ECDSA registry signatures aren't reproducible
まだ誰も着手していません。
評価
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 初心者へのやさしさ
- 45/100
- issue の種類
- ドキュメント
- 明瞭さ
- おおむね明確
- 活発さ
- 停滞
- 技術スタック
- go
調査の方向性
まず registry signatures guide と、リンクされている registry version および key endpoints を確認し、提供されている Go verification example と比較します。再現可能な ECDSA verification に必要な hashing と encoding の詳細を文書化し、動作する例をドキュメントに追加します。
索引モデルが issue の本文から書いたものです。
説明
I'm following the guide at https://docs.npmjs.com/about-registry-signatures, and I'm struggling to verify the ECDSA signatures that get published to the NPM registry.
Some example code, that shows things like which hashing algorithm is used for the contents of bundles (I'm just assuming that it's sha256 currently), and whether the keys are base64 encoded using the standard algorithm or the alternate under RFC 4648, would be immensely helpful.
I've written what I have so far below, and would appreciate some help getting it to work. Feel free to add it to your documentation once it does!
package main
import (
"bytes"
"crypto/ecdsa"
"crypto/sha256"
"crypto/x509"
"encoding/base64"
"fmt"
"io"
"net/http"
)
func downloadPackage(compressedPackage *bytes.Buffer) error {
resp, err := http.Get("https://registry.npmjs.org/light-cycle/-/light-cycle-1.4.3.tgz")
if err != nil {
return fmt.Errorf("package download failed: %v", err)
}
defer resp.Body.Close()
if resp.StatusCode != http.StatusOK {
return fmt.Errorf("pacakge download bad status code: %s", resp.Status)
}
_, err = io.Copy(compressedPackage, resp.Body)
if err != nil {
return fmt.Errorf("failed to read package to buffer: %v", err)
}
return nil
}
func verifyPackage(compressedPackage *bytes.Buffer) error {
// From https://registry.npmjs.org/light-cycle/1.4.3.
versionSignature := "MEUCIQCX/49atNeSDYZP8betYWEqB0G8zZnIyB7ibC7nRNyMiQIgHosOKHhVTVNBI/6iUNSpDokOc44zsZ7TfybMKj8YdfY="
// From https://registry.npmjs.org/-/npm/v1/keys.
publicKey := "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE1Olb3zMAFFxXKHiIkQO5cJ3Yhl5i6UPp+IhuteBJbuHcA5UogKo0EWtlWwW6KSaKoTNEYL7JlCQiVnkhBktUgg=="
// Decode and parse the public key.
publicKeyBytes, err := base64.StdEncoding.DecodeString(publicKey)
fmt.Printf("PUBLIC KEY BASE 64 BYTES: %x\n", publicKeyBytes)
if err != nil {
return fmt.Errorf("error decoding public key bytes: %v", err)
}
parsedPublicKeyUntyped, err := x509.ParsePKIXPublicKey(publicKeyBytes)
parsedPublicKey := parsedPublicKeyUntyped.(*ecdsa.PublicKey)
fmt.Printf("PARSED PUBLIC KEY X: %v, Y: %v\n", parsedPublicKey.X, parsedPublicKey.Y)
if err != nil {
return fmt.Errorf("error parsing public key: %v", err)
}
// Decode the signature.
versionSignatureBytes, err := base64.StdEncoding.DecodeString(versionSignature)
fmt.Printf("SIGNATURE BYTES: %x\n", versionSignatureBytes)
if err != nil {
return fmt.Errorf("error decoding signature bytes: %v", err)
}
// Verify the signature against the package's SHA256 sum.
// presentSHA256Bytes := md5.Sum(compressedPackage.Bytes())
presentSHA256Bytes := sha256.Sum256(compressedPackage.Bytes())
fmt.Printf("PRESENT SHA256: %x\n", presentSHA256Bytes)
if !ecdsa.VerifyASN1(parsedPublicKey, presentSHA256Bytes[:], versionSignatureBytes) {
return fmt.Errorf("signature verification failed")
}
return nil
}
func main() {
var compressedPackage bytes.Buffer
if err := downloadPackage(&compressedPackage); err != nil {
fmt.Printf("failed to download package: %v", err)
}
if err := verifyPackage(&compressedPackage); err != nil {
fmt.Printf("failed to verify package: %v", err)
}
}
Currently this outputs:
PUBLIC KEY BASE 64 BYTES: 3059301306072a8648ce3d020106082a8648ce3d03010703420004d4e95bdf3300145c572878889103b9709dd8865e62e943e9f8886eb5e0496ee1dc03952880aa34116b655b05ba29268aa1334460bec9942422567921064b5482
PARSED PUBLIC KEY X: 96302633342102462193322732537154456057293035750541189099858346903022946840289, Y: 99515156681666470022533827122417036293197994443229625834881400620927226172546
SIGNATURE BYTES: 304502210097ff8f5ab4d7920d864ff1b7ad61612a0741bccd99c8c81ee26c2ee744dc8c8902201e8b0e2878554d534123fea250d4a90e890e738e33b19ed37f26cc2a3f1875f6
PRESENT SHA256: a1b59bcdca7b8a6844c48fee7031842fcecec26fb028e4b5cbcb8c055ca0eeaa
failed to verify package: signature verification failed
Thank you for any help!
- 主要言語
- MDX
- スター
- 715
- フォーク
- 4.2k
- 平均マージ
- 6日 10時間
- マージ済み PR(30日)
- 3
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
npm/documentation のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
npm/documentation#1998 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
npm/documentation#1997 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
npm/documentation#1960 · リアクション 1 件 ·
-
Mobile header icons are hard to see再び着手できるかも このイシューのプルリクエストはマージされずにクローズされました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
npm/documentation#1948 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
npm/documentation#1929 ·
npm/documentation の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
indygreg/cryptography-rs#99 ·
-
sha2 0.11.0 aarch64 backends load 16 bytes through a one-element reference (`vld1q_u32(&K32[t])`)オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
RustCrypto/hashes#920 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 78/100
メンテナーはふだん 2 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 74/100
bitcoindevkit/bdk-tx#90 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
google/go-sev-guest#206 ·