2 * Copyright 1995-2018 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
11 #include "internal/cryptlib.h"
12 #include <openssl/safestack.h>
13 #include <openssl/asn1.h>
14 #include <openssl/objects.h>
15 #include <openssl/evp.h>
16 #include <openssl/x509.h>
17 #include <openssl/x509v3.h>
18 #include "x509_local.h"
20 int X509v3_get_ext_count(const STACK_OF(X509_EXTENSION
) *x
)
24 return sk_X509_EXTENSION_num(x
);
27 int X509v3_get_ext_by_NID(const STACK_OF(X509_EXTENSION
) *x
, int nid
,
32 obj
= OBJ_nid2obj(nid
);
35 return X509v3_get_ext_by_OBJ(x
, obj
, lastpos
);
38 int X509v3_get_ext_by_OBJ(const STACK_OF(X509_EXTENSION
) *sk
,
39 const ASN1_OBJECT
*obj
, int lastpos
)
49 n
= sk_X509_EXTENSION_num(sk
);
50 for (; lastpos
< n
; lastpos
++) {
51 ex
= sk_X509_EXTENSION_value(sk
, lastpos
);
52 if (OBJ_cmp(ex
->object
, obj
) == 0)
58 int X509v3_get_ext_by_critical(const STACK_OF(X509_EXTENSION
) *sk
, int crit
,
69 n
= sk_X509_EXTENSION_num(sk
);
70 for (; lastpos
< n
; lastpos
++) {
71 ex
= sk_X509_EXTENSION_value(sk
, lastpos
);
72 if (((ex
->critical
> 0) && crit
) || ((ex
->critical
<= 0) && !crit
))
78 X509_EXTENSION
*X509v3_get_ext(const STACK_OF(X509_EXTENSION
) *x
, int loc
)
80 if (x
== NULL
|| sk_X509_EXTENSION_num(x
) <= loc
|| loc
< 0)
83 return sk_X509_EXTENSION_value(x
, loc
);
86 X509_EXTENSION
*X509v3_delete_ext(STACK_OF(X509_EXTENSION
) *x
, int loc
)
90 if (x
== NULL
|| sk_X509_EXTENSION_num(x
) <= loc
|| loc
< 0)
92 ret
= sk_X509_EXTENSION_delete(x
, loc
);
96 STACK_OF(X509_EXTENSION
) *X509v3_add_ext(STACK_OF(X509_EXTENSION
) **x
,
97 X509_EXTENSION
*ex
, int loc
)
99 X509_EXTENSION
*new_ex
= NULL
;
101 STACK_OF(X509_EXTENSION
) *sk
= NULL
;
104 X509err(X509_F_X509V3_ADD_EXT
, ERR_R_PASSED_NULL_PARAMETER
);
109 if ((sk
= sk_X509_EXTENSION_new_null()) == NULL
)
114 n
= sk_X509_EXTENSION_num(sk
);
120 if ((new_ex
= X509_EXTENSION_dup(ex
)) == NULL
)
122 if (!sk_X509_EXTENSION_insert(sk
, new_ex
, loc
))
128 X509err(X509_F_X509V3_ADD_EXT
, ERR_R_MALLOC_FAILURE
);
130 X509_EXTENSION_free(new_ex
);
131 if (x
!= NULL
&& *x
== NULL
)
132 sk_X509_EXTENSION_free(sk
);
136 X509_EXTENSION
*X509_EXTENSION_create_by_NID(X509_EXTENSION
**ex
, int nid
,
138 ASN1_OCTET_STRING
*data
)
143 obj
= OBJ_nid2obj(nid
);
145 X509err(X509_F_X509_EXTENSION_CREATE_BY_NID
, X509_R_UNKNOWN_NID
);
148 ret
= X509_EXTENSION_create_by_OBJ(ex
, obj
, crit
, data
);
150 ASN1_OBJECT_free(obj
);
154 X509_EXTENSION
*X509_EXTENSION_create_by_OBJ(X509_EXTENSION
**ex
,
155 const ASN1_OBJECT
*obj
, int crit
,
156 ASN1_OCTET_STRING
*data
)
160 if ((ex
== NULL
) || (*ex
== NULL
)) {
161 if ((ret
= X509_EXTENSION_new()) == NULL
) {
162 X509err(X509_F_X509_EXTENSION_CREATE_BY_OBJ
,
163 ERR_R_MALLOC_FAILURE
);
169 if (!X509_EXTENSION_set_object(ret
, obj
))
171 if (!X509_EXTENSION_set_critical(ret
, crit
))
173 if (!X509_EXTENSION_set_data(ret
, data
))
176 if ((ex
!= NULL
) && (*ex
== NULL
))
180 if ((ex
== NULL
) || (ret
!= *ex
))
181 X509_EXTENSION_free(ret
);
185 int X509_EXTENSION_set_object(X509_EXTENSION
*ex
, const ASN1_OBJECT
*obj
)
187 if ((ex
== NULL
) || (obj
== NULL
))
189 ASN1_OBJECT_free(ex
->object
);
190 ex
->object
= OBJ_dup(obj
);
191 return ex
->object
!= NULL
;
194 int X509_EXTENSION_set_critical(X509_EXTENSION
*ex
, int crit
)
198 ex
->critical
= (crit
) ? 0xFF : -1;
202 int X509_EXTENSION_set_data(X509_EXTENSION
*ex
, ASN1_OCTET_STRING
*data
)
208 i
= ASN1_OCTET_STRING_set(&ex
->value
, data
->data
, data
->length
);
214 ASN1_OBJECT
*X509_EXTENSION_get_object(X509_EXTENSION
*ex
)
221 ASN1_OCTET_STRING
*X509_EXTENSION_get_data(X509_EXTENSION
*ex
)
228 int X509_EXTENSION_get_critical(const X509_EXTENSION
*ex
)
232 if (ex
->critical
> 0)