From 2f0bb90c1610ef41f4b786ad2a67f081570c5282 Mon Sep 17 00:00:00 2001 From: Alex D'Andrea Date: Fri, 30 Nov 2018 17:06:10 +0100 Subject: [PATCH] Add function & interface declarations for CA handling Namely: - `pki.createCaStore()` - `pki.verifyCertificateChain()` - interface `CAStore` ... and fix a copy&paste error in the APIDoc of `pki.Certificate.setIssuer()`. --- types/node-forge/index.d.ts | 13 ++++++++++++- types/node-forge/node-forge-tests.ts | 19 +++++++++++++++++++ 2 files changed, 31 insertions(+), 1 deletion(-) diff --git a/types/node-forge/index.d.ts b/types/node-forge/index.d.ts index 1a2b028a90..5e38861db0 100644 --- a/types/node-forge/index.d.ts +++ b/types/node-forge/index.d.ts @@ -67,6 +67,8 @@ declare module "node-forge" { function privateKeyFromPem(pem: PEM): PrivateKey; function certificateToPem(cert: Certificate, maxline?: number): PEM; function certificateFromPem(pem: PEM, computeHash?: boolean, strict?: boolean): Certificate; + function createCaStore(): CAStore; + function verifyCertificateChain(caStore: CAStore, chain: Certificate[], customVerifyCallback?: (verified: boolean | string, depth: number, chain: Certificate[]) => boolean): boolean; interface oids { [key: string]: string; @@ -202,7 +204,7 @@ declare module "node-forge" { */ setSubject(attrs: CertificateField[], uniqueId?: string): void; /** - * Sets the subject of this certificate. + * Sets the issuer of this certificate. * * @param attrs the array of subject attributes to use. * @param uniqueId an optional a unique ID to use. @@ -244,6 +246,15 @@ declare module "node-forge" { } + interface CAStore { + addCertificate(cert: Certificate | string): any; + hasCertificate(cert: Certificate | string): boolean; + removeCertificate(cert: Certificate | string): Certificate | null; + listAllCertificates(): pki.Certificate[]; + getIssuer(subject: Certificate): Certificate | null; + getBySubject(subject: string): Certificate | null; + } + function certificateFromAsn1(obj: asn1.Asn1, computeHash?: boolean): Certificate; function decryptRsaPrivateKey(pem: PEM, passphrase?: string): PrivateKey; diff --git a/types/node-forge/node-forge-tests.ts b/types/node-forge/node-forge-tests.ts index a8d352ad1a..62f0718c21 100644 --- a/types/node-forge/node-forge-tests.ts +++ b/types/node-forge/node-forge-tests.ts @@ -203,3 +203,22 @@ if (forge.util.fillString('1', 5) !== '11111') throw Error('forge.util.fillStrin throw Error("rsa signature verification fail"); } } + +{ + const emptyStore = forge.pki.createCaStore(); + + const certificate = forge.pki.createCertificate(); + const pem = forge.pki.certificateToPem(certificate); + + const caStore = forge.pki.createCaStore(); + caStore.addCertificate(certificate); + caStore.removeCertificate(certificate); + + caStore.listAllCertificates(); + + caStore.removeCertificate(certificate); + + forge.pki.verifyCertificateChain(caStore, [certificate], (verified, depth, chain) => { + return true; + }); +}