将XAdES-XL签名扩展为XAdES-A时归档时间戳哈希值错误求助
扩展XAdES-XL到XAdES-A时归档时间戳哈希值错误问题
我尝试严格遵循*ETSI EN 319 132-1 V1.2.1 (2022-02)*第5.5.2.2节的所有步骤,通过添加归档时间戳将XAdES-XL签名扩展为XAdES-A,但始终收到“归档时间戳哈希值不正确”的错误提示。
以下是我的实现代码:
using var finalOctetStream = new MemoryStream(); // ETSI EN 319 132-1 V1.2.1 (2022-02) // 5.5.2.2 >> Article 3 // Take all the ds:Reference elements in their order of appearance within ds:SignedInfo referencing whatever the signer wants to sign including the SignedProperties element. // Process each one as indicated below: foreach (Reference reference in XL_signatureDocument.XadesSignature.SignedInfo.References) { var uri = reference.Uri; byte[] referenceData; if (string.IsNullOrEmpty(uri)) { //Full document referenceData = Encoding.UTF8.GetBytes(xmlDoc.OuterXml); } else { //Select Uri target element var referencedNode = xmlDoc.SelectSingleNode($"//*[@Id='{uri.Substring(1)}']"); referenceData = Encoding.UTF8.GetBytes(referencedNode.OuterXml); } if (reference.TransformChain != null && reference.TransformChain.Count > 0) { // 5.5.2.2 >> Artcile 3-C // If the ds:Reference element contains the ds:Transforms element, then apply all the transforms indicated within the ds:Transform children elements. After that: foreach (var transform in reference.TransformChain) referenceData = XMLUtil.ApplyTransform(referenceData, (System.Security.Cryptography.Xml.Transform)transform); // c) if the output of the last transform is a XML node-set according to XMLDSIG [1], canonicalize it as specified in clause 4.5 of the present document; if (IsXmlNodeSet(referenceData)) referenceData = XMLUtil.ApplyTransform(referenceData, new XmlDsigC14NTransform()); } else { //b) if the retrieved data object is an XML node-set, then canonicalize it as specified in clause 4.5 of the present document; if (IsXmlNodeSet(referenceData)) referenceData = XMLUtil.ApplyTransform(referenceData, new XmlDsigC14NTransform()); } //d) Concatenate the resulting octets to the final octet stream. finalOctetStream.Write(referenceData, 0, referenceData.Length); } // 5.5.2.2 >>> Article 4 // Take the following XMLDSIG elements in the order they are listed below, canonicalize each one as specified in clause 4.5, and concatenate each resulting octet stream to the final octet stream: // The ds:SignedInfo element. // The ds:SignatureValue element. // The ds:KeyInfo element, if present. var signatureValueElementXpaths = new ArrayList() { "ds:SignedInfo", "ds:SignatureValue", "ds:KeyInfo" }; // 5.5.2.2 >>> Article 5 and 6 // Take the unsigned signature qualifying properties that appear before the current ArchiveTimeStamp in the order they appear within the UnsignedSignatureProperties, // canonicalize each one as specified in clause 4.5, and concatenate each resulting octet stream to the final octet stream. While concatenating, the following rules apply: signatureValueElementXpaths.Add("ds:Object/xades:QualifyingProperties/xades:UnsignedProperties/xades:UnsignedSignatureProperties/xades:SignatureTimeStamp"); signatureValueElementXpaths.Add("ds:Object/xades:QualifyingProperties/xades:UnsignedProperties/xades:UnsignedSignatureProperties/xades:CompleteCertificateRefs"); signatureValueElementXpaths.Add("ds:Object/xades:QualifyingProperties/xades:UnsignedProperties/xades:UnsignedSignatureProperties/xades:CompleteRevocationRefs"); signatureValueElementXpaths.Add("ds:Object/xades:QualifyingProperties/xades:UnsignedProperties/xades:UnsignedSignatureProperties/xades:CertificateValues"); signatureValueElementXpaths.Add("ds:Object/xades:QualifyingProperties/xades:UnsignedProperties/xades:UnsignedSignatureProperties/xades:RevocationValues"); var canonizeData = XMLUtil.ComputeCanonicalizedValueOfElementList1(XL_signatureDocument.XadesSignature, signatureValueElementXpaths, new XmlDsigC14NTransform()); finalOctetStream.Write(canonizeData, 0, canonizeData.Length); // And send to timestamp server var tstoken = GetTimeStampToken(SignatureTsa, finalOctetStream.ToArray(), SignatureType != SignatureType.XAdES_A); var archiveTimeStamp = new TimeStamp("ArchiveTimeStamp") { Id = "ArchiveTimeStamp-" + XL_signatureDocument.XadesSignature.Signature.Id, CanonicalizationMethod = new CanonicalizationMethod() { Algorithm = new XmlDsigC14NTransform().Algorithm } }; archiveTimeStamp.EncapsulatedTimeStamp.PkiData = tstoken; archiveTimeStamp.EncapsulatedTimeStamp.Id = "ArchiveTimeStamp-" + Guid.NewGuid(); unsignedProperties = XL_signatureDocument.XadesSignature.UnsignedProperties; unsignedProperties.UnsignedSignatureProperties.ArchiveTimeStampCollection.Add(archiveTimeStamp); XL_signatureDocument.XadesSignature.UnsignedProperties = unsignedProperties; XL_signatureDocument.UpdateDocument();
我使用XAdES一致性检查器和DSS验证工具进行签名验证。
内容的提问来源于stack exchange,提问作者Fatih POLAT
相关产品推荐
相关产品推荐

