Includes library modifications to allow access to AIN_4 (AIN_0 / 5)

Committer:
bryantaylor
Date:
Tue Sep 20 21:26:12 2016 +0000
Revision:
0:eafc3fd41f75
hackathon

Who changed what in which revision?

UserRevisionLine numberNew contents of line
bryantaylor 0:eafc3fd41f75 1 /*
bryantaylor 0:eafc3fd41f75 2 * X.509 Certidicate Revocation List (CRL) parsing
bryantaylor 0:eafc3fd41f75 3 *
bryantaylor 0:eafc3fd41f75 4 * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
bryantaylor 0:eafc3fd41f75 5 * SPDX-License-Identifier: Apache-2.0
bryantaylor 0:eafc3fd41f75 6 *
bryantaylor 0:eafc3fd41f75 7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
bryantaylor 0:eafc3fd41f75 8 * not use this file except in compliance with the License.
bryantaylor 0:eafc3fd41f75 9 * You may obtain a copy of the License at
bryantaylor 0:eafc3fd41f75 10 *
bryantaylor 0:eafc3fd41f75 11 * http://www.apache.org/licenses/LICENSE-2.0
bryantaylor 0:eafc3fd41f75 12 *
bryantaylor 0:eafc3fd41f75 13 * Unless required by applicable law or agreed to in writing, software
bryantaylor 0:eafc3fd41f75 14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
bryantaylor 0:eafc3fd41f75 15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
bryantaylor 0:eafc3fd41f75 16 * See the License for the specific language governing permissions and
bryantaylor 0:eafc3fd41f75 17 * limitations under the License.
bryantaylor 0:eafc3fd41f75 18 *
bryantaylor 0:eafc3fd41f75 19 * This file is part of mbed TLS (https://tls.mbed.org)
bryantaylor 0:eafc3fd41f75 20 */
bryantaylor 0:eafc3fd41f75 21 /*
bryantaylor 0:eafc3fd41f75 22 * The ITU-T X.509 standard defines a certificate format for PKI.
bryantaylor 0:eafc3fd41f75 23 *
bryantaylor 0:eafc3fd41f75 24 * http://www.ietf.org/rfc/rfc5280.txt (Certificates and CRLs)
bryantaylor 0:eafc3fd41f75 25 * http://www.ietf.org/rfc/rfc3279.txt (Alg IDs for CRLs)
bryantaylor 0:eafc3fd41f75 26 * http://www.ietf.org/rfc/rfc2986.txt (CSRs, aka PKCS#10)
bryantaylor 0:eafc3fd41f75 27 *
bryantaylor 0:eafc3fd41f75 28 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.680-0207.pdf
bryantaylor 0:eafc3fd41f75 29 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.690-0207.pdf
bryantaylor 0:eafc3fd41f75 30 */
bryantaylor 0:eafc3fd41f75 31
bryantaylor 0:eafc3fd41f75 32 #if !defined(MBEDTLS_CONFIG_FILE)
bryantaylor 0:eafc3fd41f75 33 #include "mbedtls/config.h"
bryantaylor 0:eafc3fd41f75 34 #else
bryantaylor 0:eafc3fd41f75 35 #include MBEDTLS_CONFIG_FILE
bryantaylor 0:eafc3fd41f75 36 #endif
bryantaylor 0:eafc3fd41f75 37
bryantaylor 0:eafc3fd41f75 38 #if defined(MBEDTLS_X509_CRL_PARSE_C)
bryantaylor 0:eafc3fd41f75 39
bryantaylor 0:eafc3fd41f75 40 #include "mbedtls/x509_crl.h"
bryantaylor 0:eafc3fd41f75 41 #include "mbedtls/oid.h"
bryantaylor 0:eafc3fd41f75 42
bryantaylor 0:eafc3fd41f75 43 #include <string.h>
bryantaylor 0:eafc3fd41f75 44
bryantaylor 0:eafc3fd41f75 45 #if defined(MBEDTLS_PEM_PARSE_C)
bryantaylor 0:eafc3fd41f75 46 #include "mbedtls/pem.h"
bryantaylor 0:eafc3fd41f75 47 #endif
bryantaylor 0:eafc3fd41f75 48
bryantaylor 0:eafc3fd41f75 49 #if defined(MBEDTLS_PLATFORM_C)
bryantaylor 0:eafc3fd41f75 50 #include "mbedtls/platform.h"
bryantaylor 0:eafc3fd41f75 51 #else
bryantaylor 0:eafc3fd41f75 52 #include <stdlib.h>
bryantaylor 0:eafc3fd41f75 53 #include <stdio.h>
bryantaylor 0:eafc3fd41f75 54 #define mbedtls_free free
bryantaylor 0:eafc3fd41f75 55 #define mbedtls_calloc calloc
bryantaylor 0:eafc3fd41f75 56 #define mbedtls_snprintf snprintf
bryantaylor 0:eafc3fd41f75 57 #endif
bryantaylor 0:eafc3fd41f75 58
bryantaylor 0:eafc3fd41f75 59 #if defined(_WIN32) && !defined(EFIX64) && !defined(EFI32)
bryantaylor 0:eafc3fd41f75 60 #include <windows.h>
bryantaylor 0:eafc3fd41f75 61 #else
bryantaylor 0:eafc3fd41f75 62 #include <time.h>
bryantaylor 0:eafc3fd41f75 63 #endif
bryantaylor 0:eafc3fd41f75 64
bryantaylor 0:eafc3fd41f75 65 #if defined(MBEDTLS_FS_IO) || defined(EFIX64) || defined(EFI32)
bryantaylor 0:eafc3fd41f75 66 #include <stdio.h>
bryantaylor 0:eafc3fd41f75 67 #endif
bryantaylor 0:eafc3fd41f75 68
bryantaylor 0:eafc3fd41f75 69 /* Implementation that should never be optimized out by the compiler */
bryantaylor 0:eafc3fd41f75 70 static void mbedtls_zeroize( void *v, size_t n ) {
bryantaylor 0:eafc3fd41f75 71 volatile unsigned char *p = v; while( n-- ) *p++ = 0;
bryantaylor 0:eafc3fd41f75 72 }
bryantaylor 0:eafc3fd41f75 73
bryantaylor 0:eafc3fd41f75 74 /*
bryantaylor 0:eafc3fd41f75 75 * Version ::= INTEGER { v1(0), v2(1) }
bryantaylor 0:eafc3fd41f75 76 */
bryantaylor 0:eafc3fd41f75 77 static int x509_crl_get_version( unsigned char **p,
bryantaylor 0:eafc3fd41f75 78 const unsigned char *end,
bryantaylor 0:eafc3fd41f75 79 int *ver )
bryantaylor 0:eafc3fd41f75 80 {
bryantaylor 0:eafc3fd41f75 81 int ret;
bryantaylor 0:eafc3fd41f75 82
bryantaylor 0:eafc3fd41f75 83 if( ( ret = mbedtls_asn1_get_int( p, end, ver ) ) != 0 )
bryantaylor 0:eafc3fd41f75 84 {
bryantaylor 0:eafc3fd41f75 85 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
bryantaylor 0:eafc3fd41f75 86 {
bryantaylor 0:eafc3fd41f75 87 *ver = 0;
bryantaylor 0:eafc3fd41f75 88 return( 0 );
bryantaylor 0:eafc3fd41f75 89 }
bryantaylor 0:eafc3fd41f75 90
bryantaylor 0:eafc3fd41f75 91 return( MBEDTLS_ERR_X509_INVALID_VERSION + ret );
bryantaylor 0:eafc3fd41f75 92 }
bryantaylor 0:eafc3fd41f75 93
bryantaylor 0:eafc3fd41f75 94 return( 0 );
bryantaylor 0:eafc3fd41f75 95 }
bryantaylor 0:eafc3fd41f75 96
bryantaylor 0:eafc3fd41f75 97 /*
bryantaylor 0:eafc3fd41f75 98 * X.509 CRL v2 extensions (no extensions parsed yet.)
bryantaylor 0:eafc3fd41f75 99 */
bryantaylor 0:eafc3fd41f75 100 static int x509_get_crl_ext( unsigned char **p,
bryantaylor 0:eafc3fd41f75 101 const unsigned char *end,
bryantaylor 0:eafc3fd41f75 102 mbedtls_x509_buf *ext )
bryantaylor 0:eafc3fd41f75 103 {
bryantaylor 0:eafc3fd41f75 104 int ret;
bryantaylor 0:eafc3fd41f75 105 size_t len = 0;
bryantaylor 0:eafc3fd41f75 106
bryantaylor 0:eafc3fd41f75 107 /* Get explicit tag */
bryantaylor 0:eafc3fd41f75 108 if( ( ret = mbedtls_x509_get_ext( p, end, ext, 0) ) != 0 )
bryantaylor 0:eafc3fd41f75 109 {
bryantaylor 0:eafc3fd41f75 110 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
bryantaylor 0:eafc3fd41f75 111 return( 0 );
bryantaylor 0:eafc3fd41f75 112
bryantaylor 0:eafc3fd41f75 113 return( ret );
bryantaylor 0:eafc3fd41f75 114 }
bryantaylor 0:eafc3fd41f75 115
bryantaylor 0:eafc3fd41f75 116 while( *p < end )
bryantaylor 0:eafc3fd41f75 117 {
bryantaylor 0:eafc3fd41f75 118 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
bryantaylor 0:eafc3fd41f75 119 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
bryantaylor 0:eafc3fd41f75 120 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
bryantaylor 0:eafc3fd41f75 121
bryantaylor 0:eafc3fd41f75 122 *p += len;
bryantaylor 0:eafc3fd41f75 123 }
bryantaylor 0:eafc3fd41f75 124
bryantaylor 0:eafc3fd41f75 125 if( *p != end )
bryantaylor 0:eafc3fd41f75 126 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
bryantaylor 0:eafc3fd41f75 127 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
bryantaylor 0:eafc3fd41f75 128
bryantaylor 0:eafc3fd41f75 129 return( 0 );
bryantaylor 0:eafc3fd41f75 130 }
bryantaylor 0:eafc3fd41f75 131
bryantaylor 0:eafc3fd41f75 132 /*
bryantaylor 0:eafc3fd41f75 133 * X.509 CRL v2 entry extensions (no extensions parsed yet.)
bryantaylor 0:eafc3fd41f75 134 */
bryantaylor 0:eafc3fd41f75 135 static int x509_get_crl_entry_ext( unsigned char **p,
bryantaylor 0:eafc3fd41f75 136 const unsigned char *end,
bryantaylor 0:eafc3fd41f75 137 mbedtls_x509_buf *ext )
bryantaylor 0:eafc3fd41f75 138 {
bryantaylor 0:eafc3fd41f75 139 int ret;
bryantaylor 0:eafc3fd41f75 140 size_t len = 0;
bryantaylor 0:eafc3fd41f75 141
bryantaylor 0:eafc3fd41f75 142 /* OPTIONAL */
bryantaylor 0:eafc3fd41f75 143 if( end <= *p )
bryantaylor 0:eafc3fd41f75 144 return( 0 );
bryantaylor 0:eafc3fd41f75 145
bryantaylor 0:eafc3fd41f75 146 ext->tag = **p;
bryantaylor 0:eafc3fd41f75 147 ext->p = *p;
bryantaylor 0:eafc3fd41f75 148
bryantaylor 0:eafc3fd41f75 149 /*
bryantaylor 0:eafc3fd41f75 150 * Get CRL-entry extension sequence header
bryantaylor 0:eafc3fd41f75 151 * crlEntryExtensions Extensions OPTIONAL -- if present, MUST be v2
bryantaylor 0:eafc3fd41f75 152 */
bryantaylor 0:eafc3fd41f75 153 if( ( ret = mbedtls_asn1_get_tag( p, end, &ext->len,
bryantaylor 0:eafc3fd41f75 154 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
bryantaylor 0:eafc3fd41f75 155 {
bryantaylor 0:eafc3fd41f75 156 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
bryantaylor 0:eafc3fd41f75 157 {
bryantaylor 0:eafc3fd41f75 158 ext->p = NULL;
bryantaylor 0:eafc3fd41f75 159 return( 0 );
bryantaylor 0:eafc3fd41f75 160 }
bryantaylor 0:eafc3fd41f75 161 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
bryantaylor 0:eafc3fd41f75 162 }
bryantaylor 0:eafc3fd41f75 163
bryantaylor 0:eafc3fd41f75 164 end = *p + ext->len;
bryantaylor 0:eafc3fd41f75 165
bryantaylor 0:eafc3fd41f75 166 if( end != *p + ext->len )
bryantaylor 0:eafc3fd41f75 167 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
bryantaylor 0:eafc3fd41f75 168 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
bryantaylor 0:eafc3fd41f75 169
bryantaylor 0:eafc3fd41f75 170 while( *p < end )
bryantaylor 0:eafc3fd41f75 171 {
bryantaylor 0:eafc3fd41f75 172 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
bryantaylor 0:eafc3fd41f75 173 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
bryantaylor 0:eafc3fd41f75 174 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
bryantaylor 0:eafc3fd41f75 175
bryantaylor 0:eafc3fd41f75 176 *p += len;
bryantaylor 0:eafc3fd41f75 177 }
bryantaylor 0:eafc3fd41f75 178
bryantaylor 0:eafc3fd41f75 179 if( *p != end )
bryantaylor 0:eafc3fd41f75 180 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
bryantaylor 0:eafc3fd41f75 181 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
bryantaylor 0:eafc3fd41f75 182
bryantaylor 0:eafc3fd41f75 183 return( 0 );
bryantaylor 0:eafc3fd41f75 184 }
bryantaylor 0:eafc3fd41f75 185
bryantaylor 0:eafc3fd41f75 186 /*
bryantaylor 0:eafc3fd41f75 187 * X.509 CRL Entries
bryantaylor 0:eafc3fd41f75 188 */
bryantaylor 0:eafc3fd41f75 189 static int x509_get_entries( unsigned char **p,
bryantaylor 0:eafc3fd41f75 190 const unsigned char *end,
bryantaylor 0:eafc3fd41f75 191 mbedtls_x509_crl_entry *entry )
bryantaylor 0:eafc3fd41f75 192 {
bryantaylor 0:eafc3fd41f75 193 int ret;
bryantaylor 0:eafc3fd41f75 194 size_t entry_len;
bryantaylor 0:eafc3fd41f75 195 mbedtls_x509_crl_entry *cur_entry = entry;
bryantaylor 0:eafc3fd41f75 196
bryantaylor 0:eafc3fd41f75 197 if( *p == end )
bryantaylor 0:eafc3fd41f75 198 return( 0 );
bryantaylor 0:eafc3fd41f75 199
bryantaylor 0:eafc3fd41f75 200 if( ( ret = mbedtls_asn1_get_tag( p, end, &entry_len,
bryantaylor 0:eafc3fd41f75 201 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
bryantaylor 0:eafc3fd41f75 202 {
bryantaylor 0:eafc3fd41f75 203 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
bryantaylor 0:eafc3fd41f75 204 return( 0 );
bryantaylor 0:eafc3fd41f75 205
bryantaylor 0:eafc3fd41f75 206 return( ret );
bryantaylor 0:eafc3fd41f75 207 }
bryantaylor 0:eafc3fd41f75 208
bryantaylor 0:eafc3fd41f75 209 end = *p + entry_len;
bryantaylor 0:eafc3fd41f75 210
bryantaylor 0:eafc3fd41f75 211 while( *p < end )
bryantaylor 0:eafc3fd41f75 212 {
bryantaylor 0:eafc3fd41f75 213 size_t len2;
bryantaylor 0:eafc3fd41f75 214 const unsigned char *end2;
bryantaylor 0:eafc3fd41f75 215
bryantaylor 0:eafc3fd41f75 216 if( ( ret = mbedtls_asn1_get_tag( p, end, &len2,
bryantaylor 0:eafc3fd41f75 217 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
bryantaylor 0:eafc3fd41f75 218 {
bryantaylor 0:eafc3fd41f75 219 return( ret );
bryantaylor 0:eafc3fd41f75 220 }
bryantaylor 0:eafc3fd41f75 221
bryantaylor 0:eafc3fd41f75 222 cur_entry->raw.tag = **p;
bryantaylor 0:eafc3fd41f75 223 cur_entry->raw.p = *p;
bryantaylor 0:eafc3fd41f75 224 cur_entry->raw.len = len2;
bryantaylor 0:eafc3fd41f75 225 end2 = *p + len2;
bryantaylor 0:eafc3fd41f75 226
bryantaylor 0:eafc3fd41f75 227 if( ( ret = mbedtls_x509_get_serial( p, end2, &cur_entry->serial ) ) != 0 )
bryantaylor 0:eafc3fd41f75 228 return( ret );
bryantaylor 0:eafc3fd41f75 229
bryantaylor 0:eafc3fd41f75 230 if( ( ret = mbedtls_x509_get_time( p, end2,
bryantaylor 0:eafc3fd41f75 231 &cur_entry->revocation_date ) ) != 0 )
bryantaylor 0:eafc3fd41f75 232 return( ret );
bryantaylor 0:eafc3fd41f75 233
bryantaylor 0:eafc3fd41f75 234 if( ( ret = x509_get_crl_entry_ext( p, end2,
bryantaylor 0:eafc3fd41f75 235 &cur_entry->entry_ext ) ) != 0 )
bryantaylor 0:eafc3fd41f75 236 return( ret );
bryantaylor 0:eafc3fd41f75 237
bryantaylor 0:eafc3fd41f75 238 if( *p < end )
bryantaylor 0:eafc3fd41f75 239 {
bryantaylor 0:eafc3fd41f75 240 cur_entry->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl_entry ) );
bryantaylor 0:eafc3fd41f75 241
bryantaylor 0:eafc3fd41f75 242 if( cur_entry->next == NULL )
bryantaylor 0:eafc3fd41f75 243 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
bryantaylor 0:eafc3fd41f75 244
bryantaylor 0:eafc3fd41f75 245 cur_entry = cur_entry->next;
bryantaylor 0:eafc3fd41f75 246 }
bryantaylor 0:eafc3fd41f75 247 }
bryantaylor 0:eafc3fd41f75 248
bryantaylor 0:eafc3fd41f75 249 return( 0 );
bryantaylor 0:eafc3fd41f75 250 }
bryantaylor 0:eafc3fd41f75 251
bryantaylor 0:eafc3fd41f75 252 /*
bryantaylor 0:eafc3fd41f75 253 * Parse one CRLs in DER format and append it to the chained list
bryantaylor 0:eafc3fd41f75 254 */
bryantaylor 0:eafc3fd41f75 255 int mbedtls_x509_crl_parse_der( mbedtls_x509_crl *chain,
bryantaylor 0:eafc3fd41f75 256 const unsigned char *buf, size_t buflen )
bryantaylor 0:eafc3fd41f75 257 {
bryantaylor 0:eafc3fd41f75 258 int ret;
bryantaylor 0:eafc3fd41f75 259 size_t len;
bryantaylor 0:eafc3fd41f75 260 unsigned char *p, *end;
bryantaylor 0:eafc3fd41f75 261 mbedtls_x509_buf sig_params1, sig_params2, sig_oid2;
bryantaylor 0:eafc3fd41f75 262 mbedtls_x509_crl *crl = chain;
bryantaylor 0:eafc3fd41f75 263
bryantaylor 0:eafc3fd41f75 264 /*
bryantaylor 0:eafc3fd41f75 265 * Check for valid input
bryantaylor 0:eafc3fd41f75 266 */
bryantaylor 0:eafc3fd41f75 267 if( crl == NULL || buf == NULL )
bryantaylor 0:eafc3fd41f75 268 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
bryantaylor 0:eafc3fd41f75 269
bryantaylor 0:eafc3fd41f75 270 memset( &sig_params1, 0, sizeof( mbedtls_x509_buf ) );
bryantaylor 0:eafc3fd41f75 271 memset( &sig_params2, 0, sizeof( mbedtls_x509_buf ) );
bryantaylor 0:eafc3fd41f75 272 memset( &sig_oid2, 0, sizeof( mbedtls_x509_buf ) );
bryantaylor 0:eafc3fd41f75 273
bryantaylor 0:eafc3fd41f75 274 /*
bryantaylor 0:eafc3fd41f75 275 * Add new CRL on the end of the chain if needed.
bryantaylor 0:eafc3fd41f75 276 */
bryantaylor 0:eafc3fd41f75 277 while( crl->version != 0 && crl->next != NULL )
bryantaylor 0:eafc3fd41f75 278 crl = crl->next;
bryantaylor 0:eafc3fd41f75 279
bryantaylor 0:eafc3fd41f75 280 if( crl->version != 0 && crl->next == NULL )
bryantaylor 0:eafc3fd41f75 281 {
bryantaylor 0:eafc3fd41f75 282 crl->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl ) );
bryantaylor 0:eafc3fd41f75 283
bryantaylor 0:eafc3fd41f75 284 if( crl->next == NULL )
bryantaylor 0:eafc3fd41f75 285 {
bryantaylor 0:eafc3fd41f75 286 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 287 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
bryantaylor 0:eafc3fd41f75 288 }
bryantaylor 0:eafc3fd41f75 289
bryantaylor 0:eafc3fd41f75 290 mbedtls_x509_crl_init( crl->next );
bryantaylor 0:eafc3fd41f75 291 crl = crl->next;
bryantaylor 0:eafc3fd41f75 292 }
bryantaylor 0:eafc3fd41f75 293
bryantaylor 0:eafc3fd41f75 294 /*
bryantaylor 0:eafc3fd41f75 295 * Copy raw DER-encoded CRL
bryantaylor 0:eafc3fd41f75 296 */
bryantaylor 0:eafc3fd41f75 297 if( ( p = mbedtls_calloc( 1, buflen ) ) == NULL )
bryantaylor 0:eafc3fd41f75 298 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
bryantaylor 0:eafc3fd41f75 299
bryantaylor 0:eafc3fd41f75 300 memcpy( p, buf, buflen );
bryantaylor 0:eafc3fd41f75 301
bryantaylor 0:eafc3fd41f75 302 crl->raw.p = p;
bryantaylor 0:eafc3fd41f75 303 crl->raw.len = buflen;
bryantaylor 0:eafc3fd41f75 304
bryantaylor 0:eafc3fd41f75 305 end = p + buflen;
bryantaylor 0:eafc3fd41f75 306
bryantaylor 0:eafc3fd41f75 307 /*
bryantaylor 0:eafc3fd41f75 308 * CertificateList ::= SEQUENCE {
bryantaylor 0:eafc3fd41f75 309 * tbsCertList TBSCertList,
bryantaylor 0:eafc3fd41f75 310 * signatureAlgorithm AlgorithmIdentifier,
bryantaylor 0:eafc3fd41f75 311 * signatureValue BIT STRING }
bryantaylor 0:eafc3fd41f75 312 */
bryantaylor 0:eafc3fd41f75 313 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
bryantaylor 0:eafc3fd41f75 314 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
bryantaylor 0:eafc3fd41f75 315 {
bryantaylor 0:eafc3fd41f75 316 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 317 return( MBEDTLS_ERR_X509_INVALID_FORMAT );
bryantaylor 0:eafc3fd41f75 318 }
bryantaylor 0:eafc3fd41f75 319
bryantaylor 0:eafc3fd41f75 320 if( len != (size_t) ( end - p ) )
bryantaylor 0:eafc3fd41f75 321 {
bryantaylor 0:eafc3fd41f75 322 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 323 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
bryantaylor 0:eafc3fd41f75 324 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
bryantaylor 0:eafc3fd41f75 325 }
bryantaylor 0:eafc3fd41f75 326
bryantaylor 0:eafc3fd41f75 327 /*
bryantaylor 0:eafc3fd41f75 328 * TBSCertList ::= SEQUENCE {
bryantaylor 0:eafc3fd41f75 329 */
bryantaylor 0:eafc3fd41f75 330 crl->tbs.p = p;
bryantaylor 0:eafc3fd41f75 331
bryantaylor 0:eafc3fd41f75 332 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
bryantaylor 0:eafc3fd41f75 333 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
bryantaylor 0:eafc3fd41f75 334 {
bryantaylor 0:eafc3fd41f75 335 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 336 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
bryantaylor 0:eafc3fd41f75 337 }
bryantaylor 0:eafc3fd41f75 338
bryantaylor 0:eafc3fd41f75 339 end = p + len;
bryantaylor 0:eafc3fd41f75 340 crl->tbs.len = end - crl->tbs.p;
bryantaylor 0:eafc3fd41f75 341
bryantaylor 0:eafc3fd41f75 342 /*
bryantaylor 0:eafc3fd41f75 343 * Version ::= INTEGER OPTIONAL { v1(0), v2(1) }
bryantaylor 0:eafc3fd41f75 344 * -- if present, MUST be v2
bryantaylor 0:eafc3fd41f75 345 *
bryantaylor 0:eafc3fd41f75 346 * signature AlgorithmIdentifier
bryantaylor 0:eafc3fd41f75 347 */
bryantaylor 0:eafc3fd41f75 348 if( ( ret = x509_crl_get_version( &p, end, &crl->version ) ) != 0 ||
bryantaylor 0:eafc3fd41f75 349 ( ret = mbedtls_x509_get_alg( &p, end, &crl->sig_oid, &sig_params1 ) ) != 0 )
bryantaylor 0:eafc3fd41f75 350 {
bryantaylor 0:eafc3fd41f75 351 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 352 return( ret );
bryantaylor 0:eafc3fd41f75 353 }
bryantaylor 0:eafc3fd41f75 354
bryantaylor 0:eafc3fd41f75 355 crl->version++;
bryantaylor 0:eafc3fd41f75 356
bryantaylor 0:eafc3fd41f75 357 if( crl->version > 2 )
bryantaylor 0:eafc3fd41f75 358 {
bryantaylor 0:eafc3fd41f75 359 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 360 return( MBEDTLS_ERR_X509_UNKNOWN_VERSION );
bryantaylor 0:eafc3fd41f75 361 }
bryantaylor 0:eafc3fd41f75 362
bryantaylor 0:eafc3fd41f75 363 if( ( ret = mbedtls_x509_get_sig_alg( &crl->sig_oid, &sig_params1,
bryantaylor 0:eafc3fd41f75 364 &crl->sig_md, &crl->sig_pk,
bryantaylor 0:eafc3fd41f75 365 &crl->sig_opts ) ) != 0 )
bryantaylor 0:eafc3fd41f75 366 {
bryantaylor 0:eafc3fd41f75 367 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 368 return( MBEDTLS_ERR_X509_UNKNOWN_SIG_ALG );
bryantaylor 0:eafc3fd41f75 369 }
bryantaylor 0:eafc3fd41f75 370
bryantaylor 0:eafc3fd41f75 371 /*
bryantaylor 0:eafc3fd41f75 372 * issuer Name
bryantaylor 0:eafc3fd41f75 373 */
bryantaylor 0:eafc3fd41f75 374 crl->issuer_raw.p = p;
bryantaylor 0:eafc3fd41f75 375
bryantaylor 0:eafc3fd41f75 376 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
bryantaylor 0:eafc3fd41f75 377 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
bryantaylor 0:eafc3fd41f75 378 {
bryantaylor 0:eafc3fd41f75 379 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 380 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
bryantaylor 0:eafc3fd41f75 381 }
bryantaylor 0:eafc3fd41f75 382
bryantaylor 0:eafc3fd41f75 383 if( ( ret = mbedtls_x509_get_name( &p, p + len, &crl->issuer ) ) != 0 )
bryantaylor 0:eafc3fd41f75 384 {
bryantaylor 0:eafc3fd41f75 385 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 386 return( ret );
bryantaylor 0:eafc3fd41f75 387 }
bryantaylor 0:eafc3fd41f75 388
bryantaylor 0:eafc3fd41f75 389 crl->issuer_raw.len = p - crl->issuer_raw.p;
bryantaylor 0:eafc3fd41f75 390
bryantaylor 0:eafc3fd41f75 391 /*
bryantaylor 0:eafc3fd41f75 392 * thisUpdate Time
bryantaylor 0:eafc3fd41f75 393 * nextUpdate Time OPTIONAL
bryantaylor 0:eafc3fd41f75 394 */
bryantaylor 0:eafc3fd41f75 395 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->this_update ) ) != 0 )
bryantaylor 0:eafc3fd41f75 396 {
bryantaylor 0:eafc3fd41f75 397 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 398 return( ret );
bryantaylor 0:eafc3fd41f75 399 }
bryantaylor 0:eafc3fd41f75 400
bryantaylor 0:eafc3fd41f75 401 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->next_update ) ) != 0 )
bryantaylor 0:eafc3fd41f75 402 {
bryantaylor 0:eafc3fd41f75 403 if( ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
bryantaylor 0:eafc3fd41f75 404 MBEDTLS_ERR_ASN1_UNEXPECTED_TAG ) &&
bryantaylor 0:eafc3fd41f75 405 ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
bryantaylor 0:eafc3fd41f75 406 MBEDTLS_ERR_ASN1_OUT_OF_DATA ) )
bryantaylor 0:eafc3fd41f75 407 {
bryantaylor 0:eafc3fd41f75 408 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 409 return( ret );
bryantaylor 0:eafc3fd41f75 410 }
bryantaylor 0:eafc3fd41f75 411 }
bryantaylor 0:eafc3fd41f75 412
bryantaylor 0:eafc3fd41f75 413 /*
bryantaylor 0:eafc3fd41f75 414 * revokedCertificates SEQUENCE OF SEQUENCE {
bryantaylor 0:eafc3fd41f75 415 * userCertificate CertificateSerialNumber,
bryantaylor 0:eafc3fd41f75 416 * revocationDate Time,
bryantaylor 0:eafc3fd41f75 417 * crlEntryExtensions Extensions OPTIONAL
bryantaylor 0:eafc3fd41f75 418 * -- if present, MUST be v2
bryantaylor 0:eafc3fd41f75 419 * } OPTIONAL
bryantaylor 0:eafc3fd41f75 420 */
bryantaylor 0:eafc3fd41f75 421 if( ( ret = x509_get_entries( &p, end, &crl->entry ) ) != 0 )
bryantaylor 0:eafc3fd41f75 422 {
bryantaylor 0:eafc3fd41f75 423 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 424 return( ret );
bryantaylor 0:eafc3fd41f75 425 }
bryantaylor 0:eafc3fd41f75 426
bryantaylor 0:eafc3fd41f75 427 /*
bryantaylor 0:eafc3fd41f75 428 * crlExtensions EXPLICIT Extensions OPTIONAL
bryantaylor 0:eafc3fd41f75 429 * -- if present, MUST be v2
bryantaylor 0:eafc3fd41f75 430 */
bryantaylor 0:eafc3fd41f75 431 if( crl->version == 2 )
bryantaylor 0:eafc3fd41f75 432 {
bryantaylor 0:eafc3fd41f75 433 ret = x509_get_crl_ext( &p, end, &crl->crl_ext );
bryantaylor 0:eafc3fd41f75 434
bryantaylor 0:eafc3fd41f75 435 if( ret != 0 )
bryantaylor 0:eafc3fd41f75 436 {
bryantaylor 0:eafc3fd41f75 437 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 438 return( ret );
bryantaylor 0:eafc3fd41f75 439 }
bryantaylor 0:eafc3fd41f75 440 }
bryantaylor 0:eafc3fd41f75 441
bryantaylor 0:eafc3fd41f75 442 if( p != end )
bryantaylor 0:eafc3fd41f75 443 {
bryantaylor 0:eafc3fd41f75 444 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 445 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
bryantaylor 0:eafc3fd41f75 446 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
bryantaylor 0:eafc3fd41f75 447 }
bryantaylor 0:eafc3fd41f75 448
bryantaylor 0:eafc3fd41f75 449 end = crl->raw.p + crl->raw.len;
bryantaylor 0:eafc3fd41f75 450
bryantaylor 0:eafc3fd41f75 451 /*
bryantaylor 0:eafc3fd41f75 452 * signatureAlgorithm AlgorithmIdentifier,
bryantaylor 0:eafc3fd41f75 453 * signatureValue BIT STRING
bryantaylor 0:eafc3fd41f75 454 */
bryantaylor 0:eafc3fd41f75 455 if( ( ret = mbedtls_x509_get_alg( &p, end, &sig_oid2, &sig_params2 ) ) != 0 )
bryantaylor 0:eafc3fd41f75 456 {
bryantaylor 0:eafc3fd41f75 457 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 458 return( ret );
bryantaylor 0:eafc3fd41f75 459 }
bryantaylor 0:eafc3fd41f75 460
bryantaylor 0:eafc3fd41f75 461 if( crl->sig_oid.len != sig_oid2.len ||
bryantaylor 0:eafc3fd41f75 462 memcmp( crl->sig_oid.p, sig_oid2.p, crl->sig_oid.len ) != 0 ||
bryantaylor 0:eafc3fd41f75 463 sig_params1.len != sig_params2.len ||
bryantaylor 0:eafc3fd41f75 464 ( sig_params1.len != 0 &&
bryantaylor 0:eafc3fd41f75 465 memcmp( sig_params1.p, sig_params2.p, sig_params1.len ) != 0 ) )
bryantaylor 0:eafc3fd41f75 466 {
bryantaylor 0:eafc3fd41f75 467 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 468 return( MBEDTLS_ERR_X509_SIG_MISMATCH );
bryantaylor 0:eafc3fd41f75 469 }
bryantaylor 0:eafc3fd41f75 470
bryantaylor 0:eafc3fd41f75 471 if( ( ret = mbedtls_x509_get_sig( &p, end, &crl->sig ) ) != 0 )
bryantaylor 0:eafc3fd41f75 472 {
bryantaylor 0:eafc3fd41f75 473 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 474 return( ret );
bryantaylor 0:eafc3fd41f75 475 }
bryantaylor 0:eafc3fd41f75 476
bryantaylor 0:eafc3fd41f75 477 if( p != end )
bryantaylor 0:eafc3fd41f75 478 {
bryantaylor 0:eafc3fd41f75 479 mbedtls_x509_crl_free( crl );
bryantaylor 0:eafc3fd41f75 480 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
bryantaylor 0:eafc3fd41f75 481 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
bryantaylor 0:eafc3fd41f75 482 }
bryantaylor 0:eafc3fd41f75 483
bryantaylor 0:eafc3fd41f75 484 return( 0 );
bryantaylor 0:eafc3fd41f75 485 }
bryantaylor 0:eafc3fd41f75 486
bryantaylor 0:eafc3fd41f75 487 /*
bryantaylor 0:eafc3fd41f75 488 * Parse one or more CRLs and add them to the chained list
bryantaylor 0:eafc3fd41f75 489 */
bryantaylor 0:eafc3fd41f75 490 int mbedtls_x509_crl_parse( mbedtls_x509_crl *chain, const unsigned char *buf, size_t buflen )
bryantaylor 0:eafc3fd41f75 491 {
bryantaylor 0:eafc3fd41f75 492 #if defined(MBEDTLS_PEM_PARSE_C)
bryantaylor 0:eafc3fd41f75 493 int ret;
bryantaylor 0:eafc3fd41f75 494 size_t use_len;
bryantaylor 0:eafc3fd41f75 495 mbedtls_pem_context pem;
bryantaylor 0:eafc3fd41f75 496 int is_pem = 0;
bryantaylor 0:eafc3fd41f75 497
bryantaylor 0:eafc3fd41f75 498 if( chain == NULL || buf == NULL )
bryantaylor 0:eafc3fd41f75 499 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
bryantaylor 0:eafc3fd41f75 500
bryantaylor 0:eafc3fd41f75 501 do
bryantaylor 0:eafc3fd41f75 502 {
bryantaylor 0:eafc3fd41f75 503 mbedtls_pem_init( &pem );
bryantaylor 0:eafc3fd41f75 504
bryantaylor 0:eafc3fd41f75 505 // Avoid calling mbedtls_pem_read_buffer() on non-null-terminated
bryantaylor 0:eafc3fd41f75 506 // string
bryantaylor 0:eafc3fd41f75 507 if( buflen == 0 || buf[buflen - 1] != '\0' )
bryantaylor 0:eafc3fd41f75 508 ret = MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT;
bryantaylor 0:eafc3fd41f75 509 else
bryantaylor 0:eafc3fd41f75 510 ret = mbedtls_pem_read_buffer( &pem,
bryantaylor 0:eafc3fd41f75 511 "-----BEGIN X509 CRL-----",
bryantaylor 0:eafc3fd41f75 512 "-----END X509 CRL-----",
bryantaylor 0:eafc3fd41f75 513 buf, NULL, 0, &use_len );
bryantaylor 0:eafc3fd41f75 514
bryantaylor 0:eafc3fd41f75 515 if( ret == 0 )
bryantaylor 0:eafc3fd41f75 516 {
bryantaylor 0:eafc3fd41f75 517 /*
bryantaylor 0:eafc3fd41f75 518 * Was PEM encoded
bryantaylor 0:eafc3fd41f75 519 */
bryantaylor 0:eafc3fd41f75 520 is_pem = 1;
bryantaylor 0:eafc3fd41f75 521
bryantaylor 0:eafc3fd41f75 522 buflen -= use_len;
bryantaylor 0:eafc3fd41f75 523 buf += use_len;
bryantaylor 0:eafc3fd41f75 524
bryantaylor 0:eafc3fd41f75 525 if( ( ret = mbedtls_x509_crl_parse_der( chain,
bryantaylor 0:eafc3fd41f75 526 pem.buf, pem.buflen ) ) != 0 )
bryantaylor 0:eafc3fd41f75 527 {
bryantaylor 0:eafc3fd41f75 528 return( ret );
bryantaylor 0:eafc3fd41f75 529 }
bryantaylor 0:eafc3fd41f75 530
bryantaylor 0:eafc3fd41f75 531 mbedtls_pem_free( &pem );
bryantaylor 0:eafc3fd41f75 532 }
bryantaylor 0:eafc3fd41f75 533 else if( ret != MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT )
bryantaylor 0:eafc3fd41f75 534 {
bryantaylor 0:eafc3fd41f75 535 mbedtls_pem_free( &pem );
bryantaylor 0:eafc3fd41f75 536 return( ret );
bryantaylor 0:eafc3fd41f75 537 }
bryantaylor 0:eafc3fd41f75 538 }
bryantaylor 0:eafc3fd41f75 539 /* In the PEM case, buflen is 1 at the end, for the terminated NULL byte.
bryantaylor 0:eafc3fd41f75 540 * And a valid CRL cannot be less than 1 byte anyway. */
bryantaylor 0:eafc3fd41f75 541 while( is_pem && buflen > 1 );
bryantaylor 0:eafc3fd41f75 542
bryantaylor 0:eafc3fd41f75 543 if( is_pem )
bryantaylor 0:eafc3fd41f75 544 return( 0 );
bryantaylor 0:eafc3fd41f75 545 else
bryantaylor 0:eafc3fd41f75 546 #endif /* MBEDTLS_PEM_PARSE_C */
bryantaylor 0:eafc3fd41f75 547 return( mbedtls_x509_crl_parse_der( chain, buf, buflen ) );
bryantaylor 0:eafc3fd41f75 548 }
bryantaylor 0:eafc3fd41f75 549
bryantaylor 0:eafc3fd41f75 550 #if defined(MBEDTLS_FS_IO)
bryantaylor 0:eafc3fd41f75 551 /*
bryantaylor 0:eafc3fd41f75 552 * Load one or more CRLs and add them to the chained list
bryantaylor 0:eafc3fd41f75 553 */
bryantaylor 0:eafc3fd41f75 554 int mbedtls_x509_crl_parse_file( mbedtls_x509_crl *chain, const char *path )
bryantaylor 0:eafc3fd41f75 555 {
bryantaylor 0:eafc3fd41f75 556 int ret;
bryantaylor 0:eafc3fd41f75 557 size_t n;
bryantaylor 0:eafc3fd41f75 558 unsigned char *buf;
bryantaylor 0:eafc3fd41f75 559
bryantaylor 0:eafc3fd41f75 560 if( ( ret = mbedtls_pk_load_file( path, &buf, &n ) ) != 0 )
bryantaylor 0:eafc3fd41f75 561 return( ret );
bryantaylor 0:eafc3fd41f75 562
bryantaylor 0:eafc3fd41f75 563 ret = mbedtls_x509_crl_parse( chain, buf, n );
bryantaylor 0:eafc3fd41f75 564
bryantaylor 0:eafc3fd41f75 565 mbedtls_zeroize( buf, n );
bryantaylor 0:eafc3fd41f75 566 mbedtls_free( buf );
bryantaylor 0:eafc3fd41f75 567
bryantaylor 0:eafc3fd41f75 568 return( ret );
bryantaylor 0:eafc3fd41f75 569 }
bryantaylor 0:eafc3fd41f75 570 #endif /* MBEDTLS_FS_IO */
bryantaylor 0:eafc3fd41f75 571
bryantaylor 0:eafc3fd41f75 572 /*
bryantaylor 0:eafc3fd41f75 573 * Return an informational string about the certificate.
bryantaylor 0:eafc3fd41f75 574 */
bryantaylor 0:eafc3fd41f75 575 #define BEFORE_COLON 14
bryantaylor 0:eafc3fd41f75 576 #define BC "14"
bryantaylor 0:eafc3fd41f75 577 /*
bryantaylor 0:eafc3fd41f75 578 * Return an informational string about the CRL.
bryantaylor 0:eafc3fd41f75 579 */
bryantaylor 0:eafc3fd41f75 580 int mbedtls_x509_crl_info( char *buf, size_t size, const char *prefix,
bryantaylor 0:eafc3fd41f75 581 const mbedtls_x509_crl *crl )
bryantaylor 0:eafc3fd41f75 582 {
bryantaylor 0:eafc3fd41f75 583 int ret;
bryantaylor 0:eafc3fd41f75 584 size_t n;
bryantaylor 0:eafc3fd41f75 585 char *p;
bryantaylor 0:eafc3fd41f75 586 const mbedtls_x509_crl_entry *entry;
bryantaylor 0:eafc3fd41f75 587
bryantaylor 0:eafc3fd41f75 588 p = buf;
bryantaylor 0:eafc3fd41f75 589 n = size;
bryantaylor 0:eafc3fd41f75 590
bryantaylor 0:eafc3fd41f75 591 ret = mbedtls_snprintf( p, n, "%sCRL version : %d",
bryantaylor 0:eafc3fd41f75 592 prefix, crl->version );
bryantaylor 0:eafc3fd41f75 593 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 594
bryantaylor 0:eafc3fd41f75 595 ret = mbedtls_snprintf( p, n, "\n%sissuer name : ", prefix );
bryantaylor 0:eafc3fd41f75 596 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 597 ret = mbedtls_x509_dn_gets( p, n, &crl->issuer );
bryantaylor 0:eafc3fd41f75 598 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 599
bryantaylor 0:eafc3fd41f75 600 ret = mbedtls_snprintf( p, n, "\n%sthis update : " \
bryantaylor 0:eafc3fd41f75 601 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
bryantaylor 0:eafc3fd41f75 602 crl->this_update.year, crl->this_update.mon,
bryantaylor 0:eafc3fd41f75 603 crl->this_update.day, crl->this_update.hour,
bryantaylor 0:eafc3fd41f75 604 crl->this_update.min, crl->this_update.sec );
bryantaylor 0:eafc3fd41f75 605 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 606
bryantaylor 0:eafc3fd41f75 607 ret = mbedtls_snprintf( p, n, "\n%snext update : " \
bryantaylor 0:eafc3fd41f75 608 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
bryantaylor 0:eafc3fd41f75 609 crl->next_update.year, crl->next_update.mon,
bryantaylor 0:eafc3fd41f75 610 crl->next_update.day, crl->next_update.hour,
bryantaylor 0:eafc3fd41f75 611 crl->next_update.min, crl->next_update.sec );
bryantaylor 0:eafc3fd41f75 612 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 613
bryantaylor 0:eafc3fd41f75 614 entry = &crl->entry;
bryantaylor 0:eafc3fd41f75 615
bryantaylor 0:eafc3fd41f75 616 ret = mbedtls_snprintf( p, n, "\n%sRevoked certificates:",
bryantaylor 0:eafc3fd41f75 617 prefix );
bryantaylor 0:eafc3fd41f75 618 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 619
bryantaylor 0:eafc3fd41f75 620 while( entry != NULL && entry->raw.len != 0 )
bryantaylor 0:eafc3fd41f75 621 {
bryantaylor 0:eafc3fd41f75 622 ret = mbedtls_snprintf( p, n, "\n%sserial number: ",
bryantaylor 0:eafc3fd41f75 623 prefix );
bryantaylor 0:eafc3fd41f75 624 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 625
bryantaylor 0:eafc3fd41f75 626 ret = mbedtls_x509_serial_gets( p, n, &entry->serial );
bryantaylor 0:eafc3fd41f75 627 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 628
bryantaylor 0:eafc3fd41f75 629 ret = mbedtls_snprintf( p, n, " revocation date: " \
bryantaylor 0:eafc3fd41f75 630 "%04d-%02d-%02d %02d:%02d:%02d",
bryantaylor 0:eafc3fd41f75 631 entry->revocation_date.year, entry->revocation_date.mon,
bryantaylor 0:eafc3fd41f75 632 entry->revocation_date.day, entry->revocation_date.hour,
bryantaylor 0:eafc3fd41f75 633 entry->revocation_date.min, entry->revocation_date.sec );
bryantaylor 0:eafc3fd41f75 634 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 635
bryantaylor 0:eafc3fd41f75 636 entry = entry->next;
bryantaylor 0:eafc3fd41f75 637 }
bryantaylor 0:eafc3fd41f75 638
bryantaylor 0:eafc3fd41f75 639 ret = mbedtls_snprintf( p, n, "\n%ssigned using : ", prefix );
bryantaylor 0:eafc3fd41f75 640 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 641
bryantaylor 0:eafc3fd41f75 642 ret = mbedtls_x509_sig_alg_gets( p, n, &crl->sig_oid, crl->sig_pk, crl->sig_md,
bryantaylor 0:eafc3fd41f75 643 crl->sig_opts );
bryantaylor 0:eafc3fd41f75 644 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 645
bryantaylor 0:eafc3fd41f75 646 ret = mbedtls_snprintf( p, n, "\n" );
bryantaylor 0:eafc3fd41f75 647 MBEDTLS_X509_SAFE_SNPRINTF;
bryantaylor 0:eafc3fd41f75 648
bryantaylor 0:eafc3fd41f75 649 return( (int) ( size - n ) );
bryantaylor 0:eafc3fd41f75 650 }
bryantaylor 0:eafc3fd41f75 651
bryantaylor 0:eafc3fd41f75 652 /*
bryantaylor 0:eafc3fd41f75 653 * Initialize a CRL chain
bryantaylor 0:eafc3fd41f75 654 */
bryantaylor 0:eafc3fd41f75 655 void mbedtls_x509_crl_init( mbedtls_x509_crl *crl )
bryantaylor 0:eafc3fd41f75 656 {
bryantaylor 0:eafc3fd41f75 657 memset( crl, 0, sizeof(mbedtls_x509_crl) );
bryantaylor 0:eafc3fd41f75 658 }
bryantaylor 0:eafc3fd41f75 659
bryantaylor 0:eafc3fd41f75 660 /*
bryantaylor 0:eafc3fd41f75 661 * Unallocate all CRL data
bryantaylor 0:eafc3fd41f75 662 */
bryantaylor 0:eafc3fd41f75 663 void mbedtls_x509_crl_free( mbedtls_x509_crl *crl )
bryantaylor 0:eafc3fd41f75 664 {
bryantaylor 0:eafc3fd41f75 665 mbedtls_x509_crl *crl_cur = crl;
bryantaylor 0:eafc3fd41f75 666 mbedtls_x509_crl *crl_prv;
bryantaylor 0:eafc3fd41f75 667 mbedtls_x509_name *name_cur;
bryantaylor 0:eafc3fd41f75 668 mbedtls_x509_name *name_prv;
bryantaylor 0:eafc3fd41f75 669 mbedtls_x509_crl_entry *entry_cur;
bryantaylor 0:eafc3fd41f75 670 mbedtls_x509_crl_entry *entry_prv;
bryantaylor 0:eafc3fd41f75 671
bryantaylor 0:eafc3fd41f75 672 if( crl == NULL )
bryantaylor 0:eafc3fd41f75 673 return;
bryantaylor 0:eafc3fd41f75 674
bryantaylor 0:eafc3fd41f75 675 do
bryantaylor 0:eafc3fd41f75 676 {
bryantaylor 0:eafc3fd41f75 677 #if defined(MBEDTLS_X509_RSASSA_PSS_SUPPORT)
bryantaylor 0:eafc3fd41f75 678 mbedtls_free( crl_cur->sig_opts );
bryantaylor 0:eafc3fd41f75 679 #endif
bryantaylor 0:eafc3fd41f75 680
bryantaylor 0:eafc3fd41f75 681 name_cur = crl_cur->issuer.next;
bryantaylor 0:eafc3fd41f75 682 while( name_cur != NULL )
bryantaylor 0:eafc3fd41f75 683 {
bryantaylor 0:eafc3fd41f75 684 name_prv = name_cur;
bryantaylor 0:eafc3fd41f75 685 name_cur = name_cur->next;
bryantaylor 0:eafc3fd41f75 686 mbedtls_zeroize( name_prv, sizeof( mbedtls_x509_name ) );
bryantaylor 0:eafc3fd41f75 687 mbedtls_free( name_prv );
bryantaylor 0:eafc3fd41f75 688 }
bryantaylor 0:eafc3fd41f75 689
bryantaylor 0:eafc3fd41f75 690 entry_cur = crl_cur->entry.next;
bryantaylor 0:eafc3fd41f75 691 while( entry_cur != NULL )
bryantaylor 0:eafc3fd41f75 692 {
bryantaylor 0:eafc3fd41f75 693 entry_prv = entry_cur;
bryantaylor 0:eafc3fd41f75 694 entry_cur = entry_cur->next;
bryantaylor 0:eafc3fd41f75 695 mbedtls_zeroize( entry_prv, sizeof( mbedtls_x509_crl_entry ) );
bryantaylor 0:eafc3fd41f75 696 mbedtls_free( entry_prv );
bryantaylor 0:eafc3fd41f75 697 }
bryantaylor 0:eafc3fd41f75 698
bryantaylor 0:eafc3fd41f75 699 if( crl_cur->raw.p != NULL )
bryantaylor 0:eafc3fd41f75 700 {
bryantaylor 0:eafc3fd41f75 701 mbedtls_zeroize( crl_cur->raw.p, crl_cur->raw.len );
bryantaylor 0:eafc3fd41f75 702 mbedtls_free( crl_cur->raw.p );
bryantaylor 0:eafc3fd41f75 703 }
bryantaylor 0:eafc3fd41f75 704
bryantaylor 0:eafc3fd41f75 705 crl_cur = crl_cur->next;
bryantaylor 0:eafc3fd41f75 706 }
bryantaylor 0:eafc3fd41f75 707 while( crl_cur != NULL );
bryantaylor 0:eafc3fd41f75 708
bryantaylor 0:eafc3fd41f75 709 crl_cur = crl;
bryantaylor 0:eafc3fd41f75 710 do
bryantaylor 0:eafc3fd41f75 711 {
bryantaylor 0:eafc3fd41f75 712 crl_prv = crl_cur;
bryantaylor 0:eafc3fd41f75 713 crl_cur = crl_cur->next;
bryantaylor 0:eafc3fd41f75 714
bryantaylor 0:eafc3fd41f75 715 mbedtls_zeroize( crl_prv, sizeof( mbedtls_x509_crl ) );
bryantaylor 0:eafc3fd41f75 716 if( crl_prv != crl )
bryantaylor 0:eafc3fd41f75 717 mbedtls_free( crl_prv );
bryantaylor 0:eafc3fd41f75 718 }
bryantaylor 0:eafc3fd41f75 719 while( crl_cur != NULL );
bryantaylor 0:eafc3fd41f75 720 }
bryantaylor 0:eafc3fd41f75 721
bryantaylor 0:eafc3fd41f75 722 #endif /* MBEDTLS_X509_CRL_PARSE_C */