1 | <?php |
||
22 | class AttributeCertificate |
||
23 | { |
||
24 | /** |
||
25 | * Attribute certificate info. |
||
26 | * |
||
27 | * @var AttributeCertificateInfo |
||
28 | */ |
||
29 | protected $_acinfo; |
||
30 | |||
31 | /** |
||
32 | * Signature algorithm identifier. |
||
33 | * |
||
34 | * @var SignatureAlgorithmIdentifier |
||
35 | */ |
||
36 | protected $_signatureAlgorithm; |
||
37 | |||
38 | /** |
||
39 | * Signature value. |
||
40 | * |
||
41 | * @var Signature |
||
42 | */ |
||
43 | protected $_signatureValue; |
||
44 | |||
45 | /** |
||
46 | * Constructor. |
||
47 | * |
||
48 | * @param AttributeCertificateInfo $acinfo |
||
49 | * @param SignatureAlgorithmIdentifier $algo |
||
50 | * @param Signature $signature |
||
51 | */ |
||
52 | 5 | public function __construct(AttributeCertificateInfo $acinfo, |
|
53 | SignatureAlgorithmIdentifier $algo, Signature $signature) |
||
54 | { |
||
55 | 5 | $this->_acinfo = $acinfo; |
|
56 | 5 | $this->_signatureAlgorithm = $algo; |
|
57 | 5 | $this->_signatureValue = $signature; |
|
58 | 5 | } |
|
59 | |||
60 | /** |
||
61 | * Get attribute certificate as a PEM formatted string. |
||
62 | * |
||
63 | * @return string |
||
64 | */ |
||
65 | 1 | public function __toString(): string |
|
66 | { |
||
67 | 1 | return $this->toPEM()->string(); |
|
68 | } |
||
69 | |||
70 | /** |
||
71 | * Initialize from ASN.1. |
||
72 | * |
||
73 | * @param Sequence $seq |
||
74 | * |
||
75 | * @return self |
||
76 | */ |
||
77 | 4 | public static function fromASN1(Sequence $seq): self |
|
78 | { |
||
79 | 4 | $acinfo = AttributeCertificateInfo::fromASN1($seq->at(0)->asSequence()); |
|
80 | 4 | $algo = AlgorithmIdentifier::fromASN1($seq->at(1)->asSequence()); |
|
81 | 4 | if (!$algo instanceof SignatureAlgorithmIdentifier) { |
|
82 | 1 | throw new \UnexpectedValueException( |
|
83 | 1 | 'Unsupported signature algorithm ' . $algo->oid() . '.'); |
|
84 | } |
||
85 | 3 | $signature = Signature::fromSignatureData( |
|
86 | 3 | $seq->at(2)->asBitString()->string(), $algo); |
|
87 | 3 | return new self($acinfo, $algo, $signature); |
|
88 | } |
||
89 | |||
90 | /** |
||
91 | * Initialize from DER data. |
||
92 | * |
||
93 | * @param string $data |
||
94 | * |
||
95 | * @return self |
||
96 | */ |
||
97 | 1 | public static function fromDER(string $data): self |
|
98 | { |
||
99 | 1 | return self::fromASN1(UnspecifiedType::fromDER($data)->asSequence()); |
|
100 | } |
||
101 | |||
102 | /** |
||
103 | * Initialize from PEM. |
||
104 | * |
||
105 | * @param PEM $pem |
||
106 | * |
||
107 | * @throws \UnexpectedValueException |
||
108 | * |
||
109 | * @return self |
||
110 | */ |
||
111 | 2 | public static function fromPEM(PEM $pem): self |
|
112 | { |
||
113 | 2 | if (PEM::TYPE_ATTRIBUTE_CERTIFICATE !== $pem->type()) { |
|
114 | 1 | throw new \UnexpectedValueException('Invalid PEM type.'); |
|
115 | } |
||
116 | 1 | return self::fromDER($pem->data()); |
|
117 | } |
||
118 | |||
119 | /** |
||
120 | * Get attribute certificate info. |
||
121 | * |
||
122 | * @return AttributeCertificateInfo |
||
123 | */ |
||
124 | 7 | public function acinfo(): AttributeCertificateInfo |
|
125 | { |
||
126 | 7 | return $this->_acinfo; |
|
127 | } |
||
128 | |||
129 | /** |
||
130 | * Get signature algorithm identifier. |
||
131 | * |
||
132 | * @return SignatureAlgorithmIdentifier |
||
133 | */ |
||
134 | 2 | public function signatureAlgorithm(): SignatureAlgorithmIdentifier |
|
135 | { |
||
136 | 2 | return $this->_signatureAlgorithm; |
|
137 | } |
||
138 | |||
139 | /** |
||
140 | * Get signature value. |
||
141 | * |
||
142 | * @return Signature |
||
143 | */ |
||
144 | 1 | public function signatureValue(): Signature |
|
145 | { |
||
146 | 1 | return $this->_signatureValue; |
|
147 | } |
||
148 | |||
149 | /** |
||
150 | * Get ASN.1 structure. |
||
151 | * |
||
152 | * @return Sequence |
||
153 | */ |
||
154 | 4 | public function toASN1(): Sequence |
|
155 | { |
||
156 | 4 | return new Sequence($this->_acinfo->toASN1(), |
|
157 | 4 | $this->_signatureAlgorithm->toASN1(), |
|
158 | 4 | $this->_signatureValue->bitString()); |
|
159 | } |
||
160 | |||
161 | /** |
||
162 | * Get attribute certificate as a DER. |
||
163 | * |
||
164 | * @return string |
||
165 | */ |
||
166 | 2 | public function toDER(): string |
|
167 | { |
||
168 | 2 | return $this->toASN1()->toDER(); |
|
169 | } |
||
170 | |||
171 | /** |
||
172 | * Get attribute certificate as a PEM. |
||
173 | * |
||
174 | * @return PEM |
||
175 | */ |
||
176 | 2 | public function toPEM(): PEM |
|
177 | { |
||
178 | 2 | return new PEM(PEM::TYPE_ATTRIBUTE_CERTIFICATE, $this->toDER()); |
|
179 | } |
||
180 | |||
181 | /** |
||
182 | * Check whether attribute certificate is issued to the subject identified |
||
183 | * by given public key certificate. |
||
184 | * |
||
185 | * @param Certificate $cert Certificate |
||
186 | * |
||
187 | * @return bool |
||
188 | */ |
||
189 | 13 | public function isHeldBy(Certificate $cert): bool |
|
195 | } |
||
196 | |||
197 | /** |
||
198 | * Check whether attribute certificate is issued by given public key |
||
199 | * certificate. |
||
200 | * |
||
201 | * @param Certificate $cert Certificate |
||
202 | * |
||
203 | * @return bool |
||
204 | */ |
||
205 | 11 | public function isIssuedBy(Certificate $cert): bool |
|
211 | } |
||
212 | |||
213 | /** |
||
214 | * Verify signature. |
||
215 | * |
||
216 | * @param PublicKeyInfo $pubkey_info Signer's public key |
||
217 | * @param null|Crypto $crypto Crypto engine, use default if not set |
||
218 | * |
||
219 | * @return bool |
||
220 | */ |
||
221 | 10 | public function verify(PublicKeyInfo $pubkey_info, ?Crypto $crypto = null): bool |
|
222 | { |
||
223 | 10 | $crypto = $crypto ?? Crypto::getDefault(); |
|
224 | 10 | $data = $this->_acinfo->toASN1()->toDER(); |
|
229 |