Re: Thoughts on a new mscng backend
Dmitry Belyavsky <[email protected]> Mon, 7 May 2018 10:23:43 +0300
| Newsgroups | gmane.text.xml.xmlsec |
|---|---|
| Message-ID | <CADqLbzKJQUGP=PhgG9Fa3zXXO08eszbjZ5JdpWdHw4C=cte4Sg@mail.gmail.com> |
--===============0182175333== Content-Type: multipart/alternative; boundary="000000000000c4ddb1056b988c62" --000000000000c4ddb1056b988c62 Content-Type: text/plain; charset="UTF-8" I'll ask whether there is any CNG-based GOST implementation. On Sat, May 5, 2018 at 5:08 AM, Aleksey Sanin <[email protected]> wrote: > Thanks for all the code you've wrote! > > I think the only area missing is GOST algorithms support. It > requires special configs/dlls on Windows so I don't know if > it is even available for MSCNG. May be someone on the list > has direct knowledge and can chime in? > > I was planning to ask you what would be the right time to do > an xmlsec release. Sounds like in a couple weeks is the right > timeline. I think it would be great to have others play with > mscng to find out any issues. But otherwise, it looks great! > > Aleksey > > On 5/4/18 8:33 AM, Miklos Vajna wrote: > > Hi, > > > > On Thu, Jan 04, 2018 at 03:24:51PM -0800, Aleksey Sanin < > [email protected]> wrote: > >> That sounds like a great plan! I would recommend to use the > >> skeleton folder to start. > > > > Thanks for all the reviews, current master looks reasonable to me when I > > compare 'make check' output of the mscrypto and mscng backends: > > > > - 0 tests pass only on mscrypto > > - 126 tests pass on both mscrypto and mscng > > - 3 tests pass only on mscng (ecdsa signing with sha1/256/512) > > > > I wonder what else is missing so it could be claimed that the mscng > > backend is more or less a drop-in replacement for the mscrypto one. > > There are two things I can think of: > > > > - mscrypto supports reading your OS-level certificates and use that > > during e.g. signing. > > > > - There are a few functions which are part of the mscrypto public API > > (e.g. xmlSecMSCryptoX509StoreAdoptKeyStore()) and there is no mscng > > equivalent yet. Those are probably interesting as e.g. LibreOffice > > uses those functions. > > > > I plan to get to these two in the next few weeks. But is there anything > > else larger missing? > > > > Thanks, > > > > Miklos > > > > > > > > _______________________________________________ > > xmlsec mailing list > > [email protected] > > http://www.aleksey.com/mailman/listinfo/xmlsec > > > _______________________________________________ > xmlsec mailing list > [email protected] > http://www.aleksey.com/mailman/listinfo/xmlsec > -- SY, Dmitry Belyavsky --000000000000c4ddb1056b988c62 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">I'll ask whether there is any CNG-based GOST implement= ation.</div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">On Sa= t, May 5, 2018 at 5:08 AM, Aleksey Sanin <span dir=3D"ltr"><<a href=3D"m= ailto:[email protected]" target=3D"_blank">[email protected]</a>></s= pan> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex= ;border-left:1px #ccc solid;padding-left:1ex">Thanks for all the code you&#= 39;ve wrote!<br> <br> I think the only area missing is GOST algorithms support. It<br> requires special configs/dlls on Windows so I don't know if<br> it is even available for MSCNG. May be someone on the list<br> has direct knowledge and can chime in?<br> <br> I was planning to ask you what would be the right time to do<br> an xmlsec release. Sounds like in a couple weeks is the right<br> timeline. I think it would be great to have others play with<br> mscng to find out any issues. But otherwise, it looks great!<br> <span class=3D"HOEnZb"><font color=3D"#888888"><br> Aleksey<br> </font></span><div class=3D"HOEnZb"><div class=3D"h5"><br> On 5/4/18 8:33 AM, Miklos Vajna wrote:<br> > Hi,<br> > <br> > On Thu, Jan 04, 2018 at 03:24:51PM -0800, Aleksey Sanin <<a href=3D= "mailto:[email protected]">[email protected]</a>> wrote:<br> >> That sounds like a great plan! I would recommend to use the<br> >> skeleton folder to start.<br> > <br> > Thanks for all the reviews, current master looks reasonable to me when= I<br> > compare 'make check' output of the mscrypto and mscng backends= :<br> > <br> > - 0 tests pass only on mscrypto<br> > - 126 tests pass on both mscrypto and mscng<br> > - 3 tests pass only on mscng (ecdsa signing with sha1/256/512)<br> > <br> > I wonder what else is missing so it could be claimed that the mscng<br= > > backend is more or less a drop-in replacement for the mscrypto one.<br= > > There are two things I can think of:<br> > <br> > - mscrypto supports reading your OS-level certificates and use that<br= > >=C2=A0 =C2=A0during e.g. signing.<br> > <br> > - There are a few functions which are part of the mscrypto public API<= br> >=C2=A0 =C2=A0(e.g. xmlSecMSCryptoX509StoreAdoptKe<wbr>yStore()) and the= re is no mscng<br> >=C2=A0 =C2=A0equivalent yet. Those are probably interesting as e.g. Lib= reOffice<br> >=C2=A0 =C2=A0uses those functions.<br> > <br> > I plan to get to these two in the next few weeks. But is there anythin= g<br> > else larger missing?<br> > <br> > Thanks,<br> > <br> > Miklos<br> > <br> > <br> > <br> </div></div><div class=3D"HOEnZb"><div class=3D"h5">> __________________= ____________<wbr>_________________<br> > xmlsec mailing list<br> > <a href=3D"mailto:[email protected]">[email protected]</a><br> > <a href=3D"http://www.aleksey.com/mailman/listinfo/xmlsec" rel=3D"nore= ferrer" target=3D"_blank">http://www.aleksey.com/<wbr>mailman/listinfo/xmls= ec</a><br> > <br> ______________________________<wbr>_________________<br> xmlsec mailing list<br> <a href=3D"mailto:[email protected]">[email protected]</a><br> <a href=3D"http://www.aleksey.com/mailman/listinfo/xmlsec" rel=3D"noreferre= r" target=3D"_blank">http://www.aleksey.com/<wbr>mailman/listinfo/xmlsec</a= ><br> </div></div></blockquote></div><br><br clear=3D"all"><div><br></div>-- <br>= <div class=3D"gmail_signature" data-smartmail=3D"gmail_signature">SY, Dmitr= y Belyavsky</div> </div> --000000000000c4ddb1056b988c62-- --===============0182175333== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KeG1sc2VjIG1h aWxpbmcgbGlzdAp4bWxzZWNAYWxla3NleS5jb20KaHR0cDovL3d3dy5hbGVrc2V5LmNvbS9tYWls bWFuL2xpc3RpbmZvL3htbHNlYwo= --===============0182175333==--