Skip to main content

A library to simplify working with the IB1 Trust Framework directory

Project description

IB1 Directory

A library to simplify working with the IB1 Trust Framework directory

Development

Setup

poetry install

Run tests

poetry run pytest

Package and publish

poetry build
poetry publish

Usage

Encoding and decoding

from ib1.directory.extensions import encode_roles, decode_roles
...

cert_builder = (
    x509.CertificateBuilder()
    .subject_name(subject)
    .issuer_name(issuer)
    .public_key(private_key.public_key())
    .serial_number(x509.random_serial_number())
    .not_valid_before(datetime.utcnow())
    .not_valid_after(datetime.utcnow() + timedelta(days=365))
)

cert_builder = encode_roles(cert_builder, roles)

cert = cert_builder.sign(private_key, hashes.SHA256(), default_backend())

roles = decode_roles(cert)

Require a role

from ib1 import directory
...
    cert = directory.parse_cert(quoted_certificate_from_header)
    try:
        directory.require_role(
            "https://registry.core.ib1.org/scheme/perseus/role/carbon-accounting",
            cert,
        )
    except directory.CertificateRoleError as e:
        raise HTTPException(
            status_code=401,
            detail=str(e),
        )
...

Commands for generating certificates

The included cli can generate CA and issuer key certificate pairs suitable for signing client and server CSR requests in the IB1 Trust Framework.

Generate a CA key and certificate

Usage: ib1-directory create-ca [OPTIONS]

  Generate a server signing CA key and certificate and an issuer key and
  certificate pair signed by the CA then saves all files to disk

Options:
  -u, --usage [signing|client|server]  Choose signing, server or client CA
  -c, --country TEXT           Country to use for certificate generation
  -s, --state TEXT             State to use for certificate generation
  -f, --framework TEXT         Framework this certificate is for
  --help                       Show this message and exit.

eg. to create a server CA key and certificate for the Core Trust Framework:

poetry run ib1-directory create-ca -u server -f Core

Create test client and server certficates

Client:

Usage: ib1-directory create-client-certificates [OPTIONS]

  Create a private key and use it generate a CSR, then sign the CSR with a CA
  key and certificate.

  Saves the private key, CSR, certificate and bundle to disk.

Options:
  --issuer-key-file FILENAME   Issuer key file
  --issuer-cert-file FILENAME  Issuer certificate file
  --member-uri TEXT            Member uri
  --application-uri TEXT       Application uri
  --organization-name TEXT     Organization name
  --country TEXT               Country
  --state TEXT                 State
  -r, --role TEXT              Client roles
  --help                       Show this message and exit.

Server:

Usage: ib1-directory create-server-certificates [OPTIONS]

  Create a private key and use it generate a CSR, then sign the CSR with a CA
  key and certificate.

  Saves the private key, CSR, certificate and bundle to disk.

Options:
  --issuer-key-file FILENAME   Issuer key file
  --issuer-cert-file FILENAME  Issuer certificate file
  --domain TEXT                Domain name
  --trust-framework TEXT       Trust framework
  --country TEXT               Country
  --state TEXT                 State
  --help                       Show this message and exit.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

ib1_directory-0.9.0.tar.gz (8.9 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

ib1_directory-0.9.0-py3-none-any.whl (10.8 kB view details)

Uploaded Python 3

File details

Details for the file ib1_directory-0.9.0.tar.gz.

File metadata

  • Download URL: ib1_directory-0.9.0.tar.gz
  • Upload date:
  • Size: 8.9 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.8.3 CPython/3.12.3 Darwin/24.0.0

File hashes

Hashes for ib1_directory-0.9.0.tar.gz
Algorithm Hash digest
SHA256 87c227fa18426dcc5512ec7fe6cc38c195aef040dbf8cdc20e2be50dc60f9875
MD5 5f69b41d416a8be5dc865c3c5e254634
BLAKE2b-256 84fe242e96128925c2c0bbabd9883555efb9bbe5df5573466afa82cdd029ebac

See more details on using hashes here.

File details

Details for the file ib1_directory-0.9.0-py3-none-any.whl.

File metadata

  • Download URL: ib1_directory-0.9.0-py3-none-any.whl
  • Upload date:
  • Size: 10.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: poetry/1.8.3 CPython/3.12.3 Darwin/24.0.0

File hashes

Hashes for ib1_directory-0.9.0-py3-none-any.whl
Algorithm Hash digest
SHA256 c90d81d45c95a0761fba9a50da586a1b18a4953dea4aba12fa31b44e8b932d68
MD5 c0ed0d76302bd9410b5b4cfdbe725f2a
BLAKE2b-256 6d2ebf902316e89b2ccfda7478c5c945b61f3caa2ef3cbd266941495a9ee7a94

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page