ããã¯ãUbuntu OnlineãFedora OnlineãWindows ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒããŸã㯠MAC OS ãªã³ã©ã€ã³ ãšãã¥ã¬ãŒã¿ãŒãªã©ã®è€æ°ã®ç¡æãªã³ã©ã€ã³ ã¯ãŒã¯ã¹ããŒã·ã§ã³ã® XNUMX ã€ã䜿çšããŠãOnWorks ç¡æãã¹ãã£ã³ã° ãããã€ããŒã§å®è¡ã§ããã³ãã³ã cdigidoc ã§ãã
ããã°ã©ã ïŒ
NAME
cdigidoc - XAdES 圢åŒã®ãã¡ã€ã«ã®èªã¿åããããžã¿ã«çœ²åãæ€èšŒãããã³ãã¡ã€ã«ã®æå·åã埩å·å
XMLENC圢åŒ
SYNOPSIS
cdigidoc [ -ã« ] [ -ã§ã ] [ -config
]
DESCRIPTION
cdigidoc CDigiDoc ã©ã€ãã©ãªã«ã³ãã³ã ã©ã€ã³ ã€ã³ã¿ãŒãã§ã€ã¹ãæäŸãããŠãŒãã£ãªãã£ã§ãã
ããã¯ãäœæããæ©èœãæäŸãã C ããã°ã©ãã³ã°èšèªã®ã©ã€ãã©ãªã§ãã
ãµããŒããããŠãã DigiDoc 圢åŒã®ãã¡ã€ã«ãã¹ããŒã ã«ãŒãã䜿çšã㊠DigiDoc ãã¡ã€ã«ã«çœ²åãããã
ãµããŒããããŠããä»ã®æå·ããŒã¯ã³ãã¿ã€ã ããŒã¯ãšæå¹æ§ç¢ºèªãããžã¿ã«ã«è¿œå ããŸã
OCSP ãããã³ã«ã䜿çšãã眲åãããžã¿ã«çœ²åã®æ€èšŒãããžã¿ã«æå·åãš
DigiDoc ãã¡ã€ã«ã埩å·åããŸãã cdigidoc ãŠãŒãã£ãªãã£ã CGI ããã°ã©ã ãšããŠäœ¿çšããããšãã§ããŸãã
JDigiDoc ã©ã€ãã©ãªãç°¡åã«äœ¿çšã§ããªãç°å¢ã§äœæããã Web ã¢ããªã±ãŒã·ã§ã³ããŸãã¯
ããžã¿ã«çœ²åæ©èœã䜿çšããã«ã¯ãDigiDocService Web ãµãŒãã¹ãåŒã³åºããŸãã
å®å šãªããã¥ã¡ã³ãã«ã€ããŠã¯ã次ãåç §ããŠãã ããã
https://svn.eesti.ee/projektid/idkaart_public/branches/3.6/libdigidoc/doc/SK-CDD-PRG-GUIDE.pdf
XAdES圢åŒ
http://www.w3.org/TR/XAdES
XML-ENC圢åŒ
http://www.w3.org/TR/xmlenc-core
OPTIONS
-ïŒã -ãã«ã
ã³ãã³ãæ§æã«é¢ãããã«ãã衚瀺ããŸãã
-ã®
å ¥åãã¡ã€ã«åãæå®ããŸãã ãã¡ã€ã«ãžã®ãã«ãã¹ãæž¡ãããšããå§ãããŸã
ãã®ãã©ã¡ãŒã¿ã§ã
-å€
æ°ããäœæãŸãã¯å€æŽãããããã¥ã¡ã³ãããã¡ã€ã«ã«ä¿åããŸãã
-config
CDigiDoc æ§æãã¡ã€ã«åãæå®ããŸãã æå®ããªããŸãŸã«ããå Žåã
æ§æãã¡ã€ã«ã¯ããã©ã«ãã®å Žæããæ€çŽ¢ãããŸãã
-ãã§ãã¯èšŒææž
蚌ææžã®æå¹æ§ã¹ããŒã¿ã¹ã確èªããŸãã éžæãã蚌ææžã®ç¢ºèªã«äœ¿çšãããŸã
æå¹; 蚌ææžã® CA ã® OCSP ã¬ã¹ãã³ããã OCSP å¿çãè¿ããŸãã ããŒã
ã³ãã³ããçŸåšãã¹ããããŠããªãããšã瀺ããŸãã 蚌ææžãæå¹ã§ããã°ã
æ»ãã³ãŒã (RC) ã®å€ã¯ 0 ã§ãã
-new [ãã©ãŒããã] [ããŒãžã§ã³]
æå®ããã圢åŒãšããŒãžã§ã³ã§æ°ãã digidoc ã³ã³ãããäœæããŸãã çŸåš
CDigiDoc ã©ã€ãã©ãªã® digidoc 圢åŒã¯ DIGIDOC-XML ã§ãããã©ã«ãã®ããŒãžã§ã³ã¯ 1.3 (ææ°) ã§ãã
ãã®ã³ãã³ãã§ãªãã·ã§ã³ã®ãã©ã¡ãŒã¿ version - ã䜿çšãããšã
代æ¿ããŒãžã§ã³ãäœæãããŸãã 泚: å€ã SK-XML 圢åŒã®ã¿ããµããŒããããŠããŸãã
äžäœäºææ§ã®ããã
-è¿œå [ ][ ã
æ°ããããŒã¿ ãã¡ã€ã«ã digidoc ããã¥ã¡ã³ãã«è¿œå ããŸãã digidoc ãååšããªãå Žåã¯äœæããŸã
XNUMX ã€ã¯ããã©ã«ãã®åœ¢åŒã§ãã
å ¥åãã¡ã€ã« (å¿ é )
ããŒã¿ãã¡ã€ã«ã®ååãæå®ããŸãïŒãã«ãã¹ãå«ããããšããå§ãããŸãïŒ
ãã®ãã©ã¡ãŒã¿ã§ã¯; DigiDoc ã³ã³ããã«æžã蟌ããšãã«ãã¹ãåé€ããã
ãã¡ã€ã«ïŒã
MIME ã¿ã€ã (å¿ é )
ãtext/plainããªã©ã®å ã®ãã¡ã€ã«ã® MIME ã¿ã€ããè¡šããŸãã
ãã¢ããªã±ãŒã·ã§ã³/mswordãã
å 容å
å ã®ãã¡ã€ã«ãã³ã³ããã«ã©ã®ããã«åã蟌ãŸããŠããããåæ ããŸãã
EMBEDDED_BASE64 (ããã©ã«ãã§äœ¿çš)ã 以åã®ããŒãžã§ã³ã§ã¯ cdigidoc ãèš±å¯ãããŠããŸãã
çŽç²ãª XML ãŸãã¯ããã¹ãã«çœ²åããã«ã¯ãã³ã³ãã³ã ã¿ã€ã EMBEDDED ã䜿çšããŸãã
æåã»ãã
UTF-8 ãšã³ã³ãŒãã£ã³ã°ããµããŒããããŠãããããã©ã«ãã§äœ¿çšãããŸãã
-ãµã€ã³[[[ãããã§ã¹ã] [[éœåž] [å·] [éµäŸ¿çªå·] [åœ]] [ã¹ããã(0)][ocsp(1)] [ããŒã¯ã³-
ã¿ã€ã(PKCS11)] [pkcs12ãã¡ã€ã«å]]
digidoc ããã¥ã¡ã³ãã«ããžã¿ã«çœ²åãè¿œå ããŸãã 以äžã§äœ¿çšã§ããŸã
ãã©ã¡ãŒã¿ïŒ
ãã³ã³ãŒã
ãšã¹ããã¢ã® ID ã«ãŒãã®å Žåãããžã¿ã«çœ²åã«ã¯ PIN ã³ãŒã 2 ã䜿çšãããŸãã ããã
ãœãããŠã§ã¢ ããŒã¯ã³ (PKCS#12 ãã¡ã€ã«) ã§çœ²åããPKCS#12 ã®ãã¹ã¯ãŒãã䜿çšããŸãã
ãã¡ã€ã«ãããã«å ¥åããå¿ èŠããããŸãã
ãããã§ã¹ã
眲åè ã®åœ¹å²ãŸãã¯æ±ºè°
city 眲åãäœæãããåž
state 眲åãäœæãããå·ãŸãã¯ç
zip 眲åãäœæãããå Žæã®éµäŸ¿çªå·
åœ
åç£åœã ISO 3166 ã¿ã€ãã® 2 æåã®åœã³ãŒãã䜿çšãããŸã (äŸ:
EEïŒ
ã¹ããã ã¹ããŒãã«ãŒãäžã®çœ²åè ã®ç§å¯éµã®ã¹ãããã®èå¥åã æäœæ
ããšãã°ãåäžã®ãšã¹ãã㢠ID ã«ãŒãã䜿çšãããšããã®çœ²åããŒãèŠã€ããããšãã§ããŸãã
ã¹ããã 1 - ããã©ã«ãã§äœ¿çšãããŸãã ã©ã€ãã©ãªã¯ããã€ãã®ä»®å®ãç«ãŠãŸã
PKCS#11 ãã©ã€ããŒãšã«ãŒã ã¬ã€ã¢ãŠãã«ã€ããŠ:
- ã«ãŒãã«çœ²åããŒãèªèšŒããŒããã
- ããŒãšèšŒææžã®äž¡æ¹ã XNUMX ã€ã®ã¹ãããã«ãããŸã
- 1 ã€ã®çœ²åããŒãš 1 ã€ã®èªèšŒããŒãªã©ãå€æ°ã®ããŒãããå Žåã¯ã
ç°ãªãã¹ãããã«ãããŸã
- 察å¿ãã蚌ææžãæã€çœ²åããŒã䜿çšããŠçœ²åã§ããŸãã
ãNonRepudiationãããããèšå®ãããŠããŸãã å¥ã®ã¹ããããæå®ããå¿ èŠãããå ŽåããããŸãã
ããšãã°ãåãäžã§è€æ°ã®ã¹ããŒã ã«ãŒããæäœããå Žåã«äœ¿çšãããŸãã
ã·ã¹ãã ã 眲åäžã«ã¹ããããæå®ããå¿ èŠãããå Žåã¯ã5
以åã®ãªãã·ã§ã³ã®ãã©ã¡ãŒã¿ (ãããã§ã¹ããéœåžãå·ãéµäŸ¿çªå·ãåœ) ã¯æ¬¡ã®ããã«ããå¿ èŠããããŸãã
æåã«å ¥åããŸã (é©åãªããŒã¿ãå ¥åããããå€ããªãå Žå㯠"" ãšããŠå ¥åããŸã)ã
ocsp OCSP 確èªã眲åã«è¿œå ãããã©ãããæå®ããŸãã
äœæãããŠããŸãã å¯èœãªå€ã¯ 0 ã§ã - 確èªã¯è¿œå ãããŸããã 1 -
確èªãè¿œå ãããŸãã ããã©ã«ãã§ã¯ãå€ã¯ 1 ã«èšå®ãããŠããŸãã ãã©ã¡ãŒã¿å€ 0
æè¡çœ²åãäœæãããšãã«äœ¿çšã§ããŸãã ãã¯ãã«ã«ã·ã°ããã£ã¯ã
OCSP 確èªãã¿ã€ã ã¹ã¿ã³ãå€ãå«ãŸãªã眲åã
ããŒã¯ã³ã®çš®é¡
䜿çšãã眲åããŒã¯ã³ã®ã¿ã€ããæå®ããŸãã
- PKCS11 ã®ããã©ã«ãå€ã ã¹ããŒãã«ãŒããŸãã¯ãœãããŠã§ã¢ pkcs11 ããŒã¯ã³ã䜿çšãã眲å
- Windows ãã©ãããã©ãŒã äžã® CNG ã¯çœ²åã« CSP/CNG ã䜿çšããŸã
- PKCS12 ã¯ãPKCS#12 ã㌠ã³ã³ããã䜿çšããŠçœ²åããŸãããã®ã³ã³ããã¯ã
次ã®ãã©ã¡ãŒã¿
pkcs12 ãã¡ã€ã«å
眲åã«äœ¿çšããã PKCS#12 ã㌠ã³ã³ãã ãã¡ã€ã«ã®ååã
-ããããµã€ã³[[ (EE)] [ ïŒESTïŒæ±éšåºæºæïŒ] [ (ãã¹ã)]
[ ][ ]]
Mobile-ID ãš DigiDocService ã䜿çšããŠãddoc ãã¡ã€ã«ã®ã¢ãã€ã«çœ²åãåŒã³åºããŸãã ã¢ãã€ã«-
ID ã¯ãã¢ãã€ã«èªèšŒãš
ããžã¿ã«çœ²åãçŸåšãã¹ãŠã®ãšã¹ããã¢ãšäžéšã®ãªãã¢ãã¢ã®ã¢ãã€ã«ã§ãµããŒããããŠããŸã
ãªãã¬ãŒã¿ãŒã Mobile-ID ãŠãŒã¶ãŒã¯ãç§å¯éµãå ¥ã£ãç¹å¥ãª SIM ã«ãŒããååŸããŸãã
眲åãããããã·ã¥ã¯ GSM ãããã¯ãŒã¯çµç±ã§é»è©±æ©ã«éä¿¡ããããŠãŒã¶ãŒã¯æ¬¡ã®ããšãè¡ãå¿ èŠããããŸãã
PIN ã³ãŒããå ¥åããŠçœ²åããŸãã 眲åãããçµæã¯ç¡ç·ã§è¿éãããŸãã
DigiDocService 㯠SOAP ããŒã¹ã® Web ãµãŒãã¹ã§ããããµãŒãã¹ãžã®ã¢ã¯ã»ã¹ã¯ IP ããŒã¹ã§ããã
DigiDocService ã®ãããã€ããŒãšã®æžé¢ã«ããå¥çŽãå¿ èŠã§ãã ã¢ãã€ã«IDã䜿ããŸã
次ã®ãã©ã¡ãŒã¿ã䜿çšããŠçœ²åããŸãã
é»è©±çªå·
åœã³ãŒãã +xxxx ã®åœ¢åŒã®çœ²åè ã®é»è©±çªå· (
äŸ +3706234566)
ã³ãŒãããš
眲åè ã®èå¥çªå· (å人ã®åœæ° ID çªå·)ã
åœ
åç£åœã ISO 3166 ã¿ã€ãã® 2 æåã®åœã³ãŒãã䜿çšãããŸã (äŸ:
ããã©ã«ãã¯EEã§ã)
lang æºåž¯é»è©±ã®ãŠãŒã¶ãŒ ãã€ã¢ãã°ã®èšèªã 3 æåã®å€§æåã®é åèª
䜿çšãããŠããŸã (äŸ: ããã©ã«ã㯠EST)
ãµãŒãã¹
ãµãŒãã¹ã®åå - ã¢ããªã±ãŒã·ã§ã³ãããã€ããŒãšäºåã«åæãããã®
DigiDocService ãªãã¬ãŒã¿ãŒã æå€§é· â 20 æåã (äŸ: ããã©ã«ãã¯
ãã¹ãïŒ
ãããã§ã¹ã
眲åè ã®åœ¹å²ãŸãã¯æ±ºè°
city 眲åãäœæãããåž
state 眲åãäœæãããå·ãŸãã¯ç
zip 眲åãäœæãããå Žæã®éµäŸ¿çªå·
-list èªã¿èŸŒãã ã°ããã® DigiDoc ããã¥ã¡ã³ãã®ããŒã¿ ãã¡ã€ã«ãšçœ²åæ å ±ã衚瀺ããŸãã
ãã¹ãŠã®çœ²åãæ€èšŒããŸãã
Digidoc ã³ã³ãã ããŒã¿ã次ã®åœ¢åŒã§è¿ããŸãã |
ãã¹ãŠã®ããŒã¿ ãã¡ã€ã«ã®ãªã¹ã (圢åŒ: DataFile |) | |
| |
ãã¹ãŠã®çœ²åã®ãªã¹ã (ååšããå Žå)ã圢åŒ: Signature |
èå¥å> | |
|
眲åè ã®èšŒææžæ å ±ã
OCSP ã¬ã¹ãã³ã蚌ææžæ å ±
-確èª
眲åæ€èšŒçµæãè¿ããŸã (眲åãååšããå Žå)ã
眲å | |
å人ã³ãŒã> | |
眲åè ã®èšŒææžãš OCSP ã¬ã¹ãã³ããŒèšŒææžã®æ å ±ãè¿ããŸãã
-ãšãã¹
éžæããããŒã¿ ãã¡ã€ã«ã DigiDoc ã³ã³ããããæœåºãããã¡ã€ã«ã«ä¿åããŸãã
ããŒã¿ãã¡ã€ã«IDã¯ãå éšããæœåºãããããŒã¿ãã¡ã€ã«ã®IDãè¡šããŸãã
DigiDoc ã³ã³ãã (äŸ: D0ãD1âŠ)ã åºåãã¡ã€ã«ã¯åºåã®ååãè¡šããŸã
ãã¡ã€ã«ã«ãœãããŠã§ã¢ãæå®ããå¿ èŠããããŸãã
-denc-list
èªã¿åã£ãæå·åææžã®æå·åããŒã¿ãšåä¿¡è æ å ±ã衚瀺ããŸã
ã€ã³ã
-encrecv [åä¿¡è ] [ããŒå] [ãã£ãªãŒãããããŒå]
æ°ããåä¿¡è 蚌ææžãšãã®ä»ã®ã¡ã¿ããŒã¿ãæå·åãããããã¥ã¡ã³ãã«è¿œå ããŸãã
蚌ææžãã¡ã€ã« (å¿ é ) ã¯ãå ¬éããŒã³ã³ããŒãã³ãã®å ãšãªããã¡ã€ã«ãæå®ããŸãã
ããŒã¿ãæå·åããããã«ååŸãããŸãã 埩å·åã¯æ¬¡ã®æ¹æ³ã§ã®ã¿å®è¡ã§ããŸãã
ãã®èšŒææžã«å¯Ÿå¿ããç§å¯ããŒã å ¥å蚌ææžãã¡ã€ã«
æå·åã¯ãã¡ã€ã« ã·ã¹ãã ããååŸããå¿ èŠããããŸã (PEM ãšã³ã³ãŒãã£ã³ã°ããµããŒããããŠããŸã)ã å¯èœ
蚌ææžãã¡ã€ã«ãååŸã§ãããœãŒã¹ã«ã¯æ¬¡ã®ãã®ããããŸãã Windows
蚌ææžã¹ã㢠(ãä»ã®äººã)ãLDAP ãã£ã¬ã¯ããªãã¹ããŒã ã«ãŒãå ã® ID ã«ãŒã
èªè ã ããšãã°ããšã¹ããã¢ã® ID ã«ãŒãææè ã®èšŒææžãã¡ã€ã«ã¯æ¬¡ã®ããã«ãªããŸãã
ldap://ldap.sk.ee ã® LDAP ãã£ã¬ã¯ããªããååŸãããŸãã ã¯ãšãªã¯æ¬¡ã®å Žæã§è¡ãããšãã§ããŸã
Web ãã©ãŠã¶ (IE) ãã次ã®åœ¢åŒã§ã¢ã¯ã»ã¹ããŸãã
ldap://ldap.sk.ee:389/c=EE??sub?(serialNumber= x) ã·ãªã¢ã«çªå·ã¯
åä¿¡è ã®å人èå¥çªå· (äŸ: 38307240240)ã ãã®ä»ã®ãã©ã¡ãŒã¿
次ã®ãšããã§ãã
åå人
æå®ããªãå Žåãããã°ã©ã 㯠CN å€ãå²ãåœãŠãŸãã
蚌ææžãæåã®ãã©ã¡ãŒã¿ãšããŠæž¡ãããŸãã ããã¯åŸã§ã³ãã³ããšããŠäœ¿çšãããŸã
ããŒãšã¹ããŒã ã«ãŒãã䜿çšãããåä¿¡è ãèå¥ããããã®åç·ãªãã·ã§ã³
ããŒã¿ã埩å·åããŸãã 泚: ãã®ãã©ã¡ãŒã¿ã¯ãªãã·ã§ã³ã§ããã
åä¿¡è ã®èšŒææžãã CN å€å šäœãæž¡ãããšããå§ãããŸã
ç¹ã«è€æ°ã®çžæãæ±ãå Žåãããã§ã¯åä¿¡è èå¥åãšããŠäœ¿çšããŸãã
åä¿¡è ã
ããŒå
ãµãèŠçŽ ã㌠ãªããžã§ã¯ããããé©åã«èå¥ããããã«è¿œå ã§ããŸãã
ãªãã·ã§ã³ã§ãããé©åãªåä¿¡è ã®ããŒãŸãã¯è¡šç€ºãæ€çŽ¢ããããã«äœ¿çšã§ããŸãã
ã¢ããªã±ãŒã·ã§ã³å ã®ããŒã¿ã
ãã£ãªãŒããŒå
ãµãèŠçŽ ã㌠ãªããžã§ã¯ããããé©åã«èå¥ããããã«è¿œå ã§ããŸãã
ãªãã·ã§ã³ã§ãããé©åãªåä¿¡è ã®ããŒãŸãã¯è¡šç€ºãæ€çŽ¢ããããã«äœ¿çšã§ããŸãã
ã¢ããªã±ãŒã·ã§ã³å ã®ããŒã¿ã
-æå·å-sk
æå®ãããå ¥åãã¡ã€ã«ã®ããŒã¿ãæå·åããå®æããæå·åãã¡ã€ã«ãæžã蟌ã¿ãŸãã
ãã¡ã€ã«å ã®ææžã ä»ã® DigiDoc ãšã®çžäºäœ¿çšæ§ãæäŸããããã«æšå¥š
ãœãããŠã§ã¢ã³ã³ããŒãã³ãã ãã®ã³ãã³ãã¯ãæå·åããããŒã¿ ãã¡ã€ã«ãæ°ãããã¡ã€ã«ã«é 眮ããŸãã
DigiDoc ã³ã³ããã ãããã£ãŠããã®ãããªæå·åãããããã¥ã¡ã³ãã¯åŸã§ä»ã®æ¹æ³ã§åŠçããŸãã
DigiDoc ã¢ããªã±ãŒã·ã§ã³ã¯å®å šã«ãµããŒããããŠããŸã (äŸ: DigiDoc3 ã¯ã©ã€ã¢ã³ã)ã å ¥åãã¡ã€ã«
(å¿ é ) æå·åããå ã®ããŒã¿ ãã¡ã€ã«ãæå®ããŸãã 泚: ããããŸã
ãã ããæäŸããããšã¯æšå¥šãããªã代æ¿æå·åã³ãã³ã
ä»ã® DigiDoc ãœãããŠã§ã¢ ã³ã³ããŒãã³ããšã®çžäºäœ¿çšæ§:
-æå·å
æå®ãããå ¥åãã¡ã€ã«ã®ããŒã¿ãæå·åããå®æãããã¡ã€ã«ãæžã蟌ã¿ãŸãã
ãã¡ã€ã«å ã®æå·åãããããã¥ã¡ã³ãã å°èŠæš¡ãªæå·åã®ã¿ã«äœ¿çšããå¿ èŠããããŸã
ããã¥ã¡ã³ãã¯ãã§ã« DIGIDOC-XML 圢åŒã«ãªã£ãŠããŸãã å ¥åãã¡ã€ã« (å¿ é ) ã¯æ¬¡ã®ããã«æå®ããŸã
æå·åãããå ã®ããŒã¿ ãã¡ã€ã«ã
-æå·åãã¡ã€ã«
å ¥åãã¡ã€ã«ãæå·åããŠåºåãã¡ã€ã«ã«æžã蟌ã¿ãŸãã ã®ã¿ã«äœ¿çšããå¿ èŠããããŸã
ãã§ã« DIGIDOC-XML 圢åŒã«ãªã£ãŠãã倧ããªããã¥ã¡ã³ããæå·åããŸãã 泚æããŠãã ããã
ã³ãã³ãã¯çŸåšãã¹ããããŠããŸããã å ¥åãã¡ã€ã« (å¿ é ) ã¯ã
æå·åããå ã®ããŒã¿ ãã¡ã€ã«ã åºåãã¡ã€ã« (å¿ é ) ã¯ã
çŸåšã®æå·åãã¡ã€ã«ã§äœæãããåºåãã¡ã€ã«ã®åå
ããã¥ã¡ã³ãåœ¢åŒ (ENCDOC-XML ver 1.0)ããã¡ã€ã«æ¡åŒµå .cdoc ãä»ããŠããŸãã
-埩å·å-sk [pkcs12 ãã¡ã€ã«] [ã¹ãããïŒ0ïŒ]
èªã¿åãããã³æžã蟌ã¿ãè¡ã£ãæå·åãã¡ã€ã«ã埩å·åããå Žåã«ãã£ãŠã¯è§£åããŸãã
åºåãã¡ã€ã«ã æå·åããããã¡ã€ã«ã DigiDoc ã³ã³ããå ã«ããããšãæåŸ ãããŸãã å ¥å
file (å¿ é ) ã¯å ¥åãã¡ã€ã«ã®ååãæå®ããŸãã ãã³ (å¿ é ) ã¯ã
åä¿¡è ã® pin1 (ãšã¹ããã¢ã® ID ã«ãŒãã®å Žå)ã pkcs12-ãã¡ã€ã« (ãªãã·ã§ã³)
ãœãããŠã§ã¢ ããŒã¯ã³ã䜿çšããŠåŸ©å·åãè¡ãå Žåã¯ãPKCS#12 ãã¡ã€ã«ãæå®ããŸãã ã¹ããã
ããã©ã«ãã¯ããšã¹ããã¢ã® ID ã«ãŒãèªèšŒããŒãã¢ãå«ãã¹ããã 0 ã§ãã ãã
ãã©ã¡ãŒã¿ã䜿çšããŠãã«æ¥ç¶ãããŠãã XNUMX çªç®ã® ID ã«ãŒãã®ããŒã䜿çšããŠåŸ©å·åã§ããŸãã
泚: ç¶æ³ã«å¿ããŠã埩å·åã®ããã®ä»£æ¿ã³ãã³ãããããŸãã
æå·åããããã¡ã€ã«ã®åœ¢åŒããµã€ãºãããã³åŸ©å·åã«äœ¿çšããã蚌ææžã®çš®é¡ã«ã€ããŠ
ããŒãã³ã¯
-埩å·å [pkcs12ãã¡ã€ã«] [ã¹ãããïŒ0ïŒ]
-decrypt-sk ãšåãæ©èœãæäŸããŸãã埩å·åã«äœ¿çšããå¿ èŠããããŸãã
å°ããªãã¡ã€ã« (DigiDoc ã³ã³ããå ã«ããå¿ èŠã¯ãããŸãã)ã å ¥å
file (å¿ é ) ã¯å ¥åãã¡ã€ã«ã®ååãæå®ããŸãã ãã³ (å¿ é ) ãè¡šããŸã
åä¿¡è ã® pin1 (ãšã¹ããã¢ã® ID ã«ãŒãã®å Žå)ã pkcs12 ãã¡ã€ã«
(ãªãã·ã§ã³) 埩å·åããœãããŠã§ã¢ã§è¡ãããå Žåã¯ãPKCS#12 ãã¡ã€ã«ãæå®ããŸã
ããŒã¯ã³ã ã¹ãããã®ããã©ã«ãã¯ããšã¹ããã¢ã® ID ã«ãŒãèªèšŒãå«ãã¹ããã 0 ã§ãã
ããŒãã¢ã ãã®ãã©ã¡ãŒã¿ã¯ãXNUMX çªç®ã® ID ã®ããŒã䜿çšããŠåŸ©å·åããããã«äœ¿çšã§ããŸãã
ããœã³ã³ãªã©ã«ä»å±ããŠããã«ãŒãã§ãã
-埩å·åãã¡ã€ã« [pkcs12ãã¡ã€ã«]
ããã¥ã¡ã³ãã埩å·åããããã® -decrypt ãšåãæ©èœãæäŸããŸãã
倧ããªãã¡ã€ã«ã®åŸ©å·åã«äœ¿çšãããŸãïŒDigiDocå ã«ããå¿ èŠã¯ãããŸããïŒ
容åšïŒã æå·åãããããŒã¿ã¯å§çž®ãããªãããšãæåŸ ãããŸãã 泚æããŠãã ããã
ã³ãã³ãã¯çŸåšãã¹ããããŠããŸããã å ¥åãã¡ã€ã« (å¿ é ) ã¯ã
æå·åããããã¡ã€ã«ã埩å·åããŸãã åºåãã¡ã€ã« (å¿ é ) ã¯åºåãæå®ããŸã
ãã¡ã€ã«åã Pin (å¿ é ) ã¯åä¿¡è ã® pin1 ãè¡šããŸã (
ãšã¹ããã¢ã® ID ã«ãŒã)ã pkcs12-file (ãªãã·ã§ã³) ã¯ãPKCS#12 ãã¡ã€ã«ãæå®ããŸãã
埩å·åã¯ãœãããŠã§ã¢ ããŒã¯ã³ã䜿çšããŠè¡ãããŸãã
-èšç®ç¬Šå·[ ][ ]
CGI ããã°ã©ã ã§äœ¿çšããã -sign ã³ãã³ãã®ä»£æ¿æ段ãæäŸããŸãã 眲åè ãè¿œå ããŸã
pem 圢åŒã®èšŒææžãããã³ãªãã·ã§ã³ã§ãããã§ã¹ããšçœ²åè ã®ã¢ãã¬ã¹ãš
眲åãããæçµããã·ã¥å€ãèšç®ããŸãã ãã®å€ã¯ XNUMX é²æ°ã§ãšã³ã³ãŒããããŠããã
Web ãã©ã°ã€ã³ã䜿çšããŠçœ²åãåããããã«ãŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ã«éä¿¡ãããŸãã ãã®ã³ãã³ãã¯ã
å®éã® RSA 眲åå€ãæ¬ èœããŠããäžå®å šãªçœ²åã ä¿ç®¡ããªããã°ãªããŸãã
äžæãã¡ã€ã«ã«ä¿åããåŸã§ -add-sign-value ã³ãã³ãã䜿çšããŠå®äºããŸãã -IP
"-笊å·å€ã®è¿œå " -sign ã®ä»£æ¿æ段ãæäŸããŸã
CGIããã°ã©ã ã§äœ¿çšããã³ãã³ãã RSA 眲åã® XNUMX é²ãšã³ã³ãŒãå€ã
-calc-sign ã³ãã³ãã䜿çšããŠäœæãããäžå®å šãªçœ²åã ãã®ãµã€ã³ã¯ä»ãæ®ã£ãŠããŸã
ocsp ã¿ã€ã ããŒã¯ããããŸããã-get-confirmation ã䜿çšããŠååŸã§ããããã«ãªããŸããã
ã³ãã³ãã«ããå®å šãª XAdES 眲åãçæãããŸãã
-get-確èª
DigiDoc ãã¡ã€ã«ã®çœ²åã« OCSP 確èªãè¿œå ããŸãã
äŸ
cdigidoc -new DIGIDOC-XML 1.3 -add -ãµã€ã³-å€
DIGIDOC-XML 1.3 圢åŒã§æ°ãã眲åä»ãææžãäœæããå ¥åãã¡ã€ã«ã XNUMX ã€è¿œå ãã眲åããŸã
ã¹ããŒãã«ãŒãã§ããã©ã«ãã®çœ²åã¹ãããã䜿çšãã眲åãããããã¥ã¡ã³ãã«æžã蟌ã¿ãŸã
ãã¡ã€ã«ã«ãœãããŠã§ã¢ãæå®ããå¿ èŠããããŸãã
cdigidoc -in -ãªã¹ã
眲åãããææžãèªã¿åãã眲åãæ€èšŒããçµæãã³ã³ãœãŒã«ã«åºåããŸãã
cdigidoc -in -D0ãæœåº
眲åãããææžãèªã¿åããæåã®çœ²åãããææžãèŠã€ããŠåºåã«æžã蟌ã¿ãŸãã
ãã¡ã€ã«ã«ãœãããŠã§ã¢ãæå®ããå¿ èŠããããŸãã
cdigidoc -encrecv -encrecv -æå·å-sk
-å€
ã䜿çšããŠæå·åãããå ¥åãã¡ã€ã«ãæå·åããŠãæ°ããæå·åãã¡ã€ã«ãäœæããŸãã
AES-128 ã䜿çšããçæãããã©ã³ãã ãã©ã³ã¹ããŒã ããŒã RSA ã䜿çšããŠæå·åããŸãã
åä¿¡è ã¯èšŒææžã«ãã£ãŠèå¥ãããŸãã ãã©ã³ã¹ããŒãããŒã¯æ¬¡ã䜿çšããŠæå·åãããŸã
RSA1.5ã
cdigidoc -decrypt-sk -å€
æå·åããããã¡ã€ã«ãèªã¿åããã¹ããŒãã«ãŒãã®æåã®ããŒã㢠(ãšã¹ããã¢ã® ID) ã§åŸ©å·åããŸãã
ã«ãŒãèªèšŒããŒïŒãååŸãã埩å·åãããããŒã¿ãæå®ããã putput ãã¡ã€ã«ã«æžã蟌ã¿ãŸãã
cdigidoc -decrypt-sk -å€
æå·åããããã¡ã€ã«ãèªã¿åããPKCS#12 ããŒã³ã³ããã§åŸ©å·åããŠæžã蟌ã¿ãŸãã
埩å·åãããããŒã¿ãæå®ããã putput ãã¡ã€ã«ã«ã³ããŒããŸãã
äœè
AS ã»ã«ãã£ãã£ãããŒãŒãªãã¹ã¹ã±ã¹ã¯ã¹ ïŒèªèšŒ ã»ã³ã¿ãŒ æ ªåŒäŒç€ŸïŒ
onworks.net ãµãŒãã¹ã䜿çšããŠãªã³ã©ã€ã³ã§ cdigidoc ã䜿çšãã