A library to simplify working with the IB1 Trust Framework directory
Project description
IB1 Directory
A library to simplify working with the IB1 Trust Framework directory
Development
Setup
poetry install
Run tests
poetry run pytest
Package and publish
poetry build
poetry publish
Usage
Encoding and decoding
from ib1.directory.extensions import encode_roles, decode_roles
...
cert_builder = (
x509.CertificateBuilder()
.subject_name(subject)
.issuer_name(issuer)
.public_key(private_key.public_key())
.serial_number(x509.random_serial_number())
.not_valid_before(datetime.utcnow())
.not_valid_after(datetime.utcnow() + timedelta(days=365))
)
cert_builder = encode_roles(cert_builder, roles)
cert = cert_builder.sign(private_key, hashes.SHA256(), default_backend())
roles = decode_roles(cert)
Require a role
from ib1 import directory
...
cert = directory.parse_cert(quoted_certificate_from_header)
try:
directory.require_role(
"https://registry.core.ib1.org/scheme/perseus/role/carbon-accounting",
cert,
)
except directory.CertificateRoleError as e:
raise HTTPException(
status_code=401,
detail=str(e),
)
...
Commands for generating certificates
The included cli can generate CA and issuer key certificate pairs suitable for signing client and server CSR requests in the IB1 Trust Framework.
Generate a CA key and certificate
Usage: ib1-directory create-ca [OPTIONS]
Generate a server signing CA key and certificate and an issuer key and
certificate pair signed by the CA then saves all files to disk
Options:
-u, --usage [signing|client|server] Choose signing, server or client CA
-c, --country TEXT Country to use for certificate generation
-s, --state TEXT State to use for certificate generation
-f, --framework TEXT Framework this certificate is for
--help Show this message and exit.
eg. to create a server CA key and certificate for the Core Trust Framework:
poetry run ib1-directory create-ca -u server -f Core
Create test client and server certficates
Client:
Usage: ib1-directory create-client-certificates [OPTIONS]
Create a private key and use it generate a CSR, then sign the CSR with a CA
key and certificate.
Saves the private key, CSR, certificate and bundle to disk.
Options:
--issuer-key-file FILENAME Issuer key file
--issuer-cert-file FILENAME Issuer certificate file
--member-uri TEXT Member uri
--application-uri TEXT Application uri
--organization-name TEXT Organization name
--country TEXT Country
--state TEXT State
-r, --role TEXT Client roles
--help Show this message and exit.
Server:
Usage: ib1-directory create-server-certificates [OPTIONS]
Create a private key and use it generate a CSR, then sign the CSR with a CA
key and certificate.
Saves the private key, CSR, certificate and bundle to disk.
Options:
--issuer-key-file FILENAME Issuer key file
--issuer-cert-file FILENAME Issuer certificate file
--domain TEXT Domain name
--trust-framework TEXT Trust framework
--country TEXT Country
--state TEXT State
--help Show this message and exit.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file ib1_directory-0.9.1.tar.gz.
File metadata
- Download URL: ib1_directory-0.9.1.tar.gz
- Upload date:
- Size: 9.0 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.8.3 CPython/3.12.3 Darwin/24.0.0
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
1d1effb3fdc652c6956b59b0b4fd27a088bea17268d82af7a4ee3e51306e3ea9
|
|
| MD5 |
6bd70c7796f7af8da38b7c7458e75514
|
|
| BLAKE2b-256 |
46eec48e1c13c4faaa04bdc5cdc56eeee06366f36eae0b2a1c100095c6938032
|
File details
Details for the file ib1_directory-0.9.1-py3-none-any.whl.
File metadata
- Download URL: ib1_directory-0.9.1-py3-none-any.whl
- Upload date:
- Size: 10.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: poetry/1.8.3 CPython/3.12.3 Darwin/24.0.0
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0ad311cb0764d18d552ff77f860edccaeaa582de1f5488233d73ec83a3002592
|
|
| MD5 |
64b779cd69db7393816aa09321ab0693
|
|
| BLAKE2b-256 |
6feb22476fd05d951317af5fca5342934e590c9adef1032a242372f80efa436d
|