mirror of
https://git.gnunet.org/libmicrohttpd.git
synced 2026-10-01 04:03:18 +03:00
dce
This commit is contained in:
1 parent
a61b09be33
commit
e81f372ed1
15 files changed
+1
-3874
No files matched your search
@@ -186,10 +186,6 @@ MHD__gnutls_certificate_free_credentials (MHD_gtls_cert_credentials_t sc)
|
||||
MHD__gnutls_certificate_free_keys (sc);
|
||||
MHD__gnutls_certificate_free_cas (sc);
|
||||
MHD__gnutls_certificate_free_ca_names (sc);
|
||||
#ifdef ENABLE_PKI
|
||||
MHD__gnutls_certificate_free_crls (sc);
|
||||
#endif
|
||||
|
||||
#ifdef KEYRING_HACK
|
||||
MHD__gnutls_free_datum (&sc->keyring);
|
||||
#endif
|
||||
|
||||
@@ -50,7 +50,6 @@
|
||||
#include "x509.h"
|
||||
#include "verify.h"
|
||||
#include "mpi.h"
|
||||
#include "pkcs7.h"
|
||||
#include "privkey.h"
|
||||
|
||||
|
||||
@@ -536,15 +535,6 @@ MHD__gnutls_x509_raw_privkey_to_gkey (MHD_gnutls_privkey * privkey,
|
||||
}
|
||||
|
||||
ret = MHD_gnutls_x509_privkey_import (tmpkey, raw_key, type);
|
||||
|
||||
#ifdef ENABLE_PKI
|
||||
/* If normal key decoding doesn't work try decoding a plain PKCS #8 key */
|
||||
if (ret < 0)
|
||||
ret =
|
||||
MHD_gnutls_x509_privkey_import_pkcs8 (tmpkey, raw_key, type, NULL,
|
||||
GNUTLS_PKCS_PLAIN);
|
||||
#endif
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
@@ -972,225 +962,3 @@ MHD__gnutls_certificate_set_x509_trust_mem (MHD_gtls_cert_credentials_t
|
||||
return ret;
|
||||
}
|
||||
|
||||
#ifdef ENABLE_PKI
|
||||
|
||||
static int
|
||||
parse_pem_crl_mem (MHD_gnutls_x509_crl_t ** crl_list, unsigned *ncrls,
|
||||
const opaque * input_crl, int input_crl_size)
|
||||
{
|
||||
int size, i;
|
||||
const opaque *ptr;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
int ret, count;
|
||||
|
||||
/* move to the certificate
|
||||
*/
|
||||
ptr = memmem (input_crl, input_crl_size,
|
||||
PEM_CRL_SEP, sizeof (PEM_CRL_SEP) - 1);
|
||||
if (ptr == NULL)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_BASE64_DECODING_ERROR;
|
||||
}
|
||||
|
||||
size = input_crl_size - (ptr - input_crl);
|
||||
|
||||
i = *ncrls + 1;
|
||||
count = 0;
|
||||
|
||||
do
|
||||
{
|
||||
|
||||
*crl_list =
|
||||
(MHD_gnutls_x509_crl_t *) MHD_gtls_realloc_fast (*crl_list,
|
||||
i *
|
||||
sizeof
|
||||
(MHD_gnutls_x509_crl_t));
|
||||
|
||||
if (*crl_list == NULL)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
ret = MHD_gnutls_x509_crl_init (&crl_list[0][i - 1]);
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
tmp.data = (unsigned char *) ptr;
|
||||
tmp.size = size;
|
||||
|
||||
ret =
|
||||
MHD_gnutls_x509_crl_import (crl_list[0][i - 1],
|
||||
&tmp, GNUTLS_X509_FMT_PEM);
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
/* now we move ptr after the pem header
|
||||
*/
|
||||
ptr++;
|
||||
/* find the next certificate (if any)
|
||||
*/
|
||||
|
||||
size = input_crl_size - (ptr - input_crl);
|
||||
|
||||
if (size > 0)
|
||||
ptr = memmem (ptr, size, PEM_CRL_SEP, sizeof (PEM_CRL_SEP) - 1);
|
||||
else
|
||||
ptr = NULL;
|
||||
i++;
|
||||
count++;
|
||||
|
||||
}
|
||||
while (ptr != NULL);
|
||||
|
||||
*ncrls = i - 1;
|
||||
|
||||
return count;
|
||||
}
|
||||
|
||||
/* Reads a DER encoded certificate list from memory and stores it to
|
||||
* a MHD_gnutls_cert structure.
|
||||
* returns the number of certificates parsed.
|
||||
*/
|
||||
static int
|
||||
parse_der_crl_mem (MHD_gnutls_x509_crl_t ** crl_list, unsigned *ncrls,
|
||||
const void *input_crl, int input_crl_size)
|
||||
{
|
||||
int i;
|
||||
MHD_gnutls_datum_t tmp;
|
||||
int ret;
|
||||
|
||||
i = *ncrls + 1;
|
||||
|
||||
*crl_list =
|
||||
(MHD_gnutls_x509_crl_t *) MHD_gtls_realloc_fast (*crl_list,
|
||||
i *
|
||||
sizeof
|
||||
(MHD_gnutls_x509_crl_t));
|
||||
|
||||
if (*crl_list == NULL)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
tmp.data = (opaque *) input_crl;
|
||||
tmp.size = input_crl_size;
|
||||
|
||||
ret = MHD_gnutls_x509_crl_init (&crl_list[0][i - 1]);
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
ret =
|
||||
MHD_gnutls_x509_crl_import (crl_list[0][i - 1], &tmp,
|
||||
GNUTLS_X509_FMT_DER);
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
*ncrls = i;
|
||||
|
||||
return 1; /* one certificate parsed */
|
||||
}
|
||||
|
||||
|
||||
/* Reads a DER or PEM CRL from memory
|
||||
*/
|
||||
static int
|
||||
read_crl_mem (MHD_gtls_cert_credentials_t res, const void *crl,
|
||||
int crl_size, MHD_gnutls_x509_crt_fmt_t type)
|
||||
{
|
||||
int ret;
|
||||
|
||||
/* allocate space for the certificate to add
|
||||
*/
|
||||
res->x509_crl_list = MHD_gtls_realloc_fast (res->x509_crl_list,
|
||||
(1 +
|
||||
res->x509_ncrls) *
|
||||
sizeof (MHD_gnutls_x509_crl_t));
|
||||
if (res->x509_crl_list == NULL)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return GNUTLS_E_MEMORY_ERROR;
|
||||
}
|
||||
|
||||
if (type == GNUTLS_X509_FMT_DER)
|
||||
ret = parse_der_crl_mem (&res->x509_crl_list,
|
||||
&res->x509_ncrls, crl, crl_size);
|
||||
else
|
||||
ret = parse_pem_crl_mem (&res->x509_crl_list,
|
||||
&res->x509_ncrls, crl, crl_size);
|
||||
|
||||
if (ret < 0)
|
||||
{
|
||||
MHD_gnutls_assert ();
|
||||
return ret;
|
||||
}
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
/**
|
||||
* MHD__gnutls_certificate_set_x509_crl_mem - Used to add CRLs in a MHD_gtls_cert_credentials_t structure
|
||||
* @res: is an #MHD_gtls_cert_credentials_t structure.
|
||||
* @CRL: is a list of trusted CRLs. They should have been verified before.
|
||||
* @type: is DER or PEM
|
||||
*
|
||||
* This function adds the trusted CRLs in order to verify client or
|
||||
* server certificates. In case of a client this is not required to
|
||||
* be called if the certificates are not verified using
|
||||
* MHD_gtls_certificate_verify_peers2(). This function may be called
|
||||
* multiple times.
|
||||
*
|
||||
* Returns: number of CRLs processed, or a negative value on error.
|
||||
**/
|
||||
int
|
||||
MHD__gnutls_certificate_set_x509_crl_mem (MHD_gtls_cert_credentials_t
|
||||
res, const MHD_gnutls_datum_t * CRL,
|
||||
MHD_gnutls_x509_crt_fmt_t type)
|
||||
{
|
||||
int ret;
|
||||
|
||||
if ((ret = read_crl_mem (res, CRL->data, CRL->size, type)) < 0)
|
||||
return ret;
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
/**
|
||||
* MHD__gnutls_certificate_free_crls - Used to free all the CRLs from a MHD_gtls_cert_credentials_t structure
|
||||
* @sc: is an #MHD_gtls_cert_credentials_t structure.
|
||||
*
|
||||
* This function will delete all the CRLs associated
|
||||
* with the given credentials.
|
||||
*
|
||||
**/
|
||||
void
|
||||
MHD__gnutls_certificate_free_crls (MHD_gtls_cert_credentials_t sc)
|
||||
{
|
||||
unsigned j;
|
||||
|
||||
for (j = 0; j < sc->x509_ncrls; j++)
|
||||
{
|
||||
MHD_gnutls_x509_crl_deinit (sc->x509_crl_list[j]);
|
||||
}
|
||||
|
||||
sc->x509_ncrls = 0;
|
||||
|
||||
MHD_gnutls_free (sc->x509_crl_list);
|
||||
sc->x509_crl_list = NULL;
|
||||
}
|
||||
|
||||
#endif
|
||||
Reference in new issue
Block a user