This commit is contained in:
Christian Grothoff committed 2008-11-16 04:23:30 +00:00
1 parent a61b09be33
commit e81f372ed1
15 files changed
+1 -3874

No files matched your search

-4
View File
@@ -186,10 +186,6 @@ MHD__gnutls_certificate_free_credentials (MHD_gtls_cert_credentials_t sc)
MHD__gnutls_certificate_free_keys (sc);
MHD__gnutls_certificate_free_cas (sc);
MHD__gnutls_certificate_free_ca_names (sc);
#ifdef ENABLE_PKI
MHD__gnutls_certificate_free_crls (sc);
#endif
#ifdef KEYRING_HACK
MHD__gnutls_free_datum (&sc->keyring);
#endif
-232
View File
@@ -50,7 +50,6 @@
#include "x509.h"
#include "verify.h"
#include "mpi.h"
#include "pkcs7.h"
#include "privkey.h"
@@ -536,15 +535,6 @@ MHD__gnutls_x509_raw_privkey_to_gkey (MHD_gnutls_privkey * privkey,
}
ret = MHD_gnutls_x509_privkey_import (tmpkey, raw_key, type);
#ifdef ENABLE_PKI
/* If normal key decoding doesn't work try decoding a plain PKCS #8 key */
if (ret < 0)
ret =
MHD_gnutls_x509_privkey_import_pkcs8 (tmpkey, raw_key, type, NULL,
GNUTLS_PKCS_PLAIN);
#endif
if (ret < 0)
{
MHD_gnutls_assert ();
@@ -972,225 +962,3 @@ MHD__gnutls_certificate_set_x509_trust_mem (MHD_gtls_cert_credentials_t
return ret;
}
#ifdef ENABLE_PKI
static int
parse_pem_crl_mem (MHD_gnutls_x509_crl_t ** crl_list, unsigned *ncrls,
const opaque * input_crl, int input_crl_size)
{
int size, i;
const opaque *ptr;
MHD_gnutls_datum_t tmp;
int ret, count;
/* move to the certificate
*/
ptr = memmem (input_crl, input_crl_size,
PEM_CRL_SEP, sizeof (PEM_CRL_SEP) - 1);
if (ptr == NULL)
{
MHD_gnutls_assert ();
return GNUTLS_E_BASE64_DECODING_ERROR;
}
size = input_crl_size - (ptr - input_crl);
i = *ncrls + 1;
count = 0;
do
{
*crl_list =
(MHD_gnutls_x509_crl_t *) MHD_gtls_realloc_fast (*crl_list,
i *
sizeof
(MHD_gnutls_x509_crl_t));
if (*crl_list == NULL)
{
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
ret = MHD_gnutls_x509_crl_init (&crl_list[0][i - 1]);
if (ret < 0)
{
MHD_gnutls_assert ();
return ret;
}
tmp.data = (unsigned char *) ptr;
tmp.size = size;
ret =
MHD_gnutls_x509_crl_import (crl_list[0][i - 1],
&tmp, GNUTLS_X509_FMT_PEM);
if (ret < 0)
{
MHD_gnutls_assert ();
return ret;
}
/* now we move ptr after the pem header
*/
ptr++;
/* find the next certificate (if any)
*/
size = input_crl_size - (ptr - input_crl);
if (size > 0)
ptr = memmem (ptr, size, PEM_CRL_SEP, sizeof (PEM_CRL_SEP) - 1);
else
ptr = NULL;
i++;
count++;
}
while (ptr != NULL);
*ncrls = i - 1;
return count;
}
/* Reads a DER encoded certificate list from memory and stores it to
* a MHD_gnutls_cert structure.
* returns the number of certificates parsed.
*/
static int
parse_der_crl_mem (MHD_gnutls_x509_crl_t ** crl_list, unsigned *ncrls,
const void *input_crl, int input_crl_size)
{
int i;
MHD_gnutls_datum_t tmp;
int ret;
i = *ncrls + 1;
*crl_list =
(MHD_gnutls_x509_crl_t *) MHD_gtls_realloc_fast (*crl_list,
i *
sizeof
(MHD_gnutls_x509_crl_t));
if (*crl_list == NULL)
{
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
tmp.data = (opaque *) input_crl;
tmp.size = input_crl_size;
ret = MHD_gnutls_x509_crl_init (&crl_list[0][i - 1]);
if (ret < 0)
{
MHD_gnutls_assert ();
return ret;
}
ret =
MHD_gnutls_x509_crl_import (crl_list[0][i - 1], &tmp,
GNUTLS_X509_FMT_DER);
if (ret < 0)
{
MHD_gnutls_assert ();
return ret;
}
*ncrls = i;
return 1; /* one certificate parsed */
}
/* Reads a DER or PEM CRL from memory
*/
static int
read_crl_mem (MHD_gtls_cert_credentials_t res, const void *crl,
int crl_size, MHD_gnutls_x509_crt_fmt_t type)
{
int ret;
/* allocate space for the certificate to add
*/
res->x509_crl_list = MHD_gtls_realloc_fast (res->x509_crl_list,
(1 +
res->x509_ncrls) *
sizeof (MHD_gnutls_x509_crl_t));
if (res->x509_crl_list == NULL)
{
MHD_gnutls_assert ();
return GNUTLS_E_MEMORY_ERROR;
}
if (type == GNUTLS_X509_FMT_DER)
ret = parse_der_crl_mem (&res->x509_crl_list,
&res->x509_ncrls, crl, crl_size);
else
ret = parse_pem_crl_mem (&res->x509_crl_list,
&res->x509_ncrls, crl, crl_size);
if (ret < 0)
{
MHD_gnutls_assert ();
return ret;
}
return ret;
}
/**
* MHD__gnutls_certificate_set_x509_crl_mem - Used to add CRLs in a MHD_gtls_cert_credentials_t structure
* @res: is an #MHD_gtls_cert_credentials_t structure.
* @CRL: is a list of trusted CRLs. They should have been verified before.
* @type: is DER or PEM
*
* This function adds the trusted CRLs in order to verify client or
* server certificates. In case of a client this is not required to
* be called if the certificates are not verified using
* MHD_gtls_certificate_verify_peers2(). This function may be called
* multiple times.
*
* Returns: number of CRLs processed, or a negative value on error.
**/
int
MHD__gnutls_certificate_set_x509_crl_mem (MHD_gtls_cert_credentials_t
res, const MHD_gnutls_datum_t * CRL,
MHD_gnutls_x509_crt_fmt_t type)
{
int ret;
if ((ret = read_crl_mem (res, CRL->data, CRL->size, type)) < 0)
return ret;
return ret;
}
/**
* MHD__gnutls_certificate_free_crls - Used to free all the CRLs from a MHD_gtls_cert_credentials_t structure
* @sc: is an #MHD_gtls_cert_credentials_t structure.
*
* This function will delete all the CRLs associated
* with the given credentials.
*
**/
void
MHD__gnutls_certificate_free_crls (MHD_gtls_cert_credentials_t sc)
{
unsigned j;
for (j = 0; j < sc->x509_ncrls; j++)
{
MHD_gnutls_x509_crl_deinit (sc->x509_crl_list[j]);
}
sc->x509_ncrls = 0;
MHD_gnutls_free (sc->x509_crl_list);
sc->x509_crl_list = NULL;
}
#endif