Dependents:   cobaLCDJoyMotor_Thread odometry_omni_3roda_v3 odometry_omni_3roda_v1 odometry_omni_3roda_v2 ... more

Committer:
be_bryan
Date:
Mon Dec 11 17:54:04 2017 +0000
Revision:
0:b74591d5ab33
motor ++

Who changed what in which revision?

UserRevisionLine numberNew contents of line
be_bryan 0:b74591d5ab33 1 /*
be_bryan 0:b74591d5ab33 2 * X.509 Certidicate Revocation List (CRL) parsing
be_bryan 0:b74591d5ab33 3 *
be_bryan 0:b74591d5ab33 4 * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
be_bryan 0:b74591d5ab33 5 * SPDX-License-Identifier: Apache-2.0
be_bryan 0:b74591d5ab33 6 *
be_bryan 0:b74591d5ab33 7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
be_bryan 0:b74591d5ab33 8 * not use this file except in compliance with the License.
be_bryan 0:b74591d5ab33 9 * You may obtain a copy of the License at
be_bryan 0:b74591d5ab33 10 *
be_bryan 0:b74591d5ab33 11 * http://www.apache.org/licenses/LICENSE-2.0
be_bryan 0:b74591d5ab33 12 *
be_bryan 0:b74591d5ab33 13 * Unless required by applicable law or agreed to in writing, software
be_bryan 0:b74591d5ab33 14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
be_bryan 0:b74591d5ab33 15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
be_bryan 0:b74591d5ab33 16 * See the License for the specific language governing permissions and
be_bryan 0:b74591d5ab33 17 * limitations under the License.
be_bryan 0:b74591d5ab33 18 *
be_bryan 0:b74591d5ab33 19 * This file is part of mbed TLS (https://tls.mbed.org)
be_bryan 0:b74591d5ab33 20 */
be_bryan 0:b74591d5ab33 21 /*
be_bryan 0:b74591d5ab33 22 * The ITU-T X.509 standard defines a certificate format for PKI.
be_bryan 0:b74591d5ab33 23 *
be_bryan 0:b74591d5ab33 24 * http://www.ietf.org/rfc/rfc5280.txt (Certificates and CRLs)
be_bryan 0:b74591d5ab33 25 * http://www.ietf.org/rfc/rfc3279.txt (Alg IDs for CRLs)
be_bryan 0:b74591d5ab33 26 * http://www.ietf.org/rfc/rfc2986.txt (CSRs, aka PKCS#10)
be_bryan 0:b74591d5ab33 27 *
be_bryan 0:b74591d5ab33 28 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.680-0207.pdf
be_bryan 0:b74591d5ab33 29 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.690-0207.pdf
be_bryan 0:b74591d5ab33 30 */
be_bryan 0:b74591d5ab33 31
be_bryan 0:b74591d5ab33 32 #if !defined(MBEDTLS_CONFIG_FILE)
be_bryan 0:b74591d5ab33 33 #include "mbedtls/config.h"
be_bryan 0:b74591d5ab33 34 #else
be_bryan 0:b74591d5ab33 35 #include MBEDTLS_CONFIG_FILE
be_bryan 0:b74591d5ab33 36 #endif
be_bryan 0:b74591d5ab33 37
be_bryan 0:b74591d5ab33 38 #if defined(MBEDTLS_X509_CRL_PARSE_C)
be_bryan 0:b74591d5ab33 39
be_bryan 0:b74591d5ab33 40 #include "mbedtls/x509_crl.h"
be_bryan 0:b74591d5ab33 41 #include "mbedtls/oid.h"
be_bryan 0:b74591d5ab33 42
be_bryan 0:b74591d5ab33 43 #include <string.h>
be_bryan 0:b74591d5ab33 44
be_bryan 0:b74591d5ab33 45 #if defined(MBEDTLS_PEM_PARSE_C)
be_bryan 0:b74591d5ab33 46 #include "mbedtls/pem.h"
be_bryan 0:b74591d5ab33 47 #endif
be_bryan 0:b74591d5ab33 48
be_bryan 0:b74591d5ab33 49 #if defined(MBEDTLS_PLATFORM_C)
be_bryan 0:b74591d5ab33 50 #include "mbedtls/platform.h"
be_bryan 0:b74591d5ab33 51 #else
be_bryan 0:b74591d5ab33 52 #include <stdlib.h>
be_bryan 0:b74591d5ab33 53 #include <stdio.h>
be_bryan 0:b74591d5ab33 54 #define mbedtls_free free
be_bryan 0:b74591d5ab33 55 #define mbedtls_calloc calloc
be_bryan 0:b74591d5ab33 56 #define mbedtls_snprintf snprintf
be_bryan 0:b74591d5ab33 57 #endif
be_bryan 0:b74591d5ab33 58
be_bryan 0:b74591d5ab33 59 #if defined(_WIN32) && !defined(EFIX64) && !defined(EFI32)
be_bryan 0:b74591d5ab33 60 #include <windows.h>
be_bryan 0:b74591d5ab33 61 #else
be_bryan 0:b74591d5ab33 62 #include <time.h>
be_bryan 0:b74591d5ab33 63 #endif
be_bryan 0:b74591d5ab33 64
be_bryan 0:b74591d5ab33 65 #if defined(MBEDTLS_FS_IO) || defined(EFIX64) || defined(EFI32)
be_bryan 0:b74591d5ab33 66 #include <stdio.h>
be_bryan 0:b74591d5ab33 67 #endif
be_bryan 0:b74591d5ab33 68
be_bryan 0:b74591d5ab33 69 /* Implementation that should never be optimized out by the compiler */
be_bryan 0:b74591d5ab33 70 static void mbedtls_zeroize( void *v, size_t n ) {
be_bryan 0:b74591d5ab33 71 volatile unsigned char *p = v; while( n-- ) *p++ = 0;
be_bryan 0:b74591d5ab33 72 }
be_bryan 0:b74591d5ab33 73
be_bryan 0:b74591d5ab33 74 /*
be_bryan 0:b74591d5ab33 75 * Version ::= INTEGER { v1(0), v2(1) }
be_bryan 0:b74591d5ab33 76 */
be_bryan 0:b74591d5ab33 77 static int x509_crl_get_version( unsigned char **p,
be_bryan 0:b74591d5ab33 78 const unsigned char *end,
be_bryan 0:b74591d5ab33 79 int *ver )
be_bryan 0:b74591d5ab33 80 {
be_bryan 0:b74591d5ab33 81 int ret;
be_bryan 0:b74591d5ab33 82
be_bryan 0:b74591d5ab33 83 if( ( ret = mbedtls_asn1_get_int( p, end, ver ) ) != 0 )
be_bryan 0:b74591d5ab33 84 {
be_bryan 0:b74591d5ab33 85 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
be_bryan 0:b74591d5ab33 86 {
be_bryan 0:b74591d5ab33 87 *ver = 0;
be_bryan 0:b74591d5ab33 88 return( 0 );
be_bryan 0:b74591d5ab33 89 }
be_bryan 0:b74591d5ab33 90
be_bryan 0:b74591d5ab33 91 return( MBEDTLS_ERR_X509_INVALID_VERSION + ret );
be_bryan 0:b74591d5ab33 92 }
be_bryan 0:b74591d5ab33 93
be_bryan 0:b74591d5ab33 94 return( 0 );
be_bryan 0:b74591d5ab33 95 }
be_bryan 0:b74591d5ab33 96
be_bryan 0:b74591d5ab33 97 /*
be_bryan 0:b74591d5ab33 98 * X.509 CRL v2 extensions (no extensions parsed yet.)
be_bryan 0:b74591d5ab33 99 */
be_bryan 0:b74591d5ab33 100 static int x509_get_crl_ext( unsigned char **p,
be_bryan 0:b74591d5ab33 101 const unsigned char *end,
be_bryan 0:b74591d5ab33 102 mbedtls_x509_buf *ext )
be_bryan 0:b74591d5ab33 103 {
be_bryan 0:b74591d5ab33 104 int ret;
be_bryan 0:b74591d5ab33 105 size_t len = 0;
be_bryan 0:b74591d5ab33 106
be_bryan 0:b74591d5ab33 107 /* Get explicit tag */
be_bryan 0:b74591d5ab33 108 if( ( ret = mbedtls_x509_get_ext( p, end, ext, 0) ) != 0 )
be_bryan 0:b74591d5ab33 109 {
be_bryan 0:b74591d5ab33 110 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
be_bryan 0:b74591d5ab33 111 return( 0 );
be_bryan 0:b74591d5ab33 112
be_bryan 0:b74591d5ab33 113 return( ret );
be_bryan 0:b74591d5ab33 114 }
be_bryan 0:b74591d5ab33 115
be_bryan 0:b74591d5ab33 116 while( *p < end )
be_bryan 0:b74591d5ab33 117 {
be_bryan 0:b74591d5ab33 118 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
be_bryan 0:b74591d5ab33 119 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
be_bryan 0:b74591d5ab33 120 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
be_bryan 0:b74591d5ab33 121
be_bryan 0:b74591d5ab33 122 *p += len;
be_bryan 0:b74591d5ab33 123 }
be_bryan 0:b74591d5ab33 124
be_bryan 0:b74591d5ab33 125 if( *p != end )
be_bryan 0:b74591d5ab33 126 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
be_bryan 0:b74591d5ab33 127 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
be_bryan 0:b74591d5ab33 128
be_bryan 0:b74591d5ab33 129 return( 0 );
be_bryan 0:b74591d5ab33 130 }
be_bryan 0:b74591d5ab33 131
be_bryan 0:b74591d5ab33 132 /*
be_bryan 0:b74591d5ab33 133 * X.509 CRL v2 entry extensions (no extensions parsed yet.)
be_bryan 0:b74591d5ab33 134 */
be_bryan 0:b74591d5ab33 135 static int x509_get_crl_entry_ext( unsigned char **p,
be_bryan 0:b74591d5ab33 136 const unsigned char *end,
be_bryan 0:b74591d5ab33 137 mbedtls_x509_buf *ext )
be_bryan 0:b74591d5ab33 138 {
be_bryan 0:b74591d5ab33 139 int ret;
be_bryan 0:b74591d5ab33 140 size_t len = 0;
be_bryan 0:b74591d5ab33 141
be_bryan 0:b74591d5ab33 142 /* OPTIONAL */
be_bryan 0:b74591d5ab33 143 if( end <= *p )
be_bryan 0:b74591d5ab33 144 return( 0 );
be_bryan 0:b74591d5ab33 145
be_bryan 0:b74591d5ab33 146 ext->tag = **p;
be_bryan 0:b74591d5ab33 147 ext->p = *p;
be_bryan 0:b74591d5ab33 148
be_bryan 0:b74591d5ab33 149 /*
be_bryan 0:b74591d5ab33 150 * Get CRL-entry extension sequence header
be_bryan 0:b74591d5ab33 151 * crlEntryExtensions Extensions OPTIONAL -- if present, MUST be v2
be_bryan 0:b74591d5ab33 152 */
be_bryan 0:b74591d5ab33 153 if( ( ret = mbedtls_asn1_get_tag( p, end, &ext->len,
be_bryan 0:b74591d5ab33 154 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
be_bryan 0:b74591d5ab33 155 {
be_bryan 0:b74591d5ab33 156 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
be_bryan 0:b74591d5ab33 157 {
be_bryan 0:b74591d5ab33 158 ext->p = NULL;
be_bryan 0:b74591d5ab33 159 return( 0 );
be_bryan 0:b74591d5ab33 160 }
be_bryan 0:b74591d5ab33 161 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
be_bryan 0:b74591d5ab33 162 }
be_bryan 0:b74591d5ab33 163
be_bryan 0:b74591d5ab33 164 end = *p + ext->len;
be_bryan 0:b74591d5ab33 165
be_bryan 0:b74591d5ab33 166 if( end != *p + ext->len )
be_bryan 0:b74591d5ab33 167 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
be_bryan 0:b74591d5ab33 168 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
be_bryan 0:b74591d5ab33 169
be_bryan 0:b74591d5ab33 170 while( *p < end )
be_bryan 0:b74591d5ab33 171 {
be_bryan 0:b74591d5ab33 172 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
be_bryan 0:b74591d5ab33 173 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
be_bryan 0:b74591d5ab33 174 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
be_bryan 0:b74591d5ab33 175
be_bryan 0:b74591d5ab33 176 *p += len;
be_bryan 0:b74591d5ab33 177 }
be_bryan 0:b74591d5ab33 178
be_bryan 0:b74591d5ab33 179 if( *p != end )
be_bryan 0:b74591d5ab33 180 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
be_bryan 0:b74591d5ab33 181 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
be_bryan 0:b74591d5ab33 182
be_bryan 0:b74591d5ab33 183 return( 0 );
be_bryan 0:b74591d5ab33 184 }
be_bryan 0:b74591d5ab33 185
be_bryan 0:b74591d5ab33 186 /*
be_bryan 0:b74591d5ab33 187 * X.509 CRL Entries
be_bryan 0:b74591d5ab33 188 */
be_bryan 0:b74591d5ab33 189 static int x509_get_entries( unsigned char **p,
be_bryan 0:b74591d5ab33 190 const unsigned char *end,
be_bryan 0:b74591d5ab33 191 mbedtls_x509_crl_entry *entry )
be_bryan 0:b74591d5ab33 192 {
be_bryan 0:b74591d5ab33 193 int ret;
be_bryan 0:b74591d5ab33 194 size_t entry_len;
be_bryan 0:b74591d5ab33 195 mbedtls_x509_crl_entry *cur_entry = entry;
be_bryan 0:b74591d5ab33 196
be_bryan 0:b74591d5ab33 197 if( *p == end )
be_bryan 0:b74591d5ab33 198 return( 0 );
be_bryan 0:b74591d5ab33 199
be_bryan 0:b74591d5ab33 200 if( ( ret = mbedtls_asn1_get_tag( p, end, &entry_len,
be_bryan 0:b74591d5ab33 201 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
be_bryan 0:b74591d5ab33 202 {
be_bryan 0:b74591d5ab33 203 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
be_bryan 0:b74591d5ab33 204 return( 0 );
be_bryan 0:b74591d5ab33 205
be_bryan 0:b74591d5ab33 206 return( ret );
be_bryan 0:b74591d5ab33 207 }
be_bryan 0:b74591d5ab33 208
be_bryan 0:b74591d5ab33 209 end = *p + entry_len;
be_bryan 0:b74591d5ab33 210
be_bryan 0:b74591d5ab33 211 while( *p < end )
be_bryan 0:b74591d5ab33 212 {
be_bryan 0:b74591d5ab33 213 size_t len2;
be_bryan 0:b74591d5ab33 214 const unsigned char *end2;
be_bryan 0:b74591d5ab33 215
be_bryan 0:b74591d5ab33 216 if( ( ret = mbedtls_asn1_get_tag( p, end, &len2,
be_bryan 0:b74591d5ab33 217 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
be_bryan 0:b74591d5ab33 218 {
be_bryan 0:b74591d5ab33 219 return( ret );
be_bryan 0:b74591d5ab33 220 }
be_bryan 0:b74591d5ab33 221
be_bryan 0:b74591d5ab33 222 cur_entry->raw.tag = **p;
be_bryan 0:b74591d5ab33 223 cur_entry->raw.p = *p;
be_bryan 0:b74591d5ab33 224 cur_entry->raw.len = len2;
be_bryan 0:b74591d5ab33 225 end2 = *p + len2;
be_bryan 0:b74591d5ab33 226
be_bryan 0:b74591d5ab33 227 if( ( ret = mbedtls_x509_get_serial( p, end2, &cur_entry->serial ) ) != 0 )
be_bryan 0:b74591d5ab33 228 return( ret );
be_bryan 0:b74591d5ab33 229
be_bryan 0:b74591d5ab33 230 if( ( ret = mbedtls_x509_get_time( p, end2,
be_bryan 0:b74591d5ab33 231 &cur_entry->revocation_date ) ) != 0 )
be_bryan 0:b74591d5ab33 232 return( ret );
be_bryan 0:b74591d5ab33 233
be_bryan 0:b74591d5ab33 234 if( ( ret = x509_get_crl_entry_ext( p, end2,
be_bryan 0:b74591d5ab33 235 &cur_entry->entry_ext ) ) != 0 )
be_bryan 0:b74591d5ab33 236 return( ret );
be_bryan 0:b74591d5ab33 237
be_bryan 0:b74591d5ab33 238 if( *p < end )
be_bryan 0:b74591d5ab33 239 {
be_bryan 0:b74591d5ab33 240 cur_entry->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl_entry ) );
be_bryan 0:b74591d5ab33 241
be_bryan 0:b74591d5ab33 242 if( cur_entry->next == NULL )
be_bryan 0:b74591d5ab33 243 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
be_bryan 0:b74591d5ab33 244
be_bryan 0:b74591d5ab33 245 cur_entry = cur_entry->next;
be_bryan 0:b74591d5ab33 246 }
be_bryan 0:b74591d5ab33 247 }
be_bryan 0:b74591d5ab33 248
be_bryan 0:b74591d5ab33 249 return( 0 );
be_bryan 0:b74591d5ab33 250 }
be_bryan 0:b74591d5ab33 251
be_bryan 0:b74591d5ab33 252 /*
be_bryan 0:b74591d5ab33 253 * Parse one CRLs in DER format and append it to the chained list
be_bryan 0:b74591d5ab33 254 */
be_bryan 0:b74591d5ab33 255 int mbedtls_x509_crl_parse_der( mbedtls_x509_crl *chain,
be_bryan 0:b74591d5ab33 256 const unsigned char *buf, size_t buflen )
be_bryan 0:b74591d5ab33 257 {
be_bryan 0:b74591d5ab33 258 int ret;
be_bryan 0:b74591d5ab33 259 size_t len;
be_bryan 0:b74591d5ab33 260 unsigned char *p, *end;
be_bryan 0:b74591d5ab33 261 mbedtls_x509_buf sig_params1, sig_params2, sig_oid2;
be_bryan 0:b74591d5ab33 262 mbedtls_x509_crl *crl = chain;
be_bryan 0:b74591d5ab33 263
be_bryan 0:b74591d5ab33 264 /*
be_bryan 0:b74591d5ab33 265 * Check for valid input
be_bryan 0:b74591d5ab33 266 */
be_bryan 0:b74591d5ab33 267 if( crl == NULL || buf == NULL )
be_bryan 0:b74591d5ab33 268 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
be_bryan 0:b74591d5ab33 269
be_bryan 0:b74591d5ab33 270 memset( &sig_params1, 0, sizeof( mbedtls_x509_buf ) );
be_bryan 0:b74591d5ab33 271 memset( &sig_params2, 0, sizeof( mbedtls_x509_buf ) );
be_bryan 0:b74591d5ab33 272 memset( &sig_oid2, 0, sizeof( mbedtls_x509_buf ) );
be_bryan 0:b74591d5ab33 273
be_bryan 0:b74591d5ab33 274 /*
be_bryan 0:b74591d5ab33 275 * Add new CRL on the end of the chain if needed.
be_bryan 0:b74591d5ab33 276 */
be_bryan 0:b74591d5ab33 277 while( crl->version != 0 && crl->next != NULL )
be_bryan 0:b74591d5ab33 278 crl = crl->next;
be_bryan 0:b74591d5ab33 279
be_bryan 0:b74591d5ab33 280 if( crl->version != 0 && crl->next == NULL )
be_bryan 0:b74591d5ab33 281 {
be_bryan 0:b74591d5ab33 282 crl->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl ) );
be_bryan 0:b74591d5ab33 283
be_bryan 0:b74591d5ab33 284 if( crl->next == NULL )
be_bryan 0:b74591d5ab33 285 {
be_bryan 0:b74591d5ab33 286 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 287 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
be_bryan 0:b74591d5ab33 288 }
be_bryan 0:b74591d5ab33 289
be_bryan 0:b74591d5ab33 290 mbedtls_x509_crl_init( crl->next );
be_bryan 0:b74591d5ab33 291 crl = crl->next;
be_bryan 0:b74591d5ab33 292 }
be_bryan 0:b74591d5ab33 293
be_bryan 0:b74591d5ab33 294 /*
be_bryan 0:b74591d5ab33 295 * Copy raw DER-encoded CRL
be_bryan 0:b74591d5ab33 296 */
be_bryan 0:b74591d5ab33 297 if( ( p = mbedtls_calloc( 1, buflen ) ) == NULL )
be_bryan 0:b74591d5ab33 298 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
be_bryan 0:b74591d5ab33 299
be_bryan 0:b74591d5ab33 300 memcpy( p, buf, buflen );
be_bryan 0:b74591d5ab33 301
be_bryan 0:b74591d5ab33 302 crl->raw.p = p;
be_bryan 0:b74591d5ab33 303 crl->raw.len = buflen;
be_bryan 0:b74591d5ab33 304
be_bryan 0:b74591d5ab33 305 end = p + buflen;
be_bryan 0:b74591d5ab33 306
be_bryan 0:b74591d5ab33 307 /*
be_bryan 0:b74591d5ab33 308 * CertificateList ::= SEQUENCE {
be_bryan 0:b74591d5ab33 309 * tbsCertList TBSCertList,
be_bryan 0:b74591d5ab33 310 * signatureAlgorithm AlgorithmIdentifier,
be_bryan 0:b74591d5ab33 311 * signatureValue BIT STRING }
be_bryan 0:b74591d5ab33 312 */
be_bryan 0:b74591d5ab33 313 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
be_bryan 0:b74591d5ab33 314 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
be_bryan 0:b74591d5ab33 315 {
be_bryan 0:b74591d5ab33 316 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 317 return( MBEDTLS_ERR_X509_INVALID_FORMAT );
be_bryan 0:b74591d5ab33 318 }
be_bryan 0:b74591d5ab33 319
be_bryan 0:b74591d5ab33 320 if( len != (size_t) ( end - p ) )
be_bryan 0:b74591d5ab33 321 {
be_bryan 0:b74591d5ab33 322 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 323 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
be_bryan 0:b74591d5ab33 324 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
be_bryan 0:b74591d5ab33 325 }
be_bryan 0:b74591d5ab33 326
be_bryan 0:b74591d5ab33 327 /*
be_bryan 0:b74591d5ab33 328 * TBSCertList ::= SEQUENCE {
be_bryan 0:b74591d5ab33 329 */
be_bryan 0:b74591d5ab33 330 crl->tbs.p = p;
be_bryan 0:b74591d5ab33 331
be_bryan 0:b74591d5ab33 332 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
be_bryan 0:b74591d5ab33 333 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
be_bryan 0:b74591d5ab33 334 {
be_bryan 0:b74591d5ab33 335 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 336 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
be_bryan 0:b74591d5ab33 337 }
be_bryan 0:b74591d5ab33 338
be_bryan 0:b74591d5ab33 339 end = p + len;
be_bryan 0:b74591d5ab33 340 crl->tbs.len = end - crl->tbs.p;
be_bryan 0:b74591d5ab33 341
be_bryan 0:b74591d5ab33 342 /*
be_bryan 0:b74591d5ab33 343 * Version ::= INTEGER OPTIONAL { v1(0), v2(1) }
be_bryan 0:b74591d5ab33 344 * -- if present, MUST be v2
be_bryan 0:b74591d5ab33 345 *
be_bryan 0:b74591d5ab33 346 * signature AlgorithmIdentifier
be_bryan 0:b74591d5ab33 347 */
be_bryan 0:b74591d5ab33 348 if( ( ret = x509_crl_get_version( &p, end, &crl->version ) ) != 0 ||
be_bryan 0:b74591d5ab33 349 ( ret = mbedtls_x509_get_alg( &p, end, &crl->sig_oid, &sig_params1 ) ) != 0 )
be_bryan 0:b74591d5ab33 350 {
be_bryan 0:b74591d5ab33 351 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 352 return( ret );
be_bryan 0:b74591d5ab33 353 }
be_bryan 0:b74591d5ab33 354
be_bryan 0:b74591d5ab33 355 if( crl->version < 0 || crl->version > 1 )
be_bryan 0:b74591d5ab33 356 {
be_bryan 0:b74591d5ab33 357 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 358 return( MBEDTLS_ERR_X509_UNKNOWN_VERSION );
be_bryan 0:b74591d5ab33 359 }
be_bryan 0:b74591d5ab33 360
be_bryan 0:b74591d5ab33 361 crl->version++;
be_bryan 0:b74591d5ab33 362
be_bryan 0:b74591d5ab33 363 if( ( ret = mbedtls_x509_get_sig_alg( &crl->sig_oid, &sig_params1,
be_bryan 0:b74591d5ab33 364 &crl->sig_md, &crl->sig_pk,
be_bryan 0:b74591d5ab33 365 &crl->sig_opts ) ) != 0 )
be_bryan 0:b74591d5ab33 366 {
be_bryan 0:b74591d5ab33 367 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 368 return( MBEDTLS_ERR_X509_UNKNOWN_SIG_ALG );
be_bryan 0:b74591d5ab33 369 }
be_bryan 0:b74591d5ab33 370
be_bryan 0:b74591d5ab33 371 /*
be_bryan 0:b74591d5ab33 372 * issuer Name
be_bryan 0:b74591d5ab33 373 */
be_bryan 0:b74591d5ab33 374 crl->issuer_raw.p = p;
be_bryan 0:b74591d5ab33 375
be_bryan 0:b74591d5ab33 376 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
be_bryan 0:b74591d5ab33 377 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
be_bryan 0:b74591d5ab33 378 {
be_bryan 0:b74591d5ab33 379 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 380 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
be_bryan 0:b74591d5ab33 381 }
be_bryan 0:b74591d5ab33 382
be_bryan 0:b74591d5ab33 383 if( ( ret = mbedtls_x509_get_name( &p, p + len, &crl->issuer ) ) != 0 )
be_bryan 0:b74591d5ab33 384 {
be_bryan 0:b74591d5ab33 385 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 386 return( ret );
be_bryan 0:b74591d5ab33 387 }
be_bryan 0:b74591d5ab33 388
be_bryan 0:b74591d5ab33 389 crl->issuer_raw.len = p - crl->issuer_raw.p;
be_bryan 0:b74591d5ab33 390
be_bryan 0:b74591d5ab33 391 /*
be_bryan 0:b74591d5ab33 392 * thisUpdate Time
be_bryan 0:b74591d5ab33 393 * nextUpdate Time OPTIONAL
be_bryan 0:b74591d5ab33 394 */
be_bryan 0:b74591d5ab33 395 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->this_update ) ) != 0 )
be_bryan 0:b74591d5ab33 396 {
be_bryan 0:b74591d5ab33 397 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 398 return( ret );
be_bryan 0:b74591d5ab33 399 }
be_bryan 0:b74591d5ab33 400
be_bryan 0:b74591d5ab33 401 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->next_update ) ) != 0 )
be_bryan 0:b74591d5ab33 402 {
be_bryan 0:b74591d5ab33 403 if( ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
be_bryan 0:b74591d5ab33 404 MBEDTLS_ERR_ASN1_UNEXPECTED_TAG ) &&
be_bryan 0:b74591d5ab33 405 ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
be_bryan 0:b74591d5ab33 406 MBEDTLS_ERR_ASN1_OUT_OF_DATA ) )
be_bryan 0:b74591d5ab33 407 {
be_bryan 0:b74591d5ab33 408 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 409 return( ret );
be_bryan 0:b74591d5ab33 410 }
be_bryan 0:b74591d5ab33 411 }
be_bryan 0:b74591d5ab33 412
be_bryan 0:b74591d5ab33 413 /*
be_bryan 0:b74591d5ab33 414 * revokedCertificates SEQUENCE OF SEQUENCE {
be_bryan 0:b74591d5ab33 415 * userCertificate CertificateSerialNumber,
be_bryan 0:b74591d5ab33 416 * revocationDate Time,
be_bryan 0:b74591d5ab33 417 * crlEntryExtensions Extensions OPTIONAL
be_bryan 0:b74591d5ab33 418 * -- if present, MUST be v2
be_bryan 0:b74591d5ab33 419 * } OPTIONAL
be_bryan 0:b74591d5ab33 420 */
be_bryan 0:b74591d5ab33 421 if( ( ret = x509_get_entries( &p, end, &crl->entry ) ) != 0 )
be_bryan 0:b74591d5ab33 422 {
be_bryan 0:b74591d5ab33 423 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 424 return( ret );
be_bryan 0:b74591d5ab33 425 }
be_bryan 0:b74591d5ab33 426
be_bryan 0:b74591d5ab33 427 /*
be_bryan 0:b74591d5ab33 428 * crlExtensions EXPLICIT Extensions OPTIONAL
be_bryan 0:b74591d5ab33 429 * -- if present, MUST be v2
be_bryan 0:b74591d5ab33 430 */
be_bryan 0:b74591d5ab33 431 if( crl->version == 2 )
be_bryan 0:b74591d5ab33 432 {
be_bryan 0:b74591d5ab33 433 ret = x509_get_crl_ext( &p, end, &crl->crl_ext );
be_bryan 0:b74591d5ab33 434
be_bryan 0:b74591d5ab33 435 if( ret != 0 )
be_bryan 0:b74591d5ab33 436 {
be_bryan 0:b74591d5ab33 437 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 438 return( ret );
be_bryan 0:b74591d5ab33 439 }
be_bryan 0:b74591d5ab33 440 }
be_bryan 0:b74591d5ab33 441
be_bryan 0:b74591d5ab33 442 if( p != end )
be_bryan 0:b74591d5ab33 443 {
be_bryan 0:b74591d5ab33 444 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 445 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
be_bryan 0:b74591d5ab33 446 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
be_bryan 0:b74591d5ab33 447 }
be_bryan 0:b74591d5ab33 448
be_bryan 0:b74591d5ab33 449 end = crl->raw.p + crl->raw.len;
be_bryan 0:b74591d5ab33 450
be_bryan 0:b74591d5ab33 451 /*
be_bryan 0:b74591d5ab33 452 * signatureAlgorithm AlgorithmIdentifier,
be_bryan 0:b74591d5ab33 453 * signatureValue BIT STRING
be_bryan 0:b74591d5ab33 454 */
be_bryan 0:b74591d5ab33 455 if( ( ret = mbedtls_x509_get_alg( &p, end, &sig_oid2, &sig_params2 ) ) != 0 )
be_bryan 0:b74591d5ab33 456 {
be_bryan 0:b74591d5ab33 457 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 458 return( ret );
be_bryan 0:b74591d5ab33 459 }
be_bryan 0:b74591d5ab33 460
be_bryan 0:b74591d5ab33 461 if( crl->sig_oid.len != sig_oid2.len ||
be_bryan 0:b74591d5ab33 462 memcmp( crl->sig_oid.p, sig_oid2.p, crl->sig_oid.len ) != 0 ||
be_bryan 0:b74591d5ab33 463 sig_params1.len != sig_params2.len ||
be_bryan 0:b74591d5ab33 464 ( sig_params1.len != 0 &&
be_bryan 0:b74591d5ab33 465 memcmp( sig_params1.p, sig_params2.p, sig_params1.len ) != 0 ) )
be_bryan 0:b74591d5ab33 466 {
be_bryan 0:b74591d5ab33 467 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 468 return( MBEDTLS_ERR_X509_SIG_MISMATCH );
be_bryan 0:b74591d5ab33 469 }
be_bryan 0:b74591d5ab33 470
be_bryan 0:b74591d5ab33 471 if( ( ret = mbedtls_x509_get_sig( &p, end, &crl->sig ) ) != 0 )
be_bryan 0:b74591d5ab33 472 {
be_bryan 0:b74591d5ab33 473 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 474 return( ret );
be_bryan 0:b74591d5ab33 475 }
be_bryan 0:b74591d5ab33 476
be_bryan 0:b74591d5ab33 477 if( p != end )
be_bryan 0:b74591d5ab33 478 {
be_bryan 0:b74591d5ab33 479 mbedtls_x509_crl_free( crl );
be_bryan 0:b74591d5ab33 480 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
be_bryan 0:b74591d5ab33 481 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
be_bryan 0:b74591d5ab33 482 }
be_bryan 0:b74591d5ab33 483
be_bryan 0:b74591d5ab33 484 return( 0 );
be_bryan 0:b74591d5ab33 485 }
be_bryan 0:b74591d5ab33 486
be_bryan 0:b74591d5ab33 487 /*
be_bryan 0:b74591d5ab33 488 * Parse one or more CRLs and add them to the chained list
be_bryan 0:b74591d5ab33 489 */
be_bryan 0:b74591d5ab33 490 int mbedtls_x509_crl_parse( mbedtls_x509_crl *chain, const unsigned char *buf, size_t buflen )
be_bryan 0:b74591d5ab33 491 {
be_bryan 0:b74591d5ab33 492 #if defined(MBEDTLS_PEM_PARSE_C)
be_bryan 0:b74591d5ab33 493 int ret;
be_bryan 0:b74591d5ab33 494 size_t use_len;
be_bryan 0:b74591d5ab33 495 mbedtls_pem_context pem;
be_bryan 0:b74591d5ab33 496 int is_pem = 0;
be_bryan 0:b74591d5ab33 497
be_bryan 0:b74591d5ab33 498 if( chain == NULL || buf == NULL )
be_bryan 0:b74591d5ab33 499 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
be_bryan 0:b74591d5ab33 500
be_bryan 0:b74591d5ab33 501 do
be_bryan 0:b74591d5ab33 502 {
be_bryan 0:b74591d5ab33 503 mbedtls_pem_init( &pem );
be_bryan 0:b74591d5ab33 504
be_bryan 0:b74591d5ab33 505 // Avoid calling mbedtls_pem_read_buffer() on non-null-terminated
be_bryan 0:b74591d5ab33 506 // string
be_bryan 0:b74591d5ab33 507 if( buflen == 0 || buf[buflen - 1] != '\0' )
be_bryan 0:b74591d5ab33 508 ret = MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT;
be_bryan 0:b74591d5ab33 509 else
be_bryan 0:b74591d5ab33 510 ret = mbedtls_pem_read_buffer( &pem,
be_bryan 0:b74591d5ab33 511 "-----BEGIN X509 CRL-----",
be_bryan 0:b74591d5ab33 512 "-----END X509 CRL-----",
be_bryan 0:b74591d5ab33 513 buf, NULL, 0, &use_len );
be_bryan 0:b74591d5ab33 514
be_bryan 0:b74591d5ab33 515 if( ret == 0 )
be_bryan 0:b74591d5ab33 516 {
be_bryan 0:b74591d5ab33 517 /*
be_bryan 0:b74591d5ab33 518 * Was PEM encoded
be_bryan 0:b74591d5ab33 519 */
be_bryan 0:b74591d5ab33 520 is_pem = 1;
be_bryan 0:b74591d5ab33 521
be_bryan 0:b74591d5ab33 522 buflen -= use_len;
be_bryan 0:b74591d5ab33 523 buf += use_len;
be_bryan 0:b74591d5ab33 524
be_bryan 0:b74591d5ab33 525 if( ( ret = mbedtls_x509_crl_parse_der( chain,
be_bryan 0:b74591d5ab33 526 pem.buf, pem.buflen ) ) != 0 )
be_bryan 0:b74591d5ab33 527 {
be_bryan 0:b74591d5ab33 528 mbedtls_pem_free( &pem );
be_bryan 0:b74591d5ab33 529 return( ret );
be_bryan 0:b74591d5ab33 530 }
be_bryan 0:b74591d5ab33 531 }
be_bryan 0:b74591d5ab33 532 else if( is_pem )
be_bryan 0:b74591d5ab33 533 {
be_bryan 0:b74591d5ab33 534 mbedtls_pem_free( &pem );
be_bryan 0:b74591d5ab33 535 return( ret );
be_bryan 0:b74591d5ab33 536 }
be_bryan 0:b74591d5ab33 537
be_bryan 0:b74591d5ab33 538 mbedtls_pem_free( &pem );
be_bryan 0:b74591d5ab33 539 }
be_bryan 0:b74591d5ab33 540 /* In the PEM case, buflen is 1 at the end, for the terminated NULL byte.
be_bryan 0:b74591d5ab33 541 * And a valid CRL cannot be less than 1 byte anyway. */
be_bryan 0:b74591d5ab33 542 while( is_pem && buflen > 1 );
be_bryan 0:b74591d5ab33 543
be_bryan 0:b74591d5ab33 544 if( is_pem )
be_bryan 0:b74591d5ab33 545 return( 0 );
be_bryan 0:b74591d5ab33 546 else
be_bryan 0:b74591d5ab33 547 #endif /* MBEDTLS_PEM_PARSE_C */
be_bryan 0:b74591d5ab33 548 return( mbedtls_x509_crl_parse_der( chain, buf, buflen ) );
be_bryan 0:b74591d5ab33 549 }
be_bryan 0:b74591d5ab33 550
be_bryan 0:b74591d5ab33 551 #if defined(MBEDTLS_FS_IO)
be_bryan 0:b74591d5ab33 552 /*
be_bryan 0:b74591d5ab33 553 * Load one or more CRLs and add them to the chained list
be_bryan 0:b74591d5ab33 554 */
be_bryan 0:b74591d5ab33 555 int mbedtls_x509_crl_parse_file( mbedtls_x509_crl *chain, const char *path )
be_bryan 0:b74591d5ab33 556 {
be_bryan 0:b74591d5ab33 557 int ret;
be_bryan 0:b74591d5ab33 558 size_t n;
be_bryan 0:b74591d5ab33 559 unsigned char *buf;
be_bryan 0:b74591d5ab33 560
be_bryan 0:b74591d5ab33 561 if( ( ret = mbedtls_pk_load_file( path, &buf, &n ) ) != 0 )
be_bryan 0:b74591d5ab33 562 return( ret );
be_bryan 0:b74591d5ab33 563
be_bryan 0:b74591d5ab33 564 ret = mbedtls_x509_crl_parse( chain, buf, n );
be_bryan 0:b74591d5ab33 565
be_bryan 0:b74591d5ab33 566 mbedtls_zeroize( buf, n );
be_bryan 0:b74591d5ab33 567 mbedtls_free( buf );
be_bryan 0:b74591d5ab33 568
be_bryan 0:b74591d5ab33 569 return( ret );
be_bryan 0:b74591d5ab33 570 }
be_bryan 0:b74591d5ab33 571 #endif /* MBEDTLS_FS_IO */
be_bryan 0:b74591d5ab33 572
be_bryan 0:b74591d5ab33 573 /*
be_bryan 0:b74591d5ab33 574 * Return an informational string about the certificate.
be_bryan 0:b74591d5ab33 575 */
be_bryan 0:b74591d5ab33 576 #define BEFORE_COLON 14
be_bryan 0:b74591d5ab33 577 #define BC "14"
be_bryan 0:b74591d5ab33 578 /*
be_bryan 0:b74591d5ab33 579 * Return an informational string about the CRL.
be_bryan 0:b74591d5ab33 580 */
be_bryan 0:b74591d5ab33 581 int mbedtls_x509_crl_info( char *buf, size_t size, const char *prefix,
be_bryan 0:b74591d5ab33 582 const mbedtls_x509_crl *crl )
be_bryan 0:b74591d5ab33 583 {
be_bryan 0:b74591d5ab33 584 int ret;
be_bryan 0:b74591d5ab33 585 size_t n;
be_bryan 0:b74591d5ab33 586 char *p;
be_bryan 0:b74591d5ab33 587 const mbedtls_x509_crl_entry *entry;
be_bryan 0:b74591d5ab33 588
be_bryan 0:b74591d5ab33 589 p = buf;
be_bryan 0:b74591d5ab33 590 n = size;
be_bryan 0:b74591d5ab33 591
be_bryan 0:b74591d5ab33 592 ret = mbedtls_snprintf( p, n, "%sCRL version : %d",
be_bryan 0:b74591d5ab33 593 prefix, crl->version );
be_bryan 0:b74591d5ab33 594 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 595
be_bryan 0:b74591d5ab33 596 ret = mbedtls_snprintf( p, n, "\n%sissuer name : ", prefix );
be_bryan 0:b74591d5ab33 597 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 598 ret = mbedtls_x509_dn_gets( p, n, &crl->issuer );
be_bryan 0:b74591d5ab33 599 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 600
be_bryan 0:b74591d5ab33 601 ret = mbedtls_snprintf( p, n, "\n%sthis update : " \
be_bryan 0:b74591d5ab33 602 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
be_bryan 0:b74591d5ab33 603 crl->this_update.year, crl->this_update.mon,
be_bryan 0:b74591d5ab33 604 crl->this_update.day, crl->this_update.hour,
be_bryan 0:b74591d5ab33 605 crl->this_update.min, crl->this_update.sec );
be_bryan 0:b74591d5ab33 606 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 607
be_bryan 0:b74591d5ab33 608 ret = mbedtls_snprintf( p, n, "\n%snext update : " \
be_bryan 0:b74591d5ab33 609 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
be_bryan 0:b74591d5ab33 610 crl->next_update.year, crl->next_update.mon,
be_bryan 0:b74591d5ab33 611 crl->next_update.day, crl->next_update.hour,
be_bryan 0:b74591d5ab33 612 crl->next_update.min, crl->next_update.sec );
be_bryan 0:b74591d5ab33 613 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 614
be_bryan 0:b74591d5ab33 615 entry = &crl->entry;
be_bryan 0:b74591d5ab33 616
be_bryan 0:b74591d5ab33 617 ret = mbedtls_snprintf( p, n, "\n%sRevoked certificates:",
be_bryan 0:b74591d5ab33 618 prefix );
be_bryan 0:b74591d5ab33 619 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 620
be_bryan 0:b74591d5ab33 621 while( entry != NULL && entry->raw.len != 0 )
be_bryan 0:b74591d5ab33 622 {
be_bryan 0:b74591d5ab33 623 ret = mbedtls_snprintf( p, n, "\n%sserial number: ",
be_bryan 0:b74591d5ab33 624 prefix );
be_bryan 0:b74591d5ab33 625 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 626
be_bryan 0:b74591d5ab33 627 ret = mbedtls_x509_serial_gets( p, n, &entry->serial );
be_bryan 0:b74591d5ab33 628 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 629
be_bryan 0:b74591d5ab33 630 ret = mbedtls_snprintf( p, n, " revocation date: " \
be_bryan 0:b74591d5ab33 631 "%04d-%02d-%02d %02d:%02d:%02d",
be_bryan 0:b74591d5ab33 632 entry->revocation_date.year, entry->revocation_date.mon,
be_bryan 0:b74591d5ab33 633 entry->revocation_date.day, entry->revocation_date.hour,
be_bryan 0:b74591d5ab33 634 entry->revocation_date.min, entry->revocation_date.sec );
be_bryan 0:b74591d5ab33 635 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 636
be_bryan 0:b74591d5ab33 637 entry = entry->next;
be_bryan 0:b74591d5ab33 638 }
be_bryan 0:b74591d5ab33 639
be_bryan 0:b74591d5ab33 640 ret = mbedtls_snprintf( p, n, "\n%ssigned using : ", prefix );
be_bryan 0:b74591d5ab33 641 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 642
be_bryan 0:b74591d5ab33 643 ret = mbedtls_x509_sig_alg_gets( p, n, &crl->sig_oid, crl->sig_pk, crl->sig_md,
be_bryan 0:b74591d5ab33 644 crl->sig_opts );
be_bryan 0:b74591d5ab33 645 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 646
be_bryan 0:b74591d5ab33 647 ret = mbedtls_snprintf( p, n, "\n" );
be_bryan 0:b74591d5ab33 648 MBEDTLS_X509_SAFE_SNPRINTF;
be_bryan 0:b74591d5ab33 649
be_bryan 0:b74591d5ab33 650 return( (int) ( size - n ) );
be_bryan 0:b74591d5ab33 651 }
be_bryan 0:b74591d5ab33 652
be_bryan 0:b74591d5ab33 653 /*
be_bryan 0:b74591d5ab33 654 * Initialize a CRL chain
be_bryan 0:b74591d5ab33 655 */
be_bryan 0:b74591d5ab33 656 void mbedtls_x509_crl_init( mbedtls_x509_crl *crl )
be_bryan 0:b74591d5ab33 657 {
be_bryan 0:b74591d5ab33 658 memset( crl, 0, sizeof(mbedtls_x509_crl) );
be_bryan 0:b74591d5ab33 659 }
be_bryan 0:b74591d5ab33 660
be_bryan 0:b74591d5ab33 661 /*
be_bryan 0:b74591d5ab33 662 * Unallocate all CRL data
be_bryan 0:b74591d5ab33 663 */
be_bryan 0:b74591d5ab33 664 void mbedtls_x509_crl_free( mbedtls_x509_crl *crl )
be_bryan 0:b74591d5ab33 665 {
be_bryan 0:b74591d5ab33 666 mbedtls_x509_crl *crl_cur = crl;
be_bryan 0:b74591d5ab33 667 mbedtls_x509_crl *crl_prv;
be_bryan 0:b74591d5ab33 668 mbedtls_x509_name *name_cur;
be_bryan 0:b74591d5ab33 669 mbedtls_x509_name *name_prv;
be_bryan 0:b74591d5ab33 670 mbedtls_x509_crl_entry *entry_cur;
be_bryan 0:b74591d5ab33 671 mbedtls_x509_crl_entry *entry_prv;
be_bryan 0:b74591d5ab33 672
be_bryan 0:b74591d5ab33 673 if( crl == NULL )
be_bryan 0:b74591d5ab33 674 return;
be_bryan 0:b74591d5ab33 675
be_bryan 0:b74591d5ab33 676 do
be_bryan 0:b74591d5ab33 677 {
be_bryan 0:b74591d5ab33 678 #if defined(MBEDTLS_X509_RSASSA_PSS_SUPPORT)
be_bryan 0:b74591d5ab33 679 mbedtls_free( crl_cur->sig_opts );
be_bryan 0:b74591d5ab33 680 #endif
be_bryan 0:b74591d5ab33 681
be_bryan 0:b74591d5ab33 682 name_cur = crl_cur->issuer.next;
be_bryan 0:b74591d5ab33 683 while( name_cur != NULL )
be_bryan 0:b74591d5ab33 684 {
be_bryan 0:b74591d5ab33 685 name_prv = name_cur;
be_bryan 0:b74591d5ab33 686 name_cur = name_cur->next;
be_bryan 0:b74591d5ab33 687 mbedtls_zeroize( name_prv, sizeof( mbedtls_x509_name ) );
be_bryan 0:b74591d5ab33 688 mbedtls_free( name_prv );
be_bryan 0:b74591d5ab33 689 }
be_bryan 0:b74591d5ab33 690
be_bryan 0:b74591d5ab33 691 entry_cur = crl_cur->entry.next;
be_bryan 0:b74591d5ab33 692 while( entry_cur != NULL )
be_bryan 0:b74591d5ab33 693 {
be_bryan 0:b74591d5ab33 694 entry_prv = entry_cur;
be_bryan 0:b74591d5ab33 695 entry_cur = entry_cur->next;
be_bryan 0:b74591d5ab33 696 mbedtls_zeroize( entry_prv, sizeof( mbedtls_x509_crl_entry ) );
be_bryan 0:b74591d5ab33 697 mbedtls_free( entry_prv );
be_bryan 0:b74591d5ab33 698 }
be_bryan 0:b74591d5ab33 699
be_bryan 0:b74591d5ab33 700 if( crl_cur->raw.p != NULL )
be_bryan 0:b74591d5ab33 701 {
be_bryan 0:b74591d5ab33 702 mbedtls_zeroize( crl_cur->raw.p, crl_cur->raw.len );
be_bryan 0:b74591d5ab33 703 mbedtls_free( crl_cur->raw.p );
be_bryan 0:b74591d5ab33 704 }
be_bryan 0:b74591d5ab33 705
be_bryan 0:b74591d5ab33 706 crl_cur = crl_cur->next;
be_bryan 0:b74591d5ab33 707 }
be_bryan 0:b74591d5ab33 708 while( crl_cur != NULL );
be_bryan 0:b74591d5ab33 709
be_bryan 0:b74591d5ab33 710 crl_cur = crl;
be_bryan 0:b74591d5ab33 711 do
be_bryan 0:b74591d5ab33 712 {
be_bryan 0:b74591d5ab33 713 crl_prv = crl_cur;
be_bryan 0:b74591d5ab33 714 crl_cur = crl_cur->next;
be_bryan 0:b74591d5ab33 715
be_bryan 0:b74591d5ab33 716 mbedtls_zeroize( crl_prv, sizeof( mbedtls_x509_crl ) );
be_bryan 0:b74591d5ab33 717 if( crl_prv != crl )
be_bryan 0:b74591d5ab33 718 mbedtls_free( crl_prv );
be_bryan 0:b74591d5ab33 719 }
be_bryan 0:b74591d5ab33 720 while( crl_cur != NULL );
be_bryan 0:b74591d5ab33 721 }
be_bryan 0:b74591d5ab33 722
be_bryan 0:b74591d5ab33 723 #endif /* MBEDTLS_X509_CRL_PARSE_C */