1 /**
2  * \file x509.h
3  *
4  * \brief X.509 generic defines and structures
5  */
6 /*
7  *  Copyright The Mbed TLS Contributors
8  *  SPDX-License-Identifier: Apache-2.0
9  *
10  *  Licensed under the Apache License, Version 2.0 (the "License"); you may
11  *  not use this file except in compliance with the License.
12  *  You may obtain a copy of the License at
13  *
14  *  http://www.apache.org/licenses/LICENSE-2.0
15  *
16  *  Unless required by applicable law or agreed to in writing, software
17  *  distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
18  *  WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
19  *  See the License for the specific language governing permissions and
20  *  limitations under the License.
21  */
22 #ifndef MBEDTLS_X509_H
23 #define MBEDTLS_X509_H
24 
25 #if !defined(MBEDTLS_CONFIG_FILE)
26 #include "mbedtls/config.h"
27 #else
28 #include MBEDTLS_CONFIG_FILE
29 #endif
30 
31 #include "mbedtls/asn1.h"
32 #include "mbedtls/pk.h"
33 
34 #if defined(MBEDTLS_RSA_C)
35 #include "mbedtls/rsa.h"
36 #endif
37 
38 /**
39  * \addtogroup x509_module
40  * \{
41  */
42 
43 #if !defined(MBEDTLS_X509_MAX_INTERMEDIATE_CA)
44 /**
45  * Maximum number of intermediate CAs in a verification chain.
46  * That is, maximum length of the chain, excluding the end-entity certificate
47  * and the trusted root certificate.
48  *
49  * Set this to a low value to prevent an adversary from making you waste
50  * resources verifying an overlong certificate chain.
51  */
52 #define MBEDTLS_X509_MAX_INTERMEDIATE_CA   8
53 #endif
54 
55 /**
56  * \name X509 Error codes
57  * \{
58  */
59 /** Unavailable feature, e.g. RSA hashing/encryption combination. */
60 #define MBEDTLS_ERR_X509_FEATURE_UNAVAILABLE              -0x2080
61 /** Requested OID is unknown. */
62 #define MBEDTLS_ERR_X509_UNKNOWN_OID                      -0x2100
63 /** The CRT/CRL/CSR format is invalid, e.g. different type expected. */
64 #define MBEDTLS_ERR_X509_INVALID_FORMAT                   -0x2180
65 /** The CRT/CRL/CSR version element is invalid. */
66 #define MBEDTLS_ERR_X509_INVALID_VERSION                  -0x2200
67 /** The serial tag or value is invalid. */
68 #define MBEDTLS_ERR_X509_INVALID_SERIAL                   -0x2280
69 /** The algorithm tag or value is invalid. */
70 #define MBEDTLS_ERR_X509_INVALID_ALG                      -0x2300
71 /** The name tag or value is invalid. */
72 #define MBEDTLS_ERR_X509_INVALID_NAME                     -0x2380
73 /** The date tag or value is invalid. */
74 #define MBEDTLS_ERR_X509_INVALID_DATE                     -0x2400
75 /** The signature tag or value invalid. */
76 #define MBEDTLS_ERR_X509_INVALID_SIGNATURE                -0x2480
77 /** The extension tag or value is invalid. */
78 #define MBEDTLS_ERR_X509_INVALID_EXTENSIONS               -0x2500
79 /** CRT/CRL/CSR has an unsupported version number. */
80 #define MBEDTLS_ERR_X509_UNKNOWN_VERSION                  -0x2580
81 /** Signature algorithm (oid) is unsupported. */
82 #define MBEDTLS_ERR_X509_UNKNOWN_SIG_ALG                  -0x2600
83 /** Signature algorithms do not match. (see \c ::mbedtls_x509_crt sig_oid) */
84 #define MBEDTLS_ERR_X509_SIG_MISMATCH                     -0x2680
85 /** Certificate verification failed, e.g. CRL, CA or signature check failed. */
86 #define MBEDTLS_ERR_X509_CERT_VERIFY_FAILED               -0x2700
87 /** Format not recognized as DER or PEM. */
88 #define MBEDTLS_ERR_X509_CERT_UNKNOWN_FORMAT              -0x2780
89 /** Input invalid. */
90 #define MBEDTLS_ERR_X509_BAD_INPUT_DATA                   -0x2800
91 /** Allocation of memory failed. */
92 #define MBEDTLS_ERR_X509_ALLOC_FAILED                     -0x2880
93 /** Read/write of file failed. */
94 #define MBEDTLS_ERR_X509_FILE_IO_ERROR                    -0x2900
95 /** Destination buffer is too small. */
96 #define MBEDTLS_ERR_X509_BUFFER_TOO_SMALL                 -0x2980
97 /** A fatal error occurred, eg the chain is too long or the vrfy callback failed. */
98 #define MBEDTLS_ERR_X509_FATAL_ERROR                      -0x3000
99 /** \} name X509 Error codes */
100 
101 /**
102  * \name X509 Verify codes
103  * \{
104  */
105 /* Reminder: update x509_crt_verify_strings[] in library/x509_crt.c */
106 #define MBEDTLS_X509_BADCERT_EXPIRED             0x01  /**< The certificate validity has expired. */
107 #define MBEDTLS_X509_BADCERT_REVOKED             0x02  /**< The certificate has been revoked (is on a CRL). */
108 #define MBEDTLS_X509_BADCERT_CN_MISMATCH         0x04  /**< The certificate Common Name (CN) does not match with the expected CN. */
109 #define MBEDTLS_X509_BADCERT_NOT_TRUSTED         0x08  /**< The certificate is not correctly signed by the trusted CA. */
110 #define MBEDTLS_X509_BADCRL_NOT_TRUSTED          0x10  /**< The CRL is not correctly signed by the trusted CA. */
111 #define MBEDTLS_X509_BADCRL_EXPIRED              0x20  /**< The CRL is expired. */
112 #define MBEDTLS_X509_BADCERT_MISSING             0x40  /**< Certificate was missing. */
113 #define MBEDTLS_X509_BADCERT_SKIP_VERIFY         0x80  /**< Certificate verification was skipped. */
114 #define MBEDTLS_X509_BADCERT_OTHER             0x0100  /**< Other reason (can be used by verify callback) */
115 #define MBEDTLS_X509_BADCERT_FUTURE            0x0200  /**< The certificate validity starts in the future. */
116 #define MBEDTLS_X509_BADCRL_FUTURE             0x0400  /**< The CRL is from the future */
117 #define MBEDTLS_X509_BADCERT_KEY_USAGE         0x0800  /**< Usage does not match the keyUsage extension. */
118 #define MBEDTLS_X509_BADCERT_EXT_KEY_USAGE     0x1000  /**< Usage does not match the extendedKeyUsage extension. */
119 #define MBEDTLS_X509_BADCERT_NS_CERT_TYPE      0x2000  /**< Usage does not match the nsCertType extension. */
120 #define MBEDTLS_X509_BADCERT_BAD_MD            0x4000  /**< The certificate is signed with an unacceptable hash. */
121 #define MBEDTLS_X509_BADCERT_BAD_PK            0x8000  /**< The certificate is signed with an unacceptable PK alg (eg RSA vs ECDSA). */
122 #define MBEDTLS_X509_BADCERT_BAD_KEY         0x010000  /**< The certificate is signed with an unacceptable key (eg bad curve, RSA too short). */
123 #define MBEDTLS_X509_BADCRL_BAD_MD           0x020000  /**< The CRL is signed with an unacceptable hash. */
124 #define MBEDTLS_X509_BADCRL_BAD_PK           0x040000  /**< The CRL is signed with an unacceptable PK alg (eg RSA vs ECDSA). */
125 #define MBEDTLS_X509_BADCRL_BAD_KEY          0x080000  /**< The CRL is signed with an unacceptable key (eg bad curve, RSA too short). */
126 
127 /** \} name X509 Verify codes */
128 /** \} addtogroup x509_module */
129 
130 /*
131  * X.509 v3 Subject Alternative Name types.
132  *      otherName                       [0]     OtherName,
133  *      rfc822Name                      [1]     IA5String,
134  *      dNSName                         [2]     IA5String,
135  *      x400Address                     [3]     ORAddress,
136  *      directoryName                   [4]     Name,
137  *      ediPartyName                    [5]     EDIPartyName,
138  *      uniformResourceIdentifier       [6]     IA5String,
139  *      iPAddress                       [7]     OCTET STRING,
140  *      registeredID                    [8]     OBJECT IDENTIFIER
141  */
142 #define MBEDTLS_X509_SAN_OTHER_NAME                      0
143 #define MBEDTLS_X509_SAN_RFC822_NAME                     1
144 #define MBEDTLS_X509_SAN_DNS_NAME                        2
145 #define MBEDTLS_X509_SAN_X400_ADDRESS_NAME               3
146 #define MBEDTLS_X509_SAN_DIRECTORY_NAME                  4
147 #define MBEDTLS_X509_SAN_EDI_PARTY_NAME                  5
148 #define MBEDTLS_X509_SAN_UNIFORM_RESOURCE_IDENTIFIER     6
149 #define MBEDTLS_X509_SAN_IP_ADDRESS                      7
150 #define MBEDTLS_X509_SAN_REGISTERED_ID                   8
151 
152 /*
153  * X.509 v3 Key Usage Extension flags
154  * Reminder: update x509_info_key_usage() when adding new flags.
155  */
156 #define MBEDTLS_X509_KU_DIGITAL_SIGNATURE            (0x80)  /* bit 0 */
157 #define MBEDTLS_X509_KU_NON_REPUDIATION              (0x40)  /* bit 1 */
158 #define MBEDTLS_X509_KU_KEY_ENCIPHERMENT             (0x20)  /* bit 2 */
159 #define MBEDTLS_X509_KU_DATA_ENCIPHERMENT            (0x10)  /* bit 3 */
160 #define MBEDTLS_X509_KU_KEY_AGREEMENT                (0x08)  /* bit 4 */
161 #define MBEDTLS_X509_KU_KEY_CERT_SIGN                (0x04)  /* bit 5 */
162 #define MBEDTLS_X509_KU_CRL_SIGN                     (0x02)  /* bit 6 */
163 #define MBEDTLS_X509_KU_ENCIPHER_ONLY                (0x01)  /* bit 7 */
164 #define MBEDTLS_X509_KU_DECIPHER_ONLY              (0x8000)  /* bit 8 */
165 
166 /*
167  * Netscape certificate types
168  * (http://www.mozilla.org/projects/security/pki/nss/tech-notes/tn3.html)
169  */
170 
171 #define MBEDTLS_X509_NS_CERT_TYPE_SSL_CLIENT         (0x80)  /* bit 0 */
172 #define MBEDTLS_X509_NS_CERT_TYPE_SSL_SERVER         (0x40)  /* bit 1 */
173 #define MBEDTLS_X509_NS_CERT_TYPE_EMAIL              (0x20)  /* bit 2 */
174 #define MBEDTLS_X509_NS_CERT_TYPE_OBJECT_SIGNING     (0x10)  /* bit 3 */
175 #define MBEDTLS_X509_NS_CERT_TYPE_RESERVED           (0x08)  /* bit 4 */
176 #define MBEDTLS_X509_NS_CERT_TYPE_SSL_CA             (0x04)  /* bit 5 */
177 #define MBEDTLS_X509_NS_CERT_TYPE_EMAIL_CA           (0x02)  /* bit 6 */
178 #define MBEDTLS_X509_NS_CERT_TYPE_OBJECT_SIGNING_CA  (0x01)  /* bit 7 */
179 
180 /*
181  * X.509 extension types
182  *
183  * Comments refer to the status for using certificates. Status can be
184  * different for writing certificates or reading CRLs or CSRs.
185  *
186  * Those are defined in oid.h as oid.c needs them in a data structure. Since
187  * these were previously defined here, let's have aliases for compatibility.
188  */
189 #define MBEDTLS_X509_EXT_AUTHORITY_KEY_IDENTIFIER MBEDTLS_OID_X509_EXT_AUTHORITY_KEY_IDENTIFIER
190 #define MBEDTLS_X509_EXT_SUBJECT_KEY_IDENTIFIER   MBEDTLS_OID_X509_EXT_SUBJECT_KEY_IDENTIFIER
191 #define MBEDTLS_X509_EXT_KEY_USAGE                MBEDTLS_OID_X509_EXT_KEY_USAGE
192 #define MBEDTLS_X509_EXT_CERTIFICATE_POLICIES     MBEDTLS_OID_X509_EXT_CERTIFICATE_POLICIES
193 #define MBEDTLS_X509_EXT_POLICY_MAPPINGS          MBEDTLS_OID_X509_EXT_POLICY_MAPPINGS
194 #define MBEDTLS_X509_EXT_SUBJECT_ALT_NAME         MBEDTLS_OID_X509_EXT_SUBJECT_ALT_NAME         /* Supported (DNS) */
195 #define MBEDTLS_X509_EXT_ISSUER_ALT_NAME          MBEDTLS_OID_X509_EXT_ISSUER_ALT_NAME
196 #define MBEDTLS_X509_EXT_SUBJECT_DIRECTORY_ATTRS  MBEDTLS_OID_X509_EXT_SUBJECT_DIRECTORY_ATTRS
197 #define MBEDTLS_X509_EXT_BASIC_CONSTRAINTS        MBEDTLS_OID_X509_EXT_BASIC_CONSTRAINTS        /* Supported */
198 #define MBEDTLS_X509_EXT_NAME_CONSTRAINTS         MBEDTLS_OID_X509_EXT_NAME_CONSTRAINTS
199 #define MBEDTLS_X509_EXT_POLICY_CONSTRAINTS       MBEDTLS_OID_X509_EXT_POLICY_CONSTRAINTS
200 #define MBEDTLS_X509_EXT_EXTENDED_KEY_USAGE       MBEDTLS_OID_X509_EXT_EXTENDED_KEY_USAGE
201 #define MBEDTLS_X509_EXT_CRL_DISTRIBUTION_POINTS  MBEDTLS_OID_X509_EXT_CRL_DISTRIBUTION_POINTS
202 #define MBEDTLS_X509_EXT_INIHIBIT_ANYPOLICY       MBEDTLS_OID_X509_EXT_INIHIBIT_ANYPOLICY
203 #define MBEDTLS_X509_EXT_FRESHEST_CRL             MBEDTLS_OID_X509_EXT_FRESHEST_CRL
204 #define MBEDTLS_X509_EXT_NS_CERT_TYPE             MBEDTLS_OID_X509_EXT_NS_CERT_TYPE
205 
206 /*
207  * Storage format identifiers
208  * Recognized formats: PEM and DER
209  */
210 #define MBEDTLS_X509_FORMAT_DER                 1
211 #define MBEDTLS_X509_FORMAT_PEM                 2
212 
213 #define MBEDTLS_X509_MAX_DN_NAME_SIZE         256 /**< Maximum value size of a DN entry */
214 
215 #ifdef __cplusplus
216 extern "C" {
217 #endif
218 
219 /**
220  * \addtogroup x509_module
221  * \{ */
222 
223 /**
224  * \name Structures for parsing X.509 certificates, CRLs and CSRs
225  * \{
226  */
227 
228 /**
229  * Type-length-value structure that allows for ASN1 using DER.
230  */
231 typedef mbedtls_asn1_buf mbedtls_x509_buf;
232 
233 /**
234  * Container for ASN1 bit strings.
235  */
236 typedef mbedtls_asn1_bitstring mbedtls_x509_bitstring;
237 
238 /**
239  * Container for ASN1 named information objects.
240  * It allows for Relative Distinguished Names (e.g. cn=localhost,ou=code,etc.).
241  */
242 typedef mbedtls_asn1_named_data mbedtls_x509_name;
243 
244 /**
245  * Container for a sequence of ASN.1 items
246  */
247 typedef mbedtls_asn1_sequence mbedtls_x509_sequence;
248 
249 /** Container for date and time (precision in seconds). */
250 typedef struct mbedtls_x509_time
251 {
252     int year, mon, day;         /**< Date. */
253     int hour, min, sec;         /**< Time. */
254 }
255 mbedtls_x509_time;
256 
257 /** \} name Structures for parsing X.509 certificates, CRLs and CSRs */
258 
259 /**
260  * \brief          Store the certificate DN in printable form into buf;
261  *                 no more than size characters will be written.
262  *
263  * \param buf      Buffer to write to
264  * \param size     Maximum size of buffer
265  * \param dn       The X509 name to represent
266  *
267  * \return         The length of the string written (not including the
268  *                 terminated nul byte), or a negative error code.
269  */
270 int mbedtls_x509_dn_gets( char *buf, size_t size, const mbedtls_x509_name *dn );
271 
272 /**
273  * \brief          Store the certificate serial in printable form into buf;
274  *                 no more than size characters will be written.
275  *
276  * \param buf      Buffer to write to
277  * \param size     Maximum size of buffer
278  * \param serial   The X509 serial to represent
279  *
280  * \return         The length of the string written (not including the
281  *                 terminated nul byte), or a negative error code.
282  */
283 int mbedtls_x509_serial_gets( char *buf, size_t size, const mbedtls_x509_buf *serial );
284 
285 /**
286  * \brief          Check a given mbedtls_x509_time against the system time
287  *                 and tell if it's in the past.
288  *
289  * \note           Intended usage is "if( is_past( valid_to ) ) ERROR".
290  *                 Hence the return value of 1 if on internal errors.
291  *
292  * \param to       mbedtls_x509_time to check
293  *
294  * \return         1 if the given time is in the past or an error occurred,
295  *                 0 otherwise.
296  */
297 int mbedtls_x509_time_is_past( const mbedtls_x509_time *to );
298 
299 /**
300  * \brief          Check a given mbedtls_x509_time against the system time
301  *                 and tell if it's in the future.
302  *
303  * \note           Intended usage is "if( is_future( valid_from ) ) ERROR".
304  *                 Hence the return value of 1 if on internal errors.
305  *
306  * \param from     mbedtls_x509_time to check
307  *
308  * \return         1 if the given time is in the future or an error occurred,
309  *                 0 otherwise.
310  */
311 int mbedtls_x509_time_is_future( const mbedtls_x509_time *from );
312 
313 /** \} addtogroup x509_module */
314 
315 #if defined(MBEDTLS_SELF_TEST)
316 
317 /**
318  * \brief          Checkup routine
319  *
320  * \return         0 if successful, or 1 if the test failed
321  */
322 int mbedtls_x509_self_test( int verbose );
323 
324 #endif /* MBEDTLS_SELF_TEST */
325 
326 /*
327  * Internal module functions. You probably do not want to use these unless you
328  * know you do.
329  */
330 int mbedtls_x509_get_name( unsigned char **p, const unsigned char *end,
331                    mbedtls_x509_name *cur );
332 int mbedtls_x509_get_alg_null( unsigned char **p, const unsigned char *end,
333                        mbedtls_x509_buf *alg );
334 int mbedtls_x509_get_alg( unsigned char **p, const unsigned char *end,
335                   mbedtls_x509_buf *alg, mbedtls_x509_buf *params );
336 #if defined(MBEDTLS_X509_RSASSA_PSS_SUPPORT)
337 int mbedtls_x509_get_rsassa_pss_params( const mbedtls_x509_buf *params,
338                                 mbedtls_md_type_t *md_alg, mbedtls_md_type_t *mgf_md,
339                                 int *salt_len );
340 #endif
341 int mbedtls_x509_get_sig( unsigned char **p, const unsigned char *end, mbedtls_x509_buf *sig );
342 int mbedtls_x509_get_sig_alg( const mbedtls_x509_buf *sig_oid, const mbedtls_x509_buf *sig_params,
343                       mbedtls_md_type_t *md_alg, mbedtls_pk_type_t *pk_alg,
344                       void **sig_opts );
345 int mbedtls_x509_get_time( unsigned char **p, const unsigned char *end,
346                    mbedtls_x509_time *t );
347 int mbedtls_x509_get_serial( unsigned char **p, const unsigned char *end,
348                      mbedtls_x509_buf *serial );
349 int mbedtls_x509_get_ext( unsigned char **p, const unsigned char *end,
350                   mbedtls_x509_buf *ext, int tag );
351 int mbedtls_x509_sig_alg_gets( char *buf, size_t size, const mbedtls_x509_buf *sig_oid,
352                        mbedtls_pk_type_t pk_alg, mbedtls_md_type_t md_alg,
353                        const void *sig_opts );
354 int mbedtls_x509_key_size_helper( char *buf, size_t buf_size, const char *name );
355 int mbedtls_x509_string_to_names( mbedtls_asn1_named_data **head, const char *name );
356 int mbedtls_x509_set_extension( mbedtls_asn1_named_data **head, const char *oid, size_t oid_len,
357                         int critical, const unsigned char *val,
358                         size_t val_len );
359 int mbedtls_x509_write_extensions( unsigned char **p, unsigned char *start,
360                            mbedtls_asn1_named_data *first );
361 int mbedtls_x509_write_names( unsigned char **p, unsigned char *start,
362                       mbedtls_asn1_named_data *first );
363 int mbedtls_x509_write_sig( unsigned char **p, unsigned char *start,
364                     const char *oid, size_t oid_len,
365                     unsigned char *sig, size_t size );
366 
367 #define MBEDTLS_X509_SAFE_SNPRINTF                          \
368     do {                                                    \
369         if( ret < 0 || (size_t) ret >= n )                  \
370             return( MBEDTLS_ERR_X509_BUFFER_TOO_SMALL );    \
371                                                             \
372         n -= (size_t) ret;                                  \
373         p += (size_t) ret;                                  \
374     } while( 0 )
375 
376 #ifdef __cplusplus
377 }
378 #endif
379 
380 #endif /* x509.h */
381