aboutsummaryrefslogtreecommitdiffhomepage
diff options
context:
space:
mode:
authorJ08nY2024-02-02 16:31:47 +0100
committerJ08nY2024-02-02 16:31:47 +0100
commit328ca13e97fb2bc3c49ddcd0e5ec1b45300b8127 (patch)
tree8fe8f1932e361c4da20cb08fd97142c4648facf9
parent6d129a19dc77f15981cbdb27ace62e91206deac7 (diff)
downloadsec-certs-328ca13e97fb2bc3c49ddcd0e5ec1b45300b8127.tar.gz
sec-certs-328ca13e97fb2bc3c49ddcd0e5ec1b45300b8127.tar.zst
sec-certs-328ca13e97fb2bc3c49ddcd0e5ec1b45300b8127.zip
Fix cert_lab parsing.
-rw-r--r--src/sec_certs/rules.yaml42
-rw-r--r--src/sec_certs/sample/cc.py2
2 files changed, 22 insertions, 22 deletions
diff --git a/src/sec_certs/rules.yaml b/src/sec_certs/rules.yaml
index 8973b015..3cce1ab8 100644
--- a/src/sec_certs/rules.yaml
+++ b/src/sec_certs/rules.yaml
@@ -8,8 +8,8 @@ cc_cert_id:
- "BSI-DSZ-CC-[0-9]+?-[0-9]+"
- "BSI-DSZ-CC-[0-9]+?-(?:V|v)[0-9]+-[0-9]+"
- "BSI-DSZ-CC-[0-9]+?-(?:V|v)[0-9]+"
- - "BSI-DSZ-CC-[0-9]+-(?:V|v)[0-9]+(-[0-9][0-9][0-9][0-9])*" # German BSI (number + version + year or without year)
- - "BSI-DSZ-CC-[0-9]+-[0-9][0-9][0-9][0-9]" # German BSI (number + year, no version)
+ - "BSI-DSZ-CC-[0-9]+-(?:V|v)[0-9]+(-[0-9]{4})*" # German BSI (number + version + year or without year)
+ - "BSI-DSZ-CC-[0-9]+-[0-9]{4}" # German BSI (number + year, no version)
- "BSI-DSZ-CC-[0-9]+-(?:V|v)[0-9]+(?!-)" # German BSI (number + version but no year => no - after version)
# - "BSI-DSZ-CC-[0-9]+" # Maybe?
FR:
@@ -21,8 +21,8 @@ cc_cert_id:
- "Certification Report [0-9]+/[0-9]+" # French or Australia! Solved because we limit ourselves to scheme when doing heuristics.
- "Rapport de certification [0-9]+/[0-9]+" # French
NL:
- - "NSCIB-CC-[0-9][0-9][0-9][0-9].+?" # Netherlands
- - "NSCIB-CC-[0-9][0-9][0-9][0-9][0-9]*-CR" # Netherlands
+ - "NSCIB-CC-[0-9]{4}.+?" # Netherlands
+ - "NSCIB-CC-[0-9]{4}[0-9]*-CR" # Netherlands
- "NSCIB-CC-[0-9][0-9]-[0-9]+?-CR[0-9]+?" # Netherlands
- "NSCIB-CC-[0-9][0-9]-[0-9]+(-CR[0-9]+)*" # Netherlands (old number NSCIB-CC-05-6609 or NSCIB-CC-05-6609-CR)
- "NSCIB-CC-[0-9]+-CR[0-9]*" # Netherlands (new number NSCIB-CC-111441-CR NSCIB-CC-111441-CR1)
@@ -1083,39 +1083,39 @@ fips_security_level:
#####
fips_certlike:
Certlike:
- # --- HMAC(-SHA)(-1) - (bits) (method) ((hardware/firmware cert) #id) ---
- # + added (and #id) everywhere
+ # --- HMAC(-SHA)(-1) - (bits) (method) ((hardware/firmware cert) #id) ---
+ # + added (and #id) everywhere
- "HMAC(?:[- –]*SHA)?(?:[- –]*1)?[– -]*((?:;|\\/|160|224|256|384|512)?(?:;|\\/| |[Dd]ecrypt|[Ee]ncrypt|KAT)*?[, ]*?\\(?(?: |hardware|firmware)*?[\\s(\\[]*?(?:#|cert\\.?|Cert\\.?|Certificate|sample)?[\\s#]*?)?[\\s#]*?(\\d{1,4})(?:[\\s#]*and[\\s#]*\\d+)?"
- # --- same as above, without hw or fw ---
+ # --- same as above, without hw or fw ---
- "HMAC(?:-SHA)?(?:-1)?[ -]*((?:;|\\/|160|224|256|384|512)?(?:;|\\/| |[Dd]ecrypt|[Ee]ncrypt|KAT)*?[, ]*?(?:#|cert\\.?|sample|Cert\\.?|Certificate)?[\\s#]*?)?[\\s#]*?(\\d{1,4})"
- # --- SHS/A - (bits) (method) ((cert #) numbers) ---
+ # --- SHS/A - (bits) (method) ((cert #) numbers) ---
- "SH[SA][-– 123]*(?:;|\\/|160|224|256|384|512)?(?:[\\s(\\[]*?(?:KAT|[Bb]yte [Oo]riented)*?[\\s,]*?[\\s(\\[]*?(?:#|cert\\.?|sample|Cert\\.?|Certificate)?[\\s#]*?)?[\\s#]*?(\\d{1,4})(?:\\)?\\[#?\\d+\\])?(?:[\\s#]*?and[\\s#]*?\\d+)?"
- # --- RSA (bits) (method) ((cert #)) ---
+ # --- RSA (bits) (method) ((cert #)) ---
- "RSA(?:[-– ]*(?:;|\\/|512|768|1024|1280|1536|2048|3072|4096|8192)\\s\\(\\[]*?(?:(?:;|\\/|KAT|Verify|PSS|\\s)*?)?[\\s,]*?[\\s(\\[]*?(?:#|cert\\.?|sample|Cert\\.?|Certificate)?[\\s#]*?)?[\\s#]*?(\\d{1,4})"
- # --- RSA (SSA) (PKCS) (version) (#) ---
+ # --- RSA (SSA) (PKCS) (version) (#) ---
- "(?:RSA)?[-– ]?(?:SSA)?[- ]?PKCS\\s?#?\\d(?:-[Vv]1_5| [Vv]1[-_]5)?[\\s#]*?(\\d{1,4})?"
- # --- AES (bits) (method) ((cert #)) ---
+ # --- AES (bits) (method) ((cert #)) ---
- "AES[-– ]*((?: |;|\\/|bit|key|128|192|256|CBC)*(?: |\\/|;|[Dd]ecrypt|[Ee]ncrypt|KAT|CMAC|CTR|GCM|IV|CBC)*?[,\\s(\\[]*?(?:#|cert\\.?|sample|Cert\\.?|Certificate)?[\\s#]*?)?[\\s#]*?(\\d{1,4})(?:\\)?[\\s#]*?\\[#?\\d+\\])?(?:[\\s#]*?and[\\s#]*?(\\d+))?"
- # --- Diffie Helman (CVL) ((cert #)) ---
+ # --- Diffie Helman (CVL) ((cert #)) ---
- "Diffie[-– ]*Hellman[,\\s(\\[]*?(?:CVL|\\s)*?(?:#|cert\\.?|sample|Cert\\.?|Certificate)?[\\s#]*?[\\s#]*?(\\d{1,4})"
- # --- DRBG (bits) (method) (cert #) ---
+ # --- DRBG (bits) (method) (cert #) ---
- "DRBG[ –-]*((?:;|\\/|160|224|256|384|512)?(?:;|\\/| |[Dd]ecrypt|[Ee]ncrypt|KAT)*?[,\\s(\\[]*?(?:#|cert\\.?|sample|Cert\\.?|Certificate)?[\\s#]*?)?[\\s#]*?(\\d{1,4})"
- # --- DES (bits) (method) (cert #)
+ # --- DES (bits) (method) (cert #)
- "DES[ –-]*((?:;|\\/|160|224|256|384|512)?(?:;|\\/| |[Dd]ecrypt|[Ee]ncrypt|KAT|CBC|(?:\\d(?: and \\d)? keying options?))*?[,\\s(\\[]*?(?:#|cert\\.?|sample|Cert\\.?|Certificate)*?[\\s#]*?)?[\\s#]*?(\\d{1,4})(?:[\\s#]*?and[\\s#]*?(\\d+))?"
- # --- DSA (bits) (method) (cert #)
+ # --- DSA (bits) (method) (cert #)
- "DSA[ –-]*((?:;|\\/|160|224|256|384|512)?(?: |[Dd]ecrypt|[Ee]ncrypt|KAT)*?[,\\s(\\[]*?(?:#|cert\\.?|sample|Cert\\.?|Certificate)?[\\s#]*?)?[\\s#]*?(\\d{1,4})"
- # --- platforms (#)+ - this is used in modification history ---
+ # --- platforms (#)+ - this is used in modification history ---
- "[Pp]latforms? #\\d+(?:#\\d+|,| |-|and)*[^\\n]*"
- # --- CVL (#) ---
+ # --- CVL (#) ---
- "CVL[\\s#]*?(\\d{1,4})"
- # --- PAA (#) ---
+ # --- PAA (#) ---
- "PAA[: #]*?\\d{1,4}"
- # --- (#) Type ---
+ # --- (#) Type ---
- "(?:#|cert\\.?|sample|Cert\\.?|Certificate)[\\s#]*?(\\d+)?\\s*?(?:AES|SHS|SHA|RSA|HMAC|Diffie-Hellman|DRBG|DES|CVL)"
- # --- PKCS (#) ---
+ # --- PKCS (#) ---
- "PKCS[\\s]?#?\\d+"
- "PKSC[\\s]?#?\\d+" # typo, #625
- # --- # C and # A (just in case) ---
+ # --- # C and # A (just in case) ---
- "#\\s+?[Cc]\\d+"
- "#\\s+?[Aa]\\d+"
diff --git a/src/sec_certs/sample/cc.py b/src/sec_certs/sample/cc.py
index 4cd1324d..6ee2bd1b 100644
--- a/src/sec_certs/sample/cc.py
+++ b/src/sec_certs/sample/cc.py
@@ -292,7 +292,7 @@ class CCCertificate(
labs = [
data["cert_lab"].split(" ")[0].upper()
for data in [self.bsi_data, self.anssi_data, self.niap_data, self.nscib_data, self.canada_data]
- if data
+ if data and "cert_lab" in data
]
return labs if labs else None