index.js 783 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152515351545155515651575158515951605161516251635164516551665167516851695170517151725173517451755176517751785179518051815182518351845185518651875188518951905191519251935194519551965197519851995200520152025203520452055206520752085209521052115212521352145215521652175218521952205221522252235224522552265227522852295230523152325233523452355236523752385239524052415242524352445245524652475248524952505251525252535254525552565257525852595260526152625263526452655266526752685269527052715272527352745275527652775278527952805281528252835284528552865287528852895290529152925293529452955296529752985299530053015302530353045305530653075308530953105311531253135314531553165317531853195320532153225323532453255326532753285329533053315332533353345335533653375338533953405341534253435344534553465347534853495350535153525353535453555356535753585359536053615362536353645365536653675368536953705371537253735374537553765377537853795380538153825383538453855386538753885389539053915392539353945395539653975398539954005401540254035404540554065407540854095410541154125413541454155416541754185419542054215422542354245425542654275428542954305431543254335434543554365437543854395440544154425443544454455446544754485449545054515452545354545455545654575458545954605461546254635464546554665467546854695470547154725473547454755476547754785479548054815482548354845485548654875488548954905491549254935494549554965497549854995500550155025503550455055506550755085509551055115512551355145515551655175518551955205521552255235524552555265527552855295530553155325533553455355536553755385539554055415542554355445545554655475548554955505551555255535554555555565557555855595560556155625563556455655566556755685569557055715572557355745575557655775578557955805581558255835584558555865587558855895590559155925593559455955596559755985599560056015602560356045605560656075608560956105611561256135614561556165617561856195620562156225623562456255626562756285629563056315632563356345635563656375638563956405641564256435644564556465647564856495650565156525653565456555656565756585659566056615662566356645665566656675668566956705671567256735674567556765677567856795680568156825683568456855686568756885689569056915692569356945695569656975698569957005701570257035704570557065707570857095710571157125713571457155716571757185719572057215722572357245725572657275728572957305731573257335734573557365737573857395740574157425743574457455746574757485749575057515752575357545755575657575758575957605761576257635764576557665767576857695770577157725773577457755776577757785779578057815782578357845785578657875788578957905791579257935794579557965797579857995800580158025803580458055806580758085809581058115812581358145815581658175818581958205821582258235824582558265827582858295830583158325833583458355836583758385839584058415842584358445845584658475848584958505851585258535854585558565857585858595860586158625863586458655866586758685869587058715872587358745875587658775878587958805881588258835884588558865887588858895890589158925893589458955896589758985899590059015902590359045905590659075908590959105911591259135914591559165917591859195920592159225923592459255926592759285929593059315932593359345935593659375938593959405941594259435944594559465947594859495950595159525953595459555956595759585959596059615962596359645965596659675968596959705971597259735974597559765977597859795980598159825983598459855986598759885989599059915992599359945995599659975998599960006001600260036004600560066007600860096010601160126013601460156016601760186019602060216022602360246025602660276028602960306031603260336034603560366037603860396040604160426043604460456046604760486049605060516052605360546055605660576058605960606061606260636064606560666067606860696070607160726073607460756076607760786079608060816082608360846085608660876088608960906091609260936094609560966097609860996100610161026103610461056106610761086109611061116112611361146115611661176118611961206121612261236124612561266127612861296130613161326133613461356136613761386139614061416142614361446145614661476148614961506151615261536154615561566157615861596160616161626163616461656166616761686169617061716172617361746175617661776178617961806181618261836184618561866187618861896190619161926193619461956196619761986199620062016202620362046205620662076208620962106211621262136214621562166217621862196220622162226223622462256226622762286229623062316232623362346235623662376238623962406241624262436244624562466247624862496250625162526253625462556256625762586259626062616262626362646265626662676268626962706271627262736274627562766277627862796280628162826283628462856286628762886289629062916292629362946295629662976298629963006301630263036304630563066307630863096310631163126313631463156316631763186319632063216322632363246325632663276328632963306331633263336334633563366337633863396340634163426343634463456346634763486349635063516352635363546355635663576358635963606361636263636364636563666367636863696370637163726373637463756376637763786379638063816382638363846385638663876388638963906391639263936394639563966397639863996400640164026403640464056406640764086409641064116412641364146415641664176418641964206421642264236424642564266427642864296430643164326433643464356436643764386439644064416442644364446445644664476448644964506451645264536454645564566457645864596460646164626463646464656466646764686469647064716472647364746475647664776478647964806481648264836484648564866487648864896490649164926493649464956496649764986499650065016502650365046505650665076508650965106511651265136514651565166517651865196520652165226523652465256526652765286529653065316532653365346535653665376538653965406541654265436544654565466547654865496550655165526553655465556556655765586559656065616562656365646565656665676568656965706571657265736574657565766577657865796580658165826583658465856586658765886589659065916592659365946595659665976598659966006601660266036604660566066607660866096610661166126613661466156616661766186619662066216622662366246625662666276628662966306631663266336634663566366637663866396640664166426643664466456646664766486649665066516652665366546655665666576658665966606661666266636664666566666667666866696670667166726673667466756676667766786679668066816682668366846685668666876688668966906691669266936694669566966697669866996700670167026703670467056706670767086709671067116712671367146715671667176718671967206721672267236724672567266727672867296730673167326733673467356736673767386739674067416742674367446745674667476748674967506751675267536754675567566757675867596760676167626763676467656766676767686769677067716772677367746775677667776778677967806781678267836784678567866787678867896790679167926793679467956796679767986799680068016802680368046805680668076808680968106811681268136814681568166817681868196820682168226823682468256826682768286829683068316832683368346835683668376838683968406841684268436844684568466847684868496850685168526853685468556856685768586859686068616862686368646865686668676868686968706871687268736874687568766877687868796880688168826883688468856886688768886889689068916892689368946895689668976898689969006901690269036904690569066907690869096910691169126913691469156916691769186919692069216922692369246925692669276928692969306931693269336934693569366937693869396940694169426943694469456946694769486949695069516952695369546955695669576958695969606961696269636964696569666967696869696970697169726973697469756976697769786979698069816982698369846985698669876988698969906991699269936994699569966997699869997000700170027003700470057006700770087009701070117012701370147015701670177018701970207021702270237024702570267027702870297030703170327033703470357036703770387039704070417042704370447045704670477048704970507051705270537054705570567057705870597060706170627063706470657066706770687069707070717072707370747075707670777078707970807081708270837084708570867087708870897090709170927093709470957096709770987099710071017102710371047105710671077108710971107111711271137114711571167117711871197120712171227123712471257126712771287129713071317132713371347135713671377138713971407141714271437144714571467147714871497150715171527153715471557156715771587159716071617162716371647165716671677168716971707171717271737174717571767177717871797180718171827183718471857186718771887189719071917192719371947195719671977198719972007201720272037204720572067207720872097210721172127213721472157216721772187219722072217222722372247225722672277228722972307231723272337234723572367237723872397240724172427243724472457246724772487249725072517252725372547255725672577258725972607261726272637264726572667267726872697270727172727273727472757276727772787279728072817282728372847285728672877288728972907291729272937294729572967297729872997300730173027303730473057306730773087309731073117312731373147315731673177318731973207321732273237324732573267327732873297330733173327333733473357336733773387339734073417342734373447345734673477348734973507351735273537354735573567357735873597360736173627363736473657366736773687369737073717372737373747375737673777378737973807381738273837384738573867387738873897390739173927393739473957396739773987399740074017402740374047405740674077408740974107411741274137414741574167417741874197420742174227423742474257426742774287429743074317432743374347435743674377438743974407441744274437444744574467447744874497450745174527453745474557456745774587459746074617462746374647465746674677468746974707471747274737474747574767477747874797480748174827483748474857486748774887489749074917492749374947495749674977498749975007501750275037504750575067507750875097510751175127513751475157516751775187519752075217522752375247525752675277528752975307531753275337534753575367537753875397540754175427543754475457546754775487549755075517552755375547555755675577558755975607561756275637564756575667567756875697570757175727573757475757576757775787579758075817582758375847585758675877588758975907591759275937594759575967597759875997600760176027603760476057606760776087609761076117612761376147615761676177618761976207621762276237624762576267627762876297630763176327633763476357636763776387639764076417642764376447645764676477648764976507651765276537654765576567657765876597660766176627663766476657666766776687669767076717672767376747675767676777678767976807681768276837684768576867687768876897690769176927693769476957696769776987699770077017702770377047705770677077708770977107711771277137714771577167717771877197720772177227723772477257726772777287729773077317732773377347735773677377738773977407741774277437744774577467747774877497750775177527753775477557756775777587759776077617762776377647765776677677768776977707771777277737774777577767777777877797780778177827783778477857786778777887789779077917792779377947795779677977798779978007801780278037804780578067807780878097810781178127813781478157816781778187819782078217822782378247825782678277828782978307831783278337834783578367837783878397840784178427843784478457846784778487849785078517852785378547855785678577858785978607861786278637864786578667867786878697870787178727873787478757876787778787879788078817882788378847885788678877888788978907891789278937894789578967897789878997900790179027903790479057906790779087909791079117912791379147915791679177918791979207921792279237924792579267927792879297930793179327933793479357936793779387939794079417942794379447945794679477948794979507951795279537954795579567957795879597960796179627963796479657966796779687969797079717972797379747975797679777978797979807981798279837984798579867987798879897990799179927993799479957996799779987999800080018002800380048005800680078008800980108011801280138014801580168017801880198020802180228023802480258026802780288029803080318032803380348035803680378038803980408041804280438044804580468047804880498050805180528053805480558056805780588059806080618062806380648065806680678068806980708071807280738074807580768077807880798080808180828083808480858086808780888089809080918092809380948095809680978098809981008101810281038104810581068107810881098110811181128113811481158116811781188119812081218122812381248125812681278128812981308131813281338134813581368137813881398140814181428143814481458146814781488149815081518152815381548155815681578158815981608161816281638164816581668167816881698170817181728173817481758176817781788179818081818182818381848185818681878188818981908191819281938194819581968197819881998200820182028203820482058206820782088209821082118212821382148215821682178218821982208221822282238224822582268227822882298230823182328233823482358236823782388239824082418242824382448245824682478248824982508251825282538254825582568257825882598260826182628263826482658266826782688269827082718272827382748275827682778278827982808281828282838284828582868287828882898290829182928293829482958296829782988299830083018302830383048305830683078308830983108311831283138314831583168317831883198320832183228323832483258326832783288329833083318332833383348335833683378338833983408341834283438344834583468347834883498350835183528353835483558356835783588359836083618362836383648365836683678368836983708371837283738374837583768377837883798380838183828383838483858386838783888389839083918392839383948395839683978398839984008401840284038404840584068407840884098410841184128413841484158416841784188419842084218422842384248425842684278428842984308431843284338434843584368437843884398440844184428443844484458446844784488449845084518452845384548455845684578458845984608461846284638464846584668467846884698470847184728473847484758476847784788479848084818482848384848485848684878488848984908491849284938494849584968497849884998500850185028503850485058506850785088509851085118512851385148515851685178518851985208521852285238524852585268527852885298530853185328533853485358536853785388539854085418542854385448545854685478548854985508551855285538554855585568557855885598560856185628563856485658566856785688569857085718572857385748575857685778578857985808581858285838584858585868587858885898590859185928593859485958596859785988599860086018602860386048605860686078608860986108611861286138614861586168617861886198620862186228623862486258626862786288629863086318632863386348635863686378638863986408641864286438644864586468647864886498650865186528653865486558656865786588659866086618662866386648665866686678668866986708671867286738674867586768677867886798680868186828683868486858686868786888689869086918692869386948695869686978698869987008701870287038704870587068707870887098710871187128713871487158716871787188719872087218722872387248725872687278728872987308731873287338734873587368737873887398740874187428743874487458746874787488749875087518752875387548755875687578758875987608761876287638764876587668767876887698770877187728773877487758776877787788779878087818782878387848785878687878788878987908791879287938794879587968797879887998800880188028803880488058806880788088809881088118812881388148815881688178818881988208821882288238824882588268827882888298830883188328833883488358836883788388839884088418842884388448845884688478848884988508851885288538854885588568857885888598860886188628863886488658866886788688869887088718872887388748875887688778878887988808881888288838884888588868887888888898890889188928893889488958896889788988899890089018902890389048905890689078908890989108911891289138914891589168917891889198920892189228923892489258926892789288929893089318932893389348935893689378938893989408941894289438944894589468947894889498950895189528953895489558956895789588959896089618962896389648965896689678968896989708971897289738974897589768977897889798980898189828983898489858986898789888989899089918992899389948995899689978998899990009001900290039004900590069007900890099010901190129013901490159016901790189019902090219022902390249025902690279028902990309031903290339034903590369037903890399040904190429043904490459046904790489049905090519052905390549055905690579058905990609061906290639064906590669067906890699070907190729073907490759076907790789079908090819082908390849085908690879088908990909091909290939094909590969097909890999100910191029103910491059106910791089109911091119112911391149115911691179118911991209121912291239124912591269127912891299130913191329133913491359136913791389139914091419142914391449145914691479148914991509151915291539154915591569157915891599160916191629163916491659166916791689169917091719172917391749175917691779178917991809181918291839184918591869187918891899190919191929193919491959196919791989199920092019202920392049205920692079208920992109211921292139214921592169217921892199220922192229223922492259226922792289229923092319232923392349235923692379238923992409241924292439244924592469247924892499250925192529253925492559256925792589259926092619262926392649265926692679268926992709271927292739274927592769277927892799280928192829283928492859286928792889289929092919292929392949295929692979298929993009301930293039304930593069307930893099310931193129313931493159316931793189319932093219322932393249325932693279328932993309331933293339334933593369337933893399340934193429343934493459346934793489349935093519352935393549355935693579358935993609361936293639364936593669367936893699370937193729373937493759376937793789379938093819382938393849385938693879388938993909391939293939394939593969397939893999400940194029403940494059406940794089409941094119412941394149415941694179418941994209421942294239424942594269427942894299430943194329433943494359436943794389439944094419442944394449445944694479448944994509451945294539454945594569457945894599460946194629463946494659466946794689469947094719472947394749475947694779478947994809481948294839484948594869487948894899490949194929493949494959496949794989499950095019502950395049505950695079508950995109511951295139514951595169517951895199520952195229523952495259526952795289529953095319532953395349535953695379538953995409541954295439544954595469547954895499550955195529553955495559556955795589559956095619562956395649565956695679568956995709571957295739574957595769577957895799580958195829583958495859586958795889589959095919592959395949595959695979598959996009601960296039604960596069607960896099610961196129613961496159616961796189619962096219622962396249625962696279628962996309631963296339634963596369637963896399640964196429643964496459646964796489649965096519652965396549655965696579658965996609661966296639664966596669667966896699670967196729673967496759676967796789679968096819682968396849685968696879688968996909691969296939694969596969697969896999700970197029703970497059706970797089709971097119712971397149715971697179718971997209721972297239724972597269727972897299730973197329733973497359736973797389739974097419742974397449745974697479748974997509751975297539754975597569757975897599760976197629763976497659766976797689769977097719772977397749775977697779778977997809781978297839784978597869787978897899790979197929793979497959796979797989799980098019802980398049805980698079808980998109811981298139814981598169817981898199820982198229823982498259826982798289829983098319832983398349835983698379838983998409841984298439844984598469847984898499850985198529853985498559856985798589859986098619862986398649865986698679868986998709871987298739874987598769877987898799880988198829883988498859886988798889889989098919892989398949895989698979898989999009901990299039904990599069907990899099910991199129913991499159916991799189919992099219922992399249925992699279928992999309931993299339934993599369937993899399940994199429943994499459946994799489949995099519952995399549955995699579958995999609961996299639964996599669967996899699970997199729973997499759976997799789979998099819982998399849985998699879988998999909991999299939994999599969997999899991000010001100021000310004100051000610007100081000910010100111001210013100141001510016100171001810019100201002110022100231002410025100261002710028100291003010031100321003310034100351003610037100381003910040100411004210043100441004510046100471004810049100501005110052100531005410055100561005710058100591006010061100621006310064100651006610067100681006910070100711007210073100741007510076100771007810079100801008110082100831008410085100861008710088100891009010091100921009310094100951009610097100981009910100101011010210103101041010510106101071010810109101101011110112101131011410115101161011710118101191012010121101221012310124101251012610127101281012910130101311013210133101341013510136101371013810139101401014110142101431014410145101461014710148101491015010151101521015310154101551015610157101581015910160101611016210163101641016510166101671016810169101701017110172101731017410175101761017710178101791018010181101821018310184101851018610187101881018910190101911019210193101941019510196101971019810199102001020110202102031020410205102061020710208102091021010211102121021310214102151021610217102181021910220102211022210223102241022510226102271022810229102301023110232102331023410235102361023710238102391024010241102421024310244102451024610247102481024910250102511025210253102541025510256102571025810259102601026110262102631026410265102661026710268102691027010271102721027310274102751027610277102781027910280102811028210283102841028510286102871028810289102901029110292102931029410295102961029710298102991030010301103021030310304103051030610307103081030910310103111031210313103141031510316103171031810319103201032110322103231032410325103261032710328103291033010331103321033310334103351033610337103381033910340103411034210343103441034510346103471034810349103501035110352103531035410355103561035710358103591036010361103621036310364103651036610367103681036910370103711037210373103741037510376103771037810379103801038110382103831038410385103861038710388103891039010391103921039310394103951039610397103981039910400104011040210403104041040510406104071040810409104101041110412104131041410415104161041710418104191042010421104221042310424104251042610427104281042910430104311043210433104341043510436104371043810439104401044110442104431044410445104461044710448104491045010451104521045310454104551045610457104581045910460104611046210463104641046510466104671046810469104701047110472104731047410475104761047710478104791048010481104821048310484104851048610487104881048910490104911049210493104941049510496104971049810499105001050110502105031050410505105061050710508105091051010511105121051310514105151051610517105181051910520105211052210523105241052510526105271052810529105301053110532105331053410535105361053710538105391054010541105421054310544105451054610547105481054910550105511055210553105541055510556105571055810559105601056110562105631056410565105661056710568105691057010571105721057310574105751057610577105781057910580105811058210583105841058510586105871058810589105901059110592105931059410595105961059710598105991060010601106021060310604106051060610607106081060910610106111061210613106141061510616106171061810619106201062110622106231062410625106261062710628106291063010631106321063310634106351063610637106381063910640106411064210643106441064510646106471064810649106501065110652106531065410655106561065710658106591066010661106621066310664106651066610667106681066910670106711067210673106741067510676106771067810679106801068110682106831068410685106861068710688106891069010691106921069310694106951069610697106981069910700107011070210703107041070510706107071070810709107101071110712107131071410715107161071710718107191072010721107221072310724107251072610727107281072910730107311073210733107341073510736107371073810739107401074110742107431074410745107461074710748107491075010751107521075310754107551075610757107581075910760107611076210763107641076510766107671076810769107701077110772107731077410775107761077710778107791078010781107821078310784107851078610787107881078910790107911079210793107941079510796107971079810799108001080110802108031080410805108061080710808108091081010811108121081310814108151081610817108181081910820108211082210823108241082510826108271082810829108301083110832108331083410835108361083710838108391084010841108421084310844108451084610847108481084910850108511085210853108541085510856108571085810859108601086110862108631086410865108661086710868108691087010871108721087310874108751087610877108781087910880108811088210883108841088510886108871088810889108901089110892108931089410895108961089710898108991090010901109021090310904109051090610907109081090910910109111091210913109141091510916109171091810919109201092110922109231092410925109261092710928109291093010931109321093310934109351093610937109381093910940109411094210943109441094510946109471094810949109501095110952109531095410955109561095710958109591096010961109621096310964109651096610967109681096910970109711097210973109741097510976109771097810979109801098110982109831098410985109861098710988109891099010991109921099310994109951099610997109981099911000110011100211003110041100511006110071100811009110101101111012110131101411015110161101711018110191102011021110221102311024110251102611027110281102911030110311103211033110341103511036110371103811039110401104111042110431104411045110461104711048110491105011051110521105311054110551105611057110581105911060110611106211063110641106511066110671106811069110701107111072110731107411075110761107711078110791108011081110821108311084110851108611087110881108911090110911109211093110941109511096110971109811099111001110111102111031110411105111061110711108111091111011111111121111311114111151111611117111181111911120111211112211123111241112511126111271112811129111301113111132111331113411135111361113711138111391114011141111421114311144111451114611147111481114911150111511115211153111541115511156111571115811159111601116111162111631116411165111661116711168111691117011171111721117311174111751117611177111781117911180111811118211183111841118511186111871118811189111901119111192111931119411195111961119711198111991120011201112021120311204112051120611207112081120911210112111121211213112141121511216112171121811219112201122111222112231122411225112261122711228112291123011231112321123311234112351123611237112381123911240112411124211243112441124511246112471124811249112501125111252112531125411255112561125711258112591126011261112621126311264112651126611267112681126911270112711127211273112741127511276112771127811279112801128111282112831128411285112861128711288112891129011291112921129311294112951129611297112981129911300113011130211303113041130511306113071130811309113101131111312113131131411315113161131711318113191132011321113221132311324113251132611327113281132911330113311133211333113341133511336113371133811339113401134111342113431134411345113461134711348113491135011351113521135311354113551135611357113581135911360113611136211363113641136511366113671136811369113701137111372113731137411375113761137711378113791138011381113821138311384113851138611387113881138911390113911139211393113941139511396113971139811399114001140111402114031140411405114061140711408114091141011411114121141311414114151141611417114181141911420114211142211423114241142511426114271142811429114301143111432114331143411435114361143711438114391144011441114421144311444114451144611447114481144911450114511145211453114541145511456114571145811459114601146111462114631146411465114661146711468114691147011471114721147311474114751147611477114781147911480114811148211483114841148511486114871148811489114901149111492114931149411495114961149711498114991150011501115021150311504115051150611507115081150911510115111151211513115141151511516115171151811519115201152111522115231152411525115261152711528115291153011531115321153311534115351153611537115381153911540115411154211543115441154511546115471154811549115501155111552115531155411555115561155711558115591156011561115621156311564115651156611567115681156911570115711157211573115741157511576115771157811579115801158111582115831158411585115861158711588115891159011591115921159311594115951159611597115981159911600116011160211603116041160511606116071160811609116101161111612116131161411615116161161711618116191162011621116221162311624116251162611627116281162911630116311163211633116341163511636116371163811639116401164111642116431164411645116461164711648116491165011651116521165311654116551165611657116581165911660116611166211663116641166511666116671166811669116701167111672116731167411675116761167711678116791168011681116821168311684116851168611687116881168911690116911169211693116941169511696116971169811699117001170111702117031170411705117061170711708117091171011711117121171311714117151171611717117181171911720117211172211723117241172511726117271172811729117301173111732117331173411735117361173711738117391174011741117421174311744117451174611747117481174911750117511175211753117541175511756117571175811759117601176111762117631176411765117661176711768117691177011771117721177311774117751177611777117781177911780117811178211783117841178511786117871178811789117901179111792117931179411795117961179711798117991180011801118021180311804118051180611807118081180911810118111181211813118141181511816118171181811819118201182111822118231182411825118261182711828118291183011831118321183311834118351183611837118381183911840118411184211843118441184511846118471184811849118501185111852118531185411855118561185711858118591186011861118621186311864118651186611867118681186911870118711187211873118741187511876118771187811879118801188111882118831188411885118861188711888118891189011891118921189311894118951189611897118981189911900119011190211903119041190511906119071190811909119101191111912119131191411915119161191711918119191192011921119221192311924119251192611927119281192911930119311193211933119341193511936119371193811939119401194111942119431194411945119461194711948119491195011951119521195311954119551195611957119581195911960119611196211963119641196511966119671196811969119701197111972119731197411975119761197711978119791198011981119821198311984119851198611987119881198911990119911199211993119941199511996119971199811999120001200112002120031200412005120061200712008120091201012011120121201312014120151201612017120181201912020120211202212023120241202512026120271202812029120301203112032120331203412035120361203712038120391204012041120421204312044120451204612047120481204912050120511205212053120541205512056120571205812059120601206112062120631206412065120661206712068120691207012071120721207312074120751207612077120781207912080120811208212083120841208512086120871208812089120901209112092120931209412095120961209712098120991210012101121021210312104121051210612107121081210912110121111211212113121141211512116121171211812119121201212112122121231212412125121261212712128121291213012131121321213312134121351213612137121381213912140121411214212143121441214512146121471214812149121501215112152121531215412155121561215712158121591216012161121621216312164121651216612167121681216912170121711217212173121741217512176121771217812179121801218112182121831218412185121861218712188121891219012191121921219312194121951219612197121981219912200122011220212203122041220512206122071220812209122101221112212122131221412215122161221712218122191222012221122221222312224122251222612227122281222912230122311223212233122341223512236122371223812239122401224112242122431224412245122461224712248122491225012251122521225312254122551225612257122581225912260122611226212263122641226512266122671226812269122701227112272122731227412275122761227712278122791228012281122821228312284122851228612287122881228912290122911229212293122941229512296122971229812299123001230112302123031230412305123061230712308123091231012311123121231312314123151231612317123181231912320123211232212323123241232512326123271232812329123301233112332123331233412335123361233712338123391234012341123421234312344123451234612347123481234912350123511235212353123541235512356123571235812359123601236112362123631236412365123661236712368123691237012371123721237312374123751237612377123781237912380123811238212383123841238512386123871238812389123901239112392123931239412395123961239712398123991240012401124021240312404124051240612407124081240912410124111241212413124141241512416124171241812419124201242112422124231242412425124261242712428124291243012431124321243312434124351243612437124381243912440124411244212443124441244512446124471244812449124501245112452124531245412455124561245712458124591246012461124621246312464124651246612467124681246912470124711247212473124741247512476124771247812479124801248112482124831248412485124861248712488124891249012491124921249312494124951249612497124981249912500125011250212503125041250512506125071250812509125101251112512125131251412515125161251712518125191252012521125221252312524125251252612527125281252912530125311253212533125341253512536125371253812539125401254112542125431254412545125461254712548125491255012551125521255312554125551255612557125581255912560125611256212563125641256512566125671256812569125701257112572125731257412575125761257712578125791258012581125821258312584125851258612587125881258912590125911259212593125941259512596125971259812599126001260112602126031260412605126061260712608126091261012611126121261312614126151261612617126181261912620126211262212623126241262512626126271262812629126301263112632126331263412635126361263712638126391264012641126421264312644126451264612647126481264912650126511265212653126541265512656126571265812659126601266112662126631266412665126661266712668126691267012671126721267312674126751267612677126781267912680126811268212683126841268512686126871268812689126901269112692126931269412695126961269712698126991270012701127021270312704127051270612707127081270912710127111271212713127141271512716127171271812719127201272112722127231272412725127261272712728127291273012731127321273312734127351273612737127381273912740127411274212743127441274512746127471274812749127501275112752127531275412755127561275712758127591276012761127621276312764127651276612767127681276912770127711277212773127741277512776127771277812779127801278112782127831278412785127861278712788127891279012791127921279312794127951279612797127981279912800128011280212803128041280512806128071280812809128101281112812128131281412815128161281712818128191282012821128221282312824128251282612827128281282912830128311283212833128341283512836128371283812839128401284112842128431284412845128461284712848128491285012851128521285312854128551285612857128581285912860128611286212863128641286512866128671286812869128701287112872128731287412875128761287712878128791288012881128821288312884128851288612887128881288912890128911289212893128941289512896128971289812899129001290112902129031290412905129061290712908129091291012911129121291312914129151291612917129181291912920129211292212923129241292512926129271292812929129301293112932129331293412935129361293712938129391294012941129421294312944129451294612947129481294912950129511295212953129541295512956129571295812959129601296112962129631296412965129661296712968129691297012971129721297312974129751297612977129781297912980129811298212983129841298512986129871298812989129901299112992129931299412995129961299712998129991300013001130021300313004130051300613007130081300913010130111301213013130141301513016130171301813019130201302113022130231302413025130261302713028130291303013031130321303313034130351303613037130381303913040130411304213043130441304513046130471304813049130501305113052130531305413055130561305713058130591306013061130621306313064130651306613067130681306913070130711307213073130741307513076130771307813079130801308113082130831308413085130861308713088130891309013091130921309313094130951309613097130981309913100131011310213103131041310513106131071310813109131101311113112131131311413115131161311713118131191312013121131221312313124131251312613127131281312913130131311313213133131341313513136131371313813139131401314113142131431314413145131461314713148131491315013151131521315313154131551315613157131581315913160131611316213163131641316513166131671316813169131701317113172131731317413175131761317713178131791318013181131821318313184131851318613187131881318913190131911319213193131941319513196131971319813199132001320113202132031320413205132061320713208132091321013211132121321313214132151321613217132181321913220132211322213223132241322513226132271322813229132301323113232132331323413235132361323713238132391324013241132421324313244132451324613247132481324913250132511325213253132541325513256132571325813259132601326113262132631326413265132661326713268132691327013271132721327313274132751327613277132781327913280132811328213283132841328513286132871328813289132901329113292132931329413295132961329713298132991330013301133021330313304133051330613307133081330913310133111331213313133141331513316133171331813319133201332113322133231332413325133261332713328133291333013331133321333313334133351333613337133381333913340133411334213343133441334513346133471334813349133501335113352133531335413355133561335713358133591336013361133621336313364133651336613367133681336913370133711337213373133741337513376133771337813379133801338113382133831338413385133861338713388133891339013391133921339313394133951339613397133981339913400134011340213403134041340513406134071340813409134101341113412134131341413415134161341713418134191342013421134221342313424134251342613427134281342913430134311343213433134341343513436134371343813439134401344113442134431344413445134461344713448134491345013451134521345313454134551345613457134581345913460134611346213463134641346513466134671346813469134701347113472134731347413475134761347713478134791348013481134821348313484134851348613487134881348913490134911349213493134941349513496134971349813499135001350113502135031350413505135061350713508135091351013511135121351313514135151351613517135181351913520135211352213523135241352513526135271352813529135301353113532135331353413535135361353713538135391354013541135421354313544135451354613547135481354913550135511355213553135541355513556135571355813559135601356113562135631356413565135661356713568135691357013571135721357313574135751357613577135781357913580135811358213583135841358513586135871358813589135901359113592135931359413595135961359713598135991360013601136021360313604136051360613607136081360913610136111361213613136141361513616136171361813619136201362113622136231362413625136261362713628136291363013631136321363313634136351363613637136381363913640136411364213643136441364513646136471364813649136501365113652136531365413655136561365713658136591366013661136621366313664136651366613667136681366913670136711367213673136741367513676136771367813679136801368113682136831368413685136861368713688136891369013691136921369313694136951369613697136981369913700137011370213703137041370513706137071370813709137101371113712137131371413715137161371713718137191372013721137221372313724137251372613727137281372913730137311373213733137341373513736137371373813739137401374113742137431374413745137461374713748137491375013751137521375313754137551375613757137581375913760137611376213763137641376513766137671376813769137701377113772137731377413775137761377713778137791378013781137821378313784137851378613787137881378913790137911379213793137941379513796137971379813799138001380113802138031380413805138061380713808138091381013811138121381313814138151381613817138181381913820138211382213823138241382513826138271382813829138301383113832138331383413835138361383713838138391384013841138421384313844138451384613847138481384913850138511385213853138541385513856138571385813859138601386113862138631386413865138661386713868138691387013871138721387313874138751387613877138781387913880138811388213883138841388513886138871388813889138901389113892138931389413895138961389713898138991390013901139021390313904139051390613907139081390913910139111391213913139141391513916139171391813919139201392113922139231392413925139261392713928139291393013931139321393313934139351393613937139381393913940139411394213943139441394513946139471394813949139501395113952139531395413955139561395713958139591396013961139621396313964139651396613967139681396913970139711397213973139741397513976139771397813979139801398113982139831398413985139861398713988139891399013991139921399313994139951399613997139981399914000140011400214003140041400514006140071400814009140101401114012140131401414015140161401714018140191402014021140221402314024140251402614027140281402914030140311403214033140341403514036140371403814039140401404114042140431404414045140461404714048140491405014051140521405314054140551405614057140581405914060140611406214063140641406514066140671406814069140701407114072140731407414075140761407714078140791408014081140821408314084140851408614087140881408914090140911409214093140941409514096140971409814099141001410114102141031410414105141061410714108141091411014111141121411314114141151411614117141181411914120141211412214123141241412514126141271412814129141301413114132141331413414135141361413714138141391414014141141421414314144141451414614147141481414914150141511415214153141541415514156141571415814159141601416114162141631416414165141661416714168141691417014171141721417314174141751417614177141781417914180141811418214183141841418514186141871418814189141901419114192141931419414195141961419714198141991420014201142021420314204142051420614207142081420914210142111421214213142141421514216142171421814219142201422114222142231422414225142261422714228142291423014231142321423314234142351423614237142381423914240142411424214243142441424514246142471424814249142501425114252142531425414255142561425714258142591426014261142621426314264142651426614267142681426914270142711427214273142741427514276142771427814279142801428114282142831428414285142861428714288142891429014291142921429314294142951429614297142981429914300143011430214303143041430514306143071430814309143101431114312143131431414315143161431714318143191432014321143221432314324143251432614327143281432914330143311433214333143341433514336143371433814339143401434114342143431434414345143461434714348143491435014351143521435314354143551435614357143581435914360143611436214363143641436514366143671436814369143701437114372143731437414375143761437714378143791438014381143821438314384143851438614387143881438914390143911439214393143941439514396143971439814399144001440114402144031440414405144061440714408144091441014411144121441314414144151441614417144181441914420144211442214423144241442514426144271442814429144301443114432144331443414435144361443714438144391444014441144421444314444144451444614447144481444914450144511445214453144541445514456144571445814459144601446114462144631446414465144661446714468144691447014471144721447314474144751447614477144781447914480144811448214483144841448514486144871448814489144901449114492144931449414495144961449714498144991450014501145021450314504145051450614507145081450914510145111451214513145141451514516145171451814519145201452114522145231452414525145261452714528145291453014531145321453314534145351453614537145381453914540145411454214543145441454514546145471454814549145501455114552145531455414555145561455714558145591456014561145621456314564145651456614567145681456914570145711457214573145741457514576145771457814579145801458114582145831458414585145861458714588145891459014591145921459314594145951459614597145981459914600146011460214603146041460514606146071460814609146101461114612146131461414615146161461714618146191462014621146221462314624146251462614627146281462914630146311463214633146341463514636146371463814639146401464114642146431464414645146461464714648146491465014651146521465314654146551465614657146581465914660146611466214663146641466514666146671466814669146701467114672146731467414675146761467714678146791468014681146821468314684146851468614687146881468914690146911469214693146941469514696146971469814699147001470114702147031470414705147061470714708147091471014711147121471314714147151471614717147181471914720147211472214723147241472514726147271472814729147301473114732147331473414735147361473714738147391474014741147421474314744147451474614747147481474914750147511475214753147541475514756147571475814759147601476114762147631476414765147661476714768147691477014771147721477314774147751477614777147781477914780147811478214783147841478514786147871478814789147901479114792147931479414795147961479714798147991480014801148021480314804148051480614807148081480914810148111481214813148141481514816148171481814819148201482114822148231482414825148261482714828148291483014831148321483314834148351483614837148381483914840148411484214843148441484514846148471484814849148501485114852148531485414855148561485714858148591486014861148621486314864148651486614867148681486914870148711487214873148741487514876148771487814879148801488114882148831488414885148861488714888148891489014891148921489314894148951489614897148981489914900149011490214903149041490514906149071490814909149101491114912149131491414915149161491714918149191492014921149221492314924149251492614927149281492914930149311493214933149341493514936149371493814939149401494114942149431494414945149461494714948149491495014951149521495314954149551495614957149581495914960149611496214963149641496514966149671496814969149701497114972149731497414975149761497714978149791498014981149821498314984149851498614987149881498914990149911499214993149941499514996149971499814999150001500115002150031500415005150061500715008150091501015011150121501315014150151501615017150181501915020150211502215023150241502515026150271502815029150301503115032150331503415035150361503715038150391504015041150421504315044150451504615047150481504915050150511505215053150541505515056150571505815059150601506115062150631506415065150661506715068150691507015071150721507315074150751507615077150781507915080150811508215083150841508515086150871508815089150901509115092150931509415095150961509715098150991510015101151021510315104151051510615107151081510915110151111511215113151141511515116151171511815119151201512115122151231512415125151261512715128151291513015131151321513315134151351513615137151381513915140151411514215143151441514515146151471514815149151501515115152151531515415155151561515715158151591516015161151621516315164151651516615167151681516915170151711517215173151741517515176151771517815179151801518115182151831518415185151861518715188151891519015191151921519315194151951519615197151981519915200152011520215203152041520515206152071520815209152101521115212152131521415215152161521715218152191522015221152221522315224152251522615227152281522915230152311523215233152341523515236152371523815239152401524115242152431524415245152461524715248152491525015251152521525315254152551525615257152581525915260152611526215263152641526515266152671526815269152701527115272152731527415275152761527715278152791528015281152821528315284152851528615287152881528915290152911529215293152941529515296152971529815299153001530115302153031530415305153061530715308153091531015311153121531315314153151531615317153181531915320153211532215323153241532515326153271532815329153301533115332153331533415335153361533715338153391534015341153421534315344153451534615347153481534915350153511535215353153541535515356153571535815359153601536115362153631536415365153661536715368153691537015371153721537315374153751537615377153781537915380153811538215383153841538515386153871538815389153901539115392153931539415395153961539715398153991540015401154021540315404154051540615407154081540915410154111541215413154141541515416154171541815419154201542115422154231542415425154261542715428154291543015431154321543315434154351543615437154381543915440154411544215443154441544515446154471544815449154501545115452154531545415455154561545715458154591546015461154621546315464154651546615467154681546915470154711547215473154741547515476154771547815479154801548115482154831548415485154861548715488154891549015491154921549315494154951549615497154981549915500155011550215503155041550515506155071550815509155101551115512155131551415515155161551715518155191552015521155221552315524155251552615527155281552915530155311553215533155341553515536155371553815539155401554115542155431554415545155461554715548155491555015551155521555315554155551555615557155581555915560155611556215563155641556515566155671556815569155701557115572155731557415575155761557715578155791558015581155821558315584155851558615587155881558915590155911559215593155941559515596155971559815599156001560115602156031560415605156061560715608156091561015611156121561315614156151561615617156181561915620156211562215623156241562515626156271562815629156301563115632156331563415635156361563715638156391564015641156421564315644156451564615647156481564915650156511565215653156541565515656156571565815659156601566115662156631566415665156661566715668156691567015671156721567315674156751567615677156781567915680156811568215683156841568515686156871568815689156901569115692156931569415695156961569715698156991570015701157021570315704157051570615707157081570915710157111571215713157141571515716157171571815719157201572115722157231572415725157261572715728157291573015731157321573315734157351573615737157381573915740157411574215743157441574515746157471574815749157501575115752157531575415755157561575715758157591576015761157621576315764157651576615767157681576915770157711577215773157741577515776157771577815779157801578115782157831578415785157861578715788157891579015791157921579315794157951579615797157981579915800158011580215803158041580515806158071580815809158101581115812158131581415815158161581715818158191582015821158221582315824158251582615827158281582915830158311583215833158341583515836158371583815839158401584115842158431584415845158461584715848158491585015851158521585315854158551585615857158581585915860158611586215863158641586515866158671586815869158701587115872158731587415875158761587715878158791588015881158821588315884158851588615887158881588915890158911589215893158941589515896158971589815899159001590115902159031590415905159061590715908159091591015911159121591315914159151591615917159181591915920159211592215923159241592515926159271592815929159301593115932159331593415935159361593715938159391594015941159421594315944159451594615947159481594915950159511595215953159541595515956159571595815959159601596115962159631596415965159661596715968159691597015971159721597315974159751597615977159781597915980159811598215983159841598515986159871598815989159901599115992159931599415995159961599715998159991600016001160021600316004160051600616007160081600916010160111601216013160141601516016160171601816019160201602116022160231602416025160261602716028160291603016031160321603316034160351603616037160381603916040160411604216043160441604516046160471604816049160501605116052160531605416055160561605716058160591606016061160621606316064160651606616067160681606916070160711607216073160741607516076160771607816079160801608116082160831608416085160861608716088160891609016091160921609316094160951609616097160981609916100161011610216103161041610516106161071610816109161101611116112161131611416115161161611716118161191612016121161221612316124161251612616127161281612916130161311613216133161341613516136161371613816139161401614116142161431614416145161461614716148161491615016151161521615316154161551615616157161581615916160161611616216163161641616516166161671616816169161701617116172161731617416175161761617716178161791618016181161821618316184161851618616187161881618916190161911619216193161941619516196161971619816199162001620116202162031620416205162061620716208162091621016211162121621316214162151621616217162181621916220162211622216223162241622516226162271622816229162301623116232162331623416235162361623716238162391624016241162421624316244162451624616247162481624916250162511625216253162541625516256162571625816259162601626116262162631626416265162661626716268162691627016271162721627316274162751627616277162781627916280162811628216283162841628516286162871628816289162901629116292162931629416295162961629716298162991630016301163021630316304163051630616307163081630916310163111631216313163141631516316163171631816319163201632116322163231632416325163261632716328163291633016331163321633316334163351633616337163381633916340163411634216343163441634516346163471634816349163501635116352163531635416355163561635716358163591636016361163621636316364163651636616367163681636916370163711637216373163741637516376163771637816379163801638116382163831638416385163861638716388163891639016391163921639316394163951639616397163981639916400164011640216403164041640516406164071640816409164101641116412164131641416415164161641716418164191642016421164221642316424164251642616427164281642916430164311643216433164341643516436164371643816439164401644116442164431644416445164461644716448164491645016451164521645316454164551645616457164581645916460164611646216463164641646516466164671646816469164701647116472164731647416475164761647716478164791648016481164821648316484164851648616487164881648916490164911649216493164941649516496164971649816499165001650116502165031650416505165061650716508165091651016511165121651316514165151651616517165181651916520165211652216523165241652516526165271652816529165301653116532165331653416535165361653716538165391654016541165421654316544165451654616547165481654916550165511655216553165541655516556165571655816559165601656116562165631656416565165661656716568165691657016571165721657316574165751657616577165781657916580165811658216583165841658516586165871658816589165901659116592165931659416595165961659716598165991660016601166021660316604166051660616607166081660916610166111661216613166141661516616166171661816619166201662116622166231662416625166261662716628166291663016631166321663316634166351663616637166381663916640166411664216643166441664516646166471664816649166501665116652166531665416655166561665716658166591666016661166621666316664166651666616667166681666916670166711667216673166741667516676166771667816679166801668116682166831668416685166861668716688166891669016691166921669316694166951669616697166981669916700167011670216703167041670516706167071670816709167101671116712167131671416715167161671716718167191672016721167221672316724167251672616727167281672916730167311673216733167341673516736167371673816739167401674116742167431674416745167461674716748167491675016751167521675316754167551675616757167581675916760167611676216763167641676516766167671676816769167701677116772167731677416775167761677716778167791678016781167821678316784167851678616787167881678916790167911679216793167941679516796167971679816799168001680116802168031680416805168061680716808168091681016811168121681316814168151681616817168181681916820168211682216823168241682516826168271682816829168301683116832168331683416835168361683716838168391684016841168421684316844168451684616847168481684916850168511685216853168541685516856168571685816859168601686116862168631686416865168661686716868168691687016871168721687316874168751687616877168781687916880168811688216883168841688516886168871688816889168901689116892168931689416895168961689716898168991690016901169021690316904169051690616907169081690916910169111691216913169141691516916169171691816919169201692116922169231692416925169261692716928169291693016931169321693316934169351693616937169381693916940169411694216943169441694516946169471694816949169501695116952169531695416955169561695716958169591696016961169621696316964169651696616967169681696916970169711697216973169741697516976169771697816979169801698116982169831698416985169861698716988169891699016991169921699316994169951699616997169981699917000170011700217003170041700517006170071700817009170101701117012170131701417015170161701717018170191702017021170221702317024170251702617027170281702917030170311703217033170341703517036170371703817039170401704117042170431704417045170461704717048170491705017051170521705317054170551705617057170581705917060170611706217063170641706517066170671706817069170701707117072170731707417075170761707717078170791708017081170821708317084170851708617087170881708917090170911709217093170941709517096170971709817099171001710117102171031710417105171061710717108171091711017111171121711317114171151711617117171181711917120171211712217123171241712517126171271712817129171301713117132171331713417135171361713717138171391714017141171421714317144171451714617147171481714917150171511715217153171541715517156171571715817159171601716117162171631716417165171661716717168171691717017171171721717317174171751717617177171781717917180171811718217183171841718517186171871718817189171901719117192171931719417195171961719717198171991720017201172021720317204172051720617207172081720917210172111721217213172141721517216172171721817219172201722117222172231722417225172261722717228172291723017231172321723317234172351723617237172381723917240172411724217243172441724517246172471724817249172501725117252172531725417255172561725717258172591726017261172621726317264172651726617267172681726917270172711727217273172741727517276172771727817279172801728117282172831728417285172861728717288172891729017291172921729317294172951729617297172981729917300173011730217303173041730517306173071730817309173101731117312173131731417315173161731717318173191732017321173221732317324173251732617327173281732917330173311733217333173341733517336173371733817339173401734117342173431734417345173461734717348173491735017351173521735317354173551735617357173581735917360173611736217363173641736517366173671736817369173701737117372173731737417375173761737717378173791738017381173821738317384173851738617387173881738917390173911739217393173941739517396173971739817399174001740117402174031740417405174061740717408174091741017411174121741317414174151741617417174181741917420174211742217423174241742517426174271742817429174301743117432174331743417435174361743717438174391744017441174421744317444174451744617447174481744917450174511745217453174541745517456174571745817459174601746117462174631746417465174661746717468174691747017471174721747317474174751747617477174781747917480174811748217483174841748517486174871748817489174901749117492174931749417495174961749717498174991750017501175021750317504175051750617507175081750917510175111751217513175141751517516175171751817519175201752117522175231752417525175261752717528175291753017531175321753317534175351753617537175381753917540175411754217543175441754517546175471754817549175501755117552175531755417555175561755717558175591756017561175621756317564175651756617567175681756917570175711757217573175741757517576175771757817579175801758117582175831758417585175861758717588175891759017591175921759317594175951759617597175981759917600176011760217603176041760517606176071760817609176101761117612176131761417615176161761717618176191762017621176221762317624176251762617627176281762917630176311763217633176341763517636176371763817639176401764117642176431764417645176461764717648176491765017651176521765317654176551765617657176581765917660176611766217663176641766517666176671766817669176701767117672176731767417675176761767717678176791768017681176821768317684176851768617687176881768917690176911769217693176941769517696176971769817699177001770117702177031770417705177061770717708177091771017711177121771317714177151771617717177181771917720177211772217723177241772517726177271772817729177301773117732177331773417735177361773717738177391774017741177421774317744177451774617747177481774917750177511775217753177541775517756177571775817759177601776117762177631776417765177661776717768177691777017771177721777317774177751777617777177781777917780177811778217783177841778517786177871778817789177901779117792177931779417795177961779717798177991780017801178021780317804178051780617807178081780917810178111781217813178141781517816178171781817819178201782117822178231782417825178261782717828178291783017831178321783317834178351783617837178381783917840178411784217843178441784517846178471784817849178501785117852178531785417855178561785717858178591786017861178621786317864178651786617867178681786917870178711787217873178741787517876178771787817879178801788117882178831788417885178861788717888178891789017891178921789317894178951789617897178981789917900179011790217903179041790517906179071790817909179101791117912179131791417915179161791717918179191792017921179221792317924179251792617927179281792917930179311793217933179341793517936179371793817939179401794117942179431794417945179461794717948179491795017951179521795317954179551795617957179581795917960179611796217963179641796517966179671796817969179701797117972179731797417975179761797717978179791798017981179821798317984179851798617987179881798917990179911799217993179941799517996179971799817999180001800118002180031800418005180061800718008180091801018011180121801318014180151801618017180181801918020180211802218023180241802518026180271802818029180301803118032180331803418035180361803718038180391804018041180421804318044180451804618047180481804918050180511805218053180541805518056180571805818059180601806118062180631806418065180661806718068180691807018071180721807318074180751807618077180781807918080180811808218083180841808518086180871808818089180901809118092180931809418095180961809718098180991810018101181021810318104181051810618107181081810918110181111811218113181141811518116181171811818119181201812118122181231812418125181261812718128181291813018131181321813318134181351813618137181381813918140181411814218143181441814518146181471814818149181501815118152181531815418155181561815718158181591816018161181621816318164181651816618167181681816918170181711817218173181741817518176181771817818179181801818118182181831818418185181861818718188181891819018191181921819318194181951819618197181981819918200182011820218203182041820518206182071820818209182101821118212182131821418215182161821718218182191822018221182221822318224182251822618227182281822918230182311823218233182341823518236182371823818239182401824118242182431824418245182461824718248182491825018251182521825318254182551825618257182581825918260182611826218263182641826518266182671826818269182701827118272182731827418275182761827718278182791828018281182821828318284182851828618287182881828918290182911829218293182941829518296182971829818299183001830118302183031830418305183061830718308183091831018311183121831318314183151831618317183181831918320183211832218323183241832518326183271832818329183301833118332183331833418335183361833718338183391834018341183421834318344183451834618347183481834918350183511835218353183541835518356183571835818359183601836118362183631836418365183661836718368183691837018371183721837318374183751837618377183781837918380183811838218383183841838518386183871838818389183901839118392183931839418395183961839718398183991840018401184021840318404184051840618407184081840918410184111841218413184141841518416184171841818419184201842118422184231842418425184261842718428184291843018431184321843318434184351843618437184381843918440184411844218443184441844518446184471844818449184501845118452184531845418455184561845718458184591846018461184621846318464184651846618467184681846918470184711847218473184741847518476184771847818479184801848118482184831848418485184861848718488184891849018491184921849318494184951849618497184981849918500185011850218503185041850518506185071850818509185101851118512185131851418515185161851718518185191852018521185221852318524185251852618527185281852918530185311853218533185341853518536185371853818539185401854118542185431854418545185461854718548185491855018551185521855318554185551855618557185581855918560185611856218563185641856518566185671856818569185701857118572185731857418575185761857718578185791858018581185821858318584185851858618587185881858918590185911859218593185941859518596185971859818599186001860118602186031860418605186061860718608186091861018611186121861318614186151861618617186181861918620186211862218623186241862518626186271862818629186301863118632186331863418635186361863718638186391864018641186421864318644186451864618647186481864918650186511865218653186541865518656186571865818659186601866118662186631866418665186661866718668186691867018671186721867318674186751867618677186781867918680186811868218683186841868518686186871868818689186901869118692186931869418695186961869718698186991870018701187021870318704187051870618707187081870918710187111871218713187141871518716187171871818719187201872118722187231872418725187261872718728187291873018731187321873318734187351873618737187381873918740187411874218743187441874518746187471874818749187501875118752187531875418755187561875718758187591876018761187621876318764187651876618767187681876918770187711877218773187741877518776187771877818779187801878118782187831878418785187861878718788187891879018791187921879318794187951879618797187981879918800188011880218803188041880518806188071880818809188101881118812188131881418815188161881718818188191882018821188221882318824188251882618827188281882918830188311883218833188341883518836188371883818839188401884118842188431884418845188461884718848188491885018851188521885318854188551885618857188581885918860188611886218863188641886518866188671886818869188701887118872188731887418875188761887718878188791888018881188821888318884188851888618887188881888918890188911889218893188941889518896188971889818899189001890118902189031890418905189061890718908189091891018911189121891318914189151891618917189181891918920189211892218923189241892518926189271892818929189301893118932189331893418935189361893718938189391894018941189421894318944189451894618947189481894918950189511895218953189541895518956189571895818959189601896118962189631896418965189661896718968189691897018971189721897318974189751897618977189781897918980189811898218983189841898518986189871898818989189901899118992189931899418995189961899718998189991900019001190021900319004190051900619007190081900919010190111901219013190141901519016190171901819019190201902119022190231902419025190261902719028190291903019031190321903319034190351903619037190381903919040190411904219043190441904519046190471904819049190501905119052190531905419055190561905719058190591906019061190621906319064190651906619067190681906919070190711907219073190741907519076190771907819079190801908119082190831908419085190861908719088190891909019091190921909319094190951909619097190981909919100191011910219103191041910519106191071910819109191101911119112191131911419115191161911719118191191912019121191221912319124191251912619127191281912919130191311913219133191341913519136191371913819139191401914119142191431914419145191461914719148191491915019151191521915319154191551915619157191581915919160191611916219163191641916519166191671916819169191701917119172191731917419175191761917719178191791918019181191821918319184191851918619187191881918919190191911919219193191941919519196191971919819199192001920119202192031920419205192061920719208192091921019211192121921319214192151921619217192181921919220192211922219223192241922519226192271922819229192301923119232192331923419235192361923719238192391924019241192421924319244192451924619247192481924919250192511925219253192541925519256192571925819259192601926119262192631926419265192661926719268192691927019271192721927319274192751927619277192781927919280192811928219283192841928519286192871928819289192901929119292192931929419295192961929719298192991930019301193021930319304193051930619307193081930919310193111931219313193141931519316193171931819319193201932119322193231932419325193261932719328193291933019331193321933319334193351933619337193381933919340
  1. /*!
  2. * Copyright (c) 2014, GlobalSign
  3. * Copyright (c) 2015-2019, Peculiar Ventures
  4. * All rights reserved.
  5. *
  6. * Author 2014-2019, Yury Strozhevsky
  7. *
  8. * Redistribution and use in source and binary forms, with or without modification,
  9. * are permitted provided that the following conditions are met:
  10. *
  11. * * Redistributions of source code must retain the above copyright notice, this
  12. * list of conditions and the following disclaimer.
  13. *
  14. * * Redistributions in binary form must reproduce the above copyright notice, this
  15. * list of conditions and the following disclaimer in the documentation and/or
  16. * other materials provided with the distribution.
  17. *
  18. * * Neither the name of the {organization} nor the names of its
  19. * contributors may be used to endorse or promote products derived from
  20. * this software without specific prior written permission.
  21. *
  22. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND
  23. * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
  24. * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
  25. * DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR
  26. * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
  27. * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  28. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON
  29. * ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
  30. * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
  31. * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  32. *
  33. */
  34. 'use strict';
  35. var asn1js = require('asn1js');
  36. var pvtsutils = require('pvtsutils');
  37. var pvutils = require('pvutils');
  38. var bs = require('bytestreamjs');
  39. var sha1 = require('@noble/hashes/sha1');
  40. var sha2 = require('@noble/hashes/sha2');
  41. function _interopNamespaceDefault(e) {
  42. var n = Object.create(null);
  43. if (e) {
  44. Object.keys(e).forEach(function (k) {
  45. if (k !== 'default') {
  46. var d = Object.getOwnPropertyDescriptor(e, k);
  47. Object.defineProperty(n, k, d.get ? d : {
  48. enumerable: true,
  49. get: function () { return e[k]; }
  50. });
  51. }
  52. });
  53. }
  54. n.default = e;
  55. return Object.freeze(n);
  56. }
  57. var asn1js__namespace = /*#__PURE__*/_interopNamespaceDefault(asn1js);
  58. var pvtsutils__namespace = /*#__PURE__*/_interopNamespaceDefault(pvtsutils);
  59. var pvutils__namespace = /*#__PURE__*/_interopNamespaceDefault(pvutils);
  60. var bs__namespace = /*#__PURE__*/_interopNamespaceDefault(bs);
  61. const EMPTY_BUFFER = new ArrayBuffer(0);
  62. const EMPTY_STRING = "";
  63. class ArgumentError extends TypeError {
  64. constructor() {
  65. super(...arguments);
  66. this.name = ArgumentError.NAME;
  67. }
  68. static isType(value, type) {
  69. if (typeof type === "string") {
  70. if (type === "Array" && Array.isArray(value)) {
  71. return true;
  72. }
  73. else if (type === "ArrayBuffer" && value instanceof ArrayBuffer) {
  74. return true;
  75. }
  76. else if (type === "ArrayBufferView" && ArrayBuffer.isView(value)) {
  77. return true;
  78. }
  79. else if (typeof value === type) {
  80. return true;
  81. }
  82. }
  83. else if (value instanceof type) {
  84. return true;
  85. }
  86. return false;
  87. }
  88. static assert(value, name, ...types) {
  89. for (const type of types) {
  90. if (this.isType(value, type)) {
  91. return;
  92. }
  93. }
  94. const typeNames = types.map(o => o instanceof Function && "name" in o ? o.name : `${o}`);
  95. throw new ArgumentError(`Parameter '${name}' is not of type ${typeNames.length > 1 ? `(${typeNames.join(" or ")})` : typeNames[0]}`);
  96. }
  97. }
  98. ArgumentError.NAME = "ArgumentError";
  99. class ParameterError extends TypeError {
  100. static assert(...args) {
  101. let target = null;
  102. let params;
  103. let fields;
  104. if (typeof args[0] === "string") {
  105. target = args[0];
  106. params = args[1];
  107. fields = args.slice(2);
  108. }
  109. else {
  110. params = args[0];
  111. fields = args.slice(1);
  112. }
  113. ArgumentError.assert(params, "parameters", "object");
  114. for (const field of fields) {
  115. const value = params[field];
  116. if (value === undefined || value === null) {
  117. throw new ParameterError(field, target);
  118. }
  119. }
  120. }
  121. static assertEmpty(value, name, target) {
  122. if (value === undefined || value === null) {
  123. throw new ParameterError(name, target);
  124. }
  125. }
  126. constructor(field, target = null, message) {
  127. super();
  128. this.name = ParameterError.NAME;
  129. this.field = field;
  130. if (target) {
  131. this.target = target;
  132. }
  133. if (message) {
  134. this.message = message;
  135. }
  136. else {
  137. this.message = `Absent mandatory parameter '${field}' ${target ? ` in '${target}'` : EMPTY_STRING}`;
  138. }
  139. }
  140. }
  141. ParameterError.NAME = "ParameterError";
  142. class AsnError extends Error {
  143. static assertSchema(asn1, target) {
  144. if (!asn1.verified) {
  145. throw new Error(`Object's schema was not verified against input data for ${target}`);
  146. }
  147. }
  148. static assert(asn, target) {
  149. if (asn.offset === -1) {
  150. throw new AsnError(`Error during parsing of ASN.1 data. Data is not correct for '${target}'.`);
  151. }
  152. }
  153. constructor(message) {
  154. super(message);
  155. this.name = "AsnError";
  156. }
  157. }
  158. class PkiObject {
  159. static blockName() {
  160. return this.CLASS_NAME;
  161. }
  162. static fromBER(raw) {
  163. const asn1 = asn1js__namespace.fromBER(raw);
  164. AsnError.assert(asn1, this.name);
  165. try {
  166. return new this({ schema: asn1.result });
  167. }
  168. catch (e) {
  169. throw new AsnError(`Cannot create '${this.CLASS_NAME}' from ASN.1 object`);
  170. }
  171. }
  172. static defaultValues(memberName) {
  173. throw new Error(`Invalid member name for ${this.CLASS_NAME} class: ${memberName}`);
  174. }
  175. static schema(parameters = {}) {
  176. throw new Error(`Method '${this.CLASS_NAME}.schema' should be overridden`);
  177. }
  178. get className() {
  179. return this.constructor.CLASS_NAME;
  180. }
  181. toString(encoding = "hex") {
  182. let schema;
  183. try {
  184. schema = this.toSchema();
  185. }
  186. catch {
  187. schema = this.toSchema(true);
  188. }
  189. return pvtsutils__namespace.Convert.ToString(schema.toBER(), encoding);
  190. }
  191. }
  192. PkiObject.CLASS_NAME = "PkiObject";
  193. function stringPrep(inputString) {
  194. let isSpace = false;
  195. let cutResult = EMPTY_STRING;
  196. const result = inputString.trim();
  197. for (let i = 0; i < result.length; i++) {
  198. if (result.charCodeAt(i) === 32) {
  199. if (isSpace === false)
  200. isSpace = true;
  201. }
  202. else {
  203. if (isSpace) {
  204. cutResult += " ";
  205. isSpace = false;
  206. }
  207. cutResult += result[i];
  208. }
  209. }
  210. return cutResult.toLowerCase();
  211. }
  212. const TYPE$5 = "type";
  213. const VALUE$6 = "value";
  214. class AttributeTypeAndValue extends PkiObject {
  215. constructor(parameters = {}) {
  216. super();
  217. this.type = pvutils__namespace.getParametersValue(parameters, TYPE$5, AttributeTypeAndValue.defaultValues(TYPE$5));
  218. this.value = pvutils__namespace.getParametersValue(parameters, VALUE$6, AttributeTypeAndValue.defaultValues(VALUE$6));
  219. if (parameters.schema) {
  220. this.fromSchema(parameters.schema);
  221. }
  222. }
  223. static defaultValues(memberName) {
  224. switch (memberName) {
  225. case TYPE$5:
  226. return EMPTY_STRING;
  227. case VALUE$6:
  228. return {};
  229. default:
  230. return super.defaultValues(memberName);
  231. }
  232. }
  233. static schema(parameters = {}) {
  234. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  235. return (new asn1js__namespace.Sequence({
  236. name: (names.blockName || EMPTY_STRING),
  237. value: [
  238. new asn1js__namespace.ObjectIdentifier({ name: (names.type || EMPTY_STRING) }),
  239. new asn1js__namespace.Any({ name: (names.value || EMPTY_STRING) })
  240. ]
  241. }));
  242. }
  243. fromSchema(schema) {
  244. pvutils__namespace.clearProps(schema, [
  245. TYPE$5,
  246. "typeValue"
  247. ]);
  248. const asn1 = asn1js__namespace.compareSchema(schema, schema, AttributeTypeAndValue.schema({
  249. names: {
  250. type: TYPE$5,
  251. value: "typeValue"
  252. }
  253. }));
  254. AsnError.assertSchema(asn1, this.className);
  255. this.type = asn1.result.type.valueBlock.toString();
  256. this.value = asn1.result.typeValue;
  257. }
  258. toSchema() {
  259. return (new asn1js__namespace.Sequence({
  260. value: [
  261. new asn1js__namespace.ObjectIdentifier({ value: this.type }),
  262. this.value
  263. ]
  264. }));
  265. }
  266. toJSON() {
  267. const _object = {
  268. type: this.type
  269. };
  270. if (Object.keys(this.value).length !== 0) {
  271. _object.value = (this.value).toJSON();
  272. }
  273. else {
  274. _object.value = this.value;
  275. }
  276. return _object;
  277. }
  278. isEqual(compareTo) {
  279. const stringBlockNames = [
  280. asn1js__namespace.Utf8String.blockName(),
  281. asn1js__namespace.BmpString.blockName(),
  282. asn1js__namespace.UniversalString.blockName(),
  283. asn1js__namespace.NumericString.blockName(),
  284. asn1js__namespace.PrintableString.blockName(),
  285. asn1js__namespace.TeletexString.blockName(),
  286. asn1js__namespace.VideotexString.blockName(),
  287. asn1js__namespace.IA5String.blockName(),
  288. asn1js__namespace.GraphicString.blockName(),
  289. asn1js__namespace.VisibleString.blockName(),
  290. asn1js__namespace.GeneralString.blockName(),
  291. asn1js__namespace.CharacterString.blockName()
  292. ];
  293. if (compareTo instanceof ArrayBuffer) {
  294. return pvtsutils__namespace.BufferSourceConverter.isEqual(this.value.valueBeforeDecodeView, compareTo);
  295. }
  296. if (compareTo.constructor.blockName() === AttributeTypeAndValue.blockName()) {
  297. if (this.type !== compareTo.type)
  298. return false;
  299. const isStringPair = [false, false];
  300. const thisName = this.value.constructor.blockName();
  301. for (const name of stringBlockNames) {
  302. if (thisName === name) {
  303. isStringPair[0] = true;
  304. }
  305. if (compareTo.value.constructor.blockName() === name) {
  306. isStringPair[1] = true;
  307. }
  308. }
  309. if (isStringPair[0] !== isStringPair[1]) {
  310. return false;
  311. }
  312. const isString = (isStringPair[0] && isStringPair[1]);
  313. if (isString) {
  314. const value1 = stringPrep(this.value.valueBlock.value);
  315. const value2 = stringPrep(compareTo.value.valueBlock.value);
  316. if (value1.localeCompare(value2) !== 0)
  317. return false;
  318. }
  319. else {
  320. if (!pvtsutils__namespace.BufferSourceConverter.isEqual(this.value.valueBeforeDecodeView, compareTo.value.valueBeforeDecodeView))
  321. return false;
  322. }
  323. return true;
  324. }
  325. return false;
  326. }
  327. }
  328. AttributeTypeAndValue.CLASS_NAME = "AttributeTypeAndValue";
  329. const TYPE_AND_VALUES = "typesAndValues";
  330. const VALUE_BEFORE_DECODE = "valueBeforeDecode";
  331. const RDN = "RDN";
  332. class RelativeDistinguishedNames extends PkiObject {
  333. constructor(parameters = {}) {
  334. super();
  335. this.typesAndValues = pvutils__namespace.getParametersValue(parameters, TYPE_AND_VALUES, RelativeDistinguishedNames.defaultValues(TYPE_AND_VALUES));
  336. this.valueBeforeDecode = pvutils__namespace.getParametersValue(parameters, VALUE_BEFORE_DECODE, RelativeDistinguishedNames.defaultValues(VALUE_BEFORE_DECODE));
  337. if (parameters.schema) {
  338. this.fromSchema(parameters.schema);
  339. }
  340. }
  341. static defaultValues(memberName) {
  342. switch (memberName) {
  343. case TYPE_AND_VALUES:
  344. return [];
  345. case VALUE_BEFORE_DECODE:
  346. return EMPTY_BUFFER;
  347. default:
  348. return super.defaultValues(memberName);
  349. }
  350. }
  351. static compareWithDefault(memberName, memberValue) {
  352. switch (memberName) {
  353. case TYPE_AND_VALUES:
  354. return (memberValue.length === 0);
  355. case VALUE_BEFORE_DECODE:
  356. return (memberValue.byteLength === 0);
  357. default:
  358. return super.defaultValues(memberName);
  359. }
  360. }
  361. static schema(parameters = {}) {
  362. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  363. return (new asn1js__namespace.Sequence({
  364. name: (names.blockName || EMPTY_STRING),
  365. value: [
  366. new asn1js__namespace.Repeated({
  367. name: (names.repeatedSequence || EMPTY_STRING),
  368. value: new asn1js__namespace.Set({
  369. value: [
  370. new asn1js__namespace.Repeated({
  371. name: (names.repeatedSet || EMPTY_STRING),
  372. value: AttributeTypeAndValue.schema(names.typeAndValue || {})
  373. })
  374. ]
  375. })
  376. })
  377. ]
  378. }));
  379. }
  380. fromSchema(schema) {
  381. pvutils__namespace.clearProps(schema, [
  382. RDN,
  383. TYPE_AND_VALUES
  384. ]);
  385. const asn1 = asn1js__namespace.compareSchema(schema, schema, RelativeDistinguishedNames.schema({
  386. names: {
  387. blockName: RDN,
  388. repeatedSet: TYPE_AND_VALUES
  389. }
  390. }));
  391. AsnError.assertSchema(asn1, this.className);
  392. if (TYPE_AND_VALUES in asn1.result) {
  393. this.typesAndValues = Array.from(asn1.result.typesAndValues, element => new AttributeTypeAndValue({ schema: element }));
  394. }
  395. this.valueBeforeDecode = asn1.result.RDN.valueBeforeDecodeView.slice().buffer;
  396. }
  397. toSchema() {
  398. if (this.valueBeforeDecode.byteLength === 0) {
  399. return (new asn1js__namespace.Sequence({
  400. value: [new asn1js__namespace.Set({
  401. value: Array.from(this.typesAndValues, o => o.toSchema())
  402. })]
  403. }));
  404. }
  405. const asn1 = asn1js__namespace.fromBER(this.valueBeforeDecode);
  406. AsnError.assert(asn1, "RelativeDistinguishedNames");
  407. if (!(asn1.result instanceof asn1js__namespace.Sequence)) {
  408. throw new Error("ASN.1 result should be SEQUENCE");
  409. }
  410. return asn1.result;
  411. }
  412. toJSON() {
  413. return {
  414. typesAndValues: Array.from(this.typesAndValues, o => o.toJSON())
  415. };
  416. }
  417. isEqual(compareTo) {
  418. if (compareTo instanceof RelativeDistinguishedNames) {
  419. if (this.typesAndValues.length !== compareTo.typesAndValues.length)
  420. return false;
  421. for (const [index, typeAndValue] of this.typesAndValues.entries()) {
  422. if (typeAndValue.isEqual(compareTo.typesAndValues[index]) === false)
  423. return false;
  424. }
  425. return true;
  426. }
  427. if (compareTo instanceof ArrayBuffer) {
  428. return pvutils__namespace.isEqualBuffer(this.valueBeforeDecode, compareTo);
  429. }
  430. return false;
  431. }
  432. }
  433. RelativeDistinguishedNames.CLASS_NAME = "RelativeDistinguishedNames";
  434. const TYPE$4 = "type";
  435. const VALUE$5 = "value";
  436. function builtInStandardAttributes(parameters = {}, optional = false) {
  437. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  438. return (new asn1js__namespace.Sequence({
  439. optional,
  440. value: [
  441. new asn1js__namespace.Constructed({
  442. optional: true,
  443. idBlock: {
  444. tagClass: 2,
  445. tagNumber: 1
  446. },
  447. name: (names.country_name || EMPTY_STRING),
  448. value: [
  449. new asn1js__namespace.Choice({
  450. value: [
  451. new asn1js__namespace.NumericString(),
  452. new asn1js__namespace.PrintableString()
  453. ]
  454. })
  455. ]
  456. }),
  457. new asn1js__namespace.Constructed({
  458. optional: true,
  459. idBlock: {
  460. tagClass: 2,
  461. tagNumber: 2
  462. },
  463. name: (names.administration_domain_name || EMPTY_STRING),
  464. value: [
  465. new asn1js__namespace.Choice({
  466. value: [
  467. new asn1js__namespace.NumericString(),
  468. new asn1js__namespace.PrintableString()
  469. ]
  470. })
  471. ]
  472. }),
  473. new asn1js__namespace.Primitive({
  474. optional: true,
  475. idBlock: {
  476. tagClass: 3,
  477. tagNumber: 0
  478. },
  479. name: (names.network_address || EMPTY_STRING),
  480. isHexOnly: true
  481. }),
  482. new asn1js__namespace.Primitive({
  483. optional: true,
  484. idBlock: {
  485. tagClass: 3,
  486. tagNumber: 1
  487. },
  488. name: (names.terminal_identifier || EMPTY_STRING),
  489. isHexOnly: true
  490. }),
  491. new asn1js__namespace.Constructed({
  492. optional: true,
  493. idBlock: {
  494. tagClass: 3,
  495. tagNumber: 2
  496. },
  497. name: (names.private_domain_name || EMPTY_STRING),
  498. value: [
  499. new asn1js__namespace.Choice({
  500. value: [
  501. new asn1js__namespace.NumericString(),
  502. new asn1js__namespace.PrintableString()
  503. ]
  504. })
  505. ]
  506. }),
  507. new asn1js__namespace.Primitive({
  508. optional: true,
  509. idBlock: {
  510. tagClass: 3,
  511. tagNumber: 3
  512. },
  513. name: (names.organization_name || EMPTY_STRING),
  514. isHexOnly: true
  515. }),
  516. new asn1js__namespace.Primitive({
  517. optional: true,
  518. name: (names.numeric_user_identifier || EMPTY_STRING),
  519. idBlock: {
  520. tagClass: 3,
  521. tagNumber: 4
  522. },
  523. isHexOnly: true
  524. }),
  525. new asn1js__namespace.Constructed({
  526. optional: true,
  527. name: (names.personal_name || EMPTY_STRING),
  528. idBlock: {
  529. tagClass: 3,
  530. tagNumber: 5
  531. },
  532. value: [
  533. new asn1js__namespace.Primitive({
  534. idBlock: {
  535. tagClass: 3,
  536. tagNumber: 0
  537. },
  538. isHexOnly: true
  539. }),
  540. new asn1js__namespace.Primitive({
  541. optional: true,
  542. idBlock: {
  543. tagClass: 3,
  544. tagNumber: 1
  545. },
  546. isHexOnly: true
  547. }),
  548. new asn1js__namespace.Primitive({
  549. optional: true,
  550. idBlock: {
  551. tagClass: 3,
  552. tagNumber: 2
  553. },
  554. isHexOnly: true
  555. }),
  556. new asn1js__namespace.Primitive({
  557. optional: true,
  558. idBlock: {
  559. tagClass: 3,
  560. tagNumber: 3
  561. },
  562. isHexOnly: true
  563. })
  564. ]
  565. }),
  566. new asn1js__namespace.Constructed({
  567. optional: true,
  568. name: (names.organizational_unit_names || EMPTY_STRING),
  569. idBlock: {
  570. tagClass: 3,
  571. tagNumber: 6
  572. },
  573. value: [
  574. new asn1js__namespace.Repeated({
  575. value: new asn1js__namespace.PrintableString()
  576. })
  577. ]
  578. })
  579. ]
  580. }));
  581. }
  582. function builtInDomainDefinedAttributes(optional = false) {
  583. return (new asn1js__namespace.Sequence({
  584. optional,
  585. value: [
  586. new asn1js__namespace.PrintableString(),
  587. new asn1js__namespace.PrintableString()
  588. ]
  589. }));
  590. }
  591. function extensionAttributes(optional = false) {
  592. return (new asn1js__namespace.Set({
  593. optional,
  594. value: [
  595. new asn1js__namespace.Primitive({
  596. optional: true,
  597. idBlock: {
  598. tagClass: 3,
  599. tagNumber: 0
  600. },
  601. isHexOnly: true
  602. }),
  603. new asn1js__namespace.Constructed({
  604. optional: true,
  605. idBlock: {
  606. tagClass: 3,
  607. tagNumber: 1
  608. },
  609. value: [new asn1js__namespace.Any()]
  610. })
  611. ]
  612. }));
  613. }
  614. class GeneralName extends PkiObject {
  615. constructor(parameters = {}) {
  616. super();
  617. this.type = pvutils__namespace.getParametersValue(parameters, TYPE$4, GeneralName.defaultValues(TYPE$4));
  618. this.value = pvutils__namespace.getParametersValue(parameters, VALUE$5, GeneralName.defaultValues(VALUE$5));
  619. if (parameters.schema) {
  620. this.fromSchema(parameters.schema);
  621. }
  622. }
  623. static defaultValues(memberName) {
  624. switch (memberName) {
  625. case TYPE$4:
  626. return 9;
  627. case VALUE$5:
  628. return {};
  629. default:
  630. return super.defaultValues(memberName);
  631. }
  632. }
  633. static compareWithDefault(memberName, memberValue) {
  634. switch (memberName) {
  635. case TYPE$4:
  636. return (memberValue === GeneralName.defaultValues(memberName));
  637. case VALUE$5:
  638. return (Object.keys(memberValue).length === 0);
  639. default:
  640. return super.defaultValues(memberName);
  641. }
  642. }
  643. static schema(parameters = {}) {
  644. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  645. return (new asn1js__namespace.Choice({
  646. value: [
  647. new asn1js__namespace.Constructed({
  648. idBlock: {
  649. tagClass: 3,
  650. tagNumber: 0
  651. },
  652. name: (names.blockName || EMPTY_STRING),
  653. value: [
  654. new asn1js__namespace.ObjectIdentifier(),
  655. new asn1js__namespace.Constructed({
  656. idBlock: {
  657. tagClass: 3,
  658. tagNumber: 0
  659. },
  660. value: [new asn1js__namespace.Any()]
  661. })
  662. ]
  663. }),
  664. new asn1js__namespace.Primitive({
  665. name: (names.blockName || EMPTY_STRING),
  666. idBlock: {
  667. tagClass: 3,
  668. tagNumber: 1
  669. }
  670. }),
  671. new asn1js__namespace.Primitive({
  672. name: (names.blockName || EMPTY_STRING),
  673. idBlock: {
  674. tagClass: 3,
  675. tagNumber: 2
  676. }
  677. }),
  678. new asn1js__namespace.Constructed({
  679. idBlock: {
  680. tagClass: 3,
  681. tagNumber: 3
  682. },
  683. name: (names.blockName || EMPTY_STRING),
  684. value: [
  685. builtInStandardAttributes((names.builtInStandardAttributes || {}), false),
  686. builtInDomainDefinedAttributes(true),
  687. extensionAttributes(true)
  688. ]
  689. }),
  690. new asn1js__namespace.Constructed({
  691. idBlock: {
  692. tagClass: 3,
  693. tagNumber: 4
  694. },
  695. name: (names.blockName || EMPTY_STRING),
  696. value: [RelativeDistinguishedNames.schema(names.directoryName || {})]
  697. }),
  698. new asn1js__namespace.Constructed({
  699. idBlock: {
  700. tagClass: 3,
  701. tagNumber: 5
  702. },
  703. name: (names.blockName || EMPTY_STRING),
  704. value: [
  705. new asn1js__namespace.Constructed({
  706. optional: true,
  707. idBlock: {
  708. tagClass: 3,
  709. tagNumber: 0
  710. },
  711. value: [
  712. new asn1js__namespace.Choice({
  713. value: [
  714. new asn1js__namespace.TeletexString(),
  715. new asn1js__namespace.PrintableString(),
  716. new asn1js__namespace.UniversalString(),
  717. new asn1js__namespace.Utf8String(),
  718. new asn1js__namespace.BmpString()
  719. ]
  720. })
  721. ]
  722. }),
  723. new asn1js__namespace.Constructed({
  724. idBlock: {
  725. tagClass: 3,
  726. tagNumber: 1
  727. },
  728. value: [
  729. new asn1js__namespace.Choice({
  730. value: [
  731. new asn1js__namespace.TeletexString(),
  732. new asn1js__namespace.PrintableString(),
  733. new asn1js__namespace.UniversalString(),
  734. new asn1js__namespace.Utf8String(),
  735. new asn1js__namespace.BmpString()
  736. ]
  737. })
  738. ]
  739. })
  740. ]
  741. }),
  742. new asn1js__namespace.Primitive({
  743. name: (names.blockName || EMPTY_STRING),
  744. idBlock: {
  745. tagClass: 3,
  746. tagNumber: 6
  747. }
  748. }),
  749. new asn1js__namespace.Primitive({
  750. name: (names.blockName || EMPTY_STRING),
  751. idBlock: {
  752. tagClass: 3,
  753. tagNumber: 7
  754. }
  755. }),
  756. new asn1js__namespace.Primitive({
  757. name: (names.blockName || EMPTY_STRING),
  758. idBlock: {
  759. tagClass: 3,
  760. tagNumber: 8
  761. }
  762. })
  763. ]
  764. }));
  765. }
  766. fromSchema(schema) {
  767. pvutils__namespace.clearProps(schema, [
  768. "blockName",
  769. "otherName",
  770. "rfc822Name",
  771. "dNSName",
  772. "x400Address",
  773. "directoryName",
  774. "ediPartyName",
  775. "uniformResourceIdentifier",
  776. "iPAddress",
  777. "registeredID"
  778. ]);
  779. const asn1 = asn1js__namespace.compareSchema(schema, schema, GeneralName.schema({
  780. names: {
  781. blockName: "blockName",
  782. otherName: "otherName",
  783. rfc822Name: "rfc822Name",
  784. dNSName: "dNSName",
  785. x400Address: "x400Address",
  786. directoryName: {
  787. names: {
  788. blockName: "directoryName"
  789. }
  790. },
  791. ediPartyName: "ediPartyName",
  792. uniformResourceIdentifier: "uniformResourceIdentifier",
  793. iPAddress: "iPAddress",
  794. registeredID: "registeredID"
  795. }
  796. }));
  797. AsnError.assertSchema(asn1, this.className);
  798. this.type = asn1.result.blockName.idBlock.tagNumber;
  799. switch (this.type) {
  800. case 0:
  801. this.value = asn1.result.blockName;
  802. break;
  803. case 1:
  804. case 2:
  805. case 6:
  806. {
  807. const value = asn1.result.blockName;
  808. value.idBlock.tagClass = 1;
  809. value.idBlock.tagNumber = 22;
  810. const valueBER = value.toBER(false);
  811. const asnValue = asn1js__namespace.fromBER(valueBER);
  812. AsnError.assert(asnValue, "GeneralName value");
  813. this.value = asnValue.result.valueBlock.value;
  814. }
  815. break;
  816. case 3:
  817. this.value = asn1.result.blockName;
  818. break;
  819. case 4:
  820. this.value = new RelativeDistinguishedNames({ schema: asn1.result.directoryName });
  821. break;
  822. case 5:
  823. this.value = asn1.result.ediPartyName;
  824. break;
  825. case 7:
  826. this.value = new asn1js__namespace.OctetString({ valueHex: asn1.result.blockName.valueBlock.valueHex });
  827. break;
  828. case 8:
  829. {
  830. const value = asn1.result.blockName;
  831. value.idBlock.tagClass = 1;
  832. value.idBlock.tagNumber = 6;
  833. const valueBER = value.toBER(false);
  834. const asnValue = asn1js__namespace.fromBER(valueBER);
  835. AsnError.assert(asnValue, "GeneralName registeredID");
  836. this.value = asnValue.result.valueBlock.toString();
  837. }
  838. break;
  839. }
  840. }
  841. toSchema() {
  842. switch (this.type) {
  843. case 0:
  844. case 3:
  845. case 5:
  846. return new asn1js__namespace.Constructed({
  847. idBlock: {
  848. tagClass: 3,
  849. tagNumber: this.type
  850. },
  851. value: [
  852. this.value
  853. ]
  854. });
  855. case 1:
  856. case 2:
  857. case 6:
  858. {
  859. const value = new asn1js__namespace.IA5String({ value: this.value });
  860. value.idBlock.tagClass = 3;
  861. value.idBlock.tagNumber = this.type;
  862. return value;
  863. }
  864. case 4:
  865. return new asn1js__namespace.Constructed({
  866. idBlock: {
  867. tagClass: 3,
  868. tagNumber: 4
  869. },
  870. value: [this.value.toSchema()]
  871. });
  872. case 7:
  873. {
  874. const value = this.value;
  875. value.idBlock.tagClass = 3;
  876. value.idBlock.tagNumber = this.type;
  877. return value;
  878. }
  879. case 8:
  880. {
  881. const value = new asn1js__namespace.ObjectIdentifier({ value: this.value });
  882. value.idBlock.tagClass = 3;
  883. value.idBlock.tagNumber = this.type;
  884. return value;
  885. }
  886. default:
  887. return GeneralName.schema();
  888. }
  889. }
  890. toJSON() {
  891. const _object = {
  892. type: this.type,
  893. value: EMPTY_STRING
  894. };
  895. if ((typeof this.value) === "string")
  896. _object.value = this.value;
  897. else {
  898. try {
  899. _object.value = this.value.toJSON();
  900. }
  901. catch {
  902. }
  903. }
  904. return _object;
  905. }
  906. }
  907. GeneralName.CLASS_NAME = "GeneralName";
  908. const ACCESS_METHOD = "accessMethod";
  909. const ACCESS_LOCATION = "accessLocation";
  910. const CLEAR_PROPS$1v = [
  911. ACCESS_METHOD,
  912. ACCESS_LOCATION,
  913. ];
  914. class AccessDescription extends PkiObject {
  915. constructor(parameters = {}) {
  916. super();
  917. this.accessMethod = pvutils__namespace.getParametersValue(parameters, ACCESS_METHOD, AccessDescription.defaultValues(ACCESS_METHOD));
  918. this.accessLocation = pvutils__namespace.getParametersValue(parameters, ACCESS_LOCATION, AccessDescription.defaultValues(ACCESS_LOCATION));
  919. if (parameters.schema) {
  920. this.fromSchema(parameters.schema);
  921. }
  922. }
  923. static defaultValues(memberName) {
  924. switch (memberName) {
  925. case ACCESS_METHOD:
  926. return EMPTY_STRING;
  927. case ACCESS_LOCATION:
  928. return new GeneralName();
  929. default:
  930. return super.defaultValues(memberName);
  931. }
  932. }
  933. static schema(parameters = {}) {
  934. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  935. return (new asn1js__namespace.Sequence({
  936. name: (names.blockName || EMPTY_STRING),
  937. value: [
  938. new asn1js__namespace.ObjectIdentifier({ name: (names.accessMethod || EMPTY_STRING) }),
  939. GeneralName.schema(names.accessLocation || {})
  940. ]
  941. }));
  942. }
  943. fromSchema(schema) {
  944. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1v);
  945. const asn1 = asn1js__namespace.compareSchema(schema, schema, AccessDescription.schema({
  946. names: {
  947. accessMethod: ACCESS_METHOD,
  948. accessLocation: {
  949. names: {
  950. blockName: ACCESS_LOCATION
  951. }
  952. }
  953. }
  954. }));
  955. AsnError.assertSchema(asn1, this.className);
  956. this.accessMethod = asn1.result.accessMethod.valueBlock.toString();
  957. this.accessLocation = new GeneralName({ schema: asn1.result.accessLocation });
  958. }
  959. toSchema() {
  960. return (new asn1js__namespace.Sequence({
  961. value: [
  962. new asn1js__namespace.ObjectIdentifier({ value: this.accessMethod }),
  963. this.accessLocation.toSchema()
  964. ]
  965. }));
  966. }
  967. toJSON() {
  968. return {
  969. accessMethod: this.accessMethod,
  970. accessLocation: this.accessLocation.toJSON()
  971. };
  972. }
  973. }
  974. AccessDescription.CLASS_NAME = "AccessDescription";
  975. const SECONDS = "seconds";
  976. const MILLIS = "millis";
  977. const MICROS = "micros";
  978. class Accuracy extends PkiObject {
  979. constructor(parameters = {}) {
  980. super();
  981. if (SECONDS in parameters) {
  982. this.seconds = pvutils__namespace.getParametersValue(parameters, SECONDS, Accuracy.defaultValues(SECONDS));
  983. }
  984. if (MILLIS in parameters) {
  985. this.millis = pvutils__namespace.getParametersValue(parameters, MILLIS, Accuracy.defaultValues(MILLIS));
  986. }
  987. if (MICROS in parameters) {
  988. this.micros = pvutils__namespace.getParametersValue(parameters, MICROS, Accuracy.defaultValues(MICROS));
  989. }
  990. if (parameters.schema) {
  991. this.fromSchema(parameters.schema);
  992. }
  993. }
  994. static defaultValues(memberName) {
  995. switch (memberName) {
  996. case SECONDS:
  997. case MILLIS:
  998. case MICROS:
  999. return 0;
  1000. default:
  1001. return super.defaultValues(memberName);
  1002. }
  1003. }
  1004. static compareWithDefault(memberName, memberValue) {
  1005. switch (memberName) {
  1006. case SECONDS:
  1007. case MILLIS:
  1008. case MICROS:
  1009. return (memberValue === Accuracy.defaultValues(memberName));
  1010. default:
  1011. return super.defaultValues(memberName);
  1012. }
  1013. }
  1014. static schema(parameters = {}) {
  1015. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  1016. return (new asn1js__namespace.Sequence({
  1017. name: (names.blockName || EMPTY_STRING),
  1018. optional: true,
  1019. value: [
  1020. new asn1js__namespace.Integer({
  1021. optional: true,
  1022. name: (names.seconds || EMPTY_STRING)
  1023. }),
  1024. new asn1js__namespace.Primitive({
  1025. name: (names.millis || EMPTY_STRING),
  1026. optional: true,
  1027. idBlock: {
  1028. tagClass: 3,
  1029. tagNumber: 0
  1030. }
  1031. }),
  1032. new asn1js__namespace.Primitive({
  1033. name: (names.micros || EMPTY_STRING),
  1034. optional: true,
  1035. idBlock: {
  1036. tagClass: 3,
  1037. tagNumber: 1
  1038. }
  1039. })
  1040. ]
  1041. }));
  1042. }
  1043. fromSchema(schema) {
  1044. pvutils__namespace.clearProps(schema, [
  1045. SECONDS,
  1046. MILLIS,
  1047. MICROS,
  1048. ]);
  1049. const asn1 = asn1js__namespace.compareSchema(schema, schema, Accuracy.schema({
  1050. names: {
  1051. seconds: SECONDS,
  1052. millis: MILLIS,
  1053. micros: MICROS,
  1054. }
  1055. }));
  1056. AsnError.assertSchema(asn1, this.className);
  1057. if ("seconds" in asn1.result) {
  1058. this.seconds = asn1.result.seconds.valueBlock.valueDec;
  1059. }
  1060. if ("millis" in asn1.result) {
  1061. const intMillis = new asn1js__namespace.Integer({ valueHex: asn1.result.millis.valueBlock.valueHex });
  1062. this.millis = intMillis.valueBlock.valueDec;
  1063. }
  1064. if ("micros" in asn1.result) {
  1065. const intMicros = new asn1js__namespace.Integer({ valueHex: asn1.result.micros.valueBlock.valueHex });
  1066. this.micros = intMicros.valueBlock.valueDec;
  1067. }
  1068. }
  1069. toSchema() {
  1070. const outputArray = [];
  1071. if (this.seconds !== undefined)
  1072. outputArray.push(new asn1js__namespace.Integer({ value: this.seconds }));
  1073. if (this.millis !== undefined) {
  1074. const intMillis = new asn1js__namespace.Integer({ value: this.millis });
  1075. outputArray.push(new asn1js__namespace.Primitive({
  1076. idBlock: {
  1077. tagClass: 3,
  1078. tagNumber: 0
  1079. },
  1080. valueHex: intMillis.valueBlock.valueHexView
  1081. }));
  1082. }
  1083. if (this.micros !== undefined) {
  1084. const intMicros = new asn1js__namespace.Integer({ value: this.micros });
  1085. outputArray.push(new asn1js__namespace.Primitive({
  1086. idBlock: {
  1087. tagClass: 3,
  1088. tagNumber: 1
  1089. },
  1090. valueHex: intMicros.valueBlock.valueHexView
  1091. }));
  1092. }
  1093. return (new asn1js__namespace.Sequence({
  1094. value: outputArray
  1095. }));
  1096. }
  1097. toJSON() {
  1098. const _object = {};
  1099. if (this.seconds !== undefined)
  1100. _object.seconds = this.seconds;
  1101. if (this.millis !== undefined)
  1102. _object.millis = this.millis;
  1103. if (this.micros !== undefined)
  1104. _object.micros = this.micros;
  1105. return _object;
  1106. }
  1107. }
  1108. Accuracy.CLASS_NAME = "Accuracy";
  1109. const ALGORITHM_ID = "algorithmId";
  1110. const ALGORITHM_PARAMS = "algorithmParams";
  1111. const ALGORITHM$2 = "algorithm";
  1112. const PARAMS = "params";
  1113. const CLEAR_PROPS$1u = [
  1114. ALGORITHM$2,
  1115. PARAMS
  1116. ];
  1117. class AlgorithmIdentifier extends PkiObject {
  1118. constructor(parameters = {}) {
  1119. super();
  1120. this.algorithmId = pvutils__namespace.getParametersValue(parameters, ALGORITHM_ID, AlgorithmIdentifier.defaultValues(ALGORITHM_ID));
  1121. if (ALGORITHM_PARAMS in parameters) {
  1122. this.algorithmParams = pvutils__namespace.getParametersValue(parameters, ALGORITHM_PARAMS, AlgorithmIdentifier.defaultValues(ALGORITHM_PARAMS));
  1123. }
  1124. if (parameters.schema) {
  1125. this.fromSchema(parameters.schema);
  1126. }
  1127. }
  1128. static defaultValues(memberName) {
  1129. switch (memberName) {
  1130. case ALGORITHM_ID:
  1131. return EMPTY_STRING;
  1132. case ALGORITHM_PARAMS:
  1133. return new asn1js__namespace.Any();
  1134. default:
  1135. return super.defaultValues(memberName);
  1136. }
  1137. }
  1138. static compareWithDefault(memberName, memberValue) {
  1139. switch (memberName) {
  1140. case ALGORITHM_ID:
  1141. return (memberValue === EMPTY_STRING);
  1142. case ALGORITHM_PARAMS:
  1143. return (memberValue instanceof asn1js__namespace.Any);
  1144. default:
  1145. return super.defaultValues(memberName);
  1146. }
  1147. }
  1148. static schema(parameters = {}) {
  1149. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  1150. return (new asn1js__namespace.Sequence({
  1151. name: (names.blockName || EMPTY_STRING),
  1152. optional: (names.optional || false),
  1153. value: [
  1154. new asn1js__namespace.ObjectIdentifier({ name: (names.algorithmIdentifier || EMPTY_STRING) }),
  1155. new asn1js__namespace.Any({ name: (names.algorithmParams || EMPTY_STRING), optional: true })
  1156. ]
  1157. }));
  1158. }
  1159. fromSchema(schema) {
  1160. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1u);
  1161. const asn1 = asn1js__namespace.compareSchema(schema, schema, AlgorithmIdentifier.schema({
  1162. names: {
  1163. algorithmIdentifier: ALGORITHM$2,
  1164. algorithmParams: PARAMS
  1165. }
  1166. }));
  1167. AsnError.assertSchema(asn1, this.className);
  1168. this.algorithmId = asn1.result.algorithm.valueBlock.toString();
  1169. if (PARAMS in asn1.result) {
  1170. this.algorithmParams = asn1.result.params;
  1171. }
  1172. }
  1173. toSchema() {
  1174. const outputArray = [];
  1175. outputArray.push(new asn1js__namespace.ObjectIdentifier({ value: this.algorithmId }));
  1176. if (this.algorithmParams && !(this.algorithmParams instanceof asn1js__namespace.Any)) {
  1177. outputArray.push(this.algorithmParams);
  1178. }
  1179. return (new asn1js__namespace.Sequence({
  1180. value: outputArray
  1181. }));
  1182. }
  1183. toJSON() {
  1184. const object = {
  1185. algorithmId: this.algorithmId
  1186. };
  1187. if (this.algorithmParams && !(this.algorithmParams instanceof asn1js__namespace.Any)) {
  1188. object.algorithmParams = this.algorithmParams.toJSON();
  1189. }
  1190. return object;
  1191. }
  1192. isEqual(algorithmIdentifier) {
  1193. if (!(algorithmIdentifier instanceof AlgorithmIdentifier)) {
  1194. return false;
  1195. }
  1196. if (this.algorithmId !== algorithmIdentifier.algorithmId) {
  1197. return false;
  1198. }
  1199. if (this.algorithmParams) {
  1200. if (algorithmIdentifier.algorithmParams) {
  1201. return JSON.stringify(this.algorithmParams) === JSON.stringify(algorithmIdentifier.algorithmParams);
  1202. }
  1203. return false;
  1204. }
  1205. if (algorithmIdentifier.algorithmParams) {
  1206. return false;
  1207. }
  1208. return true;
  1209. }
  1210. }
  1211. AlgorithmIdentifier.CLASS_NAME = "AlgorithmIdentifier";
  1212. const ALT_NAMES = "altNames";
  1213. const CLEAR_PROPS$1t = [
  1214. ALT_NAMES
  1215. ];
  1216. class AltName extends PkiObject {
  1217. constructor(parameters = {}) {
  1218. super();
  1219. this.altNames = pvutils__namespace.getParametersValue(parameters, ALT_NAMES, AltName.defaultValues(ALT_NAMES));
  1220. if (parameters.schema) {
  1221. this.fromSchema(parameters.schema);
  1222. }
  1223. }
  1224. static defaultValues(memberName) {
  1225. switch (memberName) {
  1226. case ALT_NAMES:
  1227. return [];
  1228. default:
  1229. return super.defaultValues(memberName);
  1230. }
  1231. }
  1232. static schema(parameters = {}) {
  1233. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  1234. return (new asn1js__namespace.Sequence({
  1235. name: (names.blockName || EMPTY_STRING),
  1236. value: [
  1237. new asn1js__namespace.Repeated({
  1238. name: (names.altNames || EMPTY_STRING),
  1239. value: GeneralName.schema()
  1240. })
  1241. ]
  1242. }));
  1243. }
  1244. fromSchema(schema) {
  1245. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1t);
  1246. const asn1 = asn1js__namespace.compareSchema(schema, schema, AltName.schema({
  1247. names: {
  1248. altNames: ALT_NAMES
  1249. }
  1250. }));
  1251. AsnError.assertSchema(asn1, this.className);
  1252. if (ALT_NAMES in asn1.result) {
  1253. this.altNames = Array.from(asn1.result.altNames, element => new GeneralName({ schema: element }));
  1254. }
  1255. }
  1256. toSchema() {
  1257. return (new asn1js__namespace.Sequence({
  1258. value: Array.from(this.altNames, o => o.toSchema())
  1259. }));
  1260. }
  1261. toJSON() {
  1262. return {
  1263. altNames: Array.from(this.altNames, o => o.toJSON())
  1264. };
  1265. }
  1266. }
  1267. AltName.CLASS_NAME = "AltName";
  1268. const TYPE$3 = "type";
  1269. const VALUES$1 = "values";
  1270. const CLEAR_PROPS$1s = [
  1271. TYPE$3,
  1272. VALUES$1
  1273. ];
  1274. class Attribute extends PkiObject {
  1275. constructor(parameters = {}) {
  1276. super();
  1277. this.type = pvutils__namespace.getParametersValue(parameters, TYPE$3, Attribute.defaultValues(TYPE$3));
  1278. this.values = pvutils__namespace.getParametersValue(parameters, VALUES$1, Attribute.defaultValues(VALUES$1));
  1279. if (parameters.schema) {
  1280. this.fromSchema(parameters.schema);
  1281. }
  1282. }
  1283. static defaultValues(memberName) {
  1284. switch (memberName) {
  1285. case TYPE$3:
  1286. return EMPTY_STRING;
  1287. case VALUES$1:
  1288. return [];
  1289. default:
  1290. return super.defaultValues(memberName);
  1291. }
  1292. }
  1293. static compareWithDefault(memberName, memberValue) {
  1294. switch (memberName) {
  1295. case TYPE$3:
  1296. return (memberValue === EMPTY_STRING);
  1297. case VALUES$1:
  1298. return (memberValue.length === 0);
  1299. default:
  1300. return super.defaultValues(memberName);
  1301. }
  1302. }
  1303. static schema(parameters = {}) {
  1304. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  1305. return (new asn1js__namespace.Sequence({
  1306. name: (names.blockName || EMPTY_STRING),
  1307. value: [
  1308. new asn1js__namespace.ObjectIdentifier({ name: (names.type || EMPTY_STRING) }),
  1309. new asn1js__namespace.Set({
  1310. name: (names.setName || EMPTY_STRING),
  1311. value: [
  1312. new asn1js__namespace.Repeated({
  1313. name: (names.values || EMPTY_STRING),
  1314. value: new asn1js__namespace.Any()
  1315. })
  1316. ]
  1317. })
  1318. ]
  1319. }));
  1320. }
  1321. fromSchema(schema) {
  1322. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1s);
  1323. const asn1 = asn1js__namespace.compareSchema(schema, schema, Attribute.schema({
  1324. names: {
  1325. type: TYPE$3,
  1326. values: VALUES$1
  1327. }
  1328. }));
  1329. AsnError.assertSchema(asn1, this.className);
  1330. this.type = asn1.result.type.valueBlock.toString();
  1331. this.values = asn1.result.values;
  1332. }
  1333. toSchema() {
  1334. return (new asn1js__namespace.Sequence({
  1335. value: [
  1336. new asn1js__namespace.ObjectIdentifier({ value: this.type }),
  1337. new asn1js__namespace.Set({
  1338. value: this.values
  1339. })
  1340. ]
  1341. }));
  1342. }
  1343. toJSON() {
  1344. return {
  1345. type: this.type,
  1346. values: Array.from(this.values, o => o.toJSON())
  1347. };
  1348. }
  1349. }
  1350. Attribute.CLASS_NAME = "Attribute";
  1351. const NOT_BEFORE_TIME = "notBeforeTime";
  1352. const NOT_AFTER_TIME = "notAfterTime";
  1353. const CLEAR_PROPS$1r = [
  1354. NOT_BEFORE_TIME,
  1355. NOT_AFTER_TIME,
  1356. ];
  1357. class AttCertValidityPeriod extends PkiObject {
  1358. constructor(parameters = {}) {
  1359. super();
  1360. this.notBeforeTime = pvutils__namespace.getParametersValue(parameters, NOT_BEFORE_TIME, AttCertValidityPeriod.defaultValues(NOT_BEFORE_TIME));
  1361. this.notAfterTime = pvutils__namespace.getParametersValue(parameters, NOT_AFTER_TIME, AttCertValidityPeriod.defaultValues(NOT_AFTER_TIME));
  1362. if (parameters.schema) {
  1363. this.fromSchema(parameters.schema);
  1364. }
  1365. }
  1366. static defaultValues(memberName) {
  1367. switch (memberName) {
  1368. case NOT_BEFORE_TIME:
  1369. case NOT_AFTER_TIME:
  1370. return new Date(0, 0, 0);
  1371. default:
  1372. return super.defaultValues(memberName);
  1373. }
  1374. }
  1375. static schema(parameters = {}) {
  1376. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  1377. return (new asn1js__namespace.Sequence({
  1378. name: (names.blockName || EMPTY_STRING),
  1379. value: [
  1380. new asn1js__namespace.GeneralizedTime({ name: (names.notBeforeTime || EMPTY_STRING) }),
  1381. new asn1js__namespace.GeneralizedTime({ name: (names.notAfterTime || EMPTY_STRING) })
  1382. ]
  1383. }));
  1384. }
  1385. fromSchema(schema) {
  1386. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1r);
  1387. const asn1 = asn1js__namespace.compareSchema(schema, schema, AttCertValidityPeriod.schema({
  1388. names: {
  1389. notBeforeTime: NOT_BEFORE_TIME,
  1390. notAfterTime: NOT_AFTER_TIME
  1391. }
  1392. }));
  1393. AsnError.assertSchema(asn1, this.className);
  1394. this.notBeforeTime = asn1.result.notBeforeTime.toDate();
  1395. this.notAfterTime = asn1.result.notAfterTime.toDate();
  1396. }
  1397. toSchema() {
  1398. return (new asn1js__namespace.Sequence({
  1399. value: [
  1400. new asn1js__namespace.GeneralizedTime({ valueDate: this.notBeforeTime }),
  1401. new asn1js__namespace.GeneralizedTime({ valueDate: this.notAfterTime }),
  1402. ]
  1403. }));
  1404. }
  1405. toJSON() {
  1406. return {
  1407. notBeforeTime: this.notBeforeTime,
  1408. notAfterTime: this.notAfterTime
  1409. };
  1410. }
  1411. }
  1412. AttCertValidityPeriod.CLASS_NAME = "AttCertValidityPeriod";
  1413. const NAMES = "names";
  1414. const GENERAL_NAMES = "generalNames";
  1415. class GeneralNames extends PkiObject {
  1416. constructor(parameters = {}) {
  1417. super();
  1418. this.names = pvutils__namespace.getParametersValue(parameters, NAMES, GeneralNames.defaultValues(NAMES));
  1419. if (parameters.schema) {
  1420. this.fromSchema(parameters.schema);
  1421. }
  1422. }
  1423. static defaultValues(memberName) {
  1424. switch (memberName) {
  1425. case "names":
  1426. return [];
  1427. default:
  1428. return super.defaultValues(memberName);
  1429. }
  1430. }
  1431. static schema(parameters = {}, optional = false) {
  1432. const names = pvutils__namespace.getParametersValue(parameters, NAMES, {});
  1433. return (new asn1js__namespace.Sequence({
  1434. optional,
  1435. name: (names.blockName || EMPTY_STRING),
  1436. value: [
  1437. new asn1js__namespace.Repeated({
  1438. name: (names.generalNames || EMPTY_STRING),
  1439. value: GeneralName.schema()
  1440. })
  1441. ]
  1442. }));
  1443. }
  1444. fromSchema(schema) {
  1445. pvutils__namespace.clearProps(schema, [
  1446. NAMES,
  1447. GENERAL_NAMES
  1448. ]);
  1449. const asn1 = asn1js__namespace.compareSchema(schema, schema, GeneralNames.schema({
  1450. names: {
  1451. blockName: NAMES,
  1452. generalNames: GENERAL_NAMES
  1453. }
  1454. }));
  1455. AsnError.assertSchema(asn1, this.className);
  1456. this.names = Array.from(asn1.result.generalNames, element => new GeneralName({ schema: element }));
  1457. }
  1458. toSchema() {
  1459. return (new asn1js__namespace.Sequence({
  1460. value: Array.from(this.names, o => o.toSchema())
  1461. }));
  1462. }
  1463. toJSON() {
  1464. return {
  1465. names: Array.from(this.names, o => o.toJSON())
  1466. };
  1467. }
  1468. }
  1469. GeneralNames.CLASS_NAME = "GeneralNames";
  1470. const id_SubjectDirectoryAttributes = "2.5.29.9";
  1471. const id_SubjectKeyIdentifier = "2.5.29.14";
  1472. const id_KeyUsage = "2.5.29.15";
  1473. const id_PrivateKeyUsagePeriod = "2.5.29.16";
  1474. const id_SubjectAltName = "2.5.29.17";
  1475. const id_IssuerAltName = "2.5.29.18";
  1476. const id_BasicConstraints = "2.5.29.19";
  1477. const id_CRLNumber = "2.5.29.20";
  1478. const id_BaseCRLNumber = "2.5.29.27";
  1479. const id_CRLReason = "2.5.29.21";
  1480. const id_InvalidityDate = "2.5.29.24";
  1481. const id_IssuingDistributionPoint = "2.5.29.28";
  1482. const id_CertificateIssuer = "2.5.29.29";
  1483. const id_NameConstraints = "2.5.29.30";
  1484. const id_CRLDistributionPoints = "2.5.29.31";
  1485. const id_FreshestCRL = "2.5.29.46";
  1486. const id_CertificatePolicies = "2.5.29.32";
  1487. const id_AnyPolicy = "2.5.29.32.0";
  1488. const id_MicrosoftAppPolicies = "1.3.6.1.4.1.311.21.10";
  1489. const id_PolicyMappings = "2.5.29.33";
  1490. const id_AuthorityKeyIdentifier = "2.5.29.35";
  1491. const id_PolicyConstraints = "2.5.29.36";
  1492. const id_ExtKeyUsage = "2.5.29.37";
  1493. const id_InhibitAnyPolicy = "2.5.29.54";
  1494. const id_AuthorityInfoAccess = "1.3.6.1.5.5.7.1.1";
  1495. const id_SubjectInfoAccess = "1.3.6.1.5.5.7.1.11";
  1496. const id_SignedCertificateTimestampList = "1.3.6.1.4.1.11129.2.4.2";
  1497. const id_MicrosoftCertTemplateV1 = "1.3.6.1.4.1.311.20.2";
  1498. const id_MicrosoftPrevCaCertHash = "1.3.6.1.4.1.311.21.2";
  1499. const id_MicrosoftCertTemplateV2 = "1.3.6.1.4.1.311.21.7";
  1500. const id_MicrosoftCaVersion = "1.3.6.1.4.1.311.21.1";
  1501. const id_QCStatements = "1.3.6.1.5.5.7.1.3";
  1502. const id_ContentType_Data = "1.2.840.113549.1.7.1";
  1503. const id_ContentType_SignedData = "1.2.840.113549.1.7.2";
  1504. const id_ContentType_EnvelopedData = "1.2.840.113549.1.7.3";
  1505. const id_ContentType_EncryptedData = "1.2.840.113549.1.7.6";
  1506. const id_eContentType_TSTInfo = "1.2.840.113549.1.9.16.1.4";
  1507. const id_CertBag_X509Certificate = "1.2.840.113549.1.9.22.1";
  1508. const id_CertBag_SDSICertificate = "1.2.840.113549.1.9.22.2";
  1509. const id_CertBag_AttributeCertificate = "1.2.840.113549.1.9.22.3";
  1510. const id_CRLBag_X509CRL = "1.2.840.113549.1.9.23.1";
  1511. const id_pkix = "1.3.6.1.5.5.7";
  1512. const id_ad = `${id_pkix}.48`;
  1513. const id_PKIX_OCSP_Basic = `${id_ad}.1.1`;
  1514. const id_ad_caIssuers = `${id_ad}.2`;
  1515. const id_ad_ocsp = `${id_ad}.1`;
  1516. const id_sha1 = "1.3.14.3.2.26";
  1517. const id_sha256 = "2.16.840.1.101.3.4.2.1";
  1518. const id_sha384 = "2.16.840.1.101.3.4.2.2";
  1519. const id_sha512 = "2.16.840.1.101.3.4.2.3";
  1520. const KEY_IDENTIFIER$1 = "keyIdentifier";
  1521. const AUTHORITY_CERT_ISSUER = "authorityCertIssuer";
  1522. const AUTHORITY_CERT_SERIAL_NUMBER = "authorityCertSerialNumber";
  1523. const CLEAR_PROPS$1q = [
  1524. KEY_IDENTIFIER$1,
  1525. AUTHORITY_CERT_ISSUER,
  1526. AUTHORITY_CERT_SERIAL_NUMBER,
  1527. ];
  1528. class AuthorityKeyIdentifier extends PkiObject {
  1529. constructor(parameters = {}) {
  1530. super();
  1531. if (KEY_IDENTIFIER$1 in parameters) {
  1532. this.keyIdentifier = pvutils__namespace.getParametersValue(parameters, KEY_IDENTIFIER$1, AuthorityKeyIdentifier.defaultValues(KEY_IDENTIFIER$1));
  1533. }
  1534. if (AUTHORITY_CERT_ISSUER in parameters) {
  1535. this.authorityCertIssuer = pvutils__namespace.getParametersValue(parameters, AUTHORITY_CERT_ISSUER, AuthorityKeyIdentifier.defaultValues(AUTHORITY_CERT_ISSUER));
  1536. }
  1537. if (AUTHORITY_CERT_SERIAL_NUMBER in parameters) {
  1538. this.authorityCertSerialNumber = pvutils__namespace.getParametersValue(parameters, AUTHORITY_CERT_SERIAL_NUMBER, AuthorityKeyIdentifier.defaultValues(AUTHORITY_CERT_SERIAL_NUMBER));
  1539. }
  1540. if (parameters.schema) {
  1541. this.fromSchema(parameters.schema);
  1542. }
  1543. }
  1544. static defaultValues(memberName) {
  1545. switch (memberName) {
  1546. case KEY_IDENTIFIER$1:
  1547. return new asn1js__namespace.OctetString();
  1548. case AUTHORITY_CERT_ISSUER:
  1549. return [];
  1550. case AUTHORITY_CERT_SERIAL_NUMBER:
  1551. return new asn1js__namespace.Integer();
  1552. default:
  1553. return super.defaultValues(memberName);
  1554. }
  1555. }
  1556. static schema(parameters = {}) {
  1557. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  1558. return (new asn1js__namespace.Sequence({
  1559. name: (names.blockName || EMPTY_STRING),
  1560. value: [
  1561. new asn1js__namespace.Primitive({
  1562. name: (names.keyIdentifier || EMPTY_STRING),
  1563. optional: true,
  1564. idBlock: {
  1565. tagClass: 3,
  1566. tagNumber: 0
  1567. }
  1568. }),
  1569. new asn1js__namespace.Constructed({
  1570. optional: true,
  1571. idBlock: {
  1572. tagClass: 3,
  1573. tagNumber: 1
  1574. },
  1575. value: [
  1576. new asn1js__namespace.Repeated({
  1577. name: (names.authorityCertIssuer || EMPTY_STRING),
  1578. value: GeneralName.schema()
  1579. })
  1580. ]
  1581. }),
  1582. new asn1js__namespace.Primitive({
  1583. name: (names.authorityCertSerialNumber || EMPTY_STRING),
  1584. optional: true,
  1585. idBlock: {
  1586. tagClass: 3,
  1587. tagNumber: 2
  1588. }
  1589. })
  1590. ]
  1591. }));
  1592. }
  1593. fromSchema(schema) {
  1594. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1q);
  1595. const asn1 = asn1js__namespace.compareSchema(schema, schema, AuthorityKeyIdentifier.schema({
  1596. names: {
  1597. keyIdentifier: KEY_IDENTIFIER$1,
  1598. authorityCertIssuer: AUTHORITY_CERT_ISSUER,
  1599. authorityCertSerialNumber: AUTHORITY_CERT_SERIAL_NUMBER
  1600. }
  1601. }));
  1602. AsnError.assertSchema(asn1, this.className);
  1603. if (KEY_IDENTIFIER$1 in asn1.result)
  1604. this.keyIdentifier = new asn1js__namespace.OctetString({ valueHex: asn1.result.keyIdentifier.valueBlock.valueHex });
  1605. if (AUTHORITY_CERT_ISSUER in asn1.result)
  1606. this.authorityCertIssuer = Array.from(asn1.result.authorityCertIssuer, o => new GeneralName({ schema: o }));
  1607. if (AUTHORITY_CERT_SERIAL_NUMBER in asn1.result)
  1608. this.authorityCertSerialNumber = new asn1js__namespace.Integer({ valueHex: asn1.result.authorityCertSerialNumber.valueBlock.valueHex });
  1609. }
  1610. toSchema() {
  1611. const outputArray = [];
  1612. if (this.keyIdentifier) {
  1613. outputArray.push(new asn1js__namespace.Primitive({
  1614. idBlock: {
  1615. tagClass: 3,
  1616. tagNumber: 0
  1617. },
  1618. valueHex: this.keyIdentifier.valueBlock.valueHexView
  1619. }));
  1620. }
  1621. if (this.authorityCertIssuer) {
  1622. outputArray.push(new asn1js__namespace.Constructed({
  1623. idBlock: {
  1624. tagClass: 3,
  1625. tagNumber: 1
  1626. },
  1627. value: Array.from(this.authorityCertIssuer, o => o.toSchema())
  1628. }));
  1629. }
  1630. if (this.authorityCertSerialNumber) {
  1631. outputArray.push(new asn1js__namespace.Primitive({
  1632. idBlock: {
  1633. tagClass: 3,
  1634. tagNumber: 2
  1635. },
  1636. valueHex: this.authorityCertSerialNumber.valueBlock.valueHexView
  1637. }));
  1638. }
  1639. return (new asn1js__namespace.Sequence({
  1640. value: outputArray
  1641. }));
  1642. }
  1643. toJSON() {
  1644. const object = {};
  1645. if (this.keyIdentifier) {
  1646. object.keyIdentifier = this.keyIdentifier.toJSON();
  1647. }
  1648. if (this.authorityCertIssuer) {
  1649. object.authorityCertIssuer = Array.from(this.authorityCertIssuer, o => o.toJSON());
  1650. }
  1651. if (this.authorityCertSerialNumber) {
  1652. object.authorityCertSerialNumber = this.authorityCertSerialNumber.toJSON();
  1653. }
  1654. return object;
  1655. }
  1656. }
  1657. AuthorityKeyIdentifier.CLASS_NAME = "AuthorityKeyIdentifier";
  1658. const PATH_LENGTH_CONSTRAINT = "pathLenConstraint";
  1659. const CA = "cA";
  1660. class BasicConstraints extends PkiObject {
  1661. constructor(parameters = {}) {
  1662. super();
  1663. this.cA = pvutils__namespace.getParametersValue(parameters, CA, false);
  1664. if (PATH_LENGTH_CONSTRAINT in parameters) {
  1665. this.pathLenConstraint = pvutils__namespace.getParametersValue(parameters, PATH_LENGTH_CONSTRAINT, 0);
  1666. }
  1667. if (parameters.schema) {
  1668. this.fromSchema(parameters.schema);
  1669. }
  1670. }
  1671. static defaultValues(memberName) {
  1672. switch (memberName) {
  1673. case CA:
  1674. return false;
  1675. default:
  1676. return super.defaultValues(memberName);
  1677. }
  1678. }
  1679. static schema(parameters = {}) {
  1680. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  1681. return (new asn1js__namespace.Sequence({
  1682. name: (names.blockName || EMPTY_STRING),
  1683. value: [
  1684. new asn1js__namespace.Boolean({
  1685. optional: true,
  1686. name: (names.cA || EMPTY_STRING)
  1687. }),
  1688. new asn1js__namespace.Integer({
  1689. optional: true,
  1690. name: (names.pathLenConstraint || EMPTY_STRING)
  1691. })
  1692. ]
  1693. }));
  1694. }
  1695. fromSchema(schema) {
  1696. pvutils__namespace.clearProps(schema, [
  1697. CA,
  1698. PATH_LENGTH_CONSTRAINT
  1699. ]);
  1700. const asn1 = asn1js__namespace.compareSchema(schema, schema, BasicConstraints.schema({
  1701. names: {
  1702. cA: CA,
  1703. pathLenConstraint: PATH_LENGTH_CONSTRAINT
  1704. }
  1705. }));
  1706. AsnError.assertSchema(asn1, this.className);
  1707. if (CA in asn1.result) {
  1708. this.cA = asn1.result.cA.valueBlock.value;
  1709. }
  1710. if (PATH_LENGTH_CONSTRAINT in asn1.result) {
  1711. if (asn1.result.pathLenConstraint.valueBlock.isHexOnly) {
  1712. this.pathLenConstraint = asn1.result.pathLenConstraint;
  1713. }
  1714. else {
  1715. this.pathLenConstraint = asn1.result.pathLenConstraint.valueBlock.valueDec;
  1716. }
  1717. }
  1718. }
  1719. toSchema() {
  1720. const outputArray = [];
  1721. if (this.cA !== BasicConstraints.defaultValues(CA))
  1722. outputArray.push(new asn1js__namespace.Boolean({ value: this.cA }));
  1723. if (PATH_LENGTH_CONSTRAINT in this) {
  1724. if (this.pathLenConstraint instanceof asn1js__namespace.Integer) {
  1725. outputArray.push(this.pathLenConstraint);
  1726. }
  1727. else {
  1728. outputArray.push(new asn1js__namespace.Integer({ value: this.pathLenConstraint }));
  1729. }
  1730. }
  1731. return (new asn1js__namespace.Sequence({
  1732. value: outputArray
  1733. }));
  1734. }
  1735. toJSON() {
  1736. const object = {};
  1737. if (this.cA !== BasicConstraints.defaultValues(CA)) {
  1738. object.cA = this.cA;
  1739. }
  1740. if (PATH_LENGTH_CONSTRAINT in this) {
  1741. if (this.pathLenConstraint instanceof asn1js__namespace.Integer) {
  1742. object.pathLenConstraint = this.pathLenConstraint.toJSON();
  1743. }
  1744. else {
  1745. object.pathLenConstraint = this.pathLenConstraint;
  1746. }
  1747. }
  1748. return object;
  1749. }
  1750. }
  1751. BasicConstraints.CLASS_NAME = "BasicConstraints";
  1752. const CERTIFICATE_INDEX = "certificateIndex";
  1753. const KEY_INDEX = "keyIndex";
  1754. class CAVersion extends PkiObject {
  1755. constructor(parameters = {}) {
  1756. super();
  1757. this.certificateIndex = pvutils__namespace.getParametersValue(parameters, CERTIFICATE_INDEX, CAVersion.defaultValues(CERTIFICATE_INDEX));
  1758. this.keyIndex = pvutils__namespace.getParametersValue(parameters, KEY_INDEX, CAVersion.defaultValues(KEY_INDEX));
  1759. if (parameters.schema) {
  1760. this.fromSchema(parameters.schema);
  1761. }
  1762. }
  1763. static defaultValues(memberName) {
  1764. switch (memberName) {
  1765. case CERTIFICATE_INDEX:
  1766. case KEY_INDEX:
  1767. return 0;
  1768. default:
  1769. return super.defaultValues(memberName);
  1770. }
  1771. }
  1772. static schema() {
  1773. return (new asn1js__namespace.Integer());
  1774. }
  1775. fromSchema(schema) {
  1776. if (schema.constructor.blockName() !== asn1js__namespace.Integer.blockName()) {
  1777. throw new Error("Object's schema was not verified against input data for CAVersion");
  1778. }
  1779. let value = schema.valueBlock.valueHex.slice(0);
  1780. const valueView = new Uint8Array(value);
  1781. switch (true) {
  1782. case (value.byteLength < 4):
  1783. {
  1784. const tempValue = new ArrayBuffer(4);
  1785. const tempValueView = new Uint8Array(tempValue);
  1786. tempValueView.set(valueView, 4 - value.byteLength);
  1787. value = tempValue.slice(0);
  1788. }
  1789. break;
  1790. case (value.byteLength > 4):
  1791. {
  1792. const tempValue = new ArrayBuffer(4);
  1793. const tempValueView = new Uint8Array(tempValue);
  1794. tempValueView.set(valueView.slice(0, 4));
  1795. value = tempValue.slice(0);
  1796. }
  1797. break;
  1798. }
  1799. const keyIndexBuffer = value.slice(0, 2);
  1800. const keyIndexView8 = new Uint8Array(keyIndexBuffer);
  1801. let temp = keyIndexView8[0];
  1802. keyIndexView8[0] = keyIndexView8[1];
  1803. keyIndexView8[1] = temp;
  1804. const keyIndexView16 = new Uint16Array(keyIndexBuffer);
  1805. this.keyIndex = keyIndexView16[0];
  1806. const certificateIndexBuffer = value.slice(2);
  1807. const certificateIndexView8 = new Uint8Array(certificateIndexBuffer);
  1808. temp = certificateIndexView8[0];
  1809. certificateIndexView8[0] = certificateIndexView8[1];
  1810. certificateIndexView8[1] = temp;
  1811. const certificateIndexView16 = new Uint16Array(certificateIndexBuffer);
  1812. this.certificateIndex = certificateIndexView16[0];
  1813. }
  1814. toSchema() {
  1815. const certificateIndexBuffer = new ArrayBuffer(2);
  1816. const certificateIndexView = new Uint16Array(certificateIndexBuffer);
  1817. certificateIndexView[0] = this.certificateIndex;
  1818. const certificateIndexView8 = new Uint8Array(certificateIndexBuffer);
  1819. let temp = certificateIndexView8[0];
  1820. certificateIndexView8[0] = certificateIndexView8[1];
  1821. certificateIndexView8[1] = temp;
  1822. const keyIndexBuffer = new ArrayBuffer(2);
  1823. const keyIndexView = new Uint16Array(keyIndexBuffer);
  1824. keyIndexView[0] = this.keyIndex;
  1825. const keyIndexView8 = new Uint8Array(keyIndexBuffer);
  1826. temp = keyIndexView8[0];
  1827. keyIndexView8[0] = keyIndexView8[1];
  1828. keyIndexView8[1] = temp;
  1829. return (new asn1js__namespace.Integer({
  1830. valueHex: pvutils__namespace.utilConcatBuf(keyIndexBuffer, certificateIndexBuffer)
  1831. }));
  1832. }
  1833. toJSON() {
  1834. return {
  1835. certificateIndex: this.certificateIndex,
  1836. keyIndex: this.keyIndex
  1837. };
  1838. }
  1839. }
  1840. CAVersion.CLASS_NAME = "CAVersion";
  1841. const POLICY_QUALIFIER_ID = "policyQualifierId";
  1842. const QUALIFIER = "qualifier";
  1843. const CLEAR_PROPS$1p = [
  1844. POLICY_QUALIFIER_ID,
  1845. QUALIFIER
  1846. ];
  1847. class PolicyQualifierInfo extends PkiObject {
  1848. constructor(parameters = {}) {
  1849. super();
  1850. this.policyQualifierId = pvutils__namespace.getParametersValue(parameters, POLICY_QUALIFIER_ID, PolicyQualifierInfo.defaultValues(POLICY_QUALIFIER_ID));
  1851. this.qualifier = pvutils__namespace.getParametersValue(parameters, QUALIFIER, PolicyQualifierInfo.defaultValues(QUALIFIER));
  1852. if (parameters.schema) {
  1853. this.fromSchema(parameters.schema);
  1854. }
  1855. }
  1856. static defaultValues(memberName) {
  1857. switch (memberName) {
  1858. case POLICY_QUALIFIER_ID:
  1859. return EMPTY_STRING;
  1860. case QUALIFIER:
  1861. return new asn1js__namespace.Any();
  1862. default:
  1863. return super.defaultValues(memberName);
  1864. }
  1865. }
  1866. static schema(parameters = {}) {
  1867. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  1868. return (new asn1js__namespace.Sequence({
  1869. name: (names.blockName || EMPTY_STRING),
  1870. value: [
  1871. new asn1js__namespace.ObjectIdentifier({ name: (names.policyQualifierId || EMPTY_STRING) }),
  1872. new asn1js__namespace.Any({ name: (names.qualifier || EMPTY_STRING) })
  1873. ]
  1874. }));
  1875. }
  1876. fromSchema(schema) {
  1877. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1p);
  1878. const asn1 = asn1js__namespace.compareSchema(schema, schema, PolicyQualifierInfo.schema({
  1879. names: {
  1880. policyQualifierId: POLICY_QUALIFIER_ID,
  1881. qualifier: QUALIFIER
  1882. }
  1883. }));
  1884. AsnError.assertSchema(asn1, this.className);
  1885. this.policyQualifierId = asn1.result.policyQualifierId.valueBlock.toString();
  1886. this.qualifier = asn1.result.qualifier;
  1887. }
  1888. toSchema() {
  1889. return (new asn1js__namespace.Sequence({
  1890. value: [
  1891. new asn1js__namespace.ObjectIdentifier({ value: this.policyQualifierId }),
  1892. this.qualifier
  1893. ]
  1894. }));
  1895. }
  1896. toJSON() {
  1897. return {
  1898. policyQualifierId: this.policyQualifierId,
  1899. qualifier: this.qualifier.toJSON()
  1900. };
  1901. }
  1902. }
  1903. PolicyQualifierInfo.CLASS_NAME = "PolicyQualifierInfo";
  1904. const POLICY_IDENTIFIER = "policyIdentifier";
  1905. const POLICY_QUALIFIERS = "policyQualifiers";
  1906. const CLEAR_PROPS$1o = [
  1907. POLICY_IDENTIFIER,
  1908. POLICY_QUALIFIERS
  1909. ];
  1910. class PolicyInformation extends PkiObject {
  1911. constructor(parameters = {}) {
  1912. super();
  1913. this.policyIdentifier = pvutils__namespace.getParametersValue(parameters, POLICY_IDENTIFIER, PolicyInformation.defaultValues(POLICY_IDENTIFIER));
  1914. if (POLICY_QUALIFIERS in parameters) {
  1915. this.policyQualifiers = pvutils__namespace.getParametersValue(parameters, POLICY_QUALIFIERS, PolicyInformation.defaultValues(POLICY_QUALIFIERS));
  1916. }
  1917. if (parameters.schema) {
  1918. this.fromSchema(parameters.schema);
  1919. }
  1920. }
  1921. static defaultValues(memberName) {
  1922. switch (memberName) {
  1923. case POLICY_IDENTIFIER:
  1924. return EMPTY_STRING;
  1925. case POLICY_QUALIFIERS:
  1926. return [];
  1927. default:
  1928. return super.defaultValues(memberName);
  1929. }
  1930. }
  1931. static schema(parameters = {}) {
  1932. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  1933. return (new asn1js__namespace.Sequence({
  1934. name: (names.blockName || EMPTY_STRING),
  1935. value: [
  1936. new asn1js__namespace.ObjectIdentifier({ name: (names.policyIdentifier || EMPTY_STRING) }),
  1937. new asn1js__namespace.Sequence({
  1938. optional: true,
  1939. value: [
  1940. new asn1js__namespace.Repeated({
  1941. name: (names.policyQualifiers || EMPTY_STRING),
  1942. value: PolicyQualifierInfo.schema()
  1943. })
  1944. ]
  1945. })
  1946. ]
  1947. }));
  1948. }
  1949. fromSchema(schema) {
  1950. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1o);
  1951. const asn1 = asn1js__namespace.compareSchema(schema, schema, PolicyInformation.schema({
  1952. names: {
  1953. policyIdentifier: POLICY_IDENTIFIER,
  1954. policyQualifiers: POLICY_QUALIFIERS
  1955. }
  1956. }));
  1957. AsnError.assertSchema(asn1, this.className);
  1958. this.policyIdentifier = asn1.result.policyIdentifier.valueBlock.toString();
  1959. if (POLICY_QUALIFIERS in asn1.result) {
  1960. this.policyQualifiers = Array.from(asn1.result.policyQualifiers, element => new PolicyQualifierInfo({ schema: element }));
  1961. }
  1962. }
  1963. toSchema() {
  1964. const outputArray = [];
  1965. outputArray.push(new asn1js__namespace.ObjectIdentifier({ value: this.policyIdentifier }));
  1966. if (this.policyQualifiers) {
  1967. outputArray.push(new asn1js__namespace.Sequence({
  1968. value: Array.from(this.policyQualifiers, o => o.toSchema())
  1969. }));
  1970. }
  1971. return (new asn1js__namespace.Sequence({
  1972. value: outputArray
  1973. }));
  1974. }
  1975. toJSON() {
  1976. const res = {
  1977. policyIdentifier: this.policyIdentifier
  1978. };
  1979. if (this.policyQualifiers)
  1980. res.policyQualifiers = Array.from(this.policyQualifiers, o => o.toJSON());
  1981. return res;
  1982. }
  1983. }
  1984. PolicyInformation.CLASS_NAME = "PolicyInformation";
  1985. const CERTIFICATE_POLICIES = "certificatePolicies";
  1986. const CLEAR_PROPS$1n = [
  1987. CERTIFICATE_POLICIES,
  1988. ];
  1989. class CertificatePolicies extends PkiObject {
  1990. constructor(parameters = {}) {
  1991. super();
  1992. this.certificatePolicies = pvutils__namespace.getParametersValue(parameters, CERTIFICATE_POLICIES, CertificatePolicies.defaultValues(CERTIFICATE_POLICIES));
  1993. if (parameters.schema) {
  1994. this.fromSchema(parameters.schema);
  1995. }
  1996. }
  1997. static defaultValues(memberName) {
  1998. switch (memberName) {
  1999. case CERTIFICATE_POLICIES:
  2000. return [];
  2001. default:
  2002. return super.defaultValues(memberName);
  2003. }
  2004. }
  2005. static schema(parameters = {}) {
  2006. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  2007. return (new asn1js__namespace.Sequence({
  2008. name: (names.blockName || EMPTY_STRING),
  2009. value: [
  2010. new asn1js__namespace.Repeated({
  2011. name: (names.certificatePolicies || EMPTY_STRING),
  2012. value: PolicyInformation.schema()
  2013. })
  2014. ]
  2015. }));
  2016. }
  2017. fromSchema(schema) {
  2018. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1n);
  2019. const asn1 = asn1js__namespace.compareSchema(schema, schema, CertificatePolicies.schema({
  2020. names: {
  2021. certificatePolicies: CERTIFICATE_POLICIES
  2022. }
  2023. }));
  2024. AsnError.assertSchema(asn1, this.className);
  2025. this.certificatePolicies = Array.from(asn1.result.certificatePolicies, element => new PolicyInformation({ schema: element }));
  2026. }
  2027. toSchema() {
  2028. return (new asn1js__namespace.Sequence({
  2029. value: Array.from(this.certificatePolicies, o => o.toSchema())
  2030. }));
  2031. }
  2032. toJSON() {
  2033. return {
  2034. certificatePolicies: Array.from(this.certificatePolicies, o => o.toJSON())
  2035. };
  2036. }
  2037. }
  2038. CertificatePolicies.CLASS_NAME = "CertificatePolicies";
  2039. const TEMPLATE_ID = "templateID";
  2040. const TEMPLATE_MAJOR_VERSION = "templateMajorVersion";
  2041. const TEMPLATE_MINOR_VERSION = "templateMinorVersion";
  2042. const CLEAR_PROPS$1m = [
  2043. TEMPLATE_ID,
  2044. TEMPLATE_MAJOR_VERSION,
  2045. TEMPLATE_MINOR_VERSION
  2046. ];
  2047. class CertificateTemplate extends PkiObject {
  2048. constructor(parameters = {}) {
  2049. super();
  2050. this.templateID = pvutils__namespace.getParametersValue(parameters, TEMPLATE_ID, CertificateTemplate.defaultValues(TEMPLATE_ID));
  2051. if (TEMPLATE_MAJOR_VERSION in parameters) {
  2052. this.templateMajorVersion = pvutils__namespace.getParametersValue(parameters, TEMPLATE_MAJOR_VERSION, CertificateTemplate.defaultValues(TEMPLATE_MAJOR_VERSION));
  2053. }
  2054. if (TEMPLATE_MINOR_VERSION in parameters) {
  2055. this.templateMinorVersion = pvutils__namespace.getParametersValue(parameters, TEMPLATE_MINOR_VERSION, CertificateTemplate.defaultValues(TEMPLATE_MINOR_VERSION));
  2056. }
  2057. if (parameters.schema) {
  2058. this.fromSchema(parameters.schema);
  2059. }
  2060. }
  2061. static defaultValues(memberName) {
  2062. switch (memberName) {
  2063. case TEMPLATE_ID:
  2064. return EMPTY_STRING;
  2065. case TEMPLATE_MAJOR_VERSION:
  2066. case TEMPLATE_MINOR_VERSION:
  2067. return 0;
  2068. default:
  2069. return super.defaultValues(memberName);
  2070. }
  2071. }
  2072. static schema(parameters = {}) {
  2073. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  2074. return (new asn1js__namespace.Sequence({
  2075. name: (names.blockName || EMPTY_STRING),
  2076. value: [
  2077. new asn1js__namespace.ObjectIdentifier({ name: (names.templateID || EMPTY_STRING) }),
  2078. new asn1js__namespace.Integer({
  2079. name: (names.templateMajorVersion || EMPTY_STRING),
  2080. optional: true
  2081. }),
  2082. new asn1js__namespace.Integer({
  2083. name: (names.templateMinorVersion || EMPTY_STRING),
  2084. optional: true
  2085. }),
  2086. ]
  2087. }));
  2088. }
  2089. fromSchema(schema) {
  2090. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1m);
  2091. const asn1 = asn1js__namespace.compareSchema(schema, schema, CertificateTemplate.schema({
  2092. names: {
  2093. templateID: TEMPLATE_ID,
  2094. templateMajorVersion: TEMPLATE_MAJOR_VERSION,
  2095. templateMinorVersion: TEMPLATE_MINOR_VERSION
  2096. }
  2097. }));
  2098. AsnError.assertSchema(asn1, this.className);
  2099. this.templateID = asn1.result.templateID.valueBlock.toString();
  2100. if (TEMPLATE_MAJOR_VERSION in asn1.result) {
  2101. this.templateMajorVersion = asn1.result.templateMajorVersion.valueBlock.valueDec;
  2102. }
  2103. if (TEMPLATE_MINOR_VERSION in asn1.result) {
  2104. this.templateMinorVersion = asn1.result.templateMinorVersion.valueBlock.valueDec;
  2105. }
  2106. }
  2107. toSchema() {
  2108. const outputArray = [];
  2109. outputArray.push(new asn1js__namespace.ObjectIdentifier({ value: this.templateID }));
  2110. if (TEMPLATE_MAJOR_VERSION in this) {
  2111. outputArray.push(new asn1js__namespace.Integer({ value: this.templateMajorVersion }));
  2112. }
  2113. if (TEMPLATE_MINOR_VERSION in this) {
  2114. outputArray.push(new asn1js__namespace.Integer({ value: this.templateMinorVersion }));
  2115. }
  2116. return (new asn1js__namespace.Sequence({
  2117. value: outputArray
  2118. }));
  2119. }
  2120. toJSON() {
  2121. const res = {
  2122. templateID: this.templateID
  2123. };
  2124. if (TEMPLATE_MAJOR_VERSION in this)
  2125. res.templateMajorVersion = this.templateMajorVersion;
  2126. if (TEMPLATE_MINOR_VERSION in this)
  2127. res.templateMinorVersion = this.templateMinorVersion;
  2128. return res;
  2129. }
  2130. }
  2131. const DISTRIBUTION_POINT$1 = "distributionPoint";
  2132. const DISTRIBUTION_POINT_NAMES$1 = "distributionPointNames";
  2133. const REASONS = "reasons";
  2134. const CRL_ISSUER = "cRLIssuer";
  2135. const CRL_ISSUER_NAMES = "cRLIssuerNames";
  2136. const CLEAR_PROPS$1l = [
  2137. DISTRIBUTION_POINT$1,
  2138. DISTRIBUTION_POINT_NAMES$1,
  2139. REASONS,
  2140. CRL_ISSUER,
  2141. CRL_ISSUER_NAMES,
  2142. ];
  2143. class DistributionPoint extends PkiObject {
  2144. constructor(parameters = {}) {
  2145. super();
  2146. if (DISTRIBUTION_POINT$1 in parameters) {
  2147. this.distributionPoint = pvutils__namespace.getParametersValue(parameters, DISTRIBUTION_POINT$1, DistributionPoint.defaultValues(DISTRIBUTION_POINT$1));
  2148. }
  2149. if (REASONS in parameters) {
  2150. this.reasons = pvutils__namespace.getParametersValue(parameters, REASONS, DistributionPoint.defaultValues(REASONS));
  2151. }
  2152. if (CRL_ISSUER in parameters) {
  2153. this.cRLIssuer = pvutils__namespace.getParametersValue(parameters, CRL_ISSUER, DistributionPoint.defaultValues(CRL_ISSUER));
  2154. }
  2155. if (parameters.schema) {
  2156. this.fromSchema(parameters.schema);
  2157. }
  2158. }
  2159. static defaultValues(memberName) {
  2160. switch (memberName) {
  2161. case DISTRIBUTION_POINT$1:
  2162. return [];
  2163. case REASONS:
  2164. return new asn1js__namespace.BitString();
  2165. case CRL_ISSUER:
  2166. return [];
  2167. default:
  2168. return super.defaultValues(memberName);
  2169. }
  2170. }
  2171. static schema(parameters = {}) {
  2172. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  2173. return (new asn1js__namespace.Sequence({
  2174. name: (names.blockName || EMPTY_STRING),
  2175. value: [
  2176. new asn1js__namespace.Constructed({
  2177. optional: true,
  2178. idBlock: {
  2179. tagClass: 3,
  2180. tagNumber: 0
  2181. },
  2182. value: [
  2183. new asn1js__namespace.Choice({
  2184. value: [
  2185. new asn1js__namespace.Constructed({
  2186. name: (names.distributionPoint || EMPTY_STRING),
  2187. optional: true,
  2188. idBlock: {
  2189. tagClass: 3,
  2190. tagNumber: 0
  2191. },
  2192. value: [
  2193. new asn1js__namespace.Repeated({
  2194. name: (names.distributionPointNames || EMPTY_STRING),
  2195. value: GeneralName.schema()
  2196. })
  2197. ]
  2198. }),
  2199. new asn1js__namespace.Constructed({
  2200. name: (names.distributionPoint || EMPTY_STRING),
  2201. optional: true,
  2202. idBlock: {
  2203. tagClass: 3,
  2204. tagNumber: 1
  2205. },
  2206. value: RelativeDistinguishedNames.schema().valueBlock.value
  2207. })
  2208. ]
  2209. })
  2210. ]
  2211. }),
  2212. new asn1js__namespace.Primitive({
  2213. name: (names.reasons || EMPTY_STRING),
  2214. optional: true,
  2215. idBlock: {
  2216. tagClass: 3,
  2217. tagNumber: 1
  2218. }
  2219. }),
  2220. new asn1js__namespace.Constructed({
  2221. name: (names.cRLIssuer || EMPTY_STRING),
  2222. optional: true,
  2223. idBlock: {
  2224. tagClass: 3,
  2225. tagNumber: 2
  2226. },
  2227. value: [
  2228. new asn1js__namespace.Repeated({
  2229. name: (names.cRLIssuerNames || EMPTY_STRING),
  2230. value: GeneralName.schema()
  2231. })
  2232. ]
  2233. })
  2234. ]
  2235. }));
  2236. }
  2237. fromSchema(schema) {
  2238. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1l);
  2239. const asn1 = asn1js__namespace.compareSchema(schema, schema, DistributionPoint.schema({
  2240. names: {
  2241. distributionPoint: DISTRIBUTION_POINT$1,
  2242. distributionPointNames: DISTRIBUTION_POINT_NAMES$1,
  2243. reasons: REASONS,
  2244. cRLIssuer: CRL_ISSUER,
  2245. cRLIssuerNames: CRL_ISSUER_NAMES
  2246. }
  2247. }));
  2248. AsnError.assertSchema(asn1, this.className);
  2249. if (DISTRIBUTION_POINT$1 in asn1.result) {
  2250. if (asn1.result.distributionPoint.idBlock.tagNumber === 0) {
  2251. this.distributionPoint = Array.from(asn1.result.distributionPointNames, element => new GeneralName({ schema: element }));
  2252. }
  2253. if (asn1.result.distributionPoint.idBlock.tagNumber === 1) {
  2254. this.distributionPoint = new RelativeDistinguishedNames({
  2255. schema: new asn1js__namespace.Sequence({
  2256. value: asn1.result.distributionPoint.valueBlock.value
  2257. })
  2258. });
  2259. }
  2260. }
  2261. if (REASONS in asn1.result) {
  2262. this.reasons = new asn1js__namespace.BitString({ valueHex: asn1.result.reasons.valueBlock.valueHex });
  2263. }
  2264. if (CRL_ISSUER in asn1.result) {
  2265. this.cRLIssuer = Array.from(asn1.result.cRLIssuerNames, element => new GeneralName({ schema: element }));
  2266. }
  2267. }
  2268. toSchema() {
  2269. const outputArray = [];
  2270. if (this.distributionPoint) {
  2271. let internalValue;
  2272. if (this.distributionPoint instanceof Array) {
  2273. internalValue = new asn1js__namespace.Constructed({
  2274. idBlock: {
  2275. tagClass: 3,
  2276. tagNumber: 0
  2277. },
  2278. value: Array.from(this.distributionPoint, o => o.toSchema())
  2279. });
  2280. }
  2281. else {
  2282. internalValue = new asn1js__namespace.Constructed({
  2283. idBlock: {
  2284. tagClass: 3,
  2285. tagNumber: 1
  2286. },
  2287. value: [this.distributionPoint.toSchema()]
  2288. });
  2289. }
  2290. outputArray.push(new asn1js__namespace.Constructed({
  2291. idBlock: {
  2292. tagClass: 3,
  2293. tagNumber: 0
  2294. },
  2295. value: [internalValue]
  2296. }));
  2297. }
  2298. if (this.reasons) {
  2299. outputArray.push(new asn1js__namespace.Primitive({
  2300. idBlock: {
  2301. tagClass: 3,
  2302. tagNumber: 1
  2303. },
  2304. valueHex: this.reasons.valueBlock.valueHexView
  2305. }));
  2306. }
  2307. if (this.cRLIssuer) {
  2308. outputArray.push(new asn1js__namespace.Constructed({
  2309. idBlock: {
  2310. tagClass: 3,
  2311. tagNumber: 2
  2312. },
  2313. value: Array.from(this.cRLIssuer, o => o.toSchema())
  2314. }));
  2315. }
  2316. return (new asn1js__namespace.Sequence({
  2317. value: outputArray
  2318. }));
  2319. }
  2320. toJSON() {
  2321. const object = {};
  2322. if (this.distributionPoint) {
  2323. if (this.distributionPoint instanceof Array) {
  2324. object.distributionPoint = Array.from(this.distributionPoint, o => o.toJSON());
  2325. }
  2326. else {
  2327. object.distributionPoint = this.distributionPoint.toJSON();
  2328. }
  2329. }
  2330. if (this.reasons) {
  2331. object.reasons = this.reasons.toJSON();
  2332. }
  2333. if (this.cRLIssuer) {
  2334. object.cRLIssuer = Array.from(this.cRLIssuer, o => o.toJSON());
  2335. }
  2336. return object;
  2337. }
  2338. }
  2339. DistributionPoint.CLASS_NAME = "DistributionPoint";
  2340. const DISTRIBUTION_POINTS = "distributionPoints";
  2341. const CLEAR_PROPS$1k = [
  2342. DISTRIBUTION_POINTS
  2343. ];
  2344. class CRLDistributionPoints extends PkiObject {
  2345. constructor(parameters = {}) {
  2346. super();
  2347. this.distributionPoints = pvutils__namespace.getParametersValue(parameters, DISTRIBUTION_POINTS, CRLDistributionPoints.defaultValues(DISTRIBUTION_POINTS));
  2348. if (parameters.schema) {
  2349. this.fromSchema(parameters.schema);
  2350. }
  2351. }
  2352. static defaultValues(memberName) {
  2353. switch (memberName) {
  2354. case DISTRIBUTION_POINTS:
  2355. return [];
  2356. default:
  2357. return super.defaultValues(memberName);
  2358. }
  2359. }
  2360. static schema(parameters = {}) {
  2361. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  2362. return (new asn1js__namespace.Sequence({
  2363. name: (names.blockName || EMPTY_STRING),
  2364. value: [
  2365. new asn1js__namespace.Repeated({
  2366. name: (names.distributionPoints || EMPTY_STRING),
  2367. value: DistributionPoint.schema()
  2368. })
  2369. ]
  2370. }));
  2371. }
  2372. fromSchema(schema) {
  2373. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1k);
  2374. const asn1 = asn1js__namespace.compareSchema(schema, schema, CRLDistributionPoints.schema({
  2375. names: {
  2376. distributionPoints: DISTRIBUTION_POINTS
  2377. }
  2378. }));
  2379. AsnError.assertSchema(asn1, this.className);
  2380. this.distributionPoints = Array.from(asn1.result.distributionPoints, element => new DistributionPoint({ schema: element }));
  2381. }
  2382. toSchema() {
  2383. return (new asn1js__namespace.Sequence({
  2384. value: Array.from(this.distributionPoints, o => o.toSchema())
  2385. }));
  2386. }
  2387. toJSON() {
  2388. return {
  2389. distributionPoints: Array.from(this.distributionPoints, o => o.toJSON())
  2390. };
  2391. }
  2392. }
  2393. CRLDistributionPoints.CLASS_NAME = "CRLDistributionPoints";
  2394. const KEY_PURPOSES = "keyPurposes";
  2395. const CLEAR_PROPS$1j = [
  2396. KEY_PURPOSES,
  2397. ];
  2398. class ExtKeyUsage extends PkiObject {
  2399. constructor(parameters = {}) {
  2400. super();
  2401. this.keyPurposes = pvutils__namespace.getParametersValue(parameters, KEY_PURPOSES, ExtKeyUsage.defaultValues(KEY_PURPOSES));
  2402. if (parameters.schema) {
  2403. this.fromSchema(parameters.schema);
  2404. }
  2405. }
  2406. static defaultValues(memberName) {
  2407. switch (memberName) {
  2408. case KEY_PURPOSES:
  2409. return [];
  2410. default:
  2411. return super.defaultValues(memberName);
  2412. }
  2413. }
  2414. static schema(parameters = {}) {
  2415. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  2416. return (new asn1js__namespace.Sequence({
  2417. name: (names.blockName || EMPTY_STRING),
  2418. value: [
  2419. new asn1js__namespace.Repeated({
  2420. name: (names.keyPurposes || EMPTY_STRING),
  2421. value: new asn1js__namespace.ObjectIdentifier()
  2422. })
  2423. ]
  2424. }));
  2425. }
  2426. fromSchema(schema) {
  2427. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1j);
  2428. const asn1 = asn1js__namespace.compareSchema(schema, schema, ExtKeyUsage.schema({
  2429. names: {
  2430. keyPurposes: KEY_PURPOSES
  2431. }
  2432. }));
  2433. AsnError.assertSchema(asn1, this.className);
  2434. this.keyPurposes = Array.from(asn1.result.keyPurposes, (element) => element.valueBlock.toString());
  2435. }
  2436. toSchema() {
  2437. return (new asn1js__namespace.Sequence({
  2438. value: Array.from(this.keyPurposes, element => new asn1js__namespace.ObjectIdentifier({ value: element }))
  2439. }));
  2440. }
  2441. toJSON() {
  2442. return {
  2443. keyPurposes: Array.from(this.keyPurposes)
  2444. };
  2445. }
  2446. }
  2447. ExtKeyUsage.CLASS_NAME = "ExtKeyUsage";
  2448. const ACCESS_DESCRIPTIONS = "accessDescriptions";
  2449. class InfoAccess extends PkiObject {
  2450. constructor(parameters = {}) {
  2451. super();
  2452. this.accessDescriptions = pvutils__namespace.getParametersValue(parameters, ACCESS_DESCRIPTIONS, InfoAccess.defaultValues(ACCESS_DESCRIPTIONS));
  2453. if (parameters.schema) {
  2454. this.fromSchema(parameters.schema);
  2455. }
  2456. }
  2457. static defaultValues(memberName) {
  2458. switch (memberName) {
  2459. case ACCESS_DESCRIPTIONS:
  2460. return [];
  2461. default:
  2462. return super.defaultValues(memberName);
  2463. }
  2464. }
  2465. static schema(parameters = {}) {
  2466. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  2467. return (new asn1js__namespace.Sequence({
  2468. name: (names.blockName || EMPTY_STRING),
  2469. value: [
  2470. new asn1js__namespace.Repeated({
  2471. name: (names.accessDescriptions || EMPTY_STRING),
  2472. value: AccessDescription.schema()
  2473. })
  2474. ]
  2475. }));
  2476. }
  2477. fromSchema(schema) {
  2478. pvutils__namespace.clearProps(schema, [
  2479. ACCESS_DESCRIPTIONS
  2480. ]);
  2481. const asn1 = asn1js__namespace.compareSchema(schema, schema, InfoAccess.schema({
  2482. names: {
  2483. accessDescriptions: ACCESS_DESCRIPTIONS
  2484. }
  2485. }));
  2486. AsnError.assertSchema(asn1, this.className);
  2487. this.accessDescriptions = Array.from(asn1.result.accessDescriptions, element => new AccessDescription({ schema: element }));
  2488. }
  2489. toSchema() {
  2490. return (new asn1js__namespace.Sequence({
  2491. value: Array.from(this.accessDescriptions, o => o.toSchema())
  2492. }));
  2493. }
  2494. toJSON() {
  2495. return {
  2496. accessDescriptions: Array.from(this.accessDescriptions, o => o.toJSON())
  2497. };
  2498. }
  2499. }
  2500. InfoAccess.CLASS_NAME = "InfoAccess";
  2501. const DISTRIBUTION_POINT = "distributionPoint";
  2502. const DISTRIBUTION_POINT_NAMES = "distributionPointNames";
  2503. const ONLY_CONTAINS_USER_CERTS = "onlyContainsUserCerts";
  2504. const ONLY_CONTAINS_CA_CERTS = "onlyContainsCACerts";
  2505. const ONLY_SOME_REASON = "onlySomeReasons";
  2506. const INDIRECT_CRL = "indirectCRL";
  2507. const ONLY_CONTAINS_ATTRIBUTE_CERTS = "onlyContainsAttributeCerts";
  2508. const CLEAR_PROPS$1i = [
  2509. DISTRIBUTION_POINT,
  2510. DISTRIBUTION_POINT_NAMES,
  2511. ONLY_CONTAINS_USER_CERTS,
  2512. ONLY_CONTAINS_CA_CERTS,
  2513. ONLY_SOME_REASON,
  2514. INDIRECT_CRL,
  2515. ONLY_CONTAINS_ATTRIBUTE_CERTS,
  2516. ];
  2517. class IssuingDistributionPoint extends PkiObject {
  2518. constructor(parameters = {}) {
  2519. super();
  2520. if (DISTRIBUTION_POINT in parameters) {
  2521. this.distributionPoint = pvutils__namespace.getParametersValue(parameters, DISTRIBUTION_POINT, IssuingDistributionPoint.defaultValues(DISTRIBUTION_POINT));
  2522. }
  2523. this.onlyContainsUserCerts = pvutils__namespace.getParametersValue(parameters, ONLY_CONTAINS_USER_CERTS, IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_USER_CERTS));
  2524. this.onlyContainsCACerts = pvutils__namespace.getParametersValue(parameters, ONLY_CONTAINS_CA_CERTS, IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_CA_CERTS));
  2525. if (ONLY_SOME_REASON in parameters) {
  2526. this.onlySomeReasons = pvutils__namespace.getParametersValue(parameters, ONLY_SOME_REASON, IssuingDistributionPoint.defaultValues(ONLY_SOME_REASON));
  2527. }
  2528. this.indirectCRL = pvutils__namespace.getParametersValue(parameters, INDIRECT_CRL, IssuingDistributionPoint.defaultValues(INDIRECT_CRL));
  2529. this.onlyContainsAttributeCerts = pvutils__namespace.getParametersValue(parameters, ONLY_CONTAINS_ATTRIBUTE_CERTS, IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_ATTRIBUTE_CERTS));
  2530. if (parameters.schema) {
  2531. this.fromSchema(parameters.schema);
  2532. }
  2533. }
  2534. static defaultValues(memberName) {
  2535. switch (memberName) {
  2536. case DISTRIBUTION_POINT:
  2537. return [];
  2538. case ONLY_CONTAINS_USER_CERTS:
  2539. return false;
  2540. case ONLY_CONTAINS_CA_CERTS:
  2541. return false;
  2542. case ONLY_SOME_REASON:
  2543. return 0;
  2544. case INDIRECT_CRL:
  2545. return false;
  2546. case ONLY_CONTAINS_ATTRIBUTE_CERTS:
  2547. return false;
  2548. default:
  2549. return super.defaultValues(memberName);
  2550. }
  2551. }
  2552. static schema(parameters = {}) {
  2553. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  2554. return (new asn1js__namespace.Sequence({
  2555. name: (names.blockName || EMPTY_STRING),
  2556. value: [
  2557. new asn1js__namespace.Constructed({
  2558. optional: true,
  2559. idBlock: {
  2560. tagClass: 3,
  2561. tagNumber: 0
  2562. },
  2563. value: [
  2564. new asn1js__namespace.Choice({
  2565. value: [
  2566. new asn1js__namespace.Constructed({
  2567. name: (names.distributionPoint || EMPTY_STRING),
  2568. idBlock: {
  2569. tagClass: 3,
  2570. tagNumber: 0
  2571. },
  2572. value: [
  2573. new asn1js__namespace.Repeated({
  2574. name: (names.distributionPointNames || EMPTY_STRING),
  2575. value: GeneralName.schema()
  2576. })
  2577. ]
  2578. }),
  2579. new asn1js__namespace.Constructed({
  2580. name: (names.distributionPoint || EMPTY_STRING),
  2581. idBlock: {
  2582. tagClass: 3,
  2583. tagNumber: 1
  2584. },
  2585. value: RelativeDistinguishedNames.schema().valueBlock.value
  2586. })
  2587. ]
  2588. })
  2589. ]
  2590. }),
  2591. new asn1js__namespace.Primitive({
  2592. name: (names.onlyContainsUserCerts || EMPTY_STRING),
  2593. optional: true,
  2594. idBlock: {
  2595. tagClass: 3,
  2596. tagNumber: 1
  2597. }
  2598. }),
  2599. new asn1js__namespace.Primitive({
  2600. name: (names.onlyContainsCACerts || EMPTY_STRING),
  2601. optional: true,
  2602. idBlock: {
  2603. tagClass: 3,
  2604. tagNumber: 2
  2605. }
  2606. }),
  2607. new asn1js__namespace.Primitive({
  2608. name: (names.onlySomeReasons || EMPTY_STRING),
  2609. optional: true,
  2610. idBlock: {
  2611. tagClass: 3,
  2612. tagNumber: 3
  2613. }
  2614. }),
  2615. new asn1js__namespace.Primitive({
  2616. name: (names.indirectCRL || EMPTY_STRING),
  2617. optional: true,
  2618. idBlock: {
  2619. tagClass: 3,
  2620. tagNumber: 4
  2621. }
  2622. }),
  2623. new asn1js__namespace.Primitive({
  2624. name: (names.onlyContainsAttributeCerts || EMPTY_STRING),
  2625. optional: true,
  2626. idBlock: {
  2627. tagClass: 3,
  2628. tagNumber: 5
  2629. }
  2630. })
  2631. ]
  2632. }));
  2633. }
  2634. fromSchema(schema) {
  2635. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1i);
  2636. const asn1 = asn1js__namespace.compareSchema(schema, schema, IssuingDistributionPoint.schema({
  2637. names: {
  2638. distributionPoint: DISTRIBUTION_POINT,
  2639. distributionPointNames: DISTRIBUTION_POINT_NAMES,
  2640. onlyContainsUserCerts: ONLY_CONTAINS_USER_CERTS,
  2641. onlyContainsCACerts: ONLY_CONTAINS_CA_CERTS,
  2642. onlySomeReasons: ONLY_SOME_REASON,
  2643. indirectCRL: INDIRECT_CRL,
  2644. onlyContainsAttributeCerts: ONLY_CONTAINS_ATTRIBUTE_CERTS
  2645. }
  2646. }));
  2647. AsnError.assertSchema(asn1, this.className);
  2648. if (DISTRIBUTION_POINT in asn1.result) {
  2649. switch (true) {
  2650. case (asn1.result.distributionPoint.idBlock.tagNumber === 0):
  2651. this.distributionPoint = Array.from(asn1.result.distributionPointNames, element => new GeneralName({ schema: element }));
  2652. break;
  2653. case (asn1.result.distributionPoint.idBlock.tagNumber === 1):
  2654. {
  2655. this.distributionPoint = new RelativeDistinguishedNames({
  2656. schema: new asn1js__namespace.Sequence({
  2657. value: asn1.result.distributionPoint.valueBlock.value
  2658. })
  2659. });
  2660. }
  2661. break;
  2662. default:
  2663. throw new Error("Unknown tagNumber for distributionPoint: {$asn1.result.distributionPoint.idBlock.tagNumber}");
  2664. }
  2665. }
  2666. if (ONLY_CONTAINS_USER_CERTS in asn1.result) {
  2667. const view = new Uint8Array(asn1.result.onlyContainsUserCerts.valueBlock.valueHex);
  2668. this.onlyContainsUserCerts = (view[0] !== 0x00);
  2669. }
  2670. if (ONLY_CONTAINS_CA_CERTS in asn1.result) {
  2671. const view = new Uint8Array(asn1.result.onlyContainsCACerts.valueBlock.valueHex);
  2672. this.onlyContainsCACerts = (view[0] !== 0x00);
  2673. }
  2674. if (ONLY_SOME_REASON in asn1.result) {
  2675. const view = new Uint8Array(asn1.result.onlySomeReasons.valueBlock.valueHex);
  2676. this.onlySomeReasons = view[0];
  2677. }
  2678. if (INDIRECT_CRL in asn1.result) {
  2679. const view = new Uint8Array(asn1.result.indirectCRL.valueBlock.valueHex);
  2680. this.indirectCRL = (view[0] !== 0x00);
  2681. }
  2682. if (ONLY_CONTAINS_ATTRIBUTE_CERTS in asn1.result) {
  2683. const view = new Uint8Array(asn1.result.onlyContainsAttributeCerts.valueBlock.valueHex);
  2684. this.onlyContainsAttributeCerts = (view[0] !== 0x00);
  2685. }
  2686. }
  2687. toSchema() {
  2688. const outputArray = [];
  2689. if (this.distributionPoint) {
  2690. let value;
  2691. if (this.distributionPoint instanceof Array) {
  2692. value = new asn1js__namespace.Constructed({
  2693. idBlock: {
  2694. tagClass: 3,
  2695. tagNumber: 0
  2696. },
  2697. value: Array.from(this.distributionPoint, o => o.toSchema())
  2698. });
  2699. }
  2700. else {
  2701. value = this.distributionPoint.toSchema();
  2702. value.idBlock.tagClass = 3;
  2703. value.idBlock.tagNumber = 1;
  2704. }
  2705. outputArray.push(new asn1js__namespace.Constructed({
  2706. idBlock: {
  2707. tagClass: 3,
  2708. tagNumber: 0
  2709. },
  2710. value: [value]
  2711. }));
  2712. }
  2713. if (this.onlyContainsUserCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_USER_CERTS)) {
  2714. outputArray.push(new asn1js__namespace.Primitive({
  2715. idBlock: {
  2716. tagClass: 3,
  2717. tagNumber: 1
  2718. },
  2719. valueHex: (new Uint8Array([0xFF])).buffer
  2720. }));
  2721. }
  2722. if (this.onlyContainsCACerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_CA_CERTS)) {
  2723. outputArray.push(new asn1js__namespace.Primitive({
  2724. idBlock: {
  2725. tagClass: 3,
  2726. tagNumber: 2
  2727. },
  2728. valueHex: (new Uint8Array([0xFF])).buffer
  2729. }));
  2730. }
  2731. if (this.onlySomeReasons !== undefined) {
  2732. const buffer = new ArrayBuffer(1);
  2733. const view = new Uint8Array(buffer);
  2734. view[0] = this.onlySomeReasons;
  2735. outputArray.push(new asn1js__namespace.Primitive({
  2736. idBlock: {
  2737. tagClass: 3,
  2738. tagNumber: 3
  2739. },
  2740. valueHex: buffer
  2741. }));
  2742. }
  2743. if (this.indirectCRL !== IssuingDistributionPoint.defaultValues(INDIRECT_CRL)) {
  2744. outputArray.push(new asn1js__namespace.Primitive({
  2745. idBlock: {
  2746. tagClass: 3,
  2747. tagNumber: 4
  2748. },
  2749. valueHex: (new Uint8Array([0xFF])).buffer
  2750. }));
  2751. }
  2752. if (this.onlyContainsAttributeCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_ATTRIBUTE_CERTS)) {
  2753. outputArray.push(new asn1js__namespace.Primitive({
  2754. idBlock: {
  2755. tagClass: 3,
  2756. tagNumber: 5
  2757. },
  2758. valueHex: (new Uint8Array([0xFF])).buffer
  2759. }));
  2760. }
  2761. return (new asn1js__namespace.Sequence({
  2762. value: outputArray
  2763. }));
  2764. }
  2765. toJSON() {
  2766. const obj = {};
  2767. if (this.distributionPoint) {
  2768. if (this.distributionPoint instanceof Array) {
  2769. obj.distributionPoint = Array.from(this.distributionPoint, o => o.toJSON());
  2770. }
  2771. else {
  2772. obj.distributionPoint = this.distributionPoint.toJSON();
  2773. }
  2774. }
  2775. if (this.onlyContainsUserCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_USER_CERTS)) {
  2776. obj.onlyContainsUserCerts = this.onlyContainsUserCerts;
  2777. }
  2778. if (this.onlyContainsCACerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_CA_CERTS)) {
  2779. obj.onlyContainsCACerts = this.onlyContainsCACerts;
  2780. }
  2781. if (ONLY_SOME_REASON in this) {
  2782. obj.onlySomeReasons = this.onlySomeReasons;
  2783. }
  2784. if (this.indirectCRL !== IssuingDistributionPoint.defaultValues(INDIRECT_CRL)) {
  2785. obj.indirectCRL = this.indirectCRL;
  2786. }
  2787. if (this.onlyContainsAttributeCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_ATTRIBUTE_CERTS)) {
  2788. obj.onlyContainsAttributeCerts = this.onlyContainsAttributeCerts;
  2789. }
  2790. return obj;
  2791. }
  2792. }
  2793. IssuingDistributionPoint.CLASS_NAME = "IssuingDistributionPoint";
  2794. const BASE = "base";
  2795. const MINIMUM = "minimum";
  2796. const MAXIMUM = "maximum";
  2797. const CLEAR_PROPS$1h = [
  2798. BASE,
  2799. MINIMUM,
  2800. MAXIMUM
  2801. ];
  2802. class GeneralSubtree extends PkiObject {
  2803. constructor(parameters = {}) {
  2804. super();
  2805. this.base = pvutils__namespace.getParametersValue(parameters, BASE, GeneralSubtree.defaultValues(BASE));
  2806. this.minimum = pvutils__namespace.getParametersValue(parameters, MINIMUM, GeneralSubtree.defaultValues(MINIMUM));
  2807. if (MAXIMUM in parameters) {
  2808. this.maximum = pvutils__namespace.getParametersValue(parameters, MAXIMUM, GeneralSubtree.defaultValues(MAXIMUM));
  2809. }
  2810. if (parameters.schema) {
  2811. this.fromSchema(parameters.schema);
  2812. }
  2813. }
  2814. static defaultValues(memberName) {
  2815. switch (memberName) {
  2816. case BASE:
  2817. return new GeneralName();
  2818. case MINIMUM:
  2819. return 0;
  2820. case MAXIMUM:
  2821. return 0;
  2822. default:
  2823. return super.defaultValues(memberName);
  2824. }
  2825. }
  2826. static schema(parameters = {}) {
  2827. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  2828. return (new asn1js__namespace.Sequence({
  2829. name: (names.blockName || EMPTY_STRING),
  2830. value: [
  2831. GeneralName.schema(names.base || {}),
  2832. new asn1js__namespace.Constructed({
  2833. optional: true,
  2834. idBlock: {
  2835. tagClass: 3,
  2836. tagNumber: 0
  2837. },
  2838. value: [new asn1js__namespace.Integer({ name: (names.minimum || EMPTY_STRING) })]
  2839. }),
  2840. new asn1js__namespace.Constructed({
  2841. optional: true,
  2842. idBlock: {
  2843. tagClass: 3,
  2844. tagNumber: 1
  2845. },
  2846. value: [new asn1js__namespace.Integer({ name: (names.maximum || EMPTY_STRING) })]
  2847. })
  2848. ]
  2849. }));
  2850. }
  2851. fromSchema(schema) {
  2852. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1h);
  2853. const asn1 = asn1js__namespace.compareSchema(schema, schema, GeneralSubtree.schema({
  2854. names: {
  2855. base: {
  2856. names: {
  2857. blockName: BASE
  2858. }
  2859. },
  2860. minimum: MINIMUM,
  2861. maximum: MAXIMUM
  2862. }
  2863. }));
  2864. AsnError.assertSchema(asn1, this.className);
  2865. this.base = new GeneralName({ schema: asn1.result.base });
  2866. if (MINIMUM in asn1.result) {
  2867. if (asn1.result.minimum.valueBlock.isHexOnly)
  2868. this.minimum = asn1.result.minimum;
  2869. else
  2870. this.minimum = asn1.result.minimum.valueBlock.valueDec;
  2871. }
  2872. if (MAXIMUM in asn1.result) {
  2873. if (asn1.result.maximum.valueBlock.isHexOnly)
  2874. this.maximum = asn1.result.maximum;
  2875. else
  2876. this.maximum = asn1.result.maximum.valueBlock.valueDec;
  2877. }
  2878. }
  2879. toSchema() {
  2880. const outputArray = [];
  2881. outputArray.push(this.base.toSchema());
  2882. if (this.minimum !== 0) {
  2883. let valueMinimum = 0;
  2884. if (this.minimum instanceof asn1js__namespace.Integer) {
  2885. valueMinimum = this.minimum;
  2886. }
  2887. else {
  2888. valueMinimum = new asn1js__namespace.Integer({ value: this.minimum });
  2889. }
  2890. outputArray.push(new asn1js__namespace.Constructed({
  2891. optional: true,
  2892. idBlock: {
  2893. tagClass: 3,
  2894. tagNumber: 0
  2895. },
  2896. value: [valueMinimum]
  2897. }));
  2898. }
  2899. if (MAXIMUM in this) {
  2900. let valueMaximum = 0;
  2901. if (this.maximum instanceof asn1js__namespace.Integer) {
  2902. valueMaximum = this.maximum;
  2903. }
  2904. else {
  2905. valueMaximum = new asn1js__namespace.Integer({ value: this.maximum });
  2906. }
  2907. outputArray.push(new asn1js__namespace.Constructed({
  2908. optional: true,
  2909. idBlock: {
  2910. tagClass: 3,
  2911. tagNumber: 1
  2912. },
  2913. value: [valueMaximum]
  2914. }));
  2915. }
  2916. return (new asn1js__namespace.Sequence({
  2917. value: outputArray
  2918. }));
  2919. }
  2920. toJSON() {
  2921. const res = {
  2922. base: this.base.toJSON()
  2923. };
  2924. if (this.minimum !== 0) {
  2925. if (typeof this.minimum === "number") {
  2926. res.minimum = this.minimum;
  2927. }
  2928. else {
  2929. res.minimum = this.minimum.toJSON();
  2930. }
  2931. }
  2932. if (this.maximum !== undefined) {
  2933. if (typeof this.maximum === "number") {
  2934. res.maximum = this.maximum;
  2935. }
  2936. else {
  2937. res.maximum = this.maximum.toJSON();
  2938. }
  2939. }
  2940. return res;
  2941. }
  2942. }
  2943. GeneralSubtree.CLASS_NAME = "GeneralSubtree";
  2944. const PERMITTED_SUBTREES = "permittedSubtrees";
  2945. const EXCLUDED_SUBTREES = "excludedSubtrees";
  2946. const CLEAR_PROPS$1g = [
  2947. PERMITTED_SUBTREES,
  2948. EXCLUDED_SUBTREES
  2949. ];
  2950. class NameConstraints extends PkiObject {
  2951. constructor(parameters = {}) {
  2952. super();
  2953. if (PERMITTED_SUBTREES in parameters) {
  2954. this.permittedSubtrees = pvutils__namespace.getParametersValue(parameters, PERMITTED_SUBTREES, NameConstraints.defaultValues(PERMITTED_SUBTREES));
  2955. }
  2956. if (EXCLUDED_SUBTREES in parameters) {
  2957. this.excludedSubtrees = pvutils__namespace.getParametersValue(parameters, EXCLUDED_SUBTREES, NameConstraints.defaultValues(EXCLUDED_SUBTREES));
  2958. }
  2959. if (parameters.schema) {
  2960. this.fromSchema(parameters.schema);
  2961. }
  2962. }
  2963. static defaultValues(memberName) {
  2964. switch (memberName) {
  2965. case PERMITTED_SUBTREES:
  2966. case EXCLUDED_SUBTREES:
  2967. return [];
  2968. default:
  2969. return super.defaultValues(memberName);
  2970. }
  2971. }
  2972. static schema(parameters = {}) {
  2973. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  2974. return (new asn1js__namespace.Sequence({
  2975. name: (names.blockName || EMPTY_STRING),
  2976. value: [
  2977. new asn1js__namespace.Constructed({
  2978. optional: true,
  2979. idBlock: {
  2980. tagClass: 3,
  2981. tagNumber: 0
  2982. },
  2983. value: [
  2984. new asn1js__namespace.Repeated({
  2985. name: (names.permittedSubtrees || EMPTY_STRING),
  2986. value: GeneralSubtree.schema()
  2987. })
  2988. ]
  2989. }),
  2990. new asn1js__namespace.Constructed({
  2991. optional: true,
  2992. idBlock: {
  2993. tagClass: 3,
  2994. tagNumber: 1
  2995. },
  2996. value: [
  2997. new asn1js__namespace.Repeated({
  2998. name: (names.excludedSubtrees || EMPTY_STRING),
  2999. value: GeneralSubtree.schema()
  3000. })
  3001. ]
  3002. })
  3003. ]
  3004. }));
  3005. }
  3006. fromSchema(schema) {
  3007. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1g);
  3008. const asn1 = asn1js__namespace.compareSchema(schema, schema, NameConstraints.schema({
  3009. names: {
  3010. permittedSubtrees: PERMITTED_SUBTREES,
  3011. excludedSubtrees: EXCLUDED_SUBTREES
  3012. }
  3013. }));
  3014. AsnError.assertSchema(asn1, this.className);
  3015. if (PERMITTED_SUBTREES in asn1.result)
  3016. this.permittedSubtrees = Array.from(asn1.result.permittedSubtrees, element => new GeneralSubtree({ schema: element }));
  3017. if (EXCLUDED_SUBTREES in asn1.result)
  3018. this.excludedSubtrees = Array.from(asn1.result.excludedSubtrees, element => new GeneralSubtree({ schema: element }));
  3019. }
  3020. toSchema() {
  3021. const outputArray = [];
  3022. if (this.permittedSubtrees) {
  3023. outputArray.push(new asn1js__namespace.Constructed({
  3024. idBlock: {
  3025. tagClass: 3,
  3026. tagNumber: 0
  3027. },
  3028. value: Array.from(this.permittedSubtrees, o => o.toSchema())
  3029. }));
  3030. }
  3031. if (this.excludedSubtrees) {
  3032. outputArray.push(new asn1js__namespace.Constructed({
  3033. idBlock: {
  3034. tagClass: 3,
  3035. tagNumber: 1
  3036. },
  3037. value: Array.from(this.excludedSubtrees, o => o.toSchema())
  3038. }));
  3039. }
  3040. return (new asn1js__namespace.Sequence({
  3041. value: outputArray
  3042. }));
  3043. }
  3044. toJSON() {
  3045. const object = {};
  3046. if (this.permittedSubtrees) {
  3047. object.permittedSubtrees = Array.from(this.permittedSubtrees, o => o.toJSON());
  3048. }
  3049. if (this.excludedSubtrees) {
  3050. object.excludedSubtrees = Array.from(this.excludedSubtrees, o => o.toJSON());
  3051. }
  3052. return object;
  3053. }
  3054. }
  3055. NameConstraints.CLASS_NAME = "NameConstraints";
  3056. const REQUIRE_EXPLICIT_POLICY = "requireExplicitPolicy";
  3057. const INHIBIT_POLICY_MAPPING = "inhibitPolicyMapping";
  3058. const CLEAR_PROPS$1f = [
  3059. REQUIRE_EXPLICIT_POLICY,
  3060. INHIBIT_POLICY_MAPPING,
  3061. ];
  3062. class PolicyConstraints extends PkiObject {
  3063. constructor(parameters = {}) {
  3064. super();
  3065. if (REQUIRE_EXPLICIT_POLICY in parameters) {
  3066. this.requireExplicitPolicy = pvutils__namespace.getParametersValue(parameters, REQUIRE_EXPLICIT_POLICY, PolicyConstraints.defaultValues(REQUIRE_EXPLICIT_POLICY));
  3067. }
  3068. if (INHIBIT_POLICY_MAPPING in parameters) {
  3069. this.inhibitPolicyMapping = pvutils__namespace.getParametersValue(parameters, INHIBIT_POLICY_MAPPING, PolicyConstraints.defaultValues(INHIBIT_POLICY_MAPPING));
  3070. }
  3071. if (parameters.schema) {
  3072. this.fromSchema(parameters.schema);
  3073. }
  3074. }
  3075. static defaultValues(memberName) {
  3076. switch (memberName) {
  3077. case REQUIRE_EXPLICIT_POLICY:
  3078. return 0;
  3079. case INHIBIT_POLICY_MAPPING:
  3080. return 0;
  3081. default:
  3082. return super.defaultValues(memberName);
  3083. }
  3084. }
  3085. static schema(parameters = {}) {
  3086. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  3087. return (new asn1js__namespace.Sequence({
  3088. name: (names.blockName || EMPTY_STRING),
  3089. value: [
  3090. new asn1js__namespace.Primitive({
  3091. name: (names.requireExplicitPolicy || EMPTY_STRING),
  3092. optional: true,
  3093. idBlock: {
  3094. tagClass: 3,
  3095. tagNumber: 0
  3096. }
  3097. }),
  3098. new asn1js__namespace.Primitive({
  3099. name: (names.inhibitPolicyMapping || EMPTY_STRING),
  3100. optional: true,
  3101. idBlock: {
  3102. tagClass: 3,
  3103. tagNumber: 1
  3104. }
  3105. })
  3106. ]
  3107. }));
  3108. }
  3109. fromSchema(schema) {
  3110. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1f);
  3111. const asn1 = asn1js__namespace.compareSchema(schema, schema, PolicyConstraints.schema({
  3112. names: {
  3113. requireExplicitPolicy: REQUIRE_EXPLICIT_POLICY,
  3114. inhibitPolicyMapping: INHIBIT_POLICY_MAPPING
  3115. }
  3116. }));
  3117. AsnError.assertSchema(asn1, this.className);
  3118. if (REQUIRE_EXPLICIT_POLICY in asn1.result) {
  3119. const field1 = asn1.result.requireExplicitPolicy;
  3120. field1.idBlock.tagClass = 1;
  3121. field1.idBlock.tagNumber = 2;
  3122. const ber1 = field1.toBER(false);
  3123. const int1 = asn1js__namespace.fromBER(ber1);
  3124. AsnError.assert(int1, "Integer");
  3125. this.requireExplicitPolicy = int1.result.valueBlock.valueDec;
  3126. }
  3127. if (INHIBIT_POLICY_MAPPING in asn1.result) {
  3128. const field2 = asn1.result.inhibitPolicyMapping;
  3129. field2.idBlock.tagClass = 1;
  3130. field2.idBlock.tagNumber = 2;
  3131. const ber2 = field2.toBER(false);
  3132. const int2 = asn1js__namespace.fromBER(ber2);
  3133. AsnError.assert(int2, "Integer");
  3134. this.inhibitPolicyMapping = int2.result.valueBlock.valueDec;
  3135. }
  3136. }
  3137. toSchema() {
  3138. const outputArray = [];
  3139. if (REQUIRE_EXPLICIT_POLICY in this) {
  3140. const int1 = new asn1js__namespace.Integer({ value: this.requireExplicitPolicy });
  3141. int1.idBlock.tagClass = 3;
  3142. int1.idBlock.tagNumber = 0;
  3143. outputArray.push(int1);
  3144. }
  3145. if (INHIBIT_POLICY_MAPPING in this) {
  3146. const int2 = new asn1js__namespace.Integer({ value: this.inhibitPolicyMapping });
  3147. int2.idBlock.tagClass = 3;
  3148. int2.idBlock.tagNumber = 1;
  3149. outputArray.push(int2);
  3150. }
  3151. return (new asn1js__namespace.Sequence({
  3152. value: outputArray
  3153. }));
  3154. }
  3155. toJSON() {
  3156. const res = {};
  3157. if (REQUIRE_EXPLICIT_POLICY in this) {
  3158. res.requireExplicitPolicy = this.requireExplicitPolicy;
  3159. }
  3160. if (INHIBIT_POLICY_MAPPING in this) {
  3161. res.inhibitPolicyMapping = this.inhibitPolicyMapping;
  3162. }
  3163. return res;
  3164. }
  3165. }
  3166. PolicyConstraints.CLASS_NAME = "PolicyConstraints";
  3167. const ISSUER_DOMAIN_POLICY = "issuerDomainPolicy";
  3168. const SUBJECT_DOMAIN_POLICY = "subjectDomainPolicy";
  3169. const CLEAR_PROPS$1e = [
  3170. ISSUER_DOMAIN_POLICY,
  3171. SUBJECT_DOMAIN_POLICY
  3172. ];
  3173. class PolicyMapping extends PkiObject {
  3174. constructor(parameters = {}) {
  3175. super();
  3176. this.issuerDomainPolicy = pvutils__namespace.getParametersValue(parameters, ISSUER_DOMAIN_POLICY, PolicyMapping.defaultValues(ISSUER_DOMAIN_POLICY));
  3177. this.subjectDomainPolicy = pvutils__namespace.getParametersValue(parameters, SUBJECT_DOMAIN_POLICY, PolicyMapping.defaultValues(SUBJECT_DOMAIN_POLICY));
  3178. if (parameters.schema) {
  3179. this.fromSchema(parameters.schema);
  3180. }
  3181. }
  3182. static defaultValues(memberName) {
  3183. switch (memberName) {
  3184. case ISSUER_DOMAIN_POLICY:
  3185. return EMPTY_STRING;
  3186. case SUBJECT_DOMAIN_POLICY:
  3187. return EMPTY_STRING;
  3188. default:
  3189. return super.defaultValues(memberName);
  3190. }
  3191. }
  3192. static schema(parameters = {}) {
  3193. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  3194. return (new asn1js__namespace.Sequence({
  3195. name: (names.blockName || EMPTY_STRING),
  3196. value: [
  3197. new asn1js__namespace.ObjectIdentifier({ name: (names.issuerDomainPolicy || EMPTY_STRING) }),
  3198. new asn1js__namespace.ObjectIdentifier({ name: (names.subjectDomainPolicy || EMPTY_STRING) })
  3199. ]
  3200. }));
  3201. }
  3202. fromSchema(schema) {
  3203. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1e);
  3204. const asn1 = asn1js__namespace.compareSchema(schema, schema, PolicyMapping.schema({
  3205. names: {
  3206. issuerDomainPolicy: ISSUER_DOMAIN_POLICY,
  3207. subjectDomainPolicy: SUBJECT_DOMAIN_POLICY
  3208. }
  3209. }));
  3210. AsnError.assertSchema(asn1, this.className);
  3211. this.issuerDomainPolicy = asn1.result.issuerDomainPolicy.valueBlock.toString();
  3212. this.subjectDomainPolicy = asn1.result.subjectDomainPolicy.valueBlock.toString();
  3213. }
  3214. toSchema() {
  3215. return (new asn1js__namespace.Sequence({
  3216. value: [
  3217. new asn1js__namespace.ObjectIdentifier({ value: this.issuerDomainPolicy }),
  3218. new asn1js__namespace.ObjectIdentifier({ value: this.subjectDomainPolicy })
  3219. ]
  3220. }));
  3221. }
  3222. toJSON() {
  3223. return {
  3224. issuerDomainPolicy: this.issuerDomainPolicy,
  3225. subjectDomainPolicy: this.subjectDomainPolicy
  3226. };
  3227. }
  3228. }
  3229. PolicyMapping.CLASS_NAME = "PolicyMapping";
  3230. const MAPPINGS = "mappings";
  3231. const CLEAR_PROPS$1d = [
  3232. MAPPINGS,
  3233. ];
  3234. class PolicyMappings extends PkiObject {
  3235. constructor(parameters = {}) {
  3236. super();
  3237. this.mappings = pvutils__namespace.getParametersValue(parameters, MAPPINGS, PolicyMappings.defaultValues(MAPPINGS));
  3238. if (parameters.schema) {
  3239. this.fromSchema(parameters.schema);
  3240. }
  3241. }
  3242. static defaultValues(memberName) {
  3243. switch (memberName) {
  3244. case MAPPINGS:
  3245. return [];
  3246. default:
  3247. return super.defaultValues(memberName);
  3248. }
  3249. }
  3250. static schema(parameters = {}) {
  3251. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  3252. return (new asn1js__namespace.Sequence({
  3253. name: (names.blockName || EMPTY_STRING),
  3254. value: [
  3255. new asn1js__namespace.Repeated({
  3256. name: (names.mappings || EMPTY_STRING),
  3257. value: PolicyMapping.schema()
  3258. })
  3259. ]
  3260. }));
  3261. }
  3262. fromSchema(schema) {
  3263. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1d);
  3264. const asn1 = asn1js__namespace.compareSchema(schema, schema, PolicyMappings.schema({
  3265. names: {
  3266. mappings: MAPPINGS
  3267. }
  3268. }));
  3269. AsnError.assertSchema(asn1, this.className);
  3270. this.mappings = Array.from(asn1.result.mappings, element => new PolicyMapping({ schema: element }));
  3271. }
  3272. toSchema() {
  3273. return (new asn1js__namespace.Sequence({
  3274. value: Array.from(this.mappings, o => o.toSchema())
  3275. }));
  3276. }
  3277. toJSON() {
  3278. return {
  3279. mappings: Array.from(this.mappings, o => o.toJSON())
  3280. };
  3281. }
  3282. }
  3283. PolicyMappings.CLASS_NAME = "PolicyMappings";
  3284. const NOT_BEFORE$1 = "notBefore";
  3285. const NOT_AFTER$1 = "notAfter";
  3286. const CLEAR_PROPS$1c = [
  3287. NOT_BEFORE$1,
  3288. NOT_AFTER$1
  3289. ];
  3290. class PrivateKeyUsagePeriod extends PkiObject {
  3291. constructor(parameters = {}) {
  3292. super();
  3293. if (NOT_BEFORE$1 in parameters) {
  3294. this.notBefore = pvutils__namespace.getParametersValue(parameters, NOT_BEFORE$1, PrivateKeyUsagePeriod.defaultValues(NOT_BEFORE$1));
  3295. }
  3296. if (NOT_AFTER$1 in parameters) {
  3297. this.notAfter = pvutils__namespace.getParametersValue(parameters, NOT_AFTER$1, PrivateKeyUsagePeriod.defaultValues(NOT_AFTER$1));
  3298. }
  3299. if (parameters.schema) {
  3300. this.fromSchema(parameters.schema);
  3301. }
  3302. }
  3303. static defaultValues(memberName) {
  3304. switch (memberName) {
  3305. case NOT_BEFORE$1:
  3306. return new Date();
  3307. case NOT_AFTER$1:
  3308. return new Date();
  3309. default:
  3310. return super.defaultValues(memberName);
  3311. }
  3312. }
  3313. static schema(parameters = {}) {
  3314. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  3315. return (new asn1js__namespace.Sequence({
  3316. name: (names.blockName || EMPTY_STRING),
  3317. value: [
  3318. new asn1js__namespace.Primitive({
  3319. name: (names.notBefore || EMPTY_STRING),
  3320. optional: true,
  3321. idBlock: {
  3322. tagClass: 3,
  3323. tagNumber: 0
  3324. }
  3325. }),
  3326. new asn1js__namespace.Primitive({
  3327. name: (names.notAfter || EMPTY_STRING),
  3328. optional: true,
  3329. idBlock: {
  3330. tagClass: 3,
  3331. tagNumber: 1
  3332. }
  3333. })
  3334. ]
  3335. }));
  3336. }
  3337. fromSchema(schema) {
  3338. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1c);
  3339. const asn1 = asn1js__namespace.compareSchema(schema, schema, PrivateKeyUsagePeriod.schema({
  3340. names: {
  3341. notBefore: NOT_BEFORE$1,
  3342. notAfter: NOT_AFTER$1
  3343. }
  3344. }));
  3345. AsnError.assertSchema(asn1, this.className);
  3346. if (NOT_BEFORE$1 in asn1.result) {
  3347. const localNotBefore = new asn1js__namespace.GeneralizedTime();
  3348. localNotBefore.fromBuffer(asn1.result.notBefore.valueBlock.valueHex);
  3349. this.notBefore = localNotBefore.toDate();
  3350. }
  3351. if (NOT_AFTER$1 in asn1.result) {
  3352. const localNotAfter = new asn1js__namespace.GeneralizedTime({ valueHex: asn1.result.notAfter.valueBlock.valueHex });
  3353. localNotAfter.fromBuffer(asn1.result.notAfter.valueBlock.valueHex);
  3354. this.notAfter = localNotAfter.toDate();
  3355. }
  3356. }
  3357. toSchema() {
  3358. const outputArray = [];
  3359. if (NOT_BEFORE$1 in this) {
  3360. outputArray.push(new asn1js__namespace.Primitive({
  3361. idBlock: {
  3362. tagClass: 3,
  3363. tagNumber: 0
  3364. },
  3365. valueHex: (new asn1js__namespace.GeneralizedTime({ valueDate: this.notBefore })).valueBlock.valueHexView
  3366. }));
  3367. }
  3368. if (NOT_AFTER$1 in this) {
  3369. outputArray.push(new asn1js__namespace.Primitive({
  3370. idBlock: {
  3371. tagClass: 3,
  3372. tagNumber: 1
  3373. },
  3374. valueHex: (new asn1js__namespace.GeneralizedTime({ valueDate: this.notAfter })).valueBlock.valueHexView
  3375. }));
  3376. }
  3377. return (new asn1js__namespace.Sequence({
  3378. value: outputArray
  3379. }));
  3380. }
  3381. toJSON() {
  3382. const res = {};
  3383. if (this.notBefore) {
  3384. res.notBefore = this.notBefore;
  3385. }
  3386. if (this.notAfter) {
  3387. res.notAfter = this.notAfter;
  3388. }
  3389. return res;
  3390. }
  3391. }
  3392. PrivateKeyUsagePeriod.CLASS_NAME = "PrivateKeyUsagePeriod";
  3393. const ID = "id";
  3394. const TYPE$2 = "type";
  3395. const VALUES = "values";
  3396. const QC_STATEMENT_CLEAR_PROPS = [
  3397. ID,
  3398. TYPE$2
  3399. ];
  3400. const QC_STATEMENTS_CLEAR_PROPS = [
  3401. VALUES
  3402. ];
  3403. class QCStatement extends PkiObject {
  3404. constructor(parameters = {}) {
  3405. super();
  3406. this.id = pvutils__namespace.getParametersValue(parameters, ID, QCStatement.defaultValues(ID));
  3407. if (TYPE$2 in parameters) {
  3408. this.type = pvutils__namespace.getParametersValue(parameters, TYPE$2, QCStatement.defaultValues(TYPE$2));
  3409. }
  3410. if (parameters.schema) {
  3411. this.fromSchema(parameters.schema);
  3412. }
  3413. }
  3414. static defaultValues(memberName) {
  3415. switch (memberName) {
  3416. case ID:
  3417. return EMPTY_STRING;
  3418. case TYPE$2:
  3419. return new asn1js__namespace.Null();
  3420. default:
  3421. return super.defaultValues(memberName);
  3422. }
  3423. }
  3424. static compareWithDefault(memberName, memberValue) {
  3425. switch (memberName) {
  3426. case ID:
  3427. return (memberValue === EMPTY_STRING);
  3428. case TYPE$2:
  3429. return (memberValue instanceof asn1js__namespace.Null);
  3430. default:
  3431. return super.defaultValues(memberName);
  3432. }
  3433. }
  3434. static schema(parameters = {}) {
  3435. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  3436. return (new asn1js__namespace.Sequence({
  3437. name: (names.blockName || EMPTY_STRING),
  3438. value: [
  3439. new asn1js__namespace.ObjectIdentifier({ name: (names.id || EMPTY_STRING) }),
  3440. new asn1js__namespace.Any({
  3441. name: (names.type || EMPTY_STRING),
  3442. optional: true
  3443. })
  3444. ]
  3445. }));
  3446. }
  3447. fromSchema(schema) {
  3448. pvutils__namespace.clearProps(schema, QC_STATEMENT_CLEAR_PROPS);
  3449. const asn1 = asn1js__namespace.compareSchema(schema, schema, QCStatement.schema({
  3450. names: {
  3451. id: ID,
  3452. type: TYPE$2
  3453. }
  3454. }));
  3455. AsnError.assertSchema(asn1, this.className);
  3456. this.id = asn1.result.id.valueBlock.toString();
  3457. if (TYPE$2 in asn1.result)
  3458. this.type = asn1.result.type;
  3459. }
  3460. toSchema() {
  3461. const value = [
  3462. new asn1js__namespace.ObjectIdentifier({ value: this.id })
  3463. ];
  3464. if (TYPE$2 in this)
  3465. value.push(this.type);
  3466. return (new asn1js__namespace.Sequence({
  3467. value,
  3468. }));
  3469. }
  3470. toJSON() {
  3471. const object = {
  3472. id: this.id
  3473. };
  3474. if (this.type) {
  3475. object.type = this.type.toJSON();
  3476. }
  3477. return object;
  3478. }
  3479. }
  3480. QCStatement.CLASS_NAME = "QCStatement";
  3481. class QCStatements extends PkiObject {
  3482. constructor(parameters = {}) {
  3483. super();
  3484. this.values = pvutils__namespace.getParametersValue(parameters, VALUES, QCStatements.defaultValues(VALUES));
  3485. if (parameters.schema) {
  3486. this.fromSchema(parameters.schema);
  3487. }
  3488. }
  3489. static defaultValues(memberName) {
  3490. switch (memberName) {
  3491. case VALUES:
  3492. return [];
  3493. default:
  3494. return super.defaultValues(memberName);
  3495. }
  3496. }
  3497. static compareWithDefault(memberName, memberValue) {
  3498. switch (memberName) {
  3499. case VALUES:
  3500. return (memberValue.length === 0);
  3501. default:
  3502. return super.defaultValues(memberName);
  3503. }
  3504. }
  3505. static schema(parameters = {}) {
  3506. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  3507. return (new asn1js__namespace.Sequence({
  3508. name: (names.blockName || EMPTY_STRING),
  3509. value: [
  3510. new asn1js__namespace.Repeated({
  3511. name: (names.values || EMPTY_STRING),
  3512. value: QCStatement.schema(names.value || {})
  3513. }),
  3514. ]
  3515. }));
  3516. }
  3517. fromSchema(schema) {
  3518. pvutils__namespace.clearProps(schema, QC_STATEMENTS_CLEAR_PROPS);
  3519. const asn1 = asn1js__namespace.compareSchema(schema, schema, QCStatements.schema({
  3520. names: {
  3521. values: VALUES
  3522. }
  3523. }));
  3524. AsnError.assertSchema(asn1, this.className);
  3525. this.values = Array.from(asn1.result.values, element => new QCStatement({ schema: element }));
  3526. }
  3527. toSchema() {
  3528. return (new asn1js__namespace.Sequence({
  3529. value: Array.from(this.values, o => o.toSchema())
  3530. }));
  3531. }
  3532. toJSON() {
  3533. return {
  3534. values: Array.from(this.values, o => o.toJSON())
  3535. };
  3536. }
  3537. }
  3538. QCStatements.CLASS_NAME = "QCStatements";
  3539. var _a;
  3540. class ECNamedCurves {
  3541. static register(name, id, size) {
  3542. this.namedCurves[name.toLowerCase()] = this.namedCurves[id] = { name, id, size };
  3543. }
  3544. static find(nameOrId) {
  3545. return this.namedCurves[nameOrId.toLowerCase()] || null;
  3546. }
  3547. }
  3548. _a = ECNamedCurves;
  3549. ECNamedCurves.namedCurves = {};
  3550. (() => {
  3551. _a.register("P-256", "1.2.840.10045.3.1.7", 32);
  3552. _a.register("P-384", "1.3.132.0.34", 48);
  3553. _a.register("P-521", "1.3.132.0.35", 66);
  3554. _a.register("brainpoolP256r1", "1.3.36.3.3.2.8.1.1.7", 32);
  3555. _a.register("brainpoolP384r1", "1.3.36.3.3.2.8.1.1.11", 48);
  3556. _a.register("brainpoolP512r1", "1.3.36.3.3.2.8.1.1.13", 64);
  3557. })();
  3558. const X = "x";
  3559. const Y = "y";
  3560. const NAMED_CURVE$1 = "namedCurve";
  3561. class ECPublicKey extends PkiObject {
  3562. constructor(parameters = {}) {
  3563. super();
  3564. this.x = pvutils__namespace.getParametersValue(parameters, X, ECPublicKey.defaultValues(X));
  3565. this.y = pvutils__namespace.getParametersValue(parameters, Y, ECPublicKey.defaultValues(Y));
  3566. this.namedCurve = pvutils__namespace.getParametersValue(parameters, NAMED_CURVE$1, ECPublicKey.defaultValues(NAMED_CURVE$1));
  3567. if (parameters.json) {
  3568. this.fromJSON(parameters.json);
  3569. }
  3570. if (parameters.schema) {
  3571. this.fromSchema(parameters.schema);
  3572. }
  3573. }
  3574. static defaultValues(memberName) {
  3575. switch (memberName) {
  3576. case X:
  3577. case Y:
  3578. return EMPTY_BUFFER;
  3579. case NAMED_CURVE$1:
  3580. return EMPTY_STRING;
  3581. default:
  3582. return super.defaultValues(memberName);
  3583. }
  3584. }
  3585. static compareWithDefault(memberName, memberValue) {
  3586. switch (memberName) {
  3587. case X:
  3588. case Y:
  3589. return memberValue instanceof ArrayBuffer &&
  3590. (pvutils__namespace.isEqualBuffer(memberValue, ECPublicKey.defaultValues(memberName)));
  3591. case NAMED_CURVE$1:
  3592. return typeof memberValue === "string" &&
  3593. memberValue === ECPublicKey.defaultValues(memberName);
  3594. default:
  3595. return super.defaultValues(memberName);
  3596. }
  3597. }
  3598. static schema() {
  3599. return new asn1js__namespace.RawData();
  3600. }
  3601. fromSchema(schema1) {
  3602. const view = pvtsutils.BufferSourceConverter.toUint8Array(schema1);
  3603. if (view[0] !== 0x04) {
  3604. throw new Error("Object's schema was not verified against input data for ECPublicKey");
  3605. }
  3606. const namedCurve = ECNamedCurves.find(this.namedCurve);
  3607. if (!namedCurve) {
  3608. throw new Error(`Incorrect curve OID: ${this.namedCurve}`);
  3609. }
  3610. const coordinateLength = namedCurve.size;
  3611. if (view.byteLength !== (coordinateLength * 2 + 1)) {
  3612. throw new Error("Object's schema was not verified against input data for ECPublicKey");
  3613. }
  3614. this.namedCurve = namedCurve.name;
  3615. this.x = view.slice(1, coordinateLength + 1).buffer;
  3616. this.y = view.slice(1 + coordinateLength, coordinateLength * 2 + 1).buffer;
  3617. }
  3618. toSchema() {
  3619. return new asn1js__namespace.RawData({
  3620. data: pvutils__namespace.utilConcatBuf((new Uint8Array([0x04])).buffer, this.x, this.y)
  3621. });
  3622. }
  3623. toJSON() {
  3624. const namedCurve = ECNamedCurves.find(this.namedCurve);
  3625. return {
  3626. crv: namedCurve ? namedCurve.name : this.namedCurve,
  3627. x: pvutils__namespace.toBase64(pvutils__namespace.arrayBufferToString(this.x), true, true, false),
  3628. y: pvutils__namespace.toBase64(pvutils__namespace.arrayBufferToString(this.y), true, true, false)
  3629. };
  3630. }
  3631. fromJSON(json) {
  3632. ParameterError.assert("json", json, "crv", "x", "y");
  3633. let coordinateLength = 0;
  3634. const namedCurve = ECNamedCurves.find(json.crv);
  3635. if (namedCurve) {
  3636. this.namedCurve = namedCurve.id;
  3637. coordinateLength = namedCurve.size;
  3638. }
  3639. const xConvertBuffer = pvutils__namespace.stringToArrayBuffer(pvutils__namespace.fromBase64(json.x, true));
  3640. if (xConvertBuffer.byteLength < coordinateLength) {
  3641. this.x = new ArrayBuffer(coordinateLength);
  3642. const view = new Uint8Array(this.x);
  3643. const convertBufferView = new Uint8Array(xConvertBuffer);
  3644. view.set(convertBufferView, 1);
  3645. }
  3646. else {
  3647. this.x = xConvertBuffer.slice(0, coordinateLength);
  3648. }
  3649. const yConvertBuffer = pvutils__namespace.stringToArrayBuffer(pvutils__namespace.fromBase64(json.y, true));
  3650. if (yConvertBuffer.byteLength < coordinateLength) {
  3651. this.y = new ArrayBuffer(coordinateLength);
  3652. const view = new Uint8Array(this.y);
  3653. const convertBufferView = new Uint8Array(yConvertBuffer);
  3654. view.set(convertBufferView, 1);
  3655. }
  3656. else {
  3657. this.y = yConvertBuffer.slice(0, coordinateLength);
  3658. }
  3659. }
  3660. }
  3661. ECPublicKey.CLASS_NAME = "ECPublicKey";
  3662. const MODULUS$1 = "modulus";
  3663. const PUBLIC_EXPONENT$1 = "publicExponent";
  3664. const CLEAR_PROPS$1b = [MODULUS$1, PUBLIC_EXPONENT$1];
  3665. class RSAPublicKey extends PkiObject {
  3666. constructor(parameters = {}) {
  3667. super();
  3668. this.modulus = pvutils__namespace.getParametersValue(parameters, MODULUS$1, RSAPublicKey.defaultValues(MODULUS$1));
  3669. this.publicExponent = pvutils__namespace.getParametersValue(parameters, PUBLIC_EXPONENT$1, RSAPublicKey.defaultValues(PUBLIC_EXPONENT$1));
  3670. if (parameters.json) {
  3671. this.fromJSON(parameters.json);
  3672. }
  3673. if (parameters.schema) {
  3674. this.fromSchema(parameters.schema);
  3675. }
  3676. }
  3677. static defaultValues(memberName) {
  3678. switch (memberName) {
  3679. case MODULUS$1:
  3680. return new asn1js__namespace.Integer();
  3681. case PUBLIC_EXPONENT$1:
  3682. return new asn1js__namespace.Integer();
  3683. default:
  3684. return super.defaultValues(memberName);
  3685. }
  3686. }
  3687. static schema(parameters = {}) {
  3688. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  3689. return (new asn1js__namespace.Sequence({
  3690. name: (names.blockName || EMPTY_STRING),
  3691. value: [
  3692. new asn1js__namespace.Integer({ name: (names.modulus || EMPTY_STRING) }),
  3693. new asn1js__namespace.Integer({ name: (names.publicExponent || EMPTY_STRING) })
  3694. ]
  3695. }));
  3696. }
  3697. fromSchema(schema) {
  3698. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1b);
  3699. const asn1 = asn1js__namespace.compareSchema(schema, schema, RSAPublicKey.schema({
  3700. names: {
  3701. modulus: MODULUS$1,
  3702. publicExponent: PUBLIC_EXPONENT$1
  3703. }
  3704. }));
  3705. AsnError.assertSchema(asn1, this.className);
  3706. this.modulus = asn1.result.modulus.convertFromDER(256);
  3707. this.publicExponent = asn1.result.publicExponent;
  3708. }
  3709. toSchema() {
  3710. return (new asn1js__namespace.Sequence({
  3711. value: [
  3712. this.modulus.convertToDER(),
  3713. this.publicExponent
  3714. ]
  3715. }));
  3716. }
  3717. toJSON() {
  3718. return {
  3719. n: pvtsutils__namespace.Convert.ToBase64Url(this.modulus.valueBlock.valueHexView),
  3720. e: pvtsutils__namespace.Convert.ToBase64Url(this.publicExponent.valueBlock.valueHexView),
  3721. };
  3722. }
  3723. fromJSON(json) {
  3724. ParameterError.assert("json", json, "n", "e");
  3725. const array = pvutils__namespace.stringToArrayBuffer(pvutils__namespace.fromBase64(json.n, true));
  3726. this.modulus = new asn1js__namespace.Integer({ valueHex: array.slice(0, Math.pow(2, pvutils__namespace.nearestPowerOf2(array.byteLength))) });
  3727. this.publicExponent = new asn1js__namespace.Integer({ valueHex: pvutils__namespace.stringToArrayBuffer(pvutils__namespace.fromBase64(json.e, true)).slice(0, 3) });
  3728. }
  3729. }
  3730. RSAPublicKey.CLASS_NAME = "RSAPublicKey";
  3731. const ALGORITHM$1 = "algorithm";
  3732. const SUBJECT_PUBLIC_KEY = "subjectPublicKey";
  3733. const CLEAR_PROPS$1a = [ALGORITHM$1, SUBJECT_PUBLIC_KEY];
  3734. class PublicKeyInfo extends PkiObject {
  3735. get parsedKey() {
  3736. if (this._parsedKey === undefined) {
  3737. switch (this.algorithm.algorithmId) {
  3738. case "1.2.840.10045.2.1":
  3739. if ("algorithmParams" in this.algorithm) {
  3740. if (this.algorithm.algorithmParams.constructor.blockName() === asn1js__namespace.ObjectIdentifier.blockName()) {
  3741. try {
  3742. this._parsedKey = new ECPublicKey({
  3743. namedCurve: this.algorithm.algorithmParams.valueBlock.toString(),
  3744. schema: this.subjectPublicKey.valueBlock.valueHexView
  3745. });
  3746. }
  3747. catch {
  3748. }
  3749. }
  3750. }
  3751. break;
  3752. case "1.2.840.113549.1.1.1":
  3753. case "1.2.840.113549.1.1.10":
  3754. {
  3755. const publicKeyASN1 = asn1js__namespace.fromBER(this.subjectPublicKey.valueBlock.valueHexView);
  3756. if (publicKeyASN1.offset !== -1) {
  3757. try {
  3758. this._parsedKey = new RSAPublicKey({ schema: publicKeyASN1.result });
  3759. }
  3760. catch {
  3761. }
  3762. }
  3763. }
  3764. break;
  3765. }
  3766. this._parsedKey || (this._parsedKey = null);
  3767. }
  3768. return this._parsedKey || undefined;
  3769. }
  3770. set parsedKey(value) {
  3771. this._parsedKey = value;
  3772. }
  3773. constructor(parameters = {}) {
  3774. super();
  3775. this.algorithm = pvutils__namespace.getParametersValue(parameters, ALGORITHM$1, PublicKeyInfo.defaultValues(ALGORITHM$1));
  3776. this.subjectPublicKey = pvutils__namespace.getParametersValue(parameters, SUBJECT_PUBLIC_KEY, PublicKeyInfo.defaultValues(SUBJECT_PUBLIC_KEY));
  3777. const parsedKey = pvutils__namespace.getParametersValue(parameters, "parsedKey", null);
  3778. if (parsedKey) {
  3779. this.parsedKey = parsedKey;
  3780. }
  3781. if (parameters.json) {
  3782. this.fromJSON(parameters.json);
  3783. }
  3784. if (parameters.schema) {
  3785. this.fromSchema(parameters.schema);
  3786. }
  3787. }
  3788. static defaultValues(memberName) {
  3789. switch (memberName) {
  3790. case ALGORITHM$1:
  3791. return new AlgorithmIdentifier();
  3792. case SUBJECT_PUBLIC_KEY:
  3793. return new asn1js__namespace.BitString();
  3794. default:
  3795. return super.defaultValues(memberName);
  3796. }
  3797. }
  3798. static schema(parameters = {}) {
  3799. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  3800. return (new asn1js__namespace.Sequence({
  3801. name: (names.blockName || EMPTY_STRING),
  3802. value: [
  3803. AlgorithmIdentifier.schema(names.algorithm || {}),
  3804. new asn1js__namespace.BitString({ name: (names.subjectPublicKey || EMPTY_STRING) })
  3805. ]
  3806. }));
  3807. }
  3808. fromSchema(schema) {
  3809. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1a);
  3810. const asn1 = asn1js__namespace.compareSchema(schema, schema, PublicKeyInfo.schema({
  3811. names: {
  3812. algorithm: {
  3813. names: {
  3814. blockName: ALGORITHM$1
  3815. }
  3816. },
  3817. subjectPublicKey: SUBJECT_PUBLIC_KEY
  3818. }
  3819. }));
  3820. AsnError.assertSchema(asn1, this.className);
  3821. this.algorithm = new AlgorithmIdentifier({ schema: asn1.result.algorithm });
  3822. this.subjectPublicKey = asn1.result.subjectPublicKey;
  3823. }
  3824. toSchema() {
  3825. return (new asn1js__namespace.Sequence({
  3826. value: [
  3827. this.algorithm.toSchema(),
  3828. this.subjectPublicKey
  3829. ]
  3830. }));
  3831. }
  3832. toJSON() {
  3833. if (!this.parsedKey) {
  3834. return {
  3835. algorithm: this.algorithm.toJSON(),
  3836. subjectPublicKey: this.subjectPublicKey.toJSON(),
  3837. };
  3838. }
  3839. const jwk = {};
  3840. switch (this.algorithm.algorithmId) {
  3841. case "1.2.840.10045.2.1":
  3842. jwk.kty = "EC";
  3843. break;
  3844. case "1.2.840.113549.1.1.1":
  3845. case "1.2.840.113549.1.1.10":
  3846. jwk.kty = "RSA";
  3847. break;
  3848. }
  3849. const publicKeyJWK = this.parsedKey.toJSON();
  3850. Object.assign(jwk, publicKeyJWK);
  3851. return jwk;
  3852. }
  3853. fromJSON(json) {
  3854. if ("kty" in json) {
  3855. switch (json.kty.toUpperCase()) {
  3856. case "EC":
  3857. this.parsedKey = new ECPublicKey({ json });
  3858. this.algorithm = new AlgorithmIdentifier({
  3859. algorithmId: "1.2.840.10045.2.1",
  3860. algorithmParams: new asn1js__namespace.ObjectIdentifier({ value: this.parsedKey.namedCurve })
  3861. });
  3862. break;
  3863. case "RSA":
  3864. this.parsedKey = new RSAPublicKey({ json });
  3865. this.algorithm = new AlgorithmIdentifier({
  3866. algorithmId: "1.2.840.113549.1.1.1",
  3867. algorithmParams: new asn1js__namespace.Null()
  3868. });
  3869. break;
  3870. default:
  3871. throw new Error(`Invalid value for "kty" parameter: ${json.kty}`);
  3872. }
  3873. this.subjectPublicKey = new asn1js__namespace.BitString({ valueHex: this.parsedKey.toSchema().toBER(false) });
  3874. }
  3875. }
  3876. async importKey(publicKey, crypto = getCrypto(true)) {
  3877. try {
  3878. if (!publicKey) {
  3879. throw new Error("Need to provide publicKey input parameter");
  3880. }
  3881. const exportedKey = await crypto.exportKey("spki", publicKey);
  3882. const asn1 = asn1js__namespace.fromBER(exportedKey);
  3883. try {
  3884. this.fromSchema(asn1.result);
  3885. }
  3886. catch {
  3887. throw new Error("Error during initializing object from schema");
  3888. }
  3889. }
  3890. catch (e) {
  3891. const message = e instanceof Error ? e.message : `${e}`;
  3892. throw new Error(`Error during exporting public key: ${message}`);
  3893. }
  3894. }
  3895. }
  3896. PublicKeyInfo.CLASS_NAME = "PublicKeyInfo";
  3897. const VERSION$l = "version";
  3898. const PRIVATE_KEY$1 = "privateKey";
  3899. const NAMED_CURVE = "namedCurve";
  3900. const PUBLIC_KEY$1 = "publicKey";
  3901. const CLEAR_PROPS$19 = [
  3902. VERSION$l,
  3903. PRIVATE_KEY$1,
  3904. NAMED_CURVE,
  3905. PUBLIC_KEY$1
  3906. ];
  3907. class ECPrivateKey extends PkiObject {
  3908. constructor(parameters = {}) {
  3909. super();
  3910. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$l, ECPrivateKey.defaultValues(VERSION$l));
  3911. this.privateKey = pvutils__namespace.getParametersValue(parameters, PRIVATE_KEY$1, ECPrivateKey.defaultValues(PRIVATE_KEY$1));
  3912. if (NAMED_CURVE in parameters) {
  3913. this.namedCurve = pvutils__namespace.getParametersValue(parameters, NAMED_CURVE, ECPrivateKey.defaultValues(NAMED_CURVE));
  3914. }
  3915. if (PUBLIC_KEY$1 in parameters) {
  3916. this.publicKey = pvutils__namespace.getParametersValue(parameters, PUBLIC_KEY$1, ECPrivateKey.defaultValues(PUBLIC_KEY$1));
  3917. }
  3918. if (parameters.json) {
  3919. this.fromJSON(parameters.json);
  3920. }
  3921. if (parameters.schema) {
  3922. this.fromSchema(parameters.schema);
  3923. }
  3924. }
  3925. static defaultValues(memberName) {
  3926. switch (memberName) {
  3927. case VERSION$l:
  3928. return 1;
  3929. case PRIVATE_KEY$1:
  3930. return new asn1js__namespace.OctetString();
  3931. case NAMED_CURVE:
  3932. return EMPTY_STRING;
  3933. case PUBLIC_KEY$1:
  3934. return new ECPublicKey();
  3935. default:
  3936. return super.defaultValues(memberName);
  3937. }
  3938. }
  3939. static compareWithDefault(memberName, memberValue) {
  3940. switch (memberName) {
  3941. case VERSION$l:
  3942. return (memberValue === ECPrivateKey.defaultValues(memberName));
  3943. case PRIVATE_KEY$1:
  3944. return (memberValue.isEqual(ECPrivateKey.defaultValues(memberName)));
  3945. case NAMED_CURVE:
  3946. return (memberValue === EMPTY_STRING);
  3947. case PUBLIC_KEY$1:
  3948. return ((ECPublicKey.compareWithDefault(NAMED_CURVE, memberValue.namedCurve)) &&
  3949. (ECPublicKey.compareWithDefault("x", memberValue.x)) &&
  3950. (ECPublicKey.compareWithDefault("y", memberValue.y)));
  3951. default:
  3952. return super.defaultValues(memberName);
  3953. }
  3954. }
  3955. static schema(parameters = {}) {
  3956. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  3957. return (new asn1js__namespace.Sequence({
  3958. name: (names.blockName || EMPTY_STRING),
  3959. value: [
  3960. new asn1js__namespace.Integer({ name: (names.version || EMPTY_STRING) }),
  3961. new asn1js__namespace.OctetString({ name: (names.privateKey || EMPTY_STRING) }),
  3962. new asn1js__namespace.Constructed({
  3963. optional: true,
  3964. idBlock: {
  3965. tagClass: 3,
  3966. tagNumber: 0
  3967. },
  3968. value: [
  3969. new asn1js__namespace.ObjectIdentifier({ name: (names.namedCurve || EMPTY_STRING) })
  3970. ]
  3971. }),
  3972. new asn1js__namespace.Constructed({
  3973. optional: true,
  3974. idBlock: {
  3975. tagClass: 3,
  3976. tagNumber: 1
  3977. },
  3978. value: [
  3979. new asn1js__namespace.BitString({ name: (names.publicKey || EMPTY_STRING) })
  3980. ]
  3981. })
  3982. ]
  3983. }));
  3984. }
  3985. fromSchema(schema) {
  3986. pvutils__namespace.clearProps(schema, CLEAR_PROPS$19);
  3987. const asn1 = asn1js__namespace.compareSchema(schema, schema, ECPrivateKey.schema({
  3988. names: {
  3989. version: VERSION$l,
  3990. privateKey: PRIVATE_KEY$1,
  3991. namedCurve: NAMED_CURVE,
  3992. publicKey: PUBLIC_KEY$1
  3993. }
  3994. }));
  3995. AsnError.assertSchema(asn1, this.className);
  3996. this.version = asn1.result.version.valueBlock.valueDec;
  3997. this.privateKey = asn1.result.privateKey;
  3998. if (NAMED_CURVE in asn1.result) {
  3999. this.namedCurve = asn1.result.namedCurve.valueBlock.toString();
  4000. }
  4001. if (PUBLIC_KEY$1 in asn1.result) {
  4002. const publicKeyData = { schema: asn1.result.publicKey.valueBlock.valueHex };
  4003. if (NAMED_CURVE in this) {
  4004. publicKeyData.namedCurve = this.namedCurve;
  4005. }
  4006. this.publicKey = new ECPublicKey(publicKeyData);
  4007. }
  4008. }
  4009. toSchema() {
  4010. const outputArray = [
  4011. new asn1js__namespace.Integer({ value: this.version }),
  4012. this.privateKey
  4013. ];
  4014. if (this.namedCurve) {
  4015. outputArray.push(new asn1js__namespace.Constructed({
  4016. idBlock: {
  4017. tagClass: 3,
  4018. tagNumber: 0
  4019. },
  4020. value: [
  4021. new asn1js__namespace.ObjectIdentifier({ value: this.namedCurve })
  4022. ]
  4023. }));
  4024. }
  4025. if (this.publicKey) {
  4026. outputArray.push(new asn1js__namespace.Constructed({
  4027. idBlock: {
  4028. tagClass: 3,
  4029. tagNumber: 1
  4030. },
  4031. value: [
  4032. new asn1js__namespace.BitString({ valueHex: this.publicKey.toSchema().toBER(false) })
  4033. ]
  4034. }));
  4035. }
  4036. return new asn1js__namespace.Sequence({
  4037. value: outputArray
  4038. });
  4039. }
  4040. toJSON() {
  4041. if (!this.namedCurve || ECPrivateKey.compareWithDefault(NAMED_CURVE, this.namedCurve)) {
  4042. throw new Error("Not enough information for making JSON: absent \"namedCurve\" value");
  4043. }
  4044. const curve = ECNamedCurves.find(this.namedCurve);
  4045. const privateKeyJSON = {
  4046. crv: curve ? curve.name : this.namedCurve,
  4047. d: pvtsutils__namespace.Convert.ToBase64Url(this.privateKey.valueBlock.valueHexView),
  4048. };
  4049. if (this.publicKey) {
  4050. const publicKeyJSON = this.publicKey.toJSON();
  4051. privateKeyJSON.x = publicKeyJSON.x;
  4052. privateKeyJSON.y = publicKeyJSON.y;
  4053. }
  4054. return privateKeyJSON;
  4055. }
  4056. fromJSON(json) {
  4057. ParameterError.assert("json", json, "crv", "d");
  4058. let coordinateLength = 0;
  4059. const curve = ECNamedCurves.find(json.crv);
  4060. if (curve) {
  4061. this.namedCurve = curve.id;
  4062. coordinateLength = curve.size;
  4063. }
  4064. const convertBuffer = pvtsutils__namespace.Convert.FromBase64Url(json.d);
  4065. if (convertBuffer.byteLength < coordinateLength) {
  4066. const buffer = new ArrayBuffer(coordinateLength);
  4067. const view = new Uint8Array(buffer);
  4068. const convertBufferView = new Uint8Array(convertBuffer);
  4069. view.set(convertBufferView, 1);
  4070. this.privateKey = new asn1js__namespace.OctetString({ valueHex: buffer });
  4071. }
  4072. else {
  4073. this.privateKey = new asn1js__namespace.OctetString({ valueHex: convertBuffer.slice(0, coordinateLength) });
  4074. }
  4075. if (json.x && json.y) {
  4076. this.publicKey = new ECPublicKey({ json });
  4077. }
  4078. }
  4079. }
  4080. ECPrivateKey.CLASS_NAME = "ECPrivateKey";
  4081. const PRIME = "prime";
  4082. const EXPONENT = "exponent";
  4083. const COEFFICIENT$1 = "coefficient";
  4084. const CLEAR_PROPS$18 = [
  4085. PRIME,
  4086. EXPONENT,
  4087. COEFFICIENT$1,
  4088. ];
  4089. class OtherPrimeInfo extends PkiObject {
  4090. constructor(parameters = {}) {
  4091. super();
  4092. this.prime = pvutils__namespace.getParametersValue(parameters, PRIME, OtherPrimeInfo.defaultValues(PRIME));
  4093. this.exponent = pvutils__namespace.getParametersValue(parameters, EXPONENT, OtherPrimeInfo.defaultValues(EXPONENT));
  4094. this.coefficient = pvutils__namespace.getParametersValue(parameters, COEFFICIENT$1, OtherPrimeInfo.defaultValues(COEFFICIENT$1));
  4095. if (parameters.json) {
  4096. this.fromJSON(parameters.json);
  4097. }
  4098. if (parameters.schema) {
  4099. this.fromSchema(parameters.schema);
  4100. }
  4101. }
  4102. static defaultValues(memberName) {
  4103. switch (memberName) {
  4104. case PRIME:
  4105. return new asn1js__namespace.Integer();
  4106. case EXPONENT:
  4107. return new asn1js__namespace.Integer();
  4108. case COEFFICIENT$1:
  4109. return new asn1js__namespace.Integer();
  4110. default:
  4111. return super.defaultValues(memberName);
  4112. }
  4113. }
  4114. static schema(parameters = {}) {
  4115. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  4116. return (new asn1js__namespace.Sequence({
  4117. name: (names.blockName || EMPTY_STRING),
  4118. value: [
  4119. new asn1js__namespace.Integer({ name: (names.prime || EMPTY_STRING) }),
  4120. new asn1js__namespace.Integer({ name: (names.exponent || EMPTY_STRING) }),
  4121. new asn1js__namespace.Integer({ name: (names.coefficient || EMPTY_STRING) })
  4122. ]
  4123. }));
  4124. }
  4125. fromSchema(schema) {
  4126. pvutils__namespace.clearProps(schema, CLEAR_PROPS$18);
  4127. const asn1 = asn1js__namespace.compareSchema(schema, schema, OtherPrimeInfo.schema({
  4128. names: {
  4129. prime: PRIME,
  4130. exponent: EXPONENT,
  4131. coefficient: COEFFICIENT$1
  4132. }
  4133. }));
  4134. AsnError.assertSchema(asn1, this.className);
  4135. this.prime = asn1.result.prime.convertFromDER();
  4136. this.exponent = asn1.result.exponent.convertFromDER();
  4137. this.coefficient = asn1.result.coefficient.convertFromDER();
  4138. }
  4139. toSchema() {
  4140. return (new asn1js__namespace.Sequence({
  4141. value: [
  4142. this.prime.convertToDER(),
  4143. this.exponent.convertToDER(),
  4144. this.coefficient.convertToDER()
  4145. ]
  4146. }));
  4147. }
  4148. toJSON() {
  4149. return {
  4150. r: pvtsutils__namespace.Convert.ToBase64Url(this.prime.valueBlock.valueHexView),
  4151. d: pvtsutils__namespace.Convert.ToBase64Url(this.exponent.valueBlock.valueHexView),
  4152. t: pvtsutils__namespace.Convert.ToBase64Url(this.coefficient.valueBlock.valueHexView),
  4153. };
  4154. }
  4155. fromJSON(json) {
  4156. ParameterError.assert("json", json, "r", "d", "r");
  4157. this.prime = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.r) });
  4158. this.exponent = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.d) });
  4159. this.coefficient = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.t) });
  4160. }
  4161. }
  4162. OtherPrimeInfo.CLASS_NAME = "OtherPrimeInfo";
  4163. const VERSION$k = "version";
  4164. const MODULUS = "modulus";
  4165. const PUBLIC_EXPONENT = "publicExponent";
  4166. const PRIVATE_EXPONENT = "privateExponent";
  4167. const PRIME1 = "prime1";
  4168. const PRIME2 = "prime2";
  4169. const EXPONENT1 = "exponent1";
  4170. const EXPONENT2 = "exponent2";
  4171. const COEFFICIENT = "coefficient";
  4172. const OTHER_PRIME_INFOS = "otherPrimeInfos";
  4173. const CLEAR_PROPS$17 = [
  4174. VERSION$k,
  4175. MODULUS,
  4176. PUBLIC_EXPONENT,
  4177. PRIVATE_EXPONENT,
  4178. PRIME1,
  4179. PRIME2,
  4180. EXPONENT1,
  4181. EXPONENT2,
  4182. COEFFICIENT,
  4183. OTHER_PRIME_INFOS
  4184. ];
  4185. class RSAPrivateKey extends PkiObject {
  4186. constructor(parameters = {}) {
  4187. super();
  4188. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$k, RSAPrivateKey.defaultValues(VERSION$k));
  4189. this.modulus = pvutils__namespace.getParametersValue(parameters, MODULUS, RSAPrivateKey.defaultValues(MODULUS));
  4190. this.publicExponent = pvutils__namespace.getParametersValue(parameters, PUBLIC_EXPONENT, RSAPrivateKey.defaultValues(PUBLIC_EXPONENT));
  4191. this.privateExponent = pvutils__namespace.getParametersValue(parameters, PRIVATE_EXPONENT, RSAPrivateKey.defaultValues(PRIVATE_EXPONENT));
  4192. this.prime1 = pvutils__namespace.getParametersValue(parameters, PRIME1, RSAPrivateKey.defaultValues(PRIME1));
  4193. this.prime2 = pvutils__namespace.getParametersValue(parameters, PRIME2, RSAPrivateKey.defaultValues(PRIME2));
  4194. this.exponent1 = pvutils__namespace.getParametersValue(parameters, EXPONENT1, RSAPrivateKey.defaultValues(EXPONENT1));
  4195. this.exponent2 = pvutils__namespace.getParametersValue(parameters, EXPONENT2, RSAPrivateKey.defaultValues(EXPONENT2));
  4196. this.coefficient = pvutils__namespace.getParametersValue(parameters, COEFFICIENT, RSAPrivateKey.defaultValues(COEFFICIENT));
  4197. if (OTHER_PRIME_INFOS in parameters) {
  4198. this.otherPrimeInfos = pvutils__namespace.getParametersValue(parameters, OTHER_PRIME_INFOS, RSAPrivateKey.defaultValues(OTHER_PRIME_INFOS));
  4199. }
  4200. if (parameters.json) {
  4201. this.fromJSON(parameters.json);
  4202. }
  4203. if (parameters.schema) {
  4204. this.fromSchema(parameters.schema);
  4205. }
  4206. }
  4207. static defaultValues(memberName) {
  4208. switch (memberName) {
  4209. case VERSION$k:
  4210. return 0;
  4211. case MODULUS:
  4212. return new asn1js__namespace.Integer();
  4213. case PUBLIC_EXPONENT:
  4214. return new asn1js__namespace.Integer();
  4215. case PRIVATE_EXPONENT:
  4216. return new asn1js__namespace.Integer();
  4217. case PRIME1:
  4218. return new asn1js__namespace.Integer();
  4219. case PRIME2:
  4220. return new asn1js__namespace.Integer();
  4221. case EXPONENT1:
  4222. return new asn1js__namespace.Integer();
  4223. case EXPONENT2:
  4224. return new asn1js__namespace.Integer();
  4225. case COEFFICIENT:
  4226. return new asn1js__namespace.Integer();
  4227. case OTHER_PRIME_INFOS:
  4228. return [];
  4229. default:
  4230. return super.defaultValues(memberName);
  4231. }
  4232. }
  4233. static schema(parameters = {}) {
  4234. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  4235. return (new asn1js__namespace.Sequence({
  4236. name: (names.blockName || EMPTY_STRING),
  4237. value: [
  4238. new asn1js__namespace.Integer({ name: (names.version || EMPTY_STRING) }),
  4239. new asn1js__namespace.Integer({ name: (names.modulus || EMPTY_STRING) }),
  4240. new asn1js__namespace.Integer({ name: (names.publicExponent || EMPTY_STRING) }),
  4241. new asn1js__namespace.Integer({ name: (names.privateExponent || EMPTY_STRING) }),
  4242. new asn1js__namespace.Integer({ name: (names.prime1 || EMPTY_STRING) }),
  4243. new asn1js__namespace.Integer({ name: (names.prime2 || EMPTY_STRING) }),
  4244. new asn1js__namespace.Integer({ name: (names.exponent1 || EMPTY_STRING) }),
  4245. new asn1js__namespace.Integer({ name: (names.exponent2 || EMPTY_STRING) }),
  4246. new asn1js__namespace.Integer({ name: (names.coefficient || EMPTY_STRING) }),
  4247. new asn1js__namespace.Sequence({
  4248. optional: true,
  4249. value: [
  4250. new asn1js__namespace.Repeated({
  4251. name: (names.otherPrimeInfosName || EMPTY_STRING),
  4252. value: OtherPrimeInfo.schema(names.otherPrimeInfo || {})
  4253. })
  4254. ]
  4255. })
  4256. ]
  4257. }));
  4258. }
  4259. fromSchema(schema) {
  4260. pvutils__namespace.clearProps(schema, CLEAR_PROPS$17);
  4261. const asn1 = asn1js__namespace.compareSchema(schema, schema, RSAPrivateKey.schema({
  4262. names: {
  4263. version: VERSION$k,
  4264. modulus: MODULUS,
  4265. publicExponent: PUBLIC_EXPONENT,
  4266. privateExponent: PRIVATE_EXPONENT,
  4267. prime1: PRIME1,
  4268. prime2: PRIME2,
  4269. exponent1: EXPONENT1,
  4270. exponent2: EXPONENT2,
  4271. coefficient: COEFFICIENT,
  4272. otherPrimeInfo: {
  4273. names: {
  4274. blockName: OTHER_PRIME_INFOS
  4275. }
  4276. }
  4277. }
  4278. }));
  4279. AsnError.assertSchema(asn1, this.className);
  4280. this.version = asn1.result.version.valueBlock.valueDec;
  4281. this.modulus = asn1.result.modulus.convertFromDER(256);
  4282. this.publicExponent = asn1.result.publicExponent;
  4283. this.privateExponent = asn1.result.privateExponent.convertFromDER(256);
  4284. this.prime1 = asn1.result.prime1.convertFromDER(128);
  4285. this.prime2 = asn1.result.prime2.convertFromDER(128);
  4286. this.exponent1 = asn1.result.exponent1.convertFromDER(128);
  4287. this.exponent2 = asn1.result.exponent2.convertFromDER(128);
  4288. this.coefficient = asn1.result.coefficient.convertFromDER(128);
  4289. if (OTHER_PRIME_INFOS in asn1.result)
  4290. this.otherPrimeInfos = Array.from(asn1.result.otherPrimeInfos, element => new OtherPrimeInfo({ schema: element }));
  4291. }
  4292. toSchema() {
  4293. const outputArray = [];
  4294. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  4295. outputArray.push(this.modulus.convertToDER());
  4296. outputArray.push(this.publicExponent);
  4297. outputArray.push(this.privateExponent.convertToDER());
  4298. outputArray.push(this.prime1.convertToDER());
  4299. outputArray.push(this.prime2.convertToDER());
  4300. outputArray.push(this.exponent1.convertToDER());
  4301. outputArray.push(this.exponent2.convertToDER());
  4302. outputArray.push(this.coefficient.convertToDER());
  4303. if (this.otherPrimeInfos) {
  4304. outputArray.push(new asn1js__namespace.Sequence({
  4305. value: Array.from(this.otherPrimeInfos, o => o.toSchema())
  4306. }));
  4307. }
  4308. return (new asn1js__namespace.Sequence({
  4309. value: outputArray
  4310. }));
  4311. }
  4312. toJSON() {
  4313. const jwk = {
  4314. n: pvtsutils__namespace.Convert.ToBase64Url(this.modulus.valueBlock.valueHexView),
  4315. e: pvtsutils__namespace.Convert.ToBase64Url(this.publicExponent.valueBlock.valueHexView),
  4316. d: pvtsutils__namespace.Convert.ToBase64Url(this.privateExponent.valueBlock.valueHexView),
  4317. p: pvtsutils__namespace.Convert.ToBase64Url(this.prime1.valueBlock.valueHexView),
  4318. q: pvtsutils__namespace.Convert.ToBase64Url(this.prime2.valueBlock.valueHexView),
  4319. dp: pvtsutils__namespace.Convert.ToBase64Url(this.exponent1.valueBlock.valueHexView),
  4320. dq: pvtsutils__namespace.Convert.ToBase64Url(this.exponent2.valueBlock.valueHexView),
  4321. qi: pvtsutils__namespace.Convert.ToBase64Url(this.coefficient.valueBlock.valueHexView),
  4322. };
  4323. if (this.otherPrimeInfos) {
  4324. jwk.oth = Array.from(this.otherPrimeInfos, o => o.toJSON());
  4325. }
  4326. return jwk;
  4327. }
  4328. fromJSON(json) {
  4329. ParameterError.assert("json", json, "n", "e", "d", "p", "q", "dp", "dq", "qi");
  4330. this.modulus = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.n) });
  4331. this.publicExponent = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.e) });
  4332. this.privateExponent = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.d) });
  4333. this.prime1 = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.p) });
  4334. this.prime2 = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.q) });
  4335. this.exponent1 = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.dp) });
  4336. this.exponent2 = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.dq) });
  4337. this.coefficient = new asn1js__namespace.Integer({ valueHex: pvtsutils__namespace.Convert.FromBase64Url(json.qi) });
  4338. if (json.oth) {
  4339. this.otherPrimeInfos = Array.from(json.oth, (element) => new OtherPrimeInfo({ json: element }));
  4340. }
  4341. }
  4342. }
  4343. RSAPrivateKey.CLASS_NAME = "RSAPrivateKey";
  4344. const VERSION$j = "version";
  4345. const PRIVATE_KEY_ALGORITHM = "privateKeyAlgorithm";
  4346. const PRIVATE_KEY = "privateKey";
  4347. const ATTRIBUTES$5 = "attributes";
  4348. const PARSED_KEY = "parsedKey";
  4349. const CLEAR_PROPS$16 = [
  4350. VERSION$j,
  4351. PRIVATE_KEY_ALGORITHM,
  4352. PRIVATE_KEY,
  4353. ATTRIBUTES$5
  4354. ];
  4355. class PrivateKeyInfo extends PkiObject {
  4356. constructor(parameters = {}) {
  4357. super();
  4358. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$j, PrivateKeyInfo.defaultValues(VERSION$j));
  4359. this.privateKeyAlgorithm = pvutils__namespace.getParametersValue(parameters, PRIVATE_KEY_ALGORITHM, PrivateKeyInfo.defaultValues(PRIVATE_KEY_ALGORITHM));
  4360. this.privateKey = pvutils__namespace.getParametersValue(parameters, PRIVATE_KEY, PrivateKeyInfo.defaultValues(PRIVATE_KEY));
  4361. if (ATTRIBUTES$5 in parameters) {
  4362. this.attributes = pvutils__namespace.getParametersValue(parameters, ATTRIBUTES$5, PrivateKeyInfo.defaultValues(ATTRIBUTES$5));
  4363. }
  4364. if (PARSED_KEY in parameters) {
  4365. this.parsedKey = pvutils__namespace.getParametersValue(parameters, PARSED_KEY, PrivateKeyInfo.defaultValues(PARSED_KEY));
  4366. }
  4367. if (parameters.json) {
  4368. this.fromJSON(parameters.json);
  4369. }
  4370. if (parameters.schema) {
  4371. this.fromSchema(parameters.schema);
  4372. }
  4373. }
  4374. static defaultValues(memberName) {
  4375. switch (memberName) {
  4376. case VERSION$j:
  4377. return 0;
  4378. case PRIVATE_KEY_ALGORITHM:
  4379. return new AlgorithmIdentifier();
  4380. case PRIVATE_KEY:
  4381. return new asn1js__namespace.OctetString();
  4382. case ATTRIBUTES$5:
  4383. return [];
  4384. case PARSED_KEY:
  4385. return {};
  4386. default:
  4387. return super.defaultValues(memberName);
  4388. }
  4389. }
  4390. static schema(parameters = {}) {
  4391. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  4392. return (new asn1js__namespace.Sequence({
  4393. name: (names.blockName || EMPTY_STRING),
  4394. value: [
  4395. new asn1js__namespace.Integer({ name: (names.version || EMPTY_STRING) }),
  4396. AlgorithmIdentifier.schema(names.privateKeyAlgorithm || {}),
  4397. new asn1js__namespace.OctetString({ name: (names.privateKey || EMPTY_STRING) }),
  4398. new asn1js__namespace.Constructed({
  4399. optional: true,
  4400. idBlock: {
  4401. tagClass: 3,
  4402. tagNumber: 0
  4403. },
  4404. value: [
  4405. new asn1js__namespace.Repeated({
  4406. name: (names.attributes || EMPTY_STRING),
  4407. value: Attribute.schema()
  4408. })
  4409. ]
  4410. })
  4411. ]
  4412. }));
  4413. }
  4414. fromSchema(schema) {
  4415. pvutils__namespace.clearProps(schema, CLEAR_PROPS$16);
  4416. const asn1 = asn1js__namespace.compareSchema(schema, schema, PrivateKeyInfo.schema({
  4417. names: {
  4418. version: VERSION$j,
  4419. privateKeyAlgorithm: {
  4420. names: {
  4421. blockName: PRIVATE_KEY_ALGORITHM
  4422. }
  4423. },
  4424. privateKey: PRIVATE_KEY,
  4425. attributes: ATTRIBUTES$5
  4426. }
  4427. }));
  4428. AsnError.assertSchema(asn1, this.className);
  4429. this.version = asn1.result.version.valueBlock.valueDec;
  4430. this.privateKeyAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.privateKeyAlgorithm });
  4431. this.privateKey = asn1.result.privateKey;
  4432. if (ATTRIBUTES$5 in asn1.result)
  4433. this.attributes = Array.from(asn1.result.attributes, element => new Attribute({ schema: element }));
  4434. switch (this.privateKeyAlgorithm.algorithmId) {
  4435. case "1.2.840.113549.1.1.1":
  4436. {
  4437. const privateKeyASN1 = asn1js__namespace.fromBER(this.privateKey.valueBlock.valueHexView);
  4438. if (privateKeyASN1.offset !== -1)
  4439. this.parsedKey = new RSAPrivateKey({ schema: privateKeyASN1.result });
  4440. }
  4441. break;
  4442. case "1.2.840.10045.2.1":
  4443. if ("algorithmParams" in this.privateKeyAlgorithm) {
  4444. if (this.privateKeyAlgorithm.algorithmParams instanceof asn1js__namespace.ObjectIdentifier) {
  4445. const privateKeyASN1 = asn1js__namespace.fromBER(this.privateKey.valueBlock.valueHexView);
  4446. if (privateKeyASN1.offset !== -1) {
  4447. this.parsedKey = new ECPrivateKey({
  4448. namedCurve: this.privateKeyAlgorithm.algorithmParams.valueBlock.toString(),
  4449. schema: privateKeyASN1.result
  4450. });
  4451. }
  4452. }
  4453. }
  4454. break;
  4455. }
  4456. }
  4457. toSchema() {
  4458. const outputArray = [
  4459. new asn1js__namespace.Integer({ value: this.version }),
  4460. this.privateKeyAlgorithm.toSchema(),
  4461. this.privateKey
  4462. ];
  4463. if (this.attributes) {
  4464. outputArray.push(new asn1js__namespace.Constructed({
  4465. optional: true,
  4466. idBlock: {
  4467. tagClass: 3,
  4468. tagNumber: 0
  4469. },
  4470. value: Array.from(this.attributes, o => o.toSchema())
  4471. }));
  4472. }
  4473. return (new asn1js__namespace.Sequence({
  4474. value: outputArray
  4475. }));
  4476. }
  4477. toJSON() {
  4478. if (!this.parsedKey) {
  4479. const object = {
  4480. version: this.version,
  4481. privateKeyAlgorithm: this.privateKeyAlgorithm.toJSON(),
  4482. privateKey: this.privateKey.toJSON(),
  4483. };
  4484. if (this.attributes) {
  4485. object.attributes = Array.from(this.attributes, o => o.toJSON());
  4486. }
  4487. return object;
  4488. }
  4489. const jwk = {};
  4490. switch (this.privateKeyAlgorithm.algorithmId) {
  4491. case "1.2.840.10045.2.1":
  4492. jwk.kty = "EC";
  4493. break;
  4494. case "1.2.840.113549.1.1.1":
  4495. jwk.kty = "RSA";
  4496. break;
  4497. }
  4498. const publicKeyJWK = this.parsedKey.toJSON();
  4499. Object.assign(jwk, publicKeyJWK);
  4500. return jwk;
  4501. }
  4502. fromJSON(json) {
  4503. if ("kty" in json) {
  4504. switch (json.kty.toUpperCase()) {
  4505. case "EC":
  4506. this.parsedKey = new ECPrivateKey({ json });
  4507. this.privateKeyAlgorithm = new AlgorithmIdentifier({
  4508. algorithmId: "1.2.840.10045.2.1",
  4509. algorithmParams: new asn1js__namespace.ObjectIdentifier({ value: this.parsedKey.namedCurve })
  4510. });
  4511. break;
  4512. case "RSA":
  4513. this.parsedKey = new RSAPrivateKey({ json });
  4514. this.privateKeyAlgorithm = new AlgorithmIdentifier({
  4515. algorithmId: "1.2.840.113549.1.1.1",
  4516. algorithmParams: new asn1js__namespace.Null()
  4517. });
  4518. break;
  4519. default:
  4520. throw new Error(`Invalid value for "kty" parameter: ${json.kty}`);
  4521. }
  4522. this.privateKey = new asn1js__namespace.OctetString({ valueHex: this.parsedKey.toSchema().toBER(false) });
  4523. }
  4524. }
  4525. }
  4526. PrivateKeyInfo.CLASS_NAME = "PrivateKeyInfo";
  4527. const CONTENT_TYPE$1 = "contentType";
  4528. const CONTENT_ENCRYPTION_ALGORITHM = "contentEncryptionAlgorithm";
  4529. const ENCRYPTED_CONTENT = "encryptedContent";
  4530. const CLEAR_PROPS$15 = [
  4531. CONTENT_TYPE$1,
  4532. CONTENT_ENCRYPTION_ALGORITHM,
  4533. ENCRYPTED_CONTENT,
  4534. ];
  4535. const PIECE_SIZE = 1024;
  4536. class EncryptedContentInfo extends PkiObject {
  4537. constructor(parameters = {}) {
  4538. super();
  4539. this.contentType = pvutils__namespace.getParametersValue(parameters, CONTENT_TYPE$1, EncryptedContentInfo.defaultValues(CONTENT_TYPE$1));
  4540. this.contentEncryptionAlgorithm = pvutils__namespace.getParametersValue(parameters, CONTENT_ENCRYPTION_ALGORITHM, EncryptedContentInfo.defaultValues(CONTENT_ENCRYPTION_ALGORITHM));
  4541. if (ENCRYPTED_CONTENT in parameters && parameters.encryptedContent) {
  4542. this.encryptedContent = parameters.encryptedContent;
  4543. if ((this.encryptedContent.idBlock.tagClass === 1) &&
  4544. (this.encryptedContent.idBlock.tagNumber === 4)) {
  4545. if (this.encryptedContent.idBlock.isConstructed === false && !parameters.disableSplit) {
  4546. const constrString = new asn1js__namespace.OctetString({
  4547. idBlock: { isConstructed: true },
  4548. isConstructed: true
  4549. });
  4550. let offset = 0;
  4551. const valueHex = this.encryptedContent.valueBlock.valueHexView.slice().buffer;
  4552. let length = valueHex.byteLength;
  4553. while (length > 0) {
  4554. const pieceView = new Uint8Array(valueHex, offset, ((offset + PIECE_SIZE) > valueHex.byteLength) ? (valueHex.byteLength - offset) : PIECE_SIZE);
  4555. const _array = new ArrayBuffer(pieceView.length);
  4556. const _view = new Uint8Array(_array);
  4557. for (let i = 0; i < _view.length; i++)
  4558. _view[i] = pieceView[i];
  4559. constrString.valueBlock.value.push(new asn1js__namespace.OctetString({ valueHex: _array }));
  4560. length -= pieceView.length;
  4561. offset += pieceView.length;
  4562. }
  4563. this.encryptedContent = constrString;
  4564. }
  4565. }
  4566. }
  4567. if (parameters.schema) {
  4568. this.fromSchema(parameters.schema);
  4569. }
  4570. }
  4571. static defaultValues(memberName) {
  4572. switch (memberName) {
  4573. case CONTENT_TYPE$1:
  4574. return EMPTY_STRING;
  4575. case CONTENT_ENCRYPTION_ALGORITHM:
  4576. return new AlgorithmIdentifier();
  4577. case ENCRYPTED_CONTENT:
  4578. return new asn1js__namespace.OctetString();
  4579. default:
  4580. return super.defaultValues(memberName);
  4581. }
  4582. }
  4583. static compareWithDefault(memberName, memberValue) {
  4584. switch (memberName) {
  4585. case CONTENT_TYPE$1:
  4586. return (memberValue === EMPTY_STRING);
  4587. case CONTENT_ENCRYPTION_ALGORITHM:
  4588. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  4589. case ENCRYPTED_CONTENT:
  4590. return (memberValue.isEqual(EncryptedContentInfo.defaultValues(ENCRYPTED_CONTENT)));
  4591. default:
  4592. return super.defaultValues(memberName);
  4593. }
  4594. }
  4595. static schema(parameters = {}) {
  4596. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  4597. return (new asn1js__namespace.Sequence({
  4598. name: (names.blockName || EMPTY_STRING),
  4599. value: [
  4600. new asn1js__namespace.ObjectIdentifier({ name: (names.contentType || EMPTY_STRING) }),
  4601. AlgorithmIdentifier.schema(names.contentEncryptionAlgorithm || {}),
  4602. new asn1js__namespace.Choice({
  4603. value: [
  4604. new asn1js__namespace.Constructed({
  4605. name: (names.encryptedContent || EMPTY_STRING),
  4606. idBlock: {
  4607. tagClass: 3,
  4608. tagNumber: 0
  4609. },
  4610. value: [
  4611. new asn1js__namespace.Repeated({
  4612. value: new asn1js__namespace.OctetString()
  4613. })
  4614. ]
  4615. }),
  4616. new asn1js__namespace.Primitive({
  4617. name: (names.encryptedContent || EMPTY_STRING),
  4618. idBlock: {
  4619. tagClass: 3,
  4620. tagNumber: 0
  4621. }
  4622. })
  4623. ]
  4624. })
  4625. ]
  4626. }));
  4627. }
  4628. fromSchema(schema) {
  4629. pvutils__namespace.clearProps(schema, CLEAR_PROPS$15);
  4630. const asn1 = asn1js__namespace.compareSchema(schema, schema, EncryptedContentInfo.schema({
  4631. names: {
  4632. contentType: CONTENT_TYPE$1,
  4633. contentEncryptionAlgorithm: {
  4634. names: {
  4635. blockName: CONTENT_ENCRYPTION_ALGORITHM
  4636. }
  4637. },
  4638. encryptedContent: ENCRYPTED_CONTENT
  4639. }
  4640. }));
  4641. AsnError.assertSchema(asn1, this.className);
  4642. this.contentType = asn1.result.contentType.valueBlock.toString();
  4643. this.contentEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.contentEncryptionAlgorithm });
  4644. if (ENCRYPTED_CONTENT in asn1.result) {
  4645. this.encryptedContent = asn1.result.encryptedContent;
  4646. this.encryptedContent.idBlock.tagClass = 1;
  4647. this.encryptedContent.idBlock.tagNumber = 4;
  4648. }
  4649. }
  4650. toSchema() {
  4651. const sequenceLengthBlock = {
  4652. isIndefiniteForm: false
  4653. };
  4654. const outputArray = [];
  4655. outputArray.push(new asn1js__namespace.ObjectIdentifier({ value: this.contentType }));
  4656. outputArray.push(this.contentEncryptionAlgorithm.toSchema());
  4657. if (this.encryptedContent) {
  4658. sequenceLengthBlock.isIndefiniteForm = this.encryptedContent.idBlock.isConstructed;
  4659. const encryptedValue = this.encryptedContent;
  4660. encryptedValue.idBlock.tagClass = 3;
  4661. encryptedValue.idBlock.tagNumber = 0;
  4662. encryptedValue.lenBlock.isIndefiniteForm = this.encryptedContent.idBlock.isConstructed;
  4663. outputArray.push(encryptedValue);
  4664. }
  4665. return (new asn1js__namespace.Sequence({
  4666. lenBlock: sequenceLengthBlock,
  4667. value: outputArray
  4668. }));
  4669. }
  4670. toJSON() {
  4671. const res = {
  4672. contentType: this.contentType,
  4673. contentEncryptionAlgorithm: this.contentEncryptionAlgorithm.toJSON()
  4674. };
  4675. if (this.encryptedContent) {
  4676. res.encryptedContent = this.encryptedContent.toJSON();
  4677. }
  4678. return res;
  4679. }
  4680. getEncryptedContent() {
  4681. if (!this.encryptedContent) {
  4682. throw new Error("Parameter 'encryptedContent' is undefined");
  4683. }
  4684. return asn1js__namespace.OctetString.prototype.getValue.call(this.encryptedContent);
  4685. }
  4686. }
  4687. EncryptedContentInfo.CLASS_NAME = "EncryptedContentInfo";
  4688. const HASH_ALGORITHM$4 = "hashAlgorithm";
  4689. const MASK_GEN_ALGORITHM$1 = "maskGenAlgorithm";
  4690. const SALT_LENGTH = "saltLength";
  4691. const TRAILER_FIELD = "trailerField";
  4692. const CLEAR_PROPS$14 = [
  4693. HASH_ALGORITHM$4,
  4694. MASK_GEN_ALGORITHM$1,
  4695. SALT_LENGTH,
  4696. TRAILER_FIELD
  4697. ];
  4698. class RSASSAPSSParams extends PkiObject {
  4699. constructor(parameters = {}) {
  4700. super();
  4701. this.hashAlgorithm = pvutils__namespace.getParametersValue(parameters, HASH_ALGORITHM$4, RSASSAPSSParams.defaultValues(HASH_ALGORITHM$4));
  4702. this.maskGenAlgorithm = pvutils__namespace.getParametersValue(parameters, MASK_GEN_ALGORITHM$1, RSASSAPSSParams.defaultValues(MASK_GEN_ALGORITHM$1));
  4703. this.saltLength = pvutils__namespace.getParametersValue(parameters, SALT_LENGTH, RSASSAPSSParams.defaultValues(SALT_LENGTH));
  4704. this.trailerField = pvutils__namespace.getParametersValue(parameters, TRAILER_FIELD, RSASSAPSSParams.defaultValues(TRAILER_FIELD));
  4705. if (parameters.schema) {
  4706. this.fromSchema(parameters.schema);
  4707. }
  4708. }
  4709. static defaultValues(memberName) {
  4710. switch (memberName) {
  4711. case HASH_ALGORITHM$4:
  4712. return new AlgorithmIdentifier({
  4713. algorithmId: "1.3.14.3.2.26",
  4714. algorithmParams: new asn1js__namespace.Null()
  4715. });
  4716. case MASK_GEN_ALGORITHM$1:
  4717. return new AlgorithmIdentifier({
  4718. algorithmId: "1.2.840.113549.1.1.8",
  4719. algorithmParams: (new AlgorithmIdentifier({
  4720. algorithmId: "1.3.14.3.2.26",
  4721. algorithmParams: new asn1js__namespace.Null()
  4722. })).toSchema()
  4723. });
  4724. case SALT_LENGTH:
  4725. return 20;
  4726. case TRAILER_FIELD:
  4727. return 1;
  4728. default:
  4729. return super.defaultValues(memberName);
  4730. }
  4731. }
  4732. static schema(parameters = {}) {
  4733. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  4734. return (new asn1js__namespace.Sequence({
  4735. name: (names.blockName || EMPTY_STRING),
  4736. value: [
  4737. new asn1js__namespace.Constructed({
  4738. idBlock: {
  4739. tagClass: 3,
  4740. tagNumber: 0
  4741. },
  4742. optional: true,
  4743. value: [AlgorithmIdentifier.schema(names.hashAlgorithm || {})]
  4744. }),
  4745. new asn1js__namespace.Constructed({
  4746. idBlock: {
  4747. tagClass: 3,
  4748. tagNumber: 1
  4749. },
  4750. optional: true,
  4751. value: [AlgorithmIdentifier.schema(names.maskGenAlgorithm || {})]
  4752. }),
  4753. new asn1js__namespace.Constructed({
  4754. idBlock: {
  4755. tagClass: 3,
  4756. tagNumber: 2
  4757. },
  4758. optional: true,
  4759. value: [new asn1js__namespace.Integer({ name: (names.saltLength || EMPTY_STRING) })]
  4760. }),
  4761. new asn1js__namespace.Constructed({
  4762. idBlock: {
  4763. tagClass: 3,
  4764. tagNumber: 3
  4765. },
  4766. optional: true,
  4767. value: [new asn1js__namespace.Integer({ name: (names.trailerField || EMPTY_STRING) })]
  4768. })
  4769. ]
  4770. }));
  4771. }
  4772. fromSchema(schema) {
  4773. pvutils__namespace.clearProps(schema, CLEAR_PROPS$14);
  4774. const asn1 = asn1js__namespace.compareSchema(schema, schema, RSASSAPSSParams.schema({
  4775. names: {
  4776. hashAlgorithm: {
  4777. names: {
  4778. blockName: HASH_ALGORITHM$4
  4779. }
  4780. },
  4781. maskGenAlgorithm: {
  4782. names: {
  4783. blockName: MASK_GEN_ALGORITHM$1
  4784. }
  4785. },
  4786. saltLength: SALT_LENGTH,
  4787. trailerField: TRAILER_FIELD
  4788. }
  4789. }));
  4790. AsnError.assertSchema(asn1, this.className);
  4791. if (HASH_ALGORITHM$4 in asn1.result)
  4792. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  4793. if (MASK_GEN_ALGORITHM$1 in asn1.result)
  4794. this.maskGenAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.maskGenAlgorithm });
  4795. if (SALT_LENGTH in asn1.result)
  4796. this.saltLength = asn1.result.saltLength.valueBlock.valueDec;
  4797. if (TRAILER_FIELD in asn1.result)
  4798. this.trailerField = asn1.result.trailerField.valueBlock.valueDec;
  4799. }
  4800. toSchema() {
  4801. const outputArray = [];
  4802. if (!this.hashAlgorithm.isEqual(RSASSAPSSParams.defaultValues(HASH_ALGORITHM$4))) {
  4803. outputArray.push(new asn1js__namespace.Constructed({
  4804. idBlock: {
  4805. tagClass: 3,
  4806. tagNumber: 0
  4807. },
  4808. value: [this.hashAlgorithm.toSchema()]
  4809. }));
  4810. }
  4811. if (!this.maskGenAlgorithm.isEqual(RSASSAPSSParams.defaultValues(MASK_GEN_ALGORITHM$1))) {
  4812. outputArray.push(new asn1js__namespace.Constructed({
  4813. idBlock: {
  4814. tagClass: 3,
  4815. tagNumber: 1
  4816. },
  4817. value: [this.maskGenAlgorithm.toSchema()]
  4818. }));
  4819. }
  4820. if (this.saltLength !== RSASSAPSSParams.defaultValues(SALT_LENGTH)) {
  4821. outputArray.push(new asn1js__namespace.Constructed({
  4822. idBlock: {
  4823. tagClass: 3,
  4824. tagNumber: 2
  4825. },
  4826. value: [new asn1js__namespace.Integer({ value: this.saltLength })]
  4827. }));
  4828. }
  4829. if (this.trailerField !== RSASSAPSSParams.defaultValues(TRAILER_FIELD)) {
  4830. outputArray.push(new asn1js__namespace.Constructed({
  4831. idBlock: {
  4832. tagClass: 3,
  4833. tagNumber: 3
  4834. },
  4835. value: [new asn1js__namespace.Integer({ value: this.trailerField })]
  4836. }));
  4837. }
  4838. return (new asn1js__namespace.Sequence({
  4839. value: outputArray
  4840. }));
  4841. }
  4842. toJSON() {
  4843. const res = {};
  4844. if (!this.hashAlgorithm.isEqual(RSASSAPSSParams.defaultValues(HASH_ALGORITHM$4))) {
  4845. res.hashAlgorithm = this.hashAlgorithm.toJSON();
  4846. }
  4847. if (!this.maskGenAlgorithm.isEqual(RSASSAPSSParams.defaultValues(MASK_GEN_ALGORITHM$1))) {
  4848. res.maskGenAlgorithm = this.maskGenAlgorithm.toJSON();
  4849. }
  4850. if (this.saltLength !== RSASSAPSSParams.defaultValues(SALT_LENGTH)) {
  4851. res.saltLength = this.saltLength;
  4852. }
  4853. if (this.trailerField !== RSASSAPSSParams.defaultValues(TRAILER_FIELD)) {
  4854. res.trailerField = this.trailerField;
  4855. }
  4856. return res;
  4857. }
  4858. }
  4859. RSASSAPSSParams.CLASS_NAME = "RSASSAPSSParams";
  4860. const SALT = "salt";
  4861. const ITERATION_COUNT = "iterationCount";
  4862. const KEY_LENGTH = "keyLength";
  4863. const PRF = "prf";
  4864. const CLEAR_PROPS$13 = [
  4865. SALT,
  4866. ITERATION_COUNT,
  4867. KEY_LENGTH,
  4868. PRF
  4869. ];
  4870. class PBKDF2Params extends PkiObject {
  4871. constructor(parameters = {}) {
  4872. super();
  4873. this.salt = pvutils__namespace.getParametersValue(parameters, SALT, PBKDF2Params.defaultValues(SALT));
  4874. this.iterationCount = pvutils__namespace.getParametersValue(parameters, ITERATION_COUNT, PBKDF2Params.defaultValues(ITERATION_COUNT));
  4875. if (KEY_LENGTH in parameters) {
  4876. this.keyLength = pvutils__namespace.getParametersValue(parameters, KEY_LENGTH, PBKDF2Params.defaultValues(KEY_LENGTH));
  4877. }
  4878. if (PRF in parameters) {
  4879. this.prf = pvutils__namespace.getParametersValue(parameters, PRF, PBKDF2Params.defaultValues(PRF));
  4880. }
  4881. if (parameters.schema) {
  4882. this.fromSchema(parameters.schema);
  4883. }
  4884. }
  4885. static defaultValues(memberName) {
  4886. switch (memberName) {
  4887. case SALT:
  4888. return {};
  4889. case ITERATION_COUNT:
  4890. return (-1);
  4891. case KEY_LENGTH:
  4892. return 0;
  4893. case PRF:
  4894. return new AlgorithmIdentifier({
  4895. algorithmId: "1.3.14.3.2.26",
  4896. algorithmParams: new asn1js__namespace.Null()
  4897. });
  4898. default:
  4899. return super.defaultValues(memberName);
  4900. }
  4901. }
  4902. static schema(parameters = {}) {
  4903. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  4904. return (new asn1js__namespace.Sequence({
  4905. name: (names.blockName || EMPTY_STRING),
  4906. value: [
  4907. new asn1js__namespace.Choice({
  4908. value: [
  4909. new asn1js__namespace.OctetString({ name: (names.saltPrimitive || EMPTY_STRING) }),
  4910. AlgorithmIdentifier.schema(names.saltConstructed || {})
  4911. ]
  4912. }),
  4913. new asn1js__namespace.Integer({ name: (names.iterationCount || EMPTY_STRING) }),
  4914. new asn1js__namespace.Integer({
  4915. name: (names.keyLength || EMPTY_STRING),
  4916. optional: true
  4917. }),
  4918. AlgorithmIdentifier.schema(names.prf || {
  4919. names: {
  4920. optional: true
  4921. }
  4922. })
  4923. ]
  4924. }));
  4925. }
  4926. fromSchema(schema) {
  4927. pvutils__namespace.clearProps(schema, CLEAR_PROPS$13);
  4928. const asn1 = asn1js__namespace.compareSchema(schema, schema, PBKDF2Params.schema({
  4929. names: {
  4930. saltPrimitive: SALT,
  4931. saltConstructed: {
  4932. names: {
  4933. blockName: SALT
  4934. }
  4935. },
  4936. iterationCount: ITERATION_COUNT,
  4937. keyLength: KEY_LENGTH,
  4938. prf: {
  4939. names: {
  4940. blockName: PRF,
  4941. optional: true
  4942. }
  4943. }
  4944. }
  4945. }));
  4946. AsnError.assertSchema(asn1, this.className);
  4947. this.salt = asn1.result.salt;
  4948. this.iterationCount = asn1.result.iterationCount.valueBlock.valueDec;
  4949. if (KEY_LENGTH in asn1.result)
  4950. this.keyLength = asn1.result.keyLength.valueBlock.valueDec;
  4951. if (PRF in asn1.result)
  4952. this.prf = new AlgorithmIdentifier({ schema: asn1.result.prf });
  4953. }
  4954. toSchema() {
  4955. const outputArray = [];
  4956. outputArray.push(this.salt);
  4957. outputArray.push(new asn1js__namespace.Integer({ value: this.iterationCount }));
  4958. if (KEY_LENGTH in this) {
  4959. if (PBKDF2Params.defaultValues(KEY_LENGTH) !== this.keyLength)
  4960. outputArray.push(new asn1js__namespace.Integer({ value: this.keyLength }));
  4961. }
  4962. if (this.prf) {
  4963. if (PBKDF2Params.defaultValues(PRF).isEqual(this.prf) === false)
  4964. outputArray.push(this.prf.toSchema());
  4965. }
  4966. return (new asn1js__namespace.Sequence({
  4967. value: outputArray
  4968. }));
  4969. }
  4970. toJSON() {
  4971. const res = {
  4972. salt: this.salt.toJSON(),
  4973. iterationCount: this.iterationCount
  4974. };
  4975. if (KEY_LENGTH in this) {
  4976. if (PBKDF2Params.defaultValues(KEY_LENGTH) !== this.keyLength)
  4977. res.keyLength = this.keyLength;
  4978. }
  4979. if (this.prf) {
  4980. if (PBKDF2Params.defaultValues(PRF).isEqual(this.prf) === false)
  4981. res.prf = this.prf.toJSON();
  4982. }
  4983. return res;
  4984. }
  4985. }
  4986. PBKDF2Params.CLASS_NAME = "PBKDF2Params";
  4987. const KEY_DERIVATION_FUNC = "keyDerivationFunc";
  4988. const ENCRYPTION_SCHEME = "encryptionScheme";
  4989. const CLEAR_PROPS$12 = [
  4990. KEY_DERIVATION_FUNC,
  4991. ENCRYPTION_SCHEME
  4992. ];
  4993. class PBES2Params extends PkiObject {
  4994. constructor(parameters = {}) {
  4995. super();
  4996. this.keyDerivationFunc = pvutils__namespace.getParametersValue(parameters, KEY_DERIVATION_FUNC, PBES2Params.defaultValues(KEY_DERIVATION_FUNC));
  4997. this.encryptionScheme = pvutils__namespace.getParametersValue(parameters, ENCRYPTION_SCHEME, PBES2Params.defaultValues(ENCRYPTION_SCHEME));
  4998. if (parameters.schema) {
  4999. this.fromSchema(parameters.schema);
  5000. }
  5001. }
  5002. static defaultValues(memberName) {
  5003. switch (memberName) {
  5004. case KEY_DERIVATION_FUNC:
  5005. return new AlgorithmIdentifier();
  5006. case ENCRYPTION_SCHEME:
  5007. return new AlgorithmIdentifier();
  5008. default:
  5009. return super.defaultValues(memberName);
  5010. }
  5011. }
  5012. static schema(parameters = {}) {
  5013. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  5014. return (new asn1js__namespace.Sequence({
  5015. name: (names.blockName || EMPTY_STRING),
  5016. value: [
  5017. AlgorithmIdentifier.schema(names.keyDerivationFunc || {}),
  5018. AlgorithmIdentifier.schema(names.encryptionScheme || {})
  5019. ]
  5020. }));
  5021. }
  5022. fromSchema(schema) {
  5023. pvutils__namespace.clearProps(schema, CLEAR_PROPS$12);
  5024. const asn1 = asn1js__namespace.compareSchema(schema, schema, PBES2Params.schema({
  5025. names: {
  5026. keyDerivationFunc: {
  5027. names: {
  5028. blockName: KEY_DERIVATION_FUNC
  5029. }
  5030. },
  5031. encryptionScheme: {
  5032. names: {
  5033. blockName: ENCRYPTION_SCHEME
  5034. }
  5035. }
  5036. }
  5037. }));
  5038. AsnError.assertSchema(asn1, this.className);
  5039. this.keyDerivationFunc = new AlgorithmIdentifier({ schema: asn1.result.keyDerivationFunc });
  5040. this.encryptionScheme = new AlgorithmIdentifier({ schema: asn1.result.encryptionScheme });
  5041. }
  5042. toSchema() {
  5043. return (new asn1js__namespace.Sequence({
  5044. value: [
  5045. this.keyDerivationFunc.toSchema(),
  5046. this.encryptionScheme.toSchema()
  5047. ]
  5048. }));
  5049. }
  5050. toJSON() {
  5051. return {
  5052. keyDerivationFunc: this.keyDerivationFunc.toJSON(),
  5053. encryptionScheme: this.encryptionScheme.toJSON()
  5054. };
  5055. }
  5056. }
  5057. PBES2Params.CLASS_NAME = "PBES2Params";
  5058. class AbstractCryptoEngine {
  5059. constructor(parameters) {
  5060. this.crypto = parameters.crypto;
  5061. this.subtle = "webkitSubtle" in parameters.crypto
  5062. ? parameters.crypto.webkitSubtle
  5063. : parameters.crypto.subtle;
  5064. this.name = pvutils__namespace.getParametersValue(parameters, "name", EMPTY_STRING);
  5065. }
  5066. async encrypt(...args) {
  5067. return this.subtle.encrypt(...args);
  5068. }
  5069. async decrypt(...args) {
  5070. return this.subtle.decrypt(...args);
  5071. }
  5072. sign(...args) {
  5073. return this.subtle.sign(...args);
  5074. }
  5075. async verify(...args) {
  5076. return this.subtle.verify(...args);
  5077. }
  5078. async digest(...args) {
  5079. return this.subtle.digest(...args);
  5080. }
  5081. async generateKey(...args) {
  5082. return this.subtle.generateKey(...args);
  5083. }
  5084. async deriveKey(...args) {
  5085. return this.subtle.deriveKey(...args);
  5086. }
  5087. async deriveBits(...args) {
  5088. return this.subtle.deriveBits(...args);
  5089. }
  5090. async wrapKey(...args) {
  5091. return this.subtle.wrapKey(...args);
  5092. }
  5093. async unwrapKey(...args) {
  5094. return this.subtle.unwrapKey(...args);
  5095. }
  5096. exportKey(...args) {
  5097. return this.subtle.exportKey(...args);
  5098. }
  5099. importKey(...args) {
  5100. return this.subtle.importKey(...args);
  5101. }
  5102. getRandomValues(array) {
  5103. if (array === null) {
  5104. throw new Error("Argument \"array\" must not be null");
  5105. }
  5106. return this.crypto.getRandomValues(array);
  5107. }
  5108. }
  5109. async function makePKCS12B2Key(hashAlgorithm, keyLength, password, salt, iterationCount) {
  5110. let u;
  5111. let v;
  5112. let md;
  5113. switch (hashAlgorithm.toUpperCase()) {
  5114. case "SHA-1":
  5115. u = 20;
  5116. v = 64;
  5117. md = sha1.sha1;
  5118. break;
  5119. case "SHA-256":
  5120. u = 32;
  5121. v = 64;
  5122. md = sha2.sha256;
  5123. break;
  5124. case "SHA-384":
  5125. u = 48;
  5126. v = 128;
  5127. md = sha2.sha384;
  5128. break;
  5129. case "SHA-512":
  5130. u = 64;
  5131. v = 128;
  5132. md = sha2.sha512;
  5133. break;
  5134. default:
  5135. throw new Error("Unsupported hashing algorithm");
  5136. }
  5137. const originalPassword = new Uint8Array(password);
  5138. let decodedPassword = new TextDecoder().decode(password);
  5139. const encodedPassword = new TextEncoder().encode(decodedPassword);
  5140. if (encodedPassword.some((byte, i) => byte !== originalPassword[i])) {
  5141. decodedPassword = String.fromCharCode(...originalPassword);
  5142. }
  5143. const passwordTransformed = new Uint8Array(decodedPassword.length * 2 + 2);
  5144. const passwordView = new DataView(passwordTransformed.buffer);
  5145. for (let i = 0; i < decodedPassword.length; i++) {
  5146. passwordView.setUint16(i * 2, decodedPassword.charCodeAt(i), false);
  5147. }
  5148. passwordView.setUint16(decodedPassword.length * 2, 0, false);
  5149. const D = new Uint8Array(v).fill(3);
  5150. const saltView = new Uint8Array(salt);
  5151. const S = new Uint8Array(v * Math.ceil(saltView.length / v)).map((_, i) => saltView[i % saltView.length]);
  5152. const P = new Uint8Array(v * Math.ceil(passwordTransformed.length / v)).map((_, i) => passwordTransformed[i % passwordTransformed.length]);
  5153. let I = new Uint8Array(S.length + P.length);
  5154. I.set(S);
  5155. I.set(P, S.length);
  5156. const c = Math.ceil((keyLength >> 3) / u);
  5157. const result = [];
  5158. for (let i = 0; i < c; i++) {
  5159. let A = new Uint8Array(D.length + I.length);
  5160. A.set(D);
  5161. A.set(I, D.length);
  5162. for (let j = 0; j < iterationCount; j++) {
  5163. A = md(A);
  5164. }
  5165. const B = new Uint8Array(v).map((_, i) => A[i % A.length]);
  5166. const k = Math.ceil(saltView.length / v) + Math.ceil(passwordTransformed.length / v);
  5167. const iRound = [];
  5168. for (let j = 0; j < k; j++) {
  5169. const chunk = Array.from(I.slice(j * v, (j + 1) * v));
  5170. let x = 0x1ff;
  5171. for (let l = B.length - 1; l >= 0; l--) {
  5172. x >>= 8;
  5173. x += B[l] + (chunk[l] || 0);
  5174. chunk[l] = x & 0xff;
  5175. }
  5176. iRound.push(...chunk);
  5177. }
  5178. I = new Uint8Array(iRound);
  5179. result.push(...A);
  5180. }
  5181. return new Uint8Array(result.slice(0, keyLength >> 3)).buffer;
  5182. }
  5183. function prepareAlgorithm(data) {
  5184. const res = typeof data === "string"
  5185. ? { name: data }
  5186. : data;
  5187. if ("hash" in res) {
  5188. return {
  5189. ...res,
  5190. hash: prepareAlgorithm(res.hash)
  5191. };
  5192. }
  5193. return res;
  5194. }
  5195. class CryptoEngine extends AbstractCryptoEngine {
  5196. async importKey(format, keyData, algorithm, extractable, keyUsages) {
  5197. var _a, _b, _c, _d, _e, _f;
  5198. let jwk = {};
  5199. const alg = prepareAlgorithm(algorithm);
  5200. switch (format.toLowerCase()) {
  5201. case "raw":
  5202. return this.subtle.importKey("raw", keyData, algorithm, extractable, keyUsages);
  5203. case "spki":
  5204. {
  5205. const asn1 = asn1js__namespace.fromBER(pvtsutils__namespace.BufferSourceConverter.toArrayBuffer(keyData));
  5206. AsnError.assert(asn1, "keyData");
  5207. const publicKeyInfo = new PublicKeyInfo();
  5208. try {
  5209. publicKeyInfo.fromSchema(asn1.result);
  5210. }
  5211. catch {
  5212. throw new ArgumentError("Incorrect keyData");
  5213. }
  5214. switch (alg.name.toUpperCase()) {
  5215. case "RSA-PSS":
  5216. {
  5217. keyUsages = ["verify"];
  5218. jwk.kty = "RSA";
  5219. jwk.ext = extractable;
  5220. jwk.key_ops = keyUsages;
  5221. if (!["1.2.840.113549.1.1.1", "1.2.840.113549.1.1.10"].includes(publicKeyInfo.algorithm.algorithmId))
  5222. throw new Error(`Incorrect public key algorithm: ${publicKeyInfo.algorithm.algorithmId}`);
  5223. if (!alg.hash) {
  5224. throw new ParameterError("hash", "algorithm.hash", "Incorrect hash algorithm: Hash algorithm is missed");
  5225. }
  5226. switch (alg.hash.name.toUpperCase()) {
  5227. case "SHA-1":
  5228. jwk.alg = "PS1";
  5229. break;
  5230. case "SHA-256":
  5231. jwk.alg = "PS256";
  5232. break;
  5233. case "SHA-384":
  5234. jwk.alg = "PS384";
  5235. break;
  5236. case "SHA-512":
  5237. jwk.alg = "PS512";
  5238. break;
  5239. default:
  5240. throw new Error(`Incorrect hash algorithm: ${alg.hash.name.toUpperCase()}`);
  5241. }
  5242. const rsaPssPublicKeyJSON = publicKeyInfo.toJSON();
  5243. Object.assign(jwk, rsaPssPublicKeyJSON);
  5244. }
  5245. break;
  5246. case "RSASSA-PKCS1-V1_5":
  5247. {
  5248. keyUsages = ["verify"];
  5249. jwk.kty = "RSA";
  5250. jwk.ext = extractable;
  5251. jwk.key_ops = keyUsages;
  5252. if (publicKeyInfo.algorithm.algorithmId !== "1.2.840.113549.1.1.1")
  5253. throw new Error(`Incorrect public key algorithm: ${publicKeyInfo.algorithm.algorithmId}`);
  5254. if (!alg.hash) {
  5255. throw new ParameterError("hash", "algorithm.hash", "Incorrect hash algorithm: Hash algorithm is missed");
  5256. }
  5257. switch (alg.hash.name.toUpperCase()) {
  5258. case "SHA-1":
  5259. jwk.alg = "RS1";
  5260. break;
  5261. case "SHA-256":
  5262. jwk.alg = "RS256";
  5263. break;
  5264. case "SHA-384":
  5265. jwk.alg = "RS384";
  5266. break;
  5267. case "SHA-512":
  5268. jwk.alg = "RS512";
  5269. break;
  5270. default:
  5271. throw new Error(`Incorrect hash algorithm: ${alg.hash.name.toUpperCase()}`);
  5272. }
  5273. const rsaPublicKeyJSON = publicKeyInfo.toJSON();
  5274. Object.assign(jwk, rsaPublicKeyJSON);
  5275. }
  5276. break;
  5277. case "ECDSA":
  5278. keyUsages = ["verify"];
  5279. case "ECDH":
  5280. {
  5281. jwk = {
  5282. kty: "EC",
  5283. ext: extractable,
  5284. key_ops: keyUsages
  5285. };
  5286. if (publicKeyInfo.algorithm.algorithmId !== "1.2.840.10045.2.1") {
  5287. throw new Error(`Incorrect public key algorithm: ${publicKeyInfo.algorithm.algorithmId}`);
  5288. }
  5289. const publicKeyJSON = publicKeyInfo.toJSON();
  5290. Object.assign(jwk, publicKeyJSON);
  5291. }
  5292. break;
  5293. case "RSA-OAEP":
  5294. {
  5295. jwk.kty = "RSA";
  5296. jwk.ext = extractable;
  5297. jwk.key_ops = keyUsages;
  5298. if (this.name.toLowerCase() === "safari")
  5299. jwk.alg = "RSA-OAEP";
  5300. else {
  5301. if (!alg.hash) {
  5302. throw new ParameterError("hash", "algorithm.hash", "Incorrect hash algorithm: Hash algorithm is missed");
  5303. }
  5304. switch (alg.hash.name.toUpperCase()) {
  5305. case "SHA-1":
  5306. jwk.alg = "RSA-OAEP";
  5307. break;
  5308. case "SHA-256":
  5309. jwk.alg = "RSA-OAEP-256";
  5310. break;
  5311. case "SHA-384":
  5312. jwk.alg = "RSA-OAEP-384";
  5313. break;
  5314. case "SHA-512":
  5315. jwk.alg = "RSA-OAEP-512";
  5316. break;
  5317. default:
  5318. throw new Error(`Incorrect hash algorithm: ${alg.hash.name.toUpperCase()}`);
  5319. }
  5320. }
  5321. const publicKeyJSON = publicKeyInfo.toJSON();
  5322. Object.assign(jwk, publicKeyJSON);
  5323. }
  5324. break;
  5325. case "RSAES-PKCS1-V1_5":
  5326. {
  5327. jwk.kty = "RSA";
  5328. jwk.ext = extractable;
  5329. jwk.key_ops = keyUsages;
  5330. jwk.alg = "PS1";
  5331. const publicKeyJSON = publicKeyInfo.toJSON();
  5332. Object.assign(jwk, publicKeyJSON);
  5333. }
  5334. break;
  5335. default:
  5336. throw new Error(`Incorrect algorithm name: ${alg.name.toUpperCase()}`);
  5337. }
  5338. }
  5339. break;
  5340. case "pkcs8":
  5341. {
  5342. const privateKeyInfo = new PrivateKeyInfo();
  5343. const asn1 = asn1js__namespace.fromBER(pvtsutils__namespace.BufferSourceConverter.toArrayBuffer(keyData));
  5344. AsnError.assert(asn1, "keyData");
  5345. try {
  5346. privateKeyInfo.fromSchema(asn1.result);
  5347. }
  5348. catch {
  5349. throw new Error("Incorrect keyData");
  5350. }
  5351. if (!privateKeyInfo.parsedKey)
  5352. throw new Error("Incorrect keyData");
  5353. switch (alg.name.toUpperCase()) {
  5354. case "RSA-PSS":
  5355. {
  5356. switch ((_a = alg.hash) === null || _a === void 0 ? void 0 : _a.name.toUpperCase()) {
  5357. case "SHA-1":
  5358. jwk.alg = "PS1";
  5359. break;
  5360. case "SHA-256":
  5361. jwk.alg = "PS256";
  5362. break;
  5363. case "SHA-384":
  5364. jwk.alg = "PS384";
  5365. break;
  5366. case "SHA-512":
  5367. jwk.alg = "PS512";
  5368. break;
  5369. default:
  5370. throw new Error(`Incorrect hash algorithm: ${(_b = alg.hash) === null || _b === void 0 ? void 0 : _b.name.toUpperCase()}`);
  5371. }
  5372. }
  5373. case "RSASSA-PKCS1-V1_5":
  5374. {
  5375. keyUsages = ["sign"];
  5376. jwk.kty = "RSA";
  5377. jwk.ext = extractable;
  5378. jwk.key_ops = keyUsages;
  5379. if (privateKeyInfo.privateKeyAlgorithm.algorithmId !== "1.2.840.113549.1.1.1")
  5380. throw new Error(`Incorrect private key algorithm: ${privateKeyInfo.privateKeyAlgorithm.algorithmId}`);
  5381. if (("alg" in jwk) === false) {
  5382. switch ((_c = alg.hash) === null || _c === void 0 ? void 0 : _c.name.toUpperCase()) {
  5383. case "SHA-1":
  5384. jwk.alg = "RS1";
  5385. break;
  5386. case "SHA-256":
  5387. jwk.alg = "RS256";
  5388. break;
  5389. case "SHA-384":
  5390. jwk.alg = "RS384";
  5391. break;
  5392. case "SHA-512":
  5393. jwk.alg = "RS512";
  5394. break;
  5395. default:
  5396. throw new Error(`Incorrect hash algorithm: ${(_d = alg.hash) === null || _d === void 0 ? void 0 : _d.name.toUpperCase()}`);
  5397. }
  5398. }
  5399. const privateKeyJSON = privateKeyInfo.toJSON();
  5400. Object.assign(jwk, privateKeyJSON);
  5401. }
  5402. break;
  5403. case "ECDSA":
  5404. keyUsages = ["sign"];
  5405. case "ECDH":
  5406. {
  5407. jwk = {
  5408. kty: "EC",
  5409. ext: extractable,
  5410. key_ops: keyUsages
  5411. };
  5412. if (privateKeyInfo.privateKeyAlgorithm.algorithmId !== "1.2.840.10045.2.1")
  5413. throw new Error(`Incorrect algorithm: ${privateKeyInfo.privateKeyAlgorithm.algorithmId}`);
  5414. const privateKeyJSON = privateKeyInfo.toJSON();
  5415. Object.assign(jwk, privateKeyJSON);
  5416. }
  5417. break;
  5418. case "RSA-OAEP":
  5419. {
  5420. jwk.kty = "RSA";
  5421. jwk.ext = extractable;
  5422. jwk.key_ops = keyUsages;
  5423. if (this.name.toLowerCase() === "safari")
  5424. jwk.alg = "RSA-OAEP";
  5425. else {
  5426. switch ((_e = alg.hash) === null || _e === void 0 ? void 0 : _e.name.toUpperCase()) {
  5427. case "SHA-1":
  5428. jwk.alg = "RSA-OAEP";
  5429. break;
  5430. case "SHA-256":
  5431. jwk.alg = "RSA-OAEP-256";
  5432. break;
  5433. case "SHA-384":
  5434. jwk.alg = "RSA-OAEP-384";
  5435. break;
  5436. case "SHA-512":
  5437. jwk.alg = "RSA-OAEP-512";
  5438. break;
  5439. default:
  5440. throw new Error(`Incorrect hash algorithm: ${(_f = alg.hash) === null || _f === void 0 ? void 0 : _f.name.toUpperCase()}`);
  5441. }
  5442. }
  5443. const privateKeyJSON = privateKeyInfo.toJSON();
  5444. Object.assign(jwk, privateKeyJSON);
  5445. }
  5446. break;
  5447. case "RSAES-PKCS1-V1_5":
  5448. {
  5449. keyUsages = ["decrypt"];
  5450. jwk.kty = "RSA";
  5451. jwk.ext = extractable;
  5452. jwk.key_ops = keyUsages;
  5453. jwk.alg = "PS1";
  5454. const privateKeyJSON = privateKeyInfo.toJSON();
  5455. Object.assign(jwk, privateKeyJSON);
  5456. }
  5457. break;
  5458. default:
  5459. throw new Error(`Incorrect algorithm name: ${alg.name.toUpperCase()}`);
  5460. }
  5461. }
  5462. break;
  5463. case "jwk":
  5464. jwk = keyData;
  5465. break;
  5466. default:
  5467. throw new Error(`Incorrect format: ${format}`);
  5468. }
  5469. if (this.name.toLowerCase() === "safari") {
  5470. try {
  5471. return this.subtle.importKey("jwk", pvutils__namespace.stringToArrayBuffer(JSON.stringify(jwk)), algorithm, extractable, keyUsages);
  5472. }
  5473. catch {
  5474. return this.subtle.importKey("jwk", jwk, algorithm, extractable, keyUsages);
  5475. }
  5476. }
  5477. return this.subtle.importKey("jwk", jwk, algorithm, extractable, keyUsages);
  5478. }
  5479. async exportKey(format, key) {
  5480. let jwk = await this.subtle.exportKey("jwk", key);
  5481. if (this.name.toLowerCase() === "safari") {
  5482. if (jwk instanceof ArrayBuffer) {
  5483. jwk = JSON.parse(pvutils__namespace.arrayBufferToString(jwk));
  5484. }
  5485. }
  5486. switch (format.toLowerCase()) {
  5487. case "raw":
  5488. return this.subtle.exportKey("raw", key);
  5489. case "spki": {
  5490. const publicKeyInfo = new PublicKeyInfo();
  5491. try {
  5492. publicKeyInfo.fromJSON(jwk);
  5493. }
  5494. catch {
  5495. throw new Error("Incorrect key data");
  5496. }
  5497. return publicKeyInfo.toSchema().toBER(false);
  5498. }
  5499. case "pkcs8": {
  5500. const privateKeyInfo = new PrivateKeyInfo();
  5501. try {
  5502. privateKeyInfo.fromJSON(jwk);
  5503. }
  5504. catch {
  5505. throw new Error("Incorrect key data");
  5506. }
  5507. return privateKeyInfo.toSchema().toBER(false);
  5508. }
  5509. case "jwk":
  5510. return jwk;
  5511. default:
  5512. throw new Error(`Incorrect format: ${format}`);
  5513. }
  5514. }
  5515. async convert(inputFormat, outputFormat, keyData, algorithm, extractable, keyUsages) {
  5516. if (inputFormat.toLowerCase() === outputFormat.toLowerCase()) {
  5517. return keyData;
  5518. }
  5519. const key = await this.importKey(inputFormat, keyData, algorithm, extractable, keyUsages);
  5520. return this.exportKey(outputFormat, key);
  5521. }
  5522. getAlgorithmByOID(oid, safety = false, target) {
  5523. switch (oid) {
  5524. case "1.2.840.113549.1.1.1":
  5525. return {
  5526. name: "RSAES-PKCS1-v1_5"
  5527. };
  5528. case "1.2.840.113549.1.1.5":
  5529. return {
  5530. name: "RSASSA-PKCS1-v1_5",
  5531. hash: {
  5532. name: "SHA-1"
  5533. }
  5534. };
  5535. case "1.2.840.113549.1.1.11":
  5536. return {
  5537. name: "RSASSA-PKCS1-v1_5",
  5538. hash: {
  5539. name: "SHA-256"
  5540. }
  5541. };
  5542. case "1.2.840.113549.1.1.12":
  5543. return {
  5544. name: "RSASSA-PKCS1-v1_5",
  5545. hash: {
  5546. name: "SHA-384"
  5547. }
  5548. };
  5549. case "1.2.840.113549.1.1.13":
  5550. return {
  5551. name: "RSASSA-PKCS1-v1_5",
  5552. hash: {
  5553. name: "SHA-512"
  5554. }
  5555. };
  5556. case "1.2.840.113549.1.1.10":
  5557. return {
  5558. name: "RSA-PSS"
  5559. };
  5560. case "1.2.840.113549.1.1.7":
  5561. return {
  5562. name: "RSA-OAEP"
  5563. };
  5564. case "1.2.840.10045.2.1":
  5565. case "1.2.840.10045.4.1":
  5566. return {
  5567. name: "ECDSA",
  5568. hash: {
  5569. name: "SHA-1"
  5570. }
  5571. };
  5572. case "1.2.840.10045.4.3.2":
  5573. return {
  5574. name: "ECDSA",
  5575. hash: {
  5576. name: "SHA-256"
  5577. }
  5578. };
  5579. case "1.2.840.10045.4.3.3":
  5580. return {
  5581. name: "ECDSA",
  5582. hash: {
  5583. name: "SHA-384"
  5584. }
  5585. };
  5586. case "1.2.840.10045.4.3.4":
  5587. return {
  5588. name: "ECDSA",
  5589. hash: {
  5590. name: "SHA-512"
  5591. }
  5592. };
  5593. case "1.3.133.16.840.63.0.2":
  5594. return {
  5595. name: "ECDH",
  5596. kdf: "SHA-1"
  5597. };
  5598. case "1.3.132.1.11.1":
  5599. return {
  5600. name: "ECDH",
  5601. kdf: "SHA-256"
  5602. };
  5603. case "1.3.132.1.11.2":
  5604. return {
  5605. name: "ECDH",
  5606. kdf: "SHA-384"
  5607. };
  5608. case "1.3.132.1.11.3":
  5609. return {
  5610. name: "ECDH",
  5611. kdf: "SHA-512"
  5612. };
  5613. case "2.16.840.1.101.3.4.1.2":
  5614. return {
  5615. name: "AES-CBC",
  5616. length: 128
  5617. };
  5618. case "2.16.840.1.101.3.4.1.22":
  5619. return {
  5620. name: "AES-CBC",
  5621. length: 192
  5622. };
  5623. case "2.16.840.1.101.3.4.1.42":
  5624. return {
  5625. name: "AES-CBC",
  5626. length: 256
  5627. };
  5628. case "2.16.840.1.101.3.4.1.6":
  5629. return {
  5630. name: "AES-GCM",
  5631. length: 128
  5632. };
  5633. case "2.16.840.1.101.3.4.1.26":
  5634. return {
  5635. name: "AES-GCM",
  5636. length: 192
  5637. };
  5638. case "2.16.840.1.101.3.4.1.46":
  5639. return {
  5640. name: "AES-GCM",
  5641. length: 256
  5642. };
  5643. case "2.16.840.1.101.3.4.1.4":
  5644. return {
  5645. name: "AES-CFB",
  5646. length: 128
  5647. };
  5648. case "2.16.840.1.101.3.4.1.24":
  5649. return {
  5650. name: "AES-CFB",
  5651. length: 192
  5652. };
  5653. case "2.16.840.1.101.3.4.1.44":
  5654. return {
  5655. name: "AES-CFB",
  5656. length: 256
  5657. };
  5658. case "2.16.840.1.101.3.4.1.5":
  5659. return {
  5660. name: "AES-KW",
  5661. length: 128
  5662. };
  5663. case "2.16.840.1.101.3.4.1.25":
  5664. return {
  5665. name: "AES-KW",
  5666. length: 192
  5667. };
  5668. case "2.16.840.1.101.3.4.1.45":
  5669. return {
  5670. name: "AES-KW",
  5671. length: 256
  5672. };
  5673. case "1.2.840.113549.2.7":
  5674. return {
  5675. name: "HMAC",
  5676. hash: {
  5677. name: "SHA-1"
  5678. }
  5679. };
  5680. case "1.2.840.113549.2.9":
  5681. return {
  5682. name: "HMAC",
  5683. hash: {
  5684. name: "SHA-256"
  5685. }
  5686. };
  5687. case "1.2.840.113549.2.10":
  5688. return {
  5689. name: "HMAC",
  5690. hash: {
  5691. name: "SHA-384"
  5692. }
  5693. };
  5694. case "1.2.840.113549.2.11":
  5695. return {
  5696. name: "HMAC",
  5697. hash: {
  5698. name: "SHA-512"
  5699. }
  5700. };
  5701. case "1.2.840.113549.1.9.16.3.5":
  5702. return {
  5703. name: "DH"
  5704. };
  5705. case "1.3.14.3.2.26":
  5706. return {
  5707. name: "SHA-1"
  5708. };
  5709. case "2.16.840.1.101.3.4.2.1":
  5710. return {
  5711. name: "SHA-256"
  5712. };
  5713. case "2.16.840.1.101.3.4.2.2":
  5714. return {
  5715. name: "SHA-384"
  5716. };
  5717. case "2.16.840.1.101.3.4.2.3":
  5718. return {
  5719. name: "SHA-512"
  5720. };
  5721. case "1.2.840.113549.1.5.12":
  5722. return {
  5723. name: "PBKDF2"
  5724. };
  5725. case "1.2.840.10045.3.1.7":
  5726. return {
  5727. name: "P-256"
  5728. };
  5729. case "1.3.132.0.34":
  5730. return {
  5731. name: "P-384"
  5732. };
  5733. case "1.3.132.0.35":
  5734. return {
  5735. name: "P-521"
  5736. };
  5737. }
  5738. if (safety) {
  5739. throw new Error(`Unsupported algorithm identifier ${target ? `for ${target} ` : EMPTY_STRING}: ${oid}`);
  5740. }
  5741. return {};
  5742. }
  5743. getOIDByAlgorithm(algorithm, safety = false, target) {
  5744. let result = EMPTY_STRING;
  5745. switch (algorithm.name.toUpperCase()) {
  5746. case "RSAES-PKCS1-V1_5":
  5747. result = "1.2.840.113549.1.1.1";
  5748. break;
  5749. case "RSASSA-PKCS1-V1_5":
  5750. switch (algorithm.hash.name.toUpperCase()) {
  5751. case "SHA-1":
  5752. result = "1.2.840.113549.1.1.5";
  5753. break;
  5754. case "SHA-256":
  5755. result = "1.2.840.113549.1.1.11";
  5756. break;
  5757. case "SHA-384":
  5758. result = "1.2.840.113549.1.1.12";
  5759. break;
  5760. case "SHA-512":
  5761. result = "1.2.840.113549.1.1.13";
  5762. break;
  5763. }
  5764. break;
  5765. case "RSA-PSS":
  5766. result = "1.2.840.113549.1.1.10";
  5767. break;
  5768. case "RSA-OAEP":
  5769. result = "1.2.840.113549.1.1.7";
  5770. break;
  5771. case "ECDSA":
  5772. switch (algorithm.hash.name.toUpperCase()) {
  5773. case "SHA-1":
  5774. result = "1.2.840.10045.4.1";
  5775. break;
  5776. case "SHA-256":
  5777. result = "1.2.840.10045.4.3.2";
  5778. break;
  5779. case "SHA-384":
  5780. result = "1.2.840.10045.4.3.3";
  5781. break;
  5782. case "SHA-512":
  5783. result = "1.2.840.10045.4.3.4";
  5784. break;
  5785. }
  5786. break;
  5787. case "ECDH":
  5788. switch (algorithm.kdf.toUpperCase()) {
  5789. case "SHA-1":
  5790. result = "1.3.133.16.840.63.0.2";
  5791. break;
  5792. case "SHA-256":
  5793. result = "1.3.132.1.11.1";
  5794. break;
  5795. case "SHA-384":
  5796. result = "1.3.132.1.11.2";
  5797. break;
  5798. case "SHA-512":
  5799. result = "1.3.132.1.11.3";
  5800. break;
  5801. }
  5802. break;
  5803. case "AES-CTR":
  5804. break;
  5805. case "AES-CBC":
  5806. switch (algorithm.length) {
  5807. case 128:
  5808. result = "2.16.840.1.101.3.4.1.2";
  5809. break;
  5810. case 192:
  5811. result = "2.16.840.1.101.3.4.1.22";
  5812. break;
  5813. case 256:
  5814. result = "2.16.840.1.101.3.4.1.42";
  5815. break;
  5816. }
  5817. break;
  5818. case "AES-CMAC":
  5819. break;
  5820. case "AES-GCM":
  5821. switch (algorithm.length) {
  5822. case 128:
  5823. result = "2.16.840.1.101.3.4.1.6";
  5824. break;
  5825. case 192:
  5826. result = "2.16.840.1.101.3.4.1.26";
  5827. break;
  5828. case 256:
  5829. result = "2.16.840.1.101.3.4.1.46";
  5830. break;
  5831. }
  5832. break;
  5833. case "AES-CFB":
  5834. switch (algorithm.length) {
  5835. case 128:
  5836. result = "2.16.840.1.101.3.4.1.4";
  5837. break;
  5838. case 192:
  5839. result = "2.16.840.1.101.3.4.1.24";
  5840. break;
  5841. case 256:
  5842. result = "2.16.840.1.101.3.4.1.44";
  5843. break;
  5844. }
  5845. break;
  5846. case "AES-KW":
  5847. switch (algorithm.length) {
  5848. case 128:
  5849. result = "2.16.840.1.101.3.4.1.5";
  5850. break;
  5851. case 192:
  5852. result = "2.16.840.1.101.3.4.1.25";
  5853. break;
  5854. case 256:
  5855. result = "2.16.840.1.101.3.4.1.45";
  5856. break;
  5857. }
  5858. break;
  5859. case "HMAC":
  5860. switch (algorithm.hash.name.toUpperCase()) {
  5861. case "SHA-1":
  5862. result = "1.2.840.113549.2.7";
  5863. break;
  5864. case "SHA-256":
  5865. result = "1.2.840.113549.2.9";
  5866. break;
  5867. case "SHA-384":
  5868. result = "1.2.840.113549.2.10";
  5869. break;
  5870. case "SHA-512":
  5871. result = "1.2.840.113549.2.11";
  5872. break;
  5873. }
  5874. break;
  5875. case "DH":
  5876. result = "1.2.840.113549.1.9.16.3.5";
  5877. break;
  5878. case "SHA-1":
  5879. result = "1.3.14.3.2.26";
  5880. break;
  5881. case "SHA-256":
  5882. result = "2.16.840.1.101.3.4.2.1";
  5883. break;
  5884. case "SHA-384":
  5885. result = "2.16.840.1.101.3.4.2.2";
  5886. break;
  5887. case "SHA-512":
  5888. result = "2.16.840.1.101.3.4.2.3";
  5889. break;
  5890. case "CONCAT":
  5891. break;
  5892. case "HKDF":
  5893. break;
  5894. case "PBKDF2":
  5895. result = "1.2.840.113549.1.5.12";
  5896. break;
  5897. case "P-256":
  5898. result = "1.2.840.10045.3.1.7";
  5899. break;
  5900. case "P-384":
  5901. result = "1.3.132.0.34";
  5902. break;
  5903. case "P-521":
  5904. result = "1.3.132.0.35";
  5905. break;
  5906. }
  5907. if (!result && safety) {
  5908. throw new Error(`Unsupported algorithm ${target ? `for ${target} ` : EMPTY_STRING}: ${algorithm.name}`);
  5909. }
  5910. return result;
  5911. }
  5912. getAlgorithmParameters(algorithmName, operation) {
  5913. let result = {
  5914. algorithm: {},
  5915. usages: []
  5916. };
  5917. switch (algorithmName.toUpperCase()) {
  5918. case "RSAES-PKCS1-V1_5":
  5919. case "RSASSA-PKCS1-V1_5":
  5920. switch (operation.toLowerCase()) {
  5921. case "generatekey":
  5922. result = {
  5923. algorithm: {
  5924. name: "RSASSA-PKCS1-v1_5",
  5925. modulusLength: 2048,
  5926. publicExponent: new Uint8Array([0x01, 0x00, 0x01]),
  5927. hash: {
  5928. name: "SHA-256"
  5929. }
  5930. },
  5931. usages: ["sign", "verify"]
  5932. };
  5933. break;
  5934. case "verify":
  5935. case "sign":
  5936. case "importkey":
  5937. result = {
  5938. algorithm: {
  5939. name: "RSASSA-PKCS1-v1_5",
  5940. hash: {
  5941. name: "SHA-256"
  5942. }
  5943. },
  5944. usages: ["verify"]
  5945. };
  5946. break;
  5947. case "exportkey":
  5948. default:
  5949. return {
  5950. algorithm: {
  5951. name: "RSASSA-PKCS1-v1_5"
  5952. },
  5953. usages: []
  5954. };
  5955. }
  5956. break;
  5957. case "RSA-PSS":
  5958. switch (operation.toLowerCase()) {
  5959. case "sign":
  5960. case "verify":
  5961. result = {
  5962. algorithm: {
  5963. name: "RSA-PSS",
  5964. hash: {
  5965. name: "SHA-1"
  5966. },
  5967. saltLength: 20
  5968. },
  5969. usages: ["sign", "verify"]
  5970. };
  5971. break;
  5972. case "generatekey":
  5973. result = {
  5974. algorithm: {
  5975. name: "RSA-PSS",
  5976. modulusLength: 2048,
  5977. publicExponent: new Uint8Array([0x01, 0x00, 0x01]),
  5978. hash: {
  5979. name: "SHA-1"
  5980. }
  5981. },
  5982. usages: ["sign", "verify"]
  5983. };
  5984. break;
  5985. case "importkey":
  5986. result = {
  5987. algorithm: {
  5988. name: "RSA-PSS",
  5989. hash: {
  5990. name: "SHA-1"
  5991. }
  5992. },
  5993. usages: ["verify"]
  5994. };
  5995. break;
  5996. case "exportkey":
  5997. default:
  5998. return {
  5999. algorithm: {
  6000. name: "RSA-PSS"
  6001. },
  6002. usages: []
  6003. };
  6004. }
  6005. break;
  6006. case "RSA-OAEP":
  6007. switch (operation.toLowerCase()) {
  6008. case "encrypt":
  6009. case "decrypt":
  6010. result = {
  6011. algorithm: {
  6012. name: "RSA-OAEP"
  6013. },
  6014. usages: ["encrypt", "decrypt"]
  6015. };
  6016. break;
  6017. case "generatekey":
  6018. result = {
  6019. algorithm: {
  6020. name: "RSA-OAEP",
  6021. modulusLength: 2048,
  6022. publicExponent: new Uint8Array([0x01, 0x00, 0x01]),
  6023. hash: {
  6024. name: "SHA-256"
  6025. }
  6026. },
  6027. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6028. };
  6029. break;
  6030. case "importkey":
  6031. result = {
  6032. algorithm: {
  6033. name: "RSA-OAEP",
  6034. hash: {
  6035. name: "SHA-256"
  6036. }
  6037. },
  6038. usages: ["encrypt"]
  6039. };
  6040. break;
  6041. case "exportkey":
  6042. default:
  6043. return {
  6044. algorithm: {
  6045. name: "RSA-OAEP"
  6046. },
  6047. usages: []
  6048. };
  6049. }
  6050. break;
  6051. case "ECDSA":
  6052. switch (operation.toLowerCase()) {
  6053. case "generatekey":
  6054. result = {
  6055. algorithm: {
  6056. name: "ECDSA",
  6057. namedCurve: "P-256"
  6058. },
  6059. usages: ["sign", "verify"]
  6060. };
  6061. break;
  6062. case "importkey":
  6063. result = {
  6064. algorithm: {
  6065. name: "ECDSA",
  6066. namedCurve: "P-256"
  6067. },
  6068. usages: ["verify"]
  6069. };
  6070. break;
  6071. case "verify":
  6072. case "sign":
  6073. result = {
  6074. algorithm: {
  6075. name: "ECDSA",
  6076. hash: {
  6077. name: "SHA-256"
  6078. }
  6079. },
  6080. usages: ["sign"]
  6081. };
  6082. break;
  6083. default:
  6084. return {
  6085. algorithm: {
  6086. name: "ECDSA"
  6087. },
  6088. usages: []
  6089. };
  6090. }
  6091. break;
  6092. case "ECDH":
  6093. switch (operation.toLowerCase()) {
  6094. case "exportkey":
  6095. case "importkey":
  6096. case "generatekey":
  6097. result = {
  6098. algorithm: {
  6099. name: "ECDH",
  6100. namedCurve: "P-256"
  6101. },
  6102. usages: ["deriveKey", "deriveBits"]
  6103. };
  6104. break;
  6105. case "derivekey":
  6106. case "derivebits":
  6107. result = {
  6108. algorithm: {
  6109. name: "ECDH",
  6110. namedCurve: "P-256",
  6111. public: []
  6112. },
  6113. usages: ["encrypt", "decrypt"]
  6114. };
  6115. break;
  6116. default:
  6117. return {
  6118. algorithm: {
  6119. name: "ECDH"
  6120. },
  6121. usages: []
  6122. };
  6123. }
  6124. break;
  6125. case "AES-CTR":
  6126. switch (operation.toLowerCase()) {
  6127. case "importkey":
  6128. case "exportkey":
  6129. case "generatekey":
  6130. result = {
  6131. algorithm: {
  6132. name: "AES-CTR",
  6133. length: 256
  6134. },
  6135. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6136. };
  6137. break;
  6138. case "decrypt":
  6139. case "encrypt":
  6140. result = {
  6141. algorithm: {
  6142. name: "AES-CTR",
  6143. counter: new Uint8Array(16),
  6144. length: 10
  6145. },
  6146. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6147. };
  6148. break;
  6149. default:
  6150. return {
  6151. algorithm: {
  6152. name: "AES-CTR"
  6153. },
  6154. usages: []
  6155. };
  6156. }
  6157. break;
  6158. case "AES-CBC":
  6159. switch (operation.toLowerCase()) {
  6160. case "importkey":
  6161. case "exportkey":
  6162. case "generatekey":
  6163. result = {
  6164. algorithm: {
  6165. name: "AES-CBC",
  6166. length: 256
  6167. },
  6168. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6169. };
  6170. break;
  6171. case "decrypt":
  6172. case "encrypt":
  6173. result = {
  6174. algorithm: {
  6175. name: "AES-CBC",
  6176. iv: this.getRandomValues(new Uint8Array(16))
  6177. },
  6178. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6179. };
  6180. break;
  6181. default:
  6182. return {
  6183. algorithm: {
  6184. name: "AES-CBC"
  6185. },
  6186. usages: []
  6187. };
  6188. }
  6189. break;
  6190. case "AES-GCM":
  6191. switch (operation.toLowerCase()) {
  6192. case "importkey":
  6193. case "exportkey":
  6194. case "generatekey":
  6195. result = {
  6196. algorithm: {
  6197. name: "AES-GCM",
  6198. length: 256
  6199. },
  6200. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6201. };
  6202. break;
  6203. case "decrypt":
  6204. case "encrypt":
  6205. result = {
  6206. algorithm: {
  6207. name: "AES-GCM",
  6208. iv: this.getRandomValues(new Uint8Array(16))
  6209. },
  6210. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6211. };
  6212. break;
  6213. default:
  6214. return {
  6215. algorithm: {
  6216. name: "AES-GCM"
  6217. },
  6218. usages: []
  6219. };
  6220. }
  6221. break;
  6222. case "AES-KW":
  6223. switch (operation.toLowerCase()) {
  6224. case "importkey":
  6225. case "exportkey":
  6226. case "generatekey":
  6227. case "wrapkey":
  6228. case "unwrapkey":
  6229. result = {
  6230. algorithm: {
  6231. name: "AES-KW",
  6232. length: 256
  6233. },
  6234. usages: ["wrapKey", "unwrapKey"]
  6235. };
  6236. break;
  6237. default:
  6238. return {
  6239. algorithm: {
  6240. name: "AES-KW"
  6241. },
  6242. usages: []
  6243. };
  6244. }
  6245. break;
  6246. case "HMAC":
  6247. switch (operation.toLowerCase()) {
  6248. case "sign":
  6249. case "verify":
  6250. result = {
  6251. algorithm: {
  6252. name: "HMAC"
  6253. },
  6254. usages: ["sign", "verify"]
  6255. };
  6256. break;
  6257. case "importkey":
  6258. case "exportkey":
  6259. case "generatekey":
  6260. result = {
  6261. algorithm: {
  6262. name: "HMAC",
  6263. length: 32,
  6264. hash: {
  6265. name: "SHA-256"
  6266. }
  6267. },
  6268. usages: ["sign", "verify"]
  6269. };
  6270. break;
  6271. default:
  6272. return {
  6273. algorithm: {
  6274. name: "HMAC"
  6275. },
  6276. usages: []
  6277. };
  6278. }
  6279. break;
  6280. case "HKDF":
  6281. switch (operation.toLowerCase()) {
  6282. case "derivekey":
  6283. result = {
  6284. algorithm: {
  6285. name: "HKDF",
  6286. hash: "SHA-256",
  6287. salt: new Uint8Array([]),
  6288. info: new Uint8Array([])
  6289. },
  6290. usages: ["encrypt", "decrypt"]
  6291. };
  6292. break;
  6293. default:
  6294. return {
  6295. algorithm: {
  6296. name: "HKDF"
  6297. },
  6298. usages: []
  6299. };
  6300. }
  6301. break;
  6302. case "PBKDF2":
  6303. switch (operation.toLowerCase()) {
  6304. case "derivekey":
  6305. result = {
  6306. algorithm: {
  6307. name: "PBKDF2",
  6308. hash: { name: "SHA-256" },
  6309. salt: new Uint8Array([]),
  6310. iterations: 10000
  6311. },
  6312. usages: ["encrypt", "decrypt"]
  6313. };
  6314. break;
  6315. default:
  6316. return {
  6317. algorithm: {
  6318. name: "PBKDF2"
  6319. },
  6320. usages: []
  6321. };
  6322. }
  6323. break;
  6324. }
  6325. return result;
  6326. }
  6327. getHashAlgorithm(signatureAlgorithm) {
  6328. let result = EMPTY_STRING;
  6329. switch (signatureAlgorithm.algorithmId) {
  6330. case "1.2.840.10045.4.1":
  6331. case "1.2.840.113549.1.1.5":
  6332. result = "SHA-1";
  6333. break;
  6334. case "1.2.840.10045.4.3.2":
  6335. case "1.2.840.113549.1.1.11":
  6336. result = "SHA-256";
  6337. break;
  6338. case "1.2.840.10045.4.3.3":
  6339. case "1.2.840.113549.1.1.12":
  6340. result = "SHA-384";
  6341. break;
  6342. case "1.2.840.10045.4.3.4":
  6343. case "1.2.840.113549.1.1.13":
  6344. result = "SHA-512";
  6345. break;
  6346. case "1.2.840.113549.1.1.10":
  6347. {
  6348. try {
  6349. const params = new RSASSAPSSParams({ schema: signatureAlgorithm.algorithmParams });
  6350. if (params.hashAlgorithm) {
  6351. const algorithm = this.getAlgorithmByOID(params.hashAlgorithm.algorithmId);
  6352. if ("name" in algorithm) {
  6353. result = algorithm.name;
  6354. }
  6355. else {
  6356. return EMPTY_STRING;
  6357. }
  6358. }
  6359. else
  6360. result = "SHA-1";
  6361. }
  6362. catch {
  6363. }
  6364. }
  6365. break;
  6366. }
  6367. return result;
  6368. }
  6369. async encryptEncryptedContentInfo(parameters) {
  6370. ParameterError.assert(parameters, "password", "contentEncryptionAlgorithm", "hmacHashAlgorithm", "iterationCount", "contentToEncrypt", "contentToEncrypt", "contentType");
  6371. const contentEncryptionOID = this.getOIDByAlgorithm(parameters.contentEncryptionAlgorithm, true, "contentEncryptionAlgorithm");
  6372. const pbkdf2OID = this.getOIDByAlgorithm({
  6373. name: "PBKDF2"
  6374. }, true, "PBKDF2");
  6375. const hmacOID = this.getOIDByAlgorithm({
  6376. name: "HMAC",
  6377. hash: {
  6378. name: parameters.hmacHashAlgorithm
  6379. }
  6380. }, true, "hmacHashAlgorithm");
  6381. const ivBuffer = new ArrayBuffer(16);
  6382. const ivView = new Uint8Array(ivBuffer);
  6383. this.getRandomValues(ivView);
  6384. const saltBuffer = new ArrayBuffer(64);
  6385. const saltView = new Uint8Array(saltBuffer);
  6386. this.getRandomValues(saltView);
  6387. const contentView = new Uint8Array(parameters.contentToEncrypt);
  6388. const pbkdf2Params = new PBKDF2Params({
  6389. salt: new asn1js__namespace.OctetString({ valueHex: saltBuffer }),
  6390. iterationCount: parameters.iterationCount,
  6391. prf: new AlgorithmIdentifier({
  6392. algorithmId: hmacOID,
  6393. algorithmParams: new asn1js__namespace.Null()
  6394. })
  6395. });
  6396. const passwordView = new Uint8Array(parameters.password);
  6397. const pbkdfKey = await this.importKey("raw", passwordView, "PBKDF2", false, ["deriveKey"]);
  6398. const derivedKey = await this.deriveKey({
  6399. name: "PBKDF2",
  6400. hash: {
  6401. name: parameters.hmacHashAlgorithm
  6402. },
  6403. salt: saltView,
  6404. iterations: parameters.iterationCount
  6405. }, pbkdfKey, parameters.contentEncryptionAlgorithm, false, ["encrypt"]);
  6406. const encryptedData = await this.encrypt({
  6407. name: parameters.contentEncryptionAlgorithm.name,
  6408. iv: ivView
  6409. }, derivedKey, contentView);
  6410. const pbes2Parameters = new PBES2Params({
  6411. keyDerivationFunc: new AlgorithmIdentifier({
  6412. algorithmId: pbkdf2OID,
  6413. algorithmParams: pbkdf2Params.toSchema()
  6414. }),
  6415. encryptionScheme: new AlgorithmIdentifier({
  6416. algorithmId: contentEncryptionOID,
  6417. algorithmParams: new asn1js__namespace.OctetString({ valueHex: ivBuffer })
  6418. })
  6419. });
  6420. return new EncryptedContentInfo({
  6421. contentType: parameters.contentType,
  6422. contentEncryptionAlgorithm: new AlgorithmIdentifier({
  6423. algorithmId: "1.2.840.113549.1.5.13",
  6424. algorithmParams: pbes2Parameters.toSchema()
  6425. }),
  6426. encryptedContent: new asn1js__namespace.OctetString({ valueHex: encryptedData })
  6427. });
  6428. }
  6429. async decryptEncryptedContentInfo(parameters) {
  6430. ParameterError.assert(parameters, "password", "encryptedContentInfo");
  6431. if (parameters.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId !== "1.2.840.113549.1.5.13")
  6432. throw new Error(`Unknown "contentEncryptionAlgorithm": ${parameters.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId}`);
  6433. let pbes2Parameters;
  6434. try {
  6435. pbes2Parameters = new PBES2Params({ schema: parameters.encryptedContentInfo.contentEncryptionAlgorithm.algorithmParams });
  6436. }
  6437. catch {
  6438. throw new Error("Incorrectly encoded \"pbes2Parameters\"");
  6439. }
  6440. let pbkdf2Params;
  6441. try {
  6442. pbkdf2Params = new PBKDF2Params({ schema: pbes2Parameters.keyDerivationFunc.algorithmParams });
  6443. }
  6444. catch {
  6445. throw new Error("Incorrectly encoded \"pbkdf2Params\"");
  6446. }
  6447. const contentEncryptionAlgorithm = this.getAlgorithmByOID(pbes2Parameters.encryptionScheme.algorithmId, true);
  6448. const ivBuffer = pbes2Parameters.encryptionScheme.algorithmParams.valueBlock.valueHex;
  6449. const ivView = new Uint8Array(ivBuffer);
  6450. const saltBuffer = pbkdf2Params.salt.valueBlock.valueHex;
  6451. const saltView = new Uint8Array(saltBuffer);
  6452. const iterationCount = pbkdf2Params.iterationCount;
  6453. let hmacHashAlgorithm = "SHA-1";
  6454. if (pbkdf2Params.prf) {
  6455. const algorithm = this.getAlgorithmByOID(pbkdf2Params.prf.algorithmId, true);
  6456. hmacHashAlgorithm = algorithm.hash.name;
  6457. }
  6458. const pbkdfKey = await this.importKey("raw", parameters.password, "PBKDF2", false, ["deriveKey"]);
  6459. const result = await this.deriveKey({
  6460. name: "PBKDF2",
  6461. hash: {
  6462. name: hmacHashAlgorithm
  6463. },
  6464. salt: saltView,
  6465. iterations: iterationCount
  6466. }, pbkdfKey, contentEncryptionAlgorithm, false, ["decrypt"]);
  6467. const dataBuffer = parameters.encryptedContentInfo.getEncryptedContent();
  6468. return this.decrypt({
  6469. name: contentEncryptionAlgorithm.name,
  6470. iv: ivView
  6471. }, result, dataBuffer);
  6472. }
  6473. async stampDataWithPassword(parameters) {
  6474. if ((parameters instanceof Object) === false)
  6475. throw new Error("Parameters must have type \"Object\"");
  6476. ParameterError.assert(parameters, "password", "hashAlgorithm", "iterationCount", "salt", "contentToStamp");
  6477. let length;
  6478. switch (parameters.hashAlgorithm.toLowerCase()) {
  6479. case "sha-1":
  6480. length = 160;
  6481. break;
  6482. case "sha-256":
  6483. length = 256;
  6484. break;
  6485. case "sha-384":
  6486. length = 384;
  6487. break;
  6488. case "sha-512":
  6489. length = 512;
  6490. break;
  6491. default:
  6492. throw new Error(`Incorrect "parameters.hashAlgorithm" parameter: ${parameters.hashAlgorithm}`);
  6493. }
  6494. const hmacAlgorithm = {
  6495. name: "HMAC",
  6496. length,
  6497. hash: {
  6498. name: parameters.hashAlgorithm
  6499. }
  6500. };
  6501. const pkcsKey = await makePKCS12B2Key(parameters.hashAlgorithm, length, parameters.password, parameters.salt, parameters.iterationCount);
  6502. const hmacKey = await this.importKey("raw", new Uint8Array(pkcsKey), hmacAlgorithm, false, ["sign"]);
  6503. return this.sign(hmacAlgorithm, hmacKey, new Uint8Array(parameters.contentToStamp));
  6504. }
  6505. async verifyDataStampedWithPassword(parameters) {
  6506. ParameterError.assert(parameters, "password", "hashAlgorithm", "salt", "iterationCount", "contentToVerify", "signatureToVerify");
  6507. let length = 0;
  6508. switch (parameters.hashAlgorithm.toLowerCase()) {
  6509. case "sha-1":
  6510. length = 160;
  6511. break;
  6512. case "sha-256":
  6513. length = 256;
  6514. break;
  6515. case "sha-384":
  6516. length = 384;
  6517. break;
  6518. case "sha-512":
  6519. length = 512;
  6520. break;
  6521. default:
  6522. throw new Error(`Incorrect "parameters.hashAlgorithm" parameter: ${parameters.hashAlgorithm}`);
  6523. }
  6524. const hmacAlgorithm = {
  6525. name: "HMAC",
  6526. length,
  6527. hash: {
  6528. name: parameters.hashAlgorithm
  6529. }
  6530. };
  6531. const pkcsKey = await makePKCS12B2Key(parameters.hashAlgorithm, length, parameters.password, parameters.salt, parameters.iterationCount);
  6532. const hmacKey = await this.importKey("raw", new Uint8Array(pkcsKey), hmacAlgorithm, false, ["verify"]);
  6533. return this.verify(hmacAlgorithm, hmacKey, new Uint8Array(parameters.signatureToVerify), new Uint8Array(parameters.contentToVerify));
  6534. }
  6535. async getSignatureParameters(privateKey, hashAlgorithm = "SHA-1") {
  6536. this.getOIDByAlgorithm({ name: hashAlgorithm }, true, "hashAlgorithm");
  6537. const signatureAlgorithm = new AlgorithmIdentifier();
  6538. const parameters = this.getAlgorithmParameters(privateKey.algorithm.name, "sign");
  6539. if (!Object.keys(parameters.algorithm).length) {
  6540. throw new Error("Parameter 'algorithm' is empty");
  6541. }
  6542. const algorithm = parameters.algorithm;
  6543. if ("hash" in privateKey.algorithm && privateKey.algorithm.hash && privateKey.algorithm.hash.name) {
  6544. algorithm.hash.name = privateKey.algorithm.hash.name;
  6545. }
  6546. else {
  6547. algorithm.hash.name = hashAlgorithm;
  6548. }
  6549. switch (privateKey.algorithm.name.toUpperCase()) {
  6550. case "RSASSA-PKCS1-V1_5":
  6551. case "ECDSA":
  6552. signatureAlgorithm.algorithmId = this.getOIDByAlgorithm(algorithm, true);
  6553. break;
  6554. case "RSA-PSS":
  6555. {
  6556. switch (algorithm.hash.name.toUpperCase()) {
  6557. case "SHA-256":
  6558. algorithm.saltLength = 32;
  6559. break;
  6560. case "SHA-384":
  6561. algorithm.saltLength = 48;
  6562. break;
  6563. case "SHA-512":
  6564. algorithm.saltLength = 64;
  6565. break;
  6566. }
  6567. const paramsObject = {};
  6568. if (algorithm.hash.name.toUpperCase() !== "SHA-1") {
  6569. const hashAlgorithmOID = this.getOIDByAlgorithm({ name: algorithm.hash.name }, true, "hashAlgorithm");
  6570. paramsObject.hashAlgorithm = new AlgorithmIdentifier({
  6571. algorithmId: hashAlgorithmOID,
  6572. algorithmParams: new asn1js__namespace.Null()
  6573. });
  6574. paramsObject.maskGenAlgorithm = new AlgorithmIdentifier({
  6575. algorithmId: "1.2.840.113549.1.1.8",
  6576. algorithmParams: paramsObject.hashAlgorithm.toSchema()
  6577. });
  6578. }
  6579. if (algorithm.saltLength !== 20)
  6580. paramsObject.saltLength = algorithm.saltLength;
  6581. const pssParameters = new RSASSAPSSParams(paramsObject);
  6582. signatureAlgorithm.algorithmId = "1.2.840.113549.1.1.10";
  6583. signatureAlgorithm.algorithmParams = pssParameters.toSchema();
  6584. }
  6585. break;
  6586. default:
  6587. throw new Error(`Unsupported signature algorithm: ${privateKey.algorithm.name}`);
  6588. }
  6589. return {
  6590. signatureAlgorithm,
  6591. parameters
  6592. };
  6593. }
  6594. async signWithPrivateKey(data, privateKey, parameters) {
  6595. const signature = await this.sign(parameters.algorithm, privateKey, data);
  6596. if (parameters.algorithm.name === "ECDSA") {
  6597. return createCMSECDSASignature(signature);
  6598. }
  6599. return signature;
  6600. }
  6601. fillPublicKeyParameters(publicKeyInfo, signatureAlgorithm) {
  6602. const parameters = {};
  6603. const shaAlgorithm = this.getHashAlgorithm(signatureAlgorithm);
  6604. if (shaAlgorithm === EMPTY_STRING)
  6605. throw new Error(`Unsupported signature algorithm: ${signatureAlgorithm.algorithmId}`);
  6606. let algorithmId;
  6607. if (signatureAlgorithm.algorithmId === "1.2.840.113549.1.1.10")
  6608. algorithmId = signatureAlgorithm.algorithmId;
  6609. else
  6610. algorithmId = publicKeyInfo.algorithm.algorithmId;
  6611. const algorithmObject = this.getAlgorithmByOID(algorithmId, true);
  6612. parameters.algorithm = this.getAlgorithmParameters(algorithmObject.name, "importKey");
  6613. if ("hash" in parameters.algorithm.algorithm)
  6614. parameters.algorithm.algorithm.hash.name = shaAlgorithm;
  6615. if (algorithmObject.name === "ECDSA") {
  6616. const publicKeyAlgorithm = publicKeyInfo.algorithm;
  6617. if (!publicKeyAlgorithm.algorithmParams) {
  6618. throw new Error("Algorithm parameters for ECDSA public key are missed");
  6619. }
  6620. const publicKeyAlgorithmParams = publicKeyAlgorithm.algorithmParams;
  6621. if ("idBlock" in publicKeyAlgorithm.algorithmParams) {
  6622. if (!((publicKeyAlgorithmParams.idBlock.tagClass === 1) && (publicKeyAlgorithmParams.idBlock.tagNumber === 6))) {
  6623. throw new Error("Incorrect type for ECDSA public key parameters");
  6624. }
  6625. }
  6626. const curveObject = this.getAlgorithmByOID(publicKeyAlgorithmParams.valueBlock.toString(), true);
  6627. parameters.algorithm.algorithm.namedCurve = curveObject.name;
  6628. }
  6629. return parameters;
  6630. }
  6631. async getPublicKey(publicKeyInfo, signatureAlgorithm, parameters) {
  6632. if (!parameters) {
  6633. parameters = this.fillPublicKeyParameters(publicKeyInfo, signatureAlgorithm);
  6634. }
  6635. const publicKeyInfoBuffer = publicKeyInfo.toSchema().toBER(false);
  6636. return this.importKey("spki", publicKeyInfoBuffer, parameters.algorithm.algorithm, true, parameters.algorithm.usages);
  6637. }
  6638. async verifyWithPublicKey(data, signature, publicKeyInfo, signatureAlgorithm, shaAlgorithm) {
  6639. let publicKey;
  6640. if (!shaAlgorithm) {
  6641. shaAlgorithm = this.getHashAlgorithm(signatureAlgorithm);
  6642. if (!shaAlgorithm)
  6643. throw new Error(`Unsupported signature algorithm: ${signatureAlgorithm.algorithmId}`);
  6644. publicKey = await this.getPublicKey(publicKeyInfo, signatureAlgorithm);
  6645. }
  6646. else {
  6647. const parameters = {};
  6648. let algorithmId;
  6649. if (signatureAlgorithm.algorithmId === "1.2.840.113549.1.1.10")
  6650. algorithmId = signatureAlgorithm.algorithmId;
  6651. else
  6652. algorithmId = publicKeyInfo.algorithm.algorithmId;
  6653. const algorithmObject = this.getAlgorithmByOID(algorithmId, true);
  6654. parameters.algorithm = this.getAlgorithmParameters(algorithmObject.name, "importKey");
  6655. if ("hash" in parameters.algorithm.algorithm)
  6656. parameters.algorithm.algorithm.hash.name = shaAlgorithm;
  6657. if (algorithmObject.name === "ECDSA") {
  6658. let algorithmParamsChecked = false;
  6659. if (("algorithmParams" in publicKeyInfo.algorithm) === true) {
  6660. if ("idBlock" in publicKeyInfo.algorithm.algorithmParams) {
  6661. if ((publicKeyInfo.algorithm.algorithmParams.idBlock.tagClass === 1) && (publicKeyInfo.algorithm.algorithmParams.idBlock.tagNumber === 6))
  6662. algorithmParamsChecked = true;
  6663. }
  6664. }
  6665. if (algorithmParamsChecked === false) {
  6666. throw new Error("Incorrect type for ECDSA public key parameters");
  6667. }
  6668. const curveObject = this.getAlgorithmByOID(publicKeyInfo.algorithm.algorithmParams.valueBlock.toString(), true);
  6669. parameters.algorithm.algorithm.namedCurve = curveObject.name;
  6670. }
  6671. publicKey = await this.getPublicKey(publicKeyInfo, null, parameters);
  6672. }
  6673. const algorithm = this.getAlgorithmParameters(publicKey.algorithm.name, "verify");
  6674. if ("hash" in algorithm.algorithm)
  6675. algorithm.algorithm.hash.name = shaAlgorithm;
  6676. let signatureValue = signature.valueBlock.valueHexView;
  6677. if (publicKey.algorithm.name === "ECDSA") {
  6678. const namedCurve = ECNamedCurves.find(publicKey.algorithm.namedCurve);
  6679. if (!namedCurve) {
  6680. throw new Error("Unsupported named curve in use");
  6681. }
  6682. const asn1 = asn1js__namespace.fromBER(signatureValue);
  6683. AsnError.assert(asn1, "Signature value");
  6684. signatureValue = createECDSASignatureFromCMS(asn1.result, namedCurve.size);
  6685. }
  6686. if (publicKey.algorithm.name === "RSA-PSS") {
  6687. const pssParameters = new RSASSAPSSParams({ schema: signatureAlgorithm.algorithmParams });
  6688. if ("saltLength" in pssParameters)
  6689. algorithm.algorithm.saltLength = pssParameters.saltLength;
  6690. else
  6691. algorithm.algorithm.saltLength = 20;
  6692. let hashAlgo = "SHA-1";
  6693. if ("hashAlgorithm" in pssParameters) {
  6694. const hashAlgorithm = this.getAlgorithmByOID(pssParameters.hashAlgorithm.algorithmId, true);
  6695. hashAlgo = hashAlgorithm.name;
  6696. }
  6697. algorithm.algorithm.hash.name = hashAlgo;
  6698. }
  6699. return this.verify(algorithm.algorithm, publicKey, signatureValue, data);
  6700. }
  6701. }
  6702. exports.engine = {
  6703. name: "none",
  6704. crypto: null,
  6705. };
  6706. function isCryptoEngine(engine) {
  6707. return engine
  6708. && typeof engine === "object"
  6709. && "crypto" in engine
  6710. ? true
  6711. : false;
  6712. }
  6713. function setEngine(name, ...args) {
  6714. let crypto = null;
  6715. if (args.length < 2) {
  6716. if (args.length) {
  6717. crypto = args[0];
  6718. }
  6719. else {
  6720. crypto = typeof self !== "undefined" && self.crypto ? new CryptoEngine({ name: "browser", crypto: self.crypto }) : null;
  6721. }
  6722. }
  6723. else {
  6724. const cryptoArg = args[0];
  6725. const subtleArg = args[1];
  6726. if (isCryptoEngine(subtleArg)) {
  6727. crypto = subtleArg;
  6728. }
  6729. else if (isCryptoEngine(cryptoArg)) {
  6730. crypto = cryptoArg;
  6731. }
  6732. else if ("subtle" in cryptoArg && "getRandomValues" in cryptoArg) {
  6733. crypto = new CryptoEngine({
  6734. crypto: cryptoArg,
  6735. });
  6736. }
  6737. }
  6738. if ((typeof process !== "undefined") && ("pid" in process) && (typeof global !== "undefined") && (typeof window === "undefined")) {
  6739. if (typeof global[process.pid] === "undefined") {
  6740. global[process.pid] = {};
  6741. }
  6742. else {
  6743. if (typeof global[process.pid] !== "object") {
  6744. throw new Error(`Name global.${process.pid} already exists and it is not an object`);
  6745. }
  6746. }
  6747. if (typeof global[process.pid].pkijs === "undefined") {
  6748. global[process.pid].pkijs = {};
  6749. }
  6750. else {
  6751. if (typeof global[process.pid].pkijs !== "object") {
  6752. throw new Error(`Name global.${process.pid}.pkijs already exists and it is not an object`);
  6753. }
  6754. }
  6755. global[process.pid].pkijs.engine = {
  6756. name: name,
  6757. crypto,
  6758. };
  6759. }
  6760. else {
  6761. exports.engine = {
  6762. name: name,
  6763. crypto,
  6764. };
  6765. }
  6766. }
  6767. function getEngine() {
  6768. if ((typeof process !== "undefined") && ("pid" in process) && (typeof global !== "undefined") && (typeof window === "undefined")) {
  6769. let _engine;
  6770. try {
  6771. _engine = global[process.pid].pkijs.engine;
  6772. }
  6773. catch {
  6774. throw new Error("Please call 'setEngine' before call to 'getEngine'");
  6775. }
  6776. return _engine;
  6777. }
  6778. return exports.engine;
  6779. }
  6780. function getCrypto(safety = false) {
  6781. const _engine = getEngine();
  6782. if (!_engine.crypto && safety) {
  6783. throw new Error("Unable to create WebCrypto object");
  6784. }
  6785. return _engine.crypto;
  6786. }
  6787. function getRandomValues(view) {
  6788. return getCrypto(true).getRandomValues(view);
  6789. }
  6790. function getOIDByAlgorithm(algorithm, safety, target) {
  6791. return getCrypto(true).getOIDByAlgorithm(algorithm, safety, target);
  6792. }
  6793. function getAlgorithmParameters(algorithmName, operation) {
  6794. return getCrypto(true).getAlgorithmParameters(algorithmName, operation);
  6795. }
  6796. function createCMSECDSASignature(signatureBuffer) {
  6797. if ((signatureBuffer.byteLength % 2) !== 0)
  6798. return EMPTY_BUFFER;
  6799. const length = signatureBuffer.byteLength / 2;
  6800. const rBuffer = new ArrayBuffer(length);
  6801. const rView = new Uint8Array(rBuffer);
  6802. rView.set(new Uint8Array(signatureBuffer, 0, length));
  6803. const rInteger = new asn1js__namespace.Integer({ valueHex: rBuffer });
  6804. const sBuffer = new ArrayBuffer(length);
  6805. const sView = new Uint8Array(sBuffer);
  6806. sView.set(new Uint8Array(signatureBuffer, length, length));
  6807. const sInteger = new asn1js__namespace.Integer({ valueHex: sBuffer });
  6808. return (new asn1js__namespace.Sequence({
  6809. value: [
  6810. rInteger.convertToDER(),
  6811. sInteger.convertToDER()
  6812. ]
  6813. })).toBER(false);
  6814. }
  6815. function createECDSASignatureFromCMS(cmsSignature, pointSize) {
  6816. if (!(cmsSignature instanceof asn1js__namespace.Sequence
  6817. && cmsSignature.valueBlock.value.length === 2
  6818. && cmsSignature.valueBlock.value[0] instanceof asn1js__namespace.Integer
  6819. && cmsSignature.valueBlock.value[1] instanceof asn1js__namespace.Integer))
  6820. return EMPTY_BUFFER;
  6821. const rValueView = cmsSignature.valueBlock.value[0].convertFromDER().valueBlock.valueHexView;
  6822. const sValueView = cmsSignature.valueBlock.value[1].convertFromDER().valueBlock.valueHexView;
  6823. const res = new Uint8Array(pointSize * 2);
  6824. res.set(rValueView, pointSize - rValueView.byteLength);
  6825. res.set(sValueView, (2 * pointSize) - sValueView.byteLength);
  6826. return res.buffer;
  6827. }
  6828. function getAlgorithmByOID(oid, safety = false, target) {
  6829. return getCrypto(true).getAlgorithmByOID(oid, safety, target);
  6830. }
  6831. function getHashAlgorithm(signatureAlgorithm) {
  6832. return getCrypto(true).getHashAlgorithm(signatureAlgorithm);
  6833. }
  6834. async function kdfWithCounter(hashFunction, zBuffer, Counter, SharedInfo, crypto) {
  6835. switch (hashFunction.toUpperCase()) {
  6836. case "SHA-1":
  6837. case "SHA-256":
  6838. case "SHA-384":
  6839. case "SHA-512":
  6840. break;
  6841. default:
  6842. throw new ArgumentError(`Unknown hash function: ${hashFunction}`);
  6843. }
  6844. ArgumentError.assert(zBuffer, "zBuffer", "ArrayBuffer");
  6845. if (zBuffer.byteLength === 0)
  6846. throw new ArgumentError("'zBuffer' has zero length, error");
  6847. ArgumentError.assert(SharedInfo, "SharedInfo", "ArrayBuffer");
  6848. if (Counter > 255)
  6849. throw new ArgumentError("Please set 'Counter' argument to value less or equal to 255");
  6850. const counterBuffer = new ArrayBuffer(4);
  6851. const counterView = new Uint8Array(counterBuffer);
  6852. counterView[0] = 0x00;
  6853. counterView[1] = 0x00;
  6854. counterView[2] = 0x00;
  6855. counterView[3] = Counter;
  6856. let combinedBuffer = EMPTY_BUFFER;
  6857. combinedBuffer = pvutils__namespace.utilConcatBuf(combinedBuffer, zBuffer);
  6858. combinedBuffer = pvutils__namespace.utilConcatBuf(combinedBuffer, counterBuffer);
  6859. combinedBuffer = pvutils__namespace.utilConcatBuf(combinedBuffer, SharedInfo);
  6860. const result = await crypto.digest({ name: hashFunction }, combinedBuffer);
  6861. return {
  6862. counter: Counter,
  6863. result
  6864. };
  6865. }
  6866. async function kdf(hashFunction, Zbuffer, keydatalen, SharedInfo, crypto = getCrypto(true)) {
  6867. let hashLength = 0;
  6868. let maxCounter = 1;
  6869. switch (hashFunction.toUpperCase()) {
  6870. case "SHA-1":
  6871. hashLength = 160;
  6872. break;
  6873. case "SHA-256":
  6874. hashLength = 256;
  6875. break;
  6876. case "SHA-384":
  6877. hashLength = 384;
  6878. break;
  6879. case "SHA-512":
  6880. hashLength = 512;
  6881. break;
  6882. default:
  6883. throw new ArgumentError(`Unknown hash function: ${hashFunction}`);
  6884. }
  6885. ArgumentError.assert(Zbuffer, "Zbuffer", "ArrayBuffer");
  6886. if (Zbuffer.byteLength === 0)
  6887. throw new ArgumentError("'Zbuffer' has zero length, error");
  6888. ArgumentError.assert(SharedInfo, "SharedInfo", "ArrayBuffer");
  6889. const quotient = keydatalen / hashLength;
  6890. if (Math.floor(quotient) > 0) {
  6891. maxCounter = Math.floor(quotient);
  6892. if ((quotient - maxCounter) > 0)
  6893. maxCounter++;
  6894. }
  6895. const incomingResult = [];
  6896. for (let i = 1; i <= maxCounter; i++)
  6897. incomingResult.push(await kdfWithCounter(hashFunction, Zbuffer, i, SharedInfo, crypto));
  6898. let combinedBuffer = EMPTY_BUFFER;
  6899. let currentCounter = 1;
  6900. let found = true;
  6901. while (found) {
  6902. found = false;
  6903. for (const result of incomingResult) {
  6904. if (result.counter === currentCounter) {
  6905. combinedBuffer = pvutils__namespace.utilConcatBuf(combinedBuffer, result.result);
  6906. found = true;
  6907. break;
  6908. }
  6909. }
  6910. currentCounter++;
  6911. }
  6912. keydatalen >>= 3;
  6913. if (combinedBuffer.byteLength > keydatalen) {
  6914. const newBuffer = new ArrayBuffer(keydatalen);
  6915. const newView = new Uint8Array(newBuffer);
  6916. const combinedView = new Uint8Array(combinedBuffer);
  6917. for (let i = 0; i < keydatalen; i++)
  6918. newView[i] = combinedView[i];
  6919. return newBuffer;
  6920. }
  6921. return combinedBuffer;
  6922. }
  6923. const VERSION$i = "version";
  6924. const LOG_ID = "logID";
  6925. const EXTENSIONS$6 = "extensions";
  6926. const TIMESTAMP = "timestamp";
  6927. const HASH_ALGORITHM$3 = "hashAlgorithm";
  6928. const SIGNATURE_ALGORITHM$8 = "signatureAlgorithm";
  6929. const SIGNATURE$7 = "signature";
  6930. const NONE = "none";
  6931. const MD5 = "md5";
  6932. const SHA1 = "sha1";
  6933. const SHA224 = "sha224";
  6934. const SHA256 = "sha256";
  6935. const SHA384 = "sha384";
  6936. const SHA512 = "sha512";
  6937. const ANONYMOUS = "anonymous";
  6938. const RSA = "rsa";
  6939. const DSA = "dsa";
  6940. const ECDSA = "ecdsa";
  6941. class SignedCertificateTimestamp extends PkiObject {
  6942. constructor(parameters = {}) {
  6943. super();
  6944. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$i, SignedCertificateTimestamp.defaultValues(VERSION$i));
  6945. this.logID = pvutils__namespace.getParametersValue(parameters, LOG_ID, SignedCertificateTimestamp.defaultValues(LOG_ID));
  6946. this.timestamp = pvutils__namespace.getParametersValue(parameters, TIMESTAMP, SignedCertificateTimestamp.defaultValues(TIMESTAMP));
  6947. this.extensions = pvutils__namespace.getParametersValue(parameters, EXTENSIONS$6, SignedCertificateTimestamp.defaultValues(EXTENSIONS$6));
  6948. this.hashAlgorithm = pvutils__namespace.getParametersValue(parameters, HASH_ALGORITHM$3, SignedCertificateTimestamp.defaultValues(HASH_ALGORITHM$3));
  6949. this.signatureAlgorithm = pvutils__namespace.getParametersValue(parameters, SIGNATURE_ALGORITHM$8, SignedCertificateTimestamp.defaultValues(SIGNATURE_ALGORITHM$8));
  6950. this.signature = pvutils__namespace.getParametersValue(parameters, SIGNATURE$7, SignedCertificateTimestamp.defaultValues(SIGNATURE$7));
  6951. if ("stream" in parameters && parameters.stream) {
  6952. this.fromStream(parameters.stream);
  6953. }
  6954. if (parameters.schema) {
  6955. this.fromSchema(parameters.schema);
  6956. }
  6957. }
  6958. static defaultValues(memberName) {
  6959. switch (memberName) {
  6960. case VERSION$i:
  6961. return 0;
  6962. case LOG_ID:
  6963. case EXTENSIONS$6:
  6964. return EMPTY_BUFFER;
  6965. case TIMESTAMP:
  6966. return new Date(0);
  6967. case HASH_ALGORITHM$3:
  6968. case SIGNATURE_ALGORITHM$8:
  6969. return EMPTY_STRING;
  6970. case SIGNATURE$7:
  6971. return EMPTY_BUFFER;
  6972. default:
  6973. return super.defaultValues(memberName);
  6974. }
  6975. }
  6976. fromSchema(schema) {
  6977. if ((schema instanceof asn1js__namespace.RawData) === false)
  6978. throw new Error("Object's schema was not verified against input data for SignedCertificateTimestamp");
  6979. const seqStream = new bs__namespace.SeqStream({
  6980. stream: new bs__namespace.ByteStream({
  6981. buffer: schema.data
  6982. })
  6983. });
  6984. this.fromStream(seqStream);
  6985. }
  6986. fromStream(stream) {
  6987. const blockLength = stream.getUint16();
  6988. this.version = (stream.getBlock(1))[0];
  6989. if (this.version === 0) {
  6990. this.logID = (new Uint8Array(stream.getBlock(32))).buffer.slice(0);
  6991. this.timestamp = new Date(pvutils__namespace.utilFromBase(new Uint8Array(stream.getBlock(8)), 8));
  6992. const extensionsLength = stream.getUint16();
  6993. this.extensions = (new Uint8Array(stream.getBlock(extensionsLength))).buffer.slice(0);
  6994. switch ((stream.getBlock(1))[0]) {
  6995. case 0:
  6996. this.hashAlgorithm = NONE;
  6997. break;
  6998. case 1:
  6999. this.hashAlgorithm = MD5;
  7000. break;
  7001. case 2:
  7002. this.hashAlgorithm = SHA1;
  7003. break;
  7004. case 3:
  7005. this.hashAlgorithm = SHA224;
  7006. break;
  7007. case 4:
  7008. this.hashAlgorithm = SHA256;
  7009. break;
  7010. case 5:
  7011. this.hashAlgorithm = SHA384;
  7012. break;
  7013. case 6:
  7014. this.hashAlgorithm = SHA512;
  7015. break;
  7016. default:
  7017. throw new Error("Object's stream was not correct for SignedCertificateTimestamp");
  7018. }
  7019. switch ((stream.getBlock(1))[0]) {
  7020. case 0:
  7021. this.signatureAlgorithm = ANONYMOUS;
  7022. break;
  7023. case 1:
  7024. this.signatureAlgorithm = RSA;
  7025. break;
  7026. case 2:
  7027. this.signatureAlgorithm = DSA;
  7028. break;
  7029. case 3:
  7030. this.signatureAlgorithm = ECDSA;
  7031. break;
  7032. default:
  7033. throw new Error("Object's stream was not correct for SignedCertificateTimestamp");
  7034. }
  7035. const signatureLength = stream.getUint16();
  7036. this.signature = new Uint8Array(stream.getBlock(signatureLength)).buffer.slice(0);
  7037. if (blockLength !== (47 + extensionsLength + signatureLength)) {
  7038. throw new Error("Object's stream was not correct for SignedCertificateTimestamp");
  7039. }
  7040. }
  7041. }
  7042. toSchema() {
  7043. const stream = this.toStream();
  7044. return new asn1js__namespace.RawData({ data: stream.stream.buffer });
  7045. }
  7046. toStream() {
  7047. const stream = new bs__namespace.SeqStream();
  7048. stream.appendUint16(47 + this.extensions.byteLength + this.signature.byteLength);
  7049. stream.appendChar(this.version);
  7050. stream.appendView(new Uint8Array(this.logID));
  7051. const timeBuffer = new ArrayBuffer(8);
  7052. const timeView = new Uint8Array(timeBuffer);
  7053. const baseArray = pvutils__namespace.utilToBase(this.timestamp.valueOf(), 8);
  7054. timeView.set(new Uint8Array(baseArray), 8 - baseArray.byteLength);
  7055. stream.appendView(timeView);
  7056. stream.appendUint16(this.extensions.byteLength);
  7057. if (this.extensions.byteLength)
  7058. stream.appendView(new Uint8Array(this.extensions));
  7059. let _hashAlgorithm;
  7060. switch (this.hashAlgorithm.toLowerCase()) {
  7061. case NONE:
  7062. _hashAlgorithm = 0;
  7063. break;
  7064. case MD5:
  7065. _hashAlgorithm = 1;
  7066. break;
  7067. case SHA1:
  7068. _hashAlgorithm = 2;
  7069. break;
  7070. case SHA224:
  7071. _hashAlgorithm = 3;
  7072. break;
  7073. case SHA256:
  7074. _hashAlgorithm = 4;
  7075. break;
  7076. case SHA384:
  7077. _hashAlgorithm = 5;
  7078. break;
  7079. case SHA512:
  7080. _hashAlgorithm = 6;
  7081. break;
  7082. default:
  7083. throw new Error(`Incorrect data for hashAlgorithm: ${this.hashAlgorithm}`);
  7084. }
  7085. stream.appendChar(_hashAlgorithm);
  7086. let _signatureAlgorithm;
  7087. switch (this.signatureAlgorithm.toLowerCase()) {
  7088. case ANONYMOUS:
  7089. _signatureAlgorithm = 0;
  7090. break;
  7091. case RSA:
  7092. _signatureAlgorithm = 1;
  7093. break;
  7094. case DSA:
  7095. _signatureAlgorithm = 2;
  7096. break;
  7097. case ECDSA:
  7098. _signatureAlgorithm = 3;
  7099. break;
  7100. default:
  7101. throw new Error(`Incorrect data for signatureAlgorithm: ${this.signatureAlgorithm}`);
  7102. }
  7103. stream.appendChar(_signatureAlgorithm);
  7104. stream.appendUint16(this.signature.byteLength);
  7105. stream.appendView(new Uint8Array(this.signature));
  7106. return stream;
  7107. }
  7108. toJSON() {
  7109. return {
  7110. version: this.version,
  7111. logID: pvutils__namespace.bufferToHexCodes(this.logID),
  7112. timestamp: this.timestamp,
  7113. extensions: pvutils__namespace.bufferToHexCodes(this.extensions),
  7114. hashAlgorithm: this.hashAlgorithm,
  7115. signatureAlgorithm: this.signatureAlgorithm,
  7116. signature: pvutils__namespace.bufferToHexCodes(this.signature),
  7117. };
  7118. }
  7119. async verify(logs, data, dataType = 0, crypto = getCrypto(true)) {
  7120. const logId = pvutils__namespace.toBase64(pvutils__namespace.arrayBufferToString(this.logID));
  7121. let publicKeyBase64 = null;
  7122. const stream = new bs__namespace.SeqStream();
  7123. for (const log of logs) {
  7124. if (log.log_id === logId) {
  7125. publicKeyBase64 = log.key;
  7126. break;
  7127. }
  7128. }
  7129. if (!publicKeyBase64) {
  7130. throw new Error(`Public key not found for CT with logId: ${logId}`);
  7131. }
  7132. const pki = pvutils__namespace.stringToArrayBuffer(pvutils__namespace.fromBase64(publicKeyBase64));
  7133. const publicKeyInfo = PublicKeyInfo.fromBER(pki);
  7134. stream.appendChar(0x00);
  7135. stream.appendChar(0x00);
  7136. const timeBuffer = new ArrayBuffer(8);
  7137. const timeView = new Uint8Array(timeBuffer);
  7138. const baseArray = pvutils__namespace.utilToBase(this.timestamp.valueOf(), 8);
  7139. timeView.set(new Uint8Array(baseArray), 8 - baseArray.byteLength);
  7140. stream.appendView(timeView);
  7141. stream.appendUint16(dataType);
  7142. if (dataType === 0)
  7143. stream.appendUint24(data.byteLength);
  7144. stream.appendView(new Uint8Array(data));
  7145. stream.appendUint16(this.extensions.byteLength);
  7146. if (this.extensions.byteLength !== 0)
  7147. stream.appendView(new Uint8Array(this.extensions));
  7148. return crypto.verifyWithPublicKey(stream.buffer.slice(0, stream.length), new asn1js__namespace.OctetString({ valueHex: this.signature }), publicKeyInfo, { algorithmId: EMPTY_STRING }, "SHA-256");
  7149. }
  7150. }
  7151. SignedCertificateTimestamp.CLASS_NAME = "SignedCertificateTimestamp";
  7152. async function verifySCTsForCertificate(certificate, issuerCertificate, logs, index = (-1), crypto = getCrypto(true)) {
  7153. let parsedValue = null;
  7154. const stream = new bs__namespace.SeqStream();
  7155. if (certificate.extensions) {
  7156. for (let i = certificate.extensions.length - 1; i >= 0; i--) {
  7157. switch (certificate.extensions[i].extnID) {
  7158. case id_SignedCertificateTimestampList:
  7159. {
  7160. parsedValue = certificate.extensions[i].parsedValue;
  7161. if (!parsedValue || parsedValue.timestamps.length === 0)
  7162. throw new Error("Nothing to verify in the certificate");
  7163. certificate.extensions.splice(i, 1);
  7164. }
  7165. break;
  7166. }
  7167. }
  7168. }
  7169. if (parsedValue === null)
  7170. throw new Error("No SignedCertificateTimestampList extension in the specified certificate");
  7171. const tbs = certificate.encodeTBS().toBER();
  7172. const issuerId = await crypto.digest({ name: "SHA-256" }, new Uint8Array(issuerCertificate.subjectPublicKeyInfo.toSchema().toBER(false)));
  7173. stream.appendView(new Uint8Array(issuerId));
  7174. stream.appendUint24(tbs.byteLength);
  7175. stream.appendView(new Uint8Array(tbs));
  7176. const preCert = stream.stream.slice(0, stream.length);
  7177. if (index === (-1)) {
  7178. const verifyArray = [];
  7179. for (const timestamp of parsedValue.timestamps) {
  7180. const verifyResult = await timestamp.verify(logs, preCert.buffer, 1, crypto);
  7181. verifyArray.push(verifyResult);
  7182. }
  7183. return verifyArray;
  7184. }
  7185. if (index >= parsedValue.timestamps.length)
  7186. index = (parsedValue.timestamps.length - 1);
  7187. return [await parsedValue.timestamps[index].verify(logs, preCert.buffer, 1, crypto)];
  7188. }
  7189. const TIMESTAMPS = "timestamps";
  7190. class SignedCertificateTimestampList extends PkiObject {
  7191. constructor(parameters = {}) {
  7192. super();
  7193. this.timestamps = pvutils__namespace.getParametersValue(parameters, TIMESTAMPS, SignedCertificateTimestampList.defaultValues(TIMESTAMPS));
  7194. if (parameters.schema) {
  7195. this.fromSchema(parameters.schema);
  7196. }
  7197. }
  7198. static defaultValues(memberName) {
  7199. switch (memberName) {
  7200. case TIMESTAMPS:
  7201. return [];
  7202. default:
  7203. return super.defaultValues(memberName);
  7204. }
  7205. }
  7206. static compareWithDefault(memberName, memberValue) {
  7207. switch (memberName) {
  7208. case TIMESTAMPS:
  7209. return (memberValue.length === 0);
  7210. default:
  7211. return super.defaultValues(memberName);
  7212. }
  7213. }
  7214. static schema(parameters = {}) {
  7215. var _a;
  7216. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  7217. (_a = names.optional) !== null && _a !== void 0 ? _a : (names.optional = false);
  7218. return (new asn1js__namespace.OctetString({
  7219. name: (names.blockName || "SignedCertificateTimestampList"),
  7220. optional: names.optional
  7221. }));
  7222. }
  7223. fromSchema(schema) {
  7224. if ((schema instanceof asn1js__namespace.OctetString) === false) {
  7225. throw new Error("Object's schema was not verified against input data for SignedCertificateTimestampList");
  7226. }
  7227. const seqStream = new bs__namespace.SeqStream({
  7228. stream: new bs__namespace.ByteStream({
  7229. buffer: schema.valueBlock.valueHex
  7230. })
  7231. });
  7232. const dataLength = seqStream.getUint16();
  7233. if (dataLength !== seqStream.length) {
  7234. throw new Error("Object's schema was not verified against input data for SignedCertificateTimestampList");
  7235. }
  7236. while (seqStream.length) {
  7237. this.timestamps.push(new SignedCertificateTimestamp({ stream: seqStream }));
  7238. }
  7239. }
  7240. toSchema() {
  7241. const stream = new bs__namespace.SeqStream();
  7242. let overallLength = 0;
  7243. const timestampsData = [];
  7244. for (const timestamp of this.timestamps) {
  7245. const timestampStream = timestamp.toStream();
  7246. timestampsData.push(timestampStream);
  7247. overallLength += timestampStream.stream.buffer.byteLength;
  7248. }
  7249. stream.appendUint16(overallLength);
  7250. for (const timestamp of timestampsData) {
  7251. stream.appendView(timestamp.stream.view);
  7252. }
  7253. return new asn1js__namespace.OctetString({ valueHex: stream.stream.buffer.slice(0) });
  7254. }
  7255. toJSON() {
  7256. return {
  7257. timestamps: Array.from(this.timestamps, o => o.toJSON())
  7258. };
  7259. }
  7260. }
  7261. SignedCertificateTimestampList.CLASS_NAME = "SignedCertificateTimestampList";
  7262. const ATTRIBUTES$4 = "attributes";
  7263. const CLEAR_PROPS$11 = [
  7264. ATTRIBUTES$4
  7265. ];
  7266. class SubjectDirectoryAttributes extends PkiObject {
  7267. constructor(parameters = {}) {
  7268. super();
  7269. this.attributes = pvutils__namespace.getParametersValue(parameters, ATTRIBUTES$4, SubjectDirectoryAttributes.defaultValues(ATTRIBUTES$4));
  7270. if (parameters.schema) {
  7271. this.fromSchema(parameters.schema);
  7272. }
  7273. }
  7274. static defaultValues(memberName) {
  7275. switch (memberName) {
  7276. case ATTRIBUTES$4:
  7277. return [];
  7278. default:
  7279. return super.defaultValues(memberName);
  7280. }
  7281. }
  7282. static schema(parameters = {}) {
  7283. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  7284. return (new asn1js__namespace.Sequence({
  7285. name: (names.blockName || EMPTY_STRING),
  7286. value: [
  7287. new asn1js__namespace.Repeated({
  7288. name: (names.attributes || EMPTY_STRING),
  7289. value: Attribute.schema()
  7290. })
  7291. ]
  7292. }));
  7293. }
  7294. fromSchema(schema) {
  7295. pvutils__namespace.clearProps(schema, CLEAR_PROPS$11);
  7296. const asn1 = asn1js__namespace.compareSchema(schema, schema, SubjectDirectoryAttributes.schema({
  7297. names: {
  7298. attributes: ATTRIBUTES$4
  7299. }
  7300. }));
  7301. AsnError.assertSchema(asn1, this.className);
  7302. this.attributes = Array.from(asn1.result.attributes, element => new Attribute({ schema: element }));
  7303. }
  7304. toSchema() {
  7305. return (new asn1js__namespace.Sequence({
  7306. value: Array.from(this.attributes, o => o.toSchema())
  7307. }));
  7308. }
  7309. toJSON() {
  7310. return {
  7311. attributes: Array.from(this.attributes, o => o.toJSON())
  7312. };
  7313. }
  7314. }
  7315. SubjectDirectoryAttributes.CLASS_NAME = "SubjectDirectoryAttributes";
  7316. class ExtensionValueFactory {
  7317. static getItems() {
  7318. if (!this.types) {
  7319. this.types = {};
  7320. ExtensionValueFactory.register(id_SubjectAltName, "SubjectAltName", AltName);
  7321. ExtensionValueFactory.register(id_IssuerAltName, "IssuerAltName", AltName);
  7322. ExtensionValueFactory.register(id_AuthorityKeyIdentifier, "AuthorityKeyIdentifier", AuthorityKeyIdentifier);
  7323. ExtensionValueFactory.register(id_BasicConstraints, "BasicConstraints", BasicConstraints);
  7324. ExtensionValueFactory.register(id_MicrosoftCaVersion, "MicrosoftCaVersion", CAVersion);
  7325. ExtensionValueFactory.register(id_CertificatePolicies, "CertificatePolicies", CertificatePolicies);
  7326. ExtensionValueFactory.register(id_MicrosoftAppPolicies, "CertificatePoliciesMicrosoft", CertificatePolicies);
  7327. ExtensionValueFactory.register(id_MicrosoftCertTemplateV2, "MicrosoftCertTemplateV2", CertificateTemplate);
  7328. ExtensionValueFactory.register(id_CRLDistributionPoints, "CRLDistributionPoints", CRLDistributionPoints);
  7329. ExtensionValueFactory.register(id_FreshestCRL, "FreshestCRL", CRLDistributionPoints);
  7330. ExtensionValueFactory.register(id_ExtKeyUsage, "ExtKeyUsage", ExtKeyUsage);
  7331. ExtensionValueFactory.register(id_CertificateIssuer, "CertificateIssuer", GeneralNames);
  7332. ExtensionValueFactory.register(id_AuthorityInfoAccess, "AuthorityInfoAccess", InfoAccess);
  7333. ExtensionValueFactory.register(id_SubjectInfoAccess, "SubjectInfoAccess", InfoAccess);
  7334. ExtensionValueFactory.register(id_IssuingDistributionPoint, "IssuingDistributionPoint", IssuingDistributionPoint);
  7335. ExtensionValueFactory.register(id_NameConstraints, "NameConstraints", NameConstraints);
  7336. ExtensionValueFactory.register(id_PolicyConstraints, "PolicyConstraints", PolicyConstraints);
  7337. ExtensionValueFactory.register(id_PolicyMappings, "PolicyMappings", PolicyMappings);
  7338. ExtensionValueFactory.register(id_PrivateKeyUsagePeriod, "PrivateKeyUsagePeriod", PrivateKeyUsagePeriod);
  7339. ExtensionValueFactory.register(id_QCStatements, "QCStatements", QCStatements);
  7340. ExtensionValueFactory.register(id_SignedCertificateTimestampList, "SignedCertificateTimestampList", SignedCertificateTimestampList);
  7341. ExtensionValueFactory.register(id_SubjectDirectoryAttributes, "SubjectDirectoryAttributes", SubjectDirectoryAttributes);
  7342. }
  7343. return this.types;
  7344. }
  7345. static fromBER(id, raw) {
  7346. const asn1 = asn1js__namespace.fromBER(raw);
  7347. if (asn1.offset === -1) {
  7348. return null;
  7349. }
  7350. const item = this.find(id);
  7351. if (item) {
  7352. try {
  7353. return new item.type({ schema: asn1.result });
  7354. }
  7355. catch {
  7356. const res = new item.type();
  7357. res.parsingError = `Incorrectly formatted value of extension ${item.name} (${id})`;
  7358. return res;
  7359. }
  7360. }
  7361. return asn1.result;
  7362. }
  7363. static find(id) {
  7364. const types = this.getItems();
  7365. return types[id] || null;
  7366. }
  7367. static register(id, name, type) {
  7368. this.getItems()[id] = { name, type };
  7369. }
  7370. }
  7371. const EXTN_ID = "extnID";
  7372. const CRITICAL = "critical";
  7373. const EXTN_VALUE = "extnValue";
  7374. const PARSED_VALUE$5 = "parsedValue";
  7375. const CLEAR_PROPS$10 = [
  7376. EXTN_ID,
  7377. CRITICAL,
  7378. EXTN_VALUE
  7379. ];
  7380. class Extension extends PkiObject {
  7381. get parsedValue() {
  7382. if (this._parsedValue === undefined) {
  7383. const parsedValue = ExtensionValueFactory.fromBER(this.extnID, this.extnValue.valueBlock.valueHexView);
  7384. this._parsedValue = parsedValue;
  7385. }
  7386. return this._parsedValue || undefined;
  7387. }
  7388. set parsedValue(value) {
  7389. this._parsedValue = value;
  7390. }
  7391. constructor(parameters = {}) {
  7392. super();
  7393. this.extnID = pvutils__namespace.getParametersValue(parameters, EXTN_ID, Extension.defaultValues(EXTN_ID));
  7394. this.critical = pvutils__namespace.getParametersValue(parameters, CRITICAL, Extension.defaultValues(CRITICAL));
  7395. if (EXTN_VALUE in parameters) {
  7396. this.extnValue = new asn1js__namespace.OctetString({ valueHex: parameters.extnValue });
  7397. }
  7398. else {
  7399. this.extnValue = Extension.defaultValues(EXTN_VALUE);
  7400. }
  7401. if (PARSED_VALUE$5 in parameters) {
  7402. this.parsedValue = pvutils__namespace.getParametersValue(parameters, PARSED_VALUE$5, Extension.defaultValues(PARSED_VALUE$5));
  7403. }
  7404. if (parameters.schema) {
  7405. this.fromSchema(parameters.schema);
  7406. }
  7407. }
  7408. static defaultValues(memberName) {
  7409. switch (memberName) {
  7410. case EXTN_ID:
  7411. return EMPTY_STRING;
  7412. case CRITICAL:
  7413. return false;
  7414. case EXTN_VALUE:
  7415. return new asn1js__namespace.OctetString();
  7416. case PARSED_VALUE$5:
  7417. return {};
  7418. default:
  7419. return super.defaultValues(memberName);
  7420. }
  7421. }
  7422. static schema(parameters = {}) {
  7423. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  7424. return (new asn1js__namespace.Sequence({
  7425. name: (names.blockName || EMPTY_STRING),
  7426. value: [
  7427. new asn1js__namespace.ObjectIdentifier({ name: (names.extnID || EMPTY_STRING) }),
  7428. new asn1js__namespace.Boolean({
  7429. name: (names.critical || EMPTY_STRING),
  7430. optional: true
  7431. }),
  7432. new asn1js__namespace.OctetString({ name: (names.extnValue || EMPTY_STRING) })
  7433. ]
  7434. }));
  7435. }
  7436. fromSchema(schema) {
  7437. pvutils__namespace.clearProps(schema, CLEAR_PROPS$10);
  7438. const asn1 = asn1js__namespace.compareSchema(schema, schema, Extension.schema({
  7439. names: {
  7440. extnID: EXTN_ID,
  7441. critical: CRITICAL,
  7442. extnValue: EXTN_VALUE
  7443. }
  7444. }));
  7445. AsnError.assertSchema(asn1, this.className);
  7446. this.extnID = asn1.result.extnID.valueBlock.toString();
  7447. if (CRITICAL in asn1.result) {
  7448. this.critical = asn1.result.critical.valueBlock.value;
  7449. }
  7450. this.extnValue = asn1.result.extnValue;
  7451. }
  7452. toSchema() {
  7453. const outputArray = [];
  7454. outputArray.push(new asn1js__namespace.ObjectIdentifier({ value: this.extnID }));
  7455. if (this.critical !== Extension.defaultValues(CRITICAL)) {
  7456. outputArray.push(new asn1js__namespace.Boolean({ value: this.critical }));
  7457. }
  7458. outputArray.push(this.extnValue);
  7459. return (new asn1js__namespace.Sequence({
  7460. value: outputArray
  7461. }));
  7462. }
  7463. toJSON() {
  7464. const object = {
  7465. extnID: this.extnID,
  7466. extnValue: this.extnValue.toJSON(),
  7467. };
  7468. if (this.critical !== Extension.defaultValues(CRITICAL)) {
  7469. object.critical = this.critical;
  7470. }
  7471. if (this.parsedValue && this.parsedValue.toJSON) {
  7472. object.parsedValue = this.parsedValue.toJSON();
  7473. }
  7474. return object;
  7475. }
  7476. }
  7477. Extension.CLASS_NAME = "Extension";
  7478. const EXTENSIONS$5 = "extensions";
  7479. const CLEAR_PROPS$$ = [
  7480. EXTENSIONS$5,
  7481. ];
  7482. class Extensions extends PkiObject {
  7483. constructor(parameters = {}) {
  7484. super();
  7485. this.extensions = pvutils__namespace.getParametersValue(parameters, EXTENSIONS$5, Extensions.defaultValues(EXTENSIONS$5));
  7486. if (parameters.schema) {
  7487. this.fromSchema(parameters.schema);
  7488. }
  7489. }
  7490. static defaultValues(memberName) {
  7491. switch (memberName) {
  7492. case EXTENSIONS$5:
  7493. return [];
  7494. default:
  7495. return super.defaultValues(memberName);
  7496. }
  7497. }
  7498. static schema(parameters = {}, optional = false) {
  7499. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  7500. return (new asn1js__namespace.Sequence({
  7501. optional,
  7502. name: (names.blockName || EMPTY_STRING),
  7503. value: [
  7504. new asn1js__namespace.Repeated({
  7505. name: (names.extensions || EMPTY_STRING),
  7506. value: Extension.schema(names.extension || {})
  7507. })
  7508. ]
  7509. }));
  7510. }
  7511. fromSchema(schema) {
  7512. pvutils__namespace.clearProps(schema, CLEAR_PROPS$$);
  7513. const asn1 = asn1js__namespace.compareSchema(schema, schema, Extensions.schema({
  7514. names: {
  7515. extensions: EXTENSIONS$5
  7516. }
  7517. }));
  7518. AsnError.assertSchema(asn1, this.className);
  7519. this.extensions = Array.from(asn1.result.extensions, element => new Extension({ schema: element }));
  7520. }
  7521. toSchema() {
  7522. return (new asn1js__namespace.Sequence({
  7523. value: Array.from(this.extensions, o => o.toSchema())
  7524. }));
  7525. }
  7526. toJSON() {
  7527. return {
  7528. extensions: this.extensions.map(o => o.toJSON())
  7529. };
  7530. }
  7531. }
  7532. Extensions.CLASS_NAME = "Extensions";
  7533. const ISSUER$5 = "issuer";
  7534. const SERIAL_NUMBER$6 = "serialNumber";
  7535. const ISSUER_UID = "issuerUID";
  7536. const CLEAR_PROPS$_ = [
  7537. ISSUER$5,
  7538. SERIAL_NUMBER$6,
  7539. ISSUER_UID,
  7540. ];
  7541. class IssuerSerial extends PkiObject {
  7542. constructor(parameters = {}) {
  7543. super();
  7544. this.issuer = pvutils__namespace.getParametersValue(parameters, ISSUER$5, IssuerSerial.defaultValues(ISSUER$5));
  7545. this.serialNumber = pvutils__namespace.getParametersValue(parameters, SERIAL_NUMBER$6, IssuerSerial.defaultValues(SERIAL_NUMBER$6));
  7546. if (ISSUER_UID in parameters) {
  7547. this.issuerUID = pvutils__namespace.getParametersValue(parameters, ISSUER_UID, IssuerSerial.defaultValues(ISSUER_UID));
  7548. }
  7549. if (parameters.schema) {
  7550. this.fromSchema(parameters.schema);
  7551. }
  7552. }
  7553. static defaultValues(memberName) {
  7554. switch (memberName) {
  7555. case ISSUER$5:
  7556. return new GeneralNames();
  7557. case SERIAL_NUMBER$6:
  7558. return new asn1js__namespace.Integer();
  7559. case ISSUER_UID:
  7560. return new asn1js__namespace.BitString();
  7561. default:
  7562. return super.defaultValues(memberName);
  7563. }
  7564. }
  7565. static schema(parameters = {}) {
  7566. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  7567. return (new asn1js__namespace.Sequence({
  7568. name: (names.blockName || EMPTY_STRING),
  7569. value: [
  7570. GeneralNames.schema(names.issuer || {}),
  7571. new asn1js__namespace.Integer({ name: (names.serialNumber || EMPTY_STRING) }),
  7572. new asn1js__namespace.BitString({
  7573. optional: true,
  7574. name: (names.issuerUID || EMPTY_STRING)
  7575. })
  7576. ]
  7577. }));
  7578. }
  7579. fromSchema(schema) {
  7580. pvutils__namespace.clearProps(schema, CLEAR_PROPS$_);
  7581. const asn1 = asn1js__namespace.compareSchema(schema, schema, IssuerSerial.schema({
  7582. names: {
  7583. issuer: {
  7584. names: {
  7585. blockName: ISSUER$5
  7586. }
  7587. },
  7588. serialNumber: SERIAL_NUMBER$6,
  7589. issuerUID: ISSUER_UID
  7590. }
  7591. }));
  7592. AsnError.assertSchema(asn1, this.className);
  7593. this.issuer = new GeneralNames({ schema: asn1.result.issuer });
  7594. this.serialNumber = asn1.result.serialNumber;
  7595. if (ISSUER_UID in asn1.result)
  7596. this.issuerUID = asn1.result.issuerUID;
  7597. }
  7598. toSchema() {
  7599. const result = new asn1js__namespace.Sequence({
  7600. value: [
  7601. this.issuer.toSchema(),
  7602. this.serialNumber
  7603. ]
  7604. });
  7605. if (this.issuerUID) {
  7606. result.valueBlock.value.push(this.issuerUID);
  7607. }
  7608. return result;
  7609. }
  7610. toJSON() {
  7611. const result = {
  7612. issuer: this.issuer.toJSON(),
  7613. serialNumber: this.serialNumber.toJSON()
  7614. };
  7615. if (this.issuerUID) {
  7616. result.issuerUID = this.issuerUID.toJSON();
  7617. }
  7618. return result;
  7619. }
  7620. }
  7621. IssuerSerial.CLASS_NAME = "IssuerSerial";
  7622. const VERSION$h = "version";
  7623. const BASE_CERTIFICATE_ID$2 = "baseCertificateID";
  7624. const SUBJECT_NAME = "subjectName";
  7625. const ISSUER$4 = "issuer";
  7626. const SIGNATURE$6 = "signature";
  7627. const SERIAL_NUMBER$5 = "serialNumber";
  7628. const ATTR_CERT_VALIDITY_PERIOD$1 = "attrCertValidityPeriod";
  7629. const ATTRIBUTES$3 = "attributes";
  7630. const ISSUER_UNIQUE_ID$2 = "issuerUniqueID";
  7631. const EXTENSIONS$4 = "extensions";
  7632. const CLEAR_PROPS$Z = [
  7633. VERSION$h,
  7634. BASE_CERTIFICATE_ID$2,
  7635. SUBJECT_NAME,
  7636. ISSUER$4,
  7637. SIGNATURE$6,
  7638. SERIAL_NUMBER$5,
  7639. ATTR_CERT_VALIDITY_PERIOD$1,
  7640. ATTRIBUTES$3,
  7641. ISSUER_UNIQUE_ID$2,
  7642. EXTENSIONS$4,
  7643. ];
  7644. class AttributeCertificateInfoV1 extends PkiObject {
  7645. constructor(parameters = {}) {
  7646. super();
  7647. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$h, AttributeCertificateInfoV1.defaultValues(VERSION$h));
  7648. if (BASE_CERTIFICATE_ID$2 in parameters) {
  7649. this.baseCertificateID = pvutils__namespace.getParametersValue(parameters, BASE_CERTIFICATE_ID$2, AttributeCertificateInfoV1.defaultValues(BASE_CERTIFICATE_ID$2));
  7650. }
  7651. if (SUBJECT_NAME in parameters) {
  7652. this.subjectName = pvutils__namespace.getParametersValue(parameters, SUBJECT_NAME, AttributeCertificateInfoV1.defaultValues(SUBJECT_NAME));
  7653. }
  7654. this.issuer = pvutils__namespace.getParametersValue(parameters, ISSUER$4, AttributeCertificateInfoV1.defaultValues(ISSUER$4));
  7655. this.signature = pvutils__namespace.getParametersValue(parameters, SIGNATURE$6, AttributeCertificateInfoV1.defaultValues(SIGNATURE$6));
  7656. this.serialNumber = pvutils__namespace.getParametersValue(parameters, SERIAL_NUMBER$5, AttributeCertificateInfoV1.defaultValues(SERIAL_NUMBER$5));
  7657. this.attrCertValidityPeriod = pvutils__namespace.getParametersValue(parameters, ATTR_CERT_VALIDITY_PERIOD$1, AttributeCertificateInfoV1.defaultValues(ATTR_CERT_VALIDITY_PERIOD$1));
  7658. this.attributes = pvutils__namespace.getParametersValue(parameters, ATTRIBUTES$3, AttributeCertificateInfoV1.defaultValues(ATTRIBUTES$3));
  7659. if (ISSUER_UNIQUE_ID$2 in parameters)
  7660. this.issuerUniqueID = pvutils__namespace.getParametersValue(parameters, ISSUER_UNIQUE_ID$2, AttributeCertificateInfoV1.defaultValues(ISSUER_UNIQUE_ID$2));
  7661. if (EXTENSIONS$4 in parameters) {
  7662. this.extensions = pvutils__namespace.getParametersValue(parameters, EXTENSIONS$4, AttributeCertificateInfoV1.defaultValues(EXTENSIONS$4));
  7663. }
  7664. if (parameters.schema) {
  7665. this.fromSchema(parameters.schema);
  7666. }
  7667. }
  7668. static defaultValues(memberName) {
  7669. switch (memberName) {
  7670. case VERSION$h:
  7671. return 0;
  7672. case BASE_CERTIFICATE_ID$2:
  7673. return new IssuerSerial();
  7674. case SUBJECT_NAME:
  7675. return new GeneralNames();
  7676. case ISSUER$4:
  7677. return new GeneralNames();
  7678. case SIGNATURE$6:
  7679. return new AlgorithmIdentifier();
  7680. case SERIAL_NUMBER$5:
  7681. return new asn1js__namespace.Integer();
  7682. case ATTR_CERT_VALIDITY_PERIOD$1:
  7683. return new AttCertValidityPeriod();
  7684. case ATTRIBUTES$3:
  7685. return [];
  7686. case ISSUER_UNIQUE_ID$2:
  7687. return new asn1js__namespace.BitString();
  7688. case EXTENSIONS$4:
  7689. return new Extensions();
  7690. default:
  7691. return super.defaultValues(memberName);
  7692. }
  7693. }
  7694. static schema(parameters = {}) {
  7695. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  7696. return (new asn1js__namespace.Sequence({
  7697. name: (names.blockName || EMPTY_STRING),
  7698. value: [
  7699. new asn1js__namespace.Integer({ name: (names.version || EMPTY_STRING) }),
  7700. new asn1js__namespace.Choice({
  7701. value: [
  7702. new asn1js__namespace.Constructed({
  7703. name: (names.baseCertificateID || EMPTY_STRING),
  7704. idBlock: {
  7705. tagClass: 3,
  7706. tagNumber: 0
  7707. },
  7708. value: IssuerSerial.schema().valueBlock.value
  7709. }),
  7710. new asn1js__namespace.Constructed({
  7711. name: (names.subjectName || EMPTY_STRING),
  7712. idBlock: {
  7713. tagClass: 3,
  7714. tagNumber: 1
  7715. },
  7716. value: GeneralNames.schema().valueBlock.value
  7717. }),
  7718. ]
  7719. }),
  7720. GeneralNames.schema({
  7721. names: {
  7722. blockName: (names.issuer || EMPTY_STRING)
  7723. }
  7724. }),
  7725. AlgorithmIdentifier.schema(names.signature || {}),
  7726. new asn1js__namespace.Integer({ name: (names.serialNumber || EMPTY_STRING) }),
  7727. AttCertValidityPeriod.schema(names.attrCertValidityPeriod || {}),
  7728. new asn1js__namespace.Sequence({
  7729. name: (names.attributes || EMPTY_STRING),
  7730. value: [
  7731. new asn1js__namespace.Repeated({
  7732. value: Attribute.schema()
  7733. })
  7734. ]
  7735. }),
  7736. new asn1js__namespace.BitString({
  7737. optional: true,
  7738. name: (names.issuerUniqueID || EMPTY_STRING)
  7739. }),
  7740. Extensions.schema(names.extensions || {}, true)
  7741. ]
  7742. }));
  7743. }
  7744. fromSchema(schema) {
  7745. pvutils__namespace.clearProps(schema, CLEAR_PROPS$Z);
  7746. const asn1 = asn1js__namespace.compareSchema(schema, schema, AttributeCertificateInfoV1.schema({
  7747. names: {
  7748. version: VERSION$h,
  7749. baseCertificateID: BASE_CERTIFICATE_ID$2,
  7750. subjectName: SUBJECT_NAME,
  7751. issuer: ISSUER$4,
  7752. signature: {
  7753. names: {
  7754. blockName: SIGNATURE$6
  7755. }
  7756. },
  7757. serialNumber: SERIAL_NUMBER$5,
  7758. attrCertValidityPeriod: {
  7759. names: {
  7760. blockName: ATTR_CERT_VALIDITY_PERIOD$1
  7761. }
  7762. },
  7763. attributes: ATTRIBUTES$3,
  7764. issuerUniqueID: ISSUER_UNIQUE_ID$2,
  7765. extensions: {
  7766. names: {
  7767. blockName: EXTENSIONS$4
  7768. }
  7769. }
  7770. }
  7771. }));
  7772. AsnError.assertSchema(asn1, this.className);
  7773. this.version = asn1.result.version.valueBlock.valueDec;
  7774. if (BASE_CERTIFICATE_ID$2 in asn1.result) {
  7775. this.baseCertificateID = new IssuerSerial({
  7776. schema: new asn1js__namespace.Sequence({
  7777. value: asn1.result.baseCertificateID.valueBlock.value
  7778. })
  7779. });
  7780. }
  7781. if (SUBJECT_NAME in asn1.result) {
  7782. this.subjectName = new GeneralNames({
  7783. schema: new asn1js__namespace.Sequence({
  7784. value: asn1.result.subjectName.valueBlock.value
  7785. })
  7786. });
  7787. }
  7788. this.issuer = asn1.result.issuer;
  7789. this.signature = new AlgorithmIdentifier({ schema: asn1.result.signature });
  7790. this.serialNumber = asn1.result.serialNumber;
  7791. this.attrCertValidityPeriod = new AttCertValidityPeriod({ schema: asn1.result.attrCertValidityPeriod });
  7792. this.attributes = Array.from(asn1.result.attributes.valueBlock.value, element => new Attribute({ schema: element }));
  7793. if (ISSUER_UNIQUE_ID$2 in asn1.result) {
  7794. this.issuerUniqueID = asn1.result.issuerUniqueID;
  7795. }
  7796. if (EXTENSIONS$4 in asn1.result) {
  7797. this.extensions = new Extensions({ schema: asn1.result.extensions });
  7798. }
  7799. }
  7800. toSchema() {
  7801. const result = new asn1js__namespace.Sequence({
  7802. value: [new asn1js__namespace.Integer({ value: this.version })]
  7803. });
  7804. if (this.baseCertificateID) {
  7805. result.valueBlock.value.push(new asn1js__namespace.Constructed({
  7806. idBlock: {
  7807. tagClass: 3,
  7808. tagNumber: 0
  7809. },
  7810. value: this.baseCertificateID.toSchema().valueBlock.value
  7811. }));
  7812. }
  7813. if (this.subjectName) {
  7814. result.valueBlock.value.push(new asn1js__namespace.Constructed({
  7815. idBlock: {
  7816. tagClass: 3,
  7817. tagNumber: 1
  7818. },
  7819. value: this.subjectName.toSchema().valueBlock.value
  7820. }));
  7821. }
  7822. result.valueBlock.value.push(this.issuer.toSchema());
  7823. result.valueBlock.value.push(this.signature.toSchema());
  7824. result.valueBlock.value.push(this.serialNumber);
  7825. result.valueBlock.value.push(this.attrCertValidityPeriod.toSchema());
  7826. result.valueBlock.value.push(new asn1js__namespace.Sequence({
  7827. value: Array.from(this.attributes, o => o.toSchema())
  7828. }));
  7829. if (this.issuerUniqueID) {
  7830. result.valueBlock.value.push(this.issuerUniqueID);
  7831. }
  7832. if (this.extensions) {
  7833. result.valueBlock.value.push(this.extensions.toSchema());
  7834. }
  7835. return result;
  7836. }
  7837. toJSON() {
  7838. const result = {
  7839. version: this.version
  7840. };
  7841. if (this.baseCertificateID) {
  7842. result.baseCertificateID = this.baseCertificateID.toJSON();
  7843. }
  7844. if (this.subjectName) {
  7845. result.subjectName = this.subjectName.toJSON();
  7846. }
  7847. result.issuer = this.issuer.toJSON();
  7848. result.signature = this.signature.toJSON();
  7849. result.serialNumber = this.serialNumber.toJSON();
  7850. result.attrCertValidityPeriod = this.attrCertValidityPeriod.toJSON();
  7851. result.attributes = Array.from(this.attributes, o => o.toJSON());
  7852. if (this.issuerUniqueID) {
  7853. result.issuerUniqueID = this.issuerUniqueID.toJSON();
  7854. }
  7855. if (this.extensions) {
  7856. result.extensions = this.extensions.toJSON();
  7857. }
  7858. return result;
  7859. }
  7860. }
  7861. AttributeCertificateInfoV1.CLASS_NAME = "AttributeCertificateInfoV1";
  7862. const ACINFO$1 = "acinfo";
  7863. const SIGNATURE_ALGORITHM$7 = "signatureAlgorithm";
  7864. const SIGNATURE_VALUE$4 = "signatureValue";
  7865. const CLEAR_PROPS$Y = [
  7866. ACINFO$1,
  7867. SIGNATURE_VALUE$4,
  7868. SIGNATURE_ALGORITHM$7
  7869. ];
  7870. class AttributeCertificateV1 extends PkiObject {
  7871. constructor(parameters = {}) {
  7872. super();
  7873. this.acinfo = pvutils__namespace.getParametersValue(parameters, ACINFO$1, AttributeCertificateV1.defaultValues(ACINFO$1));
  7874. this.signatureAlgorithm = pvutils__namespace.getParametersValue(parameters, SIGNATURE_ALGORITHM$7, AttributeCertificateV1.defaultValues(SIGNATURE_ALGORITHM$7));
  7875. this.signatureValue = pvutils__namespace.getParametersValue(parameters, SIGNATURE_VALUE$4, AttributeCertificateV1.defaultValues(SIGNATURE_VALUE$4));
  7876. if (parameters.schema) {
  7877. this.fromSchema(parameters.schema);
  7878. }
  7879. }
  7880. static defaultValues(memberName) {
  7881. switch (memberName) {
  7882. case ACINFO$1:
  7883. return new AttributeCertificateInfoV1();
  7884. case SIGNATURE_ALGORITHM$7:
  7885. return new AlgorithmIdentifier();
  7886. case SIGNATURE_VALUE$4:
  7887. return new asn1js__namespace.BitString();
  7888. default:
  7889. return super.defaultValues(memberName);
  7890. }
  7891. }
  7892. static schema(parameters = {}) {
  7893. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  7894. return (new asn1js__namespace.Sequence({
  7895. name: (names.blockName || EMPTY_STRING),
  7896. value: [
  7897. AttributeCertificateInfoV1.schema(names.acinfo || {}),
  7898. AlgorithmIdentifier.schema(names.signatureAlgorithm || {}),
  7899. new asn1js__namespace.BitString({ name: (names.signatureValue || EMPTY_STRING) })
  7900. ]
  7901. }));
  7902. }
  7903. fromSchema(schema) {
  7904. pvutils__namespace.clearProps(schema, CLEAR_PROPS$Y);
  7905. const asn1 = asn1js__namespace.compareSchema(schema, schema, AttributeCertificateV1.schema({
  7906. names: {
  7907. acinfo: {
  7908. names: {
  7909. blockName: ACINFO$1
  7910. }
  7911. },
  7912. signatureAlgorithm: {
  7913. names: {
  7914. blockName: SIGNATURE_ALGORITHM$7
  7915. }
  7916. },
  7917. signatureValue: SIGNATURE_VALUE$4
  7918. }
  7919. }));
  7920. AsnError.assertSchema(asn1, this.className);
  7921. this.acinfo = new AttributeCertificateInfoV1({ schema: asn1.result.acinfo });
  7922. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  7923. this.signatureValue = asn1.result.signatureValue;
  7924. }
  7925. toSchema() {
  7926. return (new asn1js__namespace.Sequence({
  7927. value: [
  7928. this.acinfo.toSchema(),
  7929. this.signatureAlgorithm.toSchema(),
  7930. this.signatureValue
  7931. ]
  7932. }));
  7933. }
  7934. toJSON() {
  7935. return {
  7936. acinfo: this.acinfo.toJSON(),
  7937. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  7938. signatureValue: this.signatureValue.toJSON(),
  7939. };
  7940. }
  7941. }
  7942. AttributeCertificateV1.CLASS_NAME = "AttributeCertificateV1";
  7943. const DIGESTED_OBJECT_TYPE = "digestedObjectType";
  7944. const OTHER_OBJECT_TYPE_ID = "otherObjectTypeID";
  7945. const DIGEST_ALGORITHM$2 = "digestAlgorithm";
  7946. const OBJECT_DIGEST = "objectDigest";
  7947. const CLEAR_PROPS$X = [
  7948. DIGESTED_OBJECT_TYPE,
  7949. OTHER_OBJECT_TYPE_ID,
  7950. DIGEST_ALGORITHM$2,
  7951. OBJECT_DIGEST,
  7952. ];
  7953. class ObjectDigestInfo extends PkiObject {
  7954. constructor(parameters = {}) {
  7955. super();
  7956. this.digestedObjectType = pvutils__namespace.getParametersValue(parameters, DIGESTED_OBJECT_TYPE, ObjectDigestInfo.defaultValues(DIGESTED_OBJECT_TYPE));
  7957. if (OTHER_OBJECT_TYPE_ID in parameters) {
  7958. this.otherObjectTypeID = pvutils__namespace.getParametersValue(parameters, OTHER_OBJECT_TYPE_ID, ObjectDigestInfo.defaultValues(OTHER_OBJECT_TYPE_ID));
  7959. }
  7960. this.digestAlgorithm = pvutils__namespace.getParametersValue(parameters, DIGEST_ALGORITHM$2, ObjectDigestInfo.defaultValues(DIGEST_ALGORITHM$2));
  7961. this.objectDigest = pvutils__namespace.getParametersValue(parameters, OBJECT_DIGEST, ObjectDigestInfo.defaultValues(OBJECT_DIGEST));
  7962. if (parameters.schema) {
  7963. this.fromSchema(parameters.schema);
  7964. }
  7965. }
  7966. static defaultValues(memberName) {
  7967. switch (memberName) {
  7968. case DIGESTED_OBJECT_TYPE:
  7969. return new asn1js__namespace.Enumerated();
  7970. case OTHER_OBJECT_TYPE_ID:
  7971. return new asn1js__namespace.ObjectIdentifier();
  7972. case DIGEST_ALGORITHM$2:
  7973. return new AlgorithmIdentifier();
  7974. case OBJECT_DIGEST:
  7975. return new asn1js__namespace.BitString();
  7976. default:
  7977. return super.defaultValues(memberName);
  7978. }
  7979. }
  7980. static schema(parameters = {}) {
  7981. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  7982. return (new asn1js__namespace.Sequence({
  7983. name: (names.blockName || EMPTY_STRING),
  7984. value: [
  7985. new asn1js__namespace.Enumerated({ name: (names.digestedObjectType || EMPTY_STRING) }),
  7986. new asn1js__namespace.ObjectIdentifier({
  7987. optional: true,
  7988. name: (names.otherObjectTypeID || EMPTY_STRING)
  7989. }),
  7990. AlgorithmIdentifier.schema(names.digestAlgorithm || {}),
  7991. new asn1js__namespace.BitString({ name: (names.objectDigest || EMPTY_STRING) }),
  7992. ]
  7993. }));
  7994. }
  7995. fromSchema(schema) {
  7996. pvutils__namespace.clearProps(schema, CLEAR_PROPS$X);
  7997. const asn1 = asn1js__namespace.compareSchema(schema, schema, ObjectDigestInfo.schema({
  7998. names: {
  7999. digestedObjectType: DIGESTED_OBJECT_TYPE,
  8000. otherObjectTypeID: OTHER_OBJECT_TYPE_ID,
  8001. digestAlgorithm: {
  8002. names: {
  8003. blockName: DIGEST_ALGORITHM$2
  8004. }
  8005. },
  8006. objectDigest: OBJECT_DIGEST
  8007. }
  8008. }));
  8009. AsnError.assertSchema(asn1, this.className);
  8010. this.digestedObjectType = asn1.result.digestedObjectType;
  8011. if (OTHER_OBJECT_TYPE_ID in asn1.result) {
  8012. this.otherObjectTypeID = asn1.result.otherObjectTypeID;
  8013. }
  8014. this.digestAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.digestAlgorithm });
  8015. this.objectDigest = asn1.result.objectDigest;
  8016. }
  8017. toSchema() {
  8018. const result = new asn1js__namespace.Sequence({
  8019. value: [this.digestedObjectType]
  8020. });
  8021. if (this.otherObjectTypeID) {
  8022. result.valueBlock.value.push(this.otherObjectTypeID);
  8023. }
  8024. result.valueBlock.value.push(this.digestAlgorithm.toSchema());
  8025. result.valueBlock.value.push(this.objectDigest);
  8026. return result;
  8027. }
  8028. toJSON() {
  8029. const result = {
  8030. digestedObjectType: this.digestedObjectType.toJSON(),
  8031. digestAlgorithm: this.digestAlgorithm.toJSON(),
  8032. objectDigest: this.objectDigest.toJSON(),
  8033. };
  8034. if (this.otherObjectTypeID) {
  8035. result.otherObjectTypeID = this.otherObjectTypeID.toJSON();
  8036. }
  8037. return result;
  8038. }
  8039. }
  8040. ObjectDigestInfo.CLASS_NAME = "ObjectDigestInfo";
  8041. const ISSUER_NAME = "issuerName";
  8042. const BASE_CERTIFICATE_ID$1 = "baseCertificateID";
  8043. const OBJECT_DIGEST_INFO$1 = "objectDigestInfo";
  8044. const CLEAR_PROPS$W = [
  8045. ISSUER_NAME,
  8046. BASE_CERTIFICATE_ID$1,
  8047. OBJECT_DIGEST_INFO$1
  8048. ];
  8049. class V2Form extends PkiObject {
  8050. constructor(parameters = {}) {
  8051. super();
  8052. if (ISSUER_NAME in parameters) {
  8053. this.issuerName = pvutils__namespace.getParametersValue(parameters, ISSUER_NAME, V2Form.defaultValues(ISSUER_NAME));
  8054. }
  8055. if (BASE_CERTIFICATE_ID$1 in parameters) {
  8056. this.baseCertificateID = pvutils__namespace.getParametersValue(parameters, BASE_CERTIFICATE_ID$1, V2Form.defaultValues(BASE_CERTIFICATE_ID$1));
  8057. }
  8058. if (OBJECT_DIGEST_INFO$1 in parameters) {
  8059. this.objectDigestInfo = pvutils__namespace.getParametersValue(parameters, OBJECT_DIGEST_INFO$1, V2Form.defaultValues(OBJECT_DIGEST_INFO$1));
  8060. }
  8061. if (parameters.schema) {
  8062. this.fromSchema(parameters.schema);
  8063. }
  8064. }
  8065. static defaultValues(memberName) {
  8066. switch (memberName) {
  8067. case ISSUER_NAME:
  8068. return new GeneralNames();
  8069. case BASE_CERTIFICATE_ID$1:
  8070. return new IssuerSerial();
  8071. case OBJECT_DIGEST_INFO$1:
  8072. return new ObjectDigestInfo();
  8073. default:
  8074. return super.defaultValues(memberName);
  8075. }
  8076. }
  8077. static schema(parameters = {}) {
  8078. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  8079. return (new asn1js__namespace.Sequence({
  8080. name: (names.blockName || EMPTY_STRING),
  8081. value: [
  8082. GeneralNames.schema({
  8083. names: {
  8084. blockName: names.issuerName
  8085. }
  8086. }, true),
  8087. new asn1js__namespace.Constructed({
  8088. optional: true,
  8089. name: (names.baseCertificateID || EMPTY_STRING),
  8090. idBlock: {
  8091. tagClass: 3,
  8092. tagNumber: 0
  8093. },
  8094. value: IssuerSerial.schema().valueBlock.value
  8095. }),
  8096. new asn1js__namespace.Constructed({
  8097. optional: true,
  8098. name: (names.objectDigestInfo || EMPTY_STRING),
  8099. idBlock: {
  8100. tagClass: 3,
  8101. tagNumber: 1
  8102. },
  8103. value: ObjectDigestInfo.schema().valueBlock.value
  8104. })
  8105. ]
  8106. }));
  8107. }
  8108. fromSchema(schema) {
  8109. pvutils__namespace.clearProps(schema, CLEAR_PROPS$W);
  8110. const asn1 = asn1js__namespace.compareSchema(schema, schema, V2Form.schema({
  8111. names: {
  8112. issuerName: ISSUER_NAME,
  8113. baseCertificateID: BASE_CERTIFICATE_ID$1,
  8114. objectDigestInfo: OBJECT_DIGEST_INFO$1
  8115. }
  8116. }));
  8117. AsnError.assertSchema(asn1, this.className);
  8118. if (ISSUER_NAME in asn1.result)
  8119. this.issuerName = new GeneralNames({ schema: asn1.result.issuerName });
  8120. if (BASE_CERTIFICATE_ID$1 in asn1.result) {
  8121. this.baseCertificateID = new IssuerSerial({
  8122. schema: new asn1js__namespace.Sequence({
  8123. value: asn1.result.baseCertificateID.valueBlock.value
  8124. })
  8125. });
  8126. }
  8127. if (OBJECT_DIGEST_INFO$1 in asn1.result) {
  8128. this.objectDigestInfo = new ObjectDigestInfo({
  8129. schema: new asn1js__namespace.Sequence({
  8130. value: asn1.result.objectDigestInfo.valueBlock.value
  8131. })
  8132. });
  8133. }
  8134. }
  8135. toSchema() {
  8136. const result = new asn1js__namespace.Sequence();
  8137. if (this.issuerName)
  8138. result.valueBlock.value.push(this.issuerName.toSchema());
  8139. if (this.baseCertificateID) {
  8140. result.valueBlock.value.push(new asn1js__namespace.Constructed({
  8141. idBlock: {
  8142. tagClass: 3,
  8143. tagNumber: 0
  8144. },
  8145. value: this.baseCertificateID.toSchema().valueBlock.value
  8146. }));
  8147. }
  8148. if (this.objectDigestInfo) {
  8149. result.valueBlock.value.push(new asn1js__namespace.Constructed({
  8150. idBlock: {
  8151. tagClass: 3,
  8152. tagNumber: 1
  8153. },
  8154. value: this.objectDigestInfo.toSchema().valueBlock.value
  8155. }));
  8156. }
  8157. return result;
  8158. }
  8159. toJSON() {
  8160. const result = {};
  8161. if (this.issuerName) {
  8162. result.issuerName = this.issuerName.toJSON();
  8163. }
  8164. if (this.baseCertificateID) {
  8165. result.baseCertificateID = this.baseCertificateID.toJSON();
  8166. }
  8167. if (this.objectDigestInfo) {
  8168. result.objectDigestInfo = this.objectDigestInfo.toJSON();
  8169. }
  8170. return result;
  8171. }
  8172. }
  8173. V2Form.CLASS_NAME = "V2Form";
  8174. const BASE_CERTIFICATE_ID = "baseCertificateID";
  8175. const ENTITY_NAME = "entityName";
  8176. const OBJECT_DIGEST_INFO = "objectDigestInfo";
  8177. const CLEAR_PROPS$V = [
  8178. BASE_CERTIFICATE_ID,
  8179. ENTITY_NAME,
  8180. OBJECT_DIGEST_INFO
  8181. ];
  8182. class Holder extends PkiObject {
  8183. constructor(parameters = {}) {
  8184. super();
  8185. if (BASE_CERTIFICATE_ID in parameters) {
  8186. this.baseCertificateID = pvutils__namespace.getParametersValue(parameters, BASE_CERTIFICATE_ID, Holder.defaultValues(BASE_CERTIFICATE_ID));
  8187. }
  8188. if (ENTITY_NAME in parameters) {
  8189. this.entityName = pvutils__namespace.getParametersValue(parameters, ENTITY_NAME, Holder.defaultValues(ENTITY_NAME));
  8190. }
  8191. if (OBJECT_DIGEST_INFO in parameters) {
  8192. this.objectDigestInfo = pvutils__namespace.getParametersValue(parameters, OBJECT_DIGEST_INFO, Holder.defaultValues(OBJECT_DIGEST_INFO));
  8193. }
  8194. if (parameters.schema) {
  8195. this.fromSchema(parameters.schema);
  8196. }
  8197. }
  8198. static defaultValues(memberName) {
  8199. switch (memberName) {
  8200. case BASE_CERTIFICATE_ID:
  8201. return new IssuerSerial();
  8202. case ENTITY_NAME:
  8203. return new GeneralNames();
  8204. case OBJECT_DIGEST_INFO:
  8205. return new ObjectDigestInfo();
  8206. default:
  8207. return super.defaultValues(memberName);
  8208. }
  8209. }
  8210. static schema(parameters = {}) {
  8211. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  8212. return (new asn1js__namespace.Sequence({
  8213. name: (names.blockName || EMPTY_STRING),
  8214. value: [
  8215. new asn1js__namespace.Constructed({
  8216. optional: true,
  8217. name: (names.baseCertificateID || EMPTY_STRING),
  8218. idBlock: {
  8219. tagClass: 3,
  8220. tagNumber: 0
  8221. },
  8222. value: IssuerSerial.schema().valueBlock.value
  8223. }),
  8224. new asn1js__namespace.Constructed({
  8225. optional: true,
  8226. name: (names.entityName || EMPTY_STRING),
  8227. idBlock: {
  8228. tagClass: 3,
  8229. tagNumber: 1
  8230. },
  8231. value: GeneralNames.schema().valueBlock.value
  8232. }),
  8233. new asn1js__namespace.Constructed({
  8234. optional: true,
  8235. name: (names.objectDigestInfo || EMPTY_STRING),
  8236. idBlock: {
  8237. tagClass: 3,
  8238. tagNumber: 2
  8239. },
  8240. value: ObjectDigestInfo.schema().valueBlock.value
  8241. })
  8242. ]
  8243. }));
  8244. }
  8245. fromSchema(schema) {
  8246. pvutils__namespace.clearProps(schema, CLEAR_PROPS$V);
  8247. const asn1 = asn1js__namespace.compareSchema(schema, schema, Holder.schema({
  8248. names: {
  8249. baseCertificateID: BASE_CERTIFICATE_ID,
  8250. entityName: ENTITY_NAME,
  8251. objectDigestInfo: OBJECT_DIGEST_INFO
  8252. }
  8253. }));
  8254. AsnError.assertSchema(asn1, this.className);
  8255. if (BASE_CERTIFICATE_ID in asn1.result) {
  8256. this.baseCertificateID = new IssuerSerial({
  8257. schema: new asn1js__namespace.Sequence({
  8258. value: asn1.result.baseCertificateID.valueBlock.value
  8259. })
  8260. });
  8261. }
  8262. if (ENTITY_NAME in asn1.result) {
  8263. this.entityName = new GeneralNames({
  8264. schema: new asn1js__namespace.Sequence({
  8265. value: asn1.result.entityName.valueBlock.value
  8266. })
  8267. });
  8268. }
  8269. if (OBJECT_DIGEST_INFO in asn1.result) {
  8270. this.objectDigestInfo = new ObjectDigestInfo({
  8271. schema: new asn1js__namespace.Sequence({
  8272. value: asn1.result.objectDigestInfo.valueBlock.value
  8273. })
  8274. });
  8275. }
  8276. }
  8277. toSchema() {
  8278. const result = new asn1js__namespace.Sequence();
  8279. if (this.baseCertificateID) {
  8280. result.valueBlock.value.push(new asn1js__namespace.Constructed({
  8281. idBlock: {
  8282. tagClass: 3,
  8283. tagNumber: 0
  8284. },
  8285. value: this.baseCertificateID.toSchema().valueBlock.value
  8286. }));
  8287. }
  8288. if (this.entityName) {
  8289. result.valueBlock.value.push(new asn1js__namespace.Constructed({
  8290. idBlock: {
  8291. tagClass: 3,
  8292. tagNumber: 1
  8293. },
  8294. value: this.entityName.toSchema().valueBlock.value
  8295. }));
  8296. }
  8297. if (this.objectDigestInfo) {
  8298. result.valueBlock.value.push(new asn1js__namespace.Constructed({
  8299. idBlock: {
  8300. tagClass: 3,
  8301. tagNumber: 2
  8302. },
  8303. value: this.objectDigestInfo.toSchema().valueBlock.value
  8304. }));
  8305. }
  8306. return result;
  8307. }
  8308. toJSON() {
  8309. const result = {};
  8310. if (this.baseCertificateID) {
  8311. result.baseCertificateID = this.baseCertificateID.toJSON();
  8312. }
  8313. if (this.entityName) {
  8314. result.entityName = this.entityName.toJSON();
  8315. }
  8316. if (this.objectDigestInfo) {
  8317. result.objectDigestInfo = this.objectDigestInfo.toJSON();
  8318. }
  8319. return result;
  8320. }
  8321. }
  8322. Holder.CLASS_NAME = "Holder";
  8323. const VERSION$g = "version";
  8324. const HOLDER = "holder";
  8325. const ISSUER$3 = "issuer";
  8326. const SIGNATURE$5 = "signature";
  8327. const SERIAL_NUMBER$4 = "serialNumber";
  8328. const ATTR_CERT_VALIDITY_PERIOD = "attrCertValidityPeriod";
  8329. const ATTRIBUTES$2 = "attributes";
  8330. const ISSUER_UNIQUE_ID$1 = "issuerUniqueID";
  8331. const EXTENSIONS$3 = "extensions";
  8332. const CLEAR_PROPS$U = [
  8333. VERSION$g,
  8334. HOLDER,
  8335. ISSUER$3,
  8336. SIGNATURE$5,
  8337. SERIAL_NUMBER$4,
  8338. ATTR_CERT_VALIDITY_PERIOD,
  8339. ATTRIBUTES$2,
  8340. ISSUER_UNIQUE_ID$1,
  8341. EXTENSIONS$3
  8342. ];
  8343. class AttributeCertificateInfoV2 extends PkiObject {
  8344. constructor(parameters = {}) {
  8345. super();
  8346. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$g, AttributeCertificateInfoV2.defaultValues(VERSION$g));
  8347. this.holder = pvutils__namespace.getParametersValue(parameters, HOLDER, AttributeCertificateInfoV2.defaultValues(HOLDER));
  8348. this.issuer = pvutils__namespace.getParametersValue(parameters, ISSUER$3, AttributeCertificateInfoV2.defaultValues(ISSUER$3));
  8349. this.signature = pvutils__namespace.getParametersValue(parameters, SIGNATURE$5, AttributeCertificateInfoV2.defaultValues(SIGNATURE$5));
  8350. this.serialNumber = pvutils__namespace.getParametersValue(parameters, SERIAL_NUMBER$4, AttributeCertificateInfoV2.defaultValues(SERIAL_NUMBER$4));
  8351. this.attrCertValidityPeriod = pvutils__namespace.getParametersValue(parameters, ATTR_CERT_VALIDITY_PERIOD, AttributeCertificateInfoV2.defaultValues(ATTR_CERT_VALIDITY_PERIOD));
  8352. this.attributes = pvutils__namespace.getParametersValue(parameters, ATTRIBUTES$2, AttributeCertificateInfoV2.defaultValues(ATTRIBUTES$2));
  8353. if (ISSUER_UNIQUE_ID$1 in parameters) {
  8354. this.issuerUniqueID = pvutils__namespace.getParametersValue(parameters, ISSUER_UNIQUE_ID$1, AttributeCertificateInfoV2.defaultValues(ISSUER_UNIQUE_ID$1));
  8355. }
  8356. if (EXTENSIONS$3 in parameters) {
  8357. this.extensions = pvutils__namespace.getParametersValue(parameters, EXTENSIONS$3, AttributeCertificateInfoV2.defaultValues(EXTENSIONS$3));
  8358. }
  8359. if (parameters.schema) {
  8360. this.fromSchema(parameters.schema);
  8361. }
  8362. }
  8363. static defaultValues(memberName) {
  8364. switch (memberName) {
  8365. case VERSION$g:
  8366. return 1;
  8367. case HOLDER:
  8368. return new Holder();
  8369. case ISSUER$3:
  8370. return {};
  8371. case SIGNATURE$5:
  8372. return new AlgorithmIdentifier();
  8373. case SERIAL_NUMBER$4:
  8374. return new asn1js__namespace.Integer();
  8375. case ATTR_CERT_VALIDITY_PERIOD:
  8376. return new AttCertValidityPeriod();
  8377. case ATTRIBUTES$2:
  8378. return [];
  8379. case ISSUER_UNIQUE_ID$1:
  8380. return new asn1js__namespace.BitString();
  8381. case EXTENSIONS$3:
  8382. return new Extensions();
  8383. default:
  8384. return super.defaultValues(memberName);
  8385. }
  8386. }
  8387. static schema(parameters = {}) {
  8388. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  8389. return (new asn1js__namespace.Sequence({
  8390. name: (names.blockName || EMPTY_STRING),
  8391. value: [
  8392. new asn1js__namespace.Integer({ name: (names.version || EMPTY_STRING) }),
  8393. Holder.schema(names.holder || {}),
  8394. new asn1js__namespace.Choice({
  8395. value: [
  8396. GeneralNames.schema({
  8397. names: {
  8398. blockName: (names.issuer || EMPTY_STRING)
  8399. }
  8400. }),
  8401. new asn1js__namespace.Constructed({
  8402. name: (names.issuer || EMPTY_STRING),
  8403. idBlock: {
  8404. tagClass: 3,
  8405. tagNumber: 0
  8406. },
  8407. value: V2Form.schema().valueBlock.value
  8408. })
  8409. ]
  8410. }),
  8411. AlgorithmIdentifier.schema(names.signature || {}),
  8412. new asn1js__namespace.Integer({ name: (names.serialNumber || EMPTY_STRING) }),
  8413. AttCertValidityPeriod.schema(names.attrCertValidityPeriod || {}),
  8414. new asn1js__namespace.Sequence({
  8415. name: (names.attributes || EMPTY_STRING),
  8416. value: [
  8417. new asn1js__namespace.Repeated({
  8418. value: Attribute.schema()
  8419. })
  8420. ]
  8421. }),
  8422. new asn1js__namespace.BitString({
  8423. optional: true,
  8424. name: (names.issuerUniqueID || EMPTY_STRING)
  8425. }),
  8426. Extensions.schema(names.extensions || {}, true)
  8427. ]
  8428. }));
  8429. }
  8430. fromSchema(schema) {
  8431. pvutils__namespace.clearProps(schema, CLEAR_PROPS$U);
  8432. const asn1 = asn1js__namespace.compareSchema(schema, schema, AttributeCertificateInfoV2.schema({
  8433. names: {
  8434. version: VERSION$g,
  8435. holder: {
  8436. names: {
  8437. blockName: HOLDER
  8438. }
  8439. },
  8440. issuer: ISSUER$3,
  8441. signature: {
  8442. names: {
  8443. blockName: SIGNATURE$5
  8444. }
  8445. },
  8446. serialNumber: SERIAL_NUMBER$4,
  8447. attrCertValidityPeriod: {
  8448. names: {
  8449. blockName: ATTR_CERT_VALIDITY_PERIOD
  8450. }
  8451. },
  8452. attributes: ATTRIBUTES$2,
  8453. issuerUniqueID: ISSUER_UNIQUE_ID$1,
  8454. extensions: {
  8455. names: {
  8456. blockName: EXTENSIONS$3
  8457. }
  8458. }
  8459. }
  8460. }));
  8461. AsnError.assertSchema(asn1, this.className);
  8462. this.version = asn1.result.version.valueBlock.valueDec;
  8463. this.holder = new Holder({ schema: asn1.result.holder });
  8464. switch (asn1.result.issuer.idBlock.tagClass) {
  8465. case 3:
  8466. this.issuer = new V2Form({
  8467. schema: new asn1js__namespace.Sequence({
  8468. value: asn1.result.issuer.valueBlock.value
  8469. })
  8470. });
  8471. break;
  8472. case 1:
  8473. default:
  8474. throw new Error("Incorrect value for 'issuer' in AttributeCertificateInfoV2");
  8475. }
  8476. this.signature = new AlgorithmIdentifier({ schema: asn1.result.signature });
  8477. this.serialNumber = asn1.result.serialNumber;
  8478. this.attrCertValidityPeriod = new AttCertValidityPeriod({ schema: asn1.result.attrCertValidityPeriod });
  8479. this.attributes = Array.from(asn1.result.attributes.valueBlock.value, element => new Attribute({ schema: element }));
  8480. if (ISSUER_UNIQUE_ID$1 in asn1.result) {
  8481. this.issuerUniqueID = asn1.result.issuerUniqueID;
  8482. }
  8483. if (EXTENSIONS$3 in asn1.result) {
  8484. this.extensions = new Extensions({ schema: asn1.result.extensions });
  8485. }
  8486. }
  8487. toSchema() {
  8488. const result = new asn1js__namespace.Sequence({
  8489. value: [
  8490. new asn1js__namespace.Integer({ value: this.version }),
  8491. this.holder.toSchema(),
  8492. new asn1js__namespace.Constructed({
  8493. idBlock: {
  8494. tagClass: 3,
  8495. tagNumber: 0
  8496. },
  8497. value: this.issuer.toSchema().valueBlock.value
  8498. }),
  8499. this.signature.toSchema(),
  8500. this.serialNumber,
  8501. this.attrCertValidityPeriod.toSchema(),
  8502. new asn1js__namespace.Sequence({
  8503. value: Array.from(this.attributes, o => o.toSchema())
  8504. })
  8505. ]
  8506. });
  8507. if (this.issuerUniqueID) {
  8508. result.valueBlock.value.push(this.issuerUniqueID);
  8509. }
  8510. if (this.extensions) {
  8511. result.valueBlock.value.push(this.extensions.toSchema());
  8512. }
  8513. return result;
  8514. }
  8515. toJSON() {
  8516. const result = {
  8517. version: this.version,
  8518. holder: this.holder.toJSON(),
  8519. issuer: this.issuer.toJSON(),
  8520. signature: this.signature.toJSON(),
  8521. serialNumber: this.serialNumber.toJSON(),
  8522. attrCertValidityPeriod: this.attrCertValidityPeriod.toJSON(),
  8523. attributes: Array.from(this.attributes, o => o.toJSON())
  8524. };
  8525. if (this.issuerUniqueID) {
  8526. result.issuerUniqueID = this.issuerUniqueID.toJSON();
  8527. }
  8528. if (this.extensions) {
  8529. result.extensions = this.extensions.toJSON();
  8530. }
  8531. return result;
  8532. }
  8533. }
  8534. AttributeCertificateInfoV2.CLASS_NAME = "AttributeCertificateInfoV2";
  8535. const ACINFO = "acinfo";
  8536. const SIGNATURE_ALGORITHM$6 = "signatureAlgorithm";
  8537. const SIGNATURE_VALUE$3 = "signatureValue";
  8538. const CLEAR_PROPS$T = [
  8539. ACINFO,
  8540. SIGNATURE_ALGORITHM$6,
  8541. SIGNATURE_VALUE$3,
  8542. ];
  8543. class AttributeCertificateV2 extends PkiObject {
  8544. constructor(parameters = {}) {
  8545. super();
  8546. this.acinfo = pvutils__namespace.getParametersValue(parameters, ACINFO, AttributeCertificateV2.defaultValues(ACINFO));
  8547. this.signatureAlgorithm = pvutils__namespace.getParametersValue(parameters, SIGNATURE_ALGORITHM$6, AttributeCertificateV2.defaultValues(SIGNATURE_ALGORITHM$6));
  8548. this.signatureValue = pvutils__namespace.getParametersValue(parameters, SIGNATURE_VALUE$3, AttributeCertificateV2.defaultValues(SIGNATURE_VALUE$3));
  8549. if (parameters.schema) {
  8550. this.fromSchema(parameters.schema);
  8551. }
  8552. }
  8553. static defaultValues(memberName) {
  8554. switch (memberName) {
  8555. case ACINFO:
  8556. return new AttributeCertificateInfoV2();
  8557. case SIGNATURE_ALGORITHM$6:
  8558. return new AlgorithmIdentifier();
  8559. case SIGNATURE_VALUE$3:
  8560. return new asn1js__namespace.BitString();
  8561. default:
  8562. return super.defaultValues(memberName);
  8563. }
  8564. }
  8565. static schema(parameters = {}) {
  8566. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  8567. return (new asn1js__namespace.Sequence({
  8568. name: (names.blockName || EMPTY_STRING),
  8569. value: [
  8570. AttributeCertificateInfoV2.schema(names.acinfo || {}),
  8571. AlgorithmIdentifier.schema(names.signatureAlgorithm || {}),
  8572. new asn1js__namespace.BitString({ name: (names.signatureValue || EMPTY_STRING) })
  8573. ]
  8574. }));
  8575. }
  8576. fromSchema(schema) {
  8577. pvutils__namespace.clearProps(schema, CLEAR_PROPS$T);
  8578. const asn1 = asn1js__namespace.compareSchema(schema, schema, AttributeCertificateV2.schema({
  8579. names: {
  8580. acinfo: {
  8581. names: {
  8582. blockName: ACINFO
  8583. }
  8584. },
  8585. signatureAlgorithm: {
  8586. names: {
  8587. blockName: SIGNATURE_ALGORITHM$6
  8588. }
  8589. },
  8590. signatureValue: SIGNATURE_VALUE$3
  8591. }
  8592. }));
  8593. AsnError.assertSchema(asn1, this.className);
  8594. this.acinfo = new AttributeCertificateInfoV2({ schema: asn1.result.acinfo });
  8595. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  8596. this.signatureValue = asn1.result.signatureValue;
  8597. }
  8598. toSchema() {
  8599. return (new asn1js__namespace.Sequence({
  8600. value: [
  8601. this.acinfo.toSchema(),
  8602. this.signatureAlgorithm.toSchema(),
  8603. this.signatureValue
  8604. ]
  8605. }));
  8606. }
  8607. toJSON() {
  8608. return {
  8609. acinfo: this.acinfo.toJSON(),
  8610. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  8611. signatureValue: this.signatureValue.toJSON(),
  8612. };
  8613. }
  8614. }
  8615. AttributeCertificateV2.CLASS_NAME = "AttributeCertificateV2";
  8616. const CONTENT_TYPE = "contentType";
  8617. const CONTENT = "content";
  8618. const CLEAR_PROPS$S = [CONTENT_TYPE, CONTENT];
  8619. class ContentInfo extends PkiObject {
  8620. constructor(parameters = {}) {
  8621. super();
  8622. this.contentType = pvutils__namespace.getParametersValue(parameters, CONTENT_TYPE, ContentInfo.defaultValues(CONTENT_TYPE));
  8623. this.content = pvutils__namespace.getParametersValue(parameters, CONTENT, ContentInfo.defaultValues(CONTENT));
  8624. if (parameters.schema) {
  8625. this.fromSchema(parameters.schema);
  8626. }
  8627. }
  8628. static defaultValues(memberName) {
  8629. switch (memberName) {
  8630. case CONTENT_TYPE:
  8631. return EMPTY_STRING;
  8632. case CONTENT:
  8633. return new asn1js__namespace.Any();
  8634. default:
  8635. return super.defaultValues(memberName);
  8636. }
  8637. }
  8638. static compareWithDefault(memberName, memberValue) {
  8639. switch (memberName) {
  8640. case CONTENT_TYPE:
  8641. return (typeof memberValue === "string" &&
  8642. memberValue === this.defaultValues(CONTENT_TYPE));
  8643. case CONTENT:
  8644. return (memberValue instanceof asn1js__namespace.Any);
  8645. default:
  8646. return super.defaultValues(memberName);
  8647. }
  8648. }
  8649. static schema(parameters = {}) {
  8650. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  8651. if (("optional" in names) === false) {
  8652. names.optional = false;
  8653. }
  8654. return (new asn1js__namespace.Sequence({
  8655. name: (names.blockName || "ContentInfo"),
  8656. optional: names.optional,
  8657. value: [
  8658. new asn1js__namespace.ObjectIdentifier({ name: (names.contentType || CONTENT_TYPE) }),
  8659. new asn1js__namespace.Constructed({
  8660. idBlock: {
  8661. tagClass: 3,
  8662. tagNumber: 0
  8663. },
  8664. value: [new asn1js__namespace.Any({ name: (names.content || CONTENT) })]
  8665. })
  8666. ]
  8667. }));
  8668. }
  8669. fromSchema(schema) {
  8670. pvutils__namespace.clearProps(schema, CLEAR_PROPS$S);
  8671. const asn1 = asn1js__namespace.compareSchema(schema, schema, ContentInfo.schema());
  8672. AsnError.assertSchema(asn1, this.className);
  8673. this.contentType = asn1.result.contentType.valueBlock.toString();
  8674. this.content = asn1.result.content;
  8675. }
  8676. toSchema() {
  8677. return (new asn1js__namespace.Sequence({
  8678. value: [
  8679. new asn1js__namespace.ObjectIdentifier({ value: this.contentType }),
  8680. new asn1js__namespace.Constructed({
  8681. idBlock: {
  8682. tagClass: 3,
  8683. tagNumber: 0
  8684. },
  8685. value: [this.content]
  8686. })
  8687. ]
  8688. }));
  8689. }
  8690. toJSON() {
  8691. const object = {
  8692. contentType: this.contentType
  8693. };
  8694. if (!(this.content instanceof asn1js__namespace.Any)) {
  8695. object.content = this.content.toJSON();
  8696. }
  8697. return object;
  8698. }
  8699. }
  8700. ContentInfo.CLASS_NAME = "ContentInfo";
  8701. ContentInfo.DATA = id_ContentType_Data;
  8702. ContentInfo.SIGNED_DATA = id_ContentType_SignedData;
  8703. ContentInfo.ENVELOPED_DATA = id_ContentType_EnvelopedData;
  8704. ContentInfo.ENCRYPTED_DATA = id_ContentType_EncryptedData;
  8705. const TYPE$1 = "type";
  8706. const VALUE$4 = "value";
  8707. const UTC_TIME_NAME = "utcTimeName";
  8708. const GENERAL_TIME_NAME = "generalTimeName";
  8709. const CLEAR_PROPS$R = [UTC_TIME_NAME, GENERAL_TIME_NAME];
  8710. exports.TimeType = void 0;
  8711. (function (TimeType) {
  8712. TimeType[TimeType["UTCTime"] = 0] = "UTCTime";
  8713. TimeType[TimeType["GeneralizedTime"] = 1] = "GeneralizedTime";
  8714. TimeType[TimeType["empty"] = 2] = "empty";
  8715. })(exports.TimeType || (exports.TimeType = {}));
  8716. class Time extends PkiObject {
  8717. constructor(parameters = {}) {
  8718. super();
  8719. this.type = pvutils__namespace.getParametersValue(parameters, TYPE$1, Time.defaultValues(TYPE$1));
  8720. this.value = pvutils__namespace.getParametersValue(parameters, VALUE$4, Time.defaultValues(VALUE$4));
  8721. if (parameters.schema) {
  8722. this.fromSchema(parameters.schema);
  8723. }
  8724. }
  8725. static defaultValues(memberName) {
  8726. switch (memberName) {
  8727. case TYPE$1:
  8728. return 0;
  8729. case VALUE$4:
  8730. return new Date(0, 0, 0);
  8731. default:
  8732. return super.defaultValues(memberName);
  8733. }
  8734. }
  8735. static schema(parameters = {}, optional = false) {
  8736. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  8737. return (new asn1js__namespace.Choice({
  8738. optional,
  8739. value: [
  8740. new asn1js__namespace.UTCTime({ name: (names.utcTimeName || EMPTY_STRING) }),
  8741. new asn1js__namespace.GeneralizedTime({ name: (names.generalTimeName || EMPTY_STRING) })
  8742. ]
  8743. }));
  8744. }
  8745. fromSchema(schema) {
  8746. pvutils__namespace.clearProps(schema, CLEAR_PROPS$R);
  8747. const asn1 = asn1js__namespace.compareSchema(schema, schema, Time.schema({
  8748. names: {
  8749. utcTimeName: UTC_TIME_NAME,
  8750. generalTimeName: GENERAL_TIME_NAME
  8751. }
  8752. }));
  8753. AsnError.assertSchema(asn1, this.className);
  8754. if (UTC_TIME_NAME in asn1.result) {
  8755. this.type = 0;
  8756. this.value = asn1.result.utcTimeName.toDate();
  8757. }
  8758. if (GENERAL_TIME_NAME in asn1.result) {
  8759. this.type = 1;
  8760. this.value = asn1.result.generalTimeName.toDate();
  8761. }
  8762. }
  8763. toSchema() {
  8764. if (this.type === 0) {
  8765. return new asn1js__namespace.UTCTime({ valueDate: this.value });
  8766. }
  8767. else if (this.type === 1) {
  8768. return new asn1js__namespace.GeneralizedTime({ valueDate: this.value });
  8769. }
  8770. return {};
  8771. }
  8772. toJSON() {
  8773. return {
  8774. type: this.type,
  8775. value: this.value
  8776. };
  8777. }
  8778. }
  8779. Time.CLASS_NAME = "Time";
  8780. const TBS$4 = "tbs";
  8781. const VERSION$f = "version";
  8782. const SERIAL_NUMBER$3 = "serialNumber";
  8783. const SIGNATURE$4 = "signature";
  8784. const ISSUER$2 = "issuer";
  8785. const NOT_BEFORE = "notBefore";
  8786. const NOT_AFTER = "notAfter";
  8787. const SUBJECT$1 = "subject";
  8788. const SUBJECT_PUBLIC_KEY_INFO = "subjectPublicKeyInfo";
  8789. const ISSUER_UNIQUE_ID = "issuerUniqueID";
  8790. const SUBJECT_UNIQUE_ID = "subjectUniqueID";
  8791. const EXTENSIONS$2 = "extensions";
  8792. const SIGNATURE_ALGORITHM$5 = "signatureAlgorithm";
  8793. const SIGNATURE_VALUE$2 = "signatureValue";
  8794. const TBS_CERTIFICATE = "tbsCertificate";
  8795. const TBS_CERTIFICATE_VERSION = `${TBS_CERTIFICATE}.${VERSION$f}`;
  8796. const TBS_CERTIFICATE_SERIAL_NUMBER = `${TBS_CERTIFICATE}.${SERIAL_NUMBER$3}`;
  8797. const TBS_CERTIFICATE_SIGNATURE = `${TBS_CERTIFICATE}.${SIGNATURE$4}`;
  8798. const TBS_CERTIFICATE_ISSUER = `${TBS_CERTIFICATE}.${ISSUER$2}`;
  8799. const TBS_CERTIFICATE_NOT_BEFORE = `${TBS_CERTIFICATE}.${NOT_BEFORE}`;
  8800. const TBS_CERTIFICATE_NOT_AFTER = `${TBS_CERTIFICATE}.${NOT_AFTER}`;
  8801. const TBS_CERTIFICATE_SUBJECT = `${TBS_CERTIFICATE}.${SUBJECT$1}`;
  8802. const TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY = `${TBS_CERTIFICATE}.${SUBJECT_PUBLIC_KEY_INFO}`;
  8803. const TBS_CERTIFICATE_ISSUER_UNIQUE_ID = `${TBS_CERTIFICATE}.${ISSUER_UNIQUE_ID}`;
  8804. const TBS_CERTIFICATE_SUBJECT_UNIQUE_ID = `${TBS_CERTIFICATE}.${SUBJECT_UNIQUE_ID}`;
  8805. const TBS_CERTIFICATE_EXTENSIONS = `${TBS_CERTIFICATE}.${EXTENSIONS$2}`;
  8806. const CLEAR_PROPS$Q = [
  8807. TBS_CERTIFICATE,
  8808. TBS_CERTIFICATE_VERSION,
  8809. TBS_CERTIFICATE_SERIAL_NUMBER,
  8810. TBS_CERTIFICATE_SIGNATURE,
  8811. TBS_CERTIFICATE_ISSUER,
  8812. TBS_CERTIFICATE_NOT_BEFORE,
  8813. TBS_CERTIFICATE_NOT_AFTER,
  8814. TBS_CERTIFICATE_SUBJECT,
  8815. TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY,
  8816. TBS_CERTIFICATE_ISSUER_UNIQUE_ID,
  8817. TBS_CERTIFICATE_SUBJECT_UNIQUE_ID,
  8818. TBS_CERTIFICATE_EXTENSIONS,
  8819. SIGNATURE_ALGORITHM$5,
  8820. SIGNATURE_VALUE$2
  8821. ];
  8822. function tbsCertificate(parameters = {}) {
  8823. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  8824. return (new asn1js__namespace.Sequence({
  8825. name: (names.blockName || TBS_CERTIFICATE),
  8826. value: [
  8827. new asn1js__namespace.Constructed({
  8828. optional: true,
  8829. idBlock: {
  8830. tagClass: 3,
  8831. tagNumber: 0
  8832. },
  8833. value: [
  8834. new asn1js__namespace.Integer({ name: (names.tbsCertificateVersion || TBS_CERTIFICATE_VERSION) })
  8835. ]
  8836. }),
  8837. new asn1js__namespace.Integer({ name: (names.tbsCertificateSerialNumber || TBS_CERTIFICATE_SERIAL_NUMBER) }),
  8838. AlgorithmIdentifier.schema(names.signature || {
  8839. names: {
  8840. blockName: TBS_CERTIFICATE_SIGNATURE
  8841. }
  8842. }),
  8843. RelativeDistinguishedNames.schema(names.issuer || {
  8844. names: {
  8845. blockName: TBS_CERTIFICATE_ISSUER
  8846. }
  8847. }),
  8848. new asn1js__namespace.Sequence({
  8849. name: (names.tbsCertificateValidity || "tbsCertificate.validity"),
  8850. value: [
  8851. Time.schema(names.notBefore || {
  8852. names: {
  8853. utcTimeName: TBS_CERTIFICATE_NOT_BEFORE,
  8854. generalTimeName: TBS_CERTIFICATE_NOT_BEFORE
  8855. }
  8856. }),
  8857. Time.schema(names.notAfter || {
  8858. names: {
  8859. utcTimeName: TBS_CERTIFICATE_NOT_AFTER,
  8860. generalTimeName: TBS_CERTIFICATE_NOT_AFTER
  8861. }
  8862. })
  8863. ]
  8864. }),
  8865. RelativeDistinguishedNames.schema(names.subject || {
  8866. names: {
  8867. blockName: TBS_CERTIFICATE_SUBJECT
  8868. }
  8869. }),
  8870. PublicKeyInfo.schema(names.subjectPublicKeyInfo || {
  8871. names: {
  8872. blockName: TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY
  8873. }
  8874. }),
  8875. new asn1js__namespace.Primitive({
  8876. name: (names.tbsCertificateIssuerUniqueID || TBS_CERTIFICATE_ISSUER_UNIQUE_ID),
  8877. optional: true,
  8878. idBlock: {
  8879. tagClass: 3,
  8880. tagNumber: 1
  8881. }
  8882. }),
  8883. new asn1js__namespace.Primitive({
  8884. name: (names.tbsCertificateSubjectUniqueID || TBS_CERTIFICATE_SUBJECT_UNIQUE_ID),
  8885. optional: true,
  8886. idBlock: {
  8887. tagClass: 3,
  8888. tagNumber: 2
  8889. }
  8890. }),
  8891. new asn1js__namespace.Constructed({
  8892. optional: true,
  8893. idBlock: {
  8894. tagClass: 3,
  8895. tagNumber: 3
  8896. },
  8897. value: [Extensions.schema(names.extensions || {
  8898. names: {
  8899. blockName: TBS_CERTIFICATE_EXTENSIONS
  8900. }
  8901. })]
  8902. })
  8903. ]
  8904. }));
  8905. }
  8906. class Certificate extends PkiObject {
  8907. get tbs() {
  8908. return pvtsutils__namespace.BufferSourceConverter.toArrayBuffer(this.tbsView);
  8909. }
  8910. set tbs(value) {
  8911. this.tbsView = new Uint8Array(value);
  8912. }
  8913. constructor(parameters = {}) {
  8914. super();
  8915. this.tbsView = new Uint8Array(pvutils__namespace.getParametersValue(parameters, TBS$4, Certificate.defaultValues(TBS$4)));
  8916. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$f, Certificate.defaultValues(VERSION$f));
  8917. this.serialNumber = pvutils__namespace.getParametersValue(parameters, SERIAL_NUMBER$3, Certificate.defaultValues(SERIAL_NUMBER$3));
  8918. this.signature = pvutils__namespace.getParametersValue(parameters, SIGNATURE$4, Certificate.defaultValues(SIGNATURE$4));
  8919. this.issuer = pvutils__namespace.getParametersValue(parameters, ISSUER$2, Certificate.defaultValues(ISSUER$2));
  8920. this.notBefore = pvutils__namespace.getParametersValue(parameters, NOT_BEFORE, Certificate.defaultValues(NOT_BEFORE));
  8921. this.notAfter = pvutils__namespace.getParametersValue(parameters, NOT_AFTER, Certificate.defaultValues(NOT_AFTER));
  8922. this.subject = pvutils__namespace.getParametersValue(parameters, SUBJECT$1, Certificate.defaultValues(SUBJECT$1));
  8923. this.subjectPublicKeyInfo = pvutils__namespace.getParametersValue(parameters, SUBJECT_PUBLIC_KEY_INFO, Certificate.defaultValues(SUBJECT_PUBLIC_KEY_INFO));
  8924. if (ISSUER_UNIQUE_ID in parameters) {
  8925. this.issuerUniqueID = pvutils__namespace.getParametersValue(parameters, ISSUER_UNIQUE_ID, Certificate.defaultValues(ISSUER_UNIQUE_ID));
  8926. }
  8927. if (SUBJECT_UNIQUE_ID in parameters) {
  8928. this.subjectUniqueID = pvutils__namespace.getParametersValue(parameters, SUBJECT_UNIQUE_ID, Certificate.defaultValues(SUBJECT_UNIQUE_ID));
  8929. }
  8930. if (EXTENSIONS$2 in parameters) {
  8931. this.extensions = pvutils__namespace.getParametersValue(parameters, EXTENSIONS$2, Certificate.defaultValues(EXTENSIONS$2));
  8932. }
  8933. this.signatureAlgorithm = pvutils__namespace.getParametersValue(parameters, SIGNATURE_ALGORITHM$5, Certificate.defaultValues(SIGNATURE_ALGORITHM$5));
  8934. this.signatureValue = pvutils__namespace.getParametersValue(parameters, SIGNATURE_VALUE$2, Certificate.defaultValues(SIGNATURE_VALUE$2));
  8935. if (parameters.schema) {
  8936. this.fromSchema(parameters.schema);
  8937. }
  8938. }
  8939. static defaultValues(memberName) {
  8940. switch (memberName) {
  8941. case TBS$4:
  8942. return EMPTY_BUFFER;
  8943. case VERSION$f:
  8944. return 0;
  8945. case SERIAL_NUMBER$3:
  8946. return new asn1js__namespace.Integer();
  8947. case SIGNATURE$4:
  8948. return new AlgorithmIdentifier();
  8949. case ISSUER$2:
  8950. return new RelativeDistinguishedNames();
  8951. case NOT_BEFORE:
  8952. return new Time();
  8953. case NOT_AFTER:
  8954. return new Time();
  8955. case SUBJECT$1:
  8956. return new RelativeDistinguishedNames();
  8957. case SUBJECT_PUBLIC_KEY_INFO:
  8958. return new PublicKeyInfo();
  8959. case ISSUER_UNIQUE_ID:
  8960. return EMPTY_BUFFER;
  8961. case SUBJECT_UNIQUE_ID:
  8962. return EMPTY_BUFFER;
  8963. case EXTENSIONS$2:
  8964. return [];
  8965. case SIGNATURE_ALGORITHM$5:
  8966. return new AlgorithmIdentifier();
  8967. case SIGNATURE_VALUE$2:
  8968. return new asn1js__namespace.BitString();
  8969. default:
  8970. return super.defaultValues(memberName);
  8971. }
  8972. }
  8973. static schema(parameters = {}) {
  8974. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  8975. return (new asn1js__namespace.Sequence({
  8976. name: (names.blockName || EMPTY_STRING),
  8977. value: [
  8978. tbsCertificate(names.tbsCertificate),
  8979. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  8980. names: {
  8981. blockName: SIGNATURE_ALGORITHM$5
  8982. }
  8983. }),
  8984. new asn1js__namespace.BitString({ name: (names.signatureValue || SIGNATURE_VALUE$2) })
  8985. ]
  8986. }));
  8987. }
  8988. fromSchema(schema) {
  8989. pvutils__namespace.clearProps(schema, CLEAR_PROPS$Q);
  8990. const asn1 = asn1js__namespace.compareSchema(schema, schema, Certificate.schema({
  8991. names: {
  8992. tbsCertificate: {
  8993. names: {
  8994. extensions: {
  8995. names: {
  8996. extensions: TBS_CERTIFICATE_EXTENSIONS
  8997. }
  8998. }
  8999. }
  9000. }
  9001. }
  9002. }));
  9003. AsnError.assertSchema(asn1, this.className);
  9004. this.tbsView = asn1.result.tbsCertificate.valueBeforeDecodeView;
  9005. if (TBS_CERTIFICATE_VERSION in asn1.result)
  9006. this.version = asn1.result[TBS_CERTIFICATE_VERSION].valueBlock.valueDec;
  9007. this.serialNumber = asn1.result[TBS_CERTIFICATE_SERIAL_NUMBER];
  9008. this.signature = new AlgorithmIdentifier({ schema: asn1.result[TBS_CERTIFICATE_SIGNATURE] });
  9009. this.issuer = new RelativeDistinguishedNames({ schema: asn1.result[TBS_CERTIFICATE_ISSUER] });
  9010. this.notBefore = new Time({ schema: asn1.result[TBS_CERTIFICATE_NOT_BEFORE] });
  9011. this.notAfter = new Time({ schema: asn1.result[TBS_CERTIFICATE_NOT_AFTER] });
  9012. this.subject = new RelativeDistinguishedNames({ schema: asn1.result[TBS_CERTIFICATE_SUBJECT] });
  9013. this.subjectPublicKeyInfo = new PublicKeyInfo({ schema: asn1.result[TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY] });
  9014. if (TBS_CERTIFICATE_ISSUER_UNIQUE_ID in asn1.result)
  9015. this.issuerUniqueID = asn1.result[TBS_CERTIFICATE_ISSUER_UNIQUE_ID].valueBlock.valueHex;
  9016. if (TBS_CERTIFICATE_SUBJECT_UNIQUE_ID in asn1.result)
  9017. this.subjectUniqueID = asn1.result[TBS_CERTIFICATE_SUBJECT_UNIQUE_ID].valueBlock.valueHex;
  9018. if (TBS_CERTIFICATE_EXTENSIONS in asn1.result)
  9019. this.extensions = Array.from(asn1.result[TBS_CERTIFICATE_EXTENSIONS], element => new Extension({ schema: element }));
  9020. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  9021. this.signatureValue = asn1.result.signatureValue;
  9022. }
  9023. encodeTBS() {
  9024. const outputArray = [];
  9025. if ((VERSION$f in this) && (this.version !== Certificate.defaultValues(VERSION$f))) {
  9026. outputArray.push(new asn1js__namespace.Constructed({
  9027. optional: true,
  9028. idBlock: {
  9029. tagClass: 3,
  9030. tagNumber: 0
  9031. },
  9032. value: [
  9033. new asn1js__namespace.Integer({ value: this.version })
  9034. ]
  9035. }));
  9036. }
  9037. outputArray.push(this.serialNumber);
  9038. outputArray.push(this.signature.toSchema());
  9039. outputArray.push(this.issuer.toSchema());
  9040. outputArray.push(new asn1js__namespace.Sequence({
  9041. value: [
  9042. this.notBefore.toSchema(),
  9043. this.notAfter.toSchema()
  9044. ]
  9045. }));
  9046. outputArray.push(this.subject.toSchema());
  9047. outputArray.push(this.subjectPublicKeyInfo.toSchema());
  9048. if (this.issuerUniqueID) {
  9049. outputArray.push(new asn1js__namespace.Primitive({
  9050. optional: true,
  9051. idBlock: {
  9052. tagClass: 3,
  9053. tagNumber: 1
  9054. },
  9055. valueHex: this.issuerUniqueID
  9056. }));
  9057. }
  9058. if (this.subjectUniqueID) {
  9059. outputArray.push(new asn1js__namespace.Primitive({
  9060. optional: true,
  9061. idBlock: {
  9062. tagClass: 3,
  9063. tagNumber: 2
  9064. },
  9065. valueHex: this.subjectUniqueID
  9066. }));
  9067. }
  9068. if (this.extensions) {
  9069. outputArray.push(new asn1js__namespace.Constructed({
  9070. optional: true,
  9071. idBlock: {
  9072. tagClass: 3,
  9073. tagNumber: 3
  9074. },
  9075. value: [new asn1js__namespace.Sequence({
  9076. value: Array.from(this.extensions, o => o.toSchema())
  9077. })]
  9078. }));
  9079. }
  9080. return (new asn1js__namespace.Sequence({
  9081. value: outputArray
  9082. }));
  9083. }
  9084. toSchema(encodeFlag = false) {
  9085. let tbsSchema;
  9086. if (encodeFlag === false) {
  9087. if (!this.tbsView.byteLength) {
  9088. return Certificate.schema().value[0];
  9089. }
  9090. const asn1 = asn1js__namespace.fromBER(this.tbsView);
  9091. AsnError.assert(asn1, "TBS Certificate");
  9092. tbsSchema = asn1.result;
  9093. }
  9094. else {
  9095. tbsSchema = this.encodeTBS();
  9096. }
  9097. return (new asn1js__namespace.Sequence({
  9098. value: [
  9099. tbsSchema,
  9100. this.signatureAlgorithm.toSchema(),
  9101. this.signatureValue
  9102. ]
  9103. }));
  9104. }
  9105. toJSON() {
  9106. const res = {
  9107. tbs: pvtsutils__namespace.Convert.ToHex(this.tbsView),
  9108. version: this.version,
  9109. serialNumber: this.serialNumber.toJSON(),
  9110. signature: this.signature.toJSON(),
  9111. issuer: this.issuer.toJSON(),
  9112. notBefore: this.notBefore.toJSON(),
  9113. notAfter: this.notAfter.toJSON(),
  9114. subject: this.subject.toJSON(),
  9115. subjectPublicKeyInfo: this.subjectPublicKeyInfo.toJSON(),
  9116. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  9117. signatureValue: this.signatureValue.toJSON(),
  9118. };
  9119. if ((VERSION$f in this) && (this.version !== Certificate.defaultValues(VERSION$f))) {
  9120. res.version = this.version;
  9121. }
  9122. if (this.issuerUniqueID) {
  9123. res.issuerUniqueID = pvtsutils__namespace.Convert.ToHex(this.issuerUniqueID);
  9124. }
  9125. if (this.subjectUniqueID) {
  9126. res.subjectUniqueID = pvtsutils__namespace.Convert.ToHex(this.subjectUniqueID);
  9127. }
  9128. if (this.extensions) {
  9129. res.extensions = Array.from(this.extensions, o => o.toJSON());
  9130. }
  9131. return res;
  9132. }
  9133. async getPublicKey(parameters, crypto = getCrypto(true)) {
  9134. return crypto.getPublicKey(this.subjectPublicKeyInfo, this.signatureAlgorithm, parameters);
  9135. }
  9136. async getKeyHash(hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  9137. return crypto.digest({ name: hashAlgorithm }, this.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView);
  9138. }
  9139. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  9140. if (!privateKey) {
  9141. throw new Error("Need to provide a private key for signing");
  9142. }
  9143. const signatureParameters = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  9144. const parameters = signatureParameters.parameters;
  9145. this.signature = signatureParameters.signatureAlgorithm;
  9146. this.signatureAlgorithm = signatureParameters.signatureAlgorithm;
  9147. this.tbsView = new Uint8Array(this.encodeTBS().toBER());
  9148. const signature = await crypto.signWithPrivateKey(this.tbsView, privateKey, parameters);
  9149. this.signatureValue = new asn1js__namespace.BitString({ valueHex: signature });
  9150. }
  9151. async verify(issuerCertificate, crypto = getCrypto(true)) {
  9152. let subjectPublicKeyInfo;
  9153. if (issuerCertificate) {
  9154. subjectPublicKeyInfo = issuerCertificate.subjectPublicKeyInfo;
  9155. }
  9156. else if (this.issuer.isEqual(this.subject)) {
  9157. subjectPublicKeyInfo = this.subjectPublicKeyInfo;
  9158. }
  9159. if (!(subjectPublicKeyInfo instanceof PublicKeyInfo)) {
  9160. throw new Error("Please provide issuer certificate as a parameter");
  9161. }
  9162. return crypto.verifyWithPublicKey(this.tbsView, this.signatureValue, subjectPublicKeyInfo, this.signatureAlgorithm);
  9163. }
  9164. }
  9165. Certificate.CLASS_NAME = "Certificate";
  9166. function checkCA(cert, signerCert = null) {
  9167. if (signerCert && cert.issuer.isEqual(signerCert.issuer) && cert.serialNumber.isEqual(signerCert.serialNumber)) {
  9168. return null;
  9169. }
  9170. let isCA = false;
  9171. if (cert.extensions) {
  9172. for (const extension of cert.extensions) {
  9173. if (extension.extnID === id_BasicConstraints && extension.parsedValue instanceof BasicConstraints) {
  9174. if (extension.parsedValue.cA) {
  9175. isCA = true;
  9176. break;
  9177. }
  9178. }
  9179. }
  9180. }
  9181. if (isCA) {
  9182. return cert;
  9183. }
  9184. return null;
  9185. }
  9186. const CERT_ID$1 = "certId";
  9187. const CERT_VALUE = "certValue";
  9188. const PARSED_VALUE$4 = "parsedValue";
  9189. const CLEAR_PROPS$P = [
  9190. CERT_ID$1,
  9191. CERT_VALUE
  9192. ];
  9193. class CertBag extends PkiObject {
  9194. constructor(parameters = {}) {
  9195. super();
  9196. this.certId = pvutils__namespace.getParametersValue(parameters, CERT_ID$1, CertBag.defaultValues(CERT_ID$1));
  9197. this.certValue = pvutils__namespace.getParametersValue(parameters, CERT_VALUE, CertBag.defaultValues(CERT_VALUE));
  9198. if (PARSED_VALUE$4 in parameters) {
  9199. this.parsedValue = pvutils__namespace.getParametersValue(parameters, PARSED_VALUE$4, CertBag.defaultValues(PARSED_VALUE$4));
  9200. }
  9201. if (parameters.schema) {
  9202. this.fromSchema(parameters.schema);
  9203. }
  9204. }
  9205. static defaultValues(memberName) {
  9206. switch (memberName) {
  9207. case CERT_ID$1:
  9208. return EMPTY_STRING;
  9209. case CERT_VALUE:
  9210. return (new asn1js__namespace.Any());
  9211. case PARSED_VALUE$4:
  9212. return {};
  9213. default:
  9214. return super.defaultValues(memberName);
  9215. }
  9216. }
  9217. static compareWithDefault(memberName, memberValue) {
  9218. switch (memberName) {
  9219. case CERT_ID$1:
  9220. return (memberValue === EMPTY_STRING);
  9221. case CERT_VALUE:
  9222. return (memberValue instanceof asn1js__namespace.Any);
  9223. case PARSED_VALUE$4:
  9224. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  9225. default:
  9226. return super.defaultValues(memberName);
  9227. }
  9228. }
  9229. static schema(parameters = {}) {
  9230. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  9231. return (new asn1js__namespace.Sequence({
  9232. name: (names.blockName || EMPTY_STRING),
  9233. value: [
  9234. new asn1js__namespace.ObjectIdentifier({ name: (names.id || "id") }),
  9235. new asn1js__namespace.Constructed({
  9236. idBlock: {
  9237. tagClass: 3,
  9238. tagNumber: 0
  9239. },
  9240. value: [new asn1js__namespace.Any({ name: (names.value || "value") })]
  9241. })
  9242. ]
  9243. }));
  9244. }
  9245. fromSchema(schema) {
  9246. pvutils__namespace.clearProps(schema, CLEAR_PROPS$P);
  9247. const asn1 = asn1js__namespace.compareSchema(schema, schema, CertBag.schema({
  9248. names: {
  9249. id: CERT_ID$1,
  9250. value: CERT_VALUE
  9251. }
  9252. }));
  9253. AsnError.assertSchema(asn1, this.className);
  9254. this.certId = asn1.result.certId.valueBlock.toString();
  9255. this.certValue = asn1.result.certValue;
  9256. const certValueHex = this.certValue.valueBlock.valueHexView;
  9257. switch (this.certId) {
  9258. case id_CertBag_X509Certificate:
  9259. {
  9260. try {
  9261. this.parsedValue = Certificate.fromBER(certValueHex);
  9262. }
  9263. catch {
  9264. AttributeCertificateV2.fromBER(certValueHex);
  9265. }
  9266. }
  9267. break;
  9268. case id_CertBag_AttributeCertificate:
  9269. {
  9270. this.parsedValue = AttributeCertificateV2.fromBER(certValueHex);
  9271. }
  9272. break;
  9273. case id_CertBag_SDSICertificate:
  9274. default:
  9275. throw new Error(`Incorrect CERT_ID value in CertBag: ${this.certId}`);
  9276. }
  9277. }
  9278. toSchema() {
  9279. if (PARSED_VALUE$4 in this) {
  9280. if ("acinfo" in this.parsedValue) {
  9281. this.certId = id_CertBag_AttributeCertificate;
  9282. }
  9283. else {
  9284. this.certId = id_CertBag_X509Certificate;
  9285. }
  9286. this.certValue = new asn1js__namespace.OctetString({ valueHex: this.parsedValue.toSchema().toBER(false) });
  9287. }
  9288. return (new asn1js__namespace.Sequence({
  9289. value: [
  9290. new asn1js__namespace.ObjectIdentifier({ value: this.certId }),
  9291. new asn1js__namespace.Constructed({
  9292. idBlock: {
  9293. tagClass: 3,
  9294. tagNumber: 0
  9295. },
  9296. value: [(("toSchema" in this.certValue) ? this.certValue.toSchema() : this.certValue)]
  9297. })
  9298. ]
  9299. }));
  9300. }
  9301. toJSON() {
  9302. return {
  9303. certId: this.certId,
  9304. certValue: this.certValue.toJSON()
  9305. };
  9306. }
  9307. }
  9308. CertBag.CLASS_NAME = "CertBag";
  9309. const USER_CERTIFICATE = "userCertificate";
  9310. const REVOCATION_DATE = "revocationDate";
  9311. const CRL_ENTRY_EXTENSIONS = "crlEntryExtensions";
  9312. const CLEAR_PROPS$O = [
  9313. USER_CERTIFICATE,
  9314. REVOCATION_DATE,
  9315. CRL_ENTRY_EXTENSIONS
  9316. ];
  9317. class RevokedCertificate extends PkiObject {
  9318. constructor(parameters = {}) {
  9319. super();
  9320. this.userCertificate = pvutils__namespace.getParametersValue(parameters, USER_CERTIFICATE, RevokedCertificate.defaultValues(USER_CERTIFICATE));
  9321. this.revocationDate = pvutils__namespace.getParametersValue(parameters, REVOCATION_DATE, RevokedCertificate.defaultValues(REVOCATION_DATE));
  9322. if (CRL_ENTRY_EXTENSIONS in parameters) {
  9323. this.crlEntryExtensions = pvutils__namespace.getParametersValue(parameters, CRL_ENTRY_EXTENSIONS, RevokedCertificate.defaultValues(CRL_ENTRY_EXTENSIONS));
  9324. }
  9325. if (parameters.schema) {
  9326. this.fromSchema(parameters.schema);
  9327. }
  9328. }
  9329. static defaultValues(memberName) {
  9330. switch (memberName) {
  9331. case USER_CERTIFICATE:
  9332. return new asn1js__namespace.Integer();
  9333. case REVOCATION_DATE:
  9334. return new Time();
  9335. case CRL_ENTRY_EXTENSIONS:
  9336. return new Extensions();
  9337. default:
  9338. return super.defaultValues(memberName);
  9339. }
  9340. }
  9341. static schema(parameters = {}) {
  9342. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  9343. return new asn1js__namespace.Sequence({
  9344. name: (names.blockName || EMPTY_STRING),
  9345. value: [
  9346. new asn1js__namespace.Integer({ name: (names.userCertificate || USER_CERTIFICATE) }),
  9347. Time.schema({
  9348. names: {
  9349. utcTimeName: (names.revocationDate || REVOCATION_DATE),
  9350. generalTimeName: (names.revocationDate || REVOCATION_DATE)
  9351. }
  9352. }),
  9353. Extensions.schema({
  9354. names: {
  9355. blockName: (names.crlEntryExtensions || CRL_ENTRY_EXTENSIONS)
  9356. }
  9357. }, true)
  9358. ]
  9359. });
  9360. }
  9361. fromSchema(schema) {
  9362. pvutils__namespace.clearProps(schema, CLEAR_PROPS$O);
  9363. const asn1 = asn1js__namespace.compareSchema(schema, schema, RevokedCertificate.schema());
  9364. AsnError.assertSchema(asn1, this.className);
  9365. this.userCertificate = asn1.result.userCertificate;
  9366. this.revocationDate = new Time({ schema: asn1.result.revocationDate });
  9367. if (CRL_ENTRY_EXTENSIONS in asn1.result) {
  9368. this.crlEntryExtensions = new Extensions({ schema: asn1.result.crlEntryExtensions });
  9369. }
  9370. }
  9371. toSchema() {
  9372. const outputArray = [
  9373. this.userCertificate,
  9374. this.revocationDate.toSchema()
  9375. ];
  9376. if (this.crlEntryExtensions) {
  9377. outputArray.push(this.crlEntryExtensions.toSchema());
  9378. }
  9379. return (new asn1js__namespace.Sequence({
  9380. value: outputArray
  9381. }));
  9382. }
  9383. toJSON() {
  9384. const res = {
  9385. userCertificate: this.userCertificate.toJSON(),
  9386. revocationDate: this.revocationDate.toJSON(),
  9387. };
  9388. if (this.crlEntryExtensions) {
  9389. res.crlEntryExtensions = this.crlEntryExtensions.toJSON();
  9390. }
  9391. return res;
  9392. }
  9393. }
  9394. RevokedCertificate.CLASS_NAME = "RevokedCertificate";
  9395. const TBS$3 = "tbs";
  9396. const VERSION$e = "version";
  9397. const SIGNATURE$3 = "signature";
  9398. const ISSUER$1 = "issuer";
  9399. const THIS_UPDATE$1 = "thisUpdate";
  9400. const NEXT_UPDATE$1 = "nextUpdate";
  9401. const REVOKED_CERTIFICATES = "revokedCertificates";
  9402. const CRL_EXTENSIONS = "crlExtensions";
  9403. const SIGNATURE_ALGORITHM$4 = "signatureAlgorithm";
  9404. const SIGNATURE_VALUE$1 = "signatureValue";
  9405. const TBS_CERT_LIST = "tbsCertList";
  9406. const TBS_CERT_LIST_VERSION = `${TBS_CERT_LIST}.version`;
  9407. const TBS_CERT_LIST_SIGNATURE = `${TBS_CERT_LIST}.signature`;
  9408. const TBS_CERT_LIST_ISSUER = `${TBS_CERT_LIST}.issuer`;
  9409. const TBS_CERT_LIST_THIS_UPDATE = `${TBS_CERT_LIST}.thisUpdate`;
  9410. const TBS_CERT_LIST_NEXT_UPDATE = `${TBS_CERT_LIST}.nextUpdate`;
  9411. const TBS_CERT_LIST_REVOKED_CERTIFICATES = `${TBS_CERT_LIST}.revokedCertificates`;
  9412. const TBS_CERT_LIST_EXTENSIONS = `${TBS_CERT_LIST}.extensions`;
  9413. const CLEAR_PROPS$N = [
  9414. TBS_CERT_LIST,
  9415. TBS_CERT_LIST_VERSION,
  9416. TBS_CERT_LIST_SIGNATURE,
  9417. TBS_CERT_LIST_ISSUER,
  9418. TBS_CERT_LIST_THIS_UPDATE,
  9419. TBS_CERT_LIST_NEXT_UPDATE,
  9420. TBS_CERT_LIST_REVOKED_CERTIFICATES,
  9421. TBS_CERT_LIST_EXTENSIONS,
  9422. SIGNATURE_ALGORITHM$4,
  9423. SIGNATURE_VALUE$1
  9424. ];
  9425. function tbsCertList(parameters = {}) {
  9426. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  9427. return (new asn1js__namespace.Sequence({
  9428. name: (names.blockName || TBS_CERT_LIST),
  9429. value: [
  9430. new asn1js__namespace.Integer({
  9431. optional: true,
  9432. name: (names.tbsCertListVersion || TBS_CERT_LIST_VERSION),
  9433. value: 2
  9434. }),
  9435. AlgorithmIdentifier.schema(names.signature || {
  9436. names: {
  9437. blockName: TBS_CERT_LIST_SIGNATURE
  9438. }
  9439. }),
  9440. RelativeDistinguishedNames.schema(names.issuer || {
  9441. names: {
  9442. blockName: TBS_CERT_LIST_ISSUER
  9443. }
  9444. }),
  9445. Time.schema(names.tbsCertListThisUpdate || {
  9446. names: {
  9447. utcTimeName: TBS_CERT_LIST_THIS_UPDATE,
  9448. generalTimeName: TBS_CERT_LIST_THIS_UPDATE
  9449. }
  9450. }),
  9451. Time.schema(names.tbsCertListNextUpdate || {
  9452. names: {
  9453. utcTimeName: TBS_CERT_LIST_NEXT_UPDATE,
  9454. generalTimeName: TBS_CERT_LIST_NEXT_UPDATE
  9455. }
  9456. }, true),
  9457. new asn1js__namespace.Sequence({
  9458. optional: true,
  9459. value: [
  9460. new asn1js__namespace.Repeated({
  9461. name: (names.tbsCertListRevokedCertificates || TBS_CERT_LIST_REVOKED_CERTIFICATES),
  9462. value: new asn1js__namespace.Sequence({
  9463. value: [
  9464. new asn1js__namespace.Integer(),
  9465. Time.schema(),
  9466. Extensions.schema({}, true)
  9467. ]
  9468. })
  9469. })
  9470. ]
  9471. }),
  9472. new asn1js__namespace.Constructed({
  9473. optional: true,
  9474. idBlock: {
  9475. tagClass: 3,
  9476. tagNumber: 0
  9477. },
  9478. value: [Extensions.schema(names.crlExtensions || {
  9479. names: {
  9480. blockName: TBS_CERT_LIST_EXTENSIONS
  9481. }
  9482. })]
  9483. })
  9484. ]
  9485. }));
  9486. }
  9487. const WELL_KNOWN_EXTENSIONS = [
  9488. id_AuthorityKeyIdentifier,
  9489. id_IssuerAltName,
  9490. id_CRLNumber,
  9491. id_BaseCRLNumber,
  9492. id_IssuingDistributionPoint,
  9493. id_FreshestCRL,
  9494. id_AuthorityInfoAccess,
  9495. id_CRLReason,
  9496. id_InvalidityDate,
  9497. id_CertificateIssuer,
  9498. ];
  9499. class CertificateRevocationList extends PkiObject {
  9500. get tbs() {
  9501. return pvtsutils__namespace.BufferSourceConverter.toArrayBuffer(this.tbsView);
  9502. }
  9503. set tbs(value) {
  9504. this.tbsView = new Uint8Array(value);
  9505. }
  9506. constructor(parameters = {}) {
  9507. super();
  9508. this.tbsView = new Uint8Array(pvutils__namespace.getParametersValue(parameters, TBS$3, CertificateRevocationList.defaultValues(TBS$3)));
  9509. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$e, CertificateRevocationList.defaultValues(VERSION$e));
  9510. this.signature = pvutils__namespace.getParametersValue(parameters, SIGNATURE$3, CertificateRevocationList.defaultValues(SIGNATURE$3));
  9511. this.issuer = pvutils__namespace.getParametersValue(parameters, ISSUER$1, CertificateRevocationList.defaultValues(ISSUER$1));
  9512. this.thisUpdate = pvutils__namespace.getParametersValue(parameters, THIS_UPDATE$1, CertificateRevocationList.defaultValues(THIS_UPDATE$1));
  9513. if (NEXT_UPDATE$1 in parameters) {
  9514. this.nextUpdate = pvutils__namespace.getParametersValue(parameters, NEXT_UPDATE$1, CertificateRevocationList.defaultValues(NEXT_UPDATE$1));
  9515. }
  9516. if (REVOKED_CERTIFICATES in parameters) {
  9517. this.revokedCertificates = pvutils__namespace.getParametersValue(parameters, REVOKED_CERTIFICATES, CertificateRevocationList.defaultValues(REVOKED_CERTIFICATES));
  9518. }
  9519. if (CRL_EXTENSIONS in parameters) {
  9520. this.crlExtensions = pvutils__namespace.getParametersValue(parameters, CRL_EXTENSIONS, CertificateRevocationList.defaultValues(CRL_EXTENSIONS));
  9521. }
  9522. this.signatureAlgorithm = pvutils__namespace.getParametersValue(parameters, SIGNATURE_ALGORITHM$4, CertificateRevocationList.defaultValues(SIGNATURE_ALGORITHM$4));
  9523. this.signatureValue = pvutils__namespace.getParametersValue(parameters, SIGNATURE_VALUE$1, CertificateRevocationList.defaultValues(SIGNATURE_VALUE$1));
  9524. if (parameters.schema) {
  9525. this.fromSchema(parameters.schema);
  9526. }
  9527. }
  9528. static defaultValues(memberName) {
  9529. switch (memberName) {
  9530. case TBS$3:
  9531. return EMPTY_BUFFER;
  9532. case VERSION$e:
  9533. return 0;
  9534. case SIGNATURE$3:
  9535. return new AlgorithmIdentifier();
  9536. case ISSUER$1:
  9537. return new RelativeDistinguishedNames();
  9538. case THIS_UPDATE$1:
  9539. return new Time();
  9540. case NEXT_UPDATE$1:
  9541. return new Time();
  9542. case REVOKED_CERTIFICATES:
  9543. return [];
  9544. case CRL_EXTENSIONS:
  9545. return new Extensions();
  9546. case SIGNATURE_ALGORITHM$4:
  9547. return new AlgorithmIdentifier();
  9548. case SIGNATURE_VALUE$1:
  9549. return new asn1js__namespace.BitString();
  9550. default:
  9551. return super.defaultValues(memberName);
  9552. }
  9553. }
  9554. static schema(parameters = {}) {
  9555. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  9556. return (new asn1js__namespace.Sequence({
  9557. name: (names.blockName || "CertificateList"),
  9558. value: [
  9559. tbsCertList(parameters),
  9560. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  9561. names: {
  9562. blockName: SIGNATURE_ALGORITHM$4
  9563. }
  9564. }),
  9565. new asn1js__namespace.BitString({ name: (names.signatureValue || SIGNATURE_VALUE$1) })
  9566. ]
  9567. }));
  9568. }
  9569. fromSchema(schema) {
  9570. pvutils__namespace.clearProps(schema, CLEAR_PROPS$N);
  9571. const asn1 = asn1js__namespace.compareSchema(schema, schema, CertificateRevocationList.schema());
  9572. AsnError.assertSchema(asn1, this.className);
  9573. this.tbsView = asn1.result.tbsCertList.valueBeforeDecodeView;
  9574. if (TBS_CERT_LIST_VERSION in asn1.result) {
  9575. this.version = asn1.result[TBS_CERT_LIST_VERSION].valueBlock.valueDec;
  9576. }
  9577. this.signature = new AlgorithmIdentifier({ schema: asn1.result[TBS_CERT_LIST_SIGNATURE] });
  9578. this.issuer = new RelativeDistinguishedNames({ schema: asn1.result[TBS_CERT_LIST_ISSUER] });
  9579. this.thisUpdate = new Time({ schema: asn1.result[TBS_CERT_LIST_THIS_UPDATE] });
  9580. if (TBS_CERT_LIST_NEXT_UPDATE in asn1.result) {
  9581. this.nextUpdate = new Time({ schema: asn1.result[TBS_CERT_LIST_NEXT_UPDATE] });
  9582. }
  9583. if (TBS_CERT_LIST_REVOKED_CERTIFICATES in asn1.result) {
  9584. this.revokedCertificates = Array.from(asn1.result[TBS_CERT_LIST_REVOKED_CERTIFICATES], element => new RevokedCertificate({ schema: element }));
  9585. }
  9586. if (TBS_CERT_LIST_EXTENSIONS in asn1.result) {
  9587. this.crlExtensions = new Extensions({ schema: asn1.result[TBS_CERT_LIST_EXTENSIONS] });
  9588. }
  9589. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  9590. this.signatureValue = asn1.result.signatureValue;
  9591. }
  9592. encodeTBS() {
  9593. const outputArray = [];
  9594. if (this.version !== CertificateRevocationList.defaultValues(VERSION$e)) {
  9595. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  9596. }
  9597. outputArray.push(this.signature.toSchema());
  9598. outputArray.push(this.issuer.toSchema());
  9599. outputArray.push(this.thisUpdate.toSchema());
  9600. if (this.nextUpdate) {
  9601. outputArray.push(this.nextUpdate.toSchema());
  9602. }
  9603. if (this.revokedCertificates) {
  9604. outputArray.push(new asn1js__namespace.Sequence({
  9605. value: Array.from(this.revokedCertificates, o => o.toSchema())
  9606. }));
  9607. }
  9608. if (this.crlExtensions) {
  9609. outputArray.push(new asn1js__namespace.Constructed({
  9610. optional: true,
  9611. idBlock: {
  9612. tagClass: 3,
  9613. tagNumber: 0
  9614. },
  9615. value: [
  9616. this.crlExtensions.toSchema()
  9617. ]
  9618. }));
  9619. }
  9620. return (new asn1js__namespace.Sequence({
  9621. value: outputArray
  9622. }));
  9623. }
  9624. toSchema(encodeFlag = false) {
  9625. let tbsSchema;
  9626. if (!encodeFlag) {
  9627. if (!this.tbsView.byteLength) {
  9628. return CertificateRevocationList.schema();
  9629. }
  9630. const asn1 = asn1js__namespace.fromBER(this.tbsView);
  9631. AsnError.assert(asn1, "TBS Certificate Revocation List");
  9632. tbsSchema = asn1.result;
  9633. }
  9634. else {
  9635. tbsSchema = this.encodeTBS();
  9636. }
  9637. return (new asn1js__namespace.Sequence({
  9638. value: [
  9639. tbsSchema,
  9640. this.signatureAlgorithm.toSchema(),
  9641. this.signatureValue
  9642. ]
  9643. }));
  9644. }
  9645. toJSON() {
  9646. const res = {
  9647. tbs: pvtsutils__namespace.Convert.ToHex(this.tbsView),
  9648. version: this.version,
  9649. signature: this.signature.toJSON(),
  9650. issuer: this.issuer.toJSON(),
  9651. thisUpdate: this.thisUpdate.toJSON(),
  9652. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  9653. signatureValue: this.signatureValue.toJSON()
  9654. };
  9655. if (this.version !== CertificateRevocationList.defaultValues(VERSION$e))
  9656. res.version = this.version;
  9657. if (this.nextUpdate) {
  9658. res.nextUpdate = this.nextUpdate.toJSON();
  9659. }
  9660. if (this.revokedCertificates) {
  9661. res.revokedCertificates = Array.from(this.revokedCertificates, o => o.toJSON());
  9662. }
  9663. if (this.crlExtensions) {
  9664. res.crlExtensions = this.crlExtensions.toJSON();
  9665. }
  9666. return res;
  9667. }
  9668. isCertificateRevoked(certificate) {
  9669. if (!this.issuer.isEqual(certificate.issuer)) {
  9670. return false;
  9671. }
  9672. if (!this.revokedCertificates) {
  9673. return false;
  9674. }
  9675. for (const revokedCertificate of this.revokedCertificates) {
  9676. if (revokedCertificate.userCertificate.isEqual(certificate.serialNumber)) {
  9677. return true;
  9678. }
  9679. }
  9680. return false;
  9681. }
  9682. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  9683. if (!privateKey) {
  9684. throw new Error("Need to provide a private key for signing");
  9685. }
  9686. const signatureParameters = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  9687. const { parameters } = signatureParameters;
  9688. this.signature = signatureParameters.signatureAlgorithm;
  9689. this.signatureAlgorithm = signatureParameters.signatureAlgorithm;
  9690. this.tbsView = new Uint8Array(this.encodeTBS().toBER());
  9691. const signature = await crypto.signWithPrivateKey(this.tbsView, privateKey, parameters);
  9692. this.signatureValue = new asn1js__namespace.BitString({ valueHex: signature });
  9693. }
  9694. async verify(parameters = {}, crypto = getCrypto(true)) {
  9695. let subjectPublicKeyInfo;
  9696. if (parameters.issuerCertificate) {
  9697. subjectPublicKeyInfo = parameters.issuerCertificate.subjectPublicKeyInfo;
  9698. if (!this.issuer.isEqual(parameters.issuerCertificate.subject)) {
  9699. return false;
  9700. }
  9701. }
  9702. if (parameters.publicKeyInfo) {
  9703. subjectPublicKeyInfo = parameters.publicKeyInfo;
  9704. }
  9705. if (!subjectPublicKeyInfo) {
  9706. throw new Error("Issuer's certificate must be provided as an input parameter");
  9707. }
  9708. if (this.crlExtensions) {
  9709. for (const extension of this.crlExtensions.extensions) {
  9710. if (extension.critical) {
  9711. if (!WELL_KNOWN_EXTENSIONS.includes(extension.extnID))
  9712. return false;
  9713. }
  9714. }
  9715. }
  9716. return crypto.verifyWithPublicKey(this.tbsView, this.signatureValue, subjectPublicKeyInfo, this.signatureAlgorithm);
  9717. }
  9718. }
  9719. CertificateRevocationList.CLASS_NAME = "CertificateRevocationList";
  9720. const CRL_ID = "crlId";
  9721. const CRL_VALUE = "crlValue";
  9722. const PARSED_VALUE$3 = "parsedValue";
  9723. const CLEAR_PROPS$M = [
  9724. CRL_ID,
  9725. CRL_VALUE,
  9726. ];
  9727. class CRLBag extends PkiObject {
  9728. constructor(parameters = {}) {
  9729. super();
  9730. this.crlId = pvutils__namespace.getParametersValue(parameters, CRL_ID, CRLBag.defaultValues(CRL_ID));
  9731. this.crlValue = pvutils__namespace.getParametersValue(parameters, CRL_VALUE, CRLBag.defaultValues(CRL_VALUE));
  9732. if (PARSED_VALUE$3 in parameters) {
  9733. this.parsedValue = pvutils__namespace.getParametersValue(parameters, PARSED_VALUE$3, CRLBag.defaultValues(PARSED_VALUE$3));
  9734. }
  9735. if (parameters.schema) {
  9736. this.fromSchema(parameters.schema);
  9737. }
  9738. }
  9739. static defaultValues(memberName) {
  9740. switch (memberName) {
  9741. case CRL_ID:
  9742. return EMPTY_STRING;
  9743. case CRL_VALUE:
  9744. return (new asn1js__namespace.Any());
  9745. case PARSED_VALUE$3:
  9746. return {};
  9747. default:
  9748. return super.defaultValues(memberName);
  9749. }
  9750. }
  9751. static compareWithDefault(memberName, memberValue) {
  9752. switch (memberName) {
  9753. case CRL_ID:
  9754. return (memberValue === EMPTY_STRING);
  9755. case CRL_VALUE:
  9756. return (memberValue instanceof asn1js__namespace.Any);
  9757. case PARSED_VALUE$3:
  9758. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  9759. default:
  9760. return super.defaultValues(memberName);
  9761. }
  9762. }
  9763. static schema(parameters = {}) {
  9764. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  9765. return (new asn1js__namespace.Sequence({
  9766. name: (names.blockName || EMPTY_STRING),
  9767. value: [
  9768. new asn1js__namespace.ObjectIdentifier({ name: (names.id || "id") }),
  9769. new asn1js__namespace.Constructed({
  9770. idBlock: {
  9771. tagClass: 3,
  9772. tagNumber: 0
  9773. },
  9774. value: [new asn1js__namespace.Any({ name: (names.value || "value") })]
  9775. })
  9776. ]
  9777. }));
  9778. }
  9779. fromSchema(schema) {
  9780. pvutils__namespace.clearProps(schema, CLEAR_PROPS$M);
  9781. const asn1 = asn1js__namespace.compareSchema(schema, schema, CRLBag.schema({
  9782. names: {
  9783. id: CRL_ID,
  9784. value: CRL_VALUE
  9785. }
  9786. }));
  9787. AsnError.assertSchema(asn1, this.className);
  9788. this.crlId = asn1.result.crlId.valueBlock.toString();
  9789. this.crlValue = asn1.result.crlValue;
  9790. switch (this.crlId) {
  9791. case id_CRLBag_X509CRL:
  9792. {
  9793. this.parsedValue = CertificateRevocationList.fromBER(this.certValue.valueBlock.valueHex);
  9794. }
  9795. break;
  9796. default:
  9797. throw new Error(`Incorrect CRL_ID value in CRLBag: ${this.crlId}`);
  9798. }
  9799. }
  9800. toSchema() {
  9801. if (this.parsedValue) {
  9802. this.crlId = id_CRLBag_X509CRL;
  9803. this.crlValue = new asn1js__namespace.OctetString({ valueHex: this.parsedValue.toSchema().toBER(false) });
  9804. }
  9805. return (new asn1js__namespace.Sequence({
  9806. value: [
  9807. new asn1js__namespace.ObjectIdentifier({ value: this.crlId }),
  9808. new asn1js__namespace.Constructed({
  9809. idBlock: {
  9810. tagClass: 3,
  9811. tagNumber: 0
  9812. },
  9813. value: [this.crlValue.toSchema()]
  9814. })
  9815. ]
  9816. }));
  9817. }
  9818. toJSON() {
  9819. return {
  9820. crlId: this.crlId,
  9821. crlValue: this.crlValue.toJSON()
  9822. };
  9823. }
  9824. }
  9825. CRLBag.CLASS_NAME = "CRLBag";
  9826. const VERSION$d = "version";
  9827. const ENCRYPTED_CONTENT_INFO$1 = "encryptedContentInfo";
  9828. const UNPROTECTED_ATTRS$1 = "unprotectedAttrs";
  9829. const CLEAR_PROPS$L = [
  9830. VERSION$d,
  9831. ENCRYPTED_CONTENT_INFO$1,
  9832. UNPROTECTED_ATTRS$1,
  9833. ];
  9834. class EncryptedData extends PkiObject {
  9835. constructor(parameters = {}) {
  9836. super();
  9837. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$d, EncryptedData.defaultValues(VERSION$d));
  9838. this.encryptedContentInfo = pvutils__namespace.getParametersValue(parameters, ENCRYPTED_CONTENT_INFO$1, EncryptedData.defaultValues(ENCRYPTED_CONTENT_INFO$1));
  9839. if (UNPROTECTED_ATTRS$1 in parameters) {
  9840. this.unprotectedAttrs = pvutils__namespace.getParametersValue(parameters, UNPROTECTED_ATTRS$1, EncryptedData.defaultValues(UNPROTECTED_ATTRS$1));
  9841. }
  9842. if (parameters.schema) {
  9843. this.fromSchema(parameters.schema);
  9844. }
  9845. }
  9846. static defaultValues(memberName) {
  9847. switch (memberName) {
  9848. case VERSION$d:
  9849. return 0;
  9850. case ENCRYPTED_CONTENT_INFO$1:
  9851. return new EncryptedContentInfo();
  9852. case UNPROTECTED_ATTRS$1:
  9853. return [];
  9854. default:
  9855. return super.defaultValues(memberName);
  9856. }
  9857. }
  9858. static compareWithDefault(memberName, memberValue) {
  9859. switch (memberName) {
  9860. case VERSION$d:
  9861. return (memberValue === 0);
  9862. case ENCRYPTED_CONTENT_INFO$1:
  9863. return ((EncryptedContentInfo.compareWithDefault("contentType", memberValue.contentType)) &&
  9864. (EncryptedContentInfo.compareWithDefault("contentEncryptionAlgorithm", memberValue.contentEncryptionAlgorithm)) &&
  9865. (EncryptedContentInfo.compareWithDefault("encryptedContent", memberValue.encryptedContent)));
  9866. case UNPROTECTED_ATTRS$1:
  9867. return (memberValue.length === 0);
  9868. default:
  9869. return super.defaultValues(memberName);
  9870. }
  9871. }
  9872. static schema(parameters = {}) {
  9873. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  9874. return (new asn1js__namespace.Sequence({
  9875. name: (names.blockName || EMPTY_STRING),
  9876. value: [
  9877. new asn1js__namespace.Integer({ name: (names.version || EMPTY_STRING) }),
  9878. EncryptedContentInfo.schema(names.encryptedContentInfo || {}),
  9879. new asn1js__namespace.Constructed({
  9880. optional: true,
  9881. idBlock: {
  9882. tagClass: 3,
  9883. tagNumber: 1
  9884. },
  9885. value: [
  9886. new asn1js__namespace.Repeated({
  9887. name: (names.unprotectedAttrs || EMPTY_STRING),
  9888. value: Attribute.schema()
  9889. })
  9890. ]
  9891. })
  9892. ]
  9893. }));
  9894. }
  9895. fromSchema(schema) {
  9896. pvutils__namespace.clearProps(schema, CLEAR_PROPS$L);
  9897. const asn1 = asn1js__namespace.compareSchema(schema, schema, EncryptedData.schema({
  9898. names: {
  9899. version: VERSION$d,
  9900. encryptedContentInfo: {
  9901. names: {
  9902. blockName: ENCRYPTED_CONTENT_INFO$1
  9903. }
  9904. },
  9905. unprotectedAttrs: UNPROTECTED_ATTRS$1
  9906. }
  9907. }));
  9908. AsnError.assertSchema(asn1, this.className);
  9909. this.version = asn1.result.version.valueBlock.valueDec;
  9910. this.encryptedContentInfo = new EncryptedContentInfo({ schema: asn1.result.encryptedContentInfo });
  9911. if (UNPROTECTED_ATTRS$1 in asn1.result)
  9912. this.unprotectedAttrs = Array.from(asn1.result.unprotectedAttrs, element => new Attribute({ schema: element }));
  9913. }
  9914. toSchema() {
  9915. const outputArray = [];
  9916. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  9917. outputArray.push(this.encryptedContentInfo.toSchema());
  9918. if (this.unprotectedAttrs) {
  9919. outputArray.push(new asn1js__namespace.Constructed({
  9920. optional: true,
  9921. idBlock: {
  9922. tagClass: 3,
  9923. tagNumber: 1
  9924. },
  9925. value: Array.from(this.unprotectedAttrs, o => o.toSchema())
  9926. }));
  9927. }
  9928. return (new asn1js__namespace.Sequence({
  9929. value: outputArray
  9930. }));
  9931. }
  9932. toJSON() {
  9933. const res = {
  9934. version: this.version,
  9935. encryptedContentInfo: this.encryptedContentInfo.toJSON()
  9936. };
  9937. if (this.unprotectedAttrs)
  9938. res.unprotectedAttrs = Array.from(this.unprotectedAttrs, o => o.toJSON());
  9939. return res;
  9940. }
  9941. async encrypt(parameters, crypto = getCrypto(true)) {
  9942. ArgumentError.assert(parameters, "parameters", "object");
  9943. const encryptParams = {
  9944. ...parameters,
  9945. contentType: "1.2.840.113549.1.7.1",
  9946. };
  9947. this.encryptedContentInfo = await crypto.encryptEncryptedContentInfo(encryptParams);
  9948. }
  9949. async decrypt(parameters, crypto = getCrypto(true)) {
  9950. ArgumentError.assert(parameters, "parameters", "object");
  9951. const decryptParams = {
  9952. ...parameters,
  9953. encryptedContentInfo: this.encryptedContentInfo,
  9954. };
  9955. return crypto.decryptEncryptedContentInfo(decryptParams);
  9956. }
  9957. }
  9958. EncryptedData.CLASS_NAME = "EncryptedData";
  9959. const ENCRYPTION_ALGORITHM = "encryptionAlgorithm";
  9960. const ENCRYPTED_DATA = "encryptedData";
  9961. const PARSED_VALUE$2 = "parsedValue";
  9962. const CLEAR_PROPS$K = [
  9963. ENCRYPTION_ALGORITHM,
  9964. ENCRYPTED_DATA,
  9965. ];
  9966. class PKCS8ShroudedKeyBag extends PkiObject {
  9967. constructor(parameters = {}) {
  9968. super();
  9969. this.encryptionAlgorithm = pvutils__namespace.getParametersValue(parameters, ENCRYPTION_ALGORITHM, PKCS8ShroudedKeyBag.defaultValues(ENCRYPTION_ALGORITHM));
  9970. this.encryptedData = pvutils__namespace.getParametersValue(parameters, ENCRYPTED_DATA, PKCS8ShroudedKeyBag.defaultValues(ENCRYPTED_DATA));
  9971. if (PARSED_VALUE$2 in parameters) {
  9972. this.parsedValue = pvutils__namespace.getParametersValue(parameters, PARSED_VALUE$2, PKCS8ShroudedKeyBag.defaultValues(PARSED_VALUE$2));
  9973. }
  9974. if (parameters.schema) {
  9975. this.fromSchema(parameters.schema);
  9976. }
  9977. }
  9978. static defaultValues(memberName) {
  9979. switch (memberName) {
  9980. case ENCRYPTION_ALGORITHM:
  9981. return (new AlgorithmIdentifier());
  9982. case ENCRYPTED_DATA:
  9983. return (new asn1js__namespace.OctetString());
  9984. case PARSED_VALUE$2:
  9985. return {};
  9986. default:
  9987. return super.defaultValues(memberName);
  9988. }
  9989. }
  9990. static compareWithDefault(memberName, memberValue) {
  9991. switch (memberName) {
  9992. case ENCRYPTION_ALGORITHM:
  9993. return ((AlgorithmIdentifier.compareWithDefault("algorithmId", memberValue.algorithmId)) &&
  9994. (("algorithmParams" in memberValue) === false));
  9995. case ENCRYPTED_DATA:
  9996. return (memberValue.isEqual(PKCS8ShroudedKeyBag.defaultValues(memberName)));
  9997. case PARSED_VALUE$2:
  9998. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  9999. default:
  10000. return super.defaultValues(memberName);
  10001. }
  10002. }
  10003. static schema(parameters = {}) {
  10004. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10005. return (new asn1js__namespace.Sequence({
  10006. name: (names.blockName || EMPTY_STRING),
  10007. value: [
  10008. AlgorithmIdentifier.schema(names.encryptionAlgorithm || {
  10009. names: {
  10010. blockName: ENCRYPTION_ALGORITHM
  10011. }
  10012. }),
  10013. new asn1js__namespace.Choice({
  10014. value: [
  10015. new asn1js__namespace.OctetString({ name: (names.encryptedData || ENCRYPTED_DATA) }),
  10016. new asn1js__namespace.OctetString({
  10017. idBlock: {
  10018. isConstructed: true
  10019. },
  10020. name: (names.encryptedData || ENCRYPTED_DATA)
  10021. })
  10022. ]
  10023. })
  10024. ]
  10025. }));
  10026. }
  10027. fromSchema(schema) {
  10028. pvutils__namespace.clearProps(schema, CLEAR_PROPS$K);
  10029. const asn1 = asn1js__namespace.compareSchema(schema, schema, PKCS8ShroudedKeyBag.schema({
  10030. names: {
  10031. encryptionAlgorithm: {
  10032. names: {
  10033. blockName: ENCRYPTION_ALGORITHM
  10034. }
  10035. },
  10036. encryptedData: ENCRYPTED_DATA
  10037. }
  10038. }));
  10039. AsnError.assertSchema(asn1, this.className);
  10040. this.encryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.encryptionAlgorithm });
  10041. this.encryptedData = asn1.result.encryptedData;
  10042. }
  10043. toSchema() {
  10044. return (new asn1js__namespace.Sequence({
  10045. value: [
  10046. this.encryptionAlgorithm.toSchema(),
  10047. this.encryptedData
  10048. ]
  10049. }));
  10050. }
  10051. toJSON() {
  10052. return {
  10053. encryptionAlgorithm: this.encryptionAlgorithm.toJSON(),
  10054. encryptedData: this.encryptedData.toJSON(),
  10055. };
  10056. }
  10057. async parseInternalValues(parameters, crypto = getCrypto(true)) {
  10058. const cmsEncrypted = new EncryptedData({
  10059. encryptedContentInfo: new EncryptedContentInfo({
  10060. contentEncryptionAlgorithm: this.encryptionAlgorithm,
  10061. encryptedContent: this.encryptedData
  10062. })
  10063. });
  10064. const decryptedData = await cmsEncrypted.decrypt(parameters, crypto);
  10065. this.parsedValue = PrivateKeyInfo.fromBER(decryptedData);
  10066. }
  10067. async makeInternalValues(parameters, crypto = getCrypto(true)) {
  10068. if (!this.parsedValue) {
  10069. throw new Error("Please initialize \"parsedValue\" first");
  10070. }
  10071. const cmsEncrypted = new EncryptedData();
  10072. const encryptParams = {
  10073. ...parameters,
  10074. contentToEncrypt: this.parsedValue.toSchema().toBER(false),
  10075. };
  10076. await cmsEncrypted.encrypt(encryptParams, crypto);
  10077. if (!cmsEncrypted.encryptedContentInfo.encryptedContent) {
  10078. throw new Error("The filed `encryptedContent` in EncryptedContentInfo is empty");
  10079. }
  10080. this.encryptionAlgorithm = cmsEncrypted.encryptedContentInfo.contentEncryptionAlgorithm;
  10081. this.encryptedData = cmsEncrypted.encryptedContentInfo.encryptedContent;
  10082. }
  10083. }
  10084. PKCS8ShroudedKeyBag.CLASS_NAME = "PKCS8ShroudedKeyBag";
  10085. const SECRET_TYPE_ID = "secretTypeId";
  10086. const SECRET_VALUE = "secretValue";
  10087. const CLEAR_PROPS$J = [
  10088. SECRET_TYPE_ID,
  10089. SECRET_VALUE,
  10090. ];
  10091. class SecretBag extends PkiObject {
  10092. constructor(parameters = {}) {
  10093. super();
  10094. this.secretTypeId = pvutils__namespace.getParametersValue(parameters, SECRET_TYPE_ID, SecretBag.defaultValues(SECRET_TYPE_ID));
  10095. this.secretValue = pvutils__namespace.getParametersValue(parameters, SECRET_VALUE, SecretBag.defaultValues(SECRET_VALUE));
  10096. if (parameters.schema) {
  10097. this.fromSchema(parameters.schema);
  10098. }
  10099. }
  10100. static defaultValues(memberName) {
  10101. switch (memberName) {
  10102. case SECRET_TYPE_ID:
  10103. return EMPTY_STRING;
  10104. case SECRET_VALUE:
  10105. return (new asn1js__namespace.Any());
  10106. default:
  10107. return super.defaultValues(memberName);
  10108. }
  10109. }
  10110. static compareWithDefault(memberName, memberValue) {
  10111. switch (memberName) {
  10112. case SECRET_TYPE_ID:
  10113. return (memberValue === EMPTY_STRING);
  10114. case SECRET_VALUE:
  10115. return (memberValue instanceof asn1js__namespace.Any);
  10116. default:
  10117. return super.defaultValues(memberName);
  10118. }
  10119. }
  10120. static schema(parameters = {}) {
  10121. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10122. return (new asn1js__namespace.Sequence({
  10123. name: (names.blockName || EMPTY_STRING),
  10124. value: [
  10125. new asn1js__namespace.ObjectIdentifier({ name: (names.id || "id") }),
  10126. new asn1js__namespace.Constructed({
  10127. idBlock: {
  10128. tagClass: 3,
  10129. tagNumber: 0
  10130. },
  10131. value: [new asn1js__namespace.Any({ name: (names.value || "value") })]
  10132. })
  10133. ]
  10134. }));
  10135. }
  10136. fromSchema(schema) {
  10137. pvutils__namespace.clearProps(schema, CLEAR_PROPS$J);
  10138. const asn1 = asn1js__namespace.compareSchema(schema, schema, SecretBag.schema({
  10139. names: {
  10140. id: SECRET_TYPE_ID,
  10141. value: SECRET_VALUE
  10142. }
  10143. }));
  10144. AsnError.assertSchema(asn1, this.className);
  10145. this.secretTypeId = asn1.result.secretTypeId.valueBlock.toString();
  10146. this.secretValue = asn1.result.secretValue;
  10147. }
  10148. toSchema() {
  10149. return (new asn1js__namespace.Sequence({
  10150. value: [
  10151. new asn1js__namespace.ObjectIdentifier({ value: this.secretTypeId }),
  10152. new asn1js__namespace.Constructed({
  10153. idBlock: {
  10154. tagClass: 3,
  10155. tagNumber: 0
  10156. },
  10157. value: [this.secretValue.toSchema()]
  10158. })
  10159. ]
  10160. }));
  10161. }
  10162. toJSON() {
  10163. return {
  10164. secretTypeId: this.secretTypeId,
  10165. secretValue: this.secretValue.toJSON()
  10166. };
  10167. }
  10168. }
  10169. SecretBag.CLASS_NAME = "SecretBag";
  10170. class SafeBagValueFactory {
  10171. static getItems() {
  10172. if (!this.items) {
  10173. this.items = {};
  10174. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.1", PrivateKeyInfo);
  10175. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.2", PKCS8ShroudedKeyBag);
  10176. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.3", CertBag);
  10177. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.4", CRLBag);
  10178. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.5", SecretBag);
  10179. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.6", SafeContents);
  10180. }
  10181. return this.items;
  10182. }
  10183. static register(id, type) {
  10184. this.getItems()[id] = type;
  10185. }
  10186. static find(id) {
  10187. return this.getItems()[id] || null;
  10188. }
  10189. }
  10190. const BAG_ID = "bagId";
  10191. const BAG_VALUE = "bagValue";
  10192. const BAG_ATTRIBUTES = "bagAttributes";
  10193. const CLEAR_PROPS$I = [
  10194. BAG_ID,
  10195. BAG_VALUE,
  10196. BAG_ATTRIBUTES
  10197. ];
  10198. class SafeBag extends PkiObject {
  10199. constructor(parameters = {}) {
  10200. super();
  10201. this.bagId = pvutils__namespace.getParametersValue(parameters, BAG_ID, SafeBag.defaultValues(BAG_ID));
  10202. this.bagValue = pvutils__namespace.getParametersValue(parameters, BAG_VALUE, SafeBag.defaultValues(BAG_VALUE));
  10203. if (BAG_ATTRIBUTES in parameters) {
  10204. this.bagAttributes = pvutils__namespace.getParametersValue(parameters, BAG_ATTRIBUTES, SafeBag.defaultValues(BAG_ATTRIBUTES));
  10205. }
  10206. if (parameters.schema) {
  10207. this.fromSchema(parameters.schema);
  10208. }
  10209. }
  10210. static defaultValues(memberName) {
  10211. switch (memberName) {
  10212. case BAG_ID:
  10213. return EMPTY_STRING;
  10214. case BAG_VALUE:
  10215. return (new asn1js__namespace.Any());
  10216. case BAG_ATTRIBUTES:
  10217. return [];
  10218. default:
  10219. return super.defaultValues(memberName);
  10220. }
  10221. }
  10222. static compareWithDefault(memberName, memberValue) {
  10223. switch (memberName) {
  10224. case BAG_ID:
  10225. return (memberValue === EMPTY_STRING);
  10226. case BAG_VALUE:
  10227. return (memberValue instanceof asn1js__namespace.Any);
  10228. case BAG_ATTRIBUTES:
  10229. return (memberValue.length === 0);
  10230. default:
  10231. return super.defaultValues(memberName);
  10232. }
  10233. }
  10234. static schema(parameters = {}) {
  10235. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10236. return (new asn1js__namespace.Sequence({
  10237. name: (names.blockName || EMPTY_STRING),
  10238. value: [
  10239. new asn1js__namespace.ObjectIdentifier({ name: (names.bagId || BAG_ID) }),
  10240. new asn1js__namespace.Constructed({
  10241. idBlock: {
  10242. tagClass: 3,
  10243. tagNumber: 0
  10244. },
  10245. value: [new asn1js__namespace.Any({ name: (names.bagValue || BAG_VALUE) })]
  10246. }),
  10247. new asn1js__namespace.Set({
  10248. optional: true,
  10249. value: [
  10250. new asn1js__namespace.Repeated({
  10251. name: (names.bagAttributes || BAG_ATTRIBUTES),
  10252. value: Attribute.schema()
  10253. })
  10254. ]
  10255. })
  10256. ]
  10257. }));
  10258. }
  10259. fromSchema(schema) {
  10260. pvutils__namespace.clearProps(schema, CLEAR_PROPS$I);
  10261. const asn1 = asn1js__namespace.compareSchema(schema, schema, SafeBag.schema({
  10262. names: {
  10263. bagId: BAG_ID,
  10264. bagValue: BAG_VALUE,
  10265. bagAttributes: BAG_ATTRIBUTES
  10266. }
  10267. }));
  10268. AsnError.assertSchema(asn1, this.className);
  10269. this.bagId = asn1.result.bagId.valueBlock.toString();
  10270. const bagType = SafeBagValueFactory.find(this.bagId);
  10271. if (!bagType) {
  10272. throw new Error(`Invalid BAG_ID for SafeBag: ${this.bagId}`);
  10273. }
  10274. this.bagValue = new bagType({ schema: asn1.result.bagValue });
  10275. if (BAG_ATTRIBUTES in asn1.result) {
  10276. this.bagAttributes = Array.from(asn1.result.bagAttributes, element => new Attribute({ schema: element }));
  10277. }
  10278. }
  10279. toSchema() {
  10280. const outputArray = [
  10281. new asn1js__namespace.ObjectIdentifier({ value: this.bagId }),
  10282. new asn1js__namespace.Constructed({
  10283. idBlock: {
  10284. tagClass: 3,
  10285. tagNumber: 0
  10286. },
  10287. value: [this.bagValue.toSchema()]
  10288. })
  10289. ];
  10290. if (this.bagAttributes) {
  10291. outputArray.push(new asn1js__namespace.Set({
  10292. value: Array.from(this.bagAttributes, o => o.toSchema())
  10293. }));
  10294. }
  10295. return (new asn1js__namespace.Sequence({
  10296. value: outputArray
  10297. }));
  10298. }
  10299. toJSON() {
  10300. const output = {
  10301. bagId: this.bagId,
  10302. bagValue: this.bagValue.toJSON()
  10303. };
  10304. if (this.bagAttributes) {
  10305. output.bagAttributes = Array.from(this.bagAttributes, o => o.toJSON());
  10306. }
  10307. return output;
  10308. }
  10309. }
  10310. SafeBag.CLASS_NAME = "SafeBag";
  10311. const SAFE_BUGS = "safeBags";
  10312. class SafeContents extends PkiObject {
  10313. constructor(parameters = {}) {
  10314. super();
  10315. this.safeBags = pvutils__namespace.getParametersValue(parameters, SAFE_BUGS, SafeContents.defaultValues(SAFE_BUGS));
  10316. if (parameters.schema) {
  10317. this.fromSchema(parameters.schema);
  10318. }
  10319. }
  10320. static defaultValues(memberName) {
  10321. switch (memberName) {
  10322. case SAFE_BUGS:
  10323. return [];
  10324. default:
  10325. return super.defaultValues(memberName);
  10326. }
  10327. }
  10328. static compareWithDefault(memberName, memberValue) {
  10329. switch (memberName) {
  10330. case SAFE_BUGS:
  10331. return (memberValue.length === 0);
  10332. default:
  10333. return super.defaultValues(memberName);
  10334. }
  10335. }
  10336. static schema(parameters = {}) {
  10337. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10338. return (new asn1js__namespace.Sequence({
  10339. name: (names.blockName || EMPTY_STRING),
  10340. value: [
  10341. new asn1js__namespace.Repeated({
  10342. name: (names.safeBags || EMPTY_STRING),
  10343. value: SafeBag.schema()
  10344. })
  10345. ]
  10346. }));
  10347. }
  10348. fromSchema(schema) {
  10349. pvutils__namespace.clearProps(schema, [
  10350. SAFE_BUGS
  10351. ]);
  10352. const asn1 = asn1js__namespace.compareSchema(schema, schema, SafeContents.schema({
  10353. names: {
  10354. safeBags: SAFE_BUGS
  10355. }
  10356. }));
  10357. AsnError.assertSchema(asn1, this.className);
  10358. this.safeBags = Array.from(asn1.result.safeBags, element => new SafeBag({ schema: element }));
  10359. }
  10360. toSchema() {
  10361. return (new asn1js__namespace.Sequence({
  10362. value: Array.from(this.safeBags, o => o.toSchema())
  10363. }));
  10364. }
  10365. toJSON() {
  10366. return {
  10367. safeBags: Array.from(this.safeBags, o => o.toJSON())
  10368. };
  10369. }
  10370. }
  10371. SafeContents.CLASS_NAME = "SafeContents";
  10372. const OTHER_CERT_FORMAT = "otherCertFormat";
  10373. const OTHER_CERT = "otherCert";
  10374. const CLEAR_PROPS$H = [
  10375. OTHER_CERT_FORMAT,
  10376. OTHER_CERT
  10377. ];
  10378. class OtherCertificateFormat extends PkiObject {
  10379. constructor(parameters = {}) {
  10380. super();
  10381. this.otherCertFormat = pvutils__namespace.getParametersValue(parameters, OTHER_CERT_FORMAT, OtherCertificateFormat.defaultValues(OTHER_CERT_FORMAT));
  10382. this.otherCert = pvutils__namespace.getParametersValue(parameters, OTHER_CERT, OtherCertificateFormat.defaultValues(OTHER_CERT));
  10383. if (parameters.schema) {
  10384. this.fromSchema(parameters.schema);
  10385. }
  10386. }
  10387. static defaultValues(memberName) {
  10388. switch (memberName) {
  10389. case OTHER_CERT_FORMAT:
  10390. return EMPTY_STRING;
  10391. case OTHER_CERT:
  10392. return new asn1js__namespace.Any();
  10393. default:
  10394. return super.defaultValues(memberName);
  10395. }
  10396. }
  10397. static schema(parameters = {}) {
  10398. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10399. return (new asn1js__namespace.Sequence({
  10400. name: (names.blockName || EMPTY_STRING),
  10401. value: [
  10402. new asn1js__namespace.ObjectIdentifier({ name: (names.otherCertFormat || OTHER_CERT_FORMAT) }),
  10403. new asn1js__namespace.Any({ name: (names.otherCert || OTHER_CERT) })
  10404. ]
  10405. }));
  10406. }
  10407. fromSchema(schema) {
  10408. pvutils__namespace.clearProps(schema, CLEAR_PROPS$H);
  10409. const asn1 = asn1js__namespace.compareSchema(schema, schema, OtherCertificateFormat.schema());
  10410. AsnError.assertSchema(asn1, this.className);
  10411. this.otherCertFormat = asn1.result.otherCertFormat.valueBlock.toString();
  10412. this.otherCert = asn1.result.otherCert;
  10413. }
  10414. toSchema() {
  10415. return (new asn1js__namespace.Sequence({
  10416. value: [
  10417. new asn1js__namespace.ObjectIdentifier({ value: this.otherCertFormat }),
  10418. this.otherCert
  10419. ]
  10420. }));
  10421. }
  10422. toJSON() {
  10423. const res = {
  10424. otherCertFormat: this.otherCertFormat
  10425. };
  10426. if (!(this.otherCert instanceof asn1js__namespace.Any)) {
  10427. res.otherCert = this.otherCert.toJSON();
  10428. }
  10429. return res;
  10430. }
  10431. }
  10432. const CERTIFICATES$1 = "certificates";
  10433. const CLEAR_PROPS$G = [
  10434. CERTIFICATES$1,
  10435. ];
  10436. class CertificateSet extends PkiObject {
  10437. constructor(parameters = {}) {
  10438. super();
  10439. this.certificates = pvutils__namespace.getParametersValue(parameters, CERTIFICATES$1, CertificateSet.defaultValues(CERTIFICATES$1));
  10440. if (parameters.schema) {
  10441. this.fromSchema(parameters.schema);
  10442. }
  10443. }
  10444. static defaultValues(memberName) {
  10445. switch (memberName) {
  10446. case CERTIFICATES$1:
  10447. return [];
  10448. default:
  10449. return super.defaultValues(memberName);
  10450. }
  10451. }
  10452. static schema(parameters = {}) {
  10453. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10454. return (new asn1js__namespace.Set({
  10455. name: (names.blockName || EMPTY_STRING),
  10456. value: [
  10457. new asn1js__namespace.Repeated({
  10458. name: (names.certificates || CERTIFICATES$1),
  10459. value: new asn1js__namespace.Choice({
  10460. value: [
  10461. Certificate.schema(),
  10462. new asn1js__namespace.Constructed({
  10463. idBlock: {
  10464. tagClass: 3,
  10465. tagNumber: 0
  10466. },
  10467. value: [
  10468. new asn1js__namespace.Any()
  10469. ]
  10470. }),
  10471. new asn1js__namespace.Constructed({
  10472. idBlock: {
  10473. tagClass: 3,
  10474. tagNumber: 1
  10475. },
  10476. value: [
  10477. new asn1js__namespace.Sequence
  10478. ]
  10479. }),
  10480. new asn1js__namespace.Constructed({
  10481. idBlock: {
  10482. tagClass: 3,
  10483. tagNumber: 2
  10484. },
  10485. value: AttributeCertificateV2.schema().valueBlock.value
  10486. }),
  10487. new asn1js__namespace.Constructed({
  10488. idBlock: {
  10489. tagClass: 3,
  10490. tagNumber: 3
  10491. },
  10492. value: OtherCertificateFormat.schema().valueBlock.value
  10493. })
  10494. ]
  10495. })
  10496. })
  10497. ]
  10498. }));
  10499. }
  10500. fromSchema(schema) {
  10501. pvutils__namespace.clearProps(schema, CLEAR_PROPS$G);
  10502. const asn1 = asn1js__namespace.compareSchema(schema, schema, CertificateSet.schema());
  10503. AsnError.assertSchema(asn1, this.className);
  10504. this.certificates = Array.from(asn1.result.certificates || [], (element) => {
  10505. const initialTagNumber = element.idBlock.tagNumber;
  10506. if (element.idBlock.tagClass === 1)
  10507. return new Certificate({ schema: element });
  10508. const elementSequence = new asn1js__namespace.Sequence({
  10509. value: element.valueBlock.value
  10510. });
  10511. switch (initialTagNumber) {
  10512. case 1:
  10513. if (elementSequence.valueBlock.value[0].valueBlock.value[0].valueBlock.valueDec === 1) {
  10514. return new AttributeCertificateV2({ schema: elementSequence });
  10515. }
  10516. else {
  10517. return new AttributeCertificateV1({ schema: elementSequence });
  10518. }
  10519. case 2:
  10520. return new AttributeCertificateV2({ schema: elementSequence });
  10521. case 3:
  10522. return new OtherCertificateFormat({ schema: elementSequence });
  10523. }
  10524. return element;
  10525. });
  10526. }
  10527. toSchema() {
  10528. return (new asn1js__namespace.Set({
  10529. value: Array.from(this.certificates, element => {
  10530. switch (true) {
  10531. case (element instanceof Certificate):
  10532. return element.toSchema();
  10533. case (element instanceof AttributeCertificateV1):
  10534. return new asn1js__namespace.Constructed({
  10535. idBlock: {
  10536. tagClass: 3,
  10537. tagNumber: 1
  10538. },
  10539. value: element.toSchema().valueBlock.value
  10540. });
  10541. case (element instanceof AttributeCertificateV2):
  10542. return new asn1js__namespace.Constructed({
  10543. idBlock: {
  10544. tagClass: 3,
  10545. tagNumber: 2
  10546. },
  10547. value: element.toSchema().valueBlock.value
  10548. });
  10549. case (element instanceof OtherCertificateFormat):
  10550. return new asn1js__namespace.Constructed({
  10551. idBlock: {
  10552. tagClass: 3,
  10553. tagNumber: 3
  10554. },
  10555. value: element.toSchema().valueBlock.value
  10556. });
  10557. }
  10558. return element.toSchema();
  10559. })
  10560. }));
  10561. }
  10562. toJSON() {
  10563. return {
  10564. certificates: Array.from(this.certificates, o => o.toJSON())
  10565. };
  10566. }
  10567. }
  10568. CertificateSet.CLASS_NAME = "CertificateSet";
  10569. const OTHER_REV_INFO_FORMAT = "otherRevInfoFormat";
  10570. const OTHER_REV_INFO = "otherRevInfo";
  10571. const CLEAR_PROPS$F = [
  10572. OTHER_REV_INFO_FORMAT,
  10573. OTHER_REV_INFO
  10574. ];
  10575. class OtherRevocationInfoFormat extends PkiObject {
  10576. constructor(parameters = {}) {
  10577. super();
  10578. this.otherRevInfoFormat = pvutils__namespace.getParametersValue(parameters, OTHER_REV_INFO_FORMAT, OtherRevocationInfoFormat.defaultValues(OTHER_REV_INFO_FORMAT));
  10579. this.otherRevInfo = pvutils__namespace.getParametersValue(parameters, OTHER_REV_INFO, OtherRevocationInfoFormat.defaultValues(OTHER_REV_INFO));
  10580. if (parameters.schema) {
  10581. this.fromSchema(parameters.schema);
  10582. }
  10583. }
  10584. static defaultValues(memberName) {
  10585. switch (memberName) {
  10586. case OTHER_REV_INFO_FORMAT:
  10587. return EMPTY_STRING;
  10588. case OTHER_REV_INFO:
  10589. return new asn1js__namespace.Any();
  10590. default:
  10591. return super.defaultValues(memberName);
  10592. }
  10593. }
  10594. static schema(parameters = {}) {
  10595. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10596. return (new asn1js__namespace.Sequence({
  10597. name: (names.blockName || EMPTY_STRING),
  10598. value: [
  10599. new asn1js__namespace.ObjectIdentifier({ name: (names.otherRevInfoFormat || OTHER_REV_INFO_FORMAT) }),
  10600. new asn1js__namespace.Any({ name: (names.otherRevInfo || OTHER_REV_INFO) })
  10601. ]
  10602. }));
  10603. }
  10604. fromSchema(schema) {
  10605. pvutils__namespace.clearProps(schema, CLEAR_PROPS$F);
  10606. const asn1 = asn1js__namespace.compareSchema(schema, schema, OtherRevocationInfoFormat.schema());
  10607. AsnError.assertSchema(asn1, this.className);
  10608. this.otherRevInfoFormat = asn1.result.otherRevInfoFormat.valueBlock.toString();
  10609. this.otherRevInfo = asn1.result.otherRevInfo;
  10610. }
  10611. toSchema() {
  10612. return (new asn1js__namespace.Sequence({
  10613. value: [
  10614. new asn1js__namespace.ObjectIdentifier({ value: this.otherRevInfoFormat }),
  10615. this.otherRevInfo
  10616. ]
  10617. }));
  10618. }
  10619. toJSON() {
  10620. const res = {
  10621. otherRevInfoFormat: this.otherRevInfoFormat
  10622. };
  10623. if (!(this.otherRevInfo instanceof asn1js__namespace.Any)) {
  10624. res.otherRevInfo = this.otherRevInfo.toJSON();
  10625. }
  10626. return res;
  10627. }
  10628. }
  10629. OtherRevocationInfoFormat.CLASS_NAME = "OtherRevocationInfoFormat";
  10630. const CRLS$3 = "crls";
  10631. const OTHER_REVOCATION_INFOS = "otherRevocationInfos";
  10632. const CLEAR_PROPS$E = [
  10633. CRLS$3
  10634. ];
  10635. class RevocationInfoChoices extends PkiObject {
  10636. constructor(parameters = {}) {
  10637. super();
  10638. this.crls = pvutils__namespace.getParametersValue(parameters, CRLS$3, RevocationInfoChoices.defaultValues(CRLS$3));
  10639. this.otherRevocationInfos = pvutils__namespace.getParametersValue(parameters, OTHER_REVOCATION_INFOS, RevocationInfoChoices.defaultValues(OTHER_REVOCATION_INFOS));
  10640. if (parameters.schema) {
  10641. this.fromSchema(parameters.schema);
  10642. }
  10643. }
  10644. static defaultValues(memberName) {
  10645. switch (memberName) {
  10646. case CRLS$3:
  10647. return [];
  10648. case OTHER_REVOCATION_INFOS:
  10649. return [];
  10650. default:
  10651. return super.defaultValues(memberName);
  10652. }
  10653. }
  10654. static schema(parameters = {}) {
  10655. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10656. return (new asn1js__namespace.Set({
  10657. name: (names.blockName || EMPTY_STRING),
  10658. value: [
  10659. new asn1js__namespace.Repeated({
  10660. name: (names.crls || EMPTY_STRING),
  10661. value: new asn1js__namespace.Choice({
  10662. value: [
  10663. CertificateRevocationList.schema(),
  10664. new asn1js__namespace.Constructed({
  10665. idBlock: {
  10666. tagClass: 3,
  10667. tagNumber: 1
  10668. },
  10669. value: [
  10670. new asn1js__namespace.ObjectIdentifier(),
  10671. new asn1js__namespace.Any()
  10672. ]
  10673. })
  10674. ]
  10675. })
  10676. })
  10677. ]
  10678. }));
  10679. }
  10680. fromSchema(schema) {
  10681. pvutils__namespace.clearProps(schema, CLEAR_PROPS$E);
  10682. const asn1 = asn1js__namespace.compareSchema(schema, schema, RevocationInfoChoices.schema({
  10683. names: {
  10684. crls: CRLS$3
  10685. }
  10686. }));
  10687. AsnError.assertSchema(asn1, this.className);
  10688. if (asn1.result.crls) {
  10689. for (const element of asn1.result.crls) {
  10690. if (element.idBlock.tagClass === 1)
  10691. this.crls.push(new CertificateRevocationList({ schema: element }));
  10692. else
  10693. this.otherRevocationInfos.push(new OtherRevocationInfoFormat({ schema: element }));
  10694. }
  10695. }
  10696. }
  10697. toSchema() {
  10698. const outputArray = [];
  10699. outputArray.push(...Array.from(this.crls, o => o.toSchema()));
  10700. outputArray.push(...Array.from(this.otherRevocationInfos, element => {
  10701. const schema = element.toSchema();
  10702. schema.idBlock.tagClass = 3;
  10703. schema.idBlock.tagNumber = 1;
  10704. return schema;
  10705. }));
  10706. return (new asn1js__namespace.Set({
  10707. value: outputArray
  10708. }));
  10709. }
  10710. toJSON() {
  10711. return {
  10712. crls: Array.from(this.crls, o => o.toJSON()),
  10713. otherRevocationInfos: Array.from(this.otherRevocationInfos, o => o.toJSON())
  10714. };
  10715. }
  10716. }
  10717. RevocationInfoChoices.CLASS_NAME = "RevocationInfoChoices";
  10718. const CERTS$3 = "certs";
  10719. const CRLS$2 = "crls";
  10720. const CLEAR_PROPS$D = [
  10721. CERTS$3,
  10722. CRLS$2,
  10723. ];
  10724. class OriginatorInfo extends PkiObject {
  10725. constructor(parameters = {}) {
  10726. super();
  10727. this.crls = pvutils__namespace.getParametersValue(parameters, CRLS$2, OriginatorInfo.defaultValues(CRLS$2));
  10728. if (parameters.schema) {
  10729. this.fromSchema(parameters.schema);
  10730. }
  10731. }
  10732. static defaultValues(memberName) {
  10733. switch (memberName) {
  10734. case CERTS$3:
  10735. return new CertificateSet();
  10736. case CRLS$2:
  10737. return new RevocationInfoChoices();
  10738. default:
  10739. return super.defaultValues(memberName);
  10740. }
  10741. }
  10742. static compareWithDefault(memberName, memberValue) {
  10743. switch (memberName) {
  10744. case CERTS$3:
  10745. return (memberValue.certificates.length === 0);
  10746. case CRLS$2:
  10747. return ((memberValue.crls.length === 0) && (memberValue.otherRevocationInfos.length === 0));
  10748. default:
  10749. return super.defaultValues(memberName);
  10750. }
  10751. }
  10752. static schema(parameters = {}) {
  10753. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10754. return (new asn1js__namespace.Sequence({
  10755. name: (names.blockName || EMPTY_STRING),
  10756. value: [
  10757. new asn1js__namespace.Constructed({
  10758. name: (names.certs || EMPTY_STRING),
  10759. optional: true,
  10760. idBlock: {
  10761. tagClass: 3,
  10762. tagNumber: 0
  10763. },
  10764. value: CertificateSet.schema().valueBlock.value
  10765. }),
  10766. new asn1js__namespace.Constructed({
  10767. name: (names.crls || EMPTY_STRING),
  10768. optional: true,
  10769. idBlock: {
  10770. tagClass: 3,
  10771. tagNumber: 1
  10772. },
  10773. value: RevocationInfoChoices.schema().valueBlock.value
  10774. })
  10775. ]
  10776. }));
  10777. }
  10778. fromSchema(schema) {
  10779. pvutils__namespace.clearProps(schema, CLEAR_PROPS$D);
  10780. const asn1 = asn1js__namespace.compareSchema(schema, schema, OriginatorInfo.schema({
  10781. names: {
  10782. certs: CERTS$3,
  10783. crls: CRLS$2
  10784. }
  10785. }));
  10786. AsnError.assertSchema(asn1, this.className);
  10787. if (CERTS$3 in asn1.result) {
  10788. this.certs = new CertificateSet({
  10789. schema: new asn1js__namespace.Set({
  10790. value: asn1.result.certs.valueBlock.value
  10791. })
  10792. });
  10793. }
  10794. if (CRLS$2 in asn1.result) {
  10795. this.crls = new RevocationInfoChoices({
  10796. schema: new asn1js__namespace.Set({
  10797. value: asn1.result.crls.valueBlock.value
  10798. })
  10799. });
  10800. }
  10801. }
  10802. toSchema() {
  10803. const sequenceValue = [];
  10804. if (this.certs) {
  10805. sequenceValue.push(new asn1js__namespace.Constructed({
  10806. idBlock: {
  10807. tagClass: 3,
  10808. tagNumber: 0
  10809. },
  10810. value: this.certs.toSchema().valueBlock.value
  10811. }));
  10812. }
  10813. if (this.crls) {
  10814. sequenceValue.push(new asn1js__namespace.Constructed({
  10815. idBlock: {
  10816. tagClass: 3,
  10817. tagNumber: 1
  10818. },
  10819. value: this.crls.toSchema().valueBlock.value
  10820. }));
  10821. }
  10822. return (new asn1js__namespace.Sequence({
  10823. value: sequenceValue
  10824. }));
  10825. }
  10826. toJSON() {
  10827. const res = {};
  10828. if (this.certs) {
  10829. res.certs = this.certs.toJSON();
  10830. }
  10831. if (this.crls) {
  10832. res.crls = this.crls.toJSON();
  10833. }
  10834. return res;
  10835. }
  10836. }
  10837. OriginatorInfo.CLASS_NAME = "OriginatorInfo";
  10838. const ISSUER = "issuer";
  10839. const SERIAL_NUMBER$2 = "serialNumber";
  10840. const CLEAR_PROPS$C = [
  10841. ISSUER,
  10842. SERIAL_NUMBER$2,
  10843. ];
  10844. class IssuerAndSerialNumber extends PkiObject {
  10845. constructor(parameters = {}) {
  10846. super();
  10847. this.issuer = pvutils__namespace.getParametersValue(parameters, ISSUER, IssuerAndSerialNumber.defaultValues(ISSUER));
  10848. this.serialNumber = pvutils__namespace.getParametersValue(parameters, SERIAL_NUMBER$2, IssuerAndSerialNumber.defaultValues(SERIAL_NUMBER$2));
  10849. if (parameters.schema) {
  10850. this.fromSchema(parameters.schema);
  10851. }
  10852. }
  10853. static defaultValues(memberName) {
  10854. switch (memberName) {
  10855. case ISSUER:
  10856. return new RelativeDistinguishedNames();
  10857. case SERIAL_NUMBER$2:
  10858. return new asn1js__namespace.Integer();
  10859. default:
  10860. return super.defaultValues(memberName);
  10861. }
  10862. }
  10863. static schema(parameters = {}) {
  10864. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10865. return (new asn1js__namespace.Sequence({
  10866. name: (names.blockName || EMPTY_STRING),
  10867. value: [
  10868. RelativeDistinguishedNames.schema(names.issuer || {}),
  10869. new asn1js__namespace.Integer({ name: (names.serialNumber || EMPTY_STRING) })
  10870. ]
  10871. }));
  10872. }
  10873. fromSchema(schema) {
  10874. pvutils__namespace.clearProps(schema, CLEAR_PROPS$C);
  10875. const asn1 = asn1js__namespace.compareSchema(schema, schema, IssuerAndSerialNumber.schema({
  10876. names: {
  10877. issuer: {
  10878. names: {
  10879. blockName: ISSUER
  10880. }
  10881. },
  10882. serialNumber: SERIAL_NUMBER$2
  10883. }
  10884. }));
  10885. AsnError.assertSchema(asn1, this.className);
  10886. this.issuer = new RelativeDistinguishedNames({ schema: asn1.result.issuer });
  10887. this.serialNumber = asn1.result.serialNumber;
  10888. }
  10889. toSchema() {
  10890. return (new asn1js__namespace.Sequence({
  10891. value: [
  10892. this.issuer.toSchema(),
  10893. this.serialNumber
  10894. ]
  10895. }));
  10896. }
  10897. toJSON() {
  10898. return {
  10899. issuer: this.issuer.toJSON(),
  10900. serialNumber: this.serialNumber.toJSON(),
  10901. };
  10902. }
  10903. }
  10904. IssuerAndSerialNumber.CLASS_NAME = "IssuerAndSerialNumber";
  10905. const VARIANT$3 = "variant";
  10906. const VALUE$3 = "value";
  10907. const CLEAR_PROPS$B = [
  10908. "blockName"
  10909. ];
  10910. class RecipientIdentifier extends PkiObject {
  10911. constructor(parameters = {}) {
  10912. super();
  10913. this.variant = pvutils__namespace.getParametersValue(parameters, VARIANT$3, RecipientIdentifier.defaultValues(VARIANT$3));
  10914. if (VALUE$3 in parameters) {
  10915. this.value = pvutils__namespace.getParametersValue(parameters, VALUE$3, RecipientIdentifier.defaultValues(VALUE$3));
  10916. }
  10917. if (parameters.schema) {
  10918. this.fromSchema(parameters.schema);
  10919. }
  10920. }
  10921. static defaultValues(memberName) {
  10922. switch (memberName) {
  10923. case VARIANT$3:
  10924. return (-1);
  10925. case VALUE$3:
  10926. return {};
  10927. default:
  10928. return super.defaultValues(memberName);
  10929. }
  10930. }
  10931. static compareWithDefault(memberName, memberValue) {
  10932. switch (memberName) {
  10933. case VARIANT$3:
  10934. return (memberValue === (-1));
  10935. case VALUE$3:
  10936. return (Object.keys(memberValue).length === 0);
  10937. default:
  10938. return super.defaultValues(memberName);
  10939. }
  10940. }
  10941. static schema(parameters = {}) {
  10942. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  10943. return (new asn1js__namespace.Choice({
  10944. value: [
  10945. IssuerAndSerialNumber.schema({
  10946. names: {
  10947. blockName: (names.blockName || EMPTY_STRING)
  10948. }
  10949. }),
  10950. new asn1js__namespace.Primitive({
  10951. name: (names.blockName || EMPTY_STRING),
  10952. idBlock: {
  10953. tagClass: 3,
  10954. tagNumber: 0
  10955. }
  10956. })
  10957. ]
  10958. }));
  10959. }
  10960. fromSchema(schema) {
  10961. pvutils__namespace.clearProps(schema, CLEAR_PROPS$B);
  10962. const asn1 = asn1js__namespace.compareSchema(schema, schema, RecipientIdentifier.schema({
  10963. names: {
  10964. blockName: "blockName"
  10965. }
  10966. }));
  10967. AsnError.assertSchema(asn1, this.className);
  10968. if (asn1.result.blockName.idBlock.tagClass === 1) {
  10969. this.variant = 1;
  10970. this.value = new IssuerAndSerialNumber({ schema: asn1.result.blockName });
  10971. }
  10972. else {
  10973. this.variant = 2;
  10974. this.value = new asn1js__namespace.OctetString({ valueHex: asn1.result.blockName.valueBlock.valueHex });
  10975. }
  10976. }
  10977. toSchema() {
  10978. switch (this.variant) {
  10979. case 1:
  10980. if (!(this.value instanceof IssuerAndSerialNumber)) {
  10981. throw new Error("Incorrect type of RecipientIdentifier.value. It should be IssuerAndSerialNumber.");
  10982. }
  10983. return this.value.toSchema();
  10984. case 2:
  10985. if (!(this.value instanceof asn1js__namespace.OctetString)) {
  10986. throw new Error("Incorrect type of RecipientIdentifier.value. It should be ASN.1 OctetString.");
  10987. }
  10988. return new asn1js__namespace.Primitive({
  10989. idBlock: {
  10990. tagClass: 3,
  10991. tagNumber: 0
  10992. },
  10993. valueHex: this.value.valueBlock.valueHexView
  10994. });
  10995. default:
  10996. return new asn1js__namespace.Any();
  10997. }
  10998. }
  10999. toJSON() {
  11000. const res = {
  11001. variant: this.variant
  11002. };
  11003. if ((this.variant === 1 || this.variant === 2) && this.value) {
  11004. res.value = this.value.toJSON();
  11005. }
  11006. return res;
  11007. }
  11008. }
  11009. RecipientIdentifier.CLASS_NAME = "RecipientIdentifier";
  11010. const VERSION$c = "version";
  11011. const RID$1 = "rid";
  11012. const KEY_ENCRYPTION_ALGORITHM$3 = "keyEncryptionAlgorithm";
  11013. const ENCRYPTED_KEY$3 = "encryptedKey";
  11014. const RECIPIENT_CERTIFICATE$1 = "recipientCertificate";
  11015. const CLEAR_PROPS$A = [
  11016. VERSION$c,
  11017. RID$1,
  11018. KEY_ENCRYPTION_ALGORITHM$3,
  11019. ENCRYPTED_KEY$3,
  11020. ];
  11021. class KeyTransRecipientInfo extends PkiObject {
  11022. constructor(parameters = {}) {
  11023. super();
  11024. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$c, KeyTransRecipientInfo.defaultValues(VERSION$c));
  11025. this.rid = pvutils__namespace.getParametersValue(parameters, RID$1, KeyTransRecipientInfo.defaultValues(RID$1));
  11026. this.keyEncryptionAlgorithm = pvutils__namespace.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM$3, KeyTransRecipientInfo.defaultValues(KEY_ENCRYPTION_ALGORITHM$3));
  11027. this.encryptedKey = pvutils__namespace.getParametersValue(parameters, ENCRYPTED_KEY$3, KeyTransRecipientInfo.defaultValues(ENCRYPTED_KEY$3));
  11028. this.recipientCertificate = pvutils__namespace.getParametersValue(parameters, RECIPIENT_CERTIFICATE$1, KeyTransRecipientInfo.defaultValues(RECIPIENT_CERTIFICATE$1));
  11029. if (parameters.schema) {
  11030. this.fromSchema(parameters.schema);
  11031. }
  11032. }
  11033. static defaultValues(memberName) {
  11034. switch (memberName) {
  11035. case VERSION$c:
  11036. return (-1);
  11037. case RID$1:
  11038. return {};
  11039. case KEY_ENCRYPTION_ALGORITHM$3:
  11040. return new AlgorithmIdentifier();
  11041. case ENCRYPTED_KEY$3:
  11042. return new asn1js__namespace.OctetString();
  11043. case RECIPIENT_CERTIFICATE$1:
  11044. return new Certificate();
  11045. default:
  11046. return super.defaultValues(memberName);
  11047. }
  11048. }
  11049. static compareWithDefault(memberName, memberValue) {
  11050. switch (memberName) {
  11051. case VERSION$c:
  11052. return (memberValue === KeyTransRecipientInfo.defaultValues(VERSION$c));
  11053. case RID$1:
  11054. return (Object.keys(memberValue).length === 0);
  11055. case KEY_ENCRYPTION_ALGORITHM$3:
  11056. case ENCRYPTED_KEY$3:
  11057. return memberValue.isEqual(KeyTransRecipientInfo.defaultValues(memberName));
  11058. case RECIPIENT_CERTIFICATE$1:
  11059. return false;
  11060. default:
  11061. return super.defaultValues(memberName);
  11062. }
  11063. }
  11064. static schema(parameters = {}) {
  11065. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  11066. return (new asn1js__namespace.Sequence({
  11067. name: (names.blockName || EMPTY_STRING),
  11068. value: [
  11069. new asn1js__namespace.Integer({ name: (names.version || EMPTY_STRING) }),
  11070. RecipientIdentifier.schema(names.rid || {}),
  11071. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  11072. new asn1js__namespace.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  11073. ]
  11074. }));
  11075. }
  11076. fromSchema(schema) {
  11077. pvutils__namespace.clearProps(schema, CLEAR_PROPS$A);
  11078. const asn1 = asn1js__namespace.compareSchema(schema, schema, KeyTransRecipientInfo.schema({
  11079. names: {
  11080. version: VERSION$c,
  11081. rid: {
  11082. names: {
  11083. blockName: RID$1
  11084. }
  11085. },
  11086. keyEncryptionAlgorithm: {
  11087. names: {
  11088. blockName: KEY_ENCRYPTION_ALGORITHM$3
  11089. }
  11090. },
  11091. encryptedKey: ENCRYPTED_KEY$3
  11092. }
  11093. }));
  11094. AsnError.assertSchema(asn1, this.className);
  11095. this.version = asn1.result.version.valueBlock.valueDec;
  11096. if (asn1.result.rid.idBlock.tagClass === 3) {
  11097. this.rid = new asn1js__namespace.OctetString({ valueHex: asn1.result.rid.valueBlock.valueHex });
  11098. }
  11099. else {
  11100. this.rid = new IssuerAndSerialNumber({ schema: asn1.result.rid });
  11101. }
  11102. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  11103. this.encryptedKey = asn1.result.encryptedKey;
  11104. }
  11105. toSchema() {
  11106. const outputArray = [];
  11107. if (this.rid instanceof IssuerAndSerialNumber) {
  11108. this.version = 0;
  11109. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  11110. outputArray.push(this.rid.toSchema());
  11111. }
  11112. else {
  11113. this.version = 2;
  11114. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  11115. outputArray.push(new asn1js__namespace.Primitive({
  11116. idBlock: {
  11117. tagClass: 3,
  11118. tagNumber: 0
  11119. },
  11120. valueHex: this.rid.valueBlock.valueHexView
  11121. }));
  11122. }
  11123. outputArray.push(this.keyEncryptionAlgorithm.toSchema());
  11124. outputArray.push(this.encryptedKey);
  11125. return (new asn1js__namespace.Sequence({
  11126. value: outputArray
  11127. }));
  11128. }
  11129. toJSON() {
  11130. return {
  11131. version: this.version,
  11132. rid: this.rid.toJSON(),
  11133. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  11134. encryptedKey: this.encryptedKey.toJSON(),
  11135. };
  11136. }
  11137. }
  11138. KeyTransRecipientInfo.CLASS_NAME = "KeyTransRecipientInfo";
  11139. const ALGORITHM = "algorithm";
  11140. const PUBLIC_KEY = "publicKey";
  11141. const CLEAR_PROPS$z = [
  11142. ALGORITHM,
  11143. PUBLIC_KEY
  11144. ];
  11145. class OriginatorPublicKey extends PkiObject {
  11146. constructor(parameters = {}) {
  11147. super();
  11148. this.algorithm = pvutils__namespace.getParametersValue(parameters, ALGORITHM, OriginatorPublicKey.defaultValues(ALGORITHM));
  11149. this.publicKey = pvutils__namespace.getParametersValue(parameters, PUBLIC_KEY, OriginatorPublicKey.defaultValues(PUBLIC_KEY));
  11150. if (parameters.schema) {
  11151. this.fromSchema(parameters.schema);
  11152. }
  11153. }
  11154. static defaultValues(memberName) {
  11155. switch (memberName) {
  11156. case ALGORITHM:
  11157. return new AlgorithmIdentifier();
  11158. case PUBLIC_KEY:
  11159. return new asn1js__namespace.BitString();
  11160. default:
  11161. return super.defaultValues(memberName);
  11162. }
  11163. }
  11164. static compareWithDefault(memberName, memberValue) {
  11165. switch (memberName) {
  11166. case ALGORITHM:
  11167. case PUBLIC_KEY:
  11168. return (memberValue.isEqual(OriginatorPublicKey.defaultValues(memberName)));
  11169. default:
  11170. return super.defaultValues(memberName);
  11171. }
  11172. }
  11173. static schema(parameters = {}) {
  11174. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  11175. return (new asn1js__namespace.Sequence({
  11176. name: (names.blockName || EMPTY_STRING),
  11177. value: [
  11178. AlgorithmIdentifier.schema(names.algorithm || {}),
  11179. new asn1js__namespace.BitString({ name: (names.publicKey || EMPTY_STRING) })
  11180. ]
  11181. }));
  11182. }
  11183. fromSchema(schema) {
  11184. pvutils__namespace.clearProps(schema, CLEAR_PROPS$z);
  11185. const asn1 = asn1js__namespace.compareSchema(schema, schema, OriginatorPublicKey.schema({
  11186. names: {
  11187. algorithm: {
  11188. names: {
  11189. blockName: ALGORITHM
  11190. }
  11191. },
  11192. publicKey: PUBLIC_KEY
  11193. }
  11194. }));
  11195. AsnError.assertSchema(asn1, this.className);
  11196. this.algorithm = new AlgorithmIdentifier({ schema: asn1.result.algorithm });
  11197. this.publicKey = asn1.result.publicKey;
  11198. }
  11199. toSchema() {
  11200. return (new asn1js__namespace.Sequence({
  11201. value: [
  11202. this.algorithm.toSchema(),
  11203. this.publicKey
  11204. ]
  11205. }));
  11206. }
  11207. toJSON() {
  11208. return {
  11209. algorithm: this.algorithm.toJSON(),
  11210. publicKey: this.publicKey.toJSON(),
  11211. };
  11212. }
  11213. }
  11214. OriginatorPublicKey.CLASS_NAME = "OriginatorPublicKey";
  11215. const VARIANT$2 = "variant";
  11216. const VALUE$2 = "value";
  11217. const CLEAR_PROPS$y = [
  11218. "blockName",
  11219. ];
  11220. class OriginatorIdentifierOrKey extends PkiObject {
  11221. constructor(parameters = {}) {
  11222. super();
  11223. this.variant = pvutils__namespace.getParametersValue(parameters, VARIANT$2, OriginatorIdentifierOrKey.defaultValues(VARIANT$2));
  11224. if (VALUE$2 in parameters) {
  11225. this.value = pvutils__namespace.getParametersValue(parameters, VALUE$2, OriginatorIdentifierOrKey.defaultValues(VALUE$2));
  11226. }
  11227. if (parameters.schema) {
  11228. this.fromSchema(parameters.schema);
  11229. }
  11230. }
  11231. static defaultValues(memberName) {
  11232. switch (memberName) {
  11233. case VARIANT$2:
  11234. return (-1);
  11235. case VALUE$2:
  11236. return {};
  11237. default:
  11238. return super.defaultValues(memberName);
  11239. }
  11240. }
  11241. static compareWithDefault(memberName, memberValue) {
  11242. switch (memberName) {
  11243. case VARIANT$2:
  11244. return (memberValue === (-1));
  11245. case VALUE$2:
  11246. return (Object.keys(memberValue).length === 0);
  11247. default:
  11248. return super.defaultValues(memberName);
  11249. }
  11250. }
  11251. static schema(parameters = {}) {
  11252. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  11253. return (new asn1js__namespace.Choice({
  11254. value: [
  11255. IssuerAndSerialNumber.schema({
  11256. names: {
  11257. blockName: (names.blockName || EMPTY_STRING)
  11258. }
  11259. }),
  11260. new asn1js__namespace.Primitive({
  11261. idBlock: {
  11262. tagClass: 3,
  11263. tagNumber: 0
  11264. },
  11265. name: (names.blockName || EMPTY_STRING)
  11266. }),
  11267. new asn1js__namespace.Constructed({
  11268. idBlock: {
  11269. tagClass: 3,
  11270. tagNumber: 1
  11271. },
  11272. name: (names.blockName || EMPTY_STRING),
  11273. value: OriginatorPublicKey.schema().valueBlock.value
  11274. })
  11275. ]
  11276. }));
  11277. }
  11278. fromSchema(schema) {
  11279. pvutils__namespace.clearProps(schema, CLEAR_PROPS$y);
  11280. const asn1 = asn1js__namespace.compareSchema(schema, schema, OriginatorIdentifierOrKey.schema({
  11281. names: {
  11282. blockName: "blockName"
  11283. }
  11284. }));
  11285. AsnError.assertSchema(asn1, this.className);
  11286. if (asn1.result.blockName.idBlock.tagClass === 1) {
  11287. this.variant = 1;
  11288. this.value = new IssuerAndSerialNumber({ schema: asn1.result.blockName });
  11289. }
  11290. else {
  11291. if (asn1.result.blockName.idBlock.tagNumber === 0) {
  11292. asn1.result.blockName.idBlock.tagClass = 1;
  11293. asn1.result.blockName.idBlock.tagNumber = 4;
  11294. this.variant = 2;
  11295. this.value = asn1.result.blockName;
  11296. }
  11297. else {
  11298. this.variant = 3;
  11299. this.value = new OriginatorPublicKey({
  11300. schema: new asn1js__namespace.Sequence({
  11301. value: asn1.result.blockName.valueBlock.value
  11302. })
  11303. });
  11304. }
  11305. }
  11306. }
  11307. toSchema() {
  11308. switch (this.variant) {
  11309. case 1:
  11310. return this.value.toSchema();
  11311. case 2:
  11312. this.value.idBlock.tagClass = 3;
  11313. this.value.idBlock.tagNumber = 0;
  11314. return this.value;
  11315. case 3:
  11316. {
  11317. const _schema = this.value.toSchema();
  11318. _schema.idBlock.tagClass = 3;
  11319. _schema.idBlock.tagNumber = 1;
  11320. return _schema;
  11321. }
  11322. default:
  11323. return new asn1js__namespace.Any();
  11324. }
  11325. }
  11326. toJSON() {
  11327. const res = {
  11328. variant: this.variant
  11329. };
  11330. if ((this.variant === 1) || (this.variant === 2) || (this.variant === 3)) {
  11331. res.value = this.value.toJSON();
  11332. }
  11333. return res;
  11334. }
  11335. }
  11336. OriginatorIdentifierOrKey.CLASS_NAME = "OriginatorIdentifierOrKey";
  11337. const KEY_ATTR_ID = "keyAttrId";
  11338. const KEY_ATTR = "keyAttr";
  11339. const CLEAR_PROPS$x = [
  11340. KEY_ATTR_ID,
  11341. KEY_ATTR,
  11342. ];
  11343. class OtherKeyAttribute extends PkiObject {
  11344. constructor(parameters = {}) {
  11345. super();
  11346. this.keyAttrId = pvutils__namespace.getParametersValue(parameters, KEY_ATTR_ID, OtherKeyAttribute.defaultValues(KEY_ATTR_ID));
  11347. if (KEY_ATTR in parameters) {
  11348. this.keyAttr = pvutils__namespace.getParametersValue(parameters, KEY_ATTR, OtherKeyAttribute.defaultValues(KEY_ATTR));
  11349. }
  11350. if (parameters.schema) {
  11351. this.fromSchema(parameters.schema);
  11352. }
  11353. }
  11354. static defaultValues(memberName) {
  11355. switch (memberName) {
  11356. case KEY_ATTR_ID:
  11357. return EMPTY_STRING;
  11358. case KEY_ATTR:
  11359. return {};
  11360. default:
  11361. return super.defaultValues(memberName);
  11362. }
  11363. }
  11364. static compareWithDefault(memberName, memberValue) {
  11365. switch (memberName) {
  11366. case KEY_ATTR_ID:
  11367. return (typeof memberValue === "string" && memberValue === EMPTY_STRING);
  11368. case KEY_ATTR:
  11369. return (Object.keys(memberValue).length === 0);
  11370. default:
  11371. return super.defaultValues(memberName);
  11372. }
  11373. }
  11374. static schema(parameters = {}) {
  11375. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  11376. return (new asn1js__namespace.Sequence({
  11377. optional: (names.optional || true),
  11378. name: (names.blockName || EMPTY_STRING),
  11379. value: [
  11380. new asn1js__namespace.ObjectIdentifier({ name: (names.keyAttrId || EMPTY_STRING) }),
  11381. new asn1js__namespace.Any({
  11382. optional: true,
  11383. name: (names.keyAttr || EMPTY_STRING)
  11384. })
  11385. ]
  11386. }));
  11387. }
  11388. fromSchema(schema) {
  11389. pvutils__namespace.clearProps(schema, CLEAR_PROPS$x);
  11390. const asn1 = asn1js__namespace.compareSchema(schema, schema, OtherKeyAttribute.schema({
  11391. names: {
  11392. keyAttrId: KEY_ATTR_ID,
  11393. keyAttr: KEY_ATTR
  11394. }
  11395. }));
  11396. AsnError.assertSchema(asn1, this.className);
  11397. this.keyAttrId = asn1.result.keyAttrId.valueBlock.toString();
  11398. if (KEY_ATTR in asn1.result) {
  11399. this.keyAttr = asn1.result.keyAttr;
  11400. }
  11401. }
  11402. toSchema() {
  11403. const outputArray = [];
  11404. outputArray.push(new asn1js__namespace.ObjectIdentifier({ value: this.keyAttrId }));
  11405. if (KEY_ATTR in this) {
  11406. outputArray.push(this.keyAttr);
  11407. }
  11408. return (new asn1js__namespace.Sequence({
  11409. value: outputArray,
  11410. }));
  11411. }
  11412. toJSON() {
  11413. const res = {
  11414. keyAttrId: this.keyAttrId
  11415. };
  11416. if (KEY_ATTR in this) {
  11417. res.keyAttr = this.keyAttr.toJSON();
  11418. }
  11419. return res;
  11420. }
  11421. }
  11422. OtherKeyAttribute.CLASS_NAME = "OtherKeyAttribute";
  11423. const SUBJECT_KEY_IDENTIFIER = "subjectKeyIdentifier";
  11424. const DATE$1 = "date";
  11425. const OTHER$1 = "other";
  11426. const CLEAR_PROPS$w = [
  11427. SUBJECT_KEY_IDENTIFIER,
  11428. DATE$1,
  11429. OTHER$1,
  11430. ];
  11431. class RecipientKeyIdentifier extends PkiObject {
  11432. constructor(parameters = {}) {
  11433. super();
  11434. this.subjectKeyIdentifier = pvutils__namespace.getParametersValue(parameters, SUBJECT_KEY_IDENTIFIER, RecipientKeyIdentifier.defaultValues(SUBJECT_KEY_IDENTIFIER));
  11435. if (DATE$1 in parameters) {
  11436. this.date = pvutils__namespace.getParametersValue(parameters, DATE$1, RecipientKeyIdentifier.defaultValues(DATE$1));
  11437. }
  11438. if (OTHER$1 in parameters) {
  11439. this.other = pvutils__namespace.getParametersValue(parameters, OTHER$1, RecipientKeyIdentifier.defaultValues(OTHER$1));
  11440. }
  11441. if (parameters.schema) {
  11442. this.fromSchema(parameters.schema);
  11443. }
  11444. }
  11445. static defaultValues(memberName) {
  11446. switch (memberName) {
  11447. case SUBJECT_KEY_IDENTIFIER:
  11448. return new asn1js__namespace.OctetString();
  11449. case DATE$1:
  11450. return new asn1js__namespace.GeneralizedTime();
  11451. case OTHER$1:
  11452. return new OtherKeyAttribute();
  11453. default:
  11454. return super.defaultValues(memberName);
  11455. }
  11456. }
  11457. static compareWithDefault(memberName, memberValue) {
  11458. switch (memberName) {
  11459. case SUBJECT_KEY_IDENTIFIER:
  11460. return (memberValue.isEqual(RecipientKeyIdentifier.defaultValues(SUBJECT_KEY_IDENTIFIER)));
  11461. case DATE$1:
  11462. return ((memberValue.year === 0) &&
  11463. (memberValue.month === 0) &&
  11464. (memberValue.day === 0) &&
  11465. (memberValue.hour === 0) &&
  11466. (memberValue.minute === 0) &&
  11467. (memberValue.second === 0) &&
  11468. (memberValue.millisecond === 0));
  11469. case OTHER$1:
  11470. return ((memberValue.keyAttrId === EMPTY_STRING) && (("keyAttr" in memberValue) === false));
  11471. default:
  11472. return super.defaultValues(memberName);
  11473. }
  11474. }
  11475. static schema(parameters = {}) {
  11476. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  11477. return (new asn1js__namespace.Sequence({
  11478. name: (names.blockName || EMPTY_STRING),
  11479. value: [
  11480. new asn1js__namespace.OctetString({ name: (names.subjectKeyIdentifier || EMPTY_STRING) }),
  11481. new asn1js__namespace.GeneralizedTime({
  11482. optional: true,
  11483. name: (names.date || EMPTY_STRING)
  11484. }),
  11485. OtherKeyAttribute.schema(names.other || {})
  11486. ]
  11487. }));
  11488. }
  11489. fromSchema(schema) {
  11490. pvutils__namespace.clearProps(schema, CLEAR_PROPS$w);
  11491. const asn1 = asn1js__namespace.compareSchema(schema, schema, RecipientKeyIdentifier.schema({
  11492. names: {
  11493. subjectKeyIdentifier: SUBJECT_KEY_IDENTIFIER,
  11494. date: DATE$1,
  11495. other: {
  11496. names: {
  11497. blockName: OTHER$1
  11498. }
  11499. }
  11500. }
  11501. }));
  11502. AsnError.assertSchema(asn1, this.className);
  11503. this.subjectKeyIdentifier = asn1.result.subjectKeyIdentifier;
  11504. if (DATE$1 in asn1.result)
  11505. this.date = asn1.result.date;
  11506. if (OTHER$1 in asn1.result)
  11507. this.other = new OtherKeyAttribute({ schema: asn1.result.other });
  11508. }
  11509. toSchema() {
  11510. const outputArray = [];
  11511. outputArray.push(this.subjectKeyIdentifier);
  11512. if (this.date) {
  11513. outputArray.push(this.date);
  11514. }
  11515. if (this.other) {
  11516. outputArray.push(this.other.toSchema());
  11517. }
  11518. return (new asn1js__namespace.Sequence({
  11519. value: outputArray
  11520. }));
  11521. }
  11522. toJSON() {
  11523. const res = {
  11524. subjectKeyIdentifier: this.subjectKeyIdentifier.toJSON()
  11525. };
  11526. if (this.date) {
  11527. res.date = this.date.toJSON();
  11528. }
  11529. if (this.other) {
  11530. res.other = this.other.toJSON();
  11531. }
  11532. return res;
  11533. }
  11534. }
  11535. RecipientKeyIdentifier.CLASS_NAME = "RecipientKeyIdentifier";
  11536. const VARIANT$1 = "variant";
  11537. const VALUE$1 = "value";
  11538. const CLEAR_PROPS$v = [
  11539. "blockName",
  11540. ];
  11541. class KeyAgreeRecipientIdentifier extends PkiObject {
  11542. constructor(parameters = {}) {
  11543. super();
  11544. this.variant = pvutils__namespace.getParametersValue(parameters, VARIANT$1, KeyAgreeRecipientIdentifier.defaultValues(VARIANT$1));
  11545. this.value = pvutils__namespace.getParametersValue(parameters, VALUE$1, KeyAgreeRecipientIdentifier.defaultValues(VALUE$1));
  11546. if (parameters.schema) {
  11547. this.fromSchema(parameters.schema);
  11548. }
  11549. }
  11550. static defaultValues(memberName) {
  11551. switch (memberName) {
  11552. case VARIANT$1:
  11553. return (-1);
  11554. case VALUE$1:
  11555. return {};
  11556. default:
  11557. return super.defaultValues(memberName);
  11558. }
  11559. }
  11560. static compareWithDefault(memberName, memberValue) {
  11561. switch (memberName) {
  11562. case VARIANT$1:
  11563. return (memberValue === (-1));
  11564. case VALUE$1:
  11565. return (Object.keys(memberValue).length === 0);
  11566. default:
  11567. return super.defaultValues(memberName);
  11568. }
  11569. }
  11570. static schema(parameters = {}) {
  11571. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  11572. return (new asn1js__namespace.Choice({
  11573. value: [
  11574. IssuerAndSerialNumber.schema(names.issuerAndSerialNumber || {
  11575. names: {
  11576. blockName: (names.blockName || EMPTY_STRING)
  11577. }
  11578. }),
  11579. new asn1js__namespace.Constructed({
  11580. name: (names.blockName || EMPTY_STRING),
  11581. idBlock: {
  11582. tagClass: 3,
  11583. tagNumber: 0
  11584. },
  11585. value: RecipientKeyIdentifier.schema(names.rKeyId || {
  11586. names: {
  11587. blockName: (names.blockName || EMPTY_STRING)
  11588. }
  11589. }).valueBlock.value
  11590. })
  11591. ]
  11592. }));
  11593. }
  11594. fromSchema(schema) {
  11595. pvutils__namespace.clearProps(schema, CLEAR_PROPS$v);
  11596. const asn1 = asn1js__namespace.compareSchema(schema, schema, KeyAgreeRecipientIdentifier.schema({
  11597. names: {
  11598. blockName: "blockName"
  11599. }
  11600. }));
  11601. AsnError.assertSchema(asn1, this.className);
  11602. if (asn1.result.blockName.idBlock.tagClass === 1) {
  11603. this.variant = 1;
  11604. this.value = new IssuerAndSerialNumber({ schema: asn1.result.blockName });
  11605. }
  11606. else {
  11607. this.variant = 2;
  11608. this.value = new RecipientKeyIdentifier({
  11609. schema: new asn1js__namespace.Sequence({
  11610. value: asn1.result.blockName.valueBlock.value
  11611. })
  11612. });
  11613. }
  11614. }
  11615. toSchema() {
  11616. switch (this.variant) {
  11617. case 1:
  11618. return this.value.toSchema();
  11619. case 2:
  11620. return new asn1js__namespace.Constructed({
  11621. idBlock: {
  11622. tagClass: 3,
  11623. tagNumber: 0
  11624. },
  11625. value: this.value.toSchema().valueBlock.value
  11626. });
  11627. default:
  11628. return new asn1js__namespace.Any();
  11629. }
  11630. }
  11631. toJSON() {
  11632. const res = {
  11633. variant: this.variant,
  11634. };
  11635. if ((this.variant === 1) || (this.variant === 2)) {
  11636. res.value = this.value.toJSON();
  11637. }
  11638. return res;
  11639. }
  11640. }
  11641. KeyAgreeRecipientIdentifier.CLASS_NAME = "KeyAgreeRecipientIdentifier";
  11642. const RID = "rid";
  11643. const ENCRYPTED_KEY$2 = "encryptedKey";
  11644. const CLEAR_PROPS$u = [
  11645. RID,
  11646. ENCRYPTED_KEY$2,
  11647. ];
  11648. class RecipientEncryptedKey extends PkiObject {
  11649. constructor(parameters = {}) {
  11650. super();
  11651. this.rid = pvutils__namespace.getParametersValue(parameters, RID, RecipientEncryptedKey.defaultValues(RID));
  11652. this.encryptedKey = pvutils__namespace.getParametersValue(parameters, ENCRYPTED_KEY$2, RecipientEncryptedKey.defaultValues(ENCRYPTED_KEY$2));
  11653. if (parameters.schema) {
  11654. this.fromSchema(parameters.schema);
  11655. }
  11656. }
  11657. static defaultValues(memberName) {
  11658. switch (memberName) {
  11659. case RID:
  11660. return new KeyAgreeRecipientIdentifier();
  11661. case ENCRYPTED_KEY$2:
  11662. return new asn1js__namespace.OctetString();
  11663. default:
  11664. return super.defaultValues(memberName);
  11665. }
  11666. }
  11667. static compareWithDefault(memberName, memberValue) {
  11668. switch (memberName) {
  11669. case RID:
  11670. return ((memberValue.variant === (-1)) && (("value" in memberValue) === false));
  11671. case ENCRYPTED_KEY$2:
  11672. return (memberValue.isEqual(RecipientEncryptedKey.defaultValues(ENCRYPTED_KEY$2)));
  11673. default:
  11674. return super.defaultValues(memberName);
  11675. }
  11676. }
  11677. static schema(parameters = {}) {
  11678. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  11679. return (new asn1js__namespace.Sequence({
  11680. name: (names.blockName || EMPTY_STRING),
  11681. value: [
  11682. KeyAgreeRecipientIdentifier.schema(names.rid || {}),
  11683. new asn1js__namespace.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  11684. ]
  11685. }));
  11686. }
  11687. fromSchema(schema) {
  11688. pvutils__namespace.clearProps(schema, CLEAR_PROPS$u);
  11689. const asn1 = asn1js__namespace.compareSchema(schema, schema, RecipientEncryptedKey.schema({
  11690. names: {
  11691. rid: {
  11692. names: {
  11693. blockName: RID
  11694. }
  11695. },
  11696. encryptedKey: ENCRYPTED_KEY$2
  11697. }
  11698. }));
  11699. AsnError.assertSchema(asn1, this.className);
  11700. this.rid = new KeyAgreeRecipientIdentifier({ schema: asn1.result.rid });
  11701. this.encryptedKey = asn1.result.encryptedKey;
  11702. }
  11703. toSchema() {
  11704. return (new asn1js__namespace.Sequence({
  11705. value: [
  11706. this.rid.toSchema(),
  11707. this.encryptedKey
  11708. ]
  11709. }));
  11710. }
  11711. toJSON() {
  11712. return {
  11713. rid: this.rid.toJSON(),
  11714. encryptedKey: this.encryptedKey.toJSON(),
  11715. };
  11716. }
  11717. }
  11718. RecipientEncryptedKey.CLASS_NAME = "RecipientEncryptedKey";
  11719. const ENCRYPTED_KEYS = "encryptedKeys";
  11720. const RECIPIENT_ENCRYPTED_KEYS = "RecipientEncryptedKeys";
  11721. const CLEAR_PROPS$t = [
  11722. RECIPIENT_ENCRYPTED_KEYS,
  11723. ];
  11724. class RecipientEncryptedKeys extends PkiObject {
  11725. constructor(parameters = {}) {
  11726. super();
  11727. this.encryptedKeys = pvutils__namespace.getParametersValue(parameters, ENCRYPTED_KEYS, RecipientEncryptedKeys.defaultValues(ENCRYPTED_KEYS));
  11728. if (parameters.schema) {
  11729. this.fromSchema(parameters.schema);
  11730. }
  11731. }
  11732. static defaultValues(memberName) {
  11733. switch (memberName) {
  11734. case ENCRYPTED_KEYS:
  11735. return [];
  11736. default:
  11737. return super.defaultValues(memberName);
  11738. }
  11739. }
  11740. static compareWithDefault(memberName, memberValue) {
  11741. switch (memberName) {
  11742. case ENCRYPTED_KEYS:
  11743. return (memberValue.length === 0);
  11744. default:
  11745. return super.defaultValues(memberName);
  11746. }
  11747. }
  11748. static schema(parameters = {}) {
  11749. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  11750. return (new asn1js__namespace.Sequence({
  11751. name: (names.blockName || EMPTY_STRING),
  11752. value: [
  11753. new asn1js__namespace.Repeated({
  11754. name: (names.RecipientEncryptedKeys || EMPTY_STRING),
  11755. value: RecipientEncryptedKey.schema()
  11756. })
  11757. ]
  11758. }));
  11759. }
  11760. fromSchema(schema) {
  11761. pvutils__namespace.clearProps(schema, CLEAR_PROPS$t);
  11762. const asn1 = asn1js__namespace.compareSchema(schema, schema, RecipientEncryptedKeys.schema({
  11763. names: {
  11764. RecipientEncryptedKeys: RECIPIENT_ENCRYPTED_KEYS
  11765. }
  11766. }));
  11767. AsnError.assertSchema(asn1, this.className);
  11768. this.encryptedKeys = Array.from(asn1.result.RecipientEncryptedKeys, element => new RecipientEncryptedKey({ schema: element }));
  11769. }
  11770. toSchema() {
  11771. return (new asn1js__namespace.Sequence({
  11772. value: Array.from(this.encryptedKeys, o => o.toSchema())
  11773. }));
  11774. }
  11775. toJSON() {
  11776. return {
  11777. encryptedKeys: Array.from(this.encryptedKeys, o => o.toJSON())
  11778. };
  11779. }
  11780. }
  11781. RecipientEncryptedKeys.CLASS_NAME = "RecipientEncryptedKeys";
  11782. const VERSION$b = "version";
  11783. const ORIGINATOR = "originator";
  11784. const UKM = "ukm";
  11785. const KEY_ENCRYPTION_ALGORITHM$2 = "keyEncryptionAlgorithm";
  11786. const RECIPIENT_ENCRYPTED_KEY = "recipientEncryptedKeys";
  11787. const RECIPIENT_CERTIFICATE = "recipientCertificate";
  11788. const RECIPIENT_PUBLIC_KEY = "recipientPublicKey";
  11789. const CLEAR_PROPS$s = [
  11790. VERSION$b,
  11791. ORIGINATOR,
  11792. UKM,
  11793. KEY_ENCRYPTION_ALGORITHM$2,
  11794. RECIPIENT_ENCRYPTED_KEY,
  11795. ];
  11796. class KeyAgreeRecipientInfo extends PkiObject {
  11797. constructor(parameters = {}) {
  11798. super();
  11799. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$b, KeyAgreeRecipientInfo.defaultValues(VERSION$b));
  11800. this.originator = pvutils__namespace.getParametersValue(parameters, ORIGINATOR, KeyAgreeRecipientInfo.defaultValues(ORIGINATOR));
  11801. if (UKM in parameters) {
  11802. this.ukm = pvutils__namespace.getParametersValue(parameters, UKM, KeyAgreeRecipientInfo.defaultValues(UKM));
  11803. }
  11804. this.keyEncryptionAlgorithm = pvutils__namespace.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM$2, KeyAgreeRecipientInfo.defaultValues(KEY_ENCRYPTION_ALGORITHM$2));
  11805. this.recipientEncryptedKeys = pvutils__namespace.getParametersValue(parameters, RECIPIENT_ENCRYPTED_KEY, KeyAgreeRecipientInfo.defaultValues(RECIPIENT_ENCRYPTED_KEY));
  11806. this.recipientCertificate = pvutils__namespace.getParametersValue(parameters, RECIPIENT_CERTIFICATE, KeyAgreeRecipientInfo.defaultValues(RECIPIENT_CERTIFICATE));
  11807. this.recipientPublicKey = pvutils__namespace.getParametersValue(parameters, RECIPIENT_PUBLIC_KEY, KeyAgreeRecipientInfo.defaultValues(RECIPIENT_PUBLIC_KEY));
  11808. if (parameters.schema) {
  11809. this.fromSchema(parameters.schema);
  11810. }
  11811. }
  11812. static defaultValues(memberName) {
  11813. switch (memberName) {
  11814. case VERSION$b:
  11815. return 0;
  11816. case ORIGINATOR:
  11817. return new OriginatorIdentifierOrKey();
  11818. case UKM:
  11819. return new asn1js__namespace.OctetString();
  11820. case KEY_ENCRYPTION_ALGORITHM$2:
  11821. return new AlgorithmIdentifier();
  11822. case RECIPIENT_ENCRYPTED_KEY:
  11823. return new RecipientEncryptedKeys();
  11824. case RECIPIENT_CERTIFICATE:
  11825. return new Certificate();
  11826. case RECIPIENT_PUBLIC_KEY:
  11827. return null;
  11828. default:
  11829. return super.defaultValues(memberName);
  11830. }
  11831. }
  11832. static compareWithDefault(memberName, memberValue) {
  11833. switch (memberName) {
  11834. case VERSION$b:
  11835. return (memberValue === 0);
  11836. case ORIGINATOR:
  11837. return ((memberValue.variant === (-1)) && (("value" in memberValue) === false));
  11838. case UKM:
  11839. return (memberValue.isEqual(KeyAgreeRecipientInfo.defaultValues(UKM)));
  11840. case KEY_ENCRYPTION_ALGORITHM$2:
  11841. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  11842. case RECIPIENT_ENCRYPTED_KEY:
  11843. return (memberValue.encryptedKeys.length === 0);
  11844. case RECIPIENT_CERTIFICATE:
  11845. return false;
  11846. case RECIPIENT_PUBLIC_KEY:
  11847. return false;
  11848. default:
  11849. return super.defaultValues(memberName);
  11850. }
  11851. }
  11852. static schema(parameters = {}) {
  11853. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  11854. return (new asn1js__namespace.Sequence({
  11855. name: names.blockName || EMPTY_STRING,
  11856. value: [
  11857. new asn1js__namespace.Integer({ name: names.version || EMPTY_STRING }),
  11858. new asn1js__namespace.Constructed({
  11859. idBlock: {
  11860. tagClass: 3,
  11861. tagNumber: 0
  11862. },
  11863. value: [
  11864. OriginatorIdentifierOrKey.schema(names.originator || {})
  11865. ]
  11866. }),
  11867. new asn1js__namespace.Constructed({
  11868. optional: true,
  11869. idBlock: {
  11870. tagClass: 3,
  11871. tagNumber: 1
  11872. },
  11873. value: [new asn1js__namespace.OctetString({ name: names.ukm || EMPTY_STRING })]
  11874. }),
  11875. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  11876. RecipientEncryptedKeys.schema(names.recipientEncryptedKeys || {})
  11877. ]
  11878. }));
  11879. }
  11880. fromSchema(schema) {
  11881. pvutils__namespace.clearProps(schema, CLEAR_PROPS$s);
  11882. const asn1 = asn1js__namespace.compareSchema(schema, schema, KeyAgreeRecipientInfo.schema({
  11883. names: {
  11884. version: VERSION$b,
  11885. originator: {
  11886. names: {
  11887. blockName: ORIGINATOR
  11888. }
  11889. },
  11890. ukm: UKM,
  11891. keyEncryptionAlgorithm: {
  11892. names: {
  11893. blockName: KEY_ENCRYPTION_ALGORITHM$2
  11894. }
  11895. },
  11896. recipientEncryptedKeys: {
  11897. names: {
  11898. blockName: RECIPIENT_ENCRYPTED_KEY
  11899. }
  11900. }
  11901. }
  11902. }));
  11903. AsnError.assertSchema(asn1, this.className);
  11904. this.version = asn1.result.version.valueBlock.valueDec;
  11905. this.originator = new OriginatorIdentifierOrKey({ schema: asn1.result.originator });
  11906. if (UKM in asn1.result)
  11907. this.ukm = asn1.result.ukm;
  11908. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  11909. this.recipientEncryptedKeys = new RecipientEncryptedKeys({ schema: asn1.result.recipientEncryptedKeys });
  11910. }
  11911. toSchema() {
  11912. const outputArray = [];
  11913. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  11914. outputArray.push(new asn1js__namespace.Constructed({
  11915. idBlock: {
  11916. tagClass: 3,
  11917. tagNumber: 0
  11918. },
  11919. value: [this.originator.toSchema()]
  11920. }));
  11921. if (this.ukm) {
  11922. outputArray.push(new asn1js__namespace.Constructed({
  11923. optional: true,
  11924. idBlock: {
  11925. tagClass: 3,
  11926. tagNumber: 1
  11927. },
  11928. value: [this.ukm]
  11929. }));
  11930. }
  11931. outputArray.push(this.keyEncryptionAlgorithm.toSchema());
  11932. outputArray.push(this.recipientEncryptedKeys.toSchema());
  11933. return (new asn1js__namespace.Sequence({
  11934. value: outputArray
  11935. }));
  11936. }
  11937. toJSON() {
  11938. const res = {
  11939. version: this.version,
  11940. originator: this.originator.toJSON(),
  11941. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  11942. recipientEncryptedKeys: this.recipientEncryptedKeys.toJSON(),
  11943. };
  11944. if (this.ukm) {
  11945. res.ukm = this.ukm.toJSON();
  11946. }
  11947. return res;
  11948. }
  11949. }
  11950. KeyAgreeRecipientInfo.CLASS_NAME = "KeyAgreeRecipientInfo";
  11951. const KEY_IDENTIFIER = "keyIdentifier";
  11952. const DATE = "date";
  11953. const OTHER = "other";
  11954. const CLEAR_PROPS$r = [
  11955. KEY_IDENTIFIER,
  11956. DATE,
  11957. OTHER,
  11958. ];
  11959. class KEKIdentifier extends PkiObject {
  11960. constructor(parameters = {}) {
  11961. super();
  11962. this.keyIdentifier = pvutils__namespace.getParametersValue(parameters, KEY_IDENTIFIER, KEKIdentifier.defaultValues(KEY_IDENTIFIER));
  11963. if (DATE in parameters) {
  11964. this.date = pvutils__namespace.getParametersValue(parameters, DATE, KEKIdentifier.defaultValues(DATE));
  11965. }
  11966. if (OTHER in parameters) {
  11967. this.other = pvutils__namespace.getParametersValue(parameters, OTHER, KEKIdentifier.defaultValues(OTHER));
  11968. }
  11969. if (parameters.schema) {
  11970. this.fromSchema(parameters.schema);
  11971. }
  11972. }
  11973. static defaultValues(memberName) {
  11974. switch (memberName) {
  11975. case KEY_IDENTIFIER:
  11976. return new asn1js__namespace.OctetString();
  11977. case DATE:
  11978. return new asn1js__namespace.GeneralizedTime();
  11979. case OTHER:
  11980. return new OtherKeyAttribute();
  11981. default:
  11982. return super.defaultValues(memberName);
  11983. }
  11984. }
  11985. static compareWithDefault(memberName, memberValue) {
  11986. switch (memberName) {
  11987. case KEY_IDENTIFIER:
  11988. return (memberValue.isEqual(KEKIdentifier.defaultValues(KEY_IDENTIFIER)));
  11989. case DATE:
  11990. return ((memberValue.year === 0) &&
  11991. (memberValue.month === 0) &&
  11992. (memberValue.day === 0) &&
  11993. (memberValue.hour === 0) &&
  11994. (memberValue.minute === 0) &&
  11995. (memberValue.second === 0) &&
  11996. (memberValue.millisecond === 0));
  11997. case OTHER:
  11998. return ((memberValue.compareWithDefault("keyAttrId", memberValue.keyAttrId)) &&
  11999. (("keyAttr" in memberValue) === false));
  12000. default:
  12001. return super.defaultValues(memberName);
  12002. }
  12003. }
  12004. static schema(parameters = {}) {
  12005. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  12006. return (new asn1js__namespace.Sequence({
  12007. name: (names.blockName || EMPTY_STRING),
  12008. value: [
  12009. new asn1js__namespace.OctetString({ name: (names.keyIdentifier || EMPTY_STRING) }),
  12010. new asn1js__namespace.GeneralizedTime({
  12011. optional: true,
  12012. name: (names.date || EMPTY_STRING)
  12013. }),
  12014. OtherKeyAttribute.schema(names.other || {})
  12015. ]
  12016. }));
  12017. }
  12018. fromSchema(schema) {
  12019. pvutils__namespace.clearProps(schema, CLEAR_PROPS$r);
  12020. const asn1 = asn1js__namespace.compareSchema(schema, schema, KEKIdentifier.schema({
  12021. names: {
  12022. keyIdentifier: KEY_IDENTIFIER,
  12023. date: DATE,
  12024. other: {
  12025. names: {
  12026. blockName: OTHER
  12027. }
  12028. }
  12029. }
  12030. }));
  12031. AsnError.assertSchema(asn1, this.className);
  12032. this.keyIdentifier = asn1.result.keyIdentifier;
  12033. if (DATE in asn1.result)
  12034. this.date = asn1.result.date;
  12035. if (OTHER in asn1.result)
  12036. this.other = new OtherKeyAttribute({ schema: asn1.result.other });
  12037. }
  12038. toSchema() {
  12039. const outputArray = [];
  12040. outputArray.push(this.keyIdentifier);
  12041. if (this.date) {
  12042. outputArray.push(this.date);
  12043. }
  12044. if (this.other) {
  12045. outputArray.push(this.other.toSchema());
  12046. }
  12047. return (new asn1js__namespace.Sequence({
  12048. value: outputArray
  12049. }));
  12050. }
  12051. toJSON() {
  12052. const res = {
  12053. keyIdentifier: this.keyIdentifier.toJSON()
  12054. };
  12055. if (this.date) {
  12056. res.date = this.date;
  12057. }
  12058. if (this.other) {
  12059. res.other = this.other.toJSON();
  12060. }
  12061. return res;
  12062. }
  12063. }
  12064. KEKIdentifier.CLASS_NAME = "KEKIdentifier";
  12065. const VERSION$a = "version";
  12066. const KEK_ID = "kekid";
  12067. const KEY_ENCRYPTION_ALGORITHM$1 = "keyEncryptionAlgorithm";
  12068. const ENCRYPTED_KEY$1 = "encryptedKey";
  12069. const PER_DEFINED_KEK = "preDefinedKEK";
  12070. const CLEAR_PROPS$q = [
  12071. VERSION$a,
  12072. KEK_ID,
  12073. KEY_ENCRYPTION_ALGORITHM$1,
  12074. ENCRYPTED_KEY$1,
  12075. ];
  12076. class KEKRecipientInfo extends PkiObject {
  12077. constructor(parameters = {}) {
  12078. super();
  12079. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$a, KEKRecipientInfo.defaultValues(VERSION$a));
  12080. this.kekid = pvutils__namespace.getParametersValue(parameters, KEK_ID, KEKRecipientInfo.defaultValues(KEK_ID));
  12081. this.keyEncryptionAlgorithm = pvutils__namespace.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM$1, KEKRecipientInfo.defaultValues(KEY_ENCRYPTION_ALGORITHM$1));
  12082. this.encryptedKey = pvutils__namespace.getParametersValue(parameters, ENCRYPTED_KEY$1, KEKRecipientInfo.defaultValues(ENCRYPTED_KEY$1));
  12083. this.preDefinedKEK = pvutils__namespace.getParametersValue(parameters, PER_DEFINED_KEK, KEKRecipientInfo.defaultValues(PER_DEFINED_KEK));
  12084. if (parameters.schema) {
  12085. this.fromSchema(parameters.schema);
  12086. }
  12087. }
  12088. static defaultValues(memberName) {
  12089. switch (memberName) {
  12090. case VERSION$a:
  12091. return 0;
  12092. case KEK_ID:
  12093. return new KEKIdentifier();
  12094. case KEY_ENCRYPTION_ALGORITHM$1:
  12095. return new AlgorithmIdentifier();
  12096. case ENCRYPTED_KEY$1:
  12097. return new asn1js__namespace.OctetString();
  12098. case PER_DEFINED_KEK:
  12099. return EMPTY_BUFFER;
  12100. default:
  12101. return super.defaultValues(memberName);
  12102. }
  12103. }
  12104. static compareWithDefault(memberName, memberValue) {
  12105. switch (memberName) {
  12106. case "KEKRecipientInfo":
  12107. return (memberValue === KEKRecipientInfo.defaultValues(VERSION$a));
  12108. case KEK_ID:
  12109. return ((memberValue.compareWithDefault("keyIdentifier", memberValue.keyIdentifier)) &&
  12110. (("date" in memberValue) === false) &&
  12111. (("other" in memberValue) === false));
  12112. case KEY_ENCRYPTION_ALGORITHM$1:
  12113. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  12114. case ENCRYPTED_KEY$1:
  12115. return (memberValue.isEqual(KEKRecipientInfo.defaultValues(ENCRYPTED_KEY$1)));
  12116. case PER_DEFINED_KEK:
  12117. return (memberValue.byteLength === 0);
  12118. default:
  12119. return super.defaultValues(memberName);
  12120. }
  12121. }
  12122. static schema(parameters = {}) {
  12123. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  12124. return (new asn1js__namespace.Sequence({
  12125. name: (names.blockName || EMPTY_STRING),
  12126. value: [
  12127. new asn1js__namespace.Integer({ name: (names.version || EMPTY_STRING) }),
  12128. KEKIdentifier.schema(names.kekid || {}),
  12129. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  12130. new asn1js__namespace.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  12131. ]
  12132. }));
  12133. }
  12134. fromSchema(schema) {
  12135. pvutils__namespace.clearProps(schema, CLEAR_PROPS$q);
  12136. const asn1 = asn1js__namespace.compareSchema(schema, schema, KEKRecipientInfo.schema({
  12137. names: {
  12138. version: VERSION$a,
  12139. kekid: {
  12140. names: {
  12141. blockName: KEK_ID
  12142. }
  12143. },
  12144. keyEncryptionAlgorithm: {
  12145. names: {
  12146. blockName: KEY_ENCRYPTION_ALGORITHM$1
  12147. }
  12148. },
  12149. encryptedKey: ENCRYPTED_KEY$1
  12150. }
  12151. }));
  12152. AsnError.assertSchema(asn1, this.className);
  12153. this.version = asn1.result.version.valueBlock.valueDec;
  12154. this.kekid = new KEKIdentifier({ schema: asn1.result.kekid });
  12155. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  12156. this.encryptedKey = asn1.result.encryptedKey;
  12157. }
  12158. toSchema() {
  12159. return (new asn1js__namespace.Sequence({
  12160. value: [
  12161. new asn1js__namespace.Integer({ value: this.version }),
  12162. this.kekid.toSchema(),
  12163. this.keyEncryptionAlgorithm.toSchema(),
  12164. this.encryptedKey
  12165. ]
  12166. }));
  12167. }
  12168. toJSON() {
  12169. return {
  12170. version: this.version,
  12171. kekid: this.kekid.toJSON(),
  12172. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  12173. encryptedKey: this.encryptedKey.toJSON(),
  12174. };
  12175. }
  12176. }
  12177. KEKRecipientInfo.CLASS_NAME = "KEKRecipientInfo";
  12178. const VERSION$9 = "version";
  12179. const KEY_DERIVATION_ALGORITHM = "keyDerivationAlgorithm";
  12180. const KEY_ENCRYPTION_ALGORITHM = "keyEncryptionAlgorithm";
  12181. const ENCRYPTED_KEY = "encryptedKey";
  12182. const PASSWORD = "password";
  12183. const CLEAR_PROPS$p = [
  12184. VERSION$9,
  12185. KEY_DERIVATION_ALGORITHM,
  12186. KEY_ENCRYPTION_ALGORITHM,
  12187. ENCRYPTED_KEY
  12188. ];
  12189. class PasswordRecipientinfo extends PkiObject {
  12190. constructor(parameters = {}) {
  12191. super();
  12192. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$9, PasswordRecipientinfo.defaultValues(VERSION$9));
  12193. if (KEY_DERIVATION_ALGORITHM in parameters) {
  12194. this.keyDerivationAlgorithm = pvutils__namespace.getParametersValue(parameters, KEY_DERIVATION_ALGORITHM, PasswordRecipientinfo.defaultValues(KEY_DERIVATION_ALGORITHM));
  12195. }
  12196. this.keyEncryptionAlgorithm = pvutils__namespace.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM, PasswordRecipientinfo.defaultValues(KEY_ENCRYPTION_ALGORITHM));
  12197. this.encryptedKey = pvutils__namespace.getParametersValue(parameters, ENCRYPTED_KEY, PasswordRecipientinfo.defaultValues(ENCRYPTED_KEY));
  12198. this.password = pvutils__namespace.getParametersValue(parameters, PASSWORD, PasswordRecipientinfo.defaultValues(PASSWORD));
  12199. if (parameters.schema) {
  12200. this.fromSchema(parameters.schema);
  12201. }
  12202. }
  12203. static defaultValues(memberName) {
  12204. switch (memberName) {
  12205. case VERSION$9:
  12206. return (-1);
  12207. case KEY_DERIVATION_ALGORITHM:
  12208. return new AlgorithmIdentifier();
  12209. case KEY_ENCRYPTION_ALGORITHM:
  12210. return new AlgorithmIdentifier();
  12211. case ENCRYPTED_KEY:
  12212. return new asn1js__namespace.OctetString();
  12213. case PASSWORD:
  12214. return EMPTY_BUFFER;
  12215. default:
  12216. return super.defaultValues(memberName);
  12217. }
  12218. }
  12219. static compareWithDefault(memberName, memberValue) {
  12220. switch (memberName) {
  12221. case VERSION$9:
  12222. return (memberValue === (-1));
  12223. case KEY_DERIVATION_ALGORITHM:
  12224. case KEY_ENCRYPTION_ALGORITHM:
  12225. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  12226. case ENCRYPTED_KEY:
  12227. return (memberValue.isEqual(PasswordRecipientinfo.defaultValues(ENCRYPTED_KEY)));
  12228. case PASSWORD:
  12229. return (memberValue.byteLength === 0);
  12230. default:
  12231. return super.defaultValues(memberName);
  12232. }
  12233. }
  12234. static schema(parameters = {}) {
  12235. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  12236. return (new asn1js__namespace.Sequence({
  12237. name: (names.blockName || EMPTY_STRING),
  12238. value: [
  12239. new asn1js__namespace.Integer({ name: (names.version || EMPTY_STRING) }),
  12240. new asn1js__namespace.Constructed({
  12241. name: (names.keyDerivationAlgorithm || EMPTY_STRING),
  12242. optional: true,
  12243. idBlock: {
  12244. tagClass: 3,
  12245. tagNumber: 0
  12246. },
  12247. value: AlgorithmIdentifier.schema().valueBlock.value
  12248. }),
  12249. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  12250. new asn1js__namespace.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  12251. ]
  12252. }));
  12253. }
  12254. fromSchema(schema) {
  12255. pvutils__namespace.clearProps(schema, CLEAR_PROPS$p);
  12256. const asn1 = asn1js__namespace.compareSchema(schema, schema, PasswordRecipientinfo.schema({
  12257. names: {
  12258. version: VERSION$9,
  12259. keyDerivationAlgorithm: KEY_DERIVATION_ALGORITHM,
  12260. keyEncryptionAlgorithm: {
  12261. names: {
  12262. blockName: KEY_ENCRYPTION_ALGORITHM
  12263. }
  12264. },
  12265. encryptedKey: ENCRYPTED_KEY
  12266. }
  12267. }));
  12268. AsnError.assertSchema(asn1, this.className);
  12269. this.version = asn1.result.version.valueBlock.valueDec;
  12270. if (KEY_DERIVATION_ALGORITHM in asn1.result) {
  12271. this.keyDerivationAlgorithm = new AlgorithmIdentifier({
  12272. schema: new asn1js__namespace.Sequence({
  12273. value: asn1.result.keyDerivationAlgorithm.valueBlock.value
  12274. })
  12275. });
  12276. }
  12277. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  12278. this.encryptedKey = asn1.result.encryptedKey;
  12279. }
  12280. toSchema() {
  12281. const outputArray = [];
  12282. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  12283. if (this.keyDerivationAlgorithm) {
  12284. outputArray.push(new asn1js__namespace.Constructed({
  12285. idBlock: {
  12286. tagClass: 3,
  12287. tagNumber: 0
  12288. },
  12289. value: this.keyDerivationAlgorithm.toSchema().valueBlock.value
  12290. }));
  12291. }
  12292. outputArray.push(this.keyEncryptionAlgorithm.toSchema());
  12293. outputArray.push(this.encryptedKey);
  12294. return (new asn1js__namespace.Sequence({
  12295. value: outputArray
  12296. }));
  12297. }
  12298. toJSON() {
  12299. const res = {
  12300. version: this.version,
  12301. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  12302. encryptedKey: this.encryptedKey.toJSON(),
  12303. };
  12304. if (this.keyDerivationAlgorithm) {
  12305. res.keyDerivationAlgorithm = this.keyDerivationAlgorithm.toJSON();
  12306. }
  12307. return res;
  12308. }
  12309. }
  12310. PasswordRecipientinfo.CLASS_NAME = "PasswordRecipientInfo";
  12311. const ORI_TYPE = "oriType";
  12312. const ORI_VALUE = "oriValue";
  12313. const CLEAR_PROPS$o = [
  12314. ORI_TYPE,
  12315. ORI_VALUE
  12316. ];
  12317. class OtherRecipientInfo extends PkiObject {
  12318. constructor(parameters = {}) {
  12319. super();
  12320. this.oriType = pvutils__namespace.getParametersValue(parameters, ORI_TYPE, OtherRecipientInfo.defaultValues(ORI_TYPE));
  12321. this.oriValue = pvutils__namespace.getParametersValue(parameters, ORI_VALUE, OtherRecipientInfo.defaultValues(ORI_VALUE));
  12322. if (parameters.schema) {
  12323. this.fromSchema(parameters.schema);
  12324. }
  12325. }
  12326. static defaultValues(memberName) {
  12327. switch (memberName) {
  12328. case ORI_TYPE:
  12329. return EMPTY_STRING;
  12330. case ORI_VALUE:
  12331. return {};
  12332. default:
  12333. return super.defaultValues(memberName);
  12334. }
  12335. }
  12336. static compareWithDefault(memberName, memberValue) {
  12337. switch (memberName) {
  12338. case ORI_TYPE:
  12339. return (memberValue === EMPTY_STRING);
  12340. case ORI_VALUE:
  12341. return (Object.keys(memberValue).length === 0);
  12342. default:
  12343. return super.defaultValues(memberName);
  12344. }
  12345. }
  12346. static schema(parameters = {}) {
  12347. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  12348. return (new asn1js__namespace.Sequence({
  12349. name: (names.blockName || EMPTY_STRING),
  12350. value: [
  12351. new asn1js__namespace.ObjectIdentifier({ name: (names.oriType || EMPTY_STRING) }),
  12352. new asn1js__namespace.Any({ name: (names.oriValue || EMPTY_STRING) })
  12353. ]
  12354. }));
  12355. }
  12356. fromSchema(schema) {
  12357. pvutils__namespace.clearProps(schema, CLEAR_PROPS$o);
  12358. const asn1 = asn1js__namespace.compareSchema(schema, schema, OtherRecipientInfo.schema({
  12359. names: {
  12360. oriType: ORI_TYPE,
  12361. oriValue: ORI_VALUE
  12362. }
  12363. }));
  12364. AsnError.assertSchema(asn1, this.className);
  12365. this.oriType = asn1.result.oriType.valueBlock.toString();
  12366. this.oriValue = asn1.result.oriValue;
  12367. }
  12368. toSchema() {
  12369. return (new asn1js__namespace.Sequence({
  12370. value: [
  12371. new asn1js__namespace.ObjectIdentifier({ value: this.oriType }),
  12372. this.oriValue
  12373. ]
  12374. }));
  12375. }
  12376. toJSON() {
  12377. const res = {
  12378. oriType: this.oriType
  12379. };
  12380. if (!OtherRecipientInfo.compareWithDefault(ORI_VALUE, this.oriValue)) {
  12381. res.oriValue = this.oriValue.toJSON();
  12382. }
  12383. return res;
  12384. }
  12385. }
  12386. OtherRecipientInfo.CLASS_NAME = "OtherRecipientInfo";
  12387. const VARIANT = "variant";
  12388. const VALUE = "value";
  12389. const CLEAR_PROPS$n = [
  12390. "blockName"
  12391. ];
  12392. class RecipientInfo extends PkiObject {
  12393. constructor(parameters = {}) {
  12394. super();
  12395. this.variant = pvutils__namespace.getParametersValue(parameters, VARIANT, RecipientInfo.defaultValues(VARIANT));
  12396. if (VALUE in parameters) {
  12397. this.value = pvutils__namespace.getParametersValue(parameters, VALUE, RecipientInfo.defaultValues(VALUE));
  12398. }
  12399. if (parameters.schema) {
  12400. this.fromSchema(parameters.schema);
  12401. }
  12402. }
  12403. static defaultValues(memberName) {
  12404. switch (memberName) {
  12405. case VARIANT:
  12406. return (-1);
  12407. case VALUE:
  12408. return {};
  12409. default:
  12410. return super.defaultValues(memberName);
  12411. }
  12412. }
  12413. static compareWithDefault(memberName, memberValue) {
  12414. switch (memberName) {
  12415. case VARIANT:
  12416. return (memberValue === RecipientInfo.defaultValues(memberName));
  12417. case VALUE:
  12418. return (Object.keys(memberValue).length === 0);
  12419. default:
  12420. return super.defaultValues(memberName);
  12421. }
  12422. }
  12423. static schema(parameters = {}) {
  12424. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  12425. return (new asn1js__namespace.Choice({
  12426. value: [
  12427. KeyTransRecipientInfo.schema({
  12428. names: {
  12429. blockName: (names.blockName || EMPTY_STRING)
  12430. }
  12431. }),
  12432. new asn1js__namespace.Constructed({
  12433. name: (names.blockName || EMPTY_STRING),
  12434. idBlock: {
  12435. tagClass: 3,
  12436. tagNumber: 1
  12437. },
  12438. value: KeyAgreeRecipientInfo.schema().valueBlock.value
  12439. }),
  12440. new asn1js__namespace.Constructed({
  12441. name: (names.blockName || EMPTY_STRING),
  12442. idBlock: {
  12443. tagClass: 3,
  12444. tagNumber: 2
  12445. },
  12446. value: KEKRecipientInfo.schema().valueBlock.value
  12447. }),
  12448. new asn1js__namespace.Constructed({
  12449. name: (names.blockName || EMPTY_STRING),
  12450. idBlock: {
  12451. tagClass: 3,
  12452. tagNumber: 3
  12453. },
  12454. value: PasswordRecipientinfo.schema().valueBlock.value
  12455. }),
  12456. new asn1js__namespace.Constructed({
  12457. name: (names.blockName || EMPTY_STRING),
  12458. idBlock: {
  12459. tagClass: 3,
  12460. tagNumber: 4
  12461. },
  12462. value: OtherRecipientInfo.schema().valueBlock.value
  12463. })
  12464. ]
  12465. }));
  12466. }
  12467. fromSchema(schema) {
  12468. pvutils__namespace.clearProps(schema, CLEAR_PROPS$n);
  12469. const asn1 = asn1js__namespace.compareSchema(schema, schema, RecipientInfo.schema({
  12470. names: {
  12471. blockName: "blockName"
  12472. }
  12473. }));
  12474. AsnError.assertSchema(asn1, this.className);
  12475. if (asn1.result.blockName.idBlock.tagClass === 1) {
  12476. this.variant = 1;
  12477. this.value = new KeyTransRecipientInfo({ schema: asn1.result.blockName });
  12478. }
  12479. else {
  12480. const blockSequence = new asn1js__namespace.Sequence({
  12481. value: asn1.result.blockName.valueBlock.value
  12482. });
  12483. switch (asn1.result.blockName.idBlock.tagNumber) {
  12484. case 1:
  12485. this.variant = 2;
  12486. this.value = new KeyAgreeRecipientInfo({ schema: blockSequence });
  12487. break;
  12488. case 2:
  12489. this.variant = 3;
  12490. this.value = new KEKRecipientInfo({ schema: blockSequence });
  12491. break;
  12492. case 3:
  12493. this.variant = 4;
  12494. this.value = new PasswordRecipientinfo({ schema: blockSequence });
  12495. break;
  12496. case 4:
  12497. this.variant = 5;
  12498. this.value = new OtherRecipientInfo({ schema: blockSequence });
  12499. break;
  12500. default:
  12501. throw new Error("Incorrect structure of RecipientInfo block");
  12502. }
  12503. }
  12504. }
  12505. toSchema() {
  12506. ParameterError.assertEmpty(this.value, "value", "RecipientInfo");
  12507. const _schema = this.value.toSchema();
  12508. switch (this.variant) {
  12509. case 1:
  12510. return _schema;
  12511. case 2:
  12512. case 3:
  12513. case 4:
  12514. _schema.idBlock.tagClass = 3;
  12515. _schema.idBlock.tagNumber = (this.variant - 1);
  12516. return _schema;
  12517. default:
  12518. return new asn1js__namespace.Any();
  12519. }
  12520. }
  12521. toJSON() {
  12522. const res = {
  12523. variant: this.variant
  12524. };
  12525. if (this.value && (this.variant >= 1) && (this.variant <= 4)) {
  12526. res.value = this.value.toJSON();
  12527. }
  12528. return res;
  12529. }
  12530. }
  12531. RecipientInfo.CLASS_NAME = "RecipientInfo";
  12532. const HASH_ALGORITHM$2 = "hashAlgorithm";
  12533. const MASK_GEN_ALGORITHM = "maskGenAlgorithm";
  12534. const P_SOURCE_ALGORITHM = "pSourceAlgorithm";
  12535. const CLEAR_PROPS$m = [
  12536. HASH_ALGORITHM$2,
  12537. MASK_GEN_ALGORITHM,
  12538. P_SOURCE_ALGORITHM
  12539. ];
  12540. class RSAESOAEPParams extends PkiObject {
  12541. constructor(parameters = {}) {
  12542. super();
  12543. this.hashAlgorithm = pvutils__namespace.getParametersValue(parameters, HASH_ALGORITHM$2, RSAESOAEPParams.defaultValues(HASH_ALGORITHM$2));
  12544. this.maskGenAlgorithm = pvutils__namespace.getParametersValue(parameters, MASK_GEN_ALGORITHM, RSAESOAEPParams.defaultValues(MASK_GEN_ALGORITHM));
  12545. this.pSourceAlgorithm = pvutils__namespace.getParametersValue(parameters, P_SOURCE_ALGORITHM, RSAESOAEPParams.defaultValues(P_SOURCE_ALGORITHM));
  12546. if (parameters.schema) {
  12547. this.fromSchema(parameters.schema);
  12548. }
  12549. }
  12550. static defaultValues(memberName) {
  12551. switch (memberName) {
  12552. case HASH_ALGORITHM$2:
  12553. return new AlgorithmIdentifier({
  12554. algorithmId: "1.3.14.3.2.26",
  12555. algorithmParams: new asn1js__namespace.Null()
  12556. });
  12557. case MASK_GEN_ALGORITHM:
  12558. return new AlgorithmIdentifier({
  12559. algorithmId: "1.2.840.113549.1.1.8",
  12560. algorithmParams: (new AlgorithmIdentifier({
  12561. algorithmId: "1.3.14.3.2.26",
  12562. algorithmParams: new asn1js__namespace.Null()
  12563. })).toSchema()
  12564. });
  12565. case P_SOURCE_ALGORITHM:
  12566. return new AlgorithmIdentifier({
  12567. algorithmId: "1.2.840.113549.1.1.9",
  12568. algorithmParams: new asn1js__namespace.OctetString({ valueHex: (new Uint8Array([0xda, 0x39, 0xa3, 0xee, 0x5e, 0x6b, 0x4b, 0x0d, 0x32, 0x55, 0xbf, 0xef, 0x95, 0x60, 0x18, 0x90, 0xaf, 0xd8, 0x07, 0x09])).buffer })
  12569. });
  12570. default:
  12571. return super.defaultValues(memberName);
  12572. }
  12573. }
  12574. static schema(parameters = {}) {
  12575. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  12576. return (new asn1js__namespace.Sequence({
  12577. name: (names.blockName || EMPTY_STRING),
  12578. value: [
  12579. new asn1js__namespace.Constructed({
  12580. idBlock: {
  12581. tagClass: 3,
  12582. tagNumber: 0
  12583. },
  12584. optional: true,
  12585. value: [AlgorithmIdentifier.schema(names.hashAlgorithm || {})]
  12586. }),
  12587. new asn1js__namespace.Constructed({
  12588. idBlock: {
  12589. tagClass: 3,
  12590. tagNumber: 1
  12591. },
  12592. optional: true,
  12593. value: [AlgorithmIdentifier.schema(names.maskGenAlgorithm || {})]
  12594. }),
  12595. new asn1js__namespace.Constructed({
  12596. idBlock: {
  12597. tagClass: 3,
  12598. tagNumber: 2
  12599. },
  12600. optional: true,
  12601. value: [AlgorithmIdentifier.schema(names.pSourceAlgorithm || {})]
  12602. })
  12603. ]
  12604. }));
  12605. }
  12606. fromSchema(schema) {
  12607. pvutils__namespace.clearProps(schema, CLEAR_PROPS$m);
  12608. const asn1 = asn1js__namespace.compareSchema(schema, schema, RSAESOAEPParams.schema({
  12609. names: {
  12610. hashAlgorithm: {
  12611. names: {
  12612. blockName: HASH_ALGORITHM$2
  12613. }
  12614. },
  12615. maskGenAlgorithm: {
  12616. names: {
  12617. blockName: MASK_GEN_ALGORITHM
  12618. }
  12619. },
  12620. pSourceAlgorithm: {
  12621. names: {
  12622. blockName: P_SOURCE_ALGORITHM
  12623. }
  12624. }
  12625. }
  12626. }));
  12627. AsnError.assertSchema(asn1, this.className);
  12628. if (HASH_ALGORITHM$2 in asn1.result)
  12629. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  12630. if (MASK_GEN_ALGORITHM in asn1.result)
  12631. this.maskGenAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.maskGenAlgorithm });
  12632. if (P_SOURCE_ALGORITHM in asn1.result)
  12633. this.pSourceAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.pSourceAlgorithm });
  12634. }
  12635. toSchema() {
  12636. const outputArray = [];
  12637. if (!this.hashAlgorithm.isEqual(RSAESOAEPParams.defaultValues(HASH_ALGORITHM$2))) {
  12638. outputArray.push(new asn1js__namespace.Constructed({
  12639. idBlock: {
  12640. tagClass: 3,
  12641. tagNumber: 0
  12642. },
  12643. value: [this.hashAlgorithm.toSchema()]
  12644. }));
  12645. }
  12646. if (!this.maskGenAlgorithm.isEqual(RSAESOAEPParams.defaultValues(MASK_GEN_ALGORITHM))) {
  12647. outputArray.push(new asn1js__namespace.Constructed({
  12648. idBlock: {
  12649. tagClass: 3,
  12650. tagNumber: 1
  12651. },
  12652. value: [this.maskGenAlgorithm.toSchema()]
  12653. }));
  12654. }
  12655. if (!this.pSourceAlgorithm.isEqual(RSAESOAEPParams.defaultValues(P_SOURCE_ALGORITHM))) {
  12656. outputArray.push(new asn1js__namespace.Constructed({
  12657. idBlock: {
  12658. tagClass: 3,
  12659. tagNumber: 2
  12660. },
  12661. value: [this.pSourceAlgorithm.toSchema()]
  12662. }));
  12663. }
  12664. return (new asn1js__namespace.Sequence({
  12665. value: outputArray
  12666. }));
  12667. }
  12668. toJSON() {
  12669. const res = {};
  12670. if (!this.hashAlgorithm.isEqual(RSAESOAEPParams.defaultValues(HASH_ALGORITHM$2))) {
  12671. res.hashAlgorithm = this.hashAlgorithm.toJSON();
  12672. }
  12673. if (!this.maskGenAlgorithm.isEqual(RSAESOAEPParams.defaultValues(MASK_GEN_ALGORITHM))) {
  12674. res.maskGenAlgorithm = this.maskGenAlgorithm.toJSON();
  12675. }
  12676. if (!this.pSourceAlgorithm.isEqual(RSAESOAEPParams.defaultValues(P_SOURCE_ALGORITHM))) {
  12677. res.pSourceAlgorithm = this.pSourceAlgorithm.toJSON();
  12678. }
  12679. return res;
  12680. }
  12681. }
  12682. RSAESOAEPParams.CLASS_NAME = "RSAESOAEPParams";
  12683. const KEY_INFO = "keyInfo";
  12684. const ENTITY_U_INFO = "entityUInfo";
  12685. const SUPP_PUB_INFO = "suppPubInfo";
  12686. const CLEAR_PROPS$l = [
  12687. KEY_INFO,
  12688. ENTITY_U_INFO,
  12689. SUPP_PUB_INFO
  12690. ];
  12691. class ECCCMSSharedInfo extends PkiObject {
  12692. constructor(parameters = {}) {
  12693. super();
  12694. this.keyInfo = pvutils__namespace.getParametersValue(parameters, KEY_INFO, ECCCMSSharedInfo.defaultValues(KEY_INFO));
  12695. if (ENTITY_U_INFO in parameters) {
  12696. this.entityUInfo = pvutils__namespace.getParametersValue(parameters, ENTITY_U_INFO, ECCCMSSharedInfo.defaultValues(ENTITY_U_INFO));
  12697. }
  12698. this.suppPubInfo = pvutils__namespace.getParametersValue(parameters, SUPP_PUB_INFO, ECCCMSSharedInfo.defaultValues(SUPP_PUB_INFO));
  12699. if (parameters.schema) {
  12700. this.fromSchema(parameters.schema);
  12701. }
  12702. }
  12703. static defaultValues(memberName) {
  12704. switch (memberName) {
  12705. case KEY_INFO:
  12706. return new AlgorithmIdentifier();
  12707. case ENTITY_U_INFO:
  12708. return new asn1js__namespace.OctetString();
  12709. case SUPP_PUB_INFO:
  12710. return new asn1js__namespace.OctetString();
  12711. default:
  12712. return super.defaultValues(memberName);
  12713. }
  12714. }
  12715. static compareWithDefault(memberName, memberValue) {
  12716. switch (memberName) {
  12717. case KEY_INFO:
  12718. case ENTITY_U_INFO:
  12719. case SUPP_PUB_INFO:
  12720. return (memberValue.isEqual(ECCCMSSharedInfo.defaultValues(memberName)));
  12721. default:
  12722. return super.defaultValues(memberName);
  12723. }
  12724. }
  12725. static schema(parameters = {}) {
  12726. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  12727. return (new asn1js__namespace.Sequence({
  12728. name: (names.blockName || EMPTY_STRING),
  12729. value: [
  12730. AlgorithmIdentifier.schema(names.keyInfo || {}),
  12731. new asn1js__namespace.Constructed({
  12732. name: (names.entityUInfo || EMPTY_STRING),
  12733. idBlock: {
  12734. tagClass: 3,
  12735. tagNumber: 0
  12736. },
  12737. optional: true,
  12738. value: [new asn1js__namespace.OctetString()]
  12739. }),
  12740. new asn1js__namespace.Constructed({
  12741. name: (names.suppPubInfo || EMPTY_STRING),
  12742. idBlock: {
  12743. tagClass: 3,
  12744. tagNumber: 2
  12745. },
  12746. value: [new asn1js__namespace.OctetString()]
  12747. })
  12748. ]
  12749. }));
  12750. }
  12751. fromSchema(schema) {
  12752. pvutils__namespace.clearProps(schema, CLEAR_PROPS$l);
  12753. const asn1 = asn1js__namespace.compareSchema(schema, schema, ECCCMSSharedInfo.schema({
  12754. names: {
  12755. keyInfo: {
  12756. names: {
  12757. blockName: KEY_INFO
  12758. }
  12759. },
  12760. entityUInfo: ENTITY_U_INFO,
  12761. suppPubInfo: SUPP_PUB_INFO
  12762. }
  12763. }));
  12764. AsnError.assertSchema(asn1, this.className);
  12765. this.keyInfo = new AlgorithmIdentifier({ schema: asn1.result.keyInfo });
  12766. if (ENTITY_U_INFO in asn1.result)
  12767. this.entityUInfo = asn1.result.entityUInfo.valueBlock.value[0];
  12768. this.suppPubInfo = asn1.result.suppPubInfo.valueBlock.value[0];
  12769. }
  12770. toSchema() {
  12771. const outputArray = [];
  12772. outputArray.push(this.keyInfo.toSchema());
  12773. if (this.entityUInfo) {
  12774. outputArray.push(new asn1js__namespace.Constructed({
  12775. idBlock: {
  12776. tagClass: 3,
  12777. tagNumber: 0
  12778. },
  12779. value: [this.entityUInfo]
  12780. }));
  12781. }
  12782. outputArray.push(new asn1js__namespace.Constructed({
  12783. idBlock: {
  12784. tagClass: 3,
  12785. tagNumber: 2
  12786. },
  12787. value: [this.suppPubInfo]
  12788. }));
  12789. return new asn1js__namespace.Sequence({
  12790. value: outputArray
  12791. });
  12792. }
  12793. toJSON() {
  12794. const res = {
  12795. keyInfo: this.keyInfo.toJSON(),
  12796. suppPubInfo: this.suppPubInfo.toJSON(),
  12797. };
  12798. if (this.entityUInfo) {
  12799. res.entityUInfo = this.entityUInfo.toJSON();
  12800. }
  12801. return res;
  12802. }
  12803. }
  12804. ECCCMSSharedInfo.CLASS_NAME = "ECCCMSSharedInfo";
  12805. const VERSION$8 = "version";
  12806. const ORIGINATOR_INFO = "originatorInfo";
  12807. const RECIPIENT_INFOS = "recipientInfos";
  12808. const ENCRYPTED_CONTENT_INFO = "encryptedContentInfo";
  12809. const UNPROTECTED_ATTRS = "unprotectedAttrs";
  12810. const CLEAR_PROPS$k = [
  12811. VERSION$8,
  12812. ORIGINATOR_INFO,
  12813. RECIPIENT_INFOS,
  12814. ENCRYPTED_CONTENT_INFO,
  12815. UNPROTECTED_ATTRS
  12816. ];
  12817. const defaultEncryptionParams = {
  12818. kdfAlgorithm: "SHA-512",
  12819. kekEncryptionLength: 256
  12820. };
  12821. const curveLengthByName = {
  12822. "P-256": 256,
  12823. "P-384": 384,
  12824. "P-521": 528
  12825. };
  12826. class EnvelopedData extends PkiObject {
  12827. constructor(parameters = {}) {
  12828. super();
  12829. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$8, EnvelopedData.defaultValues(VERSION$8));
  12830. if (ORIGINATOR_INFO in parameters) {
  12831. this.originatorInfo = pvutils__namespace.getParametersValue(parameters, ORIGINATOR_INFO, EnvelopedData.defaultValues(ORIGINATOR_INFO));
  12832. }
  12833. this.recipientInfos = pvutils__namespace.getParametersValue(parameters, RECIPIENT_INFOS, EnvelopedData.defaultValues(RECIPIENT_INFOS));
  12834. this.encryptedContentInfo = pvutils__namespace.getParametersValue(parameters, ENCRYPTED_CONTENT_INFO, EnvelopedData.defaultValues(ENCRYPTED_CONTENT_INFO));
  12835. if (UNPROTECTED_ATTRS in parameters) {
  12836. this.unprotectedAttrs = pvutils__namespace.getParametersValue(parameters, UNPROTECTED_ATTRS, EnvelopedData.defaultValues(UNPROTECTED_ATTRS));
  12837. }
  12838. this.policy = {
  12839. disableSplit: !!parameters.disableSplit,
  12840. };
  12841. if (parameters.schema) {
  12842. this.fromSchema(parameters.schema);
  12843. }
  12844. }
  12845. static defaultValues(memberName) {
  12846. switch (memberName) {
  12847. case VERSION$8:
  12848. return 0;
  12849. case ORIGINATOR_INFO:
  12850. return new OriginatorInfo();
  12851. case RECIPIENT_INFOS:
  12852. return [];
  12853. case ENCRYPTED_CONTENT_INFO:
  12854. return new EncryptedContentInfo();
  12855. case UNPROTECTED_ATTRS:
  12856. return [];
  12857. default:
  12858. return super.defaultValues(memberName);
  12859. }
  12860. }
  12861. static compareWithDefault(memberName, memberValue) {
  12862. switch (memberName) {
  12863. case VERSION$8:
  12864. return (memberValue === EnvelopedData.defaultValues(memberName));
  12865. case ORIGINATOR_INFO:
  12866. return ((memberValue.certs.certificates.length === 0) && (memberValue.crls.crls.length === 0));
  12867. case RECIPIENT_INFOS:
  12868. case UNPROTECTED_ATTRS:
  12869. return (memberValue.length === 0);
  12870. case ENCRYPTED_CONTENT_INFO:
  12871. return ((EncryptedContentInfo.compareWithDefault("contentType", memberValue.contentType)) &&
  12872. (EncryptedContentInfo.compareWithDefault("contentEncryptionAlgorithm", memberValue.contentEncryptionAlgorithm) &&
  12873. (EncryptedContentInfo.compareWithDefault("encryptedContent", memberValue.encryptedContent))));
  12874. default:
  12875. return super.defaultValues(memberName);
  12876. }
  12877. }
  12878. static schema(parameters = {}) {
  12879. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  12880. return (new asn1js__namespace.Sequence({
  12881. name: (names.blockName || EMPTY_STRING),
  12882. value: [
  12883. new asn1js__namespace.Integer({ name: (names.version || EMPTY_STRING) }),
  12884. new asn1js__namespace.Constructed({
  12885. name: (names.originatorInfo || EMPTY_STRING),
  12886. optional: true,
  12887. idBlock: {
  12888. tagClass: 3,
  12889. tagNumber: 0
  12890. },
  12891. value: OriginatorInfo.schema().valueBlock.value
  12892. }),
  12893. new asn1js__namespace.Set({
  12894. value: [
  12895. new asn1js__namespace.Repeated({
  12896. name: (names.recipientInfos || EMPTY_STRING),
  12897. value: RecipientInfo.schema()
  12898. })
  12899. ]
  12900. }),
  12901. EncryptedContentInfo.schema(names.encryptedContentInfo || {}),
  12902. new asn1js__namespace.Constructed({
  12903. optional: true,
  12904. idBlock: {
  12905. tagClass: 3,
  12906. tagNumber: 1
  12907. },
  12908. value: [
  12909. new asn1js__namespace.Repeated({
  12910. name: (names.unprotectedAttrs || EMPTY_STRING),
  12911. value: Attribute.schema()
  12912. })
  12913. ]
  12914. })
  12915. ]
  12916. }));
  12917. }
  12918. fromSchema(schema) {
  12919. pvutils__namespace.clearProps(schema, CLEAR_PROPS$k);
  12920. const asn1 = asn1js__namespace.compareSchema(schema, schema, EnvelopedData.schema({
  12921. names: {
  12922. version: VERSION$8,
  12923. originatorInfo: ORIGINATOR_INFO,
  12924. recipientInfos: RECIPIENT_INFOS,
  12925. encryptedContentInfo: {
  12926. names: {
  12927. blockName: ENCRYPTED_CONTENT_INFO
  12928. }
  12929. },
  12930. unprotectedAttrs: UNPROTECTED_ATTRS
  12931. }
  12932. }));
  12933. AsnError.assertSchema(asn1, this.className);
  12934. this.version = asn1.result.version.valueBlock.valueDec;
  12935. if (ORIGINATOR_INFO in asn1.result) {
  12936. this.originatorInfo = new OriginatorInfo({
  12937. schema: new asn1js__namespace.Sequence({
  12938. value: asn1.result.originatorInfo.valueBlock.value
  12939. })
  12940. });
  12941. }
  12942. this.recipientInfos = Array.from(asn1.result.recipientInfos, o => new RecipientInfo({ schema: o }));
  12943. this.encryptedContentInfo = new EncryptedContentInfo({ schema: asn1.result.encryptedContentInfo });
  12944. if (UNPROTECTED_ATTRS in asn1.result)
  12945. this.unprotectedAttrs = Array.from(asn1.result.unprotectedAttrs, o => new Attribute({ schema: o }));
  12946. }
  12947. toSchema() {
  12948. const outputArray = [];
  12949. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  12950. if (this.originatorInfo) {
  12951. outputArray.push(new asn1js__namespace.Constructed({
  12952. optional: true,
  12953. idBlock: {
  12954. tagClass: 3,
  12955. tagNumber: 0
  12956. },
  12957. value: this.originatorInfo.toSchema().valueBlock.value
  12958. }));
  12959. }
  12960. outputArray.push(new asn1js__namespace.Set({
  12961. value: Array.from(this.recipientInfos, o => o.toSchema())
  12962. }));
  12963. outputArray.push(this.encryptedContentInfo.toSchema());
  12964. if (this.unprotectedAttrs) {
  12965. outputArray.push(new asn1js__namespace.Constructed({
  12966. optional: true,
  12967. idBlock: {
  12968. tagClass: 3,
  12969. tagNumber: 1
  12970. },
  12971. value: Array.from(this.unprotectedAttrs, o => o.toSchema())
  12972. }));
  12973. }
  12974. return (new asn1js__namespace.Sequence({
  12975. value: outputArray
  12976. }));
  12977. }
  12978. toJSON() {
  12979. const res = {
  12980. version: this.version,
  12981. recipientInfos: Array.from(this.recipientInfos, o => o.toJSON()),
  12982. encryptedContentInfo: this.encryptedContentInfo.toJSON(),
  12983. };
  12984. if (this.originatorInfo)
  12985. res.originatorInfo = this.originatorInfo.toJSON();
  12986. if (this.unprotectedAttrs)
  12987. res.unprotectedAttrs = Array.from(this.unprotectedAttrs, o => o.toJSON());
  12988. return res;
  12989. }
  12990. addRecipientByCertificate(certificate, parameters, variant, crypto = getCrypto(true)) {
  12991. const encryptionParameters = Object.assign({ useOAEP: true, oaepHashAlgorithm: "SHA-512" }, defaultEncryptionParams, parameters || {});
  12992. if (certificate.subjectPublicKeyInfo.algorithm.algorithmId.indexOf("1.2.840.113549") !== (-1))
  12993. variant = 1;
  12994. else {
  12995. if (certificate.subjectPublicKeyInfo.algorithm.algorithmId.indexOf("1.2.840.10045") !== (-1))
  12996. variant = 2;
  12997. else
  12998. throw new Error(`Unknown type of certificate's public key: ${certificate.subjectPublicKeyInfo.algorithm.algorithmId}`);
  12999. }
  13000. switch (variant) {
  13001. case 1:
  13002. {
  13003. let algorithmId;
  13004. let algorithmParams;
  13005. if (encryptionParameters.useOAEP === true) {
  13006. algorithmId = crypto.getOIDByAlgorithm({
  13007. name: "RSA-OAEP"
  13008. }, true, "keyEncryptionAlgorithm");
  13009. const hashOID = crypto.getOIDByAlgorithm({
  13010. name: encryptionParameters.oaepHashAlgorithm
  13011. }, true, "RSAES-OAEP-params");
  13012. const hashAlgorithm = new AlgorithmIdentifier({
  13013. algorithmId: hashOID,
  13014. algorithmParams: new asn1js__namespace.Null()
  13015. });
  13016. const rsaOAEPParams = new RSAESOAEPParams({
  13017. hashAlgorithm,
  13018. maskGenAlgorithm: new AlgorithmIdentifier({
  13019. algorithmId: "1.2.840.113549.1.1.8",
  13020. algorithmParams: hashAlgorithm.toSchema()
  13021. })
  13022. });
  13023. algorithmParams = rsaOAEPParams.toSchema();
  13024. }
  13025. else {
  13026. algorithmId = crypto.getOIDByAlgorithm({
  13027. name: "RSAES-PKCS1-v1_5"
  13028. });
  13029. if (algorithmId === EMPTY_STRING)
  13030. throw new Error("Can not find OID for RSAES-PKCS1-v1_5");
  13031. algorithmParams = new asn1js__namespace.Null();
  13032. }
  13033. const keyInfo = new KeyTransRecipientInfo({
  13034. version: 0,
  13035. rid: new IssuerAndSerialNumber({
  13036. issuer: certificate.issuer,
  13037. serialNumber: certificate.serialNumber
  13038. }),
  13039. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13040. algorithmId,
  13041. algorithmParams
  13042. }),
  13043. recipientCertificate: certificate,
  13044. });
  13045. this.recipientInfos.push(new RecipientInfo({
  13046. variant: 1,
  13047. value: keyInfo
  13048. }));
  13049. }
  13050. break;
  13051. case 2:
  13052. {
  13053. const recipientIdentifier = new KeyAgreeRecipientIdentifier({
  13054. variant: 1,
  13055. value: new IssuerAndSerialNumber({
  13056. issuer: certificate.issuer,
  13057. serialNumber: certificate.serialNumber
  13058. })
  13059. });
  13060. this._addKeyAgreeRecipientInfo(recipientIdentifier, encryptionParameters, { recipientCertificate: certificate }, crypto);
  13061. }
  13062. break;
  13063. default:
  13064. throw new Error(`Unknown "variant" value: ${variant}`);
  13065. }
  13066. return true;
  13067. }
  13068. addRecipientByPreDefinedData(preDefinedData, parameters = {}, variant, crypto = getCrypto(true)) {
  13069. ArgumentError.assert(preDefinedData, "preDefinedData", "ArrayBuffer");
  13070. if (!preDefinedData.byteLength) {
  13071. throw new Error("Pre-defined data could have zero length");
  13072. }
  13073. if (!parameters.keyIdentifier) {
  13074. const keyIdentifierBuffer = new ArrayBuffer(16);
  13075. const keyIdentifierView = new Uint8Array(keyIdentifierBuffer);
  13076. crypto.getRandomValues(keyIdentifierView);
  13077. parameters.keyIdentifier = keyIdentifierBuffer;
  13078. }
  13079. if (!parameters.hmacHashAlgorithm)
  13080. parameters.hmacHashAlgorithm = "SHA-512";
  13081. if (parameters.iterationCount === undefined) {
  13082. parameters.iterationCount = 2048;
  13083. }
  13084. if (!parameters.keyEncryptionAlgorithm) {
  13085. parameters.keyEncryptionAlgorithm = {
  13086. name: "AES-KW",
  13087. length: 256
  13088. };
  13089. }
  13090. if (!parameters.keyEncryptionAlgorithmParams)
  13091. parameters.keyEncryptionAlgorithmParams = new asn1js__namespace.Null();
  13092. switch (variant) {
  13093. case 1:
  13094. {
  13095. const kekOID = crypto.getOIDByAlgorithm(parameters.keyEncryptionAlgorithm, true, "keyEncryptionAlgorithm");
  13096. const keyInfo = new KEKRecipientInfo({
  13097. version: 4,
  13098. kekid: new KEKIdentifier({
  13099. keyIdentifier: new asn1js__namespace.OctetString({ valueHex: parameters.keyIdentifier })
  13100. }),
  13101. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13102. algorithmId: kekOID,
  13103. algorithmParams: parameters.keyEncryptionAlgorithmParams
  13104. }),
  13105. preDefinedKEK: preDefinedData
  13106. });
  13107. this.recipientInfos.push(new RecipientInfo({
  13108. variant: 3,
  13109. value: keyInfo
  13110. }));
  13111. }
  13112. break;
  13113. case 2:
  13114. {
  13115. const pbkdf2OID = crypto.getOIDByAlgorithm({ name: "PBKDF2" }, true, "keyDerivationAlgorithm");
  13116. const saltBuffer = new ArrayBuffer(64);
  13117. const saltView = new Uint8Array(saltBuffer);
  13118. crypto.getRandomValues(saltView);
  13119. const hmacOID = crypto.getOIDByAlgorithm({
  13120. name: "HMAC",
  13121. hash: {
  13122. name: parameters.hmacHashAlgorithm
  13123. }
  13124. }, true, "hmacHashAlgorithm");
  13125. const pbkdf2Params = new PBKDF2Params({
  13126. salt: new asn1js__namespace.OctetString({ valueHex: saltBuffer }),
  13127. iterationCount: parameters.iterationCount,
  13128. prf: new AlgorithmIdentifier({
  13129. algorithmId: hmacOID,
  13130. algorithmParams: new asn1js__namespace.Null()
  13131. })
  13132. });
  13133. const kekOID = crypto.getOIDByAlgorithm(parameters.keyEncryptionAlgorithm, true, "keyEncryptionAlgorithm");
  13134. const keyInfo = new PasswordRecipientinfo({
  13135. version: 0,
  13136. keyDerivationAlgorithm: new AlgorithmIdentifier({
  13137. algorithmId: pbkdf2OID,
  13138. algorithmParams: pbkdf2Params.toSchema()
  13139. }),
  13140. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13141. algorithmId: kekOID,
  13142. algorithmParams: parameters.keyEncryptionAlgorithmParams
  13143. }),
  13144. password: preDefinedData
  13145. });
  13146. this.recipientInfos.push(new RecipientInfo({
  13147. variant: 4,
  13148. value: keyInfo
  13149. }));
  13150. }
  13151. break;
  13152. default:
  13153. throw new Error(`Unknown value for "variant": ${variant}`);
  13154. }
  13155. }
  13156. addRecipientByKeyIdentifier(key, keyId, parameters, crypto = getCrypto(true)) {
  13157. const encryptionParameters = Object.assign({}, defaultEncryptionParams, parameters || {});
  13158. const recipientIdentifier = new KeyAgreeRecipientIdentifier({
  13159. variant: 2,
  13160. value: new RecipientKeyIdentifier({
  13161. subjectKeyIdentifier: new asn1js__namespace.OctetString({ valueHex: keyId }),
  13162. })
  13163. });
  13164. this._addKeyAgreeRecipientInfo(recipientIdentifier, encryptionParameters, { recipientPublicKey: key }, crypto);
  13165. }
  13166. _addKeyAgreeRecipientInfo(recipientIdentifier, encryptionParameters, extraRecipientInfoParams, crypto = getCrypto(true)) {
  13167. const encryptedKey = new RecipientEncryptedKey({
  13168. rid: recipientIdentifier
  13169. });
  13170. const aesKWoid = crypto.getOIDByAlgorithm({
  13171. name: "AES-KW",
  13172. length: encryptionParameters.kekEncryptionLength
  13173. }, true, "keyEncryptionAlgorithm");
  13174. const aesKW = new AlgorithmIdentifier({
  13175. algorithmId: aesKWoid,
  13176. });
  13177. const ecdhOID = crypto.getOIDByAlgorithm({
  13178. name: "ECDH",
  13179. kdf: encryptionParameters.kdfAlgorithm
  13180. }, true, "KeyAgreeRecipientInfo");
  13181. const ukmBuffer = new ArrayBuffer(64);
  13182. const ukmView = new Uint8Array(ukmBuffer);
  13183. crypto.getRandomValues(ukmView);
  13184. const recipientInfoParams = {
  13185. version: 3,
  13186. ukm: new asn1js__namespace.OctetString({ valueHex: ukmBuffer }),
  13187. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13188. algorithmId: ecdhOID,
  13189. algorithmParams: aesKW.toSchema()
  13190. }),
  13191. recipientEncryptedKeys: new RecipientEncryptedKeys({
  13192. encryptedKeys: [encryptedKey]
  13193. })
  13194. };
  13195. const keyInfo = new KeyAgreeRecipientInfo(Object.assign(recipientInfoParams, extraRecipientInfoParams));
  13196. this.recipientInfos.push(new RecipientInfo({
  13197. variant: 2,
  13198. value: keyInfo
  13199. }));
  13200. }
  13201. async encrypt(contentEncryptionAlgorithm, contentToEncrypt, crypto = getCrypto(true)) {
  13202. const ivBuffer = new ArrayBuffer(16);
  13203. const ivView = new Uint8Array(ivBuffer);
  13204. crypto.getRandomValues(ivView);
  13205. const contentView = new Uint8Array(contentToEncrypt);
  13206. const contentEncryptionOID = crypto.getOIDByAlgorithm(contentEncryptionAlgorithm, true, "contentEncryptionAlgorithm");
  13207. const sessionKey = await crypto.generateKey(contentEncryptionAlgorithm, true, ["encrypt"]);
  13208. const encryptedContent = await crypto.encrypt({
  13209. name: contentEncryptionAlgorithm.name,
  13210. iv: ivView
  13211. }, sessionKey, contentView);
  13212. const exportedSessionKey = await crypto.exportKey("raw", sessionKey);
  13213. this.version = 2;
  13214. this.encryptedContentInfo = new EncryptedContentInfo({
  13215. disableSplit: this.policy.disableSplit,
  13216. contentType: "1.2.840.113549.1.7.1",
  13217. contentEncryptionAlgorithm: new AlgorithmIdentifier({
  13218. algorithmId: contentEncryptionOID,
  13219. algorithmParams: new asn1js__namespace.OctetString({ valueHex: ivBuffer })
  13220. }),
  13221. encryptedContent: new asn1js__namespace.OctetString({ valueHex: encryptedContent })
  13222. });
  13223. const SubKeyAgreeRecipientInfo = async (index) => {
  13224. const recipientInfo = this.recipientInfos[index].value;
  13225. let recipientCurve;
  13226. let recipientPublicKey;
  13227. if (recipientInfo.recipientPublicKey) {
  13228. recipientCurve = recipientInfo.recipientPublicKey.algorithm.namedCurve;
  13229. recipientPublicKey = recipientInfo.recipientPublicKey;
  13230. }
  13231. else if (recipientInfo.recipientCertificate) {
  13232. const curveObject = recipientInfo.recipientCertificate.subjectPublicKeyInfo.algorithm.algorithmParams;
  13233. if (curveObject.constructor.blockName() !== asn1js__namespace.ObjectIdentifier.blockName())
  13234. throw new Error(`Incorrect "recipientCertificate" for index ${index}`);
  13235. const curveOID = curveObject.valueBlock.toString();
  13236. switch (curveOID) {
  13237. case "1.2.840.10045.3.1.7":
  13238. recipientCurve = "P-256";
  13239. break;
  13240. case "1.3.132.0.34":
  13241. recipientCurve = "P-384";
  13242. break;
  13243. case "1.3.132.0.35":
  13244. recipientCurve = "P-521";
  13245. break;
  13246. default:
  13247. throw new Error(`Incorrect curve OID for index ${index}`);
  13248. }
  13249. recipientPublicKey = await recipientInfo.recipientCertificate.getPublicKey({
  13250. algorithm: {
  13251. algorithm: {
  13252. name: "ECDH",
  13253. namedCurve: recipientCurve
  13254. },
  13255. usages: []
  13256. }
  13257. }, crypto);
  13258. }
  13259. else {
  13260. throw new Error("Unsupported RecipientInfo");
  13261. }
  13262. const recipientCurveLength = curveLengthByName[recipientCurve];
  13263. const ecdhKeys = await crypto.generateKey({ name: "ECDH", namedCurve: recipientCurve }, true, ["deriveBits"]);
  13264. const exportedECDHPublicKey = await crypto.exportKey("spki", ecdhKeys.publicKey);
  13265. const derivedBits = await crypto.deriveBits({
  13266. name: "ECDH",
  13267. public: recipientPublicKey
  13268. }, ecdhKeys.privateKey, recipientCurveLength);
  13269. const aesKWAlgorithm = new AlgorithmIdentifier({ schema: recipientInfo.keyEncryptionAlgorithm.algorithmParams });
  13270. const kwAlgorithm = crypto.getAlgorithmByOID(aesKWAlgorithm.algorithmId, true, "aesKWAlgorithm");
  13271. let kwLength = kwAlgorithm.length;
  13272. const kwLengthBuffer = new ArrayBuffer(4);
  13273. const kwLengthView = new Uint8Array(kwLengthBuffer);
  13274. for (let j = 3; j >= 0; j--) {
  13275. kwLengthView[j] = kwLength;
  13276. kwLength >>= 8;
  13277. }
  13278. const eccInfo = new ECCCMSSharedInfo({
  13279. keyInfo: new AlgorithmIdentifier({
  13280. algorithmId: aesKWAlgorithm.algorithmId
  13281. }),
  13282. entityUInfo: recipientInfo.ukm,
  13283. suppPubInfo: new asn1js__namespace.OctetString({ valueHex: kwLengthBuffer })
  13284. });
  13285. const encodedInfo = eccInfo.toSchema().toBER(false);
  13286. const ecdhAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "ecdhAlgorithm");
  13287. const derivedKeyRaw = await kdf(ecdhAlgorithm.kdf, derivedBits, kwAlgorithm.length, encodedInfo, crypto);
  13288. const awsKW = await crypto.importKey("raw", derivedKeyRaw, { name: "AES-KW" }, true, ["wrapKey"]);
  13289. const wrappedKey = await crypto.wrapKey("raw", sessionKey, awsKW, { name: "AES-KW" });
  13290. const originator = new OriginatorIdentifierOrKey();
  13291. originator.variant = 3;
  13292. originator.value = OriginatorPublicKey.fromBER(exportedECDHPublicKey);
  13293. recipientInfo.originator = originator;
  13294. recipientInfo.recipientEncryptedKeys.encryptedKeys[0].encryptedKey = new asn1js__namespace.OctetString({ valueHex: wrappedKey });
  13295. return { ecdhPrivateKey: ecdhKeys.privateKey };
  13296. };
  13297. const SubKeyTransRecipientInfo = async (index) => {
  13298. const recipientInfo = this.recipientInfos[index].value;
  13299. const algorithmParameters = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "keyEncryptionAlgorithm");
  13300. if (algorithmParameters.name === "RSA-OAEP") {
  13301. const schema = recipientInfo.keyEncryptionAlgorithm.algorithmParams;
  13302. const rsaOAEPParams = new RSAESOAEPParams({ schema });
  13303. algorithmParameters.hash = crypto.getAlgorithmByOID(rsaOAEPParams.hashAlgorithm.algorithmId);
  13304. if (("name" in algorithmParameters.hash) === false)
  13305. throw new Error(`Incorrect OID for hash algorithm: ${rsaOAEPParams.hashAlgorithm.algorithmId}`);
  13306. }
  13307. try {
  13308. const publicKey = await recipientInfo.recipientCertificate.getPublicKey({
  13309. algorithm: {
  13310. algorithm: algorithmParameters,
  13311. usages: ["encrypt", "wrapKey"]
  13312. }
  13313. }, crypto);
  13314. const encryptedKey = await crypto.encrypt(publicKey.algorithm, publicKey, exportedSessionKey);
  13315. recipientInfo.encryptedKey = new asn1js__namespace.OctetString({ valueHex: encryptedKey });
  13316. }
  13317. catch {
  13318. }
  13319. };
  13320. const SubKEKRecipientInfo = async (index) => {
  13321. const recipientInfo = this.recipientInfos[index].value;
  13322. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "kekAlgorithm");
  13323. const kekKey = await crypto.importKey("raw", new Uint8Array(recipientInfo.preDefinedKEK), kekAlgorithm, true, ["wrapKey"]);
  13324. const wrappedKey = await crypto.wrapKey("raw", sessionKey, kekKey, kekAlgorithm);
  13325. recipientInfo.encryptedKey = new asn1js__namespace.OctetString({ valueHex: wrappedKey });
  13326. };
  13327. const SubPasswordRecipientinfo = async (index) => {
  13328. const recipientInfo = this.recipientInfos[index].value;
  13329. let pbkdf2Params;
  13330. if (!recipientInfo.keyDerivationAlgorithm)
  13331. throw new Error("Please append encoded \"keyDerivationAlgorithm\"");
  13332. if (!recipientInfo.keyDerivationAlgorithm.algorithmParams)
  13333. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13334. try {
  13335. pbkdf2Params = new PBKDF2Params({ schema: recipientInfo.keyDerivationAlgorithm.algorithmParams });
  13336. }
  13337. catch {
  13338. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13339. }
  13340. const passwordView = new Uint8Array(recipientInfo.password);
  13341. const derivationKey = await crypto.importKey("raw", passwordView, "PBKDF2", false, ["deriveKey"]);
  13342. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "kekAlgorithm");
  13343. let hmacHashAlgorithm = "SHA-1";
  13344. if (pbkdf2Params.prf) {
  13345. const prfAlgorithm = crypto.getAlgorithmByOID(pbkdf2Params.prf.algorithmId, true, "prfAlgorithm");
  13346. hmacHashAlgorithm = prfAlgorithm.hash.name;
  13347. }
  13348. const saltView = new Uint8Array(pbkdf2Params.salt.valueBlock.valueHex);
  13349. const iterations = pbkdf2Params.iterationCount;
  13350. const derivedKey = await crypto.deriveKey({
  13351. name: "PBKDF2",
  13352. hash: {
  13353. name: hmacHashAlgorithm
  13354. },
  13355. salt: saltView,
  13356. iterations
  13357. }, derivationKey, kekAlgorithm, true, ["wrapKey"]);
  13358. const wrappedKey = await crypto.wrapKey("raw", sessionKey, derivedKey, kekAlgorithm);
  13359. recipientInfo.encryptedKey = new asn1js__namespace.OctetString({ valueHex: wrappedKey });
  13360. };
  13361. const res = [];
  13362. for (let i = 0; i < this.recipientInfos.length; i++) {
  13363. switch (this.recipientInfos[i].variant) {
  13364. case 1:
  13365. res.push(await SubKeyTransRecipientInfo(i));
  13366. break;
  13367. case 2:
  13368. res.push(await SubKeyAgreeRecipientInfo(i));
  13369. break;
  13370. case 3:
  13371. res.push(await SubKEKRecipientInfo(i));
  13372. break;
  13373. case 4:
  13374. res.push(await SubPasswordRecipientinfo(i));
  13375. break;
  13376. default:
  13377. throw new Error(`Unknown recipient type in array with index ${i}`);
  13378. }
  13379. }
  13380. return res;
  13381. }
  13382. async decrypt(recipientIndex, parameters, crypto = getCrypto(true)) {
  13383. const decryptionParameters = parameters || {};
  13384. if ((recipientIndex + 1) > this.recipientInfos.length) {
  13385. throw new Error(`Maximum value for "index" is: ${this.recipientInfos.length - 1}`);
  13386. }
  13387. const SubKeyAgreeRecipientInfo = async (index) => {
  13388. const recipientInfo = this.recipientInfos[index].value;
  13389. let curveOID;
  13390. let recipientCurve;
  13391. let recipientCurveLength;
  13392. const originator = recipientInfo.originator;
  13393. if (decryptionParameters.recipientCertificate) {
  13394. const curveObject = decryptionParameters.recipientCertificate.subjectPublicKeyInfo.algorithm.algorithmParams;
  13395. if (curveObject.constructor.blockName() !== asn1js__namespace.ObjectIdentifier.blockName()) {
  13396. throw new Error(`Incorrect "recipientCertificate" for index ${index}`);
  13397. }
  13398. curveOID = curveObject.valueBlock.toString();
  13399. }
  13400. else if (originator.value.algorithm.algorithmParams) {
  13401. const curveObject = originator.value.algorithm.algorithmParams;
  13402. if (curveObject.constructor.blockName() !== asn1js__namespace.ObjectIdentifier.blockName()) {
  13403. throw new Error(`Incorrect originator for index ${index}`);
  13404. }
  13405. curveOID = curveObject.valueBlock.toString();
  13406. }
  13407. else {
  13408. throw new Error("Parameter \"recipientCertificate\" is mandatory for \"KeyAgreeRecipientInfo\" if algorithm params are missing from originator");
  13409. }
  13410. if (!decryptionParameters.recipientPrivateKey)
  13411. throw new Error("Parameter \"recipientPrivateKey\" is mandatory for \"KeyAgreeRecipientInfo\"");
  13412. switch (curveOID) {
  13413. case "1.2.840.10045.3.1.7":
  13414. recipientCurve = "P-256";
  13415. recipientCurveLength = 256;
  13416. break;
  13417. case "1.3.132.0.34":
  13418. recipientCurve = "P-384";
  13419. recipientCurveLength = 384;
  13420. break;
  13421. case "1.3.132.0.35":
  13422. recipientCurve = "P-521";
  13423. recipientCurveLength = 528;
  13424. break;
  13425. default:
  13426. throw new Error(`Incorrect curve OID for index ${index}`);
  13427. }
  13428. let ecdhPrivateKey;
  13429. let keyCrypto = crypto;
  13430. if (pvtsutils.BufferSourceConverter.isBufferSource(decryptionParameters.recipientPrivateKey)) {
  13431. ecdhPrivateKey = await crypto.importKey("pkcs8", decryptionParameters.recipientPrivateKey, {
  13432. name: "ECDH",
  13433. namedCurve: recipientCurve
  13434. }, true, ["deriveBits"]);
  13435. }
  13436. else {
  13437. ecdhPrivateKey = decryptionParameters.recipientPrivateKey;
  13438. if ("crypto" in decryptionParameters && decryptionParameters.crypto) {
  13439. keyCrypto = decryptionParameters.crypto.subtle;
  13440. }
  13441. }
  13442. if (("algorithmParams" in originator.value.algorithm) === false)
  13443. originator.value.algorithm.algorithmParams = new asn1js__namespace.ObjectIdentifier({ value: curveOID });
  13444. const buffer = originator.value.toSchema().toBER(false);
  13445. const ecdhPublicKey = await crypto.importKey("spki", buffer, {
  13446. name: "ECDH",
  13447. namedCurve: recipientCurve
  13448. }, true, []);
  13449. const sharedSecret = await keyCrypto.deriveBits({
  13450. name: "ECDH",
  13451. public: ecdhPublicKey
  13452. }, ecdhPrivateKey, recipientCurveLength);
  13453. async function applyKDF(includeAlgorithmParams) {
  13454. includeAlgorithmParams = includeAlgorithmParams || false;
  13455. const aesKWAlgorithm = new AlgorithmIdentifier({ schema: recipientInfo.keyEncryptionAlgorithm.algorithmParams });
  13456. const kwAlgorithm = crypto.getAlgorithmByOID(aesKWAlgorithm.algorithmId, true, "kwAlgorithm");
  13457. let kwLength = kwAlgorithm.length;
  13458. const kwLengthBuffer = new ArrayBuffer(4);
  13459. const kwLengthView = new Uint8Array(kwLengthBuffer);
  13460. for (let j = 3; j >= 0; j--) {
  13461. kwLengthView[j] = kwLength;
  13462. kwLength >>= 8;
  13463. }
  13464. const keyInfoAlgorithm = {
  13465. algorithmId: aesKWAlgorithm.algorithmId
  13466. };
  13467. if (includeAlgorithmParams) {
  13468. keyInfoAlgorithm.algorithmParams = new asn1js__namespace.Null();
  13469. }
  13470. const eccInfo = new ECCCMSSharedInfo({
  13471. keyInfo: new AlgorithmIdentifier(keyInfoAlgorithm),
  13472. entityUInfo: recipientInfo.ukm,
  13473. suppPubInfo: new asn1js__namespace.OctetString({ valueHex: kwLengthBuffer })
  13474. });
  13475. const encodedInfo = eccInfo.toSchema().toBER(false);
  13476. const ecdhAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "ecdhAlgorithm");
  13477. if (!ecdhAlgorithm.name) {
  13478. throw new Error(`Incorrect OID for key encryption algorithm: ${recipientInfo.keyEncryptionAlgorithm.algorithmId}`);
  13479. }
  13480. return kdf(ecdhAlgorithm.kdf, sharedSecret, kwAlgorithm.length, encodedInfo, crypto);
  13481. }
  13482. const kdfResult = await applyKDF();
  13483. const importAesKwKey = async (kdfResult) => {
  13484. return crypto.importKey("raw", kdfResult, { name: "AES-KW" }, true, ["unwrapKey"]);
  13485. };
  13486. const aesKwKey = await importAesKwKey(kdfResult);
  13487. const unwrapSessionKey = async (aesKwKey) => {
  13488. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13489. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13490. return crypto.unwrapKey("raw", recipientInfo.recipientEncryptedKeys.encryptedKeys[0].encryptedKey.valueBlock.valueHexView, aesKwKey, { name: "AES-KW" }, contentEncryptionAlgorithm, true, ["decrypt"]);
  13491. };
  13492. try {
  13493. return await unwrapSessionKey(aesKwKey);
  13494. }
  13495. catch {
  13496. const kdfResult = await applyKDF(true);
  13497. const aesKwKey = await importAesKwKey(kdfResult);
  13498. return unwrapSessionKey(aesKwKey);
  13499. }
  13500. };
  13501. const SubKeyTransRecipientInfo = async (index) => {
  13502. const recipientInfo = this.recipientInfos[index].value;
  13503. if (!decryptionParameters.recipientPrivateKey) {
  13504. throw new Error("Parameter \"recipientPrivateKey\" is mandatory for \"KeyTransRecipientInfo\"");
  13505. }
  13506. const algorithmParameters = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "keyEncryptionAlgorithm");
  13507. if (algorithmParameters.name === "RSA-OAEP") {
  13508. const schema = recipientInfo.keyEncryptionAlgorithm.algorithmParams;
  13509. const rsaOAEPParams = new RSAESOAEPParams({ schema });
  13510. algorithmParameters.hash = crypto.getAlgorithmByOID(rsaOAEPParams.hashAlgorithm.algorithmId);
  13511. if (("name" in algorithmParameters.hash) === false)
  13512. throw new Error(`Incorrect OID for hash algorithm: ${rsaOAEPParams.hashAlgorithm.algorithmId}`);
  13513. }
  13514. let privateKey;
  13515. let keyCrypto = crypto;
  13516. if (pvtsutils.BufferSourceConverter.isBufferSource(decryptionParameters.recipientPrivateKey)) {
  13517. privateKey = await crypto.importKey("pkcs8", decryptionParameters.recipientPrivateKey, algorithmParameters, true, ["decrypt"]);
  13518. }
  13519. else {
  13520. privateKey = decryptionParameters.recipientPrivateKey;
  13521. if ("crypto" in decryptionParameters && decryptionParameters.crypto) {
  13522. keyCrypto = decryptionParameters.crypto.subtle;
  13523. }
  13524. }
  13525. const sessionKey = await keyCrypto.decrypt(privateKey.algorithm, privateKey, recipientInfo.encryptedKey.valueBlock.valueHexView);
  13526. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13527. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13528. if (("name" in contentEncryptionAlgorithm) === false)
  13529. throw new Error(`Incorrect "contentEncryptionAlgorithm": ${algorithmId}`);
  13530. return crypto.importKey("raw", sessionKey, contentEncryptionAlgorithm, true, ["decrypt"]);
  13531. };
  13532. const SubKEKRecipientInfo = async (index) => {
  13533. const recipientInfo = this.recipientInfos[index].value;
  13534. if (!decryptionParameters.preDefinedData)
  13535. throw new Error("Parameter \"preDefinedData\" is mandatory for \"KEKRecipientInfo\"");
  13536. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "kekAlgorithm");
  13537. const importedKey = await crypto.importKey("raw", decryptionParameters.preDefinedData, kekAlgorithm, true, ["unwrapKey"]);
  13538. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13539. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13540. if (!contentEncryptionAlgorithm.name) {
  13541. throw new Error(`Incorrect "contentEncryptionAlgorithm": ${algorithmId}`);
  13542. }
  13543. return crypto.unwrapKey("raw", recipientInfo.encryptedKey.valueBlock.valueHexView, importedKey, kekAlgorithm, contentEncryptionAlgorithm, true, ["decrypt"]);
  13544. };
  13545. const SubPasswordRecipientinfo = async (index) => {
  13546. const recipientInfo = this.recipientInfos[index].value;
  13547. let pbkdf2Params;
  13548. if (!decryptionParameters.preDefinedData) {
  13549. throw new Error("Parameter \"preDefinedData\" is mandatory for \"KEKRecipientInfo\"");
  13550. }
  13551. if (!recipientInfo.keyDerivationAlgorithm) {
  13552. throw new Error("Please append encoded \"keyDerivationAlgorithm\"");
  13553. }
  13554. if (!recipientInfo.keyDerivationAlgorithm.algorithmParams) {
  13555. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13556. }
  13557. try {
  13558. pbkdf2Params = new PBKDF2Params({ schema: recipientInfo.keyDerivationAlgorithm.algorithmParams });
  13559. }
  13560. catch {
  13561. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13562. }
  13563. const pbkdf2Key = await crypto.importKey("raw", decryptionParameters.preDefinedData, "PBKDF2", false, ["deriveKey"]);
  13564. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "keyEncryptionAlgorithm");
  13565. const hmacHashAlgorithm = pbkdf2Params.prf
  13566. ? crypto.getAlgorithmByOID(pbkdf2Params.prf.algorithmId, true, "prfAlgorithm").hash.name
  13567. : "SHA-1";
  13568. const saltView = new Uint8Array(pbkdf2Params.salt.valueBlock.valueHex);
  13569. const iterations = pbkdf2Params.iterationCount;
  13570. const kekKey = await crypto.deriveKey({
  13571. name: "PBKDF2",
  13572. hash: {
  13573. name: hmacHashAlgorithm
  13574. },
  13575. salt: saltView,
  13576. iterations
  13577. }, pbkdf2Key, kekAlgorithm, true, ["unwrapKey"]);
  13578. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13579. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13580. return crypto.unwrapKey("raw", recipientInfo.encryptedKey.valueBlock.valueHexView, kekKey, kekAlgorithm, contentEncryptionAlgorithm, true, ["decrypt"]);
  13581. };
  13582. let unwrappedKey;
  13583. switch (this.recipientInfos[recipientIndex].variant) {
  13584. case 1:
  13585. unwrappedKey = await SubKeyTransRecipientInfo(recipientIndex);
  13586. break;
  13587. case 2:
  13588. unwrappedKey = await SubKeyAgreeRecipientInfo(recipientIndex);
  13589. break;
  13590. case 3:
  13591. unwrappedKey = await SubKEKRecipientInfo(recipientIndex);
  13592. break;
  13593. case 4:
  13594. unwrappedKey = await SubPasswordRecipientinfo(recipientIndex);
  13595. break;
  13596. default:
  13597. throw new Error(`Unknown recipient type in array with index ${recipientIndex}`);
  13598. }
  13599. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13600. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13601. const ivBuffer = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmParams.valueBlock.valueHex;
  13602. const ivView = new Uint8Array(ivBuffer);
  13603. if (!this.encryptedContentInfo.encryptedContent) {
  13604. throw new Error("Required property `encryptedContent` is empty");
  13605. }
  13606. const dataBuffer = this.encryptedContentInfo.getEncryptedContent();
  13607. return crypto.decrypt({
  13608. name: contentEncryptionAlgorithm.name,
  13609. iv: ivView
  13610. }, unwrappedKey, dataBuffer);
  13611. }
  13612. }
  13613. EnvelopedData.CLASS_NAME = "EnvelopedData";
  13614. const SAFE_CONTENTS = "safeContents";
  13615. const PARSED_VALUE$1 = "parsedValue";
  13616. const CONTENT_INFOS = "contentInfos";
  13617. class AuthenticatedSafe extends PkiObject {
  13618. constructor(parameters = {}) {
  13619. super();
  13620. this.safeContents = pvutils__namespace.getParametersValue(parameters, SAFE_CONTENTS, AuthenticatedSafe.defaultValues(SAFE_CONTENTS));
  13621. if (PARSED_VALUE$1 in parameters) {
  13622. this.parsedValue = pvutils__namespace.getParametersValue(parameters, PARSED_VALUE$1, AuthenticatedSafe.defaultValues(PARSED_VALUE$1));
  13623. }
  13624. if (parameters.schema) {
  13625. this.fromSchema(parameters.schema);
  13626. }
  13627. }
  13628. static defaultValues(memberName) {
  13629. switch (memberName) {
  13630. case SAFE_CONTENTS:
  13631. return [];
  13632. case PARSED_VALUE$1:
  13633. return {};
  13634. default:
  13635. return super.defaultValues(memberName);
  13636. }
  13637. }
  13638. static compareWithDefault(memberName, memberValue) {
  13639. switch (memberName) {
  13640. case SAFE_CONTENTS:
  13641. return (memberValue.length === 0);
  13642. case PARSED_VALUE$1:
  13643. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  13644. default:
  13645. return super.defaultValues(memberName);
  13646. }
  13647. }
  13648. static schema(parameters = {}) {
  13649. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  13650. return (new asn1js__namespace.Sequence({
  13651. name: (names.blockName || EMPTY_STRING),
  13652. value: [
  13653. new asn1js__namespace.Repeated({
  13654. name: (names.contentInfos || EMPTY_STRING),
  13655. value: ContentInfo.schema()
  13656. })
  13657. ]
  13658. }));
  13659. }
  13660. fromSchema(schema) {
  13661. pvutils__namespace.clearProps(schema, [
  13662. CONTENT_INFOS
  13663. ]);
  13664. const asn1 = asn1js__namespace.compareSchema(schema, schema, AuthenticatedSafe.schema({
  13665. names: {
  13666. contentInfos: CONTENT_INFOS
  13667. }
  13668. }));
  13669. AsnError.assertSchema(asn1, this.className);
  13670. this.safeContents = Array.from(asn1.result.contentInfos, element => new ContentInfo({ schema: element }));
  13671. }
  13672. toSchema() {
  13673. return (new asn1js__namespace.Sequence({
  13674. value: Array.from(this.safeContents, o => o.toSchema())
  13675. }));
  13676. }
  13677. toJSON() {
  13678. return {
  13679. safeContents: Array.from(this.safeContents, o => o.toJSON())
  13680. };
  13681. }
  13682. async parseInternalValues(parameters, crypto = getCrypto(true)) {
  13683. ParameterError.assert(parameters, SAFE_CONTENTS);
  13684. ArgumentError.assert(parameters.safeContents, SAFE_CONTENTS, "Array");
  13685. if (parameters.safeContents.length !== this.safeContents.length) {
  13686. throw new ArgumentError("Length of \"parameters.safeContents\" must be equal to \"this.safeContents.length\"");
  13687. }
  13688. this.parsedValue = {
  13689. safeContents: [],
  13690. };
  13691. for (const [index, content] of this.safeContents.entries()) {
  13692. const safeContent = parameters.safeContents[index];
  13693. const errorTarget = `parameters.safeContents[${index}]`;
  13694. switch (content.contentType) {
  13695. case id_ContentType_Data:
  13696. {
  13697. ArgumentError.assert(content.content, "this.safeContents[j].content", asn1js__namespace.OctetString);
  13698. const authSafeContent = content.content.getValue();
  13699. this.parsedValue.safeContents.push({
  13700. privacyMode: 0,
  13701. value: SafeContents.fromBER(authSafeContent)
  13702. });
  13703. }
  13704. break;
  13705. case id_ContentType_EnvelopedData:
  13706. {
  13707. const cmsEnveloped = new EnvelopedData({ schema: content.content });
  13708. ParameterError.assert(errorTarget, safeContent, "recipientCertificate", "recipientKey");
  13709. const envelopedData = safeContent;
  13710. const recipientCertificate = envelopedData.recipientCertificate;
  13711. const recipientKey = envelopedData.recipientKey;
  13712. const decrypted = await cmsEnveloped.decrypt(0, {
  13713. recipientCertificate,
  13714. recipientPrivateKey: recipientKey
  13715. }, crypto);
  13716. this.parsedValue.safeContents.push({
  13717. privacyMode: 2,
  13718. value: SafeContents.fromBER(decrypted),
  13719. });
  13720. }
  13721. break;
  13722. case id_ContentType_EncryptedData:
  13723. {
  13724. const cmsEncrypted = new EncryptedData({ schema: content.content });
  13725. ParameterError.assert(errorTarget, safeContent, "password");
  13726. const password = safeContent.password;
  13727. const decrypted = await cmsEncrypted.decrypt({
  13728. password
  13729. }, crypto);
  13730. this.parsedValue.safeContents.push({
  13731. privacyMode: 1,
  13732. value: SafeContents.fromBER(decrypted),
  13733. });
  13734. }
  13735. break;
  13736. default:
  13737. throw new Error(`Unknown "contentType" for AuthenticatedSafe: " ${content.contentType}`);
  13738. }
  13739. }
  13740. }
  13741. async makeInternalValues(parameters, crypto = getCrypto(true)) {
  13742. if (!(this.parsedValue)) {
  13743. throw new Error("Please run \"parseValues\" first or add \"parsedValue\" manually");
  13744. }
  13745. ArgumentError.assert(this.parsedValue, "this.parsedValue", "object");
  13746. ArgumentError.assert(this.parsedValue.safeContents, "this.parsedValue.safeContents", "Array");
  13747. ArgumentError.assert(parameters, "parameters", "object");
  13748. ParameterError.assert(parameters, "safeContents");
  13749. ArgumentError.assert(parameters.safeContents, "parameters.safeContents", "Array");
  13750. if (parameters.safeContents.length !== this.parsedValue.safeContents.length) {
  13751. throw new ArgumentError("Length of \"parameters.safeContents\" must be equal to \"this.parsedValue.safeContents\"");
  13752. }
  13753. this.safeContents = [];
  13754. for (const [index, content] of this.parsedValue.safeContents.entries()) {
  13755. ParameterError.assert("content", content, "privacyMode", "value");
  13756. ArgumentError.assert(content.value, "content.value", SafeContents);
  13757. switch (content.privacyMode) {
  13758. case 0:
  13759. {
  13760. const contentBuffer = content.value.toSchema().toBER(false);
  13761. this.safeContents.push(new ContentInfo({
  13762. contentType: "1.2.840.113549.1.7.1",
  13763. content: new asn1js__namespace.OctetString({ valueHex: contentBuffer })
  13764. }));
  13765. }
  13766. break;
  13767. case 1:
  13768. {
  13769. const cmsEncrypted = new EncryptedData();
  13770. const currentParameters = parameters.safeContents[index];
  13771. currentParameters.contentToEncrypt = content.value.toSchema().toBER(false);
  13772. await cmsEncrypted.encrypt(currentParameters, crypto);
  13773. this.safeContents.push(new ContentInfo({
  13774. contentType: "1.2.840.113549.1.7.6",
  13775. content: cmsEncrypted.toSchema()
  13776. }));
  13777. }
  13778. break;
  13779. case 2:
  13780. {
  13781. const cmsEnveloped = new EnvelopedData();
  13782. const contentToEncrypt = content.value.toSchema().toBER(false);
  13783. const safeContent = parameters.safeContents[index];
  13784. ParameterError.assert(`parameters.safeContents[${index}]`, safeContent, "encryptingCertificate", "encryptionAlgorithm");
  13785. switch (true) {
  13786. case (safeContent.encryptionAlgorithm.name.toLowerCase() === "aes-cbc"):
  13787. case (safeContent.encryptionAlgorithm.name.toLowerCase() === "aes-gcm"):
  13788. break;
  13789. default:
  13790. throw new Error(`Incorrect parameter "encryptionAlgorithm" in "parameters.safeContents[i]": ${safeContent.encryptionAlgorithm}`);
  13791. }
  13792. switch (true) {
  13793. case (safeContent.encryptionAlgorithm.length === 128):
  13794. case (safeContent.encryptionAlgorithm.length === 192):
  13795. case (safeContent.encryptionAlgorithm.length === 256):
  13796. break;
  13797. default:
  13798. throw new Error(`Incorrect parameter "encryptionAlgorithm.length" in "parameters.safeContents[i]": ${safeContent.encryptionAlgorithm.length}`);
  13799. }
  13800. const encryptionAlgorithm = safeContent.encryptionAlgorithm;
  13801. cmsEnveloped.addRecipientByCertificate(safeContent.encryptingCertificate, {}, undefined, crypto);
  13802. await cmsEnveloped.encrypt(encryptionAlgorithm, contentToEncrypt, crypto);
  13803. this.safeContents.push(new ContentInfo({
  13804. contentType: "1.2.840.113549.1.7.3",
  13805. content: cmsEnveloped.toSchema()
  13806. }));
  13807. }
  13808. break;
  13809. default:
  13810. throw new Error(`Incorrect value for "content.privacyMode": ${content.privacyMode}`);
  13811. }
  13812. }
  13813. return this;
  13814. }
  13815. }
  13816. AuthenticatedSafe.CLASS_NAME = "AuthenticatedSafe";
  13817. const HASH_ALGORITHM$1 = "hashAlgorithm";
  13818. const ISSUER_NAME_HASH = "issuerNameHash";
  13819. const ISSUER_KEY_HASH = "issuerKeyHash";
  13820. const SERIAL_NUMBER$1 = "serialNumber";
  13821. const CLEAR_PROPS$j = [
  13822. HASH_ALGORITHM$1,
  13823. ISSUER_NAME_HASH,
  13824. ISSUER_KEY_HASH,
  13825. SERIAL_NUMBER$1,
  13826. ];
  13827. class CertID extends PkiObject {
  13828. static async create(certificate, parameters, crypto = getCrypto(true)) {
  13829. const certID = new CertID();
  13830. await certID.createForCertificate(certificate, parameters, crypto);
  13831. return certID;
  13832. }
  13833. constructor(parameters = {}) {
  13834. super();
  13835. this.hashAlgorithm = pvutils__namespace.getParametersValue(parameters, HASH_ALGORITHM$1, CertID.defaultValues(HASH_ALGORITHM$1));
  13836. this.issuerNameHash = pvutils__namespace.getParametersValue(parameters, ISSUER_NAME_HASH, CertID.defaultValues(ISSUER_NAME_HASH));
  13837. this.issuerKeyHash = pvutils__namespace.getParametersValue(parameters, ISSUER_KEY_HASH, CertID.defaultValues(ISSUER_KEY_HASH));
  13838. this.serialNumber = pvutils__namespace.getParametersValue(parameters, SERIAL_NUMBER$1, CertID.defaultValues(SERIAL_NUMBER$1));
  13839. if (parameters.schema) {
  13840. this.fromSchema(parameters.schema);
  13841. }
  13842. }
  13843. static defaultValues(memberName) {
  13844. switch (memberName) {
  13845. case HASH_ALGORITHM$1:
  13846. return new AlgorithmIdentifier();
  13847. case ISSUER_NAME_HASH:
  13848. case ISSUER_KEY_HASH:
  13849. return new asn1js__namespace.OctetString();
  13850. case SERIAL_NUMBER$1:
  13851. return new asn1js__namespace.Integer();
  13852. default:
  13853. return super.defaultValues(memberName);
  13854. }
  13855. }
  13856. static compareWithDefault(memberName, memberValue) {
  13857. switch (memberName) {
  13858. case HASH_ALGORITHM$1:
  13859. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  13860. case ISSUER_NAME_HASH:
  13861. case ISSUER_KEY_HASH:
  13862. case SERIAL_NUMBER$1:
  13863. return (memberValue.isEqual(CertID.defaultValues(SERIAL_NUMBER$1)));
  13864. default:
  13865. return super.defaultValues(memberName);
  13866. }
  13867. }
  13868. static schema(parameters = {}) {
  13869. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  13870. return (new asn1js__namespace.Sequence({
  13871. name: (names.blockName || EMPTY_STRING),
  13872. value: [
  13873. AlgorithmIdentifier.schema(names.hashAlgorithmObject || {
  13874. names: {
  13875. blockName: (names.hashAlgorithm || EMPTY_STRING)
  13876. }
  13877. }),
  13878. new asn1js__namespace.OctetString({ name: (names.issuerNameHash || EMPTY_STRING) }),
  13879. new asn1js__namespace.OctetString({ name: (names.issuerKeyHash || EMPTY_STRING) }),
  13880. new asn1js__namespace.Integer({ name: (names.serialNumber || EMPTY_STRING) })
  13881. ]
  13882. }));
  13883. }
  13884. fromSchema(schema) {
  13885. pvutils__namespace.clearProps(schema, CLEAR_PROPS$j);
  13886. const asn1 = asn1js__namespace.compareSchema(schema, schema, CertID.schema({
  13887. names: {
  13888. hashAlgorithm: HASH_ALGORITHM$1,
  13889. issuerNameHash: ISSUER_NAME_HASH,
  13890. issuerKeyHash: ISSUER_KEY_HASH,
  13891. serialNumber: SERIAL_NUMBER$1
  13892. }
  13893. }));
  13894. AsnError.assertSchema(asn1, this.className);
  13895. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  13896. this.issuerNameHash = asn1.result.issuerNameHash;
  13897. this.issuerKeyHash = asn1.result.issuerKeyHash;
  13898. this.serialNumber = asn1.result.serialNumber;
  13899. }
  13900. toSchema() {
  13901. return (new asn1js__namespace.Sequence({
  13902. value: [
  13903. this.hashAlgorithm.toSchema(),
  13904. this.issuerNameHash,
  13905. this.issuerKeyHash,
  13906. this.serialNumber
  13907. ]
  13908. }));
  13909. }
  13910. toJSON() {
  13911. return {
  13912. hashAlgorithm: this.hashAlgorithm.toJSON(),
  13913. issuerNameHash: this.issuerNameHash.toJSON(),
  13914. issuerKeyHash: this.issuerKeyHash.toJSON(),
  13915. serialNumber: this.serialNumber.toJSON(),
  13916. };
  13917. }
  13918. isEqual(certificateID) {
  13919. if (this.hashAlgorithm.algorithmId !== certificateID.hashAlgorithm.algorithmId) {
  13920. return false;
  13921. }
  13922. if (!pvtsutils__namespace.BufferSourceConverter.isEqual(this.issuerNameHash.valueBlock.valueHexView, certificateID.issuerNameHash.valueBlock.valueHexView)) {
  13923. return false;
  13924. }
  13925. if (!pvtsutils__namespace.BufferSourceConverter.isEqual(this.issuerKeyHash.valueBlock.valueHexView, certificateID.issuerKeyHash.valueBlock.valueHexView)) {
  13926. return false;
  13927. }
  13928. if (!this.serialNumber.isEqual(certificateID.serialNumber)) {
  13929. return false;
  13930. }
  13931. return true;
  13932. }
  13933. async createForCertificate(certificate, parameters, crypto = getCrypto(true)) {
  13934. ParameterError.assert(parameters, HASH_ALGORITHM$1, "issuerCertificate");
  13935. const hashOID = crypto.getOIDByAlgorithm({ name: parameters.hashAlgorithm }, true, "hashAlgorithm");
  13936. this.hashAlgorithm = new AlgorithmIdentifier({
  13937. algorithmId: hashOID,
  13938. algorithmParams: new asn1js__namespace.Null()
  13939. });
  13940. const issuerCertificate = parameters.issuerCertificate;
  13941. this.serialNumber = certificate.serialNumber;
  13942. const hashIssuerName = await crypto.digest({ name: parameters.hashAlgorithm }, issuerCertificate.subject.toSchema().toBER(false));
  13943. this.issuerNameHash = new asn1js__namespace.OctetString({ valueHex: hashIssuerName });
  13944. const issuerKeyBuffer = issuerCertificate.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView;
  13945. const hashIssuerKey = await crypto.digest({ name: parameters.hashAlgorithm }, issuerKeyBuffer);
  13946. this.issuerKeyHash = new asn1js__namespace.OctetString({ valueHex: hashIssuerKey });
  13947. }
  13948. }
  13949. CertID.CLASS_NAME = "CertID";
  13950. const CERT_ID = "certID";
  13951. const CERT_STATUS = "certStatus";
  13952. const THIS_UPDATE = "thisUpdate";
  13953. const NEXT_UPDATE = "nextUpdate";
  13954. const SINGLE_EXTENSIONS = "singleExtensions";
  13955. const CLEAR_PROPS$i = [
  13956. CERT_ID,
  13957. CERT_STATUS,
  13958. THIS_UPDATE,
  13959. NEXT_UPDATE,
  13960. SINGLE_EXTENSIONS,
  13961. ];
  13962. class SingleResponse extends PkiObject {
  13963. constructor(parameters = {}) {
  13964. super();
  13965. this.certID = pvutils__namespace.getParametersValue(parameters, CERT_ID, SingleResponse.defaultValues(CERT_ID));
  13966. this.certStatus = pvutils__namespace.getParametersValue(parameters, CERT_STATUS, SingleResponse.defaultValues(CERT_STATUS));
  13967. this.thisUpdate = pvutils__namespace.getParametersValue(parameters, THIS_UPDATE, SingleResponse.defaultValues(THIS_UPDATE));
  13968. if (NEXT_UPDATE in parameters) {
  13969. this.nextUpdate = pvutils__namespace.getParametersValue(parameters, NEXT_UPDATE, SingleResponse.defaultValues(NEXT_UPDATE));
  13970. }
  13971. if (SINGLE_EXTENSIONS in parameters) {
  13972. this.singleExtensions = pvutils__namespace.getParametersValue(parameters, SINGLE_EXTENSIONS, SingleResponse.defaultValues(SINGLE_EXTENSIONS));
  13973. }
  13974. if (parameters.schema) {
  13975. this.fromSchema(parameters.schema);
  13976. }
  13977. }
  13978. static defaultValues(memberName) {
  13979. switch (memberName) {
  13980. case CERT_ID:
  13981. return new CertID();
  13982. case CERT_STATUS:
  13983. return {};
  13984. case THIS_UPDATE:
  13985. case NEXT_UPDATE:
  13986. return new Date(0, 0, 0);
  13987. case SINGLE_EXTENSIONS:
  13988. return [];
  13989. default:
  13990. return super.defaultValues(memberName);
  13991. }
  13992. }
  13993. static compareWithDefault(memberName, memberValue) {
  13994. switch (memberName) {
  13995. case CERT_ID:
  13996. return ((CertID.compareWithDefault("hashAlgorithm", memberValue.hashAlgorithm)) &&
  13997. (CertID.compareWithDefault("issuerNameHash", memberValue.issuerNameHash)) &&
  13998. (CertID.compareWithDefault("issuerKeyHash", memberValue.issuerKeyHash)) &&
  13999. (CertID.compareWithDefault("serialNumber", memberValue.serialNumber)));
  14000. case CERT_STATUS:
  14001. return (Object.keys(memberValue).length === 0);
  14002. case THIS_UPDATE:
  14003. case NEXT_UPDATE:
  14004. return (memberValue === SingleResponse.defaultValues(memberName));
  14005. default:
  14006. return super.defaultValues(memberName);
  14007. }
  14008. }
  14009. static schema(parameters = {}) {
  14010. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  14011. return (new asn1js__namespace.Sequence({
  14012. name: (names.blockName || EMPTY_STRING),
  14013. value: [
  14014. CertID.schema(names.certID || {}),
  14015. new asn1js__namespace.Choice({
  14016. value: [
  14017. new asn1js__namespace.Primitive({
  14018. name: (names.certStatus || EMPTY_STRING),
  14019. idBlock: {
  14020. tagClass: 3,
  14021. tagNumber: 0
  14022. },
  14023. }),
  14024. new asn1js__namespace.Constructed({
  14025. name: (names.certStatus || EMPTY_STRING),
  14026. idBlock: {
  14027. tagClass: 3,
  14028. tagNumber: 1
  14029. },
  14030. value: [
  14031. new asn1js__namespace.GeneralizedTime(),
  14032. new asn1js__namespace.Constructed({
  14033. optional: true,
  14034. idBlock: {
  14035. tagClass: 3,
  14036. tagNumber: 0
  14037. },
  14038. value: [new asn1js__namespace.Enumerated()]
  14039. })
  14040. ]
  14041. }),
  14042. new asn1js__namespace.Primitive({
  14043. name: (names.certStatus || EMPTY_STRING),
  14044. idBlock: {
  14045. tagClass: 3,
  14046. tagNumber: 2
  14047. },
  14048. lenBlock: { length: 1 }
  14049. })
  14050. ]
  14051. }),
  14052. new asn1js__namespace.GeneralizedTime({ name: (names.thisUpdate || EMPTY_STRING) }),
  14053. new asn1js__namespace.Constructed({
  14054. optional: true,
  14055. idBlock: {
  14056. tagClass: 3,
  14057. tagNumber: 0
  14058. },
  14059. value: [new asn1js__namespace.GeneralizedTime({ name: (names.nextUpdate || EMPTY_STRING) })]
  14060. }),
  14061. new asn1js__namespace.Constructed({
  14062. optional: true,
  14063. idBlock: {
  14064. tagClass: 3,
  14065. tagNumber: 1
  14066. },
  14067. value: [Extensions.schema(names.singleExtensions || {})]
  14068. })
  14069. ]
  14070. }));
  14071. }
  14072. fromSchema(schema) {
  14073. pvutils__namespace.clearProps(schema, CLEAR_PROPS$i);
  14074. const asn1 = asn1js__namespace.compareSchema(schema, schema, SingleResponse.schema({
  14075. names: {
  14076. certID: {
  14077. names: {
  14078. blockName: CERT_ID
  14079. }
  14080. },
  14081. certStatus: CERT_STATUS,
  14082. thisUpdate: THIS_UPDATE,
  14083. nextUpdate: NEXT_UPDATE,
  14084. singleExtensions: {
  14085. names: {
  14086. blockName: SINGLE_EXTENSIONS
  14087. }
  14088. }
  14089. }
  14090. }));
  14091. AsnError.assertSchema(asn1, this.className);
  14092. this.certID = new CertID({ schema: asn1.result.certID });
  14093. this.certStatus = asn1.result.certStatus;
  14094. this.thisUpdate = asn1.result.thisUpdate.toDate();
  14095. if (NEXT_UPDATE in asn1.result)
  14096. this.nextUpdate = asn1.result.nextUpdate.toDate();
  14097. if (SINGLE_EXTENSIONS in asn1.result)
  14098. this.singleExtensions = Array.from(asn1.result.singleExtensions.valueBlock.value, element => new Extension({ schema: element }));
  14099. }
  14100. toSchema() {
  14101. const outputArray = [];
  14102. outputArray.push(this.certID.toSchema());
  14103. outputArray.push(this.certStatus);
  14104. outputArray.push(new asn1js__namespace.GeneralizedTime({ valueDate: this.thisUpdate }));
  14105. if (this.nextUpdate) {
  14106. outputArray.push(new asn1js__namespace.Constructed({
  14107. idBlock: {
  14108. tagClass: 3,
  14109. tagNumber: 0
  14110. },
  14111. value: [new asn1js__namespace.GeneralizedTime({ valueDate: this.nextUpdate })]
  14112. }));
  14113. }
  14114. if (this.singleExtensions) {
  14115. outputArray.push(new asn1js__namespace.Constructed({
  14116. idBlock: {
  14117. tagClass: 3,
  14118. tagNumber: 1
  14119. },
  14120. value: [new asn1js__namespace.Sequence({ value: Array.from(this.singleExtensions, o => o.toSchema()) })]
  14121. }));
  14122. }
  14123. return (new asn1js__namespace.Sequence({
  14124. value: outputArray
  14125. }));
  14126. }
  14127. toJSON() {
  14128. const res = {
  14129. certID: this.certID.toJSON(),
  14130. certStatus: this.certStatus.toJSON(),
  14131. thisUpdate: this.thisUpdate
  14132. };
  14133. if (this.nextUpdate) {
  14134. res.nextUpdate = this.nextUpdate;
  14135. }
  14136. if (this.singleExtensions) {
  14137. res.singleExtensions = Array.from(this.singleExtensions, o => o.toJSON());
  14138. }
  14139. return res;
  14140. }
  14141. }
  14142. SingleResponse.CLASS_NAME = "SingleResponse";
  14143. const TBS$2 = "tbs";
  14144. const VERSION$7 = "version";
  14145. const RESPONDER_ID = "responderID";
  14146. const PRODUCED_AT = "producedAt";
  14147. const RESPONSES = "responses";
  14148. const RESPONSE_EXTENSIONS = "responseExtensions";
  14149. const RESPONSE_DATA = "ResponseData";
  14150. const RESPONSE_DATA_VERSION = `${RESPONSE_DATA}.${VERSION$7}`;
  14151. const RESPONSE_DATA_RESPONDER_ID = `${RESPONSE_DATA}.${RESPONDER_ID}`;
  14152. const RESPONSE_DATA_PRODUCED_AT = `${RESPONSE_DATA}.${PRODUCED_AT}`;
  14153. const RESPONSE_DATA_RESPONSES = `${RESPONSE_DATA}.${RESPONSES}`;
  14154. const RESPONSE_DATA_RESPONSE_EXTENSIONS = `${RESPONSE_DATA}.${RESPONSE_EXTENSIONS}`;
  14155. const CLEAR_PROPS$h = [
  14156. RESPONSE_DATA,
  14157. RESPONSE_DATA_VERSION,
  14158. RESPONSE_DATA_RESPONDER_ID,
  14159. RESPONSE_DATA_PRODUCED_AT,
  14160. RESPONSE_DATA_RESPONSES,
  14161. RESPONSE_DATA_RESPONSE_EXTENSIONS
  14162. ];
  14163. class ResponseData extends PkiObject {
  14164. get tbs() {
  14165. return pvtsutils__namespace.BufferSourceConverter.toArrayBuffer(this.tbsView);
  14166. }
  14167. set tbs(value) {
  14168. this.tbsView = new Uint8Array(value);
  14169. }
  14170. constructor(parameters = {}) {
  14171. super();
  14172. this.tbsView = new Uint8Array(pvutils__namespace.getParametersValue(parameters, TBS$2, ResponseData.defaultValues(TBS$2)));
  14173. if (VERSION$7 in parameters) {
  14174. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$7, ResponseData.defaultValues(VERSION$7));
  14175. }
  14176. this.responderID = pvutils__namespace.getParametersValue(parameters, RESPONDER_ID, ResponseData.defaultValues(RESPONDER_ID));
  14177. this.producedAt = pvutils__namespace.getParametersValue(parameters, PRODUCED_AT, ResponseData.defaultValues(PRODUCED_AT));
  14178. this.responses = pvutils__namespace.getParametersValue(parameters, RESPONSES, ResponseData.defaultValues(RESPONSES));
  14179. if (RESPONSE_EXTENSIONS in parameters) {
  14180. this.responseExtensions = pvutils__namespace.getParametersValue(parameters, RESPONSE_EXTENSIONS, ResponseData.defaultValues(RESPONSE_EXTENSIONS));
  14181. }
  14182. if (parameters.schema) {
  14183. this.fromSchema(parameters.schema);
  14184. }
  14185. }
  14186. static defaultValues(memberName) {
  14187. switch (memberName) {
  14188. case VERSION$7:
  14189. return 0;
  14190. case TBS$2:
  14191. return EMPTY_BUFFER;
  14192. case RESPONDER_ID:
  14193. return {};
  14194. case PRODUCED_AT:
  14195. return new Date(0, 0, 0);
  14196. case RESPONSES:
  14197. case RESPONSE_EXTENSIONS:
  14198. return [];
  14199. default:
  14200. return super.defaultValues(memberName);
  14201. }
  14202. }
  14203. static compareWithDefault(memberName, memberValue) {
  14204. switch (memberName) {
  14205. case TBS$2:
  14206. return (memberValue.byteLength === 0);
  14207. case RESPONDER_ID:
  14208. return (Object.keys(memberValue).length === 0);
  14209. case PRODUCED_AT:
  14210. return (memberValue === ResponseData.defaultValues(memberName));
  14211. case RESPONSES:
  14212. case RESPONSE_EXTENSIONS:
  14213. return (memberValue.length === 0);
  14214. default:
  14215. return super.defaultValues(memberName);
  14216. }
  14217. }
  14218. static schema(parameters = {}) {
  14219. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  14220. return (new asn1js__namespace.Sequence({
  14221. name: (names.blockName || RESPONSE_DATA),
  14222. value: [
  14223. new asn1js__namespace.Constructed({
  14224. optional: true,
  14225. idBlock: {
  14226. tagClass: 3,
  14227. tagNumber: 0
  14228. },
  14229. value: [new asn1js__namespace.Integer({ name: (names.version || RESPONSE_DATA_VERSION) })]
  14230. }),
  14231. new asn1js__namespace.Choice({
  14232. value: [
  14233. new asn1js__namespace.Constructed({
  14234. name: (names.responderID || RESPONSE_DATA_RESPONDER_ID),
  14235. idBlock: {
  14236. tagClass: 3,
  14237. tagNumber: 1
  14238. },
  14239. value: [RelativeDistinguishedNames.schema(names.ResponseDataByName || {
  14240. names: {
  14241. blockName: "ResponseData.byName"
  14242. }
  14243. })]
  14244. }),
  14245. new asn1js__namespace.Constructed({
  14246. name: (names.responderID || RESPONSE_DATA_RESPONDER_ID),
  14247. idBlock: {
  14248. tagClass: 3,
  14249. tagNumber: 2
  14250. },
  14251. value: [new asn1js__namespace.OctetString({ name: (names.ResponseDataByKey || "ResponseData.byKey") })]
  14252. })
  14253. ]
  14254. }),
  14255. new asn1js__namespace.GeneralizedTime({ name: (names.producedAt || RESPONSE_DATA_PRODUCED_AT) }),
  14256. new asn1js__namespace.Sequence({
  14257. value: [
  14258. new asn1js__namespace.Repeated({
  14259. name: RESPONSE_DATA_RESPONSES,
  14260. value: SingleResponse.schema(names.response || {})
  14261. })
  14262. ]
  14263. }),
  14264. new asn1js__namespace.Constructed({
  14265. optional: true,
  14266. idBlock: {
  14267. tagClass: 3,
  14268. tagNumber: 1
  14269. },
  14270. value: [Extensions.schema(names.extensions || {
  14271. names: {
  14272. blockName: RESPONSE_DATA_RESPONSE_EXTENSIONS
  14273. }
  14274. })]
  14275. })
  14276. ]
  14277. }));
  14278. }
  14279. fromSchema(schema) {
  14280. pvutils__namespace.clearProps(schema, CLEAR_PROPS$h);
  14281. const asn1 = asn1js__namespace.compareSchema(schema, schema, ResponseData.schema());
  14282. AsnError.assertSchema(asn1, this.className);
  14283. this.tbsView = asn1.result.ResponseData.valueBeforeDecodeView;
  14284. if (RESPONSE_DATA_VERSION in asn1.result)
  14285. this.version = asn1.result[RESPONSE_DATA_VERSION].valueBlock.valueDec;
  14286. if (asn1.result[RESPONSE_DATA_RESPONDER_ID].idBlock.tagNumber === 1)
  14287. this.responderID = new RelativeDistinguishedNames({ schema: asn1.result[RESPONSE_DATA_RESPONDER_ID].valueBlock.value[0] });
  14288. else
  14289. this.responderID = asn1.result[RESPONSE_DATA_RESPONDER_ID].valueBlock.value[0];
  14290. this.producedAt = asn1.result[RESPONSE_DATA_PRODUCED_AT].toDate();
  14291. this.responses = Array.from(asn1.result[RESPONSE_DATA_RESPONSES], element => new SingleResponse({ schema: element }));
  14292. if (RESPONSE_DATA_RESPONSE_EXTENSIONS in asn1.result)
  14293. this.responseExtensions = Array.from(asn1.result[RESPONSE_DATA_RESPONSE_EXTENSIONS].valueBlock.value, element => new Extension({ schema: element }));
  14294. }
  14295. toSchema(encodeFlag = false) {
  14296. let tbsSchema;
  14297. if (encodeFlag === false) {
  14298. if (!this.tbsView.byteLength) {
  14299. return ResponseData.schema();
  14300. }
  14301. const asn1 = asn1js__namespace.fromBER(this.tbsView);
  14302. AsnError.assert(asn1, "TBS Response Data");
  14303. tbsSchema = asn1.result;
  14304. }
  14305. else {
  14306. const outputArray = [];
  14307. if (VERSION$7 in this) {
  14308. outputArray.push(new asn1js__namespace.Constructed({
  14309. idBlock: {
  14310. tagClass: 3,
  14311. tagNumber: 0
  14312. },
  14313. value: [new asn1js__namespace.Integer({ value: this.version })]
  14314. }));
  14315. }
  14316. if (this.responderID instanceof RelativeDistinguishedNames) {
  14317. outputArray.push(new asn1js__namespace.Constructed({
  14318. idBlock: {
  14319. tagClass: 3,
  14320. tagNumber: 1
  14321. },
  14322. value: [this.responderID.toSchema()]
  14323. }));
  14324. }
  14325. else {
  14326. outputArray.push(new asn1js__namespace.Constructed({
  14327. idBlock: {
  14328. tagClass: 3,
  14329. tagNumber: 2
  14330. },
  14331. value: [this.responderID]
  14332. }));
  14333. }
  14334. outputArray.push(new asn1js__namespace.GeneralizedTime({ valueDate: this.producedAt }));
  14335. outputArray.push(new asn1js__namespace.Sequence({
  14336. value: Array.from(this.responses, o => o.toSchema())
  14337. }));
  14338. if (this.responseExtensions) {
  14339. outputArray.push(new asn1js__namespace.Constructed({
  14340. idBlock: {
  14341. tagClass: 3,
  14342. tagNumber: 1
  14343. },
  14344. value: [new asn1js__namespace.Sequence({
  14345. value: Array.from(this.responseExtensions, o => o.toSchema())
  14346. })]
  14347. }));
  14348. }
  14349. tbsSchema = new asn1js__namespace.Sequence({
  14350. value: outputArray
  14351. });
  14352. }
  14353. return tbsSchema;
  14354. }
  14355. toJSON() {
  14356. const res = {};
  14357. if (VERSION$7 in this) {
  14358. res.version = this.version;
  14359. }
  14360. if (this.responderID) {
  14361. res.responderID = this.responderID;
  14362. }
  14363. if (this.producedAt) {
  14364. res.producedAt = this.producedAt;
  14365. }
  14366. if (this.responses) {
  14367. res.responses = Array.from(this.responses, o => o.toJSON());
  14368. }
  14369. if (this.responseExtensions) {
  14370. res.responseExtensions = Array.from(this.responseExtensions, o => o.toJSON());
  14371. }
  14372. return res;
  14373. }
  14374. }
  14375. ResponseData.CLASS_NAME = "ResponseData";
  14376. const TRUSTED_CERTS = "trustedCerts";
  14377. const CERTS$2 = "certs";
  14378. const CRLS$1 = "crls";
  14379. const OCSPS$1 = "ocsps";
  14380. const CHECK_DATE = "checkDate";
  14381. const FIND_ORIGIN = "findOrigin";
  14382. const FIND_ISSUER = "findIssuer";
  14383. exports.ChainValidationCode = void 0;
  14384. (function (ChainValidationCode) {
  14385. ChainValidationCode[ChainValidationCode["unknown"] = -1] = "unknown";
  14386. ChainValidationCode[ChainValidationCode["success"] = 0] = "success";
  14387. ChainValidationCode[ChainValidationCode["noRevocation"] = 11] = "noRevocation";
  14388. ChainValidationCode[ChainValidationCode["noPath"] = 60] = "noPath";
  14389. ChainValidationCode[ChainValidationCode["noValidPath"] = 97] = "noValidPath";
  14390. })(exports.ChainValidationCode || (exports.ChainValidationCode = {}));
  14391. class ChainValidationError extends Error {
  14392. constructor(code, message) {
  14393. super(message);
  14394. this.name = ChainValidationError.NAME;
  14395. this.code = code;
  14396. this.message = message;
  14397. }
  14398. }
  14399. ChainValidationError.NAME = "ChainValidationError";
  14400. function isTrusted(cert, trustedList) {
  14401. for (let i = 0; i < trustedList.length; i++) {
  14402. if (pvtsutils__namespace.BufferSourceConverter.isEqual(cert.tbsView, trustedList[i].tbsView)) {
  14403. return true;
  14404. }
  14405. }
  14406. return false;
  14407. }
  14408. class CertificateChainValidationEngine {
  14409. constructor(parameters = {}) {
  14410. this.trustedCerts = pvutils__namespace.getParametersValue(parameters, TRUSTED_CERTS, this.defaultValues(TRUSTED_CERTS));
  14411. this.certs = pvutils__namespace.getParametersValue(parameters, CERTS$2, this.defaultValues(CERTS$2));
  14412. this.crls = pvutils__namespace.getParametersValue(parameters, CRLS$1, this.defaultValues(CRLS$1));
  14413. this.ocsps = pvutils__namespace.getParametersValue(parameters, OCSPS$1, this.defaultValues(OCSPS$1));
  14414. this.checkDate = pvutils__namespace.getParametersValue(parameters, CHECK_DATE, this.defaultValues(CHECK_DATE));
  14415. this.findOrigin = pvutils__namespace.getParametersValue(parameters, FIND_ORIGIN, this.defaultValues(FIND_ORIGIN));
  14416. this.findIssuer = pvutils__namespace.getParametersValue(parameters, FIND_ISSUER, this.defaultValues(FIND_ISSUER));
  14417. }
  14418. static defaultFindOrigin(certificate, validationEngine) {
  14419. if (certificate.tbsView.byteLength === 0) {
  14420. certificate.tbsView = new Uint8Array(certificate.encodeTBS().toBER());
  14421. }
  14422. for (const localCert of validationEngine.certs) {
  14423. if (localCert.tbsView.byteLength === 0) {
  14424. localCert.tbsView = new Uint8Array(localCert.encodeTBS().toBER());
  14425. }
  14426. if (pvtsutils__namespace.BufferSourceConverter.isEqual(certificate.tbsView, localCert.tbsView))
  14427. return "Intermediate Certificates";
  14428. }
  14429. for (const trustedCert of validationEngine.trustedCerts) {
  14430. if (trustedCert.tbsView.byteLength === 0)
  14431. trustedCert.tbsView = new Uint8Array(trustedCert.encodeTBS().toBER());
  14432. if (pvtsutils__namespace.BufferSourceConverter.isEqual(certificate.tbsView, trustedCert.tbsView))
  14433. return "Trusted Certificates";
  14434. }
  14435. return "Unknown";
  14436. }
  14437. async defaultFindIssuer(certificate, validationEngine, crypto = getCrypto(true)) {
  14438. const result = [];
  14439. let keyIdentifier = null;
  14440. let authorityCertIssuer = null;
  14441. let authorityCertSerialNumber = null;
  14442. if (certificate.subject.isEqual(certificate.issuer)) {
  14443. try {
  14444. const verificationResult = await certificate.verify(undefined, crypto);
  14445. if (verificationResult) {
  14446. return [certificate];
  14447. }
  14448. }
  14449. catch {
  14450. }
  14451. }
  14452. if (certificate.extensions) {
  14453. for (const extension of certificate.extensions) {
  14454. if (extension.extnID === id_AuthorityKeyIdentifier && extension.parsedValue instanceof AuthorityKeyIdentifier) {
  14455. if (extension.parsedValue.keyIdentifier) {
  14456. keyIdentifier = extension.parsedValue.keyIdentifier;
  14457. }
  14458. else {
  14459. if (extension.parsedValue.authorityCertIssuer) {
  14460. authorityCertIssuer = extension.parsedValue.authorityCertIssuer;
  14461. }
  14462. if (extension.parsedValue.authorityCertSerialNumber) {
  14463. authorityCertSerialNumber = extension.parsedValue.authorityCertSerialNumber;
  14464. }
  14465. }
  14466. break;
  14467. }
  14468. }
  14469. }
  14470. function checkCertificate(possibleIssuer) {
  14471. if (keyIdentifier !== null) {
  14472. if (possibleIssuer.extensions) {
  14473. let extensionFound = false;
  14474. for (const extension of possibleIssuer.extensions) {
  14475. if (extension.extnID === id_SubjectKeyIdentifier && extension.parsedValue) {
  14476. extensionFound = true;
  14477. if (pvtsutils__namespace.BufferSourceConverter.isEqual(extension.parsedValue.valueBlock.valueHex, keyIdentifier.valueBlock.valueHexView)) {
  14478. result.push(possibleIssuer);
  14479. }
  14480. break;
  14481. }
  14482. }
  14483. if (extensionFound) {
  14484. return;
  14485. }
  14486. }
  14487. }
  14488. let authorityCertSerialNumberEqual = false;
  14489. if (authorityCertSerialNumber !== null)
  14490. authorityCertSerialNumberEqual = possibleIssuer.serialNumber.isEqual(authorityCertSerialNumber);
  14491. if (authorityCertIssuer !== null) {
  14492. if (possibleIssuer.subject.isEqual(authorityCertIssuer)) {
  14493. if (authorityCertSerialNumberEqual)
  14494. result.push(possibleIssuer);
  14495. }
  14496. }
  14497. else {
  14498. if (certificate.issuer.isEqual(possibleIssuer.subject))
  14499. result.push(possibleIssuer);
  14500. }
  14501. }
  14502. for (const trustedCert of validationEngine.trustedCerts) {
  14503. checkCertificate(trustedCert);
  14504. }
  14505. for (const intermediateCert of validationEngine.certs) {
  14506. checkCertificate(intermediateCert);
  14507. }
  14508. for (let i = result.length - 1; i >= 0; i--) {
  14509. try {
  14510. const verificationResult = await certificate.verify(result[i], crypto);
  14511. if (verificationResult === false)
  14512. result.splice(i, 1);
  14513. }
  14514. catch {
  14515. result.splice(i, 1);
  14516. }
  14517. }
  14518. return result;
  14519. }
  14520. defaultValues(memberName) {
  14521. switch (memberName) {
  14522. case TRUSTED_CERTS:
  14523. return [];
  14524. case CERTS$2:
  14525. return [];
  14526. case CRLS$1:
  14527. return [];
  14528. case OCSPS$1:
  14529. return [];
  14530. case CHECK_DATE:
  14531. return new Date();
  14532. case FIND_ORIGIN:
  14533. return CertificateChainValidationEngine.defaultFindOrigin;
  14534. case FIND_ISSUER:
  14535. return this.defaultFindIssuer;
  14536. default:
  14537. throw new Error(`Invalid member name for CertificateChainValidationEngine class: ${memberName}`);
  14538. }
  14539. }
  14540. async sort(passedWhenNotRevValues = false, crypto = getCrypto(true)) {
  14541. const localCerts = [];
  14542. const buildPath = async (certificate, crypto) => {
  14543. const result = [];
  14544. function checkUnique(array) {
  14545. let unique = true;
  14546. for (let i = 0; i < array.length; i++) {
  14547. for (let j = 0; j < array.length; j++) {
  14548. if (j === i)
  14549. continue;
  14550. if (array[i] === array[j]) {
  14551. unique = false;
  14552. break;
  14553. }
  14554. }
  14555. if (!unique)
  14556. break;
  14557. }
  14558. return unique;
  14559. }
  14560. if (isTrusted(certificate, this.trustedCerts)) {
  14561. return [[certificate]];
  14562. }
  14563. const findIssuerResult = await this.findIssuer(certificate, this, crypto);
  14564. if (findIssuerResult.length === 0) {
  14565. throw new Error("No valid certificate paths found");
  14566. }
  14567. for (let i = 0; i < findIssuerResult.length; i++) {
  14568. if (pvtsutils__namespace.BufferSourceConverter.isEqual(findIssuerResult[i].tbsView, certificate.tbsView)) {
  14569. result.push([findIssuerResult[i]]);
  14570. continue;
  14571. }
  14572. const buildPathResult = await buildPath(findIssuerResult[i], crypto);
  14573. for (let j = 0; j < buildPathResult.length; j++) {
  14574. const copy = buildPathResult[j].slice();
  14575. copy.splice(0, 0, findIssuerResult[i]);
  14576. if (checkUnique(copy))
  14577. result.push(copy);
  14578. else
  14579. result.push(buildPathResult[j]);
  14580. }
  14581. }
  14582. return result;
  14583. };
  14584. const findCRL = async (certificate) => {
  14585. const issuerCertificates = [];
  14586. const crls = [];
  14587. const crlsAndCertificates = [];
  14588. issuerCertificates.push(...localCerts.filter(element => certificate.issuer.isEqual(element.subject)));
  14589. if (issuerCertificates.length === 0) {
  14590. return {
  14591. status: 1,
  14592. statusMessage: "No certificate's issuers"
  14593. };
  14594. }
  14595. crls.push(...this.crls.filter(o => o.issuer.isEqual(certificate.issuer)));
  14596. if (crls.length === 0) {
  14597. return {
  14598. status: 2,
  14599. statusMessage: "No CRLs for specific certificate issuer"
  14600. };
  14601. }
  14602. for (let i = 0; i < crls.length; i++) {
  14603. const crl = crls[i];
  14604. if (crl.nextUpdate && crl.nextUpdate.value < this.checkDate) {
  14605. continue;
  14606. }
  14607. for (let j = 0; j < issuerCertificates.length; j++) {
  14608. try {
  14609. const result = await crls[i].verify({ issuerCertificate: issuerCertificates[j] }, crypto);
  14610. if (result) {
  14611. crlsAndCertificates.push({
  14612. crl: crls[i],
  14613. certificate: issuerCertificates[j]
  14614. });
  14615. break;
  14616. }
  14617. }
  14618. catch {
  14619. }
  14620. }
  14621. }
  14622. if (crlsAndCertificates.length) {
  14623. return {
  14624. status: 0,
  14625. statusMessage: EMPTY_STRING,
  14626. result: crlsAndCertificates
  14627. };
  14628. }
  14629. return {
  14630. status: 3,
  14631. statusMessage: "No valid CRLs found"
  14632. };
  14633. };
  14634. const findOCSP = async (certificate, issuerCertificate) => {
  14635. const hashAlgorithm = crypto.getAlgorithmByOID(certificate.signatureAlgorithm.algorithmId);
  14636. if (!hashAlgorithm.name) {
  14637. return 1;
  14638. }
  14639. if (!hashAlgorithm.hash) {
  14640. return 1;
  14641. }
  14642. for (let i = 0; i < this.ocsps.length; i++) {
  14643. const ocsp = this.ocsps[i];
  14644. const result = await ocsp.getCertificateStatus(certificate, issuerCertificate, crypto);
  14645. if (result.isForCertificate) {
  14646. if (result.status === 0)
  14647. return 0;
  14648. return 1;
  14649. }
  14650. }
  14651. return 2;
  14652. };
  14653. async function checkForCA(certificate, needToCheckCRL = false) {
  14654. let isCA = false;
  14655. let mustBeCA = false;
  14656. let keyUsagePresent = false;
  14657. let cRLSign = false;
  14658. if (certificate.extensions) {
  14659. for (let j = 0; j < certificate.extensions.length; j++) {
  14660. const extension = certificate.extensions[j];
  14661. if (extension.critical && !extension.parsedValue) {
  14662. return {
  14663. result: false,
  14664. resultCode: 6,
  14665. resultMessage: `Unable to parse critical certificate extension: ${extension.extnID}`
  14666. };
  14667. }
  14668. if (extension.extnID === id_KeyUsage) {
  14669. keyUsagePresent = true;
  14670. const view = new Uint8Array(extension.parsedValue.valueBlock.valueHex);
  14671. if ((view[0] & 0x04) === 0x04)
  14672. mustBeCA = true;
  14673. if ((view[0] & 0x02) === 0x02)
  14674. cRLSign = true;
  14675. }
  14676. if (extension.extnID === id_BasicConstraints) {
  14677. if ("cA" in extension.parsedValue) {
  14678. if (extension.parsedValue.cA === true)
  14679. isCA = true;
  14680. }
  14681. }
  14682. }
  14683. if ((mustBeCA === true) && (isCA === false)) {
  14684. return {
  14685. result: false,
  14686. resultCode: 3,
  14687. resultMessage: "Unable to build certificate chain - using \"keyCertSign\" flag set without BasicConstraints"
  14688. };
  14689. }
  14690. if ((keyUsagePresent === true) && (isCA === true) && (mustBeCA === false)) {
  14691. return {
  14692. result: false,
  14693. resultCode: 4,
  14694. resultMessage: "Unable to build certificate chain - \"keyCertSign\" flag was not set"
  14695. };
  14696. }
  14697. if ((isCA === true) && (keyUsagePresent === true) && ((needToCheckCRL) && (cRLSign === false))) {
  14698. return {
  14699. result: false,
  14700. resultCode: 5,
  14701. resultMessage: "Unable to build certificate chain - intermediate certificate must have \"cRLSign\" key usage flag"
  14702. };
  14703. }
  14704. }
  14705. if (isCA === false) {
  14706. return {
  14707. result: false,
  14708. resultCode: 7,
  14709. resultMessage: "Unable to build certificate chain - more than one possible end-user certificate"
  14710. };
  14711. }
  14712. return {
  14713. result: true,
  14714. resultCode: 0,
  14715. resultMessage: EMPTY_STRING
  14716. };
  14717. }
  14718. const basicCheck = async (path, checkDate) => {
  14719. for (let i = 0; i < path.length; i++) {
  14720. if ((path[i].notBefore.value > checkDate) ||
  14721. (path[i].notAfter.value < checkDate)) {
  14722. return {
  14723. result: false,
  14724. resultCode: 8,
  14725. resultMessage: "The certificate is either not yet valid or expired"
  14726. };
  14727. }
  14728. }
  14729. if (path.length < 2) {
  14730. return {
  14731. result: false,
  14732. resultCode: 9,
  14733. resultMessage: "Too short certificate path"
  14734. };
  14735. }
  14736. for (let i = (path.length - 2); i >= 0; i--) {
  14737. if (path[i].issuer.isEqual(path[i].subject) === false) {
  14738. if (path[i].issuer.isEqual(path[i + 1].subject) === false) {
  14739. return {
  14740. result: false,
  14741. resultCode: 10,
  14742. resultMessage: "Incorrect name chaining"
  14743. };
  14744. }
  14745. }
  14746. }
  14747. if ((this.crls.length !== 0) || (this.ocsps.length !== 0)) {
  14748. for (let i = 0; i < (path.length - 1); i++) {
  14749. let ocspResult = 2;
  14750. let crlResult = {
  14751. status: 0,
  14752. statusMessage: EMPTY_STRING
  14753. };
  14754. if (this.ocsps.length !== 0) {
  14755. ocspResult = await findOCSP(path[i], path[i + 1]);
  14756. switch (ocspResult) {
  14757. case 0:
  14758. continue;
  14759. case 1:
  14760. return {
  14761. result: false,
  14762. resultCode: 12,
  14763. resultMessage: "One of certificates was revoked via OCSP response"
  14764. };
  14765. }
  14766. }
  14767. if (this.crls.length !== 0) {
  14768. crlResult = await findCRL(path[i]);
  14769. if (crlResult.status === 0 && crlResult.result) {
  14770. for (let j = 0; j < crlResult.result.length; j++) {
  14771. const isCertificateRevoked = crlResult.result[j].crl.isCertificateRevoked(path[i]);
  14772. if (isCertificateRevoked) {
  14773. return {
  14774. result: false,
  14775. resultCode: 12,
  14776. resultMessage: "One of certificates had been revoked"
  14777. };
  14778. }
  14779. const isCertificateCA = await checkForCA(crlResult.result[j].certificate, true);
  14780. if (isCertificateCA.result === false) {
  14781. return {
  14782. result: false,
  14783. resultCode: 13,
  14784. resultMessage: "CRL issuer certificate is not a CA certificate or does not have crlSign flag"
  14785. };
  14786. }
  14787. }
  14788. }
  14789. else {
  14790. if (passedWhenNotRevValues === false) {
  14791. throw new ChainValidationError(exports.ChainValidationCode.noRevocation, `No revocation values found for one of certificates: ${crlResult.statusMessage}`);
  14792. }
  14793. }
  14794. }
  14795. else {
  14796. if (ocspResult === 2) {
  14797. return {
  14798. result: false,
  14799. resultCode: 11,
  14800. resultMessage: "No revocation values found for one of certificates"
  14801. };
  14802. }
  14803. }
  14804. if ((ocspResult === 2) && (crlResult.status === 2) && passedWhenNotRevValues) {
  14805. const issuerCertificate = path[i + 1];
  14806. let extensionFound = false;
  14807. if (issuerCertificate.extensions) {
  14808. for (const extension of issuerCertificate.extensions) {
  14809. switch (extension.extnID) {
  14810. case id_CRLDistributionPoints:
  14811. case id_FreshestCRL:
  14812. case id_AuthorityInfoAccess:
  14813. extensionFound = true;
  14814. break;
  14815. }
  14816. }
  14817. }
  14818. if (extensionFound) {
  14819. throw new ChainValidationError(exports.ChainValidationCode.noRevocation, `No revocation values found for one of certificates: ${crlResult.statusMessage}`);
  14820. }
  14821. }
  14822. }
  14823. }
  14824. for (const [i, cert] of path.entries()) {
  14825. if (!i) {
  14826. continue;
  14827. }
  14828. const result = await checkForCA(cert);
  14829. if (!result.result) {
  14830. return {
  14831. result: false,
  14832. resultCode: 14,
  14833. resultMessage: "One of intermediate certificates is not a CA certificate"
  14834. };
  14835. }
  14836. }
  14837. return {
  14838. result: true
  14839. };
  14840. };
  14841. localCerts.push(...this.trustedCerts);
  14842. localCerts.push(...this.certs);
  14843. for (let i = 0; i < localCerts.length; i++) {
  14844. for (let j = 0; j < localCerts.length; j++) {
  14845. if (i === j)
  14846. continue;
  14847. if (pvtsutils__namespace.BufferSourceConverter.isEqual(localCerts[i].tbsView, localCerts[j].tbsView)) {
  14848. localCerts.splice(j, 1);
  14849. i = 0;
  14850. break;
  14851. }
  14852. }
  14853. }
  14854. const leafCert = localCerts[localCerts.length - 1];
  14855. let result;
  14856. const certificatePath = [leafCert];
  14857. result = await buildPath(leafCert, crypto);
  14858. if (result.length === 0) {
  14859. throw new ChainValidationError(exports.ChainValidationCode.noPath, "Unable to find certificate path");
  14860. }
  14861. for (let i = result.length - 1; i >= 0; i--) {
  14862. let found = false;
  14863. for (let j = 0; j < (result[i]).length; j++) {
  14864. const certificate = (result[i])[j];
  14865. for (let k = 0; k < this.trustedCerts.length; k++) {
  14866. if (pvtsutils__namespace.BufferSourceConverter.isEqual(certificate.tbsView, this.trustedCerts[k].tbsView)) {
  14867. found = true;
  14868. break;
  14869. }
  14870. }
  14871. if (found)
  14872. break;
  14873. }
  14874. if (!found) {
  14875. result.splice(i, 1);
  14876. }
  14877. }
  14878. if (result.length === 0) {
  14879. throw new ChainValidationError(exports.ChainValidationCode.noValidPath, "No valid certificate paths found");
  14880. }
  14881. let shortestLength = result[0].length;
  14882. let shortestIndex = 0;
  14883. for (let i = 0; i < result.length; i++) {
  14884. if (result[i].length < shortestLength) {
  14885. shortestLength = result[i].length;
  14886. shortestIndex = i;
  14887. }
  14888. }
  14889. for (let i = 0; i < result[shortestIndex].length; i++)
  14890. certificatePath.push((result[shortestIndex])[i]);
  14891. result = await basicCheck(certificatePath, this.checkDate);
  14892. if (result.result === false)
  14893. throw result;
  14894. return certificatePath;
  14895. }
  14896. async verify(parameters = {}, crypto = getCrypto(true)) {
  14897. function compareDNSName(name, constraint) {
  14898. const namePrepared = stringPrep(name);
  14899. const constraintPrepared = stringPrep(constraint);
  14900. const nameSplitted = namePrepared.split(".");
  14901. const constraintSplitted = constraintPrepared.split(".");
  14902. const nameLen = nameSplitted.length;
  14903. const constrLen = constraintSplitted.length;
  14904. if ((nameLen === 0) || (constrLen === 0) || (nameLen < constrLen)) {
  14905. return false;
  14906. }
  14907. for (let i = 0; i < nameLen; i++) {
  14908. if (nameSplitted[i].length === 0) {
  14909. return false;
  14910. }
  14911. }
  14912. for (let i = 0; i < constrLen; i++) {
  14913. if (constraintSplitted[i].length === 0) {
  14914. if (i === 0) {
  14915. if (constrLen === 1) {
  14916. return false;
  14917. }
  14918. continue;
  14919. }
  14920. return false;
  14921. }
  14922. }
  14923. for (let i = 0; i < constrLen; i++) {
  14924. if (constraintSplitted[constrLen - 1 - i].length === 0) {
  14925. continue;
  14926. }
  14927. if (nameSplitted[nameLen - 1 - i].localeCompare(constraintSplitted[constrLen - 1 - i]) !== 0) {
  14928. return false;
  14929. }
  14930. }
  14931. return true;
  14932. }
  14933. function compareRFC822Name(name, constraint) {
  14934. const namePrepared = stringPrep(name);
  14935. const constraintPrepared = stringPrep(constraint);
  14936. const nameSplitted = namePrepared.split("@");
  14937. const constraintSplitted = constraintPrepared.split("@");
  14938. if ((nameSplitted.length === 0) || (constraintSplitted.length === 0) || (nameSplitted.length < constraintSplitted.length))
  14939. return false;
  14940. if (constraintSplitted.length === 1) {
  14941. const result = compareDNSName(nameSplitted[1], constraintSplitted[0]);
  14942. if (result) {
  14943. const ns = nameSplitted[1].split(".");
  14944. const cs = constraintSplitted[0].split(".");
  14945. if (cs[0].length === 0)
  14946. return true;
  14947. return ns.length === cs.length;
  14948. }
  14949. return false;
  14950. }
  14951. return (namePrepared.localeCompare(constraintPrepared) === 0);
  14952. }
  14953. function compareUniformResourceIdentifier(name, constraint) {
  14954. let namePrepared = stringPrep(name);
  14955. const constraintPrepared = stringPrep(constraint);
  14956. const ns = namePrepared.split("/");
  14957. const cs = constraintPrepared.split("/");
  14958. if (cs.length > 1)
  14959. return false;
  14960. if (ns.length > 1) {
  14961. for (let i = 0; i < ns.length; i++) {
  14962. if ((ns[i].length > 0) && (ns[i].charAt(ns[i].length - 1) !== ":")) {
  14963. const nsPort = ns[i].split(":");
  14964. namePrepared = nsPort[0];
  14965. break;
  14966. }
  14967. }
  14968. }
  14969. const result = compareDNSName(namePrepared, constraintPrepared);
  14970. if (result) {
  14971. const nameSplitted = namePrepared.split(".");
  14972. const constraintSplitted = constraintPrepared.split(".");
  14973. if (constraintSplitted[0].length === 0)
  14974. return true;
  14975. return nameSplitted.length === constraintSplitted.length;
  14976. }
  14977. return false;
  14978. }
  14979. function compareIPAddress(name, constraint) {
  14980. const nameView = name.valueBlock.valueHexView;
  14981. const constraintView = constraint.valueBlock.valueHexView;
  14982. if ((nameView.length === 4) && (constraintView.length === 8)) {
  14983. for (let i = 0; i < 4; i++) {
  14984. if ((nameView[i] ^ constraintView[i]) & constraintView[i + 4])
  14985. return false;
  14986. }
  14987. return true;
  14988. }
  14989. if ((nameView.length === 16) && (constraintView.length === 32)) {
  14990. for (let i = 0; i < 16; i++) {
  14991. if ((nameView[i] ^ constraintView[i]) & constraintView[i + 16])
  14992. return false;
  14993. }
  14994. return true;
  14995. }
  14996. return false;
  14997. }
  14998. function compareDirectoryName(name, constraint) {
  14999. if ((name.typesAndValues.length === 0) || (constraint.typesAndValues.length === 0))
  15000. return true;
  15001. if (name.typesAndValues.length < constraint.typesAndValues.length)
  15002. return false;
  15003. let result = true;
  15004. let nameStart = 0;
  15005. for (let i = 0; i < constraint.typesAndValues.length; i++) {
  15006. let localResult = false;
  15007. for (let j = nameStart; j < name.typesAndValues.length; j++) {
  15008. localResult = name.typesAndValues[j].isEqual(constraint.typesAndValues[i]);
  15009. if (name.typesAndValues[j].type === constraint.typesAndValues[i].type)
  15010. result = result && localResult;
  15011. if (localResult === true) {
  15012. if ((nameStart === 0) || (nameStart === j)) {
  15013. nameStart = j + 1;
  15014. break;
  15015. }
  15016. else
  15017. return false;
  15018. }
  15019. }
  15020. if (localResult === false)
  15021. return false;
  15022. }
  15023. return (nameStart === 0) ? false : result;
  15024. }
  15025. try {
  15026. if (this.certs.length === 0)
  15027. throw new Error("Empty certificate array");
  15028. const passedWhenNotRevValues = parameters.passedWhenNotRevValues || false;
  15029. const initialPolicySet = parameters.initialPolicySet || [id_AnyPolicy];
  15030. const initialExplicitPolicy = parameters.initialExplicitPolicy || false;
  15031. const initialPolicyMappingInhibit = parameters.initialPolicyMappingInhibit || false;
  15032. const initialInhibitPolicy = parameters.initialInhibitPolicy || false;
  15033. const initialPermittedSubtreesSet = parameters.initialPermittedSubtreesSet || [];
  15034. const initialExcludedSubtreesSet = parameters.initialExcludedSubtreesSet || [];
  15035. const initialRequiredNameForms = parameters.initialRequiredNameForms || [];
  15036. let explicitPolicyIndicator = initialExplicitPolicy;
  15037. let policyMappingInhibitIndicator = initialPolicyMappingInhibit;
  15038. let inhibitAnyPolicyIndicator = initialInhibitPolicy;
  15039. const pendingConstraints = [
  15040. false,
  15041. false,
  15042. false,
  15043. ];
  15044. let explicitPolicyPending = 0;
  15045. let policyMappingInhibitPending = 0;
  15046. let inhibitAnyPolicyPending = 0;
  15047. let permittedSubtrees = initialPermittedSubtreesSet;
  15048. let excludedSubtrees = initialExcludedSubtreesSet;
  15049. const requiredNameForms = initialRequiredNameForms;
  15050. let pathDepth = 1;
  15051. this.certs = await this.sort(passedWhenNotRevValues, crypto);
  15052. const allPolicies = [];
  15053. allPolicies.push(id_AnyPolicy);
  15054. const policiesAndCerts = [];
  15055. const anyPolicyArray = new Array(this.certs.length - 1);
  15056. for (let ii = 0; ii < (this.certs.length - 1); ii++)
  15057. anyPolicyArray[ii] = true;
  15058. policiesAndCerts.push(anyPolicyArray);
  15059. const policyMappings = new Array(this.certs.length - 1);
  15060. const certPolicies = new Array(this.certs.length - 1);
  15061. let explicitPolicyStart = (explicitPolicyIndicator) ? (this.certs.length - 1) : (-1);
  15062. for (let i = (this.certs.length - 2); i >= 0; i--, pathDepth++) {
  15063. const cert = this.certs[i];
  15064. if (cert.extensions) {
  15065. for (let j = 0; j < cert.extensions.length; j++) {
  15066. const extension = cert.extensions[j];
  15067. if (extension.extnID === id_CertificatePolicies) {
  15068. certPolicies[i] = extension.parsedValue;
  15069. for (let s = 0; s < allPolicies.length; s++) {
  15070. if (allPolicies[s] === id_AnyPolicy) {
  15071. delete (policiesAndCerts[s])[i];
  15072. break;
  15073. }
  15074. }
  15075. for (let k = 0; k < extension.parsedValue.certificatePolicies.length; k++) {
  15076. let policyIndex = (-1);
  15077. const policyId = extension.parsedValue.certificatePolicies[k].policyIdentifier;
  15078. for (let s = 0; s < allPolicies.length; s++) {
  15079. if (policyId === allPolicies[s]) {
  15080. policyIndex = s;
  15081. break;
  15082. }
  15083. }
  15084. if (policyIndex === (-1)) {
  15085. allPolicies.push(policyId);
  15086. const certArray = new Array(this.certs.length - 1);
  15087. certArray[i] = true;
  15088. policiesAndCerts.push(certArray);
  15089. }
  15090. else
  15091. (policiesAndCerts[policyIndex])[i] = true;
  15092. }
  15093. }
  15094. if (extension.extnID === id_PolicyMappings) {
  15095. if (policyMappingInhibitIndicator) {
  15096. return {
  15097. result: false,
  15098. resultCode: 98,
  15099. resultMessage: "Policy mapping prohibited"
  15100. };
  15101. }
  15102. policyMappings[i] = extension.parsedValue;
  15103. }
  15104. if (extension.extnID === id_PolicyConstraints) {
  15105. if (explicitPolicyIndicator === false) {
  15106. if (extension.parsedValue.requireExplicitPolicy === 0) {
  15107. explicitPolicyIndicator = true;
  15108. explicitPolicyStart = i;
  15109. }
  15110. else {
  15111. if (pendingConstraints[0] === false) {
  15112. pendingConstraints[0] = true;
  15113. explicitPolicyPending = extension.parsedValue.requireExplicitPolicy;
  15114. }
  15115. else
  15116. explicitPolicyPending = (explicitPolicyPending > extension.parsedValue.requireExplicitPolicy) ? extension.parsedValue.requireExplicitPolicy : explicitPolicyPending;
  15117. }
  15118. if (extension.parsedValue.inhibitPolicyMapping === 0)
  15119. policyMappingInhibitIndicator = true;
  15120. else {
  15121. if (pendingConstraints[1] === false) {
  15122. pendingConstraints[1] = true;
  15123. policyMappingInhibitPending = extension.parsedValue.inhibitPolicyMapping + 1;
  15124. }
  15125. else
  15126. policyMappingInhibitPending = (policyMappingInhibitPending > (extension.parsedValue.inhibitPolicyMapping + 1)) ? (extension.parsedValue.inhibitPolicyMapping + 1) : policyMappingInhibitPending;
  15127. }
  15128. }
  15129. }
  15130. if (extension.extnID === id_InhibitAnyPolicy) {
  15131. if (inhibitAnyPolicyIndicator === false) {
  15132. if (extension.parsedValue.valueBlock.valueDec === 0)
  15133. inhibitAnyPolicyIndicator = true;
  15134. else {
  15135. if (pendingConstraints[2] === false) {
  15136. pendingConstraints[2] = true;
  15137. inhibitAnyPolicyPending = extension.parsedValue.valueBlock.valueDec;
  15138. }
  15139. else
  15140. inhibitAnyPolicyPending = (inhibitAnyPolicyPending > extension.parsedValue.valueBlock.valueDec) ? extension.parsedValue.valueBlock.valueDec : inhibitAnyPolicyPending;
  15141. }
  15142. }
  15143. }
  15144. }
  15145. if (inhibitAnyPolicyIndicator === true) {
  15146. let policyIndex = (-1);
  15147. for (let searchAnyPolicy = 0; searchAnyPolicy < allPolicies.length; searchAnyPolicy++) {
  15148. if (allPolicies[searchAnyPolicy] === id_AnyPolicy) {
  15149. policyIndex = searchAnyPolicy;
  15150. break;
  15151. }
  15152. }
  15153. if (policyIndex !== (-1))
  15154. delete (policiesAndCerts[0])[i];
  15155. }
  15156. if (explicitPolicyIndicator === false) {
  15157. if (pendingConstraints[0] === true) {
  15158. explicitPolicyPending--;
  15159. if (explicitPolicyPending === 0) {
  15160. explicitPolicyIndicator = true;
  15161. explicitPolicyStart = i;
  15162. pendingConstraints[0] = false;
  15163. }
  15164. }
  15165. }
  15166. if (policyMappingInhibitIndicator === false) {
  15167. if (pendingConstraints[1] === true) {
  15168. policyMappingInhibitPending--;
  15169. if (policyMappingInhibitPending === 0) {
  15170. policyMappingInhibitIndicator = true;
  15171. pendingConstraints[1] = false;
  15172. }
  15173. }
  15174. }
  15175. if (inhibitAnyPolicyIndicator === false) {
  15176. if (pendingConstraints[2] === true) {
  15177. inhibitAnyPolicyPending--;
  15178. if (inhibitAnyPolicyPending === 0) {
  15179. inhibitAnyPolicyIndicator = true;
  15180. pendingConstraints[2] = false;
  15181. }
  15182. }
  15183. }
  15184. }
  15185. }
  15186. for (let i = 0; i < (this.certs.length - 1); i++) {
  15187. if ((i < (this.certs.length - 2)) && (typeof policyMappings[i + 1] !== "undefined")) {
  15188. for (let k = 0; k < policyMappings[i + 1].mappings.length; k++) {
  15189. if ((policyMappings[i + 1].mappings[k].issuerDomainPolicy === id_AnyPolicy) || (policyMappings[i + 1].mappings[k].subjectDomainPolicy === id_AnyPolicy)) {
  15190. return {
  15191. result: false,
  15192. resultCode: 99,
  15193. resultMessage: "The \"anyPolicy\" should not be a part of policy mapping scheme"
  15194. };
  15195. }
  15196. let issuerDomainPolicyIndex = (-1);
  15197. let subjectDomainPolicyIndex = (-1);
  15198. for (let n = 0; n < allPolicies.length; n++) {
  15199. if (allPolicies[n] === policyMappings[i + 1].mappings[k].issuerDomainPolicy)
  15200. issuerDomainPolicyIndex = n;
  15201. if (allPolicies[n] === policyMappings[i + 1].mappings[k].subjectDomainPolicy)
  15202. subjectDomainPolicyIndex = n;
  15203. }
  15204. if (typeof (policiesAndCerts[issuerDomainPolicyIndex])[i] !== "undefined")
  15205. delete (policiesAndCerts[issuerDomainPolicyIndex])[i];
  15206. for (let j = 0; j < certPolicies[i].certificatePolicies.length; j++) {
  15207. if (policyMappings[i + 1].mappings[k].subjectDomainPolicy === certPolicies[i].certificatePolicies[j].policyIdentifier) {
  15208. if ((issuerDomainPolicyIndex !== (-1)) && (subjectDomainPolicyIndex !== (-1))) {
  15209. for (let m = 0; m <= i; m++) {
  15210. if (typeof (policiesAndCerts[subjectDomainPolicyIndex])[m] !== "undefined") {
  15211. (policiesAndCerts[issuerDomainPolicyIndex])[m] = true;
  15212. delete (policiesAndCerts[subjectDomainPolicyIndex])[m];
  15213. }
  15214. }
  15215. }
  15216. }
  15217. }
  15218. }
  15219. }
  15220. }
  15221. for (let i = 0; i < allPolicies.length; i++) {
  15222. if (allPolicies[i] === id_AnyPolicy) {
  15223. for (let j = 0; j < explicitPolicyStart; j++)
  15224. delete (policiesAndCerts[i])[j];
  15225. }
  15226. }
  15227. const authConstrPolicies = [];
  15228. for (let i = 0; i < policiesAndCerts.length; i++) {
  15229. let found = true;
  15230. for (let j = 0; j < (this.certs.length - 1); j++) {
  15231. let anyPolicyFound = false;
  15232. if ((j < explicitPolicyStart) && (allPolicies[i] === id_AnyPolicy) && (allPolicies.length > 1)) {
  15233. found = false;
  15234. break;
  15235. }
  15236. if (typeof (policiesAndCerts[i])[j] === "undefined") {
  15237. if (j >= explicitPolicyStart) {
  15238. for (let k = 0; k < allPolicies.length; k++) {
  15239. if (allPolicies[k] === id_AnyPolicy) {
  15240. if ((policiesAndCerts[k])[j] === true)
  15241. anyPolicyFound = true;
  15242. break;
  15243. }
  15244. }
  15245. }
  15246. if (!anyPolicyFound) {
  15247. found = false;
  15248. break;
  15249. }
  15250. }
  15251. }
  15252. if (found === true)
  15253. authConstrPolicies.push(allPolicies[i]);
  15254. }
  15255. let userConstrPolicies = [];
  15256. if ((initialPolicySet.length === 1) && (initialPolicySet[0] === id_AnyPolicy) && (explicitPolicyIndicator === false))
  15257. userConstrPolicies = initialPolicySet;
  15258. else {
  15259. if ((authConstrPolicies.length === 1) && (authConstrPolicies[0] === id_AnyPolicy))
  15260. userConstrPolicies = initialPolicySet;
  15261. else {
  15262. for (let i = 0; i < authConstrPolicies.length; i++) {
  15263. for (let j = 0; j < initialPolicySet.length; j++) {
  15264. if ((initialPolicySet[j] === authConstrPolicies[i]) || (initialPolicySet[j] === id_AnyPolicy)) {
  15265. userConstrPolicies.push(authConstrPolicies[i]);
  15266. break;
  15267. }
  15268. }
  15269. }
  15270. }
  15271. }
  15272. const policyResult = {
  15273. result: (userConstrPolicies.length > 0),
  15274. resultCode: 0,
  15275. resultMessage: (userConstrPolicies.length > 0) ? EMPTY_STRING : "Zero \"userConstrPolicies\" array, no intersections with \"authConstrPolicies\"",
  15276. authConstrPolicies,
  15277. userConstrPolicies,
  15278. explicitPolicyIndicator,
  15279. policyMappings,
  15280. certificatePath: this.certs
  15281. };
  15282. if (userConstrPolicies.length === 0)
  15283. return policyResult;
  15284. if (policyResult.result === false)
  15285. return policyResult;
  15286. pathDepth = 1;
  15287. for (let i = (this.certs.length - 2); i >= 0; i--, pathDepth++) {
  15288. const cert = this.certs[i];
  15289. let subjectAltNames = [];
  15290. let certPermittedSubtrees = [];
  15291. let certExcludedSubtrees = [];
  15292. if (cert.extensions) {
  15293. for (let j = 0; j < cert.extensions.length; j++) {
  15294. const extension = cert.extensions[j];
  15295. if (extension.extnID === id_NameConstraints) {
  15296. if ("permittedSubtrees" in extension.parsedValue)
  15297. certPermittedSubtrees = certPermittedSubtrees.concat(extension.parsedValue.permittedSubtrees);
  15298. if ("excludedSubtrees" in extension.parsedValue)
  15299. certExcludedSubtrees = certExcludedSubtrees.concat(extension.parsedValue.excludedSubtrees);
  15300. }
  15301. if (extension.extnID === id_SubjectAltName)
  15302. subjectAltNames = subjectAltNames.concat(extension.parsedValue.altNames);
  15303. }
  15304. }
  15305. let formFound = (requiredNameForms.length <= 0);
  15306. for (let j = 0; j < requiredNameForms.length; j++) {
  15307. switch (requiredNameForms[j].base.type) {
  15308. case 4:
  15309. {
  15310. if (requiredNameForms[j].base.value.typesAndValues.length !== cert.subject.typesAndValues.length)
  15311. continue;
  15312. formFound = true;
  15313. for (let k = 0; k < cert.subject.typesAndValues.length; k++) {
  15314. if (cert.subject.typesAndValues[k].type !== requiredNameForms[j].base.value.typesAndValues[k].type) {
  15315. formFound = false;
  15316. break;
  15317. }
  15318. }
  15319. if (formFound === true)
  15320. break;
  15321. }
  15322. break;
  15323. default:
  15324. }
  15325. }
  15326. if (formFound === false) {
  15327. policyResult.result = false;
  15328. policyResult.resultCode = 21;
  15329. policyResult.resultMessage = "No necessary name form found";
  15330. throw policyResult;
  15331. }
  15332. const constrGroups = [
  15333. [],
  15334. [],
  15335. [],
  15336. [],
  15337. [],
  15338. ];
  15339. for (let j = 0; j < permittedSubtrees.length; j++) {
  15340. switch (permittedSubtrees[j].base.type) {
  15341. case 1:
  15342. constrGroups[0].push(permittedSubtrees[j]);
  15343. break;
  15344. case 2:
  15345. constrGroups[1].push(permittedSubtrees[j]);
  15346. break;
  15347. case 4:
  15348. constrGroups[2].push(permittedSubtrees[j]);
  15349. break;
  15350. case 6:
  15351. constrGroups[3].push(permittedSubtrees[j]);
  15352. break;
  15353. case 7:
  15354. constrGroups[4].push(permittedSubtrees[j]);
  15355. break;
  15356. default:
  15357. }
  15358. }
  15359. for (let p = 0; p < 5; p++) {
  15360. let groupPermitted = false;
  15361. let valueExists = false;
  15362. const group = constrGroups[p];
  15363. for (let j = 0; j < group.length; j++) {
  15364. switch (p) {
  15365. case 0:
  15366. if (subjectAltNames.length > 0) {
  15367. for (let k = 0; k < subjectAltNames.length; k++) {
  15368. if (subjectAltNames[k].type === 1) {
  15369. valueExists = true;
  15370. groupPermitted = groupPermitted || compareRFC822Name(subjectAltNames[k].value, group[j].base.value);
  15371. }
  15372. }
  15373. }
  15374. else {
  15375. for (let k = 0; k < cert.subject.typesAndValues.length; k++) {
  15376. if ((cert.subject.typesAndValues[k].type === "1.2.840.113549.1.9.1") ||
  15377. (cert.subject.typesAndValues[k].type === "0.9.2342.19200300.100.1.3")) {
  15378. valueExists = true;
  15379. groupPermitted = groupPermitted || compareRFC822Name(cert.subject.typesAndValues[k].value.valueBlock.value, group[j].base.value);
  15380. }
  15381. }
  15382. }
  15383. break;
  15384. case 1:
  15385. if (subjectAltNames.length > 0) {
  15386. for (let k = 0; k < subjectAltNames.length; k++) {
  15387. if (subjectAltNames[k].type === 2) {
  15388. valueExists = true;
  15389. groupPermitted = groupPermitted || compareDNSName(subjectAltNames[k].value, group[j].base.value);
  15390. }
  15391. }
  15392. }
  15393. break;
  15394. case 2:
  15395. valueExists = true;
  15396. groupPermitted = compareDirectoryName(cert.subject, group[j].base.value);
  15397. break;
  15398. case 3:
  15399. if (subjectAltNames.length > 0) {
  15400. for (let k = 0; k < subjectAltNames.length; k++) {
  15401. if (subjectAltNames[k].type === 6) {
  15402. valueExists = true;
  15403. groupPermitted = groupPermitted || compareUniformResourceIdentifier(subjectAltNames[k].value, group[j].base.value);
  15404. }
  15405. }
  15406. }
  15407. break;
  15408. case 4:
  15409. if (subjectAltNames.length > 0) {
  15410. for (let k = 0; k < subjectAltNames.length; k++) {
  15411. if (subjectAltNames[k].type === 7) {
  15412. valueExists = true;
  15413. groupPermitted = groupPermitted || compareIPAddress(subjectAltNames[k].value, group[j].base.value);
  15414. }
  15415. }
  15416. }
  15417. break;
  15418. default:
  15419. }
  15420. if (groupPermitted)
  15421. break;
  15422. }
  15423. if ((groupPermitted === false) && (group.length > 0) && valueExists) {
  15424. policyResult.result = false;
  15425. policyResult.resultCode = 41;
  15426. policyResult.resultMessage = "Failed to meet \"permitted sub-trees\" name constraint";
  15427. throw policyResult;
  15428. }
  15429. }
  15430. let excluded = false;
  15431. for (let j = 0; j < excludedSubtrees.length; j++) {
  15432. switch (excludedSubtrees[j].base.type) {
  15433. case 1:
  15434. if (subjectAltNames.length >= 0) {
  15435. for (let k = 0; k < subjectAltNames.length; k++) {
  15436. if (subjectAltNames[k].type === 1)
  15437. excluded = excluded || compareRFC822Name(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15438. }
  15439. }
  15440. else {
  15441. for (let k = 0; k < cert.subject.typesAndValues.length; k++) {
  15442. if ((cert.subject.typesAndValues[k].type === "1.2.840.113549.1.9.1") ||
  15443. (cert.subject.typesAndValues[k].type === "0.9.2342.19200300.100.1.3"))
  15444. excluded = excluded || compareRFC822Name(cert.subject.typesAndValues[k].value.valueBlock.value, excludedSubtrees[j].base.value);
  15445. }
  15446. }
  15447. break;
  15448. case 2:
  15449. if (subjectAltNames.length > 0) {
  15450. for (let k = 0; k < subjectAltNames.length; k++) {
  15451. if (subjectAltNames[k].type === 2)
  15452. excluded = excluded || compareDNSName(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15453. }
  15454. }
  15455. break;
  15456. case 4:
  15457. excluded = excluded || compareDirectoryName(cert.subject, excludedSubtrees[j].base.value);
  15458. break;
  15459. case 6:
  15460. if (subjectAltNames.length > 0) {
  15461. for (let k = 0; k < subjectAltNames.length; k++) {
  15462. if (subjectAltNames[k].type === 6)
  15463. excluded = excluded || compareUniformResourceIdentifier(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15464. }
  15465. }
  15466. break;
  15467. case 7:
  15468. if (subjectAltNames.length > 0) {
  15469. for (let k = 0; k < subjectAltNames.length; k++) {
  15470. if (subjectAltNames[k].type === 7)
  15471. excluded = excluded || compareIPAddress(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15472. }
  15473. }
  15474. break;
  15475. default:
  15476. }
  15477. if (excluded)
  15478. break;
  15479. }
  15480. if (excluded === true) {
  15481. policyResult.result = false;
  15482. policyResult.resultCode = 42;
  15483. policyResult.resultMessage = "Failed to meet \"excluded sub-trees\" name constraint";
  15484. throw policyResult;
  15485. }
  15486. permittedSubtrees = permittedSubtrees.concat(certPermittedSubtrees);
  15487. excludedSubtrees = excludedSubtrees.concat(certExcludedSubtrees);
  15488. }
  15489. return policyResult;
  15490. }
  15491. catch (error) {
  15492. if (error instanceof Error) {
  15493. if (error instanceof ChainValidationError) {
  15494. return {
  15495. result: false,
  15496. resultCode: error.code,
  15497. resultMessage: error.message,
  15498. error: error,
  15499. };
  15500. }
  15501. return {
  15502. result: false,
  15503. resultCode: exports.ChainValidationCode.unknown,
  15504. resultMessage: error.message,
  15505. error: error,
  15506. };
  15507. }
  15508. if (error && typeof error === "object" && "resultMessage" in error) {
  15509. return error;
  15510. }
  15511. return {
  15512. result: false,
  15513. resultCode: -1,
  15514. resultMessage: `${error}`,
  15515. };
  15516. }
  15517. }
  15518. }
  15519. const TBS_RESPONSE_DATA = "tbsResponseData";
  15520. const SIGNATURE_ALGORITHM$3 = "signatureAlgorithm";
  15521. const SIGNATURE$2 = "signature";
  15522. const CERTS$1 = "certs";
  15523. const BASIC_OCSP_RESPONSE = "BasicOCSPResponse";
  15524. const BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA = `${BASIC_OCSP_RESPONSE}.${TBS_RESPONSE_DATA}`;
  15525. const BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM = `${BASIC_OCSP_RESPONSE}.${SIGNATURE_ALGORITHM$3}`;
  15526. const BASIC_OCSP_RESPONSE_SIGNATURE = `${BASIC_OCSP_RESPONSE}.${SIGNATURE$2}`;
  15527. const BASIC_OCSP_RESPONSE_CERTS = `${BASIC_OCSP_RESPONSE}.${CERTS$1}`;
  15528. const CLEAR_PROPS$g = [
  15529. BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA,
  15530. BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM,
  15531. BASIC_OCSP_RESPONSE_SIGNATURE,
  15532. BASIC_OCSP_RESPONSE_CERTS
  15533. ];
  15534. class BasicOCSPResponse extends PkiObject {
  15535. constructor(parameters = {}) {
  15536. super();
  15537. this.tbsResponseData = pvutils__namespace.getParametersValue(parameters, TBS_RESPONSE_DATA, BasicOCSPResponse.defaultValues(TBS_RESPONSE_DATA));
  15538. this.signatureAlgorithm = pvutils__namespace.getParametersValue(parameters, SIGNATURE_ALGORITHM$3, BasicOCSPResponse.defaultValues(SIGNATURE_ALGORITHM$3));
  15539. this.signature = pvutils__namespace.getParametersValue(parameters, SIGNATURE$2, BasicOCSPResponse.defaultValues(SIGNATURE$2));
  15540. if (CERTS$1 in parameters) {
  15541. this.certs = pvutils__namespace.getParametersValue(parameters, CERTS$1, BasicOCSPResponse.defaultValues(CERTS$1));
  15542. }
  15543. if (parameters.schema) {
  15544. this.fromSchema(parameters.schema);
  15545. }
  15546. }
  15547. static defaultValues(memberName) {
  15548. switch (memberName) {
  15549. case TBS_RESPONSE_DATA:
  15550. return new ResponseData();
  15551. case SIGNATURE_ALGORITHM$3:
  15552. return new AlgorithmIdentifier();
  15553. case SIGNATURE$2:
  15554. return new asn1js__namespace.BitString();
  15555. case CERTS$1:
  15556. return [];
  15557. default:
  15558. return super.defaultValues(memberName);
  15559. }
  15560. }
  15561. static compareWithDefault(memberName, memberValue) {
  15562. switch (memberName) {
  15563. case "type":
  15564. {
  15565. let comparisonResult = ((ResponseData.compareWithDefault("tbs", memberValue.tbs)) &&
  15566. (ResponseData.compareWithDefault("responderID", memberValue.responderID)) &&
  15567. (ResponseData.compareWithDefault("producedAt", memberValue.producedAt)) &&
  15568. (ResponseData.compareWithDefault("responses", memberValue.responses)));
  15569. if ("responseExtensions" in memberValue)
  15570. comparisonResult = comparisonResult && (ResponseData.compareWithDefault("responseExtensions", memberValue.responseExtensions));
  15571. return comparisonResult;
  15572. }
  15573. case SIGNATURE_ALGORITHM$3:
  15574. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  15575. case SIGNATURE$2:
  15576. return (memberValue.isEqual(BasicOCSPResponse.defaultValues(memberName)));
  15577. case CERTS$1:
  15578. return (memberValue.length === 0);
  15579. default:
  15580. return super.defaultValues(memberName);
  15581. }
  15582. }
  15583. static schema(parameters = {}) {
  15584. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  15585. return (new asn1js__namespace.Sequence({
  15586. name: (names.blockName || BASIC_OCSP_RESPONSE),
  15587. value: [
  15588. ResponseData.schema(names.tbsResponseData || {
  15589. names: {
  15590. blockName: BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA
  15591. }
  15592. }),
  15593. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  15594. names: {
  15595. blockName: BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM
  15596. }
  15597. }),
  15598. new asn1js__namespace.BitString({ name: (names.signature || BASIC_OCSP_RESPONSE_SIGNATURE) }),
  15599. new asn1js__namespace.Constructed({
  15600. optional: true,
  15601. idBlock: {
  15602. tagClass: 3,
  15603. tagNumber: 0
  15604. },
  15605. value: [
  15606. new asn1js__namespace.Sequence({
  15607. value: [new asn1js__namespace.Repeated({
  15608. name: BASIC_OCSP_RESPONSE_CERTS,
  15609. value: Certificate.schema(names.certs || {})
  15610. })]
  15611. })
  15612. ]
  15613. })
  15614. ]
  15615. }));
  15616. }
  15617. fromSchema(schema) {
  15618. pvutils__namespace.clearProps(schema, CLEAR_PROPS$g);
  15619. const asn1 = asn1js__namespace.compareSchema(schema, schema, BasicOCSPResponse.schema());
  15620. AsnError.assertSchema(asn1, this.className);
  15621. this.tbsResponseData = new ResponseData({ schema: asn1.result[BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA] });
  15622. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result[BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM] });
  15623. this.signature = asn1.result[BASIC_OCSP_RESPONSE_SIGNATURE];
  15624. if (BASIC_OCSP_RESPONSE_CERTS in asn1.result) {
  15625. this.certs = Array.from(asn1.result[BASIC_OCSP_RESPONSE_CERTS], element => new Certificate({ schema: element }));
  15626. }
  15627. }
  15628. toSchema() {
  15629. const outputArray = [];
  15630. outputArray.push(this.tbsResponseData.toSchema());
  15631. outputArray.push(this.signatureAlgorithm.toSchema());
  15632. outputArray.push(this.signature);
  15633. if (this.certs) {
  15634. outputArray.push(new asn1js__namespace.Constructed({
  15635. idBlock: {
  15636. tagClass: 3,
  15637. tagNumber: 0
  15638. },
  15639. value: [
  15640. new asn1js__namespace.Sequence({
  15641. value: Array.from(this.certs, o => o.toSchema())
  15642. })
  15643. ]
  15644. }));
  15645. }
  15646. return (new asn1js__namespace.Sequence({
  15647. value: outputArray
  15648. }));
  15649. }
  15650. toJSON() {
  15651. const res = {
  15652. tbsResponseData: this.tbsResponseData.toJSON(),
  15653. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  15654. signature: this.signature.toJSON(),
  15655. };
  15656. if (this.certs) {
  15657. res.certs = Array.from(this.certs, o => o.toJSON());
  15658. }
  15659. return res;
  15660. }
  15661. async getCertificateStatus(certificate, issuerCertificate, crypto = getCrypto(true)) {
  15662. const result = {
  15663. isForCertificate: false,
  15664. status: 2
  15665. };
  15666. const hashesObject = {};
  15667. const certIDs = [];
  15668. for (const response of this.tbsResponseData.responses) {
  15669. const hashAlgorithm = crypto.getAlgorithmByOID(response.certID.hashAlgorithm.algorithmId, true, "CertID.hashAlgorithm");
  15670. if (!hashesObject[hashAlgorithm.name]) {
  15671. hashesObject[hashAlgorithm.name] = 1;
  15672. const certID = new CertID();
  15673. certIDs.push(certID);
  15674. await certID.createForCertificate(certificate, {
  15675. hashAlgorithm: hashAlgorithm.name,
  15676. issuerCertificate
  15677. }, crypto);
  15678. }
  15679. }
  15680. for (const response of this.tbsResponseData.responses) {
  15681. for (const id of certIDs) {
  15682. if (response.certID.isEqual(id)) {
  15683. result.isForCertificate = true;
  15684. try {
  15685. switch (response.certStatus.idBlock.isConstructed) {
  15686. case true:
  15687. if (response.certStatus.idBlock.tagNumber === 1)
  15688. result.status = 1;
  15689. break;
  15690. case false:
  15691. switch (response.certStatus.idBlock.tagNumber) {
  15692. case 0:
  15693. result.status = 0;
  15694. break;
  15695. case 2:
  15696. result.status = 2;
  15697. break;
  15698. default:
  15699. }
  15700. break;
  15701. default:
  15702. }
  15703. }
  15704. catch {
  15705. }
  15706. return result;
  15707. }
  15708. }
  15709. }
  15710. return result;
  15711. }
  15712. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  15713. if (!privateKey) {
  15714. throw new Error("Need to provide a private key for signing");
  15715. }
  15716. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  15717. const algorithm = signatureParams.parameters.algorithm;
  15718. if (!("name" in algorithm)) {
  15719. throw new Error("Empty algorithm");
  15720. }
  15721. this.signatureAlgorithm = signatureParams.signatureAlgorithm;
  15722. this.tbsResponseData.tbsView = new Uint8Array(this.tbsResponseData.toSchema(true).toBER());
  15723. const signature = await crypto.signWithPrivateKey(this.tbsResponseData.tbsView, privateKey, { algorithm });
  15724. this.signature = new asn1js__namespace.BitString({ valueHex: signature });
  15725. }
  15726. async verify(params = {}, crypto = getCrypto(true)) {
  15727. let signerCert = null;
  15728. let certIndex = -1;
  15729. const trustedCerts = params.trustedCerts || [];
  15730. if (!this.certs) {
  15731. throw new Error("No certificates attached to the BasicOCSPResponse");
  15732. }
  15733. switch (true) {
  15734. case (this.tbsResponseData.responderID instanceof RelativeDistinguishedNames):
  15735. for (const [index, certificate] of this.certs.entries()) {
  15736. if (certificate.subject.isEqual(this.tbsResponseData.responderID)) {
  15737. certIndex = index;
  15738. break;
  15739. }
  15740. }
  15741. break;
  15742. case (this.tbsResponseData.responderID instanceof asn1js__namespace.OctetString):
  15743. for (const [index, cert] of this.certs.entries()) {
  15744. const hash = await crypto.digest({ name: "sha-1" }, cert.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView);
  15745. if (pvutils__namespace.isEqualBuffer(hash, this.tbsResponseData.responderID.valueBlock.valueHex)) {
  15746. certIndex = index;
  15747. break;
  15748. }
  15749. }
  15750. break;
  15751. default:
  15752. throw new Error("Wrong value for responderID");
  15753. }
  15754. if (certIndex === (-1))
  15755. throw new Error("Correct certificate was not found in OCSP response");
  15756. signerCert = this.certs[certIndex];
  15757. const additionalCerts = [signerCert];
  15758. for (const cert of this.certs) {
  15759. const caCert = await checkCA(cert, signerCert);
  15760. if (caCert) {
  15761. additionalCerts.push(caCert);
  15762. }
  15763. }
  15764. const certChain = new CertificateChainValidationEngine({
  15765. certs: additionalCerts,
  15766. trustedCerts,
  15767. });
  15768. const verificationResult = await certChain.verify({}, crypto);
  15769. if (!verificationResult.result) {
  15770. throw new Error("Validation of signer's certificate failed");
  15771. }
  15772. return crypto.verifyWithPublicKey(this.tbsResponseData.tbsView, this.signature, this.certs[certIndex].subjectPublicKeyInfo, this.signatureAlgorithm);
  15773. }
  15774. }
  15775. BasicOCSPResponse.CLASS_NAME = "BasicOCSPResponse";
  15776. const TBS$1 = "tbs";
  15777. const VERSION$6 = "version";
  15778. const SUBJECT = "subject";
  15779. const SPKI = "subjectPublicKeyInfo";
  15780. const ATTRIBUTES$1 = "attributes";
  15781. const SIGNATURE_ALGORITHM$2 = "signatureAlgorithm";
  15782. const SIGNATURE_VALUE = "signatureValue";
  15783. const CSR_INFO = "CertificationRequestInfo";
  15784. const CSR_INFO_VERSION = `${CSR_INFO}.version`;
  15785. const CSR_INFO_SUBJECT = `${CSR_INFO}.subject`;
  15786. const CSR_INFO_SPKI = `${CSR_INFO}.subjectPublicKeyInfo`;
  15787. const CSR_INFO_ATTRS = `${CSR_INFO}.attributes`;
  15788. const CLEAR_PROPS$f = [
  15789. CSR_INFO,
  15790. CSR_INFO_VERSION,
  15791. CSR_INFO_SUBJECT,
  15792. CSR_INFO_SPKI,
  15793. CSR_INFO_ATTRS,
  15794. SIGNATURE_ALGORITHM$2,
  15795. SIGNATURE_VALUE
  15796. ];
  15797. function CertificationRequestInfo(parameters = {}) {
  15798. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  15799. return (new asn1js__namespace.Sequence({
  15800. name: (names.CertificationRequestInfo || CSR_INFO),
  15801. value: [
  15802. new asn1js__namespace.Integer({ name: (names.CertificationRequestInfoVersion || CSR_INFO_VERSION) }),
  15803. RelativeDistinguishedNames.schema(names.subject || {
  15804. names: {
  15805. blockName: CSR_INFO_SUBJECT
  15806. }
  15807. }),
  15808. PublicKeyInfo.schema({
  15809. names: {
  15810. blockName: CSR_INFO_SPKI
  15811. }
  15812. }),
  15813. new asn1js__namespace.Constructed({
  15814. optional: true,
  15815. idBlock: {
  15816. tagClass: 3,
  15817. tagNumber: 0
  15818. },
  15819. value: [
  15820. new asn1js__namespace.Repeated({
  15821. optional: true,
  15822. name: (names.CertificationRequestInfoAttributes || CSR_INFO_ATTRS),
  15823. value: Attribute.schema(names.attributes || {})
  15824. })
  15825. ]
  15826. })
  15827. ]
  15828. }));
  15829. }
  15830. class CertificationRequest extends PkiObject {
  15831. get tbs() {
  15832. return pvtsutils__namespace.BufferSourceConverter.toArrayBuffer(this.tbsView);
  15833. }
  15834. set tbs(value) {
  15835. this.tbsView = new Uint8Array(value);
  15836. }
  15837. constructor(parameters = {}) {
  15838. super();
  15839. this.tbsView = new Uint8Array(pvutils__namespace.getParametersValue(parameters, TBS$1, CertificationRequest.defaultValues(TBS$1)));
  15840. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$6, CertificationRequest.defaultValues(VERSION$6));
  15841. this.subject = pvutils__namespace.getParametersValue(parameters, SUBJECT, CertificationRequest.defaultValues(SUBJECT));
  15842. this.subjectPublicKeyInfo = pvutils__namespace.getParametersValue(parameters, SPKI, CertificationRequest.defaultValues(SPKI));
  15843. if (ATTRIBUTES$1 in parameters) {
  15844. this.attributes = pvutils__namespace.getParametersValue(parameters, ATTRIBUTES$1, CertificationRequest.defaultValues(ATTRIBUTES$1));
  15845. }
  15846. this.signatureAlgorithm = pvutils__namespace.getParametersValue(parameters, SIGNATURE_ALGORITHM$2, CertificationRequest.defaultValues(SIGNATURE_ALGORITHM$2));
  15847. this.signatureValue = pvutils__namespace.getParametersValue(parameters, SIGNATURE_VALUE, CertificationRequest.defaultValues(SIGNATURE_VALUE));
  15848. if (parameters.schema) {
  15849. this.fromSchema(parameters.schema);
  15850. }
  15851. }
  15852. static defaultValues(memberName) {
  15853. switch (memberName) {
  15854. case TBS$1:
  15855. return EMPTY_BUFFER;
  15856. case VERSION$6:
  15857. return 0;
  15858. case SUBJECT:
  15859. return new RelativeDistinguishedNames();
  15860. case SPKI:
  15861. return new PublicKeyInfo();
  15862. case ATTRIBUTES$1:
  15863. return [];
  15864. case SIGNATURE_ALGORITHM$2:
  15865. return new AlgorithmIdentifier();
  15866. case SIGNATURE_VALUE:
  15867. return new asn1js__namespace.BitString();
  15868. default:
  15869. return super.defaultValues(memberName);
  15870. }
  15871. }
  15872. static schema(parameters = {}) {
  15873. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  15874. return (new asn1js__namespace.Sequence({
  15875. value: [
  15876. CertificationRequestInfo(names.certificationRequestInfo || {}),
  15877. new asn1js__namespace.Sequence({
  15878. name: (names.signatureAlgorithm || SIGNATURE_ALGORITHM$2),
  15879. value: [
  15880. new asn1js__namespace.ObjectIdentifier(),
  15881. new asn1js__namespace.Any({ optional: true })
  15882. ]
  15883. }),
  15884. new asn1js__namespace.BitString({ name: (names.signatureValue || SIGNATURE_VALUE) })
  15885. ]
  15886. }));
  15887. }
  15888. fromSchema(schema) {
  15889. pvutils__namespace.clearProps(schema, CLEAR_PROPS$f);
  15890. const asn1 = asn1js__namespace.compareSchema(schema, schema, CertificationRequest.schema());
  15891. AsnError.assertSchema(asn1, this.className);
  15892. this.tbsView = asn1.result.CertificationRequestInfo.valueBeforeDecodeView;
  15893. this.version = asn1.result[CSR_INFO_VERSION].valueBlock.valueDec;
  15894. this.subject = new RelativeDistinguishedNames({ schema: asn1.result[CSR_INFO_SUBJECT] });
  15895. this.subjectPublicKeyInfo = new PublicKeyInfo({ schema: asn1.result[CSR_INFO_SPKI] });
  15896. if (CSR_INFO_ATTRS in asn1.result) {
  15897. this.attributes = Array.from(asn1.result[CSR_INFO_ATTRS], element => new Attribute({ schema: element }));
  15898. }
  15899. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  15900. this.signatureValue = asn1.result.signatureValue;
  15901. }
  15902. encodeTBS() {
  15903. const outputArray = [
  15904. new asn1js__namespace.Integer({ value: this.version }),
  15905. this.subject.toSchema(),
  15906. this.subjectPublicKeyInfo.toSchema()
  15907. ];
  15908. if (ATTRIBUTES$1 in this) {
  15909. outputArray.push(new asn1js__namespace.Constructed({
  15910. idBlock: {
  15911. tagClass: 3,
  15912. tagNumber: 0
  15913. },
  15914. value: Array.from(this.attributes || [], o => o.toSchema())
  15915. }));
  15916. }
  15917. return (new asn1js__namespace.Sequence({
  15918. value: outputArray
  15919. }));
  15920. }
  15921. toSchema(encodeFlag = false) {
  15922. let tbsSchema;
  15923. if (encodeFlag === false) {
  15924. if (this.tbsView.byteLength === 0) {
  15925. return CertificationRequest.schema();
  15926. }
  15927. const asn1 = asn1js__namespace.fromBER(this.tbsView);
  15928. AsnError.assert(asn1, "PKCS#10 Certificate Request");
  15929. tbsSchema = asn1.result;
  15930. }
  15931. else {
  15932. tbsSchema = this.encodeTBS();
  15933. }
  15934. return (new asn1js__namespace.Sequence({
  15935. value: [
  15936. tbsSchema,
  15937. this.signatureAlgorithm.toSchema(),
  15938. this.signatureValue
  15939. ]
  15940. }));
  15941. }
  15942. toJSON() {
  15943. const object = {
  15944. tbs: pvtsutils__namespace.Convert.ToHex(this.tbsView),
  15945. version: this.version,
  15946. subject: this.subject.toJSON(),
  15947. subjectPublicKeyInfo: this.subjectPublicKeyInfo.toJSON(),
  15948. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  15949. signatureValue: this.signatureValue.toJSON(),
  15950. };
  15951. if (ATTRIBUTES$1 in this) {
  15952. object.attributes = Array.from(this.attributes || [], o => o.toJSON());
  15953. }
  15954. return object;
  15955. }
  15956. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  15957. if (!privateKey) {
  15958. throw new Error("Need to provide a private key for signing");
  15959. }
  15960. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  15961. const parameters = signatureParams.parameters;
  15962. this.signatureAlgorithm = signatureParams.signatureAlgorithm;
  15963. this.tbsView = new Uint8Array(this.encodeTBS().toBER());
  15964. const signature = await crypto.signWithPrivateKey(this.tbsView, privateKey, parameters);
  15965. this.signatureValue = new asn1js__namespace.BitString({ valueHex: signature });
  15966. }
  15967. async verify(crypto = getCrypto(true)) {
  15968. return crypto.verifyWithPublicKey(this.tbsView, this.signatureValue, this.subjectPublicKeyInfo, this.signatureAlgorithm);
  15969. }
  15970. async getPublicKey(parameters, crypto = getCrypto(true)) {
  15971. return crypto.getPublicKey(this.subjectPublicKeyInfo, this.signatureAlgorithm, parameters);
  15972. }
  15973. }
  15974. CertificationRequest.CLASS_NAME = "CertificationRequest";
  15975. const DIGEST_ALGORITHM$1 = "digestAlgorithm";
  15976. const DIGEST = "digest";
  15977. const CLEAR_PROPS$e = [
  15978. DIGEST_ALGORITHM$1,
  15979. DIGEST
  15980. ];
  15981. class DigestInfo extends PkiObject {
  15982. constructor(parameters = {}) {
  15983. super();
  15984. this.digestAlgorithm = pvutils__namespace.getParametersValue(parameters, DIGEST_ALGORITHM$1, DigestInfo.defaultValues(DIGEST_ALGORITHM$1));
  15985. this.digest = pvutils__namespace.getParametersValue(parameters, DIGEST, DigestInfo.defaultValues(DIGEST));
  15986. if (parameters.schema) {
  15987. this.fromSchema(parameters.schema);
  15988. }
  15989. }
  15990. static defaultValues(memberName) {
  15991. switch (memberName) {
  15992. case DIGEST_ALGORITHM$1:
  15993. return new AlgorithmIdentifier();
  15994. case DIGEST:
  15995. return new asn1js__namespace.OctetString();
  15996. default:
  15997. return super.defaultValues(memberName);
  15998. }
  15999. }
  16000. static compareWithDefault(memberName, memberValue) {
  16001. switch (memberName) {
  16002. case DIGEST_ALGORITHM$1:
  16003. return ((AlgorithmIdentifier.compareWithDefault("algorithmId", memberValue.algorithmId)) &&
  16004. (("algorithmParams" in memberValue) === false));
  16005. case DIGEST:
  16006. return (memberValue.isEqual(DigestInfo.defaultValues(memberName)));
  16007. default:
  16008. return super.defaultValues(memberName);
  16009. }
  16010. }
  16011. static schema(parameters = {}) {
  16012. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  16013. return (new asn1js__namespace.Sequence({
  16014. name: (names.blockName || EMPTY_STRING),
  16015. value: [
  16016. AlgorithmIdentifier.schema(names.digestAlgorithm || {
  16017. names: {
  16018. blockName: DIGEST_ALGORITHM$1
  16019. }
  16020. }),
  16021. new asn1js__namespace.OctetString({ name: (names.digest || DIGEST) })
  16022. ]
  16023. }));
  16024. }
  16025. fromSchema(schema) {
  16026. pvutils__namespace.clearProps(schema, CLEAR_PROPS$e);
  16027. const asn1 = asn1js__namespace.compareSchema(schema, schema, DigestInfo.schema({
  16028. names: {
  16029. digestAlgorithm: {
  16030. names: {
  16031. blockName: DIGEST_ALGORITHM$1
  16032. }
  16033. },
  16034. digest: DIGEST
  16035. }
  16036. }));
  16037. AsnError.assertSchema(asn1, this.className);
  16038. this.digestAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.digestAlgorithm });
  16039. this.digest = asn1.result.digest;
  16040. }
  16041. toSchema() {
  16042. return (new asn1js__namespace.Sequence({
  16043. value: [
  16044. this.digestAlgorithm.toSchema(),
  16045. this.digest
  16046. ]
  16047. }));
  16048. }
  16049. toJSON() {
  16050. return {
  16051. digestAlgorithm: this.digestAlgorithm.toJSON(),
  16052. digest: this.digest.toJSON(),
  16053. };
  16054. }
  16055. }
  16056. DigestInfo.CLASS_NAME = "DigestInfo";
  16057. const E_CONTENT_TYPE = "eContentType";
  16058. const E_CONTENT = "eContent";
  16059. const CLEAR_PROPS$d = [
  16060. E_CONTENT_TYPE,
  16061. E_CONTENT,
  16062. ];
  16063. class EncapsulatedContentInfo extends PkiObject {
  16064. constructor(parameters = {}) {
  16065. super();
  16066. this.eContentType = pvutils__namespace.getParametersValue(parameters, E_CONTENT_TYPE, EncapsulatedContentInfo.defaultValues(E_CONTENT_TYPE));
  16067. if (E_CONTENT in parameters) {
  16068. this.eContent = pvutils__namespace.getParametersValue(parameters, E_CONTENT, EncapsulatedContentInfo.defaultValues(E_CONTENT));
  16069. if ((this.eContent.idBlock.tagClass === 1) &&
  16070. (this.eContent.idBlock.tagNumber === 4)) {
  16071. if (this.eContent.idBlock.isConstructed === false) {
  16072. const constrString = new asn1js__namespace.OctetString({
  16073. idBlock: { isConstructed: true },
  16074. isConstructed: true
  16075. });
  16076. let offset = 0;
  16077. const viewHex = this.eContent.valueBlock.valueHexView.slice().buffer;
  16078. let length = viewHex.byteLength;
  16079. while (length > 0) {
  16080. const pieceView = new Uint8Array(viewHex, offset, ((offset + 65536) > viewHex.byteLength) ? (viewHex.byteLength - offset) : 65536);
  16081. const _array = new ArrayBuffer(pieceView.length);
  16082. const _view = new Uint8Array(_array);
  16083. for (let i = 0; i < _view.length; i++) {
  16084. _view[i] = pieceView[i];
  16085. }
  16086. constrString.valueBlock.value.push(new asn1js__namespace.OctetString({ valueHex: _array }));
  16087. length -= pieceView.length;
  16088. offset += pieceView.length;
  16089. }
  16090. this.eContent = constrString;
  16091. }
  16092. }
  16093. }
  16094. if (parameters.schema) {
  16095. this.fromSchema(parameters.schema);
  16096. }
  16097. }
  16098. static defaultValues(memberName) {
  16099. switch (memberName) {
  16100. case E_CONTENT_TYPE:
  16101. return EMPTY_STRING;
  16102. case E_CONTENT:
  16103. return new asn1js__namespace.OctetString();
  16104. default:
  16105. return super.defaultValues(memberName);
  16106. }
  16107. }
  16108. static compareWithDefault(memberName, memberValue) {
  16109. switch (memberName) {
  16110. case E_CONTENT_TYPE:
  16111. return (memberValue === EMPTY_STRING);
  16112. case E_CONTENT:
  16113. {
  16114. if ((memberValue.idBlock.tagClass === 1) && (memberValue.idBlock.tagNumber === 4))
  16115. return (memberValue.isEqual(EncapsulatedContentInfo.defaultValues(E_CONTENT)));
  16116. return false;
  16117. }
  16118. default:
  16119. return super.defaultValues(memberName);
  16120. }
  16121. }
  16122. static schema(parameters = {}) {
  16123. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  16124. return (new asn1js__namespace.Sequence({
  16125. name: (names.blockName || EMPTY_STRING),
  16126. value: [
  16127. new asn1js__namespace.ObjectIdentifier({ name: (names.eContentType || EMPTY_STRING) }),
  16128. new asn1js__namespace.Constructed({
  16129. optional: true,
  16130. idBlock: {
  16131. tagClass: 3,
  16132. tagNumber: 0
  16133. },
  16134. value: [
  16135. new asn1js__namespace.Any({ name: (names.eContent || EMPTY_STRING) })
  16136. ]
  16137. })
  16138. ]
  16139. }));
  16140. }
  16141. fromSchema(schema) {
  16142. pvutils__namespace.clearProps(schema, CLEAR_PROPS$d);
  16143. const asn1 = asn1js__namespace.compareSchema(schema, schema, EncapsulatedContentInfo.schema({
  16144. names: {
  16145. eContentType: E_CONTENT_TYPE,
  16146. eContent: E_CONTENT
  16147. }
  16148. }));
  16149. AsnError.assertSchema(asn1, this.className);
  16150. this.eContentType = asn1.result.eContentType.valueBlock.toString();
  16151. if (E_CONTENT in asn1.result)
  16152. this.eContent = asn1.result.eContent;
  16153. }
  16154. toSchema() {
  16155. const outputArray = [];
  16156. outputArray.push(new asn1js__namespace.ObjectIdentifier({ value: this.eContentType }));
  16157. if (this.eContent) {
  16158. if (EncapsulatedContentInfo.compareWithDefault(E_CONTENT, this.eContent) === false) {
  16159. outputArray.push(new asn1js__namespace.Constructed({
  16160. optional: true,
  16161. idBlock: {
  16162. tagClass: 3,
  16163. tagNumber: 0
  16164. },
  16165. value: [this.eContent]
  16166. }));
  16167. }
  16168. }
  16169. return (new asn1js__namespace.Sequence({
  16170. value: outputArray
  16171. }));
  16172. }
  16173. toJSON() {
  16174. const res = {
  16175. eContentType: this.eContentType
  16176. };
  16177. if (this.eContent && EncapsulatedContentInfo.compareWithDefault(E_CONTENT, this.eContent) === false) {
  16178. res.eContent = this.eContent.toJSON();
  16179. }
  16180. return res;
  16181. }
  16182. }
  16183. EncapsulatedContentInfo.CLASS_NAME = "EncapsulatedContentInfo";
  16184. class KeyBag extends PrivateKeyInfo {
  16185. constructor(parameters = {}) {
  16186. super(parameters);
  16187. }
  16188. }
  16189. const MAC = "mac";
  16190. const MAC_SALT = "macSalt";
  16191. const ITERATIONS = "iterations";
  16192. const CLEAR_PROPS$c = [
  16193. MAC,
  16194. MAC_SALT,
  16195. ITERATIONS
  16196. ];
  16197. class MacData extends PkiObject {
  16198. constructor(parameters = {}) {
  16199. super();
  16200. this.mac = pvutils__namespace.getParametersValue(parameters, MAC, MacData.defaultValues(MAC));
  16201. this.macSalt = pvutils__namespace.getParametersValue(parameters, MAC_SALT, MacData.defaultValues(MAC_SALT));
  16202. if (ITERATIONS in parameters) {
  16203. this.iterations = pvutils__namespace.getParametersValue(parameters, ITERATIONS, MacData.defaultValues(ITERATIONS));
  16204. }
  16205. if (parameters.schema) {
  16206. this.fromSchema(parameters.schema);
  16207. }
  16208. }
  16209. static defaultValues(memberName) {
  16210. switch (memberName) {
  16211. case MAC:
  16212. return new DigestInfo();
  16213. case MAC_SALT:
  16214. return new asn1js__namespace.OctetString();
  16215. case ITERATIONS:
  16216. return 1;
  16217. default:
  16218. return super.defaultValues(memberName);
  16219. }
  16220. }
  16221. static compareWithDefault(memberName, memberValue) {
  16222. switch (memberName) {
  16223. case MAC:
  16224. return ((DigestInfo.compareWithDefault("digestAlgorithm", memberValue.digestAlgorithm)) &&
  16225. (DigestInfo.compareWithDefault("digest", memberValue.digest)));
  16226. case MAC_SALT:
  16227. return (memberValue.isEqual(MacData.defaultValues(memberName)));
  16228. case ITERATIONS:
  16229. return (memberValue === MacData.defaultValues(memberName));
  16230. default:
  16231. return super.defaultValues(memberName);
  16232. }
  16233. }
  16234. static schema(parameters = {}) {
  16235. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  16236. return (new asn1js__namespace.Sequence({
  16237. name: (names.blockName || EMPTY_STRING),
  16238. optional: (names.optional || true),
  16239. value: [
  16240. DigestInfo.schema(names.mac || {
  16241. names: {
  16242. blockName: MAC
  16243. }
  16244. }),
  16245. new asn1js__namespace.OctetString({ name: (names.macSalt || MAC_SALT) }),
  16246. new asn1js__namespace.Integer({
  16247. optional: true,
  16248. name: (names.iterations || ITERATIONS)
  16249. })
  16250. ]
  16251. }));
  16252. }
  16253. fromSchema(schema) {
  16254. pvutils__namespace.clearProps(schema, CLEAR_PROPS$c);
  16255. const asn1 = asn1js__namespace.compareSchema(schema, schema, MacData.schema({
  16256. names: {
  16257. mac: {
  16258. names: {
  16259. blockName: MAC
  16260. }
  16261. },
  16262. macSalt: MAC_SALT,
  16263. iterations: ITERATIONS
  16264. }
  16265. }));
  16266. AsnError.assertSchema(asn1, this.className);
  16267. this.mac = new DigestInfo({ schema: asn1.result.mac });
  16268. this.macSalt = asn1.result.macSalt;
  16269. if (ITERATIONS in asn1.result)
  16270. this.iterations = asn1.result.iterations.valueBlock.valueDec;
  16271. }
  16272. toSchema() {
  16273. const outputArray = [
  16274. this.mac.toSchema(),
  16275. this.macSalt
  16276. ];
  16277. if (this.iterations !== undefined) {
  16278. outputArray.push(new asn1js__namespace.Integer({ value: this.iterations }));
  16279. }
  16280. return (new asn1js__namespace.Sequence({
  16281. value: outputArray
  16282. }));
  16283. }
  16284. toJSON() {
  16285. const res = {
  16286. mac: this.mac.toJSON(),
  16287. macSalt: this.macSalt.toJSON(),
  16288. };
  16289. if (this.iterations !== undefined) {
  16290. res.iterations = this.iterations;
  16291. }
  16292. return res;
  16293. }
  16294. }
  16295. MacData.CLASS_NAME = "MacData";
  16296. const HASH_ALGORITHM = "hashAlgorithm";
  16297. const HASHED_MESSAGE = "hashedMessage";
  16298. const CLEAR_PROPS$b = [
  16299. HASH_ALGORITHM,
  16300. HASHED_MESSAGE,
  16301. ];
  16302. class MessageImprint extends PkiObject {
  16303. static async create(hashAlgorithm, message, crypto = getCrypto(true)) {
  16304. const hashAlgorithmOID = crypto.getOIDByAlgorithm({ name: hashAlgorithm }, true, "hashAlgorithm");
  16305. const hashedMessage = await crypto.digest(hashAlgorithm, message);
  16306. const res = new MessageImprint({
  16307. hashAlgorithm: new AlgorithmIdentifier({
  16308. algorithmId: hashAlgorithmOID,
  16309. algorithmParams: new asn1js__namespace.Null(),
  16310. }),
  16311. hashedMessage: new asn1js__namespace.OctetString({ valueHex: hashedMessage })
  16312. });
  16313. return res;
  16314. }
  16315. constructor(parameters = {}) {
  16316. super();
  16317. this.hashAlgorithm = pvutils__namespace.getParametersValue(parameters, HASH_ALGORITHM, MessageImprint.defaultValues(HASH_ALGORITHM));
  16318. this.hashedMessage = pvutils__namespace.getParametersValue(parameters, HASHED_MESSAGE, MessageImprint.defaultValues(HASHED_MESSAGE));
  16319. if (parameters.schema) {
  16320. this.fromSchema(parameters.schema);
  16321. }
  16322. }
  16323. static defaultValues(memberName) {
  16324. switch (memberName) {
  16325. case HASH_ALGORITHM:
  16326. return new AlgorithmIdentifier();
  16327. case HASHED_MESSAGE:
  16328. return new asn1js__namespace.OctetString();
  16329. default:
  16330. return super.defaultValues(memberName);
  16331. }
  16332. }
  16333. static compareWithDefault(memberName, memberValue) {
  16334. switch (memberName) {
  16335. case HASH_ALGORITHM:
  16336. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  16337. case HASHED_MESSAGE:
  16338. return (memberValue.isEqual(MessageImprint.defaultValues(memberName)) === 0);
  16339. default:
  16340. return super.defaultValues(memberName);
  16341. }
  16342. }
  16343. static schema(parameters = {}) {
  16344. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  16345. return (new asn1js__namespace.Sequence({
  16346. name: (names.blockName || EMPTY_STRING),
  16347. value: [
  16348. AlgorithmIdentifier.schema(names.hashAlgorithm || {}),
  16349. new asn1js__namespace.OctetString({ name: (names.hashedMessage || EMPTY_STRING) })
  16350. ]
  16351. }));
  16352. }
  16353. fromSchema(schema) {
  16354. pvutils__namespace.clearProps(schema, CLEAR_PROPS$b);
  16355. const asn1 = asn1js__namespace.compareSchema(schema, schema, MessageImprint.schema({
  16356. names: {
  16357. hashAlgorithm: {
  16358. names: {
  16359. blockName: HASH_ALGORITHM
  16360. }
  16361. },
  16362. hashedMessage: HASHED_MESSAGE
  16363. }
  16364. }));
  16365. AsnError.assertSchema(asn1, this.className);
  16366. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  16367. this.hashedMessage = asn1.result.hashedMessage;
  16368. }
  16369. toSchema() {
  16370. return (new asn1js__namespace.Sequence({
  16371. value: [
  16372. this.hashAlgorithm.toSchema(),
  16373. this.hashedMessage
  16374. ]
  16375. }));
  16376. }
  16377. toJSON() {
  16378. return {
  16379. hashAlgorithm: this.hashAlgorithm.toJSON(),
  16380. hashedMessage: this.hashedMessage.toJSON(),
  16381. };
  16382. }
  16383. }
  16384. MessageImprint.CLASS_NAME = "MessageImprint";
  16385. const REQ_CERT = "reqCert";
  16386. const SINGLE_REQUEST_EXTENSIONS = "singleRequestExtensions";
  16387. const CLEAR_PROPS$a = [
  16388. REQ_CERT,
  16389. SINGLE_REQUEST_EXTENSIONS,
  16390. ];
  16391. class Request extends PkiObject {
  16392. constructor(parameters = {}) {
  16393. super();
  16394. this.reqCert = pvutils__namespace.getParametersValue(parameters, REQ_CERT, Request.defaultValues(REQ_CERT));
  16395. if (SINGLE_REQUEST_EXTENSIONS in parameters) {
  16396. this.singleRequestExtensions = pvutils__namespace.getParametersValue(parameters, SINGLE_REQUEST_EXTENSIONS, Request.defaultValues(SINGLE_REQUEST_EXTENSIONS));
  16397. }
  16398. if (parameters.schema) {
  16399. this.fromSchema(parameters.schema);
  16400. }
  16401. }
  16402. static defaultValues(memberName) {
  16403. switch (memberName) {
  16404. case REQ_CERT:
  16405. return new CertID();
  16406. case SINGLE_REQUEST_EXTENSIONS:
  16407. return [];
  16408. default:
  16409. return super.defaultValues(memberName);
  16410. }
  16411. }
  16412. static compareWithDefault(memberName, memberValue) {
  16413. switch (memberName) {
  16414. case REQ_CERT:
  16415. return (memberValue.isEqual(Request.defaultValues(memberName)));
  16416. case SINGLE_REQUEST_EXTENSIONS:
  16417. return (memberValue.length === 0);
  16418. default:
  16419. return super.defaultValues(memberName);
  16420. }
  16421. }
  16422. static schema(parameters = {}) {
  16423. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  16424. return (new asn1js__namespace.Sequence({
  16425. name: (names.blockName || EMPTY_STRING),
  16426. value: [
  16427. CertID.schema(names.reqCert || {}),
  16428. new asn1js__namespace.Constructed({
  16429. optional: true,
  16430. idBlock: {
  16431. tagClass: 3,
  16432. tagNumber: 0
  16433. },
  16434. value: [Extensions.schema(names.extensions || {
  16435. names: {
  16436. blockName: (names.singleRequestExtensions || EMPTY_STRING)
  16437. }
  16438. })]
  16439. })
  16440. ]
  16441. }));
  16442. }
  16443. fromSchema(schema) {
  16444. pvutils__namespace.clearProps(schema, CLEAR_PROPS$a);
  16445. const asn1 = asn1js__namespace.compareSchema(schema, schema, Request.schema({
  16446. names: {
  16447. reqCert: {
  16448. names: {
  16449. blockName: REQ_CERT
  16450. }
  16451. },
  16452. extensions: {
  16453. names: {
  16454. blockName: SINGLE_REQUEST_EXTENSIONS
  16455. }
  16456. }
  16457. }
  16458. }));
  16459. AsnError.assertSchema(asn1, this.className);
  16460. this.reqCert = new CertID({ schema: asn1.result.reqCert });
  16461. if (SINGLE_REQUEST_EXTENSIONS in asn1.result) {
  16462. this.singleRequestExtensions = Array.from(asn1.result.singleRequestExtensions.valueBlock.value, element => new Extension({ schema: element }));
  16463. }
  16464. }
  16465. toSchema() {
  16466. const outputArray = [];
  16467. outputArray.push(this.reqCert.toSchema());
  16468. if (this.singleRequestExtensions) {
  16469. outputArray.push(new asn1js__namespace.Constructed({
  16470. optional: true,
  16471. idBlock: {
  16472. tagClass: 3,
  16473. tagNumber: 0
  16474. },
  16475. value: [
  16476. new asn1js__namespace.Sequence({
  16477. value: Array.from(this.singleRequestExtensions, o => o.toSchema())
  16478. })
  16479. ]
  16480. }));
  16481. }
  16482. return (new asn1js__namespace.Sequence({
  16483. value: outputArray
  16484. }));
  16485. }
  16486. toJSON() {
  16487. const res = {
  16488. reqCert: this.reqCert.toJSON()
  16489. };
  16490. if (this.singleRequestExtensions) {
  16491. res.singleRequestExtensions = Array.from(this.singleRequestExtensions, o => o.toJSON());
  16492. }
  16493. return res;
  16494. }
  16495. }
  16496. Request.CLASS_NAME = "Request";
  16497. const TBS = "tbs";
  16498. const VERSION$5 = "version";
  16499. const REQUESTOR_NAME = "requestorName";
  16500. const REQUEST_LIST = "requestList";
  16501. const REQUEST_EXTENSIONS = "requestExtensions";
  16502. const TBS_REQUEST$1 = "TBSRequest";
  16503. const TBS_REQUEST_VERSION = `${TBS_REQUEST$1}.${VERSION$5}`;
  16504. const TBS_REQUEST_REQUESTOR_NAME = `${TBS_REQUEST$1}.${REQUESTOR_NAME}`;
  16505. const TBS_REQUEST_REQUESTS = `${TBS_REQUEST$1}.requests`;
  16506. const TBS_REQUEST_REQUEST_EXTENSIONS = `${TBS_REQUEST$1}.${REQUEST_EXTENSIONS}`;
  16507. const CLEAR_PROPS$9 = [
  16508. TBS_REQUEST$1,
  16509. TBS_REQUEST_VERSION,
  16510. TBS_REQUEST_REQUESTOR_NAME,
  16511. TBS_REQUEST_REQUESTS,
  16512. TBS_REQUEST_REQUEST_EXTENSIONS
  16513. ];
  16514. class TBSRequest extends PkiObject {
  16515. get tbs() {
  16516. return pvtsutils__namespace.BufferSourceConverter.toArrayBuffer(this.tbsView);
  16517. }
  16518. set tbs(value) {
  16519. this.tbsView = new Uint8Array(value);
  16520. }
  16521. constructor(parameters = {}) {
  16522. super();
  16523. this.tbsView = new Uint8Array(pvutils__namespace.getParametersValue(parameters, TBS, TBSRequest.defaultValues(TBS)));
  16524. if (VERSION$5 in parameters) {
  16525. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$5, TBSRequest.defaultValues(VERSION$5));
  16526. }
  16527. if (REQUESTOR_NAME in parameters) {
  16528. this.requestorName = pvutils__namespace.getParametersValue(parameters, REQUESTOR_NAME, TBSRequest.defaultValues(REQUESTOR_NAME));
  16529. }
  16530. this.requestList = pvutils__namespace.getParametersValue(parameters, REQUEST_LIST, TBSRequest.defaultValues(REQUEST_LIST));
  16531. if (REQUEST_EXTENSIONS in parameters) {
  16532. this.requestExtensions = pvutils__namespace.getParametersValue(parameters, REQUEST_EXTENSIONS, TBSRequest.defaultValues(REQUEST_EXTENSIONS));
  16533. }
  16534. if (parameters.schema) {
  16535. this.fromSchema(parameters.schema);
  16536. }
  16537. }
  16538. static defaultValues(memberName) {
  16539. switch (memberName) {
  16540. case TBS:
  16541. return EMPTY_BUFFER;
  16542. case VERSION$5:
  16543. return 0;
  16544. case REQUESTOR_NAME:
  16545. return new GeneralName();
  16546. case REQUEST_LIST:
  16547. case REQUEST_EXTENSIONS:
  16548. return [];
  16549. default:
  16550. return super.defaultValues(memberName);
  16551. }
  16552. }
  16553. static compareWithDefault(memberName, memberValue) {
  16554. switch (memberName) {
  16555. case TBS:
  16556. return (memberValue.byteLength === 0);
  16557. case VERSION$5:
  16558. return (memberValue === TBSRequest.defaultValues(memberName));
  16559. case REQUESTOR_NAME:
  16560. return ((memberValue.type === GeneralName.defaultValues("type")) && (Object.keys(memberValue.value).length === 0));
  16561. case REQUEST_LIST:
  16562. case REQUEST_EXTENSIONS:
  16563. return (memberValue.length === 0);
  16564. default:
  16565. return super.defaultValues(memberName);
  16566. }
  16567. }
  16568. static schema(parameters = {}) {
  16569. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  16570. return (new asn1js__namespace.Sequence({
  16571. name: (names.blockName || TBS_REQUEST$1),
  16572. value: [
  16573. new asn1js__namespace.Constructed({
  16574. optional: true,
  16575. idBlock: {
  16576. tagClass: 3,
  16577. tagNumber: 0
  16578. },
  16579. value: [new asn1js__namespace.Integer({ name: (names.TBSRequestVersion || TBS_REQUEST_VERSION) })]
  16580. }),
  16581. new asn1js__namespace.Constructed({
  16582. optional: true,
  16583. idBlock: {
  16584. tagClass: 3,
  16585. tagNumber: 1
  16586. },
  16587. value: [GeneralName.schema(names.requestorName || {
  16588. names: {
  16589. blockName: TBS_REQUEST_REQUESTOR_NAME
  16590. }
  16591. })]
  16592. }),
  16593. new asn1js__namespace.Sequence({
  16594. name: (names.requestList || "TBSRequest.requestList"),
  16595. value: [
  16596. new asn1js__namespace.Repeated({
  16597. name: (names.requests || TBS_REQUEST_REQUESTS),
  16598. value: Request.schema(names.requestNames || {})
  16599. })
  16600. ]
  16601. }),
  16602. new asn1js__namespace.Constructed({
  16603. optional: true,
  16604. idBlock: {
  16605. tagClass: 3,
  16606. tagNumber: 2
  16607. },
  16608. value: [Extensions.schema(names.extensions || {
  16609. names: {
  16610. blockName: (names.requestExtensions || TBS_REQUEST_REQUEST_EXTENSIONS)
  16611. }
  16612. })]
  16613. })
  16614. ]
  16615. }));
  16616. }
  16617. fromSchema(schema) {
  16618. pvutils__namespace.clearProps(schema, CLEAR_PROPS$9);
  16619. const asn1 = asn1js__namespace.compareSchema(schema, schema, TBSRequest.schema());
  16620. AsnError.assertSchema(asn1, this.className);
  16621. this.tbsView = asn1.result.TBSRequest.valueBeforeDecodeView;
  16622. if (TBS_REQUEST_VERSION in asn1.result)
  16623. this.version = asn1.result[TBS_REQUEST_VERSION].valueBlock.valueDec;
  16624. if (TBS_REQUEST_REQUESTOR_NAME in asn1.result)
  16625. this.requestorName = new GeneralName({ schema: asn1.result[TBS_REQUEST_REQUESTOR_NAME] });
  16626. this.requestList = Array.from(asn1.result[TBS_REQUEST_REQUESTS], element => new Request({ schema: element }));
  16627. if (TBS_REQUEST_REQUEST_EXTENSIONS in asn1.result)
  16628. this.requestExtensions = Array.from(asn1.result[TBS_REQUEST_REQUEST_EXTENSIONS].valueBlock.value, element => new Extension({ schema: element }));
  16629. }
  16630. toSchema(encodeFlag = false) {
  16631. let tbsSchema;
  16632. if (encodeFlag === false) {
  16633. if (this.tbsView.byteLength === 0)
  16634. return TBSRequest.schema();
  16635. const asn1 = asn1js__namespace.fromBER(this.tbsView);
  16636. AsnError.assert(asn1, "TBS Request");
  16637. if (!(asn1.result instanceof asn1js__namespace.Sequence)) {
  16638. throw new Error("ASN.1 result should be SEQUENCE");
  16639. }
  16640. tbsSchema = asn1.result;
  16641. }
  16642. else {
  16643. const outputArray = [];
  16644. if (this.version !== undefined) {
  16645. outputArray.push(new asn1js__namespace.Constructed({
  16646. idBlock: {
  16647. tagClass: 3,
  16648. tagNumber: 0
  16649. },
  16650. value: [new asn1js__namespace.Integer({ value: this.version })]
  16651. }));
  16652. }
  16653. if (this.requestorName) {
  16654. outputArray.push(new asn1js__namespace.Constructed({
  16655. idBlock: {
  16656. tagClass: 3,
  16657. tagNumber: 1
  16658. },
  16659. value: [this.requestorName.toSchema()]
  16660. }));
  16661. }
  16662. outputArray.push(new asn1js__namespace.Sequence({
  16663. value: Array.from(this.requestList, o => o.toSchema())
  16664. }));
  16665. if (this.requestExtensions) {
  16666. outputArray.push(new asn1js__namespace.Constructed({
  16667. idBlock: {
  16668. tagClass: 3,
  16669. tagNumber: 2
  16670. },
  16671. value: [
  16672. new asn1js__namespace.Sequence({
  16673. value: Array.from(this.requestExtensions, o => o.toSchema())
  16674. })
  16675. ]
  16676. }));
  16677. }
  16678. tbsSchema = new asn1js__namespace.Sequence({
  16679. value: outputArray
  16680. });
  16681. }
  16682. return tbsSchema;
  16683. }
  16684. toJSON() {
  16685. const res = {};
  16686. if (this.version != undefined)
  16687. res.version = this.version;
  16688. if (this.requestorName) {
  16689. res.requestorName = this.requestorName.toJSON();
  16690. }
  16691. res.requestList = Array.from(this.requestList, o => o.toJSON());
  16692. if (this.requestExtensions) {
  16693. res.requestExtensions = Array.from(this.requestExtensions, o => o.toJSON());
  16694. }
  16695. return res;
  16696. }
  16697. }
  16698. TBSRequest.CLASS_NAME = "TBSRequest";
  16699. const SIGNATURE_ALGORITHM$1 = "signatureAlgorithm";
  16700. const SIGNATURE$1 = "signature";
  16701. const CERTS = "certs";
  16702. class Signature extends PkiObject {
  16703. constructor(parameters = {}) {
  16704. super();
  16705. this.signatureAlgorithm = pvutils__namespace.getParametersValue(parameters, SIGNATURE_ALGORITHM$1, Signature.defaultValues(SIGNATURE_ALGORITHM$1));
  16706. this.signature = pvutils__namespace.getParametersValue(parameters, SIGNATURE$1, Signature.defaultValues(SIGNATURE$1));
  16707. if (CERTS in parameters) {
  16708. this.certs = pvutils__namespace.getParametersValue(parameters, CERTS, Signature.defaultValues(CERTS));
  16709. }
  16710. if (parameters.schema) {
  16711. this.fromSchema(parameters.schema);
  16712. }
  16713. }
  16714. static defaultValues(memberName) {
  16715. switch (memberName) {
  16716. case SIGNATURE_ALGORITHM$1:
  16717. return new AlgorithmIdentifier();
  16718. case SIGNATURE$1:
  16719. return new asn1js__namespace.BitString();
  16720. case CERTS:
  16721. return [];
  16722. default:
  16723. return super.defaultValues(memberName);
  16724. }
  16725. }
  16726. static compareWithDefault(memberName, memberValue) {
  16727. switch (memberName) {
  16728. case SIGNATURE_ALGORITHM$1:
  16729. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  16730. case SIGNATURE$1:
  16731. return (memberValue.isEqual(Signature.defaultValues(memberName)));
  16732. case CERTS:
  16733. return (memberValue.length === 0);
  16734. default:
  16735. return super.defaultValues(memberName);
  16736. }
  16737. }
  16738. static schema(parameters = {}) {
  16739. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  16740. return (new asn1js__namespace.Sequence({
  16741. name: (names.blockName || EMPTY_STRING),
  16742. value: [
  16743. AlgorithmIdentifier.schema(names.signatureAlgorithm || {}),
  16744. new asn1js__namespace.BitString({ name: (names.signature || EMPTY_STRING) }),
  16745. new asn1js__namespace.Constructed({
  16746. optional: true,
  16747. idBlock: {
  16748. tagClass: 3,
  16749. tagNumber: 0
  16750. },
  16751. value: [
  16752. new asn1js__namespace.Sequence({
  16753. value: [new asn1js__namespace.Repeated({
  16754. name: (names.certs || EMPTY_STRING),
  16755. value: Certificate.schema({})
  16756. })]
  16757. })
  16758. ]
  16759. })
  16760. ]
  16761. }));
  16762. }
  16763. fromSchema(schema) {
  16764. pvutils__namespace.clearProps(schema, [
  16765. SIGNATURE_ALGORITHM$1,
  16766. SIGNATURE$1,
  16767. CERTS
  16768. ]);
  16769. const asn1 = asn1js__namespace.compareSchema(schema, schema, Signature.schema({
  16770. names: {
  16771. signatureAlgorithm: {
  16772. names: {
  16773. blockName: SIGNATURE_ALGORITHM$1
  16774. }
  16775. },
  16776. signature: SIGNATURE$1,
  16777. certs: CERTS
  16778. }
  16779. }));
  16780. AsnError.assertSchema(asn1, this.className);
  16781. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  16782. this.signature = asn1.result.signature;
  16783. if (CERTS in asn1.result)
  16784. this.certs = Array.from(asn1.result.certs, element => new Certificate({ schema: element }));
  16785. }
  16786. toSchema() {
  16787. const outputArray = [];
  16788. outputArray.push(this.signatureAlgorithm.toSchema());
  16789. outputArray.push(this.signature);
  16790. if (this.certs) {
  16791. outputArray.push(new asn1js__namespace.Constructed({
  16792. optional: true,
  16793. idBlock: {
  16794. tagClass: 3,
  16795. tagNumber: 0
  16796. },
  16797. value: [
  16798. new asn1js__namespace.Sequence({
  16799. value: Array.from(this.certs, o => o.toSchema())
  16800. })
  16801. ]
  16802. }));
  16803. }
  16804. return (new asn1js__namespace.Sequence({
  16805. value: outputArray
  16806. }));
  16807. }
  16808. toJSON() {
  16809. const res = {
  16810. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  16811. signature: this.signature.toJSON(),
  16812. };
  16813. if (this.certs) {
  16814. res.certs = Array.from(this.certs, o => o.toJSON());
  16815. }
  16816. return res;
  16817. }
  16818. }
  16819. Signature.CLASS_NAME = "Signature";
  16820. const TBS_REQUEST = "tbsRequest";
  16821. const OPTIONAL_SIGNATURE = "optionalSignature";
  16822. const CLEAR_PROPS$8 = [
  16823. TBS_REQUEST,
  16824. OPTIONAL_SIGNATURE
  16825. ];
  16826. class OCSPRequest extends PkiObject {
  16827. constructor(parameters = {}) {
  16828. super();
  16829. this.tbsRequest = pvutils__namespace.getParametersValue(parameters, TBS_REQUEST, OCSPRequest.defaultValues(TBS_REQUEST));
  16830. if (OPTIONAL_SIGNATURE in parameters) {
  16831. this.optionalSignature = pvutils__namespace.getParametersValue(parameters, OPTIONAL_SIGNATURE, OCSPRequest.defaultValues(OPTIONAL_SIGNATURE));
  16832. }
  16833. if (parameters.schema) {
  16834. this.fromSchema(parameters.schema);
  16835. }
  16836. }
  16837. static defaultValues(memberName) {
  16838. switch (memberName) {
  16839. case TBS_REQUEST:
  16840. return new TBSRequest();
  16841. case OPTIONAL_SIGNATURE:
  16842. return new Signature();
  16843. default:
  16844. return super.defaultValues(memberName);
  16845. }
  16846. }
  16847. static compareWithDefault(memberName, memberValue) {
  16848. switch (memberName) {
  16849. case TBS_REQUEST:
  16850. return ((TBSRequest.compareWithDefault("tbs", memberValue.tbs)) &&
  16851. (TBSRequest.compareWithDefault("version", memberValue.version)) &&
  16852. (TBSRequest.compareWithDefault("requestorName", memberValue.requestorName)) &&
  16853. (TBSRequest.compareWithDefault("requestList", memberValue.requestList)) &&
  16854. (TBSRequest.compareWithDefault("requestExtensions", memberValue.requestExtensions)));
  16855. case OPTIONAL_SIGNATURE:
  16856. return ((Signature.compareWithDefault("signatureAlgorithm", memberValue.signatureAlgorithm)) &&
  16857. (Signature.compareWithDefault("signature", memberValue.signature)) &&
  16858. (Signature.compareWithDefault("certs", memberValue.certs)));
  16859. default:
  16860. return super.defaultValues(memberName);
  16861. }
  16862. }
  16863. static schema(parameters = {}) {
  16864. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  16865. return (new asn1js__namespace.Sequence({
  16866. name: names.blockName || "OCSPRequest",
  16867. value: [
  16868. TBSRequest.schema(names.tbsRequest || {
  16869. names: {
  16870. blockName: TBS_REQUEST
  16871. }
  16872. }),
  16873. new asn1js__namespace.Constructed({
  16874. optional: true,
  16875. idBlock: {
  16876. tagClass: 3,
  16877. tagNumber: 0
  16878. },
  16879. value: [
  16880. Signature.schema(names.optionalSignature || {
  16881. names: {
  16882. blockName: OPTIONAL_SIGNATURE
  16883. }
  16884. })
  16885. ]
  16886. })
  16887. ]
  16888. }));
  16889. }
  16890. fromSchema(schema) {
  16891. pvutils__namespace.clearProps(schema, CLEAR_PROPS$8);
  16892. const asn1 = asn1js__namespace.compareSchema(schema, schema, OCSPRequest.schema());
  16893. AsnError.assertSchema(asn1, this.className);
  16894. this.tbsRequest = new TBSRequest({ schema: asn1.result.tbsRequest });
  16895. if (OPTIONAL_SIGNATURE in asn1.result)
  16896. this.optionalSignature = new Signature({ schema: asn1.result.optionalSignature });
  16897. }
  16898. toSchema(encodeFlag = false) {
  16899. const outputArray = [];
  16900. outputArray.push(this.tbsRequest.toSchema(encodeFlag));
  16901. if (this.optionalSignature)
  16902. outputArray.push(new asn1js__namespace.Constructed({
  16903. optional: true,
  16904. idBlock: {
  16905. tagClass: 3,
  16906. tagNumber: 0
  16907. },
  16908. value: [
  16909. this.optionalSignature.toSchema()
  16910. ]
  16911. }));
  16912. return (new asn1js__namespace.Sequence({
  16913. value: outputArray
  16914. }));
  16915. }
  16916. toJSON() {
  16917. const res = {
  16918. tbsRequest: this.tbsRequest.toJSON()
  16919. };
  16920. if (this.optionalSignature) {
  16921. res.optionalSignature = this.optionalSignature.toJSON();
  16922. }
  16923. return res;
  16924. }
  16925. async createForCertificate(certificate, parameters, crypto = getCrypto(true)) {
  16926. const certID = new CertID();
  16927. await certID.createForCertificate(certificate, parameters, crypto);
  16928. this.tbsRequest.requestList.push(new Request({
  16929. reqCert: certID,
  16930. }));
  16931. }
  16932. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  16933. ParameterError.assertEmpty(privateKey, "privateKey", "OCSPRequest.sign method");
  16934. if (!this.optionalSignature) {
  16935. throw new Error("Need to create \"optionalSignature\" field before signing");
  16936. }
  16937. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  16938. const parameters = signatureParams.parameters;
  16939. this.optionalSignature.signatureAlgorithm = signatureParams.signatureAlgorithm;
  16940. const tbs = this.tbsRequest.toSchema(true).toBER(false);
  16941. const signature = await crypto.signWithPrivateKey(tbs, privateKey, parameters);
  16942. this.optionalSignature.signature = new asn1js__namespace.BitString({ valueHex: signature });
  16943. }
  16944. verify() {
  16945. }
  16946. }
  16947. OCSPRequest.CLASS_NAME = "OCSPRequest";
  16948. const RESPONSE_TYPE = "responseType";
  16949. const RESPONSE = "response";
  16950. const CLEAR_PROPS$7 = [
  16951. RESPONSE_TYPE,
  16952. RESPONSE
  16953. ];
  16954. class ResponseBytes extends PkiObject {
  16955. constructor(parameters = {}) {
  16956. super();
  16957. this.responseType = pvutils__namespace.getParametersValue(parameters, RESPONSE_TYPE, ResponseBytes.defaultValues(RESPONSE_TYPE));
  16958. this.response = pvutils__namespace.getParametersValue(parameters, RESPONSE, ResponseBytes.defaultValues(RESPONSE));
  16959. if (parameters.schema) {
  16960. this.fromSchema(parameters.schema);
  16961. }
  16962. }
  16963. static defaultValues(memberName) {
  16964. switch (memberName) {
  16965. case RESPONSE_TYPE:
  16966. return EMPTY_STRING;
  16967. case RESPONSE:
  16968. return new asn1js__namespace.OctetString();
  16969. default:
  16970. return super.defaultValues(memberName);
  16971. }
  16972. }
  16973. static compareWithDefault(memberName, memberValue) {
  16974. switch (memberName) {
  16975. case RESPONSE_TYPE:
  16976. return (memberValue === EMPTY_STRING);
  16977. case RESPONSE:
  16978. return (memberValue.isEqual(ResponseBytes.defaultValues(memberName)));
  16979. default:
  16980. return super.defaultValues(memberName);
  16981. }
  16982. }
  16983. static schema(parameters = {}) {
  16984. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  16985. return (new asn1js__namespace.Sequence({
  16986. name: (names.blockName || EMPTY_STRING),
  16987. value: [
  16988. new asn1js__namespace.ObjectIdentifier({ name: (names.responseType || EMPTY_STRING) }),
  16989. new asn1js__namespace.OctetString({ name: (names.response || EMPTY_STRING) })
  16990. ]
  16991. }));
  16992. }
  16993. fromSchema(schema) {
  16994. pvutils__namespace.clearProps(schema, CLEAR_PROPS$7);
  16995. const asn1 = asn1js__namespace.compareSchema(schema, schema, ResponseBytes.schema({
  16996. names: {
  16997. responseType: RESPONSE_TYPE,
  16998. response: RESPONSE
  16999. }
  17000. }));
  17001. AsnError.assertSchema(asn1, this.className);
  17002. this.responseType = asn1.result.responseType.valueBlock.toString();
  17003. this.response = asn1.result.response;
  17004. }
  17005. toSchema() {
  17006. return (new asn1js__namespace.Sequence({
  17007. value: [
  17008. new asn1js__namespace.ObjectIdentifier({ value: this.responseType }),
  17009. this.response
  17010. ]
  17011. }));
  17012. }
  17013. toJSON() {
  17014. return {
  17015. responseType: this.responseType,
  17016. response: this.response.toJSON(),
  17017. };
  17018. }
  17019. }
  17020. ResponseBytes.CLASS_NAME = "ResponseBytes";
  17021. const RESPONSE_STATUS = "responseStatus";
  17022. const RESPONSE_BYTES = "responseBytes";
  17023. class OCSPResponse extends PkiObject {
  17024. constructor(parameters = {}) {
  17025. super();
  17026. this.responseStatus = pvutils__namespace.getParametersValue(parameters, RESPONSE_STATUS, OCSPResponse.defaultValues(RESPONSE_STATUS));
  17027. if (RESPONSE_BYTES in parameters) {
  17028. this.responseBytes = pvutils__namespace.getParametersValue(parameters, RESPONSE_BYTES, OCSPResponse.defaultValues(RESPONSE_BYTES));
  17029. }
  17030. if (parameters.schema) {
  17031. this.fromSchema(parameters.schema);
  17032. }
  17033. }
  17034. static defaultValues(memberName) {
  17035. switch (memberName) {
  17036. case RESPONSE_STATUS:
  17037. return new asn1js__namespace.Enumerated();
  17038. case RESPONSE_BYTES:
  17039. return new ResponseBytes();
  17040. default:
  17041. return super.defaultValues(memberName);
  17042. }
  17043. }
  17044. static compareWithDefault(memberName, memberValue) {
  17045. switch (memberName) {
  17046. case RESPONSE_STATUS:
  17047. return (memberValue.isEqual(OCSPResponse.defaultValues(memberName)));
  17048. case RESPONSE_BYTES:
  17049. return ((ResponseBytes.compareWithDefault("responseType", memberValue.responseType)) &&
  17050. (ResponseBytes.compareWithDefault("response", memberValue.response)));
  17051. default:
  17052. return super.defaultValues(memberName);
  17053. }
  17054. }
  17055. static schema(parameters = {}) {
  17056. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  17057. return (new asn1js__namespace.Sequence({
  17058. name: (names.blockName || "OCSPResponse"),
  17059. value: [
  17060. new asn1js__namespace.Enumerated({ name: (names.responseStatus || RESPONSE_STATUS) }),
  17061. new asn1js__namespace.Constructed({
  17062. optional: true,
  17063. idBlock: {
  17064. tagClass: 3,
  17065. tagNumber: 0
  17066. },
  17067. value: [
  17068. ResponseBytes.schema(names.responseBytes || {
  17069. names: {
  17070. blockName: RESPONSE_BYTES
  17071. }
  17072. })
  17073. ]
  17074. })
  17075. ]
  17076. }));
  17077. }
  17078. fromSchema(schema) {
  17079. pvutils__namespace.clearProps(schema, [
  17080. RESPONSE_STATUS,
  17081. RESPONSE_BYTES
  17082. ]);
  17083. const asn1 = asn1js__namespace.compareSchema(schema, schema, OCSPResponse.schema());
  17084. AsnError.assertSchema(asn1, this.className);
  17085. this.responseStatus = asn1.result.responseStatus;
  17086. if (RESPONSE_BYTES in asn1.result)
  17087. this.responseBytes = new ResponseBytes({ schema: asn1.result.responseBytes });
  17088. }
  17089. toSchema() {
  17090. const outputArray = [];
  17091. outputArray.push(this.responseStatus);
  17092. if (this.responseBytes) {
  17093. outputArray.push(new asn1js__namespace.Constructed({
  17094. idBlock: {
  17095. tagClass: 3,
  17096. tagNumber: 0
  17097. },
  17098. value: [this.responseBytes.toSchema()]
  17099. }));
  17100. }
  17101. return (new asn1js__namespace.Sequence({
  17102. value: outputArray
  17103. }));
  17104. }
  17105. toJSON() {
  17106. const res = {
  17107. responseStatus: this.responseStatus.toJSON()
  17108. };
  17109. if (this.responseBytes) {
  17110. res.responseBytes = this.responseBytes.toJSON();
  17111. }
  17112. return res;
  17113. }
  17114. async getCertificateStatus(certificate, issuerCertificate, crypto = getCrypto(true)) {
  17115. let basicResponse;
  17116. const result = {
  17117. isForCertificate: false,
  17118. status: 2
  17119. };
  17120. if (!this.responseBytes)
  17121. return result;
  17122. if (this.responseBytes.responseType !== id_PKIX_OCSP_Basic)
  17123. return result;
  17124. try {
  17125. const asn1Basic = asn1js__namespace.fromBER(this.responseBytes.response.valueBlock.valueHexView);
  17126. AsnError.assert(asn1Basic, "Basic OCSP response");
  17127. basicResponse = new BasicOCSPResponse({ schema: asn1Basic.result });
  17128. }
  17129. catch {
  17130. return result;
  17131. }
  17132. return basicResponse.getCertificateStatus(certificate, issuerCertificate, crypto);
  17133. }
  17134. async sign(privateKey, hashAlgorithm, crypto = getCrypto(true)) {
  17135. var _a;
  17136. if (this.responseBytes && this.responseBytes.responseType === id_PKIX_OCSP_Basic) {
  17137. const basicResponse = BasicOCSPResponse.fromBER(this.responseBytes.response.valueBlock.valueHexView);
  17138. return basicResponse.sign(privateKey, hashAlgorithm, crypto);
  17139. }
  17140. throw new Error(`Unknown ResponseBytes type: ${((_a = this.responseBytes) === null || _a === void 0 ? void 0 : _a.responseType) || "Unknown"}`);
  17141. }
  17142. async verify(issuerCertificate = null, crypto = getCrypto(true)) {
  17143. var _a;
  17144. if ((RESPONSE_BYTES in this) === false)
  17145. throw new Error("Empty ResponseBytes field");
  17146. if (this.responseBytes && this.responseBytes.responseType === id_PKIX_OCSP_Basic) {
  17147. const basicResponse = BasicOCSPResponse.fromBER(this.responseBytes.response.valueBlock.valueHexView);
  17148. if (issuerCertificate !== null) {
  17149. if (!basicResponse.certs) {
  17150. basicResponse.certs = [];
  17151. }
  17152. basicResponse.certs.push(issuerCertificate);
  17153. }
  17154. return basicResponse.verify({}, crypto);
  17155. }
  17156. throw new Error(`Unknown ResponseBytes type: ${((_a = this.responseBytes) === null || _a === void 0 ? void 0 : _a.responseType) || "Unknown"}`);
  17157. }
  17158. }
  17159. OCSPResponse.CLASS_NAME = "OCSPResponse";
  17160. const TYPE = "type";
  17161. const ATTRIBUTES = "attributes";
  17162. const ENCODED_VALUE = "encodedValue";
  17163. const CLEAR_PROPS$6 = [
  17164. ATTRIBUTES
  17165. ];
  17166. class SignedAndUnsignedAttributes extends PkiObject {
  17167. constructor(parameters = {}) {
  17168. super();
  17169. this.type = pvutils__namespace.getParametersValue(parameters, TYPE, SignedAndUnsignedAttributes.defaultValues(TYPE));
  17170. this.attributes = pvutils__namespace.getParametersValue(parameters, ATTRIBUTES, SignedAndUnsignedAttributes.defaultValues(ATTRIBUTES));
  17171. this.encodedValue = pvutils__namespace.getParametersValue(parameters, ENCODED_VALUE, SignedAndUnsignedAttributes.defaultValues(ENCODED_VALUE));
  17172. if (parameters.schema) {
  17173. this.fromSchema(parameters.schema);
  17174. }
  17175. }
  17176. static defaultValues(memberName) {
  17177. switch (memberName) {
  17178. case TYPE:
  17179. return (-1);
  17180. case ATTRIBUTES:
  17181. return [];
  17182. case ENCODED_VALUE:
  17183. return EMPTY_BUFFER;
  17184. default:
  17185. return super.defaultValues(memberName);
  17186. }
  17187. }
  17188. static compareWithDefault(memberName, memberValue) {
  17189. switch (memberName) {
  17190. case TYPE:
  17191. return (memberValue === SignedAndUnsignedAttributes.defaultValues(TYPE));
  17192. case ATTRIBUTES:
  17193. return (memberValue.length === 0);
  17194. case ENCODED_VALUE:
  17195. return (memberValue.byteLength === 0);
  17196. default:
  17197. return super.defaultValues(memberName);
  17198. }
  17199. }
  17200. static schema(parameters = {}) {
  17201. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  17202. return (new asn1js__namespace.Constructed({
  17203. name: (names.blockName || EMPTY_STRING),
  17204. optional: true,
  17205. idBlock: {
  17206. tagClass: 3,
  17207. tagNumber: names.tagNumber || 0
  17208. },
  17209. value: [
  17210. new asn1js__namespace.Repeated({
  17211. name: (names.attributes || EMPTY_STRING),
  17212. value: Attribute.schema()
  17213. })
  17214. ]
  17215. }));
  17216. }
  17217. fromSchema(schema) {
  17218. pvutils__namespace.clearProps(schema, CLEAR_PROPS$6);
  17219. const asn1 = asn1js__namespace.compareSchema(schema, schema, SignedAndUnsignedAttributes.schema({
  17220. names: {
  17221. tagNumber: this.type,
  17222. attributes: ATTRIBUTES
  17223. }
  17224. }));
  17225. AsnError.assertSchema(asn1, this.className);
  17226. this.type = asn1.result.idBlock.tagNumber;
  17227. this.encodedValue = pvtsutils__namespace.BufferSourceConverter.toArrayBuffer(asn1.result.valueBeforeDecodeView);
  17228. const encodedView = new Uint8Array(this.encodedValue);
  17229. encodedView[0] = 0x31;
  17230. if ((ATTRIBUTES in asn1.result) === false) {
  17231. if (this.type === 0)
  17232. throw new Error("Wrong structure of SignedUnsignedAttributes");
  17233. else
  17234. return;
  17235. }
  17236. this.attributes = Array.from(asn1.result.attributes, element => new Attribute({ schema: element }));
  17237. }
  17238. toSchema() {
  17239. if (SignedAndUnsignedAttributes.compareWithDefault(TYPE, this.type) || SignedAndUnsignedAttributes.compareWithDefault(ATTRIBUTES, this.attributes))
  17240. throw new Error("Incorrectly initialized \"SignedAndUnsignedAttributes\" class");
  17241. return (new asn1js__namespace.Constructed({
  17242. optional: true,
  17243. idBlock: {
  17244. tagClass: 3,
  17245. tagNumber: this.type
  17246. },
  17247. value: Array.from(this.attributes, o => o.toSchema())
  17248. }));
  17249. }
  17250. toJSON() {
  17251. if (SignedAndUnsignedAttributes.compareWithDefault(TYPE, this.type) || SignedAndUnsignedAttributes.compareWithDefault(ATTRIBUTES, this.attributes))
  17252. throw new Error("Incorrectly initialized \"SignedAndUnsignedAttributes\" class");
  17253. return {
  17254. type: this.type,
  17255. attributes: Array.from(this.attributes, o => o.toJSON())
  17256. };
  17257. }
  17258. }
  17259. SignedAndUnsignedAttributes.CLASS_NAME = "SignedAndUnsignedAttributes";
  17260. const VERSION$4 = "version";
  17261. const SID = "sid";
  17262. const DIGEST_ALGORITHM = "digestAlgorithm";
  17263. const SIGNED_ATTRS = "signedAttrs";
  17264. const SIGNATURE_ALGORITHM = "signatureAlgorithm";
  17265. const SIGNATURE = "signature";
  17266. const UNSIGNED_ATTRS = "unsignedAttrs";
  17267. const SIGNER_INFO = "SignerInfo";
  17268. const SIGNER_INFO_VERSION = `${SIGNER_INFO}.${VERSION$4}`;
  17269. const SIGNER_INFO_SID = `${SIGNER_INFO}.${SID}`;
  17270. const SIGNER_INFO_DIGEST_ALGORITHM = `${SIGNER_INFO}.${DIGEST_ALGORITHM}`;
  17271. const SIGNER_INFO_SIGNED_ATTRS = `${SIGNER_INFO}.${SIGNED_ATTRS}`;
  17272. const SIGNER_INFO_SIGNATURE_ALGORITHM = `${SIGNER_INFO}.${SIGNATURE_ALGORITHM}`;
  17273. const SIGNER_INFO_SIGNATURE = `${SIGNER_INFO}.${SIGNATURE}`;
  17274. const SIGNER_INFO_UNSIGNED_ATTRS = `${SIGNER_INFO}.${UNSIGNED_ATTRS}`;
  17275. const CLEAR_PROPS$5 = [
  17276. SIGNER_INFO_VERSION,
  17277. SIGNER_INFO_SID,
  17278. SIGNER_INFO_DIGEST_ALGORITHM,
  17279. SIGNER_INFO_SIGNED_ATTRS,
  17280. SIGNER_INFO_SIGNATURE_ALGORITHM,
  17281. SIGNER_INFO_SIGNATURE,
  17282. SIGNER_INFO_UNSIGNED_ATTRS
  17283. ];
  17284. class SignerInfo extends PkiObject {
  17285. constructor(parameters = {}) {
  17286. super();
  17287. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$4, SignerInfo.defaultValues(VERSION$4));
  17288. this.sid = pvutils__namespace.getParametersValue(parameters, SID, SignerInfo.defaultValues(SID));
  17289. this.digestAlgorithm = pvutils__namespace.getParametersValue(parameters, DIGEST_ALGORITHM, SignerInfo.defaultValues(DIGEST_ALGORITHM));
  17290. if (SIGNED_ATTRS in parameters) {
  17291. this.signedAttrs = pvutils__namespace.getParametersValue(parameters, SIGNED_ATTRS, SignerInfo.defaultValues(SIGNED_ATTRS));
  17292. }
  17293. this.signatureAlgorithm = pvutils__namespace.getParametersValue(parameters, SIGNATURE_ALGORITHM, SignerInfo.defaultValues(SIGNATURE_ALGORITHM));
  17294. this.signature = pvutils__namespace.getParametersValue(parameters, SIGNATURE, SignerInfo.defaultValues(SIGNATURE));
  17295. if (UNSIGNED_ATTRS in parameters) {
  17296. this.unsignedAttrs = pvutils__namespace.getParametersValue(parameters, UNSIGNED_ATTRS, SignerInfo.defaultValues(UNSIGNED_ATTRS));
  17297. }
  17298. if (parameters.schema) {
  17299. this.fromSchema(parameters.schema);
  17300. }
  17301. }
  17302. static defaultValues(memberName) {
  17303. switch (memberName) {
  17304. case VERSION$4:
  17305. return 0;
  17306. case SID:
  17307. return new asn1js__namespace.Any();
  17308. case DIGEST_ALGORITHM:
  17309. return new AlgorithmIdentifier();
  17310. case SIGNED_ATTRS:
  17311. return new SignedAndUnsignedAttributes({ type: 0 });
  17312. case SIGNATURE_ALGORITHM:
  17313. return new AlgorithmIdentifier();
  17314. case SIGNATURE:
  17315. return new asn1js__namespace.OctetString();
  17316. case UNSIGNED_ATTRS:
  17317. return new SignedAndUnsignedAttributes({ type: 1 });
  17318. default:
  17319. return super.defaultValues(memberName);
  17320. }
  17321. }
  17322. static compareWithDefault(memberName, memberValue) {
  17323. switch (memberName) {
  17324. case VERSION$4:
  17325. return (SignerInfo.defaultValues(VERSION$4) === memberValue);
  17326. case SID:
  17327. return (memberValue instanceof asn1js__namespace.Any);
  17328. case DIGEST_ALGORITHM:
  17329. if ((memberValue instanceof AlgorithmIdentifier) === false)
  17330. return false;
  17331. return memberValue.isEqual(SignerInfo.defaultValues(DIGEST_ALGORITHM));
  17332. case SIGNED_ATTRS:
  17333. return ((SignedAndUnsignedAttributes.compareWithDefault("type", memberValue.type))
  17334. && (SignedAndUnsignedAttributes.compareWithDefault("attributes", memberValue.attributes))
  17335. && (SignedAndUnsignedAttributes.compareWithDefault("encodedValue", memberValue.encodedValue)));
  17336. case SIGNATURE_ALGORITHM:
  17337. if ((memberValue instanceof AlgorithmIdentifier) === false)
  17338. return false;
  17339. return memberValue.isEqual(SignerInfo.defaultValues(SIGNATURE_ALGORITHM));
  17340. case SIGNATURE:
  17341. case UNSIGNED_ATTRS:
  17342. return ((SignedAndUnsignedAttributes.compareWithDefault("type", memberValue.type))
  17343. && (SignedAndUnsignedAttributes.compareWithDefault("attributes", memberValue.attributes))
  17344. && (SignedAndUnsignedAttributes.compareWithDefault("encodedValue", memberValue.encodedValue)));
  17345. default:
  17346. return super.defaultValues(memberName);
  17347. }
  17348. }
  17349. static schema(parameters = {}) {
  17350. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  17351. return (new asn1js__namespace.Sequence({
  17352. name: SIGNER_INFO,
  17353. value: [
  17354. new asn1js__namespace.Integer({ name: (names.version || SIGNER_INFO_VERSION) }),
  17355. new asn1js__namespace.Choice({
  17356. value: [
  17357. IssuerAndSerialNumber.schema(names.sidSchema || {
  17358. names: {
  17359. blockName: SIGNER_INFO_SID
  17360. }
  17361. }),
  17362. new asn1js__namespace.Choice({
  17363. value: [
  17364. new asn1js__namespace.Constructed({
  17365. optional: true,
  17366. name: (names.sid || SIGNER_INFO_SID),
  17367. idBlock: {
  17368. tagClass: 3,
  17369. tagNumber: 0
  17370. },
  17371. value: [new asn1js__namespace.OctetString()]
  17372. }),
  17373. new asn1js__namespace.Primitive({
  17374. optional: true,
  17375. name: (names.sid || SIGNER_INFO_SID),
  17376. idBlock: {
  17377. tagClass: 3,
  17378. tagNumber: 0
  17379. }
  17380. }),
  17381. ]
  17382. }),
  17383. ]
  17384. }),
  17385. AlgorithmIdentifier.schema(names.digestAlgorithm || {
  17386. names: {
  17387. blockName: SIGNER_INFO_DIGEST_ALGORITHM
  17388. }
  17389. }),
  17390. SignedAndUnsignedAttributes.schema(names.signedAttrs || {
  17391. names: {
  17392. blockName: SIGNER_INFO_SIGNED_ATTRS,
  17393. tagNumber: 0
  17394. }
  17395. }),
  17396. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  17397. names: {
  17398. blockName: SIGNER_INFO_SIGNATURE_ALGORITHM
  17399. }
  17400. }),
  17401. new asn1js__namespace.OctetString({ name: (names.signature || SIGNER_INFO_SIGNATURE) }),
  17402. SignedAndUnsignedAttributes.schema(names.unsignedAttrs || {
  17403. names: {
  17404. blockName: SIGNER_INFO_UNSIGNED_ATTRS,
  17405. tagNumber: 1
  17406. }
  17407. })
  17408. ]
  17409. }));
  17410. }
  17411. fromSchema(schema) {
  17412. pvutils__namespace.clearProps(schema, CLEAR_PROPS$5);
  17413. const asn1 = asn1js__namespace.compareSchema(schema, schema, SignerInfo.schema());
  17414. AsnError.assertSchema(asn1, this.className);
  17415. this.version = asn1.result[SIGNER_INFO_VERSION].valueBlock.valueDec;
  17416. const currentSid = asn1.result[SIGNER_INFO_SID];
  17417. if (currentSid.idBlock.tagClass === 1)
  17418. this.sid = new IssuerAndSerialNumber({ schema: currentSid });
  17419. else
  17420. this.sid = currentSid;
  17421. this.digestAlgorithm = new AlgorithmIdentifier({ schema: asn1.result[SIGNER_INFO_DIGEST_ALGORITHM] });
  17422. if (SIGNER_INFO_SIGNED_ATTRS in asn1.result)
  17423. this.signedAttrs = new SignedAndUnsignedAttributes({ type: 0, schema: asn1.result[SIGNER_INFO_SIGNED_ATTRS] });
  17424. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result[SIGNER_INFO_SIGNATURE_ALGORITHM] });
  17425. this.signature = asn1.result[SIGNER_INFO_SIGNATURE];
  17426. if (SIGNER_INFO_UNSIGNED_ATTRS in asn1.result)
  17427. this.unsignedAttrs = new SignedAndUnsignedAttributes({ type: 1, schema: asn1.result[SIGNER_INFO_UNSIGNED_ATTRS] });
  17428. }
  17429. toSchema() {
  17430. if (SignerInfo.compareWithDefault(SID, this.sid))
  17431. throw new Error("Incorrectly initialized \"SignerInfo\" class");
  17432. const outputArray = [];
  17433. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  17434. if (this.sid instanceof IssuerAndSerialNumber)
  17435. outputArray.push(this.sid.toSchema());
  17436. else
  17437. outputArray.push(this.sid);
  17438. outputArray.push(this.digestAlgorithm.toSchema());
  17439. if (this.signedAttrs) {
  17440. if (SignerInfo.compareWithDefault(SIGNED_ATTRS, this.signedAttrs) === false)
  17441. outputArray.push(this.signedAttrs.toSchema());
  17442. }
  17443. outputArray.push(this.signatureAlgorithm.toSchema());
  17444. outputArray.push(this.signature);
  17445. if (this.unsignedAttrs) {
  17446. if (SignerInfo.compareWithDefault(UNSIGNED_ATTRS, this.unsignedAttrs) === false)
  17447. outputArray.push(this.unsignedAttrs.toSchema());
  17448. }
  17449. return (new asn1js__namespace.Sequence({
  17450. value: outputArray
  17451. }));
  17452. }
  17453. toJSON() {
  17454. if (SignerInfo.compareWithDefault(SID, this.sid)) {
  17455. throw new Error("Incorrectly initialized \"SignerInfo\" class");
  17456. }
  17457. const res = {
  17458. version: this.version,
  17459. digestAlgorithm: this.digestAlgorithm.toJSON(),
  17460. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  17461. signature: this.signature.toJSON(),
  17462. };
  17463. if (!(this.sid instanceof asn1js__namespace.Any))
  17464. res.sid = this.sid.toJSON();
  17465. if (this.signedAttrs && SignerInfo.compareWithDefault(SIGNED_ATTRS, this.signedAttrs) === false) {
  17466. res.signedAttrs = this.signedAttrs.toJSON();
  17467. }
  17468. if (this.unsignedAttrs && SignerInfo.compareWithDefault(UNSIGNED_ATTRS, this.unsignedAttrs) === false) {
  17469. res.unsignedAttrs = this.unsignedAttrs.toJSON();
  17470. }
  17471. return res;
  17472. }
  17473. }
  17474. SignerInfo.CLASS_NAME = "SignerInfo";
  17475. const VERSION$3 = "version";
  17476. const POLICY = "policy";
  17477. const MESSAGE_IMPRINT$1 = "messageImprint";
  17478. const SERIAL_NUMBER = "serialNumber";
  17479. const GEN_TIME = "genTime";
  17480. const ORDERING = "ordering";
  17481. const NONCE$1 = "nonce";
  17482. const ACCURACY = "accuracy";
  17483. const TSA = "tsa";
  17484. const EXTENSIONS$1 = "extensions";
  17485. const TST_INFO = "TSTInfo";
  17486. const TST_INFO_VERSION = `${TST_INFO}.${VERSION$3}`;
  17487. const TST_INFO_POLICY = `${TST_INFO}.${POLICY}`;
  17488. const TST_INFO_MESSAGE_IMPRINT = `${TST_INFO}.${MESSAGE_IMPRINT$1}`;
  17489. const TST_INFO_SERIAL_NUMBER = `${TST_INFO}.${SERIAL_NUMBER}`;
  17490. const TST_INFO_GEN_TIME = `${TST_INFO}.${GEN_TIME}`;
  17491. const TST_INFO_ACCURACY = `${TST_INFO}.${ACCURACY}`;
  17492. const TST_INFO_ORDERING = `${TST_INFO}.${ORDERING}`;
  17493. const TST_INFO_NONCE = `${TST_INFO}.${NONCE$1}`;
  17494. const TST_INFO_TSA = `${TST_INFO}.${TSA}`;
  17495. const TST_INFO_EXTENSIONS = `${TST_INFO}.${EXTENSIONS$1}`;
  17496. const CLEAR_PROPS$4 = [
  17497. TST_INFO_VERSION,
  17498. TST_INFO_POLICY,
  17499. TST_INFO_MESSAGE_IMPRINT,
  17500. TST_INFO_SERIAL_NUMBER,
  17501. TST_INFO_GEN_TIME,
  17502. TST_INFO_ACCURACY,
  17503. TST_INFO_ORDERING,
  17504. TST_INFO_NONCE,
  17505. TST_INFO_TSA,
  17506. TST_INFO_EXTENSIONS
  17507. ];
  17508. class TSTInfo extends PkiObject {
  17509. constructor(parameters = {}) {
  17510. super();
  17511. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$3, TSTInfo.defaultValues(VERSION$3));
  17512. this.policy = pvutils__namespace.getParametersValue(parameters, POLICY, TSTInfo.defaultValues(POLICY));
  17513. this.messageImprint = pvutils__namespace.getParametersValue(parameters, MESSAGE_IMPRINT$1, TSTInfo.defaultValues(MESSAGE_IMPRINT$1));
  17514. this.serialNumber = pvutils__namespace.getParametersValue(parameters, SERIAL_NUMBER, TSTInfo.defaultValues(SERIAL_NUMBER));
  17515. this.genTime = pvutils__namespace.getParametersValue(parameters, GEN_TIME, TSTInfo.defaultValues(GEN_TIME));
  17516. if (ACCURACY in parameters) {
  17517. this.accuracy = pvutils__namespace.getParametersValue(parameters, ACCURACY, TSTInfo.defaultValues(ACCURACY));
  17518. }
  17519. if (ORDERING in parameters) {
  17520. this.ordering = pvutils__namespace.getParametersValue(parameters, ORDERING, TSTInfo.defaultValues(ORDERING));
  17521. }
  17522. if (NONCE$1 in parameters) {
  17523. this.nonce = pvutils__namespace.getParametersValue(parameters, NONCE$1, TSTInfo.defaultValues(NONCE$1));
  17524. }
  17525. if (TSA in parameters) {
  17526. this.tsa = pvutils__namespace.getParametersValue(parameters, TSA, TSTInfo.defaultValues(TSA));
  17527. }
  17528. if (EXTENSIONS$1 in parameters) {
  17529. this.extensions = pvutils__namespace.getParametersValue(parameters, EXTENSIONS$1, TSTInfo.defaultValues(EXTENSIONS$1));
  17530. }
  17531. if (parameters.schema) {
  17532. this.fromSchema(parameters.schema);
  17533. }
  17534. }
  17535. static defaultValues(memberName) {
  17536. switch (memberName) {
  17537. case VERSION$3:
  17538. return 0;
  17539. case POLICY:
  17540. return EMPTY_STRING;
  17541. case MESSAGE_IMPRINT$1:
  17542. return new MessageImprint();
  17543. case SERIAL_NUMBER:
  17544. return new asn1js__namespace.Integer();
  17545. case GEN_TIME:
  17546. return new Date(0, 0, 0);
  17547. case ACCURACY:
  17548. return new Accuracy();
  17549. case ORDERING:
  17550. return false;
  17551. case NONCE$1:
  17552. return new asn1js__namespace.Integer();
  17553. case TSA:
  17554. return new GeneralName();
  17555. case EXTENSIONS$1:
  17556. return [];
  17557. default:
  17558. return super.defaultValues(memberName);
  17559. }
  17560. }
  17561. static compareWithDefault(memberName, memberValue) {
  17562. switch (memberName) {
  17563. case VERSION$3:
  17564. case POLICY:
  17565. case GEN_TIME:
  17566. case ORDERING:
  17567. return (memberValue === TSTInfo.defaultValues(ORDERING));
  17568. case MESSAGE_IMPRINT$1:
  17569. return ((MessageImprint.compareWithDefault(HASH_ALGORITHM, memberValue.hashAlgorithm)) &&
  17570. (MessageImprint.compareWithDefault(HASHED_MESSAGE, memberValue.hashedMessage)));
  17571. case SERIAL_NUMBER:
  17572. case NONCE$1:
  17573. return (memberValue.isEqual(TSTInfo.defaultValues(NONCE$1)));
  17574. case ACCURACY:
  17575. return ((Accuracy.compareWithDefault(SECONDS, memberValue.seconds)) &&
  17576. (Accuracy.compareWithDefault(MILLIS, memberValue.millis)) &&
  17577. (Accuracy.compareWithDefault(MICROS, memberValue.micros)));
  17578. case TSA:
  17579. return ((GeneralName.compareWithDefault(TYPE$4, memberValue.type)) &&
  17580. (GeneralName.compareWithDefault(VALUE$5, memberValue.value)));
  17581. case EXTENSIONS$1:
  17582. return (memberValue.length === 0);
  17583. default:
  17584. return super.defaultValues(memberName);
  17585. }
  17586. }
  17587. static schema(parameters = {}) {
  17588. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  17589. return (new asn1js__namespace.Sequence({
  17590. name: (names.blockName || TST_INFO),
  17591. value: [
  17592. new asn1js__namespace.Integer({ name: (names.version || TST_INFO_VERSION) }),
  17593. new asn1js__namespace.ObjectIdentifier({ name: (names.policy || TST_INFO_POLICY) }),
  17594. MessageImprint.schema(names.messageImprint || {
  17595. names: {
  17596. blockName: TST_INFO_MESSAGE_IMPRINT
  17597. }
  17598. }),
  17599. new asn1js__namespace.Integer({ name: (names.serialNumber || TST_INFO_SERIAL_NUMBER) }),
  17600. new asn1js__namespace.GeneralizedTime({ name: (names.genTime || TST_INFO_GEN_TIME) }),
  17601. Accuracy.schema(names.accuracy || {
  17602. names: {
  17603. blockName: TST_INFO_ACCURACY
  17604. }
  17605. }),
  17606. new asn1js__namespace.Boolean({
  17607. name: (names.ordering || TST_INFO_ORDERING),
  17608. optional: true
  17609. }),
  17610. new asn1js__namespace.Integer({
  17611. name: (names.nonce || TST_INFO_NONCE),
  17612. optional: true
  17613. }),
  17614. new asn1js__namespace.Constructed({
  17615. optional: true,
  17616. idBlock: {
  17617. tagClass: 3,
  17618. tagNumber: 0
  17619. },
  17620. value: [GeneralName.schema(names.tsa || {
  17621. names: {
  17622. blockName: TST_INFO_TSA
  17623. }
  17624. })]
  17625. }),
  17626. new asn1js__namespace.Constructed({
  17627. optional: true,
  17628. idBlock: {
  17629. tagClass: 3,
  17630. tagNumber: 1
  17631. },
  17632. value: [
  17633. new asn1js__namespace.Repeated({
  17634. name: (names.extensions || TST_INFO_EXTENSIONS),
  17635. value: Extension.schema(names.extension || {})
  17636. })
  17637. ]
  17638. })
  17639. ]
  17640. }));
  17641. }
  17642. fromSchema(schema) {
  17643. pvutils__namespace.clearProps(schema, CLEAR_PROPS$4);
  17644. const asn1 = asn1js__namespace.compareSchema(schema, schema, TSTInfo.schema());
  17645. AsnError.assertSchema(asn1, this.className);
  17646. this.version = asn1.result[TST_INFO_VERSION].valueBlock.valueDec;
  17647. this.policy = asn1.result[TST_INFO_POLICY].valueBlock.toString();
  17648. this.messageImprint = new MessageImprint({ schema: asn1.result[TST_INFO_MESSAGE_IMPRINT] });
  17649. this.serialNumber = asn1.result[TST_INFO_SERIAL_NUMBER];
  17650. this.genTime = asn1.result[TST_INFO_GEN_TIME].toDate();
  17651. if (TST_INFO_ACCURACY in asn1.result)
  17652. this.accuracy = new Accuracy({ schema: asn1.result[TST_INFO_ACCURACY] });
  17653. if (TST_INFO_ORDERING in asn1.result)
  17654. this.ordering = asn1.result[TST_INFO_ORDERING].valueBlock.value;
  17655. if (TST_INFO_NONCE in asn1.result)
  17656. this.nonce = asn1.result[TST_INFO_NONCE];
  17657. if (TST_INFO_TSA in asn1.result)
  17658. this.tsa = new GeneralName({ schema: asn1.result[TST_INFO_TSA] });
  17659. if (TST_INFO_EXTENSIONS in asn1.result)
  17660. this.extensions = Array.from(asn1.result[TST_INFO_EXTENSIONS], element => new Extension({ schema: element }));
  17661. }
  17662. toSchema() {
  17663. const outputArray = [];
  17664. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  17665. outputArray.push(new asn1js__namespace.ObjectIdentifier({ value: this.policy }));
  17666. outputArray.push(this.messageImprint.toSchema());
  17667. outputArray.push(this.serialNumber);
  17668. outputArray.push(new asn1js__namespace.GeneralizedTime({ valueDate: this.genTime }));
  17669. if (this.accuracy)
  17670. outputArray.push(this.accuracy.toSchema());
  17671. if (this.ordering !== undefined)
  17672. outputArray.push(new asn1js__namespace.Boolean({ value: this.ordering }));
  17673. if (this.nonce)
  17674. outputArray.push(this.nonce);
  17675. if (this.tsa) {
  17676. outputArray.push(new asn1js__namespace.Constructed({
  17677. optional: true,
  17678. idBlock: {
  17679. tagClass: 3,
  17680. tagNumber: 0
  17681. },
  17682. value: [this.tsa.toSchema()]
  17683. }));
  17684. }
  17685. if (this.extensions) {
  17686. outputArray.push(new asn1js__namespace.Constructed({
  17687. optional: true,
  17688. idBlock: {
  17689. tagClass: 3,
  17690. tagNumber: 1
  17691. },
  17692. value: Array.from(this.extensions, o => o.toSchema())
  17693. }));
  17694. }
  17695. return (new asn1js__namespace.Sequence({
  17696. value: outputArray
  17697. }));
  17698. }
  17699. toJSON() {
  17700. const res = {
  17701. version: this.version,
  17702. policy: this.policy,
  17703. messageImprint: this.messageImprint.toJSON(),
  17704. serialNumber: this.serialNumber.toJSON(),
  17705. genTime: this.genTime
  17706. };
  17707. if (this.accuracy)
  17708. res.accuracy = this.accuracy.toJSON();
  17709. if (this.ordering !== undefined)
  17710. res.ordering = this.ordering;
  17711. if (this.nonce)
  17712. res.nonce = this.nonce.toJSON();
  17713. if (this.tsa)
  17714. res.tsa = this.tsa.toJSON();
  17715. if (this.extensions)
  17716. res.extensions = Array.from(this.extensions, o => o.toJSON());
  17717. return res;
  17718. }
  17719. async verify(params, crypto = getCrypto(true)) {
  17720. if (!params.data) {
  17721. throw new Error("\"data\" is a mandatory attribute for TST_INFO verification");
  17722. }
  17723. const data = params.data;
  17724. if (params.notBefore) {
  17725. if (this.genTime < params.notBefore)
  17726. throw new Error("Generation time for TSTInfo object is less than notBefore value");
  17727. }
  17728. if (params.notAfter) {
  17729. if (this.genTime > params.notAfter)
  17730. throw new Error("Generation time for TSTInfo object is more than notAfter value");
  17731. }
  17732. const shaAlgorithm = crypto.getAlgorithmByOID(this.messageImprint.hashAlgorithm.algorithmId, true, "MessageImprint.hashAlgorithm");
  17733. const hash = await crypto.digest(shaAlgorithm.name, new Uint8Array(data));
  17734. return pvtsutils__namespace.BufferSourceConverter.isEqual(hash, this.messageImprint.hashedMessage.valueBlock.valueHexView);
  17735. }
  17736. }
  17737. TSTInfo.CLASS_NAME = "TSTInfo";
  17738. const VERSION$2 = "version";
  17739. const DIGEST_ALGORITHMS = "digestAlgorithms";
  17740. const ENCAP_CONTENT_INFO = "encapContentInfo";
  17741. const CERTIFICATES = "certificates";
  17742. const CRLS = "crls";
  17743. const SIGNER_INFOS = "signerInfos";
  17744. const OCSPS = "ocsps";
  17745. const SIGNED_DATA = "SignedData";
  17746. const SIGNED_DATA_VERSION = `${SIGNED_DATA}.${VERSION$2}`;
  17747. const SIGNED_DATA_DIGEST_ALGORITHMS = `${SIGNED_DATA}.${DIGEST_ALGORITHMS}`;
  17748. const SIGNED_DATA_ENCAP_CONTENT_INFO = `${SIGNED_DATA}.${ENCAP_CONTENT_INFO}`;
  17749. const SIGNED_DATA_CERTIFICATES = `${SIGNED_DATA}.${CERTIFICATES}`;
  17750. const SIGNED_DATA_CRLS = `${SIGNED_DATA}.${CRLS}`;
  17751. const SIGNED_DATA_SIGNER_INFOS = `${SIGNED_DATA}.${SIGNER_INFOS}`;
  17752. const CLEAR_PROPS$3 = [
  17753. SIGNED_DATA_VERSION,
  17754. SIGNED_DATA_DIGEST_ALGORITHMS,
  17755. SIGNED_DATA_ENCAP_CONTENT_INFO,
  17756. SIGNED_DATA_CERTIFICATES,
  17757. SIGNED_DATA_CRLS,
  17758. SIGNED_DATA_SIGNER_INFOS
  17759. ];
  17760. class SignedDataVerifyError extends Error {
  17761. constructor({ message, code = 0, date = new Date(), signatureVerified = null, signerCertificate = null, signerCertificateVerified = null, timestampSerial = null, certificatePath = [], }) {
  17762. super(message);
  17763. this.name = "SignedDataVerifyError";
  17764. this.date = date;
  17765. this.code = code;
  17766. this.timestampSerial = timestampSerial;
  17767. this.signatureVerified = signatureVerified;
  17768. this.signerCertificate = signerCertificate;
  17769. this.signerCertificateVerified = signerCertificateVerified;
  17770. this.certificatePath = certificatePath;
  17771. }
  17772. }
  17773. class SignedData extends PkiObject {
  17774. constructor(parameters = {}) {
  17775. super();
  17776. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$2, SignedData.defaultValues(VERSION$2));
  17777. this.digestAlgorithms = pvutils__namespace.getParametersValue(parameters, DIGEST_ALGORITHMS, SignedData.defaultValues(DIGEST_ALGORITHMS));
  17778. this.encapContentInfo = pvutils__namespace.getParametersValue(parameters, ENCAP_CONTENT_INFO, SignedData.defaultValues(ENCAP_CONTENT_INFO));
  17779. if (CERTIFICATES in parameters) {
  17780. this.certificates = pvutils__namespace.getParametersValue(parameters, CERTIFICATES, SignedData.defaultValues(CERTIFICATES));
  17781. }
  17782. if (CRLS in parameters) {
  17783. this.crls = pvutils__namespace.getParametersValue(parameters, CRLS, SignedData.defaultValues(CRLS));
  17784. }
  17785. if (OCSPS in parameters) {
  17786. this.ocsps = pvutils__namespace.getParametersValue(parameters, OCSPS, SignedData.defaultValues(OCSPS));
  17787. }
  17788. this.signerInfos = pvutils__namespace.getParametersValue(parameters, SIGNER_INFOS, SignedData.defaultValues(SIGNER_INFOS));
  17789. if (parameters.schema) {
  17790. this.fromSchema(parameters.schema);
  17791. }
  17792. }
  17793. static defaultValues(memberName) {
  17794. switch (memberName) {
  17795. case VERSION$2:
  17796. return 0;
  17797. case DIGEST_ALGORITHMS:
  17798. return [];
  17799. case ENCAP_CONTENT_INFO:
  17800. return new EncapsulatedContentInfo();
  17801. case CERTIFICATES:
  17802. return [];
  17803. case CRLS:
  17804. return [];
  17805. case OCSPS:
  17806. return [];
  17807. case SIGNER_INFOS:
  17808. return [];
  17809. default:
  17810. return super.defaultValues(memberName);
  17811. }
  17812. }
  17813. static compareWithDefault(memberName, memberValue) {
  17814. switch (memberName) {
  17815. case VERSION$2:
  17816. return (memberValue === SignedData.defaultValues(VERSION$2));
  17817. case ENCAP_CONTENT_INFO:
  17818. return EncapsulatedContentInfo.compareWithDefault("eContentType", memberValue.eContentType) &&
  17819. EncapsulatedContentInfo.compareWithDefault("eContent", memberValue.eContent);
  17820. case DIGEST_ALGORITHMS:
  17821. case CERTIFICATES:
  17822. case CRLS:
  17823. case OCSPS:
  17824. case SIGNER_INFOS:
  17825. return (memberValue.length === 0);
  17826. default:
  17827. return super.defaultValues(memberName);
  17828. }
  17829. }
  17830. static schema(parameters = {}) {
  17831. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  17832. if (names.optional === undefined) {
  17833. names.optional = false;
  17834. }
  17835. return (new asn1js__namespace.Sequence({
  17836. name: (names.blockName || SIGNED_DATA),
  17837. optional: names.optional,
  17838. value: [
  17839. new asn1js__namespace.Integer({ name: (names.version || SIGNED_DATA_VERSION) }),
  17840. new asn1js__namespace.Set({
  17841. value: [
  17842. new asn1js__namespace.Repeated({
  17843. name: (names.digestAlgorithms || SIGNED_DATA_DIGEST_ALGORITHMS),
  17844. value: AlgorithmIdentifier.schema()
  17845. })
  17846. ]
  17847. }),
  17848. EncapsulatedContentInfo.schema(names.encapContentInfo || {
  17849. names: {
  17850. blockName: SIGNED_DATA_ENCAP_CONTENT_INFO
  17851. }
  17852. }),
  17853. new asn1js__namespace.Constructed({
  17854. name: (names.certificates || SIGNED_DATA_CERTIFICATES),
  17855. optional: true,
  17856. idBlock: {
  17857. tagClass: 3,
  17858. tagNumber: 0
  17859. },
  17860. value: CertificateSet.schema().valueBlock.value
  17861. }),
  17862. new asn1js__namespace.Constructed({
  17863. optional: true,
  17864. idBlock: {
  17865. tagClass: 3,
  17866. tagNumber: 1
  17867. },
  17868. value: RevocationInfoChoices.schema(names.crls || {
  17869. names: {
  17870. crls: SIGNED_DATA_CRLS
  17871. }
  17872. }).valueBlock.value
  17873. }),
  17874. new asn1js__namespace.Set({
  17875. value: [
  17876. new asn1js__namespace.Repeated({
  17877. name: (names.signerInfos || SIGNED_DATA_SIGNER_INFOS),
  17878. value: SignerInfo.schema()
  17879. })
  17880. ]
  17881. })
  17882. ]
  17883. }));
  17884. }
  17885. fromSchema(schema) {
  17886. pvutils__namespace.clearProps(schema, CLEAR_PROPS$3);
  17887. const asn1 = asn1js__namespace.compareSchema(schema, schema, SignedData.schema());
  17888. AsnError.assertSchema(asn1, this.className);
  17889. this.version = asn1.result[SIGNED_DATA_VERSION].valueBlock.valueDec;
  17890. if (SIGNED_DATA_DIGEST_ALGORITHMS in asn1.result)
  17891. this.digestAlgorithms = Array.from(asn1.result[SIGNED_DATA_DIGEST_ALGORITHMS], algorithm => new AlgorithmIdentifier({ schema: algorithm }));
  17892. this.encapContentInfo = new EncapsulatedContentInfo({ schema: asn1.result[SIGNED_DATA_ENCAP_CONTENT_INFO] });
  17893. if (SIGNED_DATA_CERTIFICATES in asn1.result) {
  17894. const certificateSet = new CertificateSet({
  17895. schema: new asn1js__namespace.Set({
  17896. value: asn1.result[SIGNED_DATA_CERTIFICATES].valueBlock.value
  17897. })
  17898. });
  17899. this.certificates = certificateSet.certificates.slice(0);
  17900. }
  17901. if (SIGNED_DATA_CRLS in asn1.result) {
  17902. this.crls = Array.from(asn1.result[SIGNED_DATA_CRLS], (crl) => {
  17903. if (crl.idBlock.tagClass === 1)
  17904. return new CertificateRevocationList({ schema: crl });
  17905. crl.idBlock.tagClass = 1;
  17906. crl.idBlock.tagNumber = 16;
  17907. return new OtherRevocationInfoFormat({ schema: crl });
  17908. });
  17909. }
  17910. if (SIGNED_DATA_SIGNER_INFOS in asn1.result)
  17911. this.signerInfos = Array.from(asn1.result[SIGNED_DATA_SIGNER_INFOS], signerInfoSchema => new SignerInfo({ schema: signerInfoSchema }));
  17912. }
  17913. toSchema(encodeFlag = false) {
  17914. const outputArray = [];
  17915. if ((this.certificates && this.certificates.length && this.certificates.some(o => o instanceof OtherCertificateFormat))
  17916. || (this.crls && this.crls.length && this.crls.some(o => o instanceof OtherRevocationInfoFormat))) {
  17917. this.version = 5;
  17918. }
  17919. else if (this.certificates && this.certificates.length && this.certificates.some(o => o instanceof AttributeCertificateV2)) {
  17920. this.version = 4;
  17921. }
  17922. else if ((this.certificates && this.certificates.length && this.certificates.some(o => o instanceof AttributeCertificateV1))
  17923. || this.signerInfos.some(o => o.version === 3)
  17924. || this.encapContentInfo.eContentType !== SignedData.ID_DATA) {
  17925. this.version = 3;
  17926. }
  17927. else {
  17928. this.version = 1;
  17929. }
  17930. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  17931. outputArray.push(new asn1js__namespace.Set({
  17932. value: Array.from(this.digestAlgorithms, algorithm => algorithm.toSchema())
  17933. }));
  17934. outputArray.push(this.encapContentInfo.toSchema());
  17935. if (this.certificates) {
  17936. const certificateSet = new CertificateSet({ certificates: this.certificates });
  17937. const certificateSetSchema = certificateSet.toSchema();
  17938. outputArray.push(new asn1js__namespace.Constructed({
  17939. idBlock: {
  17940. tagClass: 3,
  17941. tagNumber: 0
  17942. },
  17943. value: certificateSetSchema.valueBlock.value
  17944. }));
  17945. }
  17946. if (this.crls) {
  17947. outputArray.push(new asn1js__namespace.Constructed({
  17948. idBlock: {
  17949. tagClass: 3,
  17950. tagNumber: 1
  17951. },
  17952. value: Array.from(this.crls, crl => {
  17953. if (crl instanceof OtherRevocationInfoFormat) {
  17954. const crlSchema = crl.toSchema();
  17955. crlSchema.idBlock.tagClass = 3;
  17956. crlSchema.idBlock.tagNumber = 1;
  17957. return crlSchema;
  17958. }
  17959. return crl.toSchema(encodeFlag);
  17960. })
  17961. }));
  17962. }
  17963. outputArray.push(new asn1js__namespace.Set({
  17964. value: Array.from(this.signerInfos, signerInfo => signerInfo.toSchema())
  17965. }));
  17966. return (new asn1js__namespace.Sequence({
  17967. value: outputArray
  17968. }));
  17969. }
  17970. toJSON() {
  17971. const res = {
  17972. version: this.version,
  17973. digestAlgorithms: Array.from(this.digestAlgorithms, algorithm => algorithm.toJSON()),
  17974. encapContentInfo: this.encapContentInfo.toJSON(),
  17975. signerInfos: Array.from(this.signerInfos, signerInfo => signerInfo.toJSON()),
  17976. };
  17977. if (this.certificates) {
  17978. res.certificates = Array.from(this.certificates, certificate => certificate.toJSON());
  17979. }
  17980. if (this.crls) {
  17981. res.crls = Array.from(this.crls, crl => crl.toJSON());
  17982. }
  17983. return res;
  17984. }
  17985. async verify({ signer = (-1), data = (EMPTY_BUFFER), trustedCerts = [], checkDate = (new Date()), checkChain = false, passedWhenNotRevValues = false, extendedMode = false, findOrigin = null, findIssuer = null } = {}, crypto = getCrypto(true)) {
  17986. let signerCert = null;
  17987. let timestampSerial = null;
  17988. try {
  17989. let messageDigestValue = EMPTY_BUFFER;
  17990. let shaAlgorithm = EMPTY_STRING;
  17991. let certificatePath = [];
  17992. const signerInfo = this.signerInfos[signer];
  17993. if (!signerInfo) {
  17994. throw new SignedDataVerifyError({
  17995. date: checkDate,
  17996. code: 1,
  17997. message: "Unable to get signer by supplied index",
  17998. });
  17999. }
  18000. if (!this.certificates) {
  18001. throw new SignedDataVerifyError({
  18002. date: checkDate,
  18003. code: 2,
  18004. message: "No certificates attached to this signed data",
  18005. });
  18006. }
  18007. if (signerInfo.sid instanceof IssuerAndSerialNumber) {
  18008. for (const certificate of this.certificates) {
  18009. if (!(certificate instanceof Certificate))
  18010. continue;
  18011. if ((certificate.issuer.isEqual(signerInfo.sid.issuer)) &&
  18012. (certificate.serialNumber.isEqual(signerInfo.sid.serialNumber))) {
  18013. signerCert = certificate;
  18014. break;
  18015. }
  18016. }
  18017. }
  18018. else {
  18019. const sid = signerInfo.sid;
  18020. const keyId = sid.idBlock.isConstructed
  18021. ? sid.valueBlock.value[0].valueBlock.valueHex
  18022. : sid.valueBlock.valueHex;
  18023. for (const certificate of this.certificates) {
  18024. if (!(certificate instanceof Certificate)) {
  18025. continue;
  18026. }
  18027. const digest = await crypto.digest({ name: "sha-1" }, certificate.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView);
  18028. if (pvutils__namespace.isEqualBuffer(digest, keyId)) {
  18029. signerCert = certificate;
  18030. break;
  18031. }
  18032. }
  18033. }
  18034. if (!signerCert) {
  18035. throw new SignedDataVerifyError({
  18036. date: checkDate,
  18037. code: 3,
  18038. message: "Unable to find signer certificate",
  18039. });
  18040. }
  18041. if (this.encapContentInfo.eContentType === id_eContentType_TSTInfo) {
  18042. if (!this.encapContentInfo.eContent) {
  18043. throw new SignedDataVerifyError({
  18044. date: checkDate,
  18045. code: 15,
  18046. message: "Error during verification: TSTInfo eContent is empty",
  18047. signatureVerified: null,
  18048. signerCertificate: signerCert,
  18049. timestampSerial,
  18050. signerCertificateVerified: true
  18051. });
  18052. }
  18053. let tstInfo;
  18054. try {
  18055. tstInfo = TSTInfo.fromBER(this.encapContentInfo.eContent.valueBlock.valueHexView);
  18056. }
  18057. catch {
  18058. throw new SignedDataVerifyError({
  18059. date: checkDate,
  18060. code: 15,
  18061. message: "Error during verification: TSTInfo wrong ASN.1 schema ",
  18062. signatureVerified: null,
  18063. signerCertificate: signerCert,
  18064. timestampSerial,
  18065. signerCertificateVerified: true
  18066. });
  18067. }
  18068. checkDate = tstInfo.genTime;
  18069. timestampSerial = tstInfo.serialNumber.valueBlock.valueHexView.slice().buffer;
  18070. if (data.byteLength === 0) {
  18071. throw new SignedDataVerifyError({
  18072. date: checkDate,
  18073. code: 4,
  18074. message: "Missed detached data input array",
  18075. });
  18076. }
  18077. if (!(await tstInfo.verify({ data }, crypto))) {
  18078. throw new SignedDataVerifyError({
  18079. date: checkDate,
  18080. code: 15,
  18081. message: "Error during verification: TSTInfo verification is failed",
  18082. signatureVerified: false,
  18083. signerCertificate: signerCert,
  18084. timestampSerial,
  18085. signerCertificateVerified: true
  18086. });
  18087. }
  18088. }
  18089. if (checkChain) {
  18090. const certs = this.certificates.filter(certificate => (certificate instanceof Certificate && !!checkCA(certificate, signerCert)));
  18091. const chainParams = {
  18092. checkDate,
  18093. certs,
  18094. trustedCerts,
  18095. };
  18096. if (findIssuer) {
  18097. chainParams.findIssuer = findIssuer;
  18098. }
  18099. if (findOrigin) {
  18100. chainParams.findOrigin = findOrigin;
  18101. }
  18102. const chainEngine = new CertificateChainValidationEngine(chainParams);
  18103. chainEngine.certs.push(signerCert);
  18104. if (this.crls) {
  18105. for (const crl of this.crls) {
  18106. if ("thisUpdate" in crl)
  18107. chainEngine.crls.push(crl);
  18108. else {
  18109. if (crl.otherRevInfoFormat === id_PKIX_OCSP_Basic)
  18110. chainEngine.ocsps.push(new BasicOCSPResponse({ schema: crl.otherRevInfo }));
  18111. }
  18112. }
  18113. }
  18114. if (this.ocsps) {
  18115. chainEngine.ocsps.push(...(this.ocsps));
  18116. }
  18117. const verificationResult = await chainEngine.verify({ passedWhenNotRevValues }, crypto)
  18118. .catch(e => {
  18119. throw new SignedDataVerifyError({
  18120. date: checkDate,
  18121. code: 5,
  18122. message: `Validation of signer's certificate failed with error: ${((e instanceof Object) ? e.resultMessage : e)}`,
  18123. signerCertificate: signerCert,
  18124. signerCertificateVerified: false
  18125. });
  18126. });
  18127. if (verificationResult.certificatePath) {
  18128. certificatePath = verificationResult.certificatePath;
  18129. }
  18130. if (!verificationResult.result)
  18131. throw new SignedDataVerifyError({
  18132. date: checkDate,
  18133. code: 5,
  18134. message: `Validation of signer's certificate failed: ${verificationResult.resultMessage}`,
  18135. signerCertificate: signerCert,
  18136. signerCertificateVerified: false
  18137. });
  18138. }
  18139. const signerInfoHashAlgorithm = crypto.getAlgorithmByOID(signerInfo.digestAlgorithm.algorithmId);
  18140. if (!("name" in signerInfoHashAlgorithm)) {
  18141. throw new SignedDataVerifyError({
  18142. date: checkDate,
  18143. code: 7,
  18144. message: `Unsupported signature algorithm: ${signerInfo.digestAlgorithm.algorithmId}`,
  18145. signerCertificate: signerCert,
  18146. signerCertificateVerified: true
  18147. });
  18148. }
  18149. shaAlgorithm = signerInfoHashAlgorithm.name;
  18150. const eContent = this.encapContentInfo.eContent;
  18151. if (eContent) {
  18152. if ((eContent.idBlock.tagClass === 1) &&
  18153. (eContent.idBlock.tagNumber === 4)) {
  18154. data = eContent.getValue();
  18155. }
  18156. else
  18157. data = eContent.valueBlock.valueBeforeDecodeView.slice().buffer;
  18158. }
  18159. else {
  18160. if (data.byteLength === 0) {
  18161. throw new SignedDataVerifyError({
  18162. date: checkDate,
  18163. code: 8,
  18164. message: "Missed detached data input array",
  18165. signerCertificate: signerCert,
  18166. signerCertificateVerified: true
  18167. });
  18168. }
  18169. }
  18170. if (signerInfo.signedAttrs) {
  18171. let foundContentType = false;
  18172. let foundMessageDigest = false;
  18173. for (const attribute of signerInfo.signedAttrs.attributes) {
  18174. if (attribute.type === "1.2.840.113549.1.9.3")
  18175. foundContentType = true;
  18176. if (attribute.type === "1.2.840.113549.1.9.4") {
  18177. foundMessageDigest = true;
  18178. messageDigestValue = attribute.values[0].valueBlock.valueHex;
  18179. }
  18180. if (foundContentType && foundMessageDigest)
  18181. break;
  18182. }
  18183. if (foundContentType === false) {
  18184. throw new SignedDataVerifyError({
  18185. date: checkDate,
  18186. code: 9,
  18187. message: "Attribute \"content-type\" is a mandatory attribute for \"signed attributes\"",
  18188. signerCertificate: signerCert,
  18189. signerCertificateVerified: true
  18190. });
  18191. }
  18192. if (foundMessageDigest === false) {
  18193. throw new SignedDataVerifyError({
  18194. date: checkDate,
  18195. code: 10,
  18196. message: "Attribute \"message-digest\" is a mandatory attribute for \"signed attributes\"",
  18197. signatureVerified: null,
  18198. signerCertificate: signerCert,
  18199. signerCertificateVerified: true
  18200. });
  18201. }
  18202. }
  18203. if (signerInfo.signedAttrs) {
  18204. const messageDigest = await crypto.digest(shaAlgorithm, new Uint8Array(data));
  18205. if (!pvutils__namespace.isEqualBuffer(messageDigest, messageDigestValue)) {
  18206. throw new SignedDataVerifyError({
  18207. date: checkDate,
  18208. code: 15,
  18209. message: "Error during verification: Message digest doesn't match",
  18210. signatureVerified: null,
  18211. signerCertificate: signerCert,
  18212. timestampSerial,
  18213. signerCertificateVerified: true
  18214. });
  18215. }
  18216. data = signerInfo.signedAttrs.encodedValue;
  18217. }
  18218. const verifyResult = signerInfo.signatureAlgorithm.algorithmId === "1.2.840.113549.1.1.1"
  18219. ? await crypto.verifyWithPublicKey(data, signerInfo.signature, signerCert.subjectPublicKeyInfo, signerInfo.signatureAlgorithm, shaAlgorithm)
  18220. : await crypto.verifyWithPublicKey(data, signerInfo.signature, signerCert.subjectPublicKeyInfo, signerInfo.signatureAlgorithm);
  18221. if (extendedMode) {
  18222. return {
  18223. date: checkDate,
  18224. code: 14,
  18225. message: EMPTY_STRING,
  18226. signatureVerified: verifyResult,
  18227. signerCertificate: signerCert,
  18228. timestampSerial,
  18229. signerCertificateVerified: true,
  18230. certificatePath
  18231. };
  18232. }
  18233. else {
  18234. return verifyResult;
  18235. }
  18236. }
  18237. catch (e) {
  18238. if (e instanceof SignedDataVerifyError) {
  18239. throw e;
  18240. }
  18241. throw new SignedDataVerifyError({
  18242. date: checkDate,
  18243. code: 15,
  18244. message: `Error during verification: ${e instanceof Error ? e.message : e}`,
  18245. signatureVerified: null,
  18246. signerCertificate: signerCert,
  18247. timestampSerial,
  18248. signerCertificateVerified: true
  18249. });
  18250. }
  18251. }
  18252. async sign(privateKey, signerIndex, hashAlgorithm = "SHA-1", data = (EMPTY_BUFFER), crypto = getCrypto(true)) {
  18253. var _a;
  18254. if (!privateKey)
  18255. throw new Error("Need to provide a private key for signing");
  18256. const signerInfo = this.signerInfos[signerIndex];
  18257. if (!signerInfo) {
  18258. throw new RangeError("SignerInfo index is out of range");
  18259. }
  18260. if (!((_a = signerInfo.signedAttrs) === null || _a === void 0 ? void 0 : _a.attributes.length) && "hash" in privateKey.algorithm && "hash" in privateKey.algorithm && privateKey.algorithm.hash) {
  18261. hashAlgorithm = privateKey.algorithm.hash.name;
  18262. }
  18263. const hashAlgorithmOID = crypto.getOIDByAlgorithm({ name: hashAlgorithm }, true, "hashAlgorithm");
  18264. if ((this.digestAlgorithms.filter(algorithm => algorithm.algorithmId === hashAlgorithmOID)).length === 0) {
  18265. this.digestAlgorithms.push(new AlgorithmIdentifier({
  18266. algorithmId: hashAlgorithmOID,
  18267. algorithmParams: new asn1js__namespace.Null()
  18268. }));
  18269. }
  18270. signerInfo.digestAlgorithm = new AlgorithmIdentifier({
  18271. algorithmId: hashAlgorithmOID,
  18272. algorithmParams: new asn1js__namespace.Null()
  18273. });
  18274. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  18275. const parameters = signatureParams.parameters;
  18276. signerInfo.signatureAlgorithm = signatureParams.signatureAlgorithm;
  18277. if (signerInfo.signedAttrs) {
  18278. if (signerInfo.signedAttrs.encodedValue.byteLength !== 0)
  18279. data = signerInfo.signedAttrs.encodedValue;
  18280. else {
  18281. data = signerInfo.signedAttrs.toSchema().toBER();
  18282. const view = pvtsutils__namespace.BufferSourceConverter.toUint8Array(data);
  18283. view[0] = 0x31;
  18284. }
  18285. }
  18286. else {
  18287. const eContent = this.encapContentInfo.eContent;
  18288. if (eContent) {
  18289. if ((eContent.idBlock.tagClass === 1) &&
  18290. (eContent.idBlock.tagNumber === 4)) {
  18291. data = eContent.getValue();
  18292. }
  18293. else
  18294. data = eContent.valueBlock.valueBeforeDecodeView.slice().buffer;
  18295. }
  18296. else {
  18297. if (data.byteLength === 0)
  18298. throw new Error("Missed detached data input array");
  18299. }
  18300. }
  18301. const signature = await crypto.signWithPrivateKey(data, privateKey, parameters);
  18302. signerInfo.signature = new asn1js__namespace.OctetString({ valueHex: signature });
  18303. }
  18304. }
  18305. SignedData.CLASS_NAME = "SignedData";
  18306. SignedData.ID_DATA = id_ContentType_Data;
  18307. const VERSION$1 = "version";
  18308. const AUTH_SAFE = "authSafe";
  18309. const MAC_DATA = "macData";
  18310. const PARSED_VALUE = "parsedValue";
  18311. const CLERA_PROPS = [
  18312. VERSION$1,
  18313. AUTH_SAFE,
  18314. MAC_DATA
  18315. ];
  18316. class PFX extends PkiObject {
  18317. constructor(parameters = {}) {
  18318. super();
  18319. this.version = pvutils__namespace.getParametersValue(parameters, VERSION$1, PFX.defaultValues(VERSION$1));
  18320. this.authSafe = pvutils__namespace.getParametersValue(parameters, AUTH_SAFE, PFX.defaultValues(AUTH_SAFE));
  18321. if (MAC_DATA in parameters) {
  18322. this.macData = pvutils__namespace.getParametersValue(parameters, MAC_DATA, PFX.defaultValues(MAC_DATA));
  18323. }
  18324. if (PARSED_VALUE in parameters) {
  18325. this.parsedValue = pvutils__namespace.getParametersValue(parameters, PARSED_VALUE, PFX.defaultValues(PARSED_VALUE));
  18326. }
  18327. if (parameters.schema) {
  18328. this.fromSchema(parameters.schema);
  18329. }
  18330. }
  18331. static defaultValues(memberName) {
  18332. switch (memberName) {
  18333. case VERSION$1:
  18334. return 3;
  18335. case AUTH_SAFE:
  18336. return (new ContentInfo());
  18337. case MAC_DATA:
  18338. return (new MacData());
  18339. case PARSED_VALUE:
  18340. return {};
  18341. default:
  18342. return super.defaultValues(memberName);
  18343. }
  18344. }
  18345. static compareWithDefault(memberName, memberValue) {
  18346. switch (memberName) {
  18347. case VERSION$1:
  18348. return (memberValue === PFX.defaultValues(memberName));
  18349. case AUTH_SAFE:
  18350. return ((ContentInfo.compareWithDefault("contentType", memberValue.contentType)) &&
  18351. (ContentInfo.compareWithDefault("content", memberValue.content)));
  18352. case MAC_DATA:
  18353. return ((MacData.compareWithDefault("mac", memberValue.mac)) &&
  18354. (MacData.compareWithDefault("macSalt", memberValue.macSalt)) &&
  18355. (MacData.compareWithDefault("iterations", memberValue.iterations)));
  18356. case PARSED_VALUE:
  18357. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  18358. default:
  18359. return super.defaultValues(memberName);
  18360. }
  18361. }
  18362. static schema(parameters = {}) {
  18363. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  18364. return (new asn1js__namespace.Sequence({
  18365. name: (names.blockName || EMPTY_STRING),
  18366. value: [
  18367. new asn1js__namespace.Integer({ name: (names.version || VERSION$1) }),
  18368. ContentInfo.schema(names.authSafe || {
  18369. names: {
  18370. blockName: AUTH_SAFE
  18371. }
  18372. }),
  18373. MacData.schema(names.macData || {
  18374. names: {
  18375. blockName: MAC_DATA,
  18376. optional: true
  18377. }
  18378. })
  18379. ]
  18380. }));
  18381. }
  18382. fromSchema(schema) {
  18383. pvutils__namespace.clearProps(schema, CLERA_PROPS);
  18384. const asn1 = asn1js__namespace.compareSchema(schema, schema, PFX.schema({
  18385. names: {
  18386. version: VERSION$1,
  18387. authSafe: {
  18388. names: {
  18389. blockName: AUTH_SAFE
  18390. }
  18391. },
  18392. macData: {
  18393. names: {
  18394. blockName: MAC_DATA
  18395. }
  18396. }
  18397. }
  18398. }));
  18399. AsnError.assertSchema(asn1, this.className);
  18400. this.version = asn1.result.version.valueBlock.valueDec;
  18401. this.authSafe = new ContentInfo({ schema: asn1.result.authSafe });
  18402. if (MAC_DATA in asn1.result)
  18403. this.macData = new MacData({ schema: asn1.result.macData });
  18404. }
  18405. toSchema() {
  18406. const outputArray = [
  18407. new asn1js__namespace.Integer({ value: this.version }),
  18408. this.authSafe.toSchema()
  18409. ];
  18410. if (this.macData) {
  18411. outputArray.push(this.macData.toSchema());
  18412. }
  18413. return (new asn1js__namespace.Sequence({
  18414. value: outputArray
  18415. }));
  18416. }
  18417. toJSON() {
  18418. const output = {
  18419. version: this.version,
  18420. authSafe: this.authSafe.toJSON()
  18421. };
  18422. if (this.macData) {
  18423. output.macData = this.macData.toJSON();
  18424. }
  18425. return output;
  18426. }
  18427. async makeInternalValues(parameters = {}, crypto = getCrypto(true)) {
  18428. ArgumentError.assert(parameters, "parameters", "object");
  18429. if (!this.parsedValue) {
  18430. throw new Error("Please call \"parseValues\" function first in order to make \"parsedValue\" data");
  18431. }
  18432. ParameterError.assertEmpty(this.parsedValue.integrityMode, "integrityMode", "parsedValue");
  18433. ParameterError.assertEmpty(this.parsedValue.authenticatedSafe, "authenticatedSafe", "parsedValue");
  18434. switch (this.parsedValue.integrityMode) {
  18435. case 0:
  18436. {
  18437. if (!("iterations" in parameters))
  18438. throw new ParameterError("iterations");
  18439. ParameterError.assertEmpty(parameters.pbkdf2HashAlgorithm, "pbkdf2HashAlgorithm");
  18440. ParameterError.assertEmpty(parameters.hmacHashAlgorithm, "hmacHashAlgorithm");
  18441. ParameterError.assertEmpty(parameters.password, "password");
  18442. const saltBuffer = new ArrayBuffer(64);
  18443. const saltView = new Uint8Array(saltBuffer);
  18444. crypto.getRandomValues(saltView);
  18445. const data = this.parsedValue.authenticatedSafe.toSchema().toBER(false);
  18446. this.authSafe = new ContentInfo({
  18447. contentType: ContentInfo.DATA,
  18448. content: new asn1js__namespace.OctetString({ valueHex: data })
  18449. });
  18450. const result = await crypto.stampDataWithPassword({
  18451. password: parameters.password,
  18452. hashAlgorithm: parameters.hmacHashAlgorithm,
  18453. salt: saltBuffer,
  18454. iterationCount: parameters.iterations,
  18455. contentToStamp: data
  18456. });
  18457. this.macData = new MacData({
  18458. mac: new DigestInfo({
  18459. digestAlgorithm: new AlgorithmIdentifier({
  18460. algorithmId: crypto.getOIDByAlgorithm({ name: parameters.hmacHashAlgorithm }, true, "hmacHashAlgorithm"),
  18461. }),
  18462. digest: new asn1js__namespace.OctetString({ valueHex: result })
  18463. }),
  18464. macSalt: new asn1js__namespace.OctetString({ valueHex: saltBuffer }),
  18465. iterations: parameters.iterations
  18466. });
  18467. }
  18468. break;
  18469. case 1:
  18470. {
  18471. if (!("signingCertificate" in parameters)) {
  18472. throw new ParameterError("signingCertificate");
  18473. }
  18474. ParameterError.assertEmpty(parameters.privateKey, "privateKey");
  18475. ParameterError.assertEmpty(parameters.hashAlgorithm, "hashAlgorithm");
  18476. const toBeSigned = this.parsedValue.authenticatedSafe.toSchema().toBER(false);
  18477. const cmsSigned = new SignedData({
  18478. version: 1,
  18479. encapContentInfo: new EncapsulatedContentInfo({
  18480. eContentType: "1.2.840.113549.1.7.1",
  18481. eContent: new asn1js__namespace.OctetString({ valueHex: toBeSigned })
  18482. }),
  18483. certificates: [parameters.signingCertificate]
  18484. });
  18485. const result = await crypto.digest({ name: parameters.hashAlgorithm }, new Uint8Array(toBeSigned));
  18486. const signedAttr = [];
  18487. signedAttr.push(new Attribute({
  18488. type: "1.2.840.113549.1.9.3",
  18489. values: [
  18490. new asn1js__namespace.ObjectIdentifier({ value: "1.2.840.113549.1.7.1" })
  18491. ]
  18492. }));
  18493. signedAttr.push(new Attribute({
  18494. type: "1.2.840.113549.1.9.5",
  18495. values: [
  18496. new asn1js__namespace.UTCTime({ valueDate: new Date() })
  18497. ]
  18498. }));
  18499. signedAttr.push(new Attribute({
  18500. type: "1.2.840.113549.1.9.4",
  18501. values: [
  18502. new asn1js__namespace.OctetString({ valueHex: result })
  18503. ]
  18504. }));
  18505. cmsSigned.signerInfos.push(new SignerInfo({
  18506. version: 1,
  18507. sid: new IssuerAndSerialNumber({
  18508. issuer: parameters.signingCertificate.issuer,
  18509. serialNumber: parameters.signingCertificate.serialNumber
  18510. }),
  18511. signedAttrs: new SignedAndUnsignedAttributes({
  18512. type: 0,
  18513. attributes: signedAttr
  18514. })
  18515. }));
  18516. await cmsSigned.sign(parameters.privateKey, 0, parameters.hashAlgorithm, undefined, crypto);
  18517. this.authSafe = new ContentInfo({
  18518. contentType: "1.2.840.113549.1.7.2",
  18519. content: cmsSigned.toSchema(true)
  18520. });
  18521. }
  18522. break;
  18523. default:
  18524. throw new Error(`Parameter "integrityMode" has unknown value: ${this.parsedValue.integrityMode}`);
  18525. }
  18526. }
  18527. async parseInternalValues(parameters, crypto = getCrypto(true)) {
  18528. ArgumentError.assert(parameters, "parameters", "object");
  18529. if (parameters.checkIntegrity === undefined) {
  18530. parameters.checkIntegrity = true;
  18531. }
  18532. this.parsedValue = {};
  18533. switch (this.authSafe.contentType) {
  18534. case ContentInfo.DATA:
  18535. {
  18536. ParameterError.assertEmpty(parameters.password, "password");
  18537. this.parsedValue.integrityMode = 0;
  18538. ArgumentError.assert(this.authSafe.content, "authSafe.content", asn1js__namespace.OctetString);
  18539. const authSafeContent = this.authSafe.content.getValue();
  18540. this.parsedValue.authenticatedSafe = AuthenticatedSafe.fromBER(authSafeContent);
  18541. if (parameters.checkIntegrity) {
  18542. if (!this.macData) {
  18543. throw new Error("Absent \"macData\" value, can not check PKCS#12 data integrity");
  18544. }
  18545. const hashAlgorithm = crypto.getAlgorithmByOID(this.macData.mac.digestAlgorithm.algorithmId, true, "digestAlgorithm");
  18546. const result = await crypto.verifyDataStampedWithPassword({
  18547. password: parameters.password,
  18548. hashAlgorithm: hashAlgorithm.name,
  18549. salt: pvtsutils.BufferSourceConverter.toArrayBuffer(this.macData.macSalt.valueBlock.valueHexView),
  18550. iterationCount: this.macData.iterations || 1,
  18551. contentToVerify: authSafeContent,
  18552. signatureToVerify: pvtsutils.BufferSourceConverter.toArrayBuffer(this.macData.mac.digest.valueBlock.valueHexView),
  18553. });
  18554. if (!result) {
  18555. throw new Error("Integrity for the PKCS#12 data is broken!");
  18556. }
  18557. }
  18558. }
  18559. break;
  18560. case ContentInfo.SIGNED_DATA:
  18561. {
  18562. this.parsedValue.integrityMode = 1;
  18563. const cmsSigned = new SignedData({ schema: this.authSafe.content });
  18564. const eContent = cmsSigned.encapContentInfo.eContent;
  18565. ParameterError.assert(eContent, "eContent", "cmsSigned.encapContentInfo");
  18566. ArgumentError.assert(eContent, "eContent", asn1js__namespace.OctetString);
  18567. const data = eContent.getValue();
  18568. this.parsedValue.authenticatedSafe = AuthenticatedSafe.fromBER(data);
  18569. const ok = await cmsSigned.verify({ signer: 0, checkChain: false }, crypto);
  18570. if (!ok) {
  18571. throw new Error("Integrity for the PKCS#12 data is broken!");
  18572. }
  18573. }
  18574. break;
  18575. default:
  18576. throw new Error(`Incorrect value for "this.authSafe.contentType": ${this.authSafe.contentType}`);
  18577. }
  18578. }
  18579. }
  18580. PFX.CLASS_NAME = "PFX";
  18581. const STATUS$1 = "status";
  18582. const STATUS_STRINGS = "statusStrings";
  18583. const FAIL_INFO = "failInfo";
  18584. const CLEAR_PROPS$2 = [
  18585. STATUS$1,
  18586. STATUS_STRINGS,
  18587. FAIL_INFO
  18588. ];
  18589. exports.PKIStatus = void 0;
  18590. (function (PKIStatus) {
  18591. PKIStatus[PKIStatus["granted"] = 0] = "granted";
  18592. PKIStatus[PKIStatus["grantedWithMods"] = 1] = "grantedWithMods";
  18593. PKIStatus[PKIStatus["rejection"] = 2] = "rejection";
  18594. PKIStatus[PKIStatus["waiting"] = 3] = "waiting";
  18595. PKIStatus[PKIStatus["revocationWarning"] = 4] = "revocationWarning";
  18596. PKIStatus[PKIStatus["revocationNotification"] = 5] = "revocationNotification";
  18597. })(exports.PKIStatus || (exports.PKIStatus = {}));
  18598. class PKIStatusInfo extends PkiObject {
  18599. constructor(parameters = {}) {
  18600. super();
  18601. this.status = pvutils__namespace.getParametersValue(parameters, STATUS$1, PKIStatusInfo.defaultValues(STATUS$1));
  18602. if (STATUS_STRINGS in parameters) {
  18603. this.statusStrings = pvutils__namespace.getParametersValue(parameters, STATUS_STRINGS, PKIStatusInfo.defaultValues(STATUS_STRINGS));
  18604. }
  18605. if (FAIL_INFO in parameters) {
  18606. this.failInfo = pvutils__namespace.getParametersValue(parameters, FAIL_INFO, PKIStatusInfo.defaultValues(FAIL_INFO));
  18607. }
  18608. if (parameters.schema) {
  18609. this.fromSchema(parameters.schema);
  18610. }
  18611. }
  18612. static defaultValues(memberName) {
  18613. switch (memberName) {
  18614. case STATUS$1:
  18615. return 2;
  18616. case STATUS_STRINGS:
  18617. return [];
  18618. case FAIL_INFO:
  18619. return new asn1js__namespace.BitString();
  18620. default:
  18621. return super.defaultValues(memberName);
  18622. }
  18623. }
  18624. static compareWithDefault(memberName, memberValue) {
  18625. switch (memberName) {
  18626. case STATUS$1:
  18627. return (memberValue === PKIStatusInfo.defaultValues(memberName));
  18628. case STATUS_STRINGS:
  18629. return (memberValue.length === 0);
  18630. case FAIL_INFO:
  18631. return (memberValue.isEqual(PKIStatusInfo.defaultValues(memberName)));
  18632. default:
  18633. return super.defaultValues(memberName);
  18634. }
  18635. }
  18636. static schema(parameters = {}) {
  18637. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  18638. return (new asn1js__namespace.Sequence({
  18639. name: (names.blockName || EMPTY_STRING),
  18640. value: [
  18641. new asn1js__namespace.Integer({ name: (names.status || EMPTY_STRING) }),
  18642. new asn1js__namespace.Sequence({
  18643. optional: true,
  18644. value: [
  18645. new asn1js__namespace.Repeated({
  18646. name: (names.statusStrings || EMPTY_STRING),
  18647. value: new asn1js__namespace.Utf8String()
  18648. })
  18649. ]
  18650. }),
  18651. new asn1js__namespace.BitString({
  18652. name: (names.failInfo || EMPTY_STRING),
  18653. optional: true
  18654. })
  18655. ]
  18656. }));
  18657. }
  18658. fromSchema(schema) {
  18659. pvutils__namespace.clearProps(schema, CLEAR_PROPS$2);
  18660. const asn1 = asn1js__namespace.compareSchema(schema, schema, PKIStatusInfo.schema({
  18661. names: {
  18662. status: STATUS$1,
  18663. statusStrings: STATUS_STRINGS,
  18664. failInfo: FAIL_INFO
  18665. }
  18666. }));
  18667. AsnError.assertSchema(asn1, this.className);
  18668. const _status = asn1.result.status;
  18669. if ((_status.valueBlock.isHexOnly === true) ||
  18670. (_status.valueBlock.valueDec < 0) ||
  18671. (_status.valueBlock.valueDec > 5))
  18672. throw new Error("PKIStatusInfo \"status\" has invalid value");
  18673. this.status = _status.valueBlock.valueDec;
  18674. if (STATUS_STRINGS in asn1.result)
  18675. this.statusStrings = asn1.result.statusStrings;
  18676. if (FAIL_INFO in asn1.result)
  18677. this.failInfo = asn1.result.failInfo;
  18678. }
  18679. toSchema() {
  18680. const outputArray = [];
  18681. outputArray.push(new asn1js__namespace.Integer({ value: this.status }));
  18682. if (this.statusStrings) {
  18683. outputArray.push(new asn1js__namespace.Sequence({
  18684. optional: true,
  18685. value: this.statusStrings
  18686. }));
  18687. }
  18688. if (this.failInfo) {
  18689. outputArray.push(this.failInfo);
  18690. }
  18691. return (new asn1js__namespace.Sequence({
  18692. value: outputArray
  18693. }));
  18694. }
  18695. toJSON() {
  18696. const res = {
  18697. status: this.status
  18698. };
  18699. if (this.statusStrings) {
  18700. res.statusStrings = Array.from(this.statusStrings, o => o.toJSON());
  18701. }
  18702. if (this.failInfo) {
  18703. res.failInfo = this.failInfo.toJSON();
  18704. }
  18705. return res;
  18706. }
  18707. }
  18708. PKIStatusInfo.CLASS_NAME = "PKIStatusInfo";
  18709. const VERSION = "version";
  18710. const MESSAGE_IMPRINT = "messageImprint";
  18711. const REQ_POLICY = "reqPolicy";
  18712. const NONCE = "nonce";
  18713. const CERT_REQ = "certReq";
  18714. const EXTENSIONS = "extensions";
  18715. const TIME_STAMP_REQ = "TimeStampReq";
  18716. const TIME_STAMP_REQ_VERSION = `${TIME_STAMP_REQ}.${VERSION}`;
  18717. const TIME_STAMP_REQ_MESSAGE_IMPRINT = `${TIME_STAMP_REQ}.${MESSAGE_IMPRINT}`;
  18718. const TIME_STAMP_REQ_POLICY = `${TIME_STAMP_REQ}.${REQ_POLICY}`;
  18719. const TIME_STAMP_REQ_NONCE = `${TIME_STAMP_REQ}.${NONCE}`;
  18720. const TIME_STAMP_REQ_CERT_REQ = `${TIME_STAMP_REQ}.${CERT_REQ}`;
  18721. const TIME_STAMP_REQ_EXTENSIONS = `${TIME_STAMP_REQ}.${EXTENSIONS}`;
  18722. const CLEAR_PROPS$1 = [
  18723. TIME_STAMP_REQ_VERSION,
  18724. TIME_STAMP_REQ_MESSAGE_IMPRINT,
  18725. TIME_STAMP_REQ_POLICY,
  18726. TIME_STAMP_REQ_NONCE,
  18727. TIME_STAMP_REQ_CERT_REQ,
  18728. TIME_STAMP_REQ_EXTENSIONS,
  18729. ];
  18730. class TimeStampReq extends PkiObject {
  18731. constructor(parameters = {}) {
  18732. super();
  18733. this.version = pvutils__namespace.getParametersValue(parameters, VERSION, TimeStampReq.defaultValues(VERSION));
  18734. this.messageImprint = pvutils__namespace.getParametersValue(parameters, MESSAGE_IMPRINT, TimeStampReq.defaultValues(MESSAGE_IMPRINT));
  18735. if (REQ_POLICY in parameters) {
  18736. this.reqPolicy = pvutils__namespace.getParametersValue(parameters, REQ_POLICY, TimeStampReq.defaultValues(REQ_POLICY));
  18737. }
  18738. if (NONCE in parameters) {
  18739. this.nonce = pvutils__namespace.getParametersValue(parameters, NONCE, TimeStampReq.defaultValues(NONCE));
  18740. }
  18741. if (CERT_REQ in parameters) {
  18742. this.certReq = pvutils__namespace.getParametersValue(parameters, CERT_REQ, TimeStampReq.defaultValues(CERT_REQ));
  18743. }
  18744. if (EXTENSIONS in parameters) {
  18745. this.extensions = pvutils__namespace.getParametersValue(parameters, EXTENSIONS, TimeStampReq.defaultValues(EXTENSIONS));
  18746. }
  18747. if (parameters.schema) {
  18748. this.fromSchema(parameters.schema);
  18749. }
  18750. }
  18751. static defaultValues(memberName) {
  18752. switch (memberName) {
  18753. case VERSION:
  18754. return 0;
  18755. case MESSAGE_IMPRINT:
  18756. return new MessageImprint();
  18757. case REQ_POLICY:
  18758. return EMPTY_STRING;
  18759. case NONCE:
  18760. return new asn1js__namespace.Integer();
  18761. case CERT_REQ:
  18762. return false;
  18763. case EXTENSIONS:
  18764. return [];
  18765. default:
  18766. return super.defaultValues(memberName);
  18767. }
  18768. }
  18769. static compareWithDefault(memberName, memberValue) {
  18770. switch (memberName) {
  18771. case VERSION:
  18772. case REQ_POLICY:
  18773. case CERT_REQ:
  18774. return (memberValue === TimeStampReq.defaultValues(memberName));
  18775. case MESSAGE_IMPRINT:
  18776. return ((MessageImprint.compareWithDefault("hashAlgorithm", memberValue.hashAlgorithm)) &&
  18777. (MessageImprint.compareWithDefault("hashedMessage", memberValue.hashedMessage)));
  18778. case NONCE:
  18779. return (memberValue.isEqual(TimeStampReq.defaultValues(memberName)));
  18780. case EXTENSIONS:
  18781. return (memberValue.length === 0);
  18782. default:
  18783. return super.defaultValues(memberName);
  18784. }
  18785. }
  18786. static schema(parameters = {}) {
  18787. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  18788. return (new asn1js__namespace.Sequence({
  18789. name: (names.blockName || TIME_STAMP_REQ),
  18790. value: [
  18791. new asn1js__namespace.Integer({ name: (names.version || TIME_STAMP_REQ_VERSION) }),
  18792. MessageImprint.schema(names.messageImprint || {
  18793. names: {
  18794. blockName: TIME_STAMP_REQ_MESSAGE_IMPRINT
  18795. }
  18796. }),
  18797. new asn1js__namespace.ObjectIdentifier({
  18798. name: (names.reqPolicy || TIME_STAMP_REQ_POLICY),
  18799. optional: true
  18800. }),
  18801. new asn1js__namespace.Integer({
  18802. name: (names.nonce || TIME_STAMP_REQ_NONCE),
  18803. optional: true
  18804. }),
  18805. new asn1js__namespace.Boolean({
  18806. name: (names.certReq || TIME_STAMP_REQ_CERT_REQ),
  18807. optional: true
  18808. }),
  18809. new asn1js__namespace.Constructed({
  18810. optional: true,
  18811. idBlock: {
  18812. tagClass: 3,
  18813. tagNumber: 0
  18814. },
  18815. value: [new asn1js__namespace.Repeated({
  18816. name: (names.extensions || TIME_STAMP_REQ_EXTENSIONS),
  18817. value: Extension.schema()
  18818. })]
  18819. })
  18820. ]
  18821. }));
  18822. }
  18823. fromSchema(schema) {
  18824. pvutils__namespace.clearProps(schema, CLEAR_PROPS$1);
  18825. const asn1 = asn1js__namespace.compareSchema(schema, schema, TimeStampReq.schema());
  18826. AsnError.assertSchema(asn1, this.className);
  18827. this.version = asn1.result[TIME_STAMP_REQ_VERSION].valueBlock.valueDec;
  18828. this.messageImprint = new MessageImprint({ schema: asn1.result[TIME_STAMP_REQ_MESSAGE_IMPRINT] });
  18829. if (TIME_STAMP_REQ_POLICY in asn1.result)
  18830. this.reqPolicy = asn1.result[TIME_STAMP_REQ_POLICY].valueBlock.toString();
  18831. if (TIME_STAMP_REQ_NONCE in asn1.result)
  18832. this.nonce = asn1.result[TIME_STAMP_REQ_NONCE];
  18833. if (TIME_STAMP_REQ_CERT_REQ in asn1.result)
  18834. this.certReq = asn1.result[TIME_STAMP_REQ_CERT_REQ].valueBlock.value;
  18835. if (TIME_STAMP_REQ_EXTENSIONS in asn1.result)
  18836. this.extensions = Array.from(asn1.result[TIME_STAMP_REQ_EXTENSIONS], element => new Extension({ schema: element }));
  18837. }
  18838. toSchema() {
  18839. const outputArray = [];
  18840. outputArray.push(new asn1js__namespace.Integer({ value: this.version }));
  18841. outputArray.push(this.messageImprint.toSchema());
  18842. if (this.reqPolicy)
  18843. outputArray.push(new asn1js__namespace.ObjectIdentifier({ value: this.reqPolicy }));
  18844. if (this.nonce)
  18845. outputArray.push(this.nonce);
  18846. if ((CERT_REQ in this) && (TimeStampReq.compareWithDefault(CERT_REQ, this.certReq) === false))
  18847. outputArray.push(new asn1js__namespace.Boolean({ value: this.certReq }));
  18848. if (this.extensions) {
  18849. outputArray.push(new asn1js__namespace.Constructed({
  18850. idBlock: {
  18851. tagClass: 3,
  18852. tagNumber: 0
  18853. },
  18854. value: Array.from(this.extensions, o => o.toSchema())
  18855. }));
  18856. }
  18857. return (new asn1js__namespace.Sequence({
  18858. value: outputArray
  18859. }));
  18860. }
  18861. toJSON() {
  18862. const res = {
  18863. version: this.version,
  18864. messageImprint: this.messageImprint.toJSON()
  18865. };
  18866. if (this.reqPolicy !== undefined)
  18867. res.reqPolicy = this.reqPolicy;
  18868. if (this.nonce !== undefined)
  18869. res.nonce = this.nonce.toJSON();
  18870. if ((this.certReq !== undefined) && (TimeStampReq.compareWithDefault(CERT_REQ, this.certReq) === false))
  18871. res.certReq = this.certReq;
  18872. if (this.extensions) {
  18873. res.extensions = Array.from(this.extensions, o => o.toJSON());
  18874. }
  18875. return res;
  18876. }
  18877. }
  18878. TimeStampReq.CLASS_NAME = "TimeStampReq";
  18879. const STATUS = "status";
  18880. const TIME_STAMP_TOKEN = "timeStampToken";
  18881. const TIME_STAMP_RESP = "TimeStampResp";
  18882. const TIME_STAMP_RESP_STATUS = `${TIME_STAMP_RESP}.${STATUS}`;
  18883. const TIME_STAMP_RESP_TOKEN = `${TIME_STAMP_RESP}.${TIME_STAMP_TOKEN}`;
  18884. const CLEAR_PROPS = [
  18885. TIME_STAMP_RESP_STATUS,
  18886. TIME_STAMP_RESP_TOKEN
  18887. ];
  18888. class TimeStampResp extends PkiObject {
  18889. constructor(parameters = {}) {
  18890. super();
  18891. this.status = pvutils__namespace.getParametersValue(parameters, STATUS, TimeStampResp.defaultValues(STATUS));
  18892. if (TIME_STAMP_TOKEN in parameters) {
  18893. this.timeStampToken = pvutils__namespace.getParametersValue(parameters, TIME_STAMP_TOKEN, TimeStampResp.defaultValues(TIME_STAMP_TOKEN));
  18894. }
  18895. if (parameters.schema) {
  18896. this.fromSchema(parameters.schema);
  18897. }
  18898. }
  18899. static defaultValues(memberName) {
  18900. switch (memberName) {
  18901. case STATUS:
  18902. return new PKIStatusInfo();
  18903. case TIME_STAMP_TOKEN:
  18904. return new ContentInfo();
  18905. default:
  18906. return super.defaultValues(memberName);
  18907. }
  18908. }
  18909. static compareWithDefault(memberName, memberValue) {
  18910. switch (memberName) {
  18911. case STATUS:
  18912. return ((PKIStatusInfo.compareWithDefault(STATUS, memberValue.status)) &&
  18913. (("statusStrings" in memberValue) === false) &&
  18914. (("failInfo" in memberValue) === false));
  18915. case TIME_STAMP_TOKEN:
  18916. return ((memberValue.contentType === EMPTY_STRING) &&
  18917. (memberValue.content instanceof asn1js__namespace.Any));
  18918. default:
  18919. return super.defaultValues(memberName);
  18920. }
  18921. }
  18922. static schema(parameters = {}) {
  18923. const names = pvutils__namespace.getParametersValue(parameters, "names", {});
  18924. return (new asn1js__namespace.Sequence({
  18925. name: (names.blockName || TIME_STAMP_RESP),
  18926. value: [
  18927. PKIStatusInfo.schema(names.status || {
  18928. names: {
  18929. blockName: TIME_STAMP_RESP_STATUS
  18930. }
  18931. }),
  18932. ContentInfo.schema(names.timeStampToken || {
  18933. names: {
  18934. blockName: TIME_STAMP_RESP_TOKEN,
  18935. optional: true
  18936. }
  18937. })
  18938. ]
  18939. }));
  18940. }
  18941. fromSchema(schema) {
  18942. pvutils__namespace.clearProps(schema, CLEAR_PROPS);
  18943. const asn1 = asn1js__namespace.compareSchema(schema, schema, TimeStampResp.schema());
  18944. AsnError.assertSchema(asn1, this.className);
  18945. this.status = new PKIStatusInfo({ schema: asn1.result[TIME_STAMP_RESP_STATUS] });
  18946. if (TIME_STAMP_RESP_TOKEN in asn1.result)
  18947. this.timeStampToken = new ContentInfo({ schema: asn1.result[TIME_STAMP_RESP_TOKEN] });
  18948. }
  18949. toSchema() {
  18950. const outputArray = [];
  18951. outputArray.push(this.status.toSchema());
  18952. if (this.timeStampToken) {
  18953. outputArray.push(this.timeStampToken.toSchema());
  18954. }
  18955. return (new asn1js__namespace.Sequence({
  18956. value: outputArray
  18957. }));
  18958. }
  18959. toJSON() {
  18960. const res = {
  18961. status: this.status.toJSON()
  18962. };
  18963. if (this.timeStampToken) {
  18964. res.timeStampToken = this.timeStampToken.toJSON();
  18965. }
  18966. return res;
  18967. }
  18968. async sign(privateKey, hashAlgorithm, crypto = getCrypto(true)) {
  18969. this.assertContentType();
  18970. const signed = new SignedData({ schema: this.timeStampToken.content });
  18971. return signed.sign(privateKey, 0, hashAlgorithm, undefined, crypto);
  18972. }
  18973. async verify(verificationParameters = { signer: 0, trustedCerts: [], data: EMPTY_BUFFER }, crypto = getCrypto(true)) {
  18974. this.assertContentType();
  18975. const signed = new SignedData({ schema: this.timeStampToken.content });
  18976. return signed.verify(verificationParameters, crypto);
  18977. }
  18978. assertContentType() {
  18979. if (!this.timeStampToken) {
  18980. throw new Error("timeStampToken is absent in TSP response");
  18981. }
  18982. if (this.timeStampToken.contentType !== id_ContentType_SignedData) {
  18983. throw new Error(`Wrong format of timeStampToken: ${this.timeStampToken.contentType}`);
  18984. }
  18985. }
  18986. }
  18987. TimeStampResp.CLASS_NAME = "TimeStampResp";
  18988. function initCryptoEngine() {
  18989. if (typeof globalThis !== "undefined" && "crypto" in globalThis) {
  18990. let engineName = "webcrypto";
  18991. if ("webkitSubtle" in globalThis.crypto) {
  18992. engineName = "safari";
  18993. }
  18994. setEngine(engineName, new CryptoEngine({ name: engineName, crypto: globalThis.crypto }));
  18995. }
  18996. else if (typeof crypto !== "undefined" && "webcrypto" in crypto) {
  18997. const name = "NodeJS ^15";
  18998. const nodeCrypto = crypto.webcrypto;
  18999. setEngine(name, new CryptoEngine({ name, crypto: nodeCrypto }));
  19000. }
  19001. }
  19002. initCryptoEngine();
  19003. exports.AbstractCryptoEngine = AbstractCryptoEngine;
  19004. exports.AccessDescription = AccessDescription;
  19005. exports.Accuracy = Accuracy;
  19006. exports.AlgorithmIdentifier = AlgorithmIdentifier;
  19007. exports.AltName = AltName;
  19008. exports.ArgumentError = ArgumentError;
  19009. exports.AsnError = AsnError;
  19010. exports.AttCertValidityPeriod = AttCertValidityPeriod;
  19011. exports.Attribute = Attribute;
  19012. exports.AttributeCertificateInfoV1 = AttributeCertificateInfoV1;
  19013. exports.AttributeCertificateInfoV2 = AttributeCertificateInfoV2;
  19014. exports.AttributeCertificateV1 = AttributeCertificateV1;
  19015. exports.AttributeCertificateV2 = AttributeCertificateV2;
  19016. exports.AttributeTypeAndValue = AttributeTypeAndValue;
  19017. exports.AuthenticatedSafe = AuthenticatedSafe;
  19018. exports.AuthorityKeyIdentifier = AuthorityKeyIdentifier;
  19019. exports.BasicConstraints = BasicConstraints;
  19020. exports.BasicOCSPResponse = BasicOCSPResponse;
  19021. exports.CAVersion = CAVersion;
  19022. exports.CRLBag = CRLBag;
  19023. exports.CRLDistributionPoints = CRLDistributionPoints;
  19024. exports.CertBag = CertBag;
  19025. exports.CertID = CertID;
  19026. exports.Certificate = Certificate;
  19027. exports.CertificateChainValidationEngine = CertificateChainValidationEngine;
  19028. exports.CertificatePolicies = CertificatePolicies;
  19029. exports.CertificateRevocationList = CertificateRevocationList;
  19030. exports.CertificateSet = CertificateSet;
  19031. exports.CertificateTemplate = CertificateTemplate;
  19032. exports.CertificationRequest = CertificationRequest;
  19033. exports.ChainValidationError = ChainValidationError;
  19034. exports.ContentInfo = ContentInfo;
  19035. exports.CryptoEngine = CryptoEngine;
  19036. exports.DigestInfo = DigestInfo;
  19037. exports.DistributionPoint = DistributionPoint;
  19038. exports.ECCCMSSharedInfo = ECCCMSSharedInfo;
  19039. exports.ECNamedCurves = ECNamedCurves;
  19040. exports.ECPrivateKey = ECPrivateKey;
  19041. exports.ECPublicKey = ECPublicKey;
  19042. exports.EncapsulatedContentInfo = EncapsulatedContentInfo;
  19043. exports.EncryptedContentInfo = EncryptedContentInfo;
  19044. exports.EncryptedData = EncryptedData;
  19045. exports.EnvelopedData = EnvelopedData;
  19046. exports.ExtKeyUsage = ExtKeyUsage;
  19047. exports.Extension = Extension;
  19048. exports.ExtensionValueFactory = ExtensionValueFactory;
  19049. exports.Extensions = Extensions;
  19050. exports.GeneralName = GeneralName;
  19051. exports.GeneralNames = GeneralNames;
  19052. exports.GeneralSubtree = GeneralSubtree;
  19053. exports.HASHED_MESSAGE = HASHED_MESSAGE;
  19054. exports.HASH_ALGORITHM = HASH_ALGORITHM;
  19055. exports.Holder = Holder;
  19056. exports.InfoAccess = InfoAccess;
  19057. exports.IssuerAndSerialNumber = IssuerAndSerialNumber;
  19058. exports.IssuerSerial = IssuerSerial;
  19059. exports.IssuingDistributionPoint = IssuingDistributionPoint;
  19060. exports.KEKIdentifier = KEKIdentifier;
  19061. exports.KEKRecipientInfo = KEKRecipientInfo;
  19062. exports.KeyAgreeRecipientIdentifier = KeyAgreeRecipientIdentifier;
  19063. exports.KeyAgreeRecipientInfo = KeyAgreeRecipientInfo;
  19064. exports.KeyBag = KeyBag;
  19065. exports.KeyTransRecipientInfo = KeyTransRecipientInfo;
  19066. exports.MICROS = MICROS;
  19067. exports.MILLIS = MILLIS;
  19068. exports.MacData = MacData;
  19069. exports.MessageImprint = MessageImprint;
  19070. exports.NameConstraints = NameConstraints;
  19071. exports.OCSPRequest = OCSPRequest;
  19072. exports.OCSPResponse = OCSPResponse;
  19073. exports.ObjectDigestInfo = ObjectDigestInfo;
  19074. exports.OriginatorIdentifierOrKey = OriginatorIdentifierOrKey;
  19075. exports.OriginatorInfo = OriginatorInfo;
  19076. exports.OriginatorPublicKey = OriginatorPublicKey;
  19077. exports.OtherCertificateFormat = OtherCertificateFormat;
  19078. exports.OtherKeyAttribute = OtherKeyAttribute;
  19079. exports.OtherPrimeInfo = OtherPrimeInfo;
  19080. exports.OtherRecipientInfo = OtherRecipientInfo;
  19081. exports.OtherRevocationInfoFormat = OtherRevocationInfoFormat;
  19082. exports.PBES2Params = PBES2Params;
  19083. exports.PBKDF2Params = PBKDF2Params;
  19084. exports.PFX = PFX;
  19085. exports.PKCS8ShroudedKeyBag = PKCS8ShroudedKeyBag;
  19086. exports.PKIStatusInfo = PKIStatusInfo;
  19087. exports.POLICY_IDENTIFIER = POLICY_IDENTIFIER;
  19088. exports.POLICY_QUALIFIERS = POLICY_QUALIFIERS;
  19089. exports.ParameterError = ParameterError;
  19090. exports.PasswordRecipientinfo = PasswordRecipientinfo;
  19091. exports.PkiObject = PkiObject;
  19092. exports.PolicyConstraints = PolicyConstraints;
  19093. exports.PolicyInformation = PolicyInformation;
  19094. exports.PolicyMapping = PolicyMapping;
  19095. exports.PolicyMappings = PolicyMappings;
  19096. exports.PolicyQualifierInfo = PolicyQualifierInfo;
  19097. exports.PrivateKeyInfo = PrivateKeyInfo;
  19098. exports.PrivateKeyUsagePeriod = PrivateKeyUsagePeriod;
  19099. exports.PublicKeyInfo = PublicKeyInfo;
  19100. exports.QCStatement = QCStatement;
  19101. exports.QCStatements = QCStatements;
  19102. exports.RDN = RDN;
  19103. exports.RSAESOAEPParams = RSAESOAEPParams;
  19104. exports.RSAPrivateKey = RSAPrivateKey;
  19105. exports.RSAPublicKey = RSAPublicKey;
  19106. exports.RSASSAPSSParams = RSASSAPSSParams;
  19107. exports.RecipientEncryptedKey = RecipientEncryptedKey;
  19108. exports.RecipientEncryptedKeys = RecipientEncryptedKeys;
  19109. exports.RecipientIdentifier = RecipientIdentifier;
  19110. exports.RecipientInfo = RecipientInfo;
  19111. exports.RecipientKeyIdentifier = RecipientKeyIdentifier;
  19112. exports.RelativeDistinguishedNames = RelativeDistinguishedNames;
  19113. exports.Request = Request;
  19114. exports.ResponseBytes = ResponseBytes;
  19115. exports.ResponseData = ResponseData;
  19116. exports.RevocationInfoChoices = RevocationInfoChoices;
  19117. exports.RevokedCertificate = RevokedCertificate;
  19118. exports.SECONDS = SECONDS;
  19119. exports.SafeBag = SafeBag;
  19120. exports.SafeBagValueFactory = SafeBagValueFactory;
  19121. exports.SafeContents = SafeContents;
  19122. exports.SecretBag = SecretBag;
  19123. exports.Signature = Signature;
  19124. exports.SignedAndUnsignedAttributes = SignedAndUnsignedAttributes;
  19125. exports.SignedCertificateTimestamp = SignedCertificateTimestamp;
  19126. exports.SignedCertificateTimestampList = SignedCertificateTimestampList;
  19127. exports.SignedData = SignedData;
  19128. exports.SignedDataVerifyError = SignedDataVerifyError;
  19129. exports.SignerInfo = SignerInfo;
  19130. exports.SingleResponse = SingleResponse;
  19131. exports.SubjectDirectoryAttributes = SubjectDirectoryAttributes;
  19132. exports.TBSRequest = TBSRequest;
  19133. exports.TSTInfo = TSTInfo;
  19134. exports.TYPE = TYPE$4;
  19135. exports.TYPE_AND_VALUES = TYPE_AND_VALUES;
  19136. exports.Time = Time;
  19137. exports.TimeStampReq = TimeStampReq;
  19138. exports.TimeStampResp = TimeStampResp;
  19139. exports.V2Form = V2Form;
  19140. exports.VALUE = VALUE$5;
  19141. exports.VALUE_BEFORE_DECODE = VALUE_BEFORE_DECODE;
  19142. exports.checkCA = checkCA;
  19143. exports.createCMSECDSASignature = createCMSECDSASignature;
  19144. exports.createECDSASignatureFromCMS = createECDSASignatureFromCMS;
  19145. exports.getAlgorithmByOID = getAlgorithmByOID;
  19146. exports.getAlgorithmParameters = getAlgorithmParameters;
  19147. exports.getCrypto = getCrypto;
  19148. exports.getEngine = getEngine;
  19149. exports.getHashAlgorithm = getHashAlgorithm;
  19150. exports.getOIDByAlgorithm = getOIDByAlgorithm;
  19151. exports.getRandomValues = getRandomValues;
  19152. exports.id_AnyPolicy = id_AnyPolicy;
  19153. exports.id_AuthorityInfoAccess = id_AuthorityInfoAccess;
  19154. exports.id_AuthorityKeyIdentifier = id_AuthorityKeyIdentifier;
  19155. exports.id_BaseCRLNumber = id_BaseCRLNumber;
  19156. exports.id_BasicConstraints = id_BasicConstraints;
  19157. exports.id_CRLBag_X509CRL = id_CRLBag_X509CRL;
  19158. exports.id_CRLDistributionPoints = id_CRLDistributionPoints;
  19159. exports.id_CRLNumber = id_CRLNumber;
  19160. exports.id_CRLReason = id_CRLReason;
  19161. exports.id_CertBag_AttributeCertificate = id_CertBag_AttributeCertificate;
  19162. exports.id_CertBag_SDSICertificate = id_CertBag_SDSICertificate;
  19163. exports.id_CertBag_X509Certificate = id_CertBag_X509Certificate;
  19164. exports.id_CertificateIssuer = id_CertificateIssuer;
  19165. exports.id_CertificatePolicies = id_CertificatePolicies;
  19166. exports.id_ContentType_Data = id_ContentType_Data;
  19167. exports.id_ContentType_EncryptedData = id_ContentType_EncryptedData;
  19168. exports.id_ContentType_EnvelopedData = id_ContentType_EnvelopedData;
  19169. exports.id_ContentType_SignedData = id_ContentType_SignedData;
  19170. exports.id_ExtKeyUsage = id_ExtKeyUsage;
  19171. exports.id_FreshestCRL = id_FreshestCRL;
  19172. exports.id_InhibitAnyPolicy = id_InhibitAnyPolicy;
  19173. exports.id_InvalidityDate = id_InvalidityDate;
  19174. exports.id_IssuerAltName = id_IssuerAltName;
  19175. exports.id_IssuingDistributionPoint = id_IssuingDistributionPoint;
  19176. exports.id_KeyUsage = id_KeyUsage;
  19177. exports.id_MicrosoftAppPolicies = id_MicrosoftAppPolicies;
  19178. exports.id_MicrosoftCaVersion = id_MicrosoftCaVersion;
  19179. exports.id_MicrosoftCertTemplateV1 = id_MicrosoftCertTemplateV1;
  19180. exports.id_MicrosoftCertTemplateV2 = id_MicrosoftCertTemplateV2;
  19181. exports.id_MicrosoftPrevCaCertHash = id_MicrosoftPrevCaCertHash;
  19182. exports.id_NameConstraints = id_NameConstraints;
  19183. exports.id_PKIX_OCSP_Basic = id_PKIX_OCSP_Basic;
  19184. exports.id_PolicyConstraints = id_PolicyConstraints;
  19185. exports.id_PolicyMappings = id_PolicyMappings;
  19186. exports.id_PrivateKeyUsagePeriod = id_PrivateKeyUsagePeriod;
  19187. exports.id_QCStatements = id_QCStatements;
  19188. exports.id_SignedCertificateTimestampList = id_SignedCertificateTimestampList;
  19189. exports.id_SubjectAltName = id_SubjectAltName;
  19190. exports.id_SubjectDirectoryAttributes = id_SubjectDirectoryAttributes;
  19191. exports.id_SubjectInfoAccess = id_SubjectInfoAccess;
  19192. exports.id_SubjectKeyIdentifier = id_SubjectKeyIdentifier;
  19193. exports.id_ad = id_ad;
  19194. exports.id_ad_caIssuers = id_ad_caIssuers;
  19195. exports.id_ad_ocsp = id_ad_ocsp;
  19196. exports.id_eContentType_TSTInfo = id_eContentType_TSTInfo;
  19197. exports.id_pkix = id_pkix;
  19198. exports.id_sha1 = id_sha1;
  19199. exports.id_sha256 = id_sha256;
  19200. exports.id_sha384 = id_sha384;
  19201. exports.id_sha512 = id_sha512;
  19202. exports.kdf = kdf;
  19203. exports.setEngine = setEngine;
  19204. exports.stringPrep = stringPrep;
  19205. exports.verifySCTsForCertificate = verifySCTsForCertificate;