v1.1 SFL Now Available
"Pawling, John" <[email protected]>
| Newsgroups | gmane.ietf.sfl |
|---|---|
| Message-ID | <33BD629222C0D211B6DB0060085ACF31360A00@WFHQEX03> |
All,
J.G. Van Dyke and Associates (VDA) has delivered Version 1.1 of the S/MIME
Freeware Library (SFL). The v1.1 SFL implements the IETF S/MIME v3 RFC 2630
Cryptographic Message Syntax (CMS) and RFC 2634 Enhanced Security Services
(ESS) specifications. It also implements portions of the RFC 2633 Message
Specification and RFC 2632 Certificate Handling document. When used in
conjunction with the Crypto++ freeware library, the SFL implements the
RFC 2631 Diffie-Hellman (D-H) Key Agreement Method specification. It has
been successfully tested using the MS Windows NT/95/98 and Solaris 2.6
operating systems. Further enhancements, ports and testing of the SFL are
still in process. Further releases of the SFL will be provided as
significant capabilities are added.
The v1.1 SFL has been successfully used to sign, verify, encrypt and decrypt
CMS/ESS objects using the mandatory algorithms (DSA, E-S D-H, 3DES)
provided by the Crypto++ 3.1 library and SHA-1 provided by
Government-furnished
freeware. The v1.1 SFL has also been used to sign, verify, encrypt
and decrypt CMS/ESS objects using the RSA suite of algorithms provided by
the RSA BSAFE v3.0 library. The SFL uses the VDA-enhanced SNACC v1.3 ASN.1
Library to encode/decode objects. The v1.1 SFL release includes: SFL
High-level library; SFL Crypto++ Crypto Token Interface Library (CTIL);
BSAFE CTIL; Fortezza CTIL; SPEX/ CTIL; VDA-enhanced GNU SNACC v1.3 rev 0.07
ASN.1 Compiler and Library; test drivers and test data.
The SFL has been successfully used to exchange signedData and envelopedData
messages with the Microsoft (MS) Internet Explorer Outlook Express v4.01 and
Netscape Communicator 4.X S/MIME v2 products. Signed messages have been
exchanged with the RSA S/MAIL, WorldTalk and Entrust S/MIME v2 products.
The SFL has also been used to perform S/MIME v3 interoperability testing
with
Microsoft that exercised the majority of the features specified by RFCs
2630,
2631 and 2634. We still need to perform signed receipt testing with
Microsoft.
We have also performed limited S/MIME v3 testing with Baltimore and Entrust.
We also plan to participate in the IETF S/MIME WG interoperability testing
including providing data for inclusion in the "Examples of S/MIME Messages"
document.
The following enhancements are included in the v1.1 SFL release (compared
with the v1.0 release):
1) CTILs have been delivered in a separate zip file. This allows them
to be delivered independently of the SFL and Certificate Management
Library (CML) deliveries.
2) Several of the libraries have been converted to Dynamically Linked
Libraries (DLL)/shared objects. There is a separate ReadmeDLL.txt file
that provides examples of how to use the DLLs with the autoHi test
driver.
These libraries have been delivered:
a) libsm (static library) includes SFL hilevel, lolevel, asn1 functions.
Note: If customers would like this library to be converted into a DLL
in a future release of the SFL, please let us know.
b) libCert (static library) includes functions relating to certificates
that are called by SFL and CML. This library will be converted into
a DLL in a later SFL release.
c) snacc32.dll (DLL/shared object) - Called by SFL and CML.
d) Test (no crypto), BSAFE, Crypto++, SPEX/ and Fortezza CTILs are
DLLs/shared objects. They are be called by SFL and CML.
3) Fortezza CTIL testing using MS Windows using the Government-furnished
v1.52 Fortezza CI Library and a Fortezza Card has been completed
including
login, sign/verify and encrypt/decrypt capabilities. Also, we
signed/verified and encrypted/decrypted using the Fortezza CTIL using a
Spyrus Lynks Card using the Fortezza algorithms.
4) SPEX/ CTIL testing using MS Windows has been completed for login and
sign/verify (RSA and DSA) functions. It was tested with the Spyrus SPEX/
Library v1.52b Release 7b, Spyrus Lynks Card and X.509 v3 Certificates
created by the Spyrus S2CA. Encrypt/decrypt capabilities are not yet
completely tested. We signed/verified and encrypted/decrypted using the
SPEX/ CTIL using a Fortezza Card.
5) Crypto++ (a.k.a Free) CTIL testing using MS Windows completed using
Crypto++ 3.1 library. We had to fix a bug in the Crypto++ 3.1 library
to make it work correctly (see below).
Note: The Crypto++, SPEX/ and Fortezza CTILs will be tested using
Solaris 2.6. If there are any changes required, then new CTILs
will be delivered.
6) Completed enhancing the BSAFE CTIL to store the user's private keys in an
encrypted form using PKCS #8. Tested using MS Windows and Solaris 2.6.
7) Finished implementation and testing of the EncryptedData content type.
8) Enhanced Crypto++ 3.1 CTIL to use RC2 algorithm provided by Crypto++ 3.1.
We used the RC2 algorithm provided by the Crypto++ 3.1 library to decrypt
data that was encrypted using the RSA BSAFE v3.0 library (and vice
versa).
9) Added code to check for erroneous attributes included in signed,
authenticated, unsigned, unauthenticated and unprotected attributes.
10) Developed new test code and configuration files to implement test cases.
11) Performed regression testing to ensure that aforementioned enhancements
did not break existing SFL functionality.
We delivered the following documents:
1) v1.1 SFL Application Programming Interface (API), 6 August 1999
2) v1.1 CTIL API, 5 August 1999
3) v1.1 SFL Software Design Description, 3 August 1999
4) v1.1 SFL Software Test Description, 6 August 1999
5) v1.1 SFL Implementers Guide, 9 August 1999
6) SFL Fact Sheet, 30 July 1999
7) SFL Overview Briefing, 2 August 1999
We are still in the process of enhancing and testing the SFL.
Future releases will include: libCert library converted to DLL/shared
object; enhanced error reporting; countersignatures; SPEX/ CTIL
encrypt/decrypt capabilities; PKCS #11 CTIL; enhance Crypto++ 3.1 CTIL
to use RSA algorithm provided by Crypto++ 3.1 library; add
sMIMEEncryptionKeyPreference attribute; additional helper functions;
add support for certificate request message generation (TBD); enhanced
test routines; bug fixes; support for other crypto APIs (possible); and
support for other operating systems. We will enhance the utilities to
generate certificates to be used as test data. We do not plan to further
enhance the SFL "C" API capabilities unless specifically requested.
The SFL software is developed to maximize portability to 32-bit
operating systems. We plan to port the SFL to the following
operating systems: Linux, HP/UX 9.x/10.x, IBM AIX 3.2,
SCO ODT 3.0/5.0 (possibly) and Macintosh (possibly).
The IMC has established an SFL web page (http://www.imc.org/imc-sfl)
which includes links to the SFL files stored on the VDA SFL Page
(http://www.jgvandyke.com/services/infosec/sfl.htm) and on the
Fortezza Developer's S/MIME Page
(http://www.armadillo.huntsville.al.us/software/smime).
The VDA-enhanced SNACC ASN.1 software and SFL documentation are freely
available to everyone at the VDA SFL Page. All other portions of the SFL
software are export controlled in accordance with the U.S. Government Export
Administration Regulations. For specific details and guidance on
exporting the SFL software, contact the U.S. Department of Commerce,
Bureau of Export Administration, Export Counseling Division, (202)
482-4811. The Bureau of Export Administration maintains additional
resources online on its Commercial Encryption Export Controls page
(http://www.bxa.doc.gov/Encryption/Default.htm).
Instructions for applying for an account on the Fortezza Developer's
S/MIME Page are available from that page. An account is required to
download the SFL files from the Fortezza Developer's S/MIME Page due
to U.S. export restrictions.
The following SFL files are not export-controlled. They are available
at the Fortezza Developer's S/MIME Page and VDA SFL Page:
Note: The VDA SFL Page has not yet been updated, but all files are
available from the Fortezza Developer's S/MIME Page.
1) SFL Documents: Fact Sheet, Software Design Description, API, CTI API,
Software Test Description, Implementers Guide, Overview Briefing and
Public License.
2) snaccvda07.zip: Zip file containing SNACC v1.3 rev 0.07 ASN.1 Compiler
and Library source code compilable for Unix and MS Windows NT/95/98 that
has been enhanced by VDA to implement the Distinguished Encoding Rules.
Project files and makefiles are included. This file includes a sample
test project demonstrating the use of the SNACC classes.
The following SFL files are export controlled and are available at the
Fortezza Developer's S/MIME Page:
1) smimeR11.zip: Zip file containing all SFL source code including:
SFL Hi-Level source code; VDA-enhanced SNACC-generated ASN.1 source
code; project files. This file also contains test driver source code,
sample CMS/ESS test data and test X.509 Certificates. This file also
includes test utilities to create X.509 Certificates that each include
a D-H, DSA or RSA public key. SNACC release and debug libraries
are compiled for MS Windows NT/95/98. MS Windows NT/95/98
project files and Unix makefiles are included for the SNACC code,
MIME++ and Crypto++. Note that the Crypto++ and MIME++ libraries are not
included. See (http://www.eskimo.com/~weidai/cryptlib.html) and
(http://hunnysoft.com/mimepp/) for these two libraries.
When building the Crypto++3.1 library be sure to set the Visual C++ project
settings to include the "(Debug) Multithreaded DLL" C/C++ compiler option
for
proper compatibility with the other SFL code. In addition, the following
code change is necessary in the Crypto++ 3.1 code to properly run it with
the sm_Free3 CTIL:
IN FILE "cbc.cpp"
...
void CBC_CTS_Encryptor::Put(byte inByte)
{
//RWC;if (counter == S)
//RWC; ProcessBuf();
buffer[counter] = reg[counter] ^ inByte;
counter++;
if (counter == S)//RWC;Added
ProcessBuf();
}
...
void CBC_CTS_Decryptor::Put(byte inByte)
{
//RWC;if (counter == S)
//RWC; ProcessBuf();
buffer2[counter++] = inByte;
if (counter == S)//RWC;Added
ProcessBuf();
}
...
2) smR11CTI.zip: Source code for the following CTILs:
Test (no crypto), Crypto++, BSAFE, Fortezza and SPEX/.
The Win95/98/NT projects are also included.
3) csmime.mdl contains SFL Class diagrams created using Microsoft
Visual Modeler (comes with MS Visual Studio 6.0, Enterprise Tools).
The file can also be viewed using Rational Rose C++ Demo 4.0
45 day evaluation copy which can be obtained from
http://www.rational.com/uml/resources/practice_uml/index.jtmpl.
Not all classes are documented in the MDL file at this time.
All source code for the SFL is being provided at no cost and with no
financial limitations regarding its use and distribution.
Organizations can use the SFL without paying any royalties or
licensing fees. VDA is developing the SFL under contract to the U.S.
Government. The U.S. Government is furnishing the SFL software at no
cost to the vendor subject to the conditions of the "SFL Public
License" available from the VDA SFL Page and Fortezza Developer's
S/MIME Page.
The SFL is composed of a high-level library that performs generic CMS
and ESS processing independent of the crypto algorithms used to
protect a specific object. The SFL high-level library makes calls to
an algorithm-independent CTIL API. The underlying, external crypto
token libraries are not distributed as part of the SFL
source code. The application developer must independently obtain these
libraries and then link them with the SFL. For example, the SFL uses
the freeware Crypto++ library to obtain 3DES, D-H and DSA. To use
the SFL with Crypto++ the vendor must download the Crypto++ freeware
library from the Crypto++ Web Page and then compile it with the
VDA-developed Crypto++ CTIL source code.
The IMC has established an SFL mail list which is used to: distribute
information regarding SFL releases; discuss SFL-related issues; and
provide a means for SFL users to provide feedback, comments, bug
reports, etc. Subscription information for the imc-sfl mailing list
is at the IMC web site listed above.
All comments regarding the SFL software and documents are welcome. We
recommend that comments should be sent to the imc-sfl mail list. We
will respond to all messages on that list.
===================================
John Pawling, [email protected]
J.G. Van Dyke & Associates, Inc.,
a Wang Government Services Company
www.jgvandyke.com
===================================