changed prefix of crl_reason_t values from CRL_ to CRL_REASON_
This commit is contained in:
@@ -16,7 +16,7 @@
|
|||||||
|
|
||||||
#include "crl.h"
|
#include "crl.h"
|
||||||
|
|
||||||
ENUM(crl_reason_names, CRL_UNSPECIFIED, CRL_REMOVE_FROM_CRL,
|
ENUM(crl_reason_names, CRL_REASON_UNSPECIFIED, CRL_REASON_REMOVE_FROM_CRL,
|
||||||
"unspecified",
|
"unspecified",
|
||||||
"key compromise",
|
"key compromise",
|
||||||
"ca compromise",
|
"ca compromise",
|
||||||
|
|||||||
@@ -32,14 +32,14 @@ typedef enum crl_reason_t crl_reason_t;
|
|||||||
* RFC 2459 CRL reason codes
|
* RFC 2459 CRL reason codes
|
||||||
*/
|
*/
|
||||||
enum crl_reason_t {
|
enum crl_reason_t {
|
||||||
CRL_UNSPECIFIED = 0,
|
CRL_REASON_UNSPECIFIED = 0,
|
||||||
CRL_KEY_COMPROMISE = 1,
|
CRL_REASON_KEY_COMPROMISE = 1,
|
||||||
CRL_CA_COMPROMISE = 2,
|
CRL_REASON_CA_COMPROMISE = 2,
|
||||||
CRL_AFFILIATION_CHANGED = 3,
|
CRL_REASON_AFFILIATION_CHANGED = 3,
|
||||||
CRL_SUPERSEDED = 4,
|
CRL_REASON_SUPERSEDED = 4,
|
||||||
CRL_CESSATION_OF_OPERATON = 5,
|
CRL_REASON_CESSATION_OF_OPERATON = 5,
|
||||||
CRL_CERTIFICATE_HOLD = 6,
|
CRL_REASON_CERTIFICATE_HOLD = 6,
|
||||||
CRL_REMOVE_FROM_CRL = 8,
|
CRL_REASON_REMOVE_FROM_CRL = 8,
|
||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|||||||
@@ -238,7 +238,7 @@ static bool parse(private_x509_crl_t *this)
|
|||||||
revoked = malloc_thing(revoked_t);
|
revoked = malloc_thing(revoked_t);
|
||||||
revoked->serial = userCertificate;
|
revoked->serial = userCertificate;
|
||||||
revoked->date = asn1_parse_time(object, level);
|
revoked->date = asn1_parse_time(object, level);
|
||||||
revoked->reason = CRL_UNSPECIFIED;
|
revoked->reason = CRL_REASON_UNSPECIFIED;
|
||||||
this->revoked->insert_last(this->revoked, (void *)revoked);
|
this->revoked->insert_last(this->revoked, (void *)revoked);
|
||||||
break;
|
break;
|
||||||
case CRL_OBJ_CRL_ENTRY_EXTN_ID:
|
case CRL_OBJ_CRL_ENTRY_EXTN_ID:
|
||||||
|
|||||||
@@ -320,7 +320,7 @@ static bool parse_singleResponse(private_x509_ocsp_response_t *this,
|
|||||||
response->serialNumber = chunk_empty;
|
response->serialNumber = chunk_empty;
|
||||||
response->status = VALIDATION_FAILED;
|
response->status = VALIDATION_FAILED;
|
||||||
response->revocationTime = 0;
|
response->revocationTime = 0;
|
||||||
response->revocationReason = CRL_UNSPECIFIED;
|
response->revocationReason = CRL_REASON_UNSPECIFIED;
|
||||||
response->thisUpdate = UNDEFINED_TIME;
|
response->thisUpdate = UNDEFINED_TIME;
|
||||||
/* if nextUpdate is missing, we give it a short lifetime */
|
/* if nextUpdate is missing, we give it a short lifetime */
|
||||||
response->nextUpdate = this->producedAt + OCSP_DEFAULT_LIFETIME;
|
response->nextUpdate = this->producedAt + OCSP_DEFAULT_LIFETIME;
|
||||||
|
|||||||
+4
-4
@@ -374,7 +374,7 @@ void load_crls(void)
|
|||||||
*/
|
*/
|
||||||
static crl_reason_t parse_crl_reasonCode(chunk_t object)
|
static crl_reason_t parse_crl_reasonCode(chunk_t object)
|
||||||
{
|
{
|
||||||
crl_reason_t reason = CRL_UNSPECIFIED;
|
crl_reason_t reason = CRL_REASON_UNSPECIFIED;
|
||||||
|
|
||||||
if (*object.ptr == ASN1_ENUMERATED
|
if (*object.ptr == ASN1_ENUMERATED
|
||||||
&& asn1_length(&object) == 1)
|
&& asn1_length(&object) == 1)
|
||||||
@@ -448,7 +448,7 @@ bool parse_x509crl(chunk_t blob, u_int level0, x509crl_t *crl)
|
|||||||
revokedCert_t *revokedCert = malloc_thing(revokedCert_t);
|
revokedCert_t *revokedCert = malloc_thing(revokedCert_t);
|
||||||
revokedCert->userCertificate = userCertificate;
|
revokedCert->userCertificate = userCertificate;
|
||||||
revokedCert->revocationDate = asn1_parse_time(object, level);
|
revokedCert->revocationDate = asn1_parse_time(object, level);
|
||||||
revokedCert->revocationReason = CRL_UNSPECIFIED;
|
revokedCert->revocationReason = CRL_REASON_UNSPECIFIED;
|
||||||
revokedCert->next = crl->revokedCertificates;
|
revokedCert->next = crl->revokedCertificates;
|
||||||
crl->revokedCertificates = revokedCert;
|
crl->revokedCertificates = revokedCert;
|
||||||
}
|
}
|
||||||
@@ -519,7 +519,7 @@ check_revocation(const x509crl_t *crl, chunk_t serial
|
|||||||
revokedCert_t *revokedCert = crl->revokedCertificates;
|
revokedCert_t *revokedCert = crl->revokedCertificates;
|
||||||
|
|
||||||
*revocationDate = UNDEFINED_TIME;
|
*revocationDate = UNDEFINED_TIME;
|
||||||
*revocationReason = CRL_UNSPECIFIED;
|
*revocationReason = CRL_REASON_UNSPECIFIED;
|
||||||
|
|
||||||
DBG(DBG_CONTROL,
|
DBG(DBG_CONTROL,
|
||||||
DBG_dump_chunk("serial number:", serial)
|
DBG_dump_chunk("serial number:", serial)
|
||||||
@@ -594,7 +594,7 @@ verify_by_crl(const x509cert_t *cert, time_t *until, time_t *revocationDate
|
|||||||
generalName_t *crluri = (ca == NULL)? NULL : ca->crluri;
|
generalName_t *crluri = (ca == NULL)? NULL : ca->crluri;
|
||||||
|
|
||||||
*revocationDate = UNDEFINED_TIME;
|
*revocationDate = UNDEFINED_TIME;
|
||||||
*revocationReason = CRL_UNSPECIFIED;
|
*revocationReason = CRL_REASON_UNSPECIFIED;
|
||||||
|
|
||||||
lock_crl_list("verify_by_crl");
|
lock_crl_list("verify_by_crl");
|
||||||
crl = get_x509crl(cert->issuer, cert->authKeySerialNumber, cert->authKeyID);
|
crl = get_x509crl(cert->issuer, cert->authKeySerialNumber, cert->authKeyID);
|
||||||
|
|||||||
+12
-12
@@ -105,16 +105,16 @@ struct single_response {
|
|||||||
};
|
};
|
||||||
|
|
||||||
const single_response_t empty_single_response = {
|
const single_response_t empty_single_response = {
|
||||||
NULL , /* *next */
|
NULL , /* *next */
|
||||||
OID_UNKNOWN , /* hash_algorithm */
|
OID_UNKNOWN , /* hash_algorithm */
|
||||||
{ NULL, 0 } , /* issuer_name_hash */
|
{ NULL, 0 } , /* issuer_name_hash */
|
||||||
{ NULL, 0 } , /* issuer_key_hash */
|
{ NULL, 0 } , /* issuer_key_hash */
|
||||||
{ NULL, 0 } , /* serial_number */
|
{ NULL, 0 } , /* serial_number */
|
||||||
CERT_UNDEFINED , /* status */
|
CERT_UNDEFINED , /* status */
|
||||||
UNDEFINED_TIME , /* revocationTime */
|
UNDEFINED_TIME , /* revocationTime */
|
||||||
CRL_UNSPECIFIED , /* revocationReason */
|
CRL_REASON_UNSPECIFIED, /* revocationReason */
|
||||||
UNDEFINED_TIME , /* this_update */
|
UNDEFINED_TIME , /* this_update */
|
||||||
UNDEFINED_TIME /* next_update */
|
UNDEFINED_TIME /* next_update */
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
||||||
@@ -425,7 +425,7 @@ cert_status_t verify_by_ocsp(const x509cert_t *cert, time_t *until,
|
|||||||
time_t nextUpdate = 0;
|
time_t nextUpdate = 0;
|
||||||
|
|
||||||
*revocationDate = UNDEFINED_TIME;
|
*revocationDate = UNDEFINED_TIME;
|
||||||
*revocationReason = CRL_UNSPECIFIED;
|
*revocationReason = CRL_REASON_UNSPECIFIED;
|
||||||
|
|
||||||
/* is an ocsp location defined? */
|
/* is an ocsp location defined? */
|
||||||
if (!build_ocsp_location(cert, &location))
|
if (!build_ocsp_location(cert, &location))
|
||||||
@@ -1292,7 +1292,7 @@ static bool parse_ocsp_single_response(chunk_t blob, int level0,
|
|||||||
break;
|
break;
|
||||||
case SINGLE_RESPONSE_CERT_STATUS_CRL_REASON:
|
case SINGLE_RESPONSE_CERT_STATUS_CRL_REASON:
|
||||||
sres->revocationReason = (object.len == 1)
|
sres->revocationReason = (object.len == 1)
|
||||||
? *object.ptr : CRL_UNSPECIFIED;
|
? *object.ptr : CRL_REASON_UNSPECIFIED;
|
||||||
break;
|
break;
|
||||||
case SINGLE_RESPONSE_CERT_STATUS_UNKNOWN:
|
case SINGLE_RESPONSE_CERT_STATUS_UNKNOWN:
|
||||||
sres->status = CERT_UNKNOWN;
|
sres->status = CERT_UNKNOWN;
|
||||||
|
|||||||
+1
-1
@@ -1986,7 +1986,7 @@ bool verify_x509cert(const x509cert_t *cert, bool strict, time_t *until)
|
|||||||
{
|
{
|
||||||
time_t nextUpdate = *until;
|
time_t nextUpdate = *until;
|
||||||
time_t revocationDate = UNDEFINED_TIME;
|
time_t revocationDate = UNDEFINED_TIME;
|
||||||
crl_reason_t revocationReason = CRL_UNSPECIFIED;
|
crl_reason_t revocationReason = CRL_REASON_UNSPECIFIED;
|
||||||
|
|
||||||
/* first check certificate revocation using ocsp */
|
/* first check certificate revocation using ocsp */
|
||||||
cert_status_t status = verify_by_ocsp(cert, &nextUpdate
|
cert_status_t status = verify_by_ocsp(cert, &nextUpdate
|
||||||
|
|||||||
Reference in New Issue
Block a user