Source file Jwa.ml

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
type kty =
  [ `oct  (** Octet sequence (used to represent symmetric keys) *)
  | `RSA  (** RSA *)
  | `EC  (** Elliptic Curve *)
  | `OKP  (** Octet Key Pair *)
  | `Unsupported of string ]

let kty_to_string : kty -> string = function
  | `oct -> "oct"
  | `RSA -> "RSA"
  | `EC -> "EC"
  | `OKP -> "OKP"
  | `Unsupported str -> str

let kty_of_string : string -> kty = function
  | "oct" -> `oct
  | "RSA" -> `RSA
  | "EC" -> `EC
  | "OKP" -> `OKP
  | str -> `Unsupported str

type alg =
  [ `RS256  (** RSASSA-PKCS1-v1_5 using SHA-256 *)
  | `HS256  (** HMAC using SHA-256 *)
  | `ES256  (** ECDSA using P-256 and SHA-256 *)
  | `ES384  (** ECDSA using P-384 and SHA-384 *)
  | `ES512  (** ECDSA using P-521 and SHA-512 *)
  | `EdDSA  (** EdDSA signature algorithm *)
  | `Ed25519  (** Ed25519 signature algorithm (RFC 9864) *)
  | `RSA_OAEP  (** RSAES OAEP using default parameters *)
  | `RSA1_5  (** RSA PKCS 1 *)
  | `None
  | `Unsupported of string ]

let alg_to_string = function
  | `RS256 -> "RS256"
  | `HS256 -> "HS256"
  | `ES256 -> "ES256"
  | `ES384 -> "ES384"
  | `ES512 -> "ES512"
  | `EdDSA -> "EdDSA"
  | `Ed25519 -> "Ed25519"
  | `RSA_OAEP -> "RSA-OAEP"
  | `RSA1_5 -> "RSA1_5"
  | `None -> "none"
  | `Unsupported string -> string

let alg_of_string = function
  | "RS256" -> `RS256
  | "HS256" -> `HS256
  | "ES256" -> `ES256
  | "ES384" -> `ES384
  | "ES512" -> `ES512
  | "EdDSA" -> `EdDSA
  | "Ed25519" -> `Ed25519
  | "RSA-OAEP" -> `RSA_OAEP
  | "RSA1_5" -> `RSA1_5
  | "none" -> `None
  | str -> `Unsupported str

let alg_to_json alg = `String (alg_to_string alg)
let alg_of_json json = Yojson.Safe.Util.to_string json |> alg_of_string

type enc =
  [ `A128CBC_HS256
    (** AES_128_CBC_HMAC_SHA_256 authenticated encryption algorithm,
        https://tools.ietf.org/html/rfc7518#section-5.2.3 *)
  | `A256GCM  (** AES GCM using 256-bit key *) ]
(** https://tools.ietf.org/html/rfc7518#section-5 *)

let enc_to_string enc =
  match enc with `A128CBC_HS256 -> "A128CBC-HS256" | `A256GCM -> "A256GCM"

let enc_of_string enc =
  match enc with
  | "A128CBC-HS256" -> `A128CBC_HS256
  | "A256GCM" -> `A256GCM
  | _ -> raise Not_found

let enc_to_length = function `A128CBC_HS256 -> 256 | `A256GCM -> 256

let enc_to_iv_length = function
  | `A128CBC_HS256 -> Mirage_crypto.AES.CBC.block_size
  (* https://www.rfc-editor.org/info/rfc7518/#section-5.3 12*8 = 96 bits*)
  | `A256GCM -> 12