1656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* crypto/pkcs7/verify.c */ 2656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) 3656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * All rights reserved. 4656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 5656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * This package is an SSL implementation written 6656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * by Eric Young (eay@cryptsoft.com). 7656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * The implementation was written so as to conform with Netscapes SSL. 8656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 9656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * This library is free for commercial and non-commercial use as long as 10656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * the following conditions are aheared to. The following conditions 11656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * apply to all code found in this distribution, be it the RC4, RSA, 12656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * lhash, DES, etc., code; not just the SSL code. The SSL documentation 13656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * included with this distribution is covered by the same copyright terms 14656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * except that the holder is Tim Hudson (tjh@cryptsoft.com). 15656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 16656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * Copyright remains Eric Young's, and as such any Copyright notices in 17656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * the code are not to be removed. 18656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * If this package is used in a product, Eric Young should be given attribution 19656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * as the author of the parts of the library used. 20656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * This can be in the form of a textual message at program startup or 21656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * in documentation (online or textual) provided with the package. 22656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 23656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * Redistribution and use in source and binary forms, with or without 24656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * modification, are permitted provided that the following conditions 25656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * are met: 26656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 1. Redistributions of source code must retain the copyright 27656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * notice, this list of conditions and the following disclaimer. 28656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 2. Redistributions in binary form must reproduce the above copyright 29656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * notice, this list of conditions and the following disclaimer in the 30656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * documentation and/or other materials provided with the distribution. 31656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 3. All advertising materials mentioning features or use of this software 32656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * must display the following acknowledgement: 33656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * "This product includes cryptographic software written by 34656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * Eric Young (eay@cryptsoft.com)" 35656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * The word 'cryptographic' can be left out if the rouines from the library 36656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * being used are not cryptographic related :-). 37656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 4. If you include any Windows specific code (or a derivative thereof) from 38656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * the apps directory (application code) you must include an acknowledgement: 39656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" 40656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 41656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND 42656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 43656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 44656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 45656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 46656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 47656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 48656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 49656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 50656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 51656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * SUCH DAMAGE. 52656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * 53656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * The licence and distribution terms for any publically available version or 54656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * derivative of this code cannot be changed. i.e. this code cannot simply be 55656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * copied and put under another distribution licence 56656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * [including the GNU Public Licence.] 57656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project */ 58656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <stdio.h> 59656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <string.h> 60656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/bio.h> 61656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/asn1.h> 62656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/x509.h> 63656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/pem.h> 64656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include <openssl/err.h> 65656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#include "example.h" 66656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 67656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint verify_callback(int ok, X509_STORE_CTX *ctx); 68656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 69656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source ProjectBIO *bio_err=NULL; 70656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source ProjectBIO *bio_out=NULL; 71656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 72656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint main(argc,argv) 73656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint argc; 74656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectchar *argv[]; 75656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 76656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project PKCS7 *p7; 77656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project PKCS7_SIGNER_INFO *si; 78656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_STORE_CTX cert_ctx; 79656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_STORE *cert_store=NULL; 80656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO *data,*detached=NULL,*p7bio=NULL; 81656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project char buf[1024*4]; 82656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project char *pp; 83656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int i,printit=0; 84656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project STACK_OF(PKCS7_SIGNER_INFO) *sk; 85656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 86656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project bio_err=BIO_new_fp(stderr,BIO_NOCLOSE); 87656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project bio_out=BIO_new_fp(stdout,BIO_NOCLOSE); 88656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#ifndef OPENSSL_NO_MD2 89656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project EVP_add_digest(EVP_md2()); 90656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#endif 91656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#ifndef OPENSSL_NO_MD5 92656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project EVP_add_digest(EVP_md5()); 93656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#endif 94656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#ifndef OPENSSL_NO_SHA1 95656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project EVP_add_digest(EVP_sha1()); 96656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#endif 97656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#ifndef OPENSSL_NO_MDC2 98656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project EVP_add_digest(EVP_mdc2()); 99656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project#endif 100656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 101656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project data=BIO_new(BIO_s_file()); 102656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 103656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project pp=NULL; 104656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project while (argc > 1) 105656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 106656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project argc--; 107656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project argv++; 108656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (strcmp(argv[0],"-p") == 0) 109656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 110656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project printit=1; 111656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 112656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project else if ((strcmp(argv[0],"-d") == 0) && (argc >= 2)) 113656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 114656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project detached=BIO_new(BIO_s_file()); 115656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BIO_read_filename(detached,argv[1])) 116656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 117656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project argc--; 118656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project argv++; 119656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 120656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project else 121656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 122656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project pp=argv[0]; 123656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!BIO_read_filename(data,argv[0])) 124656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 125656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 126656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 127656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 128656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (pp == NULL) 129656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_set_fp(data,stdin,BIO_NOCLOSE); 130656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 131656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 132656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* Load the PKCS7 object from a file */ 133656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if ((p7=PEM_read_bio_PKCS7(data,NULL,NULL,NULL)) == NULL) goto err; 134656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 135656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* This stuff is being setup for certificate verification. 136656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * When using SSL, it could be replaced with a 137656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project * cert_stre=SSL_CTX_get_cert_store(ssl_ctx); */ 138656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project cert_store=X509_STORE_new(); 139656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_STORE_set_default_paths(cert_store); 140656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_STORE_load_locations(cert_store,NULL,"../../certs"); 141656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_STORE_set_verify_cb_func(cert_store,verify_callback); 142656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 143656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ERR_clear_error(); 144656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 145656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* We need to process the data */ 146656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if ((PKCS7_get_detached(p7) || detached)) 147656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 148656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (detached == NULL) 149656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 150656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project printf("no data to verify the signature on\n"); 151656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project exit(1); 152656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 153656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project else 154656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project p7bio=PKCS7_dataInit(p7,detached); 155656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 156656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project else 157656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 158656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project p7bio=PKCS7_dataInit(p7,NULL); 159656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 160656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 161656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* We now have to 'read' from p7bio to calculate digests etc. */ 162656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project for (;;) 163656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 164656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project i=BIO_read(p7bio,buf,sizeof(buf)); 165656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* print it? */ 166656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (i <= 0) break; 167656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 168656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 169656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* We can now verify signatures */ 170656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project sk=PKCS7_get_signer_info(p7); 171656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (sk == NULL) 172656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 173656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project printf("there are no signatures on this data\n"); 174656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project exit(1); 175656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 176656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 177656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project /* Ok, first we need to, for each subject entry, see if we can verify */ 178656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project for (i=0; i<sk_PKCS7_SIGNER_INFO_num(sk); i++) 179656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 180656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ASN1_UTCTIME *tm; 181656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project char *str1,*str2; 182656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int rc; 183656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 184656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project si=sk_PKCS7_SIGNER_INFO_value(sk,i); 185656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project rc=PKCS7_dataVerify(cert_store,&cert_ctx,p7bio,p7,si); 186656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (rc <= 0) 187656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project goto err; 188656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project printf("signer info\n"); 189656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if ((tm=get_signed_time(si)) != NULL) 190656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 191656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_out,"Signed time:"); 192656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ASN1_UTCTIME_print(bio_out,tm); 193656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ASN1_UTCTIME_free(tm); 194656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_out,"\n"); 195656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 196656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (get_signed_seq2string(si,&str1,&str2)) 197656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 198656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_out,"String 1 is %s\n",str1); 199656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_out,"String 2 is %s\n",str2); 200656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 201656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 202656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 203656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 204656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_STORE_free(cert_store); 205656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 206656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project printf("done\n"); 207656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project exit(0); 208656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projecterr: 209656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ERR_load_crypto_strings(); 210656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ERR_print_errors_fp(stderr); 211656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project exit(1); 212656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 213656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 214656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project/* should be X509 * but we can just have them as char *. */ 215656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Projectint verify_callback(int ok, X509_STORE_CTX *ctx) 216656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 217656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project char buf[256]; 218656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509 *err_cert; 219656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project int err,depth; 220656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 221656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project err_cert=X509_STORE_CTX_get_current_cert(ctx); 222656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project err= X509_STORE_CTX_get_error(ctx); 223656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project depth= X509_STORE_CTX_get_error_depth(ctx); 224656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project 225656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_NAME_oneline(X509_get_subject_name(err_cert),buf,256); 226656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_err,"depth=%d %s\n",depth,buf); 227656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (!ok) 228656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 229656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_err,"verify error:num=%d:%s\n",err, 230656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_verify_cert_error_string(err)); 231656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project if (depth < 6) 232656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 233656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ok=1; 234656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_STORE_CTX_set_error(ctx,X509_V_OK); 235656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 236656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project else 237656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 238656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ok=0; 239656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_STORE_CTX_set_error(ctx,X509_V_ERR_CERT_CHAIN_TOO_LONG); 240656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 241656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 242656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project switch (ctx->error) 243656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project { 244656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project case X509_V_ERR_UNABLE_TO_GET_ISSUER_CERT: 245656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project X509_NAME_oneline(X509_get_issuer_name(ctx->current_cert),buf,256); 246656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_err,"issuer= %s\n",buf); 247656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project break; 248656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project case X509_V_ERR_CERT_NOT_YET_VALID: 249656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project case X509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD: 250656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_err,"notBefore="); 251656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ASN1_UTCTIME_print(bio_err,X509_get_notBefore(ctx->current_cert)); 252656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_err,"\n"); 253656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project break; 254656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project case X509_V_ERR_CERT_HAS_EXPIRED: 255656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project case X509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD: 256656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_err,"notAfter="); 257656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project ASN1_UTCTIME_print(bio_err,X509_get_notAfter(ctx->current_cert)); 258656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_err,"\n"); 259656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project break; 260656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 261656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project BIO_printf(bio_err,"verify return:%d\n",ok); 262656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project return(ok); 263656d9c7f52f88b3a3daccafa7655dec086c4756eThe Android Open Source Project } 264