trust_lists library
Opt-in trust anchors for signature validation: the EU trusted lists (LOTL + Member State lists, fetched and signature-verified through a host transport) and a loader for an Adobe Approved Trust List file the host supplies.
The core library ships no roots. This library ships the mechanism -
XML-signature verification of the lists, the pinned LOTL signers, and
the parsers - so a host can build a PdfTrustStore from the official
sources at run time or from a snapshot it refreshed with
tool/trust_lists/refresh_trust_lists.dart. Pure Dart, no I/O.
Classes
- PdfAatl
- Where Adobe publishes the AATL for Acrobat, and the root its signature chains to.
- PdfAatlSnapshot
- The trust anchors read from an AATL file.
- PdfEuLotl
- The EU LOTL location and the certificates allowed to sign it.
- PdfEuTrustListSnapshot
- A verified set of EU trust anchors, with the per-list problems met while building it.
- PdfTrustListEntry
- One qualified CA service certificate from a Member State list.
- PdfTrustListPointer
- A pointer in the LOTL to one Member State's list.
- PdfTrustLists
- Builders for trust stores from the supported public lists.
- XmlLiteDocument
- A parsed document: top-level comments/PIs around the single root.
- XmlLiteElement
- An element: its qualified name, attributes (namespace declarations included, as written) and children.
- XmlSignatureVerification
- The outcome of verifyEnvelopedXmlSignature.
Enums
- XmlC14nMethod
- Canonical XML flavours used by XML signatures.
Constants
- pdfTrustListExpiryGrace → const Duration
- How long past its NextUpdate a trusted list is still accepted. A list that is not reissued by its NextUpdate is expired (ETSI TS 119 612 §5.3.14) and may still carry trust anchors that have since been withdrawn; the grace only absorbs clock skew and publication lag.
Functions
-
canonicalizeDocument(
XmlLiteDocument document, {required XmlC14nMethod method, XmlLiteElement? omit, List< String> inclusivePrefixes = const []}) → Uint8List -
Canonicalizes the whole
document(comments dropped), leaving out the subtreeomit- the enveloped-signature transform. -
canonicalizeElement(
XmlLiteElement element, {required XmlC14nMethod method, XmlLiteElement? omit, List< String> inclusivePrefixes = const []}) → Uint8List -
Canonicalizes the subtree rooted at
elementas a document subset: the namespaces it inherits from its ancestors are rendered on it as needed. -
fetchAatl(
{required Future< Uint8List> fetch(Uri url), DateTime? now, Duration maxAge = PdfAatl.maxAge, String rootFingerprint = PdfAatl.adobeRootFingerprint}) → Future<PdfAatlSnapshot> -
Downloads the AATL from PdfAatl.url through the host's
fetch(the library performs no I/O), verifies that its signature chains to Adobe Root CA G2 and that it was signed withinmaxAgeofnow, and returns its trusted roots. Throws FormatException when verification fails. -
fetchEuTrustedLists(
{required PdfTrustListFetch fetch, Set< String> pinnedSigners = PdfEuLotl.signerFingerprints, DateTime? now}) → Future<PdfEuTrustListSnapshot> -
Fetches the LOTL and every Member State list through
fetch, verifies each signature (the LOTL againstpinnedSigners, each national list against the certificates the LOTL names for it) and collects the qualified CA anchors. A list that fails to download or verify is skipped and reported in PdfEuTrustListSnapshot.problems - including one that is expired atnow; a LOTL that fails or is expired is fatal (thrown). The snapshot's PdfEuTrustListSnapshot.expires is the earliest NextUpdate of the lists it was built from. -
parseAatlSecuritySettings(
Uint8List file, {bool verifySignature = true, String rootFingerprint = PdfAatl.adobeRootFingerprint, Duration? maxAge, DateTime? now}) → PdfAatlSnapshot -
Reads the trusted roots out of an AATL
.acrobatsecuritysettingsfile. -
parseEuLotl(
Uint8List bytes, {Set< String> pinnedSigners = PdfEuLotl.signerFingerprints, DateTime? now}) → ({DateTime? issued, DateTime? nextUpdate, List<PdfTrustListPointer> pointers, int? sequence}) -
Parses and verifies the LOTL: its signature must verify, its signing
certificate must be one of
pinnedSigners(SHA-256 fingerprints), and it must not be expired atnow(NextUpdate + pdfTrustListExpiryGrace). Returns the pointers to the Member State XML lists. -
parseEuTrustedList(
Uint8List bytes, PdfTrustListPointer pointer, {DateTime? now}) → ({List< PdfTrustListEntry> entries, DateTime nextUpdate}) -
Parses and verifies one Member State list against its LOTL
pointer: the list's signature must verify with one of the pointer's certificates, and it must not be expired atnow. Returns the active qualified CA service certificates and the list's NextUpdate. -
verifyEnvelopedXmlSignature(
XmlLiteDocument document) → XmlSignatureVerification -
Verifies the enveloped signature (a
ds:Signaturechild of the root) ofdocument. At least one reference must cover the whole document (URI=""or the root element's Id, with the enveloped-signature transform), so a signature over only its own properties is refused.
Typedefs
-
PdfTrustListFetch
= Future<
Uint8List> Function(Uri url) -
Downloads
urland returns the body; throws on failure. The host's transport (the library performs no I/O).