1c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org/* crypto/x509/x509_v3.c */
2c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
3c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * All rights reserved.
4c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *
5c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * This package is an SSL implementation written
6c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * by Eric Young (eay@cryptsoft.com).
7c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * The implementation was written so as to conform with Netscapes SSL.
8c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *
9c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * This library is free for commercial and non-commercial use as long as
10c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * the following conditions are aheared to.  The following conditions
11c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * apply to all code found in this distribution, be it the RC4, RSA,
12c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * lhash, DES, etc., code; not just the SSL code.  The SSL documentation
13c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * included with this distribution is covered by the same copyright terms
14c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * except that the holder is Tim Hudson (tjh@cryptsoft.com).
15c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *
16c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * Copyright remains Eric Young's, and as such any Copyright notices in
17c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * the code are not to be removed.
18c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * If this package is used in a product, Eric Young should be given attribution
19c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * as the author of the parts of the library used.
20c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * This can be in the form of a textual message at program startup or
21c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * in documentation (online or textual) provided with the package.
22c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *
23c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * Redistribution and use in source and binary forms, with or without
24c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * modification, are permitted provided that the following conditions
25c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * are met:
26c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 1. Redistributions of source code must retain the copyright
27c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *    notice, this list of conditions and the following disclaimer.
28c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 2. Redistributions in binary form must reproduce the above copyright
29c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *    notice, this list of conditions and the following disclaimer in the
30c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *    documentation and/or other materials provided with the distribution.
31c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 3. All advertising materials mentioning features or use of this software
32c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *    must display the following acknowledgement:
33c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *    "This product includes cryptographic software written by
34c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *     Eric Young (eay@cryptsoft.com)"
35c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *    The word 'cryptographic' can be left out if the rouines from the library
36c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *    being used are not cryptographic related :-).
37c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * 4. If you include any Windows specific code (or a derivative thereof) from
38c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *    the apps directory (application code) you must include an acknowledgement:
39c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
40c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *
41c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
42c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
43c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
44c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
45c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
46c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
47c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
48c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
49c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
50c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
51c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * SUCH DAMAGE.
52c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org *
53c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * The licence and distribution terms for any publically available version or
54c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * derivative of this code cannot be changed.  i.e. this code cannot simply be
55c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * copied and put under another distribution licence
56c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org * [including the GNU Public Licence.]
57c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org */
58c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
59c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include <stdio.h>
60c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include <openssl/stack.h>
61c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include "cryptlib.h"
62c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include <openssl/asn1.h>
63c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include <openssl/objects.h>
64c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include <openssl/evp.h>
65c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include <openssl/x509.h>
66c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org#include <openssl/x509v3.h>
67c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
68c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgint X509v3_get_ext_count(const STACK_OF(X509_EXTENSION) *x)
69c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
70c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (x == NULL) return(0);
71c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(sk_X509_EXTENSION_num(x));
72c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
73c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
74c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgint X509v3_get_ext_by_NID(const STACK_OF(X509_EXTENSION) *x, int nid,
75c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			  int lastpos)
76c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
77c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	ASN1_OBJECT *obj;
78c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
79c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	obj=OBJ_nid2obj(nid);
80c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (obj == NULL) return(-2);
81c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(X509v3_get_ext_by_OBJ(x,obj,lastpos));
82c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
83c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
84c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgint X509v3_get_ext_by_OBJ(const STACK_OF(X509_EXTENSION) *sk, ASN1_OBJECT *obj,
85c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			  int lastpos)
86c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
87c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	int n;
88c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	X509_EXTENSION *ex;
89c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
90c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (sk == NULL) return(-1);
91c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	lastpos++;
92c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (lastpos < 0)
93c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		lastpos=0;
94c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	n=sk_X509_EXTENSION_num(sk);
95c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	for ( ; lastpos < n; lastpos++)
96c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		{
97c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		ex=sk_X509_EXTENSION_value(sk,lastpos);
98c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		if (OBJ_cmp(ex->object,obj) == 0)
99c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			return(lastpos);
100c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		}
101c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(-1);
102c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
103c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
104c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgint X509v3_get_ext_by_critical(const STACK_OF(X509_EXTENSION) *sk, int crit,
105c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			       int lastpos)
106c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
107c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	int n;
108c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	X509_EXTENSION *ex;
109c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
110c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (sk == NULL) return(-1);
111c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	lastpos++;
112c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (lastpos < 0)
113c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		lastpos=0;
114c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	n=sk_X509_EXTENSION_num(sk);
115c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	for ( ; lastpos < n; lastpos++)
116c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		{
117c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		ex=sk_X509_EXTENSION_value(sk,lastpos);
118c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		if (	((ex->critical > 0) && crit) ||
119c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			((ex->critical <= 0) && !crit))
120c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			return(lastpos);
121c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		}
122c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(-1);
123c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
124c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
125c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgX509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc)
126c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
127c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (x == NULL || sk_X509_EXTENSION_num(x) <= loc || loc < 0)
128c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		return NULL;
129c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	else
130c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		return sk_X509_EXTENSION_value(x,loc);
131c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
132c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
133c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgX509_EXTENSION *X509v3_delete_ext(STACK_OF(X509_EXTENSION) *x, int loc)
134c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
135c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	X509_EXTENSION *ret;
136c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
137c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (x == NULL || sk_X509_EXTENSION_num(x) <= loc || loc < 0)
138c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		return(NULL);
139c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	ret=sk_X509_EXTENSION_delete(x,loc);
140c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(ret);
141c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
142c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
143c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgSTACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x,
144c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org					 X509_EXTENSION *ex, int loc)
145c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
146c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	X509_EXTENSION *new_ex=NULL;
147c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	int n;
148c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	STACK_OF(X509_EXTENSION) *sk=NULL;
149c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
150c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (x == NULL)
151c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		{
152c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		X509err(X509_F_X509V3_ADD_EXT,ERR_R_PASSED_NULL_PARAMETER);
153c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		goto err2;
154c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		}
155c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
156c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (*x == NULL)
157c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		{
158c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		if ((sk=sk_X509_EXTENSION_new_null()) == NULL)
159c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			goto err;
160c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		}
161c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	else
162c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		sk= *x;
163c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
164c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	n=sk_X509_EXTENSION_num(sk);
165c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (loc > n) loc=n;
166c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	else if (loc < 0) loc=n;
167c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
168c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if ((new_ex=X509_EXTENSION_dup(ex)) == NULL)
169c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		goto err2;
170c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (!sk_X509_EXTENSION_insert(sk,new_ex,loc))
171c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		goto err;
172c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (*x == NULL)
173c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		*x=sk;
174c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(sk);
175c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgerr:
176c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	X509err(X509_F_X509V3_ADD_EXT,ERR_R_MALLOC_FAILURE);
177c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgerr2:
178c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (new_ex != NULL) X509_EXTENSION_free(new_ex);
179c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (sk != NULL) sk_X509_EXTENSION_free(sk);
180c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(NULL);
181c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
182c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
183c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgX509_EXTENSION *X509_EXTENSION_create_by_NID(X509_EXTENSION **ex, int nid,
184c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	     int crit, ASN1_OCTET_STRING *data)
185c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
186c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	ASN1_OBJECT *obj;
187c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	X509_EXTENSION *ret;
188c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
189c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	obj=OBJ_nid2obj(nid);
190c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (obj == NULL)
191c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		{
192c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		X509err(X509_F_X509_EXTENSION_CREATE_BY_NID,X509_R_UNKNOWN_NID);
193c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		return(NULL);
194c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		}
195c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	ret=X509_EXTENSION_create_by_OBJ(ex,obj,crit,data);
196c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (ret == NULL) ASN1_OBJECT_free(obj);
197c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(ret);
198c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
199c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
200c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgX509_EXTENSION *X509_EXTENSION_create_by_OBJ(X509_EXTENSION **ex,
201c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	     ASN1_OBJECT *obj, int crit, ASN1_OCTET_STRING *data)
202c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
203c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	X509_EXTENSION *ret;
204c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
205c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if ((ex == NULL) || (*ex == NULL))
206c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		{
207c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		if ((ret=X509_EXTENSION_new()) == NULL)
208c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			{
209c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			X509err(X509_F_X509_EXTENSION_CREATE_BY_OBJ,ERR_R_MALLOC_FAILURE);
210c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			return(NULL);
211c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org			}
212c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		}
213c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	else
214c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		ret= *ex;
215c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
216c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (!X509_EXTENSION_set_object(ret,obj))
217c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		goto err;
218c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (!X509_EXTENSION_set_critical(ret,crit))
219c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		goto err;
220c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (!X509_EXTENSION_set_data(ret,data))
221c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		goto err;
222c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
223c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if ((ex != NULL) && (*ex == NULL)) *ex=ret;
224c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(ret);
225c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgerr:
226c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if ((ex == NULL) || (ret != *ex))
227c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		X509_EXTENSION_free(ret);
228c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(NULL);
229c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
230c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
231c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgint X509_EXTENSION_set_object(X509_EXTENSION *ex, ASN1_OBJECT *obj)
232c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
233c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if ((ex == NULL) || (obj == NULL))
234c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org		return(0);
235c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	ASN1_OBJECT_free(ex->object);
236c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	ex->object=OBJ_dup(obj);
237c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(1);
238c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
239c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
240c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgint X509_EXTENSION_set_critical(X509_EXTENSION *ex, int crit)
241c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
242c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (ex == NULL) return(0);
243c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	ex->critical=(crit)?0xFF:-1;
244c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(1);
245c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
246c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
247c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgint X509_EXTENSION_set_data(X509_EXTENSION *ex, ASN1_OCTET_STRING *data)
248c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
249c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	int i;
250c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
251c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (ex == NULL) return(0);
252c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	i=M_ASN1_OCTET_STRING_set(ex->value,data->data,data->length);
253c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (!i) return(0);
254c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(1);
255c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
256c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
257c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgASN1_OBJECT *X509_EXTENSION_get_object(X509_EXTENSION *ex)
258c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
259c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (ex == NULL) return(NULL);
260c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(ex->object);
261c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
262c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
263c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgASN1_OCTET_STRING *X509_EXTENSION_get_data(X509_EXTENSION *ex)
264c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
265c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (ex == NULL) return(NULL);
266c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return(ex->value);
267c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
268c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org
269c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.orgint X509_EXTENSION_get_critical(X509_EXTENSION *ex)
270c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	{
271c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if (ex == NULL) return(0);
272c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	if(ex->critical > 0) return 1;
273c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	return 0;
274c9490d33b98b7affb729b5f1db13cb0a348471aagl@chromium.org	}
275