Re: Thoughts on a new mscng backend

Miklos Vajna <[email protected]> Tue, 8 May 2018 18:38:56 +0200
Newsgroups gmane.text.xml.xmlsec
Message-ID <[email protected]>
--===============1608672335==
Content-Type: multipart/signed; micalg=pgp-sha1;
	protocol="application/pgp-signature"; boundary="xwsfqd4pkughvude"
Content-Disposition: inline


--xwsfqd4pkughvude
Content-Type: multipart/mixed; boundary="qaqzhdljdesrcb3v"
Content-Disposition: inline


--qaqzhdljdesrcb3v
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline

Hi,

On Fri, May 04, 2018 at 05:33:58PM +0200, Miklos Vajna <[email protected]> wrote:
> - mscrypto supports reading your OS-level certificates and use that
>   during e.g. signing.

I looked at this, and it took me a bit of code reading to find out how
to trigger this functionality in the nss / mscrypto backends. I attach a
signature template that does what I was looking for.

I wonder, would it make sense to include this in git under examples/?
That (as a first step) would allow easy manual testing, provided that
the cert store is set up to provide a key named "My-RSA-Key".

Regards,

Miklos

--qaqzhdljdesrcb3v
Content-Type: application/xml
Content-Disposition: attachment; filename="keysstore.xml"
Content-Transfer-Encoding: quoted-printable

<?xml version=3D"1.0" encoding=3D"UTF-8"?>=0A<Signature xmlns=3D"http://www=
=2Ew3.org/2000/09/xmldsig#">=0A  <SignedInfo>=0A    <CanonicalizationMethod=
 Algorithm=3D"http://www.w3.org/TR/2001/REC-xml-c14n-20010315" />=0A    <Si=
gnatureMethod Algorithm=3D"http://www.w3.org/2001/04/xmldsig-more#rsa-sha25=
6"/>=0A    <Reference URI=3D"#object">=0A      <DigestMethod Algorithm=3D"h=
ttp://www.w3.org/2001/04/xmlenc#sha256"/>=0A      <DigestValue></DigestValu=
e>=0A    </Reference>=0A  </SignedInfo>=0A  <SignatureValue>=0A  </Signatur=
eValue>=0A  <KeyInfo>=0A    <KeyName>My-RSA-Key</KeyName>=0A  </KeyInfo>=0A=
  <Object Id=3D"object">some text</Object>=0A</Signature>=0A
--qaqzhdljdesrcb3v--

--xwsfqd4pkughvude
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iEYEARECAAYFAlrx0p8ACgkQe81tAgORUJaSxQCaAyU4HC0acJZMj8U6NQ+AWuoz
g7wAmQFO0k7XvCr1ySDXzBR1P+0JA8Gw
=Ztgz
-----END PGP SIGNATURE-----

--xwsfqd4pkughvude--

--===============1608672335==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KeG1sc2VjIG1h
aWxpbmcgbGlzdAp4bWxzZWNAYWxla3NleS5jb20KaHR0cDovL3d3dy5hbGVrc2V5LmNvbS9tYWls
bWFuL2xpc3RpbmZvL3htbHNlYwo=

--===============1608672335==--