Latest update.
This commit is contained in:
@@ -23,6 +23,8 @@
|
||||
#include <openssl/rsa.h>
|
||||
#include <openssl/dsa.h>
|
||||
|
||||
DEFINE_STACK_OF(X509_INFO)
|
||||
|
||||
#ifndef OPENSSL_NO_STDIO
|
||||
STACK_OF(X509_INFO) *PEM_X509_INFO_read(FILE *fp, STACK_OF(X509_INFO) *sk,
|
||||
pem_password_cb *cb, void *u)
|
||||
|
||||
+23
-9
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* Copyright 1995-2018 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2020 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
@@ -806,7 +806,7 @@ static int get_header_and_data(BIO *bp, BIO **header, BIO **data, char *name,
|
||||
{
|
||||
BIO *tmp = *header;
|
||||
char *linebuf, *p;
|
||||
int len, line, ret = 0, end = 0;
|
||||
int len, line, ret = 0, end = 0, prev_partial_line_read = 0, partial_line_read = 0;
|
||||
/* 0 if not seen (yet), 1 if reading header, 2 if finished header */
|
||||
enum header_status got_header = MAYBE_HEADER;
|
||||
unsigned int flags_mask;
|
||||
@@ -824,10 +824,18 @@ static int get_header_and_data(BIO *bp, BIO **header, BIO **data, char *name,
|
||||
flags_mask = ~0u;
|
||||
len = BIO_gets(bp, linebuf, LINESIZE);
|
||||
if (len <= 0) {
|
||||
PEMerr(PEM_F_GET_HEADER_AND_DATA, PEM_R_SHORT_HEADER);
|
||||
PEMerr(PEM_F_GET_HEADER_AND_DATA, PEM_R_BAD_END_LINE);
|
||||
goto err;
|
||||
}
|
||||
|
||||
/*
|
||||
* Check if line has been read completely or if only part of the line
|
||||
* has been read. Keep the previous value to ignore newlines that
|
||||
* appear due to reading a line up until the char before the newline.
|
||||
*/
|
||||
prev_partial_line_read = partial_line_read;
|
||||
partial_line_read = len == LINESIZE-1 && linebuf[LINESIZE-2] != '\n';
|
||||
|
||||
if (got_header == MAYBE_HEADER) {
|
||||
if (memchr(linebuf, ':', len) != NULL)
|
||||
got_header = IN_HEADER;
|
||||
@@ -838,13 +846,19 @@ static int get_header_and_data(BIO *bp, BIO **header, BIO **data, char *name,
|
||||
|
||||
/* Check for end of header. */
|
||||
if (linebuf[0] == '\n') {
|
||||
if (got_header == POST_HEADER) {
|
||||
/* Another blank line is an error. */
|
||||
PEMerr(PEM_F_GET_HEADER_AND_DATA, PEM_R_BAD_END_LINE);
|
||||
goto err;
|
||||
/*
|
||||
* If previous line has been read only partially this newline is a
|
||||
* regular newline at the end of a line and not an empty line.
|
||||
*/
|
||||
if (!prev_partial_line_read) {
|
||||
if (got_header == POST_HEADER) {
|
||||
/* Another blank line is an error. */
|
||||
PEMerr(PEM_F_GET_HEADER_AND_DATA, PEM_R_BAD_END_LINE);
|
||||
goto err;
|
||||
}
|
||||
got_header = POST_HEADER;
|
||||
tmp = *data;
|
||||
}
|
||||
got_header = POST_HEADER;
|
||||
tmp = *data;
|
||||
continue;
|
||||
}
|
||||
|
||||
|
||||
+12
-7
@@ -39,8 +39,8 @@ EVP_PKEY *PEM_read_bio_PrivateKey_ex(BIO *bp, EVP_PKEY **x, pem_password_cb *cb,
|
||||
if ((ui_method = UI_UTIL_wrap_read_pem_callback(cb, 0)) == NULL)
|
||||
return NULL;
|
||||
|
||||
if ((ctx = ossl_store_attach_pem_bio(bp, ui_method, u, libctx,
|
||||
propq)) == NULL)
|
||||
if ((ctx = OSSL_STORE_attach(bp, libctx, "file", propq, ui_method, u,
|
||||
NULL, NULL)) == NULL)
|
||||
goto err;
|
||||
#ifndef OPENSSL_NO_SECURE_HEAP
|
||||
{
|
||||
@@ -56,13 +56,14 @@ EVP_PKEY *PEM_read_bio_PrivateKey_ex(BIO *bp, EVP_PKEY **x, pem_password_cb *cb,
|
||||
break;
|
||||
}
|
||||
OSSL_STORE_INFO_free(info);
|
||||
info = NULL;
|
||||
}
|
||||
|
||||
if (ret != NULL && x != NULL)
|
||||
*x = ret;
|
||||
|
||||
err:
|
||||
ossl_store_detach_pem_bio(ctx);
|
||||
OSSL_STORE_close(ctx);
|
||||
UI_destroy_method(ui_method);
|
||||
OSSL_STORE_INFO_free(info);
|
||||
return ret;
|
||||
@@ -105,7 +106,8 @@ EVP_PKEY *PEM_read_bio_Parameters(BIO *bp, EVP_PKEY **x)
|
||||
OSSL_STORE_CTX *ctx = NULL;
|
||||
OSSL_STORE_INFO *info = NULL;
|
||||
|
||||
if ((ctx = ossl_store_attach_pem_bio(bp, UI_null(), NULL, NULL, NULL)) == NULL)
|
||||
if ((ctx = OSSL_STORE_attach(bp, NULL, "file", NULL, UI_null(), NULL,
|
||||
NULL, NULL)) == NULL)
|
||||
goto err;
|
||||
|
||||
while (!OSSL_STORE_eof(ctx) && (info = OSSL_STORE_load(ctx)) != NULL) {
|
||||
@@ -114,13 +116,14 @@ EVP_PKEY *PEM_read_bio_Parameters(BIO *bp, EVP_PKEY **x)
|
||||
break;
|
||||
}
|
||||
OSSL_STORE_INFO_free(info);
|
||||
info = NULL;
|
||||
}
|
||||
|
||||
if (ret != NULL && x != NULL)
|
||||
*x = ret;
|
||||
|
||||
err:
|
||||
ossl_store_detach_pem_bio(ctx);
|
||||
OSSL_STORE_close(ctx);
|
||||
OSSL_STORE_INFO_free(info);
|
||||
return ret;
|
||||
}
|
||||
@@ -198,7 +201,8 @@ DH *PEM_read_bio_DHparams(BIO *bp, DH **x, pem_password_cb *cb, void *u)
|
||||
if ((ui_method = UI_UTIL_wrap_read_pem_callback(cb, 0)) == NULL)
|
||||
return NULL;
|
||||
|
||||
if ((ctx = ossl_store_attach_pem_bio(bp, ui_method, u, NULL, NULL)) == NULL)
|
||||
if ((ctx = OSSL_STORE_attach(bp, NULL, "file", NULL, ui_method, u,
|
||||
NULL, NULL)) == NULL)
|
||||
goto err;
|
||||
|
||||
while (!OSSL_STORE_eof(ctx) && (info = OSSL_STORE_load(ctx)) != NULL) {
|
||||
@@ -211,13 +215,14 @@ DH *PEM_read_bio_DHparams(BIO *bp, DH **x, pem_password_cb *cb, void *u)
|
||||
}
|
||||
}
|
||||
OSSL_STORE_INFO_free(info);
|
||||
info = NULL;
|
||||
}
|
||||
|
||||
if (ret != NULL && x != NULL)
|
||||
*x = ret;
|
||||
|
||||
err:
|
||||
ossl_store_detach_pem_bio(ctx);
|
||||
OSSL_STORE_close(ctx);
|
||||
UI_destroy_method(ui_method);
|
||||
OSSL_STORE_INFO_free(info);
|
||||
return ret;
|
||||
|
||||
+21
-20
@@ -20,6 +20,7 @@
|
||||
|
||||
#include "internal/cryptlib.h"
|
||||
#include <openssl/pem.h>
|
||||
#include "internal/pem_int.h"
|
||||
#include <openssl/rand.h>
|
||||
#include <openssl/bn.h>
|
||||
#if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_DSA)
|
||||
@@ -89,9 +90,9 @@ static EVP_PKEY *b2i_rsa(const unsigned char **in,
|
||||
static EVP_PKEY *b2i_dss(const unsigned char **in,
|
||||
unsigned int bitlen, int ispub);
|
||||
|
||||
static int do_blob_header(const unsigned char **in, unsigned int length,
|
||||
unsigned int *pmagic, unsigned int *pbitlen,
|
||||
int *pisdss, int *pispub)
|
||||
int ossl_do_blob_header(const unsigned char **in, unsigned int length,
|
||||
unsigned int *pmagic, unsigned int *pbitlen,
|
||||
int *pisdss, int *pispub)
|
||||
{
|
||||
const unsigned char *p = *in;
|
||||
if (length < 16)
|
||||
@@ -99,13 +100,13 @@ static int do_blob_header(const unsigned char **in, unsigned int length,
|
||||
/* bType */
|
||||
if (*p == MS_PUBLICKEYBLOB) {
|
||||
if (*pispub == 0) {
|
||||
PEMerr(PEM_F_DO_BLOB_HEADER, PEM_R_EXPECTING_PRIVATE_KEY_BLOB);
|
||||
PEMerr(PEM_F_OSSL_DO_BLOB_HEADER, PEM_R_EXPECTING_PRIVATE_KEY_BLOB);
|
||||
return 0;
|
||||
}
|
||||
*pispub = 1;
|
||||
} else if (*p == MS_PRIVATEKEYBLOB) {
|
||||
if (*pispub == 1) {
|
||||
PEMerr(PEM_F_DO_BLOB_HEADER, PEM_R_EXPECTING_PUBLIC_KEY_BLOB);
|
||||
PEMerr(PEM_F_OSSL_DO_BLOB_HEADER, PEM_R_EXPECTING_PUBLIC_KEY_BLOB);
|
||||
return 0;
|
||||
}
|
||||
*pispub = 0;
|
||||
@@ -114,7 +115,7 @@ static int do_blob_header(const unsigned char **in, unsigned int length,
|
||||
p++;
|
||||
/* Version */
|
||||
if (*p++ != 0x2) {
|
||||
PEMerr(PEM_F_DO_BLOB_HEADER, PEM_R_BAD_VERSION_NUMBER);
|
||||
PEMerr(PEM_F_OSSL_DO_BLOB_HEADER, PEM_R_BAD_VERSION_NUMBER);
|
||||
return 0;
|
||||
}
|
||||
/* Ignore reserved, aiKeyAlg */
|
||||
@@ -129,7 +130,7 @@ static int do_blob_header(const unsigned char **in, unsigned int length,
|
||||
/* fall thru */
|
||||
case MS_RSA1MAGIC:
|
||||
if (*pispub == 0) {
|
||||
PEMerr(PEM_F_DO_BLOB_HEADER, PEM_R_EXPECTING_PRIVATE_KEY_BLOB);
|
||||
PEMerr(PEM_F_OSSL_DO_BLOB_HEADER, PEM_R_EXPECTING_PRIVATE_KEY_BLOB);
|
||||
return 0;
|
||||
}
|
||||
break;
|
||||
@@ -139,13 +140,13 @@ static int do_blob_header(const unsigned char **in, unsigned int length,
|
||||
/* fall thru */
|
||||
case MS_RSA2MAGIC:
|
||||
if (*pispub == 1) {
|
||||
PEMerr(PEM_F_DO_BLOB_HEADER, PEM_R_EXPECTING_PUBLIC_KEY_BLOB);
|
||||
PEMerr(PEM_F_OSSL_DO_BLOB_HEADER, PEM_R_EXPECTING_PUBLIC_KEY_BLOB);
|
||||
return 0;
|
||||
}
|
||||
break;
|
||||
|
||||
default:
|
||||
PEMerr(PEM_F_DO_BLOB_HEADER, PEM_R_BAD_MAGIC_NUMBER);
|
||||
PEMerr(PEM_F_OSSL_DO_BLOB_HEADER, PEM_R_BAD_MAGIC_NUMBER);
|
||||
return -1;
|
||||
}
|
||||
*in = p;
|
||||
@@ -191,7 +192,7 @@ static EVP_PKEY *do_b2i(const unsigned char **in, unsigned int length,
|
||||
const unsigned char *p = *in;
|
||||
unsigned int bitlen, magic;
|
||||
int isdss;
|
||||
if (do_blob_header(&p, length, &magic, &bitlen, &isdss, &ispub) <= 0) {
|
||||
if (ossl_do_blob_header(&p, length, &magic, &bitlen, &isdss, &ispub) <= 0) {
|
||||
PEMerr(PEM_F_DO_B2I, PEM_R_KEYBLOB_HEADER_PARSE_ERROR);
|
||||
return NULL;
|
||||
}
|
||||
@@ -218,7 +219,7 @@ static EVP_PKEY *do_b2i_bio(BIO *in, int ispub)
|
||||
return NULL;
|
||||
}
|
||||
p = hdr_buf;
|
||||
if (do_blob_header(&p, 16, &magic, &bitlen, &isdss, &ispub) <= 0)
|
||||
if (ossl_do_blob_header(&p, 16, &magic, &bitlen, &isdss, &ispub) <= 0)
|
||||
return NULL;
|
||||
|
||||
length = blob_length(bitlen, isdss, ispub);
|
||||
@@ -617,26 +618,26 @@ int i2b_PublicKey_bio(BIO *out, const EVP_PKEY *pk)
|
||||
|
||||
# ifndef OPENSSL_NO_RC4
|
||||
|
||||
static int do_PVK_header(const unsigned char **in, unsigned int length,
|
||||
int skip_magic,
|
||||
unsigned int *psaltlen, unsigned int *pkeylen)
|
||||
int ossl_do_PVK_header(const unsigned char **in, unsigned int length,
|
||||
int skip_magic,
|
||||
unsigned int *psaltlen, unsigned int *pkeylen)
|
||||
{
|
||||
const unsigned char *p = *in;
|
||||
unsigned int pvk_magic, is_encrypted;
|
||||
|
||||
if (skip_magic) {
|
||||
if (length < 20) {
|
||||
PEMerr(PEM_F_DO_PVK_HEADER, PEM_R_PVK_TOO_SHORT);
|
||||
PEMerr(PEM_F_OSSL_DO_PVK_HEADER, PEM_R_PVK_TOO_SHORT);
|
||||
return 0;
|
||||
}
|
||||
} else {
|
||||
if (length < 24) {
|
||||
PEMerr(PEM_F_DO_PVK_HEADER, PEM_R_PVK_TOO_SHORT);
|
||||
PEMerr(PEM_F_OSSL_DO_PVK_HEADER, PEM_R_PVK_TOO_SHORT);
|
||||
return 0;
|
||||
}
|
||||
pvk_magic = read_ledword(&p);
|
||||
if (pvk_magic != MS_PVKMAGIC) {
|
||||
PEMerr(PEM_F_DO_PVK_HEADER, PEM_R_BAD_MAGIC_NUMBER);
|
||||
PEMerr(PEM_F_OSSL_DO_PVK_HEADER, PEM_R_BAD_MAGIC_NUMBER);
|
||||
return 0;
|
||||
}
|
||||
}
|
||||
@@ -653,7 +654,7 @@ static int do_PVK_header(const unsigned char **in, unsigned int length,
|
||||
return 0;
|
||||
|
||||
if (is_encrypted && *psaltlen == 0) {
|
||||
PEMerr(PEM_F_DO_PVK_HEADER, PEM_R_INCONSISTENT_HEADER);
|
||||
PEMerr(PEM_F_OSSL_DO_PVK_HEADER, PEM_R_INCONSISTENT_HEADER);
|
||||
return 0;
|
||||
}
|
||||
|
||||
@@ -766,7 +767,7 @@ EVP_PKEY *b2i_PVK_bio(BIO *in, pem_password_cb *cb, void *u)
|
||||
}
|
||||
p = pvk_hdr;
|
||||
|
||||
if (!do_PVK_header(&p, 24, 0, &saltlen, &keylen))
|
||||
if (!ossl_do_PVK_header(&p, 24, 0, &saltlen, &keylen))
|
||||
return 0;
|
||||
buflen = (int)keylen + saltlen;
|
||||
buf = OPENSSL_malloc(buflen);
|
||||
@@ -882,9 +883,9 @@ int i2b_PVK_bio(BIO *out, const EVP_PKEY *pk, int enclevel,
|
||||
wrlen = BIO_write(out, tmp, outlen);
|
||||
OPENSSL_free(tmp);
|
||||
if (wrlen == outlen) {
|
||||
PEMerr(PEM_F_I2B_PVK_BIO, PEM_R_BIO_WRITE_FAILURE);
|
||||
return outlen;
|
||||
}
|
||||
PEMerr(PEM_F_I2B_PVK_BIO, PEM_R_BIO_WRITE_FAILURE);
|
||||
return -1;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user