nhpip

nhpip

Decoding an X.509 certificate

Hi,

I’ve got a project where I have to decode an X.509 certificate. I’m using Erlang’s public_key module to decode either a PEM or DER file. I get back a beautiful Erlang record. I know I can use Record for this purpose, but that seems overkill. I want to avoid adding yet another library.

Anyone got any recommendations for nicely extracting items out of a nested tuple in Elixir?

Thanks

Marked As Solved

nhpip

nhpip

Thanks. I ended up using the X509 library. Took 5 lines of code.

Also Liked

voltone

voltone

Recent OTP versions support generating code from ASN.1 that produces and accepts maps:

iex(1)> path = ~c"path/to/source/of/otp/lib/public_key/asn1/OTP-PUB-KEY.set.asn"
iex(2)> :asn1ct.compile(path, [:maps])
iex(3)> :code.load_abs(~c"OTP-PUB-KEY")
iex(4)> {:ok, cert} = :"OTP-PUB-KEY".decode(:"Certificate", der)
{:ok,
 %{
   signature: <<133, 191, 235, 15, 159, 223, 81, 127, 179, 46, 167, 62, 52, 82,
     250, 40, 4, 169, 130, 49, 63, 172, 36, 83, 164, 138, 162, 50, 233, 76, 254,
     50, 216, 144, 27, 209, 244, 68, 99, 74, 40, 207, 201, 3, 50, 87, 71, ...>>,
   tbsCertificate: %{
     version: :v3,
     signature: %{
       algorithm: {1, 2, 840, 113549, 1, 1, 11},
       parameters: <<5, 0>>
     },
     extensions: [
       %{
         critical: true,
         extnID: {2, 5, 29, 19},
         extnValue: <<48, 6, 1, 1, 255, 2, 1, 1>>
       },
       %{critical: true, extnID: {2, 5, 29, 15}, extnValue: <<3, 2, 1, 134>>},
       %{
         critical: false,
         extnID: {2, 5, 29, 14},
         extnValue: <<4, 20, 103, 184, 255, 213, 187, 5, 43, 104, 112, 7, 148,
           46, 97, 212, 57, 234, 235, 127, 203, 121>>
       },
       %{
         critical: false,
         extnID: {2, 5, 29, 35},
         extnValue: <<48, 22, 128, 20, 103, 184, 255, 213, 187, 5, 43, 104, 112,
           7, 148, 46, 97, 212, 57, 234, 235, 127, 203, 121>>
       }
     ],
     serialNumber: 4655353446208655840,
     issuer: {:rdnSequence,
      [
        [%{type: {2, 5, 4, 6}, value: <<19, 2, 85, 83>>}],
        [%{type: {2, 5, 4, 8}, value: <<12, 2, 78, 84>>}],
        [%{type: {2, 5, 4, 7}, value: "\f\vSpringfield"}],
        [%{type: {2, 5, 4, 10}, value: "\f\tACME Inc."}]
      ]},
     validity: %{
       notBefore: {:utcTime, ~c"220525065848Z"},
       notAfter: {:utcTime, ~c"470525070348Z"}
     },
     subject: {:rdnSequence,
      [
        [%{type: {2, 5, 4, 6}, value: <<19, 2, 85, 83>>}],
        [%{type: {2, 5, 4, 8}, value: <<12, 2, 78, 84>>}],
        [%{type: {2, 5, 4, 7}, value: "\f\vSpringfield"}],
        [%{type: {2, 5, 4, 10}, value: "\f\tACME Inc."}]
      ]},
     subjectPublicKeyInfo: %{
       algorithm: %{
         algorithm: {1, 2, 840, 113549, 1, 1, 1},
         parameters: <<5, 0>>
       },
       subjectPublicKey: <<48, 130, 1, 10, 2, 130, 1, 1, 0, 180, 114, 112, 36,
         255, 225, 242, 197, 38, 146, 113, 132, 20, 169, 223, 175, 93, 149, 110,
         209, 12, 217, 199, 112, 222, 188, 84, ...>>
     }
   },
   signatureAlgorithm: %{
     algorithm: {1, 2, 840, 113549, 1, 1, 11},
     parameters: <<5, 0>>
   }
 }}
iex(5)> cert.tbsCertificate.validity.notAfter
{:utcTime, ~c"470525070348Z"}
D4no0

D4no0

Pattern matching, using elem/2, are you looking for anything in particular?

I would recommend to use x509 library though, it’s really neat library written by @voltone. When you start decoding things by hand, that code is really hard to comprehend afterwards, better use a well tested library instead IMO.

voltone

voltone

You could use get_in/2 and Access.elem/1, e.g.

iex(1)> tbs = 1
iex(2)> validity = 5
iex(3)> not_after = 2
iex(4)> get_in(cert, [Access.elem(tbs), Access.elem(validity), Access.elem(not_after)])
{:utcTime, ~c"470525070659Z"}

But I also like @D4no0 's suggestion :slight_smile:

Where Next?

Popular in Questions Top

Patoshizzle
After calling mix ecto.create I get this error: 17:00:32.162 [error] GenServer #PID&lt;0.412.0&gt; terminating ** (Postgrex.Error) FATAL...
New
mgjohns61585
Could someone help me? I’m making my first elixir program, number guessing game. I can’t figure out how to convert the user’s guess from ...
New
shahryarjb
Hello, I get Persian date from my client and convert it to normal calendar like this: def jalali_string_to_miladi_english_number(persi...
New
JulienCorb
I am trying to implement my new.html.eex file to create new posts on my website. new.html.eex: &lt;h1&gt;Create Post&lt;/h1&gt; &lt;%= ...
New
joeerl
Hello again - after a longish gap I’ve decided I really must dig into Elixir and see what’s been happening here - so I have a few questio...
New
Emily
I have VueJS GUIs with the project generated using Webpack. I have Elixir modules that will need to be used by the VueJS GUIs. I forese...
New
aalberti333
As the title describes, I’m trying to run Enum.map() over a list of key/value pairs, where the value is a map. My data looks like this: ...
New
lucidguppy
I have a super simple question about elixir - how would I take a file like this foo bar baz and output a new file that enumerates th...
New
WestKeys
Currently suffering from paralysis by [HTTP client] analysis. This is rather unusual in Elixirland as there tends to be consensus on the ...
New
openscript
Hello! Sorry for this astonishing simple question, but I’m really stuck. I try to set up the intellij-elixir plugin, but I don’t know ho...
New

Other popular topics Top

Darmani72
If I have a post route which an argument: post /my_post_route/:my_param1, MyController.my_post_handler How would get the post params ...
New
Harrisonl
We have an ECS cluster with 4 services, where each task joins a single cluster, via discovery ECS discovery service. Currently when I de...
New
minhajuddin
I have seen a lot of code which picks the first element from a list using Enum.at(0) instead of List.first. Is there a reason why people ...
New
msaraiva
Surface is an experimental library built on top of Phoenix LiveView and its new LiveComponent API that aims to provide a more declarative...
564 43622 214
New
Lily
In templates/appointment/index.html.eex: &lt;%= for appointment &lt;- @appointments do %&gt; &lt;tr&gt; &lt;td&gt;&lt;%= appoi...
New
SoCreat
i’m a new one to elixir which editor can i use vs code? or atom? Thanks! :smiley:
New
grych
Hi folks, Few months ago I have announced the proof-of-concept of the library to manipulate the browsers DOM objects directly from Elixi...
639 52341 488
New
PeterCarter
There are pre-rolled solutions for other frameworks that do work. However, Phoenix does not seem to have these. Have people had good expe...
New
AstonJ
Seen any cool LiveView demos, sample apps or examples? Please post them here! :003:
New
svb
Hi! Currently I want to submit a form by pressing the Enter key. However, since my input field is of type “textarea” this is just adds a...
New

We're in Beta

About us Mission Statement