Use a generic getter for all numerical X.509 constraints
This commit is contained in:
@@ -834,7 +834,7 @@ static void stroke_list_certs(linked_list_t *list, char *label,
|
|||||||
}
|
}
|
||||||
|
|
||||||
/* list optional pathLenConstraint */
|
/* list optional pathLenConstraint */
|
||||||
pathlen = x509->get_pathLenConstraint(x509);
|
pathlen = x509->get_constraint(x509, X509_PATH_LEN);
|
||||||
if (pathlen != X509_NO_CONSTRAINT)
|
if (pathlen != X509_NO_CONSTRAINT)
|
||||||
{
|
{
|
||||||
fprintf(out, " pathlen: %d\n", pathlen);
|
fprintf(out, " pathlen: %d\n", pathlen);
|
||||||
|
|||||||
@@ -31,6 +31,7 @@ typedef struct x509_cert_policy_t x509_cert_policy_t;
|
|||||||
typedef struct x509_policy_mapping_t x509_policy_mapping_t;
|
typedef struct x509_policy_mapping_t x509_policy_mapping_t;
|
||||||
typedef struct x509_cdp_t x509_cdp_t;
|
typedef struct x509_cdp_t x509_cdp_t;
|
||||||
typedef enum x509_flag_t x509_flag_t;
|
typedef enum x509_flag_t x509_flag_t;
|
||||||
|
typedef enum x509_constraint_t x509_constraint_t;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* X.509 certificate flags.
|
* X.509 certificate flags.
|
||||||
@@ -56,6 +57,18 @@ enum x509_flag_t {
|
|||||||
X509_CRL_SIGN = (1<<7),
|
X509_CRL_SIGN = (1<<7),
|
||||||
};
|
};
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Different numerical X.509 constraints.
|
||||||
|
*/
|
||||||
|
enum x509_constraint_t {
|
||||||
|
/** pathLenConstraint basicConstraints */
|
||||||
|
X509_PATH_LEN,
|
||||||
|
/** inhibitPolicyMapping policyConstraint */
|
||||||
|
X509_INHIBIT_POLICY_MAPPING,
|
||||||
|
/** requireExplicitPolicy policyConstraint */
|
||||||
|
X509_REQUIRE_EXPLICIT_POLICY,
|
||||||
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* X.509 certPolicy extension.
|
* X.509 certPolicy extension.
|
||||||
*/
|
*/
|
||||||
@@ -130,19 +143,12 @@ struct x509_t {
|
|||||||
chunk_t (*get_authKeyIdentifier)(x509_t *this);
|
chunk_t (*get_authKeyIdentifier)(x509_t *this);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Get an optional path length constraint.
|
* Get a numerical X.509 constraint.
|
||||||
*
|
*
|
||||||
* @return pathLenConstraint, X509_NO_CONSTRAINT if none found
|
* @param type type of constraint to get
|
||||||
*/
|
|
||||||
int (*get_pathLenConstraint)(x509_t *this);
|
|
||||||
|
|
||||||
/**
|
|
||||||
* Get a policyConstraint, inhibitPolicyMapping or requireExplicitPolicy.
|
|
||||||
*
|
|
||||||
* @param inhibit TRUE to get inhibitPolicyMapping
|
|
||||||
* @return constraint, X509_NO_CONSTRAINT if none found
|
* @return constraint, X509_NO_CONSTRAINT if none found
|
||||||
*/
|
*/
|
||||||
int (*get_policyConstraint)(x509_t *this, bool inhibit);
|
int (*get_constraint)(x509_t *this, x509_constraint_t type);
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Create an enumerator over all subjectAltNames.
|
* Create an enumerator over all subjectAltNames.
|
||||||
|
|||||||
@@ -40,7 +40,7 @@ static bool check_pathlen(x509_t *issuer, int pathlen)
|
|||||||
{
|
{
|
||||||
int pathlen_constraint;
|
int pathlen_constraint;
|
||||||
|
|
||||||
pathlen_constraint = issuer->get_pathLenConstraint(issuer);
|
pathlen_constraint = issuer->get_constraint(issuer, X509_PATH_LEN);
|
||||||
if (pathlen_constraint != X509_NO_CONSTRAINT &&
|
if (pathlen_constraint != X509_NO_CONSTRAINT &&
|
||||||
pathlen > pathlen_constraint)
|
pathlen > pathlen_constraint)
|
||||||
{
|
{
|
||||||
@@ -439,7 +439,7 @@ static bool check_policy_constraints(x509_t *issuer, int pathlen,
|
|||||||
enumerator = chain->create_enumerator(chain);
|
enumerator = chain->create_enumerator(chain);
|
||||||
while (enumerator->enumerate(enumerator, &x509))
|
while (enumerator->enumerate(enumerator, &x509))
|
||||||
{
|
{
|
||||||
expl = x509->get_policyConstraint(x509, FALSE);
|
expl = x509->get_constraint(x509, X509_REQUIRE_EXPLICIT_POLICY);
|
||||||
if (expl != X509_NO_CONSTRAINT)
|
if (expl != X509_NO_CONSTRAINT)
|
||||||
{
|
{
|
||||||
if (!has_policy_chain(chain, (x509_t*)subject, len - expl))
|
if (!has_policy_chain(chain, (x509_t*)subject, len - expl))
|
||||||
@@ -458,7 +458,7 @@ static bool check_policy_constraints(x509_t *issuer, int pathlen,
|
|||||||
enumerator = chain->create_enumerator(chain);
|
enumerator = chain->create_enumerator(chain);
|
||||||
while (enumerator->enumerate(enumerator, &x509))
|
while (enumerator->enumerate(enumerator, &x509))
|
||||||
{
|
{
|
||||||
expl = x509->get_policyConstraint(x509, TRUE);
|
expl = x509->get_constraint(x509, X509_INHIBIT_POLICY_MAPPING);
|
||||||
if (expl != X509_NO_CONSTRAINT)
|
if (expl != X509_NO_CONSTRAINT)
|
||||||
{
|
{
|
||||||
if (!has_policy_mapping(chain, len - expl))
|
if (!has_policy_mapping(chain, len - expl))
|
||||||
|
|||||||
@@ -250,16 +250,16 @@ METHOD(x509_t, get_authKeyIdentifier, chunk_t,
|
|||||||
return chunk_empty;
|
return chunk_empty;
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(x509_t, get_pathLenConstraint, int,
|
METHOD(x509_t, get_constraint, int,
|
||||||
private_openssl_x509_t *this)
|
private_openssl_x509_t *this, x509_constraint_t type)
|
||||||
{
|
{
|
||||||
return this->pathlen;
|
switch (type)
|
||||||
}
|
{
|
||||||
|
case X509_PATH_LEN:
|
||||||
METHOD(x509_t, get_policyConstraint, int,
|
return this->pathlen;
|
||||||
private_openssl_x509_t *this, bool inhibit)
|
default:
|
||||||
{
|
return X509_NO_CONSTRAINT;
|
||||||
return X509_NO_CONSTRAINT;
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(x509_t, create_subjectAltName_enumerator, enumerator_t*,
|
METHOD(x509_t, create_subjectAltName_enumerator, enumerator_t*,
|
||||||
@@ -526,8 +526,7 @@ static private_openssl_x509_t *create_empty()
|
|||||||
.get_serial = _get_serial,
|
.get_serial = _get_serial,
|
||||||
.get_subjectKeyIdentifier = _get_subjectKeyIdentifier,
|
.get_subjectKeyIdentifier = _get_subjectKeyIdentifier,
|
||||||
.get_authKeyIdentifier = _get_authKeyIdentifier,
|
.get_authKeyIdentifier = _get_authKeyIdentifier,
|
||||||
.get_pathLenConstraint = _get_pathLenConstraint,
|
.get_constraint = _get_constraint,
|
||||||
.get_policyConstraint = _get_policyConstraint,
|
|
||||||
.create_subjectAltName_enumerator = _create_subjectAltName_enumerator,
|
.create_subjectAltName_enumerator = _create_subjectAltName_enumerator,
|
||||||
.create_crl_uri_enumerator = _create_crl_uri_enumerator,
|
.create_crl_uri_enumerator = _create_crl_uri_enumerator,
|
||||||
.create_ocsp_uri_enumerator = _create_ocsp_uri_enumerator,
|
.create_ocsp_uri_enumerator = _create_ocsp_uri_enumerator,
|
||||||
|
|||||||
@@ -1716,20 +1716,20 @@ METHOD(x509_t, get_authKeyIdentifier, chunk_t,
|
|||||||
return this->authKeyIdentifier;
|
return this->authKeyIdentifier;
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(x509_t, get_pathLenConstraint, int,
|
METHOD(x509_t, get_constraint, int,
|
||||||
private_x509_cert_t *this)
|
private_x509_cert_t *this, x509_constraint_t type)
|
||||||
{
|
{
|
||||||
return this->pathLenConstraint;
|
switch (type)
|
||||||
}
|
|
||||||
|
|
||||||
METHOD(x509_t, get_policyConstraint, int,
|
|
||||||
private_x509_cert_t *this, bool inhibit)
|
|
||||||
{
|
|
||||||
if (inhibit)
|
|
||||||
{
|
{
|
||||||
return this->inhibit_policy_constraint;
|
case X509_PATH_LEN:
|
||||||
|
return this->pathLenConstraint;
|
||||||
|
case X509_REQUIRE_EXPLICIT_POLICY:
|
||||||
|
return this->explicit_policy_constraint;
|
||||||
|
case X509_INHIBIT_POLICY_MAPPING:
|
||||||
|
return this->inhibit_policy_constraint;
|
||||||
|
default:
|
||||||
|
return X509_NO_CONSTRAINT;
|
||||||
}
|
}
|
||||||
return this->explicit_policy_constraint;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
METHOD(x509_t, create_subjectAltName_enumerator, enumerator_t*,
|
METHOD(x509_t, create_subjectAltName_enumerator, enumerator_t*,
|
||||||
@@ -1841,8 +1841,7 @@ static private_x509_cert_t* create_empty(void)
|
|||||||
.get_serial = _get_serial,
|
.get_serial = _get_serial,
|
||||||
.get_subjectKeyIdentifier = _get_subjectKeyIdentifier,
|
.get_subjectKeyIdentifier = _get_subjectKeyIdentifier,
|
||||||
.get_authKeyIdentifier = _get_authKeyIdentifier,
|
.get_authKeyIdentifier = _get_authKeyIdentifier,
|
||||||
.get_pathLenConstraint = _get_pathLenConstraint,
|
.get_constraint = _get_constraint,
|
||||||
.get_policyConstraint = _get_policyConstraint,
|
|
||||||
.create_subjectAltName_enumerator = _create_subjectAltName_enumerator,
|
.create_subjectAltName_enumerator = _create_subjectAltName_enumerator,
|
||||||
.create_crl_uri_enumerator = _create_crl_uri_enumerator,
|
.create_crl_uri_enumerator = _create_crl_uri_enumerator,
|
||||||
.create_ocsp_uri_enumerator = _create_ocsp_uri_enumerator,
|
.create_ocsp_uri_enumerator = _create_ocsp_uri_enumerator,
|
||||||
|
|||||||
+10
-10
@@ -73,7 +73,7 @@ static void print_x509(x509_t *x509)
|
|||||||
chunk_t chunk;
|
chunk_t chunk;
|
||||||
bool first;
|
bool first;
|
||||||
char *uri;
|
char *uri;
|
||||||
int len;
|
int len, explicit, inhibit;
|
||||||
x509_flag_t flags;
|
x509_flag_t flags;
|
||||||
x509_cdp_t *cdp;
|
x509_cdp_t *cdp;
|
||||||
x509_cert_policy_t *policy;
|
x509_cert_policy_t *policy;
|
||||||
@@ -176,7 +176,7 @@ static void print_x509(x509_t *x509)
|
|||||||
}
|
}
|
||||||
enumerator->destroy(enumerator);
|
enumerator->destroy(enumerator);
|
||||||
|
|
||||||
len = x509->get_pathLenConstraint(x509);
|
len = x509->get_constraint(x509, X509_PATH_LEN);
|
||||||
if (len != X509_NO_CONSTRAINT)
|
if (len != X509_NO_CONSTRAINT)
|
||||||
{
|
{
|
||||||
printf("pathlen: %d\n", len);
|
printf("pathlen: %d\n", len);
|
||||||
@@ -259,19 +259,19 @@ static void print_x509(x509_t *x509)
|
|||||||
}
|
}
|
||||||
enumerator->destroy(enumerator);
|
enumerator->destroy(enumerator);
|
||||||
|
|
||||||
if (x509->get_policyConstraint(x509, FALSE) != X509_NO_CONSTRAINT ||
|
explicit = x509->get_constraint(x509, X509_REQUIRE_EXPLICIT_POLICY);
|
||||||
x509->get_policyConstraint(x509, TRUE) != X509_NO_CONSTRAINT)
|
inhibit = x509->get_constraint(x509, X509_INHIBIT_POLICY_MAPPING);
|
||||||
|
|
||||||
|
if (explicit != X509_NO_CONSTRAINT || inhibit != X509_NO_CONSTRAINT)
|
||||||
{
|
{
|
||||||
printf("PolicyConstraints:\n");
|
printf("PolicyConstraints:\n");
|
||||||
if (x509->get_policyConstraint(x509, FALSE) != X509_NO_CONSTRAINT)
|
if (explicit != X509_NO_CONSTRAINT)
|
||||||
{
|
{
|
||||||
printf(" requireExplicitPolicy: %d\n",
|
printf(" requireExplicitPolicy: %d\n", explicit);
|
||||||
x509->get_policyConstraint(x509, FALSE));
|
|
||||||
}
|
}
|
||||||
if (x509->get_policyConstraint(x509, TRUE) != X509_NO_CONSTRAINT)
|
if (inhibit != X509_NO_CONSTRAINT)
|
||||||
{
|
{
|
||||||
printf(" inhibitPolicyMapping: %d\n",
|
printf(" inhibitPolicyMapping: %d\n", inhibit);
|
||||||
x509->get_policyConstraint(x509, TRUE));
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+1
-1
@@ -1045,7 +1045,7 @@ static bool valid_ocsp_response(response_t *res)
|
|||||||
)
|
)
|
||||||
|
|
||||||
/* check path length constraint */
|
/* check path length constraint */
|
||||||
pathlen_constraint = x509->get_pathLenConstraint(x509);
|
pathlen_constraint = x509->get_constraint(x509, X509_PATH_LEN);
|
||||||
if (pathlen_constraint != X509_NO_CONSTRAINT &&
|
if (pathlen_constraint != X509_NO_CONSTRAINT &&
|
||||||
pathlen > pathlen_constraint)
|
pathlen > pathlen_constraint)
|
||||||
{
|
{
|
||||||
|
|||||||
+2
-2
@@ -255,7 +255,7 @@ bool verify_x509cert(cert_t *cert, bool strict, time_t *until)
|
|||||||
unlock_authcert_list("verify_x509cert");
|
unlock_authcert_list("verify_x509cert");
|
||||||
|
|
||||||
/* check path length constraint */
|
/* check path length constraint */
|
||||||
pathlen_constraint = x509->get_pathLenConstraint(x509);
|
pathlen_constraint = x509->get_constraint(x509, X509_PATH_LEN);
|
||||||
if (pathlen_constraint != X509_NO_CONSTRAINT &&
|
if (pathlen_constraint != X509_NO_CONSTRAINT &&
|
||||||
pathlen > pathlen_constraint)
|
pathlen > pathlen_constraint)
|
||||||
{
|
{
|
||||||
@@ -450,7 +450,7 @@ void list_x509cert_chain(const char *caption, cert_t* cert,
|
|||||||
}
|
}
|
||||||
|
|
||||||
/* list optional pathLenConstraint */
|
/* list optional pathLenConstraint */
|
||||||
pathlen = x509->get_pathLenConstraint(x509);
|
pathlen = x509->get_constraint(x509, X509_PATH_LEN);
|
||||||
if (pathlen != X509_NO_CONSTRAINT)
|
if (pathlen != X509_NO_CONSTRAINT)
|
||||||
{
|
{
|
||||||
whack_log(RC_COMMENT, " pathlen: %d", pathlen);
|
whack_log(RC_COMMENT, " pathlen: %d", pathlen);
|
||||||
|
|||||||
Reference in New Issue
Block a user