moved very stroke specific x509 flag handling out of core library

This commit is contained in:
Martin Willi
2009-05-18 10:42:16 +02:00
parent 7736a40448
commit 24cd2ca6ee
2 changed files with 45 additions and 27 deletions
+35 -6
View File
@@ -380,10 +380,18 @@ static certificate_t* load_ca(private_stroke_cred_t *this, char *filename)
cert = lib->creds->create(lib->creds, cert = lib->creds->create(lib->creds,
CRED_CERTIFICATE, CERT_X509, CRED_CERTIFICATE, CERT_X509,
BUILD_FROM_FILE, path, BUILD_FROM_FILE, path,
BUILD_X509_FLAG, X509_CA,
BUILD_END); BUILD_END);
if (cert) if (cert)
{ {
x509_t *x509 = (x509_t*)cert;
if (!(x509->get_flags(x509) & X509_CA))
{
cert->destroy(cert);
DBG1(DBG_CFG, " ca certificate must have ca basic constraint set, "
"discarded");
return NULL;
}
return (certificate_t*)add_cert(this, cert); return (certificate_t*)add_cert(this, cert);
} }
return NULL; return NULL;
@@ -522,11 +530,32 @@ static void load_certdir(private_stroke_cred_t *this, char *path,
switch (type) switch (type)
{ {
case CERT_X509: case CERT_X509:
cert = lib->creds->create(lib->creds, if (flag & X509_CA)
CRED_CERTIFICATE, CERT_X509, { /* for CA certificates, we strictly require CA
BUILD_FROM_FILE, file, * basicconstraints to be set */
BUILD_X509_FLAG, flag, cert = lib->creds->create(lib->creds,
BUILD_END); CRED_CERTIFICATE, CERT_X509,
BUILD_FROM_FILE, file, BUILD_END);
if (cert)
{
x509_t *x509 = (x509_t*)cert;
if (!(x509->get_flags(x509) & X509_CA))
{
DBG1(DBG_CFG, " ca certificate must have ca "
"basic constraint set, discarded");
cert->destroy(cert);
cert = NULL;
}
}
}
else
{ /* for all other flags, we add them to the certificate. */
cert = lib->creds->create(lib->creds,
CRED_CERTIFICATE, CERT_X509,
BUILD_FROM_FILE, file,
BUILD_X509_FLAG, flag, BUILD_END);
}
if (cert) if (cert)
{ {
add_cert(this, cert); add_cert(this, cert);
+10 -21
View File
@@ -1350,33 +1350,22 @@ static bool generate(private_builder_t *this)
static private_x509_cert_t *build(private_builder_t *this) static private_x509_cert_t *build(private_builder_t *this)
{ {
private_x509_cert_t *cert; private_x509_cert_t *cert;
x509_flag_t flags;
if (this->cert && !this->cert->encoding.ptr) if (this->cert)
{ {
if (!this->sign_key || !this->cert || this->cert->flags |= this->flags;
!generate(this)) if (!this->cert->encoding.ptr)
{ { /* generate a new certificate */
destroy(this->cert); if (!this->sign_key || !generate(this))
free(this); {
return NULL; destroy(this->cert);
free(this);
return NULL;
}
} }
} }
cert = this->cert; cert = this->cert;
flags = this->flags;
free(this); free(this);
if (cert == NULL)
{
return NULL;
}
if ((flags & X509_CA) && !(cert->flags & X509_CA))
{
DBG1(" ca certificate must have ca basic constraint set, discarded");
destroy(cert);
return NULL;
}
cert->flags |= flags;
return cert; return cert;
} }