Class: Ksef::Crypto::Certificate
- Inherits:
-
Data
- Object
- Data
- Ksef::Crypto::Certificate
- Defined in:
- lib/ksef/crypto/certificate.rb,
lib/ksef/crypto/certificate.rb
Overview
Reopened rather than using a Data.define block so the usage constants land on the
class rather than on Object.
Constant Summary collapse
- KSEF_TOKEN_ENCRYPTION =
The two members of the contract's
PublicKeyCertificateUsageenum. Keeping them here rather than as bare strings at call sites means a typo is aNameErrorat load time instead of an empty selection at runtime. "KsefTokenEncryption"- SYMMETRIC_KEY_ENCRYPTION =
"SymmetricKeyEncryption"- USAGES =
[KSEF_TOKEN_ENCRYPTION, SYMMETRIC_KEY_ENCRYPTION].freeze
Instance Attribute Summary collapse
-
#certificate ⇒ Object
readonly
Returns the value of attribute certificate.
-
#certificate_id ⇒ Object
readonly
Returns the value of attribute certificate_id.
-
#public_key_id ⇒ Object
readonly
Returns the value of attribute public_key_id.
-
#usage ⇒ Object
readonly
Returns the value of attribute usage.
-
#valid_from ⇒ Object
readonly
Returns the value of attribute valid_from.
-
#valid_to ⇒ Object
readonly
Returns the value of attribute valid_to.
Class Method Summary collapse
Instance Method Summary collapse
-
#encrypt(plaintext) ⇒ String
RSA-OAEP under this certificate's key.
- #public_key ⇒ OpenSSL::PKey::RSA
- #usable_for?(kind) ⇒ Boolean
- #valid_at?(now = Time.now) ⇒ Boolean
-
#x509 ⇒ OpenSSL::X509::Certificate
The contract ships the certificate as DER, base64-encoded, without PEM armour, so it cannot be handed to OpenSSL as text.
Instance Attribute Details
#certificate ⇒ Object (readonly)
Returns the value of attribute certificate
12 13 14 |
# File 'lib/ksef/crypto/certificate.rb', line 12 def certificate @certificate end |
#certificate_id ⇒ Object (readonly)
Returns the value of attribute certificate_id
12 13 14 |
# File 'lib/ksef/crypto/certificate.rb', line 12 def certificate_id @certificate_id end |
#public_key_id ⇒ Object (readonly)
Returns the value of attribute public_key_id
12 13 14 |
# File 'lib/ksef/crypto/certificate.rb', line 12 def public_key_id @public_key_id end |
#usage ⇒ Object (readonly)
Returns the value of attribute usage
12 13 14 |
# File 'lib/ksef/crypto/certificate.rb', line 12 def usage @usage end |
#valid_from ⇒ Object (readonly)
Returns the value of attribute valid_from
12 13 14 |
# File 'lib/ksef/crypto/certificate.rb', line 12 def valid_from @valid_from end |
#valid_to ⇒ Object (readonly)
Returns the value of attribute valid_to
12 13 14 |
# File 'lib/ksef/crypto/certificate.rb', line 12 def valid_to @valid_to end |
Class Method Details
.from(payload) ⇒ Object
24 25 26 27 28 29 30 31 32 33 |
# File 'lib/ksef/crypto/certificate.rb', line 24 def self.from(payload) new( certificate: payload["certificate"], certificate_id: payload["certificateId"], public_key_id: payload["publicKeyId"], valid_from: time(payload["validFrom"]), valid_to: time(payload["validTo"]), usage: Array(payload["usage"]).freeze ) end |
Instance Method Details
#encrypt(plaintext) ⇒ String
RSA-OAEP under this certificate's key. The plaintexts KSeF asks for are a 32-byte
symmetric key (§10.1) and a short token|timestamp string (§4.5), both far inside
MAX_OAEP_PLAINTEXT_BYTES.
75 |
# File 'lib/ksef/crypto/certificate.rb', line 75 def encrypt(plaintext) = Crypto.rsa_encrypt(plaintext, public_key) |
#public_key ⇒ OpenSSL::PKey::RSA
68 |
# File 'lib/ksef/crypto/certificate.rb', line 68 def public_key = x509.public_key |
#usable_for?(kind) ⇒ Boolean
50 |
# File 'lib/ksef/crypto/certificate.rb', line 50 def usable_for?(kind) = usage.include?(kind) |
#valid_at?(now = Time.now) ⇒ Boolean
52 53 54 55 56 |
# File 'lib/ksef/crypto/certificate.rb', line 52 def valid_at?(now = Time.now) return false if valid_from.nil? || valid_to.nil? now.between?(valid_from, valid_to) end |
#x509 ⇒ OpenSSL::X509::Certificate
The contract ships the certificate as DER, base64-encoded, without PEM armour, so it cannot be handed to OpenSSL as text.
Not memoised: Data instances are frozen, and this is called once per session
open or authentication, where a DER parse is not worth caching around.
65 |
# File 'lib/ksef/crypto/certificate.rb', line 65 def x509 = OpenSSL::X509::Certificate.new(Crypto.decode(certificate)) |