dcclib.signature

DCCSigner

DCCSigner(key: str, cert: str)

Class to sign XML files with a private key and certificate.

Create a new DCCSigner.

Parameters:
  • key (str) –

    the private key

  • cert (str) –

    the full certificate chain, including intermediate certificates, in PEM format.

sign_path

sign_path(path: str) -> etree.Element

Sign an XML file.

Parameters:
  • path (str) –

    the path to the XML file

Returns:
  • etree.Element –

    the signed XML tree

Raises:
  • Exception –

    if the XML could not be signed

sign_str

sign_str(xml: str) -> etree.Element

Sign an XML string.

Parameters:
  • xml (str) –

    the XML string to sign

Returns:
  • etree.Element –

    the signed XML string

Raises:
  • Exception –

    if the XML could not be signed

sign_tree

sign_tree(xml_tree: etree.Element) -> etree.Element

Sign an XML tree.

Parameters:
  • xml_tree (etree.Element) –

    the XML tree to sign

Returns:
  • etree.Element –

    the signed XML tree

Raises:
  • Exception –

    if the XML could not be signed

DCCVerifier

DCCVerifier(ca_pem_file: str | None = None)

Class to verify XML files.

Create a new DCCVerifier.

Parameters:
  • ca_pem_file (str | None, default: None ) –

    the path to the CA PEM file @warning: by default, the systems CA certificates are used. See here: https://xml-security.github.io/signxml#verifying-saml-assertions

verify_path

verify_path(path: str)

Verify an XML file.

Parameters:
  • path (str) –

    the path to the XML file

Returns:
  • –

    the verification result

Raises:
  • Exception –

    if the XML could not be verified @warning: signxml is used to verify the XML. See the security recommendations here: https://xml-security.github.io/signxml/#signxml.XMLVerifier

verify_str

verify_str(xml: str)

Verify an XML string.

Parameters:
  • xml (str) –

    the XML string to verify

Returns:
  • –

    the verification result

Raises:
  • Exception –

    if the XML could not be verified @warning: signxml is used to verify the XML. See the security recommendations here: https://xml-security.github.io/signxml/#signxml.XMLVerifier

verify_tree

verify_tree(xml_tree: etree.Element) -> DCCVerifyResult

Verify an XML tree.

Parameters:
  • xml_tree (etree.Element) –

    the XML tree to verify

Returns:
Raises:
  • Exception –

    if the XML could not be verified @warning: signxml is used to verify the XML. See the security recommendations here: https://xml-security.github.io/signxml/#signxml.XMLVerifier

DCCVerifyResult

DCCVerifyResult(signed_tree: etree.Element, signature_tree: etree.Element, cert: x509.Certificate)

Class to represent the result of a verification.

Create a new DCCVerifyResult.

Parameters:
  • signed_tree (etree.Element) –

    the tree of the signed XML

  • signature_tree (etree.Element) –

    the tree of the signature

  • cert (x509.Certificate) –

    the certificate used for signing

signature

DCCSigner

DCCSigner(key: str, cert: str)

Class to sign XML files with a private key and certificate.

Create a new DCCSigner.

Parameters:
  • key (str) –

    the private key

  • cert (str) –

    the full certificate chain, including intermediate certificates, in PEM format.

sign_path

sign_path(path: str) -> etree.Element

Sign an XML file.

Parameters:
  • path (str) –

    the path to the XML file

Returns:
  • etree.Element –

    the signed XML tree

Raises:
  • Exception –

    if the XML could not be signed

sign_str

sign_str(xml: str) -> etree.Element

Sign an XML string.

Parameters:
  • xml (str) –

    the XML string to sign

Returns:
  • etree.Element –

    the signed XML string

Raises:
  • Exception –

    if the XML could not be signed

sign_tree

sign_tree(xml_tree: etree.Element) -> etree.Element

Sign an XML tree.

Parameters:
  • xml_tree (etree.Element) –

    the XML tree to sign

Returns:
  • etree.Element –

    the signed XML tree

Raises:
  • Exception –

    if the XML could not be signed

DCCVerifier

DCCVerifier(ca_pem_file: str | None = None)

Class to verify XML files.

Create a new DCCVerifier.

Parameters:
  • ca_pem_file (str | None, default: None ) –

    the path to the CA PEM file @warning: by default, the systems CA certificates are used. See here: https://xml-security.github.io/signxml#verifying-saml-assertions

verify_path

verify_path(path: str)

Verify an XML file.

Parameters:
  • path (str) –

    the path to the XML file

Returns:
  • –

    the verification result

Raises:
  • Exception –

    if the XML could not be verified @warning: signxml is used to verify the XML. See the security recommendations here: https://xml-security.github.io/signxml/#signxml.XMLVerifier

verify_str

verify_str(xml: str)

Verify an XML string.

Parameters:
  • xml (str) –

    the XML string to verify

Returns:
  • –

    the verification result

Raises:
  • Exception –

    if the XML could not be verified @warning: signxml is used to verify the XML. See the security recommendations here: https://xml-security.github.io/signxml/#signxml.XMLVerifier

verify_tree

verify_tree(xml_tree: etree.Element) -> DCCVerifyResult

Verify an XML tree.

Parameters:
  • xml_tree (etree.Element) –

    the XML tree to verify

Returns:
Raises:
  • Exception –

    if the XML could not be verified @warning: signxml is used to verify the XML. See the security recommendations here: https://xml-security.github.io/signxml/#signxml.XMLVerifier

DCCVerifyResult

DCCVerifyResult(signed_tree: etree.Element, signature_tree: etree.Element, cert: x509.Certificate)

Class to represent the result of a verification.

Create a new DCCVerifyResult.

Parameters:
  • signed_tree (etree.Element) –

    the tree of the signed XML

  • signature_tree (etree.Element) –

    the tree of the signature

  • cert (x509.Certificate) –

    the certificate used for signing