os/ossrv/ssl/tsrc/topenssl/src/crl.c
author sl@SLION-WIN7.fritz.box
Fri, 15 Jun 2012 03:10:57 +0200
changeset 0 bde4ae8d615e
permissions -rw-r--r--
First public contribution.
sl@0
     1
/* apps/crl.c */
sl@0
     2
/* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
sl@0
     3
 * All rights reserved.
sl@0
     4
 *
sl@0
     5
 * This package is an SSL implementation written
sl@0
     6
 * by Eric Young (eay@cryptsoft.com).
sl@0
     7
 * The implementation was written so as to conform with Netscapes SSL.
sl@0
     8
 * 
sl@0
     9
 * This library is free for commercial and non-commercial use as long as
sl@0
    10
 * the following conditions are aheared to.  The following conditions
sl@0
    11
 * apply to all code found in this distribution, be it the RC4, RSA,
sl@0
    12
 * lhash, DES, etc., code; not just the SSL code.  The SSL documentation
sl@0
    13
 * included with this distribution is covered by the same copyright terms
sl@0
    14
 * except that the holder is Tim Hudson (tjh@cryptsoft.com).
sl@0
    15
 * 
sl@0
    16
 * Copyright remains Eric Young's, and as such any Copyright notices in
sl@0
    17
 * the code are not to be removed.
sl@0
    18
 * If this package is used in a product, Eric Young should be given attribution
sl@0
    19
 * as the author of the parts of the library used.
sl@0
    20
 * This can be in the form of a textual message at program startup or
sl@0
    21
 * in documentation (online or textual) provided with the package.
sl@0
    22
 * 
sl@0
    23
 * Redistribution and use in source and binary forms, with or without
sl@0
    24
 * modification, are permitted provided that the following conditions
sl@0
    25
 * are met:
sl@0
    26
 * 1. Redistributions of source code must retain the copyright
sl@0
    27
 *    notice, this list of conditions and the following disclaimer.
sl@0
    28
 * 2. Redistributions in binary form must reproduce the above copyright
sl@0
    29
 *    notice, this list of conditions and the following disclaimer in the
sl@0
    30
 *    documentation and/or other materials provided with the distribution.
sl@0
    31
 * 3. All advertising materials mentioning features or use of this software
sl@0
    32
 *    must display the following acknowledgement:
sl@0
    33
 *    "This product includes cryptographic software written by
sl@0
    34
 *     Eric Young (eay@cryptsoft.com)"
sl@0
    35
 *    The word 'cryptographic' can be left out if the rouines from the library
sl@0
    36
 *    being used are not cryptographic related :-).
sl@0
    37
 * 4. If you include any Windows specific code (or a derivative thereof) from 
sl@0
    38
 *    the apps directory (application code) you must include an acknowledgement:
sl@0
    39
 *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
sl@0
    40
 * 
sl@0
    41
 * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
sl@0
    42
 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
sl@0
    43
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
sl@0
    44
 * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
sl@0
    45
 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
sl@0
    46
 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
sl@0
    47
 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
sl@0
    48
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
sl@0
    49
 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
sl@0
    50
 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
sl@0
    51
 * SUCH DAMAGE.
sl@0
    52
 * 
sl@0
    53
 * The licence and distribution terms for any publically available version or
sl@0
    54
 * derivative of this code cannot be changed.  i.e. this code cannot simply be
sl@0
    55
 * copied and put under another distribution licence
sl@0
    56
 * [including the GNU Public Licence.]
sl@0
    57
 */
sl@0
    58
sl@0
    59
#include <stdio.h>
sl@0
    60
#include <stdlib.h>
sl@0
    61
#include <string.h>
sl@0
    62
#include "apps.h"
sl@0
    63
#include <openssl/bio.h>
sl@0
    64
#include <openssl/err.h>
sl@0
    65
#include <openssl/x509.h>
sl@0
    66
#include <openssl/x509v3.h>
sl@0
    67
#include <openssl/pem.h>
sl@0
    68
sl@0
    69
#undef PROG
sl@0
    70
#define PROG	crl_main
sl@0
    71
sl@0
    72
#undef POSTFIX
sl@0
    73
#define	POSTFIX	".rvk"
sl@0
    74
sl@0
    75
static const char *crl_usage[]={
sl@0
    76
"usage: crl args\n",
sl@0
    77
"\n",
sl@0
    78
" -inform arg     - input format - default PEM (DER or PEM)\n",
sl@0
    79
" -outform arg    - output format - default PEM\n",
sl@0
    80
" -text           - print out a text format version\n",
sl@0
    81
" -in arg         - input file - default stdin\n",
sl@0
    82
" -out arg        - output file - default stdout\n",
sl@0
    83
" -hash           - print hash value\n",
sl@0
    84
" -fingerprint    - print the crl fingerprint\n",
sl@0
    85
" -issuer         - print issuer DN\n",
sl@0
    86
" -lastupdate     - lastUpdate field\n",
sl@0
    87
" -nextupdate     - nextUpdate field\n",
sl@0
    88
" -noout          - no CRL output\n",
sl@0
    89
" -CAfile  name   - verify CRL using certificates in file \"name\"\n",
sl@0
    90
" -CApath  dir    - verify CRL using certificates in \"dir\"\n",
sl@0
    91
" -nameopt arg    - various certificate name options\n",
sl@0
    92
NULL
sl@0
    93
};
sl@0
    94
sl@0
    95
static X509_CRL *load_crl(char *file, int format);
sl@0
    96
static BIO *bio_out=NULL;
sl@0
    97
sl@0
    98
sl@0
    99
int MAIN(int, char **);
sl@0
   100
sl@0
   101
int MAIN(int argc, char **argv)
sl@0
   102
	{
sl@0
   103
	unsigned long nmflag = 0;
sl@0
   104
	X509_CRL *x=NULL;
sl@0
   105
	char *CAfile = NULL, *CApath = NULL;
sl@0
   106
	int ret=1,i,num,badops=0;
sl@0
   107
	BIO *out=NULL;
sl@0
   108
	int informat,outformat;
sl@0
   109
	char *infile=NULL,*outfile=NULL;
sl@0
   110
	int hash=0,issuer=0,lastupdate=0,nextupdate=0,noout=0,text=0;
sl@0
   111
	int fingerprint = 0;
sl@0
   112
	const char **pp;
sl@0
   113
	X509_STORE *store = NULL;
sl@0
   114
	X509_STORE_CTX ctx;
sl@0
   115
	X509_LOOKUP *lookup = NULL;
sl@0
   116
	X509_OBJECT xobj;
sl@0
   117
	EVP_PKEY *pkey;
sl@0
   118
	int do_ver = 0;
sl@0
   119
	const EVP_MD *md_alg,*digest=EVP_sha1();
sl@0
   120
sl@0
   121
	apps_startup();
sl@0
   122
sl@0
   123
	if (bio_err == NULL)
sl@0
   124
		if ((bio_err=BIO_new(BIO_s_file())) != NULL)
sl@0
   125
			BIO_set_fp(bio_err,stderr,BIO_NOCLOSE|BIO_FP_TEXT);
sl@0
   126
	if (!load_config(bio_err, NULL))
sl@0
   127
		goto end;
sl@0
   128
sl@0
   129
	if (bio_out == NULL)
sl@0
   130
sl@0
   131
		if ((bio_out=BIO_new(BIO_s_file())) != NULL)
sl@0
   132
			{
sl@0
   133
			BIO_set_fp(bio_out,stdout,BIO_NOCLOSE);
sl@0
   134
	
sl@0
   135
#ifdef OPENSSL_SYS_VMS
sl@0
   136
			{
sl@0
   137
			BIO *tmpbio = BIO_new(BIO_f_linebuffer());
sl@0
   138
			bio_out = BIO_push(tmpbio, bio_out);
sl@0
   139
			}
sl@0
   140
#endif
sl@0
   141
			}
sl@0
   142
sl@0
   143
	informat=FORMAT_PEM;
sl@0
   144
	outformat=FORMAT_PEM;
sl@0
   145
sl@0
   146
	argc--;
sl@0
   147
	argv++;
sl@0
   148
	num=0;
sl@0
   149
	while (argc >= 1)
sl@0
   150
		{
sl@0
   151
#ifdef undef
sl@0
   152
		if	(strcmp(*argv,"-p") == 0)
sl@0
   153
			{
sl@0
   154
			if (--argc < 1) goto bad;
sl@0
   155
			if (!args_from_file(++argv,Nargc,Nargv)) { goto end; }*/
sl@0
   156
			}
sl@0
   157
#endif
sl@0
   158
		if 	(strcmp(*argv,"-inform") == 0)
sl@0
   159
			{
sl@0
   160
			if (--argc < 1) goto bad;
sl@0
   161
			informat=str2fmt(*(++argv));
sl@0
   162
			}
sl@0
   163
		else if (strcmp(*argv,"-outform") == 0)
sl@0
   164
			{
sl@0
   165
			if (--argc < 1) goto bad;
sl@0
   166
			outformat=str2fmt(*(++argv));
sl@0
   167
			}
sl@0
   168
		else if (strcmp(*argv,"-in") == 0)
sl@0
   169
			{
sl@0
   170
			if (--argc < 1) goto bad;
sl@0
   171
			infile= *(++argv);
sl@0
   172
			}
sl@0
   173
		else if (strcmp(*argv,"-out") == 0)
sl@0
   174
			{
sl@0
   175
			if (--argc < 1) goto bad;
sl@0
   176
			outfile= *(++argv);
sl@0
   177
			}
sl@0
   178
		else if (strcmp(*argv,"-CApath") == 0)
sl@0
   179
			{
sl@0
   180
			if (--argc < 1) goto bad;
sl@0
   181
			CApath = *(++argv);
sl@0
   182
			do_ver = 1;
sl@0
   183
			}
sl@0
   184
		else if (strcmp(*argv,"-CAfile") == 0)
sl@0
   185
			{
sl@0
   186
			if (--argc < 1) goto bad;
sl@0
   187
			CAfile = *(++argv);
sl@0
   188
			do_ver = 1;
sl@0
   189
			}
sl@0
   190
		else if (strcmp(*argv,"-verify") == 0)
sl@0
   191
			do_ver = 1;
sl@0
   192
		else if (strcmp(*argv,"-text") == 0)
sl@0
   193
			text = 1;
sl@0
   194
		else if (strcmp(*argv,"-hash") == 0)
sl@0
   195
			hash= ++num;
sl@0
   196
		else if (strcmp(*argv,"-nameopt") == 0)
sl@0
   197
			{
sl@0
   198
			if (--argc < 1) goto bad;
sl@0
   199
			if (!set_name_ex(&nmflag, *(++argv))) goto bad;
sl@0
   200
			}
sl@0
   201
		else if (strcmp(*argv,"-issuer") == 0)
sl@0
   202
			issuer= ++num;
sl@0
   203
		else if (strcmp(*argv,"-lastupdate") == 0)
sl@0
   204
			lastupdate= ++num;
sl@0
   205
		else if (strcmp(*argv,"-nextupdate") == 0)
sl@0
   206
			nextupdate= ++num;
sl@0
   207
		else if (strcmp(*argv,"-noout") == 0)
sl@0
   208
			noout= ++num;
sl@0
   209
		else if (strcmp(*argv,"-fingerprint") == 0)
sl@0
   210
			fingerprint= ++num;
sl@0
   211
		else if ((md_alg=EVP_get_digestbyname(*argv + 1)))
sl@0
   212
			{
sl@0
   213
			/* ok */
sl@0
   214
			digest=md_alg;
sl@0
   215
			}
sl@0
   216
		else
sl@0
   217
			{
sl@0
   218
			BIO_printf(bio_err,"unknown option %s\n",*argv);
sl@0
   219
			badops=1;
sl@0
   220
			break;
sl@0
   221
			}
sl@0
   222
		argc--;
sl@0
   223
		argv++;
sl@0
   224
		}
sl@0
   225
sl@0
   226
	if (badops)
sl@0
   227
		{
sl@0
   228
bad:
sl@0
   229
		for (pp=crl_usage; (*pp != NULL); pp++)
sl@0
   230
			BIO_printf(bio_err,"%s",*pp);
sl@0
   231
		goto end;
sl@0
   232
		}
sl@0
   233
sl@0
   234
	ERR_load_crypto_strings();
sl@0
   235
	x=load_crl(infile,informat);
sl@0
   236
	if (x == NULL) { goto end; }
sl@0
   237
sl@0
   238
	if(do_ver) {
sl@0
   239
		store = X509_STORE_new();
sl@0
   240
		lookup=X509_STORE_add_lookup(store,X509_LOOKUP_file());
sl@0
   241
		if (lookup == NULL) goto end;
sl@0
   242
		if (!X509_LOOKUP_load_file(lookup,CAfile,X509_FILETYPE_PEM))
sl@0
   243
			X509_LOOKUP_load_file(lookup,NULL,X509_FILETYPE_DEFAULT);
sl@0
   244
			
sl@0
   245
		lookup=X509_STORE_add_lookup(store,X509_LOOKUP_hash_dir());
sl@0
   246
		if (lookup == NULL) goto end;
sl@0
   247
		if (!X509_LOOKUP_add_dir(lookup,CApath,X509_FILETYPE_PEM))
sl@0
   248
			X509_LOOKUP_add_dir(lookup,NULL,X509_FILETYPE_DEFAULT);
sl@0
   249
		ERR_clear_error();
sl@0
   250
sl@0
   251
		if(!X509_STORE_CTX_init(&ctx, store, NULL, NULL)) {
sl@0
   252
			BIO_printf(bio_err,
sl@0
   253
				"Error initialising X509 store\n");
sl@0
   254
			goto end;
sl@0
   255
		}
sl@0
   256
sl@0
   257
		i = X509_STORE_get_by_subject(&ctx, X509_LU_X509, 
sl@0
   258
					X509_CRL_get_issuer(x), &xobj);
sl@0
   259
		if(i <= 0) {
sl@0
   260
			BIO_printf(bio_err,
sl@0
   261
				"Error getting CRL issuer certificate\n");
sl@0
   262
			goto end;
sl@0
   263
		}
sl@0
   264
		pkey = X509_get_pubkey(xobj.data.x509);
sl@0
   265
		X509_OBJECT_free_contents(&xobj);
sl@0
   266
		if(!pkey) {
sl@0
   267
			BIO_printf(bio_err,
sl@0
   268
				"Error getting CRL issuer public key\n");
sl@0
   269
			goto end;
sl@0
   270
		}
sl@0
   271
		i = X509_CRL_verify(x, pkey);
sl@0
   272
		EVP_PKEY_free(pkey);
sl@0
   273
		if(i < 0) goto end;
sl@0
   274
		if(i == 0) BIO_printf(bio_err, "verify failure\n");
sl@0
   275
		else BIO_printf(bio_err, "verify OK\n");
sl@0
   276
	}
sl@0
   277
sl@0
   278
	if (num)
sl@0
   279
		{
sl@0
   280
		for (i=1; i<=num; i++)
sl@0
   281
			{
sl@0
   282
			if (issuer == i)
sl@0
   283
				{
sl@0
   284
				print_name(bio_out, "issuer=", X509_CRL_get_issuer(x), nmflag);
sl@0
   285
				}
sl@0
   286
sl@0
   287
			if (hash == i)
sl@0
   288
				{
sl@0
   289
				BIO_printf(bio_out,"%08lx\n",
sl@0
   290
					X509_NAME_hash(X509_CRL_get_issuer(x)));
sl@0
   291
				}
sl@0
   292
			if (lastupdate == i)
sl@0
   293
				{
sl@0
   294
				BIO_printf(bio_out,"lastUpdate=");
sl@0
   295
				ASN1_TIME_print(bio_out,
sl@0
   296
						X509_CRL_get_lastUpdate(x));
sl@0
   297
				BIO_printf(bio_out,"\n");
sl@0
   298
				}
sl@0
   299
			if (nextupdate == i)
sl@0
   300
				{
sl@0
   301
				BIO_printf(bio_out,"nextUpdate=");
sl@0
   302
				if (X509_CRL_get_nextUpdate(x)) 
sl@0
   303
					ASN1_TIME_print(bio_out,
sl@0
   304
						X509_CRL_get_nextUpdate(x));
sl@0
   305
				else
sl@0
   306
					BIO_printf(bio_out,"NONE");
sl@0
   307
				BIO_printf(bio_out,"\n");
sl@0
   308
				}
sl@0
   309
			if (fingerprint == i)
sl@0
   310
				{
sl@0
   311
				int j;
sl@0
   312
				unsigned int n;
sl@0
   313
				unsigned char md[EVP_MAX_MD_SIZE];
sl@0
   314
sl@0
   315
				if (!X509_CRL_digest(x,digest,md,&n))
sl@0
   316
					{
sl@0
   317
					BIO_printf(bio_err,"out of memory\n");
sl@0
   318
					goto end;
sl@0
   319
					}
sl@0
   320
				BIO_printf(bio_out,"%s Fingerprint=",
sl@0
   321
						OBJ_nid2sn(EVP_MD_type(digest)));
sl@0
   322
				for (j=0; j<(int)n; j++)
sl@0
   323
					{
sl@0
   324
					BIO_printf(bio_out,"%02X%c",md[j],
sl@0
   325
						(j+1 == (int)n)
sl@0
   326
						?'\n':':');
sl@0
   327
					}
sl@0
   328
				}
sl@0
   329
			}
sl@0
   330
		}
sl@0
   331
sl@0
   332
	out=BIO_new(BIO_s_file());
sl@0
   333
	if (out == NULL)
sl@0
   334
		{
sl@0
   335
		ERR_print_errors(bio_err);
sl@0
   336
		goto end;
sl@0
   337
		}
sl@0
   338
sl@0
   339
	if (outfile == NULL)
sl@0
   340
		{
sl@0
   341
		BIO_set_fp(out,stdout,BIO_NOCLOSE);
sl@0
   342
#ifdef OPENSSL_SYS_VMS
sl@0
   343
		{
sl@0
   344
		BIO *tmpbio = BIO_new(BIO_f_linebuffer());
sl@0
   345
		out = BIO_push(tmpbio, out);
sl@0
   346
		}
sl@0
   347
#endif
sl@0
   348
		}
sl@0
   349
	else
sl@0
   350
		{
sl@0
   351
		if (BIO_write_filename(out,outfile) <= 0)
sl@0
   352
			{
sl@0
   353
			perror(outfile);
sl@0
   354
			goto end;
sl@0
   355
			}
sl@0
   356
		}
sl@0
   357
sl@0
   358
	if (text) X509_CRL_print(out, x);
sl@0
   359
sl@0
   360
	if (noout) 
sl@0
   361
		{
sl@0
   362
		ret = 0;
sl@0
   363
		goto end;
sl@0
   364
		}
sl@0
   365
sl@0
   366
	if 	(outformat == FORMAT_ASN1)
sl@0
   367
		i=(int)i2d_X509_CRL_bio(out,x);
sl@0
   368
	else if (outformat == FORMAT_PEM)
sl@0
   369
		i=PEM_write_bio_X509_CRL(out,x);
sl@0
   370
	else	
sl@0
   371
		{
sl@0
   372
		BIO_printf(bio_err,"bad output format specified for outfile\n");
sl@0
   373
		goto end;
sl@0
   374
		}
sl@0
   375
	if (!i) { BIO_printf(bio_err,"unable to write CRL\n"); goto end; }
sl@0
   376
	ret=0;
sl@0
   377
end:
sl@0
   378
	BIO_free_all(out);
sl@0
   379
	BIO_free_all(bio_out);
sl@0
   380
	bio_out=NULL;
sl@0
   381
	X509_CRL_free(x);
sl@0
   382
	if(store) {
sl@0
   383
		X509_STORE_CTX_cleanup(&ctx);
sl@0
   384
		X509_STORE_free(store);
sl@0
   385
	}
sl@0
   386
	apps_shutdown();
sl@0
   387
	OPENSSL_EXIT(ret);
sl@0
   388
	}
sl@0
   389
sl@0
   390
static X509_CRL *load_crl(char *infile, int format)
sl@0
   391
	{
sl@0
   392
	X509_CRL *x=NULL;
sl@0
   393
	BIO *in=NULL;
sl@0
   394
sl@0
   395
	in=BIO_new(BIO_s_file());
sl@0
   396
	if (in == NULL)
sl@0
   397
		{
sl@0
   398
		ERR_print_errors(bio_err);
sl@0
   399
		goto end;
sl@0
   400
		}
sl@0
   401
sl@0
   402
	if (infile == NULL)
sl@0
   403
		BIO_set_fp(in,stdin,BIO_NOCLOSE);
sl@0
   404
  else
sl@0
   405
		{
sl@0
   406
		if (BIO_read_filename(in,infile) <= 0)
sl@0
   407
			{
sl@0
   408
			perror(infile);
sl@0
   409
			goto end;
sl@0
   410
			}
sl@0
   411
		}
sl@0
   412
	if 	(format == FORMAT_ASN1)
sl@0
   413
		x=d2i_X509_CRL_bio(in,NULL);
sl@0
   414
	else if (format == FORMAT_PEM)
sl@0
   415
		x=PEM_read_bio_X509_CRL(in,NULL,NULL,NULL);
sl@0
   416
	else	{
sl@0
   417
		BIO_printf(bio_err,"bad input format specified for input crl\n");
sl@0
   418
		goto end;
sl@0
   419
		}
sl@0
   420
	if (x == NULL)
sl@0
   421
		{
sl@0
   422
		BIO_printf(bio_err,"unable to load CRL\n");
sl@0
   423
		ERR_print_errors(bio_err);
sl@0
   424
		goto end;
sl@0
   425
		}
sl@0
   426
	
sl@0
   427
end:
sl@0
   428
	BIO_free(in);
sl@0
   429
	return(x);
sl@0
   430
	}
sl@0
   431