mirror of
https://github.com/yuzu-emu/mbedtls.git
synced 2025-01-09 23:25:38 +00:00
- Added support for GeneralizedTime in X509 certificates
This commit is contained in:
parent
9caf2d2d38
commit
9120018f3d
|
@ -4,6 +4,7 @@ PolarSSL ChangeLog
|
||||||
Changes
|
Changes
|
||||||
* Added option parsing for host and port selection to
|
* Added option parsing for host and port selection to
|
||||||
ssl_client2
|
ssl_client2
|
||||||
|
* Added support for GeneralizedTime in X509 parsing
|
||||||
|
|
||||||
Bug fixes
|
Bug fixes
|
||||||
* Fixed bug resulting in failure to send the last
|
* Fixed bug resulting in failure to send the last
|
||||||
|
|
|
@ -92,6 +92,7 @@
|
||||||
#define ASN1_T61_STRING 0x14
|
#define ASN1_T61_STRING 0x14
|
||||||
#define ASN1_IA5_STRING 0x16
|
#define ASN1_IA5_STRING 0x16
|
||||||
#define ASN1_UTC_TIME 0x17
|
#define ASN1_UTC_TIME 0x17
|
||||||
|
#define ASN1_GENERALIZED_TIME 0x18
|
||||||
#define ASN1_UNIVERSAL_STRING 0x1C
|
#define ASN1_UNIVERSAL_STRING 0x1C
|
||||||
#define ASN1_BMP_STRING 0x1E
|
#define ASN1_BMP_STRING 0x1E
|
||||||
#define ASN1_PRIMITIVE 0x00
|
#define ASN1_PRIMITIVE 0x00
|
||||||
|
|
|
@ -356,31 +356,66 @@ static int x509_get_name( unsigned char **p,
|
||||||
* utcTime UTCTime,
|
* utcTime UTCTime,
|
||||||
* generalTime GeneralizedTime }
|
* generalTime GeneralizedTime }
|
||||||
*/
|
*/
|
||||||
static int x509_get_UTCTime( unsigned char **p,
|
static int x509_get_time( unsigned char **p,
|
||||||
unsigned char *end,
|
unsigned char *end,
|
||||||
x509_time *time )
|
x509_time *time )
|
||||||
{
|
{
|
||||||
int ret, len;
|
int ret, len;
|
||||||
char date[64];
|
char date[64];
|
||||||
|
unsigned char tag;
|
||||||
|
|
||||||
if( ( ret = asn1_get_tag( p, end, &len, ASN1_UTC_TIME ) ) != 0 )
|
if( ( end - *p ) < 1 )
|
||||||
return( POLARSSL_ERR_X509_CERT_INVALID_DATE | ret );
|
return( POLARSSL_ERR_X509_CERT_INVALID_DATE | POLARSSL_ERR_ASN1_OUT_OF_DATA );
|
||||||
|
|
||||||
memset( date, 0, sizeof( date ) );
|
tag = **p;
|
||||||
memcpy( date, *p, ( len < (int) sizeof( date ) - 1 ) ?
|
|
||||||
len : (int) sizeof( date ) - 1 );
|
|
||||||
|
|
||||||
if( sscanf( date, "%2d%2d%2d%2d%2d%2d",
|
if ( tag == ASN1_UTC_TIME )
|
||||||
&time->year, &time->mon, &time->day,
|
{
|
||||||
&time->hour, &time->min, &time->sec ) < 5 )
|
(*p)++;
|
||||||
return( POLARSSL_ERR_X509_CERT_INVALID_DATE );
|
ret = asn1_get_len( p, end, &len );
|
||||||
|
|
||||||
time->year += 100 * ( time->year < 90 );
|
if( ret != 0 )
|
||||||
time->year += 1900;
|
return( POLARSSL_ERR_X509_CERT_INVALID_DATE | ret );
|
||||||
|
|
||||||
*p += len;
|
memset( date, 0, sizeof( date ) );
|
||||||
|
memcpy( date, *p, ( len < (int) sizeof( date ) - 1 ) ?
|
||||||
|
len : (int) sizeof( date ) - 1 );
|
||||||
|
|
||||||
return( 0 );
|
if( sscanf( date, "%2d%2d%2d%2d%2d%2d",
|
||||||
|
&time->year, &time->mon, &time->day,
|
||||||
|
&time->hour, &time->min, &time->sec ) < 5 )
|
||||||
|
return( POLARSSL_ERR_X509_CERT_INVALID_DATE );
|
||||||
|
|
||||||
|
time->year += 100 * ( time->year < 90 );
|
||||||
|
time->year += 1900;
|
||||||
|
|
||||||
|
*p += len;
|
||||||
|
|
||||||
|
return( 0 );
|
||||||
|
}
|
||||||
|
else if ( tag == ASN1_GENERALIZED_TIME )
|
||||||
|
{
|
||||||
|
(*p)++;
|
||||||
|
ret = asn1_get_len( p, end, &len );
|
||||||
|
|
||||||
|
if( ret != 0 )
|
||||||
|
return( POLARSSL_ERR_X509_CERT_INVALID_DATE | ret );
|
||||||
|
|
||||||
|
memset( date, 0, sizeof( date ) );
|
||||||
|
memcpy( date, *p, ( len < (int) sizeof( date ) - 1 ) ?
|
||||||
|
len : (int) sizeof( date ) - 1 );
|
||||||
|
|
||||||
|
if( sscanf( date, "%4d%2d%2d%2d%2d%2d",
|
||||||
|
&time->year, &time->mon, &time->day,
|
||||||
|
&time->hour, &time->min, &time->sec ) < 5 )
|
||||||
|
return( POLARSSL_ERR_X509_CERT_INVALID_DATE );
|
||||||
|
|
||||||
|
*p += len;
|
||||||
|
|
||||||
|
return( 0 );
|
||||||
|
}
|
||||||
|
else
|
||||||
|
return( POLARSSL_ERR_X509_CERT_INVALID_DATE | POLARSSL_ERR_ASN1_UNEXPECTED_TAG );
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
@ -402,13 +437,10 @@ static int x509_get_dates( unsigned char **p,
|
||||||
|
|
||||||
end = *p + len;
|
end = *p + len;
|
||||||
|
|
||||||
/*
|
if( ( ret = x509_get_time( p, end, from ) ) != 0 )
|
||||||
* TODO: also handle GeneralizedTime
|
|
||||||
*/
|
|
||||||
if( ( ret = x509_get_UTCTime( p, end, from ) ) != 0 )
|
|
||||||
return( ret );
|
return( ret );
|
||||||
|
|
||||||
if( ( ret = x509_get_UTCTime( p, end, to ) ) != 0 )
|
if( ( ret = x509_get_time( p, end, to ) ) != 0 )
|
||||||
return( ret );
|
return( ret );
|
||||||
|
|
||||||
if( *p != end )
|
if( *p != end )
|
||||||
|
@ -742,7 +774,7 @@ static int x509_get_entries( unsigned char **p,
|
||||||
if( ( ret = x509_get_serial( p, end, &cur_entry->serial ) ) != 0 )
|
if( ( ret = x509_get_serial( p, end, &cur_entry->serial ) ) != 0 )
|
||||||
return( ret );
|
return( ret );
|
||||||
|
|
||||||
if( ( ret = x509_get_UTCTime( p, end, &cur_entry->revocation_date ) ) != 0 )
|
if( ( ret = x509_get_time( p, end, &cur_entry->revocation_date ) ) != 0 )
|
||||||
return( ret );
|
return( ret );
|
||||||
|
|
||||||
if( ( ret = x509_get_crl_ext( p, end, &cur_entry->entry_ext ) ) != 0 )
|
if( ( ret = x509_get_crl_ext( p, end, &cur_entry->entry_ext ) ) != 0 )
|
||||||
|
@ -1320,13 +1352,13 @@ int x509parse_crl( x509_crl *chain, unsigned char *buf, int buflen )
|
||||||
* thisUpdate Time
|
* thisUpdate Time
|
||||||
* nextUpdate Time OPTIONAL
|
* nextUpdate Time OPTIONAL
|
||||||
*/
|
*/
|
||||||
if( ( ret = x509_get_UTCTime( &p, end, &crl->this_update ) ) != 0 )
|
if( ( ret = x509_get_time( &p, end, &crl->this_update ) ) != 0 )
|
||||||
{
|
{
|
||||||
x509_crl_free( crl );
|
x509_crl_free( crl );
|
||||||
return( ret );
|
return( ret );
|
||||||
}
|
}
|
||||||
|
|
||||||
if( ( ret = x509_get_UTCTime( &p, end, &crl->next_update ) ) != 0 )
|
if( ( ret = x509_get_time( &p, end, &crl->next_update ) ) != 0 )
|
||||||
{
|
{
|
||||||
if ( ret != ( POLARSSL_ERR_X509_CERT_INVALID_DATE |
|
if ( ret != ( POLARSSL_ERR_X509_CERT_INVALID_DATE |
|
||||||
POLARSSL_ERR_ASN1_UNEXPECTED_TAG ) &&
|
POLARSSL_ERR_ASN1_UNEXPECTED_TAG ) &&
|
||||||
|
|
|
@ -376,6 +376,9 @@ x509parse_crt:"308197308180a0030201008204deadbeef300d06092a864886f70d01010205003
|
||||||
X509 Certificate ASN1 (correct)
|
X509 Certificate ASN1 (correct)
|
||||||
x509parse_crt:"308196308180a0030201008204deadbeef300d06092a864886f70d0101020500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D010101050003190030160210ffffffffffffffffffffffffffffffff0202ffff300d06092a864886f70d0101020500030200ff":"cert. version \: 1\nserial number \: DE\:AD\:BE\:EF\nissuer name \: ?\?=Test\nsubject name \: ?\?=Test\nissued on \: 2009-01-01 00\:00\:00\nexpires on \: 2009-12-31 23\:59\:59\nsigned using \: RSA+MD2\nRSA key size \: 128 bits\n":0
|
x509parse_crt:"308196308180a0030201008204deadbeef300d06092a864886f70d0101020500300c310a30080600130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D010101050003190030160210ffffffffffffffffffffffffffffffff0202ffff300d06092a864886f70d0101020500030200ff":"cert. version \: 1\nserial number \: DE\:AD\:BE\:EF\nissuer name \: ?\?=Test\nsubject name \: ?\?=Test\nissued on \: 2009-01-01 00\:00\:00\nexpires on \: 2009-12-31 23\:59\:59\nsigned using \: RSA+MD2\nRSA key size \: 128 bits\n":0
|
||||||
|
|
||||||
|
X509 Certificate ASN1 (GeneralizedTime instead of UTCTime)
|
||||||
|
x509parse_crt:"308198308182a0030201008204deadbeef300d06092a864886f70d0101020500300c310a30080600130454657374301e180e3230313030313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D010101050003190030160210ffffffffffffffffffffffffffffffff0202ffff300d06092a864886f70d0101020500030200ff":"cert. version \: 1\nserial number \: DE\:AD\:BE\:EF\nissuer name \: ?\?=Test\nsubject name \: ?\?=Test\nissued on \: 2010-01-01 00\:00\:00\nexpires on \: 2009-12-31 23\:59\:59\nsigned using \: RSA+MD2\nRSA key size \: 128 bits\n":0
|
||||||
|
|
||||||
X509 Certificate ASN1 (Name with X520 CN)
|
X509 Certificate ASN1 (Name with X520 CN)
|
||||||
x509parse_crt:"308199308183a0030201008204deadbeef300d06092a864886f70d0101020500300f310d300b0603550403130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D010101050003190030160210ffffffffffffffffffffffffffffffff0202ffff300d06092a864886f70d0101020500030200ff":"cert. version \: 1\nserial number \: DE\:AD\:BE\:EF\nissuer name \: CN=Test\nsubject name \: ?\?=Test\nissued on \: 2009-01-01 00\:00\:00\nexpires on \: 2009-12-31 23\:59\:59\nsigned using \: RSA+MD2\nRSA key size \: 128 bits\n":0
|
x509parse_crt:"308199308183a0030201008204deadbeef300d06092a864886f70d0101020500300f310d300b0603550403130454657374301c170c303930313031303030303030170c303931323331323335393539300c310a30080600130454657374302a300d06092A864886F70D010101050003190030160210ffffffffffffffffffffffffffffffff0202ffff300d06092a864886f70d0101020500030200ff":"cert. version \: 1\nserial number \: DE\:AD\:BE\:EF\nissuer name \: CN=Test\nsubject name \: ?\?=Test\nissued on \: 2009-01-01 00\:00\:00\nexpires on \: 2009-12-31 23\:59\:59\nsigned using \: RSA+MD2\nRSA key size \: 128 bits\n":0
|
||||||
|
|
||||||
|
@ -455,7 +458,7 @@ X509 CRL ASN1 (TBSCertList, entries present, invalid sig_alg)
|
||||||
x509parse_crl:"304c3049a003020100300d06092a864886f70d01010e0500300f310d300b0603550403130441424344170c303930313031303030303030301430128202abcd170c30383132333132333539353900":"":POLARSSL_ERR_X509_CERT_INVALID_ALG | POLARSSL_ERR_ASN1_UNEXPECTED_TAG
|
x509parse_crl:"304c3049a003020100300d06092a864886f70d01010e0500300f310d300b0603550403130441424344170c303930313031303030303030301430128202abcd170c30383132333132333539353900":"":POLARSSL_ERR_X509_CERT_INVALID_ALG | POLARSSL_ERR_ASN1_UNEXPECTED_TAG
|
||||||
|
|
||||||
X509 CRL ASN1 (TBSCertList, entries present, date in entry invalid)
|
X509 CRL ASN1 (TBSCertList, entries present, date in entry invalid)
|
||||||
x509parse_crl:"304c3049a003020100300d06092a864886f70d01010e0500300f310d300b0603550403130441424344170c303930313031303030303030301430128202abcd180c30383132333132333539353900":"":POLARSSL_ERR_X509_CERT_INVALID_DATE | POLARSSL_ERR_ASN1_UNEXPECTED_TAG
|
x509parse_crl:"304c3049a003020100300d06092a864886f70d01010e0500300f310d300b0603550403130441424344170c303930313031303030303030301430128202abcd190c30383132333132333539353900":"":POLARSSL_ERR_X509_CERT_INVALID_DATE | POLARSSL_ERR_ASN1_UNEXPECTED_TAG
|
||||||
|
|
||||||
X509 CRL ASN1 (TBSCertList, sig_alg present, sig_alg does not match)
|
X509 CRL ASN1 (TBSCertList, sig_alg present, sig_alg does not match)
|
||||||
x509parse_crl:"305a3049a003020100300d06092a864886f70d01010e0500300f310d300b0603550403130441424344170c303930313031303030303030301430128202abcd170c303831323331323335393539300d06092a864886f70d01010d0500":"":POLARSSL_ERR_X509_CERT_SIG_MISMATCH
|
x509parse_crl:"305a3049a003020100300d06092a864886f70d01010e0500300f310d300b0603550403130441424344170c303930313031303030303030301430128202abcd170c303831323331323335393539300d06092a864886f70d01010d0500":"":POLARSSL_ERR_X509_CERT_SIG_MISMATCH
|
||||||
|
|
Loading…
Reference in a new issue