mbed os with nrf51 internal bandgap enabled to read battery level

Dependents:   BLE_file_test BLE_Blink ExternalEncoder

Committer:
elessair
Date:
Sun Oct 23 15:10:02 2016 +0000
Revision:
0:f269e3021894
Initial commit

Who changed what in which revision?

UserRevisionLine numberNew contents of line
elessair 0:f269e3021894 1 /*
elessair 0:f269e3021894 2 * X.509 Certidicate Revocation List (CRL) parsing
elessair 0:f269e3021894 3 *
elessair 0:f269e3021894 4 * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
elessair 0:f269e3021894 5 * SPDX-License-Identifier: Apache-2.0
elessair 0:f269e3021894 6 *
elessair 0:f269e3021894 7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
elessair 0:f269e3021894 8 * not use this file except in compliance with the License.
elessair 0:f269e3021894 9 * You may obtain a copy of the License at
elessair 0:f269e3021894 10 *
elessair 0:f269e3021894 11 * http://www.apache.org/licenses/LICENSE-2.0
elessair 0:f269e3021894 12 *
elessair 0:f269e3021894 13 * Unless required by applicable law or agreed to in writing, software
elessair 0:f269e3021894 14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
elessair 0:f269e3021894 15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
elessair 0:f269e3021894 16 * See the License for the specific language governing permissions and
elessair 0:f269e3021894 17 * limitations under the License.
elessair 0:f269e3021894 18 *
elessair 0:f269e3021894 19 * This file is part of mbed TLS (https://tls.mbed.org)
elessair 0:f269e3021894 20 */
elessair 0:f269e3021894 21 /*
elessair 0:f269e3021894 22 * The ITU-T X.509 standard defines a certificate format for PKI.
elessair 0:f269e3021894 23 *
elessair 0:f269e3021894 24 * http://www.ietf.org/rfc/rfc5280.txt (Certificates and CRLs)
elessair 0:f269e3021894 25 * http://www.ietf.org/rfc/rfc3279.txt (Alg IDs for CRLs)
elessair 0:f269e3021894 26 * http://www.ietf.org/rfc/rfc2986.txt (CSRs, aka PKCS#10)
elessair 0:f269e3021894 27 *
elessair 0:f269e3021894 28 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.680-0207.pdf
elessair 0:f269e3021894 29 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.690-0207.pdf
elessair 0:f269e3021894 30 */
elessair 0:f269e3021894 31
elessair 0:f269e3021894 32 #if !defined(MBEDTLS_CONFIG_FILE)
elessair 0:f269e3021894 33 #include "mbedtls/config.h"
elessair 0:f269e3021894 34 #else
elessair 0:f269e3021894 35 #include MBEDTLS_CONFIG_FILE
elessair 0:f269e3021894 36 #endif
elessair 0:f269e3021894 37
elessair 0:f269e3021894 38 #if defined(MBEDTLS_X509_CRL_PARSE_C)
elessair 0:f269e3021894 39
elessair 0:f269e3021894 40 #include "mbedtls/x509_crl.h"
elessair 0:f269e3021894 41 #include "mbedtls/oid.h"
elessair 0:f269e3021894 42
elessair 0:f269e3021894 43 #include <string.h>
elessair 0:f269e3021894 44
elessair 0:f269e3021894 45 #if defined(MBEDTLS_PEM_PARSE_C)
elessair 0:f269e3021894 46 #include "mbedtls/pem.h"
elessair 0:f269e3021894 47 #endif
elessair 0:f269e3021894 48
elessair 0:f269e3021894 49 #if defined(MBEDTLS_PLATFORM_C)
elessair 0:f269e3021894 50 #include "mbedtls/platform.h"
elessair 0:f269e3021894 51 #else
elessair 0:f269e3021894 52 #include <stdlib.h>
elessair 0:f269e3021894 53 #include <stdio.h>
elessair 0:f269e3021894 54 #define mbedtls_free free
elessair 0:f269e3021894 55 #define mbedtls_calloc calloc
elessair 0:f269e3021894 56 #define mbedtls_snprintf snprintf
elessair 0:f269e3021894 57 #endif
elessair 0:f269e3021894 58
elessair 0:f269e3021894 59 #if defined(_WIN32) && !defined(EFIX64) && !defined(EFI32)
elessair 0:f269e3021894 60 #include <windows.h>
elessair 0:f269e3021894 61 #else
elessair 0:f269e3021894 62 #include <time.h>
elessair 0:f269e3021894 63 #endif
elessair 0:f269e3021894 64
elessair 0:f269e3021894 65 #if defined(MBEDTLS_FS_IO) || defined(EFIX64) || defined(EFI32)
elessair 0:f269e3021894 66 #include <stdio.h>
elessair 0:f269e3021894 67 #endif
elessair 0:f269e3021894 68
elessair 0:f269e3021894 69 /* Implementation that should never be optimized out by the compiler */
elessair 0:f269e3021894 70 static void mbedtls_zeroize( void *v, size_t n ) {
elessair 0:f269e3021894 71 volatile unsigned char *p = v; while( n-- ) *p++ = 0;
elessair 0:f269e3021894 72 }
elessair 0:f269e3021894 73
elessair 0:f269e3021894 74 /*
elessair 0:f269e3021894 75 * Version ::= INTEGER { v1(0), v2(1) }
elessair 0:f269e3021894 76 */
elessair 0:f269e3021894 77 static int x509_crl_get_version( unsigned char **p,
elessair 0:f269e3021894 78 const unsigned char *end,
elessair 0:f269e3021894 79 int *ver )
elessair 0:f269e3021894 80 {
elessair 0:f269e3021894 81 int ret;
elessair 0:f269e3021894 82
elessair 0:f269e3021894 83 if( ( ret = mbedtls_asn1_get_int( p, end, ver ) ) != 0 )
elessair 0:f269e3021894 84 {
elessair 0:f269e3021894 85 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
elessair 0:f269e3021894 86 {
elessair 0:f269e3021894 87 *ver = 0;
elessair 0:f269e3021894 88 return( 0 );
elessair 0:f269e3021894 89 }
elessair 0:f269e3021894 90
elessair 0:f269e3021894 91 return( MBEDTLS_ERR_X509_INVALID_VERSION + ret );
elessair 0:f269e3021894 92 }
elessair 0:f269e3021894 93
elessair 0:f269e3021894 94 return( 0 );
elessair 0:f269e3021894 95 }
elessair 0:f269e3021894 96
elessair 0:f269e3021894 97 /*
elessair 0:f269e3021894 98 * X.509 CRL v2 extensions (no extensions parsed yet.)
elessair 0:f269e3021894 99 */
elessair 0:f269e3021894 100 static int x509_get_crl_ext( unsigned char **p,
elessair 0:f269e3021894 101 const unsigned char *end,
elessair 0:f269e3021894 102 mbedtls_x509_buf *ext )
elessair 0:f269e3021894 103 {
elessair 0:f269e3021894 104 int ret;
elessair 0:f269e3021894 105 size_t len = 0;
elessair 0:f269e3021894 106
elessair 0:f269e3021894 107 /* Get explicit tag */
elessair 0:f269e3021894 108 if( ( ret = mbedtls_x509_get_ext( p, end, ext, 0) ) != 0 )
elessair 0:f269e3021894 109 {
elessair 0:f269e3021894 110 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
elessair 0:f269e3021894 111 return( 0 );
elessair 0:f269e3021894 112
elessair 0:f269e3021894 113 return( ret );
elessair 0:f269e3021894 114 }
elessair 0:f269e3021894 115
elessair 0:f269e3021894 116 while( *p < end )
elessair 0:f269e3021894 117 {
elessair 0:f269e3021894 118 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
elessair 0:f269e3021894 119 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
elessair 0:f269e3021894 120 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
elessair 0:f269e3021894 121
elessair 0:f269e3021894 122 *p += len;
elessair 0:f269e3021894 123 }
elessair 0:f269e3021894 124
elessair 0:f269e3021894 125 if( *p != end )
elessair 0:f269e3021894 126 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
elessair 0:f269e3021894 127 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
elessair 0:f269e3021894 128
elessair 0:f269e3021894 129 return( 0 );
elessair 0:f269e3021894 130 }
elessair 0:f269e3021894 131
elessair 0:f269e3021894 132 /*
elessair 0:f269e3021894 133 * X.509 CRL v2 entry extensions (no extensions parsed yet.)
elessair 0:f269e3021894 134 */
elessair 0:f269e3021894 135 static int x509_get_crl_entry_ext( unsigned char **p,
elessair 0:f269e3021894 136 const unsigned char *end,
elessair 0:f269e3021894 137 mbedtls_x509_buf *ext )
elessair 0:f269e3021894 138 {
elessair 0:f269e3021894 139 int ret;
elessair 0:f269e3021894 140 size_t len = 0;
elessair 0:f269e3021894 141
elessair 0:f269e3021894 142 /* OPTIONAL */
elessair 0:f269e3021894 143 if( end <= *p )
elessair 0:f269e3021894 144 return( 0 );
elessair 0:f269e3021894 145
elessair 0:f269e3021894 146 ext->tag = **p;
elessair 0:f269e3021894 147 ext->p = *p;
elessair 0:f269e3021894 148
elessair 0:f269e3021894 149 /*
elessair 0:f269e3021894 150 * Get CRL-entry extension sequence header
elessair 0:f269e3021894 151 * crlEntryExtensions Extensions OPTIONAL -- if present, MUST be v2
elessair 0:f269e3021894 152 */
elessair 0:f269e3021894 153 if( ( ret = mbedtls_asn1_get_tag( p, end, &ext->len,
elessair 0:f269e3021894 154 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
elessair 0:f269e3021894 155 {
elessair 0:f269e3021894 156 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
elessair 0:f269e3021894 157 {
elessair 0:f269e3021894 158 ext->p = NULL;
elessair 0:f269e3021894 159 return( 0 );
elessair 0:f269e3021894 160 }
elessair 0:f269e3021894 161 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
elessair 0:f269e3021894 162 }
elessair 0:f269e3021894 163
elessair 0:f269e3021894 164 end = *p + ext->len;
elessair 0:f269e3021894 165
elessair 0:f269e3021894 166 if( end != *p + ext->len )
elessair 0:f269e3021894 167 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
elessair 0:f269e3021894 168 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
elessair 0:f269e3021894 169
elessair 0:f269e3021894 170 while( *p < end )
elessair 0:f269e3021894 171 {
elessair 0:f269e3021894 172 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
elessair 0:f269e3021894 173 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
elessair 0:f269e3021894 174 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
elessair 0:f269e3021894 175
elessair 0:f269e3021894 176 *p += len;
elessair 0:f269e3021894 177 }
elessair 0:f269e3021894 178
elessair 0:f269e3021894 179 if( *p != end )
elessair 0:f269e3021894 180 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
elessair 0:f269e3021894 181 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
elessair 0:f269e3021894 182
elessair 0:f269e3021894 183 return( 0 );
elessair 0:f269e3021894 184 }
elessair 0:f269e3021894 185
elessair 0:f269e3021894 186 /*
elessair 0:f269e3021894 187 * X.509 CRL Entries
elessair 0:f269e3021894 188 */
elessair 0:f269e3021894 189 static int x509_get_entries( unsigned char **p,
elessair 0:f269e3021894 190 const unsigned char *end,
elessair 0:f269e3021894 191 mbedtls_x509_crl_entry *entry )
elessair 0:f269e3021894 192 {
elessair 0:f269e3021894 193 int ret;
elessair 0:f269e3021894 194 size_t entry_len;
elessair 0:f269e3021894 195 mbedtls_x509_crl_entry *cur_entry = entry;
elessair 0:f269e3021894 196
elessair 0:f269e3021894 197 if( *p == end )
elessair 0:f269e3021894 198 return( 0 );
elessair 0:f269e3021894 199
elessair 0:f269e3021894 200 if( ( ret = mbedtls_asn1_get_tag( p, end, &entry_len,
elessair 0:f269e3021894 201 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
elessair 0:f269e3021894 202 {
elessair 0:f269e3021894 203 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
elessair 0:f269e3021894 204 return( 0 );
elessair 0:f269e3021894 205
elessair 0:f269e3021894 206 return( ret );
elessair 0:f269e3021894 207 }
elessair 0:f269e3021894 208
elessair 0:f269e3021894 209 end = *p + entry_len;
elessair 0:f269e3021894 210
elessair 0:f269e3021894 211 while( *p < end )
elessair 0:f269e3021894 212 {
elessair 0:f269e3021894 213 size_t len2;
elessair 0:f269e3021894 214 const unsigned char *end2;
elessair 0:f269e3021894 215
elessair 0:f269e3021894 216 if( ( ret = mbedtls_asn1_get_tag( p, end, &len2,
elessair 0:f269e3021894 217 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
elessair 0:f269e3021894 218 {
elessair 0:f269e3021894 219 return( ret );
elessair 0:f269e3021894 220 }
elessair 0:f269e3021894 221
elessair 0:f269e3021894 222 cur_entry->raw.tag = **p;
elessair 0:f269e3021894 223 cur_entry->raw.p = *p;
elessair 0:f269e3021894 224 cur_entry->raw.len = len2;
elessair 0:f269e3021894 225 end2 = *p + len2;
elessair 0:f269e3021894 226
elessair 0:f269e3021894 227 if( ( ret = mbedtls_x509_get_serial( p, end2, &cur_entry->serial ) ) != 0 )
elessair 0:f269e3021894 228 return( ret );
elessair 0:f269e3021894 229
elessair 0:f269e3021894 230 if( ( ret = mbedtls_x509_get_time( p, end2,
elessair 0:f269e3021894 231 &cur_entry->revocation_date ) ) != 0 )
elessair 0:f269e3021894 232 return( ret );
elessair 0:f269e3021894 233
elessair 0:f269e3021894 234 if( ( ret = x509_get_crl_entry_ext( p, end2,
elessair 0:f269e3021894 235 &cur_entry->entry_ext ) ) != 0 )
elessair 0:f269e3021894 236 return( ret );
elessair 0:f269e3021894 237
elessair 0:f269e3021894 238 if( *p < end )
elessair 0:f269e3021894 239 {
elessair 0:f269e3021894 240 cur_entry->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl_entry ) );
elessair 0:f269e3021894 241
elessair 0:f269e3021894 242 if( cur_entry->next == NULL )
elessair 0:f269e3021894 243 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
elessair 0:f269e3021894 244
elessair 0:f269e3021894 245 cur_entry = cur_entry->next;
elessair 0:f269e3021894 246 }
elessair 0:f269e3021894 247 }
elessair 0:f269e3021894 248
elessair 0:f269e3021894 249 return( 0 );
elessair 0:f269e3021894 250 }
elessair 0:f269e3021894 251
elessair 0:f269e3021894 252 /*
elessair 0:f269e3021894 253 * Parse one CRLs in DER format and append it to the chained list
elessair 0:f269e3021894 254 */
elessair 0:f269e3021894 255 int mbedtls_x509_crl_parse_der( mbedtls_x509_crl *chain,
elessair 0:f269e3021894 256 const unsigned char *buf, size_t buflen )
elessair 0:f269e3021894 257 {
elessair 0:f269e3021894 258 int ret;
elessair 0:f269e3021894 259 size_t len;
elessair 0:f269e3021894 260 unsigned char *p, *end;
elessair 0:f269e3021894 261 mbedtls_x509_buf sig_params1, sig_params2, sig_oid2;
elessair 0:f269e3021894 262 mbedtls_x509_crl *crl = chain;
elessair 0:f269e3021894 263
elessair 0:f269e3021894 264 /*
elessair 0:f269e3021894 265 * Check for valid input
elessair 0:f269e3021894 266 */
elessair 0:f269e3021894 267 if( crl == NULL || buf == NULL )
elessair 0:f269e3021894 268 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
elessair 0:f269e3021894 269
elessair 0:f269e3021894 270 memset( &sig_params1, 0, sizeof( mbedtls_x509_buf ) );
elessair 0:f269e3021894 271 memset( &sig_params2, 0, sizeof( mbedtls_x509_buf ) );
elessair 0:f269e3021894 272 memset( &sig_oid2, 0, sizeof( mbedtls_x509_buf ) );
elessair 0:f269e3021894 273
elessair 0:f269e3021894 274 /*
elessair 0:f269e3021894 275 * Add new CRL on the end of the chain if needed.
elessair 0:f269e3021894 276 */
elessair 0:f269e3021894 277 while( crl->version != 0 && crl->next != NULL )
elessair 0:f269e3021894 278 crl = crl->next;
elessair 0:f269e3021894 279
elessair 0:f269e3021894 280 if( crl->version != 0 && crl->next == NULL )
elessair 0:f269e3021894 281 {
elessair 0:f269e3021894 282 crl->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl ) );
elessair 0:f269e3021894 283
elessair 0:f269e3021894 284 if( crl->next == NULL )
elessair 0:f269e3021894 285 {
elessair 0:f269e3021894 286 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 287 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
elessair 0:f269e3021894 288 }
elessair 0:f269e3021894 289
elessair 0:f269e3021894 290 mbedtls_x509_crl_init( crl->next );
elessair 0:f269e3021894 291 crl = crl->next;
elessair 0:f269e3021894 292 }
elessair 0:f269e3021894 293
elessair 0:f269e3021894 294 /*
elessair 0:f269e3021894 295 * Copy raw DER-encoded CRL
elessair 0:f269e3021894 296 */
elessair 0:f269e3021894 297 if( ( p = mbedtls_calloc( 1, buflen ) ) == NULL )
elessair 0:f269e3021894 298 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
elessair 0:f269e3021894 299
elessair 0:f269e3021894 300 memcpy( p, buf, buflen );
elessair 0:f269e3021894 301
elessair 0:f269e3021894 302 crl->raw.p = p;
elessair 0:f269e3021894 303 crl->raw.len = buflen;
elessair 0:f269e3021894 304
elessair 0:f269e3021894 305 end = p + buflen;
elessair 0:f269e3021894 306
elessair 0:f269e3021894 307 /*
elessair 0:f269e3021894 308 * CertificateList ::= SEQUENCE {
elessair 0:f269e3021894 309 * tbsCertList TBSCertList,
elessair 0:f269e3021894 310 * signatureAlgorithm AlgorithmIdentifier,
elessair 0:f269e3021894 311 * signatureValue BIT STRING }
elessair 0:f269e3021894 312 */
elessair 0:f269e3021894 313 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
elessair 0:f269e3021894 314 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
elessair 0:f269e3021894 315 {
elessair 0:f269e3021894 316 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 317 return( MBEDTLS_ERR_X509_INVALID_FORMAT );
elessair 0:f269e3021894 318 }
elessair 0:f269e3021894 319
elessair 0:f269e3021894 320 if( len != (size_t) ( end - p ) )
elessair 0:f269e3021894 321 {
elessair 0:f269e3021894 322 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 323 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
elessair 0:f269e3021894 324 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
elessair 0:f269e3021894 325 }
elessair 0:f269e3021894 326
elessair 0:f269e3021894 327 /*
elessair 0:f269e3021894 328 * TBSCertList ::= SEQUENCE {
elessair 0:f269e3021894 329 */
elessair 0:f269e3021894 330 crl->tbs.p = p;
elessair 0:f269e3021894 331
elessair 0:f269e3021894 332 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
elessair 0:f269e3021894 333 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
elessair 0:f269e3021894 334 {
elessair 0:f269e3021894 335 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 336 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
elessair 0:f269e3021894 337 }
elessair 0:f269e3021894 338
elessair 0:f269e3021894 339 end = p + len;
elessair 0:f269e3021894 340 crl->tbs.len = end - crl->tbs.p;
elessair 0:f269e3021894 341
elessair 0:f269e3021894 342 /*
elessair 0:f269e3021894 343 * Version ::= INTEGER OPTIONAL { v1(0), v2(1) }
elessair 0:f269e3021894 344 * -- if present, MUST be v2
elessair 0:f269e3021894 345 *
elessair 0:f269e3021894 346 * signature AlgorithmIdentifier
elessair 0:f269e3021894 347 */
elessair 0:f269e3021894 348 if( ( ret = x509_crl_get_version( &p, end, &crl->version ) ) != 0 ||
elessair 0:f269e3021894 349 ( ret = mbedtls_x509_get_alg( &p, end, &crl->sig_oid, &sig_params1 ) ) != 0 )
elessair 0:f269e3021894 350 {
elessair 0:f269e3021894 351 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 352 return( ret );
elessair 0:f269e3021894 353 }
elessair 0:f269e3021894 354
elessair 0:f269e3021894 355 crl->version++;
elessair 0:f269e3021894 356
elessair 0:f269e3021894 357 if( crl->version > 2 )
elessair 0:f269e3021894 358 {
elessair 0:f269e3021894 359 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 360 return( MBEDTLS_ERR_X509_UNKNOWN_VERSION );
elessair 0:f269e3021894 361 }
elessair 0:f269e3021894 362
elessair 0:f269e3021894 363 if( ( ret = mbedtls_x509_get_sig_alg( &crl->sig_oid, &sig_params1,
elessair 0:f269e3021894 364 &crl->sig_md, &crl->sig_pk,
elessair 0:f269e3021894 365 &crl->sig_opts ) ) != 0 )
elessair 0:f269e3021894 366 {
elessair 0:f269e3021894 367 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 368 return( MBEDTLS_ERR_X509_UNKNOWN_SIG_ALG );
elessair 0:f269e3021894 369 }
elessair 0:f269e3021894 370
elessair 0:f269e3021894 371 /*
elessair 0:f269e3021894 372 * issuer Name
elessair 0:f269e3021894 373 */
elessair 0:f269e3021894 374 crl->issuer_raw.p = p;
elessair 0:f269e3021894 375
elessair 0:f269e3021894 376 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
elessair 0:f269e3021894 377 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
elessair 0:f269e3021894 378 {
elessair 0:f269e3021894 379 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 380 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
elessair 0:f269e3021894 381 }
elessair 0:f269e3021894 382
elessair 0:f269e3021894 383 if( ( ret = mbedtls_x509_get_name( &p, p + len, &crl->issuer ) ) != 0 )
elessair 0:f269e3021894 384 {
elessair 0:f269e3021894 385 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 386 return( ret );
elessair 0:f269e3021894 387 }
elessair 0:f269e3021894 388
elessair 0:f269e3021894 389 crl->issuer_raw.len = p - crl->issuer_raw.p;
elessair 0:f269e3021894 390
elessair 0:f269e3021894 391 /*
elessair 0:f269e3021894 392 * thisUpdate Time
elessair 0:f269e3021894 393 * nextUpdate Time OPTIONAL
elessair 0:f269e3021894 394 */
elessair 0:f269e3021894 395 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->this_update ) ) != 0 )
elessair 0:f269e3021894 396 {
elessair 0:f269e3021894 397 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 398 return( ret );
elessair 0:f269e3021894 399 }
elessair 0:f269e3021894 400
elessair 0:f269e3021894 401 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->next_update ) ) != 0 )
elessair 0:f269e3021894 402 {
elessair 0:f269e3021894 403 if( ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
elessair 0:f269e3021894 404 MBEDTLS_ERR_ASN1_UNEXPECTED_TAG ) &&
elessair 0:f269e3021894 405 ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
elessair 0:f269e3021894 406 MBEDTLS_ERR_ASN1_OUT_OF_DATA ) )
elessair 0:f269e3021894 407 {
elessair 0:f269e3021894 408 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 409 return( ret );
elessair 0:f269e3021894 410 }
elessair 0:f269e3021894 411 }
elessair 0:f269e3021894 412
elessair 0:f269e3021894 413 /*
elessair 0:f269e3021894 414 * revokedCertificates SEQUENCE OF SEQUENCE {
elessair 0:f269e3021894 415 * userCertificate CertificateSerialNumber,
elessair 0:f269e3021894 416 * revocationDate Time,
elessair 0:f269e3021894 417 * crlEntryExtensions Extensions OPTIONAL
elessair 0:f269e3021894 418 * -- if present, MUST be v2
elessair 0:f269e3021894 419 * } OPTIONAL
elessair 0:f269e3021894 420 */
elessair 0:f269e3021894 421 if( ( ret = x509_get_entries( &p, end, &crl->entry ) ) != 0 )
elessair 0:f269e3021894 422 {
elessair 0:f269e3021894 423 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 424 return( ret );
elessair 0:f269e3021894 425 }
elessair 0:f269e3021894 426
elessair 0:f269e3021894 427 /*
elessair 0:f269e3021894 428 * crlExtensions EXPLICIT Extensions OPTIONAL
elessair 0:f269e3021894 429 * -- if present, MUST be v2
elessair 0:f269e3021894 430 */
elessair 0:f269e3021894 431 if( crl->version == 2 )
elessair 0:f269e3021894 432 {
elessair 0:f269e3021894 433 ret = x509_get_crl_ext( &p, end, &crl->crl_ext );
elessair 0:f269e3021894 434
elessair 0:f269e3021894 435 if( ret != 0 )
elessair 0:f269e3021894 436 {
elessair 0:f269e3021894 437 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 438 return( ret );
elessair 0:f269e3021894 439 }
elessair 0:f269e3021894 440 }
elessair 0:f269e3021894 441
elessair 0:f269e3021894 442 if( p != end )
elessair 0:f269e3021894 443 {
elessair 0:f269e3021894 444 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 445 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
elessair 0:f269e3021894 446 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
elessair 0:f269e3021894 447 }
elessair 0:f269e3021894 448
elessair 0:f269e3021894 449 end = crl->raw.p + crl->raw.len;
elessair 0:f269e3021894 450
elessair 0:f269e3021894 451 /*
elessair 0:f269e3021894 452 * signatureAlgorithm AlgorithmIdentifier,
elessair 0:f269e3021894 453 * signatureValue BIT STRING
elessair 0:f269e3021894 454 */
elessair 0:f269e3021894 455 if( ( ret = mbedtls_x509_get_alg( &p, end, &sig_oid2, &sig_params2 ) ) != 0 )
elessair 0:f269e3021894 456 {
elessair 0:f269e3021894 457 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 458 return( ret );
elessair 0:f269e3021894 459 }
elessair 0:f269e3021894 460
elessair 0:f269e3021894 461 if( crl->sig_oid.len != sig_oid2.len ||
elessair 0:f269e3021894 462 memcmp( crl->sig_oid.p, sig_oid2.p, crl->sig_oid.len ) != 0 ||
elessair 0:f269e3021894 463 sig_params1.len != sig_params2.len ||
elessair 0:f269e3021894 464 ( sig_params1.len != 0 &&
elessair 0:f269e3021894 465 memcmp( sig_params1.p, sig_params2.p, sig_params1.len ) != 0 ) )
elessair 0:f269e3021894 466 {
elessair 0:f269e3021894 467 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 468 return( MBEDTLS_ERR_X509_SIG_MISMATCH );
elessair 0:f269e3021894 469 }
elessair 0:f269e3021894 470
elessair 0:f269e3021894 471 if( ( ret = mbedtls_x509_get_sig( &p, end, &crl->sig ) ) != 0 )
elessair 0:f269e3021894 472 {
elessair 0:f269e3021894 473 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 474 return( ret );
elessair 0:f269e3021894 475 }
elessair 0:f269e3021894 476
elessair 0:f269e3021894 477 if( p != end )
elessair 0:f269e3021894 478 {
elessair 0:f269e3021894 479 mbedtls_x509_crl_free( crl );
elessair 0:f269e3021894 480 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
elessair 0:f269e3021894 481 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
elessair 0:f269e3021894 482 }
elessair 0:f269e3021894 483
elessair 0:f269e3021894 484 return( 0 );
elessair 0:f269e3021894 485 }
elessair 0:f269e3021894 486
elessair 0:f269e3021894 487 /*
elessair 0:f269e3021894 488 * Parse one or more CRLs and add them to the chained list
elessair 0:f269e3021894 489 */
elessair 0:f269e3021894 490 int mbedtls_x509_crl_parse( mbedtls_x509_crl *chain, const unsigned char *buf, size_t buflen )
elessair 0:f269e3021894 491 {
elessair 0:f269e3021894 492 #if defined(MBEDTLS_PEM_PARSE_C)
elessair 0:f269e3021894 493 int ret;
elessair 0:f269e3021894 494 size_t use_len;
elessair 0:f269e3021894 495 mbedtls_pem_context pem;
elessair 0:f269e3021894 496 int is_pem = 0;
elessair 0:f269e3021894 497
elessair 0:f269e3021894 498 if( chain == NULL || buf == NULL )
elessair 0:f269e3021894 499 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
elessair 0:f269e3021894 500
elessair 0:f269e3021894 501 do
elessair 0:f269e3021894 502 {
elessair 0:f269e3021894 503 mbedtls_pem_init( &pem );
elessair 0:f269e3021894 504
elessair 0:f269e3021894 505 // Avoid calling mbedtls_pem_read_buffer() on non-null-terminated
elessair 0:f269e3021894 506 // string
elessair 0:f269e3021894 507 if( buflen == 0 || buf[buflen - 1] != '\0' )
elessair 0:f269e3021894 508 ret = MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT;
elessair 0:f269e3021894 509 else
elessair 0:f269e3021894 510 ret = mbedtls_pem_read_buffer( &pem,
elessair 0:f269e3021894 511 "-----BEGIN X509 CRL-----",
elessair 0:f269e3021894 512 "-----END X509 CRL-----",
elessair 0:f269e3021894 513 buf, NULL, 0, &use_len );
elessair 0:f269e3021894 514
elessair 0:f269e3021894 515 if( ret == 0 )
elessair 0:f269e3021894 516 {
elessair 0:f269e3021894 517 /*
elessair 0:f269e3021894 518 * Was PEM encoded
elessair 0:f269e3021894 519 */
elessair 0:f269e3021894 520 is_pem = 1;
elessair 0:f269e3021894 521
elessair 0:f269e3021894 522 buflen -= use_len;
elessair 0:f269e3021894 523 buf += use_len;
elessair 0:f269e3021894 524
elessair 0:f269e3021894 525 if( ( ret = mbedtls_x509_crl_parse_der( chain,
elessair 0:f269e3021894 526 pem.buf, pem.buflen ) ) != 0 )
elessair 0:f269e3021894 527 {
elessair 0:f269e3021894 528 return( ret );
elessair 0:f269e3021894 529 }
elessair 0:f269e3021894 530
elessair 0:f269e3021894 531 mbedtls_pem_free( &pem );
elessair 0:f269e3021894 532 }
elessair 0:f269e3021894 533 else if( ret != MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT )
elessair 0:f269e3021894 534 {
elessair 0:f269e3021894 535 mbedtls_pem_free( &pem );
elessair 0:f269e3021894 536 return( ret );
elessair 0:f269e3021894 537 }
elessair 0:f269e3021894 538 }
elessair 0:f269e3021894 539 /* In the PEM case, buflen is 1 at the end, for the terminated NULL byte.
elessair 0:f269e3021894 540 * And a valid CRL cannot be less than 1 byte anyway. */
elessair 0:f269e3021894 541 while( is_pem && buflen > 1 );
elessair 0:f269e3021894 542
elessair 0:f269e3021894 543 if( is_pem )
elessair 0:f269e3021894 544 return( 0 );
elessair 0:f269e3021894 545 else
elessair 0:f269e3021894 546 #endif /* MBEDTLS_PEM_PARSE_C */
elessair 0:f269e3021894 547 return( mbedtls_x509_crl_parse_der( chain, buf, buflen ) );
elessair 0:f269e3021894 548 }
elessair 0:f269e3021894 549
elessair 0:f269e3021894 550 #if defined(MBEDTLS_FS_IO)
elessair 0:f269e3021894 551 /*
elessair 0:f269e3021894 552 * Load one or more CRLs and add them to the chained list
elessair 0:f269e3021894 553 */
elessair 0:f269e3021894 554 int mbedtls_x509_crl_parse_file( mbedtls_x509_crl *chain, const char *path )
elessair 0:f269e3021894 555 {
elessair 0:f269e3021894 556 int ret;
elessair 0:f269e3021894 557 size_t n;
elessair 0:f269e3021894 558 unsigned char *buf;
elessair 0:f269e3021894 559
elessair 0:f269e3021894 560 if( ( ret = mbedtls_pk_load_file( path, &buf, &n ) ) != 0 )
elessair 0:f269e3021894 561 return( ret );
elessair 0:f269e3021894 562
elessair 0:f269e3021894 563 ret = mbedtls_x509_crl_parse( chain, buf, n );
elessair 0:f269e3021894 564
elessair 0:f269e3021894 565 mbedtls_zeroize( buf, n );
elessair 0:f269e3021894 566 mbedtls_free( buf );
elessair 0:f269e3021894 567
elessair 0:f269e3021894 568 return( ret );
elessair 0:f269e3021894 569 }
elessair 0:f269e3021894 570 #endif /* MBEDTLS_FS_IO */
elessair 0:f269e3021894 571
elessair 0:f269e3021894 572 /*
elessair 0:f269e3021894 573 * Return an informational string about the certificate.
elessair 0:f269e3021894 574 */
elessair 0:f269e3021894 575 #define BEFORE_COLON 14
elessair 0:f269e3021894 576 #define BC "14"
elessair 0:f269e3021894 577 /*
elessair 0:f269e3021894 578 * Return an informational string about the CRL.
elessair 0:f269e3021894 579 */
elessair 0:f269e3021894 580 int mbedtls_x509_crl_info( char *buf, size_t size, const char *prefix,
elessair 0:f269e3021894 581 const mbedtls_x509_crl *crl )
elessair 0:f269e3021894 582 {
elessair 0:f269e3021894 583 int ret;
elessair 0:f269e3021894 584 size_t n;
elessair 0:f269e3021894 585 char *p;
elessair 0:f269e3021894 586 const mbedtls_x509_crl_entry *entry;
elessair 0:f269e3021894 587
elessair 0:f269e3021894 588 p = buf;
elessair 0:f269e3021894 589 n = size;
elessair 0:f269e3021894 590
elessair 0:f269e3021894 591 ret = mbedtls_snprintf( p, n, "%sCRL version : %d",
elessair 0:f269e3021894 592 prefix, crl->version );
elessair 0:f269e3021894 593 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 594
elessair 0:f269e3021894 595 ret = mbedtls_snprintf( p, n, "\n%sissuer name : ", prefix );
elessair 0:f269e3021894 596 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 597 ret = mbedtls_x509_dn_gets( p, n, &crl->issuer );
elessair 0:f269e3021894 598 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 599
elessair 0:f269e3021894 600 ret = mbedtls_snprintf( p, n, "\n%sthis update : " \
elessair 0:f269e3021894 601 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
elessair 0:f269e3021894 602 crl->this_update.year, crl->this_update.mon,
elessair 0:f269e3021894 603 crl->this_update.day, crl->this_update.hour,
elessair 0:f269e3021894 604 crl->this_update.min, crl->this_update.sec );
elessair 0:f269e3021894 605 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 606
elessair 0:f269e3021894 607 ret = mbedtls_snprintf( p, n, "\n%snext update : " \
elessair 0:f269e3021894 608 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
elessair 0:f269e3021894 609 crl->next_update.year, crl->next_update.mon,
elessair 0:f269e3021894 610 crl->next_update.day, crl->next_update.hour,
elessair 0:f269e3021894 611 crl->next_update.min, crl->next_update.sec );
elessair 0:f269e3021894 612 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 613
elessair 0:f269e3021894 614 entry = &crl->entry;
elessair 0:f269e3021894 615
elessair 0:f269e3021894 616 ret = mbedtls_snprintf( p, n, "\n%sRevoked certificates:",
elessair 0:f269e3021894 617 prefix );
elessair 0:f269e3021894 618 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 619
elessair 0:f269e3021894 620 while( entry != NULL && entry->raw.len != 0 )
elessair 0:f269e3021894 621 {
elessair 0:f269e3021894 622 ret = mbedtls_snprintf( p, n, "\n%sserial number: ",
elessair 0:f269e3021894 623 prefix );
elessair 0:f269e3021894 624 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 625
elessair 0:f269e3021894 626 ret = mbedtls_x509_serial_gets( p, n, &entry->serial );
elessair 0:f269e3021894 627 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 628
elessair 0:f269e3021894 629 ret = mbedtls_snprintf( p, n, " revocation date: " \
elessair 0:f269e3021894 630 "%04d-%02d-%02d %02d:%02d:%02d",
elessair 0:f269e3021894 631 entry->revocation_date.year, entry->revocation_date.mon,
elessair 0:f269e3021894 632 entry->revocation_date.day, entry->revocation_date.hour,
elessair 0:f269e3021894 633 entry->revocation_date.min, entry->revocation_date.sec );
elessair 0:f269e3021894 634 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 635
elessair 0:f269e3021894 636 entry = entry->next;
elessair 0:f269e3021894 637 }
elessair 0:f269e3021894 638
elessair 0:f269e3021894 639 ret = mbedtls_snprintf( p, n, "\n%ssigned using : ", prefix );
elessair 0:f269e3021894 640 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 641
elessair 0:f269e3021894 642 ret = mbedtls_x509_sig_alg_gets( p, n, &crl->sig_oid, crl->sig_pk, crl->sig_md,
elessair 0:f269e3021894 643 crl->sig_opts );
elessair 0:f269e3021894 644 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 645
elessair 0:f269e3021894 646 ret = mbedtls_snprintf( p, n, "\n" );
elessair 0:f269e3021894 647 MBEDTLS_X509_SAFE_SNPRINTF;
elessair 0:f269e3021894 648
elessair 0:f269e3021894 649 return( (int) ( size - n ) );
elessair 0:f269e3021894 650 }
elessair 0:f269e3021894 651
elessair 0:f269e3021894 652 /*
elessair 0:f269e3021894 653 * Initialize a CRL chain
elessair 0:f269e3021894 654 */
elessair 0:f269e3021894 655 void mbedtls_x509_crl_init( mbedtls_x509_crl *crl )
elessair 0:f269e3021894 656 {
elessair 0:f269e3021894 657 memset( crl, 0, sizeof(mbedtls_x509_crl) );
elessair 0:f269e3021894 658 }
elessair 0:f269e3021894 659
elessair 0:f269e3021894 660 /*
elessair 0:f269e3021894 661 * Unallocate all CRL data
elessair 0:f269e3021894 662 */
elessair 0:f269e3021894 663 void mbedtls_x509_crl_free( mbedtls_x509_crl *crl )
elessair 0:f269e3021894 664 {
elessair 0:f269e3021894 665 mbedtls_x509_crl *crl_cur = crl;
elessair 0:f269e3021894 666 mbedtls_x509_crl *crl_prv;
elessair 0:f269e3021894 667 mbedtls_x509_name *name_cur;
elessair 0:f269e3021894 668 mbedtls_x509_name *name_prv;
elessair 0:f269e3021894 669 mbedtls_x509_crl_entry *entry_cur;
elessair 0:f269e3021894 670 mbedtls_x509_crl_entry *entry_prv;
elessair 0:f269e3021894 671
elessair 0:f269e3021894 672 if( crl == NULL )
elessair 0:f269e3021894 673 return;
elessair 0:f269e3021894 674
elessair 0:f269e3021894 675 do
elessair 0:f269e3021894 676 {
elessair 0:f269e3021894 677 #if defined(MBEDTLS_X509_RSASSA_PSS_SUPPORT)
elessair 0:f269e3021894 678 mbedtls_free( crl_cur->sig_opts );
elessair 0:f269e3021894 679 #endif
elessair 0:f269e3021894 680
elessair 0:f269e3021894 681 name_cur = crl_cur->issuer.next;
elessair 0:f269e3021894 682 while( name_cur != NULL )
elessair 0:f269e3021894 683 {
elessair 0:f269e3021894 684 name_prv = name_cur;
elessair 0:f269e3021894 685 name_cur = name_cur->next;
elessair 0:f269e3021894 686 mbedtls_zeroize( name_prv, sizeof( mbedtls_x509_name ) );
elessair 0:f269e3021894 687 mbedtls_free( name_prv );
elessair 0:f269e3021894 688 }
elessair 0:f269e3021894 689
elessair 0:f269e3021894 690 entry_cur = crl_cur->entry.next;
elessair 0:f269e3021894 691 while( entry_cur != NULL )
elessair 0:f269e3021894 692 {
elessair 0:f269e3021894 693 entry_prv = entry_cur;
elessair 0:f269e3021894 694 entry_cur = entry_cur->next;
elessair 0:f269e3021894 695 mbedtls_zeroize( entry_prv, sizeof( mbedtls_x509_crl_entry ) );
elessair 0:f269e3021894 696 mbedtls_free( entry_prv );
elessair 0:f269e3021894 697 }
elessair 0:f269e3021894 698
elessair 0:f269e3021894 699 if( crl_cur->raw.p != NULL )
elessair 0:f269e3021894 700 {
elessair 0:f269e3021894 701 mbedtls_zeroize( crl_cur->raw.p, crl_cur->raw.len );
elessair 0:f269e3021894 702 mbedtls_free( crl_cur->raw.p );
elessair 0:f269e3021894 703 }
elessair 0:f269e3021894 704
elessair 0:f269e3021894 705 crl_cur = crl_cur->next;
elessair 0:f269e3021894 706 }
elessair 0:f269e3021894 707 while( crl_cur != NULL );
elessair 0:f269e3021894 708
elessair 0:f269e3021894 709 crl_cur = crl;
elessair 0:f269e3021894 710 do
elessair 0:f269e3021894 711 {
elessair 0:f269e3021894 712 crl_prv = crl_cur;
elessair 0:f269e3021894 713 crl_cur = crl_cur->next;
elessair 0:f269e3021894 714
elessair 0:f269e3021894 715 mbedtls_zeroize( crl_prv, sizeof( mbedtls_x509_crl ) );
elessair 0:f269e3021894 716 if( crl_prv != crl )
elessair 0:f269e3021894 717 mbedtls_free( crl_prv );
elessair 0:f269e3021894 718 }
elessair 0:f269e3021894 719 while( crl_cur != NULL );
elessair 0:f269e3021894 720 }
elessair 0:f269e3021894 721
elessair 0:f269e3021894 722 #endif /* MBEDTLS_X509_CRL_PARSE_C */