Repository files navigation

node-webcrypto-p11

licensetestCoverage Statusnpm version

NPM

We wanted to be able to write Javascript that used crypto on both the client and the server but we did not want to rely on Javascript implementations of crypto. The only native cryptography availible in browser is Web Crypto, this resulted in us creating a native polyfil for WebCrypto based on Openssl.

Our project also required us to utilize Hardware Security Modules and smart cards on the server side so we made a library called Graphene that made it possible to use PKCS#11 devices from within Nodejs.

We then thought that in most cases others did not care about interacting with the token directly and would prefer a higher level API they were already familiar with. We hope that library is node-webcrypto-p11, if you have code based on WebCrypto (for example the excelent js-jose) with only a change in a constructor you can work with PKCS#11 devices.

For example to generate a key you this is all it takes:

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "RSASSA-PKCS1-v1_5",modulusLength: 1024,publicExponent: newUint8Array([1,0,1]),hash: {name: "SHA-1",},},true,["sign","verify"]);

WARNING

At this time this solution should be considered suitable for research and experimentation, further code and security review is needed before utilization in a production application.

Algorithms

Supported algorithms

Algorithm namegenerateKeydigestexport/importsign/verifyencrypt/decryptwrapKey/unwrapKeyderive
SHA-1X
SHA-256X
SHA-384X
SHA-512X
RSASSA-PKCS1-v1_5XXX
RSAES-PKCS1-v1_5 2XXXX
RSA-PSSXXX
RSA-OAEPXXXX
AES-CBCXXXX
AES-ECB 2XXXX
AES-GCMXXXX
ECDSA 1XXX
ECDH 2XXX
HMACXXX

1 Mechanism supports extended list of named curves P-256, P-384, P-521, and K-256

2 Mechanism is not defined by the WebCrypto specifications. Use of mechanism in a safe way is hard, it was added for the purpose of enabling interoperability with an existing system. We recommend against its use unless needed for interoperability.

Installation

NPM

npm install node-webcrypto-p11

Clone Repository

git clone https://github.com/PeculiarVentures/node-webcrypto-p11
cd node-webcrypto-p11

Install SoftHSM2

Install

npm install

Test

mocha

Configuration

Tests and samples use a file called config.js file for PKCS11 module configuration. The format of which is:

module.exports={library: "path/to/pkcs11/module.so",name: "Name of PKCS11 module",slot: 0,// number of slotpin: "password"readWrite: true,vendors: []// list of vendor files, optional}

Threats

The threat model is defined in terms of what each possible attacker can achieve. The list is intended to be exhaustive.

Assumptions

TODO: ADD ASSUMPTIONS

Threats From A node-webcrypto-p11 Defect

node-webcrypto-p11 handles ciphertext, cleartext, and sessions. A defect in this library could result in these values being exposed to an attacker. Examples of such defects include:

  • Buffer, Integer or other overflow related defects,
  • Parsing errors,
  • Logic errors,
  • Weak user seperation or permissions.

Threats From A PKCS#11 defect

PKCS#11 implementations are often old, poorly maintained and incomplete. This can obviously lead to defects. Defects in the PKCS#11 implementation can result in:

  • Weakly implemented or applied cryptographic primitives,
  • Leaked sessions or secrets that expose use of the key,
  • Leaked cryptographic key material.

Threats From Weak Cryptography

Secure use of cryptography requires the implementor to understand the security properties of a given algorithm as well as how to use it in a secure construction.

Additionally this library exposes some algorithms that may have known weakneses or are simply too old to be used safely.

Threats From Improper Use Of Cryptography

It is easy to apply cryptography but hard to apply it correctly. Algorithms each have their own security properties and appropriate constructions. The consumer of this library is responsible for understanding how to use the exposed algorithms securely.

Generates ECDSA key pair with named curve P-256 and signs/verifies text message.

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);constsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},keys.privateKey,Buffer.from("Hello world!"));console.log(`Signature: ${signature}`);constok=awaitcrypto.subtle.verify({name: "ECDSA",hash: "SHA-256"},keys.publicKey,signature,Buffer.from("Hello world!"));console.log(`Verification: ${ok}`);

Key Storage

The CryptoKeyStorage interface enables you to persist and retrieve keys across sessions.

Generate a cryptographic key and store it

constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);// set private key to storageconstprivateKeyID=awaitcrypto.keyStorage.setItem(keys.privateKey);// set public key to storageconstpublicKeyID=awaitcrypto.keyStorage.setItem(keys.publicKey);// get list of keysconstindexes=awaitcrypto.keyStorage.keys();console.log(indexes);// ['private-3239...', 'public-3239...']// get key by idconstprivateKey=awaitcrypto.keyStorage.getItem("private-3239...");// signing dataconstsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},key,Buffer.from("Message here"));console.log("Signature:",Buffer.from(signature).toString("hex"));

Certificate Storage

The CryptoCertificateStorage interface enables you to persist and retrieve certificates across sessions.

Add certificate to storage and use it for verification of signed data

constX509_RAW=Buffer.from("308203A830820290A003020...","hex");constx509=awaitcrypto.certStorage.importCert("raw",X509_RAW,{name: "RSASSA-PKCS1-v1_5",hash: "SHA-256"},["verify"]);console.log(x509.subjectName);// C=name, O=...constindex=awaitcrypto.certStorage.setItem(x509);console.log(index);// x509-2943...constok=awaitcrypto.subtle.verify({name: "RSASSA-PKCS1-v1_5"},x509.publicKey,SIGNATURE,MESSAGE);console.log("Signature:",ok);

Bug Reporting

Please report bugs either as pull requests or as issues in the issue tracker. Backwater has a full disclosure vulnerability policy. Please do NOT attempt to report any security vulnerability in this code privately to anybody.

Related

About

A WebCrypto Polyfill for Node in typescript built on PKCS#11.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Repository files navigation

node-webcrypto-p11

licensetestCoverage Statusnpm version

NPM

We wanted to be able to write Javascript that used crypto on both the client and the server but we did not want to rely on Javascript implementations of crypto. The only native cryptography availible in browser is Web Crypto, this resulted in us creating a native polyfil for WebCrypto based on Openssl.

Our project also required us to utilize Hardware Security Modules and smart cards on the server side so we made a library called Graphene that made it possible to use PKCS#11 devices from within Nodejs.

We then thought that in most cases others did not care about interacting with the token directly and would prefer a higher level API they were already familiar with. We hope that library is node-webcrypto-p11, if you have code based on WebCrypto (for example the excelent js-jose) with only a change in a constructor you can work with PKCS#11 devices.

For example to generate a key you this is all it takes:

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "RSASSA-PKCS1-v1_5",modulusLength: 1024,publicExponent: newUint8Array([1,0,1]),hash: {name: "SHA-1",},},true,["sign","verify"]);

WARNING

At this time this solution should be considered suitable for research and experimentation, further code and security review is needed before utilization in a production application.

Algorithms

Supported algorithms

Algorithm namegenerateKeydigestexport/importsign/verifyencrypt/decryptwrapKey/unwrapKeyderive
SHA-1X
SHA-256X
SHA-384X
SHA-512X
RSASSA-PKCS1-v1_5XXX
RSAES-PKCS1-v1_5 2XXXX
RSA-PSSXXX
RSA-OAEPXXXX
AES-CBCXXXX
AES-ECB 2XXXX
AES-GCMXXXX
ECDSA 1XXX
ECDH 2XXX
HMACXXX

1 Mechanism supports extended list of named curves P-256, P-384, P-521, and K-256

2 Mechanism is not defined by the WebCrypto specifications. Use of mechanism in a safe way is hard, it was added for the purpose of enabling interoperability with an existing system. We recommend against its use unless needed for interoperability.

Installation

NPM

npm install node-webcrypto-p11

Clone Repository

git clone https://github.com/PeculiarVentures/node-webcrypto-p11
cd node-webcrypto-p11

Install SoftHSM2

Install

npm install

Test

mocha

Configuration

Tests and samples use a file called config.js file for PKCS11 module configuration. The format of which is:

module.exports={library: "path/to/pkcs11/module.so",name: "Name of PKCS11 module",slot: 0,// number of slotpin: "password"readWrite: true,vendors: []// list of vendor files, optional}

Threats

The threat model is defined in terms of what each possible attacker can achieve. The list is intended to be exhaustive.

Assumptions

TODO: ADD ASSUMPTIONS

Threats From A node-webcrypto-p11 Defect

node-webcrypto-p11 handles ciphertext, cleartext, and sessions. A defect in this library could result in these values being exposed to an attacker. Examples of such defects include:

  • Buffer, Integer or other overflow related defects,
  • Parsing errors,
  • Logic errors,
  • Weak user seperation or permissions.

Threats From A PKCS#11 defect

PKCS#11 implementations are often old, poorly maintained and incomplete. This can obviously lead to defects. Defects in the PKCS#11 implementation can result in:

  • Weakly implemented or applied cryptographic primitives,
  • Leaked sessions or secrets that expose use of the key,
  • Leaked cryptographic key material.

Threats From Weak Cryptography

Secure use of cryptography requires the implementor to understand the security properties of a given algorithm as well as how to use it in a secure construction.

Additionally this library exposes some algorithms that may have known weakneses or are simply too old to be used safely.

Threats From Improper Use Of Cryptography

It is easy to apply cryptography but hard to apply it correctly. Algorithms each have their own security properties and appropriate constructions. The consumer of this library is responsible for understanding how to use the exposed algorithms securely.

Generates ECDSA key pair with named curve P-256 and signs/verifies text message.

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);constsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},keys.privateKey,Buffer.from("Hello world!"));console.log(`Signature: ${signature}`);constok=awaitcrypto.subtle.verify({name: "ECDSA",hash: "SHA-256"},keys.publicKey,signature,Buffer.from("Hello world!"));console.log(`Verification: ${ok}`);

Key Storage

The CryptoKeyStorage interface enables you to persist and retrieve keys across sessions.

Generate a cryptographic key and store it

constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);// set private key to storageconstprivateKeyID=awaitcrypto.keyStorage.setItem(keys.privateKey);// set public key to storageconstpublicKeyID=awaitcrypto.keyStorage.setItem(keys.publicKey);// get list of keysconstindexes=awaitcrypto.keyStorage.keys();console.log(indexes);// ['private-3239...', 'public-3239...']// get key by idconstprivateKey=awaitcrypto.keyStorage.getItem("private-3239...");// signing dataconstsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},key,Buffer.from("Message here"));console.log("Signature:",Buffer.from(signature).toString("hex"));

Certificate Storage

The CryptoCertificateStorage interface enables you to persist and retrieve certificates across sessions.

Add certificate to storage and use it for verification of signed data

constX509_RAW=Buffer.from("308203A830820290A003020...","hex");constx509=awaitcrypto.certStorage.importCert("raw",X509_RAW,{name: "RSASSA-PKCS1-v1_5",hash: "SHA-256"},["verify"]);console.log(x509.subjectName);// C=name, O=...constindex=awaitcrypto.certStorage.setItem(x509);console.log(index);// x509-2943...constok=awaitcrypto.subtle.verify({name: "RSASSA-PKCS1-v1_5"},x509.publicKey,SIGNATURE,MESSAGE);console.log("Signature:",ok);

Bug Reporting

Please report bugs either as pull requests or as issues in the issue tracker. Backwater has a full disclosure vulnerability policy. Please do NOT attempt to report any security vulnerability in this code privately to anybody.

Related

About

A WebCrypto Polyfill for Node in typescript built on PKCS#11.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

node-webcrypto-p11

licensetestCoverage Statusnpm version

NPM

We wanted to be able to write Javascript that used crypto on both the client and the server but we did not want to rely on Javascript implementations of crypto. The only native cryptography availible in browser is Web Crypto, this resulted in us creating a native polyfil for WebCrypto based on Openssl.

Our project also required us to utilize Hardware Security Modules and smart cards on the server side so we made a library called Graphene that made it possible to use PKCS#11 devices from within Nodejs.

We then thought that in most cases others did not care about interacting with the token directly and would prefer a higher level API they were already familiar with. We hope that library is node-webcrypto-p11, if you have code based on WebCrypto (for example the excelent js-jose) with only a change in a constructor you can work with PKCS#11 devices.

For example to generate a key you this is all it takes:

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "RSASSA-PKCS1-v1_5",modulusLength: 1024,publicExponent: newUint8Array([1,0,1]),hash: {name: "SHA-1",},},true,["sign","verify"]);

WARNING

At this time this solution should be considered suitable for research and experimentation, further code and security review is needed before utilization in a production application.

Algorithms

Supported algorithms

Algorithm namegenerateKeydigestexport/importsign/verifyencrypt/decryptwrapKey/unwrapKeyderive
SHA-1X
SHA-256X
SHA-384X
SHA-512X
RSASSA-PKCS1-v1_5XXX
RSAES-PKCS1-v1_5 2XXXX
RSA-PSSXXX
RSA-OAEPXXXX
AES-CBCXXXX
AES-ECB 2XXXX
AES-GCMXXXX
ECDSA 1XXX
ECDH 2XXX
HMACXXX

1 Mechanism supports extended list of named curves P-256, P-384, P-521, and K-256

2 Mechanism is not defined by the WebCrypto specifications. Use of mechanism in a safe way is hard, it was added for the purpose of enabling interoperability with an existing system. We recommend against its use unless needed for interoperability.

Installation

NPM

npm install node-webcrypto-p11

Clone Repository

git clone https://github.com/PeculiarVentures/node-webcrypto-p11
cd node-webcrypto-p11

Install SoftHSM2

Install

npm install

Test

mocha

Configuration

Tests and samples use a file called config.js file for PKCS11 module configuration. The format of which is:

module.exports={library: "path/to/pkcs11/module.so",name: "Name of PKCS11 module",slot: 0,// number of slotpin: "password"readWrite: true,vendors: []// list of vendor files, optional}

Threats

The threat model is defined in terms of what each possible attacker can achieve. The list is intended to be exhaustive.

Assumptions

TODO: ADD ASSUMPTIONS

Threats From A node-webcrypto-p11 Defect

node-webcrypto-p11 handles ciphertext, cleartext, and sessions. A defect in this library could result in these values being exposed to an attacker. Examples of such defects include:

  • Buffer, Integer or other overflow related defects,
  • Parsing errors,
  • Logic errors,
  • Weak user seperation or permissions.

Threats From A PKCS#11 defect

PKCS#11 implementations are often old, poorly maintained and incomplete. This can obviously lead to defects. Defects in the PKCS#11 implementation can result in:

  • Weakly implemented or applied cryptographic primitives,
  • Leaked sessions or secrets that expose use of the key,
  • Leaked cryptographic key material.

Threats From Weak Cryptography

Secure use of cryptography requires the implementor to understand the security properties of a given algorithm as well as how to use it in a secure construction.

Additionally this library exposes some algorithms that may have known weakneses or are simply too old to be used safely.

Threats From Improper Use Of Cryptography

It is easy to apply cryptography but hard to apply it correctly. Algorithms each have their own security properties and appropriate constructions. The consumer of this library is responsible for understanding how to use the exposed algorithms securely.

Generates ECDSA key pair with named curve P-256 and signs/verifies text message.

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);constsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},keys.privateKey,Buffer.from("Hello world!"));console.log(`Signature: ${signature}`);constok=awaitcrypto.subtle.verify({name: "ECDSA",hash: "SHA-256"},keys.publicKey,signature,Buffer.from("Hello world!"));console.log(`Verification: ${ok}`);

Key Storage

The CryptoKeyStorage interface enables you to persist and retrieve keys across sessions.

Generate a cryptographic key and store it

constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);// set private key to storageconstprivateKeyID=awaitcrypto.keyStorage.setItem(keys.privateKey);// set public key to storageconstpublicKeyID=awaitcrypto.keyStorage.setItem(keys.publicKey);// get list of keysconstindexes=awaitcrypto.keyStorage.keys();console.log(indexes);// ['private-3239...', 'public-3239...']// get key by idconstprivateKey=awaitcrypto.keyStorage.getItem("private-3239...");// signing dataconstsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},key,Buffer.from("Message here"));console.log("Signature:",Buffer.from(signature).toString("hex"));

Certificate Storage

The CryptoCertificateStorage interface enables you to persist and retrieve certificates across sessions.

Add certificate to storage and use it for verification of signed data

constX509_RAW=Buffer.from("308203A830820290A003020...","hex");constx509=awaitcrypto.certStorage.importCert("raw",X509_RAW,{name: "RSASSA-PKCS1-v1_5",hash: "SHA-256"},["verify"]);console.log(x509.subjectName);// C=name, O=...constindex=awaitcrypto.certStorage.setItem(x509);console.log(index);// x509-2943...constok=awaitcrypto.subtle.verify({name: "RSASSA-PKCS1-v1_5"},x509.publicKey,SIGNATURE,MESSAGE);console.log("Signature:",ok);

Bug Reporting

Please report bugs either as pull requests or as issues in the issue tracker. Backwater has a full disclosure vulnerability policy. Please do NOT attempt to report any security vulnerability in this code privately to anybody.

Related

About

A WebCrypto Polyfill for Node in typescript built on PKCS#11.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

node-webcrypto-p11

licensetestCoverage Statusnpm version

NPM

We wanted to be able to write Javascript that used crypto on both the client and the server but we did not want to rely on Javascript implementations of crypto. The only native cryptography availible in browser is Web Crypto, this resulted in us creating a native polyfil for WebCrypto based on Openssl.

Our project also required us to utilize Hardware Security Modules and smart cards on the server side so we made a library called Graphene that made it possible to use PKCS#11 devices from within Nodejs.

We then thought that in most cases others did not care about interacting with the token directly and would prefer a higher level API they were already familiar with. We hope that library is node-webcrypto-p11, if you have code based on WebCrypto (for example the excelent js-jose) with only a change in a constructor you can work with PKCS#11 devices.

For example to generate a key you this is all it takes:

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "RSASSA-PKCS1-v1_5",modulusLength: 1024,publicExponent: newUint8Array([1,0,1]),hash: {name: "SHA-1",},},true,["sign","verify"]);

WARNING

At this time this solution should be considered suitable for research and experimentation, further code and security review is needed before utilization in a production application.

Algorithms

Supported algorithms

Algorithm namegenerateKeydigestexport/importsign/verifyencrypt/decryptwrapKey/unwrapKeyderive
SHA-1X
SHA-256X
SHA-384X
SHA-512X
RSASSA-PKCS1-v1_5XXX
RSAES-PKCS1-v1_5 2XXXX
RSA-PSSXXX
RSA-OAEPXXXX
AES-CBCXXXX
AES-ECB 2XXXX
AES-GCMXXXX
ECDSA 1XXX
ECDH 2XXX
HMACXXX

1 Mechanism supports extended list of named curves P-256, P-384, P-521, and K-256

2 Mechanism is not defined by the WebCrypto specifications. Use of mechanism in a safe way is hard, it was added for the purpose of enabling interoperability with an existing system. We recommend against its use unless needed for interoperability.

Installation

NPM

npm install node-webcrypto-p11

Clone Repository

git clone https://github.com/PeculiarVentures/node-webcrypto-p11
cd node-webcrypto-p11

Install SoftHSM2

Install

npm install

Test

mocha

Configuration

Tests and samples use a file called config.js file for PKCS11 module configuration. The format of which is:

module.exports={library: "path/to/pkcs11/module.so",name: "Name of PKCS11 module",slot: 0,// number of slotpin: "password"readWrite: true,vendors: []// list of vendor files, optional}

Threats

The threat model is defined in terms of what each possible attacker can achieve. The list is intended to be exhaustive.

Assumptions

TODO: ADD ASSUMPTIONS

Threats From A node-webcrypto-p11 Defect

node-webcrypto-p11 handles ciphertext, cleartext, and sessions. A defect in this library could result in these values being exposed to an attacker. Examples of such defects include:

  • Buffer, Integer or other overflow related defects,
  • Parsing errors,
  • Logic errors,
  • Weak user seperation or permissions.

Threats From A PKCS#11 defect

PKCS#11 implementations are often old, poorly maintained and incomplete. This can obviously lead to defects. Defects in the PKCS#11 implementation can result in:

  • Weakly implemented or applied cryptographic primitives,
  • Leaked sessions or secrets that expose use of the key,
  • Leaked cryptographic key material.

Threats From Weak Cryptography

Secure use of cryptography requires the implementor to understand the security properties of a given algorithm as well as how to use it in a secure construction.

Additionally this library exposes some algorithms that may have known weakneses or are simply too old to be used safely.

Threats From Improper Use Of Cryptography

It is easy to apply cryptography but hard to apply it correctly. Algorithms each have their own security properties and appropriate constructions. The consumer of this library is responsible for understanding how to use the exposed algorithms securely.

Generates ECDSA key pair with named curve P-256 and signs/verifies text message.

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);constsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},keys.privateKey,Buffer.from("Hello world!"));console.log(`Signature: ${signature}`);constok=awaitcrypto.subtle.verify({name: "ECDSA",hash: "SHA-256"},keys.publicKey,signature,Buffer.from("Hello world!"));console.log(`Verification: ${ok}`);

Key Storage

The CryptoKeyStorage interface enables you to persist and retrieve keys across sessions.

Generate a cryptographic key and store it

constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);// set private key to storageconstprivateKeyID=awaitcrypto.keyStorage.setItem(keys.privateKey);// set public key to storageconstpublicKeyID=awaitcrypto.keyStorage.setItem(keys.publicKey);// get list of keysconstindexes=awaitcrypto.keyStorage.keys();console.log(indexes);// ['private-3239...', 'public-3239...']// get key by idconstprivateKey=awaitcrypto.keyStorage.getItem("private-3239...");// signing dataconstsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},key,Buffer.from("Message here"));console.log("Signature:",Buffer.from(signature).toString("hex"));

Certificate Storage

The CryptoCertificateStorage interface enables you to persist and retrieve certificates across sessions.

Add certificate to storage and use it for verification of signed data

constX509_RAW=Buffer.from("308203A830820290A003020...","hex");constx509=awaitcrypto.certStorage.importCert("raw",X509_RAW,{name: "RSASSA-PKCS1-v1_5",hash: "SHA-256"},["verify"]);console.log(x509.subjectName);// C=name, O=...constindex=awaitcrypto.certStorage.setItem(x509);console.log(index);// x509-2943...constok=awaitcrypto.subtle.verify({name: "RSASSA-PKCS1-v1_5"},x509.publicKey,SIGNATURE,MESSAGE);console.log("Signature:",ok);

Bug Reporting

Please report bugs either as pull requests or as issues in the issue tracker. Backwater has a full disclosure vulnerability policy. Please do NOT attempt to report any security vulnerability in this code privately to anybody.

Related

About

A WebCrypto Polyfill for Node in typescript built on PKCS#11.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Repository files navigation

node-webcrypto-p11

licensetestCoverage Statusnpm version

NPM

We wanted to be able to write Javascript that used crypto on both the client and the server but we did not want to rely on Javascript implementations of crypto. The only native cryptography availible in browser is Web Crypto, this resulted in us creating a native polyfil for WebCrypto based on Openssl.

Our project also required us to utilize Hardware Security Modules and smart cards on the server side so we made a library called Graphene that made it possible to use PKCS#11 devices from within Nodejs.

We then thought that in most cases others did not care about interacting with the token directly and would prefer a higher level API they were already familiar with. We hope that library is node-webcrypto-p11, if you have code based on WebCrypto (for example the excelent js-jose) with only a change in a constructor you can work with PKCS#11 devices.

For example to generate a key you this is all it takes:

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "RSASSA-PKCS1-v1_5",modulusLength: 1024,publicExponent: newUint8Array([1,0,1]),hash: {name: "SHA-1",},},true,["sign","verify"]);

WARNING

At this time this solution should be considered suitable for research and experimentation, further code and security review is needed before utilization in a production application.

Algorithms

Supported algorithms

Algorithm namegenerateKeydigestexport/importsign/verifyencrypt/decryptwrapKey/unwrapKeyderive
SHA-1X
SHA-256X
SHA-384X
SHA-512X
RSASSA-PKCS1-v1_5XXX
RSAES-PKCS1-v1_5 2XXXX
RSA-PSSXXX
RSA-OAEPXXXX
AES-CBCXXXX
AES-ECB 2XXXX
AES-GCMXXXX
ECDSA 1XXX
ECDH 2XXX
HMACXXX

1 Mechanism supports extended list of named curves P-256, P-384, P-521, and K-256

2 Mechanism is not defined by the WebCrypto specifications. Use of mechanism in a safe way is hard, it was added for the purpose of enabling interoperability with an existing system. We recommend against its use unless needed for interoperability.

Installation

NPM

npm install node-webcrypto-p11

Clone Repository

git clone https://github.com/PeculiarVentures/node-webcrypto-p11
cd node-webcrypto-p11

Install SoftHSM2

Install

npm install

Test

mocha

Configuration

Tests and samples use a file called config.js file for PKCS11 module configuration. The format of which is:

module.exports={library: "path/to/pkcs11/module.so",name: "Name of PKCS11 module",slot: 0,// number of slotpin: "password"readWrite: true,vendors: []// list of vendor files, optional}

Threats

The threat model is defined in terms of what each possible attacker can achieve. The list is intended to be exhaustive.

Assumptions

TODO: ADD ASSUMPTIONS

Threats From A node-webcrypto-p11 Defect

node-webcrypto-p11 handles ciphertext, cleartext, and sessions. A defect in this library could result in these values being exposed to an attacker. Examples of such defects include:

  • Buffer, Integer or other overflow related defects,
  • Parsing errors,
  • Logic errors,
  • Weak user seperation or permissions.

Threats From A PKCS#11 defect

PKCS#11 implementations are often old, poorly maintained and incomplete. This can obviously lead to defects. Defects in the PKCS#11 implementation can result in:

  • Weakly implemented or applied cryptographic primitives,
  • Leaked sessions or secrets that expose use of the key,
  • Leaked cryptographic key material.

Threats From Weak Cryptography

Secure use of cryptography requires the implementor to understand the security properties of a given algorithm as well as how to use it in a secure construction.

Additionally this library exposes some algorithms that may have known weakneses or are simply too old to be used safely.

Threats From Improper Use Of Cryptography

It is easy to apply cryptography but hard to apply it correctly. Algorithms each have their own security properties and appropriate constructions. The consumer of this library is responsible for understanding how to use the exposed algorithms securely.

Generates ECDSA key pair with named curve P-256 and signs/verifies text message.

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);constsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},keys.privateKey,Buffer.from("Hello world!"));console.log(`Signature: ${signature}`);constok=awaitcrypto.subtle.verify({name: "ECDSA",hash: "SHA-256"},keys.publicKey,signature,Buffer.from("Hello world!"));console.log(`Verification: ${ok}`);

Key Storage

The CryptoKeyStorage interface enables you to persist and retrieve keys across sessions.

Generate a cryptographic key and store it

constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);// set private key to storageconstprivateKeyID=awaitcrypto.keyStorage.setItem(keys.privateKey);// set public key to storageconstpublicKeyID=awaitcrypto.keyStorage.setItem(keys.publicKey);// get list of keysconstindexes=awaitcrypto.keyStorage.keys();console.log(indexes);// ['private-3239...', 'public-3239...']// get key by idconstprivateKey=awaitcrypto.keyStorage.getItem("private-3239...");// signing dataconstsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},key,Buffer.from("Message here"));console.log("Signature:",Buffer.from(signature).toString("hex"));

Certificate Storage

The CryptoCertificateStorage interface enables you to persist and retrieve certificates across sessions.

Add certificate to storage and use it for verification of signed data

constX509_RAW=Buffer.from("308203A830820290A003020...","hex");constx509=awaitcrypto.certStorage.importCert("raw",X509_RAW,{name: "RSASSA-PKCS1-v1_5",hash: "SHA-256"},["verify"]);console.log(x509.subjectName);// C=name, O=...constindex=awaitcrypto.certStorage.setItem(x509);console.log(index);// x509-2943...constok=awaitcrypto.subtle.verify({name: "RSASSA-PKCS1-v1_5"},x509.publicKey,SIGNATURE,MESSAGE);console.log("Signature:",ok);

Bug Reporting

Please report bugs either as pull requests or as issues in the issue tracker. Backwater has a full disclosure vulnerability policy. Please do NOT attempt to report any security vulnerability in this code privately to anybody.

Related

About

A WebCrypto Polyfill for Node in typescript built on PKCS#11.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

node-webcrypto-p11

licensetestCoverage Statusnpm version

NPM

We wanted to be able to write Javascript that used crypto on both the client and the server but we did not want to rely on Javascript implementations of crypto. The only native cryptography availible in browser is Web Crypto, this resulted in us creating a native polyfil for WebCrypto based on Openssl.

Our project also required us to utilize Hardware Security Modules and smart cards on the server side so we made a library called Graphene that made it possible to use PKCS#11 devices from within Nodejs.

We then thought that in most cases others did not care about interacting with the token directly and would prefer a higher level API they were already familiar with. We hope that library is node-webcrypto-p11, if you have code based on WebCrypto (for example the excelent js-jose) with only a change in a constructor you can work with PKCS#11 devices.

For example to generate a key you this is all it takes:

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "RSASSA-PKCS1-v1_5",modulusLength: 1024,publicExponent: newUint8Array([1,0,1]),hash: {name: "SHA-1",},},true,["sign","verify"]);

WARNING

At this time this solution should be considered suitable for research and experimentation, further code and security review is needed before utilization in a production application.

Algorithms

Supported algorithms

Algorithm namegenerateKeydigestexport/importsign/verifyencrypt/decryptwrapKey/unwrapKeyderive
SHA-1X
SHA-256X
SHA-384X
SHA-512X
RSASSA-PKCS1-v1_5XXX
RSAES-PKCS1-v1_5 2XXXX
RSA-PSSXXX
RSA-OAEPXXXX
AES-CBCXXXX
AES-ECB 2XXXX
AES-GCMXXXX
ECDSA 1XXX
ECDH 2XXX
HMACXXX

1 Mechanism supports extended list of named curves P-256, P-384, P-521, and K-256

2 Mechanism is not defined by the WebCrypto specifications. Use of mechanism in a safe way is hard, it was added for the purpose of enabling interoperability with an existing system. We recommend against its use unless needed for interoperability.

Installation

NPM

npm install node-webcrypto-p11

Clone Repository

git clone https://github.com/PeculiarVentures/node-webcrypto-p11
cd node-webcrypto-p11

Install SoftHSM2

Install

npm install

Test

mocha

Configuration

Tests and samples use a file called config.js file for PKCS11 module configuration. The format of which is:

module.exports={library: "path/to/pkcs11/module.so",name: "Name of PKCS11 module",slot: 0,// number of slotpin: "password"readWrite: true,vendors: []// list of vendor files, optional}

Threats

The threat model is defined in terms of what each possible attacker can achieve. The list is intended to be exhaustive.

Assumptions

TODO: ADD ASSUMPTIONS

Threats From A node-webcrypto-p11 Defect

node-webcrypto-p11 handles ciphertext, cleartext, and sessions. A defect in this library could result in these values being exposed to an attacker. Examples of such defects include:

  • Buffer, Integer or other overflow related defects,
  • Parsing errors,
  • Logic errors,
  • Weak user seperation or permissions.

Threats From A PKCS#11 defect

PKCS#11 implementations are often old, poorly maintained and incomplete. This can obviously lead to defects. Defects in the PKCS#11 implementation can result in:

  • Weakly implemented or applied cryptographic primitives,
  • Leaked sessions or secrets that expose use of the key,
  • Leaked cryptographic key material.

Threats From Weak Cryptography

Secure use of cryptography requires the implementor to understand the security properties of a given algorithm as well as how to use it in a secure construction.

Additionally this library exposes some algorithms that may have known weakneses or are simply too old to be used safely.

Threats From Improper Use Of Cryptography

It is easy to apply cryptography but hard to apply it correctly. Algorithms each have their own security properties and appropriate constructions. The consumer of this library is responsible for understanding how to use the exposed algorithms securely.

Generates ECDSA key pair with named curve P-256 and signs/verifies text message.

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);constsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},keys.privateKey,Buffer.from("Hello world!"));console.log(`Signature: ${signature}`);constok=awaitcrypto.subtle.verify({name: "ECDSA",hash: "SHA-256"},keys.publicKey,signature,Buffer.from("Hello world!"));console.log(`Verification: ${ok}`);

Key Storage

The CryptoKeyStorage interface enables you to persist and retrieve keys across sessions.

Generate a cryptographic key and store it

constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);// set private key to storageconstprivateKeyID=awaitcrypto.keyStorage.setItem(keys.privateKey);// set public key to storageconstpublicKeyID=awaitcrypto.keyStorage.setItem(keys.publicKey);// get list of keysconstindexes=awaitcrypto.keyStorage.keys();console.log(indexes);// ['private-3239...', 'public-3239...']// get key by idconstprivateKey=awaitcrypto.keyStorage.getItem("private-3239...");// signing dataconstsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},key,Buffer.from("Message here"));console.log("Signature:",Buffer.from(signature).toString("hex"));

Certificate Storage

The CryptoCertificateStorage interface enables you to persist and retrieve certificates across sessions.

Add certificate to storage and use it for verification of signed data

constX509_RAW=Buffer.from("308203A830820290A003020...","hex");constx509=awaitcrypto.certStorage.importCert("raw",X509_RAW,{name: "RSASSA-PKCS1-v1_5",hash: "SHA-256"},["verify"]);console.log(x509.subjectName);// C=name, O=...constindex=awaitcrypto.certStorage.setItem(x509);console.log(index);// x509-2943...constok=awaitcrypto.subtle.verify({name: "RSASSA-PKCS1-v1_5"},x509.publicKey,SIGNATURE,MESSAGE);console.log("Signature:",ok);

Bug Reporting

Please report bugs either as pull requests or as issues in the issue tracker. Backwater has a full disclosure vulnerability policy. Please do NOT attempt to report any security vulnerability in this code privately to anybody.

Related

About

A WebCrypto Polyfill for Node in typescript built on PKCS#11.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Repository files navigation

node-webcrypto-p11

licensetestCoverage Statusnpm version

NPM

We wanted to be able to write Javascript that used crypto on both the client and the server but we did not want to rely on Javascript implementations of crypto. The only native cryptography availible in browser is Web Crypto, this resulted in us creating a native polyfil for WebCrypto based on Openssl.

Our project also required us to utilize Hardware Security Modules and smart cards on the server side so we made a library called Graphene that made it possible to use PKCS#11 devices from within Nodejs.

We then thought that in most cases others did not care about interacting with the token directly and would prefer a higher level API they were already familiar with. We hope that library is node-webcrypto-p11, if you have code based on WebCrypto (for example the excelent js-jose) with only a change in a constructor you can work with PKCS#11 devices.

For example to generate a key you this is all it takes:

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "RSASSA-PKCS1-v1_5",modulusLength: 1024,publicExponent: newUint8Array([1,0,1]),hash: {name: "SHA-1",},},true,["sign","verify"]);

WARNING

At this time this solution should be considered suitable for research and experimentation, further code and security review is needed before utilization in a production application.

Algorithms

Supported algorithms

Algorithm namegenerateKeydigestexport/importsign/verifyencrypt/decryptwrapKey/unwrapKeyderive
SHA-1X
SHA-256X
SHA-384X
SHA-512X
RSASSA-PKCS1-v1_5XXX
RSAES-PKCS1-v1_5 2XXXX
RSA-PSSXXX
RSA-OAEPXXXX
AES-CBCXXXX
AES-ECB 2XXXX
AES-GCMXXXX
ECDSA 1XXX
ECDH 2XXX
HMACXXX

1 Mechanism supports extended list of named curves P-256, P-384, P-521, and K-256

2 Mechanism is not defined by the WebCrypto specifications. Use of mechanism in a safe way is hard, it was added for the purpose of enabling interoperability with an existing system. We recommend against its use unless needed for interoperability.

Installation

NPM

npm install node-webcrypto-p11

Clone Repository

git clone https://github.com/PeculiarVentures/node-webcrypto-p11
cd node-webcrypto-p11

Install SoftHSM2

Install

npm install

Test

mocha

Configuration

Tests and samples use a file called config.js file for PKCS11 module configuration. The format of which is:

module.exports={library: "path/to/pkcs11/module.so",name: "Name of PKCS11 module",slot: 0,// number of slotpin: "password"readWrite: true,vendors: []// list of vendor files, optional}

Threats

The threat model is defined in terms of what each possible attacker can achieve. The list is intended to be exhaustive.

Assumptions

TODO: ADD ASSUMPTIONS

Threats From A node-webcrypto-p11 Defect

node-webcrypto-p11 handles ciphertext, cleartext, and sessions. A defect in this library could result in these values being exposed to an attacker. Examples of such defects include:

  • Buffer, Integer or other overflow related defects,
  • Parsing errors,
  • Logic errors,
  • Weak user seperation or permissions.

Threats From A PKCS#11 defect

PKCS#11 implementations are often old, poorly maintained and incomplete. This can obviously lead to defects. Defects in the PKCS#11 implementation can result in:

  • Weakly implemented or applied cryptographic primitives,
  • Leaked sessions or secrets that expose use of the key,
  • Leaked cryptographic key material.

Threats From Weak Cryptography

Secure use of cryptography requires the implementor to understand the security properties of a given algorithm as well as how to use it in a secure construction.

Additionally this library exposes some algorithms that may have known weakneses or are simply too old to be used safely.

Threats From Improper Use Of Cryptography

It is easy to apply cryptography but hard to apply it correctly. Algorithms each have their own security properties and appropriate constructions. The consumer of this library is responsible for understanding how to use the exposed algorithms securely.

Generates ECDSA key pair with named curve P-256 and signs/verifies text message.

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);constsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},keys.privateKey,Buffer.from("Hello world!"));console.log(`Signature: ${signature}`);constok=awaitcrypto.subtle.verify({name: "ECDSA",hash: "SHA-256"},keys.publicKey,signature,Buffer.from("Hello world!"));console.log(`Verification: ${ok}`);

Key Storage

The CryptoKeyStorage interface enables you to persist and retrieve keys across sessions.

Generate a cryptographic key and store it

constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);// set private key to storageconstprivateKeyID=awaitcrypto.keyStorage.setItem(keys.privateKey);// set public key to storageconstpublicKeyID=awaitcrypto.keyStorage.setItem(keys.publicKey);// get list of keysconstindexes=awaitcrypto.keyStorage.keys();console.log(indexes);// ['private-3239...', 'public-3239...']// get key by idconstprivateKey=awaitcrypto.keyStorage.getItem("private-3239...");// signing dataconstsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},key,Buffer.from("Message here"));console.log("Signature:",Buffer.from(signature).toString("hex"));

Certificate Storage

The CryptoCertificateStorage interface enables you to persist and retrieve certificates across sessions.

Add certificate to storage and use it for verification of signed data

constX509_RAW=Buffer.from("308203A830820290A003020...","hex");constx509=awaitcrypto.certStorage.importCert("raw",X509_RAW,{name: "RSASSA-PKCS1-v1_5",hash: "SHA-256"},["verify"]);console.log(x509.subjectName);// C=name, O=...constindex=awaitcrypto.certStorage.setItem(x509);console.log(index);// x509-2943...constok=awaitcrypto.subtle.verify({name: "RSASSA-PKCS1-v1_5"},x509.publicKey,SIGNATURE,MESSAGE);console.log("Signature:",ok);

Bug Reporting

Please report bugs either as pull requests or as issues in the issue tracker. Backwater has a full disclosure vulnerability policy. Please do NOT attempt to report any security vulnerability in this code privately to anybody.

Related

About

A WebCrypto Polyfill for Node in typescript built on PKCS#11.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Repository files navigation

node-webcrypto-p11

licensetestCoverage Statusnpm version

NPM

We wanted to be able to write Javascript that used crypto on both the client and the server but we did not want to rely on Javascript implementations of crypto. The only native cryptography availible in browser is Web Crypto, this resulted in us creating a native polyfil for WebCrypto based on Openssl.

Our project also required us to utilize Hardware Security Modules and smart cards on the server side so we made a library called Graphene that made it possible to use PKCS#11 devices from within Nodejs.

We then thought that in most cases others did not care about interacting with the token directly and would prefer a higher level API they were already familiar with. We hope that library is node-webcrypto-p11, if you have code based on WebCrypto (for example the excelent js-jose) with only a change in a constructor you can work with PKCS#11 devices.

For example to generate a key you this is all it takes:

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "RSASSA-PKCS1-v1_5",modulusLength: 1024,publicExponent: newUint8Array([1,0,1]),hash: {name: "SHA-1",},},true,["sign","verify"]);

WARNING

At this time this solution should be considered suitable for research and experimentation, further code and security review is needed before utilization in a production application.

Algorithms

Supported algorithms

Algorithm namegenerateKeydigestexport/importsign/verifyencrypt/decryptwrapKey/unwrapKeyderive
SHA-1X
SHA-256X
SHA-384X
SHA-512X
RSASSA-PKCS1-v1_5XXX
RSAES-PKCS1-v1_5 2XXXX
RSA-PSSXXX
RSA-OAEPXXXX
AES-CBCXXXX
AES-ECB 2XXXX
AES-GCMXXXX
ECDSA 1XXX
ECDH 2XXX
HMACXXX

1 Mechanism supports extended list of named curves P-256, P-384, P-521, and K-256

2 Mechanism is not defined by the WebCrypto specifications. Use of mechanism in a safe way is hard, it was added for the purpose of enabling interoperability with an existing system. We recommend against its use unless needed for interoperability.

Installation

NPM

npm install node-webcrypto-p11

Clone Repository

git clone https://github.com/PeculiarVentures/node-webcrypto-p11
cd node-webcrypto-p11

Install SoftHSM2

Install

npm install

Test

mocha

Configuration

Tests and samples use a file called config.js file for PKCS11 module configuration. The format of which is:

module.exports={library: "path/to/pkcs11/module.so",name: "Name of PKCS11 module",slot: 0,// number of slotpin: "password"readWrite: true,vendors: []// list of vendor files, optional}

Threats

The threat model is defined in terms of what each possible attacker can achieve. The list is intended to be exhaustive.

Assumptions

TODO: ADD ASSUMPTIONS

Threats From A node-webcrypto-p11 Defect

node-webcrypto-p11 handles ciphertext, cleartext, and sessions. A defect in this library could result in these values being exposed to an attacker. Examples of such defects include:

  • Buffer, Integer or other overflow related defects,
  • Parsing errors,
  • Logic errors,
  • Weak user seperation or permissions.

Threats From A PKCS#11 defect

PKCS#11 implementations are often old, poorly maintained and incomplete. This can obviously lead to defects. Defects in the PKCS#11 implementation can result in:

  • Weakly implemented or applied cryptographic primitives,
  • Leaked sessions or secrets that expose use of the key,
  • Leaked cryptographic key material.

Threats From Weak Cryptography

Secure use of cryptography requires the implementor to understand the security properties of a given algorithm as well as how to use it in a secure construction.

Additionally this library exposes some algorithms that may have known weakneses or are simply too old to be used safely.

Threats From Improper Use Of Cryptography

It is easy to apply cryptography but hard to apply it correctly. Algorithms each have their own security properties and appropriate constructions. The consumer of this library is responsible for understanding how to use the exposed algorithms securely.

Generates ECDSA key pair with named curve P-256 and signs/verifies text message.

const{ Crypto }=require("node-webcrypto-p11");constconfig={library: "/usr/local/lib/softhsm/libsofthsm2.so",name: "SoftHSM v2.0",slot: 0,readWrite: true,pin: "12345",};constcrypto=newCrypto(config);constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);constsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},keys.privateKey,Buffer.from("Hello world!"));console.log(`Signature: ${signature}`);constok=awaitcrypto.subtle.verify({name: "ECDSA",hash: "SHA-256"},keys.publicKey,signature,Buffer.from("Hello world!"));console.log(`Verification: ${ok}`);

Key Storage

The CryptoKeyStorage interface enables you to persist and retrieve keys across sessions.

Generate a cryptographic key and store it

constkeys=awaitcrypto.subtle.generateKey({name: "ECDSA",namedCurve: "P-256"},false,["sign","verify"]);// set private key to storageconstprivateKeyID=awaitcrypto.keyStorage.setItem(keys.privateKey);// set public key to storageconstpublicKeyID=awaitcrypto.keyStorage.setItem(keys.publicKey);// get list of keysconstindexes=awaitcrypto.keyStorage.keys();console.log(indexes);// ['private-3239...', 'public-3239...']// get key by idconstprivateKey=awaitcrypto.keyStorage.getItem("private-3239...");// signing dataconstsignature=awaitcrypto.subtle.sign({name: "ECDSA",hash: "SHA-256"},key,Buffer.from("Message here"));console.log("Signature:",Buffer.from(signature).toString("hex"));

Certificate Storage

The CryptoCertificateStorage interface enables you to persist and retrieve certificates across sessions.

Add certificate to storage and use it for verification of signed data

constX509_RAW=Buffer.from("308203A830820290A003020...","hex");constx509=awaitcrypto.certStorage.importCert("raw",X509_RAW,{name: "RSASSA-PKCS1-v1_5",hash: "SHA-256"},["verify"]);console.log(x509.subjectName);// C=name, O=...constindex=awaitcrypto.certStorage.setItem(x509);console.log(index);// x509-2943...constok=awaitcrypto.subtle.verify({name: "RSASSA-PKCS1-v1_5"},x509.publicKey,SIGNATURE,MESSAGE);console.log("Signature:",ok);

Bug Reporting

Please report bugs either as pull requests or as issues in the issue tracker. Backwater has a full disclosure vulnerability policy. Please do NOT attempt to report any security vulnerability in this code privately to anybody.

Related

About

A WebCrypto Polyfill for Node in typescript built on PKCS#11.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages