KeyInfoX509Data.cs 6.5 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208
  1. //
  2. // KeyInfoX509Data.cs - KeyInfoX509Data implementation for XML Signature
  3. //
  4. // Author:
  5. // Sebastien Pouliot ([email protected])
  6. //
  7. // (C) 2002, 2003 Motus Technologies Inc. (http://www.motus.com)
  8. //
  9. using System.Collections;
  10. using System.Security.Cryptography.X509Certificates;
  11. using System.Xml;
  12. namespace System.Security.Cryptography.Xml {
  13. // FIXME: framework class isn't documented so compatibility isn't assured!
  14. internal class IssuerSerial {
  15. public string Issuer;
  16. public string Serial;
  17. public IssuerSerial (string issuer, string serial)
  18. {
  19. Issuer = issuer;
  20. Serial = serial;
  21. }
  22. }
  23. public class KeyInfoX509Data : KeyInfoClause {
  24. private byte[] x509crl;
  25. private ArrayList IssuerSerialList;
  26. private ArrayList SubjectKeyIdList;
  27. private ArrayList SubjectNameList;
  28. private ArrayList X509CertificateList;
  29. public KeyInfoX509Data ()
  30. {
  31. IssuerSerialList = new ArrayList ();
  32. SubjectKeyIdList = new ArrayList ();
  33. SubjectNameList = new ArrayList ();
  34. X509CertificateList = new ArrayList ();
  35. }
  36. public KeyInfoX509Data (byte[] rgbCert) : this ()
  37. {
  38. AddCertificate (new X509Certificate (rgbCert));
  39. }
  40. public KeyInfoX509Data (X509Certificate cert) : this ()
  41. {
  42. AddCertificate (cert);
  43. }
  44. public ArrayList Certificates {
  45. get { return X509CertificateList; }
  46. }
  47. public byte[] CRL {
  48. get { return x509crl; }
  49. set { x509crl = value; }
  50. }
  51. public ArrayList IssuerSerials {
  52. get { return IssuerSerialList; }
  53. }
  54. public ArrayList SubjectKeyIds {
  55. get { return SubjectKeyIdList; }
  56. }
  57. public ArrayList SubjectNames {
  58. get { return SubjectNameList; }
  59. }
  60. public void AddCertificate (X509Certificate certificate)
  61. {
  62. X509CertificateList.Add (certificate);
  63. }
  64. public void AddIssuerSerial (string issuerName, string serialNumber)
  65. {
  66. IssuerSerial isser = new IssuerSerial (issuerName, serialNumber);
  67. IssuerSerialList.Add (isser);
  68. }
  69. public void AddSubjectKeyId (byte[] subjectKeyId)
  70. {
  71. SubjectKeyIdList.Add (subjectKeyId);
  72. }
  73. public void AddSubjectName (string subjectName)
  74. {
  75. SubjectNameList.Add (subjectName);
  76. }
  77. public override XmlElement GetXml ()
  78. {
  79. // sanity check
  80. int count = IssuerSerialList.Count + SubjectKeyIdList.Count + SubjectNameList.Count + X509CertificateList.Count;
  81. if ((x509crl == null) && (count == 0))
  82. throw new CryptographicException ("value");
  83. XmlDocument document = new XmlDocument ();
  84. XmlElement xel = document.CreateElement (XmlSignature.ElementNames.X509Data, XmlSignature.NamespaceURI);
  85. // FIXME: hack to match MS implementation
  86. xel.SetAttribute ("xmlns", XmlSignature.NamespaceURI);
  87. // <X509IssuerSerial>
  88. if (IssuerSerialList.Count > 0) {
  89. foreach (IssuerSerial iser in IssuerSerialList) {
  90. XmlElement isl = document.CreateElement (XmlSignature.ElementNames.X509IssuerSerial, XmlSignature.NamespaceURI);
  91. XmlElement xin = document.CreateElement (XmlSignature.ElementNames.X509IssuerName, XmlSignature.NamespaceURI);
  92. xin.InnerText = iser.Issuer;
  93. isl.AppendChild (xin);
  94. XmlElement xsn = document.CreateElement (XmlSignature.ElementNames.X509SerialNumber, XmlSignature.NamespaceURI);
  95. xsn.InnerText = iser.Serial;
  96. isl.AppendChild (xsn);
  97. xel.AppendChild (isl);
  98. }
  99. }
  100. // <X509SKI>
  101. if (SubjectKeyIdList.Count > 0) {
  102. foreach (byte[] skid in SubjectKeyIdList) {
  103. XmlElement ski = document.CreateElement (XmlSignature.ElementNames.X509SKI, XmlSignature.NamespaceURI);
  104. ski.InnerText = Convert.ToBase64String (skid);
  105. xel.AppendChild (ski);
  106. }
  107. }
  108. // <X509SubjectName>
  109. if (SubjectNameList.Count > 0) {
  110. foreach (string subject in SubjectNameList) {
  111. XmlElement sn = document.CreateElement (XmlSignature.ElementNames.X509SubjectName, XmlSignature.NamespaceURI);
  112. sn.InnerText = subject;
  113. xel.AppendChild (sn);
  114. }
  115. }
  116. // <X509Certificate>
  117. if (X509CertificateList.Count > 0) {
  118. foreach (X509Certificate x509 in X509CertificateList) {
  119. XmlElement cert = document.CreateElement (XmlSignature.ElementNames.X509Certificate, XmlSignature.NamespaceURI);
  120. cert.InnerText = Convert.ToBase64String (x509.GetRawCertData ());
  121. xel.AppendChild (cert);
  122. }
  123. }
  124. // only one <X509CRL>
  125. if (x509crl != null) {
  126. XmlElement crl = document.CreateElement (XmlSignature.ElementNames.X509CRL, XmlSignature.NamespaceURI);
  127. crl.InnerText = Convert.ToBase64String (x509crl);
  128. xel.AppendChild (crl);
  129. }
  130. return xel;
  131. }
  132. public override void LoadXml (XmlElement element)
  133. {
  134. if (element == null)
  135. throw new ArgumentNullException ("element");
  136. IssuerSerialList.Clear ();
  137. SubjectKeyIdList.Clear ();
  138. SubjectNameList.Clear ();
  139. X509CertificateList.Clear ();
  140. x509crl = null;
  141. if ((element.LocalName != XmlSignature.ElementNames.X509Data) || (element.NamespaceURI != XmlSignature.NamespaceURI))
  142. throw new CryptographicException ("element");
  143. XmlNodeList xnl = null;
  144. // <X509IssuerSerial>
  145. xnl = element.GetElementsByTagName (XmlSignature.ElementNames.X509IssuerSerial, XmlSignature.NamespaceURI);
  146. if (xnl != null) {
  147. for (int i=0; i < xnl.Count; i++) {
  148. XmlElement xel = (XmlElement) xnl[i];
  149. XmlElement issuer = XmlSignature.GetChildElement (xel, XmlSignature.ElementNames.X509IssuerName, XmlSignature.NamespaceURI);
  150. XmlElement serial = XmlSignature.GetChildElement (xel, XmlSignature.ElementNames.X509SerialNumber, XmlSignature.NamespaceURI);
  151. AddIssuerSerial (issuer.InnerText, serial.InnerText);
  152. }
  153. }
  154. // <X509SKI>
  155. xnl = element.GetElementsByTagName (XmlSignature.ElementNames.X509SKI, XmlSignature.NamespaceURI);
  156. if (xnl != null) {
  157. for (int i=0; i < xnl.Count; i++) {
  158. byte[] skid = Convert.FromBase64String (xnl[i].InnerXml);
  159. AddSubjectKeyId (skid);
  160. }
  161. }
  162. // <X509SubjectName>
  163. xnl = element.GetElementsByTagName (XmlSignature.ElementNames.X509SubjectName, XmlSignature.NamespaceURI);
  164. if (xnl != null) {
  165. for (int i=0; i < xnl.Count; i++) {
  166. AddSubjectName (xnl[i].InnerXml);
  167. }
  168. }
  169. // <X509Certificate>
  170. xnl = element.GetElementsByTagName (XmlSignature.ElementNames.X509Certificate, XmlSignature.NamespaceURI);
  171. if (xnl != null) {
  172. for (int i=0; i < xnl.Count; i++) {
  173. byte[] cert = Convert.FromBase64String (xnl[i].InnerXml);
  174. AddCertificate (new X509Certificate (cert));
  175. }
  176. }
  177. // only one <X509CRL>
  178. XmlElement x509el = XmlSignature.GetChildElement (element, XmlSignature.ElementNames.X509CRL, XmlSignature.NamespaceURI);
  179. if (x509el != null) {
  180. x509crl = Convert.FromBase64String (x509el.InnerXml);
  181. }
  182. }
  183. }
  184. }