/*
- Copyright (C) 2013-2014 Carl Hetherington <cth@carlh.net>
+ Copyright (C) 2013-2015 Carl Hetherington <cth@carlh.net>
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
#include "encrypted_kdm.h"
#include "util.h"
-#include "signer.h"
+#include "certificate_chain.h"
#include <libcxml/cxml.h>
#include <libxml++/document.h>
#include <libxml++/nodes/element.h>
namespace dcp {
-/** Namespace for classes used to hold our data; they are internal to this .cc file */
+/** Namespace for classes used to hold our data; they are internal to this .cc file */
namespace data {
class Signer
{
public:
Signer () {}
-
+
Signer (shared_ptr<const cxml::Node> node)
: x509_issuer_name (node->string_child ("X509IssuerName"))
, x509_serial_number (node->string_child ("X509SerialNumber"))
{
-
+
}
void as_xml (xmlpp::Element* node) const
node->add_child("X509IssuerName", "ds")->add_child_text (x509_issuer_name);
node->add_child("X509SerialNumber", "ds")->add_child_text (x509_serial_number);
}
-
+
string x509_issuer_name;
string x509_serial_number;
};
{
public:
X509Data () {}
-
+
X509Data (boost::shared_ptr<const cxml::Node> node)
: x509_issuer_serial (Signer (node->node_child ("X509IssuerSerial")))
, x509_certificate (node->string_child ("X509Certificate"))
x509_issuer_serial.as_xml (node->add_child ("X509IssuerSerial", "ds"));
node->add_child("X509Certificate", "ds")->add_child_text (x509_certificate);
}
-
+
Signer x509_issuer_serial;
std::string x509_certificate;
};
-
+
class Reference
{
public:
Reference () {}
-
+
Reference (string u)
: uri (u)
{}
{
}
-
+
void as_xml (xmlpp::Element* node) const
{
node->set_attribute ("URI", uri);
node->add_child("DigestMethod", "ds")->set_attribute ("Algorithm", "http://www.w3.org/2001/04/xmlenc#sha256");
node->add_child("DigestValue", "ds")->add_child_text (digest_value);
}
-
+
string uri;
string digest_value;
};
node->add_child ("SignatureMethod", "ds")->set_attribute (
"Algorithm", "http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"
);
-
+
authenticated_public.as_xml (node->add_child ("Reference", "ds"));
authenticated_private.as_xml (node->add_child ("Reference", "ds"));
}
-
+
private:
Reference authenticated_public;
Reference authenticated_private;
};
-
+
class Signature
{
public:
{
signed_info.as_xml (node->add_child ("SignedInfo", "ds"));
node->add_child("SignatureValue", "ds")->add_child_text (signature_value);
-
+
xmlpp::Element* key_info_node = node->add_child ("KeyInfo", "ds");
for (std::list<X509Data>::const_iterator i = x509_data.begin(); i != x509_data.end(); ++i) {
i->as_xml (key_info_node->add_child ("X509Data", "ds"));
{
public:
AuthenticatedPrivate () {}
-
+
AuthenticatedPrivate (shared_ptr<const cxml::Node> node)
{
list<shared_ptr<cxml::Node> > encrypted_key_nodes = node->node_children ("EncryptedKey");
cipher_data->add_child("CipherValue", "enc")->add_child_text (*i);
}
}
-
+
list<string> encrypted_key;
};
{
public:
TypedKeyId () {}
-
+
TypedKeyId (shared_ptr<const cxml::Node> node)
: key_type (node->string_child ("KeyType"))
, key_id (node->string_child ("KeyId").substr (9))
{
public:
KeyIdList () {}
-
+
KeyIdList (shared_ptr<const cxml::Node> node)
{
list<shared_ptr<cxml::Node> > typed_key_id_nodes = node->node_children ("TypedKeyId");
class AuthorizedDeviceInfo
{
public:
- AuthorizedDeviceInfo ()
- : device_list_identifier (make_uuid ())
- /* Sometimes digital_cinema_tools uses this magic thumbprint instead of that from an actual
- recipient certificate. KDMs delivered to City Screen appear to use the same thing.
- */
- , certificate_thumbprint ("2jmj7l5rSw0yVb/vlWAYkK/YBwk=")
- {}
-
+ AuthorizedDeviceInfo () {}
+
AuthorizedDeviceInfo (shared_ptr<const cxml::Node> node)
: device_list_identifier (node->string_child ("DeviceListIdentifier").substr (9))
, device_list_description (node->string_child ("DeviceListDescription"))
xmlpp::Element* device_list = node->add_child ("DeviceList");
device_list->add_child("CertificateThumbprint")->add_child_text (certificate_thumbprint);
}
-
+
+ /** DeviceListIdentifier without the urn:uuid: prefix */
string device_list_identifier;
string device_list_description;
string certificate_thumbprint;
{
public:
X509IssuerSerial () {}
-
+
X509IssuerSerial (shared_ptr<const cxml::Node> node)
: x509_issuer_name (node->string_child ("X509IssuerName"))
, x509_serial_number (node->string_child ("X509SerialNumber"))
{
public:
Recipient () {}
-
+
Recipient (shared_ptr<const cxml::Node> node)
: x509_issuer_serial (node->node_child ("X509IssuerSerial"))
, x509_subject_name (node->string_child ("X509SubjectName"))
x509_issuer_serial.as_xml (node->add_child ("X509IssuerSerial"));
node->add_child("X509SubjectName")->add_child_text (x509_subject_name);
}
-
+
X509IssuerSerial x509_issuer_serial;
string x509_subject_name;
};
{
public:
KDMRequiredExtensions () {}
-
+
KDMRequiredExtensions (shared_ptr<const cxml::Node> node)
: recipient (node->node_child ("Recipient"))
, composition_playlist_id (node->string_child ("CompositionPlaylistId").substr (9))
void as_xml (xmlpp::Element* node) const
{
node->set_attribute ("xmlns", "http://www.smpte-ra.org/schemas/430-1/2006/KDM");
-
+
recipient.as_xml (node->add_child ("Recipient"));
node->add_child("CompositionPlaylistId")->add_child_text ("urn:uuid:" + composition_playlist_id);
- /* XXX: no ContentAuthenticator */
+ if (content_authenticator) {
+ node->add_child("ContentAuthenticator")->add_child_text (content_authenticator.get ());
+ }
node->add_child("ContentTitleText")->add_child_text (content_title_text);
node->add_child("ContentKeysNotValidBefore")->add_child_text (not_valid_before.as_string ());
node->add_child("ContentKeysNotValidAfter")->add_child_text (not_valid_after.as_string ());
authorized_device_info.as_xml (node->add_child ("AuthorizedDeviceInfo"));
key_id_list.as_xml (node->add_child ("KeyIdList"));
-
+
xmlpp::Element* forensic_mark_flag_list = node->add_child ("ForensicMarkFlagList");
forensic_mark_flag_list->add_child("ForensicMarkFlag")->add_child_text ("http://www.smpte-ra.org/430-1/2006/KDM#mrkflg-picture-disable");
forensic_mark_flag_list->add_child("ForensicMarkFlag")->add_child_text ("http://www.smpte-ra.org/430-1/2006/KDM#mrkflg-audio-disable");
}
-
+
Recipient recipient;
string composition_playlist_id;
+ boost::optional<string> content_authenticator;
string content_title_text;
LocalTime not_valid_before;
LocalTime not_valid_after;
{
public:
RequiredExtensions () {}
-
+
RequiredExtensions (shared_ptr<const cxml::Node> node)
: kdm_required_extensions (node->node_child ("KDMRequiredExtensions"))
{
{
kdm_required_extensions.as_xml (node->add_child ("KDMRequiredExtensions"));
}
-
+
KDMRequiredExtensions kdm_required_extensions;
};
: message_id (make_uuid ())
, issue_date (LocalTime().as_string ())
{}
-
+
AuthenticatedPublic (shared_ptr<const cxml::Node> node)
: message_id (node->string_child ("MessageId").substr (9))
, annotation_text (node->string_child ("AnnotationText"))
void as_xml (xmlpp::Element* node, map<string, xmlpp::Attribute *>& references) const
{
references["ID_AuthenticatedPublic"] = node->set_attribute ("Id", "ID_AuthenticatedPublic");
-
+
node->add_child("MessageId")->add_child_text ("urn:uuid:" + message_id);
node->add_child("MessageType")->add_child_text ("http://www.smpte-ra.org/430-1/2006/KDM#kdm-key-type");
node->add_child("AnnotationText")->add_child_text (annotation_text);
{
}
-
+
EncryptedKDMData (shared_ptr<const cxml::Node> node)
: authenticated_public (node->node_child ("AuthenticatedPublic"))
, authenticated_private (node->node_child ("AuthenticatedPrivate"))
, signature (node->node_child ("Signature"))
{
-
+
}
shared_ptr<xmlpp::Document> as_xml () const
}
}
-EncryptedKDM::EncryptedKDM (boost::filesystem::path file)
- : _data (new data::EncryptedKDMData (shared_ptr<cxml::Node> (new cxml::Document ("DCinemaSecurityMessage", file))))
+EncryptedKDM::EncryptedKDM (string s)
{
-
+ shared_ptr<cxml::Document> doc (new cxml::Document ("DCinemaSecurityMessage"));
+ doc->read_string (s);
+ _data = new data::EncryptedKDMData (doc);
}
EncryptedKDM::EncryptedKDM (
- shared_ptr<const Signer> signer,
- shared_ptr<const Certificate> recipient,
+ shared_ptr<const CertificateChain> signer,
+ Certificate recipient,
string device_list_description,
string cpl_id,
string content_title_text,
LocalTime not_valid_before,
LocalTime not_valid_after,
+ Formulation formulation,
list<pair<string, string> > key_ids,
list<string> keys
)
: _data (new data::EncryptedKDMData)
{
/* Fill our XML-ish description in with the juicy bits that the caller has given */
-
+
data::AuthenticatedPublic& aup = _data->authenticated_public;
- aup.signer.x509_issuer_name = signer->certificates().leaf()->issuer ();
- aup.signer.x509_serial_number = signer->certificates().leaf()->serial ();
+ aup.signer.x509_issuer_name = signer->leaf().issuer ();
+ aup.signer.x509_serial_number = signer->leaf().serial ();
data::KDMRequiredExtensions& kre = _data->authenticated_public.required_extensions.kdm_required_extensions;
- kre.recipient.x509_issuer_serial.x509_issuer_name = recipient->issuer ();
- kre.recipient.x509_issuer_serial.x509_serial_number = recipient->serial ();
- kre.recipient.x509_subject_name = recipient->subject ();
+ kre.recipient.x509_issuer_serial.x509_issuer_name = recipient.issuer ();
+ kre.recipient.x509_issuer_serial.x509_serial_number = recipient.serial ();
+ kre.recipient.x509_subject_name = recipient.subject ();
kre.authorized_device_info.device_list_description = device_list_description;
kre.composition_playlist_id = cpl_id;
+ if (formulation == DCI_ANY || formulation == DCI_SPECIFIC) {
+ kre.content_authenticator = signer->leaf().thumbprint ();
+ }
kre.content_title_text = content_title_text;
kre.not_valid_before = not_valid_before;
kre.not_valid_after = not_valid_after;
+ kre.authorized_device_info.device_list_identifier = make_uuid ();
+ string n = recipient.subject_common_name ();
+ if (n.find (".") != string::npos) {
+ n = n.substr (n.find (".") + 1);
+ }
+ kre.authorized_device_info.device_list_description = n;
+
+ if (formulation == MODIFIED_TRANSITIONAL_1 || formulation == DCI_ANY) {
+ /* Use the "assume trust" thumbprint */
+ kre.authorized_device_info.certificate_thumbprint = "2jmj7l5rSw0yVb/vlWAYkK/YBwk=";
+ } else if (formulation == DCI_SPECIFIC) {
+ /* Use the recipient thumbprint */
+ kre.authorized_device_info.certificate_thumbprint = recipient.thumbprint ();
+ }
for (list<pair<string, string> >::const_iterator i = key_ids.begin(); i != key_ids.end(); ++i) {
kre.key_id_list.typed_key_id.push_back (data::TypedKeyId (i->first, i->second));
fwrite (x.c_str(), 1, x.length(), f);
fclose (f);
}
-
+
string
EncryptedKDM::as_xml () const
{