certificate: Return signature scheme and parameters from issued_by() method
This also required some include restructuring (avoid including library.h in headers) to avoid unresolvable circular dependencies.
This commit is contained in:
@@ -284,7 +284,7 @@ METHOD(certificate_t, has_subject_or_issuer, id_match_t,
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_openssl_crl_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *scheme)
|
||||
signature_params_t **scheme)
|
||||
{
|
||||
chunk_t fingerprint, tbs;
|
||||
public_key_t *key;
|
||||
@@ -338,7 +338,9 @@ METHOD(certificate_t, issued_by, bool,
|
||||
key->destroy(key);
|
||||
if (valid && scheme)
|
||||
{
|
||||
*scheme = this->scheme;
|
||||
INIT(*scheme,
|
||||
.scheme = this->scheme,
|
||||
);
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
@@ -20,6 +20,7 @@
|
||||
#include "openssl_sha1_prf.h"
|
||||
|
||||
#include <openssl/sha.h>
|
||||
#include <crypto/hashers/hasher.h>
|
||||
|
||||
typedef struct private_openssl_sha1_prf_t private_openssl_sha1_prf_t;
|
||||
|
||||
|
||||
@@ -384,7 +384,7 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_openssl_x509_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *scheme)
|
||||
signature_params_t **scheme)
|
||||
{
|
||||
public_key_t *key;
|
||||
bool valid;
|
||||
@@ -392,11 +392,16 @@ METHOD(certificate_t, issued_by, bool,
|
||||
ASN1_BIT_STRING *sig;
|
||||
chunk_t tbs;
|
||||
|
||||
if (this->scheme == SIGN_UNKNOWN)
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
if (&this->public.x509.interface == issuer)
|
||||
{
|
||||
if (this->flags & X509_SELF_SIGNED)
|
||||
{
|
||||
return TRUE;
|
||||
valid = TRUE;
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
else
|
||||
@@ -414,10 +419,6 @@ METHOD(certificate_t, issued_by, bool,
|
||||
return FALSE;
|
||||
}
|
||||
}
|
||||
if (this->scheme == SIGN_UNKNOWN)
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
key = issuer->get_public_key(issuer);
|
||||
if (!key)
|
||||
{
|
||||
@@ -434,9 +435,13 @@ METHOD(certificate_t, issued_by, bool,
|
||||
openssl_asn1_str2chunk(sig));
|
||||
free(tbs.ptr);
|
||||
key->destroy(key);
|
||||
|
||||
out:
|
||||
if (valid && scheme)
|
||||
{
|
||||
*scheme = this->scheme;
|
||||
INIT(*scheme,
|
||||
.scheme = this->scheme,
|
||||
);
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
@@ -15,6 +15,8 @@
|
||||
|
||||
#include "pem_encoder.h"
|
||||
|
||||
#include <library.h>
|
||||
|
||||
#define BYTES_PER_LINE 48
|
||||
|
||||
/**
|
||||
|
||||
@@ -114,7 +114,7 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
}
|
||||
|
||||
METHOD(certificate_t, issued_by,bool,
|
||||
private_pgp_cert_t *this, certificate_t *issuer, signature_scheme_t *scheme)
|
||||
private_pgp_cert_t *this, certificate_t *issuer, signature_params_t **scheme)
|
||||
{
|
||||
/* TODO: check signature blobs for a valid signature */
|
||||
return FALSE;
|
||||
|
||||
@@ -15,6 +15,7 @@
|
||||
|
||||
#include "pgp_encoder.h"
|
||||
|
||||
#include <library.h>
|
||||
#include <utils/debug.h>
|
||||
|
||||
/**
|
||||
|
||||
@@ -137,13 +137,16 @@ METHOD(certificate_t, equals, bool,
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_pubkey_cert_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *scheme)
|
||||
signature_params_t **scheme)
|
||||
{
|
||||
if (scheme)
|
||||
bool valid = equals(this, issuer);
|
||||
if (valid && scheme)
|
||||
{
|
||||
*scheme = SIGN_UNKNOWN;
|
||||
INIT(*scheme,
|
||||
.scheme = SIGN_UNKNOWN,
|
||||
);
|
||||
}
|
||||
return equals(this, issuer);
|
||||
return valid;
|
||||
}
|
||||
|
||||
METHOD(certificate_t, get_public_key, public_key_t*,
|
||||
|
||||
@@ -886,7 +886,8 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
}
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_ac_t *this, certificate_t *issuer, signature_scheme_t *schemep)
|
||||
private_x509_ac_t *this, certificate_t *issuer,
|
||||
signature_params_t **schemep)
|
||||
{
|
||||
public_key_t *key;
|
||||
signature_scheme_t scheme;
|
||||
@@ -938,7 +939,9 @@ METHOD(certificate_t, issued_by, bool,
|
||||
key->destroy(key);
|
||||
if (valid && schemep)
|
||||
{
|
||||
*schemep = scheme;
|
||||
INIT(*schemep,
|
||||
.scheme = scheme,
|
||||
);
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
@@ -1677,18 +1677,26 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_cert_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *schemep)
|
||||
signature_params_t **schemep)
|
||||
{
|
||||
public_key_t *key;
|
||||
signature_scheme_t scheme;
|
||||
bool valid;
|
||||
x509_t *x509 = (x509_t*)issuer;
|
||||
|
||||
/* determine signature scheme */
|
||||
scheme = signature_scheme_from_oid(this->algorithm);
|
||||
if (scheme == SIGN_UNKNOWN)
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
if (&this->public.interface.interface == issuer)
|
||||
{
|
||||
if (this->flags & X509_SELF_SIGNED)
|
||||
{
|
||||
return TRUE;
|
||||
valid = TRUE;
|
||||
goto out;
|
||||
}
|
||||
}
|
||||
else
|
||||
@@ -1707,12 +1715,6 @@ METHOD(certificate_t, issued_by, bool,
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/* determine signature scheme */
|
||||
scheme = signature_scheme_from_oid(this->algorithm);
|
||||
if (scheme == SIGN_UNKNOWN)
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
/* get the public key of the issuer */
|
||||
key = issuer->get_public_key(issuer);
|
||||
if (!key)
|
||||
@@ -1722,9 +1724,13 @@ METHOD(certificate_t, issued_by, bool,
|
||||
valid = key->verify(key, scheme, NULL, this->tbsCertificate,
|
||||
this->signature);
|
||||
key->destroy(key);
|
||||
|
||||
out:
|
||||
if (valid && schemep)
|
||||
{
|
||||
*schemep = scheme;
|
||||
INIT(*schemep,
|
||||
.scheme = scheme,
|
||||
);
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
@@ -457,7 +457,8 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
}
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_crl_t *this, certificate_t *issuer, signature_scheme_t *schemep)
|
||||
private_x509_crl_t *this, certificate_t *issuer,
|
||||
signature_params_t **schemep)
|
||||
{
|
||||
public_key_t *key;
|
||||
signature_scheme_t scheme;
|
||||
@@ -506,7 +507,9 @@ METHOD(certificate_t, issued_by, bool,
|
||||
key->destroy(key);
|
||||
if (valid && schemep)
|
||||
{
|
||||
*schemep = scheme;
|
||||
INIT(*schemep,
|
||||
.scheme = scheme,
|
||||
);
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
@@ -372,7 +372,7 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_ocsp_request_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *scheme)
|
||||
signature_params_t **scheme)
|
||||
{
|
||||
DBG1(DBG_LIB, "OCSP request validation not implemented!");
|
||||
return FALSE;
|
||||
|
||||
@@ -703,7 +703,7 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_ocsp_response_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *schemep)
|
||||
signature_params_t **schemep)
|
||||
{
|
||||
public_key_t *key;
|
||||
signature_scheme_t scheme;
|
||||
@@ -758,7 +758,9 @@ METHOD(certificate_t, issued_by, bool,
|
||||
key->destroy(key);
|
||||
if (valid && schemep)
|
||||
{
|
||||
*schemep = scheme;
|
||||
INIT(*schemep,
|
||||
.scheme = scheme,
|
||||
);
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
@@ -124,7 +124,7 @@ METHOD(certificate_t, has_subject, id_match_t,
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_pkcs10_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *schemep)
|
||||
signature_params_t **schemep)
|
||||
{
|
||||
public_key_t *key;
|
||||
signature_scheme_t scheme;
|
||||
@@ -134,29 +134,32 @@ METHOD(certificate_t, issued_by, bool,
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
if (this->self_signed)
|
||||
{
|
||||
return TRUE;
|
||||
}
|
||||
|
||||
/* determine signature scheme */
|
||||
scheme = signature_scheme_from_oid(this->algorithm);
|
||||
if (scheme == SIGN_UNKNOWN)
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
|
||||
/* get the public key contained in the certificate request */
|
||||
key = this->public_key;
|
||||
if (!key)
|
||||
if (this->self_signed)
|
||||
{
|
||||
return FALSE;
|
||||
valid = TRUE;
|
||||
}
|
||||
else
|
||||
{
|
||||
/* get the public key contained in the certificate request */
|
||||
key = this->public_key;
|
||||
if (!key)
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
valid = key->verify(key, scheme, NULL, this->certificationRequestInfo,
|
||||
this->signature);
|
||||
}
|
||||
valid = key->verify(key, scheme, NULL, this->certificationRequestInfo,
|
||||
this->signature);
|
||||
if (valid && schemep)
|
||||
{
|
||||
*schemep = scheme;
|
||||
INIT(*schemep,
|
||||
.scheme = scheme,
|
||||
);
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user