pk7_lib.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589
  1. /*
  2. * Copyright 1995-2016 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the OpenSSL license (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. #include <stdio.h>
  10. #include "internal/cryptlib.h"
  11. #include <openssl/objects.h>
  12. #include <openssl/x509.h>
  13. #include "internal/asn1_int.h"
  14. #include "internal/evp_int.h"
  15. long PKCS7_ctrl(PKCS7 *p7, int cmd, long larg, char *parg)
  16. {
  17. int nid;
  18. long ret;
  19. nid = OBJ_obj2nid(p7->type);
  20. switch (cmd) {
  21. /* NOTE(emilia): does not support detached digested data. */
  22. case PKCS7_OP_SET_DETACHED_SIGNATURE:
  23. if (nid == NID_pkcs7_signed) {
  24. ret = p7->detached = (int)larg;
  25. if (ret && PKCS7_type_is_data(p7->d.sign->contents)) {
  26. ASN1_OCTET_STRING *os;
  27. os = p7->d.sign->contents->d.data;
  28. ASN1_OCTET_STRING_free(os);
  29. p7->d.sign->contents->d.data = NULL;
  30. }
  31. } else {
  32. PKCS7err(PKCS7_F_PKCS7_CTRL,
  33. PKCS7_R_OPERATION_NOT_SUPPORTED_ON_THIS_TYPE);
  34. ret = 0;
  35. }
  36. break;
  37. case PKCS7_OP_GET_DETACHED_SIGNATURE:
  38. if (nid == NID_pkcs7_signed) {
  39. if (!p7->d.sign || !p7->d.sign->contents->d.ptr)
  40. ret = 1;
  41. else
  42. ret = 0;
  43. p7->detached = ret;
  44. } else {
  45. PKCS7err(PKCS7_F_PKCS7_CTRL,
  46. PKCS7_R_OPERATION_NOT_SUPPORTED_ON_THIS_TYPE);
  47. ret = 0;
  48. }
  49. break;
  50. default:
  51. PKCS7err(PKCS7_F_PKCS7_CTRL, PKCS7_R_UNKNOWN_OPERATION);
  52. ret = 0;
  53. }
  54. return (ret);
  55. }
  56. int PKCS7_content_new(PKCS7 *p7, int type)
  57. {
  58. PKCS7 *ret = NULL;
  59. if ((ret = PKCS7_new()) == NULL)
  60. goto err;
  61. if (!PKCS7_set_type(ret, type))
  62. goto err;
  63. if (!PKCS7_set_content(p7, ret))
  64. goto err;
  65. return (1);
  66. err:
  67. PKCS7_free(ret);
  68. return (0);
  69. }
  70. int PKCS7_set_content(PKCS7 *p7, PKCS7 *p7_data)
  71. {
  72. int i;
  73. i = OBJ_obj2nid(p7->type);
  74. switch (i) {
  75. case NID_pkcs7_signed:
  76. PKCS7_free(p7->d.sign->contents);
  77. p7->d.sign->contents = p7_data;
  78. break;
  79. case NID_pkcs7_digest:
  80. PKCS7_free(p7->d.digest->contents);
  81. p7->d.digest->contents = p7_data;
  82. break;
  83. case NID_pkcs7_data:
  84. case NID_pkcs7_enveloped:
  85. case NID_pkcs7_signedAndEnveloped:
  86. case NID_pkcs7_encrypted:
  87. default:
  88. PKCS7err(PKCS7_F_PKCS7_SET_CONTENT, PKCS7_R_UNSUPPORTED_CONTENT_TYPE);
  89. goto err;
  90. }
  91. return (1);
  92. err:
  93. return (0);
  94. }
  95. int PKCS7_set_type(PKCS7 *p7, int type)
  96. {
  97. ASN1_OBJECT *obj;
  98. /*
  99. * PKCS7_content_free(p7);
  100. */
  101. obj = OBJ_nid2obj(type); /* will not fail */
  102. switch (type) {
  103. case NID_pkcs7_signed:
  104. p7->type = obj;
  105. if ((p7->d.sign = PKCS7_SIGNED_new()) == NULL)
  106. goto err;
  107. if (!ASN1_INTEGER_set(p7->d.sign->version, 1)) {
  108. PKCS7_SIGNED_free(p7->d.sign);
  109. p7->d.sign = NULL;
  110. goto err;
  111. }
  112. break;
  113. case NID_pkcs7_data:
  114. p7->type = obj;
  115. if ((p7->d.data = ASN1_OCTET_STRING_new()) == NULL)
  116. goto err;
  117. break;
  118. case NID_pkcs7_signedAndEnveloped:
  119. p7->type = obj;
  120. if ((p7->d.signed_and_enveloped = PKCS7_SIGN_ENVELOPE_new())
  121. == NULL)
  122. goto err;
  123. ASN1_INTEGER_set(p7->d.signed_and_enveloped->version, 1);
  124. if (!ASN1_INTEGER_set(p7->d.signed_and_enveloped->version, 1))
  125. goto err;
  126. p7->d.signed_and_enveloped->enc_data->content_type
  127. = OBJ_nid2obj(NID_pkcs7_data);
  128. break;
  129. case NID_pkcs7_enveloped:
  130. p7->type = obj;
  131. if ((p7->d.enveloped = PKCS7_ENVELOPE_new())
  132. == NULL)
  133. goto err;
  134. if (!ASN1_INTEGER_set(p7->d.enveloped->version, 0))
  135. goto err;
  136. p7->d.enveloped->enc_data->content_type = OBJ_nid2obj(NID_pkcs7_data);
  137. break;
  138. case NID_pkcs7_encrypted:
  139. p7->type = obj;
  140. if ((p7->d.encrypted = PKCS7_ENCRYPT_new())
  141. == NULL)
  142. goto err;
  143. if (!ASN1_INTEGER_set(p7->d.encrypted->version, 0))
  144. goto err;
  145. p7->d.encrypted->enc_data->content_type = OBJ_nid2obj(NID_pkcs7_data);
  146. break;
  147. case NID_pkcs7_digest:
  148. p7->type = obj;
  149. if ((p7->d.digest = PKCS7_DIGEST_new())
  150. == NULL)
  151. goto err;
  152. if (!ASN1_INTEGER_set(p7->d.digest->version, 0))
  153. goto err;
  154. break;
  155. default:
  156. PKCS7err(PKCS7_F_PKCS7_SET_TYPE, PKCS7_R_UNSUPPORTED_CONTENT_TYPE);
  157. goto err;
  158. }
  159. return (1);
  160. err:
  161. return (0);
  162. }
  163. int PKCS7_set0_type_other(PKCS7 *p7, int type, ASN1_TYPE *other)
  164. {
  165. p7->type = OBJ_nid2obj(type);
  166. p7->d.other = other;
  167. return 1;
  168. }
  169. int PKCS7_add_signer(PKCS7 *p7, PKCS7_SIGNER_INFO *psi)
  170. {
  171. int i, j, nid;
  172. X509_ALGOR *alg;
  173. STACK_OF(PKCS7_SIGNER_INFO) *signer_sk;
  174. STACK_OF(X509_ALGOR) *md_sk;
  175. i = OBJ_obj2nid(p7->type);
  176. switch (i) {
  177. case NID_pkcs7_signed:
  178. signer_sk = p7->d.sign->signer_info;
  179. md_sk = p7->d.sign->md_algs;
  180. break;
  181. case NID_pkcs7_signedAndEnveloped:
  182. signer_sk = p7->d.signed_and_enveloped->signer_info;
  183. md_sk = p7->d.signed_and_enveloped->md_algs;
  184. break;
  185. default:
  186. PKCS7err(PKCS7_F_PKCS7_ADD_SIGNER, PKCS7_R_WRONG_CONTENT_TYPE);
  187. return (0);
  188. }
  189. nid = OBJ_obj2nid(psi->digest_alg->algorithm);
  190. /* If the digest is not currently listed, add it */
  191. j = 0;
  192. for (i = 0; i < sk_X509_ALGOR_num(md_sk); i++) {
  193. alg = sk_X509_ALGOR_value(md_sk, i);
  194. if (OBJ_obj2nid(alg->algorithm) == nid) {
  195. j = 1;
  196. break;
  197. }
  198. }
  199. if (!j) { /* we need to add another algorithm */
  200. if ((alg = X509_ALGOR_new()) == NULL
  201. || (alg->parameter = ASN1_TYPE_new()) == NULL) {
  202. X509_ALGOR_free(alg);
  203. PKCS7err(PKCS7_F_PKCS7_ADD_SIGNER, ERR_R_MALLOC_FAILURE);
  204. return (0);
  205. }
  206. alg->algorithm = OBJ_nid2obj(nid);
  207. alg->parameter->type = V_ASN1_NULL;
  208. if (!sk_X509_ALGOR_push(md_sk, alg)) {
  209. X509_ALGOR_free(alg);
  210. return 0;
  211. }
  212. }
  213. if (!sk_PKCS7_SIGNER_INFO_push(signer_sk, psi))
  214. return 0;
  215. return (1);
  216. }
  217. int PKCS7_add_certificate(PKCS7 *p7, X509 *x509)
  218. {
  219. int i;
  220. STACK_OF(X509) **sk;
  221. i = OBJ_obj2nid(p7->type);
  222. switch (i) {
  223. case NID_pkcs7_signed:
  224. sk = &(p7->d.sign->cert);
  225. break;
  226. case NID_pkcs7_signedAndEnveloped:
  227. sk = &(p7->d.signed_and_enveloped->cert);
  228. break;
  229. default:
  230. PKCS7err(PKCS7_F_PKCS7_ADD_CERTIFICATE, PKCS7_R_WRONG_CONTENT_TYPE);
  231. return (0);
  232. }
  233. if (*sk == NULL)
  234. *sk = sk_X509_new_null();
  235. if (*sk == NULL) {
  236. PKCS7err(PKCS7_F_PKCS7_ADD_CERTIFICATE, ERR_R_MALLOC_FAILURE);
  237. return 0;
  238. }
  239. X509_up_ref(x509);
  240. if (!sk_X509_push(*sk, x509)) {
  241. X509_free(x509);
  242. return 0;
  243. }
  244. return (1);
  245. }
  246. int PKCS7_add_crl(PKCS7 *p7, X509_CRL *crl)
  247. {
  248. int i;
  249. STACK_OF(X509_CRL) **sk;
  250. i = OBJ_obj2nid(p7->type);
  251. switch (i) {
  252. case NID_pkcs7_signed:
  253. sk = &(p7->d.sign->crl);
  254. break;
  255. case NID_pkcs7_signedAndEnveloped:
  256. sk = &(p7->d.signed_and_enveloped->crl);
  257. break;
  258. default:
  259. PKCS7err(PKCS7_F_PKCS7_ADD_CRL, PKCS7_R_WRONG_CONTENT_TYPE);
  260. return (0);
  261. }
  262. if (*sk == NULL)
  263. *sk = sk_X509_CRL_new_null();
  264. if (*sk == NULL) {
  265. PKCS7err(PKCS7_F_PKCS7_ADD_CRL, ERR_R_MALLOC_FAILURE);
  266. return 0;
  267. }
  268. X509_CRL_up_ref(crl);
  269. if (!sk_X509_CRL_push(*sk, crl)) {
  270. X509_CRL_free(crl);
  271. return 0;
  272. }
  273. return (1);
  274. }
  275. int PKCS7_SIGNER_INFO_set(PKCS7_SIGNER_INFO *p7i, X509 *x509, EVP_PKEY *pkey,
  276. const EVP_MD *dgst)
  277. {
  278. int ret;
  279. /* We now need to add another PKCS7_SIGNER_INFO entry */
  280. if (!ASN1_INTEGER_set(p7i->version, 1))
  281. goto err;
  282. if (!X509_NAME_set(&p7i->issuer_and_serial->issuer,
  283. X509_get_issuer_name(x509)))
  284. goto err;
  285. /*
  286. * because ASN1_INTEGER_set is used to set a 'long' we will do things the
  287. * ugly way.
  288. */
  289. ASN1_INTEGER_free(p7i->issuer_and_serial->serial);
  290. if (!(p7i->issuer_and_serial->serial =
  291. ASN1_INTEGER_dup(X509_get_serialNumber(x509))))
  292. goto err;
  293. /* lets keep the pkey around for a while */
  294. EVP_PKEY_up_ref(pkey);
  295. p7i->pkey = pkey;
  296. /* Set the algorithms */
  297. X509_ALGOR_set0(p7i->digest_alg, OBJ_nid2obj(EVP_MD_type(dgst)),
  298. V_ASN1_NULL, NULL);
  299. if (pkey->ameth && pkey->ameth->pkey_ctrl) {
  300. ret = pkey->ameth->pkey_ctrl(pkey, ASN1_PKEY_CTRL_PKCS7_SIGN, 0, p7i);
  301. if (ret > 0)
  302. return 1;
  303. if (ret != -2) {
  304. PKCS7err(PKCS7_F_PKCS7_SIGNER_INFO_SET,
  305. PKCS7_R_SIGNING_CTRL_FAILURE);
  306. return 0;
  307. }
  308. }
  309. PKCS7err(PKCS7_F_PKCS7_SIGNER_INFO_SET,
  310. PKCS7_R_SIGNING_NOT_SUPPORTED_FOR_THIS_KEY_TYPE);
  311. err:
  312. return 0;
  313. }
  314. PKCS7_SIGNER_INFO *PKCS7_add_signature(PKCS7 *p7, X509 *x509, EVP_PKEY *pkey,
  315. const EVP_MD *dgst)
  316. {
  317. PKCS7_SIGNER_INFO *si = NULL;
  318. if (dgst == NULL) {
  319. int def_nid;
  320. if (EVP_PKEY_get_default_digest_nid(pkey, &def_nid) <= 0)
  321. goto err;
  322. dgst = EVP_get_digestbynid(def_nid);
  323. if (dgst == NULL) {
  324. PKCS7err(PKCS7_F_PKCS7_ADD_SIGNATURE, PKCS7_R_NO_DEFAULT_DIGEST);
  325. goto err;
  326. }
  327. }
  328. if ((si = PKCS7_SIGNER_INFO_new()) == NULL)
  329. goto err;
  330. if (!PKCS7_SIGNER_INFO_set(si, x509, pkey, dgst))
  331. goto err;
  332. if (!PKCS7_add_signer(p7, si))
  333. goto err;
  334. return (si);
  335. err:
  336. PKCS7_SIGNER_INFO_free(si);
  337. return (NULL);
  338. }
  339. int PKCS7_set_digest(PKCS7 *p7, const EVP_MD *md)
  340. {
  341. if (PKCS7_type_is_digest(p7)) {
  342. if ((p7->d.digest->md->parameter = ASN1_TYPE_new()) == NULL) {
  343. PKCS7err(PKCS7_F_PKCS7_SET_DIGEST, ERR_R_MALLOC_FAILURE);
  344. return 0;
  345. }
  346. p7->d.digest->md->parameter->type = V_ASN1_NULL;
  347. p7->d.digest->md->algorithm = OBJ_nid2obj(EVP_MD_nid(md));
  348. return 1;
  349. }
  350. PKCS7err(PKCS7_F_PKCS7_SET_DIGEST, PKCS7_R_WRONG_CONTENT_TYPE);
  351. return 1;
  352. }
  353. STACK_OF(PKCS7_SIGNER_INFO) *PKCS7_get_signer_info(PKCS7 *p7)
  354. {
  355. if (p7 == NULL || p7->d.ptr == NULL)
  356. return NULL;
  357. if (PKCS7_type_is_signed(p7)) {
  358. return (p7->d.sign->signer_info);
  359. } else if (PKCS7_type_is_signedAndEnveloped(p7)) {
  360. return (p7->d.signed_and_enveloped->signer_info);
  361. } else
  362. return (NULL);
  363. }
  364. void PKCS7_SIGNER_INFO_get0_algs(PKCS7_SIGNER_INFO *si, EVP_PKEY **pk,
  365. X509_ALGOR **pdig, X509_ALGOR **psig)
  366. {
  367. if (pk)
  368. *pk = si->pkey;
  369. if (pdig)
  370. *pdig = si->digest_alg;
  371. if (psig)
  372. *psig = si->digest_enc_alg;
  373. }
  374. void PKCS7_RECIP_INFO_get0_alg(PKCS7_RECIP_INFO *ri, X509_ALGOR **penc)
  375. {
  376. if (penc)
  377. *penc = ri->key_enc_algor;
  378. }
  379. PKCS7_RECIP_INFO *PKCS7_add_recipient(PKCS7 *p7, X509 *x509)
  380. {
  381. PKCS7_RECIP_INFO *ri;
  382. if ((ri = PKCS7_RECIP_INFO_new()) == NULL)
  383. goto err;
  384. if (!PKCS7_RECIP_INFO_set(ri, x509))
  385. goto err;
  386. if (!PKCS7_add_recipient_info(p7, ri))
  387. goto err;
  388. return ri;
  389. err:
  390. PKCS7_RECIP_INFO_free(ri);
  391. return NULL;
  392. }
  393. int PKCS7_add_recipient_info(PKCS7 *p7, PKCS7_RECIP_INFO *ri)
  394. {
  395. int i;
  396. STACK_OF(PKCS7_RECIP_INFO) *sk;
  397. i = OBJ_obj2nid(p7->type);
  398. switch (i) {
  399. case NID_pkcs7_signedAndEnveloped:
  400. sk = p7->d.signed_and_enveloped->recipientinfo;
  401. break;
  402. case NID_pkcs7_enveloped:
  403. sk = p7->d.enveloped->recipientinfo;
  404. break;
  405. default:
  406. PKCS7err(PKCS7_F_PKCS7_ADD_RECIPIENT_INFO,
  407. PKCS7_R_WRONG_CONTENT_TYPE);
  408. return (0);
  409. }
  410. if (!sk_PKCS7_RECIP_INFO_push(sk, ri))
  411. return 0;
  412. return (1);
  413. }
  414. int PKCS7_RECIP_INFO_set(PKCS7_RECIP_INFO *p7i, X509 *x509)
  415. {
  416. int ret;
  417. EVP_PKEY *pkey = NULL;
  418. if (!ASN1_INTEGER_set(p7i->version, 0))
  419. return 0;
  420. if (!X509_NAME_set(&p7i->issuer_and_serial->issuer,
  421. X509_get_issuer_name(x509)))
  422. return 0;
  423. ASN1_INTEGER_free(p7i->issuer_and_serial->serial);
  424. if (!(p7i->issuer_and_serial->serial =
  425. ASN1_INTEGER_dup(X509_get_serialNumber(x509))))
  426. return 0;
  427. pkey = X509_get0_pubkey(x509);
  428. if (!pkey || !pkey->ameth || !pkey->ameth->pkey_ctrl) {
  429. PKCS7err(PKCS7_F_PKCS7_RECIP_INFO_SET,
  430. PKCS7_R_ENCRYPTION_NOT_SUPPORTED_FOR_THIS_KEY_TYPE);
  431. goto err;
  432. }
  433. ret = pkey->ameth->pkey_ctrl(pkey, ASN1_PKEY_CTRL_PKCS7_ENCRYPT, 0, p7i);
  434. if (ret == -2) {
  435. PKCS7err(PKCS7_F_PKCS7_RECIP_INFO_SET,
  436. PKCS7_R_ENCRYPTION_NOT_SUPPORTED_FOR_THIS_KEY_TYPE);
  437. goto err;
  438. }
  439. if (ret <= 0) {
  440. PKCS7err(PKCS7_F_PKCS7_RECIP_INFO_SET,
  441. PKCS7_R_ENCRYPTION_CTRL_FAILURE);
  442. goto err;
  443. }
  444. X509_up_ref(x509);
  445. p7i->cert = x509;
  446. return 1;
  447. err:
  448. return 0;
  449. }
  450. X509 *PKCS7_cert_from_signer_info(PKCS7 *p7, PKCS7_SIGNER_INFO *si)
  451. {
  452. if (PKCS7_type_is_signed(p7))
  453. return (X509_find_by_issuer_and_serial(p7->d.sign->cert,
  454. si->issuer_and_serial->issuer,
  455. si->
  456. issuer_and_serial->serial));
  457. else
  458. return (NULL);
  459. }
  460. int PKCS7_set_cipher(PKCS7 *p7, const EVP_CIPHER *cipher)
  461. {
  462. int i;
  463. PKCS7_ENC_CONTENT *ec;
  464. i = OBJ_obj2nid(p7->type);
  465. switch (i) {
  466. case NID_pkcs7_signedAndEnveloped:
  467. ec = p7->d.signed_and_enveloped->enc_data;
  468. break;
  469. case NID_pkcs7_enveloped:
  470. ec = p7->d.enveloped->enc_data;
  471. break;
  472. default:
  473. PKCS7err(PKCS7_F_PKCS7_SET_CIPHER, PKCS7_R_WRONG_CONTENT_TYPE);
  474. return (0);
  475. }
  476. /* Check cipher OID exists and has data in it */
  477. i = EVP_CIPHER_type(cipher);
  478. if (i == NID_undef) {
  479. PKCS7err(PKCS7_F_PKCS7_SET_CIPHER,
  480. PKCS7_R_CIPHER_HAS_NO_OBJECT_IDENTIFIER);
  481. return (0);
  482. }
  483. ec->cipher = cipher;
  484. return 1;
  485. }
  486. int PKCS7_stream(unsigned char ***boundary, PKCS7 *p7)
  487. {
  488. ASN1_OCTET_STRING *os = NULL;
  489. switch (OBJ_obj2nid(p7->type)) {
  490. case NID_pkcs7_data:
  491. os = p7->d.data;
  492. break;
  493. case NID_pkcs7_signedAndEnveloped:
  494. os = p7->d.signed_and_enveloped->enc_data->enc_data;
  495. if (os == NULL) {
  496. os = ASN1_OCTET_STRING_new();
  497. p7->d.signed_and_enveloped->enc_data->enc_data = os;
  498. }
  499. break;
  500. case NID_pkcs7_enveloped:
  501. os = p7->d.enveloped->enc_data->enc_data;
  502. if (os == NULL) {
  503. os = ASN1_OCTET_STRING_new();
  504. p7->d.enveloped->enc_data->enc_data = os;
  505. }
  506. break;
  507. case NID_pkcs7_signed:
  508. os = p7->d.sign->contents->d.data;
  509. break;
  510. default:
  511. os = NULL;
  512. break;
  513. }
  514. if (os == NULL)
  515. return 0;
  516. os->flags |= ASN1_STRING_FLAG_NDEF;
  517. *boundary = &os->data;
  518. return 1;
  519. }