OpenSSL 1.1.1-pre2
This commit is contained in:
+8
-4
@@ -24,7 +24,7 @@
|
||||
static int ct_base64_decode(const char *in, unsigned char **out)
|
||||
{
|
||||
size_t inlen = strlen(in);
|
||||
int outlen;
|
||||
int outlen, i;
|
||||
unsigned char *outbuf = NULL;
|
||||
|
||||
if (inlen == 0) {
|
||||
@@ -45,9 +45,12 @@ static int ct_base64_decode(const char *in, unsigned char **out)
|
||||
goto err;
|
||||
}
|
||||
|
||||
/* Subtract padding bytes from |outlen| */
|
||||
/* Subtract padding bytes from |outlen|. Any more than 2 is malformed. */
|
||||
i = 0;
|
||||
while (in[--inlen] == '=') {
|
||||
--outlen;
|
||||
if (++i > 2)
|
||||
goto err;
|
||||
}
|
||||
|
||||
*out = outbuf;
|
||||
@@ -132,7 +135,7 @@ SCT *SCT_new_from_base64(unsigned char version, const char *logid_base64,
|
||||
int CTLOG_new_from_base64(CTLOG **ct_log, const char *pkey_base64, const char *name)
|
||||
{
|
||||
unsigned char *pkey_der = NULL;
|
||||
int pkey_der_len = ct_base64_decode(pkey_base64, &pkey_der);
|
||||
int pkey_der_len;
|
||||
const unsigned char *p;
|
||||
EVP_PKEY *pkey = NULL;
|
||||
|
||||
@@ -141,7 +144,8 @@ int CTLOG_new_from_base64(CTLOG **ct_log, const char *pkey_base64, const char *n
|
||||
return 0;
|
||||
}
|
||||
|
||||
if (pkey_der_len <= 0) {
|
||||
pkey_der_len = ct_base64_decode(pkey_base64, &pkey_der);
|
||||
if (pkey_der_len < 0) {
|
||||
CTerr(CT_F_CTLOG_NEW_FROM_BASE64, CT_R_LOG_CONF_INVALID_KEY);
|
||||
return 0;
|
||||
}
|
||||
|
||||
+67
-58
@@ -1,6 +1,6 @@
|
||||
/*
|
||||
* Generated by util/mkerr.pl DO NOT EDIT
|
||||
* Copyright 1995-2016 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2017 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the OpenSSL license (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
@@ -8,67 +8,77 @@
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include <stdio.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/ct.h>
|
||||
#include <openssl/cterr.h>
|
||||
|
||||
/* BEGIN ERROR CODES */
|
||||
#ifndef OPENSSL_NO_ERR
|
||||
|
||||
# define ERR_FUNC(func) ERR_PACK(ERR_LIB_CT,func,0)
|
||||
# define ERR_REASON(reason) ERR_PACK(ERR_LIB_CT,0,reason)
|
||||
|
||||
static ERR_STRING_DATA CT_str_functs[] = {
|
||||
{ERR_FUNC(CT_F_CTLOG_NEW), "CTLOG_new"},
|
||||
{ERR_FUNC(CT_F_CTLOG_NEW_FROM_BASE64), "CTLOG_new_from_base64"},
|
||||
{ERR_FUNC(CT_F_CTLOG_NEW_FROM_CONF), "ctlog_new_from_conf"},
|
||||
{ERR_FUNC(CT_F_CTLOG_STORE_LOAD_CTX_NEW), "ctlog_store_load_ctx_new"},
|
||||
{ERR_FUNC(CT_F_CTLOG_STORE_LOAD_FILE), "CTLOG_STORE_load_file"},
|
||||
{ERR_FUNC(CT_F_CTLOG_STORE_LOAD_LOG), "ctlog_store_load_log"},
|
||||
{ERR_FUNC(CT_F_CTLOG_STORE_NEW), "CTLOG_STORE_new"},
|
||||
{ERR_FUNC(CT_F_CT_BASE64_DECODE), "ct_base64_decode"},
|
||||
{ERR_FUNC(CT_F_CT_POLICY_EVAL_CTX_NEW), "CT_POLICY_EVAL_CTX_new"},
|
||||
{ERR_FUNC(CT_F_CT_V1_LOG_ID_FROM_PKEY), "ct_v1_log_id_from_pkey"},
|
||||
{ERR_FUNC(CT_F_I2O_SCT), "i2o_SCT"},
|
||||
{ERR_FUNC(CT_F_I2O_SCT_LIST), "i2o_SCT_LIST"},
|
||||
{ERR_FUNC(CT_F_I2O_SCT_SIGNATURE), "i2o_SCT_signature"},
|
||||
{ERR_FUNC(CT_F_O2I_SCT), "o2i_SCT"},
|
||||
{ERR_FUNC(CT_F_O2I_SCT_LIST), "o2i_SCT_LIST"},
|
||||
{ERR_FUNC(CT_F_O2I_SCT_SIGNATURE), "o2i_SCT_signature"},
|
||||
{ERR_FUNC(CT_F_SCT_CTX_NEW), "SCT_CTX_new"},
|
||||
{ERR_FUNC(CT_F_SCT_CTX_VERIFY), "SCT_CTX_verify"},
|
||||
{ERR_FUNC(CT_F_SCT_NEW), "SCT_new"},
|
||||
{ERR_FUNC(CT_F_SCT_NEW_FROM_BASE64), "SCT_new_from_base64"},
|
||||
{ERR_FUNC(CT_F_SCT_SET0_LOG_ID), "SCT_set0_log_id"},
|
||||
{ERR_FUNC(CT_F_SCT_SET1_EXTENSIONS), "SCT_set1_extensions"},
|
||||
{ERR_FUNC(CT_F_SCT_SET1_LOG_ID), "SCT_set1_log_id"},
|
||||
{ERR_FUNC(CT_F_SCT_SET1_SIGNATURE), "SCT_set1_signature"},
|
||||
{ERR_FUNC(CT_F_SCT_SET_LOG_ENTRY_TYPE), "SCT_set_log_entry_type"},
|
||||
{ERR_FUNC(CT_F_SCT_SET_SIGNATURE_NID), "SCT_set_signature_nid"},
|
||||
{ERR_FUNC(CT_F_SCT_SET_VERSION), "SCT_set_version"},
|
||||
static const ERR_STRING_DATA CT_str_functs[] = {
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_CTLOG_NEW, 0), "CTLOG_new"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_CTLOG_NEW_FROM_BASE64, 0),
|
||||
"CTLOG_new_from_base64"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_CTLOG_NEW_FROM_CONF, 0), "ctlog_new_from_conf"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_CTLOG_STORE_LOAD_CTX_NEW, 0),
|
||||
"ctlog_store_load_ctx_new"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_CTLOG_STORE_LOAD_FILE, 0),
|
||||
"CTLOG_STORE_load_file"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_CTLOG_STORE_LOAD_LOG, 0),
|
||||
"ctlog_store_load_log"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_CTLOG_STORE_NEW, 0), "CTLOG_STORE_new"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_CT_BASE64_DECODE, 0), "ct_base64_decode"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_CT_POLICY_EVAL_CTX_NEW, 0),
|
||||
"CT_POLICY_EVAL_CTX_new"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_CT_V1_LOG_ID_FROM_PKEY, 0),
|
||||
"ct_v1_log_id_from_pkey"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_I2O_SCT, 0), "i2o_SCT"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_I2O_SCT_LIST, 0), "i2o_SCT_LIST"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_I2O_SCT_SIGNATURE, 0), "i2o_SCT_signature"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_O2I_SCT, 0), "o2i_SCT"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_O2I_SCT_LIST, 0), "o2i_SCT_LIST"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_O2I_SCT_SIGNATURE, 0), "o2i_SCT_signature"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_CTX_NEW, 0), "SCT_CTX_new"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_CTX_VERIFY, 0), "SCT_CTX_verify"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_NEW, 0), "SCT_new"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_NEW_FROM_BASE64, 0), "SCT_new_from_base64"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_SET0_LOG_ID, 0), "SCT_set0_log_id"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_SET1_EXTENSIONS, 0), "SCT_set1_extensions"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_SET1_LOG_ID, 0), "SCT_set1_log_id"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_SET1_SIGNATURE, 0), "SCT_set1_signature"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_SET_LOG_ENTRY_TYPE, 0),
|
||||
"SCT_set_log_entry_type"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_SET_SIGNATURE_NID, 0),
|
||||
"SCT_set_signature_nid"},
|
||||
{ERR_PACK(ERR_LIB_CT, CT_F_SCT_SET_VERSION, 0), "SCT_set_version"},
|
||||
{0, NULL}
|
||||
};
|
||||
|
||||
static ERR_STRING_DATA CT_str_reasons[] = {
|
||||
{ERR_REASON(CT_R_BASE64_DECODE_ERROR), "base64 decode error"},
|
||||
{ERR_REASON(CT_R_INVALID_LOG_ID_LENGTH), "invalid log id length"},
|
||||
{ERR_REASON(CT_R_LOG_CONF_INVALID), "log conf invalid"},
|
||||
{ERR_REASON(CT_R_LOG_CONF_INVALID_KEY), "log conf invalid key"},
|
||||
{ERR_REASON(CT_R_LOG_CONF_MISSING_DESCRIPTION),
|
||||
"log conf missing description"},
|
||||
{ERR_REASON(CT_R_LOG_CONF_MISSING_KEY), "log conf missing key"},
|
||||
{ERR_REASON(CT_R_LOG_KEY_INVALID), "log key invalid"},
|
||||
{ERR_REASON(CT_R_SCT_FUTURE_TIMESTAMP), "sct future timestamp"},
|
||||
{ERR_REASON(CT_R_SCT_INVALID), "sct invalid"},
|
||||
{ERR_REASON(CT_R_SCT_INVALID_SIGNATURE), "sct invalid signature"},
|
||||
{ERR_REASON(CT_R_SCT_LIST_INVALID), "sct list invalid"},
|
||||
{ERR_REASON(CT_R_SCT_LOG_ID_MISMATCH), "sct log id mismatch"},
|
||||
{ERR_REASON(CT_R_SCT_NOT_SET), "sct not set"},
|
||||
{ERR_REASON(CT_R_SCT_UNSUPPORTED_VERSION), "sct unsupported version"},
|
||||
{ERR_REASON(CT_R_UNRECOGNIZED_SIGNATURE_NID),
|
||||
"unrecognized signature nid"},
|
||||
{ERR_REASON(CT_R_UNSUPPORTED_ENTRY_TYPE), "unsupported entry type"},
|
||||
{ERR_REASON(CT_R_UNSUPPORTED_VERSION), "unsupported version"},
|
||||
static const ERR_STRING_DATA CT_str_reasons[] = {
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_BASE64_DECODE_ERROR), "base64 decode error"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_INVALID_LOG_ID_LENGTH),
|
||||
"invalid log id length"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_LOG_CONF_INVALID), "log conf invalid"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_LOG_CONF_INVALID_KEY),
|
||||
"log conf invalid key"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_LOG_CONF_MISSING_DESCRIPTION),
|
||||
"log conf missing description"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_LOG_CONF_MISSING_KEY),
|
||||
"log conf missing key"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_LOG_KEY_INVALID), "log key invalid"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_SCT_FUTURE_TIMESTAMP),
|
||||
"sct future timestamp"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_SCT_INVALID), "sct invalid"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_SCT_INVALID_SIGNATURE),
|
||||
"sct invalid signature"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_SCT_LIST_INVALID), "sct list invalid"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_SCT_LOG_ID_MISMATCH), "sct log id mismatch"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_SCT_NOT_SET), "sct not set"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_SCT_UNSUPPORTED_VERSION),
|
||||
"sct unsupported version"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_UNRECOGNIZED_SIGNATURE_NID),
|
||||
"unrecognized signature nid"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_UNSUPPORTED_ENTRY_TYPE),
|
||||
"unsupported entry type"},
|
||||
{ERR_PACK(ERR_LIB_CT, 0, CT_R_UNSUPPORTED_VERSION), "unsupported version"},
|
||||
{0, NULL}
|
||||
};
|
||||
|
||||
@@ -77,10 +87,9 @@ static ERR_STRING_DATA CT_str_reasons[] = {
|
||||
int ERR_load_CT_strings(void)
|
||||
{
|
||||
#ifndef OPENSSL_NO_ERR
|
||||
|
||||
if (ERR_func_error_string(CT_str_functs[0].error) == NULL) {
|
||||
ERR_load_strings(0, CT_str_functs);
|
||||
ERR_load_strings(0, CT_str_reasons);
|
||||
ERR_load_strings_const(CT_str_functs);
|
||||
ERR_load_strings_const(CT_str_reasons);
|
||||
}
|
||||
#endif
|
||||
return 1;
|
||||
|
||||
+8
-5
@@ -70,10 +70,11 @@ int SCT_set_log_entry_type(SCT *sct, ct_log_entry_type_t entry_type)
|
||||
case CT_LOG_ENTRY_TYPE_PRECERT:
|
||||
sct->entry_type = entry_type;
|
||||
return 1;
|
||||
default:
|
||||
CTerr(CT_F_SCT_SET_LOG_ENTRY_TYPE, CT_R_UNSUPPORTED_ENTRY_TYPE);
|
||||
return 0;
|
||||
case CT_LOG_ENTRY_TYPE_NOT_SET:
|
||||
break;
|
||||
}
|
||||
CTerr(CT_F_SCT_SET_LOG_ENTRY_TYPE, CT_R_UNSUPPORTED_ENTRY_TYPE);
|
||||
return 0;
|
||||
}
|
||||
|
||||
int SCT_set0_log_id(SCT *sct, unsigned char *log_id, size_t log_id_len)
|
||||
@@ -274,9 +275,11 @@ int SCT_set_source(SCT *sct, sct_source_t source)
|
||||
return SCT_set_log_entry_type(sct, CT_LOG_ENTRY_TYPE_X509);
|
||||
case SCT_SOURCE_X509V3_EXTENSION:
|
||||
return SCT_set_log_entry_type(sct, CT_LOG_ENTRY_TYPE_PRECERT);
|
||||
default: /* if we aren't sure, leave the log entry type alone */
|
||||
return 1;
|
||||
case SCT_SOURCE_UNKNOWN:
|
||||
break;
|
||||
}
|
||||
/* if we aren't sure, leave the log entry type alone */
|
||||
return 1;
|
||||
}
|
||||
|
||||
sct_validation_status_t SCT_get_validation_status(const SCT *sct)
|
||||
|
||||
Reference in New Issue
Block a user