result)
  16608. this.requestExtensions = Array.from(asn1.result[TBS_REQUEST_REQUEST_EXTENSIONS].valueBlock.value, element => new Extension({ schema: element }));
  16609. }
  16610. toSchema(encodeFlag = false) {
  16611. let tbsSchema;
  16612. if (encodeFlag === false) {
  16613. if (this.tbsView.byteLength === 0)
  16614. return TBSRequest.schema();
  16615. const asn1 = asn1js.fromBER(this.tbsView);
  16616. AsnError.assert(asn1, "TBS Request");
  16617. if (!(asn1.result instanceof asn1js.Sequence)) {
  16618. throw new Error("ASN.1 result should be SEQUENCE");
  16619. }
  16620. tbsSchema = asn1.result;
  16621. }
  16622. else {
  16623. const outputArray = [];
  16624. if (this.version !== undefined) {
  16625. outputArray.push(new asn1js.Constructed({
  16626. idBlock: {
  16627. tagClass: 3,
  16628. tagNumber: 0
  16629. },
  16630. value: [new asn1js.Integer({ value: this.version })]
  16631. }));
  16632. }
  16633. if (this.requestorName) {
  16634. outputArray.push(new asn1js.Constructed({
  16635. idBlock: {
  16636. tagClass: 3,
  16637. tagNumber: 1
  16638. },
  16639. value: [this.requestorName.toSchema()]
  16640. }));
  16641. }
  16642. outputArray.push(new asn1js.Sequence({
  16643. value: Array.from(this.requestList, o => o.toSchema())
  16644. }));
  16645. if (this.requestExtensions) {
  16646. outputArray.push(new asn1js.Constructed({
  16647. idBlock: {
  16648. tagClass: 3,
  16649. tagNumber: 2
  16650. },
  16651. value: [
  16652. new asn1js.Sequence({
  16653. value: Array.from(this.requestExtensions, o => o.toSchema())
  16654. })
  16655. ]
  16656. }));
  16657. }
  16658. tbsSchema = new asn1js.Sequence({
  16659. value: outputArray
  16660. });
  16661. }
  16662. return tbsSchema;
  16663. }
  16664. toJSON() {
  16665. const res = {};
  16666. if (this.version != undefined)
  16667. res.version = this.version;
  16668. if (this.requestorName) {
  16669. res.requestorName = this.requestorName.toJSON();
  16670. }
  16671. res.requestList = Array.from(this.requestList, o => o.toJSON());
  16672. if (this.requestExtensions) {
  16673. res.requestExtensions = Array.from(this.requestExtensions, o => o.toJSON());
  16674. }
  16675. return res;
  16676. }
  16677. }
  16678. TBSRequest.CLASS_NAME = "TBSRequest";
  16679. const SIGNATURE_ALGORITHM$1 = "signatureAlgorithm";
  16680. const SIGNATURE$1 = "signature";
  16681. const CERTS = "certs";
  16682. class Signature extends PkiObject {
  16683. constructor(parameters = {}) {
  16684. super();
  16685. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$1, Signature.defaultValues(SIGNATURE_ALGORITHM$1));
  16686. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$1, Signature.defaultValues(SIGNATURE$1));
  16687. if (CERTS in parameters) {
  16688. this.certs = pvutils.getParametersValue(parameters, CERTS, Signature.defaultValues(CERTS));
  16689. }
  16690. if (parameters.schema) {
  16691. this.fromSchema(parameters.schema);
  16692. }
  16693. }
  16694. static defaultValues(memberName) {
  16695. switch (memberName) {
  16696. case SIGNATURE_ALGORITHM$1:
  16697. return new AlgorithmIdentifier();
  16698. case SIGNATURE$1:
  16699. return new asn1js.BitString();
  16700. case CERTS:
  16701. return [];
  16702. default:
  16703. return super.defaultValues(memberName);
  16704. }
  16705. }
  16706. static compareWithDefault(memberName, memberValue) {
  16707. switch (memberName) {
  16708. case SIGNATURE_ALGORITHM$1:
  16709. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  16710. case SIGNATURE$1:
  16711. return (memberValue.isEqual(Signature.defaultValues(memberName)));
  16712. case CERTS:
  16713. return (memberValue.length === 0);
  16714. default:
  16715. return super.defaultValues(memberName);
  16716. }
  16717. }
  16718. static schema(parameters = {}) {
  16719. const names = pvutils.getParametersValue(parameters, "names", {});
  16720. return (new asn1js.Sequence({
  16721. name: (names.blockName || EMPTY_STRING),
  16722. value: [
  16723. AlgorithmIdentifier.schema(names.signatureAlgorithm || {}),
  16724. new asn1js.BitString({ name: (names.signature || EMPTY_STRING) }),
  16725. new asn1js.Constructed({
  16726. optional: true,
  16727. idBlock: {
  16728. tagClass: 3,
  16729. tagNumber: 0
  16730. },
  16731. value: [
  16732. new asn1js.Sequence({
  16733. value: [new asn1js.Repeated({
  16734. name: (names.certs || EMPTY_STRING),
  16735. value: Certificate.schema({})
  16736. })]
  16737. })
  16738. ]
  16739. })
  16740. ]
  16741. }));
  16742. }
  16743. fromSchema(schema) {
  16744. pvutils.clearProps(schema, [
  16745. SIGNATURE_ALGORITHM$1,
  16746. SIGNATURE$1,
  16747. CERTS
  16748. ]);
  16749. const asn1 = asn1js.compareSchema(schema, schema, Signature.schema({
  16750. names: {
  16751. signatureAlgorithm: {
  16752. names: {
  16753. blockName: SIGNATURE_ALGORITHM$1
  16754. }
  16755. },
  16756. signature: SIGNATURE$1,
  16757. certs: CERTS
  16758. }
  16759. }));
  16760. AsnError.assertSchema(asn1, this.className);
  16761. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  16762. this.signature = asn1.result.signature;
  16763. if (CERTS in asn1.result)
  16764. this.certs = Array.from(asn1.result.certs, element => new Certificate({ schema: element }));
  16765. }
  16766. toSchema() {
  16767. const outputArray = [];
  16768. outputArray.push(this.signatureAlgorithm.toSchema());
  16769. outputArray.push(this.signature);
  16770. if (this.certs) {
  16771. outputArray.push(new asn1js.Constructed({
  16772. optional: true,
  16773. idBlock: {
  16774. tagClass: 3,
  16775. tagNumber: 0
  16776. },
  16777. value: [
  16778. new asn1js.Sequence({
  16779. value: Array.from(this.certs, o => o.toSchema())
  16780. })
  16781. ]
  16782. }));
  16783. }
  16784. return (new asn1js.Sequence({
  16785. value: outputArray
  16786. }));
  16787. }
  16788. toJSON() {
  16789. const res = {
  16790. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  16791. signature: this.signature.toJSON(),
  16792. };
  16793. if (this.certs) {
  16794. res.certs = Array.from(this.certs, o => o.toJSON());
  16795. }
  16796. return res;
  16797. }
  16798. }
  16799. Signature.CLASS_NAME = "Signature";
  16800. const TBS_REQUEST = "tbsRequest";
  16801. const OPTIONAL_SIGNATURE = "optionalSignature";
  16802. const CLEAR_PROPS$8 = [
  16803. TBS_REQUEST,
  16804. OPTIONAL_SIGNATURE
  16805. ];
  16806. class OCSPRequest extends PkiObject {
  16807. constructor(parameters = {}) {
  16808. super();
  16809. this.tbsRequest = pvutils.getParametersValue(parameters, TBS_REQUEST, OCSPRequest.defaultValues(TBS_REQUEST));
  16810. if (OPTIONAL_SIGNATURE in parameters) {
  16811. this.optionalSignature = pvutils.getParametersValue(parameters, OPTIONAL_SIGNATURE, OCSPRequest.defaultValues(OPTIONAL_SIGNATURE));
  16812. }
  16813. if (parameters.schema) {
  16814. this.fromSchema(parameters.schema);
  16815. }
  16816. }
  16817. static defaultValues(memberName) {
  16818. switch (memberName) {
  16819. case TBS_REQUEST:
  16820. return new TBSRequest();
  16821. case OPTIONAL_SIGNATURE:
  16822. return new Signature();
  16823. default:
  16824. return super.defaultValues(memberName);
  16825. }
  16826. }
  16827. static compareWithDefault(memberName, memberValue) {
  16828. switch (memberName) {
  16829. case TBS_REQUEST:
  16830. return ((TBSRequest.compareWithDefault("tbs", memberValue.tbs)) &&
  16831. (TBSRequest.compareWithDefault("version", memberValue.version)) &&
  16832. (TBSRequest.compareWithDefault("requestorName", memberValue.requestorName)) &&
  16833. (TBSRequest.compareWithDefault("requestList", memberValue.requestList)) &&
  16834. (TBSRequest.compareWithDefault("requestExtensions", memberValue.requestExtensions)));
  16835. case OPTIONAL_SIGNATURE:
  16836. return ((Signature.compareWithDefault("signatureAlgorithm", memberValue.signatureAlgorithm)) &&
  16837. (Signature.compareWithDefault("signature", memberValue.signature)) &&
  16838. (Signature.compareWithDefault("certs", memberValue.certs)));
  16839. default:
  16840. return super.defaultValues(memberName);
  16841. }
  16842. }
  16843. static schema(parameters = {}) {
  16844. const names = pvutils.getParametersValue(parameters, "names", {});
  16845. return (new asn1js.Sequence({
  16846. name: names.blockName || "OCSPRequest",
  16847. value: [
  16848. TBSRequest.schema(names.tbsRequest || {
  16849. names: {
  16850. blockName: TBS_REQUEST
  16851. }
  16852. }),
  16853. new asn1js.Constructed({
  16854. optional: true,
  16855. idBlock: {
  16856. tagClass: 3,
  16857. tagNumber: 0
  16858. },
  16859. value: [
  16860. Signature.schema(names.optionalSignature || {
  16861. names: {
  16862. blockName: OPTIONAL_SIGNATURE
  16863. }
  16864. })
  16865. ]
  16866. })
  16867. ]
  16868. }));
  16869. }
  16870. fromSchema(schema) {
  16871. pvutils.clearProps(schema, CLEAR_PROPS$8);
  16872. const asn1 = asn1js.compareSchema(schema, schema, OCSPRequest.schema());
  16873. AsnError.assertSchema(asn1, this.className);
  16874. this.tbsRequest = new TBSRequest({ schema: asn1.result.tbsRequest });
  16875. if (OPTIONAL_SIGNATURE in asn1.result)
  16876. this.optionalSignature = new Signature({ schema: asn1.result.optionalSignature });
  16877. }
  16878. toSchema(encodeFlag = false) {
  16879. const outputArray = [];
  16880. outputArray.push(this.tbsRequest.toSchema(encodeFlag));
  16881. if (this.optionalSignature)
  16882. outputArray.push(new asn1js.Constructed({
  16883. optional: true,
  16884. idBlock: {
  16885. tagClass: 3,
  16886. tagNumber: 0
  16887. },
  16888. value: [
  16889. this.optionalSignature.toSchema()
  16890. ]
  16891. }));
  16892. return (new asn1js.Sequence({
  16893. value: outputArray
  16894. }));
  16895. }
  16896. toJSON() {
  16897. const res = {
  16898. tbsRequest: this.tbsRequest.toJSON()
  16899. };
  16900. if (this.optionalSignature) {
  16901. res.optionalSignature = this.optionalSignature.toJSON();
  16902. }
  16903. return res;
  16904. }
  16905. async createForCertificate(certificate, parameters, crypto = getCrypto(true)) {
  16906. const certID = new CertID();
  16907. await certID.createForCertificate(certificate, parameters, crypto);
  16908. this.tbsRequest.requestList.push(new Request({
  16909. reqCert: certID,
  16910. }));
  16911. }
  16912. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  16913. ParameterError.assertEmpty(privateKey, "privateKey", "OCSPRequest.sign method");
  16914. if (!this.optionalSignature) {
  16915. throw new Error("Need to create \"optionalSignature\" field before signing");
  16916. }
  16917. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  16918. const parameters = signatureParams.parameters;
  16919. this.optionalSignature.signatureAlgorithm = signatureParams.signatureAlgorithm;
  16920. const tbs = this.tbsRequest.toSchema(true).toBER(false);
  16921. const signature = await crypto.signWithPrivateKey(tbs, privateKey, parameters);
  16922. this.optionalSignature.signature = new asn1js.BitString({ valueHex: signature });
  16923. }
  16924. verify() {
  16925. }
  16926. }
  16927. OCSPRequest.CLASS_NAME = "OCSPRequest";
  16928. const RESPONSE_TYPE = "responseType";
  16929. const RESPONSE = "response";
  16930. const CLEAR_PROPS$7 = [
  16931. RESPONSE_TYPE,
  16932. RESPONSE
  16933. ];
  16934. class ResponseBytes extends PkiObject {
  16935. constructor(parameters = {}) {
  16936. super();
  16937. this.responseType = pvutils.getParametersValue(parameters, RESPONSE_TYPE, ResponseBytes.defaultValues(RESPONSE_TYPE));
  16938. this.response = pvutils.getParametersValue(parameters, RESPONSE, ResponseBytes.defaultValues(RESPONSE));
  16939. if (parameters.schema) {
  16940. this.fromSchema(parameters.schema);
  16941. }
  16942. }
  16943. static defaultValues(memberName) {
  16944. switch (memberName) {
  16945. case RESPONSE_TYPE:
  16946. return EMPTY_STRING;
  16947. case RESPONSE:
  16948. return new asn1js.OctetString();
  16949. default:
  16950. return super.defaultValues(memberName);
  16951. }
  16952. }
  16953. static compareWithDefault(memberName, memberValue) {
  16954. switch (memberName) {
  16955. case RESPONSE_TYPE:
  16956. return (memberValue === EMPTY_STRING);
  16957. case RESPONSE:
  16958. return (memberValue.isEqual(ResponseBytes.defaultValues(memberName)));
  16959. default:
  16960. return super.defaultValues(memberName);
  16961. }
  16962. }
  16963. static schema(parameters = {}) {
  16964. const names = pvutils.getParametersValue(parameters, "names", {});
  16965. return (new asn1js.Sequence({
  16966. name: (names.blockName || EMPTY_STRING),
  16967. value: [
  16968. new asn1js.ObjectIdentifier({ name: (names.responseType || EMPTY_STRING) }),
  16969. new asn1js.OctetString({ name: (names.response || EMPTY_STRING) })
  16970. ]
  16971. }));
  16972. }
  16973. fromSchema(schema) {
  16974. pvutils.clearProps(schema, CLEAR_PROPS$7);
  16975. const asn1 = asn1js.compareSchema(schema, schema, ResponseBytes.schema({
  16976. names: {
  16977. responseType: RESPONSE_TYPE,
  16978. response: RESPONSE
  16979. }
  16980. }));
  16981. AsnError.assertSchema(asn1, this.className);
  16982. this.responseType = asn1.result.responseType.valueBlock.toString();
  16983. this.response = asn1.result.response;
  16984. }
  16985. toSchema() {
  16986. return (new asn1js.Sequence({
  16987. value: [
  16988. new asn1js.ObjectIdentifier({ value: this.responseType }),
  16989. this.response
  16990. ]
  16991. }));
  16992. }
  16993. toJSON() {
  16994. return {
  16995. responseType: this.responseType,
  16996. response: this.response.toJSON(),
  16997. };
  16998. }
  16999. }
  17000. ResponseBytes.CLASS_NAME = "ResponseBytes";
  17001. const RESPONSE_STATUS = "responseStatus";
  17002. const RESPONSE_BYTES = "responseBytes";
  17003. class OCSPResponse extends PkiObject {
  17004. constructor(parameters = {}) {
  17005. super();
  17006. this.responseStatus = pvutils.getParametersValue(parameters, RESPONSE_STATUS, OCSPResponse.defaultValues(RESPONSE_STATUS));
  17007. if (RESPONSE_BYTES in parameters) {
  17008. this.responseBytes = pvutils.getParametersValue(parameters, RESPONSE_BYTES, OCSPResponse.defaultValues(RESPONSE_BYTES));
  17009. }
  17010. if (parameters.schema) {
  17011. this.fromSchema(parameters.schema);
  17012. }
  17013. }
  17014. static defaultValues(memberName) {
  17015. switch (memberName) {
  17016. case RESPONSE_STATUS:
  17017. return new asn1js.Enumerated();
  17018. case RESPONSE_BYTES:
  17019. return new ResponseBytes();
  17020. default:
  17021. return super.defaultValues(memberName);
  17022. }
  17023. }
  17024. static compareWithDefault(memberName, memberValue) {
  17025. switch (memberName) {
  17026. case RESPONSE_STATUS:
  17027. return (memberValue.isEqual(OCSPResponse.defaultValues(memberName)));
  17028. case RESPONSE_BYTES:
  17029. return ((ResponseBytes.compareWithDefault("responseType", memberValue.responseType)) &&
  17030. (ResponseBytes.compareWithDefault("response", memberValue.response)));
  17031. default:
  17032. return super.defaultValues(memberName);
  17033. }
  17034. }
  17035. static schema(parameters = {}) {
  17036. const names = pvutils.getParametersValue(parameters, "names", {});
  17037. return (new asn1js.Sequence({
  17038. name: (names.blockName || "OCSPResponse"),
  17039. value: [
  17040. new asn1js.Enumerated({ name: (names.responseStatus || RESPONSE_STATUS) }),
  17041. new asn1js.Constructed({
  17042. optional: true,
  17043. idBlock: {
  17044. tagClass: 3,
  17045. tagNumber: 0
  17046. },
  17047. value: [
  17048. ResponseBytes.schema(names.responseBytes || {
  17049. names: {
  17050. blockName: RESPONSE_BYTES
  17051. }
  17052. })
  17053. ]
  17054. })
  17055. ]
  17056. }));
  17057. }
  17058. fromSchema(schema) {
  17059. pvutils.clearProps(schema, [
  17060. RESPONSE_STATUS,
  17061. RESPONSE_BYTES
  17062. ]);
  17063. const asn1 = asn1js.compareSchema(schema, schema, OCSPResponse.schema());
  17064. AsnError.assertSchema(asn1, this.className);
  17065. this.responseStatus = asn1.result.responseStatus;
  17066. if (RESPONSE_BYTES in asn1.result)
  17067. this.responseBytes = new ResponseBytes({ schema: asn1.result.responseBytes });
  17068. }
  17069. toSchema() {
  17070. const outputArray = [];
  17071. outputArray.push(this.responseStatus);
  17072. if (this.responseBytes) {
  17073. outputArray.push(new asn1js.Constructed({
  17074. idBlock: {
  17075. tagClass: 3,
  17076. tagNumber: 0
  17077. },
  17078. value: [this.responseBytes.toSchema()]
  17079. }));
  17080. }
  17081. return (new asn1js.Sequence({
  17082. value: outputArray
  17083. }));
  17084. }
  17085. toJSON() {
  17086. const res = {
  17087. responseStatus: this.responseStatus.toJSON()
  17088. };
  17089. if (this.responseBytes) {
  17090. res.responseBytes = this.responseBytes.toJSON();
  17091. }
  17092. return res;
  17093. }
  17094. async getCertificateStatus(certificate, issuerCertificate, crypto = getCrypto(true)) {
  17095. let basicResponse;
  17096. const result = {
  17097. isForCertificate: false,
  17098. status: 2
  17099. };
  17100. if (!this.responseBytes)
  17101. return result;
  17102. if (this.responseBytes.responseType !== id_PKIX_OCSP_Basic)
  17103. return result;
  17104. try {
  17105. const asn1Basic = asn1js.fromBER(this.responseBytes.response.valueBlock.valueHexView);
  17106. AsnError.assert(asn1Basic, "Basic OCSP response");
  17107. basicResponse = new BasicOCSPResponse({ schema: asn1Basic.result });
  17108. }
  17109. catch {
  17110. return result;
  17111. }
  17112. return basicResponse.getCertificateStatus(certificate, issuerCertificate, crypto);
  17113. }
  17114. async sign(privateKey, hashAlgorithm, crypto = getCrypto(true)) {
  17115. var _a;
  17116. if (this.responseBytes && this.responseBytes.responseType === id_PKIX_OCSP_Basic) {
  17117. const basicResponse = BasicOCSPResponse.fromBER(this.responseBytes.response.valueBlock.valueHexView);
  17118. return basicResponse.sign(privateKey, hashAlgorithm, crypto);
  17119. }
  17120. throw new Error(`Unknown ResponseBytes type: ${((_a = this.responseBytes) === null || _a === void 0 ? void 0 : _a.responseType) || "Unknown"}`);
  17121. }
  17122. async verify(issuerCertificate = null, crypto = getCrypto(true)) {
  17123. var _a;
  17124. if ((RESPONSE_BYTES in this) === false)
  17125. throw new Error("Empty ResponseBytes field");
  17126. if (this.responseBytes && this.responseBytes.responseType === id_PKIX_OCSP_Basic) {
  17127. const basicResponse = BasicOCSPResponse.fromBER(this.responseBytes.response.valueBlock.valueHexView);
  17128. if (issuerCertificate !== null) {
  17129. if (!basicResponse.certs) {
  17130. basicResponse.certs = [];
  17131. }
  17132. basicResponse.certs.push(issuerCertificate);
  17133. }
  17134. return basicResponse.verify({}, crypto);
  17135. }
  17136. throw new Error(`Unknown ResponseBytes type: ${((_a = this.responseBytes) === null || _a === void 0 ? void 0 : _a.responseType) || "Unknown"}`);
  17137. }
  17138. }
  17139. OCSPResponse.CLASS_NAME = "OCSPResponse";
  17140. const TYPE = "type";
  17141. const ATTRIBUTES = "attributes";
  17142. const ENCODED_VALUE = "encodedValue";
  17143. const CLEAR_PROPS$6 = [
  17144. ATTRIBUTES
  17145. ];
  17146. class SignedAndUnsignedAttributes extends PkiObject {
  17147. constructor(parameters = {}) {
  17148. super();
  17149. this.type = pvutils.getParametersValue(parameters, TYPE, SignedAndUnsignedAttributes.defaultValues(TYPE));
  17150. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES, SignedAndUnsignedAttributes.defaultValues(ATTRIBUTES));
  17151. this.encodedValue = pvutils.getParametersValue(parameters, ENCODED_VALUE, SignedAndUnsignedAttributes.defaultValues(ENCODED_VALUE));
  17152. if (parameters.schema) {
  17153. this.fromSchema(parameters.schema);
  17154. }
  17155. }
  17156. static defaultValues(memberName) {
  17157. switch (memberName) {
  17158. case TYPE:
  17159. return (-1);
  17160. case ATTRIBUTES:
  17161. return [];
  17162. case ENCODED_VALUE:
  17163. return EMPTY_BUFFER;
  17164. default:
  17165. return super.defaultValues(memberName);
  17166. }
  17167. }
  17168. static compareWithDefault(memberName, memberValue) {
  17169. switch (memberName) {
  17170. case TYPE:
  17171. return (memberValue === SignedAndUnsignedAttributes.defaultValues(TYPE));
  17172. case ATTRIBUTES:
  17173. return (memberValue.length === 0);
  17174. case ENCODED_VALUE:
  17175. return (memberValue.byteLength === 0);
  17176. default:
  17177. return super.defaultValues(memberName);
  17178. }
  17179. }
  17180. static schema(parameters = {}) {
  17181. const names = pvutils.getParametersValue(parameters, "names", {});
  17182. return (new asn1js.Constructed({
  17183. name: (names.blockName || EMPTY_STRING),
  17184. optional: true,
  17185. idBlock: {
  17186. tagClass: 3,
  17187. tagNumber: names.tagNumber || 0
  17188. },
  17189. value: [
  17190. new asn1js.Repeated({
  17191. name: (names.attributes || EMPTY_STRING),
  17192. value: Attribute.schema()
  17193. })
  17194. ]
  17195. }));
  17196. }
  17197. fromSchema(schema) {
  17198. pvutils.clearProps(schema, CLEAR_PROPS$6);
  17199. const asn1 = asn1js.compareSchema(schema, schema, SignedAndUnsignedAttributes.schema({
  17200. names: {
  17201. tagNumber: this.type,
  17202. attributes: ATTRIBUTES
  17203. }
  17204. }));
  17205. AsnError.assertSchema(asn1, this.className);
  17206. this.type = asn1.result.idBlock.tagNumber;
  17207. this.encodedValue = pvtsutils.BufferSourceConverter.toArrayBuffer(asn1.result.valueBeforeDecodeView);
  17208. const encodedView = new Uint8Array(this.encodedValue);
  17209. encodedView[0] = 0x31;
  17210. if ((ATTRIBUTES in asn1.result) === false) {
  17211. if (this.type === 0)
  17212. throw new Error("Wrong structure of SignedUnsignedAttributes");
  17213. else
  17214. return;
  17215. }
  17216. this.attributes = Array.from(asn1.result.attributes, element => new Attribute({ schema: element }));
  17217. }
  17218. toSchema() {
  17219. if (SignedAndUnsignedAttributes.compareWithDefault(TYPE, this.type) || SignedAndUnsignedAttributes.compareWithDefault(ATTRIBUTES, this.attributes))
  17220. throw new Error("Incorrectly initialized \"SignedAndUnsignedAttributes\" class");
  17221. return (new asn1js.Constructed({
  17222. optional: true,
  17223. idBlock: {
  17224. tagClass: 3,
  17225. tagNumber: this.type
  17226. },
  17227. value: Array.from(this.attributes, o => o.toSchema())
  17228. }));
  17229. }
  17230. toJSON() {
  17231. if (SignedAndUnsignedAttributes.compareWithDefault(TYPE, this.type) || SignedAndUnsignedAttributes.compareWithDefault(ATTRIBUTES, this.attributes))
  17232. throw new Error("Incorrectly initialized \"SignedAndUnsignedAttributes\" class");
  17233. return {
  17234. type: this.type,
  17235. attributes: Array.from(this.attributes, o => o.toJSON())
  17236. };
  17237. }
  17238. }
  17239. SignedAndUnsignedAttributes.CLASS_NAME = "SignedAndUnsignedAttributes";
  17240. const VERSION$4 = "version";
  17241. const SID = "sid";
  17242. const DIGEST_ALGORITHM = "digestAlgorithm";
  17243. const SIGNED_ATTRS = "signedAttrs";
  17244. const SIGNATURE_ALGORITHM = "signatureAlgorithm";
  17245. const SIGNATURE = "signature";
  17246. const UNSIGNED_ATTRS = "unsignedAttrs";
  17247. const SIGNER_INFO = "SignerInfo";
  17248. const SIGNER_INFO_VERSION = `${SIGNER_INFO}.${VERSION$4}`;
  17249. const SIGNER_INFO_SID = `${SIGNER_INFO}.${SID}`;
  17250. const SIGNER_INFO_DIGEST_ALGORITHM = `${SIGNER_INFO}.${DIGEST_ALGORITHM}`;
  17251. const SIGNER_INFO_SIGNED_ATTRS = `${SIGNER_INFO}.${SIGNED_ATTRS}`;
  17252. const SIGNER_INFO_SIGNATURE_ALGORITHM = `${SIGNER_INFO}.${SIGNATURE_ALGORITHM}`;
  17253. const SIGNER_INFO_SIGNATURE = `${SIGNER_INFO}.${SIGNATURE}`;
  17254. const SIGNER_INFO_UNSIGNED_ATTRS = `${SIGNER_INFO}.${UNSIGNED_ATTRS}`;
  17255. const CLEAR_PROPS$5 = [
  17256. SIGNER_INFO_VERSION,
  17257. SIGNER_INFO_SID,
  17258. SIGNER_INFO_DIGEST_ALGORITHM,
  17259. SIGNER_INFO_SIGNED_ATTRS,
  17260. SIGNER_INFO_SIGNATURE_ALGORITHM,
  17261. SIGNER_INFO_SIGNATURE,
  17262. SIGNER_INFO_UNSIGNED_ATTRS
  17263. ];
  17264. class SignerInfo extends PkiObject {
  17265. constructor(parameters = {}) {
  17266. super();
  17267. this.version = pvutils.getParametersValue(parameters, VERSION$4, SignerInfo.defaultValues(VERSION$4));
  17268. this.sid = pvutils.getParametersValue(parameters, SID, SignerInfo.defaultValues(SID));
  17269. this.digestAlgorithm = pvutils.getParametersValue(parameters, DIGEST_ALGORITHM, SignerInfo.defaultValues(DIGEST_ALGORITHM));
  17270. if (SIGNED_ATTRS in parameters) {
  17271. this.signedAttrs = pvutils.getParametersValue(parameters, SIGNED_ATTRS, SignerInfo.defaultValues(SIGNED_ATTRS));
  17272. }
  17273. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM, SignerInfo.defaultValues(SIGNATURE_ALGORITHM));
  17274. this.signature = pvutils.getParametersValue(parameters, SIGNATURE, SignerInfo.defaultValues(SIGNATURE));
  17275. if (UNSIGNED_ATTRS in parameters) {
  17276. this.unsignedAttrs = pvutils.getParametersValue(parameters, UNSIGNED_ATTRS, SignerInfo.defaultValues(UNSIGNED_ATTRS));
  17277. }
  17278. if (parameters.schema) {
  17279. this.fromSchema(parameters.schema);
  17280. }
  17281. }
  17282. static defaultValues(memberName) {
  17283. switch (memberName) {
  17284. case VERSION$4:
  17285. return 0;
  17286. case SID:
  17287. return new asn1js.Any();
  17288. case DIGEST_ALGORITHM:
  17289. return new AlgorithmIdentifier();
  17290. case SIGNED_ATTRS:
  17291. return new SignedAndUnsignedAttributes({ type: 0 });
  17292. case SIGNATURE_ALGORITHM:
  17293. return new AlgorithmIdentifier();
  17294. case SIGNATURE:
  17295. return new asn1js.OctetString();
  17296. case UNSIGNED_ATTRS:
  17297. return new SignedAndUnsignedAttributes({ type: 1 });
  17298. default:
  17299. return super.defaultValues(memberName);
  17300. }
  17301. }
  17302. static compareWithDefault(memberName, memberValue) {
  17303. switch (memberName) {
  17304. case VERSION$4:
  17305. return (SignerInfo.defaultValues(VERSION$4) === memberValue);
  17306. case SID:
  17307. return (memberValue instanceof asn1js.Any);
  17308. case DIGEST_ALGORITHM:
  17309. if ((memberValue instanceof AlgorithmIdentifier) === false)
  17310. return false;
  17311. return memberValue.isEqual(SignerInfo.defaultValues(DIGEST_ALGORITHM));
  17312. case SIGNED_ATTRS:
  17313. return ((SignedAndUnsignedAttributes.compareWithDefault("type", memberValue.type))
  17314. && (SignedAndUnsignedAttributes.compareWithDefault("attributes", memberValue.attributes))
  17315. && (SignedAndUnsignedAttributes.compareWithDefault("encodedValue", memberValue.encodedValue)));
  17316. case SIGNATURE_ALGORITHM:
  17317. if ((memberValue instanceof AlgorithmIdentifier) === false)
  17318. return false;
  17319. return memberValue.isEqual(SignerInfo.defaultValues(SIGNATURE_ALGORITHM));
  17320. case SIGNATURE:
  17321. case UNSIGNED_ATTRS:
  17322. return ((SignedAndUnsignedAttributes.compareWithDefault("type", memberValue.type))
  17323. && (SignedAndUnsignedAttributes.compareWithDefault("attributes", memberValue.attributes))
  17324. && (SignedAndUnsignedAttributes.compareWithDefault("encodedValue", memberValue.encodedValue)));
  17325. default:
  17326. return super.defaultValues(memberName);
  17327. }
  17328. }
  17329. static schema(parameters = {}) {
  17330. const names = pvutils.getParametersValue(parameters, "names", {});
  17331. return (new asn1js.Sequence({
  17332. name: SIGNER_INFO,
  17333. value: [
  17334. new asn1js.Integer({ name: (names.version || SIGNER_INFO_VERSION) }),
  17335. new asn1js.Choice({
  17336. value: [
  17337. IssuerAndSerialNumber.schema(names.sidSchema || {
  17338. names: {
  17339. blockName: SIGNER_INFO_SID
  17340. }
  17341. }),
  17342. new asn1js.Choice({
  17343. value: [
  17344. new asn1js.Constructed({
  17345. optional: true,
  17346. name: (names.sid || SIGNER_INFO_SID),
  17347. idBlock: {
  17348. tagClass: 3,
  17349. tagNumber: 0
  17350. },
  17351. value: [new asn1js.OctetString()]
  17352. }),
  17353. new asn1js.Primitive({
  17354. optional: true,
  17355. name: (names.sid || SIGNER_INFO_SID),
  17356. idBlock: {
  17357. tagClass: 3,
  17358. tagNumber: 0
  17359. }
  17360. }),
  17361. ]
  17362. }),
  17363. ]
  17364. }),
  17365. AlgorithmIdentifier.schema(names.digestAlgorithm || {
  17366. names: {
  17367. blockName: SIGNER_INFO_DIGEST_ALGORITHM
  17368. }
  17369. }),
  17370. SignedAndUnsignedAttributes.schema(names.signedAttrs || {
  17371. names: {
  17372. blockName: SIGNER_INFO_SIGNED_ATTRS,
  17373. tagNumber: 0
  17374. }
  17375. }),
  17376. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  17377. names: {
  17378. blockName: SIGNER_INFO_SIGNATURE_ALGORITHM
  17379. }
  17380. }),
  17381. new asn1js.OctetString({ name: (names.signature || SIGNER_INFO_SIGNATURE) }),
  17382. SignedAndUnsignedAttributes.schema(names.unsignedAttrs || {
  17383. names: {
  17384. blockName: SIGNER_INFO_UNSIGNED_ATTRS,
  17385. tagNumber: 1
  17386. }
  17387. })
  17388. ]
  17389. }));
  17390. }
  17391. fromSchema(schema) {
  17392. pvutils.clearProps(schema, CLEAR_PROPS$5);
  17393. const asn1 = asn1js.compareSchema(schema, schema, SignerInfo.schema());
  17394. AsnError.assertSchema(asn1, this.className);
  17395. this.version = asn1.result[SIGNER_INFO_VERSION].valueBlock.valueDec;
  17396. const currentSid = asn1.result[SIGNER_INFO_SID];
  17397. if (currentSid.idBlock.tagClass === 1)
  17398. this.sid = new IssuerAndSerialNumber({ schema: currentSid });
  17399. else
  17400. this.sid = currentSid;
  17401. this.digestAlgorithm = new AlgorithmIdentifier({ schema: asn1.result[SIGNER_INFO_DIGEST_ALGORITHM] });
  17402. if (SIGNER_INFO_SIGNED_ATTRS in asn1.result)
  17403. this.signedAttrs = new SignedAndUnsignedAttributes({ type: 0, schema: asn1.result[SIGNER_INFO_SIGNED_ATTRS] });
  17404. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result[SIGNER_INFO_SIGNATURE_ALGORITHM] });
  17405. this.signature = asn1.result[SIGNER_INFO_SIGNATURE];
  17406. if (SIGNER_INFO_UNSIGNED_ATTRS in asn1.result)
  17407. this.unsignedAttrs = new SignedAndUnsignedAttributes({ type: 1, schema: asn1.result[SIGNER_INFO_UNSIGNED_ATTRS] });
  17408. }
  17409. toSchema() {
  17410. if (SignerInfo.compareWithDefault(SID, this.sid))
  17411. throw new Error("Incorrectly initialized \"SignerInfo\" class");
  17412. const outputArray = [];
  17413. outputArray.push(new asn1js.Integer({ value: this.version }));
  17414. if (this.sid instanceof IssuerAndSerialNumber)
  17415. outputArray.push(this.sid.toSchema());
  17416. else
  17417. outputArray.push(this.sid);
  17418. outputArray.push(this.digestAlgorithm.toSchema());
  17419. if (this.signedAttrs) {
  17420. if (SignerInfo.compareWithDefault(SIGNED_ATTRS, this.signedAttrs) === false)
  17421. outputArray.push(this.signedAttrs.toSchema());
  17422. }
  17423. outputArray.push(this.signatureAlgorithm.toSchema());
  17424. outputArray.push(this.signature);
  17425. if (this.unsignedAttrs) {
  17426. if (SignerInfo.compareWithDefault(UNSIGNED_ATTRS, this.unsignedAttrs) === false)
  17427. outputArray.push(this.unsignedAttrs.toSchema());
  17428. }
  17429. return (new asn1js.Sequence({
  17430. value: outputArray
  17431. }));
  17432. }
  17433. toJSON() {
  17434. if (SignerInfo.compareWithDefault(SID, this.sid)) {
  17435. throw new Error("Incorrectly initialized \"SignerInfo\" class");
  17436. }
  17437. const res = {
  17438. version: this.version,
  17439. digestAlgorithm: this.digestAlgorithm.toJSON(),
  17440. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  17441. signature: this.signature.toJSON(),
  17442. };
  17443. if (!(this.sid instanceof asn1js.Any))
  17444. res.sid = this.sid.toJSON();
  17445. if (this.signedAttrs && SignerInfo.compareWithDefault(SIGNED_ATTRS, this.signedAttrs) === false) {
  17446. res.signedAttrs = this.signedAttrs.toJSON();
  17447. }
  17448. if (this.unsignedAttrs && SignerInfo.compareWithDefault(UNSIGNED_ATTRS, this.unsignedAttrs) === false) {
  17449. res.unsignedAttrs = this.unsignedAttrs.toJSON();
  17450. }
  17451. return res;
  17452. }
  17453. }
  17454. SignerInfo.CLASS_NAME = "SignerInfo";
  17455. const VERSION$3 = "version";
  17456. const POLICY = "policy";
  17457. const MESSAGE_IMPRINT$1 = "messageImprint";
  17458. const SERIAL_NUMBER = "serialNumber";
  17459. const GEN_TIME = "genTime";
  17460. const ORDERING = "ordering";
  17461. const NONCE$1 = "nonce";
  17462. const ACCURACY = "accuracy";
  17463. const TSA = "tsa";
  17464. const EXTENSIONS$1 = "extensions";
  17465. const TST_INFO = "TSTInfo";
  17466. const TST_INFO_VERSION = `${TST_INFO}.${VERSION$3}`;
  17467. const TST_INFO_POLICY = `${TST_INFO}.${POLICY}`;
  17468. const TST_INFO_MESSAGE_IMPRINT = `${TST_INFO}.${MESSAGE_IMPRINT$1}`;
  17469. const TST_INFO_SERIAL_NUMBER = `${TST_INFO}.${SERIAL_NUMBER}`;
  17470. const TST_INFO_GEN_TIME = `${TST_INFO}.${GEN_TIME}`;
  17471. const TST_INFO_ACCURACY = `${TST_INFO}.${ACCURACY}`;
  17472. const TST_INFO_ORDERING = `${TST_INFO}.${ORDERING}`;
  17473. const TST_INFO_NONCE = `${TST_INFO}.${NONCE$1}`;
  17474. const TST_INFO_TSA = `${TST_INFO}.${TSA}`;
  17475. const TST_INFO_EXTENSIONS = `${TST_INFO}.${EXTENSIONS$1}`;
  17476. const CLEAR_PROPS$4 = [
  17477. TST_INFO_VERSION,
  17478. TST_INFO_POLICY,
  17479. TST_INFO_MESSAGE_IMPRINT,
  17480. TST_INFO_SERIAL_NUMBER,
  17481. TST_INFO_GEN_TIME,
  17482. TST_INFO_ACCURACY,
  17483. TST_INFO_ORDERING,
  17484. TST_INFO_NONCE,
  17485. TST_INFO_TSA,
  17486. TST_INFO_EXTENSIONS
  17487. ];
  17488. class TSTInfo extends PkiObject {
  17489. constructor(parameters = {}) {
  17490. super();
  17491. this.version = pvutils.getParametersValue(parameters, VERSION$3, TSTInfo.defaultValues(VERSION$3));
  17492. this.policy = pvutils.getParametersValue(parameters, POLICY, TSTInfo.defaultValues(POLICY));
  17493. this.messageImprint = pvutils.getParametersValue(parameters, MESSAGE_IMPRINT$1, TSTInfo.defaultValues(MESSAGE_IMPRINT$1));
  17494. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER, TSTInfo.defaultValues(SERIAL_NUMBER));
  17495. this.genTime = pvutils.getParametersValue(parameters, GEN_TIME, TSTInfo.defaultValues(GEN_TIME));
  17496. if (ACCURACY in parameters) {
  17497. this.accuracy = pvutils.getParametersValue(parameters, ACCURACY, TSTInfo.defaultValues(ACCURACY));
  17498. }
  17499. if (ORDERING in parameters) {
  17500. this.ordering = pvutils.getParametersValue(parameters, ORDERING, TSTInfo.defaultValues(ORDERING));
  17501. }
  17502. if (NONCE$1 in parameters) {
  17503. this.nonce = pvutils.getParametersValue(parameters, NONCE$1, TSTInfo.defaultValues(NONCE$1));
  17504. }
  17505. if (TSA in parameters) {
  17506. this.tsa = pvutils.getParametersValue(parameters, TSA, TSTInfo.defaultValues(TSA));
  17507. }
  17508. if (EXTENSIONS$1 in parameters) {
  17509. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$1, TSTInfo.defaultValues(EXTENSIONS$1));
  17510. }
  17511. if (parameters.schema) {
  17512. this.fromSchema(parameters.schema);
  17513. }
  17514. }
  17515. static defaultValues(memberName) {
  17516. switch (memberName) {
  17517. case VERSION$3:
  17518. return 0;
  17519. case POLICY:
  17520. return EMPTY_STRING;
  17521. case MESSAGE_IMPRINT$1:
  17522. return new MessageImprint();
  17523. case SERIAL_NUMBER:
  17524. return new asn1js.Integer();
  17525. case GEN_TIME:
  17526. return new Date(0, 0, 0);
  17527. case ACCURACY:
  17528. return new Accuracy();
  17529. case ORDERING:
  17530. return false;
  17531. case NONCE$1:
  17532. return new asn1js.Integer();
  17533. case TSA:
  17534. return new GeneralName();
  17535. case EXTENSIONS$1:
  17536. return [];
  17537. default:
  17538. return super.defaultValues(memberName);
  17539. }
  17540. }
  17541. static compareWithDefault(memberName, memberValue) {
  17542. switch (memberName) {
  17543. case VERSION$3:
  17544. case POLICY:
  17545. case GEN_TIME:
  17546. case ORDERING:
  17547. return (memberValue === TSTInfo.defaultValues(ORDERING));
  17548. case MESSAGE_IMPRINT$1:
  17549. return ((MessageImprint.compareWithDefault(HASH_ALGORITHM, memberValue.hashAlgorithm)) &&
  17550. (MessageImprint.compareWithDefault(HASHED_MESSAGE, memberValue.hashedMessage)));
  17551. case SERIAL_NUMBER:
  17552. case NONCE$1:
  17553. return (memberValue.isEqual(TSTInfo.defaultValues(NONCE$1)));
  17554. case ACCURACY:
  17555. return ((Accuracy.compareWithDefault(SECONDS, memberValue.seconds)) &&
  17556. (Accuracy.compareWithDefault(MILLIS, memberValue.millis)) &&
  17557. (Accuracy.compareWithDefault(MICROS, memberValue.micros)));
  17558. case TSA:
  17559. return ((GeneralName.compareWithDefault(TYPE$4, memberValue.type)) &&
  17560. (GeneralName.compareWithDefault(VALUE$5, memberValue.value)));
  17561. case EXTENSIONS$1:
  17562. return (memberValue.length === 0);
  17563. default:
  17564. return super.defaultValues(memberName);
  17565. }
  17566. }
  17567. static schema(parameters = {}) {
  17568. const names = pvutils.getParametersValue(parameters, "names", {});
  17569. return (new asn1js.Sequence({
  17570. name: (names.blockName || TST_INFO),
  17571. value: [
  17572. new asn1js.Integer({ name: (names.version || TST_INFO_VERSION) }),
  17573. new asn1js.ObjectIdentifier({ name: (names.policy || TST_INFO_POLICY) }),
  17574. MessageImprint.schema(names.messageImprint || {
  17575. names: {
  17576. blockName: TST_INFO_MESSAGE_IMPRINT
  17577. }
  17578. }),
  17579. new asn1js.Integer({ name: (names.serialNumber || TST_INFO_SERIAL_NUMBER) }),
  17580. new asn1js.GeneralizedTime({ name: (names.genTime || TST_INFO_GEN_TIME) }),
  17581. Accuracy.schema(names.accuracy || {
  17582. names: {
  17583. blockName: TST_INFO_ACCURACY
  17584. }
  17585. }),
  17586. new asn1js.Boolean({
  17587. name: (names.ordering || TST_INFO_ORDERING),
  17588. optional: true
  17589. }),
  17590. new asn1js.Integer({
  17591. name: (names.nonce || TST_INFO_NONCE),
  17592. optional: true
  17593. }),
  17594. new asn1js.Constructed({
  17595. optional: true,
  17596. idBlock: {
  17597. tagClass: 3,
  17598. tagNumber: 0
  17599. },
  17600. value: [GeneralName.schema(names.tsa || {
  17601. names: {
  17602. blockName: TST_INFO_TSA
  17603. }
  17604. })]
  17605. }),
  17606. new asn1js.Constructed({
  17607. optional: true,
  17608. idBlock: {
  17609. tagClass: 3,
  17610. tagNumber: 1
  17611. },
  17612. value: [
  17613. new asn1js.Repeated({
  17614. name: (names.extensions || TST_INFO_EXTENSIONS),
  17615. value: Extension.schema(names.extension || {})
  17616. })
  17617. ]
  17618. })
  17619. ]
  17620. }));
  17621. }
  17622. fromSchema(schema) {
  17623. pvutils.clearProps(schema, CLEAR_PROPS$4);
  17624. const asn1 = asn1js.compareSchema(schema, schema, TSTInfo.schema());
  17625. AsnError.assertSchema(asn1, this.className);
  17626. this.version = asn1.result[TST_INFO_VERSION].valueBlock.valueDec;
  17627. this.policy = asn1.result[TST_INFO_POLICY].valueBlock.toString();
  17628. this.messageImprint = new MessageImprint({ schema: asn1.result[TST_INFO_MESSAGE_IMPRINT] });
  17629. this.serialNumber = asn1.result[TST_INFO_SERIAL_NUMBER];
  17630. this.genTime = asn1.result[TST_INFO_GEN_TIME].toDate();
  17631. if (TST_INFO_ACCURACY in asn1.result)
  17632. this.accuracy = new Accuracy({ schema: asn1.result[TST_INFO_ACCURACY] });
  17633. if (TST_INFO_ORDERING in asn1.result)
  17634. this.ordering = asn1.result[TST_INFO_ORDERING].valueBlock.value;
  17635. if (TST_INFO_NONCE in asn1.result)
  17636. this.nonce = asn1.result[TST_INFO_NONCE];
  17637. if (TST_INFO_TSA in asn1.result)
  17638. this.tsa = new GeneralName({ schema: asn1.result[TST_INFO_TSA] });
  17639. if (TST_INFO_EXTENSIONS in asn1.result)
  17640. this.extensions = Array.from(asn1.result[TST_INFO_EXTENSIONS], element => new Extension({ schema: element }));
  17641. }
  17642. toSchema() {
  17643. const outputArray = [];
  17644. outputArray.push(new asn1js.Integer({ value: this.version }));
  17645. outputArray.push(new asn1js.ObjectIdentifier({ value: this.policy }));
  17646. outputArray.push(this.messageImprint.toSchema());
  17647. outputArray.push(this.serialNumber);
  17648. outputArray.push(new asn1js.GeneralizedTime({ valueDate: this.genTime }));
  17649. if (this.accuracy)
  17650. outputArray.push(this.accuracy.toSchema());
  17651. if (this.ordering !== undefined)
  17652. outputArray.push(new asn1js.Boolean({ value: this.ordering }));
  17653. if (this.nonce)
  17654. outputArray.push(this.nonce);
  17655. if (this.tsa) {
  17656. outputArray.push(new asn1js.Constructed({
  17657. optional: true,
  17658. idBlock: {
  17659. tagClass: 3,
  17660. tagNumber: 0
  17661. },
  17662. value: [this.tsa.toSchema()]
  17663. }));
  17664. }
  17665. if (this.extensions) {
  17666. outputArray.push(new asn1js.Constructed({
  17667. optional: true,
  17668. idBlock: {
  17669. tagClass: 3,
  17670. tagNumber: 1
  17671. },
  17672. value: Array.from(this.extensions, o => o.toSchema())
  17673. }));
  17674. }
  17675. return (new asn1js.Sequence({
  17676. value: outputArray
  17677. }));
  17678. }
  17679. toJSON() {
  17680. const res = {
  17681. version: this.version,
  17682. policy: this.policy,
  17683. messageImprint: this.messageImprint.toJSON(),
  17684. serialNumber: this.serialNumber.toJSON(),
  17685. genTime: this.genTime
  17686. };
  17687. if (this.accuracy)
  17688. res.accuracy = this.accuracy.toJSON();
  17689. if (this.ordering !== undefined)
  17690. res.ordering = this.ordering;
  17691. if (this.nonce)
  17692. res.nonce = this.nonce.toJSON();
  17693. if (this.tsa)
  17694. res.tsa = this.tsa.toJSON();
  17695. if (this.extensions)
  17696. res.extensions = Array.from(this.extensions, o => o.toJSON());
  17697. return res;
  17698. }
  17699. async verify(params, crypto = getCrypto(true)) {
  17700. if (!params.data) {
  17701. throw new Error("\"data\" is a mandatory attribute for TST_INFO verification");
  17702. }
  17703. const data = params.data;
  17704. if (params.notBefore) {
  17705. if (this.genTime < params.notBefore)
  17706. throw new Error("Generation time for TSTInfo object is less than notBefore value");
  17707. }
  17708. if (params.notAfter) {
  17709. if (this.genTime > params.notAfter)
  17710. throw new Error("Generation time for TSTInfo object is more than notAfter value");
  17711. }
  17712. const shaAlgorithm = crypto.getAlgorithmByOID(this.messageImprint.hashAlgorithm.algorithmId, true, "MessageImprint.hashAlgorithm");
  17713. const hash = await crypto.digest(shaAlgorithm.name, new Uint8Array(data));
  17714. return pvtsutils.BufferSourceConverter.isEqual(hash, this.messageImprint.hashedMessage.valueBlock.valueHexView);
  17715. }
  17716. }
  17717. TSTInfo.CLASS_NAME = "TSTInfo";
  17718. const VERSION$2 = "version";
  17719. const DIGEST_ALGORITHMS = "digestAlgorithms";
  17720. const ENCAP_CONTENT_INFO = "encapContentInfo";
  17721. const CERTIFICATES = "certificates";
  17722. const CRLS = "crls";
  17723. const SIGNER_INFOS = "signerInfos";
  17724. const OCSPS = "ocsps";
  17725. const SIGNED_DATA = "SignedData";
  17726. const SIGNED_DATA_VERSION = `${SIGNED_DATA}.${VERSION$2}`;
  17727. const SIGNED_DATA_DIGEST_ALGORITHMS = `${SIGNED_DATA}.${DIGEST_ALGORITHMS}`;
  17728. const SIGNED_DATA_ENCAP_CONTENT_INFO = `${SIGNED_DATA}.${ENCAP_CONTENT_INFO}`;
  17729. const SIGNED_DATA_CERTIFICATES = `${SIGNED_DATA}.${CERTIFICATES}`;
  17730. const SIGNED_DATA_CRLS = `${SIGNED_DATA}.${CRLS}`;
  17731. const SIGNED_DATA_SIGNER_INFOS = `${SIGNED_DATA}.${SIGNER_INFOS}`;
  17732. const CLEAR_PROPS$3 = [
  17733. SIGNED_DATA_VERSION,
  17734. SIGNED_DATA_DIGEST_ALGORITHMS,
  17735. SIGNED_DATA_ENCAP_CONTENT_INFO,
  17736. SIGNED_DATA_CERTIFICATES,
  17737. SIGNED_DATA_CRLS,
  17738. SIGNED_DATA_SIGNER_INFOS
  17739. ];
  17740. class SignedDataVerifyError extends Error {
  17741. constructor({ message, code = 0, date = new Date(), signatureVerified = null, signerCertificate = null, signerCertificateVerified = null, timestampSerial = null, certificatePath = [], }) {
  17742. super(message);
  17743. this.name = "SignedDataVerifyError";
  17744. this.date = date;
  17745. this.code = code;
  17746. this.timestampSerial = timestampSerial;
  17747. this.signatureVerified = signatureVerified;
  17748. this.signerCertificate = signerCertificate;
  17749. this.signerCertificateVerified = signerCertificateVerified;
  17750. this.certificatePath = certificatePath;
  17751. }
  17752. }
  17753. class SignedData extends PkiObject {
  17754. constructor(parameters = {}) {
  17755. super();
  17756. this.version = pvutils.getParametersValue(parameters, VERSION$2, SignedData.defaultValues(VERSION$2));
  17757. this.digestAlgorithms = pvutils.getParametersValue(parameters, DIGEST_ALGORITHMS, SignedData.defaultValues(DIGEST_ALGORITHMS));
  17758. this.encapContentInfo = pvutils.getParametersValue(parameters, ENCAP_CONTENT_INFO, SignedData.defaultValues(ENCAP_CONTENT_INFO));
  17759. if (CERTIFICATES in parameters) {
  17760. this.certificates = pvutils.getParametersValue(parameters, CERTIFICATES, SignedData.defaultValues(CERTIFICATES));
  17761. }
  17762. if (CRLS in parameters) {
  17763. this.crls = pvutils.getParametersValue(parameters, CRLS, SignedData.defaultValues(CRLS));
  17764. }
  17765. if (OCSPS in parameters) {
  17766. this.ocsps = pvutils.getParametersValue(parameters, OCSPS, SignedData.defaultValues(OCSPS));
  17767. }
  17768. this.signerInfos = pvutils.getParametersValue(parameters, SIGNER_INFOS, SignedData.defaultValues(SIGNER_INFOS));
  17769. if (parameters.schema) {
  17770. this.fromSchema(parameters.schema);
  17771. }
  17772. }
  17773. static defaultValues(memberName) {
  17774. switch (memberName) {
  17775. case VERSION$2:
  17776. return 0;
  17777. case DIGEST_ALGORITHMS:
  17778. return [];
  17779. case ENCAP_CONTENT_INFO:
  17780. return new EncapsulatedContentInfo();
  17781. case CERTIFICATES:
  17782. return [];
  17783. case CRLS:
  17784. return [];
  17785. case OCSPS:
  17786. return [];
  17787. case SIGNER_INFOS:
  17788. return [];
  17789. default:
  17790. return super.defaultValues(memberName);
  17791. }
  17792. }
  17793. static compareWithDefault(memberName, memberValue) {
  17794. switch (memberName) {
  17795. case VERSION$2:
  17796. return (memberValue === SignedData.defaultValues(VERSION$2));
  17797. case ENCAP_CONTENT_INFO:
  17798. return EncapsulatedContentInfo.compareWithDefault("eContentType", memberValue.eContentType) &&
  17799. EncapsulatedContentInfo.compareWithDefault("eContent", memberValue.eContent);
  17800. case DIGEST_ALGORITHMS:
  17801. case CERTIFICATES:
  17802. case CRLS:
  17803. case OCSPS:
  17804. case SIGNER_INFOS:
  17805. return (memberValue.length === 0);
  17806. default:
  17807. return super.defaultValues(memberName);
  17808. }
  17809. }
  17810. static schema(parameters = {}) {
  17811. const names = pvutils.getParametersValue(parameters, "names", {});
  17812. if (names.optional === undefined) {
  17813. names.optional = false;
  17814. }
  17815. return (new asn1js.Sequence({
  17816. name: (names.blockName || SIGNED_DATA),
  17817. optional: names.optional,
  17818. value: [
  17819. new asn1js.Integer({ name: (names.version || SIGNED_DATA_VERSION) }),
  17820. new asn1js.Set({
  17821. value: [
  17822. new asn1js.Repeated({
  17823. name: (names.digestAlgorithms || SIGNED_DATA_DIGEST_ALGORITHMS),
  17824. value: AlgorithmIdentifier.schema()
  17825. })
  17826. ]
  17827. }),
  17828. EncapsulatedContentInfo.schema(names.encapContentInfo || {
  17829. names: {
  17830. blockName: SIGNED_DATA_ENCAP_CONTENT_INFO
  17831. }
  17832. }),
  17833. new asn1js.Constructed({
  17834. name: (names.certificates || SIGNED_DATA_CERTIFICATES),
  17835. optional: true,
  17836. idBlock: {
  17837. tagClass: 3,
  17838. tagNumber: 0
  17839. },
  17840. value: CertificateSet.schema().valueBlock.value
  17841. }),
  17842. new asn1js.Constructed({
  17843. optional: true,
  17844. idBlock: {
  17845. tagClass: 3,
  17846. tagNumber: 1
  17847. },
  17848. value: RevocationInfoChoices.schema(names.crls || {
  17849. names: {
  17850. crls: SIGNED_DATA_CRLS
  17851. }
  17852. }).valueBlock.value
  17853. }),
  17854. new asn1js.Set({
  17855. value: [
  17856. new asn1js.Repeated({
  17857. name: (names.signerInfos || SIGNED_DATA_SIGNER_INFOS),
  17858. value: SignerInfo.schema()
  17859. })
  17860. ]
  17861. })
  17862. ]
  17863. }));
  17864. }
  17865. fromSchema(schema) {
  17866. pvutils.clearProps(schema, CLEAR_PROPS$3);
  17867. const asn1 = asn1js.compareSchema(schema, schema, SignedData.schema());
  17868. AsnError.assertSchema(asn1, this.className);
  17869. this.version = asn1.result[SIGNED_DATA_VERSION].valueBlock.valueDec;
  17870. if (SIGNED_DATA_DIGEST_ALGORITHMS in asn1.result)
  17871. this.digestAlgorithms = Array.from(asn1.result[SIGNED_DATA_DIGEST_ALGORITHMS], algorithm => new AlgorithmIdentifier({ schema: algorithm }));
  17872. this.encapContentInfo = new EncapsulatedContentInfo({ schema: asn1.result[SIGNED_DATA_ENCAP_CONTENT_INFO] });
  17873. if (SIGNED_DATA_CERTIFICATES in asn1.result) {
  17874. const certificateSet = new CertificateSet({
  17875. schema: new asn1js.Set({
  17876. value: asn1.result[SIGNED_DATA_CERTIFICATES].valueBlock.value
  17877. })
  17878. });
  17879. this.certificates = certificateSet.certificates.slice(0);
  17880. }
  17881. if (SIGNED_DATA_CRLS in asn1.result) {
  17882. this.crls = Array.from(asn1.result[SIGNED_DATA_CRLS], (crl) => {
  17883. if (crl.idBlock.tagClass === 1)
  17884. return new CertificateRevocationList({ schema: crl });
  17885. crl.idBlock.tagClass = 1;
  17886. crl.idBlock.tagNumber = 16;
  17887. return new OtherRevocationInfoFormat({ schema: crl });
  17888. });
  17889. }
  17890. if (SIGNED_DATA_SIGNER_INFOS in asn1.result)
  17891. this.signerInfos = Array.from(asn1.result[SIGNED_DATA_SIGNER_INFOS], signerInfoSchema => new SignerInfo({ schema: signerInfoSchema }));
  17892. }
  17893. toSchema(encodeFlag = false) {
  17894. const outputArray = [];
  17895. if ((this.certificates && this.certificates.length && this.certificates.some(o => o instanceof OtherCertificateFormat))
  17896. || (this.crls && this.crls.length && this.crls.some(o => o instanceof OtherRevocationInfoFormat))) {
  17897. this.version = 5;
  17898. }
  17899. else if (this.certificates && this.certificates.length && this.certificates.some(o => o instanceof AttributeCertificateV2)) {
  17900. this.version = 4;
  17901. }
  17902. else if ((this.certificates && this.certificates.length && this.certificates.some(o => o instanceof AttributeCertificateV1))
  17903. || this.signerInfos.some(o => o.version === 3)
  17904. || this.encapContentInfo.eContentType !== SignedData.ID_DATA) {
  17905. this.version = 3;
  17906. }
  17907. else {
  17908. this.version = 1;
  17909. }
  17910. outputArray.push(new asn1js.Integer({ value: this.version }));
  17911. outputArray.push(new asn1js.Set({
  17912. value: Array.from(this.digestAlgorithms, algorithm => algorithm.toSchema())
  17913. }));
  17914. outputArray.push(this.encapContentInfo.toSchema());
  17915. if (this.certificates) {
  17916. const certificateSet = new CertificateSet({ certificates: this.certificates });
  17917. const certificateSetSchema = certificateSet.toSchema();
  17918. outputArray.push(new asn1js.Constructed({
  17919. idBlock: {
  17920. tagClass: 3,
  17921. tagNumber: 0
  17922. },
  17923. value: certificateSetSchema.valueBlock.value
  17924. }));
  17925. }
  17926. if (this.crls) {
  17927. outputArray.push(new asn1js.Constructed({
  17928. idBlock: {
  17929. tagClass: 3,
  17930. tagNumber: 1
  17931. },
  17932. value: Array.from(this.crls, crl => {
  17933. if (crl instanceof OtherRevocationInfoFormat) {
  17934. const crlSchema = crl.toSchema();
  17935. crlSchema.idBlock.tagClass = 3;
  17936. crlSchema.idBlock.tagNumber = 1;
  17937. return crlSchema;
  17938. }
  17939. return crl.toSchema(encodeFlag);
  17940. })
  17941. }));
  17942. }
  17943. outputArray.push(new asn1js.Set({
  17944. value: Array.from(this.signerInfos, signerInfo => signerInfo.toSchema())
  17945. }));
  17946. return (new asn1js.Sequence({
  17947. value: outputArray
  17948. }));
  17949. }
  17950. toJSON() {
  17951. const res = {
  17952. version: this.version,
  17953. digestAlgorithms: Array.from(this.digestAlgorithms, algorithm => algorithm.toJSON()),
  17954. encapContentInfo: this.encapContentInfo.toJSON(),
  17955. signerInfos: Array.from(this.signerInfos, signerInfo => signerInfo.toJSON()),
  17956. };
  17957. if (this.certificates) {
  17958. res.certificates = Array.from(this.certificates, certificate => certificate.toJSON());
  17959. }
  17960. if (this.crls) {
  17961. res.crls = Array.from(this.crls, crl => crl.toJSON());
  17962. }
  17963. return res;
  17964. }
  17965. async verify({ signer = (-1), data = (EMPTY_BUFFER), trustedCerts = [], checkDate = (new Date()), checkChain = false, passedWhenNotRevValues = false, extendedMode = false, findOrigin = null, findIssuer = null } = {}, crypto = getCrypto(true)) {
  17966. let signerCert = null;
  17967. let timestampSerial = null;
  17968. try {
  17969. let messageDigestValue = EMPTY_BUFFER;
  17970. let shaAlgorithm = EMPTY_STRING;
  17971. let certificatePath = [];
  17972. const signerInfo = this.signerInfos[signer];
  17973. if (!signerInfo) {
  17974. throw new SignedDataVerifyError({
  17975. date: checkDate,
  17976. code: 1,
  17977. message: "Unable to get signer by supplied index",
  17978. });
  17979. }
  17980. if (!this.certificates) {
  17981. throw new SignedDataVerifyError({
  17982. date: checkDate,
  17983. code: 2,
  17984. message: "No certificates attached to this signed data",
  17985. });
  17986. }
  17987. if (signerInfo.sid instanceof IssuerAndSerialNumber) {
  17988. for (const certificate of this.certificates) {
  17989. if (!(certificate instanceof Certificate))
  17990. continue;
  17991. if ((certificate.issuer.isEqual(signerInfo.sid.issuer)) &&
  17992. (certificate.serialNumber.isEqual(signerInfo.sid.serialNumber))) {
  17993. signerCert = certificate;
  17994. break;
  17995. }
  17996. }
  17997. }
  17998. else {
  17999. const sid = signerInfo.sid;
  18000. const keyId = sid.idBlock.isConstructed
  18001. ? sid.valueBlock.value[0].valueBlock.valueHex
  18002. : sid.valueBlock.valueHex;
  18003. for (const certificate of this.certificates) {
  18004. if (!(certificate instanceof Certificate)) {
  18005. continue;
  18006. }
  18007. const digest = await crypto.digest({ name: "sha-1" }, certificate.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView);
  18008. if (pvutils.isEqualBuffer(digest, keyId)) {
  18009. signerCert = certificate;
  18010. break;
  18011. }
  18012. }
  18013. }
  18014. if (!signerCert) {
  18015. throw new SignedDataVerifyError({
  18016. date: checkDate,
  18017. code: 3,
  18018. message: "Unable to find signer certificate",
  18019. });
  18020. }
  18021. if (this.encapContentInfo.eContentType === id_eContentType_TSTInfo) {
  18022. if (!this.encapContentInfo.eContent) {
  18023. throw new SignedDataVerifyError({
  18024. date: checkDate,
  18025. code: 15,
  18026. message: "Error during verification: TSTInfo eContent is empty",
  18027. signatureVerified: null,
  18028. signerCertificate: signerCert,
  18029. timestampSerial,
  18030. signerCertificateVerified: true
  18031. });
  18032. }
  18033. let tstInfo;
  18034. try {
  18035. tstInfo = TSTInfo.fromBER(this.encapContentInfo.eContent.valueBlock.valueHexView);
  18036. }
  18037. catch {
  18038. throw new SignedDataVerifyError({
  18039. date: checkDate,
  18040. code: 15,
  18041. message: "Error during verification: TSTInfo wrong ASN.1 schema ",
  18042. signatureVerified: null,
  18043. signerCertificate: signerCert,
  18044. timestampSerial,
  18045. signerCertificateVerified: true
  18046. });
  18047. }
  18048. checkDate = tstInfo.genTime;
  18049. timestampSerial = tstInfo.serialNumber.valueBlock.valueHexView.slice().buffer;
  18050. if (data.byteLength === 0) {
  18051. throw new SignedDataVerifyError({
  18052. date: checkDate,
  18053. code: 4,
  18054. message: "Missed detached data input array",
  18055. });
  18056. }
  18057. if (!(await tstInfo.verify({ data }, crypto))) {
  18058. throw new SignedDataVerifyError({
  18059. date: checkDate,
  18060. code: 15,
  18061. message: "Error during verification: TSTInfo verification is failed",
  18062. signatureVerified: false,
  18063. signerCertificate: signerCert,
  18064. timestampSerial,
  18065. signerCertificateVerified: true
  18066. });
  18067. }
  18068. }
  18069. if (checkChain) {
  18070. const certs = this.certificates.filter(certificate => (certificate instanceof Certificate && !!checkCA(certificate, signerCert)));
  18071. const chainParams = {
  18072. checkDate,
  18073. certs,
  18074. trustedCerts,
  18075. };
  18076. if (findIssuer) {
  18077. chainParams.findIssuer = findIssuer;
  18078. }
  18079. if (findOrigin) {
  18080. chainParams.findOrigin = findOrigin;
  18081. }
  18082. const chainEngine = new CertificateChainValidationEngine(chainParams);
  18083. chainEngine.certs.push(signerCert);
  18084. if (this.crls) {
  18085. for (const crl of this.crls) {
  18086. if ("thisUpdate" in crl)
  18087. chainEngine.crls.push(crl);
  18088. else {
  18089. if (crl.otherRevInfoFormat === id_PKIX_OCSP_Basic)
  18090. chainEngine.ocsps.push(new BasicOCSPResponse({ schema: crl.otherRevInfo }));
  18091. }
  18092. }
  18093. }
  18094. if (this.ocsps) {
  18095. chainEngine.ocsps.push(...(this.ocsps));
  18096. }
  18097. const verificationResult = await chainEngine.verify({ passedWhenNotRevValues }, crypto)
  18098. .catch(e => {
  18099. throw new SignedDataVerifyError({
  18100. date: checkDate,
  18101. code: 5,
  18102. message: `Validation of signer's certificate failed with error: ${((e instanceof Object) ? e.resultMessage : e)}`,
  18103. signerCertificate: signerCert,
  18104. signerCertificateVerified: false
  18105. });
  18106. });
  18107. if (verificationResult.certificatePath) {
  18108. certificatePath = verificationResult.certificatePath;
  18109. }
  18110. if (!verificationResult.result)
  18111. throw new SignedDataVerifyError({
  18112. date: checkDate,
  18113. code: 5,
  18114. message: `Validation of signer's certificate failed: ${verificationResult.resultMessage}`,
  18115. signerCertificate: signerCert,
  18116. signerCertificateVerified: false
  18117. });
  18118. }
  18119. const signerInfoHashAlgorithm = crypto.getAlgorithmByOID(signerInfo.digestAlgorithm.algorithmId);
  18120. if (!("name" in signerInfoHashAlgorithm)) {
  18121. throw new SignedDataVerifyError({
  18122. date: checkDate,
  18123. code: 7,
  18124. message: `Unsupported signature algorithm: ${signerInfo.digestAlgorithm.algorithmId}`,
  18125. signerCertificate: signerCert,
  18126. signerCertificateVerified: true
  18127. });
  18128. }
  18129. shaAlgorithm = signerInfoHashAlgorithm.name;
  18130. const eContent = this.encapContentInfo.eContent;
  18131. if (eContent) {
  18132. if ((eContent.idBlock.tagClass === 1) &&
  18133. (eContent.idBlock.tagNumber === 4)) {
  18134. data = eContent.getValue();
  18135. }
  18136. else
  18137. data = eContent.valueBlock.valueBeforeDecodeView.slice().buffer;
  18138. }
  18139. else {
  18140. if (data.byteLength === 0) {
  18141. throw new SignedDataVerifyError({
  18142. date: checkDate,
  18143. code: 8,
  18144. message: "Missed detached data input array",
  18145. signerCertificate: signerCert,
  18146. signerCertificateVerified: true
  18147. });
  18148. }
  18149. }
  18150. if (signerInfo.signedAttrs) {
  18151. let foundContentType = false;
  18152. let foundMessageDigest = false;
  18153. for (const attribute of signerInfo.signedAttrs.attributes) {
  18154. if (attribute.type === "1.2.840.113549.1.9.3")
  18155. foundContentType = true;
  18156. if (attribute.type === "1.2.840.113549.1.9.4") {
  18157. foundMessageDigest = true;
  18158. messageDigestValue = attribute.values[0].valueBlock.valueHex;
  18159. }
  18160. if (foundContentType && foundMessageDigest)
  18161. break;
  18162. }
  18163. if (foundContentType === false) {
  18164. throw new SignedDataVerifyError({
  18165. date: checkDate,
  18166. code: 9,
  18167. message: "Attribute \"content-type\" is a mandatory attribute for \"signed attributes\"",
  18168. signerCertificate: signerCert,
  18169. signerCertificateVerified: true
  18170. });
  18171. }
  18172. if (foundMessageDigest === false) {
  18173. throw new SignedDataVerifyError({
  18174. date: checkDate,
  18175. code: 10,
  18176. message: "Attribute \"message-digest\" is a mandatory attribute for \"signed attributes\"",
  18177. signatureVerified: null,
  18178. signerCertificate: signerCert,
  18179. signerCertificateVerified: true
  18180. });
  18181. }
  18182. }
  18183. if (signerInfo.signedAttrs) {
  18184. const messageDigest = await crypto.digest(shaAlgorithm, new Uint8Array(data));
  18185. if (!pvutils.isEqualBuffer(messageDigest, messageDigestValue)) {
  18186. throw new SignedDataVerifyError({
  18187. date: checkDate,
  18188. code: 15,
  18189. message: "Error during verification: Message digest doesn't match",
  18190. signatureVerified: null,
  18191. signerCertificate: signerCert,
  18192. timestampSerial,
  18193. signerCertificateVerified: true
  18194. });
  18195. }
  18196. data = signerInfo.signedAttrs.encodedValue;
  18197. }
  18198. const verifyResult = signerInfo.signatureAlgorithm.algorithmId === "1.2.840.113549.1.1.1"
  18199. ? await crypto.verifyWithPublicKey(data, signerInfo.signature, signerCert.subjectPublicKeyInfo, signerInfo.signatureAlgorithm, shaAlgorithm)
  18200. : await crypto.verifyWithPublicKey(data, signerInfo.signature, signerCert.subjectPublicKeyInfo, signerInfo.signatureAlgorithm);
  18201. if (extendedMode) {
  18202. return {
  18203. date: checkDate,
  18204. code: 14,
  18205. message: EMPTY_STRING,
  18206. signatureVerified: verifyResult,
  18207. signerCertificate: signerCert,
  18208. timestampSerial,
  18209. signerCertificateVerified: true,
  18210. certificatePath
  18211. };
  18212. }
  18213. else {
  18214. return verifyResult;
  18215. }
  18216. }
  18217. catch (e) {
  18218. if (e instanceof SignedDataVerifyError) {
  18219. throw e;
  18220. }
  18221. throw new SignedDataVerifyError({
  18222. date: checkDate,
  18223. code: 15,
  18224. message: `Error during verification: ${e instanceof Error ? e.message : e}`,
  18225. signatureVerified: null,
  18226. signerCertificate: signerCert,
  18227. timestampSerial,
  18228. signerCertificateVerified: true
  18229. });
  18230. }
  18231. }
  18232. async sign(privateKey, signerIndex, hashAlgorithm = "SHA-1", data = (EMPTY_BUFFER), crypto = getCrypto(true)) {
  18233. var _a;
  18234. if (!privateKey)
  18235. throw new Error("Need to provide a private key for signing");
  18236. const signerInfo = this.signerInfos[signerIndex];
  18237. if (!signerInfo) {
  18238. throw new RangeError("SignerInfo index is out of range");
  18239. }
  18240. if (!((_a = signerInfo.signedAttrs) === null || _a === void 0 ? void 0 : _a.attributes.length) && "hash" in privateKey.algorithm && "hash" in privateKey.algorithm && privateKey.algorithm.hash) {
  18241. hashAlgorithm = privateKey.algorithm.hash.name;
  18242. }
  18243. const hashAlgorithmOID = crypto.getOIDByAlgorithm({ name: hashAlgorithm }, true, "hashAlgorithm");
  18244. if ((this.digestAlgorithms.filter(algorithm => algorithm.algorithmId === hashAlgorithmOID)).length === 0) {
  18245. this.digestAlgorithms.push(new AlgorithmIdentifier({
  18246. algorithmId: hashAlgorithmOID,
  18247. algorithmParams: new asn1js.Null()
  18248. }));
  18249. }
  18250. signerInfo.digestAlgorithm = new AlgorithmIdentifier({
  18251. algorithmId: hashAlgorithmOID,
  18252. algorithmParams: new asn1js.Null()
  18253. });
  18254. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  18255. const parameters = signatureParams.parameters;
  18256. signerInfo.signatureAlgorithm = signatureParams.signatureAlgorithm;
  18257. if (signerInfo.signedAttrs) {
  18258. if (signerInfo.signedAttrs.encodedValue.byteLength !== 0)
  18259. data = signerInfo.signedAttrs.encodedValue;
  18260. else {
  18261. data = signerInfo.signedAttrs.toSchema().toBER();
  18262. const view = pvtsutils.BufferSourceConverter.toUint8Array(data);
  18263. view[0] = 0x31;
  18264. }
  18265. }
  18266. else {
  18267. const eContent = this.encapContentInfo.eContent;
  18268. if (eContent) {
  18269. if ((eContent.idBlock.tagClass === 1) &&
  18270. (eContent.idBlock.tagNumber === 4)) {
  18271. data = eContent.getValue();
  18272. }
  18273. else
  18274. data = eContent.valueBlock.valueBeforeDecodeView.slice().buffer;
  18275. }
  18276. else {
  18277. if (data.byteLength === 0)
  18278. throw new Error("Missed detached data input array");
  18279. }
  18280. }
  18281. const signature = await crypto.signWithPrivateKey(data, privateKey, parameters);
  18282. signerInfo.signature = new asn1js.OctetString({ valueHex: signature });
  18283. }
  18284. }
  18285. SignedData.CLASS_NAME = "SignedData";
  18286. SignedData.ID_DATA = id_ContentType_Data;
  18287. const VERSION$1 = "version";
  18288. const AUTH_SAFE = "authSafe";
  18289. const MAC_DATA = "macData";
  18290. const PARSED_VALUE = "parsedValue";
  18291. const CLERA_PROPS = [
  18292. VERSION$1,
  18293. AUTH_SAFE,
  18294. MAC_DATA
  18295. ];
  18296. class PFX extends PkiObject {
  18297. constructor(parameters = {}) {
  18298. super();
  18299. this.version = pvutils.getParametersValue(parameters, VERSION$1, PFX.defaultValues(VERSION$1));
  18300. this.authSafe = pvutils.getParametersValue(parameters, AUTH_SAFE, PFX.defaultValues(AUTH_SAFE));
  18301. if (MAC_DATA in parameters) {
  18302. this.macData = pvutils.getParametersValue(parameters, MAC_DATA, PFX.defaultValues(MAC_DATA));
  18303. }
  18304. if (PARSED_VALUE in parameters) {
  18305. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE, PFX.defaultValues(PARSED_VALUE));
  18306. }
  18307. if (parameters.schema) {
  18308. this.fromSchema(parameters.schema);
  18309. }
  18310. }
  18311. static defaultValues(memberName) {
  18312. switch (memberName) {
  18313. case VERSION$1:
  18314. return 3;
  18315. case AUTH_SAFE:
  18316. return (new ContentInfo());
  18317. case MAC_DATA:
  18318. return (new MacData());
  18319. case PARSED_VALUE:
  18320. return {};
  18321. default:
  18322. return super.defaultValues(memberName);
  18323. }
  18324. }
  18325. static compareWithDefault(memberName, memberValue) {
  18326. switch (memberName) {
  18327. case VERSION$1:
  18328. return (memberValue === PFX.defaultValues(memberName));
  18329. case AUTH_SAFE:
  18330. return ((ContentInfo.compareWithDefault("contentType", memberValue.contentType)) &&
  18331. (ContentInfo.compareWithDefault("content", memberValue.content)));
  18332. case MAC_DATA:
  18333. return ((MacData.compareWithDefault("mac", memberValue.mac)) &&
  18334. (MacData.compareWithDefault("macSalt", memberValue.macSalt)) &&
  18335. (MacData.compareWithDefault("iterations", memberValue.iterations)));
  18336. case PARSED_VALUE:
  18337. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  18338. default:
  18339. return super.defaultValues(memberName);
  18340. }
  18341. }
  18342. static schema(parameters = {}) {
  18343. const names = pvutils.getParametersValue(parameters, "names", {});
  18344. return (new asn1js.Sequence({
  18345. name: (names.blockName || EMPTY_STRING),
  18346. value: [
  18347. new asn1js.Integer({ name: (names.version || VERSION$1) }),
  18348. ContentInfo.schema(names.authSafe || {
  18349. names: {
  18350. blockName: AUTH_SAFE
  18351. }
  18352. }),
  18353. MacData.schema(names.macData || {
  18354. names: {
  18355. blockName: MAC_DATA,
  18356. optional: true
  18357. }
  18358. })
  18359. ]
  18360. }));
  18361. }
  18362. fromSchema(schema) {
  18363. pvutils.clearProps(schema, CLERA_PROPS);
  18364. const asn1 = asn1js.compareSchema(schema, schema, PFX.schema({
  18365. names: {
  18366. version: VERSION$1,
  18367. authSafe: {
  18368. names: {
  18369. blockName: AUTH_SAFE
  18370. }
  18371. },
  18372. macData: {
  18373. names: {
  18374. blockName: MAC_DATA
  18375. }
  18376. }
  18377. }
  18378. }));
  18379. AsnError.assertSchema(asn1, this.className);
  18380. this.version = asn1.result.version.valueBlock.valueDec;
  18381. this.authSafe = new ContentInfo({ schema: asn1.result.authSafe });
  18382. if (MAC_DATA in asn1.result)
  18383. this.macData = new MacData({ schema: asn1.result.macData });
  18384. }
  18385. toSchema() {
  18386. const outputArray = [
  18387. new asn1js.Integer({ value: this.version }),
  18388. this.authSafe.toSchema()
  18389. ];
  18390. if (this.macData) {
  18391. outputArray.push(this.macData.toSchema());
  18392. }
  18393. return (new asn1js.Sequence({
  18394. value: outputArray
  18395. }));
  18396. }
  18397. toJSON() {
  18398. const output = {
  18399. version: this.version,
  18400. authSafe: this.authSafe.toJSON()
  18401. };
  18402. if (this.macData) {
  18403. output.macData = this.macData.toJSON();
  18404. }
  18405. return output;
  18406. }
  18407. async makeInternalValues(parameters = {}, crypto = getCrypto(true)) {
  18408. ArgumentError.assert(parameters, "parameters", "object");
  18409. if (!this.parsedValue) {
  18410. throw new Error("Please call \"parseValues\" function first in order to make \"parsedValue\" data");
  18411. }
  18412. ParameterError.assertEmpty(this.parsedValue.integrityMode, "integrityMode", "parsedValue");
  18413. ParameterError.assertEmpty(this.parsedValue.authenticatedSafe, "authenticatedSafe", "parsedValue");
  18414. switch (this.parsedValue.integrityMode) {
  18415. case 0:
  18416. {
  18417. if (!("iterations" in parameters))
  18418. throw new ParameterError("iterations");
  18419. ParameterError.assertEmpty(parameters.pbkdf2HashAlgorithm, "pbkdf2HashAlgorithm");
  18420. ParameterError.assertEmpty(parameters.hmacHashAlgorithm, "hmacHashAlgorithm");
  18421. ParameterError.assertEmpty(parameters.password, "password");
  18422. const saltBuffer = new ArrayBuffer(64);
  18423. const saltView = new Uint8Array(saltBuffer);
  18424. crypto.getRandomValues(saltView);
  18425. const data = this.parsedValue.authenticatedSafe.toSchema().toBER(false);
  18426. this.authSafe = new ContentInfo({
  18427. contentType: ContentInfo.DATA,
  18428. content: new asn1js.OctetString({ valueHex: data })
  18429. });
  18430. const result = await crypto.stampDataWithPassword({
  18431. password: parameters.password,
  18432. hashAlgorithm: parameters.hmacHashAlgorithm,
  18433. salt: saltBuffer,
  18434. iterationCount: parameters.iterations,
  18435. contentToStamp: data
  18436. });
  18437. this.macData = new MacData({
  18438. mac: new DigestInfo({
  18439. digestAlgorithm: new AlgorithmIdentifier({
  18440. algorithmId: crypto.getOIDByAlgorithm({ name: parameters.hmacHashAlgorithm }, true, "hmacHashAlgorithm"),
  18441. }),
  18442. digest: new asn1js.OctetString({ valueHex: result })
  18443. }),
  18444. macSalt: new asn1js.OctetString({ valueHex: saltBuffer }),
  18445. iterations: parameters.iterations
  18446. });
  18447. }
  18448. break;
  18449. case 1:
  18450. {
  18451. if (!("signingCertificate" in parameters)) {
  18452. throw new ParameterError("signingCertificate");
  18453. }
  18454. ParameterError.assertEmpty(parameters.privateKey, "privateKey");
  18455. ParameterError.assertEmpty(parameters.hashAlgorithm, "hashAlgorithm");
  18456. const toBeSigned = this.parsedValue.authenticatedSafe.toSchema().toBER(false);
  18457. const cmsSigned = new SignedData({
  18458. version: 1,
  18459. encapContentInfo: new EncapsulatedContentInfo({
  18460. eContentType: "1.2.840.113549.1.7.1",
  18461. eContent: new asn1js.OctetString({ valueHex: toBeSigned })
  18462. }),
  18463. certificates: [parameters.signingCertificate]
  18464. });
  18465. const result = await crypto.digest({ name: parameters.hashAlgorithm }, new Uint8Array(toBeSigned));
  18466. const signedAttr = [];
  18467. signedAttr.push(new Attribute({
  18468. type: "1.2.840.113549.1.9.3",
  18469. values: [
  18470. new asn1js.ObjectIdentifier({ value: "1.2.840.113549.1.7.1" })
  18471. ]
  18472. }));
  18473. signedAttr.push(new Attribute({
  18474. type: "1.2.840.113549.1.9.5",
  18475. values: [
  18476. new asn1js.UTCTime({ valueDate: new Date() })
  18477. ]
  18478. }));
  18479. signedAttr.push(new Attribute({
  18480. type: "1.2.840.113549.1.9.4",
  18481. values: [
  18482. new asn1js.OctetString({ valueHex: result })
  18483. ]
  18484. }));
  18485. cmsSigned.signerInfos.push(new SignerInfo({
  18486. version: 1,
  18487. sid: new IssuerAndSerialNumber({
  18488. issuer: parameters.signingCertificate.issuer,
  18489. serialNumber: parameters.signingCertificate.serialNumber
  18490. }),
  18491. signedAttrs: new SignedAndUnsignedAttributes({
  18492. type: 0,
  18493. attributes: signedAttr
  18494. })
  18495. }));
  18496. await cmsSigned.sign(parameters.privateKey, 0, parameters.hashAlgorithm, undefined, crypto);
  18497. this.authSafe = new ContentInfo({
  18498. contentType: "1.2.840.113549.1.7.2",
  18499. content: cmsSigned.toSchema(true)
  18500. });
  18501. }
  18502. break;
  18503. default:
  18504. throw new Error(`Parameter "integrityMode" has unknown value: ${this.parsedValue.integrityMode}`);
  18505. }
  18506. }
  18507. async parseInternalValues(parameters, crypto = getCrypto(true)) {
  18508. ArgumentError.assert(parameters, "parameters", "object");
  18509. if (parameters.checkIntegrity === undefined) {
  18510. parameters.checkIntegrity = true;
  18511. }
  18512. this.parsedValue = {};
  18513. switch (this.authSafe.contentType) {
  18514. case ContentInfo.DATA:
  18515. {
  18516. ParameterError.assertEmpty(parameters.password, "password");
  18517. this.parsedValue.integrityMode = 0;
  18518. ArgumentError.assert(this.authSafe.content, "authSafe.content", asn1js.OctetString);
  18519. const authSafeContent = this.authSafe.content.getValue();
  18520. this.parsedValue.authenticatedSafe = AuthenticatedSafe.fromBER(authSafeContent);
  18521. if (parameters.checkIntegrity) {
  18522. if (!this.macData) {
  18523. throw new Error("Absent \"macData\" value, can not check PKCS#12 data integrity");
  18524. }
  18525. const hashAlgorithm = crypto.getAlgorithmByOID(this.macData.mac.digestAlgorithm.algorithmId, true, "digestAlgorithm");
  18526. const result = await crypto.verifyDataStampedWithPassword({
  18527. password: parameters.password,
  18528. hashAlgorithm: hashAlgorithm.name,
  18529. salt: BufferSourceConverter.toArrayBuffer(this.macData.macSalt.valueBlock.valueHexView),
  18530. iterationCount: this.macData.iterations || 1,
  18531. contentToVerify: authSafeContent,
  18532. signatureToVerify: BufferSourceConverter.toArrayBuffer(this.macData.mac.digest.valueBlock.valueHexView),
  18533. });
  18534. if (!result) {
  18535. throw new Error("Integrity for the PKCS#12 data is broken!");
  18536. }
  18537. }
  18538. }
  18539. break;
  18540. case ContentInfo.SIGNED_DATA:
  18541. {
  18542. this.parsedValue.integrityMode = 1;
  18543. const cmsSigned = new SignedData({ schema: this.authSafe.content });
  18544. const eContent = cmsSigned.encapContentInfo.eContent;
  18545. ParameterError.assert(eContent, "eContent", "cmsSigned.encapContentInfo");
  18546. ArgumentError.assert(eContent, "eContent", asn1js.OctetString);
  18547. const data = eContent.getValue();
  18548. this.parsedValue.authenticatedSafe = AuthenticatedSafe.fromBER(data);
  18549. const ok = await cmsSigned.verify({ signer: 0, checkChain: false }, crypto);
  18550. if (!ok) {
  18551. throw new Error("Integrity for the PKCS#12 data is broken!");
  18552. }
  18553. }
  18554. break;
  18555. default:
  18556. throw new Error(`Incorrect value for "this.authSafe.contentType": ${this.authSafe.contentType}`);
  18557. }
  18558. }
  18559. }
  18560. PFX.CLASS_NAME = "PFX";
  18561. const STATUS$1 = "status";
  18562. const STATUS_STRINGS = "statusStrings";
  18563. const FAIL_INFO = "failInfo";
  18564. const CLEAR_PROPS$2 = [
  18565. STATUS$1,
  18566. STATUS_STRINGS,
  18567. FAIL_INFO
  18568. ];
  18569. var PKIStatus;
  18570. (function (PKIStatus) {
  18571. PKIStatus[PKIStatus["granted"] = 0] = "granted";
  18572. PKIStatus[PKIStatus["grantedWithMods"] = 1] = "grantedWithMods";
  18573. PKIStatus[PKIStatus["rejection"] = 2] = "rejection";
  18574. PKIStatus[PKIStatus["waiting"] = 3] = "waiting";
  18575. PKIStatus[PKIStatus["revocationWarning"] = 4] = "revocationWarning";
  18576. PKIStatus[PKIStatus["revocationNotification"] = 5] = "revocationNotification";
  18577. })(PKIStatus || (PKIStatus = {}));
  18578. class PKIStatusInfo extends PkiObject {
  18579. constructor(parameters = {}) {
  18580. super();
  18581. this.status = pvutils.getParametersValue(parameters, STATUS$1, PKIStatusInfo.defaultValues(STATUS$1));
  18582. if (STATUS_STRINGS in parameters) {
  18583. this.statusStrings = pvutils.getParametersValue(parameters, STATUS_STRINGS, PKIStatusInfo.defaultValues(STATUS_STRINGS));
  18584. }
  18585. if (FAIL_INFO in parameters) {
  18586. this.failInfo = pvutils.getParametersValue(parameters, FAIL_INFO, PKIStatusInfo.defaultValues(FAIL_INFO));
  18587. }
  18588. if (parameters.schema) {
  18589. this.fromSchema(parameters.schema);
  18590. }
  18591. }
  18592. static defaultValues(memberName) {
  18593. switch (memberName) {
  18594. case STATUS$1:
  18595. return 2;
  18596. case STATUS_STRINGS:
  18597. return [];
  18598. case FAIL_INFO:
  18599. return new asn1js.BitString();
  18600. default:
  18601. return super.defaultValues(memberName);
  18602. }
  18603. }
  18604. static compareWithDefault(memberName, memberValue) {
  18605. switch (memberName) {
  18606. case STATUS$1:
  18607. return (memberValue === PKIStatusInfo.defaultValues(memberName));
  18608. case STATUS_STRINGS:
  18609. return (memberValue.length === 0);
  18610. case FAIL_INFO:
  18611. return (memberValue.isEqual(PKIStatusInfo.defaultValues(memberName)));
  18612. default:
  18613. return super.defaultValues(memberName);
  18614. }
  18615. }
  18616. static schema(parameters = {}) {
  18617. const names = pvutils.getParametersValue(parameters, "names", {});
  18618. return (new asn1js.Sequence({
  18619. name: (names.blockName || EMPTY_STRING),
  18620. value: [
  18621. new asn1js.Integer({ name: (names.status || EMPTY_STRING) }),
  18622. new asn1js.Sequence({
  18623. optional: true,
  18624. value: [
  18625. new asn1js.Repeated({
  18626. name: (names.statusStrings || EMPTY_STRING),
  18627. value: new asn1js.Utf8String()
  18628. })
  18629. ]
  18630. }),
  18631. new asn1js.BitString({
  18632. name: (names.failInfo || EMPTY_STRING),
  18633. optional: true
  18634. })
  18635. ]
  18636. }));
  18637. }
  18638. fromSchema(schema) {
  18639. pvutils.clearProps(schema, CLEAR_PROPS$2);
  18640. const asn1 = asn1js.compareSchema(schema, schema, PKIStatusInfo.schema({
  18641. names: {
  18642. status: STATUS$1,
  18643. statusStrings: STATUS_STRINGS,
  18644. failInfo: FAIL_INFO
  18645. }
  18646. }));
  18647. AsnError.assertSchema(asn1, this.className);
  18648. const _status = asn1.result.status;
  18649. if ((_status.valueBlock.isHexOnly === true) ||
  18650. (_status.valueBlock.valueDec < 0) ||
  18651. (_status.valueBlock.valueDec > 5))
  18652. throw new Error("PKIStatusInfo \"status\" has invalid value");
  18653. this.status = _status.valueBlock.valueDec;
  18654. if (STATUS_STRINGS in asn1.result)
  18655. this.statusStrings = asn1.result.statusStrings;
  18656. if (FAIL_INFO in asn1.result)
  18657. this.failInfo = asn1.result.failInfo;
  18658. }
  18659. toSchema() {
  18660. const outputArray = [];
  18661. outputArray.push(new asn1js.Integer({ value: this.status }));
  18662. if (this.statusStrings) {
  18663. outputArray.push(new asn1js.Sequence({
  18664. optional: true,
  18665. value: this.statusStrings
  18666. }));
  18667. }
  18668. if (this.failInfo) {
  18669. outputArray.push(this.failInfo);
  18670. }
  18671. return (new asn1js.Sequence({
  18672. value: outputArray
  18673. }));
  18674. }
  18675. toJSON() {
  18676. const res = {
  18677. status: this.status
  18678. };
  18679. if (this.statusStrings) {
  18680. res.statusStrings = Array.from(this.statusStrings, o => o.toJSON());
  18681. }
  18682. if (this.failInfo) {
  18683. res.failInfo = this.failInfo.toJSON();
  18684. }
  18685. return res;
  18686. }
  18687. }
  18688. PKIStatusInfo.CLASS_NAME = "PKIStatusInfo";
  18689. const VERSION = "version";
  18690. const MESSAGE_IMPRINT = "messageImprint";
  18691. const REQ_POLICY = "reqPolicy";
  18692. const NONCE = "nonce";
  18693. const CERT_REQ = "certReq";
  18694. const EXTENSIONS = "extensions";
  18695. const TIME_STAMP_REQ = "TimeStampReq";
  18696. const TIME_STAMP_REQ_VERSION = `${TIME_STAMP_REQ}.${VERSION}`;
  18697. const TIME_STAMP_REQ_MESSAGE_IMPRINT = `${TIME_STAMP_REQ}.${MESSAGE_IMPRINT}`;
  18698. const TIME_STAMP_REQ_POLICY = `${TIME_STAMP_REQ}.${REQ_POLICY}`;
  18699. const TIME_STAMP_REQ_NONCE = `${TIME_STAMP_REQ}.${NONCE}`;
  18700. const TIME_STAMP_REQ_CERT_REQ = `${TIME_STAMP_REQ}.${CERT_REQ}`;
  18701. const TIME_STAMP_REQ_EXTENSIONS = `${TIME_STAMP_REQ}.${EXTENSIONS}`;
  18702. const CLEAR_PROPS$1 = [
  18703. TIME_STAMP_REQ_VERSION,
  18704. TIME_STAMP_REQ_MESSAGE_IMPRINT,
  18705. TIME_STAMP_REQ_POLICY,
  18706. TIME_STAMP_REQ_NONCE,
  18707. TIME_STAMP_REQ_CERT_REQ,
  18708. TIME_STAMP_REQ_EXTENSIONS,
  18709. ];
  18710. class TimeStampReq extends PkiObject {
  18711. constructor(parameters = {}) {
  18712. super();
  18713. this.version = pvutils.getParametersValue(parameters, VERSION, TimeStampReq.defaultValues(VERSION));
  18714. this.messageImprint = pvutils.getParametersValue(parameters, MESSAGE_IMPRINT, TimeStampReq.defaultValues(MESSAGE_IMPRINT));
  18715. if (REQ_POLICY in parameters) {
  18716. this.reqPolicy = pvutils.getParametersValue(parameters, REQ_POLICY, TimeStampReq.defaultValues(REQ_POLICY));
  18717. }
  18718. if (NONCE in parameters) {
  18719. this.nonce = pvutils.getParametersValue(parameters, NONCE, TimeStampReq.defaultValues(NONCE));
  18720. }
  18721. if (CERT_REQ in parameters) {
  18722. this.certReq = pvutils.getParametersValue(parameters, CERT_REQ, TimeStampReq.defaultValues(CERT_REQ));
  18723. }
  18724. if (EXTENSIONS in parameters) {
  18725. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS, TimeStampReq.defaultValues(EXTENSIONS));
  18726. }
  18727. if (parameters.schema) {
  18728. this.fromSchema(parameters.schema);
  18729. }
  18730. }
  18731. static defaultValues(memberName) {
  18732. switch (memberName) {
  18733. case VERSION:
  18734. return 0;
  18735. case MESSAGE_IMPRINT:
  18736. return new MessageImprint();
  18737. case REQ_POLICY:
  18738. return EMPTY_STRING;
  18739. case NONCE:
  18740. return new asn1js.Integer();
  18741. case CERT_REQ:
  18742. return false;
  18743. case EXTENSIONS:
  18744. return [];
  18745. default:
  18746. return super.defaultValues(memberName);
  18747. }
  18748. }
  18749. static compareWithDefault(memberName, memberValue) {
  18750. switch (memberName) {
  18751. case VERSION:
  18752. case REQ_POLICY:
  18753. case CERT_REQ:
  18754. return (memberValue === TimeStampReq.defaultValues(memberName));
  18755. case MESSAGE_IMPRINT:
  18756. return ((MessageImprint.compareWithDefault("hashAlgorithm", memberValue.hashAlgorithm)) &&
  18757. (MessageImprint.compareWithDefault("hashedMessage", memberValue.hashedMessage)));
  18758. case NONCE:
  18759. return (memberValue.isEqual(TimeStampReq.defaultValues(memberName)));
  18760. case EXTENSIONS:
  18761. return (memberValue.length === 0);
  18762. default:
  18763. return super.defaultValues(memberName);
  18764. }
  18765. }
  18766. static schema(parameters = {}) {
  18767. const names = pvutils.getParametersValue(parameters, "names", {});
  18768. return (new asn1js.Sequence({
  18769. name: (names.blockName || TIME_STAMP_REQ),
  18770. value: [
  18771. new asn1js.Integer({ name: (names.version || TIME_STAMP_REQ_VERSION) }),
  18772. MessageImprint.schema(names.messageImprint || {
  18773. names: {
  18774. blockName: TIME_STAMP_REQ_MESSAGE_IMPRINT
  18775. }
  18776. }),
  18777. new asn1js.ObjectIdentifier({
  18778. name: (names.reqPolicy || TIME_STAMP_REQ_POLICY),
  18779. optional: true
  18780. }),
  18781. new asn1js.Integer({
  18782. name: (names.nonce || TIME_STAMP_REQ_NONCE),
  18783. optional: true
  18784. }),
  18785. new asn1js.Boolean({
  18786. name: (names.certReq || TIME_STAMP_REQ_CERT_REQ),
  18787. optional: true
  18788. }),
  18789. new asn1js.Constructed({
  18790. optional: true,
  18791. idBlock: {
  18792. tagClass: 3,
  18793. tagNumber: 0
  18794. },
  18795. value: [new asn1js.Repeated({
  18796. name: (names.extensions || TIME_STAMP_REQ_EXTENSIONS),
  18797. value: Extension.schema()
  18798. })]
  18799. })
  18800. ]
  18801. }));
  18802. }
  18803. fromSchema(schema) {
  18804. pvutils.clearProps(schema, CLEAR_PROPS$1);
  18805. const asn1 = asn1js.compareSchema(schema, schema, TimeStampReq.schema());
  18806. AsnError.assertSchema(asn1, this.className);
  18807. this.version = asn1.result[TIME_STAMP_REQ_VERSION].valueBlock.valueDec;
  18808. this.messageImprint = new MessageImprint({ schema: asn1.result[TIME_STAMP_REQ_MESSAGE_IMPRINT] });
  18809. if (TIME_STAMP_REQ_POLICY in asn1.result)
  18810. this.reqPolicy = asn1.result[TIME_STAMP_REQ_POLICY].valueBlock.toString();
  18811. if (TIME_STAMP_REQ_NONCE in asn1.result)
  18812. this.nonce = asn1.result[TIME_STAMP_REQ_NONCE];
  18813. if (TIME_STAMP_REQ_CERT_REQ in asn1.result)
  18814. this.certReq = asn1.result[TIME_STAMP_REQ_CERT_REQ].valueBlock.value;
  18815. if (TIME_STAMP_REQ_EXTENSIONS in asn1.result)
  18816. this.extensions = Array.from(asn1.result[TIME_STAMP_REQ_EXTENSIONS], element => new Extension({ schema: element }));
  18817. }
  18818. toSchema() {
  18819. const outputArray = [];
  18820. outputArray.push(new asn1js.Integer({ value: this.version }));
  18821. outputArray.push(this.messageImprint.toSchema());
  18822. if (this.reqPolicy)
  18823. outputArray.push(new asn1js.ObjectIdentifier({ value: this.reqPolicy }));
  18824. if (this.nonce)
  18825. outputArray.push(this.nonce);
  18826. if ((CERT_REQ in this) && (TimeStampReq.compareWithDefault(CERT_REQ, this.certReq) === false))
  18827. outputArray.push(new asn1js.Boolean({ value: this.certReq }));
  18828. if (this.extensions) {
  18829. outputArray.push(new asn1js.Constructed({
  18830. idBlock: {
  18831. tagClass: 3,
  18832. tagNumber: 0
  18833. },
  18834. value: Array.from(this.extensions, o => o.toSchema())
  18835. }));
  18836. }
  18837. return (new asn1js.Sequence({
  18838. value: outputArray
  18839. }));
  18840. }
  18841. toJSON() {
  18842. const res = {
  18843. version: this.version,
  18844. messageImprint: this.messageImprint.toJSON()
  18845. };
  18846. if (this.reqPolicy !== undefined)
  18847. res.reqPolicy = this.reqPolicy;
  18848. if (this.nonce !== undefined)
  18849. res.nonce = this.nonce.toJSON();
  18850. if ((this.certReq !== undefined) && (TimeStampReq.compareWithDefault(CERT_REQ, this.certReq) === false))
  18851. res.certReq = this.certReq;
  18852. if (this.extensions) {
  18853. res.extensions = Array.from(this.extensions, o => o.toJSON());
  18854. }
  18855. return res;
  18856. }
  18857. }
  18858. TimeStampReq.CLASS_NAME = "TimeStampReq";
  18859. const STATUS = "status";
  18860. const TIME_STAMP_TOKEN = "timeStampToken";
  18861. const TIME_STAMP_RESP = "TimeStampResp";
  18862. const TIME_STAMP_RESP_STATUS = `${TIME_STAMP_RESP}.${STATUS}`;
  18863. const TIME_STAMP_RESP_TOKEN = `${TIME_STAMP_RESP}.${TIME_STAMP_TOKEN}`;
  18864. const CLEAR_PROPS = [
  18865. TIME_STAMP_RESP_STATUS,
  18866. TIME_STAMP_RESP_TOKEN
  18867. ];
  18868. class TimeStampResp extends PkiObject {
  18869. constructor(parameters = {}) {
  18870. super();
  18871. this.status = pvutils.getParametersValue(parameters, STATUS, TimeStampResp.defaultValues(STATUS));
  18872. if (TIME_STAMP_TOKEN in parameters) {
  18873. this.timeStampToken = pvutils.getParametersValue(parameters, TIME_STAMP_TOKEN, TimeStampResp.defaultValues(TIME_STAMP_TOKEN));
  18874. }
  18875. if (parameters.schema) {
  18876. this.fromSchema(parameters.schema);
  18877. }
  18878. }
  18879. static defaultValues(memberName) {
  18880. switch (memberName) {
  18881. case STATUS:
  18882. return new PKIStatusInfo();
  18883. case TIME_STAMP_TOKEN:
  18884. return new ContentInfo();
  18885. default:
  18886. return super.defaultValues(memberName);
  18887. }
  18888. }
  18889. static compareWithDefault(memberName, memberValue) {
  18890. switch (memberName) {
  18891. case STATUS:
  18892. return ((PKIStatusInfo.compareWithDefault(STATUS, memberValue.status)) &&
  18893. (("statusStrings" in memberValue) === false) &&
  18894. (("failInfo" in memberValue) === false));
  18895. case TIME_STAMP_TOKEN:
  18896. return ((memberValue.contentType === EMPTY_STRING) &&
  18897. (memberValue.content instanceof asn1js.Any));
  18898. default:
  18899. return super.defaultValues(memberName);
  18900. }
  18901. }
  18902. static schema(parameters = {}) {
  18903. const names = pvutils.getParametersValue(parameters, "names", {});
  18904. return (new asn1js.Sequence({
  18905. name: (names.blockName || TIME_STAMP_RESP),
  18906. value: [
  18907. PKIStatusInfo.schema(names.status || {
  18908. names: {
  18909. blockName: TIME_STAMP_RESP_STATUS
  18910. }
  18911. }),
  18912. ContentInfo.schema(names.timeStampToken || {
  18913. names: {
  18914. blockName: TIME_STAMP_RESP_TOKEN,
  18915. optional: true
  18916. }
  18917. })
  18918. ]
  18919. }));
  18920. }
  18921. fromSchema(schema) {
  18922. pvutils.clearProps(schema, CLEAR_PROPS);
  18923. const asn1 = asn1js.compareSchema(schema, schema, TimeStampResp.schema());
  18924. AsnError.assertSchema(asn1, this.className);
  18925. this.status = new PKIStatusInfo({ schema: asn1.result[TIME_STAMP_RESP_STATUS] });
  18926. if (TIME_STAMP_RESP_TOKEN in asn1.result)
  18927. this.timeStampToken = new ContentInfo({ schema: asn1.result[TIME_STAMP_RESP_TOKEN] });
  18928. }
  18929. toSchema() {
  18930. const outputArray = [];
  18931. outputArray.push(this.status.toSchema());
  18932. if (this.timeStampToken) {
  18933. outputArray.push(this.timeStampToken.toSchema());
  18934. }
  18935. return (new asn1js.Sequence({
  18936. value: outputArray
  18937. }));
  18938. }
  18939. toJSON() {
  18940. const res = {
  18941. status: this.status.toJSON()
  18942. };
  18943. if (this.timeStampToken) {
  18944. res.timeStampToken = this.timeStampToken.toJSON();
  18945. }
  18946. return res;
  18947. }
  18948. async sign(privateKey, hashAlgorithm, crypto = getCrypto(true)) {
  18949. this.assertContentType();
  18950. const signed = new SignedData({ schema: this.timeStampToken.content });
  18951. return signed.sign(privateKey, 0, hashAlgorithm, undefined, crypto);
  18952. }
  18953. async verify(verificationParameters = { signer: 0, trustedCerts: [], data: EMPTY_BUFFER }, crypto = getCrypto(true)) {
  18954. this.assertContentType();
  18955. const signed = new SignedData({ schema: this.timeStampToken.content });
  18956. return signed.verify(verificationParameters, crypto);
  18957. }
  18958. assertContentType() {
  18959. if (!this.timeStampToken) {
  18960. throw new Error("timeStampToken is absent in TSP response");
  18961. }
  18962. if (this.timeStampToken.contentType !== id_ContentType_SignedData) {
  18963. throw new Error(`Wrong format of timeStampToken: ${this.timeStampToken.contentType}`);
  18964. }
  18965. }
  18966. }
  18967. TimeStampResp.CLASS_NAME = "TimeStampResp";
  18968. function initCryptoEngine() {
  18969. if (typeof globalThis !== "undefined" && "crypto" in globalThis) {
  18970. let engineName = "webcrypto";
  18971. if ("webkitSubtle" in globalThis.crypto) {
  18972. engineName = "safari";
  18973. }
  18974. setEngine(engineName, new CryptoEngine({ name: engineName, crypto: globalThis.crypto }));
  18975. }
  18976. else if (typeof crypto !== "undefined" && "webcrypto" in crypto) {
  18977. const name = "NodeJS ^15";
  18978. const nodeCrypto = crypto.webcrypto;
  18979. setEngine(name, new CryptoEngine({ name, crypto: nodeCrypto }));
  18980. }
  18981. }
  18982. initCryptoEngine();
  18983. export { AbstractCryptoEngine, AccessDescription, Accuracy, AlgorithmIdentifier, AltName, ArgumentError, AsnError, AttCertValidityPeriod, Attribute, AttributeCertificateInfoV1, AttributeCertificateInfoV2, AttributeCertificateV1, AttributeCertificateV2, AttributeTypeAndValue, AuthenticatedSafe, AuthorityKeyIdentifier, BasicConstraints, BasicOCSPResponse, CAVersion, CRLBag, CRLDistributionPoints, CertBag, CertID, Certificate, CertificateChainValidationEngine, CertificatePolicies, CertificateRevocationList, CertificateSet, CertificateTemplate, CertificationRequest, ChainValidationCode, ChainValidationError, ContentInfo, CryptoEngine, DigestInfo, DistributionPoint, ECCCMSSharedInfo, ECNamedCurves, ECPrivateKey, ECPublicKey, EncapsulatedContentInfo, EncryptedContentInfo, EncryptedData, EnvelopedData, ExtKeyUsage, Extension, ExtensionValueFactory, Extensions, GeneralName, GeneralNames, GeneralSubtree, HASHED_MESSAGE, HASH_ALGORITHM, Holder, InfoAccess, IssuerAndSerialNumber, IssuerSerial, IssuingDistributionPoint, KEKIdentifier, KEKRecipientInfo, KeyAgreeRecipientIdentifier, KeyAgreeRecipientInfo, KeyBag, KeyTransRecipientInfo, MICROS, MILLIS, MacData, MessageImprint, NameConstraints, OCSPRequest, OCSPResponse, ObjectDigestInfo, OriginatorIdentifierOrKey, OriginatorInfo, OriginatorPublicKey, OtherCertificateFormat, OtherKeyAttribute, OtherPrimeInfo, OtherRecipientInfo, OtherRevocationInfoFormat, PBES2Params, PBKDF2Params, PFX, PKCS8ShroudedKeyBag, PKIStatus, PKIStatusInfo, POLICY_IDENTIFIER, POLICY_QUALIFIERS, ParameterError, PasswordRecipientinfo, PkiObject, PolicyConstraints, PolicyInformation, PolicyMapping, PolicyMappings, PolicyQualifierInfo, PrivateKeyInfo, PrivateKeyUsagePeriod, PublicKeyInfo, QCStatement, QCStatements, RDN, RSAESOAEPParams, RSAPrivateKey, RSAPublicKey, RSASSAPSSParams, RecipientEncryptedKey, RecipientEncryptedKeys, RecipientIdentifier, RecipientInfo, RecipientKeyIdentifier, RelativeDistinguishedNames, Request, ResponseBytes, ResponseData, RevocationInfoChoices, RevokedCertificate, SECONDS, SafeBag, SafeBagValueFactory, SafeContents, SecretBag, Signature, SignedAndUnsignedAttributes, SignedCertificateTimestamp, SignedCertificateTimestampList, SignedData, SignedDataVerifyError, SignerInfo, SingleResponse, SubjectDirectoryAttributes, TBSRequest, TSTInfo, TYPE$4 as TYPE, TYPE_AND_VALUES, Time, TimeStampReq, TimeStampResp, TimeType, V2Form, VALUE$5 as VALUE, VALUE_BEFORE_DECODE, checkCA, createCMSECDSASignature, createECDSASignatureFromCMS, engine, getAlgorithmByOID, getAlgorithmParameters, getCrypto, getEngine, getHashAlgorithm, getOIDByAlgorithm, getRandomValues, id_AnyPolicy, id_AuthorityInfoAccess, id_AuthorityKeyIdentifier, id_BaseCRLNumber, id_BasicConstraints, id_CRLBag_X509CRL, id_CRLDistributionPoints, id_CRLNumber, id_CRLReason, id_CertBag_AttributeCertificate, id_CertBag_SDSICertificate, id_CertBag_X509Certificate, id_CertificateIssuer, id_CertificatePolicies, id_ContentType_Data, id_ContentType_EncryptedData, id_ContentType_EnvelopedData, id_ContentType_SignedData, id_ExtKeyUsage, id_FreshestCRL, id_InhibitAnyPolicy, id_InvalidityDate, id_IssuerAltName, id_IssuingDistributionPoint, id_KeyUsage, id_MicrosoftAppPolicies, id_MicrosoftCaVersion, id_MicrosoftCertTemplateV1, id_MicrosoftCertTemplateV2, id_MicrosoftPrevCaCertHash, id_NameConstraints, id_PKIX_OCSP_Basic, id_PolicyConstraints, id_PolicyMappings, id_PrivateKeyUsagePeriod, id_QCStatements, id_SignedCertificateTimestampList, id_SubjectAltName, id_SubjectDirectoryAttributes, id_SubjectInfoAccess, id_SubjectKeyIdentifier, id_ad, id_ad_caIssuers, id_ad_ocsp, id_eContentType_TSTInfo, id_pkix, id_sha1, id_sha256, id_sha384, id_sha512, kdf, setEngine, stringPrep, verifySCTsForCertificate };