1c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org/* pcy_cache.c */ 2c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL 3c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * project 2004. 4c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org */ 5c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org/* ==================================================================== 6c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * Copyright (c) 2004 The OpenSSL Project. All rights reserved. 7c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 8c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * Redistribution and use in source and binary forms, with or without 9c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * modification, are permitted provided that the following conditions 10c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * are met: 11c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 12c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 1. Redistributions of source code must retain the above copyright 13c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * notice, this list of conditions and the following disclaimer. 14c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 15c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 2. Redistributions in binary form must reproduce the above copyright 16c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * notice, this list of conditions and the following disclaimer in 17c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * the documentation and/or other materials provided with the 18c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * distribution. 19c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 20c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 3. All advertising materials mentioning features or use of this 21c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * software must display the following acknowledgment: 22c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * "This product includes software developed by the OpenSSL Project 23c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)" 24c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 25c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to 26c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * endorse or promote products derived from this software without 27c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * prior written permission. For written permission, please contact 28c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * licensing@OpenSSL.org. 29c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 30c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 5. Products derived from this software may not be called "OpenSSL" 31c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * nor may "OpenSSL" appear in their names without prior written 32c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * permission of the OpenSSL Project. 33c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 34c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 6. Redistributions of any form whatsoever must retain the following 35c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * acknowledgment: 36c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * "This product includes software developed by the OpenSSL Project 37c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)" 38c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 39c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY 40c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 41c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 42c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR 43c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, 44c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT 45c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; 46c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 47c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, 48c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 49c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED 50c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * OF THE POSSIBILITY OF SUCH DAMAGE. 51c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * ==================================================================== 52c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 53c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * This product includes cryptographic software written by Eric Young 54c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * (eay@cryptsoft.com). This product includes software written by Tim 55c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * Hudson (tjh@cryptsoft.com). 56c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 57c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org */ 58c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 59c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include "cryptlib.h" 60c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include <openssl/x509.h> 61c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include <openssl/x509v3.h> 62c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 63c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include "pcy_int.h" 64c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 65c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgstatic int policy_data_cmp(const X509_POLICY_DATA * const *a, 66c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org const X509_POLICY_DATA * const *b); 67c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgstatic int policy_cache_set_int(long *out, ASN1_INTEGER *value); 68c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 69c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org/* Set cache entry according to CertificatePolicies extension. 70c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * Note: this destroys the passed CERTIFICATEPOLICIES structure. 71c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org */ 72c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 73c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgstatic int policy_cache_create(X509 *x, 74c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org CERTIFICATEPOLICIES *policies, int crit) 75c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 76c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org int i; 77c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org int ret = 0; 78c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org X509_POLICY_CACHE *cache = x->policy_cache; 79c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org X509_POLICY_DATA *data = NULL; 80c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org POLICYINFO *policy; 81c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (sk_POLICYINFO_num(policies) == 0) 82c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_policy; 83c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org cache->data = sk_X509_POLICY_DATA_new(policy_data_cmp); 84c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!cache->data) 85c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_policy; 86c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org for (i = 0; i < sk_POLICYINFO_num(policies); i++) 87c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 88c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org policy = sk_POLICYINFO_value(policies, i); 89c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org data = policy_data_new(policy, NULL, crit); 90c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!data) 91c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_policy; 92c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org /* Duplicate policy OIDs are illegal: reject if matches 93c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * found. 94c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org */ 95c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (OBJ_obj2nid(data->valid_policy) == NID_any_policy) 96c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 97c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (cache->anyPolicy) 98c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 99c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ret = -1; 100c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_policy; 101c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 102c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org cache->anyPolicy = data; 103c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 104c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org else if (sk_X509_POLICY_DATA_find(cache->data, data) != -1) 105c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 106c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ret = -1; 107c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_policy; 108c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 109c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org else if (!sk_X509_POLICY_DATA_push(cache->data, data)) 110c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_policy; 111c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org data = NULL; 112c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 113c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ret = 1; 114c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org bad_policy: 115c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (ret == -1) 116c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org x->ex_flags |= EXFLAG_INVALID_POLICY; 117c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (data) 118c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org policy_data_free(data); 119c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org sk_POLICYINFO_pop_free(policies, POLICYINFO_free); 120c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (ret <= 0) 121c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 122c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org sk_X509_POLICY_DATA_pop_free(cache->data, policy_data_free); 123c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org cache->data = NULL; 124c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 125c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return ret; 126c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 127c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 128c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 129c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgstatic int policy_cache_new(X509 *x) 130c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 131c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org X509_POLICY_CACHE *cache; 132c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ASN1_INTEGER *ext_any = NULL; 133c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org POLICY_CONSTRAINTS *ext_pcons = NULL; 134c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org CERTIFICATEPOLICIES *ext_cpols = NULL; 135c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org POLICY_MAPPINGS *ext_pmaps = NULL; 136c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org int i; 137c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org cache = OPENSSL_malloc(sizeof(X509_POLICY_CACHE)); 138c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!cache) 139c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return 0; 140c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org cache->anyPolicy = NULL; 141c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org cache->data = NULL; 142c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org cache->any_skip = -1; 143c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org cache->explicit_skip = -1; 144c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org cache->map_skip = -1; 145c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 146c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org x->policy_cache = cache; 147c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 148c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org /* Handle requireExplicitPolicy *first*. Need to process this 149c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * even if we don't have any policies. 150c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org */ 151c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ext_pcons = X509_get_ext_d2i(x, NID_policy_constraints, &i, NULL); 152c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 153c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!ext_pcons) 154c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 155c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (i != -1) 156c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_cache; 157c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 158c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org else 159c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 160c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!ext_pcons->requireExplicitPolicy 161c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org && !ext_pcons->inhibitPolicyMapping) 162c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_cache; 163c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!policy_cache_set_int(&cache->explicit_skip, 164c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ext_pcons->requireExplicitPolicy)) 165c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_cache; 166c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!policy_cache_set_int(&cache->map_skip, 167c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ext_pcons->inhibitPolicyMapping)) 168c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_cache; 169c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 170c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 171c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org /* Process CertificatePolicies */ 172c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 173c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ext_cpols = X509_get_ext_d2i(x, NID_certificate_policies, &i, NULL); 174c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org /* If no CertificatePolicies extension or problem decoding then 175c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * there is no point continuing because the valid policies will be 176c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * NULL. 177c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org */ 178c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!ext_cpols) 179c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 180c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org /* If not absent some problem with extension */ 181c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (i != -1) 182c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_cache; 183c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return 1; 184c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 185c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 186c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org i = policy_cache_create(x, ext_cpols, i); 187c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 188c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org /* NB: ext_cpols freed by policy_cache_set_policies */ 189c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 190c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (i <= 0) 191c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return i; 192c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 193c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ext_pmaps = X509_get_ext_d2i(x, NID_policy_mappings, &i, NULL); 194c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 195c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!ext_pmaps) 196c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 197c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org /* If not absent some problem with extension */ 198c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (i != -1) 199c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_cache; 200c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 201c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org else 202c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 203c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org i = policy_cache_set_mapping(x, ext_pmaps); 204c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (i <= 0) 205c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_cache; 206c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 207c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 208c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ext_any = X509_get_ext_d2i(x, NID_inhibit_any_policy, &i, NULL); 209c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 210c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!ext_any) 211c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 212c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (i != -1) 213c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_cache; 214c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 215c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org else if (!policy_cache_set_int(&cache->any_skip, ext_any)) 216c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org goto bad_cache; 217c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 218c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (0) 219c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 220c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org bad_cache: 221c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org x->ex_flags |= EXFLAG_INVALID_POLICY; 222c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 223c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 224c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if(ext_pcons) 225c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org POLICY_CONSTRAINTS_free(ext_pcons); 226c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 227c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (ext_any) 228c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org ASN1_INTEGER_free(ext_any); 229c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 230c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return 1; 231c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 232c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 233c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org} 234c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 235c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgvoid policy_cache_free(X509_POLICY_CACHE *cache) 236c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 237c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (!cache) 238c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return; 239c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (cache->anyPolicy) 240c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org policy_data_free(cache->anyPolicy); 241c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (cache->data) 242c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org sk_X509_POLICY_DATA_pop_free(cache->data, policy_data_free); 243c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org OPENSSL_free(cache); 244c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 245c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 246c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgconst X509_POLICY_CACHE *policy_cache_set(X509 *x) 247c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 248c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 249c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (x->policy_cache == NULL) 250c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 251c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org CRYPTO_w_lock(CRYPTO_LOCK_X509); 252c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org policy_cache_new(x); 253c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org CRYPTO_w_unlock(CRYPTO_LOCK_X509); 254c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 255c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 256c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return x->policy_cache; 257c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 258c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 259c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 260c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgX509_POLICY_DATA *policy_cache_find_data(const X509_POLICY_CACHE *cache, 261c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org const ASN1_OBJECT *id) 262c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 263c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org int idx; 264c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org X509_POLICY_DATA tmp; 265c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org tmp.valid_policy = (ASN1_OBJECT *)id; 266c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org idx = sk_X509_POLICY_DATA_find(cache->data, &tmp); 267c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (idx == -1) 268c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return NULL; 269c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return sk_X509_POLICY_DATA_value(cache->data, idx); 270c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 271c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 272c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgstatic int policy_data_cmp(const X509_POLICY_DATA * const *a, 273c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org const X509_POLICY_DATA * const *b) 274c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 275c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return OBJ_cmp((*a)->valid_policy, (*b)->valid_policy); 276c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 277c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org 278c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgstatic int policy_cache_set_int(long *out, ASN1_INTEGER *value) 279c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org { 280c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (value == NULL) 281c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return 1; 282c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org if (value->type == V_ASN1_NEG_INTEGER) 283c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return 0; 284c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *out = ASN1_INTEGER_get(value); 285c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org return 1; 286c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org } 287