Skip to main content
iso8583sim.security.mac For testing and simulation only. Production MACs are generated inside an HSM.

Functions

generate_mac()

Generate an ISO 9797-1 MAC with DES based block ciphers. Algorithm 1 is a CBC-MAC with the whole key (single, double or triple length). Algorithm 3 is the retail MAC (ANSI X9.19): single DES CBC with the left key half, then decrypt with the right half and encrypt with the left half on the final block. Parameters
str | bytes
required
Data to authenticate. A str is encoded as ASCII, which is how this simulator carries ISO 8583 messages.
str | bytes
required
MAC key as bytes or hex (8, 16 or 24 bytes for algorithm 1; 16 for algorithm 3)
int
default:"3"
ISO 9797-1 MAC algorithm: 1 or 3
int
default:"1"
ISO 9797-1 padding method: 1 or 2
int
default:"8"
MAC length in bytes, 4 to 8. Truncation keeps the leftmost bytes.
str
The MAC as uppercase hex

verify_mac()

Check a MAC. The expected length is taken from the given MAC.

mac_field()

Return which field carries the MAC: 128 when the message has a secondary bitmap, else 64.

sign_message()

Build a message with its MAC in field 64 (or 128 with a secondary bitmap). Parameters
ISO8583Message
required
Message to build. Any existing MAC field is replaced.
str | bytes
required
MAC key as bytes or hex
ISO8583Builder | None
default:"None"
Builder to use (defaults to one for the message’s version)
int
default:"3"
ISO 9797-1 MAC algorithm: 1 or 3
int
default:"1"
ISO 9797-1 padding method: 1 or 2
str
The raw message with the MAC filled in

verify_message()

Check the MAC in field 64 or 128 of a raw message built by this simulator.