Source code

Revision control

Copy as Markdown

Other Tools

#!/usr/bin/env python
# This Source Code Form is subject to the terms of the Mozilla Public
# License, v. 2.0. If a copy of the MPL was not distributed with this
# file, You can obtain one at
Reads a key specification from stdin or a file and outputs a
PKCS #8 file representing the (private) key. Also provides
methods for signing data and representing the key as a subject
public key info for use with pyasn1.
The key specification format is as follows:
default: a 2048-bit RSA key
alternate: a different 2048-bit RSA key
ev: a 2048-bit RSA key that, when combined with the right pycert
specification, results in a certificate that is enabled for
extended validation in debug Firefox (see ExtendedValidation.cpp).
evRSA2040: a 2040-bit RSA key that, when combined with the right pycert
specification, results in a certificate that is enabled for
extended validation in debug Firefox.
rsa2040: a 2040-bit RSA key
rsa1024: a 1024-bit RSA key
rsa1016: a 1016-bit RSA key
secp256k1: an ECC key on the curve secp256k1
secp244r1: an ECC key on the curve secp244r1
secp256r1: an ECC key on the curve secp256r1
secp384r1: an ECC key on the curve secp384r1
secp521r1: an ECC key on the curve secp521r1
import base64
import binascii
import hashlib
import math
import sys
import ecdsa
import rsa
import six
from pyasn1.codec.der import encoder
from pyasn1.type import namedtype, tag, univ
from pyasn1_modules import rfc2459
# "constants" to make it easier for consumers to specify hash algorithms
HASH_MD5 = "hash:md5"
HASH_SHA1 = "hash:sha1"
HASH_SHA256 = "hash:sha256"
HASH_SHA384 = "hash:sha384"
HASH_SHA512 = "hash:sha512"
# NOTE: With bug 1621441 we migrated from one library for ecdsa to another.
# These libraries differ somewhat in terms of functionality and interface. In
# order to ensure there are no diffs and that the generated signatures are
# exactly the same between the two libraries, we need to patch some stuff in.
def _gen_k(curve):
# This calculation is arbitrary, but it matches what we were doing pre-
# bug 1621441 (see the above NOTE). Crucially, this generation of k is
# non-random; the ecdsa library exposes an option to deterministically
# generate a value of k for us, but it doesn't match up to what we were
# doing before so we have to inject a custom value.
num_bytes = int(math.log(curve.order - 1, 2) + 1) // 8 + 8
entropy = int.from_bytes(b"\04" * num_bytes, byteorder="big")
p = curve.curve.p()
return (entropy % (p - 1)) + 1
# As above, the library has built-in logic for truncating digests that are too
# large, but they use a slightly different technique than our previous library.
# Re-implement that logic here.
def _truncate_digest(digest, curve):
i = int.from_bytes(digest, byteorder="big")
p = curve.curve.p()
while i > p:
i >>= 1
return i.to_bytes(math.ceil(i.bit_length() / 8), byteorder="big")
def byteStringToHexifiedBitString(string):
"""Takes a string of bytes and returns a hex string representing
those bytes for use with pyasn1.type.univ.BitString. It must be of
the form "'<hex bytes>'H", where the trailing 'H' indicates to
pyasn1 that the input is a hex string."""
return "'%s'H" % six.ensure_binary(string).hex()
class UnknownBaseError(Exception):
"""Base class for handling unexpected input in this module."""
def __init__(self, value):
super(UnknownBaseError, self).__init__()
self.value = value
self.category = "input"
def __str__(self):
return 'Unknown %s type "%s"' % (self.category, repr(self.value))
class UnknownKeySpecificationError(UnknownBaseError):
"""Helper exception type to handle unknown key specifications."""
def __init__(self, value):
UnknownBaseError.__init__(self, value)
self.category = "key specification"
class UnknownHashAlgorithmError(UnknownBaseError):
"""Helper exception type to handle unknown key specifications."""
def __init__(self, value):
UnknownBaseError.__init__(self, value)
self.category = "hash algorithm"
class UnsupportedHashAlgorithmError(Exception):
"""Helper exception type for unsupported hash algorithms."""
def __init__(self, value):
super(UnsupportedHashAlgorithmError, self).__init__()
self.value = value
def __str__(self):
return 'Unsupported hash algorithm "%s"' % repr(self.value)
class RSAPublicKey(univ.Sequence):
"""Helper type for encoding an RSA public key"""
componentType = namedtype.NamedTypes(
namedtype.NamedType("N", univ.Integer()),
namedtype.NamedType("E", univ.Integer()),
class RSAPrivateKey(univ.Sequence):
"""Helper type for encoding an RSA private key"""
componentType = namedtype.NamedTypes(
namedtype.NamedType("version", univ.Integer()),
namedtype.NamedType("modulus", univ.Integer()),
namedtype.NamedType("publicExponent", univ.Integer()),
namedtype.NamedType("privateExponent", univ.Integer()),
namedtype.NamedType("prime1", univ.Integer()),
namedtype.NamedType("prime2", univ.Integer()),
namedtype.NamedType("exponent1", univ.Integer()),
namedtype.NamedType("exponent2", univ.Integer()),
namedtype.NamedType("coefficient", univ.Integer()),
class ECPrivateKey(univ.Sequence):
"""Helper type for encoding an EC private key
ECPrivateKey ::= SEQUENCE {
version INTEGER { ecPrivkeyVer1(1) } (ecPrivkeyVer1),
privateKey OCTET STRING,
parameters [0] ECParameters {{ NamedCurve }} OPTIONAL,
(NOTE: parameters field is not supported)
componentType = namedtype.NamedTypes(
namedtype.NamedType("version", univ.Integer()),
namedtype.NamedType("privateKey", univ.OctetString()),
explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1)
class ECPoint(univ.Sequence):
"""Helper type for encoding a EC point"""
componentType = namedtype.NamedTypes(
namedtype.NamedType("x", univ.Integer()),
namedtype.NamedType("y", univ.Integer()),
class PrivateKeyInfo(univ.Sequence):
"""Helper type for encoding a PKCS #8 private key info"""
componentType = namedtype.NamedTypes(
namedtype.NamedType("version", univ.Integer()),
namedtype.NamedType("privateKeyAlgorithm", rfc2459.AlgorithmIdentifier()),
namedtype.NamedType("privateKey", univ.OctetString()),
class RSAKey(object):
# For reference, when encoded as a subject public key info, the
# base64-encoded sha-256 hash of this key is
# VCIlmPM9NkgFQtrs4Oa5TeFcDu6MWRTKSNdePEhOgD8=
sharedRSA_N = int(
sharedRSA_E = 65537
sharedRSA_D = int(
sharedRSA_P = int(
sharedRSA_Q = int(
sharedRSA_exp1 = int(
sharedRSA_exp2 = int(
sharedRSA_coef = int(
# For reference, when encoded as a subject public key info, the
# base64-encoded sha-256 hash of this key is
alternateRSA_N = int(
alternateRSA_E = 65537
alternateRSA_D = int(
alternateRSA_P = int(
alternateRSA_Q = int(
alternateRSA_exp1 = int(
alternateRSA_exp2 = int(
alternateRSA_coef = int(
evRSA_N = int(
evRSA_E = 65537
evRSA_D = int(
evRSA_P = int(
evRSA_Q = int(
evRSA_exp1 = int(
evRSA_exp2 = int(
evRSA_coef = int(
evRSA2040_N = int(
evRSA2040_E = 65537
evRSA2040_D = int(
evRSA2040_P = int(
evRSA2040_Q = int(
evRSA2040_exp1 = int(
evRSA2040_exp2 = int(
evRSA2040_coef = int(
rsa2040_N = int(
rsa2040_E = 65537
rsa2040_D = int(
rsa2040_P = int(
rsa2040_Q = int(
rsa2040_exp1 = int(
rsa2040_exp2 = int(
rsa2040_coef = int(
rsa1024_N = int(
rsa1024_E = 65537
rsa1024_D = int(
rsa1024_P = int(
rsa1024_Q = int(
rsa1024_exp1 = int(
rsa1024_exp2 = int(
rsa1024_coef = int(
rsa1016_N = int(
rsa1016_E = 65537
rsa1016_D = int(
rsa1016_P = int(
rsa1016_Q = int(
rsa1016_exp1 = int(
rsa1016_exp2 = int(
rsa1016_coef = int(
def __init__(self, specification):
if specification == "default":
self.RSA_N = self.sharedRSA_N
self.RSA_E = self.sharedRSA_E
self.RSA_D = self.sharedRSA_D
self.RSA_P = self.sharedRSA_P
self.RSA_Q = self.sharedRSA_Q
self.RSA_exp1 = self.sharedRSA_exp1
self.RSA_exp2 = self.sharedRSA_exp2
self.RSA_coef = self.sharedRSA_coef
elif specification == "alternate":
self.RSA_N = self.alternateRSA_N
self.RSA_E = self.alternateRSA_E
self.RSA_D = self.alternateRSA_D
self.RSA_P = self.alternateRSA_P
self.RSA_Q = self.alternateRSA_Q
self.RSA_exp1 = self.alternateRSA_exp1
self.RSA_exp2 = self.alternateRSA_exp2
self.RSA_coef = self.alternateRSA_coef
elif specification == "ev":
self.RSA_N = self.evRSA_N
self.RSA_E = self.evRSA_E
self.RSA_D = self.evRSA_D
self.RSA_P = self.evRSA_P
self.RSA_Q = self.evRSA_Q
self.RSA_exp1 = self.evRSA_exp1
self.RSA_exp2 = self.evRSA_exp2
self.RSA_coef = self.evRSA_coef
elif specification == "evRSA2040":
self.RSA_N = self.evRSA2040_N
self.RSA_E = self.evRSA2040_E
self.RSA_D = self.evRSA2040_D
self.RSA_P = self.evRSA2040_P
self.RSA_Q = self.evRSA2040_Q
self.RSA_exp1 = self.evRSA2040_exp1
self.RSA_exp2 = self.evRSA2040_exp2
self.RSA_coef = self.evRSA2040_coef
elif specification == "rsa2040":
self.RSA_N = self.rsa2040_N
self.RSA_E = self.rsa2040_E
self.RSA_D = self.rsa2040_D
self.RSA_P = self.rsa2040_P
self.RSA_Q = self.rsa2040_Q
self.RSA_exp1 = self.rsa2040_exp1
self.RSA_exp2 = self.rsa2040_exp2
self.RSA_coef = self.rsa2040_coef
elif specification == "rsa1024":
self.RSA_N = self.rsa1024_N
self.RSA_E = self.rsa1024_E
self.RSA_D = self.rsa1024_D
self.RSA_P = self.rsa1024_P
self.RSA_Q = self.rsa1024_Q
self.RSA_exp1 = self.rsa1024_exp1
self.RSA_exp2 = self.rsa1024_exp2
self.RSA_coef = self.rsa1024_coef
elif specification == "rsa1016":
self.RSA_N = self.rsa1016_N
self.RSA_E = self.rsa1016_E
self.RSA_D = self.rsa1016_D
self.RSA_P = self.rsa1016_P
self.RSA_Q = self.rsa1016_Q
self.RSA_exp1 = self.rsa1016_exp1
self.RSA_exp2 = self.rsa1016_exp2
self.RSA_coef = self.rsa1016_coef
raise UnknownKeySpecificationError(specification)
def toDER(self):
privateKeyInfo = PrivateKeyInfo()
privateKeyInfo["version"] = 0
algorithmIdentifier = rfc2459.AlgorithmIdentifier()
algorithmIdentifier["algorithm"] = rfc2459.rsaEncryption
# Directly setting parameters to univ.Null doesn't currently work.
nullEncapsulated = encoder.encode(univ.Null())
algorithmIdentifier["parameters"] = univ.Any(nullEncapsulated)
privateKeyInfo["privateKeyAlgorithm"] = algorithmIdentifier
rsaPrivateKey = RSAPrivateKey()
rsaPrivateKey["version"] = 0
rsaPrivateKey["modulus"] = self.RSA_N
rsaPrivateKey["publicExponent"] = self.RSA_E
rsaPrivateKey["privateExponent"] = self.RSA_D
rsaPrivateKey["prime1"] = self.RSA_P
rsaPrivateKey["prime2"] = self.RSA_Q
rsaPrivateKey["exponent1"] = self.RSA_exp1
rsaPrivateKey["exponent2"] = self.RSA_exp2
rsaPrivateKey["coefficient"] = self.RSA_coef
rsaPrivateKeyEncoded = encoder.encode(rsaPrivateKey)
privateKeyInfo["privateKey"] = univ.OctetString(rsaPrivateKeyEncoded)
return encoder.encode(privateKeyInfo)
def toPEM(self):
output = "-----BEGIN PRIVATE KEY-----"
der = self.toDER()
b64 = six.ensure_text(base64.b64encode(der))
while b64:
output += "\n" + b64[:64]
b64 = b64[64:]
output += "\n-----END PRIVATE KEY-----"
return output
def asSubjectPublicKeyInfo(self):
"""Returns a subject public key info representing
this key for use by pyasn1."""
algorithmIdentifier = rfc2459.AlgorithmIdentifier()
algorithmIdentifier["algorithm"] = rfc2459.rsaEncryption
# Directly setting parameters to univ.Null doesn't currently work.
nullEncapsulated = encoder.encode(univ.Null())
algorithmIdentifier["parameters"] = univ.Any(nullEncapsulated)
spki = rfc2459.SubjectPublicKeyInfo()
spki["algorithm"] = algorithmIdentifier
rsaKey = RSAPublicKey()
rsaKey["N"] = univ.Integer(self.RSA_N)
rsaKey["E"] = univ.Integer(self.RSA_E)
subjectPublicKey = univ.BitString(
spki["subjectPublicKey"] = subjectPublicKey
return spki
def sign(self, data, hashAlgorithm):
"""Returns a hexified bit string representing a
signature by this key over the specified data.
Intended for use with pyasn1.type.univ.BitString"""
hashAlgorithmName = None
if hashAlgorithm == HASH_MD5:
hashAlgorithmName = "MD5"
elif hashAlgorithm == HASH_SHA1:
hashAlgorithmName = "SHA-1"
elif hashAlgorithm == HASH_SHA256:
hashAlgorithmName = "SHA-256"
elif hashAlgorithm == HASH_SHA384:
hashAlgorithmName = "SHA-384"
elif hashAlgorithm == HASH_SHA512:
hashAlgorithmName = "SHA-512"
raise UnknownHashAlgorithmError(hashAlgorithm)
rsaPrivateKey = rsa.PrivateKey(
self.RSA_N, self.RSA_E, self.RSA_D, self.RSA_P, self.RSA_Q
signature = rsa.sign(data, rsaPrivateKey, hashAlgorithmName)
return byteStringToHexifiedBitString(signature)
ecPublicKey = univ.ObjectIdentifier("1.2.840.10045.2.1")
secp256k1 = univ.ObjectIdentifier("")
secp224r1 = univ.ObjectIdentifier("")
secp256r1 = univ.ObjectIdentifier("1.2.840.10045.3.1.7")
secp384r1 = univ.ObjectIdentifier("")
secp521r1 = univ.ObjectIdentifier("")
def longToEvenLengthHexString(val):
h = format(val, "x")
if not len(h) % 2 == 0:
h = "0" + h
return h
class ECCKey(object):
secp256k1KeyPair = (
+ "4382a9500c41dad770ffd4b511bf4b492eb1238800c32c4f76c73a3f3294e7c5",
secp224r1KeyPair = (
+ "00e88f0066d7af63c3298ba377348a1202b03b37fd6b1ff415aa311e",
secp256r1KeyPair = (
+ "2a69d233456c36c4119d0706e00eedc8d19390d7991b7b2d07a304eaa04aa6c0",
secp384r1KeyPair = (
+ "32da8ce98e831534e6a9c0c0b09c8d639ade83206e5ba813473a11fa330e05da8c9"
+ "6e4383fe27873da97103be2888cff002f05af71a1fddcc8374aa6ea9ce",
+ "393772b57602ff31365efe1393246",
secp521r1KeyPair = (
+ "6ea1c483a1827a010b9128e3a08070ca33ef5f57835b7c1ba251f6cc3521dc42b01"
+ "0653451981b445d343eed3782a35d6cff0ff484f5a883d209f1b9042b726703568b"
+ "2f326e18b833bdd8aa0734392bcd19501e10d698a79f53e11e0a22bdd2aad90",
+ "8c69d2d05e8c01788a7d0b6e235aa5e783fc1bee807dcc3865f920e12cf8f2d29",
def __init__(self, specification):
if specification == "secp256k1":
key_pair = self.secp256k1KeyPair
self.keyOID = secp256k1
self.curve = ecdsa.SECP256k1
elif specification == "secp224r1":
key_pair = self.secp224r1KeyPair
self.keyOID = secp224r1
self.curve = ecdsa.NIST224p
elif specification == "secp256r1":
key_pair = self.secp256r1KeyPair
self.keyOID = secp256r1
self.curve = ecdsa.NIST256p
elif specification == "secp384r1":
key_pair = self.secp384r1KeyPair
self.keyOID = secp384r1
self.curve = ecdsa.NIST384p
elif specification == "secp521r1":
key_pair = self.secp521r1KeyPair
self.keyOID = secp521r1
self.curve = ecdsa.NIST521p
raise UnknownKeySpecificationError(specification)
self.public_key, self.private_key = (
self.key = ecdsa.SigningKey.from_string(self.private_key, curve=self.curve)
def getPublicKeyHexifiedString(self):
"""Returns the EC public key as a hex string using the uncompressed
point representation. This is intended to be used in the encoder
functions, as it surrounds the value with ''H to indicate its type."""
p1, p2 = (
self.public_key[: len(self.public_key) // 2],
self.public_key[len(self.public_key) // 2 :],
# We don't want leading zeroes.
p1, p2 = (p1.lstrip(b"\0"), p2.lstrip(b"\0"))
# '04' indicates that the points are in uncompressed form.
return byteStringToHexifiedBitString(b"\04" + p1 + p2)
def toPEM(self):
"""Return the EC private key in PEM-encoded form."""
output = "-----BEGIN EC PRIVATE KEY-----"
der = self.toDER()
b64 = six.ensure_text(base64.b64encode(der))
while b64:
output += "\n" + b64[:64]
b64 = b64[64:]
output += "\n-----END EC PRIVATE KEY-----"
return output
def toDER(self):
"""Return the EC private key in DER-encoded form, encoded per SEC 1
section C.4 format."""
privateKeyInfo = PrivateKeyInfo()
privateKeyInfo["version"] = 0
algorithmIdentifier = rfc2459.AlgorithmIdentifier()
algorithmIdentifier["algorithm"] = ecPublicKey
algorithmIdentifier["parameters"] = self.keyOID
privateKeyInfo["privateKeyAlgorithm"] = algorithmIdentifier
ecPrivateKey = ECPrivateKey()
ecPrivateKey["version"] = 1
ecPrivateKey["privateKey"] = self.private_key
ecPrivateKey["publicKey"] = univ.BitString(
).subtype(explicitTag=tag.Tag(tag.tagClassContext, tag.tagFormatSimple, 1))
ecPrivateKeyEncoded = encoder.encode(ecPrivateKey)
privateKeyInfo["privateKey"] = univ.OctetString(ecPrivateKeyEncoded)
return encoder.encode(privateKeyInfo)
def asSubjectPublicKeyInfo(self):
"""Returns a subject public key info representing
this key for use by pyasn1."""
algorithmIdentifier = rfc2459.AlgorithmIdentifier()
algorithmIdentifier["algorithm"] = ecPublicKey
algorithmIdentifier["parameters"] = self.keyOID
spki = rfc2459.SubjectPublicKeyInfo()
spki["algorithm"] = algorithmIdentifier
spki["subjectPublicKey"] = univ.BitString(self.getPublicKeyHexifiedString())
return spki
def signRaw(self, data, hashAlgorithm):
"""Performs the ECDSA signature algorithm over the given data.
The returned value is a string representing the bytes of the
resulting point when encoded by left-padding each of (r, s) to
the key size and concatenating them.
assert hashAlgorithm.startswith("hash:")
hashAlgorithm = hashAlgorithm[len("hash:") :]
k = _gen_k(self.curve)
digest =, six.ensure_binary(data)).digest()
digest = _truncate_digest(digest, self.curve)
# NOTE: Under normal circumstances it's advisable to use
# sign_digest_deterministic. In this case we don't want the library's
# default generation of k, so we call the normal "sign" method and
# inject it here.
return self.key.sign_digest(digest, sigencode=ecdsa.util.sigencode_string, k=k)
def sign(self, data, hashAlgorithm):
"""Returns a hexified bit string representing a
signature by this key over the specified data.
Intended for use with pyasn1.type.univ.BitString"""
# signRaw returns an encoded point, which is useful in some situations.
# However, for signatures on X509 certificates, we need to decode it so
# we can encode it as a BITSTRING consisting of a SEQUENCE of two
raw = self.signRaw(data, hashAlgorithm)
point = ECPoint()
point["x"] = int.from_bytes(raw[: len(raw) // 2], byteorder="big")
point["y"] = int.from_bytes(raw[len(raw) // 2 :], byteorder="big")
return byteStringToHexifiedBitString(encoder.encode(point))
def keyFromSpecification(specification):
"""Pass in a specification, get the appropriate key back."""
if specification.startswith("secp"):
return ECCKey(specification)
return RSAKey(specification)
# The build harness will call this function with an output file-like
# object and a path to a file containing a specification. This will
# read the specification and output the key as ASCII-encoded PKCS #8.
def main(output, inputPath):
with open(inputPath) as configStream:
output.write(keyFromSpecification( + "\n")
# When run as a standalone program, this will read a specification from
# stdin and output the certificate as PEM to stdout.
if __name__ == "__main__":