1 /* crypto/asn1/t_x509.c */
2 /* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com)
5 * This package is an SSL implementation written
6 * by Eric Young (eay@cryptsoft.com).
7 * The implementation was written so as to conform with Netscapes SSL.
9 * This library is free for commercial and non-commercial use as long as
10 * the following conditions are aheared to. The following conditions
11 * apply to all code found in this distribution, be it the RC4, RSA,
12 * lhash, DES, etc., code; not just the SSL code. The SSL documentation
13 * included with this distribution is covered by the same copyright terms
14 * except that the holder is Tim Hudson (tjh@cryptsoft.com).
16 * Copyright remains Eric Young's, and as such any Copyright notices in
17 * the code are not to be removed.
18 * If this package is used in a product, Eric Young should be given attribution
19 * as the author of the parts of the library used.
20 * This can be in the form of a textual message at program startup or
21 * in documentation (online or textual) provided with the package.
23 * Redistribution and use in source and binary forms, with or without
24 * modification, are permitted provided that the following conditions
26 * 1. Redistributions of source code must retain the copyright
27 * notice, this list of conditions and the following disclaimer.
28 * 2. Redistributions in binary form must reproduce the above copyright
29 * notice, this list of conditions and the following disclaimer in the
30 * documentation and/or other materials provided with the distribution.
31 * 3. All advertising materials mentioning features or use of this software
32 * must display the following acknowledgement:
33 * "This product includes cryptographic software written by
34 * Eric Young (eay@cryptsoft.com)"
35 * The word 'cryptographic' can be left out if the rouines from the library
36 * being used are not cryptographic related :-).
37 * 4. If you include any Windows specific code (or a derivative thereof) from
38 * the apps directory (application code) you must include an acknowledgement:
39 * "This product includes software written by Tim Hudson (tjh@cryptsoft.com)"
41 * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
42 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
43 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
44 * ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
45 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
46 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
47 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
48 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
49 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
50 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
53 * The licence and distribution terms for any publically available version or
54 * derivative of this code cannot be changed. i.e. this code cannot simply be
55 * copied and put under another distribution licence
56 * [including the GNU Public Licence.]
61 #include <openssl/buffer.h>
62 #include <openssl/bn.h>
63 #ifndef OPENSSL_NO_RSA
64 #include <openssl/rsa.h>
66 #ifndef OPENSSL_NO_DSA
67 #include <openssl/dsa.h>
70 #include <openssl/ec.h>
72 #include <openssl/objects.h>
73 #include <openssl/x509.h>
74 #include <openssl/x509v3.h>
76 #ifndef OPENSSL_NO_FP_API
77 int X509_print_fp(FILE *fp
, X509
*x
)
79 return X509_print_ex_fp(fp
, x
, XN_FLAG_COMPAT
, X509_FLAG_COMPAT
);
82 int X509_print_ex_fp(FILE *fp
, X509
*x
, unsigned long nmflag
, unsigned long cflag
)
87 if ((b
=BIO_new(BIO_s_file())) == NULL
)
89 X509err(X509_F_X509_PRINT_EX_FP
,ERR_R_BUF_LIB
);
92 BIO_set_fp(b
,fp
,BIO_NOCLOSE
);
93 ret
=X509_print_ex(b
, x
, nmflag
, cflag
);
99 int X509_print(BIO
*bp
, X509
*x
)
101 return X509_print_ex(bp
, x
, XN_FLAG_COMPAT
, X509_FLAG_COMPAT
);
104 int X509_print_ex(BIO
*bp
, X509
*x
, unsigned long nmflags
, unsigned long cflag
)
108 char *m
=NULL
,mlch
= ' ';
114 ASN1_STRING
*str
=NULL
;
116 if((nmflags
& XN_FLAG_SEP_MASK
) == XN_FLAG_SEP_MULTILINE
) {
121 if(nmflags
== X509_FLAG_COMPAT
)
125 if(!(cflag
& X509_FLAG_NO_HEADER
))
127 if (BIO_write(bp
,"Certificate:\n",13) <= 0) goto err
;
128 if (BIO_write(bp
," Data:\n",10) <= 0) goto err
;
130 if(!(cflag
& X509_FLAG_NO_VERSION
))
132 l
=X509_get_version(x
);
133 if (BIO_printf(bp
,"%8sVersion: %lu (0x%lx)\n","",l
+1,l
) <= 0) goto err
;
135 if(!(cflag
& X509_FLAG_NO_SERIAL
))
138 if (BIO_write(bp
," Serial Number:",22) <= 0) goto err
;
140 bs
=X509_get_serialNumber(x
);
143 l
=ASN1_INTEGER_get(bs
);
151 if (BIO_printf(bp
," %s%lu (%s0x%lx)\n",neg
,l
,neg
,l
) <= 0)
156 neg
=(bs
->type
== V_ASN1_NEG_INTEGER
)?" (Negative)":"";
157 if (BIO_printf(bp
,"\n%12s%s","",neg
) <= 0) goto err
;
159 for (i
=0; i
<bs
->length
; i
++)
161 if (BIO_printf(bp
,"%02x%c",bs
->data
[i
],
162 ((i
+1 == bs
->length
)?'\n':':')) <= 0)
169 if(!(cflag
& X509_FLAG_NO_SIGNAME
))
171 if (BIO_printf(bp
,"%8sSignature Algorithm: ","") <= 0)
173 if (i2a_ASN1_OBJECT(bp
, ci
->signature
->algorithm
) <= 0)
175 if (BIO_puts(bp
, "\n") <= 0)
179 if(!(cflag
& X509_FLAG_NO_ISSUER
))
181 if (BIO_printf(bp
," Issuer:%c",mlch
) <= 0) goto err
;
182 if (X509_NAME_print_ex(bp
,X509_get_issuer_name(x
),nmindent
, nmflags
) < 0) goto err
;
183 if (BIO_write(bp
,"\n",1) <= 0) goto err
;
185 if(!(cflag
& X509_FLAG_NO_VALIDITY
))
187 if (BIO_write(bp
," Validity\n",17) <= 0) goto err
;
188 if (BIO_write(bp
," Not Before: ",24) <= 0) goto err
;
189 if (!ASN1_TIME_print(bp
,X509_get_notBefore(x
))) goto err
;
190 if (BIO_write(bp
,"\n Not After : ",25) <= 0) goto err
;
191 if (!ASN1_TIME_print(bp
,X509_get_notAfter(x
))) goto err
;
192 if (BIO_write(bp
,"\n",1) <= 0) goto err
;
194 if(!(cflag
& X509_FLAG_NO_SUBJECT
))
196 if (BIO_printf(bp
," Subject:%c",mlch
) <= 0) goto err
;
197 if (X509_NAME_print_ex(bp
,X509_get_subject_name(x
),nmindent
, nmflags
) < 0) goto err
;
198 if (BIO_write(bp
,"\n",1) <= 0) goto err
;
200 if(!(cflag
& X509_FLAG_NO_PUBKEY
))
202 if (BIO_write(bp
," Subject Public Key Info:\n",33) <= 0)
204 if (BIO_printf(bp
,"%12sPublic Key Algorithm: ","") <= 0)
206 if (i2a_ASN1_OBJECT(bp
, ci
->key
->algor
->algorithm
) <= 0)
208 if (BIO_puts(bp
, "\n") <= 0)
211 pkey
=X509_get_pubkey(x
);
214 BIO_printf(bp
,"%12sUnable to load Public Key\n","");
215 ERR_print_errors(bp
);
218 #ifndef OPENSSL_NO_RSA
219 if (pkey
->type
== EVP_PKEY_RSA
)
221 BIO_printf(bp
,"%12sRSA Public Key: (%d bit)\n","",
222 BN_num_bits(pkey
->pkey
.rsa
->n
));
223 RSA_print(bp
,pkey
->pkey
.rsa
,16);
227 #ifndef OPENSSL_NO_DSA
228 if (pkey
->type
== EVP_PKEY_DSA
)
230 BIO_printf(bp
,"%12sDSA Public Key:\n","");
231 DSA_print(bp
,pkey
->pkey
.dsa
,16);
235 #ifndef OPENSSL_NO_EC
236 if (pkey
->type
== EVP_PKEY_EC
)
238 BIO_printf(bp
, "%12sEC Public Key:\n","");
239 EC_KEY_print(bp
, pkey
->pkey
.ec
, 16);
243 BIO_printf(bp
,"%12sUnknown Public Key:\n","");
248 if (!(cflag
& X509_FLAG_NO_EXTENSIONS
))
249 X509V3_extensions_print(bp
, "X509v3 extensions",
250 ci
->extensions
, cflag
, 8);
252 if(!(cflag
& X509_FLAG_NO_SIGDUMP
))
254 if(X509_signature_print(bp
, x
->sig_alg
, x
->signature
) <= 0) goto err
;
256 if(!(cflag
& X509_FLAG_NO_AUX
))
258 if (!X509_CERT_AUX_print(bp
, x
->aux
, 0)) goto err
;
262 if (str
!= NULL
) ASN1_STRING_free(str
);
263 if (m
!= NULL
) OPENSSL_free(m
);
267 int X509_ocspid_print (BIO
*bp
, X509
*x
)
269 unsigned char *der
=NULL
;
270 unsigned char *dertmp
;
273 unsigned char SHA1md
[SHA_DIGEST_LENGTH
];
275 /* display the hash of the subject as it would appear
277 if (BIO_printf(bp
," Subject OCSP hash: ") <= 0)
279 derlen
= i2d_X509_NAME(x
->cert_info
->subject
, NULL
);
280 if ((der
= dertmp
= (unsigned char *)OPENSSL_malloc (derlen
)) == NULL
)
282 i2d_X509_NAME(x
->cert_info
->subject
, &dertmp
);
284 EVP_Digest(der
, derlen
, SHA1md
, NULL
, EVP_sha1(), NULL
);
285 for (i
=0; i
< SHA_DIGEST_LENGTH
; i
++)
287 if (BIO_printf(bp
,"%02X",SHA1md
[i
]) <= 0) goto err
;
292 /* display the hash of the public key as it would appear
294 if (BIO_printf(bp
,"\n Public key OCSP hash: ") <= 0)
297 EVP_Digest(x
->cert_info
->key
->public_key
->data
,
298 x
->cert_info
->key
->public_key
->length
, SHA1md
, NULL
, EVP_sha1(), NULL
);
299 for (i
=0; i
< SHA_DIGEST_LENGTH
; i
++)
301 if (BIO_printf(bp
,"%02X",SHA1md
[i
]) <= 0)
308 if (der
!= NULL
) OPENSSL_free(der
);
312 int X509_signature_print(BIO
*bp
, X509_ALGOR
*sigalg
, ASN1_STRING
*sig
)
316 if (BIO_puts(bp
," Signature Algorithm: ") <= 0) return 0;
317 if (i2a_ASN1_OBJECT(bp
, sigalg
->algorithm
) <= 0) return 0;
324 if (BIO_write(bp
,"\n ",9) <= 0) return 0;
325 if (BIO_printf(bp
,"%02x%s",s
[i
],
326 ((i
+1) == n
)?"":":") <= 0) return 0;
328 if (BIO_write(bp
,"\n",1) != 1) return 0;
332 int ASN1_STRING_print(BIO
*bp
, ASN1_STRING
*v
)
337 if (v
== NULL
) return(0);
340 for (i
=0; i
<v
->length
; i
++)
342 if ((p
[i
] > '~') || ((p
[i
] < ' ') &&
343 (p
[i
] != '\n') && (p
[i
] != '\r')))
350 if (BIO_write(bp
,buf
,n
) <= 0)
356 if (BIO_write(bp
,buf
,n
) <= 0)
361 int ASN1_TIME_print(BIO
*bp
, ASN1_TIME
*tm
)
363 if(tm
->type
== V_ASN1_UTCTIME
) return ASN1_UTCTIME_print(bp
, tm
);
364 if(tm
->type
== V_ASN1_GENERALIZEDTIME
)
365 return ASN1_GENERALIZEDTIME_print(bp
, tm
);
366 BIO_write(bp
,"Bad time value",14);
370 static const char *mon
[12]=
372 "Jan","Feb","Mar","Apr","May","Jun",
373 "Jul","Aug","Sep","Oct","Nov","Dec"
376 int ASN1_GENERALIZEDTIME_print(BIO
*bp
, ASN1_GENERALIZEDTIME
*tm
)
381 int y
=0,M
=0,d
=0,h
=0,m
=0,s
=0;
386 if (i
< 12) goto err
;
387 if (v
[i
-1] == 'Z') gmt
=1;
389 if ((v
[i
] > '9') || (v
[i
] < '0')) goto err
;
390 y
= (v
[0]-'0')*1000+(v
[1]-'0')*100 + (v
[2]-'0')*10+(v
[3]-'0');
391 M
= (v
[4]-'0')*10+(v
[5]-'0');
392 if ((M
> 12) || (M
< 1)) goto err
;
393 d
= (v
[6]-'0')*10+(v
[7]-'0');
394 h
= (v
[8]-'0')*10+(v
[9]-'0');
395 m
= (v
[10]-'0')*10+(v
[11]-'0');
397 (v
[12] >= '0') && (v
[12] <= '9') &&
398 (v
[13] >= '0') && (v
[13] <= '9'))
399 s
= (v
[12]-'0')*10+(v
[13]-'0');
401 if (BIO_printf(bp
,"%s %2d %02d:%02d:%02d %d%s",
402 mon
[M
-1],d
,h
,m
,s
,y
,(gmt
)?" GMT":"") <= 0)
407 BIO_write(bp
,"Bad time value",14);
411 int ASN1_UTCTIME_print(BIO
*bp
, ASN1_UTCTIME
*tm
)
416 int y
=0,M
=0,d
=0,h
=0,m
=0,s
=0;
421 if (i
< 10) goto err
;
422 if (v
[i
-1] == 'Z') gmt
=1;
424 if ((v
[i
] > '9') || (v
[i
] < '0')) goto err
;
425 y
= (v
[0]-'0')*10+(v
[1]-'0');
427 M
= (v
[2]-'0')*10+(v
[3]-'0');
428 if ((M
> 12) || (M
< 1)) goto err
;
429 d
= (v
[4]-'0')*10+(v
[5]-'0');
430 h
= (v
[6]-'0')*10+(v
[7]-'0');
431 m
= (v
[8]-'0')*10+(v
[9]-'0');
433 (v
[10] >= '0') && (v
[10] <= '9') &&
434 (v
[11] >= '0') && (v
[11] <= '9'))
435 s
= (v
[10]-'0')*10+(v
[11]-'0');
437 if (BIO_printf(bp
,"%s %2d %02d:%02d:%02d %d%s",
438 mon
[M
-1],d
,h
,m
,s
,y
+1900,(gmt
)?" GMT":"") <= 0)
443 BIO_write(bp
,"Bad time value",14);
447 int X509_NAME_print(BIO
*bp
, X509_NAME
*name
, int obase
)
454 b
=X509_NAME_oneline(name
,NULL
,0);
460 s
=b
+1; /* skip the first slash */
465 #ifndef CHARSET_EBCDIC
467 ((s
[1] >= 'A') && (s
[1] <= 'Z') && (
469 ((s
[2] >= 'A') && (s
[2] <= 'Z') &&
484 if (BIO_write(bp
,c
,i
) != i
) goto err
;
485 c
=s
+1; /* skip following slash */
488 if (BIO_write(bp
,", ",2) != 2) goto err
;
492 if (*s
== '\0') break;
501 X509err(X509_F_X509_NAME_PRINT
,ERR_R_BUF_LIB
);