certificate_t->issued_by takes an argument to receive signature scheme
This commit is contained in:
@@ -701,7 +701,7 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
}
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_ac_t *this, certificate_t *issuer)
|
||||
private_x509_ac_t *this, certificate_t *issuer, signature_scheme_t *schemep)
|
||||
{
|
||||
public_key_t *key;
|
||||
signature_scheme_t scheme;
|
||||
@@ -750,6 +750,10 @@ METHOD(certificate_t, issued_by, bool,
|
||||
}
|
||||
valid = key->verify(key, scheme, this->certificateInfo, this->signature);
|
||||
key->destroy(key);
|
||||
if (valid && schemep)
|
||||
{
|
||||
*schemep = scheme;
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
|
||||
@@ -1483,7 +1483,8 @@ end:
|
||||
/* check if the certificate is self-signed */
|
||||
if (this->public.interface.interface.issued_by(
|
||||
&this->public.interface.interface,
|
||||
&this->public.interface.interface))
|
||||
&this->public.interface.interface,
|
||||
NULL))
|
||||
{
|
||||
this->flags |= X509_SELF_SIGNED;
|
||||
}
|
||||
@@ -1568,7 +1569,8 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
}
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_cert_t *this, certificate_t *issuer)
|
||||
private_x509_cert_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *schemep)
|
||||
{
|
||||
public_key_t *key;
|
||||
signature_scheme_t scheme;
|
||||
@@ -1612,6 +1614,10 @@ METHOD(certificate_t, issued_by, bool,
|
||||
}
|
||||
valid = key->verify(key, scheme, this->tbsCertificate, this->signature);
|
||||
key->destroy(key);
|
||||
if (valid && schemep)
|
||||
{
|
||||
*schemep = scheme;
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
|
||||
@@ -442,7 +442,7 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
}
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_crl_t *this, certificate_t *issuer)
|
||||
private_x509_crl_t *this, certificate_t *issuer, signature_scheme_t *schemep)
|
||||
{
|
||||
public_key_t *key;
|
||||
signature_scheme_t scheme;
|
||||
@@ -490,6 +490,10 @@ METHOD(certificate_t, issued_by, bool,
|
||||
}
|
||||
valid = key->verify(key, scheme, this->tbsCertList, this->signature);
|
||||
key->destroy(key);
|
||||
if (valid && schemep)
|
||||
{
|
||||
*schemep = scheme;
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
|
||||
@@ -364,7 +364,8 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
}
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_ocsp_request_t *this, certificate_t *issuer)
|
||||
private_x509_ocsp_request_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *scheme)
|
||||
{
|
||||
DBG1(DBG_LIB, "OCSP request validation not implemented!");
|
||||
return FALSE;
|
||||
|
||||
@@ -670,7 +670,8 @@ METHOD(certificate_t, has_issuer, id_match_t,
|
||||
}
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_ocsp_response_t *this, certificate_t *issuer)
|
||||
private_x509_ocsp_response_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *schemep)
|
||||
{
|
||||
public_key_t *key;
|
||||
signature_scheme_t scheme;
|
||||
@@ -722,6 +723,10 @@ METHOD(certificate_t, issued_by, bool,
|
||||
}
|
||||
valid = key->verify(key, scheme, this->tbsResponseData, this->signature);
|
||||
key->destroy(key);
|
||||
if (valid && schemep)
|
||||
{
|
||||
*schemep = scheme;
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
|
||||
@@ -123,10 +123,12 @@ METHOD(certificate_t, has_subject, id_match_t,
|
||||
}
|
||||
|
||||
METHOD(certificate_t, issued_by, bool,
|
||||
private_x509_pkcs10_t *this, certificate_t *issuer)
|
||||
private_x509_pkcs10_t *this, certificate_t *issuer,
|
||||
signature_scheme_t *schemep)
|
||||
{
|
||||
public_key_t *key;
|
||||
signature_scheme_t scheme;
|
||||
bool valid;
|
||||
|
||||
if (&this->public.interface.interface != issuer)
|
||||
{
|
||||
@@ -150,8 +152,13 @@ METHOD(certificate_t, issued_by, bool,
|
||||
{
|
||||
return FALSE;
|
||||
}
|
||||
return key->verify(key, scheme, this->certificationRequestInfo,
|
||||
this->signature);
|
||||
valid = key->verify(key, scheme, this->certificationRequestInfo,
|
||||
this->signature);
|
||||
if (valid && schemep)
|
||||
{
|
||||
*schemep = scheme;
|
||||
}
|
||||
return valid;
|
||||
}
|
||||
|
||||
METHOD(certificate_t, get_public_key, public_key_t*,
|
||||
@@ -441,7 +448,7 @@ end:
|
||||
if (success)
|
||||
{
|
||||
/* check if the certificate request is self-signed */
|
||||
if (issued_by(this, &this->public.interface.interface))
|
||||
if (issued_by(this, &this->public.interface.interface, NULL))
|
||||
{
|
||||
this->self_signed = TRUE;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user