Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 1 | /* |
| 2 | * Copyright 2006 Juan Lang |
| 3 | * |
| 4 | * This library is free software; you can redistribute it and/or |
| 5 | * modify it under the terms of the GNU Lesser General Public |
| 6 | * License as published by the Free Software Foundation; either |
| 7 | * version 2.1 of the License, or (at your option) any later version. |
| 8 | * |
| 9 | * This library is distributed in the hope that it will be useful, |
| 10 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
| 11 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU |
| 12 | * Lesser General Public License for more details. |
| 13 | * |
| 14 | * You should have received a copy of the GNU Lesser General Public |
| 15 | * License along with this library; if not, write to the Free Software |
| 16 | * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA |
| 17 | * |
| 18 | */ |
| 19 | |
| 20 | #include <assert.h> |
| 21 | #include <stdarg.h> |
Juan Lang | c84c53b | 2009-11-18 16:21:09 -0800 | [diff] [blame] | 22 | #define NONAMELESSUNION |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 23 | #include "windef.h" |
| 24 | #include "winbase.h" |
| 25 | #include "wincrypt.h" |
| 26 | #include "wine/debug.h" |
Juan Lang | c84c53b | 2009-11-18 16:21:09 -0800 | [diff] [blame] | 27 | #include "wine/unicode.h" |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 28 | #include "crypt32_private.h" |
| 29 | |
| 30 | WINE_DEFAULT_DEBUG_CHANNEL(crypt); |
| 31 | |
| 32 | PCCRL_CONTEXT WINAPI CertCreateCRLContext(DWORD dwCertEncodingType, |
| 33 | const BYTE* pbCrlEncoded, DWORD cbCrlEncoded) |
| 34 | { |
| 35 | PCRL_CONTEXT crl = NULL; |
| 36 | BOOL ret; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 37 | PCRL_INFO crlInfo = NULL; |
| 38 | DWORD size = 0; |
| 39 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 40 | TRACE("(%08x, %p, %d)\n", dwCertEncodingType, pbCrlEncoded, |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 41 | cbCrlEncoded); |
| 42 | |
| 43 | if ((dwCertEncodingType & CERT_ENCODING_TYPE_MASK) != X509_ASN_ENCODING) |
| 44 | { |
| 45 | SetLastError(E_INVALIDARG); |
| 46 | return NULL; |
| 47 | } |
Juan Lang | 13e006a | 2006-06-19 14:11:37 -0700 | [diff] [blame] | 48 | ret = CryptDecodeObjectEx(dwCertEncodingType, X509_CERT_CRL_TO_BE_SIGNED, |
| 49 | pbCrlEncoded, cbCrlEncoded, CRYPT_DECODE_ALLOC_FLAG, NULL, |
Michael Stefaniuc | 4eaaa91 | 2009-01-26 11:01:47 +0100 | [diff] [blame] | 50 | &crlInfo, &size); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 51 | if (ret) |
| 52 | { |
| 53 | BYTE *data = NULL; |
| 54 | |
Michael Stefaniuc | 7589715 | 2008-11-03 22:35:50 +0100 | [diff] [blame] | 55 | crl = Context_CreateDataContext(sizeof(CRL_CONTEXT)); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 56 | if (!crl) |
| 57 | goto end; |
| 58 | data = CryptMemAlloc(cbCrlEncoded); |
| 59 | if (!data) |
| 60 | { |
| 61 | CryptMemFree(crl); |
| 62 | crl = NULL; |
| 63 | goto end; |
| 64 | } |
| 65 | memcpy(data, pbCrlEncoded, cbCrlEncoded); |
| 66 | crl->dwCertEncodingType = dwCertEncodingType; |
| 67 | crl->pbCrlEncoded = data; |
| 68 | crl->cbCrlEncoded = cbCrlEncoded; |
| 69 | crl->pCrlInfo = crlInfo; |
| 70 | crl->hCertStore = 0; |
| 71 | } |
| 72 | |
| 73 | end: |
Michael Stefaniuc | 4eaaa91 | 2009-01-26 11:01:47 +0100 | [diff] [blame] | 74 | return crl; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 75 | } |
| 76 | |
| 77 | BOOL WINAPI CertAddEncodedCRLToStore(HCERTSTORE hCertStore, |
| 78 | DWORD dwCertEncodingType, const BYTE *pbCrlEncoded, DWORD cbCrlEncoded, |
| 79 | DWORD dwAddDisposition, PCCRL_CONTEXT *ppCrlContext) |
| 80 | { |
| 81 | PCCRL_CONTEXT crl = CertCreateCRLContext(dwCertEncodingType, |
| 82 | pbCrlEncoded, cbCrlEncoded); |
| 83 | BOOL ret; |
| 84 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 85 | TRACE("(%p, %08x, %p, %d, %08x, %p)\n", hCertStore, dwCertEncodingType, |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 86 | pbCrlEncoded, cbCrlEncoded, dwAddDisposition, ppCrlContext); |
| 87 | |
| 88 | if (crl) |
| 89 | { |
| 90 | ret = CertAddCRLContextToStore(hCertStore, crl, dwAddDisposition, |
| 91 | ppCrlContext); |
| 92 | CertFreeCRLContext(crl); |
| 93 | } |
| 94 | else |
| 95 | ret = FALSE; |
| 96 | return ret; |
| 97 | } |
| 98 | |
| 99 | typedef BOOL (*CrlCompareFunc)(PCCRL_CONTEXT pCrlContext, DWORD dwType, |
| 100 | DWORD dwFlags, const void *pvPara); |
| 101 | |
| 102 | static BOOL compare_crl_any(PCCRL_CONTEXT pCrlContext, DWORD dwType, |
| 103 | DWORD dwFlags, const void *pvPara) |
| 104 | { |
| 105 | return TRUE; |
| 106 | } |
| 107 | |
| 108 | static BOOL compare_crl_issued_by(PCCRL_CONTEXT pCrlContext, DWORD dwType, |
| 109 | DWORD dwFlags, const void *pvPara) |
| 110 | { |
| 111 | BOOL ret; |
| 112 | |
| 113 | if (pvPara) |
| 114 | { |
Michael Stefaniuc | 4eaaa91 | 2009-01-26 11:01:47 +0100 | [diff] [blame] | 115 | PCCERT_CONTEXT issuer = pvPara; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 116 | |
| 117 | ret = CertCompareCertificateName(issuer->dwCertEncodingType, |
| 118 | &issuer->pCertInfo->Issuer, &pCrlContext->pCrlInfo->Issuer); |
Juan Lang | 4727212 | 2009-11-18 16:27:49 -0800 | [diff] [blame] | 119 | if (ret && (dwFlags & CRL_FIND_ISSUED_BY_SIGNATURE_FLAG)) |
| 120 | ret = CryptVerifyCertificateSignatureEx(0, |
| 121 | issuer->dwCertEncodingType, |
| 122 | CRYPT_VERIFY_CERT_SIGN_SUBJECT_CRL, (void *)pCrlContext, |
| 123 | CRYPT_VERIFY_CERT_SIGN_ISSUER_CERT, (void *)issuer, 0, NULL); |
Juan Lang | 8fcaa52 | 2009-11-18 16:54:49 -0800 | [diff] [blame] | 124 | if (ret && (dwFlags & CRL_FIND_ISSUED_BY_AKI_FLAG)) |
| 125 | { |
| 126 | PCERT_EXTENSION aki = CertFindExtension( |
| 127 | szOID_AUTHORITY_KEY_IDENTIFIER2, pCrlContext->pCrlInfo->cExtension, |
| 128 | pCrlContext->pCrlInfo->rgExtension); |
| 129 | |
| 130 | if (aki) |
| 131 | { |
| 132 | CERT_EXTENSION *ski; |
| 133 | |
| 134 | if ((ski = CertFindExtension(szOID_SUBJECT_KEY_IDENTIFIER, |
| 135 | issuer->pCertInfo->cExtension, |
| 136 | issuer->pCertInfo->rgExtension))) |
| 137 | { |
| 138 | if (aki->Value.cbData == ski->Value.cbData) |
| 139 | ret = !memcmp(aki->Value.pbData, ski->Value.pbData, |
| 140 | aki->Value.cbData); |
| 141 | else |
| 142 | ret = FALSE; |
| 143 | } |
| 144 | else |
| 145 | ret = FALSE; |
| 146 | } |
| 147 | /* else: a CRL without an AKI matches any cert */ |
| 148 | } |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 149 | } |
| 150 | else |
| 151 | ret = TRUE; |
| 152 | return ret; |
| 153 | } |
| 154 | |
| 155 | static BOOL compare_crl_existing(PCCRL_CONTEXT pCrlContext, DWORD dwType, |
| 156 | DWORD dwFlags, const void *pvPara) |
| 157 | { |
| 158 | BOOL ret; |
| 159 | |
| 160 | if (pvPara) |
| 161 | { |
Michael Stefaniuc | 4eaaa91 | 2009-01-26 11:01:47 +0100 | [diff] [blame] | 162 | PCCRL_CONTEXT crl = pvPara; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 163 | |
| 164 | ret = CertCompareCertificateName(pCrlContext->dwCertEncodingType, |
| 165 | &pCrlContext->pCrlInfo->Issuer, &crl->pCrlInfo->Issuer); |
| 166 | } |
| 167 | else |
| 168 | ret = TRUE; |
| 169 | return ret; |
| 170 | } |
| 171 | |
Juan Lang | 4fa4f67 | 2009-11-18 10:40:08 -0800 | [diff] [blame] | 172 | static BOOL compare_crl_issued_for(PCCRL_CONTEXT pCrlContext, DWORD dwType, |
| 173 | DWORD dwFlags, const void *pvPara) |
| 174 | { |
| 175 | const CRL_FIND_ISSUED_FOR_PARA *para = pvPara; |
| 176 | BOOL ret; |
| 177 | |
| 178 | ret = CertCompareCertificateName(para->pIssuerCert->dwCertEncodingType, |
| 179 | ¶->pIssuerCert->pCertInfo->Issuer, &pCrlContext->pCrlInfo->Issuer); |
| 180 | if (ret) |
| 181 | ret = CertIsValidCRLForCertificate(para->pSubjectCert, pCrlContext, |
| 182 | 0, NULL); |
| 183 | return ret; |
| 184 | } |
| 185 | |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 186 | PCCRL_CONTEXT WINAPI CertFindCRLInStore(HCERTSTORE hCertStore, |
| 187 | DWORD dwCertEncodingType, DWORD dwFindFlags, DWORD dwFindType, |
| 188 | const void *pvFindPara, PCCRL_CONTEXT pPrevCrlContext) |
| 189 | { |
| 190 | PCCRL_CONTEXT ret; |
| 191 | CrlCompareFunc compare; |
| 192 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 193 | TRACE("(%p, %d, %d, %d, %p, %p)\n", hCertStore, dwCertEncodingType, |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 194 | dwFindFlags, dwFindType, pvFindPara, pPrevCrlContext); |
| 195 | |
| 196 | switch (dwFindType) |
| 197 | { |
| 198 | case CRL_FIND_ANY: |
| 199 | compare = compare_crl_any; |
| 200 | break; |
| 201 | case CRL_FIND_ISSUED_BY: |
| 202 | compare = compare_crl_issued_by; |
| 203 | break; |
| 204 | case CRL_FIND_EXISTING: |
| 205 | compare = compare_crl_existing; |
| 206 | break; |
Juan Lang | 4fa4f67 | 2009-11-18 10:40:08 -0800 | [diff] [blame] | 207 | case CRL_FIND_ISSUED_FOR: |
| 208 | compare = compare_crl_issued_for; |
| 209 | break; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 210 | default: |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 211 | FIXME("find type %08x unimplemented\n", dwFindType); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 212 | compare = NULL; |
| 213 | } |
| 214 | |
| 215 | if (compare) |
| 216 | { |
| 217 | BOOL matches = FALSE; |
| 218 | |
| 219 | ret = pPrevCrlContext; |
| 220 | do { |
| 221 | ret = CertEnumCRLsInStore(hCertStore, ret); |
| 222 | if (ret) |
| 223 | matches = compare(ret, dwFindType, dwFindFlags, pvFindPara); |
| 224 | } while (ret != NULL && !matches); |
| 225 | if (!ret) |
| 226 | SetLastError(CRYPT_E_NOT_FOUND); |
| 227 | } |
| 228 | else |
| 229 | { |
| 230 | SetLastError(CRYPT_E_NOT_FOUND); |
| 231 | ret = NULL; |
| 232 | } |
| 233 | return ret; |
| 234 | } |
| 235 | |
Juan Lang | 77ea583 | 2006-06-21 20:50:11 -0700 | [diff] [blame] | 236 | PCCRL_CONTEXT WINAPI CertGetCRLFromStore(HCERTSTORE hCertStore, |
| 237 | PCCERT_CONTEXT pIssuerContext, PCCRL_CONTEXT pPrevCrlContext, DWORD *pdwFlags) |
| 238 | { |
| 239 | static const DWORD supportedFlags = CERT_STORE_SIGNATURE_FLAG | |
| 240 | CERT_STORE_TIME_VALIDITY_FLAG | CERT_STORE_BASE_CRL_FLAG | |
| 241 | CERT_STORE_DELTA_CRL_FLAG; |
| 242 | PCCRL_CONTEXT ret; |
| 243 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 244 | TRACE("(%p, %p, %p, %08x)\n", hCertStore, pIssuerContext, pPrevCrlContext, |
Juan Lang | 77ea583 | 2006-06-21 20:50:11 -0700 | [diff] [blame] | 245 | *pdwFlags); |
| 246 | |
| 247 | if (*pdwFlags & ~supportedFlags) |
| 248 | { |
| 249 | SetLastError(E_INVALIDARG); |
| 250 | return NULL; |
| 251 | } |
| 252 | if (pIssuerContext) |
| 253 | ret = CertFindCRLInStore(hCertStore, pIssuerContext->dwCertEncodingType, |
| 254 | 0, CRL_FIND_ISSUED_BY, pIssuerContext, pPrevCrlContext); |
| 255 | else |
| 256 | ret = CertFindCRLInStore(hCertStore, 0, 0, CRL_FIND_ANY, NULL, |
| 257 | pPrevCrlContext); |
| 258 | if (ret) |
| 259 | { |
| 260 | if (*pdwFlags & CERT_STORE_TIME_VALIDITY_FLAG) |
| 261 | { |
| 262 | if (0 == CertVerifyCRLTimeValidity(NULL, ret->pCrlInfo)) |
| 263 | *pdwFlags &= ~CERT_STORE_TIME_VALIDITY_FLAG; |
| 264 | } |
| 265 | if (*pdwFlags & CERT_STORE_SIGNATURE_FLAG) |
| 266 | { |
| 267 | if (CryptVerifyCertificateSignatureEx(0, ret->dwCertEncodingType, |
| 268 | CRYPT_VERIFY_CERT_SIGN_SUBJECT_CRL, (void *)ret, |
| 269 | CRYPT_VERIFY_CERT_SIGN_ISSUER_CERT, (void *)pIssuerContext, 0, |
| 270 | NULL)) |
| 271 | *pdwFlags &= ~CERT_STORE_SIGNATURE_FLAG; |
| 272 | } |
| 273 | } |
| 274 | return ret; |
| 275 | } |
| 276 | |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 277 | PCCRL_CONTEXT WINAPI CertDuplicateCRLContext(PCCRL_CONTEXT pCrlContext) |
| 278 | { |
| 279 | TRACE("(%p)\n", pCrlContext); |
Juan Lang | acc9d81 | 2009-10-20 09:52:36 -0700 | [diff] [blame] | 280 | if (pCrlContext) |
| 281 | Context_AddRef((void *)pCrlContext, sizeof(CRL_CONTEXT)); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 282 | return pCrlContext; |
| 283 | } |
| 284 | |
| 285 | static void CrlDataContext_Free(void *context) |
| 286 | { |
Michael Stefaniuc | 4eaaa91 | 2009-01-26 11:01:47 +0100 | [diff] [blame] | 287 | PCRL_CONTEXT crlContext = context; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 288 | |
| 289 | CryptMemFree(crlContext->pbCrlEncoded); |
| 290 | LocalFree(crlContext->pCrlInfo); |
| 291 | } |
| 292 | |
| 293 | BOOL WINAPI CertFreeCRLContext( PCCRL_CONTEXT pCrlContext) |
| 294 | { |
Juan Lang | 40855ca | 2009-10-30 15:06:39 -0700 | [diff] [blame] | 295 | BOOL ret = TRUE; |
| 296 | |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 297 | TRACE("(%p)\n", pCrlContext); |
| 298 | |
| 299 | if (pCrlContext) |
Juan Lang | 40855ca | 2009-10-30 15:06:39 -0700 | [diff] [blame] | 300 | ret = Context_Release((void *)pCrlContext, sizeof(CRL_CONTEXT), |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 301 | CrlDataContext_Free); |
Juan Lang | 40855ca | 2009-10-30 15:06:39 -0700 | [diff] [blame] | 302 | return ret; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 303 | } |
| 304 | |
| 305 | DWORD WINAPI CertEnumCRLContextProperties(PCCRL_CONTEXT pCRLContext, |
| 306 | DWORD dwPropId) |
| 307 | { |
| 308 | PCONTEXT_PROPERTY_LIST properties = Context_GetProperties( |
Michael Stefaniuc | 4eaaa91 | 2009-01-26 11:01:47 +0100 | [diff] [blame] | 309 | pCRLContext, sizeof(CRL_CONTEXT)); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 310 | DWORD ret; |
| 311 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 312 | TRACE("(%p, %d)\n", pCRLContext, dwPropId); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 313 | |
| 314 | if (properties) |
| 315 | ret = ContextPropertyList_EnumPropIDs(properties, dwPropId); |
| 316 | else |
| 317 | ret = 0; |
| 318 | return ret; |
| 319 | } |
| 320 | |
Alexandre Julliard | 8926dce | 2008-01-02 12:22:16 +0100 | [diff] [blame] | 321 | static BOOL CRLContext_SetProperty(PCCRL_CONTEXT context, DWORD dwPropId, |
| 322 | DWORD dwFlags, const void *pvData); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 323 | |
Alexandre Julliard | 8926dce | 2008-01-02 12:22:16 +0100 | [diff] [blame] | 324 | static BOOL CRLContext_GetHashProp(PCCRL_CONTEXT context, DWORD dwPropId, |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 325 | ALG_ID algID, const BYTE *toHash, DWORD toHashLen, void *pvData, |
| 326 | DWORD *pcbData) |
| 327 | { |
| 328 | BOOL ret = CryptHashCertificate(0, algID, 0, toHash, toHashLen, pvData, |
| 329 | pcbData); |
Juan Lang | 00c50a6 | 2008-12-22 19:32:41 -0800 | [diff] [blame] | 330 | if (ret && pvData) |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 331 | { |
| 332 | CRYPT_DATA_BLOB blob = { *pcbData, pvData }; |
| 333 | |
| 334 | ret = CRLContext_SetProperty(context, dwPropId, 0, &blob); |
| 335 | } |
| 336 | return ret; |
| 337 | } |
| 338 | |
Alexandre Julliard | 8926dce | 2008-01-02 12:22:16 +0100 | [diff] [blame] | 339 | static BOOL CRLContext_GetProperty(PCCRL_CONTEXT context, DWORD dwPropId, |
| 340 | void *pvData, DWORD *pcbData) |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 341 | { |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 342 | PCONTEXT_PROPERTY_LIST properties = |
| 343 | Context_GetProperties(context, sizeof(CRL_CONTEXT)); |
| 344 | BOOL ret; |
| 345 | CRYPT_DATA_BLOB blob; |
| 346 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 347 | TRACE("(%p, %d, %p, %p)\n", context, dwPropId, pvData, pcbData); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 348 | |
| 349 | if (properties) |
| 350 | ret = ContextPropertyList_FindProperty(properties, dwPropId, &blob); |
| 351 | else |
| 352 | ret = FALSE; |
| 353 | if (ret) |
| 354 | { |
| 355 | if (!pvData) |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 356 | *pcbData = blob.cbData; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 357 | else if (*pcbData < blob.cbData) |
| 358 | { |
| 359 | SetLastError(ERROR_MORE_DATA); |
| 360 | *pcbData = blob.cbData; |
Juan Lang | 0170a41 | 2007-05-14 18:04:51 -0700 | [diff] [blame] | 361 | ret = FALSE; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 362 | } |
| 363 | else |
| 364 | { |
| 365 | memcpy(pvData, blob.pbData, blob.cbData); |
| 366 | *pcbData = blob.cbData; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 367 | } |
| 368 | } |
| 369 | else |
| 370 | { |
| 371 | /* Implicit properties */ |
| 372 | switch (dwPropId) |
| 373 | { |
| 374 | case CERT_SHA1_HASH_PROP_ID: |
| 375 | ret = CRLContext_GetHashProp(context, dwPropId, CALG_SHA1, |
Alexandre Julliard | 8926dce | 2008-01-02 12:22:16 +0100 | [diff] [blame] | 376 | context->pbCrlEncoded, context->cbCrlEncoded, pvData, |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 377 | pcbData); |
| 378 | break; |
| 379 | case CERT_MD5_HASH_PROP_ID: |
| 380 | ret = CRLContext_GetHashProp(context, dwPropId, CALG_MD5, |
Alexandre Julliard | 8926dce | 2008-01-02 12:22:16 +0100 | [diff] [blame] | 381 | context->pbCrlEncoded, context->cbCrlEncoded, pvData, |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 382 | pcbData); |
| 383 | break; |
| 384 | default: |
| 385 | SetLastError(CRYPT_E_NOT_FOUND); |
| 386 | } |
| 387 | } |
| 388 | TRACE("returning %d\n", ret); |
| 389 | return ret; |
| 390 | } |
| 391 | |
| 392 | BOOL WINAPI CertGetCRLContextProperty(PCCRL_CONTEXT pCRLContext, |
| 393 | DWORD dwPropId, void *pvData, DWORD *pcbData) |
| 394 | { |
| 395 | BOOL ret; |
| 396 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 397 | TRACE("(%p, %d, %p, %p)\n", pCRLContext, dwPropId, pvData, pcbData); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 398 | |
| 399 | switch (dwPropId) |
| 400 | { |
| 401 | case 0: |
| 402 | case CERT_CERT_PROP_ID: |
| 403 | case CERT_CRL_PROP_ID: |
| 404 | case CERT_CTL_PROP_ID: |
| 405 | SetLastError(E_INVALIDARG); |
| 406 | ret = FALSE; |
| 407 | break; |
| 408 | case CERT_ACCESS_STATE_PROP_ID: |
| 409 | if (!pvData) |
| 410 | { |
| 411 | *pcbData = sizeof(DWORD); |
| 412 | ret = TRUE; |
| 413 | } |
| 414 | else if (*pcbData < sizeof(DWORD)) |
| 415 | { |
| 416 | SetLastError(ERROR_MORE_DATA); |
| 417 | *pcbData = sizeof(DWORD); |
| 418 | ret = FALSE; |
| 419 | } |
| 420 | else |
| 421 | { |
Juan Lang | 79cd672 | 2007-05-14 18:06:48 -0700 | [diff] [blame] | 422 | if (pCRLContext->hCertStore) |
| 423 | ret = CertGetStoreProperty(pCRLContext->hCertStore, dwPropId, |
| 424 | pvData, pcbData); |
| 425 | else |
| 426 | *(DWORD *)pvData = 0; |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 427 | ret = TRUE; |
| 428 | } |
| 429 | break; |
| 430 | default: |
Alexandre Julliard | 8926dce | 2008-01-02 12:22:16 +0100 | [diff] [blame] | 431 | ret = CRLContext_GetProperty(pCRLContext, dwPropId, pvData, |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 432 | pcbData); |
| 433 | } |
| 434 | return ret; |
| 435 | } |
| 436 | |
Alexandre Julliard | 8926dce | 2008-01-02 12:22:16 +0100 | [diff] [blame] | 437 | static BOOL CRLContext_SetProperty(PCCRL_CONTEXT context, DWORD dwPropId, |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 438 | DWORD dwFlags, const void *pvData) |
| 439 | { |
| 440 | PCONTEXT_PROPERTY_LIST properties = |
Juan Lang | 0ab7781 | 2008-08-28 10:05:30 -0700 | [diff] [blame] | 441 | Context_GetProperties(context, sizeof(CRL_CONTEXT)); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 442 | BOOL ret; |
| 443 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 444 | TRACE("(%p, %d, %08x, %p)\n", context, dwPropId, dwFlags, pvData); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 445 | |
| 446 | if (!properties) |
| 447 | ret = FALSE; |
| 448 | else if (!pvData) |
| 449 | { |
| 450 | ContextPropertyList_RemoveProperty(properties, dwPropId); |
| 451 | ret = TRUE; |
| 452 | } |
| 453 | else |
| 454 | { |
| 455 | switch (dwPropId) |
| 456 | { |
| 457 | case CERT_AUTO_ENROLL_PROP_ID: |
| 458 | case CERT_CTL_USAGE_PROP_ID: /* same as CERT_ENHKEY_USAGE_PROP_ID */ |
| 459 | case CERT_DESCRIPTION_PROP_ID: |
| 460 | case CERT_FRIENDLY_NAME_PROP_ID: |
| 461 | case CERT_HASH_PROP_ID: |
| 462 | case CERT_KEY_IDENTIFIER_PROP_ID: |
| 463 | case CERT_MD5_HASH_PROP_ID: |
| 464 | case CERT_NEXT_UPDATE_LOCATION_PROP_ID: |
| 465 | case CERT_PUBKEY_ALG_PARA_PROP_ID: |
| 466 | case CERT_PVK_FILE_PROP_ID: |
| 467 | case CERT_SIGNATURE_HASH_PROP_ID: |
| 468 | case CERT_ISSUER_PUBLIC_KEY_MD5_HASH_PROP_ID: |
| 469 | case CERT_SUBJECT_NAME_MD5_HASH_PROP_ID: |
| 470 | case CERT_SUBJECT_PUBLIC_KEY_MD5_HASH_PROP_ID: |
| 471 | case CERT_ENROLLMENT_PROP_ID: |
| 472 | case CERT_CROSS_CERT_DIST_POINTS_PROP_ID: |
| 473 | case CERT_RENEWAL_PROP_ID: |
| 474 | { |
| 475 | PCRYPT_DATA_BLOB blob = (PCRYPT_DATA_BLOB)pvData; |
| 476 | |
| 477 | ret = ContextPropertyList_SetProperty(properties, dwPropId, |
| 478 | blob->pbData, blob->cbData); |
| 479 | break; |
| 480 | } |
| 481 | case CERT_DATE_STAMP_PROP_ID: |
| 482 | ret = ContextPropertyList_SetProperty(properties, dwPropId, |
Michael Stefaniuc | 4eaaa91 | 2009-01-26 11:01:47 +0100 | [diff] [blame] | 483 | pvData, sizeof(FILETIME)); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 484 | break; |
| 485 | default: |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 486 | FIXME("%d: stub\n", dwPropId); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 487 | ret = FALSE; |
| 488 | } |
| 489 | } |
| 490 | TRACE("returning %d\n", ret); |
| 491 | return ret; |
| 492 | } |
| 493 | |
| 494 | BOOL WINAPI CertSetCRLContextProperty(PCCRL_CONTEXT pCRLContext, |
| 495 | DWORD dwPropId, DWORD dwFlags, const void *pvData) |
| 496 | { |
| 497 | BOOL ret; |
| 498 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 499 | TRACE("(%p, %d, %08x, %p)\n", pCRLContext, dwPropId, dwFlags, pvData); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 500 | |
| 501 | /* Handle special cases for "read-only"/invalid prop IDs. Windows just |
| 502 | * crashes on most of these, I'll be safer. |
| 503 | */ |
| 504 | switch (dwPropId) |
| 505 | { |
| 506 | case 0: |
| 507 | case CERT_ACCESS_STATE_PROP_ID: |
| 508 | case CERT_CERT_PROP_ID: |
| 509 | case CERT_CRL_PROP_ID: |
| 510 | case CERT_CTL_PROP_ID: |
| 511 | SetLastError(E_INVALIDARG); |
| 512 | return FALSE; |
| 513 | } |
Alexandre Julliard | 8926dce | 2008-01-02 12:22:16 +0100 | [diff] [blame] | 514 | ret = CRLContext_SetProperty(pCRLContext, dwPropId, dwFlags, pvData); |
Juan Lang | c4f2bcf | 2006-05-25 09:01:03 -0700 | [diff] [blame] | 515 | TRACE("returning %d\n", ret); |
| 516 | return ret; |
| 517 | } |
Juan Lang | b29c233 | 2006-05-26 09:48:13 -0700 | [diff] [blame] | 518 | |
Juan Lang | c84c53b | 2009-11-18 16:21:09 -0800 | [diff] [blame] | 519 | static BOOL compare_dist_point_name(const CRL_DIST_POINT_NAME *name1, |
| 520 | const CRL_DIST_POINT_NAME *name2) |
| 521 | { |
| 522 | BOOL match; |
| 523 | |
| 524 | if (name1->dwDistPointNameChoice == name2->dwDistPointNameChoice) |
| 525 | { |
| 526 | match = TRUE; |
| 527 | if (name1->dwDistPointNameChoice == CRL_DIST_POINT_FULL_NAME) |
| 528 | { |
| 529 | if (name1->u.FullName.cAltEntry == name2->u.FullName.cAltEntry) |
| 530 | { |
| 531 | DWORD i; |
| 532 | |
| 533 | for (i = 0; match && i < name1->u.FullName.cAltEntry; i++) |
| 534 | { |
| 535 | const CERT_ALT_NAME_ENTRY *entry1 = |
| 536 | &name1->u.FullName.rgAltEntry[i]; |
| 537 | const CERT_ALT_NAME_ENTRY *entry2 = |
| 538 | &name2->u.FullName.rgAltEntry[i]; |
| 539 | |
| 540 | if (entry1->dwAltNameChoice == entry2->dwAltNameChoice) |
| 541 | { |
| 542 | switch (entry1->dwAltNameChoice) |
| 543 | { |
| 544 | case CERT_ALT_NAME_URL: |
| 545 | match = !strcmpiW(entry1->u.pwszURL, |
| 546 | entry2->u.pwszURL); |
| 547 | break; |
| 548 | case CERT_ALT_NAME_DIRECTORY_NAME: |
| 549 | match = (entry1->u.DirectoryName.cbData == |
| 550 | entry2->u.DirectoryName.cbData) && |
| 551 | !memcmp(entry1->u.DirectoryName.pbData, |
| 552 | entry2->u.DirectoryName.pbData, |
| 553 | entry1->u.DirectoryName.cbData); |
| 554 | break; |
| 555 | default: |
| 556 | FIXME("unimplemented for type %d\n", |
| 557 | entry1->dwAltNameChoice); |
| 558 | match = FALSE; |
| 559 | } |
| 560 | } |
| 561 | else |
| 562 | match = FALSE; |
| 563 | } |
| 564 | } |
| 565 | else |
| 566 | match = FALSE; |
| 567 | } |
| 568 | } |
| 569 | else |
| 570 | match = FALSE; |
| 571 | return match; |
| 572 | } |
| 573 | |
| 574 | static BOOL match_dist_point_with_issuing_dist_point( |
| 575 | const CRL_DIST_POINT *distPoint, const CRL_ISSUING_DIST_POINT *idp) |
| 576 | { |
| 577 | BOOL match; |
| 578 | |
| 579 | /* While RFC 5280, section 4.2.1.13 recommends against segmenting |
| 580 | * CRL distribution points by reasons, it doesn't preclude doing so. |
| 581 | * "This profile RECOMMENDS against segmenting CRLs by reason code." |
| 582 | * If the issuing distribution point for this CRL is only valid for |
| 583 | * some reasons, only match if the reasons covered also match the |
| 584 | * reasons in the CRL distribution point. |
| 585 | */ |
| 586 | if (idp->OnlySomeReasonFlags.cbData) |
| 587 | { |
| 588 | if (idp->OnlySomeReasonFlags.cbData == distPoint->ReasonFlags.cbData) |
| 589 | { |
| 590 | DWORD i; |
| 591 | |
| 592 | match = TRUE; |
| 593 | for (i = 0; match && i < distPoint->ReasonFlags.cbData; i++) |
| 594 | if (idp->OnlySomeReasonFlags.pbData[i] != |
| 595 | distPoint->ReasonFlags.pbData[i]) |
| 596 | match = FALSE; |
| 597 | } |
| 598 | else |
| 599 | match = FALSE; |
| 600 | } |
| 601 | else |
| 602 | match = TRUE; |
| 603 | if (match) |
| 604 | match = compare_dist_point_name(&idp->DistPointName, |
| 605 | &distPoint->DistPointName); |
| 606 | return match; |
| 607 | } |
| 608 | |
Juan Lang | e8992af | 2006-06-20 16:06:27 -0700 | [diff] [blame] | 609 | BOOL WINAPI CertIsValidCRLForCertificate(PCCERT_CONTEXT pCert, |
| 610 | PCCRL_CONTEXT pCrl, DWORD dwFlags, void *pvReserved) |
| 611 | { |
Juan Lang | c84c53b | 2009-11-18 16:21:09 -0800 | [diff] [blame] | 612 | PCERT_EXTENSION ext; |
| 613 | BOOL ret; |
| 614 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 615 | TRACE("(%p, %p, %08x, %p)\n", pCert, pCrl, dwFlags, pvReserved); |
Juan Lang | c84c53b | 2009-11-18 16:21:09 -0800 | [diff] [blame] | 616 | |
| 617 | if (!pCert) |
| 618 | return TRUE; |
| 619 | |
| 620 | if ((ext = CertFindExtension(szOID_ISSUING_DIST_POINT, |
| 621 | pCrl->pCrlInfo->cExtension, pCrl->pCrlInfo->rgExtension))) |
| 622 | { |
| 623 | CRL_ISSUING_DIST_POINT *idp; |
| 624 | DWORD size; |
| 625 | |
| 626 | if ((ret = CryptDecodeObjectEx(pCrl->dwCertEncodingType, |
| 627 | X509_ISSUING_DIST_POINT, ext->Value.pbData, ext->Value.cbData, |
| 628 | CRYPT_DECODE_ALLOC_FLAG, NULL, &idp, &size))) |
| 629 | { |
| 630 | if ((ext = CertFindExtension(szOID_CRL_DIST_POINTS, |
| 631 | pCert->pCertInfo->cExtension, pCert->pCertInfo->rgExtension))) |
| 632 | { |
| 633 | CRL_DIST_POINTS_INFO *distPoints; |
| 634 | |
| 635 | if ((ret = CryptDecodeObjectEx(pCert->dwCertEncodingType, |
| 636 | X509_CRL_DIST_POINTS, ext->Value.pbData, ext->Value.cbData, |
| 637 | CRYPT_DECODE_ALLOC_FLAG, NULL, &distPoints, &size))) |
| 638 | { |
| 639 | DWORD i; |
| 640 | |
| 641 | ret = FALSE; |
| 642 | for (i = 0; !ret && i < distPoints->cDistPoint; i++) |
| 643 | ret = match_dist_point_with_issuing_dist_point( |
| 644 | &distPoints->rgDistPoint[i], idp); |
| 645 | if (!ret) |
| 646 | SetLastError(CRYPT_E_NO_MATCH); |
| 647 | LocalFree(distPoints); |
| 648 | } |
| 649 | } |
| 650 | else |
| 651 | { |
Juan Lang | f378394 | 2009-11-19 11:48:53 -0800 | [diff] [blame^] | 652 | /* no CRL dist points extension in cert, can't match the CRL |
| 653 | * (which has an issuing dist point extension) |
Juan Lang | c84c53b | 2009-11-18 16:21:09 -0800 | [diff] [blame] | 654 | */ |
Juan Lang | f378394 | 2009-11-19 11:48:53 -0800 | [diff] [blame^] | 655 | ret = FALSE; |
| 656 | SetLastError(CRYPT_E_NO_MATCH); |
Juan Lang | c84c53b | 2009-11-18 16:21:09 -0800 | [diff] [blame] | 657 | } |
| 658 | LocalFree(idp); |
| 659 | } |
| 660 | } |
| 661 | else |
| 662 | ret = TRUE; |
| 663 | return ret; |
Juan Lang | e8992af | 2006-06-20 16:06:27 -0700 | [diff] [blame] | 664 | } |
| 665 | |
Andrew Talbot | e04f6be | 2007-04-09 20:28:22 +0100 | [diff] [blame] | 666 | static PCRL_ENTRY CRYPT_FindCertificateInCRL(PCERT_INFO cert, const CRL_INFO *crl) |
Juan Lang | e8992af | 2006-06-20 16:06:27 -0700 | [diff] [blame] | 667 | { |
| 668 | DWORD i; |
| 669 | PCRL_ENTRY entry = NULL; |
| 670 | |
Juan Lang | e8992af | 2006-06-20 16:06:27 -0700 | [diff] [blame] | 671 | for (i = 0; !entry && i < crl->cCRLEntry; i++) |
| 672 | if (CertCompareIntegerBlob(&crl->rgCRLEntry[i].SerialNumber, |
| 673 | &cert->SerialNumber)) |
| 674 | entry = &crl->rgCRLEntry[i]; |
| 675 | return entry; |
| 676 | } |
| 677 | |
| 678 | BOOL WINAPI CertFindCertificateInCRL(PCCERT_CONTEXT pCert, |
| 679 | PCCRL_CONTEXT pCrlContext, DWORD dwFlags, void *pvReserved, |
| 680 | PCRL_ENTRY *ppCrlEntry) |
| 681 | { |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 682 | TRACE("(%p, %p, %08x, %p, %p)\n", pCert, pCrlContext, dwFlags, pvReserved, |
Juan Lang | e8992af | 2006-06-20 16:06:27 -0700 | [diff] [blame] | 683 | ppCrlEntry); |
| 684 | |
| 685 | *ppCrlEntry = CRYPT_FindCertificateInCRL(pCert->pCertInfo, |
| 686 | pCrlContext->pCrlInfo); |
| 687 | return TRUE; |
| 688 | } |
| 689 | |
| 690 | BOOL WINAPI CertVerifyCRLRevocation(DWORD dwCertEncodingType, |
| 691 | PCERT_INFO pCertId, DWORD cCrlInfo, PCRL_INFO rgpCrlInfo[]) |
| 692 | { |
| 693 | DWORD i; |
| 694 | PCRL_ENTRY entry = NULL; |
| 695 | |
Juan Lang | f3a1f2b | 2006-10-03 21:58:09 -0700 | [diff] [blame] | 696 | TRACE("(%08x, %p, %d, %p)\n", dwCertEncodingType, pCertId, cCrlInfo, |
Juan Lang | e8992af | 2006-06-20 16:06:27 -0700 | [diff] [blame] | 697 | rgpCrlInfo); |
| 698 | |
| 699 | for (i = 0; !entry && i < cCrlInfo; i++) |
| 700 | entry = CRYPT_FindCertificateInCRL(pCertId, rgpCrlInfo[i]); |
| 701 | return entry == NULL; |
| 702 | } |
| 703 | |
Juan Lang | b29c233 | 2006-05-26 09:48:13 -0700 | [diff] [blame] | 704 | LONG WINAPI CertVerifyCRLTimeValidity(LPFILETIME pTimeToVerify, |
| 705 | PCRL_INFO pCrlInfo) |
| 706 | { |
| 707 | FILETIME fileTime; |
| 708 | LONG ret; |
| 709 | |
| 710 | if (!pTimeToVerify) |
| 711 | { |
Juan Lang | cf904c2 | 2007-10-18 11:14:12 -0700 | [diff] [blame] | 712 | GetSystemTimeAsFileTime(&fileTime); |
Juan Lang | b29c233 | 2006-05-26 09:48:13 -0700 | [diff] [blame] | 713 | pTimeToVerify = &fileTime; |
| 714 | } |
| 715 | if ((ret = CompareFileTime(pTimeToVerify, &pCrlInfo->ThisUpdate)) >= 0) |
| 716 | { |
| 717 | ret = CompareFileTime(pTimeToVerify, &pCrlInfo->NextUpdate); |
| 718 | if (ret < 0) |
| 719 | ret = 0; |
| 720 | } |
| 721 | return ret; |
| 722 | } |