v1.1 SFL Now Available

"Pawling, John" <[email protected]>
Newsgroups gmane.ietf.sfl
Message-ID <33BD629222C0D211B6DB0060085ACF31360A00@WFHQEX03>
All,

J.G. Van Dyke and Associates (VDA) has delivered Version 1.1 of the S/MIME 
Freeware Library (SFL).  The v1.1 SFL implements the IETF S/MIME v3 RFC 2630

Cryptographic Message Syntax (CMS) and RFC 2634 Enhanced Security Services
(ESS) specifications.  It also implements portions of the RFC 2633 Message
Specification and RFC 2632 Certificate Handling document.  When used in
conjunction with the Crypto++ freeware library, the SFL implements the
RFC 2631 Diffie-Hellman (D-H) Key Agreement Method specification.  It has
been successfully tested using the MS Windows NT/95/98 and Solaris 2.6 
operating systems.  Further enhancements, ports and testing of the SFL are
still in process.  Further releases of the SFL will be provided as
significant capabilities are added. 

The v1.1 SFL has been successfully used to sign, verify, encrypt and decrypt

CMS/ESS objects using the mandatory algorithms (DSA, E-S D-H, 3DES) 
provided by the Crypto++ 3.1 library and SHA-1 provided by
Government-furnished 
freeware.  The v1.1 SFL has also been used to sign, verify, encrypt 
and decrypt CMS/ESS objects using the RSA suite of algorithms provided by 
the RSA BSAFE v3.0 library. The SFL uses the VDA-enhanced SNACC v1.3 ASN.1 
Library to encode/decode objects. The v1.1 SFL release includes: SFL
High-level library; SFL Crypto++ Crypto Token Interface Library (CTIL);
BSAFE CTIL; Fortezza CTIL; SPEX/ CTIL; VDA-enhanced GNU SNACC v1.3 rev 0.07
ASN.1 Compiler and Library; test drivers and test data.

The SFL has been successfully used to exchange signedData and envelopedData 
messages with the Microsoft (MS) Internet Explorer Outlook Express v4.01 and

Netscape Communicator 4.X S/MIME v2 products.  Signed messages have been 
exchanged with the RSA S/MAIL, WorldTalk and Entrust S/MIME v2 products. 

The SFL has also been used to perform S/MIME v3 interoperability testing
with
Microsoft that exercised the majority of the features specified by RFCs
2630,
2631 and 2634.  We still need to perform signed receipt testing with
Microsoft.
We have also performed limited S/MIME v3 testing with Baltimore and Entrust.

We also plan to participate in the IETF S/MIME WG interoperability testing
including providing data for inclusion in the "Examples of S/MIME Messages"
document.

The following enhancements are included in the v1.1 SFL release (compared 
with the v1.0 release):

1) CTILs have been delivered in a separate zip file.  This allows them 
   to be delivered independently of the SFL and Certificate Management
   Library (CML) deliveries.

2) Several of the libraries have been converted to Dynamically Linked 
   Libraries (DLL)/shared objects.  There is a separate ReadmeDLL.txt file
   that provides examples of how to use the DLLs with the autoHi test
driver.
   These libraries have been delivered:
   a) libsm (static library) includes SFL hilevel, lolevel, asn1 functions.
      Note: If customers would like this library to be converted into a DLL
       in a future release of the SFL, please let us know. 
   b) libCert (static library) includes functions relating to certificates 
      that are called by SFL and CML. This library will be converted into
      a DLL in a later SFL release.
   c) snacc32.dll (DLL/shared object) - Called by SFL and CML.
   d) Test (no crypto), BSAFE, Crypto++, SPEX/ and Fortezza CTILs are
      DLLs/shared objects.  They are be called by SFL and CML.  

3) Fortezza CTIL testing using MS Windows using the Government-furnished 
   v1.52 Fortezza CI Library and a Fortezza Card has been completed
including 
   login, sign/verify and encrypt/decrypt capabilities.  Also, we 
   signed/verified and encrypted/decrypted using the Fortezza CTIL using a
   Spyrus Lynks Card using the Fortezza algorithms.

4) SPEX/ CTIL testing using MS Windows has been completed for login and
   sign/verify (RSA and DSA) functions.  It was tested with the Spyrus SPEX/
   Library v1.52b Release 7b, Spyrus Lynks Card and X.509 v3 Certificates 
   created by the Spyrus S2CA.  Encrypt/decrypt capabilities are not yet
   completely tested.  We signed/verified and encrypted/decrypted using the
   SPEX/ CTIL using a Fortezza Card.

5) Crypto++ (a.k.a Free) CTIL testing using MS Windows completed using 
   Crypto++ 3.1 library.  We had to fix a bug in the Crypto++ 3.1 library 
   to make it work correctly (see below).
 
Note: The Crypto++, SPEX/ and Fortezza CTILs will be tested using 
      Solaris 2.6.  If there are any changes required, then new CTILs
      will be delivered. 

6) Completed enhancing the BSAFE CTIL to store the user's private keys in an
   encrypted form using PKCS #8.  Tested using MS Windows and Solaris 2.6.

7) Finished implementation and testing of the EncryptedData content type.

8) Enhanced Crypto++ 3.1 CTIL to use RC2 algorithm provided by Crypto++ 3.1.
   We used the RC2 algorithm provided by the Crypto++ 3.1 library to decrypt
   data that was encrypted using the RSA BSAFE v3.0 library (and vice
versa).

9) Added code to check for erroneous attributes included in signed, 
   authenticated, unsigned, unauthenticated and unprotected attributes.

10) Developed new test code and configuration files to implement test cases.

11) Performed regression testing to ensure that aforementioned enhancements
    did not break existing SFL functionality.

We delivered the following documents:
1) v1.1 SFL Application Programming Interface (API), 6 August 1999
2) v1.1 CTIL API, 5 August 1999 
3) v1.1 SFL Software Design Description, 3 August 1999
4) v1.1 SFL Software Test Description, 6 August 1999
5) v1.1 SFL Implementers Guide, 9 August 1999
6) SFL Fact Sheet, 30 July 1999
7) SFL Overview Briefing, 2 August 1999

We are still in the process of enhancing and testing the SFL.    
Future releases will include: libCert library converted to DLL/shared 
object; enhanced error reporting; countersignatures; SPEX/ CTIL 
encrypt/decrypt capabilities; PKCS #11 CTIL; enhance Crypto++ 3.1 CTIL
to use RSA algorithm provided by Crypto++ 3.1 library; add 
sMIMEEncryptionKeyPreference attribute; additional helper functions; 
add support for certificate request message generation (TBD); enhanced
test routines; bug fixes; support for other crypto APIs (possible); and
support for other operating systems.  We will enhance the utilities to 
generate certificates to be used as test data.  We do not plan to further
enhance the SFL "C" API capabilities unless specifically requested. 

The SFL software is developed to maximize portability to 32-bit 
operating systems.  We plan to port the SFL to the following 
operating systems: Linux, HP/UX 9.x/10.x, IBM AIX 3.2,
SCO ODT 3.0/5.0 (possibly) and Macintosh (possibly).

The IMC has established an SFL web page (http://www.imc.org/imc-sfl) 
which includes links to the SFL files stored on the VDA SFL Page 
(http://www.jgvandyke.com/services/infosec/sfl.htm) and on the 
Fortezza Developer's S/MIME Page 
(http://www.armadillo.huntsville.al.us/software/smime).  

The VDA-enhanced SNACC ASN.1 software and SFL documentation are freely
available to everyone at the VDA SFL Page.  All other portions of the SFL
software are export controlled in accordance with the U.S. Government Export

Administration Regulations.  For specific details and guidance on 
exporting the SFL software, contact the U.S. Department of Commerce,
Bureau of Export Administration, Export Counseling Division, (202) 
482-4811.  The Bureau of Export Administration maintains additional 
resources online on its Commercial Encryption Export Controls page 
(http://www.bxa.doc.gov/Encryption/Default.htm).

Instructions for applying for an account on the Fortezza Developer's
S/MIME Page are available from that page.  An account is required to
download the SFL files from the Fortezza Developer's S/MIME Page due
to U.S. export restrictions.         
      

The following SFL files are not export-controlled.  They are available 
at the Fortezza Developer's S/MIME Page and VDA SFL Page:

Note: The VDA SFL Page has not yet been updated, but all files are
available from the Fortezza Developer's S/MIME Page. 

1) SFL Documents: Fact Sheet, Software Design Description, API, CTI API,
Software Test Description, Implementers Guide, Overview Briefing and 
Public License.
     
2) snaccvda07.zip: Zip file containing SNACC v1.3 rev 0.07 ASN.1 Compiler
and Library source code compilable for Unix and MS Windows NT/95/98 that 
has been enhanced by VDA to implement the Distinguished Encoding Rules.
Project files and makefiles are included.  This file includes a sample 
test project demonstrating the use of the SNACC classes.


The following SFL files are export controlled and are available at the 
Fortezza Developer's S/MIME Page:

1) smimeR11.zip:  Zip file containing all SFL source code including: 
SFL Hi-Level source code; VDA-enhanced SNACC-generated ASN.1 source 
code; project files.  This file also contains test driver source code, 
sample CMS/ESS test data and test X.509 Certificates.  This file also 
includes test utilities to create X.509 Certificates that each include 
a D-H, DSA or RSA public key.  SNACC release and debug libraries
are compiled for MS Windows NT/95/98. MS Windows NT/95/98
project files and Unix makefiles are included for the SNACC code, 
MIME++ and Crypto++.  Note that the Crypto++ and MIME++ libraries are not
included.  See (http://www.eskimo.com/~weidai/cryptlib.html) and
(http://hunnysoft.com/mimepp/) for these two libraries. 

When building the Crypto++3.1 library be sure to set the Visual C++ project
settings to include the "(Debug) Multithreaded DLL" C/C++ compiler option
for
proper compatibility with the other SFL code.  In addition, the following 
code change is necessary in the Crypto++ 3.1 code to properly run it with
the sm_Free3 CTIL:

IN FILE "cbc.cpp"
...
void CBC_CTS_Encryptor::Put(byte inByte)
{
	//RWC;if (counter == S)
	//RWC;	ProcessBuf();
	buffer[counter] = reg[counter] ^ inByte;
	counter++;
   if (counter == S)//RWC;Added
		ProcessBuf();

}
...
void CBC_CTS_Decryptor::Put(byte inByte)
{
	//RWC;if (counter == S)
	//RWC;	ProcessBuf();
	buffer2[counter++] = inByte;
   if (counter == S)//RWC;Added
		ProcessBuf();
}
...

2) smR11CTI.zip:  Source code for the following CTILs:
Test (no crypto), Crypto++, BSAFE, Fortezza and SPEX/. 
The Win95/98/NT projects are also included.

3) csmime.mdl contains SFL Class diagrams created using Microsoft 
Visual Modeler (comes with MS Visual Studio 6.0, Enterprise Tools).
The file can also be viewed using Rational Rose C++ Demo 4.0
45 day evaluation copy which can be obtained from
http://www.rational.com/uml/resources/practice_uml/index.jtmpl.
Not all classes are documented in the MDL file at this time.

All source code for the SFL is being provided at no cost and with no 
financial limitations regarding its use and distribution. 
Organizations can use the SFL without paying any royalties or 
licensing fees.  VDA is developing the SFL under contract to the U.S. 
Government.  The U.S. Government is furnishing the SFL software at no 
cost to the vendor subject to the conditions of the "SFL Public 
License" available from the VDA SFL Page and Fortezza Developer's 
S/MIME Page.

The SFL is composed of a high-level library that performs generic CMS 
and ESS processing independent of the crypto algorithms used to 
protect a specific object.  The SFL high-level library makes calls to 
an algorithm-independent CTIL API.  The underlying, external crypto
token libraries are not distributed as part of the SFL 
source code. The application developer must independently obtain these 
libraries and then link them with the SFL.  For example, the SFL uses 
the freeware Crypto++ library to obtain 3DES, D-H and DSA.  To use 
the SFL with Crypto++ the vendor must download the Crypto++ freeware 
library from the Crypto++ Web Page and then compile it with the  
VDA-developed Crypto++ CTIL source code.  

The IMC has established an SFL mail list which is used to: distribute 
information regarding SFL releases; discuss SFL-related issues; and 
provide a means for SFL users to provide feedback, comments, bug 
reports, etc.  Subscription information for the imc-sfl mailing list 
is at the IMC web site listed above.

All comments regarding the SFL software and documents are welcome.  We 
recommend that comments should be sent to the imc-sfl mail list.  We 
will respond to all messages on that list.

===================================
John Pawling, [email protected]                             
J.G. Van Dyke & Associates, Inc.,
a Wang Government Services Company
www.jgvandyke.com         
===================================
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.