73 lines
2.3 KiB
Plaintext
73 lines
2.3 KiB
Plaintext
IMPORT xml
|
|
|
|
MAIN
|
|
DEFINE doc xml.DomDocument
|
|
|
|
DEFINE root xml.DomNode
|
|
DEFINE node xml.DomNode
|
|
DEFINE sig xml.Signature
|
|
DEFINE signnode xml.DomNode
|
|
DEFINE key xml.CryptoKey
|
|
DEFINE list xml.DomNodeList
|
|
DEFINE isVerified INTEGER
|
|
|
|
DEFINE x509 xml.CryptoX509
|
|
|
|
# Create DomDocument object
|
|
LET doc = xml.DomDocument.Create()
|
|
# Notice that whitespaces are significant in cryptography,
|
|
# therefore it is recommended to remove unnecessary ones
|
|
CALL doc.setFeature("whitespace-in-element-content",FALSE)
|
|
LET x509 = xml.CryptoX509.Create()
|
|
TRY
|
|
CALL x509.loadPEM("apns-cert.pem")
|
|
CATCH
|
|
DISPLAY "Unable to load certificate :",STATUS," ",sqlca.sqlerrm
|
|
EXIT PROGRAM
|
|
END TRY
|
|
|
|
TRY
|
|
# Load original document with enveloped signature into a DomDocument object
|
|
CALL doc.load("naceSignature.xml")
|
|
# Because the signature can be anywhere in the original document,
|
|
# we must first retrieve it
|
|
LET list = doc.getElementsByTagNameNS("Signature",
|
|
"http://www.w3.org/2000/09/xmldsig#")
|
|
IF list.getCount() != 1 THEN
|
|
DISPLAY "Unable to find one Signature node"
|
|
EXIT PROGRAM (-1)
|
|
ELSE
|
|
LET node = list.getItem(1)
|
|
|
|
END IF
|
|
# Create RSA key
|
|
LET key = xml.CryptoKey.Create(
|
|
"http://www.w3.org/2001/04/xmldsig-more#rsa-sha256")
|
|
|
|
CALL key.loadPEM("apns.pem")
|
|
# Create signature object from DomNode object and set RSA key to use
|
|
LET sig = xml.Signature.CreateFromNode(node)
|
|
CALL sig.setKey(key)
|
|
# Verify enveloped signature validity of original document
|
|
LET isVerified = sig.verify(doc)
|
|
# Notice that if something has been modified in the node with
|
|
# attribute 'xml:id="code"' of the original XML document with the
|
|
# enveloped signature, the program will display "FAILED".
|
|
IF isVerified THEN
|
|
DISPLAY "Signature OK"
|
|
TRY
|
|
CALL x509.setFeature("X509Certificate",TRUE)
|
|
|
|
LET doc = x509.save()
|
|
CALL doc.setFeature("format-pretty-print",TRUE)
|
|
CALL doc.save("RSAX509Certificate.xml")
|
|
CATCH
|
|
DISPLAY "Unable to save certificate :",STATUS
|
|
END TRY
|
|
ELSE
|
|
DISPLAY "Signature FAILED"
|
|
END IF
|
|
CATCH
|
|
DISPLAY "Unable to verify the enveloped signature :",status
|
|
END TRY
|
|
END MAIN |