codekingpro/portable-devtools
114k
1#2# This file is part of pyasn1-modules software.3#4# Created by Russ Housley with assistance from asn1ate v.0.6.0.5# Modified by Russ Housley to add WithComponentsConstraints to6# enforce the requirements that are indicated in comments.7#8# Copyright (c) 2019, Vigil Security, LLC9# License: http://snmplabs.com/pyasn1/license.html10#11# Qualified Certificates12#13# ASN.1 source from:14# https://www.rfc-editor.org/rfc/rfc3739.txt15#16 17from pyasn1.type import char18from pyasn1.type import constraint19from pyasn1.type import namedtype20from pyasn1.type import namedval21from pyasn1.type import opentype22from pyasn1.type import univ23from pyasn1.type import useful24 25from pyasn1_modules import rfc528026 27MAX = float('inf')28 29 30# Initialize the qcStatement map31 32qcStatementMap = { }33 34 35# Imports from RFC 528036 37AlgorithmIdentifier = rfc5280.AlgorithmIdentifier38 39AttributeType = rfc5280.AttributeType40 41DirectoryString = rfc5280.DirectoryString42 43GeneralName = rfc5280.GeneralName44 45id_pkix = rfc5280.id_pkix46 47id_pe = rfc5280.id_pe48 49 50# Arc for QC personal data attributes51 52id_pda = id_pkix + (9, )53 54 55# Arc for QC statements56 57id_qcs = id_pkix + (11, )58 59 60# Personal data attributes61 62id_pda_dateOfBirth = id_pda + (1, )63 64class DateOfBirth(useful.GeneralizedTime):65 pass66 67 68id_pda_placeOfBirth = id_pda + (2, )69 70class PlaceOfBirth(DirectoryString):71 pass72 73 74id_pda_gender = id_pda + (3, )75 76class Gender(char.PrintableString):77 subtypeSpec = constraint.ConstraintsIntersection(78 constraint.ValueSizeConstraint(1, 1),79 constraint.SingleValueConstraint('M', 'F', 'm', 'f')80 )81 82 83id_pda_countryOfCitizenship = id_pda + (4, )84 85class CountryOfCitizenship(char.PrintableString):86 subtypeSpec = constraint.ValueSizeConstraint(2, 2)87 # ISO 3166 Country Code88 89 90id_pda_countryOfResidence = id_pda + (5, )91 92class CountryOfResidence(char.PrintableString):93 subtypeSpec = constraint.ValueSizeConstraint(2, 2)94 # ISO 3166 Country Code95 96 97# Biometric info certificate extension98 99id_pe_biometricInfo = id_pe + (2, )100 101 102class PredefinedBiometricType(univ.Integer):103 namedValues = namedval.NamedValues(104 ('picture', 0),105 ('handwritten-signature', 1)106 )107 subtypeSpec = constraint.SingleValueConstraint(0, 1)108 109 110class TypeOfBiometricData(univ.Choice):111 componentType = namedtype.NamedTypes(112 namedtype.NamedType('predefinedBiometricType', PredefinedBiometricType()),113 namedtype.NamedType('biometricDataOid', univ.ObjectIdentifier())114 )115 116 117class BiometricData(univ.Sequence):118 componentType = namedtype.NamedTypes(119 namedtype.NamedType('typeOfBiometricData', TypeOfBiometricData()),120 namedtype.NamedType('hashAlgorithm', AlgorithmIdentifier()),121 namedtype.NamedType('biometricDataHash', univ.OctetString()),122 namedtype.OptionalNamedType('sourceDataUri', char.IA5String())123 )124 125 126class BiometricSyntax(univ.SequenceOf):127 componentType = BiometricData()128 129 130# QC Statements certificate extension131# NOTE: This extension does not allow to mix critical and132# non-critical Qualified Certificate Statements. Either all133# statements must be critical or all statements must be134# non-critical.135 136id_pe_qcStatements = id_pe + (3, )137 138 139class NameRegistrationAuthorities(univ.SequenceOf):140 componentType = GeneralName()141 subtypeSpec=constraint.ValueSizeConstraint(1, MAX)142 143 144class QCStatement(univ.Sequence):145 componentType = namedtype.NamedTypes(146 namedtype.NamedType('statementId', univ.ObjectIdentifier()),147 namedtype.OptionalNamedType('statementInfo', univ.Any(),148 openType=opentype.OpenType('statementId', qcStatementMap))149 )150 151 152class QCStatements(univ.SequenceOf):153 componentType = QCStatement()154 155 156class SemanticsInformation(univ.Sequence):157 componentType = namedtype.NamedTypes(158 namedtype.OptionalNamedType('semanticsIndentifier',159 univ.ObjectIdentifier()),160 namedtype.OptionalNamedType('nameRegistrationAuthorities',161 NameRegistrationAuthorities())162 )163 subtypeSpec = constraint.ConstraintsUnion(164 constraint.WithComponentsConstraint(165 ('semanticsIndentifier', constraint.ComponentPresentConstraint())),166 constraint.WithComponentsConstraint(167 ('nameRegistrationAuthorities', constraint.ComponentPresentConstraint()))168 )169 170 171id_qcs = id_pkix + (11, )172 173 174id_qcs_pkixQCSyntax_v1 = id_qcs + (1, )175 176 177id_qcs_pkixQCSyntax_v2 = id_qcs + (2, )178 179 180# Map of Certificate Extension OIDs to Extensions181# To be added to the ones that are in rfc5280.py182 183_certificateExtensionsMap = {184 id_pe_biometricInfo: BiometricSyntax(),185 id_pe_qcStatements: QCStatements(),186}187 188rfc5280.certificateExtensionsMap.update(_certificateExtensionsMap)189 190 191# Map of AttributeType OIDs to AttributeValue added to the192# ones that are in rfc5280.py193 194_certificateAttributesMapUpdate = {195 id_pda_dateOfBirth: DateOfBirth(),196 id_pda_placeOfBirth: PlaceOfBirth(),197 id_pda_gender: Gender(),198 id_pda_countryOfCitizenship: CountryOfCitizenship(),199 id_pda_countryOfResidence: CountryOfResidence(),200}201 202rfc5280.certificateAttributesMap.update(_certificateAttributesMapUpdate)203 204 