Import Upstream version 1.1.1
Thorsten Alteholz
2 years ago
0 | arch: | |
1 | - amd64 | |
2 | - ppc64le | |
3 | ||
0 | 4 | language: go |
1 | 5 | |
2 | 6 | go: |
3 | - "1.13.x" | |
4 | 7 | - "1.14.x" |
5 | 8 | - "1.15.x" |
9 | - "1.17.x" | |
6 | 10 | - master |
10 | 10 | type Canonicalizer interface { |
11 | 11 | Canonicalize(el *etree.Element) ([]byte, error) |
12 | 12 | Algorithm() AlgorithmID |
13 | } | |
14 | ||
15 | type NullCanonicalizer struct { | |
16 | } | |
17 | ||
18 | func MakeNullCanonicalizer() Canonicalizer { | |
19 | return &NullCanonicalizer{} | |
20 | } | |
21 | ||
22 | func (c *NullCanonicalizer) Algorithm() AlgorithmID { | |
23 | return AlgorithmID("NULL") | |
24 | } | |
25 | ||
26 | func (c *NullCanonicalizer) Canonicalize(el *etree.Element) ([]byte, error) { | |
27 | scope := make(map[string]struct{}) | |
28 | return canonicalSerialize(canonicalPrep(el, scope, false)) | |
13 | 29 | } |
14 | 30 | |
15 | 31 | type c14N10ExclusiveCanonicalizer struct { |
48 | 64 | // Canonicalize transforms the input Element into a serialized XML document in canonical form. |
49 | 65 | func (c *c14N11Canonicalizer) Canonicalize(el *etree.Element) ([]byte, error) { |
50 | 66 | scope := make(map[string]struct{}) |
51 | return canonicalSerialize(canonicalPrep(el, scope)) | |
67 | return canonicalSerialize(canonicalPrep(el, scope, true)) | |
52 | 68 | } |
53 | 69 | |
54 | 70 | func (c *c14N11Canonicalizer) Algorithm() AlgorithmID { |
65 | 81 | // Canonicalize transforms the input Element into a serialized XML document in canonical form. |
66 | 82 | func (c *c14N10RecCanonicalizer) Canonicalize(el *etree.Element) ([]byte, error) { |
67 | 83 | scope := make(map[string]struct{}) |
68 | return canonicalSerialize(canonicalPrep(el, scope)) | |
84 | return canonicalSerialize(canonicalPrep(el, scope, true)) | |
69 | 85 | } |
70 | 86 | |
71 | 87 | func (c *c14N10RecCanonicalizer) Algorithm() AlgorithmID { |
82 | 98 | // Canonicalize transforms the input Element into a serialized XML document in canonical form. |
83 | 99 | func (c *c14N10CommentCanonicalizer) Canonicalize(el *etree.Element) ([]byte, error) { |
84 | 100 | scope := make(map[string]struct{}) |
85 | return canonicalSerialize(canonicalPrep(el, scope)) | |
101 | return canonicalSerialize(canonicalPrep(el, scope, true)) | |
86 | 102 | } |
87 | 103 | |
88 | 104 | func (c *c14N10CommentCanonicalizer) Algorithm() AlgorithmID { |
115 | 131 | // |
116 | 132 | // TODO(russell_h): This is very similar to excCanonicalPrep - perhaps they should |
117 | 133 | // be unified into one parameterized function? |
118 | func canonicalPrep(el *etree.Element, seenSoFar map[string]struct{}) *etree.Element { | |
134 | func canonicalPrep(el *etree.Element, seenSoFar map[string]struct{}, strip bool) *etree.Element { | |
119 | 135 | _seenSoFar := make(map[string]struct{}) |
120 | 136 | for k, v := range seenSoFar { |
121 | 137 | _seenSoFar[k] = v |
140 | 156 | for i, token := range ne.Child { |
141 | 157 | childElement, ok := token.(*etree.Element) |
142 | 158 | if ok { |
143 | ne.Child[i] = canonicalPrep(childElement, _seenSoFar) | |
159 | ne.Child[i] = canonicalPrep(childElement, _seenSoFar, strip) | |
144 | 160 | } |
145 | 161 | } |
146 | 162 |
3 | 3 | |
4 | 4 | require ( |
5 | 5 | github.com/beevik/etree v1.1.0 |
6 | github.com/jonboulle/clockwork v0.2.0 | |
6 | github.com/jonboulle/clockwork v0.2.2 | |
7 | github.com/kr/pretty v0.3.0 // indirect | |
8 | github.com/rogpeppe/go-internal v1.8.0 // indirect | |
7 | 9 | github.com/stretchr/testify v1.6.1 |
10 | gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c // indirect | |
11 | gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b // indirect | |
8 | 12 | ) |
0 | 0 | github.com/beevik/etree v1.1.0 h1:T0xke/WvNtMoCqgzPhkX2r4rjY3GDZFi+FjpRZY2Jbs= |
1 | 1 | github.com/beevik/etree v1.1.0/go.mod h1:r8Aw8JqVegEf0w2fDnATrX9VpkMcyFeM0FhwO62wh+A= |
2 | github.com/creack/pty v1.1.9/go.mod h1:oKZEueFk5CKHvIhNR5MUki03XCEU+Q6VDXinZuGJ33E= | |
2 | 3 | github.com/davecgh/go-spew v1.1.0 h1:ZDRjVQ15GmhC3fiQ8ni8+OwkZQO4DARzQgrnXU1Liz8= |
3 | 4 | github.com/davecgh/go-spew v1.1.0/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38= |
4 | 5 | github.com/jonboulle/clockwork v0.2.0 h1:J2SLSdy7HgElq8ekSl2Mxh6vrRNFxqbXGenYH2I02Vs= |
5 | 6 | github.com/jonboulle/clockwork v0.2.0/go.mod h1:Pkfl5aHPm1nk2H9h0bjmnJD/BcgbGXUBGnn1kMkgxc8= |
7 | github.com/jonboulle/clockwork v0.2.2 h1:UOGuzwb1PwsrDAObMuhUnj0p5ULPj8V/xJ7Kx9qUBdQ= | |
8 | github.com/jonboulle/clockwork v0.2.2/go.mod h1:Pkfl5aHPm1nk2H9h0bjmnJD/BcgbGXUBGnn1kMkgxc8= | |
9 | github.com/kr/pretty v0.1.0/go.mod h1:dAy3ld7l9f0ibDNOQOHHMYYIIbhfbHSm3C4ZsoJORNo= | |
10 | github.com/kr/pretty v0.2.1/go.mod h1:ipq/a2n7PKx3OHsz4KJII5eveXtPO4qwEXGdVfWzfnI= | |
11 | github.com/kr/pretty v0.3.0 h1:WgNl7dwNpEZ6jJ9k1snq4pZsg7DOEN8hP9Xw0Tsjwk0= | |
12 | github.com/kr/pretty v0.3.0/go.mod h1:640gp4NfQd8pI5XOwp5fnNeVWj67G7CFk/SaSQn7NBk= | |
13 | github.com/kr/pty v1.1.1/go.mod h1:pFQYn66WHrOpPYNljwOMqo10TkYh1fy3cYio2l3bCsQ= | |
14 | github.com/kr/text v0.1.0/go.mod h1:4Jbv+DJW3UT/LiOwJeYQe1efqtUx/iVham/4vfdArNI= | |
15 | github.com/kr/text v0.2.0 h1:5Nx0Ya0ZqY2ygV366QzturHI13Jq95ApcVaJBhpS+AY= | |
16 | github.com/kr/text v0.2.0/go.mod h1:eLer722TekiGuMkidMxC/pM04lWEeraHUUmBw8l2grE= | |
17 | github.com/pkg/diff v0.0.0-20210226163009-20ebb0f2a09e/go.mod h1:pJLUxLENpZxwdsKMEsNbx1VGcRFpLqf3715MtcvvzbA= | |
6 | 18 | github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM= |
7 | 19 | github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4= |
20 | github.com/rogpeppe/go-internal v1.6.1/go.mod h1:xXDCJY+GAPziupqXw64V24skbSoqbTEfhy4qGm1nDQc= | |
21 | github.com/rogpeppe/go-internal v1.8.0 h1:FCbCCtXNOY3UtUuHUYaghJg4y7Fd14rXifAYUAtL9R8= | |
22 | github.com/rogpeppe/go-internal v1.8.0/go.mod h1:WmiCO8CzOY8rg0OYDC4/i/2WRWAB6poM+XZ2dLUbcbE= | |
8 | 23 | github.com/stretchr/objx v0.1.0/go.mod h1:HFkY916IF+rwdDfMAkV7OtwuqBVzrE8GR6GFx+wExME= |
9 | 24 | github.com/stretchr/testify v1.6.1 h1:hDPOHmpOpP40lSULcqw7IrRb/u7w6RpDC9399XyoNd0= |
10 | 25 | github.com/stretchr/testify v1.6.1/go.mod h1:6Fq8oRcR53rry900zMqJjRRixrwX3KX962/h/Wwjteg= |
11 | gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405 h1:yhCVgyC4o1eVCa2tZl7eS0r+SDo693bJlVdllGtEeKM= | |
12 | 26 | gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= |
13 | gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c h1:dUUwHk2QECo/6vqA44rthZ8ie2QXMNeKRTHCNY2nXvo= | |
27 | gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= | |
28 | gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c h1:Hei/4ADfdWqJk1ZMxUNpqntNwaWcugrBjAiHlqqRiVk= | |
29 | gopkg.in/check.v1 v1.0.0-20201130134442-10cb98267c6c/go.mod h1:JHkPIbrfpd72SG/EVd6muEfDQjcINNoR0C8j2r3qZ4Q= | |
30 | gopkg.in/errgo.v2 v2.1.0/go.mod h1:hNsd1EY+bozCKY1Ytp96fpM3vjJbqLJn88ws8XvfDNI= | |
14 | 31 | gopkg.in/yaml.v3 v3.0.0-20200313102051-9f266ea9e77c/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= |
32 | gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b h1:h8qDotaEPuJATrMmW04NCwg7v22aHH28wwpauUhK9Oo= | |
33 | gopkg.in/yaml.v3 v3.0.0-20210107192922-496545a6307b/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM= |
91 | 91 | |
92 | 92 | dataId := el.SelectAttrValue(ctx.IdAttribute, "") |
93 | 93 | if dataId == "" { |
94 | return nil, errors.New("Missing data ID") | |
95 | } | |
96 | ||
97 | reference.CreateAttr(URIAttr, "#"+dataId) | |
94 | reference.CreateAttr(URIAttr, "") | |
95 | } else { | |
96 | reference.CreateAttr(URIAttr, "#"+dataId) | |
97 | } | |
98 | ||
98 | 99 | |
99 | 100 | // /SignedInfo/Reference/Transforms |
100 | 101 | transforms := ctx.createNamespacedElement(reference, TransformsTag) |
95 | 95 | |
96 | 96 | _, err := ctx.SignEnveloped(authnRequest) |
97 | 97 | require.Error(t, err) |
98 | ||
99 | randomKeyStore = RandomKeyStoreForTest() | |
100 | ctx = NewDefaultSigningContext(randomKeyStore) | |
101 | ||
102 | authnRequest = &etree.Element{ | |
103 | Space: "samlp", | |
104 | Tag: "AuthnRequest", | |
105 | } | |
106 | ||
107 | _, err = ctx.SignEnveloped(authnRequest) | |
108 | require.Error(t, err) | |
109 | 98 | } |
110 | 99 | |
111 | 100 | func TestSignNonDefaultID(t *testing.T) { |
110 | 110 | ref *types.Reference) (*etree.Element, Canonicalizer, error) { |
111 | 111 | transforms := ref.Transforms.Transforms |
112 | 112 | |
113 | if len(transforms) != 2 { | |
114 | return nil, nil, errors.New("Expected Enveloped and C14N transforms") | |
115 | } | |
116 | ||
117 | 113 | // map the path to the passed signature relative to the passed root, in |
118 | 114 | // order to enable removal of the signature by an enveloped signature |
119 | 115 | // transform |
156 | 152 | } |
157 | 153 | |
158 | 154 | if canonicalizer == nil { |
159 | return nil, nil, errors.New("Expected canonicalization transform") | |
155 | canonicalizer = MakeNullCanonicalizer() | |
160 | 156 | } |
161 | 157 | |
162 | 158 | return el, canonicalizer, nil |
233 | 229 | } |
234 | 230 | |
235 | 231 | func (ctx *ValidationContext) validateSignature(el *etree.Element, sig *types.Signature, cert *x509.Certificate) (*etree.Element, error) { |
236 | idAttr := el.SelectAttr(ctx.IdAttribute) | |
237 | if idAttr == nil || idAttr.Value == "" { | |
238 | return nil, errors.New("Missing ID attribute") | |
232 | idAttrEl := el.SelectAttr(ctx.IdAttribute) | |
233 | idAttr := "" | |
234 | if idAttrEl != nil { | |
235 | idAttr = idAttrEl.Value | |
239 | 236 | } |
240 | 237 | |
241 | 238 | var ref *types.Reference |
242 | 239 | |
243 | 240 | // Find the first reference which references the top-level element |
244 | 241 | for _, _ref := range sig.SignedInfo.References { |
245 | if _ref.URI == "" || _ref.URI[1:] == idAttr.Value { | |
242 | if _ref.URI == "" || _ref.URI[1:] == idAttr { | |
246 | 243 | ref = &_ref |
247 | 244 | } |
248 | 245 | } |
268 | 265 | } |
269 | 266 | |
270 | 267 | if !bytes.Equal(digest, decodedDigestValue) { |
268 | return nil, errors.New("Signature could not be verified") | |
269 | } | |
270 | if sig.SignatureValue == nil { | |
271 | 271 | return nil, errors.New("Signature could not be verified") |
272 | 272 | } |
273 | 273 | |
317 | 317 | |
318 | 318 | // findSignature searches for a Signature element referencing the passed root element. |
319 | 319 | func (ctx *ValidationContext) findSignature(root *etree.Element) (*types.Signature, error) { |
320 | idAttr := root.SelectAttr(ctx.IdAttribute) | |
321 | if idAttr == nil || idAttr.Value == "" { | |
322 | return nil, errors.New("Missing ID attribute") | |
320 | idAttrEl := root.SelectAttr(ctx.IdAttribute) | |
321 | idAttr := "" | |
322 | if idAttrEl != nil { | |
323 | idAttr = idAttrEl.Value | |
323 | 324 | } |
324 | 325 | |
325 | 326 | var sig *types.Signature |
365 | 366 | canonicalSignedInfo = detachedSignedInfo |
366 | 367 | |
367 | 368 | case CanonicalXML11AlgorithmId: |
368 | canonicalSignedInfo = canonicalPrep(detachedSignedInfo, map[string]struct{}{}) | |
369 | canonicalSignedInfo = canonicalPrep(detachedSignedInfo, map[string]struct{}{}, true) | |
369 | 370 | |
370 | 371 | case CanonicalXML10RecAlgorithmId: |
371 | canonicalSignedInfo = canonicalPrep(detachedSignedInfo, map[string]struct{}{}) | |
372 | canonicalSignedInfo = canonicalPrep(detachedSignedInfo, map[string]struct{}{}, true) | |
372 | 373 | |
373 | 374 | case CanonicalXML10CommentAlgorithmId: |
374 | canonicalSignedInfo = canonicalPrep(detachedSignedInfo, map[string]struct{}{}) | |
375 | canonicalSignedInfo = canonicalPrep(detachedSignedInfo, map[string]struct{}{}, true) | |
375 | 376 | |
376 | 377 | default: |
377 | 378 | return fmt.Errorf("invalid CanonicalizationMethod on Signature: %s", c14NAlgorithm) |
402 | 403 | // Traverse references in the signature to determine whether it has at least |
403 | 404 | // one reference to the top level element. If so, conclude the search. |
404 | 405 | for _, ref := range _sig.SignedInfo.References { |
405 | if ref.URI == "" || ref.URI[1:] == idAttr.Value { | |
406 | if ref.URI == "" || ref.URI[1:] == idAttr { | |
406 | 407 | sig = _sig |
407 | 408 | return etreeutils.ErrTraversalHalted |
408 | 409 | } |