ssl/libcrypto/src/crypto/x509v3/v3_pcons.c
changeset 31 ce057bb09d0b
parent 0 e4d67989cc36
equal deleted inserted replaced
30:e20de85af2ee 31:ce057bb09d0b
       
     1 /* v3_pcons.c */
       
     2 /* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
       
     3  * project.
       
     4  */
       
     5 /* ====================================================================
       
     6  * Copyright (c) 2003 The OpenSSL Project.  All rights reserved.
       
     7  *
       
     8  * Redistribution and use in source and binary forms, with or without
       
     9  * modification, are permitted provided that the following conditions
       
    10  * are met:
       
    11  *
       
    12  * 1. Redistributions of source code must retain the above copyright
       
    13  *    notice, this list of conditions and the following disclaimer. 
       
    14  *
       
    15  * 2. Redistributions in binary form must reproduce the above copyright
       
    16  *    notice, this list of conditions and the following disclaimer in
       
    17  *    the documentation and/or other materials provided with the
       
    18  *    distribution.
       
    19  *
       
    20  * 3. All advertising materials mentioning features or use of this
       
    21  *    software must display the following acknowledgment:
       
    22  *    "This product includes software developed by the OpenSSL Project
       
    23  *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
       
    24  *
       
    25  * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
       
    26  *    endorse or promote products derived from this software without
       
    27  *    prior written permission. For written permission, please contact
       
    28  *    licensing@OpenSSL.org.
       
    29  *
       
    30  * 5. Products derived from this software may not be called "OpenSSL"
       
    31  *    nor may "OpenSSL" appear in their names without prior written
       
    32  *    permission of the OpenSSL Project.
       
    33  *
       
    34  * 6. Redistributions of any form whatsoever must retain the following
       
    35  *    acknowledgment:
       
    36  *    "This product includes software developed by the OpenSSL Project
       
    37  *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
       
    38  *
       
    39  * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
       
    40  * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
       
    41  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
       
    42  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
       
    43  * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
       
    44  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
       
    45  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
       
    46  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
       
    47  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
       
    48  * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
       
    49  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
       
    50  * OF THE POSSIBILITY OF SUCH DAMAGE.
       
    51  * ====================================================================
       
    52  *
       
    53  * This product includes cryptographic software written by Eric Young
       
    54  * (eay@cryptsoft.com).  This product includes software written by Tim
       
    55  * Hudson (tjh@cryptsoft.com).
       
    56  *
       
    57  */
       
    58  /*
       
    59  © Portions copyright (c) 2006 Nokia Corporation.  All rights reserved.
       
    60  */
       
    61 
       
    62 
       
    63 
       
    64 #include <stdio.h>
       
    65 #include "cryptlib.h"
       
    66 #include <openssl/asn1.h>
       
    67 #include <openssl/asn1t.h>
       
    68 #include <openssl/conf.h>
       
    69 #include <openssl/x509v3.h>
       
    70 #if (defined(SYMBIAN) && (defined(__WINSCW__) || defined(__WINS__)))
       
    71 #include "libcrypto_wsd_macros.h"
       
    72 #include "libcrypto_wsd.h"
       
    73 #endif
       
    74 
       
    75 
       
    76 static STACK_OF(CONF_VALUE) *i2v_POLICY_CONSTRAINTS(X509V3_EXT_METHOD *method,
       
    77 				void *bcons, STACK_OF(CONF_VALUE) *extlist);
       
    78 static void *v2i_POLICY_CONSTRAINTS(X509V3_EXT_METHOD *method,
       
    79 				X509V3_CTX *ctx, STACK_OF(CONF_VALUE) *values);
       
    80 
       
    81 #ifndef EMULATOR
       
    82 X509V3_EXT_METHOD v3_policy_constraints = {
       
    83 NID_policy_constraints, 0,
       
    84 ASN1_ITEM_ref(POLICY_CONSTRAINTS),
       
    85 0,0,0,0,
       
    86 0,0,
       
    87 i2v_POLICY_CONSTRAINTS,
       
    88 v2i_POLICY_CONSTRAINTS,
       
    89 NULL,NULL,
       
    90 NULL
       
    91 };
       
    92 #else
       
    93 X509V3_EXT_METHOD v3_policy_constraints = {
       
    94 NID_policy_constraints, 0,
       
    95 ASN1_ITEM_ref(POLICY_CONSTRAINTS),
       
    96 0,0,0,0,
       
    97 0,0,
       
    98 i2v_POLICY_CONSTRAINTS,
       
    99 v2i_POLICY_CONSTRAINTS,
       
   100 NULL,NULL,
       
   101 NULL
       
   102 };
       
   103 #endif
       
   104 ASN1_SEQUENCE(POLICY_CONSTRAINTS) = {
       
   105 	ASN1_IMP_OPT(POLICY_CONSTRAINTS, requireExplicitPolicy, ASN1_INTEGER,0),
       
   106 	ASN1_IMP_OPT(POLICY_CONSTRAINTS, inhibitPolicyMapping, ASN1_INTEGER,1)
       
   107 } ASN1_SEQUENCE_END(POLICY_CONSTRAINTS)
       
   108 
       
   109 IMPLEMENT_ASN1_ALLOC_FUNCTIONS(POLICY_CONSTRAINTS)
       
   110 
       
   111 
       
   112 static STACK_OF(CONF_VALUE) *i2v_POLICY_CONSTRAINTS(X509V3_EXT_METHOD *method,
       
   113 	     void *a, STACK_OF(CONF_VALUE) *extlist)
       
   114 {
       
   115 	POLICY_CONSTRAINTS *pcons = a;
       
   116 	X509V3_add_value_int("Require Explicit Policy",
       
   117 			pcons->requireExplicitPolicy, &extlist);
       
   118 	X509V3_add_value_int("Inhibit Policy Mapping",
       
   119 			pcons->inhibitPolicyMapping, &extlist);
       
   120 	return extlist;
       
   121 }
       
   122 
       
   123 static void *v2i_POLICY_CONSTRAINTS(X509V3_EXT_METHOD *method,
       
   124 	     X509V3_CTX *ctx, STACK_OF(CONF_VALUE) *values)
       
   125 {
       
   126 	POLICY_CONSTRAINTS *pcons=NULL;
       
   127 	CONF_VALUE *val;
       
   128 	int i;
       
   129 	if(!(pcons = POLICY_CONSTRAINTS_new())) {
       
   130 		X509V3err(X509V3_F_V2I_POLICY_CONSTRAINTS, ERR_R_MALLOC_FAILURE);
       
   131 		return NULL;
       
   132 	}
       
   133 	for(i = 0; i < sk_CONF_VALUE_num(values); i++) {
       
   134 		val = sk_CONF_VALUE_value(values, i);
       
   135 		if(!strcmp(val->name, "requireExplicitPolicy")) {
       
   136 			if(!X509V3_get_value_int(val,
       
   137 				&pcons->requireExplicitPolicy)) goto err;
       
   138 		} else if(!strcmp(val->name, "inhibitPolicyMapping")) {
       
   139 			if(!X509V3_get_value_int(val,
       
   140 				&pcons->inhibitPolicyMapping)) goto err;
       
   141 		} else {
       
   142 			X509V3err(X509V3_F_V2I_POLICY_CONSTRAINTS, X509V3_R_INVALID_NAME);
       
   143 			X509V3_conf_err(val);
       
   144 			goto err;
       
   145 		}
       
   146 	}
       
   147 	if (!pcons->inhibitPolicyMapping && !pcons->requireExplicitPolicy) {
       
   148 		X509V3err(X509V3_F_V2I_POLICY_CONSTRAINTS, X509V3_R_ILLEGAL_EMPTY_EXTENSION);
       
   149 		goto err;
       
   150 	}
       
   151 
       
   152 	return pcons;
       
   153 	err:
       
   154 	POLICY_CONSTRAINTS_free(pcons);
       
   155 	return NULL;
       
   156 }
       
   157