1656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* crypto/x509/x509_req.c */ 2656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) 3656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * All rights reserved. 4656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 5656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * This package is an SSL implementation written 6656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * by Eric Young (eay@cryptsoft.com). 7656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * The implementation was written so as to conform with Netscapes SSL. 8656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 9656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * This library is free for commercial and non-commercial use as long as 10656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * the following conditions are aheared to. The following conditions 11656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * apply to all code found in this distribution, be it the RC4, RSA, 12656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * lhash, DES, etc., code; not just the SSL code. The SSL documentation 13656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * included with this distribution is covered by the same copyright terms 14656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * except that the holder is Tim Hudson (tjh@cryptsoft.com). 15656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 16656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * Copyright remains Eric Young's, and as such any Copyright notices in 17656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * the code are not to be removed. 18656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * If this package is used in a product, Eric Young should be given attribution 19656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * as the author of the parts of the library used. 20656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * This can be in the form of a textual message at program startup or 21656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * in documentation (online or textual) provided with the package. 22656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 23656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * Redistribution and use in source and binary forms, with or without 24656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * modification, are permitted provided that the following conditions 25656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * are met: 26656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 1. Redistributions of source code must retain the copyright 27656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * notice, this list of conditions and the following disclaimer. 28656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 2. Redistributions in binary form must reproduce the above copyright 29656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * notice, this list of conditions and the following disclaimer in the 30656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * documentation and/or other materials provided with the distribution. 31656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 3. All advertising materials mentioning features or use of this software 32656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * must display the following acknowledgement: 33656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * "This product includes cryptographic software written by 34656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * Eric Young (eay@cryptsoft.com)" 35656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * The word 'cryptographic' can be left out if the rouines from the library 36656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * being used are not cryptographic related :-). 37656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 4. If you include any Windows specific code (or a derivative thereof) from 38656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * the apps directory (application code) you must include an acknowledgement: 39656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" 40656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 41656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND 42656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 43656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 44656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 45656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 46656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 47656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 48656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 49656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 50656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 51656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * SUCH DAMAGE. 52656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 53656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * The licence and distribution terms for any publically available version or 54656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * derivative of this code cannot be changed. i.e. this code cannot simply be 55656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * copied and put under another distribution licence 56656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * [including the GNU Public Licence.] 57656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project */ 58656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 59656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <stdio.h> 60656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include "cryptlib.h" 61656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/bn.h> 62656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/evp.h> 63656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/asn1.h> 64221304ee937bc0910948a8be1320cb8cc4eb6d36Brian Carlstrom#include <openssl/asn1t.h> 65656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/x509.h> 66656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/objects.h> 67656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/buffer.h> 68656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/pem.h> 69656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 70656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source ProjectX509_REQ *X509_to_X509_REQ(X509 *x, EVP_PKEY *pkey, const EVP_MD *md) 71656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 72656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_REQ *ret; 73656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_REQ_INFO *ri; 74656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int i; 75656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project EVP_PKEY *pktmp; 76656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 77656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ret=X509_REQ_new(); 78656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (ret == NULL) 79656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 80656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509err(X509_F_X509_TO_X509_REQ,ERR_R_MALLOC_FAILURE); 81656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 82656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 83656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 84656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ri=ret->req_info; 85656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 86656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ri->version->length=1; 87656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ri->version->data=(unsigned char *)OPENSSL_malloc(1); 88656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (ri->version->data == NULL) goto err; 89656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ri->version->data[0]=0; /* version == 0 */ 90656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 91656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!X509_REQ_set_subject_name(ret,X509_get_subject_name(x))) 92656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 93656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 94656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project pktmp = X509_get_pubkey(x); 95656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project i=X509_REQ_set_pubkey(ret,pktmp); 96656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project EVP_PKEY_free(pktmp); 97656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!i) goto err; 98656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 99656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (pkey != NULL) 100656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 101656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!X509_REQ_sign(ret,pkey,md)) 102656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 103656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 104656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return(ret); 105656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projecterr: 106656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_REQ_free(ret); 107656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return(NULL); 108656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 109656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 110656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source ProjectEVP_PKEY *X509_REQ_get_pubkey(X509_REQ *req) 111656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 112656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if ((req == NULL) || (req->req_info == NULL)) 113656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return(NULL); 114656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return(X509_PUBKEY_get(req->req_info->pubkey)); 115656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 116656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 117656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_check_private_key(X509_REQ *x, EVP_PKEY *k) 118656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 119656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project EVP_PKEY *xk=NULL; 120656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int ok=0; 121656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 122656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project xk=X509_REQ_get_pubkey(x); 123656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project switch (EVP_PKEY_cmp(xk, k)) 124656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 125656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project case 1: 126656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ok=1; 127656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project break; 128656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project case 0: 129656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509err(X509_F_X509_REQ_CHECK_PRIVATE_KEY,X509_R_KEY_VALUES_MISMATCH); 130656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project break; 131656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project case -1: 132656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509err(X509_F_X509_REQ_CHECK_PRIVATE_KEY,X509_R_KEY_TYPE_MISMATCH); 133656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project break; 134656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project case -2: 135656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#ifndef OPENSSL_NO_EC 136656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (k->type == EVP_PKEY_EC) 137656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 138656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509err(X509_F_X509_REQ_CHECK_PRIVATE_KEY, ERR_R_EC_LIB); 139656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project break; 140656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 141656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#endif 142656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#ifndef OPENSSL_NO_DH 143656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (k->type == EVP_PKEY_DH) 144656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 145656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* No idea */ 146656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509err(X509_F_X509_REQ_CHECK_PRIVATE_KEY,X509_R_CANT_CHECK_DH_KEY); 147656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project break; 148656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 149656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#endif 150656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509err(X509_F_X509_REQ_CHECK_PRIVATE_KEY,X509_R_UNKNOWN_KEY_TYPE); 151656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 152656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 153656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project EVP_PKEY_free(xk); 154656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return(ok); 155656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 156656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 157656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* It seems several organisations had the same idea of including a list of 158656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * extensions in a certificate request. There are at least two OIDs that are 159656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * used and there may be more: so the list is configurable. 160656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project */ 161656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 162656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectstatic int ext_nid_list[] = { NID_ext_req, NID_ms_ext_req, NID_undef}; 163656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 164656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectstatic int *ext_nids = ext_nid_list; 165656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 166656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_extension_nid(int req_nid) 167656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 168656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int i, nid; 169656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project for(i = 0; ; i++) { 170656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project nid = ext_nids[i]; 171656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(nid == NID_undef) return 0; 172656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project else if (req_nid == nid) return 1; 173656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 174656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 175656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 176656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint *X509_REQ_get_extension_nids(void) 177656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 178656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return ext_nids; 179656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 180656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 181656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectvoid X509_REQ_set_extension_nids(int *nids) 182656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 183656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ext_nids = nids; 184656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 185656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 186656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source ProjectSTACK_OF(X509_EXTENSION) *X509_REQ_get_extensions(X509_REQ *req) 187656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 188656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_ATTRIBUTE *attr; 189656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ASN1_TYPE *ext = NULL; 190656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int idx, *pnid; 191656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project const unsigned char *p; 192656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 193656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if ((req == NULL) || (req->req_info == NULL) || !ext_nids) 194656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return(NULL); 195656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project for (pnid = ext_nids; *pnid != NID_undef; pnid++) 196656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 197656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project idx = X509_REQ_get_attr_by_NID(req, *pnid, -1); 198656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (idx == -1) 199656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project continue; 200656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project attr = X509_REQ_get_attr(req, idx); 201656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(attr->single) ext = attr->value.single; 202656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project else if(sk_ASN1_TYPE_num(attr->value.set)) 203656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ext = sk_ASN1_TYPE_value(attr->value.set, 0); 204656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project break; 205656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 206656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!ext || (ext->type != V_ASN1_SEQUENCE)) 207656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return NULL; 208656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project p = ext->value.sequence->data; 209221304ee937bc0910948a8be1320cb8cc4eb6d36Brian Carlstrom return (STACK_OF(X509_EXTENSION) *) 210221304ee937bc0910948a8be1320cb8cc4eb6d36Brian Carlstrom ASN1_item_d2i(NULL, &p, ext->value.sequence->length, 211221304ee937bc0910948a8be1320cb8cc4eb6d36Brian Carlstrom ASN1_ITEM_rptr(X509_EXTENSIONS)); 212656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 213656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 214656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* Add a STACK_OF extensions to a certificate request: allow alternative OIDs 215656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * in case we want to create a non standard one. 216656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project */ 217656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 218656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_add_extensions_nid(X509_REQ *req, STACK_OF(X509_EXTENSION) *exts, 219656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int nid) 220656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 221656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ASN1_TYPE *at = NULL; 222656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_ATTRIBUTE *attr = NULL; 223656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!(at = ASN1_TYPE_new()) || 224656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project !(at->value.sequence = ASN1_STRING_new())) goto err; 225656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 226656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project at->type = V_ASN1_SEQUENCE; 227656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* Generate encoding of extensions */ 228221304ee937bc0910948a8be1320cb8cc4eb6d36Brian Carlstrom at->value.sequence->length = 229221304ee937bc0910948a8be1320cb8cc4eb6d36Brian Carlstrom ASN1_item_i2d((ASN1_VALUE *)exts, 230221304ee937bc0910948a8be1320cb8cc4eb6d36Brian Carlstrom &at->value.sequence->data, 231221304ee937bc0910948a8be1320cb8cc4eb6d36Brian Carlstrom ASN1_ITEM_rptr(X509_EXTENSIONS)); 232656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!(attr = X509_ATTRIBUTE_new())) goto err; 233656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!(attr->value.set = sk_ASN1_TYPE_new_null())) goto err; 234656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!sk_ASN1_TYPE_push(attr->value.set, at)) goto err; 235656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project at = NULL; 236656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project attr->single = 0; 237656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project attr->object = OBJ_nid2obj(nid); 238656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!req->req_info->attributes) 239656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 240656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!(req->req_info->attributes = sk_X509_ATTRIBUTE_new_null())) 241656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 242656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 243656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(!sk_X509_ATTRIBUTE_push(req->req_info->attributes, attr)) goto err; 244656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return 1; 245656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project err: 246656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_ATTRIBUTE_free(attr); 247656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ASN1_TYPE_free(at); 248656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return 0; 249656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 250656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* This is the normal usage: use the "official" OID */ 251656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_add_extensions(X509_REQ *req, STACK_OF(X509_EXTENSION) *exts) 252656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 253656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return X509_REQ_add_extensions_nid(req, exts, NID_ext_req); 254656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 255656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 256656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* Request attribute functions */ 257656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 258656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_get_attr_count(const X509_REQ *req) 259656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 260656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return X509at_get_attr_count(req->req_info->attributes); 261656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 262656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 263656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_get_attr_by_NID(const X509_REQ *req, int nid, 264656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int lastpos) 265656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 266656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return X509at_get_attr_by_NID(req->req_info->attributes, nid, lastpos); 267656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 268656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 269656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_get_attr_by_OBJ(const X509_REQ *req, ASN1_OBJECT *obj, 270656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int lastpos) 271656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 272656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return X509at_get_attr_by_OBJ(req->req_info->attributes, obj, lastpos); 273656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 274656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 275656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source ProjectX509_ATTRIBUTE *X509_REQ_get_attr(const X509_REQ *req, int loc) 276656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 277656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return X509at_get_attr(req->req_info->attributes, loc); 278656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 279656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 280656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source ProjectX509_ATTRIBUTE *X509_REQ_delete_attr(X509_REQ *req, int loc) 281656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 282656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return X509at_delete_attr(req->req_info->attributes, loc); 283656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 284656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 285656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_add1_attr(X509_REQ *req, X509_ATTRIBUTE *attr) 286656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 287656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(X509at_add1_attr(&req->req_info->attributes, attr)) return 1; 288656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return 0; 289656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 290656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 291656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_add1_attr_by_OBJ(X509_REQ *req, 292656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project const ASN1_OBJECT *obj, int type, 293656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project const unsigned char *bytes, int len) 294656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 295656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(X509at_add1_attr_by_OBJ(&req->req_info->attributes, obj, 296656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project type, bytes, len)) return 1; 297656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return 0; 298656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 299656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 300656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_add1_attr_by_NID(X509_REQ *req, 301656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int nid, int type, 302656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project const unsigned char *bytes, int len) 303656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 304656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(X509at_add1_attr_by_NID(&req->req_info->attributes, nid, 305656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project type, bytes, len)) return 1; 306656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return 0; 307656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 308656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 309656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint X509_REQ_add1_attr_by_txt(X509_REQ *req, 310656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project const char *attrname, int type, 311656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project const unsigned char *bytes, int len) 312656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project{ 313656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if(X509at_add1_attr_by_txt(&req->req_info->attributes, attrname, 314656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project type, bytes, len)) return 1; 315656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return 0; 316656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project} 317