CCF
Loading...
Searching...
No Matches
verifier.h
Go to the documentation of this file.
1// Copyright (c) Microsoft Corporation. All rights reserved.
2// Licensed under the Apache 2.0 License.
3#pragma once
4
6#include "ccf/crypto/jwk.h"
7#include "ccf/crypto/pem.h"
9
10#include <chrono>
11
12namespace ccf::crypto
13{
15 {
16 protected:
17 std::variant<ccf::crypto::RSAPublicKeyPtr, ccf::crypto::ECPublicKeyPtr>
19
20 public:
21 Verifier() = default;
22 virtual ~Verifier() = default;
23
24 virtual std::vector<uint8_t> cert_der() = 0;
25 virtual Pem cert_pem() = 0;
26
35 [[nodiscard]] virtual bool verify(
36 const uint8_t* contents,
37 size_t contents_size,
38 const uint8_t* sig,
39 size_t sig_size,
40 MDType md_type = MDType::NONE) const;
41
48 [[nodiscard]] virtual bool verify(
49 std::span<const uint8_t> contents,
50 std::span<const uint8_t> sig,
51 MDType md_type = MDType::NONE) const
52 {
53 return verify(
54 contents.data(), contents.size(), sig.data(), sig.size(), md_type);
55 }
56
63 [[nodiscard]] virtual bool verify(
64 const std::vector<uint8_t>& contents,
65 const std::vector<uint8_t>& signature,
66 MDType md_type = MDType::NONE) const
67 {
68 return verify(
69 contents.data(),
70 contents.size(),
71 signature.data(),
72 signature.size(),
73 md_type);
74 }
75
84 virtual bool verify_hash(
85 const uint8_t* hash,
86 size_t hash_size,
87 const uint8_t* sig,
88 size_t sig_size,
89 MDType md_type = MDType::NONE);
90
97 virtual bool verify_hash(
98 const std::vector<uint8_t>& hash,
99 const std::vector<uint8_t>& signature,
100 MDType md_type = MDType::NONE)
101 {
102 return verify_hash(
103 hash.data(), hash.size(), signature.data(), signature.size(), md_type);
104 }
105
112 template <size_t SIZE>
114 const std::array<uint8_t, SIZE>& hash,
115 const std::vector<uint8_t>& signature,
116 MDType md_type = MDType::NONE)
117 {
118 return verify_hash(
119 hash.data(), hash.size(), signature.data(), signature.size(), md_type);
120 }
121
125 [[nodiscard]] virtual Pem public_key_pem() const;
126
130 [[nodiscard]] virtual std::vector<uint8_t> public_key_der() const;
131
139 [[nodiscard]] virtual bool verify_certificate(
140 const std::vector<const Pem*>& trusted_certs,
141 const std::vector<const Pem*>& chain = {},
142 bool ignore_time = false) = 0;
143
145 [[nodiscard]] virtual bool is_self_signed() const = 0;
146
148 [[nodiscard]] virtual std::string serial_number() const = 0;
149
151 [[nodiscard]] virtual std::pair<std::string, std::string> validity_period()
152 const = 0;
153
156 [[nodiscard]] virtual size_t remaining_seconds(
157 const std::chrono::system_clock::time_point& now) const = 0;
158
160 [[nodiscard]] virtual double remaining_percentage(
161 const std::chrono::system_clock::time_point& now) const = 0;
162
164 [[nodiscard]] virtual std::string subject() const = 0;
165 };
166
167 using VerifierPtr = std::shared_ptr<Verifier>;
168 using VerifierUniquePtr = std::unique_ptr<Verifier>;
169
174 VerifierUniquePtr make_unique_verifier(const std::vector<uint8_t>& cert);
175
180 VerifierPtr make_verifier(const std::vector<uint8_t>& cert);
181
187
192 VerifierPtr make_verifier(const Pem& pem);
193
194 ccf::crypto::Pem cert_der_to_pem(const std::vector<uint8_t>& der);
195 std::vector<uint8_t> cert_pem_to_der(const Pem& pem);
196
197 std::vector<uint8_t> public_key_der_from_cert(
198 const std::vector<uint8_t>& der);
199
200 ccf::crypto::Pem public_key_pem_from_cert(const std::vector<uint8_t>& der);
201
202 std::string get_subject_name(const Pem& cert);
203}
Definition pem.h:18
Definition verifier.h:15
virtual double remaining_percentage(const std::chrono::system_clock::time_point &now) const =0
virtual bool verify(std::span< const uint8_t > contents, std::span< const uint8_t > sig, MDType md_type=MDType::NONE) const
Definition verifier.h:48
virtual std::vector< uint8_t > public_key_der() const
Definition verifier.cpp:111
virtual bool verify(const std::vector< uint8_t > &contents, const std::vector< uint8_t > &signature, MDType md_type=MDType::NONE) const
Definition verifier.h:63
bool verify_hash(const std::array< uint8_t, SIZE > &hash, const std::vector< uint8_t > &signature, MDType md_type=MDType::NONE)
Definition verifier.h:113
std::variant< ccf::crypto::RSAPublicKeyPtr, ccf::crypto::ECPublicKeyPtr > public_key
Definition verifier.h:18
virtual ~Verifier()=default
virtual std::string subject() const =0
virtual bool verify_certificate(const std::vector< const Pem * > &trusted_certs, const std::vector< const Pem * > &chain={}, bool ignore_time=false)=0
virtual bool verify_hash(const std::vector< uint8_t > &hash, const std::vector< uint8_t > &signature, MDType md_type=MDType::NONE)
Definition verifier.h:97
virtual Pem cert_pem()=0
virtual bool is_self_signed() const =0
virtual std::vector< uint8_t > cert_der()=0
virtual bool verify(const uint8_t *contents, size_t contents_size, const uint8_t *sig, size_t sig_size, MDType md_type=MDType::NONE) const
Definition verifier.cpp:78
virtual std::pair< std::string, std::string > validity_period() const =0
virtual Pem public_key_pem() const
Definition verifier.cpp:98
virtual bool verify_hash(const uint8_t *hash, size_t hash_size, const uint8_t *sig, size_t sig_size, MDType md_type=MDType::NONE)
Definition verifier.cpp:58
virtual size_t remaining_seconds(const std::chrono::system_clock::time_point &now) const =0
virtual std::string serial_number() const =0
Definition base64.h:10
ccf::crypto::Pem cert_der_to_pem(const std::vector< uint8_t > &der)
Definition verifier.cpp:33
VerifierUniquePtr make_unique_verifier(const std::vector< uint8_t > &cert)
Definition verifier.cpp:13
std::unique_ptr< Verifier > VerifierUniquePtr
Definition verifier.h:168
ccf::crypto::Pem public_key_pem_from_cert(const std::vector< uint8_t > &der)
Definition verifier.cpp:48
MDType
Definition md_type.h:10
std::shared_ptr< Verifier > VerifierPtr
Definition verifier.h:167
VerifierPtr make_verifier(const std::vector< uint8_t > &cert)
Definition verifier.cpp:18
std::string get_subject_name(const Pem &cert)
Definition verifier.cpp:53
std::vector< uint8_t > public_key_der_from_cert(const std::vector< uint8_t > &der)
Definition verifier.cpp:43
std::vector< uint8_t > cert_pem_to_der(const Pem &pem)
Definition verifier.cpp:38