Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes14kdownloads
rfc6960.py224 linesDownload Raw Back to pyasn1_modules
1#2# This file is part of pyasn1-modules software.3#4# Created by Russ Housley.5#6# Copyright (c) 2019, Vigil Security, LLC7# License: http://snmplabs.com/pyasn1/license.html8#9# Online Certificate Status Protocol (OCSP)10#11# ASN.1 source from:12# https://www.rfc-editor.org/rfc/rfc6960.txt13#14 15from pyasn1.type import univ, char, namedtype, namedval, tag, constraint, useful16 17from pyasn1_modules import rfc256018from pyasn1_modules import rfc528019 20MAX = float('inf')21 22 23# Imports from RFC 528024 25AlgorithmIdentifier = rfc5280.AlgorithmIdentifier26AuthorityInfoAccessSyntax = rfc5280.AuthorityInfoAccessSyntax27Certificate = rfc5280.Certificate28CertificateSerialNumber = rfc5280.CertificateSerialNumber29CRLReason = rfc5280.CRLReason30Extensions = rfc5280.Extensions31GeneralName = rfc5280.GeneralName32Name = rfc5280.Name33 34id_kp = rfc5280.id_kp35 36id_ad_ocsp = rfc5280.id_ad_ocsp37 38 39# Imports from the original OCSP module in RFC 256040 41AcceptableResponses = rfc2560.AcceptableResponses42ArchiveCutoff = rfc2560.ArchiveCutoff43CertStatus = rfc2560.CertStatus44KeyHash = rfc2560.KeyHash45OCSPResponse = rfc2560.OCSPResponse46OCSPResponseStatus = rfc2560.OCSPResponseStatus47ResponseBytes = rfc2560.ResponseBytes48RevokedInfo = rfc2560.RevokedInfo49UnknownInfo = rfc2560.UnknownInfo50Version = rfc2560.Version51 52id_kp_OCSPSigning = rfc2560.id_kp_OCSPSigning53 54id_pkix_ocsp = rfc2560.id_pkix_ocsp55id_pkix_ocsp_archive_cutoff = rfc2560.id_pkix_ocsp_archive_cutoff56id_pkix_ocsp_basic = rfc2560.id_pkix_ocsp_basic57id_pkix_ocsp_crl = rfc2560.id_pkix_ocsp_crl58id_pkix_ocsp_nocheck = rfc2560.id_pkix_ocsp_nocheck59id_pkix_ocsp_nonce = rfc2560.id_pkix_ocsp_nonce60id_pkix_ocsp_response = rfc2560.id_pkix_ocsp_response61id_pkix_ocsp_service_locator = rfc2560.id_pkix_ocsp_service_locator62 63 64# Additional object identifiers65 66id_pkix_ocsp_pref_sig_algs = id_pkix_ocsp + (8, )67id_pkix_ocsp_extended_revoke = id_pkix_ocsp + (9, )68 69 70# Updated structures (mostly to improve openTypes support)71 72class CertID(univ.Sequence):73    componentType = namedtype.NamedTypes(74        namedtype.NamedType('hashAlgorithm', AlgorithmIdentifier()),75        namedtype.NamedType('issuerNameHash', univ.OctetString()),76        namedtype.NamedType('issuerKeyHash', univ.OctetString()),77        namedtype.NamedType('serialNumber', CertificateSerialNumber())78    )79 80 81class SingleResponse(univ.Sequence):82    componentType = namedtype.NamedTypes(83        namedtype.NamedType('certID', CertID()),84        namedtype.NamedType('certStatus', CertStatus()),85        namedtype.NamedType('thisUpdate', useful.GeneralizedTime()),86        namedtype.OptionalNamedType('nextUpdate', useful.GeneralizedTime().subtype(87            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),88        namedtype.OptionalNamedType('singleExtensions', Extensions().subtype(89            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1)))90    )91 92 93class ResponderID(univ.Choice):94    componentType = namedtype.NamedTypes(95        namedtype.NamedType('byName', Name().subtype(96            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),97        namedtype.NamedType('byKey', KeyHash().subtype(98            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2)))99    )100 101 102class ResponseData(univ.Sequence):103    componentType = namedtype.NamedTypes(104        namedtype.DefaultedNamedType('version', Version('v1').subtype(105            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),106        namedtype.NamedType('responderID', ResponderID()),107        namedtype.NamedType('producedAt', useful.GeneralizedTime()),108        namedtype.NamedType('responses', univ.SequenceOf(109            componentType=SingleResponse())),110        namedtype.OptionalNamedType('responseExtensions', Extensions().subtype(111            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1)))112    )113 114 115class BasicOCSPResponse(univ.Sequence):116    componentType = namedtype.NamedTypes(117        namedtype.NamedType('tbsResponseData', ResponseData()),118        namedtype.NamedType('signatureAlgorithm', AlgorithmIdentifier()),119        namedtype.NamedType('signature', univ.BitString()),120        namedtype.OptionalNamedType('certs', univ.SequenceOf(121            componentType=Certificate()).subtype(explicitTag=tag.Tag(122                tag.tagClassContext, tag.tagFormatSimple, 0)))123    )124 125 126class Request(univ.Sequence):127    componentType = namedtype.NamedTypes(128        namedtype.NamedType('reqCert', CertID()),129        namedtype.OptionalNamedType('singleRequestExtensions', Extensions().subtype(130            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0)))131    )132 133 134class Signature(univ.Sequence):135    componentType = namedtype.NamedTypes(136        namedtype.NamedType('signatureAlgorithm', AlgorithmIdentifier()),137        namedtype.NamedType('signature', univ.BitString()),138        namedtype.OptionalNamedType('certs', univ.SequenceOf(139            componentType=Certificate()).subtype(explicitTag=tag.Tag(140                tag.tagClassContext, tag.tagFormatSimple, 0)))141    )142 143 144class TBSRequest(univ.Sequence):145    componentType = namedtype.NamedTypes(146        namedtype.DefaultedNamedType('version', Version('v1').subtype(147            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),148        namedtype.OptionalNamedType('requestorName', GeneralName().subtype(149            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),150        namedtype.NamedType('requestList', univ.SequenceOf(151            componentType=Request())),152        namedtype.OptionalNamedType('requestExtensions', Extensions().subtype(153            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2)))154    )155 156 157class OCSPRequest(univ.Sequence):158    componentType = namedtype.NamedTypes(159        namedtype.NamedType('tbsRequest', TBSRequest()),160        namedtype.OptionalNamedType('optionalSignature', Signature().subtype(161            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0)))162    )163 164 165# Previously omitted structure166 167class ServiceLocator(univ.Sequence):168    componentType = namedtype.NamedTypes(169        namedtype.NamedType('issuer', Name()),170        namedtype.NamedType('locator', AuthorityInfoAccessSyntax())171    )172 173 174# Additional structures175 176class CrlID(univ.Sequence):177    componentType = namedtype.NamedTypes(178        namedtype.OptionalNamedType('crlUrl', char.IA5String().subtype(179            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 0))),180        namedtype.OptionalNamedType('crlNum', univ.Integer().subtype(181            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))),182        namedtype.OptionalNamedType('crlTime', useful.GeneralizedTime().subtype(183            explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 2)))184    )185 186 187class PreferredSignatureAlgorithm(univ.Sequence):188    componentType = namedtype.NamedTypes(189        namedtype.NamedType('sigIdentifier', AlgorithmIdentifier()),190        namedtype.OptionalNamedType('certIdentifier', AlgorithmIdentifier())191    )192 193 194class PreferredSignatureAlgorithms(univ.SequenceOf):195    componentType = PreferredSignatureAlgorithm()196 197 198 199# Response Type OID to Response Map200 201ocspResponseMap = {202    id_pkix_ocsp_basic: BasicOCSPResponse(),203}204 205 206# Map of Extension OIDs to Extensions added to the ones207# that are in rfc5280.py208 209_certificateExtensionsMapUpdate = {210    # Certificate Extension211    id_pkix_ocsp_nocheck: univ.Null(""),212    # OCSP Request Extensions213    id_pkix_ocsp_nonce: univ.OctetString(),214    id_pkix_ocsp_response: AcceptableResponses(),215    id_pkix_ocsp_service_locator: ServiceLocator(),216    id_pkix_ocsp_pref_sig_algs: PreferredSignatureAlgorithms(),217    # OCSP Response Extensions218    id_pkix_ocsp_crl: CrlID(),219    id_pkix_ocsp_archive_cutoff: ArchiveCutoff(),220    id_pkix_ocsp_extended_revoke: univ.Null(""),221}222 223rfc5280.certificateExtensionsMap.update(_certificateExtensionsMapUpdate)224 
codekingpro/portable-devtools · Team Ai