Repository navigation
feat(tsa): parse RFC 3161 requests and sign timestamp tokens - #352
Merged
Merged
Conversation
Add the responder that turns a TimeStampReq into a TimeStampResp. Version 1 requests with a SHA-256, SHA-384 or SHA-512 message imprint are granted; SHA-1, MD5 and other algorithms get badAlg, a different requested policy gets unacceptedPolicy, extensions get unacceptedExtension, and malformed requests get badDataFormat. The token echoes the imprint and nonce, names the configured policy, has a random 159-bit serial, a millisecond genTime and the configured accuracy, and is a SignedData built by internal/cms with a signing-certificate-v2 attribute (RFC 5816) naming the TSA certificate. Tests check the tokens with the stdlib parser and with openssl ts -verify. Refs #287 Signed-off-by: Bugs5382 <12115015+Bugs5382@users.noreply.github.com>
Contributor
Author
|
Closing summary: adds the RFC 3161 request parser and token builder ( |
This was referenced Oct 6, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What and why
Second of the RFC 3161 time-stamp authority PRs (task 3 of the issue): request parsing and token
building in
internal/tsa, on the hand-written CMS package. Still not wired into boot; the listener andthe config mapping follow.
Responder.Respondtakes a DERTimeStampReqand always answers with a DERTimeStampResp.Requests (RFC 3161 section 2.4.1):
with a hash of the right length.
badAlg. A differentreqPolicygetsunacceptedPolicy.unacceptedExtension, as section 2.4.1 requires for one the server doesnot recognise. This TSA recognises none.
badDataFormat. A signing failure getssystemFailure.statusStringsays what the failure bit means. The detail goes to the log only.Tokens (section 2.4.2, RFC 5816):
crypto/rand: positive, within the 160 bits requesters musthandle, and unique per token.
genTimeis UTC GeneralizedTime to the millisecond, with trailing zeros dropped.encoding/asn1only writes whole seconds, so it is hand-encoded.
accuracyis seconds plus millis, from the configured value.orderingis left at its default,FALSE. The
tsaname and extensions are left out.id-ct-TSTInfo, version 3) is built byinternal/cmsand signed by the TSA keythrough
CertManager.WithSigner. The signer is identified by issuer and serial number.ESSCertIDv2 has the SHA-256 hash of the TSA certificate (the DEFAULT algorithm, so DER leaves it out)
and the certificate's issuer and serial.
RSA 3072 or larger). A P-384 TPM key only signs SHA-384 digests.
certReqis set.Refs #287
Merge order: after #351 (merged). The listener PR follows this one.
No docs change in this PR: nothing is user-facing until the config mapping lands, and the docs PR
ships with that one.
Verification
How this was verified
task ciandtask licensepass locally.The tests check the tokens independently of the encoder:
encoding/asn1, and verify theSignedData with
cms.ParseSignedDataandVerify.genTimeandaccuracyencodings.openssl ts(OpenSSL 3.6) builds SHA-256, SHA-384 and SHA-512 queries, with and without a nonce,certReq and the policy.
openssl ts -verifychecks each reply against the CA, from both the query fileand the data, for both key types. It reports
Verification: OK.openssl ts -reply -textshows thepolicy, the accuracy and
Ordering: no, and reads a SHA-1 query's rejection as an unsupportedalgorithm.
As a mutation check, making the EKU non-critical makes
openssl ts -verifyfail. Dropping theESSCertIDv2 issuerSerial fails the parser tests. The OpenSSL tests skip without OpenSSL 3 locally but
fail under CI, like the CMS package's.