lego/acme/jws.go

125 lines
2.4 KiB
Go
Raw Normal View History

2015-06-11 22:13:43 +00:00
package acme
import (
"bytes"
"crypto"
"crypto/ecdsa"
"crypto/elliptic"
2015-06-11 22:13:43 +00:00
"crypto/rsa"
"fmt"
2015-06-11 22:13:43 +00:00
"net/http"
2016-04-11 04:03:21 +00:00
"errors"
2016-04-11 04:27:12 +00:00
"gopkg.in/square/go-jose.v1"
"time"
2015-06-11 22:13:43 +00:00
)
const TRY_COUNT = 10
const RETRY_PAUSE = time.Second
2015-06-11 22:13:43 +00:00
type jws struct {
directoryURL string
privKey crypto.PrivateKey
nonces []string
2015-06-11 22:13:43 +00:00
}
2015-11-12 01:06:22 +00:00
func keyAsJWK(key interface{}) *jose.JsonWebKey {
switch k := key.(type) {
case *ecdsa.PublicKey:
return &jose.JsonWebKey{Key: k, Algorithm: "EC"}
case *rsa.PublicKey:
return &jose.JsonWebKey{Key: k, Algorithm: "RSA"}
default:
return nil
}
}
2015-06-11 22:13:43 +00:00
// Posts a JWS signed message to the specified URL
func (j *jws) post(url string, content []byte) (*http.Response, error) {
signedContent, err := j.signContent(content)
if err != nil {
return nil, err
}
resp, err := httpPost(url, "application/jose+json", bytes.NewBuffer([]byte(signedContent.FullSerialize())))
if err != nil {
return nil, err
}
j.getNonceFromResponse(resp)
return resp, err
}
func (j *jws) signContent(content []byte) (*jose.JsonWebSignature, error) {
var alg jose.SignatureAlgorithm
switch k := j.privKey.(type) {
case *rsa.PrivateKey:
alg = jose.RS256
case *ecdsa.PrivateKey:
if k.Curve == elliptic.P256() {
alg = jose.ES256
} else if k.Curve == elliptic.P384() {
alg = jose.ES384
}
}
signer, err := jose.NewSigner(alg, j.privKey)
2015-06-11 22:13:43 +00:00
if err != nil {
return nil, err
}
2015-11-12 01:06:22 +00:00
signer.SetNonceSource(j)
2015-06-11 22:13:43 +00:00
2015-11-12 01:06:22 +00:00
signed, err := signer.Sign(content)
2015-06-11 22:13:43 +00:00
if err != nil {
return nil, err
}
return signed, nil
}
func (j *jws) getNonceFromResponse(resp *http.Response) error {
nonce := resp.Header.Get("Replay-Nonce")
if nonce == "" {
return fmt.Errorf("Server did not respond with a proper nonce header.")
}
j.nonces = append(j.nonces, nonce)
return nil
}
2015-06-11 22:13:43 +00:00
func (j *jws) getNonce() error {
resp, err := httpHead(j.directoryURL)
2015-06-11 22:13:43 +00:00
if err != nil {
return err
2015-06-11 22:13:43 +00:00
}
return j.getNonceFromResponse(resp)
}
2015-11-12 01:06:22 +00:00
func (j *jws) Nonce() (string, error) {
nonce := ""
if len(j.nonces) == 0 {
for i := 0; i < TRY_COUNT; i++ {
err := j.getNonce()
if err != nil {
return nonce, err
}
if len(j.nonces) != 0 {
// get nonce ok and can continue
break
}
2016-04-11 04:27:12 +00:00
if i < TRY_COUNT-1 {
time.Sleep(RETRY_PAUSE)
2016-04-11 04:26:45 +00:00
}
2016-04-11 04:03:21 +00:00
}
}
if len(j.nonces) == 0 {
return "", errors.New("Can't get nonce")
}
nonce, j.nonces = j.nonces[len(j.nonces)-1], j.nonces[:len(j.nonces)-1]
2015-11-12 01:06:22 +00:00
return nonce, nil
2015-06-11 22:13:43 +00:00
}