index.es.js 756 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366436743684369437043714372437343744375437643774378437943804381438243834384438543864387438843894390439143924393439443954396439743984399440044014402440344044405440644074408440944104411441244134414441544164417441844194420442144224423442444254426442744284429443044314432443344344435443644374438443944404441444244434444444544464447444844494450445144524453445444554456445744584459446044614462446344644465446644674468446944704471447244734474447544764477447844794480448144824483448444854486448744884489449044914492449344944495449644974498449945004501450245034504450545064507450845094510451145124513451445154516451745184519452045214522452345244525452645274528452945304531453245334534453545364537453845394540454145424543454445454546454745484549455045514552455345544555455645574558455945604561456245634564456545664567456845694570457145724573457445754576457745784579458045814582458345844585458645874588458945904591459245934594459545964597459845994600460146024603460446054606460746084609461046114612461346144615461646174618461946204621462246234624462546264627462846294630463146324633463446354636463746384639464046414642464346444645464646474648464946504651465246534654465546564657465846594660466146624663466446654666466746684669467046714672467346744675467646774678467946804681468246834684468546864687468846894690469146924693469446954696469746984699470047014702470347044705470647074708470947104711471247134714471547164717471847194720472147224723472447254726472747284729473047314732473347344735473647374738473947404741474247434744474547464747474847494750475147524753475447554756475747584759476047614762476347644765476647674768476947704771477247734774477547764777477847794780478147824783478447854786478747884789479047914792479347944795479647974798479948004801480248034804480548064807480848094810481148124813481448154816481748184819482048214822482348244825482648274828482948304831483248334834483548364837483848394840484148424843484448454846484748484849485048514852485348544855485648574858485948604861486248634864486548664867486848694870487148724873487448754876487748784879488048814882488348844885488648874888488948904891489248934894489548964897489848994900490149024903490449054906490749084909491049114912491349144915491649174918491949204921492249234924492549264927492849294930493149324933493449354936493749384939494049414942494349444945494649474948494949504951495249534954495549564957495849594960496149624963496449654966496749684969497049714972497349744975497649774978497949804981498249834984498549864987498849894990499149924993499449954996499749984999500050015002500350045005500650075008500950105011501250135014501550165017501850195020502150225023502450255026502750285029503050315032503350345035503650375038503950405041504250435044504550465047504850495050505150525053505450555056505750585059506050615062506350645065506650675068506950705071507250735074507550765077507850795080508150825083508450855086508750885089509050915092509350945095509650975098509951005101510251035104510551065107510851095110511151125113511451155116511751185119512051215122512351245125512651275128512951305131513251335134513551365137513851395140514151425143514451455146514751485149515051515152515351545155515651575158515951605161516251635164516551665167516851695170517151725173517451755176517751785179518051815182518351845185518651875188518951905191519251935194519551965197519851995200520152025203520452055206520752085209521052115212521352145215521652175218521952205221522252235224522552265227522852295230523152325233523452355236523752385239524052415242524352445245524652475248524952505251525252535254525552565257525852595260526152625263526452655266526752685269527052715272527352745275527652775278527952805281528252835284528552865287528852895290529152925293529452955296529752985299530053015302530353045305530653075308530953105311531253135314531553165317531853195320532153225323532453255326532753285329533053315332533353345335533653375338533953405341534253435344534553465347534853495350535153525353535453555356535753585359536053615362536353645365536653675368536953705371537253735374537553765377537853795380538153825383538453855386538753885389539053915392539353945395539653975398539954005401540254035404540554065407540854095410541154125413541454155416541754185419542054215422542354245425542654275428542954305431543254335434543554365437543854395440544154425443544454455446544754485449545054515452545354545455545654575458545954605461546254635464546554665467546854695470547154725473547454755476547754785479548054815482548354845485548654875488548954905491549254935494549554965497549854995500550155025503550455055506550755085509551055115512551355145515551655175518551955205521552255235524552555265527552855295530553155325533553455355536553755385539554055415542554355445545554655475548554955505551555255535554555555565557555855595560556155625563556455655566556755685569557055715572557355745575557655775578557955805581558255835584558555865587558855895590559155925593559455955596559755985599560056015602560356045605560656075608560956105611561256135614561556165617561856195620562156225623562456255626562756285629563056315632563356345635563656375638563956405641564256435644564556465647564856495650565156525653565456555656565756585659566056615662566356645665566656675668566956705671567256735674567556765677567856795680568156825683568456855686568756885689569056915692569356945695569656975698569957005701570257035704570557065707570857095710571157125713571457155716571757185719572057215722572357245725572657275728572957305731573257335734573557365737573857395740574157425743574457455746574757485749575057515752575357545755575657575758575957605761576257635764576557665767576857695770577157725773577457755776577757785779578057815782578357845785578657875788578957905791579257935794579557965797579857995800580158025803580458055806580758085809581058115812581358145815581658175818581958205821582258235824582558265827582858295830583158325833583458355836583758385839584058415842584358445845584658475848584958505851585258535854585558565857585858595860586158625863586458655866586758685869587058715872587358745875587658775878587958805881588258835884588558865887588858895890589158925893589458955896589758985899590059015902590359045905590659075908590959105911591259135914591559165917591859195920592159225923592459255926592759285929593059315932593359345935593659375938593959405941594259435944594559465947594859495950595159525953595459555956595759585959596059615962596359645965596659675968596959705971597259735974597559765977597859795980598159825983598459855986598759885989599059915992599359945995599659975998599960006001600260036004600560066007600860096010601160126013601460156016601760186019602060216022602360246025602660276028602960306031603260336034603560366037603860396040604160426043604460456046604760486049605060516052605360546055605660576058605960606061606260636064606560666067606860696070607160726073607460756076607760786079608060816082608360846085608660876088608960906091609260936094609560966097609860996100610161026103610461056106610761086109611061116112611361146115611661176118611961206121612261236124612561266127612861296130613161326133613461356136613761386139614061416142614361446145614661476148614961506151615261536154615561566157615861596160616161626163616461656166616761686169617061716172617361746175617661776178617961806181618261836184618561866187618861896190619161926193619461956196619761986199620062016202620362046205620662076208620962106211621262136214621562166217621862196220622162226223622462256226622762286229623062316232623362346235623662376238623962406241624262436244624562466247624862496250625162526253625462556256625762586259626062616262626362646265626662676268626962706271627262736274627562766277627862796280628162826283628462856286628762886289629062916292629362946295629662976298629963006301630263036304630563066307630863096310631163126313631463156316631763186319632063216322632363246325632663276328632963306331633263336334633563366337633863396340634163426343634463456346634763486349635063516352635363546355635663576358635963606361636263636364636563666367636863696370637163726373637463756376637763786379638063816382638363846385638663876388638963906391639263936394639563966397639863996400640164026403640464056406640764086409641064116412641364146415641664176418641964206421642264236424642564266427642864296430643164326433643464356436643764386439644064416442644364446445644664476448644964506451645264536454645564566457645864596460646164626463646464656466646764686469647064716472647364746475647664776478647964806481648264836484648564866487648864896490649164926493649464956496649764986499650065016502650365046505650665076508650965106511651265136514651565166517651865196520652165226523652465256526652765286529653065316532653365346535653665376538653965406541654265436544654565466547654865496550655165526553655465556556655765586559656065616562656365646565656665676568656965706571657265736574657565766577657865796580658165826583658465856586658765886589659065916592659365946595659665976598659966006601660266036604660566066607660866096610661166126613661466156616661766186619662066216622662366246625662666276628662966306631663266336634663566366637663866396640664166426643664466456646664766486649665066516652665366546655665666576658665966606661666266636664666566666667666866696670667166726673667466756676667766786679668066816682668366846685668666876688668966906691669266936694669566966697669866996700670167026703670467056706670767086709671067116712671367146715671667176718671967206721672267236724672567266727672867296730673167326733673467356736673767386739674067416742674367446745674667476748674967506751675267536754675567566757675867596760676167626763676467656766676767686769677067716772677367746775677667776778677967806781678267836784678567866787678867896790679167926793679467956796679767986799680068016802680368046805680668076808680968106811681268136814681568166817681868196820682168226823682468256826682768286829683068316832683368346835683668376838683968406841684268436844684568466847684868496850685168526853685468556856685768586859686068616862686368646865686668676868686968706871687268736874687568766877687868796880688168826883688468856886688768886889689068916892689368946895689668976898689969006901690269036904690569066907690869096910691169126913691469156916691769186919692069216922692369246925692669276928692969306931693269336934693569366937693869396940694169426943694469456946694769486949695069516952695369546955695669576958695969606961696269636964696569666967696869696970697169726973697469756976697769786979698069816982698369846985698669876988698969906991699269936994699569966997699869997000700170027003700470057006700770087009701070117012701370147015701670177018701970207021702270237024702570267027702870297030703170327033703470357036703770387039704070417042704370447045704670477048704970507051705270537054705570567057705870597060706170627063706470657066706770687069707070717072707370747075707670777078707970807081708270837084708570867087708870897090709170927093709470957096709770987099710071017102710371047105710671077108710971107111711271137114711571167117711871197120712171227123712471257126712771287129713071317132713371347135713671377138713971407141714271437144714571467147714871497150715171527153715471557156715771587159716071617162716371647165716671677168716971707171717271737174717571767177717871797180718171827183718471857186718771887189719071917192719371947195719671977198719972007201720272037204720572067207720872097210721172127213721472157216721772187219722072217222722372247225722672277228722972307231723272337234723572367237723872397240724172427243724472457246724772487249725072517252725372547255725672577258725972607261726272637264726572667267726872697270727172727273727472757276727772787279728072817282728372847285728672877288728972907291729272937294729572967297729872997300730173027303730473057306730773087309731073117312731373147315731673177318731973207321732273237324732573267327732873297330733173327333733473357336733773387339734073417342734373447345734673477348734973507351735273537354735573567357735873597360736173627363736473657366736773687369737073717372737373747375737673777378737973807381738273837384738573867387738873897390739173927393739473957396739773987399740074017402740374047405740674077408740974107411741274137414741574167417741874197420742174227423742474257426742774287429743074317432743374347435743674377438743974407441744274437444744574467447744874497450745174527453745474557456745774587459746074617462746374647465746674677468746974707471747274737474747574767477747874797480748174827483748474857486748774887489749074917492749374947495749674977498749975007501750275037504750575067507750875097510751175127513751475157516751775187519752075217522752375247525752675277528752975307531753275337534753575367537753875397540754175427543754475457546754775487549755075517552755375547555755675577558755975607561756275637564756575667567756875697570757175727573757475757576757775787579758075817582758375847585758675877588758975907591759275937594759575967597759875997600760176027603760476057606760776087609761076117612761376147615761676177618761976207621762276237624762576267627762876297630763176327633763476357636763776387639764076417642764376447645764676477648764976507651765276537654765576567657765876597660766176627663766476657666766776687669767076717672767376747675767676777678767976807681768276837684768576867687768876897690769176927693769476957696769776987699770077017702770377047705770677077708770977107711771277137714771577167717771877197720772177227723772477257726772777287729773077317732773377347735773677377738773977407741774277437744774577467747774877497750775177527753775477557756775777587759776077617762776377647765776677677768776977707771777277737774777577767777777877797780778177827783778477857786778777887789779077917792779377947795779677977798779978007801780278037804780578067807780878097810781178127813781478157816781778187819782078217822782378247825782678277828782978307831783278337834783578367837783878397840784178427843784478457846784778487849785078517852785378547855785678577858785978607861786278637864786578667867786878697870787178727873787478757876787778787879788078817882788378847885788678877888788978907891789278937894789578967897789878997900790179027903790479057906790779087909791079117912791379147915791679177918791979207921792279237924792579267927792879297930793179327933793479357936793779387939794079417942794379447945794679477948794979507951795279537954795579567957795879597960796179627963796479657966796779687969797079717972797379747975797679777978797979807981798279837984798579867987798879897990799179927993799479957996799779987999800080018002800380048005800680078008800980108011801280138014801580168017801880198020802180228023802480258026802780288029803080318032803380348035803680378038803980408041804280438044804580468047804880498050805180528053805480558056805780588059806080618062806380648065806680678068806980708071807280738074807580768077807880798080808180828083808480858086808780888089809080918092809380948095809680978098809981008101810281038104810581068107810881098110811181128113811481158116811781188119812081218122812381248125812681278128812981308131813281338134813581368137813881398140814181428143814481458146814781488149815081518152815381548155815681578158815981608161816281638164816581668167816881698170817181728173817481758176817781788179818081818182818381848185818681878188818981908191819281938194819581968197819881998200820182028203820482058206820782088209821082118212821382148215821682178218821982208221822282238224822582268227822882298230823182328233823482358236823782388239824082418242824382448245824682478248824982508251825282538254825582568257825882598260826182628263826482658266826782688269827082718272827382748275827682778278827982808281828282838284828582868287828882898290829182928293829482958296829782988299830083018302830383048305830683078308830983108311831283138314831583168317831883198320832183228323832483258326832783288329833083318332833383348335833683378338833983408341834283438344834583468347834883498350835183528353835483558356835783588359836083618362836383648365836683678368836983708371837283738374837583768377837883798380838183828383838483858386838783888389839083918392839383948395839683978398839984008401840284038404840584068407840884098410841184128413841484158416841784188419842084218422842384248425842684278428842984308431843284338434843584368437843884398440844184428443844484458446844784488449845084518452845384548455845684578458845984608461846284638464846584668467846884698470847184728473847484758476847784788479848084818482848384848485848684878488848984908491849284938494849584968497849884998500850185028503850485058506850785088509851085118512851385148515851685178518851985208521852285238524852585268527852885298530853185328533853485358536853785388539854085418542854385448545854685478548854985508551855285538554855585568557855885598560856185628563856485658566856785688569857085718572857385748575857685778578857985808581858285838584858585868587858885898590859185928593859485958596859785988599860086018602860386048605860686078608860986108611861286138614861586168617861886198620862186228623862486258626862786288629863086318632863386348635863686378638863986408641864286438644864586468647864886498650865186528653865486558656865786588659866086618662866386648665866686678668866986708671867286738674867586768677867886798680868186828683868486858686868786888689869086918692869386948695869686978698869987008701870287038704870587068707870887098710871187128713871487158716871787188719872087218722872387248725872687278728872987308731873287338734873587368737873887398740874187428743874487458746874787488749875087518752875387548755875687578758875987608761876287638764876587668767876887698770877187728773877487758776877787788779878087818782878387848785878687878788878987908791879287938794879587968797879887998800880188028803880488058806880788088809881088118812881388148815881688178818881988208821882288238824882588268827882888298830883188328833883488358836883788388839884088418842884388448845884688478848884988508851885288538854885588568857885888598860886188628863886488658866886788688869887088718872887388748875887688778878887988808881888288838884888588868887888888898890889188928893889488958896889788988899890089018902890389048905890689078908890989108911891289138914891589168917891889198920892189228923892489258926892789288929893089318932893389348935893689378938893989408941894289438944894589468947894889498950895189528953895489558956895789588959896089618962896389648965896689678968896989708971897289738974897589768977897889798980898189828983898489858986898789888989899089918992899389948995899689978998899990009001900290039004900590069007900890099010901190129013901490159016901790189019902090219022902390249025902690279028902990309031903290339034903590369037903890399040904190429043904490459046904790489049905090519052905390549055905690579058905990609061906290639064906590669067906890699070907190729073907490759076907790789079908090819082908390849085908690879088908990909091909290939094909590969097909890999100910191029103910491059106910791089109911091119112911391149115911691179118911991209121912291239124912591269127912891299130913191329133913491359136913791389139914091419142914391449145914691479148914991509151915291539154915591569157915891599160916191629163916491659166916791689169917091719172917391749175917691779178917991809181918291839184918591869187918891899190919191929193919491959196919791989199920092019202920392049205920692079208920992109211921292139214921592169217921892199220922192229223922492259226922792289229923092319232923392349235923692379238923992409241924292439244924592469247924892499250925192529253925492559256925792589259926092619262926392649265926692679268926992709271927292739274927592769277927892799280928192829283928492859286928792889289929092919292929392949295929692979298929993009301930293039304930593069307930893099310931193129313931493159316931793189319932093219322932393249325932693279328932993309331933293339334933593369337933893399340934193429343934493459346934793489349935093519352935393549355935693579358935993609361936293639364936593669367936893699370937193729373937493759376937793789379938093819382938393849385938693879388938993909391939293939394939593969397939893999400940194029403940494059406940794089409941094119412941394149415941694179418941994209421942294239424942594269427942894299430943194329433943494359436943794389439944094419442944394449445944694479448944994509451945294539454945594569457945894599460946194629463946494659466946794689469947094719472947394749475947694779478947994809481948294839484948594869487948894899490949194929493949494959496949794989499950095019502950395049505950695079508950995109511951295139514951595169517951895199520952195229523952495259526952795289529953095319532953395349535953695379538953995409541954295439544954595469547954895499550955195529553955495559556955795589559956095619562956395649565956695679568956995709571957295739574957595769577957895799580958195829583958495859586958795889589959095919592959395949595959695979598959996009601960296039604960596069607960896099610961196129613961496159616961796189619962096219622962396249625962696279628962996309631963296339634963596369637963896399640964196429643964496459646964796489649965096519652965396549655965696579658965996609661966296639664966596669667966896699670967196729673967496759676967796789679968096819682968396849685968696879688968996909691969296939694969596969697969896999700970197029703970497059706970797089709971097119712971397149715971697179718971997209721972297239724972597269727972897299730973197329733973497359736973797389739974097419742974397449745974697479748974997509751975297539754975597569757975897599760976197629763976497659766976797689769977097719772977397749775977697779778977997809781978297839784978597869787978897899790979197929793979497959796979797989799980098019802980398049805980698079808980998109811981298139814981598169817981898199820982198229823982498259826982798289829983098319832983398349835983698379838983998409841984298439844984598469847984898499850985198529853985498559856985798589859986098619862986398649865986698679868986998709871987298739874987598769877987898799880988198829883988498859886988798889889989098919892989398949895989698979898989999009901990299039904990599069907990899099910991199129913991499159916991799189919992099219922992399249925992699279928992999309931993299339934993599369937993899399940994199429943994499459946994799489949995099519952995399549955995699579958995999609961996299639964996599669967996899699970997199729973997499759976997799789979998099819982998399849985998699879988998999909991999299939994999599969997999899991000010001100021000310004100051000610007100081000910010100111001210013100141001510016100171001810019100201002110022100231002410025100261002710028100291003010031100321003310034100351003610037100381003910040100411004210043100441004510046100471004810049100501005110052100531005410055100561005710058100591006010061100621006310064100651006610067100681006910070100711007210073100741007510076100771007810079100801008110082100831008410085100861008710088100891009010091100921009310094100951009610097100981009910100101011010210103101041010510106101071010810109101101011110112101131011410115101161011710118101191012010121101221012310124101251012610127101281012910130101311013210133101341013510136101371013810139101401014110142101431014410145101461014710148101491015010151101521015310154101551015610157101581015910160101611016210163101641016510166101671016810169101701017110172101731017410175101761017710178101791018010181101821018310184101851018610187101881018910190101911019210193101941019510196101971019810199102001020110202102031020410205102061020710208102091021010211102121021310214102151021610217102181021910220102211022210223102241022510226102271022810229102301023110232102331023410235102361023710238102391024010241102421024310244102451024610247102481024910250102511025210253102541025510256102571025810259102601026110262102631026410265102661026710268102691027010271102721027310274102751027610277102781027910280102811028210283102841028510286102871028810289102901029110292102931029410295102961029710298102991030010301103021030310304103051030610307103081030910310103111031210313103141031510316103171031810319103201032110322103231032410325103261032710328103291033010331103321033310334103351033610337103381033910340103411034210343103441034510346103471034810349103501035110352103531035410355103561035710358103591036010361103621036310364103651036610367103681036910370103711037210373103741037510376103771037810379103801038110382103831038410385103861038710388103891039010391103921039310394103951039610397103981039910400104011040210403104041040510406104071040810409104101041110412104131041410415104161041710418104191042010421104221042310424104251042610427104281042910430104311043210433104341043510436104371043810439104401044110442104431044410445104461044710448104491045010451104521045310454104551045610457104581045910460104611046210463104641046510466104671046810469104701047110472104731047410475104761047710478104791048010481104821048310484104851048610487104881048910490104911049210493104941049510496104971049810499105001050110502105031050410505105061050710508105091051010511105121051310514105151051610517105181051910520105211052210523105241052510526105271052810529105301053110532105331053410535105361053710538105391054010541105421054310544105451054610547105481054910550105511055210553105541055510556105571055810559105601056110562105631056410565105661056710568105691057010571105721057310574105751057610577105781057910580105811058210583105841058510586105871058810589105901059110592105931059410595105961059710598105991060010601106021060310604106051060610607106081060910610106111061210613106141061510616106171061810619106201062110622106231062410625106261062710628106291063010631106321063310634106351063610637106381063910640106411064210643106441064510646106471064810649106501065110652106531065410655106561065710658106591066010661106621066310664106651066610667106681066910670106711067210673106741067510676106771067810679106801068110682106831068410685106861068710688106891069010691106921069310694106951069610697106981069910700107011070210703107041070510706107071070810709107101071110712107131071410715107161071710718107191072010721107221072310724107251072610727107281072910730107311073210733107341073510736107371073810739107401074110742107431074410745107461074710748107491075010751107521075310754107551075610757107581075910760107611076210763107641076510766107671076810769107701077110772107731077410775107761077710778107791078010781107821078310784107851078610787107881078910790107911079210793107941079510796107971079810799108001080110802108031080410805108061080710808108091081010811108121081310814108151081610817108181081910820108211082210823108241082510826108271082810829108301083110832108331083410835108361083710838108391084010841108421084310844108451084610847108481084910850108511085210853108541085510856108571085810859108601086110862108631086410865108661086710868108691087010871108721087310874108751087610877108781087910880108811088210883108841088510886108871088810889108901089110892108931089410895108961089710898108991090010901109021090310904109051090610907109081090910910109111091210913109141091510916109171091810919109201092110922109231092410925109261092710928109291093010931109321093310934109351093610937109381093910940109411094210943109441094510946109471094810949109501095110952109531095410955109561095710958109591096010961109621096310964109651096610967109681096910970109711097210973109741097510976109771097810979109801098110982109831098410985109861098710988109891099010991109921099310994109951099610997109981099911000110011100211003110041100511006110071100811009110101101111012110131101411015110161101711018110191102011021110221102311024110251102611027110281102911030110311103211033110341103511036110371103811039110401104111042110431104411045110461104711048110491105011051110521105311054110551105611057110581105911060110611106211063110641106511066110671106811069110701107111072110731107411075110761107711078110791108011081110821108311084110851108611087110881108911090110911109211093110941109511096110971109811099111001110111102111031110411105111061110711108111091111011111111121111311114111151111611117111181111911120111211112211123111241112511126111271112811129111301113111132111331113411135111361113711138111391114011141111421114311144111451114611147111481114911150111511115211153111541115511156111571115811159111601116111162111631116411165111661116711168111691117011171111721117311174111751117611177111781117911180111811118211183111841118511186111871118811189111901119111192111931119411195111961119711198111991120011201112021120311204112051120611207112081120911210112111121211213112141121511216112171121811219112201122111222112231122411225112261122711228112291123011231112321123311234112351123611237112381123911240112411124211243112441124511246112471124811249112501125111252112531125411255112561125711258112591126011261112621126311264112651126611267112681126911270112711127211273112741127511276112771127811279112801128111282112831128411285112861128711288112891129011291112921129311294112951129611297112981129911300113011130211303113041130511306113071130811309113101131111312113131131411315113161131711318113191132011321113221132311324113251132611327113281132911330113311133211333113341133511336113371133811339113401134111342113431134411345113461134711348113491135011351113521135311354113551135611357113581135911360113611136211363113641136511366113671136811369113701137111372113731137411375113761137711378113791138011381113821138311384113851138611387113881138911390113911139211393113941139511396113971139811399114001140111402114031140411405114061140711408114091141011411114121141311414114151141611417114181141911420114211142211423114241142511426114271142811429114301143111432114331143411435114361143711438114391144011441114421144311444114451144611447114481144911450114511145211453114541145511456114571145811459114601146111462114631146411465114661146711468114691147011471114721147311474114751147611477114781147911480114811148211483114841148511486114871148811489114901149111492114931149411495114961149711498114991150011501115021150311504115051150611507115081150911510115111151211513115141151511516115171151811519115201152111522115231152411525115261152711528115291153011531115321153311534115351153611537115381153911540115411154211543115441154511546115471154811549115501155111552115531155411555115561155711558115591156011561115621156311564115651156611567115681156911570115711157211573115741157511576115771157811579115801158111582115831158411585115861158711588115891159011591115921159311594115951159611597115981159911600116011160211603116041160511606116071160811609116101161111612116131161411615116161161711618116191162011621116221162311624116251162611627116281162911630116311163211633116341163511636116371163811639116401164111642116431164411645116461164711648116491165011651116521165311654116551165611657116581165911660116611166211663116641166511666116671166811669116701167111672116731167411675116761167711678116791168011681116821168311684116851168611687116881168911690116911169211693116941169511696116971169811699117001170111702117031170411705117061170711708117091171011711117121171311714117151171611717117181171911720117211172211723117241172511726117271172811729117301173111732117331173411735117361173711738117391174011741117421174311744117451174611747117481174911750117511175211753117541175511756117571175811759117601176111762117631176411765117661176711768117691177011771117721177311774117751177611777117781177911780117811178211783117841178511786117871178811789117901179111792117931179411795117961179711798117991180011801118021180311804118051180611807118081180911810118111181211813118141181511816118171181811819118201182111822118231182411825118261182711828118291183011831118321183311834118351183611837118381183911840118411184211843118441184511846118471184811849118501185111852118531185411855118561185711858118591186011861118621186311864118651186611867118681186911870118711187211873118741187511876118771187811879118801188111882118831188411885118861188711888118891189011891118921189311894118951189611897118981189911900119011190211903119041190511906119071190811909119101191111912119131191411915119161191711918119191192011921119221192311924119251192611927119281192911930119311193211933119341193511936119371193811939119401194111942119431194411945119461194711948119491195011951119521195311954119551195611957119581195911960119611196211963119641196511966119671196811969119701197111972119731197411975119761197711978119791198011981119821198311984119851198611987119881198911990119911199211993119941199511996119971199811999120001200112002120031200412005120061200712008120091201012011120121201312014120151201612017120181201912020120211202212023120241202512026120271202812029120301203112032120331203412035120361203712038120391204012041120421204312044120451204612047120481204912050120511205212053120541205512056120571205812059120601206112062120631206412065120661206712068120691207012071120721207312074120751207612077120781207912080120811208212083120841208512086120871208812089120901209112092120931209412095120961209712098120991210012101121021210312104121051210612107121081210912110121111211212113121141211512116121171211812119121201212112122121231212412125121261212712128121291213012131121321213312134121351213612137121381213912140121411214212143121441214512146121471214812149121501215112152121531215412155121561215712158121591216012161121621216312164121651216612167121681216912170121711217212173121741217512176121771217812179121801218112182121831218412185121861218712188121891219012191121921219312194121951219612197121981219912200122011220212203122041220512206122071220812209122101221112212122131221412215122161221712218122191222012221122221222312224122251222612227122281222912230122311223212233122341223512236122371223812239122401224112242122431224412245122461224712248122491225012251122521225312254122551225612257122581225912260122611226212263122641226512266122671226812269122701227112272122731227412275122761227712278122791228012281122821228312284122851228612287122881228912290122911229212293122941229512296122971229812299123001230112302123031230412305123061230712308123091231012311123121231312314123151231612317123181231912320123211232212323123241232512326123271232812329123301233112332123331233412335123361233712338123391234012341123421234312344123451234612347123481234912350123511235212353123541235512356123571235812359123601236112362123631236412365123661236712368123691237012371123721237312374123751237612377123781237912380123811238212383123841238512386123871238812389123901239112392123931239412395123961239712398123991240012401124021240312404124051240612407124081240912410124111241212413124141241512416124171241812419124201242112422124231242412425124261242712428124291243012431124321243312434124351243612437124381243912440124411244212443124441244512446124471244812449124501245112452124531245412455124561245712458124591246012461124621246312464124651246612467124681246912470124711247212473124741247512476124771247812479124801248112482124831248412485124861248712488124891249012491124921249312494124951249612497124981249912500125011250212503125041250512506125071250812509125101251112512125131251412515125161251712518125191252012521125221252312524125251252612527125281252912530125311253212533125341253512536125371253812539125401254112542125431254412545125461254712548125491255012551125521255312554125551255612557125581255912560125611256212563125641256512566125671256812569125701257112572125731257412575125761257712578125791258012581125821258312584125851258612587125881258912590125911259212593125941259512596125971259812599126001260112602126031260412605126061260712608126091261012611126121261312614126151261612617126181261912620126211262212623126241262512626126271262812629126301263112632126331263412635126361263712638126391264012641126421264312644126451264612647126481264912650126511265212653126541265512656126571265812659126601266112662126631266412665126661266712668126691267012671126721267312674126751267612677126781267912680126811268212683126841268512686126871268812689126901269112692126931269412695126961269712698126991270012701127021270312704127051270612707127081270912710127111271212713127141271512716127171271812719127201272112722127231272412725127261272712728127291273012731127321273312734127351273612737127381273912740127411274212743127441274512746127471274812749127501275112752127531275412755127561275712758127591276012761127621276312764127651276612767127681276912770127711277212773127741277512776127771277812779127801278112782127831278412785127861278712788127891279012791127921279312794127951279612797127981279912800128011280212803128041280512806128071280812809128101281112812128131281412815128161281712818128191282012821128221282312824128251282612827128281282912830128311283212833128341283512836128371283812839128401284112842128431284412845128461284712848128491285012851128521285312854128551285612857128581285912860128611286212863128641286512866128671286812869128701287112872128731287412875128761287712878128791288012881128821288312884128851288612887128881288912890128911289212893128941289512896128971289812899129001290112902129031290412905129061290712908129091291012911129121291312914129151291612917129181291912920129211292212923129241292512926129271292812929129301293112932129331293412935129361293712938129391294012941129421294312944129451294612947129481294912950129511295212953129541295512956129571295812959129601296112962129631296412965129661296712968129691297012971129721297312974129751297612977129781297912980129811298212983129841298512986129871298812989129901299112992129931299412995129961299712998129991300013001130021300313004130051300613007130081300913010130111301213013130141301513016130171301813019130201302113022130231302413025130261302713028130291303013031130321303313034130351303613037130381303913040130411304213043130441304513046130471304813049130501305113052130531305413055130561305713058130591306013061130621306313064130651306613067130681306913070130711307213073130741307513076130771307813079130801308113082130831308413085130861308713088130891309013091130921309313094130951309613097130981309913100131011310213103131041310513106131071310813109131101311113112131131311413115131161311713118131191312013121131221312313124131251312613127131281312913130131311313213133131341313513136131371313813139131401314113142131431314413145131461314713148131491315013151131521315313154131551315613157131581315913160131611316213163131641316513166131671316813169131701317113172131731317413175131761317713178131791318013181131821318313184131851318613187131881318913190131911319213193131941319513196131971319813199132001320113202132031320413205132061320713208132091321013211132121321313214132151321613217132181321913220132211322213223132241322513226132271322813229132301323113232132331323413235132361323713238132391324013241132421324313244132451324613247132481324913250132511325213253132541325513256132571325813259132601326113262132631326413265132661326713268132691327013271132721327313274132751327613277132781327913280132811328213283132841328513286132871328813289132901329113292132931329413295132961329713298132991330013301133021330313304133051330613307133081330913310133111331213313133141331513316133171331813319133201332113322133231332413325133261332713328133291333013331133321333313334133351333613337133381333913340133411334213343133441334513346133471334813349133501335113352133531335413355133561335713358133591336013361133621336313364133651336613367133681336913370133711337213373133741337513376133771337813379133801338113382133831338413385133861338713388133891339013391133921339313394133951339613397133981339913400134011340213403134041340513406134071340813409134101341113412134131341413415134161341713418134191342013421134221342313424134251342613427134281342913430134311343213433134341343513436134371343813439134401344113442134431344413445134461344713448134491345013451134521345313454134551345613457134581345913460134611346213463134641346513466134671346813469134701347113472134731347413475134761347713478134791348013481134821348313484134851348613487134881348913490134911349213493134941349513496134971349813499135001350113502135031350413505135061350713508135091351013511135121351313514135151351613517135181351913520135211352213523135241352513526135271352813529135301353113532135331353413535135361353713538135391354013541135421354313544135451354613547135481354913550135511355213553135541355513556135571355813559135601356113562135631356413565135661356713568135691357013571135721357313574135751357613577135781357913580135811358213583135841358513586135871358813589135901359113592135931359413595135961359713598135991360013601136021360313604136051360613607136081360913610136111361213613136141361513616136171361813619136201362113622136231362413625136261362713628136291363013631136321363313634136351363613637136381363913640136411364213643136441364513646136471364813649136501365113652136531365413655136561365713658136591366013661136621366313664136651366613667136681366913670136711367213673136741367513676136771367813679136801368113682136831368413685136861368713688136891369013691136921369313694136951369613697136981369913700137011370213703137041370513706137071370813709137101371113712137131371413715137161371713718137191372013721137221372313724137251372613727137281372913730137311373213733137341373513736137371373813739137401374113742137431374413745137461374713748137491375013751137521375313754137551375613757137581375913760137611376213763137641376513766137671376813769137701377113772137731377413775137761377713778137791378013781137821378313784137851378613787137881378913790137911379213793137941379513796137971379813799138001380113802138031380413805138061380713808138091381013811138121381313814138151381613817138181381913820138211382213823138241382513826138271382813829138301383113832138331383413835138361383713838138391384013841138421384313844138451384613847138481384913850138511385213853138541385513856138571385813859138601386113862138631386413865138661386713868138691387013871138721387313874138751387613877138781387913880138811388213883138841388513886138871388813889138901389113892138931389413895138961389713898138991390013901139021390313904139051390613907139081390913910139111391213913139141391513916139171391813919139201392113922139231392413925139261392713928139291393013931139321393313934139351393613937139381393913940139411394213943139441394513946139471394813949139501395113952139531395413955139561395713958139591396013961139621396313964139651396613967139681396913970139711397213973139741397513976139771397813979139801398113982139831398413985139861398713988139891399013991139921399313994139951399613997139981399914000140011400214003140041400514006140071400814009140101401114012140131401414015140161401714018140191402014021140221402314024140251402614027140281402914030140311403214033140341403514036140371403814039140401404114042140431404414045140461404714048140491405014051140521405314054140551405614057140581405914060140611406214063140641406514066140671406814069140701407114072140731407414075140761407714078140791408014081140821408314084140851408614087140881408914090140911409214093140941409514096140971409814099141001410114102141031410414105141061410714108141091411014111141121411314114141151411614117141181411914120141211412214123141241412514126141271412814129141301413114132141331413414135141361413714138141391414014141141421414314144141451414614147141481414914150141511415214153141541415514156141571415814159141601416114162141631416414165141661416714168141691417014171141721417314174141751417614177141781417914180141811418214183141841418514186141871418814189141901419114192141931419414195141961419714198141991420014201142021420314204142051420614207142081420914210142111421214213142141421514216142171421814219142201422114222142231422414225142261422714228142291423014231142321423314234142351423614237142381423914240142411424214243142441424514246142471424814249142501425114252142531425414255142561425714258142591426014261142621426314264142651426614267142681426914270142711427214273142741427514276142771427814279142801428114282142831428414285142861428714288142891429014291142921429314294142951429614297142981429914300143011430214303143041430514306143071430814309143101431114312143131431414315143161431714318143191432014321143221432314324143251432614327143281432914330143311433214333143341433514336143371433814339143401434114342143431434414345143461434714348143491435014351143521435314354143551435614357143581435914360143611436214363143641436514366143671436814369143701437114372143731437414375143761437714378143791438014381143821438314384143851438614387143881438914390143911439214393143941439514396143971439814399144001440114402144031440414405144061440714408144091441014411144121441314414144151441614417144181441914420144211442214423144241442514426144271442814429144301443114432144331443414435144361443714438144391444014441144421444314444144451444614447144481444914450144511445214453144541445514456144571445814459144601446114462144631446414465144661446714468144691447014471144721447314474144751447614477144781447914480144811448214483144841448514486144871448814489144901449114492144931449414495144961449714498144991450014501145021450314504145051450614507145081450914510145111451214513145141451514516145171451814519145201452114522145231452414525145261452714528145291453014531145321453314534145351453614537145381453914540145411454214543145441454514546145471454814549145501455114552145531455414555145561455714558145591456014561145621456314564145651456614567145681456914570145711457214573145741457514576145771457814579145801458114582145831458414585145861458714588145891459014591145921459314594145951459614597145981459914600146011460214603146041460514606146071460814609146101461114612146131461414615146161461714618146191462014621146221462314624146251462614627146281462914630146311463214633146341463514636146371463814639146401464114642146431464414645146461464714648146491465014651146521465314654146551465614657146581465914660146611466214663146641466514666146671466814669146701467114672146731467414675146761467714678146791468014681146821468314684146851468614687146881468914690146911469214693146941469514696146971469814699147001470114702147031470414705147061470714708147091471014711147121471314714147151471614717147181471914720147211472214723147241472514726147271472814729147301473114732147331473414735147361473714738147391474014741147421474314744147451474614747147481474914750147511475214753147541475514756147571475814759147601476114762147631476414765147661476714768147691477014771147721477314774147751477614777147781477914780147811478214783147841478514786147871478814789147901479114792147931479414795147961479714798147991480014801148021480314804148051480614807148081480914810148111481214813148141481514816148171481814819148201482114822148231482414825148261482714828148291483014831148321483314834148351483614837148381483914840148411484214843148441484514846148471484814849148501485114852148531485414855148561485714858148591486014861148621486314864148651486614867148681486914870148711487214873148741487514876148771487814879148801488114882148831488414885148861488714888148891489014891148921489314894148951489614897148981489914900149011490214903149041490514906149071490814909149101491114912149131491414915149161491714918149191492014921149221492314924149251492614927149281492914930149311493214933149341493514936149371493814939149401494114942149431494414945149461494714948149491495014951149521495314954149551495614957149581495914960149611496214963149641496514966149671496814969149701497114972149731497414975149761497714978149791498014981149821498314984149851498614987149881498914990149911499214993149941499514996149971499814999150001500115002150031500415005150061500715008150091501015011150121501315014150151501615017150181501915020150211502215023150241502515026150271502815029150301503115032150331503415035150361503715038150391504015041150421504315044150451504615047150481504915050150511505215053150541505515056150571505815059150601506115062150631506415065150661506715068150691507015071150721507315074150751507615077150781507915080150811508215083150841508515086150871508815089150901509115092150931509415095150961509715098150991510015101151021510315104151051510615107151081510915110151111511215113151141511515116151171511815119151201512115122151231512415125151261512715128151291513015131151321513315134151351513615137151381513915140151411514215143151441514515146151471514815149151501515115152151531515415155151561515715158151591516015161151621516315164151651516615167151681516915170151711517215173151741517515176151771517815179151801518115182151831518415185151861518715188151891519015191151921519315194151951519615197151981519915200152011520215203152041520515206152071520815209152101521115212152131521415215152161521715218152191522015221152221522315224152251522615227152281522915230152311523215233152341523515236152371523815239152401524115242152431524415245152461524715248152491525015251152521525315254152551525615257152581525915260152611526215263152641526515266152671526815269152701527115272152731527415275152761527715278152791528015281152821528315284152851528615287152881528915290152911529215293152941529515296152971529815299153001530115302153031530415305153061530715308153091531015311153121531315314153151531615317153181531915320153211532215323153241532515326153271532815329153301533115332153331533415335153361533715338153391534015341153421534315344153451534615347153481534915350153511535215353153541535515356153571535815359153601536115362153631536415365153661536715368153691537015371153721537315374153751537615377153781537915380153811538215383153841538515386153871538815389153901539115392153931539415395153961539715398153991540015401154021540315404154051540615407154081540915410154111541215413154141541515416154171541815419154201542115422154231542415425154261542715428154291543015431154321543315434154351543615437154381543915440154411544215443154441544515446154471544815449154501545115452154531545415455154561545715458154591546015461154621546315464154651546615467154681546915470154711547215473154741547515476154771547815479154801548115482154831548415485154861548715488154891549015491154921549315494154951549615497154981549915500155011550215503155041550515506155071550815509155101551115512155131551415515155161551715518155191552015521155221552315524155251552615527155281552915530155311553215533155341553515536155371553815539155401554115542155431554415545155461554715548155491555015551155521555315554155551555615557155581555915560155611556215563155641556515566155671556815569155701557115572155731557415575155761557715578155791558015581155821558315584155851558615587155881558915590155911559215593155941559515596155971559815599156001560115602156031560415605156061560715608156091561015611156121561315614156151561615617156181561915620156211562215623156241562515626156271562815629156301563115632156331563415635156361563715638156391564015641156421564315644156451564615647156481564915650156511565215653156541565515656156571565815659156601566115662156631566415665156661566715668156691567015671156721567315674156751567615677156781567915680156811568215683156841568515686156871568815689156901569115692156931569415695156961569715698156991570015701157021570315704157051570615707157081570915710157111571215713157141571515716157171571815719157201572115722157231572415725157261572715728157291573015731157321573315734157351573615737157381573915740157411574215743157441574515746157471574815749157501575115752157531575415755157561575715758157591576015761157621576315764157651576615767157681576915770157711577215773157741577515776157771577815779157801578115782157831578415785157861578715788157891579015791157921579315794157951579615797157981579915800158011580215803158041580515806158071580815809158101581115812158131581415815158161581715818158191582015821158221582315824158251582615827158281582915830158311583215833158341583515836158371583815839158401584115842158431584415845158461584715848158491585015851158521585315854158551585615857158581585915860158611586215863158641586515866158671586815869158701587115872158731587415875158761587715878158791588015881158821588315884158851588615887158881588915890158911589215893158941589515896158971589815899159001590115902159031590415905159061590715908159091591015911159121591315914159151591615917159181591915920159211592215923159241592515926159271592815929159301593115932159331593415935159361593715938159391594015941159421594315944159451594615947159481594915950159511595215953159541595515956159571595815959159601596115962159631596415965159661596715968159691597015971159721597315974159751597615977159781597915980159811598215983159841598515986159871598815989159901599115992159931599415995159961599715998159991600016001160021600316004160051600616007160081600916010160111601216013160141601516016160171601816019160201602116022160231602416025160261602716028160291603016031160321603316034160351603616037160381603916040160411604216043160441604516046160471604816049160501605116052160531605416055160561605716058160591606016061160621606316064160651606616067160681606916070160711607216073160741607516076160771607816079160801608116082160831608416085160861608716088160891609016091160921609316094160951609616097160981609916100161011610216103161041610516106161071610816109161101611116112161131611416115161161611716118161191612016121161221612316124161251612616127161281612916130161311613216133161341613516136161371613816139161401614116142161431614416145161461614716148161491615016151161521615316154161551615616157161581615916160161611616216163161641616516166161671616816169161701617116172161731617416175161761617716178161791618016181161821618316184161851618616187161881618916190161911619216193161941619516196161971619816199162001620116202162031620416205162061620716208162091621016211162121621316214162151621616217162181621916220162211622216223162241622516226162271622816229162301623116232162331623416235162361623716238162391624016241162421624316244162451624616247162481624916250162511625216253162541625516256162571625816259162601626116262162631626416265162661626716268162691627016271162721627316274162751627616277162781627916280162811628216283162841628516286162871628816289162901629116292162931629416295162961629716298162991630016301163021630316304163051630616307163081630916310163111631216313163141631516316163171631816319163201632116322163231632416325163261632716328163291633016331163321633316334163351633616337163381633916340163411634216343163441634516346163471634816349163501635116352163531635416355163561635716358163591636016361163621636316364163651636616367163681636916370163711637216373163741637516376163771637816379163801638116382163831638416385163861638716388163891639016391163921639316394163951639616397163981639916400164011640216403164041640516406164071640816409164101641116412164131641416415164161641716418164191642016421164221642316424164251642616427164281642916430164311643216433164341643516436164371643816439164401644116442164431644416445164461644716448164491645016451164521645316454164551645616457164581645916460164611646216463164641646516466164671646816469164701647116472164731647416475164761647716478164791648016481164821648316484164851648616487164881648916490164911649216493164941649516496164971649816499165001650116502165031650416505165061650716508165091651016511165121651316514165151651616517165181651916520165211652216523165241652516526165271652816529165301653116532165331653416535165361653716538165391654016541165421654316544165451654616547165481654916550165511655216553165541655516556165571655816559165601656116562165631656416565165661656716568165691657016571165721657316574165751657616577165781657916580165811658216583165841658516586165871658816589165901659116592165931659416595165961659716598165991660016601166021660316604166051660616607166081660916610166111661216613166141661516616166171661816619166201662116622166231662416625166261662716628166291663016631166321663316634166351663616637166381663916640166411664216643166441664516646166471664816649166501665116652166531665416655166561665716658166591666016661166621666316664166651666616667166681666916670166711667216673166741667516676166771667816679166801668116682166831668416685166861668716688166891669016691166921669316694166951669616697166981669916700167011670216703167041670516706167071670816709167101671116712167131671416715167161671716718167191672016721167221672316724167251672616727167281672916730167311673216733167341673516736167371673816739167401674116742167431674416745167461674716748167491675016751167521675316754167551675616757167581675916760167611676216763167641676516766167671676816769167701677116772167731677416775167761677716778167791678016781167821678316784167851678616787167881678916790167911679216793167941679516796167971679816799168001680116802168031680416805168061680716808168091681016811168121681316814168151681616817168181681916820168211682216823168241682516826168271682816829168301683116832168331683416835168361683716838168391684016841168421684316844168451684616847168481684916850168511685216853168541685516856168571685816859168601686116862168631686416865168661686716868168691687016871168721687316874168751687616877168781687916880168811688216883168841688516886168871688816889168901689116892168931689416895168961689716898168991690016901169021690316904169051690616907169081690916910169111691216913169141691516916169171691816919169201692116922169231692416925169261692716928169291693016931169321693316934169351693616937169381693916940169411694216943169441694516946169471694816949169501695116952169531695416955169561695716958169591696016961169621696316964169651696616967169681696916970169711697216973169741697516976169771697816979169801698116982169831698416985169861698716988169891699016991169921699316994169951699616997169981699917000170011700217003170041700517006170071700817009170101701117012170131701417015170161701717018170191702017021170221702317024170251702617027170281702917030170311703217033170341703517036170371703817039170401704117042170431704417045170461704717048170491705017051170521705317054170551705617057170581705917060170611706217063170641706517066170671706817069170701707117072170731707417075170761707717078170791708017081170821708317084170851708617087170881708917090170911709217093170941709517096170971709817099171001710117102171031710417105171061710717108171091711017111171121711317114171151711617117171181711917120171211712217123171241712517126171271712817129171301713117132171331713417135171361713717138171391714017141171421714317144171451714617147171481714917150171511715217153171541715517156171571715817159171601716117162171631716417165171661716717168171691717017171171721717317174171751717617177171781717917180171811718217183171841718517186171871718817189171901719117192171931719417195171961719717198171991720017201172021720317204172051720617207172081720917210172111721217213172141721517216172171721817219172201722117222172231722417225172261722717228172291723017231172321723317234172351723617237172381723917240172411724217243172441724517246172471724817249172501725117252172531725417255172561725717258172591726017261172621726317264172651726617267172681726917270172711727217273172741727517276172771727817279172801728117282172831728417285172861728717288172891729017291172921729317294172951729617297172981729917300173011730217303173041730517306173071730817309173101731117312173131731417315173161731717318173191732017321173221732317324173251732617327173281732917330173311733217333173341733517336173371733817339173401734117342173431734417345173461734717348173491735017351173521735317354173551735617357173581735917360173611736217363173641736517366173671736817369173701737117372173731737417375173761737717378173791738017381173821738317384173851738617387173881738917390173911739217393173941739517396173971739817399174001740117402174031740417405174061740717408174091741017411174121741317414174151741617417174181741917420174211742217423174241742517426174271742817429174301743117432174331743417435174361743717438174391744017441174421744317444174451744617447174481744917450174511745217453174541745517456174571745817459174601746117462174631746417465174661746717468174691747017471174721747317474174751747617477174781747917480174811748217483174841748517486174871748817489174901749117492174931749417495174961749717498174991750017501175021750317504175051750617507175081750917510175111751217513175141751517516175171751817519175201752117522175231752417525175261752717528175291753017531175321753317534175351753617537175381753917540175411754217543175441754517546175471754817549175501755117552175531755417555175561755717558175591756017561175621756317564175651756617567175681756917570175711757217573175741757517576175771757817579175801758117582175831758417585175861758717588175891759017591175921759317594175951759617597175981759917600176011760217603176041760517606176071760817609176101761117612176131761417615176161761717618176191762017621176221762317624176251762617627176281762917630176311763217633176341763517636176371763817639176401764117642176431764417645176461764717648176491765017651176521765317654176551765617657176581765917660176611766217663176641766517666176671766817669176701767117672176731767417675176761767717678176791768017681176821768317684176851768617687176881768917690176911769217693176941769517696176971769817699177001770117702177031770417705177061770717708177091771017711177121771317714177151771617717177181771917720177211772217723177241772517726177271772817729177301773117732177331773417735177361773717738177391774017741177421774317744177451774617747177481774917750177511775217753177541775517756177571775817759177601776117762177631776417765177661776717768177691777017771177721777317774177751777617777177781777917780177811778217783177841778517786177871778817789177901779117792177931779417795177961779717798177991780017801178021780317804178051780617807178081780917810178111781217813178141781517816178171781817819178201782117822178231782417825178261782717828178291783017831178321783317834178351783617837178381783917840178411784217843178441784517846178471784817849178501785117852178531785417855178561785717858178591786017861178621786317864178651786617867178681786917870178711787217873178741787517876178771787817879178801788117882178831788417885178861788717888178891789017891178921789317894178951789617897178981789917900179011790217903179041790517906179071790817909179101791117912179131791417915179161791717918179191792017921179221792317924179251792617927179281792917930179311793217933179341793517936179371793817939179401794117942179431794417945179461794717948179491795017951179521795317954179551795617957179581795917960179611796217963179641796517966179671796817969179701797117972179731797417975179761797717978179791798017981179821798317984179851798617987179881798917990179911799217993179941799517996179971799817999180001800118002180031800418005180061800718008180091801018011180121801318014180151801618017180181801918020180211802218023180241802518026180271802818029180301803118032180331803418035180361803718038180391804018041180421804318044180451804618047180481804918050180511805218053180541805518056180571805818059180601806118062180631806418065180661806718068180691807018071180721807318074180751807618077180781807918080180811808218083180841808518086180871808818089180901809118092180931809418095180961809718098180991810018101181021810318104181051810618107181081810918110181111811218113181141811518116181171811818119181201812118122181231812418125181261812718128181291813018131181321813318134181351813618137181381813918140181411814218143181441814518146181471814818149181501815118152181531815418155181561815718158181591816018161181621816318164181651816618167181681816918170181711817218173181741817518176181771817818179181801818118182181831818418185181861818718188181891819018191181921819318194181951819618197181981819918200182011820218203182041820518206182071820818209182101821118212182131821418215182161821718218182191822018221182221822318224182251822618227182281822918230182311823218233182341823518236182371823818239182401824118242182431824418245182461824718248182491825018251182521825318254182551825618257182581825918260182611826218263182641826518266182671826818269182701827118272182731827418275182761827718278182791828018281182821828318284182851828618287182881828918290182911829218293182941829518296182971829818299183001830118302183031830418305183061830718308183091831018311183121831318314183151831618317183181831918320183211832218323183241832518326183271832818329183301833118332183331833418335183361833718338183391834018341183421834318344183451834618347183481834918350183511835218353183541835518356183571835818359183601836118362183631836418365183661836718368183691837018371183721837318374183751837618377183781837918380183811838218383183841838518386183871838818389183901839118392183931839418395183961839718398183991840018401184021840318404184051840618407184081840918410184111841218413184141841518416184171841818419184201842118422184231842418425184261842718428184291843018431184321843318434184351843618437184381843918440184411844218443184441844518446184471844818449184501845118452184531845418455184561845718458184591846018461184621846318464184651846618467184681846918470184711847218473184741847518476184771847818479184801848118482184831848418485184861848718488184891849018491184921849318494184951849618497184981849918500185011850218503185041850518506185071850818509185101851118512185131851418515185161851718518185191852018521185221852318524185251852618527185281852918530185311853218533185341853518536185371853818539185401854118542185431854418545185461854718548185491855018551185521855318554185551855618557185581855918560185611856218563185641856518566185671856818569185701857118572185731857418575185761857718578185791858018581185821858318584185851858618587185881858918590185911859218593185941859518596185971859818599186001860118602186031860418605186061860718608186091861018611186121861318614186151861618617186181861918620186211862218623186241862518626186271862818629186301863118632186331863418635186361863718638186391864018641186421864318644186451864618647186481864918650186511865218653186541865518656186571865818659186601866118662186631866418665186661866718668186691867018671186721867318674186751867618677186781867918680186811868218683186841868518686186871868818689186901869118692186931869418695186961869718698186991870018701187021870318704187051870618707187081870918710187111871218713187141871518716187171871818719187201872118722187231872418725187261872718728187291873018731187321873318734187351873618737187381873918740187411874218743187441874518746187471874818749187501875118752187531875418755187561875718758187591876018761187621876318764187651876618767187681876918770187711877218773187741877518776187771877818779187801878118782187831878418785187861878718788187891879018791187921879318794187951879618797187981879918800188011880218803188041880518806188071880818809188101881118812188131881418815188161881718818188191882018821188221882318824188251882618827188281882918830188311883218833188341883518836188371883818839188401884118842188431884418845188461884718848188491885018851188521885318854188551885618857188581885918860188611886218863188641886518866188671886818869188701887118872188731887418875188761887718878188791888018881188821888318884188851888618887188881888918890188911889218893188941889518896188971889818899189001890118902189031890418905189061890718908189091891018911189121891318914189151891618917189181891918920189211892218923189241892518926189271892818929189301893118932189331893418935189361893718938189391894018941189421894318944189451894618947189481894918950189511895218953189541895518956189571895818959189601896118962189631896418965189661896718968189691897018971189721897318974189751897618977189781897918980189811898218983189841898518986189871898818989189901899118992189931899418995189961899718998189991900019001190021900319004190051900619007190081900919010190111901219013190141901519016190171901819019190201902119022190231902419025190261902719028190291903019031190321903319034190351903619037190381903919040190411904219043190441904519046190471904819049190501905119052190531905419055190561905719058190591906019061190621906319064190651906619067190681906919070190711907219073190741907519076190771907819079190801908119082190831908419085190861908719088190891909019091190921909319094190951909619097190981909919100191011910219103191041910519106
  1. /*!
  2. * Copyright (c) 2014, GlobalSign
  3. * Copyright (c) 2015-2019, Peculiar Ventures
  4. * All rights reserved.
  5. *
  6. * Author 2014-2019, Yury Strozhevsky
  7. *
  8. * Redistribution and use in source and binary forms, with or without modification,
  9. * are permitted provided that the following conditions are met:
  10. *
  11. * * Redistributions of source code must retain the above copyright notice, this
  12. * list of conditions and the following disclaimer.
  13. *
  14. * * Redistributions in binary form must reproduce the above copyright notice, this
  15. * list of conditions and the following disclaimer in the documentation and/or
  16. * other materials provided with the distribution.
  17. *
  18. * * Neither the name of the {organization} nor the names of its
  19. * contributors may be used to endorse or promote products derived from
  20. * this software without specific prior written permission.
  21. *
  22. * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND
  23. * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
  24. * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE
  25. * DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR
  26. * ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
  27. * (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  28. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON
  29. * ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
  30. * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS
  31. * SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  32. *
  33. */
  34. import * as asn1js from 'asn1js';
  35. import * as pvtsutils from 'pvtsutils';
  36. import { BufferSourceConverter } from 'pvtsutils';
  37. import * as pvutils from 'pvutils';
  38. import * as bs from 'bytestreamjs';
  39. import { sha1 } from '@noble/hashes/sha1';
  40. import { sha512, sha384, sha256 } from '@noble/hashes/sha2';
  41. const EMPTY_BUFFER = new ArrayBuffer(0);
  42. const EMPTY_STRING = "";
  43. class ArgumentError extends TypeError {
  44. constructor() {
  45. super(...arguments);
  46. this.name = ArgumentError.NAME;
  47. }
  48. static isType(value, type) {
  49. if (typeof type === "string") {
  50. if (type === "Array" && Array.isArray(value)) {
  51. return true;
  52. }
  53. else if (type === "ArrayBuffer" && value instanceof ArrayBuffer) {
  54. return true;
  55. }
  56. else if (type === "ArrayBufferView" && ArrayBuffer.isView(value)) {
  57. return true;
  58. }
  59. else if (typeof value === type) {
  60. return true;
  61. }
  62. }
  63. else if (value instanceof type) {
  64. return true;
  65. }
  66. return false;
  67. }
  68. static assert(value, name, ...types) {
  69. for (const type of types) {
  70. if (this.isType(value, type)) {
  71. return;
  72. }
  73. }
  74. const typeNames = types.map(o => o instanceof Function && "name" in o ? o.name : `${o}`);
  75. throw new ArgumentError(`Parameter '${name}' is not of type ${typeNames.length > 1 ? `(${typeNames.join(" or ")})` : typeNames[0]}`);
  76. }
  77. }
  78. ArgumentError.NAME = "ArgumentError";
  79. class ParameterError extends TypeError {
  80. static assert(...args) {
  81. let target = null;
  82. let params;
  83. let fields;
  84. if (typeof args[0] === "string") {
  85. target = args[0];
  86. params = args[1];
  87. fields = args.slice(2);
  88. }
  89. else {
  90. params = args[0];
  91. fields = args.slice(1);
  92. }
  93. ArgumentError.assert(params, "parameters", "object");
  94. for (const field of fields) {
  95. const value = params[field];
  96. if (value === undefined || value === null) {
  97. throw new ParameterError(field, target);
  98. }
  99. }
  100. }
  101. static assertEmpty(value, name, target) {
  102. if (value === undefined || value === null) {
  103. throw new ParameterError(name, target);
  104. }
  105. }
  106. constructor(field, target = null, message) {
  107. super();
  108. this.name = ParameterError.NAME;
  109. this.field = field;
  110. if (target) {
  111. this.target = target;
  112. }
  113. if (message) {
  114. this.message = message;
  115. }
  116. else {
  117. this.message = `Absent mandatory parameter '${field}' ${target ? ` in '${target}'` : EMPTY_STRING}`;
  118. }
  119. }
  120. }
  121. ParameterError.NAME = "ParameterError";
  122. class AsnError extends Error {
  123. static assertSchema(asn1, target) {
  124. if (!asn1.verified) {
  125. throw new Error(`Object's schema was not verified against input data for ${target}`);
  126. }
  127. }
  128. static assert(asn, target) {
  129. if (asn.offset === -1) {
  130. throw new AsnError(`Error during parsing of ASN.1 data. Data is not correct for '${target}'.`);
  131. }
  132. }
  133. constructor(message) {
  134. super(message);
  135. this.name = "AsnError";
  136. }
  137. }
  138. class PkiObject {
  139. static blockName() {
  140. return this.CLASS_NAME;
  141. }
  142. static fromBER(raw) {
  143. const asn1 = asn1js.fromBER(raw);
  144. AsnError.assert(asn1, this.name);
  145. try {
  146. return new this({ schema: asn1.result });
  147. }
  148. catch (e) {
  149. throw new AsnError(`Cannot create '${this.CLASS_NAME}' from ASN.1 object`);
  150. }
  151. }
  152. static defaultValues(memberName) {
  153. throw new Error(`Invalid member name for ${this.CLASS_NAME} class: ${memberName}`);
  154. }
  155. static schema(parameters = {}) {
  156. throw new Error(`Method '${this.CLASS_NAME}.schema' should be overridden`);
  157. }
  158. get className() {
  159. return this.constructor.CLASS_NAME;
  160. }
  161. toString(encoding = "hex") {
  162. let schema;
  163. try {
  164. schema = this.toSchema();
  165. }
  166. catch {
  167. schema = this.toSchema(true);
  168. }
  169. return pvtsutils.Convert.ToString(schema.toBER(), encoding);
  170. }
  171. }
  172. PkiObject.CLASS_NAME = "PkiObject";
  173. function stringPrep(inputString) {
  174. let isSpace = false;
  175. let cutResult = EMPTY_STRING;
  176. const result = inputString.trim();
  177. for (let i = 0; i < result.length; i++) {
  178. if (result.charCodeAt(i) === 32) {
  179. if (isSpace === false)
  180. isSpace = true;
  181. }
  182. else {
  183. if (isSpace) {
  184. cutResult += " ";
  185. isSpace = false;
  186. }
  187. cutResult += result[i];
  188. }
  189. }
  190. return cutResult.toLowerCase();
  191. }
  192. const TYPE$5 = "type";
  193. const VALUE$6 = "value";
  194. class AttributeTypeAndValue extends PkiObject {
  195. constructor(parameters = {}) {
  196. super();
  197. this.type = pvutils.getParametersValue(parameters, TYPE$5, AttributeTypeAndValue.defaultValues(TYPE$5));
  198. this.value = pvutils.getParametersValue(parameters, VALUE$6, AttributeTypeAndValue.defaultValues(VALUE$6));
  199. if (parameters.schema) {
  200. this.fromSchema(parameters.schema);
  201. }
  202. }
  203. static defaultValues(memberName) {
  204. switch (memberName) {
  205. case TYPE$5:
  206. return EMPTY_STRING;
  207. case VALUE$6:
  208. return {};
  209. default:
  210. return super.defaultValues(memberName);
  211. }
  212. }
  213. static schema(parameters = {}) {
  214. const names = pvutils.getParametersValue(parameters, "names", {});
  215. return (new asn1js.Sequence({
  216. name: (names.blockName || EMPTY_STRING),
  217. value: [
  218. new asn1js.ObjectIdentifier({ name: (names.type || EMPTY_STRING) }),
  219. new asn1js.Any({ name: (names.value || EMPTY_STRING) })
  220. ]
  221. }));
  222. }
  223. fromSchema(schema) {
  224. pvutils.clearProps(schema, [
  225. TYPE$5,
  226. "typeValue"
  227. ]);
  228. const asn1 = asn1js.compareSchema(schema, schema, AttributeTypeAndValue.schema({
  229. names: {
  230. type: TYPE$5,
  231. value: "typeValue"
  232. }
  233. }));
  234. AsnError.assertSchema(asn1, this.className);
  235. this.type = asn1.result.type.valueBlock.toString();
  236. this.value = asn1.result.typeValue;
  237. }
  238. toSchema() {
  239. return (new asn1js.Sequence({
  240. value: [
  241. new asn1js.ObjectIdentifier({ value: this.type }),
  242. this.value
  243. ]
  244. }));
  245. }
  246. toJSON() {
  247. const _object = {
  248. type: this.type
  249. };
  250. if (Object.keys(this.value).length !== 0) {
  251. _object.value = (this.value).toJSON();
  252. }
  253. else {
  254. _object.value = this.value;
  255. }
  256. return _object;
  257. }
  258. isEqual(compareTo) {
  259. const stringBlockNames = [
  260. asn1js.Utf8String.blockName(),
  261. asn1js.BmpString.blockName(),
  262. asn1js.UniversalString.blockName(),
  263. asn1js.NumericString.blockName(),
  264. asn1js.PrintableString.blockName(),
  265. asn1js.TeletexString.blockName(),
  266. asn1js.VideotexString.blockName(),
  267. asn1js.IA5String.blockName(),
  268. asn1js.GraphicString.blockName(),
  269. asn1js.VisibleString.blockName(),
  270. asn1js.GeneralString.blockName(),
  271. asn1js.CharacterString.blockName()
  272. ];
  273. if (compareTo instanceof ArrayBuffer) {
  274. return pvtsutils.BufferSourceConverter.isEqual(this.value.valueBeforeDecodeView, compareTo);
  275. }
  276. if (compareTo.constructor.blockName() === AttributeTypeAndValue.blockName()) {
  277. if (this.type !== compareTo.type)
  278. return false;
  279. const isStringPair = [false, false];
  280. const thisName = this.value.constructor.blockName();
  281. for (const name of stringBlockNames) {
  282. if (thisName === name) {
  283. isStringPair[0] = true;
  284. }
  285. if (compareTo.value.constructor.blockName() === name) {
  286. isStringPair[1] = true;
  287. }
  288. }
  289. if (isStringPair[0] !== isStringPair[1]) {
  290. return false;
  291. }
  292. const isString = (isStringPair[0] && isStringPair[1]);
  293. if (isString) {
  294. const value1 = stringPrep(this.value.valueBlock.value);
  295. const value2 = stringPrep(compareTo.value.valueBlock.value);
  296. if (value1.localeCompare(value2) !== 0)
  297. return false;
  298. }
  299. else {
  300. if (!pvtsutils.BufferSourceConverter.isEqual(this.value.valueBeforeDecodeView, compareTo.value.valueBeforeDecodeView))
  301. return false;
  302. }
  303. return true;
  304. }
  305. return false;
  306. }
  307. }
  308. AttributeTypeAndValue.CLASS_NAME = "AttributeTypeAndValue";
  309. const TYPE_AND_VALUES = "typesAndValues";
  310. const VALUE_BEFORE_DECODE = "valueBeforeDecode";
  311. const RDN = "RDN";
  312. class RelativeDistinguishedNames extends PkiObject {
  313. constructor(parameters = {}) {
  314. super();
  315. this.typesAndValues = pvutils.getParametersValue(parameters, TYPE_AND_VALUES, RelativeDistinguishedNames.defaultValues(TYPE_AND_VALUES));
  316. this.valueBeforeDecode = pvutils.getParametersValue(parameters, VALUE_BEFORE_DECODE, RelativeDistinguishedNames.defaultValues(VALUE_BEFORE_DECODE));
  317. if (parameters.schema) {
  318. this.fromSchema(parameters.schema);
  319. }
  320. }
  321. static defaultValues(memberName) {
  322. switch (memberName) {
  323. case TYPE_AND_VALUES:
  324. return [];
  325. case VALUE_BEFORE_DECODE:
  326. return EMPTY_BUFFER;
  327. default:
  328. return super.defaultValues(memberName);
  329. }
  330. }
  331. static compareWithDefault(memberName, memberValue) {
  332. switch (memberName) {
  333. case TYPE_AND_VALUES:
  334. return (memberValue.length === 0);
  335. case VALUE_BEFORE_DECODE:
  336. return (memberValue.byteLength === 0);
  337. default:
  338. return super.defaultValues(memberName);
  339. }
  340. }
  341. static schema(parameters = {}) {
  342. const names = pvutils.getParametersValue(parameters, "names", {});
  343. return (new asn1js.Sequence({
  344. name: (names.blockName || EMPTY_STRING),
  345. value: [
  346. new asn1js.Repeated({
  347. name: (names.repeatedSequence || EMPTY_STRING),
  348. value: new asn1js.Set({
  349. value: [
  350. new asn1js.Repeated({
  351. name: (names.repeatedSet || EMPTY_STRING),
  352. value: AttributeTypeAndValue.schema(names.typeAndValue || {})
  353. })
  354. ]
  355. })
  356. })
  357. ]
  358. }));
  359. }
  360. fromSchema(schema) {
  361. pvutils.clearProps(schema, [
  362. RDN,
  363. TYPE_AND_VALUES
  364. ]);
  365. const asn1 = asn1js.compareSchema(schema, schema, RelativeDistinguishedNames.schema({
  366. names: {
  367. blockName: RDN,
  368. repeatedSet: TYPE_AND_VALUES
  369. }
  370. }));
  371. AsnError.assertSchema(asn1, this.className);
  372. if (TYPE_AND_VALUES in asn1.result) {
  373. this.typesAndValues = Array.from(asn1.result.typesAndValues, element => new AttributeTypeAndValue({ schema: element }));
  374. }
  375. this.valueBeforeDecode = asn1.result.RDN.valueBeforeDecodeView.slice().buffer;
  376. }
  377. toSchema() {
  378. if (this.valueBeforeDecode.byteLength === 0) {
  379. return (new asn1js.Sequence({
  380. value: [new asn1js.Set({
  381. value: Array.from(this.typesAndValues, o => o.toSchema())
  382. })]
  383. }));
  384. }
  385. const asn1 = asn1js.fromBER(this.valueBeforeDecode);
  386. AsnError.assert(asn1, "RelativeDistinguishedNames");
  387. if (!(asn1.result instanceof asn1js.Sequence)) {
  388. throw new Error("ASN.1 result should be SEQUENCE");
  389. }
  390. return asn1.result;
  391. }
  392. toJSON() {
  393. return {
  394. typesAndValues: Array.from(this.typesAndValues, o => o.toJSON())
  395. };
  396. }
  397. isEqual(compareTo) {
  398. if (compareTo instanceof RelativeDistinguishedNames) {
  399. if (this.typesAndValues.length !== compareTo.typesAndValues.length)
  400. return false;
  401. for (const [index, typeAndValue] of this.typesAndValues.entries()) {
  402. if (typeAndValue.isEqual(compareTo.typesAndValues[index]) === false)
  403. return false;
  404. }
  405. return true;
  406. }
  407. if (compareTo instanceof ArrayBuffer) {
  408. return pvutils.isEqualBuffer(this.valueBeforeDecode, compareTo);
  409. }
  410. return false;
  411. }
  412. }
  413. RelativeDistinguishedNames.CLASS_NAME = "RelativeDistinguishedNames";
  414. const TYPE$4 = "type";
  415. const VALUE$5 = "value";
  416. function builtInStandardAttributes(parameters = {}, optional = false) {
  417. const names = pvutils.getParametersValue(parameters, "names", {});
  418. return (new asn1js.Sequence({
  419. optional,
  420. value: [
  421. new asn1js.Constructed({
  422. optional: true,
  423. idBlock: {
  424. tagClass: 2,
  425. tagNumber: 1
  426. },
  427. name: (names.country_name || EMPTY_STRING),
  428. value: [
  429. new asn1js.Choice({
  430. value: [
  431. new asn1js.NumericString(),
  432. new asn1js.PrintableString()
  433. ]
  434. })
  435. ]
  436. }),
  437. new asn1js.Constructed({
  438. optional: true,
  439. idBlock: {
  440. tagClass: 2,
  441. tagNumber: 2
  442. },
  443. name: (names.administration_domain_name || EMPTY_STRING),
  444. value: [
  445. new asn1js.Choice({
  446. value: [
  447. new asn1js.NumericString(),
  448. new asn1js.PrintableString()
  449. ]
  450. })
  451. ]
  452. }),
  453. new asn1js.Primitive({
  454. optional: true,
  455. idBlock: {
  456. tagClass: 3,
  457. tagNumber: 0
  458. },
  459. name: (names.network_address || EMPTY_STRING),
  460. isHexOnly: true
  461. }),
  462. new asn1js.Primitive({
  463. optional: true,
  464. idBlock: {
  465. tagClass: 3,
  466. tagNumber: 1
  467. },
  468. name: (names.terminal_identifier || EMPTY_STRING),
  469. isHexOnly: true
  470. }),
  471. new asn1js.Constructed({
  472. optional: true,
  473. idBlock: {
  474. tagClass: 3,
  475. tagNumber: 2
  476. },
  477. name: (names.private_domain_name || EMPTY_STRING),
  478. value: [
  479. new asn1js.Choice({
  480. value: [
  481. new asn1js.NumericString(),
  482. new asn1js.PrintableString()
  483. ]
  484. })
  485. ]
  486. }),
  487. new asn1js.Primitive({
  488. optional: true,
  489. idBlock: {
  490. tagClass: 3,
  491. tagNumber: 3
  492. },
  493. name: (names.organization_name || EMPTY_STRING),
  494. isHexOnly: true
  495. }),
  496. new asn1js.Primitive({
  497. optional: true,
  498. name: (names.numeric_user_identifier || EMPTY_STRING),
  499. idBlock: {
  500. tagClass: 3,
  501. tagNumber: 4
  502. },
  503. isHexOnly: true
  504. }),
  505. new asn1js.Constructed({
  506. optional: true,
  507. name: (names.personal_name || EMPTY_STRING),
  508. idBlock: {
  509. tagClass: 3,
  510. tagNumber: 5
  511. },
  512. value: [
  513. new asn1js.Primitive({
  514. idBlock: {
  515. tagClass: 3,
  516. tagNumber: 0
  517. },
  518. isHexOnly: true
  519. }),
  520. new asn1js.Primitive({
  521. optional: true,
  522. idBlock: {
  523. tagClass: 3,
  524. tagNumber: 1
  525. },
  526. isHexOnly: true
  527. }),
  528. new asn1js.Primitive({
  529. optional: true,
  530. idBlock: {
  531. tagClass: 3,
  532. tagNumber: 2
  533. },
  534. isHexOnly: true
  535. }),
  536. new asn1js.Primitive({
  537. optional: true,
  538. idBlock: {
  539. tagClass: 3,
  540. tagNumber: 3
  541. },
  542. isHexOnly: true
  543. })
  544. ]
  545. }),
  546. new asn1js.Constructed({
  547. optional: true,
  548. name: (names.organizational_unit_names || EMPTY_STRING),
  549. idBlock: {
  550. tagClass: 3,
  551. tagNumber: 6
  552. },
  553. value: [
  554. new asn1js.Repeated({
  555. value: new asn1js.PrintableString()
  556. })
  557. ]
  558. })
  559. ]
  560. }));
  561. }
  562. function builtInDomainDefinedAttributes(optional = false) {
  563. return (new asn1js.Sequence({
  564. optional,
  565. value: [
  566. new asn1js.PrintableString(),
  567. new asn1js.PrintableString()
  568. ]
  569. }));
  570. }
  571. function extensionAttributes(optional = false) {
  572. return (new asn1js.Set({
  573. optional,
  574. value: [
  575. new asn1js.Primitive({
  576. optional: true,
  577. idBlock: {
  578. tagClass: 3,
  579. tagNumber: 0
  580. },
  581. isHexOnly: true
  582. }),
  583. new asn1js.Constructed({
  584. optional: true,
  585. idBlock: {
  586. tagClass: 3,
  587. tagNumber: 1
  588. },
  589. value: [new asn1js.Any()]
  590. })
  591. ]
  592. }));
  593. }
  594. class GeneralName extends PkiObject {
  595. constructor(parameters = {}) {
  596. super();
  597. this.type = pvutils.getParametersValue(parameters, TYPE$4, GeneralName.defaultValues(TYPE$4));
  598. this.value = pvutils.getParametersValue(parameters, VALUE$5, GeneralName.defaultValues(VALUE$5));
  599. if (parameters.schema) {
  600. this.fromSchema(parameters.schema);
  601. }
  602. }
  603. static defaultValues(memberName) {
  604. switch (memberName) {
  605. case TYPE$4:
  606. return 9;
  607. case VALUE$5:
  608. return {};
  609. default:
  610. return super.defaultValues(memberName);
  611. }
  612. }
  613. static compareWithDefault(memberName, memberValue) {
  614. switch (memberName) {
  615. case TYPE$4:
  616. return (memberValue === GeneralName.defaultValues(memberName));
  617. case VALUE$5:
  618. return (Object.keys(memberValue).length === 0);
  619. default:
  620. return super.defaultValues(memberName);
  621. }
  622. }
  623. static schema(parameters = {}) {
  624. const names = pvutils.getParametersValue(parameters, "names", {});
  625. return (new asn1js.Choice({
  626. value: [
  627. new asn1js.Constructed({
  628. idBlock: {
  629. tagClass: 3,
  630. tagNumber: 0
  631. },
  632. name: (names.blockName || EMPTY_STRING),
  633. value: [
  634. new asn1js.ObjectIdentifier(),
  635. new asn1js.Constructed({
  636. idBlock: {
  637. tagClass: 3,
  638. tagNumber: 0
  639. },
  640. value: [new asn1js.Any()]
  641. })
  642. ]
  643. }),
  644. new asn1js.Primitive({
  645. name: (names.blockName || EMPTY_STRING),
  646. idBlock: {
  647. tagClass: 3,
  648. tagNumber: 1
  649. }
  650. }),
  651. new asn1js.Primitive({
  652. name: (names.blockName || EMPTY_STRING),
  653. idBlock: {
  654. tagClass: 3,
  655. tagNumber: 2
  656. }
  657. }),
  658. new asn1js.Constructed({
  659. idBlock: {
  660. tagClass: 3,
  661. tagNumber: 3
  662. },
  663. name: (names.blockName || EMPTY_STRING),
  664. value: [
  665. builtInStandardAttributes((names.builtInStandardAttributes || {}), false),
  666. builtInDomainDefinedAttributes(true),
  667. extensionAttributes(true)
  668. ]
  669. }),
  670. new asn1js.Constructed({
  671. idBlock: {
  672. tagClass: 3,
  673. tagNumber: 4
  674. },
  675. name: (names.blockName || EMPTY_STRING),
  676. value: [RelativeDistinguishedNames.schema(names.directoryName || {})]
  677. }),
  678. new asn1js.Constructed({
  679. idBlock: {
  680. tagClass: 3,
  681. tagNumber: 5
  682. },
  683. name: (names.blockName || EMPTY_STRING),
  684. value: [
  685. new asn1js.Constructed({
  686. optional: true,
  687. idBlock: {
  688. tagClass: 3,
  689. tagNumber: 0
  690. },
  691. value: [
  692. new asn1js.Choice({
  693. value: [
  694. new asn1js.TeletexString(),
  695. new asn1js.PrintableString(),
  696. new asn1js.UniversalString(),
  697. new asn1js.Utf8String(),
  698. new asn1js.BmpString()
  699. ]
  700. })
  701. ]
  702. }),
  703. new asn1js.Constructed({
  704. idBlock: {
  705. tagClass: 3,
  706. tagNumber: 1
  707. },
  708. value: [
  709. new asn1js.Choice({
  710. value: [
  711. new asn1js.TeletexString(),
  712. new asn1js.PrintableString(),
  713. new asn1js.UniversalString(),
  714. new asn1js.Utf8String(),
  715. new asn1js.BmpString()
  716. ]
  717. })
  718. ]
  719. })
  720. ]
  721. }),
  722. new asn1js.Primitive({
  723. name: (names.blockName || EMPTY_STRING),
  724. idBlock: {
  725. tagClass: 3,
  726. tagNumber: 6
  727. }
  728. }),
  729. new asn1js.Primitive({
  730. name: (names.blockName || EMPTY_STRING),
  731. idBlock: {
  732. tagClass: 3,
  733. tagNumber: 7
  734. }
  735. }),
  736. new asn1js.Primitive({
  737. name: (names.blockName || EMPTY_STRING),
  738. idBlock: {
  739. tagClass: 3,
  740. tagNumber: 8
  741. }
  742. })
  743. ]
  744. }));
  745. }
  746. fromSchema(schema) {
  747. pvutils.clearProps(schema, [
  748. "blockName",
  749. "otherName",
  750. "rfc822Name",
  751. "dNSName",
  752. "x400Address",
  753. "directoryName",
  754. "ediPartyName",
  755. "uniformResourceIdentifier",
  756. "iPAddress",
  757. "registeredID"
  758. ]);
  759. const asn1 = asn1js.compareSchema(schema, schema, GeneralName.schema({
  760. names: {
  761. blockName: "blockName",
  762. otherName: "otherName",
  763. rfc822Name: "rfc822Name",
  764. dNSName: "dNSName",
  765. x400Address: "x400Address",
  766. directoryName: {
  767. names: {
  768. blockName: "directoryName"
  769. }
  770. },
  771. ediPartyName: "ediPartyName",
  772. uniformResourceIdentifier: "uniformResourceIdentifier",
  773. iPAddress: "iPAddress",
  774. registeredID: "registeredID"
  775. }
  776. }));
  777. AsnError.assertSchema(asn1, this.className);
  778. this.type = asn1.result.blockName.idBlock.tagNumber;
  779. switch (this.type) {
  780. case 0:
  781. this.value = asn1.result.blockName;
  782. break;
  783. case 1:
  784. case 2:
  785. case 6:
  786. {
  787. const value = asn1.result.blockName;
  788. value.idBlock.tagClass = 1;
  789. value.idBlock.tagNumber = 22;
  790. const valueBER = value.toBER(false);
  791. const asnValue = asn1js.fromBER(valueBER);
  792. AsnError.assert(asnValue, "GeneralName value");
  793. this.value = asnValue.result.valueBlock.value;
  794. }
  795. break;
  796. case 3:
  797. this.value = asn1.result.blockName;
  798. break;
  799. case 4:
  800. this.value = new RelativeDistinguishedNames({ schema: asn1.result.directoryName });
  801. break;
  802. case 5:
  803. this.value = asn1.result.ediPartyName;
  804. break;
  805. case 7:
  806. this.value = new asn1js.OctetString({ valueHex: asn1.result.blockName.valueBlock.valueHex });
  807. break;
  808. case 8:
  809. {
  810. const value = asn1.result.blockName;
  811. value.idBlock.tagClass = 1;
  812. value.idBlock.tagNumber = 6;
  813. const valueBER = value.toBER(false);
  814. const asnValue = asn1js.fromBER(valueBER);
  815. AsnError.assert(asnValue, "GeneralName registeredID");
  816. this.value = asnValue.result.valueBlock.toString();
  817. }
  818. break;
  819. }
  820. }
  821. toSchema() {
  822. switch (this.type) {
  823. case 0:
  824. case 3:
  825. case 5:
  826. return new asn1js.Constructed({
  827. idBlock: {
  828. tagClass: 3,
  829. tagNumber: this.type
  830. },
  831. value: [
  832. this.value
  833. ]
  834. });
  835. case 1:
  836. case 2:
  837. case 6:
  838. {
  839. const value = new asn1js.IA5String({ value: this.value });
  840. value.idBlock.tagClass = 3;
  841. value.idBlock.tagNumber = this.type;
  842. return value;
  843. }
  844. case 4:
  845. return new asn1js.Constructed({
  846. idBlock: {
  847. tagClass: 3,
  848. tagNumber: 4
  849. },
  850. value: [this.value.toSchema()]
  851. });
  852. case 7:
  853. {
  854. const value = this.value;
  855. value.idBlock.tagClass = 3;
  856. value.idBlock.tagNumber = this.type;
  857. return value;
  858. }
  859. case 8:
  860. {
  861. const value = new asn1js.ObjectIdentifier({ value: this.value });
  862. value.idBlock.tagClass = 3;
  863. value.idBlock.tagNumber = this.type;
  864. return value;
  865. }
  866. default:
  867. return GeneralName.schema();
  868. }
  869. }
  870. toJSON() {
  871. const _object = {
  872. type: this.type,
  873. value: EMPTY_STRING
  874. };
  875. if ((typeof this.value) === "string")
  876. _object.value = this.value;
  877. else {
  878. try {
  879. _object.value = this.value.toJSON();
  880. }
  881. catch {
  882. }
  883. }
  884. return _object;
  885. }
  886. }
  887. GeneralName.CLASS_NAME = "GeneralName";
  888. const ACCESS_METHOD = "accessMethod";
  889. const ACCESS_LOCATION = "accessLocation";
  890. const CLEAR_PROPS$1v = [
  891. ACCESS_METHOD,
  892. ACCESS_LOCATION,
  893. ];
  894. class AccessDescription extends PkiObject {
  895. constructor(parameters = {}) {
  896. super();
  897. this.accessMethod = pvutils.getParametersValue(parameters, ACCESS_METHOD, AccessDescription.defaultValues(ACCESS_METHOD));
  898. this.accessLocation = pvutils.getParametersValue(parameters, ACCESS_LOCATION, AccessDescription.defaultValues(ACCESS_LOCATION));
  899. if (parameters.schema) {
  900. this.fromSchema(parameters.schema);
  901. }
  902. }
  903. static defaultValues(memberName) {
  904. switch (memberName) {
  905. case ACCESS_METHOD:
  906. return EMPTY_STRING;
  907. case ACCESS_LOCATION:
  908. return new GeneralName();
  909. default:
  910. return super.defaultValues(memberName);
  911. }
  912. }
  913. static schema(parameters = {}) {
  914. const names = pvutils.getParametersValue(parameters, "names", {});
  915. return (new asn1js.Sequence({
  916. name: (names.blockName || EMPTY_STRING),
  917. value: [
  918. new asn1js.ObjectIdentifier({ name: (names.accessMethod || EMPTY_STRING) }),
  919. GeneralName.schema(names.accessLocation || {})
  920. ]
  921. }));
  922. }
  923. fromSchema(schema) {
  924. pvutils.clearProps(schema, CLEAR_PROPS$1v);
  925. const asn1 = asn1js.compareSchema(schema, schema, AccessDescription.schema({
  926. names: {
  927. accessMethod: ACCESS_METHOD,
  928. accessLocation: {
  929. names: {
  930. blockName: ACCESS_LOCATION
  931. }
  932. }
  933. }
  934. }));
  935. AsnError.assertSchema(asn1, this.className);
  936. this.accessMethod = asn1.result.accessMethod.valueBlock.toString();
  937. this.accessLocation = new GeneralName({ schema: asn1.result.accessLocation });
  938. }
  939. toSchema() {
  940. return (new asn1js.Sequence({
  941. value: [
  942. new asn1js.ObjectIdentifier({ value: this.accessMethod }),
  943. this.accessLocation.toSchema()
  944. ]
  945. }));
  946. }
  947. toJSON() {
  948. return {
  949. accessMethod: this.accessMethod,
  950. accessLocation: this.accessLocation.toJSON()
  951. };
  952. }
  953. }
  954. AccessDescription.CLASS_NAME = "AccessDescription";
  955. const SECONDS = "seconds";
  956. const MILLIS = "millis";
  957. const MICROS = "micros";
  958. class Accuracy extends PkiObject {
  959. constructor(parameters = {}) {
  960. super();
  961. if (SECONDS in parameters) {
  962. this.seconds = pvutils.getParametersValue(parameters, SECONDS, Accuracy.defaultValues(SECONDS));
  963. }
  964. if (MILLIS in parameters) {
  965. this.millis = pvutils.getParametersValue(parameters, MILLIS, Accuracy.defaultValues(MILLIS));
  966. }
  967. if (MICROS in parameters) {
  968. this.micros = pvutils.getParametersValue(parameters, MICROS, Accuracy.defaultValues(MICROS));
  969. }
  970. if (parameters.schema) {
  971. this.fromSchema(parameters.schema);
  972. }
  973. }
  974. static defaultValues(memberName) {
  975. switch (memberName) {
  976. case SECONDS:
  977. case MILLIS:
  978. case MICROS:
  979. return 0;
  980. default:
  981. return super.defaultValues(memberName);
  982. }
  983. }
  984. static compareWithDefault(memberName, memberValue) {
  985. switch (memberName) {
  986. case SECONDS:
  987. case MILLIS:
  988. case MICROS:
  989. return (memberValue === Accuracy.defaultValues(memberName));
  990. default:
  991. return super.defaultValues(memberName);
  992. }
  993. }
  994. static schema(parameters = {}) {
  995. const names = pvutils.getParametersValue(parameters, "names", {});
  996. return (new asn1js.Sequence({
  997. name: (names.blockName || EMPTY_STRING),
  998. optional: true,
  999. value: [
  1000. new asn1js.Integer({
  1001. optional: true,
  1002. name: (names.seconds || EMPTY_STRING)
  1003. }),
  1004. new asn1js.Primitive({
  1005. name: (names.millis || EMPTY_STRING),
  1006. optional: true,
  1007. idBlock: {
  1008. tagClass: 3,
  1009. tagNumber: 0
  1010. }
  1011. }),
  1012. new asn1js.Primitive({
  1013. name: (names.micros || EMPTY_STRING),
  1014. optional: true,
  1015. idBlock: {
  1016. tagClass: 3,
  1017. tagNumber: 1
  1018. }
  1019. })
  1020. ]
  1021. }));
  1022. }
  1023. fromSchema(schema) {
  1024. pvutils.clearProps(schema, [
  1025. SECONDS,
  1026. MILLIS,
  1027. MICROS,
  1028. ]);
  1029. const asn1 = asn1js.compareSchema(schema, schema, Accuracy.schema({
  1030. names: {
  1031. seconds: SECONDS,
  1032. millis: MILLIS,
  1033. micros: MICROS,
  1034. }
  1035. }));
  1036. AsnError.assertSchema(asn1, this.className);
  1037. if ("seconds" in asn1.result) {
  1038. this.seconds = asn1.result.seconds.valueBlock.valueDec;
  1039. }
  1040. if ("millis" in asn1.result) {
  1041. const intMillis = new asn1js.Integer({ valueHex: asn1.result.millis.valueBlock.valueHex });
  1042. this.millis = intMillis.valueBlock.valueDec;
  1043. }
  1044. if ("micros" in asn1.result) {
  1045. const intMicros = new asn1js.Integer({ valueHex: asn1.result.micros.valueBlock.valueHex });
  1046. this.micros = intMicros.valueBlock.valueDec;
  1047. }
  1048. }
  1049. toSchema() {
  1050. const outputArray = [];
  1051. if (this.seconds !== undefined)
  1052. outputArray.push(new asn1js.Integer({ value: this.seconds }));
  1053. if (this.millis !== undefined) {
  1054. const intMillis = new asn1js.Integer({ value: this.millis });
  1055. outputArray.push(new asn1js.Primitive({
  1056. idBlock: {
  1057. tagClass: 3,
  1058. tagNumber: 0
  1059. },
  1060. valueHex: intMillis.valueBlock.valueHexView
  1061. }));
  1062. }
  1063. if (this.micros !== undefined) {
  1064. const intMicros = new asn1js.Integer({ value: this.micros });
  1065. outputArray.push(new asn1js.Primitive({
  1066. idBlock: {
  1067. tagClass: 3,
  1068. tagNumber: 1
  1069. },
  1070. valueHex: intMicros.valueBlock.valueHexView
  1071. }));
  1072. }
  1073. return (new asn1js.Sequence({
  1074. value: outputArray
  1075. }));
  1076. }
  1077. toJSON() {
  1078. const _object = {};
  1079. if (this.seconds !== undefined)
  1080. _object.seconds = this.seconds;
  1081. if (this.millis !== undefined)
  1082. _object.millis = this.millis;
  1083. if (this.micros !== undefined)
  1084. _object.micros = this.micros;
  1085. return _object;
  1086. }
  1087. }
  1088. Accuracy.CLASS_NAME = "Accuracy";
  1089. const ALGORITHM_ID = "algorithmId";
  1090. const ALGORITHM_PARAMS = "algorithmParams";
  1091. const ALGORITHM$2 = "algorithm";
  1092. const PARAMS = "params";
  1093. const CLEAR_PROPS$1u = [
  1094. ALGORITHM$2,
  1095. PARAMS
  1096. ];
  1097. class AlgorithmIdentifier extends PkiObject {
  1098. constructor(parameters = {}) {
  1099. super();
  1100. this.algorithmId = pvutils.getParametersValue(parameters, ALGORITHM_ID, AlgorithmIdentifier.defaultValues(ALGORITHM_ID));
  1101. if (ALGORITHM_PARAMS in parameters) {
  1102. this.algorithmParams = pvutils.getParametersValue(parameters, ALGORITHM_PARAMS, AlgorithmIdentifier.defaultValues(ALGORITHM_PARAMS));
  1103. }
  1104. if (parameters.schema) {
  1105. this.fromSchema(parameters.schema);
  1106. }
  1107. }
  1108. static defaultValues(memberName) {
  1109. switch (memberName) {
  1110. case ALGORITHM_ID:
  1111. return EMPTY_STRING;
  1112. case ALGORITHM_PARAMS:
  1113. return new asn1js.Any();
  1114. default:
  1115. return super.defaultValues(memberName);
  1116. }
  1117. }
  1118. static compareWithDefault(memberName, memberValue) {
  1119. switch (memberName) {
  1120. case ALGORITHM_ID:
  1121. return (memberValue === EMPTY_STRING);
  1122. case ALGORITHM_PARAMS:
  1123. return (memberValue instanceof asn1js.Any);
  1124. default:
  1125. return super.defaultValues(memberName);
  1126. }
  1127. }
  1128. static schema(parameters = {}) {
  1129. const names = pvutils.getParametersValue(parameters, "names", {});
  1130. return (new asn1js.Sequence({
  1131. name: (names.blockName || EMPTY_STRING),
  1132. optional: (names.optional || false),
  1133. value: [
  1134. new asn1js.ObjectIdentifier({ name: (names.algorithmIdentifier || EMPTY_STRING) }),
  1135. new asn1js.Any({ name: (names.algorithmParams || EMPTY_STRING), optional: true })
  1136. ]
  1137. }));
  1138. }
  1139. fromSchema(schema) {
  1140. pvutils.clearProps(schema, CLEAR_PROPS$1u);
  1141. const asn1 = asn1js.compareSchema(schema, schema, AlgorithmIdentifier.schema({
  1142. names: {
  1143. algorithmIdentifier: ALGORITHM$2,
  1144. algorithmParams: PARAMS
  1145. }
  1146. }));
  1147. AsnError.assertSchema(asn1, this.className);
  1148. this.algorithmId = asn1.result.algorithm.valueBlock.toString();
  1149. if (PARAMS in asn1.result) {
  1150. this.algorithmParams = asn1.result.params;
  1151. }
  1152. }
  1153. toSchema() {
  1154. const outputArray = [];
  1155. outputArray.push(new asn1js.ObjectIdentifier({ value: this.algorithmId }));
  1156. if (this.algorithmParams && !(this.algorithmParams instanceof asn1js.Any)) {
  1157. outputArray.push(this.algorithmParams);
  1158. }
  1159. return (new asn1js.Sequence({
  1160. value: outputArray
  1161. }));
  1162. }
  1163. toJSON() {
  1164. const object = {
  1165. algorithmId: this.algorithmId
  1166. };
  1167. if (this.algorithmParams && !(this.algorithmParams instanceof asn1js.Any)) {
  1168. object.algorithmParams = this.algorithmParams.toJSON();
  1169. }
  1170. return object;
  1171. }
  1172. isEqual(algorithmIdentifier) {
  1173. if (!(algorithmIdentifier instanceof AlgorithmIdentifier)) {
  1174. return false;
  1175. }
  1176. if (this.algorithmId !== algorithmIdentifier.algorithmId) {
  1177. return false;
  1178. }
  1179. if (this.algorithmParams) {
  1180. if (algorithmIdentifier.algorithmParams) {
  1181. return JSON.stringify(this.algorithmParams) === JSON.stringify(algorithmIdentifier.algorithmParams);
  1182. }
  1183. return false;
  1184. }
  1185. if (algorithmIdentifier.algorithmParams) {
  1186. return false;
  1187. }
  1188. return true;
  1189. }
  1190. }
  1191. AlgorithmIdentifier.CLASS_NAME = "AlgorithmIdentifier";
  1192. const ALT_NAMES = "altNames";
  1193. const CLEAR_PROPS$1t = [
  1194. ALT_NAMES
  1195. ];
  1196. class AltName extends PkiObject {
  1197. constructor(parameters = {}) {
  1198. super();
  1199. this.altNames = pvutils.getParametersValue(parameters, ALT_NAMES, AltName.defaultValues(ALT_NAMES));
  1200. if (parameters.schema) {
  1201. this.fromSchema(parameters.schema);
  1202. }
  1203. }
  1204. static defaultValues(memberName) {
  1205. switch (memberName) {
  1206. case ALT_NAMES:
  1207. return [];
  1208. default:
  1209. return super.defaultValues(memberName);
  1210. }
  1211. }
  1212. static schema(parameters = {}) {
  1213. const names = pvutils.getParametersValue(parameters, "names", {});
  1214. return (new asn1js.Sequence({
  1215. name: (names.blockName || EMPTY_STRING),
  1216. value: [
  1217. new asn1js.Repeated({
  1218. name: (names.altNames || EMPTY_STRING),
  1219. value: GeneralName.schema()
  1220. })
  1221. ]
  1222. }));
  1223. }
  1224. fromSchema(schema) {
  1225. pvutils.clearProps(schema, CLEAR_PROPS$1t);
  1226. const asn1 = asn1js.compareSchema(schema, schema, AltName.schema({
  1227. names: {
  1228. altNames: ALT_NAMES
  1229. }
  1230. }));
  1231. AsnError.assertSchema(asn1, this.className);
  1232. if (ALT_NAMES in asn1.result) {
  1233. this.altNames = Array.from(asn1.result.altNames, element => new GeneralName({ schema: element }));
  1234. }
  1235. }
  1236. toSchema() {
  1237. return (new asn1js.Sequence({
  1238. value: Array.from(this.altNames, o => o.toSchema())
  1239. }));
  1240. }
  1241. toJSON() {
  1242. return {
  1243. altNames: Array.from(this.altNames, o => o.toJSON())
  1244. };
  1245. }
  1246. }
  1247. AltName.CLASS_NAME = "AltName";
  1248. const TYPE$3 = "type";
  1249. const VALUES$1 = "values";
  1250. const CLEAR_PROPS$1s = [
  1251. TYPE$3,
  1252. VALUES$1
  1253. ];
  1254. class Attribute extends PkiObject {
  1255. constructor(parameters = {}) {
  1256. super();
  1257. this.type = pvutils.getParametersValue(parameters, TYPE$3, Attribute.defaultValues(TYPE$3));
  1258. this.values = pvutils.getParametersValue(parameters, VALUES$1, Attribute.defaultValues(VALUES$1));
  1259. if (parameters.schema) {
  1260. this.fromSchema(parameters.schema);
  1261. }
  1262. }
  1263. static defaultValues(memberName) {
  1264. switch (memberName) {
  1265. case TYPE$3:
  1266. return EMPTY_STRING;
  1267. case VALUES$1:
  1268. return [];
  1269. default:
  1270. return super.defaultValues(memberName);
  1271. }
  1272. }
  1273. static compareWithDefault(memberName, memberValue) {
  1274. switch (memberName) {
  1275. case TYPE$3:
  1276. return (memberValue === EMPTY_STRING);
  1277. case VALUES$1:
  1278. return (memberValue.length === 0);
  1279. default:
  1280. return super.defaultValues(memberName);
  1281. }
  1282. }
  1283. static schema(parameters = {}) {
  1284. const names = pvutils.getParametersValue(parameters, "names", {});
  1285. return (new asn1js.Sequence({
  1286. name: (names.blockName || EMPTY_STRING),
  1287. value: [
  1288. new asn1js.ObjectIdentifier({ name: (names.type || EMPTY_STRING) }),
  1289. new asn1js.Set({
  1290. name: (names.setName || EMPTY_STRING),
  1291. value: [
  1292. new asn1js.Repeated({
  1293. name: (names.values || EMPTY_STRING),
  1294. value: new asn1js.Any()
  1295. })
  1296. ]
  1297. })
  1298. ]
  1299. }));
  1300. }
  1301. fromSchema(schema) {
  1302. pvutils.clearProps(schema, CLEAR_PROPS$1s);
  1303. const asn1 = asn1js.compareSchema(schema, schema, Attribute.schema({
  1304. names: {
  1305. type: TYPE$3,
  1306. values: VALUES$1
  1307. }
  1308. }));
  1309. AsnError.assertSchema(asn1, this.className);
  1310. this.type = asn1.result.type.valueBlock.toString();
  1311. this.values = asn1.result.values;
  1312. }
  1313. toSchema() {
  1314. return (new asn1js.Sequence({
  1315. value: [
  1316. new asn1js.ObjectIdentifier({ value: this.type }),
  1317. new asn1js.Set({
  1318. value: this.values
  1319. })
  1320. ]
  1321. }));
  1322. }
  1323. toJSON() {
  1324. return {
  1325. type: this.type,
  1326. values: Array.from(this.values, o => o.toJSON())
  1327. };
  1328. }
  1329. }
  1330. Attribute.CLASS_NAME = "Attribute";
  1331. const NOT_BEFORE_TIME = "notBeforeTime";
  1332. const NOT_AFTER_TIME = "notAfterTime";
  1333. const CLEAR_PROPS$1r = [
  1334. NOT_BEFORE_TIME,
  1335. NOT_AFTER_TIME,
  1336. ];
  1337. class AttCertValidityPeriod extends PkiObject {
  1338. constructor(parameters = {}) {
  1339. super();
  1340. this.notBeforeTime = pvutils.getParametersValue(parameters, NOT_BEFORE_TIME, AttCertValidityPeriod.defaultValues(NOT_BEFORE_TIME));
  1341. this.notAfterTime = pvutils.getParametersValue(parameters, NOT_AFTER_TIME, AttCertValidityPeriod.defaultValues(NOT_AFTER_TIME));
  1342. if (parameters.schema) {
  1343. this.fromSchema(parameters.schema);
  1344. }
  1345. }
  1346. static defaultValues(memberName) {
  1347. switch (memberName) {
  1348. case NOT_BEFORE_TIME:
  1349. case NOT_AFTER_TIME:
  1350. return new Date(0, 0, 0);
  1351. default:
  1352. return super.defaultValues(memberName);
  1353. }
  1354. }
  1355. static schema(parameters = {}) {
  1356. const names = pvutils.getParametersValue(parameters, "names", {});
  1357. return (new asn1js.Sequence({
  1358. name: (names.blockName || EMPTY_STRING),
  1359. value: [
  1360. new asn1js.GeneralizedTime({ name: (names.notBeforeTime || EMPTY_STRING) }),
  1361. new asn1js.GeneralizedTime({ name: (names.notAfterTime || EMPTY_STRING) })
  1362. ]
  1363. }));
  1364. }
  1365. fromSchema(schema) {
  1366. pvutils.clearProps(schema, CLEAR_PROPS$1r);
  1367. const asn1 = asn1js.compareSchema(schema, schema, AttCertValidityPeriod.schema({
  1368. names: {
  1369. notBeforeTime: NOT_BEFORE_TIME,
  1370. notAfterTime: NOT_AFTER_TIME
  1371. }
  1372. }));
  1373. AsnError.assertSchema(asn1, this.className);
  1374. this.notBeforeTime = asn1.result.notBeforeTime.toDate();
  1375. this.notAfterTime = asn1.result.notAfterTime.toDate();
  1376. }
  1377. toSchema() {
  1378. return (new asn1js.Sequence({
  1379. value: [
  1380. new asn1js.GeneralizedTime({ valueDate: this.notBeforeTime }),
  1381. new asn1js.GeneralizedTime({ valueDate: this.notAfterTime }),
  1382. ]
  1383. }));
  1384. }
  1385. toJSON() {
  1386. return {
  1387. notBeforeTime: this.notBeforeTime,
  1388. notAfterTime: this.notAfterTime
  1389. };
  1390. }
  1391. }
  1392. AttCertValidityPeriod.CLASS_NAME = "AttCertValidityPeriod";
  1393. const NAMES = "names";
  1394. const GENERAL_NAMES = "generalNames";
  1395. class GeneralNames extends PkiObject {
  1396. constructor(parameters = {}) {
  1397. super();
  1398. this.names = pvutils.getParametersValue(parameters, NAMES, GeneralNames.defaultValues(NAMES));
  1399. if (parameters.schema) {
  1400. this.fromSchema(parameters.schema);
  1401. }
  1402. }
  1403. static defaultValues(memberName) {
  1404. switch (memberName) {
  1405. case "names":
  1406. return [];
  1407. default:
  1408. return super.defaultValues(memberName);
  1409. }
  1410. }
  1411. static schema(parameters = {}, optional = false) {
  1412. const names = pvutils.getParametersValue(parameters, NAMES, {});
  1413. return (new asn1js.Sequence({
  1414. optional,
  1415. name: (names.blockName || EMPTY_STRING),
  1416. value: [
  1417. new asn1js.Repeated({
  1418. name: (names.generalNames || EMPTY_STRING),
  1419. value: GeneralName.schema()
  1420. })
  1421. ]
  1422. }));
  1423. }
  1424. fromSchema(schema) {
  1425. pvutils.clearProps(schema, [
  1426. NAMES,
  1427. GENERAL_NAMES
  1428. ]);
  1429. const asn1 = asn1js.compareSchema(schema, schema, GeneralNames.schema({
  1430. names: {
  1431. blockName: NAMES,
  1432. generalNames: GENERAL_NAMES
  1433. }
  1434. }));
  1435. AsnError.assertSchema(asn1, this.className);
  1436. this.names = Array.from(asn1.result.generalNames, element => new GeneralName({ schema: element }));
  1437. }
  1438. toSchema() {
  1439. return (new asn1js.Sequence({
  1440. value: Array.from(this.names, o => o.toSchema())
  1441. }));
  1442. }
  1443. toJSON() {
  1444. return {
  1445. names: Array.from(this.names, o => o.toJSON())
  1446. };
  1447. }
  1448. }
  1449. GeneralNames.CLASS_NAME = "GeneralNames";
  1450. const id_SubjectDirectoryAttributes = "2.5.29.9";
  1451. const id_SubjectKeyIdentifier = "2.5.29.14";
  1452. const id_KeyUsage = "2.5.29.15";
  1453. const id_PrivateKeyUsagePeriod = "2.5.29.16";
  1454. const id_SubjectAltName = "2.5.29.17";
  1455. const id_IssuerAltName = "2.5.29.18";
  1456. const id_BasicConstraints = "2.5.29.19";
  1457. const id_CRLNumber = "2.5.29.20";
  1458. const id_BaseCRLNumber = "2.5.29.27";
  1459. const id_CRLReason = "2.5.29.21";
  1460. const id_InvalidityDate = "2.5.29.24";
  1461. const id_IssuingDistributionPoint = "2.5.29.28";
  1462. const id_CertificateIssuer = "2.5.29.29";
  1463. const id_NameConstraints = "2.5.29.30";
  1464. const id_CRLDistributionPoints = "2.5.29.31";
  1465. const id_FreshestCRL = "2.5.29.46";
  1466. const id_CertificatePolicies = "2.5.29.32";
  1467. const id_AnyPolicy = "2.5.29.32.0";
  1468. const id_MicrosoftAppPolicies = "1.3.6.1.4.1.311.21.10";
  1469. const id_PolicyMappings = "2.5.29.33";
  1470. const id_AuthorityKeyIdentifier = "2.5.29.35";
  1471. const id_PolicyConstraints = "2.5.29.36";
  1472. const id_ExtKeyUsage = "2.5.29.37";
  1473. const id_InhibitAnyPolicy = "2.5.29.54";
  1474. const id_AuthorityInfoAccess = "1.3.6.1.5.5.7.1.1";
  1475. const id_SubjectInfoAccess = "1.3.6.1.5.5.7.1.11";
  1476. const id_SignedCertificateTimestampList = "1.3.6.1.4.1.11129.2.4.2";
  1477. const id_MicrosoftCertTemplateV1 = "1.3.6.1.4.1.311.20.2";
  1478. const id_MicrosoftPrevCaCertHash = "1.3.6.1.4.1.311.21.2";
  1479. const id_MicrosoftCertTemplateV2 = "1.3.6.1.4.1.311.21.7";
  1480. const id_MicrosoftCaVersion = "1.3.6.1.4.1.311.21.1";
  1481. const id_QCStatements = "1.3.6.1.5.5.7.1.3";
  1482. const id_ContentType_Data = "1.2.840.113549.1.7.1";
  1483. const id_ContentType_SignedData = "1.2.840.113549.1.7.2";
  1484. const id_ContentType_EnvelopedData = "1.2.840.113549.1.7.3";
  1485. const id_ContentType_EncryptedData = "1.2.840.113549.1.7.6";
  1486. const id_eContentType_TSTInfo = "1.2.840.113549.1.9.16.1.4";
  1487. const id_CertBag_X509Certificate = "1.2.840.113549.1.9.22.1";
  1488. const id_CertBag_SDSICertificate = "1.2.840.113549.1.9.22.2";
  1489. const id_CertBag_AttributeCertificate = "1.2.840.113549.1.9.22.3";
  1490. const id_CRLBag_X509CRL = "1.2.840.113549.1.9.23.1";
  1491. const id_pkix = "1.3.6.1.5.5.7";
  1492. const id_ad = `${id_pkix}.48`;
  1493. const id_PKIX_OCSP_Basic = `${id_ad}.1.1`;
  1494. const id_ad_caIssuers = `${id_ad}.2`;
  1495. const id_ad_ocsp = `${id_ad}.1`;
  1496. const id_sha1 = "1.3.14.3.2.26";
  1497. const id_sha256 = "2.16.840.1.101.3.4.2.1";
  1498. const id_sha384 = "2.16.840.1.101.3.4.2.2";
  1499. const id_sha512 = "2.16.840.1.101.3.4.2.3";
  1500. const KEY_IDENTIFIER$1 = "keyIdentifier";
  1501. const AUTHORITY_CERT_ISSUER = "authorityCertIssuer";
  1502. const AUTHORITY_CERT_SERIAL_NUMBER = "authorityCertSerialNumber";
  1503. const CLEAR_PROPS$1q = [
  1504. KEY_IDENTIFIER$1,
  1505. AUTHORITY_CERT_ISSUER,
  1506. AUTHORITY_CERT_SERIAL_NUMBER,
  1507. ];
  1508. class AuthorityKeyIdentifier extends PkiObject {
  1509. constructor(parameters = {}) {
  1510. super();
  1511. if (KEY_IDENTIFIER$1 in parameters) {
  1512. this.keyIdentifier = pvutils.getParametersValue(parameters, KEY_IDENTIFIER$1, AuthorityKeyIdentifier.defaultValues(KEY_IDENTIFIER$1));
  1513. }
  1514. if (AUTHORITY_CERT_ISSUER in parameters) {
  1515. this.authorityCertIssuer = pvutils.getParametersValue(parameters, AUTHORITY_CERT_ISSUER, AuthorityKeyIdentifier.defaultValues(AUTHORITY_CERT_ISSUER));
  1516. }
  1517. if (AUTHORITY_CERT_SERIAL_NUMBER in parameters) {
  1518. this.authorityCertSerialNumber = pvutils.getParametersValue(parameters, AUTHORITY_CERT_SERIAL_NUMBER, AuthorityKeyIdentifier.defaultValues(AUTHORITY_CERT_SERIAL_NUMBER));
  1519. }
  1520. if (parameters.schema) {
  1521. this.fromSchema(parameters.schema);
  1522. }
  1523. }
  1524. static defaultValues(memberName) {
  1525. switch (memberName) {
  1526. case KEY_IDENTIFIER$1:
  1527. return new asn1js.OctetString();
  1528. case AUTHORITY_CERT_ISSUER:
  1529. return [];
  1530. case AUTHORITY_CERT_SERIAL_NUMBER:
  1531. return new asn1js.Integer();
  1532. default:
  1533. return super.defaultValues(memberName);
  1534. }
  1535. }
  1536. static schema(parameters = {}) {
  1537. const names = pvutils.getParametersValue(parameters, "names", {});
  1538. return (new asn1js.Sequence({
  1539. name: (names.blockName || EMPTY_STRING),
  1540. value: [
  1541. new asn1js.Primitive({
  1542. name: (names.keyIdentifier || EMPTY_STRING),
  1543. optional: true,
  1544. idBlock: {
  1545. tagClass: 3,
  1546. tagNumber: 0
  1547. }
  1548. }),
  1549. new asn1js.Constructed({
  1550. optional: true,
  1551. idBlock: {
  1552. tagClass: 3,
  1553. tagNumber: 1
  1554. },
  1555. value: [
  1556. new asn1js.Repeated({
  1557. name: (names.authorityCertIssuer || EMPTY_STRING),
  1558. value: GeneralName.schema()
  1559. })
  1560. ]
  1561. }),
  1562. new asn1js.Primitive({
  1563. name: (names.authorityCertSerialNumber || EMPTY_STRING),
  1564. optional: true,
  1565. idBlock: {
  1566. tagClass: 3,
  1567. tagNumber: 2
  1568. }
  1569. })
  1570. ]
  1571. }));
  1572. }
  1573. fromSchema(schema) {
  1574. pvutils.clearProps(schema, CLEAR_PROPS$1q);
  1575. const asn1 = asn1js.compareSchema(schema, schema, AuthorityKeyIdentifier.schema({
  1576. names: {
  1577. keyIdentifier: KEY_IDENTIFIER$1,
  1578. authorityCertIssuer: AUTHORITY_CERT_ISSUER,
  1579. authorityCertSerialNumber: AUTHORITY_CERT_SERIAL_NUMBER
  1580. }
  1581. }));
  1582. AsnError.assertSchema(asn1, this.className);
  1583. if (KEY_IDENTIFIER$1 in asn1.result)
  1584. this.keyIdentifier = new asn1js.OctetString({ valueHex: asn1.result.keyIdentifier.valueBlock.valueHex });
  1585. if (AUTHORITY_CERT_ISSUER in asn1.result)
  1586. this.authorityCertIssuer = Array.from(asn1.result.authorityCertIssuer, o => new GeneralName({ schema: o }));
  1587. if (AUTHORITY_CERT_SERIAL_NUMBER in asn1.result)
  1588. this.authorityCertSerialNumber = new asn1js.Integer({ valueHex: asn1.result.authorityCertSerialNumber.valueBlock.valueHex });
  1589. }
  1590. toSchema() {
  1591. const outputArray = [];
  1592. if (this.keyIdentifier) {
  1593. outputArray.push(new asn1js.Primitive({
  1594. idBlock: {
  1595. tagClass: 3,
  1596. tagNumber: 0
  1597. },
  1598. valueHex: this.keyIdentifier.valueBlock.valueHexView
  1599. }));
  1600. }
  1601. if (this.authorityCertIssuer) {
  1602. outputArray.push(new asn1js.Constructed({
  1603. idBlock: {
  1604. tagClass: 3,
  1605. tagNumber: 1
  1606. },
  1607. value: Array.from(this.authorityCertIssuer, o => o.toSchema())
  1608. }));
  1609. }
  1610. if (this.authorityCertSerialNumber) {
  1611. outputArray.push(new asn1js.Primitive({
  1612. idBlock: {
  1613. tagClass: 3,
  1614. tagNumber: 2
  1615. },
  1616. valueHex: this.authorityCertSerialNumber.valueBlock.valueHexView
  1617. }));
  1618. }
  1619. return (new asn1js.Sequence({
  1620. value: outputArray
  1621. }));
  1622. }
  1623. toJSON() {
  1624. const object = {};
  1625. if (this.keyIdentifier) {
  1626. object.keyIdentifier = this.keyIdentifier.toJSON();
  1627. }
  1628. if (this.authorityCertIssuer) {
  1629. object.authorityCertIssuer = Array.from(this.authorityCertIssuer, o => o.toJSON());
  1630. }
  1631. if (this.authorityCertSerialNumber) {
  1632. object.authorityCertSerialNumber = this.authorityCertSerialNumber.toJSON();
  1633. }
  1634. return object;
  1635. }
  1636. }
  1637. AuthorityKeyIdentifier.CLASS_NAME = "AuthorityKeyIdentifier";
  1638. const PATH_LENGTH_CONSTRAINT = "pathLenConstraint";
  1639. const CA = "cA";
  1640. class BasicConstraints extends PkiObject {
  1641. constructor(parameters = {}) {
  1642. super();
  1643. this.cA = pvutils.getParametersValue(parameters, CA, false);
  1644. if (PATH_LENGTH_CONSTRAINT in parameters) {
  1645. this.pathLenConstraint = pvutils.getParametersValue(parameters, PATH_LENGTH_CONSTRAINT, 0);
  1646. }
  1647. if (parameters.schema) {
  1648. this.fromSchema(parameters.schema);
  1649. }
  1650. }
  1651. static defaultValues(memberName) {
  1652. switch (memberName) {
  1653. case CA:
  1654. return false;
  1655. default:
  1656. return super.defaultValues(memberName);
  1657. }
  1658. }
  1659. static schema(parameters = {}) {
  1660. const names = pvutils.getParametersValue(parameters, "names", {});
  1661. return (new asn1js.Sequence({
  1662. name: (names.blockName || EMPTY_STRING),
  1663. value: [
  1664. new asn1js.Boolean({
  1665. optional: true,
  1666. name: (names.cA || EMPTY_STRING)
  1667. }),
  1668. new asn1js.Integer({
  1669. optional: true,
  1670. name: (names.pathLenConstraint || EMPTY_STRING)
  1671. })
  1672. ]
  1673. }));
  1674. }
  1675. fromSchema(schema) {
  1676. pvutils.clearProps(schema, [
  1677. CA,
  1678. PATH_LENGTH_CONSTRAINT
  1679. ]);
  1680. const asn1 = asn1js.compareSchema(schema, schema, BasicConstraints.schema({
  1681. names: {
  1682. cA: CA,
  1683. pathLenConstraint: PATH_LENGTH_CONSTRAINT
  1684. }
  1685. }));
  1686. AsnError.assertSchema(asn1, this.className);
  1687. if (CA in asn1.result) {
  1688. this.cA = asn1.result.cA.valueBlock.value;
  1689. }
  1690. if (PATH_LENGTH_CONSTRAINT in asn1.result) {
  1691. if (asn1.result.pathLenConstraint.valueBlock.isHexOnly) {
  1692. this.pathLenConstraint = asn1.result.pathLenConstraint;
  1693. }
  1694. else {
  1695. this.pathLenConstraint = asn1.result.pathLenConstraint.valueBlock.valueDec;
  1696. }
  1697. }
  1698. }
  1699. toSchema() {
  1700. const outputArray = [];
  1701. if (this.cA !== BasicConstraints.defaultValues(CA))
  1702. outputArray.push(new asn1js.Boolean({ value: this.cA }));
  1703. if (PATH_LENGTH_CONSTRAINT in this) {
  1704. if (this.pathLenConstraint instanceof asn1js.Integer) {
  1705. outputArray.push(this.pathLenConstraint);
  1706. }
  1707. else {
  1708. outputArray.push(new asn1js.Integer({ value: this.pathLenConstraint }));
  1709. }
  1710. }
  1711. return (new asn1js.Sequence({
  1712. value: outputArray
  1713. }));
  1714. }
  1715. toJSON() {
  1716. const object = {};
  1717. if (this.cA !== BasicConstraints.defaultValues(CA)) {
  1718. object.cA = this.cA;
  1719. }
  1720. if (PATH_LENGTH_CONSTRAINT in this) {
  1721. if (this.pathLenConstraint instanceof asn1js.Integer) {
  1722. object.pathLenConstraint = this.pathLenConstraint.toJSON();
  1723. }
  1724. else {
  1725. object.pathLenConstraint = this.pathLenConstraint;
  1726. }
  1727. }
  1728. return object;
  1729. }
  1730. }
  1731. BasicConstraints.CLASS_NAME = "BasicConstraints";
  1732. const CERTIFICATE_INDEX = "certificateIndex";
  1733. const KEY_INDEX = "keyIndex";
  1734. class CAVersion extends PkiObject {
  1735. constructor(parameters = {}) {
  1736. super();
  1737. this.certificateIndex = pvutils.getParametersValue(parameters, CERTIFICATE_INDEX, CAVersion.defaultValues(CERTIFICATE_INDEX));
  1738. this.keyIndex = pvutils.getParametersValue(parameters, KEY_INDEX, CAVersion.defaultValues(KEY_INDEX));
  1739. if (parameters.schema) {
  1740. this.fromSchema(parameters.schema);
  1741. }
  1742. }
  1743. static defaultValues(memberName) {
  1744. switch (memberName) {
  1745. case CERTIFICATE_INDEX:
  1746. case KEY_INDEX:
  1747. return 0;
  1748. default:
  1749. return super.defaultValues(memberName);
  1750. }
  1751. }
  1752. static schema() {
  1753. return (new asn1js.Integer());
  1754. }
  1755. fromSchema(schema) {
  1756. if (schema.constructor.blockName() !== asn1js.Integer.blockName()) {
  1757. throw new Error("Object's schema was not verified against input data for CAVersion");
  1758. }
  1759. let value = schema.valueBlock.valueHex.slice(0);
  1760. const valueView = new Uint8Array(value);
  1761. switch (true) {
  1762. case (value.byteLength < 4):
  1763. {
  1764. const tempValue = new ArrayBuffer(4);
  1765. const tempValueView = new Uint8Array(tempValue);
  1766. tempValueView.set(valueView, 4 - value.byteLength);
  1767. value = tempValue.slice(0);
  1768. }
  1769. break;
  1770. case (value.byteLength > 4):
  1771. {
  1772. const tempValue = new ArrayBuffer(4);
  1773. const tempValueView = new Uint8Array(tempValue);
  1774. tempValueView.set(valueView.slice(0, 4));
  1775. value = tempValue.slice(0);
  1776. }
  1777. break;
  1778. }
  1779. const keyIndexBuffer = value.slice(0, 2);
  1780. const keyIndexView8 = new Uint8Array(keyIndexBuffer);
  1781. let temp = keyIndexView8[0];
  1782. keyIndexView8[0] = keyIndexView8[1];
  1783. keyIndexView8[1] = temp;
  1784. const keyIndexView16 = new Uint16Array(keyIndexBuffer);
  1785. this.keyIndex = keyIndexView16[0];
  1786. const certificateIndexBuffer = value.slice(2);
  1787. const certificateIndexView8 = new Uint8Array(certificateIndexBuffer);
  1788. temp = certificateIndexView8[0];
  1789. certificateIndexView8[0] = certificateIndexView8[1];
  1790. certificateIndexView8[1] = temp;
  1791. const certificateIndexView16 = new Uint16Array(certificateIndexBuffer);
  1792. this.certificateIndex = certificateIndexView16[0];
  1793. }
  1794. toSchema() {
  1795. const certificateIndexBuffer = new ArrayBuffer(2);
  1796. const certificateIndexView = new Uint16Array(certificateIndexBuffer);
  1797. certificateIndexView[0] = this.certificateIndex;
  1798. const certificateIndexView8 = new Uint8Array(certificateIndexBuffer);
  1799. let temp = certificateIndexView8[0];
  1800. certificateIndexView8[0] = certificateIndexView8[1];
  1801. certificateIndexView8[1] = temp;
  1802. const keyIndexBuffer = new ArrayBuffer(2);
  1803. const keyIndexView = new Uint16Array(keyIndexBuffer);
  1804. keyIndexView[0] = this.keyIndex;
  1805. const keyIndexView8 = new Uint8Array(keyIndexBuffer);
  1806. temp = keyIndexView8[0];
  1807. keyIndexView8[0] = keyIndexView8[1];
  1808. keyIndexView8[1] = temp;
  1809. return (new asn1js.Integer({
  1810. valueHex: pvutils.utilConcatBuf(keyIndexBuffer, certificateIndexBuffer)
  1811. }));
  1812. }
  1813. toJSON() {
  1814. return {
  1815. certificateIndex: this.certificateIndex,
  1816. keyIndex: this.keyIndex
  1817. };
  1818. }
  1819. }
  1820. CAVersion.CLASS_NAME = "CAVersion";
  1821. const POLICY_QUALIFIER_ID = "policyQualifierId";
  1822. const QUALIFIER = "qualifier";
  1823. const CLEAR_PROPS$1p = [
  1824. POLICY_QUALIFIER_ID,
  1825. QUALIFIER
  1826. ];
  1827. class PolicyQualifierInfo extends PkiObject {
  1828. constructor(parameters = {}) {
  1829. super();
  1830. this.policyQualifierId = pvutils.getParametersValue(parameters, POLICY_QUALIFIER_ID, PolicyQualifierInfo.defaultValues(POLICY_QUALIFIER_ID));
  1831. this.qualifier = pvutils.getParametersValue(parameters, QUALIFIER, PolicyQualifierInfo.defaultValues(QUALIFIER));
  1832. if (parameters.schema) {
  1833. this.fromSchema(parameters.schema);
  1834. }
  1835. }
  1836. static defaultValues(memberName) {
  1837. switch (memberName) {
  1838. case POLICY_QUALIFIER_ID:
  1839. return EMPTY_STRING;
  1840. case QUALIFIER:
  1841. return new asn1js.Any();
  1842. default:
  1843. return super.defaultValues(memberName);
  1844. }
  1845. }
  1846. static schema(parameters = {}) {
  1847. const names = pvutils.getParametersValue(parameters, "names", {});
  1848. return (new asn1js.Sequence({
  1849. name: (names.blockName || EMPTY_STRING),
  1850. value: [
  1851. new asn1js.ObjectIdentifier({ name: (names.policyQualifierId || EMPTY_STRING) }),
  1852. new asn1js.Any({ name: (names.qualifier || EMPTY_STRING) })
  1853. ]
  1854. }));
  1855. }
  1856. fromSchema(schema) {
  1857. pvutils.clearProps(schema, CLEAR_PROPS$1p);
  1858. const asn1 = asn1js.compareSchema(schema, schema, PolicyQualifierInfo.schema({
  1859. names: {
  1860. policyQualifierId: POLICY_QUALIFIER_ID,
  1861. qualifier: QUALIFIER
  1862. }
  1863. }));
  1864. AsnError.assertSchema(asn1, this.className);
  1865. this.policyQualifierId = asn1.result.policyQualifierId.valueBlock.toString();
  1866. this.qualifier = asn1.result.qualifier;
  1867. }
  1868. toSchema() {
  1869. return (new asn1js.Sequence({
  1870. value: [
  1871. new asn1js.ObjectIdentifier({ value: this.policyQualifierId }),
  1872. this.qualifier
  1873. ]
  1874. }));
  1875. }
  1876. toJSON() {
  1877. return {
  1878. policyQualifierId: this.policyQualifierId,
  1879. qualifier: this.qualifier.toJSON()
  1880. };
  1881. }
  1882. }
  1883. PolicyQualifierInfo.CLASS_NAME = "PolicyQualifierInfo";
  1884. const POLICY_IDENTIFIER = "policyIdentifier";
  1885. const POLICY_QUALIFIERS = "policyQualifiers";
  1886. const CLEAR_PROPS$1o = [
  1887. POLICY_IDENTIFIER,
  1888. POLICY_QUALIFIERS
  1889. ];
  1890. class PolicyInformation extends PkiObject {
  1891. constructor(parameters = {}) {
  1892. super();
  1893. this.policyIdentifier = pvutils.getParametersValue(parameters, POLICY_IDENTIFIER, PolicyInformation.defaultValues(POLICY_IDENTIFIER));
  1894. if (POLICY_QUALIFIERS in parameters) {
  1895. this.policyQualifiers = pvutils.getParametersValue(parameters, POLICY_QUALIFIERS, PolicyInformation.defaultValues(POLICY_QUALIFIERS));
  1896. }
  1897. if (parameters.schema) {
  1898. this.fromSchema(parameters.schema);
  1899. }
  1900. }
  1901. static defaultValues(memberName) {
  1902. switch (memberName) {
  1903. case POLICY_IDENTIFIER:
  1904. return EMPTY_STRING;
  1905. case POLICY_QUALIFIERS:
  1906. return [];
  1907. default:
  1908. return super.defaultValues(memberName);
  1909. }
  1910. }
  1911. static schema(parameters = {}) {
  1912. const names = pvutils.getParametersValue(parameters, "names", {});
  1913. return (new asn1js.Sequence({
  1914. name: (names.blockName || EMPTY_STRING),
  1915. value: [
  1916. new asn1js.ObjectIdentifier({ name: (names.policyIdentifier || EMPTY_STRING) }),
  1917. new asn1js.Sequence({
  1918. optional: true,
  1919. value: [
  1920. new asn1js.Repeated({
  1921. name: (names.policyQualifiers || EMPTY_STRING),
  1922. value: PolicyQualifierInfo.schema()
  1923. })
  1924. ]
  1925. })
  1926. ]
  1927. }));
  1928. }
  1929. fromSchema(schema) {
  1930. pvutils.clearProps(schema, CLEAR_PROPS$1o);
  1931. const asn1 = asn1js.compareSchema(schema, schema, PolicyInformation.schema({
  1932. names: {
  1933. policyIdentifier: POLICY_IDENTIFIER,
  1934. policyQualifiers: POLICY_QUALIFIERS
  1935. }
  1936. }));
  1937. AsnError.assertSchema(asn1, this.className);
  1938. this.policyIdentifier = asn1.result.policyIdentifier.valueBlock.toString();
  1939. if (POLICY_QUALIFIERS in asn1.result) {
  1940. this.policyQualifiers = Array.from(asn1.result.policyQualifiers, element => new PolicyQualifierInfo({ schema: element }));
  1941. }
  1942. }
  1943. toSchema() {
  1944. const outputArray = [];
  1945. outputArray.push(new asn1js.ObjectIdentifier({ value: this.policyIdentifier }));
  1946. if (this.policyQualifiers) {
  1947. outputArray.push(new asn1js.Sequence({
  1948. value: Array.from(this.policyQualifiers, o => o.toSchema())
  1949. }));
  1950. }
  1951. return (new asn1js.Sequence({
  1952. value: outputArray
  1953. }));
  1954. }
  1955. toJSON() {
  1956. const res = {
  1957. policyIdentifier: this.policyIdentifier
  1958. };
  1959. if (this.policyQualifiers)
  1960. res.policyQualifiers = Array.from(this.policyQualifiers, o => o.toJSON());
  1961. return res;
  1962. }
  1963. }
  1964. PolicyInformation.CLASS_NAME = "PolicyInformation";
  1965. const CERTIFICATE_POLICIES = "certificatePolicies";
  1966. const CLEAR_PROPS$1n = [
  1967. CERTIFICATE_POLICIES,
  1968. ];
  1969. class CertificatePolicies extends PkiObject {
  1970. constructor(parameters = {}) {
  1971. super();
  1972. this.certificatePolicies = pvutils.getParametersValue(parameters, CERTIFICATE_POLICIES, CertificatePolicies.defaultValues(CERTIFICATE_POLICIES));
  1973. if (parameters.schema) {
  1974. this.fromSchema(parameters.schema);
  1975. }
  1976. }
  1977. static defaultValues(memberName) {
  1978. switch (memberName) {
  1979. case CERTIFICATE_POLICIES:
  1980. return [];
  1981. default:
  1982. return super.defaultValues(memberName);
  1983. }
  1984. }
  1985. static schema(parameters = {}) {
  1986. const names = pvutils.getParametersValue(parameters, "names", {});
  1987. return (new asn1js.Sequence({
  1988. name: (names.blockName || EMPTY_STRING),
  1989. value: [
  1990. new asn1js.Repeated({
  1991. name: (names.certificatePolicies || EMPTY_STRING),
  1992. value: PolicyInformation.schema()
  1993. })
  1994. ]
  1995. }));
  1996. }
  1997. fromSchema(schema) {
  1998. pvutils.clearProps(schema, CLEAR_PROPS$1n);
  1999. const asn1 = asn1js.compareSchema(schema, schema, CertificatePolicies.schema({
  2000. names: {
  2001. certificatePolicies: CERTIFICATE_POLICIES
  2002. }
  2003. }));
  2004. AsnError.assertSchema(asn1, this.className);
  2005. this.certificatePolicies = Array.from(asn1.result.certificatePolicies, element => new PolicyInformation({ schema: element }));
  2006. }
  2007. toSchema() {
  2008. return (new asn1js.Sequence({
  2009. value: Array.from(this.certificatePolicies, o => o.toSchema())
  2010. }));
  2011. }
  2012. toJSON() {
  2013. return {
  2014. certificatePolicies: Array.from(this.certificatePolicies, o => o.toJSON())
  2015. };
  2016. }
  2017. }
  2018. CertificatePolicies.CLASS_NAME = "CertificatePolicies";
  2019. const TEMPLATE_ID = "templateID";
  2020. const TEMPLATE_MAJOR_VERSION = "templateMajorVersion";
  2021. const TEMPLATE_MINOR_VERSION = "templateMinorVersion";
  2022. const CLEAR_PROPS$1m = [
  2023. TEMPLATE_ID,
  2024. TEMPLATE_MAJOR_VERSION,
  2025. TEMPLATE_MINOR_VERSION
  2026. ];
  2027. class CertificateTemplate extends PkiObject {
  2028. constructor(parameters = {}) {
  2029. super();
  2030. this.templateID = pvutils.getParametersValue(parameters, TEMPLATE_ID, CertificateTemplate.defaultValues(TEMPLATE_ID));
  2031. if (TEMPLATE_MAJOR_VERSION in parameters) {
  2032. this.templateMajorVersion = pvutils.getParametersValue(parameters, TEMPLATE_MAJOR_VERSION, CertificateTemplate.defaultValues(TEMPLATE_MAJOR_VERSION));
  2033. }
  2034. if (TEMPLATE_MINOR_VERSION in parameters) {
  2035. this.templateMinorVersion = pvutils.getParametersValue(parameters, TEMPLATE_MINOR_VERSION, CertificateTemplate.defaultValues(TEMPLATE_MINOR_VERSION));
  2036. }
  2037. if (parameters.schema) {
  2038. this.fromSchema(parameters.schema);
  2039. }
  2040. }
  2041. static defaultValues(memberName) {
  2042. switch (memberName) {
  2043. case TEMPLATE_ID:
  2044. return EMPTY_STRING;
  2045. case TEMPLATE_MAJOR_VERSION:
  2046. case TEMPLATE_MINOR_VERSION:
  2047. return 0;
  2048. default:
  2049. return super.defaultValues(memberName);
  2050. }
  2051. }
  2052. static schema(parameters = {}) {
  2053. const names = pvutils.getParametersValue(parameters, "names", {});
  2054. return (new asn1js.Sequence({
  2055. name: (names.blockName || EMPTY_STRING),
  2056. value: [
  2057. new asn1js.ObjectIdentifier({ name: (names.templateID || EMPTY_STRING) }),
  2058. new asn1js.Integer({
  2059. name: (names.templateMajorVersion || EMPTY_STRING),
  2060. optional: true
  2061. }),
  2062. new asn1js.Integer({
  2063. name: (names.templateMinorVersion || EMPTY_STRING),
  2064. optional: true
  2065. }),
  2066. ]
  2067. }));
  2068. }
  2069. fromSchema(schema) {
  2070. pvutils.clearProps(schema, CLEAR_PROPS$1m);
  2071. const asn1 = asn1js.compareSchema(schema, schema, CertificateTemplate.schema({
  2072. names: {
  2073. templateID: TEMPLATE_ID,
  2074. templateMajorVersion: TEMPLATE_MAJOR_VERSION,
  2075. templateMinorVersion: TEMPLATE_MINOR_VERSION
  2076. }
  2077. }));
  2078. AsnError.assertSchema(asn1, this.className);
  2079. this.templateID = asn1.result.templateID.valueBlock.toString();
  2080. if (TEMPLATE_MAJOR_VERSION in asn1.result) {
  2081. this.templateMajorVersion = asn1.result.templateMajorVersion.valueBlock.valueDec;
  2082. }
  2083. if (TEMPLATE_MINOR_VERSION in asn1.result) {
  2084. this.templateMinorVersion = asn1.result.templateMinorVersion.valueBlock.valueDec;
  2085. }
  2086. }
  2087. toSchema() {
  2088. const outputArray = [];
  2089. outputArray.push(new asn1js.ObjectIdentifier({ value: this.templateID }));
  2090. if (TEMPLATE_MAJOR_VERSION in this) {
  2091. outputArray.push(new asn1js.Integer({ value: this.templateMajorVersion }));
  2092. }
  2093. if (TEMPLATE_MINOR_VERSION in this) {
  2094. outputArray.push(new asn1js.Integer({ value: this.templateMinorVersion }));
  2095. }
  2096. return (new asn1js.Sequence({
  2097. value: outputArray
  2098. }));
  2099. }
  2100. toJSON() {
  2101. const res = {
  2102. templateID: this.templateID
  2103. };
  2104. if (TEMPLATE_MAJOR_VERSION in this)
  2105. res.templateMajorVersion = this.templateMajorVersion;
  2106. if (TEMPLATE_MINOR_VERSION in this)
  2107. res.templateMinorVersion = this.templateMinorVersion;
  2108. return res;
  2109. }
  2110. }
  2111. const DISTRIBUTION_POINT$1 = "distributionPoint";
  2112. const DISTRIBUTION_POINT_NAMES$1 = "distributionPointNames";
  2113. const REASONS = "reasons";
  2114. const CRL_ISSUER = "cRLIssuer";
  2115. const CRL_ISSUER_NAMES = "cRLIssuerNames";
  2116. const CLEAR_PROPS$1l = [
  2117. DISTRIBUTION_POINT$1,
  2118. DISTRIBUTION_POINT_NAMES$1,
  2119. REASONS,
  2120. CRL_ISSUER,
  2121. CRL_ISSUER_NAMES,
  2122. ];
  2123. class DistributionPoint extends PkiObject {
  2124. constructor(parameters = {}) {
  2125. super();
  2126. if (DISTRIBUTION_POINT$1 in parameters) {
  2127. this.distributionPoint = pvutils.getParametersValue(parameters, DISTRIBUTION_POINT$1, DistributionPoint.defaultValues(DISTRIBUTION_POINT$1));
  2128. }
  2129. if (REASONS in parameters) {
  2130. this.reasons = pvutils.getParametersValue(parameters, REASONS, DistributionPoint.defaultValues(REASONS));
  2131. }
  2132. if (CRL_ISSUER in parameters) {
  2133. this.cRLIssuer = pvutils.getParametersValue(parameters, CRL_ISSUER, DistributionPoint.defaultValues(CRL_ISSUER));
  2134. }
  2135. if (parameters.schema) {
  2136. this.fromSchema(parameters.schema);
  2137. }
  2138. }
  2139. static defaultValues(memberName) {
  2140. switch (memberName) {
  2141. case DISTRIBUTION_POINT$1:
  2142. return [];
  2143. case REASONS:
  2144. return new asn1js.BitString();
  2145. case CRL_ISSUER:
  2146. return [];
  2147. default:
  2148. return super.defaultValues(memberName);
  2149. }
  2150. }
  2151. static schema(parameters = {}) {
  2152. const names = pvutils.getParametersValue(parameters, "names", {});
  2153. return (new asn1js.Sequence({
  2154. name: (names.blockName || EMPTY_STRING),
  2155. value: [
  2156. new asn1js.Constructed({
  2157. optional: true,
  2158. idBlock: {
  2159. tagClass: 3,
  2160. tagNumber: 0
  2161. },
  2162. value: [
  2163. new asn1js.Choice({
  2164. value: [
  2165. new asn1js.Constructed({
  2166. name: (names.distributionPoint || EMPTY_STRING),
  2167. optional: true,
  2168. idBlock: {
  2169. tagClass: 3,
  2170. tagNumber: 0
  2171. },
  2172. value: [
  2173. new asn1js.Repeated({
  2174. name: (names.distributionPointNames || EMPTY_STRING),
  2175. value: GeneralName.schema()
  2176. })
  2177. ]
  2178. }),
  2179. new asn1js.Constructed({
  2180. name: (names.distributionPoint || EMPTY_STRING),
  2181. optional: true,
  2182. idBlock: {
  2183. tagClass: 3,
  2184. tagNumber: 1
  2185. },
  2186. value: RelativeDistinguishedNames.schema().valueBlock.value
  2187. })
  2188. ]
  2189. })
  2190. ]
  2191. }),
  2192. new asn1js.Primitive({
  2193. name: (names.reasons || EMPTY_STRING),
  2194. optional: true,
  2195. idBlock: {
  2196. tagClass: 3,
  2197. tagNumber: 1
  2198. }
  2199. }),
  2200. new asn1js.Constructed({
  2201. name: (names.cRLIssuer || EMPTY_STRING),
  2202. optional: true,
  2203. idBlock: {
  2204. tagClass: 3,
  2205. tagNumber: 2
  2206. },
  2207. value: [
  2208. new asn1js.Repeated({
  2209. name: (names.cRLIssuerNames || EMPTY_STRING),
  2210. value: GeneralName.schema()
  2211. })
  2212. ]
  2213. })
  2214. ]
  2215. }));
  2216. }
  2217. fromSchema(schema) {
  2218. pvutils.clearProps(schema, CLEAR_PROPS$1l);
  2219. const asn1 = asn1js.compareSchema(schema, schema, DistributionPoint.schema({
  2220. names: {
  2221. distributionPoint: DISTRIBUTION_POINT$1,
  2222. distributionPointNames: DISTRIBUTION_POINT_NAMES$1,
  2223. reasons: REASONS,
  2224. cRLIssuer: CRL_ISSUER,
  2225. cRLIssuerNames: CRL_ISSUER_NAMES
  2226. }
  2227. }));
  2228. AsnError.assertSchema(asn1, this.className);
  2229. if (DISTRIBUTION_POINT$1 in asn1.result) {
  2230. if (asn1.result.distributionPoint.idBlock.tagNumber === 0) {
  2231. this.distributionPoint = Array.from(asn1.result.distributionPointNames, element => new GeneralName({ schema: element }));
  2232. }
  2233. if (asn1.result.distributionPoint.idBlock.tagNumber === 1) {
  2234. this.distributionPoint = new RelativeDistinguishedNames({
  2235. schema: new asn1js.Sequence({
  2236. value: asn1.result.distributionPoint.valueBlock.value
  2237. })
  2238. });
  2239. }
  2240. }
  2241. if (REASONS in asn1.result) {
  2242. this.reasons = new asn1js.BitString({ valueHex: asn1.result.reasons.valueBlock.valueHex });
  2243. }
  2244. if (CRL_ISSUER in asn1.result) {
  2245. this.cRLIssuer = Array.from(asn1.result.cRLIssuerNames, element => new GeneralName({ schema: element }));
  2246. }
  2247. }
  2248. toSchema() {
  2249. const outputArray = [];
  2250. if (this.distributionPoint) {
  2251. let internalValue;
  2252. if (this.distributionPoint instanceof Array) {
  2253. internalValue = new asn1js.Constructed({
  2254. idBlock: {
  2255. tagClass: 3,
  2256. tagNumber: 0
  2257. },
  2258. value: Array.from(this.distributionPoint, o => o.toSchema())
  2259. });
  2260. }
  2261. else {
  2262. internalValue = new asn1js.Constructed({
  2263. idBlock: {
  2264. tagClass: 3,
  2265. tagNumber: 1
  2266. },
  2267. value: [this.distributionPoint.toSchema()]
  2268. });
  2269. }
  2270. outputArray.push(new asn1js.Constructed({
  2271. idBlock: {
  2272. tagClass: 3,
  2273. tagNumber: 0
  2274. },
  2275. value: [internalValue]
  2276. }));
  2277. }
  2278. if (this.reasons) {
  2279. outputArray.push(new asn1js.Primitive({
  2280. idBlock: {
  2281. tagClass: 3,
  2282. tagNumber: 1
  2283. },
  2284. valueHex: this.reasons.valueBlock.valueHexView
  2285. }));
  2286. }
  2287. if (this.cRLIssuer) {
  2288. outputArray.push(new asn1js.Constructed({
  2289. idBlock: {
  2290. tagClass: 3,
  2291. tagNumber: 2
  2292. },
  2293. value: Array.from(this.cRLIssuer, o => o.toSchema())
  2294. }));
  2295. }
  2296. return (new asn1js.Sequence({
  2297. value: outputArray
  2298. }));
  2299. }
  2300. toJSON() {
  2301. const object = {};
  2302. if (this.distributionPoint) {
  2303. if (this.distributionPoint instanceof Array) {
  2304. object.distributionPoint = Array.from(this.distributionPoint, o => o.toJSON());
  2305. }
  2306. else {
  2307. object.distributionPoint = this.distributionPoint.toJSON();
  2308. }
  2309. }
  2310. if (this.reasons) {
  2311. object.reasons = this.reasons.toJSON();
  2312. }
  2313. if (this.cRLIssuer) {
  2314. object.cRLIssuer = Array.from(this.cRLIssuer, o => o.toJSON());
  2315. }
  2316. return object;
  2317. }
  2318. }
  2319. DistributionPoint.CLASS_NAME = "DistributionPoint";
  2320. const DISTRIBUTION_POINTS = "distributionPoints";
  2321. const CLEAR_PROPS$1k = [
  2322. DISTRIBUTION_POINTS
  2323. ];
  2324. class CRLDistributionPoints extends PkiObject {
  2325. constructor(parameters = {}) {
  2326. super();
  2327. this.distributionPoints = pvutils.getParametersValue(parameters, DISTRIBUTION_POINTS, CRLDistributionPoints.defaultValues(DISTRIBUTION_POINTS));
  2328. if (parameters.schema) {
  2329. this.fromSchema(parameters.schema);
  2330. }
  2331. }
  2332. static defaultValues(memberName) {
  2333. switch (memberName) {
  2334. case DISTRIBUTION_POINTS:
  2335. return [];
  2336. default:
  2337. return super.defaultValues(memberName);
  2338. }
  2339. }
  2340. static schema(parameters = {}) {
  2341. const names = pvutils.getParametersValue(parameters, "names", {});
  2342. return (new asn1js.Sequence({
  2343. name: (names.blockName || EMPTY_STRING),
  2344. value: [
  2345. new asn1js.Repeated({
  2346. name: (names.distributionPoints || EMPTY_STRING),
  2347. value: DistributionPoint.schema()
  2348. })
  2349. ]
  2350. }));
  2351. }
  2352. fromSchema(schema) {
  2353. pvutils.clearProps(schema, CLEAR_PROPS$1k);
  2354. const asn1 = asn1js.compareSchema(schema, schema, CRLDistributionPoints.schema({
  2355. names: {
  2356. distributionPoints: DISTRIBUTION_POINTS
  2357. }
  2358. }));
  2359. AsnError.assertSchema(asn1, this.className);
  2360. this.distributionPoints = Array.from(asn1.result.distributionPoints, element => new DistributionPoint({ schema: element }));
  2361. }
  2362. toSchema() {
  2363. return (new asn1js.Sequence({
  2364. value: Array.from(this.distributionPoints, o => o.toSchema())
  2365. }));
  2366. }
  2367. toJSON() {
  2368. return {
  2369. distributionPoints: Array.from(this.distributionPoints, o => o.toJSON())
  2370. };
  2371. }
  2372. }
  2373. CRLDistributionPoints.CLASS_NAME = "CRLDistributionPoints";
  2374. const KEY_PURPOSES = "keyPurposes";
  2375. const CLEAR_PROPS$1j = [
  2376. KEY_PURPOSES,
  2377. ];
  2378. class ExtKeyUsage extends PkiObject {
  2379. constructor(parameters = {}) {
  2380. super();
  2381. this.keyPurposes = pvutils.getParametersValue(parameters, KEY_PURPOSES, ExtKeyUsage.defaultValues(KEY_PURPOSES));
  2382. if (parameters.schema) {
  2383. this.fromSchema(parameters.schema);
  2384. }
  2385. }
  2386. static defaultValues(memberName) {
  2387. switch (memberName) {
  2388. case KEY_PURPOSES:
  2389. return [];
  2390. default:
  2391. return super.defaultValues(memberName);
  2392. }
  2393. }
  2394. static schema(parameters = {}) {
  2395. const names = pvutils.getParametersValue(parameters, "names", {});
  2396. return (new asn1js.Sequence({
  2397. name: (names.blockName || EMPTY_STRING),
  2398. value: [
  2399. new asn1js.Repeated({
  2400. name: (names.keyPurposes || EMPTY_STRING),
  2401. value: new asn1js.ObjectIdentifier()
  2402. })
  2403. ]
  2404. }));
  2405. }
  2406. fromSchema(schema) {
  2407. pvutils.clearProps(schema, CLEAR_PROPS$1j);
  2408. const asn1 = asn1js.compareSchema(schema, schema, ExtKeyUsage.schema({
  2409. names: {
  2410. keyPurposes: KEY_PURPOSES
  2411. }
  2412. }));
  2413. AsnError.assertSchema(asn1, this.className);
  2414. this.keyPurposes = Array.from(asn1.result.keyPurposes, (element) => element.valueBlock.toString());
  2415. }
  2416. toSchema() {
  2417. return (new asn1js.Sequence({
  2418. value: Array.from(this.keyPurposes, element => new asn1js.ObjectIdentifier({ value: element }))
  2419. }));
  2420. }
  2421. toJSON() {
  2422. return {
  2423. keyPurposes: Array.from(this.keyPurposes)
  2424. };
  2425. }
  2426. }
  2427. ExtKeyUsage.CLASS_NAME = "ExtKeyUsage";
  2428. const ACCESS_DESCRIPTIONS = "accessDescriptions";
  2429. class InfoAccess extends PkiObject {
  2430. constructor(parameters = {}) {
  2431. super();
  2432. this.accessDescriptions = pvutils.getParametersValue(parameters, ACCESS_DESCRIPTIONS, InfoAccess.defaultValues(ACCESS_DESCRIPTIONS));
  2433. if (parameters.schema) {
  2434. this.fromSchema(parameters.schema);
  2435. }
  2436. }
  2437. static defaultValues(memberName) {
  2438. switch (memberName) {
  2439. case ACCESS_DESCRIPTIONS:
  2440. return [];
  2441. default:
  2442. return super.defaultValues(memberName);
  2443. }
  2444. }
  2445. static schema(parameters = {}) {
  2446. const names = pvutils.getParametersValue(parameters, "names", {});
  2447. return (new asn1js.Sequence({
  2448. name: (names.blockName || EMPTY_STRING),
  2449. value: [
  2450. new asn1js.Repeated({
  2451. name: (names.accessDescriptions || EMPTY_STRING),
  2452. value: AccessDescription.schema()
  2453. })
  2454. ]
  2455. }));
  2456. }
  2457. fromSchema(schema) {
  2458. pvutils.clearProps(schema, [
  2459. ACCESS_DESCRIPTIONS
  2460. ]);
  2461. const asn1 = asn1js.compareSchema(schema, schema, InfoAccess.schema({
  2462. names: {
  2463. accessDescriptions: ACCESS_DESCRIPTIONS
  2464. }
  2465. }));
  2466. AsnError.assertSchema(asn1, this.className);
  2467. this.accessDescriptions = Array.from(asn1.result.accessDescriptions, element => new AccessDescription({ schema: element }));
  2468. }
  2469. toSchema() {
  2470. return (new asn1js.Sequence({
  2471. value: Array.from(this.accessDescriptions, o => o.toSchema())
  2472. }));
  2473. }
  2474. toJSON() {
  2475. return {
  2476. accessDescriptions: Array.from(this.accessDescriptions, o => o.toJSON())
  2477. };
  2478. }
  2479. }
  2480. InfoAccess.CLASS_NAME = "InfoAccess";
  2481. const DISTRIBUTION_POINT = "distributionPoint";
  2482. const DISTRIBUTION_POINT_NAMES = "distributionPointNames";
  2483. const ONLY_CONTAINS_USER_CERTS = "onlyContainsUserCerts";
  2484. const ONLY_CONTAINS_CA_CERTS = "onlyContainsCACerts";
  2485. const ONLY_SOME_REASON = "onlySomeReasons";
  2486. const INDIRECT_CRL = "indirectCRL";
  2487. const ONLY_CONTAINS_ATTRIBUTE_CERTS = "onlyContainsAttributeCerts";
  2488. const CLEAR_PROPS$1i = [
  2489. DISTRIBUTION_POINT,
  2490. DISTRIBUTION_POINT_NAMES,
  2491. ONLY_CONTAINS_USER_CERTS,
  2492. ONLY_CONTAINS_CA_CERTS,
  2493. ONLY_SOME_REASON,
  2494. INDIRECT_CRL,
  2495. ONLY_CONTAINS_ATTRIBUTE_CERTS,
  2496. ];
  2497. class IssuingDistributionPoint extends PkiObject {
  2498. constructor(parameters = {}) {
  2499. super();
  2500. if (DISTRIBUTION_POINT in parameters) {
  2501. this.distributionPoint = pvutils.getParametersValue(parameters, DISTRIBUTION_POINT, IssuingDistributionPoint.defaultValues(DISTRIBUTION_POINT));
  2502. }
  2503. this.onlyContainsUserCerts = pvutils.getParametersValue(parameters, ONLY_CONTAINS_USER_CERTS, IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_USER_CERTS));
  2504. this.onlyContainsCACerts = pvutils.getParametersValue(parameters, ONLY_CONTAINS_CA_CERTS, IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_CA_CERTS));
  2505. if (ONLY_SOME_REASON in parameters) {
  2506. this.onlySomeReasons = pvutils.getParametersValue(parameters, ONLY_SOME_REASON, IssuingDistributionPoint.defaultValues(ONLY_SOME_REASON));
  2507. }
  2508. this.indirectCRL = pvutils.getParametersValue(parameters, INDIRECT_CRL, IssuingDistributionPoint.defaultValues(INDIRECT_CRL));
  2509. this.onlyContainsAttributeCerts = pvutils.getParametersValue(parameters, ONLY_CONTAINS_ATTRIBUTE_CERTS, IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_ATTRIBUTE_CERTS));
  2510. if (parameters.schema) {
  2511. this.fromSchema(parameters.schema);
  2512. }
  2513. }
  2514. static defaultValues(memberName) {
  2515. switch (memberName) {
  2516. case DISTRIBUTION_POINT:
  2517. return [];
  2518. case ONLY_CONTAINS_USER_CERTS:
  2519. return false;
  2520. case ONLY_CONTAINS_CA_CERTS:
  2521. return false;
  2522. case ONLY_SOME_REASON:
  2523. return 0;
  2524. case INDIRECT_CRL:
  2525. return false;
  2526. case ONLY_CONTAINS_ATTRIBUTE_CERTS:
  2527. return false;
  2528. default:
  2529. return super.defaultValues(memberName);
  2530. }
  2531. }
  2532. static schema(parameters = {}) {
  2533. const names = pvutils.getParametersValue(parameters, "names", {});
  2534. return (new asn1js.Sequence({
  2535. name: (names.blockName || EMPTY_STRING),
  2536. value: [
  2537. new asn1js.Constructed({
  2538. optional: true,
  2539. idBlock: {
  2540. tagClass: 3,
  2541. tagNumber: 0
  2542. },
  2543. value: [
  2544. new asn1js.Choice({
  2545. value: [
  2546. new asn1js.Constructed({
  2547. name: (names.distributionPoint || EMPTY_STRING),
  2548. idBlock: {
  2549. tagClass: 3,
  2550. tagNumber: 0
  2551. },
  2552. value: [
  2553. new asn1js.Repeated({
  2554. name: (names.distributionPointNames || EMPTY_STRING),
  2555. value: GeneralName.schema()
  2556. })
  2557. ]
  2558. }),
  2559. new asn1js.Constructed({
  2560. name: (names.distributionPoint || EMPTY_STRING),
  2561. idBlock: {
  2562. tagClass: 3,
  2563. tagNumber: 1
  2564. },
  2565. value: RelativeDistinguishedNames.schema().valueBlock.value
  2566. })
  2567. ]
  2568. })
  2569. ]
  2570. }),
  2571. new asn1js.Primitive({
  2572. name: (names.onlyContainsUserCerts || EMPTY_STRING),
  2573. optional: true,
  2574. idBlock: {
  2575. tagClass: 3,
  2576. tagNumber: 1
  2577. }
  2578. }),
  2579. new asn1js.Primitive({
  2580. name: (names.onlyContainsCACerts || EMPTY_STRING),
  2581. optional: true,
  2582. idBlock: {
  2583. tagClass: 3,
  2584. tagNumber: 2
  2585. }
  2586. }),
  2587. new asn1js.Primitive({
  2588. name: (names.onlySomeReasons || EMPTY_STRING),
  2589. optional: true,
  2590. idBlock: {
  2591. tagClass: 3,
  2592. tagNumber: 3
  2593. }
  2594. }),
  2595. new asn1js.Primitive({
  2596. name: (names.indirectCRL || EMPTY_STRING),
  2597. optional: true,
  2598. idBlock: {
  2599. tagClass: 3,
  2600. tagNumber: 4
  2601. }
  2602. }),
  2603. new asn1js.Primitive({
  2604. name: (names.onlyContainsAttributeCerts || EMPTY_STRING),
  2605. optional: true,
  2606. idBlock: {
  2607. tagClass: 3,
  2608. tagNumber: 5
  2609. }
  2610. })
  2611. ]
  2612. }));
  2613. }
  2614. fromSchema(schema) {
  2615. pvutils.clearProps(schema, CLEAR_PROPS$1i);
  2616. const asn1 = asn1js.compareSchema(schema, schema, IssuingDistributionPoint.schema({
  2617. names: {
  2618. distributionPoint: DISTRIBUTION_POINT,
  2619. distributionPointNames: DISTRIBUTION_POINT_NAMES,
  2620. onlyContainsUserCerts: ONLY_CONTAINS_USER_CERTS,
  2621. onlyContainsCACerts: ONLY_CONTAINS_CA_CERTS,
  2622. onlySomeReasons: ONLY_SOME_REASON,
  2623. indirectCRL: INDIRECT_CRL,
  2624. onlyContainsAttributeCerts: ONLY_CONTAINS_ATTRIBUTE_CERTS
  2625. }
  2626. }));
  2627. AsnError.assertSchema(asn1, this.className);
  2628. if (DISTRIBUTION_POINT in asn1.result) {
  2629. switch (true) {
  2630. case (asn1.result.distributionPoint.idBlock.tagNumber === 0):
  2631. this.distributionPoint = Array.from(asn1.result.distributionPointNames, element => new GeneralName({ schema: element }));
  2632. break;
  2633. case (asn1.result.distributionPoint.idBlock.tagNumber === 1):
  2634. {
  2635. this.distributionPoint = new RelativeDistinguishedNames({
  2636. schema: new asn1js.Sequence({
  2637. value: asn1.result.distributionPoint.valueBlock.value
  2638. })
  2639. });
  2640. }
  2641. break;
  2642. default:
  2643. throw new Error("Unknown tagNumber for distributionPoint: {$asn1.result.distributionPoint.idBlock.tagNumber}");
  2644. }
  2645. }
  2646. if (ONLY_CONTAINS_USER_CERTS in asn1.result) {
  2647. const view = new Uint8Array(asn1.result.onlyContainsUserCerts.valueBlock.valueHex);
  2648. this.onlyContainsUserCerts = (view[0] !== 0x00);
  2649. }
  2650. if (ONLY_CONTAINS_CA_CERTS in asn1.result) {
  2651. const view = new Uint8Array(asn1.result.onlyContainsCACerts.valueBlock.valueHex);
  2652. this.onlyContainsCACerts = (view[0] !== 0x00);
  2653. }
  2654. if (ONLY_SOME_REASON in asn1.result) {
  2655. const view = new Uint8Array(asn1.result.onlySomeReasons.valueBlock.valueHex);
  2656. this.onlySomeReasons = view[0];
  2657. }
  2658. if (INDIRECT_CRL in asn1.result) {
  2659. const view = new Uint8Array(asn1.result.indirectCRL.valueBlock.valueHex);
  2660. this.indirectCRL = (view[0] !== 0x00);
  2661. }
  2662. if (ONLY_CONTAINS_ATTRIBUTE_CERTS in asn1.result) {
  2663. const view = new Uint8Array(asn1.result.onlyContainsAttributeCerts.valueBlock.valueHex);
  2664. this.onlyContainsAttributeCerts = (view[0] !== 0x00);
  2665. }
  2666. }
  2667. toSchema() {
  2668. const outputArray = [];
  2669. if (this.distributionPoint) {
  2670. let value;
  2671. if (this.distributionPoint instanceof Array) {
  2672. value = new asn1js.Constructed({
  2673. idBlock: {
  2674. tagClass: 3,
  2675. tagNumber: 0
  2676. },
  2677. value: Array.from(this.distributionPoint, o => o.toSchema())
  2678. });
  2679. }
  2680. else {
  2681. value = this.distributionPoint.toSchema();
  2682. value.idBlock.tagClass = 3;
  2683. value.idBlock.tagNumber = 1;
  2684. }
  2685. outputArray.push(new asn1js.Constructed({
  2686. idBlock: {
  2687. tagClass: 3,
  2688. tagNumber: 0
  2689. },
  2690. value: [value]
  2691. }));
  2692. }
  2693. if (this.onlyContainsUserCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_USER_CERTS)) {
  2694. outputArray.push(new asn1js.Primitive({
  2695. idBlock: {
  2696. tagClass: 3,
  2697. tagNumber: 1
  2698. },
  2699. valueHex: (new Uint8Array([0xFF])).buffer
  2700. }));
  2701. }
  2702. if (this.onlyContainsCACerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_CA_CERTS)) {
  2703. outputArray.push(new asn1js.Primitive({
  2704. idBlock: {
  2705. tagClass: 3,
  2706. tagNumber: 2
  2707. },
  2708. valueHex: (new Uint8Array([0xFF])).buffer
  2709. }));
  2710. }
  2711. if (this.onlySomeReasons !== undefined) {
  2712. const buffer = new ArrayBuffer(1);
  2713. const view = new Uint8Array(buffer);
  2714. view[0] = this.onlySomeReasons;
  2715. outputArray.push(new asn1js.Primitive({
  2716. idBlock: {
  2717. tagClass: 3,
  2718. tagNumber: 3
  2719. },
  2720. valueHex: buffer
  2721. }));
  2722. }
  2723. if (this.indirectCRL !== IssuingDistributionPoint.defaultValues(INDIRECT_CRL)) {
  2724. outputArray.push(new asn1js.Primitive({
  2725. idBlock: {
  2726. tagClass: 3,
  2727. tagNumber: 4
  2728. },
  2729. valueHex: (new Uint8Array([0xFF])).buffer
  2730. }));
  2731. }
  2732. if (this.onlyContainsAttributeCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_ATTRIBUTE_CERTS)) {
  2733. outputArray.push(new asn1js.Primitive({
  2734. idBlock: {
  2735. tagClass: 3,
  2736. tagNumber: 5
  2737. },
  2738. valueHex: (new Uint8Array([0xFF])).buffer
  2739. }));
  2740. }
  2741. return (new asn1js.Sequence({
  2742. value: outputArray
  2743. }));
  2744. }
  2745. toJSON() {
  2746. const obj = {};
  2747. if (this.distributionPoint) {
  2748. if (this.distributionPoint instanceof Array) {
  2749. obj.distributionPoint = Array.from(this.distributionPoint, o => o.toJSON());
  2750. }
  2751. else {
  2752. obj.distributionPoint = this.distributionPoint.toJSON();
  2753. }
  2754. }
  2755. if (this.onlyContainsUserCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_USER_CERTS)) {
  2756. obj.onlyContainsUserCerts = this.onlyContainsUserCerts;
  2757. }
  2758. if (this.onlyContainsCACerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_CA_CERTS)) {
  2759. obj.onlyContainsCACerts = this.onlyContainsCACerts;
  2760. }
  2761. if (ONLY_SOME_REASON in this) {
  2762. obj.onlySomeReasons = this.onlySomeReasons;
  2763. }
  2764. if (this.indirectCRL !== IssuingDistributionPoint.defaultValues(INDIRECT_CRL)) {
  2765. obj.indirectCRL = this.indirectCRL;
  2766. }
  2767. if (this.onlyContainsAttributeCerts !== IssuingDistributionPoint.defaultValues(ONLY_CONTAINS_ATTRIBUTE_CERTS)) {
  2768. obj.onlyContainsAttributeCerts = this.onlyContainsAttributeCerts;
  2769. }
  2770. return obj;
  2771. }
  2772. }
  2773. IssuingDistributionPoint.CLASS_NAME = "IssuingDistributionPoint";
  2774. const BASE = "base";
  2775. const MINIMUM = "minimum";
  2776. const MAXIMUM = "maximum";
  2777. const CLEAR_PROPS$1h = [
  2778. BASE,
  2779. MINIMUM,
  2780. MAXIMUM
  2781. ];
  2782. class GeneralSubtree extends PkiObject {
  2783. constructor(parameters = {}) {
  2784. super();
  2785. this.base = pvutils.getParametersValue(parameters, BASE, GeneralSubtree.defaultValues(BASE));
  2786. this.minimum = pvutils.getParametersValue(parameters, MINIMUM, GeneralSubtree.defaultValues(MINIMUM));
  2787. if (MAXIMUM in parameters) {
  2788. this.maximum = pvutils.getParametersValue(parameters, MAXIMUM, GeneralSubtree.defaultValues(MAXIMUM));
  2789. }
  2790. if (parameters.schema) {
  2791. this.fromSchema(parameters.schema);
  2792. }
  2793. }
  2794. static defaultValues(memberName) {
  2795. switch (memberName) {
  2796. case BASE:
  2797. return new GeneralName();
  2798. case MINIMUM:
  2799. return 0;
  2800. case MAXIMUM:
  2801. return 0;
  2802. default:
  2803. return super.defaultValues(memberName);
  2804. }
  2805. }
  2806. static schema(parameters = {}) {
  2807. const names = pvutils.getParametersValue(parameters, "names", {});
  2808. return (new asn1js.Sequence({
  2809. name: (names.blockName || EMPTY_STRING),
  2810. value: [
  2811. GeneralName.schema(names.base || {}),
  2812. new asn1js.Constructed({
  2813. optional: true,
  2814. idBlock: {
  2815. tagClass: 3,
  2816. tagNumber: 0
  2817. },
  2818. value: [new asn1js.Integer({ name: (names.minimum || EMPTY_STRING) })]
  2819. }),
  2820. new asn1js.Constructed({
  2821. optional: true,
  2822. idBlock: {
  2823. tagClass: 3,
  2824. tagNumber: 1
  2825. },
  2826. value: [new asn1js.Integer({ name: (names.maximum || EMPTY_STRING) })]
  2827. })
  2828. ]
  2829. }));
  2830. }
  2831. fromSchema(schema) {
  2832. pvutils.clearProps(schema, CLEAR_PROPS$1h);
  2833. const asn1 = asn1js.compareSchema(schema, schema, GeneralSubtree.schema({
  2834. names: {
  2835. base: {
  2836. names: {
  2837. blockName: BASE
  2838. }
  2839. },
  2840. minimum: MINIMUM,
  2841. maximum: MAXIMUM
  2842. }
  2843. }));
  2844. AsnError.assertSchema(asn1, this.className);
  2845. this.base = new GeneralName({ schema: asn1.result.base });
  2846. if (MINIMUM in asn1.result) {
  2847. if (asn1.result.minimum.valueBlock.isHexOnly)
  2848. this.minimum = asn1.result.minimum;
  2849. else
  2850. this.minimum = asn1.result.minimum.valueBlock.valueDec;
  2851. }
  2852. if (MAXIMUM in asn1.result) {
  2853. if (asn1.result.maximum.valueBlock.isHexOnly)
  2854. this.maximum = asn1.result.maximum;
  2855. else
  2856. this.maximum = asn1.result.maximum.valueBlock.valueDec;
  2857. }
  2858. }
  2859. toSchema() {
  2860. const outputArray = [];
  2861. outputArray.push(this.base.toSchema());
  2862. if (this.minimum !== 0) {
  2863. let valueMinimum = 0;
  2864. if (this.minimum instanceof asn1js.Integer) {
  2865. valueMinimum = this.minimum;
  2866. }
  2867. else {
  2868. valueMinimum = new asn1js.Integer({ value: this.minimum });
  2869. }
  2870. outputArray.push(new asn1js.Constructed({
  2871. optional: true,
  2872. idBlock: {
  2873. tagClass: 3,
  2874. tagNumber: 0
  2875. },
  2876. value: [valueMinimum]
  2877. }));
  2878. }
  2879. if (MAXIMUM in this) {
  2880. let valueMaximum = 0;
  2881. if (this.maximum instanceof asn1js.Integer) {
  2882. valueMaximum = this.maximum;
  2883. }
  2884. else {
  2885. valueMaximum = new asn1js.Integer({ value: this.maximum });
  2886. }
  2887. outputArray.push(new asn1js.Constructed({
  2888. optional: true,
  2889. idBlock: {
  2890. tagClass: 3,
  2891. tagNumber: 1
  2892. },
  2893. value: [valueMaximum]
  2894. }));
  2895. }
  2896. return (new asn1js.Sequence({
  2897. value: outputArray
  2898. }));
  2899. }
  2900. toJSON() {
  2901. const res = {
  2902. base: this.base.toJSON()
  2903. };
  2904. if (this.minimum !== 0) {
  2905. if (typeof this.minimum === "number") {
  2906. res.minimum = this.minimum;
  2907. }
  2908. else {
  2909. res.minimum = this.minimum.toJSON();
  2910. }
  2911. }
  2912. if (this.maximum !== undefined) {
  2913. if (typeof this.maximum === "number") {
  2914. res.maximum = this.maximum;
  2915. }
  2916. else {
  2917. res.maximum = this.maximum.toJSON();
  2918. }
  2919. }
  2920. return res;
  2921. }
  2922. }
  2923. GeneralSubtree.CLASS_NAME = "GeneralSubtree";
  2924. const PERMITTED_SUBTREES = "permittedSubtrees";
  2925. const EXCLUDED_SUBTREES = "excludedSubtrees";
  2926. const CLEAR_PROPS$1g = [
  2927. PERMITTED_SUBTREES,
  2928. EXCLUDED_SUBTREES
  2929. ];
  2930. class NameConstraints extends PkiObject {
  2931. constructor(parameters = {}) {
  2932. super();
  2933. if (PERMITTED_SUBTREES in parameters) {
  2934. this.permittedSubtrees = pvutils.getParametersValue(parameters, PERMITTED_SUBTREES, NameConstraints.defaultValues(PERMITTED_SUBTREES));
  2935. }
  2936. if (EXCLUDED_SUBTREES in parameters) {
  2937. this.excludedSubtrees = pvutils.getParametersValue(parameters, EXCLUDED_SUBTREES, NameConstraints.defaultValues(EXCLUDED_SUBTREES));
  2938. }
  2939. if (parameters.schema) {
  2940. this.fromSchema(parameters.schema);
  2941. }
  2942. }
  2943. static defaultValues(memberName) {
  2944. switch (memberName) {
  2945. case PERMITTED_SUBTREES:
  2946. case EXCLUDED_SUBTREES:
  2947. return [];
  2948. default:
  2949. return super.defaultValues(memberName);
  2950. }
  2951. }
  2952. static schema(parameters = {}) {
  2953. const names = pvutils.getParametersValue(parameters, "names", {});
  2954. return (new asn1js.Sequence({
  2955. name: (names.blockName || EMPTY_STRING),
  2956. value: [
  2957. new asn1js.Constructed({
  2958. optional: true,
  2959. idBlock: {
  2960. tagClass: 3,
  2961. tagNumber: 0
  2962. },
  2963. value: [
  2964. new asn1js.Repeated({
  2965. name: (names.permittedSubtrees || EMPTY_STRING),
  2966. value: GeneralSubtree.schema()
  2967. })
  2968. ]
  2969. }),
  2970. new asn1js.Constructed({
  2971. optional: true,
  2972. idBlock: {
  2973. tagClass: 3,
  2974. tagNumber: 1
  2975. },
  2976. value: [
  2977. new asn1js.Repeated({
  2978. name: (names.excludedSubtrees || EMPTY_STRING),
  2979. value: GeneralSubtree.schema()
  2980. })
  2981. ]
  2982. })
  2983. ]
  2984. }));
  2985. }
  2986. fromSchema(schema) {
  2987. pvutils.clearProps(schema, CLEAR_PROPS$1g);
  2988. const asn1 = asn1js.compareSchema(schema, schema, NameConstraints.schema({
  2989. names: {
  2990. permittedSubtrees: PERMITTED_SUBTREES,
  2991. excludedSubtrees: EXCLUDED_SUBTREES
  2992. }
  2993. }));
  2994. AsnError.assertSchema(asn1, this.className);
  2995. if (PERMITTED_SUBTREES in asn1.result)
  2996. this.permittedSubtrees = Array.from(asn1.result.permittedSubtrees, element => new GeneralSubtree({ schema: element }));
  2997. if (EXCLUDED_SUBTREES in asn1.result)
  2998. this.excludedSubtrees = Array.from(asn1.result.excludedSubtrees, element => new GeneralSubtree({ schema: element }));
  2999. }
  3000. toSchema() {
  3001. const outputArray = [];
  3002. if (this.permittedSubtrees) {
  3003. outputArray.push(new asn1js.Constructed({
  3004. idBlock: {
  3005. tagClass: 3,
  3006. tagNumber: 0
  3007. },
  3008. value: Array.from(this.permittedSubtrees, o => o.toSchema())
  3009. }));
  3010. }
  3011. if (this.excludedSubtrees) {
  3012. outputArray.push(new asn1js.Constructed({
  3013. idBlock: {
  3014. tagClass: 3,
  3015. tagNumber: 1
  3016. },
  3017. value: Array.from(this.excludedSubtrees, o => o.toSchema())
  3018. }));
  3019. }
  3020. return (new asn1js.Sequence({
  3021. value: outputArray
  3022. }));
  3023. }
  3024. toJSON() {
  3025. const object = {};
  3026. if (this.permittedSubtrees) {
  3027. object.permittedSubtrees = Array.from(this.permittedSubtrees, o => o.toJSON());
  3028. }
  3029. if (this.excludedSubtrees) {
  3030. object.excludedSubtrees = Array.from(this.excludedSubtrees, o => o.toJSON());
  3031. }
  3032. return object;
  3033. }
  3034. }
  3035. NameConstraints.CLASS_NAME = "NameConstraints";
  3036. const REQUIRE_EXPLICIT_POLICY = "requireExplicitPolicy";
  3037. const INHIBIT_POLICY_MAPPING = "inhibitPolicyMapping";
  3038. const CLEAR_PROPS$1f = [
  3039. REQUIRE_EXPLICIT_POLICY,
  3040. INHIBIT_POLICY_MAPPING,
  3041. ];
  3042. class PolicyConstraints extends PkiObject {
  3043. constructor(parameters = {}) {
  3044. super();
  3045. if (REQUIRE_EXPLICIT_POLICY in parameters) {
  3046. this.requireExplicitPolicy = pvutils.getParametersValue(parameters, REQUIRE_EXPLICIT_POLICY, PolicyConstraints.defaultValues(REQUIRE_EXPLICIT_POLICY));
  3047. }
  3048. if (INHIBIT_POLICY_MAPPING in parameters) {
  3049. this.inhibitPolicyMapping = pvutils.getParametersValue(parameters, INHIBIT_POLICY_MAPPING, PolicyConstraints.defaultValues(INHIBIT_POLICY_MAPPING));
  3050. }
  3051. if (parameters.schema) {
  3052. this.fromSchema(parameters.schema);
  3053. }
  3054. }
  3055. static defaultValues(memberName) {
  3056. switch (memberName) {
  3057. case REQUIRE_EXPLICIT_POLICY:
  3058. return 0;
  3059. case INHIBIT_POLICY_MAPPING:
  3060. return 0;
  3061. default:
  3062. return super.defaultValues(memberName);
  3063. }
  3064. }
  3065. static schema(parameters = {}) {
  3066. const names = pvutils.getParametersValue(parameters, "names", {});
  3067. return (new asn1js.Sequence({
  3068. name: (names.blockName || EMPTY_STRING),
  3069. value: [
  3070. new asn1js.Primitive({
  3071. name: (names.requireExplicitPolicy || EMPTY_STRING),
  3072. optional: true,
  3073. idBlock: {
  3074. tagClass: 3,
  3075. tagNumber: 0
  3076. }
  3077. }),
  3078. new asn1js.Primitive({
  3079. name: (names.inhibitPolicyMapping || EMPTY_STRING),
  3080. optional: true,
  3081. idBlock: {
  3082. tagClass: 3,
  3083. tagNumber: 1
  3084. }
  3085. })
  3086. ]
  3087. }));
  3088. }
  3089. fromSchema(schema) {
  3090. pvutils.clearProps(schema, CLEAR_PROPS$1f);
  3091. const asn1 = asn1js.compareSchema(schema, schema, PolicyConstraints.schema({
  3092. names: {
  3093. requireExplicitPolicy: REQUIRE_EXPLICIT_POLICY,
  3094. inhibitPolicyMapping: INHIBIT_POLICY_MAPPING
  3095. }
  3096. }));
  3097. AsnError.assertSchema(asn1, this.className);
  3098. if (REQUIRE_EXPLICIT_POLICY in asn1.result) {
  3099. const field1 = asn1.result.requireExplicitPolicy;
  3100. field1.idBlock.tagClass = 1;
  3101. field1.idBlock.tagNumber = 2;
  3102. const ber1 = field1.toBER(false);
  3103. const int1 = asn1js.fromBER(ber1);
  3104. AsnError.assert(int1, "Integer");
  3105. this.requireExplicitPolicy = int1.result.valueBlock.valueDec;
  3106. }
  3107. if (INHIBIT_POLICY_MAPPING in asn1.result) {
  3108. const field2 = asn1.result.inhibitPolicyMapping;
  3109. field2.idBlock.tagClass = 1;
  3110. field2.idBlock.tagNumber = 2;
  3111. const ber2 = field2.toBER(false);
  3112. const int2 = asn1js.fromBER(ber2);
  3113. AsnError.assert(int2, "Integer");
  3114. this.inhibitPolicyMapping = int2.result.valueBlock.valueDec;
  3115. }
  3116. }
  3117. toSchema() {
  3118. const outputArray = [];
  3119. if (REQUIRE_EXPLICIT_POLICY in this) {
  3120. const int1 = new asn1js.Integer({ value: this.requireExplicitPolicy });
  3121. int1.idBlock.tagClass = 3;
  3122. int1.idBlock.tagNumber = 0;
  3123. outputArray.push(int1);
  3124. }
  3125. if (INHIBIT_POLICY_MAPPING in this) {
  3126. const int2 = new asn1js.Integer({ value: this.inhibitPolicyMapping });
  3127. int2.idBlock.tagClass = 3;
  3128. int2.idBlock.tagNumber = 1;
  3129. outputArray.push(int2);
  3130. }
  3131. return (new asn1js.Sequence({
  3132. value: outputArray
  3133. }));
  3134. }
  3135. toJSON() {
  3136. const res = {};
  3137. if (REQUIRE_EXPLICIT_POLICY in this) {
  3138. res.requireExplicitPolicy = this.requireExplicitPolicy;
  3139. }
  3140. if (INHIBIT_POLICY_MAPPING in this) {
  3141. res.inhibitPolicyMapping = this.inhibitPolicyMapping;
  3142. }
  3143. return res;
  3144. }
  3145. }
  3146. PolicyConstraints.CLASS_NAME = "PolicyConstraints";
  3147. const ISSUER_DOMAIN_POLICY = "issuerDomainPolicy";
  3148. const SUBJECT_DOMAIN_POLICY = "subjectDomainPolicy";
  3149. const CLEAR_PROPS$1e = [
  3150. ISSUER_DOMAIN_POLICY,
  3151. SUBJECT_DOMAIN_POLICY
  3152. ];
  3153. class PolicyMapping extends PkiObject {
  3154. constructor(parameters = {}) {
  3155. super();
  3156. this.issuerDomainPolicy = pvutils.getParametersValue(parameters, ISSUER_DOMAIN_POLICY, PolicyMapping.defaultValues(ISSUER_DOMAIN_POLICY));
  3157. this.subjectDomainPolicy = pvutils.getParametersValue(parameters, SUBJECT_DOMAIN_POLICY, PolicyMapping.defaultValues(SUBJECT_DOMAIN_POLICY));
  3158. if (parameters.schema) {
  3159. this.fromSchema(parameters.schema);
  3160. }
  3161. }
  3162. static defaultValues(memberName) {
  3163. switch (memberName) {
  3164. case ISSUER_DOMAIN_POLICY:
  3165. return EMPTY_STRING;
  3166. case SUBJECT_DOMAIN_POLICY:
  3167. return EMPTY_STRING;
  3168. default:
  3169. return super.defaultValues(memberName);
  3170. }
  3171. }
  3172. static schema(parameters = {}) {
  3173. const names = pvutils.getParametersValue(parameters, "names", {});
  3174. return (new asn1js.Sequence({
  3175. name: (names.blockName || EMPTY_STRING),
  3176. value: [
  3177. new asn1js.ObjectIdentifier({ name: (names.issuerDomainPolicy || EMPTY_STRING) }),
  3178. new asn1js.ObjectIdentifier({ name: (names.subjectDomainPolicy || EMPTY_STRING) })
  3179. ]
  3180. }));
  3181. }
  3182. fromSchema(schema) {
  3183. pvutils.clearProps(schema, CLEAR_PROPS$1e);
  3184. const asn1 = asn1js.compareSchema(schema, schema, PolicyMapping.schema({
  3185. names: {
  3186. issuerDomainPolicy: ISSUER_DOMAIN_POLICY,
  3187. subjectDomainPolicy: SUBJECT_DOMAIN_POLICY
  3188. }
  3189. }));
  3190. AsnError.assertSchema(asn1, this.className);
  3191. this.issuerDomainPolicy = asn1.result.issuerDomainPolicy.valueBlock.toString();
  3192. this.subjectDomainPolicy = asn1.result.subjectDomainPolicy.valueBlock.toString();
  3193. }
  3194. toSchema() {
  3195. return (new asn1js.Sequence({
  3196. value: [
  3197. new asn1js.ObjectIdentifier({ value: this.issuerDomainPolicy }),
  3198. new asn1js.ObjectIdentifier({ value: this.subjectDomainPolicy })
  3199. ]
  3200. }));
  3201. }
  3202. toJSON() {
  3203. return {
  3204. issuerDomainPolicy: this.issuerDomainPolicy,
  3205. subjectDomainPolicy: this.subjectDomainPolicy
  3206. };
  3207. }
  3208. }
  3209. PolicyMapping.CLASS_NAME = "PolicyMapping";
  3210. const MAPPINGS = "mappings";
  3211. const CLEAR_PROPS$1d = [
  3212. MAPPINGS,
  3213. ];
  3214. class PolicyMappings extends PkiObject {
  3215. constructor(parameters = {}) {
  3216. super();
  3217. this.mappings = pvutils.getParametersValue(parameters, MAPPINGS, PolicyMappings.defaultValues(MAPPINGS));
  3218. if (parameters.schema) {
  3219. this.fromSchema(parameters.schema);
  3220. }
  3221. }
  3222. static defaultValues(memberName) {
  3223. switch (memberName) {
  3224. case MAPPINGS:
  3225. return [];
  3226. default:
  3227. return super.defaultValues(memberName);
  3228. }
  3229. }
  3230. static schema(parameters = {}) {
  3231. const names = pvutils.getParametersValue(parameters, "names", {});
  3232. return (new asn1js.Sequence({
  3233. name: (names.blockName || EMPTY_STRING),
  3234. value: [
  3235. new asn1js.Repeated({
  3236. name: (names.mappings || EMPTY_STRING),
  3237. value: PolicyMapping.schema()
  3238. })
  3239. ]
  3240. }));
  3241. }
  3242. fromSchema(schema) {
  3243. pvutils.clearProps(schema, CLEAR_PROPS$1d);
  3244. const asn1 = asn1js.compareSchema(schema, schema, PolicyMappings.schema({
  3245. names: {
  3246. mappings: MAPPINGS
  3247. }
  3248. }));
  3249. AsnError.assertSchema(asn1, this.className);
  3250. this.mappings = Array.from(asn1.result.mappings, element => new PolicyMapping({ schema: element }));
  3251. }
  3252. toSchema() {
  3253. return (new asn1js.Sequence({
  3254. value: Array.from(this.mappings, o => o.toSchema())
  3255. }));
  3256. }
  3257. toJSON() {
  3258. return {
  3259. mappings: Array.from(this.mappings, o => o.toJSON())
  3260. };
  3261. }
  3262. }
  3263. PolicyMappings.CLASS_NAME = "PolicyMappings";
  3264. const NOT_BEFORE$1 = "notBefore";
  3265. const NOT_AFTER$1 = "notAfter";
  3266. const CLEAR_PROPS$1c = [
  3267. NOT_BEFORE$1,
  3268. NOT_AFTER$1
  3269. ];
  3270. class PrivateKeyUsagePeriod extends PkiObject {
  3271. constructor(parameters = {}) {
  3272. super();
  3273. if (NOT_BEFORE$1 in parameters) {
  3274. this.notBefore = pvutils.getParametersValue(parameters, NOT_BEFORE$1, PrivateKeyUsagePeriod.defaultValues(NOT_BEFORE$1));
  3275. }
  3276. if (NOT_AFTER$1 in parameters) {
  3277. this.notAfter = pvutils.getParametersValue(parameters, NOT_AFTER$1, PrivateKeyUsagePeriod.defaultValues(NOT_AFTER$1));
  3278. }
  3279. if (parameters.schema) {
  3280. this.fromSchema(parameters.schema);
  3281. }
  3282. }
  3283. static defaultValues(memberName) {
  3284. switch (memberName) {
  3285. case NOT_BEFORE$1:
  3286. return new Date();
  3287. case NOT_AFTER$1:
  3288. return new Date();
  3289. default:
  3290. return super.defaultValues(memberName);
  3291. }
  3292. }
  3293. static schema(parameters = {}) {
  3294. const names = pvutils.getParametersValue(parameters, "names", {});
  3295. return (new asn1js.Sequence({
  3296. name: (names.blockName || EMPTY_STRING),
  3297. value: [
  3298. new asn1js.Primitive({
  3299. name: (names.notBefore || EMPTY_STRING),
  3300. optional: true,
  3301. idBlock: {
  3302. tagClass: 3,
  3303. tagNumber: 0
  3304. }
  3305. }),
  3306. new asn1js.Primitive({
  3307. name: (names.notAfter || EMPTY_STRING),
  3308. optional: true,
  3309. idBlock: {
  3310. tagClass: 3,
  3311. tagNumber: 1
  3312. }
  3313. })
  3314. ]
  3315. }));
  3316. }
  3317. fromSchema(schema) {
  3318. pvutils.clearProps(schema, CLEAR_PROPS$1c);
  3319. const asn1 = asn1js.compareSchema(schema, schema, PrivateKeyUsagePeriod.schema({
  3320. names: {
  3321. notBefore: NOT_BEFORE$1,
  3322. notAfter: NOT_AFTER$1
  3323. }
  3324. }));
  3325. AsnError.assertSchema(asn1, this.className);
  3326. if (NOT_BEFORE$1 in asn1.result) {
  3327. const localNotBefore = new asn1js.GeneralizedTime();
  3328. localNotBefore.fromBuffer(asn1.result.notBefore.valueBlock.valueHex);
  3329. this.notBefore = localNotBefore.toDate();
  3330. }
  3331. if (NOT_AFTER$1 in asn1.result) {
  3332. const localNotAfter = new asn1js.GeneralizedTime({ valueHex: asn1.result.notAfter.valueBlock.valueHex });
  3333. localNotAfter.fromBuffer(asn1.result.notAfter.valueBlock.valueHex);
  3334. this.notAfter = localNotAfter.toDate();
  3335. }
  3336. }
  3337. toSchema() {
  3338. const outputArray = [];
  3339. if (NOT_BEFORE$1 in this) {
  3340. outputArray.push(new asn1js.Primitive({
  3341. idBlock: {
  3342. tagClass: 3,
  3343. tagNumber: 0
  3344. },
  3345. valueHex: (new asn1js.GeneralizedTime({ valueDate: this.notBefore })).valueBlock.valueHexView
  3346. }));
  3347. }
  3348. if (NOT_AFTER$1 in this) {
  3349. outputArray.push(new asn1js.Primitive({
  3350. idBlock: {
  3351. tagClass: 3,
  3352. tagNumber: 1
  3353. },
  3354. valueHex: (new asn1js.GeneralizedTime({ valueDate: this.notAfter })).valueBlock.valueHexView
  3355. }));
  3356. }
  3357. return (new asn1js.Sequence({
  3358. value: outputArray
  3359. }));
  3360. }
  3361. toJSON() {
  3362. const res = {};
  3363. if (this.notBefore) {
  3364. res.notBefore = this.notBefore;
  3365. }
  3366. if (this.notAfter) {
  3367. res.notAfter = this.notAfter;
  3368. }
  3369. return res;
  3370. }
  3371. }
  3372. PrivateKeyUsagePeriod.CLASS_NAME = "PrivateKeyUsagePeriod";
  3373. const ID = "id";
  3374. const TYPE$2 = "type";
  3375. const VALUES = "values";
  3376. const QC_STATEMENT_CLEAR_PROPS = [
  3377. ID,
  3378. TYPE$2
  3379. ];
  3380. const QC_STATEMENTS_CLEAR_PROPS = [
  3381. VALUES
  3382. ];
  3383. class QCStatement extends PkiObject {
  3384. constructor(parameters = {}) {
  3385. super();
  3386. this.id = pvutils.getParametersValue(parameters, ID, QCStatement.defaultValues(ID));
  3387. if (TYPE$2 in parameters) {
  3388. this.type = pvutils.getParametersValue(parameters, TYPE$2, QCStatement.defaultValues(TYPE$2));
  3389. }
  3390. if (parameters.schema) {
  3391. this.fromSchema(parameters.schema);
  3392. }
  3393. }
  3394. static defaultValues(memberName) {
  3395. switch (memberName) {
  3396. case ID:
  3397. return EMPTY_STRING;
  3398. case TYPE$2:
  3399. return new asn1js.Null();
  3400. default:
  3401. return super.defaultValues(memberName);
  3402. }
  3403. }
  3404. static compareWithDefault(memberName, memberValue) {
  3405. switch (memberName) {
  3406. case ID:
  3407. return (memberValue === EMPTY_STRING);
  3408. case TYPE$2:
  3409. return (memberValue instanceof asn1js.Null);
  3410. default:
  3411. return super.defaultValues(memberName);
  3412. }
  3413. }
  3414. static schema(parameters = {}) {
  3415. const names = pvutils.getParametersValue(parameters, "names", {});
  3416. return (new asn1js.Sequence({
  3417. name: (names.blockName || EMPTY_STRING),
  3418. value: [
  3419. new asn1js.ObjectIdentifier({ name: (names.id || EMPTY_STRING) }),
  3420. new asn1js.Any({
  3421. name: (names.type || EMPTY_STRING),
  3422. optional: true
  3423. })
  3424. ]
  3425. }));
  3426. }
  3427. fromSchema(schema) {
  3428. pvutils.clearProps(schema, QC_STATEMENT_CLEAR_PROPS);
  3429. const asn1 = asn1js.compareSchema(schema, schema, QCStatement.schema({
  3430. names: {
  3431. id: ID,
  3432. type: TYPE$2
  3433. }
  3434. }));
  3435. AsnError.assertSchema(asn1, this.className);
  3436. this.id = asn1.result.id.valueBlock.toString();
  3437. if (TYPE$2 in asn1.result)
  3438. this.type = asn1.result.type;
  3439. }
  3440. toSchema() {
  3441. const value = [
  3442. new asn1js.ObjectIdentifier({ value: this.id })
  3443. ];
  3444. if (TYPE$2 in this)
  3445. value.push(this.type);
  3446. return (new asn1js.Sequence({
  3447. value,
  3448. }));
  3449. }
  3450. toJSON() {
  3451. const object = {
  3452. id: this.id
  3453. };
  3454. if (this.type) {
  3455. object.type = this.type.toJSON();
  3456. }
  3457. return object;
  3458. }
  3459. }
  3460. QCStatement.CLASS_NAME = "QCStatement";
  3461. class QCStatements extends PkiObject {
  3462. constructor(parameters = {}) {
  3463. super();
  3464. this.values = pvutils.getParametersValue(parameters, VALUES, QCStatements.defaultValues(VALUES));
  3465. if (parameters.schema) {
  3466. this.fromSchema(parameters.schema);
  3467. }
  3468. }
  3469. static defaultValues(memberName) {
  3470. switch (memberName) {
  3471. case VALUES:
  3472. return [];
  3473. default:
  3474. return super.defaultValues(memberName);
  3475. }
  3476. }
  3477. static compareWithDefault(memberName, memberValue) {
  3478. switch (memberName) {
  3479. case VALUES:
  3480. return (memberValue.length === 0);
  3481. default:
  3482. return super.defaultValues(memberName);
  3483. }
  3484. }
  3485. static schema(parameters = {}) {
  3486. const names = pvutils.getParametersValue(parameters, "names", {});
  3487. return (new asn1js.Sequence({
  3488. name: (names.blockName || EMPTY_STRING),
  3489. value: [
  3490. new asn1js.Repeated({
  3491. name: (names.values || EMPTY_STRING),
  3492. value: QCStatement.schema(names.value || {})
  3493. }),
  3494. ]
  3495. }));
  3496. }
  3497. fromSchema(schema) {
  3498. pvutils.clearProps(schema, QC_STATEMENTS_CLEAR_PROPS);
  3499. const asn1 = asn1js.compareSchema(schema, schema, QCStatements.schema({
  3500. names: {
  3501. values: VALUES
  3502. }
  3503. }));
  3504. AsnError.assertSchema(asn1, this.className);
  3505. this.values = Array.from(asn1.result.values, element => new QCStatement({ schema: element }));
  3506. }
  3507. toSchema() {
  3508. return (new asn1js.Sequence({
  3509. value: Array.from(this.values, o => o.toSchema())
  3510. }));
  3511. }
  3512. toJSON() {
  3513. return {
  3514. values: Array.from(this.values, o => o.toJSON())
  3515. };
  3516. }
  3517. }
  3518. QCStatements.CLASS_NAME = "QCStatements";
  3519. var _a;
  3520. class ECNamedCurves {
  3521. static register(name, id, size) {
  3522. this.namedCurves[name.toLowerCase()] = this.namedCurves[id] = { name, id, size };
  3523. }
  3524. static find(nameOrId) {
  3525. return this.namedCurves[nameOrId.toLowerCase()] || null;
  3526. }
  3527. }
  3528. _a = ECNamedCurves;
  3529. ECNamedCurves.namedCurves = {};
  3530. (() => {
  3531. _a.register("P-256", "1.2.840.10045.3.1.7", 32);
  3532. _a.register("P-384", "1.3.132.0.34", 48);
  3533. _a.register("P-521", "1.3.132.0.35", 66);
  3534. _a.register("brainpoolP256r1", "1.3.36.3.3.2.8.1.1.7", 32);
  3535. _a.register("brainpoolP384r1", "1.3.36.3.3.2.8.1.1.11", 48);
  3536. _a.register("brainpoolP512r1", "1.3.36.3.3.2.8.1.1.13", 64);
  3537. })();
  3538. const X = "x";
  3539. const Y = "y";
  3540. const NAMED_CURVE$1 = "namedCurve";
  3541. class ECPublicKey extends PkiObject {
  3542. constructor(parameters = {}) {
  3543. super();
  3544. this.x = pvutils.getParametersValue(parameters, X, ECPublicKey.defaultValues(X));
  3545. this.y = pvutils.getParametersValue(parameters, Y, ECPublicKey.defaultValues(Y));
  3546. this.namedCurve = pvutils.getParametersValue(parameters, NAMED_CURVE$1, ECPublicKey.defaultValues(NAMED_CURVE$1));
  3547. if (parameters.json) {
  3548. this.fromJSON(parameters.json);
  3549. }
  3550. if (parameters.schema) {
  3551. this.fromSchema(parameters.schema);
  3552. }
  3553. }
  3554. static defaultValues(memberName) {
  3555. switch (memberName) {
  3556. case X:
  3557. case Y:
  3558. return EMPTY_BUFFER;
  3559. case NAMED_CURVE$1:
  3560. return EMPTY_STRING;
  3561. default:
  3562. return super.defaultValues(memberName);
  3563. }
  3564. }
  3565. static compareWithDefault(memberName, memberValue) {
  3566. switch (memberName) {
  3567. case X:
  3568. case Y:
  3569. return memberValue instanceof ArrayBuffer &&
  3570. (pvutils.isEqualBuffer(memberValue, ECPublicKey.defaultValues(memberName)));
  3571. case NAMED_CURVE$1:
  3572. return typeof memberValue === "string" &&
  3573. memberValue === ECPublicKey.defaultValues(memberName);
  3574. default:
  3575. return super.defaultValues(memberName);
  3576. }
  3577. }
  3578. static schema() {
  3579. return new asn1js.RawData();
  3580. }
  3581. fromSchema(schema1) {
  3582. const view = BufferSourceConverter.toUint8Array(schema1);
  3583. if (view[0] !== 0x04) {
  3584. throw new Error("Object's schema was not verified against input data for ECPublicKey");
  3585. }
  3586. const namedCurve = ECNamedCurves.find(this.namedCurve);
  3587. if (!namedCurve) {
  3588. throw new Error(`Incorrect curve OID: ${this.namedCurve}`);
  3589. }
  3590. const coordinateLength = namedCurve.size;
  3591. if (view.byteLength !== (coordinateLength * 2 + 1)) {
  3592. throw new Error("Object's schema was not verified against input data for ECPublicKey");
  3593. }
  3594. this.namedCurve = namedCurve.name;
  3595. this.x = view.slice(1, coordinateLength + 1).buffer;
  3596. this.y = view.slice(1 + coordinateLength, coordinateLength * 2 + 1).buffer;
  3597. }
  3598. toSchema() {
  3599. return new asn1js.RawData({
  3600. data: pvutils.utilConcatBuf((new Uint8Array([0x04])).buffer, this.x, this.y)
  3601. });
  3602. }
  3603. toJSON() {
  3604. const namedCurve = ECNamedCurves.find(this.namedCurve);
  3605. return {
  3606. crv: namedCurve ? namedCurve.name : this.namedCurve,
  3607. x: pvutils.toBase64(pvutils.arrayBufferToString(this.x), true, true, false),
  3608. y: pvutils.toBase64(pvutils.arrayBufferToString(this.y), true, true, false)
  3609. };
  3610. }
  3611. fromJSON(json) {
  3612. ParameterError.assert("json", json, "crv", "x", "y");
  3613. let coordinateLength = 0;
  3614. const namedCurve = ECNamedCurves.find(json.crv);
  3615. if (namedCurve) {
  3616. this.namedCurve = namedCurve.id;
  3617. coordinateLength = namedCurve.size;
  3618. }
  3619. const xConvertBuffer = pvutils.stringToArrayBuffer(pvutils.fromBase64(json.x, true));
  3620. if (xConvertBuffer.byteLength < coordinateLength) {
  3621. this.x = new ArrayBuffer(coordinateLength);
  3622. const view = new Uint8Array(this.x);
  3623. const convertBufferView = new Uint8Array(xConvertBuffer);
  3624. view.set(convertBufferView, 1);
  3625. }
  3626. else {
  3627. this.x = xConvertBuffer.slice(0, coordinateLength);
  3628. }
  3629. const yConvertBuffer = pvutils.stringToArrayBuffer(pvutils.fromBase64(json.y, true));
  3630. if (yConvertBuffer.byteLength < coordinateLength) {
  3631. this.y = new ArrayBuffer(coordinateLength);
  3632. const view = new Uint8Array(this.y);
  3633. const convertBufferView = new Uint8Array(yConvertBuffer);
  3634. view.set(convertBufferView, 1);
  3635. }
  3636. else {
  3637. this.y = yConvertBuffer.slice(0, coordinateLength);
  3638. }
  3639. }
  3640. }
  3641. ECPublicKey.CLASS_NAME = "ECPublicKey";
  3642. const MODULUS$1 = "modulus";
  3643. const PUBLIC_EXPONENT$1 = "publicExponent";
  3644. const CLEAR_PROPS$1b = [MODULUS$1, PUBLIC_EXPONENT$1];
  3645. class RSAPublicKey extends PkiObject {
  3646. constructor(parameters = {}) {
  3647. super();
  3648. this.modulus = pvutils.getParametersValue(parameters, MODULUS$1, RSAPublicKey.defaultValues(MODULUS$1));
  3649. this.publicExponent = pvutils.getParametersValue(parameters, PUBLIC_EXPONENT$1, RSAPublicKey.defaultValues(PUBLIC_EXPONENT$1));
  3650. if (parameters.json) {
  3651. this.fromJSON(parameters.json);
  3652. }
  3653. if (parameters.schema) {
  3654. this.fromSchema(parameters.schema);
  3655. }
  3656. }
  3657. static defaultValues(memberName) {
  3658. switch (memberName) {
  3659. case MODULUS$1:
  3660. return new asn1js.Integer();
  3661. case PUBLIC_EXPONENT$1:
  3662. return new asn1js.Integer();
  3663. default:
  3664. return super.defaultValues(memberName);
  3665. }
  3666. }
  3667. static schema(parameters = {}) {
  3668. const names = pvutils.getParametersValue(parameters, "names", {});
  3669. return (new asn1js.Sequence({
  3670. name: (names.blockName || EMPTY_STRING),
  3671. value: [
  3672. new asn1js.Integer({ name: (names.modulus || EMPTY_STRING) }),
  3673. new asn1js.Integer({ name: (names.publicExponent || EMPTY_STRING) })
  3674. ]
  3675. }));
  3676. }
  3677. fromSchema(schema) {
  3678. pvutils.clearProps(schema, CLEAR_PROPS$1b);
  3679. const asn1 = asn1js.compareSchema(schema, schema, RSAPublicKey.schema({
  3680. names: {
  3681. modulus: MODULUS$1,
  3682. publicExponent: PUBLIC_EXPONENT$1
  3683. }
  3684. }));
  3685. AsnError.assertSchema(asn1, this.className);
  3686. this.modulus = asn1.result.modulus.convertFromDER(256);
  3687. this.publicExponent = asn1.result.publicExponent;
  3688. }
  3689. toSchema() {
  3690. return (new asn1js.Sequence({
  3691. value: [
  3692. this.modulus.convertToDER(),
  3693. this.publicExponent
  3694. ]
  3695. }));
  3696. }
  3697. toJSON() {
  3698. return {
  3699. n: pvtsutils.Convert.ToBase64Url(this.modulus.valueBlock.valueHexView),
  3700. e: pvtsutils.Convert.ToBase64Url(this.publicExponent.valueBlock.valueHexView),
  3701. };
  3702. }
  3703. fromJSON(json) {
  3704. ParameterError.assert("json", json, "n", "e");
  3705. const array = pvutils.stringToArrayBuffer(pvutils.fromBase64(json.n, true));
  3706. this.modulus = new asn1js.Integer({ valueHex: array.slice(0, Math.pow(2, pvutils.nearestPowerOf2(array.byteLength))) });
  3707. this.publicExponent = new asn1js.Integer({ valueHex: pvutils.stringToArrayBuffer(pvutils.fromBase64(json.e, true)).slice(0, 3) });
  3708. }
  3709. }
  3710. RSAPublicKey.CLASS_NAME = "RSAPublicKey";
  3711. const ALGORITHM$1 = "algorithm";
  3712. const SUBJECT_PUBLIC_KEY = "subjectPublicKey";
  3713. const CLEAR_PROPS$1a = [ALGORITHM$1, SUBJECT_PUBLIC_KEY];
  3714. class PublicKeyInfo extends PkiObject {
  3715. get parsedKey() {
  3716. if (this._parsedKey === undefined) {
  3717. switch (this.algorithm.algorithmId) {
  3718. case "1.2.840.10045.2.1":
  3719. if ("algorithmParams" in this.algorithm) {
  3720. if (this.algorithm.algorithmParams.constructor.blockName() === asn1js.ObjectIdentifier.blockName()) {
  3721. try {
  3722. this._parsedKey = new ECPublicKey({
  3723. namedCurve: this.algorithm.algorithmParams.valueBlock.toString(),
  3724. schema: this.subjectPublicKey.valueBlock.valueHexView
  3725. });
  3726. }
  3727. catch {
  3728. }
  3729. }
  3730. }
  3731. break;
  3732. case "1.2.840.113549.1.1.1":
  3733. {
  3734. const publicKeyASN1 = asn1js.fromBER(this.subjectPublicKey.valueBlock.valueHexView);
  3735. if (publicKeyASN1.offset !== -1) {
  3736. try {
  3737. this._parsedKey = new RSAPublicKey({ schema: publicKeyASN1.result });
  3738. }
  3739. catch {
  3740. }
  3741. }
  3742. }
  3743. break;
  3744. }
  3745. this._parsedKey || (this._parsedKey = null);
  3746. }
  3747. return this._parsedKey || undefined;
  3748. }
  3749. set parsedKey(value) {
  3750. this._parsedKey = value;
  3751. }
  3752. constructor(parameters = {}) {
  3753. super();
  3754. this.algorithm = pvutils.getParametersValue(parameters, ALGORITHM$1, PublicKeyInfo.defaultValues(ALGORITHM$1));
  3755. this.subjectPublicKey = pvutils.getParametersValue(parameters, SUBJECT_PUBLIC_KEY, PublicKeyInfo.defaultValues(SUBJECT_PUBLIC_KEY));
  3756. const parsedKey = pvutils.getParametersValue(parameters, "parsedKey", null);
  3757. if (parsedKey) {
  3758. this.parsedKey = parsedKey;
  3759. }
  3760. if (parameters.json) {
  3761. this.fromJSON(parameters.json);
  3762. }
  3763. if (parameters.schema) {
  3764. this.fromSchema(parameters.schema);
  3765. }
  3766. }
  3767. static defaultValues(memberName) {
  3768. switch (memberName) {
  3769. case ALGORITHM$1:
  3770. return new AlgorithmIdentifier();
  3771. case SUBJECT_PUBLIC_KEY:
  3772. return new asn1js.BitString();
  3773. default:
  3774. return super.defaultValues(memberName);
  3775. }
  3776. }
  3777. static schema(parameters = {}) {
  3778. const names = pvutils.getParametersValue(parameters, "names", {});
  3779. return (new asn1js.Sequence({
  3780. name: (names.blockName || EMPTY_STRING),
  3781. value: [
  3782. AlgorithmIdentifier.schema(names.algorithm || {}),
  3783. new asn1js.BitString({ name: (names.subjectPublicKey || EMPTY_STRING) })
  3784. ]
  3785. }));
  3786. }
  3787. fromSchema(schema) {
  3788. pvutils.clearProps(schema, CLEAR_PROPS$1a);
  3789. const asn1 = asn1js.compareSchema(schema, schema, PublicKeyInfo.schema({
  3790. names: {
  3791. algorithm: {
  3792. names: {
  3793. blockName: ALGORITHM$1
  3794. }
  3795. },
  3796. subjectPublicKey: SUBJECT_PUBLIC_KEY
  3797. }
  3798. }));
  3799. AsnError.assertSchema(asn1, this.className);
  3800. this.algorithm = new AlgorithmIdentifier({ schema: asn1.result.algorithm });
  3801. this.subjectPublicKey = asn1.result.subjectPublicKey;
  3802. }
  3803. toSchema() {
  3804. return (new asn1js.Sequence({
  3805. value: [
  3806. this.algorithm.toSchema(),
  3807. this.subjectPublicKey
  3808. ]
  3809. }));
  3810. }
  3811. toJSON() {
  3812. if (!this.parsedKey) {
  3813. return {
  3814. algorithm: this.algorithm.toJSON(),
  3815. subjectPublicKey: this.subjectPublicKey.toJSON(),
  3816. };
  3817. }
  3818. const jwk = {};
  3819. switch (this.algorithm.algorithmId) {
  3820. case "1.2.840.10045.2.1":
  3821. jwk.kty = "EC";
  3822. break;
  3823. case "1.2.840.113549.1.1.1":
  3824. jwk.kty = "RSA";
  3825. break;
  3826. }
  3827. const publicKeyJWK = this.parsedKey.toJSON();
  3828. Object.assign(jwk, publicKeyJWK);
  3829. return jwk;
  3830. }
  3831. fromJSON(json) {
  3832. if ("kty" in json) {
  3833. switch (json.kty.toUpperCase()) {
  3834. case "EC":
  3835. this.parsedKey = new ECPublicKey({ json });
  3836. this.algorithm = new AlgorithmIdentifier({
  3837. algorithmId: "1.2.840.10045.2.1",
  3838. algorithmParams: new asn1js.ObjectIdentifier({ value: this.parsedKey.namedCurve })
  3839. });
  3840. break;
  3841. case "RSA":
  3842. this.parsedKey = new RSAPublicKey({ json });
  3843. this.algorithm = new AlgorithmIdentifier({
  3844. algorithmId: "1.2.840.113549.1.1.1",
  3845. algorithmParams: new asn1js.Null()
  3846. });
  3847. break;
  3848. default:
  3849. throw new Error(`Invalid value for "kty" parameter: ${json.kty}`);
  3850. }
  3851. this.subjectPublicKey = new asn1js.BitString({ valueHex: this.parsedKey.toSchema().toBER(false) });
  3852. }
  3853. }
  3854. async importKey(publicKey, crypto = getCrypto(true)) {
  3855. try {
  3856. if (!publicKey) {
  3857. throw new Error("Need to provide publicKey input parameter");
  3858. }
  3859. const exportedKey = await crypto.exportKey("spki", publicKey);
  3860. const asn1 = asn1js.fromBER(exportedKey);
  3861. try {
  3862. this.fromSchema(asn1.result);
  3863. }
  3864. catch {
  3865. throw new Error("Error during initializing object from schema");
  3866. }
  3867. }
  3868. catch (e) {
  3869. const message = e instanceof Error ? e.message : `${e}`;
  3870. throw new Error(`Error during exporting public key: ${message}`);
  3871. }
  3872. }
  3873. }
  3874. PublicKeyInfo.CLASS_NAME = "PublicKeyInfo";
  3875. const VERSION$l = "version";
  3876. const PRIVATE_KEY$1 = "privateKey";
  3877. const NAMED_CURVE = "namedCurve";
  3878. const PUBLIC_KEY$1 = "publicKey";
  3879. const CLEAR_PROPS$19 = [
  3880. VERSION$l,
  3881. PRIVATE_KEY$1,
  3882. NAMED_CURVE,
  3883. PUBLIC_KEY$1
  3884. ];
  3885. class ECPrivateKey extends PkiObject {
  3886. constructor(parameters = {}) {
  3887. super();
  3888. this.version = pvutils.getParametersValue(parameters, VERSION$l, ECPrivateKey.defaultValues(VERSION$l));
  3889. this.privateKey = pvutils.getParametersValue(parameters, PRIVATE_KEY$1, ECPrivateKey.defaultValues(PRIVATE_KEY$1));
  3890. if (NAMED_CURVE in parameters) {
  3891. this.namedCurve = pvutils.getParametersValue(parameters, NAMED_CURVE, ECPrivateKey.defaultValues(NAMED_CURVE));
  3892. }
  3893. if (PUBLIC_KEY$1 in parameters) {
  3894. this.publicKey = pvutils.getParametersValue(parameters, PUBLIC_KEY$1, ECPrivateKey.defaultValues(PUBLIC_KEY$1));
  3895. }
  3896. if (parameters.json) {
  3897. this.fromJSON(parameters.json);
  3898. }
  3899. if (parameters.schema) {
  3900. this.fromSchema(parameters.schema);
  3901. }
  3902. }
  3903. static defaultValues(memberName) {
  3904. switch (memberName) {
  3905. case VERSION$l:
  3906. return 1;
  3907. case PRIVATE_KEY$1:
  3908. return new asn1js.OctetString();
  3909. case NAMED_CURVE:
  3910. return EMPTY_STRING;
  3911. case PUBLIC_KEY$1:
  3912. return new ECPublicKey();
  3913. default:
  3914. return super.defaultValues(memberName);
  3915. }
  3916. }
  3917. static compareWithDefault(memberName, memberValue) {
  3918. switch (memberName) {
  3919. case VERSION$l:
  3920. return (memberValue === ECPrivateKey.defaultValues(memberName));
  3921. case PRIVATE_KEY$1:
  3922. return (memberValue.isEqual(ECPrivateKey.defaultValues(memberName)));
  3923. case NAMED_CURVE:
  3924. return (memberValue === EMPTY_STRING);
  3925. case PUBLIC_KEY$1:
  3926. return ((ECPublicKey.compareWithDefault(NAMED_CURVE, memberValue.namedCurve)) &&
  3927. (ECPublicKey.compareWithDefault("x", memberValue.x)) &&
  3928. (ECPublicKey.compareWithDefault("y", memberValue.y)));
  3929. default:
  3930. return super.defaultValues(memberName);
  3931. }
  3932. }
  3933. static schema(parameters = {}) {
  3934. const names = pvutils.getParametersValue(parameters, "names", {});
  3935. return (new asn1js.Sequence({
  3936. name: (names.blockName || EMPTY_STRING),
  3937. value: [
  3938. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  3939. new asn1js.OctetString({ name: (names.privateKey || EMPTY_STRING) }),
  3940. new asn1js.Constructed({
  3941. optional: true,
  3942. idBlock: {
  3943. tagClass: 3,
  3944. tagNumber: 0
  3945. },
  3946. value: [
  3947. new asn1js.ObjectIdentifier({ name: (names.namedCurve || EMPTY_STRING) })
  3948. ]
  3949. }),
  3950. new asn1js.Constructed({
  3951. optional: true,
  3952. idBlock: {
  3953. tagClass: 3,
  3954. tagNumber: 1
  3955. },
  3956. value: [
  3957. new asn1js.BitString({ name: (names.publicKey || EMPTY_STRING) })
  3958. ]
  3959. })
  3960. ]
  3961. }));
  3962. }
  3963. fromSchema(schema) {
  3964. pvutils.clearProps(schema, CLEAR_PROPS$19);
  3965. const asn1 = asn1js.compareSchema(schema, schema, ECPrivateKey.schema({
  3966. names: {
  3967. version: VERSION$l,
  3968. privateKey: PRIVATE_KEY$1,
  3969. namedCurve: NAMED_CURVE,
  3970. publicKey: PUBLIC_KEY$1
  3971. }
  3972. }));
  3973. AsnError.assertSchema(asn1, this.className);
  3974. this.version = asn1.result.version.valueBlock.valueDec;
  3975. this.privateKey = asn1.result.privateKey;
  3976. if (NAMED_CURVE in asn1.result) {
  3977. this.namedCurve = asn1.result.namedCurve.valueBlock.toString();
  3978. }
  3979. if (PUBLIC_KEY$1 in asn1.result) {
  3980. const publicKeyData = { schema: asn1.result.publicKey.valueBlock.valueHex };
  3981. if (NAMED_CURVE in this) {
  3982. publicKeyData.namedCurve = this.namedCurve;
  3983. }
  3984. this.publicKey = new ECPublicKey(publicKeyData);
  3985. }
  3986. }
  3987. toSchema() {
  3988. const outputArray = [
  3989. new asn1js.Integer({ value: this.version }),
  3990. this.privateKey
  3991. ];
  3992. if (this.namedCurve) {
  3993. outputArray.push(new asn1js.Constructed({
  3994. idBlock: {
  3995. tagClass: 3,
  3996. tagNumber: 0
  3997. },
  3998. value: [
  3999. new asn1js.ObjectIdentifier({ value: this.namedCurve })
  4000. ]
  4001. }));
  4002. }
  4003. if (this.publicKey) {
  4004. outputArray.push(new asn1js.Constructed({
  4005. idBlock: {
  4006. tagClass: 3,
  4007. tagNumber: 1
  4008. },
  4009. value: [
  4010. new asn1js.BitString({ valueHex: this.publicKey.toSchema().toBER(false) })
  4011. ]
  4012. }));
  4013. }
  4014. return new asn1js.Sequence({
  4015. value: outputArray
  4016. });
  4017. }
  4018. toJSON() {
  4019. if (!this.namedCurve || ECPrivateKey.compareWithDefault(NAMED_CURVE, this.namedCurve)) {
  4020. throw new Error("Not enough information for making JSON: absent \"namedCurve\" value");
  4021. }
  4022. const curve = ECNamedCurves.find(this.namedCurve);
  4023. const privateKeyJSON = {
  4024. crv: curve ? curve.name : this.namedCurve,
  4025. d: pvtsutils.Convert.ToBase64Url(this.privateKey.valueBlock.valueHexView),
  4026. };
  4027. if (this.publicKey) {
  4028. const publicKeyJSON = this.publicKey.toJSON();
  4029. privateKeyJSON.x = publicKeyJSON.x;
  4030. privateKeyJSON.y = publicKeyJSON.y;
  4031. }
  4032. return privateKeyJSON;
  4033. }
  4034. fromJSON(json) {
  4035. ParameterError.assert("json", json, "crv", "d");
  4036. let coordinateLength = 0;
  4037. const curve = ECNamedCurves.find(json.crv);
  4038. if (curve) {
  4039. this.namedCurve = curve.id;
  4040. coordinateLength = curve.size;
  4041. }
  4042. const convertBuffer = pvtsutils.Convert.FromBase64Url(json.d);
  4043. if (convertBuffer.byteLength < coordinateLength) {
  4044. const buffer = new ArrayBuffer(coordinateLength);
  4045. const view = new Uint8Array(buffer);
  4046. const convertBufferView = new Uint8Array(convertBuffer);
  4047. view.set(convertBufferView, 1);
  4048. this.privateKey = new asn1js.OctetString({ valueHex: buffer });
  4049. }
  4050. else {
  4051. this.privateKey = new asn1js.OctetString({ valueHex: convertBuffer.slice(0, coordinateLength) });
  4052. }
  4053. if (json.x && json.y) {
  4054. this.publicKey = new ECPublicKey({ json });
  4055. }
  4056. }
  4057. }
  4058. ECPrivateKey.CLASS_NAME = "ECPrivateKey";
  4059. const PRIME = "prime";
  4060. const EXPONENT = "exponent";
  4061. const COEFFICIENT$1 = "coefficient";
  4062. const CLEAR_PROPS$18 = [
  4063. PRIME,
  4064. EXPONENT,
  4065. COEFFICIENT$1,
  4066. ];
  4067. class OtherPrimeInfo extends PkiObject {
  4068. constructor(parameters = {}) {
  4069. super();
  4070. this.prime = pvutils.getParametersValue(parameters, PRIME, OtherPrimeInfo.defaultValues(PRIME));
  4071. this.exponent = pvutils.getParametersValue(parameters, EXPONENT, OtherPrimeInfo.defaultValues(EXPONENT));
  4072. this.coefficient = pvutils.getParametersValue(parameters, COEFFICIENT$1, OtherPrimeInfo.defaultValues(COEFFICIENT$1));
  4073. if (parameters.json) {
  4074. this.fromJSON(parameters.json);
  4075. }
  4076. if (parameters.schema) {
  4077. this.fromSchema(parameters.schema);
  4078. }
  4079. }
  4080. static defaultValues(memberName) {
  4081. switch (memberName) {
  4082. case PRIME:
  4083. return new asn1js.Integer();
  4084. case EXPONENT:
  4085. return new asn1js.Integer();
  4086. case COEFFICIENT$1:
  4087. return new asn1js.Integer();
  4088. default:
  4089. return super.defaultValues(memberName);
  4090. }
  4091. }
  4092. static schema(parameters = {}) {
  4093. const names = pvutils.getParametersValue(parameters, "names", {});
  4094. return (new asn1js.Sequence({
  4095. name: (names.blockName || EMPTY_STRING),
  4096. value: [
  4097. new asn1js.Integer({ name: (names.prime || EMPTY_STRING) }),
  4098. new asn1js.Integer({ name: (names.exponent || EMPTY_STRING) }),
  4099. new asn1js.Integer({ name: (names.coefficient || EMPTY_STRING) })
  4100. ]
  4101. }));
  4102. }
  4103. fromSchema(schema) {
  4104. pvutils.clearProps(schema, CLEAR_PROPS$18);
  4105. const asn1 = asn1js.compareSchema(schema, schema, OtherPrimeInfo.schema({
  4106. names: {
  4107. prime: PRIME,
  4108. exponent: EXPONENT,
  4109. coefficient: COEFFICIENT$1
  4110. }
  4111. }));
  4112. AsnError.assertSchema(asn1, this.className);
  4113. this.prime = asn1.result.prime.convertFromDER();
  4114. this.exponent = asn1.result.exponent.convertFromDER();
  4115. this.coefficient = asn1.result.coefficient.convertFromDER();
  4116. }
  4117. toSchema() {
  4118. return (new asn1js.Sequence({
  4119. value: [
  4120. this.prime.convertToDER(),
  4121. this.exponent.convertToDER(),
  4122. this.coefficient.convertToDER()
  4123. ]
  4124. }));
  4125. }
  4126. toJSON() {
  4127. return {
  4128. r: pvtsutils.Convert.ToBase64Url(this.prime.valueBlock.valueHexView),
  4129. d: pvtsutils.Convert.ToBase64Url(this.exponent.valueBlock.valueHexView),
  4130. t: pvtsutils.Convert.ToBase64Url(this.coefficient.valueBlock.valueHexView),
  4131. };
  4132. }
  4133. fromJSON(json) {
  4134. ParameterError.assert("json", json, "r", "d", "r");
  4135. this.prime = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.r) });
  4136. this.exponent = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.d) });
  4137. this.coefficient = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.t) });
  4138. }
  4139. }
  4140. OtherPrimeInfo.CLASS_NAME = "OtherPrimeInfo";
  4141. const VERSION$k = "version";
  4142. const MODULUS = "modulus";
  4143. const PUBLIC_EXPONENT = "publicExponent";
  4144. const PRIVATE_EXPONENT = "privateExponent";
  4145. const PRIME1 = "prime1";
  4146. const PRIME2 = "prime2";
  4147. const EXPONENT1 = "exponent1";
  4148. const EXPONENT2 = "exponent2";
  4149. const COEFFICIENT = "coefficient";
  4150. const OTHER_PRIME_INFOS = "otherPrimeInfos";
  4151. const CLEAR_PROPS$17 = [
  4152. VERSION$k,
  4153. MODULUS,
  4154. PUBLIC_EXPONENT,
  4155. PRIVATE_EXPONENT,
  4156. PRIME1,
  4157. PRIME2,
  4158. EXPONENT1,
  4159. EXPONENT2,
  4160. COEFFICIENT,
  4161. OTHER_PRIME_INFOS
  4162. ];
  4163. class RSAPrivateKey extends PkiObject {
  4164. constructor(parameters = {}) {
  4165. super();
  4166. this.version = pvutils.getParametersValue(parameters, VERSION$k, RSAPrivateKey.defaultValues(VERSION$k));
  4167. this.modulus = pvutils.getParametersValue(parameters, MODULUS, RSAPrivateKey.defaultValues(MODULUS));
  4168. this.publicExponent = pvutils.getParametersValue(parameters, PUBLIC_EXPONENT, RSAPrivateKey.defaultValues(PUBLIC_EXPONENT));
  4169. this.privateExponent = pvutils.getParametersValue(parameters, PRIVATE_EXPONENT, RSAPrivateKey.defaultValues(PRIVATE_EXPONENT));
  4170. this.prime1 = pvutils.getParametersValue(parameters, PRIME1, RSAPrivateKey.defaultValues(PRIME1));
  4171. this.prime2 = pvutils.getParametersValue(parameters, PRIME2, RSAPrivateKey.defaultValues(PRIME2));
  4172. this.exponent1 = pvutils.getParametersValue(parameters, EXPONENT1, RSAPrivateKey.defaultValues(EXPONENT1));
  4173. this.exponent2 = pvutils.getParametersValue(parameters, EXPONENT2, RSAPrivateKey.defaultValues(EXPONENT2));
  4174. this.coefficient = pvutils.getParametersValue(parameters, COEFFICIENT, RSAPrivateKey.defaultValues(COEFFICIENT));
  4175. if (OTHER_PRIME_INFOS in parameters) {
  4176. this.otherPrimeInfos = pvutils.getParametersValue(parameters, OTHER_PRIME_INFOS, RSAPrivateKey.defaultValues(OTHER_PRIME_INFOS));
  4177. }
  4178. if (parameters.json) {
  4179. this.fromJSON(parameters.json);
  4180. }
  4181. if (parameters.schema) {
  4182. this.fromSchema(parameters.schema);
  4183. }
  4184. }
  4185. static defaultValues(memberName) {
  4186. switch (memberName) {
  4187. case VERSION$k:
  4188. return 0;
  4189. case MODULUS:
  4190. return new asn1js.Integer();
  4191. case PUBLIC_EXPONENT:
  4192. return new asn1js.Integer();
  4193. case PRIVATE_EXPONENT:
  4194. return new asn1js.Integer();
  4195. case PRIME1:
  4196. return new asn1js.Integer();
  4197. case PRIME2:
  4198. return new asn1js.Integer();
  4199. case EXPONENT1:
  4200. return new asn1js.Integer();
  4201. case EXPONENT2:
  4202. return new asn1js.Integer();
  4203. case COEFFICIENT:
  4204. return new asn1js.Integer();
  4205. case OTHER_PRIME_INFOS:
  4206. return [];
  4207. default:
  4208. return super.defaultValues(memberName);
  4209. }
  4210. }
  4211. static schema(parameters = {}) {
  4212. const names = pvutils.getParametersValue(parameters, "names", {});
  4213. return (new asn1js.Sequence({
  4214. name: (names.blockName || EMPTY_STRING),
  4215. value: [
  4216. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  4217. new asn1js.Integer({ name: (names.modulus || EMPTY_STRING) }),
  4218. new asn1js.Integer({ name: (names.publicExponent || EMPTY_STRING) }),
  4219. new asn1js.Integer({ name: (names.privateExponent || EMPTY_STRING) }),
  4220. new asn1js.Integer({ name: (names.prime1 || EMPTY_STRING) }),
  4221. new asn1js.Integer({ name: (names.prime2 || EMPTY_STRING) }),
  4222. new asn1js.Integer({ name: (names.exponent1 || EMPTY_STRING) }),
  4223. new asn1js.Integer({ name: (names.exponent2 || EMPTY_STRING) }),
  4224. new asn1js.Integer({ name: (names.coefficient || EMPTY_STRING) }),
  4225. new asn1js.Sequence({
  4226. optional: true,
  4227. value: [
  4228. new asn1js.Repeated({
  4229. name: (names.otherPrimeInfosName || EMPTY_STRING),
  4230. value: OtherPrimeInfo.schema(names.otherPrimeInfo || {})
  4231. })
  4232. ]
  4233. })
  4234. ]
  4235. }));
  4236. }
  4237. fromSchema(schema) {
  4238. pvutils.clearProps(schema, CLEAR_PROPS$17);
  4239. const asn1 = asn1js.compareSchema(schema, schema, RSAPrivateKey.schema({
  4240. names: {
  4241. version: VERSION$k,
  4242. modulus: MODULUS,
  4243. publicExponent: PUBLIC_EXPONENT,
  4244. privateExponent: PRIVATE_EXPONENT,
  4245. prime1: PRIME1,
  4246. prime2: PRIME2,
  4247. exponent1: EXPONENT1,
  4248. exponent2: EXPONENT2,
  4249. coefficient: COEFFICIENT,
  4250. otherPrimeInfo: {
  4251. names: {
  4252. blockName: OTHER_PRIME_INFOS
  4253. }
  4254. }
  4255. }
  4256. }));
  4257. AsnError.assertSchema(asn1, this.className);
  4258. this.version = asn1.result.version.valueBlock.valueDec;
  4259. this.modulus = asn1.result.modulus.convertFromDER(256);
  4260. this.publicExponent = asn1.result.publicExponent;
  4261. this.privateExponent = asn1.result.privateExponent.convertFromDER(256);
  4262. this.prime1 = asn1.result.prime1.convertFromDER(128);
  4263. this.prime2 = asn1.result.prime2.convertFromDER(128);
  4264. this.exponent1 = asn1.result.exponent1.convertFromDER(128);
  4265. this.exponent2 = asn1.result.exponent2.convertFromDER(128);
  4266. this.coefficient = asn1.result.coefficient.convertFromDER(128);
  4267. if (OTHER_PRIME_INFOS in asn1.result)
  4268. this.otherPrimeInfos = Array.from(asn1.result.otherPrimeInfos, element => new OtherPrimeInfo({ schema: element }));
  4269. }
  4270. toSchema() {
  4271. const outputArray = [];
  4272. outputArray.push(new asn1js.Integer({ value: this.version }));
  4273. outputArray.push(this.modulus.convertToDER());
  4274. outputArray.push(this.publicExponent);
  4275. outputArray.push(this.privateExponent.convertToDER());
  4276. outputArray.push(this.prime1.convertToDER());
  4277. outputArray.push(this.prime2.convertToDER());
  4278. outputArray.push(this.exponent1.convertToDER());
  4279. outputArray.push(this.exponent2.convertToDER());
  4280. outputArray.push(this.coefficient.convertToDER());
  4281. if (this.otherPrimeInfos) {
  4282. outputArray.push(new asn1js.Sequence({
  4283. value: Array.from(this.otherPrimeInfos, o => o.toSchema())
  4284. }));
  4285. }
  4286. return (new asn1js.Sequence({
  4287. value: outputArray
  4288. }));
  4289. }
  4290. toJSON() {
  4291. const jwk = {
  4292. n: pvtsutils.Convert.ToBase64Url(this.modulus.valueBlock.valueHexView),
  4293. e: pvtsutils.Convert.ToBase64Url(this.publicExponent.valueBlock.valueHexView),
  4294. d: pvtsutils.Convert.ToBase64Url(this.privateExponent.valueBlock.valueHexView),
  4295. p: pvtsutils.Convert.ToBase64Url(this.prime1.valueBlock.valueHexView),
  4296. q: pvtsutils.Convert.ToBase64Url(this.prime2.valueBlock.valueHexView),
  4297. dp: pvtsutils.Convert.ToBase64Url(this.exponent1.valueBlock.valueHexView),
  4298. dq: pvtsutils.Convert.ToBase64Url(this.exponent2.valueBlock.valueHexView),
  4299. qi: pvtsutils.Convert.ToBase64Url(this.coefficient.valueBlock.valueHexView),
  4300. };
  4301. if (this.otherPrimeInfos) {
  4302. jwk.oth = Array.from(this.otherPrimeInfos, o => o.toJSON());
  4303. }
  4304. return jwk;
  4305. }
  4306. fromJSON(json) {
  4307. ParameterError.assert("json", json, "n", "e", "d", "p", "q", "dp", "dq", "qi");
  4308. this.modulus = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.n) });
  4309. this.publicExponent = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.e) });
  4310. this.privateExponent = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.d) });
  4311. this.prime1 = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.p) });
  4312. this.prime2 = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.q) });
  4313. this.exponent1 = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.dp) });
  4314. this.exponent2 = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.dq) });
  4315. this.coefficient = new asn1js.Integer({ valueHex: pvtsutils.Convert.FromBase64Url(json.qi) });
  4316. if (json.oth) {
  4317. this.otherPrimeInfos = Array.from(json.oth, (element) => new OtherPrimeInfo({ json: element }));
  4318. }
  4319. }
  4320. }
  4321. RSAPrivateKey.CLASS_NAME = "RSAPrivateKey";
  4322. const VERSION$j = "version";
  4323. const PRIVATE_KEY_ALGORITHM = "privateKeyAlgorithm";
  4324. const PRIVATE_KEY = "privateKey";
  4325. const ATTRIBUTES$5 = "attributes";
  4326. const PARSED_KEY = "parsedKey";
  4327. const CLEAR_PROPS$16 = [
  4328. VERSION$j,
  4329. PRIVATE_KEY_ALGORITHM,
  4330. PRIVATE_KEY,
  4331. ATTRIBUTES$5
  4332. ];
  4333. class PrivateKeyInfo extends PkiObject {
  4334. constructor(parameters = {}) {
  4335. super();
  4336. this.version = pvutils.getParametersValue(parameters, VERSION$j, PrivateKeyInfo.defaultValues(VERSION$j));
  4337. this.privateKeyAlgorithm = pvutils.getParametersValue(parameters, PRIVATE_KEY_ALGORITHM, PrivateKeyInfo.defaultValues(PRIVATE_KEY_ALGORITHM));
  4338. this.privateKey = pvutils.getParametersValue(parameters, PRIVATE_KEY, PrivateKeyInfo.defaultValues(PRIVATE_KEY));
  4339. if (ATTRIBUTES$5 in parameters) {
  4340. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES$5, PrivateKeyInfo.defaultValues(ATTRIBUTES$5));
  4341. }
  4342. if (PARSED_KEY in parameters) {
  4343. this.parsedKey = pvutils.getParametersValue(parameters, PARSED_KEY, PrivateKeyInfo.defaultValues(PARSED_KEY));
  4344. }
  4345. if (parameters.json) {
  4346. this.fromJSON(parameters.json);
  4347. }
  4348. if (parameters.schema) {
  4349. this.fromSchema(parameters.schema);
  4350. }
  4351. }
  4352. static defaultValues(memberName) {
  4353. switch (memberName) {
  4354. case VERSION$j:
  4355. return 0;
  4356. case PRIVATE_KEY_ALGORITHM:
  4357. return new AlgorithmIdentifier();
  4358. case PRIVATE_KEY:
  4359. return new asn1js.OctetString();
  4360. case ATTRIBUTES$5:
  4361. return [];
  4362. case PARSED_KEY:
  4363. return {};
  4364. default:
  4365. return super.defaultValues(memberName);
  4366. }
  4367. }
  4368. static schema(parameters = {}) {
  4369. const names = pvutils.getParametersValue(parameters, "names", {});
  4370. return (new asn1js.Sequence({
  4371. name: (names.blockName || EMPTY_STRING),
  4372. value: [
  4373. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  4374. AlgorithmIdentifier.schema(names.privateKeyAlgorithm || {}),
  4375. new asn1js.OctetString({ name: (names.privateKey || EMPTY_STRING) }),
  4376. new asn1js.Constructed({
  4377. optional: true,
  4378. idBlock: {
  4379. tagClass: 3,
  4380. tagNumber: 0
  4381. },
  4382. value: [
  4383. new asn1js.Repeated({
  4384. name: (names.attributes || EMPTY_STRING),
  4385. value: Attribute.schema()
  4386. })
  4387. ]
  4388. })
  4389. ]
  4390. }));
  4391. }
  4392. fromSchema(schema) {
  4393. pvutils.clearProps(schema, CLEAR_PROPS$16);
  4394. const asn1 = asn1js.compareSchema(schema, schema, PrivateKeyInfo.schema({
  4395. names: {
  4396. version: VERSION$j,
  4397. privateKeyAlgorithm: {
  4398. names: {
  4399. blockName: PRIVATE_KEY_ALGORITHM
  4400. }
  4401. },
  4402. privateKey: PRIVATE_KEY,
  4403. attributes: ATTRIBUTES$5
  4404. }
  4405. }));
  4406. AsnError.assertSchema(asn1, this.className);
  4407. this.version = asn1.result.version.valueBlock.valueDec;
  4408. this.privateKeyAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.privateKeyAlgorithm });
  4409. this.privateKey = asn1.result.privateKey;
  4410. if (ATTRIBUTES$5 in asn1.result)
  4411. this.attributes = Array.from(asn1.result.attributes, element => new Attribute({ schema: element }));
  4412. switch (this.privateKeyAlgorithm.algorithmId) {
  4413. case "1.2.840.113549.1.1.1":
  4414. {
  4415. const privateKeyASN1 = asn1js.fromBER(this.privateKey.valueBlock.valueHexView);
  4416. if (privateKeyASN1.offset !== -1)
  4417. this.parsedKey = new RSAPrivateKey({ schema: privateKeyASN1.result });
  4418. }
  4419. break;
  4420. case "1.2.840.10045.2.1":
  4421. if ("algorithmParams" in this.privateKeyAlgorithm) {
  4422. if (this.privateKeyAlgorithm.algorithmParams instanceof asn1js.ObjectIdentifier) {
  4423. const privateKeyASN1 = asn1js.fromBER(this.privateKey.valueBlock.valueHexView);
  4424. if (privateKeyASN1.offset !== -1) {
  4425. this.parsedKey = new ECPrivateKey({
  4426. namedCurve: this.privateKeyAlgorithm.algorithmParams.valueBlock.toString(),
  4427. schema: privateKeyASN1.result
  4428. });
  4429. }
  4430. }
  4431. }
  4432. break;
  4433. }
  4434. }
  4435. toSchema() {
  4436. const outputArray = [
  4437. new asn1js.Integer({ value: this.version }),
  4438. this.privateKeyAlgorithm.toSchema(),
  4439. this.privateKey
  4440. ];
  4441. if (this.attributes) {
  4442. outputArray.push(new asn1js.Constructed({
  4443. optional: true,
  4444. idBlock: {
  4445. tagClass: 3,
  4446. tagNumber: 0
  4447. },
  4448. value: Array.from(this.attributes, o => o.toSchema())
  4449. }));
  4450. }
  4451. return (new asn1js.Sequence({
  4452. value: outputArray
  4453. }));
  4454. }
  4455. toJSON() {
  4456. if (!this.parsedKey) {
  4457. const object = {
  4458. version: this.version,
  4459. privateKeyAlgorithm: this.privateKeyAlgorithm.toJSON(),
  4460. privateKey: this.privateKey.toJSON(),
  4461. };
  4462. if (this.attributes) {
  4463. object.attributes = Array.from(this.attributes, o => o.toJSON());
  4464. }
  4465. return object;
  4466. }
  4467. const jwk = {};
  4468. switch (this.privateKeyAlgorithm.algorithmId) {
  4469. case "1.2.840.10045.2.1":
  4470. jwk.kty = "EC";
  4471. break;
  4472. case "1.2.840.113549.1.1.1":
  4473. jwk.kty = "RSA";
  4474. break;
  4475. }
  4476. const publicKeyJWK = this.parsedKey.toJSON();
  4477. Object.assign(jwk, publicKeyJWK);
  4478. return jwk;
  4479. }
  4480. fromJSON(json) {
  4481. if ("kty" in json) {
  4482. switch (json.kty.toUpperCase()) {
  4483. case "EC":
  4484. this.parsedKey = new ECPrivateKey({ json });
  4485. this.privateKeyAlgorithm = new AlgorithmIdentifier({
  4486. algorithmId: "1.2.840.10045.2.1",
  4487. algorithmParams: new asn1js.ObjectIdentifier({ value: this.parsedKey.namedCurve })
  4488. });
  4489. break;
  4490. case "RSA":
  4491. this.parsedKey = new RSAPrivateKey({ json });
  4492. this.privateKeyAlgorithm = new AlgorithmIdentifier({
  4493. algorithmId: "1.2.840.113549.1.1.1",
  4494. algorithmParams: new asn1js.Null()
  4495. });
  4496. break;
  4497. default:
  4498. throw new Error(`Invalid value for "kty" parameter: ${json.kty}`);
  4499. }
  4500. this.privateKey = new asn1js.OctetString({ valueHex: this.parsedKey.toSchema().toBER(false) });
  4501. }
  4502. }
  4503. }
  4504. PrivateKeyInfo.CLASS_NAME = "PrivateKeyInfo";
  4505. const CONTENT_TYPE$1 = "contentType";
  4506. const CONTENT_ENCRYPTION_ALGORITHM = "contentEncryptionAlgorithm";
  4507. const ENCRYPTED_CONTENT = "encryptedContent";
  4508. const CLEAR_PROPS$15 = [
  4509. CONTENT_TYPE$1,
  4510. CONTENT_ENCRYPTION_ALGORITHM,
  4511. ENCRYPTED_CONTENT,
  4512. ];
  4513. const PIECE_SIZE = 1024;
  4514. class EncryptedContentInfo extends PkiObject {
  4515. constructor(parameters = {}) {
  4516. super();
  4517. this.contentType = pvutils.getParametersValue(parameters, CONTENT_TYPE$1, EncryptedContentInfo.defaultValues(CONTENT_TYPE$1));
  4518. this.contentEncryptionAlgorithm = pvutils.getParametersValue(parameters, CONTENT_ENCRYPTION_ALGORITHM, EncryptedContentInfo.defaultValues(CONTENT_ENCRYPTION_ALGORITHM));
  4519. if (ENCRYPTED_CONTENT in parameters && parameters.encryptedContent) {
  4520. this.encryptedContent = parameters.encryptedContent;
  4521. if ((this.encryptedContent.idBlock.tagClass === 1) &&
  4522. (this.encryptedContent.idBlock.tagNumber === 4)) {
  4523. if (this.encryptedContent.idBlock.isConstructed === false && !parameters.disableSplit) {
  4524. const constrString = new asn1js.OctetString({
  4525. idBlock: { isConstructed: true },
  4526. isConstructed: true
  4527. });
  4528. let offset = 0;
  4529. const valueHex = this.encryptedContent.valueBlock.valueHexView.slice().buffer;
  4530. let length = valueHex.byteLength;
  4531. while (length > 0) {
  4532. const pieceView = new Uint8Array(valueHex, offset, ((offset + PIECE_SIZE) > valueHex.byteLength) ? (valueHex.byteLength - offset) : PIECE_SIZE);
  4533. const _array = new ArrayBuffer(pieceView.length);
  4534. const _view = new Uint8Array(_array);
  4535. for (let i = 0; i < _view.length; i++)
  4536. _view[i] = pieceView[i];
  4537. constrString.valueBlock.value.push(new asn1js.OctetString({ valueHex: _array }));
  4538. length -= pieceView.length;
  4539. offset += pieceView.length;
  4540. }
  4541. this.encryptedContent = constrString;
  4542. }
  4543. }
  4544. }
  4545. if (parameters.schema) {
  4546. this.fromSchema(parameters.schema);
  4547. }
  4548. }
  4549. static defaultValues(memberName) {
  4550. switch (memberName) {
  4551. case CONTENT_TYPE$1:
  4552. return EMPTY_STRING;
  4553. case CONTENT_ENCRYPTION_ALGORITHM:
  4554. return new AlgorithmIdentifier();
  4555. case ENCRYPTED_CONTENT:
  4556. return new asn1js.OctetString();
  4557. default:
  4558. return super.defaultValues(memberName);
  4559. }
  4560. }
  4561. static compareWithDefault(memberName, memberValue) {
  4562. switch (memberName) {
  4563. case CONTENT_TYPE$1:
  4564. return (memberValue === EMPTY_STRING);
  4565. case CONTENT_ENCRYPTION_ALGORITHM:
  4566. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  4567. case ENCRYPTED_CONTENT:
  4568. return (memberValue.isEqual(EncryptedContentInfo.defaultValues(ENCRYPTED_CONTENT)));
  4569. default:
  4570. return super.defaultValues(memberName);
  4571. }
  4572. }
  4573. static schema(parameters = {}) {
  4574. const names = pvutils.getParametersValue(parameters, "names", {});
  4575. return (new asn1js.Sequence({
  4576. name: (names.blockName || EMPTY_STRING),
  4577. value: [
  4578. new asn1js.ObjectIdentifier({ name: (names.contentType || EMPTY_STRING) }),
  4579. AlgorithmIdentifier.schema(names.contentEncryptionAlgorithm || {}),
  4580. new asn1js.Choice({
  4581. value: [
  4582. new asn1js.Constructed({
  4583. name: (names.encryptedContent || EMPTY_STRING),
  4584. idBlock: {
  4585. tagClass: 3,
  4586. tagNumber: 0
  4587. },
  4588. value: [
  4589. new asn1js.Repeated({
  4590. value: new asn1js.OctetString()
  4591. })
  4592. ]
  4593. }),
  4594. new asn1js.Primitive({
  4595. name: (names.encryptedContent || EMPTY_STRING),
  4596. idBlock: {
  4597. tagClass: 3,
  4598. tagNumber: 0
  4599. }
  4600. })
  4601. ]
  4602. })
  4603. ]
  4604. }));
  4605. }
  4606. fromSchema(schema) {
  4607. pvutils.clearProps(schema, CLEAR_PROPS$15);
  4608. const asn1 = asn1js.compareSchema(schema, schema, EncryptedContentInfo.schema({
  4609. names: {
  4610. contentType: CONTENT_TYPE$1,
  4611. contentEncryptionAlgorithm: {
  4612. names: {
  4613. blockName: CONTENT_ENCRYPTION_ALGORITHM
  4614. }
  4615. },
  4616. encryptedContent: ENCRYPTED_CONTENT
  4617. }
  4618. }));
  4619. AsnError.assertSchema(asn1, this.className);
  4620. this.contentType = asn1.result.contentType.valueBlock.toString();
  4621. this.contentEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.contentEncryptionAlgorithm });
  4622. if (ENCRYPTED_CONTENT in asn1.result) {
  4623. this.encryptedContent = asn1.result.encryptedContent;
  4624. this.encryptedContent.idBlock.tagClass = 1;
  4625. this.encryptedContent.idBlock.tagNumber = 4;
  4626. }
  4627. }
  4628. toSchema() {
  4629. const sequenceLengthBlock = {
  4630. isIndefiniteForm: false
  4631. };
  4632. const outputArray = [];
  4633. outputArray.push(new asn1js.ObjectIdentifier({ value: this.contentType }));
  4634. outputArray.push(this.contentEncryptionAlgorithm.toSchema());
  4635. if (this.encryptedContent) {
  4636. sequenceLengthBlock.isIndefiniteForm = this.encryptedContent.idBlock.isConstructed;
  4637. const encryptedValue = this.encryptedContent;
  4638. encryptedValue.idBlock.tagClass = 3;
  4639. encryptedValue.idBlock.tagNumber = 0;
  4640. encryptedValue.lenBlock.isIndefiniteForm = this.encryptedContent.idBlock.isConstructed;
  4641. outputArray.push(encryptedValue);
  4642. }
  4643. return (new asn1js.Sequence({
  4644. lenBlock: sequenceLengthBlock,
  4645. value: outputArray
  4646. }));
  4647. }
  4648. toJSON() {
  4649. const res = {
  4650. contentType: this.contentType,
  4651. contentEncryptionAlgorithm: this.contentEncryptionAlgorithm.toJSON()
  4652. };
  4653. if (this.encryptedContent) {
  4654. res.encryptedContent = this.encryptedContent.toJSON();
  4655. }
  4656. return res;
  4657. }
  4658. getEncryptedContent() {
  4659. if (!this.encryptedContent) {
  4660. throw new Error("Parameter 'encryptedContent' is undefined");
  4661. }
  4662. return asn1js.OctetString.prototype.getValue.call(this.encryptedContent);
  4663. }
  4664. }
  4665. EncryptedContentInfo.CLASS_NAME = "EncryptedContentInfo";
  4666. const HASH_ALGORITHM$4 = "hashAlgorithm";
  4667. const MASK_GEN_ALGORITHM$1 = "maskGenAlgorithm";
  4668. const SALT_LENGTH = "saltLength";
  4669. const TRAILER_FIELD = "trailerField";
  4670. const CLEAR_PROPS$14 = [
  4671. HASH_ALGORITHM$4,
  4672. MASK_GEN_ALGORITHM$1,
  4673. SALT_LENGTH,
  4674. TRAILER_FIELD
  4675. ];
  4676. class RSASSAPSSParams extends PkiObject {
  4677. constructor(parameters = {}) {
  4678. super();
  4679. this.hashAlgorithm = pvutils.getParametersValue(parameters, HASH_ALGORITHM$4, RSASSAPSSParams.defaultValues(HASH_ALGORITHM$4));
  4680. this.maskGenAlgorithm = pvutils.getParametersValue(parameters, MASK_GEN_ALGORITHM$1, RSASSAPSSParams.defaultValues(MASK_GEN_ALGORITHM$1));
  4681. this.saltLength = pvutils.getParametersValue(parameters, SALT_LENGTH, RSASSAPSSParams.defaultValues(SALT_LENGTH));
  4682. this.trailerField = pvutils.getParametersValue(parameters, TRAILER_FIELD, RSASSAPSSParams.defaultValues(TRAILER_FIELD));
  4683. if (parameters.schema) {
  4684. this.fromSchema(parameters.schema);
  4685. }
  4686. }
  4687. static defaultValues(memberName) {
  4688. switch (memberName) {
  4689. case HASH_ALGORITHM$4:
  4690. return new AlgorithmIdentifier({
  4691. algorithmId: "1.3.14.3.2.26",
  4692. algorithmParams: new asn1js.Null()
  4693. });
  4694. case MASK_GEN_ALGORITHM$1:
  4695. return new AlgorithmIdentifier({
  4696. algorithmId: "1.2.840.113549.1.1.8",
  4697. algorithmParams: (new AlgorithmIdentifier({
  4698. algorithmId: "1.3.14.3.2.26",
  4699. algorithmParams: new asn1js.Null()
  4700. })).toSchema()
  4701. });
  4702. case SALT_LENGTH:
  4703. return 20;
  4704. case TRAILER_FIELD:
  4705. return 1;
  4706. default:
  4707. return super.defaultValues(memberName);
  4708. }
  4709. }
  4710. static schema(parameters = {}) {
  4711. const names = pvutils.getParametersValue(parameters, "names", {});
  4712. return (new asn1js.Sequence({
  4713. name: (names.blockName || EMPTY_STRING),
  4714. value: [
  4715. new asn1js.Constructed({
  4716. idBlock: {
  4717. tagClass: 3,
  4718. tagNumber: 0
  4719. },
  4720. optional: true,
  4721. value: [AlgorithmIdentifier.schema(names.hashAlgorithm || {})]
  4722. }),
  4723. new asn1js.Constructed({
  4724. idBlock: {
  4725. tagClass: 3,
  4726. tagNumber: 1
  4727. },
  4728. optional: true,
  4729. value: [AlgorithmIdentifier.schema(names.maskGenAlgorithm || {})]
  4730. }),
  4731. new asn1js.Constructed({
  4732. idBlock: {
  4733. tagClass: 3,
  4734. tagNumber: 2
  4735. },
  4736. optional: true,
  4737. value: [new asn1js.Integer({ name: (names.saltLength || EMPTY_STRING) })]
  4738. }),
  4739. new asn1js.Constructed({
  4740. idBlock: {
  4741. tagClass: 3,
  4742. tagNumber: 3
  4743. },
  4744. optional: true,
  4745. value: [new asn1js.Integer({ name: (names.trailerField || EMPTY_STRING) })]
  4746. })
  4747. ]
  4748. }));
  4749. }
  4750. fromSchema(schema) {
  4751. pvutils.clearProps(schema, CLEAR_PROPS$14);
  4752. const asn1 = asn1js.compareSchema(schema, schema, RSASSAPSSParams.schema({
  4753. names: {
  4754. hashAlgorithm: {
  4755. names: {
  4756. blockName: HASH_ALGORITHM$4
  4757. }
  4758. },
  4759. maskGenAlgorithm: {
  4760. names: {
  4761. blockName: MASK_GEN_ALGORITHM$1
  4762. }
  4763. },
  4764. saltLength: SALT_LENGTH,
  4765. trailerField: TRAILER_FIELD
  4766. }
  4767. }));
  4768. AsnError.assertSchema(asn1, this.className);
  4769. if (HASH_ALGORITHM$4 in asn1.result)
  4770. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  4771. if (MASK_GEN_ALGORITHM$1 in asn1.result)
  4772. this.maskGenAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.maskGenAlgorithm });
  4773. if (SALT_LENGTH in asn1.result)
  4774. this.saltLength = asn1.result.saltLength.valueBlock.valueDec;
  4775. if (TRAILER_FIELD in asn1.result)
  4776. this.trailerField = asn1.result.trailerField.valueBlock.valueDec;
  4777. }
  4778. toSchema() {
  4779. const outputArray = [];
  4780. if (!this.hashAlgorithm.isEqual(RSASSAPSSParams.defaultValues(HASH_ALGORITHM$4))) {
  4781. outputArray.push(new asn1js.Constructed({
  4782. idBlock: {
  4783. tagClass: 3,
  4784. tagNumber: 0
  4785. },
  4786. value: [this.hashAlgorithm.toSchema()]
  4787. }));
  4788. }
  4789. if (!this.maskGenAlgorithm.isEqual(RSASSAPSSParams.defaultValues(MASK_GEN_ALGORITHM$1))) {
  4790. outputArray.push(new asn1js.Constructed({
  4791. idBlock: {
  4792. tagClass: 3,
  4793. tagNumber: 1
  4794. },
  4795. value: [this.maskGenAlgorithm.toSchema()]
  4796. }));
  4797. }
  4798. if (this.saltLength !== RSASSAPSSParams.defaultValues(SALT_LENGTH)) {
  4799. outputArray.push(new asn1js.Constructed({
  4800. idBlock: {
  4801. tagClass: 3,
  4802. tagNumber: 2
  4803. },
  4804. value: [new asn1js.Integer({ value: this.saltLength })]
  4805. }));
  4806. }
  4807. if (this.trailerField !== RSASSAPSSParams.defaultValues(TRAILER_FIELD)) {
  4808. outputArray.push(new asn1js.Constructed({
  4809. idBlock: {
  4810. tagClass: 3,
  4811. tagNumber: 3
  4812. },
  4813. value: [new asn1js.Integer({ value: this.trailerField })]
  4814. }));
  4815. }
  4816. return (new asn1js.Sequence({
  4817. value: outputArray
  4818. }));
  4819. }
  4820. toJSON() {
  4821. const res = {};
  4822. if (!this.hashAlgorithm.isEqual(RSASSAPSSParams.defaultValues(HASH_ALGORITHM$4))) {
  4823. res.hashAlgorithm = this.hashAlgorithm.toJSON();
  4824. }
  4825. if (!this.maskGenAlgorithm.isEqual(RSASSAPSSParams.defaultValues(MASK_GEN_ALGORITHM$1))) {
  4826. res.maskGenAlgorithm = this.maskGenAlgorithm.toJSON();
  4827. }
  4828. if (this.saltLength !== RSASSAPSSParams.defaultValues(SALT_LENGTH)) {
  4829. res.saltLength = this.saltLength;
  4830. }
  4831. if (this.trailerField !== RSASSAPSSParams.defaultValues(TRAILER_FIELD)) {
  4832. res.trailerField = this.trailerField;
  4833. }
  4834. return res;
  4835. }
  4836. }
  4837. RSASSAPSSParams.CLASS_NAME = "RSASSAPSSParams";
  4838. const SALT = "salt";
  4839. const ITERATION_COUNT = "iterationCount";
  4840. const KEY_LENGTH = "keyLength";
  4841. const PRF = "prf";
  4842. const CLEAR_PROPS$13 = [
  4843. SALT,
  4844. ITERATION_COUNT,
  4845. KEY_LENGTH,
  4846. PRF
  4847. ];
  4848. class PBKDF2Params extends PkiObject {
  4849. constructor(parameters = {}) {
  4850. super();
  4851. this.salt = pvutils.getParametersValue(parameters, SALT, PBKDF2Params.defaultValues(SALT));
  4852. this.iterationCount = pvutils.getParametersValue(parameters, ITERATION_COUNT, PBKDF2Params.defaultValues(ITERATION_COUNT));
  4853. if (KEY_LENGTH in parameters) {
  4854. this.keyLength = pvutils.getParametersValue(parameters, KEY_LENGTH, PBKDF2Params.defaultValues(KEY_LENGTH));
  4855. }
  4856. if (PRF in parameters) {
  4857. this.prf = pvutils.getParametersValue(parameters, PRF, PBKDF2Params.defaultValues(PRF));
  4858. }
  4859. if (parameters.schema) {
  4860. this.fromSchema(parameters.schema);
  4861. }
  4862. }
  4863. static defaultValues(memberName) {
  4864. switch (memberName) {
  4865. case SALT:
  4866. return {};
  4867. case ITERATION_COUNT:
  4868. return (-1);
  4869. case KEY_LENGTH:
  4870. return 0;
  4871. case PRF:
  4872. return new AlgorithmIdentifier({
  4873. algorithmId: "1.3.14.3.2.26",
  4874. algorithmParams: new asn1js.Null()
  4875. });
  4876. default:
  4877. return super.defaultValues(memberName);
  4878. }
  4879. }
  4880. static schema(parameters = {}) {
  4881. const names = pvutils.getParametersValue(parameters, "names", {});
  4882. return (new asn1js.Sequence({
  4883. name: (names.blockName || EMPTY_STRING),
  4884. value: [
  4885. new asn1js.Choice({
  4886. value: [
  4887. new asn1js.OctetString({ name: (names.saltPrimitive || EMPTY_STRING) }),
  4888. AlgorithmIdentifier.schema(names.saltConstructed || {})
  4889. ]
  4890. }),
  4891. new asn1js.Integer({ name: (names.iterationCount || EMPTY_STRING) }),
  4892. new asn1js.Integer({
  4893. name: (names.keyLength || EMPTY_STRING),
  4894. optional: true
  4895. }),
  4896. AlgorithmIdentifier.schema(names.prf || {
  4897. names: {
  4898. optional: true
  4899. }
  4900. })
  4901. ]
  4902. }));
  4903. }
  4904. fromSchema(schema) {
  4905. pvutils.clearProps(schema, CLEAR_PROPS$13);
  4906. const asn1 = asn1js.compareSchema(schema, schema, PBKDF2Params.schema({
  4907. names: {
  4908. saltPrimitive: SALT,
  4909. saltConstructed: {
  4910. names: {
  4911. blockName: SALT
  4912. }
  4913. },
  4914. iterationCount: ITERATION_COUNT,
  4915. keyLength: KEY_LENGTH,
  4916. prf: {
  4917. names: {
  4918. blockName: PRF,
  4919. optional: true
  4920. }
  4921. }
  4922. }
  4923. }));
  4924. AsnError.assertSchema(asn1, this.className);
  4925. this.salt = asn1.result.salt;
  4926. this.iterationCount = asn1.result.iterationCount.valueBlock.valueDec;
  4927. if (KEY_LENGTH in asn1.result)
  4928. this.keyLength = asn1.result.keyLength.valueBlock.valueDec;
  4929. if (PRF in asn1.result)
  4930. this.prf = new AlgorithmIdentifier({ schema: asn1.result.prf });
  4931. }
  4932. toSchema() {
  4933. const outputArray = [];
  4934. outputArray.push(this.salt);
  4935. outputArray.push(new asn1js.Integer({ value: this.iterationCount }));
  4936. if (KEY_LENGTH in this) {
  4937. if (PBKDF2Params.defaultValues(KEY_LENGTH) !== this.keyLength)
  4938. outputArray.push(new asn1js.Integer({ value: this.keyLength }));
  4939. }
  4940. if (this.prf) {
  4941. if (PBKDF2Params.defaultValues(PRF).isEqual(this.prf) === false)
  4942. outputArray.push(this.prf.toSchema());
  4943. }
  4944. return (new asn1js.Sequence({
  4945. value: outputArray
  4946. }));
  4947. }
  4948. toJSON() {
  4949. const res = {
  4950. salt: this.salt.toJSON(),
  4951. iterationCount: this.iterationCount
  4952. };
  4953. if (KEY_LENGTH in this) {
  4954. if (PBKDF2Params.defaultValues(KEY_LENGTH) !== this.keyLength)
  4955. res.keyLength = this.keyLength;
  4956. }
  4957. if (this.prf) {
  4958. if (PBKDF2Params.defaultValues(PRF).isEqual(this.prf) === false)
  4959. res.prf = this.prf.toJSON();
  4960. }
  4961. return res;
  4962. }
  4963. }
  4964. PBKDF2Params.CLASS_NAME = "PBKDF2Params";
  4965. const KEY_DERIVATION_FUNC = "keyDerivationFunc";
  4966. const ENCRYPTION_SCHEME = "encryptionScheme";
  4967. const CLEAR_PROPS$12 = [
  4968. KEY_DERIVATION_FUNC,
  4969. ENCRYPTION_SCHEME
  4970. ];
  4971. class PBES2Params extends PkiObject {
  4972. constructor(parameters = {}) {
  4973. super();
  4974. this.keyDerivationFunc = pvutils.getParametersValue(parameters, KEY_DERIVATION_FUNC, PBES2Params.defaultValues(KEY_DERIVATION_FUNC));
  4975. this.encryptionScheme = pvutils.getParametersValue(parameters, ENCRYPTION_SCHEME, PBES2Params.defaultValues(ENCRYPTION_SCHEME));
  4976. if (parameters.schema) {
  4977. this.fromSchema(parameters.schema);
  4978. }
  4979. }
  4980. static defaultValues(memberName) {
  4981. switch (memberName) {
  4982. case KEY_DERIVATION_FUNC:
  4983. return new AlgorithmIdentifier();
  4984. case ENCRYPTION_SCHEME:
  4985. return new AlgorithmIdentifier();
  4986. default:
  4987. return super.defaultValues(memberName);
  4988. }
  4989. }
  4990. static schema(parameters = {}) {
  4991. const names = pvutils.getParametersValue(parameters, "names", {});
  4992. return (new asn1js.Sequence({
  4993. name: (names.blockName || EMPTY_STRING),
  4994. value: [
  4995. AlgorithmIdentifier.schema(names.keyDerivationFunc || {}),
  4996. AlgorithmIdentifier.schema(names.encryptionScheme || {})
  4997. ]
  4998. }));
  4999. }
  5000. fromSchema(schema) {
  5001. pvutils.clearProps(schema, CLEAR_PROPS$12);
  5002. const asn1 = asn1js.compareSchema(schema, schema, PBES2Params.schema({
  5003. names: {
  5004. keyDerivationFunc: {
  5005. names: {
  5006. blockName: KEY_DERIVATION_FUNC
  5007. }
  5008. },
  5009. encryptionScheme: {
  5010. names: {
  5011. blockName: ENCRYPTION_SCHEME
  5012. }
  5013. }
  5014. }
  5015. }));
  5016. AsnError.assertSchema(asn1, this.className);
  5017. this.keyDerivationFunc = new AlgorithmIdentifier({ schema: asn1.result.keyDerivationFunc });
  5018. this.encryptionScheme = new AlgorithmIdentifier({ schema: asn1.result.encryptionScheme });
  5019. }
  5020. toSchema() {
  5021. return (new asn1js.Sequence({
  5022. value: [
  5023. this.keyDerivationFunc.toSchema(),
  5024. this.encryptionScheme.toSchema()
  5025. ]
  5026. }));
  5027. }
  5028. toJSON() {
  5029. return {
  5030. keyDerivationFunc: this.keyDerivationFunc.toJSON(),
  5031. encryptionScheme: this.encryptionScheme.toJSON()
  5032. };
  5033. }
  5034. }
  5035. PBES2Params.CLASS_NAME = "PBES2Params";
  5036. class AbstractCryptoEngine {
  5037. constructor(parameters) {
  5038. this.crypto = parameters.crypto;
  5039. this.subtle = "webkitSubtle" in parameters.crypto
  5040. ? parameters.crypto.webkitSubtle
  5041. : parameters.crypto.subtle;
  5042. this.name = pvutils.getParametersValue(parameters, "name", EMPTY_STRING);
  5043. }
  5044. async encrypt(...args) {
  5045. return this.subtle.encrypt(...args);
  5046. }
  5047. async decrypt(...args) {
  5048. return this.subtle.decrypt(...args);
  5049. }
  5050. sign(...args) {
  5051. return this.subtle.sign(...args);
  5052. }
  5053. async verify(...args) {
  5054. return this.subtle.verify(...args);
  5055. }
  5056. async digest(...args) {
  5057. return this.subtle.digest(...args);
  5058. }
  5059. async generateKey(...args) {
  5060. return this.subtle.generateKey(...args);
  5061. }
  5062. async deriveKey(...args) {
  5063. return this.subtle.deriveKey(...args);
  5064. }
  5065. async deriveBits(...args) {
  5066. return this.subtle.deriveBits(...args);
  5067. }
  5068. async wrapKey(...args) {
  5069. return this.subtle.wrapKey(...args);
  5070. }
  5071. async unwrapKey(...args) {
  5072. return this.subtle.unwrapKey(...args);
  5073. }
  5074. exportKey(...args) {
  5075. return this.subtle.exportKey(...args);
  5076. }
  5077. importKey(...args) {
  5078. return this.subtle.importKey(...args);
  5079. }
  5080. getRandomValues(array) {
  5081. if (array === null) {
  5082. throw new Error("Argument \"array\" must not be null");
  5083. }
  5084. return this.crypto.getRandomValues(array);
  5085. }
  5086. }
  5087. async function makePKCS12B2Key(hashAlgorithm, keyLength, password, salt, iterationCount) {
  5088. let u;
  5089. let v;
  5090. let md;
  5091. switch (hashAlgorithm.toUpperCase()) {
  5092. case "SHA-1":
  5093. u = 20;
  5094. v = 64;
  5095. md = sha1;
  5096. break;
  5097. case "SHA-256":
  5098. u = 32;
  5099. v = 64;
  5100. md = sha256;
  5101. break;
  5102. case "SHA-384":
  5103. u = 48;
  5104. v = 128;
  5105. md = sha384;
  5106. break;
  5107. case "SHA-512":
  5108. u = 64;
  5109. v = 128;
  5110. md = sha512;
  5111. break;
  5112. default:
  5113. throw new Error("Unsupported hashing algorithm");
  5114. }
  5115. const originalPassword = new Uint8Array(password);
  5116. let decodedPassword = new TextDecoder().decode(password);
  5117. const encodedPassword = new TextEncoder().encode(decodedPassword);
  5118. if (encodedPassword.some((byte, i) => byte !== originalPassword[i])) {
  5119. decodedPassword = String.fromCharCode(...originalPassword);
  5120. }
  5121. const passwordTransformed = new Uint8Array(decodedPassword.length * 2 + 2);
  5122. const passwordView = new DataView(passwordTransformed.buffer);
  5123. for (let i = 0; i < decodedPassword.length; i++) {
  5124. passwordView.setUint16(i * 2, decodedPassword.charCodeAt(i), false);
  5125. }
  5126. passwordView.setUint16(decodedPassword.length * 2, 0, false);
  5127. const D = new Uint8Array(v).fill(3);
  5128. const saltView = new Uint8Array(salt);
  5129. const S = new Uint8Array(v * Math.ceil(saltView.length / v)).map((_, i) => saltView[i % saltView.length]);
  5130. const P = new Uint8Array(v * Math.ceil(passwordTransformed.length / v)).map((_, i) => passwordTransformed[i % passwordTransformed.length]);
  5131. let I = new Uint8Array(S.length + P.length);
  5132. I.set(S);
  5133. I.set(P, S.length);
  5134. const c = Math.ceil((keyLength >> 3) / u);
  5135. const result = [];
  5136. for (let i = 0; i < c; i++) {
  5137. let A = new Uint8Array(D.length + I.length);
  5138. A.set(D);
  5139. A.set(I, D.length);
  5140. for (let j = 0; j < iterationCount; j++) {
  5141. A = md(A);
  5142. }
  5143. const B = new Uint8Array(v).map((_, i) => A[i % A.length]);
  5144. const k = Math.ceil(saltView.length / v) + Math.ceil(passwordTransformed.length / v);
  5145. const iRound = [];
  5146. for (let j = 0; j < k; j++) {
  5147. const chunk = Array.from(I.slice(j * v, (j + 1) * v));
  5148. let x = 0x1ff;
  5149. for (let l = B.length - 1; l >= 0; l--) {
  5150. x >>= 8;
  5151. x += B[l] + (chunk[l] || 0);
  5152. chunk[l] = x & 0xff;
  5153. }
  5154. iRound.push(...chunk);
  5155. }
  5156. I = new Uint8Array(iRound);
  5157. result.push(...A);
  5158. }
  5159. return new Uint8Array(result.slice(0, keyLength >> 3)).buffer;
  5160. }
  5161. function prepareAlgorithm(data) {
  5162. const res = typeof data === "string"
  5163. ? { name: data }
  5164. : data;
  5165. if ("hash" in res) {
  5166. return {
  5167. ...res,
  5168. hash: prepareAlgorithm(res.hash)
  5169. };
  5170. }
  5171. return res;
  5172. }
  5173. class CryptoEngine extends AbstractCryptoEngine {
  5174. async importKey(format, keyData, algorithm, extractable, keyUsages) {
  5175. var _a, _b, _c, _d, _e, _f;
  5176. let jwk = {};
  5177. const alg = prepareAlgorithm(algorithm);
  5178. switch (format.toLowerCase()) {
  5179. case "raw":
  5180. return this.subtle.importKey("raw", keyData, algorithm, extractable, keyUsages);
  5181. case "spki":
  5182. {
  5183. const asn1 = asn1js.fromBER(pvtsutils.BufferSourceConverter.toArrayBuffer(keyData));
  5184. AsnError.assert(asn1, "keyData");
  5185. const publicKeyInfo = new PublicKeyInfo();
  5186. try {
  5187. publicKeyInfo.fromSchema(asn1.result);
  5188. }
  5189. catch {
  5190. throw new ArgumentError("Incorrect keyData");
  5191. }
  5192. switch (alg.name.toUpperCase()) {
  5193. case "RSA-PSS":
  5194. {
  5195. if (!alg.hash) {
  5196. throw new ParameterError("hash", "algorithm.hash", "Incorrect hash algorithm: Hash algorithm is missed");
  5197. }
  5198. switch (alg.hash.name.toUpperCase()) {
  5199. case "SHA-1":
  5200. jwk.alg = "PS1";
  5201. break;
  5202. case "SHA-256":
  5203. jwk.alg = "PS256";
  5204. break;
  5205. case "SHA-384":
  5206. jwk.alg = "PS384";
  5207. break;
  5208. case "SHA-512":
  5209. jwk.alg = "PS512";
  5210. break;
  5211. default:
  5212. throw new Error(`Incorrect hash algorithm: ${alg.hash.name.toUpperCase()}`);
  5213. }
  5214. }
  5215. case "RSASSA-PKCS1-V1_5":
  5216. {
  5217. keyUsages = ["verify"];
  5218. jwk.kty = "RSA";
  5219. jwk.ext = extractable;
  5220. jwk.key_ops = keyUsages;
  5221. if (publicKeyInfo.algorithm.algorithmId !== "1.2.840.113549.1.1.1")
  5222. throw new Error(`Incorrect public key algorithm: ${publicKeyInfo.algorithm.algorithmId}`);
  5223. if (!jwk.alg) {
  5224. if (!alg.hash) {
  5225. throw new ParameterError("hash", "algorithm.hash", "Incorrect hash algorithm: Hash algorithm is missed");
  5226. }
  5227. switch (alg.hash.name.toUpperCase()) {
  5228. case "SHA-1":
  5229. jwk.alg = "RS1";
  5230. break;
  5231. case "SHA-256":
  5232. jwk.alg = "RS256";
  5233. break;
  5234. case "SHA-384":
  5235. jwk.alg = "RS384";
  5236. break;
  5237. case "SHA-512":
  5238. jwk.alg = "RS512";
  5239. break;
  5240. default:
  5241. throw new Error(`Incorrect hash algorithm: ${alg.hash.name.toUpperCase()}`);
  5242. }
  5243. }
  5244. const publicKeyJSON = publicKeyInfo.toJSON();
  5245. Object.assign(jwk, publicKeyJSON);
  5246. }
  5247. break;
  5248. case "ECDSA":
  5249. keyUsages = ["verify"];
  5250. case "ECDH":
  5251. {
  5252. jwk = {
  5253. kty: "EC",
  5254. ext: extractable,
  5255. key_ops: keyUsages
  5256. };
  5257. if (publicKeyInfo.algorithm.algorithmId !== "1.2.840.10045.2.1") {
  5258. throw new Error(`Incorrect public key algorithm: ${publicKeyInfo.algorithm.algorithmId}`);
  5259. }
  5260. const publicKeyJSON = publicKeyInfo.toJSON();
  5261. Object.assign(jwk, publicKeyJSON);
  5262. }
  5263. break;
  5264. case "RSA-OAEP":
  5265. {
  5266. jwk.kty = "RSA";
  5267. jwk.ext = extractable;
  5268. jwk.key_ops = keyUsages;
  5269. if (this.name.toLowerCase() === "safari")
  5270. jwk.alg = "RSA-OAEP";
  5271. else {
  5272. if (!alg.hash) {
  5273. throw new ParameterError("hash", "algorithm.hash", "Incorrect hash algorithm: Hash algorithm is missed");
  5274. }
  5275. switch (alg.hash.name.toUpperCase()) {
  5276. case "SHA-1":
  5277. jwk.alg = "RSA-OAEP";
  5278. break;
  5279. case "SHA-256":
  5280. jwk.alg = "RSA-OAEP-256";
  5281. break;
  5282. case "SHA-384":
  5283. jwk.alg = "RSA-OAEP-384";
  5284. break;
  5285. case "SHA-512":
  5286. jwk.alg = "RSA-OAEP-512";
  5287. break;
  5288. default:
  5289. throw new Error(`Incorrect hash algorithm: ${alg.hash.name.toUpperCase()}`);
  5290. }
  5291. }
  5292. const publicKeyJSON = publicKeyInfo.toJSON();
  5293. Object.assign(jwk, publicKeyJSON);
  5294. }
  5295. break;
  5296. case "RSAES-PKCS1-V1_5":
  5297. {
  5298. jwk.kty = "RSA";
  5299. jwk.ext = extractable;
  5300. jwk.key_ops = keyUsages;
  5301. jwk.alg = "PS1";
  5302. const publicKeyJSON = publicKeyInfo.toJSON();
  5303. Object.assign(jwk, publicKeyJSON);
  5304. }
  5305. break;
  5306. default:
  5307. throw new Error(`Incorrect algorithm name: ${alg.name.toUpperCase()}`);
  5308. }
  5309. }
  5310. break;
  5311. case "pkcs8":
  5312. {
  5313. const privateKeyInfo = new PrivateKeyInfo();
  5314. const asn1 = asn1js.fromBER(pvtsutils.BufferSourceConverter.toArrayBuffer(keyData));
  5315. AsnError.assert(asn1, "keyData");
  5316. try {
  5317. privateKeyInfo.fromSchema(asn1.result);
  5318. }
  5319. catch {
  5320. throw new Error("Incorrect keyData");
  5321. }
  5322. if (!privateKeyInfo.parsedKey)
  5323. throw new Error("Incorrect keyData");
  5324. switch (alg.name.toUpperCase()) {
  5325. case "RSA-PSS":
  5326. {
  5327. switch ((_a = alg.hash) === null || _a === void 0 ? void 0 : _a.name.toUpperCase()) {
  5328. case "SHA-1":
  5329. jwk.alg = "PS1";
  5330. break;
  5331. case "SHA-256":
  5332. jwk.alg = "PS256";
  5333. break;
  5334. case "SHA-384":
  5335. jwk.alg = "PS384";
  5336. break;
  5337. case "SHA-512":
  5338. jwk.alg = "PS512";
  5339. break;
  5340. default:
  5341. throw new Error(`Incorrect hash algorithm: ${(_b = alg.hash) === null || _b === void 0 ? void 0 : _b.name.toUpperCase()}`);
  5342. }
  5343. }
  5344. case "RSASSA-PKCS1-V1_5":
  5345. {
  5346. keyUsages = ["sign"];
  5347. jwk.kty = "RSA";
  5348. jwk.ext = extractable;
  5349. jwk.key_ops = keyUsages;
  5350. if (privateKeyInfo.privateKeyAlgorithm.algorithmId !== "1.2.840.113549.1.1.1")
  5351. throw new Error(`Incorrect private key algorithm: ${privateKeyInfo.privateKeyAlgorithm.algorithmId}`);
  5352. if (("alg" in jwk) === false) {
  5353. switch ((_c = alg.hash) === null || _c === void 0 ? void 0 : _c.name.toUpperCase()) {
  5354. case "SHA-1":
  5355. jwk.alg = "RS1";
  5356. break;
  5357. case "SHA-256":
  5358. jwk.alg = "RS256";
  5359. break;
  5360. case "SHA-384":
  5361. jwk.alg = "RS384";
  5362. break;
  5363. case "SHA-512":
  5364. jwk.alg = "RS512";
  5365. break;
  5366. default:
  5367. throw new Error(`Incorrect hash algorithm: ${(_d = alg.hash) === null || _d === void 0 ? void 0 : _d.name.toUpperCase()}`);
  5368. }
  5369. }
  5370. const privateKeyJSON = privateKeyInfo.toJSON();
  5371. Object.assign(jwk, privateKeyJSON);
  5372. }
  5373. break;
  5374. case "ECDSA":
  5375. keyUsages = ["sign"];
  5376. case "ECDH":
  5377. {
  5378. jwk = {
  5379. kty: "EC",
  5380. ext: extractable,
  5381. key_ops: keyUsages
  5382. };
  5383. if (privateKeyInfo.privateKeyAlgorithm.algorithmId !== "1.2.840.10045.2.1")
  5384. throw new Error(`Incorrect algorithm: ${privateKeyInfo.privateKeyAlgorithm.algorithmId}`);
  5385. const privateKeyJSON = privateKeyInfo.toJSON();
  5386. Object.assign(jwk, privateKeyJSON);
  5387. }
  5388. break;
  5389. case "RSA-OAEP":
  5390. {
  5391. jwk.kty = "RSA";
  5392. jwk.ext = extractable;
  5393. jwk.key_ops = keyUsages;
  5394. if (this.name.toLowerCase() === "safari")
  5395. jwk.alg = "RSA-OAEP";
  5396. else {
  5397. switch ((_e = alg.hash) === null || _e === void 0 ? void 0 : _e.name.toUpperCase()) {
  5398. case "SHA-1":
  5399. jwk.alg = "RSA-OAEP";
  5400. break;
  5401. case "SHA-256":
  5402. jwk.alg = "RSA-OAEP-256";
  5403. break;
  5404. case "SHA-384":
  5405. jwk.alg = "RSA-OAEP-384";
  5406. break;
  5407. case "SHA-512":
  5408. jwk.alg = "RSA-OAEP-512";
  5409. break;
  5410. default:
  5411. throw new Error(`Incorrect hash algorithm: ${(_f = alg.hash) === null || _f === void 0 ? void 0 : _f.name.toUpperCase()}`);
  5412. }
  5413. }
  5414. const privateKeyJSON = privateKeyInfo.toJSON();
  5415. Object.assign(jwk, privateKeyJSON);
  5416. }
  5417. break;
  5418. case "RSAES-PKCS1-V1_5":
  5419. {
  5420. keyUsages = ["decrypt"];
  5421. jwk.kty = "RSA";
  5422. jwk.ext = extractable;
  5423. jwk.key_ops = keyUsages;
  5424. jwk.alg = "PS1";
  5425. const privateKeyJSON = privateKeyInfo.toJSON();
  5426. Object.assign(jwk, privateKeyJSON);
  5427. }
  5428. break;
  5429. default:
  5430. throw new Error(`Incorrect algorithm name: ${alg.name.toUpperCase()}`);
  5431. }
  5432. }
  5433. break;
  5434. case "jwk":
  5435. jwk = keyData;
  5436. break;
  5437. default:
  5438. throw new Error(`Incorrect format: ${format}`);
  5439. }
  5440. if (this.name.toLowerCase() === "safari") {
  5441. try {
  5442. return this.subtle.importKey("jwk", pvutils.stringToArrayBuffer(JSON.stringify(jwk)), algorithm, extractable, keyUsages);
  5443. }
  5444. catch {
  5445. return this.subtle.importKey("jwk", jwk, algorithm, extractable, keyUsages);
  5446. }
  5447. }
  5448. return this.subtle.importKey("jwk", jwk, algorithm, extractable, keyUsages);
  5449. }
  5450. async exportKey(format, key) {
  5451. let jwk = await this.subtle.exportKey("jwk", key);
  5452. if (this.name.toLowerCase() === "safari") {
  5453. if (jwk instanceof ArrayBuffer) {
  5454. jwk = JSON.parse(pvutils.arrayBufferToString(jwk));
  5455. }
  5456. }
  5457. switch (format.toLowerCase()) {
  5458. case "raw":
  5459. return this.subtle.exportKey("raw", key);
  5460. case "spki": {
  5461. const publicKeyInfo = new PublicKeyInfo();
  5462. try {
  5463. publicKeyInfo.fromJSON(jwk);
  5464. }
  5465. catch {
  5466. throw new Error("Incorrect key data");
  5467. }
  5468. return publicKeyInfo.toSchema().toBER(false);
  5469. }
  5470. case "pkcs8": {
  5471. const privateKeyInfo = new PrivateKeyInfo();
  5472. try {
  5473. privateKeyInfo.fromJSON(jwk);
  5474. }
  5475. catch {
  5476. throw new Error("Incorrect key data");
  5477. }
  5478. return privateKeyInfo.toSchema().toBER(false);
  5479. }
  5480. case "jwk":
  5481. return jwk;
  5482. default:
  5483. throw new Error(`Incorrect format: ${format}`);
  5484. }
  5485. }
  5486. async convert(inputFormat, outputFormat, keyData, algorithm, extractable, keyUsages) {
  5487. if (inputFormat.toLowerCase() === outputFormat.toLowerCase()) {
  5488. return keyData;
  5489. }
  5490. const key = await this.importKey(inputFormat, keyData, algorithm, extractable, keyUsages);
  5491. return this.exportKey(outputFormat, key);
  5492. }
  5493. getAlgorithmByOID(oid, safety = false, target) {
  5494. switch (oid) {
  5495. case "1.2.840.113549.1.1.1":
  5496. return {
  5497. name: "RSAES-PKCS1-v1_5"
  5498. };
  5499. case "1.2.840.113549.1.1.5":
  5500. return {
  5501. name: "RSASSA-PKCS1-v1_5",
  5502. hash: {
  5503. name: "SHA-1"
  5504. }
  5505. };
  5506. case "1.2.840.113549.1.1.11":
  5507. return {
  5508. name: "RSASSA-PKCS1-v1_5",
  5509. hash: {
  5510. name: "SHA-256"
  5511. }
  5512. };
  5513. case "1.2.840.113549.1.1.12":
  5514. return {
  5515. name: "RSASSA-PKCS1-v1_5",
  5516. hash: {
  5517. name: "SHA-384"
  5518. }
  5519. };
  5520. case "1.2.840.113549.1.1.13":
  5521. return {
  5522. name: "RSASSA-PKCS1-v1_5",
  5523. hash: {
  5524. name: "SHA-512"
  5525. }
  5526. };
  5527. case "1.2.840.113549.1.1.10":
  5528. return {
  5529. name: "RSA-PSS"
  5530. };
  5531. case "1.2.840.113549.1.1.7":
  5532. return {
  5533. name: "RSA-OAEP"
  5534. };
  5535. case "1.2.840.10045.2.1":
  5536. case "1.2.840.10045.4.1":
  5537. return {
  5538. name: "ECDSA",
  5539. hash: {
  5540. name: "SHA-1"
  5541. }
  5542. };
  5543. case "1.2.840.10045.4.3.2":
  5544. return {
  5545. name: "ECDSA",
  5546. hash: {
  5547. name: "SHA-256"
  5548. }
  5549. };
  5550. case "1.2.840.10045.4.3.3":
  5551. return {
  5552. name: "ECDSA",
  5553. hash: {
  5554. name: "SHA-384"
  5555. }
  5556. };
  5557. case "1.2.840.10045.4.3.4":
  5558. return {
  5559. name: "ECDSA",
  5560. hash: {
  5561. name: "SHA-512"
  5562. }
  5563. };
  5564. case "1.3.133.16.840.63.0.2":
  5565. return {
  5566. name: "ECDH",
  5567. kdf: "SHA-1"
  5568. };
  5569. case "1.3.132.1.11.1":
  5570. return {
  5571. name: "ECDH",
  5572. kdf: "SHA-256"
  5573. };
  5574. case "1.3.132.1.11.2":
  5575. return {
  5576. name: "ECDH",
  5577. kdf: "SHA-384"
  5578. };
  5579. case "1.3.132.1.11.3":
  5580. return {
  5581. name: "ECDH",
  5582. kdf: "SHA-512"
  5583. };
  5584. case "2.16.840.1.101.3.4.1.2":
  5585. return {
  5586. name: "AES-CBC",
  5587. length: 128
  5588. };
  5589. case "2.16.840.1.101.3.4.1.22":
  5590. return {
  5591. name: "AES-CBC",
  5592. length: 192
  5593. };
  5594. case "2.16.840.1.101.3.4.1.42":
  5595. return {
  5596. name: "AES-CBC",
  5597. length: 256
  5598. };
  5599. case "2.16.840.1.101.3.4.1.6":
  5600. return {
  5601. name: "AES-GCM",
  5602. length: 128
  5603. };
  5604. case "2.16.840.1.101.3.4.1.26":
  5605. return {
  5606. name: "AES-GCM",
  5607. length: 192
  5608. };
  5609. case "2.16.840.1.101.3.4.1.46":
  5610. return {
  5611. name: "AES-GCM",
  5612. length: 256
  5613. };
  5614. case "2.16.840.1.101.3.4.1.4":
  5615. return {
  5616. name: "AES-CFB",
  5617. length: 128
  5618. };
  5619. case "2.16.840.1.101.3.4.1.24":
  5620. return {
  5621. name: "AES-CFB",
  5622. length: 192
  5623. };
  5624. case "2.16.840.1.101.3.4.1.44":
  5625. return {
  5626. name: "AES-CFB",
  5627. length: 256
  5628. };
  5629. case "2.16.840.1.101.3.4.1.5":
  5630. return {
  5631. name: "AES-KW",
  5632. length: 128
  5633. };
  5634. case "2.16.840.1.101.3.4.1.25":
  5635. return {
  5636. name: "AES-KW",
  5637. length: 192
  5638. };
  5639. case "2.16.840.1.101.3.4.1.45":
  5640. return {
  5641. name: "AES-KW",
  5642. length: 256
  5643. };
  5644. case "1.2.840.113549.2.7":
  5645. return {
  5646. name: "HMAC",
  5647. hash: {
  5648. name: "SHA-1"
  5649. }
  5650. };
  5651. case "1.2.840.113549.2.9":
  5652. return {
  5653. name: "HMAC",
  5654. hash: {
  5655. name: "SHA-256"
  5656. }
  5657. };
  5658. case "1.2.840.113549.2.10":
  5659. return {
  5660. name: "HMAC",
  5661. hash: {
  5662. name: "SHA-384"
  5663. }
  5664. };
  5665. case "1.2.840.113549.2.11":
  5666. return {
  5667. name: "HMAC",
  5668. hash: {
  5669. name: "SHA-512"
  5670. }
  5671. };
  5672. case "1.2.840.113549.1.9.16.3.5":
  5673. return {
  5674. name: "DH"
  5675. };
  5676. case "1.3.14.3.2.26":
  5677. return {
  5678. name: "SHA-1"
  5679. };
  5680. case "2.16.840.1.101.3.4.2.1":
  5681. return {
  5682. name: "SHA-256"
  5683. };
  5684. case "2.16.840.1.101.3.4.2.2":
  5685. return {
  5686. name: "SHA-384"
  5687. };
  5688. case "2.16.840.1.101.3.4.2.3":
  5689. return {
  5690. name: "SHA-512"
  5691. };
  5692. case "1.2.840.113549.1.5.12":
  5693. return {
  5694. name: "PBKDF2"
  5695. };
  5696. case "1.2.840.10045.3.1.7":
  5697. return {
  5698. name: "P-256"
  5699. };
  5700. case "1.3.132.0.34":
  5701. return {
  5702. name: "P-384"
  5703. };
  5704. case "1.3.132.0.35":
  5705. return {
  5706. name: "P-521"
  5707. };
  5708. }
  5709. if (safety) {
  5710. throw new Error(`Unsupported algorithm identifier ${target ? `for ${target} ` : EMPTY_STRING}: ${oid}`);
  5711. }
  5712. return {};
  5713. }
  5714. getOIDByAlgorithm(algorithm, safety = false, target) {
  5715. let result = EMPTY_STRING;
  5716. switch (algorithm.name.toUpperCase()) {
  5717. case "RSAES-PKCS1-V1_5":
  5718. result = "1.2.840.113549.1.1.1";
  5719. break;
  5720. case "RSASSA-PKCS1-V1_5":
  5721. switch (algorithm.hash.name.toUpperCase()) {
  5722. case "SHA-1":
  5723. result = "1.2.840.113549.1.1.5";
  5724. break;
  5725. case "SHA-256":
  5726. result = "1.2.840.113549.1.1.11";
  5727. break;
  5728. case "SHA-384":
  5729. result = "1.2.840.113549.1.1.12";
  5730. break;
  5731. case "SHA-512":
  5732. result = "1.2.840.113549.1.1.13";
  5733. break;
  5734. }
  5735. break;
  5736. case "RSA-PSS":
  5737. result = "1.2.840.113549.1.1.10";
  5738. break;
  5739. case "RSA-OAEP":
  5740. result = "1.2.840.113549.1.1.7";
  5741. break;
  5742. case "ECDSA":
  5743. switch (algorithm.hash.name.toUpperCase()) {
  5744. case "SHA-1":
  5745. result = "1.2.840.10045.4.1";
  5746. break;
  5747. case "SHA-256":
  5748. result = "1.2.840.10045.4.3.2";
  5749. break;
  5750. case "SHA-384":
  5751. result = "1.2.840.10045.4.3.3";
  5752. break;
  5753. case "SHA-512":
  5754. result = "1.2.840.10045.4.3.4";
  5755. break;
  5756. }
  5757. break;
  5758. case "ECDH":
  5759. switch (algorithm.kdf.toUpperCase()) {
  5760. case "SHA-1":
  5761. result = "1.3.133.16.840.63.0.2";
  5762. break;
  5763. case "SHA-256":
  5764. result = "1.3.132.1.11.1";
  5765. break;
  5766. case "SHA-384":
  5767. result = "1.3.132.1.11.2";
  5768. break;
  5769. case "SHA-512":
  5770. result = "1.3.132.1.11.3";
  5771. break;
  5772. }
  5773. break;
  5774. case "AES-CTR":
  5775. break;
  5776. case "AES-CBC":
  5777. switch (algorithm.length) {
  5778. case 128:
  5779. result = "2.16.840.1.101.3.4.1.2";
  5780. break;
  5781. case 192:
  5782. result = "2.16.840.1.101.3.4.1.22";
  5783. break;
  5784. case 256:
  5785. result = "2.16.840.1.101.3.4.1.42";
  5786. break;
  5787. }
  5788. break;
  5789. case "AES-CMAC":
  5790. break;
  5791. case "AES-GCM":
  5792. switch (algorithm.length) {
  5793. case 128:
  5794. result = "2.16.840.1.101.3.4.1.6";
  5795. break;
  5796. case 192:
  5797. result = "2.16.840.1.101.3.4.1.26";
  5798. break;
  5799. case 256:
  5800. result = "2.16.840.1.101.3.4.1.46";
  5801. break;
  5802. }
  5803. break;
  5804. case "AES-CFB":
  5805. switch (algorithm.length) {
  5806. case 128:
  5807. result = "2.16.840.1.101.3.4.1.4";
  5808. break;
  5809. case 192:
  5810. result = "2.16.840.1.101.3.4.1.24";
  5811. break;
  5812. case 256:
  5813. result = "2.16.840.1.101.3.4.1.44";
  5814. break;
  5815. }
  5816. break;
  5817. case "AES-KW":
  5818. switch (algorithm.length) {
  5819. case 128:
  5820. result = "2.16.840.1.101.3.4.1.5";
  5821. break;
  5822. case 192:
  5823. result = "2.16.840.1.101.3.4.1.25";
  5824. break;
  5825. case 256:
  5826. result = "2.16.840.1.101.3.4.1.45";
  5827. break;
  5828. }
  5829. break;
  5830. case "HMAC":
  5831. switch (algorithm.hash.name.toUpperCase()) {
  5832. case "SHA-1":
  5833. result = "1.2.840.113549.2.7";
  5834. break;
  5835. case "SHA-256":
  5836. result = "1.2.840.113549.2.9";
  5837. break;
  5838. case "SHA-384":
  5839. result = "1.2.840.113549.2.10";
  5840. break;
  5841. case "SHA-512":
  5842. result = "1.2.840.113549.2.11";
  5843. break;
  5844. }
  5845. break;
  5846. case "DH":
  5847. result = "1.2.840.113549.1.9.16.3.5";
  5848. break;
  5849. case "SHA-1":
  5850. result = "1.3.14.3.2.26";
  5851. break;
  5852. case "SHA-256":
  5853. result = "2.16.840.1.101.3.4.2.1";
  5854. break;
  5855. case "SHA-384":
  5856. result = "2.16.840.1.101.3.4.2.2";
  5857. break;
  5858. case "SHA-512":
  5859. result = "2.16.840.1.101.3.4.2.3";
  5860. break;
  5861. case "CONCAT":
  5862. break;
  5863. case "HKDF":
  5864. break;
  5865. case "PBKDF2":
  5866. result = "1.2.840.113549.1.5.12";
  5867. break;
  5868. case "P-256":
  5869. result = "1.2.840.10045.3.1.7";
  5870. break;
  5871. case "P-384":
  5872. result = "1.3.132.0.34";
  5873. break;
  5874. case "P-521":
  5875. result = "1.3.132.0.35";
  5876. break;
  5877. }
  5878. if (!result && safety) {
  5879. throw new Error(`Unsupported algorithm ${target ? `for ${target} ` : EMPTY_STRING}: ${algorithm.name}`);
  5880. }
  5881. return result;
  5882. }
  5883. getAlgorithmParameters(algorithmName, operation) {
  5884. let result = {
  5885. algorithm: {},
  5886. usages: []
  5887. };
  5888. switch (algorithmName.toUpperCase()) {
  5889. case "RSAES-PKCS1-V1_5":
  5890. case "RSASSA-PKCS1-V1_5":
  5891. switch (operation.toLowerCase()) {
  5892. case "generatekey":
  5893. result = {
  5894. algorithm: {
  5895. name: "RSASSA-PKCS1-v1_5",
  5896. modulusLength: 2048,
  5897. publicExponent: new Uint8Array([0x01, 0x00, 0x01]),
  5898. hash: {
  5899. name: "SHA-256"
  5900. }
  5901. },
  5902. usages: ["sign", "verify"]
  5903. };
  5904. break;
  5905. case "verify":
  5906. case "sign":
  5907. case "importkey":
  5908. result = {
  5909. algorithm: {
  5910. name: "RSASSA-PKCS1-v1_5",
  5911. hash: {
  5912. name: "SHA-256"
  5913. }
  5914. },
  5915. usages: ["verify"]
  5916. };
  5917. break;
  5918. case "exportkey":
  5919. default:
  5920. return {
  5921. algorithm: {
  5922. name: "RSASSA-PKCS1-v1_5"
  5923. },
  5924. usages: []
  5925. };
  5926. }
  5927. break;
  5928. case "RSA-PSS":
  5929. switch (operation.toLowerCase()) {
  5930. case "sign":
  5931. case "verify":
  5932. result = {
  5933. algorithm: {
  5934. name: "RSA-PSS",
  5935. hash: {
  5936. name: "SHA-1"
  5937. },
  5938. saltLength: 20
  5939. },
  5940. usages: ["sign", "verify"]
  5941. };
  5942. break;
  5943. case "generatekey":
  5944. result = {
  5945. algorithm: {
  5946. name: "RSA-PSS",
  5947. modulusLength: 2048,
  5948. publicExponent: new Uint8Array([0x01, 0x00, 0x01]),
  5949. hash: {
  5950. name: "SHA-1"
  5951. }
  5952. },
  5953. usages: ["sign", "verify"]
  5954. };
  5955. break;
  5956. case "importkey":
  5957. result = {
  5958. algorithm: {
  5959. name: "RSA-PSS",
  5960. hash: {
  5961. name: "SHA-1"
  5962. }
  5963. },
  5964. usages: ["verify"]
  5965. };
  5966. break;
  5967. case "exportkey":
  5968. default:
  5969. return {
  5970. algorithm: {
  5971. name: "RSA-PSS"
  5972. },
  5973. usages: []
  5974. };
  5975. }
  5976. break;
  5977. case "RSA-OAEP":
  5978. switch (operation.toLowerCase()) {
  5979. case "encrypt":
  5980. case "decrypt":
  5981. result = {
  5982. algorithm: {
  5983. name: "RSA-OAEP"
  5984. },
  5985. usages: ["encrypt", "decrypt"]
  5986. };
  5987. break;
  5988. case "generatekey":
  5989. result = {
  5990. algorithm: {
  5991. name: "RSA-OAEP",
  5992. modulusLength: 2048,
  5993. publicExponent: new Uint8Array([0x01, 0x00, 0x01]),
  5994. hash: {
  5995. name: "SHA-256"
  5996. }
  5997. },
  5998. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  5999. };
  6000. break;
  6001. case "importkey":
  6002. result = {
  6003. algorithm: {
  6004. name: "RSA-OAEP",
  6005. hash: {
  6006. name: "SHA-256"
  6007. }
  6008. },
  6009. usages: ["encrypt"]
  6010. };
  6011. break;
  6012. case "exportkey":
  6013. default:
  6014. return {
  6015. algorithm: {
  6016. name: "RSA-OAEP"
  6017. },
  6018. usages: []
  6019. };
  6020. }
  6021. break;
  6022. case "ECDSA":
  6023. switch (operation.toLowerCase()) {
  6024. case "generatekey":
  6025. result = {
  6026. algorithm: {
  6027. name: "ECDSA",
  6028. namedCurve: "P-256"
  6029. },
  6030. usages: ["sign", "verify"]
  6031. };
  6032. break;
  6033. case "importkey":
  6034. result = {
  6035. algorithm: {
  6036. name: "ECDSA",
  6037. namedCurve: "P-256"
  6038. },
  6039. usages: ["verify"]
  6040. };
  6041. break;
  6042. case "verify":
  6043. case "sign":
  6044. result = {
  6045. algorithm: {
  6046. name: "ECDSA",
  6047. hash: {
  6048. name: "SHA-256"
  6049. }
  6050. },
  6051. usages: ["sign"]
  6052. };
  6053. break;
  6054. default:
  6055. return {
  6056. algorithm: {
  6057. name: "ECDSA"
  6058. },
  6059. usages: []
  6060. };
  6061. }
  6062. break;
  6063. case "ECDH":
  6064. switch (operation.toLowerCase()) {
  6065. case "exportkey":
  6066. case "importkey":
  6067. case "generatekey":
  6068. result = {
  6069. algorithm: {
  6070. name: "ECDH",
  6071. namedCurve: "P-256"
  6072. },
  6073. usages: ["deriveKey", "deriveBits"]
  6074. };
  6075. break;
  6076. case "derivekey":
  6077. case "derivebits":
  6078. result = {
  6079. algorithm: {
  6080. name: "ECDH",
  6081. namedCurve: "P-256",
  6082. public: []
  6083. },
  6084. usages: ["encrypt", "decrypt"]
  6085. };
  6086. break;
  6087. default:
  6088. return {
  6089. algorithm: {
  6090. name: "ECDH"
  6091. },
  6092. usages: []
  6093. };
  6094. }
  6095. break;
  6096. case "AES-CTR":
  6097. switch (operation.toLowerCase()) {
  6098. case "importkey":
  6099. case "exportkey":
  6100. case "generatekey":
  6101. result = {
  6102. algorithm: {
  6103. name: "AES-CTR",
  6104. length: 256
  6105. },
  6106. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6107. };
  6108. break;
  6109. case "decrypt":
  6110. case "encrypt":
  6111. result = {
  6112. algorithm: {
  6113. name: "AES-CTR",
  6114. counter: new Uint8Array(16),
  6115. length: 10
  6116. },
  6117. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6118. };
  6119. break;
  6120. default:
  6121. return {
  6122. algorithm: {
  6123. name: "AES-CTR"
  6124. },
  6125. usages: []
  6126. };
  6127. }
  6128. break;
  6129. case "AES-CBC":
  6130. switch (operation.toLowerCase()) {
  6131. case "importkey":
  6132. case "exportkey":
  6133. case "generatekey":
  6134. result = {
  6135. algorithm: {
  6136. name: "AES-CBC",
  6137. length: 256
  6138. },
  6139. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6140. };
  6141. break;
  6142. case "decrypt":
  6143. case "encrypt":
  6144. result = {
  6145. algorithm: {
  6146. name: "AES-CBC",
  6147. iv: this.getRandomValues(new Uint8Array(16))
  6148. },
  6149. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6150. };
  6151. break;
  6152. default:
  6153. return {
  6154. algorithm: {
  6155. name: "AES-CBC"
  6156. },
  6157. usages: []
  6158. };
  6159. }
  6160. break;
  6161. case "AES-GCM":
  6162. switch (operation.toLowerCase()) {
  6163. case "importkey":
  6164. case "exportkey":
  6165. case "generatekey":
  6166. result = {
  6167. algorithm: {
  6168. name: "AES-GCM",
  6169. length: 256
  6170. },
  6171. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6172. };
  6173. break;
  6174. case "decrypt":
  6175. case "encrypt":
  6176. result = {
  6177. algorithm: {
  6178. name: "AES-GCM",
  6179. iv: this.getRandomValues(new Uint8Array(16))
  6180. },
  6181. usages: ["encrypt", "decrypt", "wrapKey", "unwrapKey"]
  6182. };
  6183. break;
  6184. default:
  6185. return {
  6186. algorithm: {
  6187. name: "AES-GCM"
  6188. },
  6189. usages: []
  6190. };
  6191. }
  6192. break;
  6193. case "AES-KW":
  6194. switch (operation.toLowerCase()) {
  6195. case "importkey":
  6196. case "exportkey":
  6197. case "generatekey":
  6198. case "wrapkey":
  6199. case "unwrapkey":
  6200. result = {
  6201. algorithm: {
  6202. name: "AES-KW",
  6203. length: 256
  6204. },
  6205. usages: ["wrapKey", "unwrapKey"]
  6206. };
  6207. break;
  6208. default:
  6209. return {
  6210. algorithm: {
  6211. name: "AES-KW"
  6212. },
  6213. usages: []
  6214. };
  6215. }
  6216. break;
  6217. case "HMAC":
  6218. switch (operation.toLowerCase()) {
  6219. case "sign":
  6220. case "verify":
  6221. result = {
  6222. algorithm: {
  6223. name: "HMAC"
  6224. },
  6225. usages: ["sign", "verify"]
  6226. };
  6227. break;
  6228. case "importkey":
  6229. case "exportkey":
  6230. case "generatekey":
  6231. result = {
  6232. algorithm: {
  6233. name: "HMAC",
  6234. length: 32,
  6235. hash: {
  6236. name: "SHA-256"
  6237. }
  6238. },
  6239. usages: ["sign", "verify"]
  6240. };
  6241. break;
  6242. default:
  6243. return {
  6244. algorithm: {
  6245. name: "HMAC"
  6246. },
  6247. usages: []
  6248. };
  6249. }
  6250. break;
  6251. case "HKDF":
  6252. switch (operation.toLowerCase()) {
  6253. case "derivekey":
  6254. result = {
  6255. algorithm: {
  6256. name: "HKDF",
  6257. hash: "SHA-256",
  6258. salt: new Uint8Array([]),
  6259. info: new Uint8Array([])
  6260. },
  6261. usages: ["encrypt", "decrypt"]
  6262. };
  6263. break;
  6264. default:
  6265. return {
  6266. algorithm: {
  6267. name: "HKDF"
  6268. },
  6269. usages: []
  6270. };
  6271. }
  6272. break;
  6273. case "PBKDF2":
  6274. switch (operation.toLowerCase()) {
  6275. case "derivekey":
  6276. result = {
  6277. algorithm: {
  6278. name: "PBKDF2",
  6279. hash: { name: "SHA-256" },
  6280. salt: new Uint8Array([]),
  6281. iterations: 10000
  6282. },
  6283. usages: ["encrypt", "decrypt"]
  6284. };
  6285. break;
  6286. default:
  6287. return {
  6288. algorithm: {
  6289. name: "PBKDF2"
  6290. },
  6291. usages: []
  6292. };
  6293. }
  6294. break;
  6295. }
  6296. return result;
  6297. }
  6298. getHashAlgorithm(signatureAlgorithm) {
  6299. let result = EMPTY_STRING;
  6300. switch (signatureAlgorithm.algorithmId) {
  6301. case "1.2.840.10045.4.1":
  6302. case "1.2.840.113549.1.1.5":
  6303. result = "SHA-1";
  6304. break;
  6305. case "1.2.840.10045.4.3.2":
  6306. case "1.2.840.113549.1.1.11":
  6307. result = "SHA-256";
  6308. break;
  6309. case "1.2.840.10045.4.3.3":
  6310. case "1.2.840.113549.1.1.12":
  6311. result = "SHA-384";
  6312. break;
  6313. case "1.2.840.10045.4.3.4":
  6314. case "1.2.840.113549.1.1.13":
  6315. result = "SHA-512";
  6316. break;
  6317. case "1.2.840.113549.1.1.10":
  6318. {
  6319. try {
  6320. const params = new RSASSAPSSParams({ schema: signatureAlgorithm.algorithmParams });
  6321. if (params.hashAlgorithm) {
  6322. const algorithm = this.getAlgorithmByOID(params.hashAlgorithm.algorithmId);
  6323. if ("name" in algorithm) {
  6324. result = algorithm.name;
  6325. }
  6326. else {
  6327. return EMPTY_STRING;
  6328. }
  6329. }
  6330. else
  6331. result = "SHA-1";
  6332. }
  6333. catch {
  6334. }
  6335. }
  6336. break;
  6337. }
  6338. return result;
  6339. }
  6340. async encryptEncryptedContentInfo(parameters) {
  6341. ParameterError.assert(parameters, "password", "contentEncryptionAlgorithm", "hmacHashAlgorithm", "iterationCount", "contentToEncrypt", "contentToEncrypt", "contentType");
  6342. const contentEncryptionOID = this.getOIDByAlgorithm(parameters.contentEncryptionAlgorithm, true, "contentEncryptionAlgorithm");
  6343. const pbkdf2OID = this.getOIDByAlgorithm({
  6344. name: "PBKDF2"
  6345. }, true, "PBKDF2");
  6346. const hmacOID = this.getOIDByAlgorithm({
  6347. name: "HMAC",
  6348. hash: {
  6349. name: parameters.hmacHashAlgorithm
  6350. }
  6351. }, true, "hmacHashAlgorithm");
  6352. const ivBuffer = new ArrayBuffer(16);
  6353. const ivView = new Uint8Array(ivBuffer);
  6354. this.getRandomValues(ivView);
  6355. const saltBuffer = new ArrayBuffer(64);
  6356. const saltView = new Uint8Array(saltBuffer);
  6357. this.getRandomValues(saltView);
  6358. const contentView = new Uint8Array(parameters.contentToEncrypt);
  6359. const pbkdf2Params = new PBKDF2Params({
  6360. salt: new asn1js.OctetString({ valueHex: saltBuffer }),
  6361. iterationCount: parameters.iterationCount,
  6362. prf: new AlgorithmIdentifier({
  6363. algorithmId: hmacOID,
  6364. algorithmParams: new asn1js.Null()
  6365. })
  6366. });
  6367. const passwordView = new Uint8Array(parameters.password);
  6368. const pbkdfKey = await this.importKey("raw", passwordView, "PBKDF2", false, ["deriveKey"]);
  6369. const derivedKey = await this.deriveKey({
  6370. name: "PBKDF2",
  6371. hash: {
  6372. name: parameters.hmacHashAlgorithm
  6373. },
  6374. salt: saltView,
  6375. iterations: parameters.iterationCount
  6376. }, pbkdfKey, parameters.contentEncryptionAlgorithm, false, ["encrypt"]);
  6377. const encryptedData = await this.encrypt({
  6378. name: parameters.contentEncryptionAlgorithm.name,
  6379. iv: ivView
  6380. }, derivedKey, contentView);
  6381. const pbes2Parameters = new PBES2Params({
  6382. keyDerivationFunc: new AlgorithmIdentifier({
  6383. algorithmId: pbkdf2OID,
  6384. algorithmParams: pbkdf2Params.toSchema()
  6385. }),
  6386. encryptionScheme: new AlgorithmIdentifier({
  6387. algorithmId: contentEncryptionOID,
  6388. algorithmParams: new asn1js.OctetString({ valueHex: ivBuffer })
  6389. })
  6390. });
  6391. return new EncryptedContentInfo({
  6392. contentType: parameters.contentType,
  6393. contentEncryptionAlgorithm: new AlgorithmIdentifier({
  6394. algorithmId: "1.2.840.113549.1.5.13",
  6395. algorithmParams: pbes2Parameters.toSchema()
  6396. }),
  6397. encryptedContent: new asn1js.OctetString({ valueHex: encryptedData })
  6398. });
  6399. }
  6400. async decryptEncryptedContentInfo(parameters) {
  6401. ParameterError.assert(parameters, "password", "encryptedContentInfo");
  6402. if (parameters.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId !== "1.2.840.113549.1.5.13")
  6403. throw new Error(`Unknown "contentEncryptionAlgorithm": ${parameters.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId}`);
  6404. let pbes2Parameters;
  6405. try {
  6406. pbes2Parameters = new PBES2Params({ schema: parameters.encryptedContentInfo.contentEncryptionAlgorithm.algorithmParams });
  6407. }
  6408. catch {
  6409. throw new Error("Incorrectly encoded \"pbes2Parameters\"");
  6410. }
  6411. let pbkdf2Params;
  6412. try {
  6413. pbkdf2Params = new PBKDF2Params({ schema: pbes2Parameters.keyDerivationFunc.algorithmParams });
  6414. }
  6415. catch {
  6416. throw new Error("Incorrectly encoded \"pbkdf2Params\"");
  6417. }
  6418. const contentEncryptionAlgorithm = this.getAlgorithmByOID(pbes2Parameters.encryptionScheme.algorithmId, true);
  6419. const ivBuffer = pbes2Parameters.encryptionScheme.algorithmParams.valueBlock.valueHex;
  6420. const ivView = new Uint8Array(ivBuffer);
  6421. const saltBuffer = pbkdf2Params.salt.valueBlock.valueHex;
  6422. const saltView = new Uint8Array(saltBuffer);
  6423. const iterationCount = pbkdf2Params.iterationCount;
  6424. let hmacHashAlgorithm = "SHA-1";
  6425. if (pbkdf2Params.prf) {
  6426. const algorithm = this.getAlgorithmByOID(pbkdf2Params.prf.algorithmId, true);
  6427. hmacHashAlgorithm = algorithm.hash.name;
  6428. }
  6429. const pbkdfKey = await this.importKey("raw", parameters.password, "PBKDF2", false, ["deriveKey"]);
  6430. const result = await this.deriveKey({
  6431. name: "PBKDF2",
  6432. hash: {
  6433. name: hmacHashAlgorithm
  6434. },
  6435. salt: saltView,
  6436. iterations: iterationCount
  6437. }, pbkdfKey, contentEncryptionAlgorithm, false, ["decrypt"]);
  6438. const dataBuffer = parameters.encryptedContentInfo.getEncryptedContent();
  6439. return this.decrypt({
  6440. name: contentEncryptionAlgorithm.name,
  6441. iv: ivView
  6442. }, result, dataBuffer);
  6443. }
  6444. async stampDataWithPassword(parameters) {
  6445. if ((parameters instanceof Object) === false)
  6446. throw new Error("Parameters must have type \"Object\"");
  6447. ParameterError.assert(parameters, "password", "hashAlgorithm", "iterationCount", "salt", "contentToStamp");
  6448. let length;
  6449. switch (parameters.hashAlgorithm.toLowerCase()) {
  6450. case "sha-1":
  6451. length = 160;
  6452. break;
  6453. case "sha-256":
  6454. length = 256;
  6455. break;
  6456. case "sha-384":
  6457. length = 384;
  6458. break;
  6459. case "sha-512":
  6460. length = 512;
  6461. break;
  6462. default:
  6463. throw new Error(`Incorrect "parameters.hashAlgorithm" parameter: ${parameters.hashAlgorithm}`);
  6464. }
  6465. const hmacAlgorithm = {
  6466. name: "HMAC",
  6467. length,
  6468. hash: {
  6469. name: parameters.hashAlgorithm
  6470. }
  6471. };
  6472. const pkcsKey = await makePKCS12B2Key(parameters.hashAlgorithm, length, parameters.password, parameters.salt, parameters.iterationCount);
  6473. const hmacKey = await this.importKey("raw", new Uint8Array(pkcsKey), hmacAlgorithm, false, ["sign"]);
  6474. return this.sign(hmacAlgorithm, hmacKey, new Uint8Array(parameters.contentToStamp));
  6475. }
  6476. async verifyDataStampedWithPassword(parameters) {
  6477. ParameterError.assert(parameters, "password", "hashAlgorithm", "salt", "iterationCount", "contentToVerify", "signatureToVerify");
  6478. let length = 0;
  6479. switch (parameters.hashAlgorithm.toLowerCase()) {
  6480. case "sha-1":
  6481. length = 160;
  6482. break;
  6483. case "sha-256":
  6484. length = 256;
  6485. break;
  6486. case "sha-384":
  6487. length = 384;
  6488. break;
  6489. case "sha-512":
  6490. length = 512;
  6491. break;
  6492. default:
  6493. throw new Error(`Incorrect "parameters.hashAlgorithm" parameter: ${parameters.hashAlgorithm}`);
  6494. }
  6495. const hmacAlgorithm = {
  6496. name: "HMAC",
  6497. length,
  6498. hash: {
  6499. name: parameters.hashAlgorithm
  6500. }
  6501. };
  6502. const pkcsKey = await makePKCS12B2Key(parameters.hashAlgorithm, length, parameters.password, parameters.salt, parameters.iterationCount);
  6503. const hmacKey = await this.importKey("raw", new Uint8Array(pkcsKey), hmacAlgorithm, false, ["verify"]);
  6504. return this.verify(hmacAlgorithm, hmacKey, new Uint8Array(parameters.signatureToVerify), new Uint8Array(parameters.contentToVerify));
  6505. }
  6506. async getSignatureParameters(privateKey, hashAlgorithm = "SHA-1") {
  6507. this.getOIDByAlgorithm({ name: hashAlgorithm }, true, "hashAlgorithm");
  6508. const signatureAlgorithm = new AlgorithmIdentifier();
  6509. const parameters = this.getAlgorithmParameters(privateKey.algorithm.name, "sign");
  6510. if (!Object.keys(parameters.algorithm).length) {
  6511. throw new Error("Parameter 'algorithm' is empty");
  6512. }
  6513. const algorithm = parameters.algorithm;
  6514. if ("hash" in privateKey.algorithm && privateKey.algorithm.hash && privateKey.algorithm.hash.name) {
  6515. algorithm.hash.name = privateKey.algorithm.hash.name;
  6516. }
  6517. else {
  6518. algorithm.hash.name = hashAlgorithm;
  6519. }
  6520. switch (privateKey.algorithm.name.toUpperCase()) {
  6521. case "RSASSA-PKCS1-V1_5":
  6522. case "ECDSA":
  6523. signatureAlgorithm.algorithmId = this.getOIDByAlgorithm(algorithm, true);
  6524. break;
  6525. case "RSA-PSS":
  6526. {
  6527. switch (algorithm.hash.name.toUpperCase()) {
  6528. case "SHA-256":
  6529. algorithm.saltLength = 32;
  6530. break;
  6531. case "SHA-384":
  6532. algorithm.saltLength = 48;
  6533. break;
  6534. case "SHA-512":
  6535. algorithm.saltLength = 64;
  6536. break;
  6537. }
  6538. const paramsObject = {};
  6539. if (algorithm.hash.name.toUpperCase() !== "SHA-1") {
  6540. const hashAlgorithmOID = this.getOIDByAlgorithm({ name: algorithm.hash.name }, true, "hashAlgorithm");
  6541. paramsObject.hashAlgorithm = new AlgorithmIdentifier({
  6542. algorithmId: hashAlgorithmOID,
  6543. algorithmParams: new asn1js.Null()
  6544. });
  6545. paramsObject.maskGenAlgorithm = new AlgorithmIdentifier({
  6546. algorithmId: "1.2.840.113549.1.1.8",
  6547. algorithmParams: paramsObject.hashAlgorithm.toSchema()
  6548. });
  6549. }
  6550. if (algorithm.saltLength !== 20)
  6551. paramsObject.saltLength = algorithm.saltLength;
  6552. const pssParameters = new RSASSAPSSParams(paramsObject);
  6553. signatureAlgorithm.algorithmId = "1.2.840.113549.1.1.10";
  6554. signatureAlgorithm.algorithmParams = pssParameters.toSchema();
  6555. }
  6556. break;
  6557. default:
  6558. throw new Error(`Unsupported signature algorithm: ${privateKey.algorithm.name}`);
  6559. }
  6560. return {
  6561. signatureAlgorithm,
  6562. parameters
  6563. };
  6564. }
  6565. async signWithPrivateKey(data, privateKey, parameters) {
  6566. const signature = await this.sign(parameters.algorithm, privateKey, data);
  6567. if (parameters.algorithm.name === "ECDSA") {
  6568. return createCMSECDSASignature(signature);
  6569. }
  6570. return signature;
  6571. }
  6572. fillPublicKeyParameters(publicKeyInfo, signatureAlgorithm) {
  6573. const parameters = {};
  6574. const shaAlgorithm = this.getHashAlgorithm(signatureAlgorithm);
  6575. if (shaAlgorithm === EMPTY_STRING)
  6576. throw new Error(`Unsupported signature algorithm: ${signatureAlgorithm.algorithmId}`);
  6577. let algorithmId;
  6578. if (signatureAlgorithm.algorithmId === "1.2.840.113549.1.1.10")
  6579. algorithmId = signatureAlgorithm.algorithmId;
  6580. else
  6581. algorithmId = publicKeyInfo.algorithm.algorithmId;
  6582. const algorithmObject = this.getAlgorithmByOID(algorithmId, true);
  6583. parameters.algorithm = this.getAlgorithmParameters(algorithmObject.name, "importKey");
  6584. if ("hash" in parameters.algorithm.algorithm)
  6585. parameters.algorithm.algorithm.hash.name = shaAlgorithm;
  6586. if (algorithmObject.name === "ECDSA") {
  6587. const publicKeyAlgorithm = publicKeyInfo.algorithm;
  6588. if (!publicKeyAlgorithm.algorithmParams) {
  6589. throw new Error("Algorithm parameters for ECDSA public key are missed");
  6590. }
  6591. const publicKeyAlgorithmParams = publicKeyAlgorithm.algorithmParams;
  6592. if ("idBlock" in publicKeyAlgorithm.algorithmParams) {
  6593. if (!((publicKeyAlgorithmParams.idBlock.tagClass === 1) && (publicKeyAlgorithmParams.idBlock.tagNumber === 6))) {
  6594. throw new Error("Incorrect type for ECDSA public key parameters");
  6595. }
  6596. }
  6597. const curveObject = this.getAlgorithmByOID(publicKeyAlgorithmParams.valueBlock.toString(), true);
  6598. parameters.algorithm.algorithm.namedCurve = curveObject.name;
  6599. }
  6600. return parameters;
  6601. }
  6602. async getPublicKey(publicKeyInfo, signatureAlgorithm, parameters) {
  6603. if (!parameters) {
  6604. parameters = this.fillPublicKeyParameters(publicKeyInfo, signatureAlgorithm);
  6605. }
  6606. const publicKeyInfoBuffer = publicKeyInfo.toSchema().toBER(false);
  6607. return this.importKey("spki", publicKeyInfoBuffer, parameters.algorithm.algorithm, true, parameters.algorithm.usages);
  6608. }
  6609. async verifyWithPublicKey(data, signature, publicKeyInfo, signatureAlgorithm, shaAlgorithm) {
  6610. let publicKey;
  6611. if (!shaAlgorithm) {
  6612. shaAlgorithm = this.getHashAlgorithm(signatureAlgorithm);
  6613. if (!shaAlgorithm)
  6614. throw new Error(`Unsupported signature algorithm: ${signatureAlgorithm.algorithmId}`);
  6615. publicKey = await this.getPublicKey(publicKeyInfo, signatureAlgorithm);
  6616. }
  6617. else {
  6618. const parameters = {};
  6619. let algorithmId;
  6620. if (signatureAlgorithm.algorithmId === "1.2.840.113549.1.1.10")
  6621. algorithmId = signatureAlgorithm.algorithmId;
  6622. else
  6623. algorithmId = publicKeyInfo.algorithm.algorithmId;
  6624. const algorithmObject = this.getAlgorithmByOID(algorithmId, true);
  6625. parameters.algorithm = this.getAlgorithmParameters(algorithmObject.name, "importKey");
  6626. if ("hash" in parameters.algorithm.algorithm)
  6627. parameters.algorithm.algorithm.hash.name = shaAlgorithm;
  6628. if (algorithmObject.name === "ECDSA") {
  6629. let algorithmParamsChecked = false;
  6630. if (("algorithmParams" in publicKeyInfo.algorithm) === true) {
  6631. if ("idBlock" in publicKeyInfo.algorithm.algorithmParams) {
  6632. if ((publicKeyInfo.algorithm.algorithmParams.idBlock.tagClass === 1) && (publicKeyInfo.algorithm.algorithmParams.idBlock.tagNumber === 6))
  6633. algorithmParamsChecked = true;
  6634. }
  6635. }
  6636. if (algorithmParamsChecked === false) {
  6637. throw new Error("Incorrect type for ECDSA public key parameters");
  6638. }
  6639. const curveObject = this.getAlgorithmByOID(publicKeyInfo.algorithm.algorithmParams.valueBlock.toString(), true);
  6640. parameters.algorithm.algorithm.namedCurve = curveObject.name;
  6641. }
  6642. publicKey = await this.getPublicKey(publicKeyInfo, null, parameters);
  6643. }
  6644. const algorithm = this.getAlgorithmParameters(publicKey.algorithm.name, "verify");
  6645. if ("hash" in algorithm.algorithm)
  6646. algorithm.algorithm.hash.name = shaAlgorithm;
  6647. let signatureValue = signature.valueBlock.valueHexView;
  6648. if (publicKey.algorithm.name === "ECDSA") {
  6649. const namedCurve = ECNamedCurves.find(publicKey.algorithm.namedCurve);
  6650. if (!namedCurve) {
  6651. throw new Error("Unsupported named curve in use");
  6652. }
  6653. const asn1 = asn1js.fromBER(signatureValue);
  6654. AsnError.assert(asn1, "Signature value");
  6655. signatureValue = createECDSASignatureFromCMS(asn1.result, namedCurve.size);
  6656. }
  6657. if (publicKey.algorithm.name === "RSA-PSS") {
  6658. const pssParameters = new RSASSAPSSParams({ schema: signatureAlgorithm.algorithmParams });
  6659. if ("saltLength" in pssParameters)
  6660. algorithm.algorithm.saltLength = pssParameters.saltLength;
  6661. else
  6662. algorithm.algorithm.saltLength = 20;
  6663. let hashAlgo = "SHA-1";
  6664. if ("hashAlgorithm" in pssParameters) {
  6665. const hashAlgorithm = this.getAlgorithmByOID(pssParameters.hashAlgorithm.algorithmId, true);
  6666. hashAlgo = hashAlgorithm.name;
  6667. }
  6668. algorithm.algorithm.hash.name = hashAlgo;
  6669. }
  6670. return this.verify(algorithm.algorithm, publicKey, signatureValue, data);
  6671. }
  6672. }
  6673. let engine = {
  6674. name: "none",
  6675. crypto: null,
  6676. };
  6677. function isCryptoEngine(engine) {
  6678. return engine
  6679. && typeof engine === "object"
  6680. && "crypto" in engine
  6681. ? true
  6682. : false;
  6683. }
  6684. function setEngine(name, ...args) {
  6685. let crypto = null;
  6686. if (args.length < 2) {
  6687. if (args.length) {
  6688. crypto = args[0];
  6689. }
  6690. else {
  6691. crypto = typeof self !== "undefined" && self.crypto ? new CryptoEngine({ name: "browser", crypto: self.crypto }) : null;
  6692. }
  6693. }
  6694. else {
  6695. const cryptoArg = args[0];
  6696. const subtleArg = args[1];
  6697. if (isCryptoEngine(subtleArg)) {
  6698. crypto = subtleArg;
  6699. }
  6700. else if (isCryptoEngine(cryptoArg)) {
  6701. crypto = cryptoArg;
  6702. }
  6703. else if ("subtle" in cryptoArg && "getRandomValues" in cryptoArg) {
  6704. crypto = new CryptoEngine({
  6705. crypto: cryptoArg,
  6706. });
  6707. }
  6708. }
  6709. if ((typeof process !== "undefined") && ("pid" in process) && (typeof global !== "undefined") && (typeof window === "undefined")) {
  6710. if (typeof global[process.pid] === "undefined") {
  6711. global[process.pid] = {};
  6712. }
  6713. else {
  6714. if (typeof global[process.pid] !== "object") {
  6715. throw new Error(`Name global.${process.pid} already exists and it is not an object`);
  6716. }
  6717. }
  6718. if (typeof global[process.pid].pkijs === "undefined") {
  6719. global[process.pid].pkijs = {};
  6720. }
  6721. else {
  6722. if (typeof global[process.pid].pkijs !== "object") {
  6723. throw new Error(`Name global.${process.pid}.pkijs already exists and it is not an object`);
  6724. }
  6725. }
  6726. global[process.pid].pkijs.engine = {
  6727. name: name,
  6728. crypto,
  6729. };
  6730. }
  6731. else {
  6732. engine = {
  6733. name: name,
  6734. crypto,
  6735. };
  6736. }
  6737. }
  6738. function getEngine() {
  6739. if ((typeof process !== "undefined") && ("pid" in process) && (typeof global !== "undefined") && (typeof window === "undefined")) {
  6740. let _engine;
  6741. try {
  6742. _engine = global[process.pid].pkijs.engine;
  6743. }
  6744. catch {
  6745. throw new Error("Please call 'setEngine' before call to 'getEngine'");
  6746. }
  6747. return _engine;
  6748. }
  6749. return engine;
  6750. }
  6751. function getCrypto(safety = false) {
  6752. const _engine = getEngine();
  6753. if (!_engine.crypto && safety) {
  6754. throw new Error("Unable to create WebCrypto object");
  6755. }
  6756. return _engine.crypto;
  6757. }
  6758. function getRandomValues(view) {
  6759. return getCrypto(true).getRandomValues(view);
  6760. }
  6761. function getOIDByAlgorithm(algorithm, safety, target) {
  6762. return getCrypto(true).getOIDByAlgorithm(algorithm, safety, target);
  6763. }
  6764. function getAlgorithmParameters(algorithmName, operation) {
  6765. return getCrypto(true).getAlgorithmParameters(algorithmName, operation);
  6766. }
  6767. function createCMSECDSASignature(signatureBuffer) {
  6768. if ((signatureBuffer.byteLength % 2) !== 0)
  6769. return EMPTY_BUFFER;
  6770. const length = signatureBuffer.byteLength / 2;
  6771. const rBuffer = new ArrayBuffer(length);
  6772. const rView = new Uint8Array(rBuffer);
  6773. rView.set(new Uint8Array(signatureBuffer, 0, length));
  6774. const rInteger = new asn1js.Integer({ valueHex: rBuffer });
  6775. const sBuffer = new ArrayBuffer(length);
  6776. const sView = new Uint8Array(sBuffer);
  6777. sView.set(new Uint8Array(signatureBuffer, length, length));
  6778. const sInteger = new asn1js.Integer({ valueHex: sBuffer });
  6779. return (new asn1js.Sequence({
  6780. value: [
  6781. rInteger.convertToDER(),
  6782. sInteger.convertToDER()
  6783. ]
  6784. })).toBER(false);
  6785. }
  6786. function createECDSASignatureFromCMS(cmsSignature, pointSize) {
  6787. if (!(cmsSignature instanceof asn1js.Sequence
  6788. && cmsSignature.valueBlock.value.length === 2
  6789. && cmsSignature.valueBlock.value[0] instanceof asn1js.Integer
  6790. && cmsSignature.valueBlock.value[1] instanceof asn1js.Integer))
  6791. return EMPTY_BUFFER;
  6792. const rValueView = cmsSignature.valueBlock.value[0].convertFromDER().valueBlock.valueHexView;
  6793. const sValueView = cmsSignature.valueBlock.value[1].convertFromDER().valueBlock.valueHexView;
  6794. const res = new Uint8Array(pointSize * 2);
  6795. res.set(rValueView, pointSize - rValueView.byteLength);
  6796. res.set(sValueView, (2 * pointSize) - sValueView.byteLength);
  6797. return res.buffer;
  6798. }
  6799. function getAlgorithmByOID(oid, safety = false, target) {
  6800. return getCrypto(true).getAlgorithmByOID(oid, safety, target);
  6801. }
  6802. function getHashAlgorithm(signatureAlgorithm) {
  6803. return getCrypto(true).getHashAlgorithm(signatureAlgorithm);
  6804. }
  6805. async function kdfWithCounter(hashFunction, zBuffer, Counter, SharedInfo, crypto) {
  6806. switch (hashFunction.toUpperCase()) {
  6807. case "SHA-1":
  6808. case "SHA-256":
  6809. case "SHA-384":
  6810. case "SHA-512":
  6811. break;
  6812. default:
  6813. throw new ArgumentError(`Unknown hash function: ${hashFunction}`);
  6814. }
  6815. ArgumentError.assert(zBuffer, "zBuffer", "ArrayBuffer");
  6816. if (zBuffer.byteLength === 0)
  6817. throw new ArgumentError("'zBuffer' has zero length, error");
  6818. ArgumentError.assert(SharedInfo, "SharedInfo", "ArrayBuffer");
  6819. if (Counter > 255)
  6820. throw new ArgumentError("Please set 'Counter' argument to value less or equal to 255");
  6821. const counterBuffer = new ArrayBuffer(4);
  6822. const counterView = new Uint8Array(counterBuffer);
  6823. counterView[0] = 0x00;
  6824. counterView[1] = 0x00;
  6825. counterView[2] = 0x00;
  6826. counterView[3] = Counter;
  6827. let combinedBuffer = EMPTY_BUFFER;
  6828. combinedBuffer = pvutils.utilConcatBuf(combinedBuffer, zBuffer);
  6829. combinedBuffer = pvutils.utilConcatBuf(combinedBuffer, counterBuffer);
  6830. combinedBuffer = pvutils.utilConcatBuf(combinedBuffer, SharedInfo);
  6831. const result = await crypto.digest({ name: hashFunction }, combinedBuffer);
  6832. return {
  6833. counter: Counter,
  6834. result
  6835. };
  6836. }
  6837. async function kdf(hashFunction, Zbuffer, keydatalen, SharedInfo, crypto = getCrypto(true)) {
  6838. let hashLength = 0;
  6839. let maxCounter = 1;
  6840. switch (hashFunction.toUpperCase()) {
  6841. case "SHA-1":
  6842. hashLength = 160;
  6843. break;
  6844. case "SHA-256":
  6845. hashLength = 256;
  6846. break;
  6847. case "SHA-384":
  6848. hashLength = 384;
  6849. break;
  6850. case "SHA-512":
  6851. hashLength = 512;
  6852. break;
  6853. default:
  6854. throw new ArgumentError(`Unknown hash function: ${hashFunction}`);
  6855. }
  6856. ArgumentError.assert(Zbuffer, "Zbuffer", "ArrayBuffer");
  6857. if (Zbuffer.byteLength === 0)
  6858. throw new ArgumentError("'Zbuffer' has zero length, error");
  6859. ArgumentError.assert(SharedInfo, "SharedInfo", "ArrayBuffer");
  6860. const quotient = keydatalen / hashLength;
  6861. if (Math.floor(quotient) > 0) {
  6862. maxCounter = Math.floor(quotient);
  6863. if ((quotient - maxCounter) > 0)
  6864. maxCounter++;
  6865. }
  6866. const incomingResult = [];
  6867. for (let i = 1; i <= maxCounter; i++)
  6868. incomingResult.push(await kdfWithCounter(hashFunction, Zbuffer, i, SharedInfo, crypto));
  6869. let combinedBuffer = EMPTY_BUFFER;
  6870. let currentCounter = 1;
  6871. let found = true;
  6872. while (found) {
  6873. found = false;
  6874. for (const result of incomingResult) {
  6875. if (result.counter === currentCounter) {
  6876. combinedBuffer = pvutils.utilConcatBuf(combinedBuffer, result.result);
  6877. found = true;
  6878. break;
  6879. }
  6880. }
  6881. currentCounter++;
  6882. }
  6883. keydatalen >>= 3;
  6884. if (combinedBuffer.byteLength > keydatalen) {
  6885. const newBuffer = new ArrayBuffer(keydatalen);
  6886. const newView = new Uint8Array(newBuffer);
  6887. const combinedView = new Uint8Array(combinedBuffer);
  6888. for (let i = 0; i < keydatalen; i++)
  6889. newView[i] = combinedView[i];
  6890. return newBuffer;
  6891. }
  6892. return combinedBuffer;
  6893. }
  6894. const VERSION$i = "version";
  6895. const LOG_ID = "logID";
  6896. const EXTENSIONS$6 = "extensions";
  6897. const TIMESTAMP = "timestamp";
  6898. const HASH_ALGORITHM$3 = "hashAlgorithm";
  6899. const SIGNATURE_ALGORITHM$8 = "signatureAlgorithm";
  6900. const SIGNATURE$7 = "signature";
  6901. const NONE = "none";
  6902. const MD5 = "md5";
  6903. const SHA1 = "sha1";
  6904. const SHA224 = "sha224";
  6905. const SHA256 = "sha256";
  6906. const SHA384 = "sha384";
  6907. const SHA512 = "sha512";
  6908. const ANONYMOUS = "anonymous";
  6909. const RSA = "rsa";
  6910. const DSA = "dsa";
  6911. const ECDSA = "ecdsa";
  6912. class SignedCertificateTimestamp extends PkiObject {
  6913. constructor(parameters = {}) {
  6914. super();
  6915. this.version = pvutils.getParametersValue(parameters, VERSION$i, SignedCertificateTimestamp.defaultValues(VERSION$i));
  6916. this.logID = pvutils.getParametersValue(parameters, LOG_ID, SignedCertificateTimestamp.defaultValues(LOG_ID));
  6917. this.timestamp = pvutils.getParametersValue(parameters, TIMESTAMP, SignedCertificateTimestamp.defaultValues(TIMESTAMP));
  6918. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$6, SignedCertificateTimestamp.defaultValues(EXTENSIONS$6));
  6919. this.hashAlgorithm = pvutils.getParametersValue(parameters, HASH_ALGORITHM$3, SignedCertificateTimestamp.defaultValues(HASH_ALGORITHM$3));
  6920. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$8, SignedCertificateTimestamp.defaultValues(SIGNATURE_ALGORITHM$8));
  6921. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$7, SignedCertificateTimestamp.defaultValues(SIGNATURE$7));
  6922. if ("stream" in parameters && parameters.stream) {
  6923. this.fromStream(parameters.stream);
  6924. }
  6925. if (parameters.schema) {
  6926. this.fromSchema(parameters.schema);
  6927. }
  6928. }
  6929. static defaultValues(memberName) {
  6930. switch (memberName) {
  6931. case VERSION$i:
  6932. return 0;
  6933. case LOG_ID:
  6934. case EXTENSIONS$6:
  6935. return EMPTY_BUFFER;
  6936. case TIMESTAMP:
  6937. return new Date(0);
  6938. case HASH_ALGORITHM$3:
  6939. case SIGNATURE_ALGORITHM$8:
  6940. return EMPTY_STRING;
  6941. case SIGNATURE$7:
  6942. return EMPTY_BUFFER;
  6943. default:
  6944. return super.defaultValues(memberName);
  6945. }
  6946. }
  6947. fromSchema(schema) {
  6948. if ((schema instanceof asn1js.RawData) === false)
  6949. throw new Error("Object's schema was not verified against input data for SignedCertificateTimestamp");
  6950. const seqStream = new bs.SeqStream({
  6951. stream: new bs.ByteStream({
  6952. buffer: schema.data
  6953. })
  6954. });
  6955. this.fromStream(seqStream);
  6956. }
  6957. fromStream(stream) {
  6958. const blockLength = stream.getUint16();
  6959. this.version = (stream.getBlock(1))[0];
  6960. if (this.version === 0) {
  6961. this.logID = (new Uint8Array(stream.getBlock(32))).buffer.slice(0);
  6962. this.timestamp = new Date(pvutils.utilFromBase(new Uint8Array(stream.getBlock(8)), 8));
  6963. const extensionsLength = stream.getUint16();
  6964. this.extensions = (new Uint8Array(stream.getBlock(extensionsLength))).buffer.slice(0);
  6965. switch ((stream.getBlock(1))[0]) {
  6966. case 0:
  6967. this.hashAlgorithm = NONE;
  6968. break;
  6969. case 1:
  6970. this.hashAlgorithm = MD5;
  6971. break;
  6972. case 2:
  6973. this.hashAlgorithm = SHA1;
  6974. break;
  6975. case 3:
  6976. this.hashAlgorithm = SHA224;
  6977. break;
  6978. case 4:
  6979. this.hashAlgorithm = SHA256;
  6980. break;
  6981. case 5:
  6982. this.hashAlgorithm = SHA384;
  6983. break;
  6984. case 6:
  6985. this.hashAlgorithm = SHA512;
  6986. break;
  6987. default:
  6988. throw new Error("Object's stream was not correct for SignedCertificateTimestamp");
  6989. }
  6990. switch ((stream.getBlock(1))[0]) {
  6991. case 0:
  6992. this.signatureAlgorithm = ANONYMOUS;
  6993. break;
  6994. case 1:
  6995. this.signatureAlgorithm = RSA;
  6996. break;
  6997. case 2:
  6998. this.signatureAlgorithm = DSA;
  6999. break;
  7000. case 3:
  7001. this.signatureAlgorithm = ECDSA;
  7002. break;
  7003. default:
  7004. throw new Error("Object's stream was not correct for SignedCertificateTimestamp");
  7005. }
  7006. const signatureLength = stream.getUint16();
  7007. this.signature = new Uint8Array(stream.getBlock(signatureLength)).buffer.slice(0);
  7008. if (blockLength !== (47 + extensionsLength + signatureLength)) {
  7009. throw new Error("Object's stream was not correct for SignedCertificateTimestamp");
  7010. }
  7011. }
  7012. }
  7013. toSchema() {
  7014. const stream = this.toStream();
  7015. return new asn1js.RawData({ data: stream.stream.buffer });
  7016. }
  7017. toStream() {
  7018. const stream = new bs.SeqStream();
  7019. stream.appendUint16(47 + this.extensions.byteLength + this.signature.byteLength);
  7020. stream.appendChar(this.version);
  7021. stream.appendView(new Uint8Array(this.logID));
  7022. const timeBuffer = new ArrayBuffer(8);
  7023. const timeView = new Uint8Array(timeBuffer);
  7024. const baseArray = pvutils.utilToBase(this.timestamp.valueOf(), 8);
  7025. timeView.set(new Uint8Array(baseArray), 8 - baseArray.byteLength);
  7026. stream.appendView(timeView);
  7027. stream.appendUint16(this.extensions.byteLength);
  7028. if (this.extensions.byteLength)
  7029. stream.appendView(new Uint8Array(this.extensions));
  7030. let _hashAlgorithm;
  7031. switch (this.hashAlgorithm.toLowerCase()) {
  7032. case NONE:
  7033. _hashAlgorithm = 0;
  7034. break;
  7035. case MD5:
  7036. _hashAlgorithm = 1;
  7037. break;
  7038. case SHA1:
  7039. _hashAlgorithm = 2;
  7040. break;
  7041. case SHA224:
  7042. _hashAlgorithm = 3;
  7043. break;
  7044. case SHA256:
  7045. _hashAlgorithm = 4;
  7046. break;
  7047. case SHA384:
  7048. _hashAlgorithm = 5;
  7049. break;
  7050. case SHA512:
  7051. _hashAlgorithm = 6;
  7052. break;
  7053. default:
  7054. throw new Error(`Incorrect data for hashAlgorithm: ${this.hashAlgorithm}`);
  7055. }
  7056. stream.appendChar(_hashAlgorithm);
  7057. let _signatureAlgorithm;
  7058. switch (this.signatureAlgorithm.toLowerCase()) {
  7059. case ANONYMOUS:
  7060. _signatureAlgorithm = 0;
  7061. break;
  7062. case RSA:
  7063. _signatureAlgorithm = 1;
  7064. break;
  7065. case DSA:
  7066. _signatureAlgorithm = 2;
  7067. break;
  7068. case ECDSA:
  7069. _signatureAlgorithm = 3;
  7070. break;
  7071. default:
  7072. throw new Error(`Incorrect data for signatureAlgorithm: ${this.signatureAlgorithm}`);
  7073. }
  7074. stream.appendChar(_signatureAlgorithm);
  7075. stream.appendUint16(this.signature.byteLength);
  7076. stream.appendView(new Uint8Array(this.signature));
  7077. return stream;
  7078. }
  7079. toJSON() {
  7080. return {
  7081. version: this.version,
  7082. logID: pvutils.bufferToHexCodes(this.logID),
  7083. timestamp: this.timestamp,
  7084. extensions: pvutils.bufferToHexCodes(this.extensions),
  7085. hashAlgorithm: this.hashAlgorithm,
  7086. signatureAlgorithm: this.signatureAlgorithm,
  7087. signature: pvutils.bufferToHexCodes(this.signature),
  7088. };
  7089. }
  7090. async verify(logs, data, dataType = 0, crypto = getCrypto(true)) {
  7091. const logId = pvutils.toBase64(pvutils.arrayBufferToString(this.logID));
  7092. let publicKeyBase64 = null;
  7093. const stream = new bs.SeqStream();
  7094. for (const log of logs) {
  7095. if (log.log_id === logId) {
  7096. publicKeyBase64 = log.key;
  7097. break;
  7098. }
  7099. }
  7100. if (!publicKeyBase64) {
  7101. throw new Error(`Public key not found for CT with logId: ${logId}`);
  7102. }
  7103. const pki = pvutils.stringToArrayBuffer(pvutils.fromBase64(publicKeyBase64));
  7104. const publicKeyInfo = PublicKeyInfo.fromBER(pki);
  7105. stream.appendChar(0x00);
  7106. stream.appendChar(0x00);
  7107. const timeBuffer = new ArrayBuffer(8);
  7108. const timeView = new Uint8Array(timeBuffer);
  7109. const baseArray = pvutils.utilToBase(this.timestamp.valueOf(), 8);
  7110. timeView.set(new Uint8Array(baseArray), 8 - baseArray.byteLength);
  7111. stream.appendView(timeView);
  7112. stream.appendUint16(dataType);
  7113. if (dataType === 0)
  7114. stream.appendUint24(data.byteLength);
  7115. stream.appendView(new Uint8Array(data));
  7116. stream.appendUint16(this.extensions.byteLength);
  7117. if (this.extensions.byteLength !== 0)
  7118. stream.appendView(new Uint8Array(this.extensions));
  7119. return crypto.verifyWithPublicKey(stream.buffer.slice(0, stream.length), new asn1js.OctetString({ valueHex: this.signature }), publicKeyInfo, { algorithmId: EMPTY_STRING }, "SHA-256");
  7120. }
  7121. }
  7122. SignedCertificateTimestamp.CLASS_NAME = "SignedCertificateTimestamp";
  7123. async function verifySCTsForCertificate(certificate, issuerCertificate, logs, index = (-1), crypto = getCrypto(true)) {
  7124. let parsedValue = null;
  7125. const stream = new bs.SeqStream();
  7126. if (certificate.extensions) {
  7127. for (let i = certificate.extensions.length - 1; i >= 0; i--) {
  7128. switch (certificate.extensions[i].extnID) {
  7129. case id_SignedCertificateTimestampList:
  7130. {
  7131. parsedValue = certificate.extensions[i].parsedValue;
  7132. if (!parsedValue || parsedValue.timestamps.length === 0)
  7133. throw new Error("Nothing to verify in the certificate");
  7134. certificate.extensions.splice(i, 1);
  7135. }
  7136. break;
  7137. }
  7138. }
  7139. }
  7140. if (parsedValue === null)
  7141. throw new Error("No SignedCertificateTimestampList extension in the specified certificate");
  7142. const tbs = certificate.encodeTBS().toBER();
  7143. const issuerId = await crypto.digest({ name: "SHA-256" }, new Uint8Array(issuerCertificate.subjectPublicKeyInfo.toSchema().toBER(false)));
  7144. stream.appendView(new Uint8Array(issuerId));
  7145. stream.appendUint24(tbs.byteLength);
  7146. stream.appendView(new Uint8Array(tbs));
  7147. const preCert = stream.stream.slice(0, stream.length);
  7148. if (index === (-1)) {
  7149. const verifyArray = [];
  7150. for (const timestamp of parsedValue.timestamps) {
  7151. const verifyResult = await timestamp.verify(logs, preCert.buffer, 1, crypto);
  7152. verifyArray.push(verifyResult);
  7153. }
  7154. return verifyArray;
  7155. }
  7156. if (index >= parsedValue.timestamps.length)
  7157. index = (parsedValue.timestamps.length - 1);
  7158. return [await parsedValue.timestamps[index].verify(logs, preCert.buffer, 1, crypto)];
  7159. }
  7160. const TIMESTAMPS = "timestamps";
  7161. class SignedCertificateTimestampList extends PkiObject {
  7162. constructor(parameters = {}) {
  7163. super();
  7164. this.timestamps = pvutils.getParametersValue(parameters, TIMESTAMPS, SignedCertificateTimestampList.defaultValues(TIMESTAMPS));
  7165. if (parameters.schema) {
  7166. this.fromSchema(parameters.schema);
  7167. }
  7168. }
  7169. static defaultValues(memberName) {
  7170. switch (memberName) {
  7171. case TIMESTAMPS:
  7172. return [];
  7173. default:
  7174. return super.defaultValues(memberName);
  7175. }
  7176. }
  7177. static compareWithDefault(memberName, memberValue) {
  7178. switch (memberName) {
  7179. case TIMESTAMPS:
  7180. return (memberValue.length === 0);
  7181. default:
  7182. return super.defaultValues(memberName);
  7183. }
  7184. }
  7185. static schema(parameters = {}) {
  7186. var _a;
  7187. const names = pvutils.getParametersValue(parameters, "names", {});
  7188. (_a = names.optional) !== null && _a !== void 0 ? _a : (names.optional = false);
  7189. return (new asn1js.OctetString({
  7190. name: (names.blockName || "SignedCertificateTimestampList"),
  7191. optional: names.optional
  7192. }));
  7193. }
  7194. fromSchema(schema) {
  7195. if ((schema instanceof asn1js.OctetString) === false) {
  7196. throw new Error("Object's schema was not verified against input data for SignedCertificateTimestampList");
  7197. }
  7198. const seqStream = new bs.SeqStream({
  7199. stream: new bs.ByteStream({
  7200. buffer: schema.valueBlock.valueHex
  7201. })
  7202. });
  7203. const dataLength = seqStream.getUint16();
  7204. if (dataLength !== seqStream.length) {
  7205. throw new Error("Object's schema was not verified against input data for SignedCertificateTimestampList");
  7206. }
  7207. while (seqStream.length) {
  7208. this.timestamps.push(new SignedCertificateTimestamp({ stream: seqStream }));
  7209. }
  7210. }
  7211. toSchema() {
  7212. const stream = new bs.SeqStream();
  7213. let overallLength = 0;
  7214. const timestampsData = [];
  7215. for (const timestamp of this.timestamps) {
  7216. const timestampStream = timestamp.toStream();
  7217. timestampsData.push(timestampStream);
  7218. overallLength += timestampStream.stream.buffer.byteLength;
  7219. }
  7220. stream.appendUint16(overallLength);
  7221. for (const timestamp of timestampsData) {
  7222. stream.appendView(timestamp.stream.view);
  7223. }
  7224. return new asn1js.OctetString({ valueHex: stream.stream.buffer.slice(0) });
  7225. }
  7226. toJSON() {
  7227. return {
  7228. timestamps: Array.from(this.timestamps, o => o.toJSON())
  7229. };
  7230. }
  7231. }
  7232. SignedCertificateTimestampList.CLASS_NAME = "SignedCertificateTimestampList";
  7233. const ATTRIBUTES$4 = "attributes";
  7234. const CLEAR_PROPS$11 = [
  7235. ATTRIBUTES$4
  7236. ];
  7237. class SubjectDirectoryAttributes extends PkiObject {
  7238. constructor(parameters = {}) {
  7239. super();
  7240. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES$4, SubjectDirectoryAttributes.defaultValues(ATTRIBUTES$4));
  7241. if (parameters.schema) {
  7242. this.fromSchema(parameters.schema);
  7243. }
  7244. }
  7245. static defaultValues(memberName) {
  7246. switch (memberName) {
  7247. case ATTRIBUTES$4:
  7248. return [];
  7249. default:
  7250. return super.defaultValues(memberName);
  7251. }
  7252. }
  7253. static schema(parameters = {}) {
  7254. const names = pvutils.getParametersValue(parameters, "names", {});
  7255. return (new asn1js.Sequence({
  7256. name: (names.blockName || EMPTY_STRING),
  7257. value: [
  7258. new asn1js.Repeated({
  7259. name: (names.attributes || EMPTY_STRING),
  7260. value: Attribute.schema()
  7261. })
  7262. ]
  7263. }));
  7264. }
  7265. fromSchema(schema) {
  7266. pvutils.clearProps(schema, CLEAR_PROPS$11);
  7267. const asn1 = asn1js.compareSchema(schema, schema, SubjectDirectoryAttributes.schema({
  7268. names: {
  7269. attributes: ATTRIBUTES$4
  7270. }
  7271. }));
  7272. AsnError.assertSchema(asn1, this.className);
  7273. this.attributes = Array.from(asn1.result.attributes, element => new Attribute({ schema: element }));
  7274. }
  7275. toSchema() {
  7276. return (new asn1js.Sequence({
  7277. value: Array.from(this.attributes, o => o.toSchema())
  7278. }));
  7279. }
  7280. toJSON() {
  7281. return {
  7282. attributes: Array.from(this.attributes, o => o.toJSON())
  7283. };
  7284. }
  7285. }
  7286. SubjectDirectoryAttributes.CLASS_NAME = "SubjectDirectoryAttributes";
  7287. class ExtensionValueFactory {
  7288. static getItems() {
  7289. if (!this.types) {
  7290. this.types = {};
  7291. ExtensionValueFactory.register(id_SubjectAltName, "SubjectAltName", AltName);
  7292. ExtensionValueFactory.register(id_IssuerAltName, "IssuerAltName", AltName);
  7293. ExtensionValueFactory.register(id_AuthorityKeyIdentifier, "AuthorityKeyIdentifier", AuthorityKeyIdentifier);
  7294. ExtensionValueFactory.register(id_BasicConstraints, "BasicConstraints", BasicConstraints);
  7295. ExtensionValueFactory.register(id_MicrosoftCaVersion, "MicrosoftCaVersion", CAVersion);
  7296. ExtensionValueFactory.register(id_CertificatePolicies, "CertificatePolicies", CertificatePolicies);
  7297. ExtensionValueFactory.register(id_MicrosoftAppPolicies, "CertificatePoliciesMicrosoft", CertificatePolicies);
  7298. ExtensionValueFactory.register(id_MicrosoftCertTemplateV2, "MicrosoftCertTemplateV2", CertificateTemplate);
  7299. ExtensionValueFactory.register(id_CRLDistributionPoints, "CRLDistributionPoints", CRLDistributionPoints);
  7300. ExtensionValueFactory.register(id_FreshestCRL, "FreshestCRL", CRLDistributionPoints);
  7301. ExtensionValueFactory.register(id_ExtKeyUsage, "ExtKeyUsage", ExtKeyUsage);
  7302. ExtensionValueFactory.register(id_CertificateIssuer, "CertificateIssuer", GeneralNames);
  7303. ExtensionValueFactory.register(id_AuthorityInfoAccess, "AuthorityInfoAccess", InfoAccess);
  7304. ExtensionValueFactory.register(id_SubjectInfoAccess, "SubjectInfoAccess", InfoAccess);
  7305. ExtensionValueFactory.register(id_IssuingDistributionPoint, "IssuingDistributionPoint", IssuingDistributionPoint);
  7306. ExtensionValueFactory.register(id_NameConstraints, "NameConstraints", NameConstraints);
  7307. ExtensionValueFactory.register(id_PolicyConstraints, "PolicyConstraints", PolicyConstraints);
  7308. ExtensionValueFactory.register(id_PolicyMappings, "PolicyMappings", PolicyMappings);
  7309. ExtensionValueFactory.register(id_PrivateKeyUsagePeriod, "PrivateKeyUsagePeriod", PrivateKeyUsagePeriod);
  7310. ExtensionValueFactory.register(id_QCStatements, "QCStatements", QCStatements);
  7311. ExtensionValueFactory.register(id_SignedCertificateTimestampList, "SignedCertificateTimestampList", SignedCertificateTimestampList);
  7312. ExtensionValueFactory.register(id_SubjectDirectoryAttributes, "SubjectDirectoryAttributes", SubjectDirectoryAttributes);
  7313. }
  7314. return this.types;
  7315. }
  7316. static fromBER(id, raw) {
  7317. const asn1 = asn1js.fromBER(raw);
  7318. if (asn1.offset === -1) {
  7319. return null;
  7320. }
  7321. const item = this.find(id);
  7322. if (item) {
  7323. try {
  7324. return new item.type({ schema: asn1.result });
  7325. }
  7326. catch {
  7327. const res = new item.type();
  7328. res.parsingError = `Incorrectly formatted value of extension ${item.name} (${id})`;
  7329. return res;
  7330. }
  7331. }
  7332. return asn1.result;
  7333. }
  7334. static find(id) {
  7335. const types = this.getItems();
  7336. return types[id] || null;
  7337. }
  7338. static register(id, name, type) {
  7339. this.getItems()[id] = { name, type };
  7340. }
  7341. }
  7342. const EXTN_ID = "extnID";
  7343. const CRITICAL = "critical";
  7344. const EXTN_VALUE = "extnValue";
  7345. const PARSED_VALUE$5 = "parsedValue";
  7346. const CLEAR_PROPS$10 = [
  7347. EXTN_ID,
  7348. CRITICAL,
  7349. EXTN_VALUE
  7350. ];
  7351. class Extension extends PkiObject {
  7352. get parsedValue() {
  7353. if (this._parsedValue === undefined) {
  7354. const parsedValue = ExtensionValueFactory.fromBER(this.extnID, this.extnValue.valueBlock.valueHexView);
  7355. this._parsedValue = parsedValue;
  7356. }
  7357. return this._parsedValue || undefined;
  7358. }
  7359. set parsedValue(value) {
  7360. this._parsedValue = value;
  7361. }
  7362. constructor(parameters = {}) {
  7363. super();
  7364. this.extnID = pvutils.getParametersValue(parameters, EXTN_ID, Extension.defaultValues(EXTN_ID));
  7365. this.critical = pvutils.getParametersValue(parameters, CRITICAL, Extension.defaultValues(CRITICAL));
  7366. if (EXTN_VALUE in parameters) {
  7367. this.extnValue = new asn1js.OctetString({ valueHex: parameters.extnValue });
  7368. }
  7369. else {
  7370. this.extnValue = Extension.defaultValues(EXTN_VALUE);
  7371. }
  7372. if (PARSED_VALUE$5 in parameters) {
  7373. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE$5, Extension.defaultValues(PARSED_VALUE$5));
  7374. }
  7375. if (parameters.schema) {
  7376. this.fromSchema(parameters.schema);
  7377. }
  7378. }
  7379. static defaultValues(memberName) {
  7380. switch (memberName) {
  7381. case EXTN_ID:
  7382. return EMPTY_STRING;
  7383. case CRITICAL:
  7384. return false;
  7385. case EXTN_VALUE:
  7386. return new asn1js.OctetString();
  7387. case PARSED_VALUE$5:
  7388. return {};
  7389. default:
  7390. return super.defaultValues(memberName);
  7391. }
  7392. }
  7393. static schema(parameters = {}) {
  7394. const names = pvutils.getParametersValue(parameters, "names", {});
  7395. return (new asn1js.Sequence({
  7396. name: (names.blockName || EMPTY_STRING),
  7397. value: [
  7398. new asn1js.ObjectIdentifier({ name: (names.extnID || EMPTY_STRING) }),
  7399. new asn1js.Boolean({
  7400. name: (names.critical || EMPTY_STRING),
  7401. optional: true
  7402. }),
  7403. new asn1js.OctetString({ name: (names.extnValue || EMPTY_STRING) })
  7404. ]
  7405. }));
  7406. }
  7407. fromSchema(schema) {
  7408. pvutils.clearProps(schema, CLEAR_PROPS$10);
  7409. const asn1 = asn1js.compareSchema(schema, schema, Extension.schema({
  7410. names: {
  7411. extnID: EXTN_ID,
  7412. critical: CRITICAL,
  7413. extnValue: EXTN_VALUE
  7414. }
  7415. }));
  7416. AsnError.assertSchema(asn1, this.className);
  7417. this.extnID = asn1.result.extnID.valueBlock.toString();
  7418. if (CRITICAL in asn1.result) {
  7419. this.critical = asn1.result.critical.valueBlock.value;
  7420. }
  7421. this.extnValue = asn1.result.extnValue;
  7422. }
  7423. toSchema() {
  7424. const outputArray = [];
  7425. outputArray.push(new asn1js.ObjectIdentifier({ value: this.extnID }));
  7426. if (this.critical !== Extension.defaultValues(CRITICAL)) {
  7427. outputArray.push(new asn1js.Boolean({ value: this.critical }));
  7428. }
  7429. outputArray.push(this.extnValue);
  7430. return (new asn1js.Sequence({
  7431. value: outputArray
  7432. }));
  7433. }
  7434. toJSON() {
  7435. const object = {
  7436. extnID: this.extnID,
  7437. extnValue: this.extnValue.toJSON(),
  7438. };
  7439. if (this.critical !== Extension.defaultValues(CRITICAL)) {
  7440. object.critical = this.critical;
  7441. }
  7442. if (this.parsedValue && this.parsedValue.toJSON) {
  7443. object.parsedValue = this.parsedValue.toJSON();
  7444. }
  7445. return object;
  7446. }
  7447. }
  7448. Extension.CLASS_NAME = "Extension";
  7449. const EXTENSIONS$5 = "extensions";
  7450. const CLEAR_PROPS$$ = [
  7451. EXTENSIONS$5,
  7452. ];
  7453. class Extensions extends PkiObject {
  7454. constructor(parameters = {}) {
  7455. super();
  7456. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$5, Extensions.defaultValues(EXTENSIONS$5));
  7457. if (parameters.schema) {
  7458. this.fromSchema(parameters.schema);
  7459. }
  7460. }
  7461. static defaultValues(memberName) {
  7462. switch (memberName) {
  7463. case EXTENSIONS$5:
  7464. return [];
  7465. default:
  7466. return super.defaultValues(memberName);
  7467. }
  7468. }
  7469. static schema(parameters = {}, optional = false) {
  7470. const names = pvutils.getParametersValue(parameters, "names", {});
  7471. return (new asn1js.Sequence({
  7472. optional,
  7473. name: (names.blockName || EMPTY_STRING),
  7474. value: [
  7475. new asn1js.Repeated({
  7476. name: (names.extensions || EMPTY_STRING),
  7477. value: Extension.schema(names.extension || {})
  7478. })
  7479. ]
  7480. }));
  7481. }
  7482. fromSchema(schema) {
  7483. pvutils.clearProps(schema, CLEAR_PROPS$$);
  7484. const asn1 = asn1js.compareSchema(schema, schema, Extensions.schema({
  7485. names: {
  7486. extensions: EXTENSIONS$5
  7487. }
  7488. }));
  7489. AsnError.assertSchema(asn1, this.className);
  7490. this.extensions = Array.from(asn1.result.extensions, element => new Extension({ schema: element }));
  7491. }
  7492. toSchema() {
  7493. return (new asn1js.Sequence({
  7494. value: Array.from(this.extensions, o => o.toSchema())
  7495. }));
  7496. }
  7497. toJSON() {
  7498. return {
  7499. extensions: this.extensions.map(o => o.toJSON())
  7500. };
  7501. }
  7502. }
  7503. Extensions.CLASS_NAME = "Extensions";
  7504. const ISSUER$5 = "issuer";
  7505. const SERIAL_NUMBER$6 = "serialNumber";
  7506. const ISSUER_UID = "issuerUID";
  7507. const CLEAR_PROPS$_ = [
  7508. ISSUER$5,
  7509. SERIAL_NUMBER$6,
  7510. ISSUER_UID,
  7511. ];
  7512. class IssuerSerial extends PkiObject {
  7513. constructor(parameters = {}) {
  7514. super();
  7515. this.issuer = pvutils.getParametersValue(parameters, ISSUER$5, IssuerSerial.defaultValues(ISSUER$5));
  7516. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$6, IssuerSerial.defaultValues(SERIAL_NUMBER$6));
  7517. if (ISSUER_UID in parameters) {
  7518. this.issuerUID = pvutils.getParametersValue(parameters, ISSUER_UID, IssuerSerial.defaultValues(ISSUER_UID));
  7519. }
  7520. if (parameters.schema) {
  7521. this.fromSchema(parameters.schema);
  7522. }
  7523. }
  7524. static defaultValues(memberName) {
  7525. switch (memberName) {
  7526. case ISSUER$5:
  7527. return new GeneralNames();
  7528. case SERIAL_NUMBER$6:
  7529. return new asn1js.Integer();
  7530. case ISSUER_UID:
  7531. return new asn1js.BitString();
  7532. default:
  7533. return super.defaultValues(memberName);
  7534. }
  7535. }
  7536. static schema(parameters = {}) {
  7537. const names = pvutils.getParametersValue(parameters, "names", {});
  7538. return (new asn1js.Sequence({
  7539. name: (names.blockName || EMPTY_STRING),
  7540. value: [
  7541. GeneralNames.schema(names.issuer || {}),
  7542. new asn1js.Integer({ name: (names.serialNumber || EMPTY_STRING) }),
  7543. new asn1js.BitString({
  7544. optional: true,
  7545. name: (names.issuerUID || EMPTY_STRING)
  7546. })
  7547. ]
  7548. }));
  7549. }
  7550. fromSchema(schema) {
  7551. pvutils.clearProps(schema, CLEAR_PROPS$_);
  7552. const asn1 = asn1js.compareSchema(schema, schema, IssuerSerial.schema({
  7553. names: {
  7554. issuer: {
  7555. names: {
  7556. blockName: ISSUER$5
  7557. }
  7558. },
  7559. serialNumber: SERIAL_NUMBER$6,
  7560. issuerUID: ISSUER_UID
  7561. }
  7562. }));
  7563. AsnError.assertSchema(asn1, this.className);
  7564. this.issuer = new GeneralNames({ schema: asn1.result.issuer });
  7565. this.serialNumber = asn1.result.serialNumber;
  7566. if (ISSUER_UID in asn1.result)
  7567. this.issuerUID = asn1.result.issuerUID;
  7568. }
  7569. toSchema() {
  7570. const result = new asn1js.Sequence({
  7571. value: [
  7572. this.issuer.toSchema(),
  7573. this.serialNumber
  7574. ]
  7575. });
  7576. if (this.issuerUID) {
  7577. result.valueBlock.value.push(this.issuerUID);
  7578. }
  7579. return result;
  7580. }
  7581. toJSON() {
  7582. const result = {
  7583. issuer: this.issuer.toJSON(),
  7584. serialNumber: this.serialNumber.toJSON()
  7585. };
  7586. if (this.issuerUID) {
  7587. result.issuerUID = this.issuerUID.toJSON();
  7588. }
  7589. return result;
  7590. }
  7591. }
  7592. IssuerSerial.CLASS_NAME = "IssuerSerial";
  7593. const VERSION$h = "version";
  7594. const BASE_CERTIFICATE_ID$2 = "baseCertificateID";
  7595. const SUBJECT_NAME = "subjectName";
  7596. const ISSUER$4 = "issuer";
  7597. const SIGNATURE$6 = "signature";
  7598. const SERIAL_NUMBER$5 = "serialNumber";
  7599. const ATTR_CERT_VALIDITY_PERIOD$1 = "attrCertValidityPeriod";
  7600. const ATTRIBUTES$3 = "attributes";
  7601. const ISSUER_UNIQUE_ID$2 = "issuerUniqueID";
  7602. const EXTENSIONS$4 = "extensions";
  7603. const CLEAR_PROPS$Z = [
  7604. VERSION$h,
  7605. BASE_CERTIFICATE_ID$2,
  7606. SUBJECT_NAME,
  7607. ISSUER$4,
  7608. SIGNATURE$6,
  7609. SERIAL_NUMBER$5,
  7610. ATTR_CERT_VALIDITY_PERIOD$1,
  7611. ATTRIBUTES$3,
  7612. ISSUER_UNIQUE_ID$2,
  7613. EXTENSIONS$4,
  7614. ];
  7615. class AttributeCertificateInfoV1 extends PkiObject {
  7616. constructor(parameters = {}) {
  7617. super();
  7618. this.version = pvutils.getParametersValue(parameters, VERSION$h, AttributeCertificateInfoV1.defaultValues(VERSION$h));
  7619. if (BASE_CERTIFICATE_ID$2 in parameters) {
  7620. this.baseCertificateID = pvutils.getParametersValue(parameters, BASE_CERTIFICATE_ID$2, AttributeCertificateInfoV1.defaultValues(BASE_CERTIFICATE_ID$2));
  7621. }
  7622. if (SUBJECT_NAME in parameters) {
  7623. this.subjectName = pvutils.getParametersValue(parameters, SUBJECT_NAME, AttributeCertificateInfoV1.defaultValues(SUBJECT_NAME));
  7624. }
  7625. this.issuer = pvutils.getParametersValue(parameters, ISSUER$4, AttributeCertificateInfoV1.defaultValues(ISSUER$4));
  7626. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$6, AttributeCertificateInfoV1.defaultValues(SIGNATURE$6));
  7627. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$5, AttributeCertificateInfoV1.defaultValues(SERIAL_NUMBER$5));
  7628. this.attrCertValidityPeriod = pvutils.getParametersValue(parameters, ATTR_CERT_VALIDITY_PERIOD$1, AttributeCertificateInfoV1.defaultValues(ATTR_CERT_VALIDITY_PERIOD$1));
  7629. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES$3, AttributeCertificateInfoV1.defaultValues(ATTRIBUTES$3));
  7630. if (ISSUER_UNIQUE_ID$2 in parameters)
  7631. this.issuerUniqueID = pvutils.getParametersValue(parameters, ISSUER_UNIQUE_ID$2, AttributeCertificateInfoV1.defaultValues(ISSUER_UNIQUE_ID$2));
  7632. if (EXTENSIONS$4 in parameters) {
  7633. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$4, AttributeCertificateInfoV1.defaultValues(EXTENSIONS$4));
  7634. }
  7635. if (parameters.schema) {
  7636. this.fromSchema(parameters.schema);
  7637. }
  7638. }
  7639. static defaultValues(memberName) {
  7640. switch (memberName) {
  7641. case VERSION$h:
  7642. return 0;
  7643. case BASE_CERTIFICATE_ID$2:
  7644. return new IssuerSerial();
  7645. case SUBJECT_NAME:
  7646. return new GeneralNames();
  7647. case ISSUER$4:
  7648. return new GeneralNames();
  7649. case SIGNATURE$6:
  7650. return new AlgorithmIdentifier();
  7651. case SERIAL_NUMBER$5:
  7652. return new asn1js.Integer();
  7653. case ATTR_CERT_VALIDITY_PERIOD$1:
  7654. return new AttCertValidityPeriod();
  7655. case ATTRIBUTES$3:
  7656. return [];
  7657. case ISSUER_UNIQUE_ID$2:
  7658. return new asn1js.BitString();
  7659. case EXTENSIONS$4:
  7660. return new Extensions();
  7661. default:
  7662. return super.defaultValues(memberName);
  7663. }
  7664. }
  7665. static schema(parameters = {}) {
  7666. const names = pvutils.getParametersValue(parameters, "names", {});
  7667. return (new asn1js.Sequence({
  7668. name: (names.blockName || EMPTY_STRING),
  7669. value: [
  7670. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  7671. new asn1js.Choice({
  7672. value: [
  7673. new asn1js.Constructed({
  7674. name: (names.baseCertificateID || EMPTY_STRING),
  7675. idBlock: {
  7676. tagClass: 3,
  7677. tagNumber: 0
  7678. },
  7679. value: IssuerSerial.schema().valueBlock.value
  7680. }),
  7681. new asn1js.Constructed({
  7682. name: (names.subjectName || EMPTY_STRING),
  7683. idBlock: {
  7684. tagClass: 3,
  7685. tagNumber: 1
  7686. },
  7687. value: GeneralNames.schema().valueBlock.value
  7688. }),
  7689. ]
  7690. }),
  7691. GeneralNames.schema({
  7692. names: {
  7693. blockName: (names.issuer || EMPTY_STRING)
  7694. }
  7695. }),
  7696. AlgorithmIdentifier.schema(names.signature || {}),
  7697. new asn1js.Integer({ name: (names.serialNumber || EMPTY_STRING) }),
  7698. AttCertValidityPeriod.schema(names.attrCertValidityPeriod || {}),
  7699. new asn1js.Sequence({
  7700. name: (names.attributes || EMPTY_STRING),
  7701. value: [
  7702. new asn1js.Repeated({
  7703. value: Attribute.schema()
  7704. })
  7705. ]
  7706. }),
  7707. new asn1js.BitString({
  7708. optional: true,
  7709. name: (names.issuerUniqueID || EMPTY_STRING)
  7710. }),
  7711. Extensions.schema(names.extensions || {}, true)
  7712. ]
  7713. }));
  7714. }
  7715. fromSchema(schema) {
  7716. pvutils.clearProps(schema, CLEAR_PROPS$Z);
  7717. const asn1 = asn1js.compareSchema(schema, schema, AttributeCertificateInfoV1.schema({
  7718. names: {
  7719. version: VERSION$h,
  7720. baseCertificateID: BASE_CERTIFICATE_ID$2,
  7721. subjectName: SUBJECT_NAME,
  7722. issuer: ISSUER$4,
  7723. signature: {
  7724. names: {
  7725. blockName: SIGNATURE$6
  7726. }
  7727. },
  7728. serialNumber: SERIAL_NUMBER$5,
  7729. attrCertValidityPeriod: {
  7730. names: {
  7731. blockName: ATTR_CERT_VALIDITY_PERIOD$1
  7732. }
  7733. },
  7734. attributes: ATTRIBUTES$3,
  7735. issuerUniqueID: ISSUER_UNIQUE_ID$2,
  7736. extensions: {
  7737. names: {
  7738. blockName: EXTENSIONS$4
  7739. }
  7740. }
  7741. }
  7742. }));
  7743. AsnError.assertSchema(asn1, this.className);
  7744. this.version = asn1.result.version.valueBlock.valueDec;
  7745. if (BASE_CERTIFICATE_ID$2 in asn1.result) {
  7746. this.baseCertificateID = new IssuerSerial({
  7747. schema: new asn1js.Sequence({
  7748. value: asn1.result.baseCertificateID.valueBlock.value
  7749. })
  7750. });
  7751. }
  7752. if (SUBJECT_NAME in asn1.result) {
  7753. this.subjectName = new GeneralNames({
  7754. schema: new asn1js.Sequence({
  7755. value: asn1.result.subjectName.valueBlock.value
  7756. })
  7757. });
  7758. }
  7759. this.issuer = asn1.result.issuer;
  7760. this.signature = new AlgorithmIdentifier({ schema: asn1.result.signature });
  7761. this.serialNumber = asn1.result.serialNumber;
  7762. this.attrCertValidityPeriod = new AttCertValidityPeriod({ schema: asn1.result.attrCertValidityPeriod });
  7763. this.attributes = Array.from(asn1.result.attributes.valueBlock.value, element => new Attribute({ schema: element }));
  7764. if (ISSUER_UNIQUE_ID$2 in asn1.result) {
  7765. this.issuerUniqueID = asn1.result.issuerUniqueID;
  7766. }
  7767. if (EXTENSIONS$4 in asn1.result) {
  7768. this.extensions = new Extensions({ schema: asn1.result.extensions });
  7769. }
  7770. }
  7771. toSchema() {
  7772. const result = new asn1js.Sequence({
  7773. value: [new asn1js.Integer({ value: this.version })]
  7774. });
  7775. if (this.baseCertificateID) {
  7776. result.valueBlock.value.push(new asn1js.Constructed({
  7777. idBlock: {
  7778. tagClass: 3,
  7779. tagNumber: 0
  7780. },
  7781. value: this.baseCertificateID.toSchema().valueBlock.value
  7782. }));
  7783. }
  7784. if (this.subjectName) {
  7785. result.valueBlock.value.push(new asn1js.Constructed({
  7786. idBlock: {
  7787. tagClass: 3,
  7788. tagNumber: 1
  7789. },
  7790. value: this.subjectName.toSchema().valueBlock.value
  7791. }));
  7792. }
  7793. result.valueBlock.value.push(this.issuer.toSchema());
  7794. result.valueBlock.value.push(this.signature.toSchema());
  7795. result.valueBlock.value.push(this.serialNumber);
  7796. result.valueBlock.value.push(this.attrCertValidityPeriod.toSchema());
  7797. result.valueBlock.value.push(new asn1js.Sequence({
  7798. value: Array.from(this.attributes, o => o.toSchema())
  7799. }));
  7800. if (this.issuerUniqueID) {
  7801. result.valueBlock.value.push(this.issuerUniqueID);
  7802. }
  7803. if (this.extensions) {
  7804. result.valueBlock.value.push(this.extensions.toSchema());
  7805. }
  7806. return result;
  7807. }
  7808. toJSON() {
  7809. const result = {
  7810. version: this.version
  7811. };
  7812. if (this.baseCertificateID) {
  7813. result.baseCertificateID = this.baseCertificateID.toJSON();
  7814. }
  7815. if (this.subjectName) {
  7816. result.subjectName = this.subjectName.toJSON();
  7817. }
  7818. result.issuer = this.issuer.toJSON();
  7819. result.signature = this.signature.toJSON();
  7820. result.serialNumber = this.serialNumber.toJSON();
  7821. result.attrCertValidityPeriod = this.attrCertValidityPeriod.toJSON();
  7822. result.attributes = Array.from(this.attributes, o => o.toJSON());
  7823. if (this.issuerUniqueID) {
  7824. result.issuerUniqueID = this.issuerUniqueID.toJSON();
  7825. }
  7826. if (this.extensions) {
  7827. result.extensions = this.extensions.toJSON();
  7828. }
  7829. return result;
  7830. }
  7831. }
  7832. AttributeCertificateInfoV1.CLASS_NAME = "AttributeCertificateInfoV1";
  7833. const ACINFO$1 = "acinfo";
  7834. const SIGNATURE_ALGORITHM$7 = "signatureAlgorithm";
  7835. const SIGNATURE_VALUE$4 = "signatureValue";
  7836. const CLEAR_PROPS$Y = [
  7837. ACINFO$1,
  7838. SIGNATURE_VALUE$4,
  7839. SIGNATURE_ALGORITHM$7
  7840. ];
  7841. class AttributeCertificateV1 extends PkiObject {
  7842. constructor(parameters = {}) {
  7843. super();
  7844. this.acinfo = pvutils.getParametersValue(parameters, ACINFO$1, AttributeCertificateV1.defaultValues(ACINFO$1));
  7845. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$7, AttributeCertificateV1.defaultValues(SIGNATURE_ALGORITHM$7));
  7846. this.signatureValue = pvutils.getParametersValue(parameters, SIGNATURE_VALUE$4, AttributeCertificateV1.defaultValues(SIGNATURE_VALUE$4));
  7847. if (parameters.schema) {
  7848. this.fromSchema(parameters.schema);
  7849. }
  7850. }
  7851. static defaultValues(memberName) {
  7852. switch (memberName) {
  7853. case ACINFO$1:
  7854. return new AttributeCertificateInfoV1();
  7855. case SIGNATURE_ALGORITHM$7:
  7856. return new AlgorithmIdentifier();
  7857. case SIGNATURE_VALUE$4:
  7858. return new asn1js.BitString();
  7859. default:
  7860. return super.defaultValues(memberName);
  7861. }
  7862. }
  7863. static schema(parameters = {}) {
  7864. const names = pvutils.getParametersValue(parameters, "names", {});
  7865. return (new asn1js.Sequence({
  7866. name: (names.blockName || EMPTY_STRING),
  7867. value: [
  7868. AttributeCertificateInfoV1.schema(names.acinfo || {}),
  7869. AlgorithmIdentifier.schema(names.signatureAlgorithm || {}),
  7870. new asn1js.BitString({ name: (names.signatureValue || EMPTY_STRING) })
  7871. ]
  7872. }));
  7873. }
  7874. fromSchema(schema) {
  7875. pvutils.clearProps(schema, CLEAR_PROPS$Y);
  7876. const asn1 = asn1js.compareSchema(schema, schema, AttributeCertificateV1.schema({
  7877. names: {
  7878. acinfo: {
  7879. names: {
  7880. blockName: ACINFO$1
  7881. }
  7882. },
  7883. signatureAlgorithm: {
  7884. names: {
  7885. blockName: SIGNATURE_ALGORITHM$7
  7886. }
  7887. },
  7888. signatureValue: SIGNATURE_VALUE$4
  7889. }
  7890. }));
  7891. AsnError.assertSchema(asn1, this.className);
  7892. this.acinfo = new AttributeCertificateInfoV1({ schema: asn1.result.acinfo });
  7893. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  7894. this.signatureValue = asn1.result.signatureValue;
  7895. }
  7896. toSchema() {
  7897. return (new asn1js.Sequence({
  7898. value: [
  7899. this.acinfo.toSchema(),
  7900. this.signatureAlgorithm.toSchema(),
  7901. this.signatureValue
  7902. ]
  7903. }));
  7904. }
  7905. toJSON() {
  7906. return {
  7907. acinfo: this.acinfo.toJSON(),
  7908. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  7909. signatureValue: this.signatureValue.toJSON(),
  7910. };
  7911. }
  7912. }
  7913. AttributeCertificateV1.CLASS_NAME = "AttributeCertificateV1";
  7914. const DIGESTED_OBJECT_TYPE = "digestedObjectType";
  7915. const OTHER_OBJECT_TYPE_ID = "otherObjectTypeID";
  7916. const DIGEST_ALGORITHM$2 = "digestAlgorithm";
  7917. const OBJECT_DIGEST = "objectDigest";
  7918. const CLEAR_PROPS$X = [
  7919. DIGESTED_OBJECT_TYPE,
  7920. OTHER_OBJECT_TYPE_ID,
  7921. DIGEST_ALGORITHM$2,
  7922. OBJECT_DIGEST,
  7923. ];
  7924. class ObjectDigestInfo extends PkiObject {
  7925. constructor(parameters = {}) {
  7926. super();
  7927. this.digestedObjectType = pvutils.getParametersValue(parameters, DIGESTED_OBJECT_TYPE, ObjectDigestInfo.defaultValues(DIGESTED_OBJECT_TYPE));
  7928. if (OTHER_OBJECT_TYPE_ID in parameters) {
  7929. this.otherObjectTypeID = pvutils.getParametersValue(parameters, OTHER_OBJECT_TYPE_ID, ObjectDigestInfo.defaultValues(OTHER_OBJECT_TYPE_ID));
  7930. }
  7931. this.digestAlgorithm = pvutils.getParametersValue(parameters, DIGEST_ALGORITHM$2, ObjectDigestInfo.defaultValues(DIGEST_ALGORITHM$2));
  7932. this.objectDigest = pvutils.getParametersValue(parameters, OBJECT_DIGEST, ObjectDigestInfo.defaultValues(OBJECT_DIGEST));
  7933. if (parameters.schema) {
  7934. this.fromSchema(parameters.schema);
  7935. }
  7936. }
  7937. static defaultValues(memberName) {
  7938. switch (memberName) {
  7939. case DIGESTED_OBJECT_TYPE:
  7940. return new asn1js.Enumerated();
  7941. case OTHER_OBJECT_TYPE_ID:
  7942. return new asn1js.ObjectIdentifier();
  7943. case DIGEST_ALGORITHM$2:
  7944. return new AlgorithmIdentifier();
  7945. case OBJECT_DIGEST:
  7946. return new asn1js.BitString();
  7947. default:
  7948. return super.defaultValues(memberName);
  7949. }
  7950. }
  7951. static schema(parameters = {}) {
  7952. const names = pvutils.getParametersValue(parameters, "names", {});
  7953. return (new asn1js.Sequence({
  7954. name: (names.blockName || EMPTY_STRING),
  7955. value: [
  7956. new asn1js.Enumerated({ name: (names.digestedObjectType || EMPTY_STRING) }),
  7957. new asn1js.ObjectIdentifier({
  7958. optional: true,
  7959. name: (names.otherObjectTypeID || EMPTY_STRING)
  7960. }),
  7961. AlgorithmIdentifier.schema(names.digestAlgorithm || {}),
  7962. new asn1js.BitString({ name: (names.objectDigest || EMPTY_STRING) }),
  7963. ]
  7964. }));
  7965. }
  7966. fromSchema(schema) {
  7967. pvutils.clearProps(schema, CLEAR_PROPS$X);
  7968. const asn1 = asn1js.compareSchema(schema, schema, ObjectDigestInfo.schema({
  7969. names: {
  7970. digestedObjectType: DIGESTED_OBJECT_TYPE,
  7971. otherObjectTypeID: OTHER_OBJECT_TYPE_ID,
  7972. digestAlgorithm: {
  7973. names: {
  7974. blockName: DIGEST_ALGORITHM$2
  7975. }
  7976. },
  7977. objectDigest: OBJECT_DIGEST
  7978. }
  7979. }));
  7980. AsnError.assertSchema(asn1, this.className);
  7981. this.digestedObjectType = asn1.result.digestedObjectType;
  7982. if (OTHER_OBJECT_TYPE_ID in asn1.result) {
  7983. this.otherObjectTypeID = asn1.result.otherObjectTypeID;
  7984. }
  7985. this.digestAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.digestAlgorithm });
  7986. this.objectDigest = asn1.result.objectDigest;
  7987. }
  7988. toSchema() {
  7989. const result = new asn1js.Sequence({
  7990. value: [this.digestedObjectType]
  7991. });
  7992. if (this.otherObjectTypeID) {
  7993. result.valueBlock.value.push(this.otherObjectTypeID);
  7994. }
  7995. result.valueBlock.value.push(this.digestAlgorithm.toSchema());
  7996. result.valueBlock.value.push(this.objectDigest);
  7997. return result;
  7998. }
  7999. toJSON() {
  8000. const result = {
  8001. digestedObjectType: this.digestedObjectType.toJSON(),
  8002. digestAlgorithm: this.digestAlgorithm.toJSON(),
  8003. objectDigest: this.objectDigest.toJSON(),
  8004. };
  8005. if (this.otherObjectTypeID) {
  8006. result.otherObjectTypeID = this.otherObjectTypeID.toJSON();
  8007. }
  8008. return result;
  8009. }
  8010. }
  8011. ObjectDigestInfo.CLASS_NAME = "ObjectDigestInfo";
  8012. const ISSUER_NAME = "issuerName";
  8013. const BASE_CERTIFICATE_ID$1 = "baseCertificateID";
  8014. const OBJECT_DIGEST_INFO$1 = "objectDigestInfo";
  8015. const CLEAR_PROPS$W = [
  8016. ISSUER_NAME,
  8017. BASE_CERTIFICATE_ID$1,
  8018. OBJECT_DIGEST_INFO$1
  8019. ];
  8020. class V2Form extends PkiObject {
  8021. constructor(parameters = {}) {
  8022. super();
  8023. if (ISSUER_NAME in parameters) {
  8024. this.issuerName = pvutils.getParametersValue(parameters, ISSUER_NAME, V2Form.defaultValues(ISSUER_NAME));
  8025. }
  8026. if (BASE_CERTIFICATE_ID$1 in parameters) {
  8027. this.baseCertificateID = pvutils.getParametersValue(parameters, BASE_CERTIFICATE_ID$1, V2Form.defaultValues(BASE_CERTIFICATE_ID$1));
  8028. }
  8029. if (OBJECT_DIGEST_INFO$1 in parameters) {
  8030. this.objectDigestInfo = pvutils.getParametersValue(parameters, OBJECT_DIGEST_INFO$1, V2Form.defaultValues(OBJECT_DIGEST_INFO$1));
  8031. }
  8032. if (parameters.schema) {
  8033. this.fromSchema(parameters.schema);
  8034. }
  8035. }
  8036. static defaultValues(memberName) {
  8037. switch (memberName) {
  8038. case ISSUER_NAME:
  8039. return new GeneralNames();
  8040. case BASE_CERTIFICATE_ID$1:
  8041. return new IssuerSerial();
  8042. case OBJECT_DIGEST_INFO$1:
  8043. return new ObjectDigestInfo();
  8044. default:
  8045. return super.defaultValues(memberName);
  8046. }
  8047. }
  8048. static schema(parameters = {}) {
  8049. const names = pvutils.getParametersValue(parameters, "names", {});
  8050. return (new asn1js.Sequence({
  8051. name: (names.blockName || EMPTY_STRING),
  8052. value: [
  8053. GeneralNames.schema({
  8054. names: {
  8055. blockName: names.issuerName
  8056. }
  8057. }, true),
  8058. new asn1js.Constructed({
  8059. optional: true,
  8060. name: (names.baseCertificateID || EMPTY_STRING),
  8061. idBlock: {
  8062. tagClass: 3,
  8063. tagNumber: 0
  8064. },
  8065. value: IssuerSerial.schema().valueBlock.value
  8066. }),
  8067. new asn1js.Constructed({
  8068. optional: true,
  8069. name: (names.objectDigestInfo || EMPTY_STRING),
  8070. idBlock: {
  8071. tagClass: 3,
  8072. tagNumber: 1
  8073. },
  8074. value: ObjectDigestInfo.schema().valueBlock.value
  8075. })
  8076. ]
  8077. }));
  8078. }
  8079. fromSchema(schema) {
  8080. pvutils.clearProps(schema, CLEAR_PROPS$W);
  8081. const asn1 = asn1js.compareSchema(schema, schema, V2Form.schema({
  8082. names: {
  8083. issuerName: ISSUER_NAME,
  8084. baseCertificateID: BASE_CERTIFICATE_ID$1,
  8085. objectDigestInfo: OBJECT_DIGEST_INFO$1
  8086. }
  8087. }));
  8088. AsnError.assertSchema(asn1, this.className);
  8089. if (ISSUER_NAME in asn1.result)
  8090. this.issuerName = new GeneralNames({ schema: asn1.result.issuerName });
  8091. if (BASE_CERTIFICATE_ID$1 in asn1.result) {
  8092. this.baseCertificateID = new IssuerSerial({
  8093. schema: new asn1js.Sequence({
  8094. value: asn1.result.baseCertificateID.valueBlock.value
  8095. })
  8096. });
  8097. }
  8098. if (OBJECT_DIGEST_INFO$1 in asn1.result) {
  8099. this.objectDigestInfo = new ObjectDigestInfo({
  8100. schema: new asn1js.Sequence({
  8101. value: asn1.result.objectDigestInfo.valueBlock.value
  8102. })
  8103. });
  8104. }
  8105. }
  8106. toSchema() {
  8107. const result = new asn1js.Sequence();
  8108. if (this.issuerName)
  8109. result.valueBlock.value.push(this.issuerName.toSchema());
  8110. if (this.baseCertificateID) {
  8111. result.valueBlock.value.push(new asn1js.Constructed({
  8112. idBlock: {
  8113. tagClass: 3,
  8114. tagNumber: 0
  8115. },
  8116. value: this.baseCertificateID.toSchema().valueBlock.value
  8117. }));
  8118. }
  8119. if (this.objectDigestInfo) {
  8120. result.valueBlock.value.push(new asn1js.Constructed({
  8121. idBlock: {
  8122. tagClass: 3,
  8123. tagNumber: 1
  8124. },
  8125. value: this.objectDigestInfo.toSchema().valueBlock.value
  8126. }));
  8127. }
  8128. return result;
  8129. }
  8130. toJSON() {
  8131. const result = {};
  8132. if (this.issuerName) {
  8133. result.issuerName = this.issuerName.toJSON();
  8134. }
  8135. if (this.baseCertificateID) {
  8136. result.baseCertificateID = this.baseCertificateID.toJSON();
  8137. }
  8138. if (this.objectDigestInfo) {
  8139. result.objectDigestInfo = this.objectDigestInfo.toJSON();
  8140. }
  8141. return result;
  8142. }
  8143. }
  8144. V2Form.CLASS_NAME = "V2Form";
  8145. const BASE_CERTIFICATE_ID = "baseCertificateID";
  8146. const ENTITY_NAME = "entityName";
  8147. const OBJECT_DIGEST_INFO = "objectDigestInfo";
  8148. const CLEAR_PROPS$V = [
  8149. BASE_CERTIFICATE_ID,
  8150. ENTITY_NAME,
  8151. OBJECT_DIGEST_INFO
  8152. ];
  8153. class Holder extends PkiObject {
  8154. constructor(parameters = {}) {
  8155. super();
  8156. if (BASE_CERTIFICATE_ID in parameters) {
  8157. this.baseCertificateID = pvutils.getParametersValue(parameters, BASE_CERTIFICATE_ID, Holder.defaultValues(BASE_CERTIFICATE_ID));
  8158. }
  8159. if (ENTITY_NAME in parameters) {
  8160. this.entityName = pvutils.getParametersValue(parameters, ENTITY_NAME, Holder.defaultValues(ENTITY_NAME));
  8161. }
  8162. if (OBJECT_DIGEST_INFO in parameters) {
  8163. this.objectDigestInfo = pvutils.getParametersValue(parameters, OBJECT_DIGEST_INFO, Holder.defaultValues(OBJECT_DIGEST_INFO));
  8164. }
  8165. if (parameters.schema) {
  8166. this.fromSchema(parameters.schema);
  8167. }
  8168. }
  8169. static defaultValues(memberName) {
  8170. switch (memberName) {
  8171. case BASE_CERTIFICATE_ID:
  8172. return new IssuerSerial();
  8173. case ENTITY_NAME:
  8174. return new GeneralNames();
  8175. case OBJECT_DIGEST_INFO:
  8176. return new ObjectDigestInfo();
  8177. default:
  8178. return super.defaultValues(memberName);
  8179. }
  8180. }
  8181. static schema(parameters = {}) {
  8182. const names = pvutils.getParametersValue(parameters, "names", {});
  8183. return (new asn1js.Sequence({
  8184. name: (names.blockName || EMPTY_STRING),
  8185. value: [
  8186. new asn1js.Constructed({
  8187. optional: true,
  8188. name: (names.baseCertificateID || EMPTY_STRING),
  8189. idBlock: {
  8190. tagClass: 3,
  8191. tagNumber: 0
  8192. },
  8193. value: IssuerSerial.schema().valueBlock.value
  8194. }),
  8195. new asn1js.Constructed({
  8196. optional: true,
  8197. name: (names.entityName || EMPTY_STRING),
  8198. idBlock: {
  8199. tagClass: 3,
  8200. tagNumber: 1
  8201. },
  8202. value: GeneralNames.schema().valueBlock.value
  8203. }),
  8204. new asn1js.Constructed({
  8205. optional: true,
  8206. name: (names.objectDigestInfo || EMPTY_STRING),
  8207. idBlock: {
  8208. tagClass: 3,
  8209. tagNumber: 2
  8210. },
  8211. value: ObjectDigestInfo.schema().valueBlock.value
  8212. })
  8213. ]
  8214. }));
  8215. }
  8216. fromSchema(schema) {
  8217. pvutils.clearProps(schema, CLEAR_PROPS$V);
  8218. const asn1 = asn1js.compareSchema(schema, schema, Holder.schema({
  8219. names: {
  8220. baseCertificateID: BASE_CERTIFICATE_ID,
  8221. entityName: ENTITY_NAME,
  8222. objectDigestInfo: OBJECT_DIGEST_INFO
  8223. }
  8224. }));
  8225. AsnError.assertSchema(asn1, this.className);
  8226. if (BASE_CERTIFICATE_ID in asn1.result) {
  8227. this.baseCertificateID = new IssuerSerial({
  8228. schema: new asn1js.Sequence({
  8229. value: asn1.result.baseCertificateID.valueBlock.value
  8230. })
  8231. });
  8232. }
  8233. if (ENTITY_NAME in asn1.result) {
  8234. this.entityName = new GeneralNames({
  8235. schema: new asn1js.Sequence({
  8236. value: asn1.result.entityName.valueBlock.value
  8237. })
  8238. });
  8239. }
  8240. if (OBJECT_DIGEST_INFO in asn1.result) {
  8241. this.objectDigestInfo = new ObjectDigestInfo({
  8242. schema: new asn1js.Sequence({
  8243. value: asn1.result.objectDigestInfo.valueBlock.value
  8244. })
  8245. });
  8246. }
  8247. }
  8248. toSchema() {
  8249. const result = new asn1js.Sequence();
  8250. if (this.baseCertificateID) {
  8251. result.valueBlock.value.push(new asn1js.Constructed({
  8252. idBlock: {
  8253. tagClass: 3,
  8254. tagNumber: 0
  8255. },
  8256. value: this.baseCertificateID.toSchema().valueBlock.value
  8257. }));
  8258. }
  8259. if (this.entityName) {
  8260. result.valueBlock.value.push(new asn1js.Constructed({
  8261. idBlock: {
  8262. tagClass: 3,
  8263. tagNumber: 1
  8264. },
  8265. value: this.entityName.toSchema().valueBlock.value
  8266. }));
  8267. }
  8268. if (this.objectDigestInfo) {
  8269. result.valueBlock.value.push(new asn1js.Constructed({
  8270. idBlock: {
  8271. tagClass: 3,
  8272. tagNumber: 2
  8273. },
  8274. value: this.objectDigestInfo.toSchema().valueBlock.value
  8275. }));
  8276. }
  8277. return result;
  8278. }
  8279. toJSON() {
  8280. const result = {};
  8281. if (this.baseCertificateID) {
  8282. result.baseCertificateID = this.baseCertificateID.toJSON();
  8283. }
  8284. if (this.entityName) {
  8285. result.entityName = this.entityName.toJSON();
  8286. }
  8287. if (this.objectDigestInfo) {
  8288. result.objectDigestInfo = this.objectDigestInfo.toJSON();
  8289. }
  8290. return result;
  8291. }
  8292. }
  8293. Holder.CLASS_NAME = "Holder";
  8294. const VERSION$g = "version";
  8295. const HOLDER = "holder";
  8296. const ISSUER$3 = "issuer";
  8297. const SIGNATURE$5 = "signature";
  8298. const SERIAL_NUMBER$4 = "serialNumber";
  8299. const ATTR_CERT_VALIDITY_PERIOD = "attrCertValidityPeriod";
  8300. const ATTRIBUTES$2 = "attributes";
  8301. const ISSUER_UNIQUE_ID$1 = "issuerUniqueID";
  8302. const EXTENSIONS$3 = "extensions";
  8303. const CLEAR_PROPS$U = [
  8304. VERSION$g,
  8305. HOLDER,
  8306. ISSUER$3,
  8307. SIGNATURE$5,
  8308. SERIAL_NUMBER$4,
  8309. ATTR_CERT_VALIDITY_PERIOD,
  8310. ATTRIBUTES$2,
  8311. ISSUER_UNIQUE_ID$1,
  8312. EXTENSIONS$3
  8313. ];
  8314. class AttributeCertificateInfoV2 extends PkiObject {
  8315. constructor(parameters = {}) {
  8316. super();
  8317. this.version = pvutils.getParametersValue(parameters, VERSION$g, AttributeCertificateInfoV2.defaultValues(VERSION$g));
  8318. this.holder = pvutils.getParametersValue(parameters, HOLDER, AttributeCertificateInfoV2.defaultValues(HOLDER));
  8319. this.issuer = pvutils.getParametersValue(parameters, ISSUER$3, AttributeCertificateInfoV2.defaultValues(ISSUER$3));
  8320. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$5, AttributeCertificateInfoV2.defaultValues(SIGNATURE$5));
  8321. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$4, AttributeCertificateInfoV2.defaultValues(SERIAL_NUMBER$4));
  8322. this.attrCertValidityPeriod = pvutils.getParametersValue(parameters, ATTR_CERT_VALIDITY_PERIOD, AttributeCertificateInfoV2.defaultValues(ATTR_CERT_VALIDITY_PERIOD));
  8323. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES$2, AttributeCertificateInfoV2.defaultValues(ATTRIBUTES$2));
  8324. if (ISSUER_UNIQUE_ID$1 in parameters) {
  8325. this.issuerUniqueID = pvutils.getParametersValue(parameters, ISSUER_UNIQUE_ID$1, AttributeCertificateInfoV2.defaultValues(ISSUER_UNIQUE_ID$1));
  8326. }
  8327. if (EXTENSIONS$3 in parameters) {
  8328. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$3, AttributeCertificateInfoV2.defaultValues(EXTENSIONS$3));
  8329. }
  8330. if (parameters.schema) {
  8331. this.fromSchema(parameters.schema);
  8332. }
  8333. }
  8334. static defaultValues(memberName) {
  8335. switch (memberName) {
  8336. case VERSION$g:
  8337. return 1;
  8338. case HOLDER:
  8339. return new Holder();
  8340. case ISSUER$3:
  8341. return {};
  8342. case SIGNATURE$5:
  8343. return new AlgorithmIdentifier();
  8344. case SERIAL_NUMBER$4:
  8345. return new asn1js.Integer();
  8346. case ATTR_CERT_VALIDITY_PERIOD:
  8347. return new AttCertValidityPeriod();
  8348. case ATTRIBUTES$2:
  8349. return [];
  8350. case ISSUER_UNIQUE_ID$1:
  8351. return new asn1js.BitString();
  8352. case EXTENSIONS$3:
  8353. return new Extensions();
  8354. default:
  8355. return super.defaultValues(memberName);
  8356. }
  8357. }
  8358. static schema(parameters = {}) {
  8359. const names = pvutils.getParametersValue(parameters, "names", {});
  8360. return (new asn1js.Sequence({
  8361. name: (names.blockName || EMPTY_STRING),
  8362. value: [
  8363. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  8364. Holder.schema(names.holder || {}),
  8365. new asn1js.Choice({
  8366. value: [
  8367. GeneralNames.schema({
  8368. names: {
  8369. blockName: (names.issuer || EMPTY_STRING)
  8370. }
  8371. }),
  8372. new asn1js.Constructed({
  8373. name: (names.issuer || EMPTY_STRING),
  8374. idBlock: {
  8375. tagClass: 3,
  8376. tagNumber: 0
  8377. },
  8378. value: V2Form.schema().valueBlock.value
  8379. })
  8380. ]
  8381. }),
  8382. AlgorithmIdentifier.schema(names.signature || {}),
  8383. new asn1js.Integer({ name: (names.serialNumber || EMPTY_STRING) }),
  8384. AttCertValidityPeriod.schema(names.attrCertValidityPeriod || {}),
  8385. new asn1js.Sequence({
  8386. name: (names.attributes || EMPTY_STRING),
  8387. value: [
  8388. new asn1js.Repeated({
  8389. value: Attribute.schema()
  8390. })
  8391. ]
  8392. }),
  8393. new asn1js.BitString({
  8394. optional: true,
  8395. name: (names.issuerUniqueID || EMPTY_STRING)
  8396. }),
  8397. Extensions.schema(names.extensions || {}, true)
  8398. ]
  8399. }));
  8400. }
  8401. fromSchema(schema) {
  8402. pvutils.clearProps(schema, CLEAR_PROPS$U);
  8403. const asn1 = asn1js.compareSchema(schema, schema, AttributeCertificateInfoV2.schema({
  8404. names: {
  8405. version: VERSION$g,
  8406. holder: {
  8407. names: {
  8408. blockName: HOLDER
  8409. }
  8410. },
  8411. issuer: ISSUER$3,
  8412. signature: {
  8413. names: {
  8414. blockName: SIGNATURE$5
  8415. }
  8416. },
  8417. serialNumber: SERIAL_NUMBER$4,
  8418. attrCertValidityPeriod: {
  8419. names: {
  8420. blockName: ATTR_CERT_VALIDITY_PERIOD
  8421. }
  8422. },
  8423. attributes: ATTRIBUTES$2,
  8424. issuerUniqueID: ISSUER_UNIQUE_ID$1,
  8425. extensions: {
  8426. names: {
  8427. blockName: EXTENSIONS$3
  8428. }
  8429. }
  8430. }
  8431. }));
  8432. AsnError.assertSchema(asn1, this.className);
  8433. this.version = asn1.result.version.valueBlock.valueDec;
  8434. this.holder = new Holder({ schema: asn1.result.holder });
  8435. switch (asn1.result.issuer.idBlock.tagClass) {
  8436. case 3:
  8437. this.issuer = new V2Form({
  8438. schema: new asn1js.Sequence({
  8439. value: asn1.result.issuer.valueBlock.value
  8440. })
  8441. });
  8442. break;
  8443. case 1:
  8444. default:
  8445. throw new Error("Incorrect value for 'issuer' in AttributeCertificateInfoV2");
  8446. }
  8447. this.signature = new AlgorithmIdentifier({ schema: asn1.result.signature });
  8448. this.serialNumber = asn1.result.serialNumber;
  8449. this.attrCertValidityPeriod = new AttCertValidityPeriod({ schema: asn1.result.attrCertValidityPeriod });
  8450. this.attributes = Array.from(asn1.result.attributes.valueBlock.value, element => new Attribute({ schema: element }));
  8451. if (ISSUER_UNIQUE_ID$1 in asn1.result) {
  8452. this.issuerUniqueID = asn1.result.issuerUniqueID;
  8453. }
  8454. if (EXTENSIONS$3 in asn1.result) {
  8455. this.extensions = new Extensions({ schema: asn1.result.extensions });
  8456. }
  8457. }
  8458. toSchema() {
  8459. const result = new asn1js.Sequence({
  8460. value: [
  8461. new asn1js.Integer({ value: this.version }),
  8462. this.holder.toSchema(),
  8463. new asn1js.Constructed({
  8464. idBlock: {
  8465. tagClass: 3,
  8466. tagNumber: 0
  8467. },
  8468. value: this.issuer.toSchema().valueBlock.value
  8469. }),
  8470. this.signature.toSchema(),
  8471. this.serialNumber,
  8472. this.attrCertValidityPeriod.toSchema(),
  8473. new asn1js.Sequence({
  8474. value: Array.from(this.attributes, o => o.toSchema())
  8475. })
  8476. ]
  8477. });
  8478. if (this.issuerUniqueID) {
  8479. result.valueBlock.value.push(this.issuerUniqueID);
  8480. }
  8481. if (this.extensions) {
  8482. result.valueBlock.value.push(this.extensions.toSchema());
  8483. }
  8484. return result;
  8485. }
  8486. toJSON() {
  8487. const result = {
  8488. version: this.version,
  8489. holder: this.holder.toJSON(),
  8490. issuer: this.issuer.toJSON(),
  8491. signature: this.signature.toJSON(),
  8492. serialNumber: this.serialNumber.toJSON(),
  8493. attrCertValidityPeriod: this.attrCertValidityPeriod.toJSON(),
  8494. attributes: Array.from(this.attributes, o => o.toJSON())
  8495. };
  8496. if (this.issuerUniqueID) {
  8497. result.issuerUniqueID = this.issuerUniqueID.toJSON();
  8498. }
  8499. if (this.extensions) {
  8500. result.extensions = this.extensions.toJSON();
  8501. }
  8502. return result;
  8503. }
  8504. }
  8505. AttributeCertificateInfoV2.CLASS_NAME = "AttributeCertificateInfoV2";
  8506. const ACINFO = "acinfo";
  8507. const SIGNATURE_ALGORITHM$6 = "signatureAlgorithm";
  8508. const SIGNATURE_VALUE$3 = "signatureValue";
  8509. const CLEAR_PROPS$T = [
  8510. ACINFO,
  8511. SIGNATURE_ALGORITHM$6,
  8512. SIGNATURE_VALUE$3,
  8513. ];
  8514. class AttributeCertificateV2 extends PkiObject {
  8515. constructor(parameters = {}) {
  8516. super();
  8517. this.acinfo = pvutils.getParametersValue(parameters, ACINFO, AttributeCertificateV2.defaultValues(ACINFO));
  8518. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$6, AttributeCertificateV2.defaultValues(SIGNATURE_ALGORITHM$6));
  8519. this.signatureValue = pvutils.getParametersValue(parameters, SIGNATURE_VALUE$3, AttributeCertificateV2.defaultValues(SIGNATURE_VALUE$3));
  8520. if (parameters.schema) {
  8521. this.fromSchema(parameters.schema);
  8522. }
  8523. }
  8524. static defaultValues(memberName) {
  8525. switch (memberName) {
  8526. case ACINFO:
  8527. return new AttributeCertificateInfoV2();
  8528. case SIGNATURE_ALGORITHM$6:
  8529. return new AlgorithmIdentifier();
  8530. case SIGNATURE_VALUE$3:
  8531. return new asn1js.BitString();
  8532. default:
  8533. return super.defaultValues(memberName);
  8534. }
  8535. }
  8536. static schema(parameters = {}) {
  8537. const names = pvutils.getParametersValue(parameters, "names", {});
  8538. return (new asn1js.Sequence({
  8539. name: (names.blockName || EMPTY_STRING),
  8540. value: [
  8541. AttributeCertificateInfoV2.schema(names.acinfo || {}),
  8542. AlgorithmIdentifier.schema(names.signatureAlgorithm || {}),
  8543. new asn1js.BitString({ name: (names.signatureValue || EMPTY_STRING) })
  8544. ]
  8545. }));
  8546. }
  8547. fromSchema(schema) {
  8548. pvutils.clearProps(schema, CLEAR_PROPS$T);
  8549. const asn1 = asn1js.compareSchema(schema, schema, AttributeCertificateV2.schema({
  8550. names: {
  8551. acinfo: {
  8552. names: {
  8553. blockName: ACINFO
  8554. }
  8555. },
  8556. signatureAlgorithm: {
  8557. names: {
  8558. blockName: SIGNATURE_ALGORITHM$6
  8559. }
  8560. },
  8561. signatureValue: SIGNATURE_VALUE$3
  8562. }
  8563. }));
  8564. AsnError.assertSchema(asn1, this.className);
  8565. this.acinfo = new AttributeCertificateInfoV2({ schema: asn1.result.acinfo });
  8566. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  8567. this.signatureValue = asn1.result.signatureValue;
  8568. }
  8569. toSchema() {
  8570. return (new asn1js.Sequence({
  8571. value: [
  8572. this.acinfo.toSchema(),
  8573. this.signatureAlgorithm.toSchema(),
  8574. this.signatureValue
  8575. ]
  8576. }));
  8577. }
  8578. toJSON() {
  8579. return {
  8580. acinfo: this.acinfo.toJSON(),
  8581. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  8582. signatureValue: this.signatureValue.toJSON(),
  8583. };
  8584. }
  8585. }
  8586. AttributeCertificateV2.CLASS_NAME = "AttributeCertificateV2";
  8587. const CONTENT_TYPE = "contentType";
  8588. const CONTENT = "content";
  8589. const CLEAR_PROPS$S = [CONTENT_TYPE, CONTENT];
  8590. class ContentInfo extends PkiObject {
  8591. constructor(parameters = {}) {
  8592. super();
  8593. this.contentType = pvutils.getParametersValue(parameters, CONTENT_TYPE, ContentInfo.defaultValues(CONTENT_TYPE));
  8594. this.content = pvutils.getParametersValue(parameters, CONTENT, ContentInfo.defaultValues(CONTENT));
  8595. if (parameters.schema) {
  8596. this.fromSchema(parameters.schema);
  8597. }
  8598. }
  8599. static defaultValues(memberName) {
  8600. switch (memberName) {
  8601. case CONTENT_TYPE:
  8602. return EMPTY_STRING;
  8603. case CONTENT:
  8604. return new asn1js.Any();
  8605. default:
  8606. return super.defaultValues(memberName);
  8607. }
  8608. }
  8609. static compareWithDefault(memberName, memberValue) {
  8610. switch (memberName) {
  8611. case CONTENT_TYPE:
  8612. return (typeof memberValue === "string" &&
  8613. memberValue === this.defaultValues(CONTENT_TYPE));
  8614. case CONTENT:
  8615. return (memberValue instanceof asn1js.Any);
  8616. default:
  8617. return super.defaultValues(memberName);
  8618. }
  8619. }
  8620. static schema(parameters = {}) {
  8621. const names = pvutils.getParametersValue(parameters, "names", {});
  8622. if (("optional" in names) === false) {
  8623. names.optional = false;
  8624. }
  8625. return (new asn1js.Sequence({
  8626. name: (names.blockName || "ContentInfo"),
  8627. optional: names.optional,
  8628. value: [
  8629. new asn1js.ObjectIdentifier({ name: (names.contentType || CONTENT_TYPE) }),
  8630. new asn1js.Constructed({
  8631. idBlock: {
  8632. tagClass: 3,
  8633. tagNumber: 0
  8634. },
  8635. value: [new asn1js.Any({ name: (names.content || CONTENT) })]
  8636. })
  8637. ]
  8638. }));
  8639. }
  8640. fromSchema(schema) {
  8641. pvutils.clearProps(schema, CLEAR_PROPS$S);
  8642. const asn1 = asn1js.compareSchema(schema, schema, ContentInfo.schema());
  8643. AsnError.assertSchema(asn1, this.className);
  8644. this.contentType = asn1.result.contentType.valueBlock.toString();
  8645. this.content = asn1.result.content;
  8646. }
  8647. toSchema() {
  8648. return (new asn1js.Sequence({
  8649. value: [
  8650. new asn1js.ObjectIdentifier({ value: this.contentType }),
  8651. new asn1js.Constructed({
  8652. idBlock: {
  8653. tagClass: 3,
  8654. tagNumber: 0
  8655. },
  8656. value: [this.content]
  8657. })
  8658. ]
  8659. }));
  8660. }
  8661. toJSON() {
  8662. const object = {
  8663. contentType: this.contentType
  8664. };
  8665. if (!(this.content instanceof asn1js.Any)) {
  8666. object.content = this.content.toJSON();
  8667. }
  8668. return object;
  8669. }
  8670. }
  8671. ContentInfo.CLASS_NAME = "ContentInfo";
  8672. ContentInfo.DATA = id_ContentType_Data;
  8673. ContentInfo.SIGNED_DATA = id_ContentType_SignedData;
  8674. ContentInfo.ENVELOPED_DATA = id_ContentType_EnvelopedData;
  8675. ContentInfo.ENCRYPTED_DATA = id_ContentType_EncryptedData;
  8676. const TYPE$1 = "type";
  8677. const VALUE$4 = "value";
  8678. const UTC_TIME_NAME = "utcTimeName";
  8679. const GENERAL_TIME_NAME = "generalTimeName";
  8680. const CLEAR_PROPS$R = [UTC_TIME_NAME, GENERAL_TIME_NAME];
  8681. var TimeType;
  8682. (function (TimeType) {
  8683. TimeType[TimeType["UTCTime"] = 0] = "UTCTime";
  8684. TimeType[TimeType["GeneralizedTime"] = 1] = "GeneralizedTime";
  8685. TimeType[TimeType["empty"] = 2] = "empty";
  8686. })(TimeType || (TimeType = {}));
  8687. class Time extends PkiObject {
  8688. constructor(parameters = {}) {
  8689. super();
  8690. this.type = pvutils.getParametersValue(parameters, TYPE$1, Time.defaultValues(TYPE$1));
  8691. this.value = pvutils.getParametersValue(parameters, VALUE$4, Time.defaultValues(VALUE$4));
  8692. if (parameters.schema) {
  8693. this.fromSchema(parameters.schema);
  8694. }
  8695. }
  8696. static defaultValues(memberName) {
  8697. switch (memberName) {
  8698. case TYPE$1:
  8699. return 0;
  8700. case VALUE$4:
  8701. return new Date(0, 0, 0);
  8702. default:
  8703. return super.defaultValues(memberName);
  8704. }
  8705. }
  8706. static schema(parameters = {}, optional = false) {
  8707. const names = pvutils.getParametersValue(parameters, "names", {});
  8708. return (new asn1js.Choice({
  8709. optional,
  8710. value: [
  8711. new asn1js.UTCTime({ name: (names.utcTimeName || EMPTY_STRING) }),
  8712. new asn1js.GeneralizedTime({ name: (names.generalTimeName || EMPTY_STRING) })
  8713. ]
  8714. }));
  8715. }
  8716. fromSchema(schema) {
  8717. pvutils.clearProps(schema, CLEAR_PROPS$R);
  8718. const asn1 = asn1js.compareSchema(schema, schema, Time.schema({
  8719. names: {
  8720. utcTimeName: UTC_TIME_NAME,
  8721. generalTimeName: GENERAL_TIME_NAME
  8722. }
  8723. }));
  8724. AsnError.assertSchema(asn1, this.className);
  8725. if (UTC_TIME_NAME in asn1.result) {
  8726. this.type = 0;
  8727. this.value = asn1.result.utcTimeName.toDate();
  8728. }
  8729. if (GENERAL_TIME_NAME in asn1.result) {
  8730. this.type = 1;
  8731. this.value = asn1.result.generalTimeName.toDate();
  8732. }
  8733. }
  8734. toSchema() {
  8735. if (this.type === 0) {
  8736. return new asn1js.UTCTime({ valueDate: this.value });
  8737. }
  8738. else if (this.type === 1) {
  8739. return new asn1js.GeneralizedTime({ valueDate: this.value });
  8740. }
  8741. return {};
  8742. }
  8743. toJSON() {
  8744. return {
  8745. type: this.type,
  8746. value: this.value
  8747. };
  8748. }
  8749. }
  8750. Time.CLASS_NAME = "Time";
  8751. const TBS$4 = "tbs";
  8752. const VERSION$f = "version";
  8753. const SERIAL_NUMBER$3 = "serialNumber";
  8754. const SIGNATURE$4 = "signature";
  8755. const ISSUER$2 = "issuer";
  8756. const NOT_BEFORE = "notBefore";
  8757. const NOT_AFTER = "notAfter";
  8758. const SUBJECT$1 = "subject";
  8759. const SUBJECT_PUBLIC_KEY_INFO = "subjectPublicKeyInfo";
  8760. const ISSUER_UNIQUE_ID = "issuerUniqueID";
  8761. const SUBJECT_UNIQUE_ID = "subjectUniqueID";
  8762. const EXTENSIONS$2 = "extensions";
  8763. const SIGNATURE_ALGORITHM$5 = "signatureAlgorithm";
  8764. const SIGNATURE_VALUE$2 = "signatureValue";
  8765. const TBS_CERTIFICATE = "tbsCertificate";
  8766. const TBS_CERTIFICATE_VERSION = `${TBS_CERTIFICATE}.${VERSION$f}`;
  8767. const TBS_CERTIFICATE_SERIAL_NUMBER = `${TBS_CERTIFICATE}.${SERIAL_NUMBER$3}`;
  8768. const TBS_CERTIFICATE_SIGNATURE = `${TBS_CERTIFICATE}.${SIGNATURE$4}`;
  8769. const TBS_CERTIFICATE_ISSUER = `${TBS_CERTIFICATE}.${ISSUER$2}`;
  8770. const TBS_CERTIFICATE_NOT_BEFORE = `${TBS_CERTIFICATE}.${NOT_BEFORE}`;
  8771. const TBS_CERTIFICATE_NOT_AFTER = `${TBS_CERTIFICATE}.${NOT_AFTER}`;
  8772. const TBS_CERTIFICATE_SUBJECT = `${TBS_CERTIFICATE}.${SUBJECT$1}`;
  8773. const TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY = `${TBS_CERTIFICATE}.${SUBJECT_PUBLIC_KEY_INFO}`;
  8774. const TBS_CERTIFICATE_ISSUER_UNIQUE_ID = `${TBS_CERTIFICATE}.${ISSUER_UNIQUE_ID}`;
  8775. const TBS_CERTIFICATE_SUBJECT_UNIQUE_ID = `${TBS_CERTIFICATE}.${SUBJECT_UNIQUE_ID}`;
  8776. const TBS_CERTIFICATE_EXTENSIONS = `${TBS_CERTIFICATE}.${EXTENSIONS$2}`;
  8777. const CLEAR_PROPS$Q = [
  8778. TBS_CERTIFICATE,
  8779. TBS_CERTIFICATE_VERSION,
  8780. TBS_CERTIFICATE_SERIAL_NUMBER,
  8781. TBS_CERTIFICATE_SIGNATURE,
  8782. TBS_CERTIFICATE_ISSUER,
  8783. TBS_CERTIFICATE_NOT_BEFORE,
  8784. TBS_CERTIFICATE_NOT_AFTER,
  8785. TBS_CERTIFICATE_SUBJECT,
  8786. TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY,
  8787. TBS_CERTIFICATE_ISSUER_UNIQUE_ID,
  8788. TBS_CERTIFICATE_SUBJECT_UNIQUE_ID,
  8789. TBS_CERTIFICATE_EXTENSIONS,
  8790. SIGNATURE_ALGORITHM$5,
  8791. SIGNATURE_VALUE$2
  8792. ];
  8793. function tbsCertificate(parameters = {}) {
  8794. const names = pvutils.getParametersValue(parameters, "names", {});
  8795. return (new asn1js.Sequence({
  8796. name: (names.blockName || TBS_CERTIFICATE),
  8797. value: [
  8798. new asn1js.Constructed({
  8799. optional: true,
  8800. idBlock: {
  8801. tagClass: 3,
  8802. tagNumber: 0
  8803. },
  8804. value: [
  8805. new asn1js.Integer({ name: (names.tbsCertificateVersion || TBS_CERTIFICATE_VERSION) })
  8806. ]
  8807. }),
  8808. new asn1js.Integer({ name: (names.tbsCertificateSerialNumber || TBS_CERTIFICATE_SERIAL_NUMBER) }),
  8809. AlgorithmIdentifier.schema(names.signature || {
  8810. names: {
  8811. blockName: TBS_CERTIFICATE_SIGNATURE
  8812. }
  8813. }),
  8814. RelativeDistinguishedNames.schema(names.issuer || {
  8815. names: {
  8816. blockName: TBS_CERTIFICATE_ISSUER
  8817. }
  8818. }),
  8819. new asn1js.Sequence({
  8820. name: (names.tbsCertificateValidity || "tbsCertificate.validity"),
  8821. value: [
  8822. Time.schema(names.notBefore || {
  8823. names: {
  8824. utcTimeName: TBS_CERTIFICATE_NOT_BEFORE,
  8825. generalTimeName: TBS_CERTIFICATE_NOT_BEFORE
  8826. }
  8827. }),
  8828. Time.schema(names.notAfter || {
  8829. names: {
  8830. utcTimeName: TBS_CERTIFICATE_NOT_AFTER,
  8831. generalTimeName: TBS_CERTIFICATE_NOT_AFTER
  8832. }
  8833. })
  8834. ]
  8835. }),
  8836. RelativeDistinguishedNames.schema(names.subject || {
  8837. names: {
  8838. blockName: TBS_CERTIFICATE_SUBJECT
  8839. }
  8840. }),
  8841. PublicKeyInfo.schema(names.subjectPublicKeyInfo || {
  8842. names: {
  8843. blockName: TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY
  8844. }
  8845. }),
  8846. new asn1js.Primitive({
  8847. name: (names.tbsCertificateIssuerUniqueID || TBS_CERTIFICATE_ISSUER_UNIQUE_ID),
  8848. optional: true,
  8849. idBlock: {
  8850. tagClass: 3,
  8851. tagNumber: 1
  8852. }
  8853. }),
  8854. new asn1js.Primitive({
  8855. name: (names.tbsCertificateSubjectUniqueID || TBS_CERTIFICATE_SUBJECT_UNIQUE_ID),
  8856. optional: true,
  8857. idBlock: {
  8858. tagClass: 3,
  8859. tagNumber: 2
  8860. }
  8861. }),
  8862. new asn1js.Constructed({
  8863. optional: true,
  8864. idBlock: {
  8865. tagClass: 3,
  8866. tagNumber: 3
  8867. },
  8868. value: [Extensions.schema(names.extensions || {
  8869. names: {
  8870. blockName: TBS_CERTIFICATE_EXTENSIONS
  8871. }
  8872. })]
  8873. })
  8874. ]
  8875. }));
  8876. }
  8877. class Certificate extends PkiObject {
  8878. get tbs() {
  8879. return pvtsutils.BufferSourceConverter.toArrayBuffer(this.tbsView);
  8880. }
  8881. set tbs(value) {
  8882. this.tbsView = new Uint8Array(value);
  8883. }
  8884. constructor(parameters = {}) {
  8885. super();
  8886. this.tbsView = new Uint8Array(pvutils.getParametersValue(parameters, TBS$4, Certificate.defaultValues(TBS$4)));
  8887. this.version = pvutils.getParametersValue(parameters, VERSION$f, Certificate.defaultValues(VERSION$f));
  8888. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$3, Certificate.defaultValues(SERIAL_NUMBER$3));
  8889. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$4, Certificate.defaultValues(SIGNATURE$4));
  8890. this.issuer = pvutils.getParametersValue(parameters, ISSUER$2, Certificate.defaultValues(ISSUER$2));
  8891. this.notBefore = pvutils.getParametersValue(parameters, NOT_BEFORE, Certificate.defaultValues(NOT_BEFORE));
  8892. this.notAfter = pvutils.getParametersValue(parameters, NOT_AFTER, Certificate.defaultValues(NOT_AFTER));
  8893. this.subject = pvutils.getParametersValue(parameters, SUBJECT$1, Certificate.defaultValues(SUBJECT$1));
  8894. this.subjectPublicKeyInfo = pvutils.getParametersValue(parameters, SUBJECT_PUBLIC_KEY_INFO, Certificate.defaultValues(SUBJECT_PUBLIC_KEY_INFO));
  8895. if (ISSUER_UNIQUE_ID in parameters) {
  8896. this.issuerUniqueID = pvutils.getParametersValue(parameters, ISSUER_UNIQUE_ID, Certificate.defaultValues(ISSUER_UNIQUE_ID));
  8897. }
  8898. if (SUBJECT_UNIQUE_ID in parameters) {
  8899. this.subjectUniqueID = pvutils.getParametersValue(parameters, SUBJECT_UNIQUE_ID, Certificate.defaultValues(SUBJECT_UNIQUE_ID));
  8900. }
  8901. if (EXTENSIONS$2 in parameters) {
  8902. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$2, Certificate.defaultValues(EXTENSIONS$2));
  8903. }
  8904. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$5, Certificate.defaultValues(SIGNATURE_ALGORITHM$5));
  8905. this.signatureValue = pvutils.getParametersValue(parameters, SIGNATURE_VALUE$2, Certificate.defaultValues(SIGNATURE_VALUE$2));
  8906. if (parameters.schema) {
  8907. this.fromSchema(parameters.schema);
  8908. }
  8909. }
  8910. static defaultValues(memberName) {
  8911. switch (memberName) {
  8912. case TBS$4:
  8913. return EMPTY_BUFFER;
  8914. case VERSION$f:
  8915. return 0;
  8916. case SERIAL_NUMBER$3:
  8917. return new asn1js.Integer();
  8918. case SIGNATURE$4:
  8919. return new AlgorithmIdentifier();
  8920. case ISSUER$2:
  8921. return new RelativeDistinguishedNames();
  8922. case NOT_BEFORE:
  8923. return new Time();
  8924. case NOT_AFTER:
  8925. return new Time();
  8926. case SUBJECT$1:
  8927. return new RelativeDistinguishedNames();
  8928. case SUBJECT_PUBLIC_KEY_INFO:
  8929. return new PublicKeyInfo();
  8930. case ISSUER_UNIQUE_ID:
  8931. return EMPTY_BUFFER;
  8932. case SUBJECT_UNIQUE_ID:
  8933. return EMPTY_BUFFER;
  8934. case EXTENSIONS$2:
  8935. return [];
  8936. case SIGNATURE_ALGORITHM$5:
  8937. return new AlgorithmIdentifier();
  8938. case SIGNATURE_VALUE$2:
  8939. return new asn1js.BitString();
  8940. default:
  8941. return super.defaultValues(memberName);
  8942. }
  8943. }
  8944. static schema(parameters = {}) {
  8945. const names = pvutils.getParametersValue(parameters, "names", {});
  8946. return (new asn1js.Sequence({
  8947. name: (names.blockName || EMPTY_STRING),
  8948. value: [
  8949. tbsCertificate(names.tbsCertificate),
  8950. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  8951. names: {
  8952. blockName: SIGNATURE_ALGORITHM$5
  8953. }
  8954. }),
  8955. new asn1js.BitString({ name: (names.signatureValue || SIGNATURE_VALUE$2) })
  8956. ]
  8957. }));
  8958. }
  8959. fromSchema(schema) {
  8960. pvutils.clearProps(schema, CLEAR_PROPS$Q);
  8961. const asn1 = asn1js.compareSchema(schema, schema, Certificate.schema({
  8962. names: {
  8963. tbsCertificate: {
  8964. names: {
  8965. extensions: {
  8966. names: {
  8967. extensions: TBS_CERTIFICATE_EXTENSIONS
  8968. }
  8969. }
  8970. }
  8971. }
  8972. }
  8973. }));
  8974. AsnError.assertSchema(asn1, this.className);
  8975. this.tbsView = asn1.result.tbsCertificate.valueBeforeDecodeView;
  8976. if (TBS_CERTIFICATE_VERSION in asn1.result)
  8977. this.version = asn1.result[TBS_CERTIFICATE_VERSION].valueBlock.valueDec;
  8978. this.serialNumber = asn1.result[TBS_CERTIFICATE_SERIAL_NUMBER];
  8979. this.signature = new AlgorithmIdentifier({ schema: asn1.result[TBS_CERTIFICATE_SIGNATURE] });
  8980. this.issuer = new RelativeDistinguishedNames({ schema: asn1.result[TBS_CERTIFICATE_ISSUER] });
  8981. this.notBefore = new Time({ schema: asn1.result[TBS_CERTIFICATE_NOT_BEFORE] });
  8982. this.notAfter = new Time({ schema: asn1.result[TBS_CERTIFICATE_NOT_AFTER] });
  8983. this.subject = new RelativeDistinguishedNames({ schema: asn1.result[TBS_CERTIFICATE_SUBJECT] });
  8984. this.subjectPublicKeyInfo = new PublicKeyInfo({ schema: asn1.result[TBS_CERTIFICATE_SUBJECT_PUBLIC_KEY] });
  8985. if (TBS_CERTIFICATE_ISSUER_UNIQUE_ID in asn1.result)
  8986. this.issuerUniqueID = asn1.result[TBS_CERTIFICATE_ISSUER_UNIQUE_ID].valueBlock.valueHex;
  8987. if (TBS_CERTIFICATE_SUBJECT_UNIQUE_ID in asn1.result)
  8988. this.subjectUniqueID = asn1.result[TBS_CERTIFICATE_SUBJECT_UNIQUE_ID].valueBlock.valueHex;
  8989. if (TBS_CERTIFICATE_EXTENSIONS in asn1.result)
  8990. this.extensions = Array.from(asn1.result[TBS_CERTIFICATE_EXTENSIONS], element => new Extension({ schema: element }));
  8991. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  8992. this.signatureValue = asn1.result.signatureValue;
  8993. }
  8994. encodeTBS() {
  8995. const outputArray = [];
  8996. if ((VERSION$f in this) && (this.version !== Certificate.defaultValues(VERSION$f))) {
  8997. outputArray.push(new asn1js.Constructed({
  8998. optional: true,
  8999. idBlock: {
  9000. tagClass: 3,
  9001. tagNumber: 0
  9002. },
  9003. value: [
  9004. new asn1js.Integer({ value: this.version })
  9005. ]
  9006. }));
  9007. }
  9008. outputArray.push(this.serialNumber);
  9009. outputArray.push(this.signature.toSchema());
  9010. outputArray.push(this.issuer.toSchema());
  9011. outputArray.push(new asn1js.Sequence({
  9012. value: [
  9013. this.notBefore.toSchema(),
  9014. this.notAfter.toSchema()
  9015. ]
  9016. }));
  9017. outputArray.push(this.subject.toSchema());
  9018. outputArray.push(this.subjectPublicKeyInfo.toSchema());
  9019. if (this.issuerUniqueID) {
  9020. outputArray.push(new asn1js.Primitive({
  9021. optional: true,
  9022. idBlock: {
  9023. tagClass: 3,
  9024. tagNumber: 1
  9025. },
  9026. valueHex: this.issuerUniqueID
  9027. }));
  9028. }
  9029. if (this.subjectUniqueID) {
  9030. outputArray.push(new asn1js.Primitive({
  9031. optional: true,
  9032. idBlock: {
  9033. tagClass: 3,
  9034. tagNumber: 2
  9035. },
  9036. valueHex: this.subjectUniqueID
  9037. }));
  9038. }
  9039. if (this.extensions) {
  9040. outputArray.push(new asn1js.Constructed({
  9041. optional: true,
  9042. idBlock: {
  9043. tagClass: 3,
  9044. tagNumber: 3
  9045. },
  9046. value: [new asn1js.Sequence({
  9047. value: Array.from(this.extensions, o => o.toSchema())
  9048. })]
  9049. }));
  9050. }
  9051. return (new asn1js.Sequence({
  9052. value: outputArray
  9053. }));
  9054. }
  9055. toSchema(encodeFlag = false) {
  9056. let tbsSchema;
  9057. if (encodeFlag === false) {
  9058. if (!this.tbsView.byteLength) {
  9059. return Certificate.schema().value[0];
  9060. }
  9061. const asn1 = asn1js.fromBER(this.tbsView);
  9062. AsnError.assert(asn1, "TBS Certificate");
  9063. tbsSchema = asn1.result;
  9064. }
  9065. else {
  9066. tbsSchema = this.encodeTBS();
  9067. }
  9068. return (new asn1js.Sequence({
  9069. value: [
  9070. tbsSchema,
  9071. this.signatureAlgorithm.toSchema(),
  9072. this.signatureValue
  9073. ]
  9074. }));
  9075. }
  9076. toJSON() {
  9077. const res = {
  9078. tbs: pvtsutils.Convert.ToHex(this.tbsView),
  9079. version: this.version,
  9080. serialNumber: this.serialNumber.toJSON(),
  9081. signature: this.signature.toJSON(),
  9082. issuer: this.issuer.toJSON(),
  9083. notBefore: this.notBefore.toJSON(),
  9084. notAfter: this.notAfter.toJSON(),
  9085. subject: this.subject.toJSON(),
  9086. subjectPublicKeyInfo: this.subjectPublicKeyInfo.toJSON(),
  9087. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  9088. signatureValue: this.signatureValue.toJSON(),
  9089. };
  9090. if ((VERSION$f in this) && (this.version !== Certificate.defaultValues(VERSION$f))) {
  9091. res.version = this.version;
  9092. }
  9093. if (this.issuerUniqueID) {
  9094. res.issuerUniqueID = pvtsutils.Convert.ToHex(this.issuerUniqueID);
  9095. }
  9096. if (this.subjectUniqueID) {
  9097. res.subjectUniqueID = pvtsutils.Convert.ToHex(this.subjectUniqueID);
  9098. }
  9099. if (this.extensions) {
  9100. res.extensions = Array.from(this.extensions, o => o.toJSON());
  9101. }
  9102. return res;
  9103. }
  9104. async getPublicKey(parameters, crypto = getCrypto(true)) {
  9105. return crypto.getPublicKey(this.subjectPublicKeyInfo, this.signatureAlgorithm, parameters);
  9106. }
  9107. async getKeyHash(hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  9108. return crypto.digest({ name: hashAlgorithm }, this.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView);
  9109. }
  9110. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  9111. if (!privateKey) {
  9112. throw new Error("Need to provide a private key for signing");
  9113. }
  9114. const signatureParameters = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  9115. const parameters = signatureParameters.parameters;
  9116. this.signature = signatureParameters.signatureAlgorithm;
  9117. this.signatureAlgorithm = signatureParameters.signatureAlgorithm;
  9118. this.tbsView = new Uint8Array(this.encodeTBS().toBER());
  9119. const signature = await crypto.signWithPrivateKey(this.tbsView, privateKey, parameters);
  9120. this.signatureValue = new asn1js.BitString({ valueHex: signature });
  9121. }
  9122. async verify(issuerCertificate, crypto = getCrypto(true)) {
  9123. let subjectPublicKeyInfo;
  9124. if (issuerCertificate) {
  9125. subjectPublicKeyInfo = issuerCertificate.subjectPublicKeyInfo;
  9126. }
  9127. else if (this.issuer.isEqual(this.subject)) {
  9128. subjectPublicKeyInfo = this.subjectPublicKeyInfo;
  9129. }
  9130. if (!(subjectPublicKeyInfo instanceof PublicKeyInfo)) {
  9131. throw new Error("Please provide issuer certificate as a parameter");
  9132. }
  9133. return crypto.verifyWithPublicKey(this.tbsView, this.signatureValue, subjectPublicKeyInfo, this.signatureAlgorithm);
  9134. }
  9135. }
  9136. Certificate.CLASS_NAME = "Certificate";
  9137. function checkCA(cert, signerCert = null) {
  9138. if (signerCert && cert.issuer.isEqual(signerCert.issuer) && cert.serialNumber.isEqual(signerCert.serialNumber)) {
  9139. return null;
  9140. }
  9141. let isCA = false;
  9142. if (cert.extensions) {
  9143. for (const extension of cert.extensions) {
  9144. if (extension.extnID === id_BasicConstraints && extension.parsedValue instanceof BasicConstraints) {
  9145. if (extension.parsedValue.cA) {
  9146. isCA = true;
  9147. break;
  9148. }
  9149. }
  9150. }
  9151. }
  9152. if (isCA) {
  9153. return cert;
  9154. }
  9155. return null;
  9156. }
  9157. const CERT_ID$1 = "certId";
  9158. const CERT_VALUE = "certValue";
  9159. const PARSED_VALUE$4 = "parsedValue";
  9160. const CLEAR_PROPS$P = [
  9161. CERT_ID$1,
  9162. CERT_VALUE
  9163. ];
  9164. class CertBag extends PkiObject {
  9165. constructor(parameters = {}) {
  9166. super();
  9167. this.certId = pvutils.getParametersValue(parameters, CERT_ID$1, CertBag.defaultValues(CERT_ID$1));
  9168. this.certValue = pvutils.getParametersValue(parameters, CERT_VALUE, CertBag.defaultValues(CERT_VALUE));
  9169. if (PARSED_VALUE$4 in parameters) {
  9170. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE$4, CertBag.defaultValues(PARSED_VALUE$4));
  9171. }
  9172. if (parameters.schema) {
  9173. this.fromSchema(parameters.schema);
  9174. }
  9175. }
  9176. static defaultValues(memberName) {
  9177. switch (memberName) {
  9178. case CERT_ID$1:
  9179. return EMPTY_STRING;
  9180. case CERT_VALUE:
  9181. return (new asn1js.Any());
  9182. case PARSED_VALUE$4:
  9183. return {};
  9184. default:
  9185. return super.defaultValues(memberName);
  9186. }
  9187. }
  9188. static compareWithDefault(memberName, memberValue) {
  9189. switch (memberName) {
  9190. case CERT_ID$1:
  9191. return (memberValue === EMPTY_STRING);
  9192. case CERT_VALUE:
  9193. return (memberValue instanceof asn1js.Any);
  9194. case PARSED_VALUE$4:
  9195. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  9196. default:
  9197. return super.defaultValues(memberName);
  9198. }
  9199. }
  9200. static schema(parameters = {}) {
  9201. const names = pvutils.getParametersValue(parameters, "names", {});
  9202. return (new asn1js.Sequence({
  9203. name: (names.blockName || EMPTY_STRING),
  9204. value: [
  9205. new asn1js.ObjectIdentifier({ name: (names.id || "id") }),
  9206. new asn1js.Constructed({
  9207. idBlock: {
  9208. tagClass: 3,
  9209. tagNumber: 0
  9210. },
  9211. value: [new asn1js.Any({ name: (names.value || "value") })]
  9212. })
  9213. ]
  9214. }));
  9215. }
  9216. fromSchema(schema) {
  9217. pvutils.clearProps(schema, CLEAR_PROPS$P);
  9218. const asn1 = asn1js.compareSchema(schema, schema, CertBag.schema({
  9219. names: {
  9220. id: CERT_ID$1,
  9221. value: CERT_VALUE
  9222. }
  9223. }));
  9224. AsnError.assertSchema(asn1, this.className);
  9225. this.certId = asn1.result.certId.valueBlock.toString();
  9226. this.certValue = asn1.result.certValue;
  9227. const certValueHex = this.certValue.valueBlock.valueHexView;
  9228. switch (this.certId) {
  9229. case id_CertBag_X509Certificate:
  9230. {
  9231. try {
  9232. this.parsedValue = Certificate.fromBER(certValueHex);
  9233. }
  9234. catch {
  9235. AttributeCertificateV2.fromBER(certValueHex);
  9236. }
  9237. }
  9238. break;
  9239. case id_CertBag_AttributeCertificate:
  9240. {
  9241. this.parsedValue = AttributeCertificateV2.fromBER(certValueHex);
  9242. }
  9243. break;
  9244. case id_CertBag_SDSICertificate:
  9245. default:
  9246. throw new Error(`Incorrect CERT_ID value in CertBag: ${this.certId}`);
  9247. }
  9248. }
  9249. toSchema() {
  9250. if (PARSED_VALUE$4 in this) {
  9251. if ("acinfo" in this.parsedValue) {
  9252. this.certId = id_CertBag_AttributeCertificate;
  9253. }
  9254. else {
  9255. this.certId = id_CertBag_X509Certificate;
  9256. }
  9257. this.certValue = new asn1js.OctetString({ valueHex: this.parsedValue.toSchema().toBER(false) });
  9258. }
  9259. return (new asn1js.Sequence({
  9260. value: [
  9261. new asn1js.ObjectIdentifier({ value: this.certId }),
  9262. new asn1js.Constructed({
  9263. idBlock: {
  9264. tagClass: 3,
  9265. tagNumber: 0
  9266. },
  9267. value: [(("toSchema" in this.certValue) ? this.certValue.toSchema() : this.certValue)]
  9268. })
  9269. ]
  9270. }));
  9271. }
  9272. toJSON() {
  9273. return {
  9274. certId: this.certId,
  9275. certValue: this.certValue.toJSON()
  9276. };
  9277. }
  9278. }
  9279. CertBag.CLASS_NAME = "CertBag";
  9280. const USER_CERTIFICATE = "userCertificate";
  9281. const REVOCATION_DATE = "revocationDate";
  9282. const CRL_ENTRY_EXTENSIONS = "crlEntryExtensions";
  9283. const CLEAR_PROPS$O = [
  9284. USER_CERTIFICATE,
  9285. REVOCATION_DATE,
  9286. CRL_ENTRY_EXTENSIONS
  9287. ];
  9288. class RevokedCertificate extends PkiObject {
  9289. constructor(parameters = {}) {
  9290. super();
  9291. this.userCertificate = pvutils.getParametersValue(parameters, USER_CERTIFICATE, RevokedCertificate.defaultValues(USER_CERTIFICATE));
  9292. this.revocationDate = pvutils.getParametersValue(parameters, REVOCATION_DATE, RevokedCertificate.defaultValues(REVOCATION_DATE));
  9293. if (CRL_ENTRY_EXTENSIONS in parameters) {
  9294. this.crlEntryExtensions = pvutils.getParametersValue(parameters, CRL_ENTRY_EXTENSIONS, RevokedCertificate.defaultValues(CRL_ENTRY_EXTENSIONS));
  9295. }
  9296. if (parameters.schema) {
  9297. this.fromSchema(parameters.schema);
  9298. }
  9299. }
  9300. static defaultValues(memberName) {
  9301. switch (memberName) {
  9302. case USER_CERTIFICATE:
  9303. return new asn1js.Integer();
  9304. case REVOCATION_DATE:
  9305. return new Time();
  9306. case CRL_ENTRY_EXTENSIONS:
  9307. return new Extensions();
  9308. default:
  9309. return super.defaultValues(memberName);
  9310. }
  9311. }
  9312. static schema(parameters = {}) {
  9313. const names = pvutils.getParametersValue(parameters, "names", {});
  9314. return new asn1js.Sequence({
  9315. name: (names.blockName || EMPTY_STRING),
  9316. value: [
  9317. new asn1js.Integer({ name: (names.userCertificate || USER_CERTIFICATE) }),
  9318. Time.schema({
  9319. names: {
  9320. utcTimeName: (names.revocationDate || REVOCATION_DATE),
  9321. generalTimeName: (names.revocationDate || REVOCATION_DATE)
  9322. }
  9323. }),
  9324. Extensions.schema({
  9325. names: {
  9326. blockName: (names.crlEntryExtensions || CRL_ENTRY_EXTENSIONS)
  9327. }
  9328. }, true)
  9329. ]
  9330. });
  9331. }
  9332. fromSchema(schema) {
  9333. pvutils.clearProps(schema, CLEAR_PROPS$O);
  9334. const asn1 = asn1js.compareSchema(schema, schema, RevokedCertificate.schema());
  9335. AsnError.assertSchema(asn1, this.className);
  9336. this.userCertificate = asn1.result.userCertificate;
  9337. this.revocationDate = new Time({ schema: asn1.result.revocationDate });
  9338. if (CRL_ENTRY_EXTENSIONS in asn1.result) {
  9339. this.crlEntryExtensions = new Extensions({ schema: asn1.result.crlEntryExtensions });
  9340. }
  9341. }
  9342. toSchema() {
  9343. const outputArray = [
  9344. this.userCertificate,
  9345. this.revocationDate.toSchema()
  9346. ];
  9347. if (this.crlEntryExtensions) {
  9348. outputArray.push(this.crlEntryExtensions.toSchema());
  9349. }
  9350. return (new asn1js.Sequence({
  9351. value: outputArray
  9352. }));
  9353. }
  9354. toJSON() {
  9355. const res = {
  9356. userCertificate: this.userCertificate.toJSON(),
  9357. revocationDate: this.revocationDate.toJSON(),
  9358. };
  9359. if (this.crlEntryExtensions) {
  9360. res.crlEntryExtensions = this.crlEntryExtensions.toJSON();
  9361. }
  9362. return res;
  9363. }
  9364. }
  9365. RevokedCertificate.CLASS_NAME = "RevokedCertificate";
  9366. const TBS$3 = "tbs";
  9367. const VERSION$e = "version";
  9368. const SIGNATURE$3 = "signature";
  9369. const ISSUER$1 = "issuer";
  9370. const THIS_UPDATE$1 = "thisUpdate";
  9371. const NEXT_UPDATE$1 = "nextUpdate";
  9372. const REVOKED_CERTIFICATES = "revokedCertificates";
  9373. const CRL_EXTENSIONS = "crlExtensions";
  9374. const SIGNATURE_ALGORITHM$4 = "signatureAlgorithm";
  9375. const SIGNATURE_VALUE$1 = "signatureValue";
  9376. const TBS_CERT_LIST = "tbsCertList";
  9377. const TBS_CERT_LIST_VERSION = `${TBS_CERT_LIST}.version`;
  9378. const TBS_CERT_LIST_SIGNATURE = `${TBS_CERT_LIST}.signature`;
  9379. const TBS_CERT_LIST_ISSUER = `${TBS_CERT_LIST}.issuer`;
  9380. const TBS_CERT_LIST_THIS_UPDATE = `${TBS_CERT_LIST}.thisUpdate`;
  9381. const TBS_CERT_LIST_NEXT_UPDATE = `${TBS_CERT_LIST}.nextUpdate`;
  9382. const TBS_CERT_LIST_REVOKED_CERTIFICATES = `${TBS_CERT_LIST}.revokedCertificates`;
  9383. const TBS_CERT_LIST_EXTENSIONS = `${TBS_CERT_LIST}.extensions`;
  9384. const CLEAR_PROPS$N = [
  9385. TBS_CERT_LIST,
  9386. TBS_CERT_LIST_VERSION,
  9387. TBS_CERT_LIST_SIGNATURE,
  9388. TBS_CERT_LIST_ISSUER,
  9389. TBS_CERT_LIST_THIS_UPDATE,
  9390. TBS_CERT_LIST_NEXT_UPDATE,
  9391. TBS_CERT_LIST_REVOKED_CERTIFICATES,
  9392. TBS_CERT_LIST_EXTENSIONS,
  9393. SIGNATURE_ALGORITHM$4,
  9394. SIGNATURE_VALUE$1
  9395. ];
  9396. function tbsCertList(parameters = {}) {
  9397. const names = pvutils.getParametersValue(parameters, "names", {});
  9398. return (new asn1js.Sequence({
  9399. name: (names.blockName || TBS_CERT_LIST),
  9400. value: [
  9401. new asn1js.Integer({
  9402. optional: true,
  9403. name: (names.tbsCertListVersion || TBS_CERT_LIST_VERSION),
  9404. value: 2
  9405. }),
  9406. AlgorithmIdentifier.schema(names.signature || {
  9407. names: {
  9408. blockName: TBS_CERT_LIST_SIGNATURE
  9409. }
  9410. }),
  9411. RelativeDistinguishedNames.schema(names.issuer || {
  9412. names: {
  9413. blockName: TBS_CERT_LIST_ISSUER
  9414. }
  9415. }),
  9416. Time.schema(names.tbsCertListThisUpdate || {
  9417. names: {
  9418. utcTimeName: TBS_CERT_LIST_THIS_UPDATE,
  9419. generalTimeName: TBS_CERT_LIST_THIS_UPDATE
  9420. }
  9421. }),
  9422. Time.schema(names.tbsCertListNextUpdate || {
  9423. names: {
  9424. utcTimeName: TBS_CERT_LIST_NEXT_UPDATE,
  9425. generalTimeName: TBS_CERT_LIST_NEXT_UPDATE
  9426. }
  9427. }, true),
  9428. new asn1js.Sequence({
  9429. optional: true,
  9430. value: [
  9431. new asn1js.Repeated({
  9432. name: (names.tbsCertListRevokedCertificates || TBS_CERT_LIST_REVOKED_CERTIFICATES),
  9433. value: new asn1js.Sequence({
  9434. value: [
  9435. new asn1js.Integer(),
  9436. Time.schema(),
  9437. Extensions.schema({}, true)
  9438. ]
  9439. })
  9440. })
  9441. ]
  9442. }),
  9443. new asn1js.Constructed({
  9444. optional: true,
  9445. idBlock: {
  9446. tagClass: 3,
  9447. tagNumber: 0
  9448. },
  9449. value: [Extensions.schema(names.crlExtensions || {
  9450. names: {
  9451. blockName: TBS_CERT_LIST_EXTENSIONS
  9452. }
  9453. })]
  9454. })
  9455. ]
  9456. }));
  9457. }
  9458. const WELL_KNOWN_EXTENSIONS = [
  9459. id_AuthorityKeyIdentifier,
  9460. id_IssuerAltName,
  9461. id_CRLNumber,
  9462. id_BaseCRLNumber,
  9463. id_IssuingDistributionPoint,
  9464. id_FreshestCRL,
  9465. id_AuthorityInfoAccess,
  9466. id_CRLReason,
  9467. id_InvalidityDate,
  9468. id_CertificateIssuer,
  9469. ];
  9470. class CertificateRevocationList extends PkiObject {
  9471. get tbs() {
  9472. return pvtsutils.BufferSourceConverter.toArrayBuffer(this.tbsView);
  9473. }
  9474. set tbs(value) {
  9475. this.tbsView = new Uint8Array(value);
  9476. }
  9477. constructor(parameters = {}) {
  9478. super();
  9479. this.tbsView = new Uint8Array(pvutils.getParametersValue(parameters, TBS$3, CertificateRevocationList.defaultValues(TBS$3)));
  9480. this.version = pvutils.getParametersValue(parameters, VERSION$e, CertificateRevocationList.defaultValues(VERSION$e));
  9481. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$3, CertificateRevocationList.defaultValues(SIGNATURE$3));
  9482. this.issuer = pvutils.getParametersValue(parameters, ISSUER$1, CertificateRevocationList.defaultValues(ISSUER$1));
  9483. this.thisUpdate = pvutils.getParametersValue(parameters, THIS_UPDATE$1, CertificateRevocationList.defaultValues(THIS_UPDATE$1));
  9484. if (NEXT_UPDATE$1 in parameters) {
  9485. this.nextUpdate = pvutils.getParametersValue(parameters, NEXT_UPDATE$1, CertificateRevocationList.defaultValues(NEXT_UPDATE$1));
  9486. }
  9487. if (REVOKED_CERTIFICATES in parameters) {
  9488. this.revokedCertificates = pvutils.getParametersValue(parameters, REVOKED_CERTIFICATES, CertificateRevocationList.defaultValues(REVOKED_CERTIFICATES));
  9489. }
  9490. if (CRL_EXTENSIONS in parameters) {
  9491. this.crlExtensions = pvutils.getParametersValue(parameters, CRL_EXTENSIONS, CertificateRevocationList.defaultValues(CRL_EXTENSIONS));
  9492. }
  9493. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$4, CertificateRevocationList.defaultValues(SIGNATURE_ALGORITHM$4));
  9494. this.signatureValue = pvutils.getParametersValue(parameters, SIGNATURE_VALUE$1, CertificateRevocationList.defaultValues(SIGNATURE_VALUE$1));
  9495. if (parameters.schema) {
  9496. this.fromSchema(parameters.schema);
  9497. }
  9498. }
  9499. static defaultValues(memberName) {
  9500. switch (memberName) {
  9501. case TBS$3:
  9502. return EMPTY_BUFFER;
  9503. case VERSION$e:
  9504. return 0;
  9505. case SIGNATURE$3:
  9506. return new AlgorithmIdentifier();
  9507. case ISSUER$1:
  9508. return new RelativeDistinguishedNames();
  9509. case THIS_UPDATE$1:
  9510. return new Time();
  9511. case NEXT_UPDATE$1:
  9512. return new Time();
  9513. case REVOKED_CERTIFICATES:
  9514. return [];
  9515. case CRL_EXTENSIONS:
  9516. return new Extensions();
  9517. case SIGNATURE_ALGORITHM$4:
  9518. return new AlgorithmIdentifier();
  9519. case SIGNATURE_VALUE$1:
  9520. return new asn1js.BitString();
  9521. default:
  9522. return super.defaultValues(memberName);
  9523. }
  9524. }
  9525. static schema(parameters = {}) {
  9526. const names = pvutils.getParametersValue(parameters, "names", {});
  9527. return (new asn1js.Sequence({
  9528. name: (names.blockName || "CertificateList"),
  9529. value: [
  9530. tbsCertList(parameters),
  9531. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  9532. names: {
  9533. blockName: SIGNATURE_ALGORITHM$4
  9534. }
  9535. }),
  9536. new asn1js.BitString({ name: (names.signatureValue || SIGNATURE_VALUE$1) })
  9537. ]
  9538. }));
  9539. }
  9540. fromSchema(schema) {
  9541. pvutils.clearProps(schema, CLEAR_PROPS$N);
  9542. const asn1 = asn1js.compareSchema(schema, schema, CertificateRevocationList.schema());
  9543. AsnError.assertSchema(asn1, this.className);
  9544. this.tbsView = asn1.result.tbsCertList.valueBeforeDecodeView;
  9545. if (TBS_CERT_LIST_VERSION in asn1.result) {
  9546. this.version = asn1.result[TBS_CERT_LIST_VERSION].valueBlock.valueDec;
  9547. }
  9548. this.signature = new AlgorithmIdentifier({ schema: asn1.result[TBS_CERT_LIST_SIGNATURE] });
  9549. this.issuer = new RelativeDistinguishedNames({ schema: asn1.result[TBS_CERT_LIST_ISSUER] });
  9550. this.thisUpdate = new Time({ schema: asn1.result[TBS_CERT_LIST_THIS_UPDATE] });
  9551. if (TBS_CERT_LIST_NEXT_UPDATE in asn1.result) {
  9552. this.nextUpdate = new Time({ schema: asn1.result[TBS_CERT_LIST_NEXT_UPDATE] });
  9553. }
  9554. if (TBS_CERT_LIST_REVOKED_CERTIFICATES in asn1.result) {
  9555. this.revokedCertificates = Array.from(asn1.result[TBS_CERT_LIST_REVOKED_CERTIFICATES], element => new RevokedCertificate({ schema: element }));
  9556. }
  9557. if (TBS_CERT_LIST_EXTENSIONS in asn1.result) {
  9558. this.crlExtensions = new Extensions({ schema: asn1.result[TBS_CERT_LIST_EXTENSIONS] });
  9559. }
  9560. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  9561. this.signatureValue = asn1.result.signatureValue;
  9562. }
  9563. encodeTBS() {
  9564. const outputArray = [];
  9565. if (this.version !== CertificateRevocationList.defaultValues(VERSION$e)) {
  9566. outputArray.push(new asn1js.Integer({ value: this.version }));
  9567. }
  9568. outputArray.push(this.signature.toSchema());
  9569. outputArray.push(this.issuer.toSchema());
  9570. outputArray.push(this.thisUpdate.toSchema());
  9571. if (this.nextUpdate) {
  9572. outputArray.push(this.nextUpdate.toSchema());
  9573. }
  9574. if (this.revokedCertificates) {
  9575. outputArray.push(new asn1js.Sequence({
  9576. value: Array.from(this.revokedCertificates, o => o.toSchema())
  9577. }));
  9578. }
  9579. if (this.crlExtensions) {
  9580. outputArray.push(new asn1js.Constructed({
  9581. optional: true,
  9582. idBlock: {
  9583. tagClass: 3,
  9584. tagNumber: 0
  9585. },
  9586. value: [
  9587. this.crlExtensions.toSchema()
  9588. ]
  9589. }));
  9590. }
  9591. return (new asn1js.Sequence({
  9592. value: outputArray
  9593. }));
  9594. }
  9595. toSchema(encodeFlag = false) {
  9596. let tbsSchema;
  9597. if (!encodeFlag) {
  9598. if (!this.tbsView.byteLength) {
  9599. return CertificateRevocationList.schema();
  9600. }
  9601. const asn1 = asn1js.fromBER(this.tbsView);
  9602. AsnError.assert(asn1, "TBS Certificate Revocation List");
  9603. tbsSchema = asn1.result;
  9604. }
  9605. else {
  9606. tbsSchema = this.encodeTBS();
  9607. }
  9608. return (new asn1js.Sequence({
  9609. value: [
  9610. tbsSchema,
  9611. this.signatureAlgorithm.toSchema(),
  9612. this.signatureValue
  9613. ]
  9614. }));
  9615. }
  9616. toJSON() {
  9617. const res = {
  9618. tbs: pvtsutils.Convert.ToHex(this.tbsView),
  9619. version: this.version,
  9620. signature: this.signature.toJSON(),
  9621. issuer: this.issuer.toJSON(),
  9622. thisUpdate: this.thisUpdate.toJSON(),
  9623. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  9624. signatureValue: this.signatureValue.toJSON()
  9625. };
  9626. if (this.version !== CertificateRevocationList.defaultValues(VERSION$e))
  9627. res.version = this.version;
  9628. if (this.nextUpdate) {
  9629. res.nextUpdate = this.nextUpdate.toJSON();
  9630. }
  9631. if (this.revokedCertificates) {
  9632. res.revokedCertificates = Array.from(this.revokedCertificates, o => o.toJSON());
  9633. }
  9634. if (this.crlExtensions) {
  9635. res.crlExtensions = this.crlExtensions.toJSON();
  9636. }
  9637. return res;
  9638. }
  9639. isCertificateRevoked(certificate) {
  9640. if (!this.issuer.isEqual(certificate.issuer)) {
  9641. return false;
  9642. }
  9643. if (!this.revokedCertificates) {
  9644. return false;
  9645. }
  9646. for (const revokedCertificate of this.revokedCertificates) {
  9647. if (revokedCertificate.userCertificate.isEqual(certificate.serialNumber)) {
  9648. return true;
  9649. }
  9650. }
  9651. return false;
  9652. }
  9653. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  9654. if (!privateKey) {
  9655. throw new Error("Need to provide a private key for signing");
  9656. }
  9657. const signatureParameters = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  9658. const { parameters } = signatureParameters;
  9659. this.signature = signatureParameters.signatureAlgorithm;
  9660. this.signatureAlgorithm = signatureParameters.signatureAlgorithm;
  9661. this.tbsView = new Uint8Array(this.encodeTBS().toBER());
  9662. const signature = await crypto.signWithPrivateKey(this.tbsView, privateKey, parameters);
  9663. this.signatureValue = new asn1js.BitString({ valueHex: signature });
  9664. }
  9665. async verify(parameters = {}, crypto = getCrypto(true)) {
  9666. let subjectPublicKeyInfo;
  9667. if (parameters.issuerCertificate) {
  9668. subjectPublicKeyInfo = parameters.issuerCertificate.subjectPublicKeyInfo;
  9669. if (!this.issuer.isEqual(parameters.issuerCertificate.subject)) {
  9670. return false;
  9671. }
  9672. }
  9673. if (parameters.publicKeyInfo) {
  9674. subjectPublicKeyInfo = parameters.publicKeyInfo;
  9675. }
  9676. if (!subjectPublicKeyInfo) {
  9677. throw new Error("Issuer's certificate must be provided as an input parameter");
  9678. }
  9679. if (this.crlExtensions) {
  9680. for (const extension of this.crlExtensions.extensions) {
  9681. if (extension.critical) {
  9682. if (!WELL_KNOWN_EXTENSIONS.includes(extension.extnID))
  9683. return false;
  9684. }
  9685. }
  9686. }
  9687. return crypto.verifyWithPublicKey(this.tbsView, this.signatureValue, subjectPublicKeyInfo, this.signatureAlgorithm);
  9688. }
  9689. }
  9690. CertificateRevocationList.CLASS_NAME = "CertificateRevocationList";
  9691. const CRL_ID = "crlId";
  9692. const CRL_VALUE = "crlValue";
  9693. const PARSED_VALUE$3 = "parsedValue";
  9694. const CLEAR_PROPS$M = [
  9695. CRL_ID,
  9696. CRL_VALUE,
  9697. ];
  9698. class CRLBag extends PkiObject {
  9699. constructor(parameters = {}) {
  9700. super();
  9701. this.crlId = pvutils.getParametersValue(parameters, CRL_ID, CRLBag.defaultValues(CRL_ID));
  9702. this.crlValue = pvutils.getParametersValue(parameters, CRL_VALUE, CRLBag.defaultValues(CRL_VALUE));
  9703. if (PARSED_VALUE$3 in parameters) {
  9704. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE$3, CRLBag.defaultValues(PARSED_VALUE$3));
  9705. }
  9706. if (parameters.schema) {
  9707. this.fromSchema(parameters.schema);
  9708. }
  9709. }
  9710. static defaultValues(memberName) {
  9711. switch (memberName) {
  9712. case CRL_ID:
  9713. return EMPTY_STRING;
  9714. case CRL_VALUE:
  9715. return (new asn1js.Any());
  9716. case PARSED_VALUE$3:
  9717. return {};
  9718. default:
  9719. return super.defaultValues(memberName);
  9720. }
  9721. }
  9722. static compareWithDefault(memberName, memberValue) {
  9723. switch (memberName) {
  9724. case CRL_ID:
  9725. return (memberValue === EMPTY_STRING);
  9726. case CRL_VALUE:
  9727. return (memberValue instanceof asn1js.Any);
  9728. case PARSED_VALUE$3:
  9729. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  9730. default:
  9731. return super.defaultValues(memberName);
  9732. }
  9733. }
  9734. static schema(parameters = {}) {
  9735. const names = pvutils.getParametersValue(parameters, "names", {});
  9736. return (new asn1js.Sequence({
  9737. name: (names.blockName || EMPTY_STRING),
  9738. value: [
  9739. new asn1js.ObjectIdentifier({ name: (names.id || "id") }),
  9740. new asn1js.Constructed({
  9741. idBlock: {
  9742. tagClass: 3,
  9743. tagNumber: 0
  9744. },
  9745. value: [new asn1js.Any({ name: (names.value || "value") })]
  9746. })
  9747. ]
  9748. }));
  9749. }
  9750. fromSchema(schema) {
  9751. pvutils.clearProps(schema, CLEAR_PROPS$M);
  9752. const asn1 = asn1js.compareSchema(schema, schema, CRLBag.schema({
  9753. names: {
  9754. id: CRL_ID,
  9755. value: CRL_VALUE
  9756. }
  9757. }));
  9758. AsnError.assertSchema(asn1, this.className);
  9759. this.crlId = asn1.result.crlId.valueBlock.toString();
  9760. this.crlValue = asn1.result.crlValue;
  9761. switch (this.crlId) {
  9762. case id_CRLBag_X509CRL:
  9763. {
  9764. this.parsedValue = CertificateRevocationList.fromBER(this.certValue.valueBlock.valueHex);
  9765. }
  9766. break;
  9767. default:
  9768. throw new Error(`Incorrect CRL_ID value in CRLBag: ${this.crlId}`);
  9769. }
  9770. }
  9771. toSchema() {
  9772. if (this.parsedValue) {
  9773. this.crlId = id_CRLBag_X509CRL;
  9774. this.crlValue = new asn1js.OctetString({ valueHex: this.parsedValue.toSchema().toBER(false) });
  9775. }
  9776. return (new asn1js.Sequence({
  9777. value: [
  9778. new asn1js.ObjectIdentifier({ value: this.crlId }),
  9779. new asn1js.Constructed({
  9780. idBlock: {
  9781. tagClass: 3,
  9782. tagNumber: 0
  9783. },
  9784. value: [this.crlValue.toSchema()]
  9785. })
  9786. ]
  9787. }));
  9788. }
  9789. toJSON() {
  9790. return {
  9791. crlId: this.crlId,
  9792. crlValue: this.crlValue.toJSON()
  9793. };
  9794. }
  9795. }
  9796. CRLBag.CLASS_NAME = "CRLBag";
  9797. const VERSION$d = "version";
  9798. const ENCRYPTED_CONTENT_INFO$1 = "encryptedContentInfo";
  9799. const UNPROTECTED_ATTRS$1 = "unprotectedAttrs";
  9800. const CLEAR_PROPS$L = [
  9801. VERSION$d,
  9802. ENCRYPTED_CONTENT_INFO$1,
  9803. UNPROTECTED_ATTRS$1,
  9804. ];
  9805. class EncryptedData extends PkiObject {
  9806. constructor(parameters = {}) {
  9807. super();
  9808. this.version = pvutils.getParametersValue(parameters, VERSION$d, EncryptedData.defaultValues(VERSION$d));
  9809. this.encryptedContentInfo = pvutils.getParametersValue(parameters, ENCRYPTED_CONTENT_INFO$1, EncryptedData.defaultValues(ENCRYPTED_CONTENT_INFO$1));
  9810. if (UNPROTECTED_ATTRS$1 in parameters) {
  9811. this.unprotectedAttrs = pvutils.getParametersValue(parameters, UNPROTECTED_ATTRS$1, EncryptedData.defaultValues(UNPROTECTED_ATTRS$1));
  9812. }
  9813. if (parameters.schema) {
  9814. this.fromSchema(parameters.schema);
  9815. }
  9816. }
  9817. static defaultValues(memberName) {
  9818. switch (memberName) {
  9819. case VERSION$d:
  9820. return 0;
  9821. case ENCRYPTED_CONTENT_INFO$1:
  9822. return new EncryptedContentInfo();
  9823. case UNPROTECTED_ATTRS$1:
  9824. return [];
  9825. default:
  9826. return super.defaultValues(memberName);
  9827. }
  9828. }
  9829. static compareWithDefault(memberName, memberValue) {
  9830. switch (memberName) {
  9831. case VERSION$d:
  9832. return (memberValue === 0);
  9833. case ENCRYPTED_CONTENT_INFO$1:
  9834. return ((EncryptedContentInfo.compareWithDefault("contentType", memberValue.contentType)) &&
  9835. (EncryptedContentInfo.compareWithDefault("contentEncryptionAlgorithm", memberValue.contentEncryptionAlgorithm)) &&
  9836. (EncryptedContentInfo.compareWithDefault("encryptedContent", memberValue.encryptedContent)));
  9837. case UNPROTECTED_ATTRS$1:
  9838. return (memberValue.length === 0);
  9839. default:
  9840. return super.defaultValues(memberName);
  9841. }
  9842. }
  9843. static schema(parameters = {}) {
  9844. const names = pvutils.getParametersValue(parameters, "names", {});
  9845. return (new asn1js.Sequence({
  9846. name: (names.blockName || EMPTY_STRING),
  9847. value: [
  9848. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  9849. EncryptedContentInfo.schema(names.encryptedContentInfo || {}),
  9850. new asn1js.Constructed({
  9851. optional: true,
  9852. idBlock: {
  9853. tagClass: 3,
  9854. tagNumber: 1
  9855. },
  9856. value: [
  9857. new asn1js.Repeated({
  9858. name: (names.unprotectedAttrs || EMPTY_STRING),
  9859. value: Attribute.schema()
  9860. })
  9861. ]
  9862. })
  9863. ]
  9864. }));
  9865. }
  9866. fromSchema(schema) {
  9867. pvutils.clearProps(schema, CLEAR_PROPS$L);
  9868. const asn1 = asn1js.compareSchema(schema, schema, EncryptedData.schema({
  9869. names: {
  9870. version: VERSION$d,
  9871. encryptedContentInfo: {
  9872. names: {
  9873. blockName: ENCRYPTED_CONTENT_INFO$1
  9874. }
  9875. },
  9876. unprotectedAttrs: UNPROTECTED_ATTRS$1
  9877. }
  9878. }));
  9879. AsnError.assertSchema(asn1, this.className);
  9880. this.version = asn1.result.version.valueBlock.valueDec;
  9881. this.encryptedContentInfo = new EncryptedContentInfo({ schema: asn1.result.encryptedContentInfo });
  9882. if (UNPROTECTED_ATTRS$1 in asn1.result)
  9883. this.unprotectedAttrs = Array.from(asn1.result.unprotectedAttrs, element => new Attribute({ schema: element }));
  9884. }
  9885. toSchema() {
  9886. const outputArray = [];
  9887. outputArray.push(new asn1js.Integer({ value: this.version }));
  9888. outputArray.push(this.encryptedContentInfo.toSchema());
  9889. if (this.unprotectedAttrs) {
  9890. outputArray.push(new asn1js.Constructed({
  9891. optional: true,
  9892. idBlock: {
  9893. tagClass: 3,
  9894. tagNumber: 1
  9895. },
  9896. value: Array.from(this.unprotectedAttrs, o => o.toSchema())
  9897. }));
  9898. }
  9899. return (new asn1js.Sequence({
  9900. value: outputArray
  9901. }));
  9902. }
  9903. toJSON() {
  9904. const res = {
  9905. version: this.version,
  9906. encryptedContentInfo: this.encryptedContentInfo.toJSON()
  9907. };
  9908. if (this.unprotectedAttrs)
  9909. res.unprotectedAttrs = Array.from(this.unprotectedAttrs, o => o.toJSON());
  9910. return res;
  9911. }
  9912. async encrypt(parameters, crypto = getCrypto(true)) {
  9913. ArgumentError.assert(parameters, "parameters", "object");
  9914. const encryptParams = {
  9915. ...parameters,
  9916. contentType: "1.2.840.113549.1.7.1",
  9917. };
  9918. this.encryptedContentInfo = await crypto.encryptEncryptedContentInfo(encryptParams);
  9919. }
  9920. async decrypt(parameters, crypto = getCrypto(true)) {
  9921. ArgumentError.assert(parameters, "parameters", "object");
  9922. const decryptParams = {
  9923. ...parameters,
  9924. encryptedContentInfo: this.encryptedContentInfo,
  9925. };
  9926. return crypto.decryptEncryptedContentInfo(decryptParams);
  9927. }
  9928. }
  9929. EncryptedData.CLASS_NAME = "EncryptedData";
  9930. const ENCRYPTION_ALGORITHM = "encryptionAlgorithm";
  9931. const ENCRYPTED_DATA = "encryptedData";
  9932. const PARSED_VALUE$2 = "parsedValue";
  9933. const CLEAR_PROPS$K = [
  9934. ENCRYPTION_ALGORITHM,
  9935. ENCRYPTED_DATA,
  9936. ];
  9937. class PKCS8ShroudedKeyBag extends PkiObject {
  9938. constructor(parameters = {}) {
  9939. super();
  9940. this.encryptionAlgorithm = pvutils.getParametersValue(parameters, ENCRYPTION_ALGORITHM, PKCS8ShroudedKeyBag.defaultValues(ENCRYPTION_ALGORITHM));
  9941. this.encryptedData = pvutils.getParametersValue(parameters, ENCRYPTED_DATA, PKCS8ShroudedKeyBag.defaultValues(ENCRYPTED_DATA));
  9942. if (PARSED_VALUE$2 in parameters) {
  9943. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE$2, PKCS8ShroudedKeyBag.defaultValues(PARSED_VALUE$2));
  9944. }
  9945. if (parameters.schema) {
  9946. this.fromSchema(parameters.schema);
  9947. }
  9948. }
  9949. static defaultValues(memberName) {
  9950. switch (memberName) {
  9951. case ENCRYPTION_ALGORITHM:
  9952. return (new AlgorithmIdentifier());
  9953. case ENCRYPTED_DATA:
  9954. return (new asn1js.OctetString());
  9955. case PARSED_VALUE$2:
  9956. return {};
  9957. default:
  9958. return super.defaultValues(memberName);
  9959. }
  9960. }
  9961. static compareWithDefault(memberName, memberValue) {
  9962. switch (memberName) {
  9963. case ENCRYPTION_ALGORITHM:
  9964. return ((AlgorithmIdentifier.compareWithDefault("algorithmId", memberValue.algorithmId)) &&
  9965. (("algorithmParams" in memberValue) === false));
  9966. case ENCRYPTED_DATA:
  9967. return (memberValue.isEqual(PKCS8ShroudedKeyBag.defaultValues(memberName)));
  9968. case PARSED_VALUE$2:
  9969. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  9970. default:
  9971. return super.defaultValues(memberName);
  9972. }
  9973. }
  9974. static schema(parameters = {}) {
  9975. const names = pvutils.getParametersValue(parameters, "names", {});
  9976. return (new asn1js.Sequence({
  9977. name: (names.blockName || EMPTY_STRING),
  9978. value: [
  9979. AlgorithmIdentifier.schema(names.encryptionAlgorithm || {
  9980. names: {
  9981. blockName: ENCRYPTION_ALGORITHM
  9982. }
  9983. }),
  9984. new asn1js.Choice({
  9985. value: [
  9986. new asn1js.OctetString({ name: (names.encryptedData || ENCRYPTED_DATA) }),
  9987. new asn1js.OctetString({
  9988. idBlock: {
  9989. isConstructed: true
  9990. },
  9991. name: (names.encryptedData || ENCRYPTED_DATA)
  9992. })
  9993. ]
  9994. })
  9995. ]
  9996. }));
  9997. }
  9998. fromSchema(schema) {
  9999. pvutils.clearProps(schema, CLEAR_PROPS$K);
  10000. const asn1 = asn1js.compareSchema(schema, schema, PKCS8ShroudedKeyBag.schema({
  10001. names: {
  10002. encryptionAlgorithm: {
  10003. names: {
  10004. blockName: ENCRYPTION_ALGORITHM
  10005. }
  10006. },
  10007. encryptedData: ENCRYPTED_DATA
  10008. }
  10009. }));
  10010. AsnError.assertSchema(asn1, this.className);
  10011. this.encryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.encryptionAlgorithm });
  10012. this.encryptedData = asn1.result.encryptedData;
  10013. }
  10014. toSchema() {
  10015. return (new asn1js.Sequence({
  10016. value: [
  10017. this.encryptionAlgorithm.toSchema(),
  10018. this.encryptedData
  10019. ]
  10020. }));
  10021. }
  10022. toJSON() {
  10023. return {
  10024. encryptionAlgorithm: this.encryptionAlgorithm.toJSON(),
  10025. encryptedData: this.encryptedData.toJSON(),
  10026. };
  10027. }
  10028. async parseInternalValues(parameters, crypto = getCrypto(true)) {
  10029. const cmsEncrypted = new EncryptedData({
  10030. encryptedContentInfo: new EncryptedContentInfo({
  10031. contentEncryptionAlgorithm: this.encryptionAlgorithm,
  10032. encryptedContent: this.encryptedData
  10033. })
  10034. });
  10035. const decryptedData = await cmsEncrypted.decrypt(parameters, crypto);
  10036. this.parsedValue = PrivateKeyInfo.fromBER(decryptedData);
  10037. }
  10038. async makeInternalValues(parameters, crypto = getCrypto(true)) {
  10039. if (!this.parsedValue) {
  10040. throw new Error("Please initialize \"parsedValue\" first");
  10041. }
  10042. const cmsEncrypted = new EncryptedData();
  10043. const encryptParams = {
  10044. ...parameters,
  10045. contentToEncrypt: this.parsedValue.toSchema().toBER(false),
  10046. };
  10047. await cmsEncrypted.encrypt(encryptParams, crypto);
  10048. if (!cmsEncrypted.encryptedContentInfo.encryptedContent) {
  10049. throw new Error("The filed `encryptedContent` in EncryptedContentInfo is empty");
  10050. }
  10051. this.encryptionAlgorithm = cmsEncrypted.encryptedContentInfo.contentEncryptionAlgorithm;
  10052. this.encryptedData = cmsEncrypted.encryptedContentInfo.encryptedContent;
  10053. }
  10054. }
  10055. PKCS8ShroudedKeyBag.CLASS_NAME = "PKCS8ShroudedKeyBag";
  10056. const SECRET_TYPE_ID = "secretTypeId";
  10057. const SECRET_VALUE = "secretValue";
  10058. const CLEAR_PROPS$J = [
  10059. SECRET_TYPE_ID,
  10060. SECRET_VALUE,
  10061. ];
  10062. class SecretBag extends PkiObject {
  10063. constructor(parameters = {}) {
  10064. super();
  10065. this.secretTypeId = pvutils.getParametersValue(parameters, SECRET_TYPE_ID, SecretBag.defaultValues(SECRET_TYPE_ID));
  10066. this.secretValue = pvutils.getParametersValue(parameters, SECRET_VALUE, SecretBag.defaultValues(SECRET_VALUE));
  10067. if (parameters.schema) {
  10068. this.fromSchema(parameters.schema);
  10069. }
  10070. }
  10071. static defaultValues(memberName) {
  10072. switch (memberName) {
  10073. case SECRET_TYPE_ID:
  10074. return EMPTY_STRING;
  10075. case SECRET_VALUE:
  10076. return (new asn1js.Any());
  10077. default:
  10078. return super.defaultValues(memberName);
  10079. }
  10080. }
  10081. static compareWithDefault(memberName, memberValue) {
  10082. switch (memberName) {
  10083. case SECRET_TYPE_ID:
  10084. return (memberValue === EMPTY_STRING);
  10085. case SECRET_VALUE:
  10086. return (memberValue instanceof asn1js.Any);
  10087. default:
  10088. return super.defaultValues(memberName);
  10089. }
  10090. }
  10091. static schema(parameters = {}) {
  10092. const names = pvutils.getParametersValue(parameters, "names", {});
  10093. return (new asn1js.Sequence({
  10094. name: (names.blockName || EMPTY_STRING),
  10095. value: [
  10096. new asn1js.ObjectIdentifier({ name: (names.id || "id") }),
  10097. new asn1js.Constructed({
  10098. idBlock: {
  10099. tagClass: 3,
  10100. tagNumber: 0
  10101. },
  10102. value: [new asn1js.Any({ name: (names.value || "value") })]
  10103. })
  10104. ]
  10105. }));
  10106. }
  10107. fromSchema(schema) {
  10108. pvutils.clearProps(schema, CLEAR_PROPS$J);
  10109. const asn1 = asn1js.compareSchema(schema, schema, SecretBag.schema({
  10110. names: {
  10111. id: SECRET_TYPE_ID,
  10112. value: SECRET_VALUE
  10113. }
  10114. }));
  10115. AsnError.assertSchema(asn1, this.className);
  10116. this.secretTypeId = asn1.result.secretTypeId.valueBlock.toString();
  10117. this.secretValue = asn1.result.secretValue;
  10118. }
  10119. toSchema() {
  10120. return (new asn1js.Sequence({
  10121. value: [
  10122. new asn1js.ObjectIdentifier({ value: this.secretTypeId }),
  10123. new asn1js.Constructed({
  10124. idBlock: {
  10125. tagClass: 3,
  10126. tagNumber: 0
  10127. },
  10128. value: [this.secretValue.toSchema()]
  10129. })
  10130. ]
  10131. }));
  10132. }
  10133. toJSON() {
  10134. return {
  10135. secretTypeId: this.secretTypeId,
  10136. secretValue: this.secretValue.toJSON()
  10137. };
  10138. }
  10139. }
  10140. SecretBag.CLASS_NAME = "SecretBag";
  10141. class SafeBagValueFactory {
  10142. static getItems() {
  10143. if (!this.items) {
  10144. this.items = {};
  10145. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.1", PrivateKeyInfo);
  10146. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.2", PKCS8ShroudedKeyBag);
  10147. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.3", CertBag);
  10148. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.4", CRLBag);
  10149. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.5", SecretBag);
  10150. SafeBagValueFactory.register("1.2.840.113549.1.12.10.1.6", SafeContents);
  10151. }
  10152. return this.items;
  10153. }
  10154. static register(id, type) {
  10155. this.getItems()[id] = type;
  10156. }
  10157. static find(id) {
  10158. return this.getItems()[id] || null;
  10159. }
  10160. }
  10161. const BAG_ID = "bagId";
  10162. const BAG_VALUE = "bagValue";
  10163. const BAG_ATTRIBUTES = "bagAttributes";
  10164. const CLEAR_PROPS$I = [
  10165. BAG_ID,
  10166. BAG_VALUE,
  10167. BAG_ATTRIBUTES
  10168. ];
  10169. class SafeBag extends PkiObject {
  10170. constructor(parameters = {}) {
  10171. super();
  10172. this.bagId = pvutils.getParametersValue(parameters, BAG_ID, SafeBag.defaultValues(BAG_ID));
  10173. this.bagValue = pvutils.getParametersValue(parameters, BAG_VALUE, SafeBag.defaultValues(BAG_VALUE));
  10174. if (BAG_ATTRIBUTES in parameters) {
  10175. this.bagAttributes = pvutils.getParametersValue(parameters, BAG_ATTRIBUTES, SafeBag.defaultValues(BAG_ATTRIBUTES));
  10176. }
  10177. if (parameters.schema) {
  10178. this.fromSchema(parameters.schema);
  10179. }
  10180. }
  10181. static defaultValues(memberName) {
  10182. switch (memberName) {
  10183. case BAG_ID:
  10184. return EMPTY_STRING;
  10185. case BAG_VALUE:
  10186. return (new asn1js.Any());
  10187. case BAG_ATTRIBUTES:
  10188. return [];
  10189. default:
  10190. return super.defaultValues(memberName);
  10191. }
  10192. }
  10193. static compareWithDefault(memberName, memberValue) {
  10194. switch (memberName) {
  10195. case BAG_ID:
  10196. return (memberValue === EMPTY_STRING);
  10197. case BAG_VALUE:
  10198. return (memberValue instanceof asn1js.Any);
  10199. case BAG_ATTRIBUTES:
  10200. return (memberValue.length === 0);
  10201. default:
  10202. return super.defaultValues(memberName);
  10203. }
  10204. }
  10205. static schema(parameters = {}) {
  10206. const names = pvutils.getParametersValue(parameters, "names", {});
  10207. return (new asn1js.Sequence({
  10208. name: (names.blockName || EMPTY_STRING),
  10209. value: [
  10210. new asn1js.ObjectIdentifier({ name: (names.bagId || BAG_ID) }),
  10211. new asn1js.Constructed({
  10212. idBlock: {
  10213. tagClass: 3,
  10214. tagNumber: 0
  10215. },
  10216. value: [new asn1js.Any({ name: (names.bagValue || BAG_VALUE) })]
  10217. }),
  10218. new asn1js.Set({
  10219. optional: true,
  10220. value: [
  10221. new asn1js.Repeated({
  10222. name: (names.bagAttributes || BAG_ATTRIBUTES),
  10223. value: Attribute.schema()
  10224. })
  10225. ]
  10226. })
  10227. ]
  10228. }));
  10229. }
  10230. fromSchema(schema) {
  10231. pvutils.clearProps(schema, CLEAR_PROPS$I);
  10232. const asn1 = asn1js.compareSchema(schema, schema, SafeBag.schema({
  10233. names: {
  10234. bagId: BAG_ID,
  10235. bagValue: BAG_VALUE,
  10236. bagAttributes: BAG_ATTRIBUTES
  10237. }
  10238. }));
  10239. AsnError.assertSchema(asn1, this.className);
  10240. this.bagId = asn1.result.bagId.valueBlock.toString();
  10241. const bagType = SafeBagValueFactory.find(this.bagId);
  10242. if (!bagType) {
  10243. throw new Error(`Invalid BAG_ID for SafeBag: ${this.bagId}`);
  10244. }
  10245. this.bagValue = new bagType({ schema: asn1.result.bagValue });
  10246. if (BAG_ATTRIBUTES in asn1.result) {
  10247. this.bagAttributes = Array.from(asn1.result.bagAttributes, element => new Attribute({ schema: element }));
  10248. }
  10249. }
  10250. toSchema() {
  10251. const outputArray = [
  10252. new asn1js.ObjectIdentifier({ value: this.bagId }),
  10253. new asn1js.Constructed({
  10254. idBlock: {
  10255. tagClass: 3,
  10256. tagNumber: 0
  10257. },
  10258. value: [this.bagValue.toSchema()]
  10259. })
  10260. ];
  10261. if (this.bagAttributes) {
  10262. outputArray.push(new asn1js.Set({
  10263. value: Array.from(this.bagAttributes, o => o.toSchema())
  10264. }));
  10265. }
  10266. return (new asn1js.Sequence({
  10267. value: outputArray
  10268. }));
  10269. }
  10270. toJSON() {
  10271. const output = {
  10272. bagId: this.bagId,
  10273. bagValue: this.bagValue.toJSON()
  10274. };
  10275. if (this.bagAttributes) {
  10276. output.bagAttributes = Array.from(this.bagAttributes, o => o.toJSON());
  10277. }
  10278. return output;
  10279. }
  10280. }
  10281. SafeBag.CLASS_NAME = "SafeBag";
  10282. const SAFE_BUGS = "safeBags";
  10283. class SafeContents extends PkiObject {
  10284. constructor(parameters = {}) {
  10285. super();
  10286. this.safeBags = pvutils.getParametersValue(parameters, SAFE_BUGS, SafeContents.defaultValues(SAFE_BUGS));
  10287. if (parameters.schema) {
  10288. this.fromSchema(parameters.schema);
  10289. }
  10290. }
  10291. static defaultValues(memberName) {
  10292. switch (memberName) {
  10293. case SAFE_BUGS:
  10294. return [];
  10295. default:
  10296. return super.defaultValues(memberName);
  10297. }
  10298. }
  10299. static compareWithDefault(memberName, memberValue) {
  10300. switch (memberName) {
  10301. case SAFE_BUGS:
  10302. return (memberValue.length === 0);
  10303. default:
  10304. return super.defaultValues(memberName);
  10305. }
  10306. }
  10307. static schema(parameters = {}) {
  10308. const names = pvutils.getParametersValue(parameters, "names", {});
  10309. return (new asn1js.Sequence({
  10310. name: (names.blockName || EMPTY_STRING),
  10311. value: [
  10312. new asn1js.Repeated({
  10313. name: (names.safeBags || EMPTY_STRING),
  10314. value: SafeBag.schema()
  10315. })
  10316. ]
  10317. }));
  10318. }
  10319. fromSchema(schema) {
  10320. pvutils.clearProps(schema, [
  10321. SAFE_BUGS
  10322. ]);
  10323. const asn1 = asn1js.compareSchema(schema, schema, SafeContents.schema({
  10324. names: {
  10325. safeBags: SAFE_BUGS
  10326. }
  10327. }));
  10328. AsnError.assertSchema(asn1, this.className);
  10329. this.safeBags = Array.from(asn1.result.safeBags, element => new SafeBag({ schema: element }));
  10330. }
  10331. toSchema() {
  10332. return (new asn1js.Sequence({
  10333. value: Array.from(this.safeBags, o => o.toSchema())
  10334. }));
  10335. }
  10336. toJSON() {
  10337. return {
  10338. safeBags: Array.from(this.safeBags, o => o.toJSON())
  10339. };
  10340. }
  10341. }
  10342. SafeContents.CLASS_NAME = "SafeContents";
  10343. const OTHER_CERT_FORMAT = "otherCertFormat";
  10344. const OTHER_CERT = "otherCert";
  10345. const CLEAR_PROPS$H = [
  10346. OTHER_CERT_FORMAT,
  10347. OTHER_CERT
  10348. ];
  10349. class OtherCertificateFormat extends PkiObject {
  10350. constructor(parameters = {}) {
  10351. super();
  10352. this.otherCertFormat = pvutils.getParametersValue(parameters, OTHER_CERT_FORMAT, OtherCertificateFormat.defaultValues(OTHER_CERT_FORMAT));
  10353. this.otherCert = pvutils.getParametersValue(parameters, OTHER_CERT, OtherCertificateFormat.defaultValues(OTHER_CERT));
  10354. if (parameters.schema) {
  10355. this.fromSchema(parameters.schema);
  10356. }
  10357. }
  10358. static defaultValues(memberName) {
  10359. switch (memberName) {
  10360. case OTHER_CERT_FORMAT:
  10361. return EMPTY_STRING;
  10362. case OTHER_CERT:
  10363. return new asn1js.Any();
  10364. default:
  10365. return super.defaultValues(memberName);
  10366. }
  10367. }
  10368. static schema(parameters = {}) {
  10369. const names = pvutils.getParametersValue(parameters, "names", {});
  10370. return (new asn1js.Sequence({
  10371. name: (names.blockName || EMPTY_STRING),
  10372. value: [
  10373. new asn1js.ObjectIdentifier({ name: (names.otherCertFormat || OTHER_CERT_FORMAT) }),
  10374. new asn1js.Any({ name: (names.otherCert || OTHER_CERT) })
  10375. ]
  10376. }));
  10377. }
  10378. fromSchema(schema) {
  10379. pvutils.clearProps(schema, CLEAR_PROPS$H);
  10380. const asn1 = asn1js.compareSchema(schema, schema, OtherCertificateFormat.schema());
  10381. AsnError.assertSchema(asn1, this.className);
  10382. this.otherCertFormat = asn1.result.otherCertFormat.valueBlock.toString();
  10383. this.otherCert = asn1.result.otherCert;
  10384. }
  10385. toSchema() {
  10386. return (new asn1js.Sequence({
  10387. value: [
  10388. new asn1js.ObjectIdentifier({ value: this.otherCertFormat }),
  10389. this.otherCert
  10390. ]
  10391. }));
  10392. }
  10393. toJSON() {
  10394. const res = {
  10395. otherCertFormat: this.otherCertFormat
  10396. };
  10397. if (!(this.otherCert instanceof asn1js.Any)) {
  10398. res.otherCert = this.otherCert.toJSON();
  10399. }
  10400. return res;
  10401. }
  10402. }
  10403. const CERTIFICATES$1 = "certificates";
  10404. const CLEAR_PROPS$G = [
  10405. CERTIFICATES$1,
  10406. ];
  10407. class CertificateSet extends PkiObject {
  10408. constructor(parameters = {}) {
  10409. super();
  10410. this.certificates = pvutils.getParametersValue(parameters, CERTIFICATES$1, CertificateSet.defaultValues(CERTIFICATES$1));
  10411. if (parameters.schema) {
  10412. this.fromSchema(parameters.schema);
  10413. }
  10414. }
  10415. static defaultValues(memberName) {
  10416. switch (memberName) {
  10417. case CERTIFICATES$1:
  10418. return [];
  10419. default:
  10420. return super.defaultValues(memberName);
  10421. }
  10422. }
  10423. static schema(parameters = {}) {
  10424. const names = pvutils.getParametersValue(parameters, "names", {});
  10425. return (new asn1js.Set({
  10426. name: (names.blockName || EMPTY_STRING),
  10427. value: [
  10428. new asn1js.Repeated({
  10429. name: (names.certificates || CERTIFICATES$1),
  10430. value: new asn1js.Choice({
  10431. value: [
  10432. Certificate.schema(),
  10433. new asn1js.Constructed({
  10434. idBlock: {
  10435. tagClass: 3,
  10436. tagNumber: 0
  10437. },
  10438. value: [
  10439. new asn1js.Any()
  10440. ]
  10441. }),
  10442. new asn1js.Constructed({
  10443. idBlock: {
  10444. tagClass: 3,
  10445. tagNumber: 1
  10446. },
  10447. value: [
  10448. new asn1js.Sequence
  10449. ]
  10450. }),
  10451. new asn1js.Constructed({
  10452. idBlock: {
  10453. tagClass: 3,
  10454. tagNumber: 2
  10455. },
  10456. value: AttributeCertificateV2.schema().valueBlock.value
  10457. }),
  10458. new asn1js.Constructed({
  10459. idBlock: {
  10460. tagClass: 3,
  10461. tagNumber: 3
  10462. },
  10463. value: OtherCertificateFormat.schema().valueBlock.value
  10464. })
  10465. ]
  10466. })
  10467. })
  10468. ]
  10469. }));
  10470. }
  10471. fromSchema(schema) {
  10472. pvutils.clearProps(schema, CLEAR_PROPS$G);
  10473. const asn1 = asn1js.compareSchema(schema, schema, CertificateSet.schema());
  10474. AsnError.assertSchema(asn1, this.className);
  10475. this.certificates = Array.from(asn1.result.certificates || [], (element) => {
  10476. const initialTagNumber = element.idBlock.tagNumber;
  10477. if (element.idBlock.tagClass === 1)
  10478. return new Certificate({ schema: element });
  10479. const elementSequence = new asn1js.Sequence({
  10480. value: element.valueBlock.value
  10481. });
  10482. switch (initialTagNumber) {
  10483. case 1:
  10484. if (elementSequence.valueBlock.value[0].valueBlock.value[0].valueBlock.valueDec === 1) {
  10485. return new AttributeCertificateV2({ schema: elementSequence });
  10486. }
  10487. else {
  10488. return new AttributeCertificateV1({ schema: elementSequence });
  10489. }
  10490. case 2:
  10491. return new AttributeCertificateV2({ schema: elementSequence });
  10492. case 3:
  10493. return new OtherCertificateFormat({ schema: elementSequence });
  10494. }
  10495. return element;
  10496. });
  10497. }
  10498. toSchema() {
  10499. return (new asn1js.Set({
  10500. value: Array.from(this.certificates, element => {
  10501. switch (true) {
  10502. case (element instanceof Certificate):
  10503. return element.toSchema();
  10504. case (element instanceof AttributeCertificateV1):
  10505. return new asn1js.Constructed({
  10506. idBlock: {
  10507. tagClass: 3,
  10508. tagNumber: 1
  10509. },
  10510. value: element.toSchema().valueBlock.value
  10511. });
  10512. case (element instanceof AttributeCertificateV2):
  10513. return new asn1js.Constructed({
  10514. idBlock: {
  10515. tagClass: 3,
  10516. tagNumber: 2
  10517. },
  10518. value: element.toSchema().valueBlock.value
  10519. });
  10520. case (element instanceof OtherCertificateFormat):
  10521. return new asn1js.Constructed({
  10522. idBlock: {
  10523. tagClass: 3,
  10524. tagNumber: 3
  10525. },
  10526. value: element.toSchema().valueBlock.value
  10527. });
  10528. }
  10529. return element.toSchema();
  10530. })
  10531. }));
  10532. }
  10533. toJSON() {
  10534. return {
  10535. certificates: Array.from(this.certificates, o => o.toJSON())
  10536. };
  10537. }
  10538. }
  10539. CertificateSet.CLASS_NAME = "CertificateSet";
  10540. const OTHER_REV_INFO_FORMAT = "otherRevInfoFormat";
  10541. const OTHER_REV_INFO = "otherRevInfo";
  10542. const CLEAR_PROPS$F = [
  10543. OTHER_REV_INFO_FORMAT,
  10544. OTHER_REV_INFO
  10545. ];
  10546. class OtherRevocationInfoFormat extends PkiObject {
  10547. constructor(parameters = {}) {
  10548. super();
  10549. this.otherRevInfoFormat = pvutils.getParametersValue(parameters, OTHER_REV_INFO_FORMAT, OtherRevocationInfoFormat.defaultValues(OTHER_REV_INFO_FORMAT));
  10550. this.otherRevInfo = pvutils.getParametersValue(parameters, OTHER_REV_INFO, OtherRevocationInfoFormat.defaultValues(OTHER_REV_INFO));
  10551. if (parameters.schema) {
  10552. this.fromSchema(parameters.schema);
  10553. }
  10554. }
  10555. static defaultValues(memberName) {
  10556. switch (memberName) {
  10557. case OTHER_REV_INFO_FORMAT:
  10558. return EMPTY_STRING;
  10559. case OTHER_REV_INFO:
  10560. return new asn1js.Any();
  10561. default:
  10562. return super.defaultValues(memberName);
  10563. }
  10564. }
  10565. static schema(parameters = {}) {
  10566. const names = pvutils.getParametersValue(parameters, "names", {});
  10567. return (new asn1js.Sequence({
  10568. name: (names.blockName || EMPTY_STRING),
  10569. value: [
  10570. new asn1js.ObjectIdentifier({ name: (names.otherRevInfoFormat || OTHER_REV_INFO_FORMAT) }),
  10571. new asn1js.Any({ name: (names.otherRevInfo || OTHER_REV_INFO) })
  10572. ]
  10573. }));
  10574. }
  10575. fromSchema(schema) {
  10576. pvutils.clearProps(schema, CLEAR_PROPS$F);
  10577. const asn1 = asn1js.compareSchema(schema, schema, OtherRevocationInfoFormat.schema());
  10578. AsnError.assertSchema(asn1, this.className);
  10579. this.otherRevInfoFormat = asn1.result.otherRevInfoFormat.valueBlock.toString();
  10580. this.otherRevInfo = asn1.result.otherRevInfo;
  10581. }
  10582. toSchema() {
  10583. return (new asn1js.Sequence({
  10584. value: [
  10585. new asn1js.ObjectIdentifier({ value: this.otherRevInfoFormat }),
  10586. this.otherRevInfo
  10587. ]
  10588. }));
  10589. }
  10590. toJSON() {
  10591. const res = {
  10592. otherRevInfoFormat: this.otherRevInfoFormat
  10593. };
  10594. if (!(this.otherRevInfo instanceof asn1js.Any)) {
  10595. res.otherRevInfo = this.otherRevInfo.toJSON();
  10596. }
  10597. return res;
  10598. }
  10599. }
  10600. OtherRevocationInfoFormat.CLASS_NAME = "OtherRevocationInfoFormat";
  10601. const CRLS$3 = "crls";
  10602. const OTHER_REVOCATION_INFOS = "otherRevocationInfos";
  10603. const CLEAR_PROPS$E = [
  10604. CRLS$3
  10605. ];
  10606. class RevocationInfoChoices extends PkiObject {
  10607. constructor(parameters = {}) {
  10608. super();
  10609. this.crls = pvutils.getParametersValue(parameters, CRLS$3, RevocationInfoChoices.defaultValues(CRLS$3));
  10610. this.otherRevocationInfos = pvutils.getParametersValue(parameters, OTHER_REVOCATION_INFOS, RevocationInfoChoices.defaultValues(OTHER_REVOCATION_INFOS));
  10611. if (parameters.schema) {
  10612. this.fromSchema(parameters.schema);
  10613. }
  10614. }
  10615. static defaultValues(memberName) {
  10616. switch (memberName) {
  10617. case CRLS$3:
  10618. return [];
  10619. case OTHER_REVOCATION_INFOS:
  10620. return [];
  10621. default:
  10622. return super.defaultValues(memberName);
  10623. }
  10624. }
  10625. static schema(parameters = {}) {
  10626. const names = pvutils.getParametersValue(parameters, "names", {});
  10627. return (new asn1js.Set({
  10628. name: (names.blockName || EMPTY_STRING),
  10629. value: [
  10630. new asn1js.Repeated({
  10631. name: (names.crls || EMPTY_STRING),
  10632. value: new asn1js.Choice({
  10633. value: [
  10634. CertificateRevocationList.schema(),
  10635. new asn1js.Constructed({
  10636. idBlock: {
  10637. tagClass: 3,
  10638. tagNumber: 1
  10639. },
  10640. value: [
  10641. new asn1js.ObjectIdentifier(),
  10642. new asn1js.Any()
  10643. ]
  10644. })
  10645. ]
  10646. })
  10647. })
  10648. ]
  10649. }));
  10650. }
  10651. fromSchema(schema) {
  10652. pvutils.clearProps(schema, CLEAR_PROPS$E);
  10653. const asn1 = asn1js.compareSchema(schema, schema, RevocationInfoChoices.schema({
  10654. names: {
  10655. crls: CRLS$3
  10656. }
  10657. }));
  10658. AsnError.assertSchema(asn1, this.className);
  10659. if (asn1.result.crls) {
  10660. for (const element of asn1.result.crls) {
  10661. if (element.idBlock.tagClass === 1)
  10662. this.crls.push(new CertificateRevocationList({ schema: element }));
  10663. else
  10664. this.otherRevocationInfos.push(new OtherRevocationInfoFormat({ schema: element }));
  10665. }
  10666. }
  10667. }
  10668. toSchema() {
  10669. const outputArray = [];
  10670. outputArray.push(...Array.from(this.crls, o => o.toSchema()));
  10671. outputArray.push(...Array.from(this.otherRevocationInfos, element => {
  10672. const schema = element.toSchema();
  10673. schema.idBlock.tagClass = 3;
  10674. schema.idBlock.tagNumber = 1;
  10675. return schema;
  10676. }));
  10677. return (new asn1js.Set({
  10678. value: outputArray
  10679. }));
  10680. }
  10681. toJSON() {
  10682. return {
  10683. crls: Array.from(this.crls, o => o.toJSON()),
  10684. otherRevocationInfos: Array.from(this.otherRevocationInfos, o => o.toJSON())
  10685. };
  10686. }
  10687. }
  10688. RevocationInfoChoices.CLASS_NAME = "RevocationInfoChoices";
  10689. const CERTS$3 = "certs";
  10690. const CRLS$2 = "crls";
  10691. const CLEAR_PROPS$D = [
  10692. CERTS$3,
  10693. CRLS$2,
  10694. ];
  10695. class OriginatorInfo extends PkiObject {
  10696. constructor(parameters = {}) {
  10697. super();
  10698. this.crls = pvutils.getParametersValue(parameters, CRLS$2, OriginatorInfo.defaultValues(CRLS$2));
  10699. if (parameters.schema) {
  10700. this.fromSchema(parameters.schema);
  10701. }
  10702. }
  10703. static defaultValues(memberName) {
  10704. switch (memberName) {
  10705. case CERTS$3:
  10706. return new CertificateSet();
  10707. case CRLS$2:
  10708. return new RevocationInfoChoices();
  10709. default:
  10710. return super.defaultValues(memberName);
  10711. }
  10712. }
  10713. static compareWithDefault(memberName, memberValue) {
  10714. switch (memberName) {
  10715. case CERTS$3:
  10716. return (memberValue.certificates.length === 0);
  10717. case CRLS$2:
  10718. return ((memberValue.crls.length === 0) && (memberValue.otherRevocationInfos.length === 0));
  10719. default:
  10720. return super.defaultValues(memberName);
  10721. }
  10722. }
  10723. static schema(parameters = {}) {
  10724. const names = pvutils.getParametersValue(parameters, "names", {});
  10725. return (new asn1js.Sequence({
  10726. name: (names.blockName || EMPTY_STRING),
  10727. value: [
  10728. new asn1js.Constructed({
  10729. name: (names.certs || EMPTY_STRING),
  10730. optional: true,
  10731. idBlock: {
  10732. tagClass: 3,
  10733. tagNumber: 0
  10734. },
  10735. value: CertificateSet.schema().valueBlock.value
  10736. }),
  10737. new asn1js.Constructed({
  10738. name: (names.crls || EMPTY_STRING),
  10739. optional: true,
  10740. idBlock: {
  10741. tagClass: 3,
  10742. tagNumber: 1
  10743. },
  10744. value: RevocationInfoChoices.schema().valueBlock.value
  10745. })
  10746. ]
  10747. }));
  10748. }
  10749. fromSchema(schema) {
  10750. pvutils.clearProps(schema, CLEAR_PROPS$D);
  10751. const asn1 = asn1js.compareSchema(schema, schema, OriginatorInfo.schema({
  10752. names: {
  10753. certs: CERTS$3,
  10754. crls: CRLS$2
  10755. }
  10756. }));
  10757. AsnError.assertSchema(asn1, this.className);
  10758. if (CERTS$3 in asn1.result) {
  10759. this.certs = new CertificateSet({
  10760. schema: new asn1js.Set({
  10761. value: asn1.result.certs.valueBlock.value
  10762. })
  10763. });
  10764. }
  10765. if (CRLS$2 in asn1.result) {
  10766. this.crls = new RevocationInfoChoices({
  10767. schema: new asn1js.Set({
  10768. value: asn1.result.crls.valueBlock.value
  10769. })
  10770. });
  10771. }
  10772. }
  10773. toSchema() {
  10774. const sequenceValue = [];
  10775. if (this.certs) {
  10776. sequenceValue.push(new asn1js.Constructed({
  10777. idBlock: {
  10778. tagClass: 3,
  10779. tagNumber: 0
  10780. },
  10781. value: this.certs.toSchema().valueBlock.value
  10782. }));
  10783. }
  10784. if (this.crls) {
  10785. sequenceValue.push(new asn1js.Constructed({
  10786. idBlock: {
  10787. tagClass: 3,
  10788. tagNumber: 1
  10789. },
  10790. value: this.crls.toSchema().valueBlock.value
  10791. }));
  10792. }
  10793. return (new asn1js.Sequence({
  10794. value: sequenceValue
  10795. }));
  10796. }
  10797. toJSON() {
  10798. const res = {};
  10799. if (this.certs) {
  10800. res.certs = this.certs.toJSON();
  10801. }
  10802. if (this.crls) {
  10803. res.crls = this.crls.toJSON();
  10804. }
  10805. return res;
  10806. }
  10807. }
  10808. OriginatorInfo.CLASS_NAME = "OriginatorInfo";
  10809. const ISSUER = "issuer";
  10810. const SERIAL_NUMBER$2 = "serialNumber";
  10811. const CLEAR_PROPS$C = [
  10812. ISSUER,
  10813. SERIAL_NUMBER$2,
  10814. ];
  10815. class IssuerAndSerialNumber extends PkiObject {
  10816. constructor(parameters = {}) {
  10817. super();
  10818. this.issuer = pvutils.getParametersValue(parameters, ISSUER, IssuerAndSerialNumber.defaultValues(ISSUER));
  10819. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$2, IssuerAndSerialNumber.defaultValues(SERIAL_NUMBER$2));
  10820. if (parameters.schema) {
  10821. this.fromSchema(parameters.schema);
  10822. }
  10823. }
  10824. static defaultValues(memberName) {
  10825. switch (memberName) {
  10826. case ISSUER:
  10827. return new RelativeDistinguishedNames();
  10828. case SERIAL_NUMBER$2:
  10829. return new asn1js.Integer();
  10830. default:
  10831. return super.defaultValues(memberName);
  10832. }
  10833. }
  10834. static schema(parameters = {}) {
  10835. const names = pvutils.getParametersValue(parameters, "names", {});
  10836. return (new asn1js.Sequence({
  10837. name: (names.blockName || EMPTY_STRING),
  10838. value: [
  10839. RelativeDistinguishedNames.schema(names.issuer || {}),
  10840. new asn1js.Integer({ name: (names.serialNumber || EMPTY_STRING) })
  10841. ]
  10842. }));
  10843. }
  10844. fromSchema(schema) {
  10845. pvutils.clearProps(schema, CLEAR_PROPS$C);
  10846. const asn1 = asn1js.compareSchema(schema, schema, IssuerAndSerialNumber.schema({
  10847. names: {
  10848. issuer: {
  10849. names: {
  10850. blockName: ISSUER
  10851. }
  10852. },
  10853. serialNumber: SERIAL_NUMBER$2
  10854. }
  10855. }));
  10856. AsnError.assertSchema(asn1, this.className);
  10857. this.issuer = new RelativeDistinguishedNames({ schema: asn1.result.issuer });
  10858. this.serialNumber = asn1.result.serialNumber;
  10859. }
  10860. toSchema() {
  10861. return (new asn1js.Sequence({
  10862. value: [
  10863. this.issuer.toSchema(),
  10864. this.serialNumber
  10865. ]
  10866. }));
  10867. }
  10868. toJSON() {
  10869. return {
  10870. issuer: this.issuer.toJSON(),
  10871. serialNumber: this.serialNumber.toJSON(),
  10872. };
  10873. }
  10874. }
  10875. IssuerAndSerialNumber.CLASS_NAME = "IssuerAndSerialNumber";
  10876. const VARIANT$3 = "variant";
  10877. const VALUE$3 = "value";
  10878. const CLEAR_PROPS$B = [
  10879. "blockName"
  10880. ];
  10881. class RecipientIdentifier extends PkiObject {
  10882. constructor(parameters = {}) {
  10883. super();
  10884. this.variant = pvutils.getParametersValue(parameters, VARIANT$3, RecipientIdentifier.defaultValues(VARIANT$3));
  10885. if (VALUE$3 in parameters) {
  10886. this.value = pvutils.getParametersValue(parameters, VALUE$3, RecipientIdentifier.defaultValues(VALUE$3));
  10887. }
  10888. if (parameters.schema) {
  10889. this.fromSchema(parameters.schema);
  10890. }
  10891. }
  10892. static defaultValues(memberName) {
  10893. switch (memberName) {
  10894. case VARIANT$3:
  10895. return (-1);
  10896. case VALUE$3:
  10897. return {};
  10898. default:
  10899. return super.defaultValues(memberName);
  10900. }
  10901. }
  10902. static compareWithDefault(memberName, memberValue) {
  10903. switch (memberName) {
  10904. case VARIANT$3:
  10905. return (memberValue === (-1));
  10906. case VALUE$3:
  10907. return (Object.keys(memberValue).length === 0);
  10908. default:
  10909. return super.defaultValues(memberName);
  10910. }
  10911. }
  10912. static schema(parameters = {}) {
  10913. const names = pvutils.getParametersValue(parameters, "names", {});
  10914. return (new asn1js.Choice({
  10915. value: [
  10916. IssuerAndSerialNumber.schema({
  10917. names: {
  10918. blockName: (names.blockName || EMPTY_STRING)
  10919. }
  10920. }),
  10921. new asn1js.Primitive({
  10922. name: (names.blockName || EMPTY_STRING),
  10923. idBlock: {
  10924. tagClass: 3,
  10925. tagNumber: 0
  10926. }
  10927. })
  10928. ]
  10929. }));
  10930. }
  10931. fromSchema(schema) {
  10932. pvutils.clearProps(schema, CLEAR_PROPS$B);
  10933. const asn1 = asn1js.compareSchema(schema, schema, RecipientIdentifier.schema({
  10934. names: {
  10935. blockName: "blockName"
  10936. }
  10937. }));
  10938. AsnError.assertSchema(asn1, this.className);
  10939. if (asn1.result.blockName.idBlock.tagClass === 1) {
  10940. this.variant = 1;
  10941. this.value = new IssuerAndSerialNumber({ schema: asn1.result.blockName });
  10942. }
  10943. else {
  10944. this.variant = 2;
  10945. this.value = new asn1js.OctetString({ valueHex: asn1.result.blockName.valueBlock.valueHex });
  10946. }
  10947. }
  10948. toSchema() {
  10949. switch (this.variant) {
  10950. case 1:
  10951. if (!(this.value instanceof IssuerAndSerialNumber)) {
  10952. throw new Error("Incorrect type of RecipientIdentifier.value. It should be IssuerAndSerialNumber.");
  10953. }
  10954. return this.value.toSchema();
  10955. case 2:
  10956. if (!(this.value instanceof asn1js.OctetString)) {
  10957. throw new Error("Incorrect type of RecipientIdentifier.value. It should be ASN.1 OctetString.");
  10958. }
  10959. return new asn1js.Primitive({
  10960. idBlock: {
  10961. tagClass: 3,
  10962. tagNumber: 0
  10963. },
  10964. valueHex: this.value.valueBlock.valueHexView
  10965. });
  10966. default:
  10967. return new asn1js.Any();
  10968. }
  10969. }
  10970. toJSON() {
  10971. const res = {
  10972. variant: this.variant
  10973. };
  10974. if ((this.variant === 1 || this.variant === 2) && this.value) {
  10975. res.value = this.value.toJSON();
  10976. }
  10977. return res;
  10978. }
  10979. }
  10980. RecipientIdentifier.CLASS_NAME = "RecipientIdentifier";
  10981. const VERSION$c = "version";
  10982. const RID$1 = "rid";
  10983. const KEY_ENCRYPTION_ALGORITHM$3 = "keyEncryptionAlgorithm";
  10984. const ENCRYPTED_KEY$3 = "encryptedKey";
  10985. const RECIPIENT_CERTIFICATE$1 = "recipientCertificate";
  10986. const CLEAR_PROPS$A = [
  10987. VERSION$c,
  10988. RID$1,
  10989. KEY_ENCRYPTION_ALGORITHM$3,
  10990. ENCRYPTED_KEY$3,
  10991. ];
  10992. class KeyTransRecipientInfo extends PkiObject {
  10993. constructor(parameters = {}) {
  10994. super();
  10995. this.version = pvutils.getParametersValue(parameters, VERSION$c, KeyTransRecipientInfo.defaultValues(VERSION$c));
  10996. this.rid = pvutils.getParametersValue(parameters, RID$1, KeyTransRecipientInfo.defaultValues(RID$1));
  10997. this.keyEncryptionAlgorithm = pvutils.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM$3, KeyTransRecipientInfo.defaultValues(KEY_ENCRYPTION_ALGORITHM$3));
  10998. this.encryptedKey = pvutils.getParametersValue(parameters, ENCRYPTED_KEY$3, KeyTransRecipientInfo.defaultValues(ENCRYPTED_KEY$3));
  10999. this.recipientCertificate = pvutils.getParametersValue(parameters, RECIPIENT_CERTIFICATE$1, KeyTransRecipientInfo.defaultValues(RECIPIENT_CERTIFICATE$1));
  11000. if (parameters.schema) {
  11001. this.fromSchema(parameters.schema);
  11002. }
  11003. }
  11004. static defaultValues(memberName) {
  11005. switch (memberName) {
  11006. case VERSION$c:
  11007. return (-1);
  11008. case RID$1:
  11009. return {};
  11010. case KEY_ENCRYPTION_ALGORITHM$3:
  11011. return new AlgorithmIdentifier();
  11012. case ENCRYPTED_KEY$3:
  11013. return new asn1js.OctetString();
  11014. case RECIPIENT_CERTIFICATE$1:
  11015. return new Certificate();
  11016. default:
  11017. return super.defaultValues(memberName);
  11018. }
  11019. }
  11020. static compareWithDefault(memberName, memberValue) {
  11021. switch (memberName) {
  11022. case VERSION$c:
  11023. return (memberValue === KeyTransRecipientInfo.defaultValues(VERSION$c));
  11024. case RID$1:
  11025. return (Object.keys(memberValue).length === 0);
  11026. case KEY_ENCRYPTION_ALGORITHM$3:
  11027. case ENCRYPTED_KEY$3:
  11028. return memberValue.isEqual(KeyTransRecipientInfo.defaultValues(memberName));
  11029. case RECIPIENT_CERTIFICATE$1:
  11030. return false;
  11031. default:
  11032. return super.defaultValues(memberName);
  11033. }
  11034. }
  11035. static schema(parameters = {}) {
  11036. const names = pvutils.getParametersValue(parameters, "names", {});
  11037. return (new asn1js.Sequence({
  11038. name: (names.blockName || EMPTY_STRING),
  11039. value: [
  11040. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  11041. RecipientIdentifier.schema(names.rid || {}),
  11042. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  11043. new asn1js.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  11044. ]
  11045. }));
  11046. }
  11047. fromSchema(schema) {
  11048. pvutils.clearProps(schema, CLEAR_PROPS$A);
  11049. const asn1 = asn1js.compareSchema(schema, schema, KeyTransRecipientInfo.schema({
  11050. names: {
  11051. version: VERSION$c,
  11052. rid: {
  11053. names: {
  11054. blockName: RID$1
  11055. }
  11056. },
  11057. keyEncryptionAlgorithm: {
  11058. names: {
  11059. blockName: KEY_ENCRYPTION_ALGORITHM$3
  11060. }
  11061. },
  11062. encryptedKey: ENCRYPTED_KEY$3
  11063. }
  11064. }));
  11065. AsnError.assertSchema(asn1, this.className);
  11066. this.version = asn1.result.version.valueBlock.valueDec;
  11067. if (asn1.result.rid.idBlock.tagClass === 3) {
  11068. this.rid = new asn1js.OctetString({ valueHex: asn1.result.rid.valueBlock.valueHex });
  11069. }
  11070. else {
  11071. this.rid = new IssuerAndSerialNumber({ schema: asn1.result.rid });
  11072. }
  11073. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  11074. this.encryptedKey = asn1.result.encryptedKey;
  11075. }
  11076. toSchema() {
  11077. const outputArray = [];
  11078. if (this.rid instanceof IssuerAndSerialNumber) {
  11079. this.version = 0;
  11080. outputArray.push(new asn1js.Integer({ value: this.version }));
  11081. outputArray.push(this.rid.toSchema());
  11082. }
  11083. else {
  11084. this.version = 2;
  11085. outputArray.push(new asn1js.Integer({ value: this.version }));
  11086. outputArray.push(new asn1js.Primitive({
  11087. idBlock: {
  11088. tagClass: 3,
  11089. tagNumber: 0
  11090. },
  11091. valueHex: this.rid.valueBlock.valueHexView
  11092. }));
  11093. }
  11094. outputArray.push(this.keyEncryptionAlgorithm.toSchema());
  11095. outputArray.push(this.encryptedKey);
  11096. return (new asn1js.Sequence({
  11097. value: outputArray
  11098. }));
  11099. }
  11100. toJSON() {
  11101. return {
  11102. version: this.version,
  11103. rid: this.rid.toJSON(),
  11104. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  11105. encryptedKey: this.encryptedKey.toJSON(),
  11106. };
  11107. }
  11108. }
  11109. KeyTransRecipientInfo.CLASS_NAME = "KeyTransRecipientInfo";
  11110. const ALGORITHM = "algorithm";
  11111. const PUBLIC_KEY = "publicKey";
  11112. const CLEAR_PROPS$z = [
  11113. ALGORITHM,
  11114. PUBLIC_KEY
  11115. ];
  11116. class OriginatorPublicKey extends PkiObject {
  11117. constructor(parameters = {}) {
  11118. super();
  11119. this.algorithm = pvutils.getParametersValue(parameters, ALGORITHM, OriginatorPublicKey.defaultValues(ALGORITHM));
  11120. this.publicKey = pvutils.getParametersValue(parameters, PUBLIC_KEY, OriginatorPublicKey.defaultValues(PUBLIC_KEY));
  11121. if (parameters.schema) {
  11122. this.fromSchema(parameters.schema);
  11123. }
  11124. }
  11125. static defaultValues(memberName) {
  11126. switch (memberName) {
  11127. case ALGORITHM:
  11128. return new AlgorithmIdentifier();
  11129. case PUBLIC_KEY:
  11130. return new asn1js.BitString();
  11131. default:
  11132. return super.defaultValues(memberName);
  11133. }
  11134. }
  11135. static compareWithDefault(memberName, memberValue) {
  11136. switch (memberName) {
  11137. case ALGORITHM:
  11138. case PUBLIC_KEY:
  11139. return (memberValue.isEqual(OriginatorPublicKey.defaultValues(memberName)));
  11140. default:
  11141. return super.defaultValues(memberName);
  11142. }
  11143. }
  11144. static schema(parameters = {}) {
  11145. const names = pvutils.getParametersValue(parameters, "names", {});
  11146. return (new asn1js.Sequence({
  11147. name: (names.blockName || EMPTY_STRING),
  11148. value: [
  11149. AlgorithmIdentifier.schema(names.algorithm || {}),
  11150. new asn1js.BitString({ name: (names.publicKey || EMPTY_STRING) })
  11151. ]
  11152. }));
  11153. }
  11154. fromSchema(schema) {
  11155. pvutils.clearProps(schema, CLEAR_PROPS$z);
  11156. const asn1 = asn1js.compareSchema(schema, schema, OriginatorPublicKey.schema({
  11157. names: {
  11158. algorithm: {
  11159. names: {
  11160. blockName: ALGORITHM
  11161. }
  11162. },
  11163. publicKey: PUBLIC_KEY
  11164. }
  11165. }));
  11166. AsnError.assertSchema(asn1, this.className);
  11167. this.algorithm = new AlgorithmIdentifier({ schema: asn1.result.algorithm });
  11168. this.publicKey = asn1.result.publicKey;
  11169. }
  11170. toSchema() {
  11171. return (new asn1js.Sequence({
  11172. value: [
  11173. this.algorithm.toSchema(),
  11174. this.publicKey
  11175. ]
  11176. }));
  11177. }
  11178. toJSON() {
  11179. return {
  11180. algorithm: this.algorithm.toJSON(),
  11181. publicKey: this.publicKey.toJSON(),
  11182. };
  11183. }
  11184. }
  11185. OriginatorPublicKey.CLASS_NAME = "OriginatorPublicKey";
  11186. const VARIANT$2 = "variant";
  11187. const VALUE$2 = "value";
  11188. const CLEAR_PROPS$y = [
  11189. "blockName",
  11190. ];
  11191. class OriginatorIdentifierOrKey extends PkiObject {
  11192. constructor(parameters = {}) {
  11193. super();
  11194. this.variant = pvutils.getParametersValue(parameters, VARIANT$2, OriginatorIdentifierOrKey.defaultValues(VARIANT$2));
  11195. if (VALUE$2 in parameters) {
  11196. this.value = pvutils.getParametersValue(parameters, VALUE$2, OriginatorIdentifierOrKey.defaultValues(VALUE$2));
  11197. }
  11198. if (parameters.schema) {
  11199. this.fromSchema(parameters.schema);
  11200. }
  11201. }
  11202. static defaultValues(memberName) {
  11203. switch (memberName) {
  11204. case VARIANT$2:
  11205. return (-1);
  11206. case VALUE$2:
  11207. return {};
  11208. default:
  11209. return super.defaultValues(memberName);
  11210. }
  11211. }
  11212. static compareWithDefault(memberName, memberValue) {
  11213. switch (memberName) {
  11214. case VARIANT$2:
  11215. return (memberValue === (-1));
  11216. case VALUE$2:
  11217. return (Object.keys(memberValue).length === 0);
  11218. default:
  11219. return super.defaultValues(memberName);
  11220. }
  11221. }
  11222. static schema(parameters = {}) {
  11223. const names = pvutils.getParametersValue(parameters, "names", {});
  11224. return (new asn1js.Choice({
  11225. value: [
  11226. IssuerAndSerialNumber.schema({
  11227. names: {
  11228. blockName: (names.blockName || EMPTY_STRING)
  11229. }
  11230. }),
  11231. new asn1js.Primitive({
  11232. idBlock: {
  11233. tagClass: 3,
  11234. tagNumber: 0
  11235. },
  11236. name: (names.blockName || EMPTY_STRING)
  11237. }),
  11238. new asn1js.Constructed({
  11239. idBlock: {
  11240. tagClass: 3,
  11241. tagNumber: 1
  11242. },
  11243. name: (names.blockName || EMPTY_STRING),
  11244. value: OriginatorPublicKey.schema().valueBlock.value
  11245. })
  11246. ]
  11247. }));
  11248. }
  11249. fromSchema(schema) {
  11250. pvutils.clearProps(schema, CLEAR_PROPS$y);
  11251. const asn1 = asn1js.compareSchema(schema, schema, OriginatorIdentifierOrKey.schema({
  11252. names: {
  11253. blockName: "blockName"
  11254. }
  11255. }));
  11256. AsnError.assertSchema(asn1, this.className);
  11257. if (asn1.result.blockName.idBlock.tagClass === 1) {
  11258. this.variant = 1;
  11259. this.value = new IssuerAndSerialNumber({ schema: asn1.result.blockName });
  11260. }
  11261. else {
  11262. if (asn1.result.blockName.idBlock.tagNumber === 0) {
  11263. asn1.result.blockName.idBlock.tagClass = 1;
  11264. asn1.result.blockName.idBlock.tagNumber = 4;
  11265. this.variant = 2;
  11266. this.value = asn1.result.blockName;
  11267. }
  11268. else {
  11269. this.variant = 3;
  11270. this.value = new OriginatorPublicKey({
  11271. schema: new asn1js.Sequence({
  11272. value: asn1.result.blockName.valueBlock.value
  11273. })
  11274. });
  11275. }
  11276. }
  11277. }
  11278. toSchema() {
  11279. switch (this.variant) {
  11280. case 1:
  11281. return this.value.toSchema();
  11282. case 2:
  11283. this.value.idBlock.tagClass = 3;
  11284. this.value.idBlock.tagNumber = 0;
  11285. return this.value;
  11286. case 3:
  11287. {
  11288. const _schema = this.value.toSchema();
  11289. _schema.idBlock.tagClass = 3;
  11290. _schema.idBlock.tagNumber = 1;
  11291. return _schema;
  11292. }
  11293. default:
  11294. return new asn1js.Any();
  11295. }
  11296. }
  11297. toJSON() {
  11298. const res = {
  11299. variant: this.variant
  11300. };
  11301. if ((this.variant === 1) || (this.variant === 2) || (this.variant === 3)) {
  11302. res.value = this.value.toJSON();
  11303. }
  11304. return res;
  11305. }
  11306. }
  11307. OriginatorIdentifierOrKey.CLASS_NAME = "OriginatorIdentifierOrKey";
  11308. const KEY_ATTR_ID = "keyAttrId";
  11309. const KEY_ATTR = "keyAttr";
  11310. const CLEAR_PROPS$x = [
  11311. KEY_ATTR_ID,
  11312. KEY_ATTR,
  11313. ];
  11314. class OtherKeyAttribute extends PkiObject {
  11315. constructor(parameters = {}) {
  11316. super();
  11317. this.keyAttrId = pvutils.getParametersValue(parameters, KEY_ATTR_ID, OtherKeyAttribute.defaultValues(KEY_ATTR_ID));
  11318. if (KEY_ATTR in parameters) {
  11319. this.keyAttr = pvutils.getParametersValue(parameters, KEY_ATTR, OtherKeyAttribute.defaultValues(KEY_ATTR));
  11320. }
  11321. if (parameters.schema) {
  11322. this.fromSchema(parameters.schema);
  11323. }
  11324. }
  11325. static defaultValues(memberName) {
  11326. switch (memberName) {
  11327. case KEY_ATTR_ID:
  11328. return EMPTY_STRING;
  11329. case KEY_ATTR:
  11330. return {};
  11331. default:
  11332. return super.defaultValues(memberName);
  11333. }
  11334. }
  11335. static compareWithDefault(memberName, memberValue) {
  11336. switch (memberName) {
  11337. case KEY_ATTR_ID:
  11338. return (typeof memberValue === "string" && memberValue === EMPTY_STRING);
  11339. case KEY_ATTR:
  11340. return (Object.keys(memberValue).length === 0);
  11341. default:
  11342. return super.defaultValues(memberName);
  11343. }
  11344. }
  11345. static schema(parameters = {}) {
  11346. const names = pvutils.getParametersValue(parameters, "names", {});
  11347. return (new asn1js.Sequence({
  11348. optional: (names.optional || true),
  11349. name: (names.blockName || EMPTY_STRING),
  11350. value: [
  11351. new asn1js.ObjectIdentifier({ name: (names.keyAttrId || EMPTY_STRING) }),
  11352. new asn1js.Any({
  11353. optional: true,
  11354. name: (names.keyAttr || EMPTY_STRING)
  11355. })
  11356. ]
  11357. }));
  11358. }
  11359. fromSchema(schema) {
  11360. pvutils.clearProps(schema, CLEAR_PROPS$x);
  11361. const asn1 = asn1js.compareSchema(schema, schema, OtherKeyAttribute.schema({
  11362. names: {
  11363. keyAttrId: KEY_ATTR_ID,
  11364. keyAttr: KEY_ATTR
  11365. }
  11366. }));
  11367. AsnError.assertSchema(asn1, this.className);
  11368. this.keyAttrId = asn1.result.keyAttrId.valueBlock.toString();
  11369. if (KEY_ATTR in asn1.result) {
  11370. this.keyAttr = asn1.result.keyAttr;
  11371. }
  11372. }
  11373. toSchema() {
  11374. const outputArray = [];
  11375. outputArray.push(new asn1js.ObjectIdentifier({ value: this.keyAttrId }));
  11376. if (KEY_ATTR in this) {
  11377. outputArray.push(this.keyAttr);
  11378. }
  11379. return (new asn1js.Sequence({
  11380. value: outputArray,
  11381. }));
  11382. }
  11383. toJSON() {
  11384. const res = {
  11385. keyAttrId: this.keyAttrId
  11386. };
  11387. if (KEY_ATTR in this) {
  11388. res.keyAttr = this.keyAttr.toJSON();
  11389. }
  11390. return res;
  11391. }
  11392. }
  11393. OtherKeyAttribute.CLASS_NAME = "OtherKeyAttribute";
  11394. const SUBJECT_KEY_IDENTIFIER = "subjectKeyIdentifier";
  11395. const DATE$1 = "date";
  11396. const OTHER$1 = "other";
  11397. const CLEAR_PROPS$w = [
  11398. SUBJECT_KEY_IDENTIFIER,
  11399. DATE$1,
  11400. OTHER$1,
  11401. ];
  11402. class RecipientKeyIdentifier extends PkiObject {
  11403. constructor(parameters = {}) {
  11404. super();
  11405. this.subjectKeyIdentifier = pvutils.getParametersValue(parameters, SUBJECT_KEY_IDENTIFIER, RecipientKeyIdentifier.defaultValues(SUBJECT_KEY_IDENTIFIER));
  11406. if (DATE$1 in parameters) {
  11407. this.date = pvutils.getParametersValue(parameters, DATE$1, RecipientKeyIdentifier.defaultValues(DATE$1));
  11408. }
  11409. if (OTHER$1 in parameters) {
  11410. this.other = pvutils.getParametersValue(parameters, OTHER$1, RecipientKeyIdentifier.defaultValues(OTHER$1));
  11411. }
  11412. if (parameters.schema) {
  11413. this.fromSchema(parameters.schema);
  11414. }
  11415. }
  11416. static defaultValues(memberName) {
  11417. switch (memberName) {
  11418. case SUBJECT_KEY_IDENTIFIER:
  11419. return new asn1js.OctetString();
  11420. case DATE$1:
  11421. return new asn1js.GeneralizedTime();
  11422. case OTHER$1:
  11423. return new OtherKeyAttribute();
  11424. default:
  11425. return super.defaultValues(memberName);
  11426. }
  11427. }
  11428. static compareWithDefault(memberName, memberValue) {
  11429. switch (memberName) {
  11430. case SUBJECT_KEY_IDENTIFIER:
  11431. return (memberValue.isEqual(RecipientKeyIdentifier.defaultValues(SUBJECT_KEY_IDENTIFIER)));
  11432. case DATE$1:
  11433. return ((memberValue.year === 0) &&
  11434. (memberValue.month === 0) &&
  11435. (memberValue.day === 0) &&
  11436. (memberValue.hour === 0) &&
  11437. (memberValue.minute === 0) &&
  11438. (memberValue.second === 0) &&
  11439. (memberValue.millisecond === 0));
  11440. case OTHER$1:
  11441. return ((memberValue.keyAttrId === EMPTY_STRING) && (("keyAttr" in memberValue) === false));
  11442. default:
  11443. return super.defaultValues(memberName);
  11444. }
  11445. }
  11446. static schema(parameters = {}) {
  11447. const names = pvutils.getParametersValue(parameters, "names", {});
  11448. return (new asn1js.Sequence({
  11449. name: (names.blockName || EMPTY_STRING),
  11450. value: [
  11451. new asn1js.OctetString({ name: (names.subjectKeyIdentifier || EMPTY_STRING) }),
  11452. new asn1js.GeneralizedTime({
  11453. optional: true,
  11454. name: (names.date || EMPTY_STRING)
  11455. }),
  11456. OtherKeyAttribute.schema(names.other || {})
  11457. ]
  11458. }));
  11459. }
  11460. fromSchema(schema) {
  11461. pvutils.clearProps(schema, CLEAR_PROPS$w);
  11462. const asn1 = asn1js.compareSchema(schema, schema, RecipientKeyIdentifier.schema({
  11463. names: {
  11464. subjectKeyIdentifier: SUBJECT_KEY_IDENTIFIER,
  11465. date: DATE$1,
  11466. other: {
  11467. names: {
  11468. blockName: OTHER$1
  11469. }
  11470. }
  11471. }
  11472. }));
  11473. AsnError.assertSchema(asn1, this.className);
  11474. this.subjectKeyIdentifier = asn1.result.subjectKeyIdentifier;
  11475. if (DATE$1 in asn1.result)
  11476. this.date = asn1.result.date;
  11477. if (OTHER$1 in asn1.result)
  11478. this.other = new OtherKeyAttribute({ schema: asn1.result.other });
  11479. }
  11480. toSchema() {
  11481. const outputArray = [];
  11482. outputArray.push(this.subjectKeyIdentifier);
  11483. if (this.date) {
  11484. outputArray.push(this.date);
  11485. }
  11486. if (this.other) {
  11487. outputArray.push(this.other.toSchema());
  11488. }
  11489. return (new asn1js.Sequence({
  11490. value: outputArray
  11491. }));
  11492. }
  11493. toJSON() {
  11494. const res = {
  11495. subjectKeyIdentifier: this.subjectKeyIdentifier.toJSON()
  11496. };
  11497. if (this.date) {
  11498. res.date = this.date.toJSON();
  11499. }
  11500. if (this.other) {
  11501. res.other = this.other.toJSON();
  11502. }
  11503. return res;
  11504. }
  11505. }
  11506. RecipientKeyIdentifier.CLASS_NAME = "RecipientKeyIdentifier";
  11507. const VARIANT$1 = "variant";
  11508. const VALUE$1 = "value";
  11509. const CLEAR_PROPS$v = [
  11510. "blockName",
  11511. ];
  11512. class KeyAgreeRecipientIdentifier extends PkiObject {
  11513. constructor(parameters = {}) {
  11514. super();
  11515. this.variant = pvutils.getParametersValue(parameters, VARIANT$1, KeyAgreeRecipientIdentifier.defaultValues(VARIANT$1));
  11516. this.value = pvutils.getParametersValue(parameters, VALUE$1, KeyAgreeRecipientIdentifier.defaultValues(VALUE$1));
  11517. if (parameters.schema) {
  11518. this.fromSchema(parameters.schema);
  11519. }
  11520. }
  11521. static defaultValues(memberName) {
  11522. switch (memberName) {
  11523. case VARIANT$1:
  11524. return (-1);
  11525. case VALUE$1:
  11526. return {};
  11527. default:
  11528. return super.defaultValues(memberName);
  11529. }
  11530. }
  11531. static compareWithDefault(memberName, memberValue) {
  11532. switch (memberName) {
  11533. case VARIANT$1:
  11534. return (memberValue === (-1));
  11535. case VALUE$1:
  11536. return (Object.keys(memberValue).length === 0);
  11537. default:
  11538. return super.defaultValues(memberName);
  11539. }
  11540. }
  11541. static schema(parameters = {}) {
  11542. const names = pvutils.getParametersValue(parameters, "names", {});
  11543. return (new asn1js.Choice({
  11544. value: [
  11545. IssuerAndSerialNumber.schema(names.issuerAndSerialNumber || {
  11546. names: {
  11547. blockName: (names.blockName || EMPTY_STRING)
  11548. }
  11549. }),
  11550. new asn1js.Constructed({
  11551. name: (names.blockName || EMPTY_STRING),
  11552. idBlock: {
  11553. tagClass: 3,
  11554. tagNumber: 0
  11555. },
  11556. value: RecipientKeyIdentifier.schema(names.rKeyId || {
  11557. names: {
  11558. blockName: (names.blockName || EMPTY_STRING)
  11559. }
  11560. }).valueBlock.value
  11561. })
  11562. ]
  11563. }));
  11564. }
  11565. fromSchema(schema) {
  11566. pvutils.clearProps(schema, CLEAR_PROPS$v);
  11567. const asn1 = asn1js.compareSchema(schema, schema, KeyAgreeRecipientIdentifier.schema({
  11568. names: {
  11569. blockName: "blockName"
  11570. }
  11571. }));
  11572. AsnError.assertSchema(asn1, this.className);
  11573. if (asn1.result.blockName.idBlock.tagClass === 1) {
  11574. this.variant = 1;
  11575. this.value = new IssuerAndSerialNumber({ schema: asn1.result.blockName });
  11576. }
  11577. else {
  11578. this.variant = 2;
  11579. this.value = new RecipientKeyIdentifier({
  11580. schema: new asn1js.Sequence({
  11581. value: asn1.result.blockName.valueBlock.value
  11582. })
  11583. });
  11584. }
  11585. }
  11586. toSchema() {
  11587. switch (this.variant) {
  11588. case 1:
  11589. return this.value.toSchema();
  11590. case 2:
  11591. return new asn1js.Constructed({
  11592. idBlock: {
  11593. tagClass: 3,
  11594. tagNumber: 0
  11595. },
  11596. value: this.value.toSchema().valueBlock.value
  11597. });
  11598. default:
  11599. return new asn1js.Any();
  11600. }
  11601. }
  11602. toJSON() {
  11603. const res = {
  11604. variant: this.variant,
  11605. };
  11606. if ((this.variant === 1) || (this.variant === 2)) {
  11607. res.value = this.value.toJSON();
  11608. }
  11609. return res;
  11610. }
  11611. }
  11612. KeyAgreeRecipientIdentifier.CLASS_NAME = "KeyAgreeRecipientIdentifier";
  11613. const RID = "rid";
  11614. const ENCRYPTED_KEY$2 = "encryptedKey";
  11615. const CLEAR_PROPS$u = [
  11616. RID,
  11617. ENCRYPTED_KEY$2,
  11618. ];
  11619. class RecipientEncryptedKey extends PkiObject {
  11620. constructor(parameters = {}) {
  11621. super();
  11622. this.rid = pvutils.getParametersValue(parameters, RID, RecipientEncryptedKey.defaultValues(RID));
  11623. this.encryptedKey = pvutils.getParametersValue(parameters, ENCRYPTED_KEY$2, RecipientEncryptedKey.defaultValues(ENCRYPTED_KEY$2));
  11624. if (parameters.schema) {
  11625. this.fromSchema(parameters.schema);
  11626. }
  11627. }
  11628. static defaultValues(memberName) {
  11629. switch (memberName) {
  11630. case RID:
  11631. return new KeyAgreeRecipientIdentifier();
  11632. case ENCRYPTED_KEY$2:
  11633. return new asn1js.OctetString();
  11634. default:
  11635. return super.defaultValues(memberName);
  11636. }
  11637. }
  11638. static compareWithDefault(memberName, memberValue) {
  11639. switch (memberName) {
  11640. case RID:
  11641. return ((memberValue.variant === (-1)) && (("value" in memberValue) === false));
  11642. case ENCRYPTED_KEY$2:
  11643. return (memberValue.isEqual(RecipientEncryptedKey.defaultValues(ENCRYPTED_KEY$2)));
  11644. default:
  11645. return super.defaultValues(memberName);
  11646. }
  11647. }
  11648. static schema(parameters = {}) {
  11649. const names = pvutils.getParametersValue(parameters, "names", {});
  11650. return (new asn1js.Sequence({
  11651. name: (names.blockName || EMPTY_STRING),
  11652. value: [
  11653. KeyAgreeRecipientIdentifier.schema(names.rid || {}),
  11654. new asn1js.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  11655. ]
  11656. }));
  11657. }
  11658. fromSchema(schema) {
  11659. pvutils.clearProps(schema, CLEAR_PROPS$u);
  11660. const asn1 = asn1js.compareSchema(schema, schema, RecipientEncryptedKey.schema({
  11661. names: {
  11662. rid: {
  11663. names: {
  11664. blockName: RID
  11665. }
  11666. },
  11667. encryptedKey: ENCRYPTED_KEY$2
  11668. }
  11669. }));
  11670. AsnError.assertSchema(asn1, this.className);
  11671. this.rid = new KeyAgreeRecipientIdentifier({ schema: asn1.result.rid });
  11672. this.encryptedKey = asn1.result.encryptedKey;
  11673. }
  11674. toSchema() {
  11675. return (new asn1js.Sequence({
  11676. value: [
  11677. this.rid.toSchema(),
  11678. this.encryptedKey
  11679. ]
  11680. }));
  11681. }
  11682. toJSON() {
  11683. return {
  11684. rid: this.rid.toJSON(),
  11685. encryptedKey: this.encryptedKey.toJSON(),
  11686. };
  11687. }
  11688. }
  11689. RecipientEncryptedKey.CLASS_NAME = "RecipientEncryptedKey";
  11690. const ENCRYPTED_KEYS = "encryptedKeys";
  11691. const RECIPIENT_ENCRYPTED_KEYS = "RecipientEncryptedKeys";
  11692. const CLEAR_PROPS$t = [
  11693. RECIPIENT_ENCRYPTED_KEYS,
  11694. ];
  11695. class RecipientEncryptedKeys extends PkiObject {
  11696. constructor(parameters = {}) {
  11697. super();
  11698. this.encryptedKeys = pvutils.getParametersValue(parameters, ENCRYPTED_KEYS, RecipientEncryptedKeys.defaultValues(ENCRYPTED_KEYS));
  11699. if (parameters.schema) {
  11700. this.fromSchema(parameters.schema);
  11701. }
  11702. }
  11703. static defaultValues(memberName) {
  11704. switch (memberName) {
  11705. case ENCRYPTED_KEYS:
  11706. return [];
  11707. default:
  11708. return super.defaultValues(memberName);
  11709. }
  11710. }
  11711. static compareWithDefault(memberName, memberValue) {
  11712. switch (memberName) {
  11713. case ENCRYPTED_KEYS:
  11714. return (memberValue.length === 0);
  11715. default:
  11716. return super.defaultValues(memberName);
  11717. }
  11718. }
  11719. static schema(parameters = {}) {
  11720. const names = pvutils.getParametersValue(parameters, "names", {});
  11721. return (new asn1js.Sequence({
  11722. name: (names.blockName || EMPTY_STRING),
  11723. value: [
  11724. new asn1js.Repeated({
  11725. name: (names.RecipientEncryptedKeys || EMPTY_STRING),
  11726. value: RecipientEncryptedKey.schema()
  11727. })
  11728. ]
  11729. }));
  11730. }
  11731. fromSchema(schema) {
  11732. pvutils.clearProps(schema, CLEAR_PROPS$t);
  11733. const asn1 = asn1js.compareSchema(schema, schema, RecipientEncryptedKeys.schema({
  11734. names: {
  11735. RecipientEncryptedKeys: RECIPIENT_ENCRYPTED_KEYS
  11736. }
  11737. }));
  11738. AsnError.assertSchema(asn1, this.className);
  11739. this.encryptedKeys = Array.from(asn1.result.RecipientEncryptedKeys, element => new RecipientEncryptedKey({ schema: element }));
  11740. }
  11741. toSchema() {
  11742. return (new asn1js.Sequence({
  11743. value: Array.from(this.encryptedKeys, o => o.toSchema())
  11744. }));
  11745. }
  11746. toJSON() {
  11747. return {
  11748. encryptedKeys: Array.from(this.encryptedKeys, o => o.toJSON())
  11749. };
  11750. }
  11751. }
  11752. RecipientEncryptedKeys.CLASS_NAME = "RecipientEncryptedKeys";
  11753. const VERSION$b = "version";
  11754. const ORIGINATOR = "originator";
  11755. const UKM = "ukm";
  11756. const KEY_ENCRYPTION_ALGORITHM$2 = "keyEncryptionAlgorithm";
  11757. const RECIPIENT_ENCRYPTED_KEY = "recipientEncryptedKeys";
  11758. const RECIPIENT_CERTIFICATE = "recipientCertificate";
  11759. const RECIPIENT_PUBLIC_KEY = "recipientPublicKey";
  11760. const CLEAR_PROPS$s = [
  11761. VERSION$b,
  11762. ORIGINATOR,
  11763. UKM,
  11764. KEY_ENCRYPTION_ALGORITHM$2,
  11765. RECIPIENT_ENCRYPTED_KEY,
  11766. ];
  11767. class KeyAgreeRecipientInfo extends PkiObject {
  11768. constructor(parameters = {}) {
  11769. super();
  11770. this.version = pvutils.getParametersValue(parameters, VERSION$b, KeyAgreeRecipientInfo.defaultValues(VERSION$b));
  11771. this.originator = pvutils.getParametersValue(parameters, ORIGINATOR, KeyAgreeRecipientInfo.defaultValues(ORIGINATOR));
  11772. if (UKM in parameters) {
  11773. this.ukm = pvutils.getParametersValue(parameters, UKM, KeyAgreeRecipientInfo.defaultValues(UKM));
  11774. }
  11775. this.keyEncryptionAlgorithm = pvutils.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM$2, KeyAgreeRecipientInfo.defaultValues(KEY_ENCRYPTION_ALGORITHM$2));
  11776. this.recipientEncryptedKeys = pvutils.getParametersValue(parameters, RECIPIENT_ENCRYPTED_KEY, KeyAgreeRecipientInfo.defaultValues(RECIPIENT_ENCRYPTED_KEY));
  11777. this.recipientCertificate = pvutils.getParametersValue(parameters, RECIPIENT_CERTIFICATE, KeyAgreeRecipientInfo.defaultValues(RECIPIENT_CERTIFICATE));
  11778. this.recipientPublicKey = pvutils.getParametersValue(parameters, RECIPIENT_PUBLIC_KEY, KeyAgreeRecipientInfo.defaultValues(RECIPIENT_PUBLIC_KEY));
  11779. if (parameters.schema) {
  11780. this.fromSchema(parameters.schema);
  11781. }
  11782. }
  11783. static defaultValues(memberName) {
  11784. switch (memberName) {
  11785. case VERSION$b:
  11786. return 0;
  11787. case ORIGINATOR:
  11788. return new OriginatorIdentifierOrKey();
  11789. case UKM:
  11790. return new asn1js.OctetString();
  11791. case KEY_ENCRYPTION_ALGORITHM$2:
  11792. return new AlgorithmIdentifier();
  11793. case RECIPIENT_ENCRYPTED_KEY:
  11794. return new RecipientEncryptedKeys();
  11795. case RECIPIENT_CERTIFICATE:
  11796. return new Certificate();
  11797. case RECIPIENT_PUBLIC_KEY:
  11798. return null;
  11799. default:
  11800. return super.defaultValues(memberName);
  11801. }
  11802. }
  11803. static compareWithDefault(memberName, memberValue) {
  11804. switch (memberName) {
  11805. case VERSION$b:
  11806. return (memberValue === 0);
  11807. case ORIGINATOR:
  11808. return ((memberValue.variant === (-1)) && (("value" in memberValue) === false));
  11809. case UKM:
  11810. return (memberValue.isEqual(KeyAgreeRecipientInfo.defaultValues(UKM)));
  11811. case KEY_ENCRYPTION_ALGORITHM$2:
  11812. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  11813. case RECIPIENT_ENCRYPTED_KEY:
  11814. return (memberValue.encryptedKeys.length === 0);
  11815. case RECIPIENT_CERTIFICATE:
  11816. return false;
  11817. case RECIPIENT_PUBLIC_KEY:
  11818. return false;
  11819. default:
  11820. return super.defaultValues(memberName);
  11821. }
  11822. }
  11823. static schema(parameters = {}) {
  11824. const names = pvutils.getParametersValue(parameters, "names", {});
  11825. return (new asn1js.Sequence({
  11826. name: names.blockName || EMPTY_STRING,
  11827. value: [
  11828. new asn1js.Integer({ name: names.version || EMPTY_STRING }),
  11829. new asn1js.Constructed({
  11830. idBlock: {
  11831. tagClass: 3,
  11832. tagNumber: 0
  11833. },
  11834. value: [
  11835. OriginatorIdentifierOrKey.schema(names.originator || {})
  11836. ]
  11837. }),
  11838. new asn1js.Constructed({
  11839. optional: true,
  11840. idBlock: {
  11841. tagClass: 3,
  11842. tagNumber: 1
  11843. },
  11844. value: [new asn1js.OctetString({ name: names.ukm || EMPTY_STRING })]
  11845. }),
  11846. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  11847. RecipientEncryptedKeys.schema(names.recipientEncryptedKeys || {})
  11848. ]
  11849. }));
  11850. }
  11851. fromSchema(schema) {
  11852. pvutils.clearProps(schema, CLEAR_PROPS$s);
  11853. const asn1 = asn1js.compareSchema(schema, schema, KeyAgreeRecipientInfo.schema({
  11854. names: {
  11855. version: VERSION$b,
  11856. originator: {
  11857. names: {
  11858. blockName: ORIGINATOR
  11859. }
  11860. },
  11861. ukm: UKM,
  11862. keyEncryptionAlgorithm: {
  11863. names: {
  11864. blockName: KEY_ENCRYPTION_ALGORITHM$2
  11865. }
  11866. },
  11867. recipientEncryptedKeys: {
  11868. names: {
  11869. blockName: RECIPIENT_ENCRYPTED_KEY
  11870. }
  11871. }
  11872. }
  11873. }));
  11874. AsnError.assertSchema(asn1, this.className);
  11875. this.version = asn1.result.version.valueBlock.valueDec;
  11876. this.originator = new OriginatorIdentifierOrKey({ schema: asn1.result.originator });
  11877. if (UKM in asn1.result)
  11878. this.ukm = asn1.result.ukm;
  11879. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  11880. this.recipientEncryptedKeys = new RecipientEncryptedKeys({ schema: asn1.result.recipientEncryptedKeys });
  11881. }
  11882. toSchema() {
  11883. const outputArray = [];
  11884. outputArray.push(new asn1js.Integer({ value: this.version }));
  11885. outputArray.push(new asn1js.Constructed({
  11886. idBlock: {
  11887. tagClass: 3,
  11888. tagNumber: 0
  11889. },
  11890. value: [this.originator.toSchema()]
  11891. }));
  11892. if (this.ukm) {
  11893. outputArray.push(new asn1js.Constructed({
  11894. optional: true,
  11895. idBlock: {
  11896. tagClass: 3,
  11897. tagNumber: 1
  11898. },
  11899. value: [this.ukm]
  11900. }));
  11901. }
  11902. outputArray.push(this.keyEncryptionAlgorithm.toSchema());
  11903. outputArray.push(this.recipientEncryptedKeys.toSchema());
  11904. return (new asn1js.Sequence({
  11905. value: outputArray
  11906. }));
  11907. }
  11908. toJSON() {
  11909. const res = {
  11910. version: this.version,
  11911. originator: this.originator.toJSON(),
  11912. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  11913. recipientEncryptedKeys: this.recipientEncryptedKeys.toJSON(),
  11914. };
  11915. if (this.ukm) {
  11916. res.ukm = this.ukm.toJSON();
  11917. }
  11918. return res;
  11919. }
  11920. }
  11921. KeyAgreeRecipientInfo.CLASS_NAME = "KeyAgreeRecipientInfo";
  11922. const KEY_IDENTIFIER = "keyIdentifier";
  11923. const DATE = "date";
  11924. const OTHER = "other";
  11925. const CLEAR_PROPS$r = [
  11926. KEY_IDENTIFIER,
  11927. DATE,
  11928. OTHER,
  11929. ];
  11930. class KEKIdentifier extends PkiObject {
  11931. constructor(parameters = {}) {
  11932. super();
  11933. this.keyIdentifier = pvutils.getParametersValue(parameters, KEY_IDENTIFIER, KEKIdentifier.defaultValues(KEY_IDENTIFIER));
  11934. if (DATE in parameters) {
  11935. this.date = pvutils.getParametersValue(parameters, DATE, KEKIdentifier.defaultValues(DATE));
  11936. }
  11937. if (OTHER in parameters) {
  11938. this.other = pvutils.getParametersValue(parameters, OTHER, KEKIdentifier.defaultValues(OTHER));
  11939. }
  11940. if (parameters.schema) {
  11941. this.fromSchema(parameters.schema);
  11942. }
  11943. }
  11944. static defaultValues(memberName) {
  11945. switch (memberName) {
  11946. case KEY_IDENTIFIER:
  11947. return new asn1js.OctetString();
  11948. case DATE:
  11949. return new asn1js.GeneralizedTime();
  11950. case OTHER:
  11951. return new OtherKeyAttribute();
  11952. default:
  11953. return super.defaultValues(memberName);
  11954. }
  11955. }
  11956. static compareWithDefault(memberName, memberValue) {
  11957. switch (memberName) {
  11958. case KEY_IDENTIFIER:
  11959. return (memberValue.isEqual(KEKIdentifier.defaultValues(KEY_IDENTIFIER)));
  11960. case DATE:
  11961. return ((memberValue.year === 0) &&
  11962. (memberValue.month === 0) &&
  11963. (memberValue.day === 0) &&
  11964. (memberValue.hour === 0) &&
  11965. (memberValue.minute === 0) &&
  11966. (memberValue.second === 0) &&
  11967. (memberValue.millisecond === 0));
  11968. case OTHER:
  11969. return ((memberValue.compareWithDefault("keyAttrId", memberValue.keyAttrId)) &&
  11970. (("keyAttr" in memberValue) === false));
  11971. default:
  11972. return super.defaultValues(memberName);
  11973. }
  11974. }
  11975. static schema(parameters = {}) {
  11976. const names = pvutils.getParametersValue(parameters, "names", {});
  11977. return (new asn1js.Sequence({
  11978. name: (names.blockName || EMPTY_STRING),
  11979. value: [
  11980. new asn1js.OctetString({ name: (names.keyIdentifier || EMPTY_STRING) }),
  11981. new asn1js.GeneralizedTime({
  11982. optional: true,
  11983. name: (names.date || EMPTY_STRING)
  11984. }),
  11985. OtherKeyAttribute.schema(names.other || {})
  11986. ]
  11987. }));
  11988. }
  11989. fromSchema(schema) {
  11990. pvutils.clearProps(schema, CLEAR_PROPS$r);
  11991. const asn1 = asn1js.compareSchema(schema, schema, KEKIdentifier.schema({
  11992. names: {
  11993. keyIdentifier: KEY_IDENTIFIER,
  11994. date: DATE,
  11995. other: {
  11996. names: {
  11997. blockName: OTHER
  11998. }
  11999. }
  12000. }
  12001. }));
  12002. AsnError.assertSchema(asn1, this.className);
  12003. this.keyIdentifier = asn1.result.keyIdentifier;
  12004. if (DATE in asn1.result)
  12005. this.date = asn1.result.date;
  12006. if (OTHER in asn1.result)
  12007. this.other = new OtherKeyAttribute({ schema: asn1.result.other });
  12008. }
  12009. toSchema() {
  12010. const outputArray = [];
  12011. outputArray.push(this.keyIdentifier);
  12012. if (this.date) {
  12013. outputArray.push(this.date);
  12014. }
  12015. if (this.other) {
  12016. outputArray.push(this.other.toSchema());
  12017. }
  12018. return (new asn1js.Sequence({
  12019. value: outputArray
  12020. }));
  12021. }
  12022. toJSON() {
  12023. const res = {
  12024. keyIdentifier: this.keyIdentifier.toJSON()
  12025. };
  12026. if (this.date) {
  12027. res.date = this.date;
  12028. }
  12029. if (this.other) {
  12030. res.other = this.other.toJSON();
  12031. }
  12032. return res;
  12033. }
  12034. }
  12035. KEKIdentifier.CLASS_NAME = "KEKIdentifier";
  12036. const VERSION$a = "version";
  12037. const KEK_ID = "kekid";
  12038. const KEY_ENCRYPTION_ALGORITHM$1 = "keyEncryptionAlgorithm";
  12039. const ENCRYPTED_KEY$1 = "encryptedKey";
  12040. const PER_DEFINED_KEK = "preDefinedKEK";
  12041. const CLEAR_PROPS$q = [
  12042. VERSION$a,
  12043. KEK_ID,
  12044. KEY_ENCRYPTION_ALGORITHM$1,
  12045. ENCRYPTED_KEY$1,
  12046. ];
  12047. class KEKRecipientInfo extends PkiObject {
  12048. constructor(parameters = {}) {
  12049. super();
  12050. this.version = pvutils.getParametersValue(parameters, VERSION$a, KEKRecipientInfo.defaultValues(VERSION$a));
  12051. this.kekid = pvutils.getParametersValue(parameters, KEK_ID, KEKRecipientInfo.defaultValues(KEK_ID));
  12052. this.keyEncryptionAlgorithm = pvutils.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM$1, KEKRecipientInfo.defaultValues(KEY_ENCRYPTION_ALGORITHM$1));
  12053. this.encryptedKey = pvutils.getParametersValue(parameters, ENCRYPTED_KEY$1, KEKRecipientInfo.defaultValues(ENCRYPTED_KEY$1));
  12054. this.preDefinedKEK = pvutils.getParametersValue(parameters, PER_DEFINED_KEK, KEKRecipientInfo.defaultValues(PER_DEFINED_KEK));
  12055. if (parameters.schema) {
  12056. this.fromSchema(parameters.schema);
  12057. }
  12058. }
  12059. static defaultValues(memberName) {
  12060. switch (memberName) {
  12061. case VERSION$a:
  12062. return 0;
  12063. case KEK_ID:
  12064. return new KEKIdentifier();
  12065. case KEY_ENCRYPTION_ALGORITHM$1:
  12066. return new AlgorithmIdentifier();
  12067. case ENCRYPTED_KEY$1:
  12068. return new asn1js.OctetString();
  12069. case PER_DEFINED_KEK:
  12070. return EMPTY_BUFFER;
  12071. default:
  12072. return super.defaultValues(memberName);
  12073. }
  12074. }
  12075. static compareWithDefault(memberName, memberValue) {
  12076. switch (memberName) {
  12077. case "KEKRecipientInfo":
  12078. return (memberValue === KEKRecipientInfo.defaultValues(VERSION$a));
  12079. case KEK_ID:
  12080. return ((memberValue.compareWithDefault("keyIdentifier", memberValue.keyIdentifier)) &&
  12081. (("date" in memberValue) === false) &&
  12082. (("other" in memberValue) === false));
  12083. case KEY_ENCRYPTION_ALGORITHM$1:
  12084. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  12085. case ENCRYPTED_KEY$1:
  12086. return (memberValue.isEqual(KEKRecipientInfo.defaultValues(ENCRYPTED_KEY$1)));
  12087. case PER_DEFINED_KEK:
  12088. return (memberValue.byteLength === 0);
  12089. default:
  12090. return super.defaultValues(memberName);
  12091. }
  12092. }
  12093. static schema(parameters = {}) {
  12094. const names = pvutils.getParametersValue(parameters, "names", {});
  12095. return (new asn1js.Sequence({
  12096. name: (names.blockName || EMPTY_STRING),
  12097. value: [
  12098. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  12099. KEKIdentifier.schema(names.kekid || {}),
  12100. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  12101. new asn1js.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  12102. ]
  12103. }));
  12104. }
  12105. fromSchema(schema) {
  12106. pvutils.clearProps(schema, CLEAR_PROPS$q);
  12107. const asn1 = asn1js.compareSchema(schema, schema, KEKRecipientInfo.schema({
  12108. names: {
  12109. version: VERSION$a,
  12110. kekid: {
  12111. names: {
  12112. blockName: KEK_ID
  12113. }
  12114. },
  12115. keyEncryptionAlgorithm: {
  12116. names: {
  12117. blockName: KEY_ENCRYPTION_ALGORITHM$1
  12118. }
  12119. },
  12120. encryptedKey: ENCRYPTED_KEY$1
  12121. }
  12122. }));
  12123. AsnError.assertSchema(asn1, this.className);
  12124. this.version = asn1.result.version.valueBlock.valueDec;
  12125. this.kekid = new KEKIdentifier({ schema: asn1.result.kekid });
  12126. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  12127. this.encryptedKey = asn1.result.encryptedKey;
  12128. }
  12129. toSchema() {
  12130. return (new asn1js.Sequence({
  12131. value: [
  12132. new asn1js.Integer({ value: this.version }),
  12133. this.kekid.toSchema(),
  12134. this.keyEncryptionAlgorithm.toSchema(),
  12135. this.encryptedKey
  12136. ]
  12137. }));
  12138. }
  12139. toJSON() {
  12140. return {
  12141. version: this.version,
  12142. kekid: this.kekid.toJSON(),
  12143. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  12144. encryptedKey: this.encryptedKey.toJSON(),
  12145. };
  12146. }
  12147. }
  12148. KEKRecipientInfo.CLASS_NAME = "KEKRecipientInfo";
  12149. const VERSION$9 = "version";
  12150. const KEY_DERIVATION_ALGORITHM = "keyDerivationAlgorithm";
  12151. const KEY_ENCRYPTION_ALGORITHM = "keyEncryptionAlgorithm";
  12152. const ENCRYPTED_KEY = "encryptedKey";
  12153. const PASSWORD = "password";
  12154. const CLEAR_PROPS$p = [
  12155. VERSION$9,
  12156. KEY_DERIVATION_ALGORITHM,
  12157. KEY_ENCRYPTION_ALGORITHM,
  12158. ENCRYPTED_KEY
  12159. ];
  12160. class PasswordRecipientinfo extends PkiObject {
  12161. constructor(parameters = {}) {
  12162. super();
  12163. this.version = pvutils.getParametersValue(parameters, VERSION$9, PasswordRecipientinfo.defaultValues(VERSION$9));
  12164. if (KEY_DERIVATION_ALGORITHM in parameters) {
  12165. this.keyDerivationAlgorithm = pvutils.getParametersValue(parameters, KEY_DERIVATION_ALGORITHM, PasswordRecipientinfo.defaultValues(KEY_DERIVATION_ALGORITHM));
  12166. }
  12167. this.keyEncryptionAlgorithm = pvutils.getParametersValue(parameters, KEY_ENCRYPTION_ALGORITHM, PasswordRecipientinfo.defaultValues(KEY_ENCRYPTION_ALGORITHM));
  12168. this.encryptedKey = pvutils.getParametersValue(parameters, ENCRYPTED_KEY, PasswordRecipientinfo.defaultValues(ENCRYPTED_KEY));
  12169. this.password = pvutils.getParametersValue(parameters, PASSWORD, PasswordRecipientinfo.defaultValues(PASSWORD));
  12170. if (parameters.schema) {
  12171. this.fromSchema(parameters.schema);
  12172. }
  12173. }
  12174. static defaultValues(memberName) {
  12175. switch (memberName) {
  12176. case VERSION$9:
  12177. return (-1);
  12178. case KEY_DERIVATION_ALGORITHM:
  12179. return new AlgorithmIdentifier();
  12180. case KEY_ENCRYPTION_ALGORITHM:
  12181. return new AlgorithmIdentifier();
  12182. case ENCRYPTED_KEY:
  12183. return new asn1js.OctetString();
  12184. case PASSWORD:
  12185. return EMPTY_BUFFER;
  12186. default:
  12187. return super.defaultValues(memberName);
  12188. }
  12189. }
  12190. static compareWithDefault(memberName, memberValue) {
  12191. switch (memberName) {
  12192. case VERSION$9:
  12193. return (memberValue === (-1));
  12194. case KEY_DERIVATION_ALGORITHM:
  12195. case KEY_ENCRYPTION_ALGORITHM:
  12196. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  12197. case ENCRYPTED_KEY:
  12198. return (memberValue.isEqual(PasswordRecipientinfo.defaultValues(ENCRYPTED_KEY)));
  12199. case PASSWORD:
  12200. return (memberValue.byteLength === 0);
  12201. default:
  12202. return super.defaultValues(memberName);
  12203. }
  12204. }
  12205. static schema(parameters = {}) {
  12206. const names = pvutils.getParametersValue(parameters, "names", {});
  12207. return (new asn1js.Sequence({
  12208. name: (names.blockName || EMPTY_STRING),
  12209. value: [
  12210. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  12211. new asn1js.Constructed({
  12212. name: (names.keyDerivationAlgorithm || EMPTY_STRING),
  12213. optional: true,
  12214. idBlock: {
  12215. tagClass: 3,
  12216. tagNumber: 0
  12217. },
  12218. value: AlgorithmIdentifier.schema().valueBlock.value
  12219. }),
  12220. AlgorithmIdentifier.schema(names.keyEncryptionAlgorithm || {}),
  12221. new asn1js.OctetString({ name: (names.encryptedKey || EMPTY_STRING) })
  12222. ]
  12223. }));
  12224. }
  12225. fromSchema(schema) {
  12226. pvutils.clearProps(schema, CLEAR_PROPS$p);
  12227. const asn1 = asn1js.compareSchema(schema, schema, PasswordRecipientinfo.schema({
  12228. names: {
  12229. version: VERSION$9,
  12230. keyDerivationAlgorithm: KEY_DERIVATION_ALGORITHM,
  12231. keyEncryptionAlgorithm: {
  12232. names: {
  12233. blockName: KEY_ENCRYPTION_ALGORITHM
  12234. }
  12235. },
  12236. encryptedKey: ENCRYPTED_KEY
  12237. }
  12238. }));
  12239. AsnError.assertSchema(asn1, this.className);
  12240. this.version = asn1.result.version.valueBlock.valueDec;
  12241. if (KEY_DERIVATION_ALGORITHM in asn1.result) {
  12242. this.keyDerivationAlgorithm = new AlgorithmIdentifier({
  12243. schema: new asn1js.Sequence({
  12244. value: asn1.result.keyDerivationAlgorithm.valueBlock.value
  12245. })
  12246. });
  12247. }
  12248. this.keyEncryptionAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.keyEncryptionAlgorithm });
  12249. this.encryptedKey = asn1.result.encryptedKey;
  12250. }
  12251. toSchema() {
  12252. const outputArray = [];
  12253. outputArray.push(new asn1js.Integer({ value: this.version }));
  12254. if (this.keyDerivationAlgorithm) {
  12255. outputArray.push(new asn1js.Constructed({
  12256. idBlock: {
  12257. tagClass: 3,
  12258. tagNumber: 0
  12259. },
  12260. value: this.keyDerivationAlgorithm.toSchema().valueBlock.value
  12261. }));
  12262. }
  12263. outputArray.push(this.keyEncryptionAlgorithm.toSchema());
  12264. outputArray.push(this.encryptedKey);
  12265. return (new asn1js.Sequence({
  12266. value: outputArray
  12267. }));
  12268. }
  12269. toJSON() {
  12270. const res = {
  12271. version: this.version,
  12272. keyEncryptionAlgorithm: this.keyEncryptionAlgorithm.toJSON(),
  12273. encryptedKey: this.encryptedKey.toJSON(),
  12274. };
  12275. if (this.keyDerivationAlgorithm) {
  12276. res.keyDerivationAlgorithm = this.keyDerivationAlgorithm.toJSON();
  12277. }
  12278. return res;
  12279. }
  12280. }
  12281. PasswordRecipientinfo.CLASS_NAME = "PasswordRecipientInfo";
  12282. const ORI_TYPE = "oriType";
  12283. const ORI_VALUE = "oriValue";
  12284. const CLEAR_PROPS$o = [
  12285. ORI_TYPE,
  12286. ORI_VALUE
  12287. ];
  12288. class OtherRecipientInfo extends PkiObject {
  12289. constructor(parameters = {}) {
  12290. super();
  12291. this.oriType = pvutils.getParametersValue(parameters, ORI_TYPE, OtherRecipientInfo.defaultValues(ORI_TYPE));
  12292. this.oriValue = pvutils.getParametersValue(parameters, ORI_VALUE, OtherRecipientInfo.defaultValues(ORI_VALUE));
  12293. if (parameters.schema) {
  12294. this.fromSchema(parameters.schema);
  12295. }
  12296. }
  12297. static defaultValues(memberName) {
  12298. switch (memberName) {
  12299. case ORI_TYPE:
  12300. return EMPTY_STRING;
  12301. case ORI_VALUE:
  12302. return {};
  12303. default:
  12304. return super.defaultValues(memberName);
  12305. }
  12306. }
  12307. static compareWithDefault(memberName, memberValue) {
  12308. switch (memberName) {
  12309. case ORI_TYPE:
  12310. return (memberValue === EMPTY_STRING);
  12311. case ORI_VALUE:
  12312. return (Object.keys(memberValue).length === 0);
  12313. default:
  12314. return super.defaultValues(memberName);
  12315. }
  12316. }
  12317. static schema(parameters = {}) {
  12318. const names = pvutils.getParametersValue(parameters, "names", {});
  12319. return (new asn1js.Sequence({
  12320. name: (names.blockName || EMPTY_STRING),
  12321. value: [
  12322. new asn1js.ObjectIdentifier({ name: (names.oriType || EMPTY_STRING) }),
  12323. new asn1js.Any({ name: (names.oriValue || EMPTY_STRING) })
  12324. ]
  12325. }));
  12326. }
  12327. fromSchema(schema) {
  12328. pvutils.clearProps(schema, CLEAR_PROPS$o);
  12329. const asn1 = asn1js.compareSchema(schema, schema, OtherRecipientInfo.schema({
  12330. names: {
  12331. oriType: ORI_TYPE,
  12332. oriValue: ORI_VALUE
  12333. }
  12334. }));
  12335. AsnError.assertSchema(asn1, this.className);
  12336. this.oriType = asn1.result.oriType.valueBlock.toString();
  12337. this.oriValue = asn1.result.oriValue;
  12338. }
  12339. toSchema() {
  12340. return (new asn1js.Sequence({
  12341. value: [
  12342. new asn1js.ObjectIdentifier({ value: this.oriType }),
  12343. this.oriValue
  12344. ]
  12345. }));
  12346. }
  12347. toJSON() {
  12348. const res = {
  12349. oriType: this.oriType
  12350. };
  12351. if (!OtherRecipientInfo.compareWithDefault(ORI_VALUE, this.oriValue)) {
  12352. res.oriValue = this.oriValue.toJSON();
  12353. }
  12354. return res;
  12355. }
  12356. }
  12357. OtherRecipientInfo.CLASS_NAME = "OtherRecipientInfo";
  12358. const VARIANT = "variant";
  12359. const VALUE = "value";
  12360. const CLEAR_PROPS$n = [
  12361. "blockName"
  12362. ];
  12363. class RecipientInfo extends PkiObject {
  12364. constructor(parameters = {}) {
  12365. super();
  12366. this.variant = pvutils.getParametersValue(parameters, VARIANT, RecipientInfo.defaultValues(VARIANT));
  12367. if (VALUE in parameters) {
  12368. this.value = pvutils.getParametersValue(parameters, VALUE, RecipientInfo.defaultValues(VALUE));
  12369. }
  12370. if (parameters.schema) {
  12371. this.fromSchema(parameters.schema);
  12372. }
  12373. }
  12374. static defaultValues(memberName) {
  12375. switch (memberName) {
  12376. case VARIANT:
  12377. return (-1);
  12378. case VALUE:
  12379. return {};
  12380. default:
  12381. return super.defaultValues(memberName);
  12382. }
  12383. }
  12384. static compareWithDefault(memberName, memberValue) {
  12385. switch (memberName) {
  12386. case VARIANT:
  12387. return (memberValue === RecipientInfo.defaultValues(memberName));
  12388. case VALUE:
  12389. return (Object.keys(memberValue).length === 0);
  12390. default:
  12391. return super.defaultValues(memberName);
  12392. }
  12393. }
  12394. static schema(parameters = {}) {
  12395. const names = pvutils.getParametersValue(parameters, "names", {});
  12396. return (new asn1js.Choice({
  12397. value: [
  12398. KeyTransRecipientInfo.schema({
  12399. names: {
  12400. blockName: (names.blockName || EMPTY_STRING)
  12401. }
  12402. }),
  12403. new asn1js.Constructed({
  12404. name: (names.blockName || EMPTY_STRING),
  12405. idBlock: {
  12406. tagClass: 3,
  12407. tagNumber: 1
  12408. },
  12409. value: KeyAgreeRecipientInfo.schema().valueBlock.value
  12410. }),
  12411. new asn1js.Constructed({
  12412. name: (names.blockName || EMPTY_STRING),
  12413. idBlock: {
  12414. tagClass: 3,
  12415. tagNumber: 2
  12416. },
  12417. value: KEKRecipientInfo.schema().valueBlock.value
  12418. }),
  12419. new asn1js.Constructed({
  12420. name: (names.blockName || EMPTY_STRING),
  12421. idBlock: {
  12422. tagClass: 3,
  12423. tagNumber: 3
  12424. },
  12425. value: PasswordRecipientinfo.schema().valueBlock.value
  12426. }),
  12427. new asn1js.Constructed({
  12428. name: (names.blockName || EMPTY_STRING),
  12429. idBlock: {
  12430. tagClass: 3,
  12431. tagNumber: 4
  12432. },
  12433. value: OtherRecipientInfo.schema().valueBlock.value
  12434. })
  12435. ]
  12436. }));
  12437. }
  12438. fromSchema(schema) {
  12439. pvutils.clearProps(schema, CLEAR_PROPS$n);
  12440. const asn1 = asn1js.compareSchema(schema, schema, RecipientInfo.schema({
  12441. names: {
  12442. blockName: "blockName"
  12443. }
  12444. }));
  12445. AsnError.assertSchema(asn1, this.className);
  12446. if (asn1.result.blockName.idBlock.tagClass === 1) {
  12447. this.variant = 1;
  12448. this.value = new KeyTransRecipientInfo({ schema: asn1.result.blockName });
  12449. }
  12450. else {
  12451. const blockSequence = new asn1js.Sequence({
  12452. value: asn1.result.blockName.valueBlock.value
  12453. });
  12454. switch (asn1.result.blockName.idBlock.tagNumber) {
  12455. case 1:
  12456. this.variant = 2;
  12457. this.value = new KeyAgreeRecipientInfo({ schema: blockSequence });
  12458. break;
  12459. case 2:
  12460. this.variant = 3;
  12461. this.value = new KEKRecipientInfo({ schema: blockSequence });
  12462. break;
  12463. case 3:
  12464. this.variant = 4;
  12465. this.value = new PasswordRecipientinfo({ schema: blockSequence });
  12466. break;
  12467. case 4:
  12468. this.variant = 5;
  12469. this.value = new OtherRecipientInfo({ schema: blockSequence });
  12470. break;
  12471. default:
  12472. throw new Error("Incorrect structure of RecipientInfo block");
  12473. }
  12474. }
  12475. }
  12476. toSchema() {
  12477. ParameterError.assertEmpty(this.value, "value", "RecipientInfo");
  12478. const _schema = this.value.toSchema();
  12479. switch (this.variant) {
  12480. case 1:
  12481. return _schema;
  12482. case 2:
  12483. case 3:
  12484. case 4:
  12485. _schema.idBlock.tagClass = 3;
  12486. _schema.idBlock.tagNumber = (this.variant - 1);
  12487. return _schema;
  12488. default:
  12489. return new asn1js.Any();
  12490. }
  12491. }
  12492. toJSON() {
  12493. const res = {
  12494. variant: this.variant
  12495. };
  12496. if (this.value && (this.variant >= 1) && (this.variant <= 4)) {
  12497. res.value = this.value.toJSON();
  12498. }
  12499. return res;
  12500. }
  12501. }
  12502. RecipientInfo.CLASS_NAME = "RecipientInfo";
  12503. const HASH_ALGORITHM$2 = "hashAlgorithm";
  12504. const MASK_GEN_ALGORITHM = "maskGenAlgorithm";
  12505. const P_SOURCE_ALGORITHM = "pSourceAlgorithm";
  12506. const CLEAR_PROPS$m = [
  12507. HASH_ALGORITHM$2,
  12508. MASK_GEN_ALGORITHM,
  12509. P_SOURCE_ALGORITHM
  12510. ];
  12511. class RSAESOAEPParams extends PkiObject {
  12512. constructor(parameters = {}) {
  12513. super();
  12514. this.hashAlgorithm = pvutils.getParametersValue(parameters, HASH_ALGORITHM$2, RSAESOAEPParams.defaultValues(HASH_ALGORITHM$2));
  12515. this.maskGenAlgorithm = pvutils.getParametersValue(parameters, MASK_GEN_ALGORITHM, RSAESOAEPParams.defaultValues(MASK_GEN_ALGORITHM));
  12516. this.pSourceAlgorithm = pvutils.getParametersValue(parameters, P_SOURCE_ALGORITHM, RSAESOAEPParams.defaultValues(P_SOURCE_ALGORITHM));
  12517. if (parameters.schema) {
  12518. this.fromSchema(parameters.schema);
  12519. }
  12520. }
  12521. static defaultValues(memberName) {
  12522. switch (memberName) {
  12523. case HASH_ALGORITHM$2:
  12524. return new AlgorithmIdentifier({
  12525. algorithmId: "1.3.14.3.2.26",
  12526. algorithmParams: new asn1js.Null()
  12527. });
  12528. case MASK_GEN_ALGORITHM:
  12529. return new AlgorithmIdentifier({
  12530. algorithmId: "1.2.840.113549.1.1.8",
  12531. algorithmParams: (new AlgorithmIdentifier({
  12532. algorithmId: "1.3.14.3.2.26",
  12533. algorithmParams: new asn1js.Null()
  12534. })).toSchema()
  12535. });
  12536. case P_SOURCE_ALGORITHM:
  12537. return new AlgorithmIdentifier({
  12538. algorithmId: "1.2.840.113549.1.1.9",
  12539. algorithmParams: new asn1js.OctetString({ valueHex: (new Uint8Array([0xda, 0x39, 0xa3, 0xee, 0x5e, 0x6b, 0x4b, 0x0d, 0x32, 0x55, 0xbf, 0xef, 0x95, 0x60, 0x18, 0x90, 0xaf, 0xd8, 0x07, 0x09])).buffer })
  12540. });
  12541. default:
  12542. return super.defaultValues(memberName);
  12543. }
  12544. }
  12545. static schema(parameters = {}) {
  12546. const names = pvutils.getParametersValue(parameters, "names", {});
  12547. return (new asn1js.Sequence({
  12548. name: (names.blockName || EMPTY_STRING),
  12549. value: [
  12550. new asn1js.Constructed({
  12551. idBlock: {
  12552. tagClass: 3,
  12553. tagNumber: 0
  12554. },
  12555. optional: true,
  12556. value: [AlgorithmIdentifier.schema(names.hashAlgorithm || {})]
  12557. }),
  12558. new asn1js.Constructed({
  12559. idBlock: {
  12560. tagClass: 3,
  12561. tagNumber: 1
  12562. },
  12563. optional: true,
  12564. value: [AlgorithmIdentifier.schema(names.maskGenAlgorithm || {})]
  12565. }),
  12566. new asn1js.Constructed({
  12567. idBlock: {
  12568. tagClass: 3,
  12569. tagNumber: 2
  12570. },
  12571. optional: true,
  12572. value: [AlgorithmIdentifier.schema(names.pSourceAlgorithm || {})]
  12573. })
  12574. ]
  12575. }));
  12576. }
  12577. fromSchema(schema) {
  12578. pvutils.clearProps(schema, CLEAR_PROPS$m);
  12579. const asn1 = asn1js.compareSchema(schema, schema, RSAESOAEPParams.schema({
  12580. names: {
  12581. hashAlgorithm: {
  12582. names: {
  12583. blockName: HASH_ALGORITHM$2
  12584. }
  12585. },
  12586. maskGenAlgorithm: {
  12587. names: {
  12588. blockName: MASK_GEN_ALGORITHM
  12589. }
  12590. },
  12591. pSourceAlgorithm: {
  12592. names: {
  12593. blockName: P_SOURCE_ALGORITHM
  12594. }
  12595. }
  12596. }
  12597. }));
  12598. AsnError.assertSchema(asn1, this.className);
  12599. if (HASH_ALGORITHM$2 in asn1.result)
  12600. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  12601. if (MASK_GEN_ALGORITHM in asn1.result)
  12602. this.maskGenAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.maskGenAlgorithm });
  12603. if (P_SOURCE_ALGORITHM in asn1.result)
  12604. this.pSourceAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.pSourceAlgorithm });
  12605. }
  12606. toSchema() {
  12607. const outputArray = [];
  12608. if (!this.hashAlgorithm.isEqual(RSAESOAEPParams.defaultValues(HASH_ALGORITHM$2))) {
  12609. outputArray.push(new asn1js.Constructed({
  12610. idBlock: {
  12611. tagClass: 3,
  12612. tagNumber: 0
  12613. },
  12614. value: [this.hashAlgorithm.toSchema()]
  12615. }));
  12616. }
  12617. if (!this.maskGenAlgorithm.isEqual(RSAESOAEPParams.defaultValues(MASK_GEN_ALGORITHM))) {
  12618. outputArray.push(new asn1js.Constructed({
  12619. idBlock: {
  12620. tagClass: 3,
  12621. tagNumber: 1
  12622. },
  12623. value: [this.maskGenAlgorithm.toSchema()]
  12624. }));
  12625. }
  12626. if (!this.pSourceAlgorithm.isEqual(RSAESOAEPParams.defaultValues(P_SOURCE_ALGORITHM))) {
  12627. outputArray.push(new asn1js.Constructed({
  12628. idBlock: {
  12629. tagClass: 3,
  12630. tagNumber: 2
  12631. },
  12632. value: [this.pSourceAlgorithm.toSchema()]
  12633. }));
  12634. }
  12635. return (new asn1js.Sequence({
  12636. value: outputArray
  12637. }));
  12638. }
  12639. toJSON() {
  12640. const res = {};
  12641. if (!this.hashAlgorithm.isEqual(RSAESOAEPParams.defaultValues(HASH_ALGORITHM$2))) {
  12642. res.hashAlgorithm = this.hashAlgorithm.toJSON();
  12643. }
  12644. if (!this.maskGenAlgorithm.isEqual(RSAESOAEPParams.defaultValues(MASK_GEN_ALGORITHM))) {
  12645. res.maskGenAlgorithm = this.maskGenAlgorithm.toJSON();
  12646. }
  12647. if (!this.pSourceAlgorithm.isEqual(RSAESOAEPParams.defaultValues(P_SOURCE_ALGORITHM))) {
  12648. res.pSourceAlgorithm = this.pSourceAlgorithm.toJSON();
  12649. }
  12650. return res;
  12651. }
  12652. }
  12653. RSAESOAEPParams.CLASS_NAME = "RSAESOAEPParams";
  12654. const KEY_INFO = "keyInfo";
  12655. const ENTITY_U_INFO = "entityUInfo";
  12656. const SUPP_PUB_INFO = "suppPubInfo";
  12657. const CLEAR_PROPS$l = [
  12658. KEY_INFO,
  12659. ENTITY_U_INFO,
  12660. SUPP_PUB_INFO
  12661. ];
  12662. class ECCCMSSharedInfo extends PkiObject {
  12663. constructor(parameters = {}) {
  12664. super();
  12665. this.keyInfo = pvutils.getParametersValue(parameters, KEY_INFO, ECCCMSSharedInfo.defaultValues(KEY_INFO));
  12666. if (ENTITY_U_INFO in parameters) {
  12667. this.entityUInfo = pvutils.getParametersValue(parameters, ENTITY_U_INFO, ECCCMSSharedInfo.defaultValues(ENTITY_U_INFO));
  12668. }
  12669. this.suppPubInfo = pvutils.getParametersValue(parameters, SUPP_PUB_INFO, ECCCMSSharedInfo.defaultValues(SUPP_PUB_INFO));
  12670. if (parameters.schema) {
  12671. this.fromSchema(parameters.schema);
  12672. }
  12673. }
  12674. static defaultValues(memberName) {
  12675. switch (memberName) {
  12676. case KEY_INFO:
  12677. return new AlgorithmIdentifier();
  12678. case ENTITY_U_INFO:
  12679. return new asn1js.OctetString();
  12680. case SUPP_PUB_INFO:
  12681. return new asn1js.OctetString();
  12682. default:
  12683. return super.defaultValues(memberName);
  12684. }
  12685. }
  12686. static compareWithDefault(memberName, memberValue) {
  12687. switch (memberName) {
  12688. case KEY_INFO:
  12689. case ENTITY_U_INFO:
  12690. case SUPP_PUB_INFO:
  12691. return (memberValue.isEqual(ECCCMSSharedInfo.defaultValues(memberName)));
  12692. default:
  12693. return super.defaultValues(memberName);
  12694. }
  12695. }
  12696. static schema(parameters = {}) {
  12697. const names = pvutils.getParametersValue(parameters, "names", {});
  12698. return (new asn1js.Sequence({
  12699. name: (names.blockName || EMPTY_STRING),
  12700. value: [
  12701. AlgorithmIdentifier.schema(names.keyInfo || {}),
  12702. new asn1js.Constructed({
  12703. name: (names.entityUInfo || EMPTY_STRING),
  12704. idBlock: {
  12705. tagClass: 3,
  12706. tagNumber: 0
  12707. },
  12708. optional: true,
  12709. value: [new asn1js.OctetString()]
  12710. }),
  12711. new asn1js.Constructed({
  12712. name: (names.suppPubInfo || EMPTY_STRING),
  12713. idBlock: {
  12714. tagClass: 3,
  12715. tagNumber: 2
  12716. },
  12717. value: [new asn1js.OctetString()]
  12718. })
  12719. ]
  12720. }));
  12721. }
  12722. fromSchema(schema) {
  12723. pvutils.clearProps(schema, CLEAR_PROPS$l);
  12724. const asn1 = asn1js.compareSchema(schema, schema, ECCCMSSharedInfo.schema({
  12725. names: {
  12726. keyInfo: {
  12727. names: {
  12728. blockName: KEY_INFO
  12729. }
  12730. },
  12731. entityUInfo: ENTITY_U_INFO,
  12732. suppPubInfo: SUPP_PUB_INFO
  12733. }
  12734. }));
  12735. AsnError.assertSchema(asn1, this.className);
  12736. this.keyInfo = new AlgorithmIdentifier({ schema: asn1.result.keyInfo });
  12737. if (ENTITY_U_INFO in asn1.result)
  12738. this.entityUInfo = asn1.result.entityUInfo.valueBlock.value[0];
  12739. this.suppPubInfo = asn1.result.suppPubInfo.valueBlock.value[0];
  12740. }
  12741. toSchema() {
  12742. const outputArray = [];
  12743. outputArray.push(this.keyInfo.toSchema());
  12744. if (this.entityUInfo) {
  12745. outputArray.push(new asn1js.Constructed({
  12746. idBlock: {
  12747. tagClass: 3,
  12748. tagNumber: 0
  12749. },
  12750. value: [this.entityUInfo]
  12751. }));
  12752. }
  12753. outputArray.push(new asn1js.Constructed({
  12754. idBlock: {
  12755. tagClass: 3,
  12756. tagNumber: 2
  12757. },
  12758. value: [this.suppPubInfo]
  12759. }));
  12760. return new asn1js.Sequence({
  12761. value: outputArray
  12762. });
  12763. }
  12764. toJSON() {
  12765. const res = {
  12766. keyInfo: this.keyInfo.toJSON(),
  12767. suppPubInfo: this.suppPubInfo.toJSON(),
  12768. };
  12769. if (this.entityUInfo) {
  12770. res.entityUInfo = this.entityUInfo.toJSON();
  12771. }
  12772. return res;
  12773. }
  12774. }
  12775. ECCCMSSharedInfo.CLASS_NAME = "ECCCMSSharedInfo";
  12776. const VERSION$8 = "version";
  12777. const ORIGINATOR_INFO = "originatorInfo";
  12778. const RECIPIENT_INFOS = "recipientInfos";
  12779. const ENCRYPTED_CONTENT_INFO = "encryptedContentInfo";
  12780. const UNPROTECTED_ATTRS = "unprotectedAttrs";
  12781. const CLEAR_PROPS$k = [
  12782. VERSION$8,
  12783. ORIGINATOR_INFO,
  12784. RECIPIENT_INFOS,
  12785. ENCRYPTED_CONTENT_INFO,
  12786. UNPROTECTED_ATTRS
  12787. ];
  12788. const defaultEncryptionParams = {
  12789. kdfAlgorithm: "SHA-512",
  12790. kekEncryptionLength: 256
  12791. };
  12792. const curveLengthByName = {
  12793. "P-256": 256,
  12794. "P-384": 384,
  12795. "P-521": 528
  12796. };
  12797. class EnvelopedData extends PkiObject {
  12798. constructor(parameters = {}) {
  12799. super();
  12800. this.version = pvutils.getParametersValue(parameters, VERSION$8, EnvelopedData.defaultValues(VERSION$8));
  12801. if (ORIGINATOR_INFO in parameters) {
  12802. this.originatorInfo = pvutils.getParametersValue(parameters, ORIGINATOR_INFO, EnvelopedData.defaultValues(ORIGINATOR_INFO));
  12803. }
  12804. this.recipientInfos = pvutils.getParametersValue(parameters, RECIPIENT_INFOS, EnvelopedData.defaultValues(RECIPIENT_INFOS));
  12805. this.encryptedContentInfo = pvutils.getParametersValue(parameters, ENCRYPTED_CONTENT_INFO, EnvelopedData.defaultValues(ENCRYPTED_CONTENT_INFO));
  12806. if (UNPROTECTED_ATTRS in parameters) {
  12807. this.unprotectedAttrs = pvutils.getParametersValue(parameters, UNPROTECTED_ATTRS, EnvelopedData.defaultValues(UNPROTECTED_ATTRS));
  12808. }
  12809. this.policy = {
  12810. disableSplit: !!parameters.disableSplit,
  12811. };
  12812. if (parameters.schema) {
  12813. this.fromSchema(parameters.schema);
  12814. }
  12815. }
  12816. static defaultValues(memberName) {
  12817. switch (memberName) {
  12818. case VERSION$8:
  12819. return 0;
  12820. case ORIGINATOR_INFO:
  12821. return new OriginatorInfo();
  12822. case RECIPIENT_INFOS:
  12823. return [];
  12824. case ENCRYPTED_CONTENT_INFO:
  12825. return new EncryptedContentInfo();
  12826. case UNPROTECTED_ATTRS:
  12827. return [];
  12828. default:
  12829. return super.defaultValues(memberName);
  12830. }
  12831. }
  12832. static compareWithDefault(memberName, memberValue) {
  12833. switch (memberName) {
  12834. case VERSION$8:
  12835. return (memberValue === EnvelopedData.defaultValues(memberName));
  12836. case ORIGINATOR_INFO:
  12837. return ((memberValue.certs.certificates.length === 0) && (memberValue.crls.crls.length === 0));
  12838. case RECIPIENT_INFOS:
  12839. case UNPROTECTED_ATTRS:
  12840. return (memberValue.length === 0);
  12841. case ENCRYPTED_CONTENT_INFO:
  12842. return ((EncryptedContentInfo.compareWithDefault("contentType", memberValue.contentType)) &&
  12843. (EncryptedContentInfo.compareWithDefault("contentEncryptionAlgorithm", memberValue.contentEncryptionAlgorithm) &&
  12844. (EncryptedContentInfo.compareWithDefault("encryptedContent", memberValue.encryptedContent))));
  12845. default:
  12846. return super.defaultValues(memberName);
  12847. }
  12848. }
  12849. static schema(parameters = {}) {
  12850. const names = pvutils.getParametersValue(parameters, "names", {});
  12851. return (new asn1js.Sequence({
  12852. name: (names.blockName || EMPTY_STRING),
  12853. value: [
  12854. new asn1js.Integer({ name: (names.version || EMPTY_STRING) }),
  12855. new asn1js.Constructed({
  12856. name: (names.originatorInfo || EMPTY_STRING),
  12857. optional: true,
  12858. idBlock: {
  12859. tagClass: 3,
  12860. tagNumber: 0
  12861. },
  12862. value: OriginatorInfo.schema().valueBlock.value
  12863. }),
  12864. new asn1js.Set({
  12865. value: [
  12866. new asn1js.Repeated({
  12867. name: (names.recipientInfos || EMPTY_STRING),
  12868. value: RecipientInfo.schema()
  12869. })
  12870. ]
  12871. }),
  12872. EncryptedContentInfo.schema(names.encryptedContentInfo || {}),
  12873. new asn1js.Constructed({
  12874. optional: true,
  12875. idBlock: {
  12876. tagClass: 3,
  12877. tagNumber: 1
  12878. },
  12879. value: [
  12880. new asn1js.Repeated({
  12881. name: (names.unprotectedAttrs || EMPTY_STRING),
  12882. value: Attribute.schema()
  12883. })
  12884. ]
  12885. })
  12886. ]
  12887. }));
  12888. }
  12889. fromSchema(schema) {
  12890. pvutils.clearProps(schema, CLEAR_PROPS$k);
  12891. const asn1 = asn1js.compareSchema(schema, schema, EnvelopedData.schema({
  12892. names: {
  12893. version: VERSION$8,
  12894. originatorInfo: ORIGINATOR_INFO,
  12895. recipientInfos: RECIPIENT_INFOS,
  12896. encryptedContentInfo: {
  12897. names: {
  12898. blockName: ENCRYPTED_CONTENT_INFO
  12899. }
  12900. },
  12901. unprotectedAttrs: UNPROTECTED_ATTRS
  12902. }
  12903. }));
  12904. AsnError.assertSchema(asn1, this.className);
  12905. this.version = asn1.result.version.valueBlock.valueDec;
  12906. if (ORIGINATOR_INFO in asn1.result) {
  12907. this.originatorInfo = new OriginatorInfo({
  12908. schema: new asn1js.Sequence({
  12909. value: asn1.result.originatorInfo.valueBlock.value
  12910. })
  12911. });
  12912. }
  12913. this.recipientInfos = Array.from(asn1.result.recipientInfos, o => new RecipientInfo({ schema: o }));
  12914. this.encryptedContentInfo = new EncryptedContentInfo({ schema: asn1.result.encryptedContentInfo });
  12915. if (UNPROTECTED_ATTRS in asn1.result)
  12916. this.unprotectedAttrs = Array.from(asn1.result.unprotectedAttrs, o => new Attribute({ schema: o }));
  12917. }
  12918. toSchema() {
  12919. const outputArray = [];
  12920. outputArray.push(new asn1js.Integer({ value: this.version }));
  12921. if (this.originatorInfo) {
  12922. outputArray.push(new asn1js.Constructed({
  12923. optional: true,
  12924. idBlock: {
  12925. tagClass: 3,
  12926. tagNumber: 0
  12927. },
  12928. value: this.originatorInfo.toSchema().valueBlock.value
  12929. }));
  12930. }
  12931. outputArray.push(new asn1js.Set({
  12932. value: Array.from(this.recipientInfos, o => o.toSchema())
  12933. }));
  12934. outputArray.push(this.encryptedContentInfo.toSchema());
  12935. if (this.unprotectedAttrs) {
  12936. outputArray.push(new asn1js.Constructed({
  12937. optional: true,
  12938. idBlock: {
  12939. tagClass: 3,
  12940. tagNumber: 1
  12941. },
  12942. value: Array.from(this.unprotectedAttrs, o => o.toSchema())
  12943. }));
  12944. }
  12945. return (new asn1js.Sequence({
  12946. value: outputArray
  12947. }));
  12948. }
  12949. toJSON() {
  12950. const res = {
  12951. version: this.version,
  12952. recipientInfos: Array.from(this.recipientInfos, o => o.toJSON()),
  12953. encryptedContentInfo: this.encryptedContentInfo.toJSON(),
  12954. };
  12955. if (this.originatorInfo)
  12956. res.originatorInfo = this.originatorInfo.toJSON();
  12957. if (this.unprotectedAttrs)
  12958. res.unprotectedAttrs = Array.from(this.unprotectedAttrs, o => o.toJSON());
  12959. return res;
  12960. }
  12961. addRecipientByCertificate(certificate, parameters, variant, crypto = getCrypto(true)) {
  12962. const encryptionParameters = Object.assign({ useOAEP: true, oaepHashAlgorithm: "SHA-512" }, defaultEncryptionParams, parameters || {});
  12963. if (certificate.subjectPublicKeyInfo.algorithm.algorithmId.indexOf("1.2.840.113549") !== (-1))
  12964. variant = 1;
  12965. else {
  12966. if (certificate.subjectPublicKeyInfo.algorithm.algorithmId.indexOf("1.2.840.10045") !== (-1))
  12967. variant = 2;
  12968. else
  12969. throw new Error(`Unknown type of certificate's public key: ${certificate.subjectPublicKeyInfo.algorithm.algorithmId}`);
  12970. }
  12971. switch (variant) {
  12972. case 1:
  12973. {
  12974. let algorithmId;
  12975. let algorithmParams;
  12976. if (encryptionParameters.useOAEP === true) {
  12977. algorithmId = crypto.getOIDByAlgorithm({
  12978. name: "RSA-OAEP"
  12979. }, true, "keyEncryptionAlgorithm");
  12980. const hashOID = crypto.getOIDByAlgorithm({
  12981. name: encryptionParameters.oaepHashAlgorithm
  12982. }, true, "RSAES-OAEP-params");
  12983. const hashAlgorithm = new AlgorithmIdentifier({
  12984. algorithmId: hashOID,
  12985. algorithmParams: new asn1js.Null()
  12986. });
  12987. const rsaOAEPParams = new RSAESOAEPParams({
  12988. hashAlgorithm,
  12989. maskGenAlgorithm: new AlgorithmIdentifier({
  12990. algorithmId: "1.2.840.113549.1.1.8",
  12991. algorithmParams: hashAlgorithm.toSchema()
  12992. })
  12993. });
  12994. algorithmParams = rsaOAEPParams.toSchema();
  12995. }
  12996. else {
  12997. algorithmId = crypto.getOIDByAlgorithm({
  12998. name: "RSAES-PKCS1-v1_5"
  12999. });
  13000. if (algorithmId === EMPTY_STRING)
  13001. throw new Error("Can not find OID for RSAES-PKCS1-v1_5");
  13002. algorithmParams = new asn1js.Null();
  13003. }
  13004. const keyInfo = new KeyTransRecipientInfo({
  13005. version: 0,
  13006. rid: new IssuerAndSerialNumber({
  13007. issuer: certificate.issuer,
  13008. serialNumber: certificate.serialNumber
  13009. }),
  13010. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13011. algorithmId,
  13012. algorithmParams
  13013. }),
  13014. recipientCertificate: certificate,
  13015. });
  13016. this.recipientInfos.push(new RecipientInfo({
  13017. variant: 1,
  13018. value: keyInfo
  13019. }));
  13020. }
  13021. break;
  13022. case 2:
  13023. {
  13024. const recipientIdentifier = new KeyAgreeRecipientIdentifier({
  13025. variant: 1,
  13026. value: new IssuerAndSerialNumber({
  13027. issuer: certificate.issuer,
  13028. serialNumber: certificate.serialNumber
  13029. })
  13030. });
  13031. this._addKeyAgreeRecipientInfo(recipientIdentifier, encryptionParameters, { recipientCertificate: certificate }, crypto);
  13032. }
  13033. break;
  13034. default:
  13035. throw new Error(`Unknown "variant" value: ${variant}`);
  13036. }
  13037. return true;
  13038. }
  13039. addRecipientByPreDefinedData(preDefinedData, parameters = {}, variant, crypto = getCrypto(true)) {
  13040. ArgumentError.assert(preDefinedData, "preDefinedData", "ArrayBuffer");
  13041. if (!preDefinedData.byteLength) {
  13042. throw new Error("Pre-defined data could have zero length");
  13043. }
  13044. if (!parameters.keyIdentifier) {
  13045. const keyIdentifierBuffer = new ArrayBuffer(16);
  13046. const keyIdentifierView = new Uint8Array(keyIdentifierBuffer);
  13047. crypto.getRandomValues(keyIdentifierView);
  13048. parameters.keyIdentifier = keyIdentifierBuffer;
  13049. }
  13050. if (!parameters.hmacHashAlgorithm)
  13051. parameters.hmacHashAlgorithm = "SHA-512";
  13052. if (parameters.iterationCount === undefined) {
  13053. parameters.iterationCount = 2048;
  13054. }
  13055. if (!parameters.keyEncryptionAlgorithm) {
  13056. parameters.keyEncryptionAlgorithm = {
  13057. name: "AES-KW",
  13058. length: 256
  13059. };
  13060. }
  13061. if (!parameters.keyEncryptionAlgorithmParams)
  13062. parameters.keyEncryptionAlgorithmParams = new asn1js.Null();
  13063. switch (variant) {
  13064. case 1:
  13065. {
  13066. const kekOID = crypto.getOIDByAlgorithm(parameters.keyEncryptionAlgorithm, true, "keyEncryptionAlgorithm");
  13067. const keyInfo = new KEKRecipientInfo({
  13068. version: 4,
  13069. kekid: new KEKIdentifier({
  13070. keyIdentifier: new asn1js.OctetString({ valueHex: parameters.keyIdentifier })
  13071. }),
  13072. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13073. algorithmId: kekOID,
  13074. algorithmParams: parameters.keyEncryptionAlgorithmParams
  13075. }),
  13076. preDefinedKEK: preDefinedData
  13077. });
  13078. this.recipientInfos.push(new RecipientInfo({
  13079. variant: 3,
  13080. value: keyInfo
  13081. }));
  13082. }
  13083. break;
  13084. case 2:
  13085. {
  13086. const pbkdf2OID = crypto.getOIDByAlgorithm({ name: "PBKDF2" }, true, "keyDerivationAlgorithm");
  13087. const saltBuffer = new ArrayBuffer(64);
  13088. const saltView = new Uint8Array(saltBuffer);
  13089. crypto.getRandomValues(saltView);
  13090. const hmacOID = crypto.getOIDByAlgorithm({
  13091. name: "HMAC",
  13092. hash: {
  13093. name: parameters.hmacHashAlgorithm
  13094. }
  13095. }, true, "hmacHashAlgorithm");
  13096. const pbkdf2Params = new PBKDF2Params({
  13097. salt: new asn1js.OctetString({ valueHex: saltBuffer }),
  13098. iterationCount: parameters.iterationCount,
  13099. prf: new AlgorithmIdentifier({
  13100. algorithmId: hmacOID,
  13101. algorithmParams: new asn1js.Null()
  13102. })
  13103. });
  13104. const kekOID = crypto.getOIDByAlgorithm(parameters.keyEncryptionAlgorithm, true, "keyEncryptionAlgorithm");
  13105. const keyInfo = new PasswordRecipientinfo({
  13106. version: 0,
  13107. keyDerivationAlgorithm: new AlgorithmIdentifier({
  13108. algorithmId: pbkdf2OID,
  13109. algorithmParams: pbkdf2Params.toSchema()
  13110. }),
  13111. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13112. algorithmId: kekOID,
  13113. algorithmParams: parameters.keyEncryptionAlgorithmParams
  13114. }),
  13115. password: preDefinedData
  13116. });
  13117. this.recipientInfos.push(new RecipientInfo({
  13118. variant: 4,
  13119. value: keyInfo
  13120. }));
  13121. }
  13122. break;
  13123. default:
  13124. throw new Error(`Unknown value for "variant": ${variant}`);
  13125. }
  13126. }
  13127. addRecipientByKeyIdentifier(key, keyId, parameters, crypto = getCrypto(true)) {
  13128. const encryptionParameters = Object.assign({}, defaultEncryptionParams, parameters || {});
  13129. const recipientIdentifier = new KeyAgreeRecipientIdentifier({
  13130. variant: 2,
  13131. value: new RecipientKeyIdentifier({
  13132. subjectKeyIdentifier: new asn1js.OctetString({ valueHex: keyId }),
  13133. })
  13134. });
  13135. this._addKeyAgreeRecipientInfo(recipientIdentifier, encryptionParameters, { recipientPublicKey: key }, crypto);
  13136. }
  13137. _addKeyAgreeRecipientInfo(recipientIdentifier, encryptionParameters, extraRecipientInfoParams, crypto = getCrypto(true)) {
  13138. const encryptedKey = new RecipientEncryptedKey({
  13139. rid: recipientIdentifier
  13140. });
  13141. const aesKWoid = crypto.getOIDByAlgorithm({
  13142. name: "AES-KW",
  13143. length: encryptionParameters.kekEncryptionLength
  13144. }, true, "keyEncryptionAlgorithm");
  13145. const aesKW = new AlgorithmIdentifier({
  13146. algorithmId: aesKWoid,
  13147. });
  13148. const ecdhOID = crypto.getOIDByAlgorithm({
  13149. name: "ECDH",
  13150. kdf: encryptionParameters.kdfAlgorithm
  13151. }, true, "KeyAgreeRecipientInfo");
  13152. const ukmBuffer = new ArrayBuffer(64);
  13153. const ukmView = new Uint8Array(ukmBuffer);
  13154. crypto.getRandomValues(ukmView);
  13155. const recipientInfoParams = {
  13156. version: 3,
  13157. ukm: new asn1js.OctetString({ valueHex: ukmBuffer }),
  13158. keyEncryptionAlgorithm: new AlgorithmIdentifier({
  13159. algorithmId: ecdhOID,
  13160. algorithmParams: aesKW.toSchema()
  13161. }),
  13162. recipientEncryptedKeys: new RecipientEncryptedKeys({
  13163. encryptedKeys: [encryptedKey]
  13164. })
  13165. };
  13166. const keyInfo = new KeyAgreeRecipientInfo(Object.assign(recipientInfoParams, extraRecipientInfoParams));
  13167. this.recipientInfos.push(new RecipientInfo({
  13168. variant: 2,
  13169. value: keyInfo
  13170. }));
  13171. }
  13172. async encrypt(contentEncryptionAlgorithm, contentToEncrypt, crypto = getCrypto(true)) {
  13173. const ivBuffer = new ArrayBuffer(16);
  13174. const ivView = new Uint8Array(ivBuffer);
  13175. crypto.getRandomValues(ivView);
  13176. const contentView = new Uint8Array(contentToEncrypt);
  13177. const contentEncryptionOID = crypto.getOIDByAlgorithm(contentEncryptionAlgorithm, true, "contentEncryptionAlgorithm");
  13178. const sessionKey = await crypto.generateKey(contentEncryptionAlgorithm, true, ["encrypt"]);
  13179. const encryptedContent = await crypto.encrypt({
  13180. name: contentEncryptionAlgorithm.name,
  13181. iv: ivView
  13182. }, sessionKey, contentView);
  13183. const exportedSessionKey = await crypto.exportKey("raw", sessionKey);
  13184. this.version = 2;
  13185. this.encryptedContentInfo = new EncryptedContentInfo({
  13186. disableSplit: this.policy.disableSplit,
  13187. contentType: "1.2.840.113549.1.7.1",
  13188. contentEncryptionAlgorithm: new AlgorithmIdentifier({
  13189. algorithmId: contentEncryptionOID,
  13190. algorithmParams: new asn1js.OctetString({ valueHex: ivBuffer })
  13191. }),
  13192. encryptedContent: new asn1js.OctetString({ valueHex: encryptedContent })
  13193. });
  13194. const SubKeyAgreeRecipientInfo = async (index) => {
  13195. const recipientInfo = this.recipientInfos[index].value;
  13196. let recipientCurve;
  13197. let recipientPublicKey;
  13198. if (recipientInfo.recipientPublicKey) {
  13199. recipientCurve = recipientInfo.recipientPublicKey.algorithm.namedCurve;
  13200. recipientPublicKey = recipientInfo.recipientPublicKey;
  13201. }
  13202. else if (recipientInfo.recipientCertificate) {
  13203. const curveObject = recipientInfo.recipientCertificate.subjectPublicKeyInfo.algorithm.algorithmParams;
  13204. if (curveObject.constructor.blockName() !== asn1js.ObjectIdentifier.blockName())
  13205. throw new Error(`Incorrect "recipientCertificate" for index ${index}`);
  13206. const curveOID = curveObject.valueBlock.toString();
  13207. switch (curveOID) {
  13208. case "1.2.840.10045.3.1.7":
  13209. recipientCurve = "P-256";
  13210. break;
  13211. case "1.3.132.0.34":
  13212. recipientCurve = "P-384";
  13213. break;
  13214. case "1.3.132.0.35":
  13215. recipientCurve = "P-521";
  13216. break;
  13217. default:
  13218. throw new Error(`Incorrect curve OID for index ${index}`);
  13219. }
  13220. recipientPublicKey = await recipientInfo.recipientCertificate.getPublicKey({
  13221. algorithm: {
  13222. algorithm: {
  13223. name: "ECDH",
  13224. namedCurve: recipientCurve
  13225. },
  13226. usages: []
  13227. }
  13228. }, crypto);
  13229. }
  13230. else {
  13231. throw new Error("Unsupported RecipientInfo");
  13232. }
  13233. const recipientCurveLength = curveLengthByName[recipientCurve];
  13234. const ecdhKeys = await crypto.generateKey({ name: "ECDH", namedCurve: recipientCurve }, true, ["deriveBits"]);
  13235. const exportedECDHPublicKey = await crypto.exportKey("spki", ecdhKeys.publicKey);
  13236. const derivedBits = await crypto.deriveBits({
  13237. name: "ECDH",
  13238. public: recipientPublicKey
  13239. }, ecdhKeys.privateKey, recipientCurveLength);
  13240. const aesKWAlgorithm = new AlgorithmIdentifier({ schema: recipientInfo.keyEncryptionAlgorithm.algorithmParams });
  13241. const kwAlgorithm = crypto.getAlgorithmByOID(aesKWAlgorithm.algorithmId, true, "aesKWAlgorithm");
  13242. let kwLength = kwAlgorithm.length;
  13243. const kwLengthBuffer = new ArrayBuffer(4);
  13244. const kwLengthView = new Uint8Array(kwLengthBuffer);
  13245. for (let j = 3; j >= 0; j--) {
  13246. kwLengthView[j] = kwLength;
  13247. kwLength >>= 8;
  13248. }
  13249. const eccInfo = new ECCCMSSharedInfo({
  13250. keyInfo: new AlgorithmIdentifier({
  13251. algorithmId: aesKWAlgorithm.algorithmId
  13252. }),
  13253. entityUInfo: recipientInfo.ukm,
  13254. suppPubInfo: new asn1js.OctetString({ valueHex: kwLengthBuffer })
  13255. });
  13256. const encodedInfo = eccInfo.toSchema().toBER(false);
  13257. const ecdhAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "ecdhAlgorithm");
  13258. const derivedKeyRaw = await kdf(ecdhAlgorithm.kdf, derivedBits, kwAlgorithm.length, encodedInfo, crypto);
  13259. const awsKW = await crypto.importKey("raw", derivedKeyRaw, { name: "AES-KW" }, true, ["wrapKey"]);
  13260. const wrappedKey = await crypto.wrapKey("raw", sessionKey, awsKW, { name: "AES-KW" });
  13261. const originator = new OriginatorIdentifierOrKey();
  13262. originator.variant = 3;
  13263. originator.value = OriginatorPublicKey.fromBER(exportedECDHPublicKey);
  13264. recipientInfo.originator = originator;
  13265. recipientInfo.recipientEncryptedKeys.encryptedKeys[0].encryptedKey = new asn1js.OctetString({ valueHex: wrappedKey });
  13266. return { ecdhPrivateKey: ecdhKeys.privateKey };
  13267. };
  13268. const SubKeyTransRecipientInfo = async (index) => {
  13269. const recipientInfo = this.recipientInfos[index].value;
  13270. const algorithmParameters = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "keyEncryptionAlgorithm");
  13271. if (algorithmParameters.name === "RSA-OAEP") {
  13272. const schema = recipientInfo.keyEncryptionAlgorithm.algorithmParams;
  13273. const rsaOAEPParams = new RSAESOAEPParams({ schema });
  13274. algorithmParameters.hash = crypto.getAlgorithmByOID(rsaOAEPParams.hashAlgorithm.algorithmId);
  13275. if (("name" in algorithmParameters.hash) === false)
  13276. throw new Error(`Incorrect OID for hash algorithm: ${rsaOAEPParams.hashAlgorithm.algorithmId}`);
  13277. }
  13278. try {
  13279. const publicKey = await recipientInfo.recipientCertificate.getPublicKey({
  13280. algorithm: {
  13281. algorithm: algorithmParameters,
  13282. usages: ["encrypt", "wrapKey"]
  13283. }
  13284. }, crypto);
  13285. const encryptedKey = await crypto.encrypt(publicKey.algorithm, publicKey, exportedSessionKey);
  13286. recipientInfo.encryptedKey = new asn1js.OctetString({ valueHex: encryptedKey });
  13287. }
  13288. catch {
  13289. }
  13290. };
  13291. const SubKEKRecipientInfo = async (index) => {
  13292. const recipientInfo = this.recipientInfos[index].value;
  13293. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "kekAlgorithm");
  13294. const kekKey = await crypto.importKey("raw", new Uint8Array(recipientInfo.preDefinedKEK), kekAlgorithm, true, ["wrapKey"]);
  13295. const wrappedKey = await crypto.wrapKey("raw", sessionKey, kekKey, kekAlgorithm);
  13296. recipientInfo.encryptedKey = new asn1js.OctetString({ valueHex: wrappedKey });
  13297. };
  13298. const SubPasswordRecipientinfo = async (index) => {
  13299. const recipientInfo = this.recipientInfos[index].value;
  13300. let pbkdf2Params;
  13301. if (!recipientInfo.keyDerivationAlgorithm)
  13302. throw new Error("Please append encoded \"keyDerivationAlgorithm\"");
  13303. if (!recipientInfo.keyDerivationAlgorithm.algorithmParams)
  13304. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13305. try {
  13306. pbkdf2Params = new PBKDF2Params({ schema: recipientInfo.keyDerivationAlgorithm.algorithmParams });
  13307. }
  13308. catch {
  13309. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13310. }
  13311. const passwordView = new Uint8Array(recipientInfo.password);
  13312. const derivationKey = await crypto.importKey("raw", passwordView, "PBKDF2", false, ["deriveKey"]);
  13313. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "kekAlgorithm");
  13314. let hmacHashAlgorithm = "SHA-1";
  13315. if (pbkdf2Params.prf) {
  13316. const prfAlgorithm = crypto.getAlgorithmByOID(pbkdf2Params.prf.algorithmId, true, "prfAlgorithm");
  13317. hmacHashAlgorithm = prfAlgorithm.hash.name;
  13318. }
  13319. const saltView = new Uint8Array(pbkdf2Params.salt.valueBlock.valueHex);
  13320. const iterations = pbkdf2Params.iterationCount;
  13321. const derivedKey = await crypto.deriveKey({
  13322. name: "PBKDF2",
  13323. hash: {
  13324. name: hmacHashAlgorithm
  13325. },
  13326. salt: saltView,
  13327. iterations
  13328. }, derivationKey, kekAlgorithm, true, ["wrapKey"]);
  13329. const wrappedKey = await crypto.wrapKey("raw", sessionKey, derivedKey, kekAlgorithm);
  13330. recipientInfo.encryptedKey = new asn1js.OctetString({ valueHex: wrappedKey });
  13331. };
  13332. const res = [];
  13333. for (let i = 0; i < this.recipientInfos.length; i++) {
  13334. switch (this.recipientInfos[i].variant) {
  13335. case 1:
  13336. res.push(await SubKeyTransRecipientInfo(i));
  13337. break;
  13338. case 2:
  13339. res.push(await SubKeyAgreeRecipientInfo(i));
  13340. break;
  13341. case 3:
  13342. res.push(await SubKEKRecipientInfo(i));
  13343. break;
  13344. case 4:
  13345. res.push(await SubPasswordRecipientinfo(i));
  13346. break;
  13347. default:
  13348. throw new Error(`Unknown recipient type in array with index ${i}`);
  13349. }
  13350. }
  13351. return res;
  13352. }
  13353. async decrypt(recipientIndex, parameters, crypto = getCrypto(true)) {
  13354. const decryptionParameters = parameters || {};
  13355. if ((recipientIndex + 1) > this.recipientInfos.length) {
  13356. throw new Error(`Maximum value for "index" is: ${this.recipientInfos.length - 1}`);
  13357. }
  13358. const SubKeyAgreeRecipientInfo = async (index) => {
  13359. const recipientInfo = this.recipientInfos[index].value;
  13360. let curveOID;
  13361. let recipientCurve;
  13362. let recipientCurveLength;
  13363. const originator = recipientInfo.originator;
  13364. if (decryptionParameters.recipientCertificate) {
  13365. const curveObject = decryptionParameters.recipientCertificate.subjectPublicKeyInfo.algorithm.algorithmParams;
  13366. if (curveObject.constructor.blockName() !== asn1js.ObjectIdentifier.blockName()) {
  13367. throw new Error(`Incorrect "recipientCertificate" for index ${index}`);
  13368. }
  13369. curveOID = curveObject.valueBlock.toString();
  13370. }
  13371. else if (originator.value.algorithm.algorithmParams) {
  13372. const curveObject = originator.value.algorithm.algorithmParams;
  13373. if (curveObject.constructor.blockName() !== asn1js.ObjectIdentifier.blockName()) {
  13374. throw new Error(`Incorrect originator for index ${index}`);
  13375. }
  13376. curveOID = curveObject.valueBlock.toString();
  13377. }
  13378. else {
  13379. throw new Error("Parameter \"recipientCertificate\" is mandatory for \"KeyAgreeRecipientInfo\" if algorithm params are missing from originator");
  13380. }
  13381. if (!decryptionParameters.recipientPrivateKey)
  13382. throw new Error("Parameter \"recipientPrivateKey\" is mandatory for \"KeyAgreeRecipientInfo\"");
  13383. switch (curveOID) {
  13384. case "1.2.840.10045.3.1.7":
  13385. recipientCurve = "P-256";
  13386. recipientCurveLength = 256;
  13387. break;
  13388. case "1.3.132.0.34":
  13389. recipientCurve = "P-384";
  13390. recipientCurveLength = 384;
  13391. break;
  13392. case "1.3.132.0.35":
  13393. recipientCurve = "P-521";
  13394. recipientCurveLength = 528;
  13395. break;
  13396. default:
  13397. throw new Error(`Incorrect curve OID for index ${index}`);
  13398. }
  13399. let ecdhPrivateKey;
  13400. let keyCrypto = crypto;
  13401. if (BufferSourceConverter.isBufferSource(decryptionParameters.recipientPrivateKey)) {
  13402. ecdhPrivateKey = await crypto.importKey("pkcs8", decryptionParameters.recipientPrivateKey, {
  13403. name: "ECDH",
  13404. namedCurve: recipientCurve
  13405. }, true, ["deriveBits"]);
  13406. }
  13407. else {
  13408. ecdhPrivateKey = decryptionParameters.recipientPrivateKey;
  13409. if ("crypto" in decryptionParameters && decryptionParameters.crypto) {
  13410. keyCrypto = decryptionParameters.crypto.subtle;
  13411. }
  13412. }
  13413. if (("algorithmParams" in originator.value.algorithm) === false)
  13414. originator.value.algorithm.algorithmParams = new asn1js.ObjectIdentifier({ value: curveOID });
  13415. const buffer = originator.value.toSchema().toBER(false);
  13416. const ecdhPublicKey = await crypto.importKey("spki", buffer, {
  13417. name: "ECDH",
  13418. namedCurve: recipientCurve
  13419. }, true, []);
  13420. const sharedSecret = await keyCrypto.deriveBits({
  13421. name: "ECDH",
  13422. public: ecdhPublicKey
  13423. }, ecdhPrivateKey, recipientCurveLength);
  13424. async function applyKDF(includeAlgorithmParams) {
  13425. includeAlgorithmParams = includeAlgorithmParams || false;
  13426. const aesKWAlgorithm = new AlgorithmIdentifier({ schema: recipientInfo.keyEncryptionAlgorithm.algorithmParams });
  13427. const kwAlgorithm = crypto.getAlgorithmByOID(aesKWAlgorithm.algorithmId, true, "kwAlgorithm");
  13428. let kwLength = kwAlgorithm.length;
  13429. const kwLengthBuffer = new ArrayBuffer(4);
  13430. const kwLengthView = new Uint8Array(kwLengthBuffer);
  13431. for (let j = 3; j >= 0; j--) {
  13432. kwLengthView[j] = kwLength;
  13433. kwLength >>= 8;
  13434. }
  13435. const keyInfoAlgorithm = {
  13436. algorithmId: aesKWAlgorithm.algorithmId
  13437. };
  13438. if (includeAlgorithmParams) {
  13439. keyInfoAlgorithm.algorithmParams = new asn1js.Null();
  13440. }
  13441. const eccInfo = new ECCCMSSharedInfo({
  13442. keyInfo: new AlgorithmIdentifier(keyInfoAlgorithm),
  13443. entityUInfo: recipientInfo.ukm,
  13444. suppPubInfo: new asn1js.OctetString({ valueHex: kwLengthBuffer })
  13445. });
  13446. const encodedInfo = eccInfo.toSchema().toBER(false);
  13447. const ecdhAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "ecdhAlgorithm");
  13448. if (!ecdhAlgorithm.name) {
  13449. throw new Error(`Incorrect OID for key encryption algorithm: ${recipientInfo.keyEncryptionAlgorithm.algorithmId}`);
  13450. }
  13451. return kdf(ecdhAlgorithm.kdf, sharedSecret, kwAlgorithm.length, encodedInfo, crypto);
  13452. }
  13453. const kdfResult = await applyKDF();
  13454. const importAesKwKey = async (kdfResult) => {
  13455. return crypto.importKey("raw", kdfResult, { name: "AES-KW" }, true, ["unwrapKey"]);
  13456. };
  13457. const aesKwKey = await importAesKwKey(kdfResult);
  13458. const unwrapSessionKey = async (aesKwKey) => {
  13459. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13460. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13461. return crypto.unwrapKey("raw", recipientInfo.recipientEncryptedKeys.encryptedKeys[0].encryptedKey.valueBlock.valueHexView, aesKwKey, { name: "AES-KW" }, contentEncryptionAlgorithm, true, ["decrypt"]);
  13462. };
  13463. try {
  13464. return await unwrapSessionKey(aesKwKey);
  13465. }
  13466. catch {
  13467. const kdfResult = await applyKDF(true);
  13468. const aesKwKey = await importAesKwKey(kdfResult);
  13469. return unwrapSessionKey(aesKwKey);
  13470. }
  13471. };
  13472. const SubKeyTransRecipientInfo = async (index) => {
  13473. const recipientInfo = this.recipientInfos[index].value;
  13474. if (!decryptionParameters.recipientPrivateKey) {
  13475. throw new Error("Parameter \"recipientPrivateKey\" is mandatory for \"KeyTransRecipientInfo\"");
  13476. }
  13477. const algorithmParameters = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "keyEncryptionAlgorithm");
  13478. if (algorithmParameters.name === "RSA-OAEP") {
  13479. const schema = recipientInfo.keyEncryptionAlgorithm.algorithmParams;
  13480. const rsaOAEPParams = new RSAESOAEPParams({ schema });
  13481. algorithmParameters.hash = crypto.getAlgorithmByOID(rsaOAEPParams.hashAlgorithm.algorithmId);
  13482. if (("name" in algorithmParameters.hash) === false)
  13483. throw new Error(`Incorrect OID for hash algorithm: ${rsaOAEPParams.hashAlgorithm.algorithmId}`);
  13484. }
  13485. let privateKey;
  13486. let keyCrypto = crypto;
  13487. if (BufferSourceConverter.isBufferSource(decryptionParameters.recipientPrivateKey)) {
  13488. privateKey = await crypto.importKey("pkcs8", decryptionParameters.recipientPrivateKey, algorithmParameters, true, ["decrypt"]);
  13489. }
  13490. else {
  13491. privateKey = decryptionParameters.recipientPrivateKey;
  13492. if ("crypto" in decryptionParameters && decryptionParameters.crypto) {
  13493. keyCrypto = decryptionParameters.crypto.subtle;
  13494. }
  13495. }
  13496. const sessionKey = await keyCrypto.decrypt(privateKey.algorithm, privateKey, recipientInfo.encryptedKey.valueBlock.valueHexView);
  13497. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13498. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13499. if (("name" in contentEncryptionAlgorithm) === false)
  13500. throw new Error(`Incorrect "contentEncryptionAlgorithm": ${algorithmId}`);
  13501. return crypto.importKey("raw", sessionKey, contentEncryptionAlgorithm, true, ["decrypt"]);
  13502. };
  13503. const SubKEKRecipientInfo = async (index) => {
  13504. const recipientInfo = this.recipientInfos[index].value;
  13505. if (!decryptionParameters.preDefinedData)
  13506. throw new Error("Parameter \"preDefinedData\" is mandatory for \"KEKRecipientInfo\"");
  13507. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "kekAlgorithm");
  13508. const importedKey = await crypto.importKey("raw", decryptionParameters.preDefinedData, kekAlgorithm, true, ["unwrapKey"]);
  13509. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13510. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13511. if (!contentEncryptionAlgorithm.name) {
  13512. throw new Error(`Incorrect "contentEncryptionAlgorithm": ${algorithmId}`);
  13513. }
  13514. return crypto.unwrapKey("raw", recipientInfo.encryptedKey.valueBlock.valueHexView, importedKey, kekAlgorithm, contentEncryptionAlgorithm, true, ["decrypt"]);
  13515. };
  13516. const SubPasswordRecipientinfo = async (index) => {
  13517. const recipientInfo = this.recipientInfos[index].value;
  13518. let pbkdf2Params;
  13519. if (!decryptionParameters.preDefinedData) {
  13520. throw new Error("Parameter \"preDefinedData\" is mandatory for \"KEKRecipientInfo\"");
  13521. }
  13522. if (!recipientInfo.keyDerivationAlgorithm) {
  13523. throw new Error("Please append encoded \"keyDerivationAlgorithm\"");
  13524. }
  13525. if (!recipientInfo.keyDerivationAlgorithm.algorithmParams) {
  13526. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13527. }
  13528. try {
  13529. pbkdf2Params = new PBKDF2Params({ schema: recipientInfo.keyDerivationAlgorithm.algorithmParams });
  13530. }
  13531. catch {
  13532. throw new Error("Incorrectly encoded \"keyDerivationAlgorithm\"");
  13533. }
  13534. const pbkdf2Key = await crypto.importKey("raw", decryptionParameters.preDefinedData, "PBKDF2", false, ["deriveKey"]);
  13535. const kekAlgorithm = crypto.getAlgorithmByOID(recipientInfo.keyEncryptionAlgorithm.algorithmId, true, "keyEncryptionAlgorithm");
  13536. const hmacHashAlgorithm = pbkdf2Params.prf
  13537. ? crypto.getAlgorithmByOID(pbkdf2Params.prf.algorithmId, true, "prfAlgorithm").hash.name
  13538. : "SHA-1";
  13539. const saltView = new Uint8Array(pbkdf2Params.salt.valueBlock.valueHex);
  13540. const iterations = pbkdf2Params.iterationCount;
  13541. const kekKey = await crypto.deriveKey({
  13542. name: "PBKDF2",
  13543. hash: {
  13544. name: hmacHashAlgorithm
  13545. },
  13546. salt: saltView,
  13547. iterations
  13548. }, pbkdf2Key, kekAlgorithm, true, ["unwrapKey"]);
  13549. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13550. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13551. return crypto.unwrapKey("raw", recipientInfo.encryptedKey.valueBlock.valueHexView, kekKey, kekAlgorithm, contentEncryptionAlgorithm, true, ["decrypt"]);
  13552. };
  13553. let unwrappedKey;
  13554. switch (this.recipientInfos[recipientIndex].variant) {
  13555. case 1:
  13556. unwrappedKey = await SubKeyTransRecipientInfo(recipientIndex);
  13557. break;
  13558. case 2:
  13559. unwrappedKey = await SubKeyAgreeRecipientInfo(recipientIndex);
  13560. break;
  13561. case 3:
  13562. unwrappedKey = await SubKEKRecipientInfo(recipientIndex);
  13563. break;
  13564. case 4:
  13565. unwrappedKey = await SubPasswordRecipientinfo(recipientIndex);
  13566. break;
  13567. default:
  13568. throw new Error(`Unknown recipient type in array with index ${recipientIndex}`);
  13569. }
  13570. const algorithmId = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmId;
  13571. const contentEncryptionAlgorithm = crypto.getAlgorithmByOID(algorithmId, true, "contentEncryptionAlgorithm");
  13572. const ivBuffer = this.encryptedContentInfo.contentEncryptionAlgorithm.algorithmParams.valueBlock.valueHex;
  13573. const ivView = new Uint8Array(ivBuffer);
  13574. if (!this.encryptedContentInfo.encryptedContent) {
  13575. throw new Error("Required property `encryptedContent` is empty");
  13576. }
  13577. const dataBuffer = this.encryptedContentInfo.getEncryptedContent();
  13578. return crypto.decrypt({
  13579. name: contentEncryptionAlgorithm.name,
  13580. iv: ivView
  13581. }, unwrappedKey, dataBuffer);
  13582. }
  13583. }
  13584. EnvelopedData.CLASS_NAME = "EnvelopedData";
  13585. const SAFE_CONTENTS = "safeContents";
  13586. const PARSED_VALUE$1 = "parsedValue";
  13587. const CONTENT_INFOS = "contentInfos";
  13588. class AuthenticatedSafe extends PkiObject {
  13589. constructor(parameters = {}) {
  13590. super();
  13591. this.safeContents = pvutils.getParametersValue(parameters, SAFE_CONTENTS, AuthenticatedSafe.defaultValues(SAFE_CONTENTS));
  13592. if (PARSED_VALUE$1 in parameters) {
  13593. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE$1, AuthenticatedSafe.defaultValues(PARSED_VALUE$1));
  13594. }
  13595. if (parameters.schema) {
  13596. this.fromSchema(parameters.schema);
  13597. }
  13598. }
  13599. static defaultValues(memberName) {
  13600. switch (memberName) {
  13601. case SAFE_CONTENTS:
  13602. return [];
  13603. case PARSED_VALUE$1:
  13604. return {};
  13605. default:
  13606. return super.defaultValues(memberName);
  13607. }
  13608. }
  13609. static compareWithDefault(memberName, memberValue) {
  13610. switch (memberName) {
  13611. case SAFE_CONTENTS:
  13612. return (memberValue.length === 0);
  13613. case PARSED_VALUE$1:
  13614. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  13615. default:
  13616. return super.defaultValues(memberName);
  13617. }
  13618. }
  13619. static schema(parameters = {}) {
  13620. const names = pvutils.getParametersValue(parameters, "names", {});
  13621. return (new asn1js.Sequence({
  13622. name: (names.blockName || EMPTY_STRING),
  13623. value: [
  13624. new asn1js.Repeated({
  13625. name: (names.contentInfos || EMPTY_STRING),
  13626. value: ContentInfo.schema()
  13627. })
  13628. ]
  13629. }));
  13630. }
  13631. fromSchema(schema) {
  13632. pvutils.clearProps(schema, [
  13633. CONTENT_INFOS
  13634. ]);
  13635. const asn1 = asn1js.compareSchema(schema, schema, AuthenticatedSafe.schema({
  13636. names: {
  13637. contentInfos: CONTENT_INFOS
  13638. }
  13639. }));
  13640. AsnError.assertSchema(asn1, this.className);
  13641. this.safeContents = Array.from(asn1.result.contentInfos, element => new ContentInfo({ schema: element }));
  13642. }
  13643. toSchema() {
  13644. return (new asn1js.Sequence({
  13645. value: Array.from(this.safeContents, o => o.toSchema())
  13646. }));
  13647. }
  13648. toJSON() {
  13649. return {
  13650. safeContents: Array.from(this.safeContents, o => o.toJSON())
  13651. };
  13652. }
  13653. async parseInternalValues(parameters, crypto = getCrypto(true)) {
  13654. ParameterError.assert(parameters, SAFE_CONTENTS);
  13655. ArgumentError.assert(parameters.safeContents, SAFE_CONTENTS, "Array");
  13656. if (parameters.safeContents.length !== this.safeContents.length) {
  13657. throw new ArgumentError("Length of \"parameters.safeContents\" must be equal to \"this.safeContents.length\"");
  13658. }
  13659. this.parsedValue = {
  13660. safeContents: [],
  13661. };
  13662. for (const [index, content] of this.safeContents.entries()) {
  13663. const safeContent = parameters.safeContents[index];
  13664. const errorTarget = `parameters.safeContents[${index}]`;
  13665. switch (content.contentType) {
  13666. case id_ContentType_Data:
  13667. {
  13668. ArgumentError.assert(content.content, "this.safeContents[j].content", asn1js.OctetString);
  13669. const authSafeContent = content.content.getValue();
  13670. this.parsedValue.safeContents.push({
  13671. privacyMode: 0,
  13672. value: SafeContents.fromBER(authSafeContent)
  13673. });
  13674. }
  13675. break;
  13676. case id_ContentType_EnvelopedData:
  13677. {
  13678. const cmsEnveloped = new EnvelopedData({ schema: content.content });
  13679. ParameterError.assert(errorTarget, safeContent, "recipientCertificate", "recipientKey");
  13680. const envelopedData = safeContent;
  13681. const recipientCertificate = envelopedData.recipientCertificate;
  13682. const recipientKey = envelopedData.recipientKey;
  13683. const decrypted = await cmsEnveloped.decrypt(0, {
  13684. recipientCertificate,
  13685. recipientPrivateKey: recipientKey
  13686. }, crypto);
  13687. this.parsedValue.safeContents.push({
  13688. privacyMode: 2,
  13689. value: SafeContents.fromBER(decrypted),
  13690. });
  13691. }
  13692. break;
  13693. case id_ContentType_EncryptedData:
  13694. {
  13695. const cmsEncrypted = new EncryptedData({ schema: content.content });
  13696. ParameterError.assert(errorTarget, safeContent, "password");
  13697. const password = safeContent.password;
  13698. const decrypted = await cmsEncrypted.decrypt({
  13699. password
  13700. }, crypto);
  13701. this.parsedValue.safeContents.push({
  13702. privacyMode: 1,
  13703. value: SafeContents.fromBER(decrypted),
  13704. });
  13705. }
  13706. break;
  13707. default:
  13708. throw new Error(`Unknown "contentType" for AuthenticatedSafe: " ${content.contentType}`);
  13709. }
  13710. }
  13711. }
  13712. async makeInternalValues(parameters, crypto = getCrypto(true)) {
  13713. if (!(this.parsedValue)) {
  13714. throw new Error("Please run \"parseValues\" first or add \"parsedValue\" manually");
  13715. }
  13716. ArgumentError.assert(this.parsedValue, "this.parsedValue", "object");
  13717. ArgumentError.assert(this.parsedValue.safeContents, "this.parsedValue.safeContents", "Array");
  13718. ArgumentError.assert(parameters, "parameters", "object");
  13719. ParameterError.assert(parameters, "safeContents");
  13720. ArgumentError.assert(parameters.safeContents, "parameters.safeContents", "Array");
  13721. if (parameters.safeContents.length !== this.parsedValue.safeContents.length) {
  13722. throw new ArgumentError("Length of \"parameters.safeContents\" must be equal to \"this.parsedValue.safeContents\"");
  13723. }
  13724. this.safeContents = [];
  13725. for (const [index, content] of this.parsedValue.safeContents.entries()) {
  13726. ParameterError.assert("content", content, "privacyMode", "value");
  13727. ArgumentError.assert(content.value, "content.value", SafeContents);
  13728. switch (content.privacyMode) {
  13729. case 0:
  13730. {
  13731. const contentBuffer = content.value.toSchema().toBER(false);
  13732. this.safeContents.push(new ContentInfo({
  13733. contentType: "1.2.840.113549.1.7.1",
  13734. content: new asn1js.OctetString({ valueHex: contentBuffer })
  13735. }));
  13736. }
  13737. break;
  13738. case 1:
  13739. {
  13740. const cmsEncrypted = new EncryptedData();
  13741. const currentParameters = parameters.safeContents[index];
  13742. currentParameters.contentToEncrypt = content.value.toSchema().toBER(false);
  13743. await cmsEncrypted.encrypt(currentParameters, crypto);
  13744. this.safeContents.push(new ContentInfo({
  13745. contentType: "1.2.840.113549.1.7.6",
  13746. content: cmsEncrypted.toSchema()
  13747. }));
  13748. }
  13749. break;
  13750. case 2:
  13751. {
  13752. const cmsEnveloped = new EnvelopedData();
  13753. const contentToEncrypt = content.value.toSchema().toBER(false);
  13754. const safeContent = parameters.safeContents[index];
  13755. ParameterError.assert(`parameters.safeContents[${index}]`, safeContent, "encryptingCertificate", "encryptionAlgorithm");
  13756. switch (true) {
  13757. case (safeContent.encryptionAlgorithm.name.toLowerCase() === "aes-cbc"):
  13758. case (safeContent.encryptionAlgorithm.name.toLowerCase() === "aes-gcm"):
  13759. break;
  13760. default:
  13761. throw new Error(`Incorrect parameter "encryptionAlgorithm" in "parameters.safeContents[i]": ${safeContent.encryptionAlgorithm}`);
  13762. }
  13763. switch (true) {
  13764. case (safeContent.encryptionAlgorithm.length === 128):
  13765. case (safeContent.encryptionAlgorithm.length === 192):
  13766. case (safeContent.encryptionAlgorithm.length === 256):
  13767. break;
  13768. default:
  13769. throw new Error(`Incorrect parameter "encryptionAlgorithm.length" in "parameters.safeContents[i]": ${safeContent.encryptionAlgorithm.length}`);
  13770. }
  13771. const encryptionAlgorithm = safeContent.encryptionAlgorithm;
  13772. cmsEnveloped.addRecipientByCertificate(safeContent.encryptingCertificate, {}, undefined, crypto);
  13773. await cmsEnveloped.encrypt(encryptionAlgorithm, contentToEncrypt, crypto);
  13774. this.safeContents.push(new ContentInfo({
  13775. contentType: "1.2.840.113549.1.7.3",
  13776. content: cmsEnveloped.toSchema()
  13777. }));
  13778. }
  13779. break;
  13780. default:
  13781. throw new Error(`Incorrect value for "content.privacyMode": ${content.privacyMode}`);
  13782. }
  13783. }
  13784. return this;
  13785. }
  13786. }
  13787. AuthenticatedSafe.CLASS_NAME = "AuthenticatedSafe";
  13788. const HASH_ALGORITHM$1 = "hashAlgorithm";
  13789. const ISSUER_NAME_HASH = "issuerNameHash";
  13790. const ISSUER_KEY_HASH = "issuerKeyHash";
  13791. const SERIAL_NUMBER$1 = "serialNumber";
  13792. const CLEAR_PROPS$j = [
  13793. HASH_ALGORITHM$1,
  13794. ISSUER_NAME_HASH,
  13795. ISSUER_KEY_HASH,
  13796. SERIAL_NUMBER$1,
  13797. ];
  13798. class CertID extends PkiObject {
  13799. static async create(certificate, parameters, crypto = getCrypto(true)) {
  13800. const certID = new CertID();
  13801. await certID.createForCertificate(certificate, parameters, crypto);
  13802. return certID;
  13803. }
  13804. constructor(parameters = {}) {
  13805. super();
  13806. this.hashAlgorithm = pvutils.getParametersValue(parameters, HASH_ALGORITHM$1, CertID.defaultValues(HASH_ALGORITHM$1));
  13807. this.issuerNameHash = pvutils.getParametersValue(parameters, ISSUER_NAME_HASH, CertID.defaultValues(ISSUER_NAME_HASH));
  13808. this.issuerKeyHash = pvutils.getParametersValue(parameters, ISSUER_KEY_HASH, CertID.defaultValues(ISSUER_KEY_HASH));
  13809. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER$1, CertID.defaultValues(SERIAL_NUMBER$1));
  13810. if (parameters.schema) {
  13811. this.fromSchema(parameters.schema);
  13812. }
  13813. }
  13814. static defaultValues(memberName) {
  13815. switch (memberName) {
  13816. case HASH_ALGORITHM$1:
  13817. return new AlgorithmIdentifier();
  13818. case ISSUER_NAME_HASH:
  13819. case ISSUER_KEY_HASH:
  13820. return new asn1js.OctetString();
  13821. case SERIAL_NUMBER$1:
  13822. return new asn1js.Integer();
  13823. default:
  13824. return super.defaultValues(memberName);
  13825. }
  13826. }
  13827. static compareWithDefault(memberName, memberValue) {
  13828. switch (memberName) {
  13829. case HASH_ALGORITHM$1:
  13830. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  13831. case ISSUER_NAME_HASH:
  13832. case ISSUER_KEY_HASH:
  13833. case SERIAL_NUMBER$1:
  13834. return (memberValue.isEqual(CertID.defaultValues(SERIAL_NUMBER$1)));
  13835. default:
  13836. return super.defaultValues(memberName);
  13837. }
  13838. }
  13839. static schema(parameters = {}) {
  13840. const names = pvutils.getParametersValue(parameters, "names", {});
  13841. return (new asn1js.Sequence({
  13842. name: (names.blockName || EMPTY_STRING),
  13843. value: [
  13844. AlgorithmIdentifier.schema(names.hashAlgorithmObject || {
  13845. names: {
  13846. blockName: (names.hashAlgorithm || EMPTY_STRING)
  13847. }
  13848. }),
  13849. new asn1js.OctetString({ name: (names.issuerNameHash || EMPTY_STRING) }),
  13850. new asn1js.OctetString({ name: (names.issuerKeyHash || EMPTY_STRING) }),
  13851. new asn1js.Integer({ name: (names.serialNumber || EMPTY_STRING) })
  13852. ]
  13853. }));
  13854. }
  13855. fromSchema(schema) {
  13856. pvutils.clearProps(schema, CLEAR_PROPS$j);
  13857. const asn1 = asn1js.compareSchema(schema, schema, CertID.schema({
  13858. names: {
  13859. hashAlgorithm: HASH_ALGORITHM$1,
  13860. issuerNameHash: ISSUER_NAME_HASH,
  13861. issuerKeyHash: ISSUER_KEY_HASH,
  13862. serialNumber: SERIAL_NUMBER$1
  13863. }
  13864. }));
  13865. AsnError.assertSchema(asn1, this.className);
  13866. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  13867. this.issuerNameHash = asn1.result.issuerNameHash;
  13868. this.issuerKeyHash = asn1.result.issuerKeyHash;
  13869. this.serialNumber = asn1.result.serialNumber;
  13870. }
  13871. toSchema() {
  13872. return (new asn1js.Sequence({
  13873. value: [
  13874. this.hashAlgorithm.toSchema(),
  13875. this.issuerNameHash,
  13876. this.issuerKeyHash,
  13877. this.serialNumber
  13878. ]
  13879. }));
  13880. }
  13881. toJSON() {
  13882. return {
  13883. hashAlgorithm: this.hashAlgorithm.toJSON(),
  13884. issuerNameHash: this.issuerNameHash.toJSON(),
  13885. issuerKeyHash: this.issuerKeyHash.toJSON(),
  13886. serialNumber: this.serialNumber.toJSON(),
  13887. };
  13888. }
  13889. isEqual(certificateID) {
  13890. if (this.hashAlgorithm.algorithmId !== certificateID.hashAlgorithm.algorithmId) {
  13891. return false;
  13892. }
  13893. if (!pvtsutils.BufferSourceConverter.isEqual(this.issuerNameHash.valueBlock.valueHexView, certificateID.issuerNameHash.valueBlock.valueHexView)) {
  13894. return false;
  13895. }
  13896. if (!pvtsutils.BufferSourceConverter.isEqual(this.issuerKeyHash.valueBlock.valueHexView, certificateID.issuerKeyHash.valueBlock.valueHexView)) {
  13897. return false;
  13898. }
  13899. if (!this.serialNumber.isEqual(certificateID.serialNumber)) {
  13900. return false;
  13901. }
  13902. return true;
  13903. }
  13904. async createForCertificate(certificate, parameters, crypto = getCrypto(true)) {
  13905. ParameterError.assert(parameters, HASH_ALGORITHM$1, "issuerCertificate");
  13906. const hashOID = crypto.getOIDByAlgorithm({ name: parameters.hashAlgorithm }, true, "hashAlgorithm");
  13907. this.hashAlgorithm = new AlgorithmIdentifier({
  13908. algorithmId: hashOID,
  13909. algorithmParams: new asn1js.Null()
  13910. });
  13911. const issuerCertificate = parameters.issuerCertificate;
  13912. this.serialNumber = certificate.serialNumber;
  13913. const hashIssuerName = await crypto.digest({ name: parameters.hashAlgorithm }, issuerCertificate.subject.toSchema().toBER(false));
  13914. this.issuerNameHash = new asn1js.OctetString({ valueHex: hashIssuerName });
  13915. const issuerKeyBuffer = issuerCertificate.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView;
  13916. const hashIssuerKey = await crypto.digest({ name: parameters.hashAlgorithm }, issuerKeyBuffer);
  13917. this.issuerKeyHash = new asn1js.OctetString({ valueHex: hashIssuerKey });
  13918. }
  13919. }
  13920. CertID.CLASS_NAME = "CertID";
  13921. const CERT_ID = "certID";
  13922. const CERT_STATUS = "certStatus";
  13923. const THIS_UPDATE = "thisUpdate";
  13924. const NEXT_UPDATE = "nextUpdate";
  13925. const SINGLE_EXTENSIONS = "singleExtensions";
  13926. const CLEAR_PROPS$i = [
  13927. CERT_ID,
  13928. CERT_STATUS,
  13929. THIS_UPDATE,
  13930. NEXT_UPDATE,
  13931. SINGLE_EXTENSIONS,
  13932. ];
  13933. class SingleResponse extends PkiObject {
  13934. constructor(parameters = {}) {
  13935. super();
  13936. this.certID = pvutils.getParametersValue(parameters, CERT_ID, SingleResponse.defaultValues(CERT_ID));
  13937. this.certStatus = pvutils.getParametersValue(parameters, CERT_STATUS, SingleResponse.defaultValues(CERT_STATUS));
  13938. this.thisUpdate = pvutils.getParametersValue(parameters, THIS_UPDATE, SingleResponse.defaultValues(THIS_UPDATE));
  13939. if (NEXT_UPDATE in parameters) {
  13940. this.nextUpdate = pvutils.getParametersValue(parameters, NEXT_UPDATE, SingleResponse.defaultValues(NEXT_UPDATE));
  13941. }
  13942. if (SINGLE_EXTENSIONS in parameters) {
  13943. this.singleExtensions = pvutils.getParametersValue(parameters, SINGLE_EXTENSIONS, SingleResponse.defaultValues(SINGLE_EXTENSIONS));
  13944. }
  13945. if (parameters.schema) {
  13946. this.fromSchema(parameters.schema);
  13947. }
  13948. }
  13949. static defaultValues(memberName) {
  13950. switch (memberName) {
  13951. case CERT_ID:
  13952. return new CertID();
  13953. case CERT_STATUS:
  13954. return {};
  13955. case THIS_UPDATE:
  13956. case NEXT_UPDATE:
  13957. return new Date(0, 0, 0);
  13958. case SINGLE_EXTENSIONS:
  13959. return [];
  13960. default:
  13961. return super.defaultValues(memberName);
  13962. }
  13963. }
  13964. static compareWithDefault(memberName, memberValue) {
  13965. switch (memberName) {
  13966. case CERT_ID:
  13967. return ((CertID.compareWithDefault("hashAlgorithm", memberValue.hashAlgorithm)) &&
  13968. (CertID.compareWithDefault("issuerNameHash", memberValue.issuerNameHash)) &&
  13969. (CertID.compareWithDefault("issuerKeyHash", memberValue.issuerKeyHash)) &&
  13970. (CertID.compareWithDefault("serialNumber", memberValue.serialNumber)));
  13971. case CERT_STATUS:
  13972. return (Object.keys(memberValue).length === 0);
  13973. case THIS_UPDATE:
  13974. case NEXT_UPDATE:
  13975. return (memberValue === SingleResponse.defaultValues(memberName));
  13976. default:
  13977. return super.defaultValues(memberName);
  13978. }
  13979. }
  13980. static schema(parameters = {}) {
  13981. const names = pvutils.getParametersValue(parameters, "names", {});
  13982. return (new asn1js.Sequence({
  13983. name: (names.blockName || EMPTY_STRING),
  13984. value: [
  13985. CertID.schema(names.certID || {}),
  13986. new asn1js.Choice({
  13987. value: [
  13988. new asn1js.Primitive({
  13989. name: (names.certStatus || EMPTY_STRING),
  13990. idBlock: {
  13991. tagClass: 3,
  13992. tagNumber: 0
  13993. },
  13994. }),
  13995. new asn1js.Constructed({
  13996. name: (names.certStatus || EMPTY_STRING),
  13997. idBlock: {
  13998. tagClass: 3,
  13999. tagNumber: 1
  14000. },
  14001. value: [
  14002. new asn1js.GeneralizedTime(),
  14003. new asn1js.Constructed({
  14004. optional: true,
  14005. idBlock: {
  14006. tagClass: 3,
  14007. tagNumber: 0
  14008. },
  14009. value: [new asn1js.Enumerated()]
  14010. })
  14011. ]
  14012. }),
  14013. new asn1js.Primitive({
  14014. name: (names.certStatus || EMPTY_STRING),
  14015. idBlock: {
  14016. tagClass: 3,
  14017. tagNumber: 2
  14018. },
  14019. lenBlock: { length: 1 }
  14020. })
  14021. ]
  14022. }),
  14023. new asn1js.GeneralizedTime({ name: (names.thisUpdate || EMPTY_STRING) }),
  14024. new asn1js.Constructed({
  14025. optional: true,
  14026. idBlock: {
  14027. tagClass: 3,
  14028. tagNumber: 0
  14029. },
  14030. value: [new asn1js.GeneralizedTime({ name: (names.nextUpdate || EMPTY_STRING) })]
  14031. }),
  14032. new asn1js.Constructed({
  14033. optional: true,
  14034. idBlock: {
  14035. tagClass: 3,
  14036. tagNumber: 1
  14037. },
  14038. value: [Extensions.schema(names.singleExtensions || {})]
  14039. })
  14040. ]
  14041. }));
  14042. }
  14043. fromSchema(schema) {
  14044. pvutils.clearProps(schema, CLEAR_PROPS$i);
  14045. const asn1 = asn1js.compareSchema(schema, schema, SingleResponse.schema({
  14046. names: {
  14047. certID: {
  14048. names: {
  14049. blockName: CERT_ID
  14050. }
  14051. },
  14052. certStatus: CERT_STATUS,
  14053. thisUpdate: THIS_UPDATE,
  14054. nextUpdate: NEXT_UPDATE,
  14055. singleExtensions: {
  14056. names: {
  14057. blockName: SINGLE_EXTENSIONS
  14058. }
  14059. }
  14060. }
  14061. }));
  14062. AsnError.assertSchema(asn1, this.className);
  14063. this.certID = new CertID({ schema: asn1.result.certID });
  14064. this.certStatus = asn1.result.certStatus;
  14065. this.thisUpdate = asn1.result.thisUpdate.toDate();
  14066. if (NEXT_UPDATE in asn1.result)
  14067. this.nextUpdate = asn1.result.nextUpdate.toDate();
  14068. if (SINGLE_EXTENSIONS in asn1.result)
  14069. this.singleExtensions = Array.from(asn1.result.singleExtensions.valueBlock.value, element => new Extension({ schema: element }));
  14070. }
  14071. toSchema() {
  14072. const outputArray = [];
  14073. outputArray.push(this.certID.toSchema());
  14074. outputArray.push(this.certStatus);
  14075. outputArray.push(new asn1js.GeneralizedTime({ valueDate: this.thisUpdate }));
  14076. if (this.nextUpdate) {
  14077. outputArray.push(new asn1js.Constructed({
  14078. idBlock: {
  14079. tagClass: 3,
  14080. tagNumber: 0
  14081. },
  14082. value: [new asn1js.GeneralizedTime({ valueDate: this.nextUpdate })]
  14083. }));
  14084. }
  14085. if (this.singleExtensions) {
  14086. outputArray.push(new asn1js.Constructed({
  14087. idBlock: {
  14088. tagClass: 3,
  14089. tagNumber: 1
  14090. },
  14091. value: [new asn1js.Sequence({ value: Array.from(this.singleExtensions, o => o.toSchema()) })]
  14092. }));
  14093. }
  14094. return (new asn1js.Sequence({
  14095. value: outputArray
  14096. }));
  14097. }
  14098. toJSON() {
  14099. const res = {
  14100. certID: this.certID.toJSON(),
  14101. certStatus: this.certStatus.toJSON(),
  14102. thisUpdate: this.thisUpdate
  14103. };
  14104. if (this.nextUpdate) {
  14105. res.nextUpdate = this.nextUpdate;
  14106. }
  14107. if (this.singleExtensions) {
  14108. res.singleExtensions = Array.from(this.singleExtensions, o => o.toJSON());
  14109. }
  14110. return res;
  14111. }
  14112. }
  14113. SingleResponse.CLASS_NAME = "SingleResponse";
  14114. const TBS$2 = "tbs";
  14115. const VERSION$7 = "version";
  14116. const RESPONDER_ID = "responderID";
  14117. const PRODUCED_AT = "producedAt";
  14118. const RESPONSES = "responses";
  14119. const RESPONSE_EXTENSIONS = "responseExtensions";
  14120. const RESPONSE_DATA = "ResponseData";
  14121. const RESPONSE_DATA_VERSION = `${RESPONSE_DATA}.${VERSION$7}`;
  14122. const RESPONSE_DATA_RESPONDER_ID = `${RESPONSE_DATA}.${RESPONDER_ID}`;
  14123. const RESPONSE_DATA_PRODUCED_AT = `${RESPONSE_DATA}.${PRODUCED_AT}`;
  14124. const RESPONSE_DATA_RESPONSES = `${RESPONSE_DATA}.${RESPONSES}`;
  14125. const RESPONSE_DATA_RESPONSE_EXTENSIONS = `${RESPONSE_DATA}.${RESPONSE_EXTENSIONS}`;
  14126. const CLEAR_PROPS$h = [
  14127. RESPONSE_DATA,
  14128. RESPONSE_DATA_VERSION,
  14129. RESPONSE_DATA_RESPONDER_ID,
  14130. RESPONSE_DATA_PRODUCED_AT,
  14131. RESPONSE_DATA_RESPONSES,
  14132. RESPONSE_DATA_RESPONSE_EXTENSIONS
  14133. ];
  14134. class ResponseData extends PkiObject {
  14135. get tbs() {
  14136. return pvtsutils.BufferSourceConverter.toArrayBuffer(this.tbsView);
  14137. }
  14138. set tbs(value) {
  14139. this.tbsView = new Uint8Array(value);
  14140. }
  14141. constructor(parameters = {}) {
  14142. super();
  14143. this.tbsView = new Uint8Array(pvutils.getParametersValue(parameters, TBS$2, ResponseData.defaultValues(TBS$2)));
  14144. if (VERSION$7 in parameters) {
  14145. this.version = pvutils.getParametersValue(parameters, VERSION$7, ResponseData.defaultValues(VERSION$7));
  14146. }
  14147. this.responderID = pvutils.getParametersValue(parameters, RESPONDER_ID, ResponseData.defaultValues(RESPONDER_ID));
  14148. this.producedAt = pvutils.getParametersValue(parameters, PRODUCED_AT, ResponseData.defaultValues(PRODUCED_AT));
  14149. this.responses = pvutils.getParametersValue(parameters, RESPONSES, ResponseData.defaultValues(RESPONSES));
  14150. if (RESPONSE_EXTENSIONS in parameters) {
  14151. this.responseExtensions = pvutils.getParametersValue(parameters, RESPONSE_EXTENSIONS, ResponseData.defaultValues(RESPONSE_EXTENSIONS));
  14152. }
  14153. if (parameters.schema) {
  14154. this.fromSchema(parameters.schema);
  14155. }
  14156. }
  14157. static defaultValues(memberName) {
  14158. switch (memberName) {
  14159. case VERSION$7:
  14160. return 0;
  14161. case TBS$2:
  14162. return EMPTY_BUFFER;
  14163. case RESPONDER_ID:
  14164. return {};
  14165. case PRODUCED_AT:
  14166. return new Date(0, 0, 0);
  14167. case RESPONSES:
  14168. case RESPONSE_EXTENSIONS:
  14169. return [];
  14170. default:
  14171. return super.defaultValues(memberName);
  14172. }
  14173. }
  14174. static compareWithDefault(memberName, memberValue) {
  14175. switch (memberName) {
  14176. case TBS$2:
  14177. return (memberValue.byteLength === 0);
  14178. case RESPONDER_ID:
  14179. return (Object.keys(memberValue).length === 0);
  14180. case PRODUCED_AT:
  14181. return (memberValue === ResponseData.defaultValues(memberName));
  14182. case RESPONSES:
  14183. case RESPONSE_EXTENSIONS:
  14184. return (memberValue.length === 0);
  14185. default:
  14186. return super.defaultValues(memberName);
  14187. }
  14188. }
  14189. static schema(parameters = {}) {
  14190. const names = pvutils.getParametersValue(parameters, "names", {});
  14191. return (new asn1js.Sequence({
  14192. name: (names.blockName || RESPONSE_DATA),
  14193. value: [
  14194. new asn1js.Constructed({
  14195. optional: true,
  14196. idBlock: {
  14197. tagClass: 3,
  14198. tagNumber: 0
  14199. },
  14200. value: [new asn1js.Integer({ name: (names.version || RESPONSE_DATA_VERSION) })]
  14201. }),
  14202. new asn1js.Choice({
  14203. value: [
  14204. new asn1js.Constructed({
  14205. name: (names.responderID || RESPONSE_DATA_RESPONDER_ID),
  14206. idBlock: {
  14207. tagClass: 3,
  14208. tagNumber: 1
  14209. },
  14210. value: [RelativeDistinguishedNames.schema(names.ResponseDataByName || {
  14211. names: {
  14212. blockName: "ResponseData.byName"
  14213. }
  14214. })]
  14215. }),
  14216. new asn1js.Constructed({
  14217. name: (names.responderID || RESPONSE_DATA_RESPONDER_ID),
  14218. idBlock: {
  14219. tagClass: 3,
  14220. tagNumber: 2
  14221. },
  14222. value: [new asn1js.OctetString({ name: (names.ResponseDataByKey || "ResponseData.byKey") })]
  14223. })
  14224. ]
  14225. }),
  14226. new asn1js.GeneralizedTime({ name: (names.producedAt || RESPONSE_DATA_PRODUCED_AT) }),
  14227. new asn1js.Sequence({
  14228. value: [
  14229. new asn1js.Repeated({
  14230. name: RESPONSE_DATA_RESPONSES,
  14231. value: SingleResponse.schema(names.response || {})
  14232. })
  14233. ]
  14234. }),
  14235. new asn1js.Constructed({
  14236. optional: true,
  14237. idBlock: {
  14238. tagClass: 3,
  14239. tagNumber: 1
  14240. },
  14241. value: [Extensions.schema(names.extensions || {
  14242. names: {
  14243. blockName: RESPONSE_DATA_RESPONSE_EXTENSIONS
  14244. }
  14245. })]
  14246. })
  14247. ]
  14248. }));
  14249. }
  14250. fromSchema(schema) {
  14251. pvutils.clearProps(schema, CLEAR_PROPS$h);
  14252. const asn1 = asn1js.compareSchema(schema, schema, ResponseData.schema());
  14253. AsnError.assertSchema(asn1, this.className);
  14254. this.tbsView = asn1.result.ResponseData.valueBeforeDecodeView;
  14255. if (RESPONSE_DATA_VERSION in asn1.result)
  14256. this.version = asn1.result[RESPONSE_DATA_VERSION].valueBlock.valueDec;
  14257. if (asn1.result[RESPONSE_DATA_RESPONDER_ID].idBlock.tagNumber === 1)
  14258. this.responderID = new RelativeDistinguishedNames({ schema: asn1.result[RESPONSE_DATA_RESPONDER_ID].valueBlock.value[0] });
  14259. else
  14260. this.responderID = asn1.result[RESPONSE_DATA_RESPONDER_ID].valueBlock.value[0];
  14261. this.producedAt = asn1.result[RESPONSE_DATA_PRODUCED_AT].toDate();
  14262. this.responses = Array.from(asn1.result[RESPONSE_DATA_RESPONSES], element => new SingleResponse({ schema: element }));
  14263. if (RESPONSE_DATA_RESPONSE_EXTENSIONS in asn1.result)
  14264. this.responseExtensions = Array.from(asn1.result[RESPONSE_DATA_RESPONSE_EXTENSIONS].valueBlock.value, element => new Extension({ schema: element }));
  14265. }
  14266. toSchema(encodeFlag = false) {
  14267. let tbsSchema;
  14268. if (encodeFlag === false) {
  14269. if (!this.tbsView.byteLength) {
  14270. return ResponseData.schema();
  14271. }
  14272. const asn1 = asn1js.fromBER(this.tbsView);
  14273. AsnError.assert(asn1, "TBS Response Data");
  14274. tbsSchema = asn1.result;
  14275. }
  14276. else {
  14277. const outputArray = [];
  14278. if (VERSION$7 in this) {
  14279. outputArray.push(new asn1js.Constructed({
  14280. idBlock: {
  14281. tagClass: 3,
  14282. tagNumber: 0
  14283. },
  14284. value: [new asn1js.Integer({ value: this.version })]
  14285. }));
  14286. }
  14287. if (this.responderID instanceof RelativeDistinguishedNames) {
  14288. outputArray.push(new asn1js.Constructed({
  14289. idBlock: {
  14290. tagClass: 3,
  14291. tagNumber: 1
  14292. },
  14293. value: [this.responderID.toSchema()]
  14294. }));
  14295. }
  14296. else {
  14297. outputArray.push(new asn1js.Constructed({
  14298. idBlock: {
  14299. tagClass: 3,
  14300. tagNumber: 2
  14301. },
  14302. value: [this.responderID]
  14303. }));
  14304. }
  14305. outputArray.push(new asn1js.GeneralizedTime({ valueDate: this.producedAt }));
  14306. outputArray.push(new asn1js.Sequence({
  14307. value: Array.from(this.responses, o => o.toSchema())
  14308. }));
  14309. if (this.responseExtensions) {
  14310. outputArray.push(new asn1js.Constructed({
  14311. idBlock: {
  14312. tagClass: 3,
  14313. tagNumber: 1
  14314. },
  14315. value: [new asn1js.Sequence({
  14316. value: Array.from(this.responseExtensions, o => o.toSchema())
  14317. })]
  14318. }));
  14319. }
  14320. tbsSchema = new asn1js.Sequence({
  14321. value: outputArray
  14322. });
  14323. }
  14324. return tbsSchema;
  14325. }
  14326. toJSON() {
  14327. const res = {};
  14328. if (VERSION$7 in this) {
  14329. res.version = this.version;
  14330. }
  14331. if (this.responderID) {
  14332. res.responderID = this.responderID;
  14333. }
  14334. if (this.producedAt) {
  14335. res.producedAt = this.producedAt;
  14336. }
  14337. if (this.responses) {
  14338. res.responses = Array.from(this.responses, o => o.toJSON());
  14339. }
  14340. if (this.responseExtensions) {
  14341. res.responseExtensions = Array.from(this.responseExtensions, o => o.toJSON());
  14342. }
  14343. return res;
  14344. }
  14345. }
  14346. ResponseData.CLASS_NAME = "ResponseData";
  14347. const TRUSTED_CERTS = "trustedCerts";
  14348. const CERTS$2 = "certs";
  14349. const CRLS$1 = "crls";
  14350. const OCSPS$1 = "ocsps";
  14351. const CHECK_DATE = "checkDate";
  14352. const FIND_ORIGIN = "findOrigin";
  14353. const FIND_ISSUER = "findIssuer";
  14354. var ChainValidationCode;
  14355. (function (ChainValidationCode) {
  14356. ChainValidationCode[ChainValidationCode["unknown"] = -1] = "unknown";
  14357. ChainValidationCode[ChainValidationCode["success"] = 0] = "success";
  14358. ChainValidationCode[ChainValidationCode["noRevocation"] = 11] = "noRevocation";
  14359. ChainValidationCode[ChainValidationCode["noPath"] = 60] = "noPath";
  14360. ChainValidationCode[ChainValidationCode["noValidPath"] = 97] = "noValidPath";
  14361. })(ChainValidationCode || (ChainValidationCode = {}));
  14362. class ChainValidationError extends Error {
  14363. constructor(code, message) {
  14364. super(message);
  14365. this.name = ChainValidationError.NAME;
  14366. this.code = code;
  14367. this.message = message;
  14368. }
  14369. }
  14370. ChainValidationError.NAME = "ChainValidationError";
  14371. function isTrusted(cert, trustedList) {
  14372. for (let i = 0; i < trustedList.length; i++) {
  14373. if (pvtsutils.BufferSourceConverter.isEqual(cert.tbsView, trustedList[i].tbsView)) {
  14374. return true;
  14375. }
  14376. }
  14377. return false;
  14378. }
  14379. class CertificateChainValidationEngine {
  14380. constructor(parameters = {}) {
  14381. this.trustedCerts = pvutils.getParametersValue(parameters, TRUSTED_CERTS, this.defaultValues(TRUSTED_CERTS));
  14382. this.certs = pvutils.getParametersValue(parameters, CERTS$2, this.defaultValues(CERTS$2));
  14383. this.crls = pvutils.getParametersValue(parameters, CRLS$1, this.defaultValues(CRLS$1));
  14384. this.ocsps = pvutils.getParametersValue(parameters, OCSPS$1, this.defaultValues(OCSPS$1));
  14385. this.checkDate = pvutils.getParametersValue(parameters, CHECK_DATE, this.defaultValues(CHECK_DATE));
  14386. this.findOrigin = pvutils.getParametersValue(parameters, FIND_ORIGIN, this.defaultValues(FIND_ORIGIN));
  14387. this.findIssuer = pvutils.getParametersValue(parameters, FIND_ISSUER, this.defaultValues(FIND_ISSUER));
  14388. }
  14389. static defaultFindOrigin(certificate, validationEngine) {
  14390. if (certificate.tbsView.byteLength === 0) {
  14391. certificate.tbsView = new Uint8Array(certificate.encodeTBS().toBER());
  14392. }
  14393. for (const localCert of validationEngine.certs) {
  14394. if (localCert.tbsView.byteLength === 0) {
  14395. localCert.tbsView = new Uint8Array(localCert.encodeTBS().toBER());
  14396. }
  14397. if (pvtsutils.BufferSourceConverter.isEqual(certificate.tbsView, localCert.tbsView))
  14398. return "Intermediate Certificates";
  14399. }
  14400. for (const trustedCert of validationEngine.trustedCerts) {
  14401. if (trustedCert.tbsView.byteLength === 0)
  14402. trustedCert.tbsView = new Uint8Array(trustedCert.encodeTBS().toBER());
  14403. if (pvtsutils.BufferSourceConverter.isEqual(certificate.tbsView, trustedCert.tbsView))
  14404. return "Trusted Certificates";
  14405. }
  14406. return "Unknown";
  14407. }
  14408. async defaultFindIssuer(certificate, validationEngine, crypto = getCrypto(true)) {
  14409. const result = [];
  14410. let keyIdentifier = null;
  14411. let authorityCertIssuer = null;
  14412. let authorityCertSerialNumber = null;
  14413. if (certificate.subject.isEqual(certificate.issuer)) {
  14414. try {
  14415. const verificationResult = await certificate.verify(undefined, crypto);
  14416. if (verificationResult) {
  14417. return [certificate];
  14418. }
  14419. }
  14420. catch {
  14421. }
  14422. }
  14423. if (certificate.extensions) {
  14424. for (const extension of certificate.extensions) {
  14425. if (extension.extnID === id_AuthorityKeyIdentifier && extension.parsedValue instanceof AuthorityKeyIdentifier) {
  14426. if (extension.parsedValue.keyIdentifier) {
  14427. keyIdentifier = extension.parsedValue.keyIdentifier;
  14428. }
  14429. else {
  14430. if (extension.parsedValue.authorityCertIssuer) {
  14431. authorityCertIssuer = extension.parsedValue.authorityCertIssuer;
  14432. }
  14433. if (extension.parsedValue.authorityCertSerialNumber) {
  14434. authorityCertSerialNumber = extension.parsedValue.authorityCertSerialNumber;
  14435. }
  14436. }
  14437. break;
  14438. }
  14439. }
  14440. }
  14441. function checkCertificate(possibleIssuer) {
  14442. if (keyIdentifier !== null) {
  14443. if (possibleIssuer.extensions) {
  14444. let extensionFound = false;
  14445. for (const extension of possibleIssuer.extensions) {
  14446. if (extension.extnID === id_SubjectKeyIdentifier && extension.parsedValue) {
  14447. extensionFound = true;
  14448. if (pvtsutils.BufferSourceConverter.isEqual(extension.parsedValue.valueBlock.valueHex, keyIdentifier.valueBlock.valueHexView)) {
  14449. result.push(possibleIssuer);
  14450. }
  14451. break;
  14452. }
  14453. }
  14454. if (extensionFound) {
  14455. return;
  14456. }
  14457. }
  14458. }
  14459. let authorityCertSerialNumberEqual = false;
  14460. if (authorityCertSerialNumber !== null)
  14461. authorityCertSerialNumberEqual = possibleIssuer.serialNumber.isEqual(authorityCertSerialNumber);
  14462. if (authorityCertIssuer !== null) {
  14463. if (possibleIssuer.subject.isEqual(authorityCertIssuer)) {
  14464. if (authorityCertSerialNumberEqual)
  14465. result.push(possibleIssuer);
  14466. }
  14467. }
  14468. else {
  14469. if (certificate.issuer.isEqual(possibleIssuer.subject))
  14470. result.push(possibleIssuer);
  14471. }
  14472. }
  14473. for (const trustedCert of validationEngine.trustedCerts) {
  14474. checkCertificate(trustedCert);
  14475. }
  14476. for (const intermediateCert of validationEngine.certs) {
  14477. checkCertificate(intermediateCert);
  14478. }
  14479. for (let i = result.length - 1; i >= 0; i--) {
  14480. try {
  14481. const verificationResult = await certificate.verify(result[i], crypto);
  14482. if (verificationResult === false)
  14483. result.splice(i, 1);
  14484. }
  14485. catch {
  14486. result.splice(i, 1);
  14487. }
  14488. }
  14489. return result;
  14490. }
  14491. defaultValues(memberName) {
  14492. switch (memberName) {
  14493. case TRUSTED_CERTS:
  14494. return [];
  14495. case CERTS$2:
  14496. return [];
  14497. case CRLS$1:
  14498. return [];
  14499. case OCSPS$1:
  14500. return [];
  14501. case CHECK_DATE:
  14502. return new Date();
  14503. case FIND_ORIGIN:
  14504. return CertificateChainValidationEngine.defaultFindOrigin;
  14505. case FIND_ISSUER:
  14506. return this.defaultFindIssuer;
  14507. default:
  14508. throw new Error(`Invalid member name for CertificateChainValidationEngine class: ${memberName}`);
  14509. }
  14510. }
  14511. async sort(passedWhenNotRevValues = false, crypto = getCrypto(true)) {
  14512. const localCerts = [];
  14513. const buildPath = async (certificate, crypto) => {
  14514. const result = [];
  14515. function checkUnique(array) {
  14516. let unique = true;
  14517. for (let i = 0; i < array.length; i++) {
  14518. for (let j = 0; j < array.length; j++) {
  14519. if (j === i)
  14520. continue;
  14521. if (array[i] === array[j]) {
  14522. unique = false;
  14523. break;
  14524. }
  14525. }
  14526. if (!unique)
  14527. break;
  14528. }
  14529. return unique;
  14530. }
  14531. if (isTrusted(certificate, this.trustedCerts)) {
  14532. return [[certificate]];
  14533. }
  14534. const findIssuerResult = await this.findIssuer(certificate, this, crypto);
  14535. if (findIssuerResult.length === 0) {
  14536. throw new Error("No valid certificate paths found");
  14537. }
  14538. for (let i = 0; i < findIssuerResult.length; i++) {
  14539. if (pvtsutils.BufferSourceConverter.isEqual(findIssuerResult[i].tbsView, certificate.tbsView)) {
  14540. result.push([findIssuerResult[i]]);
  14541. continue;
  14542. }
  14543. const buildPathResult = await buildPath(findIssuerResult[i], crypto);
  14544. for (let j = 0; j < buildPathResult.length; j++) {
  14545. const copy = buildPathResult[j].slice();
  14546. copy.splice(0, 0, findIssuerResult[i]);
  14547. if (checkUnique(copy))
  14548. result.push(copy);
  14549. else
  14550. result.push(buildPathResult[j]);
  14551. }
  14552. }
  14553. return result;
  14554. };
  14555. const findCRL = async (certificate) => {
  14556. const issuerCertificates = [];
  14557. const crls = [];
  14558. const crlsAndCertificates = [];
  14559. issuerCertificates.push(...localCerts.filter(element => certificate.issuer.isEqual(element.subject)));
  14560. if (issuerCertificates.length === 0) {
  14561. return {
  14562. status: 1,
  14563. statusMessage: "No certificate's issuers"
  14564. };
  14565. }
  14566. crls.push(...this.crls.filter(o => o.issuer.isEqual(certificate.issuer)));
  14567. if (crls.length === 0) {
  14568. return {
  14569. status: 2,
  14570. statusMessage: "No CRLs for specific certificate issuer"
  14571. };
  14572. }
  14573. for (let i = 0; i < crls.length; i++) {
  14574. const crl = crls[i];
  14575. if (crl.nextUpdate && crl.nextUpdate.value < this.checkDate) {
  14576. continue;
  14577. }
  14578. for (let j = 0; j < issuerCertificates.length; j++) {
  14579. try {
  14580. const result = await crls[i].verify({ issuerCertificate: issuerCertificates[j] }, crypto);
  14581. if (result) {
  14582. crlsAndCertificates.push({
  14583. crl: crls[i],
  14584. certificate: issuerCertificates[j]
  14585. });
  14586. break;
  14587. }
  14588. }
  14589. catch {
  14590. }
  14591. }
  14592. }
  14593. if (crlsAndCertificates.length) {
  14594. return {
  14595. status: 0,
  14596. statusMessage: EMPTY_STRING,
  14597. result: crlsAndCertificates
  14598. };
  14599. }
  14600. return {
  14601. status: 3,
  14602. statusMessage: "No valid CRLs found"
  14603. };
  14604. };
  14605. const findOCSP = async (certificate, issuerCertificate) => {
  14606. const hashAlgorithm = crypto.getAlgorithmByOID(certificate.signatureAlgorithm.algorithmId);
  14607. if (!hashAlgorithm.name) {
  14608. return 1;
  14609. }
  14610. if (!hashAlgorithm.hash) {
  14611. return 1;
  14612. }
  14613. for (let i = 0; i < this.ocsps.length; i++) {
  14614. const ocsp = this.ocsps[i];
  14615. const result = await ocsp.getCertificateStatus(certificate, issuerCertificate, crypto);
  14616. if (result.isForCertificate) {
  14617. if (result.status === 0)
  14618. return 0;
  14619. return 1;
  14620. }
  14621. }
  14622. return 2;
  14623. };
  14624. async function checkForCA(certificate, needToCheckCRL = false) {
  14625. let isCA = false;
  14626. let mustBeCA = false;
  14627. let keyUsagePresent = false;
  14628. let cRLSign = false;
  14629. if (certificate.extensions) {
  14630. for (let j = 0; j < certificate.extensions.length; j++) {
  14631. const extension = certificate.extensions[j];
  14632. if (extension.critical && !extension.parsedValue) {
  14633. return {
  14634. result: false,
  14635. resultCode: 6,
  14636. resultMessage: `Unable to parse critical certificate extension: ${extension.extnID}`
  14637. };
  14638. }
  14639. if (extension.extnID === id_KeyUsage) {
  14640. keyUsagePresent = true;
  14641. const view = new Uint8Array(extension.parsedValue.valueBlock.valueHex);
  14642. if ((view[0] & 0x04) === 0x04)
  14643. mustBeCA = true;
  14644. if ((view[0] & 0x02) === 0x02)
  14645. cRLSign = true;
  14646. }
  14647. if (extension.extnID === id_BasicConstraints) {
  14648. if ("cA" in extension.parsedValue) {
  14649. if (extension.parsedValue.cA === true)
  14650. isCA = true;
  14651. }
  14652. }
  14653. }
  14654. if ((mustBeCA === true) && (isCA === false)) {
  14655. return {
  14656. result: false,
  14657. resultCode: 3,
  14658. resultMessage: "Unable to build certificate chain - using \"keyCertSign\" flag set without BasicConstraints"
  14659. };
  14660. }
  14661. if ((keyUsagePresent === true) && (isCA === true) && (mustBeCA === false)) {
  14662. return {
  14663. result: false,
  14664. resultCode: 4,
  14665. resultMessage: "Unable to build certificate chain - \"keyCertSign\" flag was not set"
  14666. };
  14667. }
  14668. if ((isCA === true) && (keyUsagePresent === true) && ((needToCheckCRL) && (cRLSign === false))) {
  14669. return {
  14670. result: false,
  14671. resultCode: 5,
  14672. resultMessage: "Unable to build certificate chain - intermediate certificate must have \"cRLSign\" key usage flag"
  14673. };
  14674. }
  14675. }
  14676. if (isCA === false) {
  14677. return {
  14678. result: false,
  14679. resultCode: 7,
  14680. resultMessage: "Unable to build certificate chain - more than one possible end-user certificate"
  14681. };
  14682. }
  14683. return {
  14684. result: true,
  14685. resultCode: 0,
  14686. resultMessage: EMPTY_STRING
  14687. };
  14688. }
  14689. const basicCheck = async (path, checkDate) => {
  14690. for (let i = 0; i < path.length; i++) {
  14691. if ((path[i].notBefore.value > checkDate) ||
  14692. (path[i].notAfter.value < checkDate)) {
  14693. return {
  14694. result: false,
  14695. resultCode: 8,
  14696. resultMessage: "The certificate is either not yet valid or expired"
  14697. };
  14698. }
  14699. }
  14700. if (path.length < 2) {
  14701. return {
  14702. result: false,
  14703. resultCode: 9,
  14704. resultMessage: "Too short certificate path"
  14705. };
  14706. }
  14707. for (let i = (path.length - 2); i >= 0; i--) {
  14708. if (path[i].issuer.isEqual(path[i].subject) === false) {
  14709. if (path[i].issuer.isEqual(path[i + 1].subject) === false) {
  14710. return {
  14711. result: false,
  14712. resultCode: 10,
  14713. resultMessage: "Incorrect name chaining"
  14714. };
  14715. }
  14716. }
  14717. }
  14718. if ((this.crls.length !== 0) || (this.ocsps.length !== 0)) {
  14719. for (let i = 0; i < (path.length - 1); i++) {
  14720. let ocspResult = 2;
  14721. let crlResult = {
  14722. status: 0,
  14723. statusMessage: EMPTY_STRING
  14724. };
  14725. if (this.ocsps.length !== 0) {
  14726. ocspResult = await findOCSP(path[i], path[i + 1]);
  14727. switch (ocspResult) {
  14728. case 0:
  14729. continue;
  14730. case 1:
  14731. return {
  14732. result: false,
  14733. resultCode: 12,
  14734. resultMessage: "One of certificates was revoked via OCSP response"
  14735. };
  14736. }
  14737. }
  14738. if (this.crls.length !== 0) {
  14739. crlResult = await findCRL(path[i]);
  14740. if (crlResult.status === 0 && crlResult.result) {
  14741. for (let j = 0; j < crlResult.result.length; j++) {
  14742. const isCertificateRevoked = crlResult.result[j].crl.isCertificateRevoked(path[i]);
  14743. if (isCertificateRevoked) {
  14744. return {
  14745. result: false,
  14746. resultCode: 12,
  14747. resultMessage: "One of certificates had been revoked"
  14748. };
  14749. }
  14750. const isCertificateCA = await checkForCA(crlResult.result[j].certificate, true);
  14751. if (isCertificateCA.result === false) {
  14752. return {
  14753. result: false,
  14754. resultCode: 13,
  14755. resultMessage: "CRL issuer certificate is not a CA certificate or does not have crlSign flag"
  14756. };
  14757. }
  14758. }
  14759. }
  14760. else {
  14761. if (passedWhenNotRevValues === false) {
  14762. throw new ChainValidationError(ChainValidationCode.noRevocation, `No revocation values found for one of certificates: ${crlResult.statusMessage}`);
  14763. }
  14764. }
  14765. }
  14766. else {
  14767. if (ocspResult === 2) {
  14768. return {
  14769. result: false,
  14770. resultCode: 11,
  14771. resultMessage: "No revocation values found for one of certificates"
  14772. };
  14773. }
  14774. }
  14775. if ((ocspResult === 2) && (crlResult.status === 2) && passedWhenNotRevValues) {
  14776. const issuerCertificate = path[i + 1];
  14777. let extensionFound = false;
  14778. if (issuerCertificate.extensions) {
  14779. for (const extension of issuerCertificate.extensions) {
  14780. switch (extension.extnID) {
  14781. case id_CRLDistributionPoints:
  14782. case id_FreshestCRL:
  14783. case id_AuthorityInfoAccess:
  14784. extensionFound = true;
  14785. break;
  14786. }
  14787. }
  14788. }
  14789. if (extensionFound) {
  14790. throw new ChainValidationError(ChainValidationCode.noRevocation, `No revocation values found for one of certificates: ${crlResult.statusMessage}`);
  14791. }
  14792. }
  14793. }
  14794. }
  14795. for (const [i, cert] of path.entries()) {
  14796. if (!i) {
  14797. continue;
  14798. }
  14799. const result = await checkForCA(cert);
  14800. if (!result.result) {
  14801. return {
  14802. result: false,
  14803. resultCode: 14,
  14804. resultMessage: "One of intermediate certificates is not a CA certificate"
  14805. };
  14806. }
  14807. }
  14808. return {
  14809. result: true
  14810. };
  14811. };
  14812. localCerts.push(...this.trustedCerts);
  14813. localCerts.push(...this.certs);
  14814. for (let i = 0; i < localCerts.length; i++) {
  14815. for (let j = 0; j < localCerts.length; j++) {
  14816. if (i === j)
  14817. continue;
  14818. if (pvtsutils.BufferSourceConverter.isEqual(localCerts[i].tbsView, localCerts[j].tbsView)) {
  14819. localCerts.splice(j, 1);
  14820. i = 0;
  14821. break;
  14822. }
  14823. }
  14824. }
  14825. const leafCert = localCerts[localCerts.length - 1];
  14826. let result;
  14827. const certificatePath = [leafCert];
  14828. result = await buildPath(leafCert, crypto);
  14829. if (result.length === 0) {
  14830. throw new ChainValidationError(ChainValidationCode.noPath, "Unable to find certificate path");
  14831. }
  14832. for (let i = result.length - 1; i >= 0; i--) {
  14833. let found = false;
  14834. for (let j = 0; j < (result[i]).length; j++) {
  14835. const certificate = (result[i])[j];
  14836. for (let k = 0; k < this.trustedCerts.length; k++) {
  14837. if (pvtsutils.BufferSourceConverter.isEqual(certificate.tbsView, this.trustedCerts[k].tbsView)) {
  14838. found = true;
  14839. break;
  14840. }
  14841. }
  14842. if (found)
  14843. break;
  14844. }
  14845. if (!found) {
  14846. result.splice(i, 1);
  14847. }
  14848. }
  14849. if (result.length === 0) {
  14850. throw new ChainValidationError(ChainValidationCode.noValidPath, "No valid certificate paths found");
  14851. }
  14852. let shortestLength = result[0].length;
  14853. let shortestIndex = 0;
  14854. for (let i = 0; i < result.length; i++) {
  14855. if (result[i].length < shortestLength) {
  14856. shortestLength = result[i].length;
  14857. shortestIndex = i;
  14858. }
  14859. }
  14860. for (let i = 0; i < result[shortestIndex].length; i++)
  14861. certificatePath.push((result[shortestIndex])[i]);
  14862. result = await basicCheck(certificatePath, this.checkDate);
  14863. if (result.result === false)
  14864. throw result;
  14865. return certificatePath;
  14866. }
  14867. async verify(parameters = {}, crypto = getCrypto(true)) {
  14868. function compareDNSName(name, constraint) {
  14869. const namePrepared = stringPrep(name);
  14870. const constraintPrepared = stringPrep(constraint);
  14871. const nameSplitted = namePrepared.split(".");
  14872. const constraintSplitted = constraintPrepared.split(".");
  14873. const nameLen = nameSplitted.length;
  14874. const constrLen = constraintSplitted.length;
  14875. if ((nameLen === 0) || (constrLen === 0) || (nameLen < constrLen)) {
  14876. return false;
  14877. }
  14878. for (let i = 0; i < nameLen; i++) {
  14879. if (nameSplitted[i].length === 0) {
  14880. return false;
  14881. }
  14882. }
  14883. for (let i = 0; i < constrLen; i++) {
  14884. if (constraintSplitted[i].length === 0) {
  14885. if (i === 0) {
  14886. if (constrLen === 1) {
  14887. return false;
  14888. }
  14889. continue;
  14890. }
  14891. return false;
  14892. }
  14893. }
  14894. for (let i = 0; i < constrLen; i++) {
  14895. if (constraintSplitted[constrLen - 1 - i].length === 0) {
  14896. continue;
  14897. }
  14898. if (nameSplitted[nameLen - 1 - i].localeCompare(constraintSplitted[constrLen - 1 - i]) !== 0) {
  14899. return false;
  14900. }
  14901. }
  14902. return true;
  14903. }
  14904. function compareRFC822Name(name, constraint) {
  14905. const namePrepared = stringPrep(name);
  14906. const constraintPrepared = stringPrep(constraint);
  14907. const nameSplitted = namePrepared.split("@");
  14908. const constraintSplitted = constraintPrepared.split("@");
  14909. if ((nameSplitted.length === 0) || (constraintSplitted.length === 0) || (nameSplitted.length < constraintSplitted.length))
  14910. return false;
  14911. if (constraintSplitted.length === 1) {
  14912. const result = compareDNSName(nameSplitted[1], constraintSplitted[0]);
  14913. if (result) {
  14914. const ns = nameSplitted[1].split(".");
  14915. const cs = constraintSplitted[0].split(".");
  14916. if (cs[0].length === 0)
  14917. return true;
  14918. return ns.length === cs.length;
  14919. }
  14920. return false;
  14921. }
  14922. return (namePrepared.localeCompare(constraintPrepared) === 0);
  14923. }
  14924. function compareUniformResourceIdentifier(name, constraint) {
  14925. let namePrepared = stringPrep(name);
  14926. const constraintPrepared = stringPrep(constraint);
  14927. const ns = namePrepared.split("/");
  14928. const cs = constraintPrepared.split("/");
  14929. if (cs.length > 1)
  14930. return false;
  14931. if (ns.length > 1) {
  14932. for (let i = 0; i < ns.length; i++) {
  14933. if ((ns[i].length > 0) && (ns[i].charAt(ns[i].length - 1) !== ":")) {
  14934. const nsPort = ns[i].split(":");
  14935. namePrepared = nsPort[0];
  14936. break;
  14937. }
  14938. }
  14939. }
  14940. const result = compareDNSName(namePrepared, constraintPrepared);
  14941. if (result) {
  14942. const nameSplitted = namePrepared.split(".");
  14943. const constraintSplitted = constraintPrepared.split(".");
  14944. if (constraintSplitted[0].length === 0)
  14945. return true;
  14946. return nameSplitted.length === constraintSplitted.length;
  14947. }
  14948. return false;
  14949. }
  14950. function compareIPAddress(name, constraint) {
  14951. const nameView = name.valueBlock.valueHexView;
  14952. const constraintView = constraint.valueBlock.valueHexView;
  14953. if ((nameView.length === 4) && (constraintView.length === 8)) {
  14954. for (let i = 0; i < 4; i++) {
  14955. if ((nameView[i] ^ constraintView[i]) & constraintView[i + 4])
  14956. return false;
  14957. }
  14958. return true;
  14959. }
  14960. if ((nameView.length === 16) && (constraintView.length === 32)) {
  14961. for (let i = 0; i < 16; i++) {
  14962. if ((nameView[i] ^ constraintView[i]) & constraintView[i + 16])
  14963. return false;
  14964. }
  14965. return true;
  14966. }
  14967. return false;
  14968. }
  14969. function compareDirectoryName(name, constraint) {
  14970. if ((name.typesAndValues.length === 0) || (constraint.typesAndValues.length === 0))
  14971. return true;
  14972. if (name.typesAndValues.length < constraint.typesAndValues.length)
  14973. return false;
  14974. let result = true;
  14975. let nameStart = 0;
  14976. for (let i = 0; i < constraint.typesAndValues.length; i++) {
  14977. let localResult = false;
  14978. for (let j = nameStart; j < name.typesAndValues.length; j++) {
  14979. localResult = name.typesAndValues[j].isEqual(constraint.typesAndValues[i]);
  14980. if (name.typesAndValues[j].type === constraint.typesAndValues[i].type)
  14981. result = result && localResult;
  14982. if (localResult === true) {
  14983. if ((nameStart === 0) || (nameStart === j)) {
  14984. nameStart = j + 1;
  14985. break;
  14986. }
  14987. else
  14988. return false;
  14989. }
  14990. }
  14991. if (localResult === false)
  14992. return false;
  14993. }
  14994. return (nameStart === 0) ? false : result;
  14995. }
  14996. try {
  14997. if (this.certs.length === 0)
  14998. throw new Error("Empty certificate array");
  14999. const passedWhenNotRevValues = parameters.passedWhenNotRevValues || false;
  15000. const initialPolicySet = parameters.initialPolicySet || [id_AnyPolicy];
  15001. const initialExplicitPolicy = parameters.initialExplicitPolicy || false;
  15002. const initialPolicyMappingInhibit = parameters.initialPolicyMappingInhibit || false;
  15003. const initialInhibitPolicy = parameters.initialInhibitPolicy || false;
  15004. const initialPermittedSubtreesSet = parameters.initialPermittedSubtreesSet || [];
  15005. const initialExcludedSubtreesSet = parameters.initialExcludedSubtreesSet || [];
  15006. const initialRequiredNameForms = parameters.initialRequiredNameForms || [];
  15007. let explicitPolicyIndicator = initialExplicitPolicy;
  15008. let policyMappingInhibitIndicator = initialPolicyMappingInhibit;
  15009. let inhibitAnyPolicyIndicator = initialInhibitPolicy;
  15010. const pendingConstraints = [
  15011. false,
  15012. false,
  15013. false,
  15014. ];
  15015. let explicitPolicyPending = 0;
  15016. let policyMappingInhibitPending = 0;
  15017. let inhibitAnyPolicyPending = 0;
  15018. let permittedSubtrees = initialPermittedSubtreesSet;
  15019. let excludedSubtrees = initialExcludedSubtreesSet;
  15020. const requiredNameForms = initialRequiredNameForms;
  15021. let pathDepth = 1;
  15022. this.certs = await this.sort(passedWhenNotRevValues, crypto);
  15023. const allPolicies = [];
  15024. allPolicies.push(id_AnyPolicy);
  15025. const policiesAndCerts = [];
  15026. const anyPolicyArray = new Array(this.certs.length - 1);
  15027. for (let ii = 0; ii < (this.certs.length - 1); ii++)
  15028. anyPolicyArray[ii] = true;
  15029. policiesAndCerts.push(anyPolicyArray);
  15030. const policyMappings = new Array(this.certs.length - 1);
  15031. const certPolicies = new Array(this.certs.length - 1);
  15032. let explicitPolicyStart = (explicitPolicyIndicator) ? (this.certs.length - 1) : (-1);
  15033. for (let i = (this.certs.length - 2); i >= 0; i--, pathDepth++) {
  15034. const cert = this.certs[i];
  15035. if (cert.extensions) {
  15036. for (let j = 0; j < cert.extensions.length; j++) {
  15037. const extension = cert.extensions[j];
  15038. if (extension.extnID === id_CertificatePolicies) {
  15039. certPolicies[i] = extension.parsedValue;
  15040. for (let s = 0; s < allPolicies.length; s++) {
  15041. if (allPolicies[s] === id_AnyPolicy) {
  15042. delete (policiesAndCerts[s])[i];
  15043. break;
  15044. }
  15045. }
  15046. for (let k = 0; k < extension.parsedValue.certificatePolicies.length; k++) {
  15047. let policyIndex = (-1);
  15048. const policyId = extension.parsedValue.certificatePolicies[k].policyIdentifier;
  15049. for (let s = 0; s < allPolicies.length; s++) {
  15050. if (policyId === allPolicies[s]) {
  15051. policyIndex = s;
  15052. break;
  15053. }
  15054. }
  15055. if (policyIndex === (-1)) {
  15056. allPolicies.push(policyId);
  15057. const certArray = new Array(this.certs.length - 1);
  15058. certArray[i] = true;
  15059. policiesAndCerts.push(certArray);
  15060. }
  15061. else
  15062. (policiesAndCerts[policyIndex])[i] = true;
  15063. }
  15064. }
  15065. if (extension.extnID === id_PolicyMappings) {
  15066. if (policyMappingInhibitIndicator) {
  15067. return {
  15068. result: false,
  15069. resultCode: 98,
  15070. resultMessage: "Policy mapping prohibited"
  15071. };
  15072. }
  15073. policyMappings[i] = extension.parsedValue;
  15074. }
  15075. if (extension.extnID === id_PolicyConstraints) {
  15076. if (explicitPolicyIndicator === false) {
  15077. if (extension.parsedValue.requireExplicitPolicy === 0) {
  15078. explicitPolicyIndicator = true;
  15079. explicitPolicyStart = i;
  15080. }
  15081. else {
  15082. if (pendingConstraints[0] === false) {
  15083. pendingConstraints[0] = true;
  15084. explicitPolicyPending = extension.parsedValue.requireExplicitPolicy;
  15085. }
  15086. else
  15087. explicitPolicyPending = (explicitPolicyPending > extension.parsedValue.requireExplicitPolicy) ? extension.parsedValue.requireExplicitPolicy : explicitPolicyPending;
  15088. }
  15089. if (extension.parsedValue.inhibitPolicyMapping === 0)
  15090. policyMappingInhibitIndicator = true;
  15091. else {
  15092. if (pendingConstraints[1] === false) {
  15093. pendingConstraints[1] = true;
  15094. policyMappingInhibitPending = extension.parsedValue.inhibitPolicyMapping + 1;
  15095. }
  15096. else
  15097. policyMappingInhibitPending = (policyMappingInhibitPending > (extension.parsedValue.inhibitPolicyMapping + 1)) ? (extension.parsedValue.inhibitPolicyMapping + 1) : policyMappingInhibitPending;
  15098. }
  15099. }
  15100. }
  15101. if (extension.extnID === id_InhibitAnyPolicy) {
  15102. if (inhibitAnyPolicyIndicator === false) {
  15103. if (extension.parsedValue.valueBlock.valueDec === 0)
  15104. inhibitAnyPolicyIndicator = true;
  15105. else {
  15106. if (pendingConstraints[2] === false) {
  15107. pendingConstraints[2] = true;
  15108. inhibitAnyPolicyPending = extension.parsedValue.valueBlock.valueDec;
  15109. }
  15110. else
  15111. inhibitAnyPolicyPending = (inhibitAnyPolicyPending > extension.parsedValue.valueBlock.valueDec) ? extension.parsedValue.valueBlock.valueDec : inhibitAnyPolicyPending;
  15112. }
  15113. }
  15114. }
  15115. }
  15116. if (inhibitAnyPolicyIndicator === true) {
  15117. let policyIndex = (-1);
  15118. for (let searchAnyPolicy = 0; searchAnyPolicy < allPolicies.length; searchAnyPolicy++) {
  15119. if (allPolicies[searchAnyPolicy] === id_AnyPolicy) {
  15120. policyIndex = searchAnyPolicy;
  15121. break;
  15122. }
  15123. }
  15124. if (policyIndex !== (-1))
  15125. delete (policiesAndCerts[0])[i];
  15126. }
  15127. if (explicitPolicyIndicator === false) {
  15128. if (pendingConstraints[0] === true) {
  15129. explicitPolicyPending--;
  15130. if (explicitPolicyPending === 0) {
  15131. explicitPolicyIndicator = true;
  15132. explicitPolicyStart = i;
  15133. pendingConstraints[0] = false;
  15134. }
  15135. }
  15136. }
  15137. if (policyMappingInhibitIndicator === false) {
  15138. if (pendingConstraints[1] === true) {
  15139. policyMappingInhibitPending--;
  15140. if (policyMappingInhibitPending === 0) {
  15141. policyMappingInhibitIndicator = true;
  15142. pendingConstraints[1] = false;
  15143. }
  15144. }
  15145. }
  15146. if (inhibitAnyPolicyIndicator === false) {
  15147. if (pendingConstraints[2] === true) {
  15148. inhibitAnyPolicyPending--;
  15149. if (inhibitAnyPolicyPending === 0) {
  15150. inhibitAnyPolicyIndicator = true;
  15151. pendingConstraints[2] = false;
  15152. }
  15153. }
  15154. }
  15155. }
  15156. }
  15157. for (let i = 0; i < (this.certs.length - 1); i++) {
  15158. if ((i < (this.certs.length - 2)) && (typeof policyMappings[i + 1] !== "undefined")) {
  15159. for (let k = 0; k < policyMappings[i + 1].mappings.length; k++) {
  15160. if ((policyMappings[i + 1].mappings[k].issuerDomainPolicy === id_AnyPolicy) || (policyMappings[i + 1].mappings[k].subjectDomainPolicy === id_AnyPolicy)) {
  15161. return {
  15162. result: false,
  15163. resultCode: 99,
  15164. resultMessage: "The \"anyPolicy\" should not be a part of policy mapping scheme"
  15165. };
  15166. }
  15167. let issuerDomainPolicyIndex = (-1);
  15168. let subjectDomainPolicyIndex = (-1);
  15169. for (let n = 0; n < allPolicies.length; n++) {
  15170. if (allPolicies[n] === policyMappings[i + 1].mappings[k].issuerDomainPolicy)
  15171. issuerDomainPolicyIndex = n;
  15172. if (allPolicies[n] === policyMappings[i + 1].mappings[k].subjectDomainPolicy)
  15173. subjectDomainPolicyIndex = n;
  15174. }
  15175. if (typeof (policiesAndCerts[issuerDomainPolicyIndex])[i] !== "undefined")
  15176. delete (policiesAndCerts[issuerDomainPolicyIndex])[i];
  15177. for (let j = 0; j < certPolicies[i].certificatePolicies.length; j++) {
  15178. if (policyMappings[i + 1].mappings[k].subjectDomainPolicy === certPolicies[i].certificatePolicies[j].policyIdentifier) {
  15179. if ((issuerDomainPolicyIndex !== (-1)) && (subjectDomainPolicyIndex !== (-1))) {
  15180. for (let m = 0; m <= i; m++) {
  15181. if (typeof (policiesAndCerts[subjectDomainPolicyIndex])[m] !== "undefined") {
  15182. (policiesAndCerts[issuerDomainPolicyIndex])[m] = true;
  15183. delete (policiesAndCerts[subjectDomainPolicyIndex])[m];
  15184. }
  15185. }
  15186. }
  15187. }
  15188. }
  15189. }
  15190. }
  15191. }
  15192. for (let i = 0; i < allPolicies.length; i++) {
  15193. if (allPolicies[i] === id_AnyPolicy) {
  15194. for (let j = 0; j < explicitPolicyStart; j++)
  15195. delete (policiesAndCerts[i])[j];
  15196. }
  15197. }
  15198. const authConstrPolicies = [];
  15199. for (let i = 0; i < policiesAndCerts.length; i++) {
  15200. let found = true;
  15201. for (let j = 0; j < (this.certs.length - 1); j++) {
  15202. let anyPolicyFound = false;
  15203. if ((j < explicitPolicyStart) && (allPolicies[i] === id_AnyPolicy) && (allPolicies.length > 1)) {
  15204. found = false;
  15205. break;
  15206. }
  15207. if (typeof (policiesAndCerts[i])[j] === "undefined") {
  15208. if (j >= explicitPolicyStart) {
  15209. for (let k = 0; k < allPolicies.length; k++) {
  15210. if (allPolicies[k] === id_AnyPolicy) {
  15211. if ((policiesAndCerts[k])[j] === true)
  15212. anyPolicyFound = true;
  15213. break;
  15214. }
  15215. }
  15216. }
  15217. if (!anyPolicyFound) {
  15218. found = false;
  15219. break;
  15220. }
  15221. }
  15222. }
  15223. if (found === true)
  15224. authConstrPolicies.push(allPolicies[i]);
  15225. }
  15226. let userConstrPolicies = [];
  15227. if ((initialPolicySet.length === 1) && (initialPolicySet[0] === id_AnyPolicy) && (explicitPolicyIndicator === false))
  15228. userConstrPolicies = initialPolicySet;
  15229. else {
  15230. if ((authConstrPolicies.length === 1) && (authConstrPolicies[0] === id_AnyPolicy))
  15231. userConstrPolicies = initialPolicySet;
  15232. else {
  15233. for (let i = 0; i < authConstrPolicies.length; i++) {
  15234. for (let j = 0; j < initialPolicySet.length; j++) {
  15235. if ((initialPolicySet[j] === authConstrPolicies[i]) || (initialPolicySet[j] === id_AnyPolicy)) {
  15236. userConstrPolicies.push(authConstrPolicies[i]);
  15237. break;
  15238. }
  15239. }
  15240. }
  15241. }
  15242. }
  15243. const policyResult = {
  15244. result: (userConstrPolicies.length > 0),
  15245. resultCode: 0,
  15246. resultMessage: (userConstrPolicies.length > 0) ? EMPTY_STRING : "Zero \"userConstrPolicies\" array, no intersections with \"authConstrPolicies\"",
  15247. authConstrPolicies,
  15248. userConstrPolicies,
  15249. explicitPolicyIndicator,
  15250. policyMappings,
  15251. certificatePath: this.certs
  15252. };
  15253. if (userConstrPolicies.length === 0)
  15254. return policyResult;
  15255. if (policyResult.result === false)
  15256. return policyResult;
  15257. pathDepth = 1;
  15258. for (let i = (this.certs.length - 2); i >= 0; i--, pathDepth++) {
  15259. const cert = this.certs[i];
  15260. let subjectAltNames = [];
  15261. let certPermittedSubtrees = [];
  15262. let certExcludedSubtrees = [];
  15263. if (cert.extensions) {
  15264. for (let j = 0; j < cert.extensions.length; j++) {
  15265. const extension = cert.extensions[j];
  15266. if (extension.extnID === id_NameConstraints) {
  15267. if ("permittedSubtrees" in extension.parsedValue)
  15268. certPermittedSubtrees = certPermittedSubtrees.concat(extension.parsedValue.permittedSubtrees);
  15269. if ("excludedSubtrees" in extension.parsedValue)
  15270. certExcludedSubtrees = certExcludedSubtrees.concat(extension.parsedValue.excludedSubtrees);
  15271. }
  15272. if (extension.extnID === id_SubjectAltName)
  15273. subjectAltNames = subjectAltNames.concat(extension.parsedValue.altNames);
  15274. }
  15275. }
  15276. let formFound = (requiredNameForms.length <= 0);
  15277. for (let j = 0; j < requiredNameForms.length; j++) {
  15278. switch (requiredNameForms[j].base.type) {
  15279. case 4:
  15280. {
  15281. if (requiredNameForms[j].base.value.typesAndValues.length !== cert.subject.typesAndValues.length)
  15282. continue;
  15283. formFound = true;
  15284. for (let k = 0; k < cert.subject.typesAndValues.length; k++) {
  15285. if (cert.subject.typesAndValues[k].type !== requiredNameForms[j].base.value.typesAndValues[k].type) {
  15286. formFound = false;
  15287. break;
  15288. }
  15289. }
  15290. if (formFound === true)
  15291. break;
  15292. }
  15293. break;
  15294. default:
  15295. }
  15296. }
  15297. if (formFound === false) {
  15298. policyResult.result = false;
  15299. policyResult.resultCode = 21;
  15300. policyResult.resultMessage = "No necessary name form found";
  15301. throw policyResult;
  15302. }
  15303. const constrGroups = [
  15304. [],
  15305. [],
  15306. [],
  15307. [],
  15308. [],
  15309. ];
  15310. for (let j = 0; j < permittedSubtrees.length; j++) {
  15311. switch (permittedSubtrees[j].base.type) {
  15312. case 1:
  15313. constrGroups[0].push(permittedSubtrees[j]);
  15314. break;
  15315. case 2:
  15316. constrGroups[1].push(permittedSubtrees[j]);
  15317. break;
  15318. case 4:
  15319. constrGroups[2].push(permittedSubtrees[j]);
  15320. break;
  15321. case 6:
  15322. constrGroups[3].push(permittedSubtrees[j]);
  15323. break;
  15324. case 7:
  15325. constrGroups[4].push(permittedSubtrees[j]);
  15326. break;
  15327. default:
  15328. }
  15329. }
  15330. for (let p = 0; p < 5; p++) {
  15331. let groupPermitted = false;
  15332. let valueExists = false;
  15333. const group = constrGroups[p];
  15334. for (let j = 0; j < group.length; j++) {
  15335. switch (p) {
  15336. case 0:
  15337. if (subjectAltNames.length > 0) {
  15338. for (let k = 0; k < subjectAltNames.length; k++) {
  15339. if (subjectAltNames[k].type === 1) {
  15340. valueExists = true;
  15341. groupPermitted = groupPermitted || compareRFC822Name(subjectAltNames[k].value, group[j].base.value);
  15342. }
  15343. }
  15344. }
  15345. else {
  15346. for (let k = 0; k < cert.subject.typesAndValues.length; k++) {
  15347. if ((cert.subject.typesAndValues[k].type === "1.2.840.113549.1.9.1") ||
  15348. (cert.subject.typesAndValues[k].type === "0.9.2342.19200300.100.1.3")) {
  15349. valueExists = true;
  15350. groupPermitted = groupPermitted || compareRFC822Name(cert.subject.typesAndValues[k].value.valueBlock.value, group[j].base.value);
  15351. }
  15352. }
  15353. }
  15354. break;
  15355. case 1:
  15356. if (subjectAltNames.length > 0) {
  15357. for (let k = 0; k < subjectAltNames.length; k++) {
  15358. if (subjectAltNames[k].type === 2) {
  15359. valueExists = true;
  15360. groupPermitted = groupPermitted || compareDNSName(subjectAltNames[k].value, group[j].base.value);
  15361. }
  15362. }
  15363. }
  15364. break;
  15365. case 2:
  15366. valueExists = true;
  15367. groupPermitted = compareDirectoryName(cert.subject, group[j].base.value);
  15368. break;
  15369. case 3:
  15370. if (subjectAltNames.length > 0) {
  15371. for (let k = 0; k < subjectAltNames.length; k++) {
  15372. if (subjectAltNames[k].type === 6) {
  15373. valueExists = true;
  15374. groupPermitted = groupPermitted || compareUniformResourceIdentifier(subjectAltNames[k].value, group[j].base.value);
  15375. }
  15376. }
  15377. }
  15378. break;
  15379. case 4:
  15380. if (subjectAltNames.length > 0) {
  15381. for (let k = 0; k < subjectAltNames.length; k++) {
  15382. if (subjectAltNames[k].type === 7) {
  15383. valueExists = true;
  15384. groupPermitted = groupPermitted || compareIPAddress(subjectAltNames[k].value, group[j].base.value);
  15385. }
  15386. }
  15387. }
  15388. break;
  15389. default:
  15390. }
  15391. if (groupPermitted)
  15392. break;
  15393. }
  15394. if ((groupPermitted === false) && (group.length > 0) && valueExists) {
  15395. policyResult.result = false;
  15396. policyResult.resultCode = 41;
  15397. policyResult.resultMessage = "Failed to meet \"permitted sub-trees\" name constraint";
  15398. throw policyResult;
  15399. }
  15400. }
  15401. let excluded = false;
  15402. for (let j = 0; j < excludedSubtrees.length; j++) {
  15403. switch (excludedSubtrees[j].base.type) {
  15404. case 1:
  15405. if (subjectAltNames.length >= 0) {
  15406. for (let k = 0; k < subjectAltNames.length; k++) {
  15407. if (subjectAltNames[k].type === 1)
  15408. excluded = excluded || compareRFC822Name(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15409. }
  15410. }
  15411. else {
  15412. for (let k = 0; k < cert.subject.typesAndValues.length; k++) {
  15413. if ((cert.subject.typesAndValues[k].type === "1.2.840.113549.1.9.1") ||
  15414. (cert.subject.typesAndValues[k].type === "0.9.2342.19200300.100.1.3"))
  15415. excluded = excluded || compareRFC822Name(cert.subject.typesAndValues[k].value.valueBlock.value, excludedSubtrees[j].base.value);
  15416. }
  15417. }
  15418. break;
  15419. case 2:
  15420. if (subjectAltNames.length > 0) {
  15421. for (let k = 0; k < subjectAltNames.length; k++) {
  15422. if (subjectAltNames[k].type === 2)
  15423. excluded = excluded || compareDNSName(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15424. }
  15425. }
  15426. break;
  15427. case 4:
  15428. excluded = excluded || compareDirectoryName(cert.subject, excludedSubtrees[j].base.value);
  15429. break;
  15430. case 6:
  15431. if (subjectAltNames.length > 0) {
  15432. for (let k = 0; k < subjectAltNames.length; k++) {
  15433. if (subjectAltNames[k].type === 6)
  15434. excluded = excluded || compareUniformResourceIdentifier(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15435. }
  15436. }
  15437. break;
  15438. case 7:
  15439. if (subjectAltNames.length > 0) {
  15440. for (let k = 0; k < subjectAltNames.length; k++) {
  15441. if (subjectAltNames[k].type === 7)
  15442. excluded = excluded || compareIPAddress(subjectAltNames[k].value, excludedSubtrees[j].base.value);
  15443. }
  15444. }
  15445. break;
  15446. default:
  15447. }
  15448. if (excluded)
  15449. break;
  15450. }
  15451. if (excluded === true) {
  15452. policyResult.result = false;
  15453. policyResult.resultCode = 42;
  15454. policyResult.resultMessage = "Failed to meet \"excluded sub-trees\" name constraint";
  15455. throw policyResult;
  15456. }
  15457. permittedSubtrees = permittedSubtrees.concat(certPermittedSubtrees);
  15458. excludedSubtrees = excludedSubtrees.concat(certExcludedSubtrees);
  15459. }
  15460. return policyResult;
  15461. }
  15462. catch (error) {
  15463. if (error instanceof Error) {
  15464. if (error instanceof ChainValidationError) {
  15465. return {
  15466. result: false,
  15467. resultCode: error.code,
  15468. resultMessage: error.message,
  15469. error: error,
  15470. };
  15471. }
  15472. return {
  15473. result: false,
  15474. resultCode: ChainValidationCode.unknown,
  15475. resultMessage: error.message,
  15476. error: error,
  15477. };
  15478. }
  15479. if (error && typeof error === "object" && "resultMessage" in error) {
  15480. return error;
  15481. }
  15482. return {
  15483. result: false,
  15484. resultCode: -1,
  15485. resultMessage: `${error}`,
  15486. };
  15487. }
  15488. }
  15489. }
  15490. const TBS_RESPONSE_DATA = "tbsResponseData";
  15491. const SIGNATURE_ALGORITHM$3 = "signatureAlgorithm";
  15492. const SIGNATURE$2 = "signature";
  15493. const CERTS$1 = "certs";
  15494. const BASIC_OCSP_RESPONSE = "BasicOCSPResponse";
  15495. const BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA = `${BASIC_OCSP_RESPONSE}.${TBS_RESPONSE_DATA}`;
  15496. const BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM = `${BASIC_OCSP_RESPONSE}.${SIGNATURE_ALGORITHM$3}`;
  15497. const BASIC_OCSP_RESPONSE_SIGNATURE = `${BASIC_OCSP_RESPONSE}.${SIGNATURE$2}`;
  15498. const BASIC_OCSP_RESPONSE_CERTS = `${BASIC_OCSP_RESPONSE}.${CERTS$1}`;
  15499. const CLEAR_PROPS$g = [
  15500. BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA,
  15501. BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM,
  15502. BASIC_OCSP_RESPONSE_SIGNATURE,
  15503. BASIC_OCSP_RESPONSE_CERTS
  15504. ];
  15505. class BasicOCSPResponse extends PkiObject {
  15506. constructor(parameters = {}) {
  15507. super();
  15508. this.tbsResponseData = pvutils.getParametersValue(parameters, TBS_RESPONSE_DATA, BasicOCSPResponse.defaultValues(TBS_RESPONSE_DATA));
  15509. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$3, BasicOCSPResponse.defaultValues(SIGNATURE_ALGORITHM$3));
  15510. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$2, BasicOCSPResponse.defaultValues(SIGNATURE$2));
  15511. if (CERTS$1 in parameters) {
  15512. this.certs = pvutils.getParametersValue(parameters, CERTS$1, BasicOCSPResponse.defaultValues(CERTS$1));
  15513. }
  15514. if (parameters.schema) {
  15515. this.fromSchema(parameters.schema);
  15516. }
  15517. }
  15518. static defaultValues(memberName) {
  15519. switch (memberName) {
  15520. case TBS_RESPONSE_DATA:
  15521. return new ResponseData();
  15522. case SIGNATURE_ALGORITHM$3:
  15523. return new AlgorithmIdentifier();
  15524. case SIGNATURE$2:
  15525. return new asn1js.BitString();
  15526. case CERTS$1:
  15527. return [];
  15528. default:
  15529. return super.defaultValues(memberName);
  15530. }
  15531. }
  15532. static compareWithDefault(memberName, memberValue) {
  15533. switch (memberName) {
  15534. case "type":
  15535. {
  15536. let comparisonResult = ((ResponseData.compareWithDefault("tbs", memberValue.tbs)) &&
  15537. (ResponseData.compareWithDefault("responderID", memberValue.responderID)) &&
  15538. (ResponseData.compareWithDefault("producedAt", memberValue.producedAt)) &&
  15539. (ResponseData.compareWithDefault("responses", memberValue.responses)));
  15540. if ("responseExtensions" in memberValue)
  15541. comparisonResult = comparisonResult && (ResponseData.compareWithDefault("responseExtensions", memberValue.responseExtensions));
  15542. return comparisonResult;
  15543. }
  15544. case SIGNATURE_ALGORITHM$3:
  15545. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  15546. case SIGNATURE$2:
  15547. return (memberValue.isEqual(BasicOCSPResponse.defaultValues(memberName)));
  15548. case CERTS$1:
  15549. return (memberValue.length === 0);
  15550. default:
  15551. return super.defaultValues(memberName);
  15552. }
  15553. }
  15554. static schema(parameters = {}) {
  15555. const names = pvutils.getParametersValue(parameters, "names", {});
  15556. return (new asn1js.Sequence({
  15557. name: (names.blockName || BASIC_OCSP_RESPONSE),
  15558. value: [
  15559. ResponseData.schema(names.tbsResponseData || {
  15560. names: {
  15561. blockName: BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA
  15562. }
  15563. }),
  15564. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  15565. names: {
  15566. blockName: BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM
  15567. }
  15568. }),
  15569. new asn1js.BitString({ name: (names.signature || BASIC_OCSP_RESPONSE_SIGNATURE) }),
  15570. new asn1js.Constructed({
  15571. optional: true,
  15572. idBlock: {
  15573. tagClass: 3,
  15574. tagNumber: 0
  15575. },
  15576. value: [
  15577. new asn1js.Sequence({
  15578. value: [new asn1js.Repeated({
  15579. name: BASIC_OCSP_RESPONSE_CERTS,
  15580. value: Certificate.schema(names.certs || {})
  15581. })]
  15582. })
  15583. ]
  15584. })
  15585. ]
  15586. }));
  15587. }
  15588. fromSchema(schema) {
  15589. pvutils.clearProps(schema, CLEAR_PROPS$g);
  15590. const asn1 = asn1js.compareSchema(schema, schema, BasicOCSPResponse.schema());
  15591. AsnError.assertSchema(asn1, this.className);
  15592. this.tbsResponseData = new ResponseData({ schema: asn1.result[BASIC_OCSP_RESPONSE_TBS_RESPONSE_DATA] });
  15593. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result[BASIC_OCSP_RESPONSE_SIGNATURE_ALGORITHM] });
  15594. this.signature = asn1.result[BASIC_OCSP_RESPONSE_SIGNATURE];
  15595. if (BASIC_OCSP_RESPONSE_CERTS in asn1.result) {
  15596. this.certs = Array.from(asn1.result[BASIC_OCSP_RESPONSE_CERTS], element => new Certificate({ schema: element }));
  15597. }
  15598. }
  15599. toSchema() {
  15600. const outputArray = [];
  15601. outputArray.push(this.tbsResponseData.toSchema());
  15602. outputArray.push(this.signatureAlgorithm.toSchema());
  15603. outputArray.push(this.signature);
  15604. if (this.certs) {
  15605. outputArray.push(new asn1js.Constructed({
  15606. idBlock: {
  15607. tagClass: 3,
  15608. tagNumber: 0
  15609. },
  15610. value: [
  15611. new asn1js.Sequence({
  15612. value: Array.from(this.certs, o => o.toSchema())
  15613. })
  15614. ]
  15615. }));
  15616. }
  15617. return (new asn1js.Sequence({
  15618. value: outputArray
  15619. }));
  15620. }
  15621. toJSON() {
  15622. const res = {
  15623. tbsResponseData: this.tbsResponseData.toJSON(),
  15624. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  15625. signature: this.signature.toJSON(),
  15626. };
  15627. if (this.certs) {
  15628. res.certs = Array.from(this.certs, o => o.toJSON());
  15629. }
  15630. return res;
  15631. }
  15632. async getCertificateStatus(certificate, issuerCertificate, crypto = getCrypto(true)) {
  15633. const result = {
  15634. isForCertificate: false,
  15635. status: 2
  15636. };
  15637. const hashesObject = {};
  15638. const certIDs = [];
  15639. for (const response of this.tbsResponseData.responses) {
  15640. const hashAlgorithm = crypto.getAlgorithmByOID(response.certID.hashAlgorithm.algorithmId, true, "CertID.hashAlgorithm");
  15641. if (!hashesObject[hashAlgorithm.name]) {
  15642. hashesObject[hashAlgorithm.name] = 1;
  15643. const certID = new CertID();
  15644. certIDs.push(certID);
  15645. await certID.createForCertificate(certificate, {
  15646. hashAlgorithm: hashAlgorithm.name,
  15647. issuerCertificate
  15648. }, crypto);
  15649. }
  15650. }
  15651. for (const response of this.tbsResponseData.responses) {
  15652. for (const id of certIDs) {
  15653. if (response.certID.isEqual(id)) {
  15654. result.isForCertificate = true;
  15655. try {
  15656. switch (response.certStatus.idBlock.isConstructed) {
  15657. case true:
  15658. if (response.certStatus.idBlock.tagNumber === 1)
  15659. result.status = 1;
  15660. break;
  15661. case false:
  15662. switch (response.certStatus.idBlock.tagNumber) {
  15663. case 0:
  15664. result.status = 0;
  15665. break;
  15666. case 2:
  15667. result.status = 2;
  15668. break;
  15669. default:
  15670. }
  15671. break;
  15672. default:
  15673. }
  15674. }
  15675. catch {
  15676. }
  15677. return result;
  15678. }
  15679. }
  15680. }
  15681. return result;
  15682. }
  15683. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  15684. if (!privateKey) {
  15685. throw new Error("Need to provide a private key for signing");
  15686. }
  15687. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  15688. const algorithm = signatureParams.parameters.algorithm;
  15689. if (!("name" in algorithm)) {
  15690. throw new Error("Empty algorithm");
  15691. }
  15692. this.signatureAlgorithm = signatureParams.signatureAlgorithm;
  15693. this.tbsResponseData.tbsView = new Uint8Array(this.tbsResponseData.toSchema(true).toBER());
  15694. const signature = await crypto.signWithPrivateKey(this.tbsResponseData.tbsView, privateKey, { algorithm });
  15695. this.signature = new asn1js.BitString({ valueHex: signature });
  15696. }
  15697. async verify(params = {}, crypto = getCrypto(true)) {
  15698. let signerCert = null;
  15699. let certIndex = -1;
  15700. const trustedCerts = params.trustedCerts || [];
  15701. if (!this.certs) {
  15702. throw new Error("No certificates attached to the BasicOCSPResponse");
  15703. }
  15704. switch (true) {
  15705. case (this.tbsResponseData.responderID instanceof RelativeDistinguishedNames):
  15706. for (const [index, certificate] of this.certs.entries()) {
  15707. if (certificate.subject.isEqual(this.tbsResponseData.responderID)) {
  15708. certIndex = index;
  15709. break;
  15710. }
  15711. }
  15712. break;
  15713. case (this.tbsResponseData.responderID instanceof asn1js.OctetString):
  15714. for (const [index, cert] of this.certs.entries()) {
  15715. const hash = await crypto.digest({ name: "sha-1" }, cert.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView);
  15716. if (pvutils.isEqualBuffer(hash, this.tbsResponseData.responderID.valueBlock.valueHex)) {
  15717. certIndex = index;
  15718. break;
  15719. }
  15720. }
  15721. break;
  15722. default:
  15723. throw new Error("Wrong value for responderID");
  15724. }
  15725. if (certIndex === (-1))
  15726. throw new Error("Correct certificate was not found in OCSP response");
  15727. signerCert = this.certs[certIndex];
  15728. const additionalCerts = [signerCert];
  15729. for (const cert of this.certs) {
  15730. const caCert = await checkCA(cert, signerCert);
  15731. if (caCert) {
  15732. additionalCerts.push(caCert);
  15733. }
  15734. }
  15735. const certChain = new CertificateChainValidationEngine({
  15736. certs: additionalCerts,
  15737. trustedCerts,
  15738. });
  15739. const verificationResult = await certChain.verify({}, crypto);
  15740. if (!verificationResult.result) {
  15741. throw new Error("Validation of signer's certificate failed");
  15742. }
  15743. return crypto.verifyWithPublicKey(this.tbsResponseData.tbsView, this.signature, this.certs[certIndex].subjectPublicKeyInfo, this.signatureAlgorithm);
  15744. }
  15745. }
  15746. BasicOCSPResponse.CLASS_NAME = "BasicOCSPResponse";
  15747. const TBS$1 = "tbs";
  15748. const VERSION$6 = "version";
  15749. const SUBJECT = "subject";
  15750. const SPKI = "subjectPublicKeyInfo";
  15751. const ATTRIBUTES$1 = "attributes";
  15752. const SIGNATURE_ALGORITHM$2 = "signatureAlgorithm";
  15753. const SIGNATURE_VALUE = "signatureValue";
  15754. const CSR_INFO = "CertificationRequestInfo";
  15755. const CSR_INFO_VERSION = `${CSR_INFO}.version`;
  15756. const CSR_INFO_SUBJECT = `${CSR_INFO}.subject`;
  15757. const CSR_INFO_SPKI = `${CSR_INFO}.subjectPublicKeyInfo`;
  15758. const CSR_INFO_ATTRS = `${CSR_INFO}.attributes`;
  15759. const CLEAR_PROPS$f = [
  15760. CSR_INFO,
  15761. CSR_INFO_VERSION,
  15762. CSR_INFO_SUBJECT,
  15763. CSR_INFO_SPKI,
  15764. CSR_INFO_ATTRS,
  15765. SIGNATURE_ALGORITHM$2,
  15766. SIGNATURE_VALUE
  15767. ];
  15768. function CertificationRequestInfo(parameters = {}) {
  15769. const names = pvutils.getParametersValue(parameters, "names", {});
  15770. return (new asn1js.Sequence({
  15771. name: (names.CertificationRequestInfo || CSR_INFO),
  15772. value: [
  15773. new asn1js.Integer({ name: (names.CertificationRequestInfoVersion || CSR_INFO_VERSION) }),
  15774. RelativeDistinguishedNames.schema(names.subject || {
  15775. names: {
  15776. blockName: CSR_INFO_SUBJECT
  15777. }
  15778. }),
  15779. PublicKeyInfo.schema({
  15780. names: {
  15781. blockName: CSR_INFO_SPKI
  15782. }
  15783. }),
  15784. new asn1js.Constructed({
  15785. optional: true,
  15786. idBlock: {
  15787. tagClass: 3,
  15788. tagNumber: 0
  15789. },
  15790. value: [
  15791. new asn1js.Repeated({
  15792. optional: true,
  15793. name: (names.CertificationRequestInfoAttributes || CSR_INFO_ATTRS),
  15794. value: Attribute.schema(names.attributes || {})
  15795. })
  15796. ]
  15797. })
  15798. ]
  15799. }));
  15800. }
  15801. class CertificationRequest extends PkiObject {
  15802. get tbs() {
  15803. return pvtsutils.BufferSourceConverter.toArrayBuffer(this.tbsView);
  15804. }
  15805. set tbs(value) {
  15806. this.tbsView = new Uint8Array(value);
  15807. }
  15808. constructor(parameters = {}) {
  15809. super();
  15810. this.tbsView = new Uint8Array(pvutils.getParametersValue(parameters, TBS$1, CertificationRequest.defaultValues(TBS$1)));
  15811. this.version = pvutils.getParametersValue(parameters, VERSION$6, CertificationRequest.defaultValues(VERSION$6));
  15812. this.subject = pvutils.getParametersValue(parameters, SUBJECT, CertificationRequest.defaultValues(SUBJECT));
  15813. this.subjectPublicKeyInfo = pvutils.getParametersValue(parameters, SPKI, CertificationRequest.defaultValues(SPKI));
  15814. if (ATTRIBUTES$1 in parameters) {
  15815. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES$1, CertificationRequest.defaultValues(ATTRIBUTES$1));
  15816. }
  15817. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$2, CertificationRequest.defaultValues(SIGNATURE_ALGORITHM$2));
  15818. this.signatureValue = pvutils.getParametersValue(parameters, SIGNATURE_VALUE, CertificationRequest.defaultValues(SIGNATURE_VALUE));
  15819. if (parameters.schema) {
  15820. this.fromSchema(parameters.schema);
  15821. }
  15822. }
  15823. static defaultValues(memberName) {
  15824. switch (memberName) {
  15825. case TBS$1:
  15826. return EMPTY_BUFFER;
  15827. case VERSION$6:
  15828. return 0;
  15829. case SUBJECT:
  15830. return new RelativeDistinguishedNames();
  15831. case SPKI:
  15832. return new PublicKeyInfo();
  15833. case ATTRIBUTES$1:
  15834. return [];
  15835. case SIGNATURE_ALGORITHM$2:
  15836. return new AlgorithmIdentifier();
  15837. case SIGNATURE_VALUE:
  15838. return new asn1js.BitString();
  15839. default:
  15840. return super.defaultValues(memberName);
  15841. }
  15842. }
  15843. static schema(parameters = {}) {
  15844. const names = pvutils.getParametersValue(parameters, "names", {});
  15845. return (new asn1js.Sequence({
  15846. value: [
  15847. CertificationRequestInfo(names.certificationRequestInfo || {}),
  15848. new asn1js.Sequence({
  15849. name: (names.signatureAlgorithm || SIGNATURE_ALGORITHM$2),
  15850. value: [
  15851. new asn1js.ObjectIdentifier(),
  15852. new asn1js.Any({ optional: true })
  15853. ]
  15854. }),
  15855. new asn1js.BitString({ name: (names.signatureValue || SIGNATURE_VALUE) })
  15856. ]
  15857. }));
  15858. }
  15859. fromSchema(schema) {
  15860. pvutils.clearProps(schema, CLEAR_PROPS$f);
  15861. const asn1 = asn1js.compareSchema(schema, schema, CertificationRequest.schema());
  15862. AsnError.assertSchema(asn1, this.className);
  15863. this.tbsView = asn1.result.CertificationRequestInfo.valueBeforeDecodeView;
  15864. this.version = asn1.result[CSR_INFO_VERSION].valueBlock.valueDec;
  15865. this.subject = new RelativeDistinguishedNames({ schema: asn1.result[CSR_INFO_SUBJECT] });
  15866. this.subjectPublicKeyInfo = new PublicKeyInfo({ schema: asn1.result[CSR_INFO_SPKI] });
  15867. if (CSR_INFO_ATTRS in asn1.result) {
  15868. this.attributes = Array.from(asn1.result[CSR_INFO_ATTRS], element => new Attribute({ schema: element }));
  15869. }
  15870. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  15871. this.signatureValue = asn1.result.signatureValue;
  15872. }
  15873. encodeTBS() {
  15874. const outputArray = [
  15875. new asn1js.Integer({ value: this.version }),
  15876. this.subject.toSchema(),
  15877. this.subjectPublicKeyInfo.toSchema()
  15878. ];
  15879. if (ATTRIBUTES$1 in this) {
  15880. outputArray.push(new asn1js.Constructed({
  15881. idBlock: {
  15882. tagClass: 3,
  15883. tagNumber: 0
  15884. },
  15885. value: Array.from(this.attributes || [], o => o.toSchema())
  15886. }));
  15887. }
  15888. return (new asn1js.Sequence({
  15889. value: outputArray
  15890. }));
  15891. }
  15892. toSchema(encodeFlag = false) {
  15893. let tbsSchema;
  15894. if (encodeFlag === false) {
  15895. if (this.tbsView.byteLength === 0) {
  15896. return CertificationRequest.schema();
  15897. }
  15898. const asn1 = asn1js.fromBER(this.tbsView);
  15899. AsnError.assert(asn1, "PKCS#10 Certificate Request");
  15900. tbsSchema = asn1.result;
  15901. }
  15902. else {
  15903. tbsSchema = this.encodeTBS();
  15904. }
  15905. return (new asn1js.Sequence({
  15906. value: [
  15907. tbsSchema,
  15908. this.signatureAlgorithm.toSchema(),
  15909. this.signatureValue
  15910. ]
  15911. }));
  15912. }
  15913. toJSON() {
  15914. const object = {
  15915. tbs: pvtsutils.Convert.ToHex(this.tbsView),
  15916. version: this.version,
  15917. subject: this.subject.toJSON(),
  15918. subjectPublicKeyInfo: this.subjectPublicKeyInfo.toJSON(),
  15919. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  15920. signatureValue: this.signatureValue.toJSON(),
  15921. };
  15922. if (ATTRIBUTES$1 in this) {
  15923. object.attributes = Array.from(this.attributes || [], o => o.toJSON());
  15924. }
  15925. return object;
  15926. }
  15927. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  15928. if (!privateKey) {
  15929. throw new Error("Need to provide a private key for signing");
  15930. }
  15931. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  15932. const parameters = signatureParams.parameters;
  15933. this.signatureAlgorithm = signatureParams.signatureAlgorithm;
  15934. this.tbsView = new Uint8Array(this.encodeTBS().toBER());
  15935. const signature = await crypto.signWithPrivateKey(this.tbsView, privateKey, parameters);
  15936. this.signatureValue = new asn1js.BitString({ valueHex: signature });
  15937. }
  15938. async verify(crypto = getCrypto(true)) {
  15939. return crypto.verifyWithPublicKey(this.tbsView, this.signatureValue, this.subjectPublicKeyInfo, this.signatureAlgorithm);
  15940. }
  15941. async getPublicKey(parameters, crypto = getCrypto(true)) {
  15942. return crypto.getPublicKey(this.subjectPublicKeyInfo, this.signatureAlgorithm, parameters);
  15943. }
  15944. }
  15945. CertificationRequest.CLASS_NAME = "CertificationRequest";
  15946. const DIGEST_ALGORITHM$1 = "digestAlgorithm";
  15947. const DIGEST = "digest";
  15948. const CLEAR_PROPS$e = [
  15949. DIGEST_ALGORITHM$1,
  15950. DIGEST
  15951. ];
  15952. class DigestInfo extends PkiObject {
  15953. constructor(parameters = {}) {
  15954. super();
  15955. this.digestAlgorithm = pvutils.getParametersValue(parameters, DIGEST_ALGORITHM$1, DigestInfo.defaultValues(DIGEST_ALGORITHM$1));
  15956. this.digest = pvutils.getParametersValue(parameters, DIGEST, DigestInfo.defaultValues(DIGEST));
  15957. if (parameters.schema) {
  15958. this.fromSchema(parameters.schema);
  15959. }
  15960. }
  15961. static defaultValues(memberName) {
  15962. switch (memberName) {
  15963. case DIGEST_ALGORITHM$1:
  15964. return new AlgorithmIdentifier();
  15965. case DIGEST:
  15966. return new asn1js.OctetString();
  15967. default:
  15968. return super.defaultValues(memberName);
  15969. }
  15970. }
  15971. static compareWithDefault(memberName, memberValue) {
  15972. switch (memberName) {
  15973. case DIGEST_ALGORITHM$1:
  15974. return ((AlgorithmIdentifier.compareWithDefault("algorithmId", memberValue.algorithmId)) &&
  15975. (("algorithmParams" in memberValue) === false));
  15976. case DIGEST:
  15977. return (memberValue.isEqual(DigestInfo.defaultValues(memberName)));
  15978. default:
  15979. return super.defaultValues(memberName);
  15980. }
  15981. }
  15982. static schema(parameters = {}) {
  15983. const names = pvutils.getParametersValue(parameters, "names", {});
  15984. return (new asn1js.Sequence({
  15985. name: (names.blockName || EMPTY_STRING),
  15986. value: [
  15987. AlgorithmIdentifier.schema(names.digestAlgorithm || {
  15988. names: {
  15989. blockName: DIGEST_ALGORITHM$1
  15990. }
  15991. }),
  15992. new asn1js.OctetString({ name: (names.digest || DIGEST) })
  15993. ]
  15994. }));
  15995. }
  15996. fromSchema(schema) {
  15997. pvutils.clearProps(schema, CLEAR_PROPS$e);
  15998. const asn1 = asn1js.compareSchema(schema, schema, DigestInfo.schema({
  15999. names: {
  16000. digestAlgorithm: {
  16001. names: {
  16002. blockName: DIGEST_ALGORITHM$1
  16003. }
  16004. },
  16005. digest: DIGEST
  16006. }
  16007. }));
  16008. AsnError.assertSchema(asn1, this.className);
  16009. this.digestAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.digestAlgorithm });
  16010. this.digest = asn1.result.digest;
  16011. }
  16012. toSchema() {
  16013. return (new asn1js.Sequence({
  16014. value: [
  16015. this.digestAlgorithm.toSchema(),
  16016. this.digest
  16017. ]
  16018. }));
  16019. }
  16020. toJSON() {
  16021. return {
  16022. digestAlgorithm: this.digestAlgorithm.toJSON(),
  16023. digest: this.digest.toJSON(),
  16024. };
  16025. }
  16026. }
  16027. DigestInfo.CLASS_NAME = "DigestInfo";
  16028. const E_CONTENT_TYPE = "eContentType";
  16029. const E_CONTENT = "eContent";
  16030. const CLEAR_PROPS$d = [
  16031. E_CONTENT_TYPE,
  16032. E_CONTENT,
  16033. ];
  16034. class EncapsulatedContentInfo extends PkiObject {
  16035. constructor(parameters = {}) {
  16036. super();
  16037. this.eContentType = pvutils.getParametersValue(parameters, E_CONTENT_TYPE, EncapsulatedContentInfo.defaultValues(E_CONTENT_TYPE));
  16038. if (E_CONTENT in parameters) {
  16039. this.eContent = pvutils.getParametersValue(parameters, E_CONTENT, EncapsulatedContentInfo.defaultValues(E_CONTENT));
  16040. if ((this.eContent.idBlock.tagClass === 1) &&
  16041. (this.eContent.idBlock.tagNumber === 4)) {
  16042. if (this.eContent.idBlock.isConstructed === false) {
  16043. const constrString = new asn1js.OctetString({
  16044. idBlock: { isConstructed: true },
  16045. isConstructed: true
  16046. });
  16047. let offset = 0;
  16048. const viewHex = this.eContent.valueBlock.valueHexView.slice().buffer;
  16049. let length = viewHex.byteLength;
  16050. while (length > 0) {
  16051. const pieceView = new Uint8Array(viewHex, offset, ((offset + 65536) > viewHex.byteLength) ? (viewHex.byteLength - offset) : 65536);
  16052. const _array = new ArrayBuffer(pieceView.length);
  16053. const _view = new Uint8Array(_array);
  16054. for (let i = 0; i < _view.length; i++) {
  16055. _view[i] = pieceView[i];
  16056. }
  16057. constrString.valueBlock.value.push(new asn1js.OctetString({ valueHex: _array }));
  16058. length -= pieceView.length;
  16059. offset += pieceView.length;
  16060. }
  16061. this.eContent = constrString;
  16062. }
  16063. }
  16064. }
  16065. if (parameters.schema) {
  16066. this.fromSchema(parameters.schema);
  16067. }
  16068. }
  16069. static defaultValues(memberName) {
  16070. switch (memberName) {
  16071. case E_CONTENT_TYPE:
  16072. return EMPTY_STRING;
  16073. case E_CONTENT:
  16074. return new asn1js.OctetString();
  16075. default:
  16076. return super.defaultValues(memberName);
  16077. }
  16078. }
  16079. static compareWithDefault(memberName, memberValue) {
  16080. switch (memberName) {
  16081. case E_CONTENT_TYPE:
  16082. return (memberValue === EMPTY_STRING);
  16083. case E_CONTENT:
  16084. {
  16085. if ((memberValue.idBlock.tagClass === 1) && (memberValue.idBlock.tagNumber === 4))
  16086. return (memberValue.isEqual(EncapsulatedContentInfo.defaultValues(E_CONTENT)));
  16087. return false;
  16088. }
  16089. default:
  16090. return super.defaultValues(memberName);
  16091. }
  16092. }
  16093. static schema(parameters = {}) {
  16094. const names = pvutils.getParametersValue(parameters, "names", {});
  16095. return (new asn1js.Sequence({
  16096. name: (names.blockName || EMPTY_STRING),
  16097. value: [
  16098. new asn1js.ObjectIdentifier({ name: (names.eContentType || EMPTY_STRING) }),
  16099. new asn1js.Constructed({
  16100. optional: true,
  16101. idBlock: {
  16102. tagClass: 3,
  16103. tagNumber: 0
  16104. },
  16105. value: [
  16106. new asn1js.Any({ name: (names.eContent || EMPTY_STRING) })
  16107. ]
  16108. })
  16109. ]
  16110. }));
  16111. }
  16112. fromSchema(schema) {
  16113. pvutils.clearProps(schema, CLEAR_PROPS$d);
  16114. const asn1 = asn1js.compareSchema(schema, schema, EncapsulatedContentInfo.schema({
  16115. names: {
  16116. eContentType: E_CONTENT_TYPE,
  16117. eContent: E_CONTENT
  16118. }
  16119. }));
  16120. AsnError.assertSchema(asn1, this.className);
  16121. this.eContentType = asn1.result.eContentType.valueBlock.toString();
  16122. if (E_CONTENT in asn1.result)
  16123. this.eContent = asn1.result.eContent;
  16124. }
  16125. toSchema() {
  16126. const outputArray = [];
  16127. outputArray.push(new asn1js.ObjectIdentifier({ value: this.eContentType }));
  16128. if (this.eContent) {
  16129. if (EncapsulatedContentInfo.compareWithDefault(E_CONTENT, this.eContent) === false) {
  16130. outputArray.push(new asn1js.Constructed({
  16131. optional: true,
  16132. idBlock: {
  16133. tagClass: 3,
  16134. tagNumber: 0
  16135. },
  16136. value: [this.eContent]
  16137. }));
  16138. }
  16139. }
  16140. return (new asn1js.Sequence({
  16141. value: outputArray
  16142. }));
  16143. }
  16144. toJSON() {
  16145. const res = {
  16146. eContentType: this.eContentType
  16147. };
  16148. if (this.eContent && EncapsulatedContentInfo.compareWithDefault(E_CONTENT, this.eContent) === false) {
  16149. res.eContent = this.eContent.toJSON();
  16150. }
  16151. return res;
  16152. }
  16153. }
  16154. EncapsulatedContentInfo.CLASS_NAME = "EncapsulatedContentInfo";
  16155. class KeyBag extends PrivateKeyInfo {
  16156. constructor(parameters = {}) {
  16157. super(parameters);
  16158. }
  16159. }
  16160. const MAC = "mac";
  16161. const MAC_SALT = "macSalt";
  16162. const ITERATIONS = "iterations";
  16163. const CLEAR_PROPS$c = [
  16164. MAC,
  16165. MAC_SALT,
  16166. ITERATIONS
  16167. ];
  16168. class MacData extends PkiObject {
  16169. constructor(parameters = {}) {
  16170. super();
  16171. this.mac = pvutils.getParametersValue(parameters, MAC, MacData.defaultValues(MAC));
  16172. this.macSalt = pvutils.getParametersValue(parameters, MAC_SALT, MacData.defaultValues(MAC_SALT));
  16173. if (ITERATIONS in parameters) {
  16174. this.iterations = pvutils.getParametersValue(parameters, ITERATIONS, MacData.defaultValues(ITERATIONS));
  16175. }
  16176. if (parameters.schema) {
  16177. this.fromSchema(parameters.schema);
  16178. }
  16179. }
  16180. static defaultValues(memberName) {
  16181. switch (memberName) {
  16182. case MAC:
  16183. return new DigestInfo();
  16184. case MAC_SALT:
  16185. return new asn1js.OctetString();
  16186. case ITERATIONS:
  16187. return 1;
  16188. default:
  16189. return super.defaultValues(memberName);
  16190. }
  16191. }
  16192. static compareWithDefault(memberName, memberValue) {
  16193. switch (memberName) {
  16194. case MAC:
  16195. return ((DigestInfo.compareWithDefault("digestAlgorithm", memberValue.digestAlgorithm)) &&
  16196. (DigestInfo.compareWithDefault("digest", memberValue.digest)));
  16197. case MAC_SALT:
  16198. return (memberValue.isEqual(MacData.defaultValues(memberName)));
  16199. case ITERATIONS:
  16200. return (memberValue === MacData.defaultValues(memberName));
  16201. default:
  16202. return super.defaultValues(memberName);
  16203. }
  16204. }
  16205. static schema(parameters = {}) {
  16206. const names = pvutils.getParametersValue(parameters, "names", {});
  16207. return (new asn1js.Sequence({
  16208. name: (names.blockName || EMPTY_STRING),
  16209. optional: (names.optional || true),
  16210. value: [
  16211. DigestInfo.schema(names.mac || {
  16212. names: {
  16213. blockName: MAC
  16214. }
  16215. }),
  16216. new asn1js.OctetString({ name: (names.macSalt || MAC_SALT) }),
  16217. new asn1js.Integer({
  16218. optional: true,
  16219. name: (names.iterations || ITERATIONS)
  16220. })
  16221. ]
  16222. }));
  16223. }
  16224. fromSchema(schema) {
  16225. pvutils.clearProps(schema, CLEAR_PROPS$c);
  16226. const asn1 = asn1js.compareSchema(schema, schema, MacData.schema({
  16227. names: {
  16228. mac: {
  16229. names: {
  16230. blockName: MAC
  16231. }
  16232. },
  16233. macSalt: MAC_SALT,
  16234. iterations: ITERATIONS
  16235. }
  16236. }));
  16237. AsnError.assertSchema(asn1, this.className);
  16238. this.mac = new DigestInfo({ schema: asn1.result.mac });
  16239. this.macSalt = asn1.result.macSalt;
  16240. if (ITERATIONS in asn1.result)
  16241. this.iterations = asn1.result.iterations.valueBlock.valueDec;
  16242. }
  16243. toSchema() {
  16244. const outputArray = [
  16245. this.mac.toSchema(),
  16246. this.macSalt
  16247. ];
  16248. if (this.iterations !== undefined) {
  16249. outputArray.push(new asn1js.Integer({ value: this.iterations }));
  16250. }
  16251. return (new asn1js.Sequence({
  16252. value: outputArray
  16253. }));
  16254. }
  16255. toJSON() {
  16256. const res = {
  16257. mac: this.mac.toJSON(),
  16258. macSalt: this.macSalt.toJSON(),
  16259. };
  16260. if (this.iterations !== undefined) {
  16261. res.iterations = this.iterations;
  16262. }
  16263. return res;
  16264. }
  16265. }
  16266. MacData.CLASS_NAME = "MacData";
  16267. const HASH_ALGORITHM = "hashAlgorithm";
  16268. const HASHED_MESSAGE = "hashedMessage";
  16269. const CLEAR_PROPS$b = [
  16270. HASH_ALGORITHM,
  16271. HASHED_MESSAGE,
  16272. ];
  16273. class MessageImprint extends PkiObject {
  16274. static async create(hashAlgorithm, message, crypto = getCrypto(true)) {
  16275. const hashAlgorithmOID = crypto.getOIDByAlgorithm({ name: hashAlgorithm }, true, "hashAlgorithm");
  16276. const hashedMessage = await crypto.digest(hashAlgorithm, message);
  16277. const res = new MessageImprint({
  16278. hashAlgorithm: new AlgorithmIdentifier({
  16279. algorithmId: hashAlgorithmOID,
  16280. algorithmParams: new asn1js.Null(),
  16281. }),
  16282. hashedMessage: new asn1js.OctetString({ valueHex: hashedMessage })
  16283. });
  16284. return res;
  16285. }
  16286. constructor(parameters = {}) {
  16287. super();
  16288. this.hashAlgorithm = pvutils.getParametersValue(parameters, HASH_ALGORITHM, MessageImprint.defaultValues(HASH_ALGORITHM));
  16289. this.hashedMessage = pvutils.getParametersValue(parameters, HASHED_MESSAGE, MessageImprint.defaultValues(HASHED_MESSAGE));
  16290. if (parameters.schema) {
  16291. this.fromSchema(parameters.schema);
  16292. }
  16293. }
  16294. static defaultValues(memberName) {
  16295. switch (memberName) {
  16296. case HASH_ALGORITHM:
  16297. return new AlgorithmIdentifier();
  16298. case HASHED_MESSAGE:
  16299. return new asn1js.OctetString();
  16300. default:
  16301. return super.defaultValues(memberName);
  16302. }
  16303. }
  16304. static compareWithDefault(memberName, memberValue) {
  16305. switch (memberName) {
  16306. case HASH_ALGORITHM:
  16307. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  16308. case HASHED_MESSAGE:
  16309. return (memberValue.isEqual(MessageImprint.defaultValues(memberName)) === 0);
  16310. default:
  16311. return super.defaultValues(memberName);
  16312. }
  16313. }
  16314. static schema(parameters = {}) {
  16315. const names = pvutils.getParametersValue(parameters, "names", {});
  16316. return (new asn1js.Sequence({
  16317. name: (names.blockName || EMPTY_STRING),
  16318. value: [
  16319. AlgorithmIdentifier.schema(names.hashAlgorithm || {}),
  16320. new asn1js.OctetString({ name: (names.hashedMessage || EMPTY_STRING) })
  16321. ]
  16322. }));
  16323. }
  16324. fromSchema(schema) {
  16325. pvutils.clearProps(schema, CLEAR_PROPS$b);
  16326. const asn1 = asn1js.compareSchema(schema, schema, MessageImprint.schema({
  16327. names: {
  16328. hashAlgorithm: {
  16329. names: {
  16330. blockName: HASH_ALGORITHM
  16331. }
  16332. },
  16333. hashedMessage: HASHED_MESSAGE
  16334. }
  16335. }));
  16336. AsnError.assertSchema(asn1, this.className);
  16337. this.hashAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.hashAlgorithm });
  16338. this.hashedMessage = asn1.result.hashedMessage;
  16339. }
  16340. toSchema() {
  16341. return (new asn1js.Sequence({
  16342. value: [
  16343. this.hashAlgorithm.toSchema(),
  16344. this.hashedMessage
  16345. ]
  16346. }));
  16347. }
  16348. toJSON() {
  16349. return {
  16350. hashAlgorithm: this.hashAlgorithm.toJSON(),
  16351. hashedMessage: this.hashedMessage.toJSON(),
  16352. };
  16353. }
  16354. }
  16355. MessageImprint.CLASS_NAME = "MessageImprint";
  16356. const REQ_CERT = "reqCert";
  16357. const SINGLE_REQUEST_EXTENSIONS = "singleRequestExtensions";
  16358. const CLEAR_PROPS$a = [
  16359. REQ_CERT,
  16360. SINGLE_REQUEST_EXTENSIONS,
  16361. ];
  16362. class Request extends PkiObject {
  16363. constructor(parameters = {}) {
  16364. super();
  16365. this.reqCert = pvutils.getParametersValue(parameters, REQ_CERT, Request.defaultValues(REQ_CERT));
  16366. if (SINGLE_REQUEST_EXTENSIONS in parameters) {
  16367. this.singleRequestExtensions = pvutils.getParametersValue(parameters, SINGLE_REQUEST_EXTENSIONS, Request.defaultValues(SINGLE_REQUEST_EXTENSIONS));
  16368. }
  16369. if (parameters.schema) {
  16370. this.fromSchema(parameters.schema);
  16371. }
  16372. }
  16373. static defaultValues(memberName) {
  16374. switch (memberName) {
  16375. case REQ_CERT:
  16376. return new CertID();
  16377. case SINGLE_REQUEST_EXTENSIONS:
  16378. return [];
  16379. default:
  16380. return super.defaultValues(memberName);
  16381. }
  16382. }
  16383. static compareWithDefault(memberName, memberValue) {
  16384. switch (memberName) {
  16385. case REQ_CERT:
  16386. return (memberValue.isEqual(Request.defaultValues(memberName)));
  16387. case SINGLE_REQUEST_EXTENSIONS:
  16388. return (memberValue.length === 0);
  16389. default:
  16390. return super.defaultValues(memberName);
  16391. }
  16392. }
  16393. static schema(parameters = {}) {
  16394. const names = pvutils.getParametersValue(parameters, "names", {});
  16395. return (new asn1js.Sequence({
  16396. name: (names.blockName || EMPTY_STRING),
  16397. value: [
  16398. CertID.schema(names.reqCert || {}),
  16399. new asn1js.Constructed({
  16400. optional: true,
  16401. idBlock: {
  16402. tagClass: 3,
  16403. tagNumber: 0
  16404. },
  16405. value: [Extensions.schema(names.extensions || {
  16406. names: {
  16407. blockName: (names.singleRequestExtensions || EMPTY_STRING)
  16408. }
  16409. })]
  16410. })
  16411. ]
  16412. }));
  16413. }
  16414. fromSchema(schema) {
  16415. pvutils.clearProps(schema, CLEAR_PROPS$a);
  16416. const asn1 = asn1js.compareSchema(schema, schema, Request.schema({
  16417. names: {
  16418. reqCert: {
  16419. names: {
  16420. blockName: REQ_CERT
  16421. }
  16422. },
  16423. extensions: {
  16424. names: {
  16425. blockName: SINGLE_REQUEST_EXTENSIONS
  16426. }
  16427. }
  16428. }
  16429. }));
  16430. AsnError.assertSchema(asn1, this.className);
  16431. this.reqCert = new CertID({ schema: asn1.result.reqCert });
  16432. if (SINGLE_REQUEST_EXTENSIONS in asn1.result) {
  16433. this.singleRequestExtensions = Array.from(asn1.result.singleRequestExtensions.valueBlock.value, element => new Extension({ schema: element }));
  16434. }
  16435. }
  16436. toSchema() {
  16437. const outputArray = [];
  16438. outputArray.push(this.reqCert.toSchema());
  16439. if (this.singleRequestExtensions) {
  16440. outputArray.push(new asn1js.Constructed({
  16441. optional: true,
  16442. idBlock: {
  16443. tagClass: 3,
  16444. tagNumber: 0
  16445. },
  16446. value: [
  16447. new asn1js.Sequence({
  16448. value: Array.from(this.singleRequestExtensions, o => o.toSchema())
  16449. })
  16450. ]
  16451. }));
  16452. }
  16453. return (new asn1js.Sequence({
  16454. value: outputArray
  16455. }));
  16456. }
  16457. toJSON() {
  16458. const res = {
  16459. reqCert: this.reqCert.toJSON()
  16460. };
  16461. if (this.singleRequestExtensions) {
  16462. res.singleRequestExtensions = Array.from(this.singleRequestExtensions, o => o.toJSON());
  16463. }
  16464. return res;
  16465. }
  16466. }
  16467. Request.CLASS_NAME = "Request";
  16468. const TBS = "tbs";
  16469. const VERSION$5 = "version";
  16470. const REQUESTOR_NAME = "requestorName";
  16471. const REQUEST_LIST = "requestList";
  16472. const REQUEST_EXTENSIONS = "requestExtensions";
  16473. const TBS_REQUEST$1 = "TBSRequest";
  16474. const TBS_REQUEST_VERSION = `${TBS_REQUEST$1}.${VERSION$5}`;
  16475. const TBS_REQUEST_REQUESTOR_NAME = `${TBS_REQUEST$1}.${REQUESTOR_NAME}`;
  16476. const TBS_REQUEST_REQUESTS = `${TBS_REQUEST$1}.requests`;
  16477. const TBS_REQUEST_REQUEST_EXTENSIONS = `${TBS_REQUEST$1}.${REQUEST_EXTENSIONS}`;
  16478. const CLEAR_PROPS$9 = [
  16479. TBS_REQUEST$1,
  16480. TBS_REQUEST_VERSION,
  16481. TBS_REQUEST_REQUESTOR_NAME,
  16482. TBS_REQUEST_REQUESTS,
  16483. TBS_REQUEST_REQUEST_EXTENSIONS
  16484. ];
  16485. class TBSRequest extends PkiObject {
  16486. get tbs() {
  16487. return pvtsutils.BufferSourceConverter.toArrayBuffer(this.tbsView);
  16488. }
  16489. set tbs(value) {
  16490. this.tbsView = new Uint8Array(value);
  16491. }
  16492. constructor(parameters = {}) {
  16493. super();
  16494. this.tbsView = new Uint8Array(pvutils.getParametersValue(parameters, TBS, TBSRequest.defaultValues(TBS)));
  16495. if (VERSION$5 in parameters) {
  16496. this.version = pvutils.getParametersValue(parameters, VERSION$5, TBSRequest.defaultValues(VERSION$5));
  16497. }
  16498. if (REQUESTOR_NAME in parameters) {
  16499. this.requestorName = pvutils.getParametersValue(parameters, REQUESTOR_NAME, TBSRequest.defaultValues(REQUESTOR_NAME));
  16500. }
  16501. this.requestList = pvutils.getParametersValue(parameters, REQUEST_LIST, TBSRequest.defaultValues(REQUEST_LIST));
  16502. if (REQUEST_EXTENSIONS in parameters) {
  16503. this.requestExtensions = pvutils.getParametersValue(parameters, REQUEST_EXTENSIONS, TBSRequest.defaultValues(REQUEST_EXTENSIONS));
  16504. }
  16505. if (parameters.schema) {
  16506. this.fromSchema(parameters.schema);
  16507. }
  16508. }
  16509. static defaultValues(memberName) {
  16510. switch (memberName) {
  16511. case TBS:
  16512. return EMPTY_BUFFER;
  16513. case VERSION$5:
  16514. return 0;
  16515. case REQUESTOR_NAME:
  16516. return new GeneralName();
  16517. case REQUEST_LIST:
  16518. case REQUEST_EXTENSIONS:
  16519. return [];
  16520. default:
  16521. return super.defaultValues(memberName);
  16522. }
  16523. }
  16524. static compareWithDefault(memberName, memberValue) {
  16525. switch (memberName) {
  16526. case TBS:
  16527. return (memberValue.byteLength === 0);
  16528. case VERSION$5:
  16529. return (memberValue === TBSRequest.defaultValues(memberName));
  16530. case REQUESTOR_NAME:
  16531. return ((memberValue.type === GeneralName.defaultValues("type")) && (Object.keys(memberValue.value).length === 0));
  16532. case REQUEST_LIST:
  16533. case REQUEST_EXTENSIONS:
  16534. return (memberValue.length === 0);
  16535. default:
  16536. return super.defaultValues(memberName);
  16537. }
  16538. }
  16539. static schema(parameters = {}) {
  16540. const names = pvutils.getParametersValue(parameters, "names", {});
  16541. return (new asn1js.Sequence({
  16542. name: (names.blockName || TBS_REQUEST$1),
  16543. value: [
  16544. new asn1js.Constructed({
  16545. optional: true,
  16546. idBlock: {
  16547. tagClass: 3,
  16548. tagNumber: 0
  16549. },
  16550. value: [new asn1js.Integer({ name: (names.TBSRequestVersion || TBS_REQUEST_VERSION) })]
  16551. }),
  16552. new asn1js.Constructed({
  16553. optional: true,
  16554. idBlock: {
  16555. tagClass: 3,
  16556. tagNumber: 1
  16557. },
  16558. value: [GeneralName.schema(names.requestorName || {
  16559. names: {
  16560. blockName: TBS_REQUEST_REQUESTOR_NAME
  16561. }
  16562. })]
  16563. }),
  16564. new asn1js.Sequence({
  16565. name: (names.requestList || "TBSRequest.requestList"),
  16566. value: [
  16567. new asn1js.Repeated({
  16568. name: (names.requests || TBS_REQUEST_REQUESTS),
  16569. value: Request.schema(names.requestNames || {})
  16570. })
  16571. ]
  16572. }),
  16573. new asn1js.Constructed({
  16574. optional: true,
  16575. idBlock: {
  16576. tagClass: 3,
  16577. tagNumber: 2
  16578. },
  16579. value: [Extensions.schema(names.extensions || {
  16580. names: {
  16581. blockName: (names.requestExtensions || TBS_REQUEST_REQUEST_EXTENSIONS)
  16582. }
  16583. })]
  16584. })
  16585. ]
  16586. }));
  16587. }
  16588. fromSchema(schema) {
  16589. pvutils.clearProps(schema, CLEAR_PROPS$9);
  16590. const asn1 = asn1js.compareSchema(schema, schema, TBSRequest.schema());
  16591. AsnError.assertSchema(asn1, this.className);
  16592. this.tbsView = asn1.result.TBSRequest.valueBeforeDecodeView;
  16593. if (TBS_REQUEST_VERSION in asn1.result)
  16594. this.version = asn1.result[TBS_REQUEST_VERSION].valueBlock.valueDec;
  16595. if (TBS_REQUEST_REQUESTOR_NAME in asn1.result)
  16596. this.requestorName = new GeneralName({ schema: asn1.result[TBS_REQUEST_REQUESTOR_NAME] });
  16597. this.requestList = Array.from(asn1.result[TBS_REQUEST_REQUESTS], element => new Request({ schema: element }));
  16598. if (TBS_REQUEST_REQUEST_EXTENSIONS in asn1.result)
  16599. this.requestExtensions = Array.from(asn1.result[TBS_REQUEST_REQUEST_EXTENSIONS].valueBlock.value, element => new Extension({ schema: element }));
  16600. }
  16601. toSchema(encodeFlag = false) {
  16602. let tbsSchema;
  16603. if (encodeFlag === false) {
  16604. if (this.tbsView.byteLength === 0)
  16605. return TBSRequest.schema();
  16606. const asn1 = asn1js.fromBER(this.tbsView);
  16607. AsnError.assert(asn1, "TBS Request");
  16608. if (!(asn1.result instanceof asn1js.Sequence)) {
  16609. throw new Error("ASN.1 result should be SEQUENCE");
  16610. }
  16611. tbsSchema = asn1.result;
  16612. }
  16613. else {
  16614. const outputArray = [];
  16615. if (this.version !== undefined) {
  16616. outputArray.push(new asn1js.Constructed({
  16617. idBlock: {
  16618. tagClass: 3,
  16619. tagNumber: 0
  16620. },
  16621. value: [new asn1js.Integer({ value: this.version })]
  16622. }));
  16623. }
  16624. if (this.requestorName) {
  16625. outputArray.push(new asn1js.Constructed({
  16626. idBlock: {
  16627. tagClass: 3,
  16628. tagNumber: 1
  16629. },
  16630. value: [this.requestorName.toSchema()]
  16631. }));
  16632. }
  16633. outputArray.push(new asn1js.Sequence({
  16634. value: Array.from(this.requestList, o => o.toSchema())
  16635. }));
  16636. if (this.requestExtensions) {
  16637. outputArray.push(new asn1js.Constructed({
  16638. idBlock: {
  16639. tagClass: 3,
  16640. tagNumber: 2
  16641. },
  16642. value: [
  16643. new asn1js.Sequence({
  16644. value: Array.from(this.requestExtensions, o => o.toSchema())
  16645. })
  16646. ]
  16647. }));
  16648. }
  16649. tbsSchema = new asn1js.Sequence({
  16650. value: outputArray
  16651. });
  16652. }
  16653. return tbsSchema;
  16654. }
  16655. toJSON() {
  16656. const res = {};
  16657. if (this.version != undefined)
  16658. res.version = this.version;
  16659. if (this.requestorName) {
  16660. res.requestorName = this.requestorName.toJSON();
  16661. }
  16662. res.requestList = Array.from(this.requestList, o => o.toJSON());
  16663. if (this.requestExtensions) {
  16664. res.requestExtensions = Array.from(this.requestExtensions, o => o.toJSON());
  16665. }
  16666. return res;
  16667. }
  16668. }
  16669. TBSRequest.CLASS_NAME = "TBSRequest";
  16670. const SIGNATURE_ALGORITHM$1 = "signatureAlgorithm";
  16671. const SIGNATURE$1 = "signature";
  16672. const CERTS = "certs";
  16673. class Signature extends PkiObject {
  16674. constructor(parameters = {}) {
  16675. super();
  16676. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM$1, Signature.defaultValues(SIGNATURE_ALGORITHM$1));
  16677. this.signature = pvutils.getParametersValue(parameters, SIGNATURE$1, Signature.defaultValues(SIGNATURE$1));
  16678. if (CERTS in parameters) {
  16679. this.certs = pvutils.getParametersValue(parameters, CERTS, Signature.defaultValues(CERTS));
  16680. }
  16681. if (parameters.schema) {
  16682. this.fromSchema(parameters.schema);
  16683. }
  16684. }
  16685. static defaultValues(memberName) {
  16686. switch (memberName) {
  16687. case SIGNATURE_ALGORITHM$1:
  16688. return new AlgorithmIdentifier();
  16689. case SIGNATURE$1:
  16690. return new asn1js.BitString();
  16691. case CERTS:
  16692. return [];
  16693. default:
  16694. return super.defaultValues(memberName);
  16695. }
  16696. }
  16697. static compareWithDefault(memberName, memberValue) {
  16698. switch (memberName) {
  16699. case SIGNATURE_ALGORITHM$1:
  16700. return ((memberValue.algorithmId === EMPTY_STRING) && (("algorithmParams" in memberValue) === false));
  16701. case SIGNATURE$1:
  16702. return (memberValue.isEqual(Signature.defaultValues(memberName)));
  16703. case CERTS:
  16704. return (memberValue.length === 0);
  16705. default:
  16706. return super.defaultValues(memberName);
  16707. }
  16708. }
  16709. static schema(parameters = {}) {
  16710. const names = pvutils.getParametersValue(parameters, "names", {});
  16711. return (new asn1js.Sequence({
  16712. name: (names.blockName || EMPTY_STRING),
  16713. value: [
  16714. AlgorithmIdentifier.schema(names.signatureAlgorithm || {}),
  16715. new asn1js.BitString({ name: (names.signature || EMPTY_STRING) }),
  16716. new asn1js.Constructed({
  16717. optional: true,
  16718. idBlock: {
  16719. tagClass: 3,
  16720. tagNumber: 0
  16721. },
  16722. value: [
  16723. new asn1js.Sequence({
  16724. value: [new asn1js.Repeated({
  16725. name: (names.certs || EMPTY_STRING),
  16726. value: Certificate.schema({})
  16727. })]
  16728. })
  16729. ]
  16730. })
  16731. ]
  16732. }));
  16733. }
  16734. fromSchema(schema) {
  16735. pvutils.clearProps(schema, [
  16736. SIGNATURE_ALGORITHM$1,
  16737. SIGNATURE$1,
  16738. CERTS
  16739. ]);
  16740. const asn1 = asn1js.compareSchema(schema, schema, Signature.schema({
  16741. names: {
  16742. signatureAlgorithm: {
  16743. names: {
  16744. blockName: SIGNATURE_ALGORITHM$1
  16745. }
  16746. },
  16747. signature: SIGNATURE$1,
  16748. certs: CERTS
  16749. }
  16750. }));
  16751. AsnError.assertSchema(asn1, this.className);
  16752. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result.signatureAlgorithm });
  16753. this.signature = asn1.result.signature;
  16754. if (CERTS in asn1.result)
  16755. this.certs = Array.from(asn1.result.certs, element => new Certificate({ schema: element }));
  16756. }
  16757. toSchema() {
  16758. const outputArray = [];
  16759. outputArray.push(this.signatureAlgorithm.toSchema());
  16760. outputArray.push(this.signature);
  16761. if (this.certs) {
  16762. outputArray.push(new asn1js.Constructed({
  16763. optional: true,
  16764. idBlock: {
  16765. tagClass: 3,
  16766. tagNumber: 0
  16767. },
  16768. value: [
  16769. new asn1js.Sequence({
  16770. value: Array.from(this.certs, o => o.toSchema())
  16771. })
  16772. ]
  16773. }));
  16774. }
  16775. return (new asn1js.Sequence({
  16776. value: outputArray
  16777. }));
  16778. }
  16779. toJSON() {
  16780. const res = {
  16781. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  16782. signature: this.signature.toJSON(),
  16783. };
  16784. if (this.certs) {
  16785. res.certs = Array.from(this.certs, o => o.toJSON());
  16786. }
  16787. return res;
  16788. }
  16789. }
  16790. Signature.CLASS_NAME = "Signature";
  16791. const TBS_REQUEST = "tbsRequest";
  16792. const OPTIONAL_SIGNATURE = "optionalSignature";
  16793. const CLEAR_PROPS$8 = [
  16794. TBS_REQUEST,
  16795. OPTIONAL_SIGNATURE
  16796. ];
  16797. class OCSPRequest extends PkiObject {
  16798. constructor(parameters = {}) {
  16799. super();
  16800. this.tbsRequest = pvutils.getParametersValue(parameters, TBS_REQUEST, OCSPRequest.defaultValues(TBS_REQUEST));
  16801. if (OPTIONAL_SIGNATURE in parameters) {
  16802. this.optionalSignature = pvutils.getParametersValue(parameters, OPTIONAL_SIGNATURE, OCSPRequest.defaultValues(OPTIONAL_SIGNATURE));
  16803. }
  16804. if (parameters.schema) {
  16805. this.fromSchema(parameters.schema);
  16806. }
  16807. }
  16808. static defaultValues(memberName) {
  16809. switch (memberName) {
  16810. case TBS_REQUEST:
  16811. return new TBSRequest();
  16812. case OPTIONAL_SIGNATURE:
  16813. return new Signature();
  16814. default:
  16815. return super.defaultValues(memberName);
  16816. }
  16817. }
  16818. static compareWithDefault(memberName, memberValue) {
  16819. switch (memberName) {
  16820. case TBS_REQUEST:
  16821. return ((TBSRequest.compareWithDefault("tbs", memberValue.tbs)) &&
  16822. (TBSRequest.compareWithDefault("version", memberValue.version)) &&
  16823. (TBSRequest.compareWithDefault("requestorName", memberValue.requestorName)) &&
  16824. (TBSRequest.compareWithDefault("requestList", memberValue.requestList)) &&
  16825. (TBSRequest.compareWithDefault("requestExtensions", memberValue.requestExtensions)));
  16826. case OPTIONAL_SIGNATURE:
  16827. return ((Signature.compareWithDefault("signatureAlgorithm", memberValue.signatureAlgorithm)) &&
  16828. (Signature.compareWithDefault("signature", memberValue.signature)) &&
  16829. (Signature.compareWithDefault("certs", memberValue.certs)));
  16830. default:
  16831. return super.defaultValues(memberName);
  16832. }
  16833. }
  16834. static schema(parameters = {}) {
  16835. const names = pvutils.getParametersValue(parameters, "names", {});
  16836. return (new asn1js.Sequence({
  16837. name: names.blockName || "OCSPRequest",
  16838. value: [
  16839. TBSRequest.schema(names.tbsRequest || {
  16840. names: {
  16841. blockName: TBS_REQUEST
  16842. }
  16843. }),
  16844. new asn1js.Constructed({
  16845. optional: true,
  16846. idBlock: {
  16847. tagClass: 3,
  16848. tagNumber: 0
  16849. },
  16850. value: [
  16851. Signature.schema(names.optionalSignature || {
  16852. names: {
  16853. blockName: OPTIONAL_SIGNATURE
  16854. }
  16855. })
  16856. ]
  16857. })
  16858. ]
  16859. }));
  16860. }
  16861. fromSchema(schema) {
  16862. pvutils.clearProps(schema, CLEAR_PROPS$8);
  16863. const asn1 = asn1js.compareSchema(schema, schema, OCSPRequest.schema());
  16864. AsnError.assertSchema(asn1, this.className);
  16865. this.tbsRequest = new TBSRequest({ schema: asn1.result.tbsRequest });
  16866. if (OPTIONAL_SIGNATURE in asn1.result)
  16867. this.optionalSignature = new Signature({ schema: asn1.result.optionalSignature });
  16868. }
  16869. toSchema(encodeFlag = false) {
  16870. const outputArray = [];
  16871. outputArray.push(this.tbsRequest.toSchema(encodeFlag));
  16872. if (this.optionalSignature)
  16873. outputArray.push(new asn1js.Constructed({
  16874. optional: true,
  16875. idBlock: {
  16876. tagClass: 3,
  16877. tagNumber: 0
  16878. },
  16879. value: [
  16880. this.optionalSignature.toSchema()
  16881. ]
  16882. }));
  16883. return (new asn1js.Sequence({
  16884. value: outputArray
  16885. }));
  16886. }
  16887. toJSON() {
  16888. const res = {
  16889. tbsRequest: this.tbsRequest.toJSON()
  16890. };
  16891. if (this.optionalSignature) {
  16892. res.optionalSignature = this.optionalSignature.toJSON();
  16893. }
  16894. return res;
  16895. }
  16896. async createForCertificate(certificate, parameters, crypto = getCrypto(true)) {
  16897. const certID = new CertID();
  16898. await certID.createForCertificate(certificate, parameters, crypto);
  16899. this.tbsRequest.requestList.push(new Request({
  16900. reqCert: certID,
  16901. }));
  16902. }
  16903. async sign(privateKey, hashAlgorithm = "SHA-1", crypto = getCrypto(true)) {
  16904. ParameterError.assertEmpty(privateKey, "privateKey", "OCSPRequest.sign method");
  16905. if (!this.optionalSignature) {
  16906. throw new Error("Need to create \"optionalSignature\" field before signing");
  16907. }
  16908. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  16909. const parameters = signatureParams.parameters;
  16910. this.optionalSignature.signatureAlgorithm = signatureParams.signatureAlgorithm;
  16911. const tbs = this.tbsRequest.toSchema(true).toBER(false);
  16912. const signature = await crypto.signWithPrivateKey(tbs, privateKey, parameters);
  16913. this.optionalSignature.signature = new asn1js.BitString({ valueHex: signature });
  16914. }
  16915. verify() {
  16916. }
  16917. }
  16918. OCSPRequest.CLASS_NAME = "OCSPRequest";
  16919. const RESPONSE_TYPE = "responseType";
  16920. const RESPONSE = "response";
  16921. const CLEAR_PROPS$7 = [
  16922. RESPONSE_TYPE,
  16923. RESPONSE
  16924. ];
  16925. class ResponseBytes extends PkiObject {
  16926. constructor(parameters = {}) {
  16927. super();
  16928. this.responseType = pvutils.getParametersValue(parameters, RESPONSE_TYPE, ResponseBytes.defaultValues(RESPONSE_TYPE));
  16929. this.response = pvutils.getParametersValue(parameters, RESPONSE, ResponseBytes.defaultValues(RESPONSE));
  16930. if (parameters.schema) {
  16931. this.fromSchema(parameters.schema);
  16932. }
  16933. }
  16934. static defaultValues(memberName) {
  16935. switch (memberName) {
  16936. case RESPONSE_TYPE:
  16937. return EMPTY_STRING;
  16938. case RESPONSE:
  16939. return new asn1js.OctetString();
  16940. default:
  16941. return super.defaultValues(memberName);
  16942. }
  16943. }
  16944. static compareWithDefault(memberName, memberValue) {
  16945. switch (memberName) {
  16946. case RESPONSE_TYPE:
  16947. return (memberValue === EMPTY_STRING);
  16948. case RESPONSE:
  16949. return (memberValue.isEqual(ResponseBytes.defaultValues(memberName)));
  16950. default:
  16951. return super.defaultValues(memberName);
  16952. }
  16953. }
  16954. static schema(parameters = {}) {
  16955. const names = pvutils.getParametersValue(parameters, "names", {});
  16956. return (new asn1js.Sequence({
  16957. name: (names.blockName || EMPTY_STRING),
  16958. value: [
  16959. new asn1js.ObjectIdentifier({ name: (names.responseType || EMPTY_STRING) }),
  16960. new asn1js.OctetString({ name: (names.response || EMPTY_STRING) })
  16961. ]
  16962. }));
  16963. }
  16964. fromSchema(schema) {
  16965. pvutils.clearProps(schema, CLEAR_PROPS$7);
  16966. const asn1 = asn1js.compareSchema(schema, schema, ResponseBytes.schema({
  16967. names: {
  16968. responseType: RESPONSE_TYPE,
  16969. response: RESPONSE
  16970. }
  16971. }));
  16972. AsnError.assertSchema(asn1, this.className);
  16973. this.responseType = asn1.result.responseType.valueBlock.toString();
  16974. this.response = asn1.result.response;
  16975. }
  16976. toSchema() {
  16977. return (new asn1js.Sequence({
  16978. value: [
  16979. new asn1js.ObjectIdentifier({ value: this.responseType }),
  16980. this.response
  16981. ]
  16982. }));
  16983. }
  16984. toJSON() {
  16985. return {
  16986. responseType: this.responseType,
  16987. response: this.response.toJSON(),
  16988. };
  16989. }
  16990. }
  16991. ResponseBytes.CLASS_NAME = "ResponseBytes";
  16992. const RESPONSE_STATUS = "responseStatus";
  16993. const RESPONSE_BYTES = "responseBytes";
  16994. class OCSPResponse extends PkiObject {
  16995. constructor(parameters = {}) {
  16996. super();
  16997. this.responseStatus = pvutils.getParametersValue(parameters, RESPONSE_STATUS, OCSPResponse.defaultValues(RESPONSE_STATUS));
  16998. if (RESPONSE_BYTES in parameters) {
  16999. this.responseBytes = pvutils.getParametersValue(parameters, RESPONSE_BYTES, OCSPResponse.defaultValues(RESPONSE_BYTES));
  17000. }
  17001. if (parameters.schema) {
  17002. this.fromSchema(parameters.schema);
  17003. }
  17004. }
  17005. static defaultValues(memberName) {
  17006. switch (memberName) {
  17007. case RESPONSE_STATUS:
  17008. return new asn1js.Enumerated();
  17009. case RESPONSE_BYTES:
  17010. return new ResponseBytes();
  17011. default:
  17012. return super.defaultValues(memberName);
  17013. }
  17014. }
  17015. static compareWithDefault(memberName, memberValue) {
  17016. switch (memberName) {
  17017. case RESPONSE_STATUS:
  17018. return (memberValue.isEqual(OCSPResponse.defaultValues(memberName)));
  17019. case RESPONSE_BYTES:
  17020. return ((ResponseBytes.compareWithDefault("responseType", memberValue.responseType)) &&
  17021. (ResponseBytes.compareWithDefault("response", memberValue.response)));
  17022. default:
  17023. return super.defaultValues(memberName);
  17024. }
  17025. }
  17026. static schema(parameters = {}) {
  17027. const names = pvutils.getParametersValue(parameters, "names", {});
  17028. return (new asn1js.Sequence({
  17029. name: (names.blockName || "OCSPResponse"),
  17030. value: [
  17031. new asn1js.Enumerated({ name: (names.responseStatus || RESPONSE_STATUS) }),
  17032. new asn1js.Constructed({
  17033. optional: true,
  17034. idBlock: {
  17035. tagClass: 3,
  17036. tagNumber: 0
  17037. },
  17038. value: [
  17039. ResponseBytes.schema(names.responseBytes || {
  17040. names: {
  17041. blockName: RESPONSE_BYTES
  17042. }
  17043. })
  17044. ]
  17045. })
  17046. ]
  17047. }));
  17048. }
  17049. fromSchema(schema) {
  17050. pvutils.clearProps(schema, [
  17051. RESPONSE_STATUS,
  17052. RESPONSE_BYTES
  17053. ]);
  17054. const asn1 = asn1js.compareSchema(schema, schema, OCSPResponse.schema());
  17055. AsnError.assertSchema(asn1, this.className);
  17056. this.responseStatus = asn1.result.responseStatus;
  17057. if (RESPONSE_BYTES in asn1.result)
  17058. this.responseBytes = new ResponseBytes({ schema: asn1.result.responseBytes });
  17059. }
  17060. toSchema() {
  17061. const outputArray = [];
  17062. outputArray.push(this.responseStatus);
  17063. if (this.responseBytes) {
  17064. outputArray.push(new asn1js.Constructed({
  17065. idBlock: {
  17066. tagClass: 3,
  17067. tagNumber: 0
  17068. },
  17069. value: [this.responseBytes.toSchema()]
  17070. }));
  17071. }
  17072. return (new asn1js.Sequence({
  17073. value: outputArray
  17074. }));
  17075. }
  17076. toJSON() {
  17077. const res = {
  17078. responseStatus: this.responseStatus.toJSON()
  17079. };
  17080. if (this.responseBytes) {
  17081. res.responseBytes = this.responseBytes.toJSON();
  17082. }
  17083. return res;
  17084. }
  17085. async getCertificateStatus(certificate, issuerCertificate, crypto = getCrypto(true)) {
  17086. let basicResponse;
  17087. const result = {
  17088. isForCertificate: false,
  17089. status: 2
  17090. };
  17091. if (!this.responseBytes)
  17092. return result;
  17093. if (this.responseBytes.responseType !== id_PKIX_OCSP_Basic)
  17094. return result;
  17095. try {
  17096. const asn1Basic = asn1js.fromBER(this.responseBytes.response.valueBlock.valueHexView);
  17097. AsnError.assert(asn1Basic, "Basic OCSP response");
  17098. basicResponse = new BasicOCSPResponse({ schema: asn1Basic.result });
  17099. }
  17100. catch {
  17101. return result;
  17102. }
  17103. return basicResponse.getCertificateStatus(certificate, issuerCertificate, crypto);
  17104. }
  17105. async sign(privateKey, hashAlgorithm, crypto = getCrypto(true)) {
  17106. var _a;
  17107. if (this.responseBytes && this.responseBytes.responseType === id_PKIX_OCSP_Basic) {
  17108. const basicResponse = BasicOCSPResponse.fromBER(this.responseBytes.response.valueBlock.valueHexView);
  17109. return basicResponse.sign(privateKey, hashAlgorithm, crypto);
  17110. }
  17111. throw new Error(`Unknown ResponseBytes type: ${((_a = this.responseBytes) === null || _a === void 0 ? void 0 : _a.responseType) || "Unknown"}`);
  17112. }
  17113. async verify(issuerCertificate = null, crypto = getCrypto(true)) {
  17114. var _a;
  17115. if ((RESPONSE_BYTES in this) === false)
  17116. throw new Error("Empty ResponseBytes field");
  17117. if (this.responseBytes && this.responseBytes.responseType === id_PKIX_OCSP_Basic) {
  17118. const basicResponse = BasicOCSPResponse.fromBER(this.responseBytes.response.valueBlock.valueHexView);
  17119. if (issuerCertificate !== null) {
  17120. if (!basicResponse.certs) {
  17121. basicResponse.certs = [];
  17122. }
  17123. basicResponse.certs.push(issuerCertificate);
  17124. }
  17125. return basicResponse.verify({}, crypto);
  17126. }
  17127. throw new Error(`Unknown ResponseBytes type: ${((_a = this.responseBytes) === null || _a === void 0 ? void 0 : _a.responseType) || "Unknown"}`);
  17128. }
  17129. }
  17130. OCSPResponse.CLASS_NAME = "OCSPResponse";
  17131. const TYPE = "type";
  17132. const ATTRIBUTES = "attributes";
  17133. const ENCODED_VALUE = "encodedValue";
  17134. const CLEAR_PROPS$6 = [
  17135. ATTRIBUTES
  17136. ];
  17137. class SignedAndUnsignedAttributes extends PkiObject {
  17138. constructor(parameters = {}) {
  17139. super();
  17140. this.type = pvutils.getParametersValue(parameters, TYPE, SignedAndUnsignedAttributes.defaultValues(TYPE));
  17141. this.attributes = pvutils.getParametersValue(parameters, ATTRIBUTES, SignedAndUnsignedAttributes.defaultValues(ATTRIBUTES));
  17142. this.encodedValue = pvutils.getParametersValue(parameters, ENCODED_VALUE, SignedAndUnsignedAttributes.defaultValues(ENCODED_VALUE));
  17143. if (parameters.schema) {
  17144. this.fromSchema(parameters.schema);
  17145. }
  17146. }
  17147. static defaultValues(memberName) {
  17148. switch (memberName) {
  17149. case TYPE:
  17150. return (-1);
  17151. case ATTRIBUTES:
  17152. return [];
  17153. case ENCODED_VALUE:
  17154. return EMPTY_BUFFER;
  17155. default:
  17156. return super.defaultValues(memberName);
  17157. }
  17158. }
  17159. static compareWithDefault(memberName, memberValue) {
  17160. switch (memberName) {
  17161. case TYPE:
  17162. return (memberValue === SignedAndUnsignedAttributes.defaultValues(TYPE));
  17163. case ATTRIBUTES:
  17164. return (memberValue.length === 0);
  17165. case ENCODED_VALUE:
  17166. return (memberValue.byteLength === 0);
  17167. default:
  17168. return super.defaultValues(memberName);
  17169. }
  17170. }
  17171. static schema(parameters = {}) {
  17172. const names = pvutils.getParametersValue(parameters, "names", {});
  17173. return (new asn1js.Constructed({
  17174. name: (names.blockName || EMPTY_STRING),
  17175. optional: true,
  17176. idBlock: {
  17177. tagClass: 3,
  17178. tagNumber: names.tagNumber || 0
  17179. },
  17180. value: [
  17181. new asn1js.Repeated({
  17182. name: (names.attributes || EMPTY_STRING),
  17183. value: Attribute.schema()
  17184. })
  17185. ]
  17186. }));
  17187. }
  17188. fromSchema(schema) {
  17189. pvutils.clearProps(schema, CLEAR_PROPS$6);
  17190. const asn1 = asn1js.compareSchema(schema, schema, SignedAndUnsignedAttributes.schema({
  17191. names: {
  17192. tagNumber: this.type,
  17193. attributes: ATTRIBUTES
  17194. }
  17195. }));
  17196. AsnError.assertSchema(asn1, this.className);
  17197. this.type = asn1.result.idBlock.tagNumber;
  17198. this.encodedValue = pvtsutils.BufferSourceConverter.toArrayBuffer(asn1.result.valueBeforeDecodeView);
  17199. const encodedView = new Uint8Array(this.encodedValue);
  17200. encodedView[0] = 0x31;
  17201. if ((ATTRIBUTES in asn1.result) === false) {
  17202. if (this.type === 0)
  17203. throw new Error("Wrong structure of SignedUnsignedAttributes");
  17204. else
  17205. return;
  17206. }
  17207. this.attributes = Array.from(asn1.result.attributes, element => new Attribute({ schema: element }));
  17208. }
  17209. toSchema() {
  17210. if (SignedAndUnsignedAttributes.compareWithDefault(TYPE, this.type) || SignedAndUnsignedAttributes.compareWithDefault(ATTRIBUTES, this.attributes))
  17211. throw new Error("Incorrectly initialized \"SignedAndUnsignedAttributes\" class");
  17212. return (new asn1js.Constructed({
  17213. optional: true,
  17214. idBlock: {
  17215. tagClass: 3,
  17216. tagNumber: this.type
  17217. },
  17218. value: Array.from(this.attributes, o => o.toSchema())
  17219. }));
  17220. }
  17221. toJSON() {
  17222. if (SignedAndUnsignedAttributes.compareWithDefault(TYPE, this.type) || SignedAndUnsignedAttributes.compareWithDefault(ATTRIBUTES, this.attributes))
  17223. throw new Error("Incorrectly initialized \"SignedAndUnsignedAttributes\" class");
  17224. return {
  17225. type: this.type,
  17226. attributes: Array.from(this.attributes, o => o.toJSON())
  17227. };
  17228. }
  17229. }
  17230. SignedAndUnsignedAttributes.CLASS_NAME = "SignedAndUnsignedAttributes";
  17231. const VERSION$4 = "version";
  17232. const SID = "sid";
  17233. const DIGEST_ALGORITHM = "digestAlgorithm";
  17234. const SIGNED_ATTRS = "signedAttrs";
  17235. const SIGNATURE_ALGORITHM = "signatureAlgorithm";
  17236. const SIGNATURE = "signature";
  17237. const UNSIGNED_ATTRS = "unsignedAttrs";
  17238. const SIGNER_INFO = "SignerInfo";
  17239. const SIGNER_INFO_VERSION = `${SIGNER_INFO}.${VERSION$4}`;
  17240. const SIGNER_INFO_SID = `${SIGNER_INFO}.${SID}`;
  17241. const SIGNER_INFO_DIGEST_ALGORITHM = `${SIGNER_INFO}.${DIGEST_ALGORITHM}`;
  17242. const SIGNER_INFO_SIGNED_ATTRS = `${SIGNER_INFO}.${SIGNED_ATTRS}`;
  17243. const SIGNER_INFO_SIGNATURE_ALGORITHM = `${SIGNER_INFO}.${SIGNATURE_ALGORITHM}`;
  17244. const SIGNER_INFO_SIGNATURE = `${SIGNER_INFO}.${SIGNATURE}`;
  17245. const SIGNER_INFO_UNSIGNED_ATTRS = `${SIGNER_INFO}.${UNSIGNED_ATTRS}`;
  17246. const CLEAR_PROPS$5 = [
  17247. SIGNER_INFO_VERSION,
  17248. SIGNER_INFO_SID,
  17249. SIGNER_INFO_DIGEST_ALGORITHM,
  17250. SIGNER_INFO_SIGNED_ATTRS,
  17251. SIGNER_INFO_SIGNATURE_ALGORITHM,
  17252. SIGNER_INFO_SIGNATURE,
  17253. SIGNER_INFO_UNSIGNED_ATTRS
  17254. ];
  17255. class SignerInfo extends PkiObject {
  17256. constructor(parameters = {}) {
  17257. super();
  17258. this.version = pvutils.getParametersValue(parameters, VERSION$4, SignerInfo.defaultValues(VERSION$4));
  17259. this.sid = pvutils.getParametersValue(parameters, SID, SignerInfo.defaultValues(SID));
  17260. this.digestAlgorithm = pvutils.getParametersValue(parameters, DIGEST_ALGORITHM, SignerInfo.defaultValues(DIGEST_ALGORITHM));
  17261. if (SIGNED_ATTRS in parameters) {
  17262. this.signedAttrs = pvutils.getParametersValue(parameters, SIGNED_ATTRS, SignerInfo.defaultValues(SIGNED_ATTRS));
  17263. }
  17264. this.signatureAlgorithm = pvutils.getParametersValue(parameters, SIGNATURE_ALGORITHM, SignerInfo.defaultValues(SIGNATURE_ALGORITHM));
  17265. this.signature = pvutils.getParametersValue(parameters, SIGNATURE, SignerInfo.defaultValues(SIGNATURE));
  17266. if (UNSIGNED_ATTRS in parameters) {
  17267. this.unsignedAttrs = pvutils.getParametersValue(parameters, UNSIGNED_ATTRS, SignerInfo.defaultValues(UNSIGNED_ATTRS));
  17268. }
  17269. if (parameters.schema) {
  17270. this.fromSchema(parameters.schema);
  17271. }
  17272. }
  17273. static defaultValues(memberName) {
  17274. switch (memberName) {
  17275. case VERSION$4:
  17276. return 0;
  17277. case SID:
  17278. return new asn1js.Any();
  17279. case DIGEST_ALGORITHM:
  17280. return new AlgorithmIdentifier();
  17281. case SIGNED_ATTRS:
  17282. return new SignedAndUnsignedAttributes({ type: 0 });
  17283. case SIGNATURE_ALGORITHM:
  17284. return new AlgorithmIdentifier();
  17285. case SIGNATURE:
  17286. return new asn1js.OctetString();
  17287. case UNSIGNED_ATTRS:
  17288. return new SignedAndUnsignedAttributes({ type: 1 });
  17289. default:
  17290. return super.defaultValues(memberName);
  17291. }
  17292. }
  17293. static compareWithDefault(memberName, memberValue) {
  17294. switch (memberName) {
  17295. case VERSION$4:
  17296. return (SignerInfo.defaultValues(VERSION$4) === memberValue);
  17297. case SID:
  17298. return (memberValue instanceof asn1js.Any);
  17299. case DIGEST_ALGORITHM:
  17300. if ((memberValue instanceof AlgorithmIdentifier) === false)
  17301. return false;
  17302. return memberValue.isEqual(SignerInfo.defaultValues(DIGEST_ALGORITHM));
  17303. case SIGNED_ATTRS:
  17304. return ((SignedAndUnsignedAttributes.compareWithDefault("type", memberValue.type))
  17305. && (SignedAndUnsignedAttributes.compareWithDefault("attributes", memberValue.attributes))
  17306. && (SignedAndUnsignedAttributes.compareWithDefault("encodedValue", memberValue.encodedValue)));
  17307. case SIGNATURE_ALGORITHM:
  17308. if ((memberValue instanceof AlgorithmIdentifier) === false)
  17309. return false;
  17310. return memberValue.isEqual(SignerInfo.defaultValues(SIGNATURE_ALGORITHM));
  17311. case SIGNATURE:
  17312. case UNSIGNED_ATTRS:
  17313. return ((SignedAndUnsignedAttributes.compareWithDefault("type", memberValue.type))
  17314. && (SignedAndUnsignedAttributes.compareWithDefault("attributes", memberValue.attributes))
  17315. && (SignedAndUnsignedAttributes.compareWithDefault("encodedValue", memberValue.encodedValue)));
  17316. default:
  17317. return super.defaultValues(memberName);
  17318. }
  17319. }
  17320. static schema(parameters = {}) {
  17321. const names = pvutils.getParametersValue(parameters, "names", {});
  17322. return (new asn1js.Sequence({
  17323. name: SIGNER_INFO,
  17324. value: [
  17325. new asn1js.Integer({ name: (names.version || SIGNER_INFO_VERSION) }),
  17326. new asn1js.Choice({
  17327. value: [
  17328. IssuerAndSerialNumber.schema(names.sidSchema || {
  17329. names: {
  17330. blockName: SIGNER_INFO_SID
  17331. }
  17332. }),
  17333. new asn1js.Choice({
  17334. value: [
  17335. new asn1js.Constructed({
  17336. optional: true,
  17337. name: (names.sid || SIGNER_INFO_SID),
  17338. idBlock: {
  17339. tagClass: 3,
  17340. tagNumber: 0
  17341. },
  17342. value: [new asn1js.OctetString()]
  17343. }),
  17344. new asn1js.Primitive({
  17345. optional: true,
  17346. name: (names.sid || SIGNER_INFO_SID),
  17347. idBlock: {
  17348. tagClass: 3,
  17349. tagNumber: 0
  17350. }
  17351. }),
  17352. ]
  17353. }),
  17354. ]
  17355. }),
  17356. AlgorithmIdentifier.schema(names.digestAlgorithm || {
  17357. names: {
  17358. blockName: SIGNER_INFO_DIGEST_ALGORITHM
  17359. }
  17360. }),
  17361. SignedAndUnsignedAttributes.schema(names.signedAttrs || {
  17362. names: {
  17363. blockName: SIGNER_INFO_SIGNED_ATTRS,
  17364. tagNumber: 0
  17365. }
  17366. }),
  17367. AlgorithmIdentifier.schema(names.signatureAlgorithm || {
  17368. names: {
  17369. blockName: SIGNER_INFO_SIGNATURE_ALGORITHM
  17370. }
  17371. }),
  17372. new asn1js.OctetString({ name: (names.signature || SIGNER_INFO_SIGNATURE) }),
  17373. SignedAndUnsignedAttributes.schema(names.unsignedAttrs || {
  17374. names: {
  17375. blockName: SIGNER_INFO_UNSIGNED_ATTRS,
  17376. tagNumber: 1
  17377. }
  17378. })
  17379. ]
  17380. }));
  17381. }
  17382. fromSchema(schema) {
  17383. pvutils.clearProps(schema, CLEAR_PROPS$5);
  17384. const asn1 = asn1js.compareSchema(schema, schema, SignerInfo.schema());
  17385. AsnError.assertSchema(asn1, this.className);
  17386. this.version = asn1.result[SIGNER_INFO_VERSION].valueBlock.valueDec;
  17387. const currentSid = asn1.result[SIGNER_INFO_SID];
  17388. if (currentSid.idBlock.tagClass === 1)
  17389. this.sid = new IssuerAndSerialNumber({ schema: currentSid });
  17390. else
  17391. this.sid = currentSid;
  17392. this.digestAlgorithm = new AlgorithmIdentifier({ schema: asn1.result[SIGNER_INFO_DIGEST_ALGORITHM] });
  17393. if (SIGNER_INFO_SIGNED_ATTRS in asn1.result)
  17394. this.signedAttrs = new SignedAndUnsignedAttributes({ type: 0, schema: asn1.result[SIGNER_INFO_SIGNED_ATTRS] });
  17395. this.signatureAlgorithm = new AlgorithmIdentifier({ schema: asn1.result[SIGNER_INFO_SIGNATURE_ALGORITHM] });
  17396. this.signature = asn1.result[SIGNER_INFO_SIGNATURE];
  17397. if (SIGNER_INFO_UNSIGNED_ATTRS in asn1.result)
  17398. this.unsignedAttrs = new SignedAndUnsignedAttributes({ type: 1, schema: asn1.result[SIGNER_INFO_UNSIGNED_ATTRS] });
  17399. }
  17400. toSchema() {
  17401. if (SignerInfo.compareWithDefault(SID, this.sid))
  17402. throw new Error("Incorrectly initialized \"SignerInfo\" class");
  17403. const outputArray = [];
  17404. outputArray.push(new asn1js.Integer({ value: this.version }));
  17405. if (this.sid instanceof IssuerAndSerialNumber)
  17406. outputArray.push(this.sid.toSchema());
  17407. else
  17408. outputArray.push(this.sid);
  17409. outputArray.push(this.digestAlgorithm.toSchema());
  17410. if (this.signedAttrs) {
  17411. if (SignerInfo.compareWithDefault(SIGNED_ATTRS, this.signedAttrs) === false)
  17412. outputArray.push(this.signedAttrs.toSchema());
  17413. }
  17414. outputArray.push(this.signatureAlgorithm.toSchema());
  17415. outputArray.push(this.signature);
  17416. if (this.unsignedAttrs) {
  17417. if (SignerInfo.compareWithDefault(UNSIGNED_ATTRS, this.unsignedAttrs) === false)
  17418. outputArray.push(this.unsignedAttrs.toSchema());
  17419. }
  17420. return (new asn1js.Sequence({
  17421. value: outputArray
  17422. }));
  17423. }
  17424. toJSON() {
  17425. if (SignerInfo.compareWithDefault(SID, this.sid)) {
  17426. throw new Error("Incorrectly initialized \"SignerInfo\" class");
  17427. }
  17428. const res = {
  17429. version: this.version,
  17430. digestAlgorithm: this.digestAlgorithm.toJSON(),
  17431. signatureAlgorithm: this.signatureAlgorithm.toJSON(),
  17432. signature: this.signature.toJSON(),
  17433. };
  17434. if (!(this.sid instanceof asn1js.Any))
  17435. res.sid = this.sid.toJSON();
  17436. if (this.signedAttrs && SignerInfo.compareWithDefault(SIGNED_ATTRS, this.signedAttrs) === false) {
  17437. res.signedAttrs = this.signedAttrs.toJSON();
  17438. }
  17439. if (this.unsignedAttrs && SignerInfo.compareWithDefault(UNSIGNED_ATTRS, this.unsignedAttrs) === false) {
  17440. res.unsignedAttrs = this.unsignedAttrs.toJSON();
  17441. }
  17442. return res;
  17443. }
  17444. }
  17445. SignerInfo.CLASS_NAME = "SignerInfo";
  17446. const VERSION$3 = "version";
  17447. const POLICY = "policy";
  17448. const MESSAGE_IMPRINT$1 = "messageImprint";
  17449. const SERIAL_NUMBER = "serialNumber";
  17450. const GEN_TIME = "genTime";
  17451. const ORDERING = "ordering";
  17452. const NONCE$1 = "nonce";
  17453. const ACCURACY = "accuracy";
  17454. const TSA = "tsa";
  17455. const EXTENSIONS$1 = "extensions";
  17456. const TST_INFO = "TSTInfo";
  17457. const TST_INFO_VERSION = `${TST_INFO}.${VERSION$3}`;
  17458. const TST_INFO_POLICY = `${TST_INFO}.${POLICY}`;
  17459. const TST_INFO_MESSAGE_IMPRINT = `${TST_INFO}.${MESSAGE_IMPRINT$1}`;
  17460. const TST_INFO_SERIAL_NUMBER = `${TST_INFO}.${SERIAL_NUMBER}`;
  17461. const TST_INFO_GEN_TIME = `${TST_INFO}.${GEN_TIME}`;
  17462. const TST_INFO_ACCURACY = `${TST_INFO}.${ACCURACY}`;
  17463. const TST_INFO_ORDERING = `${TST_INFO}.${ORDERING}`;
  17464. const TST_INFO_NONCE = `${TST_INFO}.${NONCE$1}`;
  17465. const TST_INFO_TSA = `${TST_INFO}.${TSA}`;
  17466. const TST_INFO_EXTENSIONS = `${TST_INFO}.${EXTENSIONS$1}`;
  17467. const CLEAR_PROPS$4 = [
  17468. TST_INFO_VERSION,
  17469. TST_INFO_POLICY,
  17470. TST_INFO_MESSAGE_IMPRINT,
  17471. TST_INFO_SERIAL_NUMBER,
  17472. TST_INFO_GEN_TIME,
  17473. TST_INFO_ACCURACY,
  17474. TST_INFO_ORDERING,
  17475. TST_INFO_NONCE,
  17476. TST_INFO_TSA,
  17477. TST_INFO_EXTENSIONS
  17478. ];
  17479. class TSTInfo extends PkiObject {
  17480. constructor(parameters = {}) {
  17481. super();
  17482. this.version = pvutils.getParametersValue(parameters, VERSION$3, TSTInfo.defaultValues(VERSION$3));
  17483. this.policy = pvutils.getParametersValue(parameters, POLICY, TSTInfo.defaultValues(POLICY));
  17484. this.messageImprint = pvutils.getParametersValue(parameters, MESSAGE_IMPRINT$1, TSTInfo.defaultValues(MESSAGE_IMPRINT$1));
  17485. this.serialNumber = pvutils.getParametersValue(parameters, SERIAL_NUMBER, TSTInfo.defaultValues(SERIAL_NUMBER));
  17486. this.genTime = pvutils.getParametersValue(parameters, GEN_TIME, TSTInfo.defaultValues(GEN_TIME));
  17487. if (ACCURACY in parameters) {
  17488. this.accuracy = pvutils.getParametersValue(parameters, ACCURACY, TSTInfo.defaultValues(ACCURACY));
  17489. }
  17490. if (ORDERING in parameters) {
  17491. this.ordering = pvutils.getParametersValue(parameters, ORDERING, TSTInfo.defaultValues(ORDERING));
  17492. }
  17493. if (NONCE$1 in parameters) {
  17494. this.nonce = pvutils.getParametersValue(parameters, NONCE$1, TSTInfo.defaultValues(NONCE$1));
  17495. }
  17496. if (TSA in parameters) {
  17497. this.tsa = pvutils.getParametersValue(parameters, TSA, TSTInfo.defaultValues(TSA));
  17498. }
  17499. if (EXTENSIONS$1 in parameters) {
  17500. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS$1, TSTInfo.defaultValues(EXTENSIONS$1));
  17501. }
  17502. if (parameters.schema) {
  17503. this.fromSchema(parameters.schema);
  17504. }
  17505. }
  17506. static defaultValues(memberName) {
  17507. switch (memberName) {
  17508. case VERSION$3:
  17509. return 0;
  17510. case POLICY:
  17511. return EMPTY_STRING;
  17512. case MESSAGE_IMPRINT$1:
  17513. return new MessageImprint();
  17514. case SERIAL_NUMBER:
  17515. return new asn1js.Integer();
  17516. case GEN_TIME:
  17517. return new Date(0, 0, 0);
  17518. case ACCURACY:
  17519. return new Accuracy();
  17520. case ORDERING:
  17521. return false;
  17522. case NONCE$1:
  17523. return new asn1js.Integer();
  17524. case TSA:
  17525. return new GeneralName();
  17526. case EXTENSIONS$1:
  17527. return [];
  17528. default:
  17529. return super.defaultValues(memberName);
  17530. }
  17531. }
  17532. static compareWithDefault(memberName, memberValue) {
  17533. switch (memberName) {
  17534. case VERSION$3:
  17535. case POLICY:
  17536. case GEN_TIME:
  17537. case ORDERING:
  17538. return (memberValue === TSTInfo.defaultValues(ORDERING));
  17539. case MESSAGE_IMPRINT$1:
  17540. return ((MessageImprint.compareWithDefault(HASH_ALGORITHM, memberValue.hashAlgorithm)) &&
  17541. (MessageImprint.compareWithDefault(HASHED_MESSAGE, memberValue.hashedMessage)));
  17542. case SERIAL_NUMBER:
  17543. case NONCE$1:
  17544. return (memberValue.isEqual(TSTInfo.defaultValues(NONCE$1)));
  17545. case ACCURACY:
  17546. return ((Accuracy.compareWithDefault(SECONDS, memberValue.seconds)) &&
  17547. (Accuracy.compareWithDefault(MILLIS, memberValue.millis)) &&
  17548. (Accuracy.compareWithDefault(MICROS, memberValue.micros)));
  17549. case TSA:
  17550. return ((GeneralName.compareWithDefault(TYPE$4, memberValue.type)) &&
  17551. (GeneralName.compareWithDefault(VALUE$5, memberValue.value)));
  17552. case EXTENSIONS$1:
  17553. return (memberValue.length === 0);
  17554. default:
  17555. return super.defaultValues(memberName);
  17556. }
  17557. }
  17558. static schema(parameters = {}) {
  17559. const names = pvutils.getParametersValue(parameters, "names", {});
  17560. return (new asn1js.Sequence({
  17561. name: (names.blockName || TST_INFO),
  17562. value: [
  17563. new asn1js.Integer({ name: (names.version || TST_INFO_VERSION) }),
  17564. new asn1js.ObjectIdentifier({ name: (names.policy || TST_INFO_POLICY) }),
  17565. MessageImprint.schema(names.messageImprint || {
  17566. names: {
  17567. blockName: TST_INFO_MESSAGE_IMPRINT
  17568. }
  17569. }),
  17570. new asn1js.Integer({ name: (names.serialNumber || TST_INFO_SERIAL_NUMBER) }),
  17571. new asn1js.GeneralizedTime({ name: (names.genTime || TST_INFO_GEN_TIME) }),
  17572. Accuracy.schema(names.accuracy || {
  17573. names: {
  17574. blockName: TST_INFO_ACCURACY
  17575. }
  17576. }),
  17577. new asn1js.Boolean({
  17578. name: (names.ordering || TST_INFO_ORDERING),
  17579. optional: true
  17580. }),
  17581. new asn1js.Integer({
  17582. name: (names.nonce || TST_INFO_NONCE),
  17583. optional: true
  17584. }),
  17585. new asn1js.Constructed({
  17586. optional: true,
  17587. idBlock: {
  17588. tagClass: 3,
  17589. tagNumber: 0
  17590. },
  17591. value: [GeneralName.schema(names.tsa || {
  17592. names: {
  17593. blockName: TST_INFO_TSA
  17594. }
  17595. })]
  17596. }),
  17597. new asn1js.Constructed({
  17598. optional: true,
  17599. idBlock: {
  17600. tagClass: 3,
  17601. tagNumber: 1
  17602. },
  17603. value: [
  17604. new asn1js.Repeated({
  17605. name: (names.extensions || TST_INFO_EXTENSIONS),
  17606. value: Extension.schema(names.extension || {})
  17607. })
  17608. ]
  17609. })
  17610. ]
  17611. }));
  17612. }
  17613. fromSchema(schema) {
  17614. pvutils.clearProps(schema, CLEAR_PROPS$4);
  17615. const asn1 = asn1js.compareSchema(schema, schema, TSTInfo.schema());
  17616. AsnError.assertSchema(asn1, this.className);
  17617. this.version = asn1.result[TST_INFO_VERSION].valueBlock.valueDec;
  17618. this.policy = asn1.result[TST_INFO_POLICY].valueBlock.toString();
  17619. this.messageImprint = new MessageImprint({ schema: asn1.result[TST_INFO_MESSAGE_IMPRINT] });
  17620. this.serialNumber = asn1.result[TST_INFO_SERIAL_NUMBER];
  17621. this.genTime = asn1.result[TST_INFO_GEN_TIME].toDate();
  17622. if (TST_INFO_ACCURACY in asn1.result)
  17623. this.accuracy = new Accuracy({ schema: asn1.result[TST_INFO_ACCURACY] });
  17624. if (TST_INFO_ORDERING in asn1.result)
  17625. this.ordering = asn1.result[TST_INFO_ORDERING].valueBlock.value;
  17626. if (TST_INFO_NONCE in asn1.result)
  17627. this.nonce = asn1.result[TST_INFO_NONCE];
  17628. if (TST_INFO_TSA in asn1.result)
  17629. this.tsa = new GeneralName({ schema: asn1.result[TST_INFO_TSA] });
  17630. if (TST_INFO_EXTENSIONS in asn1.result)
  17631. this.extensions = Array.from(asn1.result[TST_INFO_EXTENSIONS], element => new Extension({ schema: element }));
  17632. }
  17633. toSchema() {
  17634. const outputArray = [];
  17635. outputArray.push(new asn1js.Integer({ value: this.version }));
  17636. outputArray.push(new asn1js.ObjectIdentifier({ value: this.policy }));
  17637. outputArray.push(this.messageImprint.toSchema());
  17638. outputArray.push(this.serialNumber);
  17639. outputArray.push(new asn1js.GeneralizedTime({ valueDate: this.genTime }));
  17640. if (this.accuracy)
  17641. outputArray.push(this.accuracy.toSchema());
  17642. if (this.ordering !== undefined)
  17643. outputArray.push(new asn1js.Boolean({ value: this.ordering }));
  17644. if (this.nonce)
  17645. outputArray.push(this.nonce);
  17646. if (this.tsa) {
  17647. outputArray.push(new asn1js.Constructed({
  17648. optional: true,
  17649. idBlock: {
  17650. tagClass: 3,
  17651. tagNumber: 0
  17652. },
  17653. value: [this.tsa.toSchema()]
  17654. }));
  17655. }
  17656. if (this.extensions) {
  17657. outputArray.push(new asn1js.Constructed({
  17658. optional: true,
  17659. idBlock: {
  17660. tagClass: 3,
  17661. tagNumber: 1
  17662. },
  17663. value: Array.from(this.extensions, o => o.toSchema())
  17664. }));
  17665. }
  17666. return (new asn1js.Sequence({
  17667. value: outputArray
  17668. }));
  17669. }
  17670. toJSON() {
  17671. const res = {
  17672. version: this.version,
  17673. policy: this.policy,
  17674. messageImprint: this.messageImprint.toJSON(),
  17675. serialNumber: this.serialNumber.toJSON(),
  17676. genTime: this.genTime
  17677. };
  17678. if (this.accuracy)
  17679. res.accuracy = this.accuracy.toJSON();
  17680. if (this.ordering !== undefined)
  17681. res.ordering = this.ordering;
  17682. if (this.nonce)
  17683. res.nonce = this.nonce.toJSON();
  17684. if (this.tsa)
  17685. res.tsa = this.tsa.toJSON();
  17686. if (this.extensions)
  17687. res.extensions = Array.from(this.extensions, o => o.toJSON());
  17688. return res;
  17689. }
  17690. async verify(params, crypto = getCrypto(true)) {
  17691. if (!params.data) {
  17692. throw new Error("\"data\" is a mandatory attribute for TST_INFO verification");
  17693. }
  17694. const data = params.data;
  17695. if (params.notBefore) {
  17696. if (this.genTime < params.notBefore)
  17697. throw new Error("Generation time for TSTInfo object is less than notBefore value");
  17698. }
  17699. if (params.notAfter) {
  17700. if (this.genTime > params.notAfter)
  17701. throw new Error("Generation time for TSTInfo object is more than notAfter value");
  17702. }
  17703. const shaAlgorithm = crypto.getAlgorithmByOID(this.messageImprint.hashAlgorithm.algorithmId, true, "MessageImprint.hashAlgorithm");
  17704. const hash = await crypto.digest(shaAlgorithm.name, new Uint8Array(data));
  17705. return pvtsutils.BufferSourceConverter.isEqual(hash, this.messageImprint.hashedMessage.valueBlock.valueHexView);
  17706. }
  17707. }
  17708. TSTInfo.CLASS_NAME = "TSTInfo";
  17709. const VERSION$2 = "version";
  17710. const DIGEST_ALGORITHMS = "digestAlgorithms";
  17711. const ENCAP_CONTENT_INFO = "encapContentInfo";
  17712. const CERTIFICATES = "certificates";
  17713. const CRLS = "crls";
  17714. const SIGNER_INFOS = "signerInfos";
  17715. const OCSPS = "ocsps";
  17716. const SIGNED_DATA = "SignedData";
  17717. const SIGNED_DATA_VERSION = `${SIGNED_DATA}.${VERSION$2}`;
  17718. const SIGNED_DATA_DIGEST_ALGORITHMS = `${SIGNED_DATA}.${DIGEST_ALGORITHMS}`;
  17719. const SIGNED_DATA_ENCAP_CONTENT_INFO = `${SIGNED_DATA}.${ENCAP_CONTENT_INFO}`;
  17720. const SIGNED_DATA_CERTIFICATES = `${SIGNED_DATA}.${CERTIFICATES}`;
  17721. const SIGNED_DATA_CRLS = `${SIGNED_DATA}.${CRLS}`;
  17722. const SIGNED_DATA_SIGNER_INFOS = `${SIGNED_DATA}.${SIGNER_INFOS}`;
  17723. const CLEAR_PROPS$3 = [
  17724. SIGNED_DATA_VERSION,
  17725. SIGNED_DATA_DIGEST_ALGORITHMS,
  17726. SIGNED_DATA_ENCAP_CONTENT_INFO,
  17727. SIGNED_DATA_CERTIFICATES,
  17728. SIGNED_DATA_CRLS,
  17729. SIGNED_DATA_SIGNER_INFOS
  17730. ];
  17731. class SignedDataVerifyError extends Error {
  17732. constructor({ message, code = 0, date = new Date(), signatureVerified = null, signerCertificate = null, signerCertificateVerified = null, timestampSerial = null, certificatePath = [], }) {
  17733. super(message);
  17734. this.name = "SignedDataVerifyError";
  17735. this.date = date;
  17736. this.code = code;
  17737. this.timestampSerial = timestampSerial;
  17738. this.signatureVerified = signatureVerified;
  17739. this.signerCertificate = signerCertificate;
  17740. this.signerCertificateVerified = signerCertificateVerified;
  17741. this.certificatePath = certificatePath;
  17742. }
  17743. }
  17744. class SignedData extends PkiObject {
  17745. constructor(parameters = {}) {
  17746. super();
  17747. this.version = pvutils.getParametersValue(parameters, VERSION$2, SignedData.defaultValues(VERSION$2));
  17748. this.digestAlgorithms = pvutils.getParametersValue(parameters, DIGEST_ALGORITHMS, SignedData.defaultValues(DIGEST_ALGORITHMS));
  17749. this.encapContentInfo = pvutils.getParametersValue(parameters, ENCAP_CONTENT_INFO, SignedData.defaultValues(ENCAP_CONTENT_INFO));
  17750. if (CERTIFICATES in parameters) {
  17751. this.certificates = pvutils.getParametersValue(parameters, CERTIFICATES, SignedData.defaultValues(CERTIFICATES));
  17752. }
  17753. if (CRLS in parameters) {
  17754. this.crls = pvutils.getParametersValue(parameters, CRLS, SignedData.defaultValues(CRLS));
  17755. }
  17756. if (OCSPS in parameters) {
  17757. this.ocsps = pvutils.getParametersValue(parameters, OCSPS, SignedData.defaultValues(OCSPS));
  17758. }
  17759. this.signerInfos = pvutils.getParametersValue(parameters, SIGNER_INFOS, SignedData.defaultValues(SIGNER_INFOS));
  17760. if (parameters.schema) {
  17761. this.fromSchema(parameters.schema);
  17762. }
  17763. }
  17764. static defaultValues(memberName) {
  17765. switch (memberName) {
  17766. case VERSION$2:
  17767. return 0;
  17768. case DIGEST_ALGORITHMS:
  17769. return [];
  17770. case ENCAP_CONTENT_INFO:
  17771. return new EncapsulatedContentInfo();
  17772. case CERTIFICATES:
  17773. return [];
  17774. case CRLS:
  17775. return [];
  17776. case OCSPS:
  17777. return [];
  17778. case SIGNER_INFOS:
  17779. return [];
  17780. default:
  17781. return super.defaultValues(memberName);
  17782. }
  17783. }
  17784. static compareWithDefault(memberName, memberValue) {
  17785. switch (memberName) {
  17786. case VERSION$2:
  17787. return (memberValue === SignedData.defaultValues(VERSION$2));
  17788. case ENCAP_CONTENT_INFO:
  17789. return EncapsulatedContentInfo.compareWithDefault("eContentType", memberValue.eContentType) &&
  17790. EncapsulatedContentInfo.compareWithDefault("eContent", memberValue.eContent);
  17791. case DIGEST_ALGORITHMS:
  17792. case CERTIFICATES:
  17793. case CRLS:
  17794. case OCSPS:
  17795. case SIGNER_INFOS:
  17796. return (memberValue.length === 0);
  17797. default:
  17798. return super.defaultValues(memberName);
  17799. }
  17800. }
  17801. static schema(parameters = {}) {
  17802. const names = pvutils.getParametersValue(parameters, "names", {});
  17803. if (names.optional === undefined) {
  17804. names.optional = false;
  17805. }
  17806. return (new asn1js.Sequence({
  17807. name: (names.blockName || SIGNED_DATA),
  17808. optional: names.optional,
  17809. value: [
  17810. new asn1js.Integer({ name: (names.version || SIGNED_DATA_VERSION) }),
  17811. new asn1js.Set({
  17812. value: [
  17813. new asn1js.Repeated({
  17814. name: (names.digestAlgorithms || SIGNED_DATA_DIGEST_ALGORITHMS),
  17815. value: AlgorithmIdentifier.schema()
  17816. })
  17817. ]
  17818. }),
  17819. EncapsulatedContentInfo.schema(names.encapContentInfo || {
  17820. names: {
  17821. blockName: SIGNED_DATA_ENCAP_CONTENT_INFO
  17822. }
  17823. }),
  17824. new asn1js.Constructed({
  17825. name: (names.certificates || SIGNED_DATA_CERTIFICATES),
  17826. optional: true,
  17827. idBlock: {
  17828. tagClass: 3,
  17829. tagNumber: 0
  17830. },
  17831. value: CertificateSet.schema().valueBlock.value
  17832. }),
  17833. new asn1js.Constructed({
  17834. optional: true,
  17835. idBlock: {
  17836. tagClass: 3,
  17837. tagNumber: 1
  17838. },
  17839. value: RevocationInfoChoices.schema(names.crls || {
  17840. names: {
  17841. crls: SIGNED_DATA_CRLS
  17842. }
  17843. }).valueBlock.value
  17844. }),
  17845. new asn1js.Set({
  17846. value: [
  17847. new asn1js.Repeated({
  17848. name: (names.signerInfos || SIGNED_DATA_SIGNER_INFOS),
  17849. value: SignerInfo.schema()
  17850. })
  17851. ]
  17852. })
  17853. ]
  17854. }));
  17855. }
  17856. fromSchema(schema) {
  17857. pvutils.clearProps(schema, CLEAR_PROPS$3);
  17858. const asn1 = asn1js.compareSchema(schema, schema, SignedData.schema());
  17859. AsnError.assertSchema(asn1, this.className);
  17860. this.version = asn1.result[SIGNED_DATA_VERSION].valueBlock.valueDec;
  17861. if (SIGNED_DATA_DIGEST_ALGORITHMS in asn1.result)
  17862. this.digestAlgorithms = Array.from(asn1.result[SIGNED_DATA_DIGEST_ALGORITHMS], algorithm => new AlgorithmIdentifier({ schema: algorithm }));
  17863. this.encapContentInfo = new EncapsulatedContentInfo({ schema: asn1.result[SIGNED_DATA_ENCAP_CONTENT_INFO] });
  17864. if (SIGNED_DATA_CERTIFICATES in asn1.result) {
  17865. const certificateSet = new CertificateSet({
  17866. schema: new asn1js.Set({
  17867. value: asn1.result[SIGNED_DATA_CERTIFICATES].valueBlock.value
  17868. })
  17869. });
  17870. this.certificates = certificateSet.certificates.slice(0);
  17871. }
  17872. if (SIGNED_DATA_CRLS in asn1.result) {
  17873. this.crls = Array.from(asn1.result[SIGNED_DATA_CRLS], (crl) => {
  17874. if (crl.idBlock.tagClass === 1)
  17875. return new CertificateRevocationList({ schema: crl });
  17876. crl.idBlock.tagClass = 1;
  17877. crl.idBlock.tagNumber = 16;
  17878. return new OtherRevocationInfoFormat({ schema: crl });
  17879. });
  17880. }
  17881. if (SIGNED_DATA_SIGNER_INFOS in asn1.result)
  17882. this.signerInfos = Array.from(asn1.result[SIGNED_DATA_SIGNER_INFOS], signerInfoSchema => new SignerInfo({ schema: signerInfoSchema }));
  17883. }
  17884. toSchema(encodeFlag = false) {
  17885. const outputArray = [];
  17886. if ((this.certificates && this.certificates.length && this.certificates.some(o => o instanceof OtherCertificateFormat))
  17887. || (this.crls && this.crls.length && this.crls.some(o => o instanceof OtherRevocationInfoFormat))) {
  17888. this.version = 5;
  17889. }
  17890. else if (this.certificates && this.certificates.length && this.certificates.some(o => o instanceof AttributeCertificateV2)) {
  17891. this.version = 4;
  17892. }
  17893. else if ((this.certificates && this.certificates.length && this.certificates.some(o => o instanceof AttributeCertificateV1))
  17894. || this.signerInfos.some(o => o.version === 3)
  17895. || this.encapContentInfo.eContentType !== SignedData.ID_DATA) {
  17896. this.version = 3;
  17897. }
  17898. else {
  17899. this.version = 1;
  17900. }
  17901. outputArray.push(new asn1js.Integer({ value: this.version }));
  17902. outputArray.push(new asn1js.Set({
  17903. value: Array.from(this.digestAlgorithms, algorithm => algorithm.toSchema())
  17904. }));
  17905. outputArray.push(this.encapContentInfo.toSchema());
  17906. if (this.certificates) {
  17907. const certificateSet = new CertificateSet({ certificates: this.certificates });
  17908. const certificateSetSchema = certificateSet.toSchema();
  17909. outputArray.push(new asn1js.Constructed({
  17910. idBlock: {
  17911. tagClass: 3,
  17912. tagNumber: 0
  17913. },
  17914. value: certificateSetSchema.valueBlock.value
  17915. }));
  17916. }
  17917. if (this.crls) {
  17918. outputArray.push(new asn1js.Constructed({
  17919. idBlock: {
  17920. tagClass: 3,
  17921. tagNumber: 1
  17922. },
  17923. value: Array.from(this.crls, crl => {
  17924. if (crl instanceof OtherRevocationInfoFormat) {
  17925. const crlSchema = crl.toSchema();
  17926. crlSchema.idBlock.tagClass = 3;
  17927. crlSchema.idBlock.tagNumber = 1;
  17928. return crlSchema;
  17929. }
  17930. return crl.toSchema(encodeFlag);
  17931. })
  17932. }));
  17933. }
  17934. outputArray.push(new asn1js.Set({
  17935. value: Array.from(this.signerInfos, signerInfo => signerInfo.toSchema())
  17936. }));
  17937. return (new asn1js.Sequence({
  17938. value: outputArray
  17939. }));
  17940. }
  17941. toJSON() {
  17942. const res = {
  17943. version: this.version,
  17944. digestAlgorithms: Array.from(this.digestAlgorithms, algorithm => algorithm.toJSON()),
  17945. encapContentInfo: this.encapContentInfo.toJSON(),
  17946. signerInfos: Array.from(this.signerInfos, signerInfo => signerInfo.toJSON()),
  17947. };
  17948. if (this.certificates) {
  17949. res.certificates = Array.from(this.certificates, certificate => certificate.toJSON());
  17950. }
  17951. if (this.crls) {
  17952. res.crls = Array.from(this.crls, crl => crl.toJSON());
  17953. }
  17954. return res;
  17955. }
  17956. async verify({ signer = (-1), data = (EMPTY_BUFFER), trustedCerts = [], checkDate = (new Date()), checkChain = false, passedWhenNotRevValues = false, extendedMode = false, findOrigin = null, findIssuer = null } = {}, crypto = getCrypto(true)) {
  17957. let signerCert = null;
  17958. let timestampSerial = null;
  17959. try {
  17960. let messageDigestValue = EMPTY_BUFFER;
  17961. let shaAlgorithm = EMPTY_STRING;
  17962. let certificatePath = [];
  17963. const signerInfo = this.signerInfos[signer];
  17964. if (!signerInfo) {
  17965. throw new SignedDataVerifyError({
  17966. date: checkDate,
  17967. code: 1,
  17968. message: "Unable to get signer by supplied index",
  17969. });
  17970. }
  17971. if (!this.certificates) {
  17972. throw new SignedDataVerifyError({
  17973. date: checkDate,
  17974. code: 2,
  17975. message: "No certificates attached to this signed data",
  17976. });
  17977. }
  17978. if (signerInfo.sid instanceof IssuerAndSerialNumber) {
  17979. for (const certificate of this.certificates) {
  17980. if (!(certificate instanceof Certificate))
  17981. continue;
  17982. if ((certificate.issuer.isEqual(signerInfo.sid.issuer)) &&
  17983. (certificate.serialNumber.isEqual(signerInfo.sid.serialNumber))) {
  17984. signerCert = certificate;
  17985. break;
  17986. }
  17987. }
  17988. }
  17989. else {
  17990. const sid = signerInfo.sid;
  17991. const keyId = sid.idBlock.isConstructed
  17992. ? sid.valueBlock.value[0].valueBlock.valueHex
  17993. : sid.valueBlock.valueHex;
  17994. for (const certificate of this.certificates) {
  17995. if (!(certificate instanceof Certificate)) {
  17996. continue;
  17997. }
  17998. const digest = await crypto.digest({ name: "sha-1" }, certificate.subjectPublicKeyInfo.subjectPublicKey.valueBlock.valueHexView);
  17999. if (pvutils.isEqualBuffer(digest, keyId)) {
  18000. signerCert = certificate;
  18001. break;
  18002. }
  18003. }
  18004. }
  18005. if (!signerCert) {
  18006. throw new SignedDataVerifyError({
  18007. date: checkDate,
  18008. code: 3,
  18009. message: "Unable to find signer certificate",
  18010. });
  18011. }
  18012. if (this.encapContentInfo.eContentType === id_eContentType_TSTInfo) {
  18013. if (!this.encapContentInfo.eContent) {
  18014. throw new SignedDataVerifyError({
  18015. date: checkDate,
  18016. code: 15,
  18017. message: "Error during verification: TSTInfo eContent is empty",
  18018. signatureVerified: null,
  18019. signerCertificate: signerCert,
  18020. timestampSerial,
  18021. signerCertificateVerified: true
  18022. });
  18023. }
  18024. let tstInfo;
  18025. try {
  18026. tstInfo = TSTInfo.fromBER(this.encapContentInfo.eContent.valueBlock.valueHexView);
  18027. }
  18028. catch {
  18029. throw new SignedDataVerifyError({
  18030. date: checkDate,
  18031. code: 15,
  18032. message: "Error during verification: TSTInfo wrong ASN.1 schema ",
  18033. signatureVerified: null,
  18034. signerCertificate: signerCert,
  18035. timestampSerial,
  18036. signerCertificateVerified: true
  18037. });
  18038. }
  18039. checkDate = tstInfo.genTime;
  18040. timestampSerial = tstInfo.serialNumber.valueBlock.valueHexView.slice().buffer;
  18041. if (data.byteLength === 0) {
  18042. throw new SignedDataVerifyError({
  18043. date: checkDate,
  18044. code: 4,
  18045. message: "Missed detached data input array",
  18046. });
  18047. }
  18048. if (!(await tstInfo.verify({ data }, crypto))) {
  18049. throw new SignedDataVerifyError({
  18050. date: checkDate,
  18051. code: 15,
  18052. message: "Error during verification: TSTInfo verification is failed",
  18053. signatureVerified: false,
  18054. signerCertificate: signerCert,
  18055. timestampSerial,
  18056. signerCertificateVerified: true
  18057. });
  18058. }
  18059. }
  18060. if (checkChain) {
  18061. const certs = this.certificates.filter(certificate => (certificate instanceof Certificate && !!checkCA(certificate, signerCert)));
  18062. const chainParams = {
  18063. checkDate,
  18064. certs,
  18065. trustedCerts,
  18066. };
  18067. if (findIssuer) {
  18068. chainParams.findIssuer = findIssuer;
  18069. }
  18070. if (findOrigin) {
  18071. chainParams.findOrigin = findOrigin;
  18072. }
  18073. const chainEngine = new CertificateChainValidationEngine(chainParams);
  18074. chainEngine.certs.push(signerCert);
  18075. if (this.crls) {
  18076. for (const crl of this.crls) {
  18077. if ("thisUpdate" in crl)
  18078. chainEngine.crls.push(crl);
  18079. else {
  18080. if (crl.otherRevInfoFormat === id_PKIX_OCSP_Basic)
  18081. chainEngine.ocsps.push(new BasicOCSPResponse({ schema: crl.otherRevInfo }));
  18082. }
  18083. }
  18084. }
  18085. if (this.ocsps) {
  18086. chainEngine.ocsps.push(...(this.ocsps));
  18087. }
  18088. const verificationResult = await chainEngine.verify({ passedWhenNotRevValues }, crypto)
  18089. .catch(e => {
  18090. throw new SignedDataVerifyError({
  18091. date: checkDate,
  18092. code: 5,
  18093. message: `Validation of signer's certificate failed with error: ${((e instanceof Object) ? e.resultMessage : e)}`,
  18094. signerCertificate: signerCert,
  18095. signerCertificateVerified: false
  18096. });
  18097. });
  18098. if (verificationResult.certificatePath) {
  18099. certificatePath = verificationResult.certificatePath;
  18100. }
  18101. if (!verificationResult.result)
  18102. throw new SignedDataVerifyError({
  18103. date: checkDate,
  18104. code: 5,
  18105. message: `Validation of signer's certificate failed: ${verificationResult.resultMessage}`,
  18106. signerCertificate: signerCert,
  18107. signerCertificateVerified: false
  18108. });
  18109. }
  18110. const signerInfoHashAlgorithm = crypto.getAlgorithmByOID(signerInfo.digestAlgorithm.algorithmId);
  18111. if (!("name" in signerInfoHashAlgorithm)) {
  18112. throw new SignedDataVerifyError({
  18113. date: checkDate,
  18114. code: 7,
  18115. message: `Unsupported signature algorithm: ${signerInfo.digestAlgorithm.algorithmId}`,
  18116. signerCertificate: signerCert,
  18117. signerCertificateVerified: true
  18118. });
  18119. }
  18120. shaAlgorithm = signerInfoHashAlgorithm.name;
  18121. const eContent = this.encapContentInfo.eContent;
  18122. if (eContent) {
  18123. if ((eContent.idBlock.tagClass === 1) &&
  18124. (eContent.idBlock.tagNumber === 4)) {
  18125. data = eContent.getValue();
  18126. }
  18127. else
  18128. data = eContent.valueBlock.valueBeforeDecodeView.slice().buffer;
  18129. }
  18130. else {
  18131. if (data.byteLength === 0) {
  18132. throw new SignedDataVerifyError({
  18133. date: checkDate,
  18134. code: 8,
  18135. message: "Missed detached data input array",
  18136. signerCertificate: signerCert,
  18137. signerCertificateVerified: true
  18138. });
  18139. }
  18140. }
  18141. if (signerInfo.signedAttrs) {
  18142. let foundContentType = false;
  18143. let foundMessageDigest = false;
  18144. for (const attribute of signerInfo.signedAttrs.attributes) {
  18145. if (attribute.type === "1.2.840.113549.1.9.3")
  18146. foundContentType = true;
  18147. if (attribute.type === "1.2.840.113549.1.9.4") {
  18148. foundMessageDigest = true;
  18149. messageDigestValue = attribute.values[0].valueBlock.valueHex;
  18150. }
  18151. if (foundContentType && foundMessageDigest)
  18152. break;
  18153. }
  18154. if (foundContentType === false) {
  18155. throw new SignedDataVerifyError({
  18156. date: checkDate,
  18157. code: 9,
  18158. message: "Attribute \"content-type\" is a mandatory attribute for \"signed attributes\"",
  18159. signerCertificate: signerCert,
  18160. signerCertificateVerified: true
  18161. });
  18162. }
  18163. if (foundMessageDigest === false) {
  18164. throw new SignedDataVerifyError({
  18165. date: checkDate,
  18166. code: 10,
  18167. message: "Attribute \"message-digest\" is a mandatory attribute for \"signed attributes\"",
  18168. signatureVerified: null,
  18169. signerCertificate: signerCert,
  18170. signerCertificateVerified: true
  18171. });
  18172. }
  18173. }
  18174. if (signerInfo.signedAttrs) {
  18175. const messageDigest = await crypto.digest(shaAlgorithm, new Uint8Array(data));
  18176. if (!pvutils.isEqualBuffer(messageDigest, messageDigestValue)) {
  18177. throw new SignedDataVerifyError({
  18178. date: checkDate,
  18179. code: 15,
  18180. message: "Error during verification: Message digest doesn't match",
  18181. signatureVerified: null,
  18182. signerCertificate: signerCert,
  18183. timestampSerial,
  18184. signerCertificateVerified: true
  18185. });
  18186. }
  18187. data = signerInfo.signedAttrs.encodedValue;
  18188. }
  18189. const verifyResult = signerInfo.signatureAlgorithm.algorithmId === "1.2.840.113549.1.1.1"
  18190. ? await crypto.verifyWithPublicKey(data, signerInfo.signature, signerCert.subjectPublicKeyInfo, signerInfo.signatureAlgorithm, shaAlgorithm)
  18191. : await crypto.verifyWithPublicKey(data, signerInfo.signature, signerCert.subjectPublicKeyInfo, signerInfo.signatureAlgorithm);
  18192. if (extendedMode) {
  18193. return {
  18194. date: checkDate,
  18195. code: 14,
  18196. message: EMPTY_STRING,
  18197. signatureVerified: verifyResult,
  18198. signerCertificate: signerCert,
  18199. timestampSerial,
  18200. signerCertificateVerified: true,
  18201. certificatePath
  18202. };
  18203. }
  18204. else {
  18205. return verifyResult;
  18206. }
  18207. }
  18208. catch (e) {
  18209. if (e instanceof SignedDataVerifyError) {
  18210. throw e;
  18211. }
  18212. throw new SignedDataVerifyError({
  18213. date: checkDate,
  18214. code: 15,
  18215. message: `Error during verification: ${e instanceof Error ? e.message : e}`,
  18216. signatureVerified: null,
  18217. signerCertificate: signerCert,
  18218. timestampSerial,
  18219. signerCertificateVerified: true
  18220. });
  18221. }
  18222. }
  18223. async sign(privateKey, signerIndex, hashAlgorithm = "SHA-1", data = (EMPTY_BUFFER), crypto = getCrypto(true)) {
  18224. var _a;
  18225. if (!privateKey)
  18226. throw new Error("Need to provide a private key for signing");
  18227. const signerInfo = this.signerInfos[signerIndex];
  18228. if (!signerInfo) {
  18229. throw new RangeError("SignerInfo index is out of range");
  18230. }
  18231. if (!((_a = signerInfo.signedAttrs) === null || _a === void 0 ? void 0 : _a.attributes.length) && "hash" in privateKey.algorithm && "hash" in privateKey.algorithm && privateKey.algorithm.hash) {
  18232. hashAlgorithm = privateKey.algorithm.hash.name;
  18233. }
  18234. const hashAlgorithmOID = crypto.getOIDByAlgorithm({ name: hashAlgorithm }, true, "hashAlgorithm");
  18235. if ((this.digestAlgorithms.filter(algorithm => algorithm.algorithmId === hashAlgorithmOID)).length === 0) {
  18236. this.digestAlgorithms.push(new AlgorithmIdentifier({
  18237. algorithmId: hashAlgorithmOID,
  18238. algorithmParams: new asn1js.Null()
  18239. }));
  18240. }
  18241. signerInfo.digestAlgorithm = new AlgorithmIdentifier({
  18242. algorithmId: hashAlgorithmOID,
  18243. algorithmParams: new asn1js.Null()
  18244. });
  18245. const signatureParams = await crypto.getSignatureParameters(privateKey, hashAlgorithm);
  18246. const parameters = signatureParams.parameters;
  18247. signerInfo.signatureAlgorithm = signatureParams.signatureAlgorithm;
  18248. if (signerInfo.signedAttrs) {
  18249. if (signerInfo.signedAttrs.encodedValue.byteLength !== 0)
  18250. data = signerInfo.signedAttrs.encodedValue;
  18251. else {
  18252. data = signerInfo.signedAttrs.toSchema().toBER();
  18253. const view = pvtsutils.BufferSourceConverter.toUint8Array(data);
  18254. view[0] = 0x31;
  18255. }
  18256. }
  18257. else {
  18258. const eContent = this.encapContentInfo.eContent;
  18259. if (eContent) {
  18260. if ((eContent.idBlock.tagClass === 1) &&
  18261. (eContent.idBlock.tagNumber === 4)) {
  18262. data = eContent.getValue();
  18263. }
  18264. else
  18265. data = eContent.valueBlock.valueBeforeDecodeView.slice().buffer;
  18266. }
  18267. else {
  18268. if (data.byteLength === 0)
  18269. throw new Error("Missed detached data input array");
  18270. }
  18271. }
  18272. const signature = await crypto.signWithPrivateKey(data, privateKey, parameters);
  18273. signerInfo.signature = new asn1js.OctetString({ valueHex: signature });
  18274. }
  18275. }
  18276. SignedData.CLASS_NAME = "SignedData";
  18277. SignedData.ID_DATA = id_ContentType_Data;
  18278. const VERSION$1 = "version";
  18279. const AUTH_SAFE = "authSafe";
  18280. const MAC_DATA = "macData";
  18281. const PARSED_VALUE = "parsedValue";
  18282. const CLERA_PROPS = [
  18283. VERSION$1,
  18284. AUTH_SAFE,
  18285. MAC_DATA
  18286. ];
  18287. class PFX extends PkiObject {
  18288. constructor(parameters = {}) {
  18289. super();
  18290. this.version = pvutils.getParametersValue(parameters, VERSION$1, PFX.defaultValues(VERSION$1));
  18291. this.authSafe = pvutils.getParametersValue(parameters, AUTH_SAFE, PFX.defaultValues(AUTH_SAFE));
  18292. if (MAC_DATA in parameters) {
  18293. this.macData = pvutils.getParametersValue(parameters, MAC_DATA, PFX.defaultValues(MAC_DATA));
  18294. }
  18295. if (PARSED_VALUE in parameters) {
  18296. this.parsedValue = pvutils.getParametersValue(parameters, PARSED_VALUE, PFX.defaultValues(PARSED_VALUE));
  18297. }
  18298. if (parameters.schema) {
  18299. this.fromSchema(parameters.schema);
  18300. }
  18301. }
  18302. static defaultValues(memberName) {
  18303. switch (memberName) {
  18304. case VERSION$1:
  18305. return 3;
  18306. case AUTH_SAFE:
  18307. return (new ContentInfo());
  18308. case MAC_DATA:
  18309. return (new MacData());
  18310. case PARSED_VALUE:
  18311. return {};
  18312. default:
  18313. return super.defaultValues(memberName);
  18314. }
  18315. }
  18316. static compareWithDefault(memberName, memberValue) {
  18317. switch (memberName) {
  18318. case VERSION$1:
  18319. return (memberValue === PFX.defaultValues(memberName));
  18320. case AUTH_SAFE:
  18321. return ((ContentInfo.compareWithDefault("contentType", memberValue.contentType)) &&
  18322. (ContentInfo.compareWithDefault("content", memberValue.content)));
  18323. case MAC_DATA:
  18324. return ((MacData.compareWithDefault("mac", memberValue.mac)) &&
  18325. (MacData.compareWithDefault("macSalt", memberValue.macSalt)) &&
  18326. (MacData.compareWithDefault("iterations", memberValue.iterations)));
  18327. case PARSED_VALUE:
  18328. return ((memberValue instanceof Object) && (Object.keys(memberValue).length === 0));
  18329. default:
  18330. return super.defaultValues(memberName);
  18331. }
  18332. }
  18333. static schema(parameters = {}) {
  18334. const names = pvutils.getParametersValue(parameters, "names", {});
  18335. return (new asn1js.Sequence({
  18336. name: (names.blockName || EMPTY_STRING),
  18337. value: [
  18338. new asn1js.Integer({ name: (names.version || VERSION$1) }),
  18339. ContentInfo.schema(names.authSafe || {
  18340. names: {
  18341. blockName: AUTH_SAFE
  18342. }
  18343. }),
  18344. MacData.schema(names.macData || {
  18345. names: {
  18346. blockName: MAC_DATA,
  18347. optional: true
  18348. }
  18349. })
  18350. ]
  18351. }));
  18352. }
  18353. fromSchema(schema) {
  18354. pvutils.clearProps(schema, CLERA_PROPS);
  18355. const asn1 = asn1js.compareSchema(schema, schema, PFX.schema({
  18356. names: {
  18357. version: VERSION$1,
  18358. authSafe: {
  18359. names: {
  18360. blockName: AUTH_SAFE
  18361. }
  18362. },
  18363. macData: {
  18364. names: {
  18365. blockName: MAC_DATA
  18366. }
  18367. }
  18368. }
  18369. }));
  18370. AsnError.assertSchema(asn1, this.className);
  18371. this.version = asn1.result.version.valueBlock.valueDec;
  18372. this.authSafe = new ContentInfo({ schema: asn1.result.authSafe });
  18373. if (MAC_DATA in asn1.result)
  18374. this.macData = new MacData({ schema: asn1.result.macData });
  18375. }
  18376. toSchema() {
  18377. const outputArray = [
  18378. new asn1js.Integer({ value: this.version }),
  18379. this.authSafe.toSchema()
  18380. ];
  18381. if (this.macData) {
  18382. outputArray.push(this.macData.toSchema());
  18383. }
  18384. return (new asn1js.Sequence({
  18385. value: outputArray
  18386. }));
  18387. }
  18388. toJSON() {
  18389. const output = {
  18390. version: this.version,
  18391. authSafe: this.authSafe.toJSON()
  18392. };
  18393. if (this.macData) {
  18394. output.macData = this.macData.toJSON();
  18395. }
  18396. return output;
  18397. }
  18398. async makeInternalValues(parameters = {}, crypto = getCrypto(true)) {
  18399. ArgumentError.assert(parameters, "parameters", "object");
  18400. if (!this.parsedValue) {
  18401. throw new Error("Please call \"parseValues\" function first in order to make \"parsedValue\" data");
  18402. }
  18403. ParameterError.assertEmpty(this.parsedValue.integrityMode, "integrityMode", "parsedValue");
  18404. ParameterError.assertEmpty(this.parsedValue.authenticatedSafe, "authenticatedSafe", "parsedValue");
  18405. switch (this.parsedValue.integrityMode) {
  18406. case 0:
  18407. {
  18408. if (!("iterations" in parameters))
  18409. throw new ParameterError("iterations");
  18410. ParameterError.assertEmpty(parameters.pbkdf2HashAlgorithm, "pbkdf2HashAlgorithm");
  18411. ParameterError.assertEmpty(parameters.hmacHashAlgorithm, "hmacHashAlgorithm");
  18412. ParameterError.assertEmpty(parameters.password, "password");
  18413. const saltBuffer = new ArrayBuffer(64);
  18414. const saltView = new Uint8Array(saltBuffer);
  18415. crypto.getRandomValues(saltView);
  18416. const data = this.parsedValue.authenticatedSafe.toSchema().toBER(false);
  18417. this.authSafe = new ContentInfo({
  18418. contentType: ContentInfo.DATA,
  18419. content: new asn1js.OctetString({ valueHex: data })
  18420. });
  18421. const result = await crypto.stampDataWithPassword({
  18422. password: parameters.password,
  18423. hashAlgorithm: parameters.hmacHashAlgorithm,
  18424. salt: saltBuffer,
  18425. iterationCount: parameters.iterations,
  18426. contentToStamp: data
  18427. });
  18428. this.macData = new MacData({
  18429. mac: new DigestInfo({
  18430. digestAlgorithm: new AlgorithmIdentifier({
  18431. algorithmId: crypto.getOIDByAlgorithm({ name: parameters.hmacHashAlgorithm }, true, "hmacHashAlgorithm"),
  18432. }),
  18433. digest: new asn1js.OctetString({ valueHex: result })
  18434. }),
  18435. macSalt: new asn1js.OctetString({ valueHex: saltBuffer }),
  18436. iterations: parameters.iterations
  18437. });
  18438. }
  18439. break;
  18440. case 1:
  18441. {
  18442. if (!("signingCertificate" in parameters)) {
  18443. throw new ParameterError("signingCertificate");
  18444. }
  18445. ParameterError.assertEmpty(parameters.privateKey, "privateKey");
  18446. ParameterError.assertEmpty(parameters.hashAlgorithm, "hashAlgorithm");
  18447. const toBeSigned = this.parsedValue.authenticatedSafe.toSchema().toBER(false);
  18448. const cmsSigned = new SignedData({
  18449. version: 1,
  18450. encapContentInfo: new EncapsulatedContentInfo({
  18451. eContentType: "1.2.840.113549.1.7.1",
  18452. eContent: new asn1js.OctetString({ valueHex: toBeSigned })
  18453. }),
  18454. certificates: [parameters.signingCertificate]
  18455. });
  18456. const result = await crypto.digest({ name: parameters.hashAlgorithm }, new Uint8Array(toBeSigned));
  18457. const signedAttr = [];
  18458. signedAttr.push(new Attribute({
  18459. type: "1.2.840.113549.1.9.3",
  18460. values: [
  18461. new asn1js.ObjectIdentifier({ value: "1.2.840.113549.1.7.1" })
  18462. ]
  18463. }));
  18464. signedAttr.push(new Attribute({
  18465. type: "1.2.840.113549.1.9.5",
  18466. values: [
  18467. new asn1js.UTCTime({ valueDate: new Date() })
  18468. ]
  18469. }));
  18470. signedAttr.push(new Attribute({
  18471. type: "1.2.840.113549.1.9.4",
  18472. values: [
  18473. new asn1js.OctetString({ valueHex: result })
  18474. ]
  18475. }));
  18476. cmsSigned.signerInfos.push(new SignerInfo({
  18477. version: 1,
  18478. sid: new IssuerAndSerialNumber({
  18479. issuer: parameters.signingCertificate.issuer,
  18480. serialNumber: parameters.signingCertificate.serialNumber
  18481. }),
  18482. signedAttrs: new SignedAndUnsignedAttributes({
  18483. type: 0,
  18484. attributes: signedAttr
  18485. })
  18486. }));
  18487. await cmsSigned.sign(parameters.privateKey, 0, parameters.hashAlgorithm, undefined, crypto);
  18488. this.authSafe = new ContentInfo({
  18489. contentType: "1.2.840.113549.1.7.2",
  18490. content: cmsSigned.toSchema(true)
  18491. });
  18492. }
  18493. break;
  18494. default:
  18495. throw new Error(`Parameter "integrityMode" has unknown value: ${this.parsedValue.integrityMode}`);
  18496. }
  18497. }
  18498. async parseInternalValues(parameters, crypto = getCrypto(true)) {
  18499. ArgumentError.assert(parameters, "parameters", "object");
  18500. if (parameters.checkIntegrity === undefined) {
  18501. parameters.checkIntegrity = true;
  18502. }
  18503. this.parsedValue = {};
  18504. switch (this.authSafe.contentType) {
  18505. case ContentInfo.DATA:
  18506. {
  18507. ParameterError.assertEmpty(parameters.password, "password");
  18508. this.parsedValue.integrityMode = 0;
  18509. ArgumentError.assert(this.authSafe.content, "authSafe.content", asn1js.OctetString);
  18510. const authSafeContent = this.authSafe.content.getValue();
  18511. this.parsedValue.authenticatedSafe = AuthenticatedSafe.fromBER(authSafeContent);
  18512. if (parameters.checkIntegrity) {
  18513. if (!this.macData) {
  18514. throw new Error("Absent \"macData\" value, can not check PKCS#12 data integrity");
  18515. }
  18516. const hashAlgorithm = crypto.getAlgorithmByOID(this.macData.mac.digestAlgorithm.algorithmId, true, "digestAlgorithm");
  18517. const result = await crypto.verifyDataStampedWithPassword({
  18518. password: parameters.password,
  18519. hashAlgorithm: hashAlgorithm.name,
  18520. salt: BufferSourceConverter.toArrayBuffer(this.macData.macSalt.valueBlock.valueHexView),
  18521. iterationCount: this.macData.iterations || 1,
  18522. contentToVerify: authSafeContent,
  18523. signatureToVerify: BufferSourceConverter.toArrayBuffer(this.macData.mac.digest.valueBlock.valueHexView),
  18524. });
  18525. if (!result) {
  18526. throw new Error("Integrity for the PKCS#12 data is broken!");
  18527. }
  18528. }
  18529. }
  18530. break;
  18531. case ContentInfo.SIGNED_DATA:
  18532. {
  18533. this.parsedValue.integrityMode = 1;
  18534. const cmsSigned = new SignedData({ schema: this.authSafe.content });
  18535. const eContent = cmsSigned.encapContentInfo.eContent;
  18536. ParameterError.assert(eContent, "eContent", "cmsSigned.encapContentInfo");
  18537. ArgumentError.assert(eContent, "eContent", asn1js.OctetString);
  18538. const data = eContent.getValue();
  18539. this.parsedValue.authenticatedSafe = AuthenticatedSafe.fromBER(data);
  18540. const ok = await cmsSigned.verify({ signer: 0, checkChain: false }, crypto);
  18541. if (!ok) {
  18542. throw new Error("Integrity for the PKCS#12 data is broken!");
  18543. }
  18544. }
  18545. break;
  18546. default:
  18547. throw new Error(`Incorrect value for "this.authSafe.contentType": ${this.authSafe.contentType}`);
  18548. }
  18549. }
  18550. }
  18551. PFX.CLASS_NAME = "PFX";
  18552. const STATUS$1 = "status";
  18553. const STATUS_STRINGS = "statusStrings";
  18554. const FAIL_INFO = "failInfo";
  18555. const CLEAR_PROPS$2 = [
  18556. STATUS$1,
  18557. STATUS_STRINGS,
  18558. FAIL_INFO
  18559. ];
  18560. var PKIStatus;
  18561. (function (PKIStatus) {
  18562. PKIStatus[PKIStatus["granted"] = 0] = "granted";
  18563. PKIStatus[PKIStatus["grantedWithMods"] = 1] = "grantedWithMods";
  18564. PKIStatus[PKIStatus["rejection"] = 2] = "rejection";
  18565. PKIStatus[PKIStatus["waiting"] = 3] = "waiting";
  18566. PKIStatus[PKIStatus["revocationWarning"] = 4] = "revocationWarning";
  18567. PKIStatus[PKIStatus["revocationNotification"] = 5] = "revocationNotification";
  18568. })(PKIStatus || (PKIStatus = {}));
  18569. class PKIStatusInfo extends PkiObject {
  18570. constructor(parameters = {}) {
  18571. super();
  18572. this.status = pvutils.getParametersValue(parameters, STATUS$1, PKIStatusInfo.defaultValues(STATUS$1));
  18573. if (STATUS_STRINGS in parameters) {
  18574. this.statusStrings = pvutils.getParametersValue(parameters, STATUS_STRINGS, PKIStatusInfo.defaultValues(STATUS_STRINGS));
  18575. }
  18576. if (FAIL_INFO in parameters) {
  18577. this.failInfo = pvutils.getParametersValue(parameters, FAIL_INFO, PKIStatusInfo.defaultValues(FAIL_INFO));
  18578. }
  18579. if (parameters.schema) {
  18580. this.fromSchema(parameters.schema);
  18581. }
  18582. }
  18583. static defaultValues(memberName) {
  18584. switch (memberName) {
  18585. case STATUS$1:
  18586. return 2;
  18587. case STATUS_STRINGS:
  18588. return [];
  18589. case FAIL_INFO:
  18590. return new asn1js.BitString();
  18591. default:
  18592. return super.defaultValues(memberName);
  18593. }
  18594. }
  18595. static compareWithDefault(memberName, memberValue) {
  18596. switch (memberName) {
  18597. case STATUS$1:
  18598. return (memberValue === PKIStatusInfo.defaultValues(memberName));
  18599. case STATUS_STRINGS:
  18600. return (memberValue.length === 0);
  18601. case FAIL_INFO:
  18602. return (memberValue.isEqual(PKIStatusInfo.defaultValues(memberName)));
  18603. default:
  18604. return super.defaultValues(memberName);
  18605. }
  18606. }
  18607. static schema(parameters = {}) {
  18608. const names = pvutils.getParametersValue(parameters, "names", {});
  18609. return (new asn1js.Sequence({
  18610. name: (names.blockName || EMPTY_STRING),
  18611. value: [
  18612. new asn1js.Integer({ name: (names.status || EMPTY_STRING) }),
  18613. new asn1js.Sequence({
  18614. optional: true,
  18615. value: [
  18616. new asn1js.Repeated({
  18617. name: (names.statusStrings || EMPTY_STRING),
  18618. value: new asn1js.Utf8String()
  18619. })
  18620. ]
  18621. }),
  18622. new asn1js.BitString({
  18623. name: (names.failInfo || EMPTY_STRING),
  18624. optional: true
  18625. })
  18626. ]
  18627. }));
  18628. }
  18629. fromSchema(schema) {
  18630. pvutils.clearProps(schema, CLEAR_PROPS$2);
  18631. const asn1 = asn1js.compareSchema(schema, schema, PKIStatusInfo.schema({
  18632. names: {
  18633. status: STATUS$1,
  18634. statusStrings: STATUS_STRINGS,
  18635. failInfo: FAIL_INFO
  18636. }
  18637. }));
  18638. AsnError.assertSchema(asn1, this.className);
  18639. const _status = asn1.result.status;
  18640. if ((_status.valueBlock.isHexOnly === true) ||
  18641. (_status.valueBlock.valueDec < 0) ||
  18642. (_status.valueBlock.valueDec > 5))
  18643. throw new Error("PKIStatusInfo \"status\" has invalid value");
  18644. this.status = _status.valueBlock.valueDec;
  18645. if (STATUS_STRINGS in asn1.result)
  18646. this.statusStrings = asn1.result.statusStrings;
  18647. if (FAIL_INFO in asn1.result)
  18648. this.failInfo = asn1.result.failInfo;
  18649. }
  18650. toSchema() {
  18651. const outputArray = [];
  18652. outputArray.push(new asn1js.Integer({ value: this.status }));
  18653. if (this.statusStrings) {
  18654. outputArray.push(new asn1js.Sequence({
  18655. optional: true,
  18656. value: this.statusStrings
  18657. }));
  18658. }
  18659. if (this.failInfo) {
  18660. outputArray.push(this.failInfo);
  18661. }
  18662. return (new asn1js.Sequence({
  18663. value: outputArray
  18664. }));
  18665. }
  18666. toJSON() {
  18667. const res = {
  18668. status: this.status
  18669. };
  18670. if (this.statusStrings) {
  18671. res.statusStrings = Array.from(this.statusStrings, o => o.toJSON());
  18672. }
  18673. if (this.failInfo) {
  18674. res.failInfo = this.failInfo.toJSON();
  18675. }
  18676. return res;
  18677. }
  18678. }
  18679. PKIStatusInfo.CLASS_NAME = "PKIStatusInfo";
  18680. const VERSION = "version";
  18681. const MESSAGE_IMPRINT = "messageImprint";
  18682. const REQ_POLICY = "reqPolicy";
  18683. const NONCE = "nonce";
  18684. const CERT_REQ = "certReq";
  18685. const EXTENSIONS = "extensions";
  18686. const TIME_STAMP_REQ = "TimeStampReq";
  18687. const TIME_STAMP_REQ_VERSION = `${TIME_STAMP_REQ}.${VERSION}`;
  18688. const TIME_STAMP_REQ_MESSAGE_IMPRINT = `${TIME_STAMP_REQ}.${MESSAGE_IMPRINT}`;
  18689. const TIME_STAMP_REQ_POLICY = `${TIME_STAMP_REQ}.${REQ_POLICY}`;
  18690. const TIME_STAMP_REQ_NONCE = `${TIME_STAMP_REQ}.${NONCE}`;
  18691. const TIME_STAMP_REQ_CERT_REQ = `${TIME_STAMP_REQ}.${CERT_REQ}`;
  18692. const TIME_STAMP_REQ_EXTENSIONS = `${TIME_STAMP_REQ}.${EXTENSIONS}`;
  18693. const CLEAR_PROPS$1 = [
  18694. TIME_STAMP_REQ_VERSION,
  18695. TIME_STAMP_REQ_MESSAGE_IMPRINT,
  18696. TIME_STAMP_REQ_POLICY,
  18697. TIME_STAMP_REQ_NONCE,
  18698. TIME_STAMP_REQ_CERT_REQ,
  18699. TIME_STAMP_REQ_EXTENSIONS,
  18700. ];
  18701. class TimeStampReq extends PkiObject {
  18702. constructor(parameters = {}) {
  18703. super();
  18704. this.version = pvutils.getParametersValue(parameters, VERSION, TimeStampReq.defaultValues(VERSION));
  18705. this.messageImprint = pvutils.getParametersValue(parameters, MESSAGE_IMPRINT, TimeStampReq.defaultValues(MESSAGE_IMPRINT));
  18706. if (REQ_POLICY in parameters) {
  18707. this.reqPolicy = pvutils.getParametersValue(parameters, REQ_POLICY, TimeStampReq.defaultValues(REQ_POLICY));
  18708. }
  18709. if (NONCE in parameters) {
  18710. this.nonce = pvutils.getParametersValue(parameters, NONCE, TimeStampReq.defaultValues(NONCE));
  18711. }
  18712. if (CERT_REQ in parameters) {
  18713. this.certReq = pvutils.getParametersValue(parameters, CERT_REQ, TimeStampReq.defaultValues(CERT_REQ));
  18714. }
  18715. if (EXTENSIONS in parameters) {
  18716. this.extensions = pvutils.getParametersValue(parameters, EXTENSIONS, TimeStampReq.defaultValues(EXTENSIONS));
  18717. }
  18718. if (parameters.schema) {
  18719. this.fromSchema(parameters.schema);
  18720. }
  18721. }
  18722. static defaultValues(memberName) {
  18723. switch (memberName) {
  18724. case VERSION:
  18725. return 0;
  18726. case MESSAGE_IMPRINT:
  18727. return new MessageImprint();
  18728. case REQ_POLICY:
  18729. return EMPTY_STRING;
  18730. case NONCE:
  18731. return new asn1js.Integer();
  18732. case CERT_REQ:
  18733. return false;
  18734. case EXTENSIONS:
  18735. return [];
  18736. default:
  18737. return super.defaultValues(memberName);
  18738. }
  18739. }
  18740. static compareWithDefault(memberName, memberValue) {
  18741. switch (memberName) {
  18742. case VERSION:
  18743. case REQ_POLICY:
  18744. case CERT_REQ:
  18745. return (memberValue === TimeStampReq.defaultValues(memberName));
  18746. case MESSAGE_IMPRINT:
  18747. return ((MessageImprint.compareWithDefault("hashAlgorithm", memberValue.hashAlgorithm)) &&
  18748. (MessageImprint.compareWithDefault("hashedMessage", memberValue.hashedMessage)));
  18749. case NONCE:
  18750. return (memberValue.isEqual(TimeStampReq.defaultValues(memberName)));
  18751. case EXTENSIONS:
  18752. return (memberValue.length === 0);
  18753. default:
  18754. return super.defaultValues(memberName);
  18755. }
  18756. }
  18757. static schema(parameters = {}) {
  18758. const names = pvutils.getParametersValue(parameters, "names", {});
  18759. return (new asn1js.Sequence({
  18760. name: (names.blockName || TIME_STAMP_REQ),
  18761. value: [
  18762. new asn1js.Integer({ name: (names.version || TIME_STAMP_REQ_VERSION) }),
  18763. MessageImprint.schema(names.messageImprint || {
  18764. names: {
  18765. blockName: TIME_STAMP_REQ_MESSAGE_IMPRINT
  18766. }
  18767. }),
  18768. new asn1js.ObjectIdentifier({
  18769. name: (names.reqPolicy || TIME_STAMP_REQ_POLICY),
  18770. optional: true
  18771. }),
  18772. new asn1js.Integer({
  18773. name: (names.nonce || TIME_STAMP_REQ_NONCE),
  18774. optional: true
  18775. }),
  18776. new asn1js.Boolean({
  18777. name: (names.certReq || TIME_STAMP_REQ_CERT_REQ),
  18778. optional: true
  18779. }),
  18780. new asn1js.Constructed({
  18781. optional: true,
  18782. idBlock: {
  18783. tagClass: 3,
  18784. tagNumber: 0
  18785. },
  18786. value: [new asn1js.Repeated({
  18787. name: (names.extensions || TIME_STAMP_REQ_EXTENSIONS),
  18788. value: Extension.schema()
  18789. })]
  18790. })
  18791. ]
  18792. }));
  18793. }
  18794. fromSchema(schema) {
  18795. pvutils.clearProps(schema, CLEAR_PROPS$1);
  18796. const asn1 = asn1js.compareSchema(schema, schema, TimeStampReq.schema());
  18797. AsnError.assertSchema(asn1, this.className);
  18798. this.version = asn1.result[TIME_STAMP_REQ_VERSION].valueBlock.valueDec;
  18799. this.messageImprint = new MessageImprint({ schema: asn1.result[TIME_STAMP_REQ_MESSAGE_IMPRINT] });
  18800. if (TIME_STAMP_REQ_POLICY in asn1.result)
  18801. this.reqPolicy = asn1.result[TIME_STAMP_REQ_POLICY].valueBlock.toString();
  18802. if (TIME_STAMP_REQ_NONCE in asn1.result)
  18803. this.nonce = asn1.result[TIME_STAMP_REQ_NONCE];
  18804. if (TIME_STAMP_REQ_CERT_REQ in asn1.result)
  18805. this.certReq = asn1.result[TIME_STAMP_REQ_CERT_REQ].valueBlock.value;
  18806. if (TIME_STAMP_REQ_EXTENSIONS in asn1.result)
  18807. this.extensions = Array.from(asn1.result[TIME_STAMP_REQ_EXTENSIONS], element => new Extension({ schema: element }));
  18808. }
  18809. toSchema() {
  18810. const outputArray = [];
  18811. outputArray.push(new asn1js.Integer({ value: this.version }));
  18812. outputArray.push(this.messageImprint.toSchema());
  18813. if (this.reqPolicy)
  18814. outputArray.push(new asn1js.ObjectIdentifier({ value: this.reqPolicy }));
  18815. if (this.nonce)
  18816. outputArray.push(this.nonce);
  18817. if ((CERT_REQ in this) && (TimeStampReq.compareWithDefault(CERT_REQ, this.certReq) === false))
  18818. outputArray.push(new asn1js.Boolean({ value: this.certReq }));
  18819. if (this.extensions) {
  18820. outputArray.push(new asn1js.Constructed({
  18821. idBlock: {
  18822. tagClass: 3,
  18823. tagNumber: 0
  18824. },
  18825. value: Array.from(this.extensions, o => o.toSchema())
  18826. }));
  18827. }
  18828. return (new asn1js.Sequence({
  18829. value: outputArray
  18830. }));
  18831. }
  18832. toJSON() {
  18833. const res = {
  18834. version: this.version,
  18835. messageImprint: this.messageImprint.toJSON()
  18836. };
  18837. if (this.reqPolicy !== undefined)
  18838. res.reqPolicy = this.reqPolicy;
  18839. if (this.nonce !== undefined)
  18840. res.nonce = this.nonce.toJSON();
  18841. if ((this.certReq !== undefined) && (TimeStampReq.compareWithDefault(CERT_REQ, this.certReq) === false))
  18842. res.certReq = this.certReq;
  18843. if (this.extensions) {
  18844. res.extensions = Array.from(this.extensions, o => o.toJSON());
  18845. }
  18846. return res;
  18847. }
  18848. }
  18849. TimeStampReq.CLASS_NAME = "TimeStampReq";
  18850. const STATUS = "status";
  18851. const TIME_STAMP_TOKEN = "timeStampToken";
  18852. const TIME_STAMP_RESP = "TimeStampResp";
  18853. const TIME_STAMP_RESP_STATUS = `${TIME_STAMP_RESP}.${STATUS}`;
  18854. const TIME_STAMP_RESP_TOKEN = `${TIME_STAMP_RESP}.${TIME_STAMP_TOKEN}`;
  18855. const CLEAR_PROPS = [
  18856. TIME_STAMP_RESP_STATUS,
  18857. TIME_STAMP_RESP_TOKEN
  18858. ];
  18859. class TimeStampResp extends PkiObject {
  18860. constructor(parameters = {}) {
  18861. super();
  18862. this.status = pvutils.getParametersValue(parameters, STATUS, TimeStampResp.defaultValues(STATUS));
  18863. if (TIME_STAMP_TOKEN in parameters) {
  18864. this.timeStampToken = pvutils.getParametersValue(parameters, TIME_STAMP_TOKEN, TimeStampResp.defaultValues(TIME_STAMP_TOKEN));
  18865. }
  18866. if (parameters.schema) {
  18867. this.fromSchema(parameters.schema);
  18868. }
  18869. }
  18870. static defaultValues(memberName) {
  18871. switch (memberName) {
  18872. case STATUS:
  18873. return new PKIStatusInfo();
  18874. case TIME_STAMP_TOKEN:
  18875. return new ContentInfo();
  18876. default:
  18877. return super.defaultValues(memberName);
  18878. }
  18879. }
  18880. static compareWithDefault(memberName, memberValue) {
  18881. switch (memberName) {
  18882. case STATUS:
  18883. return ((PKIStatusInfo.compareWithDefault(STATUS, memberValue.status)) &&
  18884. (("statusStrings" in memberValue) === false) &&
  18885. (("failInfo" in memberValue) === false));
  18886. case TIME_STAMP_TOKEN:
  18887. return ((memberValue.contentType === EMPTY_STRING) &&
  18888. (memberValue.content instanceof asn1js.Any));
  18889. default:
  18890. return super.defaultValues(memberName);
  18891. }
  18892. }
  18893. static schema(parameters = {}) {
  18894. const names = pvutils.getParametersValue(parameters, "names", {});
  18895. return (new asn1js.Sequence({
  18896. name: (names.blockName || TIME_STAMP_RESP),
  18897. value: [
  18898. PKIStatusInfo.schema(names.status || {
  18899. names: {
  18900. blockName: TIME_STAMP_RESP_STATUS
  18901. }
  18902. }),
  18903. ContentInfo.schema(names.timeStampToken || {
  18904. names: {
  18905. blockName: TIME_STAMP_RESP_TOKEN,
  18906. optional: true
  18907. }
  18908. })
  18909. ]
  18910. }));
  18911. }
  18912. fromSchema(schema) {
  18913. pvutils.clearProps(schema, CLEAR_PROPS);
  18914. const asn1 = asn1js.compareSchema(schema, schema, TimeStampResp.schema());
  18915. AsnError.assertSchema(asn1, this.className);
  18916. this.status = new PKIStatusInfo({ schema: asn1.result[TIME_STAMP_RESP_STATUS] });
  18917. if (TIME_STAMP_RESP_TOKEN in asn1.result)
  18918. this.timeStampToken = new ContentInfo({ schema: asn1.result[TIME_STAMP_RESP_TOKEN] });
  18919. }
  18920. toSchema() {
  18921. const outputArray = [];
  18922. outputArray.push(this.status.toSchema());
  18923. if (this.timeStampToken) {
  18924. outputArray.push(this.timeStampToken.toSchema());
  18925. }
  18926. return (new asn1js.Sequence({
  18927. value: outputArray
  18928. }));
  18929. }
  18930. toJSON() {
  18931. const res = {
  18932. status: this.status.toJSON()
  18933. };
  18934. if (this.timeStampToken) {
  18935. res.timeStampToken = this.timeStampToken.toJSON();
  18936. }
  18937. return res;
  18938. }
  18939. async sign(privateKey, hashAlgorithm, crypto = getCrypto(true)) {
  18940. this.assertContentType();
  18941. const signed = new SignedData({ schema: this.timeStampToken.content });
  18942. return signed.sign(privateKey, 0, hashAlgorithm, undefined, crypto);
  18943. }
  18944. async verify(verificationParameters = { signer: 0, trustedCerts: [], data: EMPTY_BUFFER }, crypto = getCrypto(true)) {
  18945. this.assertContentType();
  18946. const signed = new SignedData({ schema: this.timeStampToken.content });
  18947. return signed.verify(verificationParameters, crypto);
  18948. }
  18949. assertContentType() {
  18950. if (!this.timeStampToken) {
  18951. throw new Error("timeStampToken is absent in TSP response");
  18952. }
  18953. if (this.timeStampToken.contentType !== id_ContentType_SignedData) {
  18954. throw new Error(`Wrong format of timeStampToken: ${this.timeStampToken.contentType}`);
  18955. }
  18956. }
  18957. }
  18958. TimeStampResp.CLASS_NAME = "TimeStampResp";
  18959. function initCryptoEngine() {
  18960. if (typeof globalThis !== "undefined" && "crypto" in globalThis) {
  18961. let engineName = "webcrypto";
  18962. if ("webkitSubtle" in globalThis.crypto) {
  18963. engineName = "safari";
  18964. }
  18965. setEngine(engineName, new CryptoEngine({ name: engineName, crypto: globalThis.crypto }));
  18966. }
  18967. else if (typeof crypto !== "undefined" && "webcrypto" in crypto) {
  18968. const name = "NodeJS ^15";
  18969. const nodeCrypto = crypto.webcrypto;
  18970. setEngine(name, new CryptoEngine({ name, crypto: nodeCrypto }));
  18971. }
  18972. }
  18973. initCryptoEngine();
  18974. export { AbstractCryptoEngine, AccessDescription, Accuracy, AlgorithmIdentifier, AltName, ArgumentError, AsnError, AttCertValidityPeriod, Attribute, AttributeCertificateInfoV1, AttributeCertificateInfoV2, AttributeCertificateV1, AttributeCertificateV2, AttributeTypeAndValue, AuthenticatedSafe, AuthorityKeyIdentifier, BasicConstraints, BasicOCSPResponse, CAVersion, CRLBag, CRLDistributionPoints, CertBag, CertID, Certificate, CertificateChainValidationEngine, CertificatePolicies, CertificateRevocationList, CertificateSet, CertificateTemplate, CertificationRequest, ChainValidationCode, ChainValidationError, ContentInfo, CryptoEngine, DigestInfo, DistributionPoint, ECCCMSSharedInfo, ECNamedCurves, ECPrivateKey, ECPublicKey, EncapsulatedContentInfo, EncryptedContentInfo, EncryptedData, EnvelopedData, ExtKeyUsage, Extension, ExtensionValueFactory, Extensions, GeneralName, GeneralNames, GeneralSubtree, HASHED_MESSAGE, HASH_ALGORITHM, Holder, InfoAccess, IssuerAndSerialNumber, IssuerSerial, IssuingDistributionPoint, KEKIdentifier, KEKRecipientInfo, KeyAgreeRecipientIdentifier, KeyAgreeRecipientInfo, KeyBag, KeyTransRecipientInfo, MICROS, MILLIS, MacData, MessageImprint, NameConstraints, OCSPRequest, OCSPResponse, ObjectDigestInfo, OriginatorIdentifierOrKey, OriginatorInfo, OriginatorPublicKey, OtherCertificateFormat, OtherKeyAttribute, OtherPrimeInfo, OtherRecipientInfo, OtherRevocationInfoFormat, PBES2Params, PBKDF2Params, PFX, PKCS8ShroudedKeyBag, PKIStatus, PKIStatusInfo, POLICY_IDENTIFIER, POLICY_QUALIFIERS, ParameterError, PasswordRecipientinfo, PkiObject, PolicyConstraints, PolicyInformation, PolicyMapping, PolicyMappings, PolicyQualifierInfo, PrivateKeyInfo, PrivateKeyUsagePeriod, PublicKeyInfo, QCStatement, QCStatements, RDN, RSAESOAEPParams, RSAPrivateKey, RSAPublicKey, RSASSAPSSParams, RecipientEncryptedKey, RecipientEncryptedKeys, RecipientIdentifier, RecipientInfo, RecipientKeyIdentifier, RelativeDistinguishedNames, Request, ResponseBytes, ResponseData, RevocationInfoChoices, RevokedCertificate, SECONDS, SafeBag, SafeBagValueFactory, SafeContents, SecretBag, Signature, SignedAndUnsignedAttributes, SignedCertificateTimestamp, SignedCertificateTimestampList, SignedData, SignedDataVerifyError, SignerInfo, SingleResponse, SubjectDirectoryAttributes, TBSRequest, TSTInfo, TYPE$4 as TYPE, TYPE_AND_VALUES, Time, TimeStampReq, TimeStampResp, TimeType, V2Form, VALUE$5 as VALUE, VALUE_BEFORE_DECODE, checkCA, createCMSECDSASignature, createECDSASignatureFromCMS, engine, getAlgorithmByOID, getAlgorithmParameters, getCrypto, getEngine, getHashAlgorithm, getOIDByAlgorithm, getRandomValues, id_AnyPolicy, id_AuthorityInfoAccess, id_AuthorityKeyIdentifier, id_BaseCRLNumber, id_BasicConstraints, id_CRLBag_X509CRL, id_CRLDistributionPoints, id_CRLNumber, id_CRLReason, id_CertBag_AttributeCertificate, id_CertBag_SDSICertificate, id_CertBag_X509Certificate, id_CertificateIssuer, id_CertificatePolicies, id_ContentType_Data, id_ContentType_EncryptedData, id_ContentType_EnvelopedData, id_ContentType_SignedData, id_ExtKeyUsage, id_FreshestCRL, id_InhibitAnyPolicy, id_InvalidityDate, id_IssuerAltName, id_IssuingDistributionPoint, id_KeyUsage, id_MicrosoftAppPolicies, id_MicrosoftCaVersion, id_MicrosoftCertTemplateV1, id_MicrosoftCertTemplateV2, id_MicrosoftPrevCaCertHash, id_NameConstraints, id_PKIX_OCSP_Basic, id_PolicyConstraints, id_PolicyMappings, id_PrivateKeyUsagePeriod, id_QCStatements, id_SignedCertificateTimestampList, id_SubjectAltName, id_SubjectDirectoryAttributes, id_SubjectInfoAccess, id_SubjectKeyIdentifier, id_ad, id_ad_caIssuers, id_ad_ocsp, id_eContentType_TSTInfo, id_pkix, id_sha1, id_sha256, id_sha384, id_sha512, kdf, setEngine, stringPrep, verifySCTsForCertificate };