Greg Steiert / pegasus_dev

Dependents:   blinky_max32630fthr

Committer:
switches
Date:
Fri Nov 11 20:59:50 2016 +0000
Revision:
0:5c4d7b2438d3
Initial commit

Who changed what in which revision?

UserRevisionLine numberNew contents of line
switches 0:5c4d7b2438d3 1 /*
switches 0:5c4d7b2438d3 2 * X.509 Certidicate Revocation List (CRL) parsing
switches 0:5c4d7b2438d3 3 *
switches 0:5c4d7b2438d3 4 * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
switches 0:5c4d7b2438d3 5 * SPDX-License-Identifier: Apache-2.0
switches 0:5c4d7b2438d3 6 *
switches 0:5c4d7b2438d3 7 * Licensed under the Apache License, Version 2.0 (the "License"); you may
switches 0:5c4d7b2438d3 8 * not use this file except in compliance with the License.
switches 0:5c4d7b2438d3 9 * You may obtain a copy of the License at
switches 0:5c4d7b2438d3 10 *
switches 0:5c4d7b2438d3 11 * http://www.apache.org/licenses/LICENSE-2.0
switches 0:5c4d7b2438d3 12 *
switches 0:5c4d7b2438d3 13 * Unless required by applicable law or agreed to in writing, software
switches 0:5c4d7b2438d3 14 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
switches 0:5c4d7b2438d3 15 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
switches 0:5c4d7b2438d3 16 * See the License for the specific language governing permissions and
switches 0:5c4d7b2438d3 17 * limitations under the License.
switches 0:5c4d7b2438d3 18 *
switches 0:5c4d7b2438d3 19 * This file is part of mbed TLS (https://tls.mbed.org)
switches 0:5c4d7b2438d3 20 */
switches 0:5c4d7b2438d3 21 /*
switches 0:5c4d7b2438d3 22 * The ITU-T X.509 standard defines a certificate format for PKI.
switches 0:5c4d7b2438d3 23 *
switches 0:5c4d7b2438d3 24 * http://www.ietf.org/rfc/rfc5280.txt (Certificates and CRLs)
switches 0:5c4d7b2438d3 25 * http://www.ietf.org/rfc/rfc3279.txt (Alg IDs for CRLs)
switches 0:5c4d7b2438d3 26 * http://www.ietf.org/rfc/rfc2986.txt (CSRs, aka PKCS#10)
switches 0:5c4d7b2438d3 27 *
switches 0:5c4d7b2438d3 28 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.680-0207.pdf
switches 0:5c4d7b2438d3 29 * http://www.itu.int/ITU-T/studygroups/com17/languages/X.690-0207.pdf
switches 0:5c4d7b2438d3 30 */
switches 0:5c4d7b2438d3 31
switches 0:5c4d7b2438d3 32 #if !defined(MBEDTLS_CONFIG_FILE)
switches 0:5c4d7b2438d3 33 #include "mbedtls/config.h"
switches 0:5c4d7b2438d3 34 #else
switches 0:5c4d7b2438d3 35 #include MBEDTLS_CONFIG_FILE
switches 0:5c4d7b2438d3 36 #endif
switches 0:5c4d7b2438d3 37
switches 0:5c4d7b2438d3 38 #if defined(MBEDTLS_X509_CRL_PARSE_C)
switches 0:5c4d7b2438d3 39
switches 0:5c4d7b2438d3 40 #include "mbedtls/x509_crl.h"
switches 0:5c4d7b2438d3 41 #include "mbedtls/oid.h"
switches 0:5c4d7b2438d3 42
switches 0:5c4d7b2438d3 43 #include <string.h>
switches 0:5c4d7b2438d3 44
switches 0:5c4d7b2438d3 45 #if defined(MBEDTLS_PEM_PARSE_C)
switches 0:5c4d7b2438d3 46 #include "mbedtls/pem.h"
switches 0:5c4d7b2438d3 47 #endif
switches 0:5c4d7b2438d3 48
switches 0:5c4d7b2438d3 49 #if defined(MBEDTLS_PLATFORM_C)
switches 0:5c4d7b2438d3 50 #include "mbedtls/platform.h"
switches 0:5c4d7b2438d3 51 #else
switches 0:5c4d7b2438d3 52 #include <stdlib.h>
switches 0:5c4d7b2438d3 53 #include <stdio.h>
switches 0:5c4d7b2438d3 54 #define mbedtls_free free
switches 0:5c4d7b2438d3 55 #define mbedtls_calloc calloc
switches 0:5c4d7b2438d3 56 #define mbedtls_snprintf snprintf
switches 0:5c4d7b2438d3 57 #endif
switches 0:5c4d7b2438d3 58
switches 0:5c4d7b2438d3 59 #if defined(_WIN32) && !defined(EFIX64) && !defined(EFI32)
switches 0:5c4d7b2438d3 60 #include <windows.h>
switches 0:5c4d7b2438d3 61 #else
switches 0:5c4d7b2438d3 62 #include <time.h>
switches 0:5c4d7b2438d3 63 #endif
switches 0:5c4d7b2438d3 64
switches 0:5c4d7b2438d3 65 #if defined(MBEDTLS_FS_IO) || defined(EFIX64) || defined(EFI32)
switches 0:5c4d7b2438d3 66 #include <stdio.h>
switches 0:5c4d7b2438d3 67 #endif
switches 0:5c4d7b2438d3 68
switches 0:5c4d7b2438d3 69 /* Implementation that should never be optimized out by the compiler */
switches 0:5c4d7b2438d3 70 static void mbedtls_zeroize( void *v, size_t n ) {
switches 0:5c4d7b2438d3 71 volatile unsigned char *p = v; while( n-- ) *p++ = 0;
switches 0:5c4d7b2438d3 72 }
switches 0:5c4d7b2438d3 73
switches 0:5c4d7b2438d3 74 /*
switches 0:5c4d7b2438d3 75 * Version ::= INTEGER { v1(0), v2(1) }
switches 0:5c4d7b2438d3 76 */
switches 0:5c4d7b2438d3 77 static int x509_crl_get_version( unsigned char **p,
switches 0:5c4d7b2438d3 78 const unsigned char *end,
switches 0:5c4d7b2438d3 79 int *ver )
switches 0:5c4d7b2438d3 80 {
switches 0:5c4d7b2438d3 81 int ret;
switches 0:5c4d7b2438d3 82
switches 0:5c4d7b2438d3 83 if( ( ret = mbedtls_asn1_get_int( p, end, ver ) ) != 0 )
switches 0:5c4d7b2438d3 84 {
switches 0:5c4d7b2438d3 85 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
switches 0:5c4d7b2438d3 86 {
switches 0:5c4d7b2438d3 87 *ver = 0;
switches 0:5c4d7b2438d3 88 return( 0 );
switches 0:5c4d7b2438d3 89 }
switches 0:5c4d7b2438d3 90
switches 0:5c4d7b2438d3 91 return( MBEDTLS_ERR_X509_INVALID_VERSION + ret );
switches 0:5c4d7b2438d3 92 }
switches 0:5c4d7b2438d3 93
switches 0:5c4d7b2438d3 94 return( 0 );
switches 0:5c4d7b2438d3 95 }
switches 0:5c4d7b2438d3 96
switches 0:5c4d7b2438d3 97 /*
switches 0:5c4d7b2438d3 98 * X.509 CRL v2 extensions (no extensions parsed yet.)
switches 0:5c4d7b2438d3 99 */
switches 0:5c4d7b2438d3 100 static int x509_get_crl_ext( unsigned char **p,
switches 0:5c4d7b2438d3 101 const unsigned char *end,
switches 0:5c4d7b2438d3 102 mbedtls_x509_buf *ext )
switches 0:5c4d7b2438d3 103 {
switches 0:5c4d7b2438d3 104 int ret;
switches 0:5c4d7b2438d3 105 size_t len = 0;
switches 0:5c4d7b2438d3 106
switches 0:5c4d7b2438d3 107 /* Get explicit tag */
switches 0:5c4d7b2438d3 108 if( ( ret = mbedtls_x509_get_ext( p, end, ext, 0) ) != 0 )
switches 0:5c4d7b2438d3 109 {
switches 0:5c4d7b2438d3 110 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
switches 0:5c4d7b2438d3 111 return( 0 );
switches 0:5c4d7b2438d3 112
switches 0:5c4d7b2438d3 113 return( ret );
switches 0:5c4d7b2438d3 114 }
switches 0:5c4d7b2438d3 115
switches 0:5c4d7b2438d3 116 while( *p < end )
switches 0:5c4d7b2438d3 117 {
switches 0:5c4d7b2438d3 118 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
switches 0:5c4d7b2438d3 119 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
switches 0:5c4d7b2438d3 120 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
switches 0:5c4d7b2438d3 121
switches 0:5c4d7b2438d3 122 *p += len;
switches 0:5c4d7b2438d3 123 }
switches 0:5c4d7b2438d3 124
switches 0:5c4d7b2438d3 125 if( *p != end )
switches 0:5c4d7b2438d3 126 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
switches 0:5c4d7b2438d3 127 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
switches 0:5c4d7b2438d3 128
switches 0:5c4d7b2438d3 129 return( 0 );
switches 0:5c4d7b2438d3 130 }
switches 0:5c4d7b2438d3 131
switches 0:5c4d7b2438d3 132 /*
switches 0:5c4d7b2438d3 133 * X.509 CRL v2 entry extensions (no extensions parsed yet.)
switches 0:5c4d7b2438d3 134 */
switches 0:5c4d7b2438d3 135 static int x509_get_crl_entry_ext( unsigned char **p,
switches 0:5c4d7b2438d3 136 const unsigned char *end,
switches 0:5c4d7b2438d3 137 mbedtls_x509_buf *ext )
switches 0:5c4d7b2438d3 138 {
switches 0:5c4d7b2438d3 139 int ret;
switches 0:5c4d7b2438d3 140 size_t len = 0;
switches 0:5c4d7b2438d3 141
switches 0:5c4d7b2438d3 142 /* OPTIONAL */
switches 0:5c4d7b2438d3 143 if( end <= *p )
switches 0:5c4d7b2438d3 144 return( 0 );
switches 0:5c4d7b2438d3 145
switches 0:5c4d7b2438d3 146 ext->tag = **p;
switches 0:5c4d7b2438d3 147 ext->p = *p;
switches 0:5c4d7b2438d3 148
switches 0:5c4d7b2438d3 149 /*
switches 0:5c4d7b2438d3 150 * Get CRL-entry extension sequence header
switches 0:5c4d7b2438d3 151 * crlEntryExtensions Extensions OPTIONAL -- if present, MUST be v2
switches 0:5c4d7b2438d3 152 */
switches 0:5c4d7b2438d3 153 if( ( ret = mbedtls_asn1_get_tag( p, end, &ext->len,
switches 0:5c4d7b2438d3 154 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
switches 0:5c4d7b2438d3 155 {
switches 0:5c4d7b2438d3 156 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
switches 0:5c4d7b2438d3 157 {
switches 0:5c4d7b2438d3 158 ext->p = NULL;
switches 0:5c4d7b2438d3 159 return( 0 );
switches 0:5c4d7b2438d3 160 }
switches 0:5c4d7b2438d3 161 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
switches 0:5c4d7b2438d3 162 }
switches 0:5c4d7b2438d3 163
switches 0:5c4d7b2438d3 164 end = *p + ext->len;
switches 0:5c4d7b2438d3 165
switches 0:5c4d7b2438d3 166 if( end != *p + ext->len )
switches 0:5c4d7b2438d3 167 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
switches 0:5c4d7b2438d3 168 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
switches 0:5c4d7b2438d3 169
switches 0:5c4d7b2438d3 170 while( *p < end )
switches 0:5c4d7b2438d3 171 {
switches 0:5c4d7b2438d3 172 if( ( ret = mbedtls_asn1_get_tag( p, end, &len,
switches 0:5c4d7b2438d3 173 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
switches 0:5c4d7b2438d3 174 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS + ret );
switches 0:5c4d7b2438d3 175
switches 0:5c4d7b2438d3 176 *p += len;
switches 0:5c4d7b2438d3 177 }
switches 0:5c4d7b2438d3 178
switches 0:5c4d7b2438d3 179 if( *p != end )
switches 0:5c4d7b2438d3 180 return( MBEDTLS_ERR_X509_INVALID_EXTENSIONS +
switches 0:5c4d7b2438d3 181 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
switches 0:5c4d7b2438d3 182
switches 0:5c4d7b2438d3 183 return( 0 );
switches 0:5c4d7b2438d3 184 }
switches 0:5c4d7b2438d3 185
switches 0:5c4d7b2438d3 186 /*
switches 0:5c4d7b2438d3 187 * X.509 CRL Entries
switches 0:5c4d7b2438d3 188 */
switches 0:5c4d7b2438d3 189 static int x509_get_entries( unsigned char **p,
switches 0:5c4d7b2438d3 190 const unsigned char *end,
switches 0:5c4d7b2438d3 191 mbedtls_x509_crl_entry *entry )
switches 0:5c4d7b2438d3 192 {
switches 0:5c4d7b2438d3 193 int ret;
switches 0:5c4d7b2438d3 194 size_t entry_len;
switches 0:5c4d7b2438d3 195 mbedtls_x509_crl_entry *cur_entry = entry;
switches 0:5c4d7b2438d3 196
switches 0:5c4d7b2438d3 197 if( *p == end )
switches 0:5c4d7b2438d3 198 return( 0 );
switches 0:5c4d7b2438d3 199
switches 0:5c4d7b2438d3 200 if( ( ret = mbedtls_asn1_get_tag( p, end, &entry_len,
switches 0:5c4d7b2438d3 201 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
switches 0:5c4d7b2438d3 202 {
switches 0:5c4d7b2438d3 203 if( ret == MBEDTLS_ERR_ASN1_UNEXPECTED_TAG )
switches 0:5c4d7b2438d3 204 return( 0 );
switches 0:5c4d7b2438d3 205
switches 0:5c4d7b2438d3 206 return( ret );
switches 0:5c4d7b2438d3 207 }
switches 0:5c4d7b2438d3 208
switches 0:5c4d7b2438d3 209 end = *p + entry_len;
switches 0:5c4d7b2438d3 210
switches 0:5c4d7b2438d3 211 while( *p < end )
switches 0:5c4d7b2438d3 212 {
switches 0:5c4d7b2438d3 213 size_t len2;
switches 0:5c4d7b2438d3 214 const unsigned char *end2;
switches 0:5c4d7b2438d3 215
switches 0:5c4d7b2438d3 216 if( ( ret = mbedtls_asn1_get_tag( p, end, &len2,
switches 0:5c4d7b2438d3 217 MBEDTLS_ASN1_SEQUENCE | MBEDTLS_ASN1_CONSTRUCTED ) ) != 0 )
switches 0:5c4d7b2438d3 218 {
switches 0:5c4d7b2438d3 219 return( ret );
switches 0:5c4d7b2438d3 220 }
switches 0:5c4d7b2438d3 221
switches 0:5c4d7b2438d3 222 cur_entry->raw.tag = **p;
switches 0:5c4d7b2438d3 223 cur_entry->raw.p = *p;
switches 0:5c4d7b2438d3 224 cur_entry->raw.len = len2;
switches 0:5c4d7b2438d3 225 end2 = *p + len2;
switches 0:5c4d7b2438d3 226
switches 0:5c4d7b2438d3 227 if( ( ret = mbedtls_x509_get_serial( p, end2, &cur_entry->serial ) ) != 0 )
switches 0:5c4d7b2438d3 228 return( ret );
switches 0:5c4d7b2438d3 229
switches 0:5c4d7b2438d3 230 if( ( ret = mbedtls_x509_get_time( p, end2,
switches 0:5c4d7b2438d3 231 &cur_entry->revocation_date ) ) != 0 )
switches 0:5c4d7b2438d3 232 return( ret );
switches 0:5c4d7b2438d3 233
switches 0:5c4d7b2438d3 234 if( ( ret = x509_get_crl_entry_ext( p, end2,
switches 0:5c4d7b2438d3 235 &cur_entry->entry_ext ) ) != 0 )
switches 0:5c4d7b2438d3 236 return( ret );
switches 0:5c4d7b2438d3 237
switches 0:5c4d7b2438d3 238 if( *p < end )
switches 0:5c4d7b2438d3 239 {
switches 0:5c4d7b2438d3 240 cur_entry->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl_entry ) );
switches 0:5c4d7b2438d3 241
switches 0:5c4d7b2438d3 242 if( cur_entry->next == NULL )
switches 0:5c4d7b2438d3 243 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
switches 0:5c4d7b2438d3 244
switches 0:5c4d7b2438d3 245 cur_entry = cur_entry->next;
switches 0:5c4d7b2438d3 246 }
switches 0:5c4d7b2438d3 247 }
switches 0:5c4d7b2438d3 248
switches 0:5c4d7b2438d3 249 return( 0 );
switches 0:5c4d7b2438d3 250 }
switches 0:5c4d7b2438d3 251
switches 0:5c4d7b2438d3 252 /*
switches 0:5c4d7b2438d3 253 * Parse one CRLs in DER format and append it to the chained list
switches 0:5c4d7b2438d3 254 */
switches 0:5c4d7b2438d3 255 int mbedtls_x509_crl_parse_der( mbedtls_x509_crl *chain,
switches 0:5c4d7b2438d3 256 const unsigned char *buf, size_t buflen )
switches 0:5c4d7b2438d3 257 {
switches 0:5c4d7b2438d3 258 int ret;
switches 0:5c4d7b2438d3 259 size_t len;
switches 0:5c4d7b2438d3 260 unsigned char *p, *end;
switches 0:5c4d7b2438d3 261 mbedtls_x509_buf sig_params1, sig_params2, sig_oid2;
switches 0:5c4d7b2438d3 262 mbedtls_x509_crl *crl = chain;
switches 0:5c4d7b2438d3 263
switches 0:5c4d7b2438d3 264 /*
switches 0:5c4d7b2438d3 265 * Check for valid input
switches 0:5c4d7b2438d3 266 */
switches 0:5c4d7b2438d3 267 if( crl == NULL || buf == NULL )
switches 0:5c4d7b2438d3 268 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
switches 0:5c4d7b2438d3 269
switches 0:5c4d7b2438d3 270 memset( &sig_params1, 0, sizeof( mbedtls_x509_buf ) );
switches 0:5c4d7b2438d3 271 memset( &sig_params2, 0, sizeof( mbedtls_x509_buf ) );
switches 0:5c4d7b2438d3 272 memset( &sig_oid2, 0, sizeof( mbedtls_x509_buf ) );
switches 0:5c4d7b2438d3 273
switches 0:5c4d7b2438d3 274 /*
switches 0:5c4d7b2438d3 275 * Add new CRL on the end of the chain if needed.
switches 0:5c4d7b2438d3 276 */
switches 0:5c4d7b2438d3 277 while( crl->version != 0 && crl->next != NULL )
switches 0:5c4d7b2438d3 278 crl = crl->next;
switches 0:5c4d7b2438d3 279
switches 0:5c4d7b2438d3 280 if( crl->version != 0 && crl->next == NULL )
switches 0:5c4d7b2438d3 281 {
switches 0:5c4d7b2438d3 282 crl->next = mbedtls_calloc( 1, sizeof( mbedtls_x509_crl ) );
switches 0:5c4d7b2438d3 283
switches 0:5c4d7b2438d3 284 if( crl->next == NULL )
switches 0:5c4d7b2438d3 285 {
switches 0:5c4d7b2438d3 286 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 287 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
switches 0:5c4d7b2438d3 288 }
switches 0:5c4d7b2438d3 289
switches 0:5c4d7b2438d3 290 mbedtls_x509_crl_init( crl->next );
switches 0:5c4d7b2438d3 291 crl = crl->next;
switches 0:5c4d7b2438d3 292 }
switches 0:5c4d7b2438d3 293
switches 0:5c4d7b2438d3 294 /*
switches 0:5c4d7b2438d3 295 * Copy raw DER-encoded CRL
switches 0:5c4d7b2438d3 296 */
switches 0:5c4d7b2438d3 297 if( ( p = mbedtls_calloc( 1, buflen ) ) == NULL )
switches 0:5c4d7b2438d3 298 return( MBEDTLS_ERR_X509_ALLOC_FAILED );
switches 0:5c4d7b2438d3 299
switches 0:5c4d7b2438d3 300 memcpy( p, buf, buflen );
switches 0:5c4d7b2438d3 301
switches 0:5c4d7b2438d3 302 crl->raw.p = p;
switches 0:5c4d7b2438d3 303 crl->raw.len = buflen;
switches 0:5c4d7b2438d3 304
switches 0:5c4d7b2438d3 305 end = p + buflen;
switches 0:5c4d7b2438d3 306
switches 0:5c4d7b2438d3 307 /*
switches 0:5c4d7b2438d3 308 * CertificateList ::= SEQUENCE {
switches 0:5c4d7b2438d3 309 * tbsCertList TBSCertList,
switches 0:5c4d7b2438d3 310 * signatureAlgorithm AlgorithmIdentifier,
switches 0:5c4d7b2438d3 311 * signatureValue BIT STRING }
switches 0:5c4d7b2438d3 312 */
switches 0:5c4d7b2438d3 313 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
switches 0:5c4d7b2438d3 314 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
switches 0:5c4d7b2438d3 315 {
switches 0:5c4d7b2438d3 316 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 317 return( MBEDTLS_ERR_X509_INVALID_FORMAT );
switches 0:5c4d7b2438d3 318 }
switches 0:5c4d7b2438d3 319
switches 0:5c4d7b2438d3 320 if( len != (size_t) ( end - p ) )
switches 0:5c4d7b2438d3 321 {
switches 0:5c4d7b2438d3 322 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 323 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
switches 0:5c4d7b2438d3 324 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
switches 0:5c4d7b2438d3 325 }
switches 0:5c4d7b2438d3 326
switches 0:5c4d7b2438d3 327 /*
switches 0:5c4d7b2438d3 328 * TBSCertList ::= SEQUENCE {
switches 0:5c4d7b2438d3 329 */
switches 0:5c4d7b2438d3 330 crl->tbs.p = p;
switches 0:5c4d7b2438d3 331
switches 0:5c4d7b2438d3 332 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
switches 0:5c4d7b2438d3 333 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
switches 0:5c4d7b2438d3 334 {
switches 0:5c4d7b2438d3 335 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 336 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
switches 0:5c4d7b2438d3 337 }
switches 0:5c4d7b2438d3 338
switches 0:5c4d7b2438d3 339 end = p + len;
switches 0:5c4d7b2438d3 340 crl->tbs.len = end - crl->tbs.p;
switches 0:5c4d7b2438d3 341
switches 0:5c4d7b2438d3 342 /*
switches 0:5c4d7b2438d3 343 * Version ::= INTEGER OPTIONAL { v1(0), v2(1) }
switches 0:5c4d7b2438d3 344 * -- if present, MUST be v2
switches 0:5c4d7b2438d3 345 *
switches 0:5c4d7b2438d3 346 * signature AlgorithmIdentifier
switches 0:5c4d7b2438d3 347 */
switches 0:5c4d7b2438d3 348 if( ( ret = x509_crl_get_version( &p, end, &crl->version ) ) != 0 ||
switches 0:5c4d7b2438d3 349 ( ret = mbedtls_x509_get_alg( &p, end, &crl->sig_oid, &sig_params1 ) ) != 0 )
switches 0:5c4d7b2438d3 350 {
switches 0:5c4d7b2438d3 351 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 352 return( ret );
switches 0:5c4d7b2438d3 353 }
switches 0:5c4d7b2438d3 354
switches 0:5c4d7b2438d3 355 crl->version++;
switches 0:5c4d7b2438d3 356
switches 0:5c4d7b2438d3 357 if( crl->version > 2 )
switches 0:5c4d7b2438d3 358 {
switches 0:5c4d7b2438d3 359 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 360 return( MBEDTLS_ERR_X509_UNKNOWN_VERSION );
switches 0:5c4d7b2438d3 361 }
switches 0:5c4d7b2438d3 362
switches 0:5c4d7b2438d3 363 if( ( ret = mbedtls_x509_get_sig_alg( &crl->sig_oid, &sig_params1,
switches 0:5c4d7b2438d3 364 &crl->sig_md, &crl->sig_pk,
switches 0:5c4d7b2438d3 365 &crl->sig_opts ) ) != 0 )
switches 0:5c4d7b2438d3 366 {
switches 0:5c4d7b2438d3 367 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 368 return( MBEDTLS_ERR_X509_UNKNOWN_SIG_ALG );
switches 0:5c4d7b2438d3 369 }
switches 0:5c4d7b2438d3 370
switches 0:5c4d7b2438d3 371 /*
switches 0:5c4d7b2438d3 372 * issuer Name
switches 0:5c4d7b2438d3 373 */
switches 0:5c4d7b2438d3 374 crl->issuer_raw.p = p;
switches 0:5c4d7b2438d3 375
switches 0:5c4d7b2438d3 376 if( ( ret = mbedtls_asn1_get_tag( &p, end, &len,
switches 0:5c4d7b2438d3 377 MBEDTLS_ASN1_CONSTRUCTED | MBEDTLS_ASN1_SEQUENCE ) ) != 0 )
switches 0:5c4d7b2438d3 378 {
switches 0:5c4d7b2438d3 379 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 380 return( MBEDTLS_ERR_X509_INVALID_FORMAT + ret );
switches 0:5c4d7b2438d3 381 }
switches 0:5c4d7b2438d3 382
switches 0:5c4d7b2438d3 383 if( ( ret = mbedtls_x509_get_name( &p, p + len, &crl->issuer ) ) != 0 )
switches 0:5c4d7b2438d3 384 {
switches 0:5c4d7b2438d3 385 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 386 return( ret );
switches 0:5c4d7b2438d3 387 }
switches 0:5c4d7b2438d3 388
switches 0:5c4d7b2438d3 389 crl->issuer_raw.len = p - crl->issuer_raw.p;
switches 0:5c4d7b2438d3 390
switches 0:5c4d7b2438d3 391 /*
switches 0:5c4d7b2438d3 392 * thisUpdate Time
switches 0:5c4d7b2438d3 393 * nextUpdate Time OPTIONAL
switches 0:5c4d7b2438d3 394 */
switches 0:5c4d7b2438d3 395 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->this_update ) ) != 0 )
switches 0:5c4d7b2438d3 396 {
switches 0:5c4d7b2438d3 397 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 398 return( ret );
switches 0:5c4d7b2438d3 399 }
switches 0:5c4d7b2438d3 400
switches 0:5c4d7b2438d3 401 if( ( ret = mbedtls_x509_get_time( &p, end, &crl->next_update ) ) != 0 )
switches 0:5c4d7b2438d3 402 {
switches 0:5c4d7b2438d3 403 if( ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
switches 0:5c4d7b2438d3 404 MBEDTLS_ERR_ASN1_UNEXPECTED_TAG ) &&
switches 0:5c4d7b2438d3 405 ret != ( MBEDTLS_ERR_X509_INVALID_DATE +
switches 0:5c4d7b2438d3 406 MBEDTLS_ERR_ASN1_OUT_OF_DATA ) )
switches 0:5c4d7b2438d3 407 {
switches 0:5c4d7b2438d3 408 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 409 return( ret );
switches 0:5c4d7b2438d3 410 }
switches 0:5c4d7b2438d3 411 }
switches 0:5c4d7b2438d3 412
switches 0:5c4d7b2438d3 413 /*
switches 0:5c4d7b2438d3 414 * revokedCertificates SEQUENCE OF SEQUENCE {
switches 0:5c4d7b2438d3 415 * userCertificate CertificateSerialNumber,
switches 0:5c4d7b2438d3 416 * revocationDate Time,
switches 0:5c4d7b2438d3 417 * crlEntryExtensions Extensions OPTIONAL
switches 0:5c4d7b2438d3 418 * -- if present, MUST be v2
switches 0:5c4d7b2438d3 419 * } OPTIONAL
switches 0:5c4d7b2438d3 420 */
switches 0:5c4d7b2438d3 421 if( ( ret = x509_get_entries( &p, end, &crl->entry ) ) != 0 )
switches 0:5c4d7b2438d3 422 {
switches 0:5c4d7b2438d3 423 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 424 return( ret );
switches 0:5c4d7b2438d3 425 }
switches 0:5c4d7b2438d3 426
switches 0:5c4d7b2438d3 427 /*
switches 0:5c4d7b2438d3 428 * crlExtensions EXPLICIT Extensions OPTIONAL
switches 0:5c4d7b2438d3 429 * -- if present, MUST be v2
switches 0:5c4d7b2438d3 430 */
switches 0:5c4d7b2438d3 431 if( crl->version == 2 )
switches 0:5c4d7b2438d3 432 {
switches 0:5c4d7b2438d3 433 ret = x509_get_crl_ext( &p, end, &crl->crl_ext );
switches 0:5c4d7b2438d3 434
switches 0:5c4d7b2438d3 435 if( ret != 0 )
switches 0:5c4d7b2438d3 436 {
switches 0:5c4d7b2438d3 437 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 438 return( ret );
switches 0:5c4d7b2438d3 439 }
switches 0:5c4d7b2438d3 440 }
switches 0:5c4d7b2438d3 441
switches 0:5c4d7b2438d3 442 if( p != end )
switches 0:5c4d7b2438d3 443 {
switches 0:5c4d7b2438d3 444 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 445 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
switches 0:5c4d7b2438d3 446 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
switches 0:5c4d7b2438d3 447 }
switches 0:5c4d7b2438d3 448
switches 0:5c4d7b2438d3 449 end = crl->raw.p + crl->raw.len;
switches 0:5c4d7b2438d3 450
switches 0:5c4d7b2438d3 451 /*
switches 0:5c4d7b2438d3 452 * signatureAlgorithm AlgorithmIdentifier,
switches 0:5c4d7b2438d3 453 * signatureValue BIT STRING
switches 0:5c4d7b2438d3 454 */
switches 0:5c4d7b2438d3 455 if( ( ret = mbedtls_x509_get_alg( &p, end, &sig_oid2, &sig_params2 ) ) != 0 )
switches 0:5c4d7b2438d3 456 {
switches 0:5c4d7b2438d3 457 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 458 return( ret );
switches 0:5c4d7b2438d3 459 }
switches 0:5c4d7b2438d3 460
switches 0:5c4d7b2438d3 461 if( crl->sig_oid.len != sig_oid2.len ||
switches 0:5c4d7b2438d3 462 memcmp( crl->sig_oid.p, sig_oid2.p, crl->sig_oid.len ) != 0 ||
switches 0:5c4d7b2438d3 463 sig_params1.len != sig_params2.len ||
switches 0:5c4d7b2438d3 464 ( sig_params1.len != 0 &&
switches 0:5c4d7b2438d3 465 memcmp( sig_params1.p, sig_params2.p, sig_params1.len ) != 0 ) )
switches 0:5c4d7b2438d3 466 {
switches 0:5c4d7b2438d3 467 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 468 return( MBEDTLS_ERR_X509_SIG_MISMATCH );
switches 0:5c4d7b2438d3 469 }
switches 0:5c4d7b2438d3 470
switches 0:5c4d7b2438d3 471 if( ( ret = mbedtls_x509_get_sig( &p, end, &crl->sig ) ) != 0 )
switches 0:5c4d7b2438d3 472 {
switches 0:5c4d7b2438d3 473 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 474 return( ret );
switches 0:5c4d7b2438d3 475 }
switches 0:5c4d7b2438d3 476
switches 0:5c4d7b2438d3 477 if( p != end )
switches 0:5c4d7b2438d3 478 {
switches 0:5c4d7b2438d3 479 mbedtls_x509_crl_free( crl );
switches 0:5c4d7b2438d3 480 return( MBEDTLS_ERR_X509_INVALID_FORMAT +
switches 0:5c4d7b2438d3 481 MBEDTLS_ERR_ASN1_LENGTH_MISMATCH );
switches 0:5c4d7b2438d3 482 }
switches 0:5c4d7b2438d3 483
switches 0:5c4d7b2438d3 484 return( 0 );
switches 0:5c4d7b2438d3 485 }
switches 0:5c4d7b2438d3 486
switches 0:5c4d7b2438d3 487 /*
switches 0:5c4d7b2438d3 488 * Parse one or more CRLs and add them to the chained list
switches 0:5c4d7b2438d3 489 */
switches 0:5c4d7b2438d3 490 int mbedtls_x509_crl_parse( mbedtls_x509_crl *chain, const unsigned char *buf, size_t buflen )
switches 0:5c4d7b2438d3 491 {
switches 0:5c4d7b2438d3 492 #if defined(MBEDTLS_PEM_PARSE_C)
switches 0:5c4d7b2438d3 493 int ret;
switches 0:5c4d7b2438d3 494 size_t use_len;
switches 0:5c4d7b2438d3 495 mbedtls_pem_context pem;
switches 0:5c4d7b2438d3 496 int is_pem = 0;
switches 0:5c4d7b2438d3 497
switches 0:5c4d7b2438d3 498 if( chain == NULL || buf == NULL )
switches 0:5c4d7b2438d3 499 return( MBEDTLS_ERR_X509_BAD_INPUT_DATA );
switches 0:5c4d7b2438d3 500
switches 0:5c4d7b2438d3 501 do
switches 0:5c4d7b2438d3 502 {
switches 0:5c4d7b2438d3 503 mbedtls_pem_init( &pem );
switches 0:5c4d7b2438d3 504
switches 0:5c4d7b2438d3 505 // Avoid calling mbedtls_pem_read_buffer() on non-null-terminated
switches 0:5c4d7b2438d3 506 // string
switches 0:5c4d7b2438d3 507 if( buflen == 0 || buf[buflen - 1] != '\0' )
switches 0:5c4d7b2438d3 508 ret = MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT;
switches 0:5c4d7b2438d3 509 else
switches 0:5c4d7b2438d3 510 ret = mbedtls_pem_read_buffer( &pem,
switches 0:5c4d7b2438d3 511 "-----BEGIN X509 CRL-----",
switches 0:5c4d7b2438d3 512 "-----END X509 CRL-----",
switches 0:5c4d7b2438d3 513 buf, NULL, 0, &use_len );
switches 0:5c4d7b2438d3 514
switches 0:5c4d7b2438d3 515 if( ret == 0 )
switches 0:5c4d7b2438d3 516 {
switches 0:5c4d7b2438d3 517 /*
switches 0:5c4d7b2438d3 518 * Was PEM encoded
switches 0:5c4d7b2438d3 519 */
switches 0:5c4d7b2438d3 520 is_pem = 1;
switches 0:5c4d7b2438d3 521
switches 0:5c4d7b2438d3 522 buflen -= use_len;
switches 0:5c4d7b2438d3 523 buf += use_len;
switches 0:5c4d7b2438d3 524
switches 0:5c4d7b2438d3 525 if( ( ret = mbedtls_x509_crl_parse_der( chain,
switches 0:5c4d7b2438d3 526 pem.buf, pem.buflen ) ) != 0 )
switches 0:5c4d7b2438d3 527 {
switches 0:5c4d7b2438d3 528 return( ret );
switches 0:5c4d7b2438d3 529 }
switches 0:5c4d7b2438d3 530
switches 0:5c4d7b2438d3 531 mbedtls_pem_free( &pem );
switches 0:5c4d7b2438d3 532 }
switches 0:5c4d7b2438d3 533 else if( ret != MBEDTLS_ERR_PEM_NO_HEADER_FOOTER_PRESENT )
switches 0:5c4d7b2438d3 534 {
switches 0:5c4d7b2438d3 535 mbedtls_pem_free( &pem );
switches 0:5c4d7b2438d3 536 return( ret );
switches 0:5c4d7b2438d3 537 }
switches 0:5c4d7b2438d3 538 }
switches 0:5c4d7b2438d3 539 /* In the PEM case, buflen is 1 at the end, for the terminated NULL byte.
switches 0:5c4d7b2438d3 540 * And a valid CRL cannot be less than 1 byte anyway. */
switches 0:5c4d7b2438d3 541 while( is_pem && buflen > 1 );
switches 0:5c4d7b2438d3 542
switches 0:5c4d7b2438d3 543 if( is_pem )
switches 0:5c4d7b2438d3 544 return( 0 );
switches 0:5c4d7b2438d3 545 else
switches 0:5c4d7b2438d3 546 #endif /* MBEDTLS_PEM_PARSE_C */
switches 0:5c4d7b2438d3 547 return( mbedtls_x509_crl_parse_der( chain, buf, buflen ) );
switches 0:5c4d7b2438d3 548 }
switches 0:5c4d7b2438d3 549
switches 0:5c4d7b2438d3 550 #if defined(MBEDTLS_FS_IO)
switches 0:5c4d7b2438d3 551 /*
switches 0:5c4d7b2438d3 552 * Load one or more CRLs and add them to the chained list
switches 0:5c4d7b2438d3 553 */
switches 0:5c4d7b2438d3 554 int mbedtls_x509_crl_parse_file( mbedtls_x509_crl *chain, const char *path )
switches 0:5c4d7b2438d3 555 {
switches 0:5c4d7b2438d3 556 int ret;
switches 0:5c4d7b2438d3 557 size_t n;
switches 0:5c4d7b2438d3 558 unsigned char *buf;
switches 0:5c4d7b2438d3 559
switches 0:5c4d7b2438d3 560 if( ( ret = mbedtls_pk_load_file( path, &buf, &n ) ) != 0 )
switches 0:5c4d7b2438d3 561 return( ret );
switches 0:5c4d7b2438d3 562
switches 0:5c4d7b2438d3 563 ret = mbedtls_x509_crl_parse( chain, buf, n );
switches 0:5c4d7b2438d3 564
switches 0:5c4d7b2438d3 565 mbedtls_zeroize( buf, n );
switches 0:5c4d7b2438d3 566 mbedtls_free( buf );
switches 0:5c4d7b2438d3 567
switches 0:5c4d7b2438d3 568 return( ret );
switches 0:5c4d7b2438d3 569 }
switches 0:5c4d7b2438d3 570 #endif /* MBEDTLS_FS_IO */
switches 0:5c4d7b2438d3 571
switches 0:5c4d7b2438d3 572 /*
switches 0:5c4d7b2438d3 573 * Return an informational string about the certificate.
switches 0:5c4d7b2438d3 574 */
switches 0:5c4d7b2438d3 575 #define BEFORE_COLON 14
switches 0:5c4d7b2438d3 576 #define BC "14"
switches 0:5c4d7b2438d3 577 /*
switches 0:5c4d7b2438d3 578 * Return an informational string about the CRL.
switches 0:5c4d7b2438d3 579 */
switches 0:5c4d7b2438d3 580 int mbedtls_x509_crl_info( char *buf, size_t size, const char *prefix,
switches 0:5c4d7b2438d3 581 const mbedtls_x509_crl *crl )
switches 0:5c4d7b2438d3 582 {
switches 0:5c4d7b2438d3 583 int ret;
switches 0:5c4d7b2438d3 584 size_t n;
switches 0:5c4d7b2438d3 585 char *p;
switches 0:5c4d7b2438d3 586 const mbedtls_x509_crl_entry *entry;
switches 0:5c4d7b2438d3 587
switches 0:5c4d7b2438d3 588 p = buf;
switches 0:5c4d7b2438d3 589 n = size;
switches 0:5c4d7b2438d3 590
switches 0:5c4d7b2438d3 591 ret = mbedtls_snprintf( p, n, "%sCRL version : %d",
switches 0:5c4d7b2438d3 592 prefix, crl->version );
switches 0:5c4d7b2438d3 593 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 594
switches 0:5c4d7b2438d3 595 ret = mbedtls_snprintf( p, n, "\n%sissuer name : ", prefix );
switches 0:5c4d7b2438d3 596 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 597 ret = mbedtls_x509_dn_gets( p, n, &crl->issuer );
switches 0:5c4d7b2438d3 598 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 599
switches 0:5c4d7b2438d3 600 ret = mbedtls_snprintf( p, n, "\n%sthis update : " \
switches 0:5c4d7b2438d3 601 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
switches 0:5c4d7b2438d3 602 crl->this_update.year, crl->this_update.mon,
switches 0:5c4d7b2438d3 603 crl->this_update.day, crl->this_update.hour,
switches 0:5c4d7b2438d3 604 crl->this_update.min, crl->this_update.sec );
switches 0:5c4d7b2438d3 605 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 606
switches 0:5c4d7b2438d3 607 ret = mbedtls_snprintf( p, n, "\n%snext update : " \
switches 0:5c4d7b2438d3 608 "%04d-%02d-%02d %02d:%02d:%02d", prefix,
switches 0:5c4d7b2438d3 609 crl->next_update.year, crl->next_update.mon,
switches 0:5c4d7b2438d3 610 crl->next_update.day, crl->next_update.hour,
switches 0:5c4d7b2438d3 611 crl->next_update.min, crl->next_update.sec );
switches 0:5c4d7b2438d3 612 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 613
switches 0:5c4d7b2438d3 614 entry = &crl->entry;
switches 0:5c4d7b2438d3 615
switches 0:5c4d7b2438d3 616 ret = mbedtls_snprintf( p, n, "\n%sRevoked certificates:",
switches 0:5c4d7b2438d3 617 prefix );
switches 0:5c4d7b2438d3 618 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 619
switches 0:5c4d7b2438d3 620 while( entry != NULL && entry->raw.len != 0 )
switches 0:5c4d7b2438d3 621 {
switches 0:5c4d7b2438d3 622 ret = mbedtls_snprintf( p, n, "\n%sserial number: ",
switches 0:5c4d7b2438d3 623 prefix );
switches 0:5c4d7b2438d3 624 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 625
switches 0:5c4d7b2438d3 626 ret = mbedtls_x509_serial_gets( p, n, &entry->serial );
switches 0:5c4d7b2438d3 627 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 628
switches 0:5c4d7b2438d3 629 ret = mbedtls_snprintf( p, n, " revocation date: " \
switches 0:5c4d7b2438d3 630 "%04d-%02d-%02d %02d:%02d:%02d",
switches 0:5c4d7b2438d3 631 entry->revocation_date.year, entry->revocation_date.mon,
switches 0:5c4d7b2438d3 632 entry->revocation_date.day, entry->revocation_date.hour,
switches 0:5c4d7b2438d3 633 entry->revocation_date.min, entry->revocation_date.sec );
switches 0:5c4d7b2438d3 634 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 635
switches 0:5c4d7b2438d3 636 entry = entry->next;
switches 0:5c4d7b2438d3 637 }
switches 0:5c4d7b2438d3 638
switches 0:5c4d7b2438d3 639 ret = mbedtls_snprintf( p, n, "\n%ssigned using : ", prefix );
switches 0:5c4d7b2438d3 640 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 641
switches 0:5c4d7b2438d3 642 ret = mbedtls_x509_sig_alg_gets( p, n, &crl->sig_oid, crl->sig_pk, crl->sig_md,
switches 0:5c4d7b2438d3 643 crl->sig_opts );
switches 0:5c4d7b2438d3 644 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 645
switches 0:5c4d7b2438d3 646 ret = mbedtls_snprintf( p, n, "\n" );
switches 0:5c4d7b2438d3 647 MBEDTLS_X509_SAFE_SNPRINTF;
switches 0:5c4d7b2438d3 648
switches 0:5c4d7b2438d3 649 return( (int) ( size - n ) );
switches 0:5c4d7b2438d3 650 }
switches 0:5c4d7b2438d3 651
switches 0:5c4d7b2438d3 652 /*
switches 0:5c4d7b2438d3 653 * Initialize a CRL chain
switches 0:5c4d7b2438d3 654 */
switches 0:5c4d7b2438d3 655 void mbedtls_x509_crl_init( mbedtls_x509_crl *crl )
switches 0:5c4d7b2438d3 656 {
switches 0:5c4d7b2438d3 657 memset( crl, 0, sizeof(mbedtls_x509_crl) );
switches 0:5c4d7b2438d3 658 }
switches 0:5c4d7b2438d3 659
switches 0:5c4d7b2438d3 660 /*
switches 0:5c4d7b2438d3 661 * Unallocate all CRL data
switches 0:5c4d7b2438d3 662 */
switches 0:5c4d7b2438d3 663 void mbedtls_x509_crl_free( mbedtls_x509_crl *crl )
switches 0:5c4d7b2438d3 664 {
switches 0:5c4d7b2438d3 665 mbedtls_x509_crl *crl_cur = crl;
switches 0:5c4d7b2438d3 666 mbedtls_x509_crl *crl_prv;
switches 0:5c4d7b2438d3 667 mbedtls_x509_name *name_cur;
switches 0:5c4d7b2438d3 668 mbedtls_x509_name *name_prv;
switches 0:5c4d7b2438d3 669 mbedtls_x509_crl_entry *entry_cur;
switches 0:5c4d7b2438d3 670 mbedtls_x509_crl_entry *entry_prv;
switches 0:5c4d7b2438d3 671
switches 0:5c4d7b2438d3 672 if( crl == NULL )
switches 0:5c4d7b2438d3 673 return;
switches 0:5c4d7b2438d3 674
switches 0:5c4d7b2438d3 675 do
switches 0:5c4d7b2438d3 676 {
switches 0:5c4d7b2438d3 677 #if defined(MBEDTLS_X509_RSASSA_PSS_SUPPORT)
switches 0:5c4d7b2438d3 678 mbedtls_free( crl_cur->sig_opts );
switches 0:5c4d7b2438d3 679 #endif
switches 0:5c4d7b2438d3 680
switches 0:5c4d7b2438d3 681 name_cur = crl_cur->issuer.next;
switches 0:5c4d7b2438d3 682 while( name_cur != NULL )
switches 0:5c4d7b2438d3 683 {
switches 0:5c4d7b2438d3 684 name_prv = name_cur;
switches 0:5c4d7b2438d3 685 name_cur = name_cur->next;
switches 0:5c4d7b2438d3 686 mbedtls_zeroize( name_prv, sizeof( mbedtls_x509_name ) );
switches 0:5c4d7b2438d3 687 mbedtls_free( name_prv );
switches 0:5c4d7b2438d3 688 }
switches 0:5c4d7b2438d3 689
switches 0:5c4d7b2438d3 690 entry_cur = crl_cur->entry.next;
switches 0:5c4d7b2438d3 691 while( entry_cur != NULL )
switches 0:5c4d7b2438d3 692 {
switches 0:5c4d7b2438d3 693 entry_prv = entry_cur;
switches 0:5c4d7b2438d3 694 entry_cur = entry_cur->next;
switches 0:5c4d7b2438d3 695 mbedtls_zeroize( entry_prv, sizeof( mbedtls_x509_crl_entry ) );
switches 0:5c4d7b2438d3 696 mbedtls_free( entry_prv );
switches 0:5c4d7b2438d3 697 }
switches 0:5c4d7b2438d3 698
switches 0:5c4d7b2438d3 699 if( crl_cur->raw.p != NULL )
switches 0:5c4d7b2438d3 700 {
switches 0:5c4d7b2438d3 701 mbedtls_zeroize( crl_cur->raw.p, crl_cur->raw.len );
switches 0:5c4d7b2438d3 702 mbedtls_free( crl_cur->raw.p );
switches 0:5c4d7b2438d3 703 }
switches 0:5c4d7b2438d3 704
switches 0:5c4d7b2438d3 705 crl_cur = crl_cur->next;
switches 0:5c4d7b2438d3 706 }
switches 0:5c4d7b2438d3 707 while( crl_cur != NULL );
switches 0:5c4d7b2438d3 708
switches 0:5c4d7b2438d3 709 crl_cur = crl;
switches 0:5c4d7b2438d3 710 do
switches 0:5c4d7b2438d3 711 {
switches 0:5c4d7b2438d3 712 crl_prv = crl_cur;
switches 0:5c4d7b2438d3 713 crl_cur = crl_cur->next;
switches 0:5c4d7b2438d3 714
switches 0:5c4d7b2438d3 715 mbedtls_zeroize( crl_prv, sizeof( mbedtls_x509_crl ) );
switches 0:5c4d7b2438d3 716 if( crl_prv != crl )
switches 0:5c4d7b2438d3 717 mbedtls_free( crl_prv );
switches 0:5c4d7b2438d3 718 }
switches 0:5c4d7b2438d3 719 while( crl_cur != NULL );
switches 0:5c4d7b2438d3 720 }
switches 0:5c4d7b2438d3 721
switches 0:5c4d7b2438d3 722 #endif /* MBEDTLS_X509_CRL_PARSE_C */