x509name.c 9.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359
  1. /*
  2. * Copyright 1995-2020 The OpenSSL Project Authors. All Rights Reserved.
  3. *
  4. * Licensed under the Apache License 2.0 (the "License"). You may not use
  5. * this file except in compliance with the License. You can obtain a copy
  6. * in the file LICENSE in the source distribution or at
  7. * https://www.openssl.org/source/license.html
  8. */
  9. #include <stdio.h>
  10. #include "internal/cryptlib.h"
  11. #include <openssl/safestack.h>
  12. #include <openssl/asn1.h>
  13. #include <openssl/objects.h>
  14. #include <openssl/evp.h>
  15. #include <openssl/x509.h>
  16. #include "crypto/x509.h"
  17. int X509_NAME_get_text_by_NID(const X509_NAME *name, int nid,
  18. char *buf, int len)
  19. {
  20. ASN1_OBJECT *obj;
  21. obj = OBJ_nid2obj(nid);
  22. if (obj == NULL)
  23. return -1;
  24. return X509_NAME_get_text_by_OBJ(name, obj, buf, len);
  25. }
  26. int X509_NAME_get_text_by_OBJ(const X509_NAME *name, const ASN1_OBJECT *obj,
  27. char *buf, int len)
  28. {
  29. int i;
  30. const ASN1_STRING *data;
  31. i = X509_NAME_get_index_by_OBJ(name, obj, -1);
  32. if (i < 0)
  33. return -1;
  34. data = X509_NAME_ENTRY_get_data(X509_NAME_get_entry(name, i));
  35. if (buf == NULL)
  36. return data->length;
  37. if (len <= 0)
  38. return 0;
  39. i = (data->length > (len - 1)) ? (len - 1) : data->length;
  40. memcpy(buf, data->data, i);
  41. buf[i] = '\0';
  42. return i;
  43. }
  44. int X509_NAME_entry_count(const X509_NAME *name)
  45. {
  46. int ret;
  47. if (name == NULL)
  48. return 0;
  49. ret = sk_X509_NAME_ENTRY_num(name->entries);
  50. return ret > 0 ? ret : 0;
  51. }
  52. int X509_NAME_get_index_by_NID(const X509_NAME *name, int nid, int lastpos)
  53. {
  54. ASN1_OBJECT *obj;
  55. obj = OBJ_nid2obj(nid);
  56. if (obj == NULL)
  57. return -2;
  58. return X509_NAME_get_index_by_OBJ(name, obj, lastpos);
  59. }
  60. /* NOTE: you should be passing -1, not 0 as lastpos */
  61. int X509_NAME_get_index_by_OBJ(const X509_NAME *name, const ASN1_OBJECT *obj,
  62. int lastpos)
  63. {
  64. int n;
  65. X509_NAME_ENTRY *ne;
  66. STACK_OF(X509_NAME_ENTRY) *sk;
  67. if (name == NULL)
  68. return -1;
  69. if (lastpos < 0)
  70. lastpos = -1;
  71. sk = name->entries;
  72. n = sk_X509_NAME_ENTRY_num(sk);
  73. for (lastpos++; lastpos < n; lastpos++) {
  74. ne = sk_X509_NAME_ENTRY_value(sk, lastpos);
  75. if (OBJ_cmp(ne->object, obj) == 0)
  76. return lastpos;
  77. }
  78. return -1;
  79. }
  80. X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc)
  81. {
  82. if (name == NULL || sk_X509_NAME_ENTRY_num(name->entries) <= loc
  83. || loc < 0)
  84. return NULL;
  85. return sk_X509_NAME_ENTRY_value(name->entries, loc);
  86. }
  87. X509_NAME_ENTRY *X509_NAME_delete_entry(X509_NAME *name, int loc)
  88. {
  89. X509_NAME_ENTRY *ret;
  90. int i, n, set_prev, set_next;
  91. STACK_OF(X509_NAME_ENTRY) *sk;
  92. if (name == NULL || sk_X509_NAME_ENTRY_num(name->entries) <= loc
  93. || loc < 0)
  94. return NULL;
  95. sk = name->entries;
  96. ret = sk_X509_NAME_ENTRY_delete(sk, loc);
  97. n = sk_X509_NAME_ENTRY_num(sk);
  98. name->modified = 1;
  99. if (loc == n)
  100. return ret;
  101. /* else we need to fixup the set field */
  102. if (loc != 0)
  103. set_prev = (sk_X509_NAME_ENTRY_value(sk, loc - 1))->set;
  104. else
  105. set_prev = ret->set - 1;
  106. set_next = sk_X509_NAME_ENTRY_value(sk, loc)->set;
  107. /*-
  108. * set_prev is the previous set
  109. * set is the current set
  110. * set_next is the following
  111. * prev 1 1 1 1 1 1 1 1
  112. * set 1 1 2 2
  113. * next 1 1 2 2 2 2 3 2
  114. * so basically only if prev and next differ by 2, then
  115. * re-number down by 1
  116. */
  117. if (set_prev + 1 < set_next)
  118. for (i = loc; i < n; i++)
  119. sk_X509_NAME_ENTRY_value(sk, i)->set--;
  120. return ret;
  121. }
  122. int X509_NAME_add_entry_by_OBJ(X509_NAME *name, const ASN1_OBJECT *obj, int type,
  123. const unsigned char *bytes, int len, int loc,
  124. int set)
  125. {
  126. X509_NAME_ENTRY *ne;
  127. int ret;
  128. ne = X509_NAME_ENTRY_create_by_OBJ(NULL, obj, type, bytes, len);
  129. if (!ne)
  130. return 0;
  131. ret = X509_NAME_add_entry(name, ne, loc, set);
  132. X509_NAME_ENTRY_free(ne);
  133. return ret;
  134. }
  135. int X509_NAME_add_entry_by_NID(X509_NAME *name, int nid, int type,
  136. const unsigned char *bytes, int len, int loc,
  137. int set)
  138. {
  139. X509_NAME_ENTRY *ne;
  140. int ret;
  141. ne = X509_NAME_ENTRY_create_by_NID(NULL, nid, type, bytes, len);
  142. if (!ne)
  143. return 0;
  144. ret = X509_NAME_add_entry(name, ne, loc, set);
  145. X509_NAME_ENTRY_free(ne);
  146. return ret;
  147. }
  148. int X509_NAME_add_entry_by_txt(X509_NAME *name, const char *field, int type,
  149. const unsigned char *bytes, int len, int loc,
  150. int set)
  151. {
  152. X509_NAME_ENTRY *ne;
  153. int ret;
  154. ne = X509_NAME_ENTRY_create_by_txt(NULL, field, type, bytes, len);
  155. if (!ne)
  156. return 0;
  157. ret = X509_NAME_add_entry(name, ne, loc, set);
  158. X509_NAME_ENTRY_free(ne);
  159. return ret;
  160. }
  161. /*
  162. * if set is -1, append to previous set, 0 'a new one', and 1, prepend to the
  163. * guy we are about to stomp on.
  164. */
  165. int X509_NAME_add_entry(X509_NAME *name, const X509_NAME_ENTRY *ne, int loc,
  166. int set)
  167. {
  168. X509_NAME_ENTRY *new_name = NULL;
  169. int n, i, inc;
  170. STACK_OF(X509_NAME_ENTRY) *sk;
  171. if (name == NULL)
  172. return 0;
  173. sk = name->entries;
  174. n = sk_X509_NAME_ENTRY_num(sk);
  175. if (loc > n)
  176. loc = n;
  177. else if (loc < 0)
  178. loc = n;
  179. inc = (set == 0);
  180. name->modified = 1;
  181. if (set == -1) {
  182. if (loc == 0) {
  183. set = 0;
  184. inc = 1;
  185. } else {
  186. set = sk_X509_NAME_ENTRY_value(sk, loc - 1)->set;
  187. }
  188. } else { /* if (set >= 0) */
  189. if (loc >= n) {
  190. if (loc != 0)
  191. set = sk_X509_NAME_ENTRY_value(sk, loc - 1)->set + 1;
  192. else
  193. set = 0;
  194. } else
  195. set = sk_X509_NAME_ENTRY_value(sk, loc)->set;
  196. }
  197. if ((new_name = X509_NAME_ENTRY_dup(ne)) == NULL)
  198. goto err;
  199. new_name->set = set;
  200. if (!sk_X509_NAME_ENTRY_insert(sk, new_name, loc)) {
  201. ERR_raise(ERR_LIB_X509, ERR_R_CRYPTO_LIB);
  202. goto err;
  203. }
  204. if (inc) {
  205. n = sk_X509_NAME_ENTRY_num(sk);
  206. for (i = loc + 1; i < n; i++)
  207. sk_X509_NAME_ENTRY_value(sk, i)->set += 1;
  208. }
  209. return 1;
  210. err:
  211. X509_NAME_ENTRY_free(new_name);
  212. return 0;
  213. }
  214. X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_txt(X509_NAME_ENTRY **ne,
  215. const char *field, int type,
  216. const unsigned char *bytes,
  217. int len)
  218. {
  219. ASN1_OBJECT *obj;
  220. X509_NAME_ENTRY *nentry;
  221. obj = OBJ_txt2obj(field, 0);
  222. if (obj == NULL) {
  223. ERR_raise_data(ERR_LIB_X509, X509_R_INVALID_FIELD_NAME,
  224. "name=%s", field);
  225. return NULL;
  226. }
  227. nentry = X509_NAME_ENTRY_create_by_OBJ(ne, obj, type, bytes, len);
  228. ASN1_OBJECT_free(obj);
  229. return nentry;
  230. }
  231. X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_NID(X509_NAME_ENTRY **ne, int nid,
  232. int type,
  233. const unsigned char *bytes,
  234. int len)
  235. {
  236. ASN1_OBJECT *obj;
  237. X509_NAME_ENTRY *nentry;
  238. obj = OBJ_nid2obj(nid);
  239. if (obj == NULL) {
  240. ERR_raise(ERR_LIB_X509, X509_R_UNKNOWN_NID);
  241. return NULL;
  242. }
  243. nentry = X509_NAME_ENTRY_create_by_OBJ(ne, obj, type, bytes, len);
  244. ASN1_OBJECT_free(obj);
  245. return nentry;
  246. }
  247. X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_OBJ(X509_NAME_ENTRY **ne,
  248. const ASN1_OBJECT *obj, int type,
  249. const unsigned char *bytes,
  250. int len)
  251. {
  252. X509_NAME_ENTRY *ret;
  253. if ((ne == NULL) || (*ne == NULL)) {
  254. if ((ret = X509_NAME_ENTRY_new()) == NULL)
  255. return NULL;
  256. } else
  257. ret = *ne;
  258. if (!X509_NAME_ENTRY_set_object(ret, obj))
  259. goto err;
  260. if (!X509_NAME_ENTRY_set_data(ret, type, bytes, len))
  261. goto err;
  262. if ((ne != NULL) && (*ne == NULL))
  263. *ne = ret;
  264. return ret;
  265. err:
  266. if ((ne == NULL) || (ret != *ne))
  267. X509_NAME_ENTRY_free(ret);
  268. return NULL;
  269. }
  270. int X509_NAME_ENTRY_set_object(X509_NAME_ENTRY *ne, const ASN1_OBJECT *obj)
  271. {
  272. if ((ne == NULL) || (obj == NULL)) {
  273. ERR_raise(ERR_LIB_X509, ERR_R_PASSED_NULL_PARAMETER);
  274. return 0;
  275. }
  276. ASN1_OBJECT_free(ne->object);
  277. ne->object = OBJ_dup(obj);
  278. return ((ne->object == NULL) ? 0 : 1);
  279. }
  280. int X509_NAME_ENTRY_set_data(X509_NAME_ENTRY *ne, int type,
  281. const unsigned char *bytes, int len)
  282. {
  283. int i;
  284. if ((ne == NULL) || ((bytes == NULL) && (len != 0)))
  285. return 0;
  286. if ((type > 0) && (type & MBSTRING_FLAG))
  287. return ASN1_STRING_set_by_NID(&ne->value, bytes,
  288. len, type,
  289. OBJ_obj2nid(ne->object)) ? 1 : 0;
  290. if (len < 0)
  291. len = strlen((const char *)bytes);
  292. i = ASN1_STRING_set(ne->value, bytes, len);
  293. if (!i)
  294. return 0;
  295. if (type != V_ASN1_UNDEF) {
  296. if (type == V_ASN1_APP_CHOOSE)
  297. ne->value->type = ASN1_PRINTABLE_type(bytes, len);
  298. else
  299. ne->value->type = type;
  300. }
  301. return 1;
  302. }
  303. ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne)
  304. {
  305. if (ne == NULL)
  306. return NULL;
  307. return ne->object;
  308. }
  309. ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne)
  310. {
  311. if (ne == NULL)
  312. return NULL;
  313. return ne->value;
  314. }
  315. int X509_NAME_ENTRY_set(const X509_NAME_ENTRY *ne)
  316. {
  317. return ne->set;
  318. }