forked from treetopllc/xml
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathxml_dsig.go
59 lines (51 loc) · 1.45 KB
/
xml_dsig.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
//
// Package xml is a simple wrapper for libxml2.
package xml
/*
#include <stdlib.h>
#include "xml.h"
*/
import "C"
import (
"errors"
"unsafe"
)
/* TODO add wrappers for these and provide methods instead of plain functions
type KeysManager struct {
Ptr C.xmlSecKeysMngrPtr
}
type DigitalSignature struct {
Ptr C.xmlSecDSigCtxPtr
}
*/
// Digitally sign a node in a document using the key and cert pem encoded data
func DigitallySign(doc *Document, node *Node, keyName string, key []byte, cert []byte) error {
keyNameCStr := C.CString(keyName)
defer C.free(unsafe.Pointer(keyNameCStr))
keyPtr := unsafe.Pointer(&key[0])
keyLen := (C.size_t)(len(key))
certPtr := unsafe.Pointer(&cert[0])
certLen := (C.size_t)(len(cert))
res := C.xmlSign(doc.Ptr, node.Ptr, keyNameCStr, keyPtr, keyLen, certPtr, certLen)
if int(res) != 0 {
return errors.New("error digitally signing xml")
}
return nil
}
// DigitallyVerify a signed node in a document using a given pem encoded cert data
func VerifySignature(node *Node, keyName string, key []byte) (bool, error) {
if node == nil || node.Ptr == nil {
return false, nil
}
keyNameCStr := C.CString(keyName)
defer C.free(unsafe.Pointer(keyNameCStr))
keyPtr := unsafe.Pointer(&key[0])
keyLen := (C.size_t)(len(key))
res := int(C.xmlVerify(node.Ptr, keyNameCStr, keyPtr, keyLen))
if res < 0 {
return false, errors.New("error verifying digitally signing xml")
} else if res == 1 {
return true, nil
}
return false, nil
}