ERUCES::TEX509AuthenticationContext
#include <teauthcertctx.h>
The TEX509AuthenticationContext class manages X.509 digital certificates.
The TEX509AuthenticationContext class represents an X.509 digital certificate authentication context in which user is authenticated by X.509 certificate and private key. This class is derived from the TEAuthenticationContext class.
© Pi Soft, 2018-2026 · Tricryption Engine 8.1
Inheritance
- Inherits ERUCES::TEAuthenticationContext
Protected Member Functions
| Member | Description |
|---|---|
TEX509AuthenticationContext() | The TEX509AuthenticationContext constructor is the default class constructor. |
Public Member Functions
| Member | Description |
|---|---|
void getCertificate(unsigned char *buffer, size_t &bufsize)=0 | The getCertificate method must be implemented in inherited class certificate is expected to presented for authentication claim. |
void decryptAndSign(const unsigned char *message, size_t messageLen, _TESTD vector< unsigned char > &signature)=0 | The decryptAndSign method must be implemented in the inherited class: it signs the channel-bound message with the private key corresponding to the certificate submitted earlier, and hands the signature back. |
te_oid authenticate() | The authenticate method performs authentication. |
TEObject * clone() const | The clone method clones the TEAuthenticationContext object. |
Static Public Member Functions
| Member | Description |
|---|---|
void signChannelBound(EVP_PKEY *key, const unsigned char *message, size_t messageLen, _TESTD vector< unsigned char > &signature) | The signChannelBound method signs the channel-bound message with an OpenSSL private key under the scheme the Key Service verifies – the whole of decryptAndSign for an implementer that holds an EVP_PKEY. |
Member Function Documentation
TEX509AuthenticationContext()
The TEX509AuthenticationContext constructor is the default class constructor.
void getCertificate(unsigned char *buffer, size_t &bufsize)=0
The getCertificate method must be implemented in inherited class certificate is expected to presented for authentication claim.
Parameters
| Parameter | Description |
|---|---|
buffer | A string representing the certificate. |
bufsize | The size of the buffer. |
void decryptAndSign(const unsigned char *message, size_t messageLen, _TESTD vector< unsigned char > &signature)=0
The decryptAndSign method must be implemented in the inherited class: it signs the channel-bound message with the private key corresponding to the certificate submitted earlier, and hands the signature back.
What it is GIVEN: message / messageLen is M – the 89 bytes "TE-AM08-CHANNEL-BOUND-v1" || 0x00 || SHA-256("tls-exporter:" || exporter) || challenge – already built by the SDK from this connection's channel binding and the Key Service's challenge (the last 32 bytes). The implementer does not build M and does not read the exporter. M is the SDK's and is read-only.
What it must PRODUCE: signature holding the signature over M under the certificate key's scheme – RSASSA-PSS with SHA-256, MGF1-SHA-256 and a salt of exactly 32 bytes for an RSA key; ECDSA over SHA-256, DER-encoded, for an EC key. The vector is the implementer's to size: a signature is not the size of M, and only the signer knows how long it is. The SDK sends exactly the bytes the vector holds on return, and refuses to send an empty one.
An implementer holding the key as an OpenSSL EVP_PKEY calls signChannelBound, which applies exactly that scheme; one signing elsewhere (a token, a service) reproduces it from the description above, and test/ks-fixture/x509_sigvec.cpp is the reference vector to check against.
Parameters
| Parameter | Description |
|---|---|
message | M, read-only. |
messageLen | The length of M in bytes (89). |
signature | Out: the signature over M, sized by the implementer. |
Remark: The name is kept from the original contract, whose "decrypt" half was never on the wire: the Key Service sends a plaintext challenge and expects a signature. Until TE81-444 (ADR-0107) the implementer was handed the bare 32-byte challenge and the signature was a raw PKCS#1 v1.5 primitive over it; that construction is refused. Until TE81-450 (ADR 0124) M arrived in, and the signature left through, one in-place internal buffer type; the signature is now the implementer's own vector, so this contract is compilable from the shipped headers.
te_oid authenticate()
The authenticate method performs authentication.
Returns: Principal ID of authenticated principal.
TEObject * clone() const
The clone method clones the TEAuthenticationContext object.
Returns: Cloned TEAuthenticationContext object
void signChannelBound(EVP_PKEY *key, const unsigned char *message, size_t messageLen, _TESTD vector< unsigned char > &signature)
The signChannelBound method signs the channel-bound message with an OpenSSL private key under the scheme the Key Service verifies – the whole of decryptAndSign for an implementer that holds an EVP_PKEY.
RSA (including an RSA-PSS key): RSASSA-PSS, SHA-256, MGF1-SHA-256, salt length 32. EC: ECDSA over SHA-256, DER. A null key, or any other key type, is refused with a TEException naming it, and signature is left empty.
Parameters
| Parameter | Description |
|---|---|
key | The certificate's private key. |
message | M, as decryptAndSign received it. |
messageLen | The length of M in bytes. |
signature | Out: the signature over M, sized here. |