2022-10-20 20:06:50 +03:00
|
|
|
|
<?php
|
|
|
|
|
|
|
|
|
|
namespace Webmasterskaya\CryptoPro;
|
|
|
|
|
|
2022-11-04 16:37:33 +03:00
|
|
|
|
use Webmasterskaya\CryptoPro\Dictionary\IssuerTagsDictionary;
|
2022-11-04 16:56:06 +03:00
|
|
|
|
use Webmasterskaya\CryptoPro\Dictionary\OIDDictionary;
|
2022-11-04 16:37:33 +03:00
|
|
|
|
use Webmasterskaya\CryptoPro\Dictionary\SubjectTagsDictionary;
|
2022-10-24 20:03:09 +03:00
|
|
|
|
use Webmasterskaya\CryptoPro\Helpers\ArrayHelper;
|
|
|
|
|
use Webmasterskaya\CryptoPro\Helpers\CertificateHelper;
|
|
|
|
|
use Webmasterskaya\CryptoPro\Helpers\ErrorMessageHelper;
|
|
|
|
|
|
2022-10-20 20:06:50 +03:00
|
|
|
|
class Certificate
|
|
|
|
|
{
|
2022-10-21 17:17:51 +03:00
|
|
|
|
|
|
|
|
|
public $_cadesCertificate;
|
|
|
|
|
public $name;
|
|
|
|
|
public $issuerName;
|
|
|
|
|
public $subjectName;
|
|
|
|
|
public $thumbprint;
|
|
|
|
|
public $validFrom;
|
|
|
|
|
public $validTo;
|
|
|
|
|
|
|
|
|
|
public function __construct(
|
|
|
|
|
\CPCertificate $cadesCertificate,
|
|
|
|
|
string $name,
|
|
|
|
|
string $issuerName,
|
|
|
|
|
string $subjectName,
|
|
|
|
|
string $thumbprint,
|
|
|
|
|
string $validFrom,
|
|
|
|
|
string $validTo
|
|
|
|
|
)
|
|
|
|
|
{
|
|
|
|
|
$this->_cadesCertificate = $cadesCertificate;
|
|
|
|
|
$this->name = $name;
|
|
|
|
|
$this->issuerName = $issuerName;
|
|
|
|
|
$this->subjectName = $subjectName;
|
|
|
|
|
$this->thumbprint = $thumbprint;
|
|
|
|
|
$this->validFrom = $validFrom;
|
|
|
|
|
$this->validTo = $validTo;
|
|
|
|
|
}
|
|
|
|
|
|
2022-10-20 20:06:50 +03:00
|
|
|
|
/**
|
|
|
|
|
* возвращает флаг действительности сертификата
|
|
|
|
|
*
|
2022-10-24 20:03:09 +03:00
|
|
|
|
* @throws \Exception
|
|
|
|
|
* @return bool
|
2022-10-20 20:06:50 +03:00
|
|
|
|
*/
|
|
|
|
|
public function isValid()
|
|
|
|
|
{
|
2022-10-24 20:03:09 +03:00
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
$isValid = $this->_cadesCertificate->IsValid();
|
|
|
|
|
$isValid = (bool) $isValid->get_Result();
|
|
|
|
|
}
|
|
|
|
|
catch (\Throwable $e)
|
|
|
|
|
{
|
|
|
|
|
throw new \Exception(ErrorMessageHelper::getErrorMessage($e, 'Ошибка при проверке сертификата'));
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return $isValid;
|
2022-10-20 20:06:50 +03:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* возвращает указанное внутренее свойство у сертификата в формате Cades
|
|
|
|
|
*
|
2022-10-24 20:03:09 +03:00
|
|
|
|
* @param string $propName наименование свойства
|
|
|
|
|
*
|
|
|
|
|
* @throws \Exception
|
|
|
|
|
* @return mixed
|
2022-10-20 20:06:50 +03:00
|
|
|
|
*/
|
2022-10-24 20:03:09 +03:00
|
|
|
|
public function getCadesProp(string $propName)
|
2022-10-20 20:06:50 +03:00
|
|
|
|
{
|
2022-10-24 20:03:09 +03:00
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
if (method_exists($this->_cadesCertificate, 'get_' . $propName))
|
|
|
|
|
{
|
|
|
|
|
$propertyValue = call_user_func([$this->_cadesCertificate, 'get_' . $propName]);
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
throw new \Exception();
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
catch (\Throwable $e)
|
|
|
|
|
{
|
|
|
|
|
throw new \Exception(ErrorMessageHelper::getErrorMessage($e, 'Ошибка при обращении к свойству сертификата'));
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return $propertyValue;
|
2022-10-20 20:06:50 +03:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* возвращает сертификат в формате base64
|
|
|
|
|
*
|
|
|
|
|
* @return void
|
|
|
|
|
*/
|
|
|
|
|
public function exportBase64()
|
|
|
|
|
{
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* возвращает информацию об алгоритме сертификата
|
|
|
|
|
*
|
2022-10-24 20:03:09 +03:00
|
|
|
|
* @throws \Exception
|
|
|
|
|
* @return AlgorithmInfoInterface
|
2022-10-20 20:06:50 +03:00
|
|
|
|
*/
|
|
|
|
|
public function getAlgorithm()
|
|
|
|
|
{
|
2022-10-24 20:03:09 +03:00
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
$cadesPublicKey = $this->_cadesCertificate->PublicKey();
|
|
|
|
|
$cadesPublicKeyAlgorithm = $cadesPublicKey->get_Algorithm();
|
|
|
|
|
$algorithmInfo = new class(
|
|
|
|
|
$cadesPublicKeyAlgorithm->get_FriendlyName(),
|
|
|
|
|
$cadesPublicKeyAlgorithm->get_Value()) extends AbstractAlgorithmInfo {
|
|
|
|
|
};
|
|
|
|
|
}
|
|
|
|
|
catch (\Throwable $e)
|
|
|
|
|
{
|
|
|
|
|
throw new \Exception(ErrorMessageHelper::getErrorMessage($e, 'Ошибка при получении алгоритма'));
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return $algorithmInfo;
|
2022-10-20 20:06:50 +03:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* возвращает расшифрованную информацию о владельце сертификата
|
|
|
|
|
*
|
2022-10-24 20:03:09 +03:00
|
|
|
|
* @throws \Exception
|
|
|
|
|
* @return array|array[]
|
2022-10-20 20:06:50 +03:00
|
|
|
|
*/
|
|
|
|
|
public function getOwnerInfo()
|
|
|
|
|
{
|
2022-11-04 16:37:33 +03:00
|
|
|
|
return $this->getInfo(SubjectTagsDictionary::class, 'SubjectName');
|
2022-10-24 20:03:09 +03:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
2022-11-04 16:37:33 +03:00
|
|
|
|
* @param string $dictionary
|
2022-10-24 20:03:09 +03:00
|
|
|
|
* @param string $entitiesPath
|
|
|
|
|
*
|
|
|
|
|
* @throws \Exception
|
|
|
|
|
* @return array|array[]
|
|
|
|
|
*/
|
2022-11-04 16:37:33 +03:00
|
|
|
|
protected function getInfo(string $dictionary, string $entitiesPath)
|
2022-10-24 20:03:09 +03:00
|
|
|
|
{
|
2022-11-04 16:37:33 +03:00
|
|
|
|
try
|
2022-10-24 20:03:09 +03:00
|
|
|
|
{
|
2022-11-04 16:37:33 +03:00
|
|
|
|
$entities = $this->getCadesProp($entitiesPath);
|
2022-10-24 20:03:09 +03:00
|
|
|
|
}
|
2022-11-04 16:37:33 +03:00
|
|
|
|
catch (\Throwable $e)
|
2022-10-24 20:03:09 +03:00
|
|
|
|
{
|
2022-11-04 16:37:33 +03:00
|
|
|
|
throw new \Exception(ErrorMessageHelper::getErrorMessage($e, 'Ошибка при извлечении информации из сертификата'));
|
2022-10-24 20:03:09 +03:00
|
|
|
|
}
|
|
|
|
|
|
2022-11-04 16:37:33 +03:00
|
|
|
|
return CertificateHelper::parseCertInfo($dictionary, $entities);
|
2022-10-20 20:06:50 +03:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* возвращает расшифрованную информацию об издателе сертификата
|
|
|
|
|
*
|
2022-10-24 20:03:09 +03:00
|
|
|
|
* @throws \Exception
|
|
|
|
|
* @return array|array[]
|
2022-10-20 20:06:50 +03:00
|
|
|
|
*/
|
|
|
|
|
public function getIssuerInfo()
|
|
|
|
|
{
|
2022-11-04 16:37:33 +03:00
|
|
|
|
return $this->getInfo(IssuerTagsDictionary::class, 'IssuerName');
|
2022-10-20 20:06:50 +03:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* возвращает ОИД'ы сертификата
|
|
|
|
|
*
|
2022-11-03 17:59:07 +03:00
|
|
|
|
* @throws \Exception
|
2022-10-24 20:03:09 +03:00
|
|
|
|
* @return array
|
2022-10-20 20:06:50 +03:00
|
|
|
|
*/
|
|
|
|
|
public function getExtendedKeyUsage()
|
|
|
|
|
{
|
2022-10-24 20:03:09 +03:00
|
|
|
|
$OIDs = [];
|
|
|
|
|
|
|
|
|
|
try
|
|
|
|
|
{
|
|
|
|
|
$cadesExtendedKeysUsage = $this->_cadesCertificate->ExtendedKeyUsage();
|
|
|
|
|
$cadesExtendedKeysUsage = $cadesExtendedKeysUsage->get_EKUs();
|
|
|
|
|
$cadesExtendedKeysUsageCount = $cadesExtendedKeysUsage->get_Count();
|
|
|
|
|
|
|
|
|
|
if ($cadesExtendedKeysUsageCount > 0)
|
|
|
|
|
{
|
|
|
|
|
while ($cadesExtendedKeysUsageCount)
|
|
|
|
|
{
|
|
|
|
|
$cadesExtendedKeyUsage = $cadesExtendedKeysUsage->get_Item($cadesExtendedKeysUsageCount);
|
2022-11-04 16:56:06 +03:00
|
|
|
|
$OIDs[] = trim($cadesExtendedKeyUsage->get_OID());
|
2022-10-24 20:03:09 +03:00
|
|
|
|
|
|
|
|
|
$cadesExtendedKeysUsageCount--;
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
catch (\Throwable $e)
|
|
|
|
|
{
|
|
|
|
|
throw new \Exception(ErrorMessageHelper::getErrorMessage($e, "Ошибка при получении ОИД'ов"));
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return $OIDs;
|
2022-10-20 20:06:50 +03:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* возвращает расшифрованные ОИД'ы
|
|
|
|
|
*
|
2022-11-03 17:59:07 +03:00
|
|
|
|
* @throws \Exception
|
2022-10-24 20:03:09 +03:00
|
|
|
|
* @return array
|
2022-10-20 20:06:50 +03:00
|
|
|
|
*/
|
|
|
|
|
public function getDecodedExtendedKeyUsage()
|
|
|
|
|
{
|
2022-10-24 20:03:09 +03:00
|
|
|
|
$certOIDs = $this->getExtendedKeyUsage();
|
|
|
|
|
|
|
|
|
|
$decodedOIDs = [];
|
|
|
|
|
|
|
|
|
|
foreach ($certOIDs as $OID)
|
|
|
|
|
{
|
2022-11-04 16:56:06 +03:00
|
|
|
|
$dictionaryItem = OIDDictionary::getByOID($OID);
|
|
|
|
|
$decodedOIDs[$OID] = $dictionaryItem ? $dictionaryItem->title ?? null : null;
|
2022-10-24 20:03:09 +03:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return $decodedOIDs;
|
2022-10-20 20:06:50 +03:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/**
|
|
|
|
|
* проверяет наличие ОИД'а (ОИД'ов) у сертификата
|
|
|
|
|
*
|
2022-10-24 20:03:09 +03:00
|
|
|
|
* @param string|array $OIDs
|
|
|
|
|
*
|
|
|
|
|
* @throws \Exception
|
|
|
|
|
* @return bool
|
2022-10-20 20:06:50 +03:00
|
|
|
|
*/
|
2022-10-24 20:03:09 +03:00
|
|
|
|
public function hasExtendedKeyUsage($OIDs)
|
2022-10-20 20:06:50 +03:00
|
|
|
|
{
|
2022-10-24 20:03:09 +03:00
|
|
|
|
$certOIDs = $this->getExtendedKeyUsage();
|
|
|
|
|
|
|
|
|
|
if (is_string($OIDs))
|
|
|
|
|
{
|
|
|
|
|
$OIDs = [$OIDs];
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
if (!is_array($OIDs))
|
|
|
|
|
{
|
|
|
|
|
$OIDs = (array) $OIDs;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
return ArrayHelper::every($OIDs, function ($oidToCheck) use ($certOIDs) {
|
|
|
|
|
return in_array($oidToCheck, $certOIDs);
|
|
|
|
|
});
|
2022-10-20 20:06:50 +03:00
|
|
|
|
}
|
|
|
|
|
}
|