KeyInfoX509Data.cs 6.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198
  1. //
  2. // KeyInfoX509Data.cs - KeyInfoX509Data implementation for XML Signature
  3. //
  4. // Authors:
  5. // Sebastien Pouliot <[email protected]>
  6. // Atsushi Enomoto ([email protected])
  7. //
  8. // (C) 2002, 2003 Motus Technologies Inc. (http://www.motus.com)
  9. // (C) 2004 Novell Inc.
  10. //
  11. using System.Collections;
  12. using System.Security.Cryptography.X509Certificates;
  13. using System.Xml;
  14. namespace System.Security.Cryptography.Xml {
  15. public class KeyInfoX509Data : KeyInfoClause {
  16. private byte[] x509crl;
  17. private ArrayList IssuerSerialList;
  18. private ArrayList SubjectKeyIdList;
  19. private ArrayList SubjectNameList;
  20. private ArrayList X509CertificateList;
  21. public KeyInfoX509Data ()
  22. {
  23. IssuerSerialList = new ArrayList ();
  24. SubjectKeyIdList = new ArrayList ();
  25. SubjectNameList = new ArrayList ();
  26. X509CertificateList = new ArrayList ();
  27. }
  28. public KeyInfoX509Data (byte[] rgbCert) : this ()
  29. {
  30. AddCertificate (new X509Certificate (rgbCert));
  31. }
  32. public KeyInfoX509Data (X509Certificate cert) : this ()
  33. {
  34. AddCertificate (cert);
  35. }
  36. public ArrayList Certificates {
  37. get { return X509CertificateList.Count != 0 ? X509CertificateList : null; }
  38. }
  39. public byte[] CRL {
  40. get { return x509crl; }
  41. set { x509crl = value; }
  42. }
  43. public ArrayList IssuerSerials {
  44. get { return IssuerSerialList.Count != 0 ? IssuerSerialList : null; }
  45. }
  46. public ArrayList SubjectKeyIds {
  47. get { return SubjectKeyIdList.Count != 0 ? SubjectKeyIdList : null; }
  48. }
  49. public ArrayList SubjectNames {
  50. get { return SubjectNameList.Count != 0 ? SubjectNameList : null; }
  51. }
  52. public void AddCertificate (X509Certificate certificate)
  53. {
  54. X509CertificateList.Add (certificate);
  55. }
  56. public void AddIssuerSerial (string issuerName, string serialNumber)
  57. {
  58. X509IssuerSerial xis = new X509IssuerSerial (issuerName, serialNumber);
  59. IssuerSerialList.Add (xis);
  60. }
  61. public void AddSubjectKeyId (byte[] subjectKeyId)
  62. {
  63. SubjectKeyIdList.Add (subjectKeyId);
  64. }
  65. public void AddSubjectName (string subjectName)
  66. {
  67. SubjectNameList.Add (subjectName);
  68. }
  69. public override XmlElement GetXml ()
  70. {
  71. // sanity check
  72. int count = IssuerSerialList.Count + SubjectKeyIdList.Count + SubjectNameList.Count + X509CertificateList.Count;
  73. if ((x509crl == null) && (count == 0))
  74. throw new CryptographicException ("value");
  75. XmlDocument document = new XmlDocument ();
  76. XmlElement xel = document.CreateElement (XmlSignature.ElementNames.X509Data, XmlSignature.NamespaceURI);
  77. // FIXME: hack to match MS implementation
  78. xel.SetAttribute ("xmlns", XmlSignature.NamespaceURI);
  79. // <X509IssuerSerial>
  80. if (IssuerSerialList.Count > 0) {
  81. foreach (X509IssuerSerial iser in IssuerSerialList) {
  82. XmlElement isl = document.CreateElement (XmlSignature.ElementNames.X509IssuerSerial, XmlSignature.NamespaceURI);
  83. XmlElement xin = document.CreateElement (XmlSignature.ElementNames.X509IssuerName, XmlSignature.NamespaceURI);
  84. xin.InnerText = iser.IssuerName;
  85. isl.AppendChild (xin);
  86. XmlElement xsn = document.CreateElement (XmlSignature.ElementNames.X509SerialNumber, XmlSignature.NamespaceURI);
  87. xsn.InnerText = iser.SerialNumber;
  88. isl.AppendChild (xsn);
  89. xel.AppendChild (isl);
  90. }
  91. }
  92. // <X509SKI>
  93. if (SubjectKeyIdList.Count > 0) {
  94. foreach (byte[] skid in SubjectKeyIdList) {
  95. XmlElement ski = document.CreateElement (XmlSignature.ElementNames.X509SKI, XmlSignature.NamespaceURI);
  96. ski.InnerText = Convert.ToBase64String (skid);
  97. xel.AppendChild (ski);
  98. }
  99. }
  100. // <X509SubjectName>
  101. if (SubjectNameList.Count > 0) {
  102. foreach (string subject in SubjectNameList) {
  103. XmlElement sn = document.CreateElement (XmlSignature.ElementNames.X509SubjectName, XmlSignature.NamespaceURI);
  104. sn.InnerText = subject;
  105. xel.AppendChild (sn);
  106. }
  107. }
  108. // <X509Certificate>
  109. if (X509CertificateList.Count > 0) {
  110. foreach (X509Certificate x509 in X509CertificateList) {
  111. XmlElement cert = document.CreateElement (XmlSignature.ElementNames.X509Certificate, XmlSignature.NamespaceURI);
  112. cert.InnerText = Convert.ToBase64String (x509.GetRawCertData ());
  113. xel.AppendChild (cert);
  114. }
  115. }
  116. // only one <X509CRL>
  117. if (x509crl != null) {
  118. XmlElement crl = document.CreateElement (XmlSignature.ElementNames.X509CRL, XmlSignature.NamespaceURI);
  119. crl.InnerText = Convert.ToBase64String (x509crl);
  120. xel.AppendChild (crl);
  121. }
  122. return xel;
  123. }
  124. public override void LoadXml (XmlElement element)
  125. {
  126. if (element == null)
  127. throw new ArgumentNullException ("element");
  128. IssuerSerialList.Clear ();
  129. SubjectKeyIdList.Clear ();
  130. SubjectNameList.Clear ();
  131. X509CertificateList.Clear ();
  132. x509crl = null;
  133. if ((element.LocalName != XmlSignature.ElementNames.X509Data) || (element.NamespaceURI != XmlSignature.NamespaceURI))
  134. throw new CryptographicException ("element");
  135. XmlElement [] xnl = null;
  136. // <X509IssuerSerial>
  137. xnl = XmlSignature.GetChildElements (element, XmlSignature.ElementNames.X509IssuerSerial);
  138. if (xnl != null) {
  139. for (int i=0; i < xnl.Length; i++) {
  140. XmlElement xel = (XmlElement) xnl[i];
  141. XmlElement issuer = XmlSignature.GetChildElement (xel, XmlSignature.ElementNames.X509IssuerName, XmlSignature.NamespaceURI);
  142. XmlElement serial = XmlSignature.GetChildElement (xel, XmlSignature.ElementNames.X509SerialNumber, XmlSignature.NamespaceURI);
  143. AddIssuerSerial (issuer.InnerText, serial.InnerText);
  144. }
  145. }
  146. // <X509SKI>
  147. xnl = XmlSignature.GetChildElements (element, XmlSignature.ElementNames.X509SKI);
  148. if (xnl != null) {
  149. for (int i=0; i < xnl.Length; i++) {
  150. byte[] skid = Convert.FromBase64String (xnl[i].InnerXml);
  151. AddSubjectKeyId (skid);
  152. }
  153. }
  154. // <X509SubjectName>
  155. xnl = XmlSignature.GetChildElements (element, XmlSignature.ElementNames.X509SubjectName);
  156. if (xnl != null) {
  157. for (int i=0; i < xnl.Length; i++) {
  158. AddSubjectName (xnl[i].InnerXml);
  159. }
  160. }
  161. // <X509Certificate>
  162. xnl = XmlSignature.GetChildElements (element, XmlSignature.ElementNames.X509Certificate);
  163. if (xnl != null) {
  164. for (int i=0; i < xnl.Length; i++) {
  165. byte[] cert = Convert.FromBase64String (xnl[i].InnerXml);
  166. AddCertificate (new X509Certificate (cert));
  167. }
  168. }
  169. // only one <X509CRL>
  170. XmlElement x509el = XmlSignature.GetChildElement (element, XmlSignature.ElementNames.X509CRL, XmlSignature.NamespaceURI);
  171. if (x509el != null) {
  172. x509crl = Convert.FromBase64String (x509el.InnerXml);
  173. }
  174. }
  175. }
  176. }