crmf_asn.c 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239
  1. /*-
  2. * Copyright 2007-2020 The OpenSSL Project Authors. All Rights Reserved.
  3. * Copyright Nokia 2007-2019
  4. * Copyright Siemens AG 2015-2019
  5. *
  6. * Licensed under the Apache License 2.0 (the "License"). You may not use
  7. * this file except in compliance with the License. You can obtain a copy
  8. * in the file LICENSE in the source distribution or at
  9. * https://www.openssl.org/source/license.html
  10. *
  11. * CRMF implementation by Martin Peylo, Miikka Viljanen, and David von Oheimb.
  12. */
  13. #include <openssl/asn1t.h>
  14. #include "crmf_local.h"
  15. /* explicit #includes not strictly needed since implied by the above: */
  16. #include <openssl/crmf.h>
  17. ASN1_SEQUENCE(OSSL_CRMF_PRIVATEKEYINFO) = {
  18. ASN1_SIMPLE(OSSL_CRMF_PRIVATEKEYINFO, version, ASN1_INTEGER),
  19. ASN1_SIMPLE(OSSL_CRMF_PRIVATEKEYINFO, privateKeyAlgorithm, X509_ALGOR),
  20. ASN1_SIMPLE(OSSL_CRMF_PRIVATEKEYINFO, privateKey, ASN1_OCTET_STRING),
  21. ASN1_IMP_SET_OF_OPT(OSSL_CRMF_PRIVATEKEYINFO, attributes, X509_ATTRIBUTE, 0)
  22. } ASN1_SEQUENCE_END(OSSL_CRMF_PRIVATEKEYINFO)
  23. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_PRIVATEKEYINFO)
  24. ASN1_CHOICE(OSSL_CRMF_ENCKEYWITHID_IDENTIFIER) = {
  25. ASN1_SIMPLE(OSSL_CRMF_ENCKEYWITHID_IDENTIFIER, value.string, ASN1_UTF8STRING),
  26. ASN1_SIMPLE(OSSL_CRMF_ENCKEYWITHID_IDENTIFIER, value.generalName, GENERAL_NAME)
  27. } ASN1_CHOICE_END(OSSL_CRMF_ENCKEYWITHID_IDENTIFIER)
  28. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_ENCKEYWITHID_IDENTIFIER)
  29. ASN1_SEQUENCE(OSSL_CRMF_ENCKEYWITHID) = {
  30. ASN1_SIMPLE(OSSL_CRMF_ENCKEYWITHID, privateKey, OSSL_CRMF_PRIVATEKEYINFO),
  31. ASN1_OPT(OSSL_CRMF_ENCKEYWITHID, identifier,
  32. OSSL_CRMF_ENCKEYWITHID_IDENTIFIER)
  33. } ASN1_SEQUENCE_END(OSSL_CRMF_ENCKEYWITHID)
  34. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_ENCKEYWITHID)
  35. ASN1_SEQUENCE(OSSL_CRMF_CERTID) = {
  36. ASN1_SIMPLE(OSSL_CRMF_CERTID, issuer, GENERAL_NAME),
  37. ASN1_SIMPLE(OSSL_CRMF_CERTID, serialNumber, ASN1_INTEGER)
  38. } ASN1_SEQUENCE_END(OSSL_CRMF_CERTID)
  39. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_CERTID)
  40. IMPLEMENT_ASN1_DUP_FUNCTION(OSSL_CRMF_CERTID)
  41. ASN1_SEQUENCE(OSSL_CRMF_ENCRYPTEDVALUE) = {
  42. ASN1_IMP_OPT(OSSL_CRMF_ENCRYPTEDVALUE, intendedAlg, X509_ALGOR, 0),
  43. ASN1_IMP_OPT(OSSL_CRMF_ENCRYPTEDVALUE, symmAlg, X509_ALGOR, 1),
  44. ASN1_IMP_OPT(OSSL_CRMF_ENCRYPTEDVALUE, encSymmKey, ASN1_BIT_STRING, 2),
  45. ASN1_IMP_OPT(OSSL_CRMF_ENCRYPTEDVALUE, keyAlg, X509_ALGOR, 3),
  46. ASN1_IMP_OPT(OSSL_CRMF_ENCRYPTEDVALUE, valueHint, ASN1_OCTET_STRING, 4),
  47. ASN1_SIMPLE(OSSL_CRMF_ENCRYPTEDVALUE, encValue, ASN1_BIT_STRING)
  48. } ASN1_SEQUENCE_END(OSSL_CRMF_ENCRYPTEDVALUE)
  49. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_ENCRYPTEDVALUE)
  50. ASN1_SEQUENCE(OSSL_CRMF_SINGLEPUBINFO) = {
  51. ASN1_SIMPLE(OSSL_CRMF_SINGLEPUBINFO, pubMethod, ASN1_INTEGER),
  52. ASN1_SIMPLE(OSSL_CRMF_SINGLEPUBINFO, pubLocation, GENERAL_NAME)
  53. } ASN1_SEQUENCE_END(OSSL_CRMF_SINGLEPUBINFO)
  54. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_SINGLEPUBINFO)
  55. ASN1_SEQUENCE(OSSL_CRMF_PKIPUBLICATIONINFO) = {
  56. ASN1_SIMPLE(OSSL_CRMF_PKIPUBLICATIONINFO, action, ASN1_INTEGER),
  57. ASN1_SEQUENCE_OF_OPT(OSSL_CRMF_PKIPUBLICATIONINFO, pubInfos,
  58. OSSL_CRMF_SINGLEPUBINFO)
  59. } ASN1_SEQUENCE_END(OSSL_CRMF_PKIPUBLICATIONINFO)
  60. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_PKIPUBLICATIONINFO)
  61. IMPLEMENT_ASN1_DUP_FUNCTION(OSSL_CRMF_PKIPUBLICATIONINFO)
  62. ASN1_SEQUENCE(OSSL_CRMF_PKMACVALUE) = {
  63. ASN1_SIMPLE(OSSL_CRMF_PKMACVALUE, algId, X509_ALGOR),
  64. ASN1_SIMPLE(OSSL_CRMF_PKMACVALUE, value, ASN1_BIT_STRING)
  65. } ASN1_SEQUENCE_END(OSSL_CRMF_PKMACVALUE)
  66. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_PKMACVALUE)
  67. ASN1_CHOICE(OSSL_CRMF_POPOPRIVKEY) = {
  68. ASN1_IMP(OSSL_CRMF_POPOPRIVKEY, value.thisMessage, ASN1_BIT_STRING, 0),
  69. ASN1_IMP(OSSL_CRMF_POPOPRIVKEY, value.subsequentMessage, ASN1_INTEGER, 1),
  70. ASN1_IMP(OSSL_CRMF_POPOPRIVKEY, value.dhMAC, ASN1_BIT_STRING, 2),
  71. ASN1_IMP(OSSL_CRMF_POPOPRIVKEY, value.agreeMAC, OSSL_CRMF_PKMACVALUE, 3),
  72. /*
  73. * TODO: This is not ASN1_NULL but CMS_ENVELOPEDDATA which should be somehow
  74. * taken from crypto/cms which exists now - this is not used anywhere so far
  75. */
  76. ASN1_IMP(OSSL_CRMF_POPOPRIVKEY, value.encryptedKey, ASN1_NULL, 4),
  77. } ASN1_CHOICE_END(OSSL_CRMF_POPOPRIVKEY)
  78. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_POPOPRIVKEY)
  79. ASN1_SEQUENCE(OSSL_CRMF_PBMPARAMETER) = {
  80. ASN1_SIMPLE(OSSL_CRMF_PBMPARAMETER, salt, ASN1_OCTET_STRING),
  81. ASN1_SIMPLE(OSSL_CRMF_PBMPARAMETER, owf, X509_ALGOR),
  82. ASN1_SIMPLE(OSSL_CRMF_PBMPARAMETER, iterationCount, ASN1_INTEGER),
  83. ASN1_SIMPLE(OSSL_CRMF_PBMPARAMETER, mac, X509_ALGOR)
  84. } ASN1_SEQUENCE_END(OSSL_CRMF_PBMPARAMETER)
  85. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_PBMPARAMETER)
  86. ASN1_CHOICE(OSSL_CRMF_POPOSIGNINGKEYINPUT_AUTHINFO) = {
  87. ASN1_EXP(OSSL_CRMF_POPOSIGNINGKEYINPUT_AUTHINFO, value.sender,
  88. GENERAL_NAME, 0),
  89. ASN1_SIMPLE(OSSL_CRMF_POPOSIGNINGKEYINPUT_AUTHINFO, value.publicKeyMAC,
  90. OSSL_CRMF_PKMACVALUE)
  91. } ASN1_CHOICE_END(OSSL_CRMF_POPOSIGNINGKEYINPUT_AUTHINFO)
  92. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_POPOSIGNINGKEYINPUT_AUTHINFO)
  93. ASN1_SEQUENCE(OSSL_CRMF_POPOSIGNINGKEYINPUT) = {
  94. ASN1_SIMPLE(OSSL_CRMF_POPOSIGNINGKEYINPUT, authInfo,
  95. OSSL_CRMF_POPOSIGNINGKEYINPUT_AUTHINFO),
  96. ASN1_SIMPLE(OSSL_CRMF_POPOSIGNINGKEYINPUT, publicKey, X509_PUBKEY)
  97. } ASN1_SEQUENCE_END(OSSL_CRMF_POPOSIGNINGKEYINPUT)
  98. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_POPOSIGNINGKEYINPUT)
  99. ASN1_SEQUENCE(OSSL_CRMF_POPOSIGNINGKEY) = {
  100. ASN1_IMP_OPT(OSSL_CRMF_POPOSIGNINGKEY, poposkInput,
  101. OSSL_CRMF_POPOSIGNINGKEYINPUT, 0),
  102. ASN1_SIMPLE(OSSL_CRMF_POPOSIGNINGKEY, algorithmIdentifier, X509_ALGOR),
  103. ASN1_SIMPLE(OSSL_CRMF_POPOSIGNINGKEY, signature, ASN1_BIT_STRING)
  104. } ASN1_SEQUENCE_END(OSSL_CRMF_POPOSIGNINGKEY)
  105. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_POPOSIGNINGKEY)
  106. ASN1_CHOICE(OSSL_CRMF_POPO) = {
  107. ASN1_IMP(OSSL_CRMF_POPO, value.raVerified, ASN1_NULL, 0),
  108. ASN1_IMP(OSSL_CRMF_POPO, value.signature, OSSL_CRMF_POPOSIGNINGKEY, 1),
  109. ASN1_EXP(OSSL_CRMF_POPO, value.keyEncipherment, OSSL_CRMF_POPOPRIVKEY, 2),
  110. ASN1_EXP(OSSL_CRMF_POPO, value.keyAgreement, OSSL_CRMF_POPOPRIVKEY, 3)
  111. } ASN1_CHOICE_END(OSSL_CRMF_POPO)
  112. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_POPO)
  113. ASN1_ADB_TEMPLATE(attributetypeandvalue_default) =
  114. ASN1_OPT(OSSL_CRMF_ATTRIBUTETYPEANDVALUE, value.other, ASN1_ANY);
  115. ASN1_ADB(OSSL_CRMF_ATTRIBUTETYPEANDVALUE) = {
  116. ADB_ENTRY(NID_id_regCtrl_regToken,
  117. ASN1_SIMPLE(OSSL_CRMF_ATTRIBUTETYPEANDVALUE,
  118. value.regToken, ASN1_UTF8STRING)),
  119. ADB_ENTRY(NID_id_regCtrl_authenticator,
  120. ASN1_SIMPLE(OSSL_CRMF_ATTRIBUTETYPEANDVALUE,
  121. value.authenticator, ASN1_UTF8STRING)),
  122. ADB_ENTRY(NID_id_regCtrl_pkiPublicationInfo,
  123. ASN1_SIMPLE(OSSL_CRMF_ATTRIBUTETYPEANDVALUE,
  124. value.pkiPublicationInfo,
  125. OSSL_CRMF_PKIPUBLICATIONINFO)),
  126. ADB_ENTRY(NID_id_regCtrl_oldCertID,
  127. ASN1_SIMPLE(OSSL_CRMF_ATTRIBUTETYPEANDVALUE,
  128. value.oldCertID, OSSL_CRMF_CERTID)),
  129. ADB_ENTRY(NID_id_regCtrl_protocolEncrKey,
  130. ASN1_SIMPLE(OSSL_CRMF_ATTRIBUTETYPEANDVALUE,
  131. value.protocolEncrKey, X509_PUBKEY)),
  132. ADB_ENTRY(NID_id_regInfo_utf8Pairs,
  133. ASN1_SIMPLE(OSSL_CRMF_ATTRIBUTETYPEANDVALUE,
  134. value.utf8Pairs, ASN1_UTF8STRING)),
  135. ADB_ENTRY(NID_id_regInfo_certReq,
  136. ASN1_SIMPLE(OSSL_CRMF_ATTRIBUTETYPEANDVALUE,
  137. value.certReq, OSSL_CRMF_CERTREQUEST)),
  138. } ASN1_ADB_END(OSSL_CRMF_ATTRIBUTETYPEANDVALUE, 0, type, 0,
  139. &attributetypeandvalue_default_tt, NULL);
  140. ASN1_SEQUENCE(OSSL_CRMF_ATTRIBUTETYPEANDVALUE) = {
  141. ASN1_SIMPLE(OSSL_CRMF_ATTRIBUTETYPEANDVALUE, type, ASN1_OBJECT),
  142. ASN1_ADB_OBJECT(OSSL_CRMF_ATTRIBUTETYPEANDVALUE)
  143. } ASN1_SEQUENCE_END(OSSL_CRMF_ATTRIBUTETYPEANDVALUE)
  144. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_ATTRIBUTETYPEANDVALUE)
  145. IMPLEMENT_ASN1_DUP_FUNCTION(OSSL_CRMF_ATTRIBUTETYPEANDVALUE)
  146. ASN1_SEQUENCE(OSSL_CRMF_OPTIONALVALIDITY) = {
  147. ASN1_EXP_OPT(OSSL_CRMF_OPTIONALVALIDITY, notBefore, ASN1_TIME, 0),
  148. ASN1_EXP_OPT(OSSL_CRMF_OPTIONALVALIDITY, notAfter, ASN1_TIME, 1)
  149. } ASN1_SEQUENCE_END(OSSL_CRMF_OPTIONALVALIDITY)
  150. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_OPTIONALVALIDITY)
  151. ASN1_SEQUENCE(OSSL_CRMF_CERTTEMPLATE) = {
  152. ASN1_IMP_OPT(OSSL_CRMF_CERTTEMPLATE, version, ASN1_INTEGER, 0),
  153. /*
  154. * serialNumber MUST be omitted. This field is assigned by the CA
  155. * during certificate creation.
  156. */
  157. ASN1_IMP_OPT(OSSL_CRMF_CERTTEMPLATE, serialNumber, ASN1_INTEGER, 1),
  158. /*
  159. * signingAlg MUST be omitted. This field is assigned by the CA
  160. * during certificate creation.
  161. */
  162. ASN1_IMP_OPT(OSSL_CRMF_CERTTEMPLATE, signingAlg, X509_ALGOR, 2),
  163. ASN1_EXP_OPT(OSSL_CRMF_CERTTEMPLATE, issuer, X509_NAME, 3),
  164. ASN1_IMP_OPT(OSSL_CRMF_CERTTEMPLATE, validity,
  165. OSSL_CRMF_OPTIONALVALIDITY, 4),
  166. ASN1_EXP_OPT(OSSL_CRMF_CERTTEMPLATE, subject, X509_NAME, 5),
  167. ASN1_IMP_OPT(OSSL_CRMF_CERTTEMPLATE, publicKey, X509_PUBKEY, 6),
  168. /* issuerUID is deprecated in version 2 */
  169. ASN1_IMP_OPT(OSSL_CRMF_CERTTEMPLATE, issuerUID, ASN1_BIT_STRING, 7),
  170. /* subjectUID is deprecated in version 2 */
  171. ASN1_IMP_OPT(OSSL_CRMF_CERTTEMPLATE, subjectUID, ASN1_BIT_STRING, 8),
  172. ASN1_IMP_SEQUENCE_OF_OPT(OSSL_CRMF_CERTTEMPLATE, extensions,
  173. X509_EXTENSION, 9),
  174. } ASN1_SEQUENCE_END(OSSL_CRMF_CERTTEMPLATE)
  175. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_CERTTEMPLATE)
  176. ASN1_SEQUENCE(OSSL_CRMF_CERTREQUEST) = {
  177. ASN1_SIMPLE(OSSL_CRMF_CERTREQUEST, certReqId, ASN1_INTEGER),
  178. ASN1_SIMPLE(OSSL_CRMF_CERTREQUEST, certTemplate, OSSL_CRMF_CERTTEMPLATE),
  179. ASN1_SEQUENCE_OF_OPT(OSSL_CRMF_CERTREQUEST, controls,
  180. OSSL_CRMF_ATTRIBUTETYPEANDVALUE)
  181. } ASN1_SEQUENCE_END(OSSL_CRMF_CERTREQUEST)
  182. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_CERTREQUEST)
  183. IMPLEMENT_ASN1_DUP_FUNCTION(OSSL_CRMF_CERTREQUEST)
  184. ASN1_SEQUENCE(OSSL_CRMF_MSG) = {
  185. ASN1_SIMPLE(OSSL_CRMF_MSG, certReq, OSSL_CRMF_CERTREQUEST),
  186. ASN1_OPT(OSSL_CRMF_MSG, popo, OSSL_CRMF_POPO),
  187. ASN1_SEQUENCE_OF_OPT(OSSL_CRMF_MSG, regInfo,
  188. OSSL_CRMF_ATTRIBUTETYPEANDVALUE)
  189. } ASN1_SEQUENCE_END(OSSL_CRMF_MSG)
  190. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_MSG)
  191. ASN1_ITEM_TEMPLATE(OSSL_CRMF_MSGS) =
  192. ASN1_EX_TEMPLATE_TYPE(ASN1_TFLG_SEQUENCE_OF, 0,
  193. OSSL_CRMF_MSGS, OSSL_CRMF_MSG)
  194. ASN1_ITEM_TEMPLATE_END(OSSL_CRMF_MSGS)
  195. IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_MSGS)