You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

XAdESSignatureFacet.java 14KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304
  1. /* ====================================================================
  2. Licensed to the Apache Software Foundation (ASF) under one or more
  3. contributor license agreements. See the NOTICE file distributed with
  4. this work for additional information regarding copyright ownership.
  5. The ASF licenses this file to You under the Apache License, Version 2.0
  6. (the "License"); you may not use this file except in compliance with
  7. the License. You may obtain a copy of the License at
  8. http://www.apache.org/licenses/LICENSE-2.0
  9. Unless required by applicable law or agreed to in writing, software
  10. distributed under the License is distributed on an "AS IS" BASIS,
  11. WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. See the License for the specific language governing permissions and
  13. limitations under the License.
  14. ==================================================================== */
  15. /* ====================================================================
  16. This product contains an ASLv2 licensed version of the OOXML signer
  17. package from the eID Applet project
  18. http://code.google.com/p/eid-applet/source/browse/trunk/README.txt
  19. Copyright (C) 2008-2014 FedICT.
  20. ================================================================= */
  21. package org.apache.poi.poifs.crypt.dsig.facets;
  22. import java.security.InvalidAlgorithmParameterException;
  23. import java.security.MessageDigest;
  24. import java.security.NoSuchAlgorithmException;
  25. import java.security.cert.CertificateEncodingException;
  26. import java.security.cert.X509Certificate;
  27. import java.util.ArrayList;
  28. import java.util.Calendar;
  29. import java.util.HashMap;
  30. import java.util.List;
  31. import java.util.Map;
  32. import java.util.TimeZone;
  33. import javax.xml.crypto.XMLStructure;
  34. import javax.xml.crypto.dom.DOMStructure;
  35. import javax.xml.crypto.dsig.CanonicalizationMethod;
  36. import javax.xml.crypto.dsig.DigestMethod;
  37. import javax.xml.crypto.dsig.Reference;
  38. import javax.xml.crypto.dsig.Transform;
  39. import javax.xml.crypto.dsig.XMLObject;
  40. import javax.xml.crypto.dsig.XMLSignatureFactory;
  41. import javax.xml.crypto.dsig.spec.TransformParameterSpec;
  42. import org.apache.poi.poifs.crypt.CryptoFunctions;
  43. import org.apache.poi.poifs.crypt.HashAlgorithm;
  44. import org.apache.poi.poifs.crypt.dsig.SignatureConfig;
  45. import org.apache.poi.poifs.crypt.dsig.services.SignaturePolicyService;
  46. import org.apache.poi.util.POILogFactory;
  47. import org.apache.poi.util.POILogger;
  48. import org.apache.xmlbeans.XmlCursor;
  49. import org.apache.xmlbeans.XmlObject;
  50. import org.apache.xmlbeans.XmlString;
  51. import org.etsi.uri.x01903.v13.AnyType;
  52. import org.etsi.uri.x01903.v13.CertIDListType;
  53. import org.etsi.uri.x01903.v13.CertIDType;
  54. import org.etsi.uri.x01903.v13.ClaimedRolesListType;
  55. import org.etsi.uri.x01903.v13.DataObjectFormatType;
  56. import org.etsi.uri.x01903.v13.DigestAlgAndValueType;
  57. import org.etsi.uri.x01903.v13.IdentifierType;
  58. import org.etsi.uri.x01903.v13.ObjectIdentifierType;
  59. import org.etsi.uri.x01903.v13.QualifyingPropertiesDocument;
  60. import org.etsi.uri.x01903.v13.QualifyingPropertiesType;
  61. import org.etsi.uri.x01903.v13.SigPolicyQualifiersListType;
  62. import org.etsi.uri.x01903.v13.SignaturePolicyIdType;
  63. import org.etsi.uri.x01903.v13.SignaturePolicyIdentifierType;
  64. import org.etsi.uri.x01903.v13.SignedDataObjectPropertiesType;
  65. import org.etsi.uri.x01903.v13.SignedPropertiesType;
  66. import org.etsi.uri.x01903.v13.SignedSignaturePropertiesType;
  67. import org.etsi.uri.x01903.v13.SignerRoleType;
  68. import org.w3.x2000.x09.xmldsig.DigestMethodType;
  69. import org.w3.x2000.x09.xmldsig.X509IssuerSerialType;
  70. import org.w3c.dom.Document;
  71. import org.w3c.dom.Element;
  72. /**
  73. * XAdES Signature Facet. Implements XAdES v1.4.1 which is compatible with XAdES
  74. * v1.3.2. The implemented XAdES format is XAdES-BES/EPES. It's up to another
  75. * part of the signature service to upgrade the XAdES-BES to a XAdES-X-L.
  76. *
  77. * This implementation has been tested against an implementation that
  78. * participated multiple ETSI XAdES plugtests.
  79. *
  80. * @author Frank Cornelis
  81. * @see http://en.wikipedia.org/wiki/XAdES
  82. *
  83. */
  84. public class XAdESSignatureFacet implements SignatureFacet {
  85. private static final POILogger LOG = POILogFactory.getLogger(XAdESSignatureFacet.class);
  86. private static final String XADES_TYPE = "http://uri.etsi.org/01903#SignedProperties";
  87. private SignatureConfig signatureConfig;
  88. private Map<String, String> dataObjectFormatMimeTypes = new HashMap<String, String>();
  89. public void setSignatureConfig(SignatureConfig signatureConfig) {
  90. this.signatureConfig = signatureConfig;
  91. }
  92. @Override
  93. public void postSign(Document document, List<X509Certificate> signingCertificateChain) {
  94. LOG.log(POILogger.DEBUG, "postSign");
  95. }
  96. @Override
  97. public void preSign(Document document,
  98. XMLSignatureFactory signatureFactory,
  99. List<Reference> references, List<XMLObject> objects)
  100. throws NoSuchAlgorithmException, InvalidAlgorithmParameterException {
  101. LOG.log(POILogger.DEBUG, "preSign");
  102. // QualifyingProperties
  103. QualifyingPropertiesDocument qualDoc = QualifyingPropertiesDocument.Factory.newInstance();
  104. QualifyingPropertiesType qualifyingProperties = qualDoc.addNewQualifyingProperties();
  105. qualifyingProperties.setTarget("#" + signatureConfig.getPackageSignatureId());
  106. // SignedProperties
  107. SignedPropertiesType signedProperties = qualifyingProperties.addNewSignedProperties();
  108. signedProperties.setId(signatureConfig.getXadesSignatureId());
  109. // SignedSignatureProperties
  110. SignedSignaturePropertiesType signedSignatureProperties = signedProperties.addNewSignedSignatureProperties();
  111. // SigningTime
  112. Calendar xmlGregorianCalendar = Calendar.getInstance();
  113. xmlGregorianCalendar.setTimeZone(TimeZone.getTimeZone("Z"));
  114. xmlGregorianCalendar.setTime(signatureConfig.getExecutionTime());
  115. xmlGregorianCalendar.clear(Calendar.MILLISECOND);
  116. signedSignatureProperties.setSigningTime(xmlGregorianCalendar);
  117. // SigningCertificate
  118. if (signatureConfig.getSigningCertificateChain() == null
  119. || signatureConfig.getSigningCertificateChain().isEmpty()) {
  120. throw new RuntimeException("no signing certificate chain available");
  121. }
  122. CertIDListType signingCertificates = signedSignatureProperties.addNewSigningCertificate();
  123. CertIDType certId = signingCertificates.addNewCert();
  124. X509Certificate certificate = signatureConfig.getSigningCertificateChain().get(0);
  125. setCertID(certId, signatureConfig, signatureConfig.isXadesIssuerNameNoReverseOrder(), certificate);
  126. // ClaimedRole
  127. String role = signatureConfig.getXadesRole();
  128. if (role != null && !role.isEmpty()) {
  129. SignerRoleType signerRole = signedSignatureProperties.addNewSignerRole();
  130. signedSignatureProperties.setSignerRole(signerRole);
  131. ClaimedRolesListType claimedRolesList = signerRole.addNewClaimedRoles();
  132. AnyType claimedRole = claimedRolesList.addNewClaimedRole();
  133. XmlString roleString = XmlString.Factory.newInstance();
  134. roleString.setStringValue(role);
  135. insertXChild(claimedRole, roleString);
  136. }
  137. // XAdES-EPES
  138. SignaturePolicyService policyService = signatureConfig.getSignaturePolicyService();
  139. if (policyService != null) {
  140. SignaturePolicyIdentifierType signaturePolicyIdentifier =
  141. signedSignatureProperties.addNewSignaturePolicyIdentifier();
  142. SignaturePolicyIdType signaturePolicyId = signaturePolicyIdentifier.addNewSignaturePolicyId();
  143. ObjectIdentifierType objectIdentifier = signaturePolicyId.addNewSigPolicyId();
  144. objectIdentifier.setDescription(policyService.getSignaturePolicyDescription());
  145. IdentifierType identifier = objectIdentifier.addNewIdentifier();
  146. identifier.setStringValue(policyService.getSignaturePolicyIdentifier());
  147. byte[] signaturePolicyDocumentData = policyService.getSignaturePolicyDocument();
  148. DigestAlgAndValueType sigPolicyHash = signaturePolicyId.addNewSigPolicyHash();
  149. setDigestAlgAndValue(sigPolicyHash, signaturePolicyDocumentData, signatureConfig.getDigestAlgo());
  150. String signaturePolicyDownloadUrl = policyService.getSignaturePolicyDownloadUrl();
  151. if (null != signaturePolicyDownloadUrl) {
  152. SigPolicyQualifiersListType sigPolicyQualifiers = signaturePolicyId.addNewSigPolicyQualifiers();
  153. AnyType sigPolicyQualifier = sigPolicyQualifiers.addNewSigPolicyQualifier();
  154. XmlString spUriElement = XmlString.Factory.newInstance();
  155. spUriElement.setStringValue(signaturePolicyDownloadUrl);
  156. insertXChild(sigPolicyQualifier, spUriElement);
  157. }
  158. } else if (signatureConfig.isXadesSignaturePolicyImplied()) {
  159. SignaturePolicyIdentifierType signaturePolicyIdentifier =
  160. signedSignatureProperties.addNewSignaturePolicyIdentifier();
  161. signaturePolicyIdentifier.addNewSignaturePolicyImplied();
  162. }
  163. // DataObjectFormat
  164. if (!dataObjectFormatMimeTypes.isEmpty()) {
  165. SignedDataObjectPropertiesType signedDataObjectProperties =
  166. signedProperties.addNewSignedDataObjectProperties();
  167. List<DataObjectFormatType> dataObjectFormats = signedDataObjectProperties
  168. .getDataObjectFormatList();
  169. for (Map.Entry<String, String> dataObjectFormatMimeType : this.dataObjectFormatMimeTypes
  170. .entrySet()) {
  171. DataObjectFormatType dataObjectFormat = DataObjectFormatType.Factory.newInstance();
  172. dataObjectFormat.setObjectReference("#" + dataObjectFormatMimeType.getKey());
  173. dataObjectFormat.setMimeType(dataObjectFormatMimeType.getValue());
  174. dataObjectFormats.add(dataObjectFormat);
  175. }
  176. }
  177. // add XAdES ds:Object
  178. List<XMLStructure> xadesObjectContent = new ArrayList<XMLStructure>();
  179. Element qualDocElSrc = (Element)qualifyingProperties.getDomNode();
  180. Element qualDocEl = (Element)document.importNode(qualDocElSrc, true);
  181. xadesObjectContent.add(new DOMStructure(qualDocEl));
  182. XMLObject xadesObject = signatureFactory.newXMLObject(xadesObjectContent, null, null, null);
  183. objects.add(xadesObject);
  184. // add XAdES ds:Reference
  185. DigestMethod digestMethod = signatureFactory.newDigestMethod(signatureConfig.getDigestMethodUri(), null);
  186. List<Transform> transforms = new ArrayList<Transform>();
  187. Transform exclusiveTransform = signatureFactory
  188. .newTransform(CanonicalizationMethod.INCLUSIVE,
  189. (TransformParameterSpec) null);
  190. transforms.add(exclusiveTransform);
  191. Reference reference = signatureFactory.newReference
  192. ("#"+signatureConfig.getXadesSignatureId(), digestMethod, transforms, XADES_TYPE, null);
  193. references.add(reference);
  194. }
  195. /**
  196. * Gives back the JAXB DigestAlgAndValue data structure.
  197. *
  198. * @param data
  199. * @param xadesObjectFactory
  200. * @param xmldsigObjectFactory
  201. * @param hashAlgo
  202. * @return
  203. */
  204. protected static void setDigestAlgAndValue(
  205. DigestAlgAndValueType digestAlgAndValue,
  206. byte[] data,
  207. HashAlgorithm digestAlgo) {
  208. DigestMethodType digestMethod = digestAlgAndValue.addNewDigestMethod();
  209. digestMethod.setAlgorithm(SignatureConfig.getDigestMethodUri(digestAlgo));
  210. MessageDigest messageDigest = CryptoFunctions.getMessageDigest(digestAlgo);
  211. byte[] digestValue = messageDigest.digest(data);
  212. digestAlgAndValue.setDigestValue(digestValue);
  213. }
  214. /**
  215. * Gives back the JAXB CertID data structure.
  216. */
  217. protected static void setCertID
  218. (CertIDType certId, SignatureConfig signatureConfig, boolean issuerNameNoReverseOrder, X509Certificate certificate) {
  219. X509IssuerSerialType issuerSerial = certId.addNewIssuerSerial();
  220. String issuerName;
  221. if (issuerNameNoReverseOrder) {
  222. /*
  223. * Make sure the DN is encoded using the same order as present
  224. * within the certificate. This is an Office2010 work-around.
  225. * Should be reverted back.
  226. *
  227. * XXX: not correct according to RFC 4514.
  228. */
  229. // TODO: check if issuerName is different on getTBSCertificate
  230. // issuerName = PrincipalUtil.getIssuerX509Principal(certificate).getName().replace(",", ", ");
  231. issuerName = certificate.getIssuerDN().getName().replace(",", ", ");
  232. } else {
  233. issuerName = certificate.getIssuerX500Principal().toString();
  234. }
  235. issuerSerial.setX509IssuerName(issuerName);
  236. issuerSerial.setX509SerialNumber(certificate.getSerialNumber());
  237. byte[] encodedCertificate;
  238. try {
  239. encodedCertificate = certificate.getEncoded();
  240. } catch (CertificateEncodingException e) {
  241. throw new RuntimeException("certificate encoding error: "
  242. + e.getMessage(), e);
  243. }
  244. DigestAlgAndValueType certDigest = certId.addNewCertDigest();
  245. setDigestAlgAndValue(certDigest, encodedCertificate, signatureConfig.getXadesDigestAlgo());
  246. }
  247. /**
  248. * Adds a mime-type for the given ds:Reference (referred via its @URI). This
  249. * information is added via the xades:DataObjectFormat element.
  250. *
  251. * @param dsReferenceUri
  252. * @param mimetype
  253. */
  254. public void addMimeType(String dsReferenceUri, String mimetype) {
  255. this.dataObjectFormatMimeTypes.put(dsReferenceUri, mimetype);
  256. }
  257. protected static void insertXChild(XmlObject root, XmlObject child) {
  258. XmlCursor rootCursor = root.newCursor();
  259. rootCursor.toEndToken();
  260. XmlCursor childCursor = child.newCursor();
  261. childCursor.toNextToken();
  262. childCursor.moveXml(rootCursor);
  263. childCursor.dispose();
  264. rootCursor.dispose();
  265. }
  266. }