Home GnuPG
Diffusion GnuPG 209caaff66fb

gpg: Prepare parser for the new attestation certificates.

Description

gpg: Prepare parser for the new attestation certificates.

* common/openpgpdefs.h (SIGSUBPKT_ATTST_SIGS): New.
* g10/keydb.h (IS_ATTST_SIGS): New.
(IS_CERT): Include the new one.
* g10/sign.c (mk_notation_policy_etc): Do not put notations into
attestation key signatures.
* g10/parse-packet.c (dump_sig_subpkt): Add new arg digest_algo.
Print the attestation sigs.
(parse_one_sig_subpkt): Support SIGSUBPKT_ATTST_SIGS.
(can_handle_critical): Ditto.
(enum_sig_subpkt): Pass digest algo to dump_sig_subpkt.

This change allows to list the new subpacket with --list-packets.
Example output:

:signature packet: algo 22, keyid C694723A1370EAB1
        version 4, created 1567097576, md5len 0, sigclass 0x16
        digest algo 8, begin of digest ff 0c
        hashed subpkt 2 len 4 (sig created 2019-08-29)
        hashed subpkt 37 len 32 (attst-sigs: 1
                                 A794C6E9CCFE2F34C67E07[...])
        hashed subpkt 33 len 21 (issuer fpr v4 156A3872[...])
        subpkt 16 len 8 (issuer key ID C694723A1370EAB1)
        data: [256 bits]
        data: [256 bits]
  • GnuPG-bug-id: T4694
  • Signed-off-by: Werner Koch <wk@gnupg.org>

Details

Provenance
wernerAuthored on Sep 5 2019, 9:27 PM
Parents
rGe1d9be730ca0: gpg: Rework the signature subpacket iteration function.
Branches
Unknown
Tags
Unknown
Tasks
T4694: manage first-party attestations