|
1 /* v3_ocsp.c */ |
|
2 /* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL |
|
3 * project 1999. |
|
4 */ |
|
5 /* ==================================================================== |
|
6 * Copyright (c) 1999 The OpenSSL Project. All rights reserved. |
|
7 * |
|
8 * Redistribution and use in source and binary forms, with or without |
|
9 * modification, are permitted provided that the following conditions |
|
10 * are met: |
|
11 * |
|
12 * 1. Redistributions of source code must retain the above copyright |
|
13 * notice, this list of conditions and the following disclaimer. |
|
14 * |
|
15 * 2. Redistributions in binary form must reproduce the above copyright |
|
16 * notice, this list of conditions and the following disclaimer in |
|
17 * the documentation and/or other materials provided with the |
|
18 * distribution. |
|
19 * |
|
20 * 3. All advertising materials mentioning features or use of this |
|
21 * software must display the following acknowledgment: |
|
22 * "This product includes software developed by the OpenSSL Project |
|
23 * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)" |
|
24 * |
|
25 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to |
|
26 * endorse or promote products derived from this software without |
|
27 * prior written permission. For written permission, please contact |
|
28 * licensing@OpenSSL.org. |
|
29 * |
|
30 * 5. Products derived from this software may not be called "OpenSSL" |
|
31 * nor may "OpenSSL" appear in their names without prior written |
|
32 * permission of the OpenSSL Project. |
|
33 * |
|
34 * 6. Redistributions of any form whatsoever must retain the following |
|
35 * acknowledgment: |
|
36 * "This product includes software developed by the OpenSSL Project |
|
37 * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)" |
|
38 * |
|
39 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY |
|
40 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE |
|
41 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR |
|
42 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR |
|
43 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, |
|
44 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT |
|
45 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; |
|
46 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) |
|
47 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, |
|
48 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) |
|
49 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED |
|
50 * OF THE POSSIBILITY OF SUCH DAMAGE. |
|
51 * ==================================================================== |
|
52 * |
|
53 * This product includes cryptographic software written by Eric Young |
|
54 * (eay@cryptsoft.com). This product includes software written by Tim |
|
55 * Hudson (tjh@cryptsoft.com). |
|
56 * |
|
57 */ |
|
58 /* |
|
59 © Portions copyright (c) 2006 Nokia Corporation. All rights reserved. |
|
60 */ |
|
61 |
|
62 #ifndef OPENSSL_NO_OCSP |
|
63 |
|
64 #include <stdio.h> |
|
65 #include "cryptlib.h" |
|
66 #include <openssl/conf.h> |
|
67 #include <openssl/asn1.h> |
|
68 #include <openssl/ocsp.h> |
|
69 #include <openssl/x509v3.h> |
|
70 #if (defined(SYMBIAN) && (defined(__WINSCW__) || defined(__WINS__))) |
|
71 #include "libcrypto_wsd_macros.h" |
|
72 #include "libcrypto_wsd.h" |
|
73 #endif |
|
74 |
|
75 /* OCSP extensions and a couple of CRL entry extensions |
|
76 */ |
|
77 |
|
78 static int i2r_ocsp_crlid(X509V3_EXT_METHOD *method, void *nonce, BIO *out, int indent); |
|
79 static int i2r_ocsp_acutoff(X509V3_EXT_METHOD *method, void *nonce, BIO *out, int indent); |
|
80 static int i2r_object(X509V3_EXT_METHOD *method, void *obj, BIO *out, int indent); |
|
81 |
|
82 static void *ocsp_nonce_new(void); |
|
83 static int i2d_ocsp_nonce(void *a, unsigned char **pp); |
|
84 static void *d2i_ocsp_nonce(void *a, const unsigned char **pp, long length); |
|
85 static void ocsp_nonce_free(void *a); |
|
86 static int i2r_ocsp_nonce(X509V3_EXT_METHOD *method, void *nonce, BIO *out, int indent); |
|
87 |
|
88 static int i2r_ocsp_nocheck(X509V3_EXT_METHOD *method, void *nocheck, BIO *out, int indent); |
|
89 static void *s2i_ocsp_nocheck(X509V3_EXT_METHOD *method, X509V3_CTX *ctx, const char *str); |
|
90 static int i2r_ocsp_serviceloc(X509V3_EXT_METHOD *method, void *in, BIO *bp, int ind); |
|
91 |
|
92 #ifndef EMULATOR |
|
93 X509V3_EXT_METHOD v3_ocsp_crlid = { |
|
94 NID_id_pkix_OCSP_CrlID, 0, ASN1_ITEM_ref(OCSP_CRLID), |
|
95 0,0,0,0, |
|
96 0,0, |
|
97 0,0, |
|
98 i2r_ocsp_crlid,0, |
|
99 NULL |
|
100 }; |
|
101 |
|
102 X509V3_EXT_METHOD v3_ocsp_acutoff = { |
|
103 NID_id_pkix_OCSP_archiveCutoff, 0, ASN1_ITEM_ref(ASN1_GENERALIZEDTIME), |
|
104 0,0,0,0, |
|
105 0,0, |
|
106 0,0, |
|
107 i2r_ocsp_acutoff,0, |
|
108 NULL |
|
109 }; |
|
110 |
|
111 X509V3_EXT_METHOD v3_crl_invdate = { |
|
112 NID_invalidity_date, 0, ASN1_ITEM_ref(ASN1_GENERALIZEDTIME), |
|
113 0,0,0,0, |
|
114 0,0, |
|
115 0,0, |
|
116 i2r_ocsp_acutoff,0, |
|
117 NULL |
|
118 }; |
|
119 |
|
120 X509V3_EXT_METHOD v3_crl_hold = { |
|
121 NID_hold_instruction_code, 0, ASN1_ITEM_ref(ASN1_OBJECT), |
|
122 0,0,0,0, |
|
123 0,0, |
|
124 0,0, |
|
125 i2r_object,0, |
|
126 NULL |
|
127 }; |
|
128 |
|
129 X509V3_EXT_METHOD v3_ocsp_nonce = { |
|
130 NID_id_pkix_OCSP_Nonce, 0, NULL, |
|
131 ocsp_nonce_new, |
|
132 ocsp_nonce_free, |
|
133 d2i_ocsp_nonce, |
|
134 i2d_ocsp_nonce, |
|
135 0,0, |
|
136 0,0, |
|
137 i2r_ocsp_nonce,0, |
|
138 NULL |
|
139 }; |
|
140 |
|
141 X509V3_EXT_METHOD v3_ocsp_nocheck = { |
|
142 NID_id_pkix_OCSP_noCheck, 0, ASN1_ITEM_ref(ASN1_NULL), |
|
143 0,0,0,0, |
|
144 0,s2i_ocsp_nocheck, |
|
145 0,0, |
|
146 i2r_ocsp_nocheck,0, |
|
147 NULL |
|
148 }; |
|
149 |
|
150 X509V3_EXT_METHOD v3_ocsp_serviceloc = { |
|
151 NID_id_pkix_OCSP_serviceLocator, 0, ASN1_ITEM_ref(OCSP_SERVICELOC), |
|
152 0,0,0,0, |
|
153 0,0, |
|
154 0,0, |
|
155 i2r_ocsp_serviceloc,0, |
|
156 NULL |
|
157 }; |
|
158 #else |
|
159 const X509V3_EXT_METHOD v3_ocsp_crlid = { |
|
160 NID_id_pkix_OCSP_CrlID, 0, ASN1_ITEM_ref(OCSP_CRLID), |
|
161 0,0,0,0, |
|
162 0,0, |
|
163 0,0, |
|
164 i2r_ocsp_crlid,0, |
|
165 NULL |
|
166 }; |
|
167 |
|
168 const X509V3_EXT_METHOD v3_ocsp_acutoff = { |
|
169 NID_id_pkix_OCSP_archiveCutoff, 0, ASN1_ITEM_ref(ASN1_GENERALIZEDTIME), |
|
170 0,0,0,0, |
|
171 0,0, |
|
172 0,0, |
|
173 i2r_ocsp_acutoff,0, |
|
174 NULL |
|
175 }; |
|
176 |
|
177 const X509V3_EXT_METHOD v3_crl_invdate = { |
|
178 NID_invalidity_date, 0, ASN1_ITEM_ref(ASN1_GENERALIZEDTIME), |
|
179 0,0,0,0, |
|
180 0,0, |
|
181 0,0, |
|
182 i2r_ocsp_acutoff,0, |
|
183 NULL |
|
184 }; |
|
185 |
|
186 const X509V3_EXT_METHOD v3_crl_hold = { |
|
187 NID_hold_instruction_code, 0, ASN1_ITEM_ref(ASN1_OBJECT), |
|
188 0,0,0,0, |
|
189 0,0, |
|
190 0,0, |
|
191 i2r_object,0, |
|
192 NULL |
|
193 }; |
|
194 |
|
195 const X509V3_EXT_METHOD v3_ocsp_nonce = { |
|
196 NID_id_pkix_OCSP_Nonce, 0, NULL, |
|
197 ocsp_nonce_new, |
|
198 ocsp_nonce_free, |
|
199 d2i_ocsp_nonce, |
|
200 i2d_ocsp_nonce, |
|
201 0,0, |
|
202 0,0, |
|
203 i2r_ocsp_nonce,0, |
|
204 NULL |
|
205 }; |
|
206 |
|
207 const X509V3_EXT_METHOD v3_ocsp_nocheck = { |
|
208 NID_id_pkix_OCSP_noCheck, 0, ASN1_ITEM_ref(ASN1_NULL), |
|
209 0,0,0,0, |
|
210 0,s2i_ocsp_nocheck, |
|
211 0,0, |
|
212 i2r_ocsp_nocheck,0, |
|
213 NULL |
|
214 }; |
|
215 |
|
216 const X509V3_EXT_METHOD v3_ocsp_serviceloc = { |
|
217 NID_id_pkix_OCSP_serviceLocator, 0, ASN1_ITEM_ref(OCSP_SERVICELOC), |
|
218 0,0,0,0, |
|
219 0,0, |
|
220 0,0, |
|
221 i2r_ocsp_serviceloc,0, |
|
222 NULL |
|
223 }; |
|
224 |
|
225 #endif |
|
226 static int i2r_ocsp_crlid(X509V3_EXT_METHOD *method, void *in, BIO *bp, int ind) |
|
227 { |
|
228 OCSP_CRLID *a = in; |
|
229 if (a->crlUrl) |
|
230 { |
|
231 if (!BIO_printf(bp, "%*scrlUrl: ", ind, "")) goto err; |
|
232 if (!ASN1_STRING_print(bp, (ASN1_STRING*)a->crlUrl)) goto err; |
|
233 if (!BIO_write(bp, "\n", 1)) goto err; |
|
234 } |
|
235 if (a->crlNum) |
|
236 { |
|
237 if (!BIO_printf(bp, "%*scrlNum: ", ind, "")) goto err; |
|
238 if (!i2a_ASN1_INTEGER(bp, a->crlNum)) goto err; |
|
239 if (!BIO_write(bp, "\n", 1)) goto err; |
|
240 } |
|
241 if (a->crlTime) |
|
242 { |
|
243 if (!BIO_printf(bp, "%*scrlTime: ", ind, "")) goto err; |
|
244 if (!ASN1_GENERALIZEDTIME_print(bp, a->crlTime)) goto err; |
|
245 if (!BIO_write(bp, "\n", 1)) goto err; |
|
246 } |
|
247 return 1; |
|
248 err: |
|
249 return 0; |
|
250 } |
|
251 |
|
252 static int i2r_ocsp_acutoff(X509V3_EXT_METHOD *method, void *cutoff, BIO *bp, int ind) |
|
253 { |
|
254 if (!BIO_printf(bp, "%*s", ind, "")) return 0; |
|
255 if(!ASN1_GENERALIZEDTIME_print(bp, cutoff)) return 0; |
|
256 return 1; |
|
257 } |
|
258 |
|
259 |
|
260 static int i2r_object(X509V3_EXT_METHOD *method, void *oid, BIO *bp, int ind) |
|
261 { |
|
262 if (!BIO_printf(bp, "%*s", ind, "")) return 0; |
|
263 if(!i2a_ASN1_OBJECT(bp, oid)) return 0; |
|
264 return 1; |
|
265 } |
|
266 |
|
267 /* OCSP nonce. This is needs special treatment because it doesn't have |
|
268 * an ASN1 encoding at all: it just contains arbitrary data. |
|
269 */ |
|
270 |
|
271 static void *ocsp_nonce_new(void) |
|
272 { |
|
273 return ASN1_OCTET_STRING_new(); |
|
274 } |
|
275 |
|
276 static int i2d_ocsp_nonce(void *a, unsigned char **pp) |
|
277 { |
|
278 ASN1_OCTET_STRING *os = a; |
|
279 if(pp) { |
|
280 memcpy(*pp, os->data, os->length); |
|
281 *pp += os->length; |
|
282 } |
|
283 return os->length; |
|
284 } |
|
285 |
|
286 static void *d2i_ocsp_nonce(void *a, const unsigned char **pp, long length) |
|
287 { |
|
288 ASN1_OCTET_STRING *os, **pos; |
|
289 pos = a; |
|
290 if(!pos || !*pos) os = ASN1_OCTET_STRING_new(); |
|
291 else os = *pos; |
|
292 if(!ASN1_OCTET_STRING_set(os, *pp, length)) goto err; |
|
293 |
|
294 *pp += length; |
|
295 |
|
296 if(pos) *pos = os; |
|
297 return os; |
|
298 |
|
299 err: |
|
300 if(os && (!pos || (*pos != os))) M_ASN1_OCTET_STRING_free(os); |
|
301 OCSPerr(OCSP_F_D2I_OCSP_NONCE, ERR_R_MALLOC_FAILURE); |
|
302 return NULL; |
|
303 } |
|
304 |
|
305 static void ocsp_nonce_free(void *a) |
|
306 { |
|
307 M_ASN1_OCTET_STRING_free(a); |
|
308 } |
|
309 |
|
310 static int i2r_ocsp_nonce(X509V3_EXT_METHOD *method, void *nonce, BIO *out, int indent) |
|
311 { |
|
312 if(BIO_printf(out, "%*s", indent, "") <= 0) return 0; |
|
313 if(i2a_ASN1_STRING(out, nonce, V_ASN1_OCTET_STRING) <= 0) return 0; |
|
314 return 1; |
|
315 } |
|
316 |
|
317 /* Nocheck is just a single NULL. Don't print anything and always set it */ |
|
318 |
|
319 static int i2r_ocsp_nocheck(X509V3_EXT_METHOD *method, void *nocheck, BIO *out, int indent) |
|
320 { |
|
321 return 1; |
|
322 } |
|
323 |
|
324 static void *s2i_ocsp_nocheck(X509V3_EXT_METHOD *method, X509V3_CTX *ctx, const char *str) |
|
325 { |
|
326 return ASN1_NULL_new(); |
|
327 } |
|
328 |
|
329 static int i2r_ocsp_serviceloc(X509V3_EXT_METHOD *method, void *in, BIO *bp, int ind) |
|
330 { |
|
331 int i; |
|
332 OCSP_SERVICELOC *a = in; |
|
333 ACCESS_DESCRIPTION *ad; |
|
334 |
|
335 if (BIO_printf(bp, "%*sIssuer: ", ind, "") <= 0) goto err; |
|
336 if (X509_NAME_print_ex(bp, a->issuer, 0, XN_FLAG_ONELINE) <= 0) goto err; |
|
337 for (i = 0; i < sk_ACCESS_DESCRIPTION_num(a->locator); i++) |
|
338 { |
|
339 ad = sk_ACCESS_DESCRIPTION_value(a->locator,i); |
|
340 if (BIO_printf(bp, "\n%*s", (2*ind), "") <= 0) |
|
341 goto err; |
|
342 if(i2a_ASN1_OBJECT(bp, ad->method) <= 0) goto err; |
|
343 if(BIO_puts(bp, " - ") <= 0) goto err; |
|
344 if(GENERAL_NAME_print(bp, ad->location) <= 0) goto err; |
|
345 } |
|
346 return 1; |
|
347 err: |
|
348 return 0; |
|
349 } |
|
350 #endif |