mirror of
https://git.gnunet.org/libmicrohttpd.git
synced 2026-10-07 04:02:18 +03:00
indentation
This commit is contained in:
1 parent
d8e2c71150
commit
705bb243b0
119 files changed
+2909
-2452
No files matched your search
@@ -258,8 +258,9 @@ MHD__gnutls_x509_oid2ldap_string (const char *oid)
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_oid_data2string (const char *oid,
|
||||
void *value,
|
||||
int value_size, char *res, size_t * res_size)
|
||||
void *value,
|
||||
int value_size, char *res,
|
||||
size_t * res_size)
|
||||
{
|
||||
char str[MAX_STRING_LEN], tmpname[128];
|
||||
const char *ANAME = NULL;
|
||||
@@ -292,17 +293,19 @@ MHD__gnutls_x509_oid_data2string (const char *oid,
|
||||
MHD_gtls_str_cat (str, sizeof (str), ANAME);
|
||||
|
||||
if ((result = MHD__asn1_create_element (MHD__gnutls_get_pkix (), str,
|
||||
&tmpasn)) != ASN1_SUCCESS)
|
||||
&tmpasn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
if ((result = MHD__asn1_der_decoding (&tmpasn, value, value_size, MHD__asn1_err))
|
||||
!= ASN1_SUCCESS)
|
||||
if ((result =
|
||||
MHD__asn1_der_decoding (&tmpasn, value, value_size,
|
||||
MHD__asn1_err)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
MHD__gnutls_x509_log ("MHD__asn1_der_decoding: %s:%s\n", str, MHD__asn1_err);
|
||||
MHD__gnutls_x509_log ("MHD__asn1_der_decoding: %s:%s\n", str,
|
||||
MHD__asn1_err);
|
||||
MHD__asn1_delete_structure (&tmpasn);
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
@@ -381,7 +384,9 @@ MHD__gnutls_x509_oid_data2string (const char *oid,
|
||||
}
|
||||
else
|
||||
{
|
||||
result = MHD__gnutls_x509_data2hex ((const unsigned char*) str, len, (unsigned char*) res, res_size);
|
||||
result =
|
||||
MHD__gnutls_x509_data2hex ((const unsigned char *) str, len,
|
||||
(unsigned char *) res, res_size);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -400,7 +405,8 @@ MHD__gnutls_x509_oid_data2string (const char *oid,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_data2hex (const opaque * data,
|
||||
size_t data_size, opaque * out, size_t * sizeof_out)
|
||||
size_t data_size, opaque * out,
|
||||
size_t * sizeof_out)
|
||||
{
|
||||
char *res;
|
||||
char escaped[MAX_STRING_LEN];
|
||||
@@ -425,8 +431,8 @@ MHD__gnutls_x509_data2hex (const opaque * data,
|
||||
|
||||
if (out)
|
||||
{
|
||||
strcpy ((char*) out, "#");
|
||||
strcat ((char*) out, res);
|
||||
strcpy ((char *) out, "#");
|
||||
strcat ((char *) out, res);
|
||||
}
|
||||
|
||||
return 0;
|
||||
@@ -726,10 +732,10 @@ MHD__gnutls_x509_san_find_type (char *str_type)
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_export_int (ASN1_TYPE MHD__asn1_data,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
char *pem_header,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size)
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
char *pem_header,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size)
|
||||
{
|
||||
int result, len;
|
||||
|
||||
@@ -741,8 +747,9 @@ MHD__gnutls_x509_export_int (ASN1_TYPE MHD__asn1_data,
|
||||
|
||||
len = *output_data_size;
|
||||
|
||||
if ((result = MHD__asn1_der_coding (MHD__asn1_data, "", output_data, &len,
|
||||
NULL)) != ASN1_SUCCESS)
|
||||
if ((result =
|
||||
MHD__asn1_der_coding (MHD__asn1_data, "", output_data, &len,
|
||||
NULL)) != ASN1_SUCCESS)
|
||||
{
|
||||
*output_data_size = len;
|
||||
if (result == ASN1_MEM_ERROR)
|
||||
@@ -768,7 +775,8 @@ MHD__gnutls_x509_export_int (ASN1_TYPE MHD__asn1_data,
|
||||
return result;
|
||||
}
|
||||
|
||||
result = MHD__gnutls_fbase64_encode (pem_header, tmp.data, tmp.size, &out);
|
||||
result =
|
||||
MHD__gnutls_fbase64_encode (pem_header, tmp.data, tmp.size, &out);
|
||||
|
||||
MHD__gnutls_free_datum (&tmp);
|
||||
|
||||
@@ -815,9 +823,9 @@ MHD__gnutls_x509_export_int (ASN1_TYPE MHD__asn1_data,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_decode_octet_string (const char *string_type,
|
||||
const opaque * der,
|
||||
size_t der_size,
|
||||
opaque * output, size_t * output_size)
|
||||
const opaque * der,
|
||||
size_t der_size,
|
||||
opaque * output, size_t * output_size)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result, tmp_output_size;
|
||||
@@ -833,7 +841,7 @@ MHD__gnutls_x509_decode_octet_string (const char *string_type,
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), strname,
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -875,7 +883,8 @@ cleanup:if (c2)
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_read_value (ASN1_TYPE c,
|
||||
const char *root, MHD_gnutls_datum_t * ret, int flags)
|
||||
const char *root, MHD_gnutls_datum_t * ret,
|
||||
int flags)
|
||||
{
|
||||
int len = 0, result;
|
||||
size_t slen;
|
||||
@@ -917,7 +926,8 @@ MHD__gnutls_x509_read_value (ASN1_TYPE c,
|
||||
if (flags == 1)
|
||||
{
|
||||
slen = len;
|
||||
result = MHD__gnutls_x509_decode_octet_string (NULL, tmp, slen, tmp, &slen);
|
||||
result =
|
||||
MHD__gnutls_x509_decode_octet_string (NULL, tmp, slen, tmp, &slen);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -942,7 +952,8 @@ cleanup:MHD_gnutls_free (tmp);
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_der_encode (ASN1_TYPE src,
|
||||
const char *src_name, MHD_gnutls_datum_t * res, int str)
|
||||
const char *src_name, MHD_gnutls_datum_t * res,
|
||||
int str)
|
||||
{
|
||||
int size, result;
|
||||
int asize;
|
||||
@@ -984,8 +995,9 @@ MHD__gnutls_x509_der_encode (ASN1_TYPE src,
|
||||
if (str)
|
||||
{
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-Data",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-7-Data",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -1030,9 +1042,9 @@ cleanup:MHD_gnutls_free (data);
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_der_encode_and_copy (ASN1_TYPE src,
|
||||
const char *src_name,
|
||||
ASN1_TYPE dest,
|
||||
const char *dest_name, int str)
|
||||
const char *src_name,
|
||||
ASN1_TYPE dest,
|
||||
const char *dest_name, int str)
|
||||
{
|
||||
int result;
|
||||
MHD_gnutls_datum_t encoded;
|
||||
@@ -1047,7 +1059,8 @@ MHD__gnutls_x509_der_encode_and_copy (ASN1_TYPE src,
|
||||
|
||||
/* Write the data.
|
||||
*/
|
||||
result = MHD__asn1_write_value (dest, dest_name, encoded.data, encoded.size);
|
||||
result =
|
||||
MHD__asn1_write_value (dest, dest_name, encoded.data, encoded.size);
|
||||
|
||||
MHD__gnutls_free_datum (&encoded);
|
||||
|
||||
@@ -1065,8 +1078,8 @@ MHD__gnutls_x509_der_encode_and_copy (ASN1_TYPE src,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_write_value (ASN1_TYPE c,
|
||||
const char *root,
|
||||
const MHD_gnutls_datum_t * data, int str)
|
||||
const char *root,
|
||||
const MHD_gnutls_datum_t * data, int str)
|
||||
{
|
||||
int result;
|
||||
int asize;
|
||||
@@ -1088,8 +1101,9 @@ MHD__gnutls_x509_write_value (ASN1_TYPE c,
|
||||
/* Convert it to OCTET STRING
|
||||
*/
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-Data",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-7-Data",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -1144,10 +1158,11 @@ cleanup:if (val.data != data->data)
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
const char *dst_name,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm,
|
||||
mpi_t * params, int params_size)
|
||||
const char *dst_name,
|
||||
enum
|
||||
MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm, mpi_t * params,
|
||||
int params_size)
|
||||
{
|
||||
const char *pk;
|
||||
MHD_gnutls_datum_t der = { NULL,
|
||||
@@ -1219,7 +1234,7 @@ MHD__gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
const char *src_name, unsigned int *bits)
|
||||
const char *src_name, unsigned int *bits)
|
||||
{
|
||||
int result;
|
||||
opaque *str = NULL;
|
||||
@@ -1295,7 +1310,8 @@ MHD__gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
{
|
||||
case MHD_GNUTLS_PK_RSA:
|
||||
{
|
||||
if ((result = MHD__gnutls_x509_read_rsa_params (str, len, params)) < 0)
|
||||
if ((result =
|
||||
MHD__gnutls_x509_read_rsa_params (str, len, params)) < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return result;
|
||||
@@ -1321,8 +1337,8 @@ MHD__gnutls_x509_get_pk_algorithm (ASN1_TYPE src,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_get_signed_data (ASN1_TYPE src,
|
||||
const char *src_name,
|
||||
MHD_gnutls_datum_t * signed_data)
|
||||
const char *src_name,
|
||||
MHD_gnutls_datum_t * signed_data)
|
||||
{
|
||||
MHD_gnutls_datum_t der;
|
||||
int start, end, result;
|
||||
@@ -1337,7 +1353,7 @@ MHD__gnutls_x509_get_signed_data (ASN1_TYPE src,
|
||||
/* Get the signed data
|
||||
*/
|
||||
result = MHD__asn1_der_decoding_startEnd (src, der.data, der.size, src_name,
|
||||
&start, &end);
|
||||
&start, &end);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -1345,7 +1361,8 @@ MHD__gnutls_x509_get_signed_data (ASN1_TYPE src,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = MHD__gnutls_set_datum (signed_data, &der.data[start], end - start + 1);
|
||||
result =
|
||||
MHD__gnutls_set_datum (signed_data, &der.data[start], end - start + 1);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -1365,7 +1382,8 @@ cleanup:MHD__gnutls_free_datum (&der);
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_get_signature (ASN1_TYPE src,
|
||||
const char *src_name, MHD_gnutls_datum_t * signature)
|
||||
const char *src_name,
|
||||
MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int bits, result, len;
|
||||
|
||||
|
||||
@@ -59,13 +59,14 @@
|
||||
#define SIG_GOST_R3410_2001_OID "1.2.643.2.2.3"
|
||||
|
||||
int MHD__gnutls_x509_decode_octet_string (const char *string_type,
|
||||
const opaque * der, size_t der_size,
|
||||
opaque * output, size_t * output_size);
|
||||
const opaque * der, size_t der_size,
|
||||
opaque * output,
|
||||
size_t * output_size);
|
||||
int MHD__gnutls_x509_oid_data2string (const char *OID, void *value,
|
||||
int value_size, char *res,
|
||||
size_t * res_size);
|
||||
int value_size, char *res,
|
||||
size_t * res_size);
|
||||
int MHD__gnutls_x509_data2hex (const opaque * data, size_t data_size,
|
||||
opaque * out, size_t * sizeof_out);
|
||||
opaque * out, size_t * sizeof_out);
|
||||
|
||||
const char *MHD__gnutls_x509_oid2ldap_string (const char *OID);
|
||||
|
||||
@@ -74,50 +75,51 @@ int MHD__gnutls_x509_oid_data_printable (const char *OID);
|
||||
|
||||
time_t MHD__gnutls_x509_get_time (ASN1_TYPE c2, const char *when);
|
||||
|
||||
MHD_gnutls_x509_subject_alt_name_t MHD__gnutls_x509_san_find_type (char *str_type);
|
||||
MHD_gnutls_x509_subject_alt_name_t MHD__gnutls_x509_san_find_type (char
|
||||
*str_type);
|
||||
|
||||
int MHD__gnutls_x509_der_encode_and_copy (ASN1_TYPE src, const char *src_name,
|
||||
ASN1_TYPE dest, const char *dest_name,
|
||||
int str);
|
||||
ASN1_TYPE dest,
|
||||
const char *dest_name, int str);
|
||||
int MHD__gnutls_x509_der_encode (ASN1_TYPE src, const char *src_name,
|
||||
MHD_gnutls_datum_t * res, int str);
|
||||
MHD_gnutls_datum_t * res, int str);
|
||||
|
||||
int MHD__gnutls_x509_export_int (ASN1_TYPE MHD__asn1_data,
|
||||
MHD_gnutls_x509_crt_fmt_t format, char *pem_header,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
char *pem_header, unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
int MHD__gnutls_x509_read_value (ASN1_TYPE c, const char *root,
|
||||
MHD_gnutls_datum_t * ret, int str);
|
||||
MHD_gnutls_datum_t * ret, int str);
|
||||
int MHD__gnutls_x509_write_value (ASN1_TYPE c, const char *root,
|
||||
const MHD_gnutls_datum_t * data, int str);
|
||||
const MHD_gnutls_datum_t * data, int str);
|
||||
|
||||
int MHD__gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where,
|
||||
const void *data,
|
||||
int sizeof_data, int multi);
|
||||
ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where,
|
||||
const void *data,
|
||||
int sizeof_data, int multi);
|
||||
int MHD__gnutls_x509_decode_and_read_attribute (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where, char *oid,
|
||||
int oid_size,
|
||||
MHD_gnutls_datum_t * value, int multi,
|
||||
int octet);
|
||||
const char *where, char *oid,
|
||||
int oid_size,
|
||||
MHD_gnutls_datum_t * value,
|
||||
int multi, int octet);
|
||||
|
||||
int MHD__gnutls_x509_get_pk_algorithm (ASN1_TYPE src, const char *src_name,
|
||||
unsigned int *bits);
|
||||
unsigned int *bits);
|
||||
|
||||
int MHD__gnutls_x509_encode_and_copy_PKI_params (ASN1_TYPE dst,
|
||||
const char *dst_name,
|
||||
enum
|
||||
MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm, mpi_t * params,
|
||||
int params_size);
|
||||
const char *dst_name,
|
||||
enum
|
||||
MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm, mpi_t * params,
|
||||
int params_size);
|
||||
int MHD__gnutls_asn1_copy_node (ASN1_TYPE * dst, const char *dst_name,
|
||||
ASN1_TYPE src, const char *src_name);
|
||||
ASN1_TYPE src, const char *src_name);
|
||||
|
||||
int MHD__gnutls_x509_get_signed_data (ASN1_TYPE src, const char *src_name,
|
||||
MHD_gnutls_datum_t * signed_data);
|
||||
MHD_gnutls_datum_t * signed_data);
|
||||
int MHD__gnutls_x509_get_signature (ASN1_TYPE src, const char *src_name,
|
||||
MHD_gnutls_datum_t * signature);
|
||||
MHD_gnutls_datum_t * signature);
|
||||
|
||||
#endif
|
||||
+40
-34
@@ -56,8 +56,8 @@ MHD_gnutls_x509_crl_init (MHD_gnutls_x509_crl_t * crl)
|
||||
if (*crl)
|
||||
{
|
||||
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.CertificateList",
|
||||
&(*crl)->crl);
|
||||
"PKIX1.CertificateList",
|
||||
&(*crl)->crl);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -104,8 +104,8 @@ MHD_gnutls_x509_crl_deinit (MHD_gnutls_x509_crl_t crl)
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crl_import (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
MHD_gnutls_datum_t _data;
|
||||
@@ -125,7 +125,8 @@ MHD_gnutls_x509_crl_import (MHD_gnutls_x509_crl_t crl,
|
||||
{
|
||||
opaque *out;
|
||||
|
||||
result = MHD__gnutls_fbase64_decode (PEM_CRL, data->data, data->size, &out);
|
||||
result =
|
||||
MHD__gnutls_fbase64_decode (PEM_CRL, data->data, data->size, &out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
@@ -181,7 +182,7 @@ cleanup:
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crl_get_issuer_dn (const MHD_gnutls_x509_crl_t crl, char *buf,
|
||||
size_t * sizeof_buf)
|
||||
size_t * sizeof_buf)
|
||||
{
|
||||
if (crl == NULL)
|
||||
{
|
||||
@@ -190,8 +191,8 @@ MHD_gnutls_x509_crl_get_issuer_dn (const MHD_gnutls_x509_crl_t crl, char *buf,
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_parse_dn (crl->crl,
|
||||
"tbsCertList.issuer.rdnSequence",
|
||||
buf, sizeof_buf);
|
||||
"tbsCertList.issuer.rdnSequence",
|
||||
buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -221,9 +222,9 @@ MHD_gnutls_x509_crl_get_issuer_dn (const MHD_gnutls_x509_crl_t crl, char *buf,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crl_get_issuer_dn_by_oid (MHD_gnutls_x509_crl_t crl,
|
||||
const char *oid, int indx,
|
||||
unsigned int raw_flag, void *buf,
|
||||
size_t * sizeof_buf)
|
||||
const char *oid, int indx,
|
||||
unsigned int raw_flag, void *buf,
|
||||
size_t * sizeof_buf)
|
||||
{
|
||||
if (crl == NULL)
|
||||
{
|
||||
@@ -232,8 +233,8 @@ MHD_gnutls_x509_crl_get_issuer_dn_by_oid (MHD_gnutls_x509_crl_t crl,
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_parse_dn_oid (crl->crl,
|
||||
"tbsCertList.issuer.rdnSequence",
|
||||
oid, indx, raw_flag, buf, sizeof_buf);
|
||||
"tbsCertList.issuer.rdnSequence",
|
||||
oid, indx, raw_flag, buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -255,7 +256,7 @@ MHD_gnutls_x509_crl_get_issuer_dn_by_oid (MHD_gnutls_x509_crl_t crl,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crl_get_dn_oid (MHD_gnutls_x509_crl_t crl,
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
{
|
||||
if (crl == NULL)
|
||||
{
|
||||
@@ -264,8 +265,8 @@ MHD_gnutls_x509_crl_get_dn_oid (MHD_gnutls_x509_crl_t crl,
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_get_dn_oid (crl->crl,
|
||||
"tbsCertList.issuer.rdnSequence", indx,
|
||||
oid, sizeof_oid);
|
||||
"tbsCertList.issuer.rdnSequence", indx,
|
||||
oid, sizeof_oid);
|
||||
}
|
||||
|
||||
|
||||
@@ -297,7 +298,7 @@ MHD_gnutls_x509_crl_get_signature_algorithm (MHD_gnutls_x509_crl_t crl)
|
||||
|
||||
result =
|
||||
MHD__gnutls_x509_read_value (crl->crl, "signatureAlgorithm.algorithm",
|
||||
&sa, 0);
|
||||
&sa, 0);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -324,7 +325,7 @@ MHD_gnutls_x509_crl_get_signature_algorithm (MHD_gnutls_x509_crl_t crl)
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crl_get_signature (MHD_gnutls_x509_crl_t crl,
|
||||
char *sig, size_t * sizeof_sig)
|
||||
char *sig, size_t * sizeof_sig)
|
||||
{
|
||||
int result;
|
||||
int bits, len;
|
||||
@@ -391,7 +392,7 @@ MHD_gnutls_x509_crl_get_version (MHD_gnutls_x509_crl_t crl)
|
||||
len = sizeof (version);
|
||||
if ((result =
|
||||
MHD__asn1_read_value (crl->crl, "tbsCertList.version", version,
|
||||
&len)) != ASN1_SUCCESS)
|
||||
&len)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -468,7 +469,7 @@ MHD_gnutls_x509_crl_get_crt_count (MHD_gnutls_x509_crl_t crl)
|
||||
|
||||
result =
|
||||
MHD__asn1_number_of_elements (crl->crl,
|
||||
"tbsCertList.revokedCertificates", &count);
|
||||
"tbsCertList.revokedCertificates", &count);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -495,8 +496,8 @@ MHD_gnutls_x509_crl_get_crt_count (MHD_gnutls_x509_crl_t crl)
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl, int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t)
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t)
|
||||
{
|
||||
|
||||
int result, _serial_size;
|
||||
@@ -515,7 +516,8 @@ MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl, int indx,
|
||||
"tbsCertList.revokedCertificates.?%u.revocationDate", indx + 1);
|
||||
|
||||
_serial_size = *serial_size;
|
||||
result = MHD__asn1_read_value (crl->crl, serial_name, serial, &_serial_size);
|
||||
result =
|
||||
MHD__asn1_read_value (crl->crl, serial_name, serial, &_serial_size);
|
||||
|
||||
*serial_size = _serial_size;
|
||||
if (result != ASN1_SUCCESS)
|
||||
@@ -547,7 +549,7 @@ MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl, int indx,
|
||||
-*/
|
||||
int
|
||||
MHD__gnutls_x509_crl_get_raw_issuer_dn (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_datum_t * dn)
|
||||
MHD_gnutls_datum_t * dn)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result, len1;
|
||||
@@ -564,14 +566,15 @@ MHD__gnutls_x509_crl_get_raw_issuer_dn (MHD_gnutls_x509_crl_t crl,
|
||||
*/
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.TBSCertList",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
MHD__gnutls_x509_get_signed_data (crl->crl, "tbsCertList", &crl_signed_data);
|
||||
MHD__gnutls_x509_get_signed_data (crl->crl, "tbsCertList",
|
||||
&crl_signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -579,7 +582,8 @@ MHD__gnutls_x509_crl_get_raw_issuer_dn (MHD_gnutls_x509_crl_t crl,
|
||||
}
|
||||
|
||||
result =
|
||||
MHD__asn1_der_decoding (&c2, crl_signed_data.data, crl_signed_data.size, NULL);
|
||||
MHD__asn1_der_decoding (&c2, crl_signed_data.data, crl_signed_data.size,
|
||||
NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
/* couldn't decode DER */
|
||||
@@ -591,8 +595,8 @@ MHD__gnutls_x509_crl_get_raw_issuer_dn (MHD_gnutls_x509_crl_t crl,
|
||||
|
||||
result =
|
||||
MHD__asn1_der_decoding_startEnd (c2, crl_signed_data.data,
|
||||
crl_signed_data.size, "issuer",
|
||||
&start1, &end1);
|
||||
crl_signed_data.size, "issuer",
|
||||
&start1, &end1);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -633,8 +637,8 @@ cleanup:
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
size_t * output_data_size)
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size)
|
||||
{
|
||||
if (crl == NULL)
|
||||
{
|
||||
@@ -643,7 +647,7 @@ MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_export_int (crl->crl, format, PEM_CRL,
|
||||
output_data, output_data_size);
|
||||
output_data, output_data_size);
|
||||
}
|
||||
|
||||
/*-
|
||||
@@ -657,14 +661,16 @@ MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
|
||||
*
|
||||
-*/
|
||||
int
|
||||
MHD__gnutls_x509_crl_cpy (MHD_gnutls_x509_crl_t dest, MHD_gnutls_x509_crl_t src)
|
||||
MHD__gnutls_x509_crl_cpy (MHD_gnutls_x509_crl_t dest,
|
||||
MHD_gnutls_x509_crl_t src)
|
||||
{
|
||||
int ret;
|
||||
size_t der_size;
|
||||
opaque *der;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
|
||||
ret = MHD_gnutls_x509_crl_export (src, GNUTLS_X509_FMT_DER, NULL, &der_size);
|
||||
ret =
|
||||
MHD_gnutls_x509_crl_export (src, GNUTLS_X509_FMT_DER, NULL, &der_size);
|
||||
if (ret != GNUTLS_E_SHORT_MEMORY_BUFFER)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
|
||||
+67
-56
@@ -59,8 +59,8 @@ MHD_gnutls_x509_crq_init (MHD_gnutls_x509_crq_t * crq)
|
||||
if (*crq)
|
||||
{
|
||||
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-10-CertificationRequest",
|
||||
&((*crq)->crq));
|
||||
"PKIX1.pkcs-10-CertificationRequest",
|
||||
&((*crq)->crq));
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -110,8 +110,8 @@ MHD_gnutls_x509_crq_deinit (MHD_gnutls_x509_crq_t crq)
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_import (MHD_gnutls_x509_crq_t crq,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
MHD_gnutls_datum_t _data;
|
||||
@@ -132,7 +132,8 @@ MHD_gnutls_x509_crq_import (MHD_gnutls_x509_crq_t crq,
|
||||
opaque *out;
|
||||
|
||||
/* Try the first header */
|
||||
result = MHD__gnutls_fbase64_decode (PEM_CRQ, data->data, data->size, &out);
|
||||
result =
|
||||
MHD__gnutls_fbase64_decode (PEM_CRQ, data->data, data->size, &out);
|
||||
|
||||
if (result <= 0) /* Go for the second header */
|
||||
result =
|
||||
@@ -189,7 +190,8 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_get_dn (MHD_gnutls_x509_crq_t crq, char *buf, size_t * sizeof_buf)
|
||||
MHD_gnutls_x509_crq_get_dn (MHD_gnutls_x509_crq_t crq, char *buf,
|
||||
size_t * sizeof_buf)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
@@ -198,8 +200,8 @@ MHD_gnutls_x509_crq_get_dn (MHD_gnutls_x509_crq_t crq, char *buf, size_t * sizeo
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_parse_dn (crq->crq,
|
||||
"certificationRequestInfo.subject.rdnSequence",
|
||||
buf, sizeof_buf);
|
||||
"certificationRequestInfo.subject.rdnSequence",
|
||||
buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -232,8 +234,8 @@ MHD_gnutls_x509_crq_get_dn (MHD_gnutls_x509_crq_t crq, char *buf, size_t * sizeo
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_get_dn_by_oid (MHD_gnutls_x509_crq_t crq, const char *oid,
|
||||
int indx, unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
int indx, unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
@@ -242,8 +244,8 @@ MHD_gnutls_x509_crq_get_dn_by_oid (MHD_gnutls_x509_crq_t crq, const char *oid,
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_parse_dn_oid (crq->crq,
|
||||
"certificationRequestInfo.subject.rdnSequence",
|
||||
oid, indx, raw_flag, buf, sizeof_buf);
|
||||
"certificationRequestInfo.subject.rdnSequence",
|
||||
oid, indx, raw_flag, buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -265,7 +267,7 @@ MHD_gnutls_x509_crq_get_dn_by_oid (MHD_gnutls_x509_crq_t crq, const char *oid,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_get_dn_oid (MHD_gnutls_x509_crq_t crq,
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
@@ -274,8 +276,8 @@ MHD_gnutls_x509_crq_get_dn_oid (MHD_gnutls_x509_crq_t crq,
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_get_dn_oid (crq->crq,
|
||||
"certificationRequestInfo.subject.rdnSequence",
|
||||
indx, oid, sizeof_oid);
|
||||
"certificationRequestInfo.subject.rdnSequence",
|
||||
indx, oid, sizeof_oid);
|
||||
}
|
||||
|
||||
/* Parses an Attribute list in the MHD__asn1_struct, and searches for the
|
||||
@@ -319,7 +321,8 @@ parse_attribute (ASN1_TYPE MHD__asn1_struct,
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -362,7 +365,8 @@ parse_attribute (ASN1_TYPE MHD__asn1_struct,
|
||||
tmpbuffer1, indx + 1);
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, value, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, value, &len);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -434,7 +438,7 @@ cleanup:
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_get_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
char *pass, size_t * sizeof_pass)
|
||||
char *pass, size_t * sizeof_pass)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
@@ -461,8 +465,8 @@ MHD_gnutls_x509_crq_get_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_set_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid, void *buf,
|
||||
size_t sizeof_buf)
|
||||
const char *oid, void *buf,
|
||||
size_t sizeof_buf)
|
||||
{
|
||||
int result;
|
||||
|
||||
@@ -476,7 +480,7 @@ MHD_gnutls_x509_crq_set_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
*/
|
||||
result =
|
||||
MHD__asn1_write_value (crq->crq, "certificationRequestInfo.attributes",
|
||||
"NEW", 1);
|
||||
"NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -485,9 +489,9 @@ MHD_gnutls_x509_crq_set_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
|
||||
result =
|
||||
MHD__gnutls_x509_encode_and_write_attribute (oid,
|
||||
crq->crq,
|
||||
"certificationRequestInfo.attributes.?LAST",
|
||||
buf, sizeof_buf, 1);
|
||||
crq->crq,
|
||||
"certificationRequestInfo.attributes.?LAST",
|
||||
buf, sizeof_buf, 1);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -515,8 +519,8 @@ MHD_gnutls_x509_crq_set_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_get_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid, int indx, void *buf,
|
||||
size_t * sizeof_buf)
|
||||
const char *oid, int indx,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
@@ -550,8 +554,8 @@ MHD_gnutls_x509_crq_get_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_set_dn_by_oid (MHD_gnutls_x509_crq_t crq, const char *oid,
|
||||
unsigned int raw_flag, const void *data,
|
||||
unsigned int sizeof_data)
|
||||
unsigned int raw_flag, const void *data,
|
||||
unsigned int sizeof_data)
|
||||
{
|
||||
if (sizeof_data == 0 || data == NULL || crq == NULL)
|
||||
{
|
||||
@@ -559,8 +563,8 @@ MHD_gnutls_x509_crq_set_dn_by_oid (MHD_gnutls_x509_crq_t crq, const char *oid,
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_set_dn_oid (crq->crq,
|
||||
"certificationRequestInfo.subject", oid,
|
||||
raw_flag, data, sizeof_data);
|
||||
"certificationRequestInfo.subject", oid,
|
||||
raw_flag, data, sizeof_data);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -575,7 +579,8 @@ MHD_gnutls_x509_crq_set_dn_by_oid (MHD_gnutls_x509_crq_t crq, const char *oid,
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_set_version (MHD_gnutls_x509_crq_t crq, unsigned int version)
|
||||
MHD_gnutls_x509_crq_set_version (MHD_gnutls_x509_crq_t crq,
|
||||
unsigned int version)
|
||||
{
|
||||
int result;
|
||||
unsigned char null = version;
|
||||
@@ -590,7 +595,8 @@ MHD_gnutls_x509_crq_set_version (MHD_gnutls_x509_crq_t crq, unsigned int version
|
||||
null--;
|
||||
|
||||
result =
|
||||
MHD__asn1_write_value (crq->crq, "certificationRequestInfo.version", &null, 1);
|
||||
MHD__asn1_write_value (crq->crq, "certificationRequestInfo.version",
|
||||
&null, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -624,7 +630,7 @@ MHD_gnutls_x509_crq_get_version (MHD_gnutls_x509_crq_t crq)
|
||||
len = sizeof (version);
|
||||
if ((result =
|
||||
MHD__asn1_read_value (crq->crq, "certificationRequestInfo.version",
|
||||
version, &len)) != ASN1_SUCCESS)
|
||||
version, &len)) != ASN1_SUCCESS)
|
||||
{
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
@@ -648,7 +654,8 @@ MHD_gnutls_x509_crq_get_version (MHD_gnutls_x509_crq_t crq)
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_set_key (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key)
|
||||
MHD_gnutls_x509_crq_set_key (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_privkey_t key)
|
||||
{
|
||||
int result;
|
||||
|
||||
@@ -659,10 +666,10 @@ MHD_gnutls_x509_crq_set_key (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_encode_and_copy_PKI_params (crq->crq,
|
||||
"certificationRequestInfo.subjectPKInfo",
|
||||
key->pk_algorithm,
|
||||
key->params,
|
||||
key->params_size);
|
||||
"certificationRequestInfo.subjectPKInfo",
|
||||
key->pk_algorithm,
|
||||
key->params,
|
||||
key->params_size);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -685,7 +692,7 @@ MHD_gnutls_x509_crq_set_key (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_set_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
const char *pass)
|
||||
const char *pass)
|
||||
{
|
||||
int result;
|
||||
|
||||
@@ -699,7 +706,7 @@ MHD_gnutls_x509_crq_set_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
*/
|
||||
result =
|
||||
MHD__asn1_write_value (crq->crq, "certificationRequestInfo.attributes",
|
||||
"NEW", 1);
|
||||
"NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -708,9 +715,9 @@ MHD_gnutls_x509_crq_set_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
|
||||
result =
|
||||
MHD__gnutls_x509_encode_and_write_attribute ("1.2.840.113549.1.9.7",
|
||||
crq->crq,
|
||||
"certificationRequestInfo.attributes.?LAST",
|
||||
pass, strlen (pass), 1);
|
||||
crq->crq,
|
||||
"certificationRequestInfo.attributes.?LAST",
|
||||
pass, strlen (pass), 1);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -739,8 +746,10 @@ MHD_gnutls_x509_crq_set_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm dig, unsigned int flags)
|
||||
MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm dig,
|
||||
unsigned int flags)
|
||||
{
|
||||
int result;
|
||||
MHD_gnutls_datum_t signature;
|
||||
@@ -755,7 +764,7 @@ MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t
|
||||
*/
|
||||
result =
|
||||
MHD__gnutls_x509_sign_tbs (crq->crq, "certificationRequestInfo",
|
||||
dig, key, &signature);
|
||||
dig, key, &signature);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -767,7 +776,7 @@ MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t
|
||||
*/
|
||||
result =
|
||||
MHD__asn1_write_value (crq->crq, "signature", signature.data,
|
||||
signature.size * 8);
|
||||
signature.size * 8);
|
||||
|
||||
MHD__gnutls_free_datum (&signature);
|
||||
|
||||
@@ -780,8 +789,8 @@ MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t
|
||||
/* Step 3. Write the signatureAlgorithm field.
|
||||
*/
|
||||
result = MHD__gnutls_x509_write_sig_params (crq->crq, "signatureAlgorithm",
|
||||
key->pk_algorithm, dig, key->params,
|
||||
key->params_size);
|
||||
key->pk_algorithm, dig,
|
||||
key->params, key->params_size);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -803,7 +812,8 @@ MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_sign (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key)
|
||||
MHD_gnutls_x509_crq_sign (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_privkey_t key)
|
||||
{
|
||||
return MHD_gnutls_x509_crq_sign2 (crq, key, MHD_GNUTLS_MAC_SHA1, 0);
|
||||
}
|
||||
@@ -831,8 +841,8 @@ MHD_gnutls_x509_crq_sign (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t k
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_export (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
size_t * output_data_size)
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size)
|
||||
{
|
||||
if (crq == NULL)
|
||||
{
|
||||
@@ -841,7 +851,7 @@ MHD_gnutls_x509_crq_export (MHD_gnutls_x509_crq_t crq,
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_export_int (crq->crq, format, PEM_CRQ,
|
||||
output_data, output_data_size);
|
||||
output_data, output_data_size);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -862,7 +872,8 @@ MHD_gnutls_x509_crq_export (MHD_gnutls_x509_crq_t crq,
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crq_get_pk_algorithm (MHD_gnutls_x509_crq_t crq, unsigned int *bits)
|
||||
MHD_gnutls_x509_crq_get_pk_algorithm (MHD_gnutls_x509_crq_t crq,
|
||||
unsigned int *bits)
|
||||
{
|
||||
int result;
|
||||
|
||||
@@ -874,8 +885,8 @@ MHD_gnutls_x509_crq_get_pk_algorithm (MHD_gnutls_x509_crq_t crq, unsigned int *b
|
||||
|
||||
result =
|
||||
MHD__gnutls_x509_get_pk_algorithm (crq->crq,
|
||||
"certificationRequestInfo.subjectPKInfo",
|
||||
bits);
|
||||
"certificationRequestInfo.subjectPKInfo",
|
||||
bits);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
|
||||
+96
-64
@@ -88,8 +88,8 @@ str_escape (char *str, char *buffer, unsigned int buffer_size)
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name, char *buf,
|
||||
size_t * sizeof_buf)
|
||||
const char *MHD__asn1_rdn_name, char *buf,
|
||||
size_t * sizeof_buf)
|
||||
{
|
||||
MHD_gtls_string out_str;
|
||||
int k2, k1, result;
|
||||
@@ -115,7 +115,8 @@ MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
else
|
||||
*sizeof_buf = 0;
|
||||
|
||||
MHD_gtls_string_init (&out_str, MHD_gnutls_malloc, MHD_gnutls_realloc, MHD_gnutls_free);
|
||||
MHD_gtls_string_init (&out_str, MHD_gnutls_malloc, MHD_gnutls_realloc,
|
||||
MHD_gnutls_free);
|
||||
|
||||
k1 = 0;
|
||||
do
|
||||
@@ -125,13 +126,14 @@ MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
/* create a string like "tbsCertList.issuer.rdnSequence.?1"
|
||||
*/
|
||||
if (MHD__asn1_rdn_name[0] != 0)
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", MHD__asn1_rdn_name,
|
||||
k1);
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u",
|
||||
MHD__asn1_rdn_name, k1);
|
||||
else
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -162,7 +164,8 @@ MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
*/
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
break;
|
||||
@@ -179,7 +182,8 @@ MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
break;
|
||||
@@ -196,7 +200,8 @@ MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
|
||||
len = 0;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, NULL, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, NULL, &len);
|
||||
|
||||
value2 = MHD_gnutls_malloc (len);
|
||||
if (value2 == NULL)
|
||||
@@ -206,7 +211,8 @@ MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, value2, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, value2, &len);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -268,12 +274,14 @@ MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
if (printable)
|
||||
result =
|
||||
MHD__gnutls_x509_oid_data2string (oid,
|
||||
value2, len,
|
||||
string, &sizeof_string);
|
||||
value2, len,
|
||||
string, &sizeof_string);
|
||||
|
||||
if (!printable || result < 0)
|
||||
result =
|
||||
MHD__gnutls_x509_data2hex ((const unsigned char*) value2, len, (unsigned char*) string, &sizeof_string);
|
||||
MHD__gnutls_x509_data2hex ((const unsigned char *) value2, len,
|
||||
(unsigned char *) string,
|
||||
&sizeof_string);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -338,10 +346,10 @@ cleanup:
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name,
|
||||
const char *given_oid, int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
const char *MHD__asn1_rdn_name,
|
||||
const char *given_oid, int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
{
|
||||
int k2, k1, result;
|
||||
char tmpbuffer1[MAX_NAME_SIZE];
|
||||
@@ -366,13 +374,14 @@ MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
/* create a string like "tbsCertList.issuer.rdnSequence.?1"
|
||||
*/
|
||||
if (MHD__asn1_rdn_name[0] != 0)
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", MHD__asn1_rdn_name,
|
||||
k1);
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u",
|
||||
MHD__asn1_rdn_name, k1);
|
||||
else
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -404,7 +413,8 @@ MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
*/
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -423,7 +433,8 @@ MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
break;
|
||||
@@ -443,7 +454,9 @@ MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".value");
|
||||
|
||||
len = *sizeof_buf;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, buf, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, buf,
|
||||
&len);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -474,10 +487,12 @@ MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
if (printable == 1)
|
||||
result =
|
||||
MHD__gnutls_x509_oid_data2string (oid, buf, len,
|
||||
cbuf, sizeof_buf);
|
||||
cbuf, sizeof_buf);
|
||||
else
|
||||
result =
|
||||
MHD__gnutls_x509_data2hex (buf, len, (unsigned char*) cbuf, sizeof_buf);
|
||||
MHD__gnutls_x509_data2hex (buf, len,
|
||||
(unsigned char *) cbuf,
|
||||
sizeof_buf);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -515,8 +530,8 @@ cleanup:
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_get_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name,
|
||||
int indx, void *_oid, size_t * sizeof_oid)
|
||||
const char *MHD__asn1_rdn_name,
|
||||
int indx, void *_oid, size_t * sizeof_oid)
|
||||
{
|
||||
int k2, k1, result;
|
||||
char tmpbuffer1[MAX_NAME_SIZE];
|
||||
@@ -535,13 +550,14 @@ MHD__gnutls_x509_get_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
/* create a string like "tbsCertList.issuer.rdnSequence.?1"
|
||||
*/
|
||||
if (MHD__asn1_rdn_name[0] != 0)
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u", MHD__asn1_rdn_name,
|
||||
k1);
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "%s.?%u",
|
||||
MHD__asn1_rdn_name, k1);
|
||||
else
|
||||
snprintf (tmpbuffer1, sizeof (tmpbuffer1), "?%u", k1);
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer1, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -573,7 +589,8 @@ MHD__gnutls_x509_get_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
*/
|
||||
|
||||
len = sizeof (value) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer2, value, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
{
|
||||
@@ -592,7 +609,8 @@ MHD__gnutls_x509_get_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
MHD_gtls_str_cat (tmpbuffer3, sizeof (tmpbuffer3), ".type");
|
||||
|
||||
len = sizeof (oid) - 1;
|
||||
result = MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (MHD__asn1_struct, tmpbuffer3, oid, &len);
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
break;
|
||||
@@ -640,10 +658,10 @@ cleanup:
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where,
|
||||
const void *_data,
|
||||
int sizeof_data, int multi)
|
||||
ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where,
|
||||
const void *_data,
|
||||
int sizeof_data, int multi)
|
||||
{
|
||||
const char *val_name;
|
||||
const opaque *data = _data;
|
||||
@@ -654,7 +672,8 @@ MHD__gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
|
||||
/* Find how to encode the data.
|
||||
*/
|
||||
val_name = MHD__asn1_find_structure_from_oid (MHD__gnutls_get_pkix (), given_oid);
|
||||
val_name =
|
||||
MHD__asn1_find_structure_from_oid (MHD__gnutls_get_pkix (), given_oid);
|
||||
if (val_name == NULL)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -736,7 +755,8 @@ MHD__gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_der_encode_and_copy (c2, "", MHD__asn1_struct, tmp, 0);
|
||||
result =
|
||||
MHD__gnutls_x509_der_encode_and_copy (c2, "", MHD__asn1_struct, tmp, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -763,8 +783,9 @@ MHD__gnutls_x509_encode_and_write_attribute (const char *given_oid,
|
||||
*/
|
||||
static int
|
||||
MHD__gnutls_x509_write_attribute (const char *given_oid,
|
||||
ASN1_TYPE MHD__asn1_struct, const char *where,
|
||||
const void *_data, int sizeof_data)
|
||||
ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where, const void *_data,
|
||||
int sizeof_data)
|
||||
{
|
||||
char tmp[128];
|
||||
int result;
|
||||
@@ -808,9 +829,10 @@ MHD__gnutls_x509_write_attribute (const char *given_oid,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_decode_and_read_attribute (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *where, char *oid,
|
||||
int oid_size, MHD_gnutls_datum_t * value,
|
||||
int multi, int octet_string)
|
||||
const char *where, char *oid,
|
||||
int oid_size,
|
||||
MHD_gnutls_datum_t * value,
|
||||
int multi, int octet_string)
|
||||
{
|
||||
char tmpbuffer[128];
|
||||
int len, result;
|
||||
@@ -840,7 +862,8 @@ MHD__gnutls_x509_decode_and_read_attribute (ASN1_TYPE MHD__asn1_struct,
|
||||
MHD_gtls_str_cat (tmpbuffer, sizeof (tmpbuffer), "s.?1"); /* .values.?1 */
|
||||
|
||||
result =
|
||||
MHD__gnutls_x509_read_value (MHD__asn1_struct, tmpbuffer, value, octet_string);
|
||||
MHD__gnutls_x509_read_value (MHD__asn1_struct, tmpbuffer, value,
|
||||
octet_string);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -860,8 +883,9 @@ MHD__gnutls_x509_decode_and_read_attribute (ASN1_TYPE MHD__asn1_struct,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_set_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_name, const char *given_oid,
|
||||
int raw_flag, const char *name, int sizeof_name)
|
||||
const char *MHD__asn1_name,
|
||||
const char *given_oid, int raw_flag,
|
||||
const char *name, int sizeof_name)
|
||||
{
|
||||
int result;
|
||||
char tmp[MAX_NAME_SIZE], MHD__asn1_rdn_name[MAX_NAME_SIZE];
|
||||
@@ -874,19 +898,24 @@ MHD__gnutls_x509_set_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
|
||||
/* create the rdnSequence
|
||||
*/
|
||||
result = MHD__asn1_write_value (MHD__asn1_struct, MHD__asn1_name, "rdnSequence", 1);
|
||||
result =
|
||||
MHD__asn1_write_value (MHD__asn1_struct, MHD__asn1_name, "rdnSequence",
|
||||
1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
MHD_gtls_str_cpy (MHD__asn1_rdn_name, sizeof (MHD__asn1_rdn_name), MHD__asn1_name);
|
||||
MHD_gtls_str_cat (MHD__asn1_rdn_name, sizeof (MHD__asn1_rdn_name), ".rdnSequence");
|
||||
MHD_gtls_str_cpy (MHD__asn1_rdn_name, sizeof (MHD__asn1_rdn_name),
|
||||
MHD__asn1_name);
|
||||
MHD_gtls_str_cat (MHD__asn1_rdn_name, sizeof (MHD__asn1_rdn_name),
|
||||
".rdnSequence");
|
||||
|
||||
/* create a new element
|
||||
*/
|
||||
result = MHD__asn1_write_value (MHD__asn1_struct, MHD__asn1_rdn_name, "NEW", 1);
|
||||
result =
|
||||
MHD__asn1_write_value (MHD__asn1_struct, MHD__asn1_rdn_name, "NEW", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -915,14 +944,15 @@ MHD__gnutls_x509_set_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
{
|
||||
result =
|
||||
MHD__gnutls_x509_encode_and_write_attribute (given_oid,
|
||||
MHD__asn1_struct,
|
||||
tmp, name, sizeof_name, 0);
|
||||
MHD__asn1_struct,
|
||||
tmp, name, sizeof_name,
|
||||
0);
|
||||
}
|
||||
else
|
||||
{
|
||||
result =
|
||||
MHD__gnutls_x509_write_attribute (given_oid, MHD__asn1_struct,
|
||||
tmp, name, sizeof_name);
|
||||
tmp, name, sizeof_name);
|
||||
}
|
||||
|
||||
if (result < 0)
|
||||
@@ -952,7 +982,7 @@ MHD__gnutls_x509_set_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_rdn_get (const MHD_gnutls_datum_t * idn,
|
||||
char *buf, size_t * sizeof_buf)
|
||||
char *buf, size_t * sizeof_buf)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE dn = ASN1_TYPE_EMPTY;
|
||||
@@ -969,7 +999,7 @@ MHD_gnutls_x509_rdn_get (const MHD_gnutls_datum_t * idn,
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
|
||||
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -1010,9 +1040,10 @@ MHD_gnutls_x509_rdn_get (const MHD_gnutls_datum_t * idn,
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_rdn_get_by_oid (const MHD_gnutls_datum_t * idn, const char *oid,
|
||||
int indx, unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
MHD_gnutls_x509_rdn_get_by_oid (const MHD_gnutls_datum_t * idn,
|
||||
const char *oid, int indx,
|
||||
unsigned int raw_flag, void *buf,
|
||||
size_t * sizeof_buf)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE dn = ASN1_TYPE_EMPTY;
|
||||
@@ -1024,7 +1055,7 @@ MHD_gnutls_x509_rdn_get_by_oid (const MHD_gnutls_datum_t * idn, const char *oid,
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
|
||||
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -1041,7 +1072,7 @@ MHD_gnutls_x509_rdn_get_by_oid (const MHD_gnutls_datum_t * idn, const char *oid,
|
||||
|
||||
result =
|
||||
MHD__gnutls_x509_parse_dn_oid (dn, "rdnSequence", oid, indx,
|
||||
raw_flag, buf, sizeof_buf);
|
||||
raw_flag, buf, sizeof_buf);
|
||||
|
||||
MHD__asn1_delete_structure (&dn);
|
||||
return result;
|
||||
@@ -1064,7 +1095,7 @@ MHD_gnutls_x509_rdn_get_by_oid (const MHD_gnutls_datum_t * idn, const char *oid,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_rdn_get_oid (const MHD_gnutls_datum_t * idn,
|
||||
int indx, void *buf, size_t * sizeof_buf)
|
||||
int indx, void *buf, size_t * sizeof_buf)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE dn = ASN1_TYPE_EMPTY;
|
||||
@@ -1076,7 +1107,7 @@ MHD_gnutls_x509_rdn_get_oid (const MHD_gnutls_datum_t * idn,
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
|
||||
"PKIX1.Name", &dn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -1091,7 +1122,8 @@ MHD_gnutls_x509_rdn_get_oid (const MHD_gnutls_datum_t * idn,
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_get_dn_oid (dn, "rdnSequence", indx, buf, sizeof_buf);
|
||||
result =
|
||||
MHD__gnutls_x509_get_dn_oid (dn, "rdnSequence", indx, buf, sizeof_buf);
|
||||
|
||||
MHD__asn1_delete_structure (&dn);
|
||||
return result;
|
||||
@@ -1108,7 +1140,7 @@ MHD_gnutls_x509_rdn_get_oid (const MHD_gnutls_datum_t * idn,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_compare_raw_dn (const MHD_gnutls_datum_t * dn1,
|
||||
const MHD_gnutls_datum_t * dn2)
|
||||
const MHD_gnutls_datum_t * dn2)
|
||||
{
|
||||
|
||||
if (dn1->size != dn2->size)
|
||||
|
||||
+12
-10
@@ -38,21 +38,23 @@
|
||||
#define OID_PKCS9_EMAIL "1.2.840.113549.1.9.1"
|
||||
|
||||
int MHD__gnutls_x509_parse_dn (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name, char *buf,
|
||||
size_t * sizeof_buf);
|
||||
|
||||
int MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name, const char *oid,
|
||||
int indx, unsigned int raw_flag, void *buf,
|
||||
const char *MHD__asn1_rdn_name, char *buf,
|
||||
size_t * sizeof_buf);
|
||||
|
||||
int MHD__gnutls_x509_parse_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name,
|
||||
const char *oid, int indx,
|
||||
unsigned int raw_flag, void *buf,
|
||||
size_t * sizeof_buf);
|
||||
|
||||
int MHD__gnutls_x509_set_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name, const char *oid,
|
||||
int raw_flag, const char *name, int sizeof_name);
|
||||
const char *MHD__asn1_rdn_name,
|
||||
const char *oid, int raw_flag,
|
||||
const char *name, int sizeof_name);
|
||||
|
||||
int MHD__gnutls_x509_get_dn_oid (ASN1_TYPE MHD__asn1_struct,
|
||||
const char *MHD__asn1_rdn_name,
|
||||
int indx, void *_oid, size_t * sizeof_oid);
|
||||
const char *MHD__asn1_rdn_name,
|
||||
int indx, void *_oid, size_t * sizeof_oid);
|
||||
|
||||
|
||||
#endif
|
||||
@@ -22,4 +22,5 @@
|
||||
*
|
||||
*/
|
||||
|
||||
int MHD__gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len, int bits);
|
||||
int MHD__gnutls_dsa_generate_params (mpi_t * resarr, int *resarr_len,
|
||||
int bits);
|
||||
@@ -46,8 +46,9 @@
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_crt_get_extension (MHD_gnutls_x509_crt_t cert,
|
||||
const char *extension_id, int indx,
|
||||
MHD_gnutls_datum_t * ret, unsigned int *_critical)
|
||||
const char *extension_id, int indx,
|
||||
MHD_gnutls_datum_t * ret,
|
||||
unsigned int *_critical)
|
||||
{
|
||||
int k, result, len;
|
||||
char name[MAX_NAME_SIZE], name2[MAX_NAME_SIZE];
|
||||
@@ -136,7 +137,8 @@ MHD__gnutls_x509_crt_get_extension (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gtls_str_cpy (name2, sizeof (name2), name);
|
||||
MHD_gtls_str_cat (name2, sizeof (name2), ".extnValue");
|
||||
|
||||
result = MHD__gnutls_x509_read_value (cert->cert, name2, &value, 0);
|
||||
result =
|
||||
MHD__gnutls_x509_read_value (cert->cert, name2, &value, 0);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -177,7 +179,8 @@ MHD__gnutls_x509_crt_get_extension (MHD_gnutls_x509_crt_t cert,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx, void *oid, size_t * sizeof_oid)
|
||||
int indx, void *oid,
|
||||
size_t * sizeof_oid)
|
||||
{
|
||||
int k, result, len;
|
||||
char name[MAX_NAME_SIZE], name2[MAX_NAME_SIZE];
|
||||
@@ -264,7 +267,7 @@ MHD__gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
|
||||
opaque * extnValue, int extnValueLen)
|
||||
opaque * extnValue, int extnValueLen)
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
int len, result;
|
||||
@@ -309,16 +312,17 @@ MHD__gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_ext_extract_basicConstraints (int *CA,
|
||||
int *pathLenConstraint,
|
||||
opaque * extnValue,
|
||||
int extnValueLen)
|
||||
int *pathLenConstraint,
|
||||
opaque * extnValue,
|
||||
int extnValueLen)
|
||||
{
|
||||
ASN1_TYPE ext = ASN1_TYPE_EMPTY;
|
||||
char str[128];
|
||||
int len, result;
|
||||
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.BasicConstraints", &ext)) != ASN1_SUCCESS)
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.BasicConstraints",
|
||||
&ext)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -335,7 +339,8 @@ MHD__gnutls_x509_ext_extract_basicConstraints (int *CA,
|
||||
if (pathLenConstraint)
|
||||
{
|
||||
result = MHD__gnutls_x509_read_uint (ext, "pathLenConstraint",
|
||||
(unsigned int*) pathLenConstraint);
|
||||
(unsigned int *)
|
||||
pathLenConstraint);
|
||||
if (result == GNUTLS_E_ASN1_ELEMENT_NOT_FOUND)
|
||||
*pathLenConstraint = -1;
|
||||
else if (result != GNUTLS_E_SUCCESS)
|
||||
|
||||
@@ -23,16 +23,17 @@
|
||||
*/
|
||||
|
||||
int MHD__gnutls_x509_crt_get_extension (MHD_gnutls_x509_crt_t cert,
|
||||
const char *extension_id, int indx,
|
||||
MHD_gnutls_datum_t * ret,
|
||||
unsigned int *critical);
|
||||
const char *extension_id, int indx,
|
||||
MHD_gnutls_datum_t * ret,
|
||||
unsigned int *critical);
|
||||
|
||||
int MHD__gnutls_x509_crt_get_extension_oid (MHD_gnutls_x509_crt_t cert,
|
||||
int indx, void *ret,
|
||||
size_t * ret_size);
|
||||
int indx, void *ret,
|
||||
size_t * ret_size);
|
||||
int MHD__gnutls_x509_ext_extract_keyUsage (uint16_t * keyUsage,
|
||||
opaque * extnValue, int extnValueLen);
|
||||
opaque * extnValue,
|
||||
int extnValueLen);
|
||||
int MHD__gnutls_x509_ext_extract_basicConstraints (int *CA,
|
||||
int *pathLenConstraint,
|
||||
opaque * extnValue,
|
||||
int extnValueLen);
|
||||
int *pathLenConstraint,
|
||||
opaque * extnValue,
|
||||
int extnValueLen);
|
||||
+32
-24
@@ -44,8 +44,9 @@ MHD__gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.RSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.RSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -94,7 +95,7 @@ MHD__gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params)
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.Dss-Parms",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -161,8 +162,9 @@ MHD__gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out)
|
||||
|
||||
/* == INTEGER */
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.DSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -206,7 +208,7 @@ MHD__gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params)
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_crt_get_mpis (MHD_gnutls_x509_crt_t cert,
|
||||
mpi_t * params, int *params_size)
|
||||
mpi_t * params, int *params_size)
|
||||
{
|
||||
int result;
|
||||
int pk_algorithm;
|
||||
@@ -220,8 +222,8 @@ MHD__gnutls_x509_crt_get_mpis (MHD_gnutls_x509_crt_t cert,
|
||||
*/
|
||||
result
|
||||
= MHD__gnutls_x509_read_value (cert->cert,
|
||||
"tbsCertificate.subjectPublicKeyInfo.subjectPublicKey",
|
||||
&tmp, 2);
|
||||
"tbsCertificate.subjectPublicKeyInfo.subjectPublicKey",
|
||||
&tmp, 2);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -276,7 +278,7 @@ error:MHD__gnutls_free_datum (&tmp);
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_write_rsa_params (mpi_t * params,
|
||||
int params_size, MHD_gnutls_datum_t * der)
|
||||
int params_size, MHD_gnutls_datum_t * der)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
|
||||
@@ -292,8 +294,9 @@ MHD__gnutls_x509_write_rsa_params (mpi_t * params,
|
||||
}
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.RSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.RSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -334,11 +337,11 @@ cleanup:MHD__asn1_delete_structure (&spk);
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_write_sig_params (ASN1_TYPE dst,
|
||||
const char *dst_name,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm,
|
||||
enum MHD_GNUTLS_HashAlgorithm dig,
|
||||
mpi_t * params, int params_size)
|
||||
const char *dst_name,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm,
|
||||
enum MHD_GNUTLS_HashAlgorithm dig,
|
||||
mpi_t * params, int params_size)
|
||||
{
|
||||
int result;
|
||||
char name[128];
|
||||
@@ -391,7 +394,7 @@ MHD__gnutls_x509_write_sig_params (ASN1_TYPE dst,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_write_dsa_params (mpi_t * params,
|
||||
int params_size, MHD_gnutls_datum_t * der)
|
||||
int params_size, MHD_gnutls_datum_t * der)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
|
||||
@@ -407,8 +410,9 @@ MHD__gnutls_x509_write_dsa_params (mpi_t * params,
|
||||
}
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAParameters",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.DSAParameters",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -456,7 +460,8 @@ cleanup:MHD__asn1_delete_structure (&spk);
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_write_dsa_public_key (mpi_t * params,
|
||||
int params_size, MHD_gnutls_datum_t * der)
|
||||
int params_size,
|
||||
MHD_gnutls_datum_t * der)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE spk = ASN1_TYPE_EMPTY;
|
||||
@@ -472,8 +477,9 @@ MHD__gnutls_x509_write_dsa_public_key (mpi_t * params,
|
||||
}
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.DSAPublicKey",
|
||||
&spk)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -505,7 +511,8 @@ cleanup:MHD__asn1_delete_structure (&spk);
|
||||
* steps.
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_read_uint (ASN1_TYPE node, const char *value, unsigned int *ret)
|
||||
MHD__gnutls_x509_read_uint (ASN1_TYPE node, const char *value,
|
||||
unsigned int *ret)
|
||||
{
|
||||
int len, result;
|
||||
opaque *tmpstr;
|
||||
@@ -557,7 +564,8 @@ MHD__gnutls_x509_read_uint (ASN1_TYPE node, const char *value, unsigned int *ret
|
||||
/* Writes the specified integer into the specified node.
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value, uint32_t num)
|
||||
MHD__gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value,
|
||||
uint32_t num)
|
||||
{
|
||||
opaque tmpstr[4];
|
||||
int result;
|
||||
|
||||
+19
-16
@@ -26,32 +26,35 @@
|
||||
#include "x509.h"
|
||||
|
||||
int MHD__gnutls_x509_crt_get_mpis (MHD_gnutls_x509_crt_t cert,
|
||||
mpi_t * params, int *params_size);
|
||||
int MHD__gnutls_x509_read_rsa_params (opaque * der, int dersize, mpi_t * params);
|
||||
int MHD__gnutls_x509_read_dsa_pubkey (opaque * der, int dersize, mpi_t * params);
|
||||
int MHD__gnutls_x509_read_dsa_params (opaque * der, int dersize, mpi_t * params);
|
||||
mpi_t * params, int *params_size);
|
||||
int MHD__gnutls_x509_read_rsa_params (opaque * der, int dersize,
|
||||
mpi_t * params);
|
||||
int MHD__gnutls_x509_read_dsa_pubkey (opaque * der, int dersize,
|
||||
mpi_t * params);
|
||||
int MHD__gnutls_x509_read_dsa_params (opaque * der, int dersize,
|
||||
mpi_t * params);
|
||||
|
||||
int MHD__gnutls_x509_write_rsa_params (mpi_t * params, int params_size,
|
||||
MHD_gnutls_datum_t * der);
|
||||
int MHD__gnutls_x509_write_dsa_params (mpi_t * params, int params_size,
|
||||
MHD_gnutls_datum_t * der);
|
||||
int MHD__gnutls_x509_write_dsa_public_key (mpi_t * params, int params_size,
|
||||
MHD_gnutls_datum_t * der);
|
||||
int MHD__gnutls_x509_write_dsa_params (mpi_t * params, int params_size,
|
||||
MHD_gnutls_datum_t * der);
|
||||
int MHD__gnutls_x509_write_dsa_public_key (mpi_t * params, int params_size,
|
||||
MHD_gnutls_datum_t * der);
|
||||
|
||||
int MHD__gnutls_x509_read_uint (ASN1_TYPE node, const char *value,
|
||||
unsigned int *ret);
|
||||
unsigned int *ret);
|
||||
|
||||
int MHD__gnutls_x509_read_der_int (opaque * der, int dersize, mpi_t * out);
|
||||
|
||||
int MHD__gnutls_x509_read_int (ASN1_TYPE node, const char *value,
|
||||
mpi_t * ret_mpi);
|
||||
mpi_t * ret_mpi);
|
||||
int MHD__gnutls_x509_write_int (ASN1_TYPE node, const char *value, mpi_t mpi,
|
||||
int lz);
|
||||
int lz);
|
||||
int MHD__gnutls_x509_write_uint32 (ASN1_TYPE node, const char *value,
|
||||
uint32_t num);
|
||||
uint32_t num);
|
||||
|
||||
int MHD__gnutls_x509_write_sig_params (ASN1_TYPE dst, const char *dst_name,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
mpi_t * params, int params_size);
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm
|
||||
pk_algorithm,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
mpi_t * params, int params_size);
|
||||
@@ -81,37 +81,40 @@ extern "C"
|
||||
int MHD_gnutls_pkcs12_init (MHD_gnutls_pkcs12_t * pkcs12);
|
||||
void MHD_gnutls_pkcs12_deinit (MHD_gnutls_pkcs12_t pkcs12);
|
||||
int MHD_gnutls_pkcs12_import (MHD_gnutls_pkcs12_t pkcs12,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format, unsigned int flags);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
unsigned int flags);
|
||||
int MHD_gnutls_pkcs12_export (MHD_gnutls_pkcs12_t pkcs12,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int MHD_gnutls_pkcs12_bag_decrypt (MHD_gnutls_pkcs12_bag_t bag, const char *pass);
|
||||
int MHD_gnutls_pkcs12_bag_decrypt (MHD_gnutls_pkcs12_bag_t bag,
|
||||
const char *pass);
|
||||
int MHD_gnutls_pkcs12_bag_encrypt (MHD_gnutls_pkcs12_bag_t bag,
|
||||
const char *pass, unsigned int flags);
|
||||
const char *pass, unsigned int flags);
|
||||
|
||||
int MHD_gnutls_pkcs12_bag_get_data (MHD_gnutls_pkcs12_bag_t bag,
|
||||
int indx, MHD_gnutls_datum_t * data);
|
||||
int indx, MHD_gnutls_datum_t * data);
|
||||
int MHD_gnutls_pkcs12_bag_set_data (MHD_gnutls_pkcs12_bag_t bag,
|
||||
MHD_gnutls_pkcs12_bag_type_t type,
|
||||
const MHD_gnutls_datum_t * data);
|
||||
MHD_gnutls_pkcs12_bag_type_t type,
|
||||
const MHD_gnutls_datum_t * data);
|
||||
int MHD_gnutls_pkcs12_bag_set_crl (MHD_gnutls_pkcs12_bag_t bag,
|
||||
MHD_gnutls_x509_crl_t crl);
|
||||
MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_pkcs12_bag_set_crt (MHD_gnutls_pkcs12_bag_t bag,
|
||||
MHD_gnutls_x509_crt_t crt);
|
||||
MHD_gnutls_x509_crt_t crt);
|
||||
|
||||
int MHD_gnutls_pkcs12_bag_get_count (MHD_gnutls_pkcs12_bag_t bag);
|
||||
|
||||
int MHD_gnutls_pkcs12_bag_get_key_id (MHD_gnutls_pkcs12_bag_t bag,
|
||||
int indx, MHD_gnutls_datum_t * id);
|
||||
int indx, MHD_gnutls_datum_t * id);
|
||||
int MHD_gnutls_pkcs12_bag_set_key_id (MHD_gnutls_pkcs12_bag_t bag,
|
||||
int indx, const MHD_gnutls_datum_t * id);
|
||||
int indx,
|
||||
const MHD_gnutls_datum_t * id);
|
||||
|
||||
int MHD_gnutls_pkcs12_bag_get_friendly_name (MHD_gnutls_pkcs12_bag_t bag,
|
||||
int indx, char **name);
|
||||
int indx, char **name);
|
||||
int MHD_gnutls_pkcs12_bag_set_friendly_name (MHD_gnutls_pkcs12_bag_t bag,
|
||||
int indx, const char *name);
|
||||
int indx, const char *name);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
@@ -136,10 +139,10 @@ typedef enum schema_id
|
||||
} schema_id;
|
||||
|
||||
int MHD_pkcs12_string_to_key (unsigned int id,
|
||||
const opaque * salt,
|
||||
unsigned int salt_size,
|
||||
unsigned int iter,
|
||||
const char *pw,
|
||||
unsigned int req_keylen, opaque * keybuf);
|
||||
const opaque * salt,
|
||||
unsigned int salt_size,
|
||||
unsigned int iter,
|
||||
const char *pw,
|
||||
unsigned int req_keylen, opaque * keybuf);
|
||||
|
||||
#endif /* GNUTLS_PKCS12_H */
|
||||
@@ -55,9 +55,9 @@ MHD_pkcs12_check_pass (const char *pass, size_t plen)
|
||||
*/
|
||||
int
|
||||
MHD_pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
unsigned int salt_size, unsigned int iter,
|
||||
const char *pw, unsigned int req_keylen,
|
||||
opaque * keybuf)
|
||||
unsigned int salt_size, unsigned int iter,
|
||||
const char *pw, unsigned int req_keylen,
|
||||
opaque * keybuf)
|
||||
{
|
||||
int rc;
|
||||
unsigned int i, j;
|
||||
@@ -115,13 +115,13 @@ MHD_pkcs12_string_to_key (unsigned int id, const opaque * salt,
|
||||
for (i = 0; i < 64; i++)
|
||||
{
|
||||
unsigned char lid = id & 0xFF;
|
||||
MHD_gc_hash_write (md, 1, (const char*) &lid);
|
||||
MHD_gc_hash_write (md, 1, (const char *) &lid);
|
||||
}
|
||||
MHD_gc_hash_write (md, pw ? 128 : 64, (const char*) buf_i);
|
||||
MHD_gc_hash_write (md, pw ? 128 : 64, (const char *) buf_i);
|
||||
memcpy (hash, MHD_gc_hash_read (md), 20);
|
||||
MHD_gc_hash_close (md);
|
||||
for (i = 1; i < iter; i++)
|
||||
MHD_gc_hash_buffer (GC_SHA1, hash, 20, (char*) hash);
|
||||
MHD_gc_hash_buffer (GC_SHA1, hash, 20, (char *) hash);
|
||||
for (i = 0; i < 20 && cur_keylen < req_keylen; i++)
|
||||
keybuf[cur_keylen++] = hash[i];
|
||||
if (cur_keylen == req_keylen)
|
||||
|
||||
@@ -69,7 +69,8 @@ _decode_pkcs7_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata,
|
||||
}
|
||||
|
||||
if ((result = MHD__asn1_create_element
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-SignedData", &c2)) != ASN1_SUCCESS)
|
||||
(MHD__gnutls_get_pkix (), "PKIX1.pkcs-7-SignedData",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -158,8 +159,8 @@ MHD_gnutls_pkcs7_init (MHD_gnutls_pkcs7_t * pkcs7)
|
||||
if (*pkcs7)
|
||||
{
|
||||
int result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-7-ContentInfo",
|
||||
&(*pkcs7)->pkcs7);
|
||||
"PKIX1.pkcs-7-ContentInfo",
|
||||
&(*pkcs7)->pkcs7);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -205,8 +206,9 @@ MHD_gnutls_pkcs7_deinit (MHD_gnutls_pkcs7_t pkcs7)
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_pkcs7_import (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
MHD_gnutls_pkcs7_import (MHD_gnutls_pkcs7_t pkcs7,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
MHD_gnutls_datum_t _data;
|
||||
@@ -224,7 +226,7 @@ MHD_gnutls_pkcs7_import (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * da
|
||||
opaque *out;
|
||||
|
||||
result = MHD__gnutls_fbase64_decode (PEM_PKCS7, data->data, data->size,
|
||||
&out);
|
||||
&out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
@@ -241,7 +243,8 @@ MHD_gnutls_pkcs7_import (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * da
|
||||
}
|
||||
|
||||
|
||||
result = MHD__asn1_der_decoding (&pkcs7->pkcs7, _data.data, _data.size, NULL);
|
||||
result =
|
||||
MHD__asn1_der_decoding (&pkcs7->pkcs7, _data.data, _data.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -277,8 +280,8 @@ cleanup:
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_pkcs7_get_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
int indx, void *certificate,
|
||||
size_t * certificate_size)
|
||||
int indx, void *certificate,
|
||||
size_t * certificate_size)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result, len;
|
||||
@@ -327,7 +330,7 @@ MHD_gnutls_pkcs7_get_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
int start, end;
|
||||
|
||||
result = MHD__asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
|
||||
root2, &start, &end);
|
||||
root2, &start, &end);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -432,14 +435,14 @@ MHD_gnutls_pkcs7_get_crt_count (MHD_gnutls_pkcs7_t pkcs7)
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_pkcs7_export (MHD_gnutls_pkcs7_t pkcs7,
|
||||
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
size_t * output_data_size)
|
||||
MHD_gnutls_x509_crt_fmt_t format, void *output_data,
|
||||
size_t * output_data_size)
|
||||
{
|
||||
if (pkcs7 == NULL)
|
||||
return GNUTLS_E_INVALID_REQUEST;
|
||||
|
||||
return MHD__gnutls_x509_export_int (pkcs7->pkcs7, format, PEM_PKCS7,
|
||||
output_data, output_data_size);
|
||||
output_data, output_data_size);
|
||||
}
|
||||
|
||||
/* Creates an empty signed data structure in the pkcs7
|
||||
@@ -478,7 +481,7 @@ create_empty_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata)
|
||||
/* id-data */
|
||||
result =
|
||||
MHD__asn1_write_value (*sdata, "encapContentInfo.eContentType",
|
||||
"1.2.840.113549.1.7.5", 1);
|
||||
"1.2.840.113549.1.7.5", 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -486,7 +489,8 @@ create_empty_signed_data (ASN1_TYPE pkcs7, ASN1_TYPE * sdata)
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = MHD__asn1_write_value (*sdata, "encapContentInfo.eContent", NULL, 0);
|
||||
result =
|
||||
MHD__asn1_write_value (*sdata, "encapContentInfo.eContent", NULL, 0);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -531,7 +535,8 @@ cleanup:
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_pkcs7_set_crt_raw (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * crt)
|
||||
MHD_gnutls_pkcs7_set_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
const MHD_gnutls_datum_t * crt)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
@@ -585,7 +590,7 @@ MHD_gnutls_pkcs7_set_crt_raw (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t
|
||||
|
||||
result =
|
||||
MHD__asn1_write_value (c2, "certificates.?LAST.certificate", crt->data,
|
||||
crt->size);
|
||||
crt->size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -735,7 +740,7 @@ cleanup:
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_pkcs7_get_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
int indx, void *crl, size_t * crl_size)
|
||||
int indx, void *crl, size_t * crl_size)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
@@ -763,7 +768,7 @@ MHD_gnutls_pkcs7_get_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
/* Get the raw CRL
|
||||
*/
|
||||
result = MHD__asn1_der_decoding_startEnd (c2, tmp.data, tmp.size,
|
||||
root2, &start, &end);
|
||||
root2, &start, &end);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -849,7 +854,8 @@ MHD_gnutls_pkcs7_get_crl_count (MHD_gnutls_pkcs7_t pkcs7)
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_pkcs7_set_crl_raw (MHD_gnutls_pkcs7_t pkcs7, const MHD_gnutls_datum_t * crl)
|
||||
MHD_gnutls_pkcs7_set_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
const MHD_gnutls_datum_t * crl)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
|
||||
@@ -25,7 +25,8 @@
|
||||
#include "x509.h"
|
||||
|
||||
ASN1_TYPE MHD__gnutls_privkey_decode_pkcs1_rsa_key (const MHD_gnutls_datum_t *
|
||||
raw_key,
|
||||
MHD_gnutls_x509_privkey_t pkey);
|
||||
raw_key,
|
||||
MHD_gnutls_x509_privkey_t
|
||||
pkey);
|
||||
|
||||
int MHD__gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params);
|
||||
@@ -82,7 +82,7 @@ static int decrypt_data (schema_id, ASN1_TYPE pkcs8_asn, const char *root,
|
||||
static int decode_private_key_info (const MHD_gnutls_datum_t * der,
|
||||
MHD_gnutls_x509_privkey_t pkey);
|
||||
static int readMHD_pkcs12_kdf_params (ASN1_TYPE pbes2_asn,
|
||||
struct pbkdf2_params *params);
|
||||
struct pbkdf2_params *params);
|
||||
|
||||
#define PEM_PKCS8 "ENCRYPTED PRIVATE KEY"
|
||||
#define PEM_UNENCRYPTED_PKCS8 "PRIVATE KEY"
|
||||
@@ -106,7 +106,8 @@ check_schema (const char *oid)
|
||||
if (strcmp (oid, PKCS12_PBE_RC2_40_SHA1_OID) == 0)
|
||||
return PKCS12_RC2_40_SHA1;
|
||||
|
||||
MHD__gnutls_x509_log ("PKCS encryption schema OID '%s' is unsupported.\n", oid);
|
||||
MHD__gnutls_x509_log ("PKCS encryption schema OID '%s' is unsupported.\n",
|
||||
oid);
|
||||
|
||||
return GNUTLS_E_UNKNOWN_CIPHER_TYPE;
|
||||
}
|
||||
@@ -134,8 +135,8 @@ read_pkcs_schema_params (schema_id schema, const char *password,
|
||||
*/
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-5-PBES2-params",
|
||||
&pbes2_asn)) != ASN1_SUCCESS)
|
||||
"PKIX1.pkcs-5-PBES2-params",
|
||||
&pbes2_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -197,8 +198,8 @@ read_pkcs_schema_params (schema_id schema, const char *password,
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-12-PbeParams",
|
||||
&pbes2_asn)) != ASN1_SUCCESS)
|
||||
"PKIX1.pkcs-12-PbeParams",
|
||||
&pbes2_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -226,9 +227,9 @@ read_pkcs_schema_params (schema_id schema, const char *password,
|
||||
{
|
||||
result =
|
||||
MHD_pkcs12_string_to_key (2 /*IV*/, kdf_params->salt,
|
||||
kdf_params->salt_size,
|
||||
kdf_params->iter_count, password,
|
||||
enc_params->iv_size, enc_params->iv);
|
||||
kdf_params->salt_size,
|
||||
kdf_params->iter_count, password,
|
||||
enc_params->iv_size, enc_params->iv);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -270,15 +271,16 @@ decode_pkcs8_key (const MHD_gnutls_datum_t * raw_key,
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-8-EncryptedPrivateKeyInfo",
|
||||
&pkcs8_asn)) != ASN1_SUCCESS)
|
||||
"PKIX1.pkcs-8-EncryptedPrivateKeyInfo",
|
||||
&pkcs8_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto error;
|
||||
}
|
||||
|
||||
result = MHD__asn1_der_decoding (&pkcs8_asn, raw_key->data, raw_key->size, NULL);
|
||||
result =
|
||||
MHD__asn1_der_decoding (&pkcs8_asn, raw_key->data, raw_key->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -291,7 +293,7 @@ decode_pkcs8_key (const MHD_gnutls_datum_t * raw_key,
|
||||
len = sizeof (enc_oid);
|
||||
result =
|
||||
MHD__asn1_read_value (pkcs8_asn, "encryptionAlgorithm.algorithm",
|
||||
enc_oid, &len);
|
||||
enc_oid, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -310,9 +312,9 @@ decode_pkcs8_key (const MHD_gnutls_datum_t * raw_key,
|
||||
*/
|
||||
result =
|
||||
MHD__asn1_der_decoding_startEnd (pkcs8_asn, raw_key->data,
|
||||
raw_key->size,
|
||||
"encryptionAlgorithm.parameters",
|
||||
¶ms_start, ¶ms_end);
|
||||
raw_key->size,
|
||||
"encryptionAlgorithm.parameters",
|
||||
¶ms_start, ¶ms_end);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -416,8 +418,8 @@ decode_private_key_info (const MHD_gnutls_datum_t * der,
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-8-PrivateKeyInfo",
|
||||
&pkcs8_asn)) != ASN1_SUCCESS)
|
||||
"PKIX1.pkcs-8-PrivateKeyInfo",
|
||||
&pkcs8_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -436,7 +438,8 @@ decode_private_key_info (const MHD_gnutls_datum_t * der,
|
||||
*/
|
||||
len = sizeof (oid);
|
||||
result =
|
||||
MHD__asn1_read_value (pkcs8_asn, "privateKeyAlgorithm.algorithm", oid, &len);
|
||||
MHD__asn1_read_value (pkcs8_asn, "privateKeyAlgorithm.algorithm", oid,
|
||||
&len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -446,7 +449,7 @@ decode_private_key_info (const MHD_gnutls_datum_t * der,
|
||||
|
||||
/* we only support RSA and DSA private keys.
|
||||
*/
|
||||
if (strcmp ((const char*) oid, PK_PKIX1_RSA_OID) == 0)
|
||||
if (strcmp ((const char *) oid, PK_PKIX1_RSA_OID) == 0)
|
||||
pkey->pk_algorithm = MHD_GNUTLS_PK_RSA;
|
||||
else
|
||||
{
|
||||
@@ -502,9 +505,10 @@ error:
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_privkey_import_pkcs8 (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
const char *password, unsigned int flags)
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
const char *password,
|
||||
unsigned int flags)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
MHD_gnutls_datum_t _data;
|
||||
@@ -530,13 +534,14 @@ MHD_gnutls_x509_privkey_import_pkcs8 (MHD_gnutls_x509_privkey_t key,
|
||||
*/
|
||||
result =
|
||||
MHD__gnutls_fbase64_decode (PEM_UNENCRYPTED_PKCS8,
|
||||
data->data, data->size, &out);
|
||||
data->data, data->size, &out);
|
||||
|
||||
if (result < 0)
|
||||
{ /* Try the encrypted header
|
||||
*/
|
||||
result =
|
||||
MHD__gnutls_fbase64_decode (PEM_PKCS8, data->data, data->size, &out);
|
||||
MHD__gnutls_fbase64_decode (PEM_PKCS8, data->data, data->size,
|
||||
&out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
@@ -589,7 +594,8 @@ cleanup:
|
||||
*/
|
||||
static int
|
||||
read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
const MHD_gnutls_datum_t * der, struct pbkdf2_params *params)
|
||||
const MHD_gnutls_datum_t * der,
|
||||
struct pbkdf2_params *params)
|
||||
{
|
||||
int params_start, params_end;
|
||||
int params_len, len, result;
|
||||
@@ -602,7 +608,8 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
*/
|
||||
len = sizeof (oid);
|
||||
result =
|
||||
MHD__asn1_read_value (pbes2_asn, "keyDerivationFunc.algorithm", oid, &len);
|
||||
MHD__asn1_read_value (pbes2_asn, "keyDerivationFunc.algorithm", oid,
|
||||
&len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -620,8 +627,8 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
|
||||
result =
|
||||
MHD__asn1_der_decoding_startEnd (pbes2_asn, der->data, der->size,
|
||||
"keyDerivationFunc.parameters",
|
||||
¶ms_start, ¶ms_end);
|
||||
"keyDerivationFunc.parameters",
|
||||
¶ms_start, ¶ms_end);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -634,8 +641,8 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
*/
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-5-PBKDF2-params",
|
||||
&pbkdf2_asn)) != ASN1_SUCCESS)
|
||||
"PKIX1.pkcs-5-PBKDF2-params",
|
||||
&pbkdf2_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -643,7 +650,7 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
|
||||
result =
|
||||
MHD__asn1_der_decoding (&pbkdf2_asn, &der->data[params_start],
|
||||
params_len, NULL);
|
||||
params_len, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -655,7 +662,7 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
params->salt_size = sizeof (params->salt);
|
||||
result =
|
||||
MHD__asn1_read_value (pbkdf2_asn, "salt.specified", params->salt,
|
||||
¶ms->salt_size);
|
||||
¶ms->salt_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -668,7 +675,7 @@ read_pbkdf2_params (ASN1_TYPE pbes2_asn,
|
||||
*/
|
||||
result =
|
||||
MHD__gnutls_x509_read_uint (pbkdf2_asn, "iterationCount",
|
||||
¶ms->iter_count);
|
||||
¶ms->iter_count);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -709,7 +716,8 @@ readMHD_pkcs12_kdf_params (ASN1_TYPE pbes2_asn, struct pbkdf2_params *params)
|
||||
/* read the salt */
|
||||
params->salt_size = sizeof (params->salt);
|
||||
result =
|
||||
MHD__asn1_read_value (pbes2_asn, "salt", params->salt, ¶ms->salt_size);
|
||||
MHD__asn1_read_value (pbes2_asn, "salt", params->salt,
|
||||
¶ms->salt_size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -794,8 +802,8 @@ read_pbe_enc_params (ASN1_TYPE pbes2_asn,
|
||||
|
||||
result =
|
||||
MHD__asn1_der_decoding_startEnd (pbes2_asn, der->data, der->size,
|
||||
"encryptionScheme.parameters",
|
||||
¶ms_start, ¶ms_end);
|
||||
"encryptionScheme.parameters",
|
||||
¶ms_start, ¶ms_end);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -807,15 +815,16 @@ read_pbe_enc_params (ASN1_TYPE pbes2_asn,
|
||||
*/
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.pkcs-5-des-EDE3-CBC-params",
|
||||
&pbe_asn)) != ASN1_SUCCESS)
|
||||
"PKIX1.pkcs-5-des-EDE3-CBC-params",
|
||||
&pbe_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result =
|
||||
MHD__asn1_der_decoding (&pbe_asn, &der->data[params_start], params_len, NULL);
|
||||
MHD__asn1_der_decoding (&pbe_asn, &der->data[params_start], params_len,
|
||||
NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -899,9 +908,10 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
if (schema == PBES2)
|
||||
{
|
||||
result = MHD_gc_pbkdf2_sha1 (password, strlen (password),
|
||||
(const char*) kdf_params->salt, kdf_params->salt_size,
|
||||
kdf_params->iter_count,
|
||||
(char*) key, key_size);
|
||||
(const char *) kdf_params->salt,
|
||||
kdf_params->salt_size,
|
||||
kdf_params->iter_count, (char *) key,
|
||||
key_size);
|
||||
|
||||
if (result != GC_OK)
|
||||
{
|
||||
@@ -914,9 +924,9 @@ decrypt_data (schema_id schema, ASN1_TYPE pkcs8_asn,
|
||||
{
|
||||
result =
|
||||
MHD_pkcs12_string_to_key (1 /*KEY*/, kdf_params->salt,
|
||||
kdf_params->salt_size,
|
||||
kdf_params->iter_count, password,
|
||||
key_size, key);
|
||||
kdf_params->salt_size,
|
||||
kdf_params->iter_count, password,
|
||||
key_size, key);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
|
||||
@@ -84,7 +84,8 @@ MHD__gnutls_hostname_compare (const char *certname, const char *hostname)
|
||||
* Returns non zero for a successful match, and zero on failure.
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_check_hostname (MHD_gnutls_x509_crt_t cert, const char *hostname)
|
||||
MHD_gnutls_x509_crt_check_hostname (MHD_gnutls_x509_crt_t cert,
|
||||
const char *hostname)
|
||||
{
|
||||
|
||||
char dnsname[MAX_CN];
|
||||
@@ -112,8 +113,8 @@ MHD_gnutls_x509_crt_check_hostname (MHD_gnutls_x509_crt_t cert, const char *host
|
||||
|
||||
dnsnamesize = sizeof (dnsname);
|
||||
ret = MHD_gnutls_x509_crt_get_subject_alt_name (cert, i,
|
||||
dnsname, &dnsnamesize,
|
||||
NULL);
|
||||
dnsname, &dnsnamesize,
|
||||
NULL);
|
||||
|
||||
if (ret == GNUTLS_SAN_DNSNAME)
|
||||
{
|
||||
@@ -141,7 +142,7 @@ MHD_gnutls_x509_crt_check_hostname (MHD_gnutls_x509_crt_t cert, const char *host
|
||||
*/
|
||||
dnsnamesize = sizeof (dnsname);
|
||||
if (MHD_gnutls_x509_crt_get_dn_by_oid (cert, OID_X520_COMMON_NAME, 0,
|
||||
0, dnsname, &dnsnamesize) < 0)
|
||||
0, dnsname, &dnsnamesize) < 0)
|
||||
{
|
||||
/* got an error, can't find a name
|
||||
*/
|
||||
|
||||
@@ -50,7 +50,8 @@
|
||||
*/
|
||||
static int
|
||||
encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
const MHD_gnutls_datum_t * digest, MHD_gnutls_datum_t * info)
|
||||
const MHD_gnutls_datum_t * digest,
|
||||
MHD_gnutls_datum_t * info)
|
||||
{
|
||||
ASN1_TYPE dinfo = ASN1_TYPE_EMPTY;
|
||||
int result;
|
||||
@@ -65,14 +66,15 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
}
|
||||
|
||||
if ((result = MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.DigestInfo",
|
||||
&dinfo)) != ASN1_SUCCESS)
|
||||
"GNUTLS.DigestInfo",
|
||||
&dinfo)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = MHD__asn1_write_value (dinfo, "digestAlgorithm.algorithm", algo, 1);
|
||||
result =
|
||||
MHD__asn1_write_value (dinfo, "digestAlgorithm.algorithm", algo, 1);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -86,7 +88,7 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
Regardless of what is correct, this appears to be what most
|
||||
implementations do. */
|
||||
result = MHD__asn1_write_value (dinfo, "digestAlgorithm.parameters",
|
||||
"\x05\x00", 2);
|
||||
"\x05\x00", 2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -94,7 +96,8 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = MHD__asn1_write_value (dinfo, "digest", digest->data, digest->size);
|
||||
result =
|
||||
MHD__asn1_write_value (dinfo, "digest", digest->data, digest->size);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -103,7 +106,7 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
}
|
||||
|
||||
info->size = 0;
|
||||
MHD__asn1_der_coding (dinfo, "", NULL, (int*) &info->size, NULL);
|
||||
MHD__asn1_der_coding (dinfo, "", NULL, (int *) &info->size, NULL);
|
||||
|
||||
info->data = MHD_gnutls_malloc (info->size);
|
||||
if (info->data == NULL)
|
||||
@@ -113,7 +116,8 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
result = MHD__asn1_der_coding (dinfo, "", info->data, (int*) &info->size, NULL);
|
||||
result =
|
||||
MHD__asn1_der_coding (dinfo, "", info->data, (int *) &info->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -133,8 +137,8 @@ encode_ber_digest_info (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
*/
|
||||
static int
|
||||
pkcs1_rsa_sign (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
const MHD_gnutls_datum_t * text, mpi_t * params, int params_len,
|
||||
MHD_gnutls_datum_t * signature)
|
||||
const MHD_gnutls_datum_t * text, mpi_t * params,
|
||||
int params_len, MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int ret;
|
||||
opaque _digest[MAX_HASH_SIZE];
|
||||
@@ -187,8 +191,9 @@ pkcs1_rsa_sign (enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
*/
|
||||
static int
|
||||
MHD__gnutls_x509_sign (const MHD_gnutls_datum_t * tbs,
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
MHD_gnutls_x509_privkey_t signer, MHD_gnutls_datum_t * signature)
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
MHD_gnutls_x509_privkey_t signer,
|
||||
MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int ret;
|
||||
|
||||
@@ -218,9 +223,9 @@ MHD__gnutls_x509_sign (const MHD_gnutls_datum_t * tbs,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
MHD_gnutls_x509_privkey_t signer,
|
||||
MHD_gnutls_datum_t * signature)
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
MHD_gnutls_x509_privkey_t signer,
|
||||
MHD_gnutls_datum_t * signature)
|
||||
{
|
||||
int result;
|
||||
opaque *buf;
|
||||
|
||||
@@ -23,6 +23,6 @@
|
||||
*/
|
||||
|
||||
int MHD__gnutls_x509_sign_tbs (ASN1_TYPE cert, const char *tbs_name,
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
MHD_gnutls_x509_privkey_t signer,
|
||||
MHD_gnutls_datum_t * signature);
|
||||
enum MHD_GNUTLS_HashAlgorithm hash,
|
||||
MHD_gnutls_x509_privkey_t signer,
|
||||
MHD_gnutls_datum_t * signature);
|
||||
@@ -25,10 +25,12 @@
|
||||
#include "x509.h"
|
||||
|
||||
int MHD_gnutls_x509_crt_is_issuer (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
int MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
int MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
int MHD__gnutls_x509_privkey_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_privkey_t issuer);
|
||||
const MHD_gnutls_datum_t *
|
||||
signature,
|
||||
MHD_gnutls_x509_privkey_t
|
||||
issuer);
|
||||
@@ -51,14 +51,15 @@
|
||||
int
|
||||
MHD_gnutls_x509_crt_init (MHD_gnutls_x509_crt_t * cert)
|
||||
{
|
||||
MHD_gnutls_x509_crt_t tmp = MHD_gnutls_calloc (1, sizeof (MHD_gnutls_x509_crt_int));
|
||||
MHD_gnutls_x509_crt_t tmp =
|
||||
MHD_gnutls_calloc (1, sizeof (MHD_gnutls_x509_crt_int));
|
||||
int result;
|
||||
|
||||
if (!tmp)
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
|
||||
result = MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.Certificate", &tmp->cert);
|
||||
"PKIX1.Certificate", &tmp->cert);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -107,8 +108,8 @@ MHD_gnutls_x509_crt_deinit (MHD_gnutls_x509_crt_t cert)
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_import (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
MHD_gnutls_datum_t _data;
|
||||
@@ -130,14 +131,15 @@ MHD_gnutls_x509_crt_import (MHD_gnutls_x509_crt_t cert,
|
||||
opaque *out;
|
||||
|
||||
/* Try the first header */
|
||||
result = MHD__gnutls_fbase64_decode (PEM_X509_CERT2, data->data, data->size,
|
||||
&out);
|
||||
result =
|
||||
MHD__gnutls_fbase64_decode (PEM_X509_CERT2, data->data, data->size,
|
||||
&out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
/* try for the second header */
|
||||
result = MHD__gnutls_fbase64_decode (PEM_X509_CERT, data->data,
|
||||
data->size, &out);
|
||||
data->size, &out);
|
||||
|
||||
if (result <= 0)
|
||||
{
|
||||
@@ -205,10 +207,10 @@ cleanup:MHD_gnutls_free (signature);
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_get_dn_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf)
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
@@ -217,8 +219,8 @@ MHD_gnutls_x509_crt_get_dn_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_parse_dn_oid (cert->cert,
|
||||
"tbsCertificate.subject.rdnSequence", oid,
|
||||
indx, raw_flag, buf, sizeof_buf);
|
||||
"tbsCertificate.subject.rdnSequence",
|
||||
oid, indx, raw_flag, buf, sizeof_buf);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -247,8 +249,8 @@ MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert)
|
||||
* read. They will be read from the issuer's certificate if needed.
|
||||
*/
|
||||
result =
|
||||
MHD__gnutls_x509_read_value (cert->cert, "signatureAlgorithm.algorithm", &sa,
|
||||
0);
|
||||
MHD__gnutls_x509_read_value (cert->cert, "signatureAlgorithm.algorithm",
|
||||
&sa, 0);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -256,7 +258,7 @@ MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert)
|
||||
return result;
|
||||
}
|
||||
|
||||
result = MHD_gtls_x509_oid2sign_algorithm ((const char*) sa.data);
|
||||
result = MHD_gtls_x509_oid2sign_algorithm ((const char *) sa.data);
|
||||
|
||||
MHD__gnutls_free_datum (&sa);
|
||||
|
||||
@@ -275,7 +277,7 @@ MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert)
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_get_signature (MHD_gnutls_x509_crt_t cert,
|
||||
char *sig, size_t * sizeof_sig)
|
||||
char *sig, size_t * sizeof_sig)
|
||||
{
|
||||
int result;
|
||||
int bits, len;
|
||||
@@ -342,7 +344,7 @@ MHD_gnutls_x509_crt_get_version (MHD_gnutls_x509_crt_t cert)
|
||||
len = sizeof (version);
|
||||
if ((result =
|
||||
MHD__asn1_read_value (cert->cert, "tbsCertificate.version", version,
|
||||
&len)) != ASN1_SUCCESS)
|
||||
&len)) != ASN1_SUCCESS)
|
||||
{
|
||||
|
||||
if (result == ASN1_ELEMENT_NOT_FOUND)
|
||||
@@ -373,7 +375,7 @@ MHD_gnutls_x509_crt_get_activation_time (MHD_gnutls_x509_crt_t cert)
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_get_time (cert->cert,
|
||||
"tbsCertificate.validity.notBefore");
|
||||
"tbsCertificate.validity.notBefore");
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -395,7 +397,7 @@ MHD_gnutls_x509_crt_get_expiration_time (MHD_gnutls_x509_crt_t cert)
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_get_time (cert->cert,
|
||||
"tbsCertificate.validity.notAfter");
|
||||
"tbsCertificate.validity.notAfter");
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -415,7 +417,7 @@ MHD_gnutls_x509_crt_get_expiration_time (MHD_gnutls_x509_crt_t cert)
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
|
||||
void *result, size_t * result_size)
|
||||
void *result, size_t * result_size)
|
||||
{
|
||||
int ret, len;
|
||||
|
||||
@@ -428,7 +430,8 @@ MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
|
||||
len = *result_size;
|
||||
ret
|
||||
=
|
||||
MHD__asn1_read_value (cert->cert, "tbsCertificate.serialNumber", result, &len);
|
||||
MHD__asn1_read_value (cert->cert, "tbsCertificate.serialNumber", result,
|
||||
&len);
|
||||
*result_size = len;
|
||||
|
||||
if (ret != ASN1_SUCCESS)
|
||||
@@ -459,7 +462,8 @@ MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert, unsigned int *bits)
|
||||
MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *bits)
|
||||
{
|
||||
int result;
|
||||
|
||||
@@ -470,8 +474,8 @@ MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert, unsigned int *
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_get_pk_algorithm (cert->cert,
|
||||
"tbsCertificate.subjectPublicKeyInfo",
|
||||
bits);
|
||||
"tbsCertificate.subjectPublicKeyInfo",
|
||||
bits);
|
||||
|
||||
if (result < 0)
|
||||
{
|
||||
@@ -533,7 +537,7 @@ parse_general_name (ASN1_TYPE src,
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
type = MHD__gnutls_x509_san_find_type ((char*) choice_type);
|
||||
type = MHD__gnutls_x509_san_find_type ((char *) choice_type);
|
||||
if (type == (MHD_gnutls_x509_subject_alt_name_t) - 1)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -591,8 +595,8 @@ parse_general_name (ASN1_TYPE src,
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
|
||||
result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.XmppAddr",
|
||||
&c2);
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.XmppAddr", &c2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -636,7 +640,7 @@ parse_general_name (ASN1_TYPE src,
|
||||
size_t orig_name_size = *name_size;
|
||||
|
||||
MHD_gtls_str_cat (nptr, sizeof (nptr), ".");
|
||||
MHD_gtls_str_cat (nptr, sizeof (nptr), (const char*) choice_type);
|
||||
MHD_gtls_str_cat (nptr, sizeof (nptr), (const char *) choice_type);
|
||||
|
||||
len = *name_size;
|
||||
result = MHD__asn1_read_value (src, nptr, name, &len);
|
||||
@@ -700,7 +704,7 @@ get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
|
||||
if ((result =
|
||||
MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.17", 0, &dnsname,
|
||||
critical)) < 0)
|
||||
critical)) < 0)
|
||||
{
|
||||
return result;
|
||||
}
|
||||
@@ -712,7 +716,8 @@ get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.SubjectAltName", &c2);
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.SubjectAltName",
|
||||
&c2);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -781,10 +786,10 @@ get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical)
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical)
|
||||
{
|
||||
return get_subject_alt_name (cert, seq, ret, ret_size, NULL, critical, 0);
|
||||
}
|
||||
@@ -811,8 +816,8 @@ MHD_gnutls_x509_crt_get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
**/
|
||||
static int
|
||||
MHD_gnutls_x509_crt_get_basic_constraints (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *critical,
|
||||
int *ca, int *pathlen)
|
||||
unsigned int *critical,
|
||||
int *ca, int *pathlen)
|
||||
{
|
||||
int result;
|
||||
MHD_gnutls_datum_t basicConstraints;
|
||||
@@ -825,8 +830,8 @@ MHD_gnutls_x509_crt_get_basic_constraints (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
if ((result = MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.19", 0,
|
||||
&basicConstraints, critical))
|
||||
< 0)
|
||||
&basicConstraints,
|
||||
critical)) < 0)
|
||||
{
|
||||
return result;
|
||||
}
|
||||
@@ -838,8 +843,10 @@ MHD_gnutls_x509_crt_get_basic_constraints (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_ext_extract_basicConstraints (&tmp_ca, pathlen,
|
||||
basicConstraints.data,
|
||||
basicConstraints.size);
|
||||
basicConstraints.
|
||||
data,
|
||||
basicConstraints.
|
||||
size);
|
||||
if (ca)
|
||||
*ca = tmp_ca;
|
||||
MHD__gnutls_free_datum (&basicConstraints);
|
||||
@@ -872,11 +879,12 @@ MHD_gnutls_x509_crt_get_basic_constraints (MHD_gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert, unsigned int *critical)
|
||||
MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *critical)
|
||||
{
|
||||
int ca, pathlen;
|
||||
return MHD_gnutls_x509_crt_get_basic_constraints (cert, critical, &ca,
|
||||
&pathlen);
|
||||
&pathlen);
|
||||
}
|
||||
|
||||
/**
|
||||
@@ -900,8 +908,8 @@ MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert, unsigned int *cri
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical)
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical)
|
||||
{
|
||||
int result;
|
||||
MHD_gnutls_datum_t keyUsage;
|
||||
@@ -915,7 +923,7 @@ MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
|
||||
|
||||
if ((result =
|
||||
MHD__gnutls_x509_crt_get_extension (cert, "2.5.29.15", 0, &keyUsage,
|
||||
critical)) < 0)
|
||||
critical)) < 0)
|
||||
{
|
||||
return result;
|
||||
}
|
||||
@@ -927,7 +935,7 @@ MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_ext_extract_keyUsage (&_usage, keyUsage.data,
|
||||
keyUsage.size);
|
||||
keyUsage.size);
|
||||
MHD__gnutls_free_datum (&keyUsage);
|
||||
|
||||
*key_usage = _usage;
|
||||
@@ -944,7 +952,8 @@ MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
|
||||
|
||||
static int
|
||||
MHD__gnutls_x509_crt_get_raw_dn2 (MHD_gnutls_x509_crt_t cert,
|
||||
const char *whom, MHD_gnutls_datum_t * start)
|
||||
const char *whom,
|
||||
MHD_gnutls_datum_t * start)
|
||||
{
|
||||
ASN1_TYPE c2 = ASN1_TYPE_EMPTY;
|
||||
int result, len1;
|
||||
@@ -956,22 +965,24 @@ MHD__gnutls_x509_crt_get_raw_dn2 (MHD_gnutls_x509_crt_t cert,
|
||||
/* get the issuer of 'cert'
|
||||
*/
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (), "PKIX1.TBSCertificate",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
MHD__asn1_create_element (MHD__gnutls_get_pkix (),
|
||||
"PKIX1.TBSCertificate",
|
||||
&c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
|
||||
&signed_data);
|
||||
&signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = MHD__asn1_der_decoding (&c2, signed_data.data, signed_data.size, NULL);
|
||||
result =
|
||||
MHD__asn1_der_decoding (&c2, signed_data.data, signed_data.size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -980,8 +991,9 @@ MHD__gnutls_x509_crt_get_raw_dn2 (MHD_gnutls_x509_crt_t cert,
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = MHD__asn1_der_decoding_startEnd (c2, signed_data.data, signed_data.size,
|
||||
whom, &start1, &end1);
|
||||
result =
|
||||
MHD__asn1_der_decoding_startEnd (c2, signed_data.data, signed_data.size,
|
||||
whom, &start1, &end1);
|
||||
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
@@ -1014,7 +1026,7 @@ cleanup:MHD__asn1_delete_structure (&c2);
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_get_raw_issuer_dn (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_datum_t * start)
|
||||
MHD_gnutls_datum_t * start)
|
||||
{
|
||||
return MHD__gnutls_x509_crt_get_raw_dn2 (cert, "issuer", start);
|
||||
}
|
||||
@@ -1031,13 +1043,15 @@ MHD_gnutls_x509_crt_get_raw_issuer_dn (MHD_gnutls_x509_crt_t cert,
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_get_raw_dn (MHD_gnutls_x509_crt_t cert, MHD_gnutls_datum_t * start)
|
||||
MHD_gnutls_x509_crt_get_raw_dn (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_datum_t * start)
|
||||
{
|
||||
return MHD__gnutls_x509_crt_get_raw_dn2 (cert, "subject", start);
|
||||
}
|
||||
|
||||
static int
|
||||
get_dn (MHD_gnutls_x509_crt_t cert, const char *whom, MHD_gnutls_x509_dn_t * dn)
|
||||
get_dn (MHD_gnutls_x509_crt_t cert, const char *whom,
|
||||
MHD_gnutls_x509_dn_t * dn)
|
||||
{
|
||||
*dn = MHD__asn1_find_node (cert->cert, whom);
|
||||
if (!*dn)
|
||||
@@ -1056,7 +1070,8 @@ get_dn (MHD_gnutls_x509_crt_t cert, const char *whom, MHD_gnutls_x509_dn_t * dn)
|
||||
* Returns: Returns 0 on success, or an error code.
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_get_subject (MHD_gnutls_x509_crt_t cert, MHD_gnutls_x509_dn_t * dn)
|
||||
MHD_gnutls_x509_crt_get_subject (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_dn_t * dn)
|
||||
{
|
||||
return get_dn (cert, "tbsCertificate.subject.rdnSequence", dn);
|
||||
}
|
||||
@@ -1083,8 +1098,8 @@ MHD_gnutls_x509_crt_get_subject (MHD_gnutls_x509_crt_t cert, MHD_gnutls_x509_dn_
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size)
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size)
|
||||
{
|
||||
if (cert == NULL)
|
||||
{
|
||||
@@ -1093,7 +1108,7 @@ MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
return MHD__gnutls_x509_export_int (cert->cert, format, "CERTIFICATE",
|
||||
output_data, output_data_size);
|
||||
output_data, output_data_size);
|
||||
}
|
||||
|
||||
#ifdef ENABLE_PKI
|
||||
@@ -1112,8 +1127,8 @@ MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crl_t * crl_list,
|
||||
int crl_list_length)
|
||||
const MHD_gnutls_x509_crl_t * crl_list,
|
||||
int crl_list_length)
|
||||
{
|
||||
opaque serial[64];
|
||||
opaque cert_serial[64];
|
||||
@@ -1160,7 +1175,8 @@ MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
|
||||
/* Step 2. Read the certificate's serial number
|
||||
*/
|
||||
cert_serial_size = sizeof (cert_serial);
|
||||
ret = MHD_gnutls_x509_crt_get_serial (cert, cert_serial, &cert_serial_size);
|
||||
ret =
|
||||
MHD_gnutls_x509_crt_get_serial (cert, cert_serial, &cert_serial_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -1182,7 +1198,7 @@ MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
|
||||
{
|
||||
serial_size = sizeof (serial);
|
||||
ret = MHD_gnutls_x509_crl_get_crt_serial (crl_list[j], i, serial,
|
||||
&serial_size, NULL);
|
||||
&serial_size, NULL);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
@@ -1205,4 +1221,3 @@ MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
#endif
|
||||
|
||||
+269
-247
@@ -90,17 +90,19 @@ extern "C"
|
||||
int MHD_gnutls_x509_crt_init (MHD_gnutls_x509_crt_t * cert);
|
||||
void MHD_gnutls_x509_crt_deinit (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_import (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int MHD_gnutls_x509_crt_check_hostname (MHD_gnutls_x509_crt_t cert,
|
||||
const char *hostname);
|
||||
const char *hostname);
|
||||
|
||||
int MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t
|
||||
cert);
|
||||
int MHD_gnutls_x509_crt_get_signature (MHD_gnutls_x509_crt_t cert,
|
||||
char *sig, size_t * sizeof_sig);
|
||||
char *sig, size_t * sizeof_sig);
|
||||
int MHD_gnutls_x509_crt_get_version (MHD_gnutls_x509_crt_t cert);
|
||||
|
||||
#define GNUTLS_CRL_REASON_UNUSED 128
|
||||
@@ -116,86 +118,90 @@ extern "C"
|
||||
time_t MHD_gnutls_x509_crt_get_activation_time (MHD_gnutls_x509_crt_t cert);
|
||||
time_t MHD_gnutls_x509_crt_get_expiration_time (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
|
||||
void *result, size_t * result_size);
|
||||
void *result, size_t * result_size);
|
||||
|
||||
int MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *bits);
|
||||
unsigned int *bits);
|
||||
int MHD_gnutls_x509_crt_get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
int MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *critical);
|
||||
unsigned int *critical);
|
||||
/* The key_usage flags are defined in gnutls.h. They are the
|
||||
* GNUTLS_KEY_* definitions.
|
||||
*/
|
||||
int MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical);
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical);
|
||||
int MHD_gnutls_x509_crt_set_key_usage (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int usage);
|
||||
unsigned int usage);
|
||||
|
||||
int MHD_gnutls_x509_dn_oid_known (const char *oid);
|
||||
|
||||
/* Read extensions by sequence number. */
|
||||
int MHD_gnutls_x509_crt_set_extension_by_oid (MHD_gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
const void *buf,
|
||||
size_t sizeof_buf,
|
||||
unsigned int critical);
|
||||
const char *oid,
|
||||
const void *buf,
|
||||
size_t sizeof_buf,
|
||||
unsigned int critical);
|
||||
|
||||
/* X.509 Certificate writing.
|
||||
*/
|
||||
int MHD_gnutls_x509_crt_set_dn_by_oid (MHD_gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int MHD_gnutls_x509_crt_set_issuer_dn_by_oid (MHD_gnutls_x509_crt_t crt,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int MHD_gnutls_x509_crt_set_version (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int version);
|
||||
unsigned int version);
|
||||
int MHD_gnutls_x509_crt_set_key (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_crt_set_ca_status (MHD_gnutls_x509_crt_t crt, unsigned int ca);
|
||||
MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_crt_set_ca_status (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int ca);
|
||||
int MHD_gnutls_x509_crt_set_basic_constraints (MHD_gnutls_x509_crt_t crt,
|
||||
unsigned int ca,
|
||||
int pathLenConstraint);
|
||||
int MHD_gnutls_x509_crt_set_subject_alternative_name (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_subject_alt_name_t
|
||||
type,
|
||||
const char *data_string);
|
||||
unsigned int ca,
|
||||
int pathLenConstraint);
|
||||
int MHD_gnutls_x509_crt_set_subject_alternative_name (MHD_gnutls_x509_crt_t
|
||||
crt,
|
||||
MHD_gnutls_x509_subject_alt_name_t
|
||||
type,
|
||||
const char
|
||||
*data_string);
|
||||
int MHD_gnutls_x509_crt_sign (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key);
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key);
|
||||
int MHD_gnutls_x509_crt_sign2 (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int MHD_gnutls_x509_crt_set_activation_time (MHD_gnutls_x509_crt_t cert,
|
||||
time_t act_time);
|
||||
time_t act_time);
|
||||
int MHD_gnutls_x509_crt_set_expiration_time (MHD_gnutls_x509_crt_t cert,
|
||||
time_t exp_time);
|
||||
time_t exp_time);
|
||||
int MHD_gnutls_x509_crt_set_serial (MHD_gnutls_x509_crt_t cert,
|
||||
const void *serial, size_t serial_size);
|
||||
const void *serial, size_t serial_size);
|
||||
|
||||
int MHD_gnutls_x509_crt_set_subject_key_id (MHD_gnutls_x509_crt_t cert,
|
||||
const void *id, size_t id_size);
|
||||
const void *id, size_t id_size);
|
||||
|
||||
int MHD_gnutls_x509_crt_set_proxy_dn (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_crt_t eecrt,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
MHD_gnutls_x509_crt_t eecrt,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int MHD_gnutls_x509_crt_set_proxy (MHD_gnutls_x509_crt_t crt,
|
||||
int pathLenConstraint,
|
||||
const char *policyLanguage,
|
||||
const char *policy, size_t sizeof_policy);
|
||||
int pathLenConstraint,
|
||||
const char *policyLanguage,
|
||||
const char *policy,
|
||||
size_t sizeof_policy);
|
||||
|
||||
typedef enum MHD_gnutls_certificate_print_formats
|
||||
{
|
||||
@@ -205,31 +211,31 @@ extern "C"
|
||||
} MHD_gnutls_certificate_print_formats_t;
|
||||
|
||||
int MHD_gnutls_x509_crt_print (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_certificate_print_formats_t format,
|
||||
MHD_gnutls_datum_t * out);
|
||||
MHD_gnutls_certificate_print_formats_t
|
||||
format, MHD_gnutls_datum_t * out);
|
||||
int MHD_gnutls_x509_crl_print (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_certificate_print_formats_t format,
|
||||
MHD_gnutls_datum_t * out);
|
||||
MHD_gnutls_certificate_print_formats_t
|
||||
format, MHD_gnutls_datum_t * out);
|
||||
|
||||
/* Access to internal Certificate fields.
|
||||
*/
|
||||
int MHD_gnutls_x509_crt_get_raw_issuer_dn (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_datum_t * start);
|
||||
MHD_gnutls_datum_t * start);
|
||||
int MHD_gnutls_x509_crt_get_raw_dn (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_datum_t * start);
|
||||
MHD_gnutls_datum_t * start);
|
||||
|
||||
/* RDN handling.
|
||||
*/
|
||||
int MHD_gnutls_x509_rdn_get (const MHD_gnutls_datum_t * idn,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int MHD_gnutls_x509_rdn_get_oid (const MHD_gnutls_datum_t * idn,
|
||||
int indx, void *buf, size_t * sizeof_buf);
|
||||
int indx, void *buf, size_t * sizeof_buf);
|
||||
|
||||
int MHD_gnutls_x509_rdn_get_by_oid (const MHD_gnutls_datum_t * idn,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
|
||||
typedef void *MHD_gnutls_x509_dn_t;
|
||||
|
||||
@@ -241,30 +247,32 @@ extern "C"
|
||||
} MHD_gnutls_x509_ava_st;
|
||||
|
||||
int MHD_gnutls_x509_crt_get_subject (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_dn_t * dn);
|
||||
MHD_gnutls_x509_dn_t * dn);
|
||||
/* CRL handling functions.
|
||||
*/
|
||||
int MHD_gnutls_x509_crl_init (MHD_gnutls_x509_crl_t * crl);
|
||||
void MHD_gnutls_x509_crl_deinit (MHD_gnutls_x509_crl_t crl);
|
||||
|
||||
int MHD_gnutls_x509_crl_import (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
int MHD_gnutls_x509_crl_get_issuer_dn_by_oid (MHD_gnutls_x509_crl_t crl,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int MHD_gnutls_x509_crl_get_dn_oid (MHD_gnutls_x509_crl_t crl,
|
||||
int indx, void *oid, size_t * sizeof_oid);
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int MHD_gnutls_x509_crl_get_dn_oid (MHD_gnutls_x509_crl_t crl, int indx,
|
||||
void *oid, size_t * sizeof_oid);
|
||||
|
||||
int MHD_gnutls_x509_crl_get_signature_algorithm (MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_x509_crl_get_signature (MHD_gnutls_x509_crl_t crl,
|
||||
char *sig, size_t * sizeof_sig);
|
||||
char *sig, size_t * sizeof_sig);
|
||||
int MHD_gnutls_x509_crl_get_version (MHD_gnutls_x509_crl_t crl);
|
||||
|
||||
time_t MHD_gnutls_x509_crl_get_this_update (MHD_gnutls_x509_crl_t crl);
|
||||
@@ -272,37 +280,38 @@ extern "C"
|
||||
|
||||
int MHD_gnutls_x509_crl_get_crt_count (MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl,
|
||||
int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t);
|
||||
int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t);
|
||||
#define MHD_gnutls_x509_crl_get_certificate_count MHD_gnutls_x509_crl_get_crt_count
|
||||
#define MHD_gnutls_x509_crl_get_certificate MHD_gnutls_x509_crl_get_crt_serial
|
||||
|
||||
int MHD_gnutls_x509_crl_check_issuer (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
|
||||
/* CRL writing.
|
||||
*/
|
||||
int MHD_gnutls_x509_crl_set_version (MHD_gnutls_x509_crl_t crl,
|
||||
unsigned int version);
|
||||
unsigned int version);
|
||||
int MHD_gnutls_x509_crl_sign (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key);
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key);
|
||||
int MHD_gnutls_x509_crl_sign2 (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
MHD_gnutls_x509_crt_t issuer,
|
||||
MHD_gnutls_x509_privkey_t issuer_key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int MHD_gnutls_x509_crl_set_this_update (MHD_gnutls_x509_crl_t crl,
|
||||
time_t act_time);
|
||||
time_t act_time);
|
||||
int MHD_gnutls_x509_crl_set_next_update (MHD_gnutls_x509_crl_t crl,
|
||||
time_t exp_time);
|
||||
time_t exp_time);
|
||||
int MHD_gnutls_x509_crl_set_crt_serial (MHD_gnutls_x509_crl_t crl,
|
||||
const void *serial,
|
||||
size_t serial_size,
|
||||
time_t revocation_time);
|
||||
const void *serial,
|
||||
size_t serial_size,
|
||||
time_t revocation_time);
|
||||
int MHD_gnutls_x509_crl_set_crt (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_t crt, time_t revocation_time);
|
||||
MHD_gnutls_x509_crt_t crt,
|
||||
time_t revocation_time);
|
||||
|
||||
/* PKCS7 structures handling
|
||||
*/
|
||||
@@ -312,29 +321,32 @@ extern "C"
|
||||
int MHD_gnutls_pkcs7_init (MHD_gnutls_pkcs7_t * pkcs7);
|
||||
void MHD_gnutls_pkcs7_deinit (MHD_gnutls_pkcs7_t pkcs7);
|
||||
int MHD_gnutls_pkcs7_import (MHD_gnutls_pkcs7_t pkcs7,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_pkcs7_export (MHD_gnutls_pkcs7_t pkcs7,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int MHD_gnutls_pkcs7_get_crt_count (MHD_gnutls_pkcs7_t pkcs7);
|
||||
int MHD_gnutls_pkcs7_get_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
int indx,
|
||||
void *certificate, size_t * certificate_size);
|
||||
int indx,
|
||||
void *certificate,
|
||||
size_t * certificate_size);
|
||||
|
||||
int MHD_gnutls_pkcs7_set_crt_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
const MHD_gnutls_datum_t * crt);
|
||||
int MHD_gnutls_pkcs7_set_crt (MHD_gnutls_pkcs7_t pkcs7, MHD_gnutls_x509_crt_t crt);
|
||||
const MHD_gnutls_datum_t * crt);
|
||||
int MHD_gnutls_pkcs7_set_crt (MHD_gnutls_pkcs7_t pkcs7,
|
||||
MHD_gnutls_x509_crt_t crt);
|
||||
int MHD_gnutls_pkcs7_delete_crt (MHD_gnutls_pkcs7_t pkcs7, int indx);
|
||||
|
||||
int MHD_gnutls_pkcs7_get_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
int indx, void *crl, size_t * crl_size);
|
||||
int indx, void *crl, size_t * crl_size);
|
||||
int MHD_gnutls_pkcs7_get_crl_count (MHD_gnutls_pkcs7_t pkcs7);
|
||||
|
||||
int MHD_gnutls_pkcs7_set_crl_raw (MHD_gnutls_pkcs7_t pkcs7,
|
||||
const MHD_gnutls_datum_t * crt);
|
||||
int MHD_gnutls_pkcs7_set_crl (MHD_gnutls_pkcs7_t pkcs7, MHD_gnutls_x509_crl_t crl);
|
||||
const MHD_gnutls_datum_t * crt);
|
||||
int MHD_gnutls_pkcs7_set_crl (MHD_gnutls_pkcs7_t pkcs7,
|
||||
MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_pkcs7_delete_crl (MHD_gnutls_pkcs7_t pkcs7, int indx);
|
||||
|
||||
/* X.509 Certificate verification functions.
|
||||
@@ -375,28 +387,29 @@ extern "C"
|
||||
} MHD_gnutls_certificate_verify_flags;
|
||||
|
||||
int MHD_gnutls_x509_crt_check_issuer (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
|
||||
int MHD_gnutls_x509_crt_list_verify (const MHD_gnutls_x509_crt_t * cert_list,
|
||||
int cert_list_length,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
const MHD_gnutls_x509_crl_t * CRL_list,
|
||||
int CRL_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
int MHD_gnutls_x509_crt_list_verify (const MHD_gnutls_x509_crt_t *
|
||||
cert_list, int cert_list_length,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
const MHD_gnutls_x509_crl_t * CRL_list,
|
||||
int CRL_list_length,
|
||||
unsigned int flags,
|
||||
unsigned int *verify);
|
||||
|
||||
int MHD_gnutls_x509_crt_verify (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
int MHD_gnutls_x509_crl_verify (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify);
|
||||
|
||||
int MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crl_t *
|
||||
crl_list, int crl_list_length);
|
||||
const MHD_gnutls_x509_crl_t *
|
||||
crl_list, int crl_list_length);
|
||||
|
||||
|
||||
/* Flags for the MHD_gnutls_x509_privkey_export_pkcs8() function.
|
||||
@@ -420,62 +433,65 @@ extern "C"
|
||||
int MHD_gnutls_x509_privkey_init (MHD_gnutls_x509_privkey_t * key);
|
||||
void MHD_gnutls_x509_privkey_deinit (MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_privkey_cpy (MHD_gnutls_x509_privkey_t dst,
|
||||
MHD_gnutls_x509_privkey_t src);
|
||||
MHD_gnutls_x509_privkey_t src);
|
||||
int MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_privkey_import_pkcs8 (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
const char *pass, unsigned int flags);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
const char *pass,
|
||||
unsigned int flags);
|
||||
int MHD_gnutls_x509_privkey_import_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * m,
|
||||
const MHD_gnutls_datum_t * e,
|
||||
const MHD_gnutls_datum_t * d,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * u);
|
||||
const MHD_gnutls_datum_t * m,
|
||||
const MHD_gnutls_datum_t * e,
|
||||
const MHD_gnutls_datum_t * d,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * u);
|
||||
int MHD_gnutls_x509_privkey_export_dsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * g,
|
||||
MHD_gnutls_datum_t * y,
|
||||
MHD_gnutls_datum_t * x);
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * g,
|
||||
MHD_gnutls_datum_t * y,
|
||||
MHD_gnutls_datum_t * x);
|
||||
int MHD_gnutls_x509_privkey_import_dsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * g,
|
||||
const MHD_gnutls_datum_t * y,
|
||||
const MHD_gnutls_datum_t * x);
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * g,
|
||||
const MHD_gnutls_datum_t * y,
|
||||
const MHD_gnutls_datum_t * x);
|
||||
|
||||
int MHD_gnutls_x509_privkey_get_pk_algorithm (MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_privkey_get_pk_algorithm (MHD_gnutls_x509_privkey_t
|
||||
key);
|
||||
int MHD_gnutls_x509_privkey_get_key_id (MHD_gnutls_x509_privkey_t key,
|
||||
unsigned int flags,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
unsigned int flags,
|
||||
unsigned char *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
int MHD_gnutls_x509_privkey_export (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int MHD_gnutls_x509_privkey_export_pkcs8 (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
const char *password,
|
||||
unsigned int flags,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
const char *password,
|
||||
unsigned int flags,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
int MHD_gnutls_x509_privkey_export_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_datum_t * m,
|
||||
MHD_gnutls_datum_t * e,
|
||||
MHD_gnutls_datum_t * d,
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * u);
|
||||
MHD_gnutls_datum_t * m,
|
||||
MHD_gnutls_datum_t * e,
|
||||
MHD_gnutls_datum_t * d,
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * u);
|
||||
|
||||
int MHD_gnutls_x509_privkey_verify_data (MHD_gnutls_x509_privkey_t key,
|
||||
unsigned int flags,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
const MHD_gnutls_datum_t * signature);
|
||||
unsigned int flags,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
const MHD_gnutls_datum_t *
|
||||
signature);
|
||||
|
||||
/* Certificate request stuff.
|
||||
*/
|
||||
@@ -485,53 +501,57 @@ extern "C"
|
||||
int MHD_gnutls_x509_crq_init (MHD_gnutls_x509_crq_t * crq);
|
||||
void MHD_gnutls_x509_crq_deinit (MHD_gnutls_x509_crq_t crq);
|
||||
int MHD_gnutls_x509_crq_import (MHD_gnutls_x509_crq_t crq,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_crq_get_pk_algorithm (MHD_gnutls_x509_crq_t crq,
|
||||
unsigned int *bits);
|
||||
unsigned int *bits);
|
||||
int MHD_gnutls_x509_crq_get_dn (MHD_gnutls_x509_crq_t crq,
|
||||
char *buf, size_t * sizeof_buf);
|
||||
char *buf, size_t * sizeof_buf);
|
||||
int MHD_gnutls_x509_crq_get_dn_oid (MHD_gnutls_x509_crq_t crq,
|
||||
int indx, void *oid, size_t * sizeof_oid);
|
||||
int indx, void *oid,
|
||||
size_t * sizeof_oid);
|
||||
int MHD_gnutls_x509_crq_get_dn_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
const char *oid, int indx,
|
||||
unsigned int raw_flag, void *buf,
|
||||
size_t * sizeof_buf);
|
||||
int MHD_gnutls_x509_crq_set_dn_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
const char *oid,
|
||||
unsigned int raw_flag,
|
||||
const void *name,
|
||||
unsigned int sizeof_name);
|
||||
int MHD_gnutls_x509_crq_set_version (MHD_gnutls_x509_crq_t crq,
|
||||
unsigned int version);
|
||||
unsigned int version);
|
||||
int MHD_gnutls_x509_crq_set_key (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_privkey_t key);
|
||||
MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_crq_sign2 (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int MHD_gnutls_x509_crq_sign (MHD_gnutls_x509_crq_t crq, MHD_gnutls_x509_privkey_t key);
|
||||
MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_HashAlgorithm,
|
||||
unsigned int flags);
|
||||
int MHD_gnutls_x509_crq_sign (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_privkey_t key);
|
||||
|
||||
int MHD_gnutls_x509_crq_set_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
const char *pass);
|
||||
const char *pass);
|
||||
int MHD_gnutls_x509_crq_get_challenge_password (MHD_gnutls_x509_crq_t crq,
|
||||
char *pass,
|
||||
size_t * sizeof_pass);
|
||||
char *pass,
|
||||
size_t * sizeof_pass);
|
||||
|
||||
int MHD_gnutls_x509_crq_set_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
void *buf, size_t sizeof_buf);
|
||||
const char *oid,
|
||||
void *buf, size_t sizeof_buf);
|
||||
int MHD_gnutls_x509_crq_get_attribute_by_oid (MHD_gnutls_x509_crq_t crq,
|
||||
const char *oid,
|
||||
int indx,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
const char *oid,
|
||||
int indx,
|
||||
void *buf,
|
||||
size_t * sizeof_buf);
|
||||
|
||||
int MHD_gnutls_x509_crq_export (MHD_gnutls_x509_crq_t crq,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
int MHD_gnutls_x509_crt_set_crq (MHD_gnutls_x509_crt_t crt, MHD_gnutls_x509_crq_t crq);
|
||||
int MHD_gnutls_x509_crt_set_crq (MHD_gnutls_x509_crt_t crt,
|
||||
MHD_gnutls_x509_crq_t crq);
|
||||
|
||||
#ifdef __cplusplus
|
||||
}
|
||||
@@ -605,65 +625,66 @@ typedef struct MHD_gtls_x509_privkey_int
|
||||
} MHD_gnutls_x509_privkey_int;
|
||||
|
||||
int MHD_gnutls_x509_crt_get_issuer_dn_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int MHD_gnutls_x509_crt_get_subject_alt_name (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
unsigned int seq,
|
||||
void *ret,
|
||||
size_t * ret_size,
|
||||
unsigned int *critical);
|
||||
int MHD_gnutls_x509_crt_get_dn_by_oid (MHD_gnutls_x509_crt_t cert,
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
const char *oid,
|
||||
int indx,
|
||||
unsigned int raw_flag,
|
||||
void *buf, size_t * sizeof_buf);
|
||||
int MHD_gnutls_x509_crt_get_ca_status (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *critical);
|
||||
unsigned int *critical);
|
||||
int MHD_gnutls_x509_crt_get_pk_algorithm (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *bits);
|
||||
unsigned int *bits);
|
||||
|
||||
int MHD_gnutls_x509_crt_get_serial (MHD_gnutls_x509_crt_t cert,
|
||||
void *result, size_t * result_size);
|
||||
void *result, size_t * result_size);
|
||||
|
||||
int MHD__gnutls_x509_compare_raw_dn (const MHD_gnutls_datum_t * dn1,
|
||||
const MHD_gnutls_datum_t * dn2);
|
||||
const MHD_gnutls_datum_t * dn2);
|
||||
|
||||
int MHD_gnutls_x509_crt_check_revocation (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crl_t * crl_list,
|
||||
int crl_list_length);
|
||||
const MHD_gnutls_x509_crl_t *
|
||||
crl_list, int crl_list_length);
|
||||
|
||||
int MHD__gnutls_x509_crl_cpy (MHD_gnutls_x509_crl_t dest, MHD_gnutls_x509_crl_t src);
|
||||
int MHD__gnutls_x509_crl_cpy (MHD_gnutls_x509_crl_t dest,
|
||||
MHD_gnutls_x509_crl_t src);
|
||||
int MHD__gnutls_x509_crl_get_raw_issuer_dn (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_datum_t * dn);
|
||||
MHD_gnutls_datum_t * dn);
|
||||
int MHD_gnutls_x509_crl_get_crt_count (MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_x509_crl_get_crt_serial (MHD_gnutls_x509_crl_t crl,
|
||||
int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t);
|
||||
int indx,
|
||||
unsigned char *serial,
|
||||
size_t * serial_size, time_t * t);
|
||||
|
||||
void MHD_gnutls_x509_crl_deinit (MHD_gnutls_x509_crl_t crl);
|
||||
int MHD_gnutls_x509_crl_init (MHD_gnutls_x509_crl_t * crl);
|
||||
int MHD_gnutls_x509_crl_import (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_crl_export (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int MHD_gnutls_x509_crt_init (MHD_gnutls_x509_crt_t * cert);
|
||||
void MHD_gnutls_x509_crt_deinit (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_import (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_crt_export (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
|
||||
int MHD_gnutls_x509_crt_get_key_usage (MHD_gnutls_x509_crt_t cert,
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical);
|
||||
unsigned int *key_usage,
|
||||
unsigned int *critical);
|
||||
int MHD_gnutls_x509_crt_get_signature_algorithm (MHD_gnutls_x509_crt_t cert);
|
||||
int MHD_gnutls_x509_crt_get_version (MHD_gnutls_x509_crt_t cert);
|
||||
|
||||
@@ -671,30 +692,31 @@ int MHD_gnutls_x509_privkey_init (MHD_gnutls_x509_privkey_t * key);
|
||||
void MHD_gnutls_x509_privkey_deinit (MHD_gnutls_x509_privkey_t key);
|
||||
|
||||
int MHD_gnutls_x509_privkey_generate (MHD_gnutls_x509_privkey_t key,
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
|
||||
unsigned int bits, unsigned int flags);
|
||||
enum MHD_GNUTLS_PublicKeyAlgorithm algo,
|
||||
unsigned int bits, unsigned int flags);
|
||||
|
||||
int MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format);
|
||||
int MHD_gnutls_x509_privkey_get_pk_algorithm (MHD_gnutls_x509_privkey_t key);
|
||||
int MHD_gnutls_x509_privkey_import_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * m,
|
||||
const MHD_gnutls_datum_t * e,
|
||||
const MHD_gnutls_datum_t * d,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * u);
|
||||
const MHD_gnutls_datum_t * m,
|
||||
const MHD_gnutls_datum_t * e,
|
||||
const MHD_gnutls_datum_t * d,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * u);
|
||||
int MHD_gnutls_x509_privkey_export_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_datum_t * m,
|
||||
MHD_gnutls_datum_t * e,
|
||||
MHD_gnutls_datum_t * d,
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * u);
|
||||
MHD_gnutls_datum_t * m,
|
||||
MHD_gnutls_datum_t * e,
|
||||
MHD_gnutls_datum_t * d,
|
||||
MHD_gnutls_datum_t * p,
|
||||
MHD_gnutls_datum_t * q,
|
||||
MHD_gnutls_datum_t * u);
|
||||
int MHD_gnutls_x509_privkey_export (MHD_gnutls_x509_privkey_t key,
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data, size_t * output_data_size);
|
||||
MHD_gnutls_x509_crt_fmt_t format,
|
||||
void *output_data,
|
||||
size_t * output_data_size);
|
||||
|
||||
#define GNUTLS_CRL_REASON_UNUSED 128
|
||||
#define GNUTLS_CRL_REASON_KEY_COMPROMISE 64
|
||||
|
||||
@@ -104,7 +104,8 @@ MHD_gnutls_x509_privkey_deinit (MHD_gnutls_x509_privkey_t key)
|
||||
*
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_privkey_cpy (MHD_gnutls_x509_privkey_t dst, MHD_gnutls_x509_privkey_t src)
|
||||
MHD_gnutls_x509_privkey_cpy (MHD_gnutls_x509_privkey_t dst,
|
||||
MHD_gnutls_x509_privkey_t src)
|
||||
{
|
||||
int i, ret;
|
||||
|
||||
@@ -148,14 +149,14 @@ MHD_gnutls_x509_privkey_cpy (MHD_gnutls_x509_privkey_t dst, MHD_gnutls_x509_priv
|
||||
*/
|
||||
ASN1_TYPE
|
||||
MHD__gnutls_privkey_decode_pkcs1_rsa_key (const MHD_gnutls_datum_t * raw_key,
|
||||
MHD_gnutls_x509_privkey_t pkey)
|
||||
MHD_gnutls_x509_privkey_t pkey)
|
||||
{
|
||||
int result;
|
||||
ASN1_TYPE pkey_asn;
|
||||
|
||||
if ((result = MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.RSAPrivateKey",
|
||||
&pkey_asn)) != ASN1_SUCCESS)
|
||||
"GNUTLS.RSAPrivateKey",
|
||||
&pkey_asn)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return NULL;
|
||||
@@ -168,43 +169,44 @@ MHD__gnutls_privkey_decode_pkcs1_rsa_key (const MHD_gnutls_datum_t * raw_key,
|
||||
return NULL;
|
||||
}
|
||||
|
||||
result = MHD__asn1_der_decoding (&pkey_asn, raw_key->data, raw_key->size, NULL);
|
||||
result =
|
||||
MHD__asn1_der_decoding (&pkey_asn, raw_key->data, raw_key->size, NULL);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "modulus", &pkey->params[0]))
|
||||
< 0)
|
||||
if ((result =
|
||||
MHD__gnutls_x509_read_int (pkey_asn, "modulus", &pkey->params[0])) < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "publicExponent",
|
||||
&pkey->params[1])) < 0)
|
||||
&pkey->params[1])) < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "privateExponent",
|
||||
&pkey->params[2])) < 0)
|
||||
&pkey->params[2])) < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "prime1", &pkey->params[3]))
|
||||
< 0)
|
||||
if ((result =
|
||||
MHD__gnutls_x509_read_int (pkey_asn, "prime1", &pkey->params[3])) < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
}
|
||||
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "prime2", &pkey->params[4]))
|
||||
< 0)
|
||||
if ((result =
|
||||
MHD__gnutls_x509_read_int (pkey_asn, "prime2", &pkey->params[4])) < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
@@ -227,7 +229,7 @@ MHD__gnutls_privkey_decode_pkcs1_rsa_key (const MHD_gnutls_datum_t * raw_key,
|
||||
/* p, q */
|
||||
#else
|
||||
if ((result = MHD__gnutls_x509_read_int (pkey_asn, "coefficient",
|
||||
&pkey->params[5])) < 0)
|
||||
&pkey->params[5])) < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
goto error;
|
||||
@@ -267,8 +269,8 @@ error:MHD__asn1_delete_structure (&pkey_asn);
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
const MHD_gnutls_datum_t * data,
|
||||
MHD_gnutls_x509_crt_fmt_t format)
|
||||
{
|
||||
int result = 0, need_free = 0;
|
||||
MHD_gnutls_datum_t _data;
|
||||
@@ -291,7 +293,9 @@ MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
|
||||
|
||||
/* Try the first header */
|
||||
result
|
||||
= MHD__gnutls_fbase64_decode (PEM_KEY_RSA, data->data, data->size, &out);
|
||||
=
|
||||
MHD__gnutls_fbase64_decode (PEM_KEY_RSA, data->data, data->size,
|
||||
&out);
|
||||
key->pk_algorithm = MHD_GNUTLS_PK_RSA;
|
||||
|
||||
_data.data = out;
|
||||
@@ -360,12 +364,12 @@ MHD_gnutls_x509_privkey_import (MHD_gnutls_x509_privkey_t key,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_privkey_import_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
const MHD_gnutls_datum_t * m,
|
||||
const MHD_gnutls_datum_t * e,
|
||||
const MHD_gnutls_datum_t * d,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * u)
|
||||
const MHD_gnutls_datum_t * m,
|
||||
const MHD_gnutls_datum_t * e,
|
||||
const MHD_gnutls_datum_t * d,
|
||||
const MHD_gnutls_datum_t * p,
|
||||
const MHD_gnutls_datum_t * q,
|
||||
const MHD_gnutls_datum_t * u)
|
||||
{
|
||||
int i = 0, ret;
|
||||
size_t siz = 0;
|
||||
@@ -417,7 +421,8 @@ MHD_gnutls_x509_privkey_import_rsa_raw (MHD_gnutls_x509_privkey_t key,
|
||||
}
|
||||
|
||||
#ifdef CALC_COEFF
|
||||
key->params[5] = MHD__gnutls_mpi_snew (MHD__gnutls_mpi_get_nbits (key->params[0]));
|
||||
key->params[5] =
|
||||
MHD__gnutls_mpi_snew (MHD__gnutls_mpi_get_nbits (key->params[0]));
|
||||
|
||||
if (key->params[5] == NULL)
|
||||
{
|
||||
@@ -501,7 +506,7 @@ MHD__gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
|
||||
/* Now generate exp1 and exp2
|
||||
*/
|
||||
exp1 = MHD__gnutls_mpi_salloc_like (params[0]); /* like modulus */
|
||||
exp1 = MHD__gnutls_mpi_salloc_like (params[0]); /* like modulus */
|
||||
if (exp1 == NULL)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -600,8 +605,8 @@ MHD__gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
*/
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.RSAPrivateKey",
|
||||
c2)) != ASN1_SUCCESS)
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.RSAPrivateKey", c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -618,16 +623,18 @@ MHD__gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = MHD__asn1_write_value (*c2, "publicExponent", pube_data, size[1]))
|
||||
!= ASN1_SUCCESS)
|
||||
if ((result =
|
||||
MHD__asn1_write_value (*c2, "publicExponent", pube_data,
|
||||
size[1])) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = MHD__asn1_write_value (*c2, "privateExponent", prie_data, size[2]))
|
||||
!= ASN1_SUCCESS)
|
||||
if ((result =
|
||||
MHD__asn1_write_value (*c2, "privateExponent", prie_data,
|
||||
size[2])) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -682,14 +689,15 @@ MHD__gnutls_asn1_encode_rsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
MHD_gnutls_free (all_data);
|
||||
|
||||
if ((result = MHD__asn1_write_value (*c2, "otherPrimeInfos",
|
||||
NULL, 0)) != ASN1_SUCCESS)
|
||||
NULL, 0)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = MHD__asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
|
||||
if ((result =
|
||||
MHD__asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -760,8 +768,8 @@ MHD__gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
*/
|
||||
|
||||
if ((result =
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (), "GNUTLS.DSAPrivateKey",
|
||||
c2)) != ASN1_SUCCESS)
|
||||
MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.DSAPrivateKey", c2)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -770,28 +778,32 @@ MHD__gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
|
||||
/* Write PRIME
|
||||
*/
|
||||
if ((result = MHD__asn1_write_value (*c2, "p", p_data, size[0])) != ASN1_SUCCESS)
|
||||
if ((result =
|
||||
MHD__asn1_write_value (*c2, "p", p_data, size[0])) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = MHD__asn1_write_value (*c2, "q", q_data, size[1])) != ASN1_SUCCESS)
|
||||
if ((result =
|
||||
MHD__asn1_write_value (*c2, "q", q_data, size[1])) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = MHD__asn1_write_value (*c2, "g", g_data, size[2])) != ASN1_SUCCESS)
|
||||
if ((result =
|
||||
MHD__asn1_write_value (*c2, "g", g_data, size[2])) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
if ((result = MHD__asn1_write_value (*c2, "Y", y_data, size[3])) != ASN1_SUCCESS)
|
||||
if ((result =
|
||||
MHD__asn1_write_value (*c2, "Y", y_data, size[3])) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -808,7 +820,8 @@ MHD__gnutls_asn1_encode_dsa (ASN1_TYPE * c2, mpi_t * params)
|
||||
|
||||
MHD_gnutls_free (all_data);
|
||||
|
||||
if ((result = MHD__asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
|
||||
if ((result =
|
||||
MHD__asn1_write_value (*c2, "version", &null, 1)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
result = MHD_gtls_asn2err (result);
|
||||
@@ -822,4 +835,3 @@ cleanup:MHD__asn1_delete_structure (c2);
|
||||
|
||||
return result;
|
||||
}
|
||||
|
||||
@@ -42,20 +42,21 @@
|
||||
#include <verify.h>
|
||||
|
||||
static int MHD__gnutls_verify_certificate2 (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size,
|
||||
unsigned int flags,
|
||||
unsigned int *output);
|
||||
const MHD_gnutls_x509_crt_t *
|
||||
trusted_cas, int tcas_size,
|
||||
unsigned int flags,
|
||||
unsigned int *output);
|
||||
int MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * signed_data,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_crt_t issuer);
|
||||
|
||||
static
|
||||
int is_crl_issuer (MHD_gnutls_x509_crl_t crl, MHD_gnutls_x509_crt_t issuer_cert);
|
||||
int is_crl_issuer (MHD_gnutls_x509_crl_t crl,
|
||||
MHD_gnutls_x509_crt_t issuer_cert);
|
||||
static int MHD__gnutls_verify_crl2 (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size,
|
||||
unsigned int flags, unsigned int *output);
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size, unsigned int flags,
|
||||
unsigned int *output);
|
||||
|
||||
/* Checks if the issuer of a certificate is a
|
||||
* Certificate Authority, or if the certificate is the same
|
||||
@@ -88,7 +89,7 @@ check_if_ca (MHD_gnutls_x509_crt_t cert,
|
||||
*/
|
||||
|
||||
result = MHD__gnutls_x509_get_signed_data (issuer->cert, "tbsCertificate",
|
||||
&issuer_signed_data);
|
||||
&issuer_signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -96,7 +97,7 @@ check_if_ca (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
|
||||
&cert_signed_data);
|
||||
&cert_signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -104,7 +105,7 @@ check_if_ca (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_get_signature (issuer->cert, "signature",
|
||||
&issuer_signature);
|
||||
&issuer_signature);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -228,9 +229,9 @@ find_issuer (MHD_gnutls_x509_crt_t cert,
|
||||
*/
|
||||
static int
|
||||
MHD__gnutls_verify_certificate2 (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size,
|
||||
unsigned int flags, unsigned int *output)
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size,
|
||||
unsigned int flags, unsigned int *output)
|
||||
{
|
||||
MHD_gnutls_datum_t cert_signed_data = { NULL,
|
||||
0
|
||||
@@ -287,7 +288,7 @@ MHD__gnutls_verify_certificate2 (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_get_signed_data (cert->cert, "tbsCertificate",
|
||||
&cert_signed_data);
|
||||
&cert_signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -303,7 +304,7 @@ MHD__gnutls_verify_certificate2 (MHD_gnutls_x509_crt_t cert,
|
||||
}
|
||||
|
||||
ret = MHD__gnutls_x509_verify_signature (&cert_signed_data, &cert_signature,
|
||||
issuer);
|
||||
issuer);
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -360,7 +361,7 @@ cleanup:MHD__gnutls_free_datum (&cert_signed_data);
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_check_issuer (MHD_gnutls_x509_crt_t cert,
|
||||
MHD_gnutls_x509_crt_t issuer)
|
||||
MHD_gnutls_x509_crt_t issuer)
|
||||
{
|
||||
return is_issuer (cert, issuer);
|
||||
}
|
||||
@@ -377,12 +378,12 @@ MHD_gnutls_x509_crt_check_issuer (MHD_gnutls_x509_crt_t cert,
|
||||
* lead to a trusted CA in order to be trusted.
|
||||
*/
|
||||
static unsigned int
|
||||
MHD__gnutls_x509_verify_certificate (const MHD_gnutls_x509_crt_t * certificate_list,
|
||||
int clist_size,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size,
|
||||
const MHD_gnutls_x509_crl_t * CRLs,
|
||||
int crls_size, unsigned int flags)
|
||||
MHD__gnutls_x509_verify_certificate (const MHD_gnutls_x509_crt_t *
|
||||
certificate_list, int clist_size,
|
||||
const MHD_gnutls_x509_crt_t *
|
||||
trusted_cas, int tcas_size,
|
||||
const MHD_gnutls_x509_crl_t * CRLs,
|
||||
int crls_size, unsigned int flags)
|
||||
{
|
||||
int i = 0, ret;
|
||||
unsigned int status = 0, output;
|
||||
@@ -394,7 +395,8 @@ MHD__gnutls_x509_verify_certificate (const MHD_gnutls_x509_crt_t * certificate_l
|
||||
* in self signed etc certificates.
|
||||
*/
|
||||
ret = MHD__gnutls_verify_certificate2 (certificate_list[clist_size - 1],
|
||||
trusted_cas, tcas_size, flags, &output);
|
||||
trusted_cas, tcas_size, flags,
|
||||
&output);
|
||||
|
||||
if (ret == 0)
|
||||
{
|
||||
@@ -414,7 +416,7 @@ MHD__gnutls_x509_verify_certificate (const MHD_gnutls_x509_crt_t * certificate_l
|
||||
for (i = 0; i < clist_size; i++)
|
||||
{
|
||||
ret = MHD_gnutls_x509_crt_check_revocation (certificate_list[i],
|
||||
CRLs, crls_size);
|
||||
CRLs, crls_size);
|
||||
if (ret == 1)
|
||||
{ /* revoked */
|
||||
status |= GNUTLS_CERT_REVOKED;
|
||||
@@ -429,7 +431,7 @@ MHD__gnutls_x509_verify_certificate (const MHD_gnutls_x509_crt_t * certificate_l
|
||||
* leads to a trusted party by us, not the server's).
|
||||
*/
|
||||
if (MHD_gnutls_x509_crt_check_issuer (certificate_list[clist_size - 1],
|
||||
certificate_list[clist_size - 1]) > 0
|
||||
certificate_list[clist_size - 1]) > 0
|
||||
&& clist_size > 0)
|
||||
{
|
||||
clist_size--;
|
||||
@@ -448,8 +450,8 @@ MHD__gnutls_x509_verify_certificate (const MHD_gnutls_x509_crt_t * certificate_l
|
||||
if (!(flags & GNUTLS_VERIFY_ALLOW_ANY_X509_V1_CA_CRT))
|
||||
flags ^= GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT;
|
||||
if ((ret = MHD__gnutls_verify_certificate2 (certificate_list[i - 1],
|
||||
&certificate_list[i], 1, flags,
|
||||
NULL)) == 0)
|
||||
&certificate_list[i], 1,
|
||||
flags, NULL)) == 0)
|
||||
{
|
||||
status |= GNUTLS_CERT_INVALID;
|
||||
return status;
|
||||
@@ -474,8 +476,8 @@ decode_ber_digest_info (const MHD_gnutls_datum_t * info,
|
||||
int len;
|
||||
|
||||
if ((result = MHD__asn1_create_element (MHD__gnutls_getMHD__gnutls_asn (),
|
||||
"GNUTLS.DigestInfo",
|
||||
&dinfo)) != ASN1_SUCCESS)
|
||||
"GNUTLS.DigestInfo",
|
||||
&dinfo)) != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return MHD_gtls_asn2err (result);
|
||||
@@ -490,7 +492,8 @@ decode_ber_digest_info (const MHD_gnutls_datum_t * info,
|
||||
}
|
||||
|
||||
len = sizeof (str) - 1;
|
||||
result = MHD__asn1_read_value (dinfo, "digestAlgorithm.algorithm", str, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (dinfo, "digestAlgorithm.algorithm", str, &len);
|
||||
if (result != ASN1_SUCCESS)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -511,7 +514,8 @@ decode_ber_digest_info (const MHD_gnutls_datum_t * info,
|
||||
}
|
||||
|
||||
len = sizeof (str) - 1;
|
||||
result = MHD__asn1_read_value (dinfo, "digestAlgorithm.parameters", str, &len);
|
||||
result =
|
||||
MHD__asn1_read_value (dinfo, "digestAlgorithm.parameters", str, &len);
|
||||
/* To avoid permitting garbage in the parameters field, either the
|
||||
parameters field is not present, or it contains 0x05 0x00. */
|
||||
if (!
|
||||
@@ -640,8 +644,8 @@ verify_sig (const MHD_gnutls_datum_t * tbs,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_crt_t issuer)
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_crt_t issuer)
|
||||
{
|
||||
mpi_t issuer_params[MAX_PUBLIC_PARAMS_SIZE];
|
||||
int ret, issuer_params_size, i;
|
||||
@@ -650,16 +654,18 @@ MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
*/
|
||||
issuer_params_size = MAX_PUBLIC_PARAMS_SIZE;
|
||||
ret =
|
||||
MHD__gnutls_x509_crt_get_mpis (issuer, issuer_params, &issuer_params_size);
|
||||
MHD__gnutls_x509_crt_get_mpis (issuer, issuer_params,
|
||||
&issuer_params_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret = verify_sig (tbs, signature, MHD_gnutls_x509_crt_get_pk_algorithm (issuer,
|
||||
NULL),
|
||||
issuer_params, issuer_params_size);
|
||||
ret =
|
||||
verify_sig (tbs, signature,
|
||||
MHD_gnutls_x509_crt_get_pk_algorithm (issuer, NULL),
|
||||
issuer_params, issuer_params_size);
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -683,8 +689,9 @@ MHD__gnutls_x509_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
*/
|
||||
int
|
||||
MHD__gnutls_x509_privkey_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
const MHD_gnutls_datum_t * signature,
|
||||
MHD_gnutls_x509_privkey_t issuer)
|
||||
const MHD_gnutls_datum_t *
|
||||
signature,
|
||||
MHD_gnutls_x509_privkey_t issuer)
|
||||
{
|
||||
int ret;
|
||||
|
||||
@@ -734,12 +741,12 @@ MHD__gnutls_x509_privkey_verify_signature (const MHD_gnutls_datum_t * tbs,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_list_verify (const MHD_gnutls_x509_crt_t * cert_list,
|
||||
int cert_list_length,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
const MHD_gnutls_x509_crl_t * CRL_list,
|
||||
int CRL_list_length,
|
||||
unsigned int flags, unsigned int *verify)
|
||||
int cert_list_length,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
const MHD_gnutls_x509_crl_t * CRL_list,
|
||||
int CRL_list_length,
|
||||
unsigned int flags, unsigned int *verify)
|
||||
{
|
||||
if (cert_list == NULL || cert_list_length == 0)
|
||||
return GNUTLS_E_NO_CERTIFICATE_FOUND;
|
||||
@@ -747,9 +754,9 @@ MHD_gnutls_x509_crt_list_verify (const MHD_gnutls_x509_crt_t * cert_list,
|
||||
/* Verify certificate
|
||||
*/
|
||||
*verify = MHD__gnutls_x509_verify_certificate (cert_list, cert_list_length,
|
||||
CA_list, CA_list_length,
|
||||
CRL_list, CRL_list_length,
|
||||
flags);
|
||||
CA_list, CA_list_length,
|
||||
CRL_list, CRL_list_length,
|
||||
flags);
|
||||
|
||||
return 0;
|
||||
}
|
||||
@@ -770,15 +777,15 @@ MHD_gnutls_x509_crt_list_verify (const MHD_gnutls_x509_crt_t * cert_list,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crt_verify (MHD_gnutls_x509_crt_t cert,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify)
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length,
|
||||
unsigned int flags, unsigned int *verify)
|
||||
{
|
||||
int ret;
|
||||
/* Verify certificate
|
||||
*/
|
||||
ret = MHD__gnutls_verify_certificate2 (cert, CA_list, CA_list_length, flags,
|
||||
verify);
|
||||
verify);
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -804,7 +811,7 @@ MHD_gnutls_x509_crt_verify (MHD_gnutls_x509_crt_t cert,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crl_check_issuer (MHD_gnutls_x509_crl_t cert,
|
||||
MHD_gnutls_x509_crt_t issuer)
|
||||
MHD_gnutls_x509_crt_t issuer)
|
||||
{
|
||||
return is_crl_issuer (cert, issuer);
|
||||
}
|
||||
@@ -826,9 +833,9 @@ MHD_gnutls_x509_crl_check_issuer (MHD_gnutls_x509_crl_t cert,
|
||||
**/
|
||||
int
|
||||
MHD_gnutls_x509_crl_verify (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length, unsigned int flags,
|
||||
unsigned int *verify)
|
||||
const MHD_gnutls_x509_crt_t * CA_list,
|
||||
int CA_list_length, unsigned int flags,
|
||||
unsigned int *verify)
|
||||
{
|
||||
int ret;
|
||||
/* Verify crl
|
||||
@@ -906,8 +913,9 @@ find_crl_issuer (MHD_gnutls_x509_crl_t crl,
|
||||
*/
|
||||
static int
|
||||
MHD__gnutls_verify_crl2 (MHD_gnutls_x509_crl_t crl,
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size, unsigned int flags, unsigned int *output)
|
||||
const MHD_gnutls_x509_crt_t * trusted_cas,
|
||||
int tcas_size, unsigned int flags,
|
||||
unsigned int *output)
|
||||
{
|
||||
/* CRL is ignored for now */
|
||||
MHD_gnutls_datum_t crl_signed_data = { NULL, 0 };
|
||||
@@ -951,14 +959,16 @@ MHD__gnutls_verify_crl2 (MHD_gnutls_x509_crl_t crl,
|
||||
}
|
||||
|
||||
result =
|
||||
MHD__gnutls_x509_get_signed_data (crl->crl, "tbsCertList", &crl_signed_data);
|
||||
MHD__gnutls_x509_get_signed_data (crl->crl, "tbsCertList",
|
||||
&crl_signed_data);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
result = MHD__gnutls_x509_get_signature (crl->crl, "signature", &crl_signature);
|
||||
result =
|
||||
MHD__gnutls_x509_get_signature (crl->crl, "signature", &crl_signature);
|
||||
if (result < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -966,7 +976,8 @@ MHD__gnutls_verify_crl2 (MHD_gnutls_x509_crl_t crl,
|
||||
}
|
||||
|
||||
ret =
|
||||
MHD__gnutls_x509_verify_signature (&crl_signed_data, &crl_signature, issuer);
|
||||
MHD__gnutls_x509_verify_signature (&crl_signed_data, &crl_signature,
|
||||
issuer);
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
|
||||
Reference in new issue
Block a user