Preliminary main mbed library for nexpaq development

Committer:
nexpaq
Date:
Fri Nov 04 20:27:58 2016 +0000
Revision:
0:6c56fb4bc5f0
Moving to library for sharing updates

Who changed what in which revision?

UserRevisionLine numberNew contents of line
nexpaq 0:6c56fb4bc5f0 1 /*
nexpaq 0:6c56fb4bc5f0 2 * X.509 Certidicate Revocation List (CRL) parsing
nexpaq 0:6c56fb4bc5f0 3 *
nexpaq 0:6c56fb4bc5f0 4 * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
nexpaq 0:6c56fb4bc5f0 5 * SPDX-License-Identifier: Apache-2.0
nexpaq 0:6c56fb4bc5f0 6 *
nexpaq 0:6c56fb4bc5f0 7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
nexpaq 0:6c56fb4bc5f0 8 * not use this file except in compliance with the License.
nexpaq 0:6c56fb4bc5f0 9 * You may obtain a copy of the License at
nexpaq 0:6c56fb4bc5f0 10 *
nexpaq 0:6c56fb4bc5f0 11 * http://www.apache.org/licenses/LICENSE-2.0
nexpaq 0:6c56fb4bc5f0 12 *
nexpaq 0:6c56fb4bc5f0 13 * Unless required by applicable law or agreed to in writing, software
nexpaq 0:6c56fb4bc5f0 14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
nexpaq 0:6c56fb4bc5f0 15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
nexpaq 0:6c56fb4bc5f0 16 * See the License for the specific language governing permissions and
nexpaq 0:6c56fb4bc5f0 17 * limitations under the License.
nexpaq 0:6c56fb4bc5f0 18 *
nexpaq 0:6c56fb4bc5f0 19 * This file is part of mbed TLS (https://tls.mbed.org)
nexpaq 0:6c56fb4bc5f0 20 */
nexpaq 0:6c56fb4bc5f0 21 /*
nexpaq 0:6c56fb4bc5f0 22 * The ITU-T X.509 standard defines a certificate format for PKI.
nexpaq 0:6c56fb4bc5f0 23 *
nexpaq 0:6c56fb4bc5f0 24 * http://www.ietf.org/rfc/rfc5280.txt (Certificates and CRLs)
nexpaq 0:6c56fb4bc5f0 25 * http://www.ietf.org/rfc/rfc3279.txt (Alg IDs for CRLs)
nexpaq 0:6c56fb4bc5f0 26 * http://www.ietf.org/rfc/rfc2986.txt (CSRs, aka PKCS#10)
nexpaq 0:6c56fb4bc5f0 27 *
nexpaq 0:6c56fb4bc5f0 28 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.680-0207.pdf
nexpaq 0:6c56fb4bc5f0 29 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.690-0207.pdf
nexpaq 0:6c56fb4bc5f0 30 */
nexpaq 0:6c56fb4bc5f0 31
nexpaq 0:6c56fb4bc5f0 32 #if !defined(MBEDTLS_CONFIG_FILE)
nexpaq 0:6c56fb4bc5f0 33 #include "mbedtls/config.h"
nexpaq 0:6c56fb4bc5f0 34 #else
nexpaq 0:6c56fb4bc5f0 35 #include MBEDTLS_CONFIG_FILE
nexpaq 0:6c56fb4bc5f0 36 #endif
nexpaq 0:6c56fb4bc5f0 37
nexpaq 0:6c56fb4bc5f0 38 #if defined(MBEDTLS_X509_CRL_PARSE_C)
nexpaq 0:6c56fb4bc5f0 39
nexpaq 0:6c56fb4bc5f0 40 #include "mbedtls/x509_crl.h"
nexpaq 0:6c56fb4bc5f0 41 #include "mbedtls/oid.h"
nexpaq 0:6c56fb4bc5f0 42
nexpaq 0:6c56fb4bc5f0 43 #include <string.h>
nexpaq 0:6c56fb4bc5f0 44
nexpaq 0:6c56fb4bc5f0 45 #if defined(MBEDTLS_PEM_PARSE_C)
nexpaq 0:6c56fb4bc5f0 46 #include "mbedtls/pem.h"
nexpaq 0:6c56fb4bc5f0 47 #endif
nexpaq 0:6c56fb4bc5f0 48
nexpaq 0:6c56fb4bc5f0 49 #if defined(MBEDTLS_PLATFORM_C)
nexpaq 0:6c56fb4bc5f0 50 #include "mbedtls/platform.h"
nexpaq 0:6c56fb4bc5f0 51 #else
nexpaq 0:6c56fb4bc5f0 52 #include <stdlib.h>
nexpaq 0:6c56fb4bc5f0 53 #include <stdio.h>
nexpaq 0:6c56fb4bc5f0 54 #define mbedtls_free free
nexpaq 0:6c56fb4bc5f0 55 #define mbedtls_calloc calloc
nexpaq 0:6c56fb4bc5f0 56 #define mbedtls_snprintf snprintf
nexpaq 0:6c56fb4bc5f0 57 #endif
nexpaq 0:6c56fb4bc5f0 58
nexpaq 0:6c56fb4bc5f0 59 #if defined(_WIN32) && !defined(EFIX64) && !defined(EFI32)
nexpaq 0:6c56fb4bc5f0 60 #include <windows.h>
nexpaq 0:6c56fb4bc5f0 61 #else
nexpaq 0:6c56fb4bc5f0 62 #include <time.h>
nexpaq 0:6c56fb4bc5f0 63 #endif
nexpaq 0:6c56fb4bc5f0 64
nexpaq 0:6c56fb4bc5f0 65 #if defined(MBEDTLS_FS_IO) || defined(EFIX64) || defined(EFI32)
nexpaq 0:6c56fb4bc5f0 66 #include <stdio.h>
nexpaq 0:6c56fb4bc5f0 67 #endif
nexpaq 0:6c56fb4bc5f0 68
nexpaq 0:6c56fb4bc5f0 69 /* Implementation that should never be optimized out by the compiler */
nexpaq 0:6c56fb4bc5f0 70 static void mbedtls_zeroize( void *v, size_t n ) {
nexpaq 0:6c56fb4bc5f0 71 volatile unsigned char *p = v; while( n-- ) *p++ = 0;
nexpaq 0:6c56fb4bc5f0 72 }
nexpaq 0:6c56fb4bc5f0 73
nexpaq 0:6c56fb4bc5f0 74 /*
nexpaq 0:6c56fb4bc5f0 75 * Version ::= INTEGER { v1(0), v2(1) }
nexpaq 0:6c56fb4bc5f0 76 */
nexpaq 0:6c56fb4bc5f0 77 static int x509_crl_get_version( unsigned char **p,
nexpaq 0:6c56fb4bc5f0 78 const unsigned char *end,
nexpaq 0:6c56fb4bc5f0 79 int *ver )
nexpaq 0:6c56fb4bc5f0 80 {
nexpaq 0:6c56fb4bc5f0 81 int ret;
nexpaq 0:6c56fb4bc5f0 82
nexpaq 0:6c56fb4bc5f0 83 if( ( ret = mbedtls_asn1_get_int( p, end, ver ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 84 {
nexpaq 0:6c56fb4bc5f0 85 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
nexpaq 0:6c56fb4bc5f0 86 {
nexpaq 0:6c56fb4bc5f0 87 *ver = 0;
nexpaq 0:6c56fb4bc5f0 88 return( 0 );
nexpaq 0:6c56fb4bc5f0 89 }
nexpaq 0:6c56fb4bc5f0 90
nexpaq 0:6c56fb4bc5f0 91 return( MBEDTLS_ERR_X509_INVALID_VERSION + ret );
nexpaq 0:6c56fb4bc5f0 92 }
nexpaq 0:6c56fb4bc5f0 93
nexpaq 0:6c56fb4bc5f0 94 return( 0 );
nexpaq 0:6c56fb4bc5f0 95 }
nexpaq 0:6c56fb4bc5f0 96
nexpaq 0:6c56fb4bc5f0 97 /*
nexpaq 0:6c56fb4bc5f0 98 * X.509 CRL v2 extensions (no extensions parsed yet.)
nexpaq 0:6c56fb4bc5f0 99 */
nexpaq 0:6c56fb4bc5f0 100 static int x509_get_crl_ext( unsigned char **p,
nexpaq 0:6c56fb4bc5f0 101 const unsigned char *end,
nexpaq 0:6c56fb4bc5f0 102 mbedtls_x509_buf *ext )
nexpaq 0:6c56fb4bc5f0 103 {
nexpaq 0:6c56fb4bc5f0 104 int ret;
nexpaq 0:6c56fb4bc5f0 105 size_t len = 0;
nexpaq 0:6c56fb4bc5f0 106
nexpaq 0:6c56fb4bc5f0 107 /* Get explicit tag */
nexpaq 0:6c56fb4bc5f0 108 if( ( ret = mbedtls_x509_get_ext( p, end, ext, 0) ) != 0 )
nexpaq 0:6c56fb4bc5f0 109 {
nexpaq 0:6c56fb4bc5f0 110 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
nexpaq 0:6c56fb4bc5f0 111 return( 0 );
nexpaq 0:6c56fb4bc5f0 112
nexpaq 0:6c56fb4bc5f0 113 return( ret );
nexpaq 0:6c56fb4bc5f0 114 }
nexpaq 0:6c56fb4bc5f0 115
nexpaq 0:6c56fb4bc5f0 116 while( *p < end )
nexpaq 0:6c56fb4bc5f0 117 {
nexpaq 0:6c56fb4bc5f0 118 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
nexpaq 0:6c56fb4bc5f0 119 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 120 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
nexpaq 0:6c56fb4bc5f0 121
nexpaq 0:6c56fb4bc5f0 122 *p += len;
nexpaq 0:6c56fb4bc5f0 123 }
nexpaq 0:6c56fb4bc5f0 124
nexpaq 0:6c56fb4bc5f0 125 if( *p != end )
nexpaq 0:6c56fb4bc5f0 126 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
nexpaq 0:6c56fb4bc5f0 127 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
nexpaq 0:6c56fb4bc5f0 128
nexpaq 0:6c56fb4bc5f0 129 return( 0 );
nexpaq 0:6c56fb4bc5f0 130 }
nexpaq 0:6c56fb4bc5f0 131
nexpaq 0:6c56fb4bc5f0 132 /*
nexpaq 0:6c56fb4bc5f0 133 * X.509 CRL v2 entry extensions (no extensions parsed yet.)
nexpaq 0:6c56fb4bc5f0 134 */
nexpaq 0:6c56fb4bc5f0 135 static int x509_get_crl_entry_ext( unsigned char **p,
nexpaq 0:6c56fb4bc5f0 136 const unsigned char *end,
nexpaq 0:6c56fb4bc5f0 137 mbedtls_x509_buf *ext )
nexpaq 0:6c56fb4bc5f0 138 {
nexpaq 0:6c56fb4bc5f0 139 int ret;
nexpaq 0:6c56fb4bc5f0 140 size_t len = 0;
nexpaq 0:6c56fb4bc5f0 141
nexpaq 0:6c56fb4bc5f0 142 /* OPTIONAL */
nexpaq 0:6c56fb4bc5f0 143 if( end <= *p )
nexpaq 0:6c56fb4bc5f0 144 return( 0 );
nexpaq 0:6c56fb4bc5f0 145
nexpaq 0:6c56fb4bc5f0 146 ext->tag = **p;
nexpaq 0:6c56fb4bc5f0 147 ext->p = *p;
nexpaq 0:6c56fb4bc5f0 148
nexpaq 0:6c56fb4bc5f0 149 /*
nexpaq 0:6c56fb4bc5f0 150 * Get CRL-entry extension sequence header
nexpaq 0:6c56fb4bc5f0 151 * crlEntryExtensions Extensions OPTIONAL -- if present, MUST be v2
nexpaq 0:6c56fb4bc5f0 152 */
nexpaq 0:6c56fb4bc5f0 153 if( ( ret = mbedtls_asn1_get_tag( p, end, &ext->len,
nexpaq 0:6c56fb4bc5f0 154 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 155 {
nexpaq 0:6c56fb4bc5f0 156 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
nexpaq 0:6c56fb4bc5f0 157 {
nexpaq 0:6c56fb4bc5f0 158 ext->p = NULL;
nexpaq 0:6c56fb4bc5f0 159 return( 0 );
nexpaq 0:6c56fb4bc5f0 160 }
nexpaq 0:6c56fb4bc5f0 161 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
nexpaq 0:6c56fb4bc5f0 162 }
nexpaq 0:6c56fb4bc5f0 163
nexpaq 0:6c56fb4bc5f0 164 end = *p + ext->len;
nexpaq 0:6c56fb4bc5f0 165
nexpaq 0:6c56fb4bc5f0 166 if( end != *p + ext->len )
nexpaq 0:6c56fb4bc5f0 167 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
nexpaq 0:6c56fb4bc5f0 168 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
nexpaq 0:6c56fb4bc5f0 169
nexpaq 0:6c56fb4bc5f0 170 while( *p < end )
nexpaq 0:6c56fb4bc5f0 171 {
nexpaq 0:6c56fb4bc5f0 172 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
nexpaq 0:6c56fb4bc5f0 173 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 174 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
nexpaq 0:6c56fb4bc5f0 175
nexpaq 0:6c56fb4bc5f0 176 *p += len;
nexpaq 0:6c56fb4bc5f0 177 }
nexpaq 0:6c56fb4bc5f0 178
nexpaq 0:6c56fb4bc5f0 179 if( *p != end )
nexpaq 0:6c56fb4bc5f0 180 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
nexpaq 0:6c56fb4bc5f0 181 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
nexpaq 0:6c56fb4bc5f0 182
nexpaq 0:6c56fb4bc5f0 183 return( 0 );
nexpaq 0:6c56fb4bc5f0 184 }
nexpaq 0:6c56fb4bc5f0 185
nexpaq 0:6c56fb4bc5f0 186 /*
nexpaq 0:6c56fb4bc5f0 187 * X.509 CRL Entries
nexpaq 0:6c56fb4bc5f0 188 */
nexpaq 0:6c56fb4bc5f0 189 static int x509_get_entries( unsigned char **p,
nexpaq 0:6c56fb4bc5f0 190 const unsigned char *end,
nexpaq 0:6c56fb4bc5f0 191 mbedtls_x509_crl_entry *entry )
nexpaq 0:6c56fb4bc5f0 192 {
nexpaq 0:6c56fb4bc5f0 193 int ret;
nexpaq 0:6c56fb4bc5f0 194 size_t entry_len;
nexpaq 0:6c56fb4bc5f0 195 mbedtls_x509_crl_entry *cur_entry = entry;
nexpaq 0:6c56fb4bc5f0 196
nexpaq 0:6c56fb4bc5f0 197 if( *p == end )
nexpaq 0:6c56fb4bc5f0 198 return( 0 );
nexpaq 0:6c56fb4bc5f0 199
nexpaq 0:6c56fb4bc5f0 200 if( ( ret = mbedtls_asn1_get_tag( p, end, &entry_len,
nexpaq 0:6c56fb4bc5f0 201 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 202 {
nexpaq 0:6c56fb4bc5f0 203 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
nexpaq 0:6c56fb4bc5f0 204 return( 0 );
nexpaq 0:6c56fb4bc5f0 205
nexpaq 0:6c56fb4bc5f0 206 return( ret );
nexpaq 0:6c56fb4bc5f0 207 }
nexpaq 0:6c56fb4bc5f0 208
nexpaq 0:6c56fb4bc5f0 209 end = *p + entry_len;
nexpaq 0:6c56fb4bc5f0 210
nexpaq 0:6c56fb4bc5f0 211 while( *p < end )
nexpaq 0:6c56fb4bc5f0 212 {
nexpaq 0:6c56fb4bc5f0 213 size_t len2;
nexpaq 0:6c56fb4bc5f0 214 const unsigned char *end2;
nexpaq 0:6c56fb4bc5f0 215
nexpaq 0:6c56fb4bc5f0 216 if( ( ret = mbedtls_asn1_get_tag( p, end, &len2,
nexpaq 0:6c56fb4bc5f0 217 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 218 {
nexpaq 0:6c56fb4bc5f0 219 return( ret );
nexpaq 0:6c56fb4bc5f0 220 }
nexpaq 0:6c56fb4bc5f0 221
nexpaq 0:6c56fb4bc5f0 222 cur_entry->raw.tag = **p;
nexpaq 0:6c56fb4bc5f0 223 cur_entry->raw.p = *p;
nexpaq 0:6c56fb4bc5f0 224 cur_entry->raw.len = len2;
nexpaq 0:6c56fb4bc5f0 225 end2 = *p + len2;
nexpaq 0:6c56fb4bc5f0 226
nexpaq 0:6c56fb4bc5f0 227 if( ( ret = mbedtls_x509_get_serial( p, end2, &cur_entry->serial ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 228 return( ret );
nexpaq 0:6c56fb4bc5f0 229
nexpaq 0:6c56fb4bc5f0 230 if( ( ret = mbedtls_x509_get_time( p, end2,
nexpaq 0:6c56fb4bc5f0 231 &cur_entry->revocation_date ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 232 return( ret );
nexpaq 0:6c56fb4bc5f0 233
nexpaq 0:6c56fb4bc5f0 234 if( ( ret = x509_get_crl_entry_ext( p, end2,
nexpaq 0:6c56fb4bc5f0 235 &cur_entry->entry_ext ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 236 return( ret );
nexpaq 0:6c56fb4bc5f0 237
nexpaq 0:6c56fb4bc5f0 238 if( *p < end )
nexpaq 0:6c56fb4bc5f0 239 {
nexpaq 0:6c56fb4bc5f0 240 cur_entry->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl_entry ) );
nexpaq 0:6c56fb4bc5f0 241
nexpaq 0:6c56fb4bc5f0 242 if( cur_entry->next == NULL )
nexpaq 0:6c56fb4bc5f0 243 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
nexpaq 0:6c56fb4bc5f0 244
nexpaq 0:6c56fb4bc5f0 245 cur_entry = cur_entry->next;
nexpaq 0:6c56fb4bc5f0 246 }
nexpaq 0:6c56fb4bc5f0 247 }
nexpaq 0:6c56fb4bc5f0 248
nexpaq 0:6c56fb4bc5f0 249 return( 0 );
nexpaq 0:6c56fb4bc5f0 250 }
nexpaq 0:6c56fb4bc5f0 251
nexpaq 0:6c56fb4bc5f0 252 /*
nexpaq 0:6c56fb4bc5f0 253 * Parse one CRLs in DER format and append it to the chained list
nexpaq 0:6c56fb4bc5f0 254 */
nexpaq 0:6c56fb4bc5f0 255 int mbedtls_x509_crl_parse_der( mbedtls_x509_crl *chain,
nexpaq 0:6c56fb4bc5f0 256 const unsigned char *buf, size_t buflen )
nexpaq 0:6c56fb4bc5f0 257 {
nexpaq 0:6c56fb4bc5f0 258 int ret;
nexpaq 0:6c56fb4bc5f0 259 size_t len;
nexpaq 0:6c56fb4bc5f0 260 unsigned char *p, *end;
nexpaq 0:6c56fb4bc5f0 261 mbedtls_x509_buf sig_params1, sig_params2, sig_oid2;
nexpaq 0:6c56fb4bc5f0 262 mbedtls_x509_crl *crl = chain;
nexpaq 0:6c56fb4bc5f0 263
nexpaq 0:6c56fb4bc5f0 264 /*
nexpaq 0:6c56fb4bc5f0 265 * Check for valid input
nexpaq 0:6c56fb4bc5f0 266 */
nexpaq 0:6c56fb4bc5f0 267 if( crl == NULL || buf == NULL )
nexpaq 0:6c56fb4bc5f0 268 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
nexpaq 0:6c56fb4bc5f0 269
nexpaq 0:6c56fb4bc5f0 270 memset( &sig_params1, 0, sizeof( mbedtls_x509_buf ) );
nexpaq 0:6c56fb4bc5f0 271 memset( &sig_params2, 0, sizeof( mbedtls_x509_buf ) );
nexpaq 0:6c56fb4bc5f0 272 memset( &sig_oid2, 0, sizeof( mbedtls_x509_buf ) );
nexpaq 0:6c56fb4bc5f0 273
nexpaq 0:6c56fb4bc5f0 274 /*
nexpaq 0:6c56fb4bc5f0 275 * Add new CRL on the end of the chain if needed.
nexpaq 0:6c56fb4bc5f0 276 */
nexpaq 0:6c56fb4bc5f0 277 while( crl->version != 0 && crl->next != NULL )
nexpaq 0:6c56fb4bc5f0 278 crl = crl->next;
nexpaq 0:6c56fb4bc5f0 279
nexpaq 0:6c56fb4bc5f0 280 if( crl->version != 0 && crl->next == NULL )
nexpaq 0:6c56fb4bc5f0 281 {
nexpaq 0:6c56fb4bc5f0 282 crl->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl ) );
nexpaq 0:6c56fb4bc5f0 283
nexpaq 0:6c56fb4bc5f0 284 if( crl->next == NULL )
nexpaq 0:6c56fb4bc5f0 285 {
nexpaq 0:6c56fb4bc5f0 286 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 287 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
nexpaq 0:6c56fb4bc5f0 288 }
nexpaq 0:6c56fb4bc5f0 289
nexpaq 0:6c56fb4bc5f0 290 mbedtls_x509_crl_init( crl->next );
nexpaq 0:6c56fb4bc5f0 291 crl = crl->next;
nexpaq 0:6c56fb4bc5f0 292 }
nexpaq 0:6c56fb4bc5f0 293
nexpaq 0:6c56fb4bc5f0 294 /*
nexpaq 0:6c56fb4bc5f0 295 * Copy raw DER-encoded CRL
nexpaq 0:6c56fb4bc5f0 296 */
nexpaq 0:6c56fb4bc5f0 297 if( ( p = mbedtls_calloc( 1, buflen ) ) == NULL )
nexpaq 0:6c56fb4bc5f0 298 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
nexpaq 0:6c56fb4bc5f0 299
nexpaq 0:6c56fb4bc5f0 300 memcpy( p, buf, buflen );
nexpaq 0:6c56fb4bc5f0 301
nexpaq 0:6c56fb4bc5f0 302 crl->raw.p = p;
nexpaq 0:6c56fb4bc5f0 303 crl->raw.len = buflen;
nexpaq 0:6c56fb4bc5f0 304
nexpaq 0:6c56fb4bc5f0 305 end = p + buflen;
nexpaq 0:6c56fb4bc5f0 306
nexpaq 0:6c56fb4bc5f0 307 /*
nexpaq 0:6c56fb4bc5f0 308 * CertificateList ::= SEQUENCE {
nexpaq 0:6c56fb4bc5f0 309 * tbsCertList TBSCertList,
nexpaq 0:6c56fb4bc5f0 310 * signatureAlgorithm AlgorithmIdentifier,
nexpaq 0:6c56fb4bc5f0 311 * signatureValue BIT STRING }
nexpaq 0:6c56fb4bc5f0 312 */
nexpaq 0:6c56fb4bc5f0 313 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
nexpaq 0:6c56fb4bc5f0 314 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 315 {
nexpaq 0:6c56fb4bc5f0 316 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 317 return( MBEDTLS_ERR_X509_INVALID_FORMAT );
nexpaq 0:6c56fb4bc5f0 318 }
nexpaq 0:6c56fb4bc5f0 319
nexpaq 0:6c56fb4bc5f0 320 if( len != (size_t) ( end - p ) )
nexpaq 0:6c56fb4bc5f0 321 {
nexpaq 0:6c56fb4bc5f0 322 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 323 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
nexpaq 0:6c56fb4bc5f0 324 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
nexpaq 0:6c56fb4bc5f0 325 }
nexpaq 0:6c56fb4bc5f0 326
nexpaq 0:6c56fb4bc5f0 327 /*
nexpaq 0:6c56fb4bc5f0 328 * TBSCertList ::= SEQUENCE {
nexpaq 0:6c56fb4bc5f0 329 */
nexpaq 0:6c56fb4bc5f0 330 crl->tbs.p = p;
nexpaq 0:6c56fb4bc5f0 331
nexpaq 0:6c56fb4bc5f0 332 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
nexpaq 0:6c56fb4bc5f0 333 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 334 {
nexpaq 0:6c56fb4bc5f0 335 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 336 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
nexpaq 0:6c56fb4bc5f0 337 }
nexpaq 0:6c56fb4bc5f0 338
nexpaq 0:6c56fb4bc5f0 339 end = p + len;
nexpaq 0:6c56fb4bc5f0 340 crl->tbs.len = end - crl->tbs.p;
nexpaq 0:6c56fb4bc5f0 341
nexpaq 0:6c56fb4bc5f0 342 /*
nexpaq 0:6c56fb4bc5f0 343 * Version ::= INTEGER OPTIONAL { v1(0), v2(1) }
nexpaq 0:6c56fb4bc5f0 344 * -- if present, MUST be v2
nexpaq 0:6c56fb4bc5f0 345 *
nexpaq 0:6c56fb4bc5f0 346 * signature AlgorithmIdentifier
nexpaq 0:6c56fb4bc5f0 347 */
nexpaq 0:6c56fb4bc5f0 348 if( ( ret = x509_crl_get_version( &p, end, &crl->version ) ) != 0 ||
nexpaq 0:6c56fb4bc5f0 349 ( ret = mbedtls_x509_get_alg( &p, end, &crl->sig_oid, &sig_params1 ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 350 {
nexpaq 0:6c56fb4bc5f0 351 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 352 return( ret );
nexpaq 0:6c56fb4bc5f0 353 }
nexpaq 0:6c56fb4bc5f0 354
nexpaq 0:6c56fb4bc5f0 355 crl->version++;
nexpaq 0:6c56fb4bc5f0 356
nexpaq 0:6c56fb4bc5f0 357 if( crl->version > 2 )
nexpaq 0:6c56fb4bc5f0 358 {
nexpaq 0:6c56fb4bc5f0 359 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 360 return( MBEDTLS_ERR_X509_UNKNOWN_VERSION );
nexpaq 0:6c56fb4bc5f0 361 }
nexpaq 0:6c56fb4bc5f0 362
nexpaq 0:6c56fb4bc5f0 363 if( ( ret = mbedtls_x509_get_sig_alg( &crl->sig_oid, &sig_params1,
nexpaq 0:6c56fb4bc5f0 364 &crl->sig_md, &crl->sig_pk,
nexpaq 0:6c56fb4bc5f0 365 &crl->sig_opts ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 366 {
nexpaq 0:6c56fb4bc5f0 367 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 368 return( MBEDTLS_ERR_X509_UNKNOWN_SIG_ALG );
nexpaq 0:6c56fb4bc5f0 369 }
nexpaq 0:6c56fb4bc5f0 370
nexpaq 0:6c56fb4bc5f0 371 /*
nexpaq 0:6c56fb4bc5f0 372 * issuer Name
nexpaq 0:6c56fb4bc5f0 373 */
nexpaq 0:6c56fb4bc5f0 374 crl->issuer_raw.p = p;
nexpaq 0:6c56fb4bc5f0 375
nexpaq 0:6c56fb4bc5f0 376 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
nexpaq 0:6c56fb4bc5f0 377 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 378 {
nexpaq 0:6c56fb4bc5f0 379 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 380 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
nexpaq 0:6c56fb4bc5f0 381 }
nexpaq 0:6c56fb4bc5f0 382
nexpaq 0:6c56fb4bc5f0 383 if( ( ret = mbedtls_x509_get_name( &p, p + len, &crl->issuer ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 384 {
nexpaq 0:6c56fb4bc5f0 385 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 386 return( ret );
nexpaq 0:6c56fb4bc5f0 387 }
nexpaq 0:6c56fb4bc5f0 388
nexpaq 0:6c56fb4bc5f0 389 crl->issuer_raw.len = p - crl->issuer_raw.p;
nexpaq 0:6c56fb4bc5f0 390
nexpaq 0:6c56fb4bc5f0 391 /*
nexpaq 0:6c56fb4bc5f0 392 * thisUpdate Time
nexpaq 0:6c56fb4bc5f0 393 * nextUpdate Time OPTIONAL
nexpaq 0:6c56fb4bc5f0 394 */
nexpaq 0:6c56fb4bc5f0 395 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->this_update ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 396 {
nexpaq 0:6c56fb4bc5f0 397 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 398 return( ret );
nexpaq 0:6c56fb4bc5f0 399 }
nexpaq 0:6c56fb4bc5f0 400
nexpaq 0:6c56fb4bc5f0 401 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->next_update ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 402 {
nexpaq 0:6c56fb4bc5f0 403 if( ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
nexpaq 0:6c56fb4bc5f0 404 MBEDTLS_ERR_ASN1_UNEXPECTED_TAG ) &&
nexpaq 0:6c56fb4bc5f0 405 ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
nexpaq 0:6c56fb4bc5f0 406 MBEDTLS_ERR_ASN1_OUT_OF_DATA ) )
nexpaq 0:6c56fb4bc5f0 407 {
nexpaq 0:6c56fb4bc5f0 408 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 409 return( ret );
nexpaq 0:6c56fb4bc5f0 410 }
nexpaq 0:6c56fb4bc5f0 411 }
nexpaq 0:6c56fb4bc5f0 412
nexpaq 0:6c56fb4bc5f0 413 /*
nexpaq 0:6c56fb4bc5f0 414 * revokedCertificates SEQUENCE OF SEQUENCE {
nexpaq 0:6c56fb4bc5f0 415 * userCertificate CertificateSerialNumber,
nexpaq 0:6c56fb4bc5f0 416 * revocationDate Time,
nexpaq 0:6c56fb4bc5f0 417 * crlEntryExtensions Extensions OPTIONAL
nexpaq 0:6c56fb4bc5f0 418 * -- if present, MUST be v2
nexpaq 0:6c56fb4bc5f0 419 * } OPTIONAL
nexpaq 0:6c56fb4bc5f0 420 */
nexpaq 0:6c56fb4bc5f0 421 if( ( ret = x509_get_entries( &p, end, &crl->entry ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 422 {
nexpaq 0:6c56fb4bc5f0 423 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 424 return( ret );
nexpaq 0:6c56fb4bc5f0 425 }
nexpaq 0:6c56fb4bc5f0 426
nexpaq 0:6c56fb4bc5f0 427 /*
nexpaq 0:6c56fb4bc5f0 428 * crlExtensions EXPLICIT Extensions OPTIONAL
nexpaq 0:6c56fb4bc5f0 429 * -- if present, MUST be v2
nexpaq 0:6c56fb4bc5f0 430 */
nexpaq 0:6c56fb4bc5f0 431 if( crl->version == 2 )
nexpaq 0:6c56fb4bc5f0 432 {
nexpaq 0:6c56fb4bc5f0 433 ret = x509_get_crl_ext( &p, end, &crl->crl_ext );
nexpaq 0:6c56fb4bc5f0 434
nexpaq 0:6c56fb4bc5f0 435 if( ret != 0 )
nexpaq 0:6c56fb4bc5f0 436 {
nexpaq 0:6c56fb4bc5f0 437 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 438 return( ret );
nexpaq 0:6c56fb4bc5f0 439 }
nexpaq 0:6c56fb4bc5f0 440 }
nexpaq 0:6c56fb4bc5f0 441
nexpaq 0:6c56fb4bc5f0 442 if( p != end )
nexpaq 0:6c56fb4bc5f0 443 {
nexpaq 0:6c56fb4bc5f0 444 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 445 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
nexpaq 0:6c56fb4bc5f0 446 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
nexpaq 0:6c56fb4bc5f0 447 }
nexpaq 0:6c56fb4bc5f0 448
nexpaq 0:6c56fb4bc5f0 449 end = crl->raw.p + crl->raw.len;
nexpaq 0:6c56fb4bc5f0 450
nexpaq 0:6c56fb4bc5f0 451 /*
nexpaq 0:6c56fb4bc5f0 452 * signatureAlgorithm AlgorithmIdentifier,
nexpaq 0:6c56fb4bc5f0 453 * signatureValue BIT STRING
nexpaq 0:6c56fb4bc5f0 454 */
nexpaq 0:6c56fb4bc5f0 455 if( ( ret = mbedtls_x509_get_alg( &p, end, &sig_oid2, &sig_params2 ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 456 {
nexpaq 0:6c56fb4bc5f0 457 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 458 return( ret );
nexpaq 0:6c56fb4bc5f0 459 }
nexpaq 0:6c56fb4bc5f0 460
nexpaq 0:6c56fb4bc5f0 461 if( crl->sig_oid.len != sig_oid2.len ||
nexpaq 0:6c56fb4bc5f0 462 memcmp( crl->sig_oid.p, sig_oid2.p, crl->sig_oid.len ) != 0 ||
nexpaq 0:6c56fb4bc5f0 463 sig_params1.len != sig_params2.len ||
nexpaq 0:6c56fb4bc5f0 464 ( sig_params1.len != 0 &&
nexpaq 0:6c56fb4bc5f0 465 memcmp( sig_params1.p, sig_params2.p, sig_params1.len ) != 0 ) )
nexpaq 0:6c56fb4bc5f0 466 {
nexpaq 0:6c56fb4bc5f0 467 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 468 return( MBEDTLS_ERR_X509_SIG_MISMATCH );
nexpaq 0:6c56fb4bc5f0 469 }
nexpaq 0:6c56fb4bc5f0 470
nexpaq 0:6c56fb4bc5f0 471 if( ( ret = mbedtls_x509_get_sig( &p, end, &crl->sig ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 472 {
nexpaq 0:6c56fb4bc5f0 473 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 474 return( ret );
nexpaq 0:6c56fb4bc5f0 475 }
nexpaq 0:6c56fb4bc5f0 476
nexpaq 0:6c56fb4bc5f0 477 if( p != end )
nexpaq 0:6c56fb4bc5f0 478 {
nexpaq 0:6c56fb4bc5f0 479 mbedtls_x509_crl_free( crl );
nexpaq 0:6c56fb4bc5f0 480 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
nexpaq 0:6c56fb4bc5f0 481 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
nexpaq 0:6c56fb4bc5f0 482 }
nexpaq 0:6c56fb4bc5f0 483
nexpaq 0:6c56fb4bc5f0 484 return( 0 );
nexpaq 0:6c56fb4bc5f0 485 }
nexpaq 0:6c56fb4bc5f0 486
nexpaq 0:6c56fb4bc5f0 487 /*
nexpaq 0:6c56fb4bc5f0 488 * Parse one or more CRLs and add them to the chained list
nexpaq 0:6c56fb4bc5f0 489 */
nexpaq 0:6c56fb4bc5f0 490 int mbedtls_x509_crl_parse( mbedtls_x509_crl *chain, const unsigned char *buf, size_t buflen )
nexpaq 0:6c56fb4bc5f0 491 {
nexpaq 0:6c56fb4bc5f0 492 #if defined(MBEDTLS_PEM_PARSE_C)
nexpaq 0:6c56fb4bc5f0 493 int ret;
nexpaq 0:6c56fb4bc5f0 494 size_t use_len;
nexpaq 0:6c56fb4bc5f0 495 mbedtls_pem_context pem;
nexpaq 0:6c56fb4bc5f0 496 int is_pem = 0;
nexpaq 0:6c56fb4bc5f0 497
nexpaq 0:6c56fb4bc5f0 498 if( chain == NULL || buf == NULL )
nexpaq 0:6c56fb4bc5f0 499 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
nexpaq 0:6c56fb4bc5f0 500
nexpaq 0:6c56fb4bc5f0 501 do
nexpaq 0:6c56fb4bc5f0 502 {
nexpaq 0:6c56fb4bc5f0 503 mbedtls_pem_init( &pem );
nexpaq 0:6c56fb4bc5f0 504
nexpaq 0:6c56fb4bc5f0 505 // Avoid calling mbedtls_pem_read_buffer() on non-null-terminated
nexpaq 0:6c56fb4bc5f0 506 // string
nexpaq 0:6c56fb4bc5f0 507 if( buflen == 0 || buf[buflen - 1] != '\0' )
nexpaq 0:6c56fb4bc5f0 508 ret = MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT;
nexpaq 0:6c56fb4bc5f0 509 else
nexpaq 0:6c56fb4bc5f0 510 ret = mbedtls_pem_read_buffer( &pem,
nexpaq 0:6c56fb4bc5f0 511 "-----BEGIN X509 CRL-----",
nexpaq 0:6c56fb4bc5f0 512 "-----END X509 CRL-----",
nexpaq 0:6c56fb4bc5f0 513 buf, NULL, 0, &use_len );
nexpaq 0:6c56fb4bc5f0 514
nexpaq 0:6c56fb4bc5f0 515 if( ret == 0 )
nexpaq 0:6c56fb4bc5f0 516 {
nexpaq 0:6c56fb4bc5f0 517 /*
nexpaq 0:6c56fb4bc5f0 518 * Was PEM encoded
nexpaq 0:6c56fb4bc5f0 519 */
nexpaq 0:6c56fb4bc5f0 520 is_pem = 1;
nexpaq 0:6c56fb4bc5f0 521
nexpaq 0:6c56fb4bc5f0 522 buflen -= use_len;
nexpaq 0:6c56fb4bc5f0 523 buf += use_len;
nexpaq 0:6c56fb4bc5f0 524
nexpaq 0:6c56fb4bc5f0 525 if( ( ret = mbedtls_x509_crl_parse_der( chain,
nexpaq 0:6c56fb4bc5f0 526 pem.buf, pem.buflen ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 527 {
nexpaq 0:6c56fb4bc5f0 528 return( ret );
nexpaq 0:6c56fb4bc5f0 529 }
nexpaq 0:6c56fb4bc5f0 530
nexpaq 0:6c56fb4bc5f0 531 mbedtls_pem_free( &pem );
nexpaq 0:6c56fb4bc5f0 532 }
nexpaq 0:6c56fb4bc5f0 533 else if( ret != MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT )
nexpaq 0:6c56fb4bc5f0 534 {
nexpaq 0:6c56fb4bc5f0 535 mbedtls_pem_free( &pem );
nexpaq 0:6c56fb4bc5f0 536 return( ret );
nexpaq 0:6c56fb4bc5f0 537 }
nexpaq 0:6c56fb4bc5f0 538 }
nexpaq 0:6c56fb4bc5f0 539 /* In the PEM case, buflen is 1 at the end, for the terminated NULL byte.
nexpaq 0:6c56fb4bc5f0 540 * And a valid CRL cannot be less than 1 byte anyway. */
nexpaq 0:6c56fb4bc5f0 541 while( is_pem && buflen > 1 );
nexpaq 0:6c56fb4bc5f0 542
nexpaq 0:6c56fb4bc5f0 543 if( is_pem )
nexpaq 0:6c56fb4bc5f0 544 return( 0 );
nexpaq 0:6c56fb4bc5f0 545 else
nexpaq 0:6c56fb4bc5f0 546 #endif /* MBEDTLS_PEM_PARSE_C */
nexpaq 0:6c56fb4bc5f0 547 return( mbedtls_x509_crl_parse_der( chain, buf, buflen ) );
nexpaq 0:6c56fb4bc5f0 548 }
nexpaq 0:6c56fb4bc5f0 549
nexpaq 0:6c56fb4bc5f0 550 #if defined(MBEDTLS_FS_IO)
nexpaq 0:6c56fb4bc5f0 551 /*
nexpaq 0:6c56fb4bc5f0 552 * Load one or more CRLs and add them to the chained list
nexpaq 0:6c56fb4bc5f0 553 */
nexpaq 0:6c56fb4bc5f0 554 int mbedtls_x509_crl_parse_file( mbedtls_x509_crl *chain, const char *path )
nexpaq 0:6c56fb4bc5f0 555 {
nexpaq 0:6c56fb4bc5f0 556 int ret;
nexpaq 0:6c56fb4bc5f0 557 size_t n;
nexpaq 0:6c56fb4bc5f0 558 unsigned char *buf;
nexpaq 0:6c56fb4bc5f0 559
nexpaq 0:6c56fb4bc5f0 560 if( ( ret = mbedtls_pk_load_file( path, &buf, &n ) ) != 0 )
nexpaq 0:6c56fb4bc5f0 561 return( ret );
nexpaq 0:6c56fb4bc5f0 562
nexpaq 0:6c56fb4bc5f0 563 ret = mbedtls_x509_crl_parse( chain, buf, n );
nexpaq 0:6c56fb4bc5f0 564
nexpaq 0:6c56fb4bc5f0 565 mbedtls_zeroize( buf, n );
nexpaq 0:6c56fb4bc5f0 566 mbedtls_free( buf );
nexpaq 0:6c56fb4bc5f0 567
nexpaq 0:6c56fb4bc5f0 568 return( ret );
nexpaq 0:6c56fb4bc5f0 569 }
nexpaq 0:6c56fb4bc5f0 570 #endif /* MBEDTLS_FS_IO */
nexpaq 0:6c56fb4bc5f0 571
nexpaq 0:6c56fb4bc5f0 572 /*
nexpaq 0:6c56fb4bc5f0 573 * Return an informational string about the certificate.
nexpaq 0:6c56fb4bc5f0 574 */
nexpaq 0:6c56fb4bc5f0 575 #define BEFORE_COLON 14
nexpaq 0:6c56fb4bc5f0 576 #define BC "14"
nexpaq 0:6c56fb4bc5f0 577 /*
nexpaq 0:6c56fb4bc5f0 578 * Return an informational string about the CRL.
nexpaq 0:6c56fb4bc5f0 579 */
nexpaq 0:6c56fb4bc5f0 580 int mbedtls_x509_crl_info( char *buf, size_t size, const char *prefix,
nexpaq 0:6c56fb4bc5f0 581 const mbedtls_x509_crl *crl )
nexpaq 0:6c56fb4bc5f0 582 {
nexpaq 0:6c56fb4bc5f0 583 int ret;
nexpaq 0:6c56fb4bc5f0 584 size_t n;
nexpaq 0:6c56fb4bc5f0 585 char *p;
nexpaq 0:6c56fb4bc5f0 586 const mbedtls_x509_crl_entry *entry;
nexpaq 0:6c56fb4bc5f0 587
nexpaq 0:6c56fb4bc5f0 588 p = buf;
nexpaq 0:6c56fb4bc5f0 589 n = size;
nexpaq 0:6c56fb4bc5f0 590
nexpaq 0:6c56fb4bc5f0 591 ret = mbedtls_snprintf( p, n, "%sCRL version : %d",
nexpaq 0:6c56fb4bc5f0 592 prefix, crl->version );
nexpaq 0:6c56fb4bc5f0 593 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 594
nexpaq 0:6c56fb4bc5f0 595 ret = mbedtls_snprintf( p, n, "\n%sissuer name : ", prefix );
nexpaq 0:6c56fb4bc5f0 596 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 597 ret = mbedtls_x509_dn_gets( p, n, &crl->issuer );
nexpaq 0:6c56fb4bc5f0 598 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 599
nexpaq 0:6c56fb4bc5f0 600 ret = mbedtls_snprintf( p, n, "\n%sthis update : " \
nexpaq 0:6c56fb4bc5f0 601 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
nexpaq 0:6c56fb4bc5f0 602 crl->this_update.year, crl->this_update.mon,
nexpaq 0:6c56fb4bc5f0 603 crl->this_update.day, crl->this_update.hour,
nexpaq 0:6c56fb4bc5f0 604 crl->this_update.min, crl->this_update.sec );
nexpaq 0:6c56fb4bc5f0 605 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 606
nexpaq 0:6c56fb4bc5f0 607 ret = mbedtls_snprintf( p, n, "\n%snext update : " \
nexpaq 0:6c56fb4bc5f0 608 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
nexpaq 0:6c56fb4bc5f0 609 crl->next_update.year, crl->next_update.mon,
nexpaq 0:6c56fb4bc5f0 610 crl->next_update.day, crl->next_update.hour,
nexpaq 0:6c56fb4bc5f0 611 crl->next_update.min, crl->next_update.sec );
nexpaq 0:6c56fb4bc5f0 612 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 613
nexpaq 0:6c56fb4bc5f0 614 entry = &crl->entry;
nexpaq 0:6c56fb4bc5f0 615
nexpaq 0:6c56fb4bc5f0 616 ret = mbedtls_snprintf( p, n, "\n%sRevoked certificates:",
nexpaq 0:6c56fb4bc5f0 617 prefix );
nexpaq 0:6c56fb4bc5f0 618 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 619
nexpaq 0:6c56fb4bc5f0 620 while( entry != NULL && entry->raw.len != 0 )
nexpaq 0:6c56fb4bc5f0 621 {
nexpaq 0:6c56fb4bc5f0 622 ret = mbedtls_snprintf( p, n, "\n%sserial number: ",
nexpaq 0:6c56fb4bc5f0 623 prefix );
nexpaq 0:6c56fb4bc5f0 624 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 625
nexpaq 0:6c56fb4bc5f0 626 ret = mbedtls_x509_serial_gets( p, n, &entry->serial );
nexpaq 0:6c56fb4bc5f0 627 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 628
nexpaq 0:6c56fb4bc5f0 629 ret = mbedtls_snprintf( p, n, " revocation date: " \
nexpaq 0:6c56fb4bc5f0 630 "%04d-%02d-%02d %02d:%02d:%02d",
nexpaq 0:6c56fb4bc5f0 631 entry->revocation_date.year, entry->revocation_date.mon,
nexpaq 0:6c56fb4bc5f0 632 entry->revocation_date.day, entry->revocation_date.hour,
nexpaq 0:6c56fb4bc5f0 633 entry->revocation_date.min, entry->revocation_date.sec );
nexpaq 0:6c56fb4bc5f0 634 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 635
nexpaq 0:6c56fb4bc5f0 636 entry = entry->next;
nexpaq 0:6c56fb4bc5f0 637 }
nexpaq 0:6c56fb4bc5f0 638
nexpaq 0:6c56fb4bc5f0 639 ret = mbedtls_snprintf( p, n, "\n%ssigned using : ", prefix );
nexpaq 0:6c56fb4bc5f0 640 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 641
nexpaq 0:6c56fb4bc5f0 642 ret = mbedtls_x509_sig_alg_gets( p, n, &crl->sig_oid, crl->sig_pk, crl->sig_md,
nexpaq 0:6c56fb4bc5f0 643 crl->sig_opts );
nexpaq 0:6c56fb4bc5f0 644 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 645
nexpaq 0:6c56fb4bc5f0 646 ret = mbedtls_snprintf( p, n, "\n" );
nexpaq 0:6c56fb4bc5f0 647 MBEDTLS_X509_SAFE_SNPRINTF;
nexpaq 0:6c56fb4bc5f0 648
nexpaq 0:6c56fb4bc5f0 649 return( (int) ( size - n ) );
nexpaq 0:6c56fb4bc5f0 650 }
nexpaq 0:6c56fb4bc5f0 651
nexpaq 0:6c56fb4bc5f0 652 /*
nexpaq 0:6c56fb4bc5f0 653 * Initialize a CRL chain
nexpaq 0:6c56fb4bc5f0 654 */
nexpaq 0:6c56fb4bc5f0 655 void mbedtls_x509_crl_init( mbedtls_x509_crl *crl )
nexpaq 0:6c56fb4bc5f0 656 {
nexpaq 0:6c56fb4bc5f0 657 memset( crl, 0, sizeof(mbedtls_x509_crl) );
nexpaq 0:6c56fb4bc5f0 658 }
nexpaq 0:6c56fb4bc5f0 659
nexpaq 0:6c56fb4bc5f0 660 /*
nexpaq 0:6c56fb4bc5f0 661 * Unallocate all CRL data
nexpaq 0:6c56fb4bc5f0 662 */
nexpaq 0:6c56fb4bc5f0 663 void mbedtls_x509_crl_free( mbedtls_x509_crl *crl )
nexpaq 0:6c56fb4bc5f0 664 {
nexpaq 0:6c56fb4bc5f0 665 mbedtls_x509_crl *crl_cur = crl;
nexpaq 0:6c56fb4bc5f0 666 mbedtls_x509_crl *crl_prv;
nexpaq 0:6c56fb4bc5f0 667 mbedtls_x509_name *name_cur;
nexpaq 0:6c56fb4bc5f0 668 mbedtls_x509_name *name_prv;
nexpaq 0:6c56fb4bc5f0 669 mbedtls_x509_crl_entry *entry_cur;
nexpaq 0:6c56fb4bc5f0 670 mbedtls_x509_crl_entry *entry_prv;
nexpaq 0:6c56fb4bc5f0 671
nexpaq 0:6c56fb4bc5f0 672 if( crl == NULL )
nexpaq 0:6c56fb4bc5f0 673 return;
nexpaq 0:6c56fb4bc5f0 674
nexpaq 0:6c56fb4bc5f0 675 do
nexpaq 0:6c56fb4bc5f0 676 {
nexpaq 0:6c56fb4bc5f0 677 #if defined(MBEDTLS_X509_RSASSA_PSS_SUPPORT)
nexpaq 0:6c56fb4bc5f0 678 mbedtls_free( crl_cur->sig_opts );
nexpaq 0:6c56fb4bc5f0 679 #endif
nexpaq 0:6c56fb4bc5f0 680
nexpaq 0:6c56fb4bc5f0 681 name_cur = crl_cur->issuer.next;
nexpaq 0:6c56fb4bc5f0 682 while( name_cur != NULL )
nexpaq 0:6c56fb4bc5f0 683 {
nexpaq 0:6c56fb4bc5f0 684 name_prv = name_cur;
nexpaq 0:6c56fb4bc5f0 685 name_cur = name_cur->next;
nexpaq 0:6c56fb4bc5f0 686 mbedtls_zeroize( name_prv, sizeof( mbedtls_x509_name ) );
nexpaq 0:6c56fb4bc5f0 687 mbedtls_free( name_prv );
nexpaq 0:6c56fb4bc5f0 688 }
nexpaq 0:6c56fb4bc5f0 689
nexpaq 0:6c56fb4bc5f0 690 entry_cur = crl_cur->entry.next;
nexpaq 0:6c56fb4bc5f0 691 while( entry_cur != NULL )
nexpaq 0:6c56fb4bc5f0 692 {
nexpaq 0:6c56fb4bc5f0 693 entry_prv = entry_cur;
nexpaq 0:6c56fb4bc5f0 694 entry_cur = entry_cur->next;
nexpaq 0:6c56fb4bc5f0 695 mbedtls_zeroize( entry_prv, sizeof( mbedtls_x509_crl_entry ) );
nexpaq 0:6c56fb4bc5f0 696 mbedtls_free( entry_prv );
nexpaq 0:6c56fb4bc5f0 697 }
nexpaq 0:6c56fb4bc5f0 698
nexpaq 0:6c56fb4bc5f0 699 if( crl_cur->raw.p != NULL )
nexpaq 0:6c56fb4bc5f0 700 {
nexpaq 0:6c56fb4bc5f0 701 mbedtls_zeroize( crl_cur->raw.p, crl_cur->raw.len );
nexpaq 0:6c56fb4bc5f0 702 mbedtls_free( crl_cur->raw.p );
nexpaq 0:6c56fb4bc5f0 703 }
nexpaq 0:6c56fb4bc5f0 704
nexpaq 0:6c56fb4bc5f0 705 crl_cur = crl_cur->next;
nexpaq 0:6c56fb4bc5f0 706 }
nexpaq 0:6c56fb4bc5f0 707 while( crl_cur != NULL );
nexpaq 0:6c56fb4bc5f0 708
nexpaq 0:6c56fb4bc5f0 709 crl_cur = crl;
nexpaq 0:6c56fb4bc5f0 710 do
nexpaq 0:6c56fb4bc5f0 711 {
nexpaq 0:6c56fb4bc5f0 712 crl_prv = crl_cur;
nexpaq 0:6c56fb4bc5f0 713 crl_cur = crl_cur->next;
nexpaq 0:6c56fb4bc5f0 714
nexpaq 0:6c56fb4bc5f0 715 mbedtls_zeroize( crl_prv, sizeof( mbedtls_x509_crl ) );
nexpaq 0:6c56fb4bc5f0 716 if( crl_prv != crl )
nexpaq 0:6c56fb4bc5f0 717 mbedtls_free( crl_prv );
nexpaq 0:6c56fb4bc5f0 718 }
nexpaq 0:6c56fb4bc5f0 719 while( crl_cur != NULL );
nexpaq 0:6c56fb4bc5f0 720 }
nexpaq 0:6c56fb4bc5f0 721
nexpaq 0:6c56fb4bc5f0 722 #endif /* MBEDTLS_X509_CRL_PARSE_C */