mega-renaming to avoid exporting symbols not starting with MHD

This commit is contained in:
Christian Grothoff committed 2008-10-09 21:26:26 +00:00
1 parent 7ba36f02ae
commit 6ff7b62145
156 files changed
+9535 -9575

No files matched your search

+242 -242
View File
@@ -170,7 +170,7 @@ static const oid2string _oid2str[] = {
/* Returns 1 if the data defined by the OID are printable.
*/
int
_gnutls_x509_oid_data_printable (const char *oid)
MHD__gnutls_x509_oid_data_printable (const char *oid)
{
int i = 0;
@@ -186,11 +186,11 @@ _gnutls_x509_oid_data_printable (const char *oid)
}
/**
* gnutls_x509_dn_oid_known - This function will return true if the given OID is known
* MHD_gnutls_x509_dn_oid_known - This function will return true if the given OID is known
* @oid: holds an Object Identifier in a null terminated string
*
* This function will inform about known DN OIDs. This is useful since functions
* like gnutls_x509_crt_set_dn_by_oid() use the information on known
* like MHD_gnutls_x509_crt_set_dn_by_oid() use the information on known
* OIDs to properly encode their input. Object Identifiers that are not
* known are not encoded by these functions, and their input is stored directly
* into the ASN.1 structure. In that case of unknown OIDs, you have
@@ -200,7 +200,7 @@ _gnutls_x509_oid_data_printable (const char *oid)
*
**/
int
gnutls_x509_dn_oid_known (const char *oid)
MHD_gnutls_x509_dn_oid_known (const char *oid)
{
int i = 0;
@@ -219,7 +219,7 @@ gnutls_x509_dn_oid_known (const char *oid)
* type.
*/
int
_gnutls_x509_oid_data_choice (const char *oid)
MHD__gnutls_x509_oid_data_choice (const char *oid)
{
int i = 0;
@@ -235,7 +235,7 @@ _gnutls_x509_oid_data_choice (const char *oid)
}
const char *
_gnutls_x509_oid2ldap_string (const char *oid)
MHD__gnutls_x509_oid2ldap_string (const char *oid)
{
int i = 0;
@@ -257,7 +257,7 @@ _gnutls_x509_oid2ldap_string (const char *oid)
* hold the string.
*/
int
_gnutls_x509_oid_data2string (const char *oid,
MHD__gnutls_x509_oid_data2string (const char *oid,
void *value,
int value_size, char *res, size_t * res_size)
{
@@ -265,57 +265,57 @@ _gnutls_x509_oid_data2string (const char *oid,
const char *ANAME = NULL;
int CHOICE = -1, len = -1, result;
ASN1_TYPE tmpasn = ASN1_TYPE_EMPTY;
char asn1_err[MAX_ERROR_DESCRIPTION_SIZE] = "";
char MHD__asn1_err[MAX_ERROR_DESCRIPTION_SIZE] = "";
if (value == NULL || value_size <= 0 || res_size == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (_gnutls_x509_oid_data_printable (oid) == 0)
if (MHD__gnutls_x509_oid_data_printable (oid) == 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
}
ANAME = asn1_find_structure_from_oid (_gnutls_get_pkix (), oid);
CHOICE = _gnutls_x509_oid_data_choice (oid);
ANAME = MHD__asn1_find_structure_from_oid (MHD__gnutls_get_pkix (), oid);
CHOICE = MHD__gnutls_x509_oid_data_choice (oid);
if (ANAME == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
}
mhd_gtls_str_cpy (str, sizeof (str), "PKIX1.");
mhd_gtls_str_cat (str, sizeof (str), ANAME);
MHD_gtls_str_cpy (str, sizeof (str), "PKIX1.");
MHD_gtls_str_cat (str, sizeof (str), ANAME);
if ((result = asn1_create_element (_gnutls_get_pkix (), str,
if ((result = MHD__asn1_create_element (MHD__gnutls_get_pkix (), str,
&tmpasn)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if ((result = asn1_der_decoding (&tmpasn, value, value_size, asn1_err))
if ((result = MHD__asn1_der_decoding (&tmpasn, value, value_size, MHD__asn1_err))
!= ASN1_SUCCESS)
{
gnutls_assert ();
_gnutls_x509_log ("asn1_der_decoding: %s:%s\n", str, asn1_err);
asn1_delete_structure (&tmpasn);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__gnutls_x509_log ("MHD__asn1_der_decoding: %s:%s\n", str, MHD__asn1_err);
MHD__asn1_delete_structure (&tmpasn);
return MHD_gtls_asn2err (result);
}
/* If this is a choice then we read the choice. Otherwise it
* is the value;
*/
len = sizeof (str) - 1;
if ((result = asn1_read_value (tmpasn, "", str, &len)) != ASN1_SUCCESS)
if ((result = MHD__asn1_read_value (tmpasn, "", str, &len)) != ASN1_SUCCESS)
{ /* CHOICE */
gnutls_assert ();
asn1_delete_structure (&tmpasn);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&tmpasn);
return MHD_gtls_asn2err (result);
}
if (CHOICE == 0)
@@ -323,10 +323,10 @@ _gnutls_x509_oid_data2string (const char *oid,
str[len] = 0;
if (res)
mhd_gtls_str_cpy (res, *res_size, str);
MHD_gtls_str_cpy (res, *res_size, str);
*res_size = len;
asn1_delete_structure (&tmpasn);
MHD__asn1_delete_structure (&tmpasn);
}
else
{ /* CHOICE */
@@ -345,17 +345,17 @@ _gnutls_x509_oid_data2string (const char *oid,
if (strcmp (str, "teletexString") == 0)
teletex = 1;
mhd_gtls_str_cpy (tmpname, sizeof (tmpname), str);
MHD_gtls_str_cpy (tmpname, sizeof (tmpname), str);
len = sizeof (str) - 1;
if ((result = asn1_read_value (tmpasn, tmpname, str, &len))
if ((result = MHD__asn1_read_value (tmpasn, tmpname, str, &len))
!= ASN1_SUCCESS)
{
asn1_delete_structure (&tmpasn);
return mhd_gtls_asn2err (result);
MHD__asn1_delete_structure (&tmpasn);
return MHD_gtls_asn2err (result);
}
asn1_delete_structure (&tmpasn);
MHD__asn1_delete_structure (&tmpasn);
if (teletex != 0)
{
@@ -376,15 +376,15 @@ _gnutls_x509_oid_data2string (const char *oid,
if (non_printable == 0)
{
str[len] = 0;
mhd_gtls_str_cpy (res, *res_size, str);
MHD_gtls_str_cpy (res, *res_size, str);
*res_size = len;
}
else
{
result = _gnutls_x509_data2hex (str, len, res, res_size);
result = MHD__gnutls_x509_data2hex (str, len, res, res_size);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
}
@@ -399,7 +399,7 @@ _gnutls_x509_oid_data2string (const char *oid,
* something like '#01020304'
*/
int
_gnutls_x509_data2hex (const opaque * data,
MHD__gnutls_x509_data2hex (const opaque * data,
size_t data_size, opaque * out, size_t * sizeof_out)
{
char *res;
@@ -407,11 +407,11 @@ _gnutls_x509_data2hex (const opaque * data,
if (2 * data_size + 1 > MAX_STRING_LEN)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
}
res = mhd_gtls_bin2hex (data, data_size, escaped, sizeof (escaped));
res = MHD_gtls_bin2hex (data, data_size, escaped, sizeof (escaped));
if (res)
{
@@ -433,7 +433,7 @@ _gnutls_x509_data2hex (const opaque * data,
}
else
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
}
@@ -522,7 +522,7 @@ mktime_utc (const struct fake_tm *tm)
* and year is given. Returns a time_t date.
*/
time_t
_gnutls_x509_time2gtime (const char *ttime, int year)
MHD__gnutls_x509_time2gtime (const char *ttime, int year)
{
char xx[3];
struct fake_tm etime;
@@ -530,7 +530,7 @@ _gnutls_x509_time2gtime (const char *ttime, int year)
if (strlen (ttime) < 8)
{
gnutls_assert ();
MHD_gnutls_assert ();
return (time_t) - 1;
}
@@ -589,14 +589,14 @@ _gnutls_x509_time2gtime (const char *ttime, int year)
* (seconds are optional)
*/
time_t
_gnutls_x509_utcTime2gtime (const char *ttime)
MHD__gnutls_x509_utcTime2gtime (const char *ttime)
{
char xx[3];
int year;
if (strlen (ttime) < 10)
{
gnutls_assert ();
MHD_gnutls_assert ();
return (time_t) - 1;
}
xx[2] = 0;
@@ -611,7 +611,7 @@ _gnutls_x509_utcTime2gtime (const char *ttime)
else
year += 2000;
return _gnutls_x509_time2gtime (ttime, year);
return MHD__gnutls_x509_time2gtime (ttime, year);
}
/* returns a time value that contains the given time.
@@ -619,7 +619,7 @@ _gnutls_x509_utcTime2gtime (const char *ttime)
* YEAR(2)|MONTH(2)|DAY(2)|HOUR(2)|MIN(2)|SEC(2)
*/
int
_gnutls_x509_gtime2utcTime (time_t gtime, char *str_time, int str_time_size)
MHD__gnutls_x509_gtime2utcTime (time_t gtime, char *str_time, int str_time_size)
{
size_t ret;
@@ -639,7 +639,7 @@ _gnutls_x509_gtime2utcTime (time_t gtime, char *str_time, int str_time_size)
if (!ret)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
@@ -652,20 +652,20 @@ _gnutls_x509_gtime2utcTime (time_t gtime, char *str_time, int str_time_size)
* YEAR(4)|MONTH(2)|DAY(2)|HOUR(2)|MIN(2)|SEC(2)*
*/
time_t
_gnutls_x509_generalTime2gtime (const char *ttime)
MHD__gnutls_x509_generalTime2gtime (const char *ttime)
{
char xx[5];
int year;
if (strlen (ttime) < 12)
{
gnutls_assert ();
MHD_gnutls_assert ();
return (time_t) - 1;
}
if (strchr (ttime, 'Z') == 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
/* sorry we don't support it yet
*/
return (time_t) - 1;
@@ -678,7 +678,7 @@ _gnutls_x509_generalTime2gtime (const char *ttime)
year = atoi (xx);
ttime += 4;
return _gnutls_x509_time2gtime (ttime, year);
return MHD__gnutls_x509_time2gtime (ttime, year);
}
@@ -687,19 +687,19 @@ _gnutls_x509_generalTime2gtime (const char *ttime)
*/
#define MAX_TIME 64
time_t
_gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
MHD__gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
{
char ttime[MAX_TIME];
char name[128];
time_t c_time = (time_t) - 1;
int len, result;
mhd_gtls_str_cpy (name, sizeof (name), when);
MHD_gtls_str_cpy (name, sizeof (name), when);
len = sizeof (ttime) - 1;
if ((result = asn1_read_value (c2, name, ttime, &len)) < 0)
if ((result = MHD__asn1_read_value (c2, name, ttime, &len)) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return (time_t) (-1);
}
@@ -707,20 +707,20 @@ _gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
if (strcmp (ttime, "generalTime") == 0)
{
mhd_gtls_str_cat (name, sizeof (name), ".generalTime");
MHD_gtls_str_cat (name, sizeof (name), ".generalTime");
len = sizeof (ttime) - 1;
result = asn1_read_value (c2, name, ttime, &len);
result = MHD__asn1_read_value (c2, name, ttime, &len);
if (result == ASN1_SUCCESS)
c_time = _gnutls_x509_generalTime2gtime (ttime);
c_time = MHD__gnutls_x509_generalTime2gtime (ttime);
}
else
{ /* UTCTIME */
mhd_gtls_str_cat (name, sizeof (name), ".utcTime");
MHD_gtls_str_cat (name, sizeof (name), ".utcTime");
len = sizeof (ttime) - 1;
result = asn1_read_value (c2, name, ttime, &len);
result = MHD__asn1_read_value (c2, name, ttime, &len);
if (result == ASN1_SUCCESS)
c_time = _gnutls_x509_utcTime2gtime (ttime);
c_time = MHD__gnutls_x509_utcTime2gtime (ttime);
}
/* We cannot handle dates after 2031 in 32 bit machines.
@@ -729,7 +729,7 @@ _gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
return (time_t) (-1);
}
return c_time;
@@ -739,42 +739,42 @@ _gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
* be something like "tbsCertList.thisUpdate".
*/
int
_gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim)
MHD__gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim)
{
char str_time[MAX_TIME];
char name[128];
int result, len;
mhd_gtls_str_cpy (name, sizeof (name), where);
MHD_gtls_str_cpy (name, sizeof (name), where);
if ((result = asn1_write_value (c2, name, "utcTime", 1)) < 0)
if ((result = MHD__asn1_write_value (c2, name, "utcTime", 1)) < 0)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_gtime2utcTime (tim, str_time, sizeof (str_time));
result = MHD__gnutls_x509_gtime2utcTime (tim, str_time, sizeof (str_time));
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
mhd_gtls_str_cat (name, sizeof (name), ".utcTime");
MHD_gtls_str_cat (name, sizeof (name), ".utcTime");
len = strlen (str_time);
result = asn1_write_value (c2, name, str_time, len);
result = MHD__asn1_write_value (c2, name, str_time, len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
}
gnutls_x509_subject_alt_name_t
_gnutls_x509_san_find_type (char *str_type)
MHD_gnutls_x509_subject_alt_name_t
MHD__gnutls_x509_san_find_type (char *str_type)
{
if (strcmp (str_type, "dNSName") == 0)
return GNUTLS_SAN_DNSNAME;
@@ -788,15 +788,15 @@ _gnutls_x509_san_find_type (char *str_type)
return GNUTLS_SAN_OTHERNAME;
if (strcmp (str_type, "directoryName") == 0)
return GNUTLS_SAN_DN;
return (gnutls_x509_subject_alt_name_t) - 1;
return (MHD_gnutls_x509_subject_alt_name_t) - 1;
}
/* A generic export function. Will export the given ASN.1 encoded data
* to PEM or DER raw data.
*/
int
_gnutls_x509_export_int (ASN1_TYPE asn1_data,
gnutls_x509_crt_fmt_t format,
MHD__gnutls_x509_export_int (ASN1_TYPE MHD__asn1_data,
MHD_gnutls_x509_crt_fmt_t format,
char *pem_header,
unsigned char *output_data,
size_t * output_data_size)
@@ -811,7 +811,7 @@ _gnutls_x509_export_int (ASN1_TYPE asn1_data,
len = *output_data_size;
if ((result = asn1_der_coding (asn1_data, "", output_data, &len,
if ((result = MHD__asn1_der_coding (MHD__asn1_data, "", output_data, &len,
NULL)) != ASN1_SUCCESS)
{
*output_data_size = len;
@@ -819,8 +819,8 @@ _gnutls_x509_export_int (ASN1_TYPE asn1_data,
{
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
*output_data_size = len;
@@ -829,35 +829,35 @@ _gnutls_x509_export_int (ASN1_TYPE asn1_data,
else
{ /* PEM */
opaque *out;
gnutls_datum_t tmp;
MHD_gnutls_datum_t tmp;
result = _gnutls_x509_der_encode (asn1_data, "", &tmp, 0);
result = MHD__gnutls_x509_der_encode (MHD__asn1_data, "", &tmp, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
result = _gnutls_fbase64_encode (pem_header, tmp.data, tmp.size, &out);
result = MHD__gnutls_fbase64_encode (pem_header, tmp.data, tmp.size, &out);
_gnutls_free_datum (&tmp);
MHD__gnutls_free_datum (&tmp);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
if (result == 0)
{ /* oooops */
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
}
if ((unsigned) result > *output_data_size)
{
gnutls_assert ();
gnutls_free (out);
MHD_gnutls_assert ();
MHD_gnutls_free (out);
*output_data_size = result;
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
@@ -872,7 +872,7 @@ _gnutls_x509_export_int (ASN1_TYPE asn1_data,
*/
*output_data_size = result - 1;
}
gnutls_free (out);
MHD_gnutls_free (out);
}
@@ -884,7 +884,7 @@ _gnutls_x509_export_int (ASN1_TYPE asn1_data,
* etc.
*/
int
_gnutls_x509_decode_octet_string (const char *string_type,
MHD__gnutls_x509_decode_octet_string (const char *string_type,
const opaque * der,
size_t der_size,
opaque * output, size_t * output_size)
@@ -894,45 +894,45 @@ _gnutls_x509_decode_octet_string (const char *string_type,
char strname[64];
if (string_type == NULL)
mhd_gtls_str_cpy (strname, sizeof (strname), "PKIX1.pkcs-7-Data");
MHD_gtls_str_cpy (strname, sizeof (strname), "PKIX1.pkcs-7-Data");
else
{
mhd_gtls_str_cpy (strname, sizeof (strname), "PKIX1.");
mhd_gtls_str_cat (strname, sizeof (strname), string_type);
MHD_gtls_str_cpy (strname, sizeof (strname), "PKIX1.");
MHD_gtls_str_cat (strname, sizeof (strname), string_type);
}
if ((result =
asn1_create_element (_gnutls_get_pkix (), strname,
MHD__asn1_create_element (MHD__gnutls_get_pkix (), strname,
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_der_decoding (&c2, der, der_size, NULL);
result = MHD__asn1_der_decoding (&c2, der, der_size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
tmp_output_size = *output_size;
result = asn1_read_value (c2, "", output, &tmp_output_size);
result = MHD__asn1_read_value (c2, "", output, &tmp_output_size);
*output_size = tmp_output_size;
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
return 0;
cleanup:if (c2)
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
@@ -944,37 +944,37 @@ cleanup:if (c2)
* flags == 2 the value is a BIT STRING
*/
int
_gnutls_x509_read_value (ASN1_TYPE c,
const char *root, gnutls_datum_t * ret, int flags)
MHD__gnutls_x509_read_value (ASN1_TYPE c,
const char *root, MHD_gnutls_datum_t * ret, int flags)
{
int len = 0, result;
size_t slen;
opaque *tmp = NULL;
result = asn1_read_value (c, root, NULL, &len);
result = MHD__asn1_read_value (c, root, NULL, &len);
if (result != ASN1_MEM_ERROR)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
return result;
}
if (flags == 2)
len /= 8;
tmp = gnutls_malloc (len);
tmp = MHD_gnutls_malloc (len);
if (tmp == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
result = asn1_read_value (c, root, tmp, &len);
result = MHD__asn1_read_value (c, root, tmp, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -987,10 +987,10 @@ _gnutls_x509_read_value (ASN1_TYPE c,
if (flags == 1)
{
slen = len;
result = _gnutls_x509_decode_octet_string (NULL, tmp, slen, tmp, &slen);
result = MHD__gnutls_x509_decode_octet_string (NULL, tmp, slen, tmp, &slen);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
len = slen;
@@ -1001,7 +1001,7 @@ _gnutls_x509_read_value (ASN1_TYPE c,
return 0;
cleanup:gnutls_free (tmp);
cleanup:MHD_gnutls_free (tmp);
return result;
}
@@ -1011,8 +1011,8 @@ cleanup:gnutls_free (tmp);
* an OCTET STRING.
*/
int
_gnutls_x509_der_encode (ASN1_TYPE src,
const char *src_name, gnutls_datum_t * res, int str)
MHD__gnutls_x509_der_encode (ASN1_TYPE src,
const char *src_name, MHD_gnutls_datum_t * res, int str)
{
int size, result;
int asize;
@@ -1020,11 +1020,11 @@ _gnutls_x509_der_encode (ASN1_TYPE src,
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
size = 0;
result = asn1_der_coding (src, src_name, NULL, &size, NULL);
result = MHD__asn1_der_coding (src, src_name, NULL, &size, NULL);
if (result != ASN1_MEM_ERROR)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -1035,60 +1035,60 @@ _gnutls_x509_der_encode (ASN1_TYPE src,
size += 16; /* for later to include the octet tags */
asize = size;
data = gnutls_malloc (size);
data = MHD_gnutls_malloc (size);
if (data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
result = asn1_der_coding (src, src_name, data, &size, NULL);
result = MHD__asn1_der_coding (src, src_name, data, &size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if (str)
{
if ((result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.pkcs-7-Data",
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-Data",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_write_value (c2, "", data, size);
result = MHD__asn1_write_value (c2, "", data, size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_der_coding (c2, "", data, &asize, NULL);
result = MHD__asn1_der_coding (c2, "", data, &asize, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
size = asize;
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
}
res->data = data;
res->size = size;
return 0;
cleanup:gnutls_free (data);
asn1_delete_structure (&c2);
cleanup:MHD_gnutls_free (data);
MHD__asn1_delete_structure (&c2);
return result;
}
@@ -1099,32 +1099,32 @@ cleanup:gnutls_free (data);
* an OCTET STRING.
*/
int
_gnutls_x509_der_encode_and_copy (ASN1_TYPE src,
MHD__gnutls_x509_der_encode_and_copy (ASN1_TYPE src,
const char *src_name,
ASN1_TYPE dest,
const char *dest_name, int str)
{
int result;
gnutls_datum_t encoded;
MHD_gnutls_datum_t encoded;
result = _gnutls_x509_der_encode (src, src_name, &encoded, str);
result = MHD__gnutls_x509_der_encode (src, src_name, &encoded, str);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* Write the data.
*/
result = asn1_write_value (dest, dest_name, encoded.data, encoded.size);
result = MHD__asn1_write_value (dest, dest_name, encoded.data, encoded.size);
_gnutls_free_datum (&encoded);
MHD__gnutls_free_datum (&encoded);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
@@ -1134,21 +1134,21 @@ _gnutls_x509_der_encode_and_copy (ASN1_TYPE src,
* zero it encodes it as OCTET STRING.
*/
int
_gnutls_x509_write_value (ASN1_TYPE c,
MHD__gnutls_x509_write_value (ASN1_TYPE c,
const char *root,
const gnutls_datum_t * data, int str)
const MHD_gnutls_datum_t * data, int str)
{
int result;
int asize;
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
gnutls_datum_t val;
MHD_gnutls_datum_t val;
asize = data->size + 16;
val.data = gnutls_malloc (asize);
val.data = MHD_gnutls_malloc (asize);
if (val.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
@@ -1158,26 +1158,26 @@ _gnutls_x509_write_value (ASN1_TYPE c,
/* Convert it to OCTET STRING
*/
if ((result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.pkcs-7-Data",
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-Data",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_write_value (c2, "", data->data, data->size);
result = MHD__asn1_write_value (c2, "", data->data, data->size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = _gnutls_x509_der_encode (c2, "", &val, 0);
result = MHD__gnutls_x509_der_encode (c2, "", &val, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
@@ -1190,21 +1190,21 @@ _gnutls_x509_write_value (ASN1_TYPE c,
/* Write the data.
*/
result = asn1_write_value (c, root, val.data, val.size);
result = MHD__asn1_write_value (c, root, val.data, val.size);
if (val.data != data->data)
_gnutls_free_datum (&val);
MHD__gnutls_free_datum (&val);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
cleanup:if (val.data != data->data)
_gnutls_free_datum (&val);
MHD__gnutls_free_datum (&val);
return result;
}
@@ -1213,69 +1213,69 @@ cleanup:if (val.data != data->data)
*
*/
int
_gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
MHD__gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
const char *dst_name,
enum MHD_GNUTLS_PublicKeyAlgorithm
pk_algorithm,
mpi_t * params, int params_size)
{
const char *pk;
gnutls_datum_t der = { NULL,
MHD_gnutls_datum_t der = { NULL,
0
};
int result;
char name[128];
pk = mhd_gtls_x509_pk_to_oid (pk_algorithm);
pk = MHD_gtls_x509_pk_to_oid (pk_algorithm);
if (pk == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_UNKNOWN_PK_ALGORITHM;
}
/* write the OID
*/
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
mhd_gtls_str_cat (name, sizeof (name), ".algorithm.algorithm");
result = asn1_write_value (dst, name, pk, 1);
MHD_gtls_str_cpy (name, sizeof (name), dst_name);
MHD_gtls_str_cat (name, sizeof (name), ".algorithm.algorithm");
result = MHD__asn1_write_value (dst, name, pk, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (pk_algorithm == MHD_GNUTLS_PK_RSA)
{
/* disable parameters, which are not used in RSA.
*/
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
mhd_gtls_str_cat (name, sizeof (name), ".algorithm.parameters");
result = asn1_write_value (dst, name, NULL, 0);
MHD_gtls_str_cpy (name, sizeof (name), dst_name);
MHD_gtls_str_cat (name, sizeof (name), ".algorithm.parameters");
result = MHD__asn1_write_value (dst, name, NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_write_rsa_params (params, params_size, &der);
result = MHD__gnutls_x509_write_rsa_params (params, params_size, &der);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* Write the DER parameters. (in bits)
*/
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
mhd_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
result = asn1_write_value (dst, name, der.data, der.size * 8);
MHD_gtls_str_cpy (name, sizeof (name), dst_name);
MHD_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
result = MHD__asn1_write_value (dst, name, der.data, der.size * 8);
_gnutls_free_datum (&der);
MHD__gnutls_free_datum (&der);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
}
else
@@ -1288,7 +1288,7 @@ _gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
* ASN.1 structure. src_name should be something like "tbsCertificate.subjectPublicKeyInfo".
*/
int
_gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
MHD__gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
const char *src_name, unsigned int *bits)
{
int result;
@@ -1299,64 +1299,64 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
mpi_t params[MAX_PUBLIC_PARAMS_SIZE];
char name[128];
mhd_gtls_str_cpy (name, sizeof (name), src_name);
mhd_gtls_str_cat (name, sizeof (name), ".algorithm.algorithm");
MHD_gtls_str_cpy (name, sizeof (name), src_name);
MHD_gtls_str_cat (name, sizeof (name), ".algorithm.algorithm");
len = sizeof (oid);
result = asn1_read_value (src, name, oid, &len);
result = MHD__asn1_read_value (src, name, oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
algo = mhd_gtls_x509_oid2pk_algorithm (oid);
algo = MHD_gtls_x509_oid2pk_algorithm (oid);
if (bits == NULL)
{
gnutls_free (str);
MHD_gnutls_free (str);
return algo;
}
/* Now read the parameters' bits
*/
mhd_gtls_str_cpy (name, sizeof (name), src_name);
mhd_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
MHD_gtls_str_cpy (name, sizeof (name), src_name);
MHD_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
len = 0;
result = asn1_read_value (src, name, NULL, &len);
result = MHD__asn1_read_value (src, name, NULL, &len);
if (result != ASN1_MEM_ERROR)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (len % 8 != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_CERTIFICATE_ERROR;
}
len /= 8;
str = gnutls_malloc (len);
str = MHD_gnutls_malloc (len);
if (str == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
mhd_gtls_str_cpy (name, sizeof (name), src_name);
mhd_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
MHD_gtls_str_cpy (name, sizeof (name), src_name);
MHD_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
result = asn1_read_value (src, name, str, &len);
result = MHD__asn1_read_value (src, name, str, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
gnutls_free (str);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD_gnutls_free (str);
return MHD_gtls_asn2err (result);
}
len /= 8;
@@ -1365,24 +1365,24 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
{
case MHD_GNUTLS_PK_RSA:
{
if ((result = _gnutls_x509_read_rsa_params (str, len, params)) < 0)
if ((result = MHD__gnutls_x509_read_rsa_params (str, len, params)) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
bits[0] = _gnutls_mpi_get_nbits (params[0]);
bits[0] = MHD__gnutls_mpi_get_nbits (params[0]);
mhd_gtls_mpi_release (&params[0]);
mhd_gtls_mpi_release (&params[1]);
MHD_gtls_mpi_release (&params[0]);
MHD_gtls_mpi_release (&params[1]);
}
break;
default:
_gnutls_x509_log
("_gnutls_x509_get_pk_algorithm: unhandled algorithm %d\n", algo);
MHD__gnutls_x509_log
("MHD__gnutls_x509_get_pk_algorithm: unhandled algorithm %d\n", algo);
}
gnutls_free (str);
MHD_gnutls_free (str);
return algo;
}
@@ -1390,42 +1390,42 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
* returns them into signed_data.
*/
int
_gnutls_x509_get_signed_data (ASN1_TYPE src,
MHD__gnutls_x509_get_signed_data (ASN1_TYPE src,
const char *src_name,
gnutls_datum_t * signed_data)
MHD_gnutls_datum_t * signed_data)
{
gnutls_datum_t der;
MHD_gnutls_datum_t der;
int start, end, result;
result = _gnutls_x509_der_encode (src, "", &der, 0);
result = MHD__gnutls_x509_der_encode (src, "", &der, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* Get the signed data
*/
result = asn1_der_decoding_startEnd (src, der.data, der.size, src_name,
result = MHD__asn1_der_decoding_startEnd (src, der.data, der.size, src_name,
&start, &end);
if (result != ASN1_SUCCESS)
{
result = mhd_gtls_asn2err (result);
gnutls_assert ();
result = MHD_gtls_asn2err (result);
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_set_datum (signed_data, &der.data[start], end - start + 1);
result = MHD__gnutls_set_datum (signed_data, &der.data[start], end - start + 1);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = 0;
cleanup:_gnutls_free_datum (&der);
cleanup:MHD__gnutls_free_datum (&der);
return result;
}
@@ -1434,8 +1434,8 @@ cleanup:_gnutls_free_datum (&der);
* returns them into signed_data.
*/
int
_gnutls_x509_get_signature (ASN1_TYPE src,
const char *src_name, gnutls_datum_t * signature)
MHD__gnutls_x509_get_signature (ASN1_TYPE src,
const char *src_name, MHD_gnutls_datum_t * signature)
{
int bits, result, len;
@@ -1445,28 +1445,28 @@ _gnutls_x509_get_signature (ASN1_TYPE src,
/* Read the signature
*/
bits = 0;
result = asn1_read_value (src, src_name, NULL, &bits);
result = MHD__asn1_read_value (src, src_name, NULL, &bits);
if (result != ASN1_MEM_ERROR)
{
result = mhd_gtls_asn2err (result);
gnutls_assert ();
result = MHD_gtls_asn2err (result);
MHD_gnutls_assert ();
goto cleanup;
}
if (bits % 8 != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_CERTIFICATE_ERROR;
goto cleanup;
}
len = bits / 8;
signature->data = gnutls_malloc (len);
signature->data = MHD_gnutls_malloc (len);
if (signature->data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
return result;
}
@@ -1474,12 +1474,12 @@ _gnutls_x509_get_signature (ASN1_TYPE src,
/* read the bit string of the signature
*/
bits = len;
result = asn1_read_value (src, src_name, signature->data, &bits);
result = MHD__asn1_read_value (src, src_name, signature->data, &bits);
if (result != ASN1_SUCCESS)
{
result = mhd_gtls_asn2err (result);
gnutls_assert ();
result = MHD_gtls_asn2err (result);
MHD_gnutls_assert ();
goto cleanup;
}
+31 -31
View File
@@ -58,70 +58,70 @@
#define SIG_GOST_R3410_94_OID "1.2.643.2.2.4"
#define SIG_GOST_R3410_2001_OID "1.2.643.2.2.3"
time_t _gnutls_x509_utcTime2gtime (const char *ttime);
time_t _gnutls_x509_generalTime2gtime (const char *ttime);
int _gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim);
time_t MHD__gnutls_x509_utcTime2gtime (const char *ttime);
time_t MHD__gnutls_x509_generalTime2gtime (const char *ttime);
int MHD__gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim);
int _gnutls_x509_decode_octet_string (const char *string_type,
int MHD__gnutls_x509_decode_octet_string (const char *string_type,
const opaque * der, size_t der_size,
opaque * output, size_t * output_size);
int _gnutls_x509_oid_data2string (const char *OID, void *value,
int MHD__gnutls_x509_oid_data2string (const char *OID, void *value,
int value_size, char *res,
size_t * res_size);
int _gnutls_x509_data2hex (const opaque * data, size_t data_size,
int MHD__gnutls_x509_data2hex (const opaque * data, size_t data_size,
opaque * out, size_t * sizeof_out);
const char *_gnutls_x509_oid2ldap_string (const char *OID);
const char *MHD__gnutls_x509_oid2ldap_string (const char *OID);
int _gnutls_x509_oid_data_choice (const char *OID);
int _gnutls_x509_oid_data_printable (const char *OID);
int MHD__gnutls_x509_oid_data_choice (const char *OID);
int MHD__gnutls_x509_oid_data_printable (const char *OID);
time_t _gnutls_x509_get_time (ASN1_TYPE c2, const char *when);
time_t MHD__gnutls_x509_get_time (ASN1_TYPE c2, const char *when);
gnutls_x509_subject_alt_name_t _gnutls_x509_san_find_type (char *str_type);
MHD_gnutls_x509_subject_alt_name_t MHD__gnutls_x509_san_find_type (char *str_type);
int _gnutls_x509_der_encode_and_copy (ASN1_TYPE src, const char *src_name,
int MHD__gnutls_x509_der_encode_and_copy (ASN1_TYPE src, const char *src_name,
ASN1_TYPE dest, const char *dest_name,
int str);
int _gnutls_x509_der_encode (ASN1_TYPE src, const char *src_name,
gnutls_datum_t * res, int str);
int MHD__gnutls_x509_der_encode (ASN1_TYPE src, const char *src_name,
MHD_gnutls_datum_t * res, int str);
int _gnutls_x509_export_int (ASN1_TYPE asn1_data,
gnutls_x509_crt_fmt_t format, char *pem_header,
int MHD__gnutls_x509_export_int (ASN1_TYPE MHD__asn1_data,
MHD_gnutls_x509_crt_fmt_t format, char *pem_header,
unsigned char *output_data,
size_t * output_data_size);
int _gnutls_x509_read_value (ASN1_TYPE c, const char *root,
gnutls_datum_t * ret, int str);
int _gnutls_x509_write_value (ASN1_TYPE c, const char *root,
const gnutls_datum_t * data, int str);
int MHD__gnutls_x509_read_value (ASN1_TYPE c, const char *root,
MHD_gnutls_datum_t * ret, int str);
int MHD__gnutls_x509_write_value (ASN1_TYPE c, const char *root,
const MHD_gnutls_datum_t * data, int str);
int _gnutls_x509_encode_and_write_attribute (const char *given_oid,
ASN1_TYPE asn1_struct,
int MHD__gnutls_x509_encode_and_write_attribute (const char *given_oid,
ASN1_TYPE MHD__asn1_struct,
const char *where,
const void *data,
int sizeof_data, int multi);
int _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
int MHD__gnutls_x509_decode_and_read_attribute (ASN1_TYPE MHD__asn1_struct,
const char *where, char *oid,
int oid_size,
gnutls_datum_t * value, int multi,
MHD_gnutls_datum_t * value, int multi,
int octet);
int _gnutls_x509_get_pk_algorithm (ASN1_TYPE src, const char *src_name,
int MHD__gnutls_x509_get_pk_algorithm (ASN1_TYPE src, const char *src_name,
unsigned int *bits);
int _gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
int MHD__gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
const char *dst_name,
enum
MHD_GNUTLS_PublicKeyAlgorithm
pk_algorithm, mpi_t * params,
int params_size);
int _gnutls_asn1_copy_node (ASN1_TYPE * dst, const char *dst_name,
int MHD__gnutlsMHD__asn1_copy_node (ASN1_TYPE * dst, const char *dst_name,
ASN1_TYPE src, const char *src_name);
int _gnutls_x509_get_signed_data (ASN1_TYPE src, const char *src_name,
gnutls_datum_t * signed_data);
int _gnutls_x509_get_signature (ASN1_TYPE src, const char *src_name,
gnutls_datum_t * signature);
int MHD__gnutls_x509_get_signed_data (ASN1_TYPE src, const char *src_name,
MHD_gnutls_datum_t * signed_data);
int MHD__gnutls_x509_get_signature (ASN1_TYPE src, const char *src_name,
MHD_gnutls_datum_t * signature);
#endif
+132 -132
View File
@@ -36,7 +36,7 @@
#include <dn.h>
/**
* gnutls_x509_crl_init - This function initializes a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_init - This function initializes a MHD_gnutls_x509_crl_t structure
* @crl: The structure to be initialized
*
* This function will initialize a CRL structure. CRL stands for
@@ -49,20 +49,20 @@
*
**/
int
gnutls_x509_crl_init (gnutls_x509_crl_t * crl)
MHD_gnutls_x509_crl_init (MHD_gnutls_x509_crl_t * crl)
{
*crl = gnutls_calloc (1, sizeof (gnutls_x509_crl_int));
*crl = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_x509_crl_int));
if (*crl)
{
int result = asn1_create_element (_gnutls_get_pkix (),
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.CertificateList",
&(*crl)->crl);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
gnutls_free (*crl);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD_gnutls_free (*crl);
return MHD_gtls_asn2err (result);
}
return 0; /* success */
}
@@ -70,32 +70,32 @@ gnutls_x509_crl_init (gnutls_x509_crl_t * crl)
}
/**
* gnutls_x509_crl_deinit - This function deinitializes memory used by a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_deinit - This function deinitializes memory used by a MHD_gnutls_x509_crl_t structure
* @crl: The structure to be initialized
*
* This function will deinitialize a CRL structure.
*
**/
void
gnutls_x509_crl_deinit (gnutls_x509_crl_t crl)
MHD_gnutls_x509_crl_deinit (MHD_gnutls_x509_crl_t crl)
{
if (!crl)
return;
if (crl->crl)
asn1_delete_structure (&crl->crl);
MHD__asn1_delete_structure (&crl->crl);
gnutls_free (crl);
MHD_gnutls_free (crl);
}
/**
* gnutls_x509_crl_import - This function will import a DER or PEM encoded CRL
* MHD_gnutls_x509_crl_import - This function will import a DER or PEM encoded CRL
* @crl: The structure to store the parsed CRL.
* @data: The DER or PEM encoded CRL.
* @format: One of DER or PEM
*
* This function will convert the given DER or PEM encoded CRL
* to the native gnutls_x509_crl_t format. The output will be stored in 'crl'.
* to the native MHD_gnutls_x509_crl_t format. The output will be stored in 'crl'.
*
* If the CRL is PEM encoded it should have a header of "X509 CRL".
*
@@ -103,19 +103,19 @@ gnutls_x509_crl_deinit (gnutls_x509_crl_t crl)
*
**/
int
gnutls_x509_crl_import (gnutls_x509_crl_t crl,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format)
MHD_gnutls_x509_crl_import (MHD_gnutls_x509_crl_t crl,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format)
{
int result = 0, need_free = 0;
gnutls_datum_t _data;
MHD_gnutls_datum_t _data;
_data.data = data->data;
_data.size = data->size;
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -125,13 +125,13 @@ gnutls_x509_crl_import (gnutls_x509_crl_t crl,
{
opaque *out;
result = _gnutls_fbase64_decode (PEM_CRL, data->data, data->size, &out);
result = MHD__gnutls_fbase64_decode (PEM_CRL, data->data, data->size, &out);
if (result <= 0)
{
if (result == 0)
result = GNUTLS_E_INTERNAL_ERROR;
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -142,29 +142,29 @@ gnutls_x509_crl_import (gnutls_x509_crl_t crl,
}
result = asn1_der_decoding (&crl->crl, _data.data, _data.size, NULL);
result = MHD__asn1_der_decoding (&crl->crl, _data.data, _data.size, NULL);
if (result != ASN1_SUCCESS)
{
result = mhd_gtls_asn2err (result);
gnutls_assert ();
result = MHD_gtls_asn2err (result);
MHD_gnutls_assert ();
goto cleanup;
}
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
return 0;
cleanup:
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
return result;
}
/**
* gnutls_x509_crl_get_issuer_dn - This function returns the CRL's issuer distinguished name
* @crl: should contain a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_get_issuer_dn - This function returns the CRL's issuer distinguished name
* @crl: should contain a MHD_gnutls_x509_crl_t structure
* @buf: a pointer to a structure to hold the peer's name (may be null)
* @sizeof_buf: initially holds the size of @buf
*
@@ -180,23 +180,23 @@ cleanup:
*
**/
int
gnutls_x509_crl_get_issuer_dn (const gnutls_x509_crl_t crl, char *buf,
MHD_gnutls_x509_crl_get_issuer_dn (const MHD_gnutls_x509_crl_t crl, char *buf,
size_t * sizeof_buf)
{
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_parse_dn (crl->crl,
return MHD__gnutls_x509_parse_dn (crl->crl,
"tbsCertList.issuer.rdnSequence",
buf, sizeof_buf);
}
/**
* gnutls_x509_crl_get_issuer_dn_by_oid - This function returns the CRL's issuer distinguished name
* @crl: should contain a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_get_issuer_dn_by_oid - This function returns the CRL's issuer distinguished name
* @crl: should contain a MHD_gnutls_x509_crl_t structure
* @oid: holds an Object Identified in null terminated string
* @indx: In case multiple same OIDs exist in the RDN, this specifies which to send. Use zero to get the first one.
* @raw_flag: If non zero returns the raw DER data of the DN part.
@@ -210,7 +210,7 @@ gnutls_x509_crl_get_issuer_dn (const gnutls_x509_crl_t crl, char *buf,
* Some helper macros with popular OIDs can be found in gnutls/x509.h
* If raw flag is zero, this function will only return known OIDs as text. Other OIDs
* will be DER encoded, as described in RFC2253 -- in hex format with a '\#' prefix.
* You can check about known OIDs using gnutls_x509_dn_oid_known().
* You can check about known OIDs using MHD_gnutls_x509_dn_oid_known().
*
* If buf is null then only the size will be filled.
*
@@ -220,25 +220,25 @@ gnutls_x509_crl_get_issuer_dn (const gnutls_x509_crl_t crl, char *buf,
*
**/
int
gnutls_x509_crl_get_issuer_dn_by_oid (gnutls_x509_crl_t crl,
MHD_gnutls_x509_crl_get_issuer_dn_by_oid (MHD_gnutls_x509_crl_t crl,
const char *oid, int indx,
unsigned int raw_flag, void *buf,
size_t * sizeof_buf)
{
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_parse_dn_oid (crl->crl,
return MHD__gnutls_x509_parse_dn_oid (crl->crl,
"tbsCertList.issuer.rdnSequence",
oid, indx, raw_flag, buf, sizeof_buf);
}
/**
* gnutls_x509_crl_get_dn_oid - This function returns the Certificate request issuer's distinguished name OIDs
* @crl: should contain a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_get_dn_oid - This function returns the Certificate request issuer's distinguished name OIDs
* @crl: should contain a MHD_gnutls_x509_crl_t structure
* @indx: Specifies which DN OID to send. Use zero to get the first one.
* @oid: a pointer to a structure to hold the name (may be null)
* @sizeof_oid: initially holds the size of 'oid'
@@ -254,40 +254,40 @@ gnutls_x509_crl_get_issuer_dn_by_oid (gnutls_x509_crl_t crl,
*
**/
int
gnutls_x509_crl_get_dn_oid (gnutls_x509_crl_t crl,
MHD_gnutls_x509_crl_get_dn_oid (MHD_gnutls_x509_crl_t crl,
int indx, void *oid, size_t * sizeof_oid)
{
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_get_dn_oid (crl->crl,
return MHD__gnutls_x509_get_dn_oid (crl->crl,
"tbsCertList.issuer.rdnSequence", indx,
oid, sizeof_oid);
}
/**
* gnutls_x509_crl_get_signature_algorithm - This function returns the CRL's signature algorithm
* @crl: should contain a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_get_signature_algorithm - This function returns the CRL's signature algorithm
* @crl: should contain a MHD_gnutls_x509_crl_t structure
*
* This function will return a value of the gnutls_sign_algorithm_t enumeration that
* This function will return a value of the MHD_gnutls_sign_algorithm_t enumeration that
* is the signature algorithm.
*
* Returns a negative value on error.
*
**/
int
gnutls_x509_crl_get_signature_algorithm (gnutls_x509_crl_t crl)
MHD_gnutls_x509_crl_get_signature_algorithm (MHD_gnutls_x509_crl_t crl)
{
int result;
gnutls_datum_t sa;
MHD_gnutls_datum_t sa;
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -296,25 +296,25 @@ gnutls_x509_crl_get_signature_algorithm (gnutls_x509_crl_t crl)
*/
result =
_gnutls_x509_read_value (crl->crl, "signatureAlgorithm.algorithm",
MHD__gnutls_x509_read_value (crl->crl, "signatureAlgorithm.algorithm",
&sa, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
result = mhd_gtls_x509_oid2sign_algorithm ((const char *) sa.data);
result = MHD_gtls_x509_oid2sign_algorithm ((const char *) sa.data);
_gnutls_free_datum (&sa);
MHD__gnutls_free_datum (&sa);
return result;
}
/**
* gnutls_x509_crl_get_signature - Returns the CRL's signature
* @crl: should contain a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_get_signature - Returns the CRL's signature
* @crl: should contain a MHD_gnutls_x509_crl_t structure
* @sig: a pointer where the signature part will be copied (may be null).
* @sizeof_sig: initially holds the size of @sig
*
@@ -323,7 +323,7 @@ gnutls_x509_crl_get_signature_algorithm (gnutls_x509_crl_t crl)
* Returns 0 on success, and a negative value on error.
**/
int
gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
MHD_gnutls_x509_crl_get_signature (MHD_gnutls_x509_crl_t crl,
char *sig, size_t * sizeof_sig)
{
int result;
@@ -331,21 +331,21 @@ gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
bits = 0;
result = asn1_read_value (crl->crl, "signature", NULL, &bits);
result = MHD__asn1_read_value (crl->crl, "signature", NULL, &bits);
if (result != ASN1_MEM_ERROR)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (bits % 8 != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_CERTIFICATE_ERROR;
}
@@ -357,19 +357,19 @@ gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
result = asn1_read_value (crl->crl, "signature", sig, &len);
result = MHD__asn1_read_value (crl->crl, "signature", sig, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
}
/**
* gnutls_x509_crl_get_version - This function returns the CRL's version number
* @crl: should contain a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_get_version - This function returns the CRL's version number
* @crl: should contain a MHD_gnutls_x509_crl_t structure
*
* This function will return the version of the specified CRL.
*
@@ -377,32 +377,32 @@ gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
*
**/
int
gnutls_x509_crl_get_version (gnutls_x509_crl_t crl)
MHD_gnutls_x509_crl_get_version (MHD_gnutls_x509_crl_t crl)
{
opaque version[5];
int len, result;
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
len = sizeof (version);
if ((result =
asn1_read_value (crl->crl, "tbsCertList.version", version,
MHD__asn1_read_value (crl->crl, "tbsCertList.version", version,
&len)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return (int) version[0] + 1;
}
/**
* gnutls_x509_crl_get_this_update - This function returns the CRL's thisUpdate time
* @crl: should contain a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_get_this_update - This function returns the CRL's thisUpdate time
* @crl: should contain a MHD_gnutls_x509_crl_t structure
*
* This function will return the time this CRL was issued.
*
@@ -410,20 +410,20 @@ gnutls_x509_crl_get_version (gnutls_x509_crl_t crl)
*
**/
time_t
gnutls_x509_crl_get_this_update (gnutls_x509_crl_t crl)
MHD_gnutls_x509_crl_get_this_update (MHD_gnutls_x509_crl_t crl)
{
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return (time_t) - 1;
}
return _gnutls_x509_get_time (crl->crl, "tbsCertList.thisUpdate");
return MHD__gnutls_x509_get_time (crl->crl, "tbsCertList.thisUpdate");
}
/**
* gnutls_x509_crl_get_next_update - This function returns the CRL's nextUpdate time
* @crl: should contain a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_get_next_update - This function returns the CRL's nextUpdate time
* @crl: should contain a MHD_gnutls_x509_crl_t structure
*
* This function will return the time the next CRL will be issued.
* This field is optional in a CRL so it might be normal to get
@@ -433,20 +433,20 @@ gnutls_x509_crl_get_this_update (gnutls_x509_crl_t crl)
*
**/
time_t
gnutls_x509_crl_get_next_update (gnutls_x509_crl_t crl)
MHD_gnutls_x509_crl_get_next_update (MHD_gnutls_x509_crl_t crl)
{
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return (time_t) - 1;
}
return _gnutls_x509_get_time (crl->crl, "tbsCertList.nextUpdate");
return MHD__gnutls_x509_get_time (crl->crl, "tbsCertList.nextUpdate");
}
/**
* gnutls_x509_crl_get_crt_count - This function returns the number of revoked certificates in a CRL
* @crl: should contain a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_get_crt_count - This function returns the number of revoked certificates in a CRL
* @crl: should contain a MHD_gnutls_x509_crl_t structure
*
* This function will return the number of revoked certificates in the
* given CRL.
@@ -455,24 +455,24 @@ gnutls_x509_crl_get_next_update (gnutls_x509_crl_t crl)
*
**/
int
gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl)
MHD_gnutls_x509_crl_get_crt_count (MHD_gnutls_x509_crl_t crl)
{
int count, result;
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
result =
asn1_number_of_elements (crl->crl,
MHD__asn1_number_of_elements (crl->crl,
"tbsCertList.revokedCertificates", &count);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
return 0; /* no certificates */
}
@@ -480,8 +480,8 @@ gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl)
}
/**
* gnutls_x509_crl_get_crt_serial - This function returns the serial number of a revoked certificate
* @crl: should contain a gnutls_x509_crl_t structure
* MHD_gnutls_x509_crl_get_crt_serial - This function returns the serial number of a revoked certificate
* @crl: should contain a MHD_gnutls_x509_crl_t structure
* @indx: the index of the certificate to extract (starting from 0)
* @serial: where the serial number will be copied
* @serial_size: initially holds the size of serial
@@ -494,7 +494,7 @@ gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl)
*
**/
int
gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl, int indx,
MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl, int indx,
unsigned char *serial,
size_t * serial_size, time_t * t)
{
@@ -505,7 +505,7 @@ gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl, int indx,
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -515,28 +515,28 @@ gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl, int indx,
"tbsCertList.revokedCertificates.?%u.revocationDate", indx + 1);
_serial_size = *serial_size;
result = asn1_read_value (crl->crl, serial_name, serial, &_serial_size);
result = MHD__asn1_read_value (crl->crl, serial_name, serial, &_serial_size);
*serial_size = _serial_size;
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
if (result == ASN1_ELEMENT_NOT_FOUND)
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
return mhd_gtls_asn2err (result);
return MHD_gtls_asn2err (result);
}
if (t)
{
*t = _gnutls_x509_get_time (crl->crl, date_name);
*t = MHD__gnutls_x509_get_time (crl->crl, date_name);
}
return 0;
}
/*-
* _gnutls_x509_crl_get_raw_issuer_dn - This function returns the issuer's DN DER encoded
* @crl: should contain a gnutls_x509_crl_t structure
* MHD__gnutls_x509_crl_get_raw_issuer_dn - This function returns the issuer's DN DER encoded
* @crl: should contain a MHD_gnutls_x509_crl_t structure
* @dn: will hold the starting point of the DN
*
* This function will return a pointer to the DER encoded DN structure and
@@ -546,75 +546,75 @@ gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl, int indx,
*
-*/
int
_gnutls_x509_crl_get_raw_issuer_dn (gnutls_x509_crl_t crl,
gnutls_datum_t * dn)
MHD__gnutls_x509_crl_get_raw_issuer_dn (MHD_gnutls_x509_crl_t crl,
MHD_gnutls_datum_t * dn)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int result, len1;
int start1, end1;
gnutls_datum_t crl_signed_data;
MHD_gnutls_datum_t crl_signed_data;
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
/* get the issuer of 'crl'
*/
if ((result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.TBSCertList",
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.TBSCertList",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result =
_gnutls_x509_get_signed_data (crl->crl, "tbsCertList", &crl_signed_data);
MHD__gnutls_x509_get_signed_data (crl->crl, "tbsCertList", &crl_signed_data);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result =
asn1_der_decoding (&c2, crl_signed_data.data, crl_signed_data.size, NULL);
MHD__asn1_der_decoding (&c2, crl_signed_data.data, crl_signed_data.size, NULL);
if (result != ASN1_SUCCESS)
{
/* couldn't decode DER */
gnutls_assert ();
asn1_delete_structure (&c2);
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result =
asn1_der_decoding_startEnd (c2, crl_signed_data.data,
MHD__asn1_der_decoding_startEnd (c2, crl_signed_data.data,
crl_signed_data.size, "issuer",
&start1, &end1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
len1 = end1 - start1 + 1;
_gnutls_set_datum (dn, &crl_signed_data.data[start1], len1);
MHD__gnutls_set_datum (dn, &crl_signed_data.data[start1], len1);
result = 0;
cleanup:
asn1_delete_structure (&c2);
_gnutls_free_datum (&crl_signed_data);
MHD__asn1_delete_structure (&c2);
MHD__gnutls_free_datum (&crl_signed_data);
return result;
}
/**
* gnutls_x509_crl_export - This function will export the CRL
* MHD_gnutls_x509_crl_export - This function will export the CRL
* @crl: Holds the revocation list
* @format: the format of output params. One of PEM or DER.
* @output_data: will contain a private key PEM or DER encoded
@@ -632,22 +632,22 @@ cleanup:
*
**/
int
gnutls_x509_crl_export (gnutls_x509_crl_t crl,
gnutls_x509_crt_fmt_t format, void *output_data,
MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
size_t * output_data_size)
{
if (crl == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_export_int (crl->crl, format, PEM_CRL,
return MHD__gnutls_x509_export_int (crl->crl, format, PEM_CRL,
output_data, output_data_size);
}
/*-
* _gnutls_x509_crl_cpy - This function copies a gnutls_x509_crl_t structure
* MHD__gnutls_x509_crl_cpy - This function copies a MHD_gnutls_x509_crl_t structure
* @dest: The structure where to copy
* @src: The structure to be copied
*
@@ -657,44 +657,44 @@ gnutls_x509_crl_export (gnutls_x509_crl_t crl,
*
-*/
int
_gnutls_x509_crl_cpy (gnutls_x509_crl_t dest, gnutls_x509_crl_t src)
MHD__gnutls_x509_crl_cpy (MHD_gnutls_x509_crl_t dest, MHD_gnutls_x509_crl_t src)
{
int ret;
size_t der_size;
opaque *der;
gnutls_datum_t tmp;
MHD_gnutls_datum_t tmp;
ret = gnutls_x509_crl_export (src, GNUTLS_X509_FMT_DER, NULL, &der_size);
ret = MHD_gnutls_x509_crl_export (src, GNUTLS_X509_FMT_DER, NULL, &der_size);
if (ret != GNUTLS_E_SHORT_MEMORY_BUFFER)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
der = gnutls_alloca (der_size);
der = MHD_gnutls_alloca (der_size);
if (der == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
ret = gnutls_x509_crl_export (src, GNUTLS_X509_FMT_DER, der, &der_size);
ret = MHD_gnutls_x509_crl_export (src, GNUTLS_X509_FMT_DER, der, &der_size);
if (ret < 0)
{
gnutls_assert ();
gnutls_afree (der);
MHD_gnutls_assert ();
MHD_gnutls_afree (der);
return ret;
}
tmp.data = der;
tmp.size = der_size;
ret = gnutls_x509_crl_import (dest, &tmp, GNUTLS_X509_FMT_DER);
ret = MHD_gnutls_x509_crl_import (dest, &tmp, GNUTLS_X509_FMT_DER);
gnutls_afree (der);
MHD_gnutls_afree (der);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
+144 -144
View File
@@ -43,7 +43,7 @@
#include <libtasn1.h>
/**
* gnutls_x509_crq_init - This function initializes a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_init - This function initializes a MHD_gnutls_x509_crq_t structure
* @crq: The structure to be initialized
*
* This function will initialize a PKCS10 certificate request structure.
@@ -52,20 +52,20 @@
*
**/
int
gnutls_x509_crq_init (gnutls_x509_crq_t * crq)
MHD_gnutls_x509_crq_init (MHD_gnutls_x509_crq_t * crq)
{
*crq = gnutls_calloc (1, sizeof (gnutls_x509_crq_int));
*crq = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_x509_crq_int));
if (*crq)
{
int result = asn1_create_element (_gnutls_get_pkix (),
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-10-CertificationRequest",
&((*crq)->crq));
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
gnutls_free (*crq);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD_gnutls_free (*crq);
return MHD_gtls_asn2err (result);
}
return 0; /* success */
}
@@ -73,35 +73,35 @@ gnutls_x509_crq_init (gnutls_x509_crq_t * crq)
}
/**
* gnutls_x509_crq_deinit - This function deinitializes memory used by a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_deinit - This function deinitializes memory used by a MHD_gnutls_x509_crq_t structure
* @crq: The structure to be initialized
*
* This function will deinitialize a CRL structure.
*
**/
void
gnutls_x509_crq_deinit (gnutls_x509_crq_t crq)
MHD_gnutls_x509_crq_deinit (MHD_gnutls_x509_crq_t crq)
{
if (!crq)
return;
if (crq->crq)
asn1_delete_structure (&crq->crq);
MHD__asn1_delete_structure (&crq->crq);
gnutls_free (crq);
MHD_gnutls_free (crq);
}
#define PEM_CRQ "NEW CERTIFICATE REQUEST"
#define PEM_CRQ2 "CERTIFICATE REQUEST"
/**
* gnutls_x509_crq_import - This function will import a DER or PEM encoded Certificate request
* MHD_gnutls_x509_crq_import - This function will import a DER or PEM encoded Certificate request
* @crq: The structure to store the parsed certificate request.
* @data: The DER or PEM encoded certificate.
* @format: One of DER or PEM
*
* This function will convert the given DER or PEM encoded Certificate
* to the native gnutls_x509_crq_t format. The output will be stored in @cert.
* to the native MHD_gnutls_x509_crq_t format. The output will be stored in @cert.
*
* If the Certificate is PEM encoded it should have a header of "NEW CERTIFICATE REQUEST".
*
@@ -109,16 +109,16 @@ gnutls_x509_crq_deinit (gnutls_x509_crq_t crq)
*
**/
int
gnutls_x509_crq_import (gnutls_x509_crq_t crq,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format)
MHD_gnutls_x509_crq_import (MHD_gnutls_x509_crq_t crq,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format)
{
int result = 0, need_free = 0;
gnutls_datum_t _data;
MHD_gnutls_datum_t _data;
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -132,17 +132,17 @@ gnutls_x509_crq_import (gnutls_x509_crq_t crq,
opaque *out;
/* Try the first header */
result = _gnutls_fbase64_decode (PEM_CRQ, data->data, data->size, &out);
result = MHD__gnutls_fbase64_decode (PEM_CRQ, data->data, data->size, &out);
if (result <= 0) /* Go for the second header */
result =
_gnutls_fbase64_decode (PEM_CRQ2, data->data, data->size, &out);
MHD__gnutls_fbase64_decode (PEM_CRQ2, data->data, data->size, &out);
if (result <= 0)
{
if (result == 0)
result = GNUTLS_E_INTERNAL_ERROR;
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -152,11 +152,11 @@ gnutls_x509_crq_import (gnutls_x509_crq_t crq,
need_free = 1;
}
result = asn1_der_decoding (&crq->crq, _data.data, _data.size, NULL);
result = MHD__asn1_der_decoding (&crq->crq, _data.data, _data.size, NULL);
if (result != ASN1_SUCCESS)
{
result = mhd_gtls_asn2err (result);
gnutls_assert ();
result = MHD_gtls_asn2err (result);
MHD_gnutls_assert ();
goto cleanup;
}
@@ -164,15 +164,15 @@ gnutls_x509_crq_import (gnutls_x509_crq_t crq,
cleanup:
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
return result;
}
/**
* gnutls_x509_crq_get_dn - This function returns the Certificate request subject's distinguished name
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_get_dn - This function returns the Certificate request subject's distinguished name
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @buf: a pointer to a structure to hold the name (may be null)
* @sizeof_buf: initially holds the size of @buf
*
@@ -189,22 +189,22 @@ cleanup:
*
**/
int
gnutls_x509_crq_get_dn (gnutls_x509_crq_t crq, char *buf, size_t * sizeof_buf)
MHD_gnutls_x509_crq_get_dn (MHD_gnutls_x509_crq_t crq, char *buf, size_t * sizeof_buf)
{
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_parse_dn (crq->crq,
return MHD__gnutls_x509_parse_dn (crq->crq,
"certificationRequestInfo.subject.rdnSequence",
buf, sizeof_buf);
}
/**
* gnutls_x509_crq_get_dn_by_oid - This function returns the Certificate request subject's distinguished name
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_get_dn_by_oid - This function returns the Certificate request subject's distinguished name
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @oid: holds an Object Identified in null terminated string
* @indx: In case multiple same OIDs exist in the RDN, this specifies
* which to send. Use zero to get the first one.
@@ -221,7 +221,7 @@ gnutls_x509_crq_get_dn (gnutls_x509_crq_t crq, char *buf, size_t * sizeof_buf)
* If raw flag is zero, this function will only return known OIDs as
* text. Other OIDs will be DER encoded, as described in RFC2253 --
* in hex format with a '\#' prefix. You can check about known OIDs
* using gnutls_x509_dn_oid_known().
* using MHD_gnutls_x509_dn_oid_known().
*
* If @buf is null then only the size will be filled.
*
@@ -231,24 +231,24 @@ gnutls_x509_crq_get_dn (gnutls_x509_crq_t crq, char *buf, size_t * sizeof_buf)
*
**/
int
gnutls_x509_crq_get_dn_by_oid (gnutls_x509_crq_t crq, const char *oid,
MHD_gnutls_x509_crq_get_dn_by_oid (MHD_gnutls_x509_crq_t crq, const char *oid,
int indx, unsigned int raw_flag,
void *buf, size_t * sizeof_buf)
{
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_parse_dn_oid (crq->crq,
return MHD__gnutls_x509_parse_dn_oid (crq->crq,
"certificationRequestInfo.subject.rdnSequence",
oid, indx, raw_flag, buf, sizeof_buf);
}
/**
* gnutls_x509_crq_get_dn_oid - This function returns the Certificate request subject's distinguished name OIDs
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_get_dn_oid - This function returns the Certificate request subject's distinguished name OIDs
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @indx: Specifies which DN OID to send. Use zero to get the first one.
* @oid: a pointer to a structure to hold the name (may be null)
* @sizeof_oid: initially holds the size of @oid
@@ -264,30 +264,30 @@ gnutls_x509_crq_get_dn_by_oid (gnutls_x509_crq_t crq, const char *oid,
*
**/
int
gnutls_x509_crq_get_dn_oid (gnutls_x509_crq_t crq,
MHD_gnutls_x509_crq_get_dn_oid (MHD_gnutls_x509_crq_t crq,
int indx, void *oid, size_t * sizeof_oid)
{
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_get_dn_oid (crq->crq,
return MHD__gnutls_x509_get_dn_oid (crq->crq,
"certificationRequestInfo.subject.rdnSequence",
indx, oid, sizeof_oid);
}
/* Parses an Attribute list in the asn1_struct, and searches for the
/* Parses an Attribute list in the MHD__asn1_struct, and searches for the
* given OID. The index indicates the attribute value to be returned.
*
* If raw==0 only printable data are returned, or GNUTLS_E_X509_UNSUPPORTED_ATTRIBUTE.
*
* asn1_attr_name must be a string in the form "certificationRequestInfo.attributes"
* MHD__asn1_attr_name must be a string in the form "certificationRequestInfo.attributes"
*
*/
static int
parse_attribute (ASN1_TYPE asn1_struct,
parse_attribute (ASN1_TYPE MHD__asn1_struct,
const char *attr_name, const char *given_oid, int indx,
int raw, char *buf, size_t * sizeof_buf)
{
@@ -300,7 +300,7 @@ parse_attribute (ASN1_TYPE asn1_struct,
if (*sizeof_buf == 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -319,18 +319,18 @@ parse_attribute (ASN1_TYPE asn1_struct,
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
len = sizeof (value) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer1, value, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
gnutls_assert ();
MHD_gnutls_assert ();
break;
}
if (result != ASN1_VALUE_NOT_FOUND)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -338,18 +338,18 @@ parse_attribute (ASN1_TYPE asn1_struct,
*/
/* Read the OID
*/
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer1);
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer1);
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
len = sizeof (oid) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
break;
else if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -362,32 +362,32 @@ parse_attribute (ASN1_TYPE asn1_struct,
tmpbuffer1, indx + 1);
len = sizeof (value) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer3, value, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, value, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if (raw == 0)
{
printable = _gnutls_x509_oid_data_printable (oid);
printable = MHD__gnutls_x509_oid_data_printable (oid);
if (printable == 1)
{
if ((result =
_gnutls_x509_oid_data2string
MHD__gnutls_x509_oid_data2string
(oid, value, len, buf, sizeof_buf)) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
return 0;
}
else
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_X509_UNSUPPORTED_ATTRIBUTE;
}
}
@@ -403,7 +403,7 @@ parse_attribute (ASN1_TYPE asn1_struct,
else
{
*sizeof_buf = len;
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
}
@@ -412,7 +412,7 @@ parse_attribute (ASN1_TYPE asn1_struct,
}
while (1);
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
@@ -421,8 +421,8 @@ cleanup:
}
/**
* gnutls_x509_crq_get_challenge_password - This function will get the challenge password
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_get_challenge_password - This function will get the challenge password
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @pass: will hold a null terminated password
* @sizeof_pass: Initially holds the size of @pass.
*
@@ -433,12 +433,12 @@ cleanup:
*
**/
int
gnutls_x509_crq_get_challenge_password (gnutls_x509_crq_t crq,
MHD_gnutls_x509_crq_get_challenge_password (MHD_gnutls_x509_crq_t crq,
char *pass, size_t * sizeof_pass)
{
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -447,8 +447,8 @@ gnutls_x509_crq_get_challenge_password (gnutls_x509_crq_t crq,
}
/**
* gnutls_x509_crq_set_attribute_by_oid - This function will set an attribute in the request
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_set_attribute_by_oid - This function will set an attribute in the request
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @oid: holds an Object Identified in null terminated string
* @buf: a pointer to a structure that holds the attribute data
* @sizeof_buf: holds the size of @buf
@@ -460,7 +460,7 @@ gnutls_x509_crq_get_challenge_password (gnutls_x509_crq_t crq,
*
**/
int
gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
MHD_gnutls_x509_crq_set_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
const char *oid, void *buf,
size_t sizeof_buf)
{
@@ -468,30 +468,30 @@ gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
/* Add the attribute.
*/
result =
asn1_write_value (crq->crq, "certificationRequestInfo.attributes",
MHD__asn1_write_value (crq->crq, "certificationRequestInfo.attributes",
"NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result =
_gnutls_x509_encode_and_write_attribute (oid,
MHD__gnutls_x509_encode_and_write_attribute (oid,
crq->crq,
"certificationRequestInfo.attributes.?LAST",
buf, sizeof_buf, 1);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -499,8 +499,8 @@ gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
}
/**
* gnutls_x509_crq_get_attribute_by_oid - This function will get an attribute of the request
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_get_attribute_by_oid - This function will get an attribute of the request
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @oid: holds an Object Identified in null terminated string
* @indx: In case multiple same OIDs exist in the attribute list, this specifies
* which to send. Use zero to get the first one.
@@ -514,13 +514,13 @@ gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
*
**/
int
gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
MHD_gnutls_x509_crq_get_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
const char *oid, int indx, void *buf,
size_t * sizeof_buf)
{
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -529,8 +529,8 @@ gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
}
/**
* gnutls_x509_crq_set_dn_by_oid - This function will set the Certificate request subject's distinguished name
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_set_dn_by_oid - This function will set the Certificate request subject's distinguished name
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @oid: holds an Object Identifier in a null terminated string
* @raw_flag: must be 0, or 1 if the data are DER encoded
* @data: a pointer to the input data
@@ -541,7 +541,7 @@ gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
*
* Some helper macros with popular OIDs can be found in gnutls/x509.h
* With this function you can only set the known OIDs. You can test
* for known OIDs using gnutls_x509_dn_oid_known(). For OIDs that are
* for known OIDs using MHD_gnutls_x509_dn_oid_known(). For OIDs that are
* not known (by gnutls) you should properly DER encode your data, and
* call this function with raw_flag set.
*
@@ -549,7 +549,7 @@ gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
*
**/
int
gnutls_x509_crq_set_dn_by_oid (gnutls_x509_crq_t crq, const char *oid,
MHD_gnutls_x509_crq_set_dn_by_oid (MHD_gnutls_x509_crq_t crq, const char *oid,
unsigned int raw_flag, const void *data,
unsigned int sizeof_data)
{
@@ -558,14 +558,14 @@ gnutls_x509_crq_set_dn_by_oid (gnutls_x509_crq_t crq, const char *oid,
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_set_dn_oid (crq->crq,
return MHD__gnutls_x509_set_dn_oid (crq->crq,
"certificationRequestInfo.subject", oid,
raw_flag, data, sizeof_data);
}
/**
* gnutls_x509_crq_set_version - This function will set the Certificate request version
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_set_version - This function will set the Certificate request version
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @version: holds the version number. For v1 Requests must be 1.
*
* This function will set the version of the certificate request. For
@@ -575,14 +575,14 @@ gnutls_x509_crq_set_dn_by_oid (gnutls_x509_crq_t crq, const char *oid,
*
**/
int
gnutls_x509_crq_set_version (gnutls_x509_crq_t crq, unsigned int version)
MHD_gnutls_x509_crq_set_version (MHD_gnutls_x509_crq_t crq, unsigned int version)
{
int result;
unsigned char null = version;
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -590,19 +590,19 @@ gnutls_x509_crq_set_version (gnutls_x509_crq_t crq, unsigned int version)
null--;
result =
asn1_write_value (crq->crq, "certificationRequestInfo.version", &null, 1);
MHD__asn1_write_value (crq->crq, "certificationRequestInfo.version", &null, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
}
/**
* gnutls_x509_crq_get_version - This function returns the Certificate request's version number
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_get_version - This function returns the Certificate request's version number
* @crq: should contain a MHD_gnutls_x509_crq_t structure
*
* This function will return the version of the specified Certificate request.
*
@@ -610,35 +610,35 @@ gnutls_x509_crq_set_version (gnutls_x509_crq_t crq, unsigned int version)
*
**/
int
gnutls_x509_crq_get_version (gnutls_x509_crq_t crq)
MHD_gnutls_x509_crq_get_version (MHD_gnutls_x509_crq_t crq)
{
opaque version[5];
int len, result;
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
len = sizeof (version);
if ((result =
asn1_read_value (crq->crq, "certificationRequestInfo.version",
MHD__asn1_read_value (crq->crq, "certificationRequestInfo.version",
version, &len)) != ASN1_SUCCESS)
{
if (result == ASN1_ELEMENT_NOT_FOUND)
return 1; /* the DEFAULT version */
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return (int) version[0] + 1;
}
/**
* gnutls_x509_crq_set_key - This function will associate the Certificate request with a key
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_set_key - This function will associate the Certificate request with a key
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @key: holds a private key
*
* This function will set the public parameters from the given private key to the
@@ -648,17 +648,17 @@ gnutls_x509_crq_get_version (gnutls_x509_crq_t crq)
*
**/
int
gnutls_x509_crq_set_key (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
MHD_gnutls_x509_crq_set_key (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key)
{
int result;
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
result = _gnutls_x509_encode_and_copy_PKI_params (crq->crq,
result = MHD__gnutls_x509_encode_and_copy_PKI_params (crq->crq,
"certificationRequestInfo.subjectPKInfo",
key->pk_algorithm,
key->params,
@@ -666,7 +666,7 @@ gnutls_x509_crq_set_key (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -674,8 +674,8 @@ gnutls_x509_crq_set_key (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
}
/**
* gnutls_x509_crq_set_challenge_password - This function will set a challenge password
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_set_challenge_password - This function will set a challenge password
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @pass: holds a null terminated password
*
* This function will set a challenge password to be used when revoking the request.
@@ -684,37 +684,37 @@ gnutls_x509_crq_set_key (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
*
**/
int
gnutls_x509_crq_set_challenge_password (gnutls_x509_crq_t crq,
MHD_gnutls_x509_crq_set_challenge_password (MHD_gnutls_x509_crq_t crq,
const char *pass)
{
int result;
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
/* Add the attribute.
*/
result =
asn1_write_value (crq->crq, "certificationRequestInfo.attributes",
MHD__asn1_write_value (crq->crq, "certificationRequestInfo.attributes",
"NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result =
_gnutls_x509_encode_and_write_attribute ("1.2.840.113549.1.9.7",
MHD__gnutls_x509_encode_and_write_attribute ("1.2.840.113549.1.9.7",
crq->crq,
"certificationRequestInfo.attributes.?LAST",
pass, strlen (pass), 1);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -722,14 +722,14 @@ gnutls_x509_crq_set_challenge_password (gnutls_x509_crq_t crq,
}
/**
* gnutls_x509_crq_sign2 - This function will sign a Certificate request with a key
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_sign2 - This function will sign a Certificate request with a key
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @key: holds a private key
* @dig: The message digest to use. GNUTLS_DIG_SHA1 is the safe choice unless you know what you're doing.
* @flags: must be 0
*
* This function will sign the certificate request with a private key.
* This must be the same key as the one used in gnutls_x509_crt_set_key() since a
* This must be the same key as the one used in MHD_gnutls_x509_crt_set_key() since a
* certificate request is self signed.
*
* This must be the last step in a certificate request generation since all
@@ -739,52 +739,52 @@ gnutls_x509_crq_set_challenge_password (gnutls_x509_crq_t crq,
*
**/
int
gnutls_x509_crq_sign2 (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key,
MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key,
enum MHD_GNUTLS_HashAlgorithm dig, unsigned int flags)
{
int result;
gnutls_datum_t signature;
MHD_gnutls_datum_t signature;
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
/* Step 1. Self sign the request.
*/
result =
_gnutls_x509_sign_tbs (crq->crq, "certificationRequestInfo",
MHD__gnutls_x509_sign_tbs (crq->crq, "certificationRequestInfo",
dig, key, &signature);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* Step 2. write the signature (bits)
*/
result =
asn1_write_value (crq->crq, "signature", signature.data,
MHD__asn1_write_value (crq->crq, "signature", signature.data,
signature.size * 8);
_gnutls_free_datum (&signature);
MHD__gnutls_free_datum (&signature);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* Step 3. Write the signatureAlgorithm field.
*/
result = _gnutls_x509_write_sig_params (crq->crq, "signatureAlgorithm",
result = MHD__gnutls_x509_write_sig_params (crq->crq, "signatureAlgorithm",
key->pk_algorithm, dig, key->params,
key->params_size);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -792,24 +792,24 @@ gnutls_x509_crq_sign2 (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key,
}
/**
* gnutls_x509_crq_sign - This function will sign a Certificate request with a key
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_sign - This function will sign a Certificate request with a key
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @key: holds a private key
*
* This function is the same a gnutls_x509_crq_sign2() with no flags, and
* This function is the same a MHD_gnutls_x509_crq_sign2() with no flags, and
* SHA1 as the hash algorithm.
*
* Returns 0 on success.
*
**/
int
gnutls_x509_crq_sign (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
MHD_gnutls_x509_crq_sign (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key)
{
return gnutls_x509_crq_sign2 (crq, key, MHD_GNUTLS_MAC_SHA1, 0);
return MHD_gnutls_x509_crq_sign2 (crq, key, MHD_GNUTLS_MAC_SHA1, 0);
}
/**
* gnutls_x509_crq_export - Export the generated certificate request
* MHD_gnutls_x509_crq_export - Export the generated certificate request
* @crq: Holds the request
* @format: the format of output params. One of PEM or DER.
* @output_data: will contain a certificate request PEM or DER encoded
@@ -830,23 +830,23 @@ gnutls_x509_crq_sign (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
*
**/
int
gnutls_x509_crq_export (gnutls_x509_crq_t crq,
gnutls_x509_crt_fmt_t format, void *output_data,
MHD_gnutls_x509_crq_export (MHD_gnutls_x509_crq_t crq,
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
size_t * output_data_size)
{
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_export_int (crq->crq, format, PEM_CRQ,
return MHD__gnutls_x509_export_int (crq->crq, format, PEM_CRQ,
output_data, output_data_size);
}
/**
* gnutls_x509_crq_get_pk_algorithm - This function returns the certificate request's PublicKey algorithm
* @crq: should contain a gnutls_x509_crq_t structure
* MHD_gnutls_x509_crq_get_pk_algorithm - This function returns the certificate request's PublicKey algorithm
* @crq: should contain a MHD_gnutls_x509_crq_t structure
* @bits: if bits is non null it will hold the size of the parameters' in bits
*
* This function will return the public key algorithm of a PKCS \#10
@@ -862,23 +862,23 @@ gnutls_x509_crq_export (gnutls_x509_crq_t crq,
*
**/
int
gnutls_x509_crq_get_pk_algorithm (gnutls_x509_crq_t crq, unsigned int *bits)
MHD_gnutls_x509_crq_get_pk_algorithm (MHD_gnutls_x509_crq_t crq, unsigned int *bits)
{
int result;
if (crq == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
result =
_gnutls_x509_get_pk_algorithm (crq->crq,
MHD__gnutls_x509_get_pk_algorithm (crq->crq,
"certificationRequestInfo.subjectPKInfo",
bits);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
}
return result;
+2 -2
View File
@@ -24,7 +24,7 @@
#include <x509.h>
typedef struct gnutls_x509_crq_int
typedef struct MHD_gnutls_x509_crq_int
{
ASN1_TYPE crq;
} gnutls_x509_crq_int;
} MHD_gnutls_x509_crq_int;
+217 -217
View File
@@ -44,7 +44,7 @@ oid2ldap_string (const char *oid)
{
const char *ret;
ret = _gnutls_x509_oid2ldap_string (oid);
ret = MHD__gnutls_x509_oid2ldap_string (oid);
if (ret)
return ret;
@@ -80,18 +80,18 @@ str_escape (char *str, char *buffer, unsigned int buffer_size)
return buffer;
}
/* Parses an X509 DN in the asn1_struct, and puts the output into
/* Parses an X509 DN in the MHD__asn1_struct, and puts the output into
* the string buf. The output is an LDAP encoded DN.
*
* asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
* MHD__asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
* That is to point in the rndSequence.
*/
int
_gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
const char *asn1_rdn_name, char *buf,
MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
const char *MHD__asn1_rdn_name, char *buf,
size_t * sizeof_buf)
{
mhd_gtls_string out_str;
MHD_gtls_string out_str;
int k2, k1, result;
char tmpbuffer1[MAX_NAME_SIZE];
char tmpbuffer2[MAX_NAME_SIZE];
@@ -106,7 +106,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
if (sizeof_buf == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -115,7 +115,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
else
*sizeof_buf = 0;
mhd_gtls_string_init (&out_str, gnutls_malloc, gnutls_realloc, gnutls_free);
MHD_gtls_string_init (&out_str, MHD_gnutls_malloc, MHD_gnutls_realloc, MHD_gnutls_free);
k1 = 0;
do
@@ -124,14 +124,14 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
k1++;
/* create a string like "tbsCertList.issuer.rdnSequence.?1"
*/
if (asn1_rdn_name[0] != 0)
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", asn1_rdn_name,
if (MHD__asn1_rdn_name[0] != 0)
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", MHD__asn1_rdn_name,
k1);
else
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
len = sizeof (value) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer1, value, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
@@ -140,8 +140,8 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
if (result != ASN1_VALUE_NOT_FOUND)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -162,60 +162,60 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
*/
len = sizeof (value) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer2, value, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
break;
if (result != ASN1_VALUE_NOT_FOUND)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Read the OID
*/
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
len = sizeof (oid) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
break;
else if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Read the Value
*/
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
len = 0;
result = asn1_read_value (asn1_struct, tmpbuffer3, NULL, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, NULL, &len);
value2 = gnutls_malloc (len);
value2 = MHD_gnutls_malloc (len);
if (value2 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
result = asn1_read_value (asn1_struct, tmpbuffer3, value2, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, value2, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
#define STR_APPEND(y) if ((result=mhd_gtls_string_append_str( &out_str, y)) < 0) { \
gnutls_assert(); \
#define STR_APPEND(y) if ((result=MHD_gtls_string_append_str( &out_str, y)) < 0) { \
MHD_gnutls_assert(); \
goto cleanup; \
}
/* The encodings of adjoining RelativeDistinguishedNames are separated
@@ -239,24 +239,24 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
}
ldap_desc = oid2ldap_string (oid);
printable = _gnutls_x509_oid_data_printable (oid);
printable = MHD__gnutls_x509_oid_data_printable (oid);
sizeof_escaped = 2 * len + 1;
escaped = gnutls_malloc (sizeof_escaped);
escaped = MHD_gnutls_malloc (sizeof_escaped);
if (escaped == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
sizeof_string = 2 * len + 2; /* in case it is not printable */
string = gnutls_malloc (sizeof_string);
string = MHD_gnutls_malloc (sizeof_string);
if (string == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
@@ -267,30 +267,30 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
if (printable)
result =
_gnutls_x509_oid_data2string (oid,
MHD__gnutls_x509_oid_data2string (oid,
value2, len,
string, &sizeof_string);
if (!printable || result < 0)
result =
_gnutls_x509_data2hex (value2, len, string, &sizeof_string);
MHD__gnutls_x509_data2hex (value2, len, string, &sizeof_string);
if (result < 0)
{
gnutls_assert ();
_gnutls_x509_log
MHD_gnutls_assert ();
MHD__gnutls_x509_log
("Found OID: '%s' with value '%s'\n",
oid, mhd_gtls_bin2hex (value2, len, escaped,
oid, MHD_gtls_bin2hex (value2, len, escaped,
sizeof_escaped));
goto cleanup;
}
STR_APPEND (str_escape (string, escaped, sizeof_escaped));
gnutls_free (string);
MHD_gnutls_free (string);
string = NULL;
gnutls_free (escaped);
MHD_gnutls_free (escaped);
escaped = NULL;
gnutls_free (value2);
MHD_gnutls_free (value2);
value2 = NULL;
}
@@ -301,7 +301,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
if (out_str.length >= (unsigned int) *sizeof_buf)
{
gnutls_assert ();
MHD_gnutls_assert ();
*sizeof_buf = out_str.length + 1;
result = GNUTLS_E_SHORT_MEMORY_BUFFER;
goto cleanup;
@@ -317,28 +317,28 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
result = 0;
cleanup:
gnutls_free (value2);
gnutls_free (string);
gnutls_free (escaped);
mhd_gtls_string_clear (&out_str);
MHD_gnutls_free (value2);
MHD_gnutls_free (string);
MHD_gnutls_free (escaped);
MHD_gtls_string_clear (&out_str);
return result;
}
/* Parses an X509 DN in the asn1_struct, and searches for the
/* Parses an X509 DN in the MHD__asn1_struct, and searches for the
* given OID in the DN.
*
* If raw_flag == 0, the output will be encoded in the LDAP way. (#hex for non printable)
* Otherwise the raw DER data are returned.
*
* asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
* MHD__asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
* That is to point in the rndSequence.
*
* indx specifies which OID to return. Ie 0 means return the first specified
* OID found, 1 the second etc.
*/
int
_gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
const char *asn1_rdn_name,
MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
const char *MHD__asn1_rdn_name,
const char *given_oid, int indx,
unsigned int raw_flag,
void *buf, size_t * sizeof_buf)
@@ -365,25 +365,25 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
k1++;
/* create a string like "tbsCertList.issuer.rdnSequence.?1"
*/
if (asn1_rdn_name[0] != 0)
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", asn1_rdn_name,
if (MHD__asn1_rdn_name[0] != 0)
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", MHD__asn1_rdn_name,
k1);
else
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
len = sizeof (value) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer1, value, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
gnutls_assert ();
MHD_gnutls_assert ();
break;
}
if (result != ASN1_VALUE_NOT_FOUND)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -404,7 +404,7 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
*/
len = sizeof (value) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer2, value, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
@@ -412,25 +412,25 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
}
if (result != ASN1_VALUE_NOT_FOUND)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Read the OID
*/
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
len = sizeof (oid) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
break;
else if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -439,18 +439,18 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
/* Read the Value
*/
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
len = *sizeof_buf;
result = asn1_read_value (asn1_struct, tmpbuffer3, buf, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, buf, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
if (result == ASN1_MEM_ERROR)
*sizeof_buf = len;
result = mhd_gtls_asn2err (result);
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -469,19 +469,19 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
}
else
{ /* parse data. raw_flag == 0 */
printable = _gnutls_x509_oid_data_printable (oid);
printable = MHD__gnutls_x509_oid_data_printable (oid);
if (printable == 1)
result =
_gnutls_x509_oid_data2string (oid, buf, len,
MHD__gnutls_x509_oid_data2string (oid, buf, len,
cbuf, sizeof_buf);
else
result =
_gnutls_x509_data2hex (buf, len, cbuf, sizeof_buf);
MHD__gnutls_x509_data2hex (buf, len, cbuf, sizeof_buf);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
@@ -495,7 +495,7 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
}
while (1);
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
@@ -504,18 +504,18 @@ cleanup:
}
/* Parses an X509 DN in the asn1_struct, and returns the requested
/* Parses an X509 DN in the MHD__asn1_struct, and returns the requested
* DN OID.
*
* asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
* MHD__asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
* That is to point in the rndSequence.
*
* indx specifies which OID to return. Ie 0 means return the first specified
* OID found, 1 the second etc.
*/
int
_gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
const char *asn1_rdn_name,
MHD__gnutls_x509_get_dn_oid (ASN1_TYPE MHD__asn1_struct,
const char *MHD__asn1_rdn_name,
int indx, void *_oid, size_t * sizeof_oid)
{
int k2, k1, result;
@@ -534,25 +534,25 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
k1++;
/* create a string like "tbsCertList.issuer.rdnSequence.?1"
*/
if (asn1_rdn_name[0] != 0)
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", asn1_rdn_name,
if (MHD__asn1_rdn_name[0] != 0)
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", MHD__asn1_rdn_name,
k1);
else
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
len = sizeof (value) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer1, value, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
gnutls_assert ();
MHD_gnutls_assert ();
break;
}
if (result != ASN1_VALUE_NOT_FOUND)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -573,7 +573,7 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
*/
len = sizeof (value) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer2, value, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
@@ -581,25 +581,25 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
}
if (result != ASN1_VALUE_NOT_FOUND)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Read the OID
*/
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
len = sizeof (oid) - 1;
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
break;
else if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -611,7 +611,7 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
if (*sizeof_oid < (unsigned) len)
{
*sizeof_oid = len;
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
@@ -626,7 +626,7 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
}
while (1);
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
@@ -639,8 +639,8 @@ cleanup:
* In all cases only one value is written.
*/
int
_gnutls_x509_encode_and_write_attribute (const char *given_oid,
ASN1_TYPE asn1_struct,
MHD__gnutls_x509_encode_and_write_attribute (const char *given_oid,
ASN1_TYPE MHD__asn1_struct,
const char *where,
const void *_data,
int sizeof_data, int multi)
@@ -654,26 +654,26 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
/* Find how to encode the data.
*/
val_name = asn1_find_structure_from_oid (_gnutls_get_pkix (), given_oid);
val_name = MHD__asn1_find_structure_from_oid (MHD__gnutls_get_pkix (), given_oid);
if (val_name == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_X509_UNSUPPORTED_OID;
}
mhd_gtls_str_cpy (tmp, sizeof (tmp), "PKIX1.");
mhd_gtls_str_cat (tmp, sizeof (tmp), val_name);
MHD_gtls_str_cpy (tmp, sizeof (tmp), "PKIX1.");
MHD_gtls_str_cat (tmp, sizeof (tmp), val_name);
result = asn1_create_element (_gnutls_get_pkix (), tmp, &c2);
result = MHD__asn1_create_element (MHD__gnutls_get_pkix (), tmp, &c2);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
tmp[0] = 0;
if ((result = _gnutls_x509_oid_data_choice (given_oid)) > 0)
if ((result = MHD__gnutls_x509_oid_data_choice (given_oid)) > 0)
{
char *string_type;
int i;
@@ -695,64 +695,64 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
/* if the type is a CHOICE then write the
* type we'll use.
*/
result = asn1_write_value (c2, "", string_type, 1);
result = MHD__asn1_write_value (c2, "", string_type, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
return MHD_gtls_asn2err (result);
}
mhd_gtls_str_cpy (tmp, sizeof (tmp), string_type);
MHD_gtls_str_cpy (tmp, sizeof (tmp), string_type);
}
result = asn1_write_value (c2, tmp, data, sizeof_data);
result = MHD__asn1_write_value (c2, tmp, data, sizeof_data);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
return MHD_gtls_asn2err (result);
}
/* write the data (value)
*/
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
mhd_gtls_str_cat (tmp, sizeof (tmp), ".value");
MHD_gtls_str_cpy (tmp, sizeof (tmp), where);
MHD_gtls_str_cat (tmp, sizeof (tmp), ".value");
if (multi != 0)
{ /* if not writing an AttributeTypeAndValue, but an Attribute */
mhd_gtls_str_cat (tmp, sizeof (tmp), "s"); /* values */
MHD_gtls_str_cat (tmp, sizeof (tmp), "s"); /* values */
result = asn1_write_value (asn1_struct, tmp, "NEW", 1);
result = MHD__asn1_write_value (MHD__asn1_struct, tmp, "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
mhd_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
MHD_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
}
result = _gnutls_x509_der_encode_and_copy (c2, "", asn1_struct, tmp, 0);
result = MHD__gnutls_x509_der_encode_and_copy (c2, "", MHD__asn1_struct, tmp, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* write the type
*/
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
mhd_gtls_str_cat (tmp, sizeof (tmp), ".type");
MHD_gtls_str_cpy (tmp, sizeof (tmp), where);
MHD_gtls_str_cat (tmp, sizeof (tmp), ".type");
result = asn1_write_value (asn1_struct, tmp, given_oid, 1);
result = MHD__asn1_write_value (MHD__asn1_struct, tmp, given_oid, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
@@ -762,8 +762,8 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
* In all cases only one value is written.
*/
static int
_gnutls_x509_write_attribute (const char *given_oid,
ASN1_TYPE asn1_struct, const char *where,
MHD__gnutls_x509_write_attribute (const char *given_oid,
ASN1_TYPE MHD__asn1_struct, const char *where,
const void *_data, int sizeof_data)
{
char tmp[128];
@@ -772,26 +772,26 @@ _gnutls_x509_write_attribute (const char *given_oid,
/* write the data (value)
*/
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
mhd_gtls_str_cat (tmp, sizeof (tmp), ".value");
MHD_gtls_str_cpy (tmp, sizeof (tmp), where);
MHD_gtls_str_cat (tmp, sizeof (tmp), ".value");
result = asn1_write_value (asn1_struct, tmp, _data, sizeof_data);
result = MHD__asn1_write_value (MHD__asn1_struct, tmp, _data, sizeof_data);
if (result < 0)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* write the type
*/
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
mhd_gtls_str_cat (tmp, sizeof (tmp), ".type");
MHD_gtls_str_cpy (tmp, sizeof (tmp), where);
MHD_gtls_str_cat (tmp, sizeof (tmp), ".type");
result = asn1_write_value (asn1_struct, tmp, given_oid, 1);
result = MHD__asn1_write_value (MHD__asn1_struct, tmp, given_oid, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
@@ -807,9 +807,9 @@ _gnutls_x509_write_attribute (const char *given_oid,
* The output is allocated and stored in value.
*/
int
_gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
MHD__gnutls_x509_decode_and_read_attribute (ASN1_TYPE MHD__asn1_struct,
const char *where, char *oid,
int oid_size, gnutls_datum_t * value,
int oid_size, MHD_gnutls_datum_t * value,
int multi, int octet_string)
{
char tmpbuffer[128];
@@ -817,33 +817,33 @@ _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
/* Read the OID
*/
mhd_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".type");
MHD_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
MHD_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".type");
len = oid_size - 1;
result = asn1_read_value (asn1_struct, tmpbuffer, oid, &len);
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer, oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
return result;
}
/* Read the Value
*/
mhd_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".value");
MHD_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
MHD_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".value");
if (multi)
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), "s.?1"); /* .values.?1 */
MHD_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), "s.?1"); /* .values.?1 */
result =
_gnutls_x509_read_value (asn1_struct, tmpbuffer, value, octet_string);
MHD__gnutls_x509_read_value (MHD__asn1_struct, tmpbuffer, value, octet_string);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -851,83 +851,83 @@ _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
}
/* Sets an X509 DN in the asn1_struct, and puts the given OID in the DN.
/* Sets an X509 DN in the MHD__asn1_struct, and puts the given OID in the DN.
* The input is assumed to be raw data.
*
* asn1_rdn_name must be a string in the form "tbsCertificate.issuer".
* MHD__asn1_rdn_name must be a string in the form "tbsCertificate.issuer".
* That is to point before the rndSequence.
*
*/
int
_gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
const char *asn1_name, const char *given_oid,
MHD__gnutls_x509_set_dn_oid (ASN1_TYPE MHD__asn1_struct,
const char *MHD__asn1_name, const char *given_oid,
int raw_flag, const char *name, int sizeof_name)
{
int result;
char tmp[MAX_NAME_SIZE], asn1_rdn_name[MAX_NAME_SIZE];
char tmp[MAX_NAME_SIZE], MHD__asn1_rdn_name[MAX_NAME_SIZE];
if (sizeof_name == 0 || name == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
/* create the rdnSequence
*/
result = asn1_write_value (asn1_struct, asn1_name, "rdnSequence", 1);
result = MHD__asn1_write_value (MHD__asn1_struct, MHD__asn1_name, "rdnSequence", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
mhd_gtls_str_cpy (asn1_rdn_name, sizeof (asn1_rdn_name), asn1_name);
mhd_gtls_str_cat (asn1_rdn_name, sizeof (asn1_rdn_name), ".rdnSequence");
MHD_gtls_str_cpy (MHD__asn1_rdn_name, sizeof (MHD__asn1_rdn_name), MHD__asn1_name);
MHD_gtls_str_cat (MHD__asn1_rdn_name, sizeof (MHD__asn1_rdn_name), ".rdnSequence");
/* create a new element
*/
result = asn1_write_value (asn1_struct, asn1_rdn_name, "NEW", 1);
result = MHD__asn1_write_value (MHD__asn1_struct, MHD__asn1_rdn_name, "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
mhd_gtls_str_cpy (tmp, sizeof (tmp), asn1_rdn_name);
mhd_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
MHD_gtls_str_cpy (tmp, sizeof (tmp), MHD__asn1_rdn_name);
MHD_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
/* create the set with only one element
*/
result = asn1_write_value (asn1_struct, tmp, "NEW", 1);
result = MHD__asn1_write_value (MHD__asn1_struct, tmp, "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* Encode and write the data
*/
mhd_gtls_str_cpy (tmp, sizeof (tmp), asn1_rdn_name);
mhd_gtls_str_cat (tmp, sizeof (tmp), ".?LAST.?LAST");
MHD_gtls_str_cpy (tmp, sizeof (tmp), MHD__asn1_rdn_name);
MHD_gtls_str_cat (tmp, sizeof (tmp), ".?LAST.?LAST");
if (!raw_flag)
{
result =
_gnutls_x509_encode_and_write_attribute (given_oid,
asn1_struct,
MHD__gnutls_x509_encode_and_write_attribute (given_oid,
MHD__asn1_struct,
tmp, name, sizeof_name, 0);
}
else
{
result =
_gnutls_x509_write_attribute (given_oid, asn1_struct,
MHD__gnutls_x509_write_attribute (given_oid, MHD__asn1_struct,
tmp, name, sizeof_name);
}
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -936,7 +936,7 @@ _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
/**
* gnutls_x509_rdn_get - This function parses an RDN sequence and returns a string
* MHD_gnutls_x509_rdn_get - This function parses an RDN sequence and returns a string
* @idn: should contain a DER encoded RDN sequence
* @buf: a pointer to a structure to hold the peer's name
* @sizeof_buf: holds the size of @buf
@@ -951,7 +951,7 @@ _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
*
**/
int
gnutls_x509_rdn_get (const gnutls_datum_t * idn,
MHD_gnutls_x509_rdn_get (const MHD_gnutls_datum_t * idn,
char *buf, size_t * sizeof_buf)
{
int result;
@@ -959,7 +959,7 @@ gnutls_x509_rdn_get (const gnutls_datum_t * idn,
if (sizeof_buf == 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -968,31 +968,31 @@ gnutls_x509_rdn_get (const gnutls_datum_t * idn,
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&dn, idn->data, idn->size, NULL);
result = MHD__asn1_der_decoding (&dn, idn->data, idn->size, NULL);
if (result != ASN1_SUCCESS)
{
/* couldn't decode DER */
gnutls_assert ();
asn1_delete_structure (&dn);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dn);
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_parse_dn (dn, "rdnSequence", buf, sizeof_buf);
result = MHD__gnutls_x509_parse_dn (dn, "rdnSequence", buf, sizeof_buf);
asn1_delete_structure (&dn);
MHD__asn1_delete_structure (&dn);
return result;
}
/**
* gnutls_x509_rdn_get_by_oid - This function parses an RDN sequence and returns a string
* MHD_gnutls_x509_rdn_get_by_oid - This function parses an RDN sequence and returns a string
* @idn: should contain a DER encoded RDN sequence
* @oid: an Object Identifier
* @indx: In case multiple same OIDs exist in the RDN indicates which
@@ -1010,7 +1010,7 @@ gnutls_x509_rdn_get (const gnutls_datum_t * idn,
*
**/
int
gnutls_x509_rdn_get_by_oid (const gnutls_datum_t * idn, const char *oid,
MHD_gnutls_x509_rdn_get_by_oid (const MHD_gnutls_datum_t * idn, const char *oid,
int indx, unsigned int raw_flag,
void *buf, size_t * sizeof_buf)
{
@@ -1023,33 +1023,33 @@ gnutls_x509_rdn_get_by_oid (const gnutls_datum_t * idn, const char *oid,
}
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&dn, idn->data, idn->size, NULL);
result = MHD__asn1_der_decoding (&dn, idn->data, idn->size, NULL);
if (result != ASN1_SUCCESS)
{
/* couldn't decode DER */
gnutls_assert ();
asn1_delete_structure (&dn);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dn);
return MHD_gtls_asn2err (result);
}
result =
_gnutls_x509_parse_dn_oid (dn, "rdnSequence", oid, indx,
MHD__gnutls_x509_parse_dn_oid (dn, "rdnSequence", oid, indx,
raw_flag, buf, sizeof_buf);
asn1_delete_structure (&dn);
MHD__asn1_delete_structure (&dn);
return result;
}
/**
* gnutls_x509_rdn_get_oid - This function parses an RDN sequence and returns an OID.
* MHD_gnutls_x509_rdn_get_oid - This function parses an RDN sequence and returns an OID.
* @idn: should contain a DER encoded RDN sequence
* @indx: Indicates which OID to return. Use 0 for the first one.
* @oid: a pointer to a structure to hold the peer's name OID
@@ -1063,7 +1063,7 @@ gnutls_x509_rdn_get_by_oid (const gnutls_datum_t * idn, const char *oid,
*
**/
int
gnutls_x509_rdn_get_oid (const gnutls_datum_t * idn,
MHD_gnutls_x509_rdn_get_oid (const MHD_gnutls_datum_t * idn,
int indx, void *buf, size_t * sizeof_buf)
{
int result;
@@ -1075,25 +1075,25 @@ gnutls_x509_rdn_get_oid (const gnutls_datum_t * idn,
}
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&dn, idn->data, idn->size, NULL);
result = MHD__asn1_der_decoding (&dn, idn->data, idn->size, NULL);
if (result != ASN1_SUCCESS)
{
/* couldn't decode DER */
gnutls_assert ();
asn1_delete_structure (&dn);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dn);
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_get_dn_oid (dn, "rdnSequence", indx, buf, sizeof_buf);
result = MHD__gnutls_x509_get_dn_oid (dn, "rdnSequence", indx, buf, sizeof_buf);
asn1_delete_structure (&dn);
MHD__asn1_delete_structure (&dn);
return result;
}
@@ -1107,18 +1107,18 @@ gnutls_x509_rdn_get_oid (const gnutls_datum_t * idn,
* a negative value is returned to indicate error.
*/
int
_gnutls_x509_compare_raw_dn (const gnutls_datum_t * dn1,
const gnutls_datum_t * dn2)
MHD__gnutls_x509_compare_raw_dn (const MHD_gnutls_datum_t * dn1,
const MHD_gnutls_datum_t * dn2)
{
if (dn1->size != dn2->size)
{
gnutls_assert ();
MHD_gnutls_assert ();
return 0;
}
if (memcmp (dn1->data, dn2->data, dn2->size) != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return 0;
}
return 1; /* they match */
+8 -8
View File
@@ -37,21 +37,21 @@
#define OID_LDAP_UID "0.9.2342.19200300.100.1.1"
#define OID_PKCS9_EMAIL "1.2.840.113549.1.9.1"
int _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
const char *asn1_rdn_name, char *buf,
int MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
const char *MHD__asn1_rdn_name, char *buf,
size_t * sizeof_buf);
int _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
const char *asn1_rdn_name, const char *oid,
int MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
const char *MHD__asn1_rdn_name, const char *oid,
int indx, unsigned int raw_flag, void *buf,
size_t * sizeof_buf);
int _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
const char *asn1_rdn_name, const char *oid,
int MHD__gnutls_x509_set_dn_oid (ASN1_TYPE MHD__asn1_struct,
const char *MHD__asn1_rdn_name, const char *oid,
int raw_flag, const char *name, int sizeof_name);
int _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
const char *asn1_rdn_name,
int MHD__gnutls_x509_get_dn_oid (ASN1_TYPE MHD__asn1_struct,
const char *MHD__asn1_rdn_name,
int indx, void *_oid, size_t * sizeof_oid);
+15 -15
View File
@@ -33,7 +33,7 @@
/* resarr will contain: p(0), q(1), g(2), y(3), x(4).
*/
int
_gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
MHD__gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
{
int ret;
@@ -42,20 +42,20 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
/* FIXME: Remove me once we depend on 1.3.1 */
if (bits > 1024 && gcry_check_version ("1.3.1") == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (bits < 512)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
ret = gcry_sexp_build (&parms, NULL, "(genkey(dsa(nbits %d)))", bits);
if (ret != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
}
@@ -66,14 +66,14 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
if (ret != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
}
list = gcry_sexp_find_token (key, "p", 0);
if (list == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
gcry_sexp_release (key);
return GNUTLS_E_INTERNAL_ERROR;
}
@@ -84,7 +84,7 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
list = gcry_sexp_find_token (key, "q", 0);
if (list == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
gcry_sexp_release (key);
return GNUTLS_E_INTERNAL_ERROR;
}
@@ -95,7 +95,7 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
list = gcry_sexp_find_token (key, "g", 0);
if (list == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
gcry_sexp_release (key);
return GNUTLS_E_INTERNAL_ERROR;
}
@@ -106,7 +106,7 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
list = gcry_sexp_find_token (key, "y", 0);
if (list == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
gcry_sexp_release (key);
return GNUTLS_E_INTERNAL_ERROR;
}
@@ -118,7 +118,7 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
list = gcry_sexp_find_token (key, "x", 0);
if (list == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
gcry_sexp_release (key);
return GNUTLS_E_INTERNAL_ERROR;
}
@@ -129,11 +129,11 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
gcry_sexp_release (key);
_gnutls_dump_mpi ("p: ", resarr[0]);
_gnutls_dump_mpi ("q: ", resarr[1]);
_gnutls_dump_mpi ("g: ", resarr[2]);
_gnutls_dump_mpi ("y: ", resarr[3]);
_gnutls_dump_mpi ("x: ", resarr[4]);
MHD__gnutls_dump_mpi ("p: ", resarr[0]);
MHD__gnutls_dump_mpi ("q: ", resarr[1]);
MHD__gnutls_dump_mpi ("g: ", resarr[2]);
MHD__gnutls_dump_mpi ("y: ", resarr[3]);
MHD__gnutls_dump_mpi ("x: ", resarr[4]);
*resarr_len = 5;
+1 -1
View File
@@ -22,4 +22,4 @@
*
*/
int _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits);
int MHD__gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits);
+244 -244
View File
@@ -45,9 +45,9 @@
* be returned.
*/
int
_gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
MHD__gnutls_x509_crt_get_extension (MHD_gnutls_x509_crt_t cert,
const char *extension_id, int indx,
gnutls_datum_t * ret, unsigned int *_critical)
MHD_gnutls_datum_t * ret, unsigned int *_critical)
{
int k, result, len;
char name[MAX_NAME_SIZE], name2[MAX_NAME_SIZE];
@@ -55,7 +55,7 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
char str_critical[10];
int critical = 0;
char extnID[128];
gnutls_datum_t value;
MHD_gnutls_datum_t value;
int indx_counter = 0;
ret->data = NULL;
@@ -69,7 +69,7 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
snprintf (name, sizeof (name), "tbsCertificate.extensions.?%u", k);
len = sizeof (str) - 1;
result = asn1_read_value (cert->cert, name, str, &len);
result = MHD__asn1_read_value (cert->cert, name, str, &len);
/* move to next
*/
@@ -82,21 +82,21 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
do
{
mhd_gtls_str_cpy (name2, sizeof (name2), name);
mhd_gtls_str_cat (name2, sizeof (name2), ".extnID");
MHD_gtls_str_cpy (name2, sizeof (name2), name);
MHD_gtls_str_cat (name2, sizeof (name2), ".extnID");
len = sizeof (extnID) - 1;
result = asn1_read_value (cert->cert, name2, extnID, &len);
result = MHD__asn1_read_value (cert->cert, name2, extnID, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
gnutls_assert ();
MHD_gnutls_assert ();
break;
}
else if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* Handle Extension
@@ -108,22 +108,22 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
/* read the critical status.
*/
mhd_gtls_str_cpy (name2, sizeof (name2), name);
mhd_gtls_str_cat (name2, sizeof (name2), ".critical");
MHD_gtls_str_cpy (name2, sizeof (name2), name);
MHD_gtls_str_cat (name2, sizeof (name2), ".critical");
len = sizeof (str_critical);
result =
asn1_read_value (cert->cert, name2, str_critical, &len);
MHD__asn1_read_value (cert->cert, name2, str_critical, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
gnutls_assert ();
MHD_gnutls_assert ();
break;
}
else if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (str_critical[0] == 'T')
@@ -133,13 +133,13 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
/* read the value.
*/
mhd_gtls_str_cpy (name2, sizeof (name2), name);
mhd_gtls_str_cat (name2, sizeof (name2), ".extnValue");
MHD_gtls_str_cpy (name2, sizeof (name2), name);
MHD_gtls_str_cat (name2, sizeof (name2), ".extnValue");
result = _gnutls_x509_read_value (cert->cert, name2, &value, 0);
result = MHD__gnutls_x509_read_value (cert->cert, name2, &value, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -164,8 +164,8 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
}
else
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
}
@@ -176,7 +176,7 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
* be returned.
*/
int
_gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
MHD__gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
int indx, void *oid, size_t * sizeof_oid)
{
int k, result, len;
@@ -193,7 +193,7 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
snprintf (name, sizeof (name), "tbsCertificate.extensions.?%u", k);
len = sizeof (str) - 1;
result = asn1_read_value (cert->cert, name, str, &len);
result = MHD__asn1_read_value (cert->cert, name, str, &len);
/* move to next
*/
@@ -206,21 +206,21 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
do
{
mhd_gtls_str_cpy (name2, sizeof (name2), name);
mhd_gtls_str_cat (name2, sizeof (name2), ".extnID");
MHD_gtls_str_cpy (name2, sizeof (name2), name);
MHD_gtls_str_cat (name2, sizeof (name2), ".extnID");
len = sizeof (extnID) - 1;
result = asn1_read_value (cert->cert, name2, extnID, &len);
result = MHD__asn1_read_value (cert->cert, name2, extnID, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
gnutls_assert ();
MHD_gnutls_assert ();
break;
}
else if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* Handle Extension
@@ -232,7 +232,7 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
if (*sizeof_oid < (unsigned) len)
{
*sizeof_oid = len;
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
@@ -254,8 +254,8 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
}
else
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
}
@@ -266,27 +266,27 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
*/
static int
set_extension (ASN1_TYPE asn, const char *extension_id,
const gnutls_datum_t * ext_data, unsigned int critical)
const MHD_gnutls_datum_t * ext_data, unsigned int critical)
{
int result;
const char *str;
/* Add a new extension in the list.
*/
result = asn1_write_value (asn, "tbsCertificate.extensions", "NEW", 1);
result = MHD__asn1_write_value (asn, "tbsCertificate.extensions", "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result =
asn1_write_value (asn, "tbsCertificate.extensions.?LAST.extnID",
MHD__asn1_write_value (asn, "tbsCertificate.extensions.?LAST.extnID",
extension_id, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (critical == 0)
@@ -296,21 +296,21 @@ set_extension (ASN1_TYPE asn, const char *extension_id,
result =
asn1_write_value (asn, "tbsCertificate.extensions.?LAST.critical",
MHD__asn1_write_value (asn, "tbsCertificate.extensions.?LAST.critical",
str, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result =
_gnutls_x509_write_value (asn,
MHD__gnutls_x509_write_value (asn,
"tbsCertificate.extensions.?LAST.extnValue",
ext_data, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -322,7 +322,7 @@ set_extension (ASN1_TYPE asn, const char *extension_id,
*/
static int
overwrite_extension (ASN1_TYPE asn, unsigned int indx,
const gnutls_datum_t * ext_data, unsigned int critical)
const MHD_gnutls_datum_t * ext_data, unsigned int critical)
{
char name[MAX_NAME_SIZE], name2[MAX_NAME_SIZE];
const char *str;
@@ -335,23 +335,23 @@ overwrite_extension (ASN1_TYPE asn, unsigned int indx,
else
str = "TRUE";
mhd_gtls_str_cpy (name2, sizeof (name2), name);
mhd_gtls_str_cat (name2, sizeof (name2), ".critical");
MHD_gtls_str_cpy (name2, sizeof (name2), name);
MHD_gtls_str_cat (name2, sizeof (name2), ".critical");
result = asn1_write_value (asn, name2, str, 1);
result = MHD__asn1_write_value (asn, name2, str, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
mhd_gtls_str_cpy (name2, sizeof (name2), name);
mhd_gtls_str_cat (name2, sizeof (name2), ".extnValue");
MHD_gtls_str_cpy (name2, sizeof (name2), name);
MHD_gtls_str_cat (name2, sizeof (name2), ".extnValue");
result = _gnutls_x509_write_value (asn, name2, ext_data, 0);
result = MHD__gnutls_x509_write_value (asn, name2, ext_data, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -364,9 +364,9 @@ overwrite_extension (ASN1_TYPE asn, unsigned int indx,
* Critical will be either 0 or 1.
*/
int
_gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
MHD__gnutls_x509_crt_set_extension (MHD_gnutls_x509_crt_t cert,
const char *ext_id,
const gnutls_datum_t * ext_data,
const MHD_gnutls_datum_t * ext_data,
unsigned int critical)
{
int result;
@@ -384,7 +384,7 @@ _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
snprintf (name, sizeof (name), "tbsCertificate.extensions.?%u", k);
len = sizeof (extnID) - 1;
result = asn1_read_value (cert->cert, name, extnID, &len);
result = MHD__asn1_read_value (cert->cert, name, extnID, &len);
/* move to next
*/
@@ -397,21 +397,21 @@ _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
do
{
mhd_gtls_str_cpy (name2, sizeof (name2), name);
mhd_gtls_str_cat (name2, sizeof (name2), ".extnID");
MHD_gtls_str_cpy (name2, sizeof (name2), name);
MHD_gtls_str_cat (name2, sizeof (name2), ".extnID");
len = sizeof (extnID) - 1;
result = asn1_read_value (cert->cert, name2, extnID, &len);
result = MHD__asn1_read_value (cert->cert, name2, extnID, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
gnutls_assert ();
MHD_gnutls_assert ();
break;
}
else if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* Handle Extension
@@ -435,8 +435,8 @@ _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
}
else
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
@@ -448,7 +448,7 @@ _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
* extension.
*/
int
_gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
MHD__gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
opaque * extnValue, int extnValueLen)
{
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
@@ -458,34 +458,34 @@ _gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
str[0] = str[1] = 0;
*keyUsage = 0;
if ((result = asn1_create_element
(_gnutls_get_pkix (), "PKIX1.KeyUsage", &ext)) != ASN1_SUCCESS)
if ((result = MHD__asn1_create_element
(MHD__gnutls_get_pkix (), "PKIX1.KeyUsage", &ext)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
result = MHD__asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
len = sizeof (str);
result = asn1_read_value (ext, "", str, &len);
result = MHD__asn1_read_value (ext, "", str, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&ext);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return 0;
}
*keyUsage = str[0] | (str[1] << 8);
asn1_delete_structure (&ext);
MHD__asn1_delete_structure (&ext);
return 0;
}
@@ -493,7 +493,7 @@ _gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
/* extract the basicConstraints from the DER encoded extension
*/
int
_gnutls_x509_ext_extract_basicConstraints (int *CA,
MHD__gnutls_x509_ext_extract_basicConstraints (int *CA,
int *pathLenConstraint,
opaque * extnValue,
int extnValueLen)
@@ -502,45 +502,45 @@ _gnutls_x509_ext_extract_basicConstraints (int *CA,
char str[128];
int len, result;
if ((result = asn1_create_element
(_gnutls_get_pkix (), "PKIX1.BasicConstraints", &ext)) != ASN1_SUCCESS)
if ((result = MHD__asn1_create_element
(MHD__gnutls_get_pkix (), "PKIX1.BasicConstraints", &ext)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
result = MHD__asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
if (pathLenConstraint)
{
result = _gnutls_x509_read_uint (ext, "pathLenConstraint",
result = MHD__gnutls_x509_read_uint (ext, "pathLenConstraint",
pathLenConstraint);
if (result == GNUTLS_E_ASN1_ELEMENT_NOT_FOUND)
*pathLenConstraint = -1;
else if (result != GNUTLS_E_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
}
/* the default value of cA is false.
*/
len = sizeof (str) - 1;
result = asn1_read_value (ext, "cA", str, &len);
result = MHD__asn1_read_value (ext, "cA", str, &len);
if (result == ASN1_SUCCESS && strcmp (str, "TRUE") == 0)
*CA = 1;
else
*CA = 0;
asn1_delete_structure (&ext);
MHD__asn1_delete_structure (&ext);
return 0;
}
@@ -551,9 +551,9 @@ _gnutls_x509_ext_extract_basicConstraints (int *CA,
* should not be present, >= 0 to indicate set values.
*/
int
_gnutls_x509_ext_gen_basicConstraints (int CA,
MHD__gnutls_x509_ext_gen_basicConstraints (int CA,
int pathLenConstraint,
gnutls_datum_t * der_ext)
MHD_gnutls_datum_t * der_ext)
{
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
const char *str;
@@ -565,44 +565,44 @@ _gnutls_x509_ext_gen_basicConstraints (int CA,
str = "TRUE";
result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.BasicConstraints", &ext);
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.BasicConstraints", &ext);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_write_value (ext, "cA", str, 1);
result = MHD__asn1_write_value (ext, "cA", str, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
if (pathLenConstraint < 0)
{
result = asn1_write_value (ext, "pathLenConstraint", NULL, 0);
result = MHD__asn1_write_value (ext, "pathLenConstraint", NULL, 0);
if (result < 0)
result = mhd_gtls_asn2err (result);
result = MHD_gtls_asn2err (result);
}
else
result = _gnutls_x509_write_uint32 (ext, "pathLenConstraint",
result = MHD__gnutls_x509_write_uint32 (ext, "pathLenConstraint",
pathLenConstraint);
if (result < 0)
{
gnutls_assert ();
asn1_delete_structure (&ext);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return result;
}
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
asn1_delete_structure (&ext);
MHD__asn1_delete_structure (&ext);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -613,37 +613,37 @@ _gnutls_x509_ext_gen_basicConstraints (int CA,
* Use an ORed SEQUENCE of GNUTLS_KEY_* for usage.
*/
int
_gnutls_x509_ext_gen_keyUsage (uint16_t usage, gnutls_datum_t * der_ext)
MHD__gnutls_x509_ext_gen_keyUsage (uint16_t usage, MHD_gnutls_datum_t * der_ext)
{
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
int result;
uint8_t str[2];
result = asn1_create_element (_gnutls_get_pkix (), "PKIX1.KeyUsage", &ext);
result = MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.KeyUsage", &ext);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
str[0] = usage & 0xff;
str[1] = usage >> 8;
result = asn1_write_value (ext, "", str, 9);
result = MHD__asn1_write_value (ext, "", str, 9);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
asn1_delete_structure (&ext);
MHD__asn1_delete_structure (&ext);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -652,18 +652,18 @@ _gnutls_x509_ext_gen_keyUsage (uint16_t usage, gnutls_datum_t * der_ext)
static int
write_new_general_name (ASN1_TYPE ext, const char *ext_name,
gnutls_x509_subject_alt_name_t type,
MHD_gnutls_x509_subject_alt_name_t type,
const char *data_string)
{
const char *str;
int result;
char name[128];
result = asn1_write_value (ext, ext_name, "NEW", 1);
result = MHD__asn1_write_value (ext, ext_name, "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
switch (type)
@@ -681,36 +681,36 @@ write_new_general_name (ASN1_TYPE ext, const char *ext_name,
str = "iPAddress";
break;
default:
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
}
if (ext_name[0] == 0)
{ /* no dot */
mhd_gtls_str_cpy (name, sizeof (name), "?LAST");
MHD_gtls_str_cpy (name, sizeof (name), "?LAST");
}
else
{
mhd_gtls_str_cpy (name, sizeof (name), ext_name);
mhd_gtls_str_cat (name, sizeof (name), ".?LAST");
MHD_gtls_str_cpy (name, sizeof (name), ext_name);
MHD_gtls_str_cat (name, sizeof (name), ".?LAST");
}
result = asn1_write_value (ext, name, str, 1);
result = MHD__asn1_write_value (ext, name, str, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
mhd_gtls_str_cat (name, sizeof (name), ".");
mhd_gtls_str_cat (name, sizeof (name), str);
MHD_gtls_str_cat (name, sizeof (name), ".");
MHD_gtls_str_cat (name, sizeof (name), str);
result = asn1_write_value (ext, name, data_string, strlen (data_string));
result = MHD__asn1_write_value (ext, name, data_string, strlen (data_string));
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
return 0;
@@ -720,36 +720,36 @@ write_new_general_name (ASN1_TYPE ext, const char *ext_name,
* This is the same as subject alternative name.
*/
int
_gnutls_x509_ext_gen_subject_alt_name (gnutls_x509_subject_alt_name_t
MHD__gnutls_x509_ext_gen_subject_alt_name (MHD_gnutls_x509_subject_alt_name_t
type, const char *data_string,
gnutls_datum_t * der_ext)
MHD_gnutls_datum_t * der_ext)
{
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
int result;
result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.GeneralNames", &ext);
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.GeneralNames", &ext);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = write_new_general_name (ext, "", type, data_string);
if (result < 0)
{
gnutls_assert ();
asn1_delete_structure (&ext);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return result;
}
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
asn1_delete_structure (&ext);
MHD__asn1_delete_structure (&ext);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -759,36 +759,36 @@ _gnutls_x509_ext_gen_subject_alt_name (gnutls_x509_subject_alt_name_t
/* generate the SubjectKeyID in a DER encoded extension
*/
int
_gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
gnutls_datum_t * der_ext)
MHD__gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
MHD_gnutls_datum_t * der_ext)
{
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
int result;
result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.SubjectKeyIdentifier", &ext);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_write_value (ext, "", id, id_size);
result = MHD__asn1_write_value (ext, "", id, id_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
asn1_delete_structure (&ext);
MHD__asn1_delete_structure (&ext);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -798,39 +798,39 @@ _gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
/* generate the AuthorityKeyID in a DER encoded extension
*/
int
_gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
gnutls_datum_t * der_ext)
MHD__gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
MHD_gnutls_datum_t * der_ext)
{
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
int result;
result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.AuthorityKeyIdentifier", &ext);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_write_value (ext, "keyIdentifier", id, id_size);
result = MHD__asn1_write_value (ext, "keyIdentifier", id, id_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
asn1_write_value (ext, "authorityCertIssuer", NULL, 0);
asn1_write_value (ext, "authorityCertSerialNumber", NULL, 0);
MHD__asn1_write_value (ext, "authorityCertIssuer", NULL, 0);
MHD__asn1_write_value (ext, "authorityCertSerialNumber", NULL, 0);
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
asn1_delete_structure (&ext);
MHD__asn1_delete_structure (&ext);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -844,13 +844,13 @@ _gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
*
*/
int
_gnutls_x509_ext_gen_crl_dist_points (gnutls_x509_subject_alt_name_t
MHD__gnutls_x509_ext_gen_crl_dist_points (MHD_gnutls_x509_subject_alt_name_t
type, const void *data_string,
unsigned int reason_flags,
gnutls_datum_t * der_ext)
MHD_gnutls_datum_t * der_ext)
{
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
gnutls_datum_t gnames = { NULL, 0 };
MHD_gnutls_datum_t gnames = { NULL, 0 };
int result;
uint8_t reasons[2];
@@ -858,65 +858,65 @@ _gnutls_x509_ext_gen_crl_dist_points (gnutls_x509_subject_alt_name_t
reasons[1] = reason_flags >> 8;
result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.CRLDistributionPoints", &ext);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_write_value (ext, "", "NEW", 1);
result = MHD__asn1_write_value (ext, "", "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if (reason_flags)
{
result = asn1_write_value (ext, "?LAST.reasons", reasons, 9);
result = MHD__asn1_write_value (ext, "?LAST.reasons", reasons, 9);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
}
else
{
result = asn1_write_value (ext, "?LAST.reasons", NULL, 0);
result = MHD__asn1_write_value (ext, "?LAST.reasons", NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
}
result = asn1_write_value (ext, "?LAST.cRLIssuer", NULL, 0);
result = MHD__asn1_write_value (ext, "?LAST.cRLIssuer", NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* When used as type CHOICE.
*/
result = asn1_write_value (ext, "?LAST.distributionPoint", "fullName", 1);
result = MHD__asn1_write_value (ext, "?LAST.distributionPoint", "fullName", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
#if 0
/* only needed in old code (where defined as SEQUENCE OF) */
asn1_write_value (ext,
MHD__asn1_write_value (ext,
"?LAST.distributionPoint.nameRelativeToCRLIssuer",
NULL, 0);
#endif
@@ -926,23 +926,23 @@ _gnutls_x509_ext_gen_crl_dist_points (gnutls_x509_subject_alt_name_t
type, data_string);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = 0;
cleanup:
_gnutls_free_datum (&gnames);
asn1_delete_structure (&ext);
MHD__gnutls_free_datum (&gnames);
MHD__asn1_delete_structure (&ext);
return result;
}
@@ -950,7 +950,7 @@ cleanup:
/* extract the proxyCertInfo from the DER encoded extension
*/
int
_gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
MHD__gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
char **policyLanguage,
char **policy,
size_t * sizeof_policy,
@@ -958,49 +958,49 @@ _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
{
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
int result;
gnutls_datum_t value;
MHD_gnutls_datum_t value;
if ((result = asn1_create_element
(_gnutls_get_pkix (), "PKIX1.ProxyCertInfo", &ext)) != ASN1_SUCCESS)
if ((result = MHD__asn1_create_element
(MHD__gnutls_get_pkix (), "PKIX1.ProxyCertInfo", &ext)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
result = MHD__asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
if (pathLenConstraint)
{
result = _gnutls_x509_read_uint (ext, "pCPathLenConstraint",
result = MHD__gnutls_x509_read_uint (ext, "pCPathLenConstraint",
pathLenConstraint);
if (result == GNUTLS_E_ASN1_ELEMENT_NOT_FOUND)
*pathLenConstraint = -1;
else if (result != GNUTLS_E_SUCCESS)
{
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
}
result = _gnutls_x509_read_value (ext, "proxyPolicy.policyLanguage",
result = MHD__gnutls_x509_read_value (ext, "proxyPolicy.policyLanguage",
&value, 0);
if (result < 0)
{
gnutls_assert ();
asn1_delete_structure (&ext);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return result;
}
if (policyLanguage)
*policyLanguage = gnutls_strdup (value.data);
*policyLanguage = MHD_gnutls_strdup (value.data);
result = _gnutls_x509_read_value (ext, "proxyPolicy.policy", &value, 0);
result = MHD__gnutls_x509_read_value (ext, "proxyPolicy.policy", &value, 0);
if (result == GNUTLS_E_ASN1_ELEMENT_NOT_FOUND)
{
if (policy)
@@ -1010,8 +1010,8 @@ _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
}
else if (result < 0)
{
gnutls_assert ();
asn1_delete_structure (&ext);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return result;
}
else
@@ -1022,7 +1022,7 @@ _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
*sizeof_policy = value.size;
}
asn1_delete_structure (&ext);
MHD__asn1_delete_structure (&ext);
return 0;
}
@@ -1030,64 +1030,64 @@ _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
/* generate the proxyCertInfo in a DER encoded extension
*/
int
_gnutls_x509_ext_gen_proxyCertInfo (int pathLenConstraint,
MHD__gnutls_x509_ext_gen_proxyCertInfo (int pathLenConstraint,
const char *policyLanguage,
const char *policy,
size_t sizeof_policy,
gnutls_datum_t * der_ext)
MHD_gnutls_datum_t * der_ext)
{
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
int result;
result = asn1_create_element (_gnutls_get_pkix (),
result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.ProxyCertInfo", &ext);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (pathLenConstraint < 0)
{
result = asn1_write_value (ext, "pCPathLenConstraint", NULL, 0);
result = MHD__asn1_write_value (ext, "pCPathLenConstraint", NULL, 0);
if (result < 0)
result = mhd_gtls_asn2err (result);
result = MHD_gtls_asn2err (result);
}
else
result = _gnutls_x509_write_uint32 (ext, "pCPathLenConstraint",
result = MHD__gnutls_x509_write_uint32 (ext, "pCPathLenConstraint",
pathLenConstraint);
if (result < 0)
{
gnutls_assert ();
asn1_delete_structure (&ext);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return result;
}
result = asn1_write_value (ext, "proxyPolicy.policyLanguage",
result = MHD__asn1_write_value (ext, "proxyPolicy.policyLanguage",
policyLanguage, 1);
if (result < 0)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
result = asn1_write_value (ext, "proxyPolicy.policy",
result = MHD__asn1_write_value (ext, "proxyPolicy.policy",
policy, sizeof_policy);
if (result < 0)
{
gnutls_assert ();
asn1_delete_structure (&ext);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&ext);
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
asn1_delete_structure (&ext);
MHD__asn1_delete_structure (&ext);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
+21 -21
View File
@@ -22,47 +22,47 @@
*
*/
int _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
int MHD__gnutls_x509_crt_get_extension (MHD_gnutls_x509_crt_t cert,
const char *extension_id, int indx,
gnutls_datum_t * ret,
MHD_gnutls_datum_t * ret,
unsigned int *critical);
int _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
int MHD__gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
int indx, void *ret,
size_t * ret_size);
int _gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
int MHD__gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
opaque * extnValue, int extnValueLen);
int _gnutls_x509_ext_extract_basicConstraints (int *CA,
int MHD__gnutls_x509_ext_extract_basicConstraints (int *CA,
int *pathLenConstraint,
opaque * extnValue,
int extnValueLen);
int _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
int MHD__gnutls_x509_crt_set_extension (MHD_gnutls_x509_crt_t cert,
const char *extension_id,
const gnutls_datum_t * ext_data,
const MHD_gnutls_datum_t * ext_data,
unsigned int critical);
int _gnutls_x509_ext_gen_basicConstraints (int CA, int pathLenConstraint,
gnutls_datum_t * der_ext);
int _gnutls_x509_ext_gen_keyUsage (uint16_t usage, gnutls_datum_t * der_ext);
int _gnutls_x509_ext_gen_subject_alt_name (gnutls_x509_subject_alt_name_t
int MHD__gnutls_x509_ext_gen_basicConstraints (int CA, int pathLenConstraint,
MHD_gnutls_datum_t * der_ext);
int MHD__gnutls_x509_ext_gen_keyUsage (uint16_t usage, MHD_gnutls_datum_t * der_ext);
int MHD__gnutls_x509_ext_gen_subject_alt_name (MHD_gnutls_x509_subject_alt_name_t
type, const char *data_string,
gnutls_datum_t * der_ext);
int _gnutls_x509_ext_gen_crl_dist_points (gnutls_x509_subject_alt_name_t
MHD_gnutls_datum_t * der_ext);
int MHD__gnutls_x509_ext_gen_crl_dist_points (MHD_gnutls_x509_subject_alt_name_t
type, const void *data_string,
unsigned int reason_flags,
gnutls_datum_t * der_ext);
int _gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
gnutls_datum_t * der_data);
int _gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
gnutls_datum_t * der_data);
MHD_gnutls_datum_t * der_ext);
int MHD__gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
MHD_gnutls_datum_t * der_data);
int MHD__gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
MHD_gnutls_datum_t * der_data);
int _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
int MHD__gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
char **policyLanguage,
char **policy,
size_t * sizeof_policy,
opaque * extnValue,
int extnValueLen);
int _gnutls_x509_ext_gen_proxyCertInfo (int pathLenConstraint,
int MHD__gnutls_x509_ext_gen_proxyCertInfo (int pathLenConstraint,
const char *policyLanguage,
const char *policy,
size_t sizeof_policy,
gnutls_datum_t * der_ext);
MHD_gnutls_datum_t * der_ext);
+137 -137
View File
@@ -38,45 +38,45 @@
* Returns 2 parameters (m,e).
*/
int
_gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params)
MHD__gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params)
{
int result;
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
if ((result =
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.RSAPublicKey",
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.RSAPublicKey",
&spk)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&spk, der, dersize, NULL);
result = MHD__asn1_der_decoding (&spk, der, dersize, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&spk);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&spk);
return MHD_gtls_asn2err (result);
}
if ((result = _gnutls_x509_read_int (spk, "modulus", &params[0])) < 0)
if ((result = MHD__gnutls_x509_read_int (spk, "modulus", &params[0])) < 0)
{
gnutls_assert ();
asn1_delete_structure (&spk);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&spk);
return GNUTLS_E_ASN1_GENERIC_ERROR;
}
if ((result =
_gnutls_x509_read_int (spk, "publicExponent", &params[1])) < 0)
MHD__gnutls_x509_read_int (spk, "publicExponent", &params[1])) < 0)
{
gnutls_assert ();
mhd_gtls_mpi_release (&params[0]);
asn1_delete_structure (&spk);
MHD_gnutls_assert ();
MHD_gtls_mpi_release (&params[0]);
MHD__asn1_delete_structure (&spk);
return GNUTLS_E_ASN1_GENERIC_ERROR;
}
asn1_delete_structure (&spk);
MHD__asn1_delete_structure (&spk);
return 0;
@@ -87,26 +87,26 @@ _gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params)
* params[0-2]
*/
int
_gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
MHD__gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
{
int result;
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
if ((result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.Dss-Parms",
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.Dss-Parms",
&spk)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&spk, der, dersize, NULL);
result = MHD__asn1_der_decoding (&spk, der, dersize, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&spk);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&spk);
return MHD_gtls_asn2err (result);
}
/* FIXME: If the parameters are not included in the certificate
@@ -116,35 +116,35 @@ _gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
/* Read p */
if ((result = _gnutls_x509_read_int (spk, "p", &params[0])) < 0)
if ((result = MHD__gnutls_x509_read_int (spk, "p", &params[0])) < 0)
{
gnutls_assert ();
asn1_delete_structure (&spk);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&spk);
return GNUTLS_E_ASN1_GENERIC_ERROR;
}
/* Read q */
if ((result = _gnutls_x509_read_int (spk, "q", &params[1])) < 0)
if ((result = MHD__gnutls_x509_read_int (spk, "q", &params[1])) < 0)
{
gnutls_assert ();
asn1_delete_structure (&spk);
mhd_gtls_mpi_release (&params[0]);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&spk);
MHD_gtls_mpi_release (&params[0]);
return GNUTLS_E_ASN1_GENERIC_ERROR;
}
/* Read g */
if ((result = _gnutls_x509_read_int (spk, "g", &params[2])) < 0)
if ((result = MHD__gnutls_x509_read_int (spk, "g", &params[2])) < 0)
{
gnutls_assert ();
asn1_delete_structure (&spk);
mhd_gtls_mpi_release (&params[0]);
mhd_gtls_mpi_release (&params[1]);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&spk);
MHD_gtls_mpi_release (&params[0]);
MHD_gtls_mpi_release (&params[1]);
return GNUTLS_E_ASN1_GENERIC_ERROR;
}
asn1_delete_structure (&spk);
MHD__asn1_delete_structure (&spk);
return 0;
@@ -154,39 +154,39 @@ _gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
*/
int
_gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out)
MHD__gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out)
{
int result;
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
/* == INTEGER */
if ((result =
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.DSAPublicKey",
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAPublicKey",
&spk)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&spk, der, dersize, NULL);
result = MHD__asn1_der_decoding (&spk, der, dersize, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&spk);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&spk);
return MHD_gtls_asn2err (result);
}
/* Read Y */
if ((result = _gnutls_x509_read_int (spk, "", out)) < 0)
if ((result = MHD__gnutls_x509_read_int (spk, "", out)) < 0)
{
gnutls_assert ();
asn1_delete_structure (&spk);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&spk);
return MHD_gtls_asn2err (result);
}
asn1_delete_structure (&spk);
MHD__asn1_delete_structure (&spk);
return 0;
@@ -197,35 +197,35 @@ _gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out)
* only sets params[3]
*/
int
_gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params)
MHD__gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params)
{
return _gnutls_x509_read_der_int (der, dersize, &params[3]);
return MHD__gnutls_x509_read_der_int (der, dersize, &params[3]);
}
/* Extracts DSA and RSA parameters from a certificate.
*/
int
_gnutls_x509_crt_get_mpis (gnutls_x509_crt_t cert,
MHD__gnutls_x509_crt_get_mpis (MHD_gnutls_x509_crt_t cert,
mpi_t * params, int *params_size)
{
int result;
int pk_algorithm;
gnutls_datum_t tmp = { NULL, 0 };
MHD_gnutls_datum_t tmp = { NULL, 0 };
/* Read the algorithm's OID
*/
pk_algorithm = gnutls_x509_crt_get_pk_algorithm (cert, NULL);
pk_algorithm = MHD_gnutls_x509_crt_get_pk_algorithm (cert, NULL);
/* Read the algorithm's parameters
*/
result
= _gnutls_x509_read_value (cert->cert,
= MHD__gnutls_x509_read_value (cert->cert,
"tbsCertificate.subjectPublicKeyInfo.subjectPublicKey",
&tmp, 2);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -237,16 +237,16 @@ _gnutls_x509_crt_get_mpis (gnutls_x509_crt_t cert,
*/
if (*params_size < RSA_PUBLIC_PARAMS)
{
gnutls_assert ();
MHD_gnutls_assert ();
/* internal error. Increase the mpi_ts in params */
result = GNUTLS_E_INTERNAL_ERROR;
goto error;
}
if ((result =
_gnutls_x509_read_rsa_params (tmp.data, tmp.size, params)) < 0)
MHD__gnutls_x509_read_rsa_params (tmp.data, tmp.size, params)) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
*params_size = RSA_PUBLIC_PARAMS;
@@ -256,14 +256,14 @@ _gnutls_x509_crt_get_mpis (gnutls_x509_crt_t cert,
/* other types like DH
* currently not supported
*/
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_X509_CERTIFICATE_ERROR;
goto error;
}
result = 0;
error:_gnutls_free_datum (&tmp);
error:MHD__gnutls_free_datum (&tmp);
return result;
}
@@ -275,8 +275,8 @@ error:_gnutls_free_datum (&tmp);
* Allocates the space used to store the DER data.
*/
int
_gnutls_x509_write_rsa_params (mpi_t * params,
int params_size, gnutls_datum_t * der)
MHD__gnutls_x509_write_rsa_params (mpi_t * params,
int params_size, MHD_gnutls_datum_t * der)
{
int result;
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
@@ -286,44 +286,44 @@ _gnutls_x509_write_rsa_params (mpi_t * params,
if (params_size < 2)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_INVALID_REQUEST;
goto cleanup;
}
if ((result =
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.RSAPublicKey",
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.RSAPublicKey",
&spk)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_write_int (spk, "modulus", params[0], 0);
result = MHD__gnutls_x509_write_int (spk, "modulus", params[0], 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_write_int (spk, "publicExponent", params[1], 0);
result = MHD__gnutls_x509_write_int (spk, "publicExponent", params[1], 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_der_encode (spk, "", der, 0);
result = MHD__gnutls_x509_der_encode (spk, "", der, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
asn1_delete_structure (&spk);
MHD__asn1_delete_structure (&spk);
return 0;
cleanup:asn1_delete_structure (&spk);
cleanup:MHD__asn1_delete_structure (&spk);
return result;
}
@@ -333,7 +333,7 @@ cleanup:asn1_delete_structure (&spk);
* This is the "signatureAlgorithm" fields.
*/
int
_gnutls_x509_write_sig_params (ASN1_TYPE dst,
MHD__gnutls_x509_write_sig_params (ASN1_TYPE dst,
const char *dst_name,
enum MHD_GNUTLS_PublicKeyAlgorithm
pk_algorithm,
@@ -344,39 +344,39 @@ _gnutls_x509_write_sig_params (ASN1_TYPE dst,
char name[128];
const char *pk;
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
mhd_gtls_str_cat (name, sizeof (name), ".algorithm");
MHD_gtls_str_cpy (name, sizeof (name), dst_name);
MHD_gtls_str_cat (name, sizeof (name), ".algorithm");
pk = mhd_gtls_x509_sign_to_oid (pk_algorithm, HASH2MAC (dig));
pk = MHD_gtls_x509_sign_to_oid (pk_algorithm, HASH2MAC (dig));
if (pk == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
/* write the OID.
*/
result = asn1_write_value (dst, name, pk, 1);
result = MHD__asn1_write_value (dst, name, pk, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
mhd_gtls_str_cat (name, sizeof (name), ".parameters");
MHD_gtls_str_cpy (name, sizeof (name), dst_name);
MHD_gtls_str_cat (name, sizeof (name), ".parameters");
if (pk_algorithm == MHD_GNUTLS_PK_RSA)
{ /* RSA */
result = asn1_write_value (dst, name, NULL, 0);
result = MHD__asn1_write_value (dst, name, NULL, 0);
if (result != ASN1_SUCCESS && result != ASN1_ELEMENT_NOT_FOUND)
{
/* Here we ignore the element not found error, since this
* may have been disabled before.
*/
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
}
@@ -390,8 +390,8 @@ _gnutls_x509_write_sig_params (ASN1_TYPE dst,
* Allocates the space used to store the DER data.
*/
int
_gnutls_x509_write_dsa_params (mpi_t * params,
int params_size, gnutls_datum_t * der)
MHD__gnutls_x509_write_dsa_params (mpi_t * params,
int params_size, MHD_gnutls_datum_t * der)
{
int result;
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
@@ -401,50 +401,50 @@ _gnutls_x509_write_dsa_params (mpi_t * params,
if (params_size < 3)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_INVALID_REQUEST;
goto cleanup;
}
if ((result =
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.DSAParameters",
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAParameters",
&spk)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_write_int (spk, "p", params[0], 0);
result = MHD__gnutls_x509_write_int (spk, "p", params[0], 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_write_int (spk, "q", params[1], 0);
result = MHD__gnutls_x509_write_int (spk, "q", params[1], 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_write_int (spk, "g", params[2], 0);
result = MHD__gnutls_x509_write_int (spk, "g", params[2], 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_der_encode (spk, "", der, 0);
result = MHD__gnutls_x509_der_encode (spk, "", der, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = 0;
cleanup:asn1_delete_structure (&spk);
cleanup:MHD__asn1_delete_structure (&spk);
return result;
}
@@ -455,8 +455,8 @@ cleanup:asn1_delete_structure (&spk);
* Allocates the space used to store the DER data.
*/
int
_gnutls_x509_write_dsa_public_key (mpi_t * params,
int params_size, gnutls_datum_t * der)
MHD__gnutls_x509_write_dsa_public_key (mpi_t * params,
int params_size, MHD_gnutls_datum_t * der)
{
int result;
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
@@ -466,37 +466,37 @@ _gnutls_x509_write_dsa_public_key (mpi_t * params,
if (params_size < 3)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_INVALID_REQUEST;
goto cleanup;
}
if ((result =
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.DSAPublicKey",
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAPublicKey",
&spk)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_write_int (spk, "", params[3], 0);
result = MHD__gnutls_x509_write_int (spk, "", params[3], 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_der_encode (spk, "", der, 0);
result = MHD__gnutls_x509_der_encode (spk, "", der, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
asn1_delete_structure (&spk);
MHD__asn1_delete_structure (&spk);
return 0;
cleanup:asn1_delete_structure (&spk);
cleanup:MHD__asn1_delete_structure (&spk);
return result;
}
@@ -505,51 +505,51 @@ cleanup:asn1_delete_structure (&spk);
* steps.
*/
int
_gnutls_x509_read_uint (ASN1_TYPE node, const char *value, unsigned int *ret)
MHD__gnutls_x509_read_uint (ASN1_TYPE node, const char *value, unsigned int *ret)
{
int len, result;
opaque *tmpstr;
len = 0;
result = asn1_read_value (node, value, NULL, &len);
result = MHD__asn1_read_value (node, value, NULL, &len);
if (result != ASN1_MEM_ERROR)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
tmpstr = gnutls_alloca (len);
tmpstr = MHD_gnutls_alloca (len);
if (tmpstr == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
result = asn1_read_value (node, value, tmpstr, &len);
result = MHD__asn1_read_value (node, value, tmpstr, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
gnutls_afree (tmpstr);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD_gnutls_afree (tmpstr);
return MHD_gtls_asn2err (result);
}
if (len == 1)
*ret = tmpstr[0];
else if (len == 2)
*ret = mhd_gtls_read_uint16 (tmpstr);
*ret = MHD_gtls_read_uint16 (tmpstr);
else if (len == 3)
*ret = mhd_gtls_read_uint24 (tmpstr);
*ret = MHD_gtls_read_uint24 (tmpstr);
else if (len == 4)
*ret = mhd_gtls_read_uint32 (tmpstr);
*ret = MHD_gtls_read_uint32 (tmpstr);
else
{
gnutls_assert ();
gnutls_afree (tmpstr);
MHD_gnutls_assert ();
MHD_gnutls_afree (tmpstr);
return GNUTLS_E_INTERNAL_ERROR;
}
gnutls_afree (tmpstr);
MHD_gnutls_afree (tmpstr);
return 0;
}
@@ -557,19 +557,19 @@ _gnutls_x509_read_uint (ASN1_TYPE node, const char *value, unsigned int *ret)
/* Writes the specified integer into the specified node.
*/
int
_gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value, uint32_t num)
MHD__gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value, uint32_t num)
{
opaque tmpstr[4];
int result;
mhd_gtls_write_uint32 (num, tmpstr);
MHD_gtls_write_uint32 (num, tmpstr);
result = asn1_write_value (node, value, tmpstr, 4);
result = MHD__asn1_write_value (node, value, tmpstr, 4);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
+16 -16
View File
@@ -25,32 +25,32 @@
#include <gnutls_int.h>
#include "x509.h"
int _gnutls_x509_crt_get_mpis (gnutls_x509_crt_t cert,
int MHD__gnutls_x509_crt_get_mpis (MHD_gnutls_x509_crt_t cert,
mpi_t * params, int *params_size);
int _gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params);
int _gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params);
int _gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params);
int MHD__gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params);
int MHD__gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params);
int MHD__gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params);
int _gnutls_x509_write_rsa_params (mpi_t * params, int params_size,
gnutls_datum_t * der);
int _gnutls_x509_write_dsa_params (mpi_t * params, int params_size,
gnutls_datum_t * der);
int _gnutls_x509_write_dsa_public_key (mpi_t * params, int params_size,
gnutls_datum_t * der);
int MHD__gnutls_x509_write_rsa_params (mpi_t * params, int params_size,
MHD_gnutls_datum_t * der);
int MHD__gnutls_x509_write_dsa_params (mpi_t * params, int params_size,
MHD_gnutls_datum_t * der);
int MHD__gnutls_x509_write_dsa_public_key (mpi_t * params, int params_size,
MHD_gnutls_datum_t * der);
int _gnutls_x509_read_uint (ASN1_TYPE node, const char *value,
int MHD__gnutls_x509_read_uint (ASN1_TYPE node, const char *value,
unsigned int *ret);
int _gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out);
int MHD__gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out);
int _gnutls_x509_read_int (ASN1_TYPE node, const char *value,
int MHD__gnutls_x509_read_int (ASN1_TYPE node, const char *value,
mpi_t * ret_mpi);
int _gnutls_x509_write_int (ASN1_TYPE node, const char *value, mpi_t mpi,
int MHD__gnutls_x509_write_int (ASN1_TYPE node, const char *value, mpi_t mpi,
int lz);
int _gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value,
int MHD__gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value,
uint32_t num);
int _gnutls_x509_write_sig_params (ASN1_TYPE dst, const char *dst_name,
int MHD__gnutls_x509_write_sig_params (ASN1_TYPE dst, const char *dst_name,
enum MHD_GNUTLS_PublicKeyAlgorithm
pk_algorithm,
enum MHD_GNUTLS_HashAlgorithm,
+251 -251
View File
@@ -46,26 +46,26 @@
* which holds them. Returns an ASN1_TYPE of authenticatedSafe.
*/
static int
_decode_pkcs12_auth_safe (ASN1_TYPE pkcs12, ASN1_TYPE * authen_safe,
gnutls_datum_t * raw)
_decodeMHD_pkcs12_auth_safe (ASN1_TYPE pkcs12, ASN1_TYPE * authen_safe,
MHD_gnutls_datum_t * raw)
{
char oid[128];
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
gnutls_datum_t auth_safe = { NULL, 0 };
MHD_gnutls_datum_t auth_safe = { NULL, 0 };
int tmp_size, len, result;
len = sizeof (oid) - 1;
result = asn1_read_value (pkcs12, "authSafe.contentType", oid, &len);
result = MHD__asn1_read_value (pkcs12, "authSafe.contentType", oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (strcmp (oid, DATA_OID) != 0)
{
gnutls_assert ();
_gnutls_x509_log ("Unknown PKCS12 Content OID '%s'\n", oid);
MHD_gnutls_assert ();
MHD__gnutls_x509_log ("Unknown PKCS12 Content OID '%s'\n", oid);
return GNUTLS_E_UNKNOWN_PKCS_CONTENT_TYPE;
}
@@ -74,36 +74,36 @@ _decode_pkcs12_auth_safe (ASN1_TYPE pkcs12, ASN1_TYPE * authen_safe,
tmp_size = 0;
result =
_gnutls_x509_read_value (pkcs12, "authSafe.content", &auth_safe, 1);
MHD__gnutls_x509_read_value (pkcs12, "authSafe.content", &auth_safe, 1);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
/* Step 2. Extract the authenticatedSafe.
*/
if ((result = asn1_create_element
(_gnutls_get_pkix (), "PKIX1.pkcs-12-AuthenticatedSafe",
if ((result = MHD__asn1_create_element
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-12-AuthenticatedSafe",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_der_decoding (&c2, auth_safe.data, auth_safe.size, NULL);
result = MHD__asn1_der_decoding (&c2, auth_safe.data, auth_safe.size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if (raw == NULL)
{
_gnutls_free_datum (&auth_safe);
MHD__gnutls_free_datum (&auth_safe);
}
else
{
@@ -114,19 +114,19 @@ _decode_pkcs12_auth_safe (ASN1_TYPE pkcs12, ASN1_TYPE * authen_safe,
if (authen_safe)
*authen_safe = c2;
else
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return 0;
cleanup:
if (c2)
asn1_delete_structure (&c2);
_gnutls_free_datum (&auth_safe);
MHD__asn1_delete_structure (&c2);
MHD__gnutls_free_datum (&auth_safe);
return result;
}
/**
* gnutls_pkcs12_init - This function initializes a gnutls_pkcs12_t structure
* MHD_gnutlsMHD_pkcs12_init - This function initializes a MHD_gnutlsMHD_pkcs12_t structure
* @pkcs12: The structure to be initialized
*
* This function will initialize a PKCS12 structure. PKCS12 structures
@@ -137,20 +137,20 @@ cleanup:
*
**/
int
gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12)
MHD_gnutlsMHD_pkcs12_init (MHD_gnutlsMHD_pkcs12_t * pkcs12)
{
*pkcs12 = gnutls_calloc (1, sizeof (gnutls_pkcs12_int));
*pkcs12 = MHD_gnutls_calloc (1, sizeof (MHD_gnutlsMHD_pkcs12_int));
if (*pkcs12)
{
int result = asn1_create_element (_gnutls_get_pkix (),
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-12-PFX",
&(*pkcs12)->pkcs12);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
gnutls_free (*pkcs12);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD_gnutls_free (*pkcs12);
return MHD_gtls_asn2err (result);
}
return 0; /* success */
}
@@ -158,33 +158,33 @@ gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12)
}
/**
* gnutls_pkcs12_deinit - This function deinitializes memory used by a gnutls_pkcs12_t structure
* MHD_gnutlsMHD_pkcs12_deinit - This function deinitializes memory used by a MHD_gnutlsMHD_pkcs12_t structure
* @pkcs12: The structure to be initialized
*
* This function will deinitialize a PKCS12 structure.
*
**/
void
gnutls_pkcs12_deinit (gnutls_pkcs12_t pkcs12)
MHD_gnutlsMHD_pkcs12_deinit (MHD_gnutlsMHD_pkcs12_t pkcs12)
{
if (!pkcs12)
return;
if (pkcs12->pkcs12)
asn1_delete_structure (&pkcs12->pkcs12);
MHD__asn1_delete_structure (&pkcs12->pkcs12);
gnutls_free (pkcs12);
MHD_gnutls_free (pkcs12);
}
/**
* gnutls_pkcs12_import - This function will import a DER or PEM encoded PKCS12 structure
* MHD_gnutlsMHD_pkcs12_import - This function will import a DER or PEM encoded PKCS12 structure
* @pkcs12: The structure to store the parsed PKCS12.
* @data: The DER or PEM encoded PKCS12.
* @format: One of DER or PEM
* @flags: an ORed sequence of gnutls_privkey_pkcs8_flags
* @flags: an ORed sequence of MHD_gnutls_privkey_pkcs8_flags
*
* This function will convert the given DER or PEM encoded PKCS12
* to the native gnutls_pkcs12_t format. The output will be stored in 'pkcs12'.
* to the native MHD_gnutlsMHD_pkcs12_t format. The output will be stored in 'pkcs12'.
*
* If the PKCS12 is PEM encoded it should have a header of "PKCS12".
*
@@ -192,19 +192,19 @@ gnutls_pkcs12_deinit (gnutls_pkcs12_t pkcs12)
*
**/
int
gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format, unsigned int flags)
MHD_gnutlsMHD_pkcs12_import (MHD_gnutlsMHD_pkcs12_t pkcs12,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format, unsigned int flags)
{
int result = 0, need_free = 0;
gnutls_datum_t _data;
MHD_gnutls_datum_t _data;
_data.data = data->data;
_data.size = data->size;
if (pkcs12 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -214,14 +214,14 @@ gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
{
opaque *out;
result = _gnutls_fbase64_decode (PEM_PKCS12, data->data, data->size,
result = MHD__gnutls_fbase64_decode (PEM_PKCS12, data->data, data->size,
&out);
if (result <= 0)
{
if (result == 0)
result = GNUTLS_E_INTERNAL_ERROR;
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -231,28 +231,28 @@ gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
need_free = 1;
}
result = asn1_der_decoding (&pkcs12->pkcs12, _data.data, _data.size, NULL);
result = MHD__asn1_der_decoding (&pkcs12->pkcs12, _data.data, _data.size, NULL);
if (result != ASN1_SUCCESS)
{
result = mhd_gtls_asn2err (result);
gnutls_assert ();
result = MHD_gtls_asn2err (result);
MHD_gnutls_assert ();
goto cleanup;
}
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
return 0;
cleanup:
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
return result;
}
/**
* gnutls_pkcs12_export - This function will export the pkcs12 structure
* MHD_gnutlsMHD_pkcs12_export - This function will export the pkcs12 structure
* @pkcs12: Holds the pkcs12 structure
* @format: the format of output params. One of PEM or DER.
* @output_data: will contain a structure PEM or DER encoded
@@ -273,17 +273,17 @@ cleanup:
*
**/
int
gnutls_pkcs12_export (gnutls_pkcs12_t pkcs12,
gnutls_x509_crt_fmt_t format, void *output_data,
MHD_gnutlsMHD_pkcs12_export (MHD_gnutlsMHD_pkcs12_t pkcs12,
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
size_t * output_data_size)
{
if (pkcs12 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_export_int (pkcs12->pkcs12, format, PEM_PKCS12,
return MHD__gnutls_x509_export_int (pkcs12->pkcs12, format, PEM_PKCS12,
output_data, output_data_size);
}
@@ -341,44 +341,44 @@ ucs2_to_ascii (char *data, int size)
* the given bag.
*/
int
_pkcs12_decode_safe_contents (const gnutls_datum_t * content,
gnutls_pkcs12_bag_t bag)
MHD_pkcs12_decode_safe_contents (const MHD_gnutls_datum_t * content,
MHD_gnutlsMHD_pkcs12_bag_t bag)
{
char oid[128], root[MAX_NAME_SIZE];
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int len, result;
int bag_type;
gnutls_datum_t attr_val;
MHD_gnutls_datum_t attr_val;
int count = 0, i, attributes, j;
size_t size;
/* Step 1. Extract the SEQUENCE.
*/
if ((result = asn1_create_element
(_gnutls_get_pkix (), "PKIX1.pkcs-12-SafeContents",
if ((result = MHD__asn1_create_element
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-12-SafeContents",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_der_decoding (&c2, content->data, content->size, NULL);
result = MHD__asn1_der_decoding (&c2, content->data, content->size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Count the number of bags
*/
result = asn1_number_of_elements (c2, "", &count);
result = MHD__asn1_number_of_elements (c2, "", &count);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -390,11 +390,11 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
snprintf (root, sizeof (root), "?%u.bagId", i + 1);
len = sizeof (oid);
result = asn1_read_value (c2, root, oid, &len);
result = MHD__asn1_read_value (c2, root, oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -404,7 +404,7 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
if (bag_type < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
@@ -413,37 +413,37 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
snprintf (root, sizeof (root), "?%u.bagValue", i + 1);
result = _gnutls_x509_read_value (c2, root, &bag->element[i].data, 0);
result = MHD__gnutls_x509_read_value (c2, root, &bag->element[i].data, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
if (bag_type == GNUTLS_BAG_CERTIFICATE || bag_type == GNUTLS_BAG_CRL)
{
gnutls_datum_t tmp = bag->element[i].data;
MHD_gnutls_datum_t tmp = bag->element[i].data;
result =
_pkcs12_decode_crt_bag (bag_type, &tmp, &bag->element[i].data);
MHD_pkcs12_decode_crt_bag (bag_type, &tmp, &bag->element[i].data);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
_gnutls_free_datum (&tmp);
MHD__gnutls_free_datum (&tmp);
}
/* read the bag attributes
*/
snprintf (root, sizeof (root), "?%u.bagAttributes", i + 1);
result = asn1_number_of_elements (c2, root, &attributes);
result = MHD__asn1_number_of_elements (c2, root, &attributes);
if (result != ASN1_SUCCESS && result != ASN1_ELEMENT_NOT_FOUND)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -458,13 +458,13 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
j + 1);
result =
_gnutls_x509_decode_and_read_attribute (c2, root, oid,
MHD__gnutls_x509_decode_and_read_attribute (c2, root, oid,
sizeof (oid), &attr_val,
1, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
continue; /* continue in case we find some known attributes */
}
@@ -473,14 +473,14 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
size = attr_val.size;
result =
_gnutls_x509_decode_octet_string (NULL, attr_val.data, size,
MHD__gnutls_x509_decode_octet_string (NULL, attr_val.data, size,
attr_val.data, &size);
attr_val.size = size;
if (result < 0)
{
_gnutls_free_datum (&attr_val);
gnutls_assert ();
_gnutls_x509_log
MHD__gnutls_free_datum (&attr_val);
MHD_gnutls_assert ();
MHD__gnutls_x509_log
("Error decoding PKCS12 Bag Attribute OID '%s'\n", oid);
continue;
}
@@ -490,15 +490,15 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
{
size = attr_val.size;
result =
_gnutls_x509_decode_octet_string ("BMPString",
MHD__gnutls_x509_decode_octet_string ("BMPString",
attr_val.data, size,
attr_val.data, &size);
attr_val.size = size;
if (result < 0)
{
_gnutls_free_datum (&attr_val);
gnutls_assert ();
_gnutls_x509_log
MHD__gnutls_free_datum (&attr_val);
MHD_gnutls_assert ();
MHD__gnutls_x509_log
("Error decoding PKCS12 Bag Attribute OID '%s'\n", oid);
continue;
}
@@ -507,8 +507,8 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
}
else
{
_gnutls_free_datum (&attr_val);
_gnutls_x509_log
MHD__gnutls_free_datum (&attr_val);
MHD__gnutls_x509_log
("Unknown PKCS12 Bag Attribute OID '%s'\n", oid);
}
}
@@ -518,14 +518,14 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
}
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return 0;
cleanup:
if (c2)
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
@@ -533,41 +533,41 @@ cleanup:
static int
_parse_safe_contents (ASN1_TYPE sc, const char *sc_name,
gnutls_pkcs12_bag_t bag)
MHD_gnutlsMHD_pkcs12_bag_t bag)
{
gnutls_datum_t content = { NULL, 0 };
MHD_gnutls_datum_t content = { NULL, 0 };
int result;
/* Step 1. Extract the content.
*/
result = _gnutls_x509_read_value (sc, sc_name, &content, 1);
result = MHD__gnutls_x509_read_value (sc, sc_name, &content, 1);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _pkcs12_decode_safe_contents (&content, bag);
result = MHD_pkcs12_decode_safe_contents (&content, bag);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
_gnutls_free_datum (&content);
MHD__gnutls_free_datum (&content);
return 0;
cleanup:
_gnutls_free_datum (&content);
MHD__gnutls_free_datum (&content);
return result;
}
/**
* gnutls_pkcs12_get_bag - This function returns a Bag from a PKCS12 structure
* @pkcs12: should contain a gnutls_pkcs12_t structure
* MHD_gnutlsMHD_pkcs12_get_bag - This function returns a Bag from a PKCS12 structure
* @pkcs12: should contain a MHD_gnutlsMHD_pkcs12_t structure
* @indx: contains the index of the bag to extract
* @bag: An initialized bag, where the contents of the bag will be copied
*
@@ -579,8 +579,8 @@ cleanup:
*
**/
int
gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
int indx, gnutls_pkcs12_bag_t bag)
MHD_gnutlsMHD_pkcs12_get_bag (MHD_gnutlsMHD_pkcs12_t pkcs12,
int indx, MHD_gnutlsMHD_pkcs12_bag_t bag)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int result, len;
@@ -589,16 +589,16 @@ gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
if (pkcs12 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
/* Step 1. decode the data.
*/
result = _decode_pkcs12_auth_safe (pkcs12->pkcs12, &c2, NULL);
result = _decodeMHD_pkcs12_auth_safe (pkcs12->pkcs12, &c2, NULL);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -608,7 +608,7 @@ gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
snprintf (root2, sizeof (root2), "?%u.contentType", indx + 1);
len = sizeof (oid) - 1;
result = asn1_read_value (c2, root2, oid, &len);
result = MHD__asn1_read_value (c2, root2, oid, &len);
if (result == ASN1_ELEMENT_NOT_FOUND)
{
@@ -618,8 +618,8 @@ gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -639,10 +639,10 @@ gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
bag->element[0].type = GNUTLS_BAG_ENCRYPTED;
bag->bag_elements = 1;
result = _gnutls_x509_read_value (c2, root2, &bag->element[0].data, 0);
result = MHD__gnutls_x509_read_value (c2, root2, &bag->element[0].data, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
@@ -650,7 +650,7 @@ gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
cleanup:
if (c2)
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
@@ -665,21 +665,21 @@ create_empty_pfx (ASN1_TYPE pkcs12)
/* Use version 3
*/
result = asn1_write_value (pkcs12, "version", &three, 1);
result = MHD__asn1_write_value (pkcs12, "version", &three, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Write the content type of the data
*/
result = asn1_write_value (pkcs12, "authSafe.contentType", DATA_OID, 1);
result = MHD__asn1_write_value (pkcs12, "authSafe.contentType", DATA_OID, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -687,35 +687,35 @@ create_empty_pfx (ASN1_TYPE pkcs12)
* null one in that case.
*/
if ((result = asn1_create_element
(_gnutls_get_pkix (), "PKIX1.pkcs-12-AuthenticatedSafe",
if ((result = MHD__asn1_create_element
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-12-AuthenticatedSafe",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result =
_gnutls_x509_der_encode_and_copy (c2, "", pkcs12, "authSafe.content", 1);
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs12, "authSafe.content", 1);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return 0;
cleanup:
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
/**
* gnutls_pkcs12_set_bag - This function inserts a Bag into a PKCS12 structure
* @pkcs12: should contain a gnutls_pkcs12_t structure
* MHD_gnutlsMHD_pkcs12_set_bag - This function inserts a Bag into a PKCS12 structure
* @pkcs12: should contain a MHD_gnutlsMHD_pkcs12_t structure
* @bag: An initialized bag
*
* This function will insert a Bag into the PKCS12 structure.
@@ -723,7 +723,7 @@ cleanup:
*
**/
int
gnutls_pkcs12_set_bag (gnutls_pkcs12_t pkcs12, gnutls_pkcs12_bag_t bag)
MHD_gnutlsMHD_pkcs12_set_bag (MHD_gnutlsMHD_pkcs12_t pkcs12, MHD_gnutlsMHD_pkcs12_bag_t bag)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
ASN1_TYPE safe_cont = ASN1_TYPE_EMPTY;
@@ -733,62 +733,62 @@ gnutls_pkcs12_set_bag (gnutls_pkcs12_t pkcs12, gnutls_pkcs12_bag_t bag)
if (pkcs12 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
/* Step 1. Check if the pkcs12 structure is empty. In that
* case generate an empty PFX.
*/
result = asn1_read_value (pkcs12->pkcs12, "authSafe.content", &null, &dum);
result = MHD__asn1_read_value (pkcs12->pkcs12, "authSafe.content", &null, &dum);
if (result == ASN1_VALUE_NOT_FOUND)
{
result = create_empty_pfx (pkcs12->pkcs12);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
}
/* Step 2. decode the authenticatedSafe.
*/
result = _decode_pkcs12_auth_safe (pkcs12->pkcs12, &c2, NULL);
result = _decodeMHD_pkcs12_auth_safe (pkcs12->pkcs12, &c2, NULL);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* Step 3. Encode the bag elements into a SafeContents
* structure.
*/
result = _pkcs12_encode_safe_contents (bag, &safe_cont, &enc);
result = MHD_pkcs12_encode_safe_contents (bag, &safe_cont, &enc);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* Step 4. Insert the encoded SafeContents into the AuthenticatedSafe
* structure.
*/
result = asn1_write_value (c2, "", "NEW", 1);
result = MHD__asn1_write_value (c2, "", "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if (enc)
result = asn1_write_value (c2, "?LAST.contentType", ENC_DATA_OID, 1);
result = MHD__asn1_write_value (c2, "?LAST.contentType", ENC_DATA_OID, 1);
else
result = asn1_write_value (c2, "?LAST.contentType", DATA_OID, 1);
result = MHD__asn1_write_value (c2, "?LAST.contentType", DATA_OID, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -797,56 +797,56 @@ gnutls_pkcs12_set_bag (gnutls_pkcs12_t pkcs12, gnutls_pkcs12_bag_t bag)
/* Encrypted packets are written directly.
*/
result =
asn1_write_value (c2, "?LAST.content",
MHD__asn1_write_value (c2, "?LAST.content",
bag->element[0].data.data,
bag->element[0].data.size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
}
else
{
result =
_gnutls_x509_der_encode_and_copy (safe_cont, "", c2,
MHD__gnutls_x509_der_encode_and_copy (safe_cont, "", c2,
"?LAST.content", 1);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
}
asn1_delete_structure (&safe_cont);
MHD__asn1_delete_structure (&safe_cont);
/* Step 5. Reencode and copy the AuthenticatedSafe into the pkcs12
* structure.
*/
result =
_gnutls_x509_der_encode_and_copy (c2, "", pkcs12->pkcs12,
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs12->pkcs12,
"authSafe.content", 1);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return 0;
cleanup:
asn1_delete_structure (&c2);
asn1_delete_structure (&safe_cont);
MHD__asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&safe_cont);
return result;
}
/**
* gnutls_pkcs12_generate_mac - This function generates the MAC of the PKCS12 structure
* @pkcs12: should contain a gnutls_pkcs12_t structure
* MHD_gnutlsMHD_pkcs12_generate_mac - This function generates the MAC of the PKCS12 structure
* @pkcs12: should contain a MHD_gnutlsMHD_pkcs12_t structure
* @pass: The password for the MAC
*
* This function will generate a MAC for the PKCS12 structure.
@@ -854,115 +854,115 @@ cleanup:
*
**/
int
gnutls_pkcs12_generate_mac (gnutls_pkcs12_t pkcs12, const char *pass)
MHD_gnutlsMHD_pkcs12_generate_mac (MHD_gnutlsMHD_pkcs12_t pkcs12, const char *pass)
{
opaque salt[8], key[20];
int result;
mac_hd_t td1 = NULL;
gnutls_datum_t tmp = { NULL, 0 };
MHD_gnutls_datum_t tmp = { NULL, 0 };
opaque sha_mac[20];
if (pkcs12 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
/* Generate the salt.
*/
if (gc_nonce (salt, sizeof (salt)) != GC_OK)
if (MHD_gc_nonce (salt, sizeof (salt)) != GC_OK)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_RANDOM_FAILED;
}
/* Write the salt into the structure.
*/
result =
asn1_write_value (pkcs12->pkcs12, "macData.macSalt", salt, sizeof (salt));
MHD__asn1_write_value (pkcs12->pkcs12, "macData.macSalt", salt, sizeof (salt));
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Generate the key.
*/
result = _pkcs12_string_to_key (3 /*MAC*/, salt, sizeof (salt),
result = MHD_pkcs12_string_to_key (3 /*MAC*/, salt, sizeof (salt),
1, pass, sizeof (key), key);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
/* Get the data to be MACed
*/
result = _decode_pkcs12_auth_safe (pkcs12->pkcs12, NULL, &tmp);
result = _decodeMHD_pkcs12_auth_safe (pkcs12->pkcs12, NULL, &tmp);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
/* MAC the data
*/
td1 = mhd_gtls_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
td1 = MHD_gtls_MHD_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
if (td1 == GNUTLS_MAC_FAILED)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_INTERNAL_ERROR;
goto cleanup;
}
mhd_gnutls_hash (td1, tmp.data, tmp.size);
_gnutls_free_datum (&tmp);
MHD_gnutls_hash (td1, tmp.data, tmp.size);
MHD__gnutls_free_datum (&tmp);
mhd_gnutls_hmac_deinit (td1, sha_mac);
MHD_gnutls_MHD_hmac_deinit (td1, sha_mac);
result =
asn1_write_value (pkcs12->pkcs12, "macData.mac.digest", sha_mac,
MHD__asn1_write_value (pkcs12->pkcs12, "macData.mac.digest", sha_mac,
sizeof (sha_mac));
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result =
asn1_write_value (pkcs12->pkcs12,
MHD__asn1_write_value (pkcs12->pkcs12,
"macData.mac.digestAlgorithm.parameters", NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result =
asn1_write_value (pkcs12->pkcs12,
MHD__asn1_write_value (pkcs12->pkcs12,
"macData.mac.digestAlgorithm.algorithm", HASH_OID_SHA1,
1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
return 0;
cleanup:
_gnutls_free_datum (&tmp);
MHD__gnutls_free_datum (&tmp);
return result;
}
/**
* gnutls_pkcs12_verify_mac - This function verifies the MAC of the PKCS12 structure
* @pkcs12: should contain a gnutls_pkcs12_t structure
* MHD_gnutlsMHD_pkcs12_verify_mac - This function verifies the MAC of the PKCS12 structure
* @pkcs12: should contain a MHD_gnutlsMHD_pkcs12_t structure
* @pass: The password for the MAC
*
* This function will verify the MAC for the PKCS12 structure.
@@ -970,14 +970,14 @@ cleanup:
*
**/
int
gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass)
MHD_gnutlsMHD_pkcs12_verify_mac (MHD_gnutlsMHD_pkcs12_t pkcs12, const char *pass)
{
opaque key[20];
int result;
unsigned int iter;
int len;
mac_hd_t td1 = NULL;
gnutls_datum_t tmp = { NULL, 0 }, salt =
MHD_gnutls_datum_t tmp = { NULL, 0 }, salt =
{
NULL, 0};
opaque sha_mac[20];
@@ -985,7 +985,7 @@ gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass)
if (pkcs12 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -993,7 +993,7 @@ gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass)
*/
result =
_gnutls_x509_read_uint (pkcs12->pkcs12, "macData.iterations", &iter);
MHD__gnutls_x509_read_uint (pkcs12->pkcs12, "macData.iterations", &iter);
if (result < 0)
{
iter = 1; /* the default */
@@ -1003,78 +1003,78 @@ gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass)
/* Read the salt from the structure.
*/
result =
_gnutls_x509_read_value (pkcs12->pkcs12, "macData.macSalt", &salt, 0);
MHD__gnutls_x509_read_value (pkcs12->pkcs12, "macData.macSalt", &salt, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Generate the key.
*/
result = _pkcs12_string_to_key (3 /*MAC*/, salt.data, salt.size,
result = MHD_pkcs12_string_to_key (3 /*MAC*/, salt.data, salt.size,
iter, pass, sizeof (key), key);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
_gnutls_free_datum (&salt);
MHD__gnutls_free_datum (&salt);
/* Get the data to be MACed
*/
result = _decode_pkcs12_auth_safe (pkcs12->pkcs12, NULL, &tmp);
result = _decodeMHD_pkcs12_auth_safe (pkcs12->pkcs12, NULL, &tmp);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
/* MAC the data
*/
td1 = mhd_gtls_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
td1 = MHD_gtls_MHD_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
if (td1 == GNUTLS_MAC_FAILED)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_INTERNAL_ERROR;
goto cleanup;
}
mhd_gnutls_hash (td1, tmp.data, tmp.size);
_gnutls_free_datum (&tmp);
MHD_gnutls_hash (td1, tmp.data, tmp.size);
MHD__gnutls_free_datum (&tmp);
mhd_gnutls_hmac_deinit (td1, sha_mac);
MHD_gnutls_MHD_hmac_deinit (td1, sha_mac);
len = sizeof (sha_mac_orig);
result =
asn1_read_value (pkcs12->pkcs12, "macData.mac.digest", sha_mac_orig,
MHD__asn1_read_value (pkcs12->pkcs12, "macData.mac.digest", sha_mac_orig,
&len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if (memcmp (sha_mac_orig, sha_mac, sizeof (sha_mac)) != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MAC_VERIFY_FAILED;
}
return 0;
cleanup:
_gnutls_free_datum (&tmp);
_gnutls_free_datum (&salt);
MHD__gnutls_free_datum (&tmp);
MHD__gnutls_free_datum (&salt);
return result;
}
static int
write_attributes (gnutls_pkcs12_bag_t bag, int elem,
write_attributes (MHD_gnutlsMHD_pkcs12_bag_t bag, int elem,
ASN1_TYPE c2, const char *where)
{
int result;
@@ -1088,11 +1088,11 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
{
/* no attributes
*/
result = asn1_write_value (c2, where, NULL, 0);
result = MHD__asn1_write_value (c2, where, NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
@@ -1103,25 +1103,25 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
/* Add a new Attribute
*/
result = asn1_write_value (c2, where, "NEW", 1);
result = MHD__asn1_write_value (c2, where, "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
mhd_gtls_str_cpy (root, sizeof (root), where);
mhd_gtls_str_cat (root, sizeof (root), ".?LAST");
MHD_gtls_str_cpy (root, sizeof (root), where);
MHD_gtls_str_cat (root, sizeof (root), ".?LAST");
result =
_gnutls_x509_encode_and_write_attribute (KEY_ID_OID, c2, root,
MHD__gnutls_x509_encode_and_write_attribute (KEY_ID_OID, c2, root,
bag->element[elem].
local_key_id.data,
bag->element[elem].
local_key_id.size, 1);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
}
@@ -1134,21 +1134,21 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
/* Add a new Attribute
*/
result = asn1_write_value (c2, where, "NEW", 1);
result = MHD__asn1_write_value (c2, where, "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* convert name to BMPString
*/
size = strlen (bag->element[elem].friendly_name) * 2;
name = gnutls_malloc (size);
name = MHD_gnutls_malloc (size);
if (name == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
@@ -1160,18 +1160,18 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
p++;
}
mhd_gtls_str_cpy (root, sizeof (root), where);
mhd_gtls_str_cat (root, sizeof (root), ".?LAST");
MHD_gtls_str_cpy (root, sizeof (root), where);
MHD_gtls_str_cat (root, sizeof (root), ".?LAST");
result =
_gnutls_x509_encode_and_write_attribute (FRIENDLY_NAME_OID, c2,
MHD__gnutls_x509_encode_and_write_attribute (FRIENDLY_NAME_OID, c2,
root, name, size, 1);
gnutls_free (name);
MHD_gnutls_free (name);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
}
@@ -1184,7 +1184,7 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
* the given datum. Enc is set to non zero if the data are encrypted;
*/
int
_pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
MHD_pkcs12_encode_safe_contents (MHD_gnutlsMHD_pkcs12_bag_t bag, ASN1_TYPE * contents,
int *enc)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
@@ -1203,12 +1203,12 @@ _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
/* Step 1. Create the SEQUENCE.
*/
if ((result = asn1_create_element
(_gnutls_get_pkix (), "PKIX1.pkcs-12-SafeContents",
if ((result = MHD__asn1_create_element
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-12-SafeContents",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -1218,25 +1218,25 @@ _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
oid = bag_to_oid (bag->element[i].type);
if (oid == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
continue;
}
result = asn1_write_value (c2, "", "NEW", 1);
result = MHD__asn1_write_value (c2, "", "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Copy the bag type.
*/
result = asn1_write_value (c2, "?LAST.bagId", oid, 1);
result = MHD__asn1_write_value (c2, "?LAST.bagId", oid, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -1245,7 +1245,7 @@ _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
result = write_attributes (bag, i, c2, "?LAST.bagAttributes");
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
@@ -1256,37 +1256,37 @@ _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
if (bag->element[i].type == GNUTLS_BAG_CERTIFICATE ||
bag->element[i].type == GNUTLS_BAG_CRL)
{
gnutls_datum_t tmp;
MHD_gnutls_datum_t tmp;
/* in that case encode it to a CertBag or
* a CrlBag.
*/
result =
_pkcs12_encode_crt_bag (bag->element[i].type,
MHD_pkcs12_encode_crt_bag (bag->element[i].type,
&bag->element[i].data, &tmp);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_write_value (c2, "?LAST.bagValue", &tmp, 0);
result = MHD__gnutls_x509_write_value (c2, "?LAST.bagValue", &tmp, 0);
_gnutls_free_datum (&tmp);
MHD__gnutls_free_datum (&tmp);
}
else
{
result = _gnutls_x509_write_value (c2, "?LAST.bagValue",
result = MHD__gnutls_x509_write_value (c2, "?LAST.bagValue",
&bag->element[i].data, 0);
}
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
@@ -1300,7 +1300,7 @@ _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
cleanup:
if (c2)
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
+68 -68
View File
@@ -37,15 +37,15 @@ extern "C"
/* PKCS12 structures handling
*/
struct gnutls_pkcs12_int;
struct MHD_gnutlsMHD_pkcs12_int;
struct gnutls_pkcs12_bag_int;
typedef struct gnutls_pkcs12_int
struct MHD_gnutlsMHD_pkcs12_bag_int;
typedef struct MHD_gnutlsMHD_pkcs12_int
{
ASN1_TYPE pkcs12;
} gnutls_pkcs12_int;
} MHD_gnutlsMHD_pkcs12_int;
typedef enum gnutls_pkcs12_bag_type_t
typedef enum MHD_gnutlsMHD_pkcs12_bag_type_t
{
GNUTLS_BAG_EMPTY = 0,
@@ -55,73 +55,73 @@ extern "C"
GNUTLS_BAG_CRL,
GNUTLS_BAG_ENCRYPTED = 10,
GNUTLS_BAG_UNKNOWN = 20
} gnutls_pkcs12_bag_type_t;
} MHD_gnutlsMHD_pkcs12_bag_type_t;
struct bag_element
{
gnutls_datum_t data;
gnutls_pkcs12_bag_type_t type;
gnutls_datum_t local_key_id;
MHD_gnutls_datum_t data;
MHD_gnutlsMHD_pkcs12_bag_type_t type;
MHD_gnutls_datum_t local_key_id;
char *friendly_name;
};
typedef struct gnutls_pkcs12_bag_int
typedef struct MHD_gnutlsMHD_pkcs12_bag_int
{
struct bag_element element[MAX_BAG_ELEMENTS];
int bag_elements;
} gnutls_pkcs12_bag_int;
} MHD_gnutlsMHD_pkcs12_bag_int;
/* Bag attributes */
#define FRIENDLY_NAME_OID "1.2.840.113549.1.9.20"
#define KEY_ID_OID "1.2.840.113549.1.9.21"
typedef struct gnutls_pkcs12_int *gnutls_pkcs12_t;
typedef struct gnutls_pkcs12_bag_int *gnutls_pkcs12_bag_t;
typedef struct MHD_gnutlsMHD_pkcs12_int *MHD_gnutlsMHD_pkcs12_t;
typedef struct MHD_gnutlsMHD_pkcs12_bag_int *MHD_gnutlsMHD_pkcs12_bag_t;
int gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12);
void gnutls_pkcs12_deinit (gnutls_pkcs12_t pkcs12);
int gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format, unsigned int flags);
int gnutls_pkcs12_export (gnutls_pkcs12_t pkcs12,
gnutls_x509_crt_fmt_t format,
int MHD_gnutlsMHD_pkcs12_init (MHD_gnutlsMHD_pkcs12_t * pkcs12);
void MHD_gnutlsMHD_pkcs12_deinit (MHD_gnutlsMHD_pkcs12_t pkcs12);
int MHD_gnutlsMHD_pkcs12_import (MHD_gnutlsMHD_pkcs12_t pkcs12,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format, unsigned int flags);
int MHD_gnutlsMHD_pkcs12_export (MHD_gnutlsMHD_pkcs12_t pkcs12,
MHD_gnutls_x509_crt_fmt_t format,
void *output_data, size_t * output_data_size);
int gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
int indx, gnutls_pkcs12_bag_t bag);
int gnutls_pkcs12_set_bag (gnutls_pkcs12_t pkcs12, gnutls_pkcs12_bag_t bag);
int MHD_gnutlsMHD_pkcs12_get_bag (MHD_gnutlsMHD_pkcs12_t pkcs12,
int indx, MHD_gnutlsMHD_pkcs12_bag_t bag);
int MHD_gnutlsMHD_pkcs12_set_bag (MHD_gnutlsMHD_pkcs12_t pkcs12, MHD_gnutlsMHD_pkcs12_bag_t bag);
int gnutls_pkcs12_generate_mac (gnutls_pkcs12_t pkcs12, const char *pass);
int gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass);
int MHD_gnutlsMHD_pkcs12_generate_mac (MHD_gnutlsMHD_pkcs12_t pkcs12, const char *pass);
int MHD_gnutlsMHD_pkcs12_verify_mac (MHD_gnutlsMHD_pkcs12_t pkcs12, const char *pass);
int gnutls_pkcs12_bag_decrypt (gnutls_pkcs12_bag_t bag, const char *pass);
int gnutls_pkcs12_bag_encrypt (gnutls_pkcs12_bag_t bag,
int MHD_gnutlsMHD_pkcs12_bag_decrypt (MHD_gnutlsMHD_pkcs12_bag_t bag, const char *pass);
int MHD_gnutlsMHD_pkcs12_bag_encrypt (MHD_gnutlsMHD_pkcs12_bag_t bag,
const char *pass, unsigned int flags);
gnutls_pkcs12_bag_type_t gnutls_pkcs12_bag_get_type (gnutls_pkcs12_bag_t
MHD_gnutlsMHD_pkcs12_bag_type_t MHD_gnutlsMHD_pkcs12_bag_get_type (MHD_gnutlsMHD_pkcs12_bag_t
bag, int indx);
int gnutls_pkcs12_bag_get_data (gnutls_pkcs12_bag_t bag,
int indx, gnutls_datum_t * data);
int gnutls_pkcs12_bag_set_data (gnutls_pkcs12_bag_t bag,
gnutls_pkcs12_bag_type_t type,
const gnutls_datum_t * data);
int gnutls_pkcs12_bag_set_crl (gnutls_pkcs12_bag_t bag,
gnutls_x509_crl_t crl);
int gnutls_pkcs12_bag_set_crt (gnutls_pkcs12_bag_t bag,
gnutls_x509_crt_t crt);
int MHD_gnutlsMHD_pkcs12_bag_get_data (MHD_gnutlsMHD_pkcs12_bag_t bag,
int indx, MHD_gnutls_datum_t * data);
int MHD_gnutlsMHD_pkcs12_bag_set_data (MHD_gnutlsMHD_pkcs12_bag_t bag,
MHD_gnutlsMHD_pkcs12_bag_type_t type,
const MHD_gnutls_datum_t * data);
int MHD_gnutlsMHD_pkcs12_bag_set_crl (MHD_gnutlsMHD_pkcs12_bag_t bag,
MHD_gnutls_x509_crl_t crl);
int MHD_gnutlsMHD_pkcs12_bag_set_crt (MHD_gnutlsMHD_pkcs12_bag_t bag,
MHD_gnutls_x509_crt_t crt);
int gnutls_pkcs12_bag_init (gnutls_pkcs12_bag_t * bag);
void gnutls_pkcs12_bag_deinit (gnutls_pkcs12_bag_t bag);
int gnutls_pkcs12_bag_get_count (gnutls_pkcs12_bag_t bag);
int MHD_gnutlsMHD_pkcs12_bag_init (MHD_gnutlsMHD_pkcs12_bag_t * bag);
void MHD_gnutlsMHD_pkcs12_bag_deinit (MHD_gnutlsMHD_pkcs12_bag_t bag);
int MHD_gnutlsMHD_pkcs12_bag_get_count (MHD_gnutlsMHD_pkcs12_bag_t bag);
int gnutls_pkcs12_bag_get_key_id (gnutls_pkcs12_bag_t bag,
int indx, gnutls_datum_t * id);
int gnutls_pkcs12_bag_set_key_id (gnutls_pkcs12_bag_t bag,
int indx, const gnutls_datum_t * id);
int MHD_gnutlsMHD_pkcs12_bag_get_key_id (MHD_gnutlsMHD_pkcs12_bag_t bag,
int indx, MHD_gnutls_datum_t * id);
int MHD_gnutlsMHD_pkcs12_bag_set_key_id (MHD_gnutlsMHD_pkcs12_bag_t bag,
int indx, const MHD_gnutls_datum_t * id);
int gnutls_pkcs12_bag_get_friendly_name (gnutls_pkcs12_bag_t bag,
int MHD_gnutlsMHD_pkcs12_bag_get_friendly_name (MHD_gnutlsMHD_pkcs12_bag_t bag,
int indx, char **name);
int gnutls_pkcs12_bag_set_friendly_name (gnutls_pkcs12_bag_t bag,
int MHD_gnutlsMHD_pkcs12_bag_set_friendly_name (MHD_gnutlsMHD_pkcs12_bag_t bag,
int indx, const char *name);
#ifdef __cplusplus
@@ -138,27 +138,27 @@ extern "C"
#define DATA_OID "1.2.840.113549.1.7.1"
#define ENC_DATA_OID "1.2.840.113549.1.7.6"
int gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12);
void gnutls_pkcs12_deinit (gnutls_pkcs12_t pkcs12);
int gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format, unsigned int flags);
int MHD_gnutlsMHD_pkcs12_init (MHD_gnutlsMHD_pkcs12_t * pkcs12);
void MHD_gnutlsMHD_pkcs12_deinit (MHD_gnutlsMHD_pkcs12_t pkcs12);
int MHD_gnutlsMHD_pkcs12_import (MHD_gnutlsMHD_pkcs12_t pkcs12,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format, unsigned int flags);
int gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
int indx, gnutls_pkcs12_bag_t bag);
int MHD_gnutlsMHD_pkcs12_get_bag (MHD_gnutlsMHD_pkcs12_t pkcs12,
int indx, MHD_gnutlsMHD_pkcs12_bag_t bag);
int gnutls_pkcs12_bag_init (gnutls_pkcs12_bag_t * bag);
void gnutls_pkcs12_bag_deinit (gnutls_pkcs12_bag_t bag);
int MHD_gnutlsMHD_pkcs12_bag_init (MHD_gnutlsMHD_pkcs12_bag_t * bag);
void MHD_gnutlsMHD_pkcs12_bag_deinit (MHD_gnutlsMHD_pkcs12_bag_t bag);
int _pkcs12_string_to_key (unsigned int id,
int MHD_pkcs12_string_to_key (unsigned int id,
const opaque * salt,
unsigned int salt_size,
unsigned int iter,
const char *pw,
unsigned int req_keylen, opaque * keybuf);
int _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
const char *password, gnutls_datum_t * dec);
int MHD__gnutls_pkcs7_decrypt_data (const MHD_gnutls_datum_t * data,
const char *password, MHD_gnutls_datum_t * dec);
typedef enum schema_id
{
@@ -168,18 +168,18 @@ typedef enum schema_id
PKCS12_RC2_40_SHA1
} schema_id;
int _gnutls_pkcs7_encrypt_data (schema_id schema,
const gnutls_datum_t * data,
const char *password, gnutls_datum_t * enc);
int _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
gnutls_pkcs12_bag_t bag);
int MHD__gnutls_pkcs7_encrypt_data (schema_id schema,
const MHD_gnutls_datum_t * data,
const char *password, MHD_gnutls_datum_t * enc);
int MHD_pkcs12_decode_safe_contents (const MHD_gnutls_datum_t * content,
MHD_gnutlsMHD_pkcs12_bag_t bag);
int _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag,
int MHD_pkcs12_encode_safe_contents (MHD_gnutlsMHD_pkcs12_bag_t bag,
ASN1_TYPE * content, int *enc);
int _pkcs12_decode_crt_bag (gnutls_pkcs12_bag_type_t type,
const gnutls_datum_t * in, gnutls_datum_t * out);
int _pkcs12_encode_crt_bag (gnutls_pkcs12_bag_type_t type,
const gnutls_datum_t * raw, gnutls_datum_t * out);
int MHD_pkcs12_decode_crt_bag (MHD_gnutlsMHD_pkcs12_bag_type_t type,
const MHD_gnutls_datum_t * in, MHD_gnutls_datum_t * out);
int MHD_pkcs12_encode_crt_bag (MHD_gnutlsMHD_pkcs12_bag_type_t type,
const MHD_gnutls_datum_t * raw, MHD_gnutls_datum_t * out);
#endif /* GNUTLS_PKCS12_H */
+142 -142
View File
@@ -37,7 +37,7 @@
#include <privkey.h>
/**
* gnutls_pkcs12_bag_init - This function initializes a gnutls_pkcs12_bag_t structure
* MHD_gnutlsMHD_pkcs12_bag_init - This function initializes a MHD_gnutlsMHD_pkcs12_bag_t structure
* @bag: The structure to be initialized
*
* This function will initialize a PKCS12 bag structure. PKCS12 Bags
@@ -48,9 +48,9 @@
*
**/
int
gnutls_pkcs12_bag_init (gnutls_pkcs12_bag_t * bag)
MHD_gnutlsMHD_pkcs12_bag_init (MHD_gnutlsMHD_pkcs12_bag_t * bag)
{
*bag = gnutls_calloc (1, sizeof (gnutls_pkcs12_bag_int));
*bag = MHD_gnutls_calloc (1, sizeof (MHD_gnutlsMHD_pkcs12_bag_int));
if (*bag)
{
@@ -60,15 +60,15 @@ gnutls_pkcs12_bag_init (gnutls_pkcs12_bag_t * bag)
}
static inline void
_pkcs12_bag_free_data (gnutls_pkcs12_bag_t bag)
MHD_pkcs12_bag_free_data (MHD_gnutlsMHD_pkcs12_bag_t bag)
{
int i;
for (i = 0; i < bag->bag_elements; i++)
{
_gnutls_free_datum (&bag->element[i].data);
_gnutls_free_datum (&bag->element[i].local_key_id);
gnutls_free (bag->element[i].friendly_name);
MHD__gnutls_free_datum (&bag->element[i].data);
MHD__gnutls_free_datum (&bag->element[i].local_key_id);
MHD_gnutls_free (bag->element[i].friendly_name);
bag->element[i].friendly_name = NULL;
bag->element[i].type = 0;
}
@@ -77,38 +77,38 @@ _pkcs12_bag_free_data (gnutls_pkcs12_bag_t bag)
/**
* gnutls_pkcs12_bag_deinit - This function deinitializes memory used by a gnutls_pkcs12_t structure
* MHD_gnutlsMHD_pkcs12_bag_deinit - This function deinitializes memory used by a MHD_gnutlsMHD_pkcs12_t structure
* @bag: The structure to be initialized
*
* This function will deinitialize a PKCS12 Bag structure.
*
**/
void
gnutls_pkcs12_bag_deinit (gnutls_pkcs12_bag_t bag)
MHD_gnutlsMHD_pkcs12_bag_deinit (MHD_gnutlsMHD_pkcs12_bag_t bag)
{
if (!bag)
return;
_pkcs12_bag_free_data (bag);
MHD_pkcs12_bag_free_data (bag);
gnutls_free (bag);
MHD_gnutls_free (bag);
}
/**
* gnutls_pkcs12_bag_get_type - This function returns the bag's type
* MHD_gnutlsMHD_pkcs12_bag_get_type - This function returns the bag's type
* @bag: The bag
* @indx: The element of the bag to get the type
*
* This function will return the bag's type. One of the gnutls_pkcs12_bag_type_t
* This function will return the bag's type. One of the MHD_gnutlsMHD_pkcs12_bag_type_t
* enumerations.
*
**/
gnutls_pkcs12_bag_type_t
gnutls_pkcs12_bag_get_type (gnutls_pkcs12_bag_t bag, int indx)
MHD_gnutlsMHD_pkcs12_bag_type_t
MHD_gnutlsMHD_pkcs12_bag_get_type (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx)
{
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -118,18 +118,18 @@ gnutls_pkcs12_bag_get_type (gnutls_pkcs12_bag_t bag, int indx)
}
/**
* gnutls_pkcs12_bag_get_count - This function returns the bag's elements count
* MHD_gnutlsMHD_pkcs12_bag_get_count - This function returns the bag's elements count
* @bag: The bag
*
* This function will return the number of the elements withing the bag.
*
**/
int
gnutls_pkcs12_bag_get_count (gnutls_pkcs12_bag_t bag)
MHD_gnutlsMHD_pkcs12_bag_get_count (MHD_gnutlsMHD_pkcs12_bag_t bag)
{
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -137,7 +137,7 @@ gnutls_pkcs12_bag_get_count (gnutls_pkcs12_bag_t bag)
}
/**
* gnutls_pkcs12_bag_get_data - This function returns the bag's data
* MHD_gnutlsMHD_pkcs12_bag_get_data - This function returns the bag's data
* @bag: The bag
* @indx: The element of the bag to get the data from
* @data: where the bag's data will be. Should be treated as constant.
@@ -150,12 +150,12 @@ gnutls_pkcs12_bag_get_count (gnutls_pkcs12_bag_t bag)
*
**/
int
gnutls_pkcs12_bag_get_data (gnutls_pkcs12_bag_t bag, int indx,
gnutls_datum_t * data)
MHD_gnutlsMHD_pkcs12_bag_get_data (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx,
MHD_gnutls_datum_t * data)
{
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -172,161 +172,161 @@ gnutls_pkcs12_bag_get_data (gnutls_pkcs12_bag_t bag, int indx,
#define X509_CRL_OID "1.2.840.113549.1.9.23.1"
int
_pkcs12_decode_crt_bag (gnutls_pkcs12_bag_type_t type,
const gnutls_datum_t * in, gnutls_datum_t * out)
MHD_pkcs12_decode_crt_bag (MHD_gnutlsMHD_pkcs12_bag_type_t type,
const MHD_gnutls_datum_t * in, MHD_gnutls_datum_t * out)
{
int ret;
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
if (type == GNUTLS_BAG_CERTIFICATE)
{
if ((ret = asn1_create_element (_gnutls_get_pkix (),
if ((ret = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-12-CertBag",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
ret = mhd_gtls_asn2err (ret);
MHD_gnutls_assert ();
ret = MHD_gtls_asn2err (ret);
goto cleanup;
}
ret = asn1_der_decoding (&c2, in->data, in->size, NULL);
ret = MHD__asn1_der_decoding (&c2, in->data, in->size, NULL);
if (ret != ASN1_SUCCESS)
{
gnutls_assert ();
ret = mhd_gtls_asn2err (ret);
MHD_gnutls_assert ();
ret = MHD_gtls_asn2err (ret);
goto cleanup;
}
ret = _gnutls_x509_read_value (c2, "certValue", out, 1);
ret = MHD__gnutls_x509_read_value (c2, "certValue", out, 1);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
}
else
{ /* CRL */
if ((ret = asn1_create_element (_gnutls_get_pkix (),
if ((ret = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-12-CRLBag",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
ret = mhd_gtls_asn2err (ret);
MHD_gnutls_assert ();
ret = MHD_gtls_asn2err (ret);
goto cleanup;
}
ret = asn1_der_decoding (&c2, in->data, in->size, NULL);
ret = MHD__asn1_der_decoding (&c2, in->data, in->size, NULL);
if (ret != ASN1_SUCCESS)
{
gnutls_assert ();
ret = mhd_gtls_asn2err (ret);
MHD_gnutls_assert ();
ret = MHD_gtls_asn2err (ret);
goto cleanup;
}
ret = _gnutls_x509_read_value (c2, "crlValue", out, 1);
ret = MHD__gnutls_x509_read_value (c2, "crlValue", out, 1);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
}
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return 0;
cleanup:
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return ret;
}
int
_pkcs12_encode_crt_bag (gnutls_pkcs12_bag_type_t type,
const gnutls_datum_t * raw, gnutls_datum_t * out)
MHD_pkcs12_encode_crt_bag (MHD_gnutlsMHD_pkcs12_bag_type_t type,
const MHD_gnutls_datum_t * raw, MHD_gnutls_datum_t * out)
{
int ret;
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
if (type == GNUTLS_BAG_CERTIFICATE)
{
if ((ret = asn1_create_element (_gnutls_get_pkix (),
if ((ret = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-12-CertBag",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
ret = mhd_gtls_asn2err (ret);
MHD_gnutls_assert ();
ret = MHD_gtls_asn2err (ret);
goto cleanup;
}
ret = asn1_write_value (c2, "certId", X509_CERT_OID, 1);
ret = MHD__asn1_write_value (c2, "certId", X509_CERT_OID, 1);
if (ret != ASN1_SUCCESS)
{
gnutls_assert ();
ret = mhd_gtls_asn2err (ret);
MHD_gnutls_assert ();
ret = MHD_gtls_asn2err (ret);
goto cleanup;
}
ret = _gnutls_x509_write_value (c2, "certValue", raw, 1);
ret = MHD__gnutls_x509_write_value (c2, "certValue", raw, 1);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
}
else
{ /* CRL */
if ((ret = asn1_create_element (_gnutls_get_pkix (),
if ((ret = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-12-CRLBag",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
ret = mhd_gtls_asn2err (ret);
MHD_gnutls_assert ();
ret = MHD_gtls_asn2err (ret);
goto cleanup;
}
ret = asn1_write_value (c2, "crlId", X509_CRL_OID, 1);
ret = MHD__asn1_write_value (c2, "crlId", X509_CRL_OID, 1);
if (ret != ASN1_SUCCESS)
{
gnutls_assert ();
ret = mhd_gtls_asn2err (ret);
MHD_gnutls_assert ();
ret = MHD_gtls_asn2err (ret);
goto cleanup;
}
ret = _gnutls_x509_write_value (c2, "crlValue", raw, 1);
ret = MHD__gnutls_x509_write_value (c2, "crlValue", raw, 1);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
}
ret = _gnutls_x509_der_encode (c2, "", out, 0);
ret = MHD__gnutls_x509_der_encode (c2, "", out, 0);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return 0;
cleanup:
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return ret;
}
/**
* gnutls_pkcs12_bag_set_data - This function inserts data into the bag
* MHD_gnutlsMHD_pkcs12_bag_set_data - This function inserts data into the bag
* @bag: The bag
* @type: The data's type
* @data: the data to be copied.
@@ -339,20 +339,20 @@ cleanup:
*
**/
int
gnutls_pkcs12_bag_set_data (gnutls_pkcs12_bag_t bag,
gnutls_pkcs12_bag_type_t type,
const gnutls_datum_t * data)
MHD_gnutlsMHD_pkcs12_bag_set_data (MHD_gnutlsMHD_pkcs12_bag_t bag,
MHD_gnutlsMHD_pkcs12_bag_type_t type,
const MHD_gnutls_datum_t * data)
{
int ret;
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (bag->bag_elements == MAX_BAG_ELEMENTS - 1)
{
gnutls_assert ();
MHD_gnutls_assert ();
/* bag is full */
return GNUTLS_E_MEMORY_ERROR;
}
@@ -367,18 +367,18 @@ gnutls_pkcs12_bag_set_data (gnutls_pkcs12_bag_t bag,
bag->element[0].type == GNUTLS_BAG_PKCS8_ENCRYPTED_KEY ||
bag->element[0].type == GNUTLS_BAG_ENCRYPTED)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
}
ret =
_gnutls_set_datum (&bag->element[bag->bag_elements].data,
MHD__gnutls_set_datum (&bag->element[bag->bag_elements].data,
data->data, data->size);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -390,84 +390,84 @@ gnutls_pkcs12_bag_set_data (gnutls_pkcs12_bag_t bag,
}
/**
* gnutls_pkcs12_bag_set_crt - This function inserts a certificate into the bag
* MHD_gnutlsMHD_pkcs12_bag_set_crt - This function inserts a certificate into the bag
* @bag: The bag
* @crt: the certificate to be copied.
*
* This function will insert the given certificate into the
* bag. This is just a wrapper over gnutls_pkcs12_bag_set_data().
* bag. This is just a wrapper over MHD_gnutlsMHD_pkcs12_bag_set_data().
*
* Returns the index of the added bag on success, or a negative
* value on failure.
*
**/
int
gnutls_pkcs12_bag_set_crt (gnutls_pkcs12_bag_t bag, gnutls_x509_crt_t crt)
MHD_gnutlsMHD_pkcs12_bag_set_crt (MHD_gnutlsMHD_pkcs12_bag_t bag, MHD_gnutls_x509_crt_t crt)
{
int ret;
gnutls_datum_t data;
MHD_gnutls_datum_t data;
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
ret = _gnutls_x509_der_encode (crt->cert, "", &data, 0);
ret = MHD__gnutls_x509_der_encode (crt->cert, "", &data, 0);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
ret = gnutls_pkcs12_bag_set_data (bag, GNUTLS_BAG_CERTIFICATE, &data);
ret = MHD_gnutlsMHD_pkcs12_bag_set_data (bag, GNUTLS_BAG_CERTIFICATE, &data);
_gnutls_free_datum (&data);
MHD__gnutls_free_datum (&data);
return ret;
}
/**
* gnutls_pkcs12_bag_set_crl - This function inserts the CRL into the bag
* MHD_gnutlsMHD_pkcs12_bag_set_crl - This function inserts the CRL into the bag
* @bag: The bag
* @crl: the CRL to be copied.
*
* This function will insert the given CRL into the
* bag. This is just a wrapper over gnutls_pkcs12_bag_set_data().
* bag. This is just a wrapper over MHD_gnutlsMHD_pkcs12_bag_set_data().
*
* Returns the index of the added bag on success, or a negative
* value on failure.
*
**/
int
gnutls_pkcs12_bag_set_crl (gnutls_pkcs12_bag_t bag, gnutls_x509_crl_t crl)
MHD_gnutlsMHD_pkcs12_bag_set_crl (MHD_gnutlsMHD_pkcs12_bag_t bag, MHD_gnutls_x509_crl_t crl)
{
int ret;
gnutls_datum_t data;
MHD_gnutls_datum_t data;
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
ret = _gnutls_x509_der_encode (crl->crl, "", &data, 0);
ret = MHD__gnutls_x509_der_encode (crl->crl, "", &data, 0);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
ret = gnutls_pkcs12_bag_set_data (bag, GNUTLS_BAG_CRL, &data);
ret = MHD_gnutlsMHD_pkcs12_bag_set_data (bag, GNUTLS_BAG_CRL, &data);
_gnutls_free_datum (&data);
MHD__gnutls_free_datum (&data);
return ret;
}
/**
* gnutls_pkcs12_bag_set_key_id - This function sets a key ID into the bag element
* MHD_gnutlsMHD_pkcs12_bag_set_key_id - This function sets a key ID into the bag element
* @bag: The bag
* @indx: The bag's element to add the id
* @id: the ID
@@ -480,30 +480,30 @@ gnutls_pkcs12_bag_set_crl (gnutls_pkcs12_bag_t bag, gnutls_x509_crl_t crl)
*
**/
int
gnutls_pkcs12_bag_set_key_id (gnutls_pkcs12_bag_t bag, int indx,
const gnutls_datum_t * id)
MHD_gnutlsMHD_pkcs12_bag_set_key_id (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx,
const MHD_gnutls_datum_t * id)
{
int ret;
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (indx > bag->bag_elements - 1)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
ret = _gnutls_set_datum (&bag->element[indx].local_key_id,
ret = MHD__gnutls_set_datum (&bag->element[indx].local_key_id,
id->data, id->size);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -511,7 +511,7 @@ gnutls_pkcs12_bag_set_key_id (gnutls_pkcs12_bag_t bag, int indx,
}
/**
* gnutls_pkcs12_bag_get_key_id - This function gets the key ID from the bag element
* MHD_gnutlsMHD_pkcs12_bag_get_key_id - This function gets the key ID from the bag element
* @bag: The bag
* @indx: The bag's element to add the id
* @id: where the ID will be copied (to be treated as const)
@@ -523,18 +523,18 @@ gnutls_pkcs12_bag_set_key_id (gnutls_pkcs12_bag_t bag, int indx,
*
**/
int
gnutls_pkcs12_bag_get_key_id (gnutls_pkcs12_bag_t bag, int indx,
gnutls_datum_t * id)
MHD_gnutlsMHD_pkcs12_bag_get_key_id (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx,
MHD_gnutls_datum_t * id)
{
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (indx > bag->bag_elements - 1)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -545,7 +545,7 @@ gnutls_pkcs12_bag_get_key_id (gnutls_pkcs12_bag_t bag, int indx,
}
/**
* gnutls_pkcs12_bag_get_friendly_name - This function returns the friendly name of the bag element
* MHD_gnutlsMHD_pkcs12_bag_get_friendly_name - This function returns the friendly name of the bag element
* @bag: The bag
* @indx: The bag's element to add the id
* @name: will hold a pointer to the name (to be treated as const)
@@ -557,18 +557,18 @@ gnutls_pkcs12_bag_get_key_id (gnutls_pkcs12_bag_t bag, int indx,
*
**/
int
gnutls_pkcs12_bag_get_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
MHD_gnutlsMHD_pkcs12_bag_get_friendly_name (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx,
char **name)
{
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (indx > bag->bag_elements - 1)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -579,7 +579,7 @@ gnutls_pkcs12_bag_get_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
/**
* gnutls_pkcs12_bag_set_friendly_name - This function sets a friendly name into the bag element
* MHD_gnutlsMHD_pkcs12_bag_set_friendly_name - This function sets a friendly name into the bag element
* @bag: The bag
* @indx: The bag's element to add the id
* @name: the name
@@ -592,26 +592,26 @@ gnutls_pkcs12_bag_get_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
*
**/
int
gnutls_pkcs12_bag_set_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
MHD_gnutlsMHD_pkcs12_bag_set_friendly_name (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx,
const char *name)
{
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (indx > bag->bag_elements - 1)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
bag->element[indx].friendly_name = gnutls_strdup (name);
bag->element[indx].friendly_name = MHD_gnutls_strdup (name);
if (name == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
@@ -620,7 +620,7 @@ gnutls_pkcs12_bag_set_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
/**
* gnutls_pkcs12_bag_decrypt - This function will decrypt an encrypted bag
* MHD_gnutlsMHD_pkcs12_bag_decrypt - This function will decrypt an encrypted bag
* @bag: The bag
* @pass: The password used for encryption. This can only be ASCII.
*
@@ -628,28 +628,28 @@ gnutls_pkcs12_bag_set_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
*
**/
int
gnutls_pkcs12_bag_decrypt (gnutls_pkcs12_bag_t bag, const char *pass)
MHD_gnutlsMHD_pkcs12_bag_decrypt (MHD_gnutlsMHD_pkcs12_bag_t bag, const char *pass)
{
int ret;
gnutls_datum_t dec;
MHD_gnutls_datum_t dec;
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (bag->element[0].type != GNUTLS_BAG_ENCRYPTED)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
ret = _gnutls_pkcs7_decrypt_data (&bag->element[0].data, pass, &dec);
ret = MHD__gnutls_pkcs7_decrypt_data (&bag->element[0].data, pass, &dec);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -657,15 +657,15 @@ gnutls_pkcs12_bag_decrypt (gnutls_pkcs12_bag_t bag, const char *pass)
* stuff, and parse it.
*/
_gnutls_free_datum (&bag->element[0].data);
MHD__gnutls_free_datum (&bag->element[0].data);
ret = _pkcs12_decode_safe_contents (&dec, bag);
ret = MHD_pkcs12_decode_safe_contents (&dec, bag);
_gnutls_free_datum (&dec);
MHD__gnutls_free_datum (&dec);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -673,61 +673,61 @@ gnutls_pkcs12_bag_decrypt (gnutls_pkcs12_bag_t bag, const char *pass)
}
/**
* gnutls_pkcs12_bag_encrypt - This function will encrypt a bag
* MHD_gnutlsMHD_pkcs12_bag_encrypt - This function will encrypt a bag
* @bag: The bag
* @pass: The password used for encryption. This can only be ASCII.
* @flags: should be one of gnutls_pkcs_encrypt_flags_t elements bitwise or'd
* @flags: should be one of MHD_gnutls_pkcs_encrypt_flags_t elements bitwise or'd
*
* This function will encrypt the given bag and return 0 on success.
*
**/
int
gnutls_pkcs12_bag_encrypt (gnutls_pkcs12_bag_t bag, const char *pass,
MHD_gnutlsMHD_pkcs12_bag_encrypt (MHD_gnutlsMHD_pkcs12_bag_t bag, const char *pass,
unsigned int flags)
{
int ret;
ASN1_TYPE safe_cont = ASN1_TYPE_EMPTY;
gnutls_datum_t der = { NULL, 0 };
gnutls_datum_t enc = { NULL, 0 };
MHD_gnutls_datum_t der = { NULL, 0 };
MHD_gnutls_datum_t enc = { NULL, 0 };
schema_id id;
if (bag == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (bag->element[0].type == GNUTLS_BAG_ENCRYPTED)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
/* Encode the whole bag to a safe contents
* structure.
*/
ret = _pkcs12_encode_safe_contents (bag, &safe_cont, NULL);
ret = MHD_pkcs12_encode_safe_contents (bag, &safe_cont, NULL);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
/* DER encode the SafeContents.
*/
ret = _gnutls_x509_der_encode (safe_cont, "", &der, 0);
ret = MHD__gnutls_x509_der_encode (safe_cont, "", &der, 0);
asn1_delete_structure (&safe_cont);
MHD__asn1_delete_structure (&safe_cont);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
if (flags & GNUTLS_PKCS_PLAIN)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -742,20 +742,20 @@ gnutls_pkcs12_bag_encrypt (gnutls_pkcs12_bag_t bag, const char *pass,
/* Now encrypt them.
*/
ret = _gnutls_pkcs7_encrypt_data (id, &der, pass, &enc);
ret = MHD__gnutls_pkcs7_encrypt_data (id, &der, pass, &enc);
_gnutls_free_datum (&der);
MHD__gnutls_free_datum (&der);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
/* encryption succeeded.
*/
_pkcs12_bag_free_data (bag);
MHD_pkcs12_bag_free_data (bag);
bag->element[0].type = GNUTLS_BAG_ENCRYPTED;
bag->element[0].data = enc;
+19 -19
View File
@@ -33,7 +33,7 @@
* code instead.
*/
static int
_pkcs12_check_pass (const char *pass, size_t plen)
MHD_pkcs12_check_pass (const char *pass, size_t plen)
{
const unsigned char *p = pass;
unsigned int i;
@@ -54,14 +54,14 @@ _pkcs12_check_pass (const char *pass, size_t plen)
* 1 for encryption key
*/
int
_pkcs12_string_to_key (unsigned int id, const opaque * salt,
MHD_pkcs12_string_to_key (unsigned int id, const opaque * salt,
unsigned int salt_size, unsigned int iter,
const char *pw, unsigned int req_keylen,
opaque * keybuf)
{
int rc;
unsigned int i, j;
gc_hash_handle md;
MHD_gc_hash_handle md;
mpi_t num_b1 = NULL;
unsigned int pwlen;
opaque hash[20], buf_b[64], buf_i[128], *p;
@@ -77,13 +77,13 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
if (pwlen > 63 / 2)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if ((rc = _pkcs12_check_pass (pw, pwlen)) < 0)
if ((rc = MHD_pkcs12_check_pass (pw, pwlen)) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return rc;
}
@@ -106,22 +106,22 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
for (;;)
{
rc = gc_hash_open (GC_SHA1, 0, &md);
rc = MHD_gc_hash_open (GC_SHA1, 0, &md);
if (rc)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_DECRYPTION_FAILED;
}
for (i = 0; i < 64; i++)
{
unsigned char lid = id & 0xFF;
gc_hash_write (md, 1, &lid);
MHD_gc_hash_write (md, 1, &lid);
}
gc_hash_write (md, pw ? 128 : 64, buf_i);
memcpy (hash, gc_hash_read (md), 20);
gc_hash_close (md);
MHD_gc_hash_write (md, pw ? 128 : 64, buf_i);
memcpy (hash, MHD_gc_hash_read (md), 20);
MHD_gc_hash_close (md);
for (i = 1; i < iter; i++)
gc_hash_buffer (GC_SHA1, hash, 20, hash);
MHD_gc_hash_buffer (GC_SHA1, hash, 20, hash);
for (i = 0; i < 20 && cur_keylen < req_keylen; i++)
keybuf[cur_keylen++] = hash[i];
if (cur_keylen == req_keylen)
@@ -134,10 +134,10 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
for (i = 0; i < 64; i++)
buf_b[i] = hash[i % 20];
n = 64;
rc = mhd_gtls_mpi_scan (&num_b1, buf_b, &n);
rc = MHD_gtls_mpi_scan (&num_b1, buf_b, &n);
if (rc < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return rc;
}
gcry_mpi_add_ui (num_b1, num_b1, 1);
@@ -146,19 +146,19 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
mpi_t num_ij;
n = 64;
rc = mhd_gtls_mpi_scan (&num_ij, buf_i + i, &n);
rc = MHD_gtls_mpi_scan (&num_ij, buf_i + i, &n);
if (rc < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return rc;
}
gcry_mpi_add (num_ij, num_ij, num_b1);
gcry_mpi_clear_highbit (num_ij, 64 * 8);
n = 64;
rc = mhd_gtls_mpi_print (buf_i + i, &n, num_ij);
rc = MHD_gtls_mpi_print (buf_i + i, &n, num_ij);
if (rc < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return rc;
}
gcry_mpi_release (num_ij);
+179 -179
View File
@@ -46,7 +46,7 @@
*/
static int
_decode_pkcs7_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata,
gnutls_datum_t * raw)
MHD_gnutls_datum_t * raw)
{
char oid[128];
ASN1_TYPE c2;
@@ -54,52 +54,52 @@ _decode_pkcs7_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata,
int tmp_size, len, result;
len = sizeof (oid) - 1;
result = asn1_read_value (pkcs7, "contentType", oid, &len);
result = MHD__asn1_read_value (pkcs7, "contentType", oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (strcmp (oid, SIGNED_DATA_OID) != 0)
{
gnutls_assert ();
_gnutls_x509_log ("Unknown PKCS7 Content OID '%s'\n", oid);
MHD_gnutls_assert ();
MHD__gnutls_x509_log ("Unknown PKCS7 Content OID '%s'\n", oid);
return GNUTLS_E_UNKNOWN_PKCS_CONTENT_TYPE;
}
if ((result = asn1_create_element
(_gnutls_get_pkix (), "PKIX1.pkcs-7-SignedData", &c2)) != ASN1_SUCCESS)
if ((result = MHD__asn1_create_element
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-SignedData", &c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* the Signed-data has been created, so
* decode them.
*/
tmp_size = 0;
result = asn1_read_value (pkcs7, "content", NULL, &tmp_size);
result = MHD__asn1_read_value (pkcs7, "content", NULL, &tmp_size);
if (result != ASN1_MEM_ERROR)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
tmp = gnutls_malloc (tmp_size);
tmp = MHD_gnutls_malloc (tmp_size);
if (tmp == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
result = asn1_read_value (pkcs7, "content", tmp, &tmp_size);
result = MHD__asn1_read_value (pkcs7, "content", tmp, &tmp_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -110,17 +110,17 @@ _decode_pkcs7_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata,
/* Step 1. In case of a signed structure extract certificate set.
*/
result = asn1_der_decoding (&c2, tmp, tmp_size, NULL);
result = MHD__asn1_der_decoding (&c2, tmp, tmp_size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if (raw == NULL)
{
gnutls_free (tmp);
MHD_gnutls_free (tmp);
}
else
{
@@ -134,13 +134,13 @@ _decode_pkcs7_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata,
cleanup:
if (c2)
asn1_delete_structure (&c2);
gnutls_free (tmp);
MHD__asn1_delete_structure (&c2);
MHD_gnutls_free (tmp);
return result;
}
/**
* gnutls_pkcs7_init - This function initializes a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_init - This function initializes a MHD_gnutls_pkcs7_t structure
* @pkcs7: The structure to be initialized
*
* This function will initialize a PKCS7 structure. PKCS7 structures
@@ -151,20 +151,20 @@ cleanup:
*
**/
int
gnutls_pkcs7_init (gnutls_pkcs7_t * pkcs7)
MHD_gnutls_pkcs7_init (MHD_gnutls_pkcs7_t * pkcs7)
{
*pkcs7 = gnutls_calloc (1, sizeof (gnutls_pkcs7_int));
*pkcs7 = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_pkcs7_int));
if (*pkcs7)
{
int result = asn1_create_element (_gnutls_get_pkix (),
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-7-ContentInfo",
&(*pkcs7)->pkcs7);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
gnutls_free (*pkcs7);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD_gnutls_free (*pkcs7);
return MHD_gtls_asn2err (result);
}
return 0; /* success */
}
@@ -172,32 +172,32 @@ gnutls_pkcs7_init (gnutls_pkcs7_t * pkcs7)
}
/**
* gnutls_pkcs7_deinit - This function deinitializes memory used by a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_deinit - This function deinitializes memory used by a MHD_gnutls_pkcs7_t structure
* @pkcs7: The structure to be initialized
*
* This function will deinitialize a PKCS7 structure.
*
**/
void
gnutls_pkcs7_deinit (gnutls_pkcs7_t pkcs7)
MHD_gnutls_pkcs7_deinit (MHD_gnutls_pkcs7_t pkcs7)
{
if (!pkcs7)
return;
if (pkcs7->pkcs7)
asn1_delete_structure (&pkcs7->pkcs7);
MHD__asn1_delete_structure (&pkcs7->pkcs7);
gnutls_free (pkcs7);
MHD_gnutls_free (pkcs7);
}
/**
* gnutls_pkcs7_import - This function will import a DER or PEM encoded PKCS7
* MHD_gnutls_pkcs7_import - This function will import a DER or PEM encoded PKCS7
* @pkcs7: The structure to store the parsed PKCS7.
* @data: The DER or PEM encoded PKCS7.
* @format: One of DER or PEM
*
* This function will convert the given DER or PEM encoded PKCS7
* to the native gnutls_pkcs7_t format. The output will be stored in 'pkcs7'.
* to the native MHD_gnutls_pkcs7_t format. The output will be stored in 'pkcs7'.
*
* If the PKCS7 is PEM encoded it should have a header of "PKCS7".
*
@@ -205,11 +205,11 @@ gnutls_pkcs7_deinit (gnutls_pkcs7_t pkcs7)
*
**/
int
gnutls_pkcs7_import (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format)
MHD_gnutls_pkcs7_import (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format)
{
int result = 0, need_free = 0;
gnutls_datum_t _data;
MHD_gnutls_datum_t _data;
if (pkcs7 == NULL)
return GNUTLS_E_INVALID_REQUEST;
@@ -223,14 +223,14 @@ gnutls_pkcs7_import (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * data,
{
opaque *out;
result = _gnutls_fbase64_decode (PEM_PKCS7, data->data, data->size,
result = MHD__gnutls_fbase64_decode (PEM_PKCS7, data->data, data->size,
&out);
if (result <= 0)
{
if (result == 0)
result = GNUTLS_E_INTERNAL_ERROR;
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -241,28 +241,28 @@ gnutls_pkcs7_import (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * data,
}
result = asn1_der_decoding (&pkcs7->pkcs7, _data.data, _data.size, NULL);
result = MHD__asn1_der_decoding (&pkcs7->pkcs7, _data.data, _data.size, NULL);
if (result != ASN1_SUCCESS)
{
result = mhd_gtls_asn2err (result);
gnutls_assert ();
result = MHD_gtls_asn2err (result);
MHD_gnutls_assert ();
goto cleanup;
}
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
return 0;
cleanup:
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
return result;
}
/**
* gnutls_pkcs7_get_crt_raw - This function returns a certificate in a PKCS7 certificate set
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_get_crt_raw - This function returns a certificate in a PKCS7 certificate set
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
* @indx: contains the index of the certificate to extract
* @certificate: the contents of the certificate will be copied there (may be null)
* @certificate_size: should hold the size of the certificate
@@ -276,7 +276,7 @@ cleanup:
*
**/
int
gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
MHD_gnutls_pkcs7_get_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
int indx, void *certificate,
size_t * certificate_size)
{
@@ -284,7 +284,7 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
int result, len;
char root2[MAX_NAME_SIZE];
char oid[128];
gnutls_datum_t tmp = { NULL, 0 };
MHD_gnutls_datum_t tmp = { NULL, 0 };
if (certificate_size == NULL || pkcs7 == NULL)
return GNUTLS_E_INVALID_REQUEST;
@@ -294,7 +294,7 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, &tmp);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -305,7 +305,7 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
len = sizeof (oid) - 1;
result = asn1_read_value (c2, root2, oid, &len);
result = MHD__asn1_read_value (c2, root2, oid, &len);
if (result == ASN1_VALUE_NOT_FOUND)
{
@@ -315,8 +315,8 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -326,13 +326,13 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
{
int start, end;
result = asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
result = MHD__asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
root2, &start, &end);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -359,15 +359,15 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
}
cleanup:
_gnutls_free_datum (&tmp);
MHD__gnutls_free_datum (&tmp);
if (c2)
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
/**
* gnutls_pkcs7_get_crt_count - This function returns the number of certificates in a PKCS7 certificate set
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_get_crt_count - This function returns the number of certificates in a PKCS7 certificate set
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
*
* This function will return the number of certifcates in the PKCS7 or
* RFC2630 certificate set.
@@ -376,7 +376,7 @@ cleanup:
*
**/
int
gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7)
MHD_gnutls_pkcs7_get_crt_count (MHD_gnutls_pkcs7_t pkcs7)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int result, count;
@@ -389,19 +389,19 @@ gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7)
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* Step 2. Count the CertificateSet */
result = asn1_number_of_elements (c2, "certificates", &count);
result = MHD__asn1_number_of_elements (c2, "certificates", &count);
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
return 0; /* no certificates */
}
@@ -410,7 +410,7 @@ gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7)
}
/**
* gnutls_pkcs7_export - This function will export the pkcs7 structure
* MHD_gnutls_pkcs7_export - This function will export the pkcs7 structure
* @pkcs7: Holds the pkcs7 structure
* @format: the format of output params. One of PEM or DER.
* @output_data: will contain a structure PEM or DER encoded
@@ -431,14 +431,14 @@ gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7)
*
**/
int
gnutls_pkcs7_export (gnutls_pkcs7_t pkcs7,
gnutls_x509_crt_fmt_t format, void *output_data,
MHD_gnutls_pkcs7_export (MHD_gnutls_pkcs7_t pkcs7,
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
size_t * output_data_size)
{
if (pkcs7 == NULL)
return GNUTLS_E_INVALID_REQUEST;
return _gnutls_x509_export_int (pkcs7->pkcs7, format, PEM_PKCS7,
return MHD__gnutls_x509_export_int (pkcs7->pkcs7, format, PEM_PKCS7,
output_data, output_data_size);
}
@@ -453,22 +453,22 @@ create_empty_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata)
*sdata = ASN1_TYPE_EMPTY;
if ((result = asn1_create_element
(_gnutls_get_pkix (), "PKIX1.pkcs-7-SignedData",
if ((result = MHD__asn1_create_element
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-SignedData",
sdata)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Use version 1
*/
result = asn1_write_value (*sdata, "version", &one, 1);
result = MHD__asn1_write_value (*sdata, "version", &one, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -477,20 +477,20 @@ create_empty_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata)
/* id-data */
result =
asn1_write_value (*sdata, "encapContentInfo.eContentType",
MHD__asn1_write_value (*sdata, "encapContentInfo.eContentType",
"1.2.840.113549.1.7.5", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_write_value (*sdata, "encapContentInfo.eContent", NULL, 0);
result = MHD__asn1_write_value (*sdata, "encapContentInfo.eContent", NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -505,25 +505,25 @@ create_empty_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata)
/* Write the content type of the signed data
*/
result = asn1_write_value (pkcs7, "contentType", SIGNED_DATA_OID, 1);
result = MHD__asn1_write_value (pkcs7, "contentType", SIGNED_DATA_OID, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
return 0;
cleanup:
asn1_delete_structure (sdata);
MHD__asn1_delete_structure (sdata);
return result;
}
/**
* gnutls_pkcs7_set_crt_raw - This function adds a certificate in a PKCS7 certificate set
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_set_crt_raw - This function adds a certificate in a PKCS7 certificate set
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
* @crt: the DER encoded certificate to be added
*
* This function will add a certificate to the PKCS7 or RFC2630 certificate set.
@@ -531,7 +531,7 @@ cleanup:
*
**/
int
gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crt)
MHD_gnutls_pkcs7_set_crt_raw (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * crt)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int result;
@@ -544,7 +544,7 @@ gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crt)
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
if (result < 0 && result != GNUTLS_E_ASN1_VALUE_NOT_FOUND)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -559,7 +559,7 @@ gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crt)
result = create_empty_signed_data (pkcs7->pkcs7, &c2);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
}
@@ -567,86 +567,86 @@ gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crt)
/* Step 2. Append the new certificate.
*/
result = asn1_write_value (c2, "certificates", "NEW", 1);
result = MHD__asn1_write_value (c2, "certificates", "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_write_value (c2, "certificates.?LAST", "certificate", 1);
result = MHD__asn1_write_value (c2, "certificates.?LAST", "certificate", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result =
asn1_write_value (c2, "certificates.?LAST.certificate", crt->data,
MHD__asn1_write_value (c2, "certificates.?LAST.certificate", crt->data,
crt->size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Step 3. Replace the old content with the new
*/
result =
_gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return 0;
cleanup:
if (c2)
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
/**
* gnutls_pkcs7_set_crt - This function adds a parsed certificate in a PKCS7 certificate set
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_set_crt - This function adds a parsed certificate in a PKCS7 certificate set
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
* @crt: the certificate to be copied.
*
* This function will add a parsed certificate to the PKCS7 or RFC2630 certificate set.
* This is a wrapper function over gnutls_pkcs7_set_crt_raw() .
* This is a wrapper function over MHD_gnutls_pkcs7_set_crt_raw() .
*
* Returns 0 on success.
*
**/
int
gnutls_pkcs7_set_crt (gnutls_pkcs7_t pkcs7, gnutls_x509_crt_t crt)
MHD_gnutls_pkcs7_set_crt (MHD_gnutls_pkcs7_t pkcs7, MHD_gnutls_x509_crt_t crt)
{
int ret;
gnutls_datum_t data;
MHD_gnutls_datum_t data;
if (pkcs7 == NULL)
return GNUTLS_E_INVALID_REQUEST;
ret = _gnutls_x509_der_encode (crt->cert, "", &data, 0);
ret = MHD__gnutls_x509_der_encode (crt->cert, "", &data, 0);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
ret = gnutls_pkcs7_set_crt_raw (pkcs7, &data);
ret = MHD_gnutls_pkcs7_set_crt_raw (pkcs7, &data);
_gnutls_free_datum (&data);
MHD__gnutls_free_datum (&data);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -655,8 +655,8 @@ gnutls_pkcs7_set_crt (gnutls_pkcs7_t pkcs7, gnutls_x509_crt_t crt)
/**
* gnutls_pkcs7_delete_crt - This function deletes a certificate from a PKCS7 certificate set
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_delete_crt - This function deletes a certificate from a PKCS7 certificate set
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
* @indx: the index of the certificate to delete
*
* This function will delete a certificate from a PKCS7 or RFC2630 certificate set.
@@ -664,7 +664,7 @@ gnutls_pkcs7_set_crt (gnutls_pkcs7_t pkcs7, gnutls_x509_crt_t crt)
*
**/
int
gnutls_pkcs7_delete_crt (gnutls_pkcs7_t pkcs7, int indx)
MHD_gnutls_pkcs7_delete_crt (MHD_gnutls_pkcs7_t pkcs7, int indx)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int result;
@@ -678,7 +678,7 @@ gnutls_pkcs7_delete_crt (gnutls_pkcs7_t pkcs7, int indx)
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -687,31 +687,31 @@ gnutls_pkcs7_delete_crt (gnutls_pkcs7_t pkcs7, int indx)
snprintf (root2, sizeof (root2), "certificates.?%u", indx + 1);
result = asn1_write_value (c2, root2, NULL, 0);
result = MHD__asn1_write_value (c2, root2, NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Step 3. Replace the old content with the new
*/
result =
_gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return 0;
cleanup:
if (c2)
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
@@ -719,8 +719,8 @@ cleanup:
*/
/**
* gnutls_pkcs7_get_crl_raw - This function returns a crl in a PKCS7 crl set
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_get_crl_raw - This function returns a crl in a PKCS7 crl set
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
* @indx: contains the index of the crl to extract
* @crl: the contents of the crl will be copied there (may be null)
* @crl_size: should hold the size of the crl
@@ -734,13 +734,13 @@ cleanup:
*
**/
int
gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
MHD_gnutls_pkcs7_get_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
int indx, void *crl, size_t * crl_size)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int result;
char root2[MAX_NAME_SIZE];
gnutls_datum_t tmp = { NULL, 0 };
MHD_gnutls_datum_t tmp = { NULL, 0 };
int start, end;
if (pkcs7 == NULL || crl_size == NULL)
@@ -751,7 +751,7 @@ gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, &tmp);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -762,13 +762,13 @@ gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
/* Get the raw CRL
*/
result = asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
result = MHD__asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
root2, &start, &end);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
@@ -789,15 +789,15 @@ gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
result = 0;
cleanup:
_gnutls_free_datum (&tmp);
MHD__gnutls_free_datum (&tmp);
if (c2)
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
/**
* gnutls_pkcs7_get_crl_count - This function returns the number of crls in a PKCS7 crl set
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_get_crl_count - This function returns the number of crls in a PKCS7 crl set
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
*
* This function will return the number of certifcates in the PKCS7 or
* RFC2630 crl set.
@@ -806,7 +806,7 @@ cleanup:
*
**/
int
gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7)
MHD_gnutls_pkcs7_get_crl_count (MHD_gnutls_pkcs7_t pkcs7)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int result, count;
@@ -819,19 +819,19 @@ gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7)
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* Step 2. Count the CertificateSet */
result = asn1_number_of_elements (c2, "crls", &count);
result = MHD__asn1_number_of_elements (c2, "crls", &count);
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
return 0; /* no crls */
}
@@ -840,8 +840,8 @@ gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7)
}
/**
* gnutls_pkcs7_set_crl_raw - This function adds a crl in a PKCS7 crl set
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_set_crl_raw - This function adds a crl in a PKCS7 crl set
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
* @crl: the DER encoded crl to be added
*
* This function will add a crl to the PKCS7 or RFC2630 crl set.
@@ -849,7 +849,7 @@ gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7)
*
**/
int
gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crl)
MHD_gnutls_pkcs7_set_crl_raw (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * crl)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int result;
@@ -862,7 +862,7 @@ gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crl)
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
if (result < 0 && result != GNUTLS_E_ASN1_VALUE_NOT_FOUND)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -877,7 +877,7 @@ gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crl)
result = create_empty_signed_data (pkcs7->pkcs7, &c2);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
}
@@ -885,45 +885,45 @@ gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crl)
/* Step 2. Append the new crl.
*/
result = asn1_write_value (c2, "crls", "NEW", 1);
result = MHD__asn1_write_value (c2, "crls", "NEW", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_write_value (c2, "crls.?LAST", crl->data, crl->size);
result = MHD__asn1_write_value (c2, "crls.?LAST", crl->data, crl->size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Step 3. Replace the old content with the new
*/
result =
_gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return 0;
cleanup:
if (c2)
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
/**
* gnutls_pkcs7_set_crl - This function adds a parsed crl in a PKCS7 crl set
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_set_crl - This function adds a parsed crl in a PKCS7 crl set
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
* @crl: the DER encoded crl to be added
*
* This function will add a parsed crl to the PKCS7 or RFC2630 crl set.
@@ -931,28 +931,28 @@ cleanup:
*
**/
int
gnutls_pkcs7_set_crl (gnutls_pkcs7_t pkcs7, gnutls_x509_crl_t crl)
MHD_gnutls_pkcs7_set_crl (MHD_gnutls_pkcs7_t pkcs7, MHD_gnutls_x509_crl_t crl)
{
int ret;
gnutls_datum_t data;
MHD_gnutls_datum_t data;
if (pkcs7 == NULL)
return GNUTLS_E_INVALID_REQUEST;
ret = _gnutls_x509_der_encode (crl->crl, "", &data, 0);
ret = MHD__gnutls_x509_der_encode (crl->crl, "", &data, 0);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
ret = gnutls_pkcs7_set_crl_raw (pkcs7, &data);
ret = MHD_gnutls_pkcs7_set_crl_raw (pkcs7, &data);
_gnutls_free_datum (&data);
MHD__gnutls_free_datum (&data);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -960,8 +960,8 @@ gnutls_pkcs7_set_crl (gnutls_pkcs7_t pkcs7, gnutls_x509_crl_t crl)
}
/**
* gnutls_pkcs7_delete_crl - This function deletes a crl from a PKCS7 crl set
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
* MHD_gnutls_pkcs7_delete_crl - This function deletes a crl from a PKCS7 crl set
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
* @indx: the index of the crl to delete
*
* This function will delete a crl from a PKCS7 or RFC2630 crl set.
@@ -969,7 +969,7 @@ gnutls_pkcs7_set_crl (gnutls_pkcs7_t pkcs7, gnutls_x509_crl_t crl)
*
**/
int
gnutls_pkcs7_delete_crl (gnutls_pkcs7_t pkcs7, int indx)
MHD_gnutls_pkcs7_delete_crl (MHD_gnutls_pkcs7_t pkcs7, int indx)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int result;
@@ -983,7 +983,7 @@ gnutls_pkcs7_delete_crl (gnutls_pkcs7_t pkcs7, int indx)
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -992,31 +992,31 @@ gnutls_pkcs7_delete_crl (gnutls_pkcs7_t pkcs7, int indx)
snprintf (root2, sizeof (root2), "crls.?%u", indx + 1);
result = asn1_write_value (c2, root2, NULL, 0);
result = MHD__asn1_write_value (c2, root2, NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Step 3. Replace the old content with the new
*/
result =
_gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return 0;
cleanup:
if (c2)
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
+2 -2
View File
@@ -24,7 +24,7 @@
#include "x509.h"
typedef struct gnutls_pkcs7_int
typedef struct MHD_gnutls_pkcs7_int
{
ASN1_TYPE pkcs7;
} gnutls_pkcs7_int;
} MHD_gnutls_pkcs7_int;
+3 -3
View File
@@ -24,8 +24,8 @@
#include "x509.h"
ASN1_TYPE _gnutls_privkey_decode_pkcs1_rsa_key (const gnutls_datum_t *
ASN1_TYPE MHD__gnutls_privkey_decode_pkcs1_rsa_key (const MHD_gnutls_datum_t *
raw_key,
gnutls_x509_privkey_t pkey);
MHD_gnutls_x509_privkey_t pkey);
int _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
int MHD__gnutlsMHD__asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
+346 -346
View File
@@ -71,31 +71,31 @@ struct pbe_enc_params
static int generate_key (schema_id schema, const char *password,
struct pbkdf2_params *kdf_params,
struct pbe_enc_params *enc_params,
gnutls_datum_t * key);
MHD_gnutls_datum_t * key);
static int read_pbkdf2_params (ASN1_TYPE pbes2_asn,
const gnutls_datum_t * der,
const MHD_gnutls_datum_t * der,
struct pbkdf2_params *params);
static int read_pbe_enc_params (ASN1_TYPE pbes2_asn,
const gnutls_datum_t * der,
const MHD_gnutls_datum_t * der,
struct pbe_enc_params *params);
static int decrypt_data (schema_id, ASN1_TYPE pkcs8_asn, const char *root,
const char *password,
const struct pbkdf2_params *kdf_params,
const struct pbe_enc_params *enc_params,
gnutls_datum_t * decrypted_data);
static int decode_private_key_info (const gnutls_datum_t * der,
gnutls_x509_privkey_t pkey);
MHD_gnutls_datum_t * decrypted_data);
static int decode_private_key_info (const MHD_gnutls_datum_t * der,
MHD_gnutls_x509_privkey_t pkey);
static int write_schema_params (schema_id schema, ASN1_TYPE pkcs8_asn,
const char *where,
const struct pbkdf2_params *kdf_params,
const struct pbe_enc_params *enc_params);
static int encrypt_data (const gnutls_datum_t * plain,
static int encrypt_data (const MHD_gnutls_datum_t * plain,
const struct pbe_enc_params *enc_params,
gnutls_datum_t * key, gnutls_datum_t * encrypted);
MHD_gnutls_datum_t * key, MHD_gnutls_datum_t * encrypted);
static int read_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
static int readMHD_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
struct pbkdf2_params *params);
static int write_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
static int writeMHD_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
const struct pbkdf2_params *params);
#define PEM_PKCS8 "ENCRYPTED PRIVATE KEY"
@@ -120,7 +120,7 @@ check_schema (const char *oid)
if (strcmp (oid, PKCS12_PBE_RC2_40_SHA1_OID) == 0)
return PKCS12_RC2_40_SHA1;
_gnutls_x509_log ("PKCS encryption schema OID '%s' is unsupported.\n", oid);
MHD__gnutls_x509_log ("PKCS encryption schema OID '%s' is unsupported.\n", oid);
return GNUTLS_E_UNKNOWN_CIPHER_TYPE;
}
@@ -136,7 +136,7 @@ read_pkcs_schema_params (schema_id schema, const char *password,
{
ASN1_TYPE pbes2_asn = ASN1_TYPE_EMPTY;
int result;
gnutls_datum_t tmp;
MHD_gnutls_datum_t tmp;
switch (schema)
{
@@ -147,22 +147,22 @@ read_pkcs_schema_params (schema_id schema, const char *password,
* functions.
*/
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-5-PBES2-params",
&pbes2_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
/* Decode the parameters.
*/
result = asn1_der_decoding (&pbes2_asn, data, data_size, NULL);
result = MHD__asn1_der_decoding (&pbes2_asn, data, data_size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
@@ -172,20 +172,20 @@ read_pkcs_schema_params (schema_id schema, const char *password,
result = read_pbkdf2_params (pbes2_asn, &tmp, kdf_params);
if (result < 0)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
result = read_pbe_enc_params (pbes2_asn, &tmp, enc_params);
if (result < 0)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
asn1_delete_structure (&pbes2_asn);
MHD__asn1_delete_structure (&pbes2_asn);
return 0;
break;
@@ -210,48 +210,48 @@ read_pkcs_schema_params (schema_id schema, const char *password,
}
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-12-PbeParams",
&pbes2_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
/* Decode the parameters.
*/
result = asn1_der_decoding (&pbes2_asn, data, data_size, NULL);
result = MHD__asn1_der_decoding (&pbes2_asn, data, data_size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
result = read_pkcs12_kdf_params (pbes2_asn, kdf_params);
result = readMHD_pkcs12_kdf_params (pbes2_asn, kdf_params);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
if (enc_params->iv_size)
{
result =
_pkcs12_string_to_key (2 /*IV*/, kdf_params->salt,
MHD_pkcs12_string_to_key (2 /*IV*/, kdf_params->salt,
kdf_params->salt_size,
kdf_params->iter_count, password,
enc_params->iv_size, enc_params->iv);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
}
asn1_delete_structure (&pbes2_asn);
MHD__asn1_delete_structure (&pbes2_asn);
return 0;
break;
@@ -261,21 +261,21 @@ read_pkcs_schema_params (schema_id schema, const char *password,
return GNUTLS_E_UNKNOWN_CIPHER_TYPE;
error:
asn1_delete_structure (&pbes2_asn);
MHD__asn1_delete_structure (&pbes2_asn);
return result;
}
/* Converts a PKCS #8 key to
* an internal structure (gnutls_private_key)
* an internal structure (MHD_gnutls_private_key)
* (normally a PKCS #1 encoded RSA key)
*/
static int
decode_pkcs8_key (const gnutls_datum_t * raw_key,
const char *password, gnutls_x509_privkey_t pkey)
decode_pkcs8_key (const MHD_gnutls_datum_t * raw_key,
const char *password, MHD_gnutls_x509_privkey_t pkey)
{
int result, len;
char enc_oid[64];
gnutls_datum_t tmp;
MHD_gnutls_datum_t tmp;
ASN1_TYPE pbes2_asn = ASN1_TYPE_EMPTY, pkcs8_asn = ASN1_TYPE_EMPTY;
int params_start, params_end, params_len;
struct pbkdf2_params kdf_params;
@@ -283,20 +283,20 @@ decode_pkcs8_key (const gnutls_datum_t * raw_key,
schema_id schema;
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-8-EncryptedPrivateKeyInfo",
&pkcs8_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
result = asn1_der_decoding (&pkcs8_asn, raw_key->data, raw_key->size, NULL);
result = MHD__asn1_der_decoding (&pkcs8_asn, raw_key->data, raw_key->size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
@@ -304,17 +304,17 @@ decode_pkcs8_key (const gnutls_datum_t * raw_key,
*/
len = sizeof (enc_oid);
result =
asn1_read_value (pkcs8_asn, "encryptionAlgorithm.algorithm",
MHD__asn1_read_value (pkcs8_asn, "encryptionAlgorithm.algorithm",
enc_oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
if ((result = check_schema (enc_oid)) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
@@ -323,14 +323,14 @@ decode_pkcs8_key (const gnutls_datum_t * raw_key,
/* Get the DER encoding of the parameters.
*/
result =
asn1_der_decoding_startEnd (pkcs8_asn, raw_key->data,
MHD__asn1_der_decoding_startEnd (pkcs8_asn, raw_key->data,
raw_key->size,
"encryptionAlgorithm.parameters",
&params_start, &params_end);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
params_len = params_end - params_start + 1;
@@ -348,14 +348,14 @@ decode_pkcs8_key (const gnutls_datum_t * raw_key,
&kdf_params, &enc_params, &tmp);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
asn1_delete_structure (&pkcs8_asn);
MHD__asn1_delete_structure (&pkcs8_asn);
result = decode_private_key_info (&tmp, pkey);
_gnutls_free_datum (&tmp);
MHD__gnutls_free_datum (&tmp);
if (result < 0)
{
@@ -378,106 +378,106 @@ decode_pkcs8_key (const gnutls_datum_t * raw_key,
result = GNUTLS_E_DECRYPTION_FAILED;
}
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
return 0;
error:
asn1_delete_structure (&pbes2_asn);
asn1_delete_structure (&pkcs8_asn);
MHD__asn1_delete_structure (&pbes2_asn);
MHD__asn1_delete_structure (&pkcs8_asn);
return result;
}
/* Decodes an RSA privateKey from a PKCS8 structure.
*/
static int
_decode_pkcs8_rsa_key (ASN1_TYPE pkcs8_asn, gnutls_x509_privkey_t pkey)
_decode_pkcs8_rsa_key (ASN1_TYPE pkcs8_asn, MHD_gnutls_x509_privkey_t pkey)
{
int ret;
gnutls_datum_t tmp;
MHD_gnutls_datum_t tmp;
ret = _gnutls_x509_read_value (pkcs8_asn, "privateKey", &tmp, 0);
ret = MHD__gnutls_x509_read_value (pkcs8_asn, "privateKey", &tmp, 0);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
pkey->key = _gnutls_privkey_decode_pkcs1_rsa_key (&tmp, pkey);
_gnutls_free_datum (&tmp);
pkey->key = MHD__gnutls_privkey_decode_pkcs1_rsa_key (&tmp, pkey);
MHD__gnutls_free_datum (&tmp);
if (pkey->key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
return 0;
error:
gnutls_x509_privkey_deinit (pkey);
MHD_gnutls_x509_privkey_deinit (pkey);
return ret;
}
/* TODO rm if unsed - we will probable support only RSA certificates */
/* Decodes an DSA privateKey and params from a PKCS8 structure.
static int
_decode_pkcs8_dsa_key (ASN1_TYPE pkcs8_asn, gnutls_x509_privkey pkey)
_decode_pkcs8_dsa_key (ASN1_TYPE pkcs8_asn, MHD_gnutls_x509_privkey pkey)
{
int ret;
gnutls_datum tmp;
MHD_gnutls_datum tmp;
ret = _gnutls_x509_read_value (pkcs8_asn, "privateKey", &tmp, 0);
ret = MHD__gnutls_x509_read_value (pkcs8_asn, "privateKey", &tmp, 0);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
ret = _gnutls_x509_read_der_int (tmp.data, tmp.size, &pkey->params[4]);
_gnutls_free_datum (&tmp);
ret = MHD__gnutls_x509_read_der_int (tmp.data, tmp.size, &pkey->params[4]);
MHD__gnutls_free_datum (&tmp);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
ret =
_gnutls_x509_read_value (pkcs8_asn, "privateKeyAlgorithm.parameters",
MHD__gnutls_x509_read_value (pkcs8_asn, "privateKeyAlgorithm.parameters",
&tmp, 0);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
ret = _gnutls_x509_read_dsa_params (tmp.data, tmp.size, pkey->params);
_gnutls_free_datum (&tmp);
ret = MHD__gnutls_x509_read_dsa_params (tmp.data, tmp.size, pkey->params);
MHD__gnutls_free_datum (&tmp);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
the public key can be generated as g^x mod p
pkey->params[3] = _gnutls_mpi_alloc_like (pkey->params[0]);
pkey->params[3] = MHD__gnutls_mpi_alloc_like (pkey->params[0]);
if (pkey->params[3] == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
_gnutls_mpi_powm (pkey->params[3], pkey->params[2], pkey->params[4],
MHD__gnutls_mpi_powm (pkey->params[3], pkey->params[2], pkey->params[4],
pkey->params[0]);
if (!pkey->crippled)
{
ret = _gnutls_asn1_encode_dsa (&pkey->key, pkey->params);
ret = MHD__gnutlsMHD__asn1_encode_dsa (&pkey->key, pkey->params);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
}
@@ -487,34 +487,34 @@ _decode_pkcs8_dsa_key (ASN1_TYPE pkcs8_asn, gnutls_x509_privkey pkey)
return 0;
error:
gnutls_x509_privkey_deinit (pkey);
MHD_gnutls_x509_privkey_deinit (pkey);
return ret;
}
*/
static int
decode_private_key_info (const gnutls_datum_t * der,
gnutls_x509_privkey_t pkey)
decode_private_key_info (const MHD_gnutls_datum_t * der,
MHD_gnutls_x509_privkey_t pkey)
{
int result, len;
opaque oid[64];
ASN1_TYPE pkcs8_asn = ASN1_TYPE_EMPTY;
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-8-PrivateKeyInfo",
&pkcs8_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
result = asn1_der_decoding (&pkcs8_asn, der->data, der->size, NULL);
result = MHD__asn1_der_decoding (&pkcs8_asn, der->data, der->size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
@@ -522,11 +522,11 @@ decode_private_key_info (const gnutls_datum_t * der,
*/
len = sizeof (oid);
result =
asn1_read_value (pkcs8_asn, "privateKeyAlgorithm.algorithm", oid, &len);
MHD__asn1_read_value (pkcs8_asn, "privateKeyAlgorithm.algorithm", oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
@@ -536,8 +536,8 @@ decode_private_key_info (const gnutls_datum_t * der,
pkey->pk_algorithm = MHD_GNUTLS_PK_RSA;
else
{
gnutls_assert ();
_gnutls_x509_log
MHD_gnutls_assert ();
MHD__gnutls_x509_log
("PKCS #8 private key OID '%s' is unsupported.\n", oid);
result = GNUTLS_E_UNKNOWN_PK_ALGORITHM;
goto error;
@@ -550,21 +550,21 @@ decode_private_key_info (const gnutls_datum_t * der,
result = _decode_pkcs8_rsa_key (pkcs8_asn, pkey);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
result = 0;
error:
asn1_delete_structure (&pkcs8_asn);
MHD__asn1_delete_structure (&pkcs8_asn);
return result;
}
/**
* gnutls_x509_privkey_import_pkcs8 - This function will import a DER or PEM PKCS8 encoded key
* MHD_gnutls_x509_privkey_import_pkcs8 - This function will import a DER or PEM PKCS8 encoded key
* @key: The structure to store the parsed key
* @data: The DER or PEM encoded key.
* @format: One of DER or PEM
@@ -572,7 +572,7 @@ error:
* @flags: 0 if encrypted or GNUTLS_PKCS_PLAIN if not encrypted.
*
* This function will convert the given DER or PEM encoded PKCS8 2.0 encrypted key
* to the native gnutls_x509_privkey_t format. The output will be stored in @key.
* to the native MHD_gnutls_x509_privkey_t format. The output will be stored in @key.
* Both RSA and DSA keys can be imported, and flags can only be used to indicate
* an unencrypted key.
*
@@ -587,17 +587,17 @@ error:
*
**/
int
gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format,
MHD_gnutls_x509_privkey_import_pkcs8 (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format,
const char *password, unsigned int flags)
{
int result = 0, need_free = 0;
gnutls_datum_t _data;
MHD_gnutls_datum_t _data;
if (key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -615,20 +615,20 @@ gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
/* Try the first header
*/
result =
_gnutls_fbase64_decode (PEM_UNENCRYPTED_PKCS8,
MHD__gnutls_fbase64_decode (PEM_UNENCRYPTED_PKCS8,
data->data, data->size, &out);
if (result < 0)
{ /* Try the encrypted header
*/
result =
_gnutls_fbase64_decode (PEM_PKCS8, data->data, data->size, &out);
MHD__gnutls_fbase64_decode (PEM_PKCS8, data->data, data->size, &out);
if (result <= 0)
{
if (result == 0)
result = GNUTLS_E_INTERNAL_ERROR;
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
}
@@ -652,12 +652,12 @@ gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
/* The key has now been decoded.
*/
@@ -667,7 +667,7 @@ gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
cleanup:
key->pk_algorithm = MHD_GNUTLS_PK_UNKNOWN;
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
return result;
}
@@ -675,7 +675,7 @@ cleanup:
*/
static int
read_pbkdf2_params (ASN1_TYPE pbes2_asn,
const gnutls_datum_t * der, struct pbkdf2_params *params)
const MHD_gnutls_datum_t * der, struct pbkdf2_params *params)
{
int params_start, params_end;
int params_len, len, result;
@@ -688,30 +688,30 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
*/
len = sizeof (oid);
result =
asn1_read_value (pbes2_asn, "keyDerivationFunc.algorithm", oid, &len);
MHD__asn1_read_value (pbes2_asn, "keyDerivationFunc.algorithm", oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
_gnutls_hard_log ("keyDerivationFunc.algorithm: %s\n", oid);
MHD__gnutls_hard_log ("keyDerivationFunc.algorithm: %s\n", oid);
if (strcmp (oid, PBKDF2_OID) != 0)
{
gnutls_assert ();
_gnutls_x509_log
MHD_gnutls_assert ();
MHD__gnutls_x509_log
("PKCS #8 key derivation OID '%s' is unsupported.\n", oid);
return mhd_gtls_asn2err (result);
return MHD_gtls_asn2err (result);
}
result =
asn1_der_decoding_startEnd (pbes2_asn, der->data, der->size,
MHD__asn1_der_decoding_startEnd (pbes2_asn, der->data, der->size,
"keyDerivationFunc.parameters",
&params_start, &params_end);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
params_len = params_end - params_start + 1;
@@ -719,58 +719,58 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
* functions.
*/
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-5-PBKDF2-params",
&pbkdf2_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result =
asn1_der_decoding (&pbkdf2_asn, &der->data[params_start],
MHD__asn1_der_decoding (&pbkdf2_asn, &der->data[params_start],
params_len, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
/* read the salt */
params->salt_size = sizeof (params->salt);
result =
asn1_read_value (pbkdf2_asn, "salt.specified", params->salt,
MHD__asn1_read_value (pbkdf2_asn, "salt.specified", params->salt,
&params->salt_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
_gnutls_hard_log ("salt.specified.size: %d\n", params->salt_size);
MHD__gnutls_hard_log ("salt.specified.size: %d\n", params->salt_size);
/* read the iteration count
*/
result =
_gnutls_x509_read_uint (pbkdf2_asn, "iterationCount",
MHD__gnutls_x509_read_uint (pbkdf2_asn, "iterationCount",
&params->iter_count);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
_gnutls_hard_log ("iterationCount: %d\n", params->iter_count);
MHD__gnutls_hard_log ("iterationCount: %d\n", params->iter_count);
/* read the keylength, if it is set.
*/
result =
_gnutls_x509_read_uint (pbkdf2_asn, "keyLength", &params->key_size);
MHD__gnutls_x509_read_uint (pbkdf2_asn, "keyLength", &params->key_size);
if (result < 0)
{
params->key_size = 0;
}
_gnutls_hard_log ("keyLength: %d\n", params->key_size);
MHD__gnutls_hard_log ("keyLength: %d\n", params->key_size);
/* We don't read the PRF. We only use the default.
*/
@@ -778,7 +778,7 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
return 0;
error:
asn1_delete_structure (&pbkdf2_asn);
MHD__asn1_delete_structure (&pbkdf2_asn);
return result;
}
@@ -786,7 +786,7 @@ error:
/* Reads the PBE parameters from PKCS-12 schemas (*&#%*&#% RSA).
*/
static int
read_pkcs12_kdf_params (ASN1_TYPE pbes2_asn, struct pbkdf2_params *params)
readMHD_pkcs12_kdf_params (ASN1_TYPE pbes2_asn, struct pbkdf2_params *params)
{
int result;
@@ -795,25 +795,25 @@ read_pkcs12_kdf_params (ASN1_TYPE pbes2_asn, struct pbkdf2_params *params)
/* read the salt */
params->salt_size = sizeof (params->salt);
result =
asn1_read_value (pbes2_asn, "salt", params->salt, &params->salt_size);
MHD__asn1_read_value (pbes2_asn, "salt", params->salt, &params->salt_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
_gnutls_hard_log ("salt.size: %d\n", params->salt_size);
MHD__gnutls_hard_log ("salt.size: %d\n", params->salt_size);
/* read the iteration count
*/
result =
_gnutls_x509_read_uint (pbes2_asn, "iterations", &params->iter_count);
MHD__gnutls_x509_read_uint (pbes2_asn, "iterations", &params->iter_count);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
_gnutls_hard_log ("iterationCount: %d\n", params->iter_count);
MHD__gnutls_hard_log ("iterationCount: %d\n", params->iter_count);
params->key_size = 0;
@@ -827,7 +827,7 @@ error:
/* Writes the PBE parameters for PKCS-12 schemas.
*/
static int
write_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
writeMHD_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
const struct pbkdf2_params *kdf_params)
{
int result;
@@ -835,27 +835,27 @@ write_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
/* write the salt
*/
result =
asn1_write_value (pbes2_asn, "salt",
MHD__asn1_write_value (pbes2_asn, "salt",
kdf_params->salt, kdf_params->salt_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
_gnutls_hard_log ("salt.size: %d\n", kdf_params->salt_size);
MHD__gnutls_hard_log ("salt.size: %d\n", kdf_params->salt_size);
/* write the iteration count
*/
result =
_gnutls_x509_write_uint32 (pbes2_asn, "iterations",
MHD__gnutls_x509_write_uint32 (pbes2_asn, "iterations",
kdf_params->iter_count);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
_gnutls_hard_log ("iterationCount: %d\n", kdf_params->iter_count);
MHD__gnutls_hard_log ("iterationCount: %d\n", kdf_params->iter_count);
return 0;
@@ -884,13 +884,13 @@ oid2cipher (const char *oid, enum MHD_GNUTLS_CipherAlgorithm *algo)
return 0;
}
_gnutls_x509_log ("PKCS #8 encryption OID '%s' is unsupported.\n", oid);
MHD__gnutls_x509_log ("PKCS #8 encryption OID '%s' is unsupported.\n", oid);
return GNUTLS_E_UNKNOWN_CIPHER_TYPE;
}
static int
read_pbe_enc_params (ASN1_TYPE pbes2_asn,
const gnutls_datum_t * der,
const MHD_gnutls_datum_t * der,
struct pbe_enc_params *params)
{
int params_start, params_end;
@@ -904,66 +904,66 @@ read_pbe_enc_params (ASN1_TYPE pbes2_asn,
*/
len = sizeof (oid);
result =
asn1_read_value (pbes2_asn, "encryptionScheme.algorithm", oid, &len);
MHD__asn1_read_value (pbes2_asn, "encryptionScheme.algorithm", oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
_gnutls_hard_log ("encryptionScheme.algorithm: %s\n", oid);
MHD__gnutls_hard_log ("encryptionScheme.algorithm: %s\n", oid);
if ((result = oid2cipher (oid, &params->cipher)) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
result =
asn1_der_decoding_startEnd (pbes2_asn, der->data, der->size,
MHD__asn1_der_decoding_startEnd (pbes2_asn, der->data, der->size,
"encryptionScheme.parameters",
&params_start, &params_end);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
params_len = params_end - params_start + 1;
/* Now check the encryption parameters.
*/
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-5-des-EDE3-CBC-params",
&pbe_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result =
asn1_der_decoding (&pbe_asn, &der->data[params_start], params_len, NULL);
MHD__asn1_der_decoding (&pbe_asn, &der->data[params_start], params_len, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
/* read the IV */
params->iv_size = sizeof (params->iv);
result = asn1_read_value (pbe_asn, "", params->iv, &params->iv_size);
result = MHD__asn1_read_value (pbe_asn, "", params->iv, &params->iv_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
_gnutls_hard_log ("IV.size: %d\n", params->iv_size);
MHD__gnutls_hard_log ("IV.size: %d\n", params->iv_size);
return 0;
error:
asn1_delete_structure (&pbe_asn);
MHD__asn1_delete_structure (&pbe_asn);
return result;
}
@@ -973,49 +973,49 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
const char *root, const char *password,
const struct pbkdf2_params *kdf_params,
const struct pbe_enc_params *enc_params,
gnutls_datum_t * decrypted_data)
MHD_gnutls_datum_t * decrypted_data)
{
int result;
int data_size;
opaque *data = NULL, *key = NULL;
gnutls_datum_t dkey, d_iv;
MHD_gnutls_datum_t dkey, d_iv;
cipher_hd_t ch = NULL;
int key_size;
data_size = 0;
result = asn1_read_value (pkcs8_asn, root, NULL, &data_size);
result = MHD__asn1_read_value (pkcs8_asn, root, NULL, &data_size);
if (result != ASN1_MEM_ERROR)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
data = gnutls_malloc (data_size);
data = MHD_gnutls_malloc (data_size);
if (data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
result = asn1_read_value (pkcs8_asn, root, data, &data_size);
result = MHD__asn1_read_value (pkcs8_asn, root, data, &data_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
if (kdf_params->key_size == 0)
{
key_size = MHD_gnutls_cipher_get_key_size (enc_params->cipher);
key_size = MHD__gnutls_cipher_get_key_size (enc_params->cipher);
}
else
key_size = kdf_params->key_size;
key = gnutls_alloca (key_size);
key = MHD_gnutls_alloca (key_size);
if (key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto error;
}
@@ -1024,13 +1024,13 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
*/
if (schema == PBES2)
{
result = gc_pbkdf2_sha1 (password, strlen (password),
result = MHD_gc_pbkdf2_sha1 (password, strlen (password),
kdf_params->salt, kdf_params->salt_size,
kdf_params->iter_count, key, key_size);
if (result != GC_OK)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_DECRYPTION_FAILED;
goto error;
}
@@ -1038,14 +1038,14 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
else
{
result =
_pkcs12_string_to_key (1 /*KEY*/, kdf_params->salt,
MHD_pkcs12_string_to_key (1 /*KEY*/, kdf_params->salt,
kdf_params->salt_size,
kdf_params->iter_count, password,
key_size, key);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
}
@@ -1057,41 +1057,41 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
d_iv.data = (opaque *) enc_params->iv;
d_iv.size = enc_params->iv_size;
ch = mhd_gtls_cipher_init (enc_params->cipher, &dkey, &d_iv);
ch = MHD_gtls_cipher_init (enc_params->cipher, &dkey, &d_iv);
gnutls_afree (key);
MHD_gnutls_afree (key);
key = NULL;
if (ch == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_DECRYPTION_FAILED;
goto error;
}
result = mhd_gtls_cipher_decrypt (ch, data, data_size);
result = MHD_gtls_cipher_decrypt (ch, data, data_size);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
decrypted_data->data = data;
if (mhd_gtls_cipher_get_block_size (enc_params->cipher) != 1)
if (MHD_gtls_cipher_get_block_size (enc_params->cipher) != 1)
decrypted_data->size = data_size - data[data_size - 1];
else
decrypted_data->size = data_size;
mhd_gnutls_cipher_deinit (ch);
MHD_gnutls_cipher_deinit (ch);
return 0;
error:
gnutls_free (data);
gnutls_afree (key);
MHD_gnutls_free (data);
MHD_gnutls_afree (key);
if (ch != NULL)
mhd_gnutls_cipher_deinit (ch);
MHD_gnutls_cipher_deinit (ch);
return result;
}
@@ -1108,97 +1108,97 @@ write_pbkdf2_params (ASN1_TYPE pbes2_asn,
/* Write the key derivation algorithm
*/
result =
asn1_write_value (pbes2_asn, "keyDerivationFunc.algorithm",
MHD__asn1_write_value (pbes2_asn, "keyDerivationFunc.algorithm",
PBKDF2_OID, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* Now write the key derivation and the encryption
* functions.
*/
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-5-PBKDF2-params",
&pbkdf2_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_write_value (pbkdf2_asn, "salt", "specified", 1);
result = MHD__asn1_write_value (pbkdf2_asn, "salt", "specified", 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
/* write the salt
*/
result =
asn1_write_value (pbkdf2_asn, "salt.specified",
MHD__asn1_write_value (pbkdf2_asn, "salt.specified",
kdf_params->salt, kdf_params->salt_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
_gnutls_hard_log ("salt.specified.size: %d\n", kdf_params->salt_size);
MHD__gnutls_hard_log ("salt.specified.size: %d\n", kdf_params->salt_size);
/* write the iteration count
*/
mhd_gtls_write_uint32 (kdf_params->iter_count, tmp);
MHD_gtls_write_uint32 (kdf_params->iter_count, tmp);
result = asn1_write_value (pbkdf2_asn, "iterationCount", tmp, 4);
result = MHD__asn1_write_value (pbkdf2_asn, "iterationCount", tmp, 4);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
_gnutls_hard_log ("iterationCount: %d\n", kdf_params->iter_count);
MHD__gnutls_hard_log ("iterationCount: %d\n", kdf_params->iter_count);
/* write the keylength, if it is set.
*/
result = asn1_write_value (pbkdf2_asn, "keyLength", NULL, 0);
result = MHD__asn1_write_value (pbkdf2_asn, "keyLength", NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
/* We write an emptry prf.
*/
result = asn1_write_value (pbkdf2_asn, "prf", NULL, 0);
result = MHD__asn1_write_value (pbkdf2_asn, "prf", NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
/* now encode them an put the DER output
* in the keyDerivationFunc.parameters
*/
result = _gnutls_x509_der_encode_and_copy (pbkdf2_asn, "",
result = MHD__gnutls_x509_der_encode_and_copy (pbkdf2_asn, "",
pbes2_asn,
"keyDerivationFunc.parameters",
0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
return 0;
error:
asn1_delete_structure (&pbkdf2_asn);
MHD__asn1_delete_structure (&pbkdf2_asn);
return result;
}
@@ -1213,53 +1213,53 @@ write_pbe_enc_params (ASN1_TYPE pbes2_asn,
/* Write the encryption algorithm
*/
result =
asn1_write_value (pbes2_asn, "encryptionScheme.algorithm",
MHD__asn1_write_value (pbes2_asn, "encryptionScheme.algorithm",
DES_EDE3_CBC_OID, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
_gnutls_hard_log ("encryptionScheme.algorithm: %s\n", DES_EDE3_CBC_OID);
MHD__gnutls_hard_log ("encryptionScheme.algorithm: %s\n", DES_EDE3_CBC_OID);
/* Now check the encryption parameters.
*/
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-5-des-EDE3-CBC-params",
&pbe_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* read the salt */
result = asn1_write_value (pbe_asn, "", params->iv, params->iv_size);
result = MHD__asn1_write_value (pbe_asn, "", params->iv, params->iv_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
_gnutls_hard_log ("IV.size: %d\n", params->iv_size);
MHD__gnutls_hard_log ("IV.size: %d\n", params->iv_size);
/* now encode them an put the DER output
* in the encryptionScheme.parameters
*/
result = _gnutls_x509_der_encode_and_copy (pbe_asn, "",
result = MHD__gnutls_x509_der_encode_and_copy (pbe_asn, "",
pbes2_asn,
"encryptionScheme.parameters",
0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
return 0;
error:
asn1_delete_structure (&pbe_asn);
MHD__asn1_delete_structure (&pbe_asn);
return result;
}
@@ -1270,7 +1270,7 @@ static int
generate_key (schema_id schema,
const char *password,
struct pbkdf2_params *kdf_params,
struct pbe_enc_params *enc_params, gnutls_datum_t * key)
struct pbe_enc_params *enc_params, MHD_gnutls_datum_t * key)
{
opaque rnd[2];
int ret;
@@ -1286,9 +1286,9 @@ generate_key (schema_id schema,
else if (schema == PKCS12_RC2_40_SHA1)
enc_params->cipher = MHD_GNUTLS_CIPHER_RC2_40_CBC;
if (gc_pseudo_random (rnd, 2) != GC_OK)
if (MHD_gc_pseudo_random (rnd, 2) != GC_OK)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_RANDOM_FAILED;
}
@@ -1302,22 +1302,22 @@ generate_key (schema_id schema,
else
kdf_params->salt_size = 8;
if (gc_pseudo_random (kdf_params->salt, kdf_params->salt_size) != GC_OK)
if (MHD_gc_pseudo_random (kdf_params->salt, kdf_params->salt_size) != GC_OK)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_RANDOM_FAILED;
}
kdf_params->iter_count = 256 + rnd[0];
key->size = kdf_params->key_size =
MHD_gnutls_cipher_get_key_size (enc_params->cipher);
MHD__gnutls_cipher_get_key_size (enc_params->cipher);
enc_params->iv_size = mhd_gtls_cipher_get_iv_size (enc_params->cipher);
enc_params->iv_size = MHD_gtls_cipher_get_iv_size (enc_params->cipher);
key->data = gnutls_secure_malloc (key->size);
key->data = MHD_gnutls_secure_malloc (key->size);
if (key->data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
@@ -1327,33 +1327,33 @@ generate_key (schema_id schema,
if (schema == PBES2)
{
ret = gc_pbkdf2_sha1 (password, strlen (password),
ret = MHD_gc_pbkdf2_sha1 (password, strlen (password),
kdf_params->salt, kdf_params->salt_size,
kdf_params->iter_count,
key->data, kdf_params->key_size);
if (ret != GC_OK)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_ENCRYPTION_FAILED;
}
if (enc_params->iv_size &&
gc_nonce (enc_params->iv, enc_params->iv_size) != GC_OK)
MHD_gc_nonce (enc_params->iv, enc_params->iv_size) != GC_OK)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_RANDOM_FAILED;
}
}
else
{ /* PKCS12 schemas */
ret =
_pkcs12_string_to_key (1 /*KEY*/, kdf_params->salt,
MHD_pkcs12_string_to_key (1 /*KEY*/, kdf_params->salt,
kdf_params->salt_size,
kdf_params->iter_count, password,
kdf_params->key_size, key->data);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -1362,13 +1362,13 @@ generate_key (schema_id schema,
if (enc_params->iv_size)
{
ret =
_pkcs12_string_to_key (2 /*IV*/, kdf_params->salt,
MHD_pkcs12_string_to_key (2 /*IV*/, kdf_params->salt,
kdf_params->salt_size,
kdf_params->iter_count, password,
enc_params->iv_size, enc_params->iv);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
}
@@ -1392,99 +1392,99 @@ write_schema_params (schema_id schema, ASN1_TYPE pkcs8_asn,
if (schema == PBES2)
{
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-5-PBES2-params",
&pbes2_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = write_pbkdf2_params (pbes2_asn, kdf_params);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
result = write_pbe_enc_params (pbes2_asn, enc_params);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
result = _gnutls_x509_der_encode_and_copy (pbes2_asn, "",
result = MHD__gnutls_x509_der_encode_and_copy (pbes2_asn, "",
pkcs8_asn, where, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
asn1_delete_structure (&pbes2_asn);
MHD__asn1_delete_structure (&pbes2_asn);
}
else
{ /* PKCS12 schemas */
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-12-PbeParams",
&pbes2_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
result = write_pkcs12_kdf_params (pbes2_asn, kdf_params);
result = writeMHD_pkcs12_kdf_params (pbes2_asn, kdf_params);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
result = _gnutls_x509_der_encode_and_copy (pbes2_asn, "",
result = MHD__gnutls_x509_der_encode_and_copy (pbes2_asn, "",
pkcs8_asn, where, 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
asn1_delete_structure (&pbes2_asn);
MHD__asn1_delete_structure (&pbes2_asn);
}
return 0;
error:
asn1_delete_structure (&pbes2_asn);
MHD__asn1_delete_structure (&pbes2_asn);
return result;
}
static int
encrypt_data (const gnutls_datum_t * plain,
encrypt_data (const MHD_gnutls_datum_t * plain,
const struct pbe_enc_params *enc_params,
gnutls_datum_t * key, gnutls_datum_t * encrypted)
MHD_gnutls_datum_t * key, MHD_gnutls_datum_t * encrypted)
{
int result;
int data_size;
opaque *data = NULL;
gnutls_datum_t d_iv;
MHD_gnutls_datum_t d_iv;
cipher_hd_t ch = NULL;
opaque pad, pad_size;
pad_size = mhd_gtls_cipher_get_block_size (enc_params->cipher);
pad_size = MHD_gtls_cipher_get_block_size (enc_params->cipher);
if (pad_size == 1) /* stream */
pad_size = 0;
data = gnutls_malloc (plain->size + pad_size);
data = MHD_gnutls_malloc (plain->size + pad_size);
if (data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
@@ -1504,33 +1504,33 @@ encrypt_data (const gnutls_datum_t * plain,
d_iv.data = (opaque *) enc_params->iv;
d_iv.size = enc_params->iv_size;
ch = mhd_gtls_cipher_init (enc_params->cipher, key, &d_iv);
ch = MHD_gtls_cipher_init (enc_params->cipher, key, &d_iv);
if (ch == GNUTLS_CIPHER_FAILED)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_ENCRYPTION_FAILED;
goto error;
}
result = mhd_gtls_cipher_encrypt (ch, data, data_size);
result = MHD_gtls_cipher_encrypt (ch, data, data_size);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
encrypted->data = data;
encrypted->size = data_size;
mhd_gnutls_cipher_deinit (ch);
MHD_gnutls_cipher_deinit (ch);
return 0;
error:
gnutls_free (data);
MHD_gnutls_free (data);
if (ch != NULL)
mhd_gnutls_cipher_deinit (ch);
MHD_gnutls_cipher_deinit (ch);
return result;
}
@@ -1538,12 +1538,12 @@ error:
* and stored in dec.
*/
int
_gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
const char *password, gnutls_datum_t * dec)
MHD__gnutls_pkcs7_decrypt_data (const MHD_gnutls_datum_t * data,
const char *password, MHD_gnutls_datum_t * dec)
{
int result, len;
char enc_oid[64];
gnutls_datum_t tmp;
MHD_gnutls_datum_t tmp;
ASN1_TYPE pbes2_asn = ASN1_TYPE_EMPTY, pkcs7_asn = ASN1_TYPE_EMPTY;
int params_start, params_end, params_len;
struct pbkdf2_params kdf_params;
@@ -1551,20 +1551,20 @@ _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
schema_id schema;
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-7-EncryptedData",
&pkcs7_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
result = asn1_der_decoding (&pkcs7_asn, data->data, data->size, NULL);
result = MHD__asn1_der_decoding (&pkcs7_asn, data->data, data->size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
@@ -1572,19 +1572,19 @@ _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
*/
len = sizeof (enc_oid);
result =
asn1_read_value (pkcs7_asn,
MHD__asn1_read_value (pkcs7_asn,
"encryptedContentInfo.contentEncryptionAlgorithm.algorithm",
enc_oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
if ((result = check_schema (enc_oid)) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
schema = result;
@@ -1592,13 +1592,13 @@ _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
/* Get the DER encoding of the parameters.
*/
result =
asn1_der_decoding_startEnd (pkcs7_asn, data->data, data->size,
MHD__asn1_der_decoding_startEnd (pkcs7_asn, data->data, data->size,
"encryptedContentInfo.contentEncryptionAlgorithm.parameters",
&params_start, &params_end);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
params_len = params_end - params_start + 1;
@@ -1609,8 +1609,8 @@ _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
params_len, &kdf_params, &enc_params);
if (result < ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
@@ -1624,19 +1624,19 @@ _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
&kdf_params, &enc_params, &tmp);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
asn1_delete_structure (&pkcs7_asn);
MHD__asn1_delete_structure (&pkcs7_asn);
*dec = tmp;
return 0;
error:
asn1_delete_structure (&pbes2_asn);
asn1_delete_structure (&pkcs7_asn);
MHD__asn1_delete_structure (&pbes2_asn);
MHD__asn1_delete_structure (&pkcs7_asn);
return result;
}
@@ -1644,24 +1644,24 @@ error:
* and stored in enc.
*/
int
_gnutls_pkcs7_encrypt_data (schema_id schema,
const gnutls_datum_t * data,
const char *password, gnutls_datum_t * enc)
MHD__gnutls_pkcs7_encrypt_data (schema_id schema,
const MHD_gnutls_datum_t * data,
const char *password, MHD_gnutls_datum_t * enc)
{
int result;
gnutls_datum_t key = { NULL, 0 };
gnutls_datum_t tmp = { NULL, 0 };
MHD_gnutls_datum_t key = { NULL, 0 };
MHD_gnutls_datum_t tmp = { NULL, 0 };
ASN1_TYPE pkcs7_asn = ASN1_TYPE_EMPTY;
struct pbkdf2_params kdf_params;
struct pbe_enc_params enc_params;
if ((result =
asn1_create_element (_gnutls_get_pkix (),
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.pkcs-7-EncryptedData",
&pkcs7_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
@@ -1671,25 +1671,25 @@ _gnutls_pkcs7_encrypt_data (schema_id schema,
{
case PBES2:
result =
asn1_write_value (pkcs7_asn,
MHD__asn1_write_value (pkcs7_asn,
"encryptedContentInfo.contentEncryptionAlgorithm.algorithm",
PBES2_OID, 1);
break;
case PKCS12_3DES_SHA1:
result =
asn1_write_value (pkcs7_asn,
MHD__asn1_write_value (pkcs7_asn,
"encryptedContentInfo.contentEncryptionAlgorithm.algorithm",
PKCS12_PBE_3DES_SHA1_OID, 1);
break;
case PKCS12_ARCFOUR_SHA1:
result =
asn1_write_value (pkcs7_asn,
MHD__asn1_write_value (pkcs7_asn,
"encryptedContentInfo.contentEncryptionAlgorithm.algorithm",
PKCS12_PBE_ARCFOUR_SHA1_OID, 1);
break;
case PKCS12_RC2_40_SHA1:
result =
asn1_write_value (pkcs7_asn,
MHD__asn1_write_value (pkcs7_asn,
"encryptedContentInfo.contentEncryptionAlgorithm.algorithm",
PKCS12_PBE_RC2_40_SHA1_OID, 1);
break;
@@ -1698,8 +1698,8 @@ _gnutls_pkcs7_encrypt_data (schema_id schema,
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
@@ -1709,7 +1709,7 @@ _gnutls_pkcs7_encrypt_data (schema_id schema,
result = generate_key (schema, password, &kdf_params, &enc_params, &key);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
@@ -1718,7 +1718,7 @@ _gnutls_pkcs7_encrypt_data (schema_id schema,
&kdf_params, &enc_params);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
@@ -1728,70 +1728,70 @@ _gnutls_pkcs7_encrypt_data (schema_id schema,
result = encrypt_data (data, &enc_params, &key, &tmp);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
/* write the encrypted data.
*/
result =
asn1_write_value (pkcs7_asn,
MHD__asn1_write_value (pkcs7_asn,
"encryptedContentInfo.encryptedContent", tmp.data,
tmp.size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
_gnutls_free_datum (&tmp);
_gnutls_free_datum (&key);
MHD__gnutls_free_datum (&tmp);
MHD__gnutls_free_datum (&key);
/* Now write the rest of the pkcs-7 stuff.
*/
result = _gnutls_x509_write_uint32 (pkcs7_asn, "version", 0);
result = MHD__gnutls_x509_write_uint32 (pkcs7_asn, "version", 0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
result =
asn1_write_value (pkcs7_asn, "encryptedContentInfo.contentType",
MHD__asn1_write_value (pkcs7_asn, "encryptedContentInfo.contentType",
DATA_OID, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
result = asn1_write_value (pkcs7_asn, "unprotectedAttrs", NULL, 0);
result = MHD__asn1_write_value (pkcs7_asn, "unprotectedAttrs", NULL, 0);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto error;
}
/* Now encode and copy the DER stuff.
*/
result = _gnutls_x509_der_encode (pkcs7_asn, "", enc, 0);
result = MHD__gnutls_x509_der_encode (pkcs7_asn, "", enc, 0);
asn1_delete_structure (&pkcs7_asn);
MHD__asn1_delete_structure (&pkcs7_asn);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
error:
_gnutls_free_datum (&key);
_gnutls_free_datum (&tmp);
asn1_delete_structure (&pkcs7_asn);
MHD__gnutls_free_datum (&key);
MHD__gnutls_free_datum (&tmp);
MHD__asn1_delete_structure (&pkcs7_asn);
return result;
}
+1 -1
View File
@@ -22,5 +22,5 @@
*
*/
int _gnutls_hostname_compare (const char *certname, const char *hostname);
int MHD__gnutls_hostname_compare (const char *certname, const char *hostname);
#define MAX_CN 256
+9 -9
View File
@@ -32,7 +32,7 @@
* return 1 on success or 0 on error
*/
int
_gnutls_hostname_compare (const char *certname, const char *hostname)
MHD__gnutls_hostname_compare (const char *certname, const char *hostname)
{
const char *cmpstr1, *cmpstr2;
@@ -71,8 +71,8 @@ _gnutls_hostname_compare (const char *certname, const char *hostname)
}
/**
* gnutls_x509_crt_check_hostname - This function compares the given hostname with the hostname in the certificate
* @cert: should contain an gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_check_hostname - This function compares the given hostname with the hostname in the certificate
* @cert: should contain an MHD_gnutls_x509_crt_t structure
* @hostname: A null terminated string that contains a DNS name
*
* This function will check if the given certificate's subject
@@ -84,7 +84,7 @@ _gnutls_hostname_compare (const char *certname, const char *hostname)
* Returns non zero for a successful match, and zero on failure.
**/
int
gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert, const char *hostname)
MHD_gnutls_x509_crt_check_hostname (MHD_gnutls_x509_crt_t cert, const char *hostname)
{
char dnsname[MAX_CN];
@@ -111,14 +111,14 @@ gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert, const char *hostname)
{
dnsnamesize = sizeof (dnsname);
ret = gnutls_x509_crt_get_subject_alt_name (cert, i,
ret = MHD_gnutls_x509_crt_get_subject_alt_name (cert, i,
dnsname, &dnsnamesize,
NULL);
if (ret == GNUTLS_SAN_DNSNAME)
{
found_dnsname = 1;
if (_gnutls_hostname_compare (dnsname, hostname))
if (MHD__gnutls_hostname_compare (dnsname, hostname))
{
return 1;
}
@@ -128,7 +128,7 @@ gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert, const char *hostname)
found_dnsname = 1; /* RFC 2818 is unclear whether the CN
should be compared for IP addresses
too, but we won't do it. */
if (_gnutls_hostname_compare (dnsname, hostname))
if (MHD__gnutls_hostname_compare (dnsname, hostname))
{
return 1;
}
@@ -140,7 +140,7 @@ gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert, const char *hostname)
/* not got the necessary extension, use CN instead
*/
dnsnamesize = sizeof (dnsname);
if (gnutls_x509_crt_get_dn_by_oid (cert, OID_X520_COMMON_NAME, 0,
if (MHD_gnutls_x509_crt_get_dn_by_oid (cert, OID_X520_COMMON_NAME, 0,
0, dnsname, &dnsnamesize) < 0)
{
/* got an error, can't find a name
@@ -148,7 +148,7 @@ gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert, const char *hostname)
return 0;
}
if (_gnutls_hostname_compare (dnsname, hostname))
if (MHD__gnutls_hostname_compare (dnsname, hostname))
{
return 1;
}
+81 -81
View File
@@ -50,34 +50,34 @@
*/
static int
encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
const gnutls_datum_t * digest, gnutls_datum_t * info)
const MHD_gnutls_datum_t * digest, MHD_gnutls_datum_t * info)
{
ASN1_TYPE dinfo = ASN1_TYPE_EMPTY;
int result;
const char *algo;
algo = mhd_gtls_x509_mac_to_oid ((enum MHD_GNUTLS_HashAlgorithm) hash);
algo = MHD_gtls_x509_mac_to_oid ((enum MHD_GNUTLS_HashAlgorithm) hash);
if (algo == NULL)
{
gnutls_assert ();
_gnutls_x509_log ("Hash algorithm: %d\n", hash);
MHD_gnutls_assert ();
MHD__gnutls_x509_log ("Hash algorithm: %d\n", hash);
return GNUTLS_E_UNKNOWN_PK_ALGORITHM;
}
if ((result = asn1_create_element (_gnutls_get_gnutls_asn (),
if ((result = MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
"GNUTLS.DigestInfo",
&dinfo)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_write_value (dinfo, "digestAlgorithm.algorithm", algo, 1);
result = MHD__asn1_write_value (dinfo, "digestAlgorithm.algorithm", algo, 1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&dinfo);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dinfo);
return MHD_gtls_asn2err (result);
}
/* Write an ASN.1 NULL in the parameters field. This matches RFC
@@ -85,43 +85,43 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
perspective (see those documents for more information).
Regardless of what is correct, this appears to be what most
implementations do. */
result = asn1_write_value (dinfo, "digestAlgorithm.parameters",
result = MHD__asn1_write_value (dinfo, "digestAlgorithm.parameters",
"\x05\x00", 2);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&dinfo);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dinfo);
return MHD_gtls_asn2err (result);
}
result = asn1_write_value (dinfo, "digest", digest->data, digest->size);
result = MHD__asn1_write_value (dinfo, "digest", digest->data, digest->size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&dinfo);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dinfo);
return MHD_gtls_asn2err (result);
}
info->size = 0;
asn1_der_coding (dinfo, "", NULL, &info->size, NULL);
MHD__asn1_der_coding (dinfo, "", NULL, &info->size, NULL);
info->data = gnutls_malloc (info->size);
info->data = MHD_gnutls_malloc (info->size);
if (info->data == NULL)
{
gnutls_assert ();
asn1_delete_structure (&dinfo);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dinfo);
return GNUTLS_E_MEMORY_ERROR;
}
result = asn1_der_coding (dinfo, "", info->data, &info->size, NULL);
result = MHD__asn1_der_coding (dinfo, "", info->data, &info->size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&dinfo);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dinfo);
return MHD_gtls_asn2err (result);
}
asn1_delete_structure (&dinfo);
MHD__asn1_delete_structure (&dinfo);
return 0;
}
@@ -133,45 +133,45 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
*/
static int
pkcs1_rsa_sign (enum MHD_GNUTLS_HashAlgorithm hash,
const gnutls_datum_t * text, mpi_t * params, int params_len,
gnutls_datum_t * signature)
const MHD_gnutls_datum_t * text, mpi_t * params, int params_len,
MHD_gnutls_datum_t * signature)
{
int ret;
opaque _digest[MAX_HASH_SIZE];
GNUTLS_HASH_HANDLE hd;
gnutls_datum_t digest, info;
MHD_gnutls_datum_t digest, info;
hd = mhd_gtls_hash_init (HASH2MAC (hash));
hd = MHD_gtls_hash_init (HASH2MAC (hash));
if (hd == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_HASH_FAILED;
}
mhd_gnutls_hash (hd, text->data, text->size);
mhd_gnutls_hash_deinit (hd, _digest);
MHD_gnutls_hash (hd, text->data, text->size);
MHD_gnutls_hash_deinit (hd, _digest);
digest.data = _digest;
digest.size = mhd_gnutls_hash_get_algo_len (HASH2MAC (hash));
digest.size = MHD_gnutls_hash_get_algo_len (HASH2MAC (hash));
/* Encode the digest as a DigestInfo
*/
if ((ret = encode_ber_digest_info (hash, &digest, &info)) != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
if ((ret =
mhd_gtls_sign (MHD_GNUTLS_PK_RSA, params, params_len, &info,
MHD_gtls_sign (MHD_GNUTLS_PK_RSA, params, params_len, &info,
signature)) < 0)
{
gnutls_assert ();
_gnutls_free_datum (&info);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (&info);
return ret;
}
_gnutls_free_datum (&info);
MHD__gnutls_free_datum (&info);
return 0;
}
@@ -186,9 +186,9 @@ pkcs1_rsa_sign (enum MHD_GNUTLS_HashAlgorithm hash,
* 'hash' is only used in PKCS1 RSA signing.
*/
int
_gnutls_x509_sign (const gnutls_datum_t * tbs,
MHD__gnutls_x509_sign (const MHD_gnutls_datum_t * tbs,
enum MHD_GNUTLS_HashAlgorithm hash,
gnutls_x509_privkey_t signer, gnutls_datum_t * signature)
MHD_gnutls_x509_privkey_t signer, MHD_gnutls_datum_t * signature)
{
int ret;
@@ -200,63 +200,63 @@ _gnutls_x509_sign (const gnutls_datum_t * tbs,
signature);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
return 0;
break;
default:
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
}
}
/* This is the same as the _gnutls_x509_sign, but this one will decode
/* This is the same as the MHD__gnutls_x509_sign, but this one will decode
* the ASN1_TYPE given, and sign the DER data. Actually used to get the DER
* of the TBS and sign it on the fly.
*/
int
_gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
MHD__gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
enum MHD_GNUTLS_HashAlgorithm hash,
gnutls_x509_privkey_t signer,
gnutls_datum_t * signature)
MHD_gnutls_x509_privkey_t signer,
MHD_gnutls_datum_t * signature)
{
int result;
opaque *buf;
int buf_size;
gnutls_datum_t tbs;
MHD_gnutls_datum_t tbs;
buf_size = 0;
asn1_der_coding (cert, tbs_name, NULL, &buf_size, NULL);
MHD__asn1_der_coding (cert, tbs_name, NULL, &buf_size, NULL);
buf = gnutls_alloca (buf_size);
buf = MHD_gnutls_alloca (buf_size);
if (buf == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
result = asn1_der_coding (cert, tbs_name, buf, &buf_size, NULL);
result = MHD__asn1_der_coding (cert, tbs_name, buf, &buf_size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
gnutls_afree (buf);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD_gnutls_afree (buf);
return MHD_gtls_asn2err (result);
}
tbs.data = buf;
tbs.size = buf_size;
result = _gnutls_x509_sign (&tbs, hash, signer, signature);
gnutls_afree (buf);
result = MHD__gnutls_x509_sign (&tbs, hash, signer, signature);
MHD_gnutls_afree (buf);
return result;
}
/*-
* _gnutls_x509_pkix_sign - This function will sign a CRL or a certificate with a key
* MHD__gnutls_x509_pkix_sign - This function will sign a CRL or a certificate with a key
* @src: should contain an ASN1_TYPE
* @issuer: is the certificate of the certificate issuer
* @issuer_key: holds the issuer's private key
@@ -268,76 +268,76 @@ _gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
*
-*/
int
_gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
MHD__gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
enum MHD_GNUTLS_HashAlgorithm dig,
gnutls_x509_crt_t issuer,
gnutls_x509_privkey_t issuer_key)
MHD_gnutls_x509_crt_t issuer,
MHD_gnutls_x509_privkey_t issuer_key)
{
int result;
gnutls_datum_t signature;
MHD_gnutls_datum_t signature;
char name[128];
/* Step 1. Copy the issuer's name into the certificate.
*/
mhd_gtls_str_cpy (name, sizeof (name), src_name);
mhd_gtls_str_cat (name, sizeof (name), ".issuer");
MHD_gtls_str_cpy (name, sizeof (name), src_name);
MHD_gtls_str_cat (name, sizeof (name), ".issuer");
result = asn1_copy_node (src, name, issuer->cert, "tbsCertificate.subject");
result = MHD__asn1_copy_node (src, name, issuer->cert, "tbsCertificate.subject");
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* Step 1.5. Write the signature stuff in the tbsCertificate.
*/
mhd_gtls_str_cpy (name, sizeof (name), src_name);
mhd_gtls_str_cat (name, sizeof (name), ".signature");
MHD_gtls_str_cpy (name, sizeof (name), src_name);
MHD_gtls_str_cat (name, sizeof (name), ".signature");
result = _gnutls_x509_write_sig_params (src, name,
result = MHD__gnutls_x509_write_sig_params (src, name,
issuer_key->pk_algorithm, dig,
issuer_key->params,
issuer_key->params_size);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* Step 2. Sign the certificate.
*/
result = _gnutls_x509_sign_tbs (src, src_name, dig, issuer_key, &signature);
result = MHD__gnutls_x509_sign_tbs (src, src_name, dig, issuer_key, &signature);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
/* write the signature (bits)
*/
result =
asn1_write_value (src, "signature", signature.data, signature.size * 8);
MHD__asn1_write_value (src, "signature", signature.data, signature.size * 8);
_gnutls_free_datum (&signature);
MHD__gnutls_free_datum (&signature);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
/* Step 3. Move up and write the AlgorithmIdentifier, which is also
* the same.
*/
result = _gnutls_x509_write_sig_params (src, "signatureAlgorithm",
result = MHD__gnutls_x509_write_sig_params (src, "signatureAlgorithm",
issuer_key->pk_algorithm, dig,
issuer_key->params,
issuer_key->params_size);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
+9 -9
View File
@@ -22,15 +22,15 @@
*
*/
int _gnutls_x509_sign (const gnutls_datum_t * tbs,
int MHD__gnutls_x509_sign (const MHD_gnutls_datum_t * tbs,
enum MHD_GNUTLS_HashAlgorithm hash,
gnutls_x509_privkey_t signer,
gnutls_datum_t * signature);
int _gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
MHD_gnutls_x509_privkey_t signer,
MHD_gnutls_datum_t * signature);
int MHD__gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
enum MHD_GNUTLS_HashAlgorithm hash,
gnutls_x509_privkey_t signer,
gnutls_datum_t * signature);
int _gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
MHD_gnutls_x509_privkey_t signer,
MHD_gnutls_datum_t * signature);
int MHD__gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
enum MHD_GNUTLS_HashAlgorithm,
gnutls_x509_crt_t issuer,
gnutls_x509_privkey_t issuer_key);
MHD_gnutls_x509_crt_t issuer,
MHD_gnutls_x509_privkey_t issuer_key);
+8 -8
View File
@@ -24,11 +24,11 @@
#include "x509.h"
int gnutls_x509_crt_is_issuer (gnutls_x509_crt_t cert,
gnutls_x509_crt_t issuer);
int _gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
const gnutls_datum_t * signature,
gnutls_x509_crt_t issuer);
int _gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
const gnutls_datum_t * signature,
gnutls_x509_privkey_t issuer);
int MHD_gnutls_x509_crt_is_issuer (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_t issuer);
int MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * tbs,
const MHD_gnutls_datum_t * signature,
MHD_gnutls_x509_crt_t issuer);
int MHD__gnutls_x509_privkey_verify_signature (const MHD_gnutls_datum_t * tbs,
const MHD_gnutls_datum_t * signature,
MHD_gnutls_x509_privkey_t issuer);
+534 -534
View File
@@ -40,7 +40,7 @@
#include <verify.h>
/**
* gnutls_x509_crt_init - This function initializes a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_init - This function initializes a MHD_gnutls_x509_crt_t structure
* @cert: The structure to be initialized
*
* This function will initialize an X.509 certificate structure.
@@ -49,21 +49,21 @@
*
**/
int
gnutls_x509_crt_init (gnutls_x509_crt_t * cert)
MHD_gnutls_x509_crt_init (MHD_gnutls_x509_crt_t * cert)
{
gnutls_x509_crt_t tmp = gnutls_calloc (1, sizeof (gnutls_x509_crt_int));
MHD_gnutls_x509_crt_t tmp = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_x509_crt_int));
int result;
if (!tmp)
return GNUTLS_E_MEMORY_ERROR;
result = asn1_create_element (_gnutls_get_pkix (),
result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
"PKIX1.Certificate", &tmp->cert);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
gnutls_free (tmp);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD_gnutls_free (tmp);
return MHD_gtls_asn2err (result);
}
*cert = tmp;
@@ -72,7 +72,7 @@ gnutls_x509_crt_init (gnutls_x509_crt_t * cert)
}
/*-
* _gnutls_x509_crt_cpy - This function copies a gnutls_x509_crt_t structure
* MHD__gnutls_x509_crt_cpy - This function copies a MHD_gnutls_x509_crt_t structure
* @dest: The structure where to copy
* @src: The structure to be copied
*
@@ -82,44 +82,44 @@ gnutls_x509_crt_init (gnutls_x509_crt_t * cert)
*
-*/
int
_gnutls_x509_crt_cpy (gnutls_x509_crt_t dest, gnutls_x509_crt_t src)
MHD__gnutls_x509_crt_cpy (MHD_gnutls_x509_crt_t dest, MHD_gnutls_x509_crt_t src)
{
int ret;
size_t der_size;
opaque *der;
gnutls_datum_t tmp;
MHD_gnutls_datum_t tmp;
ret = gnutls_x509_crt_export (src, GNUTLS_X509_FMT_DER, NULL, &der_size);
ret = MHD_gnutls_x509_crt_export (src, GNUTLS_X509_FMT_DER, NULL, &der_size);
if (ret != GNUTLS_E_SHORT_MEMORY_BUFFER)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
der = gnutls_alloca (der_size);
der = MHD_gnutls_alloca (der_size);
if (der == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
ret = gnutls_x509_crt_export (src, GNUTLS_X509_FMT_DER, der, &der_size);
ret = MHD_gnutls_x509_crt_export (src, GNUTLS_X509_FMT_DER, der, &der_size);
if (ret < 0)
{
gnutls_assert ();
gnutls_afree (der);
MHD_gnutls_assert ();
MHD_gnutls_afree (der);
return ret;
}
tmp.data = der;
tmp.size = der_size;
ret = gnutls_x509_crt_import (dest, &tmp, GNUTLS_X509_FMT_DER);
ret = MHD_gnutls_x509_crt_import (dest, &tmp, GNUTLS_X509_FMT_DER);
gnutls_afree (der);
MHD_gnutls_afree (der);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -128,32 +128,32 @@ _gnutls_x509_crt_cpy (gnutls_x509_crt_t dest, gnutls_x509_crt_t src)
}
/**
* gnutls_x509_crt_deinit - This function deinitializes memory used by a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_deinit - This function deinitializes memory used by a MHD_gnutls_x509_crt_t structure
* @cert: The structure to be initialized
*
* This function will deinitialize a CRL structure.
*
**/
void
gnutls_x509_crt_deinit (gnutls_x509_crt_t cert)
MHD_gnutls_x509_crt_deinit (MHD_gnutls_x509_crt_t cert)
{
if (!cert)
return;
if (cert->cert)
asn1_delete_structure (&cert->cert);
MHD__asn1_delete_structure (&cert->cert);
gnutls_free (cert);
MHD_gnutls_free (cert);
}
/**
* gnutls_x509_crt_import - This function will import a DER or PEM encoded Certificate
* MHD_gnutls_x509_crt_import - This function will import a DER or PEM encoded Certificate
* @cert: The structure to store the parsed certificate.
* @data: The DER or PEM encoded certificate.
* @format: One of DER or PEM
*
* This function will convert the given DER or PEM encoded Certificate
* to the native gnutls_x509_crt_t format. The output will be stored in @cert.
* to the native MHD_gnutls_x509_crt_t format. The output will be stored in @cert.
*
* If the Certificate is PEM encoded it should have a header of "X509 CERTIFICATE", or
* "CERTIFICATE".
@@ -162,17 +162,17 @@ gnutls_x509_crt_deinit (gnutls_x509_crt_t cert)
*
**/
int
gnutls_x509_crt_import (gnutls_x509_crt_t cert,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format)
MHD_gnutls_x509_crt_import (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format)
{
int result = 0, need_free = 0;
gnutls_datum_t _data;
MHD_gnutls_datum_t _data;
opaque *signature = NULL;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -186,20 +186,20 @@ gnutls_x509_crt_import (gnutls_x509_crt_t cert,
opaque *out;
/* Try the first header */
result = _gnutls_fbase64_decode (PEM_X509_CERT2, data->data, data->size,
result = MHD__gnutls_fbase64_decode (PEM_X509_CERT2, data->data, data->size,
&out);
if (result <= 0)
{
/* try for the second header */
result = _gnutls_fbase64_decode (PEM_X509_CERT, data->data,
result = MHD__gnutls_fbase64_decode (PEM_X509_CERT, data->data,
data->size, &out);
if (result <= 0)
{
if (result == 0)
result = GNUTLS_E_INTERNAL_ERROR;
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
}
@@ -210,11 +210,11 @@ gnutls_x509_crt_import (gnutls_x509_crt_t cert,
need_free = 1;
}
result = asn1_der_decoding (&cert->cert, _data.data, _data.size, NULL);
result = MHD__asn1_der_decoding (&cert->cert, _data.data, _data.size, NULL);
if (result != ASN1_SUCCESS)
{
result = mhd_gtls_asn2err (result);
gnutls_assert ();
result = MHD_gtls_asn2err (result);
MHD_gnutls_assert ();
goto cleanup;
}
@@ -222,19 +222,19 @@ gnutls_x509_crt_import (gnutls_x509_crt_t cert,
*/
cert->use_extensions = 1;
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
return 0;
cleanup:gnutls_free (signature);
cleanup:MHD_gnutls_free (signature);
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
return result;
}
/**
* gnutls_x509_crt_get_issuer_dn - This function returns the Certificate's issuer distinguished name
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_issuer_dn - This function returns the Certificate's issuer distinguished name
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @buf: a pointer to a structure to hold the name (may be null)
* @sizeof_buf: initially holds the size of @buf
*
@@ -251,23 +251,23 @@ cleanup:gnutls_free (signature);
*
**/
int
gnutls_x509_crt_get_issuer_dn (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_issuer_dn (MHD_gnutls_x509_crt_t cert,
char *buf, size_t * sizeof_buf)
{
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_parse_dn (cert->cert,
return MHD__gnutls_x509_parse_dn (cert->cert,
"tbsCertificate.issuer.rdnSequence", buf,
sizeof_buf);
}
/**
* gnutls_x509_crt_get_issuer_dn_by_oid - This function returns the Certificate's issuer distinguished name
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_issuer_dn_by_oid - This function returns the Certificate's issuer distinguished name
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @oid: holds an Object Identified in null terminated string
* @indx: In case multiple same OIDs exist in the RDN, this specifies which to send. Use zero to get the first one.
* @raw_flag: If non zero returns the raw DER data of the DN part.
@@ -283,7 +283,7 @@ gnutls_x509_crt_get_issuer_dn (gnutls_x509_crt_t cert,
* If raw flag is zero, this function will only return known OIDs as
* text. Other OIDs will be DER encoded, as described in RFC2253 --
* in hex format with a '\#' prefix. You can check about known OIDs
* using gnutls_x509_dn_oid_known().
* using MHD_gnutls_x509_dn_oid_known().
*
* If @buf is null then only the size will be filled.
*
@@ -293,7 +293,7 @@ gnutls_x509_crt_get_issuer_dn (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_issuer_dn_by_oid (MHD_gnutls_x509_crt_t cert,
const char *oid,
int indx,
unsigned int raw_flag,
@@ -301,18 +301,18 @@ gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
{
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_parse_dn_oid (cert->cert,
return MHD__gnutls_x509_parse_dn_oid (cert->cert,
"tbsCertificate.issuer.rdnSequence", oid,
indx, raw_flag, buf, sizeof_buf);
}
/**
* gnutls_x509_crt_get_issuer_dn_oid - This function returns the Certificate's issuer distinguished name OIDs
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_issuer_dn_oid - This function returns the Certificate's issuer distinguished name OIDs
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @indx: This specifies which OID to return. Use zero to get the first one.
* @oid: a pointer to a buffer to hold the OID (may be null)
* @sizeof_oid: initially holds the size of @oid
@@ -328,23 +328,23 @@ gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_issuer_dn_oid (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_issuer_dn_oid (MHD_gnutls_x509_crt_t cert,
int indx, void *oid, size_t * sizeof_oid)
{
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_get_dn_oid (cert->cert,
return MHD__gnutls_x509_get_dn_oid (cert->cert,
"tbsCertificate.issuer.rdnSequence", indx,
oid, sizeof_oid);
}
/**
* gnutls_x509_crt_get_dn - This function returns the Certificate's distinguished name
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_dn - This function returns the Certificate's distinguished name
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @buf: a pointer to a structure to hold the name (may be null)
* @sizeof_buf: initially holds the size of @buf
*
@@ -361,23 +361,23 @@ gnutls_x509_crt_get_issuer_dn_oid (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_dn (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_dn (MHD_gnutls_x509_crt_t cert,
char *buf, size_t * sizeof_buf)
{
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_parse_dn (cert->cert,
return MHD__gnutls_x509_parse_dn (cert->cert,
"tbsCertificate.subject.rdnSequence", buf,
sizeof_buf);
}
/**
* gnutls_x509_crt_get_dn_by_oid - This function returns the Certificate's distinguished name
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_dn_by_oid - This function returns the Certificate's distinguished name
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @oid: holds an Object Identified in null terminated string
* @indx: In case multiple same OIDs exist in the RDN, this specifies which to send. Use zero to get the first one.
* @raw_flag: If non zero returns the raw DER data of the DN part.
@@ -393,7 +393,7 @@ gnutls_x509_crt_get_dn (gnutls_x509_crt_t cert,
* If raw flag is zero, this function will only return known OIDs as
* text. Other OIDs will be DER encoded, as described in RFC2253 --
* in hex format with a '\#' prefix. You can check about known OIDs
* using gnutls_x509_dn_oid_known().
* using MHD_gnutls_x509_dn_oid_known().
*
* If @buf is null then only the size will be filled.
*
@@ -403,7 +403,7 @@ gnutls_x509_crt_get_dn (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_dn_by_oid (MHD_gnutls_x509_crt_t cert,
const char *oid,
int indx,
unsigned int raw_flag,
@@ -411,18 +411,18 @@ gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
{
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_parse_dn_oid (cert->cert,
return MHD__gnutls_x509_parse_dn_oid (cert->cert,
"tbsCertificate.subject.rdnSequence", oid,
indx, raw_flag, buf, sizeof_buf);
}
/**
* gnutls_x509_crt_get_dn_oid - This function returns the Certificate's subject distinguished name OIDs
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_dn_oid - This function returns the Certificate's subject distinguished name OIDs
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @indx: This specifies which OID to return. Use zero to get the first one.
* @oid: a pointer to a buffer to hold the OID (may be null)
* @sizeof_oid: initially holds the size of @oid
@@ -438,39 +438,39 @@ gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_dn_oid (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_dn_oid (MHD_gnutls_x509_crt_t cert,
int indx, void *oid, size_t * sizeof_oid)
{
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_get_dn_oid (cert->cert,
return MHD__gnutls_x509_get_dn_oid (cert->cert,
"tbsCertificate.subject.rdnSequence", indx,
oid, sizeof_oid);
}
/**
* gnutls_x509_crt_get_signature_algorithm - This function returns the Certificate's signature algorithm
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_signature_algorithm - This function returns the Certificate's signature algorithm
* @cert: should contain a MHD_gnutls_x509_crt_t structure
*
* This function will return a value of the gnutls_sign_algorithm_t enumeration that
* This function will return a value of the MHD_gnutls_sign_algorithm_t enumeration that
* is the signature algorithm.
*
* Returns a negative value on error.
*
**/
int
gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert)
MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert)
{
int result;
gnutls_datum_t sa;
MHD_gnutls_datum_t sa;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -478,25 +478,25 @@ gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert)
* read. They will be read from the issuer's certificate if needed.
*/
result =
_gnutls_x509_read_value (cert->cert, "signatureAlgorithm.algorithm", &sa,
MHD__gnutls_x509_read_value (cert->cert, "signatureAlgorithm.algorithm", &sa,
0);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
result = mhd_gtls_x509_oid2sign_algorithm (sa.data);
result = MHD_gtls_x509_oid2sign_algorithm (sa.data);
_gnutls_free_datum (&sa);
MHD__gnutls_free_datum (&sa);
return result;
}
/**
* gnutls_x509_crt_get_signature - Returns the Certificate's signature
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_signature - Returns the Certificate's signature
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @sig: a pointer where the signature part will be copied (may be null).
* @sizeof_sig: initially holds the size of @sig
*
@@ -505,7 +505,7 @@ gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert)
* Returns 0 on success, and a negative value on error.
**/
int
gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_signature (MHD_gnutls_x509_crt_t cert,
char *sig, size_t * sizeof_sig)
{
int result;
@@ -513,21 +513,21 @@ gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
bits = 0;
result = asn1_read_value (cert->cert, "signature", NULL, &bits);
result = MHD__asn1_read_value (cert->cert, "signature", NULL, &bits);
if (result != ASN1_MEM_ERROR)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (bits % 8 != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_CERTIFICATE_ERROR;
}
@@ -539,19 +539,19 @@ gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
result = asn1_read_value (cert->cert, "signature", sig, &len);
result = MHD__asn1_read_value (cert->cert, "signature", sig, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
}
/**
* gnutls_x509_crt_get_version - This function returns the Certificate's version number
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_version - This function returns the Certificate's version number
* @cert: should contain a MHD_gnutls_x509_crt_t structure
*
* This function will return the version of the specified Certificate.
*
@@ -559,35 +559,35 @@ gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_version (gnutls_x509_crt_t cert)
MHD_gnutls_x509_crt_get_version (MHD_gnutls_x509_crt_t cert)
{
opaque version[5];
int len, result;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
len = sizeof (version);
if ((result =
asn1_read_value (cert->cert, "tbsCertificate.version", version,
MHD__asn1_read_value (cert->cert, "tbsCertificate.version", version,
&len)) != ASN1_SUCCESS)
{
if (result == ASN1_ELEMENT_NOT_FOUND)
return 1; /* the DEFAULT version */
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return (int) version[0] + 1;
}
/**
* gnutls_x509_crt_get_activation_time - This function returns the Certificate's activation time
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_activation_time - This function returns the Certificate's activation time
* @cert: should contain a MHD_gnutls_x509_crt_t structure
*
* This function will return the time this Certificate was or will be activated.
*
@@ -595,21 +595,21 @@ gnutls_x509_crt_get_version (gnutls_x509_crt_t cert)
*
**/
time_t
gnutls_x509_crt_get_activation_time (gnutls_x509_crt_t cert)
MHD_gnutls_x509_crt_get_activation_time (MHD_gnutls_x509_crt_t cert)
{
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return (time_t) - 1;
}
return _gnutls_x509_get_time (cert->cert,
return MHD__gnutls_x509_get_time (cert->cert,
"tbsCertificate.validity.notBefore");
}
/**
* gnutls_x509_crt_get_expiration_time - This function returns the Certificate's expiration time
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_expiration_time - This function returns the Certificate's expiration time
* @cert: should contain a MHD_gnutls_x509_crt_t structure
*
* This function will return the time this Certificate was or will be expired.
*
@@ -617,21 +617,21 @@ gnutls_x509_crt_get_activation_time (gnutls_x509_crt_t cert)
*
**/
time_t
gnutls_x509_crt_get_expiration_time (gnutls_x509_crt_t cert)
MHD_gnutls_x509_crt_get_expiration_time (MHD_gnutls_x509_crt_t cert)
{
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return (time_t) - 1;
}
return _gnutls_x509_get_time (cert->cert,
return MHD__gnutls_x509_get_time (cert->cert,
"tbsCertificate.validity.notAfter");
}
/**
* gnutls_x509_crt_get_serial - This function returns the certificate's serial number
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_serial - This function returns the certificate's serial number
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @result: The place where the serial number will be copied
* @result_size: Holds the size of the result field.
*
@@ -645,35 +645,35 @@ gnutls_x509_crt_get_expiration_time (gnutls_x509_crt_t cert)
*
**/
int
gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
void *result, size_t * result_size)
{
int ret, len;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
len = *result_size;
ret
=
asn1_read_value (cert->cert, "tbsCertificate.serialNumber", result, &len);
MHD__asn1_read_value (cert->cert, "tbsCertificate.serialNumber", result, &len);
*result_size = len;
if (ret != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (ret);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (ret);
}
return 0;
}
/**
* gnutls_x509_crt_get_subject_key_id - This function returns the certificate's key identifier
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_subject_key_id - This function returns the certificate's key identifier
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @ret: The place where the identifier will be copied
* @ret_size: Holds the size of the result field.
* @critical: will be non zero if the extension is marked as critical (may be null)
@@ -686,17 +686,17 @@ gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_subject_key_id (MHD_gnutls_x509_crt_t cert,
void *ret,
size_t * ret_size, unsigned int *critical)
{
int result, len;
gnutls_datum_t id;
MHD_gnutls_datum_t id;
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -705,7 +705,7 @@ gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
else
*ret_size = 0;
if ((result = _gnutls_x509_crt_get_extension (cert, "2.5.29.14", 0, &id,
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.14", 0, &id,
critical)) < 0)
{
return result;
@@ -713,35 +713,35 @@ gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
if (id.size == 0 || id.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
}
result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.SubjectKeyIdentifier",
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.SubjectKeyIdentifier",
&c2);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
_gnutls_free_datum (&id);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (&id);
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&c2, id.data, id.size, NULL);
_gnutls_free_datum (&id);
result = MHD__asn1_der_decoding (&c2, id.data, id.size, NULL);
MHD__gnutls_free_datum (&id);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
return MHD_gtls_asn2err (result);
}
len = *ret_size;
result = asn1_read_value (c2, "", ret, &len);
result = MHD__asn1_read_value (c2, "", ret, &len);
*ret_size = len;
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
if (result == ASN1_VALUE_NOT_FOUND || result == ASN1_ELEMENT_NOT_FOUND)
{
@@ -750,16 +750,16 @@ gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
}
/**
* gnutls_x509_crt_get_authority_key_id - This function returns the certificate authority's identifier
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_authority_key_id - This function returns the certificate authority's identifier
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @result: The place where the identifier will be copied
* @result_size: Holds the size of the result field.
* @critical: will be non zero if the extension is marked as critical (may be null)
@@ -773,18 +773,18 @@ gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_authority_key_id (MHD_gnutls_x509_crt_t cert,
void *ret,
size_t * ret_size,
unsigned int *critical)
{
int result, len;
gnutls_datum_t id;
MHD_gnutls_datum_t id;
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -793,7 +793,7 @@ gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
else
*ret_size = 0;
if ((result = _gnutls_x509_crt_get_extension (cert, "2.5.29.35", 0, &id,
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.35", 0, &id,
critical)) < 0)
{
return result;
@@ -801,35 +801,35 @@ gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
if (id.size == 0 || id.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
}
result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.AuthorityKeyIdentifier",
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.AuthorityKeyIdentifier",
&c2);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
_gnutls_free_datum (&id);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (&id);
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&c2, id.data, id.size, NULL);
_gnutls_free_datum (&id);
result = MHD__asn1_der_decoding (&c2, id.data, id.size, NULL);
MHD__gnutls_free_datum (&id);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
return MHD_gtls_asn2err (result);
}
len = *ret_size;
result = asn1_read_value (c2, "keyIdentifier", ret, &len);
result = MHD__asn1_read_value (c2, "keyIdentifier", ret, &len);
*ret_size = len;
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
if (result == ASN1_VALUE_NOT_FOUND || result == ASN1_ELEMENT_NOT_FOUND)
{
@@ -838,16 +838,16 @@ gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
}
/**
* gnutls_x509_crt_get_pk_algorithm - This function returns the certificate's PublicKey algorithm
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_pk_algorithm - This function returns the certificate's PublicKey algorithm
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @bits: if bits is non null it will hold the size of the parameters' in bits
*
* This function will return the public key algorithm of an X.509
@@ -863,23 +863,23 @@ gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_pk_algorithm (gnutls_x509_crt_t cert, unsigned int *bits)
MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert, unsigned int *bits)
{
int result;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
result = _gnutls_x509_get_pk_algorithm (cert->cert,
result = MHD__gnutls_x509_get_pk_algorithm (cert->cert,
"tbsCertificate.subjectPublicKeyInfo",
bits);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -914,7 +914,7 @@ parse_general_name (ASN1_TYPE src,
char nptr[MAX_NAME_SIZE];
int result;
opaque choice_type[128];
gnutls_x509_subject_alt_name_t type;
MHD_gnutls_x509_subject_alt_name_t type;
seq++; /* 0->1, 1->2 etc */
@@ -924,7 +924,7 @@ parse_general_name (ASN1_TYPE src,
snprintf (nptr, sizeof (nptr), "?%u", seq);
len = sizeof (choice_type);
result = asn1_read_value (src, nptr, choice_type, &len);
result = MHD__asn1_read_value (src, nptr, choice_type, &len);
if (result == ASN1_VALUE_NOT_FOUND || result == ASN1_ELEMENT_NOT_FOUND)
{
@@ -933,14 +933,14 @@ parse_general_name (ASN1_TYPE src,
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
type = _gnutls_x509_san_find_type (choice_type);
if (type == (gnutls_x509_subject_alt_name_t) - 1)
type = MHD__gnutls_x509_san_find_type (choice_type);
if (type == (MHD_gnutls_x509_subject_alt_name_t) - 1)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_X509_UNKNOWN_SAN;
}
@@ -950,12 +950,12 @@ parse_general_name (ASN1_TYPE src,
if (type == GNUTLS_SAN_OTHERNAME)
{
if (othername_oid)
mhd_gtls_str_cat (nptr, sizeof (nptr), ".otherName.type-id");
MHD_gtls_str_cat (nptr, sizeof (nptr), ".otherName.type-id");
else
mhd_gtls_str_cat (nptr, sizeof (nptr), ".otherName.value");
MHD_gtls_str_cat (nptr, sizeof (nptr), ".otherName.value");
len = *name_size;
result = asn1_read_value (src, nptr, name, &len);
result = MHD__asn1_read_value (src, nptr, name, &len);
*name_size = len;
if (result == ASN1_MEM_ERROR)
@@ -963,8 +963,8 @@ parse_general_name (ASN1_TYPE src,
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (othername_oid)
@@ -983,11 +983,11 @@ parse_general_name (ASN1_TYPE src,
snprintf (nptr, sizeof (nptr), "?%u.otherName.type-id", seq);
len = sizeof (oid);
result = asn1_read_value (src, nptr, oid, &len);
result = MHD__asn1_read_value (src, nptr, oid, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (len > strlen (XMPP_OID) && strcmp (oid, XMPP_OID) == 0)
@@ -995,41 +995,41 @@ parse_general_name (ASN1_TYPE src,
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.XmppAddr",
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.XmppAddr",
&c2);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&c2, name, *name_size, NULL);
result = MHD__asn1_der_decoding (&c2, name, *name_size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
return MHD_gtls_asn2err (result);
}
result = asn1_read_value (c2, "", name, &len);
result = MHD__asn1_read_value (c2, "", name, &len);
*name_size = len;
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
return MHD_gtls_asn2err (result);
}
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
}
}
}
else if (type == GNUTLS_SAN_DN)
{
mhd_gtls_str_cat (nptr, sizeof (nptr), ".directoryName");
result = _gnutls_x509_parse_dn (src, nptr, name, name_size);
MHD_gtls_str_cat (nptr, sizeof (nptr), ".directoryName");
result = MHD__gnutls_x509_parse_dn (src, nptr, name, name_size);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
}
@@ -1039,11 +1039,11 @@ parse_general_name (ASN1_TYPE src,
{
size_t orig_name_size = *name_size;
mhd_gtls_str_cat (nptr, sizeof (nptr), ".");
mhd_gtls_str_cat (nptr, sizeof (nptr), choice_type);
MHD_gtls_str_cat (nptr, sizeof (nptr), ".");
MHD_gtls_str_cat (nptr, sizeof (nptr), choice_type);
len = *name_size;
result = asn1_read_value (src, nptr, name, &len);
result = MHD__asn1_read_value (src, nptr, name, &len);
*name_size = len;
if (result == ASN1_MEM_ERROR)
@@ -1055,8 +1055,8 @@ parse_general_name (ASN1_TYPE src,
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (is_type_printable (type))
@@ -1064,7 +1064,7 @@ parse_general_name (ASN1_TYPE src,
if (len + 1 > orig_name_size)
{
gnutls_assert ();
MHD_gnutls_assert ();
(*name_size)++;
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
@@ -1079,7 +1079,7 @@ parse_general_name (ASN1_TYPE src,
}
static int
get_subject_alt_name (gnutls_x509_crt_t cert,
get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
unsigned int seq,
void *ret,
size_t * ret_size,
@@ -1087,13 +1087,13 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
unsigned int *critical, int othername_oid)
{
int result;
gnutls_datum_t dnsname;
MHD_gnutls_datum_t dnsname;
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
gnutls_x509_subject_alt_name_t type;
MHD_gnutls_x509_subject_alt_name_t type;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -1103,7 +1103,7 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
*ret_size = 0;
if ((result =
_gnutls_x509_crt_get_extension (cert, "2.5.29.17", 0, &dnsname,
MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.17", 0, &dnsname,
critical)) < 0)
{
return result;
@@ -1111,33 +1111,33 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
if (dnsname.size == 0 || dnsname.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
}
result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.SubjectAltName", &c2);
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.SubjectAltName", &c2);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
_gnutls_free_datum (&dnsname);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (&dnsname);
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&c2, dnsname.data, dnsname.size, NULL);
_gnutls_free_datum (&dnsname);
result = MHD__asn1_der_decoding (&c2, dnsname.data, dnsname.size, NULL);
MHD__gnutls_free_datum (&dnsname);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
return MHD_gtls_asn2err (result);
}
result = parse_general_name (c2, "", seq, ret, ret_size, ret_type,
othername_oid);
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
if (result < 0)
{
@@ -1150,8 +1150,8 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_subject_alt_name - Get certificate's alternative name, if any
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_subject_alt_name - Get certificate's alternative name, if any
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @seq: specifies the sequence number of the alt name (0 for the first one, 1 for the second etc.)
* @ret: is the place where the alternative name will be copied to
* @ret_size: holds the size of ret.
@@ -1165,7 +1165,7 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
*
* When the SAN type is otherName, it will extract the data in the
* otherName's value field, and %GNUTLS_SAN_OTHERNAME is returned.
* You may use gnutls_x509_crt_get_subject_alt_othername_oid() to get
* You may use MHD_gnutls_x509_crt_get_subject_alt_othername_oid() to get
* the corresponding OID and the "virtual" SAN types (e.g.,
* %GNUTLS_SAN_OTHERNAME_XMPP).
*
@@ -1175,7 +1175,7 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
* recognized.
*
* Returns the alternative subject name type on success. The type is
* one of the enumerated gnutls_x509_subject_alt_name_t. It will
* one of the enumerated MHD_gnutls_x509_subject_alt_name_t. It will
* return %GNUTLS_E_SHORT_MEMORY_BUFFER if @ret_size is not large
* enough to hold the value. In that case @ret_size will be updated
* with the required size. If the certificate does not have an
@@ -1184,7 +1184,7 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_subject_alt_name (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
unsigned int seq,
void *ret,
size_t * ret_size,
@@ -1194,25 +1194,25 @@ gnutls_x509_crt_get_subject_alt_name (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_subject_alt_name2 - Get certificate's alternative name, if any
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_subject_alt_name2 - Get certificate's alternative name, if any
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @seq: specifies the sequence number of the alt name (0 for the first one, 1 for the second etc.)
* @ret: is the place where the alternative name will be copied to
* @ret_size: holds the size of ret.
* @ret_type: holds the type of the alternative name (one of gnutls_x509_subject_alt_name_t).
* @ret_type: holds the type of the alternative name (one of MHD_gnutls_x509_subject_alt_name_t).
* @critical: will be non zero if the extension is marked as critical (may be null)
*
* This function will return the alternative names, contained in the
* given certificate. It is the same as gnutls_x509_crt_get_subject_alt_name()
* given certificate. It is the same as MHD_gnutls_x509_crt_get_subject_alt_name()
* except for the fact that it will return the type of the alternative
* name in @ret_type even if the function fails for some reason (i.e.
* the buffer provided is not enough).
*
* The return values are the same as with gnutls_x509_crt_get_subject_alt_name().
* The return values are the same as with MHD_gnutls_x509_crt_get_subject_alt_name().
*
**/
int
gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_subject_alt_name2 (MHD_gnutls_x509_crt_t cert,
unsigned int seq,
void *ret,
size_t * ret_size,
@@ -1224,8 +1224,8 @@ gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_subject_alt_othername_oid - Get SAN otherName OID
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_subject_alt_othername_oid - Get SAN otherName OID
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @seq: specifies the sequence number of the alt name (0 for the first one, 1 for the second etc.)
* @ret: is the place where the otherName OID will be copied to
* @ret_size: holds the size of ret.
@@ -1235,11 +1235,11 @@ gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
* the type as an enumerated element.
*
* This function is only useful if
* gnutls_x509_crt_get_subject_alt_name() returned
* MHD_gnutls_x509_crt_get_subject_alt_name() returned
* %GNUTLS_SAN_OTHERNAME.
*
* Returns the alternative subject name type on success. The type is
* one of the enumerated gnutls_x509_subject_alt_name_t. For
* one of the enumerated MHD_gnutls_x509_subject_alt_name_t. For
* supported OIDs, it will return one of the virtual
* (GNUTLS_SAN_OTHERNAME_*) types, e.g. %GNUTLS_SAN_OTHERNAME_XMPP,
* and %GNUTLS_SAN_OTHERNAME for unknown OIDs. It will return
@@ -1250,7 +1250,7 @@ gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
* then %GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE is returned.
**/
int
gnutls_x509_crt_get_subject_alt_othername_oid (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_subject_alt_othername_oid (MHD_gnutls_x509_crt_t cert,
unsigned int seq,
void *ret, size_t * ret_size)
{
@@ -1258,8 +1258,8 @@ gnutls_x509_crt_get_subject_alt_othername_oid (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_basic_constraints - This function returns the certificate basic constraints
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_basic_constraints - This function returns the certificate basic constraints
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @critical: will be non zero if the extension is marked as critical
* @ca: pointer to output integer indicating CA status, may be NULL,
* value is 1 if the certificate CA flag is set, 0 otherwise.
@@ -1278,21 +1278,21 @@ gnutls_x509_crt_get_subject_alt_othername_oid (gnutls_x509_crt_t cert,
* GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE will be returned.
**/
int
gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_basic_constraints (MHD_gnutls_x509_crt_t cert,
unsigned int *critical,
int *ca, int *pathlen)
{
int result;
gnutls_datum_t basicConstraints;
MHD_gnutls_datum_t basicConstraints;
int tmp_ca;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if ((result = _gnutls_x509_crt_get_extension (cert, "2.5.29.19", 0,
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.19", 0,
&basicConstraints, critical))
< 0)
{
@@ -1301,20 +1301,20 @@ gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
if (basicConstraints.size == 0 || basicConstraints.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
}
result = _gnutls_x509_ext_extract_basicConstraints (&tmp_ca, pathlen,
result = MHD__gnutls_x509_ext_extract_basicConstraints (&tmp_ca, pathlen,
basicConstraints.data,
basicConstraints.size);
if (ca)
*ca = tmp_ca;
_gnutls_free_datum (&basicConstraints);
MHD__gnutls_free_datum (&basicConstraints);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -1322,8 +1322,8 @@ gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_ca_status - This function returns the certificate CA status
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_ca_status - This function returns the certificate CA status
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @critical: will be non zero if the extension is marked as critical
*
* This function will return certificates CA status, by reading the
@@ -1331,7 +1331,7 @@ gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
* a CA a positive value will be returned, or zero if the certificate
* does not have CA flag set.
*
* Use gnutls_x509_crt_get_basic_constraints() if you want to read the
* Use MHD_gnutls_x509_crt_get_basic_constraints() if you want to read the
* pathLenConstraint field too.
*
* A negative value may be returned in case of parsing error.
@@ -1340,16 +1340,16 @@ gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert, unsigned int *critical)
MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert, unsigned int *critical)
{
int ca, pathlen;
return gnutls_x509_crt_get_basic_constraints (cert, critical, &ca,
return MHD_gnutls_x509_crt_get_basic_constraints (cert, critical, &ca,
&pathlen);
}
/**
* gnutls_x509_crt_get_key_usage - This function returns the certificate's key usage
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_key_usage - This function returns the certificate's key usage
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @key_usage: where the key usage bits will be stored
* @critical: will be non zero if the extension is marked as critical
*
@@ -1367,22 +1367,22 @@ gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert, unsigned int *critical)
*
**/
int
gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
unsigned int *key_usage,
unsigned int *critical)
{
int result;
gnutls_datum_t keyUsage;
MHD_gnutls_datum_t keyUsage;
uint16_t _usage;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if ((result =
_gnutls_x509_crt_get_extension (cert, "2.5.29.15", 0, &keyUsage,
MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.15", 0, &keyUsage,
critical)) < 0)
{
return result;
@@ -1390,19 +1390,19 @@ gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
if (keyUsage.size == 0 || keyUsage.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
}
result = _gnutls_x509_ext_extract_keyUsage (&_usage, keyUsage.data,
result = MHD__gnutls_x509_ext_extract_keyUsage (&_usage, keyUsage.data,
keyUsage.size);
_gnutls_free_datum (&keyUsage);
MHD__gnutls_free_datum (&keyUsage);
*key_usage = _usage;
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -1410,8 +1410,8 @@ gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_proxy - This function returns the proxy certificate info
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_proxy - This function returns the proxy certificate info
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @critical: will be non zero if the extension is marked as critical
* @pathlen: pointer to output integer indicating path length (may be
* NULL), non-negative values indicate a present pCPathLenConstraint
@@ -1428,22 +1428,22 @@ gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
* GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE will be returned.
**/
int
gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_proxy (MHD_gnutls_x509_crt_t cert,
unsigned int *critical,
int *pathlen,
char **policyLanguage,
char **policy, size_t * sizeof_policy)
{
int result;
gnutls_datum_t proxyCertInfo;
MHD_gnutls_datum_t proxyCertInfo;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if ((result = _gnutls_x509_crt_get_extension (cert, "1.3.6.1.5.5.7.1.14", 0,
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "1.3.6.1.5.5.7.1.14", 0,
&proxyCertInfo,
critical)) < 0)
{
@@ -1452,18 +1452,18 @@ gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
if (proxyCertInfo.size == 0 || proxyCertInfo.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
}
result = _gnutls_x509_ext_extract_proxyCertInfo (pathlen, policyLanguage,
result = MHD__gnutls_x509_ext_extract_proxyCertInfo (pathlen, policyLanguage,
policy, sizeof_policy,
proxyCertInfo.data,
proxyCertInfo.size);
_gnutls_free_datum (&proxyCertInfo);
MHD__gnutls_free_datum (&proxyCertInfo);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -1471,8 +1471,8 @@ gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_extension_by_oid - This function returns the specified extension
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_extension_by_oid - This function returns the specified extension
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @oid: holds an Object Identified in null terminated string
* @indx: In case multiple same OIDs exist in the extensions, this specifies which to send. Use zero to get the first one.
* @buf: a pointer to a structure to hold the name (may be null)
@@ -1489,7 +1489,7 @@ gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_extension_by_oid (MHD_gnutls_x509_crt_t cert,
const char *oid,
int indx,
void *buf,
@@ -1497,31 +1497,31 @@ gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
unsigned int *critical)
{
int result;
gnutls_datum_t output;
MHD_gnutls_datum_t output;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if ((result = _gnutls_x509_crt_get_extension (cert, oid, indx, &output,
if ((result = MHD__gnutls_x509_crt_get_extension (cert, oid, indx, &output,
critical)) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
if (output.size == 0 || output.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
}
if (output.size > (unsigned int) *sizeof_buf)
{
*sizeof_buf = output.size;
_gnutls_free_datum (&output);
MHD__gnutls_free_datum (&output);
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
@@ -1530,15 +1530,15 @@ gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
if (buf)
memcpy (buf, output.data, output.size);
_gnutls_free_datum (&output);
MHD__gnutls_free_datum (&output);
return 0;
}
/**
* gnutls_x509_crt_get_extension_oid - This function returns the specified extension OID
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_extension_oid - This function returns the specified extension OID
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @indx: Specifies which extension OID to send. Use zero to get the first one.
* @oid: a pointer to a structure to hold the OID (may be null)
* @sizeof_oid: initially holds the size of @oid
@@ -1552,18 +1552,18 @@ gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
int indx, void *oid, size_t * sizeof_oid)
{
int result;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
result = _gnutls_x509_crt_get_extension_oid (cert, indx, oid, sizeof_oid);
result = MHD__gnutls_x509_crt_get_extension_oid (cert, indx, oid, sizeof_oid);
if (result < 0)
{
return result;
@@ -1574,8 +1574,8 @@ gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_extension_info - Get extension id and criticality
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_extension_info - Get extension id and criticality
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @indx: Specifies which extension OID to send. Use zero to get the first one.
* @oid: a pointer to a structure to hold the OID
* @sizeof_oid: initially holds the size of @oid
@@ -1584,7 +1584,7 @@ gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
* This function will return the requested extension OID in the
* certificate, and the critical flag for it. The extension OID will
* be stored as a string in the provided buffer. Use
* gnutls_x509_crt_get_extension_data() to extract the data.
* MHD_gnutls_x509_crt_get_extension_data() to extract the data.
*
* Return 0 on success. A negative value may be returned in case of
* parsing error. If you have reached the last extension available
@@ -1592,7 +1592,7 @@ gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_extension_info (MHD_gnutls_x509_crt_t cert,
int indx,
void *oid,
size_t * sizeof_oid, int *critical)
@@ -1604,7 +1604,7 @@ gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
if (!cert)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -1612,25 +1612,25 @@ gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
indx + 1);
len = *sizeof_oid;
result = asn1_read_value (cert->cert, name, oid, &len);
result = MHD__asn1_read_value (cert->cert, name, oid, &len);
*sizeof_oid = len;
if (result == ASN1_ELEMENT_NOT_FOUND)
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
else if (result < 0)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
snprintf (name, sizeof (name), "tbsCertificate.extensions.?%u.critical",
indx + 1);
len = sizeof (str_critical);
result = asn1_read_value (cert->cert, name, str_critical, &len);
result = MHD__asn1_read_value (cert->cert, name, str_critical, &len);
if (result < 0)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
if (critical)
@@ -1646,8 +1646,8 @@ gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_extension_data - Get the specified extension data
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_extension_data - Get the specified extension data
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @indx: Specifies which extension OID to send. Use zero to get the first one.
* @data: a pointer to a structure to hold the data (may be null)
* @sizeof_data: initially holds the size of @oid
@@ -1656,8 +1656,8 @@ gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
* certificate. The extension data will be stored as a string in the
* provided buffer.
*
* Use gnutls_x509_crt_get_extension_info() to extract the OID and
* critical flag. Use gnutls_x509_crt_get_extension_by_oid() instead,
* Use MHD_gnutls_x509_crt_get_extension_info() to extract the OID and
* critical flag. Use MHD_gnutls_x509_crt_get_extension_by_oid() instead,
* if you want to get data indexed by the extension OID rather than
* sequence.
*
@@ -1666,7 +1666,7 @@ gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
* GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE will be returned.
**/
int
gnutls_x509_crt_get_extension_data (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_extension_data (MHD_gnutls_x509_crt_t cert,
int indx,
void *data, size_t * sizeof_data)
{
@@ -1675,7 +1675,7 @@ gnutls_x509_crt_get_extension_data (gnutls_x509_crt_t cert,
if (!cert)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -1683,82 +1683,82 @@ gnutls_x509_crt_get_extension_data (gnutls_x509_crt_t cert,
indx + 1);
len = *sizeof_data;
result = asn1_read_value (cert->cert, name, data, &len);
result = MHD__asn1_read_value (cert->cert, name, data, &len);
*sizeof_data = len;
if (result == ASN1_ELEMENT_NOT_FOUND)
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
else if (result < 0)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
}
static int
_gnutls_x509_crt_get_raw_dn2 (gnutls_x509_crt_t cert,
const char *whom, gnutls_datum_t * start)
MHD__gnutls_x509_crt_get_raw_dn2 (MHD_gnutls_x509_crt_t cert,
const char *whom, MHD_gnutls_datum_t * start)
{
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
int result, len1;
int start1, end1;
gnutls_datum_t signed_data = { NULL,
MHD_gnutls_datum_t signed_data = { NULL,
0
};
/* get the issuer of 'cert'
*/
if ((result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.TBSCertificate",
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.TBSCertificate",
&c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = _gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
result = MHD__gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
&signed_data);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = asn1_der_decoding (&c2, signed_data.data, signed_data.size, NULL);
result = MHD__asn1_der_decoding (&c2, signed_data.data, signed_data.size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
result = MHD_gtls_asn2err (result);
goto cleanup;
}
result = asn1_der_decoding_startEnd (c2, signed_data.data, signed_data.size,
result = MHD__asn1_der_decoding_startEnd (c2, signed_data.data, signed_data.size,
whom, &start1, &end1);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
len1 = end1 - start1 + 1;
_gnutls_set_datum (start, &signed_data.data[start1], len1);
MHD__gnutls_set_datum (start, &signed_data.data[start1], len1);
result = 0;
cleanup:asn1_delete_structure (&c2);
_gnutls_free_datum (&signed_data);
cleanup:MHD__asn1_delete_structure (&c2);
MHD__gnutls_free_datum (&signed_data);
return result;
}
/**
* gnutls_x509_crt_get_raw_issuer_dn - This function returns the issuer's DN DER encoded
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_raw_issuer_dn - This function returns the issuer's DN DER encoded
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @start: will hold the starting point of the DN
*
* This function will return a pointer to the DER encoded DN structure
@@ -1768,15 +1768,15 @@ cleanup:asn1_delete_structure (&c2);
*
**/
int
gnutls_x509_crt_get_raw_issuer_dn (gnutls_x509_crt_t cert,
gnutls_datum_t * start)
MHD_gnutls_x509_crt_get_raw_issuer_dn (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_datum_t * start)
{
return _gnutls_x509_crt_get_raw_dn2 (cert, "issuer", start);
return MHD__gnutls_x509_crt_get_raw_dn2 (cert, "issuer", start);
}
/**
* gnutls_x509_crt_get_raw_dn - This function returns the subject's DN DER encoded
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_raw_dn - This function returns the subject's DN DER encoded
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @start: will hold the starting point of the DN
*
* This function will return a pointer to the DER encoded DN structure and
@@ -1786,43 +1786,43 @@ gnutls_x509_crt_get_raw_issuer_dn (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crt_get_raw_dn (gnutls_x509_crt_t cert, gnutls_datum_t * start)
MHD_gnutls_x509_crt_get_raw_dn (MHD_gnutls_x509_crt_t cert, MHD_gnutls_datum_t * start)
{
return _gnutls_x509_crt_get_raw_dn2 (cert, "subject", start);
return MHD__gnutls_x509_crt_get_raw_dn2 (cert, "subject", start);
}
static int
get_dn (gnutls_x509_crt_t cert, const char *whom, gnutls_x509_dn_t * dn)
get_dn (MHD_gnutls_x509_crt_t cert, const char *whom, MHD_gnutls_x509_dn_t * dn)
{
*dn = asn1_find_node (cert->cert, whom);
*dn = MHD__asn1_find_node (cert->cert, whom);
if (!*dn)
return GNUTLS_E_ASN1_ELEMENT_NOT_FOUND;
return 0;
}
/**
* gnutls_x509_crt_get_subject: get opaque subject DN pointer
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_subject: get opaque subject DN pointer
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @dn: output variable with pointer to opaque DN.
*
* Return the Certificate's Subject DN as an opaque data type. You
* may use gnutls_x509_dn_get_rdn_ava() to decode the DN.
* may use MHD_gnutls_x509_dn_get_rdn_ava() to decode the DN.
*
* Returns: Returns 0 on success, or an error code.
**/
int
gnutls_x509_crt_get_subject (gnutls_x509_crt_t cert, gnutls_x509_dn_t * dn)
MHD_gnutls_x509_crt_get_subject (MHD_gnutls_x509_crt_t cert, MHD_gnutls_x509_dn_t * dn)
{
return get_dn (cert, "tbsCertificate.subject.rdnSequence", dn);
}
/**
* gnutls_x509_crt_get_issuer: get opaque issuer DN pointer
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_issuer: get opaque issuer DN pointer
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @dn: output variable with pointer to opaque DN
*
* Return the Certificate's Issuer DN as an opaque data type. You may
* use gnutls_x509_dn_get_rdn_ava() to decode the DN.
* use MHD_gnutls_x509_dn_get_rdn_ava() to decode the DN.
*
* Note that @dn points into the @cert object, and thus you may not
* deallocate @cert and continue to access @dn.
@@ -1830,13 +1830,13 @@ gnutls_x509_crt_get_subject (gnutls_x509_crt_t cert, gnutls_x509_dn_t * dn)
* Returns: Returns 0 on success, or an error code.
**/
int
gnutls_x509_crt_get_issuer (gnutls_x509_crt_t cert, gnutls_x509_dn_t * dn)
MHD_gnutls_x509_crt_get_issuer (MHD_gnutls_x509_crt_t cert, MHD_gnutls_x509_dn_t * dn)
{
return get_dn (cert, "tbsCertificate.issuer.rdnSequence", dn);
}
/**
* gnutls_x509_dn_get_rdn_ava:
* MHD_gnutls_x509_dn_get_rdn_ava:
* @dn: input variable with opaque DN pointer
* @irdn: index of RDN
* @iava: index of AVA.
@@ -1852,8 +1852,8 @@ gnutls_x509_crt_get_issuer (gnutls_x509_crt_t cert, gnutls_x509_dn_t * dn)
* Returns: Returns 0 on success, or an error code.
**/
int
gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
int irdn, int iava, gnutls_x509_ava_st * ava)
MHD_gnutls_x509_dn_get_rdn_ava (MHD_gnutls_x509_dn_t dn,
int irdn, int iava, MHD_gnutls_x509_ava_st * ava)
{
ASN1_TYPE rdn, elem;
long len;
@@ -1865,18 +1865,18 @@ gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
irdn++; /* 0->1, 1->2 etc */
snprintf (rbuf, sizeof (rbuf), "rdnSequence.?%d.?%d", irdn, iava);
rdn = asn1_find_node (dn, rbuf);
rdn = MHD__asn1_find_node (dn, rbuf);
if (!rdn)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_ASN1_ELEMENT_NOT_FOUND;
}
snprintf (rbuf, sizeof (rbuf), "?%d.type", iava);
elem = asn1_find_node (rdn, rbuf);
elem = MHD__asn1_find_node (rdn, rbuf);
if (!elem)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_ASN1_ELEMENT_NOT_FOUND;
}
@@ -1884,10 +1884,10 @@ gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
ava->oid.size = elem->value_len;
snprintf (rbuf, sizeof (rbuf), "?%d.value", iava);
elem = asn1_find_node (rdn, rbuf);
elem = MHD__asn1_find_node (rdn, rbuf);
if (!elem)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_ASN1_ELEMENT_NOT_FOUND;
}
@@ -1897,34 +1897,34 @@ gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
ptr = elem->value;
remlen = elem->value_len;
len = asn1_get_length_der (ptr, remlen, &lenlen);
len = MHD__asn1_get_length_der (ptr, remlen, &lenlen);
if (len < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_ASN1_DER_ERROR;
}
ptr += lenlen;
remlen -= lenlen;
ret = asn1_get_tag_der (ptr, remlen, &cls, &lenlen, &ava->value_tag);
ret = MHD__asn1_get_tag_der (ptr, remlen, &cls, &lenlen, &ava->value_tag);
if (ret)
{
gnutls_assert ();
return mhd_gtls_asn2err (ret);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (ret);
}
ptr += lenlen;
remlen -= lenlen;
ava->value.size = asn1_get_length_der (ptr, remlen, &lenlen);
ava->value.size = MHD__asn1_get_length_der (ptr, remlen, &lenlen);
ava->value.data = ptr + lenlen;
return 0;
}
/**
* gnutls_x509_crt_get_fingerprint - This function returns the Certificate's fingerprint
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_fingerprint - This function returns the Certificate's fingerprint
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @algo: is a digest algorithm
* @buf: a pointer to a structure to hold the fingerprint (may be null)
* @sizeof_buf: initially holds the size of @buf
@@ -1939,14 +1939,14 @@ gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
* with the required size. On success 0 is returned.
**/
int
gnutls_x509_crt_get_fingerprint (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_fingerprint (MHD_gnutls_x509_crt_t cert,
enum MHD_GNUTLS_HashAlgorithm algo,
void *buf, size_t * sizeof_buf)
{
opaque *cert_buf;
int cert_buf_size;
int result;
gnutls_datum_t tmp;
MHD_gnutls_datum_t tmp;
if (sizeof_buf == 0 || cert == NULL)
{
@@ -1954,35 +1954,35 @@ gnutls_x509_crt_get_fingerprint (gnutls_x509_crt_t cert,
}
cert_buf_size = 0;
asn1_der_coding (cert->cert, "", NULL, &cert_buf_size, NULL);
MHD__asn1_der_coding (cert->cert, "", NULL, &cert_buf_size, NULL);
cert_buf = gnutls_alloca (cert_buf_size);
cert_buf = MHD_gnutls_alloca (cert_buf_size);
if (cert_buf == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
result = asn1_der_coding (cert->cert, "", cert_buf, &cert_buf_size, NULL);
result = MHD__asn1_der_coding (cert->cert, "", cert_buf, &cert_buf_size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
gnutls_afree (cert_buf);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD_gnutls_afree (cert_buf);
return MHD_gtls_asn2err (result);
}
tmp.data = cert_buf;
tmp.size = cert_buf_size;
result = MHD_gnutls_fingerprint (algo, &tmp, buf, sizeof_buf);
gnutls_afree (cert_buf);
result = MHD__gnutls_fingerprint (algo, &tmp, buf, sizeof_buf);
MHD_gnutls_afree (cert_buf);
return result;
}
/**
* gnutls_x509_crt_export - This function will export the certificate
* MHD_gnutls_x509_crt_export - This function will export the certificate
* @cert: Holds the certificate
* @format: the format of output params. One of PEM or DER.
* @output_data: will contain a certificate PEM or DER encoded
@@ -2002,82 +2002,82 @@ gnutls_x509_crt_get_fingerprint (gnutls_x509_crt_t cert,
* returned, and 0 on success.
**/
int
gnutls_x509_crt_export (gnutls_x509_crt_t cert,
gnutls_x509_crt_fmt_t format,
MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_fmt_t format,
void *output_data, size_t * output_data_size)
{
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
return _gnutls_x509_export_int (cert->cert, format, "CERTIFICATE",
return MHD__gnutls_x509_export_int (cert->cert, format, "CERTIFICATE",
output_data, output_data_size);
}
static int
rsadsa_get_key_id (gnutls_x509_crt_t crt,
rsadsa_get_key_id (MHD_gnutls_x509_crt_t crt,
int pk,
unsigned char *output_data, size_t * output_data_size)
{
mpi_t params[MAX_PUBLIC_PARAMS_SIZE];
int params_size = MAX_PUBLIC_PARAMS_SIZE;
int i, result = 0;
gnutls_datum_t der = { NULL,
MHD_gnutls_datum_t der = { NULL,
0
};
GNUTLS_HASH_HANDLE hd;
result = _gnutls_x509_crt_get_mpis (crt, params, &params_size);
result = MHD__gnutls_x509_crt_get_mpis (crt, params, &params_size);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
if (pk == MHD_GNUTLS_PK_RSA)
{
result = _gnutls_x509_write_rsa_params (params, params_size, &der);
result = MHD__gnutls_x509_write_rsa_params (params, params_size, &der);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
}
else
return GNUTLS_E_INTERNAL_ERROR;
hd = mhd_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
hd = MHD_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
if (hd == GNUTLS_HASH_FAILED)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_INTERNAL_ERROR;
goto cleanup;
}
mhd_gnutls_hash (hd, der.data, der.size);
MHD_gnutls_hash (hd, der.data, der.size);
mhd_gnutls_hash_deinit (hd, output_data);
MHD_gnutls_hash_deinit (hd, output_data);
*output_data_size = 20;
result = 0;
cleanup:
_gnutls_free_datum (&der);
MHD__gnutls_free_datum (&der);
/* release all allocated MPIs
*/
for (i = 0; i < params_size; i++)
{
mhd_gtls_mpi_release (&params[i]);
MHD_gtls_mpi_release (&params[i]);
}
return result;
}
/**
* gnutls_x509_crt_get_key_id - Return unique ID of public key's parameters
* MHD_gnutls_x509_crt_get_key_id - Return unique ID of public key's parameters
* @crt: Holds the certificate
* @flags: should be 0 for now
* @output_data: will contain the key ID
@@ -2097,31 +2097,31 @@ cleanup:
* returned, and 0 on success.
**/
int
gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
MHD_gnutls_x509_crt_get_key_id (MHD_gnutls_x509_crt_t crt,
unsigned int flags,
unsigned char *output_data,
size_t * output_data_size)
{
int pk, result = 0;
gnutls_datum_t pubkey;
MHD_gnutls_datum_t pubkey;
if (crt == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (*output_data_size < 20)
{
gnutls_assert ();
MHD_gnutls_assert ();
*output_data_size = 20;
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
pk = gnutls_x509_crt_get_pk_algorithm (crt, NULL);
pk = MHD_gnutls_x509_crt_get_pk_algorithm (crt, NULL);
if (pk < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return pk;
}
@@ -2136,34 +2136,34 @@ gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
}
pubkey.size = 0;
result = asn1_der_coding (crt->cert, "tbsCertificate.subjectPublicKeyInfo",
result = MHD__asn1_der_coding (crt->cert, "tbsCertificate.subjectPublicKeyInfo",
NULL, &pubkey.size, NULL);
if (result != ASN1_MEM_ERROR)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
pubkey.data = gnutls_alloca (pubkey.size);
pubkey.data = MHD_gnutls_alloca (pubkey.size);
if (pubkey.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
result = asn1_der_coding (crt->cert, "tbsCertificate.subjectPublicKeyInfo",
result = MHD__asn1_der_coding (crt->cert, "tbsCertificate.subjectPublicKeyInfo",
pubkey.data, &pubkey.size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
gnutls_afree (pubkey.data);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD_gnutls_afree (pubkey.data);
return MHD_gtls_asn2err (result);
}
result = MHD_gnutls_fingerprint (MHD_GNUTLS_MAC_SHA1, &pubkey, output_data,
result = MHD__gnutls_fingerprint (MHD_GNUTLS_MAC_SHA1, &pubkey, output_data,
output_data_size);
gnutls_afree (pubkey.data);
MHD_gnutls_afree (pubkey.data);
return result;
}
@@ -2171,9 +2171,9 @@ gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
#ifdef ENABLE_PKI
/**
* gnutls_x509_crt_check_revocation - This function checks if the given certificate is revoked
* @cert: should contain a gnutls_x509_crt_t structure
* @crl_list: should contain a list of gnutls_x509_crl_t structures
* MHD_gnutls_x509_crt_check_revocation - This function checks if the given certificate is revoked
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @crl_list: should contain a list of MHD_gnutls_x509_crl_t structures
* @crl_list_length: the length of the crl_list
*
* This function will return check if the given certificate is
@@ -2183,19 +2183,19 @@ gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
* negative value is returned on error.
**/
int
gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
const gnutls_x509_crl_t * crl_list,
MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_x509_crl_t * crl_list,
int crl_list_length)
{
opaque serial[64];
opaque cert_serial[64];
size_t serial_size, cert_serial_size;
int ncerts, ret, i, j;
gnutls_datum_t dn1, dn2;
MHD_gnutls_datum_t dn1, dn2;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -2204,23 +2204,23 @@ gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
/* Step 1. check if issuer's DN match
*/
ret = _gnutls_x509_crl_get_raw_issuer_dn (crl_list[j], &dn1);
ret = MHD__gnutls_x509_crl_get_raw_issuer_dn (crl_list[j], &dn1);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
ret = gnutls_x509_crt_get_raw_issuer_dn (cert, &dn2);
ret = MHD_gnutls_x509_crt_get_raw_issuer_dn (cert, &dn2);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
ret = _gnutls_x509_compare_raw_dn (&dn1, &dn2);
_gnutls_free_datum (&dn1);
_gnutls_free_datum (&dn2);
ret = MHD__gnutls_x509_compare_raw_dn (&dn1, &dn2);
MHD__gnutls_free_datum (&dn1);
MHD__gnutls_free_datum (&dn2);
if (ret == 0)
{
/* issuers do not match so don't even
@@ -2232,10 +2232,10 @@ gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
/* Step 2. Read the certificate's serial number
*/
cert_serial_size = sizeof (cert_serial);
ret = gnutls_x509_crt_get_serial (cert, cert_serial, &cert_serial_size);
ret = MHD_gnutls_x509_crt_get_serial (cert, cert_serial, &cert_serial_size);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -2243,22 +2243,22 @@ gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
* certificate serial we have.
*/
ncerts = gnutls_x509_crl_get_crt_count (crl_list[j]);
ncerts = MHD_gnutls_x509_crl_get_crt_count (crl_list[j]);
if (ncerts < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ncerts;
}
for (i = 0; i < ncerts; i++)
{
serial_size = sizeof (serial);
ret = gnutls_x509_crl_get_crt_serial (crl_list[j], i, serial,
ret = MHD_gnutls_x509_crl_get_crt_serial (crl_list[j], i, serial,
&serial_size, NULL);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -2277,7 +2277,7 @@ gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_verify_data - This function will verify the given signed data.
* MHD_gnutls_x509_crt_verify_data - This function will verify the given signed data.
* @crt: Holds the certificate
* @flags: should be 0 for now
* @data: holds the data to be signed
@@ -2290,23 +2290,23 @@ gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
* success.
**/
int
gnutls_x509_crt_verify_data (gnutls_x509_crt_t crt,
MHD_gnutls_x509_crt_verify_data (MHD_gnutls_x509_crt_t crt,
unsigned int flags,
const gnutls_datum_t * data,
const gnutls_datum_t * signature)
const MHD_gnutls_datum_t * data,
const MHD_gnutls_datum_t * signature)
{
int result;
if (crt == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
result = _gnutls_x509_verify_signature (data, signature, crt);
result = MHD__gnutls_x509_verify_signature (data, signature, crt);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return 0;
}
@@ -2314,8 +2314,8 @@ gnutls_x509_crt_verify_data (gnutls_x509_crt_t crt,
}
/**
* gnutls_x509_crt_get_crl_dist_points - This function returns the CRL distribution points
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_crl_dist_points - This function returns the CRL distribution points
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @seq: specifies the sequence number of the distribution point (0 for the first one, 1 for the second etc.)
* @ret: is the place where the distribution point will be copied to
* @ret_size: holds the size of ret.
@@ -2342,13 +2342,13 @@ gnutls_x509_crt_verify_data (gnutls_x509_crt_t crt,
* Returns %GNUTLS_E_SHORT_MEMORY_BUFFER and updates &@ret_size if
* &@ret_size is not enough to hold the distribution point, or the
* type of the distribution point if everything was ok. The type is
* one of the enumerated %gnutls_x509_subject_alt_name_t. If the
* one of the enumerated %MHD_gnutls_x509_subject_alt_name_t. If the
* certificate does not have an Alternative name with the specified
* sequence number then %GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE is
* returned.
**/
int
gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_crl_dist_points (MHD_gnutls_x509_crt_t cert,
unsigned int seq,
void *ret,
size_t * ret_size,
@@ -2356,18 +2356,18 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
unsigned int *critical)
{
int result;
gnutls_datum_t dist_points = { NULL,
MHD_gnutls_datum_t dist_points = { NULL,
0
};
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
char name[MAX_NAME_SIZE];
int len;
gnutls_x509_subject_alt_name_t type;
MHD_gnutls_x509_subject_alt_name_t type;
uint8_t reasons[2];
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -2379,7 +2379,7 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
if (reason_flags)
*reason_flags = 0;
result = _gnutls_x509_crt_get_extension (cert, "2.5.29.31", 0, &dist_points,
result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.31", 0, &dist_points,
critical);
if (result < 0)
{
@@ -2388,39 +2388,39 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
if (dist_points.size == 0 || dist_points.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
}
result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.CRLDistributionPoints",
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.CRLDistributionPoints",
&c2);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
_gnutls_free_datum (&dist_points);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (&dist_points);
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&c2, dist_points.data, dist_points.size, NULL);
_gnutls_free_datum (&dist_points);
result = MHD__asn1_der_decoding (&c2, dist_points.data, dist_points.size, NULL);
MHD__gnutls_free_datum (&dist_points);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
return MHD_gtls_asn2err (result);
}
/* Return the different names from the first CRLDistr. point.
* The whole thing is a mess.
*/
mhd_gtls_str_cpy (name, sizeof (name), "?1.distributionPoint.fullName");
MHD_gtls_str_cpy (name, sizeof (name), "?1.distributionPoint.fullName");
result = parse_general_name (c2, name, seq, ret, ret_size, NULL, 0);
if (result < 0)
{
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
return result;
}
@@ -2430,18 +2430,18 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
*/
if (reason_flags)
{
mhd_gtls_str_cpy (name, sizeof (name), "?1.reasons");
MHD_gtls_str_cpy (name, sizeof (name), "?1.reasons");
reasons[0] = reasons[1] = 0;
len = sizeof (reasons);
result = asn1_read_value (c2, name, reasons, &len);
result = MHD__asn1_read_value (c2, name, reasons, &len);
if (result != ASN1_VALUE_NOT_FOUND && result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
return MHD_gtls_asn2err (result);
}
*reason_flags = reasons[0] | (reasons[1] << 8);
@@ -2451,8 +2451,8 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_key_purpose_oid - This function returns the Certificate's key purpose OIDs
* @cert: should contain a gnutls_x509_crt_t structure
* MHD_gnutls_x509_crt_get_key_purpose_oid - This function returns the Certificate's key purpose OIDs
* @cert: should contain a MHD_gnutls_x509_crt_t structure
* @indx: This specifies which OID to return. Use zero to get the first one.
* @oid: a pointer to a buffer to hold the OID (may be null)
* @sizeof_oid: initially holds the size of @oid
@@ -2469,7 +2469,7 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
* with the required size. On success 0 is returned.
**/
int
gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_get_key_purpose_oid (MHD_gnutls_x509_crt_t cert,
int indx,
void *oid,
size_t * sizeof_oid,
@@ -2477,12 +2477,12 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
{
char tmpstr[MAX_NAME_SIZE];
int result, len;
gnutls_datum_t id;
MHD_gnutls_datum_t id;
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
if (cert == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -2491,7 +2491,7 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
else
*sizeof_oid = 0;
if ((result = _gnutls_x509_crt_get_extension (cert, "2.5.29.37", 0, &id,
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.37", 0, &id,
critical)) < 0)
{
return result;
@@ -2499,27 +2499,27 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
if (id.size == 0 || id.data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
}
result =
asn1_create_element (_gnutls_get_pkix (), "PKIX1.ExtKeyUsageSyntax", &c2);
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.ExtKeyUsageSyntax", &c2);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
_gnutls_free_datum (&id);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (&id);
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&c2, id.data, id.size, NULL);
_gnutls_free_datum (&id);
result = MHD__asn1_der_decoding (&c2, id.data, id.size, NULL);
MHD__gnutls_free_datum (&id);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&c2);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&c2);
return MHD_gtls_asn2err (result);
}
indx++;
@@ -2528,10 +2528,10 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
snprintf (tmpstr, sizeof (tmpstr), "?%u", indx);
len = *sizeof_oid;
result = asn1_read_value (c2, tmpstr, oid, &len);
result = MHD__asn1_read_value (c2, tmpstr, oid, &len);
*sizeof_oid = len;
asn1_delete_structure (&c2);
MHD__asn1_delete_structure (&c2);
if (result == ASN1_VALUE_NOT_FOUND || result == ASN1_ELEMENT_NOT_FOUND)
{
@@ -2540,8 +2540,8 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
return 0;
@@ -2549,20 +2549,20 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
}
/**
* gnutls_x509_crt_get_pk_rsa_raw - This function will export the RSA public key
* MHD_gnutls_x509_crt_get_pk_rsa_raw - This function will export the RSA public key
* @crt: Holds the certificate
* @m: will hold the modulus
* @e: will hold the public exponent
*
* This function will export the RSA public key's parameters found in
* the given structure. The new parameters will be allocated using
* gnutls_malloc() and will be stored in the appropriate datum.
* MHD_gnutls_malloc() and will be stored in the appropriate datum.
*
* Returns: %GNUTLS_E_SUCCESS on success, otherwise an error.
**/
int
gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
gnutls_datum_t * m, gnutls_datum_t * e)
MHD_gnutls_x509_crt_get_pk_rsa_raw (MHD_gnutls_x509_crt_t crt,
MHD_gnutls_datum_t * m, MHD_gnutls_datum_t * e)
{
int ret;
mpi_t params[MAX_PUBLIC_PARAMS_SIZE];
@@ -2571,36 +2571,36 @@ gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
if (crt == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
ret = gnutls_x509_crt_get_pk_algorithm (crt, NULL);
ret = MHD_gnutls_x509_crt_get_pk_algorithm (crt, NULL);
if (ret != MHD_GNUTLS_PK_RSA)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
ret = _gnutls_x509_crt_get_mpis (crt, params, &params_size);
ret = MHD__gnutls_x509_crt_get_mpis (crt, params, &params_size);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
ret = mhd_gtls_mpi_dprint (m, params[0]);
ret = MHD_gtls_mpi_dprint (m, params[0]);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
ret = mhd_gtls_mpi_dprint (e, params[1]);
ret = MHD_gtls_mpi_dprint (e, params[1]);
if (ret < 0)
{
gnutls_assert ();
_gnutls_free_datum (m);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (m);
goto cleanup;
}
@@ -2608,13 +2608,13 @@ gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
cleanup:for (i = 0; i < params_size; i++)
{
mhd_gtls_mpi_release (&params[i]);
MHD_gtls_mpi_release (&params[i]);
}
return ret;
}
/**
* gnutls_x509_crt_get_pk_dsa_raw - This function will export the DSA public key
* MHD_gnutls_x509_crt_get_pk_dsa_raw - This function will export the DSA public key
* @crt: Holds the certificate
* @p: will hold the p
* @q: will hold the q
@@ -2623,15 +2623,15 @@ cleanup:for (i = 0; i < params_size; i++)
*
* This function will export the DSA public key's parameters found in
* the given certificate. The new parameters will be allocated using
* gnutls_malloc() and will be stored in the appropriate datum.
* MHD_gnutls_malloc() and will be stored in the appropriate datum.
*
* Returns: %GNUTLS_E_SUCCESS on success, otherwise an error.
**/
int
gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
gnutls_datum_t * p,
gnutls_datum_t * q,
gnutls_datum_t * g, gnutls_datum_t * y)
MHD_gnutls_x509_crt_get_pk_dsa_raw (MHD_gnutls_x509_crt_t crt,
MHD_gnutls_datum_t * p,
MHD_gnutls_datum_t * q,
MHD_gnutls_datum_t * g, MHD_gnutls_datum_t * y)
{
int ret;
mpi_t params[MAX_PUBLIC_PARAMS_SIZE];
@@ -2640,54 +2640,54 @@ gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
if (crt == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
ret = gnutls_x509_crt_get_pk_algorithm (crt, NULL);
ret = MHD_gnutls_x509_crt_get_pk_algorithm (crt, NULL);
ret = _gnutls_x509_crt_get_mpis (crt, params, &params_size);
ret = MHD__gnutls_x509_crt_get_mpis (crt, params, &params_size);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
/* P */
ret = mhd_gtls_mpi_dprint (p, params[0]);
ret = MHD_gtls_mpi_dprint (p, params[0]);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
/* Q */
ret = mhd_gtls_mpi_dprint (q, params[1]);
ret = MHD_gtls_mpi_dprint (q, params[1]);
if (ret < 0)
{
gnutls_assert ();
_gnutls_free_datum (p);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (p);
goto cleanup;
}
/* G */
ret = mhd_gtls_mpi_dprint (g, params[2]);
ret = MHD_gtls_mpi_dprint (g, params[2]);
if (ret < 0)
{
gnutls_assert ();
_gnutls_free_datum (p);
_gnutls_free_datum (q);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (p);
MHD__gnutls_free_datum (q);
goto cleanup;
}
/* Y */
ret = mhd_gtls_mpi_dprint (y, params[3]);
ret = MHD_gtls_mpi_dprint (y, params[3]);
if (ret < 0)
{
gnutls_assert ();
_gnutls_free_datum (p);
_gnutls_free_datum (g);
_gnutls_free_datum (q);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (p);
MHD__gnutls_free_datum (g);
MHD__gnutls_free_datum (q);
goto cleanup;
}
@@ -2695,7 +2695,7 @@ gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
cleanup:for (i = 0; i < params_size; i++)
{
mhd_gtls_mpi_release (&params[i]);
MHD_gtls_mpi_release (&params[i]);
}
return ret;
@@ -2704,15 +2704,15 @@ cleanup:for (i = 0; i < params_size; i++)
#endif
/**
* gnutls_x509_crt_list_import - This function will import a PEM encoded certificate list
* MHD_gnutls_x509_crt_list_import - This function will import a PEM encoded certificate list
* @certs: The structures to store the parsed certificate. Must not be initialized.
* @cert_max: Initially must hold the maximum number of certs. It will be updated with the number of certs available.
* @data: The PEM encoded certificate.
* @format: One of DER or PEM.
* @flags: must be zero or an OR'd sequence of gnutls_certificate_import_flags.
* @flags: must be zero or an OR'd sequence of MHD_gnutls_certificate_import_flags.
*
* This function will convert the given PEM encoded certificate list
* to the native gnutls_x509_crt_t format. The output will be stored
* to the native MHD_gnutls_x509_crt_t format. The output will be stored
* in @certs. They will be automatically initialized.
*
* If the Certificate is PEM encoded it should have a header of "X509
@@ -2721,14 +2721,14 @@ cleanup:for (i = 0; i < params_size; i++)
* Returns: the number of certificates read or a negative error value.
**/
int
gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
MHD_gnutls_x509_crt_list_import (MHD_gnutls_x509_crt_t * certs,
unsigned int *cert_max,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format, unsigned int flags)
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format, unsigned int flags)
{
int size;
const char *ptr;
gnutls_datum_t tmp;
MHD_gnutls_datum_t tmp;
int ret, nocopy = 0;
unsigned int count = 0, j;
@@ -2742,17 +2742,17 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
count = 1; /* import only the first one */
ret = gnutls_x509_crt_init (&certs[0]);
ret = MHD_gnutls_x509_crt_init (&certs[0]);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
ret = gnutls_x509_crt_import (certs[0], data, format);
ret = MHD_gnutls_x509_crt_import (certs[0], data, format);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
@@ -2762,15 +2762,15 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
/* move to the certificate
*/
ptr = memmem (data->data, data->size,
ptr = MHD_memmem (data->data, data->size,
PEM_CERT_SEP, sizeof (PEM_CERT_SEP) - 1);
if (ptr == NULL)
ptr = memmem (data->data, data->size,
ptr = MHD_memmem (data->data, data->size,
PEM_CERT_SEP2, sizeof (PEM_CERT_SEP2) - 1);
if (ptr == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_BASE64_DECODING_ERROR;
}
size = data->size - (ptr - (char *) data->data);
@@ -2789,10 +2789,10 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
if (!nocopy)
{
ret = gnutls_x509_crt_init (&certs[count]);
ret = MHD_gnutls_x509_crt_init (&certs[count]);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
@@ -2800,10 +2800,10 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
tmp.size = size;
ret =
gnutls_x509_crt_import (certs[count], &tmp, GNUTLS_X509_FMT_PEM);
MHD_gnutls_x509_crt_import (certs[count], &tmp, GNUTLS_X509_FMT_PEM);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
}
@@ -2819,10 +2819,10 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
{
char *ptr2;
ptr2 = memmem (ptr, size, PEM_CERT_SEP, sizeof (PEM_CERT_SEP) - 1);
ptr2 = MHD_memmem (ptr, size, PEM_CERT_SEP, sizeof (PEM_CERT_SEP) - 1);
if (ptr2 == NULL)
ptr2 =
memmem (ptr, size, PEM_CERT_SEP2, sizeof (PEM_CERT_SEP2) - 1);
MHD_memmem (ptr, size, PEM_CERT_SEP2, sizeof (PEM_CERT_SEP2) - 1);
ptr = ptr2;
}
@@ -2841,6 +2841,6 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
return GNUTLS_E_SHORT_MEMORY_BUFFER;
error:for (j = 0; j < count; j++)
gnutls_x509_crt_deinit (certs[j]);
MHD_gnutls_x509_crt_deinit (certs[j]);
return ret;
}
+317 -317
View File
@@ -78,67 +78,67 @@ extern "C"
/* Certificate handling functions.
*/
typedef enum gnutls_certificate_import_flags
typedef enum MHD_gnutls_certificate_import_flags
{
/* Fail if the certificates in the buffer are more than the space
* allocated for certificates. The error code will be
* GNUTLS_E_SHORT_MEMORY_BUFFER.
*/
GNUTLS_X509_CRT_LIST_IMPORT_FAIL_IF_EXCEED = 1
} gnutls_certificate_import_flags;
} MHD_gnutls_certificate_import_flags;
int gnutls_x509_crt_init (gnutls_x509_crt_t * cert);
void gnutls_x509_crt_deinit (gnutls_x509_crt_t cert);
int gnutls_x509_crt_import (gnutls_x509_crt_t cert,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format);
int gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
int MHD_gnutls_x509_crt_init (MHD_gnutls_x509_crt_t * cert);
void MHD_gnutls_x509_crt_deinit (MHD_gnutls_x509_crt_t cert);
int MHD_gnutls_x509_crt_import (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format);
int MHD_gnutls_x509_crt_list_import (MHD_gnutls_x509_crt_t * certs,
unsigned int *cert_max,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format,
unsigned int flags);
int gnutls_x509_crt_export (gnutls_x509_crt_t cert,
gnutls_x509_crt_fmt_t format,
int MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_fmt_t format,
void *output_data, size_t * output_data_size);
int gnutls_x509_crt_get_issuer_dn (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_issuer_dn (MHD_gnutls_x509_crt_t cert,
char *buf, size_t * sizeof_buf);
int gnutls_x509_crt_get_issuer_dn_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_issuer_dn_oid (MHD_gnutls_x509_crt_t cert,
int indx,
void *oid, size_t * sizeof_oid);
int gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_issuer_dn_by_oid (MHD_gnutls_x509_crt_t cert,
const char *oid,
int indx,
unsigned int raw_flag,
void *buf, size_t * sizeof_buf);
int gnutls_x509_crt_get_dn (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_dn (MHD_gnutls_x509_crt_t cert,
char *buf, size_t * sizeof_buf);
int gnutls_x509_crt_get_dn_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_dn_oid (MHD_gnutls_x509_crt_t cert,
int indx, void *oid, size_t * sizeof_oid);
int gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_dn_by_oid (MHD_gnutls_x509_crt_t cert,
const char *oid,
int indx,
unsigned int raw_flag,
void *buf, size_t * sizeof_buf);
int gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_check_hostname (MHD_gnutls_x509_crt_t cert,
const char *hostname);
int gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert);
int gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert);
int MHD_gnutls_x509_crt_get_signature (MHD_gnutls_x509_crt_t cert,
char *sig, size_t * sizeof_sig);
int gnutls_x509_crt_get_version (gnutls_x509_crt_t cert);
int gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
int MHD_gnutls_x509_crt_get_version (MHD_gnutls_x509_crt_t cert);
int MHD_gnutls_x509_crt_get_key_id (MHD_gnutls_x509_crt_t crt,
unsigned int flags,
unsigned char *output_data,
size_t * output_data_size);
int gnutls_x509_crt_set_authority_key_id (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_set_authority_key_id (MHD_gnutls_x509_crt_t cert,
const void *id, size_t id_size);
int gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_authority_key_id (MHD_gnutls_x509_crt_t cert,
void *ret,
size_t * ret_size,
unsigned int *critical);
int gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_subject_key_id (MHD_gnutls_x509_crt_t cert,
void *ret,
size_t * ret_size,
unsigned int *critical);
@@ -153,79 +153,79 @@ extern "C"
#define GNUTLS_CRL_REASON_PRIVILEGE_WITHDRAWN 1
#define GNUTLS_CRL_REASON_AA_COMPROMISE 32768
int gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_crl_dist_points (MHD_gnutls_x509_crt_t cert,
unsigned int seq,
void *ret,
size_t * ret_size,
unsigned int *reason_flags,
unsigned int *critical);
int gnutls_x509_crt_set_crl_dist_points (gnutls_x509_crt_t crt,
gnutls_x509_subject_alt_name_t
int MHD_gnutls_x509_crt_set_crl_dist_points (MHD_gnutls_x509_crt_t crt,
MHD_gnutls_x509_subject_alt_name_t
type,
const void *data_string,
unsigned int reason_flags);
int gnutls_x509_crt_cpy_crl_dist_points (gnutls_x509_crt_t dst,
gnutls_x509_crt_t src);
int MHD_gnutls_x509_crt_cpy_crl_dist_points (MHD_gnutls_x509_crt_t dst,
MHD_gnutls_x509_crt_t src);
time_t gnutls_x509_crt_get_activation_time (gnutls_x509_crt_t cert);
time_t gnutls_x509_crt_get_expiration_time (gnutls_x509_crt_t cert);
int gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
time_t MHD_gnutls_x509_crt_get_activation_time (MHD_gnutls_x509_crt_t cert);
time_t MHD_gnutls_x509_crt_get_expiration_time (MHD_gnutls_x509_crt_t cert);
int MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
void *result, size_t * result_size);
int gnutls_x509_crt_get_pk_algorithm (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert,
unsigned int *bits);
int gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
gnutls_datum_t * m, gnutls_datum_t * e);
int gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
gnutls_datum_t * p,
gnutls_datum_t * q,
gnutls_datum_t * g, gnutls_datum_t * y);
int MHD_gnutls_x509_crt_get_pk_rsa_raw (MHD_gnutls_x509_crt_t crt,
MHD_gnutls_datum_t * m, MHD_gnutls_datum_t * e);
int MHD_gnutls_x509_crt_get_pk_dsa_raw (MHD_gnutls_x509_crt_t crt,
MHD_gnutls_datum_t * p,
MHD_gnutls_datum_t * q,
MHD_gnutls_datum_t * g, MHD_gnutls_datum_t * y);
int gnutls_x509_crt_get_subject_alt_name (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
unsigned int seq,
void *ret,
size_t * ret_size,
unsigned int *critical);
int gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_subject_alt_name2 (MHD_gnutls_x509_crt_t cert,
unsigned int seq,
void *ret,
size_t * ret_size,
unsigned int *ret_type,
unsigned int *critical);
int gnutls_x509_crt_get_subject_alt_othername_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_subject_alt_othername_oid (MHD_gnutls_x509_crt_t cert,
unsigned int seq,
void *ret,
size_t * ret_size);
int gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert,
unsigned int *critical);
int gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_basic_constraints (MHD_gnutls_x509_crt_t cert,
unsigned int *critical,
int *ca, int *pathlen);
/* The key_usage flags are defined in gnutls.h. They are the
* GNUTLS_KEY_* definitions.
*/
int gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
unsigned int *key_usage,
unsigned int *critical);
int gnutls_x509_crt_set_key_usage (gnutls_x509_crt_t crt,
int MHD_gnutls_x509_crt_set_key_usage (MHD_gnutls_x509_crt_t crt,
unsigned int usage);
int gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_proxy (MHD_gnutls_x509_crt_t cert,
unsigned int *critical,
int *pathlen,
char **policyLanguage,
char **policy, size_t * sizeof_policy);
int gnutls_x509_dn_oid_known (const char *oid);
int MHD_gnutls_x509_dn_oid_known (const char *oid);
/* Read extensions by OID. */
int gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
int indx,
void *oid, size_t * sizeof_oid);
int gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_extension_by_oid (MHD_gnutls_x509_crt_t cert,
const char *oid,
int indx,
void *buf,
@@ -233,15 +233,15 @@ extern "C"
unsigned int *critical);
/* Read extensions by sequence number. */
int gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_extension_info (MHD_gnutls_x509_crt_t cert,
int indx,
void *oid,
size_t * sizeof_oid, int *critical);
int gnutls_x509_crt_get_extension_data (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_extension_data (MHD_gnutls_x509_crt_t cert,
int indx,
void *data, size_t * sizeof_data);
int gnutls_x509_crt_set_extension_by_oid (gnutls_x509_crt_t crt,
int MHD_gnutls_x509_crt_set_extension_by_oid (MHD_gnutls_x509_crt_t crt,
const char *oid,
const void *buf,
size_t sizeof_buf,
@@ -249,207 +249,207 @@ extern "C"
/* X.509 Certificate writing.
*/
int gnutls_x509_crt_set_dn_by_oid (gnutls_x509_crt_t crt,
int MHD_gnutls_x509_crt_set_dn_by_oid (MHD_gnutls_x509_crt_t crt,
const char *oid,
unsigned int raw_flag,
const void *name,
unsigned int sizeof_name);
int gnutls_x509_crt_set_issuer_dn_by_oid (gnutls_x509_crt_t crt,
int MHD_gnutls_x509_crt_set_issuer_dn_by_oid (MHD_gnutls_x509_crt_t crt,
const char *oid,
unsigned int raw_flag,
const void *name,
unsigned int sizeof_name);
int gnutls_x509_crt_set_version (gnutls_x509_crt_t crt,
int MHD_gnutls_x509_crt_set_version (MHD_gnutls_x509_crt_t crt,
unsigned int version);
int gnutls_x509_crt_set_key (gnutls_x509_crt_t crt,
gnutls_x509_privkey_t key);
int gnutls_x509_crt_set_ca_status (gnutls_x509_crt_t crt, unsigned int ca);
int gnutls_x509_crt_set_basic_constraints (gnutls_x509_crt_t crt,
int MHD_gnutls_x509_crt_set_key (MHD_gnutls_x509_crt_t crt,
MHD_gnutls_x509_privkey_t key);
int MHD_gnutls_x509_crt_set_ca_status (MHD_gnutls_x509_crt_t crt, unsigned int ca);
int MHD_gnutls_x509_crt_set_basic_constraints (MHD_gnutls_x509_crt_t crt,
unsigned int ca,
int pathLenConstraint);
int gnutls_x509_crt_set_subject_alternative_name (gnutls_x509_crt_t crt,
gnutls_x509_subject_alt_name_t
int MHD_gnutls_x509_crt_set_subject_alternative_name (MHD_gnutls_x509_crt_t crt,
MHD_gnutls_x509_subject_alt_name_t
type,
const char *data_string);
int gnutls_x509_crt_sign (gnutls_x509_crt_t crt,
gnutls_x509_crt_t issuer,
gnutls_x509_privkey_t issuer_key);
int gnutls_x509_crt_sign2 (gnutls_x509_crt_t crt,
gnutls_x509_crt_t issuer,
gnutls_x509_privkey_t issuer_key,
int MHD_gnutls_x509_crt_sign (MHD_gnutls_x509_crt_t crt,
MHD_gnutls_x509_crt_t issuer,
MHD_gnutls_x509_privkey_t issuer_key);
int MHD_gnutls_x509_crt_sign2 (MHD_gnutls_x509_crt_t crt,
MHD_gnutls_x509_crt_t issuer,
MHD_gnutls_x509_privkey_t issuer_key,
enum MHD_GNUTLS_HashAlgorithm,
unsigned int flags);
int gnutls_x509_crt_set_activation_time (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_set_activation_time (MHD_gnutls_x509_crt_t cert,
time_t act_time);
int gnutls_x509_crt_set_expiration_time (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_set_expiration_time (MHD_gnutls_x509_crt_t cert,
time_t exp_time);
int gnutls_x509_crt_set_serial (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_set_serial (MHD_gnutls_x509_crt_t cert,
const void *serial, size_t serial_size);
int gnutls_x509_crt_set_subject_key_id (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_set_subject_key_id (MHD_gnutls_x509_crt_t cert,
const void *id, size_t id_size);
int gnutls_x509_crt_set_proxy_dn (gnutls_x509_crt_t crt,
gnutls_x509_crt_t eecrt,
int MHD_gnutls_x509_crt_set_proxy_dn (MHD_gnutls_x509_crt_t crt,
MHD_gnutls_x509_crt_t eecrt,
unsigned int raw_flag,
const void *name,
unsigned int sizeof_name);
int gnutls_x509_crt_set_proxy (gnutls_x509_crt_t crt,
int MHD_gnutls_x509_crt_set_proxy (MHD_gnutls_x509_crt_t crt,
int pathLenConstraint,
const char *policyLanguage,
const char *policy, size_t sizeof_policy);
typedef enum gnutls_certificate_print_formats
typedef enum MHD_gnutls_certificate_print_formats
{
GNUTLS_X509_CRT_FULL,
GNUTLS_X509_CRT_ONELINE,
GNUTLS_X509_CRT_UNSIGNED_FULL
} gnutls_certificate_print_formats_t;
} MHD_gnutls_certificate_print_formats_t;
int gnutls_x509_crt_print (gnutls_x509_crt_t cert,
gnutls_certificate_print_formats_t format,
gnutls_datum_t * out);
int gnutls_x509_crl_print (gnutls_x509_crl_t crl,
gnutls_certificate_print_formats_t format,
gnutls_datum_t * out);
int MHD_gnutls_x509_crt_print (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_certificate_print_formats_t format,
MHD_gnutls_datum_t * out);
int MHD_gnutls_x509_crl_print (MHD_gnutls_x509_crl_t crl,
MHD_gnutls_certificate_print_formats_t format,
MHD_gnutls_datum_t * out);
/* Access to internal Certificate fields.
*/
int gnutls_x509_crt_get_raw_issuer_dn (gnutls_x509_crt_t cert,
gnutls_datum_t * start);
int gnutls_x509_crt_get_raw_dn (gnutls_x509_crt_t cert,
gnutls_datum_t * start);
int MHD_gnutls_x509_crt_get_raw_issuer_dn (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_datum_t * start);
int MHD_gnutls_x509_crt_get_raw_dn (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_datum_t * start);
/* RDN handling.
*/
int gnutls_x509_rdn_get (const gnutls_datum_t * idn,
int MHD_gnutls_x509_rdn_get (const MHD_gnutls_datum_t * idn,
char *buf, size_t * sizeof_buf);
int gnutls_x509_rdn_get_oid (const gnutls_datum_t * idn,
int MHD_gnutls_x509_rdn_get_oid (const MHD_gnutls_datum_t * idn,
int indx, void *buf, size_t * sizeof_buf);
int gnutls_x509_rdn_get_by_oid (const gnutls_datum_t * idn,
int MHD_gnutls_x509_rdn_get_by_oid (const MHD_gnutls_datum_t * idn,
const char *oid,
int indx,
unsigned int raw_flag,
void *buf, size_t * sizeof_buf);
typedef void *gnutls_x509_dn_t;
typedef void *MHD_gnutls_x509_dn_t;
typedef struct gnutls_x509_ava_st
typedef struct MHD_gnutls_x509_ava_st
{
gnutls_datum_t oid;
gnutls_datum_t value;
MHD_gnutls_datum_t oid;
MHD_gnutls_datum_t value;
unsigned long value_tag;
} gnutls_x509_ava_st;
} MHD_gnutls_x509_ava_st;
int gnutls_x509_crt_get_subject (gnutls_x509_crt_t cert,
gnutls_x509_dn_t * dn);
int gnutls_x509_crt_get_issuer (gnutls_x509_crt_t cert,
gnutls_x509_dn_t * dn);
int gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
int MHD_gnutls_x509_crt_get_subject (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_x509_dn_t * dn);
int MHD_gnutls_x509_crt_get_issuer (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_x509_dn_t * dn);
int MHD_gnutls_x509_dn_get_rdn_ava (MHD_gnutls_x509_dn_t dn,
int irdn,
int iava, gnutls_x509_ava_st * avast);
int iava, MHD_gnutls_x509_ava_st * avast);
/* CRL handling functions.
*/
int gnutls_x509_crl_init (gnutls_x509_crl_t * crl);
void gnutls_x509_crl_deinit (gnutls_x509_crl_t crl);
int MHD_gnutls_x509_crl_init (MHD_gnutls_x509_crl_t * crl);
void MHD_gnutls_x509_crl_deinit (MHD_gnutls_x509_crl_t crl);
int gnutls_x509_crl_import (gnutls_x509_crl_t crl,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format);
int gnutls_x509_crl_export (gnutls_x509_crl_t crl,
gnutls_x509_crt_fmt_t format,
int MHD_gnutls_x509_crl_import (MHD_gnutls_x509_crl_t crl,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format);
int MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
MHD_gnutls_x509_crt_fmt_t format,
void *output_data, size_t * output_data_size);
int gnutls_x509_crl_get_issuer_dn (const gnutls_x509_crl_t crl,
int MHD_gnutls_x509_crl_get_issuer_dn (const MHD_gnutls_x509_crl_t crl,
char *buf, size_t * sizeof_buf);
int gnutls_x509_crl_get_issuer_dn_by_oid (gnutls_x509_crl_t crl,
int MHD_gnutls_x509_crl_get_issuer_dn_by_oid (MHD_gnutls_x509_crl_t crl,
const char *oid,
int indx,
unsigned int raw_flag,
void *buf, size_t * sizeof_buf);
int gnutls_x509_crl_get_dn_oid (gnutls_x509_crl_t crl,
int MHD_gnutls_x509_crl_get_dn_oid (MHD_gnutls_x509_crl_t crl,
int indx, void *oid, size_t * sizeof_oid);
int gnutls_x509_crl_get_signature_algorithm (gnutls_x509_crl_t crl);
int gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
int MHD_gnutls_x509_crl_get_signature_algorithm (MHD_gnutls_x509_crl_t crl);
int MHD_gnutls_x509_crl_get_signature (MHD_gnutls_x509_crl_t crl,
char *sig, size_t * sizeof_sig);
int gnutls_x509_crl_get_version (gnutls_x509_crl_t crl);
int MHD_gnutls_x509_crl_get_version (MHD_gnutls_x509_crl_t crl);
time_t gnutls_x509_crl_get_this_update (gnutls_x509_crl_t crl);
time_t gnutls_x509_crl_get_next_update (gnutls_x509_crl_t crl);
time_t MHD_gnutls_x509_crl_get_this_update (MHD_gnutls_x509_crl_t crl);
time_t MHD_gnutls_x509_crl_get_next_update (MHD_gnutls_x509_crl_t crl);
int gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl);
int gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl,
int MHD_gnutls_x509_crl_get_crt_count (MHD_gnutls_x509_crl_t crl);
int MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl,
int indx,
unsigned char *serial,
size_t * serial_size, time_t * t);
#define gnutls_x509_crl_get_certificate_count gnutls_x509_crl_get_crt_count
#define gnutls_x509_crl_get_certificate gnutls_x509_crl_get_crt_serial
#define MHD_gnutls_x509_crl_get_certificate_count MHD_gnutls_x509_crl_get_crt_count
#define MHD_gnutls_x509_crl_get_certificate MHD_gnutls_x509_crl_get_crt_serial
int gnutls_x509_crl_check_issuer (gnutls_x509_crl_t crl,
gnutls_x509_crt_t issuer);
int MHD_gnutls_x509_crl_check_issuer (MHD_gnutls_x509_crl_t crl,
MHD_gnutls_x509_crt_t issuer);
/* CRL writing.
*/
int gnutls_x509_crl_set_version (gnutls_x509_crl_t crl,
int MHD_gnutls_x509_crl_set_version (MHD_gnutls_x509_crl_t crl,
unsigned int version);
int gnutls_x509_crl_sign (gnutls_x509_crl_t crl,
gnutls_x509_crt_t issuer,
gnutls_x509_privkey_t issuer_key);
int gnutls_x509_crl_sign2 (gnutls_x509_crl_t crl,
gnutls_x509_crt_t issuer,
gnutls_x509_privkey_t issuer_key,
int MHD_gnutls_x509_crl_sign (MHD_gnutls_x509_crl_t crl,
MHD_gnutls_x509_crt_t issuer,
MHD_gnutls_x509_privkey_t issuer_key);
int MHD_gnutls_x509_crl_sign2 (MHD_gnutls_x509_crl_t crl,
MHD_gnutls_x509_crt_t issuer,
MHD_gnutls_x509_privkey_t issuer_key,
enum MHD_GNUTLS_HashAlgorithm,
unsigned int flags);
int gnutls_x509_crl_set_this_update (gnutls_x509_crl_t crl,
int MHD_gnutls_x509_crl_set_this_update (MHD_gnutls_x509_crl_t crl,
time_t act_time);
int gnutls_x509_crl_set_next_update (gnutls_x509_crl_t crl,
int MHD_gnutls_x509_crl_set_next_update (MHD_gnutls_x509_crl_t crl,
time_t exp_time);
int gnutls_x509_crl_set_crt_serial (gnutls_x509_crl_t crl,
int MHD_gnutls_x509_crl_set_crt_serial (MHD_gnutls_x509_crl_t crl,
const void *serial,
size_t serial_size,
time_t revocation_time);
int gnutls_x509_crl_set_crt (gnutls_x509_crl_t crl,
gnutls_x509_crt_t crt, time_t revocation_time);
int MHD_gnutls_x509_crl_set_crt (MHD_gnutls_x509_crl_t crl,
MHD_gnutls_x509_crt_t crt, time_t revocation_time);
/* PKCS7 structures handling
*/
struct gnutls_pkcs7_int;
typedef struct gnutls_pkcs7_int *gnutls_pkcs7_t;
struct MHD_gnutls_pkcs7_int;
typedef struct MHD_gnutls_pkcs7_int *MHD_gnutls_pkcs7_t;
int gnutls_pkcs7_init (gnutls_pkcs7_t * pkcs7);
void gnutls_pkcs7_deinit (gnutls_pkcs7_t pkcs7);
int gnutls_pkcs7_import (gnutls_pkcs7_t pkcs7,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format);
int gnutls_pkcs7_export (gnutls_pkcs7_t pkcs7,
gnutls_x509_crt_fmt_t format,
int MHD_gnutls_pkcs7_init (MHD_gnutls_pkcs7_t * pkcs7);
void MHD_gnutls_pkcs7_deinit (MHD_gnutls_pkcs7_t pkcs7);
int MHD_gnutls_pkcs7_import (MHD_gnutls_pkcs7_t pkcs7,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format);
int MHD_gnutls_pkcs7_export (MHD_gnutls_pkcs7_t pkcs7,
MHD_gnutls_x509_crt_fmt_t format,
void *output_data, size_t * output_data_size);
int gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7);
int gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
int MHD_gnutls_pkcs7_get_crt_count (MHD_gnutls_pkcs7_t pkcs7);
int MHD_gnutls_pkcs7_get_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
int indx,
void *certificate, size_t * certificate_size);
int gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7,
const gnutls_datum_t * crt);
int gnutls_pkcs7_set_crt (gnutls_pkcs7_t pkcs7, gnutls_x509_crt_t crt);
int gnutls_pkcs7_delete_crt (gnutls_pkcs7_t pkcs7, int indx);
int MHD_gnutls_pkcs7_set_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
const MHD_gnutls_datum_t * crt);
int MHD_gnutls_pkcs7_set_crt (MHD_gnutls_pkcs7_t pkcs7, MHD_gnutls_x509_crt_t crt);
int MHD_gnutls_pkcs7_delete_crt (MHD_gnutls_pkcs7_t pkcs7, int indx);
int gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
int MHD_gnutls_pkcs7_get_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
int indx, void *crl, size_t * crl_size);
int gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7);
int MHD_gnutls_pkcs7_get_crl_count (MHD_gnutls_pkcs7_t pkcs7);
int gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7,
const gnutls_datum_t * crt);
int gnutls_pkcs7_set_crl (gnutls_pkcs7_t pkcs7, gnutls_x509_crl_t crl);
int gnutls_pkcs7_delete_crl (gnutls_pkcs7_t pkcs7, int indx);
int MHD_gnutls_pkcs7_set_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
const MHD_gnutls_datum_t * crt);
int MHD_gnutls_pkcs7_set_crl (MHD_gnutls_pkcs7_t pkcs7, MHD_gnutls_x509_crl_t crl);
int MHD_gnutls_pkcs7_delete_crl (MHD_gnutls_pkcs7_t pkcs7, int indx);
/* X.509 Certificate verification functions.
*/
typedef enum gnutls_certificate_verify_flags
typedef enum MHD_gnutls_certificate_verify_flags
{
/* If set a signer does not have to be a certificate authority. This
* flag should normaly be disabled, unless you know what this means.
@@ -482,51 +482,51 @@ extern "C"
/* Allow certificates to be signed using the broken MD5 algorithm.
*/
GNUTLS_VERIFY_ALLOW_SIGN_RSA_MD5 = 32
} gnutls_certificate_verify_flags;
} MHD_gnutls_certificate_verify_flags;
int gnutls_x509_crt_check_issuer (gnutls_x509_crt_t cert,
gnutls_x509_crt_t issuer);
int MHD_gnutls_x509_crt_check_issuer (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_t issuer);
int gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
int MHD_gnutls_x509_crt_list_verify (const MHD_gnutls_x509_crt_t * cert_list,
int cert_list_length,
const gnutls_x509_crt_t * CA_list,
const MHD_gnutls_x509_crt_t * CA_list,
int CA_list_length,
const gnutls_x509_crl_t * CRL_list,
const MHD_gnutls_x509_crl_t * CRL_list,
int CRL_list_length,
unsigned int flags, unsigned int *verify);
int gnutls_x509_crt_verify (gnutls_x509_crt_t cert,
const gnutls_x509_crt_t * CA_list,
int MHD_gnutls_x509_crt_verify (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_x509_crt_t * CA_list,
int CA_list_length,
unsigned int flags, unsigned int *verify);
int gnutls_x509_crl_verify (gnutls_x509_crl_t crl,
const gnutls_x509_crt_t * CA_list,
int MHD_gnutls_x509_crl_verify (MHD_gnutls_x509_crl_t crl,
const MHD_gnutls_x509_crt_t * CA_list,
int CA_list_length,
unsigned int flags, unsigned int *verify);
int gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
const gnutls_x509_crl_t *
int MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_x509_crl_t *
crl_list, int crl_list_length);
int gnutls_x509_crt_get_fingerprint (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_fingerprint (MHD_gnutls_x509_crt_t cert,
enum MHD_GNUTLS_HashAlgorithm algo,
void *buf, size_t * sizeof_buf);
int gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_key_purpose_oid (MHD_gnutls_x509_crt_t cert,
int indx,
void *oid,
size_t * sizeof_oid,
unsigned int *critical);
int gnutls_x509_crt_set_key_purpose_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_set_key_purpose_oid (MHD_gnutls_x509_crt_t cert,
const void *oid,
unsigned int critical);
/* Private key handling.
*/
/* Flags for the gnutls_x509_privkey_export_pkcs8() function.
/* Flags for the MHD_gnutls_x509_privkey_export_pkcs8() function.
*/
typedef enum gnutls_pkcs_encrypt_flags_t
typedef enum MHD_gnutls_pkcs_encrypt_flags_t
{
GNUTLS_PKCS_PLAIN = 1, /* if set the private key will not
* be encrypted.
@@ -535,150 +535,150 @@ extern "C"
GNUTLS_PKCS_USE_PKCS12_ARCFOUR = 4,
GNUTLS_PKCS_USE_PKCS12_RC2_40 = 8,
GNUTLS_PKCS_USE_PBES2_3DES = 16
} gnutls_pkcs_encrypt_flags_t;
} MHD_gnutls_pkcs_encrypt_flags_t;
#define GNUTLS_PKCS8_PLAIN GNUTLS_PKCS_PLAIN
#define GNUTLS_PKCS8_USE_PKCS12_3DES GNUTLS_PKCS_USE_PKCS12_3DES
#define GNUTLS_PKCS8_USE_PKCS12_ARCFOUR GNUTLS_PKCS_USE_PKCS12_ARCFOUR
#define GNUTLS_PKCS8_USE_PKCS12_RC2_40 GNUTLS_PKCS_USE_PKCS12_RC2_40
int gnutls_x509_privkey_init (gnutls_x509_privkey_t * key);
void gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key);
int gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst,
gnutls_x509_privkey_t src);
int gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format);
int gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format,
int MHD_gnutls_x509_privkey_init (MHD_gnutls_x509_privkey_t * key);
void MHD_gnutls_x509_privkey_deinit (MHD_gnutls_x509_privkey_t key);
int MHD_gnutls_x509_privkey_cpy (MHD_gnutls_x509_privkey_t dst,
MHD_gnutls_x509_privkey_t src);
int MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format);
int MHD_gnutls_x509_privkey_import_pkcs8 (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format,
const char *pass, unsigned int flags);
int gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
const gnutls_datum_t * m,
const gnutls_datum_t * e,
const gnutls_datum_t * d,
const gnutls_datum_t * p,
const gnutls_datum_t * q,
const gnutls_datum_t * u);
int gnutls_x509_privkey_fix (gnutls_x509_privkey_t key);
int MHD_gnutls_x509_privkey_import_rsa_raw (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * m,
const MHD_gnutls_datum_t * e,
const MHD_gnutls_datum_t * d,
const MHD_gnutls_datum_t * p,
const MHD_gnutls_datum_t * q,
const MHD_gnutls_datum_t * u);
int MHD_gnutls_x509_privkey_fix (MHD_gnutls_x509_privkey_t key);
int gnutls_x509_privkey_export_dsa_raw (gnutls_x509_privkey_t key,
gnutls_datum_t * p,
gnutls_datum_t * q,
gnutls_datum_t * g,
gnutls_datum_t * y,
gnutls_datum_t * x);
int gnutls_x509_privkey_import_dsa_raw (gnutls_x509_privkey_t key,
const gnutls_datum_t * p,
const gnutls_datum_t * q,
const gnutls_datum_t * g,
const gnutls_datum_t * y,
const gnutls_datum_t * x);
int MHD_gnutls_x509_privkey_export_dsa_raw (MHD_gnutls_x509_privkey_t key,
MHD_gnutls_datum_t * p,
MHD_gnutls_datum_t * q,
MHD_gnutls_datum_t * g,
MHD_gnutls_datum_t * y,
MHD_gnutls_datum_t * x);
int MHD_gnutls_x509_privkey_import_dsa_raw (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * p,
const MHD_gnutls_datum_t * q,
const MHD_gnutls_datum_t * g,
const MHD_gnutls_datum_t * y,
const MHD_gnutls_datum_t * x);
int gnutls_x509_privkey_get_pk_algorithm (gnutls_x509_privkey_t key);
int gnutls_x509_privkey_get_key_id (gnutls_x509_privkey_t key,
int MHD_gnutls_x509_privkey_get_pk_algorithm (MHD_gnutls_x509_privkey_t key);
int MHD_gnutls_x509_privkey_get_key_id (MHD_gnutls_x509_privkey_t key,
unsigned int flags,
unsigned char *output_data,
size_t * output_data_size);
int gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
int MHD_gnutls_x509_privkey_generate (MHD_gnutls_x509_privkey_t key,
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
unsigned int bits, unsigned int flags);
int gnutls_x509_privkey_export (gnutls_x509_privkey_t key,
gnutls_x509_crt_fmt_t format,
int MHD_gnutls_x509_privkey_export (MHD_gnutls_x509_privkey_t key,
MHD_gnutls_x509_crt_fmt_t format,
void *output_data,
size_t * output_data_size);
int gnutls_x509_privkey_export_pkcs8 (gnutls_x509_privkey_t key,
gnutls_x509_crt_fmt_t format,
int MHD_gnutls_x509_privkey_export_pkcs8 (MHD_gnutls_x509_privkey_t key,
MHD_gnutls_x509_crt_fmt_t format,
const char *password,
unsigned int flags,
void *output_data,
size_t * output_data_size);
int gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
gnutls_datum_t * m,
gnutls_datum_t * e,
gnutls_datum_t * d,
gnutls_datum_t * p,
gnutls_datum_t * q,
gnutls_datum_t * u);
int MHD_gnutls_x509_privkey_export_rsa_raw (MHD_gnutls_x509_privkey_t key,
MHD_gnutls_datum_t * m,
MHD_gnutls_datum_t * e,
MHD_gnutls_datum_t * d,
MHD_gnutls_datum_t * p,
MHD_gnutls_datum_t * q,
MHD_gnutls_datum_t * u);
/* Signing stuff.
*/
int gnutls_x509_privkey_sign_data (gnutls_x509_privkey_t key,
int MHD_gnutls_x509_privkey_sign_data (MHD_gnutls_x509_privkey_t key,
enum MHD_GNUTLS_HashAlgorithm digest,
unsigned int flags,
const gnutls_datum_t * data,
const MHD_gnutls_datum_t * data,
void *signature,
size_t * signature_size);
int gnutls_x509_privkey_verify_data (gnutls_x509_privkey_t key,
int MHD_gnutls_x509_privkey_verify_data (MHD_gnutls_x509_privkey_t key,
unsigned int flags,
const gnutls_datum_t * data,
const gnutls_datum_t * signature);
int gnutls_x509_crt_verify_data (gnutls_x509_crt_t crt,
const MHD_gnutls_datum_t * data,
const MHD_gnutls_datum_t * signature);
int MHD_gnutls_x509_crt_verify_data (MHD_gnutls_x509_crt_t crt,
unsigned int flags,
const gnutls_datum_t * data,
const gnutls_datum_t * signature);
const MHD_gnutls_datum_t * data,
const MHD_gnutls_datum_t * signature);
int gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
const gnutls_datum_t * hash,
gnutls_datum_t * signature);
int MHD_gnutls_x509_privkey_sign_hash (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * hash,
MHD_gnutls_datum_t * signature);
/* Certificate request stuff.
*/
struct gnutls_x509_crq_int;
typedef struct gnutls_x509_crq_int *gnutls_x509_crq_t;
struct MHD_gnutls_x509_crq_int;
typedef struct MHD_gnutls_x509_crq_int *MHD_gnutls_x509_crq_t;
int gnutls_x509_crq_init (gnutls_x509_crq_t * crq);
void gnutls_x509_crq_deinit (gnutls_x509_crq_t crq);
int gnutls_x509_crq_import (gnutls_x509_crq_t crq,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format);
int gnutls_x509_crq_get_pk_algorithm (gnutls_x509_crq_t crq,
int MHD_gnutls_x509_crq_init (MHD_gnutls_x509_crq_t * crq);
void MHD_gnutls_x509_crq_deinit (MHD_gnutls_x509_crq_t crq);
int MHD_gnutls_x509_crq_import (MHD_gnutls_x509_crq_t crq,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format);
int MHD_gnutls_x509_crq_get_pk_algorithm (MHD_gnutls_x509_crq_t crq,
unsigned int *bits);
int gnutls_x509_crq_get_dn (gnutls_x509_crq_t crq,
int MHD_gnutls_x509_crq_get_dn (MHD_gnutls_x509_crq_t crq,
char *buf, size_t * sizeof_buf);
int gnutls_x509_crq_get_dn_oid (gnutls_x509_crq_t crq,
int MHD_gnutls_x509_crq_get_dn_oid (MHD_gnutls_x509_crq_t crq,
int indx, void *oid, size_t * sizeof_oid);
int gnutls_x509_crq_get_dn_by_oid (gnutls_x509_crq_t crq,
int MHD_gnutls_x509_crq_get_dn_by_oid (MHD_gnutls_x509_crq_t crq,
const char *oid,
int indx,
unsigned int raw_flag,
void *buf, size_t * sizeof_buf);
int gnutls_x509_crq_set_dn_by_oid (gnutls_x509_crq_t crq,
int MHD_gnutls_x509_crq_set_dn_by_oid (MHD_gnutls_x509_crq_t crq,
const char *oid,
unsigned int raw_flag,
const void *name,
unsigned int sizeof_name);
int gnutls_x509_crq_set_version (gnutls_x509_crq_t crq,
int MHD_gnutls_x509_crq_set_version (MHD_gnutls_x509_crq_t crq,
unsigned int version);
int gnutls_x509_crq_set_key (gnutls_x509_crq_t crq,
gnutls_x509_privkey_t key);
int gnutls_x509_crq_sign2 (gnutls_x509_crq_t crq,
gnutls_x509_privkey_t key,
int MHD_gnutls_x509_crq_set_key (MHD_gnutls_x509_crq_t crq,
MHD_gnutls_x509_privkey_t key);
int MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq,
MHD_gnutls_x509_privkey_t key,
enum MHD_GNUTLS_HashAlgorithm,
unsigned int flags);
int gnutls_x509_crq_sign (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key);
int MHD_gnutls_x509_crq_sign (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key);
int gnutls_x509_crq_set_challenge_password (gnutls_x509_crq_t crq,
int MHD_gnutls_x509_crq_set_challenge_password (MHD_gnutls_x509_crq_t crq,
const char *pass);
int gnutls_x509_crq_get_challenge_password (gnutls_x509_crq_t crq,
int MHD_gnutls_x509_crq_get_challenge_password (MHD_gnutls_x509_crq_t crq,
char *pass,
size_t * sizeof_pass);
int gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
int MHD_gnutls_x509_crq_set_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
const char *oid,
void *buf, size_t sizeof_buf);
int gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
int MHD_gnutls_x509_crq_get_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
const char *oid,
int indx,
void *buf, size_t * sizeof_buf);
int gnutls_x509_crq_export (gnutls_x509_crq_t crq,
gnutls_x509_crt_fmt_t format,
int MHD_gnutls_x509_crq_export (MHD_gnutls_x509_crq_t crq,
MHD_gnutls_x509_crt_fmt_t format,
void *output_data, size_t * output_data_size);
int gnutls_x509_crt_set_crq (gnutls_x509_crt_t crt, gnutls_x509_crq_t crq);
int MHD_gnutls_x509_crt_set_crq (MHD_gnutls_x509_crt_t crt, MHD_gnutls_x509_crq_t crq);
#ifdef __cplusplus
}
@@ -692,16 +692,16 @@ extern "C"
#define HASH_OID_SHA384 "2.16.840.1.101.3.4.2.2"
#define HASH_OID_SHA512 "2.16.840.1.101.3.4.2.3"
typedef struct gnutls_x509_crl_int
typedef struct MHD_gnutls_x509_crl_int
{
ASN1_TYPE crl;
} gnutls_x509_crl_int;
} MHD_gnutls_x509_crl_int;
typedef struct gnutls_x509_crt_int
typedef struct MHD_gnutls_x509_crt_int
{
ASN1_TYPE cert;
int use_extensions;
} gnutls_x509_crt_int;
} MHD_gnutls_x509_crt_int;
#define MAX_PRIV_PARAMS_SIZE 6 /* ok for RSA and DSA */
@@ -749,100 +749,100 @@ typedef struct MHD_gtls_x509_privkey_int
* the exported API (used internally only).
*/
ASN1_TYPE key;
} gnutls_x509_privkey_int;
} MHD_gnutls_x509_privkey_int;
int gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_issuer_dn_by_oid (MHD_gnutls_x509_crt_t cert,
const char *oid,
int indx,
unsigned int raw_flag,
void *buf, size_t * sizeof_buf);
int gnutls_x509_crt_get_subject_alt_name (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
unsigned int seq,
void *ret,
size_t * ret_size,
unsigned int *critical);
int gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_dn_by_oid (MHD_gnutls_x509_crt_t cert,
const char *oid,
int indx,
unsigned int raw_flag,
void *buf, size_t * sizeof_buf);
int gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert,
unsigned int *critical);
int gnutls_x509_crt_get_pk_algorithm (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert,
unsigned int *bits);
int _gnutls_x509_crt_cpy (gnutls_x509_crt_t dest, gnutls_x509_crt_t src);
int MHD__gnutls_x509_crt_cpy (MHD_gnutls_x509_crt_t dest, MHD_gnutls_x509_crt_t src);
int gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
void *result, size_t * result_size);
int _gnutls_x509_compare_raw_dn (const gnutls_datum_t * dn1,
const gnutls_datum_t * dn2);
int MHD__gnutls_x509_compare_raw_dn (const MHD_gnutls_datum_t * dn1,
const MHD_gnutls_datum_t * dn2);
int gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
const gnutls_x509_crl_t * crl_list,
int MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_x509_crl_t * crl_list,
int crl_list_length);
int _gnutls_x509_crl_cpy (gnutls_x509_crl_t dest, gnutls_x509_crl_t src);
int _gnutls_x509_crl_get_raw_issuer_dn (gnutls_x509_crl_t crl,
gnutls_datum_t * dn);
int gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl);
int gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl,
int MHD__gnutls_x509_crl_cpy (MHD_gnutls_x509_crl_t dest, MHD_gnutls_x509_crl_t src);
int MHD__gnutls_x509_crl_get_raw_issuer_dn (MHD_gnutls_x509_crl_t crl,
MHD_gnutls_datum_t * dn);
int MHD_gnutls_x509_crl_get_crt_count (MHD_gnutls_x509_crl_t crl);
int MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl,
int indx,
unsigned char *serial,
size_t * serial_size, time_t * t);
void gnutls_x509_crl_deinit (gnutls_x509_crl_t crl);
int gnutls_x509_crl_init (gnutls_x509_crl_t * crl);
int gnutls_x509_crl_import (gnutls_x509_crl_t crl,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format);
int gnutls_x509_crl_export (gnutls_x509_crl_t crl,
gnutls_x509_crt_fmt_t format,
void MHD_gnutls_x509_crl_deinit (MHD_gnutls_x509_crl_t crl);
int MHD_gnutls_x509_crl_init (MHD_gnutls_x509_crl_t * crl);
int MHD_gnutls_x509_crl_import (MHD_gnutls_x509_crl_t crl,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format);
int MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
MHD_gnutls_x509_crt_fmt_t format,
void *output_data, size_t * output_data_size);
int gnutls_x509_crt_init (gnutls_x509_crt_t * cert);
void gnutls_x509_crt_deinit (gnutls_x509_crt_t cert);
int gnutls_x509_crt_import (gnutls_x509_crt_t cert,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format);
int gnutls_x509_crt_export (gnutls_x509_crt_t cert,
gnutls_x509_crt_fmt_t format,
int MHD_gnutls_x509_crt_init (MHD_gnutls_x509_crt_t * cert);
void MHD_gnutls_x509_crt_deinit (MHD_gnutls_x509_crt_t cert);
int MHD_gnutls_x509_crt_import (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format);
int MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_fmt_t format,
void *output_data, size_t * output_data_size);
int gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
int MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
unsigned int *key_usage,
unsigned int *critical);
int gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert);
int gnutls_x509_crt_get_version (gnutls_x509_crt_t cert);
int MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert);
int MHD_gnutls_x509_crt_get_version (MHD_gnutls_x509_crt_t cert);
int gnutls_x509_privkey_init (gnutls_x509_privkey_t * key);
void gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key);
int MHD_gnutls_x509_privkey_init (MHD_gnutls_x509_privkey_t * key);
void MHD_gnutls_x509_privkey_deinit (MHD_gnutls_x509_privkey_t key);
int gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
int MHD_gnutls_x509_privkey_generate (MHD_gnutls_x509_privkey_t key,
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
unsigned int bits, unsigned int flags);
int gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format);
int gnutls_x509_privkey_get_pk_algorithm (gnutls_x509_privkey_t key);
int gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
const gnutls_datum_t * m,
const gnutls_datum_t * e,
const gnutls_datum_t * d,
const gnutls_datum_t * p,
const gnutls_datum_t * q,
const gnutls_datum_t * u);
int gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
gnutls_datum_t * m,
gnutls_datum_t * e,
gnutls_datum_t * d,
gnutls_datum_t * p,
gnutls_datum_t * q,
gnutls_datum_t * u);
int gnutls_x509_privkey_export (gnutls_x509_privkey_t key,
gnutls_x509_crt_fmt_t format,
int MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format);
int MHD_gnutls_x509_privkey_get_pk_algorithm (MHD_gnutls_x509_privkey_t key);
int MHD_gnutls_x509_privkey_import_rsa_raw (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * m,
const MHD_gnutls_datum_t * e,
const MHD_gnutls_datum_t * d,
const MHD_gnutls_datum_t * p,
const MHD_gnutls_datum_t * q,
const MHD_gnutls_datum_t * u);
int MHD_gnutls_x509_privkey_export_rsa_raw (MHD_gnutls_x509_privkey_t key,
MHD_gnutls_datum_t * m,
MHD_gnutls_datum_t * e,
MHD_gnutls_datum_t * d,
MHD_gnutls_datum_t * p,
MHD_gnutls_datum_t * q,
MHD_gnutls_datum_t * u);
int MHD_gnutls_x509_privkey_export (MHD_gnutls_x509_privkey_t key,
MHD_gnutls_x509_crt_fmt_t format,
void *output_data, size_t * output_data_size);
#define GNUTLS_CRL_REASON_UNUSED 128
+254 -254
View File
@@ -39,8 +39,8 @@
#include <dsa.h>
#include <verify.h>
static int _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params);
int _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
static int MHD__gnutlsMHD__asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params);
int MHD__gnutlsMHD__asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
/* remove this when libgcrypt can handle the PKCS #1 coefficients from
* rsa keys
@@ -48,7 +48,7 @@ int _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
#define CALC_COEFF 1
/**
* gnutls_x509_privkey_init - This function initializes a gnutls_crl structure
* MHD_gnutls_x509_privkey_init - This function initializes a MHD_gnutls_crl structure
* @key: The structure to be initialized
*
* This function will initialize an private key structure.
@@ -57,9 +57,9 @@ int _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
*
**/
int
gnutls_x509_privkey_init (gnutls_x509_privkey_t * key)
MHD_gnutls_x509_privkey_init (MHD_gnutls_x509_privkey_t * key)
{
*key = gnutls_calloc (1, sizeof (gnutls_x509_privkey_int));
*key = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_x509_privkey_int));
if (*key)
{
@@ -72,14 +72,14 @@ gnutls_x509_privkey_init (gnutls_x509_privkey_t * key)
}
/**
* gnutls_x509_privkey_deinit - This function deinitializes memory used by a gnutls_x509_privkey_t structure
* MHD_gnutls_x509_privkey_deinit - This function deinitializes memory used by a MHD_gnutls_x509_privkey_t structure
* @key: The structure to be initialized
*
* This function will deinitialize a private key structure.
*
**/
void
gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key)
MHD_gnutls_x509_privkey_deinit (MHD_gnutls_x509_privkey_t key)
{
int i;
@@ -88,15 +88,15 @@ gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key)
for (i = 0; i < key->params_size; i++)
{
mhd_gtls_mpi_release (&key->params[i]);
MHD_gtls_mpi_release (&key->params[i]);
}
asn1_delete_structure (&key->key);
gnutls_free (key);
MHD__asn1_delete_structure (&key->key);
MHD_gnutls_free (key);
}
/**
* gnutls_x509_privkey_cpy - This function copies a private key
* MHD_gnutls_x509_privkey_cpy - This function copies a private key
* @dst: The destination key, which should be initialized.
* @src: The source key
*
@@ -104,7 +104,7 @@ gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key)
*
**/
int
gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst, gnutls_x509_privkey_t src)
MHD_gnutls_x509_privkey_cpy (MHD_gnutls_x509_privkey_t dst, MHD_gnutls_x509_privkey_t src)
{
int i, ret;
@@ -113,7 +113,7 @@ gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst, gnutls_x509_privkey_t src)
for (i = 0; i < src->params_size; i++)
{
dst->params[i] = _gnutls_mpi_copy (src->params[i]);
dst->params[i] = MHD__gnutls_mpi_copy (src->params[i]);
if (dst->params[i] == NULL)
return GNUTLS_E_MEMORY_ERROR;
}
@@ -127,15 +127,15 @@ gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst, gnutls_x509_privkey_t src)
switch (dst->pk_algorithm)
{
case MHD_GNUTLS_PK_RSA:
ret = _gnutls_asn1_encode_rsa (&dst->key, dst->params);
ret = MHD__gnutlsMHD__asn1_encode_rsa (&dst->key, dst->params);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
break;
default:
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
}
@@ -144,69 +144,69 @@ gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst, gnutls_x509_privkey_t src)
}
/* Converts an RSA PKCS#1 key to
* an internal structure (gnutls_private_key)
* an internal structure (MHD_gnutls_private_key)
*/
ASN1_TYPE
_gnutls_privkey_decode_pkcs1_rsa_key (const gnutls_datum_t * raw_key,
gnutls_x509_privkey_t pkey)
MHD__gnutls_privkey_decode_pkcs1_rsa_key (const MHD_gnutls_datum_t * raw_key,
MHD_gnutls_x509_privkey_t pkey)
{
int result;
ASN1_TYPE pkey_asn;
if ((result = asn1_create_element (_gnutls_get_gnutls_asn (),
if ((result = MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
"GNUTLS.RSAPrivateKey",
&pkey_asn)) != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
return NULL;
}
if ((sizeof (pkey->params) / sizeof (mpi_t)) < RSA_PRIVATE_PARAMS)
{
gnutls_assert ();
MHD_gnutls_assert ();
/* internal error. Increase the mpi_ts in params */
return NULL;
}
result = asn1_der_decoding (&pkey_asn, raw_key->data, raw_key->size, NULL);
result = MHD__asn1_der_decoding (&pkey_asn, raw_key->data, raw_key->size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
if ((result = _gnutls_x509_read_int (pkey_asn, "modulus", &pkey->params[0]))
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "modulus", &pkey->params[0]))
< 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
if ((result = _gnutls_x509_read_int (pkey_asn, "publicExponent",
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "publicExponent",
&pkey->params[1])) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
if ((result = _gnutls_x509_read_int (pkey_asn, "privateExponent",
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "privateExponent",
&pkey->params[2])) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
if ((result = _gnutls_x509_read_int (pkey_asn, "prime1", &pkey->params[3]))
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "prime1", &pkey->params[3]))
< 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
if ((result = _gnutls_x509_read_int (pkey_asn, "prime2", &pkey->params[4]))
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "prime2", &pkey->params[4]))
< 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
@@ -215,21 +215,21 @@ _gnutls_privkey_decode_pkcs1_rsa_key (const gnutls_datum_t * raw_key,
* library is uses the p,q in the reverse order.
*/
pkey->params[5] =
_gnutls_mpi_snew (_gnutls_mpi_get_nbits (pkey->params[0]));
MHD__gnutls_mpi_snew (MHD__gnutls_mpi_get_nbits (pkey->params[0]));
if (pkey->params[5] == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
_gnutls_mpi_invm (pkey->params[5], pkey->params[3], pkey->params[4]);
MHD__gnutls_mpi_invm (pkey->params[5], pkey->params[3], pkey->params[4]);
/* p, q */
#else
if ((result = _gnutls_x509_read_int (pkey_asn, "coefficient",
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "coefficient",
&pkey->params[5])) < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto error;
}
#endif
@@ -237,13 +237,13 @@ _gnutls_privkey_decode_pkcs1_rsa_key (const gnutls_datum_t * raw_key,
return pkey_asn;
error:asn1_delete_structure (&pkey_asn);
mhd_gtls_mpi_release (&pkey->params[0]);
mhd_gtls_mpi_release (&pkey->params[1]);
mhd_gtls_mpi_release (&pkey->params[2]);
mhd_gtls_mpi_release (&pkey->params[3]);
mhd_gtls_mpi_release (&pkey->params[4]);
mhd_gtls_mpi_release (&pkey->params[5]);
error:MHD__asn1_delete_structure (&pkey_asn);
MHD_gtls_mpi_release (&pkey->params[0]);
MHD_gtls_mpi_release (&pkey->params[1]);
MHD_gtls_mpi_release (&pkey->params[2]);
MHD_gtls_mpi_release (&pkey->params[3]);
MHD_gtls_mpi_release (&pkey->params[4]);
MHD_gtls_mpi_release (&pkey->params[5]);
return NULL;
}
@@ -251,13 +251,13 @@ error:asn1_delete_structure (&pkey_asn);
#define PEM_KEY_RSA "RSA PRIVATE KEY"
/**
* gnutls_x509_privkey_import - This function will import a DER or PEM encoded key
* MHD_gnutls_x509_privkey_import - This function will import a DER or PEM encoded key
* @key: The structure to store the parsed key
* @data: The DER or PEM encoded certificate.
* @format: One of DER or PEM
*
* This function will convert the given DER or PEM encoded key
* to the native gnutls_x509_privkey_t format. The output will be stored in @key .
* to the native MHD_gnutls_x509_privkey_t format. The output will be stored in @key .
*
* If the key is PEM encoded it should have a header of "RSA PRIVATE KEY", or
* "DSA PRIVATE KEY".
@@ -266,16 +266,16 @@ error:asn1_delete_structure (&pkey_asn);
*
**/
int
gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
const gnutls_datum_t * data,
gnutls_x509_crt_fmt_t format)
MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * data,
MHD_gnutls_x509_crt_fmt_t format)
{
int result = 0, need_free = 0;
gnutls_datum_t _data;
MHD_gnutls_datum_t _data;
if (key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -291,7 +291,7 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
/* Try the first header */
result
= _gnutls_fbase64_decode (PEM_KEY_RSA, data->data, data->size, &out);
= MHD__gnutls_fbase64_decode (PEM_KEY_RSA, data->data, data->size, &out);
key->pk_algorithm = MHD_GNUTLS_PK_RSA;
_data.data = out;
@@ -302,15 +302,15 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
if (key->pk_algorithm == MHD_GNUTLS_PK_RSA)
{
key->key = _gnutls_privkey_decode_pkcs1_rsa_key (&_data, key);
key->key = MHD__gnutls_privkey_decode_pkcs1_rsa_key (&_data, key);
if (key->key == NULL)
gnutls_assert ();
MHD_gnutls_assert ();
}
else
{
/* Try decoding with both, and accept the one that succeeds. */
key->pk_algorithm = MHD_GNUTLS_PK_RSA;
key->key = _gnutls_privkey_decode_pkcs1_rsa_key (&_data, key);
key->key = MHD__gnutls_privkey_decode_pkcs1_rsa_key (&_data, key);
// TODO rm
// if (key->key == NULL)
@@ -318,20 +318,20 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
// key->pk_algorithm = GNUTLS_PK_DSA;
// key->key = decode_dsa_key(&_data, key);
// if (key->key == NULL)
// gnutls_assert();
// MHD_gnutls_assert();
// }
}
if (key->key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_ASN1_DER_ERROR;
key->pk_algorithm = MHD_GNUTLS_PK_UNKNOWN;
return result;
}
if (need_free)
_gnutls_free_datum (&_data);
MHD__gnutls_free_datum (&_data);
/* The key has now been decoded.
*/
@@ -340,12 +340,12 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
}
#define FREE_RSA_PRIVATE_PARAMS for (i=0;i<RSA_PRIVATE_PARAMS;i++) \
mhd_gtls_mpi_release(&key->params[i])
MHD_gtls_mpi_release(&key->params[i])
#define FREE_DSA_PRIVATE_PARAMS for (i=0;i<DSA_PRIVATE_PARAMS;i++) \
mhd_gtls_mpi_release(&key->params[i])
MHD_gtls_mpi_release(&key->params[i])
/**
* gnutls_x509_privkey_import_rsa_raw - This function will import a raw RSA key
* MHD_gnutls_x509_privkey_import_rsa_raw - This function will import a raw RSA key
* @key: The structure to store the parsed key
* @m: holds the modulus
* @e: holds the public exponent
@@ -355,83 +355,83 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
* @u: holds the coefficient
*
* This function will convert the given RSA raw parameters
* to the native gnutls_x509_privkey_t format. The output will be stored in @key.
* to the native MHD_gnutls_x509_privkey_t format. The output will be stored in @key.
*
**/
int
gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
const gnutls_datum_t * m,
const gnutls_datum_t * e,
const gnutls_datum_t * d,
const gnutls_datum_t * p,
const gnutls_datum_t * q,
const gnutls_datum_t * u)
MHD_gnutls_x509_privkey_import_rsa_raw (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * m,
const MHD_gnutls_datum_t * e,
const MHD_gnutls_datum_t * d,
const MHD_gnutls_datum_t * p,
const MHD_gnutls_datum_t * q,
const MHD_gnutls_datum_t * u)
{
int i = 0, ret;
size_t siz = 0;
if (key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
siz = m->size;
if (mhd_gtls_mpi_scan_nz (&key->params[0], m->data, &siz))
if (MHD_gtls_mpi_scan_nz (&key->params[0], m->data, &siz))
{
gnutls_assert ();
MHD_gnutls_assert ();
FREE_RSA_PRIVATE_PARAMS;
return GNUTLS_E_MPI_SCAN_FAILED;
}
siz = e->size;
if (mhd_gtls_mpi_scan_nz (&key->params[1], e->data, &siz))
if (MHD_gtls_mpi_scan_nz (&key->params[1], e->data, &siz))
{
gnutls_assert ();
MHD_gnutls_assert ();
FREE_RSA_PRIVATE_PARAMS;
return GNUTLS_E_MPI_SCAN_FAILED;
}
siz = d->size;
if (mhd_gtls_mpi_scan_nz (&key->params[2], d->data, &siz))
if (MHD_gtls_mpi_scan_nz (&key->params[2], d->data, &siz))
{
gnutls_assert ();
MHD_gnutls_assert ();
FREE_RSA_PRIVATE_PARAMS;
return GNUTLS_E_MPI_SCAN_FAILED;
}
siz = p->size;
if (mhd_gtls_mpi_scan_nz (&key->params[3], p->data, &siz))
if (MHD_gtls_mpi_scan_nz (&key->params[3], p->data, &siz))
{
gnutls_assert ();
MHD_gnutls_assert ();
FREE_RSA_PRIVATE_PARAMS;
return GNUTLS_E_MPI_SCAN_FAILED;
}
siz = q->size;
if (mhd_gtls_mpi_scan_nz (&key->params[4], q->data, &siz))
if (MHD_gtls_mpi_scan_nz (&key->params[4], q->data, &siz))
{
gnutls_assert ();
MHD_gnutls_assert ();
FREE_RSA_PRIVATE_PARAMS;
return GNUTLS_E_MPI_SCAN_FAILED;
}
#ifdef CALC_COEFF
key->params[5] = _gnutls_mpi_snew (_gnutls_mpi_get_nbits (key->params[0]));
key->params[5] = MHD__gnutls_mpi_snew (MHD__gnutls_mpi_get_nbits (key->params[0]));
if (key->params[5] == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
FREE_RSA_PRIVATE_PARAMS;
return GNUTLS_E_MEMORY_ERROR;
}
_gnutls_mpi_invm (key->params[5], key->params[3], key->params[4]);
MHD__gnutls_mpi_invm (key->params[5], key->params[3], key->params[4]);
#else
siz = u->size;
if (mhd_gtls_mpi_scan_nz (&key->params[5], u->data, &siz))
if (MHD_gtls_mpi_scan_nz (&key->params[5], u->data, &siz))
{
gnutls_assert ();
MHD_gnutls_assert ();
FREE_RSA_PRIVATE_PARAMS;
return GNUTLS_E_MPI_SCAN_FAILED;
}
@@ -439,10 +439,10 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
if (!key->crippled)
{
ret = _gnutls_asn1_encode_rsa (&key->key, key->params);
ret = MHD__gnutlsMHD__asn1_encode_rsa (&key->key, key->params);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
FREE_RSA_PRIVATE_PARAMS;
return ret;
}
@@ -456,8 +456,8 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
}
/**
* gnutls_x509_privkey_get_pk_algorithm - This function returns the key's PublicKey algorithm
* @key: should contain a gnutls_x509_privkey_t structure
* MHD_gnutls_x509_privkey_get_pk_algorithm - This function returns the key's PublicKey algorithm
* @key: should contain a MHD_gnutls_x509_privkey_t structure
*
* This function will return the public key algorithm of a private
* key.
@@ -467,11 +467,11 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
*
**/
int
gnutls_x509_privkey_get_pk_algorithm (gnutls_x509_privkey_t key)
MHD_gnutls_x509_privkey_get_pk_algorithm (MHD_gnutls_x509_privkey_t key)
{
if (key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -481,7 +481,7 @@ gnutls_x509_privkey_get_pk_algorithm (gnutls_x509_privkey_t key)
/* Encodes the RSA parameters into an ASN.1 RSA private key structure.
*/
static int
_gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
MHD__gnutlsMHD__asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
{
int result, i;
size_t size[8], total;
@@ -495,77 +495,77 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
total = 0;
for (i = 0; i < 5; i++)
{
mhd_gtls_mpi_print_lz (NULL, &size[i], params[i]);
MHD_gtls_mpi_print_lz (NULL, &size[i], params[i]);
total += size[i];
}
/* Now generate exp1 and exp2
*/
exp1 = _gnutls_mpi_salloc_like (params[0]); /* like modulus */
exp1 = MHD__gnutls_mpi_salloc_like (params[0]); /* like modulus */
if (exp1 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
exp2 = _gnutls_mpi_salloc_like (params[0]);
exp2 = MHD__gnutls_mpi_salloc_like (params[0]);
if (exp2 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
q1 = _gnutls_mpi_salloc_like (params[4]);
q1 = MHD__gnutls_mpi_salloc_like (params[4]);
if (q1 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
p1 = _gnutls_mpi_salloc_like (params[3]);
p1 = MHD__gnutls_mpi_salloc_like (params[3]);
if (p1 == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
u = _gnutls_mpi_salloc_like (params[3]);
u = MHD__gnutls_mpi_salloc_like (params[3]);
if (u == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
_gnutls_mpi_invm (u, params[4], params[3]);
MHD__gnutls_mpi_invm (u, params[4], params[3]);
/* inverse of q mod p */
mhd_gtls_mpi_print_lz (NULL, &size[5], u);
MHD_gtls_mpi_print_lz (NULL, &size[5], u);
total += size[5];
_gnutls_mpi_sub_ui (p1, params[3], 1);
_gnutls_mpi_sub_ui (q1, params[4], 1);
MHD__gnutls_mpi_sub_ui (p1, params[3], 1);
MHD__gnutls_mpi_sub_ui (q1, params[4], 1);
_gnutls_mpi_mod (exp1, params[2], p1);
_gnutls_mpi_mod (exp2, params[2], q1);
MHD__gnutls_mpi_mod (exp1, params[2], p1);
MHD__gnutls_mpi_mod (exp2, params[2], q1);
/* calculate exp's size */
mhd_gtls_mpi_print_lz (NULL, &size[6], exp1);
MHD_gtls_mpi_print_lz (NULL, &size[6], exp1);
total += size[6];
mhd_gtls_mpi_print_lz (NULL, &size[7], exp2);
MHD_gtls_mpi_print_lz (NULL, &size[7], exp2);
total += size[7];
/* Encoding phase.
* allocate data enough to hold everything
*/
all_data = gnutls_secure_malloc (total);
all_data = MHD_gnutls_secure_malloc (total);
if (all_data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
@@ -587,124 +587,124 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
p += size[6];
exp2_data = p;
mhd_gtls_mpi_print_lz (m_data, &size[0], params[0]);
mhd_gtls_mpi_print_lz (pube_data, &size[1], params[1]);
mhd_gtls_mpi_print_lz (prie_data, &size[2], params[2]);
mhd_gtls_mpi_print_lz (p1_data, &size[3], params[3]);
mhd_gtls_mpi_print_lz (p2_data, &size[4], params[4]);
mhd_gtls_mpi_print_lz (u_data, &size[5], u);
mhd_gtls_mpi_print_lz (exp1_data, &size[6], exp1);
mhd_gtls_mpi_print_lz (exp2_data, &size[7], exp2);
MHD_gtls_mpi_print_lz (m_data, &size[0], params[0]);
MHD_gtls_mpi_print_lz (pube_data, &size[1], params[1]);
MHD_gtls_mpi_print_lz (prie_data, &size[2], params[2]);
MHD_gtls_mpi_print_lz (p1_data, &size[3], params[3]);
MHD_gtls_mpi_print_lz (p2_data, &size[4], params[4]);
MHD_gtls_mpi_print_lz (u_data, &size[5], u);
MHD_gtls_mpi_print_lz (exp1_data, &size[6], exp1);
MHD_gtls_mpi_print_lz (exp2_data, &size[7], exp2);
/* Ok. Now we have the data. Create the asn1 structures
*/
if ((result =
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.RSAPrivateKey",
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.RSAPrivateKey",
c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Write PRIME
*/
if ((result = asn1_write_value (*c2, "modulus", m_data, size[0]))
if ((result = MHD__asn1_write_value (*c2, "modulus", m_data, size[0]))
!= ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "publicExponent", pube_data, size[1]))
if ((result = MHD__asn1_write_value (*c2, "publicExponent", pube_data, size[1]))
!= ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "privateExponent", prie_data, size[2]))
if ((result = MHD__asn1_write_value (*c2, "privateExponent", prie_data, size[2]))
!= ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "prime1", p1_data, size[3]))
if ((result = MHD__asn1_write_value (*c2, "prime1", p1_data, size[3]))
!= ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "prime2", p2_data, size[4]))
if ((result = MHD__asn1_write_value (*c2, "prime2", p2_data, size[4]))
!= ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "exponent1", exp1_data, size[6]))
if ((result = MHD__asn1_write_value (*c2, "exponent1", exp1_data, size[6]))
!= ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "exponent2", exp2_data, size[7]))
if ((result = MHD__asn1_write_value (*c2, "exponent2", exp2_data, size[7]))
!= ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "coefficient", u_data, size[5]))
if ((result = MHD__asn1_write_value (*c2, "coefficient", u_data, size[5]))
!= ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
mhd_gtls_mpi_release (&exp1);
mhd_gtls_mpi_release (&exp2);
mhd_gtls_mpi_release (&q1);
mhd_gtls_mpi_release (&p1);
mhd_gtls_mpi_release (&u);
gnutls_free (all_data);
MHD_gtls_mpi_release (&exp1);
MHD_gtls_mpi_release (&exp2);
MHD_gtls_mpi_release (&q1);
MHD_gtls_mpi_release (&p1);
MHD_gtls_mpi_release (&u);
MHD_gnutls_free (all_data);
if ((result = asn1_write_value (*c2, "otherPrimeInfos",
if ((result = MHD__asn1_write_value (*c2, "otherPrimeInfos",
NULL, 0)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
if ((result = MHD__asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
return 0;
cleanup:mhd_gtls_mpi_release (&u);
mhd_gtls_mpi_release (&exp1);
mhd_gtls_mpi_release (&exp2);
mhd_gtls_mpi_release (&q1);
mhd_gtls_mpi_release (&p1);
asn1_delete_structure (c2);
gnutls_free (all_data);
cleanup:MHD_gtls_mpi_release (&u);
MHD_gtls_mpi_release (&exp1);
MHD_gtls_mpi_release (&exp2);
MHD_gtls_mpi_release (&q1);
MHD_gtls_mpi_release (&p1);
MHD__asn1_delete_structure (c2);
MHD_gnutls_free (all_data);
return result;
}
@@ -712,7 +712,7 @@ cleanup:mhd_gtls_mpi_release (&u);
/* Encodes the DSA parameters into an ASN.1 DSAPrivateKey structure.
*/
int
_gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
MHD__gnutlsMHD__asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
{
int result, i;
size_t size[DSA_PRIVATE_PARAMS], total;
@@ -724,17 +724,17 @@ _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
total = 0;
for (i = 0; i < DSA_PRIVATE_PARAMS; i++)
{
mhd_gtls_mpi_print_lz (NULL, &size[i], params[i]);
MHD_gtls_mpi_print_lz (NULL, &size[i], params[i]);
total += size[i];
}
/* Encoding phase.
* allocate data enough to hold everything
*/
all_data = gnutls_secure_malloc (total);
all_data = MHD_gnutls_secure_malloc (total);
if (all_data == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_MEMORY_ERROR;
goto cleanup;
}
@@ -750,82 +750,82 @@ _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
p += size[3];
x_data = p;
mhd_gtls_mpi_print_lz (p_data, &size[0], params[0]);
mhd_gtls_mpi_print_lz (q_data, &size[1], params[1]);
mhd_gtls_mpi_print_lz (g_data, &size[2], params[2]);
mhd_gtls_mpi_print_lz (y_data, &size[3], params[3]);
mhd_gtls_mpi_print_lz (x_data, &size[4], params[4]);
MHD_gtls_mpi_print_lz (p_data, &size[0], params[0]);
MHD_gtls_mpi_print_lz (q_data, &size[1], params[1]);
MHD_gtls_mpi_print_lz (g_data, &size[2], params[2]);
MHD_gtls_mpi_print_lz (y_data, &size[3], params[3]);
MHD_gtls_mpi_print_lz (x_data, &size[4], params[4]);
/* Ok. Now we have the data. Create the asn1 structures
*/
if ((result =
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.DSAPrivateKey",
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAPrivateKey",
c2)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
/* Write PRIME
*/
if ((result = asn1_write_value (*c2, "p", p_data, size[0])) != ASN1_SUCCESS)
if ((result = MHD__asn1_write_value (*c2, "p", p_data, size[0])) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "q", q_data, size[1])) != ASN1_SUCCESS)
if ((result = MHD__asn1_write_value (*c2, "q", q_data, size[1])) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "g", g_data, size[2])) != ASN1_SUCCESS)
if ((result = MHD__asn1_write_value (*c2, "g", g_data, size[2])) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result = asn1_write_value (*c2, "Y", y_data, size[3])) != ASN1_SUCCESS)
if ((result = MHD__asn1_write_value (*c2, "Y", y_data, size[3])) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
if ((result =
asn1_write_value (*c2, "priv", x_data, size[4])) != ASN1_SUCCESS)
MHD__asn1_write_value (*c2, "priv", x_data, size[4])) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
gnutls_free (all_data);
MHD_gnutls_free (all_data);
if ((result = asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
if ((result = MHD__asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
{
gnutls_assert ();
result = mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
result = MHD_gtls_asn2err (result);
goto cleanup;
}
return 0;
cleanup:asn1_delete_structure (c2);
gnutls_free (all_data);
cleanup:MHD__asn1_delete_structure (c2);
MHD_gnutls_free (all_data);
return result;
}
/**
* gnutls_x509_privkey_generate - This function will generate a private key
* @key: should contain a gnutls_x509_privkey_t structure
* MHD_gnutls_x509_privkey_generate - This function will generate a private key
* @key: should contain a MHD_gnutls_x509_privkey_t structure
* @algo: is one of RSA or DSA.
* @bits: the size of the modulus
* @flags: unused for now. Must be 0.
@@ -837,7 +837,7 @@ cleanup:asn1_delete_structure (c2);
*
**/
int
gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
MHD_gnutls_x509_privkey_generate (MHD_gnutls_x509_privkey_t key,
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
unsigned int bits, unsigned int flags)
{
@@ -846,26 +846,26 @@ gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
if (key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
switch (algo)
{
case MHD_GNUTLS_PK_RSA:
ret = _gnutls_rsa_generate_params (key->params, &params_len, bits);
ret = MHD__gnutls_rsa_generate_params (key->params, &params_len, bits);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
if (!key->crippled)
{
ret = _gnutls_asn1_encode_rsa (&key->key, key->params);
ret = MHD__gnutlsMHD__asn1_encode_rsa (&key->key, key->params);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
}
@@ -875,7 +875,7 @@ gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
break;
default:
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
@@ -884,13 +884,13 @@ gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
cleanup:key->pk_algorithm = MHD_GNUTLS_PK_UNKNOWN;
key->params_size = 0;
for (i = 0; i < params_len; i++)
mhd_gtls_mpi_release (&key->params[i]);
MHD_gtls_mpi_release (&key->params[i]);
return ret;
}
/**
* gnutls_x509_privkey_get_key_id - Return unique ID of the key's parameters
* MHD_gnutls_x509_privkey_get_key_id - Return unique ID of the key's parameters
* @key: Holds the key
* @flags: should be 0 for now
* @output_data: will contain the key ID
@@ -911,68 +911,68 @@ cleanup:key->pk_algorithm = MHD_GNUTLS_PK_UNKNOWN;
*
**/
int
gnutls_x509_privkey_get_key_id (gnutls_x509_privkey_t key,
MHD_gnutls_x509_privkey_get_key_id (MHD_gnutls_x509_privkey_t key,
unsigned int flags,
unsigned char *output_data,
size_t * output_data_size)
{
int result;
GNUTLS_HASH_HANDLE hd;
gnutls_datum_t der = { NULL,
MHD_gnutls_datum_t der = { NULL,
0
};
if (key == NULL || key->crippled)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (*output_data_size < 20)
{
gnutls_assert ();
MHD_gnutls_assert ();
*output_data_size = 20;
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
if (key->pk_algorithm == MHD_GNUTLS_PK_RSA)
{
result = _gnutls_x509_write_rsa_params (key->params, key->params_size,
result = MHD__gnutls_x509_write_rsa_params (key->params, key->params_size,
&der);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
}
else
return GNUTLS_E_INTERNAL_ERROR;
hd = mhd_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
hd = MHD_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
if (hd == GNUTLS_HASH_FAILED)
{
gnutls_assert ();
MHD_gnutls_assert ();
result = GNUTLS_E_INTERNAL_ERROR;
goto cleanup;
}
mhd_gnutls_hash (hd, der.data, der.size);
MHD_gnutls_hash (hd, der.data, der.size);
mhd_gnutls_hash_deinit (hd, output_data);
MHD_gnutls_hash_deinit (hd, output_data);
*output_data_size = 20;
result = 0;
cleanup:
_gnutls_free_datum (&der);
MHD__gnutls_free_datum (&der);
return result;
}
#ifdef ENABLE_PKI
/**
* gnutls_x509_privkey_sign_data - This function will sign the given data using the private key params
* MHD_gnutls_x509_privkey_sign_data - This function will sign the given data using the private key params
* @key: Holds the key
* @digest: should be MD5 or SHA1
* @flags: should be 0 for now
@@ -995,45 +995,45 @@ cleanup:
*
**/
int
gnutls_x509_privkey_sign_data (gnutls_x509_privkey_t key,
MHD_gnutls_x509_privkey_sign_data (MHD_gnutls_x509_privkey_t key,
enum MHD_GNUTLS_HashAlgorithm digest,
unsigned int flags,
const gnutls_datum_t * data,
const MHD_gnutls_datum_t * data,
void *signature, size_t * signature_size)
{
int result;
gnutls_datum_t sig = { NULL, 0 };
MHD_gnutls_datum_t sig = { NULL, 0 };
if (key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
result = _gnutls_x509_sign (data, digest, key, &sig);
result = MHD__gnutls_x509_sign (data, digest, key, &sig);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
if (*signature_size < sig.size)
{
*signature_size = sig.size;
_gnutls_free_datum (&sig);
MHD__gnutls_free_datum (&sig);
return GNUTLS_E_SHORT_MEMORY_BUFFER;
}
*signature_size = sig.size;
memcpy (signature, sig.data, sig.size);
_gnutls_free_datum (&sig);
MHD__gnutls_free_datum (&sig);
return 0;
}
/**
* gnutls_x509_privkey_sign_hash - This function will sign the given data using the private key params
* MHD_gnutls_x509_privkey_sign_hash - This function will sign the given data using the private key params
* @key: Holds the key
* @hash: holds the data to be signed
* @signature: will contain newly allocated signature
@@ -1044,23 +1044,23 @@ gnutls_x509_privkey_sign_data (gnutls_x509_privkey_t key,
* and 0 on success.
**/
int
gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
const gnutls_datum_t * hash,
gnutls_datum_t * signature)
MHD_gnutls_x509_privkey_sign_hash (MHD_gnutls_x509_privkey_t key,
const MHD_gnutls_datum_t * hash,
MHD_gnutls_datum_t * signature)
{
int result;
if (key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
result = mhd_gtls_sign (key->pk_algorithm, key->params,
result = MHD_gtls_sign (key->pk_algorithm, key->params,
key->params_size, hash, signature);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return result;
}
@@ -1068,7 +1068,7 @@ gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
}
/**
* gnutls_x509_privkey_verify_data - This function will verify the given signed data.
* MHD_gnutls_x509_privkey_verify_data - This function will verify the given signed data.
* @key: Holds the key
* @flags: should be 0 for now
* @data: holds the data to be signed
@@ -1082,23 +1082,23 @@ gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
*
**/
int
gnutls_x509_privkey_verify_data (gnutls_x509_privkey_t key,
MHD_gnutls_x509_privkey_verify_data (MHD_gnutls_x509_privkey_t key,
unsigned int flags,
const gnutls_datum_t * data,
const gnutls_datum_t * signature)
const MHD_gnutls_datum_t * data,
const MHD_gnutls_datum_t * signature)
{
int result;
if (key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
result = _gnutls_x509_privkey_verify_signature (data, signature, key);
result = MHD__gnutls_x509_privkey_verify_signature (data, signature, key);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return 0;
}
@@ -1106,7 +1106,7 @@ gnutls_x509_privkey_verify_data (gnutls_x509_privkey_t key,
}
/**
* gnutls_x509_privkey_fix - This function will recalculate some parameters of the key.
* MHD_gnutls_x509_privkey_fix - This function will recalculate some parameters of the key.
* @key: Holds the key
*
* This function will recalculate the secondary parameters in a key.
@@ -1117,30 +1117,30 @@ gnutls_x509_privkey_verify_data (gnutls_x509_privkey_t key,
*
**/
int
gnutls_x509_privkey_fix (gnutls_x509_privkey_t key)
MHD_gnutls_x509_privkey_fix (MHD_gnutls_x509_privkey_t key)
{
int ret;
if (key == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
if (!key->crippled)
asn1_delete_structure (&key->key);
MHD__asn1_delete_structure (&key->key);
switch (key->pk_algorithm)
{
case MHD_GNUTLS_PK_RSA:
ret = _gnutls_asn1_encode_rsa (&key->key, key->params);
ret = MHD__gnutlsMHD__asn1_encode_rsa (&key->key, key->params);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
break;
default:
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INVALID_REQUEST;
}
+193 -193
View File
@@ -41,19 +41,19 @@
#include <common.h>
#include <verify.h>
static int _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
const gnutls_x509_crt_t * trusted_cas,
static int MHD__gnutls_verify_certificate2 (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_x509_crt_t * trusted_cas,
int tcas_size,
unsigned int flags,
unsigned int *output);
int _gnutls_x509_verify_signature (const gnutls_datum_t * signed_data,
const gnutls_datum_t * signature,
gnutls_x509_crt_t issuer);
int MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * signed_data,
const MHD_gnutls_datum_t * signature,
MHD_gnutls_x509_crt_t issuer);
static
int is_crl_issuer (gnutls_x509_crl_t crl, gnutls_x509_crt_t issuer_cert);
static int _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
const gnutls_x509_crt_t * trusted_cas,
int is_crl_issuer (MHD_gnutls_x509_crl_t crl, MHD_gnutls_x509_crt_t issuer_cert);
static int MHD__gnutls_verify_crl2 (MHD_gnutls_x509_crl_t crl,
const MHD_gnutls_x509_crt_t * trusted_cas,
int tcas_size,
unsigned int flags, unsigned int *output);
@@ -65,19 +65,19 @@ static int _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
* or not.
*/
static int
check_if_ca (gnutls_x509_crt_t cert,
gnutls_x509_crt_t issuer, unsigned int flags)
check_if_ca (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_t issuer, unsigned int flags)
{
gnutls_datum_t cert_signed_data = { NULL,
MHD_gnutls_datum_t cert_signed_data = { NULL,
0
};
gnutls_datum_t issuer_signed_data = { NULL,
MHD_gnutls_datum_t issuer_signed_data = { NULL,
0
};
gnutls_datum_t cert_signature = { NULL,
MHD_gnutls_datum_t cert_signature = { NULL,
0
};
gnutls_datum_t issuer_signature = { NULL,
MHD_gnutls_datum_t issuer_signature = { NULL,
0
};
int result;
@@ -87,35 +87,35 @@ check_if_ca (gnutls_x509_crt_t cert,
* certificates to be able to verify themselves.
*/
result = _gnutls_x509_get_signed_data (issuer->cert, "tbsCertificate",
result = MHD__gnutls_x509_get_signed_data (issuer->cert, "tbsCertificate",
&issuer_signed_data);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
result = MHD__gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
&cert_signed_data);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_get_signature (issuer->cert, "signature",
result = MHD__gnutls_x509_get_signature (issuer->cert, "signature",
&issuer_signature);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result =
_gnutls_x509_get_signature (cert->cert, "signature", &cert_signature);
MHD__gnutls_x509_get_signature (cert->cert, "signature", &cert_signature);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
@@ -139,20 +139,20 @@ check_if_ca (gnutls_x509_crt_t cert,
}
}
if (gnutls_x509_crt_get_ca_status (issuer, NULL) == 1)
if (MHD_gnutls_x509_crt_get_ca_status (issuer, NULL) == 1)
{
result = 1;
goto cleanup;
}
else
gnutls_assert ();
MHD_gnutls_assert ();
result = 0;
cleanup:_gnutls_free_datum (&cert_signed_data);
_gnutls_free_datum (&issuer_signed_data);
_gnutls_free_datum (&cert_signature);
_gnutls_free_datum (&issuer_signature);
cleanup:MHD__gnutls_free_datum (&cert_signed_data);
MHD__gnutls_free_datum (&issuer_signed_data);
MHD__gnutls_free_datum (&cert_signature);
MHD__gnutls_free_datum (&issuer_signature);
return result;
}
@@ -164,40 +164,40 @@ cleanup:_gnutls_free_datum (&cert_signed_data);
* a negative value is returned to indicate error.
*/
static int
is_issuer (gnutls_x509_crt_t cert, gnutls_x509_crt_t issuer_cert)
is_issuer (MHD_gnutls_x509_crt_t cert, MHD_gnutls_x509_crt_t issuer_cert)
{
gnutls_datum_t dn1 = { NULL,
MHD_gnutls_datum_t dn1 = { NULL,
0
}, dn2 =
{
NULL, 0};
int ret;
ret = gnutls_x509_crt_get_raw_issuer_dn (cert, &dn1);
ret = MHD_gnutls_x509_crt_get_raw_issuer_dn (cert, &dn1);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
ret = gnutls_x509_crt_get_raw_dn (issuer_cert, &dn2);
ret = MHD_gnutls_x509_crt_get_raw_dn (issuer_cert, &dn2);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
ret = _gnutls_x509_compare_raw_dn (&dn1, &dn2);
ret = MHD__gnutls_x509_compare_raw_dn (&dn1, &dn2);
cleanup:_gnutls_free_datum (&dn1);
_gnutls_free_datum (&dn2);
cleanup:MHD__gnutls_free_datum (&dn1);
MHD__gnutls_free_datum (&dn2);
return ret;
}
static inline gnutls_x509_crt_t
find_issuer (gnutls_x509_crt_t cert,
const gnutls_x509_crt_t * trusted_cas, int tcas_size)
static inline MHD_gnutls_x509_crt_t
find_issuer (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_x509_crt_t * trusted_cas, int tcas_size)
{
int i;
@@ -210,7 +210,7 @@ find_issuer (gnutls_x509_crt_t cert,
return trusted_cas[i];
}
gnutls_assert ();
MHD_gnutls_assert ();
return NULL;
}
@@ -221,24 +221,24 @@ find_issuer (gnutls_x509_crt_t cert,
* Returns only 0 or 1. If 1 it means that the certificate
* was successfuly verified.
*
* 'flags': an OR of the gnutls_certificate_verify_flags enumeration.
* 'flags': an OR of the MHD_gnutls_certificate_verify_flags enumeration.
*
* Output will hold some extra information about the verification
* procedure.
*/
static int
_gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
const gnutls_x509_crt_t * trusted_cas,
MHD__gnutls_verify_certificate2 (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_x509_crt_t * trusted_cas,
int tcas_size,
unsigned int flags, unsigned int *output)
{
gnutls_datum_t cert_signed_data = { NULL,
MHD_gnutls_datum_t cert_signed_data = { NULL,
0
};
gnutls_datum_t cert_signature = { NULL,
MHD_gnutls_datum_t cert_signature = { NULL,
0
};
gnutls_x509_crt_t issuer;
MHD_gnutls_x509_crt_t issuer;
int ret, issuer_version, result;
if (output)
@@ -248,7 +248,7 @@ _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
issuer = find_issuer (cert, trusted_cas, tcas_size);
else
{
gnutls_assert ();
MHD_gnutls_assert ();
if (output)
*output |= GNUTLS_CERT_SIGNER_NOT_FOUND | GNUTLS_CERT_INVALID;
return 0;
@@ -261,14 +261,14 @@ _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
{
if (output)
*output |= GNUTLS_CERT_SIGNER_NOT_FOUND | GNUTLS_CERT_INVALID;
gnutls_assert ();
MHD_gnutls_assert ();
return 0;
}
issuer_version = gnutls_x509_crt_get_version (issuer);
issuer_version = MHD_gnutls_x509_crt_get_version (issuer);
if (issuer_version < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return issuer_version;
}
@@ -279,38 +279,38 @@ _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
{
if (check_if_ca (cert, issuer, flags) == 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
if (output)
*output |= GNUTLS_CERT_SIGNER_NOT_CA | GNUTLS_CERT_INVALID;
return 0;
}
}
result = _gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
result = MHD__gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
&cert_signed_data);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result =
_gnutls_x509_get_signature (cert->cert, "signature", &cert_signature);
MHD__gnutls_x509_get_signature (cert->cert, "signature", &cert_signature);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
ret = _gnutls_x509_verify_signature (&cert_signed_data, &cert_signature,
ret = MHD__gnutls_x509_verify_signature (&cert_signed_data, &cert_signature,
issuer);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
}
else if (ret == 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
/* error. ignore it */
if (output)
*output |= GNUTLS_CERT_INVALID;
@@ -325,7 +325,7 @@ _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
{
int sigalg;
sigalg = gnutls_x509_crt_get_signature_algorithm (cert);
sigalg = MHD_gnutls_x509_crt_get_signature_algorithm (cert);
if (((sigalg == GNUTLS_SIGN_RSA_MD2) && !(flags
&
@@ -340,14 +340,14 @@ _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
result = ret;
cleanup:_gnutls_free_datum (&cert_signed_data);
_gnutls_free_datum (&cert_signature);
cleanup:MHD__gnutls_free_datum (&cert_signed_data);
MHD__gnutls_free_datum (&cert_signature);
return result;
}
/**
* gnutls_x509_crt_check_issuer - This function checks if the certificate given has the given issuer
* MHD_gnutls_x509_crt_check_issuer - This function checks if the certificate given has the given issuer
* @cert: is the certificate to be checked
* @issuer: is the certificate of a possible issuer
*
@@ -359,8 +359,8 @@ cleanup:_gnutls_free_datum (&cert_signed_data);
*
**/
int
gnutls_x509_crt_check_issuer (gnutls_x509_crt_t cert,
gnutls_x509_crt_t issuer)
MHD_gnutls_x509_crt_check_issuer (MHD_gnutls_x509_crt_t cert,
MHD_gnutls_x509_crt_t issuer)
{
return is_issuer (cert, issuer);
}
@@ -377,11 +377,11 @@ gnutls_x509_crt_check_issuer (gnutls_x509_crt_t cert,
* lead to a trusted CA in order to be trusted.
*/
static unsigned int
_gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
MHD__gnutls_x509_verify_certificate (const MHD_gnutls_x509_crt_t * certificate_list,
int clist_size,
const gnutls_x509_crt_t * trusted_cas,
const MHD_gnutls_x509_crt_t * trusted_cas,
int tcas_size,
const gnutls_x509_crl_t * CRLs,
const MHD_gnutls_x509_crl_t * CRLs,
int crls_size, unsigned int flags)
{
int i = 0, ret;
@@ -393,7 +393,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
* If no CAs are present returns CERT_INVALID. Thus works
* in self signed etc certificates.
*/
ret = _gnutls_verify_certificate2 (certificate_list[clist_size - 1],
ret = MHD__gnutls_verify_certificate2 (certificate_list[clist_size - 1],
trusted_cas, tcas_size, flags, &output);
if (ret == 0)
@@ -402,7 +402,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
* list is invalid, then the certificate is not
* trusted.
*/
gnutls_assert ();
MHD_gnutls_assert ();
status |= output;
status |= GNUTLS_CERT_INVALID;
return status;
@@ -413,7 +413,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
#ifdef ENABLE_PKI
for (i = 0; i < clist_size; i++)
{
ret = gnutls_x509_crt_check_revocation (certificate_list[i],
ret = MHD_gnutls_x509_crt_check_revocation (certificate_list[i],
CRLs, crls_size);
if (ret == 1)
{ /* revoked */
@@ -428,7 +428,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
* In that case ignore it (a certificate is trusted only if it
* leads to a trusted party by us, not the server's).
*/
if (gnutls_x509_crt_check_issuer (certificate_list[clist_size - 1],
if (MHD_gnutls_x509_crt_check_issuer (certificate_list[clist_size - 1],
certificate_list[clist_size - 1]) > 0
&& clist_size > 0)
{
@@ -447,7 +447,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
*/
if (!(flags & GNUTLS_VERIFY_ALLOW_ANY_X509_V1_CA_CRT))
flags ^= GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT;
if ((ret = _gnutls_verify_certificate2 (certificate_list[i - 1],
if ((ret = MHD__gnutls_verify_certificate2 (certificate_list[i - 1],
&certificate_list[i], 1, flags,
NULL)) == 0)
{
@@ -464,7 +464,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
* anyway.
*/
static int
decode_ber_digest_info (const gnutls_datum_t * info,
decode_ber_digest_info (const MHD_gnutls_datum_t * info,
enum MHD_GNUTLS_HashAlgorithm *hash,
opaque * digest, int *digest_size)
{
@@ -473,45 +473,45 @@ decode_ber_digest_info (const gnutls_datum_t * info,
char str[1024];
int len;
if ((result = asn1_create_element (_gnutls_get_gnutls_asn (),
if ((result = MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
"GNUTLS.DigestInfo",
&dinfo)) != ASN1_SUCCESS)
{
gnutls_assert ();
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
return MHD_gtls_asn2err (result);
}
result = asn1_der_decoding (&dinfo, info->data, info->size, NULL);
result = MHD__asn1_der_decoding (&dinfo, info->data, info->size, NULL);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&dinfo);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dinfo);
return MHD_gtls_asn2err (result);
}
len = sizeof (str) - 1;
result = asn1_read_value (dinfo, "digestAlgorithm.algorithm", str, &len);
result = MHD__asn1_read_value (dinfo, "digestAlgorithm.algorithm", str, &len);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&dinfo);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dinfo);
return MHD_gtls_asn2err (result);
}
*hash = mhd_gtls_x509_oid2mac_algorithm (str);
*hash = MHD_gtls_x509_oid2mac_algorithm (str);
if (*hash == MHD_GNUTLS_MAC_UNKNOWN)
{
_gnutls_x509_log ("verify.c: HASH OID: %s\n", str);
MHD__gnutls_x509_log ("verify.c: HASH OID: %s\n", str);
gnutls_assert ();
asn1_delete_structure (&dinfo);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dinfo);
return GNUTLS_E_UNKNOWN_ALGORITHM;
}
len = sizeof (str) - 1;
result = asn1_read_value (dinfo, "digestAlgorithm.parameters", str, &len);
result = MHD__asn1_read_value (dinfo, "digestAlgorithm.parameters", str, &len);
/* To avoid permitting garbage in the parameters field, either the
parameters field is not present, or it contains 0x05 0x00. */
if (!
@@ -519,20 +519,20 @@ decode_ber_digest_info (const gnutls_datum_t * info,
|| (result == ASN1_SUCCESS && len == 2 && str[0] == 0x05
&& str[1] == 0x00)))
{
gnutls_assert ();
asn1_delete_structure (&dinfo);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dinfo);
return GNUTLS_E_ASN1_GENERIC_ERROR;
}
result = asn1_read_value (dinfo, "digest", digest, digest_size);
result = MHD__asn1_read_value (dinfo, "digest", digest, digest_size);
if (result != ASN1_SUCCESS)
{
gnutls_assert ();
asn1_delete_structure (&dinfo);
return mhd_gtls_asn2err (result);
MHD_gnutls_assert ();
MHD__asn1_delete_structure (&dinfo);
return MHD_gtls_asn2err (result);
}
asn1_delete_structure (&dinfo);
MHD__asn1_delete_structure (&dinfo);
return 0;
}
@@ -543,8 +543,8 @@ decode_ber_digest_info (const gnutls_datum_t * info,
* params[1] is public key
*/
static int
_pkcs1_rsa_verify_sig (const gnutls_datum_t * text,
const gnutls_datum_t * signature,
_pkcs1_rsa_verify_sig (const MHD_gnutls_datum_t * text,
const MHD_gnutls_datum_t * signature,
mpi_t * params, int params_len)
{
enum MHD_GNUTLS_HashAlgorithm hash = MHD_GNUTLS_MAC_UNKNOWN;
@@ -552,13 +552,13 @@ _pkcs1_rsa_verify_sig (const gnutls_datum_t * text,
opaque digest[MAX_HASH_SIZE], md[MAX_HASH_SIZE];
int digest_size;
GNUTLS_HASH_HANDLE hd;
gnutls_datum_t decrypted;
MHD_gnutls_datum_t decrypted;
ret =
mhd_gtls_pkcs1_rsa_decrypt (&decrypted, signature, params, params_len, 1);
MHD_gtls_pkcs1_rsa_decrypt (&decrypted, signature, params, params_len, 1);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -569,32 +569,32 @@ _pkcs1_rsa_verify_sig (const gnutls_datum_t * text,
if ((ret = decode_ber_digest_info (&decrypted, &hash, digest, &digest_size))
!= 0)
{
gnutls_assert ();
_gnutls_free_datum (&decrypted);
MHD_gnutls_assert ();
MHD__gnutls_free_datum (&decrypted);
return ret;
}
_gnutls_free_datum (&decrypted);
MHD__gnutls_free_datum (&decrypted);
if (digest_size != mhd_gnutls_hash_get_algo_len (hash))
if (digest_size != MHD_gnutls_hash_get_algo_len (hash))
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_ASN1_GENERIC_ERROR;
}
hd = mhd_gtls_hash_init (hash);
hd = MHD_gtls_hash_init (hash);
if (hd == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_HASH_FAILED;
}
mhd_gnutls_hash (hd, text->data, text->size);
mhd_gnutls_hash_deinit (hd, md);
MHD_gnutls_hash (hd, text->data, text->size);
MHD_gnutls_hash_deinit (hd, md);
if (memcmp (md, digest, digest_size) != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_PK_SIG_VERIFY_FAILED;
}
@@ -604,29 +604,29 @@ _pkcs1_rsa_verify_sig (const gnutls_datum_t * text,
/* Hashes input data and verifies a DSA signature.
*/
static int
dsa_verify_sig (const gnutls_datum_t * text,
const gnutls_datum_t * signature,
dsa_verify_sig (const MHD_gnutls_datum_t * text,
const MHD_gnutls_datum_t * signature,
mpi_t * params, int params_len)
{
int ret;
opaque _digest[MAX_HASH_SIZE];
gnutls_datum_t digest;
MHD_gnutls_datum_t digest;
GNUTLS_HASH_HANDLE hd;
hd = mhd_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
hd = MHD_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
if (hd == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_HASH_FAILED;
}
mhd_gnutls_hash (hd, text->data, text->size);
mhd_gnutls_hash_deinit (hd, _digest);
MHD_gnutls_hash (hd, text->data, text->size);
MHD_gnutls_hash_deinit (hd, _digest);
digest.data = _digest;
digest.size = 20;
ret = mhd_gtls_dsa_verify (&digest, signature, params, params_len);
ret = MHD_gtls_dsa_verify (&digest, signature, params, params_len);
return ret;
}
@@ -635,8 +635,8 @@ dsa_verify_sig (const gnutls_datum_t * text,
* or 1 otherwise.
*/
static int
verify_sig (const gnutls_datum_t * tbs,
const gnutls_datum_t * signature,
verify_sig (const MHD_gnutls_datum_t * tbs,
const MHD_gnutls_datum_t * signature,
enum MHD_GNUTLS_PublicKeyAlgorithm pk,
mpi_t * issuer_params, int issuer_params_size)
{
@@ -648,7 +648,7 @@ verify_sig (const gnutls_datum_t * tbs,
if (_pkcs1_rsa_verify_sig
(tbs, signature, issuer_params, issuer_params_size) != 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return 0;
}
@@ -656,7 +656,7 @@ verify_sig (const gnutls_datum_t * tbs,
break;
default:
gnutls_assert ();
MHD_gnutls_assert ();
return GNUTLS_E_INTERNAL_ERROR;
}
@@ -669,9 +669,9 @@ verify_sig (const gnutls_datum_t * tbs,
* 'signature' is the signature!
*/
int
_gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
const gnutls_datum_t * signature,
gnutls_x509_crt_t issuer)
MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * tbs,
const MHD_gnutls_datum_t * signature,
MHD_gnutls_x509_crt_t issuer)
{
mpi_t issuer_params[MAX_PUBLIC_PARAMS_SIZE];
int ret, issuer_params_size, i;
@@ -680,26 +680,26 @@ _gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
*/
issuer_params_size = MAX_PUBLIC_PARAMS_SIZE;
ret =
_gnutls_x509_crt_get_mpis (issuer, issuer_params, &issuer_params_size);
MHD__gnutls_x509_crt_get_mpis (issuer, issuer_params, &issuer_params_size);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
ret = verify_sig (tbs, signature, gnutls_x509_crt_get_pk_algorithm (issuer,
ret = verify_sig (tbs, signature, MHD_gnutls_x509_crt_get_pk_algorithm (issuer,
NULL),
issuer_params, issuer_params_size);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
}
/* release all allocated MPIs
*/
for (i = 0; i < issuer_params_size; i++)
{
mhd_gtls_mpi_release (&issuer_params[i]);
MHD_gtls_mpi_release (&issuer_params[i]);
}
return ret;
@@ -712,9 +712,9 @@ _gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
* 'signature' is the signature!
*/
int
_gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
const gnutls_datum_t * signature,
gnutls_x509_privkey_t issuer)
MHD__gnutls_x509_privkey_verify_signature (const MHD_gnutls_datum_t * tbs,
const MHD_gnutls_datum_t * signature,
MHD_gnutls_x509_privkey_t issuer)
{
int ret;
@@ -722,21 +722,21 @@ _gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
issuer->params_size);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
}
return ret;
}
/**
* gnutls_x509_crt_list_verify - This function verifies the given certificate list
* MHD_gnutls_x509_crt_list_verify - This function verifies the given certificate list
* @cert_list: is the certificate list to be verified
* @cert_list_length: holds the number of certificate in cert_list
* @CA_list: is the CA list which will be used in verification
* @CA_list_length: holds the number of CA certificate in CA_list
* @CRL_list: holds a list of CRLs.
* @CRL_list_length: the length of CRL list.
* @flags: Flags that may be used to change the verification algorithm. Use OR of the gnutls_certificate_verify_flags enumerations.
* @flags: Flags that may be used to change the verification algorithm. Use OR of the MHD_gnutls_certificate_verify_flags enumerations.
* @verify: will hold the certificate verification output.
*
* This function will try to verify the given certificate list and return its status.
@@ -751,8 +751,8 @@ _gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
* certificate belongs to the actual peer.
*
* The certificate verification output will be put in @verify and will be
* one or more of the gnutls_certificate_status_t enumerated elements bitwise or'd.
* For a more detailed verification status use gnutls_x509_crt_verify() per list
* one or more of the MHD_gnutls_certificate_status_t enumerated elements bitwise or'd.
* For a more detailed verification status use MHD_gnutls_x509_crt_verify() per list
* element.
*
* GNUTLS_CERT_INVALID: the certificate chain is not valid.
@@ -763,11 +763,11 @@ _gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
*
**/
int
gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
MHD_gnutls_x509_crt_list_verify (const MHD_gnutls_x509_crt_t * cert_list,
int cert_list_length,
const gnutls_x509_crt_t * CA_list,
const MHD_gnutls_x509_crt_t * CA_list,
int CA_list_length,
const gnutls_x509_crl_t * CRL_list,
const MHD_gnutls_x509_crl_t * CRL_list,
int CRL_list_length,
unsigned int flags, unsigned int *verify)
{
@@ -776,7 +776,7 @@ gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
/* Verify certificate
*/
*verify = _gnutls_x509_verify_certificate (cert_list, cert_list_length,
*verify = MHD__gnutls_x509_verify_certificate (cert_list, cert_list_length,
CA_list, CA_list_length,
CRL_list, CRL_list_length,
flags);
@@ -785,11 +785,11 @@ gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
}
/**
* gnutls_x509_crt_verify - This function verifies the given certificate against a given trusted one
* MHD_gnutls_x509_crt_verify - This function verifies the given certificate against a given trusted one
* @cert: is the certificate to be verified
* @CA_list: is one certificate that is considered to be trusted one
* @CA_list_length: holds the number of CA certificate in CA_list
* @flags: Flags that may be used to change the verification algorithm. Use OR of the gnutls_certificate_verify_flags enumerations.
* @flags: Flags that may be used to change the verification algorithm. Use OR of the MHD_gnutls_certificate_verify_flags enumerations.
* @verify: will hold the certificate verification output.
*
* This function will try to verify the given certificate and return its status.
@@ -799,19 +799,19 @@ gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
*
**/
int
gnutls_x509_crt_verify (gnutls_x509_crt_t cert,
const gnutls_x509_crt_t * CA_list,
MHD_gnutls_x509_crt_verify (MHD_gnutls_x509_crt_t cert,
const MHD_gnutls_x509_crt_t * CA_list,
int CA_list_length,
unsigned int flags, unsigned int *verify)
{
int ret;
/* Verify certificate
*/
ret = _gnutls_verify_certificate2 (cert, CA_list, CA_list_length, flags,
ret = MHD__gnutls_verify_certificate2 (cert, CA_list, CA_list_length, flags,
verify);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -821,7 +821,7 @@ gnutls_x509_crt_verify (gnutls_x509_crt_t cert,
#ifdef ENABLE_PKI
/**
* gnutls_x509_crl_check_issuer - This function checks if the CRL given has the given issuer
* MHD_gnutls_x509_crl_check_issuer - This function checks if the CRL given has the given issuer
* @crl: is the CRL to be checked
* @issuer: is the certificate of a possible issuer
*
@@ -833,40 +833,40 @@ gnutls_x509_crt_verify (gnutls_x509_crt_t cert,
*
**/
int
gnutls_x509_crl_check_issuer (gnutls_x509_crl_t cert,
gnutls_x509_crt_t issuer)
MHD_gnutls_x509_crl_check_issuer (MHD_gnutls_x509_crl_t cert,
MHD_gnutls_x509_crt_t issuer)
{
return is_crl_issuer (cert, issuer);
}
/**
* gnutls_x509_crl_verify - This function verifies the given crl against a given trusted one
* MHD_gnutls_x509_crl_verify - This function verifies the given crl against a given trusted one
* @crl: is the crl to be verified
* @CA_list: is a certificate list that is considered to be trusted one
* @CA_list_length: holds the number of CA certificates in CA_list
* @flags: Flags that may be used to change the verification algorithm. Use OR of the gnutls_certificate_verify_flags enumerations.
* @flags: Flags that may be used to change the verification algorithm. Use OR of the MHD_gnutls_certificate_verify_flags enumerations.
* @verify: will hold the crl verification output.
*
* This function will try to verify the given crl and return its status.
* See gnutls_x509_crt_list_verify() for a detailed description of
* See MHD_gnutls_x509_crt_list_verify() for a detailed description of
* return values.
*
* Returns 0 on success and a negative value in case of an error.
*
**/
int
gnutls_x509_crl_verify (gnutls_x509_crl_t crl,
const gnutls_x509_crt_t * CA_list,
MHD_gnutls_x509_crl_verify (MHD_gnutls_x509_crl_t crl,
const MHD_gnutls_x509_crt_t * CA_list,
int CA_list_length, unsigned int flags,
unsigned int *verify)
{
int ret;
/* Verify crl
*/
ret = _gnutls_verify_crl2 (crl, CA_list, CA_list_length, flags, verify);
ret = MHD__gnutls_verify_crl2 (crl, CA_list, CA_list_length, flags, verify);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
@@ -876,39 +876,39 @@ gnutls_x509_crl_verify (gnutls_x509_crl_t crl,
/* The same as above, but here we've got a CRL.
*/
static int
is_crl_issuer (gnutls_x509_crl_t crl, gnutls_x509_crt_t issuer_cert)
is_crl_issuer (MHD_gnutls_x509_crl_t crl, MHD_gnutls_x509_crt_t issuer_cert)
{
gnutls_datum_t dn1 = { NULL, 0 }, dn2 =
MHD_gnutls_datum_t dn1 = { NULL, 0 }, dn2 =
{
NULL, 0};
int ret;
ret = _gnutls_x509_crl_get_raw_issuer_dn (crl, &dn1);
ret = MHD__gnutls_x509_crl_get_raw_issuer_dn (crl, &dn1);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
ret = gnutls_x509_crt_get_raw_dn (issuer_cert, &dn2);
ret = MHD_gnutls_x509_crt_get_raw_dn (issuer_cert, &dn2);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
return ret;
}
ret = _gnutls_x509_compare_raw_dn (&dn1, &dn2);
ret = MHD__gnutls_x509_compare_raw_dn (&dn1, &dn2);
cleanup:
_gnutls_free_datum (&dn1);
_gnutls_free_datum (&dn2);
MHD__gnutls_free_datum (&dn1);
MHD__gnutls_free_datum (&dn2);
return ret;
}
static inline gnutls_x509_crt_t
find_crl_issuer (gnutls_x509_crl_t crl,
const gnutls_x509_crt_t * trusted_cas, int tcas_size)
static inline MHD_gnutls_x509_crt_t
find_crl_issuer (MHD_gnutls_x509_crl_t crl,
const MHD_gnutls_x509_crt_t * trusted_cas, int tcas_size)
{
int i;
@@ -921,7 +921,7 @@ find_crl_issuer (gnutls_x509_crl_t crl,
return trusted_cas[i];
}
gnutls_assert ();
MHD_gnutls_assert ();
return NULL;
}
@@ -929,20 +929,20 @@ find_crl_issuer (gnutls_x509_crl_t crl,
* Returns only 0 or 1. If 1 it means that the CRL
* was successfuly verified.
*
* 'flags': an OR of the gnutls_certificate_verify_flags enumeration.
* 'flags': an OR of the MHD_gnutls_certificate_verify_flags enumeration.
*
* Output will hold information about the verification
* procedure.
*/
static int
_gnutls_verify_crl2 (gnutls_x509_crl_t crl,
const gnutls_x509_crt_t * trusted_cas,
MHD__gnutls_verify_crl2 (MHD_gnutls_x509_crl_t crl,
const MHD_gnutls_x509_crt_t * trusted_cas,
int tcas_size, unsigned int flags, unsigned int *output)
{
/* CRL is ignored for now */
gnutls_datum_t crl_signed_data = { NULL, 0 };
gnutls_datum_t crl_signature = { NULL, 0 };
gnutls_x509_crt_t issuer;
MHD_gnutls_datum_t crl_signed_data = { NULL, 0 };
MHD_gnutls_datum_t crl_signature = { NULL, 0 };
MHD_gnutls_x509_crt_t issuer;
int ret, result;
if (output)
@@ -952,7 +952,7 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
issuer = find_crl_issuer (crl, trusted_cas, tcas_size);
else
{
gnutls_assert ();
MHD_gnutls_assert ();
if (output)
*output |= GNUTLS_CERT_SIGNER_NOT_FOUND | GNUTLS_CERT_INVALID;
return 0;
@@ -963,7 +963,7 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
*/
if (issuer == NULL)
{
gnutls_assert ();
MHD_gnutls_assert ();
if (output)
*output |= GNUTLS_CERT_SIGNER_NOT_FOUND | GNUTLS_CERT_INVALID;
return 0;
@@ -971,9 +971,9 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
if (!(flags & GNUTLS_VERIFY_DISABLE_CA_SIGN))
{
if (gnutls_x509_crt_get_ca_status (issuer, NULL) != 1)
if (MHD_gnutls_x509_crt_get_ca_status (issuer, NULL) != 1)
{
gnutls_assert ();
MHD_gnutls_assert ();
if (output)
*output |= GNUTLS_CERT_SIGNER_NOT_CA | GNUTLS_CERT_INVALID;
return 0;
@@ -981,29 +981,29 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
}
result =
_gnutls_x509_get_signed_data (crl->crl, "tbsCertList", &crl_signed_data);
MHD__gnutls_x509_get_signed_data (crl->crl, "tbsCertList", &crl_signed_data);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
result = _gnutls_x509_get_signature (crl->crl, "signature", &crl_signature);
result = MHD__gnutls_x509_get_signature (crl->crl, "signature", &crl_signature);
if (result < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
goto cleanup;
}
ret =
_gnutls_x509_verify_signature (&crl_signed_data, &crl_signature, issuer);
MHD__gnutls_x509_verify_signature (&crl_signed_data, &crl_signature, issuer);
if (ret < 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
}
else if (ret == 0)
{
gnutls_assert ();
MHD_gnutls_assert ();
/* error. ignore it */
if (output)
*output |= GNUTLS_CERT_INVALID;
@@ -1013,7 +1013,7 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
{
int sigalg;
sigalg = gnutls_x509_crl_get_signature_algorithm (crl);
sigalg = MHD_gnutls_x509_crl_get_signature_algorithm (crl);
if (((sigalg == GNUTLS_SIGN_RSA_MD2) &&
!(flags & GNUTLS_VERIFY_ALLOW_SIGN_RSA_MD2)) ||
@@ -1028,8 +1028,8 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
result = ret;
cleanup:
_gnutls_free_datum (&crl_signed_data);
_gnutls_free_datum (&crl_signature);
MHD__gnutls_free_datum (&crl_signed_data);
MHD__gnutls_free_datum (&crl_signature);
return result;
}