]> git.ipfire.org Git - thirdparty/openssl.git/blame - crypto/pkcs12/p12_crt.c
Fix safestack issues in pkcs7.h
[thirdparty/openssl.git] / crypto / pkcs12 / p12_crt.c
CommitLineData
0f113f3e 1/*
7e06a675 2 * Copyright 1999-2020 The OpenSSL Project Authors. All Rights Reserved.
8d8c7266 3 *
54fffdf4 4 * Licensed under the Apache License 2.0 (the "License"). You may not use
b1322259
RS
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
8d8c7266
DSH
8 */
9
10#include <stdio.h>
b39fc560 11#include "internal/cryptlib.h"
ec577822 12#include <openssl/pkcs12.h>
706457b7 13#include "p12_local.h"
8d8c7266 14
852c2ed2
RS
15DEFINE_STACK_OF(PKCS12_SAFEBAG)
16
0f113f3e
MC
17static int pkcs12_add_bag(STACK_OF(PKCS12_SAFEBAG) **pbags,
18 PKCS12_SAFEBAG *bag);
9a48b07e 19
8528128b 20static int copy_bag_attr(PKCS12_SAFEBAG *bag, EVP_PKEY *pkey, int nid)
0f113f3e
MC
21{
22 int idx;
23 X509_ATTRIBUTE *attr;
24 idx = EVP_PKEY_get_attr_by_NID(pkey, nid, -1);
25 if (idx < 0)
26 return 1;
27 attr = EVP_PKEY_get_attr(pkey, idx);
28 if (!X509at_add1_attr(&bag->attrib, attr))
29 return 0;
30 return 1;
31}
8528128b 32
82af00fb 33PKCS12 *PKCS12_create(const char *pass, const char *name, EVP_PKEY *pkey, X509 *cert,
0f113f3e
MC
34 STACK_OF(X509) *ca, int nid_key, int nid_cert, int iter,
35 int mac_iter, int keytype)
8d8c7266 36{
0f113f3e
MC
37 PKCS12 *p12 = NULL;
38 STACK_OF(PKCS7) *safes = NULL;
39 STACK_OF(PKCS12_SAFEBAG) *bags = NULL;
40 PKCS12_SAFEBAG *bag = NULL;
41 int i;
42 unsigned char keyid[EVP_MAX_MD_SIZE];
43 unsigned int keyidlen = 0;
44
45 /* Set defaults */
46 if (!nid_cert)
558c94ef 47#ifdef OPENSSL_NO_RC2
0f113f3e 48 nid_cert = NID_pbe_WithSHA1And3_Key_TripleDES_CBC;
558c94ef 49#else
0f113f3e 50 nid_cert = NID_pbe_WithSHA1And40BitRC2_CBC;
558c94ef 51#endif
0f113f3e
MC
52 if (!nid_key)
53 nid_key = NID_pbe_WithSHA1And3_Key_TripleDES_CBC;
54 if (!iter)
55 iter = PKCS12_DEFAULT_ITER;
56 if (!mac_iter)
57 mac_iter = 1;
58
12a765a5 59 if (pkey == NULL && cert == NULL && ca == NULL) {
0f113f3e
MC
60 PKCS12err(PKCS12_F_PKCS12_CREATE, PKCS12_R_INVALID_NULL_ARGUMENT);
61 return NULL;
62 }
63
64 if (pkey && cert) {
65 if (!X509_check_private_key(cert, pkey))
66 return NULL;
7e06a675
BE
67 if (!X509_digest(cert, EVP_sha1(), keyid, &keyidlen))
68 return NULL;
0f113f3e
MC
69 }
70
71 if (cert) {
72 bag = PKCS12_add_cert(&bags, cert);
73 if (name && !PKCS12_add_friendlyname(bag, name, -1))
74 goto err;
75 if (keyidlen && !PKCS12_add_localkeyid(bag, keyid, keyidlen))
76 goto err;
77 }
78
79 /* Add all other certificates */
80 for (i = 0; i < sk_X509_num(ca); i++) {
81 if (!PKCS12_add_cert(&bags, sk_X509_value(ca, i)))
82 goto err;
83 }
84
85 if (bags && !PKCS12_add_safe(&safes, bags, nid_cert, iter, pass))
86 goto err;
87
88 sk_PKCS12_SAFEBAG_pop_free(bags, PKCS12_SAFEBAG_free);
89 bags = NULL;
90
91 if (pkey) {
92 bag = PKCS12_add_key(&bags, pkey, keytype, iter, nid_key, pass);
93
94 if (!bag)
95 goto err;
96
97 if (!copy_bag_attr(bag, pkey, NID_ms_csp_name))
98 goto err;
99 if (!copy_bag_attr(bag, pkey, NID_LocalKeySet))
100 goto err;
101
102 if (name && !PKCS12_add_friendlyname(bag, name, -1))
103 goto err;
104 if (keyidlen && !PKCS12_add_localkeyid(bag, keyid, keyidlen))
105 goto err;
106 }
107
108 if (bags && !PKCS12_add_safe(&safes, bags, -1, 0, NULL))
109 goto err;
110
111 sk_PKCS12_SAFEBAG_pop_free(bags, PKCS12_SAFEBAG_free);
112 bags = NULL;
113
114 p12 = PKCS12_add_safes(safes, 0);
115
12a765a5 116 if (p12 == NULL)
0f113f3e
MC
117 goto err;
118
119 sk_PKCS7_pop_free(safes, PKCS7_free);
120
121 safes = NULL;
122
123 if ((mac_iter != -1) &&
124 !PKCS12_set_mac(p12, pass, -1, NULL, 0, mac_iter, NULL))
125 goto err;
126
127 return p12;
128
129 err:
e0e920b1
RS
130 PKCS12_free(p12);
131 sk_PKCS7_pop_free(safes, PKCS7_free);
132 sk_PKCS12_SAFEBAG_pop_free(bags, PKCS12_SAFEBAG_free);
0f113f3e 133 return NULL;
9a48b07e
DSH
134
135}
136
137PKCS12_SAFEBAG *PKCS12_add_cert(STACK_OF(PKCS12_SAFEBAG) **pbags, X509 *cert)
0f113f3e
MC
138{
139 PKCS12_SAFEBAG *bag = NULL;
140 char *name;
141 int namelen = -1;
142 unsigned char *keyid;
143 int keyidlen = -1;
8d8c7266 144
0f113f3e 145 /* Add user certificate */
293042c9 146 if ((bag = PKCS12_SAFEBAG_create_cert(cert)) == NULL)
0f113f3e 147 goto err;
9a48b07e 148
0f113f3e
MC
149 /*
150 * Use friendlyName and localKeyID in certificate. (if present)
151 */
9a48b07e 152
0f113f3e 153 name = (char *)X509_alias_get0(cert, &namelen);
9a48b07e 154
0f113f3e
MC
155 if (name && !PKCS12_add_friendlyname(bag, name, namelen))
156 goto err;
9a48b07e 157
0f113f3e 158 keyid = X509_keyid_get0(cert, &keyidlen);
9a48b07e 159
0f113f3e
MC
160 if (keyid && !PKCS12_add_localkeyid(bag, keyid, keyidlen))
161 goto err;
9a48b07e 162
0f113f3e
MC
163 if (!pkcs12_add_bag(pbags, bag))
164 goto err;
9a48b07e 165
0f113f3e 166 return bag;
9a48b07e 167
0f113f3e 168 err:
e0e920b1 169 PKCS12_SAFEBAG_free(bag);
0f113f3e 170 return NULL;
8d8c7266 171
0f113f3e 172}
9a48b07e 173
0f113f3e
MC
174PKCS12_SAFEBAG *PKCS12_add_key(STACK_OF(PKCS12_SAFEBAG) **pbags,
175 EVP_PKEY *key, int key_usage, int iter,
82af00fb 176 int nid_key, const char *pass)
0f113f3e 177{
9a48b07e 178
0f113f3e
MC
179 PKCS12_SAFEBAG *bag = NULL;
180 PKCS8_PRIV_KEY_INFO *p8 = NULL;
9a48b07e 181
0f113f3e 182 /* Make a PKCS#8 structure */
75ebbd9a 183 if ((p8 = EVP_PKEY2PKCS8(key)) == NULL)
0f113f3e
MC
184 goto err;
185 if (key_usage && !PKCS8_add_keyusage(p8, key_usage))
186 goto err;
187 if (nid_key != -1) {
425f3300
DSH
188 bag = PKCS12_SAFEBAG_create_pkcs8_encrypt(nid_key, pass, -1, NULL, 0,
189 iter, p8);
0f113f3e
MC
190 PKCS8_PRIV_KEY_INFO_free(p8);
191 } else
425f3300 192 bag = PKCS12_SAFEBAG_create0_p8inf(p8);
9a48b07e 193
0f113f3e
MC
194 if (!bag)
195 goto err;
9a48b07e 196
0f113f3e
MC
197 if (!pkcs12_add_bag(pbags, bag))
198 goto err;
9a48b07e 199
0f113f3e 200 return bag;
9a48b07e 201
0f113f3e 202 err:
e0e920b1 203 PKCS12_SAFEBAG_free(bag);
0f113f3e 204 return NULL;
9a48b07e 205
0f113f3e 206}
8d8c7266 207
c5ec6dcf
JS
208PKCS12_SAFEBAG *PKCS12_add_secret(STACK_OF(PKCS12_SAFEBAG) **pbags,
209 int nid_type, const unsigned char *value, int len)
210{
211 PKCS12_SAFEBAG *bag = NULL;
212
213 /* Add secret, storing the value as an octet string */
214 if ((bag = PKCS12_SAFEBAG_create_secret(nid_type, V_ASN1_OCTET_STRING, value, len)) == NULL)
215 goto err;
216
217 if (!pkcs12_add_bag(pbags, bag))
218 goto err;
219
220 return bag;
221 err:
222 PKCS12_SAFEBAG_free(bag);
223 return NULL;
224}
225
9a48b07e 226int PKCS12_add_safe(STACK_OF(PKCS7) **psafes, STACK_OF(PKCS12_SAFEBAG) *bags,
82af00fb 227 int nid_safe, int iter, const char *pass)
0f113f3e
MC
228{
229 PKCS7 *p7 = NULL;
230 int free_safes = 0;
231
12a765a5 232 if (*psafes == NULL) {
0f113f3e 233 *psafes = sk_PKCS7_new_null();
12a765a5 234 if (*psafes == NULL)
0f113f3e
MC
235 return 0;
236 free_safes = 1;
12a765a5 237 }
0f113f3e
MC
238
239 if (nid_safe == 0)
558c94ef 240#ifdef OPENSSL_NO_RC2
0f113f3e 241 nid_safe = NID_pbe_WithSHA1And3_Key_TripleDES_CBC;
558c94ef 242#else
0f113f3e 243 nid_safe = NID_pbe_WithSHA1And40BitRC2_CBC;
558c94ef 244#endif
9a48b07e 245
0f113f3e
MC
246 if (nid_safe == -1)
247 p7 = PKCS12_pack_p7data(bags);
248 else
249 p7 = PKCS12_pack_p7encdata(nid_safe, pass, -1, NULL, 0, iter, bags);
12a765a5 250 if (p7 == NULL)
0f113f3e
MC
251 goto err;
252
253 if (!sk_PKCS7_push(*psafes, p7))
254 goto err;
255
256 return 1;
257
258 err:
259 if (free_safes) {
260 sk_PKCS7_free(*psafes);
261 *psafes = NULL;
262 }
e0e920b1 263 PKCS7_free(p7);
0f113f3e
MC
264 return 0;
265
266}
267
268static int pkcs12_add_bag(STACK_OF(PKCS12_SAFEBAG) **pbags,
269 PKCS12_SAFEBAG *bag)
270{
12a765a5
RS
271 int free_bags = 0;
272
273 if (pbags == NULL)
0f113f3e 274 return 1;
12a765a5 275 if (*pbags == NULL) {
0f113f3e 276 *pbags = sk_PKCS12_SAFEBAG_new_null();
12a765a5 277 if (*pbags == NULL)
0f113f3e
MC
278 return 0;
279 free_bags = 1;
12a765a5 280 }
0f113f3e
MC
281
282 if (!sk_PKCS12_SAFEBAG_push(*pbags, bag)) {
283 if (free_bags) {
284 sk_PKCS12_SAFEBAG_free(*pbags);
285 *pbags = NULL;
286 }
287 return 0;
288 }
289
290 return 1;
291
292}
9a48b07e
DSH
293
294PKCS12 *PKCS12_add_safes(STACK_OF(PKCS7) *safes, int nid_p7)
0f113f3e
MC
295{
296 PKCS12 *p12;
12a765a5 297
0f113f3e
MC
298 if (nid_p7 <= 0)
299 nid_p7 = NID_pkcs7_data;
300 p12 = PKCS12_init(nid_p7);
12a765a5 301 if (p12 == NULL)
0f113f3e 302 return NULL;
9a48b07e 303
0f113f3e
MC
304 if (!PKCS12_pack_authsafes(p12, safes)) {
305 PKCS12_free(p12);
306 return NULL;
307 }
8d8c7266 308
0f113f3e 309 return p12;
8d8c7266 310
0f113f3e 311}