-
Notifications
You must be signed in to change notification settings - Fork 92
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Work towards supporting Cryptographic Message Syntax (CMS) in libcrypto.
Cryptographic Message Syntax (CMS) is a standard for cryptographically protecting messages, as defined in RFC 5652. It is derived from PKCS #7 version 1.5 and utilises various ASN.1 structures, making it complex and fairly heavyweight. Various protocols - including RPKI (RFC 6480) - have been built on top of it, which means it is necessary to support CMS, in order to support RPKI. This imports around 6,000 lines of code from OpenSSL 1.1.1, which is still under the original OpenSSL license. Further work will occur in tree. Requested by and discussed with many. ok deraadt@ tb@
- Loading branch information
jsing
committed
Aug 10, 2019
1 parent
140472e
commit b7b5eaa
Showing
15 changed files
with
6,172 additions
and
0 deletions.
There are no files selected for viewing
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,152 @@ | ||
/* | ||
* Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved. | ||
* | ||
* Licensed under the OpenSSL license (the "License"). You may not use | ||
* this file except in compliance with the License. You can obtain a copy | ||
* in the file LICENSE in the source distribution or at | ||
* https://www.openssl.org/source/license.html | ||
*/ | ||
|
||
#include <openssl/asn1t.h> | ||
#include <openssl/pem.h> | ||
#include <openssl/x509v3.h> | ||
#include <openssl/err.h> | ||
#include <openssl/cms.h> | ||
#include "cms_lcl.h" | ||
|
||
/* CMS SignedData Attribute utilities */ | ||
|
||
int CMS_signed_get_attr_count(const CMS_SignerInfo *si) | ||
{ | ||
return X509at_get_attr_count(si->signedAttrs); | ||
} | ||
|
||
int CMS_signed_get_attr_by_NID(const CMS_SignerInfo *si, int nid, int lastpos) | ||
{ | ||
return X509at_get_attr_by_NID(si->signedAttrs, nid, lastpos); | ||
} | ||
|
||
int CMS_signed_get_attr_by_OBJ(const CMS_SignerInfo *si, const ASN1_OBJECT *obj, | ||
int lastpos) | ||
{ | ||
return X509at_get_attr_by_OBJ(si->signedAttrs, obj, lastpos); | ||
} | ||
|
||
X509_ATTRIBUTE *CMS_signed_get_attr(const CMS_SignerInfo *si, int loc) | ||
{ | ||
return X509at_get_attr(si->signedAttrs, loc); | ||
} | ||
|
||
X509_ATTRIBUTE *CMS_signed_delete_attr(CMS_SignerInfo *si, int loc) | ||
{ | ||
return X509at_delete_attr(si->signedAttrs, loc); | ||
} | ||
|
||
int CMS_signed_add1_attr(CMS_SignerInfo *si, X509_ATTRIBUTE *attr) | ||
{ | ||
if (X509at_add1_attr(&si->signedAttrs, attr)) | ||
return 1; | ||
return 0; | ||
} | ||
|
||
int CMS_signed_add1_attr_by_OBJ(CMS_SignerInfo *si, | ||
const ASN1_OBJECT *obj, int type, | ||
const void *bytes, int len) | ||
{ | ||
if (X509at_add1_attr_by_OBJ(&si->signedAttrs, obj, type, bytes, len)) | ||
return 1; | ||
return 0; | ||
} | ||
|
||
int CMS_signed_add1_attr_by_NID(CMS_SignerInfo *si, | ||
int nid, int type, const void *bytes, int len) | ||
{ | ||
if (X509at_add1_attr_by_NID(&si->signedAttrs, nid, type, bytes, len)) | ||
return 1; | ||
return 0; | ||
} | ||
|
||
int CMS_signed_add1_attr_by_txt(CMS_SignerInfo *si, | ||
const char *attrname, int type, | ||
const void *bytes, int len) | ||
{ | ||
if (X509at_add1_attr_by_txt(&si->signedAttrs, attrname, type, bytes, len)) | ||
return 1; | ||
return 0; | ||
} | ||
|
||
void *CMS_signed_get0_data_by_OBJ(CMS_SignerInfo *si, const ASN1_OBJECT *oid, | ||
int lastpos, int type) | ||
{ | ||
return X509at_get0_data_by_OBJ(si->signedAttrs, oid, lastpos, type); | ||
} | ||
|
||
int CMS_unsigned_get_attr_count(const CMS_SignerInfo *si) | ||
{ | ||
return X509at_get_attr_count(si->unsignedAttrs); | ||
} | ||
|
||
int CMS_unsigned_get_attr_by_NID(const CMS_SignerInfo *si, int nid, | ||
int lastpos) | ||
{ | ||
return X509at_get_attr_by_NID(si->unsignedAttrs, nid, lastpos); | ||
} | ||
|
||
int CMS_unsigned_get_attr_by_OBJ(const CMS_SignerInfo *si, | ||
const ASN1_OBJECT *obj, int lastpos) | ||
{ | ||
return X509at_get_attr_by_OBJ(si->unsignedAttrs, obj, lastpos); | ||
} | ||
|
||
X509_ATTRIBUTE *CMS_unsigned_get_attr(const CMS_SignerInfo *si, int loc) | ||
{ | ||
return X509at_get_attr(si->unsignedAttrs, loc); | ||
} | ||
|
||
X509_ATTRIBUTE *CMS_unsigned_delete_attr(CMS_SignerInfo *si, int loc) | ||
{ | ||
return X509at_delete_attr(si->unsignedAttrs, loc); | ||
} | ||
|
||
int CMS_unsigned_add1_attr(CMS_SignerInfo *si, X509_ATTRIBUTE *attr) | ||
{ | ||
if (X509at_add1_attr(&si->unsignedAttrs, attr)) | ||
return 1; | ||
return 0; | ||
} | ||
|
||
int CMS_unsigned_add1_attr_by_OBJ(CMS_SignerInfo *si, | ||
const ASN1_OBJECT *obj, int type, | ||
const void *bytes, int len) | ||
{ | ||
if (X509at_add1_attr_by_OBJ(&si->unsignedAttrs, obj, type, bytes, len)) | ||
return 1; | ||
return 0; | ||
} | ||
|
||
int CMS_unsigned_add1_attr_by_NID(CMS_SignerInfo *si, | ||
int nid, int type, | ||
const void *bytes, int len) | ||
{ | ||
if (X509at_add1_attr_by_NID(&si->unsignedAttrs, nid, type, bytes, len)) | ||
return 1; | ||
return 0; | ||
} | ||
|
||
int CMS_unsigned_add1_attr_by_txt(CMS_SignerInfo *si, | ||
const char *attrname, int type, | ||
const void *bytes, int len) | ||
{ | ||
if (X509at_add1_attr_by_txt(&si->unsignedAttrs, attrname, | ||
type, bytes, len)) | ||
return 1; | ||
return 0; | ||
} | ||
|
||
void *CMS_unsigned_get0_data_by_OBJ(CMS_SignerInfo *si, ASN1_OBJECT *oid, | ||
int lastpos, int type) | ||
{ | ||
return X509at_get0_data_by_OBJ(si->unsignedAttrs, oid, lastpos, type); | ||
} | ||
|
||
/* Specific attribute cases */ |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,82 @@ | ||
/* | ||
* Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved. | ||
* | ||
* Licensed under the OpenSSL license (the "License"). You may not use | ||
* this file except in compliance with the License. You can obtain a copy | ||
* in the file LICENSE in the source distribution or at | ||
* https://www.openssl.org/source/license.html | ||
*/ | ||
|
||
#include "internal/cryptlib.h" | ||
#include <openssl/asn1t.h> | ||
#include <openssl/pem.h> | ||
#include <openssl/x509v3.h> | ||
#include <openssl/err.h> | ||
#include <openssl/cms.h> | ||
#include <openssl/bio.h> | ||
#include <openssl/comp.h> | ||
#include "cms_lcl.h" | ||
|
||
#ifdef ZLIB | ||
|
||
/* CMS CompressedData Utilities */ | ||
|
||
CMS_ContentInfo *cms_CompressedData_create(int comp_nid) | ||
{ | ||
CMS_ContentInfo *cms; | ||
CMS_CompressedData *cd; | ||
/* | ||
* Will need something cleverer if there is ever more than one | ||
* compression algorithm or parameters have some meaning... | ||
*/ | ||
if (comp_nid != NID_zlib_compression) { | ||
CMSerr(CMS_F_CMS_COMPRESSEDDATA_CREATE, | ||
CMS_R_UNSUPPORTED_COMPRESSION_ALGORITHM); | ||
return NULL; | ||
} | ||
cms = CMS_ContentInfo_new(); | ||
if (cms == NULL) | ||
return NULL; | ||
|
||
cd = M_ASN1_new_of(CMS_CompressedData); | ||
|
||
if (cd == NULL) | ||
goto err; | ||
|
||
cms->contentType = OBJ_nid2obj(NID_id_smime_ct_compressedData); | ||
cms->d.compressedData = cd; | ||
|
||
cd->version = 0; | ||
|
||
X509_ALGOR_set0(cd->compressionAlgorithm, | ||
OBJ_nid2obj(NID_zlib_compression), V_ASN1_UNDEF, NULL); | ||
|
||
cd->encapContentInfo->eContentType = OBJ_nid2obj(NID_pkcs7_data); | ||
|
||
return cms; | ||
|
||
err: | ||
CMS_ContentInfo_free(cms); | ||
return NULL; | ||
} | ||
|
||
BIO *cms_CompressedData_init_bio(CMS_ContentInfo *cms) | ||
{ | ||
CMS_CompressedData *cd; | ||
const ASN1_OBJECT *compoid; | ||
if (OBJ_obj2nid(cms->contentType) != NID_id_smime_ct_compressedData) { | ||
CMSerr(CMS_F_CMS_COMPRESSEDDATA_INIT_BIO, | ||
CMS_R_CONTENT_TYPE_NOT_COMPRESSED_DATA); | ||
return NULL; | ||
} | ||
cd = cms->d.compressedData; | ||
X509_ALGOR_get0(&compoid, NULL, NULL, cd->compressionAlgorithm); | ||
if (OBJ_obj2nid(compoid) != NID_zlib_compression) { | ||
CMSerr(CMS_F_CMS_COMPRESSEDDATA_INIT_BIO, | ||
CMS_R_UNSUPPORTED_COMPRESSION_ALGORITHM); | ||
return NULL; | ||
} | ||
return BIO_new(BIO_f_zlib()); | ||
} | ||
|
||
#endif |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,99 @@ | ||
/* | ||
* Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved. | ||
* | ||
* Licensed under the OpenSSL license (the "License"). You may not use | ||
* this file except in compliance with the License. You can obtain a copy | ||
* in the file LICENSE in the source distribution or at | ||
* https://www.openssl.org/source/license.html | ||
*/ | ||
|
||
#include "internal/cryptlib.h" | ||
#include <openssl/asn1t.h> | ||
#include <openssl/pem.h> | ||
#include <openssl/x509v3.h> | ||
#include <openssl/err.h> | ||
#include <openssl/cms.h> | ||
#include "cms_lcl.h" | ||
|
||
/* CMS DigestedData Utilities */ | ||
|
||
CMS_ContentInfo *cms_DigestedData_create(const EVP_MD *md) | ||
{ | ||
CMS_ContentInfo *cms; | ||
CMS_DigestedData *dd; | ||
cms = CMS_ContentInfo_new(); | ||
if (cms == NULL) | ||
return NULL; | ||
|
||
dd = M_ASN1_new_of(CMS_DigestedData); | ||
|
||
if (dd == NULL) | ||
goto err; | ||
|
||
cms->contentType = OBJ_nid2obj(NID_pkcs7_digest); | ||
cms->d.digestedData = dd; | ||
|
||
dd->version = 0; | ||
dd->encapContentInfo->eContentType = OBJ_nid2obj(NID_pkcs7_data); | ||
|
||
X509_ALGOR_set_md(dd->digestAlgorithm, md); | ||
|
||
return cms; | ||
|
||
err: | ||
CMS_ContentInfo_free(cms); | ||
return NULL; | ||
} | ||
|
||
BIO *cms_DigestedData_init_bio(CMS_ContentInfo *cms) | ||
{ | ||
CMS_DigestedData *dd; | ||
dd = cms->d.digestedData; | ||
return cms_DigestAlgorithm_init_bio(dd->digestAlgorithm); | ||
} | ||
|
||
int cms_DigestedData_do_final(CMS_ContentInfo *cms, BIO *chain, int verify) | ||
{ | ||
EVP_MD_CTX *mctx = EVP_MD_CTX_new(); | ||
unsigned char md[EVP_MAX_MD_SIZE]; | ||
unsigned int mdlen; | ||
int r = 0; | ||
CMS_DigestedData *dd; | ||
|
||
if (mctx == NULL) { | ||
CMSerr(CMS_F_CMS_DIGESTEDDATA_DO_FINAL, ERR_R_MALLOC_FAILURE); | ||
goto err; | ||
} | ||
|
||
dd = cms->d.digestedData; | ||
|
||
if (!cms_DigestAlgorithm_find_ctx(mctx, chain, dd->digestAlgorithm)) | ||
goto err; | ||
|
||
if (EVP_DigestFinal_ex(mctx, md, &mdlen) <= 0) | ||
goto err; | ||
|
||
if (verify) { | ||
if (mdlen != (unsigned int)dd->digest->length) { | ||
CMSerr(CMS_F_CMS_DIGESTEDDATA_DO_FINAL, | ||
CMS_R_MESSAGEDIGEST_WRONG_LENGTH); | ||
goto err; | ||
} | ||
|
||
if (memcmp(md, dd->digest->data, mdlen)) | ||
CMSerr(CMS_F_CMS_DIGESTEDDATA_DO_FINAL, | ||
CMS_R_VERIFICATION_FAILURE); | ||
else | ||
r = 1; | ||
} else { | ||
if (!ASN1_STRING_set(dd->digest, md, mdlen)) | ||
goto err; | ||
r = 1; | ||
} | ||
|
||
err: | ||
EVP_MD_CTX_free(mctx); | ||
|
||
return r; | ||
|
||
} |
Oops, something went wrong.