Research
Security News
Quasar RAT Disguised as an npm Package for Detecting Vulnerabilities in Ethereum Smart Contracts
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
@peculiar/asn1-x509
Advanced tools
ASN.1 schema of `Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile` (RFC5280)
@peculiar/asn1-x509 is an npm package that provides tools for working with ASN.1 (Abstract Syntax Notation One) and X.509 certificates. It allows developers to parse, encode, and manipulate X.509 certificates and related structures in JavaScript.
Parsing X.509 Certificates
This feature allows you to parse a raw X.509 certificate from a binary format (BER). The code sample demonstrates how to convert a base64-encoded certificate into a Certificate object.
const { Certificate } = require('@peculiar/asn1-x509');
const rawCert = Buffer.from('MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1J...', 'base64');
const cert = Certificate.fromBER(rawCert);
console.log(cert);
Encoding X.509 Certificates
This feature allows you to encode an X.509 certificate into a binary format (BER). The code sample demonstrates how to create a Certificate object and convert it into a base64-encoded string.
const { Certificate } = require('@peculiar/asn1-x509');
const cert = new Certificate({
tbsCertificate: {
version: 2,
serialNumber: new Uint8Array([1, 2, 3, 4]),
signature: { algorithm: '1.2.840.113549.1.1.11' },
issuer: { type: 'rdnSequence', value: [] },
validity: { notBefore: new Date(), notAfter: new Date() },
subject: { type: 'rdnSequence', value: [] },
subjectPublicKeyInfo: { algorithm: { algorithm: '1.2.840.113549.1.1.1' }, subjectPublicKey: new Uint8Array([1, 2, 3, 4]) }
},
signatureAlgorithm: { algorithm: '1.2.840.113549.1.1.11' },
signatureValue: new Uint8Array([1, 2, 3, 4])
});
const rawCert = cert.toSchema().toBER(false);
console.log(Buffer.from(rawCert).toString('base64'));
Manipulating Certificate Extensions
This feature allows you to manipulate extensions within an X.509 certificate. The code sample demonstrates how to add a new extension to a Certificate object.
const { Certificate, Extension } = require('@peculiar/asn1-x509');
const cert = new Certificate();
const ext = new Extension({
extnID: '2.5.29.14',
critical: false,
extnValue: new Uint8Array([1, 2, 3, 4])
});
cert.tbsCertificate.extensions = [ext];
console.log(cert.tbsCertificate.extensions);
node-forge is a robust library for implementing various cryptographic functions in JavaScript, including working with X.509 certificates. It provides a higher-level API compared to @peculiar/asn1-x509 and includes additional features like PKCS#12 and TLS.
asn1js is a library for encoding and decoding ASN.1 data structures in JavaScript. It is more general-purpose compared to @peculiar/asn1-x509, which is specifically tailored for X.509 certificates.
pkijs is a library built on top of asn1js for working with PKI (Public Key Infrastructure) in JavaScript. It provides comprehensive support for X.509 certificates, CRLs, OCSP, and more, making it a more feature-rich alternative to @peculiar/asn1-x509.
@peculiar/asn1-x509
RFC 5280 Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile.
FAQs
ASN.1 schema of `Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List (CRL) Profile` (RFC5280)
The npm package @peculiar/asn1-x509 receives a total of 188,958 weekly downloads. As such, @peculiar/asn1-x509 popularity was classified as popular.
We found that @peculiar/asn1-x509 demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 6 open source maintainers collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket researchers uncover a malicious npm package posing as a tool for detecting vulnerabilities in Etherium smart contracts.
Security News
Research
A supply chain attack on Rspack's npm packages injected cryptomining malware, potentially impacting thousands of developers.
Research
Security News
Socket researchers discovered a malware campaign on npm delivering the Skuld infostealer via typosquatted packages, exposing sensitive data.