2 * Copyright 1995-2017 The OpenSSL Project Authors. All Rights Reserved.
4 * Licensed under the Apache License 2.0 (the "License"). You may not use
5 * this file except in compliance with the License. You can obtain a copy
6 * in the file LICENSE in the source distribution or at
7 * https://www.openssl.org/source/license.html
11 * Low level APIs are deprecated for public use, but still ok for
14 #include "internal/deprecated.h"
17 #include "internal/cryptlib.h"
18 #include <openssl/buffer.h>
19 #include <openssl/asn1.h>
20 #include <openssl/evp.h>
21 #include <openssl/x509.h>
22 #include "crypto/x509.h"
23 #include <openssl/ocsp.h>
24 #include <openssl/rsa.h>
25 #include <openssl/dsa.h>
26 #include <openssl/x509v3.h>
28 static void clean_id_ctx(EVP_MD_CTX *ctx)
30 EVP_PKEY_CTX *pctx = EVP_MD_CTX_pkey_ctx(ctx);
32 EVP_PKEY_CTX_free(pctx);
36 static EVP_MD_CTX *make_id_ctx(EVP_PKEY *r, ASN1_OCTET_STRING *id)
38 EVP_MD_CTX *ctx = NULL;
39 EVP_PKEY_CTX *pctx = NULL;
41 if ((ctx = EVP_MD_CTX_new()) == NULL
42 || (pctx = EVP_PKEY_CTX_new(r, NULL)) == NULL) {
43 X509err(0, ERR_R_MALLOC_FAILURE);
48 if (EVP_PKEY_CTX_set1_id(pctx, id->data, id->length) <= 0) {
49 X509err(0, ERR_R_MALLOC_FAILURE);
54 EVP_MD_CTX_set_pkey_ctx(ctx, pctx);
58 EVP_PKEY_CTX_free(pctx);
63 int X509_verify(X509 *a, EVP_PKEY *r)
66 EVP_MD_CTX *ctx = NULL;
67 ASN1_OCTET_STRING *id = NULL;
69 if (X509_ALGOR_cmp(&a->sig_alg, &a->cert_info.signature))
72 #ifndef OPENSSL_NO_SM2
76 if ((ctx = make_id_ctx(r, id)) != NULL) {
77 rv = ASN1_item_verify_ctx(ASN1_ITEM_rptr(X509_CINF), &a->sig_alg,
78 &a->signature, &a->cert_info, ctx);
84 int X509_REQ_verify(X509_REQ *a, EVP_PKEY *r)
87 EVP_MD_CTX *ctx = NULL;
88 ASN1_OCTET_STRING *id = NULL;
90 #ifndef OPENSSL_NO_SM2
94 if ((ctx = make_id_ctx(r, id)) != NULL) {
95 rv = ASN1_item_verify_ctx(ASN1_ITEM_rptr(X509_REQ_INFO), &a->sig_alg,
96 a->signature, &a->req_info, ctx);
102 int NETSCAPE_SPKI_verify(NETSCAPE_SPKI *a, EVP_PKEY *r)
104 return (ASN1_item_verify(ASN1_ITEM_rptr(NETSCAPE_SPKAC),
105 &a->sig_algor, a->signature, a->spkac, r));
108 int X509_sign(X509 *x, EVP_PKEY *pkey, const EVP_MD *md)
110 x->cert_info.enc.modified = 1;
111 return (ASN1_item_sign(ASN1_ITEM_rptr(X509_CINF), &x->cert_info.signature,
112 &x->sig_alg, &x->signature, &x->cert_info, pkey,
116 int X509_sign_ctx(X509 *x, EVP_MD_CTX *ctx)
118 x->cert_info.enc.modified = 1;
119 return ASN1_item_sign_ctx(ASN1_ITEM_rptr(X509_CINF),
120 &x->cert_info.signature,
121 &x->sig_alg, &x->signature, &x->cert_info, ctx);
124 #ifndef OPENSSL_NO_OCSP
125 int X509_http_nbio(OCSP_REQ_CTX *rctx, X509 **pcert)
127 return OCSP_REQ_CTX_nbio_d2i(rctx,
128 (ASN1_VALUE **)pcert, ASN1_ITEM_rptr(X509));
132 int X509_REQ_sign(X509_REQ *x, EVP_PKEY *pkey, const EVP_MD *md)
134 return (ASN1_item_sign(ASN1_ITEM_rptr(X509_REQ_INFO), &x->sig_alg, NULL,
135 x->signature, &x->req_info, pkey, md));
138 int X509_REQ_sign_ctx(X509_REQ *x, EVP_MD_CTX *ctx)
140 return ASN1_item_sign_ctx(ASN1_ITEM_rptr(X509_REQ_INFO),
141 &x->sig_alg, NULL, x->signature, &x->req_info,
145 int X509_CRL_sign(X509_CRL *x, EVP_PKEY *pkey, const EVP_MD *md)
147 x->crl.enc.modified = 1;
148 return (ASN1_item_sign(ASN1_ITEM_rptr(X509_CRL_INFO), &x->crl.sig_alg,
149 &x->sig_alg, &x->signature, &x->crl, pkey, md));
152 int X509_CRL_sign_ctx(X509_CRL *x, EVP_MD_CTX *ctx)
154 x->crl.enc.modified = 1;
155 return ASN1_item_sign_ctx(ASN1_ITEM_rptr(X509_CRL_INFO),
156 &x->crl.sig_alg, &x->sig_alg, &x->signature,
160 #ifndef OPENSSL_NO_OCSP
161 int X509_CRL_http_nbio(OCSP_REQ_CTX *rctx, X509_CRL **pcrl)
163 return OCSP_REQ_CTX_nbio_d2i(rctx,
165 ASN1_ITEM_rptr(X509_CRL));
169 int NETSCAPE_SPKI_sign(NETSCAPE_SPKI *x, EVP_PKEY *pkey, const EVP_MD *md)
171 return (ASN1_item_sign(ASN1_ITEM_rptr(NETSCAPE_SPKAC), &x->sig_algor, NULL,
172 x->signature, x->spkac, pkey, md));
175 #ifndef OPENSSL_NO_STDIO
176 X509 *d2i_X509_fp(FILE *fp, X509 **x509)
178 return ASN1_item_d2i_fp(ASN1_ITEM_rptr(X509), fp, x509);
181 int i2d_X509_fp(FILE *fp, const X509 *x509)
183 return ASN1_item_i2d_fp(ASN1_ITEM_rptr(X509), fp, x509);
187 X509 *d2i_X509_bio(BIO *bp, X509 **x509)
189 return ASN1_item_d2i_bio(ASN1_ITEM_rptr(X509), bp, x509);
192 int i2d_X509_bio(BIO *bp, const X509 *x509)
194 return ASN1_item_i2d_bio(ASN1_ITEM_rptr(X509), bp, x509);
197 #ifndef OPENSSL_NO_STDIO
198 X509_CRL *d2i_X509_CRL_fp(FILE *fp, X509_CRL **crl)
200 return ASN1_item_d2i_fp(ASN1_ITEM_rptr(X509_CRL), fp, crl);
203 int i2d_X509_CRL_fp(FILE *fp, const X509_CRL *crl)
205 return ASN1_item_i2d_fp(ASN1_ITEM_rptr(X509_CRL), fp, crl);
209 X509_CRL *d2i_X509_CRL_bio(BIO *bp, X509_CRL **crl)
211 return ASN1_item_d2i_bio(ASN1_ITEM_rptr(X509_CRL), bp, crl);
214 int i2d_X509_CRL_bio(BIO *bp, const X509_CRL *crl)
216 return ASN1_item_i2d_bio(ASN1_ITEM_rptr(X509_CRL), bp, crl);
219 #ifndef OPENSSL_NO_STDIO
220 PKCS7 *d2i_PKCS7_fp(FILE *fp, PKCS7 **p7)
222 return ASN1_item_d2i_fp(ASN1_ITEM_rptr(PKCS7), fp, p7);
225 int i2d_PKCS7_fp(FILE *fp, const PKCS7 *p7)
227 return ASN1_item_i2d_fp(ASN1_ITEM_rptr(PKCS7), fp, p7);
231 PKCS7 *d2i_PKCS7_bio(BIO *bp, PKCS7 **p7)
233 return ASN1_item_d2i_bio(ASN1_ITEM_rptr(PKCS7), bp, p7);
236 int i2d_PKCS7_bio(BIO *bp, const PKCS7 *p7)
238 return ASN1_item_i2d_bio(ASN1_ITEM_rptr(PKCS7), bp, p7);
241 #ifndef OPENSSL_NO_STDIO
242 X509_REQ *d2i_X509_REQ_fp(FILE *fp, X509_REQ **req)
244 return ASN1_item_d2i_fp(ASN1_ITEM_rptr(X509_REQ), fp, req);
247 int i2d_X509_REQ_fp(FILE *fp, const X509_REQ *req)
249 return ASN1_item_i2d_fp(ASN1_ITEM_rptr(X509_REQ), fp, req);
253 X509_REQ *d2i_X509_REQ_bio(BIO *bp, X509_REQ **req)
255 return ASN1_item_d2i_bio(ASN1_ITEM_rptr(X509_REQ), bp, req);
258 int i2d_X509_REQ_bio(BIO *bp, const X509_REQ *req)
260 return ASN1_item_i2d_bio(ASN1_ITEM_rptr(X509_REQ), bp, req);
263 #ifndef OPENSSL_NO_RSA
265 # ifndef OPENSSL_NO_STDIO
266 RSA *d2i_RSAPrivateKey_fp(FILE *fp, RSA **rsa)
268 return ASN1_item_d2i_fp(ASN1_ITEM_rptr(RSAPrivateKey), fp, rsa);
271 int i2d_RSAPrivateKey_fp(FILE *fp, const RSA *rsa)
273 return ASN1_item_i2d_fp(ASN1_ITEM_rptr(RSAPrivateKey), fp, rsa);
276 RSA *d2i_RSAPublicKey_fp(FILE *fp, RSA **rsa)
278 return ASN1_item_d2i_fp(ASN1_ITEM_rptr(RSAPublicKey), fp, rsa);
281 RSA *d2i_RSA_PUBKEY_fp(FILE *fp, RSA **rsa)
283 return ASN1_d2i_fp((void *(*)(void))
284 RSA_new, (D2I_OF(void)) d2i_RSA_PUBKEY, fp,
288 int i2d_RSAPublicKey_fp(FILE *fp, const RSA *rsa)
290 return ASN1_item_i2d_fp(ASN1_ITEM_rptr(RSAPublicKey), fp, rsa);
293 int i2d_RSA_PUBKEY_fp(FILE *fp, const RSA *rsa)
295 return ASN1_i2d_fp((I2D_OF(void))i2d_RSA_PUBKEY, fp, rsa);
299 RSA *d2i_RSAPrivateKey_bio(BIO *bp, RSA **rsa)
301 return ASN1_item_d2i_bio(ASN1_ITEM_rptr(RSAPrivateKey), bp, rsa);
304 int i2d_RSAPrivateKey_bio(BIO *bp, const RSA *rsa)
306 return ASN1_item_i2d_bio(ASN1_ITEM_rptr(RSAPrivateKey), bp, rsa);
309 RSA *d2i_RSAPublicKey_bio(BIO *bp, RSA **rsa)
311 return ASN1_item_d2i_bio(ASN1_ITEM_rptr(RSAPublicKey), bp, rsa);
314 RSA *d2i_RSA_PUBKEY_bio(BIO *bp, RSA **rsa)
316 return ASN1_d2i_bio_of(RSA, RSA_new, d2i_RSA_PUBKEY, bp, rsa);
319 int i2d_RSAPublicKey_bio(BIO *bp, const RSA *rsa)
321 return ASN1_item_i2d_bio(ASN1_ITEM_rptr(RSAPublicKey), bp, rsa);
324 int i2d_RSA_PUBKEY_bio(BIO *bp, const RSA *rsa)
326 return ASN1_i2d_bio_of(RSA, i2d_RSA_PUBKEY, bp, rsa);
330 #ifndef OPENSSL_NO_DSA
331 # ifndef OPENSSL_NO_STDIO
332 DSA *d2i_DSAPrivateKey_fp(FILE *fp, DSA **dsa)
334 return ASN1_d2i_fp_of(DSA, DSA_new, d2i_DSAPrivateKey, fp, dsa);
337 int i2d_DSAPrivateKey_fp(FILE *fp, const DSA *dsa)
339 return ASN1_i2d_fp_of(DSA, i2d_DSAPrivateKey, fp, dsa);
342 DSA *d2i_DSA_PUBKEY_fp(FILE *fp, DSA **dsa)
344 return ASN1_d2i_fp_of(DSA, DSA_new, d2i_DSA_PUBKEY, fp, dsa);
347 int i2d_DSA_PUBKEY_fp(FILE *fp, const DSA *dsa)
349 return ASN1_i2d_fp_of(DSA, i2d_DSA_PUBKEY, fp, dsa);
353 DSA *d2i_DSAPrivateKey_bio(BIO *bp, DSA **dsa)
355 return ASN1_d2i_bio_of(DSA, DSA_new, d2i_DSAPrivateKey, bp, dsa);
358 int i2d_DSAPrivateKey_bio(BIO *bp, const DSA *dsa)
360 return ASN1_i2d_bio_of(DSA, i2d_DSAPrivateKey, bp, dsa);
363 DSA *d2i_DSA_PUBKEY_bio(BIO *bp, DSA **dsa)
365 return ASN1_d2i_bio_of(DSA, DSA_new, d2i_DSA_PUBKEY, bp, dsa);
368 int i2d_DSA_PUBKEY_bio(BIO *bp, const DSA *dsa)
370 return ASN1_i2d_bio_of(DSA, i2d_DSA_PUBKEY, bp, dsa);
375 #ifndef OPENSSL_NO_EC
376 # ifndef OPENSSL_NO_STDIO
377 EC_KEY *d2i_EC_PUBKEY_fp(FILE *fp, EC_KEY **eckey)
379 return ASN1_d2i_fp_of(EC_KEY, EC_KEY_new, d2i_EC_PUBKEY, fp, eckey);
382 int i2d_EC_PUBKEY_fp(FILE *fp, const EC_KEY *eckey)
384 return ASN1_i2d_fp_of(EC_KEY, i2d_EC_PUBKEY, fp, eckey);
387 EC_KEY *d2i_ECPrivateKey_fp(FILE *fp, EC_KEY **eckey)
389 return ASN1_d2i_fp_of(EC_KEY, EC_KEY_new, d2i_ECPrivateKey, fp, eckey);
392 int i2d_ECPrivateKey_fp(FILE *fp, const EC_KEY *eckey)
394 return ASN1_i2d_fp_of(EC_KEY, i2d_ECPrivateKey, fp, eckey);
397 EC_KEY *d2i_EC_PUBKEY_bio(BIO *bp, EC_KEY **eckey)
399 return ASN1_d2i_bio_of(EC_KEY, EC_KEY_new, d2i_EC_PUBKEY, bp, eckey);
402 int i2d_EC_PUBKEY_bio(BIO *bp, const EC_KEY *ecdsa)
404 return ASN1_i2d_bio_of(EC_KEY, i2d_EC_PUBKEY, bp, ecdsa);
407 EC_KEY *d2i_ECPrivateKey_bio(BIO *bp, EC_KEY **eckey)
409 return ASN1_d2i_bio_of(EC_KEY, EC_KEY_new, d2i_ECPrivateKey, bp, eckey);
412 int i2d_ECPrivateKey_bio(BIO *bp, const EC_KEY *eckey)
414 return ASN1_i2d_bio_of(EC_KEY, i2d_ECPrivateKey, bp, eckey);
418 int X509_pubkey_digest(const X509 *data, const EVP_MD *type,
419 unsigned char *md, unsigned int *len)
421 ASN1_BIT_STRING *key;
422 key = X509_get0_pubkey_bitstr(data);
425 return EVP_Digest(key->data, key->length, md, len, type, NULL);
428 int X509_digest(const X509 *data, const EVP_MD *type, unsigned char *md,
431 if (type == EVP_sha1() && (data->ex_flags & EXFLAG_SET) != 0) {
432 /* Asking for SHA1 and we already computed it. */
434 *len = sizeof(data->sha1_hash);
435 memcpy(md, data->sha1_hash, sizeof(data->sha1_hash));
438 return (ASN1_item_digest
439 (ASN1_ITEM_rptr(X509), type, (char *)data, md, len));
442 int X509_CRL_digest(const X509_CRL *data, const EVP_MD *type,
443 unsigned char *md, unsigned int *len)
445 if (type == EVP_sha1() && (data->flags & EXFLAG_SET) != 0) {
446 /* Asking for SHA1; always computed in CRL d2i. */
448 *len = sizeof(data->sha1_hash);
449 memcpy(md, data->sha1_hash, sizeof(data->sha1_hash));
452 return (ASN1_item_digest
453 (ASN1_ITEM_rptr(X509_CRL), type, (char *)data, md, len));
456 int X509_REQ_digest(const X509_REQ *data, const EVP_MD *type,
457 unsigned char *md, unsigned int *len)
459 return (ASN1_item_digest
460 (ASN1_ITEM_rptr(X509_REQ), type, (char *)data, md, len));
463 int X509_NAME_digest(const X509_NAME *data, const EVP_MD *type,
464 unsigned char *md, unsigned int *len)
466 return (ASN1_item_digest
467 (ASN1_ITEM_rptr(X509_NAME), type, (char *)data, md, len));
470 int PKCS7_ISSUER_AND_SERIAL_digest(PKCS7_ISSUER_AND_SERIAL *data,
471 const EVP_MD *type, unsigned char *md,
474 return (ASN1_item_digest(ASN1_ITEM_rptr(PKCS7_ISSUER_AND_SERIAL), type,
475 (char *)data, md, len));
478 #ifndef OPENSSL_NO_STDIO
479 X509_SIG *d2i_PKCS8_fp(FILE *fp, X509_SIG **p8)
481 return ASN1_d2i_fp_of(X509_SIG, X509_SIG_new, d2i_X509_SIG, fp, p8);
484 int i2d_PKCS8_fp(FILE *fp, const X509_SIG *p8)
486 return ASN1_i2d_fp_of(X509_SIG, i2d_X509_SIG, fp, p8);
490 X509_SIG *d2i_PKCS8_bio(BIO *bp, X509_SIG **p8)
492 return ASN1_d2i_bio_of(X509_SIG, X509_SIG_new, d2i_X509_SIG, bp, p8);
495 int i2d_PKCS8_bio(BIO *bp, const X509_SIG *p8)
497 return ASN1_i2d_bio_of(X509_SIG, i2d_X509_SIG, bp, p8);
500 #ifndef OPENSSL_NO_STDIO
501 X509_PUBKEY *d2i_X509_PUBKEY_fp(FILE *fp, X509_PUBKEY **xpk)
503 return ASN1_d2i_fp_of(X509_PUBKEY, X509_PUBKEY_new, d2i_X509_PUBKEY,
507 int i2d_X509_PUBKEY_fp(FILE *fp, const X509_PUBKEY *xpk)
509 return ASN1_i2d_fp_of(X509_PUBKEY, i2d_X509_PUBKEY, fp, xpk);
513 X509_PUBKEY *d2i_X509_PUBKEY_bio(BIO *bp, X509_PUBKEY **xpk)
515 return ASN1_d2i_bio_of(X509_PUBKEY, X509_PUBKEY_new, d2i_X509_PUBKEY,
519 int i2d_X509_PUBKEY_bio(BIO *bp, const X509_PUBKEY *xpk)
521 return ASN1_i2d_bio_of(X509_PUBKEY, i2d_X509_PUBKEY, bp, xpk);
524 #ifndef OPENSSL_NO_STDIO
525 PKCS8_PRIV_KEY_INFO *d2i_PKCS8_PRIV_KEY_INFO_fp(FILE *fp,
526 PKCS8_PRIV_KEY_INFO **p8inf)
528 return ASN1_d2i_fp_of(PKCS8_PRIV_KEY_INFO, PKCS8_PRIV_KEY_INFO_new,
529 d2i_PKCS8_PRIV_KEY_INFO, fp, p8inf);
532 int i2d_PKCS8_PRIV_KEY_INFO_fp(FILE *fp, const PKCS8_PRIV_KEY_INFO *p8inf)
534 return ASN1_i2d_fp_of(PKCS8_PRIV_KEY_INFO, i2d_PKCS8_PRIV_KEY_INFO, fp,
538 int i2d_PKCS8PrivateKeyInfo_fp(FILE *fp, const EVP_PKEY *key)
540 PKCS8_PRIV_KEY_INFO *p8inf;
543 p8inf = EVP_PKEY2PKCS8(key);
546 ret = i2d_PKCS8_PRIV_KEY_INFO_fp(fp, p8inf);
547 PKCS8_PRIV_KEY_INFO_free(p8inf);
551 int i2d_PrivateKey_fp(FILE *fp, const EVP_PKEY *pkey)
553 return ASN1_i2d_fp_of(EVP_PKEY, i2d_PrivateKey, fp, pkey);
556 EVP_PKEY *d2i_PrivateKey_fp(FILE *fp, EVP_PKEY **a)
558 return ASN1_d2i_fp_of(EVP_PKEY, EVP_PKEY_new, d2i_AutoPrivateKey, fp, a);
561 int i2d_PUBKEY_fp(FILE *fp, const EVP_PKEY *pkey)
563 return ASN1_i2d_fp_of(EVP_PKEY, i2d_PUBKEY, fp, pkey);
566 EVP_PKEY *d2i_PUBKEY_fp(FILE *fp, EVP_PKEY **a)
568 return ASN1_d2i_fp_of(EVP_PKEY, EVP_PKEY_new, d2i_PUBKEY, fp, a);
573 PKCS8_PRIV_KEY_INFO *d2i_PKCS8_PRIV_KEY_INFO_bio(BIO *bp,
574 PKCS8_PRIV_KEY_INFO **p8inf)
576 return ASN1_d2i_bio_of(PKCS8_PRIV_KEY_INFO, PKCS8_PRIV_KEY_INFO_new,
577 d2i_PKCS8_PRIV_KEY_INFO, bp, p8inf);
580 int i2d_PKCS8_PRIV_KEY_INFO_bio(BIO *bp, const PKCS8_PRIV_KEY_INFO *p8inf)
582 return ASN1_i2d_bio_of(PKCS8_PRIV_KEY_INFO, i2d_PKCS8_PRIV_KEY_INFO, bp,
586 int i2d_PKCS8PrivateKeyInfo_bio(BIO *bp, const EVP_PKEY *key)
588 PKCS8_PRIV_KEY_INFO *p8inf;
591 p8inf = EVP_PKEY2PKCS8(key);
594 ret = i2d_PKCS8_PRIV_KEY_INFO_bio(bp, p8inf);
595 PKCS8_PRIV_KEY_INFO_free(p8inf);
599 int i2d_PrivateKey_bio(BIO *bp, const EVP_PKEY *pkey)
601 return ASN1_i2d_bio_of(EVP_PKEY, i2d_PrivateKey, bp, pkey);
604 EVP_PKEY *d2i_PrivateKey_bio(BIO *bp, EVP_PKEY **a)
606 return ASN1_d2i_bio_of(EVP_PKEY, EVP_PKEY_new, d2i_AutoPrivateKey, bp, a);
609 int i2d_PUBKEY_bio(BIO *bp, const EVP_PKEY *pkey)
611 return ASN1_i2d_bio_of(EVP_PKEY, i2d_PUBKEY, bp, pkey);
614 EVP_PKEY *d2i_PUBKEY_bio(BIO *bp, EVP_PKEY **a)
616 return ASN1_d2i_bio_of(EVP_PKEY, EVP_PKEY_new, d2i_PUBKEY, bp, a);