x509name.c 9.8 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360
  1. /*
  2. * Copyright 1995-2018 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the OpenSSL license (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. #include <stdio.h>
  10. #include "internal/cryptlib.h"
  11. #include <openssl/safestack.h>
  12. #include <openssl/asn1.h>
  13. #include <openssl/objects.h>
  14. #include <openssl/evp.h>
  15. #include <openssl/x509.h>
  16. #include "crypto/x509.h"
  17. int X509_NAME_get_text_by_NID(X509_NAME *name, int nid, char *buf, int len)
  18. {
  19. ASN1_OBJECT *obj;
  20. obj = OBJ_nid2obj(nid);
  21. if (obj == NULL)
  22. return -1;
  23. return X509_NAME_get_text_by_OBJ(name, obj, buf, len);
  24. }
  25. int X509_NAME_get_text_by_OBJ(X509_NAME *name, const ASN1_OBJECT *obj,
  26. char *buf, int len)
  27. {
  28. int i;
  29. const ASN1_STRING *data;
  30. i = X509_NAME_get_index_by_OBJ(name, obj, -1);
  31. if (i < 0)
  32. return -1;
  33. data = X509_NAME_ENTRY_get_data(X509_NAME_get_entry(name, i));
  34. if (buf == NULL)
  35. return data->length;
  36. if (len <= 0)
  37. return 0;
  38. i = (data->length > (len - 1)) ? (len - 1) : data->length;
  39. memcpy(buf, data->data, i);
  40. buf[i] = '\0';
  41. return i;
  42. }
  43. int X509_NAME_entry_count(const X509_NAME *name)
  44. {
  45. if (name == NULL)
  46. return 0;
  47. return sk_X509_NAME_ENTRY_num(name->entries);
  48. }
  49. int X509_NAME_get_index_by_NID(X509_NAME *name, int nid, int lastpos)
  50. {
  51. ASN1_OBJECT *obj;
  52. obj = OBJ_nid2obj(nid);
  53. if (obj == NULL)
  54. return -2;
  55. return X509_NAME_get_index_by_OBJ(name, obj, lastpos);
  56. }
  57. /* NOTE: you should be passing -1, not 0 as lastpos */
  58. int X509_NAME_get_index_by_OBJ(X509_NAME *name, const ASN1_OBJECT *obj, int lastpos)
  59. {
  60. int n;
  61. X509_NAME_ENTRY *ne;
  62. STACK_OF(X509_NAME_ENTRY) *sk;
  63. if (name == NULL)
  64. return -1;
  65. if (lastpos < 0)
  66. lastpos = -1;
  67. sk = name->entries;
  68. n = sk_X509_NAME_ENTRY_num(sk);
  69. for (lastpos++; lastpos < n; lastpos++) {
  70. ne = sk_X509_NAME_ENTRY_value(sk, lastpos);
  71. if (OBJ_cmp(ne->object, obj) == 0)
  72. return lastpos;
  73. }
  74. return -1;
  75. }
  76. X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc)
  77. {
  78. if (name == NULL || sk_X509_NAME_ENTRY_num(name->entries) <= loc
  79. || loc < 0)
  80. return NULL;
  81. return sk_X509_NAME_ENTRY_value(name->entries, loc);
  82. }
  83. X509_NAME_ENTRY *X509_NAME_delete_entry(X509_NAME *name, int loc)
  84. {
  85. X509_NAME_ENTRY *ret;
  86. int i, n, set_prev, set_next;
  87. STACK_OF(X509_NAME_ENTRY) *sk;
  88. if (name == NULL || sk_X509_NAME_ENTRY_num(name->entries) <= loc
  89. || loc < 0)
  90. return NULL;
  91. sk = name->entries;
  92. ret = sk_X509_NAME_ENTRY_delete(sk, loc);
  93. n = sk_X509_NAME_ENTRY_num(sk);
  94. name->modified = 1;
  95. if (loc == n)
  96. return ret;
  97. /* else we need to fixup the set field */
  98. if (loc != 0)
  99. set_prev = (sk_X509_NAME_ENTRY_value(sk, loc - 1))->set;
  100. else
  101. set_prev = ret->set - 1;
  102. set_next = sk_X509_NAME_ENTRY_value(sk, loc)->set;
  103. /*-
  104. * set_prev is the previous set
  105. * set is the current set
  106. * set_next is the following
  107. * prev 1 1 1 1 1 1 1 1
  108. * set 1 1 2 2
  109. * next 1 1 2 2 2 2 3 2
  110. * so basically only if prev and next differ by 2, then
  111. * re-number down by 1
  112. */
  113. if (set_prev + 1 < set_next)
  114. for (i = loc; i < n; i++)
  115. sk_X509_NAME_ENTRY_value(sk, i)->set--;
  116. return ret;
  117. }
  118. int X509_NAME_add_entry_by_OBJ(X509_NAME *name, const ASN1_OBJECT *obj, int type,
  119. const unsigned char *bytes, int len, int loc,
  120. int set)
  121. {
  122. X509_NAME_ENTRY *ne;
  123. int ret;
  124. ne = X509_NAME_ENTRY_create_by_OBJ(NULL, obj, type, bytes, len);
  125. if (!ne)
  126. return 0;
  127. ret = X509_NAME_add_entry(name, ne, loc, set);
  128. X509_NAME_ENTRY_free(ne);
  129. return ret;
  130. }
  131. int X509_NAME_add_entry_by_NID(X509_NAME *name, int nid, int type,
  132. const unsigned char *bytes, int len, int loc,
  133. int set)
  134. {
  135. X509_NAME_ENTRY *ne;
  136. int ret;
  137. ne = X509_NAME_ENTRY_create_by_NID(NULL, nid, type, bytes, len);
  138. if (!ne)
  139. return 0;
  140. ret = X509_NAME_add_entry(name, ne, loc, set);
  141. X509_NAME_ENTRY_free(ne);
  142. return ret;
  143. }
  144. int X509_NAME_add_entry_by_txt(X509_NAME *name, const char *field, int type,
  145. const unsigned char *bytes, int len, int loc,
  146. int set)
  147. {
  148. X509_NAME_ENTRY *ne;
  149. int ret;
  150. ne = X509_NAME_ENTRY_create_by_txt(NULL, field, type, bytes, len);
  151. if (!ne)
  152. return 0;
  153. ret = X509_NAME_add_entry(name, ne, loc, set);
  154. X509_NAME_ENTRY_free(ne);
  155. return ret;
  156. }
  157. /*
  158. * if set is -1, append to previous set, 0 'a new one', and 1, prepend to the
  159. * guy we are about to stomp on.
  160. */
  161. int X509_NAME_add_entry(X509_NAME *name, const X509_NAME_ENTRY *ne, int loc,
  162. int set)
  163. {
  164. X509_NAME_ENTRY *new_name = NULL;
  165. int n, i, inc;
  166. STACK_OF(X509_NAME_ENTRY) *sk;
  167. if (name == NULL)
  168. return 0;
  169. sk = name->entries;
  170. n = sk_X509_NAME_ENTRY_num(sk);
  171. if (loc > n)
  172. loc = n;
  173. else if (loc < 0)
  174. loc = n;
  175. inc = (set == 0);
  176. name->modified = 1;
  177. if (set == -1) {
  178. if (loc == 0) {
  179. set = 0;
  180. inc = 1;
  181. } else {
  182. set = sk_X509_NAME_ENTRY_value(sk, loc - 1)->set;
  183. }
  184. } else { /* if (set >= 0) */
  185. if (loc >= n) {
  186. if (loc != 0)
  187. set = sk_X509_NAME_ENTRY_value(sk, loc - 1)->set + 1;
  188. else
  189. set = 0;
  190. } else
  191. set = sk_X509_NAME_ENTRY_value(sk, loc)->set;
  192. }
  193. /*
  194. * X509_NAME_ENTRY_dup is ASN1 generated code, that can't be easily
  195. * const'ified; harmless cast since dup() don't modify its input.
  196. */
  197. if ((new_name = X509_NAME_ENTRY_dup((X509_NAME_ENTRY *)ne)) == NULL)
  198. goto err;
  199. new_name->set = set;
  200. if (!sk_X509_NAME_ENTRY_insert(sk, new_name, loc)) {
  201. X509err(X509_F_X509_NAME_ADD_ENTRY, ERR_R_MALLOC_FAILURE);
  202. goto err;
  203. }
  204. if (inc) {
  205. n = sk_X509_NAME_ENTRY_num(sk);
  206. for (i = loc + 1; i < n; i++)
  207. sk_X509_NAME_ENTRY_value(sk, i)->set += 1;
  208. }
  209. return 1;
  210. err:
  211. X509_NAME_ENTRY_free(new_name);
  212. return 0;
  213. }
  214. X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_txt(X509_NAME_ENTRY **ne,
  215. const char *field, int type,
  216. const unsigned char *bytes,
  217. int len)
  218. {
  219. ASN1_OBJECT *obj;
  220. X509_NAME_ENTRY *nentry;
  221. obj = OBJ_txt2obj(field, 0);
  222. if (obj == NULL) {
  223. X509err(X509_F_X509_NAME_ENTRY_CREATE_BY_TXT,
  224. X509_R_INVALID_FIELD_NAME);
  225. ERR_add_error_data(2, "name=", field);
  226. return NULL;
  227. }
  228. nentry = X509_NAME_ENTRY_create_by_OBJ(ne, obj, type, bytes, len);
  229. ASN1_OBJECT_free(obj);
  230. return nentry;
  231. }
  232. X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_NID(X509_NAME_ENTRY **ne, int nid,
  233. int type,
  234. const unsigned char *bytes,
  235. int len)
  236. {
  237. ASN1_OBJECT *obj;
  238. X509_NAME_ENTRY *nentry;
  239. obj = OBJ_nid2obj(nid);
  240. if (obj == NULL) {
  241. X509err(X509_F_X509_NAME_ENTRY_CREATE_BY_NID, X509_R_UNKNOWN_NID);
  242. return NULL;
  243. }
  244. nentry = X509_NAME_ENTRY_create_by_OBJ(ne, obj, type, bytes, len);
  245. ASN1_OBJECT_free(obj);
  246. return nentry;
  247. }
  248. X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_OBJ(X509_NAME_ENTRY **ne,
  249. const ASN1_OBJECT *obj, int type,
  250. const unsigned char *bytes,
  251. int len)
  252. {
  253. X509_NAME_ENTRY *ret;
  254. if ((ne == NULL) || (*ne == NULL)) {
  255. if ((ret = X509_NAME_ENTRY_new()) == NULL)
  256. return NULL;
  257. } else
  258. ret = *ne;
  259. if (!X509_NAME_ENTRY_set_object(ret, obj))
  260. goto err;
  261. if (!X509_NAME_ENTRY_set_data(ret, type, bytes, len))
  262. goto err;
  263. if ((ne != NULL) && (*ne == NULL))
  264. *ne = ret;
  265. return ret;
  266. err:
  267. if ((ne == NULL) || (ret != *ne))
  268. X509_NAME_ENTRY_free(ret);
  269. return NULL;
  270. }
  271. int X509_NAME_ENTRY_set_object(X509_NAME_ENTRY *ne, const ASN1_OBJECT *obj)
  272. {
  273. if ((ne == NULL) || (obj == NULL)) {
  274. X509err(X509_F_X509_NAME_ENTRY_SET_OBJECT,
  275. ERR_R_PASSED_NULL_PARAMETER);
  276. return 0;
  277. }
  278. ASN1_OBJECT_free(ne->object);
  279. ne->object = OBJ_dup(obj);
  280. return ((ne->object == NULL) ? 0 : 1);
  281. }
  282. int X509_NAME_ENTRY_set_data(X509_NAME_ENTRY *ne, int type,
  283. const unsigned char *bytes, int len)
  284. {
  285. int i;
  286. if ((ne == NULL) || ((bytes == NULL) && (len != 0)))
  287. return 0;
  288. if ((type > 0) && (type & MBSTRING_FLAG))
  289. return ASN1_STRING_set_by_NID(&ne->value, bytes,
  290. len, type,
  291. OBJ_obj2nid(ne->object)) ? 1 : 0;
  292. if (len < 0)
  293. len = strlen((const char *)bytes);
  294. i = ASN1_STRING_set(ne->value, bytes, len);
  295. if (!i)
  296. return 0;
  297. if (type != V_ASN1_UNDEF) {
  298. if (type == V_ASN1_APP_CHOOSE)
  299. ne->value->type = ASN1_PRINTABLE_type(bytes, len);
  300. else
  301. ne->value->type = type;
  302. }
  303. return 1;
  304. }
  305. ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne)
  306. {
  307. if (ne == NULL)
  308. return NULL;
  309. return ne->object;
  310. }
  311. ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne)
  312. {
  313. if (ne == NULL)
  314. return NULL;
  315. return ne->value;
  316. }
  317. int X509_NAME_ENTRY_set(const X509_NAME_ENTRY *ne)
  318. {
  319. return ne->set;
  320. }