Use a generic getter for all numerical X.509 constraints

This commit is contained in:
Martin Willi
2011-01-05 16:46:05 +01:00
parent b1703d6cb3
commit b3d359e58f
8 changed files with 55 additions and 51 deletions
+1 -1
View File
@@ -834,7 +834,7 @@ static void stroke_list_certs(linked_list_t *list, char *label,
} }
/* list optional pathLenConstraint */ /* list optional pathLenConstraint */
pathlen = x509->get_pathLenConstraint(x509); pathlen = x509->get_constraint(x509, X509_PATH_LEN);
if (pathlen != X509_NO_CONSTRAINT) if (pathlen != X509_NO_CONSTRAINT)
{ {
fprintf(out, " pathlen: %d\n", pathlen); fprintf(out, " pathlen: %d\n", pathlen);
@@ -31,6 +31,7 @@ typedef struct x509_cert_policy_t x509_cert_policy_t;
typedef struct x509_policy_mapping_t x509_policy_mapping_t; typedef struct x509_policy_mapping_t x509_policy_mapping_t;
typedef struct x509_cdp_t x509_cdp_t; typedef struct x509_cdp_t x509_cdp_t;
typedef enum x509_flag_t x509_flag_t; typedef enum x509_flag_t x509_flag_t;
typedef enum x509_constraint_t x509_constraint_t;
/** /**
* X.509 certificate flags. * X.509 certificate flags.
@@ -56,6 +57,18 @@ enum x509_flag_t {
X509_CRL_SIGN = (1<<7), X509_CRL_SIGN = (1<<7),
}; };
/**
* Different numerical X.509 constraints.
*/
enum x509_constraint_t {
/** pathLenConstraint basicConstraints */
X509_PATH_LEN,
/** inhibitPolicyMapping policyConstraint */
X509_INHIBIT_POLICY_MAPPING,
/** requireExplicitPolicy policyConstraint */
X509_REQUIRE_EXPLICIT_POLICY,
};
/** /**
* X.509 certPolicy extension. * X.509 certPolicy extension.
*/ */
@@ -130,19 +143,12 @@ struct x509_t {
chunk_t (*get_authKeyIdentifier)(x509_t *this); chunk_t (*get_authKeyIdentifier)(x509_t *this);
/** /**
* Get an optional path length constraint. * Get a numerical X.509 constraint.
* *
* @return pathLenConstraint, X509_NO_CONSTRAINT if none found * @param type type of constraint to get
*/
int (*get_pathLenConstraint)(x509_t *this);
/**
* Get a policyConstraint, inhibitPolicyMapping or requireExplicitPolicy.
*
* @param inhibit TRUE to get inhibitPolicyMapping
* @return constraint, X509_NO_CONSTRAINT if none found * @return constraint, X509_NO_CONSTRAINT if none found
*/ */
int (*get_policyConstraint)(x509_t *this, bool inhibit); int (*get_constraint)(x509_t *this, x509_constraint_t type);
/** /**
* Create an enumerator over all subjectAltNames. * Create an enumerator over all subjectAltNames.
@@ -40,7 +40,7 @@ static bool check_pathlen(x509_t *issuer, int pathlen)
{ {
int pathlen_constraint; int pathlen_constraint;
pathlen_constraint = issuer->get_pathLenConstraint(issuer); pathlen_constraint = issuer->get_constraint(issuer, X509_PATH_LEN);
if (pathlen_constraint != X509_NO_CONSTRAINT && if (pathlen_constraint != X509_NO_CONSTRAINT &&
pathlen > pathlen_constraint) pathlen > pathlen_constraint)
{ {
@@ -439,7 +439,7 @@ static bool check_policy_constraints(x509_t *issuer, int pathlen,
enumerator = chain->create_enumerator(chain); enumerator = chain->create_enumerator(chain);
while (enumerator->enumerate(enumerator, &x509)) while (enumerator->enumerate(enumerator, &x509))
{ {
expl = x509->get_policyConstraint(x509, FALSE); expl = x509->get_constraint(x509, X509_REQUIRE_EXPLICIT_POLICY);
if (expl != X509_NO_CONSTRAINT) if (expl != X509_NO_CONSTRAINT)
{ {
if (!has_policy_chain(chain, (x509_t*)subject, len - expl)) if (!has_policy_chain(chain, (x509_t*)subject, len - expl))
@@ -458,7 +458,7 @@ static bool check_policy_constraints(x509_t *issuer, int pathlen,
enumerator = chain->create_enumerator(chain); enumerator = chain->create_enumerator(chain);
while (enumerator->enumerate(enumerator, &x509)) while (enumerator->enumerate(enumerator, &x509))
{ {
expl = x509->get_policyConstraint(x509, TRUE); expl = x509->get_constraint(x509, X509_INHIBIT_POLICY_MAPPING);
if (expl != X509_NO_CONSTRAINT) if (expl != X509_NO_CONSTRAINT)
{ {
if (!has_policy_mapping(chain, len - expl)) if (!has_policy_mapping(chain, len - expl))
@@ -250,16 +250,16 @@ METHOD(x509_t, get_authKeyIdentifier, chunk_t,
return chunk_empty; return chunk_empty;
} }
METHOD(x509_t, get_pathLenConstraint, int, METHOD(x509_t, get_constraint, int,
private_openssl_x509_t *this) private_openssl_x509_t *this, x509_constraint_t type)
{ {
return this->pathlen; switch (type)
} {
case X509_PATH_LEN:
METHOD(x509_t, get_policyConstraint, int, return this->pathlen;
private_openssl_x509_t *this, bool inhibit) default:
{ return X509_NO_CONSTRAINT;
return X509_NO_CONSTRAINT; }
} }
METHOD(x509_t, create_subjectAltName_enumerator, enumerator_t*, METHOD(x509_t, create_subjectAltName_enumerator, enumerator_t*,
@@ -526,8 +526,7 @@ static private_openssl_x509_t *create_empty()
.get_serial = _get_serial, .get_serial = _get_serial,
.get_subjectKeyIdentifier = _get_subjectKeyIdentifier, .get_subjectKeyIdentifier = _get_subjectKeyIdentifier,
.get_authKeyIdentifier = _get_authKeyIdentifier, .get_authKeyIdentifier = _get_authKeyIdentifier,
.get_pathLenConstraint = _get_pathLenConstraint, .get_constraint = _get_constraint,
.get_policyConstraint = _get_policyConstraint,
.create_subjectAltName_enumerator = _create_subjectAltName_enumerator, .create_subjectAltName_enumerator = _create_subjectAltName_enumerator,
.create_crl_uri_enumerator = _create_crl_uri_enumerator, .create_crl_uri_enumerator = _create_crl_uri_enumerator,
.create_ocsp_uri_enumerator = _create_ocsp_uri_enumerator, .create_ocsp_uri_enumerator = _create_ocsp_uri_enumerator,
+12 -13
View File
@@ -1716,20 +1716,20 @@ METHOD(x509_t, get_authKeyIdentifier, chunk_t,
return this->authKeyIdentifier; return this->authKeyIdentifier;
} }
METHOD(x509_t, get_pathLenConstraint, int, METHOD(x509_t, get_constraint, int,
private_x509_cert_t *this) private_x509_cert_t *this, x509_constraint_t type)
{ {
return this->pathLenConstraint; switch (type)
}
METHOD(x509_t, get_policyConstraint, int,
private_x509_cert_t *this, bool inhibit)
{
if (inhibit)
{ {
return this->inhibit_policy_constraint; case X509_PATH_LEN:
return this->pathLenConstraint;
case X509_REQUIRE_EXPLICIT_POLICY:
return this->explicit_policy_constraint;
case X509_INHIBIT_POLICY_MAPPING:
return this->inhibit_policy_constraint;
default:
return X509_NO_CONSTRAINT;
} }
return this->explicit_policy_constraint;
} }
METHOD(x509_t, create_subjectAltName_enumerator, enumerator_t*, METHOD(x509_t, create_subjectAltName_enumerator, enumerator_t*,
@@ -1841,8 +1841,7 @@ static private_x509_cert_t* create_empty(void)
.get_serial = _get_serial, .get_serial = _get_serial,
.get_subjectKeyIdentifier = _get_subjectKeyIdentifier, .get_subjectKeyIdentifier = _get_subjectKeyIdentifier,
.get_authKeyIdentifier = _get_authKeyIdentifier, .get_authKeyIdentifier = _get_authKeyIdentifier,
.get_pathLenConstraint = _get_pathLenConstraint, .get_constraint = _get_constraint,
.get_policyConstraint = _get_policyConstraint,
.create_subjectAltName_enumerator = _create_subjectAltName_enumerator, .create_subjectAltName_enumerator = _create_subjectAltName_enumerator,
.create_crl_uri_enumerator = _create_crl_uri_enumerator, .create_crl_uri_enumerator = _create_crl_uri_enumerator,
.create_ocsp_uri_enumerator = _create_ocsp_uri_enumerator, .create_ocsp_uri_enumerator = _create_ocsp_uri_enumerator,
+10 -10
View File
@@ -73,7 +73,7 @@ static void print_x509(x509_t *x509)
chunk_t chunk; chunk_t chunk;
bool first; bool first;
char *uri; char *uri;
int len; int len, explicit, inhibit;
x509_flag_t flags; x509_flag_t flags;
x509_cdp_t *cdp; x509_cdp_t *cdp;
x509_cert_policy_t *policy; x509_cert_policy_t *policy;
@@ -176,7 +176,7 @@ static void print_x509(x509_t *x509)
} }
enumerator->destroy(enumerator); enumerator->destroy(enumerator);
len = x509->get_pathLenConstraint(x509); len = x509->get_constraint(x509, X509_PATH_LEN);
if (len != X509_NO_CONSTRAINT) if (len != X509_NO_CONSTRAINT)
{ {
printf("pathlen: %d\n", len); printf("pathlen: %d\n", len);
@@ -259,19 +259,19 @@ static void print_x509(x509_t *x509)
} }
enumerator->destroy(enumerator); enumerator->destroy(enumerator);
if (x509->get_policyConstraint(x509, FALSE) != X509_NO_CONSTRAINT || explicit = x509->get_constraint(x509, X509_REQUIRE_EXPLICIT_POLICY);
x509->get_policyConstraint(x509, TRUE) != X509_NO_CONSTRAINT) inhibit = x509->get_constraint(x509, X509_INHIBIT_POLICY_MAPPING);
if (explicit != X509_NO_CONSTRAINT || inhibit != X509_NO_CONSTRAINT)
{ {
printf("PolicyConstraints:\n"); printf("PolicyConstraints:\n");
if (x509->get_policyConstraint(x509, FALSE) != X509_NO_CONSTRAINT) if (explicit != X509_NO_CONSTRAINT)
{ {
printf(" requireExplicitPolicy: %d\n", printf(" requireExplicitPolicy: %d\n", explicit);
x509->get_policyConstraint(x509, FALSE));
} }
if (x509->get_policyConstraint(x509, TRUE) != X509_NO_CONSTRAINT) if (inhibit != X509_NO_CONSTRAINT)
{ {
printf(" inhibitPolicyMapping: %d\n", printf(" inhibitPolicyMapping: %d\n", inhibit);
x509->get_policyConstraint(x509, TRUE));
} }
} }
+1 -1
View File
@@ -1045,7 +1045,7 @@ static bool valid_ocsp_response(response_t *res)
) )
/* check path length constraint */ /* check path length constraint */
pathlen_constraint = x509->get_pathLenConstraint(x509); pathlen_constraint = x509->get_constraint(x509, X509_PATH_LEN);
if (pathlen_constraint != X509_NO_CONSTRAINT && if (pathlen_constraint != X509_NO_CONSTRAINT &&
pathlen > pathlen_constraint) pathlen > pathlen_constraint)
{ {
+2 -2
View File
@@ -255,7 +255,7 @@ bool verify_x509cert(cert_t *cert, bool strict, time_t *until)
unlock_authcert_list("verify_x509cert"); unlock_authcert_list("verify_x509cert");
/* check path length constraint */ /* check path length constraint */
pathlen_constraint = x509->get_pathLenConstraint(x509); pathlen_constraint = x509->get_constraint(x509, X509_PATH_LEN);
if (pathlen_constraint != X509_NO_CONSTRAINT && if (pathlen_constraint != X509_NO_CONSTRAINT &&
pathlen > pathlen_constraint) pathlen > pathlen_constraint)
{ {
@@ -450,7 +450,7 @@ void list_x509cert_chain(const char *caption, cert_t* cert,
} }
/* list optional pathLenConstraint */ /* list optional pathLenConstraint */
pathlen = x509->get_pathLenConstraint(x509); pathlen = x509->get_constraint(x509, X509_PATH_LEN);
if (pathlen != X509_NO_CONSTRAINT) if (pathlen != X509_NO_CONSTRAINT)
{ {
whack_log(RC_COMMENT, " pathlen: %d", pathlen); whack_log(RC_COMMENT, " pathlen: %d", pathlen);