2 * Copyright 1995-2020 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
11 #include "internal/cryptlib.h"
12 #include <openssl/safestack.h>
13 #include <openssl/asn1.h>
14 #include <openssl/objects.h>
15 #include <openssl/evp.h>
16 #include <openssl/x509.h>
17 #include <openssl/x509v3.h>
18 #include "x509_local.h"
20 int X509v3_get_ext_count(const STACK_OF(X509_EXTENSION
) *x
)
26 ret
= sk_X509_EXTENSION_num(x
);
27 return ret
> 0 ? ret
: 0;
30 int X509v3_get_ext_by_NID(const STACK_OF(X509_EXTENSION
) *x
, int nid
,
35 obj
= OBJ_nid2obj(nid
);
38 return X509v3_get_ext_by_OBJ(x
, obj
, lastpos
);
41 int X509v3_get_ext_by_OBJ(const STACK_OF(X509_EXTENSION
) *sk
,
42 const ASN1_OBJECT
*obj
, int lastpos
)
52 n
= sk_X509_EXTENSION_num(sk
);
53 for (; lastpos
< n
; lastpos
++) {
54 ex
= sk_X509_EXTENSION_value(sk
, lastpos
);
55 if (OBJ_cmp(ex
->object
, obj
) == 0)
61 int X509v3_get_ext_by_critical(const STACK_OF(X509_EXTENSION
) *sk
, int crit
,
72 n
= sk_X509_EXTENSION_num(sk
);
73 for (; lastpos
< n
; lastpos
++) {
74 ex
= sk_X509_EXTENSION_value(sk
, lastpos
);
75 c
= X509_EXTENSION_get_critical(ex
);
83 X509_EXTENSION
*X509v3_get_ext(const STACK_OF(X509_EXTENSION
) *x
, int loc
)
85 if (x
== NULL
|| sk_X509_EXTENSION_num(x
) <= loc
|| loc
< 0)
88 return sk_X509_EXTENSION_value(x
, loc
);
91 X509_EXTENSION
*X509v3_delete_ext(STACK_OF(X509_EXTENSION
) *x
, int loc
)
95 if (x
== NULL
|| sk_X509_EXTENSION_num(x
) <= loc
|| loc
< 0)
97 ret
= sk_X509_EXTENSION_delete(x
, loc
);
101 STACK_OF(X509_EXTENSION
) *X509v3_add_ext(STACK_OF(X509_EXTENSION
) **x
,
102 X509_EXTENSION
*ex
, int loc
)
104 X509_EXTENSION
*new_ex
= NULL
;
106 STACK_OF(X509_EXTENSION
) *sk
= NULL
;
109 ERR_raise(ERR_LIB_X509
, ERR_R_PASSED_NULL_PARAMETER
);
114 if ((sk
= sk_X509_EXTENSION_new_null()) == NULL
) {
115 ERR_raise(ERR_LIB_X509
, ERR_R_CRYPTO_LIB
);
121 n
= sk_X509_EXTENSION_num(sk
);
127 if ((new_ex
= X509_EXTENSION_dup(ex
)) == NULL
) {
128 ERR_raise(ERR_LIB_X509
, ERR_R_ASN1_LIB
);
131 if (!sk_X509_EXTENSION_insert(sk
, new_ex
, loc
)) {
132 ERR_raise(ERR_LIB_X509
, ERR_R_CRYPTO_LIB
);
139 X509_EXTENSION_free(new_ex
);
140 if (x
!= NULL
&& *x
== NULL
)
141 sk_X509_EXTENSION_free(sk
);
145 X509_EXTENSION
*X509_EXTENSION_create_by_NID(X509_EXTENSION
**ex
, int nid
,
147 ASN1_OCTET_STRING
*data
)
152 obj
= OBJ_nid2obj(nid
);
154 ERR_raise(ERR_LIB_X509
, X509_R_UNKNOWN_NID
);
157 ret
= X509_EXTENSION_create_by_OBJ(ex
, obj
, crit
, data
);
159 ASN1_OBJECT_free(obj
);
163 X509_EXTENSION
*X509_EXTENSION_create_by_OBJ(X509_EXTENSION
**ex
,
164 const ASN1_OBJECT
*obj
, int crit
,
165 ASN1_OCTET_STRING
*data
)
169 if ((ex
== NULL
) || (*ex
== NULL
)) {
170 if ((ret
= X509_EXTENSION_new()) == NULL
) {
171 ERR_raise(ERR_LIB_X509
, ERR_R_ASN1_LIB
);
177 if (!X509_EXTENSION_set_object(ret
, obj
))
179 if (!X509_EXTENSION_set_critical(ret
, crit
))
181 if (!X509_EXTENSION_set_data(ret
, data
))
184 if ((ex
!= NULL
) && (*ex
== NULL
))
188 if ((ex
== NULL
) || (ret
!= *ex
))
189 X509_EXTENSION_free(ret
);
193 int X509_EXTENSION_set_object(X509_EXTENSION
*ex
, const ASN1_OBJECT
*obj
)
195 if ((ex
== NULL
) || (obj
== NULL
))
197 ASN1_OBJECT_free(ex
->object
);
198 ex
->object
= OBJ_dup(obj
);
199 return ex
->object
!= NULL
;
202 int X509_EXTENSION_set_critical(X509_EXTENSION
*ex
, int crit
)
206 ex
->critical
= (crit
) ? 0xFF : 0;
210 int X509_EXTENSION_set_data(X509_EXTENSION
*ex
, ASN1_OCTET_STRING
*data
)
216 i
= ASN1_OCTET_STRING_set(&ex
->value
, data
->data
, data
->length
);
222 ASN1_OBJECT
*X509_EXTENSION_get_object(X509_EXTENSION
*ex
)
229 ASN1_OCTET_STRING
*X509_EXTENSION_get_data(X509_EXTENSION
*ex
)
236 int X509_EXTENSION_get_critical(const X509_EXTENSION
*ex
)
240 if (ex
->critical
> 0)