mirror of
https://git.gnunet.org/libmicrohttpd.git
synced 2026-10-07 04:02:18 +03:00
gnutls code cleanup
symbol refactoring
This commit is contained in:
1 parent
41886bcf92
commit
1c893a971f
129 files changed
+3935
-6783
No files matched your search
@@ -32,6 +32,5 @@ sign.c \
|
||||
x509_verify.c \
|
||||
x509.c \
|
||||
x509_write.c
|
||||
# output.c
|
||||
|
||||
|
||||
@@ -288,8 +288,8 @@ _gnutls_x509_oid_data2string (const char *oid,
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
_gnutls_str_cpy (str, sizeof (str), "PKIX1.");
|
||||
_gnutls_str_cat (str, sizeof (str), ANAME);
|
||||
mhd_gtls_str_cpy (str, sizeof (str), "PKIX1.");
|
||||
mhd_gtls_str_cat (str, sizeof (str), ANAME);
|
||||
|
||||
if ((result = asn1_create_element (_gnutls_get_pkix (), str,
|
||||
&tmpasn)) != ASN1_SUCCESS)
|
||||
@@ -323,7 +323,7 @@ _gnutls_x509_oid_data2string (const char *oid,
|
||||
str[len] = 0;
|
||||
|
||||
if (res)
|
||||
_gnutls_str_cpy (res, *res_size, str);
|
||||
mhd_gtls_str_cpy (res, *res_size, str);
|
||||
*res_size = len;
|
||||
|
||||
asn1_delete_structure (&tmpasn);
|
||||
@@ -345,7 +345,7 @@ _gnutls_x509_oid_data2string (const char *oid,
|
||||
if (strcmp (str, "teletexString") == 0)
|
||||
teletex = 1;
|
||||
|
||||
_gnutls_str_cpy (tmpname, sizeof (tmpname), str);
|
||||
mhd_gtls_str_cpy (tmpname, sizeof (tmpname), str);
|
||||
|
||||
len = sizeof (str) - 1;
|
||||
if ((result = asn1_read_value (tmpasn, tmpname, str, &len))
|
||||
@@ -376,7 +376,7 @@ _gnutls_x509_oid_data2string (const char *oid,
|
||||
if (non_printable == 0)
|
||||
{
|
||||
str[len] = 0;
|
||||
_gnutls_str_cpy (res, *res_size, str);
|
||||
mhd_gtls_str_cpy (res, *res_size, str);
|
||||
*res_size = len;
|
||||
}
|
||||
else
|
||||
@@ -411,7 +411,7 @@ _gnutls_x509_data2hex (const opaque * data,
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
res = _gnutls_bin2hex (data, data_size, escaped, sizeof (escaped));
|
||||
res = mhd_gtls_bin2hex (data, data_size, escaped, sizeof (escaped));
|
||||
|
||||
if (res)
|
||||
{
|
||||
@@ -694,7 +694,7 @@ _gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
|
||||
time_t c_time = (time_t) - 1;
|
||||
int len, result;
|
||||
|
||||
_gnutls_str_cpy (name, sizeof (name), when);
|
||||
mhd_gtls_str_cpy (name, sizeof (name), when);
|
||||
|
||||
len = sizeof (ttime) - 1;
|
||||
if ((result = asn1_read_value (c2, name, ttime, &len)) < 0)
|
||||
@@ -707,7 +707,7 @@ _gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
|
||||
if (strcmp (ttime, "generalTime") == 0)
|
||||
{
|
||||
|
||||
_gnutls_str_cat (name, sizeof (name), ".generalTime");
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".generalTime");
|
||||
len = sizeof (ttime) - 1;
|
||||
result = asn1_read_value (c2, name, ttime, &len);
|
||||
if (result == ASN1_SUCCESS)
|
||||
@@ -716,7 +716,7 @@ _gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
|
||||
else
|
||||
{ /* UTCTIME */
|
||||
|
||||
_gnutls_str_cat (name, sizeof (name), ".utcTime");
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".utcTime");
|
||||
len = sizeof (ttime) - 1;
|
||||
result = asn1_read_value (c2, name, ttime, &len);
|
||||
if (result == ASN1_SUCCESS)
|
||||
@@ -745,7 +745,7 @@ _gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim)
|
||||
char name[128];
|
||||
int result, len;
|
||||
|
||||
_gnutls_str_cpy (name, sizeof (name), where);
|
||||
mhd_gtls_str_cpy (name, sizeof (name), where);
|
||||
|
||||
if ((result = asn1_write_value (c2, name, "utcTime", 1)) < 0)
|
||||
{
|
||||
@@ -760,7 +760,7 @@ _gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim)
|
||||
return result;
|
||||
}
|
||||
|
||||
_gnutls_str_cat (name, sizeof (name), ".utcTime");
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".utcTime");
|
||||
|
||||
len = strlen (str_time);
|
||||
result = asn1_write_value (c2, name, str_time, len);
|
||||
@@ -894,11 +894,11 @@ _gnutls_x509_decode_octet_string (const char *string_type,
|
||||
char strname[64];
|
||||
|
||||
if (string_type == NULL)
|
||||
_gnutls_str_cpy (strname, sizeof (strname), "PKIX1.pkcs-7-Data");
|
||||
mhd_gtls_str_cpy (strname, sizeof (strname), "PKIX1.pkcs-7-Data");
|
||||
else
|
||||
{
|
||||
_gnutls_str_cpy (strname, sizeof (strname), "PKIX1.");
|
||||
_gnutls_str_cat (strname, sizeof (strname), string_type);
|
||||
mhd_gtls_str_cpy (strname, sizeof (strname), "PKIX1.");
|
||||
mhd_gtls_str_cat (strname, sizeof (strname), string_type);
|
||||
}
|
||||
|
||||
if ((result =
|
||||
@@ -1226,7 +1226,7 @@ _gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
int result;
|
||||
char name[128];
|
||||
|
||||
pk = _gnutls_x509_pk_to_oid (pk_algorithm);
|
||||
pk = mhd_gtls_x509_pk_to_oid (pk_algorithm);
|
||||
if (pk == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -1235,8 +1235,8 @@ _gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
|
||||
/* write the OID
|
||||
*/
|
||||
_gnutls_str_cpy (name, sizeof (name), dst_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".algorithm.algorithm");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".algorithm.algorithm");
|
||||
result = asn1_write_value (dst, name, pk, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -1248,8 +1248,8 @@ _gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
{
|
||||
/* disable parameters, which are not used in RSA.
|
||||
*/
|
||||
_gnutls_str_cpy (name, sizeof (name), dst_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".algorithm.parameters");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".algorithm.parameters");
|
||||
result = asn1_write_value (dst, name, NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -1266,8 +1266,8 @@ _gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
|
||||
/* Write the DER parameters. (in bits)
|
||||
*/
|
||||
_gnutls_str_cpy (name, sizeof (name), dst_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
result = asn1_write_value (dst, name, der.data, der.size * 8);
|
||||
|
||||
_gnutls_free_datum (&der);
|
||||
@@ -1299,8 +1299,8 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
mpi_t params[MAX_PUBLIC_PARAMS_SIZE];
|
||||
char name[128];
|
||||
|
||||
_gnutls_str_cpy (name, sizeof (name), src_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".algorithm.algorithm");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".algorithm.algorithm");
|
||||
|
||||
len = sizeof (oid);
|
||||
result = asn1_read_value (src, name, oid, &len);
|
||||
@@ -1311,7 +1311,7 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
algo = _gnutls_x509_oid2pk_algorithm (oid);
|
||||
algo = mhd_gtls_x509_oid2pk_algorithm (oid);
|
||||
|
||||
if (bits == NULL)
|
||||
{
|
||||
@@ -1321,8 +1321,8 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
|
||||
/* Now read the parameters' bits
|
||||
*/
|
||||
_gnutls_str_cpy (name, sizeof (name), src_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
|
||||
len = 0;
|
||||
result = asn1_read_value (src, name, NULL, &len);
|
||||
@@ -1347,8 +1347,8 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
_gnutls_str_cpy (name, sizeof (name), src_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
|
||||
result = asn1_read_value (src, name, str, &len);
|
||||
|
||||
@@ -1373,8 +1373,8 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
|
||||
bits[0] = _gnutls_mpi_get_nbits (params[0]);
|
||||
|
||||
_gnutls_mpi_release (¶ms[0]);
|
||||
_gnutls_mpi_release (¶ms[1]);
|
||||
mhd_gtls_mpi_release (¶ms[0]);
|
||||
mhd_gtls_mpi_release (¶ms[1]);
|
||||
}
|
||||
break;
|
||||
default:
|
||||
|
||||
@@ -305,7 +305,7 @@ gnutls_x509_crl_get_signature_algorithm (gnutls_x509_crl_t crl)
|
||||
return result;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_oid2sign_algorithm ((const char *) sa.data);
|
||||
result = mhd_gtls_x509_oid2sign_algorithm ((const char *) sa.data);
|
||||
|
||||
_gnutls_free_datum (&sa);
|
||||
|
||||
|
||||
@@ -338,8 +338,8 @@ parse_attribute (ASN1_TYPE asn1_struct,
|
||||
*/
|
||||
/* Read the OID
|
||||
*/
|
||||
_gnutls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer1);
|
||||
_gnutls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer1);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
|
||||
|
||||
+41
-41
@@ -91,7 +91,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name, char *buf,
|
||||
size_t * sizeof_buf)
|
||||
{
|
||||
gnutls_string out_str;
|
||||
mhd_gtls_string out_str;
|
||||
int k2, k1, result;
|
||||
char tmpbuffer1[MAX_NAME_SIZE];
|
||||
char tmpbuffer2[MAX_NAME_SIZE];
|
||||
@@ -115,7 +115,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
else
|
||||
*sizeof_buf = 0;
|
||||
|
||||
_gnutls_string_init (&out_str, gnutls_malloc, gnutls_realloc, gnutls_free);
|
||||
mhd_gtls_string_init (&out_str, gnutls_malloc, gnutls_realloc, gnutls_free);
|
||||
|
||||
k1 = 0;
|
||||
do
|
||||
@@ -175,8 +175,8 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
|
||||
/* Read the OID
|
||||
*/
|
||||
_gnutls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
_gnutls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
|
||||
@@ -192,8 +192,8 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
|
||||
/* Read the Value
|
||||
*/
|
||||
_gnutls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
_gnutls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
|
||||
len = 0;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, NULL, &len);
|
||||
@@ -214,7 +214,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
result = _gnutls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
#define STR_APPEND(y) if ((result=_gnutls_string_append_str( &out_str, y)) < 0) { \
|
||||
#define STR_APPEND(y) if ((result=mhd_gtls_string_append_str( &out_str, y)) < 0) { \
|
||||
gnutls_assert(); \
|
||||
goto cleanup; \
|
||||
}
|
||||
@@ -280,7 +280,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log
|
||||
("Found OID: '%s' with value '%s'\n",
|
||||
oid, _gnutls_bin2hex (value2, len, escaped, sizeof_escaped));
|
||||
oid, mhd_gtls_bin2hex (value2, len, escaped, sizeof_escaped));
|
||||
goto cleanup;
|
||||
}
|
||||
STR_APPEND (str_escape (string, escaped, sizeof_escaped));
|
||||
@@ -319,7 +319,7 @@ cleanup:
|
||||
gnutls_free (value2);
|
||||
gnutls_free (string);
|
||||
gnutls_free (escaped);
|
||||
_gnutls_string_clear (&out_str);
|
||||
mhd_gtls_string_clear (&out_str);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -418,8 +418,8 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
|
||||
/* Read the OID
|
||||
*/
|
||||
_gnutls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
_gnutls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
|
||||
@@ -438,8 +438,8 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
|
||||
/* Read the Value
|
||||
*/
|
||||
_gnutls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
_gnutls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
|
||||
len = *sizeof_buf;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, buf, &len);
|
||||
@@ -587,8 +587,8 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
|
||||
|
||||
/* Read the OID
|
||||
*/
|
||||
_gnutls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
_gnutls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
|
||||
@@ -660,8 +660,8 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
return GNUTLS_E_X509_UNSUPPORTED_OID;
|
||||
}
|
||||
|
||||
_gnutls_str_cpy (tmp, sizeof (tmp), "PKIX1.");
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), val_name);
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), "PKIX1.");
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), val_name);
|
||||
|
||||
result = asn1_create_element (_gnutls_get_pkix (), tmp, &c2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -702,7 +702,7 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
_gnutls_str_cpy (tmp, sizeof (tmp), string_type);
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), string_type);
|
||||
}
|
||||
|
||||
result = asn1_write_value (c2, tmp, data, sizeof_data);
|
||||
@@ -717,12 +717,12 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
/* write the data (value)
|
||||
*/
|
||||
|
||||
_gnutls_str_cpy (tmp, sizeof (tmp), where);
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), ".value");
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".value");
|
||||
|
||||
if (multi != 0)
|
||||
{ /* if not writing an AttributeTypeAndValue, but an Attribute */
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), "s"); /* values */
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), "s"); /* values */
|
||||
|
||||
result = asn1_write_value (asn1_struct, tmp, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -731,7 +731,7 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), ".?LAST");
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
|
||||
|
||||
}
|
||||
|
||||
@@ -744,8 +744,8 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
|
||||
/* write the type
|
||||
*/
|
||||
_gnutls_str_cpy (tmp, sizeof (tmp), where);
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), ".type");
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".type");
|
||||
|
||||
result = asn1_write_value (asn1_struct, tmp, given_oid, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -772,12 +772,12 @@ _gnutls_x509_write_attribute (const char *given_oid,
|
||||
/* write the data (value)
|
||||
*/
|
||||
|
||||
_gnutls_str_cpy (tmp, sizeof (tmp), where);
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), ".value");
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".value");
|
||||
|
||||
if (multi != 0)
|
||||
{ /* if not writing an AttributeTypeAndValue, but an Attribute */
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), "s"); /* values */
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), "s"); /* values */
|
||||
|
||||
result = asn1_write_value (asn1_struct, tmp, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -786,7 +786,7 @@ _gnutls_x509_write_attribute (const char *given_oid,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), ".?LAST");
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
|
||||
|
||||
}
|
||||
|
||||
@@ -799,8 +799,8 @@ _gnutls_x509_write_attribute (const char *given_oid,
|
||||
|
||||
/* write the type
|
||||
*/
|
||||
_gnutls_str_cpy (tmp, sizeof (tmp), where);
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), ".type");
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".type");
|
||||
|
||||
result = asn1_write_value (asn1_struct, tmp, given_oid, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -832,8 +832,8 @@ _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
|
||||
|
||||
/* Read the OID
|
||||
*/
|
||||
_gnutls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
|
||||
_gnutls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".type");
|
||||
mhd_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
|
||||
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".type");
|
||||
|
||||
len = oid_size - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer, oid, &len);
|
||||
@@ -848,11 +848,11 @@ _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
|
||||
/* Read the Value
|
||||
*/
|
||||
|
||||
_gnutls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
|
||||
_gnutls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".value");
|
||||
mhd_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
|
||||
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".value");
|
||||
|
||||
if (multi)
|
||||
_gnutls_str_cat (tmpbuffer, sizeof (tmpbuffer), "s.?1"); /* .values.?1 */
|
||||
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), "s.?1"); /* .values.?1 */
|
||||
|
||||
result =
|
||||
_gnutls_x509_read_value (asn1_struct, tmpbuffer, value, octet_string);
|
||||
@@ -896,8 +896,8 @@ _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
_gnutls_str_cpy (asn1_rdn_name, sizeof (asn1_rdn_name), asn1_name);
|
||||
_gnutls_str_cat (asn1_rdn_name, sizeof (asn1_rdn_name), ".rdnSequence");
|
||||
mhd_gtls_str_cpy (asn1_rdn_name, sizeof (asn1_rdn_name), asn1_name);
|
||||
mhd_gtls_str_cat (asn1_rdn_name, sizeof (asn1_rdn_name), ".rdnSequence");
|
||||
|
||||
/* create a new element
|
||||
*/
|
||||
@@ -908,8 +908,8 @@ _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
_gnutls_str_cpy (tmp, sizeof (tmp), asn1_rdn_name);
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), ".?LAST");
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), asn1_rdn_name);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
|
||||
|
||||
/* create the set with only one element
|
||||
*/
|
||||
@@ -923,8 +923,8 @@ _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
|
||||
|
||||
/* Encode and write the data
|
||||
*/
|
||||
_gnutls_str_cpy (tmp, sizeof (tmp), asn1_rdn_name);
|
||||
_gnutls_str_cat (tmp, sizeof (tmp), ".?LAST.?LAST");
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), asn1_rdn_name);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".?LAST.?LAST");
|
||||
|
||||
if (!raw_flag)
|
||||
{
|
||||
|
||||
@@ -82,8 +82,8 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
do
|
||||
{
|
||||
|
||||
_gnutls_str_cpy (name2, sizeof (name2), name);
|
||||
_gnutls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
|
||||
len = sizeof (extnID) - 1;
|
||||
result = asn1_read_value (cert->cert, name2, extnID, &len);
|
||||
@@ -108,8 +108,8 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
|
||||
/* read the critical status.
|
||||
*/
|
||||
_gnutls_str_cpy (name2, sizeof (name2), name);
|
||||
_gnutls_str_cat (name2, sizeof (name2), ".critical");
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".critical");
|
||||
|
||||
len = sizeof (str_critical);
|
||||
result =
|
||||
@@ -133,8 +133,8 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
|
||||
/* read the value.
|
||||
*/
|
||||
_gnutls_str_cpy (name2, sizeof (name2), name);
|
||||
_gnutls_str_cat (name2, sizeof (name2), ".extnValue");
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".extnValue");
|
||||
|
||||
result = _gnutls_x509_read_value (cert->cert, name2, &value, 0);
|
||||
if (result < 0)
|
||||
@@ -206,8 +206,8 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
do
|
||||
{
|
||||
|
||||
_gnutls_str_cpy (name2, sizeof (name2), name);
|
||||
_gnutls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
|
||||
len = sizeof (extnID) - 1;
|
||||
result = asn1_read_value (cert->cert, name2, extnID, &len);
|
||||
@@ -335,8 +335,8 @@ overwrite_extension (ASN1_TYPE asn, unsigned int indx,
|
||||
else
|
||||
str = "TRUE";
|
||||
|
||||
_gnutls_str_cpy (name2, sizeof (name2), name);
|
||||
_gnutls_str_cat (name2, sizeof (name2), ".critical");
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".critical");
|
||||
|
||||
result = asn1_write_value (asn, name2, str, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -345,8 +345,8 @@ overwrite_extension (ASN1_TYPE asn, unsigned int indx,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
_gnutls_str_cpy (name2, sizeof (name2), name);
|
||||
_gnutls_str_cat (name2, sizeof (name2), ".extnValue");
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".extnValue");
|
||||
|
||||
result = _gnutls_x509_write_value (asn, name2, ext_data, 0);
|
||||
if (result < 0)
|
||||
@@ -397,8 +397,8 @@ _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
|
||||
do
|
||||
{
|
||||
|
||||
_gnutls_str_cpy (name2, sizeof (name2), name);
|
||||
_gnutls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
|
||||
len = sizeof (extnID) - 1;
|
||||
result = asn1_read_value (cert->cert, name2, extnID, &len);
|
||||
@@ -687,12 +687,12 @@ write_new_general_name (ASN1_TYPE ext, const char *ext_name,
|
||||
|
||||
if (ext_name[0] == 0)
|
||||
{ /* no dot */
|
||||
_gnutls_str_cpy (name, sizeof (name), "?LAST");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), "?LAST");
|
||||
}
|
||||
else
|
||||
{
|
||||
_gnutls_str_cpy (name, sizeof (name), ext_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".?LAST");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), ext_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".?LAST");
|
||||
}
|
||||
|
||||
result = asn1_write_value (ext, name, str, 1);
|
||||
@@ -702,8 +702,8 @@ write_new_general_name (ASN1_TYPE ext, const char *ext_name,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
_gnutls_str_cat (name, sizeof (name), ".");
|
||||
_gnutls_str_cat (name, sizeof (name), str);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".");
|
||||
mhd_gtls_str_cat (name, sizeof (name), str);
|
||||
|
||||
result = asn1_write_value (ext, name, data_string, strlen (data_string));
|
||||
if (result != ASN1_SUCCESS)
|
||||
|
||||
+13
-13
@@ -71,7 +71,7 @@ _gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
_gnutls_x509_read_int (spk, "publicExponent", ¶ms[1])) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_mpi_release (¶ms[0]);
|
||||
mhd_gtls_mpi_release (¶ms[0]);
|
||||
asn1_delete_structure (&spk);
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
@@ -129,7 +129,7 @@ _gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&spk);
|
||||
_gnutls_mpi_release (¶ms[0]);
|
||||
mhd_gtls_mpi_release (¶ms[0]);
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
|
||||
@@ -139,8 +139,8 @@ _gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&spk);
|
||||
_gnutls_mpi_release (¶ms[0]);
|
||||
_gnutls_mpi_release (¶ms[1]);
|
||||
mhd_gtls_mpi_release (¶ms[0]);
|
||||
mhd_gtls_mpi_release (¶ms[1]);
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
|
||||
@@ -343,10 +343,10 @@ _gnutls_x509_write_sig_params (ASN1_TYPE dst,
|
||||
char name[128];
|
||||
const char *pk;
|
||||
|
||||
_gnutls_str_cpy (name, sizeof (name), dst_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".algorithm");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".algorithm");
|
||||
|
||||
pk = _gnutls_x509_sign_to_oid (pk_algorithm, HASH2MAC (dig));
|
||||
pk = mhd_gtls_x509_sign_to_oid (pk_algorithm, HASH2MAC (dig));
|
||||
if (pk == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -362,8 +362,8 @@ _gnutls_x509_write_sig_params (ASN1_TYPE dst,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
_gnutls_str_cpy (name, sizeof (name), dst_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".parameters");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".parameters");
|
||||
|
||||
if (pk_algorithm == MHD_GNUTLS_PK_RSA)
|
||||
{ /* RSA */
|
||||
@@ -536,11 +536,11 @@ _gnutls_x509_read_uint (ASN1_TYPE node, const char *value, unsigned int *ret)
|
||||
if (len == 1)
|
||||
*ret = tmpstr[0];
|
||||
else if (len == 2)
|
||||
*ret = _gnutls_read_uint16 (tmpstr);
|
||||
*ret = mhd_gtls_read_uint16 (tmpstr);
|
||||
else if (len == 3)
|
||||
*ret = _gnutls_read_uint24 (tmpstr);
|
||||
*ret = mhd_gtls_read_uint24 (tmpstr);
|
||||
else if (len == 4)
|
||||
*ret = _gnutls_read_uint32 (tmpstr);
|
||||
*ret = mhd_gtls_read_uint32 (tmpstr);
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -561,7 +561,7 @@ _gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value, uint32_t num)
|
||||
opaque tmpstr[4];
|
||||
int result;
|
||||
|
||||
_gnutls_write_uint32 (num, tmpstr);
|
||||
mhd_gtls_write_uint32 (num, tmpstr);
|
||||
|
||||
result = asn1_write_value (node, value, tmpstr, 4);
|
||||
|
||||
|
||||
@@ -1,1360 +0,0 @@
|
||||
/*
|
||||
* Copyright (C) 2007 Free Software Foundation
|
||||
*
|
||||
* Author: Simon Josefsson
|
||||
*
|
||||
* This file is part of GNUTLS.
|
||||
*
|
||||
* The GNUTLS library is free software; you can redistribute it and/or
|
||||
* modify it under the terms of the GNU Lesser General Public License
|
||||
* as published by the Free Software Foundation; either version 2.1 of
|
||||
* the License, or (at your option) any later version.
|
||||
*
|
||||
* This library is distributed in the hope that it will be useful, but
|
||||
* WITHOUT ANY WARRANTY; without even the implied warranty of
|
||||
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
||||
* Lesser General Public License for more details.
|
||||
*
|
||||
* You should have received a copy of the GNU Lesser General Public
|
||||
* License along with this library; if not, write to the Free Software
|
||||
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA
|
||||
* 02110-1301, USA
|
||||
*
|
||||
*/
|
||||
|
||||
/* Functions for printing X.509 Certificate structures
|
||||
*/
|
||||
|
||||
#include <gnutls_int.h>
|
||||
#include <common.h>
|
||||
#include <gnutls_x509.h>
|
||||
#include <x509.h>
|
||||
#include <gnutls_errors.h>
|
||||
|
||||
/* I18n of error codes. */
|
||||
#include "gettext.h"
|
||||
#define _(String) dgettext (PACKAGE, String)
|
||||
#define N_(String) gettext_noop (String)
|
||||
|
||||
#define addf _gnutls_string_append_printf
|
||||
#define adds _gnutls_string_append_str
|
||||
|
||||
static void
|
||||
hexdump (gnutls_string * str, const char *data, size_t len, const char *spc)
|
||||
{
|
||||
size_t j;
|
||||
|
||||
if (spc)
|
||||
adds (str, spc);
|
||||
for (j = 0; j < len; j++)
|
||||
{
|
||||
if (((j + 1) % 16) == 0)
|
||||
{
|
||||
addf (str, "%.2x\n", (unsigned char) data[j]);
|
||||
if (spc && j != (len - 1))
|
||||
adds (str, spc);
|
||||
}
|
||||
else if (j == (len - 1))
|
||||
addf (str, "%.2x", (unsigned char) data[j]);
|
||||
else
|
||||
addf (str, "%.2x:", (unsigned char) data[j]);
|
||||
}
|
||||
if ((j % 16) != 0)
|
||||
adds (str, "\n");
|
||||
}
|
||||
|
||||
static void
|
||||
hexprint (gnutls_string * str, const char *data, size_t len)
|
||||
{
|
||||
size_t j;
|
||||
|
||||
if (len == 0)
|
||||
adds (str, "00");
|
||||
else
|
||||
{
|
||||
for (j = 0; j < len; j++)
|
||||
addf (str, "%.2x", (unsigned char) data[j]);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
static void
|
||||
asciiprint (gnutls_string * str, const char *data, size_t len)
|
||||
{
|
||||
size_t j;
|
||||
|
||||
for (j = 0; j < len; j++)
|
||||
if (isprint (data[j]))
|
||||
addf (str, "%c", (unsigned char) data[j]);
|
||||
else
|
||||
addf (str, ".");
|
||||
}
|
||||
|
||||
static void
|
||||
print_proxy (gnutls_string * str, gnutls_x509_crt_t cert)
|
||||
{
|
||||
int pathlen;
|
||||
char *policyLanguage;
|
||||
char *policy;
|
||||
size_t npolicy;
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_proxy (cert, NULL,
|
||||
&pathlen, &policyLanguage,
|
||||
&policy, &npolicy);
|
||||
if (err < 0)
|
||||
{
|
||||
addf (str, "error: get_proxy: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
if (pathlen >= 0)
|
||||
addf (str, _("\t\t\tPath Length Constraint: %d\n"), pathlen);
|
||||
addf (str, _("\t\t\tPolicy Language: %s"), policyLanguage);
|
||||
if (strcmp (policyLanguage, "1.3.6.1.5.5.7.21.1") == 0)
|
||||
adds (str, " (id-ppl-inheritALL)\n");
|
||||
else if (strcmp (policyLanguage, "1.3.6.1.5.5.7.21.2") == 0)
|
||||
adds (str, " (id-ppl-independent)\n");
|
||||
else
|
||||
adds (str, "\n");
|
||||
if (npolicy)
|
||||
{
|
||||
adds (str, _("\t\t\tPolicy:\n\t\t\t\tASCII: "));
|
||||
asciiprint (str, policy, npolicy);
|
||||
adds (str, _("\n\t\t\t\tHexdump: "));
|
||||
hexprint (str, policy, npolicy);
|
||||
adds (str, "\n");
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
print_ski (gnutls_string * str, gnutls_x509_crt_t cert)
|
||||
{
|
||||
char *buffer = NULL;
|
||||
size_t size = 0;
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_subject_key_id (cert, buffer, &size, NULL);
|
||||
if (err != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
addf (str, "error: get_subject_key_id: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
buffer = gnutls_malloc (size);
|
||||
if (!buffer)
|
||||
{
|
||||
addf (str, "error: malloc: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
err = gnutls_x509_crt_get_subject_key_id (cert, buffer, &size, NULL);
|
||||
if (err < 0)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: get_subject_key_id2: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
adds (str, "\t\t\t");
|
||||
hexprint (str, buffer, size);
|
||||
adds (str, "\n");
|
||||
|
||||
gnutls_free (buffer);
|
||||
}
|
||||
|
||||
static void
|
||||
print_aki (gnutls_string * str, gnutls_x509_crt_t cert)
|
||||
{
|
||||
char *buffer = NULL;
|
||||
size_t size = 0;
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_authority_key_id (cert, buffer, &size, NULL);
|
||||
if (err != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
addf (str, "error: get_authority_key_id: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
buffer = gnutls_malloc (size);
|
||||
if (!buffer)
|
||||
{
|
||||
addf (str, "error: malloc: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
err = gnutls_x509_crt_get_authority_key_id (cert, buffer, &size, NULL);
|
||||
if (err < 0)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: get_authority_key_id2: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
adds (str, "\t\t\t");
|
||||
hexprint (str, buffer, size);
|
||||
adds (str, "\n");
|
||||
|
||||
gnutls_free (buffer);
|
||||
}
|
||||
|
||||
static void
|
||||
print_key_usage (gnutls_string * str, gnutls_x509_crt_t cert)
|
||||
{
|
||||
unsigned int key_usage;
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_key_usage (cert, &key_usage, NULL);
|
||||
if (err < 0)
|
||||
{
|
||||
addf (str, "error: get_key_usage: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
if (key_usage & GNUTLS_KEY_DIGITAL_SIGNATURE)
|
||||
addf (str, _("\t\t\tDigital signature.\n"));
|
||||
if (key_usage & GNUTLS_KEY_NON_REPUDIATION)
|
||||
addf (str, _("\t\t\tNon repudiation.\n"));
|
||||
if (key_usage & GNUTLS_KEY_KEY_ENCIPHERMENT)
|
||||
addf (str, _("\t\t\tKey encipherment.\n"));
|
||||
if (key_usage & GNUTLS_KEY_DATA_ENCIPHERMENT)
|
||||
addf (str, _("\t\t\tData encipherment.\n"));
|
||||
if (key_usage & GNUTLS_KEY_KEY_AGREEMENT)
|
||||
addf (str, _("\t\t\tKey agreement.\n"));
|
||||
if (key_usage & GNUTLS_KEY_KEY_CERT_SIGN)
|
||||
addf (str, _("\t\t\tCertificate signing.\n"));
|
||||
if (key_usage & GNUTLS_KEY_CRL_SIGN)
|
||||
addf (str, _("\t\t\tCRL signing.\n"));
|
||||
if (key_usage & GNUTLS_KEY_ENCIPHER_ONLY)
|
||||
addf (str, _("\t\t\tKey encipher only.\n"));
|
||||
if (key_usage & GNUTLS_KEY_DECIPHER_ONLY)
|
||||
addf (str, _("\t\t\tKey decipher only.\n"));
|
||||
}
|
||||
|
||||
static void
|
||||
print_crldist (gnutls_string * str, gnutls_x509_crt_t cert)
|
||||
{
|
||||
char *buffer = NULL;
|
||||
size_t size;
|
||||
int err;
|
||||
int indx;
|
||||
|
||||
for (indx = 0;; indx++)
|
||||
{
|
||||
size = 0;
|
||||
err = gnutls_x509_crt_get_crl_dist_points (cert, indx, buffer, &size,
|
||||
NULL, NULL);
|
||||
if (err == GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE)
|
||||
return;
|
||||
if (err != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
addf (str, "error: get_crl_dist_points: %s\n",
|
||||
gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
buffer = gnutls_malloc (size);
|
||||
if (!buffer)
|
||||
{
|
||||
addf (str, "error: malloc: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
err = gnutls_x509_crt_get_crl_dist_points (cert, indx, buffer, &size,
|
||||
NULL, NULL);
|
||||
if (err < 0)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: get_crl_dist_points2: %s\n",
|
||||
gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
switch (err)
|
||||
{
|
||||
case GNUTLS_SAN_DNSNAME:
|
||||
addf (str, "\t\t\tDNSname: %.*s\n", size, buffer);
|
||||
break;
|
||||
|
||||
case GNUTLS_SAN_RFC822NAME:
|
||||
addf (str, "\t\t\tRFC822name: %.*s\n", size, buffer);
|
||||
break;
|
||||
|
||||
case GNUTLS_SAN_URI:
|
||||
addf (str, "\t\t\tURI: %.*s\n", size, buffer);
|
||||
break;
|
||||
|
||||
case GNUTLS_SAN_IPADDRESS:
|
||||
addf (str, "\t\t\tIPAddress: %.*s\n", size, buffer);
|
||||
break;
|
||||
|
||||
case GNUTLS_SAN_DN:
|
||||
addf (str, "\t\t\tdirectoryName: %.*s\n", size, buffer);
|
||||
break;
|
||||
|
||||
default:
|
||||
addf (str, "error: unknown SAN\n");
|
||||
break;
|
||||
}
|
||||
gnutls_free (buffer);
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
print_key_purpose (gnutls_string * str, gnutls_x509_crt_t cert)
|
||||
{
|
||||
int indx;
|
||||
char *buffer = NULL;
|
||||
size_t size;
|
||||
int err;
|
||||
|
||||
for (indx = 0;; indx++)
|
||||
{
|
||||
size = 0;
|
||||
err = gnutls_x509_crt_get_key_purpose_oid (cert, indx, buffer,
|
||||
&size, NULL);
|
||||
if (err == GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE)
|
||||
return;
|
||||
if (err != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
addf (str, "error: get_key_purpose_oid: %s\n",
|
||||
gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
buffer = gnutls_malloc (size);
|
||||
if (!buffer)
|
||||
{
|
||||
addf (str, "error: malloc: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
err = gnutls_x509_crt_get_key_purpose_oid (cert, indx, buffer,
|
||||
&size, NULL);
|
||||
if (err < 0)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: get_key_purpose_oid2: %s\n",
|
||||
gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
if (strcmp (buffer, GNUTLS_KP_TLS_WWW_SERVER) == 0)
|
||||
addf (str, _("\t\t\tTLS WWW Server.\n"));
|
||||
else if (strcmp (buffer, GNUTLS_KP_TLS_WWW_CLIENT) == 0)
|
||||
addf (str, _("\t\t\tTLS WWW Client.\n"));
|
||||
else if (strcmp (buffer, GNUTLS_KP_CODE_SIGNING) == 0)
|
||||
addf (str, _("\t\t\tCode signing.\n"));
|
||||
else if (strcmp (buffer, GNUTLS_KP_EMAIL_PROTECTION) == 0)
|
||||
addf (str, _("\t\t\tEmail protection.\n"));
|
||||
else if (strcmp (buffer, GNUTLS_KP_TIME_STAMPING) == 0)
|
||||
addf (str, _("\t\t\tTime stamping.\n"));
|
||||
else if (strcmp (buffer, GNUTLS_KP_OCSP_SIGNING) == 0)
|
||||
addf (str, _("\t\t\tOCSP signing.\n"));
|
||||
else if (strcmp (buffer, GNUTLS_KP_ANY) == 0)
|
||||
addf (str, _("\t\t\tAny purpose.\n"));
|
||||
else
|
||||
addf (str, "\t\t\t%s\n", buffer);
|
||||
|
||||
gnutls_free (buffer);
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
print_basic (gnutls_string * str, gnutls_x509_crt_t cert)
|
||||
{
|
||||
int pathlen;
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_basic_constraints (cert, NULL, NULL, &pathlen);
|
||||
if (err < 0)
|
||||
{
|
||||
addf (str, "error: get_basic_constraints: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
if (err == 0)
|
||||
addf (str, _("\t\t\tCertificate Authority (CA): FALSE\n"));
|
||||
else
|
||||
addf (str, _("\t\t\tCertificate Authority (CA): TRUE\n"));
|
||||
|
||||
if (pathlen >= 0)
|
||||
addf (str, _("\t\t\tPath Length Constraint: %d\n"), pathlen);
|
||||
}
|
||||
|
||||
static void
|
||||
print_san (gnutls_string * str, gnutls_x509_crt_t cert)
|
||||
{
|
||||
unsigned int san_idx;
|
||||
|
||||
for (san_idx = 0;; san_idx++)
|
||||
{
|
||||
char *buffer = NULL;
|
||||
size_t size = 0;
|
||||
int err;
|
||||
|
||||
err =
|
||||
gnutls_x509_crt_get_subject_alt_name (cert, san_idx, buffer, &size,
|
||||
NULL);
|
||||
if (err == GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE)
|
||||
break;
|
||||
if (err != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
addf (str, "error: get_subject_alt_name: %s\n",
|
||||
gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
buffer = gnutls_malloc (size);
|
||||
if (!buffer)
|
||||
{
|
||||
addf (str, "error: malloc: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
err = gnutls_x509_crt_get_subject_alt_name (cert, san_idx,
|
||||
buffer, &size, NULL);
|
||||
if (err < 0)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: get_subject_alt_name2: %s\n",
|
||||
gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
switch (err)
|
||||
{
|
||||
case GNUTLS_SAN_DNSNAME:
|
||||
addf (str, "\t\t\tDNSname: %.*s\n", size, buffer);
|
||||
break;
|
||||
|
||||
case GNUTLS_SAN_RFC822NAME:
|
||||
addf (str, "\t\t\tRFC822name: %.*s\n", size, buffer);
|
||||
break;
|
||||
|
||||
case GNUTLS_SAN_URI:
|
||||
addf (str, "\t\t\tURI: %.*s\n", size, buffer);
|
||||
break;
|
||||
|
||||
case GNUTLS_SAN_IPADDRESS:
|
||||
addf (str, "\t\t\tIPAddress: %.*s\n", size, buffer);
|
||||
break;
|
||||
|
||||
case GNUTLS_SAN_DN:
|
||||
addf (str, "\t\t\tdirectoryName: %.*s\n", size, buffer);
|
||||
break;
|
||||
|
||||
case GNUTLS_SAN_OTHERNAME:
|
||||
{
|
||||
char *oid = NULL;
|
||||
size_t oidsize;
|
||||
|
||||
oidsize = 0;
|
||||
err = gnutls_x509_crt_get_subject_alt_othername_oid
|
||||
(cert, san_idx, oid, &oidsize);
|
||||
if (err != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: get_subject_alt_othername_oid: %s\n",
|
||||
gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
oid = gnutls_malloc (oidsize);
|
||||
if (!oid)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: malloc: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
err = gnutls_x509_crt_get_subject_alt_othername_oid
|
||||
(cert, san_idx, oid, &oidsize);
|
||||
if (err < 0)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
gnutls_free (oid);
|
||||
addf (str, "error: get_subject_alt_othername_oid2: %s\n",
|
||||
gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
if (err == GNUTLS_SAN_OTHERNAME_XMPP)
|
||||
addf (str, _("\t\t\tXMPP Address: %.*s\n"), size, buffer);
|
||||
else
|
||||
{
|
||||
addf (str, _("\t\t\totherName OID: %.*s\n"), oidsize, oid);
|
||||
addf (str, _("\t\t\totherName DER: "));
|
||||
hexprint (str, buffer, size);
|
||||
addf (str, _("\n\t\t\totherName ASCII: "));
|
||||
asciiprint (str, buffer, size);
|
||||
addf (str, "\n");
|
||||
}
|
||||
gnutls_free (oid);
|
||||
}
|
||||
break;
|
||||
|
||||
default:
|
||||
addf (str, "error: unknown SAN\n");
|
||||
break;
|
||||
}
|
||||
|
||||
gnutls_free (buffer);
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
print_cert (gnutls_string * str, gnutls_x509_crt_t cert, int notsigned)
|
||||
{
|
||||
/* Version. */
|
||||
{
|
||||
int version = gnutls_x509_crt_get_version (cert);
|
||||
if (version < 0)
|
||||
addf (str, "error: get_version: %s\n", gnutls_strerror (version));
|
||||
else
|
||||
addf (str, _("\tVersion: %d\n"), version);
|
||||
}
|
||||
|
||||
/* Serial. */
|
||||
{
|
||||
char serial[128];
|
||||
size_t serial_size = sizeof (serial);
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_serial (cert, serial, &serial_size);
|
||||
if (err < 0)
|
||||
addf (str, "error: get_serial: %s\n", gnutls_strerror (err));
|
||||
else
|
||||
{
|
||||
addf (str, _("\tSerial Number (hex): "));
|
||||
hexprint (str, serial, serial_size);
|
||||
addf (str, "\n");
|
||||
}
|
||||
}
|
||||
|
||||
/* Issuer. */
|
||||
if (!notsigned)
|
||||
{
|
||||
char dn[1024];
|
||||
size_t dn_size = sizeof (dn);
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_issuer_dn (cert, dn, &dn_size);
|
||||
if (err < 0)
|
||||
addf (str, "error: get_issuer_dn: %s\n", gnutls_strerror (err));
|
||||
else
|
||||
addf (str, _("\tIssuer: %s\n"), dn);
|
||||
}
|
||||
|
||||
/* Validity. */
|
||||
{
|
||||
time_t tim;
|
||||
|
||||
addf (str, _("\tValidity:\n"));
|
||||
|
||||
tim = gnutls_x509_crt_get_activation_time (cert);
|
||||
{
|
||||
char s[42];
|
||||
size_t max = sizeof (s);
|
||||
struct tm t;
|
||||
|
||||
if (gmtime_r (&tim, &t) == NULL)
|
||||
addf (str, "error: gmtime_r (%d)\n", t);
|
||||
else if (strftime (s, max, "%a %b %e %H:%M:%S UTC %Y", &t) == 0)
|
||||
addf (str, "error: strftime (%d)\n", t);
|
||||
else
|
||||
addf (str, _("\t\tNot Before: %s\n"), s);
|
||||
}
|
||||
|
||||
tim = gnutls_x509_crt_get_expiration_time (cert);
|
||||
{
|
||||
char s[42];
|
||||
size_t max = sizeof (s);
|
||||
struct tm t;
|
||||
|
||||
if (gmtime_r (&tim, &t) == NULL)
|
||||
addf (str, "error: gmtime_r (%d)\n", t);
|
||||
else if (strftime (s, max, "%a %b %e %H:%M:%S UTC %Y", &t) == 0)
|
||||
addf (str, "error: strftime (%d)\n", t);
|
||||
else
|
||||
addf (str, _("\t\tNot After: %s\n"), s);
|
||||
}
|
||||
}
|
||||
|
||||
/* Subject. */
|
||||
{
|
||||
char dn[1024];
|
||||
size_t dn_size = sizeof (dn);
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_dn (cert, dn, &dn_size);
|
||||
if (err < 0)
|
||||
addf (str, "error: get_dn: %s\n", gnutls_strerror (err));
|
||||
else
|
||||
addf (str, _("\tSubject: %s\n"), dn);
|
||||
}
|
||||
|
||||
/* SubjectPublicKeyInfo. */
|
||||
{
|
||||
int err;
|
||||
unsigned int bits;
|
||||
|
||||
err = gnutls_x509_crt_get_pk_algorithm (cert, &bits);
|
||||
if (err < 0)
|
||||
addf (str, "error: get_pk_algorithm: %s\n", gnutls_strerror (err));
|
||||
else
|
||||
{
|
||||
const char *name = gnutls_pk_algorithm_get_name (err);
|
||||
if (name == NULL)
|
||||
name = "Unknown";
|
||||
|
||||
addf (str, _("\tSubject Public Key Algorithm: %s\n"), name);
|
||||
switch (err)
|
||||
{
|
||||
case MHD_GNUTLS_PK_RSA:
|
||||
{
|
||||
gnutls_datum_t m, e;
|
||||
|
||||
err = gnutls_x509_crt_get_pk_rsa_raw (cert, &m, &e);
|
||||
if (err < 0)
|
||||
addf (str, "error: get_pk_rsa_raw: %s\n",
|
||||
gnutls_strerror (err));
|
||||
else
|
||||
{
|
||||
addf (str, _("\t\tModulus (bits %d):\n"), bits);
|
||||
hexdump (str, m.data, m.size, "\t\t\t");
|
||||
addf (str, _("\t\tExponent:\n"));
|
||||
hexdump (str, e.data, e.size, "\t\t\t");
|
||||
}
|
||||
|
||||
gnutls_free (m.data);
|
||||
gnutls_free (e.data);
|
||||
}
|
||||
break;
|
||||
|
||||
case GNUTLS_PK_DSA:
|
||||
{
|
||||
gnutls_datum_t p, q, g, y;
|
||||
|
||||
err = gnutls_x509_crt_get_pk_dsa_raw (cert, &p, &q, &g, &y);
|
||||
if (err < 0)
|
||||
addf (str, "error: get_pk_dsa_raw: %s\n",
|
||||
gnutls_strerror (err));
|
||||
else
|
||||
{
|
||||
addf (str, _("\t\tPublic key (bits %d):\n"), bits);
|
||||
hexdump (str, y.data, y.size, "\t\t\t");
|
||||
addf (str, _("\t\tP:\n"));
|
||||
hexdump (str, p.data, p.size, "\t\t\t");
|
||||
addf (str, _("\t\tQ:\n"));
|
||||
hexdump (str, q.data, q.size, "\t\t\t");
|
||||
addf (str, _("\t\tG:\n"));
|
||||
hexdump (str, g.data, g.size, "\t\t\t");
|
||||
}
|
||||
}
|
||||
break;
|
||||
|
||||
default:
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/* Extensions. */
|
||||
if (gnutls_x509_crt_get_version (cert) >= 3)
|
||||
{
|
||||
size_t i;
|
||||
int err = 0;
|
||||
|
||||
for (i = 0;; i++)
|
||||
{
|
||||
char oid[128] = "";
|
||||
size_t sizeof_oid = sizeof (oid);
|
||||
int critical;
|
||||
size_t san_idx = 0;
|
||||
size_t proxy_idx = 0;
|
||||
size_t basic_idx = 0;
|
||||
size_t keyusage_idx = 0;
|
||||
size_t keypurpose_idx = 0;
|
||||
size_t ski_idx = 0;
|
||||
size_t aki_idx = 0;
|
||||
size_t crldist_idx = 0;
|
||||
|
||||
err = gnutls_x509_crt_get_extension_info (cert, i,
|
||||
oid, &sizeof_oid,
|
||||
&critical);
|
||||
if (err < 0)
|
||||
{
|
||||
if (err == GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE)
|
||||
break;
|
||||
addf (str, "error: get_extension_info: %s\n",
|
||||
gnutls_strerror (err));
|
||||
continue;
|
||||
}
|
||||
|
||||
if (i == 0)
|
||||
addf (str, _("\tExtensions:\n"));
|
||||
|
||||
if (strcmp (oid, "2.5.29.19") == 0)
|
||||
{
|
||||
if (basic_idx)
|
||||
{
|
||||
addf (str, "error: more than one basic constraint\n");
|
||||
continue;
|
||||
}
|
||||
|
||||
addf (str, _("\t\tBasic Constraints (%s):\n"),
|
||||
critical ? _("critical") : _("not critical"));
|
||||
|
||||
print_basic (str, cert);
|
||||
|
||||
basic_idx++;
|
||||
}
|
||||
else if (strcmp (oid, "2.5.29.14") == 0)
|
||||
{
|
||||
if (ski_idx)
|
||||
{
|
||||
addf (str, "error: more than one SKI extension\n");
|
||||
continue;
|
||||
}
|
||||
|
||||
addf (str, _("\t\tSubject Key Identifier (%s):\n"),
|
||||
critical ? _("critical") : _("not critical"));
|
||||
|
||||
print_ski (str, cert);
|
||||
|
||||
ski_idx++;
|
||||
}
|
||||
else if (strcmp (oid, "2.5.29.35") == 0)
|
||||
{
|
||||
if (aki_idx)
|
||||
{
|
||||
addf (str, "error: more than one AKI extension\n");
|
||||
continue;
|
||||
}
|
||||
|
||||
addf (str, _("\t\tAuthority Key Identifier (%s):\n"),
|
||||
critical ? _("critical") : _("not critical"));
|
||||
|
||||
print_aki (str, cert);
|
||||
|
||||
aki_idx++;
|
||||
}
|
||||
else if (strcmp (oid, "2.5.29.15") == 0)
|
||||
{
|
||||
if (keyusage_idx)
|
||||
{
|
||||
addf (str, "error: more than one key usage extension\n");
|
||||
continue;
|
||||
}
|
||||
|
||||
addf (str, _("\t\tKey Usage (%s):\n"),
|
||||
critical ? _("critical") : _("not critical"));
|
||||
|
||||
print_key_usage (str, cert);
|
||||
|
||||
keyusage_idx++;
|
||||
}
|
||||
else if (strcmp (oid, "2.5.29.37") == 0)
|
||||
{
|
||||
if (keypurpose_idx)
|
||||
{
|
||||
addf (str, "error: more than one key purpose extension\n");
|
||||
continue;
|
||||
}
|
||||
|
||||
addf (str, _("\t\tKey Purpose (%s):\n"),
|
||||
critical ? _("critical") : _("not critical"));
|
||||
|
||||
print_key_purpose (str, cert);
|
||||
|
||||
keypurpose_idx++;
|
||||
}
|
||||
else if (strcmp (oid, "2.5.29.17") == 0)
|
||||
{
|
||||
if (san_idx)
|
||||
{
|
||||
addf (str, "error: more than one SKI extension\n");
|
||||
continue;
|
||||
}
|
||||
|
||||
addf (str, _("\t\tSubject Alternative Name (%s):\n"),
|
||||
critical ? _("critical") : _("not critical"));
|
||||
|
||||
print_san (str, cert);
|
||||
|
||||
san_idx++;
|
||||
}
|
||||
else if (strcmp (oid, "2.5.29.31") == 0)
|
||||
{
|
||||
if (crldist_idx)
|
||||
{
|
||||
addf (str, "error: more than one CRL distribution point\n");
|
||||
continue;
|
||||
}
|
||||
|
||||
addf (str, _("\t\tCRL Distribution points (%s):\n"),
|
||||
critical ? _("critical") : _("not critical"));
|
||||
|
||||
print_crldist (str, cert);
|
||||
|
||||
crldist_idx++;
|
||||
}
|
||||
else if (strcmp (oid, "1.3.6.1.5.5.7.1.14") == 0)
|
||||
{
|
||||
if (proxy_idx)
|
||||
{
|
||||
addf (str, "error: more than one proxy extension\n");
|
||||
continue;
|
||||
}
|
||||
|
||||
addf (str, _("\t\tProxy Certificate Information (%s):\n"),
|
||||
critical ? _("critical") : _("not critical"));
|
||||
|
||||
print_proxy (str, cert);
|
||||
|
||||
proxy_idx++;
|
||||
}
|
||||
else
|
||||
{
|
||||
char *buffer;
|
||||
size_t extlen = 0;
|
||||
|
||||
addf (str, _("\t\tUnknown extension %s (%s):\n"), oid,
|
||||
critical ? _("critical") : _("not critical"));
|
||||
|
||||
err = gnutls_x509_crt_get_extension_data (cert, i,
|
||||
NULL, &extlen);
|
||||
if (err < 0)
|
||||
{
|
||||
addf (str, "error: get_extension_data: %s\n",
|
||||
gnutls_strerror (err));
|
||||
continue;
|
||||
}
|
||||
|
||||
buffer = gnutls_malloc (extlen);
|
||||
if (!buffer)
|
||||
{
|
||||
addf (str, "error: malloc: %s\n", gnutls_strerror (err));
|
||||
continue;
|
||||
}
|
||||
|
||||
err = gnutls_x509_crt_get_extension_data (cert, i,
|
||||
buffer, &extlen);
|
||||
if (err < 0)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: get_extension_data2: %s\n",
|
||||
gnutls_strerror (err));
|
||||
continue;
|
||||
}
|
||||
|
||||
addf (str, _("\t\t\tASCII: "));
|
||||
asciiprint (str, buffer, extlen);
|
||||
addf (str, "\n");
|
||||
|
||||
addf (str, _("\t\t\tHexdump: "));
|
||||
hexprint (str, buffer, extlen);
|
||||
adds (str, "\n");
|
||||
|
||||
gnutls_free (buffer);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/* Signature. */
|
||||
if (!notsigned)
|
||||
{
|
||||
int err;
|
||||
size_t size = 0;
|
||||
char *buffer = NULL;
|
||||
|
||||
err = gnutls_x509_crt_get_signature_algorithm (cert);
|
||||
if (err < 0)
|
||||
addf (str, "error: get_signature_algorithm: %s\n",
|
||||
gnutls_strerror (err));
|
||||
else
|
||||
{
|
||||
const char *name = gnutls_sign_algorithm_get_name (err);
|
||||
if (name == NULL)
|
||||
name = "Unknown";
|
||||
addf (str, _("\tSignature Algorithm: %s\n"), name);
|
||||
}
|
||||
if (err == GNUTLS_SIGN_RSA_MD5 || err == GNUTLS_SIGN_RSA_MD2)
|
||||
{
|
||||
addf (str,
|
||||
_
|
||||
("warning: signed using a broken signature algorithm that can be forged.\n"));
|
||||
}
|
||||
|
||||
err = gnutls_x509_crt_get_signature (cert, buffer, &size);
|
||||
if (err != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
addf (str, "error: get_signature: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
buffer = gnutls_malloc (size);
|
||||
if (!buffer)
|
||||
{
|
||||
addf (str, "error: malloc: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
err = gnutls_x509_crt_get_signature (cert, buffer, &size);
|
||||
if (err < 0)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: get_signature2: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
addf (str, _("\tSignature:\n"));
|
||||
hexdump (str, buffer, size, "\t\t");
|
||||
|
||||
gnutls_free (buffer);
|
||||
}
|
||||
}
|
||||
|
||||
static void
|
||||
print_fingerprint (gnutls_string * str, gnutls_x509_crt_t cert,
|
||||
gnutls_digest_algorithm_t algo)
|
||||
{
|
||||
int err;
|
||||
char buffer[MAX_HASH_SIZE];
|
||||
size_t size = sizeof (buffer);
|
||||
|
||||
err = gnutls_x509_crt_get_fingerprint (cert, algo, buffer, &size);
|
||||
if (err < 0)
|
||||
{
|
||||
addf (str, "error: get_fingerprint: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
if (algo == MHD_GNUTLS_DIG_MD5)
|
||||
addf (str, _("\tMD5 fingerprint:\n\t\t"));
|
||||
else
|
||||
addf (str, _("\tSHA-1 fingerprint:\n\t\t"));
|
||||
hexprint (str, buffer, size);
|
||||
adds (str, "\n");
|
||||
}
|
||||
|
||||
static void
|
||||
print_keyid (gnutls_string * str, gnutls_x509_crt_t cert)
|
||||
{
|
||||
int err;
|
||||
size_t size = 0;
|
||||
char *buffer = NULL;
|
||||
|
||||
err = gnutls_x509_crt_get_key_id (cert, 0, buffer, &size);
|
||||
if (err != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
addf (str, "error: get_key_id: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
buffer = gnutls_malloc (size);
|
||||
if (!buffer)
|
||||
{
|
||||
addf (str, "error: malloc: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
err = gnutls_x509_crt_get_key_id (cert, 0, buffer, &size);
|
||||
if (err < 0)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: get_key_id2: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
addf (str, _("\tPublic Key Id:\n\t\t"));
|
||||
hexprint (str, buffer, size);
|
||||
adds (str, "\n");
|
||||
|
||||
gnutls_free (buffer);
|
||||
}
|
||||
|
||||
static void
|
||||
print_other (gnutls_string * str, gnutls_x509_crt_t cert, int notsigned)
|
||||
{
|
||||
if (!notsigned)
|
||||
{
|
||||
print_fingerprint (str, cert, MHD_GNUTLS_DIG_MD5);
|
||||
print_fingerprint (str, cert, MHD_GNUTLS_DIG_SHA1);
|
||||
}
|
||||
print_keyid (str, cert);
|
||||
}
|
||||
|
||||
static void
|
||||
print_oneline (gnutls_string * str, gnutls_x509_crt_t cert)
|
||||
{
|
||||
|
||||
/* Subject. */
|
||||
{
|
||||
char dn[1024];
|
||||
size_t dn_size = sizeof (dn);
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_dn (cert, dn, &dn_size);
|
||||
if (err < 0)
|
||||
addf (str, "unknown subject (%s), ", gnutls_strerror (err));
|
||||
else
|
||||
addf (str, "subject `%s', ", dn);
|
||||
}
|
||||
|
||||
/* Issuer. */
|
||||
{
|
||||
char dn[1024];
|
||||
size_t dn_size = sizeof (dn);
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_issuer_dn (cert, dn, &dn_size);
|
||||
if (err < 0)
|
||||
addf (str, "unknown issuer (%s), ", gnutls_strerror (err));
|
||||
else
|
||||
addf (str, "issuer `%s', ", dn);
|
||||
}
|
||||
|
||||
{
|
||||
int bits;
|
||||
const char *name = gnutls_pk_algorithm_get_name
|
||||
(gnutls_x509_crt_get_pk_algorithm (cert, &bits));
|
||||
if (name == NULL)
|
||||
name = "Unknown";
|
||||
addf (str, "%s key %d bits, ", name, bits);
|
||||
}
|
||||
|
||||
/* Validity. */
|
||||
{
|
||||
time_t tim;
|
||||
|
||||
tim = gnutls_x509_crt_get_activation_time (cert);
|
||||
{
|
||||
char s[42];
|
||||
size_t max = sizeof (s);
|
||||
struct tm t;
|
||||
|
||||
if (gmtime_r (&tim, &t) == NULL)
|
||||
addf (str, "unknown activation (%d), ", t);
|
||||
else if (strftime (s, max, "%Y-%m-%d %H:%M:%S UTC", &t) == 0)
|
||||
addf (str, "failed activation (%d), ", t);
|
||||
else
|
||||
addf (str, "activated `%s', ", s);
|
||||
}
|
||||
|
||||
tim = gnutls_x509_crt_get_expiration_time (cert);
|
||||
{
|
||||
char s[42];
|
||||
size_t max = sizeof (s);
|
||||
struct tm t;
|
||||
|
||||
if (gmtime_r (&tim, &t) == NULL)
|
||||
addf (str, "unknown expiry (%d), ", t);
|
||||
else if (strftime (s, max, "%Y-%m-%d %H:%M:%S UTC", &t) == 0)
|
||||
addf (str, "failed expiry (%d), ", t);
|
||||
else
|
||||
addf (str, "expires `%s', ", s);
|
||||
}
|
||||
}
|
||||
|
||||
{
|
||||
int pathlen;
|
||||
char *policyLanguage;
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_proxy (cert, NULL,
|
||||
&pathlen, &policyLanguage, NULL, NULL);
|
||||
if (err == 0)
|
||||
{
|
||||
addf (str, "proxy certificate (policy=");
|
||||
if (strcmp (policyLanguage, "1.3.6.1.5.5.7.21.1") == 0)
|
||||
addf (str, "id-ppl-inheritALL");
|
||||
else if (strcmp (policyLanguage, "1.3.6.1.5.5.7.21.2") == 0)
|
||||
addf (str, "id-ppl-independent");
|
||||
else
|
||||
addf (str, "%s", policyLanguage);
|
||||
if (pathlen >= 0)
|
||||
addf (str, ", pathlen=%d), ", pathlen);
|
||||
else
|
||||
addf (str, "), ");
|
||||
gnutls_free (policyLanguage);
|
||||
}
|
||||
}
|
||||
|
||||
{
|
||||
char buffer[20];
|
||||
size_t size = sizeof (buffer);
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crt_get_fingerprint (cert, MHD_GNUTLS_DIG_SHA1,
|
||||
buffer, &size);
|
||||
if (err < 0)
|
||||
{
|
||||
addf (str, "unknown fingerprint (%s)", gnutls_strerror (err));
|
||||
}
|
||||
else
|
||||
{
|
||||
addf (str, "SHA-1 fingerprint `");
|
||||
hexprint (str, buffer, size);
|
||||
adds (str, "'");
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_print - Pretty print X.509 certificates
|
||||
* @cert: The structure to be printed
|
||||
* @format: Indicate the format to use
|
||||
* @out: Newly allocated datum with zero terminated string.
|
||||
*
|
||||
* This function will pretty print a X.509 certificate, suitable for
|
||||
* display to a human.
|
||||
*
|
||||
* If the format is %GNUTLS_X509_CRT_FULL then all fields of the
|
||||
* certificate will be output, on multiple lines. The
|
||||
* %GNUTLS_X509_CRT_ONELINE format will generate one line with some
|
||||
* selected fields, which is useful for logging purposes.
|
||||
*
|
||||
* The output @out needs to be deallocate using gnutls_free().
|
||||
*
|
||||
* Returns 0 on success.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_print (gnutls_x509_crt_t cert,
|
||||
gnutls_certificate_print_formats_t format,
|
||||
gnutls_datum_t * out)
|
||||
{
|
||||
gnutls_string str;
|
||||
|
||||
if (format == GNUTLS_X509_CRT_FULL
|
||||
|| format == GNUTLS_X509_CRT_UNSIGNED_FULL)
|
||||
{
|
||||
_gnutls_string_init (&str, gnutls_malloc, gnutls_realloc, gnutls_free);
|
||||
|
||||
_gnutls_string_append_str (&str, _("X.509 Certificate Information:\n"));
|
||||
|
||||
print_cert (&str, cert, format == GNUTLS_X509_CRT_UNSIGNED_FULL);
|
||||
|
||||
_gnutls_string_append_str (&str, _("Other Information:\n"));
|
||||
|
||||
print_other (&str, cert, format == GNUTLS_X509_CRT_UNSIGNED_FULL);
|
||||
|
||||
_gnutls_string_append_data (&str, "\0", 1);
|
||||
out->data = str.data;
|
||||
out->size = strlen (str.data);
|
||||
}
|
||||
else if (format == GNUTLS_X509_CRT_ONELINE)
|
||||
{
|
||||
_gnutls_string_init (&str, gnutls_malloc, gnutls_realloc, gnutls_free);
|
||||
|
||||
print_oneline (&str, cert);
|
||||
|
||||
_gnutls_string_append_data (&str, "\0", 1);
|
||||
out->data = str.data;
|
||||
out->size = strlen (str.data);
|
||||
}
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
static void
|
||||
print_crl (gnutls_string * str, gnutls_x509_crl_t crl, int notsigned)
|
||||
{
|
||||
/* Version. */
|
||||
{
|
||||
int version = gnutls_x509_crl_get_version (crl);
|
||||
if (version == GNUTLS_E_ASN1_ELEMENT_NOT_FOUND)
|
||||
addf (str, _("\tVersion: 1 (default)\n"));
|
||||
else if (version < 0)
|
||||
addf (str, "error: get_version: %s\n", gnutls_strerror (version));
|
||||
else
|
||||
addf (str, _("\tVersion: %d\n"), version);
|
||||
}
|
||||
|
||||
/* Issuer. */
|
||||
if (!notsigned)
|
||||
{
|
||||
char dn[1024];
|
||||
size_t dn_size = sizeof (dn);
|
||||
int err;
|
||||
|
||||
err = gnutls_x509_crl_get_issuer_dn (crl, dn, &dn_size);
|
||||
if (err < 0)
|
||||
addf (str, "error: get_issuer_dn: %s\n", gnutls_strerror (err));
|
||||
else
|
||||
addf (str, _("\tIssuer: %s\n"), dn);
|
||||
}
|
||||
|
||||
/* Validity. */
|
||||
{
|
||||
time_t tim;
|
||||
|
||||
addf (str, _("\tUpdate dates:\n"));
|
||||
|
||||
tim = gnutls_x509_crl_get_this_update (crl);
|
||||
{
|
||||
char s[42];
|
||||
size_t max = sizeof (s);
|
||||
struct tm t;
|
||||
|
||||
if (gmtime_r (&tim, &t) == NULL)
|
||||
addf (str, "error: gmtime_r (%d)\n", t);
|
||||
else if (strftime (s, max, "%a %b %e %H:%M:%S UTC %Y", &t) == 0)
|
||||
addf (str, "error: strftime (%d)\n", t);
|
||||
else
|
||||
addf (str, _("\t\tIssued: %s\n"), s);
|
||||
}
|
||||
|
||||
tim = gnutls_x509_crl_get_next_update (crl);
|
||||
{
|
||||
char s[42];
|
||||
size_t max = sizeof (s);
|
||||
struct tm t;
|
||||
|
||||
if (tim == -1)
|
||||
addf (str, "\t\tNo next update time.\n");
|
||||
else if (gmtime_r (&tim, &t) == NULL)
|
||||
addf (str, "error: gmtime_r (%d)\n", t);
|
||||
else if (strftime (s, max, "%a %b %e %H:%M:%S UTC %Y", &t) == 0)
|
||||
addf (str, "error: strftime (%d)\n", t);
|
||||
else
|
||||
addf (str, _("\t\tNext at: %s\n"), s);
|
||||
}
|
||||
}
|
||||
|
||||
/* Revoked certificates. */
|
||||
{
|
||||
int num = gnutls_x509_crl_get_crt_count (crl);
|
||||
int j;
|
||||
|
||||
if (num)
|
||||
addf (str, _("\tRevoked certificates (%d):\n"), num);
|
||||
else
|
||||
addf (str, _("\tNo revoked certificates.\n"));
|
||||
|
||||
for (j = 0; j < num; j++)
|
||||
{
|
||||
char serial[128];
|
||||
size_t serial_size = sizeof (serial);
|
||||
int err;
|
||||
time_t tim;
|
||||
|
||||
err = gnutls_x509_crl_get_crt_serial (crl, j, serial,
|
||||
&serial_size, &tim);
|
||||
if (err < 0)
|
||||
addf (str, "error: get_crt_serial: %s\n", gnutls_strerror (err));
|
||||
else
|
||||
{
|
||||
char s[42];
|
||||
size_t max = sizeof (s);
|
||||
struct tm t;
|
||||
|
||||
addf (str, _("\t\tSerial Number (hex): "));
|
||||
hexprint (str, serial, serial_size);
|
||||
adds (str, "\n");
|
||||
|
||||
if (gmtime_r (&tim, &t) == NULL)
|
||||
addf (str, "error: gmtime_r (%d)\n", t);
|
||||
else if (strftime (s, max, "%a %b %e %H:%M:%S UTC %Y", &t) == 0)
|
||||
addf (str, "error: strftime (%d)\n", t);
|
||||
else
|
||||
addf (str, _("\t\tRevoked at: %s\n"), s);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/* Signature. */
|
||||
if (!notsigned)
|
||||
{
|
||||
int err;
|
||||
size_t size = 0;
|
||||
char *buffer = NULL;
|
||||
|
||||
err = gnutls_x509_crl_get_signature_algorithm (crl);
|
||||
if (err < 0)
|
||||
addf (str, "error: get_signature_algorithm: %s\n",
|
||||
gnutls_strerror (err));
|
||||
else
|
||||
{
|
||||
const char *name = gnutls_sign_algorithm_get_name (err);
|
||||
if (name == NULL)
|
||||
name = "Unknown";
|
||||
addf (str, _("\tSignature Algorithm: %s\n"), name);
|
||||
}
|
||||
if (err == GNUTLS_SIGN_RSA_MD5 || err == GNUTLS_SIGN_RSA_MD2)
|
||||
{
|
||||
addf (str,
|
||||
_
|
||||
("warning: signed using a broken signature algorithm that can be forged.\n"));
|
||||
}
|
||||
|
||||
err = gnutls_x509_crl_get_signature (crl, buffer, &size);
|
||||
if (err != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
addf (str, "error: get_signature: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
buffer = gnutls_malloc (size);
|
||||
if (!buffer)
|
||||
{
|
||||
addf (str, "error: malloc: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
err = gnutls_x509_crl_get_signature (crl, buffer, &size);
|
||||
if (err < 0)
|
||||
{
|
||||
gnutls_free (buffer);
|
||||
addf (str, "error: get_signature2: %s\n", gnutls_strerror (err));
|
||||
return;
|
||||
}
|
||||
|
||||
addf (str, _("\tSignature:\n"));
|
||||
hexdump (str, buffer, size, "\t\t");
|
||||
|
||||
gnutls_free (buffer);
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_print - Pretty print X.509 certificate revocation list
|
||||
* @crl: The structure to be printed
|
||||
* @format: Indicate the format to use
|
||||
* @out: Newly allocated datum with zero terminated string.
|
||||
*
|
||||
* This function will pretty print a X.509 certificate revocation
|
||||
* list, suitable for display to a human.
|
||||
*
|
||||
* The output @out needs to be deallocate using gnutls_free().
|
||||
*
|
||||
* Returns 0 on success.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_print (gnutls_x509_crl_t crl,
|
||||
gnutls_certificate_print_formats_t format,
|
||||
gnutls_datum_t * out)
|
||||
{
|
||||
gnutls_string str;
|
||||
|
||||
_gnutls_string_init (&str, gnutls_malloc, gnutls_realloc, gnutls_free);
|
||||
|
||||
_gnutls_string_append_str
|
||||
(&str, _("X.509 Certificate Revocation List Information:\n"));
|
||||
|
||||
print_crl (&str, crl, format == GNUTLS_X509_CRT_UNSIGNED_FULL);
|
||||
|
||||
_gnutls_string_append_data (&str, "\0", 1);
|
||||
out->data = str.data;
|
||||
out->size = strlen (str.data);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -161,7 +161,7 @@ gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12)
|
||||
* gnutls_pkcs12_deinit - This function deinitializes memory used by a gnutls_pkcs12_t structure
|
||||
* @pkcs12: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a PKCS12 structure.
|
||||
* This function will deinitialize a PKCS12 structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
@@ -338,7 +338,7 @@ ucs2_to_ascii (char *data, int size)
|
||||
}
|
||||
|
||||
/* Decodes the SafeContents, and puts the output in
|
||||
* the given bag.
|
||||
* the given bag.
|
||||
*/
|
||||
int
|
||||
_pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
@@ -760,7 +760,7 @@ gnutls_pkcs12_set_bag (gnutls_pkcs12_t pkcs12, gnutls_pkcs12_bag_t bag)
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Step 3. Encode the bag elements into a SafeContents
|
||||
/* Step 3. Encode the bag elements into a SafeContents
|
||||
* structure.
|
||||
*/
|
||||
result = _pkcs12_encode_safe_contents (bag, &safe_cont, &enc);
|
||||
@@ -924,7 +924,7 @@ gnutls_pkcs12_generate_mac (gnutls_pkcs12_t pkcs12, const char *pass)
|
||||
|
||||
/* MAC the data
|
||||
*/
|
||||
td1 = _gnutls_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
|
||||
td1 = mhd_gtls_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
|
||||
if (td1 == GNUTLS_MAC_FAILED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -932,10 +932,10 @@ gnutls_pkcs12_generate_mac (gnutls_pkcs12_t pkcs12, const char *pass)
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
_gnutls_hmac (td1, tmp.data, tmp.size);
|
||||
mhd_gnutls_hash (td1, tmp.data, tmp.size);
|
||||
_gnutls_free_datum (&tmp);
|
||||
|
||||
_gnutls_hmac_deinit (td1, sha_mac);
|
||||
mhd_gnutls_hmac_deinit (td1, sha_mac);
|
||||
|
||||
|
||||
result =
|
||||
@@ -1050,7 +1050,7 @@ gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass)
|
||||
|
||||
/* MAC the data
|
||||
*/
|
||||
td1 = _gnutls_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
|
||||
td1 = mhd_gtls_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
|
||||
if (td1 == GNUTLS_MAC_FAILED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -1058,10 +1058,10 @@ gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass)
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
_gnutls_hmac (td1, tmp.data, tmp.size);
|
||||
mhd_gnutls_hash (td1, tmp.data, tmp.size);
|
||||
_gnutls_free_datum (&tmp);
|
||||
|
||||
_gnutls_hmac_deinit (td1, sha_mac);
|
||||
mhd_gnutls_hmac_deinit (td1, sha_mac);
|
||||
|
||||
len = sizeof (sha_mac_orig);
|
||||
result =
|
||||
@@ -1126,8 +1126,8 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
_gnutls_str_cpy (root, sizeof (root), where);
|
||||
_gnutls_str_cat (root, sizeof (root), ".?LAST");
|
||||
mhd_gtls_str_cpy (root, sizeof (root), where);
|
||||
mhd_gtls_str_cat (root, sizeof (root), ".?LAST");
|
||||
|
||||
result =
|
||||
_gnutls_x509_encode_and_write_attribute (KEY_ID_OID, c2, root,
|
||||
@@ -1176,8 +1176,8 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
|
||||
p++;
|
||||
}
|
||||
|
||||
_gnutls_str_cpy (root, sizeof (root), where);
|
||||
_gnutls_str_cat (root, sizeof (root), ".?LAST");
|
||||
mhd_gtls_str_cpy (root, sizeof (root), where);
|
||||
mhd_gtls_str_cat (root, sizeof (root), ".?LAST");
|
||||
|
||||
result =
|
||||
_gnutls_x509_encode_and_write_attribute (FRIENDLY_NAME_OID, c2,
|
||||
|
||||
@@ -134,7 +134,7 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
for (i = 0; i < 64; i++)
|
||||
buf_b[i] = hash[i % 20];
|
||||
n = 64;
|
||||
rc = _gnutls_mpi_scan (&num_b1, buf_b, &n);
|
||||
rc = mhd_gtls_mpi_scan (&num_b1, buf_b, &n);
|
||||
if (rc < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -146,7 +146,7 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
mpi_t num_ij;
|
||||
|
||||
n = 64;
|
||||
rc = _gnutls_mpi_scan (&num_ij, buf_i + i, &n);
|
||||
rc = mhd_gtls_mpi_scan (&num_ij, buf_i + i, &n);
|
||||
if (rc < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -155,7 +155,7 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
gcry_mpi_add (num_ij, num_ij, num_b1);
|
||||
gcry_mpi_clear_highbit (num_ij, 64 * 8);
|
||||
n = 64;
|
||||
rc = _gnutls_mpi_print (buf_i + i, &n, num_ij);
|
||||
rc = mhd_gtls_mpi_print (buf_i + i, &n, num_ij);
|
||||
if (rc < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
|
||||
@@ -1424,7 +1424,7 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
|
||||
if (kdf_params->key_size == 0)
|
||||
{
|
||||
key_size = gnutls_cipher_get_key_size (enc_params->cipher);
|
||||
key_size = MHD_gnutls_cipher_get_key_size (enc_params->cipher);
|
||||
}
|
||||
else
|
||||
key_size = kdf_params->key_size;
|
||||
@@ -1474,7 +1474,7 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
|
||||
d_iv.data = (opaque *) enc_params->iv;
|
||||
d_iv.size = enc_params->iv_size;
|
||||
ch = _gnutls_cipher_init (enc_params->cipher, &dkey, &d_iv);
|
||||
ch = mhd_gtls_cipher_init (enc_params->cipher, &dkey, &d_iv);
|
||||
|
||||
gnutls_afree (key);
|
||||
key = NULL;
|
||||
@@ -1486,7 +1486,7 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = _gnutls_cipher_decrypt (ch, data, data_size);
|
||||
result = mhd_gtls_cipher_decrypt (ch, data, data_size);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -1495,12 +1495,12 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
|
||||
decrypted_data->data = data;
|
||||
|
||||
if (_gnutls_cipher_get_block_size (enc_params->cipher) != 1)
|
||||
if (mhd_gtls_cipher_get_block_size (enc_params->cipher) != 1)
|
||||
decrypted_data->size = data_size - data[data_size - 1];
|
||||
else
|
||||
decrypted_data->size = data_size;
|
||||
|
||||
_gnutls_cipher_deinit (ch);
|
||||
mhd_gnutls_cipher_deinit (ch);
|
||||
|
||||
return 0;
|
||||
|
||||
@@ -1508,7 +1508,7 @@ error:
|
||||
gnutls_free (data);
|
||||
gnutls_afree (key);
|
||||
if (ch != NULL)
|
||||
_gnutls_cipher_deinit (ch);
|
||||
mhd_gnutls_cipher_deinit (ch);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -1568,7 +1568,7 @@ write_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
|
||||
/* write the iteration count
|
||||
*/
|
||||
_gnutls_write_uint32 (kdf_params->iter_count, tmp);
|
||||
mhd_gtls_write_uint32 (kdf_params->iter_count, tmp);
|
||||
|
||||
result = asn1_write_value (pbkdf2_asn, "iterationCount", tmp, 4);
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -1727,9 +1727,9 @@ generate_key (schema_id schema,
|
||||
|
||||
kdf_params->iter_count = 256 + rnd[0];
|
||||
key->size = kdf_params->key_size =
|
||||
gnutls_cipher_get_key_size (enc_params->cipher);
|
||||
MHD_gnutls_cipher_get_key_size (enc_params->cipher);
|
||||
|
||||
enc_params->iv_size = _gnutls_cipher_get_iv_size (enc_params->cipher);
|
||||
enc_params->iv_size = mhd_gtls_cipher_get_iv_size (enc_params->cipher);
|
||||
|
||||
key->data = gnutls_secure_malloc (key->size);
|
||||
if (key->data == NULL)
|
||||
@@ -1893,7 +1893,7 @@ encrypt_data (const gnutls_datum_t * plain,
|
||||
cipher_hd_t ch = NULL;
|
||||
opaque pad, pad_size;
|
||||
|
||||
pad_size = _gnutls_cipher_get_block_size (enc_params->cipher);
|
||||
pad_size = mhd_gtls_cipher_get_block_size (enc_params->cipher);
|
||||
|
||||
if (pad_size == 1) /* stream */
|
||||
pad_size = 0;
|
||||
@@ -1921,7 +1921,7 @@ encrypt_data (const gnutls_datum_t * plain,
|
||||
|
||||
d_iv.data = (opaque *) enc_params->iv;
|
||||
d_iv.size = enc_params->iv_size;
|
||||
ch = _gnutls_cipher_init (enc_params->cipher, key, &d_iv);
|
||||
ch = mhd_gtls_cipher_init (enc_params->cipher, key, &d_iv);
|
||||
|
||||
if (ch == GNUTLS_CIPHER_FAILED)
|
||||
{
|
||||
@@ -1930,7 +1930,7 @@ encrypt_data (const gnutls_datum_t * plain,
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = _gnutls_cipher_encrypt (ch, data, data_size);
|
||||
result = mhd_gtls_cipher_encrypt (ch, data, data_size);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -1940,14 +1940,14 @@ encrypt_data (const gnutls_datum_t * plain,
|
||||
encrypted->data = data;
|
||||
encrypted->size = data_size;
|
||||
|
||||
_gnutls_cipher_deinit (ch);
|
||||
mhd_gnutls_cipher_deinit (ch);
|
||||
|
||||
return 0;
|
||||
|
||||
error:
|
||||
gnutls_free (data);
|
||||
if (ch != NULL)
|
||||
_gnutls_cipher_deinit (ch);
|
||||
mhd_gnutls_cipher_deinit (ch);
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
@@ -56,7 +56,7 @@ encode_ber_digest_info (gnutls_digest_algorithm_t hash,
|
||||
int result;
|
||||
const char *algo;
|
||||
|
||||
algo = _gnutls_x509_mac_to_oid ((gnutls_mac_algorithm_t) hash);
|
||||
algo = mhd_gtls_x509_mac_to_oid ((gnutls_mac_algorithm_t) hash);
|
||||
if (algo == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -140,18 +140,18 @@ pkcs1_rsa_sign (gnutls_digest_algorithm_t hash, const gnutls_datum_t * text,
|
||||
GNUTLS_HASH_HANDLE hd;
|
||||
gnutls_datum_t digest, info;
|
||||
|
||||
hd = _gnutls_hash_init (HASH2MAC (hash));
|
||||
hd = mhd_gtls_hash_init (HASH2MAC (hash));
|
||||
if (hd == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return GNUTLS_E_HASH_FAILED;
|
||||
}
|
||||
|
||||
_gnutls_hash (hd, text->data, text->size);
|
||||
_gnutls_hash_deinit (hd, _digest);
|
||||
mhd_gnutls_hash (hd, text->data, text->size);
|
||||
mhd_gnutls_hash_deinit (hd, _digest);
|
||||
|
||||
digest.data = _digest;
|
||||
digest.size = _gnutls_hash_get_algo_len (HASH2MAC (hash));
|
||||
digest.size = mhd_gnutls_hash_get_algo_len (HASH2MAC (hash));
|
||||
|
||||
/* Encode the digest as a DigestInfo
|
||||
*/
|
||||
@@ -162,7 +162,7 @@ pkcs1_rsa_sign (gnutls_digest_algorithm_t hash, const gnutls_datum_t * text,
|
||||
}
|
||||
|
||||
if ((ret =
|
||||
_gnutls_sign (MHD_GNUTLS_PK_RSA, params, params_len, &info,
|
||||
mhd_gtls_sign (MHD_GNUTLS_PK_RSA, params, params_len, &info,
|
||||
signature)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -278,8 +278,8 @@ _gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
|
||||
|
||||
/* Step 1. Copy the issuer's name into the certificate.
|
||||
*/
|
||||
_gnutls_str_cpy (name, sizeof (name), src_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".issuer");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".issuer");
|
||||
|
||||
result = asn1_copy_node (src, name, issuer->cert, "tbsCertificate.subject");
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -290,8 +290,8 @@ _gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
|
||||
|
||||
/* Step 1.5. Write the signature stuff in the tbsCertificate.
|
||||
*/
|
||||
_gnutls_str_cpy (name, sizeof (name), src_name);
|
||||
_gnutls_str_cat (name, sizeof (name), ".signature");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".signature");
|
||||
|
||||
result = _gnutls_x509_write_sig_params (src, name,
|
||||
issuer_key->pk_algorithm, dig,
|
||||
|
||||
@@ -487,7 +487,7 @@ gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert)
|
||||
return result;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_oid2sign_algorithm (sa.data);
|
||||
result = mhd_gtls_x509_oid2sign_algorithm (sa.data);
|
||||
|
||||
_gnutls_free_datum (&sa);
|
||||
|
||||
@@ -950,9 +950,9 @@ parse_general_name (ASN1_TYPE src,
|
||||
if (type == GNUTLS_SAN_OTHERNAME)
|
||||
{
|
||||
if (othername_oid)
|
||||
_gnutls_str_cat (nptr, sizeof (nptr), ".otherName.type-id");
|
||||
mhd_gtls_str_cat (nptr, sizeof (nptr), ".otherName.type-id");
|
||||
else
|
||||
_gnutls_str_cat (nptr, sizeof (nptr), ".otherName.value");
|
||||
mhd_gtls_str_cat (nptr, sizeof (nptr), ".otherName.value");
|
||||
|
||||
len = *name_size;
|
||||
result = asn1_read_value (src, nptr, name, &len);
|
||||
@@ -1025,7 +1025,7 @@ parse_general_name (ASN1_TYPE src,
|
||||
}
|
||||
else if (type == GNUTLS_SAN_DN)
|
||||
{
|
||||
_gnutls_str_cat (nptr, sizeof (nptr), ".directoryName");
|
||||
mhd_gtls_str_cat (nptr, sizeof (nptr), ".directoryName");
|
||||
result = _gnutls_x509_parse_dn (src, nptr, name, name_size);
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -1039,8 +1039,8 @@ parse_general_name (ASN1_TYPE src,
|
||||
{
|
||||
size_t orig_name_size = *name_size;
|
||||
|
||||
_gnutls_str_cat (nptr, sizeof (nptr), ".");
|
||||
_gnutls_str_cat (nptr, sizeof (nptr), choice_type);
|
||||
mhd_gtls_str_cat (nptr, sizeof (nptr), ".");
|
||||
mhd_gtls_str_cat (nptr, sizeof (nptr), choice_type);
|
||||
|
||||
len = *name_size;
|
||||
result = asn1_read_value (src, nptr, name, &len);
|
||||
@@ -1980,7 +1980,7 @@ gnutls_x509_crt_get_fingerprint (gnutls_x509_crt_t cert,
|
||||
tmp.data = cert_buf;
|
||||
tmp.size = cert_buf_size;
|
||||
|
||||
result = gnutls_fingerprint (algo, &tmp, buf, sizeof_buf);
|
||||
result = MHD_gnutls_fingerprint (algo, &tmp, buf, sizeof_buf);
|
||||
gnutls_afree (cert_buf);
|
||||
|
||||
return result;
|
||||
@@ -2053,7 +2053,7 @@ rsadsa_get_key_id (gnutls_x509_crt_t crt,
|
||||
else
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
|
||||
hd = _gnutls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
hd = mhd_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
if (hd == GNUTLS_HASH_FAILED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -2061,9 +2061,9 @@ rsadsa_get_key_id (gnutls_x509_crt_t crt,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
_gnutls_hash (hd, der.data, der.size);
|
||||
mhd_gnutls_hash (hd, der.data, der.size);
|
||||
|
||||
_gnutls_hash_deinit (hd, output_data);
|
||||
mhd_gnutls_hash_deinit (hd, output_data);
|
||||
*output_data_size = 20;
|
||||
|
||||
result = 0;
|
||||
@@ -2076,7 +2076,7 @@ cleanup:
|
||||
*/
|
||||
for (i = 0; i < params_size; i++)
|
||||
{
|
||||
_gnutls_mpi_release (¶ms[i]);
|
||||
mhd_gtls_mpi_release (¶ms[i]);
|
||||
}
|
||||
return result;
|
||||
}
|
||||
@@ -2165,7 +2165,7 @@ gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
result = gnutls_fingerprint (MHD_GNUTLS_DIG_SHA1, &pubkey, output_data,
|
||||
result = MHD_gnutls_fingerprint (MHD_GNUTLS_DIG_SHA1, &pubkey, output_data,
|
||||
output_data_size);
|
||||
|
||||
gnutls_afree (pubkey.data);
|
||||
@@ -2420,7 +2420,7 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
/* Return the different names from the first CRLDistr. point.
|
||||
* The whole thing is a mess.
|
||||
*/
|
||||
_gnutls_str_cpy (name, sizeof (name), "?1.distributionPoint.fullName");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), "?1.distributionPoint.fullName");
|
||||
|
||||
result = parse_general_name (c2, name, seq, ret, ret_size, NULL, 0);
|
||||
if (result < 0)
|
||||
@@ -2435,7 +2435,7 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
*/
|
||||
if (reason_flags)
|
||||
{
|
||||
_gnutls_str_cpy (name, sizeof (name), "?1.reasons");
|
||||
mhd_gtls_str_cpy (name, sizeof (name), "?1.reasons");
|
||||
|
||||
reasons[0] = reasons[1] = 0;
|
||||
|
||||
@@ -2594,14 +2594,14 @@ gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = _gnutls_mpi_dprint (m, params[0]);
|
||||
ret = mhd_gtls_mpi_dprint (m, params[0]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = _gnutls_mpi_dprint (e, params[1]);
|
||||
ret = mhd_gtls_mpi_dprint (e, params[1]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -2613,7 +2613,7 @@ gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
|
||||
|
||||
cleanup:for (i = 0; i < params_size; i++)
|
||||
{
|
||||
_gnutls_mpi_release (¶ms[i]);
|
||||
mhd_gtls_mpi_release (¶ms[i]);
|
||||
}
|
||||
return ret;
|
||||
}
|
||||
@@ -2659,7 +2659,7 @@ gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
|
||||
}
|
||||
|
||||
/* P */
|
||||
ret = _gnutls_mpi_dprint (p, params[0]);
|
||||
ret = mhd_gtls_mpi_dprint (p, params[0]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -2667,7 +2667,7 @@ gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
|
||||
}
|
||||
|
||||
/* Q */
|
||||
ret = _gnutls_mpi_dprint (q, params[1]);
|
||||
ret = mhd_gtls_mpi_dprint (q, params[1]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -2676,7 +2676,7 @@ gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
|
||||
}
|
||||
|
||||
/* G */
|
||||
ret = _gnutls_mpi_dprint (g, params[2]);
|
||||
ret = mhd_gtls_mpi_dprint (g, params[2]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -2686,7 +2686,7 @@ gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
|
||||
}
|
||||
|
||||
/* Y */
|
||||
ret = _gnutls_mpi_dprint (y, params[3]);
|
||||
ret = mhd_gtls_mpi_dprint (y, params[3]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -2700,7 +2700,7 @@ gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
|
||||
|
||||
cleanup:for (i = 0; i < params_size; i++)
|
||||
{
|
||||
_gnutls_mpi_release (¶ms[i]);
|
||||
mhd_gtls_mpi_release (¶ms[i]);
|
||||
}
|
||||
return ret;
|
||||
|
||||
|
||||
@@ -778,7 +778,7 @@ typedef struct gnutls_x509_crt_int
|
||||
# error INCREASE MAX_PRIV_PARAMS
|
||||
#endif
|
||||
|
||||
typedef struct gnutls_x509_privkey_int
|
||||
typedef struct MHD_gtls_x509_privkey_int
|
||||
{
|
||||
mpi_t params[MAX_PRIV_PARAMS_SIZE]; /* the size of params depends on the public
|
||||
* key algorithm
|
||||
|
||||
@@ -88,7 +88,7 @@ gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key)
|
||||
|
||||
for (i = 0; i < key->params_size; i++)
|
||||
{
|
||||
_gnutls_mpi_release (&key->params[i]);
|
||||
mhd_gtls_mpi_release (&key->params[i]);
|
||||
}
|
||||
|
||||
asn1_delete_structure (&key->key);
|
||||
@@ -238,12 +238,12 @@ _gnutls_privkey_decode_pkcs1_rsa_key (const gnutls_datum_t * raw_key,
|
||||
return pkey_asn;
|
||||
|
||||
error:asn1_delete_structure (&pkey_asn);
|
||||
_gnutls_mpi_release (&pkey->params[0]);
|
||||
_gnutls_mpi_release (&pkey->params[1]);
|
||||
_gnutls_mpi_release (&pkey->params[2]);
|
||||
_gnutls_mpi_release (&pkey->params[3]);
|
||||
_gnutls_mpi_release (&pkey->params[4]);
|
||||
_gnutls_mpi_release (&pkey->params[5]);
|
||||
mhd_gtls_mpi_release (&pkey->params[0]);
|
||||
mhd_gtls_mpi_release (&pkey->params[1]);
|
||||
mhd_gtls_mpi_release (&pkey->params[2]);
|
||||
mhd_gtls_mpi_release (&pkey->params[3]);
|
||||
mhd_gtls_mpi_release (&pkey->params[4]);
|
||||
mhd_gtls_mpi_release (&pkey->params[5]);
|
||||
return NULL;
|
||||
|
||||
}
|
||||
@@ -311,11 +311,11 @@ decode_dsa_key (const gnutls_datum_t * raw_key, gnutls_x509_privkey_t pkey)
|
||||
return dsa_asn;
|
||||
|
||||
error:asn1_delete_structure (&dsa_asn);
|
||||
_gnutls_mpi_release (&pkey->params[0]);
|
||||
_gnutls_mpi_release (&pkey->params[1]);
|
||||
_gnutls_mpi_release (&pkey->params[2]);
|
||||
_gnutls_mpi_release (&pkey->params[3]);
|
||||
_gnutls_mpi_release (&pkey->params[4]);
|
||||
mhd_gtls_mpi_release (&pkey->params[0]);
|
||||
mhd_gtls_mpi_release (&pkey->params[1]);
|
||||
mhd_gtls_mpi_release (&pkey->params[2]);
|
||||
mhd_gtls_mpi_release (&pkey->params[3]);
|
||||
mhd_gtls_mpi_release (&pkey->params[4]);
|
||||
return NULL;
|
||||
|
||||
}
|
||||
@@ -430,9 +430,9 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
#define FREE_RSA_PRIVATE_PARAMS for (i=0;i<RSA_PRIVATE_PARAMS;i++) \
|
||||
_gnutls_mpi_release(&key->params[i])
|
||||
mhd_gtls_mpi_release(&key->params[i])
|
||||
#define FREE_DSA_PRIVATE_PARAMS for (i=0;i<DSA_PRIVATE_PARAMS;i++) \
|
||||
_gnutls_mpi_release(&key->params[i])
|
||||
mhd_gtls_mpi_release(&key->params[i])
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_import_rsa_raw - This function will import a raw RSA key
|
||||
@@ -467,7 +467,7 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
siz = m->size;
|
||||
if (_gnutls_mpi_scan_nz (&key->params[0], m->data, &siz))
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[0], m->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
@@ -475,7 +475,7 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
siz = e->size;
|
||||
if (_gnutls_mpi_scan_nz (&key->params[1], e->data, &siz))
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[1], e->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
@@ -483,7 +483,7 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
siz = d->size;
|
||||
if (_gnutls_mpi_scan_nz (&key->params[2], d->data, &siz))
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[2], d->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
@@ -491,7 +491,7 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
siz = p->size;
|
||||
if (_gnutls_mpi_scan_nz (&key->params[3], p->data, &siz))
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[3], p->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
@@ -499,7 +499,7 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
siz = q->size;
|
||||
if (_gnutls_mpi_scan_nz (&key->params[4], q->data, &siz))
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[4], q->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
@@ -519,7 +519,7 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
_gnutls_mpi_invm (key->params[5], key->params[3], key->params[4]);
|
||||
#else
|
||||
siz = u->size;
|
||||
if (_gnutls_mpi_scan_nz (&key->params[5], u->data, &siz))
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[5], u->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
@@ -668,7 +668,7 @@ gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
m->data = e->data = d->data = p->data = q->data = u->data = NULL;
|
||||
m->size = e->size = d->size = p->size = q->size = u->size = 0;
|
||||
|
||||
ret = _gnutls_mpi_dprint (m, key->params[0]);
|
||||
ret = mhd_gtls_mpi_dprint (m, key->params[0]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -676,7 +676,7 @@ gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/* E */
|
||||
ret = _gnutls_mpi_dprint (e, key->params[1]);
|
||||
ret = mhd_gtls_mpi_dprint (e, key->params[1]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -684,7 +684,7 @@ gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/* D */
|
||||
ret = _gnutls_mpi_dprint (d, key->params[2]);
|
||||
ret = mhd_gtls_mpi_dprint (d, key->params[2]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -692,7 +692,7 @@ gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/* P */
|
||||
ret = _gnutls_mpi_dprint (p, key->params[3]);
|
||||
ret = mhd_gtls_mpi_dprint (p, key->params[3]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -700,7 +700,7 @@ gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/* Q */
|
||||
ret = _gnutls_mpi_dprint (q, key->params[4]);
|
||||
ret = mhd_gtls_mpi_dprint (q, key->params[4]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -718,17 +718,17 @@ gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
_gnutls_mpi_invm (coeff, key->params[4], key->params[3]);
|
||||
ret = _gnutls_mpi_dprint (u, coeff);
|
||||
ret = mhd_gtls_mpi_dprint (u, coeff);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
_gnutls_mpi_release (&coeff);
|
||||
mhd_gtls_mpi_release (&coeff);
|
||||
#else
|
||||
/* U */
|
||||
ret = _gnutls_mpi_dprint (u, key->params[5]);
|
||||
ret = mhd_gtls_mpi_dprint (u, key->params[5]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -743,7 +743,7 @@ error:_gnutls_free_datum (m);
|
||||
_gnutls_free_datum (e);
|
||||
_gnutls_free_datum (p);
|
||||
_gnutls_free_datum (q);
|
||||
_gnutls_mpi_release (&coeff);
|
||||
mhd_gtls_mpi_release (&coeff);
|
||||
|
||||
return ret;
|
||||
}
|
||||
@@ -778,7 +778,7 @@ gnutls_x509_privkey_export_dsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/* P */
|
||||
ret = _gnutls_mpi_dprint (p, key->params[0]);
|
||||
ret = mhd_gtls_mpi_dprint (p, key->params[0]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -786,7 +786,7 @@ gnutls_x509_privkey_export_dsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/* Q */
|
||||
ret = _gnutls_mpi_dprint (q, key->params[1]);
|
||||
ret = mhd_gtls_mpi_dprint (q, key->params[1]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -795,7 +795,7 @@ gnutls_x509_privkey_export_dsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/* G */
|
||||
ret = _gnutls_mpi_dprint (g, key->params[2]);
|
||||
ret = mhd_gtls_mpi_dprint (g, key->params[2]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -805,7 +805,7 @@ gnutls_x509_privkey_export_dsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/* Y */
|
||||
ret = _gnutls_mpi_dprint (y, key->params[3]);
|
||||
ret = mhd_gtls_mpi_dprint (y, key->params[3]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -816,7 +816,7 @@ gnutls_x509_privkey_export_dsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/* X */
|
||||
ret = _gnutls_mpi_dprint (x, key->params[4]);
|
||||
ret = mhd_gtls_mpi_dprint (x, key->params[4]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -847,7 +847,7 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
total = 0;
|
||||
for (i = 0; i < 5; i++)
|
||||
{
|
||||
_gnutls_mpi_print_lz (NULL, &size[i], params[i]);
|
||||
mhd_gtls_mpi_print_lz (NULL, &size[i], params[i]);
|
||||
total += size[i];
|
||||
}
|
||||
|
||||
@@ -895,7 +895,7 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
|
||||
_gnutls_mpi_invm (u, params[4], params[3]);
|
||||
/* inverse of q mod p */
|
||||
_gnutls_mpi_print_lz (NULL, &size[5], u);
|
||||
mhd_gtls_mpi_print_lz (NULL, &size[5], u);
|
||||
total += size[5];
|
||||
|
||||
_gnutls_mpi_sub_ui (p1, params[3], 1);
|
||||
@@ -905,10 +905,10 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
_gnutls_mpi_mod (exp2, params[2], q1);
|
||||
|
||||
/* calculate exp's size */
|
||||
_gnutls_mpi_print_lz (NULL, &size[6], exp1);
|
||||
mhd_gtls_mpi_print_lz (NULL, &size[6], exp1);
|
||||
total += size[6];
|
||||
|
||||
_gnutls_mpi_print_lz (NULL, &size[7], exp2);
|
||||
mhd_gtls_mpi_print_lz (NULL, &size[7], exp2);
|
||||
total += size[7];
|
||||
|
||||
/* Encoding phase.
|
||||
@@ -939,14 +939,14 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
p += size[6];
|
||||
exp2_data = p;
|
||||
|
||||
_gnutls_mpi_print_lz (m_data, &size[0], params[0]);
|
||||
_gnutls_mpi_print_lz (pube_data, &size[1], params[1]);
|
||||
_gnutls_mpi_print_lz (prie_data, &size[2], params[2]);
|
||||
_gnutls_mpi_print_lz (p1_data, &size[3], params[3]);
|
||||
_gnutls_mpi_print_lz (p2_data, &size[4], params[4]);
|
||||
_gnutls_mpi_print_lz (u_data, &size[5], u);
|
||||
_gnutls_mpi_print_lz (exp1_data, &size[6], exp1);
|
||||
_gnutls_mpi_print_lz (exp2_data, &size[7], exp2);
|
||||
mhd_gtls_mpi_print_lz (m_data, &size[0], params[0]);
|
||||
mhd_gtls_mpi_print_lz (pube_data, &size[1], params[1]);
|
||||
mhd_gtls_mpi_print_lz (prie_data, &size[2], params[2]);
|
||||
mhd_gtls_mpi_print_lz (p1_data, &size[3], params[3]);
|
||||
mhd_gtls_mpi_print_lz (p2_data, &size[4], params[4]);
|
||||
mhd_gtls_mpi_print_lz (u_data, &size[5], u);
|
||||
mhd_gtls_mpi_print_lz (exp1_data, &size[6], exp1);
|
||||
mhd_gtls_mpi_print_lz (exp2_data, &size[7], exp2);
|
||||
|
||||
/* Ok. Now we have the data. Create the asn1 structures
|
||||
*/
|
||||
@@ -1026,11 +1026,11 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
_gnutls_mpi_release (&exp1);
|
||||
_gnutls_mpi_release (&exp2);
|
||||
_gnutls_mpi_release (&q1);
|
||||
_gnutls_mpi_release (&p1);
|
||||
_gnutls_mpi_release (&u);
|
||||
mhd_gtls_mpi_release (&exp1);
|
||||
mhd_gtls_mpi_release (&exp2);
|
||||
mhd_gtls_mpi_release (&q1);
|
||||
mhd_gtls_mpi_release (&p1);
|
||||
mhd_gtls_mpi_release (&u);
|
||||
gnutls_free (all_data);
|
||||
|
||||
if ((result = asn1_write_value (*c2, "otherPrimeInfos",
|
||||
@@ -1050,11 +1050,11 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:_gnutls_mpi_release (&u);
|
||||
_gnutls_mpi_release (&exp1);
|
||||
_gnutls_mpi_release (&exp2);
|
||||
_gnutls_mpi_release (&q1);
|
||||
_gnutls_mpi_release (&p1);
|
||||
cleanup:mhd_gtls_mpi_release (&u);
|
||||
mhd_gtls_mpi_release (&exp1);
|
||||
mhd_gtls_mpi_release (&exp2);
|
||||
mhd_gtls_mpi_release (&q1);
|
||||
mhd_gtls_mpi_release (&p1);
|
||||
asn1_delete_structure (c2);
|
||||
gnutls_free (all_data);
|
||||
|
||||
@@ -1076,7 +1076,7 @@ _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
total = 0;
|
||||
for (i = 0; i < DSA_PRIVATE_PARAMS; i++)
|
||||
{
|
||||
_gnutls_mpi_print_lz (NULL, &size[i], params[i]);
|
||||
mhd_gtls_mpi_print_lz (NULL, &size[i], params[i]);
|
||||
total += size[i];
|
||||
}
|
||||
|
||||
@@ -1102,11 +1102,11 @@ _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
p += size[3];
|
||||
x_data = p;
|
||||
|
||||
_gnutls_mpi_print_lz (p_data, &size[0], params[0]);
|
||||
_gnutls_mpi_print_lz (q_data, &size[1], params[1]);
|
||||
_gnutls_mpi_print_lz (g_data, &size[2], params[2]);
|
||||
_gnutls_mpi_print_lz (y_data, &size[3], params[3]);
|
||||
_gnutls_mpi_print_lz (x_data, &size[4], params[4]);
|
||||
mhd_gtls_mpi_print_lz (p_data, &size[0], params[0]);
|
||||
mhd_gtls_mpi_print_lz (q_data, &size[1], params[1]);
|
||||
mhd_gtls_mpi_print_lz (g_data, &size[2], params[2]);
|
||||
mhd_gtls_mpi_print_lz (y_data, &size[3], params[3]);
|
||||
mhd_gtls_mpi_print_lz (x_data, &size[4], params[4]);
|
||||
|
||||
/* Ok. Now we have the data. Create the asn1 structures
|
||||
*/
|
||||
@@ -1236,7 +1236,7 @@ gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
|
||||
cleanup:key->pk_algorithm = MHD_GNUTLS_PK_UNKNOWN;
|
||||
key->params_size = 0;
|
||||
for (i = 0; i < params_len; i++)
|
||||
_gnutls_mpi_release (&key->params[i]);
|
||||
mhd_gtls_mpi_release (&key->params[i]);
|
||||
|
||||
return ret;
|
||||
}
|
||||
@@ -1300,7 +1300,7 @@ gnutls_x509_privkey_get_key_id (gnutls_x509_privkey_t key,
|
||||
else
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
|
||||
hd = _gnutls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
hd = mhd_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
if (hd == GNUTLS_HASH_FAILED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -1308,9 +1308,9 @@ gnutls_x509_privkey_get_key_id (gnutls_x509_privkey_t key,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
_gnutls_hash (hd, der.data, der.size);
|
||||
mhd_gnutls_hash (hd, der.data, der.size);
|
||||
|
||||
_gnutls_hash_deinit (hd, output_data);
|
||||
mhd_gnutls_hash_deinit (hd, output_data);
|
||||
*output_data_size = 20;
|
||||
|
||||
result = 0;
|
||||
@@ -1408,7 +1408,7 @@ gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
result = _gnutls_sign (key->pk_algorithm, key->params,
|
||||
result = mhd_gtls_sign (key->pk_algorithm, key->params,
|
||||
key->params_size, hash, signature);
|
||||
if (result < 0)
|
||||
{
|
||||
|
||||
@@ -498,7 +498,7 @@ decode_ber_digest_info (const gnutls_datum_t * info,
|
||||
return _gnutls_asn2err (result);
|
||||
}
|
||||
|
||||
*hash = _gnutls_x509_oid2mac_algorithm (str);
|
||||
*hash = mhd_gtls_x509_oid2mac_algorithm (str);
|
||||
|
||||
if (*hash == MHD_GNUTLS_MAC_UNKNOWN)
|
||||
{
|
||||
@@ -555,7 +555,7 @@ _pkcs1_rsa_verify_sig (const gnutls_datum_t * text,
|
||||
gnutls_datum_t decrypted;
|
||||
|
||||
ret =
|
||||
_gnutls_pkcs1_rsa_decrypt (&decrypted, signature, params, params_len, 1);
|
||||
mhd_gtls_pkcs1_rsa_decrypt (&decrypted, signature, params, params_len, 1);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
@@ -576,21 +576,21 @@ _pkcs1_rsa_verify_sig (const gnutls_datum_t * text,
|
||||
|
||||
_gnutls_free_datum (&decrypted);
|
||||
|
||||
if (digest_size != _gnutls_hash_get_algo_len (hash))
|
||||
if (digest_size != mhd_gnutls_hash_get_algo_len (hash))
|
||||
{
|
||||
gnutls_assert ();
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
|
||||
hd = _gnutls_hash_init (hash);
|
||||
hd = mhd_gtls_hash_init (hash);
|
||||
if (hd == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return GNUTLS_E_HASH_FAILED;
|
||||
}
|
||||
|
||||
_gnutls_hash (hd, text->data, text->size);
|
||||
_gnutls_hash_deinit (hd, md);
|
||||
mhd_gnutls_hash (hd, text->data, text->size);
|
||||
mhd_gnutls_hash_deinit (hd, md);
|
||||
|
||||
if (memcmp (md, digest, digest_size) != 0)
|
||||
{
|
||||
@@ -613,20 +613,20 @@ dsa_verify_sig (const gnutls_datum_t * text,
|
||||
gnutls_datum_t digest;
|
||||
GNUTLS_HASH_HANDLE hd;
|
||||
|
||||
hd = _gnutls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
hd = mhd_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
if (hd == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return GNUTLS_E_HASH_FAILED;
|
||||
}
|
||||
|
||||
_gnutls_hash (hd, text->data, text->size);
|
||||
_gnutls_hash_deinit (hd, _digest);
|
||||
mhd_gnutls_hash (hd, text->data, text->size);
|
||||
mhd_gnutls_hash_deinit (hd, _digest);
|
||||
|
||||
digest.data = _digest;
|
||||
digest.size = 20;
|
||||
|
||||
ret = _gnutls_dsa_verify (&digest, signature, params, params_len);
|
||||
ret = mhd_gtls_dsa_verify (&digest, signature, params, params_len);
|
||||
|
||||
return ret;
|
||||
}
|
||||
@@ -699,7 +699,7 @@ _gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
|
||||
*/
|
||||
for (i = 0; i < issuer_params_size; i++)
|
||||
{
|
||||
_gnutls_mpi_release (&issuer_params[i]);
|
||||
mhd_gtls_mpi_release (&issuer_params[i]);
|
||||
}
|
||||
|
||||
return ret;
|
||||
|
||||
Reference in new issue
Block a user