Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 9 additions & 7 deletions Stack/Core/Security/Certificates/DirectoryCertificateStore.cs
Original file line number Diff line number Diff line change
Expand Up @@ -426,15 +426,17 @@ public X509Certificate2 LoadPrivateKey(string thumbprint, string subjectName, st
(password == null) ? String.Empty : password,
X509KeyStorageFlags.Exportable | X509KeyStorageFlags.DefaultKeySet);

RSA rsa = certificate.GetRSAPrivateKey();
if (rsa != null)
using (RSA rsa = certificate.GetRSAPrivateKey())
{
int inputBlockSize = rsa.KeySize / 8 - 42;
byte[] bytes1 = rsa.Encrypt(new byte[inputBlockSize], RSAEncryptionPadding.OaepSHA1);
byte[] bytes2 = rsa.Decrypt(bytes1, RSAEncryptionPadding.OaepSHA1);
if (bytes2 != null)
if (rsa != null)
{
return certificate;
int inputBlockSize = rsa.KeySize / 8 - 42;
byte[] bytes1 = rsa.Encrypt(new byte[inputBlockSize], RSAEncryptionPadding.OaepSHA1);
byte[] bytes2 = rsa.Decrypt(bytes1, RSAEncryptionPadding.OaepSHA1);
if (bytes2 != null)
{
return certificate;
}
}
}
}
Expand Down
252 changes: 117 additions & 135 deletions Stack/Core/Security/Certificates/RsaUtils.cs
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,6 @@ MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.
using System.IO;
using System.Security.Cryptography;
using System.Security.Cryptography.X509Certificates;
using Windows.Security.Cryptography;
using Windows.Security.Cryptography.Core;
using Windows.Storage.Streams;

namespace Opc.Ua
{
Expand All @@ -31,20 +28,20 @@ public static class RsaUtils
/// </summary>
public static int GetPlainTextBlockSize(X509Certificate2 encryptingCertificate, bool useOaep)
{
RSA rsa = encryptingCertificate.GetRSAPublicKey();

if (rsa != null)
using (RSA rsa = encryptingCertificate.GetRSAPublicKey())
{
if (useOaep)
{
return rsa.KeySize / 8 - 42;
}
else
if (rsa != null)
{
return rsa.KeySize / 8 - 11;
if (useOaep)
{
return rsa.KeySize / 8 - 42;
}
else
{
return rsa.KeySize / 8 - 11;
}
}
}

return -1;
}

Expand All @@ -53,13 +50,13 @@ public static int GetPlainTextBlockSize(X509Certificate2 encryptingCertificate,
/// </summary>
public static int GetCipherTextBlockSize(X509Certificate2 encryptingCertificate, bool useOaep)
{
RSA rsa = encryptingCertificate.GetRSAPublicKey();

if (rsa != null)
using (RSA rsa = encryptingCertificate.GetRSAPublicKey())
{
return rsa.KeySize / 8;
if (rsa != null)
{
return rsa.KeySize / 8;
}
}

return -1;
}

Expand All @@ -68,14 +65,15 @@ public static int GetCipherTextBlockSize(X509Certificate2 encryptingCertificate,
/// </summary>
public static int RsaPkcs15Sha1_GetSignatureLength(X509Certificate2 signingCertificate)
{
RSA rsa = signingCertificate.GetRSAPublicKey();

if (rsa == null)
using (RSA rsa = signingCertificate.GetRSAPublicKey())
{
throw ServiceResultException.Create(StatusCodes.BadSecurityChecksFailed, "No public key for certificate.");
}
if (rsa == null)
{
throw ServiceResultException.Create(StatusCodes.BadSecurityChecksFailed, "No public key for certificate.");
}

return rsa.KeySize / 8;
return rsa.KeySize / 8;
}
}

/// <summary>
Expand All @@ -86,27 +84,17 @@ public static byte[] RsaPkcs15Sha1_Sign(
X509Certificate2 signingCertificate)
{
// extract the private key.
RSA rsa = signingCertificate.GetRSAPrivateKey();

if (rsa == null)
using (RSA rsa = signingCertificate.GetRSAPrivateKey())
{
throw ServiceResultException.Create(StatusCodes.BadSecurityChecksFailed, "No private key for certificate.");
}

// compute the hash of message.
MemoryStream istrm = new MemoryStream(dataToSign.Array, dataToSign.Offset, dataToSign.Count, false);

// create the hmac.
HashAlgorithmProvider sha1Provider = HashAlgorithmProvider.OpenAlgorithm(HashAlgorithmNames.Sha1);
IBuffer buffer = CryptographicBuffer.CreateFromByteArray(istrm.ToArray());
buffer = sha1Provider.HashData(buffer);
byte[] digest = new byte[buffer.Length];
CryptographicBuffer.CopyToByteArray(buffer, out digest);

istrm.Dispose();
if (rsa == null)
{
throw ServiceResultException.Create(StatusCodes.BadSecurityChecksFailed, "No private key for certificate.");
}

// create the signature.
return rsa.SignHash(digest, HashAlgorithmName.SHA1, RSASignaturePadding.Pkcs1);
// create the signature.
return rsa.SignData(dataToSign.Array, dataToSign.Offset, dataToSign.Count, HashAlgorithmName.SHA1, RSASignaturePadding.Pkcs1);
}
}

/// <summary>
Expand All @@ -118,26 +106,17 @@ public static bool RsaPkcs15Sha1_Verify(
X509Certificate2 signingCertificate)
{
// extract the private key.
RSA rsa = signingCertificate.GetRSAPublicKey();

if (rsa == null)
using (RSA rsa = signingCertificate.GetRSAPublicKey())
{
throw ServiceResultException.Create(StatusCodes.BadSecurityChecksFailed, "No public key for certificate.");
}

// compute the hash of message.
MemoryStream istrm = new MemoryStream(dataToVerify.Array, dataToVerify.Offset, dataToVerify.Count, false);

HashAlgorithmProvider sha1Provider = HashAlgorithmProvider.OpenAlgorithm(HashAlgorithmNames.Sha1);
IBuffer buffer = CryptographicBuffer.CreateFromByteArray(istrm.ToArray());
buffer = sha1Provider.HashData(buffer);
byte[] digest = new byte[buffer.Length];
CryptographicBuffer.CopyToByteArray(buffer, out digest);

istrm.Dispose();
if (rsa == null)
{
throw ServiceResultException.Create(StatusCodes.BadSecurityChecksFailed, "No public key for certificate.");
}

// verify signature.
return rsa.VerifyHash(digest, signature, HashAlgorithmName.SHA1, RSASignaturePadding.Pkcs1);
// verify signature.
return rsa.VerifyData(dataToVerify.Array, dataToVerify.Offset, dataToVerify.Count, signature, HashAlgorithmName.SHA1, RSASignaturePadding.Pkcs1);
}
}

/// <summary>
Expand Down Expand Up @@ -181,54 +160,56 @@ public static ArraySegment<byte> Encrypt(
ArraySegment<byte> outputBuffer)
{
// get the encrypting key.
RSA rsa = encryptingCertificate.GetRSAPublicKey();

if (rsa == null)
{
throw ServiceResultException.Create(StatusCodes.BadSecurityChecksFailed, "No public key for certificate.");
}

int inputBlockSize = GetPlainTextBlockSize(encryptingCertificate, useOaep);
int outputBlockSize = rsa.KeySize / 8;

// verify the input data is the correct block size.
if (dataToEncrypt.Count % inputBlockSize != 0)
using (RSA rsa = encryptingCertificate.GetRSAPublicKey())
{
Utils.Trace("Message is not an integral multiple of the block size. Length = {0}, BlockSize = {1}.", dataToEncrypt.Count, inputBlockSize);
}

byte[] encryptedBuffer = outputBuffer.Array;

MemoryStream ostrm = new MemoryStream(
encryptedBuffer,
outputBuffer.Offset,
outputBuffer.Count);
if (rsa == null)
{
throw ServiceResultException.Create(StatusCodes.BadSecurityChecksFailed, "No public key for certificate.");
}

// encrypt body.
byte[] input = new byte[inputBlockSize];
int inputBlockSize = GetPlainTextBlockSize(encryptingCertificate, useOaep);
int outputBlockSize = rsa.KeySize / 8;

for (int ii = dataToEncrypt.Offset; ii < dataToEncrypt.Offset + dataToEncrypt.Count; ii += inputBlockSize)
{
Array.Copy(dataToEncrypt.Array, ii, input, 0, input.Length);
if (useOaep == true)
// verify the input data is the correct block size.
if (dataToEncrypt.Count % inputBlockSize != 0)
{
byte[] cipherText = rsa.Encrypt(input, RSAEncryptionPadding.OaepSHA1);
ostrm.Write(cipherText, 0, cipherText.Length);
Utils.Trace("Message is not an integral multiple of the block size. Length = {0}, BlockSize = {1}.", dataToEncrypt.Count, inputBlockSize);
}
else

byte[] encryptedBuffer = outputBuffer.Array;

using (MemoryStream ostrm = new MemoryStream(
encryptedBuffer,
outputBuffer.Offset,
outputBuffer.Count))
{
byte[] cipherText = rsa.Encrypt(input, RSAEncryptionPadding.Pkcs1);
ostrm.Write(cipherText, 0, cipherText.Length);
}
}

ostrm.Dispose();
// encrypt body.
byte[] input = new byte[inputBlockSize];

for (int ii = dataToEncrypt.Offset; ii < dataToEncrypt.Offset + dataToEncrypt.Count; ii += inputBlockSize)
{
Array.Copy(dataToEncrypt.Array, ii, input, 0, input.Length);
if (useOaep == true)
{
byte[] cipherText = rsa.Encrypt(input, RSAEncryptionPadding.OaepSHA1);
ostrm.Write(cipherText, 0, cipherText.Length);
}
else
{
byte[] cipherText = rsa.Encrypt(input, RSAEncryptionPadding.Pkcs1);
ostrm.Write(cipherText, 0, cipherText.Length);
}
}
}

// return buffer
return new ArraySegment<byte>(
encryptedBuffer,
outputBuffer.Offset,
(dataToEncrypt.Count / inputBlockSize) * outputBlockSize);
// return buffer
return new ArraySegment<byte>(
encryptedBuffer,
outputBuffer.Offset,
(dataToEncrypt.Count / inputBlockSize) * outputBlockSize);
}
}

/// <summary>
Expand Down Expand Up @@ -270,51 +251,52 @@ public static ArraySegment<byte> Decrypt(
ArraySegment<byte> outputBuffer)
{
// get the encrypting key.
RSA rsa = encryptingCertificate.GetRSAPrivateKey();

if (rsa == null)
using (RSA rsa = encryptingCertificate.GetRSAPrivateKey())
{
throw ServiceResultException.Create(StatusCodes.BadSecurityChecksFailed, "No private key for certificate.");
}

int inputBlockSize = rsa.KeySize / 8;
int outputBlockSize = GetPlainTextBlockSize(encryptingCertificate, useOaep);

// verify the input data is the correct block size.
if (dataToDecrypt.Count % inputBlockSize != 0)
{
Utils.Trace("Message is not an integral multiple of the block size. Length = {0}, BlockSize = {1}.", dataToDecrypt.Count, inputBlockSize);
}

byte[] decryptedBuffer = outputBuffer.Array;

MemoryStream ostrm = new MemoryStream(
decryptedBuffer,
outputBuffer.Offset,
outputBuffer.Count);
if (rsa == null)
{
throw ServiceResultException.Create(StatusCodes.BadSecurityChecksFailed, "No private key for certificate.");
}

// decrypt body.
byte[] input = new byte[inputBlockSize];
int inputBlockSize = rsa.KeySize / 8;
int outputBlockSize = GetPlainTextBlockSize(encryptingCertificate, useOaep);

for (int ii = dataToDecrypt.Offset; ii < dataToDecrypt.Offset + dataToDecrypt.Count; ii += inputBlockSize)
{
Array.Copy(dataToDecrypt.Array, ii, input, 0, input.Length);
if (useOaep == true)
// verify the input data is the correct block size.
if (dataToDecrypt.Count % inputBlockSize != 0)
{
byte[] plainText = rsa.Decrypt(input, RSAEncryptionPadding.OaepSHA1);
ostrm.Write(plainText, 0, plainText.Length);
Utils.Trace("Message is not an integral multiple of the block size. Length = {0}, BlockSize = {1}.", dataToDecrypt.Count, inputBlockSize);
}
else

byte[] decryptedBuffer = outputBuffer.Array;

using (MemoryStream ostrm = new MemoryStream(
decryptedBuffer,
outputBuffer.Offset,
outputBuffer.Count))
{
byte[] plainText = rsa.Decrypt(input, RSAEncryptionPadding.Pkcs1);
ostrm.Write(plainText, 0, plainText.Length);
}
}

ostrm.Dispose();
// decrypt body.
byte[] input = new byte[inputBlockSize];

for (int ii = dataToDecrypt.Offset; ii < dataToDecrypt.Offset + dataToDecrypt.Count; ii += inputBlockSize)
{
Array.Copy(dataToDecrypt.Array, ii, input, 0, input.Length);
if (useOaep == true)
{
byte[] plainText = rsa.Decrypt(input, RSAEncryptionPadding.OaepSHA1);
ostrm.Write(plainText, 0, plainText.Length);
}
else
{
byte[] plainText = rsa.Decrypt(input, RSAEncryptionPadding.Pkcs1);
ostrm.Write(plainText, 0, plainText.Length);
}
}
}

// return buffers.
return new ArraySegment<byte>(decryptedBuffer, outputBuffer.Offset, (dataToDecrypt.Count / inputBlockSize) * outputBlockSize);
// return buffers.
return new ArraySegment<byte>(decryptedBuffer, outputBuffer.Offset, (dataToDecrypt.Count / inputBlockSize) * outputBlockSize);
}
}
#endregion
}
Expand Down
Loading