Time-Stamp Protocol (TSP) package for Go
The package timestamp implements the Time-Stamp Protocol (TSP) as specified in RFC3161 (Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP)).
Time-Stamp Protocol (TSP) implementation for Go as specified in RFC3161
Home Page: https://pkg.go.dev/github.com/digitorus/timestamp?tab=doc
License: BSD 2-Clause "Simplified" License
In your CreateRequest
function you have the code
b := make([]byte, 32)
But you need to aware that this length would be valid only in case of your default SHA-256. In most one cases you would fail.
I strongly suspect that I am "using it wrong", but the structure returned by ParseResponse does not include the signature and may be missing other information which might be necessary to verifying a response.
Within the TimeStampResp, the SignedData structure has its version set to 1
, but I believe the correct value should be 3
.
According to the CMS Spec (RFC 5652). The version
field of the SignedData
struct should be set to 3
if the encapsulated content type is anything other than 1.2.840.113549.1.7.1
.
From section 5.1:
For the TimeStampResp, the encapsulated content type is set to 1.2.840.113549.1.9.16.1.4
(TSTInfo):
Hi,
is this output mismatch while go test
just a CN paring error or a problem while verification? Can this be fixed easily?
$ go test
--- FAIL: ExampleCreateRequest_ParseResponse (0.82s)
got:
[140 222 43 143 28 80 96 97 4 176 145 205 188 119 197 142 149 101 26 96 188 163 178 64 230 162 199 171 176 178 173 128]
1.2.3.4.1
CN=www.freetsa.org,OU=TSA,O=Free TSA,L=Wuerzburg,ST=Bayern,C=DE,1.2.840.113549.1.9.1=#0c13627573696c657a617340676d61696c2e636f6d,2.5.4.13=#136d54686973206365727469666963617465206469676974616c6c79207369676e7320646f63756d656e747320616e642074696d65207374616d70207265717565737473206d616465207573696e672074686520667265657473612e6f7267206f6e6c696e65207365727669636573
want:
[140 222 43 143 28 80 96 97 4 176 145 205 188 119 197 142 149 101 26 96 188 163 178 64 230 162 199 171 176 178 173 128]
1.2.3.4.1
CN=www.freetsa.org,OU=TSA,O=Free TSA,L=Wuerzburg,ST=Bayern,C=DE
FAIL
exit status 1
FAIL github.com/digitorus/timestamp 0.835s
$ go version
go version go1.15.6 linux/amd64
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.