2 * Copyright 1995-2020 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
11 #include "internal/cryptlib.h"
12 #include <openssl/safestack.h>
13 #include <openssl/asn1.h>
14 #include <openssl/objects.h>
15 #include <openssl/evp.h>
16 #include <openssl/x509.h>
17 #include <openssl/x509v3.h>
18 #include "x509_local.h"
20 int X509v3_get_ext_count(const STACK_OF(X509_EXTENSION
) *x
)
26 ret
= sk_X509_EXTENSION_num(x
);
27 return ret
> 0 ? ret
: 0;
30 int X509v3_get_ext_by_NID(const STACK_OF(X509_EXTENSION
) *x
, int nid
,
35 obj
= OBJ_nid2obj(nid
);
38 return X509v3_get_ext_by_OBJ(x
, obj
, lastpos
);
41 int X509v3_get_ext_by_OBJ(const STACK_OF(X509_EXTENSION
) *sk
,
42 const ASN1_OBJECT
*obj
, int lastpos
)
52 n
= sk_X509_EXTENSION_num(sk
);
53 for (; lastpos
< n
; lastpos
++) {
54 ex
= sk_X509_EXTENSION_value(sk
, lastpos
);
55 if (OBJ_cmp(ex
->object
, obj
) == 0)
61 int X509v3_get_ext_by_critical(const STACK_OF(X509_EXTENSION
) *sk
, int crit
,
72 n
= sk_X509_EXTENSION_num(sk
);
73 for (; lastpos
< n
; lastpos
++) {
74 ex
= sk_X509_EXTENSION_value(sk
, lastpos
);
75 if (((ex
->critical
> 0) && crit
) || ((ex
->critical
<= 0) && !crit
))
81 X509_EXTENSION
*X509v3_get_ext(const STACK_OF(X509_EXTENSION
) *x
, int loc
)
83 if (x
== NULL
|| sk_X509_EXTENSION_num(x
) <= loc
|| loc
< 0)
86 return sk_X509_EXTENSION_value(x
, loc
);
89 X509_EXTENSION
*X509v3_delete_ext(STACK_OF(X509_EXTENSION
) *x
, int loc
)
93 if (x
== NULL
|| sk_X509_EXTENSION_num(x
) <= loc
|| loc
< 0)
95 ret
= sk_X509_EXTENSION_delete(x
, loc
);
99 STACK_OF(X509_EXTENSION
) *X509v3_add_ext(STACK_OF(X509_EXTENSION
) **x
,
100 X509_EXTENSION
*ex
, int loc
)
102 X509_EXTENSION
*new_ex
= NULL
;
104 STACK_OF(X509_EXTENSION
) *sk
= NULL
;
107 ERR_raise(ERR_LIB_X509
, ERR_R_PASSED_NULL_PARAMETER
);
112 if ((sk
= sk_X509_EXTENSION_new_null()) == NULL
) {
113 ERR_raise(ERR_LIB_X509
, ERR_R_CRYPTO_LIB
);
119 n
= sk_X509_EXTENSION_num(sk
);
125 if ((new_ex
= X509_EXTENSION_dup(ex
)) == NULL
) {
126 ERR_raise(ERR_LIB_X509
, ERR_R_ASN1_LIB
);
129 if (!sk_X509_EXTENSION_insert(sk
, new_ex
, loc
)) {
130 ERR_raise(ERR_LIB_X509
, ERR_R_CRYPTO_LIB
);
137 X509_EXTENSION_free(new_ex
);
138 if (x
!= NULL
&& *x
== NULL
)
139 sk_X509_EXTENSION_free(sk
);
143 X509_EXTENSION
*X509_EXTENSION_create_by_NID(X509_EXTENSION
**ex
, int nid
,
145 ASN1_OCTET_STRING
*data
)
150 obj
= OBJ_nid2obj(nid
);
152 ERR_raise(ERR_LIB_X509
, X509_R_UNKNOWN_NID
);
155 ret
= X509_EXTENSION_create_by_OBJ(ex
, obj
, crit
, data
);
157 ASN1_OBJECT_free(obj
);
161 X509_EXTENSION
*X509_EXTENSION_create_by_OBJ(X509_EXTENSION
**ex
,
162 const ASN1_OBJECT
*obj
, int crit
,
163 ASN1_OCTET_STRING
*data
)
167 if ((ex
== NULL
) || (*ex
== NULL
)) {
168 if ((ret
= X509_EXTENSION_new()) == NULL
) {
169 ERR_raise(ERR_LIB_X509
, ERR_R_ASN1_LIB
);
175 if (!X509_EXTENSION_set_object(ret
, obj
))
177 if (!X509_EXTENSION_set_critical(ret
, crit
))
179 if (!X509_EXTENSION_set_data(ret
, data
))
182 if ((ex
!= NULL
) && (*ex
== NULL
))
186 if ((ex
== NULL
) || (ret
!= *ex
))
187 X509_EXTENSION_free(ret
);
191 int X509_EXTENSION_set_object(X509_EXTENSION
*ex
, const ASN1_OBJECT
*obj
)
193 if ((ex
== NULL
) || (obj
== NULL
))
195 ASN1_OBJECT_free(ex
->object
);
196 ex
->object
= OBJ_dup(obj
);
197 return ex
->object
!= NULL
;
200 int X509_EXTENSION_set_critical(X509_EXTENSION
*ex
, int crit
)
204 ex
->critical
= (crit
) ? 0xFF : -1;
208 int X509_EXTENSION_set_data(X509_EXTENSION
*ex
, ASN1_OCTET_STRING
*data
)
214 i
= ASN1_OCTET_STRING_set(&ex
->value
, data
->data
, data
->length
);
220 ASN1_OBJECT
*X509_EXTENSION_get_object(X509_EXTENSION
*ex
)
227 ASN1_OCTET_STRING
*X509_EXTENSION_get_data(X509_EXTENSION
*ex
)
234 int X509_EXTENSION_get_critical(const X509_EXTENSION
*ex
)
238 if (ex
->critical
> 0)