Latest update.
This commit is contained in:
@@ -48,7 +48,7 @@ OCSP_ONEREQ *OCSP_request_add0_id(OCSP_REQUEST *req, OCSP_CERTID *cid)
|
||||
|
||||
/* Set requestorName from an X509_NAME structure */
|
||||
|
||||
int OCSP_request_set1_name(OCSP_REQUEST *req, X509_NAME *nm)
|
||||
int OCSP_request_set1_name(OCSP_REQUEST *req, const X509_NAME *nm)
|
||||
{
|
||||
GENERAL_NAME *gen;
|
||||
|
||||
|
||||
@@ -430,7 +430,7 @@ X509_EXTENSION *OCSP_archive_cutoff_new(char *tim)
|
||||
* two--NID_ad_ocsp, NID_id_ad_caIssuers--and GeneralName value. This method
|
||||
* forces NID_ad_ocsp and uniformResourceLocator [6] IA5String.
|
||||
*/
|
||||
X509_EXTENSION *OCSP_url_svcloc_new(X509_NAME *issuer, const char **urls)
|
||||
X509_EXTENSION *OCSP_url_svcloc_new(const X509_NAME *issuer, const char **urls)
|
||||
{
|
||||
X509_EXTENSION *x = NULL;
|
||||
ASN1_IA5STRING *ia5 = NULL;
|
||||
|
||||
@@ -22,7 +22,7 @@
|
||||
OCSP_CERTID *OCSP_cert_to_id(const EVP_MD *dgst, const X509 *subject,
|
||||
const X509 *issuer)
|
||||
{
|
||||
X509_NAME *iname;
|
||||
const X509_NAME *iname;
|
||||
const ASN1_INTEGER *serial;
|
||||
ASN1_BIT_STRING *ikey;
|
||||
if (!dgst)
|
||||
|
||||
+43
-14
@@ -259,45 +259,67 @@ int OCSP_RESPID_set_by_name(OCSP_RESPID *respid, X509 *cert)
|
||||
return 1;
|
||||
}
|
||||
|
||||
int OCSP_RESPID_set_by_key(OCSP_RESPID *respid, X509 *cert)
|
||||
int OCSP_RESPID_set_by_key_ex(OCSP_RESPID *respid, X509 *cert,
|
||||
OPENSSL_CTX *libctx, const char *propq)
|
||||
{
|
||||
ASN1_OCTET_STRING *byKey = NULL;
|
||||
unsigned char md[SHA_DIGEST_LENGTH];
|
||||
EVP_MD *sha1 = EVP_MD_fetch(libctx, "SHA1", propq);
|
||||
int ret = 0;
|
||||
|
||||
if (sha1 == NULL)
|
||||
return 0;
|
||||
|
||||
/* RFC2560 requires SHA1 */
|
||||
if (!X509_pubkey_digest(cert, EVP_sha1(), md, NULL))
|
||||
return 0;
|
||||
if (!X509_pubkey_digest(cert, sha1, md, NULL))
|
||||
goto err;
|
||||
|
||||
byKey = ASN1_OCTET_STRING_new();
|
||||
if (byKey == NULL)
|
||||
return 0;
|
||||
goto err;
|
||||
|
||||
if (!(ASN1_OCTET_STRING_set(byKey, md, SHA_DIGEST_LENGTH))) {
|
||||
ASN1_OCTET_STRING_free(byKey);
|
||||
return 0;
|
||||
goto err;
|
||||
}
|
||||
|
||||
respid->type = V_OCSP_RESPID_KEY;
|
||||
respid->value.byKey = byKey;
|
||||
|
||||
return 1;
|
||||
ret = 1;
|
||||
err:
|
||||
EVP_MD_free(sha1);
|
||||
return ret;
|
||||
}
|
||||
|
||||
int OCSP_RESPID_match(OCSP_RESPID *respid, X509 *cert)
|
||||
int OCSP_RESPID_set_by_key(OCSP_RESPID *respid, X509 *cert)
|
||||
{
|
||||
return OCSP_RESPID_set_by_key_ex(respid, cert, NULL, NULL);
|
||||
}
|
||||
|
||||
int OCSP_RESPID_match_ex(OCSP_RESPID *respid, X509 *cert, OPENSSL_CTX *libctx,
|
||||
const char *propq)
|
||||
{
|
||||
EVP_MD *sha1 = NULL;
|
||||
int ret = 0;
|
||||
|
||||
if (respid->type == V_OCSP_RESPID_KEY) {
|
||||
unsigned char md[SHA_DIGEST_LENGTH];
|
||||
|
||||
sha1 = EVP_MD_fetch(libctx, "SHA1", propq);
|
||||
if (sha1 == NULL)
|
||||
goto err;
|
||||
|
||||
if (respid->value.byKey == NULL)
|
||||
return 0;
|
||||
goto err;
|
||||
|
||||
/* RFC2560 requires SHA1 */
|
||||
if (!X509_pubkey_digest(cert, EVP_sha1(), md, NULL))
|
||||
return 0;
|
||||
if (!X509_pubkey_digest(cert, sha1, md, NULL))
|
||||
goto err;
|
||||
|
||||
return (ASN1_STRING_length(respid->value.byKey) == SHA_DIGEST_LENGTH)
|
||||
&& (memcmp(ASN1_STRING_get0_data(respid->value.byKey), md,
|
||||
SHA_DIGEST_LENGTH) == 0);
|
||||
ret = (ASN1_STRING_length(respid->value.byKey) == SHA_DIGEST_LENGTH)
|
||||
&& (memcmp(ASN1_STRING_get0_data(respid->value.byKey), md,
|
||||
SHA_DIGEST_LENGTH) == 0);
|
||||
} else if (respid->type == V_OCSP_RESPID_NAME) {
|
||||
if (respid->value.byName == NULL)
|
||||
return 0;
|
||||
@@ -306,5 +328,12 @@ int OCSP_RESPID_match(OCSP_RESPID *respid, X509 *cert)
|
||||
X509_get_subject_name(cert)) == 0;
|
||||
}
|
||||
|
||||
return 0;
|
||||
err:
|
||||
EVP_MD_free(sha1);
|
||||
return ret;
|
||||
}
|
||||
|
||||
int OCSP_RESPID_match(OCSP_RESPID *respid, X509 *cert)
|
||||
{
|
||||
return OCSP_RESPID_match_ex(respid, cert, NULL, NULL);
|
||||
}
|
||||
@@ -22,7 +22,7 @@ static int ocsp_match_issuerid(X509 *cert, OCSP_CERTID *cid,
|
||||
STACK_OF(OCSP_SINGLERESP) *sresp);
|
||||
static int ocsp_check_delegated(X509 *x);
|
||||
static int ocsp_req_find_signer(X509 **psigner, OCSP_REQUEST *req,
|
||||
X509_NAME *nm, STACK_OF(X509) *certs,
|
||||
const X509_NAME *nm, STACK_OF(X509) *certs,
|
||||
unsigned long flags);
|
||||
|
||||
/* Verify a basic response message */
|
||||
@@ -279,7 +279,7 @@ static int ocsp_match_issuerid(X509 *cert, OCSP_CERTID *cid,
|
||||
/* If only one ID to match then do it */
|
||||
if (cid) {
|
||||
const EVP_MD *dgst;
|
||||
X509_NAME *iname;
|
||||
const X509_NAME *iname;
|
||||
int mdlen;
|
||||
unsigned char md[EVP_MAX_MD_SIZE];
|
||||
if ((dgst = EVP_get_digestbyobj(cid->hashAlgorithm.algorithm))
|
||||
@@ -340,7 +340,7 @@ int OCSP_request_verify(OCSP_REQUEST *req, STACK_OF(X509) *certs,
|
||||
X509_STORE *store, unsigned long flags)
|
||||
{
|
||||
X509 *signer;
|
||||
X509_NAME *nm;
|
||||
const X509_NAME *nm;
|
||||
GENERAL_NAME *gen;
|
||||
int ret = 0;
|
||||
X509_STORE_CTX *ctx = X509_STORE_CTX_new();
|
||||
@@ -414,7 +414,7 @@ end:
|
||||
}
|
||||
|
||||
static int ocsp_req_find_signer(X509 **psigner, OCSP_REQUEST *req,
|
||||
X509_NAME *nm, STACK_OF(X509) *certs,
|
||||
const X509_NAME *nm, STACK_OF(X509) *certs,
|
||||
unsigned long flags)
|
||||
{
|
||||
X509 *signer;
|
||||
|
||||
Reference in New Issue
Block a user