Skip to main content

Certomancer-based dummy CSC server implementation

Overview

This package contains a minimal implementation of the Cloud Signature Consortium (CSC) API for remote signing. It's intended for use in integration tests and demonstrations. Most of the heavy lifting is actually done by Certomancer. This package merely wraps calls to Certomancer in an aiohttp-based web interface that exposes (a subset of) the CSC API.

This is a testing tool, and it omits all sorts of essential security features:

  • Requests are not authenticated
  • No SAD replay prevention of any sort, other than the standard hash pinning supported by the CSC protocol
  • All keys in the Certomancer config can be used to sign hashes in CSC calls

It goes without saying that you should never use this implementation, or any derivative thereof, with production keys.

Missing features

Besides most authentication-related endpoints, the credentials/extendTransaction endpoint is currently also unavailable. Support for this endpoint may be implemented in the future.

The other obvious missing feature is "anything resembling a decent user interface". This code was essentially isolated from pyHanko's integration tests in the hope that it might be useful for others to play around with, and the primitive CLI reflects that.

Invocation

The package is on PyPI and can be installed via pip:

pip install certomancer-csc-dummy

This is the command syntax. All parameters are required.

certomancer-csc CERTOMANCER_CONFIG PORT SCAL

The meaning of the parameters is as follows:

  • CERTOMANCER_CONFIG is the path to your Certomancer config file, usually called certomancer.yml
  • PORT is the port on which you want the dummy server to listen
  • SCAL indicates whether SAD data is required to be bound to hashes (1=no, 2=yes) — see the CSC specification for details.

The credentials exposed in the CSC API are in one-to-one correspondence with certificates in Certomancer (assuming Certomancer has access to all the private keys). The naming convention for credentials is <arch>/<cert-label>, where <arch> is the name of the Certomancer PKI architecture you're trying to access, and <cert-label> is the label of the certificate that will be treated as the signer's certificate. Example: testing-ca/signer1 would access the certificate signer1 in the architecture labelled testing-ca. Signatures will be produced by the corresponding private key.

Again, note that all credentials are always available without any form of authentication, although the caller is still required to go through the motions of requesting a SAD token before any signatures will be returned.

Note: The CSC dummy server currently does not launch Certomancer Animator or otherwise expose access to trust services managed by Certomancer. For now, you need to launch Certomancer Animator in a separate process if you need those.

(The reason is that Certomancer doesn't (yet) natively integrate with aiohttp, it currently only does WSGI. That may change in the future.)

Example usage

See here:

License

MIT license.

Metadata

Release files for certomancer-csc-dummy 0.4.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for certomancer-csc-dummy 0.4.2
File Size Uploaded
certomancer_csc_dummy-0.4.2.tar.gz 10.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for certomancer-csc-dummy 0.4.2
File Interpreter ABI Platform
certomancer_csc_dummy-0.4.2-py3-none-any.whl Python 3 none any Details

Total release size: 22.1 kB

Release files / certomancer_csc_dummy-0.4.2.tar.gz

Download URL certomancer_csc_dummy-0.4.2.tar.gz
Size 10.6 kB
Tags Source
SHA-256 checksum
How to use checksums
3f816c1907fa21bd5124687b7fb0b91ed839eadbdf84b928a832ce9f48376a0b
BLAKE2b-256 checksum
How to use checksums
5b4e7ca81f14b6940ac00827ff379d82b50d5a6f0f37660db91b9fed8f67ac5f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.10.4

Release files / certomancer_csc_dummy-0.4.2-py3-none-any.whl

Download URL certomancer_csc_dummy-0.4.2-py3-none-any.whl
Size 11.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
59aadb99f59e91c726b051a4f7e5e31aafa7afd08356c90b16df7abec0feefc9
BLAKE2b-256 checksum
How to use checksums
7f9aa01281a42dc391dd6183f2b57a284aaead5de0460c787688b354b7c98205
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.10.4

Release history Release notifications | RSS feed

This release

0.4.2 This release

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page