Branch data Line data Source code
1 : : /* 2 : : * Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved. 3 : : * 4 : : * Licensed under the Apache License, Version 2.0 (the "License"). 5 : : * You may not use this file except in compliance with the License. 6 : : * A copy of the License is located at 7 : : * 8 : : * http://aws.amazon.com/apache2.0 9 : : * 10 : : * or in the "license" file accompanying this file. This file is distributed 11 : : * on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either 12 : : * express or implied. See the License for the specific language governing 13 : : * permissions and limitations under the License. 14 : : */ 15 : : 16 : : #pragma once 17 : : 18 : : #include <openssl/asn1.h> 19 : : #include <openssl/x509.h> 20 : : #include <stdint.h> 21 : : 22 : : #include "crypto/s2n_certificate.h" 23 : : #include "utils/s2n_blob.h" 24 : : #include "utils/s2n_safety.h" 25 : : 26 : : /* OpenSSL 4.0 and AWS-LC return const pointers from the X509 getters. Older 27 : : * OpenSSL returns non-const. Qualify the declaration instead of duplicating it. 28 : : */ 29 : : #if defined(S2N_LIBCRYPTO_SUPPORTS_CONST_X509_GETTERS) 30 : : #define S2N_X509_CONST const 31 : : #else 32 : : #define S2N_X509_CONST 33 : : #endif 34 : : 35 : : /* ASN1_STRING_data was removed in OpenSSL 4.0. Its replacement returns const. */ 36 : : #if defined(S2N_LIBCRYPTO_SUPPORTS_ASN1_STRING_GET0_DATA) 37 : 1079 : #define S2N_ASN1_STRING_DATA(str) ASN1_STRING_get0_data(str) 38 : : #else 39 : : #define S2N_ASN1_STRING_DATA(str) ASN1_STRING_data(str) 40 : : #endif 41 : : 42 : : #define S2N_MAX_ALLOWED_CERT_TRAILING_BYTES 3 43 : : 44 : : DEFINE_POINTER_CLEANUP_FUNC(X509 *, X509_free); 45 : : 46 : : S2N_CLEANUP_RESULT s2n_openssl_x509_stack_pop_free(STACK_OF(X509) **cert_chain); 47 : : 48 : : S2N_CLEANUP_RESULT s2n_openssl_asn1_time_free_pointer(ASN1_GENERALIZEDTIME **time); 49 : : 50 : : /* 51 : : * This function is used to convert an s2n_blob into an openssl X509 cert. It 52 : : * will additionally ensure that there are 3 or fewer trailing bytes in 53 : : * `asn1der`. 54 : : */ 55 : : S2N_RESULT s2n_openssl_x509_parse(struct s2n_blob *asn1der, X509 **cert_out); 56 : : 57 : : /* 58 : : * This function is used to convert an s2n_blob into an openssl X509 cert. 59 : : * Unlike `s2n_openssl_x509_parse` no additional validation is done. This 60 : : * function should only be used in places where it is necessary to maintain 61 : : * compatibility with previous permissive parsing behavior. 62 : : */ 63 : : S2N_RESULT s2n_openssl_x509_parse_without_length_validation(struct s2n_blob *asn1der, X509 **cert_out); 64 : : 65 : : S2N_RESULT s2n_openssl_x509_get_cert_info(X509 *cert, struct s2n_cert_info *info);