1 /* crypto/x509/by_dir.c */ 2 /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) 3 * All rights reserved. 4 * 5 * This package is an SSL implementation written 6 * by Eric Young (eay@cryptsoft.com). 7 * The implementation was written so as to conform with Netscapes SSL. 8 * 9 * This library is free for commercial and non-commercial use as long as 10 * the following conditions are aheared to. The following conditions 11 * apply to all code found in this distribution, be it the RC4, RSA, 12 * lhash, DES, etc., code; not just the SSL code. The SSL documentation 13 * included with this distribution is covered by the same copyright terms 14 * except that the holder is Tim Hudson (tjh@cryptsoft.com). 15 * 16 * Copyright remains Eric Young's, and as such any Copyright notices in 17 * the code are not to be removed. 18 * If this package is used in a product, Eric Young should be given attribution 19 * as the author of the parts of the library used. 20 * This can be in the form of a textual message at program startup or 21 * in documentation (online or textual) provided with the package. 22 * 23 * Redistribution and use in source and binary forms, with or without 24 * modification, are permitted provided that the following conditions 25 * are met: 26 * 1. Redistributions of source code must retain the copyright 27 * notice, this list of conditions and the following disclaimer. 28 * 2. Redistributions in binary form must reproduce the above copyright 29 * notice, this list of conditions and the following disclaimer in the 30 * documentation and/or other materials provided with the distribution. 31 * 3. All advertising materials mentioning features or use of this software 32 * must display the following acknowledgement: 33 * "This product includes cryptographic software written by 34 * Eric Young (eay@cryptsoft.com)" 35 * The word 'cryptographic' can be left out if the rouines from the library 36 * being used are not cryptographic related :-). 37 * 4. If you include any Windows specific code (or a derivative thereof) from 38 * the apps directory (application code) you must include an acknowledgement: 39 * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" 40 * 41 * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND 42 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 43 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 44 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE 45 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 46 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 47 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 48 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 49 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 50 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 51 * SUCH DAMAGE. 52 * 53 * The licence and distribution terms for any publically available version or 54 * derivative of this code cannot be changed. i.e. this code cannot simply be 55 * copied and put under another distribution licence 56 * [including the GNU Public Licence.] 57 */ 58 59 #include <stdio.h> 60 #include <time.h> 61 #include <errno.h> 62 63 #include "cryptlib.h" 64 65 #ifndef NO_SYS_TYPES_H 66 # include <sys/types.h> 67 #endif 68 #ifdef MAC_OS_pre_X 69 # include <stat.h> 70 #else 71 # include <sys/stat.h> 72 #endif 73 74 #include <openssl/lhash.h> 75 #include <openssl/x509.h> 76 77 #ifdef _WIN32 78 #define stat _stat 79 #endif 80 81 typedef struct lookup_dir_st 82 { 83 BUF_MEM *buffer; 84 int num_dirs; 85 char **dirs; 86 int *dirs_type; 87 int num_dirs_alloced; 88 } BY_DIR; 89 90 static int dir_ctrl(X509_LOOKUP *ctx, int cmd, const char *argp, long argl, 91 char **ret); 92 static int new_dir(X509_LOOKUP *lu); 93 static void free_dir(X509_LOOKUP *lu); 94 static int add_cert_dir(BY_DIR *ctx,const char *dir,int type); 95 static int get_cert_by_subject(X509_LOOKUP *xl,int type,X509_NAME *name, 96 X509_OBJECT *ret); 97 X509_LOOKUP_METHOD x509_dir_lookup= 98 { 99 "Load certs from files in a directory", 100 new_dir, /* new */ 101 free_dir, /* free */ 102 NULL, /* init */ 103 NULL, /* shutdown */ 104 dir_ctrl, /* ctrl */ 105 get_cert_by_subject, /* get_by_subject */ 106 NULL, /* get_by_issuer_serial */ 107 NULL, /* get_by_fingerprint */ 108 NULL, /* get_by_alias */ 109 }; 110 111 X509_LOOKUP_METHOD *X509_LOOKUP_hash_dir(void) 112 { 113 return(&x509_dir_lookup); 114 } 115 116 static int dir_ctrl(X509_LOOKUP *ctx, int cmd, const char *argp, long argl, 117 char **retp) 118 { 119 int ret=0; 120 BY_DIR *ld; 121 char *dir = NULL; 122 123 ld=(BY_DIR *)ctx->method_data; 124 125 switch (cmd) 126 { 127 case X509_L_ADD_DIR: 128 if (argl == X509_FILETYPE_DEFAULT) 129 { 130 dir=(char *)Getenv(X509_get_default_cert_dir_env()); 131 if (dir) 132 ret=add_cert_dir(ld,dir,X509_FILETYPE_PEM); 133 else 134 ret=add_cert_dir(ld,X509_get_default_cert_dir(), 135 X509_FILETYPE_PEM); 136 if (!ret) 137 { 138 X509err(X509_F_DIR_CTRL,X509_R_LOADING_CERT_DIR); 139 } 140 } 141 else 142 ret=add_cert_dir(ld,argp,(int)argl); 143 break; 144 } 145 return(ret); 146 } 147 148 static int new_dir(X509_LOOKUP *lu) 149 { 150 BY_DIR *a; 151 152 if ((a=(BY_DIR *)OPENSSL_malloc(sizeof(BY_DIR))) == NULL) 153 return(0); 154 if ((a->buffer=BUF_MEM_new()) == NULL) 155 { 156 OPENSSL_free(a); 157 return(0); 158 } 159 a->num_dirs=0; 160 a->dirs=NULL; 161 a->dirs_type=NULL; 162 a->num_dirs_alloced=0; 163 lu->method_data=(char *)a; 164 return(1); 165 } 166 167 static void free_dir(X509_LOOKUP *lu) 168 { 169 BY_DIR *a; 170 int i; 171 172 a=(BY_DIR *)lu->method_data; 173 for (i=0; i<a->num_dirs; i++) 174 if (a->dirs[i] != NULL) OPENSSL_free(a->dirs[i]); 175 if (a->dirs != NULL) OPENSSL_free(a->dirs); 176 if (a->dirs_type != NULL) OPENSSL_free(a->dirs_type); 177 if (a->buffer != NULL) BUF_MEM_free(a->buffer); 178 OPENSSL_free(a); 179 } 180 181 static int add_cert_dir(BY_DIR *ctx, const char *dir, int type) 182 { 183 int j,len; 184 int *ip; 185 const char *s,*ss,*p; 186 char **pp; 187 188 if (dir == NULL || !*dir) 189 { 190 X509err(X509_F_ADD_CERT_DIR,X509_R_INVALID_DIRECTORY); 191 return 0; 192 } 193 194 s=dir; 195 p=s; 196 for (;;p++) 197 { 198 if ((*p == LIST_SEPARATOR_CHAR) || (*p == '\0')) 199 { 200 ss=s; 201 s=p+1; 202 len=(int)(p-ss); 203 if (len == 0) continue; 204 for (j=0; j<ctx->num_dirs; j++) 205 if (strlen(ctx->dirs[j]) == (size_t)len && 206 strncmp(ctx->dirs[j],ss,(unsigned int)len) == 0) 207 break; 208 if (j<ctx->num_dirs) 209 continue; 210 if (ctx->num_dirs_alloced < (ctx->num_dirs+1)) 211 { 212 ctx->num_dirs_alloced+=10; 213 pp=(char **)OPENSSL_malloc(ctx->num_dirs_alloced* 214 sizeof(char *)); 215 ip=(int *)OPENSSL_malloc(ctx->num_dirs_alloced* 216 sizeof(int)); 217 if ((pp == NULL) || (ip == NULL)) 218 { 219 X509err(X509_F_ADD_CERT_DIR,ERR_R_MALLOC_FAILURE); 220 return(0); 221 } 222 memcpy(pp,ctx->dirs,(ctx->num_dirs_alloced-10)* 223 sizeof(char *)); 224 memcpy(ip,ctx->dirs_type,(ctx->num_dirs_alloced-10)* 225 sizeof(int)); 226 if (ctx->dirs != NULL) 227 OPENSSL_free(ctx->dirs); 228 if (ctx->dirs_type != NULL) 229 OPENSSL_free(ctx->dirs_type); 230 ctx->dirs=pp; 231 ctx->dirs_type=ip; 232 } 233 ctx->dirs_type[ctx->num_dirs]=type; 234 ctx->dirs[ctx->num_dirs]=(char *)OPENSSL_malloc((unsigned int)len+1); 235 if (ctx->dirs[ctx->num_dirs] == NULL) return(0); 236 strncpy(ctx->dirs[ctx->num_dirs],ss,(unsigned int)len); 237 ctx->dirs[ctx->num_dirs][len]='\0'; 238 ctx->num_dirs++; 239 } 240 if (*p == '\0') break; 241 } 242 return(1); 243 } 244 245 static int get_cert_by_subject(X509_LOOKUP *xl, int type, X509_NAME *name, 246 X509_OBJECT *ret) 247 { 248 BY_DIR *ctx; 249 union { 250 struct { 251 X509 st_x509; 252 X509_CINF st_x509_cinf; 253 } x509; 254 struct { 255 X509_CRL st_crl; 256 X509_CRL_INFO st_crl_info; 257 } crl; 258 } data; 259 int ok=0; 260 int i,j,k; 261 unsigned long h; 262 BUF_MEM *b=NULL; 263 struct stat st; 264 X509_OBJECT stmp,*tmp; 265 const char *postfix=""; 266 267 if (name == NULL) return(0); 268 269 stmp.type=type; 270 if (type == X509_LU_X509) 271 { 272 data.x509.st_x509.cert_info= &data.x509.st_x509_cinf; 273 data.x509.st_x509_cinf.subject=name; 274 stmp.data.x509= &data.x509.st_x509; 275 postfix=""; 276 } 277 else if (type == X509_LU_CRL) 278 { 279 data.crl.st_crl.crl= &data.crl.st_crl_info; 280 data.crl.st_crl_info.issuer=name; 281 stmp.data.crl= &data.crl.st_crl; 282 postfix="r"; 283 } 284 else 285 { 286 X509err(X509_F_GET_CERT_BY_SUBJECT,X509_R_WRONG_LOOKUP_TYPE); 287 goto finish; 288 } 289 290 if ((b=BUF_MEM_new()) == NULL) 291 { 292 X509err(X509_F_GET_CERT_BY_SUBJECT,ERR_R_BUF_LIB); 293 goto finish; 294 } 295 296 ctx=(BY_DIR *)xl->method_data; 297 298 h=X509_NAME_hash(name); 299 for (i=0; i<ctx->num_dirs; i++) 300 { 301 j=strlen(ctx->dirs[i])+1+8+6+1+1; 302 if (!BUF_MEM_grow(b,j)) 303 { 304 X509err(X509_F_GET_CERT_BY_SUBJECT,ERR_R_MALLOC_FAILURE); 305 goto finish; 306 } 307 k=0; 308 for (;;) 309 { 310 char c = '/'; 311 #ifdef OPENSSL_SYS_VMS 312 c = ctx->dirs[i][strlen(ctx->dirs[i])-1]; 313 if (c != ':' && c != '>' && c != ']') 314 { 315 /* If no separator is present, we assume the 316 directory specifier is a logical name, and 317 add a colon. We really should use better 318 VMS routines for merging things like this, 319 but this will do for now... 320 -- Richard Levitte */ 321 c = ':'; 322 } 323 else 324 { 325 c = '\0'; 326 } 327 #endif 328 if (c == '\0') 329 { 330 /* This is special. When c == '\0', no 331 directory separator should be added. */ 332 BIO_snprintf(b->data,b->max, 333 "%s%08lx.%s%d",ctx->dirs[i],h, 334 postfix,k); 335 } 336 else 337 { 338 BIO_snprintf(b->data,b->max, 339 "%s%c%08lx.%s%d",ctx->dirs[i],c,h, 340 postfix,k); 341 } 342 k++; 343 if (stat(b->data,&st) < 0) 344 break; 345 /* found one. */ 346 if (type == X509_LU_X509) 347 { 348 if ((X509_load_cert_file(xl,b->data, 349 ctx->dirs_type[i])) == 0) 350 break; 351 } 352 else if (type == X509_LU_CRL) 353 { 354 if ((X509_load_crl_file(xl,b->data, 355 ctx->dirs_type[i])) == 0) 356 break; 357 } 358 /* else case will caught higher up */ 359 } 360 361 /* we have added it to the cache so now pull 362 * it out again */ 363 CRYPTO_r_lock(CRYPTO_LOCK_X509_STORE); 364 j = sk_X509_OBJECT_find(xl->store_ctx->objs,&stmp); 365 if(j != -1) tmp=sk_X509_OBJECT_value(xl->store_ctx->objs,j); 366 else tmp = NULL; 367 CRYPTO_r_unlock(CRYPTO_LOCK_X509_STORE); 368 369 if (tmp != NULL) 370 { 371 ok=1; 372 ret->type=tmp->type; 373 memcpy(&ret->data,&tmp->data,sizeof(ret->data)); 374 /* If we were going to up the reference count, 375 * we would need to do it on a perl 'type' 376 * basis */ 377 /* CRYPTO_add(&tmp->data.x509->references,1, 378 CRYPTO_LOCK_X509);*/ 379 goto finish; 380 } 381 } 382 finish: 383 if (b != NULL) BUF_MEM_free(b); 384 return(ok); 385 } 386 387