2025-07-07 11:25:58 -04:00
|
|
|
package varsig
|
|
|
|
|
|
|
|
|
|
import (
|
|
|
|
|
"encoding/binary"
|
|
|
|
|
)
|
|
|
|
|
|
2025-07-10 11:24:14 +02:00
|
|
|
// DiscriminatorRSA is the value specifying an RSA signature.
|
|
|
|
|
const DiscriminatorRSA = Discriminator(0x1205)
|
2025-07-07 11:25:58 -04:00
|
|
|
|
2025-07-08 18:38:23 +02:00
|
|
|
var _ Varsig = RSAVarsig{}
|
2025-07-07 11:25:58 -04:00
|
|
|
|
|
|
|
|
// RSAVarsig is a varsig that encodes the parameters required to describe
|
2025-07-08 07:34:57 -04:00
|
|
|
// an RSA signature.
|
2025-07-07 11:25:58 -04:00
|
|
|
type RSAVarsig struct {
|
2025-07-08 18:38:23 +02:00
|
|
|
varsig
|
2025-07-07 11:25:58 -04:00
|
|
|
hashAlg HashAlgorithm
|
|
|
|
|
sigLen uint64
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// NewRSAVarsig creates and validates an RSA varsig with the provided
|
2025-07-08 07:34:57 -04:00
|
|
|
// hash algorithm, key length and payload encoding.
|
2025-07-08 18:38:23 +02:00
|
|
|
func NewRSAVarsig(hashAlgorithm HashAlgorithm, keyLength uint64, payloadEncoding PayloadEncoding, opts ...Option) (RSAVarsig, error) {
|
2025-07-07 11:25:58 -04:00
|
|
|
options := newOptions(opts...)
|
|
|
|
|
|
|
|
|
|
var (
|
|
|
|
|
vers = Version1
|
2025-07-08 18:38:23 +02:00
|
|
|
sig []byte
|
2025-07-07 11:25:58 -04:00
|
|
|
)
|
|
|
|
|
|
|
|
|
|
if options.ForceVersion0() {
|
|
|
|
|
vers = Version0
|
|
|
|
|
sig = options.Signature()
|
|
|
|
|
}
|
|
|
|
|
|
2025-07-08 18:38:23 +02:00
|
|
|
v := RSAVarsig{
|
|
|
|
|
varsig: varsig{
|
2025-07-08 07:34:57 -04:00
|
|
|
vers: vers,
|
|
|
|
|
disc: DiscriminatorRSA,
|
|
|
|
|
payEnc: payloadEncoding,
|
|
|
|
|
sig: sig,
|
2025-07-07 11:25:58 -04:00
|
|
|
},
|
|
|
|
|
hashAlg: hashAlgorithm,
|
|
|
|
|
sigLen: keyLength,
|
|
|
|
|
}
|
|
|
|
|
|
2025-07-08 14:13:47 -04:00
|
|
|
return validateSig(v, v.sigLen)
|
2025-07-07 11:25:58 -04:00
|
|
|
}
|
|
|
|
|
|
2025-07-08 07:34:57 -04:00
|
|
|
// Encode returns the encoded byte format of the RSAVarsig.
|
2025-07-07 11:25:58 -04:00
|
|
|
func (v RSAVarsig) Encode() []byte {
|
|
|
|
|
buf := v.encode()
|
|
|
|
|
buf = binary.AppendUvarint(buf, uint64(v.hashAlg))
|
|
|
|
|
buf = binary.AppendUvarint(buf, v.sigLen)
|
|
|
|
|
buf = binary.AppendUvarint(buf, uint64(v.payEnc))
|
|
|
|
|
buf = append(buf, v.Signature()...)
|
|
|
|
|
|
|
|
|
|
return buf
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// HashAlgorithm returns the hash algorithm used to has the payload content.
|
2025-07-08 18:38:23 +02:00
|
|
|
func (v RSAVarsig) HashAlgorithm() HashAlgorithm {
|
2025-07-07 11:25:58 -04:00
|
|
|
return v.hashAlg
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
// KeyLength returns the length of the RSA key used to sign the payload
|
|
|
|
|
// content.
|
2025-07-08 18:38:23 +02:00
|
|
|
func (v RSAVarsig) KeyLength() uint64 {
|
2025-07-07 11:25:58 -04:00
|
|
|
return v.sigLen
|
|
|
|
|
}
|
|
|
|
|
|
2025-07-08 18:38:23 +02:00
|
|
|
func decodeRSA(r BytesReader, vers Version, disc Discriminator) (Varsig, error) {
|
2025-07-07 11:25:58 -04:00
|
|
|
hashAlg, err := DecodeHashAlgorithm(r)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
sigLen, err := binary.ReadUvarint(r)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
|
|
|
|
|
2025-07-08 18:38:23 +02:00
|
|
|
vs := RSAVarsig{
|
|
|
|
|
varsig: varsig{
|
2025-07-08 07:34:57 -04:00
|
|
|
vers: vers,
|
|
|
|
|
disc: disc,
|
2025-07-07 11:25:58 -04:00
|
|
|
},
|
2025-07-08 11:27:18 -04:00
|
|
|
hashAlg: hashAlg,
|
2025-07-07 11:25:58 -04:00
|
|
|
sigLen: sigLen,
|
|
|
|
|
}
|
|
|
|
|
|
2025-07-08 18:38:23 +02:00
|
|
|
vs.payEnc, vs.sig, err = vs.decodePayEncAndSig(r)
|
|
|
|
|
if err != nil {
|
|
|
|
|
return nil, err
|
|
|
|
|
}
|
|
|
|
|
|
2025-07-08 14:13:47 -04:00
|
|
|
return validateSig(vs, vs.sigLen)
|
2025-07-07 11:25:58 -04:00
|
|
|
}
|