]> git.ipfire.org Git - thirdparty/openssl.git/blame - crypto/pkcs12/p12_crt.c
Allow PKCS12 export to set arbitrary bag attributes
[thirdparty/openssl.git] / crypto / pkcs12 / p12_crt.c
CommitLineData
0f113f3e 1/*
8020d79b 2 * Copyright 1999-2021 The OpenSSL Project Authors. All Rights Reserved.
8d8c7266 3 *
54fffdf4 4 * Licensed under the Apache License 2.0 (the "License"). You may not use
b1322259
RS
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
8d8c7266
DSH
8 */
9
10#include <stdio.h>
b39fc560 11#include "internal/cryptlib.h"
ec577822 12#include <openssl/pkcs12.h>
706457b7 13#include "p12_local.h"
8d8c7266 14
0f113f3e
MC
15static int pkcs12_add_bag(STACK_OF(PKCS12_SAFEBAG) **pbags,
16 PKCS12_SAFEBAG *bag);
e869c867
GW
17static int pkcs12_remove_bag(STACK_OF(PKCS12_SAFEBAG) **pbags,
18 PKCS12_SAFEBAG *bag);
9a48b07e 19
8528128b 20static int copy_bag_attr(PKCS12_SAFEBAG *bag, EVP_PKEY *pkey, int nid)
0f113f3e 21{
ba9e3721
DDO
22 int idx = EVP_PKEY_get_attr_by_NID(pkey, nid, -1);
23
0f113f3e
MC
24 if (idx < 0)
25 return 1;
ba9e3721 26 return X509at_add1_attr(&bag->attrib, EVP_PKEY_get_attr(pkey, idx)) != NULL;
0f113f3e 27}
8528128b 28
e869c867
GW
29PKCS12 *PKCS12_create_ex2(const char *pass, const char *name, EVP_PKEY *pkey,
30 X509 *cert, STACK_OF(X509) *ca, int nid_key, int nid_cert,
31 int iter, int mac_iter, int keytype,
32 OSSL_LIB_CTX *ctx, const char *propq,
33 PKCS12_create_cb *cb, void *cbarg)
8d8c7266 34{
0f113f3e
MC
35 PKCS12 *p12 = NULL;
36 STACK_OF(PKCS7) *safes = NULL;
37 STACK_OF(PKCS12_SAFEBAG) *bags = NULL;
38 PKCS12_SAFEBAG *bag = NULL;
e869c867 39 int i, cbret;
0f113f3e
MC
40 unsigned char keyid[EVP_MAX_MD_SIZE];
41 unsigned int keyidlen = 0;
42
43 /* Set defaults */
762970bd
TM
44 if (nid_cert == NID_undef)
45 nid_cert = NID_aes_256_cbc;
46 if (nid_key == NID_undef)
47 nid_key = NID_aes_256_cbc;
0f113f3e
MC
48 if (!iter)
49 iter = PKCS12_DEFAULT_ITER;
50 if (!mac_iter)
762970bd 51 mac_iter = PKCS12_DEFAULT_ITER;
0f113f3e 52
12a765a5 53 if (pkey == NULL && cert == NULL && ca == NULL) {
9311d0c4 54 ERR_raise(ERR_LIB_PKCS12, PKCS12_R_INVALID_NULL_ARGUMENT);
0f113f3e
MC
55 return NULL;
56 }
57
58 if (pkey && cert) {
59 if (!X509_check_private_key(cert, pkey))
60 return NULL;
7e06a675
BE
61 if (!X509_digest(cert, EVP_sha1(), keyid, &keyidlen))
62 return NULL;
0f113f3e
MC
63 }
64
65 if (cert) {
66 bag = PKCS12_add_cert(&bags, cert);
67 if (name && !PKCS12_add_friendlyname(bag, name, -1))
68 goto err;
69 if (keyidlen && !PKCS12_add_localkeyid(bag, keyid, keyidlen))
70 goto err;
e869c867
GW
71 if (cb != NULL) {
72 cbret = cb(bag, cbarg);
73 if (cbret == -1) {
74 ERR_raise(ERR_LIB_PKCS12, PKCS12_R_CALLBACK_FAILED);
75 goto err;
76 } else if (cbret == 0) {
77 pkcs12_remove_bag(&bags, bag);
78 }
79 }
0f113f3e
MC
80 }
81
82 /* Add all other certificates */
83 for (i = 0; i < sk_X509_num(ca); i++) {
e869c867 84 if ((bag = PKCS12_add_cert(&bags, sk_X509_value(ca, i))) == NULL)
0f113f3e 85 goto err;
e869c867
GW
86 if (cb != NULL) {
87 cbret = cb(bag, cbarg);
88 if (cbret == -1) {
89 ERR_raise(ERR_LIB_PKCS12, PKCS12_R_CALLBACK_FAILED);
90 goto err;
91 } else if (cbret == 0) {
92 pkcs12_remove_bag(&bags, bag);
93 }
94 }
0f113f3e
MC
95 }
96
b536880c
JS
97 if (bags && !PKCS12_add_safe_ex(&safes, bags, nid_cert, iter, pass,
98 ctx, propq))
0f113f3e
MC
99 goto err;
100
101 sk_PKCS12_SAFEBAG_pop_free(bags, PKCS12_SAFEBAG_free);
102 bags = NULL;
103
104 if (pkey) {
b536880c
JS
105 bag = PKCS12_add_key_ex(&bags, pkey, keytype, iter, nid_key, pass,
106 ctx, propq);
0f113f3e
MC
107
108 if (!bag)
109 goto err;
110
111 if (!copy_bag_attr(bag, pkey, NID_ms_csp_name))
112 goto err;
113 if (!copy_bag_attr(bag, pkey, NID_LocalKeySet))
114 goto err;
115
116 if (name && !PKCS12_add_friendlyname(bag, name, -1))
117 goto err;
118 if (keyidlen && !PKCS12_add_localkeyid(bag, keyid, keyidlen))
119 goto err;
e869c867
GW
120 if (cb != NULL) {
121 cbret = cb(bag, cbarg);
122 if (cbret == -1) {
123 ERR_raise(ERR_LIB_PKCS12, PKCS12_R_CALLBACK_FAILED);
124 goto err;
125 } else if (cbret == 0) {
126 pkcs12_remove_bag(&bags, bag);
127 }
128 }
0f113f3e
MC
129 }
130
131 if (bags && !PKCS12_add_safe(&safes, bags, -1, 0, NULL))
132 goto err;
133
134 sk_PKCS12_SAFEBAG_pop_free(bags, PKCS12_SAFEBAG_free);
135 bags = NULL;
136
b536880c 137 p12 = PKCS12_add_safes_ex(safes, 0, ctx, propq);
0f113f3e 138
12a765a5 139 if (p12 == NULL)
0f113f3e
MC
140 goto err;
141
142 sk_PKCS7_pop_free(safes, PKCS7_free);
143
144 safes = NULL;
145
146 if ((mac_iter != -1) &&
147 !PKCS12_set_mac(p12, pass, -1, NULL, 0, mac_iter, NULL))
148 goto err;
149
150 return p12;
151
152 err:
e0e920b1
RS
153 PKCS12_free(p12);
154 sk_PKCS7_pop_free(safes, PKCS7_free);
155 sk_PKCS12_SAFEBAG_pop_free(bags, PKCS12_SAFEBAG_free);
0f113f3e 156 return NULL;
9a48b07e
DSH
157
158}
159
e869c867
GW
160PKCS12 *PKCS12_create_ex(const char *pass, const char *name, EVP_PKEY *pkey, X509 *cert,
161 STACK_OF(X509) *ca, int nid_key, int nid_cert, int iter,
162 int mac_iter, int keytype,
163 OSSL_LIB_CTX *ctx, const char *propq)
164{
165 return PKCS12_create_ex2(pass, name, pkey, cert, ca, nid_key, nid_cert,
166 iter, mac_iter, keytype, ctx, propq,
167 NULL, NULL);
168}
169
b536880c
JS
170PKCS12 *PKCS12_create(const char *pass, const char *name, EVP_PKEY *pkey, X509 *cert,
171 STACK_OF(X509) *ca, int nid_key, int nid_cert, int iter,
172 int mac_iter, int keytype)
173{
174 return PKCS12_create_ex(pass, name, pkey, cert, ca, nid_key, nid_cert,
175 iter, mac_iter, keytype, NULL, NULL);
176}
177
9a48b07e 178PKCS12_SAFEBAG *PKCS12_add_cert(STACK_OF(PKCS12_SAFEBAG) **pbags, X509 *cert)
0f113f3e
MC
179{
180 PKCS12_SAFEBAG *bag = NULL;
181 char *name;
182 int namelen = -1;
183 unsigned char *keyid;
184 int keyidlen = -1;
8d8c7266 185
0f113f3e 186 /* Add user certificate */
293042c9 187 if ((bag = PKCS12_SAFEBAG_create_cert(cert)) == NULL)
0f113f3e 188 goto err;
9a48b07e 189
0f113f3e
MC
190 /*
191 * Use friendlyName and localKeyID in certificate. (if present)
192 */
9a48b07e 193
0f113f3e 194 name = (char *)X509_alias_get0(cert, &namelen);
9a48b07e 195
0f113f3e
MC
196 if (name && !PKCS12_add_friendlyname(bag, name, namelen))
197 goto err;
9a48b07e 198
0f113f3e 199 keyid = X509_keyid_get0(cert, &keyidlen);
9a48b07e 200
0f113f3e
MC
201 if (keyid && !PKCS12_add_localkeyid(bag, keyid, keyidlen))
202 goto err;
9a48b07e 203
0f113f3e
MC
204 if (!pkcs12_add_bag(pbags, bag))
205 goto err;
9a48b07e 206
0f113f3e 207 return bag;
9a48b07e 208
0f113f3e 209 err:
e0e920b1 210 PKCS12_SAFEBAG_free(bag);
0f113f3e 211 return NULL;
8d8c7266 212
0f113f3e 213}
9a48b07e 214
b536880c
JS
215PKCS12_SAFEBAG *PKCS12_add_key_ex(STACK_OF(PKCS12_SAFEBAG) **pbags,
216 EVP_PKEY *key, int key_usage, int iter,
217 int nid_key, const char *pass,
218 OSSL_LIB_CTX *ctx, const char *propq)
0f113f3e 219{
9a48b07e 220
0f113f3e
MC
221 PKCS12_SAFEBAG *bag = NULL;
222 PKCS8_PRIV_KEY_INFO *p8 = NULL;
9a48b07e 223
0f113f3e 224 /* Make a PKCS#8 structure */
75ebbd9a 225 if ((p8 = EVP_PKEY2PKCS8(key)) == NULL)
0f113f3e
MC
226 goto err;
227 if (key_usage && !PKCS8_add_keyusage(p8, key_usage))
228 goto err;
229 if (nid_key != -1) {
b536880c
JS
230 bag = PKCS12_SAFEBAG_create_pkcs8_encrypt_ex(nid_key, pass, -1, NULL, 0,
231 iter, p8, ctx, propq);
0f113f3e
MC
232 PKCS8_PRIV_KEY_INFO_free(p8);
233 } else
425f3300 234 bag = PKCS12_SAFEBAG_create0_p8inf(p8);
9a48b07e 235
0f113f3e
MC
236 if (!bag)
237 goto err;
9a48b07e 238
0f113f3e
MC
239 if (!pkcs12_add_bag(pbags, bag))
240 goto err;
9a48b07e 241
0f113f3e 242 return bag;
9a48b07e 243
0f113f3e 244 err:
e0e920b1 245 PKCS12_SAFEBAG_free(bag);
0f113f3e 246 return NULL;
9a48b07e 247
0f113f3e 248}
8d8c7266 249
b536880c
JS
250PKCS12_SAFEBAG *PKCS12_add_key(STACK_OF(PKCS12_SAFEBAG) **pbags,
251 EVP_PKEY *key, int key_usage, int iter,
252 int nid_key, const char *pass)
253{
254 return PKCS12_add_key_ex(pbags, key, key_usage, iter, nid_key, pass,
255 NULL, NULL);
256}
257
c5ec6dcf
JS
258PKCS12_SAFEBAG *PKCS12_add_secret(STACK_OF(PKCS12_SAFEBAG) **pbags,
259 int nid_type, const unsigned char *value, int len)
260{
261 PKCS12_SAFEBAG *bag = NULL;
262
263 /* Add secret, storing the value as an octet string */
264 if ((bag = PKCS12_SAFEBAG_create_secret(nid_type, V_ASN1_OCTET_STRING, value, len)) == NULL)
265 goto err;
266
267 if (!pkcs12_add_bag(pbags, bag))
268 goto err;
269
270 return bag;
271 err:
272 PKCS12_SAFEBAG_free(bag);
273 return NULL;
274}
275
b536880c
JS
276int PKCS12_add_safe_ex(STACK_OF(PKCS7) **psafes, STACK_OF(PKCS12_SAFEBAG) *bags,
277 int nid_safe, int iter, const char *pass,
278 OSSL_LIB_CTX *ctx, const char *propq)
0f113f3e
MC
279{
280 PKCS7 *p7 = NULL;
281 int free_safes = 0;
282
12a765a5 283 if (*psafes == NULL) {
0f113f3e 284 *psafes = sk_PKCS7_new_null();
12a765a5 285 if (*psafes == NULL)
0f113f3e
MC
286 return 0;
287 free_safes = 1;
12a765a5 288 }
0f113f3e
MC
289
290 if (nid_safe == 0)
558c94ef 291#ifdef OPENSSL_NO_RC2
0f113f3e 292 nid_safe = NID_pbe_WithSHA1And3_Key_TripleDES_CBC;
558c94ef 293#else
0f113f3e 294 nid_safe = NID_pbe_WithSHA1And40BitRC2_CBC;
558c94ef 295#endif
9a48b07e 296
0f113f3e
MC
297 if (nid_safe == -1)
298 p7 = PKCS12_pack_p7data(bags);
299 else
b536880c 300 p7 = PKCS12_pack_p7encdata_ex(nid_safe, pass, -1, NULL, 0, iter, bags, ctx, propq);
12a765a5 301 if (p7 == NULL)
0f113f3e
MC
302 goto err;
303
304 if (!sk_PKCS7_push(*psafes, p7))
305 goto err;
306
307 return 1;
308
309 err:
310 if (free_safes) {
311 sk_PKCS7_free(*psafes);
312 *psafes = NULL;
313 }
e0e920b1 314 PKCS7_free(p7);
0f113f3e 315 return 0;
b536880c 316}
0f113f3e 317
b536880c
JS
318int PKCS12_add_safe(STACK_OF(PKCS7) **psafes, STACK_OF(PKCS12_SAFEBAG) *bags,
319 int nid_safe, int iter, const char *pass)
320{
321 return PKCS12_add_safe_ex(psafes, bags, nid_safe, iter, pass, NULL, NULL);
0f113f3e
MC
322}
323
e869c867
GW
324
325static int pkcs12_remove_bag(STACK_OF(PKCS12_SAFEBAG) **pbags,
326 PKCS12_SAFEBAG *bag)
327{
328 PKCS12_SAFEBAG *tmp;
329
330 if (pbags == NULL || bag == NULL)
331 return 1;
332
333 if ((tmp = sk_PKCS12_SAFEBAG_delete_ptr(*pbags, bag)) == NULL)
334 return 0;
335
336 PKCS12_SAFEBAG_free(tmp);
337 return 1;
338}
339
0f113f3e
MC
340static int pkcs12_add_bag(STACK_OF(PKCS12_SAFEBAG) **pbags,
341 PKCS12_SAFEBAG *bag)
342{
12a765a5
RS
343 int free_bags = 0;
344
345 if (pbags == NULL)
0f113f3e 346 return 1;
12a765a5 347 if (*pbags == NULL) {
0f113f3e 348 *pbags = sk_PKCS12_SAFEBAG_new_null();
12a765a5 349 if (*pbags == NULL)
0f113f3e
MC
350 return 0;
351 free_bags = 1;
12a765a5 352 }
0f113f3e
MC
353
354 if (!sk_PKCS12_SAFEBAG_push(*pbags, bag)) {
355 if (free_bags) {
356 sk_PKCS12_SAFEBAG_free(*pbags);
357 *pbags = NULL;
358 }
359 return 0;
360 }
361
362 return 1;
363
364}
9a48b07e 365
b536880c
JS
366PKCS12 *PKCS12_add_safes_ex(STACK_OF(PKCS7) *safes, int nid_p7,
367 OSSL_LIB_CTX *ctx, const char *propq)
0f113f3e
MC
368{
369 PKCS12 *p12;
12a765a5 370
0f113f3e
MC
371 if (nid_p7 <= 0)
372 nid_p7 = NID_pkcs7_data;
b536880c 373 p12 = PKCS12_init_ex(nid_p7, ctx, propq);
12a765a5 374 if (p12 == NULL)
0f113f3e 375 return NULL;
9a48b07e 376
0f113f3e
MC
377 if (!PKCS12_pack_authsafes(p12, safes)) {
378 PKCS12_free(p12);
379 return NULL;
380 }
8d8c7266 381
0f113f3e 382 return p12;
8d8c7266 383
0f113f3e 384}
b536880c
JS
385
386PKCS12 *PKCS12_add_safes(STACK_OF(PKCS7) *safes, int nid_p7)
387{
388 return PKCS12_add_safes_ex(safes, nid_p7, NULL, NULL);
389}