/*
- Copyright (C) 2013-2015 Carl Hetherington <cth@carlh.net>
+ Copyright (C) 2013-2016 Carl Hetherington <cth@carlh.net>
This program is free software; you can redistribute it and/or modify
it under the terms of the GNU General Public License as published by
#include <libxml++/nodes/element.h>
#include <libxml/parser.h>
#include <boost/date_time/posix_time/posix_time.hpp>
+#include <boost/foreach.hpp>
using std::list;
+using std::vector;
using std::string;
using std::map;
using std::pair;
using boost::shared_ptr;
+using boost::optional;
using namespace dcp;
namespace dcp {
for (list<string>::const_iterator i = encrypted_key.begin(); i != encrypted_key.end(); ++i) {
xmlpp::Element* encrypted_key = node->add_child ("EncryptedKey", "enc");
+ /* XXX: hack for testing with Dolby */
+ encrypted_key->set_namespace_declaration ("http://www.w3.org/2001/04/xmlenc#", "enc");
xmlpp::Element* encryption_method = encrypted_key->add_child ("EncryptionMethod", "enc");
encryption_method->set_attribute ("Algorithm", "http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p");
xmlpp::Element* digest_method = encryption_method->add_child ("DigestMethod", "ds");
+ /* XXX: hack for testing with Dolby */
+ digest_method->set_namespace_declaration ("http://www.w3.org/2000/09/xmldsig#", "ds");
digest_method->set_attribute ("Algorithm", "http://www.w3.org/2000/09/xmldsig#sha1");
xmlpp::Element* cipher_data = encrypted_key->add_child ("CipherData", "enc");
cipher_data->add_child("CipherValue", "enc")->add_child_text (*i);
TypedKeyId (shared_ptr<const cxml::Node> node)
: key_type (node->string_child ("KeyType"))
- , key_id (node->string_child ("KeyId").substr (9))
+ , key_id (remove_urn_uuid (node->string_child ("KeyId")))
{
}
void as_xml (xmlpp::Element* node) const
{
- node->add_child("KeyType")->add_child_text (key_type);
+ xmlpp::Element* type = node->add_child("KeyType");
+ type->add_child_text (key_type);
node->add_child("KeyId")->add_child_text ("urn:uuid:" + key_id);
+ /* XXX: this feels like a bit of a hack */
+ if (key_type == "MDEK") {
+ type->set_attribute ("scope", "http://www.dolby.com/cp850/2012/KDM#kdm-key-type");
+ }
}
string key_type;
AuthorizedDeviceInfo () {}
AuthorizedDeviceInfo (shared_ptr<const cxml::Node> node)
- : device_list_identifier (node->string_child ("DeviceListIdentifier").substr (9))
+ : device_list_identifier (remove_urn_uuid (node->string_child ("DeviceListIdentifier")))
, device_list_description (node->optional_string_child ("DeviceListDescription"))
- , certificate_thumbprint (node->node_child("DeviceList")->string_child ("CertificateThumbprint"))
{
-
+ BOOST_FOREACH (cxml::ConstNodePtr i, node->node_child("DeviceList")->node_children("CertificateThumbprint")) {
+ certificate_thumbprints.push_back (i->content ());
+ }
}
void as_xml (xmlpp::Element* node) const
node->add_child ("DeviceListDescription")->add_child_text (device_list_description.get());
}
xmlpp::Element* device_list = node->add_child ("DeviceList");
- device_list->add_child("CertificateThumbprint")->add_child_text (certificate_thumbprint);
+ BOOST_FOREACH (string i, certificate_thumbprints) {
+ device_list->add_child("CertificateThumbprint")->add_child_text (i);
+ }
}
/** DeviceListIdentifier without the urn:uuid: prefix */
string device_list_identifier;
boost::optional<string> device_list_description;
- string certificate_thumbprint;
+ std::list<string> certificate_thumbprints;
};
class X509IssuerSerial
KDMRequiredExtensions (shared_ptr<const cxml::Node> node)
: recipient (node->node_child ("Recipient"))
- , composition_playlist_id (node->string_child ("CompositionPlaylistId").substr (9))
+ , composition_playlist_id (remove_urn_uuid (node->string_child ("CompositionPlaylistId")))
, content_title_text (node->string_child ("ContentTitleText"))
, not_valid_before (node->string_child ("ContentKeysNotValidBefore"))
, not_valid_after (node->string_child ("ContentKeysNotValidAfter"))
public:
AuthenticatedPublic ()
: message_id (make_uuid ())
+ /* XXX: hack for Dolby to see if there must be a not-empty annotation text */
+ , annotation_text ("none")
, issue_date (LocalTime().as_string ())
{}
AuthenticatedPublic (shared_ptr<const cxml::Node> node)
- : message_id (node->string_child ("MessageId").substr (9))
- , annotation_text (node->string_child ("AnnotationText"))
+ : message_id (remove_urn_uuid (node->string_child ("MessageId")))
+ , annotation_text (node->optional_string_child ("AnnotationText"))
, issue_date (node->string_child ("IssueDate"))
, signer (node->node_child ("Signer"))
, required_extensions (node->node_child ("RequiredExtensions"))
node->add_child("MessageId")->add_child_text ("urn:uuid:" + message_id);
node->add_child("MessageType")->add_child_text ("http://www.smpte-ra.org/430-1/2006/KDM#kdm-key-type");
- node->add_child("AnnotationText")->add_child_text (annotation_text);
+ if (annotation_text) {
+ node->add_child("AnnotationText")->add_child_text (annotation_text.get ());
+ }
node->add_child("IssueDate")->add_child_text (issue_date);
signer.as_xml (node->add_child ("Signer"));
}
string message_id;
- string annotation_text;
+ optional<string> annotation_text;
string issue_date;
Signer signer;
RequiredExtensions required_extensions;
EncryptedKDM::EncryptedKDM (
shared_ptr<const CertificateChain> signer,
Certificate recipient,
+ vector<Certificate> trusted_devices,
string device_list_description,
string cpl_id,
string content_title_text,
if (formulation == MODIFIED_TRANSITIONAL_1 || formulation == DCI_ANY) {
/* Use the "assume trust" thumbprint */
- kre.authorized_device_info.certificate_thumbprint = "2jmj7l5rSw0yVb/vlWAYkK/YBwk=";
+ kre.authorized_device_info.certificate_thumbprints.push_back ("2jmj7l5rSw0yVb/vlWAYkK/YBwk=");
} else if (formulation == DCI_SPECIFIC) {
- /* Use the recipient thumbprint */
- kre.authorized_device_info.certificate_thumbprint = recipient.thumbprint ();
+ /* As I read the standard we should use the recipient
+ /and/ other trusted device thumbprints here. MJD
+ reports that this doesn't work with his setup;
+ a working KDM does not include the recipient's
+ thumbprint (recipient.thumbprint()).
+ */
+ BOOST_FOREACH (Certificate const & i, trusted_devices) {
+ kre.authorized_device_info.certificate_thumbprints.push_back (i.thumbprint ());
+ }
}
for (list<pair<string, string> >::const_iterator i = key_ids.begin(); i != key_ids.end(); ++i) {
string
EncryptedKDM::as_xml () const
{
- xmlpp::Document document;
- xmlpp::Element* root = document.create_root_node ("DCinemaSecurityMessage", "http://www.smpte-ra.org/schemas/430-3/2006/ETM");
- root->set_namespace_declaration ("http://www.w3.org/2000/09/xmldsig#", "ds");
- root->set_namespace_declaration ("http://www.w3.org/2001/04/xmlenc#", "enc");
-
return _data->as_xml()->write_to_string ("UTF-8");
}
return _data->authenticated_private.encrypted_key;
}
-string
+optional<string>
EncryptedKDM::annotation_text () const
{
return _data->authenticated_public.annotation_text;
return _data->authenticated_public.required_extensions.kdm_required_extensions.content_title_text;
}
+string
+EncryptedKDM::cpl_id () const
+{
+ return _data->authenticated_public.required_extensions.kdm_required_extensions.composition_playlist_id;
+}
+
string
EncryptedKDM::issue_date () const
{