The WDCInterface is is a drop-in replacement for an EthernetInterface class that allows the user to connect to the Internet with a Wistron NeWeb Corporation (WNC) M14A2A Series data module using the standard network Socket API's. This interface class is used in the AT&T Cellular IoT Starter Kit which is sold by Avnet (http://cloudconnectkits.org/product/att-cellular-iot-starter-kit).

Dependencies:   WncControllerK64F

Dependents:   WNCProximityMqtt Pubnub_ATT_IoT_SK_WNC_sync BluemixDemo BluemixQS ... more

See the WNCInterface README in the Wiki tab for detailed information on this library.

Committer:
JMF
Date:
Tue Nov 01 14:22:56 2016 +0000
Revision:
12:0071cb144c7a
Adding mbedtls files

Who changed what in which revision?

UserRevisionLine numberNew contents of line
JMF 12:0071cb144c7a 1 /*
JMF 12:0071cb144c7a 2 * X.509 Certidicate Revocation List (CRL) parsing
JMF 12:0071cb144c7a 3 *
JMF 12:0071cb144c7a 4 * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
JMF 12:0071cb144c7a 5 * SPDX-License-Identifier: Apache-2.0
JMF 12:0071cb144c7a 6 *
JMF 12:0071cb144c7a 7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
JMF 12:0071cb144c7a 8 * not use this file except in compliance with the License.
JMF 12:0071cb144c7a 9 * You may obtain a copy of the License at
JMF 12:0071cb144c7a 10 *
JMF 12:0071cb144c7a 11 * http://www.apache.org/licenses/LICENSE-2.0
JMF 12:0071cb144c7a 12 *
JMF 12:0071cb144c7a 13 * Unless required by applicable law or agreed to in writing, software
JMF 12:0071cb144c7a 14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
JMF 12:0071cb144c7a 15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
JMF 12:0071cb144c7a 16 * See the License for the specific language governing permissions and
JMF 12:0071cb144c7a 17 * limitations under the License.
JMF 12:0071cb144c7a 18 *
JMF 12:0071cb144c7a 19 * This file is part of mbed TLS (https://tls.mbed.org)
JMF 12:0071cb144c7a 20 */
JMF 12:0071cb144c7a 21 /*
JMF 12:0071cb144c7a 22 * The ITU-T X.509 standard defines a certificate format for PKI.
JMF 12:0071cb144c7a 23 *
JMF 12:0071cb144c7a 24 * http://www.ietf.org/rfc/rfc5280.txt (Certificates and CRLs)
JMF 12:0071cb144c7a 25 * http://www.ietf.org/rfc/rfc3279.txt (Alg IDs for CRLs)
JMF 12:0071cb144c7a 26 * http://www.ietf.org/rfc/rfc2986.txt (CSRs, aka PKCS#10)
JMF 12:0071cb144c7a 27 *
JMF 12:0071cb144c7a 28 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.680-0207.pdf
JMF 12:0071cb144c7a 29 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.690-0207.pdf
JMF 12:0071cb144c7a 30 */
JMF 12:0071cb144c7a 31
JMF 12:0071cb144c7a 32 #if !defined(MBEDTLS_CONFIG_FILE)
JMF 12:0071cb144c7a 33 #include "mbedtls/config.h"
JMF 12:0071cb144c7a 34 #else
JMF 12:0071cb144c7a 35 #include MBEDTLS_CONFIG_FILE
JMF 12:0071cb144c7a 36 #endif
JMF 12:0071cb144c7a 37
JMF 12:0071cb144c7a 38 #if defined(MBEDTLS_X509_CRL_PARSE_C)
JMF 12:0071cb144c7a 39
JMF 12:0071cb144c7a 40 #include "mbedtls/x509_crl.h"
JMF 12:0071cb144c7a 41 #include "mbedtls/oid.h"
JMF 12:0071cb144c7a 42
JMF 12:0071cb144c7a 43 #include <string.h>
JMF 12:0071cb144c7a 44
JMF 12:0071cb144c7a 45 #if defined(MBEDTLS_PEM_PARSE_C)
JMF 12:0071cb144c7a 46 #include "mbedtls/pem.h"
JMF 12:0071cb144c7a 47 #endif
JMF 12:0071cb144c7a 48
JMF 12:0071cb144c7a 49 #if defined(MBEDTLS_PLATFORM_C)
JMF 12:0071cb144c7a 50 #include "mbedtls/platform.h"
JMF 12:0071cb144c7a 51 #else
JMF 12:0071cb144c7a 52 #include <stdlib.h>
JMF 12:0071cb144c7a 53 #include <stdio.h>
JMF 12:0071cb144c7a 54 #define mbedtls_free free
JMF 12:0071cb144c7a 55 #define mbedtls_calloc calloc
JMF 12:0071cb144c7a 56 #define mbedtls_snprintf snprintf
JMF 12:0071cb144c7a 57 #endif
JMF 12:0071cb144c7a 58
JMF 12:0071cb144c7a 59 #if defined(_WIN32) && !defined(EFIX64) && !defined(EFI32)
JMF 12:0071cb144c7a 60 #include <windows.h>
JMF 12:0071cb144c7a 61 #else
JMF 12:0071cb144c7a 62 #include <time.h>
JMF 12:0071cb144c7a 63 #endif
JMF 12:0071cb144c7a 64
JMF 12:0071cb144c7a 65 #if defined(MBEDTLS_FS_IO) || defined(EFIX64) || defined(EFI32)
JMF 12:0071cb144c7a 66 #include <stdio.h>
JMF 12:0071cb144c7a 67 #endif
JMF 12:0071cb144c7a 68
JMF 12:0071cb144c7a 69 /* Implementation that should never be optimized out by the compiler */
JMF 12:0071cb144c7a 70 static void mbedtls_zeroize( void *v, size_t n ) {
JMF 12:0071cb144c7a 71 volatile unsigned char *p = v; while( n-- ) *p++ = 0;
JMF 12:0071cb144c7a 72 }
JMF 12:0071cb144c7a 73
JMF 12:0071cb144c7a 74 /*
JMF 12:0071cb144c7a 75 * Version ::= INTEGER { v1(0), v2(1) }
JMF 12:0071cb144c7a 76 */
JMF 12:0071cb144c7a 77 static int x509_crl_get_version( unsigned char **p,
JMF 12:0071cb144c7a 78 const unsigned char *end,
JMF 12:0071cb144c7a 79 int *ver )
JMF 12:0071cb144c7a 80 {
JMF 12:0071cb144c7a 81 int ret;
JMF 12:0071cb144c7a 82
JMF 12:0071cb144c7a 83 if( ( ret = mbedtls_asn1_get_int( p, end, ver ) ) != 0 )
JMF 12:0071cb144c7a 84 {
JMF 12:0071cb144c7a 85 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
JMF 12:0071cb144c7a 86 {
JMF 12:0071cb144c7a 87 *ver = 0;
JMF 12:0071cb144c7a 88 return( 0 );
JMF 12:0071cb144c7a 89 }
JMF 12:0071cb144c7a 90
JMF 12:0071cb144c7a 91 return( MBEDTLS_ERR_X509_INVALID_VERSION + ret );
JMF 12:0071cb144c7a 92 }
JMF 12:0071cb144c7a 93
JMF 12:0071cb144c7a 94 return( 0 );
JMF 12:0071cb144c7a 95 }
JMF 12:0071cb144c7a 96
JMF 12:0071cb144c7a 97 /*
JMF 12:0071cb144c7a 98 * X.509 CRL v2 extensions (no extensions parsed yet.)
JMF 12:0071cb144c7a 99 */
JMF 12:0071cb144c7a 100 static int x509_get_crl_ext( unsigned char **p,
JMF 12:0071cb144c7a 101 const unsigned char *end,
JMF 12:0071cb144c7a 102 mbedtls_x509_buf *ext )
JMF 12:0071cb144c7a 103 {
JMF 12:0071cb144c7a 104 int ret;
JMF 12:0071cb144c7a 105 size_t len = 0;
JMF 12:0071cb144c7a 106
JMF 12:0071cb144c7a 107 /* Get explicit tag */
JMF 12:0071cb144c7a 108 if( ( ret = mbedtls_x509_get_ext( p, end, ext, 0) ) != 0 )
JMF 12:0071cb144c7a 109 {
JMF 12:0071cb144c7a 110 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
JMF 12:0071cb144c7a 111 return( 0 );
JMF 12:0071cb144c7a 112
JMF 12:0071cb144c7a 113 return( ret );
JMF 12:0071cb144c7a 114 }
JMF 12:0071cb144c7a 115
JMF 12:0071cb144c7a 116 while( *p < end )
JMF 12:0071cb144c7a 117 {
JMF 12:0071cb144c7a 118 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
JMF 12:0071cb144c7a 119 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
JMF 12:0071cb144c7a 120 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
JMF 12:0071cb144c7a 121
JMF 12:0071cb144c7a 122 *p += len;
JMF 12:0071cb144c7a 123 }
JMF 12:0071cb144c7a 124
JMF 12:0071cb144c7a 125 if( *p != end )
JMF 12:0071cb144c7a 126 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
JMF 12:0071cb144c7a 127 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
JMF 12:0071cb144c7a 128
JMF 12:0071cb144c7a 129 return( 0 );
JMF 12:0071cb144c7a 130 }
JMF 12:0071cb144c7a 131
JMF 12:0071cb144c7a 132 /*
JMF 12:0071cb144c7a 133 * X.509 CRL v2 entry extensions (no extensions parsed yet.)
JMF 12:0071cb144c7a 134 */
JMF 12:0071cb144c7a 135 static int x509_get_crl_entry_ext( unsigned char **p,
JMF 12:0071cb144c7a 136 const unsigned char *end,
JMF 12:0071cb144c7a 137 mbedtls_x509_buf *ext )
JMF 12:0071cb144c7a 138 {
JMF 12:0071cb144c7a 139 int ret;
JMF 12:0071cb144c7a 140 size_t len = 0;
JMF 12:0071cb144c7a 141
JMF 12:0071cb144c7a 142 /* OPTIONAL */
JMF 12:0071cb144c7a 143 if( end <= *p )
JMF 12:0071cb144c7a 144 return( 0 );
JMF 12:0071cb144c7a 145
JMF 12:0071cb144c7a 146 ext->tag = **p;
JMF 12:0071cb144c7a 147 ext->p = *p;
JMF 12:0071cb144c7a 148
JMF 12:0071cb144c7a 149 /*
JMF 12:0071cb144c7a 150 * Get CRL-entry extension sequence header
JMF 12:0071cb144c7a 151 * crlEntryExtensions Extensions OPTIONAL -- if present, MUST be v2
JMF 12:0071cb144c7a 152 */
JMF 12:0071cb144c7a 153 if( ( ret = mbedtls_asn1_get_tag( p, end, &ext->len,
JMF 12:0071cb144c7a 154 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
JMF 12:0071cb144c7a 155 {
JMF 12:0071cb144c7a 156 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
JMF 12:0071cb144c7a 157 {
JMF 12:0071cb144c7a 158 ext->p = NULL;
JMF 12:0071cb144c7a 159 return( 0 );
JMF 12:0071cb144c7a 160 }
JMF 12:0071cb144c7a 161 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
JMF 12:0071cb144c7a 162 }
JMF 12:0071cb144c7a 163
JMF 12:0071cb144c7a 164 end = *p + ext->len;
JMF 12:0071cb144c7a 165
JMF 12:0071cb144c7a 166 if( end != *p + ext->len )
JMF 12:0071cb144c7a 167 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
JMF 12:0071cb144c7a 168 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
JMF 12:0071cb144c7a 169
JMF 12:0071cb144c7a 170 while( *p < end )
JMF 12:0071cb144c7a 171 {
JMF 12:0071cb144c7a 172 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
JMF 12:0071cb144c7a 173 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
JMF 12:0071cb144c7a 174 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
JMF 12:0071cb144c7a 175
JMF 12:0071cb144c7a 176 *p += len;
JMF 12:0071cb144c7a 177 }
JMF 12:0071cb144c7a 178
JMF 12:0071cb144c7a 179 if( *p != end )
JMF 12:0071cb144c7a 180 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
JMF 12:0071cb144c7a 181 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
JMF 12:0071cb144c7a 182
JMF 12:0071cb144c7a 183 return( 0 );
JMF 12:0071cb144c7a 184 }
JMF 12:0071cb144c7a 185
JMF 12:0071cb144c7a 186 /*
JMF 12:0071cb144c7a 187 * X.509 CRL Entries
JMF 12:0071cb144c7a 188 */
JMF 12:0071cb144c7a 189 static int x509_get_entries( unsigned char **p,
JMF 12:0071cb144c7a 190 const unsigned char *end,
JMF 12:0071cb144c7a 191 mbedtls_x509_crl_entry *entry )
JMF 12:0071cb144c7a 192 {
JMF 12:0071cb144c7a 193 int ret;
JMF 12:0071cb144c7a 194 size_t entry_len;
JMF 12:0071cb144c7a 195 mbedtls_x509_crl_entry *cur_entry = entry;
JMF 12:0071cb144c7a 196
JMF 12:0071cb144c7a 197 if( *p == end )
JMF 12:0071cb144c7a 198 return( 0 );
JMF 12:0071cb144c7a 199
JMF 12:0071cb144c7a 200 if( ( ret = mbedtls_asn1_get_tag( p, end, &entry_len,
JMF 12:0071cb144c7a 201 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
JMF 12:0071cb144c7a 202 {
JMF 12:0071cb144c7a 203 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
JMF 12:0071cb144c7a 204 return( 0 );
JMF 12:0071cb144c7a 205
JMF 12:0071cb144c7a 206 return( ret );
JMF 12:0071cb144c7a 207 }
JMF 12:0071cb144c7a 208
JMF 12:0071cb144c7a 209 end = *p + entry_len;
JMF 12:0071cb144c7a 210
JMF 12:0071cb144c7a 211 while( *p < end )
JMF 12:0071cb144c7a 212 {
JMF 12:0071cb144c7a 213 size_t len2;
JMF 12:0071cb144c7a 214 const unsigned char *end2;
JMF 12:0071cb144c7a 215
JMF 12:0071cb144c7a 216 if( ( ret = mbedtls_asn1_get_tag( p, end, &len2,
JMF 12:0071cb144c7a 217 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
JMF 12:0071cb144c7a 218 {
JMF 12:0071cb144c7a 219 return( ret );
JMF 12:0071cb144c7a 220 }
JMF 12:0071cb144c7a 221
JMF 12:0071cb144c7a 222 cur_entry->raw.tag = **p;
JMF 12:0071cb144c7a 223 cur_entry->raw.p = *p;
JMF 12:0071cb144c7a 224 cur_entry->raw.len = len2;
JMF 12:0071cb144c7a 225 end2 = *p + len2;
JMF 12:0071cb144c7a 226
JMF 12:0071cb144c7a 227 if( ( ret = mbedtls_x509_get_serial( p, end2, &cur_entry->serial ) ) != 0 )
JMF 12:0071cb144c7a 228 return( ret );
JMF 12:0071cb144c7a 229
JMF 12:0071cb144c7a 230 if( ( ret = mbedtls_x509_get_time( p, end2,
JMF 12:0071cb144c7a 231 &cur_entry->revocation_date ) ) != 0 )
JMF 12:0071cb144c7a 232 return( ret );
JMF 12:0071cb144c7a 233
JMF 12:0071cb144c7a 234 if( ( ret = x509_get_crl_entry_ext( p, end2,
JMF 12:0071cb144c7a 235 &cur_entry->entry_ext ) ) != 0 )
JMF 12:0071cb144c7a 236 return( ret );
JMF 12:0071cb144c7a 237
JMF 12:0071cb144c7a 238 if( *p < end )
JMF 12:0071cb144c7a 239 {
JMF 12:0071cb144c7a 240 cur_entry->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl_entry ) );
JMF 12:0071cb144c7a 241
JMF 12:0071cb144c7a 242 if( cur_entry->next == NULL )
JMF 12:0071cb144c7a 243 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
JMF 12:0071cb144c7a 244
JMF 12:0071cb144c7a 245 cur_entry = cur_entry->next;
JMF 12:0071cb144c7a 246 }
JMF 12:0071cb144c7a 247 }
JMF 12:0071cb144c7a 248
JMF 12:0071cb144c7a 249 return( 0 );
JMF 12:0071cb144c7a 250 }
JMF 12:0071cb144c7a 251
JMF 12:0071cb144c7a 252 /*
JMF 12:0071cb144c7a 253 * Parse one CRLs in DER format and append it to the chained list
JMF 12:0071cb144c7a 254 */
JMF 12:0071cb144c7a 255 int mbedtls_x509_crl_parse_der( mbedtls_x509_crl *chain,
JMF 12:0071cb144c7a 256 const unsigned char *buf, size_t buflen )
JMF 12:0071cb144c7a 257 {
JMF 12:0071cb144c7a 258 int ret;
JMF 12:0071cb144c7a 259 size_t len;
JMF 12:0071cb144c7a 260 unsigned char *p, *end;
JMF 12:0071cb144c7a 261 mbedtls_x509_buf sig_params1, sig_params2, sig_oid2;
JMF 12:0071cb144c7a 262 mbedtls_x509_crl *crl = chain;
JMF 12:0071cb144c7a 263
JMF 12:0071cb144c7a 264 /*
JMF 12:0071cb144c7a 265 * Check for valid input
JMF 12:0071cb144c7a 266 */
JMF 12:0071cb144c7a 267 if( crl == NULL || buf == NULL )
JMF 12:0071cb144c7a 268 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
JMF 12:0071cb144c7a 269
JMF 12:0071cb144c7a 270 memset( &sig_params1, 0, sizeof( mbedtls_x509_buf ) );
JMF 12:0071cb144c7a 271 memset( &sig_params2, 0, sizeof( mbedtls_x509_buf ) );
JMF 12:0071cb144c7a 272 memset( &sig_oid2, 0, sizeof( mbedtls_x509_buf ) );
JMF 12:0071cb144c7a 273
JMF 12:0071cb144c7a 274 /*
JMF 12:0071cb144c7a 275 * Add new CRL on the end of the chain if needed.
JMF 12:0071cb144c7a 276 */
JMF 12:0071cb144c7a 277 while( crl->version != 0 && crl->next != NULL )
JMF 12:0071cb144c7a 278 crl = crl->next;
JMF 12:0071cb144c7a 279
JMF 12:0071cb144c7a 280 if( crl->version != 0 && crl->next == NULL )
JMF 12:0071cb144c7a 281 {
JMF 12:0071cb144c7a 282 crl->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl ) );
JMF 12:0071cb144c7a 283
JMF 12:0071cb144c7a 284 if( crl->next == NULL )
JMF 12:0071cb144c7a 285 {
JMF 12:0071cb144c7a 286 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 287 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
JMF 12:0071cb144c7a 288 }
JMF 12:0071cb144c7a 289
JMF 12:0071cb144c7a 290 mbedtls_x509_crl_init( crl->next );
JMF 12:0071cb144c7a 291 crl = crl->next;
JMF 12:0071cb144c7a 292 }
JMF 12:0071cb144c7a 293
JMF 12:0071cb144c7a 294 /*
JMF 12:0071cb144c7a 295 * Copy raw DER-encoded CRL
JMF 12:0071cb144c7a 296 */
JMF 12:0071cb144c7a 297 if( ( p = mbedtls_calloc( 1, buflen ) ) == NULL )
JMF 12:0071cb144c7a 298 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
JMF 12:0071cb144c7a 299
JMF 12:0071cb144c7a 300 memcpy( p, buf, buflen );
JMF 12:0071cb144c7a 301
JMF 12:0071cb144c7a 302 crl->raw.p = p;
JMF 12:0071cb144c7a 303 crl->raw.len = buflen;
JMF 12:0071cb144c7a 304
JMF 12:0071cb144c7a 305 end = p + buflen;
JMF 12:0071cb144c7a 306
JMF 12:0071cb144c7a 307 /*
JMF 12:0071cb144c7a 308 * CertificateList ::= SEQUENCE {
JMF 12:0071cb144c7a 309 * tbsCertList TBSCertList,
JMF 12:0071cb144c7a 310 * signatureAlgorithm AlgorithmIdentifier,
JMF 12:0071cb144c7a 311 * signatureValue BIT STRING }
JMF 12:0071cb144c7a 312 */
JMF 12:0071cb144c7a 313 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
JMF 12:0071cb144c7a 314 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
JMF 12:0071cb144c7a 315 {
JMF 12:0071cb144c7a 316 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 317 return( MBEDTLS_ERR_X509_INVALID_FORMAT );
JMF 12:0071cb144c7a 318 }
JMF 12:0071cb144c7a 319
JMF 12:0071cb144c7a 320 if( len != (size_t) ( end - p ) )
JMF 12:0071cb144c7a 321 {
JMF 12:0071cb144c7a 322 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 323 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
JMF 12:0071cb144c7a 324 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
JMF 12:0071cb144c7a 325 }
JMF 12:0071cb144c7a 326
JMF 12:0071cb144c7a 327 /*
JMF 12:0071cb144c7a 328 * TBSCertList ::= SEQUENCE {
JMF 12:0071cb144c7a 329 */
JMF 12:0071cb144c7a 330 crl->tbs.p = p;
JMF 12:0071cb144c7a 331
JMF 12:0071cb144c7a 332 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
JMF 12:0071cb144c7a 333 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
JMF 12:0071cb144c7a 334 {
JMF 12:0071cb144c7a 335 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 336 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
JMF 12:0071cb144c7a 337 }
JMF 12:0071cb144c7a 338
JMF 12:0071cb144c7a 339 end = p + len;
JMF 12:0071cb144c7a 340 crl->tbs.len = end - crl->tbs.p;
JMF 12:0071cb144c7a 341
JMF 12:0071cb144c7a 342 /*
JMF 12:0071cb144c7a 343 * Version ::= INTEGER OPTIONAL { v1(0), v2(1) }
JMF 12:0071cb144c7a 344 * -- if present, MUST be v2
JMF 12:0071cb144c7a 345 *
JMF 12:0071cb144c7a 346 * signature AlgorithmIdentifier
JMF 12:0071cb144c7a 347 */
JMF 12:0071cb144c7a 348 if( ( ret = x509_crl_get_version( &p, end, &crl->version ) ) != 0 ||
JMF 12:0071cb144c7a 349 ( ret = mbedtls_x509_get_alg( &p, end, &crl->sig_oid, &sig_params1 ) ) != 0 )
JMF 12:0071cb144c7a 350 {
JMF 12:0071cb144c7a 351 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 352 return( ret );
JMF 12:0071cb144c7a 353 }
JMF 12:0071cb144c7a 354
JMF 12:0071cb144c7a 355 crl->version++;
JMF 12:0071cb144c7a 356
JMF 12:0071cb144c7a 357 if( crl->version > 2 )
JMF 12:0071cb144c7a 358 {
JMF 12:0071cb144c7a 359 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 360 return( MBEDTLS_ERR_X509_UNKNOWN_VERSION );
JMF 12:0071cb144c7a 361 }
JMF 12:0071cb144c7a 362
JMF 12:0071cb144c7a 363 if( ( ret = mbedtls_x509_get_sig_alg( &crl->sig_oid, &sig_params1,
JMF 12:0071cb144c7a 364 &crl->sig_md, &crl->sig_pk,
JMF 12:0071cb144c7a 365 &crl->sig_opts ) ) != 0 )
JMF 12:0071cb144c7a 366 {
JMF 12:0071cb144c7a 367 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 368 return( MBEDTLS_ERR_X509_UNKNOWN_SIG_ALG );
JMF 12:0071cb144c7a 369 }
JMF 12:0071cb144c7a 370
JMF 12:0071cb144c7a 371 /*
JMF 12:0071cb144c7a 372 * issuer Name
JMF 12:0071cb144c7a 373 */
JMF 12:0071cb144c7a 374 crl->issuer_raw.p = p;
JMF 12:0071cb144c7a 375
JMF 12:0071cb144c7a 376 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
JMF 12:0071cb144c7a 377 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
JMF 12:0071cb144c7a 378 {
JMF 12:0071cb144c7a 379 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 380 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
JMF 12:0071cb144c7a 381 }
JMF 12:0071cb144c7a 382
JMF 12:0071cb144c7a 383 if( ( ret = mbedtls_x509_get_name( &p, p + len, &crl->issuer ) ) != 0 )
JMF 12:0071cb144c7a 384 {
JMF 12:0071cb144c7a 385 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 386 return( ret );
JMF 12:0071cb144c7a 387 }
JMF 12:0071cb144c7a 388
JMF 12:0071cb144c7a 389 crl->issuer_raw.len = p - crl->issuer_raw.p;
JMF 12:0071cb144c7a 390
JMF 12:0071cb144c7a 391 /*
JMF 12:0071cb144c7a 392 * thisUpdate Time
JMF 12:0071cb144c7a 393 * nextUpdate Time OPTIONAL
JMF 12:0071cb144c7a 394 */
JMF 12:0071cb144c7a 395 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->this_update ) ) != 0 )
JMF 12:0071cb144c7a 396 {
JMF 12:0071cb144c7a 397 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 398 return( ret );
JMF 12:0071cb144c7a 399 }
JMF 12:0071cb144c7a 400
JMF 12:0071cb144c7a 401 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->next_update ) ) != 0 )
JMF 12:0071cb144c7a 402 {
JMF 12:0071cb144c7a 403 if( ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
JMF 12:0071cb144c7a 404 MBEDTLS_ERR_ASN1_UNEXPECTED_TAG ) &&
JMF 12:0071cb144c7a 405 ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
JMF 12:0071cb144c7a 406 MBEDTLS_ERR_ASN1_OUT_OF_DATA ) )
JMF 12:0071cb144c7a 407 {
JMF 12:0071cb144c7a 408 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 409 return( ret );
JMF 12:0071cb144c7a 410 }
JMF 12:0071cb144c7a 411 }
JMF 12:0071cb144c7a 412
JMF 12:0071cb144c7a 413 /*
JMF 12:0071cb144c7a 414 * revokedCertificates SEQUENCE OF SEQUENCE {
JMF 12:0071cb144c7a 415 * userCertificate CertificateSerialNumber,
JMF 12:0071cb144c7a 416 * revocationDate Time,
JMF 12:0071cb144c7a 417 * crlEntryExtensions Extensions OPTIONAL
JMF 12:0071cb144c7a 418 * -- if present, MUST be v2
JMF 12:0071cb144c7a 419 * } OPTIONAL
JMF 12:0071cb144c7a 420 */
JMF 12:0071cb144c7a 421 if( ( ret = x509_get_entries( &p, end, &crl->entry ) ) != 0 )
JMF 12:0071cb144c7a 422 {
JMF 12:0071cb144c7a 423 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 424 return( ret );
JMF 12:0071cb144c7a 425 }
JMF 12:0071cb144c7a 426
JMF 12:0071cb144c7a 427 /*
JMF 12:0071cb144c7a 428 * crlExtensions EXPLICIT Extensions OPTIONAL
JMF 12:0071cb144c7a 429 * -- if present, MUST be v2
JMF 12:0071cb144c7a 430 */
JMF 12:0071cb144c7a 431 if( crl->version == 2 )
JMF 12:0071cb144c7a 432 {
JMF 12:0071cb144c7a 433 ret = x509_get_crl_ext( &p, end, &crl->crl_ext );
JMF 12:0071cb144c7a 434
JMF 12:0071cb144c7a 435 if( ret != 0 )
JMF 12:0071cb144c7a 436 {
JMF 12:0071cb144c7a 437 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 438 return( ret );
JMF 12:0071cb144c7a 439 }
JMF 12:0071cb144c7a 440 }
JMF 12:0071cb144c7a 441
JMF 12:0071cb144c7a 442 if( p != end )
JMF 12:0071cb144c7a 443 {
JMF 12:0071cb144c7a 444 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 445 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
JMF 12:0071cb144c7a 446 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
JMF 12:0071cb144c7a 447 }
JMF 12:0071cb144c7a 448
JMF 12:0071cb144c7a 449 end = crl->raw.p + crl->raw.len;
JMF 12:0071cb144c7a 450
JMF 12:0071cb144c7a 451 /*
JMF 12:0071cb144c7a 452 * signatureAlgorithm AlgorithmIdentifier,
JMF 12:0071cb144c7a 453 * signatureValue BIT STRING
JMF 12:0071cb144c7a 454 */
JMF 12:0071cb144c7a 455 if( ( ret = mbedtls_x509_get_alg( &p, end, &sig_oid2, &sig_params2 ) ) != 0 )
JMF 12:0071cb144c7a 456 {
JMF 12:0071cb144c7a 457 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 458 return( ret );
JMF 12:0071cb144c7a 459 }
JMF 12:0071cb144c7a 460
JMF 12:0071cb144c7a 461 if( crl->sig_oid.len != sig_oid2.len ||
JMF 12:0071cb144c7a 462 memcmp( crl->sig_oid.p, sig_oid2.p, crl->sig_oid.len ) != 0 ||
JMF 12:0071cb144c7a 463 sig_params1.len != sig_params2.len ||
JMF 12:0071cb144c7a 464 ( sig_params1.len != 0 &&
JMF 12:0071cb144c7a 465 memcmp( sig_params1.p, sig_params2.p, sig_params1.len ) != 0 ) )
JMF 12:0071cb144c7a 466 {
JMF 12:0071cb144c7a 467 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 468 return( MBEDTLS_ERR_X509_SIG_MISMATCH );
JMF 12:0071cb144c7a 469 }
JMF 12:0071cb144c7a 470
JMF 12:0071cb144c7a 471 if( ( ret = mbedtls_x509_get_sig( &p, end, &crl->sig ) ) != 0 )
JMF 12:0071cb144c7a 472 {
JMF 12:0071cb144c7a 473 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 474 return( ret );
JMF 12:0071cb144c7a 475 }
JMF 12:0071cb144c7a 476
JMF 12:0071cb144c7a 477 if( p != end )
JMF 12:0071cb144c7a 478 {
JMF 12:0071cb144c7a 479 mbedtls_x509_crl_free( crl );
JMF 12:0071cb144c7a 480 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
JMF 12:0071cb144c7a 481 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
JMF 12:0071cb144c7a 482 }
JMF 12:0071cb144c7a 483
JMF 12:0071cb144c7a 484 return( 0 );
JMF 12:0071cb144c7a 485 }
JMF 12:0071cb144c7a 486
JMF 12:0071cb144c7a 487 /*
JMF 12:0071cb144c7a 488 * Parse one or more CRLs and add them to the chained list
JMF 12:0071cb144c7a 489 */
JMF 12:0071cb144c7a 490 int mbedtls_x509_crl_parse( mbedtls_x509_crl *chain, const unsigned char *buf, size_t buflen )
JMF 12:0071cb144c7a 491 {
JMF 12:0071cb144c7a 492 #if defined(MBEDTLS_PEM_PARSE_C)
JMF 12:0071cb144c7a 493 int ret;
JMF 12:0071cb144c7a 494 size_t use_len;
JMF 12:0071cb144c7a 495 mbedtls_pem_context pem;
JMF 12:0071cb144c7a 496 int is_pem = 0;
JMF 12:0071cb144c7a 497
JMF 12:0071cb144c7a 498 if( chain == NULL || buf == NULL )
JMF 12:0071cb144c7a 499 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
JMF 12:0071cb144c7a 500
JMF 12:0071cb144c7a 501 do
JMF 12:0071cb144c7a 502 {
JMF 12:0071cb144c7a 503 mbedtls_pem_init( &pem );
JMF 12:0071cb144c7a 504
JMF 12:0071cb144c7a 505 // Avoid calling mbedtls_pem_read_buffer() on non-null-terminated
JMF 12:0071cb144c7a 506 // string
JMF 12:0071cb144c7a 507 if( buflen == 0 || buf[buflen - 1] != '\0' )
JMF 12:0071cb144c7a 508 ret = MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT;
JMF 12:0071cb144c7a 509 else
JMF 12:0071cb144c7a 510 ret = mbedtls_pem_read_buffer( &pem,
JMF 12:0071cb144c7a 511 "-----BEGIN X509 CRL-----",
JMF 12:0071cb144c7a 512 "-----END X509 CRL-----",
JMF 12:0071cb144c7a 513 buf, NULL, 0, &use_len );
JMF 12:0071cb144c7a 514
JMF 12:0071cb144c7a 515 if( ret == 0 )
JMF 12:0071cb144c7a 516 {
JMF 12:0071cb144c7a 517 /*
JMF 12:0071cb144c7a 518 * Was PEM encoded
JMF 12:0071cb144c7a 519 */
JMF 12:0071cb144c7a 520 is_pem = 1;
JMF 12:0071cb144c7a 521
JMF 12:0071cb144c7a 522 buflen -= use_len;
JMF 12:0071cb144c7a 523 buf += use_len;
JMF 12:0071cb144c7a 524
JMF 12:0071cb144c7a 525 if( ( ret = mbedtls_x509_crl_parse_der( chain,
JMF 12:0071cb144c7a 526 pem.buf, pem.buflen ) ) != 0 )
JMF 12:0071cb144c7a 527 {
JMF 12:0071cb144c7a 528 return( ret );
JMF 12:0071cb144c7a 529 }
JMF 12:0071cb144c7a 530
JMF 12:0071cb144c7a 531 mbedtls_pem_free( &pem );
JMF 12:0071cb144c7a 532 }
JMF 12:0071cb144c7a 533 else if( ret != MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT )
JMF 12:0071cb144c7a 534 {
JMF 12:0071cb144c7a 535 mbedtls_pem_free( &pem );
JMF 12:0071cb144c7a 536 return( ret );
JMF 12:0071cb144c7a 537 }
JMF 12:0071cb144c7a 538 }
JMF 12:0071cb144c7a 539 /* In the PEM case, buflen is 1 at the end, for the terminated NULL byte.
JMF 12:0071cb144c7a 540 * And a valid CRL cannot be less than 1 byte anyway. */
JMF 12:0071cb144c7a 541 while( is_pem && buflen > 1 );
JMF 12:0071cb144c7a 542
JMF 12:0071cb144c7a 543 if( is_pem )
JMF 12:0071cb144c7a 544 return( 0 );
JMF 12:0071cb144c7a 545 else
JMF 12:0071cb144c7a 546 #endif /* MBEDTLS_PEM_PARSE_C */
JMF 12:0071cb144c7a 547 return( mbedtls_x509_crl_parse_der( chain, buf, buflen ) );
JMF 12:0071cb144c7a 548 }
JMF 12:0071cb144c7a 549
JMF 12:0071cb144c7a 550 #if defined(MBEDTLS_FS_IO)
JMF 12:0071cb144c7a 551 /*
JMF 12:0071cb144c7a 552 * Load one or more CRLs and add them to the chained list
JMF 12:0071cb144c7a 553 */
JMF 12:0071cb144c7a 554 int mbedtls_x509_crl_parse_file( mbedtls_x509_crl *chain, const char *path )
JMF 12:0071cb144c7a 555 {
JMF 12:0071cb144c7a 556 int ret;
JMF 12:0071cb144c7a 557 size_t n;
JMF 12:0071cb144c7a 558 unsigned char *buf;
JMF 12:0071cb144c7a 559
JMF 12:0071cb144c7a 560 if( ( ret = mbedtls_pk_load_file( path, &buf, &n ) ) != 0 )
JMF 12:0071cb144c7a 561 return( ret );
JMF 12:0071cb144c7a 562
JMF 12:0071cb144c7a 563 ret = mbedtls_x509_crl_parse( chain, buf, n );
JMF 12:0071cb144c7a 564
JMF 12:0071cb144c7a 565 mbedtls_zeroize( buf, n );
JMF 12:0071cb144c7a 566 mbedtls_free( buf );
JMF 12:0071cb144c7a 567
JMF 12:0071cb144c7a 568 return( ret );
JMF 12:0071cb144c7a 569 }
JMF 12:0071cb144c7a 570 #endif /* MBEDTLS_FS_IO */
JMF 12:0071cb144c7a 571
JMF 12:0071cb144c7a 572 /*
JMF 12:0071cb144c7a 573 * Return an informational string about the certificate.
JMF 12:0071cb144c7a 574 */
JMF 12:0071cb144c7a 575 #define BEFORE_COLON 14
JMF 12:0071cb144c7a 576 #define BC "14"
JMF 12:0071cb144c7a 577 /*
JMF 12:0071cb144c7a 578 * Return an informational string about the CRL.
JMF 12:0071cb144c7a 579 */
JMF 12:0071cb144c7a 580 int mbedtls_x509_crl_info( char *buf, size_t size, const char *prefix,
JMF 12:0071cb144c7a 581 const mbedtls_x509_crl *crl )
JMF 12:0071cb144c7a 582 {
JMF 12:0071cb144c7a 583 int ret;
JMF 12:0071cb144c7a 584 size_t n;
JMF 12:0071cb144c7a 585 char *p;
JMF 12:0071cb144c7a 586 const mbedtls_x509_crl_entry *entry;
JMF 12:0071cb144c7a 587
JMF 12:0071cb144c7a 588 p = buf;
JMF 12:0071cb144c7a 589 n = size;
JMF 12:0071cb144c7a 590
JMF 12:0071cb144c7a 591 ret = mbedtls_snprintf( p, n, "%sCRL version : %d",
JMF 12:0071cb144c7a 592 prefix, crl->version );
JMF 12:0071cb144c7a 593 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 594
JMF 12:0071cb144c7a 595 ret = mbedtls_snprintf( p, n, "\n%sissuer name : ", prefix );
JMF 12:0071cb144c7a 596 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 597 ret = mbedtls_x509_dn_gets( p, n, &crl->issuer );
JMF 12:0071cb144c7a 598 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 599
JMF 12:0071cb144c7a 600 ret = mbedtls_snprintf( p, n, "\n%sthis update : " \
JMF 12:0071cb144c7a 601 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
JMF 12:0071cb144c7a 602 crl->this_update.year, crl->this_update.mon,
JMF 12:0071cb144c7a 603 crl->this_update.day, crl->this_update.hour,
JMF 12:0071cb144c7a 604 crl->this_update.min, crl->this_update.sec );
JMF 12:0071cb144c7a 605 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 606
JMF 12:0071cb144c7a 607 ret = mbedtls_snprintf( p, n, "\n%snext update : " \
JMF 12:0071cb144c7a 608 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
JMF 12:0071cb144c7a 609 crl->next_update.year, crl->next_update.mon,
JMF 12:0071cb144c7a 610 crl->next_update.day, crl->next_update.hour,
JMF 12:0071cb144c7a 611 crl->next_update.min, crl->next_update.sec );
JMF 12:0071cb144c7a 612 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 613
JMF 12:0071cb144c7a 614 entry = &crl->entry;
JMF 12:0071cb144c7a 615
JMF 12:0071cb144c7a 616 ret = mbedtls_snprintf( p, n, "\n%sRevoked certificates:",
JMF 12:0071cb144c7a 617 prefix );
JMF 12:0071cb144c7a 618 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 619
JMF 12:0071cb144c7a 620 while( entry != NULL && entry->raw.len != 0 )
JMF 12:0071cb144c7a 621 {
JMF 12:0071cb144c7a 622 ret = mbedtls_snprintf( p, n, "\n%sserial number: ",
JMF 12:0071cb144c7a 623 prefix );
JMF 12:0071cb144c7a 624 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 625
JMF 12:0071cb144c7a 626 ret = mbedtls_x509_serial_gets( p, n, &entry->serial );
JMF 12:0071cb144c7a 627 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 628
JMF 12:0071cb144c7a 629 ret = mbedtls_snprintf( p, n, " revocation date: " \
JMF 12:0071cb144c7a 630 "%04d-%02d-%02d %02d:%02d:%02d",
JMF 12:0071cb144c7a 631 entry->revocation_date.year, entry->revocation_date.mon,
JMF 12:0071cb144c7a 632 entry->revocation_date.day, entry->revocation_date.hour,
JMF 12:0071cb144c7a 633 entry->revocation_date.min, entry->revocation_date.sec );
JMF 12:0071cb144c7a 634 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 635
JMF 12:0071cb144c7a 636 entry = entry->next;
JMF 12:0071cb144c7a 637 }
JMF 12:0071cb144c7a 638
JMF 12:0071cb144c7a 639 ret = mbedtls_snprintf( p, n, "\n%ssigned using : ", prefix );
JMF 12:0071cb144c7a 640 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 641
JMF 12:0071cb144c7a 642 ret = mbedtls_x509_sig_alg_gets( p, n, &crl->sig_oid, crl->sig_pk, crl->sig_md,
JMF 12:0071cb144c7a 643 crl->sig_opts );
JMF 12:0071cb144c7a 644 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 645
JMF 12:0071cb144c7a 646 ret = mbedtls_snprintf( p, n, "\n" );
JMF 12:0071cb144c7a 647 MBEDTLS_X509_SAFE_SNPRINTF;
JMF 12:0071cb144c7a 648
JMF 12:0071cb144c7a 649 return( (int) ( size - n ) );
JMF 12:0071cb144c7a 650 }
JMF 12:0071cb144c7a 651
JMF 12:0071cb144c7a 652 /*
JMF 12:0071cb144c7a 653 * Initialize a CRL chain
JMF 12:0071cb144c7a 654 */
JMF 12:0071cb144c7a 655 void mbedtls_x509_crl_init( mbedtls_x509_crl *crl )
JMF 12:0071cb144c7a 656 {
JMF 12:0071cb144c7a 657 memset( crl, 0, sizeof(mbedtls_x509_crl) );
JMF 12:0071cb144c7a 658 }
JMF 12:0071cb144c7a 659
JMF 12:0071cb144c7a 660 /*
JMF 12:0071cb144c7a 661 * Unallocate all CRL data
JMF 12:0071cb144c7a 662 */
JMF 12:0071cb144c7a 663 void mbedtls_x509_crl_free( mbedtls_x509_crl *crl )
JMF 12:0071cb144c7a 664 {
JMF 12:0071cb144c7a 665 mbedtls_x509_crl *crl_cur = crl;
JMF 12:0071cb144c7a 666 mbedtls_x509_crl *crl_prv;
JMF 12:0071cb144c7a 667 mbedtls_x509_name *name_cur;
JMF 12:0071cb144c7a 668 mbedtls_x509_name *name_prv;
JMF 12:0071cb144c7a 669 mbedtls_x509_crl_entry *entry_cur;
JMF 12:0071cb144c7a 670 mbedtls_x509_crl_entry *entry_prv;
JMF 12:0071cb144c7a 671
JMF 12:0071cb144c7a 672 if( crl == NULL )
JMF 12:0071cb144c7a 673 return;
JMF 12:0071cb144c7a 674
JMF 12:0071cb144c7a 675 do
JMF 12:0071cb144c7a 676 {
JMF 12:0071cb144c7a 677 #if defined(MBEDTLS_X509_RSASSA_PSS_SUPPORT)
JMF 12:0071cb144c7a 678 mbedtls_free( crl_cur->sig_opts );
JMF 12:0071cb144c7a 679 #endif
JMF 12:0071cb144c7a 680
JMF 12:0071cb144c7a 681 name_cur = crl_cur->issuer.next;
JMF 12:0071cb144c7a 682 while( name_cur != NULL )
JMF 12:0071cb144c7a 683 {
JMF 12:0071cb144c7a 684 name_prv = name_cur;
JMF 12:0071cb144c7a 685 name_cur = name_cur->next;
JMF 12:0071cb144c7a 686 mbedtls_zeroize( name_prv, sizeof( mbedtls_x509_name ) );
JMF 12:0071cb144c7a 687 mbedtls_free( name_prv );
JMF 12:0071cb144c7a 688 }
JMF 12:0071cb144c7a 689
JMF 12:0071cb144c7a 690 entry_cur = crl_cur->entry.next;
JMF 12:0071cb144c7a 691 while( entry_cur != NULL )
JMF 12:0071cb144c7a 692 {
JMF 12:0071cb144c7a 693 entry_prv = entry_cur;
JMF 12:0071cb144c7a 694 entry_cur = entry_cur->next;
JMF 12:0071cb144c7a 695 mbedtls_zeroize( entry_prv, sizeof( mbedtls_x509_crl_entry ) );
JMF 12:0071cb144c7a 696 mbedtls_free( entry_prv );
JMF 12:0071cb144c7a 697 }
JMF 12:0071cb144c7a 698
JMF 12:0071cb144c7a 699 if( crl_cur->raw.p != NULL )
JMF 12:0071cb144c7a 700 {
JMF 12:0071cb144c7a 701 mbedtls_zeroize( crl_cur->raw.p, crl_cur->raw.len );
JMF 12:0071cb144c7a 702 mbedtls_free( crl_cur->raw.p );
JMF 12:0071cb144c7a 703 }
JMF 12:0071cb144c7a 704
JMF 12:0071cb144c7a 705 crl_cur = crl_cur->next;
JMF 12:0071cb144c7a 706 }
JMF 12:0071cb144c7a 707 while( crl_cur != NULL );
JMF 12:0071cb144c7a 708
JMF 12:0071cb144c7a 709 crl_cur = crl;
JMF 12:0071cb144c7a 710 do
JMF 12:0071cb144c7a 711 {
JMF 12:0071cb144c7a 712 crl_prv = crl_cur;
JMF 12:0071cb144c7a 713 crl_cur = crl_cur->next;
JMF 12:0071cb144c7a 714
JMF 12:0071cb144c7a 715 mbedtls_zeroize( crl_prv, sizeof( mbedtls_x509_crl ) );
JMF 12:0071cb144c7a 716 if( crl_prv != crl )
JMF 12:0071cb144c7a 717 mbedtls_free( crl_prv );
JMF 12:0071cb144c7a 718 }
JMF 12:0071cb144c7a 719 while( crl_cur != NULL );
JMF 12:0071cb144c7a 720 }
JMF 12:0071cb144c7a 721
JMF 12:0071cb144c7a 722 #endif /* MBEDTLS_X509_CRL_PARSE_C */