What are formatPEM.js and pkcs12chain, where are they from, why aren't they installed via npm and are you sure pki.js or asn1js doesn't already provide this? Whenever you pull in external files please add them in separate commit and add into commit description where they came from and why they were added
HASH_ALG, RSA_SIGN_ALG, EC_SIGN_ALG, KEY_SIZE should all really go away and they should be pulled from /api/bootstrap instead. Looks like at least hash algorithm is missing, please add it under certificate.authority dict. There's more hardcoded stuff that should really be pulled from /api/bootstraphttps://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L250
All the P12 stuff should really happen inside case 'p12':
crypto.generateKey is the only long running function call, I don't see reason to complicate code with sequence here?
PKI terminologiy is a mess, to clarify:
DER format is the ASN1 structure encoded to bytes
BER is subset of DER, to simplify things consider them equivalent
PEM is the same DER piece encoded in base64 and surrounded by ----- BEGIN ... ----- and ----- END ... -----
PKCS 12 = PKCS#12 = P12 = PFX which is format to store key+cert bundles. It's really painful to work with because it lacks support everywhere but it's the only method to supply key+cert to StrongSwan client on Android/iOS
* What are `formatPEM.js` and `pkcs12chain`, where are they from, why aren't they installed via `npm` and are you sure `pki.js` or `asn1js` doesn't already provide this? Whenever you pull in external files please add them in separate commit and add into commit description where they came from and why they were added
* `HASH_ALG`, `RSA_SIGN_ALG`, `EC_SIGN_ALG`, `KEY_SIZE` should all really go away and they should be pulled from `/api/bootstrap` instead. Looks like at least hash algorithm is missing, please add it under `certificate.authority` dict. There's more hardcoded stuff that should really be pulled from `/api/bootstrap` https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L250
* All the [P12 stuff](https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L236) should really happen inside `case 'p12':`
* Please remove all messy inline conversions and use external function for converting between PEM/DER/whatever (base64 convert, line length limit and also ASCII armor text): https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L135 https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L231 https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L274 https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L324 etc. Create own functions if you're sure `pki.js` or `asn1js` doesn't include what you need
* `crypto.generateKey` is the only long running function call, I don't see reason to complicate code with `sequence` here?
PKI terminologiy is a mess, to clarify:
* DER format is the ASN1 structure encoded to bytes
* BER is subset of DER, to simplify things consider them equivalent
* PEM is the same DER piece encoded in base64 and surrounded by `----- BEGIN ... -----` and `----- END ... -----`
* PKCS 12 = PKCS#12 = P12 = PFX which is format to store key+cert bundles. It's really painful to work with because it lacks support everywhere but it's the only method to supply key+cert to StrongSwan client on Android/iOS
Did you test downloading StrongSwan profile (.sswan)? It should contain sensible JSON and the `local.p12` attribute should contain P12 bundle that you should be able to parse with `openssl pkcs12`. For more info see https://wiki.strongswan.org/projects/strongswan/wiki/AndroidVPNClientProfiles
What are formatPEM.js and pkcs12chain, where are they from, why aren't they installed via npm and are you sure pki.js or asn1js doesn't already provide this? Whenever you pull in external files please add them in separate commit and add into commit description where they came from and why they were added
HASH_ALG, RSA_SIGN_ALG, EC_SIGN_ALG, KEY_SIZE should all really go away and they should be pulled from /api/bootstrap instead. Looks like at least hash algorithm is missing, please add it under certificate.authority dict. There's more hardcoded stuff that should really be pulled from /api/bootstrap https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L250
Fixed
All the P12 stuff should really happen inside case 'p12':
crypto.generateKey is the only long running function call, I don't see reason to complicate code with sequence here?
Fixed
> What are formatPEM.js and pkcs12chain, where are they from, why aren't they installed via npm and are you sure pki.js or asn1js doesn't already provide this? Whenever you pull in external files please add them in separate commit and add into commit description where they came from and why they were added
* formatPEM.js formats a string into PEM format (64 chars per line), comes from https://github.com/PeculiarVentures/PKI.js/blob/f4768689ba4f4ea0a65fda25f9af6eb4d72c3a45/examples/examples_common.js.
pkcs12chain.js wraps boilerplate for generating a PFX instance with a cert chain, comes from https://github.com/PeculiarVentures/PKI.js/issues/104.
> HASH_ALG, RSA_SIGN_ALG, EC_SIGN_ALG, KEY_SIZE should all really go away and they should be pulled from /api/bootstrap instead. Looks like at least hash algorithm is missing, please add it under certificate.authority dict. There's more hardcoded stuff that should really be pulled from /api/bootstrap https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L250
* Fixed
> All the P12 stuff should really happen inside case 'p12':
* Fixed
> Please remove all messy inline conversions and use external function for converting between PEM/DER/whatever (base64 convert, line length limit and also ASCII armor text): https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L135 https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L231 https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L274 https://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L324 etc. Create own functions if you're sure pki.js or asn1js doesn't include what you need
* Fixed
> crypto.generateKey is the only long running function call, I don't see reason to complicate code with sequence here?
* Fixed
-----BEGIN PRIVATE KEY-----
-----END PRIVATE KEY-----
then its working with EC to
Change
```
-----BEGIN RSA PRIVATE KEY-----
-----END RSA PRIVATE KEY-----
```
to
```
-----BEGIN PRIVATE KEY-----
-----END PRIVATE KEY-----
then its working with EC to
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Didn't find replacement for forge.pki.certificateToAsn1() and forge.asn1.toDer().
formatPEM.jsandpkcs12chain, where are they from, why aren't they installed vianpmand are you surepki.jsorasn1jsdoesn't already provide this? Whenever you pull in external files please add them in separate commit and add into commit description where they came from and why they were addedHASH_ALG,RSA_SIGN_ALG,EC_SIGN_ALG,KEY_SIZEshould all really go away and they should be pulled from/api/bootstrapinstead. Looks like at least hash algorithm is missing, please add it undercertificate.authoritydict. There's more hardcoded stuff that should really be pulled from/api/bootstraphttps://git.k-space.ee/pinecrypt/frontend/src/branch/master/static/js/certidude.js#L250case 'p12':pki.jsorasn1jsdoesn't include what you needcrypto.generateKeyis the only long running function call, I don't see reason to complicate code withsequencehere?PKI terminologiy is a mess, to clarify:
----- BEGIN ... -----and----- END ... -----Did you test downloading StrongSwan profile (.sswan)? It should contain sensible JSON and the
local.p12attribute should contain P12 bundle that you should be able to parse withopenssl pkcs12. For more info see https://wiki.strongswan.org/projects/strongswan/wiki/AndroidVPNClientProfilesbe409827f5tobaa6acbf77pkcs12chain.js wraps boilerplate for generating a PFX instance with a cert chain, comes from https://github.com/PeculiarVentures/PKI.js/issues/104.
Change
to