2016-12-26 02:16:37 +01:00
|
|
|
package jwt
|
|
|
|
|
|
|
|
import (
|
|
|
|
"crypto"
|
|
|
|
"crypto/ecdsa"
|
|
|
|
"errors"
|
|
|
|
"math/big"
|
|
|
|
)
|
|
|
|
|
|
|
|
var (
|
|
|
|
// Sadly this is missing from crypto/ecdsa compared to crypto/rsa
|
|
|
|
ErrECDSAVerification = errors.New("crypto/ecdsa: verification error")
|
|
|
|
)
|
|
|
|
|
|
|
|
// Implements the ECDSA family of signing methods signing methods
|
2019-07-06 17:16:43 +02:00
|
|
|
// Expects *ecdsa.PrivateKey for signing and *ecdsa.PublicKey for verification
|
2016-12-26 02:16:37 +01:00
|
|
|
type SigningMethodECDSA struct {
|
|
|
|
Name string
|
|
|
|
Hash crypto.Hash
|
|
|
|
KeySize int
|
|
|
|
CurveBits int
|
|
|
|
}
|
|
|
|
|
|
|
|
// Specific instances for EC256 and company
|
|
|
|
var (
|
|
|
|
SigningMethodES256 *SigningMethodECDSA
|
|
|
|
SigningMethodES384 *SigningMethodECDSA
|
|
|
|
SigningMethodES512 *SigningMethodECDSA
|
|
|
|
)
|
|
|
|
|
|
|
|
func init() {
|
|
|
|
// ES256
|
|
|
|
SigningMethodES256 = &SigningMethodECDSA{"ES256", crypto.SHA256, 32, 256}
|
|
|
|
RegisterSigningMethod(SigningMethodES256.Alg(), func() SigningMethod {
|
|
|
|
return SigningMethodES256
|
|
|
|
})
|
|
|
|
|
|
|
|
// ES384
|
|
|
|
SigningMethodES384 = &SigningMethodECDSA{"ES384", crypto.SHA384, 48, 384}
|
|
|
|
RegisterSigningMethod(SigningMethodES384.Alg(), func() SigningMethod {
|
|
|
|
return SigningMethodES384
|
|
|
|
})
|
|
|
|
|
|
|
|
// ES512
|
|
|
|
SigningMethodES512 = &SigningMethodECDSA{"ES512", crypto.SHA512, 66, 521}
|
|
|
|
RegisterSigningMethod(SigningMethodES512.Alg(), func() SigningMethod {
|
|
|
|
return SigningMethodES512
|
|
|
|
})
|
|
|
|
}
|
|
|
|
|
|
|
|
func (m *SigningMethodECDSA) Alg() string {
|
|
|
|
return m.Name
|
|
|
|
}
|
|
|
|
|
|
|
|
// Implements the Verify method from SigningMethod
|
|
|
|
// For this verify method, key must be an ecdsa.PublicKey struct
|
|
|
|
func (m *SigningMethodECDSA) Verify(signingString, signature string, key interface{}) error {
|
|
|
|
var err error
|
|
|
|
|
|
|
|
// Decode the signature
|
|
|
|
var sig []byte
|
|
|
|
if sig, err = DecodeSegment(signature); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
// Get the key
|
|
|
|
var ecdsaKey *ecdsa.PublicKey
|
|
|
|
switch k := key.(type) {
|
|
|
|
case *ecdsa.PublicKey:
|
|
|
|
ecdsaKey = k
|
|
|
|
default:
|
|
|
|
return ErrInvalidKeyType
|
|
|
|
}
|
|
|
|
|
|
|
|
if len(sig) != 2*m.KeySize {
|
|
|
|
return ErrECDSAVerification
|
|
|
|
}
|
|
|
|
|
|
|
|
r := big.NewInt(0).SetBytes(sig[:m.KeySize])
|
|
|
|
s := big.NewInt(0).SetBytes(sig[m.KeySize:])
|
|
|
|
|
|
|
|
// Create hasher
|
|
|
|
if !m.Hash.Available() {
|
|
|
|
return ErrHashUnavailable
|
|
|
|
}
|
|
|
|
hasher := m.Hash.New()
|
|
|
|
hasher.Write([]byte(signingString))
|
|
|
|
|
|
|
|
// Verify the signature
|
2021-07-24 17:13:56 +02:00
|
|
|
if verifystatus := ecdsa.Verify(ecdsaKey, hasher.Sum(nil), r, s); verifystatus {
|
2016-12-26 02:16:37 +01:00
|
|
|
return nil
|
|
|
|
}
|
2021-07-24 17:13:56 +02:00
|
|
|
|
|
|
|
return ErrECDSAVerification
|
2016-12-26 02:16:37 +01:00
|
|
|
}
|