iya-sts
    Preparing search index...

    The wire format of Kerberos FAST (RFC 6113), OTP pre-authentication (RFC 6560) and authentication indicators (RFC 7751, RFC 8129): structures to DER and back, built on the vendored codec's primitives.

    It knows no key and no policy; a structure that does not decode throws. A static utility class.

    Index
    AD: {
        AUTHENTICATION_INDICATOR: number;
        CAMMAC: number;
        FX_FAST_ARMOR: number;
        FX_FAST_USED: number;
        IF_RELEVANT: number;
    } = ...

    The authorization data types: AD-IF-RELEVANT, RFC 6113's two FAST markers, AD-CAMMAC and AD-AUTHENTICATION-INDICATOR.

    ARMOR_AP_REQUEST: 1

    The one FAST armor type defined, an AP-REQ (RFC 6113 section 5.4.1).

    ERROR: {
        INVALID_HASH_ALG: number;
        INVALID_ITERATION_COUNT: number;
        MORE_PREAUTH_DATA_REQUIRED: number;
        PIN_EXPIRED: number;
        PIN_REQUIRED: number;
        PREAUTH_BAD_AUTHENTICATION_SET: number;
        PREAUTH_EXPIRED: number;
        UNKNOWN_CRITICAL_FAST_OPTIONS: number;
    } = ...

    The error codes of RFC 6113 section 6.1 and RFC 6560 section 2.3.

    FAST_OPTION: {
        HIDE_CLIENT_NAMES: number;
        KDC_FOLLOW_REFERRALS: number;
        RESERVED: number;
    } = ...

    The FastOptions bits (RFC 6113 section 5.4.2); bits 0 to 15 are critical.

    KEY_USAGE: {
        CAMMAC: number;
        ENC_CHALLENGE_CLIENT: number;
        ENC_CHALLENGE_KDC: number;
        FAST_ENC: number;
        FAST_FINISHED: number;
        FAST_REP: number;
        FAST_REQ_CHKSUM: number;
        FX_COOKIE: number;
        OTP_REQUEST: number;
    } = ...

    The key usages: RFC 6560's, RFC 6113's, RFC 7751's, and MIT's private usage for the PA-FX-COOKIE.

    OTP_FLAG: {
        CHECK_DIGIT: number;
        COLLECT_PIN: number;
        COMBINE: number;
        DO_NOT_COLLECT_PIN: number;
        MUST_ENCRYPT_NONCE: number;
        NEXT_OTP: number;
        SEPARATE_PIN_REQUIRED: number;
    } = ...

    The OTPFlags bits (RFC 6560 section 4.1), numbered from the most significant bit.

    OTP_FORMAT: {
        ALPHANUMERIC: number;
        BASE64: number;
        BINARY: number;
        DECIMAL: number;
        HEXADECIMAL: number;
    } = ...

    The otp-format values (RFC 6560).

    PA: {
        AUTH_SET_SELECTED: number;
        AUTHENTICATION_SET: number;
        ENCRYPTED_CHALLENGE: number;
        FX_COOKIE: number;
        FX_ERROR: number;
        FX_FAST: number;
        OTP_CHALLENGE: number;
        OTP_PIN_CHANGE: number;
        OTP_REQUEST: number;
    } = ...

    The padata types of RFC 6113 section 6.4 and RFC 6560 section 5.

    • Reads an implicitly tagged TLV back as the universal type it replaces.

      Parameters

      • t: any

        the context-tagged TLV

      • tag: number

        the universal tag to read it as

      Returns any

      the TLV

    • Decodes a UTF8String.

      Parameters

      • t: any

        the decoded TLV

      Returns string

      the text

      Error when the TLV is not a UTF8String

    • Encodes a KrbFastArmor.

      Parameters

      • armor: any

        { type, value }

      Returns Uint8Array

      the DER

    • Encodes an AD-CAMMAC around the already-encoded AuthorizationData its verifiers' MACs cover.

      Parameters

      • c: any

        { elementsBytes, kdcVerifier, svcVerifier }

      Returns Uint8Array

      the DER

    • Encodes a KrbFastFinished.

      Parameters

      • fin: any

        { timestamp, usec, crealm, cname, ticketChecksum }

      Returns Uint8Array

      the DER

    • Encodes a PA-FX-FAST-REPLY around the encrypted KrbFastResponse.

      Parameters

      • encFastRep: any

        the EncryptedData

      Returns Uint8Array

      the DER

    • Encodes a KrbFastReq; a reqBody carrying its raw bytes is placed as they are.

      Parameters

      • req: any

        { fastOptions, padata, reqBody }

      Returns Uint8Array

      the DER

    • Encodes a PA-FX-FAST-REQUEST, a KrbFastArmoredReq in its [0] alternative.

      Parameters

      • req: any

        { armor, reqChecksum, encFastReq }, armor optional

      Returns Uint8Array

      the DER

    • Encodes a KrbFastResponse.

      Parameters

      • rep: any

        { padata, strengthenKey, finished, nonce }, the middle two optional

      Returns Uint8Array

      the DER

    • Encodes an AD-AUTHENTICATION-INDICATOR.

      Parameters

      • list: string[]

        the indicators

      Returns Uint8Array

      the DER

    • Encodes a PA-OTP-CHALLENGE, every tag implicit.

      Parameters

      • chl: any

        { nonce, service, tokenInfo, salt, s2kparams }

      Returns Uint8Array

      the DER

    • Encodes a PA-OTP-ENC-REQUEST.

      Parameters

      • nonce: Uint8Array

        the nonce

      Returns Uint8Array

      the DER

    • Encodes a PA-OTP-REQUEST, every tag implicit.

      Parameters

      • req: any

        { flags, nonce, encData, value, pin, time, vendor }

      Returns Uint8Array

      the DER

    • Encodes a SEQUENCE OF PA-DATA.

      Parameters

      • list: any[]

        the PA-DATA

      Returns Uint8Array

      the DER

    • Encodes an OTP-TOKENINFO; the two hashing fields are never written.

      Parameters

      • ti: any

        { flags, vendor, challenge, length, format, tokenId, algId }

      Returns Uint8Array

      the DER

    • Encodes a UTF8String.

      Parameters

      • text: string

        the text

      Returns Uint8Array

      the DER

    • Encodes a Verifier-MAC.

      Parameters

      • v: any

        { identifier, kvno, enctype, mac }, all but mac optional

      Returns Uint8Array

      the DER

    • Returns the one element inside an explicit context tag [n], which is how a CHOICE alternative arrives.

      Parameters

      • bytes: Uint8Array

        the DER

      • n: number

        the context tag number

      Returns any

      the inner TLV

      Error unless it is exactly [n] round one element

    • Returns a SEQUENCE's context-tagged fields, by tag number.

      Parameters

      • t: any

        the SEQUENCE's TLV

      • what: string

        the structure's name, for the error

      Returns any

      the fields

      Error when it is not a SEQUENCE

    • Returns the PA-DATA of a type in a list.

      Parameters

      • list: any[]

        the PA-DATA

      • type: number

        the padata type

      Returns any

      the PA-DATA, or null

    • Encodes an implicitly tagged INTEGER field.

      Parameters

      • n: number

        the context tag number

      • value: number

        the integer

      Returns Uint8Array<ArrayBufferLike>

      the TLV, or null when absent

    • Turns an encoded universal TLV into its implicitly context-tagged form [n], the constructed bit kept.

      Parameters

      • n: number

        the context tag number

      • encoded: Uint8Array<ArrayBufferLike>

        the universal TLV

      Returns Uint8Array<ArrayBufferLike>

      the retagged TLV, or null for null

    • Returns the fields of an implicitly tagged SEQUENCE, by context tag number.

      Parameters

      • t: any

        the SEQUENCE's TLV

      • what: string

        the structure's name, for the error

      Returns any

      the fields

      Error when it is not a SEQUENCE or a field is not context-tagged

    • Encodes a SEQUENCE of the fields that are present.

      Parameters

      • fields: Uint8Array<ArrayBufferLike>[]

        the encoded fields, null for absent

      Returns Uint8Array

      the DER

    • Encodes an implicitly tagged OCTET STRING field.

      Parameters

      • n: number

        the context tag number

      • value: Uint8Array<ArrayBufferLike>

        the bytes

      Returns Uint8Array<ArrayBufferLike>

      the TLV, or null when absent

    • Encodes an implicitly tagged UTF8String field.

      Parameters

      • n: number

        the context tag number

      • value: string

        the text

      Returns Uint8Array<ArrayBufferLike>

      the TLV, or null when absent

    • Decodes a SEQUENCE OF PA-DATA.

      Parameters

      • t: any

        the SEQUENCE's TLV

      Returns any[]

      the PA-DATA

    • Decodes a KrbFastArmor.

      Parameters

      • t: any

        the SEQUENCE's TLV

      Returns any

      { type, value }

      Error when it does not decode

    • Decodes an AD-CAMMAC, keeping the elements' bytes for checking the MACs.

      Parameters

      • bytes: Uint8Array

        the DER

      Returns any

      { elementsBytes, elements, kdcVerifier, svcVerifier }

      Error when it does not decode

    • Decodes a KrbFastFinished.

      Parameters

      • t: any

        the SEQUENCE's TLV

      Returns any

      { timestamp, usec, crealm, cname, ticketChecksum }

      Error when it does not decode

    • Decodes a PA-FX-FAST-REPLY.

      Parameters

      • bytes: Uint8Array

        the DER

      Returns any

      the EncryptedData

      Error when it does not decode

    • Decodes a KrbFastReq, the req-body with the vendored KDC-REQ-BODY reader.

      Parameters

      • bytes: Uint8Array

        the DER

      Returns any

      { fastOptions, padata, reqBody }

      Error when it does not decode

    • Decodes a PA-FX-FAST-REQUEST.

      Parameters

      • bytes: Uint8Array

        the DER

      Returns any

      { armor, reqChecksum, encFastReq }

      Error when it does not decode

    • Decodes a KrbFastResponse.

      Parameters

      • bytes: Uint8Array

        the DER

      Returns any

      { padata, strengthenKey, finished, nonce }

      Error when it does not decode

    • Decodes an AD-AUTHENTICATION-INDICATOR.

      Parameters

      • bytes: Uint8Array

        the DER

      Returns string[]

      the indicators

      Error when it does not decode

    • Decodes a PA-OTP-CHALLENGE.

      Parameters

      • bytes: Uint8Array

        the DER

      Returns any

      { nonce, service, tokenInfo, salt, s2kparams }

      Error when it does not decode

    • Decodes what an OTP request's encData opened to: a PA-OTP-ENC-REQUEST (four-pass) or a PA-ENC-TS-ENC (two-pass), told apart by field 0's tag.

      Parameters

      • bytes: Uint8Array

        the DER

      Returns any

      { nonce } or { timestamp }

      Error when it is neither

    • Decodes a PA-OTP-REQUEST; hashing is true for a hashAlg or an iterationCount above zero.

      Parameters

      • bytes: Uint8Array

        the DER

      Returns any

      { flags, nonce, encData, hashing, value, pin, time, vendor }

      Error when it does not decode

    • Decodes an OTP-TOKENINFO.

      Parameters

      • t: any

        the SEQUENCE's TLV

      Returns any

      { flags, vendor, challenge, length, format, tokenId, algId, hashing }

      Error when it does not decode

    • Decodes a Verifier-MAC.

      Parameters

      • t: any

        the SEQUENCE's TLV

      Returns any

      { identifier, kvno, enctype, mac }

      Error when it does not decode

    • Returns a required field of a decoded SEQUENCE.

      Parameters

      • f: any

        the fields, by tag number

      • n: number

        the tag number

      • what: string

        the structure's name, for the error

      Returns any

      the field

      Error when the field is absent