mirror of
https://git.gnunet.org/libmicrohttpd.git
synced 2026-10-07 04:02:18 +03:00
mega-renaming to avoid exporting symbols not starting with MHD
This commit is contained in:
1 parent
7ba36f02ae
commit
6ff7b62145
156 files changed
+9535
-9575
No files matched your search
+242
-242
@@ -170,7 +170,7 @@ static const oid2string _oid2str[] = {
|
||||
/* Returns 1 if the data defined by the OID are printable.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_oid_data_printable (const char *oid)
|
||||
MHD__gnutls_x509_oid_data_printable (const char *oid)
|
||||
{
|
||||
int i = 0;
|
||||
|
||||
@@ -186,11 +186,11 @@ _gnutls_x509_oid_data_printable (const char *oid)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_dn_oid_known - This function will return true if the given OID is known
|
||||
* MHD_gnutls_x509_dn_oid_known - This function will return true if the given OID is known
|
||||
* @oid: holds an Object Identifier in a null terminated string
|
||||
*
|
||||
* This function will inform about known DN OIDs. This is useful since functions
|
||||
* like gnutls_x509_crt_set_dn_by_oid() use the information on known
|
||||
* like MHD_gnutls_x509_crt_set_dn_by_oid() use the information on known
|
||||
* OIDs to properly encode their input. Object Identifiers that are not
|
||||
* known are not encoded by these functions, and their input is stored directly
|
||||
* into the ASN.1 structure. In that case of unknown OIDs, you have
|
||||
@@ -200,7 +200,7 @@ _gnutls_x509_oid_data_printable (const char *oid)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_dn_oid_known (const char *oid)
|
||||
MHD_gnutls_x509_dn_oid_known (const char *oid)
|
||||
{
|
||||
int i = 0;
|
||||
|
||||
@@ -219,7 +219,7 @@ gnutls_x509_dn_oid_known (const char *oid)
|
||||
* type.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_oid_data_choice (const char *oid)
|
||||
MHD__gnutls_x509_oid_data_choice (const char *oid)
|
||||
{
|
||||
int i = 0;
|
||||
|
||||
@@ -235,7 +235,7 @@ _gnutls_x509_oid_data_choice (const char *oid)
|
||||
}
|
||||
|
||||
const char *
|
||||
_gnutls_x509_oid2ldap_string (const char *oid)
|
||||
MHD__gnutls_x509_oid2ldap_string (const char *oid)
|
||||
{
|
||||
int i = 0;
|
||||
|
||||
@@ -257,7 +257,7 @@ _gnutls_x509_oid2ldap_string (const char *oid)
|
||||
* hold the string.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_oid_data2string (const char *oid,
|
||||
MHD__gnutls_x509_oid_data2string (const char *oid,
|
||||
void *value,
|
||||
int value_size, char *res, size_t * res_size)
|
||||
{
|
||||
@@ -265,57 +265,57 @@ _gnutls_x509_oid_data2string (const char *oid,
|
||||
const char *ANAME = NULL;
|
||||
int CHOICE = -1, len = -1, result;
|
||||
ASN1_TYPE tmpasn = ASN1_TYPE_EMPTY;
|
||||
char asn1_err[MAX_ERROR_DESCRIPTION_SIZE] = "";
|
||||
char MHD__asn1_err[MAX_ERROR_DESCRIPTION_SIZE] = "";
|
||||
|
||||
if (value == NULL || value_size <= 0 || res_size == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (_gnutls_x509_oid_data_printable (oid) == 0)
|
||||
if (MHD__gnutls_x509_oid_data_printable (oid) == 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
ANAME = asn1_find_structure_from_oid (_gnutls_get_pkix (), oid);
|
||||
CHOICE = _gnutls_x509_oid_data_choice (oid);
|
||||
ANAME = MHD__asn1_find_structure_from_oid (MHD__gnutls_get_pkix (), oid);
|
||||
CHOICE = MHD__gnutls_x509_oid_data_choice (oid);
|
||||
|
||||
if (ANAME == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
mhd_gtls_str_cpy (str, sizeof (str), "PKIX1.");
|
||||
mhd_gtls_str_cat (str, sizeof (str), ANAME);
|
||||
MHD_gtls_str_cpy (str, sizeof (str), "PKIX1.");
|
||||
MHD_gtls_str_cat (str, sizeof (str), ANAME);
|
||||
|
||||
if ((result = asn1_create_element (_gnutls_get_pkix (), str,
|
||||
if ((result = MHD__asn1_create_element (MHD__gnutls_get_pkix (), str,
|
||||
&tmpasn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if ((result = asn1_der_decoding (&tmpasn, value, value_size, asn1_err))
|
||||
if ((result = MHD__asn1_der_decoding (&tmpasn, value, value_size, MHD__asn1_err))
|
||||
!= ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log ("asn1_der_decoding: %s:%s\n", str, asn1_err);
|
||||
asn1_delete_structure (&tmpasn);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_x509_log ("MHD__asn1_der_decoding: %s:%s\n", str, MHD__asn1_err);
|
||||
MHD__asn1_delete_structure (&tmpasn);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* If this is a choice then we read the choice. Otherwise it
|
||||
* is the value;
|
||||
*/
|
||||
len = sizeof (str) - 1;
|
||||
if ((result = asn1_read_value (tmpasn, "", str, &len)) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_read_value (tmpasn, "", str, &len)) != ASN1_SUCCESS)
|
||||
{ /* CHOICE */
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&tmpasn);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&tmpasn);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (CHOICE == 0)
|
||||
@@ -323,10 +323,10 @@ _gnutls_x509_oid_data2string (const char *oid,
|
||||
str[len] = 0;
|
||||
|
||||
if (res)
|
||||
mhd_gtls_str_cpy (res, *res_size, str);
|
||||
MHD_gtls_str_cpy (res, *res_size, str);
|
||||
*res_size = len;
|
||||
|
||||
asn1_delete_structure (&tmpasn);
|
||||
MHD__asn1_delete_structure (&tmpasn);
|
||||
}
|
||||
else
|
||||
{ /* CHOICE */
|
||||
@@ -345,17 +345,17 @@ _gnutls_x509_oid_data2string (const char *oid,
|
||||
if (strcmp (str, "teletexString") == 0)
|
||||
teletex = 1;
|
||||
|
||||
mhd_gtls_str_cpy (tmpname, sizeof (tmpname), str);
|
||||
MHD_gtls_str_cpy (tmpname, sizeof (tmpname), str);
|
||||
|
||||
len = sizeof (str) - 1;
|
||||
if ((result = asn1_read_value (tmpasn, tmpname, str, &len))
|
||||
if ((result = MHD__asn1_read_value (tmpasn, tmpname, str, &len))
|
||||
!= ASN1_SUCCESS)
|
||||
{
|
||||
asn1_delete_structure (&tmpasn);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD__asn1_delete_structure (&tmpasn);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
asn1_delete_structure (&tmpasn);
|
||||
MHD__asn1_delete_structure (&tmpasn);
|
||||
|
||||
if (teletex != 0)
|
||||
{
|
||||
@@ -376,15 +376,15 @@ _gnutls_x509_oid_data2string (const char *oid,
|
||||
if (non_printable == 0)
|
||||
{
|
||||
str[len] = 0;
|
||||
mhd_gtls_str_cpy (res, *res_size, str);
|
||||
MHD_gtls_str_cpy (res, *res_size, str);
|
||||
*res_size = len;
|
||||
}
|
||||
else
|
||||
{
|
||||
result = _gnutls_x509_data2hex (str, len, res, res_size);
|
||||
result = MHD__gnutls_x509_data2hex (str, len, res, res_size);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
}
|
||||
@@ -399,7 +399,7 @@ _gnutls_x509_oid_data2string (const char *oid,
|
||||
* something like '#01020304'
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_data2hex (const opaque * data,
|
||||
MHD__gnutls_x509_data2hex (const opaque * data,
|
||||
size_t data_size, opaque * out, size_t * sizeof_out)
|
||||
{
|
||||
char *res;
|
||||
@@ -407,11 +407,11 @@ _gnutls_x509_data2hex (const opaque * data,
|
||||
|
||||
if (2 * data_size + 1 > MAX_STRING_LEN)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
res = mhd_gtls_bin2hex (data, data_size, escaped, sizeof (escaped));
|
||||
res = MHD_gtls_bin2hex (data, data_size, escaped, sizeof (escaped));
|
||||
|
||||
if (res)
|
||||
{
|
||||
@@ -433,7 +433,7 @@ _gnutls_x509_data2hex (const opaque * data,
|
||||
}
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
@@ -522,7 +522,7 @@ mktime_utc (const struct fake_tm *tm)
|
||||
* and year is given. Returns a time_t date.
|
||||
*/
|
||||
time_t
|
||||
_gnutls_x509_time2gtime (const char *ttime, int year)
|
||||
MHD__gnutls_x509_time2gtime (const char *ttime, int year)
|
||||
{
|
||||
char xx[3];
|
||||
struct fake_tm etime;
|
||||
@@ -530,7 +530,7 @@ _gnutls_x509_time2gtime (const char *ttime, int year)
|
||||
|
||||
if (strlen (ttime) < 8)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return (time_t) - 1;
|
||||
}
|
||||
|
||||
@@ -589,14 +589,14 @@ _gnutls_x509_time2gtime (const char *ttime, int year)
|
||||
* (seconds are optional)
|
||||
*/
|
||||
time_t
|
||||
_gnutls_x509_utcTime2gtime (const char *ttime)
|
||||
MHD__gnutls_x509_utcTime2gtime (const char *ttime)
|
||||
{
|
||||
char xx[3];
|
||||
int year;
|
||||
|
||||
if (strlen (ttime) < 10)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return (time_t) - 1;
|
||||
}
|
||||
xx[2] = 0;
|
||||
@@ -611,7 +611,7 @@ _gnutls_x509_utcTime2gtime (const char *ttime)
|
||||
else
|
||||
year += 2000;
|
||||
|
||||
return _gnutls_x509_time2gtime (ttime, year);
|
||||
return MHD__gnutls_x509_time2gtime (ttime, year);
|
||||
}
|
||||
|
||||
/* returns a time value that contains the given time.
|
||||
@@ -619,7 +619,7 @@ _gnutls_x509_utcTime2gtime (const char *ttime)
|
||||
* YEAR(2)|MONTH(2)|DAY(2)|HOUR(2)|MIN(2)|SEC(2)
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_gtime2utcTime (time_t gtime, char *str_time, int str_time_size)
|
||||
MHD__gnutls_x509_gtime2utcTime (time_t gtime, char *str_time, int str_time_size)
|
||||
{
|
||||
size_t ret;
|
||||
|
||||
@@ -639,7 +639,7 @@ _gnutls_x509_gtime2utcTime (time_t gtime, char *str_time, int str_time_size)
|
||||
|
||||
if (!ret)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
|
||||
@@ -652,20 +652,20 @@ _gnutls_x509_gtime2utcTime (time_t gtime, char *str_time, int str_time_size)
|
||||
* YEAR(4)|MONTH(2)|DAY(2)|HOUR(2)|MIN(2)|SEC(2)*
|
||||
*/
|
||||
time_t
|
||||
_gnutls_x509_generalTime2gtime (const char *ttime)
|
||||
MHD__gnutls_x509_generalTime2gtime (const char *ttime)
|
||||
{
|
||||
char xx[5];
|
||||
int year;
|
||||
|
||||
if (strlen (ttime) < 12)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return (time_t) - 1;
|
||||
}
|
||||
|
||||
if (strchr (ttime, 'Z') == 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
/* sorry we don't support it yet
|
||||
*/
|
||||
return (time_t) - 1;
|
||||
@@ -678,7 +678,7 @@ _gnutls_x509_generalTime2gtime (const char *ttime)
|
||||
year = atoi (xx);
|
||||
ttime += 4;
|
||||
|
||||
return _gnutls_x509_time2gtime (ttime, year);
|
||||
return MHD__gnutls_x509_time2gtime (ttime, year);
|
||||
|
||||
}
|
||||
|
||||
@@ -687,19 +687,19 @@ _gnutls_x509_generalTime2gtime (const char *ttime)
|
||||
*/
|
||||
#define MAX_TIME 64
|
||||
time_t
|
||||
_gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
|
||||
MHD__gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
|
||||
{
|
||||
char ttime[MAX_TIME];
|
||||
char name[128];
|
||||
time_t c_time = (time_t) - 1;
|
||||
int len, result;
|
||||
|
||||
mhd_gtls_str_cpy (name, sizeof (name), when);
|
||||
MHD_gtls_str_cpy (name, sizeof (name), when);
|
||||
|
||||
len = sizeof (ttime) - 1;
|
||||
if ((result = asn1_read_value (c2, name, ttime, &len)) < 0)
|
||||
if ((result = MHD__asn1_read_value (c2, name, ttime, &len)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return (time_t) (-1);
|
||||
}
|
||||
|
||||
@@ -707,20 +707,20 @@ _gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
|
||||
if (strcmp (ttime, "generalTime") == 0)
|
||||
{
|
||||
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".generalTime");
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".generalTime");
|
||||
len = sizeof (ttime) - 1;
|
||||
result = asn1_read_value (c2, name, ttime, &len);
|
||||
result = MHD__asn1_read_value (c2, name, ttime, &len);
|
||||
if (result == ASN1_SUCCESS)
|
||||
c_time = _gnutls_x509_generalTime2gtime (ttime);
|
||||
c_time = MHD__gnutls_x509_generalTime2gtime (ttime);
|
||||
}
|
||||
else
|
||||
{ /* UTCTIME */
|
||||
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".utcTime");
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".utcTime");
|
||||
len = sizeof (ttime) - 1;
|
||||
result = asn1_read_value (c2, name, ttime, &len);
|
||||
result = MHD__asn1_read_value (c2, name, ttime, &len);
|
||||
if (result == ASN1_SUCCESS)
|
||||
c_time = _gnutls_x509_utcTime2gtime (ttime);
|
||||
c_time = MHD__gnutls_x509_utcTime2gtime (ttime);
|
||||
}
|
||||
|
||||
/* We cannot handle dates after 2031 in 32 bit machines.
|
||||
@@ -729,7 +729,7 @@ _gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return (time_t) (-1);
|
||||
}
|
||||
return c_time;
|
||||
@@ -739,42 +739,42 @@ _gnutls_x509_get_time (ASN1_TYPE c2, const char *when)
|
||||
* be something like "tbsCertList.thisUpdate".
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim)
|
||||
MHD__gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim)
|
||||
{
|
||||
char str_time[MAX_TIME];
|
||||
char name[128];
|
||||
int result, len;
|
||||
|
||||
mhd_gtls_str_cpy (name, sizeof (name), where);
|
||||
MHD_gtls_str_cpy (name, sizeof (name), where);
|
||||
|
||||
if ((result = asn1_write_value (c2, name, "utcTime", 1)) < 0)
|
||||
if ((result = MHD__asn1_write_value (c2, name, "utcTime", 1)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_gtime2utcTime (tim, str_time, sizeof (str_time));
|
||||
result = MHD__gnutls_x509_gtime2utcTime (tim, str_time, sizeof (str_time));
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".utcTime");
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".utcTime");
|
||||
|
||||
len = strlen (str_time);
|
||||
result = asn1_write_value (c2, name, str_time, len);
|
||||
result = MHD__asn1_write_value (c2, name, str_time, len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
gnutls_x509_subject_alt_name_t
|
||||
_gnutls_x509_san_find_type (char *str_type)
|
||||
MHD_gnutls_x509_subject_alt_name_t
|
||||
MHD__gnutls_x509_san_find_type (char *str_type)
|
||||
{
|
||||
if (strcmp (str_type, "dNSName") == 0)
|
||||
return GNUTLS_SAN_DNSNAME;
|
||||
@@ -788,15 +788,15 @@ _gnutls_x509_san_find_type (char *str_type)
|
||||
return GNUTLS_SAN_OTHERNAME;
|
||||
if (strcmp (str_type, "directoryName") == 0)
|
||||
return GNUTLS_SAN_DN;
|
||||
return (gnutls_x509_subject_alt_name_t) - 1;
|
||||
return (MHD_gnutls_x509_subject_alt_name_t) - 1;
|
||||
}
|
||||
|
||||
/* A generic export function. Will export the given ASN.1 encoded data
|
||||
* to PEM or DER raw data.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_export_int (ASN1_TYPE asn1_data,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
MHD__gnutls_x509_export_int (ASN1_TYPE MHD__asn1_data,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
char *pem_header,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size)
|
||||
@@ -811,7 +811,7 @@ _gnutls_x509_export_int (ASN1_TYPE asn1_data,
|
||||
|
||||
len = *output_data_size;
|
||||
|
||||
if ((result = asn1_der_coding (asn1_data, "", output_data, &len,
|
||||
if ((result = MHD__asn1_der_coding (MHD__asn1_data, "", output_data, &len,
|
||||
NULL)) != ASN1_SUCCESS)
|
||||
{
|
||||
*output_data_size = len;
|
||||
@@ -819,8 +819,8 @@ _gnutls_x509_export_int (ASN1_TYPE asn1_data,
|
||||
{
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
*output_data_size = len;
|
||||
@@ -829,35 +829,35 @@ _gnutls_x509_export_int (ASN1_TYPE asn1_data,
|
||||
else
|
||||
{ /* PEM */
|
||||
opaque *out;
|
||||
gnutls_datum_t tmp;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
|
||||
result = _gnutls_x509_der_encode (asn1_data, "", &tmp, 0);
|
||||
result = MHD__gnutls_x509_der_encode (MHD__asn1_data, "", &tmp, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
result = _gnutls_fbase64_encode (pem_header, tmp.data, tmp.size, &out);
|
||||
result = MHD__gnutls_fbase64_encode (pem_header, tmp.data, tmp.size, &out);
|
||||
|
||||
_gnutls_free_datum (&tmp);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
if (result == 0)
|
||||
{ /* oooops */
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
if ((unsigned) result > *output_data_size)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_free (out);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_free (out);
|
||||
*output_data_size = result;
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
@@ -872,7 +872,7 @@ _gnutls_x509_export_int (ASN1_TYPE asn1_data,
|
||||
*/
|
||||
*output_data_size = result - 1;
|
||||
}
|
||||
gnutls_free (out);
|
||||
MHD_gnutls_free (out);
|
||||
|
||||
}
|
||||
|
||||
@@ -884,7 +884,7 @@ _gnutls_x509_export_int (ASN1_TYPE asn1_data,
|
||||
* etc.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_decode_octet_string (const char *string_type,
|
||||
MHD__gnutls_x509_decode_octet_string (const char *string_type,
|
||||
const opaque * der,
|
||||
size_t der_size,
|
||||
opaque * output, size_t * output_size)
|
||||
@@ -894,45 +894,45 @@ _gnutls_x509_decode_octet_string (const char *string_type,
|
||||
char strname[64];
|
||||
|
||||
if (string_type == NULL)
|
||||
mhd_gtls_str_cpy (strname, sizeof (strname), "PKIX1.pkcs-7-Data");
|
||||
MHD_gtls_str_cpy (strname, sizeof (strname), "PKIX1.pkcs-7-Data");
|
||||
else
|
||||
{
|
||||
mhd_gtls_str_cpy (strname, sizeof (strname), "PKIX1.");
|
||||
mhd_gtls_str_cat (strname, sizeof (strname), string_type);
|
||||
MHD_gtls_str_cpy (strname, sizeof (strname), "PKIX1.");
|
||||
MHD_gtls_str_cat (strname, sizeof (strname), string_type);
|
||||
}
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (), strname,
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), strname,
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&c2, der, der_size, NULL);
|
||||
result = MHD__asn1_der_decoding (&c2, der, der_size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
tmp_output_size = *output_size;
|
||||
result = asn1_read_value (c2, "", output, &tmp_output_size);
|
||||
result = MHD__asn1_read_value (c2, "", output, &tmp_output_size);
|
||||
*output_size = tmp_output_size;
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
return result;
|
||||
}
|
||||
@@ -944,37 +944,37 @@ cleanup:if (c2)
|
||||
* flags == 2 the value is a BIT STRING
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_read_value (ASN1_TYPE c,
|
||||
const char *root, gnutls_datum_t * ret, int flags)
|
||||
MHD__gnutls_x509_read_value (ASN1_TYPE c,
|
||||
const char *root, MHD_gnutls_datum_t * ret, int flags)
|
||||
{
|
||||
int len = 0, result;
|
||||
size_t slen;
|
||||
opaque *tmp = NULL;
|
||||
|
||||
result = asn1_read_value (c, root, NULL, &len);
|
||||
result = MHD__asn1_read_value (c, root, NULL, &len);
|
||||
if (result != ASN1_MEM_ERROR)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
return result;
|
||||
}
|
||||
|
||||
if (flags == 2)
|
||||
len /= 8;
|
||||
|
||||
tmp = gnutls_malloc (len);
|
||||
tmp = MHD_gnutls_malloc (len);
|
||||
if (tmp == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_read_value (c, root, tmp, &len);
|
||||
result = MHD__asn1_read_value (c, root, tmp, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -987,10 +987,10 @@ _gnutls_x509_read_value (ASN1_TYPE c,
|
||||
if (flags == 1)
|
||||
{
|
||||
slen = len;
|
||||
result = _gnutls_x509_decode_octet_string (NULL, tmp, slen, tmp, &slen);
|
||||
result = MHD__gnutls_x509_decode_octet_string (NULL, tmp, slen, tmp, &slen);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
len = slen;
|
||||
@@ -1001,7 +1001,7 @@ _gnutls_x509_read_value (ASN1_TYPE c,
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:gnutls_free (tmp);
|
||||
cleanup:MHD_gnutls_free (tmp);
|
||||
return result;
|
||||
|
||||
}
|
||||
@@ -1011,8 +1011,8 @@ cleanup:gnutls_free (tmp);
|
||||
* an OCTET STRING.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_der_encode (ASN1_TYPE src,
|
||||
const char *src_name, gnutls_datum_t * res, int str)
|
||||
MHD__gnutls_x509_der_encode (ASN1_TYPE src,
|
||||
const char *src_name, MHD_gnutls_datum_t * res, int str)
|
||||
{
|
||||
int size, result;
|
||||
int asize;
|
||||
@@ -1020,11 +1020,11 @@ _gnutls_x509_der_encode (ASN1_TYPE src,
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
|
||||
size = 0;
|
||||
result = asn1_der_coding (src, src_name, NULL, &size, NULL);
|
||||
result = MHD__asn1_der_coding (src, src_name, NULL, &size, NULL);
|
||||
if (result != ASN1_MEM_ERROR)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -1035,60 +1035,60 @@ _gnutls_x509_der_encode (ASN1_TYPE src,
|
||||
size += 16; /* for later to include the octet tags */
|
||||
asize = size;
|
||||
|
||||
data = gnutls_malloc (size);
|
||||
data = MHD_gnutls_malloc (size);
|
||||
if (data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_der_coding (src, src_name, data, &size, NULL);
|
||||
result = MHD__asn1_der_coding (src, src_name, data, &size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (str)
|
||||
{
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.pkcs-7-Data",
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-Data",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_write_value (c2, "", data, size);
|
||||
result = MHD__asn1_write_value (c2, "", data, size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_der_coding (c2, "", data, &asize, NULL);
|
||||
result = MHD__asn1_der_coding (c2, "", data, &asize, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
size = asize;
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
}
|
||||
|
||||
res->data = data;
|
||||
res->size = size;
|
||||
return 0;
|
||||
|
||||
cleanup:gnutls_free (data);
|
||||
asn1_delete_structure (&c2);
|
||||
cleanup:MHD_gnutls_free (data);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
|
||||
}
|
||||
@@ -1099,32 +1099,32 @@ cleanup:gnutls_free (data);
|
||||
* an OCTET STRING.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_der_encode_and_copy (ASN1_TYPE src,
|
||||
MHD__gnutls_x509_der_encode_and_copy (ASN1_TYPE src,
|
||||
const char *src_name,
|
||||
ASN1_TYPE dest,
|
||||
const char *dest_name, int str)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t encoded;
|
||||
MHD_gnutls_datum_t encoded;
|
||||
|
||||
result = _gnutls_x509_der_encode (src, src_name, &encoded, str);
|
||||
result = MHD__gnutls_x509_der_encode (src, src_name, &encoded, str);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Write the data.
|
||||
*/
|
||||
result = asn1_write_value (dest, dest_name, encoded.data, encoded.size);
|
||||
result = MHD__asn1_write_value (dest, dest_name, encoded.data, encoded.size);
|
||||
|
||||
_gnutls_free_datum (&encoded);
|
||||
MHD__gnutls_free_datum (&encoded);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
@@ -1134,21 +1134,21 @@ _gnutls_x509_der_encode_and_copy (ASN1_TYPE src,
|
||||
* zero it encodes it as OCTET STRING.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_write_value (ASN1_TYPE c,
|
||||
MHD__gnutls_x509_write_value (ASN1_TYPE c,
|
||||
const char *root,
|
||||
const gnutls_datum_t * data, int str)
|
||||
const MHD_gnutls_datum_t * data, int str)
|
||||
{
|
||||
int result;
|
||||
int asize;
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
gnutls_datum_t val;
|
||||
MHD_gnutls_datum_t val;
|
||||
|
||||
asize = data->size + 16;
|
||||
|
||||
val.data = gnutls_malloc (asize);
|
||||
val.data = MHD_gnutls_malloc (asize);
|
||||
if (val.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
@@ -1158,26 +1158,26 @@ _gnutls_x509_write_value (ASN1_TYPE c,
|
||||
/* Convert it to OCTET STRING
|
||||
*/
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.pkcs-7-Data",
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-Data",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_write_value (c2, "", data->data, data->size);
|
||||
result = MHD__asn1_write_value (c2, "", data->data, data->size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode (c2, "", &val, 0);
|
||||
result = MHD__gnutls_x509_der_encode (c2, "", &val, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -1190,21 +1190,21 @@ _gnutls_x509_write_value (ASN1_TYPE c,
|
||||
|
||||
/* Write the data.
|
||||
*/
|
||||
result = asn1_write_value (c, root, val.data, val.size);
|
||||
result = MHD__asn1_write_value (c, root, val.data, val.size);
|
||||
|
||||
if (val.data != data->data)
|
||||
_gnutls_free_datum (&val);
|
||||
MHD__gnutls_free_datum (&val);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:if (val.data != data->data)
|
||||
_gnutls_free_datum (&val);
|
||||
MHD__gnutls_free_datum (&val);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -1213,69 +1213,69 @@ cleanup:if (val.data != data->data)
|
||||
*
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
MHD__gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
const char *dst_name,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm,
|
||||
mpi_t * params, int params_size)
|
||||
{
|
||||
const char *pk;
|
||||
gnutls_datum_t der = { NULL,
|
||||
MHD_gnutls_datum_t der = { NULL,
|
||||
0
|
||||
};
|
||||
int result;
|
||||
char name[128];
|
||||
|
||||
pk = mhd_gtls_x509_pk_to_oid (pk_algorithm);
|
||||
pk = MHD_gtls_x509_pk_to_oid (pk_algorithm);
|
||||
if (pk == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_UNKNOWN_PK_ALGORITHM;
|
||||
}
|
||||
|
||||
/* write the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".algorithm.algorithm");
|
||||
result = asn1_write_value (dst, name, pk, 1);
|
||||
MHD_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".algorithm.algorithm");
|
||||
result = MHD__asn1_write_value (dst, name, pk, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (pk_algorithm == MHD_GNUTLS_PK_RSA)
|
||||
{
|
||||
/* disable parameters, which are not used in RSA.
|
||||
*/
|
||||
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".algorithm.parameters");
|
||||
result = asn1_write_value (dst, name, NULL, 0);
|
||||
MHD_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".algorithm.parameters");
|
||||
result = MHD__asn1_write_value (dst, name, NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_write_rsa_params (params, params_size, &der);
|
||||
result = MHD__gnutls_x509_write_rsa_params (params, params_size, &der);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Write the DER parameters. (in bits)
|
||||
*/
|
||||
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
result = asn1_write_value (dst, name, der.data, der.size * 8);
|
||||
MHD_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
result = MHD__asn1_write_value (dst, name, der.data, der.size * 8);
|
||||
|
||||
_gnutls_free_datum (&der);
|
||||
MHD__gnutls_free_datum (&der);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
}
|
||||
else
|
||||
@@ -1288,7 +1288,7 @@ _gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
* ASN.1 structure. src_name should be something like "tbsCertificate.subjectPublicKeyInfo".
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
MHD__gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
const char *src_name, unsigned int *bits)
|
||||
{
|
||||
int result;
|
||||
@@ -1299,64 +1299,64 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
mpi_t params[MAX_PUBLIC_PARAMS_SIZE];
|
||||
char name[128];
|
||||
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".algorithm.algorithm");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".algorithm.algorithm");
|
||||
|
||||
len = sizeof (oid);
|
||||
result = asn1_read_value (src, name, oid, &len);
|
||||
result = MHD__asn1_read_value (src, name, oid, &len);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
algo = mhd_gtls_x509_oid2pk_algorithm (oid);
|
||||
algo = MHD_gtls_x509_oid2pk_algorithm (oid);
|
||||
|
||||
if (bits == NULL)
|
||||
{
|
||||
gnutls_free (str);
|
||||
MHD_gnutls_free (str);
|
||||
return algo;
|
||||
}
|
||||
|
||||
/* Now read the parameters' bits
|
||||
*/
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
|
||||
len = 0;
|
||||
result = asn1_read_value (src, name, NULL, &len);
|
||||
result = MHD__asn1_read_value (src, name, NULL, &len);
|
||||
if (result != ASN1_MEM_ERROR)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (len % 8 != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_CERTIFICATE_ERROR;
|
||||
}
|
||||
|
||||
len /= 8;
|
||||
|
||||
str = gnutls_malloc (len);
|
||||
str = MHD_gnutls_malloc (len);
|
||||
if (str == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".subjectPublicKey");
|
||||
|
||||
result = asn1_read_value (src, name, str, &len);
|
||||
result = MHD__asn1_read_value (src, name, str, &len);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_free (str);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_free (str);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
len /= 8;
|
||||
@@ -1365,24 +1365,24 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
{
|
||||
case MHD_GNUTLS_PK_RSA:
|
||||
{
|
||||
if ((result = _gnutls_x509_read_rsa_params (str, len, params)) < 0)
|
||||
if ((result = MHD__gnutls_x509_read_rsa_params (str, len, params)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
bits[0] = _gnutls_mpi_get_nbits (params[0]);
|
||||
bits[0] = MHD__gnutls_mpi_get_nbits (params[0]);
|
||||
|
||||
mhd_gtls_mpi_release (¶ms[0]);
|
||||
mhd_gtls_mpi_release (¶ms[1]);
|
||||
MHD_gtls_mpi_release (¶ms[0]);
|
||||
MHD_gtls_mpi_release (¶ms[1]);
|
||||
}
|
||||
break;
|
||||
default:
|
||||
_gnutls_x509_log
|
||||
("_gnutls_x509_get_pk_algorithm: unhandled algorithm %d\n", algo);
|
||||
MHD__gnutls_x509_log
|
||||
("MHD__gnutls_x509_get_pk_algorithm: unhandled algorithm %d\n", algo);
|
||||
}
|
||||
|
||||
gnutls_free (str);
|
||||
MHD_gnutls_free (str);
|
||||
return algo;
|
||||
}
|
||||
|
||||
@@ -1390,42 +1390,42 @@ _gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
* returns them into signed_data.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_get_signed_data (ASN1_TYPE src,
|
||||
MHD__gnutls_x509_get_signed_data (ASN1_TYPE src,
|
||||
const char *src_name,
|
||||
gnutls_datum_t * signed_data)
|
||||
MHD_gnutls_datum_t * signed_data)
|
||||
{
|
||||
gnutls_datum_t der;
|
||||
MHD_gnutls_datum_t der;
|
||||
int start, end, result;
|
||||
|
||||
result = _gnutls_x509_der_encode (src, "", &der, 0);
|
||||
result = MHD__gnutls_x509_der_encode (src, "", &der, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Get the signed data
|
||||
*/
|
||||
result = asn1_der_decoding_startEnd (src, der.data, der.size, src_name,
|
||||
result = MHD__asn1_der_decoding_startEnd (src, der.data, der.size, src_name,
|
||||
&start, &end);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
result = mhd_gtls_asn2err (result);
|
||||
gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_set_datum (signed_data, &der.data[start], end - start + 1);
|
||||
result = MHD__gnutls_set_datum (signed_data, &der.data[start], end - start + 1);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = 0;
|
||||
|
||||
cleanup:_gnutls_free_datum (&der);
|
||||
cleanup:MHD__gnutls_free_datum (&der);
|
||||
|
||||
return result;
|
||||
}
|
||||
@@ -1434,8 +1434,8 @@ cleanup:_gnutls_free_datum (&der);
|
||||
* returns them into signed_data.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_get_signature (ASN1_TYPE src,
|
||||
const char *src_name, gnutls_datum_t * signature)
|
||||
MHD__gnutls_x509_get_signature (ASN1_TYPE src,
|
||||
const char *src_name, MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int bits, result, len;
|
||||
|
||||
@@ -1445,28 +1445,28 @@ _gnutls_x509_get_signature (ASN1_TYPE src,
|
||||
/* Read the signature
|
||||
*/
|
||||
bits = 0;
|
||||
result = asn1_read_value (src, src_name, NULL, &bits);
|
||||
result = MHD__asn1_read_value (src, src_name, NULL, &bits);
|
||||
|
||||
if (result != ASN1_MEM_ERROR)
|
||||
{
|
||||
result = mhd_gtls_asn2err (result);
|
||||
gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (bits % 8 != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_CERTIFICATE_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
len = bits / 8;
|
||||
|
||||
signature->data = gnutls_malloc (len);
|
||||
signature->data = MHD_gnutls_malloc (len);
|
||||
if (signature->data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
return result;
|
||||
}
|
||||
@@ -1474,12 +1474,12 @@ _gnutls_x509_get_signature (ASN1_TYPE src,
|
||||
/* read the bit string of the signature
|
||||
*/
|
||||
bits = len;
|
||||
result = asn1_read_value (src, src_name, signature->data, &bits);
|
||||
result = MHD__asn1_read_value (src, src_name, signature->data, &bits);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
result = mhd_gtls_asn2err (result);
|
||||
gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
|
||||
@@ -58,70 +58,70 @@
|
||||
#define SIG_GOST_R3410_94_OID "1.2.643.2.2.4"
|
||||
#define SIG_GOST_R3410_2001_OID "1.2.643.2.2.3"
|
||||
|
||||
time_t _gnutls_x509_utcTime2gtime (const char *ttime);
|
||||
time_t _gnutls_x509_generalTime2gtime (const char *ttime);
|
||||
int _gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim);
|
||||
time_t MHD__gnutls_x509_utcTime2gtime (const char *ttime);
|
||||
time_t MHD__gnutls_x509_generalTime2gtime (const char *ttime);
|
||||
int MHD__gnutls_x509_set_time (ASN1_TYPE c2, const char *where, time_t tim);
|
||||
|
||||
int _gnutls_x509_decode_octet_string (const char *string_type,
|
||||
int MHD__gnutls_x509_decode_octet_string (const char *string_type,
|
||||
const opaque * der, size_t der_size,
|
||||
opaque * output, size_t * output_size);
|
||||
int _gnutls_x509_oid_data2string (const char *OID, void *value,
|
||||
int MHD__gnutls_x509_oid_data2string (const char *OID, void *value,
|
||||
int value_size, char *res,
|
||||
size_t * res_size);
|
||||
int _gnutls_x509_data2hex (const opaque * data, size_t data_size,
|
||||
int MHD__gnutls_x509_data2hex (const opaque * data, size_t data_size,
|
||||
opaque * out, size_t * sizeof_out);
|
||||
|
||||
const char *_gnutls_x509_oid2ldap_string (const char *OID);
|
||||
const char *MHD__gnutls_x509_oid2ldap_string (const char *OID);
|
||||
|
||||
int _gnutls_x509_oid_data_choice (const char *OID);
|
||||
int _gnutls_x509_oid_data_printable (const char *OID);
|
||||
int MHD__gnutls_x509_oid_data_choice (const char *OID);
|
||||
int MHD__gnutls_x509_oid_data_printable (const char *OID);
|
||||
|
||||
time_t _gnutls_x509_get_time (ASN1_TYPE c2, const char *when);
|
||||
time_t MHD__gnutls_x509_get_time (ASN1_TYPE c2, const char *when);
|
||||
|
||||
gnutls_x509_subject_alt_name_t _gnutls_x509_san_find_type (char *str_type);
|
||||
MHD_gnutls_x509_subject_alt_name_t MHD__gnutls_x509_san_find_type (char *str_type);
|
||||
|
||||
int _gnutls_x509_der_encode_and_copy (ASN1_TYPE src, const char *src_name,
|
||||
int MHD__gnutls_x509_der_encode_and_copy (ASN1_TYPE src, const char *src_name,
|
||||
ASN1_TYPE dest, const char *dest_name,
|
||||
int str);
|
||||
int _gnutls_x509_der_encode (ASN1_TYPE src, const char *src_name,
|
||||
gnutls_datum_t * res, int str);
|
||||
int MHD__gnutls_x509_der_encode (ASN1_TYPE src, const char *src_name,
|
||||
MHD_gnutls_datum_t * res, int str);
|
||||
|
||||
int _gnutls_x509_export_int (ASN1_TYPE asn1_data,
|
||||
gnutls_x509_crt_fmt_t format, char *pem_header,
|
||||
int MHD__gnutls_x509_export_int (ASN1_TYPE MHD__asn1_data,
|
||||
MHD_gnutls_x509_crt_fmt_t format, char *pem_header,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
int _gnutls_x509_read_value (ASN1_TYPE c, const char *root,
|
||||
gnutls_datum_t * ret, int str);
|
||||
int _gnutls_x509_write_value (ASN1_TYPE c, const char *root,
|
||||
const gnutls_datum_t * data, int str);
|
||||
int MHD__gnutls_x509_read_value (ASN1_TYPE c, const char *root,
|
||||
MHD_gnutls_datum_t * ret, int str);
|
||||
int MHD__gnutls_x509_write_value (ASN1_TYPE c, const char *root,
|
||||
const MHD_gnutls_datum_t * data, int str);
|
||||
|
||||
int _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
ASN1_TYPE asn1_struct,
|
||||
int MHD__gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where,
|
||||
const void *data,
|
||||
int sizeof_data, int multi);
|
||||
int _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
|
||||
int MHD__gnutls_x509_decode_and_read_attribute (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where, char *oid,
|
||||
int oid_size,
|
||||
gnutls_datum_t * value, int multi,
|
||||
MHD_gnutls_datum_t * value, int multi,
|
||||
int octet);
|
||||
|
||||
int _gnutls_x509_get_pk_algorithm (ASN1_TYPE src, const char *src_name,
|
||||
int MHD__gnutls_x509_get_pk_algorithm (ASN1_TYPE src, const char *src_name,
|
||||
unsigned int *bits);
|
||||
|
||||
int _gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
int MHD__gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
const char *dst_name,
|
||||
enum
|
||||
MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm, mpi_t * params,
|
||||
int params_size);
|
||||
int _gnutls_asn1_copy_node (ASN1_TYPE * dst, const char *dst_name,
|
||||
int MHD__gnutlsMHD__asn1_copy_node (ASN1_TYPE * dst, const char *dst_name,
|
||||
ASN1_TYPE src, const char *src_name);
|
||||
|
||||
int _gnutls_x509_get_signed_data (ASN1_TYPE src, const char *src_name,
|
||||
gnutls_datum_t * signed_data);
|
||||
int _gnutls_x509_get_signature (ASN1_TYPE src, const char *src_name,
|
||||
gnutls_datum_t * signature);
|
||||
int MHD__gnutls_x509_get_signed_data (ASN1_TYPE src, const char *src_name,
|
||||
MHD_gnutls_datum_t * signed_data);
|
||||
int MHD__gnutls_x509_get_signature (ASN1_TYPE src, const char *src_name,
|
||||
MHD_gnutls_datum_t * signature);
|
||||
|
||||
#endif
|
||||
+132
-132
@@ -36,7 +36,7 @@
|
||||
#include <dn.h>
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_init - This function initializes a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_init - This function initializes a MHD_gnutls_x509_crl_t structure
|
||||
* @crl: The structure to be initialized
|
||||
*
|
||||
* This function will initialize a CRL structure. CRL stands for
|
||||
@@ -49,20 +49,20 @@
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_init (gnutls_x509_crl_t * crl)
|
||||
MHD_gnutls_x509_crl_init (MHD_gnutls_x509_crl_t * crl)
|
||||
{
|
||||
*crl = gnutls_calloc (1, sizeof (gnutls_x509_crl_int));
|
||||
*crl = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_x509_crl_int));
|
||||
|
||||
if (*crl)
|
||||
{
|
||||
int result = asn1_create_element (_gnutls_get_pkix (),
|
||||
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.CertificateList",
|
||||
&(*crl)->crl);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_free (*crl);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_free (*crl);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
return 0; /* success */
|
||||
}
|
||||
@@ -70,32 +70,32 @@ gnutls_x509_crl_init (gnutls_x509_crl_t * crl)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_deinit - This function deinitializes memory used by a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_deinit - This function deinitializes memory used by a MHD_gnutls_x509_crl_t structure
|
||||
* @crl: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a CRL structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
gnutls_x509_crl_deinit (gnutls_x509_crl_t crl)
|
||||
MHD_gnutls_x509_crl_deinit (MHD_gnutls_x509_crl_t crl)
|
||||
{
|
||||
if (!crl)
|
||||
return;
|
||||
|
||||
if (crl->crl)
|
||||
asn1_delete_structure (&crl->crl);
|
||||
MHD__asn1_delete_structure (&crl->crl);
|
||||
|
||||
gnutls_free (crl);
|
||||
MHD_gnutls_free (crl);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_import - This function will import a DER or PEM encoded CRL
|
||||
* MHD_gnutls_x509_crl_import - This function will import a DER or PEM encoded CRL
|
||||
* @crl: The structure to store the parsed CRL.
|
||||
* @data: The DER or PEM encoded CRL.
|
||||
* @format: One of DER or PEM
|
||||
*
|
||||
* This function will convert the given DER or PEM encoded CRL
|
||||
* to the native gnutls_x509_crl_t format. The output will be stored in 'crl'.
|
||||
* to the native MHD_gnutls_x509_crl_t format. The output will be stored in 'crl'.
|
||||
*
|
||||
* If the CRL is PEM encoded it should have a header of "X509 CRL".
|
||||
*
|
||||
@@ -103,19 +103,19 @@ gnutls_x509_crl_deinit (gnutls_x509_crl_t crl)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_import (gnutls_x509_crl_t crl,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format)
|
||||
MHD_gnutls_x509_crl_import (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
gnutls_datum_t _data;
|
||||
MHD_gnutls_datum_t _data;
|
||||
|
||||
_data.data = data->data;
|
||||
_data.size = data->size;
|
||||
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -125,13 +125,13 @@ gnutls_x509_crl_import (gnutls_x509_crl_t crl,
|
||||
{
|
||||
opaque *out;
|
||||
|
||||
result = _gnutls_fbase64_decode (PEM_CRL, data->data, data->size, &out);
|
||||
result = MHD__gnutls_fbase64_decode (PEM_CRL, data->data, data->size, &out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
if (result == 0)
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -142,29 +142,29 @@ gnutls_x509_crl_import (gnutls_x509_crl_t crl,
|
||||
}
|
||||
|
||||
|
||||
result = asn1_der_decoding (&crl->crl, _data.data, _data.size, NULL);
|
||||
result = MHD__asn1_der_decoding (&crl->crl, _data.data, _data.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
result = mhd_gtls_asn2err (result);
|
||||
gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_get_issuer_dn - This function returns the CRL's issuer distinguished name
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_get_issuer_dn - This function returns the CRL's issuer distinguished name
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
* @buf: a pointer to a structure to hold the peer's name (may be null)
|
||||
* @sizeof_buf: initially holds the size of @buf
|
||||
*
|
||||
@@ -180,23 +180,23 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_get_issuer_dn (const gnutls_x509_crl_t crl, char *buf,
|
||||
MHD_gnutls_x509_crl_get_issuer_dn (const MHD_gnutls_x509_crl_t crl, char *buf,
|
||||
size_t * sizeof_buf)
|
||||
{
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_parse_dn (crl->crl,
|
||||
return MHD__gnutls_x509_parse_dn (crl->crl,
|
||||
"tbsCertList.issuer.rdnSequence",
|
||||
buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_get_issuer_dn_by_oid - This function returns the CRL's issuer distinguished name
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_get_issuer_dn_by_oid - This function returns the CRL's issuer distinguished name
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
* @oid: holds an Object Identified in null terminated string
|
||||
* @indx: In case multiple same OIDs exist in the RDN, this specifies which to send. Use zero to get the first one.
|
||||
* @raw_flag: If non zero returns the raw DER data of the DN part.
|
||||
@@ -210,7 +210,7 @@ gnutls_x509_crl_get_issuer_dn (const gnutls_x509_crl_t crl, char *buf,
|
||||
* Some helper macros with popular OIDs can be found in gnutls/x509.h
|
||||
* If raw flag is zero, this function will only return known OIDs as text. Other OIDs
|
||||
* will be DER encoded, as described in RFC2253 -- in hex format with a '\#' prefix.
|
||||
* You can check about known OIDs using gnutls_x509_dn_oid_known().
|
||||
* You can check about known OIDs using MHD_gnutls_x509_dn_oid_known().
|
||||
*
|
||||
* If buf is null then only the size will be filled.
|
||||
*
|
||||
@@ -220,25 +220,25 @@ gnutls_x509_crl_get_issuer_dn (const gnutls_x509_crl_t crl, char *buf,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_get_issuer_dn_by_oid (gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crl_get_issuer_dn_by_oid (MHD_gnutls_x509_crl_t crl,
|
||||
const char *oid, int indx,
|
||||
unsigned int raw_flag, void *buf,
|
||||
size_t * sizeof_buf)
|
||||
{
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_parse_dn_oid (crl->crl,
|
||||
return MHD__gnutls_x509_parse_dn_oid (crl->crl,
|
||||
"tbsCertList.issuer.rdnSequence",
|
||||
oid, indx, raw_flag, buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_get_dn_oid - This function returns the Certificate request issuer's distinguished name OIDs
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_get_dn_oid - This function returns the Certificate request issuer's distinguished name OIDs
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
* @indx: Specifies which DN OID to send. Use zero to get the first one.
|
||||
* @oid: a pointer to a structure to hold the name (may be null)
|
||||
* @sizeof_oid: initially holds the size of 'oid'
|
||||
@@ -254,40 +254,40 @@ gnutls_x509_crl_get_issuer_dn_by_oid (gnutls_x509_crl_t crl,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_get_dn_oid (gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crl_get_dn_oid (MHD_gnutls_x509_crl_t crl,
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
{
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_get_dn_oid (crl->crl,
|
||||
return MHD__gnutls_x509_get_dn_oid (crl->crl,
|
||||
"tbsCertList.issuer.rdnSequence", indx,
|
||||
oid, sizeof_oid);
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_get_signature_algorithm - This function returns the CRL's signature algorithm
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_get_signature_algorithm - This function returns the CRL's signature algorithm
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
*
|
||||
* This function will return a value of the gnutls_sign_algorithm_t enumeration that
|
||||
* This function will return a value of the MHD_gnutls_sign_algorithm_t enumeration that
|
||||
* is the signature algorithm.
|
||||
*
|
||||
* Returns a negative value on error.
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_get_signature_algorithm (gnutls_x509_crl_t crl)
|
||||
MHD_gnutls_x509_crl_get_signature_algorithm (MHD_gnutls_x509_crl_t crl)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t sa;
|
||||
MHD_gnutls_datum_t sa;
|
||||
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -296,25 +296,25 @@ gnutls_x509_crl_get_signature_algorithm (gnutls_x509_crl_t crl)
|
||||
*/
|
||||
|
||||
result =
|
||||
_gnutls_x509_read_value (crl->crl, "signatureAlgorithm.algorithm",
|
||||
MHD__gnutls_x509_read_value (crl->crl, "signatureAlgorithm.algorithm",
|
||||
&sa, 0);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
result = mhd_gtls_x509_oid2sign_algorithm ((const char *) sa.data);
|
||||
result = MHD_gtls_x509_oid2sign_algorithm ((const char *) sa.data);
|
||||
|
||||
_gnutls_free_datum (&sa);
|
||||
MHD__gnutls_free_datum (&sa);
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_get_signature - Returns the CRL's signature
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_get_signature - Returns the CRL's signature
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
* @sig: a pointer where the signature part will be copied (may be null).
|
||||
* @sizeof_sig: initially holds the size of @sig
|
||||
*
|
||||
@@ -323,7 +323,7 @@ gnutls_x509_crl_get_signature_algorithm (gnutls_x509_crl_t crl)
|
||||
* Returns 0 on success, and a negative value on error.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crl_get_signature (MHD_gnutls_x509_crl_t crl,
|
||||
char *sig, size_t * sizeof_sig)
|
||||
{
|
||||
int result;
|
||||
@@ -331,21 +331,21 @@ gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
|
||||
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
bits = 0;
|
||||
result = asn1_read_value (crl->crl, "signature", NULL, &bits);
|
||||
result = MHD__asn1_read_value (crl->crl, "signature", NULL, &bits);
|
||||
if (result != ASN1_MEM_ERROR)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (bits % 8 != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_CERTIFICATE_ERROR;
|
||||
}
|
||||
|
||||
@@ -357,19 +357,19 @@ gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
|
||||
result = asn1_read_value (crl->crl, "signature", sig, &len);
|
||||
result = MHD__asn1_read_value (crl->crl, "signature", sig, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_get_version - This function returns the CRL's version number
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_get_version - This function returns the CRL's version number
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
*
|
||||
* This function will return the version of the specified CRL.
|
||||
*
|
||||
@@ -377,32 +377,32 @@ gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_get_version (gnutls_x509_crl_t crl)
|
||||
MHD_gnutls_x509_crl_get_version (MHD_gnutls_x509_crl_t crl)
|
||||
{
|
||||
opaque version[5];
|
||||
int len, result;
|
||||
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
len = sizeof (version);
|
||||
if ((result =
|
||||
asn1_read_value (crl->crl, "tbsCertList.version", version,
|
||||
MHD__asn1_read_value (crl->crl, "tbsCertList.version", version,
|
||||
&len)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return (int) version[0] + 1;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_get_this_update - This function returns the CRL's thisUpdate time
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_get_this_update - This function returns the CRL's thisUpdate time
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
*
|
||||
* This function will return the time this CRL was issued.
|
||||
*
|
||||
@@ -410,20 +410,20 @@ gnutls_x509_crl_get_version (gnutls_x509_crl_t crl)
|
||||
*
|
||||
**/
|
||||
time_t
|
||||
gnutls_x509_crl_get_this_update (gnutls_x509_crl_t crl)
|
||||
MHD_gnutls_x509_crl_get_this_update (MHD_gnutls_x509_crl_t crl)
|
||||
{
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return (time_t) - 1;
|
||||
}
|
||||
|
||||
return _gnutls_x509_get_time (crl->crl, "tbsCertList.thisUpdate");
|
||||
return MHD__gnutls_x509_get_time (crl->crl, "tbsCertList.thisUpdate");
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_get_next_update - This function returns the CRL's nextUpdate time
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_get_next_update - This function returns the CRL's nextUpdate time
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
*
|
||||
* This function will return the time the next CRL will be issued.
|
||||
* This field is optional in a CRL so it might be normal to get
|
||||
@@ -433,20 +433,20 @@ gnutls_x509_crl_get_this_update (gnutls_x509_crl_t crl)
|
||||
*
|
||||
**/
|
||||
time_t
|
||||
gnutls_x509_crl_get_next_update (gnutls_x509_crl_t crl)
|
||||
MHD_gnutls_x509_crl_get_next_update (MHD_gnutls_x509_crl_t crl)
|
||||
{
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return (time_t) - 1;
|
||||
}
|
||||
|
||||
return _gnutls_x509_get_time (crl->crl, "tbsCertList.nextUpdate");
|
||||
return MHD__gnutls_x509_get_time (crl->crl, "tbsCertList.nextUpdate");
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_get_crt_count - This function returns the number of revoked certificates in a CRL
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_get_crt_count - This function returns the number of revoked certificates in a CRL
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
*
|
||||
* This function will return the number of revoked certificates in the
|
||||
* given CRL.
|
||||
@@ -455,24 +455,24 @@ gnutls_x509_crl_get_next_update (gnutls_x509_crl_t crl)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl)
|
||||
MHD_gnutls_x509_crl_get_crt_count (MHD_gnutls_x509_crl_t crl)
|
||||
{
|
||||
|
||||
int count, result;
|
||||
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_number_of_elements (crl->crl,
|
||||
MHD__asn1_number_of_elements (crl->crl,
|
||||
"tbsCertList.revokedCertificates", &count);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return 0; /* no certificates */
|
||||
}
|
||||
|
||||
@@ -480,8 +480,8 @@ gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_get_crt_serial - This function returns the serial number of a revoked certificate
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD_gnutls_x509_crl_get_crt_serial - This function returns the serial number of a revoked certificate
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
* @indx: the index of the certificate to extract (starting from 0)
|
||||
* @serial: where the serial number will be copied
|
||||
* @serial_size: initially holds the size of serial
|
||||
@@ -494,7 +494,7 @@ gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl, int indx,
|
||||
MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl, int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t)
|
||||
{
|
||||
@@ -505,7 +505,7 @@ gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl, int indx,
|
||||
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -515,28 +515,28 @@ gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl, int indx,
|
||||
"tbsCertList.revokedCertificates.?%u.revocationDate", indx + 1);
|
||||
|
||||
_serial_size = *serial_size;
|
||||
result = asn1_read_value (crl->crl, serial_name, serial, &_serial_size);
|
||||
result = MHD__asn1_read_value (crl->crl, serial_name, serial, &_serial_size);
|
||||
|
||||
*serial_size = _serial_size;
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
return mhd_gtls_asn2err (result);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (t)
|
||||
{
|
||||
*t = _gnutls_x509_get_time (crl->crl, date_name);
|
||||
*t = MHD__gnutls_x509_get_time (crl->crl, date_name);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/*-
|
||||
* _gnutls_x509_crl_get_raw_issuer_dn - This function returns the issuer's DN DER encoded
|
||||
* @crl: should contain a gnutls_x509_crl_t structure
|
||||
* MHD__gnutls_x509_crl_get_raw_issuer_dn - This function returns the issuer's DN DER encoded
|
||||
* @crl: should contain a MHD_gnutls_x509_crl_t structure
|
||||
* @dn: will hold the starting point of the DN
|
||||
*
|
||||
* This function will return a pointer to the DER encoded DN structure and
|
||||
@@ -546,75 +546,75 @@ gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl, int indx,
|
||||
*
|
||||
-*/
|
||||
int
|
||||
_gnutls_x509_crl_get_raw_issuer_dn (gnutls_x509_crl_t crl,
|
||||
gnutls_datum_t * dn)
|
||||
MHD__gnutls_x509_crl_get_raw_issuer_dn (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_datum_t * dn)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result, len1;
|
||||
int start1, end1;
|
||||
gnutls_datum_t crl_signed_data;
|
||||
MHD_gnutls_datum_t crl_signed_data;
|
||||
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
/* get the issuer of 'crl'
|
||||
*/
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.TBSCertList",
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.TBSCertList",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
_gnutls_x509_get_signed_data (crl->crl, "tbsCertList", &crl_signed_data);
|
||||
MHD__gnutls_x509_get_signed_data (crl->crl, "tbsCertList", &crl_signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_der_decoding (&c2, crl_signed_data.data, crl_signed_data.size, NULL);
|
||||
MHD__asn1_der_decoding (&c2, crl_signed_data.data, crl_signed_data.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
/* couldn't decode DER */
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_der_decoding_startEnd (c2, crl_signed_data.data,
|
||||
MHD__asn1_der_decoding_startEnd (c2, crl_signed_data.data,
|
||||
crl_signed_data.size, "issuer",
|
||||
&start1, &end1);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
len1 = end1 - start1 + 1;
|
||||
|
||||
_gnutls_set_datum (dn, &crl_signed_data.data[start1], len1);
|
||||
MHD__gnutls_set_datum (dn, &crl_signed_data.data[start1], len1);
|
||||
|
||||
result = 0;
|
||||
|
||||
cleanup:
|
||||
asn1_delete_structure (&c2);
|
||||
_gnutls_free_datum (&crl_signed_data);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
MHD__gnutls_free_datum (&crl_signed_data);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_export - This function will export the CRL
|
||||
* MHD_gnutls_x509_crl_export - This function will export the CRL
|
||||
* @crl: Holds the revocation list
|
||||
* @format: the format of output params. One of PEM or DER.
|
||||
* @output_data: will contain a private key PEM or DER encoded
|
||||
@@ -632,22 +632,22 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_export (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
size_t * output_data_size)
|
||||
{
|
||||
if (crl == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_export_int (crl->crl, format, PEM_CRL,
|
||||
return MHD__gnutls_x509_export_int (crl->crl, format, PEM_CRL,
|
||||
output_data, output_data_size);
|
||||
}
|
||||
|
||||
/*-
|
||||
* _gnutls_x509_crl_cpy - This function copies a gnutls_x509_crl_t structure
|
||||
* MHD__gnutls_x509_crl_cpy - This function copies a MHD_gnutls_x509_crl_t structure
|
||||
* @dest: The structure where to copy
|
||||
* @src: The structure to be copied
|
||||
*
|
||||
@@ -657,44 +657,44 @@ gnutls_x509_crl_export (gnutls_x509_crl_t crl,
|
||||
*
|
||||
-*/
|
||||
int
|
||||
_gnutls_x509_crl_cpy (gnutls_x509_crl_t dest, gnutls_x509_crl_t src)
|
||||
MHD__gnutls_x509_crl_cpy (MHD_gnutls_x509_crl_t dest, MHD_gnutls_x509_crl_t src)
|
||||
{
|
||||
int ret;
|
||||
size_t der_size;
|
||||
opaque *der;
|
||||
gnutls_datum_t tmp;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
|
||||
ret = gnutls_x509_crl_export (src, GNUTLS_X509_FMT_DER, NULL, &der_size);
|
||||
ret = MHD_gnutls_x509_crl_export (src, GNUTLS_X509_FMT_DER, NULL, &der_size);
|
||||
if (ret != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
der = gnutls_alloca (der_size);
|
||||
der = MHD_gnutls_alloca (der_size);
|
||||
if (der == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
ret = gnutls_x509_crl_export (src, GNUTLS_X509_FMT_DER, der, &der_size);
|
||||
ret = MHD_gnutls_x509_crl_export (src, GNUTLS_X509_FMT_DER, der, &der_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_afree (der);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_afree (der);
|
||||
return ret;
|
||||
}
|
||||
|
||||
tmp.data = der;
|
||||
tmp.size = der_size;
|
||||
ret = gnutls_x509_crl_import (dest, &tmp, GNUTLS_X509_FMT_DER);
|
||||
ret = MHD_gnutls_x509_crl_import (dest, &tmp, GNUTLS_X509_FMT_DER);
|
||||
|
||||
gnutls_afree (der);
|
||||
MHD_gnutls_afree (der);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
||||
+144
-144
@@ -43,7 +43,7 @@
|
||||
#include <libtasn1.h>
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_init - This function initializes a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_init - This function initializes a MHD_gnutls_x509_crq_t structure
|
||||
* @crq: The structure to be initialized
|
||||
*
|
||||
* This function will initialize a PKCS10 certificate request structure.
|
||||
@@ -52,20 +52,20 @@
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_init (gnutls_x509_crq_t * crq)
|
||||
MHD_gnutls_x509_crq_init (MHD_gnutls_x509_crq_t * crq)
|
||||
{
|
||||
*crq = gnutls_calloc (1, sizeof (gnutls_x509_crq_int));
|
||||
*crq = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_x509_crq_int));
|
||||
|
||||
if (*crq)
|
||||
{
|
||||
int result = asn1_create_element (_gnutls_get_pkix (),
|
||||
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-10-CertificationRequest",
|
||||
&((*crq)->crq));
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_free (*crq);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_free (*crq);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
return 0; /* success */
|
||||
}
|
||||
@@ -73,35 +73,35 @@ gnutls_x509_crq_init (gnutls_x509_crq_t * crq)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_deinit - This function deinitializes memory used by a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_deinit - This function deinitializes memory used by a MHD_gnutls_x509_crq_t structure
|
||||
* @crq: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a CRL structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
gnutls_x509_crq_deinit (gnutls_x509_crq_t crq)
|
||||
MHD_gnutls_x509_crq_deinit (MHD_gnutls_x509_crq_t crq)
|
||||
{
|
||||
if (!crq)
|
||||
return;
|
||||
|
||||
if (crq->crq)
|
||||
asn1_delete_structure (&crq->crq);
|
||||
MHD__asn1_delete_structure (&crq->crq);
|
||||
|
||||
gnutls_free (crq);
|
||||
MHD_gnutls_free (crq);
|
||||
}
|
||||
|
||||
#define PEM_CRQ "NEW CERTIFICATE REQUEST"
|
||||
#define PEM_CRQ2 "CERTIFICATE REQUEST"
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_import - This function will import a DER or PEM encoded Certificate request
|
||||
* MHD_gnutls_x509_crq_import - This function will import a DER or PEM encoded Certificate request
|
||||
* @crq: The structure to store the parsed certificate request.
|
||||
* @data: The DER or PEM encoded certificate.
|
||||
* @format: One of DER or PEM
|
||||
*
|
||||
* This function will convert the given DER or PEM encoded Certificate
|
||||
* to the native gnutls_x509_crq_t format. The output will be stored in @cert.
|
||||
* to the native MHD_gnutls_x509_crq_t format. The output will be stored in @cert.
|
||||
*
|
||||
* If the Certificate is PEM encoded it should have a header of "NEW CERTIFICATE REQUEST".
|
||||
*
|
||||
@@ -109,16 +109,16 @@ gnutls_x509_crq_deinit (gnutls_x509_crq_t crq)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_import (gnutls_x509_crq_t crq,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format)
|
||||
MHD_gnutls_x509_crq_import (MHD_gnutls_x509_crq_t crq,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
gnutls_datum_t _data;
|
||||
MHD_gnutls_datum_t _data;
|
||||
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -132,17 +132,17 @@ gnutls_x509_crq_import (gnutls_x509_crq_t crq,
|
||||
opaque *out;
|
||||
|
||||
/* Try the first header */
|
||||
result = _gnutls_fbase64_decode (PEM_CRQ, data->data, data->size, &out);
|
||||
result = MHD__gnutls_fbase64_decode (PEM_CRQ, data->data, data->size, &out);
|
||||
|
||||
if (result <= 0) /* Go for the second header */
|
||||
result =
|
||||
_gnutls_fbase64_decode (PEM_CRQ2, data->data, data->size, &out);
|
||||
MHD__gnutls_fbase64_decode (PEM_CRQ2, data->data, data->size, &out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
if (result == 0)
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -152,11 +152,11 @@ gnutls_x509_crq_import (gnutls_x509_crq_t crq,
|
||||
need_free = 1;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&crq->crq, _data.data, _data.size, NULL);
|
||||
result = MHD__asn1_der_decoding (&crq->crq, _data.data, _data.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
result = mhd_gtls_asn2err (result);
|
||||
gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -164,15 +164,15 @@ gnutls_x509_crq_import (gnutls_x509_crq_t crq,
|
||||
|
||||
cleanup:
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_get_dn - This function returns the Certificate request subject's distinguished name
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_get_dn - This function returns the Certificate request subject's distinguished name
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @buf: a pointer to a structure to hold the name (may be null)
|
||||
* @sizeof_buf: initially holds the size of @buf
|
||||
*
|
||||
@@ -189,22 +189,22 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_get_dn (gnutls_x509_crq_t crq, char *buf, size_t * sizeof_buf)
|
||||
MHD_gnutls_x509_crq_get_dn (MHD_gnutls_x509_crq_t crq, char *buf, size_t * sizeof_buf)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_parse_dn (crq->crq,
|
||||
return MHD__gnutls_x509_parse_dn (crq->crq,
|
||||
"certificationRequestInfo.subject.rdnSequence",
|
||||
buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_get_dn_by_oid - This function returns the Certificate request subject's distinguished name
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_get_dn_by_oid - This function returns the Certificate request subject's distinguished name
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @oid: holds an Object Identified in null terminated string
|
||||
* @indx: In case multiple same OIDs exist in the RDN, this specifies
|
||||
* which to send. Use zero to get the first one.
|
||||
@@ -221,7 +221,7 @@ gnutls_x509_crq_get_dn (gnutls_x509_crq_t crq, char *buf, size_t * sizeof_buf)
|
||||
* If raw flag is zero, this function will only return known OIDs as
|
||||
* text. Other OIDs will be DER encoded, as described in RFC2253 --
|
||||
* in hex format with a '\#' prefix. You can check about known OIDs
|
||||
* using gnutls_x509_dn_oid_known().
|
||||
* using MHD_gnutls_x509_dn_oid_known().
|
||||
*
|
||||
* If @buf is null then only the size will be filled.
|
||||
*
|
||||
@@ -231,24 +231,24 @@ gnutls_x509_crq_get_dn (gnutls_x509_crq_t crq, char *buf, size_t * sizeof_buf)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_get_dn_by_oid (gnutls_x509_crq_t crq, const char *oid,
|
||||
MHD_gnutls_x509_crq_get_dn_by_oid (MHD_gnutls_x509_crq_t crq, const char *oid,
|
||||
int indx, unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_parse_dn_oid (crq->crq,
|
||||
return MHD__gnutls_x509_parse_dn_oid (crq->crq,
|
||||
"certificationRequestInfo.subject.rdnSequence",
|
||||
oid, indx, raw_flag, buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_get_dn_oid - This function returns the Certificate request subject's distinguished name OIDs
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_get_dn_oid - This function returns the Certificate request subject's distinguished name OIDs
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @indx: Specifies which DN OID to send. Use zero to get the first one.
|
||||
* @oid: a pointer to a structure to hold the name (may be null)
|
||||
* @sizeof_oid: initially holds the size of @oid
|
||||
@@ -264,30 +264,30 @@ gnutls_x509_crq_get_dn_by_oid (gnutls_x509_crq_t crq, const char *oid,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_get_dn_oid (gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_crq_get_dn_oid (MHD_gnutls_x509_crq_t crq,
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_get_dn_oid (crq->crq,
|
||||
return MHD__gnutls_x509_get_dn_oid (crq->crq,
|
||||
"certificationRequestInfo.subject.rdnSequence",
|
||||
indx, oid, sizeof_oid);
|
||||
}
|
||||
|
||||
/* Parses an Attribute list in the asn1_struct, and searches for the
|
||||
/* Parses an Attribute list in the MHD__asn1_struct, and searches for the
|
||||
* given OID. The index indicates the attribute value to be returned.
|
||||
*
|
||||
* If raw==0 only printable data are returned, or GNUTLS_E_X509_UNSUPPORTED_ATTRIBUTE.
|
||||
*
|
||||
* asn1_attr_name must be a string in the form "certificationRequestInfo.attributes"
|
||||
* MHD__asn1_attr_name must be a string in the form "certificationRequestInfo.attributes"
|
||||
*
|
||||
*/
|
||||
static int
|
||||
parse_attribute (ASN1_TYPE asn1_struct,
|
||||
parse_attribute (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *attr_name, const char *given_oid, int indx,
|
||||
int raw, char *buf, size_t * sizeof_buf)
|
||||
{
|
||||
@@ -300,7 +300,7 @@ parse_attribute (ASN1_TYPE asn1_struct,
|
||||
|
||||
if (*sizeof_buf == 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -319,18 +319,18 @@ parse_attribute (ASN1_TYPE asn1_struct,
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer1, value, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
break;
|
||||
}
|
||||
|
||||
if (result != ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -338,18 +338,18 @@ parse_attribute (ASN1_TYPE asn1_struct,
|
||||
*/
|
||||
/* Read the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer1);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer1);
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
break;
|
||||
else if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -362,32 +362,32 @@ parse_attribute (ASN1_TYPE asn1_struct,
|
||||
tmpbuffer1, indx + 1);
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, value, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, value, &len);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (raw == 0)
|
||||
{
|
||||
printable = _gnutls_x509_oid_data_printable (oid);
|
||||
printable = MHD__gnutls_x509_oid_data_printable (oid);
|
||||
if (printable == 1)
|
||||
{
|
||||
if ((result =
|
||||
_gnutls_x509_oid_data2string
|
||||
MHD__gnutls_x509_oid_data2string
|
||||
(oid, value, len, buf, sizeof_buf)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
return 0;
|
||||
}
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_X509_UNSUPPORTED_ATTRIBUTE;
|
||||
}
|
||||
}
|
||||
@@ -403,7 +403,7 @@ parse_attribute (ASN1_TYPE asn1_struct,
|
||||
else
|
||||
{
|
||||
*sizeof_buf = len;
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
}
|
||||
@@ -412,7 +412,7 @@ parse_attribute (ASN1_TYPE asn1_struct,
|
||||
}
|
||||
while (1);
|
||||
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
|
||||
result = GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
|
||||
@@ -421,8 +421,8 @@ cleanup:
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_get_challenge_password - This function will get the challenge password
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_get_challenge_password - This function will get the challenge password
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @pass: will hold a null terminated password
|
||||
* @sizeof_pass: Initially holds the size of @pass.
|
||||
*
|
||||
@@ -433,12 +433,12 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_get_challenge_password (gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_crq_get_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
char *pass, size_t * sizeof_pass)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -447,8 +447,8 @@ gnutls_x509_crq_get_challenge_password (gnutls_x509_crq_t crq,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_set_attribute_by_oid - This function will set an attribute in the request
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_set_attribute_by_oid - This function will set an attribute in the request
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @oid: holds an Object Identified in null terminated string
|
||||
* @buf: a pointer to a structure that holds the attribute data
|
||||
* @sizeof_buf: holds the size of @buf
|
||||
@@ -460,7 +460,7 @@ gnutls_x509_crq_get_challenge_password (gnutls_x509_crq_t crq,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_crq_set_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid, void *buf,
|
||||
size_t sizeof_buf)
|
||||
{
|
||||
@@ -468,30 +468,30 @@ gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
/* Add the attribute.
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (crq->crq, "certificationRequestInfo.attributes",
|
||||
MHD__asn1_write_value (crq->crq, "certificationRequestInfo.attributes",
|
||||
"NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
_gnutls_x509_encode_and_write_attribute (oid,
|
||||
MHD__gnutls_x509_encode_and_write_attribute (oid,
|
||||
crq->crq,
|
||||
"certificationRequestInfo.attributes.?LAST",
|
||||
buf, sizeof_buf, 1);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -499,8 +499,8 @@ gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_get_attribute_by_oid - This function will get an attribute of the request
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_get_attribute_by_oid - This function will get an attribute of the request
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @oid: holds an Object Identified in null terminated string
|
||||
* @indx: In case multiple same OIDs exist in the attribute list, this specifies
|
||||
* which to send. Use zero to get the first one.
|
||||
@@ -514,13 +514,13 @@ gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_crq_get_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid, int indx, void *buf,
|
||||
size_t * sizeof_buf)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -529,8 +529,8 @@ gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_set_dn_by_oid - This function will set the Certificate request subject's distinguished name
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_set_dn_by_oid - This function will set the Certificate request subject's distinguished name
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @oid: holds an Object Identifier in a null terminated string
|
||||
* @raw_flag: must be 0, or 1 if the data are DER encoded
|
||||
* @data: a pointer to the input data
|
||||
@@ -541,7 +541,7 @@ gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
*
|
||||
* Some helper macros with popular OIDs can be found in gnutls/x509.h
|
||||
* With this function you can only set the known OIDs. You can test
|
||||
* for known OIDs using gnutls_x509_dn_oid_known(). For OIDs that are
|
||||
* for known OIDs using MHD_gnutls_x509_dn_oid_known(). For OIDs that are
|
||||
* not known (by gnutls) you should properly DER encode your data, and
|
||||
* call this function with raw_flag set.
|
||||
*
|
||||
@@ -549,7 +549,7 @@ gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_set_dn_by_oid (gnutls_x509_crq_t crq, const char *oid,
|
||||
MHD_gnutls_x509_crq_set_dn_by_oid (MHD_gnutls_x509_crq_t crq, const char *oid,
|
||||
unsigned int raw_flag, const void *data,
|
||||
unsigned int sizeof_data)
|
||||
{
|
||||
@@ -558,14 +558,14 @@ gnutls_x509_crq_set_dn_by_oid (gnutls_x509_crq_t crq, const char *oid,
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_set_dn_oid (crq->crq,
|
||||
return MHD__gnutls_x509_set_dn_oid (crq->crq,
|
||||
"certificationRequestInfo.subject", oid,
|
||||
raw_flag, data, sizeof_data);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_set_version - This function will set the Certificate request version
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_set_version - This function will set the Certificate request version
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @version: holds the version number. For v1 Requests must be 1.
|
||||
*
|
||||
* This function will set the version of the certificate request. For
|
||||
@@ -575,14 +575,14 @@ gnutls_x509_crq_set_dn_by_oid (gnutls_x509_crq_t crq, const char *oid,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_set_version (gnutls_x509_crq_t crq, unsigned int version)
|
||||
MHD_gnutls_x509_crq_set_version (MHD_gnutls_x509_crq_t crq, unsigned int version)
|
||||
{
|
||||
int result;
|
||||
unsigned char null = version;
|
||||
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -590,19 +590,19 @@ gnutls_x509_crq_set_version (gnutls_x509_crq_t crq, unsigned int version)
|
||||
null--;
|
||||
|
||||
result =
|
||||
asn1_write_value (crq->crq, "certificationRequestInfo.version", &null, 1);
|
||||
MHD__asn1_write_value (crq->crq, "certificationRequestInfo.version", &null, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_get_version - This function returns the Certificate request's version number
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_get_version - This function returns the Certificate request's version number
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
*
|
||||
* This function will return the version of the specified Certificate request.
|
||||
*
|
||||
@@ -610,35 +610,35 @@ gnutls_x509_crq_set_version (gnutls_x509_crq_t crq, unsigned int version)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_get_version (gnutls_x509_crq_t crq)
|
||||
MHD_gnutls_x509_crq_get_version (MHD_gnutls_x509_crq_t crq)
|
||||
{
|
||||
opaque version[5];
|
||||
int len, result;
|
||||
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
len = sizeof (version);
|
||||
if ((result =
|
||||
asn1_read_value (crq->crq, "certificationRequestInfo.version",
|
||||
MHD__asn1_read_value (crq->crq, "certificationRequestInfo.version",
|
||||
version, &len)) != ASN1_SUCCESS)
|
||||
{
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
return 1; /* the DEFAULT version */
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return (int) version[0] + 1;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_set_key - This function will associate the Certificate request with a key
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_set_key - This function will associate the Certificate request with a key
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @key: holds a private key
|
||||
*
|
||||
* This function will set the public parameters from the given private key to the
|
||||
@@ -648,17 +648,17 @@ gnutls_x509_crq_get_version (gnutls_x509_crq_t crq)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_set_key (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
|
||||
MHD_gnutls_x509_crq_set_key (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key)
|
||||
{
|
||||
int result;
|
||||
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_encode_and_copy_PKI_params (crq->crq,
|
||||
result = MHD__gnutls_x509_encode_and_copy_PKI_params (crq->crq,
|
||||
"certificationRequestInfo.subjectPKInfo",
|
||||
key->pk_algorithm,
|
||||
key->params,
|
||||
@@ -666,7 +666,7 @@ gnutls_x509_crq_set_key (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -674,8 +674,8 @@ gnutls_x509_crq_set_key (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_set_challenge_password - This function will set a challenge password
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_set_challenge_password - This function will set a challenge password
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @pass: holds a null terminated password
|
||||
*
|
||||
* This function will set a challenge password to be used when revoking the request.
|
||||
@@ -684,37 +684,37 @@ gnutls_x509_crq_set_key (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_set_challenge_password (gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_crq_set_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
const char *pass)
|
||||
{
|
||||
int result;
|
||||
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
/* Add the attribute.
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (crq->crq, "certificationRequestInfo.attributes",
|
||||
MHD__asn1_write_value (crq->crq, "certificationRequestInfo.attributes",
|
||||
"NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
_gnutls_x509_encode_and_write_attribute ("1.2.840.113549.1.9.7",
|
||||
MHD__gnutls_x509_encode_and_write_attribute ("1.2.840.113549.1.9.7",
|
||||
crq->crq,
|
||||
"certificationRequestInfo.attributes.?LAST",
|
||||
pass, strlen (pass), 1);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -722,14 +722,14 @@ gnutls_x509_crq_set_challenge_password (gnutls_x509_crq_t crq,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_sign2 - This function will sign a Certificate request with a key
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_sign2 - This function will sign a Certificate request with a key
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @key: holds a private key
|
||||
* @dig: The message digest to use. GNUTLS_DIG_SHA1 is the safe choice unless you know what you're doing.
|
||||
* @flags: must be 0
|
||||
*
|
||||
* This function will sign the certificate request with a private key.
|
||||
* This must be the same key as the one used in gnutls_x509_crt_set_key() since a
|
||||
* This must be the same key as the one used in MHD_gnutls_x509_crt_set_key() since a
|
||||
* certificate request is self signed.
|
||||
*
|
||||
* This must be the last step in a certificate request generation since all
|
||||
@@ -739,52 +739,52 @@ gnutls_x509_crq_set_challenge_password (gnutls_x509_crq_t crq,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_sign2 (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm dig, unsigned int flags)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t signature;
|
||||
MHD_gnutls_datum_t signature;
|
||||
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
/* Step 1. Self sign the request.
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_sign_tbs (crq->crq, "certificationRequestInfo",
|
||||
MHD__gnutls_x509_sign_tbs (crq->crq, "certificationRequestInfo",
|
||||
dig, key, &signature);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Step 2. write the signature (bits)
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (crq->crq, "signature", signature.data,
|
||||
MHD__asn1_write_value (crq->crq, "signature", signature.data,
|
||||
signature.size * 8);
|
||||
|
||||
_gnutls_free_datum (&signature);
|
||||
MHD__gnutls_free_datum (&signature);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Step 3. Write the signatureAlgorithm field.
|
||||
*/
|
||||
result = _gnutls_x509_write_sig_params (crq->crq, "signatureAlgorithm",
|
||||
result = MHD__gnutls_x509_write_sig_params (crq->crq, "signatureAlgorithm",
|
||||
key->pk_algorithm, dig, key->params,
|
||||
key->params_size);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -792,24 +792,24 @@ gnutls_x509_crq_sign2 (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_sign - This function will sign a Certificate request with a key
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_sign - This function will sign a Certificate request with a key
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @key: holds a private key
|
||||
*
|
||||
* This function is the same a gnutls_x509_crq_sign2() with no flags, and
|
||||
* This function is the same a MHD_gnutls_x509_crq_sign2() with no flags, and
|
||||
* SHA1 as the hash algorithm.
|
||||
*
|
||||
* Returns 0 on success.
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_sign (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
|
||||
MHD_gnutls_x509_crq_sign (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key)
|
||||
{
|
||||
return gnutls_x509_crq_sign2 (crq, key, MHD_GNUTLS_MAC_SHA1, 0);
|
||||
return MHD_gnutls_x509_crq_sign2 (crq, key, MHD_GNUTLS_MAC_SHA1, 0);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_export - Export the generated certificate request
|
||||
* MHD_gnutls_x509_crq_export - Export the generated certificate request
|
||||
* @crq: Holds the request
|
||||
* @format: the format of output params. One of PEM or DER.
|
||||
* @output_data: will contain a certificate request PEM or DER encoded
|
||||
@@ -830,23 +830,23 @@ gnutls_x509_crq_sign (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_export (gnutls_x509_crq_t crq,
|
||||
gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
MHD_gnutls_x509_crq_export (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
size_t * output_data_size)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_export_int (crq->crq, format, PEM_CRQ,
|
||||
return MHD__gnutls_x509_export_int (crq->crq, format, PEM_CRQ,
|
||||
output_data, output_data_size);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crq_get_pk_algorithm - This function returns the certificate request's PublicKey algorithm
|
||||
* @crq: should contain a gnutls_x509_crq_t structure
|
||||
* MHD_gnutls_x509_crq_get_pk_algorithm - This function returns the certificate request's PublicKey algorithm
|
||||
* @crq: should contain a MHD_gnutls_x509_crq_t structure
|
||||
* @bits: if bits is non null it will hold the size of the parameters' in bits
|
||||
*
|
||||
* This function will return the public key algorithm of a PKCS \#10
|
||||
@@ -862,23 +862,23 @@ gnutls_x509_crq_export (gnutls_x509_crq_t crq,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crq_get_pk_algorithm (gnutls_x509_crq_t crq, unsigned int *bits)
|
||||
MHD_gnutls_x509_crq_get_pk_algorithm (MHD_gnutls_x509_crq_t crq, unsigned int *bits)
|
||||
{
|
||||
int result;
|
||||
|
||||
if (crq == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
result =
|
||||
_gnutls_x509_get_pk_algorithm (crq->crq,
|
||||
MHD__gnutls_x509_get_pk_algorithm (crq->crq,
|
||||
"certificationRequestInfo.subjectPKInfo",
|
||||
bits);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
}
|
||||
|
||||
return result;
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
|
||||
#include <x509.h>
|
||||
|
||||
typedef struct gnutls_x509_crq_int
|
||||
typedef struct MHD_gnutls_x509_crq_int
|
||||
{
|
||||
ASN1_TYPE crq;
|
||||
} gnutls_x509_crq_int;
|
||||
} MHD_gnutls_x509_crq_int;
|
||||
+217
-217
@@ -44,7 +44,7 @@ oid2ldap_string (const char *oid)
|
||||
{
|
||||
const char *ret;
|
||||
|
||||
ret = _gnutls_x509_oid2ldap_string (oid);
|
||||
ret = MHD__gnutls_x509_oid2ldap_string (oid);
|
||||
if (ret)
|
||||
return ret;
|
||||
|
||||
@@ -80,18 +80,18 @@ str_escape (char *str, char *buffer, unsigned int buffer_size)
|
||||
return buffer;
|
||||
}
|
||||
|
||||
/* Parses an X509 DN in the asn1_struct, and puts the output into
|
||||
/* Parses an X509 DN in the MHD__asn1_struct, and puts the output into
|
||||
* the string buf. The output is an LDAP encoded DN.
|
||||
*
|
||||
* asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
|
||||
* MHD__asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
|
||||
* That is to point in the rndSequence.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name, char *buf,
|
||||
MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name, char *buf,
|
||||
size_t * sizeof_buf)
|
||||
{
|
||||
mhd_gtls_string out_str;
|
||||
MHD_gtls_string out_str;
|
||||
int k2, k1, result;
|
||||
char tmpbuffer1[MAX_NAME_SIZE];
|
||||
char tmpbuffer2[MAX_NAME_SIZE];
|
||||
@@ -106,7 +106,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
|
||||
if (sizeof_buf == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -115,7 +115,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
else
|
||||
*sizeof_buf = 0;
|
||||
|
||||
mhd_gtls_string_init (&out_str, gnutls_malloc, gnutls_realloc, gnutls_free);
|
||||
MHD_gtls_string_init (&out_str, MHD_gnutls_malloc, MHD_gnutls_realloc, MHD_gnutls_free);
|
||||
|
||||
k1 = 0;
|
||||
do
|
||||
@@ -124,14 +124,14 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
k1++;
|
||||
/* create a string like "tbsCertList.issuer.rdnSequence.?1"
|
||||
*/
|
||||
if (asn1_rdn_name[0] != 0)
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", asn1_rdn_name,
|
||||
if (MHD__asn1_rdn_name[0] != 0)
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", MHD__asn1_rdn_name,
|
||||
k1);
|
||||
else
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer1, value, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -140,8 +140,8 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
|
||||
if (result != ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -162,60 +162,60 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
*/
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer2, value, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
break;
|
||||
if (result != ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Read the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
break;
|
||||
else if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Read the Value
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
|
||||
len = 0;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, NULL, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, NULL, &len);
|
||||
|
||||
value2 = gnutls_malloc (len);
|
||||
value2 = MHD_gnutls_malloc (len);
|
||||
if (value2 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, value2, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, value2, &len);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
#define STR_APPEND(y) if ((result=mhd_gtls_string_append_str( &out_str, y)) < 0) { \
|
||||
gnutls_assert(); \
|
||||
#define STR_APPEND(y) if ((result=MHD_gtls_string_append_str( &out_str, y)) < 0) { \
|
||||
MHD_gnutls_assert(); \
|
||||
goto cleanup; \
|
||||
}
|
||||
/* The encodings of adjoining RelativeDistinguishedNames are separated
|
||||
@@ -239,24 +239,24 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
}
|
||||
|
||||
ldap_desc = oid2ldap_string (oid);
|
||||
printable = _gnutls_x509_oid_data_printable (oid);
|
||||
printable = MHD__gnutls_x509_oid_data_printable (oid);
|
||||
|
||||
sizeof_escaped = 2 * len + 1;
|
||||
|
||||
escaped = gnutls_malloc (sizeof_escaped);
|
||||
escaped = MHD_gnutls_malloc (sizeof_escaped);
|
||||
if (escaped == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
sizeof_string = 2 * len + 2; /* in case it is not printable */
|
||||
|
||||
string = gnutls_malloc (sizeof_string);
|
||||
string = MHD_gnutls_malloc (sizeof_string);
|
||||
if (string == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
@@ -267,30 +267,30 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
|
||||
if (printable)
|
||||
result =
|
||||
_gnutls_x509_oid_data2string (oid,
|
||||
MHD__gnutls_x509_oid_data2string (oid,
|
||||
value2, len,
|
||||
string, &sizeof_string);
|
||||
|
||||
if (!printable || result < 0)
|
||||
result =
|
||||
_gnutls_x509_data2hex (value2, len, string, &sizeof_string);
|
||||
MHD__gnutls_x509_data2hex (value2, len, string, &sizeof_string);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_x509_log
|
||||
("Found OID: '%s' with value '%s'\n",
|
||||
oid, mhd_gtls_bin2hex (value2, len, escaped,
|
||||
oid, MHD_gtls_bin2hex (value2, len, escaped,
|
||||
sizeof_escaped));
|
||||
goto cleanup;
|
||||
}
|
||||
STR_APPEND (str_escape (string, escaped, sizeof_escaped));
|
||||
gnutls_free (string);
|
||||
MHD_gnutls_free (string);
|
||||
string = NULL;
|
||||
|
||||
gnutls_free (escaped);
|
||||
MHD_gnutls_free (escaped);
|
||||
escaped = NULL;
|
||||
gnutls_free (value2);
|
||||
MHD_gnutls_free (value2);
|
||||
value2 = NULL;
|
||||
|
||||
}
|
||||
@@ -301,7 +301,7 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
|
||||
if (out_str.length >= (unsigned int) *sizeof_buf)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
*sizeof_buf = out_str.length + 1;
|
||||
result = GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
goto cleanup;
|
||||
@@ -317,28 +317,28 @@ _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
result = 0;
|
||||
|
||||
cleanup:
|
||||
gnutls_free (value2);
|
||||
gnutls_free (string);
|
||||
gnutls_free (escaped);
|
||||
mhd_gtls_string_clear (&out_str);
|
||||
MHD_gnutls_free (value2);
|
||||
MHD_gnutls_free (string);
|
||||
MHD_gnutls_free (escaped);
|
||||
MHD_gtls_string_clear (&out_str);
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Parses an X509 DN in the asn1_struct, and searches for the
|
||||
/* Parses an X509 DN in the MHD__asn1_struct, and searches for the
|
||||
* given OID in the DN.
|
||||
*
|
||||
* If raw_flag == 0, the output will be encoded in the LDAP way. (#hex for non printable)
|
||||
* Otherwise the raw DER data are returned.
|
||||
*
|
||||
* asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
|
||||
* MHD__asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
|
||||
* That is to point in the rndSequence.
|
||||
*
|
||||
* indx specifies which OID to return. Ie 0 means return the first specified
|
||||
* OID found, 1 the second etc.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name,
|
||||
MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name,
|
||||
const char *given_oid, int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
@@ -365,25 +365,25 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
k1++;
|
||||
/* create a string like "tbsCertList.issuer.rdnSequence.?1"
|
||||
*/
|
||||
if (asn1_rdn_name[0] != 0)
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", asn1_rdn_name,
|
||||
if (MHD__asn1_rdn_name[0] != 0)
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", MHD__asn1_rdn_name,
|
||||
k1);
|
||||
else
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer1, value, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
break;
|
||||
}
|
||||
|
||||
if (result != ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -404,7 +404,7 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
*/
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer2, value, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -412,25 +412,25 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
}
|
||||
if (result != ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Read the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
break;
|
||||
else if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -439,18 +439,18 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
|
||||
/* Read the Value
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
|
||||
len = *sizeof_buf;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, buf, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, buf, &len);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
if (result == ASN1_MEM_ERROR)
|
||||
*sizeof_buf = len;
|
||||
result = mhd_gtls_asn2err (result);
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -469,19 +469,19 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
}
|
||||
else
|
||||
{ /* parse data. raw_flag == 0 */
|
||||
printable = _gnutls_x509_oid_data_printable (oid);
|
||||
printable = MHD__gnutls_x509_oid_data_printable (oid);
|
||||
|
||||
if (printable == 1)
|
||||
result =
|
||||
_gnutls_x509_oid_data2string (oid, buf, len,
|
||||
MHD__gnutls_x509_oid_data2string (oid, buf, len,
|
||||
cbuf, sizeof_buf);
|
||||
else
|
||||
result =
|
||||
_gnutls_x509_data2hex (buf, len, cbuf, sizeof_buf);
|
||||
MHD__gnutls_x509_data2hex (buf, len, cbuf, sizeof_buf);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -495,7 +495,7 @@ _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
}
|
||||
while (1);
|
||||
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
|
||||
result = GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
|
||||
@@ -504,18 +504,18 @@ cleanup:
|
||||
}
|
||||
|
||||
|
||||
/* Parses an X509 DN in the asn1_struct, and returns the requested
|
||||
/* Parses an X509 DN in the MHD__asn1_struct, and returns the requested
|
||||
* DN OID.
|
||||
*
|
||||
* asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
|
||||
* MHD__asn1_rdn_name must be a string in the form "tbsCertificate.issuer.rdnSequence".
|
||||
* That is to point in the rndSequence.
|
||||
*
|
||||
* indx specifies which OID to return. Ie 0 means return the first specified
|
||||
* OID found, 1 the second etc.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name,
|
||||
MHD__gnutls_x509_get_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name,
|
||||
int indx, void *_oid, size_t * sizeof_oid)
|
||||
{
|
||||
int k2, k1, result;
|
||||
@@ -534,25 +534,25 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
|
||||
k1++;
|
||||
/* create a string like "tbsCertList.issuer.rdnSequence.?1"
|
||||
*/
|
||||
if (asn1_rdn_name[0] != 0)
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", asn1_rdn_name,
|
||||
if (MHD__asn1_rdn_name[0] != 0)
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", MHD__asn1_rdn_name,
|
||||
k1);
|
||||
else
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer1, value, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
break;
|
||||
}
|
||||
|
||||
if (result != ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -573,7 +573,7 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
|
||||
*/
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer2, value, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -581,25 +581,25 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
|
||||
}
|
||||
if (result != ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Read the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
mhd_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
MHD_gtls_str_cpy (tmpbuffer3, sizeof (tmpbuffer3), tmpbuffer2);
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer3, oid, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
break;
|
||||
else if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -611,7 +611,7 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
|
||||
if (*sizeof_oid < (unsigned) len)
|
||||
{
|
||||
*sizeof_oid = len;
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
|
||||
@@ -626,7 +626,7 @@ _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
|
||||
}
|
||||
while (1);
|
||||
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
|
||||
result = GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
|
||||
@@ -639,8 +639,8 @@ cleanup:
|
||||
* In all cases only one value is written.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
ASN1_TYPE asn1_struct,
|
||||
MHD__gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where,
|
||||
const void *_data,
|
||||
int sizeof_data, int multi)
|
||||
@@ -654,26 +654,26 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
|
||||
/* Find how to encode the data.
|
||||
*/
|
||||
val_name = asn1_find_structure_from_oid (_gnutls_get_pkix (), given_oid);
|
||||
val_name = MHD__asn1_find_structure_from_oid (MHD__gnutls_get_pkix (), given_oid);
|
||||
if (val_name == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_X509_UNSUPPORTED_OID;
|
||||
}
|
||||
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), "PKIX1.");
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), val_name);
|
||||
MHD_gtls_str_cpy (tmp, sizeof (tmp), "PKIX1.");
|
||||
MHD_gtls_str_cat (tmp, sizeof (tmp), val_name);
|
||||
|
||||
result = asn1_create_element (_gnutls_get_pkix (), tmp, &c2);
|
||||
result = MHD__asn1_create_element (MHD__gnutls_get_pkix (), tmp, &c2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
tmp[0] = 0;
|
||||
|
||||
if ((result = _gnutls_x509_oid_data_choice (given_oid)) > 0)
|
||||
if ((result = MHD__gnutls_x509_oid_data_choice (given_oid)) > 0)
|
||||
{
|
||||
char *string_type;
|
||||
int i;
|
||||
@@ -695,64 +695,64 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
/* if the type is a CHOICE then write the
|
||||
* type we'll use.
|
||||
*/
|
||||
result = asn1_write_value (c2, "", string_type, 1);
|
||||
result = MHD__asn1_write_value (c2, "", string_type, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), string_type);
|
||||
MHD_gtls_str_cpy (tmp, sizeof (tmp), string_type);
|
||||
}
|
||||
|
||||
result = asn1_write_value (c2, tmp, data, sizeof_data);
|
||||
result = MHD__asn1_write_value (c2, tmp, data, sizeof_data);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
|
||||
/* write the data (value)
|
||||
*/
|
||||
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".value");
|
||||
MHD_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
MHD_gtls_str_cat (tmp, sizeof (tmp), ".value");
|
||||
|
||||
if (multi != 0)
|
||||
{ /* if not writing an AttributeTypeAndValue, but an Attribute */
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), "s"); /* values */
|
||||
MHD_gtls_str_cat (tmp, sizeof (tmp), "s"); /* values */
|
||||
|
||||
result = asn1_write_value (asn1_struct, tmp, "NEW", 1);
|
||||
result = MHD__asn1_write_value (MHD__asn1_struct, tmp, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
|
||||
MHD_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
|
||||
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode_and_copy (c2, "", asn1_struct, tmp, 0);
|
||||
result = MHD__gnutls_x509_der_encode_and_copy (c2, "", MHD__asn1_struct, tmp, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* write the type
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".type");
|
||||
MHD_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
MHD_gtls_str_cat (tmp, sizeof (tmp), ".type");
|
||||
|
||||
result = asn1_write_value (asn1_struct, tmp, given_oid, 1);
|
||||
result = MHD__asn1_write_value (MHD__asn1_struct, tmp, given_oid, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
@@ -762,8 +762,8 @@ _gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
* In all cases only one value is written.
|
||||
*/
|
||||
static int
|
||||
_gnutls_x509_write_attribute (const char *given_oid,
|
||||
ASN1_TYPE asn1_struct, const char *where,
|
||||
MHD__gnutls_x509_write_attribute (const char *given_oid,
|
||||
ASN1_TYPE MHD__asn1_struct, const char *where,
|
||||
const void *_data, int sizeof_data)
|
||||
{
|
||||
char tmp[128];
|
||||
@@ -772,26 +772,26 @@ _gnutls_x509_write_attribute (const char *given_oid,
|
||||
/* write the data (value)
|
||||
*/
|
||||
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".value");
|
||||
MHD_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
MHD_gtls_str_cat (tmp, sizeof (tmp), ".value");
|
||||
|
||||
result = asn1_write_value (asn1_struct, tmp, _data, sizeof_data);
|
||||
result = MHD__asn1_write_value (MHD__asn1_struct, tmp, _data, sizeof_data);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* write the type
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".type");
|
||||
MHD_gtls_str_cpy (tmp, sizeof (tmp), where);
|
||||
MHD_gtls_str_cat (tmp, sizeof (tmp), ".type");
|
||||
|
||||
result = asn1_write_value (asn1_struct, tmp, given_oid, 1);
|
||||
result = MHD__asn1_write_value (MHD__asn1_struct, tmp, given_oid, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
@@ -807,9 +807,9 @@ _gnutls_x509_write_attribute (const char *given_oid,
|
||||
* The output is allocated and stored in value.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
|
||||
MHD__gnutls_x509_decode_and_read_attribute (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where, char *oid,
|
||||
int oid_size, gnutls_datum_t * value,
|
||||
int oid_size, MHD_gnutls_datum_t * value,
|
||||
int multi, int octet_string)
|
||||
{
|
||||
char tmpbuffer[128];
|
||||
@@ -817,33 +817,33 @@ _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
|
||||
|
||||
/* Read the OID
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
|
||||
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".type");
|
||||
MHD_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
|
||||
MHD_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".type");
|
||||
|
||||
len = oid_size - 1;
|
||||
result = asn1_read_value (asn1_struct, tmpbuffer, oid, &len);
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer, oid, &len);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Read the Value
|
||||
*/
|
||||
|
||||
mhd_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
|
||||
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".value");
|
||||
MHD_gtls_str_cpy (tmpbuffer, sizeof (tmpbuffer), where);
|
||||
MHD_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), ".value");
|
||||
|
||||
if (multi)
|
||||
mhd_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), "s.?1"); /* .values.?1 */
|
||||
MHD_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), "s.?1"); /* .values.?1 */
|
||||
|
||||
result =
|
||||
_gnutls_x509_read_value (asn1_struct, tmpbuffer, value, octet_string);
|
||||
MHD__gnutls_x509_read_value (MHD__asn1_struct, tmpbuffer, value, octet_string);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -851,83 +851,83 @@ _gnutls_x509_decode_and_read_attribute (ASN1_TYPE asn1_struct,
|
||||
|
||||
}
|
||||
|
||||
/* Sets an X509 DN in the asn1_struct, and puts the given OID in the DN.
|
||||
/* Sets an X509 DN in the MHD__asn1_struct, and puts the given OID in the DN.
|
||||
* The input is assumed to be raw data.
|
||||
*
|
||||
* asn1_rdn_name must be a string in the form "tbsCertificate.issuer".
|
||||
* MHD__asn1_rdn_name must be a string in the form "tbsCertificate.issuer".
|
||||
* That is to point before the rndSequence.
|
||||
*
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_name, const char *given_oid,
|
||||
MHD__gnutls_x509_set_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_name, const char *given_oid,
|
||||
int raw_flag, const char *name, int sizeof_name)
|
||||
{
|
||||
int result;
|
||||
char tmp[MAX_NAME_SIZE], asn1_rdn_name[MAX_NAME_SIZE];
|
||||
char tmp[MAX_NAME_SIZE], MHD__asn1_rdn_name[MAX_NAME_SIZE];
|
||||
|
||||
if (sizeof_name == 0 || name == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
/* create the rdnSequence
|
||||
*/
|
||||
result = asn1_write_value (asn1_struct, asn1_name, "rdnSequence", 1);
|
||||
result = MHD__asn1_write_value (MHD__asn1_struct, MHD__asn1_name, "rdnSequence", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
mhd_gtls_str_cpy (asn1_rdn_name, sizeof (asn1_rdn_name), asn1_name);
|
||||
mhd_gtls_str_cat (asn1_rdn_name, sizeof (asn1_rdn_name), ".rdnSequence");
|
||||
MHD_gtls_str_cpy (MHD__asn1_rdn_name, sizeof (MHD__asn1_rdn_name), MHD__asn1_name);
|
||||
MHD_gtls_str_cat (MHD__asn1_rdn_name, sizeof (MHD__asn1_rdn_name), ".rdnSequence");
|
||||
|
||||
/* create a new element
|
||||
*/
|
||||
result = asn1_write_value (asn1_struct, asn1_rdn_name, "NEW", 1);
|
||||
result = MHD__asn1_write_value (MHD__asn1_struct, MHD__asn1_rdn_name, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), asn1_rdn_name);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
|
||||
MHD_gtls_str_cpy (tmp, sizeof (tmp), MHD__asn1_rdn_name);
|
||||
MHD_gtls_str_cat (tmp, sizeof (tmp), ".?LAST");
|
||||
|
||||
/* create the set with only one element
|
||||
*/
|
||||
result = asn1_write_value (asn1_struct, tmp, "NEW", 1);
|
||||
result = MHD__asn1_write_value (MHD__asn1_struct, tmp, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
|
||||
/* Encode and write the data
|
||||
*/
|
||||
mhd_gtls_str_cpy (tmp, sizeof (tmp), asn1_rdn_name);
|
||||
mhd_gtls_str_cat (tmp, sizeof (tmp), ".?LAST.?LAST");
|
||||
MHD_gtls_str_cpy (tmp, sizeof (tmp), MHD__asn1_rdn_name);
|
||||
MHD_gtls_str_cat (tmp, sizeof (tmp), ".?LAST.?LAST");
|
||||
|
||||
if (!raw_flag)
|
||||
{
|
||||
result =
|
||||
_gnutls_x509_encode_and_write_attribute (given_oid,
|
||||
asn1_struct,
|
||||
MHD__gnutls_x509_encode_and_write_attribute (given_oid,
|
||||
MHD__asn1_struct,
|
||||
tmp, name, sizeof_name, 0);
|
||||
}
|
||||
else
|
||||
{
|
||||
result =
|
||||
_gnutls_x509_write_attribute (given_oid, asn1_struct,
|
||||
MHD__gnutls_x509_write_attribute (given_oid, MHD__asn1_struct,
|
||||
tmp, name, sizeof_name);
|
||||
}
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -936,7 +936,7 @@ _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_x509_rdn_get - This function parses an RDN sequence and returns a string
|
||||
* MHD_gnutls_x509_rdn_get - This function parses an RDN sequence and returns a string
|
||||
* @idn: should contain a DER encoded RDN sequence
|
||||
* @buf: a pointer to a structure to hold the peer's name
|
||||
* @sizeof_buf: holds the size of @buf
|
||||
@@ -951,7 +951,7 @@ _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_rdn_get (const gnutls_datum_t * idn,
|
||||
MHD_gnutls_x509_rdn_get (const MHD_gnutls_datum_t * idn,
|
||||
char *buf, size_t * sizeof_buf)
|
||||
{
|
||||
int result;
|
||||
@@ -959,7 +959,7 @@ gnutls_x509_rdn_get (const gnutls_datum_t * idn,
|
||||
|
||||
if (sizeof_buf == 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -968,31 +968,31 @@ gnutls_x509_rdn_get (const gnutls_datum_t * idn,
|
||||
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&dn, idn->data, idn->size, NULL);
|
||||
result = MHD__asn1_der_decoding (&dn, idn->data, idn->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
/* couldn't decode DER */
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dn);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dn);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_parse_dn (dn, "rdnSequence", buf, sizeof_buf);
|
||||
result = MHD__gnutls_x509_parse_dn (dn, "rdnSequence", buf, sizeof_buf);
|
||||
|
||||
asn1_delete_structure (&dn);
|
||||
MHD__asn1_delete_structure (&dn);
|
||||
return result;
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_rdn_get_by_oid - This function parses an RDN sequence and returns a string
|
||||
* MHD_gnutls_x509_rdn_get_by_oid - This function parses an RDN sequence and returns a string
|
||||
* @idn: should contain a DER encoded RDN sequence
|
||||
* @oid: an Object Identifier
|
||||
* @indx: In case multiple same OIDs exist in the RDN indicates which
|
||||
@@ -1010,7 +1010,7 @@ gnutls_x509_rdn_get (const gnutls_datum_t * idn,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_rdn_get_by_oid (const gnutls_datum_t * idn, const char *oid,
|
||||
MHD_gnutls_x509_rdn_get_by_oid (const MHD_gnutls_datum_t * idn, const char *oid,
|
||||
int indx, unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
{
|
||||
@@ -1023,33 +1023,33 @@ gnutls_x509_rdn_get_by_oid (const gnutls_datum_t * idn, const char *oid,
|
||||
}
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&dn, idn->data, idn->size, NULL);
|
||||
result = MHD__asn1_der_decoding (&dn, idn->data, idn->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
/* couldn't decode DER */
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dn);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dn);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
_gnutls_x509_parse_dn_oid (dn, "rdnSequence", oid, indx,
|
||||
MHD__gnutls_x509_parse_dn_oid (dn, "rdnSequence", oid, indx,
|
||||
raw_flag, buf, sizeof_buf);
|
||||
|
||||
asn1_delete_structure (&dn);
|
||||
MHD__asn1_delete_structure (&dn);
|
||||
return result;
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_rdn_get_oid - This function parses an RDN sequence and returns an OID.
|
||||
* MHD_gnutls_x509_rdn_get_oid - This function parses an RDN sequence and returns an OID.
|
||||
* @idn: should contain a DER encoded RDN sequence
|
||||
* @indx: Indicates which OID to return. Use 0 for the first one.
|
||||
* @oid: a pointer to a structure to hold the peer's name OID
|
||||
@@ -1063,7 +1063,7 @@ gnutls_x509_rdn_get_by_oid (const gnutls_datum_t * idn, const char *oid,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_rdn_get_oid (const gnutls_datum_t * idn,
|
||||
MHD_gnutls_x509_rdn_get_oid (const MHD_gnutls_datum_t * idn,
|
||||
int indx, void *buf, size_t * sizeof_buf)
|
||||
{
|
||||
int result;
|
||||
@@ -1075,25 +1075,25 @@ gnutls_x509_rdn_get_oid (const gnutls_datum_t * idn,
|
||||
}
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&dn, idn->data, idn->size, NULL);
|
||||
result = MHD__asn1_der_decoding (&dn, idn->data, idn->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
/* couldn't decode DER */
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dn);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dn);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_get_dn_oid (dn, "rdnSequence", indx, buf, sizeof_buf);
|
||||
result = MHD__gnutls_x509_get_dn_oid (dn, "rdnSequence", indx, buf, sizeof_buf);
|
||||
|
||||
asn1_delete_structure (&dn);
|
||||
MHD__asn1_delete_structure (&dn);
|
||||
return result;
|
||||
|
||||
}
|
||||
@@ -1107,18 +1107,18 @@ gnutls_x509_rdn_get_oid (const gnutls_datum_t * idn,
|
||||
* a negative value is returned to indicate error.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_compare_raw_dn (const gnutls_datum_t * dn1,
|
||||
const gnutls_datum_t * dn2)
|
||||
MHD__gnutls_x509_compare_raw_dn (const MHD_gnutls_datum_t * dn1,
|
||||
const MHD_gnutls_datum_t * dn2)
|
||||
{
|
||||
|
||||
if (dn1->size != dn2->size)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return 0;
|
||||
}
|
||||
if (memcmp (dn1->data, dn2->data, dn2->size) != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return 0;
|
||||
}
|
||||
return 1; /* they match */
|
||||
|
||||
@@ -37,21 +37,21 @@
|
||||
#define OID_LDAP_UID "0.9.2342.19200300.100.1.1"
|
||||
#define OID_PKCS9_EMAIL "1.2.840.113549.1.9.1"
|
||||
|
||||
int _gnutls_x509_parse_dn (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name, char *buf,
|
||||
int MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name, char *buf,
|
||||
size_t * sizeof_buf);
|
||||
|
||||
int _gnutls_x509_parse_dn_oid (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name, const char *oid,
|
||||
int MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name, const char *oid,
|
||||
int indx, unsigned int raw_flag, void *buf,
|
||||
size_t * sizeof_buf);
|
||||
|
||||
int _gnutls_x509_set_dn_oid (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name, const char *oid,
|
||||
int MHD__gnutls_x509_set_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name, const char *oid,
|
||||
int raw_flag, const char *name, int sizeof_name);
|
||||
|
||||
int _gnutls_x509_get_dn_oid (ASN1_TYPE asn1_struct,
|
||||
const char *asn1_rdn_name,
|
||||
int MHD__gnutls_x509_get_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name,
|
||||
int indx, void *_oid, size_t * sizeof_oid);
|
||||
|
||||
|
||||
|
||||
+15
-15
@@ -33,7 +33,7 @@
|
||||
/* resarr will contain: p(0), q(1), g(2), y(3), x(4).
|
||||
*/
|
||||
int
|
||||
_gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
|
||||
MHD__gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
|
||||
{
|
||||
|
||||
int ret;
|
||||
@@ -42,20 +42,20 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
|
||||
/* FIXME: Remove me once we depend on 1.3.1 */
|
||||
if (bits > 1024 && gcry_check_version ("1.3.1") == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (bits < 512)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
ret = gcry_sexp_build (&parms, NULL, "(genkey(dsa(nbits %d)))", bits);
|
||||
if (ret != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
@@ -66,14 +66,14 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
|
||||
|
||||
if (ret != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
list = gcry_sexp_find_token (key, "p", 0);
|
||||
if (list == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
gcry_sexp_release (key);
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
@@ -84,7 +84,7 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
|
||||
list = gcry_sexp_find_token (key, "q", 0);
|
||||
if (list == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
gcry_sexp_release (key);
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
@@ -95,7 +95,7 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
|
||||
list = gcry_sexp_find_token (key, "g", 0);
|
||||
if (list == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
gcry_sexp_release (key);
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
@@ -106,7 +106,7 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
|
||||
list = gcry_sexp_find_token (key, "y", 0);
|
||||
if (list == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
gcry_sexp_release (key);
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
@@ -118,7 +118,7 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
|
||||
list = gcry_sexp_find_token (key, "x", 0);
|
||||
if (list == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
gcry_sexp_release (key);
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
@@ -129,11 +129,11 @@ _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits)
|
||||
|
||||
gcry_sexp_release (key);
|
||||
|
||||
_gnutls_dump_mpi ("p: ", resarr[0]);
|
||||
_gnutls_dump_mpi ("q: ", resarr[1]);
|
||||
_gnutls_dump_mpi ("g: ", resarr[2]);
|
||||
_gnutls_dump_mpi ("y: ", resarr[3]);
|
||||
_gnutls_dump_mpi ("x: ", resarr[4]);
|
||||
MHD__gnutls_dump_mpi ("p: ", resarr[0]);
|
||||
MHD__gnutls_dump_mpi ("q: ", resarr[1]);
|
||||
MHD__gnutls_dump_mpi ("g: ", resarr[2]);
|
||||
MHD__gnutls_dump_mpi ("y: ", resarr[3]);
|
||||
MHD__gnutls_dump_mpi ("x: ", resarr[4]);
|
||||
|
||||
*resarr_len = 5;
|
||||
|
||||
|
||||
@@ -22,4 +22,4 @@
|
||||
*
|
||||
*/
|
||||
|
||||
int _gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits);
|
||||
int MHD__gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits);
|
||||
+244
-244
@@ -45,9 +45,9 @@
|
||||
* be returned.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
MHD__gnutls_x509_crt_get_extension (MHD_gnutls_x509_crt_t cert,
|
||||
const char *extension_id, int indx,
|
||||
gnutls_datum_t * ret, unsigned int *_critical)
|
||||
MHD_gnutls_datum_t * ret, unsigned int *_critical)
|
||||
{
|
||||
int k, result, len;
|
||||
char name[MAX_NAME_SIZE], name2[MAX_NAME_SIZE];
|
||||
@@ -55,7 +55,7 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
char str_critical[10];
|
||||
int critical = 0;
|
||||
char extnID[128];
|
||||
gnutls_datum_t value;
|
||||
MHD_gnutls_datum_t value;
|
||||
int indx_counter = 0;
|
||||
|
||||
ret->data = NULL;
|
||||
@@ -69,7 +69,7 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
snprintf (name, sizeof (name), "tbsCertificate.extensions.?%u", k);
|
||||
|
||||
len = sizeof (str) - 1;
|
||||
result = asn1_read_value (cert->cert, name, str, &len);
|
||||
result = MHD__asn1_read_value (cert->cert, name, str, &len);
|
||||
|
||||
/* move to next
|
||||
*/
|
||||
@@ -82,21 +82,21 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
do
|
||||
{
|
||||
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
MHD_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
MHD_gtls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
|
||||
len = sizeof (extnID) - 1;
|
||||
result = asn1_read_value (cert->cert, name2, extnID, &len);
|
||||
result = MHD__asn1_read_value (cert->cert, name2, extnID, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
break;
|
||||
}
|
||||
else if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Handle Extension
|
||||
@@ -108,22 +108,22 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
|
||||
/* read the critical status.
|
||||
*/
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".critical");
|
||||
MHD_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
MHD_gtls_str_cat (name2, sizeof (name2), ".critical");
|
||||
|
||||
len = sizeof (str_critical);
|
||||
result =
|
||||
asn1_read_value (cert->cert, name2, str_critical, &len);
|
||||
MHD__asn1_read_value (cert->cert, name2, str_critical, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
break;
|
||||
}
|
||||
else if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (str_critical[0] == 'T')
|
||||
@@ -133,13 +133,13 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
|
||||
/* read the value.
|
||||
*/
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".extnValue");
|
||||
MHD_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
MHD_gtls_str_cat (name2, sizeof (name2), ".extnValue");
|
||||
|
||||
result = _gnutls_x509_read_value (cert->cert, name2, &value, 0);
|
||||
result = MHD__gnutls_x509_read_value (cert->cert, name2, &value, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -164,8 +164,8 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
}
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -176,7 +176,7 @@ _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
* be returned.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
MHD__gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
{
|
||||
int k, result, len;
|
||||
@@ -193,7 +193,7 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
snprintf (name, sizeof (name), "tbsCertificate.extensions.?%u", k);
|
||||
|
||||
len = sizeof (str) - 1;
|
||||
result = asn1_read_value (cert->cert, name, str, &len);
|
||||
result = MHD__asn1_read_value (cert->cert, name, str, &len);
|
||||
|
||||
/* move to next
|
||||
*/
|
||||
@@ -206,21 +206,21 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
do
|
||||
{
|
||||
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
MHD_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
MHD_gtls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
|
||||
len = sizeof (extnID) - 1;
|
||||
result = asn1_read_value (cert->cert, name2, extnID, &len);
|
||||
result = MHD__asn1_read_value (cert->cert, name2, extnID, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
break;
|
||||
}
|
||||
else if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Handle Extension
|
||||
@@ -232,7 +232,7 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
if (*sizeof_oid < (unsigned) len)
|
||||
{
|
||||
*sizeof_oid = len;
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
|
||||
@@ -254,8 +254,8 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
}
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -266,27 +266,27 @@ _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
*/
|
||||
static int
|
||||
set_extension (ASN1_TYPE asn, const char *extension_id,
|
||||
const gnutls_datum_t * ext_data, unsigned int critical)
|
||||
const MHD_gnutls_datum_t * ext_data, unsigned int critical)
|
||||
{
|
||||
int result;
|
||||
const char *str;
|
||||
|
||||
/* Add a new extension in the list.
|
||||
*/
|
||||
result = asn1_write_value (asn, "tbsCertificate.extensions", "NEW", 1);
|
||||
result = MHD__asn1_write_value (asn, "tbsCertificate.extensions", "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_write_value (asn, "tbsCertificate.extensions.?LAST.extnID",
|
||||
MHD__asn1_write_value (asn, "tbsCertificate.extensions.?LAST.extnID",
|
||||
extension_id, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (critical == 0)
|
||||
@@ -296,21 +296,21 @@ set_extension (ASN1_TYPE asn, const char *extension_id,
|
||||
|
||||
|
||||
result =
|
||||
asn1_write_value (asn, "tbsCertificate.extensions.?LAST.critical",
|
||||
MHD__asn1_write_value (asn, "tbsCertificate.extensions.?LAST.critical",
|
||||
str, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
_gnutls_x509_write_value (asn,
|
||||
MHD__gnutls_x509_write_value (asn,
|
||||
"tbsCertificate.extensions.?LAST.extnValue",
|
||||
ext_data, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -322,7 +322,7 @@ set_extension (ASN1_TYPE asn, const char *extension_id,
|
||||
*/
|
||||
static int
|
||||
overwrite_extension (ASN1_TYPE asn, unsigned int indx,
|
||||
const gnutls_datum_t * ext_data, unsigned int critical)
|
||||
const MHD_gnutls_datum_t * ext_data, unsigned int critical)
|
||||
{
|
||||
char name[MAX_NAME_SIZE], name2[MAX_NAME_SIZE];
|
||||
const char *str;
|
||||
@@ -335,23 +335,23 @@ overwrite_extension (ASN1_TYPE asn, unsigned int indx,
|
||||
else
|
||||
str = "TRUE";
|
||||
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".critical");
|
||||
MHD_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
MHD_gtls_str_cat (name2, sizeof (name2), ".critical");
|
||||
|
||||
result = asn1_write_value (asn, name2, str, 1);
|
||||
result = MHD__asn1_write_value (asn, name2, str, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".extnValue");
|
||||
MHD_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
MHD_gtls_str_cat (name2, sizeof (name2), ".extnValue");
|
||||
|
||||
result = _gnutls_x509_write_value (asn, name2, ext_data, 0);
|
||||
result = MHD__gnutls_x509_write_value (asn, name2, ext_data, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -364,9 +364,9 @@ overwrite_extension (ASN1_TYPE asn, unsigned int indx,
|
||||
* Critical will be either 0 or 1.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
|
||||
MHD__gnutls_x509_crt_set_extension (MHD_gnutls_x509_crt_t cert,
|
||||
const char *ext_id,
|
||||
const gnutls_datum_t * ext_data,
|
||||
const MHD_gnutls_datum_t * ext_data,
|
||||
unsigned int critical)
|
||||
{
|
||||
int result;
|
||||
@@ -384,7 +384,7 @@ _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
|
||||
snprintf (name, sizeof (name), "tbsCertificate.extensions.?%u", k);
|
||||
|
||||
len = sizeof (extnID) - 1;
|
||||
result = asn1_read_value (cert->cert, name, extnID, &len);
|
||||
result = MHD__asn1_read_value (cert->cert, name, extnID, &len);
|
||||
|
||||
/* move to next
|
||||
*/
|
||||
@@ -397,21 +397,21 @@ _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
|
||||
do
|
||||
{
|
||||
|
||||
mhd_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
mhd_gtls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
MHD_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
MHD_gtls_str_cat (name2, sizeof (name2), ".extnID");
|
||||
|
||||
len = sizeof (extnID) - 1;
|
||||
result = asn1_read_value (cert->cert, name2, extnID, &len);
|
||||
result = MHD__asn1_read_value (cert->cert, name2, extnID, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
break;
|
||||
}
|
||||
else if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Handle Extension
|
||||
@@ -435,8 +435,8 @@ _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
|
||||
}
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
|
||||
@@ -448,7 +448,7 @@ _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
|
||||
* extension.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
|
||||
MHD__gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
|
||||
opaque * extnValue, int extnValueLen)
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
@@ -458,34 +458,34 @@ _gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
|
||||
str[0] = str[1] = 0;
|
||||
*keyUsage = 0;
|
||||
|
||||
if ((result = asn1_create_element
|
||||
(_gnutls_get_pkix (), "PKIX1.KeyUsage", &ext)) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.KeyUsage", &ext)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
|
||||
result = MHD__asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
len = sizeof (str);
|
||||
result = asn1_read_value (ext, "", str, &len);
|
||||
result = MHD__asn1_read_value (ext, "", str, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return 0;
|
||||
}
|
||||
|
||||
*keyUsage = str[0] | (str[1] << 8);
|
||||
|
||||
asn1_delete_structure (&ext);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -493,7 +493,7 @@ _gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
|
||||
/* extract the basicConstraints from the DER encoded extension
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_ext_extract_basicConstraints (int *CA,
|
||||
MHD__gnutls_x509_ext_extract_basicConstraints (int *CA,
|
||||
int *pathLenConstraint,
|
||||
opaque * extnValue,
|
||||
int extnValueLen)
|
||||
@@ -502,45 +502,45 @@ _gnutls_x509_ext_extract_basicConstraints (int *CA,
|
||||
char str[128];
|
||||
int len, result;
|
||||
|
||||
if ((result = asn1_create_element
|
||||
(_gnutls_get_pkix (), "PKIX1.BasicConstraints", &ext)) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.BasicConstraints", &ext)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
|
||||
result = MHD__asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (pathLenConstraint)
|
||||
{
|
||||
result = _gnutls_x509_read_uint (ext, "pathLenConstraint",
|
||||
result = MHD__gnutls_x509_read_uint (ext, "pathLenConstraint",
|
||||
pathLenConstraint);
|
||||
if (result == GNUTLS_E_ASN1_ELEMENT_NOT_FOUND)
|
||||
*pathLenConstraint = -1;
|
||||
else if (result != GNUTLS_E_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
}
|
||||
|
||||
/* the default value of cA is false.
|
||||
*/
|
||||
len = sizeof (str) - 1;
|
||||
result = asn1_read_value (ext, "cA", str, &len);
|
||||
result = MHD__asn1_read_value (ext, "cA", str, &len);
|
||||
if (result == ASN1_SUCCESS && strcmp (str, "TRUE") == 0)
|
||||
*CA = 1;
|
||||
else
|
||||
*CA = 0;
|
||||
|
||||
asn1_delete_structure (&ext);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -551,9 +551,9 @@ _gnutls_x509_ext_extract_basicConstraints (int *CA,
|
||||
* should not be present, >= 0 to indicate set values.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_ext_gen_basicConstraints (int CA,
|
||||
MHD__gnutls_x509_ext_gen_basicConstraints (int CA,
|
||||
int pathLenConstraint,
|
||||
gnutls_datum_t * der_ext)
|
||||
MHD_gnutls_datum_t * der_ext)
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
const char *str;
|
||||
@@ -565,44 +565,44 @@ _gnutls_x509_ext_gen_basicConstraints (int CA,
|
||||
str = "TRUE";
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.BasicConstraints", &ext);
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.BasicConstraints", &ext);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_write_value (ext, "cA", str, 1);
|
||||
result = MHD__asn1_write_value (ext, "cA", str, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (pathLenConstraint < 0)
|
||||
{
|
||||
result = asn1_write_value (ext, "pathLenConstraint", NULL, 0);
|
||||
result = MHD__asn1_write_value (ext, "pathLenConstraint", NULL, 0);
|
||||
if (result < 0)
|
||||
result = mhd_gtls_asn2err (result);
|
||||
result = MHD_gtls_asn2err (result);
|
||||
}
|
||||
else
|
||||
result = _gnutls_x509_write_uint32 (ext, "pathLenConstraint",
|
||||
result = MHD__gnutls_x509_write_uint32 (ext, "pathLenConstraint",
|
||||
pathLenConstraint);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return result;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
|
||||
asn1_delete_structure (&ext);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -613,37 +613,37 @@ _gnutls_x509_ext_gen_basicConstraints (int CA,
|
||||
* Use an ORed SEQUENCE of GNUTLS_KEY_* for usage.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_ext_gen_keyUsage (uint16_t usage, gnutls_datum_t * der_ext)
|
||||
MHD__gnutls_x509_ext_gen_keyUsage (uint16_t usage, MHD_gnutls_datum_t * der_ext)
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
uint8_t str[2];
|
||||
|
||||
result = asn1_create_element (_gnutls_get_pkix (), "PKIX1.KeyUsage", &ext);
|
||||
result = MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.KeyUsage", &ext);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
str[0] = usage & 0xff;
|
||||
str[1] = usage >> 8;
|
||||
|
||||
result = asn1_write_value (ext, "", str, 9);
|
||||
result = MHD__asn1_write_value (ext, "", str, 9);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
|
||||
asn1_delete_structure (&ext);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -652,18 +652,18 @@ _gnutls_x509_ext_gen_keyUsage (uint16_t usage, gnutls_datum_t * der_ext)
|
||||
|
||||
static int
|
||||
write_new_general_name (ASN1_TYPE ext, const char *ext_name,
|
||||
gnutls_x509_subject_alt_name_t type,
|
||||
MHD_gnutls_x509_subject_alt_name_t type,
|
||||
const char *data_string)
|
||||
{
|
||||
const char *str;
|
||||
int result;
|
||||
char name[128];
|
||||
|
||||
result = asn1_write_value (ext, ext_name, "NEW", 1);
|
||||
result = MHD__asn1_write_value (ext, ext_name, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
switch (type)
|
||||
@@ -681,36 +681,36 @@ write_new_general_name (ASN1_TYPE ext, const char *ext_name,
|
||||
str = "iPAddress";
|
||||
break;
|
||||
default:
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
if (ext_name[0] == 0)
|
||||
{ /* no dot */
|
||||
mhd_gtls_str_cpy (name, sizeof (name), "?LAST");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), "?LAST");
|
||||
}
|
||||
else
|
||||
{
|
||||
mhd_gtls_str_cpy (name, sizeof (name), ext_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".?LAST");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), ext_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".?LAST");
|
||||
}
|
||||
|
||||
result = asn1_write_value (ext, name, str, 1);
|
||||
result = MHD__asn1_write_value (ext, name, str, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".");
|
||||
mhd_gtls_str_cat (name, sizeof (name), str);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".");
|
||||
MHD_gtls_str_cat (name, sizeof (name), str);
|
||||
|
||||
result = asn1_write_value (ext, name, data_string, strlen (data_string));
|
||||
result = MHD__asn1_write_value (ext, name, data_string, strlen (data_string));
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
@@ -720,36 +720,36 @@ write_new_general_name (ASN1_TYPE ext, const char *ext_name,
|
||||
* This is the same as subject alternative name.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_ext_gen_subject_alt_name (gnutls_x509_subject_alt_name_t
|
||||
MHD__gnutls_x509_ext_gen_subject_alt_name (MHD_gnutls_x509_subject_alt_name_t
|
||||
type, const char *data_string,
|
||||
gnutls_datum_t * der_ext)
|
||||
MHD_gnutls_datum_t * der_ext)
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.GeneralNames", &ext);
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.GeneralNames", &ext);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = write_new_general_name (ext, "", type, data_string);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return result;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
|
||||
asn1_delete_structure (&ext);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -759,36 +759,36 @@ _gnutls_x509_ext_gen_subject_alt_name (gnutls_x509_subject_alt_name_t
|
||||
/* generate the SubjectKeyID in a DER encoded extension
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
|
||||
gnutls_datum_t * der_ext)
|
||||
MHD__gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
|
||||
MHD_gnutls_datum_t * der_ext)
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.SubjectKeyIdentifier", &ext);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_write_value (ext, "", id, id_size);
|
||||
result = MHD__asn1_write_value (ext, "", id, id_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
|
||||
asn1_delete_structure (&ext);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -798,39 +798,39 @@ _gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
|
||||
/* generate the AuthorityKeyID in a DER encoded extension
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
|
||||
gnutls_datum_t * der_ext)
|
||||
MHD__gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
|
||||
MHD_gnutls_datum_t * der_ext)
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.AuthorityKeyIdentifier", &ext);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_write_value (ext, "keyIdentifier", id, id_size);
|
||||
result = MHD__asn1_write_value (ext, "keyIdentifier", id, id_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
asn1_write_value (ext, "authorityCertIssuer", NULL, 0);
|
||||
asn1_write_value (ext, "authorityCertSerialNumber", NULL, 0);
|
||||
MHD__asn1_write_value (ext, "authorityCertIssuer", NULL, 0);
|
||||
MHD__asn1_write_value (ext, "authorityCertSerialNumber", NULL, 0);
|
||||
|
||||
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
|
||||
asn1_delete_structure (&ext);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -844,13 +844,13 @@ _gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
|
||||
*
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_ext_gen_crl_dist_points (gnutls_x509_subject_alt_name_t
|
||||
MHD__gnutls_x509_ext_gen_crl_dist_points (MHD_gnutls_x509_subject_alt_name_t
|
||||
type, const void *data_string,
|
||||
unsigned int reason_flags,
|
||||
gnutls_datum_t * der_ext)
|
||||
MHD_gnutls_datum_t * der_ext)
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
gnutls_datum_t gnames = { NULL, 0 };
|
||||
MHD_gnutls_datum_t gnames = { NULL, 0 };
|
||||
int result;
|
||||
uint8_t reasons[2];
|
||||
|
||||
@@ -858,65 +858,65 @@ _gnutls_x509_ext_gen_crl_dist_points (gnutls_x509_subject_alt_name_t
|
||||
reasons[1] = reason_flags >> 8;
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.CRLDistributionPoints", &ext);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_write_value (ext, "", "NEW", 1);
|
||||
result = MHD__asn1_write_value (ext, "", "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (reason_flags)
|
||||
{
|
||||
result = asn1_write_value (ext, "?LAST.reasons", reasons, 9);
|
||||
result = MHD__asn1_write_value (ext, "?LAST.reasons", reasons, 9);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
result = asn1_write_value (ext, "?LAST.reasons", NULL, 0);
|
||||
result = MHD__asn1_write_value (ext, "?LAST.reasons", NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
|
||||
result = asn1_write_value (ext, "?LAST.cRLIssuer", NULL, 0);
|
||||
result = MHD__asn1_write_value (ext, "?LAST.cRLIssuer", NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* When used as type CHOICE.
|
||||
*/
|
||||
result = asn1_write_value (ext, "?LAST.distributionPoint", "fullName", 1);
|
||||
result = MHD__asn1_write_value (ext, "?LAST.distributionPoint", "fullName", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
#if 0
|
||||
/* only needed in old code (where defined as SEQUENCE OF) */
|
||||
asn1_write_value (ext,
|
||||
MHD__asn1_write_value (ext,
|
||||
"?LAST.distributionPoint.nameRelativeToCRLIssuer",
|
||||
NULL, 0);
|
||||
#endif
|
||||
@@ -926,23 +926,23 @@ _gnutls_x509_ext_gen_crl_dist_points (gnutls_x509_subject_alt_name_t
|
||||
type, data_string);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = 0;
|
||||
|
||||
cleanup:
|
||||
_gnutls_free_datum (&gnames);
|
||||
asn1_delete_structure (&ext);
|
||||
MHD__gnutls_free_datum (&gnames);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
|
||||
return result;
|
||||
}
|
||||
@@ -950,7 +950,7 @@ cleanup:
|
||||
/* extract the proxyCertInfo from the DER encoded extension
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
|
||||
MHD__gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
|
||||
char **policyLanguage,
|
||||
char **policy,
|
||||
size_t * sizeof_policy,
|
||||
@@ -958,49 +958,49 @@ _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
gnutls_datum_t value;
|
||||
MHD_gnutls_datum_t value;
|
||||
|
||||
if ((result = asn1_create_element
|
||||
(_gnutls_get_pkix (), "PKIX1.ProxyCertInfo", &ext)) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.ProxyCertInfo", &ext)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
|
||||
result = MHD__asn1_der_decoding (&ext, extnValue, extnValueLen, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (pathLenConstraint)
|
||||
{
|
||||
result = _gnutls_x509_read_uint (ext, "pCPathLenConstraint",
|
||||
result = MHD__gnutls_x509_read_uint (ext, "pCPathLenConstraint",
|
||||
pathLenConstraint);
|
||||
if (result == GNUTLS_E_ASN1_ELEMENT_NOT_FOUND)
|
||||
*pathLenConstraint = -1;
|
||||
else if (result != GNUTLS_E_SUCCESS)
|
||||
{
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
}
|
||||
|
||||
result = _gnutls_x509_read_value (ext, "proxyPolicy.policyLanguage",
|
||||
result = MHD__gnutls_x509_read_value (ext, "proxyPolicy.policyLanguage",
|
||||
&value, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return result;
|
||||
}
|
||||
|
||||
if (policyLanguage)
|
||||
*policyLanguage = gnutls_strdup (value.data);
|
||||
*policyLanguage = MHD_gnutls_strdup (value.data);
|
||||
|
||||
result = _gnutls_x509_read_value (ext, "proxyPolicy.policy", &value, 0);
|
||||
result = MHD__gnutls_x509_read_value (ext, "proxyPolicy.policy", &value, 0);
|
||||
if (result == GNUTLS_E_ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
if (policy)
|
||||
@@ -1010,8 +1010,8 @@ _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
|
||||
}
|
||||
else if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return result;
|
||||
}
|
||||
else
|
||||
@@ -1022,7 +1022,7 @@ _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
|
||||
*sizeof_policy = value.size;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&ext);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -1030,64 +1030,64 @@ _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
|
||||
/* generate the proxyCertInfo in a DER encoded extension
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_ext_gen_proxyCertInfo (int pathLenConstraint,
|
||||
MHD__gnutls_x509_ext_gen_proxyCertInfo (int pathLenConstraint,
|
||||
const char *policyLanguage,
|
||||
const char *policy,
|
||||
size_t sizeof_policy,
|
||||
gnutls_datum_t * der_ext)
|
||||
MHD_gnutls_datum_t * der_ext)
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
|
||||
result = asn1_create_element (_gnutls_get_pkix (),
|
||||
result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.ProxyCertInfo", &ext);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (pathLenConstraint < 0)
|
||||
{
|
||||
result = asn1_write_value (ext, "pCPathLenConstraint", NULL, 0);
|
||||
result = MHD__asn1_write_value (ext, "pCPathLenConstraint", NULL, 0);
|
||||
if (result < 0)
|
||||
result = mhd_gtls_asn2err (result);
|
||||
result = MHD_gtls_asn2err (result);
|
||||
}
|
||||
else
|
||||
result = _gnutls_x509_write_uint32 (ext, "pCPathLenConstraint",
|
||||
result = MHD__gnutls_x509_write_uint32 (ext, "pCPathLenConstraint",
|
||||
pathLenConstraint);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return result;
|
||||
}
|
||||
|
||||
result = asn1_write_value (ext, "proxyPolicy.policyLanguage",
|
||||
result = MHD__asn1_write_value (ext, "proxyPolicy.policyLanguage",
|
||||
policyLanguage, 1);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_write_value (ext, "proxyPolicy.policy",
|
||||
result = MHD__asn1_write_value (ext, "proxyPolicy.policy",
|
||||
policy, sizeof_policy);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&ext);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
result = MHD__gnutls_x509_der_encode (ext, "", der_ext, 0);
|
||||
|
||||
asn1_delete_structure (&ext);
|
||||
MHD__asn1_delete_structure (&ext);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
@@ -22,47 +22,47 @@
|
||||
*
|
||||
*/
|
||||
|
||||
int _gnutls_x509_crt_get_extension (gnutls_x509_crt_t cert,
|
||||
int MHD__gnutls_x509_crt_get_extension (MHD_gnutls_x509_crt_t cert,
|
||||
const char *extension_id, int indx,
|
||||
gnutls_datum_t * ret,
|
||||
MHD_gnutls_datum_t * ret,
|
||||
unsigned int *critical);
|
||||
|
||||
int _gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
int MHD__gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx, void *ret,
|
||||
size_t * ret_size);
|
||||
int _gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
|
||||
int MHD__gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
|
||||
opaque * extnValue, int extnValueLen);
|
||||
int _gnutls_x509_ext_extract_basicConstraints (int *CA,
|
||||
int MHD__gnutls_x509_ext_extract_basicConstraints (int *CA,
|
||||
int *pathLenConstraint,
|
||||
opaque * extnValue,
|
||||
int extnValueLen);
|
||||
int _gnutls_x509_crt_set_extension (gnutls_x509_crt_t cert,
|
||||
int MHD__gnutls_x509_crt_set_extension (MHD_gnutls_x509_crt_t cert,
|
||||
const char *extension_id,
|
||||
const gnutls_datum_t * ext_data,
|
||||
const MHD_gnutls_datum_t * ext_data,
|
||||
unsigned int critical);
|
||||
int _gnutls_x509_ext_gen_basicConstraints (int CA, int pathLenConstraint,
|
||||
gnutls_datum_t * der_ext);
|
||||
int _gnutls_x509_ext_gen_keyUsage (uint16_t usage, gnutls_datum_t * der_ext);
|
||||
int _gnutls_x509_ext_gen_subject_alt_name (gnutls_x509_subject_alt_name_t
|
||||
int MHD__gnutls_x509_ext_gen_basicConstraints (int CA, int pathLenConstraint,
|
||||
MHD_gnutls_datum_t * der_ext);
|
||||
int MHD__gnutls_x509_ext_gen_keyUsage (uint16_t usage, MHD_gnutls_datum_t * der_ext);
|
||||
int MHD__gnutls_x509_ext_gen_subject_alt_name (MHD_gnutls_x509_subject_alt_name_t
|
||||
type, const char *data_string,
|
||||
gnutls_datum_t * der_ext);
|
||||
int _gnutls_x509_ext_gen_crl_dist_points (gnutls_x509_subject_alt_name_t
|
||||
MHD_gnutls_datum_t * der_ext);
|
||||
int MHD__gnutls_x509_ext_gen_crl_dist_points (MHD_gnutls_x509_subject_alt_name_t
|
||||
type, const void *data_string,
|
||||
unsigned int reason_flags,
|
||||
gnutls_datum_t * der_ext);
|
||||
int _gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
|
||||
gnutls_datum_t * der_data);
|
||||
int _gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
|
||||
gnutls_datum_t * der_data);
|
||||
MHD_gnutls_datum_t * der_ext);
|
||||
int MHD__gnutls_x509_ext_gen_key_id (const void *id, size_t id_size,
|
||||
MHD_gnutls_datum_t * der_data);
|
||||
int MHD__gnutls_x509_ext_gen_auth_key_id (const void *id, size_t id_size,
|
||||
MHD_gnutls_datum_t * der_data);
|
||||
|
||||
int _gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
|
||||
int MHD__gnutls_x509_ext_extract_proxyCertInfo (int *pathLenConstraint,
|
||||
char **policyLanguage,
|
||||
char **policy,
|
||||
size_t * sizeof_policy,
|
||||
opaque * extnValue,
|
||||
int extnValueLen);
|
||||
int _gnutls_x509_ext_gen_proxyCertInfo (int pathLenConstraint,
|
||||
int MHD__gnutls_x509_ext_gen_proxyCertInfo (int pathLenConstraint,
|
||||
const char *policyLanguage,
|
||||
const char *policy,
|
||||
size_t sizeof_policy,
|
||||
gnutls_datum_t * der_ext);
|
||||
MHD_gnutls_datum_t * der_ext);
|
||||
+137
-137
@@ -38,45 +38,45 @@
|
||||
* Returns 2 parameters (m,e).
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
MHD__gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.RSAPublicKey",
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.RSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&spk, der, dersize, NULL);
|
||||
result = MHD__asn1_der_decoding (&spk, der, dersize, NULL);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&spk);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if ((result = _gnutls_x509_read_int (spk, "modulus", ¶ms[0])) < 0)
|
||||
if ((result = MHD__gnutls_x509_read_int (spk, "modulus", ¶ms[0])) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&spk);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
|
||||
if ((result =
|
||||
_gnutls_x509_read_int (spk, "publicExponent", ¶ms[1])) < 0)
|
||||
MHD__gnutls_x509_read_int (spk, "publicExponent", ¶ms[1])) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
mhd_gtls_mpi_release (¶ms[0]);
|
||||
asn1_delete_structure (&spk);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gtls_mpi_release (¶ms[0]);
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&spk);
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
|
||||
return 0;
|
||||
|
||||
@@ -87,26 +87,26 @@ _gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
* params[0-2]
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
MHD__gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.Dss-Parms",
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.Dss-Parms",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&spk, der, dersize, NULL);
|
||||
result = MHD__asn1_der_decoding (&spk, der, dersize, NULL);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&spk);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* FIXME: If the parameters are not included in the certificate
|
||||
@@ -116,35 +116,35 @@ _gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
|
||||
/* Read p */
|
||||
|
||||
if ((result = _gnutls_x509_read_int (spk, "p", ¶ms[0])) < 0)
|
||||
if ((result = MHD__gnutls_x509_read_int (spk, "p", ¶ms[0])) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&spk);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
|
||||
/* Read q */
|
||||
|
||||
if ((result = _gnutls_x509_read_int (spk, "q", ¶ms[1])) < 0)
|
||||
if ((result = MHD__gnutls_x509_read_int (spk, "q", ¶ms[1])) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&spk);
|
||||
mhd_gtls_mpi_release (¶ms[0]);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
MHD_gtls_mpi_release (¶ms[0]);
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
|
||||
/* Read g */
|
||||
|
||||
if ((result = _gnutls_x509_read_int (spk, "g", ¶ms[2])) < 0)
|
||||
if ((result = MHD__gnutls_x509_read_int (spk, "g", ¶ms[2])) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&spk);
|
||||
mhd_gtls_mpi_release (¶ms[0]);
|
||||
mhd_gtls_mpi_release (¶ms[1]);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
MHD_gtls_mpi_release (¶ms[0]);
|
||||
MHD_gtls_mpi_release (¶ms[1]);
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&spk);
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
|
||||
return 0;
|
||||
|
||||
@@ -154,39 +154,39 @@ _gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
*/
|
||||
|
||||
int
|
||||
_gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out)
|
||||
MHD__gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
|
||||
|
||||
/* == INTEGER */
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.DSAPublicKey",
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&spk, der, dersize, NULL);
|
||||
result = MHD__asn1_der_decoding (&spk, der, dersize, NULL);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&spk);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Read Y */
|
||||
|
||||
if ((result = _gnutls_x509_read_int (spk, "", out)) < 0)
|
||||
if ((result = MHD__gnutls_x509_read_int (spk, "", out)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&spk);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
asn1_delete_structure (&spk);
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
|
||||
return 0;
|
||||
|
||||
@@ -197,35 +197,35 @@ _gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out)
|
||||
* only sets params[3]
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params)
|
||||
MHD__gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params)
|
||||
{
|
||||
return _gnutls_x509_read_der_int (der, dersize, ¶ms[3]);
|
||||
return MHD__gnutls_x509_read_der_int (der, dersize, ¶ms[3]);
|
||||
}
|
||||
|
||||
/* Extracts DSA and RSA parameters from a certificate.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_crt_get_mpis (gnutls_x509_crt_t cert,
|
||||
MHD__gnutls_x509_crt_get_mpis (MHD_gnutls_x509_crt_t cert,
|
||||
mpi_t * params, int *params_size)
|
||||
{
|
||||
int result;
|
||||
int pk_algorithm;
|
||||
gnutls_datum_t tmp = { NULL, 0 };
|
||||
MHD_gnutls_datum_t tmp = { NULL, 0 };
|
||||
|
||||
/* Read the algorithm's OID
|
||||
*/
|
||||
pk_algorithm = gnutls_x509_crt_get_pk_algorithm (cert, NULL);
|
||||
pk_algorithm = MHD_gnutls_x509_crt_get_pk_algorithm (cert, NULL);
|
||||
|
||||
/* Read the algorithm's parameters
|
||||
*/
|
||||
result
|
||||
= _gnutls_x509_read_value (cert->cert,
|
||||
= MHD__gnutls_x509_read_value (cert->cert,
|
||||
"tbsCertificate.subjectPublicKeyInfo.subjectPublicKey",
|
||||
&tmp, 2);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -237,16 +237,16 @@ _gnutls_x509_crt_get_mpis (gnutls_x509_crt_t cert,
|
||||
*/
|
||||
if (*params_size < RSA_PUBLIC_PARAMS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
/* internal error. Increase the mpi_ts in params */
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result =
|
||||
_gnutls_x509_read_rsa_params (tmp.data, tmp.size, params)) < 0)
|
||||
MHD__gnutls_x509_read_rsa_params (tmp.data, tmp.size, params)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
*params_size = RSA_PUBLIC_PARAMS;
|
||||
@@ -256,14 +256,14 @@ _gnutls_x509_crt_get_mpis (gnutls_x509_crt_t cert,
|
||||
/* other types like DH
|
||||
* currently not supported
|
||||
*/
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_X509_CERTIFICATE_ERROR;
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = 0;
|
||||
|
||||
error:_gnutls_free_datum (&tmp);
|
||||
error:MHD__gnutls_free_datum (&tmp);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -275,8 +275,8 @@ error:_gnutls_free_datum (&tmp);
|
||||
* Allocates the space used to store the DER data.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_write_rsa_params (mpi_t * params,
|
||||
int params_size, gnutls_datum_t * der)
|
||||
MHD__gnutls_x509_write_rsa_params (mpi_t * params,
|
||||
int params_size, MHD_gnutls_datum_t * der)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
|
||||
@@ -286,44 +286,44 @@ _gnutls_x509_write_rsa_params (mpi_t * params,
|
||||
|
||||
if (params_size < 2)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_INVALID_REQUEST;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.RSAPublicKey",
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.RSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_write_int (spk, "modulus", params[0], 0);
|
||||
result = MHD__gnutls_x509_write_int (spk, "modulus", params[0], 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_write_int (spk, "publicExponent", params[1], 0);
|
||||
result = MHD__gnutls_x509_write_int (spk, "publicExponent", params[1], 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode (spk, "", der, 0);
|
||||
result = MHD__gnutls_x509_der_encode (spk, "", der, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&spk);
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
return 0;
|
||||
|
||||
cleanup:asn1_delete_structure (&spk);
|
||||
cleanup:MHD__asn1_delete_structure (&spk);
|
||||
|
||||
return result;
|
||||
}
|
||||
@@ -333,7 +333,7 @@ cleanup:asn1_delete_structure (&spk);
|
||||
* This is the "signatureAlgorithm" fields.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_write_sig_params (ASN1_TYPE dst,
|
||||
MHD__gnutls_x509_write_sig_params (ASN1_TYPE dst,
|
||||
const char *dst_name,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm,
|
||||
@@ -344,39 +344,39 @@ _gnutls_x509_write_sig_params (ASN1_TYPE dst,
|
||||
char name[128];
|
||||
const char *pk;
|
||||
|
||||
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".algorithm");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".algorithm");
|
||||
|
||||
pk = mhd_gtls_x509_sign_to_oid (pk_algorithm, HASH2MAC (dig));
|
||||
pk = MHD_gtls_x509_sign_to_oid (pk_algorithm, HASH2MAC (dig));
|
||||
if (pk == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
/* write the OID.
|
||||
*/
|
||||
result = asn1_write_value (dst, name, pk, 1);
|
||||
result = MHD__asn1_write_value (dst, name, pk, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
mhd_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".parameters");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), dst_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".parameters");
|
||||
|
||||
if (pk_algorithm == MHD_GNUTLS_PK_RSA)
|
||||
{ /* RSA */
|
||||
result = asn1_write_value (dst, name, NULL, 0);
|
||||
result = MHD__asn1_write_value (dst, name, NULL, 0);
|
||||
|
||||
if (result != ASN1_SUCCESS && result != ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
/* Here we ignore the element not found error, since this
|
||||
* may have been disabled before.
|
||||
*/
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -390,8 +390,8 @@ _gnutls_x509_write_sig_params (ASN1_TYPE dst,
|
||||
* Allocates the space used to store the DER data.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_write_dsa_params (mpi_t * params,
|
||||
int params_size, gnutls_datum_t * der)
|
||||
MHD__gnutls_x509_write_dsa_params (mpi_t * params,
|
||||
int params_size, MHD_gnutls_datum_t * der)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
|
||||
@@ -401,50 +401,50 @@ _gnutls_x509_write_dsa_params (mpi_t * params,
|
||||
|
||||
if (params_size < 3)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_INVALID_REQUEST;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.DSAParameters",
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAParameters",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_write_int (spk, "p", params[0], 0);
|
||||
result = MHD__gnutls_x509_write_int (spk, "p", params[0], 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_write_int (spk, "q", params[1], 0);
|
||||
result = MHD__gnutls_x509_write_int (spk, "q", params[1], 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_write_int (spk, "g", params[2], 0);
|
||||
result = MHD__gnutls_x509_write_int (spk, "g", params[2], 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode (spk, "", der, 0);
|
||||
result = MHD__gnutls_x509_der_encode (spk, "", der, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = 0;
|
||||
|
||||
cleanup:asn1_delete_structure (&spk);
|
||||
cleanup:MHD__asn1_delete_structure (&spk);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -455,8 +455,8 @@ cleanup:asn1_delete_structure (&spk);
|
||||
* Allocates the space used to store the DER data.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_write_dsa_public_key (mpi_t * params,
|
||||
int params_size, gnutls_datum_t * der)
|
||||
MHD__gnutls_x509_write_dsa_public_key (mpi_t * params,
|
||||
int params_size, MHD_gnutls_datum_t * der)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
|
||||
@@ -466,37 +466,37 @@ _gnutls_x509_write_dsa_public_key (mpi_t * params,
|
||||
|
||||
if (params_size < 3)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_INVALID_REQUEST;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.DSAPublicKey",
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_write_int (spk, "", params[3], 0);
|
||||
result = MHD__gnutls_x509_write_int (spk, "", params[3], 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode (spk, "", der, 0);
|
||||
result = MHD__gnutls_x509_der_encode (spk, "", der, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&spk);
|
||||
MHD__asn1_delete_structure (&spk);
|
||||
return 0;
|
||||
|
||||
cleanup:asn1_delete_structure (&spk);
|
||||
cleanup:MHD__asn1_delete_structure (&spk);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -505,51 +505,51 @@ cleanup:asn1_delete_structure (&spk);
|
||||
* steps.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_read_uint (ASN1_TYPE node, const char *value, unsigned int *ret)
|
||||
MHD__gnutls_x509_read_uint (ASN1_TYPE node, const char *value, unsigned int *ret)
|
||||
{
|
||||
int len, result;
|
||||
opaque *tmpstr;
|
||||
|
||||
len = 0;
|
||||
result = asn1_read_value (node, value, NULL, &len);
|
||||
result = MHD__asn1_read_value (node, value, NULL, &len);
|
||||
if (result != ASN1_MEM_ERROR)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
tmpstr = gnutls_alloca (len);
|
||||
tmpstr = MHD_gnutls_alloca (len);
|
||||
if (tmpstr == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
result = asn1_read_value (node, value, tmpstr, &len);
|
||||
result = MHD__asn1_read_value (node, value, tmpstr, &len);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_afree (tmpstr);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_afree (tmpstr);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (len == 1)
|
||||
*ret = tmpstr[0];
|
||||
else if (len == 2)
|
||||
*ret = mhd_gtls_read_uint16 (tmpstr);
|
||||
*ret = MHD_gtls_read_uint16 (tmpstr);
|
||||
else if (len == 3)
|
||||
*ret = mhd_gtls_read_uint24 (tmpstr);
|
||||
*ret = MHD_gtls_read_uint24 (tmpstr);
|
||||
else if (len == 4)
|
||||
*ret = mhd_gtls_read_uint32 (tmpstr);
|
||||
*ret = MHD_gtls_read_uint32 (tmpstr);
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_afree (tmpstr);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_afree (tmpstr);
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
gnutls_afree (tmpstr);
|
||||
MHD_gnutls_afree (tmpstr);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -557,19 +557,19 @@ _gnutls_x509_read_uint (ASN1_TYPE node, const char *value, unsigned int *ret)
|
||||
/* Writes the specified integer into the specified node.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value, uint32_t num)
|
||||
MHD__gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value, uint32_t num)
|
||||
{
|
||||
opaque tmpstr[4];
|
||||
int result;
|
||||
|
||||
mhd_gtls_write_uint32 (num, tmpstr);
|
||||
MHD_gtls_write_uint32 (num, tmpstr);
|
||||
|
||||
result = asn1_write_value (node, value, tmpstr, 4);
|
||||
result = MHD__asn1_write_value (node, value, tmpstr, 4);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
+16
-16
@@ -25,32 +25,32 @@
|
||||
#include <gnutls_int.h>
|
||||
#include "x509.h"
|
||||
|
||||
int _gnutls_x509_crt_get_mpis (gnutls_x509_crt_t cert,
|
||||
int MHD__gnutls_x509_crt_get_mpis (MHD_gnutls_x509_crt_t cert,
|
||||
mpi_t * params, int *params_size);
|
||||
int _gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params);
|
||||
int _gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params);
|
||||
int _gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params);
|
||||
int MHD__gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params);
|
||||
int MHD__gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params);
|
||||
int MHD__gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params);
|
||||
|
||||
int _gnutls_x509_write_rsa_params (mpi_t * params, int params_size,
|
||||
gnutls_datum_t * der);
|
||||
int _gnutls_x509_write_dsa_params (mpi_t * params, int params_size,
|
||||
gnutls_datum_t * der);
|
||||
int _gnutls_x509_write_dsa_public_key (mpi_t * params, int params_size,
|
||||
gnutls_datum_t * der);
|
||||
int MHD__gnutls_x509_write_rsa_params (mpi_t * params, int params_size,
|
||||
MHD_gnutls_datum_t * der);
|
||||
int MHD__gnutls_x509_write_dsa_params (mpi_t * params, int params_size,
|
||||
MHD_gnutls_datum_t * der);
|
||||
int MHD__gnutls_x509_write_dsa_public_key (mpi_t * params, int params_size,
|
||||
MHD_gnutls_datum_t * der);
|
||||
|
||||
int _gnutls_x509_read_uint (ASN1_TYPE node, const char *value,
|
||||
int MHD__gnutls_x509_read_uint (ASN1_TYPE node, const char *value,
|
||||
unsigned int *ret);
|
||||
|
||||
int _gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out);
|
||||
int MHD__gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out);
|
||||
|
||||
int _gnutls_x509_read_int (ASN1_TYPE node, const char *value,
|
||||
int MHD__gnutls_x509_read_int (ASN1_TYPE node, const char *value,
|
||||
mpi_t * ret_mpi);
|
||||
int _gnutls_x509_write_int (ASN1_TYPE node, const char *value, mpi_t mpi,
|
||||
int MHD__gnutls_x509_write_int (ASN1_TYPE node, const char *value, mpi_t mpi,
|
||||
int lz);
|
||||
int _gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value,
|
||||
int MHD__gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value,
|
||||
uint32_t num);
|
||||
|
||||
int _gnutls_x509_write_sig_params (ASN1_TYPE dst, const char *dst_name,
|
||||
int MHD__gnutls_x509_write_sig_params (ASN1_TYPE dst, const char *dst_name,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
|
||||
+251
-251
@@ -46,26 +46,26 @@
|
||||
* which holds them. Returns an ASN1_TYPE of authenticatedSafe.
|
||||
*/
|
||||
static int
|
||||
_decode_pkcs12_auth_safe (ASN1_TYPE pkcs12, ASN1_TYPE * authen_safe,
|
||||
gnutls_datum_t * raw)
|
||||
_decodeMHD_pkcs12_auth_safe (ASN1_TYPE pkcs12, ASN1_TYPE * authen_safe,
|
||||
MHD_gnutls_datum_t * raw)
|
||||
{
|
||||
char oid[128];
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
gnutls_datum_t auth_safe = { NULL, 0 };
|
||||
MHD_gnutls_datum_t auth_safe = { NULL, 0 };
|
||||
int tmp_size, len, result;
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (pkcs12, "authSafe.contentType", oid, &len);
|
||||
result = MHD__asn1_read_value (pkcs12, "authSafe.contentType", oid, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (strcmp (oid, DATA_OID) != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log ("Unknown PKCS12 Content OID '%s'\n", oid);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_x509_log ("Unknown PKCS12 Content OID '%s'\n", oid);
|
||||
return GNUTLS_E_UNKNOWN_PKCS_CONTENT_TYPE;
|
||||
}
|
||||
|
||||
@@ -74,36 +74,36 @@ _decode_pkcs12_auth_safe (ASN1_TYPE pkcs12, ASN1_TYPE * authen_safe,
|
||||
|
||||
tmp_size = 0;
|
||||
result =
|
||||
_gnutls_x509_read_value (pkcs12, "authSafe.content", &auth_safe, 1);
|
||||
MHD__gnutls_x509_read_value (pkcs12, "authSafe.content", &auth_safe, 1);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Step 2. Extract the authenticatedSafe.
|
||||
*/
|
||||
|
||||
if ((result = asn1_create_element
|
||||
(_gnutls_get_pkix (), "PKIX1.pkcs-12-AuthenticatedSafe",
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-12-AuthenticatedSafe",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&c2, auth_safe.data, auth_safe.size, NULL);
|
||||
result = MHD__asn1_der_decoding (&c2, auth_safe.data, auth_safe.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (raw == NULL)
|
||||
{
|
||||
_gnutls_free_datum (&auth_safe);
|
||||
MHD__gnutls_free_datum (&auth_safe);
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -114,19 +114,19 @@ _decode_pkcs12_auth_safe (ASN1_TYPE pkcs12, ASN1_TYPE * authen_safe,
|
||||
if (authen_safe)
|
||||
*authen_safe = c2;
|
||||
else
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
_gnutls_free_datum (&auth_safe);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
MHD__gnutls_free_datum (&auth_safe);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_init - This function initializes a gnutls_pkcs12_t structure
|
||||
* MHD_gnutlsMHD_pkcs12_init - This function initializes a MHD_gnutlsMHD_pkcs12_t structure
|
||||
* @pkcs12: The structure to be initialized
|
||||
*
|
||||
* This function will initialize a PKCS12 structure. PKCS12 structures
|
||||
@@ -137,20 +137,20 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12)
|
||||
MHD_gnutlsMHD_pkcs12_init (MHD_gnutlsMHD_pkcs12_t * pkcs12)
|
||||
{
|
||||
*pkcs12 = gnutls_calloc (1, sizeof (gnutls_pkcs12_int));
|
||||
*pkcs12 = MHD_gnutls_calloc (1, sizeof (MHD_gnutlsMHD_pkcs12_int));
|
||||
|
||||
if (*pkcs12)
|
||||
{
|
||||
int result = asn1_create_element (_gnutls_get_pkix (),
|
||||
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-12-PFX",
|
||||
&(*pkcs12)->pkcs12);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_free (*pkcs12);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_free (*pkcs12);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
return 0; /* success */
|
||||
}
|
||||
@@ -158,33 +158,33 @@ gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_deinit - This function deinitializes memory used by a gnutls_pkcs12_t structure
|
||||
* MHD_gnutlsMHD_pkcs12_deinit - This function deinitializes memory used by a MHD_gnutlsMHD_pkcs12_t structure
|
||||
* @pkcs12: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a PKCS12 structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
gnutls_pkcs12_deinit (gnutls_pkcs12_t pkcs12)
|
||||
MHD_gnutlsMHD_pkcs12_deinit (MHD_gnutlsMHD_pkcs12_t pkcs12)
|
||||
{
|
||||
if (!pkcs12)
|
||||
return;
|
||||
|
||||
if (pkcs12->pkcs12)
|
||||
asn1_delete_structure (&pkcs12->pkcs12);
|
||||
MHD__asn1_delete_structure (&pkcs12->pkcs12);
|
||||
|
||||
gnutls_free (pkcs12);
|
||||
MHD_gnutls_free (pkcs12);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_import - This function will import a DER or PEM encoded PKCS12 structure
|
||||
* MHD_gnutlsMHD_pkcs12_import - This function will import a DER or PEM encoded PKCS12 structure
|
||||
* @pkcs12: The structure to store the parsed PKCS12.
|
||||
* @data: The DER or PEM encoded PKCS12.
|
||||
* @format: One of DER or PEM
|
||||
* @flags: an ORed sequence of gnutls_privkey_pkcs8_flags
|
||||
* @flags: an ORed sequence of MHD_gnutls_privkey_pkcs8_flags
|
||||
*
|
||||
* This function will convert the given DER or PEM encoded PKCS12
|
||||
* to the native gnutls_pkcs12_t format. The output will be stored in 'pkcs12'.
|
||||
* to the native MHD_gnutlsMHD_pkcs12_t format. The output will be stored in 'pkcs12'.
|
||||
*
|
||||
* If the PKCS12 is PEM encoded it should have a header of "PKCS12".
|
||||
*
|
||||
@@ -192,19 +192,19 @@ gnutls_pkcs12_deinit (gnutls_pkcs12_t pkcs12)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format, unsigned int flags)
|
||||
MHD_gnutlsMHD_pkcs12_import (MHD_gnutlsMHD_pkcs12_t pkcs12,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format, unsigned int flags)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
gnutls_datum_t _data;
|
||||
MHD_gnutls_datum_t _data;
|
||||
|
||||
_data.data = data->data;
|
||||
_data.size = data->size;
|
||||
|
||||
if (pkcs12 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -214,14 +214,14 @@ gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
|
||||
{
|
||||
opaque *out;
|
||||
|
||||
result = _gnutls_fbase64_decode (PEM_PKCS12, data->data, data->size,
|
||||
result = MHD__gnutls_fbase64_decode (PEM_PKCS12, data->data, data->size,
|
||||
&out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
if (result == 0)
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -231,28 +231,28 @@ gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
|
||||
need_free = 1;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&pkcs12->pkcs12, _data.data, _data.size, NULL);
|
||||
result = MHD__asn1_der_decoding (&pkcs12->pkcs12, _data.data, _data.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
result = mhd_gtls_asn2err (result);
|
||||
gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_export - This function will export the pkcs12 structure
|
||||
* MHD_gnutlsMHD_pkcs12_export - This function will export the pkcs12 structure
|
||||
* @pkcs12: Holds the pkcs12 structure
|
||||
* @format: the format of output params. One of PEM or DER.
|
||||
* @output_data: will contain a structure PEM or DER encoded
|
||||
@@ -273,17 +273,17 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_export (gnutls_pkcs12_t pkcs12,
|
||||
gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
MHD_gnutlsMHD_pkcs12_export (MHD_gnutlsMHD_pkcs12_t pkcs12,
|
||||
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
size_t * output_data_size)
|
||||
{
|
||||
if (pkcs12 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_export_int (pkcs12->pkcs12, format, PEM_PKCS12,
|
||||
return MHD__gnutls_x509_export_int (pkcs12->pkcs12, format, PEM_PKCS12,
|
||||
output_data, output_data_size);
|
||||
}
|
||||
|
||||
@@ -341,44 +341,44 @@ ucs2_to_ascii (char *data, int size)
|
||||
* the given bag.
|
||||
*/
|
||||
int
|
||||
_pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
gnutls_pkcs12_bag_t bag)
|
||||
MHD_pkcs12_decode_safe_contents (const MHD_gnutls_datum_t * content,
|
||||
MHD_gnutlsMHD_pkcs12_bag_t bag)
|
||||
{
|
||||
char oid[128], root[MAX_NAME_SIZE];
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int len, result;
|
||||
int bag_type;
|
||||
gnutls_datum_t attr_val;
|
||||
MHD_gnutls_datum_t attr_val;
|
||||
int count = 0, i, attributes, j;
|
||||
size_t size;
|
||||
|
||||
/* Step 1. Extract the SEQUENCE.
|
||||
*/
|
||||
|
||||
if ((result = asn1_create_element
|
||||
(_gnutls_get_pkix (), "PKIX1.pkcs-12-SafeContents",
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-12-SafeContents",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&c2, content->data, content->size, NULL);
|
||||
result = MHD__asn1_der_decoding (&c2, content->data, content->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Count the number of bags
|
||||
*/
|
||||
result = asn1_number_of_elements (c2, "", &count);
|
||||
result = MHD__asn1_number_of_elements (c2, "", &count);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -390,11 +390,11 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
snprintf (root, sizeof (root), "?%u.bagId", i + 1);
|
||||
|
||||
len = sizeof (oid);
|
||||
result = asn1_read_value (c2, root, oid, &len);
|
||||
result = MHD__asn1_read_value (c2, root, oid, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -404,7 +404,7 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
|
||||
if (bag_type < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -413,37 +413,37 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
|
||||
snprintf (root, sizeof (root), "?%u.bagValue", i + 1);
|
||||
|
||||
result = _gnutls_x509_read_value (c2, root, &bag->element[i].data, 0);
|
||||
result = MHD__gnutls_x509_read_value (c2, root, &bag->element[i].data, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (bag_type == GNUTLS_BAG_CERTIFICATE || bag_type == GNUTLS_BAG_CRL)
|
||||
{
|
||||
gnutls_datum_t tmp = bag->element[i].data;
|
||||
MHD_gnutls_datum_t tmp = bag->element[i].data;
|
||||
|
||||
result =
|
||||
_pkcs12_decode_crt_bag (bag_type, &tmp, &bag->element[i].data);
|
||||
MHD_pkcs12_decode_crt_bag (bag_type, &tmp, &bag->element[i].data);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
_gnutls_free_datum (&tmp);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
}
|
||||
|
||||
/* read the bag attributes
|
||||
*/
|
||||
snprintf (root, sizeof (root), "?%u.bagAttributes", i + 1);
|
||||
|
||||
result = asn1_number_of_elements (c2, root, &attributes);
|
||||
result = MHD__asn1_number_of_elements (c2, root, &attributes);
|
||||
if (result != ASN1_SUCCESS && result != ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -458,13 +458,13 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
j + 1);
|
||||
|
||||
result =
|
||||
_gnutls_x509_decode_and_read_attribute (c2, root, oid,
|
||||
MHD__gnutls_x509_decode_and_read_attribute (c2, root, oid,
|
||||
sizeof (oid), &attr_val,
|
||||
1, 0);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
continue; /* continue in case we find some known attributes */
|
||||
}
|
||||
|
||||
@@ -473,14 +473,14 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
size = attr_val.size;
|
||||
|
||||
result =
|
||||
_gnutls_x509_decode_octet_string (NULL, attr_val.data, size,
|
||||
MHD__gnutls_x509_decode_octet_string (NULL, attr_val.data, size,
|
||||
attr_val.data, &size);
|
||||
attr_val.size = size;
|
||||
if (result < 0)
|
||||
{
|
||||
_gnutls_free_datum (&attr_val);
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log
|
||||
MHD__gnutls_free_datum (&attr_val);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_x509_log
|
||||
("Error decoding PKCS12 Bag Attribute OID '%s'\n", oid);
|
||||
continue;
|
||||
}
|
||||
@@ -490,15 +490,15 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
{
|
||||
size = attr_val.size;
|
||||
result =
|
||||
_gnutls_x509_decode_octet_string ("BMPString",
|
||||
MHD__gnutls_x509_decode_octet_string ("BMPString",
|
||||
attr_val.data, size,
|
||||
attr_val.data, &size);
|
||||
attr_val.size = size;
|
||||
if (result < 0)
|
||||
{
|
||||
_gnutls_free_datum (&attr_val);
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log
|
||||
MHD__gnutls_free_datum (&attr_val);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_x509_log
|
||||
("Error decoding PKCS12 Bag Attribute OID '%s'\n", oid);
|
||||
continue;
|
||||
}
|
||||
@@ -507,8 +507,8 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
}
|
||||
else
|
||||
{
|
||||
_gnutls_free_datum (&attr_val);
|
||||
_gnutls_x509_log
|
||||
MHD__gnutls_free_datum (&attr_val);
|
||||
MHD__gnutls_x509_log
|
||||
("Unknown PKCS12 Bag Attribute OID '%s'\n", oid);
|
||||
}
|
||||
}
|
||||
@@ -518,14 +518,14 @@ _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
|
||||
}
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
|
||||
}
|
||||
@@ -533,41 +533,41 @@ cleanup:
|
||||
|
||||
static int
|
||||
_parse_safe_contents (ASN1_TYPE sc, const char *sc_name,
|
||||
gnutls_pkcs12_bag_t bag)
|
||||
MHD_gnutlsMHD_pkcs12_bag_t bag)
|
||||
{
|
||||
gnutls_datum_t content = { NULL, 0 };
|
||||
MHD_gnutls_datum_t content = { NULL, 0 };
|
||||
int result;
|
||||
|
||||
/* Step 1. Extract the content.
|
||||
*/
|
||||
|
||||
result = _gnutls_x509_read_value (sc, sc_name, &content, 1);
|
||||
result = MHD__gnutls_x509_read_value (sc, sc_name, &content, 1);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _pkcs12_decode_safe_contents (&content, bag);
|
||||
result = MHD_pkcs12_decode_safe_contents (&content, bag);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
_gnutls_free_datum (&content);
|
||||
MHD__gnutls_free_datum (&content);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
_gnutls_free_datum (&content);
|
||||
MHD__gnutls_free_datum (&content);
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_get_bag - This function returns a Bag from a PKCS12 structure
|
||||
* @pkcs12: should contain a gnutls_pkcs12_t structure
|
||||
* MHD_gnutlsMHD_pkcs12_get_bag - This function returns a Bag from a PKCS12 structure
|
||||
* @pkcs12: should contain a MHD_gnutlsMHD_pkcs12_t structure
|
||||
* @indx: contains the index of the bag to extract
|
||||
* @bag: An initialized bag, where the contents of the bag will be copied
|
||||
*
|
||||
@@ -579,8 +579,8 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
|
||||
int indx, gnutls_pkcs12_bag_t bag)
|
||||
MHD_gnutlsMHD_pkcs12_get_bag (MHD_gnutlsMHD_pkcs12_t pkcs12,
|
||||
int indx, MHD_gnutlsMHD_pkcs12_bag_t bag)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result, len;
|
||||
@@ -589,16 +589,16 @@ gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
|
||||
|
||||
if (pkcs12 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
/* Step 1. decode the data.
|
||||
*/
|
||||
result = _decode_pkcs12_auth_safe (pkcs12->pkcs12, &c2, NULL);
|
||||
result = _decodeMHD_pkcs12_auth_safe (pkcs12->pkcs12, &c2, NULL);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -608,7 +608,7 @@ gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
|
||||
snprintf (root2, sizeof (root2), "?%u.contentType", indx + 1);
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (c2, root2, oid, &len);
|
||||
result = MHD__asn1_read_value (c2, root2, oid, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -618,8 +618,8 @@ gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -639,10 +639,10 @@ gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
|
||||
bag->element[0].type = GNUTLS_BAG_ENCRYPTED;
|
||||
bag->bag_elements = 1;
|
||||
|
||||
result = _gnutls_x509_read_value (c2, root2, &bag->element[0].data, 0);
|
||||
result = MHD__gnutls_x509_read_value (c2, root2, &bag->element[0].data, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -650,7 +650,7 @@ gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
|
||||
|
||||
cleanup:
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -665,21 +665,21 @@ create_empty_pfx (ASN1_TYPE pkcs12)
|
||||
|
||||
/* Use version 3
|
||||
*/
|
||||
result = asn1_write_value (pkcs12, "version", &three, 1);
|
||||
result = MHD__asn1_write_value (pkcs12, "version", &three, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Write the content type of the data
|
||||
*/
|
||||
result = asn1_write_value (pkcs12, "authSafe.contentType", DATA_OID, 1);
|
||||
result = MHD__asn1_write_value (pkcs12, "authSafe.contentType", DATA_OID, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -687,35 +687,35 @@ create_empty_pfx (ASN1_TYPE pkcs12)
|
||||
* null one in that case.
|
||||
*/
|
||||
|
||||
if ((result = asn1_create_element
|
||||
(_gnutls_get_pkix (), "PKIX1.pkcs-12-AuthenticatedSafe",
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-12-AuthenticatedSafe",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result =
|
||||
_gnutls_x509_der_encode_and_copy (c2, "", pkcs12, "authSafe.content", 1);
|
||||
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs12, "authSafe.content", 1);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_set_bag - This function inserts a Bag into a PKCS12 structure
|
||||
* @pkcs12: should contain a gnutls_pkcs12_t structure
|
||||
* MHD_gnutlsMHD_pkcs12_set_bag - This function inserts a Bag into a PKCS12 structure
|
||||
* @pkcs12: should contain a MHD_gnutlsMHD_pkcs12_t structure
|
||||
* @bag: An initialized bag
|
||||
*
|
||||
* This function will insert a Bag into the PKCS12 structure.
|
||||
@@ -723,7 +723,7 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_set_bag (gnutls_pkcs12_t pkcs12, gnutls_pkcs12_bag_t bag)
|
||||
MHD_gnutlsMHD_pkcs12_set_bag (MHD_gnutlsMHD_pkcs12_t pkcs12, MHD_gnutlsMHD_pkcs12_bag_t bag)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
ASN1_TYPE safe_cont = ASN1_TYPE_EMPTY;
|
||||
@@ -733,62 +733,62 @@ gnutls_pkcs12_set_bag (gnutls_pkcs12_t pkcs12, gnutls_pkcs12_bag_t bag)
|
||||
|
||||
if (pkcs12 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
/* Step 1. Check if the pkcs12 structure is empty. In that
|
||||
* case generate an empty PFX.
|
||||
*/
|
||||
result = asn1_read_value (pkcs12->pkcs12, "authSafe.content", &null, &dum);
|
||||
result = MHD__asn1_read_value (pkcs12->pkcs12, "authSafe.content", &null, &dum);
|
||||
if (result == ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
result = create_empty_pfx (pkcs12->pkcs12);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
}
|
||||
|
||||
/* Step 2. decode the authenticatedSafe.
|
||||
*/
|
||||
result = _decode_pkcs12_auth_safe (pkcs12->pkcs12, &c2, NULL);
|
||||
result = _decodeMHD_pkcs12_auth_safe (pkcs12->pkcs12, &c2, NULL);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Step 3. Encode the bag elements into a SafeContents
|
||||
* structure.
|
||||
*/
|
||||
result = _pkcs12_encode_safe_contents (bag, &safe_cont, &enc);
|
||||
result = MHD_pkcs12_encode_safe_contents (bag, &safe_cont, &enc);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Step 4. Insert the encoded SafeContents into the AuthenticatedSafe
|
||||
* structure.
|
||||
*/
|
||||
result = asn1_write_value (c2, "", "NEW", 1);
|
||||
result = MHD__asn1_write_value (c2, "", "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (enc)
|
||||
result = asn1_write_value (c2, "?LAST.contentType", ENC_DATA_OID, 1);
|
||||
result = MHD__asn1_write_value (c2, "?LAST.contentType", ENC_DATA_OID, 1);
|
||||
else
|
||||
result = asn1_write_value (c2, "?LAST.contentType", DATA_OID, 1);
|
||||
result = MHD__asn1_write_value (c2, "?LAST.contentType", DATA_OID, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -797,56 +797,56 @@ gnutls_pkcs12_set_bag (gnutls_pkcs12_t pkcs12, gnutls_pkcs12_bag_t bag)
|
||||
/* Encrypted packets are written directly.
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (c2, "?LAST.content",
|
||||
MHD__asn1_write_value (c2, "?LAST.content",
|
||||
bag->element[0].data.data,
|
||||
bag->element[0].data.size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
else
|
||||
{
|
||||
result =
|
||||
_gnutls_x509_der_encode_and_copy (safe_cont, "", c2,
|
||||
MHD__gnutls_x509_der_encode_and_copy (safe_cont, "", c2,
|
||||
"?LAST.content", 1);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
|
||||
asn1_delete_structure (&safe_cont);
|
||||
MHD__asn1_delete_structure (&safe_cont);
|
||||
|
||||
|
||||
/* Step 5. Reencode and copy the AuthenticatedSafe into the pkcs12
|
||||
* structure.
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_der_encode_and_copy (c2, "", pkcs12->pkcs12,
|
||||
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs12->pkcs12,
|
||||
"authSafe.content", 1);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
asn1_delete_structure (&c2);
|
||||
asn1_delete_structure (&safe_cont);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&safe_cont);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_generate_mac - This function generates the MAC of the PKCS12 structure
|
||||
* @pkcs12: should contain a gnutls_pkcs12_t structure
|
||||
* MHD_gnutlsMHD_pkcs12_generate_mac - This function generates the MAC of the PKCS12 structure
|
||||
* @pkcs12: should contain a MHD_gnutlsMHD_pkcs12_t structure
|
||||
* @pass: The password for the MAC
|
||||
*
|
||||
* This function will generate a MAC for the PKCS12 structure.
|
||||
@@ -854,115 +854,115 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_generate_mac (gnutls_pkcs12_t pkcs12, const char *pass)
|
||||
MHD_gnutlsMHD_pkcs12_generate_mac (MHD_gnutlsMHD_pkcs12_t pkcs12, const char *pass)
|
||||
{
|
||||
opaque salt[8], key[20];
|
||||
int result;
|
||||
mac_hd_t td1 = NULL;
|
||||
gnutls_datum_t tmp = { NULL, 0 };
|
||||
MHD_gnutls_datum_t tmp = { NULL, 0 };
|
||||
opaque sha_mac[20];
|
||||
|
||||
if (pkcs12 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
/* Generate the salt.
|
||||
*/
|
||||
if (gc_nonce (salt, sizeof (salt)) != GC_OK)
|
||||
if (MHD_gc_nonce (salt, sizeof (salt)) != GC_OK)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_RANDOM_FAILED;
|
||||
}
|
||||
|
||||
/* Write the salt into the structure.
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (pkcs12->pkcs12, "macData.macSalt", salt, sizeof (salt));
|
||||
MHD__asn1_write_value (pkcs12->pkcs12, "macData.macSalt", salt, sizeof (salt));
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Generate the key.
|
||||
*/
|
||||
result = _pkcs12_string_to_key (3 /*MAC*/, salt, sizeof (salt),
|
||||
result = MHD_pkcs12_string_to_key (3 /*MAC*/, salt, sizeof (salt),
|
||||
1, pass, sizeof (key), key);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Get the data to be MACed
|
||||
*/
|
||||
result = _decode_pkcs12_auth_safe (pkcs12->pkcs12, NULL, &tmp);
|
||||
result = _decodeMHD_pkcs12_auth_safe (pkcs12->pkcs12, NULL, &tmp);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* MAC the data
|
||||
*/
|
||||
td1 = mhd_gtls_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
|
||||
td1 = MHD_gtls_MHD_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
|
||||
if (td1 == GNUTLS_MAC_FAILED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
mhd_gnutls_hash (td1, tmp.data, tmp.size);
|
||||
_gnutls_free_datum (&tmp);
|
||||
MHD_gnutls_hash (td1, tmp.data, tmp.size);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
|
||||
mhd_gnutls_hmac_deinit (td1, sha_mac);
|
||||
MHD_gnutls_MHD_hmac_deinit (td1, sha_mac);
|
||||
|
||||
|
||||
result =
|
||||
asn1_write_value (pkcs12->pkcs12, "macData.mac.digest", sha_mac,
|
||||
MHD__asn1_write_value (pkcs12->pkcs12, "macData.mac.digest", sha_mac,
|
||||
sizeof (sha_mac));
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_write_value (pkcs12->pkcs12,
|
||||
MHD__asn1_write_value (pkcs12->pkcs12,
|
||||
"macData.mac.digestAlgorithm.parameters", NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_write_value (pkcs12->pkcs12,
|
||||
MHD__asn1_write_value (pkcs12->pkcs12,
|
||||
"macData.mac.digestAlgorithm.algorithm", HASH_OID_SHA1,
|
||||
1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
_gnutls_free_datum (&tmp);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_verify_mac - This function verifies the MAC of the PKCS12 structure
|
||||
* @pkcs12: should contain a gnutls_pkcs12_t structure
|
||||
* MHD_gnutlsMHD_pkcs12_verify_mac - This function verifies the MAC of the PKCS12 structure
|
||||
* @pkcs12: should contain a MHD_gnutlsMHD_pkcs12_t structure
|
||||
* @pass: The password for the MAC
|
||||
*
|
||||
* This function will verify the MAC for the PKCS12 structure.
|
||||
@@ -970,14 +970,14 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass)
|
||||
MHD_gnutlsMHD_pkcs12_verify_mac (MHD_gnutlsMHD_pkcs12_t pkcs12, const char *pass)
|
||||
{
|
||||
opaque key[20];
|
||||
int result;
|
||||
unsigned int iter;
|
||||
int len;
|
||||
mac_hd_t td1 = NULL;
|
||||
gnutls_datum_t tmp = { NULL, 0 }, salt =
|
||||
MHD_gnutls_datum_t tmp = { NULL, 0 }, salt =
|
||||
{
|
||||
NULL, 0};
|
||||
opaque sha_mac[20];
|
||||
@@ -985,7 +985,7 @@ gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass)
|
||||
|
||||
if (pkcs12 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -993,7 +993,7 @@ gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass)
|
||||
*/
|
||||
|
||||
result =
|
||||
_gnutls_x509_read_uint (pkcs12->pkcs12, "macData.iterations", &iter);
|
||||
MHD__gnutls_x509_read_uint (pkcs12->pkcs12, "macData.iterations", &iter);
|
||||
if (result < 0)
|
||||
{
|
||||
iter = 1; /* the default */
|
||||
@@ -1003,78 +1003,78 @@ gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass)
|
||||
/* Read the salt from the structure.
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_read_value (pkcs12->pkcs12, "macData.macSalt", &salt, 0);
|
||||
MHD__gnutls_x509_read_value (pkcs12->pkcs12, "macData.macSalt", &salt, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Generate the key.
|
||||
*/
|
||||
result = _pkcs12_string_to_key (3 /*MAC*/, salt.data, salt.size,
|
||||
result = MHD_pkcs12_string_to_key (3 /*MAC*/, salt.data, salt.size,
|
||||
iter, pass, sizeof (key), key);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
_gnutls_free_datum (&salt);
|
||||
MHD__gnutls_free_datum (&salt);
|
||||
|
||||
/* Get the data to be MACed
|
||||
*/
|
||||
result = _decode_pkcs12_auth_safe (pkcs12->pkcs12, NULL, &tmp);
|
||||
result = _decodeMHD_pkcs12_auth_safe (pkcs12->pkcs12, NULL, &tmp);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* MAC the data
|
||||
*/
|
||||
td1 = mhd_gtls_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
|
||||
td1 = MHD_gtls_MHD_hmac_init (MHD_GNUTLS_MAC_SHA1, key, sizeof (key));
|
||||
if (td1 == GNUTLS_MAC_FAILED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
mhd_gnutls_hash (td1, tmp.data, tmp.size);
|
||||
_gnutls_free_datum (&tmp);
|
||||
MHD_gnutls_hash (td1, tmp.data, tmp.size);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
|
||||
mhd_gnutls_hmac_deinit (td1, sha_mac);
|
||||
MHD_gnutls_MHD_hmac_deinit (td1, sha_mac);
|
||||
|
||||
len = sizeof (sha_mac_orig);
|
||||
result =
|
||||
asn1_read_value (pkcs12->pkcs12, "macData.mac.digest", sha_mac_orig,
|
||||
MHD__asn1_read_value (pkcs12->pkcs12, "macData.mac.digest", sha_mac_orig,
|
||||
&len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (memcmp (sha_mac_orig, sha_mac, sizeof (sha_mac)) != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MAC_VERIFY_FAILED;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
_gnutls_free_datum (&tmp);
|
||||
_gnutls_free_datum (&salt);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
MHD__gnutls_free_datum (&salt);
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
static int
|
||||
write_attributes (gnutls_pkcs12_bag_t bag, int elem,
|
||||
write_attributes (MHD_gnutlsMHD_pkcs12_bag_t bag, int elem,
|
||||
ASN1_TYPE c2, const char *where)
|
||||
{
|
||||
int result;
|
||||
@@ -1088,11 +1088,11 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
|
||||
{
|
||||
/* no attributes
|
||||
*/
|
||||
result = asn1_write_value (c2, where, NULL, 0);
|
||||
result = MHD__asn1_write_value (c2, where, NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
@@ -1103,25 +1103,25 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
|
||||
|
||||
/* Add a new Attribute
|
||||
*/
|
||||
result = asn1_write_value (c2, where, "NEW", 1);
|
||||
result = MHD__asn1_write_value (c2, where, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
mhd_gtls_str_cpy (root, sizeof (root), where);
|
||||
mhd_gtls_str_cat (root, sizeof (root), ".?LAST");
|
||||
MHD_gtls_str_cpy (root, sizeof (root), where);
|
||||
MHD_gtls_str_cat (root, sizeof (root), ".?LAST");
|
||||
|
||||
result =
|
||||
_gnutls_x509_encode_and_write_attribute (KEY_ID_OID, c2, root,
|
||||
MHD__gnutls_x509_encode_and_write_attribute (KEY_ID_OID, c2, root,
|
||||
bag->element[elem].
|
||||
local_key_id.data,
|
||||
bag->element[elem].
|
||||
local_key_id.size, 1);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
}
|
||||
@@ -1134,21 +1134,21 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
|
||||
|
||||
/* Add a new Attribute
|
||||
*/
|
||||
result = asn1_write_value (c2, where, "NEW", 1);
|
||||
result = MHD__asn1_write_value (c2, where, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* convert name to BMPString
|
||||
*/
|
||||
size = strlen (bag->element[elem].friendly_name) * 2;
|
||||
name = gnutls_malloc (size);
|
||||
name = MHD_gnutls_malloc (size);
|
||||
|
||||
if (name == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
@@ -1160,18 +1160,18 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
|
||||
p++;
|
||||
}
|
||||
|
||||
mhd_gtls_str_cpy (root, sizeof (root), where);
|
||||
mhd_gtls_str_cat (root, sizeof (root), ".?LAST");
|
||||
MHD_gtls_str_cpy (root, sizeof (root), where);
|
||||
MHD_gtls_str_cat (root, sizeof (root), ".?LAST");
|
||||
|
||||
result =
|
||||
_gnutls_x509_encode_and_write_attribute (FRIENDLY_NAME_OID, c2,
|
||||
MHD__gnutls_x509_encode_and_write_attribute (FRIENDLY_NAME_OID, c2,
|
||||
root, name, size, 1);
|
||||
|
||||
gnutls_free (name);
|
||||
MHD_gnutls_free (name);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
}
|
||||
@@ -1184,7 +1184,7 @@ write_attributes (gnutls_pkcs12_bag_t bag, int elem,
|
||||
* the given datum. Enc is set to non zero if the data are encrypted;
|
||||
*/
|
||||
int
|
||||
_pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
|
||||
MHD_pkcs12_encode_safe_contents (MHD_gnutlsMHD_pkcs12_bag_t bag, ASN1_TYPE * contents,
|
||||
int *enc)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
@@ -1203,12 +1203,12 @@ _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
|
||||
/* Step 1. Create the SEQUENCE.
|
||||
*/
|
||||
|
||||
if ((result = asn1_create_element
|
||||
(_gnutls_get_pkix (), "PKIX1.pkcs-12-SafeContents",
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-12-SafeContents",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -1218,25 +1218,25 @@ _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
|
||||
oid = bag_to_oid (bag->element[i].type);
|
||||
if (oid == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
continue;
|
||||
}
|
||||
|
||||
result = asn1_write_value (c2, "", "NEW", 1);
|
||||
result = MHD__asn1_write_value (c2, "", "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Copy the bag type.
|
||||
*/
|
||||
result = asn1_write_value (c2, "?LAST.bagId", oid, 1);
|
||||
result = MHD__asn1_write_value (c2, "?LAST.bagId", oid, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -1245,7 +1245,7 @@ _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
|
||||
result = write_attributes (bag, i, c2, "?LAST.bagAttributes");
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -1256,37 +1256,37 @@ _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
|
||||
if (bag->element[i].type == GNUTLS_BAG_CERTIFICATE ||
|
||||
bag->element[i].type == GNUTLS_BAG_CRL)
|
||||
{
|
||||
gnutls_datum_t tmp;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
|
||||
/* in that case encode it to a CertBag or
|
||||
* a CrlBag.
|
||||
*/
|
||||
|
||||
result =
|
||||
_pkcs12_encode_crt_bag (bag->element[i].type,
|
||||
MHD_pkcs12_encode_crt_bag (bag->element[i].type,
|
||||
&bag->element[i].data, &tmp);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_write_value (c2, "?LAST.bagValue", &tmp, 0);
|
||||
result = MHD__gnutls_x509_write_value (c2, "?LAST.bagValue", &tmp, 0);
|
||||
|
||||
_gnutls_free_datum (&tmp);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
|
||||
}
|
||||
else
|
||||
{
|
||||
|
||||
result = _gnutls_x509_write_value (c2, "?LAST.bagValue",
|
||||
result = MHD__gnutls_x509_write_value (c2, "?LAST.bagValue",
|
||||
&bag->element[i].data, 0);
|
||||
}
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -1300,7 +1300,7 @@ _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag, ASN1_TYPE * contents,
|
||||
|
||||
cleanup:
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
|
||||
}
|
||||
|
||||
@@ -37,15 +37,15 @@ extern "C"
|
||||
|
||||
/* PKCS12 structures handling
|
||||
*/
|
||||
struct gnutls_pkcs12_int;
|
||||
struct MHD_gnutlsMHD_pkcs12_int;
|
||||
|
||||
struct gnutls_pkcs12_bag_int;
|
||||
typedef struct gnutls_pkcs12_int
|
||||
struct MHD_gnutlsMHD_pkcs12_bag_int;
|
||||
typedef struct MHD_gnutlsMHD_pkcs12_int
|
||||
{
|
||||
ASN1_TYPE pkcs12;
|
||||
} gnutls_pkcs12_int;
|
||||
} MHD_gnutlsMHD_pkcs12_int;
|
||||
|
||||
typedef enum gnutls_pkcs12_bag_type_t
|
||||
typedef enum MHD_gnutlsMHD_pkcs12_bag_type_t
|
||||
{
|
||||
GNUTLS_BAG_EMPTY = 0,
|
||||
|
||||
@@ -55,73 +55,73 @@ extern "C"
|
||||
GNUTLS_BAG_CRL,
|
||||
GNUTLS_BAG_ENCRYPTED = 10,
|
||||
GNUTLS_BAG_UNKNOWN = 20
|
||||
} gnutls_pkcs12_bag_type_t;
|
||||
} MHD_gnutlsMHD_pkcs12_bag_type_t;
|
||||
|
||||
struct bag_element
|
||||
{
|
||||
gnutls_datum_t data;
|
||||
gnutls_pkcs12_bag_type_t type;
|
||||
gnutls_datum_t local_key_id;
|
||||
MHD_gnutls_datum_t data;
|
||||
MHD_gnutlsMHD_pkcs12_bag_type_t type;
|
||||
MHD_gnutls_datum_t local_key_id;
|
||||
char *friendly_name;
|
||||
};
|
||||
|
||||
typedef struct gnutls_pkcs12_bag_int
|
||||
typedef struct MHD_gnutlsMHD_pkcs12_bag_int
|
||||
{
|
||||
struct bag_element element[MAX_BAG_ELEMENTS];
|
||||
int bag_elements;
|
||||
} gnutls_pkcs12_bag_int;
|
||||
} MHD_gnutlsMHD_pkcs12_bag_int;
|
||||
|
||||
/* Bag attributes */
|
||||
#define FRIENDLY_NAME_OID "1.2.840.113549.1.9.20"
|
||||
#define KEY_ID_OID "1.2.840.113549.1.9.21"
|
||||
|
||||
typedef struct gnutls_pkcs12_int *gnutls_pkcs12_t;
|
||||
typedef struct gnutls_pkcs12_bag_int *gnutls_pkcs12_bag_t;
|
||||
typedef struct MHD_gnutlsMHD_pkcs12_int *MHD_gnutlsMHD_pkcs12_t;
|
||||
typedef struct MHD_gnutlsMHD_pkcs12_bag_int *MHD_gnutlsMHD_pkcs12_bag_t;
|
||||
|
||||
int gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12);
|
||||
void gnutls_pkcs12_deinit (gnutls_pkcs12_t pkcs12);
|
||||
int gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format, unsigned int flags);
|
||||
int gnutls_pkcs12_export (gnutls_pkcs12_t pkcs12,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
int MHD_gnutlsMHD_pkcs12_init (MHD_gnutlsMHD_pkcs12_t * pkcs12);
|
||||
void MHD_gnutlsMHD_pkcs12_deinit (MHD_gnutlsMHD_pkcs12_t pkcs12);
|
||||
int MHD_gnutlsMHD_pkcs12_import (MHD_gnutlsMHD_pkcs12_t pkcs12,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format, unsigned int flags);
|
||||
int MHD_gnutlsMHD_pkcs12_export (MHD_gnutlsMHD_pkcs12_t pkcs12,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
|
||||
int indx, gnutls_pkcs12_bag_t bag);
|
||||
int gnutls_pkcs12_set_bag (gnutls_pkcs12_t pkcs12, gnutls_pkcs12_bag_t bag);
|
||||
int MHD_gnutlsMHD_pkcs12_get_bag (MHD_gnutlsMHD_pkcs12_t pkcs12,
|
||||
int indx, MHD_gnutlsMHD_pkcs12_bag_t bag);
|
||||
int MHD_gnutlsMHD_pkcs12_set_bag (MHD_gnutlsMHD_pkcs12_t pkcs12, MHD_gnutlsMHD_pkcs12_bag_t bag);
|
||||
|
||||
int gnutls_pkcs12_generate_mac (gnutls_pkcs12_t pkcs12, const char *pass);
|
||||
int gnutls_pkcs12_verify_mac (gnutls_pkcs12_t pkcs12, const char *pass);
|
||||
int MHD_gnutlsMHD_pkcs12_generate_mac (MHD_gnutlsMHD_pkcs12_t pkcs12, const char *pass);
|
||||
int MHD_gnutlsMHD_pkcs12_verify_mac (MHD_gnutlsMHD_pkcs12_t pkcs12, const char *pass);
|
||||
|
||||
int gnutls_pkcs12_bag_decrypt (gnutls_pkcs12_bag_t bag, const char *pass);
|
||||
int gnutls_pkcs12_bag_encrypt (gnutls_pkcs12_bag_t bag,
|
||||
int MHD_gnutlsMHD_pkcs12_bag_decrypt (MHD_gnutlsMHD_pkcs12_bag_t bag, const char *pass);
|
||||
int MHD_gnutlsMHD_pkcs12_bag_encrypt (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
const char *pass, unsigned int flags);
|
||||
|
||||
gnutls_pkcs12_bag_type_t gnutls_pkcs12_bag_get_type (gnutls_pkcs12_bag_t
|
||||
MHD_gnutlsMHD_pkcs12_bag_type_t MHD_gnutlsMHD_pkcs12_bag_get_type (MHD_gnutlsMHD_pkcs12_bag_t
|
||||
bag, int indx);
|
||||
int gnutls_pkcs12_bag_get_data (gnutls_pkcs12_bag_t bag,
|
||||
int indx, gnutls_datum_t * data);
|
||||
int gnutls_pkcs12_bag_set_data (gnutls_pkcs12_bag_t bag,
|
||||
gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * data);
|
||||
int gnutls_pkcs12_bag_set_crl (gnutls_pkcs12_bag_t bag,
|
||||
gnutls_x509_crl_t crl);
|
||||
int gnutls_pkcs12_bag_set_crt (gnutls_pkcs12_bag_t bag,
|
||||
gnutls_x509_crt_t crt);
|
||||
int MHD_gnutlsMHD_pkcs12_bag_get_data (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
int indx, MHD_gnutls_datum_t * data);
|
||||
int MHD_gnutlsMHD_pkcs12_bag_set_data (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
MHD_gnutlsMHD_pkcs12_bag_type_t type,
|
||||
const MHD_gnutls_datum_t * data);
|
||||
int MHD_gnutlsMHD_pkcs12_bag_set_crl (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutlsMHD_pkcs12_bag_set_crt (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
MHD_gnutls_x509_crt_t crt);
|
||||
|
||||
int gnutls_pkcs12_bag_init (gnutls_pkcs12_bag_t * bag);
|
||||
void gnutls_pkcs12_bag_deinit (gnutls_pkcs12_bag_t bag);
|
||||
int gnutls_pkcs12_bag_get_count (gnutls_pkcs12_bag_t bag);
|
||||
int MHD_gnutlsMHD_pkcs12_bag_init (MHD_gnutlsMHD_pkcs12_bag_t * bag);
|
||||
void MHD_gnutlsMHD_pkcs12_bag_deinit (MHD_gnutlsMHD_pkcs12_bag_t bag);
|
||||
int MHD_gnutlsMHD_pkcs12_bag_get_count (MHD_gnutlsMHD_pkcs12_bag_t bag);
|
||||
|
||||
int gnutls_pkcs12_bag_get_key_id (gnutls_pkcs12_bag_t bag,
|
||||
int indx, gnutls_datum_t * id);
|
||||
int gnutls_pkcs12_bag_set_key_id (gnutls_pkcs12_bag_t bag,
|
||||
int indx, const gnutls_datum_t * id);
|
||||
int MHD_gnutlsMHD_pkcs12_bag_get_key_id (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
int indx, MHD_gnutls_datum_t * id);
|
||||
int MHD_gnutlsMHD_pkcs12_bag_set_key_id (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
int indx, const MHD_gnutls_datum_t * id);
|
||||
|
||||
int gnutls_pkcs12_bag_get_friendly_name (gnutls_pkcs12_bag_t bag,
|
||||
int MHD_gnutlsMHD_pkcs12_bag_get_friendly_name (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
int indx, char **name);
|
||||
int gnutls_pkcs12_bag_set_friendly_name (gnutls_pkcs12_bag_t bag,
|
||||
int MHD_gnutlsMHD_pkcs12_bag_set_friendly_name (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
int indx, const char *name);
|
||||
|
||||
#ifdef __cplusplus
|
||||
@@ -138,27 +138,27 @@ extern "C"
|
||||
#define DATA_OID "1.2.840.113549.1.7.1"
|
||||
#define ENC_DATA_OID "1.2.840.113549.1.7.6"
|
||||
|
||||
int gnutls_pkcs12_init (gnutls_pkcs12_t * pkcs12);
|
||||
void gnutls_pkcs12_deinit (gnutls_pkcs12_t pkcs12);
|
||||
int gnutls_pkcs12_import (gnutls_pkcs12_t pkcs12,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format, unsigned int flags);
|
||||
int MHD_gnutlsMHD_pkcs12_init (MHD_gnutlsMHD_pkcs12_t * pkcs12);
|
||||
void MHD_gnutlsMHD_pkcs12_deinit (MHD_gnutlsMHD_pkcs12_t pkcs12);
|
||||
int MHD_gnutlsMHD_pkcs12_import (MHD_gnutlsMHD_pkcs12_t pkcs12,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format, unsigned int flags);
|
||||
|
||||
int gnutls_pkcs12_get_bag (gnutls_pkcs12_t pkcs12,
|
||||
int indx, gnutls_pkcs12_bag_t bag);
|
||||
int MHD_gnutlsMHD_pkcs12_get_bag (MHD_gnutlsMHD_pkcs12_t pkcs12,
|
||||
int indx, MHD_gnutlsMHD_pkcs12_bag_t bag);
|
||||
|
||||
int gnutls_pkcs12_bag_init (gnutls_pkcs12_bag_t * bag);
|
||||
void gnutls_pkcs12_bag_deinit (gnutls_pkcs12_bag_t bag);
|
||||
int MHD_gnutlsMHD_pkcs12_bag_init (MHD_gnutlsMHD_pkcs12_bag_t * bag);
|
||||
void MHD_gnutlsMHD_pkcs12_bag_deinit (MHD_gnutlsMHD_pkcs12_bag_t bag);
|
||||
|
||||
int _pkcs12_string_to_key (unsigned int id,
|
||||
int MHD_pkcs12_string_to_key (unsigned int id,
|
||||
const opaque * salt,
|
||||
unsigned int salt_size,
|
||||
unsigned int iter,
|
||||
const char *pw,
|
||||
unsigned int req_keylen, opaque * keybuf);
|
||||
|
||||
int _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
|
||||
const char *password, gnutls_datum_t * dec);
|
||||
int MHD__gnutls_pkcs7_decrypt_data (const MHD_gnutls_datum_t * data,
|
||||
const char *password, MHD_gnutls_datum_t * dec);
|
||||
|
||||
typedef enum schema_id
|
||||
{
|
||||
@@ -168,18 +168,18 @@ typedef enum schema_id
|
||||
PKCS12_RC2_40_SHA1
|
||||
} schema_id;
|
||||
|
||||
int _gnutls_pkcs7_encrypt_data (schema_id schema,
|
||||
const gnutls_datum_t * data,
|
||||
const char *password, gnutls_datum_t * enc);
|
||||
int _pkcs12_decode_safe_contents (const gnutls_datum_t * content,
|
||||
gnutls_pkcs12_bag_t bag);
|
||||
int MHD__gnutls_pkcs7_encrypt_data (schema_id schema,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
const char *password, MHD_gnutls_datum_t * enc);
|
||||
int MHD_pkcs12_decode_safe_contents (const MHD_gnutls_datum_t * content,
|
||||
MHD_gnutlsMHD_pkcs12_bag_t bag);
|
||||
|
||||
int _pkcs12_encode_safe_contents (gnutls_pkcs12_bag_t bag,
|
||||
int MHD_pkcs12_encode_safe_contents (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
ASN1_TYPE * content, int *enc);
|
||||
|
||||
int _pkcs12_decode_crt_bag (gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * in, gnutls_datum_t * out);
|
||||
int _pkcs12_encode_crt_bag (gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * raw, gnutls_datum_t * out);
|
||||
int MHD_pkcs12_decode_crt_bag (MHD_gnutlsMHD_pkcs12_bag_type_t type,
|
||||
const MHD_gnutls_datum_t * in, MHD_gnutls_datum_t * out);
|
||||
int MHD_pkcs12_encode_crt_bag (MHD_gnutlsMHD_pkcs12_bag_type_t type,
|
||||
const MHD_gnutls_datum_t * raw, MHD_gnutls_datum_t * out);
|
||||
|
||||
#endif /* GNUTLS_PKCS12_H */
|
||||
+142
-142
@@ -37,7 +37,7 @@
|
||||
#include <privkey.h>
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_init - This function initializes a gnutls_pkcs12_bag_t structure
|
||||
* MHD_gnutlsMHD_pkcs12_bag_init - This function initializes a MHD_gnutlsMHD_pkcs12_bag_t structure
|
||||
* @bag: The structure to be initialized
|
||||
*
|
||||
* This function will initialize a PKCS12 bag structure. PKCS12 Bags
|
||||
@@ -48,9 +48,9 @@
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_init (gnutls_pkcs12_bag_t * bag)
|
||||
MHD_gnutlsMHD_pkcs12_bag_init (MHD_gnutlsMHD_pkcs12_bag_t * bag)
|
||||
{
|
||||
*bag = gnutls_calloc (1, sizeof (gnutls_pkcs12_bag_int));
|
||||
*bag = MHD_gnutls_calloc (1, sizeof (MHD_gnutlsMHD_pkcs12_bag_int));
|
||||
|
||||
if (*bag)
|
||||
{
|
||||
@@ -60,15 +60,15 @@ gnutls_pkcs12_bag_init (gnutls_pkcs12_bag_t * bag)
|
||||
}
|
||||
|
||||
static inline void
|
||||
_pkcs12_bag_free_data (gnutls_pkcs12_bag_t bag)
|
||||
MHD_pkcs12_bag_free_data (MHD_gnutlsMHD_pkcs12_bag_t bag)
|
||||
{
|
||||
int i;
|
||||
|
||||
for (i = 0; i < bag->bag_elements; i++)
|
||||
{
|
||||
_gnutls_free_datum (&bag->element[i].data);
|
||||
_gnutls_free_datum (&bag->element[i].local_key_id);
|
||||
gnutls_free (bag->element[i].friendly_name);
|
||||
MHD__gnutls_free_datum (&bag->element[i].data);
|
||||
MHD__gnutls_free_datum (&bag->element[i].local_key_id);
|
||||
MHD_gnutls_free (bag->element[i].friendly_name);
|
||||
bag->element[i].friendly_name = NULL;
|
||||
bag->element[i].type = 0;
|
||||
}
|
||||
@@ -77,38 +77,38 @@ _pkcs12_bag_free_data (gnutls_pkcs12_bag_t bag)
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_deinit - This function deinitializes memory used by a gnutls_pkcs12_t structure
|
||||
* MHD_gnutlsMHD_pkcs12_bag_deinit - This function deinitializes memory used by a MHD_gnutlsMHD_pkcs12_t structure
|
||||
* @bag: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a PKCS12 Bag structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
gnutls_pkcs12_bag_deinit (gnutls_pkcs12_bag_t bag)
|
||||
MHD_gnutlsMHD_pkcs12_bag_deinit (MHD_gnutlsMHD_pkcs12_bag_t bag)
|
||||
{
|
||||
if (!bag)
|
||||
return;
|
||||
|
||||
_pkcs12_bag_free_data (bag);
|
||||
MHD_pkcs12_bag_free_data (bag);
|
||||
|
||||
gnutls_free (bag);
|
||||
MHD_gnutls_free (bag);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_get_type - This function returns the bag's type
|
||||
* MHD_gnutlsMHD_pkcs12_bag_get_type - This function returns the bag's type
|
||||
* @bag: The bag
|
||||
* @indx: The element of the bag to get the type
|
||||
*
|
||||
* This function will return the bag's type. One of the gnutls_pkcs12_bag_type_t
|
||||
* This function will return the bag's type. One of the MHD_gnutlsMHD_pkcs12_bag_type_t
|
||||
* enumerations.
|
||||
*
|
||||
**/
|
||||
gnutls_pkcs12_bag_type_t
|
||||
gnutls_pkcs12_bag_get_type (gnutls_pkcs12_bag_t bag, int indx)
|
||||
MHD_gnutlsMHD_pkcs12_bag_type_t
|
||||
MHD_gnutlsMHD_pkcs12_bag_get_type (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx)
|
||||
{
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -118,18 +118,18 @@ gnutls_pkcs12_bag_get_type (gnutls_pkcs12_bag_t bag, int indx)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_get_count - This function returns the bag's elements count
|
||||
* MHD_gnutlsMHD_pkcs12_bag_get_count - This function returns the bag's elements count
|
||||
* @bag: The bag
|
||||
*
|
||||
* This function will return the number of the elements withing the bag.
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_get_count (gnutls_pkcs12_bag_t bag)
|
||||
MHD_gnutlsMHD_pkcs12_bag_get_count (MHD_gnutlsMHD_pkcs12_bag_t bag)
|
||||
{
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -137,7 +137,7 @@ gnutls_pkcs12_bag_get_count (gnutls_pkcs12_bag_t bag)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_get_data - This function returns the bag's data
|
||||
* MHD_gnutlsMHD_pkcs12_bag_get_data - This function returns the bag's data
|
||||
* @bag: The bag
|
||||
* @indx: The element of the bag to get the data from
|
||||
* @data: where the bag's data will be. Should be treated as constant.
|
||||
@@ -150,12 +150,12 @@ gnutls_pkcs12_bag_get_count (gnutls_pkcs12_bag_t bag)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_get_data (gnutls_pkcs12_bag_t bag, int indx,
|
||||
gnutls_datum_t * data)
|
||||
MHD_gnutlsMHD_pkcs12_bag_get_data (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx,
|
||||
MHD_gnutls_datum_t * data)
|
||||
{
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -172,161 +172,161 @@ gnutls_pkcs12_bag_get_data (gnutls_pkcs12_bag_t bag, int indx,
|
||||
#define X509_CRL_OID "1.2.840.113549.1.9.23.1"
|
||||
|
||||
int
|
||||
_pkcs12_decode_crt_bag (gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * in, gnutls_datum_t * out)
|
||||
MHD_pkcs12_decode_crt_bag (MHD_gnutlsMHD_pkcs12_bag_type_t type,
|
||||
const MHD_gnutls_datum_t * in, MHD_gnutls_datum_t * out)
|
||||
{
|
||||
int ret;
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
|
||||
if (type == GNUTLS_BAG_CERTIFICATE)
|
||||
{
|
||||
if ((ret = asn1_create_element (_gnutls_get_pkix (),
|
||||
if ((ret = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-12-CertBag",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
ret = mhd_gtls_asn2err (ret);
|
||||
MHD_gnutls_assert ();
|
||||
ret = MHD_gtls_asn2err (ret);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = asn1_der_decoding (&c2, in->data, in->size, NULL);
|
||||
ret = MHD__asn1_der_decoding (&c2, in->data, in->size, NULL);
|
||||
if (ret != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
ret = mhd_gtls_asn2err (ret);
|
||||
MHD_gnutls_assert ();
|
||||
ret = MHD_gtls_asn2err (ret);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_read_value (c2, "certValue", out, 1);
|
||||
ret = MHD__gnutls_x509_read_value (c2, "certValue", out, 1);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
}
|
||||
else
|
||||
{ /* CRL */
|
||||
if ((ret = asn1_create_element (_gnutls_get_pkix (),
|
||||
if ((ret = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-12-CRLBag",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
ret = mhd_gtls_asn2err (ret);
|
||||
MHD_gnutls_assert ();
|
||||
ret = MHD_gtls_asn2err (ret);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = asn1_der_decoding (&c2, in->data, in->size, NULL);
|
||||
ret = MHD__asn1_der_decoding (&c2, in->data, in->size, NULL);
|
||||
if (ret != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
ret = mhd_gtls_asn2err (ret);
|
||||
MHD_gnutls_assert ();
|
||||
ret = MHD_gtls_asn2err (ret);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_read_value (c2, "crlValue", out, 1);
|
||||
ret = MHD__gnutls_x509_read_value (c2, "crlValue", out, 1);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
return 0;
|
||||
|
||||
|
||||
cleanup:
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
||||
int
|
||||
_pkcs12_encode_crt_bag (gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * raw, gnutls_datum_t * out)
|
||||
MHD_pkcs12_encode_crt_bag (MHD_gnutlsMHD_pkcs12_bag_type_t type,
|
||||
const MHD_gnutls_datum_t * raw, MHD_gnutls_datum_t * out)
|
||||
{
|
||||
int ret;
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
|
||||
if (type == GNUTLS_BAG_CERTIFICATE)
|
||||
{
|
||||
if ((ret = asn1_create_element (_gnutls_get_pkix (),
|
||||
if ((ret = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-12-CertBag",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
ret = mhd_gtls_asn2err (ret);
|
||||
MHD_gnutls_assert ();
|
||||
ret = MHD_gtls_asn2err (ret);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = asn1_write_value (c2, "certId", X509_CERT_OID, 1);
|
||||
ret = MHD__asn1_write_value (c2, "certId", X509_CERT_OID, 1);
|
||||
if (ret != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
ret = mhd_gtls_asn2err (ret);
|
||||
MHD_gnutls_assert ();
|
||||
ret = MHD_gtls_asn2err (ret);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_write_value (c2, "certValue", raw, 1);
|
||||
ret = MHD__gnutls_x509_write_value (c2, "certValue", raw, 1);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
}
|
||||
else
|
||||
{ /* CRL */
|
||||
if ((ret = asn1_create_element (_gnutls_get_pkix (),
|
||||
if ((ret = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-12-CRLBag",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
ret = mhd_gtls_asn2err (ret);
|
||||
MHD_gnutls_assert ();
|
||||
ret = MHD_gtls_asn2err (ret);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = asn1_write_value (c2, "crlId", X509_CRL_OID, 1);
|
||||
ret = MHD__asn1_write_value (c2, "crlId", X509_CRL_OID, 1);
|
||||
if (ret != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
ret = mhd_gtls_asn2err (ret);
|
||||
MHD_gnutls_assert ();
|
||||
ret = MHD_gtls_asn2err (ret);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_write_value (c2, "crlValue", raw, 1);
|
||||
ret = MHD__gnutls_x509_write_value (c2, "crlValue", raw, 1);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_der_encode (c2, "", out, 0);
|
||||
ret = MHD__gnutls_x509_der_encode (c2, "", out, 0);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
return 0;
|
||||
|
||||
|
||||
cleanup:
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_set_data - This function inserts data into the bag
|
||||
* MHD_gnutlsMHD_pkcs12_bag_set_data - This function inserts data into the bag
|
||||
* @bag: The bag
|
||||
* @type: The data's type
|
||||
* @data: the data to be copied.
|
||||
@@ -339,20 +339,20 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_set_data (gnutls_pkcs12_bag_t bag,
|
||||
gnutls_pkcs12_bag_type_t type,
|
||||
const gnutls_datum_t * data)
|
||||
MHD_gnutlsMHD_pkcs12_bag_set_data (MHD_gnutlsMHD_pkcs12_bag_t bag,
|
||||
MHD_gnutlsMHD_pkcs12_bag_type_t type,
|
||||
const MHD_gnutls_datum_t * data)
|
||||
{
|
||||
int ret;
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (bag->bag_elements == MAX_BAG_ELEMENTS - 1)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
/* bag is full */
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
@@ -367,18 +367,18 @@ gnutls_pkcs12_bag_set_data (gnutls_pkcs12_bag_t bag,
|
||||
bag->element[0].type == GNUTLS_BAG_PKCS8_ENCRYPTED_KEY ||
|
||||
bag->element[0].type == GNUTLS_BAG_ENCRYPTED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
}
|
||||
|
||||
ret =
|
||||
_gnutls_set_datum (&bag->element[bag->bag_elements].data,
|
||||
MHD__gnutls_set_datum (&bag->element[bag->bag_elements].data,
|
||||
data->data, data->size);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -390,84 +390,84 @@ gnutls_pkcs12_bag_set_data (gnutls_pkcs12_bag_t bag,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_set_crt - This function inserts a certificate into the bag
|
||||
* MHD_gnutlsMHD_pkcs12_bag_set_crt - This function inserts a certificate into the bag
|
||||
* @bag: The bag
|
||||
* @crt: the certificate to be copied.
|
||||
*
|
||||
* This function will insert the given certificate into the
|
||||
* bag. This is just a wrapper over gnutls_pkcs12_bag_set_data().
|
||||
* bag. This is just a wrapper over MHD_gnutlsMHD_pkcs12_bag_set_data().
|
||||
*
|
||||
* Returns the index of the added bag on success, or a negative
|
||||
* value on failure.
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_set_crt (gnutls_pkcs12_bag_t bag, gnutls_x509_crt_t crt)
|
||||
MHD_gnutlsMHD_pkcs12_bag_set_crt (MHD_gnutlsMHD_pkcs12_bag_t bag, MHD_gnutls_x509_crt_t crt)
|
||||
{
|
||||
int ret;
|
||||
gnutls_datum_t data;
|
||||
MHD_gnutls_datum_t data;
|
||||
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_der_encode (crt->cert, "", &data, 0);
|
||||
ret = MHD__gnutls_x509_der_encode (crt->cert, "", &data, 0);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = gnutls_pkcs12_bag_set_data (bag, GNUTLS_BAG_CERTIFICATE, &data);
|
||||
ret = MHD_gnutlsMHD_pkcs12_bag_set_data (bag, GNUTLS_BAG_CERTIFICATE, &data);
|
||||
|
||||
_gnutls_free_datum (&data);
|
||||
MHD__gnutls_free_datum (&data);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_set_crl - This function inserts the CRL into the bag
|
||||
* MHD_gnutlsMHD_pkcs12_bag_set_crl - This function inserts the CRL into the bag
|
||||
* @bag: The bag
|
||||
* @crl: the CRL to be copied.
|
||||
*
|
||||
* This function will insert the given CRL into the
|
||||
* bag. This is just a wrapper over gnutls_pkcs12_bag_set_data().
|
||||
* bag. This is just a wrapper over MHD_gnutlsMHD_pkcs12_bag_set_data().
|
||||
*
|
||||
* Returns the index of the added bag on success, or a negative
|
||||
* value on failure.
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_set_crl (gnutls_pkcs12_bag_t bag, gnutls_x509_crl_t crl)
|
||||
MHD_gnutlsMHD_pkcs12_bag_set_crl (MHD_gnutlsMHD_pkcs12_bag_t bag, MHD_gnutls_x509_crl_t crl)
|
||||
{
|
||||
int ret;
|
||||
gnutls_datum_t data;
|
||||
MHD_gnutls_datum_t data;
|
||||
|
||||
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_der_encode (crl->crl, "", &data, 0);
|
||||
ret = MHD__gnutls_x509_der_encode (crl->crl, "", &data, 0);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = gnutls_pkcs12_bag_set_data (bag, GNUTLS_BAG_CRL, &data);
|
||||
ret = MHD_gnutlsMHD_pkcs12_bag_set_data (bag, GNUTLS_BAG_CRL, &data);
|
||||
|
||||
_gnutls_free_datum (&data);
|
||||
MHD__gnutls_free_datum (&data);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_set_key_id - This function sets a key ID into the bag element
|
||||
* MHD_gnutlsMHD_pkcs12_bag_set_key_id - This function sets a key ID into the bag element
|
||||
* @bag: The bag
|
||||
* @indx: The bag's element to add the id
|
||||
* @id: the ID
|
||||
@@ -480,30 +480,30 @@ gnutls_pkcs12_bag_set_crl (gnutls_pkcs12_bag_t bag, gnutls_x509_crl_t crl)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_set_key_id (gnutls_pkcs12_bag_t bag, int indx,
|
||||
const gnutls_datum_t * id)
|
||||
MHD_gnutlsMHD_pkcs12_bag_set_key_id (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx,
|
||||
const MHD_gnutls_datum_t * id)
|
||||
{
|
||||
int ret;
|
||||
|
||||
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (indx > bag->bag_elements - 1)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
ret = _gnutls_set_datum (&bag->element[indx].local_key_id,
|
||||
ret = MHD__gnutls_set_datum (&bag->element[indx].local_key_id,
|
||||
id->data, id->size);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -511,7 +511,7 @@ gnutls_pkcs12_bag_set_key_id (gnutls_pkcs12_bag_t bag, int indx,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_get_key_id - This function gets the key ID from the bag element
|
||||
* MHD_gnutlsMHD_pkcs12_bag_get_key_id - This function gets the key ID from the bag element
|
||||
* @bag: The bag
|
||||
* @indx: The bag's element to add the id
|
||||
* @id: where the ID will be copied (to be treated as const)
|
||||
@@ -523,18 +523,18 @@ gnutls_pkcs12_bag_set_key_id (gnutls_pkcs12_bag_t bag, int indx,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_get_key_id (gnutls_pkcs12_bag_t bag, int indx,
|
||||
gnutls_datum_t * id)
|
||||
MHD_gnutlsMHD_pkcs12_bag_get_key_id (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx,
|
||||
MHD_gnutls_datum_t * id)
|
||||
{
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (indx > bag->bag_elements - 1)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -545,7 +545,7 @@ gnutls_pkcs12_bag_get_key_id (gnutls_pkcs12_bag_t bag, int indx,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_get_friendly_name - This function returns the friendly name of the bag element
|
||||
* MHD_gnutlsMHD_pkcs12_bag_get_friendly_name - This function returns the friendly name of the bag element
|
||||
* @bag: The bag
|
||||
* @indx: The bag's element to add the id
|
||||
* @name: will hold a pointer to the name (to be treated as const)
|
||||
@@ -557,18 +557,18 @@ gnutls_pkcs12_bag_get_key_id (gnutls_pkcs12_bag_t bag, int indx,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_get_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
|
||||
MHD_gnutlsMHD_pkcs12_bag_get_friendly_name (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx,
|
||||
char **name)
|
||||
{
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (indx > bag->bag_elements - 1)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -579,7 +579,7 @@ gnutls_pkcs12_bag_get_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_set_friendly_name - This function sets a friendly name into the bag element
|
||||
* MHD_gnutlsMHD_pkcs12_bag_set_friendly_name - This function sets a friendly name into the bag element
|
||||
* @bag: The bag
|
||||
* @indx: The bag's element to add the id
|
||||
* @name: the name
|
||||
@@ -592,26 +592,26 @@ gnutls_pkcs12_bag_get_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_set_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
|
||||
MHD_gnutlsMHD_pkcs12_bag_set_friendly_name (MHD_gnutlsMHD_pkcs12_bag_t bag, int indx,
|
||||
const char *name)
|
||||
{
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (indx > bag->bag_elements - 1)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
bag->element[indx].friendly_name = gnutls_strdup (name);
|
||||
bag->element[indx].friendly_name = MHD_gnutls_strdup (name);
|
||||
|
||||
if (name == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
@@ -620,7 +620,7 @@ gnutls_pkcs12_bag_set_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_decrypt - This function will decrypt an encrypted bag
|
||||
* MHD_gnutlsMHD_pkcs12_bag_decrypt - This function will decrypt an encrypted bag
|
||||
* @bag: The bag
|
||||
* @pass: The password used for encryption. This can only be ASCII.
|
||||
*
|
||||
@@ -628,28 +628,28 @@ gnutls_pkcs12_bag_set_friendly_name (gnutls_pkcs12_bag_t bag, int indx,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_decrypt (gnutls_pkcs12_bag_t bag, const char *pass)
|
||||
MHD_gnutlsMHD_pkcs12_bag_decrypt (MHD_gnutlsMHD_pkcs12_bag_t bag, const char *pass)
|
||||
{
|
||||
int ret;
|
||||
gnutls_datum_t dec;
|
||||
MHD_gnutls_datum_t dec;
|
||||
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (bag->element[0].type != GNUTLS_BAG_ENCRYPTED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
ret = _gnutls_pkcs7_decrypt_data (&bag->element[0].data, pass, &dec);
|
||||
ret = MHD__gnutls_pkcs7_decrypt_data (&bag->element[0].data, pass, &dec);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -657,15 +657,15 @@ gnutls_pkcs12_bag_decrypt (gnutls_pkcs12_bag_t bag, const char *pass)
|
||||
* stuff, and parse it.
|
||||
*/
|
||||
|
||||
_gnutls_free_datum (&bag->element[0].data);
|
||||
MHD__gnutls_free_datum (&bag->element[0].data);
|
||||
|
||||
ret = _pkcs12_decode_safe_contents (&dec, bag);
|
||||
ret = MHD_pkcs12_decode_safe_contents (&dec, bag);
|
||||
|
||||
_gnutls_free_datum (&dec);
|
||||
MHD__gnutls_free_datum (&dec);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -673,61 +673,61 @@ gnutls_pkcs12_bag_decrypt (gnutls_pkcs12_bag_t bag, const char *pass)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs12_bag_encrypt - This function will encrypt a bag
|
||||
* MHD_gnutlsMHD_pkcs12_bag_encrypt - This function will encrypt a bag
|
||||
* @bag: The bag
|
||||
* @pass: The password used for encryption. This can only be ASCII.
|
||||
* @flags: should be one of gnutls_pkcs_encrypt_flags_t elements bitwise or'd
|
||||
* @flags: should be one of MHD_gnutls_pkcs_encrypt_flags_t elements bitwise or'd
|
||||
*
|
||||
* This function will encrypt the given bag and return 0 on success.
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs12_bag_encrypt (gnutls_pkcs12_bag_t bag, const char *pass,
|
||||
MHD_gnutlsMHD_pkcs12_bag_encrypt (MHD_gnutlsMHD_pkcs12_bag_t bag, const char *pass,
|
||||
unsigned int flags)
|
||||
{
|
||||
int ret;
|
||||
ASN1_TYPE safe_cont = ASN1_TYPE_EMPTY;
|
||||
gnutls_datum_t der = { NULL, 0 };
|
||||
gnutls_datum_t enc = { NULL, 0 };
|
||||
MHD_gnutls_datum_t der = { NULL, 0 };
|
||||
MHD_gnutls_datum_t enc = { NULL, 0 };
|
||||
schema_id id;
|
||||
|
||||
if (bag == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (bag->element[0].type == GNUTLS_BAG_ENCRYPTED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
/* Encode the whole bag to a safe contents
|
||||
* structure.
|
||||
*/
|
||||
ret = _pkcs12_encode_safe_contents (bag, &safe_cont, NULL);
|
||||
ret = MHD_pkcs12_encode_safe_contents (bag, &safe_cont, NULL);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
/* DER encode the SafeContents.
|
||||
*/
|
||||
ret = _gnutls_x509_der_encode (safe_cont, "", &der, 0);
|
||||
ret = MHD__gnutls_x509_der_encode (safe_cont, "", &der, 0);
|
||||
|
||||
asn1_delete_structure (&safe_cont);
|
||||
MHD__asn1_delete_structure (&safe_cont);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
if (flags & GNUTLS_PKCS_PLAIN)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -742,20 +742,20 @@ gnutls_pkcs12_bag_encrypt (gnutls_pkcs12_bag_t bag, const char *pass,
|
||||
|
||||
/* Now encrypt them.
|
||||
*/
|
||||
ret = _gnutls_pkcs7_encrypt_data (id, &der, pass, &enc);
|
||||
ret = MHD__gnutls_pkcs7_encrypt_data (id, &der, pass, &enc);
|
||||
|
||||
_gnutls_free_datum (&der);
|
||||
MHD__gnutls_free_datum (&der);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
/* encryption succeeded.
|
||||
*/
|
||||
|
||||
_pkcs12_bag_free_data (bag);
|
||||
MHD_pkcs12_bag_free_data (bag);
|
||||
|
||||
bag->element[0].type = GNUTLS_BAG_ENCRYPTED;
|
||||
bag->element[0].data = enc;
|
||||
|
||||
@@ -33,7 +33,7 @@
|
||||
* code instead.
|
||||
*/
|
||||
static int
|
||||
_pkcs12_check_pass (const char *pass, size_t plen)
|
||||
MHD_pkcs12_check_pass (const char *pass, size_t plen)
|
||||
{
|
||||
const unsigned char *p = pass;
|
||||
unsigned int i;
|
||||
@@ -54,14 +54,14 @@ _pkcs12_check_pass (const char *pass, size_t plen)
|
||||
* 1 for encryption key
|
||||
*/
|
||||
int
|
||||
_pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
MHD_pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
unsigned int salt_size, unsigned int iter,
|
||||
const char *pw, unsigned int req_keylen,
|
||||
opaque * keybuf)
|
||||
{
|
||||
int rc;
|
||||
unsigned int i, j;
|
||||
gc_hash_handle md;
|
||||
MHD_gc_hash_handle md;
|
||||
mpi_t num_b1 = NULL;
|
||||
unsigned int pwlen;
|
||||
opaque hash[20], buf_b[64], buf_i[128], *p;
|
||||
@@ -77,13 +77,13 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
|
||||
if (pwlen > 63 / 2)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if ((rc = _pkcs12_check_pass (pw, pwlen)) < 0)
|
||||
if ((rc = MHD_pkcs12_check_pass (pw, pwlen)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return rc;
|
||||
}
|
||||
|
||||
@@ -106,22 +106,22 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
|
||||
for (;;)
|
||||
{
|
||||
rc = gc_hash_open (GC_SHA1, 0, &md);
|
||||
rc = MHD_gc_hash_open (GC_SHA1, 0, &md);
|
||||
if (rc)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_DECRYPTION_FAILED;
|
||||
}
|
||||
for (i = 0; i < 64; i++)
|
||||
{
|
||||
unsigned char lid = id & 0xFF;
|
||||
gc_hash_write (md, 1, &lid);
|
||||
MHD_gc_hash_write (md, 1, &lid);
|
||||
}
|
||||
gc_hash_write (md, pw ? 128 : 64, buf_i);
|
||||
memcpy (hash, gc_hash_read (md), 20);
|
||||
gc_hash_close (md);
|
||||
MHD_gc_hash_write (md, pw ? 128 : 64, buf_i);
|
||||
memcpy (hash, MHD_gc_hash_read (md), 20);
|
||||
MHD_gc_hash_close (md);
|
||||
for (i = 1; i < iter; i++)
|
||||
gc_hash_buffer (GC_SHA1, hash, 20, hash);
|
||||
MHD_gc_hash_buffer (GC_SHA1, hash, 20, hash);
|
||||
for (i = 0; i < 20 && cur_keylen < req_keylen; i++)
|
||||
keybuf[cur_keylen++] = hash[i];
|
||||
if (cur_keylen == req_keylen)
|
||||
@@ -134,10 +134,10 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
for (i = 0; i < 64; i++)
|
||||
buf_b[i] = hash[i % 20];
|
||||
n = 64;
|
||||
rc = mhd_gtls_mpi_scan (&num_b1, buf_b, &n);
|
||||
rc = MHD_gtls_mpi_scan (&num_b1, buf_b, &n);
|
||||
if (rc < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return rc;
|
||||
}
|
||||
gcry_mpi_add_ui (num_b1, num_b1, 1);
|
||||
@@ -146,19 +146,19 @@ _pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
mpi_t num_ij;
|
||||
|
||||
n = 64;
|
||||
rc = mhd_gtls_mpi_scan (&num_ij, buf_i + i, &n);
|
||||
rc = MHD_gtls_mpi_scan (&num_ij, buf_i + i, &n);
|
||||
if (rc < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return rc;
|
||||
}
|
||||
gcry_mpi_add (num_ij, num_ij, num_b1);
|
||||
gcry_mpi_clear_highbit (num_ij, 64 * 8);
|
||||
n = 64;
|
||||
rc = mhd_gtls_mpi_print (buf_i + i, &n, num_ij);
|
||||
rc = MHD_gtls_mpi_print (buf_i + i, &n, num_ij);
|
||||
if (rc < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return rc;
|
||||
}
|
||||
gcry_mpi_release (num_ij);
|
||||
|
||||
+179
-179
@@ -46,7 +46,7 @@
|
||||
*/
|
||||
static int
|
||||
_decode_pkcs7_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata,
|
||||
gnutls_datum_t * raw)
|
||||
MHD_gnutls_datum_t * raw)
|
||||
{
|
||||
char oid[128];
|
||||
ASN1_TYPE c2;
|
||||
@@ -54,52 +54,52 @@ _decode_pkcs7_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata,
|
||||
int tmp_size, len, result;
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = asn1_read_value (pkcs7, "contentType", oid, &len);
|
||||
result = MHD__asn1_read_value (pkcs7, "contentType", oid, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (strcmp (oid, SIGNED_DATA_OID) != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log ("Unknown PKCS7 Content OID '%s'\n", oid);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_x509_log ("Unknown PKCS7 Content OID '%s'\n", oid);
|
||||
return GNUTLS_E_UNKNOWN_PKCS_CONTENT_TYPE;
|
||||
}
|
||||
|
||||
if ((result = asn1_create_element
|
||||
(_gnutls_get_pkix (), "PKIX1.pkcs-7-SignedData", &c2)) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-SignedData", &c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* the Signed-data has been created, so
|
||||
* decode them.
|
||||
*/
|
||||
tmp_size = 0;
|
||||
result = asn1_read_value (pkcs7, "content", NULL, &tmp_size);
|
||||
result = MHD__asn1_read_value (pkcs7, "content", NULL, &tmp_size);
|
||||
if (result != ASN1_MEM_ERROR)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
tmp = gnutls_malloc (tmp_size);
|
||||
tmp = MHD_gnutls_malloc (tmp_size);
|
||||
if (tmp == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_read_value (pkcs7, "content", tmp, &tmp_size);
|
||||
result = MHD__asn1_read_value (pkcs7, "content", tmp, &tmp_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -110,17 +110,17 @@ _decode_pkcs7_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata,
|
||||
/* Step 1. In case of a signed structure extract certificate set.
|
||||
*/
|
||||
|
||||
result = asn1_der_decoding (&c2, tmp, tmp_size, NULL);
|
||||
result = MHD__asn1_der_decoding (&c2, tmp, tmp_size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (raw == NULL)
|
||||
{
|
||||
gnutls_free (tmp);
|
||||
MHD_gnutls_free (tmp);
|
||||
}
|
||||
else
|
||||
{
|
||||
@@ -134,13 +134,13 @@ _decode_pkcs7_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata,
|
||||
|
||||
cleanup:
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
gnutls_free (tmp);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
MHD_gnutls_free (tmp);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_init - This function initializes a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_init - This function initializes a MHD_gnutls_pkcs7_t structure
|
||||
* @pkcs7: The structure to be initialized
|
||||
*
|
||||
* This function will initialize a PKCS7 structure. PKCS7 structures
|
||||
@@ -151,20 +151,20 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_init (gnutls_pkcs7_t * pkcs7)
|
||||
MHD_gnutls_pkcs7_init (MHD_gnutls_pkcs7_t * pkcs7)
|
||||
{
|
||||
*pkcs7 = gnutls_calloc (1, sizeof (gnutls_pkcs7_int));
|
||||
*pkcs7 = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_pkcs7_int));
|
||||
|
||||
if (*pkcs7)
|
||||
{
|
||||
int result = asn1_create_element (_gnutls_get_pkix (),
|
||||
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-7-ContentInfo",
|
||||
&(*pkcs7)->pkcs7);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_free (*pkcs7);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_free (*pkcs7);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
return 0; /* success */
|
||||
}
|
||||
@@ -172,32 +172,32 @@ gnutls_pkcs7_init (gnutls_pkcs7_t * pkcs7)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_deinit - This function deinitializes memory used by a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_deinit - This function deinitializes memory used by a MHD_gnutls_pkcs7_t structure
|
||||
* @pkcs7: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a PKCS7 structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
gnutls_pkcs7_deinit (gnutls_pkcs7_t pkcs7)
|
||||
MHD_gnutls_pkcs7_deinit (MHD_gnutls_pkcs7_t pkcs7)
|
||||
{
|
||||
if (!pkcs7)
|
||||
return;
|
||||
|
||||
if (pkcs7->pkcs7)
|
||||
asn1_delete_structure (&pkcs7->pkcs7);
|
||||
MHD__asn1_delete_structure (&pkcs7->pkcs7);
|
||||
|
||||
gnutls_free (pkcs7);
|
||||
MHD_gnutls_free (pkcs7);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_import - This function will import a DER or PEM encoded PKCS7
|
||||
* MHD_gnutls_pkcs7_import - This function will import a DER or PEM encoded PKCS7
|
||||
* @pkcs7: The structure to store the parsed PKCS7.
|
||||
* @data: The DER or PEM encoded PKCS7.
|
||||
* @format: One of DER or PEM
|
||||
*
|
||||
* This function will convert the given DER or PEM encoded PKCS7
|
||||
* to the native gnutls_pkcs7_t format. The output will be stored in 'pkcs7'.
|
||||
* to the native MHD_gnutls_pkcs7_t format. The output will be stored in 'pkcs7'.
|
||||
*
|
||||
* If the PKCS7 is PEM encoded it should have a header of "PKCS7".
|
||||
*
|
||||
@@ -205,11 +205,11 @@ gnutls_pkcs7_deinit (gnutls_pkcs7_t pkcs7)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_import (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format)
|
||||
MHD_gnutls_pkcs7_import (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
gnutls_datum_t _data;
|
||||
MHD_gnutls_datum_t _data;
|
||||
|
||||
if (pkcs7 == NULL)
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
@@ -223,14 +223,14 @@ gnutls_pkcs7_import (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * data,
|
||||
{
|
||||
opaque *out;
|
||||
|
||||
result = _gnutls_fbase64_decode (PEM_PKCS7, data->data, data->size,
|
||||
result = MHD__gnutls_fbase64_decode (PEM_PKCS7, data->data, data->size,
|
||||
&out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
if (result == 0)
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -241,28 +241,28 @@ gnutls_pkcs7_import (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * data,
|
||||
}
|
||||
|
||||
|
||||
result = asn1_der_decoding (&pkcs7->pkcs7, _data.data, _data.size, NULL);
|
||||
result = MHD__asn1_der_decoding (&pkcs7->pkcs7, _data.data, _data.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
result = mhd_gtls_asn2err (result);
|
||||
gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_get_crt_raw - This function returns a certificate in a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_get_crt_raw - This function returns a certificate in a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
|
||||
* @indx: contains the index of the certificate to extract
|
||||
* @certificate: the contents of the certificate will be copied there (may be null)
|
||||
* @certificate_size: should hold the size of the certificate
|
||||
@@ -276,7 +276,7 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
MHD_gnutls_pkcs7_get_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
int indx, void *certificate,
|
||||
size_t * certificate_size)
|
||||
{
|
||||
@@ -284,7 +284,7 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
int result, len;
|
||||
char root2[MAX_NAME_SIZE];
|
||||
char oid[128];
|
||||
gnutls_datum_t tmp = { NULL, 0 };
|
||||
MHD_gnutls_datum_t tmp = { NULL, 0 };
|
||||
|
||||
if (certificate_size == NULL || pkcs7 == NULL)
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
@@ -294,7 +294,7 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, &tmp);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -305,7 +305,7 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
|
||||
result = asn1_read_value (c2, root2, oid, &len);
|
||||
result = MHD__asn1_read_value (c2, root2, oid, &len);
|
||||
|
||||
if (result == ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
@@ -315,8 +315,8 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -326,13 +326,13 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
{
|
||||
int start, end;
|
||||
|
||||
result = asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
|
||||
result = MHD__asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
|
||||
root2, &start, &end);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -359,15 +359,15 @@ gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
}
|
||||
|
||||
cleanup:
|
||||
_gnutls_free_datum (&tmp);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_get_crt_count - This function returns the number of certificates in a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_get_crt_count - This function returns the number of certificates in a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
|
||||
*
|
||||
* This function will return the number of certifcates in the PKCS7 or
|
||||
* RFC2630 certificate set.
|
||||
@@ -376,7 +376,7 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7)
|
||||
MHD_gnutls_pkcs7_get_crt_count (MHD_gnutls_pkcs7_t pkcs7)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result, count;
|
||||
@@ -389,19 +389,19 @@ gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7)
|
||||
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Step 2. Count the CertificateSet */
|
||||
|
||||
result = asn1_number_of_elements (c2, "certificates", &count);
|
||||
result = MHD__asn1_number_of_elements (c2, "certificates", &count);
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return 0; /* no certificates */
|
||||
}
|
||||
|
||||
@@ -410,7 +410,7 @@ gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_export - This function will export the pkcs7 structure
|
||||
* MHD_gnutls_pkcs7_export - This function will export the pkcs7 structure
|
||||
* @pkcs7: Holds the pkcs7 structure
|
||||
* @format: the format of output params. One of PEM or DER.
|
||||
* @output_data: will contain a structure PEM or DER encoded
|
||||
@@ -431,14 +431,14 @@ gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_export (gnutls_pkcs7_t pkcs7,
|
||||
gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
MHD_gnutls_pkcs7_export (MHD_gnutls_pkcs7_t pkcs7,
|
||||
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
size_t * output_data_size)
|
||||
{
|
||||
if (pkcs7 == NULL)
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
|
||||
return _gnutls_x509_export_int (pkcs7->pkcs7, format, PEM_PKCS7,
|
||||
return MHD__gnutls_x509_export_int (pkcs7->pkcs7, format, PEM_PKCS7,
|
||||
output_data, output_data_size);
|
||||
}
|
||||
|
||||
@@ -453,22 +453,22 @@ create_empty_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata)
|
||||
|
||||
*sdata = ASN1_TYPE_EMPTY;
|
||||
|
||||
if ((result = asn1_create_element
|
||||
(_gnutls_get_pkix (), "PKIX1.pkcs-7-SignedData",
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-SignedData",
|
||||
sdata)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Use version 1
|
||||
*/
|
||||
result = asn1_write_value (*sdata, "version", &one, 1);
|
||||
result = MHD__asn1_write_value (*sdata, "version", &one, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -477,20 +477,20 @@ create_empty_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata)
|
||||
|
||||
/* id-data */
|
||||
result =
|
||||
asn1_write_value (*sdata, "encapContentInfo.eContentType",
|
||||
MHD__asn1_write_value (*sdata, "encapContentInfo.eContentType",
|
||||
"1.2.840.113549.1.7.5", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_write_value (*sdata, "encapContentInfo.eContent", NULL, 0);
|
||||
result = MHD__asn1_write_value (*sdata, "encapContentInfo.eContent", NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -505,25 +505,25 @@ create_empty_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata)
|
||||
|
||||
/* Write the content type of the signed data
|
||||
*/
|
||||
result = asn1_write_value (pkcs7, "contentType", SIGNED_DATA_OID, 1);
|
||||
result = MHD__asn1_write_value (pkcs7, "contentType", SIGNED_DATA_OID, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
asn1_delete_structure (sdata);
|
||||
MHD__asn1_delete_structure (sdata);
|
||||
return result;
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_set_crt_raw - This function adds a certificate in a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_set_crt_raw - This function adds a certificate in a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
|
||||
* @crt: the DER encoded certificate to be added
|
||||
*
|
||||
* This function will add a certificate to the PKCS7 or RFC2630 certificate set.
|
||||
@@ -531,7 +531,7 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crt)
|
||||
MHD_gnutls_pkcs7_set_crt_raw (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * crt)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
@@ -544,7 +544,7 @@ gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crt)
|
||||
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
|
||||
if (result < 0 && result != GNUTLS_E_ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -559,7 +559,7 @@ gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crt)
|
||||
result = create_empty_signed_data (pkcs7->pkcs7, &c2);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
}
|
||||
@@ -567,86 +567,86 @@ gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crt)
|
||||
/* Step 2. Append the new certificate.
|
||||
*/
|
||||
|
||||
result = asn1_write_value (c2, "certificates", "NEW", 1);
|
||||
result = MHD__asn1_write_value (c2, "certificates", "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_write_value (c2, "certificates.?LAST", "certificate", 1);
|
||||
result = MHD__asn1_write_value (c2, "certificates.?LAST", "certificate", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_write_value (c2, "certificates.?LAST.certificate", crt->data,
|
||||
MHD__asn1_write_value (c2, "certificates.?LAST.certificate", crt->data,
|
||||
crt->size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Step 3. Replace the old content with the new
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
|
||||
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_set_crt - This function adds a parsed certificate in a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_set_crt - This function adds a parsed certificate in a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
|
||||
* @crt: the certificate to be copied.
|
||||
*
|
||||
* This function will add a parsed certificate to the PKCS7 or RFC2630 certificate set.
|
||||
* This is a wrapper function over gnutls_pkcs7_set_crt_raw() .
|
||||
* This is a wrapper function over MHD_gnutls_pkcs7_set_crt_raw() .
|
||||
*
|
||||
* Returns 0 on success.
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_set_crt (gnutls_pkcs7_t pkcs7, gnutls_x509_crt_t crt)
|
||||
MHD_gnutls_pkcs7_set_crt (MHD_gnutls_pkcs7_t pkcs7, MHD_gnutls_x509_crt_t crt)
|
||||
{
|
||||
int ret;
|
||||
gnutls_datum_t data;
|
||||
MHD_gnutls_datum_t data;
|
||||
|
||||
if (pkcs7 == NULL)
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
|
||||
ret = _gnutls_x509_der_encode (crt->cert, "", &data, 0);
|
||||
ret = MHD__gnutls_x509_der_encode (crt->cert, "", &data, 0);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = gnutls_pkcs7_set_crt_raw (pkcs7, &data);
|
||||
ret = MHD_gnutls_pkcs7_set_crt_raw (pkcs7, &data);
|
||||
|
||||
_gnutls_free_datum (&data);
|
||||
MHD__gnutls_free_datum (&data);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -655,8 +655,8 @@ gnutls_pkcs7_set_crt (gnutls_pkcs7_t pkcs7, gnutls_x509_crt_t crt)
|
||||
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_delete_crt - This function deletes a certificate from a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_delete_crt - This function deletes a certificate from a PKCS7 certificate set
|
||||
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
|
||||
* @indx: the index of the certificate to delete
|
||||
*
|
||||
* This function will delete a certificate from a PKCS7 or RFC2630 certificate set.
|
||||
@@ -664,7 +664,7 @@ gnutls_pkcs7_set_crt (gnutls_pkcs7_t pkcs7, gnutls_x509_crt_t crt)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_delete_crt (gnutls_pkcs7_t pkcs7, int indx)
|
||||
MHD_gnutls_pkcs7_delete_crt (MHD_gnutls_pkcs7_t pkcs7, int indx)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
@@ -678,7 +678,7 @@ gnutls_pkcs7_delete_crt (gnutls_pkcs7_t pkcs7, int indx)
|
||||
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -687,31 +687,31 @@ gnutls_pkcs7_delete_crt (gnutls_pkcs7_t pkcs7, int indx)
|
||||
|
||||
snprintf (root2, sizeof (root2), "certificates.?%u", indx + 1);
|
||||
|
||||
result = asn1_write_value (c2, root2, NULL, 0);
|
||||
result = MHD__asn1_write_value (c2, root2, NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Step 3. Replace the old content with the new
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
|
||||
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -719,8 +719,8 @@ cleanup:
|
||||
*/
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_get_crl_raw - This function returns a crl in a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_get_crl_raw - This function returns a crl in a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
|
||||
* @indx: contains the index of the crl to extract
|
||||
* @crl: the contents of the crl will be copied there (may be null)
|
||||
* @crl_size: should hold the size of the crl
|
||||
@@ -734,13 +734,13 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
|
||||
MHD_gnutls_pkcs7_get_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
int indx, void *crl, size_t * crl_size)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
char root2[MAX_NAME_SIZE];
|
||||
gnutls_datum_t tmp = { NULL, 0 };
|
||||
MHD_gnutls_datum_t tmp = { NULL, 0 };
|
||||
int start, end;
|
||||
|
||||
if (pkcs7 == NULL || crl_size == NULL)
|
||||
@@ -751,7 +751,7 @@ gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
|
||||
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, &tmp);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -762,13 +762,13 @@ gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
|
||||
|
||||
/* Get the raw CRL
|
||||
*/
|
||||
result = asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
|
||||
result = MHD__asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
|
||||
root2, &start, &end);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -789,15 +789,15 @@ gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
|
||||
result = 0;
|
||||
|
||||
cleanup:
|
||||
_gnutls_free_datum (&tmp);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_get_crl_count - This function returns the number of crls in a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_get_crl_count - This function returns the number of crls in a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
|
||||
*
|
||||
* This function will return the number of certifcates in the PKCS7 or
|
||||
* RFC2630 crl set.
|
||||
@@ -806,7 +806,7 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7)
|
||||
MHD_gnutls_pkcs7_get_crl_count (MHD_gnutls_pkcs7_t pkcs7)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result, count;
|
||||
@@ -819,19 +819,19 @@ gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7)
|
||||
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Step 2. Count the CertificateSet */
|
||||
|
||||
result = asn1_number_of_elements (c2, "crls", &count);
|
||||
result = MHD__asn1_number_of_elements (c2, "crls", &count);
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return 0; /* no crls */
|
||||
}
|
||||
|
||||
@@ -840,8 +840,8 @@ gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_set_crl_raw - This function adds a crl in a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_set_crl_raw - This function adds a crl in a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
|
||||
* @crl: the DER encoded crl to be added
|
||||
*
|
||||
* This function will add a crl to the PKCS7 or RFC2630 crl set.
|
||||
@@ -849,7 +849,7 @@ gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crl)
|
||||
MHD_gnutls_pkcs7_set_crl_raw (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * crl)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
@@ -862,7 +862,7 @@ gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crl)
|
||||
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
|
||||
if (result < 0 && result != GNUTLS_E_ASN1_VALUE_NOT_FOUND)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -877,7 +877,7 @@ gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crl)
|
||||
result = create_empty_signed_data (pkcs7->pkcs7, &c2);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
}
|
||||
@@ -885,45 +885,45 @@ gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7, const gnutls_datum_t * crl)
|
||||
/* Step 2. Append the new crl.
|
||||
*/
|
||||
|
||||
result = asn1_write_value (c2, "crls", "NEW", 1);
|
||||
result = MHD__asn1_write_value (c2, "crls", "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_write_value (c2, "crls.?LAST", crl->data, crl->size);
|
||||
result = MHD__asn1_write_value (c2, "crls.?LAST", crl->data, crl->size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Step 3. Replace the old content with the new
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
|
||||
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_set_crl - This function adds a parsed crl in a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_set_crl - This function adds a parsed crl in a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
|
||||
* @crl: the DER encoded crl to be added
|
||||
*
|
||||
* This function will add a parsed crl to the PKCS7 or RFC2630 crl set.
|
||||
@@ -931,28 +931,28 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_set_crl (gnutls_pkcs7_t pkcs7, gnutls_x509_crl_t crl)
|
||||
MHD_gnutls_pkcs7_set_crl (MHD_gnutls_pkcs7_t pkcs7, MHD_gnutls_x509_crl_t crl)
|
||||
{
|
||||
int ret;
|
||||
gnutls_datum_t data;
|
||||
MHD_gnutls_datum_t data;
|
||||
|
||||
if (pkcs7 == NULL)
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
|
||||
ret = _gnutls_x509_der_encode (crl->crl, "", &data, 0);
|
||||
ret = MHD__gnutls_x509_der_encode (crl->crl, "", &data, 0);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = gnutls_pkcs7_set_crl_raw (pkcs7, &data);
|
||||
ret = MHD_gnutls_pkcs7_set_crl_raw (pkcs7, &data);
|
||||
|
||||
_gnutls_free_datum (&data);
|
||||
MHD__gnutls_free_datum (&data);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -960,8 +960,8 @@ gnutls_pkcs7_set_crl (gnutls_pkcs7_t pkcs7, gnutls_x509_crl_t crl)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_pkcs7_delete_crl - This function deletes a crl from a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a gnutls_pkcs7_t structure
|
||||
* MHD_gnutls_pkcs7_delete_crl - This function deletes a crl from a PKCS7 crl set
|
||||
* @pkcs7_struct: should contain a MHD_gnutls_pkcs7_t structure
|
||||
* @indx: the index of the crl to delete
|
||||
*
|
||||
* This function will delete a crl from a PKCS7 or RFC2630 crl set.
|
||||
@@ -969,7 +969,7 @@ gnutls_pkcs7_set_crl (gnutls_pkcs7_t pkcs7, gnutls_x509_crl_t crl)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_pkcs7_delete_crl (gnutls_pkcs7_t pkcs7, int indx)
|
||||
MHD_gnutls_pkcs7_delete_crl (MHD_gnutls_pkcs7_t pkcs7, int indx)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
@@ -983,7 +983,7 @@ gnutls_pkcs7_delete_crl (gnutls_pkcs7_t pkcs7, int indx)
|
||||
result = _decode_pkcs7_signed_data (pkcs7->pkcs7, &c2, NULL);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -992,31 +992,31 @@ gnutls_pkcs7_delete_crl (gnutls_pkcs7_t pkcs7, int indx)
|
||||
|
||||
snprintf (root2, sizeof (root2), "crls.?%u", indx + 1);
|
||||
|
||||
result = asn1_write_value (c2, root2, NULL, 0);
|
||||
result = MHD__asn1_write_value (c2, root2, NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Step 3. Replace the old content with the new
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
|
||||
MHD__gnutls_x509_der_encode_and_copy (c2, "", pkcs7->pkcs7, "content", 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:
|
||||
if (c2)
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
@@ -24,7 +24,7 @@
|
||||
|
||||
#include "x509.h"
|
||||
|
||||
typedef struct gnutls_pkcs7_int
|
||||
typedef struct MHD_gnutls_pkcs7_int
|
||||
{
|
||||
ASN1_TYPE pkcs7;
|
||||
} gnutls_pkcs7_int;
|
||||
} MHD_gnutls_pkcs7_int;
|
||||
@@ -24,8 +24,8 @@
|
||||
|
||||
#include "x509.h"
|
||||
|
||||
ASN1_TYPE _gnutls_privkey_decode_pkcs1_rsa_key (const gnutls_datum_t *
|
||||
ASN1_TYPE MHD__gnutls_privkey_decode_pkcs1_rsa_key (const MHD_gnutls_datum_t *
|
||||
raw_key,
|
||||
gnutls_x509_privkey_t pkey);
|
||||
MHD_gnutls_x509_privkey_t pkey);
|
||||
|
||||
int _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
|
||||
int MHD__gnutlsMHD__asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
|
||||
@@ -71,31 +71,31 @@ struct pbe_enc_params
|
||||
static int generate_key (schema_id schema, const char *password,
|
||||
struct pbkdf2_params *kdf_params,
|
||||
struct pbe_enc_params *enc_params,
|
||||
gnutls_datum_t * key);
|
||||
MHD_gnutls_datum_t * key);
|
||||
static int read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
const gnutls_datum_t * der,
|
||||
const MHD_gnutls_datum_t * der,
|
||||
struct pbkdf2_params *params);
|
||||
static int read_pbe_enc_params (ASN1_TYPE pbes2_asn,
|
||||
const gnutls_datum_t * der,
|
||||
const MHD_gnutls_datum_t * der,
|
||||
struct pbe_enc_params *params);
|
||||
static int decrypt_data (schema_id, ASN1_TYPE pkcs8_asn, const char *root,
|
||||
const char *password,
|
||||
const struct pbkdf2_params *kdf_params,
|
||||
const struct pbe_enc_params *enc_params,
|
||||
gnutls_datum_t * decrypted_data);
|
||||
static int decode_private_key_info (const gnutls_datum_t * der,
|
||||
gnutls_x509_privkey_t pkey);
|
||||
MHD_gnutls_datum_t * decrypted_data);
|
||||
static int decode_private_key_info (const MHD_gnutls_datum_t * der,
|
||||
MHD_gnutls_x509_privkey_t pkey);
|
||||
static int write_schema_params (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
const char *where,
|
||||
const struct pbkdf2_params *kdf_params,
|
||||
const struct pbe_enc_params *enc_params);
|
||||
static int encrypt_data (const gnutls_datum_t * plain,
|
||||
static int encrypt_data (const MHD_gnutls_datum_t * plain,
|
||||
const struct pbe_enc_params *enc_params,
|
||||
gnutls_datum_t * key, gnutls_datum_t * encrypted);
|
||||
MHD_gnutls_datum_t * key, MHD_gnutls_datum_t * encrypted);
|
||||
|
||||
static int read_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
|
||||
static int readMHD_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
|
||||
struct pbkdf2_params *params);
|
||||
static int write_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
|
||||
static int writeMHD_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
|
||||
const struct pbkdf2_params *params);
|
||||
|
||||
#define PEM_PKCS8 "ENCRYPTED PRIVATE KEY"
|
||||
@@ -120,7 +120,7 @@ check_schema (const char *oid)
|
||||
if (strcmp (oid, PKCS12_PBE_RC2_40_SHA1_OID) == 0)
|
||||
return PKCS12_RC2_40_SHA1;
|
||||
|
||||
_gnutls_x509_log ("PKCS encryption schema OID '%s' is unsupported.\n", oid);
|
||||
MHD__gnutls_x509_log ("PKCS encryption schema OID '%s' is unsupported.\n", oid);
|
||||
|
||||
return GNUTLS_E_UNKNOWN_CIPHER_TYPE;
|
||||
}
|
||||
@@ -136,7 +136,7 @@ read_pkcs_schema_params (schema_id schema, const char *password,
|
||||
{
|
||||
ASN1_TYPE pbes2_asn = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
gnutls_datum_t tmp;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
|
||||
switch (schema)
|
||||
{
|
||||
@@ -147,22 +147,22 @@ read_pkcs_schema_params (schema_id schema, const char *password,
|
||||
* functions.
|
||||
*/
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-5-PBES2-params",
|
||||
&pbes2_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
/* Decode the parameters.
|
||||
*/
|
||||
result = asn1_der_decoding (&pbes2_asn, data, data_size, NULL);
|
||||
result = MHD__asn1_der_decoding (&pbes2_asn, data, data_size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -172,20 +172,20 @@ read_pkcs_schema_params (schema_id schema, const char *password,
|
||||
result = read_pbkdf2_params (pbes2_asn, &tmp, kdf_params);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = read_pbe_enc_params (pbes2_asn, &tmp, enc_params);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&pbes2_asn);
|
||||
MHD__asn1_delete_structure (&pbes2_asn);
|
||||
return 0;
|
||||
break;
|
||||
|
||||
@@ -210,48 +210,48 @@ read_pkcs_schema_params (schema_id schema, const char *password,
|
||||
}
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-12-PbeParams",
|
||||
&pbes2_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
/* Decode the parameters.
|
||||
*/
|
||||
result = asn1_der_decoding (&pbes2_asn, data, data_size, NULL);
|
||||
result = MHD__asn1_der_decoding (&pbes2_asn, data, data_size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = read_pkcs12_kdf_params (pbes2_asn, kdf_params);
|
||||
result = readMHD_pkcs12_kdf_params (pbes2_asn, kdf_params);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if (enc_params->iv_size)
|
||||
{
|
||||
result =
|
||||
_pkcs12_string_to_key (2 /*IV*/, kdf_params->salt,
|
||||
MHD_pkcs12_string_to_key (2 /*IV*/, kdf_params->salt,
|
||||
kdf_params->salt_size,
|
||||
kdf_params->iter_count, password,
|
||||
enc_params->iv_size, enc_params->iv);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
asn1_delete_structure (&pbes2_asn);
|
||||
MHD__asn1_delete_structure (&pbes2_asn);
|
||||
|
||||
return 0;
|
||||
break;
|
||||
@@ -261,21 +261,21 @@ read_pkcs_schema_params (schema_id schema, const char *password,
|
||||
return GNUTLS_E_UNKNOWN_CIPHER_TYPE;
|
||||
|
||||
error:
|
||||
asn1_delete_structure (&pbes2_asn);
|
||||
MHD__asn1_delete_structure (&pbes2_asn);
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Converts a PKCS #8 key to
|
||||
* an internal structure (gnutls_private_key)
|
||||
* an internal structure (MHD_gnutls_private_key)
|
||||
* (normally a PKCS #1 encoded RSA key)
|
||||
*/
|
||||
static int
|
||||
decode_pkcs8_key (const gnutls_datum_t * raw_key,
|
||||
const char *password, gnutls_x509_privkey_t pkey)
|
||||
decode_pkcs8_key (const MHD_gnutls_datum_t * raw_key,
|
||||
const char *password, MHD_gnutls_x509_privkey_t pkey)
|
||||
{
|
||||
int result, len;
|
||||
char enc_oid[64];
|
||||
gnutls_datum_t tmp;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
ASN1_TYPE pbes2_asn = ASN1_TYPE_EMPTY, pkcs8_asn = ASN1_TYPE_EMPTY;
|
||||
int params_start, params_end, params_len;
|
||||
struct pbkdf2_params kdf_params;
|
||||
@@ -283,20 +283,20 @@ decode_pkcs8_key (const gnutls_datum_t * raw_key,
|
||||
schema_id schema;
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-8-EncryptedPrivateKeyInfo",
|
||||
&pkcs8_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&pkcs8_asn, raw_key->data, raw_key->size, NULL);
|
||||
result = MHD__asn1_der_decoding (&pkcs8_asn, raw_key->data, raw_key->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -304,17 +304,17 @@ decode_pkcs8_key (const gnutls_datum_t * raw_key,
|
||||
*/
|
||||
len = sizeof (enc_oid);
|
||||
result =
|
||||
asn1_read_value (pkcs8_asn, "encryptionAlgorithm.algorithm",
|
||||
MHD__asn1_read_value (pkcs8_asn, "encryptionAlgorithm.algorithm",
|
||||
enc_oid, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = check_schema (enc_oid)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -323,14 +323,14 @@ decode_pkcs8_key (const gnutls_datum_t * raw_key,
|
||||
/* Get the DER encoding of the parameters.
|
||||
*/
|
||||
result =
|
||||
asn1_der_decoding_startEnd (pkcs8_asn, raw_key->data,
|
||||
MHD__asn1_der_decoding_startEnd (pkcs8_asn, raw_key->data,
|
||||
raw_key->size,
|
||||
"encryptionAlgorithm.parameters",
|
||||
¶ms_start, ¶ms_end);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
params_len = params_end - params_start + 1;
|
||||
@@ -348,14 +348,14 @@ decode_pkcs8_key (const gnutls_datum_t * raw_key,
|
||||
&kdf_params, &enc_params, &tmp);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&pkcs8_asn);
|
||||
MHD__asn1_delete_structure (&pkcs8_asn);
|
||||
|
||||
result = decode_private_key_info (&tmp, pkey);
|
||||
_gnutls_free_datum (&tmp);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -378,106 +378,106 @@ decode_pkcs8_key (const gnutls_datum_t * raw_key,
|
||||
result = GNUTLS_E_DECRYPTION_FAILED;
|
||||
}
|
||||
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
error:
|
||||
asn1_delete_structure (&pbes2_asn);
|
||||
asn1_delete_structure (&pkcs8_asn);
|
||||
MHD__asn1_delete_structure (&pbes2_asn);
|
||||
MHD__asn1_delete_structure (&pkcs8_asn);
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Decodes an RSA privateKey from a PKCS8 structure.
|
||||
*/
|
||||
static int
|
||||
_decode_pkcs8_rsa_key (ASN1_TYPE pkcs8_asn, gnutls_x509_privkey_t pkey)
|
||||
_decode_pkcs8_rsa_key (ASN1_TYPE pkcs8_asn, MHD_gnutls_x509_privkey_t pkey)
|
||||
{
|
||||
int ret;
|
||||
gnutls_datum_t tmp;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
|
||||
ret = _gnutls_x509_read_value (pkcs8_asn, "privateKey", &tmp, 0);
|
||||
ret = MHD__gnutls_x509_read_value (pkcs8_asn, "privateKey", &tmp, 0);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
pkey->key = _gnutls_privkey_decode_pkcs1_rsa_key (&tmp, pkey);
|
||||
_gnutls_free_datum (&tmp);
|
||||
pkey->key = MHD__gnutls_privkey_decode_pkcs1_rsa_key (&tmp, pkey);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
if (pkey->key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
error:
|
||||
gnutls_x509_privkey_deinit (pkey);
|
||||
MHD_gnutls_x509_privkey_deinit (pkey);
|
||||
return ret;
|
||||
}
|
||||
|
||||
/* TODO rm if unsed - we will probable support only RSA certificates */
|
||||
/* Decodes an DSA privateKey and params from a PKCS8 structure.
|
||||
static int
|
||||
_decode_pkcs8_dsa_key (ASN1_TYPE pkcs8_asn, gnutls_x509_privkey pkey)
|
||||
_decode_pkcs8_dsa_key (ASN1_TYPE pkcs8_asn, MHD_gnutls_x509_privkey pkey)
|
||||
{
|
||||
int ret;
|
||||
gnutls_datum tmp;
|
||||
MHD_gnutls_datum tmp;
|
||||
|
||||
ret = _gnutls_x509_read_value (pkcs8_asn, "privateKey", &tmp, 0);
|
||||
ret = MHD__gnutls_x509_read_value (pkcs8_asn, "privateKey", &tmp, 0);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_read_der_int (tmp.data, tmp.size, &pkey->params[4]);
|
||||
_gnutls_free_datum (&tmp);
|
||||
ret = MHD__gnutls_x509_read_der_int (tmp.data, tmp.size, &pkey->params[4]);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
ret =
|
||||
_gnutls_x509_read_value (pkcs8_asn, "privateKeyAlgorithm.parameters",
|
||||
MHD__gnutls_x509_read_value (pkcs8_asn, "privateKeyAlgorithm.parameters",
|
||||
&tmp, 0);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_read_dsa_params (tmp.data, tmp.size, pkey->params);
|
||||
_gnutls_free_datum (&tmp);
|
||||
ret = MHD__gnutls_x509_read_dsa_params (tmp.data, tmp.size, pkey->params);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
the public key can be generated as g^x mod p
|
||||
pkey->params[3] = _gnutls_mpi_alloc_like (pkey->params[0]);
|
||||
pkey->params[3] = MHD__gnutls_mpi_alloc_like (pkey->params[0]);
|
||||
if (pkey->params[3] == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
_gnutls_mpi_powm (pkey->params[3], pkey->params[2], pkey->params[4],
|
||||
MHD__gnutls_mpi_powm (pkey->params[3], pkey->params[2], pkey->params[4],
|
||||
pkey->params[0]);
|
||||
|
||||
if (!pkey->crippled)
|
||||
{
|
||||
ret = _gnutls_asn1_encode_dsa (&pkey->key, pkey->params);
|
||||
ret = MHD__gnutlsMHD__asn1_encode_dsa (&pkey->key, pkey->params);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
}
|
||||
@@ -487,34 +487,34 @@ _decode_pkcs8_dsa_key (ASN1_TYPE pkcs8_asn, gnutls_x509_privkey pkey)
|
||||
return 0;
|
||||
|
||||
error:
|
||||
gnutls_x509_privkey_deinit (pkey);
|
||||
MHD_gnutls_x509_privkey_deinit (pkey);
|
||||
return ret;
|
||||
}
|
||||
*/
|
||||
|
||||
static int
|
||||
decode_private_key_info (const gnutls_datum_t * der,
|
||||
gnutls_x509_privkey_t pkey)
|
||||
decode_private_key_info (const MHD_gnutls_datum_t * der,
|
||||
MHD_gnutls_x509_privkey_t pkey)
|
||||
{
|
||||
int result, len;
|
||||
opaque oid[64];
|
||||
ASN1_TYPE pkcs8_asn = ASN1_TYPE_EMPTY;
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-8-PrivateKeyInfo",
|
||||
&pkcs8_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&pkcs8_asn, der->data, der->size, NULL);
|
||||
result = MHD__asn1_der_decoding (&pkcs8_asn, der->data, der->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -522,11 +522,11 @@ decode_private_key_info (const gnutls_datum_t * der,
|
||||
*/
|
||||
len = sizeof (oid);
|
||||
result =
|
||||
asn1_read_value (pkcs8_asn, "privateKeyAlgorithm.algorithm", oid, &len);
|
||||
MHD__asn1_read_value (pkcs8_asn, "privateKeyAlgorithm.algorithm", oid, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -536,8 +536,8 @@ decode_private_key_info (const gnutls_datum_t * der,
|
||||
pkey->pk_algorithm = MHD_GNUTLS_PK_RSA;
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_x509_log
|
||||
("PKCS #8 private key OID '%s' is unsupported.\n", oid);
|
||||
result = GNUTLS_E_UNKNOWN_PK_ALGORITHM;
|
||||
goto error;
|
||||
@@ -550,21 +550,21 @@ decode_private_key_info (const gnutls_datum_t * der,
|
||||
result = _decode_pkcs8_rsa_key (pkcs8_asn, pkey);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
result = 0;
|
||||
|
||||
error:
|
||||
asn1_delete_structure (&pkcs8_asn);
|
||||
MHD__asn1_delete_structure (&pkcs8_asn);
|
||||
|
||||
return result;
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_import_pkcs8 - This function will import a DER or PEM PKCS8 encoded key
|
||||
* MHD_gnutls_x509_privkey_import_pkcs8 - This function will import a DER or PEM PKCS8 encoded key
|
||||
* @key: The structure to store the parsed key
|
||||
* @data: The DER or PEM encoded key.
|
||||
* @format: One of DER or PEM
|
||||
@@ -572,7 +572,7 @@ error:
|
||||
* @flags: 0 if encrypted or GNUTLS_PKCS_PLAIN if not encrypted.
|
||||
*
|
||||
* This function will convert the given DER or PEM encoded PKCS8 2.0 encrypted key
|
||||
* to the native gnutls_x509_privkey_t format. The output will be stored in @key.
|
||||
* to the native MHD_gnutls_x509_privkey_t format. The output will be stored in @key.
|
||||
* Both RSA and DSA keys can be imported, and flags can only be used to indicate
|
||||
* an unencrypted key.
|
||||
*
|
||||
@@ -587,17 +587,17 @@ error:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
MHD_gnutls_x509_privkey_import_pkcs8 (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
const char *password, unsigned int flags)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
gnutls_datum_t _data;
|
||||
MHD_gnutls_datum_t _data;
|
||||
|
||||
if (key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -615,20 +615,20 @@ gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
|
||||
/* Try the first header
|
||||
*/
|
||||
result =
|
||||
_gnutls_fbase64_decode (PEM_UNENCRYPTED_PKCS8,
|
||||
MHD__gnutls_fbase64_decode (PEM_UNENCRYPTED_PKCS8,
|
||||
data->data, data->size, &out);
|
||||
|
||||
if (result < 0)
|
||||
{ /* Try the encrypted header
|
||||
*/
|
||||
result =
|
||||
_gnutls_fbase64_decode (PEM_PKCS8, data->data, data->size, &out);
|
||||
MHD__gnutls_fbase64_decode (PEM_PKCS8, data->data, data->size, &out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
if (result == 0)
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
}
|
||||
@@ -652,12 +652,12 @@ gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
|
||||
/* The key has now been decoded.
|
||||
*/
|
||||
@@ -667,7 +667,7 @@ gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
|
||||
cleanup:
|
||||
key->pk_algorithm = MHD_GNUTLS_PK_UNKNOWN;
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -675,7 +675,7 @@ cleanup:
|
||||
*/
|
||||
static int
|
||||
read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
const gnutls_datum_t * der, struct pbkdf2_params *params)
|
||||
const MHD_gnutls_datum_t * der, struct pbkdf2_params *params)
|
||||
{
|
||||
int params_start, params_end;
|
||||
int params_len, len, result;
|
||||
@@ -688,30 +688,30 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
*/
|
||||
len = sizeof (oid);
|
||||
result =
|
||||
asn1_read_value (pbes2_asn, "keyDerivationFunc.algorithm", oid, &len);
|
||||
MHD__asn1_read_value (pbes2_asn, "keyDerivationFunc.algorithm", oid, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
_gnutls_hard_log ("keyDerivationFunc.algorithm: %s\n", oid);
|
||||
MHD__gnutls_hard_log ("keyDerivationFunc.algorithm: %s\n", oid);
|
||||
|
||||
if (strcmp (oid, PBKDF2_OID) != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_x509_log
|
||||
("PKCS #8 key derivation OID '%s' is unsupported.\n", oid);
|
||||
return mhd_gtls_asn2err (result);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_der_decoding_startEnd (pbes2_asn, der->data, der->size,
|
||||
MHD__asn1_der_decoding_startEnd (pbes2_asn, der->data, der->size,
|
||||
"keyDerivationFunc.parameters",
|
||||
¶ms_start, ¶ms_end);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
params_len = params_end - params_start + 1;
|
||||
|
||||
@@ -719,58 +719,58 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
* functions.
|
||||
*/
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-5-PBKDF2-params",
|
||||
&pbkdf2_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_der_decoding (&pbkdf2_asn, &der->data[params_start],
|
||||
MHD__asn1_der_decoding (&pbkdf2_asn, &der->data[params_start],
|
||||
params_len, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
/* read the salt */
|
||||
params->salt_size = sizeof (params->salt);
|
||||
result =
|
||||
asn1_read_value (pbkdf2_asn, "salt.specified", params->salt,
|
||||
MHD__asn1_read_value (pbkdf2_asn, "salt.specified", params->salt,
|
||||
¶ms->salt_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("salt.specified.size: %d\n", params->salt_size);
|
||||
MHD__gnutls_hard_log ("salt.specified.size: %d\n", params->salt_size);
|
||||
|
||||
/* read the iteration count
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_read_uint (pbkdf2_asn, "iterationCount",
|
||||
MHD__gnutls_x509_read_uint (pbkdf2_asn, "iterationCount",
|
||||
¶ms->iter_count);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("iterationCount: %d\n", params->iter_count);
|
||||
MHD__gnutls_hard_log ("iterationCount: %d\n", params->iter_count);
|
||||
|
||||
/* read the keylength, if it is set.
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_read_uint (pbkdf2_asn, "keyLength", ¶ms->key_size);
|
||||
MHD__gnutls_x509_read_uint (pbkdf2_asn, "keyLength", ¶ms->key_size);
|
||||
if (result < 0)
|
||||
{
|
||||
params->key_size = 0;
|
||||
}
|
||||
_gnutls_hard_log ("keyLength: %d\n", params->key_size);
|
||||
MHD__gnutls_hard_log ("keyLength: %d\n", params->key_size);
|
||||
|
||||
/* We don't read the PRF. We only use the default.
|
||||
*/
|
||||
@@ -778,7 +778,7 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
return 0;
|
||||
|
||||
error:
|
||||
asn1_delete_structure (&pbkdf2_asn);
|
||||
MHD__asn1_delete_structure (&pbkdf2_asn);
|
||||
return result;
|
||||
|
||||
}
|
||||
@@ -786,7 +786,7 @@ error:
|
||||
/* Reads the PBE parameters from PKCS-12 schemas (*&#%*&#% RSA).
|
||||
*/
|
||||
static int
|
||||
read_pkcs12_kdf_params (ASN1_TYPE pbes2_asn, struct pbkdf2_params *params)
|
||||
readMHD_pkcs12_kdf_params (ASN1_TYPE pbes2_asn, struct pbkdf2_params *params)
|
||||
{
|
||||
int result;
|
||||
|
||||
@@ -795,25 +795,25 @@ read_pkcs12_kdf_params (ASN1_TYPE pbes2_asn, struct pbkdf2_params *params)
|
||||
/* read the salt */
|
||||
params->salt_size = sizeof (params->salt);
|
||||
result =
|
||||
asn1_read_value (pbes2_asn, "salt", params->salt, ¶ms->salt_size);
|
||||
MHD__asn1_read_value (pbes2_asn, "salt", params->salt, ¶ms->salt_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("salt.size: %d\n", params->salt_size);
|
||||
MHD__gnutls_hard_log ("salt.size: %d\n", params->salt_size);
|
||||
|
||||
/* read the iteration count
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_read_uint (pbes2_asn, "iterations", ¶ms->iter_count);
|
||||
MHD__gnutls_x509_read_uint (pbes2_asn, "iterations", ¶ms->iter_count);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("iterationCount: %d\n", params->iter_count);
|
||||
MHD__gnutls_hard_log ("iterationCount: %d\n", params->iter_count);
|
||||
|
||||
params->key_size = 0;
|
||||
|
||||
@@ -827,7 +827,7 @@ error:
|
||||
/* Writes the PBE parameters for PKCS-12 schemas.
|
||||
*/
|
||||
static int
|
||||
write_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
|
||||
writeMHD_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
|
||||
const struct pbkdf2_params *kdf_params)
|
||||
{
|
||||
int result;
|
||||
@@ -835,27 +835,27 @@ write_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
|
||||
/* write the salt
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (pbes2_asn, "salt",
|
||||
MHD__asn1_write_value (pbes2_asn, "salt",
|
||||
kdf_params->salt, kdf_params->salt_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("salt.size: %d\n", kdf_params->salt_size);
|
||||
MHD__gnutls_hard_log ("salt.size: %d\n", kdf_params->salt_size);
|
||||
|
||||
/* write the iteration count
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_write_uint32 (pbes2_asn, "iterations",
|
||||
MHD__gnutls_x509_write_uint32 (pbes2_asn, "iterations",
|
||||
kdf_params->iter_count);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("iterationCount: %d\n", kdf_params->iter_count);
|
||||
MHD__gnutls_hard_log ("iterationCount: %d\n", kdf_params->iter_count);
|
||||
|
||||
return 0;
|
||||
|
||||
@@ -884,13 +884,13 @@ oid2cipher (const char *oid, enum MHD_GNUTLS_CipherAlgorithm *algo)
|
||||
return 0;
|
||||
}
|
||||
|
||||
_gnutls_x509_log ("PKCS #8 encryption OID '%s' is unsupported.\n", oid);
|
||||
MHD__gnutls_x509_log ("PKCS #8 encryption OID '%s' is unsupported.\n", oid);
|
||||
return GNUTLS_E_UNKNOWN_CIPHER_TYPE;
|
||||
}
|
||||
|
||||
static int
|
||||
read_pbe_enc_params (ASN1_TYPE pbes2_asn,
|
||||
const gnutls_datum_t * der,
|
||||
const MHD_gnutls_datum_t * der,
|
||||
struct pbe_enc_params *params)
|
||||
{
|
||||
int params_start, params_end;
|
||||
@@ -904,66 +904,66 @@ read_pbe_enc_params (ASN1_TYPE pbes2_asn,
|
||||
*/
|
||||
len = sizeof (oid);
|
||||
result =
|
||||
asn1_read_value (pbes2_asn, "encryptionScheme.algorithm", oid, &len);
|
||||
MHD__asn1_read_value (pbes2_asn, "encryptionScheme.algorithm", oid, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("encryptionScheme.algorithm: %s\n", oid);
|
||||
MHD__gnutls_hard_log ("encryptionScheme.algorithm: %s\n", oid);
|
||||
|
||||
if ((result = oid2cipher (oid, ¶ms->cipher)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_der_decoding_startEnd (pbes2_asn, der->data, der->size,
|
||||
MHD__asn1_der_decoding_startEnd (pbes2_asn, der->data, der->size,
|
||||
"encryptionScheme.parameters",
|
||||
¶ms_start, ¶ms_end);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
params_len = params_end - params_start + 1;
|
||||
|
||||
/* Now check the encryption parameters.
|
||||
*/
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-5-des-EDE3-CBC-params",
|
||||
&pbe_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_der_decoding (&pbe_asn, &der->data[params_start], params_len, NULL);
|
||||
MHD__asn1_der_decoding (&pbe_asn, &der->data[params_start], params_len, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
/* read the IV */
|
||||
params->iv_size = sizeof (params->iv);
|
||||
result = asn1_read_value (pbe_asn, "", params->iv, ¶ms->iv_size);
|
||||
result = MHD__asn1_read_value (pbe_asn, "", params->iv, ¶ms->iv_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("IV.size: %d\n", params->iv_size);
|
||||
MHD__gnutls_hard_log ("IV.size: %d\n", params->iv_size);
|
||||
|
||||
return 0;
|
||||
|
||||
error:
|
||||
asn1_delete_structure (&pbe_asn);
|
||||
MHD__asn1_delete_structure (&pbe_asn);
|
||||
return result;
|
||||
|
||||
}
|
||||
@@ -973,49 +973,49 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
const char *root, const char *password,
|
||||
const struct pbkdf2_params *kdf_params,
|
||||
const struct pbe_enc_params *enc_params,
|
||||
gnutls_datum_t * decrypted_data)
|
||||
MHD_gnutls_datum_t * decrypted_data)
|
||||
{
|
||||
int result;
|
||||
int data_size;
|
||||
opaque *data = NULL, *key = NULL;
|
||||
gnutls_datum_t dkey, d_iv;
|
||||
MHD_gnutls_datum_t dkey, d_iv;
|
||||
cipher_hd_t ch = NULL;
|
||||
int key_size;
|
||||
|
||||
data_size = 0;
|
||||
result = asn1_read_value (pkcs8_asn, root, NULL, &data_size);
|
||||
result = MHD__asn1_read_value (pkcs8_asn, root, NULL, &data_size);
|
||||
if (result != ASN1_MEM_ERROR)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
data = gnutls_malloc (data_size);
|
||||
data = MHD_gnutls_malloc (data_size);
|
||||
if (data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
result = asn1_read_value (pkcs8_asn, root, data, &data_size);
|
||||
result = MHD__asn1_read_value (pkcs8_asn, root, data, &data_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
if (kdf_params->key_size == 0)
|
||||
{
|
||||
key_size = MHD_gnutls_cipher_get_key_size (enc_params->cipher);
|
||||
key_size = MHD__gnutls_cipher_get_key_size (enc_params->cipher);
|
||||
}
|
||||
else
|
||||
key_size = kdf_params->key_size;
|
||||
|
||||
key = gnutls_alloca (key_size);
|
||||
key = MHD_gnutls_alloca (key_size);
|
||||
if (key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto error;
|
||||
}
|
||||
@@ -1024,13 +1024,13 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
*/
|
||||
if (schema == PBES2)
|
||||
{
|
||||
result = gc_pbkdf2_sha1 (password, strlen (password),
|
||||
result = MHD_gc_pbkdf2_sha1 (password, strlen (password),
|
||||
kdf_params->salt, kdf_params->salt_size,
|
||||
kdf_params->iter_count, key, key_size);
|
||||
|
||||
if (result != GC_OK)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_DECRYPTION_FAILED;
|
||||
goto error;
|
||||
}
|
||||
@@ -1038,14 +1038,14 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
else
|
||||
{
|
||||
result =
|
||||
_pkcs12_string_to_key (1 /*KEY*/, kdf_params->salt,
|
||||
MHD_pkcs12_string_to_key (1 /*KEY*/, kdf_params->salt,
|
||||
kdf_params->salt_size,
|
||||
kdf_params->iter_count, password,
|
||||
key_size, key);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
}
|
||||
@@ -1057,41 +1057,41 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
|
||||
d_iv.data = (opaque *) enc_params->iv;
|
||||
d_iv.size = enc_params->iv_size;
|
||||
ch = mhd_gtls_cipher_init (enc_params->cipher, &dkey, &d_iv);
|
||||
ch = MHD_gtls_cipher_init (enc_params->cipher, &dkey, &d_iv);
|
||||
|
||||
gnutls_afree (key);
|
||||
MHD_gnutls_afree (key);
|
||||
key = NULL;
|
||||
|
||||
if (ch == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_DECRYPTION_FAILED;
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = mhd_gtls_cipher_decrypt (ch, data, data_size);
|
||||
result = MHD_gtls_cipher_decrypt (ch, data, data_size);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
decrypted_data->data = data;
|
||||
|
||||
if (mhd_gtls_cipher_get_block_size (enc_params->cipher) != 1)
|
||||
if (MHD_gtls_cipher_get_block_size (enc_params->cipher) != 1)
|
||||
decrypted_data->size = data_size - data[data_size - 1];
|
||||
else
|
||||
decrypted_data->size = data_size;
|
||||
|
||||
mhd_gnutls_cipher_deinit (ch);
|
||||
MHD_gnutls_cipher_deinit (ch);
|
||||
|
||||
return 0;
|
||||
|
||||
error:
|
||||
gnutls_free (data);
|
||||
gnutls_afree (key);
|
||||
MHD_gnutls_free (data);
|
||||
MHD_gnutls_afree (key);
|
||||
if (ch != NULL)
|
||||
mhd_gnutls_cipher_deinit (ch);
|
||||
MHD_gnutls_cipher_deinit (ch);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -1108,97 +1108,97 @@ write_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
/* Write the key derivation algorithm
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (pbes2_asn, "keyDerivationFunc.algorithm",
|
||||
MHD__asn1_write_value (pbes2_asn, "keyDerivationFunc.algorithm",
|
||||
PBKDF2_OID, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Now write the key derivation and the encryption
|
||||
* functions.
|
||||
*/
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-5-PBKDF2-params",
|
||||
&pbkdf2_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_write_value (pbkdf2_asn, "salt", "specified", 1);
|
||||
result = MHD__asn1_write_value (pbkdf2_asn, "salt", "specified", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
/* write the salt
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (pbkdf2_asn, "salt.specified",
|
||||
MHD__asn1_write_value (pbkdf2_asn, "salt.specified",
|
||||
kdf_params->salt, kdf_params->salt_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("salt.specified.size: %d\n", kdf_params->salt_size);
|
||||
MHD__gnutls_hard_log ("salt.specified.size: %d\n", kdf_params->salt_size);
|
||||
|
||||
/* write the iteration count
|
||||
*/
|
||||
mhd_gtls_write_uint32 (kdf_params->iter_count, tmp);
|
||||
MHD_gtls_write_uint32 (kdf_params->iter_count, tmp);
|
||||
|
||||
result = asn1_write_value (pbkdf2_asn, "iterationCount", tmp, 4);
|
||||
result = MHD__asn1_write_value (pbkdf2_asn, "iterationCount", tmp, 4);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("iterationCount: %d\n", kdf_params->iter_count);
|
||||
MHD__gnutls_hard_log ("iterationCount: %d\n", kdf_params->iter_count);
|
||||
|
||||
/* write the keylength, if it is set.
|
||||
*/
|
||||
result = asn1_write_value (pbkdf2_asn, "keyLength", NULL, 0);
|
||||
result = MHD__asn1_write_value (pbkdf2_asn, "keyLength", NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
/* We write an emptry prf.
|
||||
*/
|
||||
result = asn1_write_value (pbkdf2_asn, "prf", NULL, 0);
|
||||
result = MHD__asn1_write_value (pbkdf2_asn, "prf", NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
/* now encode them an put the DER output
|
||||
* in the keyDerivationFunc.parameters
|
||||
*/
|
||||
result = _gnutls_x509_der_encode_and_copy (pbkdf2_asn, "",
|
||||
result = MHD__gnutls_x509_der_encode_and_copy (pbkdf2_asn, "",
|
||||
pbes2_asn,
|
||||
"keyDerivationFunc.parameters",
|
||||
0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
error:
|
||||
asn1_delete_structure (&pbkdf2_asn);
|
||||
MHD__asn1_delete_structure (&pbkdf2_asn);
|
||||
return result;
|
||||
|
||||
}
|
||||
@@ -1213,53 +1213,53 @@ write_pbe_enc_params (ASN1_TYPE pbes2_asn,
|
||||
/* Write the encryption algorithm
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (pbes2_asn, "encryptionScheme.algorithm",
|
||||
MHD__asn1_write_value (pbes2_asn, "encryptionScheme.algorithm",
|
||||
DES_EDE3_CBC_OID, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("encryptionScheme.algorithm: %s\n", DES_EDE3_CBC_OID);
|
||||
MHD__gnutls_hard_log ("encryptionScheme.algorithm: %s\n", DES_EDE3_CBC_OID);
|
||||
|
||||
/* Now check the encryption parameters.
|
||||
*/
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-5-des-EDE3-CBC-params",
|
||||
&pbe_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* read the salt */
|
||||
result = asn1_write_value (pbe_asn, "", params->iv, params->iv_size);
|
||||
result = MHD__asn1_write_value (pbe_asn, "", params->iv, params->iv_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
_gnutls_hard_log ("IV.size: %d\n", params->iv_size);
|
||||
MHD__gnutls_hard_log ("IV.size: %d\n", params->iv_size);
|
||||
|
||||
/* now encode them an put the DER output
|
||||
* in the encryptionScheme.parameters
|
||||
*/
|
||||
result = _gnutls_x509_der_encode_and_copy (pbe_asn, "",
|
||||
result = MHD__gnutls_x509_der_encode_and_copy (pbe_asn, "",
|
||||
pbes2_asn,
|
||||
"encryptionScheme.parameters",
|
||||
0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
error:
|
||||
asn1_delete_structure (&pbe_asn);
|
||||
MHD__asn1_delete_structure (&pbe_asn);
|
||||
return result;
|
||||
|
||||
}
|
||||
@@ -1270,7 +1270,7 @@ static int
|
||||
generate_key (schema_id schema,
|
||||
const char *password,
|
||||
struct pbkdf2_params *kdf_params,
|
||||
struct pbe_enc_params *enc_params, gnutls_datum_t * key)
|
||||
struct pbe_enc_params *enc_params, MHD_gnutls_datum_t * key)
|
||||
{
|
||||
opaque rnd[2];
|
||||
int ret;
|
||||
@@ -1286,9 +1286,9 @@ generate_key (schema_id schema,
|
||||
else if (schema == PKCS12_RC2_40_SHA1)
|
||||
enc_params->cipher = MHD_GNUTLS_CIPHER_RC2_40_CBC;
|
||||
|
||||
if (gc_pseudo_random (rnd, 2) != GC_OK)
|
||||
if (MHD_gc_pseudo_random (rnd, 2) != GC_OK)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_RANDOM_FAILED;
|
||||
}
|
||||
|
||||
@@ -1302,22 +1302,22 @@ generate_key (schema_id schema,
|
||||
else
|
||||
kdf_params->salt_size = 8;
|
||||
|
||||
if (gc_pseudo_random (kdf_params->salt, kdf_params->salt_size) != GC_OK)
|
||||
if (MHD_gc_pseudo_random (kdf_params->salt, kdf_params->salt_size) != GC_OK)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_RANDOM_FAILED;
|
||||
}
|
||||
|
||||
kdf_params->iter_count = 256 + rnd[0];
|
||||
key->size = kdf_params->key_size =
|
||||
MHD_gnutls_cipher_get_key_size (enc_params->cipher);
|
||||
MHD__gnutls_cipher_get_key_size (enc_params->cipher);
|
||||
|
||||
enc_params->iv_size = mhd_gtls_cipher_get_iv_size (enc_params->cipher);
|
||||
enc_params->iv_size = MHD_gtls_cipher_get_iv_size (enc_params->cipher);
|
||||
|
||||
key->data = gnutls_secure_malloc (key->size);
|
||||
key->data = MHD_gnutls_secure_malloc (key->size);
|
||||
if (key->data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
@@ -1327,33 +1327,33 @@ generate_key (schema_id schema,
|
||||
if (schema == PBES2)
|
||||
{
|
||||
|
||||
ret = gc_pbkdf2_sha1 (password, strlen (password),
|
||||
ret = MHD_gc_pbkdf2_sha1 (password, strlen (password),
|
||||
kdf_params->salt, kdf_params->salt_size,
|
||||
kdf_params->iter_count,
|
||||
key->data, kdf_params->key_size);
|
||||
if (ret != GC_OK)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_ENCRYPTION_FAILED;
|
||||
}
|
||||
|
||||
if (enc_params->iv_size &&
|
||||
gc_nonce (enc_params->iv, enc_params->iv_size) != GC_OK)
|
||||
MHD_gc_nonce (enc_params->iv, enc_params->iv_size) != GC_OK)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_RANDOM_FAILED;
|
||||
}
|
||||
}
|
||||
else
|
||||
{ /* PKCS12 schemas */
|
||||
ret =
|
||||
_pkcs12_string_to_key (1 /*KEY*/, kdf_params->salt,
|
||||
MHD_pkcs12_string_to_key (1 /*KEY*/, kdf_params->salt,
|
||||
kdf_params->salt_size,
|
||||
kdf_params->iter_count, password,
|
||||
kdf_params->key_size, key->data);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -1362,13 +1362,13 @@ generate_key (schema_id schema,
|
||||
if (enc_params->iv_size)
|
||||
{
|
||||
ret =
|
||||
_pkcs12_string_to_key (2 /*IV*/, kdf_params->salt,
|
||||
MHD_pkcs12_string_to_key (2 /*IV*/, kdf_params->salt,
|
||||
kdf_params->salt_size,
|
||||
kdf_params->iter_count, password,
|
||||
enc_params->iv_size, enc_params->iv);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
}
|
||||
@@ -1392,99 +1392,99 @@ write_schema_params (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
if (schema == PBES2)
|
||||
{
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-5-PBES2-params",
|
||||
&pbes2_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = write_pbkdf2_params (pbes2_asn, kdf_params);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = write_pbe_enc_params (pbes2_asn, enc_params);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode_and_copy (pbes2_asn, "",
|
||||
result = MHD__gnutls_x509_der_encode_and_copy (pbes2_asn, "",
|
||||
pkcs8_asn, where, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&pbes2_asn);
|
||||
MHD__asn1_delete_structure (&pbes2_asn);
|
||||
}
|
||||
else
|
||||
{ /* PKCS12 schemas */
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-12-PbeParams",
|
||||
&pbes2_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = write_pkcs12_kdf_params (pbes2_asn, kdf_params);
|
||||
result = writeMHD_pkcs12_kdf_params (pbes2_asn, kdf_params);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_der_encode_and_copy (pbes2_asn, "",
|
||||
result = MHD__gnutls_x509_der_encode_and_copy (pbes2_asn, "",
|
||||
pkcs8_asn, where, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&pbes2_asn);
|
||||
MHD__asn1_delete_structure (&pbes2_asn);
|
||||
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
error:
|
||||
asn1_delete_structure (&pbes2_asn);
|
||||
MHD__asn1_delete_structure (&pbes2_asn);
|
||||
return result;
|
||||
|
||||
}
|
||||
|
||||
static int
|
||||
encrypt_data (const gnutls_datum_t * plain,
|
||||
encrypt_data (const MHD_gnutls_datum_t * plain,
|
||||
const struct pbe_enc_params *enc_params,
|
||||
gnutls_datum_t * key, gnutls_datum_t * encrypted)
|
||||
MHD_gnutls_datum_t * key, MHD_gnutls_datum_t * encrypted)
|
||||
{
|
||||
int result;
|
||||
int data_size;
|
||||
opaque *data = NULL;
|
||||
gnutls_datum_t d_iv;
|
||||
MHD_gnutls_datum_t d_iv;
|
||||
cipher_hd_t ch = NULL;
|
||||
opaque pad, pad_size;
|
||||
|
||||
pad_size = mhd_gtls_cipher_get_block_size (enc_params->cipher);
|
||||
pad_size = MHD_gtls_cipher_get_block_size (enc_params->cipher);
|
||||
|
||||
if (pad_size == 1) /* stream */
|
||||
pad_size = 0;
|
||||
|
||||
data = gnutls_malloc (plain->size + pad_size);
|
||||
data = MHD_gnutls_malloc (plain->size + pad_size);
|
||||
if (data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
@@ -1504,33 +1504,33 @@ encrypt_data (const gnutls_datum_t * plain,
|
||||
|
||||
d_iv.data = (opaque *) enc_params->iv;
|
||||
d_iv.size = enc_params->iv_size;
|
||||
ch = mhd_gtls_cipher_init (enc_params->cipher, key, &d_iv);
|
||||
ch = MHD_gtls_cipher_init (enc_params->cipher, key, &d_iv);
|
||||
|
||||
if (ch == GNUTLS_CIPHER_FAILED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_ENCRYPTION_FAILED;
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = mhd_gtls_cipher_encrypt (ch, data, data_size);
|
||||
result = MHD_gtls_cipher_encrypt (ch, data, data_size);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
encrypted->data = data;
|
||||
encrypted->size = data_size;
|
||||
|
||||
mhd_gnutls_cipher_deinit (ch);
|
||||
MHD_gnutls_cipher_deinit (ch);
|
||||
|
||||
return 0;
|
||||
|
||||
error:
|
||||
gnutls_free (data);
|
||||
MHD_gnutls_free (data);
|
||||
if (ch != NULL)
|
||||
mhd_gnutls_cipher_deinit (ch);
|
||||
MHD_gnutls_cipher_deinit (ch);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -1538,12 +1538,12 @@ error:
|
||||
* and stored in dec.
|
||||
*/
|
||||
int
|
||||
_gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
|
||||
const char *password, gnutls_datum_t * dec)
|
||||
MHD__gnutls_pkcs7_decrypt_data (const MHD_gnutls_datum_t * data,
|
||||
const char *password, MHD_gnutls_datum_t * dec)
|
||||
{
|
||||
int result, len;
|
||||
char enc_oid[64];
|
||||
gnutls_datum_t tmp;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
ASN1_TYPE pbes2_asn = ASN1_TYPE_EMPTY, pkcs7_asn = ASN1_TYPE_EMPTY;
|
||||
int params_start, params_end, params_len;
|
||||
struct pbkdf2_params kdf_params;
|
||||
@@ -1551,20 +1551,20 @@ _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
|
||||
schema_id schema;
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-7-EncryptedData",
|
||||
&pkcs7_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&pkcs7_asn, data->data, data->size, NULL);
|
||||
result = MHD__asn1_der_decoding (&pkcs7_asn, data->data, data->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -1572,19 +1572,19 @@ _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
|
||||
*/
|
||||
len = sizeof (enc_oid);
|
||||
result =
|
||||
asn1_read_value (pkcs7_asn,
|
||||
MHD__asn1_read_value (pkcs7_asn,
|
||||
"encryptedContentInfo.contentEncryptionAlgorithm.algorithm",
|
||||
enc_oid, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = check_schema (enc_oid)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
schema = result;
|
||||
@@ -1592,13 +1592,13 @@ _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
|
||||
/* Get the DER encoding of the parameters.
|
||||
*/
|
||||
result =
|
||||
asn1_der_decoding_startEnd (pkcs7_asn, data->data, data->size,
|
||||
MHD__asn1_der_decoding_startEnd (pkcs7_asn, data->data, data->size,
|
||||
"encryptedContentInfo.contentEncryptionAlgorithm.parameters",
|
||||
¶ms_start, ¶ms_end);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
params_len = params_end - params_start + 1;
|
||||
@@ -1609,8 +1609,8 @@ _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
|
||||
params_len, &kdf_params, &enc_params);
|
||||
if (result < ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -1624,19 +1624,19 @@ _gnutls_pkcs7_decrypt_data (const gnutls_datum_t * data,
|
||||
&kdf_params, &enc_params, &tmp);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
asn1_delete_structure (&pkcs7_asn);
|
||||
MHD__asn1_delete_structure (&pkcs7_asn);
|
||||
|
||||
*dec = tmp;
|
||||
|
||||
return 0;
|
||||
|
||||
error:
|
||||
asn1_delete_structure (&pbes2_asn);
|
||||
asn1_delete_structure (&pkcs7_asn);
|
||||
MHD__asn1_delete_structure (&pbes2_asn);
|
||||
MHD__asn1_delete_structure (&pkcs7_asn);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -1644,24 +1644,24 @@ error:
|
||||
* and stored in enc.
|
||||
*/
|
||||
int
|
||||
_gnutls_pkcs7_encrypt_data (schema_id schema,
|
||||
const gnutls_datum_t * data,
|
||||
const char *password, gnutls_datum_t * enc)
|
||||
MHD__gnutls_pkcs7_encrypt_data (schema_id schema,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
const char *password, MHD_gnutls_datum_t * enc)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t key = { NULL, 0 };
|
||||
gnutls_datum_t tmp = { NULL, 0 };
|
||||
MHD_gnutls_datum_t key = { NULL, 0 };
|
||||
MHD_gnutls_datum_t tmp = { NULL, 0 };
|
||||
ASN1_TYPE pkcs7_asn = ASN1_TYPE_EMPTY;
|
||||
struct pbkdf2_params kdf_params;
|
||||
struct pbe_enc_params enc_params;
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (),
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-7-EncryptedData",
|
||||
&pkcs7_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -1671,25 +1671,25 @@ _gnutls_pkcs7_encrypt_data (schema_id schema,
|
||||
{
|
||||
case PBES2:
|
||||
result =
|
||||
asn1_write_value (pkcs7_asn,
|
||||
MHD__asn1_write_value (pkcs7_asn,
|
||||
"encryptedContentInfo.contentEncryptionAlgorithm.algorithm",
|
||||
PBES2_OID, 1);
|
||||
break;
|
||||
case PKCS12_3DES_SHA1:
|
||||
result =
|
||||
asn1_write_value (pkcs7_asn,
|
||||
MHD__asn1_write_value (pkcs7_asn,
|
||||
"encryptedContentInfo.contentEncryptionAlgorithm.algorithm",
|
||||
PKCS12_PBE_3DES_SHA1_OID, 1);
|
||||
break;
|
||||
case PKCS12_ARCFOUR_SHA1:
|
||||
result =
|
||||
asn1_write_value (pkcs7_asn,
|
||||
MHD__asn1_write_value (pkcs7_asn,
|
||||
"encryptedContentInfo.contentEncryptionAlgorithm.algorithm",
|
||||
PKCS12_PBE_ARCFOUR_SHA1_OID, 1);
|
||||
break;
|
||||
case PKCS12_RC2_40_SHA1:
|
||||
result =
|
||||
asn1_write_value (pkcs7_asn,
|
||||
MHD__asn1_write_value (pkcs7_asn,
|
||||
"encryptedContentInfo.contentEncryptionAlgorithm.algorithm",
|
||||
PKCS12_PBE_RC2_40_SHA1_OID, 1);
|
||||
break;
|
||||
@@ -1698,8 +1698,8 @@ _gnutls_pkcs7_encrypt_data (schema_id schema,
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -1709,7 +1709,7 @@ _gnutls_pkcs7_encrypt_data (schema_id schema,
|
||||
result = generate_key (schema, password, &kdf_params, &enc_params, &key);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -1718,7 +1718,7 @@ _gnutls_pkcs7_encrypt_data (schema_id schema,
|
||||
&kdf_params, &enc_params);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -1728,70 +1728,70 @@ _gnutls_pkcs7_encrypt_data (schema_id schema,
|
||||
result = encrypt_data (data, &enc_params, &key, &tmp);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
/* write the encrypted data.
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (pkcs7_asn,
|
||||
MHD__asn1_write_value (pkcs7_asn,
|
||||
"encryptedContentInfo.encryptedContent", tmp.data,
|
||||
tmp.size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
_gnutls_free_datum (&tmp);
|
||||
_gnutls_free_datum (&key);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
MHD__gnutls_free_datum (&key);
|
||||
|
||||
/* Now write the rest of the pkcs-7 stuff.
|
||||
*/
|
||||
|
||||
result = _gnutls_x509_write_uint32 (pkcs7_asn, "version", 0);
|
||||
result = MHD__gnutls_x509_write_uint32 (pkcs7_asn, "version", 0);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_write_value (pkcs7_asn, "encryptedContentInfo.contentType",
|
||||
MHD__asn1_write_value (pkcs7_asn, "encryptedContentInfo.contentType",
|
||||
DATA_OID, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = asn1_write_value (pkcs7_asn, "unprotectedAttrs", NULL, 0);
|
||||
result = MHD__asn1_write_value (pkcs7_asn, "unprotectedAttrs", NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
/* Now encode and copy the DER stuff.
|
||||
*/
|
||||
result = _gnutls_x509_der_encode (pkcs7_asn, "", enc, 0);
|
||||
result = MHD__gnutls_x509_der_encode (pkcs7_asn, "", enc, 0);
|
||||
|
||||
asn1_delete_structure (&pkcs7_asn);
|
||||
MHD__asn1_delete_structure (&pkcs7_asn);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
error:
|
||||
_gnutls_free_datum (&key);
|
||||
_gnutls_free_datum (&tmp);
|
||||
asn1_delete_structure (&pkcs7_asn);
|
||||
MHD__gnutls_free_datum (&key);
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
MHD__asn1_delete_structure (&pkcs7_asn);
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
@@ -22,5 +22,5 @@
|
||||
*
|
||||
*/
|
||||
|
||||
int _gnutls_hostname_compare (const char *certname, const char *hostname);
|
||||
int MHD__gnutls_hostname_compare (const char *certname, const char *hostname);
|
||||
#define MAX_CN 256
|
||||
@@ -32,7 +32,7 @@
|
||||
* return 1 on success or 0 on error
|
||||
*/
|
||||
int
|
||||
_gnutls_hostname_compare (const char *certname, const char *hostname)
|
||||
MHD__gnutls_hostname_compare (const char *certname, const char *hostname)
|
||||
{
|
||||
const char *cmpstr1, *cmpstr2;
|
||||
|
||||
@@ -71,8 +71,8 @@ _gnutls_hostname_compare (const char *certname, const char *hostname)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_check_hostname - This function compares the given hostname with the hostname in the certificate
|
||||
* @cert: should contain an gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_check_hostname - This function compares the given hostname with the hostname in the certificate
|
||||
* @cert: should contain an MHD_gnutls_x509_crt_t structure
|
||||
* @hostname: A null terminated string that contains a DNS name
|
||||
*
|
||||
* This function will check if the given certificate's subject
|
||||
@@ -84,7 +84,7 @@ _gnutls_hostname_compare (const char *certname, const char *hostname)
|
||||
* Returns non zero for a successful match, and zero on failure.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert, const char *hostname)
|
||||
MHD_gnutls_x509_crt_check_hostname (MHD_gnutls_x509_crt_t cert, const char *hostname)
|
||||
{
|
||||
|
||||
char dnsname[MAX_CN];
|
||||
@@ -111,14 +111,14 @@ gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert, const char *hostname)
|
||||
{
|
||||
|
||||
dnsnamesize = sizeof (dnsname);
|
||||
ret = gnutls_x509_crt_get_subject_alt_name (cert, i,
|
||||
ret = MHD_gnutls_x509_crt_get_subject_alt_name (cert, i,
|
||||
dnsname, &dnsnamesize,
|
||||
NULL);
|
||||
|
||||
if (ret == GNUTLS_SAN_DNSNAME)
|
||||
{
|
||||
found_dnsname = 1;
|
||||
if (_gnutls_hostname_compare (dnsname, hostname))
|
||||
if (MHD__gnutls_hostname_compare (dnsname, hostname))
|
||||
{
|
||||
return 1;
|
||||
}
|
||||
@@ -128,7 +128,7 @@ gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert, const char *hostname)
|
||||
found_dnsname = 1; /* RFC 2818 is unclear whether the CN
|
||||
should be compared for IP addresses
|
||||
too, but we won't do it. */
|
||||
if (_gnutls_hostname_compare (dnsname, hostname))
|
||||
if (MHD__gnutls_hostname_compare (dnsname, hostname))
|
||||
{
|
||||
return 1;
|
||||
}
|
||||
@@ -140,7 +140,7 @@ gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert, const char *hostname)
|
||||
/* not got the necessary extension, use CN instead
|
||||
*/
|
||||
dnsnamesize = sizeof (dnsname);
|
||||
if (gnutls_x509_crt_get_dn_by_oid (cert, OID_X520_COMMON_NAME, 0,
|
||||
if (MHD_gnutls_x509_crt_get_dn_by_oid (cert, OID_X520_COMMON_NAME, 0,
|
||||
0, dnsname, &dnsnamesize) < 0)
|
||||
{
|
||||
/* got an error, can't find a name
|
||||
@@ -148,7 +148,7 @@ gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert, const char *hostname)
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (_gnutls_hostname_compare (dnsname, hostname))
|
||||
if (MHD__gnutls_hostname_compare (dnsname, hostname))
|
||||
{
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -50,34 +50,34 @@
|
||||
*/
|
||||
static int
|
||||
encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
const gnutls_datum_t * digest, gnutls_datum_t * info)
|
||||
const MHD_gnutls_datum_t * digest, MHD_gnutls_datum_t * info)
|
||||
{
|
||||
ASN1_TYPE dinfo = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
const char *algo;
|
||||
|
||||
algo = mhd_gtls_x509_mac_to_oid ((enum MHD_GNUTLS_HashAlgorithm) hash);
|
||||
algo = MHD_gtls_x509_mac_to_oid ((enum MHD_GNUTLS_HashAlgorithm) hash);
|
||||
if (algo == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_x509_log ("Hash algorithm: %d\n", hash);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_x509_log ("Hash algorithm: %d\n", hash);
|
||||
return GNUTLS_E_UNKNOWN_PK_ALGORITHM;
|
||||
}
|
||||
|
||||
if ((result = asn1_create_element (_gnutls_get_gnutls_asn (),
|
||||
if ((result = MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.DigestInfo",
|
||||
&dinfo)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_write_value (dinfo, "digestAlgorithm.algorithm", algo, 1);
|
||||
result = MHD__asn1_write_value (dinfo, "digestAlgorithm.algorithm", algo, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dinfo);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Write an ASN.1 NULL in the parameters field. This matches RFC
|
||||
@@ -85,43 +85,43 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
perspective (see those documents for more information).
|
||||
Regardless of what is correct, this appears to be what most
|
||||
implementations do. */
|
||||
result = asn1_write_value (dinfo, "digestAlgorithm.parameters",
|
||||
result = MHD__asn1_write_value (dinfo, "digestAlgorithm.parameters",
|
||||
"\x05\x00", 2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dinfo);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_write_value (dinfo, "digest", digest->data, digest->size);
|
||||
result = MHD__asn1_write_value (dinfo, "digest", digest->data, digest->size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dinfo);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
info->size = 0;
|
||||
asn1_der_coding (dinfo, "", NULL, &info->size, NULL);
|
||||
MHD__asn1_der_coding (dinfo, "", NULL, &info->size, NULL);
|
||||
|
||||
info->data = gnutls_malloc (info->size);
|
||||
info->data = MHD_gnutls_malloc (info->size);
|
||||
if (info->data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dinfo);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
result = asn1_der_coding (dinfo, "", info->data, &info->size, NULL);
|
||||
result = MHD__asn1_der_coding (dinfo, "", info->data, &info->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dinfo);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
asn1_delete_structure (&dinfo);
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -133,45 +133,45 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
*/
|
||||
static int
|
||||
pkcs1_rsa_sign (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
const gnutls_datum_t * text, mpi_t * params, int params_len,
|
||||
gnutls_datum_t * signature)
|
||||
const MHD_gnutls_datum_t * text, mpi_t * params, int params_len,
|
||||
MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int ret;
|
||||
opaque _digest[MAX_HASH_SIZE];
|
||||
GNUTLS_HASH_HANDLE hd;
|
||||
gnutls_datum_t digest, info;
|
||||
MHD_gnutls_datum_t digest, info;
|
||||
|
||||
hd = mhd_gtls_hash_init (HASH2MAC (hash));
|
||||
hd = MHD_gtls_hash_init (HASH2MAC (hash));
|
||||
if (hd == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_HASH_FAILED;
|
||||
}
|
||||
|
||||
mhd_gnutls_hash (hd, text->data, text->size);
|
||||
mhd_gnutls_hash_deinit (hd, _digest);
|
||||
MHD_gnutls_hash (hd, text->data, text->size);
|
||||
MHD_gnutls_hash_deinit (hd, _digest);
|
||||
|
||||
digest.data = _digest;
|
||||
digest.size = mhd_gnutls_hash_get_algo_len (HASH2MAC (hash));
|
||||
digest.size = MHD_gnutls_hash_get_algo_len (HASH2MAC (hash));
|
||||
|
||||
/* Encode the digest as a DigestInfo
|
||||
*/
|
||||
if ((ret = encode_ber_digest_info (hash, &digest, &info)) != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
if ((ret =
|
||||
mhd_gtls_sign (MHD_GNUTLS_PK_RSA, params, params_len, &info,
|
||||
MHD_gtls_sign (MHD_GNUTLS_PK_RSA, params, params_len, &info,
|
||||
signature)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (&info);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (&info);
|
||||
return ret;
|
||||
}
|
||||
|
||||
_gnutls_free_datum (&info);
|
||||
MHD__gnutls_free_datum (&info);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -186,9 +186,9 @@ pkcs1_rsa_sign (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
* 'hash' is only used in PKCS1 RSA signing.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_sign (const gnutls_datum_t * tbs,
|
||||
MHD__gnutls_x509_sign (const MHD_gnutls_datum_t * tbs,
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
gnutls_x509_privkey_t signer, gnutls_datum_t * signature)
|
||||
MHD_gnutls_x509_privkey_t signer, MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int ret;
|
||||
|
||||
@@ -200,63 +200,63 @@ _gnutls_x509_sign (const gnutls_datum_t * tbs,
|
||||
signature);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
return 0;
|
||||
break;
|
||||
default:
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
/* This is the same as the _gnutls_x509_sign, but this one will decode
|
||||
/* This is the same as the MHD__gnutls_x509_sign, but this one will decode
|
||||
* the ASN1_TYPE given, and sign the DER data. Actually used to get the DER
|
||||
* of the TBS and sign it on the fly.
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
|
||||
MHD__gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
gnutls_x509_privkey_t signer,
|
||||
gnutls_datum_t * signature)
|
||||
MHD_gnutls_x509_privkey_t signer,
|
||||
MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int result;
|
||||
opaque *buf;
|
||||
int buf_size;
|
||||
gnutls_datum_t tbs;
|
||||
MHD_gnutls_datum_t tbs;
|
||||
|
||||
buf_size = 0;
|
||||
asn1_der_coding (cert, tbs_name, NULL, &buf_size, NULL);
|
||||
MHD__asn1_der_coding (cert, tbs_name, NULL, &buf_size, NULL);
|
||||
|
||||
buf = gnutls_alloca (buf_size);
|
||||
buf = MHD_gnutls_alloca (buf_size);
|
||||
if (buf == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
result = asn1_der_coding (cert, tbs_name, buf, &buf_size, NULL);
|
||||
result = MHD__asn1_der_coding (cert, tbs_name, buf, &buf_size, NULL);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_afree (buf);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_afree (buf);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
tbs.data = buf;
|
||||
tbs.size = buf_size;
|
||||
|
||||
result = _gnutls_x509_sign (&tbs, hash, signer, signature);
|
||||
gnutls_afree (buf);
|
||||
result = MHD__gnutls_x509_sign (&tbs, hash, signer, signature);
|
||||
MHD_gnutls_afree (buf);
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
/*-
|
||||
* _gnutls_x509_pkix_sign - This function will sign a CRL or a certificate with a key
|
||||
* MHD__gnutls_x509_pkix_sign - This function will sign a CRL or a certificate with a key
|
||||
* @src: should contain an ASN1_TYPE
|
||||
* @issuer: is the certificate of the certificate issuer
|
||||
* @issuer_key: holds the issuer's private key
|
||||
@@ -268,76 +268,76 @@ _gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
|
||||
*
|
||||
-*/
|
||||
int
|
||||
_gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
|
||||
MHD__gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
|
||||
enum MHD_GNUTLS_HashAlgorithm dig,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key)
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t signature;
|
||||
MHD_gnutls_datum_t signature;
|
||||
char name[128];
|
||||
|
||||
/* Step 1. Copy the issuer's name into the certificate.
|
||||
*/
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".issuer");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".issuer");
|
||||
|
||||
result = asn1_copy_node (src, name, issuer->cert, "tbsCertificate.subject");
|
||||
result = MHD__asn1_copy_node (src, name, issuer->cert, "tbsCertificate.subject");
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Step 1.5. Write the signature stuff in the tbsCertificate.
|
||||
*/
|
||||
mhd_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
mhd_gtls_str_cat (name, sizeof (name), ".signature");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), src_name);
|
||||
MHD_gtls_str_cat (name, sizeof (name), ".signature");
|
||||
|
||||
result = _gnutls_x509_write_sig_params (src, name,
|
||||
result = MHD__gnutls_x509_write_sig_params (src, name,
|
||||
issuer_key->pk_algorithm, dig,
|
||||
issuer_key->params,
|
||||
issuer_key->params_size);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* Step 2. Sign the certificate.
|
||||
*/
|
||||
result = _gnutls_x509_sign_tbs (src, src_name, dig, issuer_key, &signature);
|
||||
result = MHD__gnutls_x509_sign_tbs (src, src_name, dig, issuer_key, &signature);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
/* write the signature (bits)
|
||||
*/
|
||||
result =
|
||||
asn1_write_value (src, "signature", signature.data, signature.size * 8);
|
||||
MHD__asn1_write_value (src, "signature", signature.data, signature.size * 8);
|
||||
|
||||
_gnutls_free_datum (&signature);
|
||||
MHD__gnutls_free_datum (&signature);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Step 3. Move up and write the AlgorithmIdentifier, which is also
|
||||
* the same.
|
||||
*/
|
||||
|
||||
result = _gnutls_x509_write_sig_params (src, "signatureAlgorithm",
|
||||
result = MHD__gnutls_x509_write_sig_params (src, "signatureAlgorithm",
|
||||
issuer_key->pk_algorithm, dig,
|
||||
issuer_key->params,
|
||||
issuer_key->params_size);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
|
||||
@@ -22,15 +22,15 @@
|
||||
*
|
||||
*/
|
||||
|
||||
int _gnutls_x509_sign (const gnutls_datum_t * tbs,
|
||||
int MHD__gnutls_x509_sign (const MHD_gnutls_datum_t * tbs,
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
gnutls_x509_privkey_t signer,
|
||||
gnutls_datum_t * signature);
|
||||
int _gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
|
||||
MHD_gnutls_x509_privkey_t signer,
|
||||
MHD_gnutls_datum_t * signature);
|
||||
int MHD__gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
gnutls_x509_privkey_t signer,
|
||||
gnutls_datum_t * signature);
|
||||
int _gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
|
||||
MHD_gnutls_x509_privkey_t signer,
|
||||
MHD_gnutls_datum_t * signature);
|
||||
int MHD__gnutls_x509_pkix_sign (ASN1_TYPE src, const char *src_name,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key);
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key);
|
||||
@@ -24,11 +24,11 @@
|
||||
|
||||
#include "x509.h"
|
||||
|
||||
int gnutls_x509_crt_is_issuer (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_t issuer);
|
||||
int _gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
|
||||
const gnutls_datum_t * signature,
|
||||
gnutls_x509_crt_t issuer);
|
||||
int _gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
|
||||
const gnutls_datum_t * signature,
|
||||
gnutls_x509_privkey_t issuer);
|
||||
int MHD_gnutls_x509_crt_is_issuer (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
int MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
int MHD__gnutls_x509_privkey_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_privkey_t issuer);
|
||||
+534
-534
@@ -40,7 +40,7 @@
|
||||
#include <verify.h>
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_init - This function initializes a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_init - This function initializes a MHD_gnutls_x509_crt_t structure
|
||||
* @cert: The structure to be initialized
|
||||
*
|
||||
* This function will initialize an X.509 certificate structure.
|
||||
@@ -49,21 +49,21 @@
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_init (gnutls_x509_crt_t * cert)
|
||||
MHD_gnutls_x509_crt_init (MHD_gnutls_x509_crt_t * cert)
|
||||
{
|
||||
gnutls_x509_crt_t tmp = gnutls_calloc (1, sizeof (gnutls_x509_crt_int));
|
||||
MHD_gnutls_x509_crt_t tmp = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_x509_crt_int));
|
||||
int result;
|
||||
|
||||
if (!tmp)
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
|
||||
result = asn1_create_element (_gnutls_get_pkix (),
|
||||
result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.Certificate", &tmp->cert);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_free (tmp);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_free (tmp);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
*cert = tmp;
|
||||
@@ -72,7 +72,7 @@ gnutls_x509_crt_init (gnutls_x509_crt_t * cert)
|
||||
}
|
||||
|
||||
/*-
|
||||
* _gnutls_x509_crt_cpy - This function copies a gnutls_x509_crt_t structure
|
||||
* MHD__gnutls_x509_crt_cpy - This function copies a MHD_gnutls_x509_crt_t structure
|
||||
* @dest: The structure where to copy
|
||||
* @src: The structure to be copied
|
||||
*
|
||||
@@ -82,44 +82,44 @@ gnutls_x509_crt_init (gnutls_x509_crt_t * cert)
|
||||
*
|
||||
-*/
|
||||
int
|
||||
_gnutls_x509_crt_cpy (gnutls_x509_crt_t dest, gnutls_x509_crt_t src)
|
||||
MHD__gnutls_x509_crt_cpy (MHD_gnutls_x509_crt_t dest, MHD_gnutls_x509_crt_t src)
|
||||
{
|
||||
int ret;
|
||||
size_t der_size;
|
||||
opaque *der;
|
||||
gnutls_datum_t tmp;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
|
||||
ret = gnutls_x509_crt_export (src, GNUTLS_X509_FMT_DER, NULL, &der_size);
|
||||
ret = MHD_gnutls_x509_crt_export (src, GNUTLS_X509_FMT_DER, NULL, &der_size);
|
||||
if (ret != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
der = gnutls_alloca (der_size);
|
||||
der = MHD_gnutls_alloca (der_size);
|
||||
if (der == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
ret = gnutls_x509_crt_export (src, GNUTLS_X509_FMT_DER, der, &der_size);
|
||||
ret = MHD_gnutls_x509_crt_export (src, GNUTLS_X509_FMT_DER, der, &der_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_afree (der);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_afree (der);
|
||||
return ret;
|
||||
}
|
||||
|
||||
tmp.data = der;
|
||||
tmp.size = der_size;
|
||||
ret = gnutls_x509_crt_import (dest, &tmp, GNUTLS_X509_FMT_DER);
|
||||
ret = MHD_gnutls_x509_crt_import (dest, &tmp, GNUTLS_X509_FMT_DER);
|
||||
|
||||
gnutls_afree (der);
|
||||
MHD_gnutls_afree (der);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -128,32 +128,32 @@ _gnutls_x509_crt_cpy (gnutls_x509_crt_t dest, gnutls_x509_crt_t src)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_deinit - This function deinitializes memory used by a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_deinit - This function deinitializes memory used by a MHD_gnutls_x509_crt_t structure
|
||||
* @cert: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a CRL structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
gnutls_x509_crt_deinit (gnutls_x509_crt_t cert)
|
||||
MHD_gnutls_x509_crt_deinit (MHD_gnutls_x509_crt_t cert)
|
||||
{
|
||||
if (!cert)
|
||||
return;
|
||||
|
||||
if (cert->cert)
|
||||
asn1_delete_structure (&cert->cert);
|
||||
MHD__asn1_delete_structure (&cert->cert);
|
||||
|
||||
gnutls_free (cert);
|
||||
MHD_gnutls_free (cert);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_import - This function will import a DER or PEM encoded Certificate
|
||||
* MHD_gnutls_x509_crt_import - This function will import a DER or PEM encoded Certificate
|
||||
* @cert: The structure to store the parsed certificate.
|
||||
* @data: The DER or PEM encoded certificate.
|
||||
* @format: One of DER or PEM
|
||||
*
|
||||
* This function will convert the given DER or PEM encoded Certificate
|
||||
* to the native gnutls_x509_crt_t format. The output will be stored in @cert.
|
||||
* to the native MHD_gnutls_x509_crt_t format. The output will be stored in @cert.
|
||||
*
|
||||
* If the Certificate is PEM encoded it should have a header of "X509 CERTIFICATE", or
|
||||
* "CERTIFICATE".
|
||||
@@ -162,17 +162,17 @@ gnutls_x509_crt_deinit (gnutls_x509_crt_t cert)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_import (gnutls_x509_crt_t cert,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format)
|
||||
MHD_gnutls_x509_crt_import (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
gnutls_datum_t _data;
|
||||
MHD_gnutls_datum_t _data;
|
||||
opaque *signature = NULL;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -186,20 +186,20 @@ gnutls_x509_crt_import (gnutls_x509_crt_t cert,
|
||||
opaque *out;
|
||||
|
||||
/* Try the first header */
|
||||
result = _gnutls_fbase64_decode (PEM_X509_CERT2, data->data, data->size,
|
||||
result = MHD__gnutls_fbase64_decode (PEM_X509_CERT2, data->data, data->size,
|
||||
&out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
/* try for the second header */
|
||||
result = _gnutls_fbase64_decode (PEM_X509_CERT, data->data,
|
||||
result = MHD__gnutls_fbase64_decode (PEM_X509_CERT, data->data,
|
||||
data->size, &out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
if (result == 0)
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
}
|
||||
@@ -210,11 +210,11 @@ gnutls_x509_crt_import (gnutls_x509_crt_t cert,
|
||||
need_free = 1;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&cert->cert, _data.data, _data.size, NULL);
|
||||
result = MHD__asn1_der_decoding (&cert->cert, _data.data, _data.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
result = mhd_gtls_asn2err (result);
|
||||
gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -222,19 +222,19 @@ gnutls_x509_crt_import (gnutls_x509_crt_t cert,
|
||||
*/
|
||||
cert->use_extensions = 1;
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:gnutls_free (signature);
|
||||
cleanup:MHD_gnutls_free (signature);
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_issuer_dn - This function returns the Certificate's issuer distinguished name
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_issuer_dn - This function returns the Certificate's issuer distinguished name
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @buf: a pointer to a structure to hold the name (may be null)
|
||||
* @sizeof_buf: initially holds the size of @buf
|
||||
*
|
||||
@@ -251,23 +251,23 @@ cleanup:gnutls_free (signature);
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_issuer_dn (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_issuer_dn (MHD_gnutls_x509_crt_t cert,
|
||||
char *buf, size_t * sizeof_buf)
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_parse_dn (cert->cert,
|
||||
return MHD__gnutls_x509_parse_dn (cert->cert,
|
||||
"tbsCertificate.issuer.rdnSequence", buf,
|
||||
sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_issuer_dn_by_oid - This function returns the Certificate's issuer distinguished name
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_issuer_dn_by_oid - This function returns the Certificate's issuer distinguished name
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @oid: holds an Object Identified in null terminated string
|
||||
* @indx: In case multiple same OIDs exist in the RDN, this specifies which to send. Use zero to get the first one.
|
||||
* @raw_flag: If non zero returns the raw DER data of the DN part.
|
||||
@@ -283,7 +283,7 @@ gnutls_x509_crt_get_issuer_dn (gnutls_x509_crt_t cert,
|
||||
* If raw flag is zero, this function will only return known OIDs as
|
||||
* text. Other OIDs will be DER encoded, as described in RFC2253 --
|
||||
* in hex format with a '\#' prefix. You can check about known OIDs
|
||||
* using gnutls_x509_dn_oid_known().
|
||||
* using MHD_gnutls_x509_dn_oid_known().
|
||||
*
|
||||
* If @buf is null then only the size will be filled.
|
||||
*
|
||||
@@ -293,7 +293,7 @@ gnutls_x509_crt_get_issuer_dn (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_issuer_dn_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
@@ -301,18 +301,18 @@ gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_parse_dn_oid (cert->cert,
|
||||
return MHD__gnutls_x509_parse_dn_oid (cert->cert,
|
||||
"tbsCertificate.issuer.rdnSequence", oid,
|
||||
indx, raw_flag, buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_issuer_dn_oid - This function returns the Certificate's issuer distinguished name OIDs
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_issuer_dn_oid - This function returns the Certificate's issuer distinguished name OIDs
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @indx: This specifies which OID to return. Use zero to get the first one.
|
||||
* @oid: a pointer to a buffer to hold the OID (may be null)
|
||||
* @sizeof_oid: initially holds the size of @oid
|
||||
@@ -328,23 +328,23 @@ gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_issuer_dn_oid (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_issuer_dn_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_get_dn_oid (cert->cert,
|
||||
return MHD__gnutls_x509_get_dn_oid (cert->cert,
|
||||
"tbsCertificate.issuer.rdnSequence", indx,
|
||||
oid, sizeof_oid);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_dn - This function returns the Certificate's distinguished name
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_dn - This function returns the Certificate's distinguished name
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @buf: a pointer to a structure to hold the name (may be null)
|
||||
* @sizeof_buf: initially holds the size of @buf
|
||||
*
|
||||
@@ -361,23 +361,23 @@ gnutls_x509_crt_get_issuer_dn_oid (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_dn (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_dn (MHD_gnutls_x509_crt_t cert,
|
||||
char *buf, size_t * sizeof_buf)
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_parse_dn (cert->cert,
|
||||
return MHD__gnutls_x509_parse_dn (cert->cert,
|
||||
"tbsCertificate.subject.rdnSequence", buf,
|
||||
sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_dn_by_oid - This function returns the Certificate's distinguished name
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_dn_by_oid - This function returns the Certificate's distinguished name
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @oid: holds an Object Identified in null terminated string
|
||||
* @indx: In case multiple same OIDs exist in the RDN, this specifies which to send. Use zero to get the first one.
|
||||
* @raw_flag: If non zero returns the raw DER data of the DN part.
|
||||
@@ -393,7 +393,7 @@ gnutls_x509_crt_get_dn (gnutls_x509_crt_t cert,
|
||||
* If raw flag is zero, this function will only return known OIDs as
|
||||
* text. Other OIDs will be DER encoded, as described in RFC2253 --
|
||||
* in hex format with a '\#' prefix. You can check about known OIDs
|
||||
* using gnutls_x509_dn_oid_known().
|
||||
* using MHD_gnutls_x509_dn_oid_known().
|
||||
*
|
||||
* If @buf is null then only the size will be filled.
|
||||
*
|
||||
@@ -403,7 +403,7 @@ gnutls_x509_crt_get_dn (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_dn_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
@@ -411,18 +411,18 @@ gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_parse_dn_oid (cert->cert,
|
||||
return MHD__gnutls_x509_parse_dn_oid (cert->cert,
|
||||
"tbsCertificate.subject.rdnSequence", oid,
|
||||
indx, raw_flag, buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_dn_oid - This function returns the Certificate's subject distinguished name OIDs
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_dn_oid - This function returns the Certificate's subject distinguished name OIDs
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @indx: This specifies which OID to return. Use zero to get the first one.
|
||||
* @oid: a pointer to a buffer to hold the OID (may be null)
|
||||
* @sizeof_oid: initially holds the size of @oid
|
||||
@@ -438,39 +438,39 @@ gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_dn_oid (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_dn_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_get_dn_oid (cert->cert,
|
||||
return MHD__gnutls_x509_get_dn_oid (cert->cert,
|
||||
"tbsCertificate.subject.rdnSequence", indx,
|
||||
oid, sizeof_oid);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_signature_algorithm - This function returns the Certificate's signature algorithm
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_signature_algorithm - This function returns the Certificate's signature algorithm
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
*
|
||||
* This function will return a value of the gnutls_sign_algorithm_t enumeration that
|
||||
* This function will return a value of the MHD_gnutls_sign_algorithm_t enumeration that
|
||||
* is the signature algorithm.
|
||||
*
|
||||
* Returns a negative value on error.
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert)
|
||||
MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t sa;
|
||||
MHD_gnutls_datum_t sa;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -478,25 +478,25 @@ gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert)
|
||||
* read. They will be read from the issuer's certificate if needed.
|
||||
*/
|
||||
result =
|
||||
_gnutls_x509_read_value (cert->cert, "signatureAlgorithm.algorithm", &sa,
|
||||
MHD__gnutls_x509_read_value (cert->cert, "signatureAlgorithm.algorithm", &sa,
|
||||
0);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
result = mhd_gtls_x509_oid2sign_algorithm (sa.data);
|
||||
result = MHD_gtls_x509_oid2sign_algorithm (sa.data);
|
||||
|
||||
_gnutls_free_datum (&sa);
|
||||
MHD__gnutls_free_datum (&sa);
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_signature - Returns the Certificate's signature
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_signature - Returns the Certificate's signature
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @sig: a pointer where the signature part will be copied (may be null).
|
||||
* @sizeof_sig: initially holds the size of @sig
|
||||
*
|
||||
@@ -505,7 +505,7 @@ gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert)
|
||||
* Returns 0 on success, and a negative value on error.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_signature (MHD_gnutls_x509_crt_t cert,
|
||||
char *sig, size_t * sizeof_sig)
|
||||
{
|
||||
int result;
|
||||
@@ -513,21 +513,21 @@ gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
bits = 0;
|
||||
result = asn1_read_value (cert->cert, "signature", NULL, &bits);
|
||||
result = MHD__asn1_read_value (cert->cert, "signature", NULL, &bits);
|
||||
if (result != ASN1_MEM_ERROR)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (bits % 8 != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_CERTIFICATE_ERROR;
|
||||
}
|
||||
|
||||
@@ -539,19 +539,19 @@ gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
|
||||
result = asn1_read_value (cert->cert, "signature", sig, &len);
|
||||
result = MHD__asn1_read_value (cert->cert, "signature", sig, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_version - This function returns the Certificate's version number
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_version - This function returns the Certificate's version number
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
*
|
||||
* This function will return the version of the specified Certificate.
|
||||
*
|
||||
@@ -559,35 +559,35 @@ gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_version (gnutls_x509_crt_t cert)
|
||||
MHD_gnutls_x509_crt_get_version (MHD_gnutls_x509_crt_t cert)
|
||||
{
|
||||
opaque version[5];
|
||||
int len, result;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
len = sizeof (version);
|
||||
if ((result =
|
||||
asn1_read_value (cert->cert, "tbsCertificate.version", version,
|
||||
MHD__asn1_read_value (cert->cert, "tbsCertificate.version", version,
|
||||
&len)) != ASN1_SUCCESS)
|
||||
{
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
return 1; /* the DEFAULT version */
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return (int) version[0] + 1;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_activation_time - This function returns the Certificate's activation time
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_activation_time - This function returns the Certificate's activation time
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
*
|
||||
* This function will return the time this Certificate was or will be activated.
|
||||
*
|
||||
@@ -595,21 +595,21 @@ gnutls_x509_crt_get_version (gnutls_x509_crt_t cert)
|
||||
*
|
||||
**/
|
||||
time_t
|
||||
gnutls_x509_crt_get_activation_time (gnutls_x509_crt_t cert)
|
||||
MHD_gnutls_x509_crt_get_activation_time (MHD_gnutls_x509_crt_t cert)
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return (time_t) - 1;
|
||||
}
|
||||
|
||||
return _gnutls_x509_get_time (cert->cert,
|
||||
return MHD__gnutls_x509_get_time (cert->cert,
|
||||
"tbsCertificate.validity.notBefore");
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_expiration_time - This function returns the Certificate's expiration time
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_expiration_time - This function returns the Certificate's expiration time
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
*
|
||||
* This function will return the time this Certificate was or will be expired.
|
||||
*
|
||||
@@ -617,21 +617,21 @@ gnutls_x509_crt_get_activation_time (gnutls_x509_crt_t cert)
|
||||
*
|
||||
**/
|
||||
time_t
|
||||
gnutls_x509_crt_get_expiration_time (gnutls_x509_crt_t cert)
|
||||
MHD_gnutls_x509_crt_get_expiration_time (MHD_gnutls_x509_crt_t cert)
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return (time_t) - 1;
|
||||
}
|
||||
|
||||
return _gnutls_x509_get_time (cert->cert,
|
||||
return MHD__gnutls_x509_get_time (cert->cert,
|
||||
"tbsCertificate.validity.notAfter");
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_serial - This function returns the certificate's serial number
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_serial - This function returns the certificate's serial number
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @result: The place where the serial number will be copied
|
||||
* @result_size: Holds the size of the result field.
|
||||
*
|
||||
@@ -645,35 +645,35 @@ gnutls_x509_crt_get_expiration_time (gnutls_x509_crt_t cert)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
|
||||
void *result, size_t * result_size)
|
||||
{
|
||||
int ret, len;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
len = *result_size;
|
||||
ret
|
||||
=
|
||||
asn1_read_value (cert->cert, "tbsCertificate.serialNumber", result, &len);
|
||||
MHD__asn1_read_value (cert->cert, "tbsCertificate.serialNumber", result, &len);
|
||||
*result_size = len;
|
||||
|
||||
if (ret != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (ret);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (ret);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_subject_key_id - This function returns the certificate's key identifier
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_subject_key_id - This function returns the certificate's key identifier
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @ret: The place where the identifier will be copied
|
||||
* @ret_size: Holds the size of the result field.
|
||||
* @critical: will be non zero if the extension is marked as critical (may be null)
|
||||
@@ -686,17 +686,17 @@ gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_subject_key_id (MHD_gnutls_x509_crt_t cert,
|
||||
void *ret,
|
||||
size_t * ret_size, unsigned int *critical)
|
||||
{
|
||||
int result, len;
|
||||
gnutls_datum_t id;
|
||||
MHD_gnutls_datum_t id;
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -705,7 +705,7 @@ gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
|
||||
else
|
||||
*ret_size = 0;
|
||||
|
||||
if ((result = _gnutls_x509_crt_get_extension (cert, "2.5.29.14", 0, &id,
|
||||
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.14", 0, &id,
|
||||
critical)) < 0)
|
||||
{
|
||||
return result;
|
||||
@@ -713,35 +713,35 @@ gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
|
||||
|
||||
if (id.size == 0 || id.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.SubjectKeyIdentifier",
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.SubjectKeyIdentifier",
|
||||
&c2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (&id);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (&id);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&c2, id.data, id.size, NULL);
|
||||
_gnutls_free_datum (&id);
|
||||
result = MHD__asn1_der_decoding (&c2, id.data, id.size, NULL);
|
||||
MHD__gnutls_free_datum (&id);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
len = *ret_size;
|
||||
result = asn1_read_value (c2, "", ret, &len);
|
||||
result = MHD__asn1_read_value (c2, "", ret, &len);
|
||||
|
||||
*ret_size = len;
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
if (result == ASN1_VALUE_NOT_FOUND || result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -750,16 +750,16 @@ gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_authority_key_id - This function returns the certificate authority's identifier
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_authority_key_id - This function returns the certificate authority's identifier
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @result: The place where the identifier will be copied
|
||||
* @result_size: Holds the size of the result field.
|
||||
* @critical: will be non zero if the extension is marked as critical (may be null)
|
||||
@@ -773,18 +773,18 @@ gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_authority_key_id (MHD_gnutls_x509_crt_t cert,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical)
|
||||
{
|
||||
int result, len;
|
||||
gnutls_datum_t id;
|
||||
MHD_gnutls_datum_t id;
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -793,7 +793,7 @@ gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
|
||||
else
|
||||
*ret_size = 0;
|
||||
|
||||
if ((result = _gnutls_x509_crt_get_extension (cert, "2.5.29.35", 0, &id,
|
||||
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.35", 0, &id,
|
||||
critical)) < 0)
|
||||
{
|
||||
return result;
|
||||
@@ -801,35 +801,35 @@ gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
|
||||
|
||||
if (id.size == 0 || id.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.AuthorityKeyIdentifier",
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.AuthorityKeyIdentifier",
|
||||
&c2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (&id);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (&id);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&c2, id.data, id.size, NULL);
|
||||
_gnutls_free_datum (&id);
|
||||
result = MHD__asn1_der_decoding (&c2, id.data, id.size, NULL);
|
||||
MHD__gnutls_free_datum (&id);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
len = *ret_size;
|
||||
result = asn1_read_value (c2, "keyIdentifier", ret, &len);
|
||||
result = MHD__asn1_read_value (c2, "keyIdentifier", ret, &len);
|
||||
|
||||
*ret_size = len;
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
if (result == ASN1_VALUE_NOT_FOUND || result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -838,16 +838,16 @@ gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_pk_algorithm - This function returns the certificate's PublicKey algorithm
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_pk_algorithm - This function returns the certificate's PublicKey algorithm
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @bits: if bits is non null it will hold the size of the parameters' in bits
|
||||
*
|
||||
* This function will return the public key algorithm of an X.509
|
||||
@@ -863,23 +863,23 @@ gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_pk_algorithm (gnutls_x509_crt_t cert, unsigned int *bits)
|
||||
MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert, unsigned int *bits)
|
||||
{
|
||||
int result;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_get_pk_algorithm (cert->cert,
|
||||
result = MHD__gnutls_x509_get_pk_algorithm (cert->cert,
|
||||
"tbsCertificate.subjectPublicKeyInfo",
|
||||
bits);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -914,7 +914,7 @@ parse_general_name (ASN1_TYPE src,
|
||||
char nptr[MAX_NAME_SIZE];
|
||||
int result;
|
||||
opaque choice_type[128];
|
||||
gnutls_x509_subject_alt_name_t type;
|
||||
MHD_gnutls_x509_subject_alt_name_t type;
|
||||
|
||||
seq++; /* 0->1, 1->2 etc */
|
||||
|
||||
@@ -924,7 +924,7 @@ parse_general_name (ASN1_TYPE src,
|
||||
snprintf (nptr, sizeof (nptr), "?%u", seq);
|
||||
|
||||
len = sizeof (choice_type);
|
||||
result = asn1_read_value (src, nptr, choice_type, &len);
|
||||
result = MHD__asn1_read_value (src, nptr, choice_type, &len);
|
||||
|
||||
if (result == ASN1_VALUE_NOT_FOUND || result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -933,14 +933,14 @@ parse_general_name (ASN1_TYPE src,
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
type = _gnutls_x509_san_find_type (choice_type);
|
||||
if (type == (gnutls_x509_subject_alt_name_t) - 1)
|
||||
type = MHD__gnutls_x509_san_find_type (choice_type);
|
||||
if (type == (MHD_gnutls_x509_subject_alt_name_t) - 1)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_X509_UNKNOWN_SAN;
|
||||
}
|
||||
|
||||
@@ -950,12 +950,12 @@ parse_general_name (ASN1_TYPE src,
|
||||
if (type == GNUTLS_SAN_OTHERNAME)
|
||||
{
|
||||
if (othername_oid)
|
||||
mhd_gtls_str_cat (nptr, sizeof (nptr), ".otherName.type-id");
|
||||
MHD_gtls_str_cat (nptr, sizeof (nptr), ".otherName.type-id");
|
||||
else
|
||||
mhd_gtls_str_cat (nptr, sizeof (nptr), ".otherName.value");
|
||||
MHD_gtls_str_cat (nptr, sizeof (nptr), ".otherName.value");
|
||||
|
||||
len = *name_size;
|
||||
result = asn1_read_value (src, nptr, name, &len);
|
||||
result = MHD__asn1_read_value (src, nptr, name, &len);
|
||||
*name_size = len;
|
||||
|
||||
if (result == ASN1_MEM_ERROR)
|
||||
@@ -963,8 +963,8 @@ parse_general_name (ASN1_TYPE src,
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (othername_oid)
|
||||
@@ -983,11 +983,11 @@ parse_general_name (ASN1_TYPE src,
|
||||
snprintf (nptr, sizeof (nptr), "?%u.otherName.type-id", seq);
|
||||
|
||||
len = sizeof (oid);
|
||||
result = asn1_read_value (src, nptr, oid, &len);
|
||||
result = MHD__asn1_read_value (src, nptr, oid, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (len > strlen (XMPP_OID) && strcmp (oid, XMPP_OID) == 0)
|
||||
@@ -995,41 +995,41 @@ parse_general_name (ASN1_TYPE src,
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.XmppAddr",
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.XmppAddr",
|
||||
&c2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&c2, name, *name_size, NULL);
|
||||
result = MHD__asn1_der_decoding (&c2, name, *name_size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_read_value (c2, "", name, &len);
|
||||
result = MHD__asn1_read_value (c2, "", name, &len);
|
||||
*name_size = len;
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
}
|
||||
}
|
||||
}
|
||||
else if (type == GNUTLS_SAN_DN)
|
||||
{
|
||||
mhd_gtls_str_cat (nptr, sizeof (nptr), ".directoryName");
|
||||
result = _gnutls_x509_parse_dn (src, nptr, name, name_size);
|
||||
MHD_gtls_str_cat (nptr, sizeof (nptr), ".directoryName");
|
||||
result = MHD__gnutls_x509_parse_dn (src, nptr, name, name_size);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
}
|
||||
@@ -1039,11 +1039,11 @@ parse_general_name (ASN1_TYPE src,
|
||||
{
|
||||
size_t orig_name_size = *name_size;
|
||||
|
||||
mhd_gtls_str_cat (nptr, sizeof (nptr), ".");
|
||||
mhd_gtls_str_cat (nptr, sizeof (nptr), choice_type);
|
||||
MHD_gtls_str_cat (nptr, sizeof (nptr), ".");
|
||||
MHD_gtls_str_cat (nptr, sizeof (nptr), choice_type);
|
||||
|
||||
len = *name_size;
|
||||
result = asn1_read_value (src, nptr, name, &len);
|
||||
result = MHD__asn1_read_value (src, nptr, name, &len);
|
||||
*name_size = len;
|
||||
|
||||
if (result == ASN1_MEM_ERROR)
|
||||
@@ -1055,8 +1055,8 @@ parse_general_name (ASN1_TYPE src,
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (is_type_printable (type))
|
||||
@@ -1064,7 +1064,7 @@ parse_general_name (ASN1_TYPE src,
|
||||
|
||||
if (len + 1 > orig_name_size)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
(*name_size)++;
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
@@ -1079,7 +1079,7 @@ parse_general_name (ASN1_TYPE src,
|
||||
}
|
||||
|
||||
static int
|
||||
get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
@@ -1087,13 +1087,13 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
unsigned int *critical, int othername_oid)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t dnsname;
|
||||
MHD_gnutls_datum_t dnsname;
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
gnutls_x509_subject_alt_name_t type;
|
||||
MHD_gnutls_x509_subject_alt_name_t type;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -1103,7 +1103,7 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
*ret_size = 0;
|
||||
|
||||
if ((result =
|
||||
_gnutls_x509_crt_get_extension (cert, "2.5.29.17", 0, &dnsname,
|
||||
MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.17", 0, &dnsname,
|
||||
critical)) < 0)
|
||||
{
|
||||
return result;
|
||||
@@ -1111,33 +1111,33 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
|
||||
if (dnsname.size == 0 || dnsname.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.SubjectAltName", &c2);
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.SubjectAltName", &c2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (&dnsname);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (&dnsname);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&c2, dnsname.data, dnsname.size, NULL);
|
||||
_gnutls_free_datum (&dnsname);
|
||||
result = MHD__asn1_der_decoding (&c2, dnsname.data, dnsname.size, NULL);
|
||||
MHD__gnutls_free_datum (&dnsname);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = parse_general_name (c2, "", seq, ret, ret_size, ret_type,
|
||||
othername_oid);
|
||||
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -1150,8 +1150,8 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_subject_alt_name - Get certificate's alternative name, if any
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_subject_alt_name - Get certificate's alternative name, if any
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @seq: specifies the sequence number of the alt name (0 for the first one, 1 for the second etc.)
|
||||
* @ret: is the place where the alternative name will be copied to
|
||||
* @ret_size: holds the size of ret.
|
||||
@@ -1165,7 +1165,7 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
*
|
||||
* When the SAN type is otherName, it will extract the data in the
|
||||
* otherName's value field, and %GNUTLS_SAN_OTHERNAME is returned.
|
||||
* You may use gnutls_x509_crt_get_subject_alt_othername_oid() to get
|
||||
* You may use MHD_gnutls_x509_crt_get_subject_alt_othername_oid() to get
|
||||
* the corresponding OID and the "virtual" SAN types (e.g.,
|
||||
* %GNUTLS_SAN_OTHERNAME_XMPP).
|
||||
*
|
||||
@@ -1175,7 +1175,7 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
* recognized.
|
||||
*
|
||||
* Returns the alternative subject name type on success. The type is
|
||||
* one of the enumerated gnutls_x509_subject_alt_name_t. It will
|
||||
* one of the enumerated MHD_gnutls_x509_subject_alt_name_t. It will
|
||||
* return %GNUTLS_E_SHORT_MEMORY_BUFFER if @ret_size is not large
|
||||
* enough to hold the value. In that case @ret_size will be updated
|
||||
* with the required size. If the certificate does not have an
|
||||
@@ -1184,7 +1184,7 @@ get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
@@ -1194,25 +1194,25 @@ gnutls_x509_crt_get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_subject_alt_name2 - Get certificate's alternative name, if any
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_subject_alt_name2 - Get certificate's alternative name, if any
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @seq: specifies the sequence number of the alt name (0 for the first one, 1 for the second etc.)
|
||||
* @ret: is the place where the alternative name will be copied to
|
||||
* @ret_size: holds the size of ret.
|
||||
* @ret_type: holds the type of the alternative name (one of gnutls_x509_subject_alt_name_t).
|
||||
* @ret_type: holds the type of the alternative name (one of MHD_gnutls_x509_subject_alt_name_t).
|
||||
* @critical: will be non zero if the extension is marked as critical (may be null)
|
||||
*
|
||||
* This function will return the alternative names, contained in the
|
||||
* given certificate. It is the same as gnutls_x509_crt_get_subject_alt_name()
|
||||
* given certificate. It is the same as MHD_gnutls_x509_crt_get_subject_alt_name()
|
||||
* except for the fact that it will return the type of the alternative
|
||||
* name in @ret_type even if the function fails for some reason (i.e.
|
||||
* the buffer provided is not enough).
|
||||
*
|
||||
* The return values are the same as with gnutls_x509_crt_get_subject_alt_name().
|
||||
* The return values are the same as with MHD_gnutls_x509_crt_get_subject_alt_name().
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_subject_alt_name2 (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
@@ -1224,8 +1224,8 @@ gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_subject_alt_othername_oid - Get SAN otherName OID
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_subject_alt_othername_oid - Get SAN otherName OID
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @seq: specifies the sequence number of the alt name (0 for the first one, 1 for the second etc.)
|
||||
* @ret: is the place where the otherName OID will be copied to
|
||||
* @ret_size: holds the size of ret.
|
||||
@@ -1235,11 +1235,11 @@ gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
|
||||
* the type as an enumerated element.
|
||||
*
|
||||
* This function is only useful if
|
||||
* gnutls_x509_crt_get_subject_alt_name() returned
|
||||
* MHD_gnutls_x509_crt_get_subject_alt_name() returned
|
||||
* %GNUTLS_SAN_OTHERNAME.
|
||||
*
|
||||
* Returns the alternative subject name type on success. The type is
|
||||
* one of the enumerated gnutls_x509_subject_alt_name_t. For
|
||||
* one of the enumerated MHD_gnutls_x509_subject_alt_name_t. For
|
||||
* supported OIDs, it will return one of the virtual
|
||||
* (GNUTLS_SAN_OTHERNAME_*) types, e.g. %GNUTLS_SAN_OTHERNAME_XMPP,
|
||||
* and %GNUTLS_SAN_OTHERNAME for unknown OIDs. It will return
|
||||
@@ -1250,7 +1250,7 @@ gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
|
||||
* then %GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE is returned.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_subject_alt_othername_oid (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_subject_alt_othername_oid (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret, size_t * ret_size)
|
||||
{
|
||||
@@ -1258,8 +1258,8 @@ gnutls_x509_crt_get_subject_alt_othername_oid (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_basic_constraints - This function returns the certificate basic constraints
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_basic_constraints - This function returns the certificate basic constraints
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @critical: will be non zero if the extension is marked as critical
|
||||
* @ca: pointer to output integer indicating CA status, may be NULL,
|
||||
* value is 1 if the certificate CA flag is set, 0 otherwise.
|
||||
@@ -1278,21 +1278,21 @@ gnutls_x509_crt_get_subject_alt_othername_oid (gnutls_x509_crt_t cert,
|
||||
* GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE will be returned.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_basic_constraints (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *critical,
|
||||
int *ca, int *pathlen)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t basicConstraints;
|
||||
MHD_gnutls_datum_t basicConstraints;
|
||||
int tmp_ca;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if ((result = _gnutls_x509_crt_get_extension (cert, "2.5.29.19", 0,
|
||||
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.19", 0,
|
||||
&basicConstraints, critical))
|
||||
< 0)
|
||||
{
|
||||
@@ -1301,20 +1301,20 @@ gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
|
||||
|
||||
if (basicConstraints.size == 0 || basicConstraints.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_ext_extract_basicConstraints (&tmp_ca, pathlen,
|
||||
result = MHD__gnutls_x509_ext_extract_basicConstraints (&tmp_ca, pathlen,
|
||||
basicConstraints.data,
|
||||
basicConstraints.size);
|
||||
if (ca)
|
||||
*ca = tmp_ca;
|
||||
_gnutls_free_datum (&basicConstraints);
|
||||
MHD__gnutls_free_datum (&basicConstraints);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -1322,8 +1322,8 @@ gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_ca_status - This function returns the certificate CA status
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_ca_status - This function returns the certificate CA status
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @critical: will be non zero if the extension is marked as critical
|
||||
*
|
||||
* This function will return certificates CA status, by reading the
|
||||
@@ -1331,7 +1331,7 @@ gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
|
||||
* a CA a positive value will be returned, or zero if the certificate
|
||||
* does not have CA flag set.
|
||||
*
|
||||
* Use gnutls_x509_crt_get_basic_constraints() if you want to read the
|
||||
* Use MHD_gnutls_x509_crt_get_basic_constraints() if you want to read the
|
||||
* pathLenConstraint field too.
|
||||
*
|
||||
* A negative value may be returned in case of parsing error.
|
||||
@@ -1340,16 +1340,16 @@ gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert, unsigned int *critical)
|
||||
MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert, unsigned int *critical)
|
||||
{
|
||||
int ca, pathlen;
|
||||
return gnutls_x509_crt_get_basic_constraints (cert, critical, &ca,
|
||||
return MHD_gnutls_x509_crt_get_basic_constraints (cert, critical, &ca,
|
||||
&pathlen);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_key_usage - This function returns the certificate's key usage
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_key_usage - This function returns the certificate's key usage
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @key_usage: where the key usage bits will be stored
|
||||
* @critical: will be non zero if the extension is marked as critical
|
||||
*
|
||||
@@ -1367,22 +1367,22 @@ gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert, unsigned int *critical)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t keyUsage;
|
||||
MHD_gnutls_datum_t keyUsage;
|
||||
uint16_t _usage;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if ((result =
|
||||
_gnutls_x509_crt_get_extension (cert, "2.5.29.15", 0, &keyUsage,
|
||||
MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.15", 0, &keyUsage,
|
||||
critical)) < 0)
|
||||
{
|
||||
return result;
|
||||
@@ -1390,19 +1390,19 @@ gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
|
||||
|
||||
if (keyUsage.size == 0 || keyUsage.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_ext_extract_keyUsage (&_usage, keyUsage.data,
|
||||
result = MHD__gnutls_x509_ext_extract_keyUsage (&_usage, keyUsage.data,
|
||||
keyUsage.size);
|
||||
_gnutls_free_datum (&keyUsage);
|
||||
MHD__gnutls_free_datum (&keyUsage);
|
||||
|
||||
*key_usage = _usage;
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -1410,8 +1410,8 @@ gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_proxy - This function returns the proxy certificate info
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_proxy - This function returns the proxy certificate info
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @critical: will be non zero if the extension is marked as critical
|
||||
* @pathlen: pointer to output integer indicating path length (may be
|
||||
* NULL), non-negative values indicate a present pCPathLenConstraint
|
||||
@@ -1428,22 +1428,22 @@ gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
|
||||
* GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE will be returned.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_proxy (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *critical,
|
||||
int *pathlen,
|
||||
char **policyLanguage,
|
||||
char **policy, size_t * sizeof_policy)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t proxyCertInfo;
|
||||
MHD_gnutls_datum_t proxyCertInfo;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if ((result = _gnutls_x509_crt_get_extension (cert, "1.3.6.1.5.5.7.1.14", 0,
|
||||
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "1.3.6.1.5.5.7.1.14", 0,
|
||||
&proxyCertInfo,
|
||||
critical)) < 0)
|
||||
{
|
||||
@@ -1452,18 +1452,18 @@ gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
|
||||
|
||||
if (proxyCertInfo.size == 0 || proxyCertInfo.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_ext_extract_proxyCertInfo (pathlen, policyLanguage,
|
||||
result = MHD__gnutls_x509_ext_extract_proxyCertInfo (pathlen, policyLanguage,
|
||||
policy, sizeof_policy,
|
||||
proxyCertInfo.data,
|
||||
proxyCertInfo.size);
|
||||
_gnutls_free_datum (&proxyCertInfo);
|
||||
MHD__gnutls_free_datum (&proxyCertInfo);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -1471,8 +1471,8 @@ gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_extension_by_oid - This function returns the specified extension
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_extension_by_oid - This function returns the specified extension
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @oid: holds an Object Identified in null terminated string
|
||||
* @indx: In case multiple same OIDs exist in the extensions, this specifies which to send. Use zero to get the first one.
|
||||
* @buf: a pointer to a structure to hold the name (may be null)
|
||||
@@ -1489,7 +1489,7 @@ gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_extension_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
void *buf,
|
||||
@@ -1497,31 +1497,31 @@ gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
|
||||
unsigned int *critical)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t output;
|
||||
MHD_gnutls_datum_t output;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if ((result = _gnutls_x509_crt_get_extension (cert, oid, indx, &output,
|
||||
if ((result = MHD__gnutls_x509_crt_get_extension (cert, oid, indx, &output,
|
||||
critical)) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
if (output.size == 0 || output.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
}
|
||||
|
||||
if (output.size > (unsigned int) *sizeof_buf)
|
||||
{
|
||||
*sizeof_buf = output.size;
|
||||
_gnutls_free_datum (&output);
|
||||
MHD__gnutls_free_datum (&output);
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
|
||||
@@ -1530,15 +1530,15 @@ gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
|
||||
if (buf)
|
||||
memcpy (buf, output.data, output.size);
|
||||
|
||||
_gnutls_free_datum (&output);
|
||||
MHD__gnutls_free_datum (&output);
|
||||
|
||||
return 0;
|
||||
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_extension_oid - This function returns the specified extension OID
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_extension_oid - This function returns the specified extension OID
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @indx: Specifies which extension OID to send. Use zero to get the first one.
|
||||
* @oid: a pointer to a structure to hold the OID (may be null)
|
||||
* @sizeof_oid: initially holds the size of @oid
|
||||
@@ -1552,18 +1552,18 @@ gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
{
|
||||
int result;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_crt_get_extension_oid (cert, indx, oid, sizeof_oid);
|
||||
result = MHD__gnutls_x509_crt_get_extension_oid (cert, indx, oid, sizeof_oid);
|
||||
if (result < 0)
|
||||
{
|
||||
return result;
|
||||
@@ -1574,8 +1574,8 @@ gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_extension_info - Get extension id and criticality
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_extension_info - Get extension id and criticality
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @indx: Specifies which extension OID to send. Use zero to get the first one.
|
||||
* @oid: a pointer to a structure to hold the OID
|
||||
* @sizeof_oid: initially holds the size of @oid
|
||||
@@ -1584,7 +1584,7 @@ gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
* This function will return the requested extension OID in the
|
||||
* certificate, and the critical flag for it. The extension OID will
|
||||
* be stored as a string in the provided buffer. Use
|
||||
* gnutls_x509_crt_get_extension_data() to extract the data.
|
||||
* MHD_gnutls_x509_crt_get_extension_data() to extract the data.
|
||||
*
|
||||
* Return 0 on success. A negative value may be returned in case of
|
||||
* parsing error. If you have reached the last extension available
|
||||
@@ -1592,7 +1592,7 @@ gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_extension_info (MHD_gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid, int *critical)
|
||||
@@ -1604,7 +1604,7 @@ gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
|
||||
|
||||
if (!cert)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -1612,25 +1612,25 @@ gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
|
||||
indx + 1);
|
||||
|
||||
len = *sizeof_oid;
|
||||
result = asn1_read_value (cert->cert, name, oid, &len);
|
||||
result = MHD__asn1_read_value (cert->cert, name, oid, &len);
|
||||
*sizeof_oid = len;
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
else if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
snprintf (name, sizeof (name), "tbsCertificate.extensions.?%u.critical",
|
||||
indx + 1);
|
||||
len = sizeof (str_critical);
|
||||
result = asn1_read_value (cert->cert, name, str_critical, &len);
|
||||
result = MHD__asn1_read_value (cert->cert, name, str_critical, &len);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if (critical)
|
||||
@@ -1646,8 +1646,8 @@ gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_extension_data - Get the specified extension data
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_extension_data - Get the specified extension data
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @indx: Specifies which extension OID to send. Use zero to get the first one.
|
||||
* @data: a pointer to a structure to hold the data (may be null)
|
||||
* @sizeof_data: initially holds the size of @oid
|
||||
@@ -1656,8 +1656,8 @@ gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
|
||||
* certificate. The extension data will be stored as a string in the
|
||||
* provided buffer.
|
||||
*
|
||||
* Use gnutls_x509_crt_get_extension_info() to extract the OID and
|
||||
* critical flag. Use gnutls_x509_crt_get_extension_by_oid() instead,
|
||||
* Use MHD_gnutls_x509_crt_get_extension_info() to extract the OID and
|
||||
* critical flag. Use MHD_gnutls_x509_crt_get_extension_by_oid() instead,
|
||||
* if you want to get data indexed by the extension OID rather than
|
||||
* sequence.
|
||||
*
|
||||
@@ -1666,7 +1666,7 @@ gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
|
||||
* GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE will be returned.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_extension_data (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_extension_data (MHD_gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *data, size_t * sizeof_data)
|
||||
{
|
||||
@@ -1675,7 +1675,7 @@ gnutls_x509_crt_get_extension_data (gnutls_x509_crt_t cert,
|
||||
|
||||
if (!cert)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -1683,82 +1683,82 @@ gnutls_x509_crt_get_extension_data (gnutls_x509_crt_t cert,
|
||||
indx + 1);
|
||||
|
||||
len = *sizeof_data;
|
||||
result = asn1_read_value (cert->cert, name, data, &len);
|
||||
result = MHD__asn1_read_value (cert->cert, name, data, &len);
|
||||
*sizeof_data = len;
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
else if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
static int
|
||||
_gnutls_x509_crt_get_raw_dn2 (gnutls_x509_crt_t cert,
|
||||
const char *whom, gnutls_datum_t * start)
|
||||
MHD__gnutls_x509_crt_get_raw_dn2 (MHD_gnutls_x509_crt_t cert,
|
||||
const char *whom, MHD_gnutls_datum_t * start)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result, len1;
|
||||
int start1, end1;
|
||||
gnutls_datum_t signed_data = { NULL,
|
||||
MHD_gnutls_datum_t signed_data = { NULL,
|
||||
0
|
||||
};
|
||||
|
||||
/* get the issuer of 'cert'
|
||||
*/
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.TBSCertificate",
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.TBSCertificate",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = _gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
|
||||
result = MHD__gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
|
||||
&signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&c2, signed_data.data, signed_data.size, NULL);
|
||||
result = MHD__asn1_der_decoding (&c2, signed_data.data, signed_data.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding_startEnd (c2, signed_data.data, signed_data.size,
|
||||
result = MHD__asn1_der_decoding_startEnd (c2, signed_data.data, signed_data.size,
|
||||
whom, &start1, &end1);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
len1 = end1 - start1 + 1;
|
||||
|
||||
_gnutls_set_datum (start, &signed_data.data[start1], len1);
|
||||
MHD__gnutls_set_datum (start, &signed_data.data[start1], len1);
|
||||
|
||||
result = 0;
|
||||
|
||||
cleanup:asn1_delete_structure (&c2);
|
||||
_gnutls_free_datum (&signed_data);
|
||||
cleanup:MHD__asn1_delete_structure (&c2);
|
||||
MHD__gnutls_free_datum (&signed_data);
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_raw_issuer_dn - This function returns the issuer's DN DER encoded
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_raw_issuer_dn - This function returns the issuer's DN DER encoded
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @start: will hold the starting point of the DN
|
||||
*
|
||||
* This function will return a pointer to the DER encoded DN structure
|
||||
@@ -1768,15 +1768,15 @@ cleanup:asn1_delete_structure (&c2);
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_raw_issuer_dn (gnutls_x509_crt_t cert,
|
||||
gnutls_datum_t * start)
|
||||
MHD_gnutls_x509_crt_get_raw_issuer_dn (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_datum_t * start)
|
||||
{
|
||||
return _gnutls_x509_crt_get_raw_dn2 (cert, "issuer", start);
|
||||
return MHD__gnutls_x509_crt_get_raw_dn2 (cert, "issuer", start);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_raw_dn - This function returns the subject's DN DER encoded
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_raw_dn - This function returns the subject's DN DER encoded
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @start: will hold the starting point of the DN
|
||||
*
|
||||
* This function will return a pointer to the DER encoded DN structure and
|
||||
@@ -1786,43 +1786,43 @@ gnutls_x509_crt_get_raw_issuer_dn (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_raw_dn (gnutls_x509_crt_t cert, gnutls_datum_t * start)
|
||||
MHD_gnutls_x509_crt_get_raw_dn (MHD_gnutls_x509_crt_t cert, MHD_gnutls_datum_t * start)
|
||||
{
|
||||
return _gnutls_x509_crt_get_raw_dn2 (cert, "subject", start);
|
||||
return MHD__gnutls_x509_crt_get_raw_dn2 (cert, "subject", start);
|
||||
}
|
||||
|
||||
static int
|
||||
get_dn (gnutls_x509_crt_t cert, const char *whom, gnutls_x509_dn_t * dn)
|
||||
get_dn (MHD_gnutls_x509_crt_t cert, const char *whom, MHD_gnutls_x509_dn_t * dn)
|
||||
{
|
||||
*dn = asn1_find_node (cert->cert, whom);
|
||||
*dn = MHD__asn1_find_node (cert->cert, whom);
|
||||
if (!*dn)
|
||||
return GNUTLS_E_ASN1_ELEMENT_NOT_FOUND;
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_subject: get opaque subject DN pointer
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_subject: get opaque subject DN pointer
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @dn: output variable with pointer to opaque DN.
|
||||
*
|
||||
* Return the Certificate's Subject DN as an opaque data type. You
|
||||
* may use gnutls_x509_dn_get_rdn_ava() to decode the DN.
|
||||
* may use MHD_gnutls_x509_dn_get_rdn_ava() to decode the DN.
|
||||
*
|
||||
* Returns: Returns 0 on success, or an error code.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_subject (gnutls_x509_crt_t cert, gnutls_x509_dn_t * dn)
|
||||
MHD_gnutls_x509_crt_get_subject (MHD_gnutls_x509_crt_t cert, MHD_gnutls_x509_dn_t * dn)
|
||||
{
|
||||
return get_dn (cert, "tbsCertificate.subject.rdnSequence", dn);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_issuer: get opaque issuer DN pointer
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_issuer: get opaque issuer DN pointer
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @dn: output variable with pointer to opaque DN
|
||||
*
|
||||
* Return the Certificate's Issuer DN as an opaque data type. You may
|
||||
* use gnutls_x509_dn_get_rdn_ava() to decode the DN.
|
||||
* use MHD_gnutls_x509_dn_get_rdn_ava() to decode the DN.
|
||||
*
|
||||
* Note that @dn points into the @cert object, and thus you may not
|
||||
* deallocate @cert and continue to access @dn.
|
||||
@@ -1830,13 +1830,13 @@ gnutls_x509_crt_get_subject (gnutls_x509_crt_t cert, gnutls_x509_dn_t * dn)
|
||||
* Returns: Returns 0 on success, or an error code.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_issuer (gnutls_x509_crt_t cert, gnutls_x509_dn_t * dn)
|
||||
MHD_gnutls_x509_crt_get_issuer (MHD_gnutls_x509_crt_t cert, MHD_gnutls_x509_dn_t * dn)
|
||||
{
|
||||
return get_dn (cert, "tbsCertificate.issuer.rdnSequence", dn);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_dn_get_rdn_ava:
|
||||
* MHD_gnutls_x509_dn_get_rdn_ava:
|
||||
* @dn: input variable with opaque DN pointer
|
||||
* @irdn: index of RDN
|
||||
* @iava: index of AVA.
|
||||
@@ -1852,8 +1852,8 @@ gnutls_x509_crt_get_issuer (gnutls_x509_crt_t cert, gnutls_x509_dn_t * dn)
|
||||
* Returns: Returns 0 on success, or an error code.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
|
||||
int irdn, int iava, gnutls_x509_ava_st * ava)
|
||||
MHD_gnutls_x509_dn_get_rdn_ava (MHD_gnutls_x509_dn_t dn,
|
||||
int irdn, int iava, MHD_gnutls_x509_ava_st * ava)
|
||||
{
|
||||
ASN1_TYPE rdn, elem;
|
||||
long len;
|
||||
@@ -1865,18 +1865,18 @@ gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
|
||||
irdn++; /* 0->1, 1->2 etc */
|
||||
|
||||
snprintf (rbuf, sizeof (rbuf), "rdnSequence.?%d.?%d", irdn, iava);
|
||||
rdn = asn1_find_node (dn, rbuf);
|
||||
rdn = MHD__asn1_find_node (dn, rbuf);
|
||||
if (!rdn)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_ASN1_ELEMENT_NOT_FOUND;
|
||||
}
|
||||
|
||||
snprintf (rbuf, sizeof (rbuf), "?%d.type", iava);
|
||||
elem = asn1_find_node (rdn, rbuf);
|
||||
elem = MHD__asn1_find_node (rdn, rbuf);
|
||||
if (!elem)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_ASN1_ELEMENT_NOT_FOUND;
|
||||
}
|
||||
|
||||
@@ -1884,10 +1884,10 @@ gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
|
||||
ava->oid.size = elem->value_len;
|
||||
|
||||
snprintf (rbuf, sizeof (rbuf), "?%d.value", iava);
|
||||
elem = asn1_find_node (rdn, rbuf);
|
||||
elem = MHD__asn1_find_node (rdn, rbuf);
|
||||
if (!elem)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_ASN1_ELEMENT_NOT_FOUND;
|
||||
}
|
||||
|
||||
@@ -1897,34 +1897,34 @@ gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
|
||||
|
||||
ptr = elem->value;
|
||||
remlen = elem->value_len;
|
||||
len = asn1_get_length_der (ptr, remlen, &lenlen);
|
||||
len = MHD__asn1_get_length_der (ptr, remlen, &lenlen);
|
||||
if (len < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_ASN1_DER_ERROR;
|
||||
}
|
||||
|
||||
ptr += lenlen;
|
||||
remlen -= lenlen;
|
||||
ret = asn1_get_tag_der (ptr, remlen, &cls, &lenlen, &ava->value_tag);
|
||||
ret = MHD__asn1_get_tag_der (ptr, remlen, &cls, &lenlen, &ava->value_tag);
|
||||
if (ret)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (ret);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (ret);
|
||||
}
|
||||
|
||||
ptr += lenlen;
|
||||
remlen -= lenlen;
|
||||
|
||||
ava->value.size = asn1_get_length_der (ptr, remlen, &lenlen);
|
||||
ava->value.size = MHD__asn1_get_length_der (ptr, remlen, &lenlen);
|
||||
ava->value.data = ptr + lenlen;
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_fingerprint - This function returns the Certificate's fingerprint
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_fingerprint - This function returns the Certificate's fingerprint
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @algo: is a digest algorithm
|
||||
* @buf: a pointer to a structure to hold the fingerprint (may be null)
|
||||
* @sizeof_buf: initially holds the size of @buf
|
||||
@@ -1939,14 +1939,14 @@ gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
|
||||
* with the required size. On success 0 is returned.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_fingerprint (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_fingerprint (MHD_gnutls_x509_crt_t cert,
|
||||
enum MHD_GNUTLS_HashAlgorithm algo,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
{
|
||||
opaque *cert_buf;
|
||||
int cert_buf_size;
|
||||
int result;
|
||||
gnutls_datum_t tmp;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
|
||||
if (sizeof_buf == 0 || cert == NULL)
|
||||
{
|
||||
@@ -1954,35 +1954,35 @@ gnutls_x509_crt_get_fingerprint (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
cert_buf_size = 0;
|
||||
asn1_der_coding (cert->cert, "", NULL, &cert_buf_size, NULL);
|
||||
MHD__asn1_der_coding (cert->cert, "", NULL, &cert_buf_size, NULL);
|
||||
|
||||
cert_buf = gnutls_alloca (cert_buf_size);
|
||||
cert_buf = MHD_gnutls_alloca (cert_buf_size);
|
||||
if (cert_buf == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
result = asn1_der_coding (cert->cert, "", cert_buf, &cert_buf_size, NULL);
|
||||
result = MHD__asn1_der_coding (cert->cert, "", cert_buf, &cert_buf_size, NULL);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_afree (cert_buf);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_afree (cert_buf);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
tmp.data = cert_buf;
|
||||
tmp.size = cert_buf_size;
|
||||
|
||||
result = MHD_gnutls_fingerprint (algo, &tmp, buf, sizeof_buf);
|
||||
gnutls_afree (cert_buf);
|
||||
result = MHD__gnutls_fingerprint (algo, &tmp, buf, sizeof_buf);
|
||||
MHD_gnutls_afree (cert_buf);
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_export - This function will export the certificate
|
||||
* MHD_gnutls_x509_crt_export - This function will export the certificate
|
||||
* @cert: Holds the certificate
|
||||
* @format: the format of output params. One of PEM or DER.
|
||||
* @output_data: will contain a certificate PEM or DER encoded
|
||||
@@ -2002,82 +2002,82 @@ gnutls_x509_crt_get_fingerprint (gnutls_x509_crt_t cert,
|
||||
* returned, and 0 on success.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_export (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size)
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
return _gnutls_x509_export_int (cert->cert, format, "CERTIFICATE",
|
||||
return MHD__gnutls_x509_export_int (cert->cert, format, "CERTIFICATE",
|
||||
output_data, output_data_size);
|
||||
}
|
||||
|
||||
static int
|
||||
rsadsa_get_key_id (gnutls_x509_crt_t crt,
|
||||
rsadsa_get_key_id (MHD_gnutls_x509_crt_t crt,
|
||||
int pk,
|
||||
unsigned char *output_data, size_t * output_data_size)
|
||||
{
|
||||
mpi_t params[MAX_PUBLIC_PARAMS_SIZE];
|
||||
int params_size = MAX_PUBLIC_PARAMS_SIZE;
|
||||
int i, result = 0;
|
||||
gnutls_datum_t der = { NULL,
|
||||
MHD_gnutls_datum_t der = { NULL,
|
||||
0
|
||||
};
|
||||
GNUTLS_HASH_HANDLE hd;
|
||||
|
||||
result = _gnutls_x509_crt_get_mpis (crt, params, ¶ms_size);
|
||||
result = MHD__gnutls_x509_crt_get_mpis (crt, params, ¶ms_size);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
if (pk == MHD_GNUTLS_PK_RSA)
|
||||
{
|
||||
result = _gnutls_x509_write_rsa_params (params, params_size, &der);
|
||||
result = MHD__gnutls_x509_write_rsa_params (params, params_size, &der);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
else
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
|
||||
hd = mhd_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
hd = MHD_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
if (hd == GNUTLS_HASH_FAILED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
mhd_gnutls_hash (hd, der.data, der.size);
|
||||
MHD_gnutls_hash (hd, der.data, der.size);
|
||||
|
||||
mhd_gnutls_hash_deinit (hd, output_data);
|
||||
MHD_gnutls_hash_deinit (hd, output_data);
|
||||
*output_data_size = 20;
|
||||
|
||||
result = 0;
|
||||
|
||||
cleanup:
|
||||
|
||||
_gnutls_free_datum (&der);
|
||||
MHD__gnutls_free_datum (&der);
|
||||
|
||||
/* release all allocated MPIs
|
||||
*/
|
||||
for (i = 0; i < params_size; i++)
|
||||
{
|
||||
mhd_gtls_mpi_release (¶ms[i]);
|
||||
MHD_gtls_mpi_release (¶ms[i]);
|
||||
}
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_key_id - Return unique ID of public key's parameters
|
||||
* MHD_gnutls_x509_crt_get_key_id - Return unique ID of public key's parameters
|
||||
* @crt: Holds the certificate
|
||||
* @flags: should be 0 for now
|
||||
* @output_data: will contain the key ID
|
||||
@@ -2097,31 +2097,31 @@ cleanup:
|
||||
* returned, and 0 on success.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_crt_get_key_id (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int flags,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size)
|
||||
{
|
||||
int pk, result = 0;
|
||||
gnutls_datum_t pubkey;
|
||||
MHD_gnutls_datum_t pubkey;
|
||||
|
||||
if (crt == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (*output_data_size < 20)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
*output_data_size = 20;
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
|
||||
pk = gnutls_x509_crt_get_pk_algorithm (crt, NULL);
|
||||
pk = MHD_gnutls_x509_crt_get_pk_algorithm (crt, NULL);
|
||||
if (pk < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return pk;
|
||||
}
|
||||
|
||||
@@ -2136,34 +2136,34 @@ gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
|
||||
}
|
||||
|
||||
pubkey.size = 0;
|
||||
result = asn1_der_coding (crt->cert, "tbsCertificate.subjectPublicKeyInfo",
|
||||
result = MHD__asn1_der_coding (crt->cert, "tbsCertificate.subjectPublicKeyInfo",
|
||||
NULL, &pubkey.size, NULL);
|
||||
if (result != ASN1_MEM_ERROR)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
pubkey.data = gnutls_alloca (pubkey.size);
|
||||
pubkey.data = MHD_gnutls_alloca (pubkey.size);
|
||||
if (pubkey.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
result = asn1_der_coding (crt->cert, "tbsCertificate.subjectPublicKeyInfo",
|
||||
result = MHD__asn1_der_coding (crt->cert, "tbsCertificate.subjectPublicKeyInfo",
|
||||
pubkey.data, &pubkey.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
gnutls_afree (pubkey.data);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD_gnutls_afree (pubkey.data);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = MHD_gnutls_fingerprint (MHD_GNUTLS_MAC_SHA1, &pubkey, output_data,
|
||||
result = MHD__gnutls_fingerprint (MHD_GNUTLS_MAC_SHA1, &pubkey, output_data,
|
||||
output_data_size);
|
||||
|
||||
gnutls_afree (pubkey.data);
|
||||
MHD_gnutls_afree (pubkey.data);
|
||||
|
||||
return result;
|
||||
}
|
||||
@@ -2171,9 +2171,9 @@ gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
|
||||
#ifdef ENABLE_PKI
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_check_revocation - This function checks if the given certificate is revoked
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* @crl_list: should contain a list of gnutls_x509_crl_t structures
|
||||
* MHD_gnutls_x509_crt_check_revocation - This function checks if the given certificate is revoked
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @crl_list: should contain a list of MHD_gnutls_x509_crl_t structures
|
||||
* @crl_list_length: the length of the crl_list
|
||||
*
|
||||
* This function will return check if the given certificate is
|
||||
@@ -2183,19 +2183,19 @@ gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
|
||||
* negative value is returned on error.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crl_t * crl_list,
|
||||
MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crl_t * crl_list,
|
||||
int crl_list_length)
|
||||
{
|
||||
opaque serial[64];
|
||||
opaque cert_serial[64];
|
||||
size_t serial_size, cert_serial_size;
|
||||
int ncerts, ret, i, j;
|
||||
gnutls_datum_t dn1, dn2;
|
||||
MHD_gnutls_datum_t dn1, dn2;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -2204,23 +2204,23 @@ gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
|
||||
|
||||
/* Step 1. check if issuer's DN match
|
||||
*/
|
||||
ret = _gnutls_x509_crl_get_raw_issuer_dn (crl_list[j], &dn1);
|
||||
ret = MHD__gnutls_x509_crl_get_raw_issuer_dn (crl_list[j], &dn1);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = gnutls_x509_crt_get_raw_issuer_dn (cert, &dn2);
|
||||
ret = MHD_gnutls_x509_crt_get_raw_issuer_dn (cert, &dn2);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_compare_raw_dn (&dn1, &dn2);
|
||||
_gnutls_free_datum (&dn1);
|
||||
_gnutls_free_datum (&dn2);
|
||||
ret = MHD__gnutls_x509_compare_raw_dn (&dn1, &dn2);
|
||||
MHD__gnutls_free_datum (&dn1);
|
||||
MHD__gnutls_free_datum (&dn2);
|
||||
if (ret == 0)
|
||||
{
|
||||
/* issuers do not match so don't even
|
||||
@@ -2232,10 +2232,10 @@ gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
|
||||
/* Step 2. Read the certificate's serial number
|
||||
*/
|
||||
cert_serial_size = sizeof (cert_serial);
|
||||
ret = gnutls_x509_crt_get_serial (cert, cert_serial, &cert_serial_size);
|
||||
ret = MHD_gnutls_x509_crt_get_serial (cert, cert_serial, &cert_serial_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -2243,22 +2243,22 @@ gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
|
||||
* certificate serial we have.
|
||||
*/
|
||||
|
||||
ncerts = gnutls_x509_crl_get_crt_count (crl_list[j]);
|
||||
ncerts = MHD_gnutls_x509_crl_get_crt_count (crl_list[j]);
|
||||
if (ncerts < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ncerts;
|
||||
}
|
||||
|
||||
for (i = 0; i < ncerts; i++)
|
||||
{
|
||||
serial_size = sizeof (serial);
|
||||
ret = gnutls_x509_crl_get_crt_serial (crl_list[j], i, serial,
|
||||
ret = MHD_gnutls_x509_crl_get_crt_serial (crl_list[j], i, serial,
|
||||
&serial_size, NULL);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -2277,7 +2277,7 @@ gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_verify_data - This function will verify the given signed data.
|
||||
* MHD_gnutls_x509_crt_verify_data - This function will verify the given signed data.
|
||||
* @crt: Holds the certificate
|
||||
* @flags: should be 0 for now
|
||||
* @data: holds the data to be signed
|
||||
@@ -2290,23 +2290,23 @@ gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
|
||||
* success.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_verify_data (gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_crt_verify_data (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
const gnutls_datum_t * signature)
|
||||
const MHD_gnutls_datum_t * data,
|
||||
const MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int result;
|
||||
|
||||
if (crt == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_verify_signature (data, signature, crt);
|
||||
result = MHD__gnutls_x509_verify_signature (data, signature, crt);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -2314,8 +2314,8 @@ gnutls_x509_crt_verify_data (gnutls_x509_crt_t crt,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_crl_dist_points - This function returns the CRL distribution points
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_crl_dist_points - This function returns the CRL distribution points
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @seq: specifies the sequence number of the distribution point (0 for the first one, 1 for the second etc.)
|
||||
* @ret: is the place where the distribution point will be copied to
|
||||
* @ret_size: holds the size of ret.
|
||||
@@ -2342,13 +2342,13 @@ gnutls_x509_crt_verify_data (gnutls_x509_crt_t crt,
|
||||
* Returns %GNUTLS_E_SHORT_MEMORY_BUFFER and updates &@ret_size if
|
||||
* &@ret_size is not enough to hold the distribution point, or the
|
||||
* type of the distribution point if everything was ok. The type is
|
||||
* one of the enumerated %gnutls_x509_subject_alt_name_t. If the
|
||||
* one of the enumerated %MHD_gnutls_x509_subject_alt_name_t. If the
|
||||
* certificate does not have an Alternative name with the specified
|
||||
* sequence number then %GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE is
|
||||
* returned.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_crl_dist_points (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
@@ -2356,18 +2356,18 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
unsigned int *critical)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t dist_points = { NULL,
|
||||
MHD_gnutls_datum_t dist_points = { NULL,
|
||||
0
|
||||
};
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
char name[MAX_NAME_SIZE];
|
||||
int len;
|
||||
gnutls_x509_subject_alt_name_t type;
|
||||
MHD_gnutls_x509_subject_alt_name_t type;
|
||||
uint8_t reasons[2];
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -2379,7 +2379,7 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
if (reason_flags)
|
||||
*reason_flags = 0;
|
||||
|
||||
result = _gnutls_x509_crt_get_extension (cert, "2.5.29.31", 0, &dist_points,
|
||||
result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.31", 0, &dist_points,
|
||||
critical);
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -2388,39 +2388,39 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
|
||||
if (dist_points.size == 0 || dist_points.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.CRLDistributionPoints",
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.CRLDistributionPoints",
|
||||
&c2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (&dist_points);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (&dist_points);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&c2, dist_points.data, dist_points.size, NULL);
|
||||
_gnutls_free_datum (&dist_points);
|
||||
result = MHD__asn1_der_decoding (&c2, dist_points.data, dist_points.size, NULL);
|
||||
MHD__gnutls_free_datum (&dist_points);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
/* Return the different names from the first CRLDistr. point.
|
||||
* The whole thing is a mess.
|
||||
*/
|
||||
mhd_gtls_str_cpy (name, sizeof (name), "?1.distributionPoint.fullName");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), "?1.distributionPoint.fullName");
|
||||
|
||||
result = parse_general_name (c2, name, seq, ret, ret_size, NULL, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -2430,18 +2430,18 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
*/
|
||||
if (reason_flags)
|
||||
{
|
||||
mhd_gtls_str_cpy (name, sizeof (name), "?1.reasons");
|
||||
MHD_gtls_str_cpy (name, sizeof (name), "?1.reasons");
|
||||
|
||||
reasons[0] = reasons[1] = 0;
|
||||
|
||||
len = sizeof (reasons);
|
||||
result = asn1_read_value (c2, name, reasons, &len);
|
||||
result = MHD__asn1_read_value (c2, name, reasons, &len);
|
||||
|
||||
if (result != ASN1_VALUE_NOT_FOUND && result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
*reason_flags = reasons[0] | (reasons[1] << 8);
|
||||
@@ -2451,8 +2451,8 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_key_purpose_oid - This function returns the Certificate's key purpose OIDs
|
||||
* @cert: should contain a gnutls_x509_crt_t structure
|
||||
* MHD_gnutls_x509_crt_get_key_purpose_oid - This function returns the Certificate's key purpose OIDs
|
||||
* @cert: should contain a MHD_gnutls_x509_crt_t structure
|
||||
* @indx: This specifies which OID to return. Use zero to get the first one.
|
||||
* @oid: a pointer to a buffer to hold the OID (may be null)
|
||||
* @sizeof_oid: initially holds the size of @oid
|
||||
@@ -2469,7 +2469,7 @@ gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
* with the required size. On success 0 is returned.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_get_key_purpose_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid,
|
||||
@@ -2477,12 +2477,12 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
{
|
||||
char tmpstr[MAX_NAME_SIZE];
|
||||
int result, len;
|
||||
gnutls_datum_t id;
|
||||
MHD_gnutls_datum_t id;
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
|
||||
if (cert == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -2491,7 +2491,7 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
else
|
||||
*sizeof_oid = 0;
|
||||
|
||||
if ((result = _gnutls_x509_crt_get_extension (cert, "2.5.29.37", 0, &id,
|
||||
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.37", 0, &id,
|
||||
critical)) < 0)
|
||||
{
|
||||
return result;
|
||||
@@ -2499,27 +2499,27 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
|
||||
if (id.size == 0 || id.data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE;
|
||||
}
|
||||
|
||||
result =
|
||||
asn1_create_element (_gnutls_get_pkix (), "PKIX1.ExtKeyUsageSyntax", &c2);
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.ExtKeyUsageSyntax", &c2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (&id);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (&id);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&c2, id.data, id.size, NULL);
|
||||
_gnutls_free_datum (&id);
|
||||
result = MHD__asn1_der_decoding (&c2, id.data, id.size, NULL);
|
||||
MHD__gnutls_free_datum (&id);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&c2);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
indx++;
|
||||
@@ -2528,10 +2528,10 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
snprintf (tmpstr, sizeof (tmpstr), "?%u", indx);
|
||||
|
||||
len = *sizeof_oid;
|
||||
result = asn1_read_value (c2, tmpstr, oid, &len);
|
||||
result = MHD__asn1_read_value (c2, tmpstr, oid, &len);
|
||||
|
||||
*sizeof_oid = len;
|
||||
asn1_delete_structure (&c2);
|
||||
MHD__asn1_delete_structure (&c2);
|
||||
|
||||
if (result == ASN1_VALUE_NOT_FOUND || result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -2540,8 +2540,8 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
return 0;
|
||||
@@ -2549,20 +2549,20 @@ gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_pk_rsa_raw - This function will export the RSA public key
|
||||
* MHD_gnutls_x509_crt_get_pk_rsa_raw - This function will export the RSA public key
|
||||
* @crt: Holds the certificate
|
||||
* @m: will hold the modulus
|
||||
* @e: will hold the public exponent
|
||||
*
|
||||
* This function will export the RSA public key's parameters found in
|
||||
* the given structure. The new parameters will be allocated using
|
||||
* gnutls_malloc() and will be stored in the appropriate datum.
|
||||
* MHD_gnutls_malloc() and will be stored in the appropriate datum.
|
||||
*
|
||||
* Returns: %GNUTLS_E_SUCCESS on success, otherwise an error.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
|
||||
gnutls_datum_t * m, gnutls_datum_t * e)
|
||||
MHD_gnutls_x509_crt_get_pk_rsa_raw (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_datum_t * m, MHD_gnutls_datum_t * e)
|
||||
{
|
||||
int ret;
|
||||
mpi_t params[MAX_PUBLIC_PARAMS_SIZE];
|
||||
@@ -2571,36 +2571,36 @@ gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
|
||||
|
||||
if (crt == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
ret = gnutls_x509_crt_get_pk_algorithm (crt, NULL);
|
||||
ret = MHD_gnutls_x509_crt_get_pk_algorithm (crt, NULL);
|
||||
if (ret != MHD_GNUTLS_PK_RSA)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_crt_get_mpis (crt, params, ¶ms_size);
|
||||
ret = MHD__gnutls_x509_crt_get_mpis (crt, params, ¶ms_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = mhd_gtls_mpi_dprint (m, params[0]);
|
||||
ret = MHD_gtls_mpi_dprint (m, params[0]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = mhd_gtls_mpi_dprint (e, params[1]);
|
||||
ret = MHD_gtls_mpi_dprint (e, params[1]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (m);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (m);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -2608,13 +2608,13 @@ gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
|
||||
|
||||
cleanup:for (i = 0; i < params_size; i++)
|
||||
{
|
||||
mhd_gtls_mpi_release (¶ms[i]);
|
||||
MHD_gtls_mpi_release (¶ms[i]);
|
||||
}
|
||||
return ret;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_get_pk_dsa_raw - This function will export the DSA public key
|
||||
* MHD_gnutls_x509_crt_get_pk_dsa_raw - This function will export the DSA public key
|
||||
* @crt: Holds the certificate
|
||||
* @p: will hold the p
|
||||
* @q: will hold the q
|
||||
@@ -2623,15 +2623,15 @@ cleanup:for (i = 0; i < params_size; i++)
|
||||
*
|
||||
* This function will export the DSA public key's parameters found in
|
||||
* the given certificate. The new parameters will be allocated using
|
||||
* gnutls_malloc() and will be stored in the appropriate datum.
|
||||
* MHD_gnutls_malloc() and will be stored in the appropriate datum.
|
||||
*
|
||||
* Returns: %GNUTLS_E_SUCCESS on success, otherwise an error.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * g, gnutls_datum_t * y)
|
||||
MHD_gnutls_x509_crt_get_pk_dsa_raw (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * g, MHD_gnutls_datum_t * y)
|
||||
{
|
||||
int ret;
|
||||
mpi_t params[MAX_PUBLIC_PARAMS_SIZE];
|
||||
@@ -2640,54 +2640,54 @@ gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
|
||||
|
||||
if (crt == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
ret = gnutls_x509_crt_get_pk_algorithm (crt, NULL);
|
||||
ret = MHD_gnutls_x509_crt_get_pk_algorithm (crt, NULL);
|
||||
|
||||
ret = _gnutls_x509_crt_get_mpis (crt, params, ¶ms_size);
|
||||
ret = MHD__gnutls_x509_crt_get_mpis (crt, params, ¶ms_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
/* P */
|
||||
ret = mhd_gtls_mpi_dprint (p, params[0]);
|
||||
ret = MHD_gtls_mpi_dprint (p, params[0]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Q */
|
||||
ret = mhd_gtls_mpi_dprint (q, params[1]);
|
||||
ret = MHD_gtls_mpi_dprint (q, params[1]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (p);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (p);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* G */
|
||||
ret = mhd_gtls_mpi_dprint (g, params[2]);
|
||||
ret = MHD_gtls_mpi_dprint (g, params[2]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (p);
|
||||
_gnutls_free_datum (q);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (p);
|
||||
MHD__gnutls_free_datum (q);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Y */
|
||||
ret = mhd_gtls_mpi_dprint (y, params[3]);
|
||||
ret = MHD_gtls_mpi_dprint (y, params[3]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (p);
|
||||
_gnutls_free_datum (g);
|
||||
_gnutls_free_datum (q);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (p);
|
||||
MHD__gnutls_free_datum (g);
|
||||
MHD__gnutls_free_datum (q);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -2695,7 +2695,7 @@ gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
|
||||
|
||||
cleanup:for (i = 0; i < params_size; i++)
|
||||
{
|
||||
mhd_gtls_mpi_release (¶ms[i]);
|
||||
MHD_gtls_mpi_release (¶ms[i]);
|
||||
}
|
||||
return ret;
|
||||
|
||||
@@ -2704,15 +2704,15 @@ cleanup:for (i = 0; i < params_size; i++)
|
||||
#endif
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_list_import - This function will import a PEM encoded certificate list
|
||||
* MHD_gnutls_x509_crt_list_import - This function will import a PEM encoded certificate list
|
||||
* @certs: The structures to store the parsed certificate. Must not be initialized.
|
||||
* @cert_max: Initially must hold the maximum number of certs. It will be updated with the number of certs available.
|
||||
* @data: The PEM encoded certificate.
|
||||
* @format: One of DER or PEM.
|
||||
* @flags: must be zero or an OR'd sequence of gnutls_certificate_import_flags.
|
||||
* @flags: must be zero or an OR'd sequence of MHD_gnutls_certificate_import_flags.
|
||||
*
|
||||
* This function will convert the given PEM encoded certificate list
|
||||
* to the native gnutls_x509_crt_t format. The output will be stored
|
||||
* to the native MHD_gnutls_x509_crt_t format. The output will be stored
|
||||
* in @certs. They will be automatically initialized.
|
||||
*
|
||||
* If the Certificate is PEM encoded it should have a header of "X509
|
||||
@@ -2721,14 +2721,14 @@ cleanup:for (i = 0; i < params_size; i++)
|
||||
* Returns: the number of certificates read or a negative error value.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
|
||||
MHD_gnutls_x509_crt_list_import (MHD_gnutls_x509_crt_t * certs,
|
||||
unsigned int *cert_max,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format, unsigned int flags)
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format, unsigned int flags)
|
||||
{
|
||||
int size;
|
||||
const char *ptr;
|
||||
gnutls_datum_t tmp;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
int ret, nocopy = 0;
|
||||
unsigned int count = 0, j;
|
||||
|
||||
@@ -2742,17 +2742,17 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
|
||||
|
||||
count = 1; /* import only the first one */
|
||||
|
||||
ret = gnutls_x509_crt_init (&certs[0]);
|
||||
ret = MHD_gnutls_x509_crt_init (&certs[0]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
ret = gnutls_x509_crt_import (certs[0], data, format);
|
||||
ret = MHD_gnutls_x509_crt_import (certs[0], data, format);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -2762,15 +2762,15 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
|
||||
|
||||
/* move to the certificate
|
||||
*/
|
||||
ptr = memmem (data->data, data->size,
|
||||
ptr = MHD_memmem (data->data, data->size,
|
||||
PEM_CERT_SEP, sizeof (PEM_CERT_SEP) - 1);
|
||||
if (ptr == NULL)
|
||||
ptr = memmem (data->data, data->size,
|
||||
ptr = MHD_memmem (data->data, data->size,
|
||||
PEM_CERT_SEP2, sizeof (PEM_CERT_SEP2) - 1);
|
||||
|
||||
if (ptr == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_BASE64_DECODING_ERROR;
|
||||
}
|
||||
size = data->size - (ptr - (char *) data->data);
|
||||
@@ -2789,10 +2789,10 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
|
||||
|
||||
if (!nocopy)
|
||||
{
|
||||
ret = gnutls_x509_crt_init (&certs[count]);
|
||||
ret = MHD_gnutls_x509_crt_init (&certs[count]);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -2800,10 +2800,10 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
|
||||
tmp.size = size;
|
||||
|
||||
ret =
|
||||
gnutls_x509_crt_import (certs[count], &tmp, GNUTLS_X509_FMT_PEM);
|
||||
MHD_gnutls_x509_crt_import (certs[count], &tmp, GNUTLS_X509_FMT_PEM);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
}
|
||||
@@ -2819,10 +2819,10 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
|
||||
{
|
||||
char *ptr2;
|
||||
|
||||
ptr2 = memmem (ptr, size, PEM_CERT_SEP, sizeof (PEM_CERT_SEP) - 1);
|
||||
ptr2 = MHD_memmem (ptr, size, PEM_CERT_SEP, sizeof (PEM_CERT_SEP) - 1);
|
||||
if (ptr2 == NULL)
|
||||
ptr2 =
|
||||
memmem (ptr, size, PEM_CERT_SEP2, sizeof (PEM_CERT_SEP2) - 1);
|
||||
MHD_memmem (ptr, size, PEM_CERT_SEP2, sizeof (PEM_CERT_SEP2) - 1);
|
||||
|
||||
ptr = ptr2;
|
||||
}
|
||||
@@ -2841,6 +2841,6 @@ gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
|
||||
error:for (j = 0; j < count; j++)
|
||||
gnutls_x509_crt_deinit (certs[j]);
|
||||
MHD_gnutls_x509_crt_deinit (certs[j]);
|
||||
return ret;
|
||||
}
|
||||
+317
-317
@@ -78,67 +78,67 @@ extern "C"
|
||||
|
||||
/* Certificate handling functions.
|
||||
*/
|
||||
typedef enum gnutls_certificate_import_flags
|
||||
typedef enum MHD_gnutls_certificate_import_flags
|
||||
{
|
||||
/* Fail if the certificates in the buffer are more than the space
|
||||
* allocated for certificates. The error code will be
|
||||
* GNUTLS_E_SHORT_MEMORY_BUFFER.
|
||||
*/
|
||||
GNUTLS_X509_CRT_LIST_IMPORT_FAIL_IF_EXCEED = 1
|
||||
} gnutls_certificate_import_flags;
|
||||
} MHD_gnutls_certificate_import_flags;
|
||||
|
||||
int gnutls_x509_crt_init (gnutls_x509_crt_t * cert);
|
||||
void gnutls_x509_crt_deinit (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_import (gnutls_x509_crt_t cert,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crt_list_import (gnutls_x509_crt_t * certs,
|
||||
int MHD_gnutls_x509_crt_init (MHD_gnutls_x509_crt_t * cert);
|
||||
void MHD_gnutls_x509_crt_deinit (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_import (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_crt_list_import (MHD_gnutls_x509_crt_t * certs,
|
||||
unsigned int *cert_max,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crt_export (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
int MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
int gnutls_x509_crt_get_issuer_dn (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_issuer_dn (MHD_gnutls_x509_crt_t cert,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_issuer_dn_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_issuer_dn_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid, size_t * sizeof_oid);
|
||||
int gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_issuer_dn_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_dn (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_dn (MHD_gnutls_x509_crt_t cert,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_dn_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_dn_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx, void *oid, size_t * sizeof_oid);
|
||||
int gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_dn_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_check_hostname (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_check_hostname (MHD_gnutls_x509_crt_t cert,
|
||||
const char *hostname);
|
||||
|
||||
int gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_signature (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_get_signature (MHD_gnutls_x509_crt_t cert,
|
||||
char *sig, size_t * sizeof_sig);
|
||||
int gnutls_x509_crt_get_version (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_key_id (gnutls_x509_crt_t crt,
|
||||
int MHD_gnutls_x509_crt_get_version (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_get_key_id (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int flags,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_crt_set_authority_key_id (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_set_authority_key_id (MHD_gnutls_x509_crt_t cert,
|
||||
const void *id, size_t id_size);
|
||||
int gnutls_x509_crt_get_authority_key_id (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_authority_key_id (MHD_gnutls_x509_crt_t cert,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
|
||||
int gnutls_x509_crt_get_subject_key_id (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_subject_key_id (MHD_gnutls_x509_crt_t cert,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
@@ -153,79 +153,79 @@ extern "C"
|
||||
#define GNUTLS_CRL_REASON_PRIVILEGE_WITHDRAWN 1
|
||||
#define GNUTLS_CRL_REASON_AA_COMPROMISE 32768
|
||||
|
||||
int gnutls_x509_crt_get_crl_dist_points (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_crl_dist_points (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *reason_flags,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_set_crl_dist_points (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_subject_alt_name_t
|
||||
int MHD_gnutls_x509_crt_set_crl_dist_points (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_subject_alt_name_t
|
||||
type,
|
||||
const void *data_string,
|
||||
unsigned int reason_flags);
|
||||
int gnutls_x509_crt_cpy_crl_dist_points (gnutls_x509_crt_t dst,
|
||||
gnutls_x509_crt_t src);
|
||||
int MHD_gnutls_x509_crt_cpy_crl_dist_points (MHD_gnutls_x509_crt_t dst,
|
||||
MHD_gnutls_x509_crt_t src);
|
||||
|
||||
time_t gnutls_x509_crt_get_activation_time (gnutls_x509_crt_t cert);
|
||||
time_t gnutls_x509_crt_get_expiration_time (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
|
||||
time_t MHD_gnutls_x509_crt_get_activation_time (MHD_gnutls_x509_crt_t cert);
|
||||
time_t MHD_gnutls_x509_crt_get_expiration_time (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
|
||||
void *result, size_t * result_size);
|
||||
|
||||
int gnutls_x509_crt_get_pk_algorithm (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *bits);
|
||||
int gnutls_x509_crt_get_pk_rsa_raw (gnutls_x509_crt_t crt,
|
||||
gnutls_datum_t * m, gnutls_datum_t * e);
|
||||
int gnutls_x509_crt_get_pk_dsa_raw (gnutls_x509_crt_t crt,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * g, gnutls_datum_t * y);
|
||||
int MHD_gnutls_x509_crt_get_pk_rsa_raw (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_datum_t * m, MHD_gnutls_datum_t * e);
|
||||
int MHD_gnutls_x509_crt_get_pk_dsa_raw (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * g, MHD_gnutls_datum_t * y);
|
||||
|
||||
int gnutls_x509_crt_get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_subject_alt_name2 (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_subject_alt_name2 (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *ret_type,
|
||||
unsigned int *critical);
|
||||
|
||||
int gnutls_x509_crt_get_subject_alt_othername_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_subject_alt_othername_oid (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size);
|
||||
|
||||
int gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_basic_constraints (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_basic_constraints (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *critical,
|
||||
int *ca, int *pathlen);
|
||||
|
||||
/* The key_usage flags are defined in gnutls.h. They are the
|
||||
* GNUTLS_KEY_* definitions.
|
||||
*/
|
||||
int gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_set_key_usage (gnutls_x509_crt_t crt,
|
||||
int MHD_gnutls_x509_crt_set_key_usage (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int usage);
|
||||
|
||||
int gnutls_x509_crt_get_proxy (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_proxy (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *critical,
|
||||
int *pathlen,
|
||||
char **policyLanguage,
|
||||
char **policy, size_t * sizeof_policy);
|
||||
|
||||
int gnutls_x509_dn_oid_known (const char *oid);
|
||||
int MHD_gnutls_x509_dn_oid_known (const char *oid);
|
||||
|
||||
/* Read extensions by OID. */
|
||||
int gnutls_x509_crt_get_extension_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid, size_t * sizeof_oid);
|
||||
int gnutls_x509_crt_get_extension_by_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_extension_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
void *buf,
|
||||
@@ -233,15 +233,15 @@ extern "C"
|
||||
unsigned int *critical);
|
||||
|
||||
/* Read extensions by sequence number. */
|
||||
int gnutls_x509_crt_get_extension_info (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_extension_info (MHD_gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid, int *critical);
|
||||
int gnutls_x509_crt_get_extension_data (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_extension_data (MHD_gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *data, size_t * sizeof_data);
|
||||
|
||||
int gnutls_x509_crt_set_extension_by_oid (gnutls_x509_crt_t crt,
|
||||
int MHD_gnutls_x509_crt_set_extension_by_oid (MHD_gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
const void *buf,
|
||||
size_t sizeof_buf,
|
||||
@@ -249,207 +249,207 @@ extern "C"
|
||||
|
||||
/* X.509 Certificate writing.
|
||||
*/
|
||||
int gnutls_x509_crt_set_dn_by_oid (gnutls_x509_crt_t crt,
|
||||
int MHD_gnutls_x509_crt_set_dn_by_oid (MHD_gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crt_set_issuer_dn_by_oid (gnutls_x509_crt_t crt,
|
||||
int MHD_gnutls_x509_crt_set_issuer_dn_by_oid (MHD_gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crt_set_version (gnutls_x509_crt_t crt,
|
||||
int MHD_gnutls_x509_crt_set_version (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int version);
|
||||
int gnutls_x509_crt_set_key (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_crt_set_ca_status (gnutls_x509_crt_t crt, unsigned int ca);
|
||||
int gnutls_x509_crt_set_basic_constraints (gnutls_x509_crt_t crt,
|
||||
int MHD_gnutls_x509_crt_set_key (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_crt_set_ca_status (MHD_gnutls_x509_crt_t crt, unsigned int ca);
|
||||
int MHD_gnutls_x509_crt_set_basic_constraints (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int ca,
|
||||
int pathLenConstraint);
|
||||
int gnutls_x509_crt_set_subject_alternative_name (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_subject_alt_name_t
|
||||
int MHD_gnutls_x509_crt_set_subject_alternative_name (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_subject_alt_name_t
|
||||
type,
|
||||
const char *data_string);
|
||||
int gnutls_x509_crt_sign (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key);
|
||||
int gnutls_x509_crt_sign2 (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key,
|
||||
int MHD_gnutls_x509_crt_sign (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key);
|
||||
int MHD_gnutls_x509_crt_sign2 (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crt_set_activation_time (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_set_activation_time (MHD_gnutls_x509_crt_t cert,
|
||||
time_t act_time);
|
||||
int gnutls_x509_crt_set_expiration_time (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_set_expiration_time (MHD_gnutls_x509_crt_t cert,
|
||||
time_t exp_time);
|
||||
int gnutls_x509_crt_set_serial (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_set_serial (MHD_gnutls_x509_crt_t cert,
|
||||
const void *serial, size_t serial_size);
|
||||
|
||||
int gnutls_x509_crt_set_subject_key_id (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_set_subject_key_id (MHD_gnutls_x509_crt_t cert,
|
||||
const void *id, size_t id_size);
|
||||
|
||||
int gnutls_x509_crt_set_proxy_dn (gnutls_x509_crt_t crt,
|
||||
gnutls_x509_crt_t eecrt,
|
||||
int MHD_gnutls_x509_crt_set_proxy_dn (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_crt_t eecrt,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crt_set_proxy (gnutls_x509_crt_t crt,
|
||||
int MHD_gnutls_x509_crt_set_proxy (MHD_gnutls_x509_crt_t crt,
|
||||
int pathLenConstraint,
|
||||
const char *policyLanguage,
|
||||
const char *policy, size_t sizeof_policy);
|
||||
|
||||
typedef enum gnutls_certificate_print_formats
|
||||
typedef enum MHD_gnutls_certificate_print_formats
|
||||
{
|
||||
GNUTLS_X509_CRT_FULL,
|
||||
GNUTLS_X509_CRT_ONELINE,
|
||||
GNUTLS_X509_CRT_UNSIGNED_FULL
|
||||
} gnutls_certificate_print_formats_t;
|
||||
} MHD_gnutls_certificate_print_formats_t;
|
||||
|
||||
int gnutls_x509_crt_print (gnutls_x509_crt_t cert,
|
||||
gnutls_certificate_print_formats_t format,
|
||||
gnutls_datum_t * out);
|
||||
int gnutls_x509_crl_print (gnutls_x509_crl_t crl,
|
||||
gnutls_certificate_print_formats_t format,
|
||||
gnutls_datum_t * out);
|
||||
int MHD_gnutls_x509_crt_print (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_certificate_print_formats_t format,
|
||||
MHD_gnutls_datum_t * out);
|
||||
int MHD_gnutls_x509_crl_print (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_certificate_print_formats_t format,
|
||||
MHD_gnutls_datum_t * out);
|
||||
|
||||
/* Access to internal Certificate fields.
|
||||
*/
|
||||
int gnutls_x509_crt_get_raw_issuer_dn (gnutls_x509_crt_t cert,
|
||||
gnutls_datum_t * start);
|
||||
int gnutls_x509_crt_get_raw_dn (gnutls_x509_crt_t cert,
|
||||
gnutls_datum_t * start);
|
||||
int MHD_gnutls_x509_crt_get_raw_issuer_dn (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_datum_t * start);
|
||||
int MHD_gnutls_x509_crt_get_raw_dn (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_datum_t * start);
|
||||
|
||||
/* RDN handling.
|
||||
*/
|
||||
int gnutls_x509_rdn_get (const gnutls_datum_t * idn,
|
||||
int MHD_gnutls_x509_rdn_get (const MHD_gnutls_datum_t * idn,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_rdn_get_oid (const gnutls_datum_t * idn,
|
||||
int MHD_gnutls_x509_rdn_get_oid (const MHD_gnutls_datum_t * idn,
|
||||
int indx, void *buf, size_t * sizeof_buf);
|
||||
|
||||
int gnutls_x509_rdn_get_by_oid (const gnutls_datum_t * idn,
|
||||
int MHD_gnutls_x509_rdn_get_by_oid (const MHD_gnutls_datum_t * idn,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
|
||||
typedef void *gnutls_x509_dn_t;
|
||||
typedef void *MHD_gnutls_x509_dn_t;
|
||||
|
||||
typedef struct gnutls_x509_ava_st
|
||||
typedef struct MHD_gnutls_x509_ava_st
|
||||
{
|
||||
gnutls_datum_t oid;
|
||||
gnutls_datum_t value;
|
||||
MHD_gnutls_datum_t oid;
|
||||
MHD_gnutls_datum_t value;
|
||||
unsigned long value_tag;
|
||||
} gnutls_x509_ava_st;
|
||||
} MHD_gnutls_x509_ava_st;
|
||||
|
||||
int gnutls_x509_crt_get_subject (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_dn_t * dn);
|
||||
int gnutls_x509_crt_get_issuer (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_dn_t * dn);
|
||||
int gnutls_x509_dn_get_rdn_ava (gnutls_x509_dn_t dn,
|
||||
int MHD_gnutls_x509_crt_get_subject (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_dn_t * dn);
|
||||
int MHD_gnutls_x509_crt_get_issuer (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_dn_t * dn);
|
||||
int MHD_gnutls_x509_dn_get_rdn_ava (MHD_gnutls_x509_dn_t dn,
|
||||
int irdn,
|
||||
int iava, gnutls_x509_ava_st * avast);
|
||||
int iava, MHD_gnutls_x509_ava_st * avast);
|
||||
|
||||
/* CRL handling functions.
|
||||
*/
|
||||
int gnutls_x509_crl_init (gnutls_x509_crl_t * crl);
|
||||
void gnutls_x509_crl_deinit (gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_x509_crl_init (MHD_gnutls_x509_crl_t * crl);
|
||||
void MHD_gnutls_x509_crl_deinit (MHD_gnutls_x509_crl_t crl);
|
||||
|
||||
int gnutls_x509_crl_import (gnutls_x509_crl_t crl,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crl_export (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
int MHD_gnutls_x509_crl_import (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_crl_get_issuer_dn (const gnutls_x509_crl_t crl,
|
||||
int MHD_gnutls_x509_crl_get_issuer_dn (const MHD_gnutls_x509_crl_t crl,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crl_get_issuer_dn_by_oid (gnutls_x509_crl_t crl,
|
||||
int MHD_gnutls_x509_crl_get_issuer_dn_by_oid (MHD_gnutls_x509_crl_t crl,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crl_get_dn_oid (gnutls_x509_crl_t crl,
|
||||
int MHD_gnutls_x509_crl_get_dn_oid (MHD_gnutls_x509_crl_t crl,
|
||||
int indx, void *oid, size_t * sizeof_oid);
|
||||
|
||||
int gnutls_x509_crl_get_signature_algorithm (gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_get_signature (gnutls_x509_crl_t crl,
|
||||
int MHD_gnutls_x509_crl_get_signature_algorithm (MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_x509_crl_get_signature (MHD_gnutls_x509_crl_t crl,
|
||||
char *sig, size_t * sizeof_sig);
|
||||
int gnutls_x509_crl_get_version (gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_x509_crl_get_version (MHD_gnutls_x509_crl_t crl);
|
||||
|
||||
time_t gnutls_x509_crl_get_this_update (gnutls_x509_crl_t crl);
|
||||
time_t gnutls_x509_crl_get_next_update (gnutls_x509_crl_t crl);
|
||||
time_t MHD_gnutls_x509_crl_get_this_update (MHD_gnutls_x509_crl_t crl);
|
||||
time_t MHD_gnutls_x509_crl_get_next_update (MHD_gnutls_x509_crl_t crl);
|
||||
|
||||
int gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl,
|
||||
int MHD_gnutls_x509_crl_get_crt_count (MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl,
|
||||
int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t);
|
||||
#define gnutls_x509_crl_get_certificate_count gnutls_x509_crl_get_crt_count
|
||||
#define gnutls_x509_crl_get_certificate gnutls_x509_crl_get_crt_serial
|
||||
#define MHD_gnutls_x509_crl_get_certificate_count MHD_gnutls_x509_crl_get_crt_count
|
||||
#define MHD_gnutls_x509_crl_get_certificate MHD_gnutls_x509_crl_get_crt_serial
|
||||
|
||||
int gnutls_x509_crl_check_issuer (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t issuer);
|
||||
int MHD_gnutls_x509_crl_check_issuer (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
|
||||
/* CRL writing.
|
||||
*/
|
||||
int gnutls_x509_crl_set_version (gnutls_x509_crl_t crl,
|
||||
int MHD_gnutls_x509_crl_set_version (MHD_gnutls_x509_crl_t crl,
|
||||
unsigned int version);
|
||||
int gnutls_x509_crl_sign (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key);
|
||||
int gnutls_x509_crl_sign2 (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t issuer,
|
||||
gnutls_x509_privkey_t issuer_key,
|
||||
int MHD_gnutls_x509_crl_sign (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key);
|
||||
int MHD_gnutls_x509_crl_sign2 (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crl_set_this_update (gnutls_x509_crl_t crl,
|
||||
int MHD_gnutls_x509_crl_set_this_update (MHD_gnutls_x509_crl_t crl,
|
||||
time_t act_time);
|
||||
int gnutls_x509_crl_set_next_update (gnutls_x509_crl_t crl,
|
||||
int MHD_gnutls_x509_crl_set_next_update (MHD_gnutls_x509_crl_t crl,
|
||||
time_t exp_time);
|
||||
int gnutls_x509_crl_set_crt_serial (gnutls_x509_crl_t crl,
|
||||
int MHD_gnutls_x509_crl_set_crt_serial (MHD_gnutls_x509_crl_t crl,
|
||||
const void *serial,
|
||||
size_t serial_size,
|
||||
time_t revocation_time);
|
||||
int gnutls_x509_crl_set_crt (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_t crt, time_t revocation_time);
|
||||
int MHD_gnutls_x509_crl_set_crt (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_t crt, time_t revocation_time);
|
||||
|
||||
/* PKCS7 structures handling
|
||||
*/
|
||||
struct gnutls_pkcs7_int;
|
||||
typedef struct gnutls_pkcs7_int *gnutls_pkcs7_t;
|
||||
struct MHD_gnutls_pkcs7_int;
|
||||
typedef struct MHD_gnutls_pkcs7_int *MHD_gnutls_pkcs7_t;
|
||||
|
||||
int gnutls_pkcs7_init (gnutls_pkcs7_t * pkcs7);
|
||||
void gnutls_pkcs7_deinit (gnutls_pkcs7_t pkcs7);
|
||||
int gnutls_pkcs7_import (gnutls_pkcs7_t pkcs7,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_pkcs7_export (gnutls_pkcs7_t pkcs7,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
int MHD_gnutls_pkcs7_init (MHD_gnutls_pkcs7_t * pkcs7);
|
||||
void MHD_gnutls_pkcs7_deinit (MHD_gnutls_pkcs7_t pkcs7);
|
||||
int MHD_gnutls_pkcs7_import (MHD_gnutls_pkcs7_t pkcs7,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_pkcs7_export (MHD_gnutls_pkcs7_t pkcs7,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_pkcs7_get_crt_count (gnutls_pkcs7_t pkcs7);
|
||||
int gnutls_pkcs7_get_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
int MHD_gnutls_pkcs7_get_crt_count (MHD_gnutls_pkcs7_t pkcs7);
|
||||
int MHD_gnutls_pkcs7_get_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
int indx,
|
||||
void *certificate, size_t * certificate_size);
|
||||
|
||||
int gnutls_pkcs7_set_crt_raw (gnutls_pkcs7_t pkcs7,
|
||||
const gnutls_datum_t * crt);
|
||||
int gnutls_pkcs7_set_crt (gnutls_pkcs7_t pkcs7, gnutls_x509_crt_t crt);
|
||||
int gnutls_pkcs7_delete_crt (gnutls_pkcs7_t pkcs7, int indx);
|
||||
int MHD_gnutls_pkcs7_set_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
const MHD_gnutls_datum_t * crt);
|
||||
int MHD_gnutls_pkcs7_set_crt (MHD_gnutls_pkcs7_t pkcs7, MHD_gnutls_x509_crt_t crt);
|
||||
int MHD_gnutls_pkcs7_delete_crt (MHD_gnutls_pkcs7_t pkcs7, int indx);
|
||||
|
||||
int gnutls_pkcs7_get_crl_raw (gnutls_pkcs7_t pkcs7,
|
||||
int MHD_gnutls_pkcs7_get_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
int indx, void *crl, size_t * crl_size);
|
||||
int gnutls_pkcs7_get_crl_count (gnutls_pkcs7_t pkcs7);
|
||||
int MHD_gnutls_pkcs7_get_crl_count (MHD_gnutls_pkcs7_t pkcs7);
|
||||
|
||||
int gnutls_pkcs7_set_crl_raw (gnutls_pkcs7_t pkcs7,
|
||||
const gnutls_datum_t * crt);
|
||||
int gnutls_pkcs7_set_crl (gnutls_pkcs7_t pkcs7, gnutls_x509_crl_t crl);
|
||||
int gnutls_pkcs7_delete_crl (gnutls_pkcs7_t pkcs7, int indx);
|
||||
int MHD_gnutls_pkcs7_set_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
const MHD_gnutls_datum_t * crt);
|
||||
int MHD_gnutls_pkcs7_set_crl (MHD_gnutls_pkcs7_t pkcs7, MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_pkcs7_delete_crl (MHD_gnutls_pkcs7_t pkcs7, int indx);
|
||||
|
||||
/* X.509 Certificate verification functions.
|
||||
*/
|
||||
typedef enum gnutls_certificate_verify_flags
|
||||
typedef enum MHD_gnutls_certificate_verify_flags
|
||||
{
|
||||
/* If set a signer does not have to be a certificate authority. This
|
||||
* flag should normaly be disabled, unless you know what this means.
|
||||
@@ -482,51 +482,51 @@ extern "C"
|
||||
/* Allow certificates to be signed using the broken MD5 algorithm.
|
||||
*/
|
||||
GNUTLS_VERIFY_ALLOW_SIGN_RSA_MD5 = 32
|
||||
} gnutls_certificate_verify_flags;
|
||||
} MHD_gnutls_certificate_verify_flags;
|
||||
|
||||
int gnutls_x509_crt_check_issuer (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_t issuer);
|
||||
int MHD_gnutls_x509_crt_check_issuer (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
|
||||
int gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
|
||||
int MHD_gnutls_x509_crt_list_verify (const MHD_gnutls_x509_crt_t * cert_list,
|
||||
int cert_list_length,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
const gnutls_x509_crl_t * CRL_list,
|
||||
const MHD_gnutls_x509_crl_t * CRL_list,
|
||||
int CRL_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
|
||||
int gnutls_x509_crt_verify (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
int MHD_gnutls_x509_crt_verify (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
int gnutls_x509_crl_verify (gnutls_x509_crl_t crl,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
int MHD_gnutls_x509_crl_verify (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
|
||||
int gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crl_t *
|
||||
int MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crl_t *
|
||||
crl_list, int crl_list_length);
|
||||
|
||||
int gnutls_x509_crt_get_fingerprint (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_fingerprint (MHD_gnutls_x509_crt_t cert,
|
||||
enum MHD_GNUTLS_HashAlgorithm algo,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
|
||||
int gnutls_x509_crt_get_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_key_purpose_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx,
|
||||
void *oid,
|
||||
size_t * sizeof_oid,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_set_key_purpose_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_set_key_purpose_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const void *oid,
|
||||
unsigned int critical);
|
||||
|
||||
/* Private key handling.
|
||||
*/
|
||||
|
||||
/* Flags for the gnutls_x509_privkey_export_pkcs8() function.
|
||||
/* Flags for the MHD_gnutls_x509_privkey_export_pkcs8() function.
|
||||
*/
|
||||
typedef enum gnutls_pkcs_encrypt_flags_t
|
||||
typedef enum MHD_gnutls_pkcs_encrypt_flags_t
|
||||
{
|
||||
GNUTLS_PKCS_PLAIN = 1, /* if set the private key will not
|
||||
* be encrypted.
|
||||
@@ -535,150 +535,150 @@ extern "C"
|
||||
GNUTLS_PKCS_USE_PKCS12_ARCFOUR = 4,
|
||||
GNUTLS_PKCS_USE_PKCS12_RC2_40 = 8,
|
||||
GNUTLS_PKCS_USE_PBES2_3DES = 16
|
||||
} gnutls_pkcs_encrypt_flags_t;
|
||||
} MHD_gnutls_pkcs_encrypt_flags_t;
|
||||
|
||||
#define GNUTLS_PKCS8_PLAIN GNUTLS_PKCS_PLAIN
|
||||
#define GNUTLS_PKCS8_USE_PKCS12_3DES GNUTLS_PKCS_USE_PKCS12_3DES
|
||||
#define GNUTLS_PKCS8_USE_PKCS12_ARCFOUR GNUTLS_PKCS_USE_PKCS12_ARCFOUR
|
||||
#define GNUTLS_PKCS8_USE_PKCS12_RC2_40 GNUTLS_PKCS_USE_PKCS12_RC2_40
|
||||
|
||||
int gnutls_x509_privkey_init (gnutls_x509_privkey_t * key);
|
||||
void gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst,
|
||||
gnutls_x509_privkey_t src);
|
||||
int gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_privkey_import_pkcs8 (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
int MHD_gnutls_x509_privkey_init (MHD_gnutls_x509_privkey_t * key);
|
||||
void MHD_gnutls_x509_privkey_deinit (MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_privkey_cpy (MHD_gnutls_x509_privkey_t dst,
|
||||
MHD_gnutls_x509_privkey_t src);
|
||||
int MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_privkey_import_pkcs8 (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
const char *pass, unsigned int flags);
|
||||
int gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * m,
|
||||
const gnutls_datum_t * e,
|
||||
const gnutls_datum_t * d,
|
||||
const gnutls_datum_t * p,
|
||||
const gnutls_datum_t * q,
|
||||
const gnutls_datum_t * u);
|
||||
int gnutls_x509_privkey_fix (gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_privkey_import_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * m,
|
||||
const MHD_gnutls_datum_t * e,
|
||||
const MHD_gnutls_datum_t * d,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * u);
|
||||
int MHD_gnutls_x509_privkey_fix (MHD_gnutls_x509_privkey_t key);
|
||||
|
||||
int gnutls_x509_privkey_export_dsa_raw (gnutls_x509_privkey_t key,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * g,
|
||||
gnutls_datum_t * y,
|
||||
gnutls_datum_t * x);
|
||||
int gnutls_x509_privkey_import_dsa_raw (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * p,
|
||||
const gnutls_datum_t * q,
|
||||
const gnutls_datum_t * g,
|
||||
const gnutls_datum_t * y,
|
||||
const gnutls_datum_t * x);
|
||||
int MHD_gnutls_x509_privkey_export_dsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * g,
|
||||
MHD_gnutls_datum_t * y,
|
||||
MHD_gnutls_datum_t * x);
|
||||
int MHD_gnutls_x509_privkey_import_dsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * g,
|
||||
const MHD_gnutls_datum_t * y,
|
||||
const MHD_gnutls_datum_t * x);
|
||||
|
||||
int gnutls_x509_privkey_get_pk_algorithm (gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_privkey_get_key_id (gnutls_x509_privkey_t key,
|
||||
int MHD_gnutls_x509_privkey_get_pk_algorithm (MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_privkey_get_key_id (MHD_gnutls_x509_privkey_t key,
|
||||
unsigned int flags,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
|
||||
int MHD_gnutls_x509_privkey_generate (MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
|
||||
unsigned int bits, unsigned int flags);
|
||||
|
||||
int gnutls_x509_privkey_export (gnutls_x509_privkey_t key,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
int MHD_gnutls_x509_privkey_export (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_privkey_export_pkcs8 (gnutls_x509_privkey_t key,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
int MHD_gnutls_x509_privkey_export_pkcs8 (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
const char *password,
|
||||
unsigned int flags,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
gnutls_datum_t * m,
|
||||
gnutls_datum_t * e,
|
||||
gnutls_datum_t * d,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * u);
|
||||
int MHD_gnutls_x509_privkey_export_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_datum_t * m,
|
||||
MHD_gnutls_datum_t * e,
|
||||
MHD_gnutls_datum_t * d,
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * u);
|
||||
|
||||
/* Signing stuff.
|
||||
*/
|
||||
int gnutls_x509_privkey_sign_data (gnutls_x509_privkey_t key,
|
||||
int MHD_gnutls_x509_privkey_sign_data (MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm digest,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
void *signature,
|
||||
size_t * signature_size);
|
||||
int gnutls_x509_privkey_verify_data (gnutls_x509_privkey_t key,
|
||||
int MHD_gnutls_x509_privkey_verify_data (MHD_gnutls_x509_privkey_t key,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
const gnutls_datum_t * signature);
|
||||
int gnutls_x509_crt_verify_data (gnutls_x509_crt_t crt,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
const MHD_gnutls_datum_t * signature);
|
||||
int MHD_gnutls_x509_crt_verify_data (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
const gnutls_datum_t * signature);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
const MHD_gnutls_datum_t * signature);
|
||||
|
||||
int gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * hash,
|
||||
gnutls_datum_t * signature);
|
||||
int MHD_gnutls_x509_privkey_sign_hash (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * hash,
|
||||
MHD_gnutls_datum_t * signature);
|
||||
|
||||
/* Certificate request stuff.
|
||||
*/
|
||||
struct gnutls_x509_crq_int;
|
||||
typedef struct gnutls_x509_crq_int *gnutls_x509_crq_t;
|
||||
struct MHD_gnutls_x509_crq_int;
|
||||
typedef struct MHD_gnutls_x509_crq_int *MHD_gnutls_x509_crq_t;
|
||||
|
||||
int gnutls_x509_crq_init (gnutls_x509_crq_t * crq);
|
||||
void gnutls_x509_crq_deinit (gnutls_x509_crq_t crq);
|
||||
int gnutls_x509_crq_import (gnutls_x509_crq_t crq,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crq_get_pk_algorithm (gnutls_x509_crq_t crq,
|
||||
int MHD_gnutls_x509_crq_init (MHD_gnutls_x509_crq_t * crq);
|
||||
void MHD_gnutls_x509_crq_deinit (MHD_gnutls_x509_crq_t crq);
|
||||
int MHD_gnutls_x509_crq_import (MHD_gnutls_x509_crq_t crq,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_crq_get_pk_algorithm (MHD_gnutls_x509_crq_t crq,
|
||||
unsigned int *bits);
|
||||
int gnutls_x509_crq_get_dn (gnutls_x509_crq_t crq,
|
||||
int MHD_gnutls_x509_crq_get_dn (MHD_gnutls_x509_crq_t crq,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crq_get_dn_oid (gnutls_x509_crq_t crq,
|
||||
int MHD_gnutls_x509_crq_get_dn_oid (MHD_gnutls_x509_crq_t crq,
|
||||
int indx, void *oid, size_t * sizeof_oid);
|
||||
int gnutls_x509_crq_get_dn_by_oid (gnutls_x509_crq_t crq,
|
||||
int MHD_gnutls_x509_crq_get_dn_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crq_set_dn_by_oid (gnutls_x509_crq_t crq,
|
||||
int MHD_gnutls_x509_crq_set_dn_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int gnutls_x509_crq_set_version (gnutls_x509_crq_t crq,
|
||||
int MHD_gnutls_x509_crq_set_version (MHD_gnutls_x509_crq_t crq,
|
||||
unsigned int version);
|
||||
int gnutls_x509_crq_set_key (gnutls_x509_crq_t crq,
|
||||
gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_crq_sign2 (gnutls_x509_crq_t crq,
|
||||
gnutls_x509_privkey_t key,
|
||||
int MHD_gnutls_x509_crq_set_key (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int gnutls_x509_crq_sign (gnutls_x509_crq_t crq, gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_crq_sign (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key);
|
||||
|
||||
int gnutls_x509_crq_set_challenge_password (gnutls_x509_crq_t crq,
|
||||
int MHD_gnutls_x509_crq_set_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
const char *pass);
|
||||
int gnutls_x509_crq_get_challenge_password (gnutls_x509_crq_t crq,
|
||||
int MHD_gnutls_x509_crq_get_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
char *pass,
|
||||
size_t * sizeof_pass);
|
||||
|
||||
int gnutls_x509_crq_set_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
int MHD_gnutls_x509_crq_set_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
void *buf, size_t sizeof_buf);
|
||||
int gnutls_x509_crq_get_attribute_by_oid (gnutls_x509_crq_t crq,
|
||||
int MHD_gnutls_x509_crq_get_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
int indx,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
|
||||
int gnutls_x509_crq_export (gnutls_x509_crq_t crq,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
int MHD_gnutls_x509_crq_export (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_crt_set_crq (gnutls_x509_crt_t crt, gnutls_x509_crq_t crq);
|
||||
int MHD_gnutls_x509_crt_set_crq (MHD_gnutls_x509_crt_t crt, MHD_gnutls_x509_crq_t crq);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
@@ -692,16 +692,16 @@ extern "C"
|
||||
#define HASH_OID_SHA384 "2.16.840.1.101.3.4.2.2"
|
||||
#define HASH_OID_SHA512 "2.16.840.1.101.3.4.2.3"
|
||||
|
||||
typedef struct gnutls_x509_crl_int
|
||||
typedef struct MHD_gnutls_x509_crl_int
|
||||
{
|
||||
ASN1_TYPE crl;
|
||||
} gnutls_x509_crl_int;
|
||||
} MHD_gnutls_x509_crl_int;
|
||||
|
||||
typedef struct gnutls_x509_crt_int
|
||||
typedef struct MHD_gnutls_x509_crt_int
|
||||
{
|
||||
ASN1_TYPE cert;
|
||||
int use_extensions;
|
||||
} gnutls_x509_crt_int;
|
||||
} MHD_gnutls_x509_crt_int;
|
||||
|
||||
#define MAX_PRIV_PARAMS_SIZE 6 /* ok for RSA and DSA */
|
||||
|
||||
@@ -749,100 +749,100 @@ typedef struct MHD_gtls_x509_privkey_int
|
||||
* the exported API (used internally only).
|
||||
*/
|
||||
ASN1_TYPE key;
|
||||
} gnutls_x509_privkey_int;
|
||||
} MHD_gnutls_x509_privkey_int;
|
||||
|
||||
int gnutls_x509_crt_get_issuer_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_issuer_dn_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_subject_alt_name (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_dn_by_oid (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_dn_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int gnutls_x509_crt_get_ca_status (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_pk_algorithm (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *bits);
|
||||
|
||||
int _gnutls_x509_crt_cpy (gnutls_x509_crt_t dest, gnutls_x509_crt_t src);
|
||||
int MHD__gnutls_x509_crt_cpy (MHD_gnutls_x509_crt_t dest, MHD_gnutls_x509_crt_t src);
|
||||
|
||||
int gnutls_x509_crt_get_serial (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
|
||||
void *result, size_t * result_size);
|
||||
|
||||
int _gnutls_x509_compare_raw_dn (const gnutls_datum_t * dn1,
|
||||
const gnutls_datum_t * dn2);
|
||||
int MHD__gnutls_x509_compare_raw_dn (const MHD_gnutls_datum_t * dn1,
|
||||
const MHD_gnutls_datum_t * dn2);
|
||||
|
||||
int gnutls_x509_crt_check_revocation (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crl_t * crl_list,
|
||||
int MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crl_t * crl_list,
|
||||
int crl_list_length);
|
||||
|
||||
int _gnutls_x509_crl_cpy (gnutls_x509_crl_t dest, gnutls_x509_crl_t src);
|
||||
int _gnutls_x509_crl_get_raw_issuer_dn (gnutls_x509_crl_t crl,
|
||||
gnutls_datum_t * dn);
|
||||
int gnutls_x509_crl_get_crt_count (gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_get_crt_serial (gnutls_x509_crl_t crl,
|
||||
int MHD__gnutls_x509_crl_cpy (MHD_gnutls_x509_crl_t dest, MHD_gnutls_x509_crl_t src);
|
||||
int MHD__gnutls_x509_crl_get_raw_issuer_dn (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_datum_t * dn);
|
||||
int MHD_gnutls_x509_crl_get_crt_count (MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl,
|
||||
int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t);
|
||||
|
||||
void gnutls_x509_crl_deinit (gnutls_x509_crl_t crl);
|
||||
int gnutls_x509_crl_init (gnutls_x509_crl_t * crl);
|
||||
int gnutls_x509_crl_import (gnutls_x509_crl_t crl,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crl_export (gnutls_x509_crl_t crl,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
void MHD_gnutls_x509_crl_deinit (MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_x509_crl_init (MHD_gnutls_x509_crl_t * crl);
|
||||
int MHD_gnutls_x509_crl_import (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_crt_init (gnutls_x509_crt_t * cert);
|
||||
void gnutls_x509_crt_deinit (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_import (gnutls_x509_crt_t cert,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_crt_export (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
int MHD_gnutls_x509_crt_init (MHD_gnutls_x509_crt_t * cert);
|
||||
void MHD_gnutls_x509_crt_deinit (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_import (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int gnutls_x509_crt_get_key_usage (gnutls_x509_crt_t cert,
|
||||
int MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical);
|
||||
int gnutls_x509_crt_get_signature_algorithm (gnutls_x509_crt_t cert);
|
||||
int gnutls_x509_crt_get_version (gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_get_version (MHD_gnutls_x509_crt_t cert);
|
||||
|
||||
int gnutls_x509_privkey_init (gnutls_x509_privkey_t * key);
|
||||
void gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_privkey_init (MHD_gnutls_x509_privkey_t * key);
|
||||
void MHD_gnutls_x509_privkey_deinit (MHD_gnutls_x509_privkey_t key);
|
||||
|
||||
int gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
|
||||
int MHD_gnutls_x509_privkey_generate (MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
|
||||
unsigned int bits, unsigned int flags);
|
||||
|
||||
int gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format);
|
||||
int gnutls_x509_privkey_get_pk_algorithm (gnutls_x509_privkey_t key);
|
||||
int gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * m,
|
||||
const gnutls_datum_t * e,
|
||||
const gnutls_datum_t * d,
|
||||
const gnutls_datum_t * p,
|
||||
const gnutls_datum_t * q,
|
||||
const gnutls_datum_t * u);
|
||||
int gnutls_x509_privkey_export_rsa_raw (gnutls_x509_privkey_t key,
|
||||
gnutls_datum_t * m,
|
||||
gnutls_datum_t * e,
|
||||
gnutls_datum_t * d,
|
||||
gnutls_datum_t * p,
|
||||
gnutls_datum_t * q,
|
||||
gnutls_datum_t * u);
|
||||
int gnutls_x509_privkey_export (gnutls_x509_privkey_t key,
|
||||
gnutls_x509_crt_fmt_t format,
|
||||
int MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_privkey_get_pk_algorithm (MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_privkey_import_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * m,
|
||||
const MHD_gnutls_datum_t * e,
|
||||
const MHD_gnutls_datum_t * d,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * u);
|
||||
int MHD_gnutls_x509_privkey_export_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_datum_t * m,
|
||||
MHD_gnutls_datum_t * e,
|
||||
MHD_gnutls_datum_t * d,
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * u);
|
||||
int MHD_gnutls_x509_privkey_export (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
#define GNUTLS_CRL_REASON_UNUSED 128
|
||||
|
||||
@@ -39,8 +39,8 @@
|
||||
#include <dsa.h>
|
||||
#include <verify.h>
|
||||
|
||||
static int _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params);
|
||||
int _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
|
||||
static int MHD__gnutlsMHD__asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params);
|
||||
int MHD__gnutlsMHD__asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
|
||||
|
||||
/* remove this when libgcrypt can handle the PKCS #1 coefficients from
|
||||
* rsa keys
|
||||
@@ -48,7 +48,7 @@ int _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
|
||||
#define CALC_COEFF 1
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_init - This function initializes a gnutls_crl structure
|
||||
* MHD_gnutls_x509_privkey_init - This function initializes a MHD_gnutls_crl structure
|
||||
* @key: The structure to be initialized
|
||||
*
|
||||
* This function will initialize an private key structure.
|
||||
@@ -57,9 +57,9 @@ int _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_init (gnutls_x509_privkey_t * key)
|
||||
MHD_gnutls_x509_privkey_init (MHD_gnutls_x509_privkey_t * key)
|
||||
{
|
||||
*key = gnutls_calloc (1, sizeof (gnutls_x509_privkey_int));
|
||||
*key = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_x509_privkey_int));
|
||||
|
||||
if (*key)
|
||||
{
|
||||
@@ -72,14 +72,14 @@ gnutls_x509_privkey_init (gnutls_x509_privkey_t * key)
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_deinit - This function deinitializes memory used by a gnutls_x509_privkey_t structure
|
||||
* MHD_gnutls_x509_privkey_deinit - This function deinitializes memory used by a MHD_gnutls_x509_privkey_t structure
|
||||
* @key: The structure to be initialized
|
||||
*
|
||||
* This function will deinitialize a private key structure.
|
||||
*
|
||||
**/
|
||||
void
|
||||
gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key)
|
||||
MHD_gnutls_x509_privkey_deinit (MHD_gnutls_x509_privkey_t key)
|
||||
{
|
||||
int i;
|
||||
|
||||
@@ -88,15 +88,15 @@ gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key)
|
||||
|
||||
for (i = 0; i < key->params_size; i++)
|
||||
{
|
||||
mhd_gtls_mpi_release (&key->params[i]);
|
||||
MHD_gtls_mpi_release (&key->params[i]);
|
||||
}
|
||||
|
||||
asn1_delete_structure (&key->key);
|
||||
gnutls_free (key);
|
||||
MHD__asn1_delete_structure (&key->key);
|
||||
MHD_gnutls_free (key);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_cpy - This function copies a private key
|
||||
* MHD_gnutls_x509_privkey_cpy - This function copies a private key
|
||||
* @dst: The destination key, which should be initialized.
|
||||
* @src: The source key
|
||||
*
|
||||
@@ -104,7 +104,7 @@ gnutls_x509_privkey_deinit (gnutls_x509_privkey_t key)
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst, gnutls_x509_privkey_t src)
|
||||
MHD_gnutls_x509_privkey_cpy (MHD_gnutls_x509_privkey_t dst, MHD_gnutls_x509_privkey_t src)
|
||||
{
|
||||
int i, ret;
|
||||
|
||||
@@ -113,7 +113,7 @@ gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst, gnutls_x509_privkey_t src)
|
||||
|
||||
for (i = 0; i < src->params_size; i++)
|
||||
{
|
||||
dst->params[i] = _gnutls_mpi_copy (src->params[i]);
|
||||
dst->params[i] = MHD__gnutls_mpi_copy (src->params[i]);
|
||||
if (dst->params[i] == NULL)
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
@@ -127,15 +127,15 @@ gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst, gnutls_x509_privkey_t src)
|
||||
switch (dst->pk_algorithm)
|
||||
{
|
||||
case MHD_GNUTLS_PK_RSA:
|
||||
ret = _gnutls_asn1_encode_rsa (&dst->key, dst->params);
|
||||
ret = MHD__gnutlsMHD__asn1_encode_rsa (&dst->key, dst->params);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
}
|
||||
@@ -144,69 +144,69 @@ gnutls_x509_privkey_cpy (gnutls_x509_privkey_t dst, gnutls_x509_privkey_t src)
|
||||
}
|
||||
|
||||
/* Converts an RSA PKCS#1 key to
|
||||
* an internal structure (gnutls_private_key)
|
||||
* an internal structure (MHD_gnutls_private_key)
|
||||
*/
|
||||
ASN1_TYPE
|
||||
_gnutls_privkey_decode_pkcs1_rsa_key (const gnutls_datum_t * raw_key,
|
||||
gnutls_x509_privkey_t pkey)
|
||||
MHD__gnutls_privkey_decode_pkcs1_rsa_key (const MHD_gnutls_datum_t * raw_key,
|
||||
MHD_gnutls_x509_privkey_t pkey)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE pkey_asn;
|
||||
|
||||
if ((result = asn1_create_element (_gnutls_get_gnutls_asn (),
|
||||
if ((result = MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.RSAPrivateKey",
|
||||
&pkey_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return NULL;
|
||||
}
|
||||
|
||||
if ((sizeof (pkey->params) / sizeof (mpi_t)) < RSA_PRIVATE_PARAMS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
/* internal error. Increase the mpi_ts in params */
|
||||
return NULL;
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&pkey_asn, raw_key->data, raw_key->size, NULL);
|
||||
result = MHD__asn1_der_decoding (&pkey_asn, raw_key->data, raw_key->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = _gnutls_x509_read_int (pkey_asn, "modulus", &pkey->params[0]))
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "modulus", &pkey->params[0]))
|
||||
< 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = _gnutls_x509_read_int (pkey_asn, "publicExponent",
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "publicExponent",
|
||||
&pkey->params[1])) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = _gnutls_x509_read_int (pkey_asn, "privateExponent",
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "privateExponent",
|
||||
&pkey->params[2])) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = _gnutls_x509_read_int (pkey_asn, "prime1", &pkey->params[3]))
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "prime1", &pkey->params[3]))
|
||||
< 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = _gnutls_x509_read_int (pkey_asn, "prime2", &pkey->params[4]))
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "prime2", &pkey->params[4]))
|
||||
< 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
@@ -215,21 +215,21 @@ _gnutls_privkey_decode_pkcs1_rsa_key (const gnutls_datum_t * raw_key,
|
||||
* library is uses the p,q in the reverse order.
|
||||
*/
|
||||
pkey->params[5] =
|
||||
_gnutls_mpi_snew (_gnutls_mpi_get_nbits (pkey->params[0]));
|
||||
MHD__gnutls_mpi_snew (MHD__gnutls_mpi_get_nbits (pkey->params[0]));
|
||||
|
||||
if (pkey->params[5] == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
_gnutls_mpi_invm (pkey->params[5], pkey->params[3], pkey->params[4]);
|
||||
MHD__gnutls_mpi_invm (pkey->params[5], pkey->params[3], pkey->params[4]);
|
||||
/* p, q */
|
||||
#else
|
||||
if ((result = _gnutls_x509_read_int (pkey_asn, "coefficient",
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "coefficient",
|
||||
&pkey->params[5])) < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
#endif
|
||||
@@ -237,13 +237,13 @@ _gnutls_privkey_decode_pkcs1_rsa_key (const gnutls_datum_t * raw_key,
|
||||
|
||||
return pkey_asn;
|
||||
|
||||
error:asn1_delete_structure (&pkey_asn);
|
||||
mhd_gtls_mpi_release (&pkey->params[0]);
|
||||
mhd_gtls_mpi_release (&pkey->params[1]);
|
||||
mhd_gtls_mpi_release (&pkey->params[2]);
|
||||
mhd_gtls_mpi_release (&pkey->params[3]);
|
||||
mhd_gtls_mpi_release (&pkey->params[4]);
|
||||
mhd_gtls_mpi_release (&pkey->params[5]);
|
||||
error:MHD__asn1_delete_structure (&pkey_asn);
|
||||
MHD_gtls_mpi_release (&pkey->params[0]);
|
||||
MHD_gtls_mpi_release (&pkey->params[1]);
|
||||
MHD_gtls_mpi_release (&pkey->params[2]);
|
||||
MHD_gtls_mpi_release (&pkey->params[3]);
|
||||
MHD_gtls_mpi_release (&pkey->params[4]);
|
||||
MHD_gtls_mpi_release (&pkey->params[5]);
|
||||
return NULL;
|
||||
|
||||
}
|
||||
@@ -251,13 +251,13 @@ error:asn1_delete_structure (&pkey_asn);
|
||||
#define PEM_KEY_RSA "RSA PRIVATE KEY"
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_import - This function will import a DER or PEM encoded key
|
||||
* MHD_gnutls_x509_privkey_import - This function will import a DER or PEM encoded key
|
||||
* @key: The structure to store the parsed key
|
||||
* @data: The DER or PEM encoded certificate.
|
||||
* @format: One of DER or PEM
|
||||
*
|
||||
* This function will convert the given DER or PEM encoded key
|
||||
* to the native gnutls_x509_privkey_t format. The output will be stored in @key .
|
||||
* to the native MHD_gnutls_x509_privkey_t format. The output will be stored in @key .
|
||||
*
|
||||
* If the key is PEM encoded it should have a header of "RSA PRIVATE KEY", or
|
||||
* "DSA PRIVATE KEY".
|
||||
@@ -266,16 +266,16 @@ error:asn1_delete_structure (&pkey_asn);
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * data,
|
||||
gnutls_x509_crt_fmt_t format)
|
||||
MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
gnutls_datum_t _data;
|
||||
MHD_gnutls_datum_t _data;
|
||||
|
||||
if (key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -291,7 +291,7 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
|
||||
/* Try the first header */
|
||||
result
|
||||
= _gnutls_fbase64_decode (PEM_KEY_RSA, data->data, data->size, &out);
|
||||
= MHD__gnutls_fbase64_decode (PEM_KEY_RSA, data->data, data->size, &out);
|
||||
key->pk_algorithm = MHD_GNUTLS_PK_RSA;
|
||||
|
||||
_data.data = out;
|
||||
@@ -302,15 +302,15 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
|
||||
if (key->pk_algorithm == MHD_GNUTLS_PK_RSA)
|
||||
{
|
||||
key->key = _gnutls_privkey_decode_pkcs1_rsa_key (&_data, key);
|
||||
key->key = MHD__gnutls_privkey_decode_pkcs1_rsa_key (&_data, key);
|
||||
if (key->key == NULL)
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
}
|
||||
else
|
||||
{
|
||||
/* Try decoding with both, and accept the one that succeeds. */
|
||||
key->pk_algorithm = MHD_GNUTLS_PK_RSA;
|
||||
key->key = _gnutls_privkey_decode_pkcs1_rsa_key (&_data, key);
|
||||
key->key = MHD__gnutls_privkey_decode_pkcs1_rsa_key (&_data, key);
|
||||
|
||||
// TODO rm
|
||||
// if (key->key == NULL)
|
||||
@@ -318,20 +318,20 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
// key->pk_algorithm = GNUTLS_PK_DSA;
|
||||
// key->key = decode_dsa_key(&_data, key);
|
||||
// if (key->key == NULL)
|
||||
// gnutls_assert();
|
||||
// MHD_gnutls_assert();
|
||||
// }
|
||||
}
|
||||
|
||||
if (key->key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_ASN1_DER_ERROR;
|
||||
key->pk_algorithm = MHD_GNUTLS_PK_UNKNOWN;
|
||||
return result;
|
||||
}
|
||||
|
||||
if (need_free)
|
||||
_gnutls_free_datum (&_data);
|
||||
MHD__gnutls_free_datum (&_data);
|
||||
|
||||
/* The key has now been decoded.
|
||||
*/
|
||||
@@ -340,12 +340,12 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
#define FREE_RSA_PRIVATE_PARAMS for (i=0;i<RSA_PRIVATE_PARAMS;i++) \
|
||||
mhd_gtls_mpi_release(&key->params[i])
|
||||
MHD_gtls_mpi_release(&key->params[i])
|
||||
#define FREE_DSA_PRIVATE_PARAMS for (i=0;i<DSA_PRIVATE_PARAMS;i++) \
|
||||
mhd_gtls_mpi_release(&key->params[i])
|
||||
MHD_gtls_mpi_release(&key->params[i])
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_import_rsa_raw - This function will import a raw RSA key
|
||||
* MHD_gnutls_x509_privkey_import_rsa_raw - This function will import a raw RSA key
|
||||
* @key: The structure to store the parsed key
|
||||
* @m: holds the modulus
|
||||
* @e: holds the public exponent
|
||||
@@ -355,83 +355,83 @@ gnutls_x509_privkey_import (gnutls_x509_privkey_t key,
|
||||
* @u: holds the coefficient
|
||||
*
|
||||
* This function will convert the given RSA raw parameters
|
||||
* to the native gnutls_x509_privkey_t format. The output will be stored in @key.
|
||||
* to the native MHD_gnutls_x509_privkey_t format. The output will be stored in @key.
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * m,
|
||||
const gnutls_datum_t * e,
|
||||
const gnutls_datum_t * d,
|
||||
const gnutls_datum_t * p,
|
||||
const gnutls_datum_t * q,
|
||||
const gnutls_datum_t * u)
|
||||
MHD_gnutls_x509_privkey_import_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * m,
|
||||
const MHD_gnutls_datum_t * e,
|
||||
const MHD_gnutls_datum_t * d,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * u)
|
||||
{
|
||||
int i = 0, ret;
|
||||
size_t siz = 0;
|
||||
|
||||
if (key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
siz = m->size;
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[0], m->data, &siz))
|
||||
if (MHD_gtls_mpi_scan_nz (&key->params[0], m->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
return GNUTLS_E_MPI_SCAN_FAILED;
|
||||
}
|
||||
|
||||
siz = e->size;
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[1], e->data, &siz))
|
||||
if (MHD_gtls_mpi_scan_nz (&key->params[1], e->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
return GNUTLS_E_MPI_SCAN_FAILED;
|
||||
}
|
||||
|
||||
siz = d->size;
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[2], d->data, &siz))
|
||||
if (MHD_gtls_mpi_scan_nz (&key->params[2], d->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
return GNUTLS_E_MPI_SCAN_FAILED;
|
||||
}
|
||||
|
||||
siz = p->size;
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[3], p->data, &siz))
|
||||
if (MHD_gtls_mpi_scan_nz (&key->params[3], p->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
return GNUTLS_E_MPI_SCAN_FAILED;
|
||||
}
|
||||
|
||||
siz = q->size;
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[4], q->data, &siz))
|
||||
if (MHD_gtls_mpi_scan_nz (&key->params[4], q->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
return GNUTLS_E_MPI_SCAN_FAILED;
|
||||
}
|
||||
|
||||
#ifdef CALC_COEFF
|
||||
key->params[5] = _gnutls_mpi_snew (_gnutls_mpi_get_nbits (key->params[0]));
|
||||
key->params[5] = MHD__gnutls_mpi_snew (MHD__gnutls_mpi_get_nbits (key->params[0]));
|
||||
|
||||
if (key->params[5] == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
_gnutls_mpi_invm (key->params[5], key->params[3], key->params[4]);
|
||||
MHD__gnutls_mpi_invm (key->params[5], key->params[3], key->params[4]);
|
||||
#else
|
||||
siz = u->size;
|
||||
if (mhd_gtls_mpi_scan_nz (&key->params[5], u->data, &siz))
|
||||
if (MHD_gtls_mpi_scan_nz (&key->params[5], u->data, &siz))
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
return GNUTLS_E_MPI_SCAN_FAILED;
|
||||
}
|
||||
@@ -439,10 +439,10 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
|
||||
if (!key->crippled)
|
||||
{
|
||||
ret = _gnutls_asn1_encode_rsa (&key->key, key->params);
|
||||
ret = MHD__gnutlsMHD__asn1_encode_rsa (&key->key, key->params);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
FREE_RSA_PRIVATE_PARAMS;
|
||||
return ret;
|
||||
}
|
||||
@@ -456,8 +456,8 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_get_pk_algorithm - This function returns the key's PublicKey algorithm
|
||||
* @key: should contain a gnutls_x509_privkey_t structure
|
||||
* MHD_gnutls_x509_privkey_get_pk_algorithm - This function returns the key's PublicKey algorithm
|
||||
* @key: should contain a MHD_gnutls_x509_privkey_t structure
|
||||
*
|
||||
* This function will return the public key algorithm of a private
|
||||
* key.
|
||||
@@ -467,11 +467,11 @@ gnutls_x509_privkey_import_rsa_raw (gnutls_x509_privkey_t key,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_get_pk_algorithm (gnutls_x509_privkey_t key)
|
||||
MHD_gnutls_x509_privkey_get_pk_algorithm (MHD_gnutls_x509_privkey_t key)
|
||||
{
|
||||
if (key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -481,7 +481,7 @@ gnutls_x509_privkey_get_pk_algorithm (gnutls_x509_privkey_t key)
|
||||
/* Encodes the RSA parameters into an ASN.1 RSA private key structure.
|
||||
*/
|
||||
static int
|
||||
_gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
MHD__gnutlsMHD__asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
{
|
||||
int result, i;
|
||||
size_t size[8], total;
|
||||
@@ -495,77 +495,77 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
total = 0;
|
||||
for (i = 0; i < 5; i++)
|
||||
{
|
||||
mhd_gtls_mpi_print_lz (NULL, &size[i], params[i]);
|
||||
MHD_gtls_mpi_print_lz (NULL, &size[i], params[i]);
|
||||
total += size[i];
|
||||
}
|
||||
|
||||
/* Now generate exp1 and exp2
|
||||
*/
|
||||
exp1 = _gnutls_mpi_salloc_like (params[0]); /* like modulus */
|
||||
exp1 = MHD__gnutls_mpi_salloc_like (params[0]); /* like modulus */
|
||||
if (exp1 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
exp2 = _gnutls_mpi_salloc_like (params[0]);
|
||||
exp2 = MHD__gnutls_mpi_salloc_like (params[0]);
|
||||
if (exp2 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
q1 = _gnutls_mpi_salloc_like (params[4]);
|
||||
q1 = MHD__gnutls_mpi_salloc_like (params[4]);
|
||||
if (q1 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
p1 = _gnutls_mpi_salloc_like (params[3]);
|
||||
p1 = MHD__gnutls_mpi_salloc_like (params[3]);
|
||||
if (p1 == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
u = _gnutls_mpi_salloc_like (params[3]);
|
||||
u = MHD__gnutls_mpi_salloc_like (params[3]);
|
||||
if (u == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
_gnutls_mpi_invm (u, params[4], params[3]);
|
||||
MHD__gnutls_mpi_invm (u, params[4], params[3]);
|
||||
/* inverse of q mod p */
|
||||
mhd_gtls_mpi_print_lz (NULL, &size[5], u);
|
||||
MHD_gtls_mpi_print_lz (NULL, &size[5], u);
|
||||
total += size[5];
|
||||
|
||||
_gnutls_mpi_sub_ui (p1, params[3], 1);
|
||||
_gnutls_mpi_sub_ui (q1, params[4], 1);
|
||||
MHD__gnutls_mpi_sub_ui (p1, params[3], 1);
|
||||
MHD__gnutls_mpi_sub_ui (q1, params[4], 1);
|
||||
|
||||
_gnutls_mpi_mod (exp1, params[2], p1);
|
||||
_gnutls_mpi_mod (exp2, params[2], q1);
|
||||
MHD__gnutls_mpi_mod (exp1, params[2], p1);
|
||||
MHD__gnutls_mpi_mod (exp2, params[2], q1);
|
||||
|
||||
/* calculate exp's size */
|
||||
mhd_gtls_mpi_print_lz (NULL, &size[6], exp1);
|
||||
MHD_gtls_mpi_print_lz (NULL, &size[6], exp1);
|
||||
total += size[6];
|
||||
|
||||
mhd_gtls_mpi_print_lz (NULL, &size[7], exp2);
|
||||
MHD_gtls_mpi_print_lz (NULL, &size[7], exp2);
|
||||
total += size[7];
|
||||
|
||||
/* Encoding phase.
|
||||
* allocate data enough to hold everything
|
||||
*/
|
||||
all_data = gnutls_secure_malloc (total);
|
||||
all_data = MHD_gnutls_secure_malloc (total);
|
||||
if (all_data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
@@ -587,124 +587,124 @@ _gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
p += size[6];
|
||||
exp2_data = p;
|
||||
|
||||
mhd_gtls_mpi_print_lz (m_data, &size[0], params[0]);
|
||||
mhd_gtls_mpi_print_lz (pube_data, &size[1], params[1]);
|
||||
mhd_gtls_mpi_print_lz (prie_data, &size[2], params[2]);
|
||||
mhd_gtls_mpi_print_lz (p1_data, &size[3], params[3]);
|
||||
mhd_gtls_mpi_print_lz (p2_data, &size[4], params[4]);
|
||||
mhd_gtls_mpi_print_lz (u_data, &size[5], u);
|
||||
mhd_gtls_mpi_print_lz (exp1_data, &size[6], exp1);
|
||||
mhd_gtls_mpi_print_lz (exp2_data, &size[7], exp2);
|
||||
MHD_gtls_mpi_print_lz (m_data, &size[0], params[0]);
|
||||
MHD_gtls_mpi_print_lz (pube_data, &size[1], params[1]);
|
||||
MHD_gtls_mpi_print_lz (prie_data, &size[2], params[2]);
|
||||
MHD_gtls_mpi_print_lz (p1_data, &size[3], params[3]);
|
||||
MHD_gtls_mpi_print_lz (p2_data, &size[4], params[4]);
|
||||
MHD_gtls_mpi_print_lz (u_data, &size[5], u);
|
||||
MHD_gtls_mpi_print_lz (exp1_data, &size[6], exp1);
|
||||
MHD_gtls_mpi_print_lz (exp2_data, &size[7], exp2);
|
||||
|
||||
/* Ok. Now we have the data. Create the asn1 structures
|
||||
*/
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.RSAPrivateKey",
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.RSAPrivateKey",
|
||||
c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Write PRIME
|
||||
*/
|
||||
if ((result = asn1_write_value (*c2, "modulus", m_data, size[0]))
|
||||
if ((result = MHD__asn1_write_value (*c2, "modulus", m_data, size[0]))
|
||||
!= ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "publicExponent", pube_data, size[1]))
|
||||
if ((result = MHD__asn1_write_value (*c2, "publicExponent", pube_data, size[1]))
|
||||
!= ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "privateExponent", prie_data, size[2]))
|
||||
if ((result = MHD__asn1_write_value (*c2, "privateExponent", prie_data, size[2]))
|
||||
!= ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "prime1", p1_data, size[3]))
|
||||
if ((result = MHD__asn1_write_value (*c2, "prime1", p1_data, size[3]))
|
||||
!= ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "prime2", p2_data, size[4]))
|
||||
if ((result = MHD__asn1_write_value (*c2, "prime2", p2_data, size[4]))
|
||||
!= ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "exponent1", exp1_data, size[6]))
|
||||
if ((result = MHD__asn1_write_value (*c2, "exponent1", exp1_data, size[6]))
|
||||
!= ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "exponent2", exp2_data, size[7]))
|
||||
if ((result = MHD__asn1_write_value (*c2, "exponent2", exp2_data, size[7]))
|
||||
!= ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "coefficient", u_data, size[5]))
|
||||
if ((result = MHD__asn1_write_value (*c2, "coefficient", u_data, size[5]))
|
||||
!= ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
mhd_gtls_mpi_release (&exp1);
|
||||
mhd_gtls_mpi_release (&exp2);
|
||||
mhd_gtls_mpi_release (&q1);
|
||||
mhd_gtls_mpi_release (&p1);
|
||||
mhd_gtls_mpi_release (&u);
|
||||
gnutls_free (all_data);
|
||||
MHD_gtls_mpi_release (&exp1);
|
||||
MHD_gtls_mpi_release (&exp2);
|
||||
MHD_gtls_mpi_release (&q1);
|
||||
MHD_gtls_mpi_release (&p1);
|
||||
MHD_gtls_mpi_release (&u);
|
||||
MHD_gnutls_free (all_data);
|
||||
|
||||
if ((result = asn1_write_value (*c2, "otherPrimeInfos",
|
||||
if ((result = MHD__asn1_write_value (*c2, "otherPrimeInfos",
|
||||
NULL, 0)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:mhd_gtls_mpi_release (&u);
|
||||
mhd_gtls_mpi_release (&exp1);
|
||||
mhd_gtls_mpi_release (&exp2);
|
||||
mhd_gtls_mpi_release (&q1);
|
||||
mhd_gtls_mpi_release (&p1);
|
||||
asn1_delete_structure (c2);
|
||||
gnutls_free (all_data);
|
||||
cleanup:MHD_gtls_mpi_release (&u);
|
||||
MHD_gtls_mpi_release (&exp1);
|
||||
MHD_gtls_mpi_release (&exp2);
|
||||
MHD_gtls_mpi_release (&q1);
|
||||
MHD_gtls_mpi_release (&p1);
|
||||
MHD__asn1_delete_structure (c2);
|
||||
MHD_gnutls_free (all_data);
|
||||
|
||||
return result;
|
||||
}
|
||||
@@ -712,7 +712,7 @@ cleanup:mhd_gtls_mpi_release (&u);
|
||||
/* Encodes the DSA parameters into an ASN.1 DSAPrivateKey structure.
|
||||
*/
|
||||
int
|
||||
_gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
MHD__gnutlsMHD__asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
{
|
||||
int result, i;
|
||||
size_t size[DSA_PRIVATE_PARAMS], total;
|
||||
@@ -724,17 +724,17 @@ _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
total = 0;
|
||||
for (i = 0; i < DSA_PRIVATE_PARAMS; i++)
|
||||
{
|
||||
mhd_gtls_mpi_print_lz (NULL, &size[i], params[i]);
|
||||
MHD_gtls_mpi_print_lz (NULL, &size[i], params[i]);
|
||||
total += size[i];
|
||||
}
|
||||
|
||||
/* Encoding phase.
|
||||
* allocate data enough to hold everything
|
||||
*/
|
||||
all_data = gnutls_secure_malloc (total);
|
||||
all_data = MHD_gnutls_secure_malloc (total);
|
||||
if (all_data == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_MEMORY_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
@@ -750,82 +750,82 @@ _gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
p += size[3];
|
||||
x_data = p;
|
||||
|
||||
mhd_gtls_mpi_print_lz (p_data, &size[0], params[0]);
|
||||
mhd_gtls_mpi_print_lz (q_data, &size[1], params[1]);
|
||||
mhd_gtls_mpi_print_lz (g_data, &size[2], params[2]);
|
||||
mhd_gtls_mpi_print_lz (y_data, &size[3], params[3]);
|
||||
mhd_gtls_mpi_print_lz (x_data, &size[4], params[4]);
|
||||
MHD_gtls_mpi_print_lz (p_data, &size[0], params[0]);
|
||||
MHD_gtls_mpi_print_lz (q_data, &size[1], params[1]);
|
||||
MHD_gtls_mpi_print_lz (g_data, &size[2], params[2]);
|
||||
MHD_gtls_mpi_print_lz (y_data, &size[3], params[3]);
|
||||
MHD_gtls_mpi_print_lz (x_data, &size[4], params[4]);
|
||||
|
||||
/* Ok. Now we have the data. Create the asn1 structures
|
||||
*/
|
||||
|
||||
if ((result =
|
||||
asn1_create_element (_gnutls_get_gnutls_asn (), "GNUTLS.DSAPrivateKey",
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAPrivateKey",
|
||||
c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Write PRIME
|
||||
*/
|
||||
if ((result = asn1_write_value (*c2, "p", p_data, size[0])) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_write_value (*c2, "p", p_data, size[0])) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "q", q_data, size[1])) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_write_value (*c2, "q", q_data, size[1])) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "g", g_data, size[2])) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_write_value (*c2, "g", g_data, size[2])) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = asn1_write_value (*c2, "Y", y_data, size[3])) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_write_value (*c2, "Y", y_data, size[3])) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result =
|
||||
asn1_write_value (*c2, "priv", x_data, size[4])) != ASN1_SUCCESS)
|
||||
MHD__asn1_write_value (*c2, "priv", x_data, size[4])) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
gnutls_free (all_data);
|
||||
MHD_gnutls_free (all_data);
|
||||
|
||||
if ((result = asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
|
||||
if ((result = MHD__asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
result = mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
cleanup:asn1_delete_structure (c2);
|
||||
gnutls_free (all_data);
|
||||
cleanup:MHD__asn1_delete_structure (c2);
|
||||
MHD_gnutls_free (all_data);
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_generate - This function will generate a private key
|
||||
* @key: should contain a gnutls_x509_privkey_t structure
|
||||
* MHD_gnutls_x509_privkey_generate - This function will generate a private key
|
||||
* @key: should contain a MHD_gnutls_x509_privkey_t structure
|
||||
* @algo: is one of RSA or DSA.
|
||||
* @bits: the size of the modulus
|
||||
* @flags: unused for now. Must be 0.
|
||||
@@ -837,7 +837,7 @@ cleanup:asn1_delete_structure (c2);
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_privkey_generate (MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
|
||||
unsigned int bits, unsigned int flags)
|
||||
{
|
||||
@@ -846,26 +846,26 @@ gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
|
||||
|
||||
if (key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
switch (algo)
|
||||
{
|
||||
case MHD_GNUTLS_PK_RSA:
|
||||
ret = _gnutls_rsa_generate_params (key->params, ¶ms_len, bits);
|
||||
ret = MHD__gnutls_rsa_generate_params (key->params, ¶ms_len, bits);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
if (!key->crippled)
|
||||
{
|
||||
ret = _gnutls_asn1_encode_rsa (&key->key, key->params);
|
||||
ret = MHD__gnutlsMHD__asn1_encode_rsa (&key->key, key->params);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
@@ -875,7 +875,7 @@ gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
|
||||
|
||||
break;
|
||||
default:
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
@@ -884,13 +884,13 @@ gnutls_x509_privkey_generate (gnutls_x509_privkey_t key,
|
||||
cleanup:key->pk_algorithm = MHD_GNUTLS_PK_UNKNOWN;
|
||||
key->params_size = 0;
|
||||
for (i = 0; i < params_len; i++)
|
||||
mhd_gtls_mpi_release (&key->params[i]);
|
||||
MHD_gtls_mpi_release (&key->params[i]);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_get_key_id - Return unique ID of the key's parameters
|
||||
* MHD_gnutls_x509_privkey_get_key_id - Return unique ID of the key's parameters
|
||||
* @key: Holds the key
|
||||
* @flags: should be 0 for now
|
||||
* @output_data: will contain the key ID
|
||||
@@ -911,68 +911,68 @@ cleanup:key->pk_algorithm = MHD_GNUTLS_PK_UNKNOWN;
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_get_key_id (gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_privkey_get_key_id (MHD_gnutls_x509_privkey_t key,
|
||||
unsigned int flags,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size)
|
||||
{
|
||||
int result;
|
||||
GNUTLS_HASH_HANDLE hd;
|
||||
gnutls_datum_t der = { NULL,
|
||||
MHD_gnutls_datum_t der = { NULL,
|
||||
0
|
||||
};
|
||||
|
||||
if (key == NULL || key->crippled)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (*output_data_size < 20)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
*output_data_size = 20;
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
|
||||
if (key->pk_algorithm == MHD_GNUTLS_PK_RSA)
|
||||
{
|
||||
result = _gnutls_x509_write_rsa_params (key->params, key->params_size,
|
||||
result = MHD__gnutls_x509_write_rsa_params (key->params, key->params_size,
|
||||
&der);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
}
|
||||
else
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
|
||||
hd = mhd_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
hd = MHD_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
if (hd == GNUTLS_HASH_FAILED)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
result = GNUTLS_E_INTERNAL_ERROR;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
mhd_gnutls_hash (hd, der.data, der.size);
|
||||
MHD_gnutls_hash (hd, der.data, der.size);
|
||||
|
||||
mhd_gnutls_hash_deinit (hd, output_data);
|
||||
MHD_gnutls_hash_deinit (hd, output_data);
|
||||
*output_data_size = 20;
|
||||
|
||||
result = 0;
|
||||
|
||||
cleanup:
|
||||
|
||||
_gnutls_free_datum (&der);
|
||||
MHD__gnutls_free_datum (&der);
|
||||
return result;
|
||||
}
|
||||
|
||||
#ifdef ENABLE_PKI
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_sign_data - This function will sign the given data using the private key params
|
||||
* MHD_gnutls_x509_privkey_sign_data - This function will sign the given data using the private key params
|
||||
* @key: Holds the key
|
||||
* @digest: should be MD5 or SHA1
|
||||
* @flags: should be 0 for now
|
||||
@@ -995,45 +995,45 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_sign_data (gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_privkey_sign_data (MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm digest,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
void *signature, size_t * signature_size)
|
||||
{
|
||||
int result;
|
||||
gnutls_datum_t sig = { NULL, 0 };
|
||||
MHD_gnutls_datum_t sig = { NULL, 0 };
|
||||
|
||||
if (key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_sign (data, digest, key, &sig);
|
||||
result = MHD__gnutls_x509_sign (data, digest, key, &sig);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
if (*signature_size < sig.size)
|
||||
{
|
||||
*signature_size = sig.size;
|
||||
_gnutls_free_datum (&sig);
|
||||
MHD__gnutls_free_datum (&sig);
|
||||
return GNUTLS_E_SHORT_MEMORY_BUFFER;
|
||||
}
|
||||
|
||||
*signature_size = sig.size;
|
||||
memcpy (signature, sig.data, sig.size);
|
||||
|
||||
_gnutls_free_datum (&sig);
|
||||
MHD__gnutls_free_datum (&sig);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_sign_hash - This function will sign the given data using the private key params
|
||||
* MHD_gnutls_x509_privkey_sign_hash - This function will sign the given data using the private key params
|
||||
* @key: Holds the key
|
||||
* @hash: holds the data to be signed
|
||||
* @signature: will contain newly allocated signature
|
||||
@@ -1044,23 +1044,23 @@ gnutls_x509_privkey_sign_data (gnutls_x509_privkey_t key,
|
||||
* and 0 on success.
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
|
||||
const gnutls_datum_t * hash,
|
||||
gnutls_datum_t * signature)
|
||||
MHD_gnutls_x509_privkey_sign_hash (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * hash,
|
||||
MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int result;
|
||||
|
||||
if (key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
result = mhd_gtls_sign (key->pk_algorithm, key->params,
|
||||
result = MHD_gtls_sign (key->pk_algorithm, key->params,
|
||||
key->params_size, hash, signature);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -1068,7 +1068,7 @@ gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_verify_data - This function will verify the given signed data.
|
||||
* MHD_gnutls_x509_privkey_verify_data - This function will verify the given signed data.
|
||||
* @key: Holds the key
|
||||
* @flags: should be 0 for now
|
||||
* @data: holds the data to be signed
|
||||
@@ -1082,23 +1082,23 @@ gnutls_x509_privkey_sign_hash (gnutls_x509_privkey_t key,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_verify_data (gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_privkey_verify_data (MHD_gnutls_x509_privkey_t key,
|
||||
unsigned int flags,
|
||||
const gnutls_datum_t * data,
|
||||
const gnutls_datum_t * signature)
|
||||
const MHD_gnutls_datum_t * data,
|
||||
const MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int result;
|
||||
|
||||
if (key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_privkey_verify_signature (data, signature, key);
|
||||
result = MHD__gnutls_x509_privkey_verify_signature (data, signature, key);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -1106,7 +1106,7 @@ gnutls_x509_privkey_verify_data (gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_privkey_fix - This function will recalculate some parameters of the key.
|
||||
* MHD_gnutls_x509_privkey_fix - This function will recalculate some parameters of the key.
|
||||
* @key: Holds the key
|
||||
*
|
||||
* This function will recalculate the secondary parameters in a key.
|
||||
@@ -1117,30 +1117,30 @@ gnutls_x509_privkey_verify_data (gnutls_x509_privkey_t key,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_privkey_fix (gnutls_x509_privkey_t key)
|
||||
MHD_gnutls_x509_privkey_fix (MHD_gnutls_x509_privkey_t key)
|
||||
{
|
||||
int ret;
|
||||
|
||||
if (key == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
if (!key->crippled)
|
||||
asn1_delete_structure (&key->key);
|
||||
MHD__asn1_delete_structure (&key->key);
|
||||
switch (key->pk_algorithm)
|
||||
{
|
||||
case MHD_GNUTLS_PK_RSA:
|
||||
ret = _gnutls_asn1_encode_rsa (&key->key, key->params);
|
||||
ret = MHD__gnutlsMHD__asn1_encode_rsa (&key->key, key->params);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
break;
|
||||
default:
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
}
|
||||
|
||||
|
||||
+193
-193
@@ -41,19 +41,19 @@
|
||||
#include <common.h>
|
||||
#include <verify.h>
|
||||
|
||||
static int _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crt_t * trusted_cas,
|
||||
static int MHD__gnutls_verify_certificate2 (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size,
|
||||
unsigned int flags,
|
||||
unsigned int *output);
|
||||
int _gnutls_x509_verify_signature (const gnutls_datum_t * signed_data,
|
||||
const gnutls_datum_t * signature,
|
||||
gnutls_x509_crt_t issuer);
|
||||
int MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * signed_data,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
|
||||
static
|
||||
int is_crl_issuer (gnutls_x509_crl_t crl, gnutls_x509_crt_t issuer_cert);
|
||||
static int _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
|
||||
const gnutls_x509_crt_t * trusted_cas,
|
||||
int is_crl_issuer (MHD_gnutls_x509_crl_t crl, MHD_gnutls_x509_crt_t issuer_cert);
|
||||
static int MHD__gnutls_verify_crl2 (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size,
|
||||
unsigned int flags, unsigned int *output);
|
||||
|
||||
@@ -65,19 +65,19 @@ static int _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
|
||||
* or not.
|
||||
*/
|
||||
static int
|
||||
check_if_ca (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_t issuer, unsigned int flags)
|
||||
check_if_ca (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_t issuer, unsigned int flags)
|
||||
{
|
||||
gnutls_datum_t cert_signed_data = { NULL,
|
||||
MHD_gnutls_datum_t cert_signed_data = { NULL,
|
||||
0
|
||||
};
|
||||
gnutls_datum_t issuer_signed_data = { NULL,
|
||||
MHD_gnutls_datum_t issuer_signed_data = { NULL,
|
||||
0
|
||||
};
|
||||
gnutls_datum_t cert_signature = { NULL,
|
||||
MHD_gnutls_datum_t cert_signature = { NULL,
|
||||
0
|
||||
};
|
||||
gnutls_datum_t issuer_signature = { NULL,
|
||||
MHD_gnutls_datum_t issuer_signature = { NULL,
|
||||
0
|
||||
};
|
||||
int result;
|
||||
@@ -87,35 +87,35 @@ check_if_ca (gnutls_x509_crt_t cert,
|
||||
* certificates to be able to verify themselves.
|
||||
*/
|
||||
|
||||
result = _gnutls_x509_get_signed_data (issuer->cert, "tbsCertificate",
|
||||
result = MHD__gnutls_x509_get_signed_data (issuer->cert, "tbsCertificate",
|
||||
&issuer_signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
|
||||
result = MHD__gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
|
||||
&cert_signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_get_signature (issuer->cert, "signature",
|
||||
result = MHD__gnutls_x509_get_signature (issuer->cert, "signature",
|
||||
&issuer_signature);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result =
|
||||
_gnutls_x509_get_signature (cert->cert, "signature", &cert_signature);
|
||||
MHD__gnutls_x509_get_signature (cert->cert, "signature", &cert_signature);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
@@ -139,20 +139,20 @@ check_if_ca (gnutls_x509_crt_t cert,
|
||||
}
|
||||
}
|
||||
|
||||
if (gnutls_x509_crt_get_ca_status (issuer, NULL) == 1)
|
||||
if (MHD_gnutls_x509_crt_get_ca_status (issuer, NULL) == 1)
|
||||
{
|
||||
result = 1;
|
||||
goto cleanup;
|
||||
}
|
||||
else
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
|
||||
result = 0;
|
||||
|
||||
cleanup:_gnutls_free_datum (&cert_signed_data);
|
||||
_gnutls_free_datum (&issuer_signed_data);
|
||||
_gnutls_free_datum (&cert_signature);
|
||||
_gnutls_free_datum (&issuer_signature);
|
||||
cleanup:MHD__gnutls_free_datum (&cert_signed_data);
|
||||
MHD__gnutls_free_datum (&issuer_signed_data);
|
||||
MHD__gnutls_free_datum (&cert_signature);
|
||||
MHD__gnutls_free_datum (&issuer_signature);
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -164,40 +164,40 @@ cleanup:_gnutls_free_datum (&cert_signed_data);
|
||||
* a negative value is returned to indicate error.
|
||||
*/
|
||||
static int
|
||||
is_issuer (gnutls_x509_crt_t cert, gnutls_x509_crt_t issuer_cert)
|
||||
is_issuer (MHD_gnutls_x509_crt_t cert, MHD_gnutls_x509_crt_t issuer_cert)
|
||||
{
|
||||
gnutls_datum_t dn1 = { NULL,
|
||||
MHD_gnutls_datum_t dn1 = { NULL,
|
||||
0
|
||||
}, dn2 =
|
||||
{
|
||||
NULL, 0};
|
||||
int ret;
|
||||
|
||||
ret = gnutls_x509_crt_get_raw_issuer_dn (cert, &dn1);
|
||||
ret = MHD_gnutls_x509_crt_get_raw_issuer_dn (cert, &dn1);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = gnutls_x509_crt_get_raw_dn (issuer_cert, &dn2);
|
||||
ret = MHD_gnutls_x509_crt_get_raw_dn (issuer_cert, &dn2);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_compare_raw_dn (&dn1, &dn2);
|
||||
ret = MHD__gnutls_x509_compare_raw_dn (&dn1, &dn2);
|
||||
|
||||
cleanup:_gnutls_free_datum (&dn1);
|
||||
_gnutls_free_datum (&dn2);
|
||||
cleanup:MHD__gnutls_free_datum (&dn1);
|
||||
MHD__gnutls_free_datum (&dn2);
|
||||
return ret;
|
||||
|
||||
}
|
||||
|
||||
static inline gnutls_x509_crt_t
|
||||
find_issuer (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crt_t * trusted_cas, int tcas_size)
|
||||
static inline MHD_gnutls_x509_crt_t
|
||||
find_issuer (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas, int tcas_size)
|
||||
{
|
||||
int i;
|
||||
|
||||
@@ -210,7 +210,7 @@ find_issuer (gnutls_x509_crt_t cert,
|
||||
return trusted_cas[i];
|
||||
}
|
||||
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -221,24 +221,24 @@ find_issuer (gnutls_x509_crt_t cert,
|
||||
* Returns only 0 or 1. If 1 it means that the certificate
|
||||
* was successfuly verified.
|
||||
*
|
||||
* 'flags': an OR of the gnutls_certificate_verify_flags enumeration.
|
||||
* 'flags': an OR of the MHD_gnutls_certificate_verify_flags enumeration.
|
||||
*
|
||||
* Output will hold some extra information about the verification
|
||||
* procedure.
|
||||
*/
|
||||
static int
|
||||
_gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crt_t * trusted_cas,
|
||||
MHD__gnutls_verify_certificate2 (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size,
|
||||
unsigned int flags, unsigned int *output)
|
||||
{
|
||||
gnutls_datum_t cert_signed_data = { NULL,
|
||||
MHD_gnutls_datum_t cert_signed_data = { NULL,
|
||||
0
|
||||
};
|
||||
gnutls_datum_t cert_signature = { NULL,
|
||||
MHD_gnutls_datum_t cert_signature = { NULL,
|
||||
0
|
||||
};
|
||||
gnutls_x509_crt_t issuer;
|
||||
MHD_gnutls_x509_crt_t issuer;
|
||||
int ret, issuer_version, result;
|
||||
|
||||
if (output)
|
||||
@@ -248,7 +248,7 @@ _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
|
||||
issuer = find_issuer (cert, trusted_cas, tcas_size);
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
if (output)
|
||||
*output |= GNUTLS_CERT_SIGNER_NOT_FOUND | GNUTLS_CERT_INVALID;
|
||||
return 0;
|
||||
@@ -261,14 +261,14 @@ _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
|
||||
{
|
||||
if (output)
|
||||
*output |= GNUTLS_CERT_SIGNER_NOT_FOUND | GNUTLS_CERT_INVALID;
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return 0;
|
||||
}
|
||||
|
||||
issuer_version = gnutls_x509_crt_get_version (issuer);
|
||||
issuer_version = MHD_gnutls_x509_crt_get_version (issuer);
|
||||
if (issuer_version < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return issuer_version;
|
||||
}
|
||||
|
||||
@@ -279,38 +279,38 @@ _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
|
||||
{
|
||||
if (check_if_ca (cert, issuer, flags) == 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
if (output)
|
||||
*output |= GNUTLS_CERT_SIGNER_NOT_CA | GNUTLS_CERT_INVALID;
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
|
||||
result = _gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
|
||||
result = MHD__gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
|
||||
&cert_signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result =
|
||||
_gnutls_x509_get_signature (cert->cert, "signature", &cert_signature);
|
||||
MHD__gnutls_x509_get_signature (cert->cert, "signature", &cert_signature);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_verify_signature (&cert_signed_data, &cert_signature,
|
||||
ret = MHD__gnutls_x509_verify_signature (&cert_signed_data, &cert_signature,
|
||||
issuer);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
}
|
||||
else if (ret == 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
/* error. ignore it */
|
||||
if (output)
|
||||
*output |= GNUTLS_CERT_INVALID;
|
||||
@@ -325,7 +325,7 @@ _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
|
||||
{
|
||||
int sigalg;
|
||||
|
||||
sigalg = gnutls_x509_crt_get_signature_algorithm (cert);
|
||||
sigalg = MHD_gnutls_x509_crt_get_signature_algorithm (cert);
|
||||
|
||||
if (((sigalg == GNUTLS_SIGN_RSA_MD2) && !(flags
|
||||
&
|
||||
@@ -340,14 +340,14 @@ _gnutls_verify_certificate2 (gnutls_x509_crt_t cert,
|
||||
|
||||
result = ret;
|
||||
|
||||
cleanup:_gnutls_free_datum (&cert_signed_data);
|
||||
_gnutls_free_datum (&cert_signature);
|
||||
cleanup:MHD__gnutls_free_datum (&cert_signed_data);
|
||||
MHD__gnutls_free_datum (&cert_signature);
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_check_issuer - This function checks if the certificate given has the given issuer
|
||||
* MHD_gnutls_x509_crt_check_issuer - This function checks if the certificate given has the given issuer
|
||||
* @cert: is the certificate to be checked
|
||||
* @issuer: is the certificate of a possible issuer
|
||||
*
|
||||
@@ -359,8 +359,8 @@ cleanup:_gnutls_free_datum (&cert_signed_data);
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_check_issuer (gnutls_x509_crt_t cert,
|
||||
gnutls_x509_crt_t issuer)
|
||||
MHD_gnutls_x509_crt_check_issuer (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_t issuer)
|
||||
{
|
||||
return is_issuer (cert, issuer);
|
||||
}
|
||||
@@ -377,11 +377,11 @@ gnutls_x509_crt_check_issuer (gnutls_x509_crt_t cert,
|
||||
* lead to a trusted CA in order to be trusted.
|
||||
*/
|
||||
static unsigned int
|
||||
_gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
|
||||
MHD__gnutls_x509_verify_certificate (const MHD_gnutls_x509_crt_t * certificate_list,
|
||||
int clist_size,
|
||||
const gnutls_x509_crt_t * trusted_cas,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size,
|
||||
const gnutls_x509_crl_t * CRLs,
|
||||
const MHD_gnutls_x509_crl_t * CRLs,
|
||||
int crls_size, unsigned int flags)
|
||||
{
|
||||
int i = 0, ret;
|
||||
@@ -393,7 +393,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
|
||||
* If no CAs are present returns CERT_INVALID. Thus works
|
||||
* in self signed etc certificates.
|
||||
*/
|
||||
ret = _gnutls_verify_certificate2 (certificate_list[clist_size - 1],
|
||||
ret = MHD__gnutls_verify_certificate2 (certificate_list[clist_size - 1],
|
||||
trusted_cas, tcas_size, flags, &output);
|
||||
|
||||
if (ret == 0)
|
||||
@@ -402,7 +402,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
|
||||
* list is invalid, then the certificate is not
|
||||
* trusted.
|
||||
*/
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
status |= output;
|
||||
status |= GNUTLS_CERT_INVALID;
|
||||
return status;
|
||||
@@ -413,7 +413,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
|
||||
#ifdef ENABLE_PKI
|
||||
for (i = 0; i < clist_size; i++)
|
||||
{
|
||||
ret = gnutls_x509_crt_check_revocation (certificate_list[i],
|
||||
ret = MHD_gnutls_x509_crt_check_revocation (certificate_list[i],
|
||||
CRLs, crls_size);
|
||||
if (ret == 1)
|
||||
{ /* revoked */
|
||||
@@ -428,7 +428,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
|
||||
* In that case ignore it (a certificate is trusted only if it
|
||||
* leads to a trusted party by us, not the server's).
|
||||
*/
|
||||
if (gnutls_x509_crt_check_issuer (certificate_list[clist_size - 1],
|
||||
if (MHD_gnutls_x509_crt_check_issuer (certificate_list[clist_size - 1],
|
||||
certificate_list[clist_size - 1]) > 0
|
||||
&& clist_size > 0)
|
||||
{
|
||||
@@ -447,7 +447,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
|
||||
*/
|
||||
if (!(flags & GNUTLS_VERIFY_ALLOW_ANY_X509_V1_CA_CRT))
|
||||
flags ^= GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT;
|
||||
if ((ret = _gnutls_verify_certificate2 (certificate_list[i - 1],
|
||||
if ((ret = MHD__gnutls_verify_certificate2 (certificate_list[i - 1],
|
||||
&certificate_list[i], 1, flags,
|
||||
NULL)) == 0)
|
||||
{
|
||||
@@ -464,7 +464,7 @@ _gnutls_x509_verify_certificate (const gnutls_x509_crt_t * certificate_list,
|
||||
* anyway.
|
||||
*/
|
||||
static int
|
||||
decode_ber_digest_info (const gnutls_datum_t * info,
|
||||
decode_ber_digest_info (const MHD_gnutls_datum_t * info,
|
||||
enum MHD_GNUTLS_HashAlgorithm *hash,
|
||||
opaque * digest, int *digest_size)
|
||||
{
|
||||
@@ -473,45 +473,45 @@ decode_ber_digest_info (const gnutls_datum_t * info,
|
||||
char str[1024];
|
||||
int len;
|
||||
|
||||
if ((result = asn1_create_element (_gnutls_get_gnutls_asn (),
|
||||
if ((result = MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.DigestInfo",
|
||||
&dinfo)) != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = asn1_der_decoding (&dinfo, info->data, info->size, NULL);
|
||||
result = MHD__asn1_der_decoding (&dinfo, info->data, info->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dinfo);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
len = sizeof (str) - 1;
|
||||
result = asn1_read_value (dinfo, "digestAlgorithm.algorithm", str, &len);
|
||||
result = MHD__asn1_read_value (dinfo, "digestAlgorithm.algorithm", str, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dinfo);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
*hash = mhd_gtls_x509_oid2mac_algorithm (str);
|
||||
*hash = MHD_gtls_x509_oid2mac_algorithm (str);
|
||||
|
||||
if (*hash == MHD_GNUTLS_MAC_UNKNOWN)
|
||||
{
|
||||
|
||||
_gnutls_x509_log ("verify.c: HASH OID: %s\n", str);
|
||||
MHD__gnutls_x509_log ("verify.c: HASH OID: %s\n", str);
|
||||
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dinfo);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
return GNUTLS_E_UNKNOWN_ALGORITHM;
|
||||
}
|
||||
|
||||
len = sizeof (str) - 1;
|
||||
result = asn1_read_value (dinfo, "digestAlgorithm.parameters", str, &len);
|
||||
result = MHD__asn1_read_value (dinfo, "digestAlgorithm.parameters", str, &len);
|
||||
/* To avoid permitting garbage in the parameters field, either the
|
||||
parameters field is not present, or it contains 0x05 0x00. */
|
||||
if (!
|
||||
@@ -519,20 +519,20 @@ decode_ber_digest_info (const gnutls_datum_t * info,
|
||||
|| (result == ASN1_SUCCESS && len == 2 && str[0] == 0x05
|
||||
&& str[1] == 0x00)))
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dinfo);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
|
||||
result = asn1_read_value (dinfo, "digest", digest, digest_size);
|
||||
result = MHD__asn1_read_value (dinfo, "digest", digest, digest_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
gnutls_assert ();
|
||||
asn1_delete_structure (&dinfo);
|
||||
return mhd_gtls_asn2err (result);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
asn1_delete_structure (&dinfo);
|
||||
MHD__asn1_delete_structure (&dinfo);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -543,8 +543,8 @@ decode_ber_digest_info (const gnutls_datum_t * info,
|
||||
* params[1] is public key
|
||||
*/
|
||||
static int
|
||||
_pkcs1_rsa_verify_sig (const gnutls_datum_t * text,
|
||||
const gnutls_datum_t * signature,
|
||||
_pkcs1_rsa_verify_sig (const MHD_gnutls_datum_t * text,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
mpi_t * params, int params_len)
|
||||
{
|
||||
enum MHD_GNUTLS_HashAlgorithm hash = MHD_GNUTLS_MAC_UNKNOWN;
|
||||
@@ -552,13 +552,13 @@ _pkcs1_rsa_verify_sig (const gnutls_datum_t * text,
|
||||
opaque digest[MAX_HASH_SIZE], md[MAX_HASH_SIZE];
|
||||
int digest_size;
|
||||
GNUTLS_HASH_HANDLE hd;
|
||||
gnutls_datum_t decrypted;
|
||||
MHD_gnutls_datum_t decrypted;
|
||||
|
||||
ret =
|
||||
mhd_gtls_pkcs1_rsa_decrypt (&decrypted, signature, params, params_len, 1);
|
||||
MHD_gtls_pkcs1_rsa_decrypt (&decrypted, signature, params, params_len, 1);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -569,32 +569,32 @@ _pkcs1_rsa_verify_sig (const gnutls_datum_t * text,
|
||||
if ((ret = decode_ber_digest_info (&decrypted, &hash, digest, &digest_size))
|
||||
!= 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
_gnutls_free_datum (&decrypted);
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_free_datum (&decrypted);
|
||||
return ret;
|
||||
}
|
||||
|
||||
_gnutls_free_datum (&decrypted);
|
||||
MHD__gnutls_free_datum (&decrypted);
|
||||
|
||||
if (digest_size != mhd_gnutls_hash_get_algo_len (hash))
|
||||
if (digest_size != MHD_gnutls_hash_get_algo_len (hash))
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_ASN1_GENERIC_ERROR;
|
||||
}
|
||||
|
||||
hd = mhd_gtls_hash_init (hash);
|
||||
hd = MHD_gtls_hash_init (hash);
|
||||
if (hd == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_HASH_FAILED;
|
||||
}
|
||||
|
||||
mhd_gnutls_hash (hd, text->data, text->size);
|
||||
mhd_gnutls_hash_deinit (hd, md);
|
||||
MHD_gnutls_hash (hd, text->data, text->size);
|
||||
MHD_gnutls_hash_deinit (hd, md);
|
||||
|
||||
if (memcmp (md, digest, digest_size) != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_PK_SIG_VERIFY_FAILED;
|
||||
}
|
||||
|
||||
@@ -604,29 +604,29 @@ _pkcs1_rsa_verify_sig (const gnutls_datum_t * text,
|
||||
/* Hashes input data and verifies a DSA signature.
|
||||
*/
|
||||
static int
|
||||
dsa_verify_sig (const gnutls_datum_t * text,
|
||||
const gnutls_datum_t * signature,
|
||||
dsa_verify_sig (const MHD_gnutls_datum_t * text,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
mpi_t * params, int params_len)
|
||||
{
|
||||
int ret;
|
||||
opaque _digest[MAX_HASH_SIZE];
|
||||
gnutls_datum_t digest;
|
||||
MHD_gnutls_datum_t digest;
|
||||
GNUTLS_HASH_HANDLE hd;
|
||||
|
||||
hd = mhd_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
hd = MHD_gtls_hash_init (MHD_GNUTLS_MAC_SHA1);
|
||||
if (hd == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_HASH_FAILED;
|
||||
}
|
||||
|
||||
mhd_gnutls_hash (hd, text->data, text->size);
|
||||
mhd_gnutls_hash_deinit (hd, _digest);
|
||||
MHD_gnutls_hash (hd, text->data, text->size);
|
||||
MHD_gnutls_hash_deinit (hd, _digest);
|
||||
|
||||
digest.data = _digest;
|
||||
digest.size = 20;
|
||||
|
||||
ret = mhd_gtls_dsa_verify (&digest, signature, params, params_len);
|
||||
ret = MHD_gtls_dsa_verify (&digest, signature, params, params_len);
|
||||
|
||||
return ret;
|
||||
}
|
||||
@@ -635,8 +635,8 @@ dsa_verify_sig (const gnutls_datum_t * text,
|
||||
* or 1 otherwise.
|
||||
*/
|
||||
static int
|
||||
verify_sig (const gnutls_datum_t * tbs,
|
||||
const gnutls_datum_t * signature,
|
||||
verify_sig (const MHD_gnutls_datum_t * tbs,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm pk,
|
||||
mpi_t * issuer_params, int issuer_params_size)
|
||||
{
|
||||
@@ -648,7 +648,7 @@ verify_sig (const gnutls_datum_t * tbs,
|
||||
if (_pkcs1_rsa_verify_sig
|
||||
(tbs, signature, issuer_params, issuer_params_size) != 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -656,7 +656,7 @@ verify_sig (const gnutls_datum_t * tbs,
|
||||
break;
|
||||
|
||||
default:
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_INTERNAL_ERROR;
|
||||
|
||||
}
|
||||
@@ -669,9 +669,9 @@ verify_sig (const gnutls_datum_t * tbs,
|
||||
* 'signature' is the signature!
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
|
||||
const gnutls_datum_t * signature,
|
||||
gnutls_x509_crt_t issuer)
|
||||
MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_crt_t issuer)
|
||||
{
|
||||
mpi_t issuer_params[MAX_PUBLIC_PARAMS_SIZE];
|
||||
int ret, issuer_params_size, i;
|
||||
@@ -680,26 +680,26 @@ _gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
|
||||
*/
|
||||
issuer_params_size = MAX_PUBLIC_PARAMS_SIZE;
|
||||
ret =
|
||||
_gnutls_x509_crt_get_mpis (issuer, issuer_params, &issuer_params_size);
|
||||
MHD__gnutls_x509_crt_get_mpis (issuer, issuer_params, &issuer_params_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = verify_sig (tbs, signature, gnutls_x509_crt_get_pk_algorithm (issuer,
|
||||
ret = verify_sig (tbs, signature, MHD_gnutls_x509_crt_get_pk_algorithm (issuer,
|
||||
NULL),
|
||||
issuer_params, issuer_params_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
}
|
||||
|
||||
/* release all allocated MPIs
|
||||
*/
|
||||
for (i = 0; i < issuer_params_size; i++)
|
||||
{
|
||||
mhd_gtls_mpi_release (&issuer_params[i]);
|
||||
MHD_gtls_mpi_release (&issuer_params[i]);
|
||||
}
|
||||
|
||||
return ret;
|
||||
@@ -712,9 +712,9 @@ _gnutls_x509_verify_signature (const gnutls_datum_t * tbs,
|
||||
* 'signature' is the signature!
|
||||
*/
|
||||
int
|
||||
_gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
|
||||
const gnutls_datum_t * signature,
|
||||
gnutls_x509_privkey_t issuer)
|
||||
MHD__gnutls_x509_privkey_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_privkey_t issuer)
|
||||
{
|
||||
int ret;
|
||||
|
||||
@@ -722,21 +722,21 @@ _gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
|
||||
issuer->params_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
}
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_list_verify - This function verifies the given certificate list
|
||||
* MHD_gnutls_x509_crt_list_verify - This function verifies the given certificate list
|
||||
* @cert_list: is the certificate list to be verified
|
||||
* @cert_list_length: holds the number of certificate in cert_list
|
||||
* @CA_list: is the CA list which will be used in verification
|
||||
* @CA_list_length: holds the number of CA certificate in CA_list
|
||||
* @CRL_list: holds a list of CRLs.
|
||||
* @CRL_list_length: the length of CRL list.
|
||||
* @flags: Flags that may be used to change the verification algorithm. Use OR of the gnutls_certificate_verify_flags enumerations.
|
||||
* @flags: Flags that may be used to change the verification algorithm. Use OR of the MHD_gnutls_certificate_verify_flags enumerations.
|
||||
* @verify: will hold the certificate verification output.
|
||||
*
|
||||
* This function will try to verify the given certificate list and return its status.
|
||||
@@ -751,8 +751,8 @@ _gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
|
||||
* certificate belongs to the actual peer.
|
||||
*
|
||||
* The certificate verification output will be put in @verify and will be
|
||||
* one or more of the gnutls_certificate_status_t enumerated elements bitwise or'd.
|
||||
* For a more detailed verification status use gnutls_x509_crt_verify() per list
|
||||
* one or more of the MHD_gnutls_certificate_status_t enumerated elements bitwise or'd.
|
||||
* For a more detailed verification status use MHD_gnutls_x509_crt_verify() per list
|
||||
* element.
|
||||
*
|
||||
* GNUTLS_CERT_INVALID: the certificate chain is not valid.
|
||||
@@ -763,11 +763,11 @@ _gnutls_x509_privkey_verify_signature (const gnutls_datum_t * tbs,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
|
||||
MHD_gnutls_x509_crt_list_verify (const MHD_gnutls_x509_crt_t * cert_list,
|
||||
int cert_list_length,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
const gnutls_x509_crl_t * CRL_list,
|
||||
const MHD_gnutls_x509_crl_t * CRL_list,
|
||||
int CRL_list_length,
|
||||
unsigned int flags, unsigned int *verify)
|
||||
{
|
||||
@@ -776,7 +776,7 @@ gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
|
||||
|
||||
/* Verify certificate
|
||||
*/
|
||||
*verify = _gnutls_x509_verify_certificate (cert_list, cert_list_length,
|
||||
*verify = MHD__gnutls_x509_verify_certificate (cert_list, cert_list_length,
|
||||
CA_list, CA_list_length,
|
||||
CRL_list, CRL_list_length,
|
||||
flags);
|
||||
@@ -785,11 +785,11 @@ gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crt_verify - This function verifies the given certificate against a given trusted one
|
||||
* MHD_gnutls_x509_crt_verify - This function verifies the given certificate against a given trusted one
|
||||
* @cert: is the certificate to be verified
|
||||
* @CA_list: is one certificate that is considered to be trusted one
|
||||
* @CA_list_length: holds the number of CA certificate in CA_list
|
||||
* @flags: Flags that may be used to change the verification algorithm. Use OR of the gnutls_certificate_verify_flags enumerations.
|
||||
* @flags: Flags that may be used to change the verification algorithm. Use OR of the MHD_gnutls_certificate_verify_flags enumerations.
|
||||
* @verify: will hold the certificate verification output.
|
||||
*
|
||||
* This function will try to verify the given certificate and return its status.
|
||||
@@ -799,19 +799,19 @@ gnutls_x509_crt_list_verify (const gnutls_x509_crt_t * cert_list,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crt_verify (gnutls_x509_crt_t cert,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
MHD_gnutls_x509_crt_verify (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify)
|
||||
{
|
||||
int ret;
|
||||
/* Verify certificate
|
||||
*/
|
||||
ret = _gnutls_verify_certificate2 (cert, CA_list, CA_list_length, flags,
|
||||
ret = MHD__gnutls_verify_certificate2 (cert, CA_list, CA_list_length, flags,
|
||||
verify);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -821,7 +821,7 @@ gnutls_x509_crt_verify (gnutls_x509_crt_t cert,
|
||||
#ifdef ENABLE_PKI
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_check_issuer - This function checks if the CRL given has the given issuer
|
||||
* MHD_gnutls_x509_crl_check_issuer - This function checks if the CRL given has the given issuer
|
||||
* @crl: is the CRL to be checked
|
||||
* @issuer: is the certificate of a possible issuer
|
||||
*
|
||||
@@ -833,40 +833,40 @@ gnutls_x509_crt_verify (gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_check_issuer (gnutls_x509_crl_t cert,
|
||||
gnutls_x509_crt_t issuer)
|
||||
MHD_gnutls_x509_crl_check_issuer (MHD_gnutls_x509_crl_t cert,
|
||||
MHD_gnutls_x509_crt_t issuer)
|
||||
{
|
||||
return is_crl_issuer (cert, issuer);
|
||||
}
|
||||
|
||||
/**
|
||||
* gnutls_x509_crl_verify - This function verifies the given crl against a given trusted one
|
||||
* MHD_gnutls_x509_crl_verify - This function verifies the given crl against a given trusted one
|
||||
* @crl: is the crl to be verified
|
||||
* @CA_list: is a certificate list that is considered to be trusted one
|
||||
* @CA_list_length: holds the number of CA certificates in CA_list
|
||||
* @flags: Flags that may be used to change the verification algorithm. Use OR of the gnutls_certificate_verify_flags enumerations.
|
||||
* @flags: Flags that may be used to change the verification algorithm. Use OR of the MHD_gnutls_certificate_verify_flags enumerations.
|
||||
* @verify: will hold the crl verification output.
|
||||
*
|
||||
* This function will try to verify the given crl and return its status.
|
||||
* See gnutls_x509_crt_list_verify() for a detailed description of
|
||||
* See MHD_gnutls_x509_crt_list_verify() for a detailed description of
|
||||
* return values.
|
||||
*
|
||||
* Returns 0 on success and a negative value in case of an error.
|
||||
*
|
||||
**/
|
||||
int
|
||||
gnutls_x509_crl_verify (gnutls_x509_crl_t crl,
|
||||
const gnutls_x509_crt_t * CA_list,
|
||||
MHD_gnutls_x509_crl_verify (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length, unsigned int flags,
|
||||
unsigned int *verify)
|
||||
{
|
||||
int ret;
|
||||
/* Verify crl
|
||||
*/
|
||||
ret = _gnutls_verify_crl2 (crl, CA_list, CA_list_length, flags, verify);
|
||||
ret = MHD__gnutls_verify_crl2 (crl, CA_list, CA_list_length, flags, verify);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -876,39 +876,39 @@ gnutls_x509_crl_verify (gnutls_x509_crl_t crl,
|
||||
/* The same as above, but here we've got a CRL.
|
||||
*/
|
||||
static int
|
||||
is_crl_issuer (gnutls_x509_crl_t crl, gnutls_x509_crt_t issuer_cert)
|
||||
is_crl_issuer (MHD_gnutls_x509_crl_t crl, MHD_gnutls_x509_crt_t issuer_cert)
|
||||
{
|
||||
gnutls_datum_t dn1 = { NULL, 0 }, dn2 =
|
||||
MHD_gnutls_datum_t dn1 = { NULL, 0 }, dn2 =
|
||||
{
|
||||
NULL, 0};
|
||||
int ret;
|
||||
|
||||
ret = _gnutls_x509_crl_get_raw_issuer_dn (crl, &dn1);
|
||||
ret = MHD__gnutls_x509_crl_get_raw_issuer_dn (crl, &dn1);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret = gnutls_x509_crt_get_raw_dn (issuer_cert, &dn2);
|
||||
ret = MHD_gnutls_x509_crt_get_raw_dn (issuer_cert, &dn2);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = _gnutls_x509_compare_raw_dn (&dn1, &dn2);
|
||||
ret = MHD__gnutls_x509_compare_raw_dn (&dn1, &dn2);
|
||||
|
||||
cleanup:
|
||||
_gnutls_free_datum (&dn1);
|
||||
_gnutls_free_datum (&dn2);
|
||||
MHD__gnutls_free_datum (&dn1);
|
||||
MHD__gnutls_free_datum (&dn2);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
static inline gnutls_x509_crt_t
|
||||
find_crl_issuer (gnutls_x509_crl_t crl,
|
||||
const gnutls_x509_crt_t * trusted_cas, int tcas_size)
|
||||
static inline MHD_gnutls_x509_crt_t
|
||||
find_crl_issuer (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas, int tcas_size)
|
||||
{
|
||||
int i;
|
||||
|
||||
@@ -921,7 +921,7 @@ find_crl_issuer (gnutls_x509_crl_t crl,
|
||||
return trusted_cas[i];
|
||||
}
|
||||
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -929,20 +929,20 @@ find_crl_issuer (gnutls_x509_crl_t crl,
|
||||
* Returns only 0 or 1. If 1 it means that the CRL
|
||||
* was successfuly verified.
|
||||
*
|
||||
* 'flags': an OR of the gnutls_certificate_verify_flags enumeration.
|
||||
* 'flags': an OR of the MHD_gnutls_certificate_verify_flags enumeration.
|
||||
*
|
||||
* Output will hold information about the verification
|
||||
* procedure.
|
||||
*/
|
||||
static int
|
||||
_gnutls_verify_crl2 (gnutls_x509_crl_t crl,
|
||||
const gnutls_x509_crt_t * trusted_cas,
|
||||
MHD__gnutls_verify_crl2 (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size, unsigned int flags, unsigned int *output)
|
||||
{
|
||||
/* CRL is ignored for now */
|
||||
gnutls_datum_t crl_signed_data = { NULL, 0 };
|
||||
gnutls_datum_t crl_signature = { NULL, 0 };
|
||||
gnutls_x509_crt_t issuer;
|
||||
MHD_gnutls_datum_t crl_signed_data = { NULL, 0 };
|
||||
MHD_gnutls_datum_t crl_signature = { NULL, 0 };
|
||||
MHD_gnutls_x509_crt_t issuer;
|
||||
int ret, result;
|
||||
|
||||
if (output)
|
||||
@@ -952,7 +952,7 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
|
||||
issuer = find_crl_issuer (crl, trusted_cas, tcas_size);
|
||||
else
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
if (output)
|
||||
*output |= GNUTLS_CERT_SIGNER_NOT_FOUND | GNUTLS_CERT_INVALID;
|
||||
return 0;
|
||||
@@ -963,7 +963,7 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
|
||||
*/
|
||||
if (issuer == NULL)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
if (output)
|
||||
*output |= GNUTLS_CERT_SIGNER_NOT_FOUND | GNUTLS_CERT_INVALID;
|
||||
return 0;
|
||||
@@ -971,9 +971,9 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
|
||||
|
||||
if (!(flags & GNUTLS_VERIFY_DISABLE_CA_SIGN))
|
||||
{
|
||||
if (gnutls_x509_crt_get_ca_status (issuer, NULL) != 1)
|
||||
if (MHD_gnutls_x509_crt_get_ca_status (issuer, NULL) != 1)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
if (output)
|
||||
*output |= GNUTLS_CERT_SIGNER_NOT_CA | GNUTLS_CERT_INVALID;
|
||||
return 0;
|
||||
@@ -981,29 +981,29 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
|
||||
}
|
||||
|
||||
result =
|
||||
_gnutls_x509_get_signed_data (crl->crl, "tbsCertList", &crl_signed_data);
|
||||
MHD__gnutls_x509_get_signed_data (crl->crl, "tbsCertList", &crl_signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = _gnutls_x509_get_signature (crl->crl, "signature", &crl_signature);
|
||||
result = MHD__gnutls_x509_get_signature (crl->crl, "signature", &crl_signature);
|
||||
if (result < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
ret =
|
||||
_gnutls_x509_verify_signature (&crl_signed_data, &crl_signature, issuer);
|
||||
MHD__gnutls_x509_verify_signature (&crl_signed_data, &crl_signature, issuer);
|
||||
if (ret < 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
}
|
||||
else if (ret == 0)
|
||||
{
|
||||
gnutls_assert ();
|
||||
MHD_gnutls_assert ();
|
||||
/* error. ignore it */
|
||||
if (output)
|
||||
*output |= GNUTLS_CERT_INVALID;
|
||||
@@ -1013,7 +1013,7 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
|
||||
{
|
||||
int sigalg;
|
||||
|
||||
sigalg = gnutls_x509_crl_get_signature_algorithm (crl);
|
||||
sigalg = MHD_gnutls_x509_crl_get_signature_algorithm (crl);
|
||||
|
||||
if (((sigalg == GNUTLS_SIGN_RSA_MD2) &&
|
||||
!(flags & GNUTLS_VERIFY_ALLOW_SIGN_RSA_MD2)) ||
|
||||
@@ -1028,8 +1028,8 @@ _gnutls_verify_crl2 (gnutls_x509_crl_t crl,
|
||||
result = ret;
|
||||
|
||||
cleanup:
|
||||
_gnutls_free_datum (&crl_signed_data);
|
||||
_gnutls_free_datum (&crl_signature);
|
||||
MHD__gnutls_free_datum (&crl_signed_data);
|
||||
MHD__gnutls_free_datum (&crl_signature);
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
Reference in new issue
Block a user