summary refs log tree commit diff
path: root/crypto/src/asn1/pkcs/CertificationRequestInfo.cs
blob: 38d2d39ddeb0fb5b7509b2df4e1b3c00eb3bc89b (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
using System;

using Org.BouncyCastle.Asn1.X509;

namespace Org.BouncyCastle.Asn1.Pkcs
{
    /**
     * Pkcs10 CertificationRequestInfo object.
     * <pre>
     *  CertificationRequestInfo ::= Sequence {
     *   version             Integer { v1(0) } (v1,...),
     *   subject             Name,
     *   subjectPKInfo   SubjectPublicKeyInfo{{ PKInfoAlgorithms }},
     *   attributes          [0] Attributes{{ CRIAttributes }}
     *  }
     *
     *  Attributes { ATTRIBUTE:IOSet } ::= Set OF Attr{{ IOSet }}
     *
     *  Attr { ATTRIBUTE:IOSet } ::= Sequence {
     *    type    ATTRIBUTE.&amp;id({IOSet}),
     *    values  Set SIZE(1..MAX) OF ATTRIBUTE.&amp;Type({IOSet}{\@type})
     *  }
     * </pre>
     */
    public class CertificationRequestInfo
        : Asn1Encodable
    {
		public static CertificationRequestInfo GetInstance(object obj)
        {
            if (obj == null)
                return null;
            if (obj is CertificationRequestInfo certificationRequestInfo)
                return certificationRequestInfo;
            return new CertificationRequestInfo(Asn1Sequence.GetInstance(obj));
		}

        public static CertificationRequestInfo GetInstance(Asn1TaggedObject taggedObject, bool declaredExplicit)
        {
            return new CertificationRequestInfo(Asn1Sequence.GetInstance(taggedObject, declaredExplicit));
        }

        private readonly DerInteger m_version;
        private readonly X509Name m_subject;
        private readonly SubjectPublicKeyInfo m_subjectPKInfo;
        private readonly Asn1Set m_attributes;

        public CertificationRequestInfo(X509Name subject, SubjectPublicKeyInfo pkInfo, Asn1Set attributes)
        {
            m_version = DerInteger.Zero;
            m_subject = subject ?? throw new ArgumentNullException(nameof(subject));
            m_subjectPKInfo = pkInfo ?? throw new ArgumentNullException(nameof(pkInfo));
            m_attributes = ValidateAttributes(attributes);
        }

		private CertificationRequestInfo(Asn1Sequence seq)
        {
            int count = seq.Count, pos = 0;
            if (count < 3 || count > 4)
                throw new ArgumentException("Bad sequence size: " + count, nameof(seq));

            m_version = DerInteger.GetInstance(seq[pos++]);
            m_subject = X509Name.GetInstance(seq[pos++]);
            m_subjectPKInfo = SubjectPublicKeyInfo.GetInstance(seq[pos++]);

            // NOTE: some CertificationRequestInfo objects seem to treat this field as optional.
            m_attributes = Asn1Utilities.ReadOptionalContextTagged(seq, ref pos, 0, false, Asn1Set.GetTagged);

            if (pos != count)
                throw new ArgumentException("Unexpected elements in sequence", nameof(seq));

            ValidateAttributes(m_attributes);
        }

        public DerInteger Version => m_version;

        public X509Name Subject => m_subject;

        public SubjectPublicKeyInfo SubjectPublicKeyInfo => m_subjectPKInfo;

        public Asn1Set Attributes => m_attributes;

        public override Asn1Object ToAsn1Object()
        {
            Asn1EncodableVector v = new Asn1EncodableVector(4);
            v.Add(m_version, m_subject, m_subjectPKInfo);
            v.AddOptionalTagged(false, 0, m_attributes);
            return new DerSequence(v);
        }

        private static Asn1Set ValidateAttributes(Asn1Set attributes)
        {
            if (attributes != null)
            {
                foreach (var element in attributes)
                {
                    AttributePkcs attr = AttributePkcs.GetInstance(element);
                    if (PkcsObjectIdentifiers.Pkcs9AtChallengePassword.Equals(attr.AttrType))
                    {
                        if (attr.AttrValues.Count != 1)
                            throw new ArgumentException("challengePassword attribute must have one value");
                    }
                }
            }
            return attributes;
        }
    }
}