summary refs log tree commit diff
path: root/crypto/src/asn1/bc/LinkedCertificate.cs
blob: e530cd82cab08eae69dac8f8d90b21fc0e25f3eb (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
using System;

using Org.BouncyCastle.Asn1.X509;

namespace Org.BouncyCastle.Asn1.BC
{
    /**
     * Extension to tie an alternate certificate to the containing certificate.
     * <pre>
     *     LinkedCertificate := SEQUENCE {
     *         digest        DigestInfo,                   -- digest of PQC certificate
     *         certLocation  GeneralName,                  -- location of PQC certificate
     *         certIssuer    [0] Name OPTIONAL,            -- issuer of PQC cert (if different from current certificate)
     *         cACerts       [1] GeneralNames OPTIONAL,    -- CA certificates for PQC cert (one of more locations)
     * }
     * </pre>
     */
    public class LinkedCertificate
        : Asn1Encodable
    {
        public static LinkedCertificate GetInstance(object obj)
        {
            if (obj == null)
                return null;
            if (obj is LinkedCertificate linkedCertificate)
                return linkedCertificate;
            return new LinkedCertificate(Asn1Sequence.GetInstance(obj));
        }

        public static LinkedCertificate GetInstance(Asn1TaggedObject taggedObject, bool declaredExplicit)
        {
            return new LinkedCertificate(Asn1Sequence.GetInstance(taggedObject, declaredExplicit));
        }

        private readonly DigestInfo m_digest;
        private readonly GeneralName m_certLocation;
        private readonly X509Name m_certIssuer;
        private readonly GeneralNames m_cACerts;

        public LinkedCertificate(DigestInfo digest, GeneralName certLocation)
            : this(digest, certLocation, null, null)
        {
        }

        public LinkedCertificate(DigestInfo digest, GeneralName certLocation, X509Name certIssuer, GeneralNames caCerts)
        {
            m_digest = digest ?? throw new ArgumentNullException(nameof(digest));
            m_certLocation = certLocation ?? throw new ArgumentNullException(nameof(certLocation));
            m_certIssuer = certIssuer;
            m_cACerts = caCerts;
        }

        private LinkedCertificate(Asn1Sequence seq)
        {
            int count = seq.Count;
            if (count < 2 || count > 4)
                throw new ArgumentException("Bad sequence size: " + count, nameof(seq));

            int pos = 0;

            m_digest = DigestInfo.GetInstance(seq[pos++]);
            m_certLocation = GeneralName.GetInstance(seq[pos++]);
            m_certIssuer = Asn1Utilities.ReadOptionalContextTagged(seq, ref pos, 0, false, X509Name.GetInstance);
            m_cACerts = Asn1Utilities.ReadOptionalContextTagged(seq, ref pos, 1, false, GeneralNames.GetInstance);

            if (pos != count)
                throw new ArgumentException("Unexpected elements in sequence", nameof(seq));
        }

        public virtual DigestInfo Digest => m_digest;

        public virtual GeneralName CertLocation => m_certLocation;

        public virtual X509Name CertIssuer => m_certIssuer;

        public virtual GeneralNames CACerts => m_cACerts;

        public override Asn1Object ToAsn1Object()
        {
            Asn1EncodableVector v = new Asn1EncodableVector(4);
            v.Add(m_digest, m_certLocation);
            v.AddOptionalTagged(false, 0, m_certIssuer);
            v.AddOptionalTagged(false, 1, m_cACerts);
            return new DerSequence(v);
        }
    }
}