1 | /** |
2 | * \file oid.c |
3 | * |
4 | * \brief Object Identifier (OID) database |
5 | * |
6 | * Copyright The Mbed TLS Contributors |
7 | * SPDX-License-Identifier: Apache-2.0 |
8 | * |
9 | * Licensed under the Apache License, Version 2.0 (the "License"); you may |
10 | * not use this file except in compliance with the License. |
11 | * You may obtain a copy of the License at |
12 | * |
13 | * http://www.apache.org/licenses/LICENSE-2.0 |
14 | * |
15 | * Unless required by applicable law or agreed to in writing, software |
16 | * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT |
17 | * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
18 | * See the License for the specific language governing permissions and |
19 | * limitations under the License. |
20 | */ |
21 | |
22 | #include "common.h" |
23 | |
24 | #if defined(MBEDTLS_OID_C) |
25 | |
26 | #include "mbedtls/oid.h" |
27 | #include "mbedtls/rsa.h" |
28 | #include "mbedtls/error.h" |
29 | |
30 | #include <stdio.h> |
31 | #include <string.h> |
32 | |
33 | #include "mbedtls/platform.h" |
34 | |
35 | /* |
36 | * Macro to automatically add the size of #define'd OIDs |
37 | */ |
38 | #define ADD_LEN(s) s, MBEDTLS_OID_SIZE(s) |
39 | |
40 | /* |
41 | * Macro to generate an internal function for oid_XXX_from_asn1() (used by |
42 | * the other functions) |
43 | */ |
44 | #define FN_OID_TYPED_FROM_ASN1(TYPE_T, NAME, LIST) \ |
45 | static const TYPE_T *oid_ ## NAME ## _from_asn1( \ |
46 | const mbedtls_asn1_buf *oid) \ |
47 | { \ |
48 | const TYPE_T *p = (LIST); \ |
49 | const mbedtls_oid_descriptor_t *cur = \ |
50 | (const mbedtls_oid_descriptor_t *) p; \ |
51 | if (p == NULL || oid == NULL) return NULL; \ |
52 | while (cur->asn1 != NULL) { \ |
53 | if (cur->asn1_len == oid->len && \ |
54 | memcmp(cur->asn1, oid->p, oid->len) == 0) { \ |
55 | return p; \ |
56 | } \ |
57 | p++; \ |
58 | cur = (const mbedtls_oid_descriptor_t *) p; \ |
59 | } \ |
60 | return NULL; \ |
61 | } |
62 | |
63 | /* |
64 | * Macro to generate a function for retrieving a single attribute from the |
65 | * descriptor of an mbedtls_oid_descriptor_t wrapper. |
66 | */ |
67 | #define FN_OID_GET_DESCRIPTOR_ATTR1(FN_NAME, TYPE_T, TYPE_NAME, ATTR1_TYPE, ATTR1) \ |
68 | int FN_NAME(const mbedtls_asn1_buf *oid, ATTR1_TYPE * ATTR1) \ |
69 | { \ |
70 | const TYPE_T *data = oid_ ## TYPE_NAME ## _from_asn1(oid); \ |
71 | if (data == NULL) return MBEDTLS_ERR_OID_NOT_FOUND; \ |
72 | *ATTR1 = data->descriptor.ATTR1; \ |
73 | return 0; \ |
74 | } |
75 | |
76 | /* |
77 | * Macro to generate a function for retrieving a single attribute from an |
78 | * mbedtls_oid_descriptor_t wrapper. |
79 | */ |
80 | #define FN_OID_GET_ATTR1(FN_NAME, TYPE_T, TYPE_NAME, ATTR1_TYPE, ATTR1) \ |
81 | int FN_NAME(const mbedtls_asn1_buf *oid, ATTR1_TYPE * ATTR1) \ |
82 | { \ |
83 | const TYPE_T *data = oid_ ## TYPE_NAME ## _from_asn1(oid); \ |
84 | if (data == NULL) return MBEDTLS_ERR_OID_NOT_FOUND; \ |
85 | *ATTR1 = data->ATTR1; \ |
86 | return 0; \ |
87 | } |
88 | |
89 | /* |
90 | * Macro to generate a function for retrieving two attributes from an |
91 | * mbedtls_oid_descriptor_t wrapper. |
92 | */ |
93 | #define FN_OID_GET_ATTR2(FN_NAME, TYPE_T, TYPE_NAME, ATTR1_TYPE, ATTR1, \ |
94 | ATTR2_TYPE, ATTR2) \ |
95 | int FN_NAME(const mbedtls_asn1_buf *oid, ATTR1_TYPE * ATTR1, \ |
96 | ATTR2_TYPE * ATTR2) \ |
97 | { \ |
98 | const TYPE_T *data = oid_ ## TYPE_NAME ## _from_asn1(oid); \ |
99 | if (data == NULL) return MBEDTLS_ERR_OID_NOT_FOUND; \ |
100 | *(ATTR1) = data->ATTR1; \ |
101 | *(ATTR2) = data->ATTR2; \ |
102 | return 0; \ |
103 | } |
104 | |
105 | /* |
106 | * Macro to generate a function for retrieving the OID based on a single |
107 | * attribute from a mbedtls_oid_descriptor_t wrapper. |
108 | */ |
109 | #define FN_OID_GET_OID_BY_ATTR1(FN_NAME, TYPE_T, LIST, ATTR1_TYPE, ATTR1) \ |
110 | int FN_NAME(ATTR1_TYPE ATTR1, const char **oid, size_t *olen) \ |
111 | { \ |
112 | const TYPE_T *cur = (LIST); \ |
113 | while (cur->descriptor.asn1 != NULL) { \ |
114 | if (cur->ATTR1 == (ATTR1)) { \ |
115 | *oid = cur->descriptor.asn1; \ |
116 | *olen = cur->descriptor.asn1_len; \ |
117 | return 0; \ |
118 | } \ |
119 | cur++; \ |
120 | } \ |
121 | return MBEDTLS_ERR_OID_NOT_FOUND; \ |
122 | } |
123 | |
124 | /* |
125 | * Macro to generate a function for retrieving the OID based on two |
126 | * attributes from a mbedtls_oid_descriptor_t wrapper. |
127 | */ |
128 | #define FN_OID_GET_OID_BY_ATTR2(FN_NAME, TYPE_T, LIST, ATTR1_TYPE, ATTR1, \ |
129 | ATTR2_TYPE, ATTR2) \ |
130 | int FN_NAME(ATTR1_TYPE ATTR1, ATTR2_TYPE ATTR2, const char **oid, \ |
131 | size_t *olen) \ |
132 | { \ |
133 | const TYPE_T *cur = (LIST); \ |
134 | while (cur->descriptor.asn1 != NULL) { \ |
135 | if (cur->ATTR1 == (ATTR1) && cur->ATTR2 == (ATTR2)) { \ |
136 | *oid = cur->descriptor.asn1; \ |
137 | *olen = cur->descriptor.asn1_len; \ |
138 | return 0; \ |
139 | } \ |
140 | cur++; \ |
141 | } \ |
142 | return MBEDTLS_ERR_OID_NOT_FOUND; \ |
143 | } |
144 | |
145 | /* |
146 | * For X520 attribute types |
147 | */ |
148 | typedef struct { |
149 | mbedtls_oid_descriptor_t descriptor; |
150 | const char *short_name; |
151 | } oid_x520_attr_t; |
152 | |
153 | static const oid_x520_attr_t oid_x520_attr_type[] = |
154 | { |
155 | { |
156 | { ADD_LEN(MBEDTLS_OID_AT_CN), "id-at-commonName" , "Common Name" }, |
157 | "CN" , |
158 | }, |
159 | { |
160 | { ADD_LEN(MBEDTLS_OID_AT_COUNTRY), "id-at-countryName" , "Country" }, |
161 | "C" , |
162 | }, |
163 | { |
164 | { ADD_LEN(MBEDTLS_OID_AT_LOCALITY), "id-at-locality" , "Locality" }, |
165 | "L" , |
166 | }, |
167 | { |
168 | { ADD_LEN(MBEDTLS_OID_AT_STATE), "id-at-state" , "State" }, |
169 | "ST" , |
170 | }, |
171 | { |
172 | { ADD_LEN(MBEDTLS_OID_AT_ORGANIZATION), "id-at-organizationName" , "Organization" }, |
173 | "O" , |
174 | }, |
175 | { |
176 | { ADD_LEN(MBEDTLS_OID_AT_ORG_UNIT), "id-at-organizationalUnitName" , "Org Unit" }, |
177 | "OU" , |
178 | }, |
179 | { |
180 | { ADD_LEN(MBEDTLS_OID_PKCS9_EMAIL), "emailAddress" , "E-mail address" }, |
181 | "emailAddress" , |
182 | }, |
183 | { |
184 | { ADD_LEN(MBEDTLS_OID_AT_SERIAL_NUMBER), "id-at-serialNumber" , "Serial number" }, |
185 | "serialNumber" , |
186 | }, |
187 | { |
188 | { ADD_LEN(MBEDTLS_OID_AT_POSTAL_ADDRESS), "id-at-postalAddress" , |
189 | "Postal address" }, |
190 | "postalAddress" , |
191 | }, |
192 | { |
193 | { ADD_LEN(MBEDTLS_OID_AT_POSTAL_CODE), "id-at-postalCode" , "Postal code" }, |
194 | "postalCode" , |
195 | }, |
196 | { |
197 | { ADD_LEN(MBEDTLS_OID_AT_SUR_NAME), "id-at-surName" , "Surname" }, |
198 | "SN" , |
199 | }, |
200 | { |
201 | { ADD_LEN(MBEDTLS_OID_AT_GIVEN_NAME), "id-at-givenName" , "Given name" }, |
202 | "GN" , |
203 | }, |
204 | { |
205 | { ADD_LEN(MBEDTLS_OID_AT_INITIALS), "id-at-initials" , "Initials" }, |
206 | "initials" , |
207 | }, |
208 | { |
209 | { ADD_LEN(MBEDTLS_OID_AT_GENERATION_QUALIFIER), "id-at-generationQualifier" , |
210 | "Generation qualifier" }, |
211 | "generationQualifier" , |
212 | }, |
213 | { |
214 | { ADD_LEN(MBEDTLS_OID_AT_TITLE), "id-at-title" , "Title" }, |
215 | "title" , |
216 | }, |
217 | { |
218 | { ADD_LEN(MBEDTLS_OID_AT_DN_QUALIFIER), "id-at-dnQualifier" , |
219 | "Distinguished Name qualifier" }, |
220 | "dnQualifier" , |
221 | }, |
222 | { |
223 | { ADD_LEN(MBEDTLS_OID_AT_PSEUDONYM), "id-at-pseudonym" , "Pseudonym" }, |
224 | "pseudonym" , |
225 | }, |
226 | { |
227 | { ADD_LEN(MBEDTLS_OID_DOMAIN_COMPONENT), "id-domainComponent" , |
228 | "Domain component" }, |
229 | "DC" , |
230 | }, |
231 | { |
232 | { ADD_LEN(MBEDTLS_OID_AT_UNIQUE_IDENTIFIER), "id-at-uniqueIdentifier" , |
233 | "Unique Identifier" }, |
234 | "uniqueIdentifier" , |
235 | }, |
236 | { |
237 | { NULL, 0, NULL, NULL }, |
238 | NULL, |
239 | } |
240 | }; |
241 | |
242 | FN_OID_TYPED_FROM_ASN1(oid_x520_attr_t, x520_attr, oid_x520_attr_type) |
243 | FN_OID_GET_ATTR1(mbedtls_oid_get_attr_short_name, |
244 | oid_x520_attr_t, |
245 | x520_attr, |
246 | const char *, |
247 | short_name) |
248 | |
249 | /* |
250 | * For X509 extensions |
251 | */ |
252 | typedef struct { |
253 | mbedtls_oid_descriptor_t descriptor; |
254 | int ext_type; |
255 | } oid_x509_ext_t; |
256 | |
257 | static const oid_x509_ext_t oid_x509_ext[] = |
258 | { |
259 | { |
260 | { ADD_LEN(MBEDTLS_OID_BASIC_CONSTRAINTS), "id-ce-basicConstraints" , |
261 | "Basic Constraints" }, |
262 | MBEDTLS_OID_X509_EXT_BASIC_CONSTRAINTS, |
263 | }, |
264 | { |
265 | { ADD_LEN(MBEDTLS_OID_KEY_USAGE), "id-ce-keyUsage" , "Key Usage" }, |
266 | MBEDTLS_OID_X509_EXT_KEY_USAGE, |
267 | }, |
268 | { |
269 | { ADD_LEN(MBEDTLS_OID_EXTENDED_KEY_USAGE), "id-ce-extKeyUsage" , |
270 | "Extended Key Usage" }, |
271 | MBEDTLS_OID_X509_EXT_EXTENDED_KEY_USAGE, |
272 | }, |
273 | { |
274 | { ADD_LEN(MBEDTLS_OID_SUBJECT_ALT_NAME), "id-ce-subjectAltName" , |
275 | "Subject Alt Name" }, |
276 | MBEDTLS_OID_X509_EXT_SUBJECT_ALT_NAME, |
277 | }, |
278 | { |
279 | { ADD_LEN(MBEDTLS_OID_NS_CERT_TYPE), "id-netscape-certtype" , |
280 | "Netscape Certificate Type" }, |
281 | MBEDTLS_OID_X509_EXT_NS_CERT_TYPE, |
282 | }, |
283 | { |
284 | { ADD_LEN(MBEDTLS_OID_CERTIFICATE_POLICIES), "id-ce-certificatePolicies" , |
285 | "Certificate Policies" }, |
286 | MBEDTLS_OID_X509_EXT_CERTIFICATE_POLICIES, |
287 | }, |
288 | { |
289 | { NULL, 0, NULL, NULL }, |
290 | 0, |
291 | }, |
292 | }; |
293 | |
294 | FN_OID_TYPED_FROM_ASN1(oid_x509_ext_t, x509_ext, oid_x509_ext) |
295 | FN_OID_GET_ATTR1(mbedtls_oid_get_x509_ext_type, oid_x509_ext_t, x509_ext, int, ext_type) |
296 | |
297 | static const mbedtls_oid_descriptor_t oid_ext_key_usage[] = |
298 | { |
299 | { ADD_LEN(MBEDTLS_OID_SERVER_AUTH), "id-kp-serverAuth" , |
300 | "TLS Web Server Authentication" }, |
301 | { ADD_LEN(MBEDTLS_OID_CLIENT_AUTH), "id-kp-clientAuth" , |
302 | "TLS Web Client Authentication" }, |
303 | { ADD_LEN(MBEDTLS_OID_CODE_SIGNING), "id-kp-codeSigning" , "Code Signing" }, |
304 | { ADD_LEN(MBEDTLS_OID_EMAIL_PROTECTION), "id-kp-emailProtection" , "E-mail Protection" }, |
305 | { ADD_LEN(MBEDTLS_OID_TIME_STAMPING), "id-kp-timeStamping" , "Time Stamping" }, |
306 | { ADD_LEN(MBEDTLS_OID_OCSP_SIGNING), "id-kp-OCSPSigning" , "OCSP Signing" }, |
307 | { ADD_LEN(MBEDTLS_OID_WISUN_FAN), "id-kp-wisun-fan-device" , |
308 | "Wi-SUN Alliance Field Area Network (FAN)" }, |
309 | { NULL, 0, NULL, NULL }, |
310 | }; |
311 | |
312 | FN_OID_TYPED_FROM_ASN1(mbedtls_oid_descriptor_t, ext_key_usage, oid_ext_key_usage) |
313 | FN_OID_GET_ATTR1(mbedtls_oid_get_extended_key_usage, |
314 | mbedtls_oid_descriptor_t, |
315 | ext_key_usage, |
316 | const char *, |
317 | description) |
318 | |
319 | static const mbedtls_oid_descriptor_t oid_certificate_policies[] = |
320 | { |
321 | { ADD_LEN(MBEDTLS_OID_ANY_POLICY), "anyPolicy" , "Any Policy" }, |
322 | { NULL, 0, NULL, NULL }, |
323 | }; |
324 | |
325 | FN_OID_TYPED_FROM_ASN1(mbedtls_oid_descriptor_t, certificate_policies, oid_certificate_policies) |
326 | FN_OID_GET_ATTR1(mbedtls_oid_get_certificate_policies, |
327 | mbedtls_oid_descriptor_t, |
328 | certificate_policies, |
329 | const char *, |
330 | description) |
331 | |
332 | #if defined(MBEDTLS_MD_C) |
333 | /* |
334 | * For SignatureAlgorithmIdentifier |
335 | */ |
336 | typedef struct { |
337 | mbedtls_oid_descriptor_t descriptor; |
338 | mbedtls_md_type_t md_alg; |
339 | mbedtls_pk_type_t pk_alg; |
340 | } oid_sig_alg_t; |
341 | |
342 | static const oid_sig_alg_t oid_sig_alg[] = |
343 | { |
344 | #if defined(MBEDTLS_RSA_C) |
345 | #if defined(MBEDTLS_MD2_C) |
346 | { |
347 | { ADD_LEN(MBEDTLS_OID_PKCS1_MD2), "md2WithRSAEncryption" , "RSA with MD2" }, |
348 | MBEDTLS_MD_MD2, MBEDTLS_PK_RSA, |
349 | }, |
350 | #endif /* MBEDTLS_MD2_C */ |
351 | #if defined(MBEDTLS_MD4_C) |
352 | { |
353 | { ADD_LEN(MBEDTLS_OID_PKCS1_MD4), "md4WithRSAEncryption" , "RSA with MD4" }, |
354 | MBEDTLS_MD_MD4, MBEDTLS_PK_RSA, |
355 | }, |
356 | #endif /* MBEDTLS_MD4_C */ |
357 | #if defined(MBEDTLS_MD5_C) |
358 | { |
359 | { ADD_LEN(MBEDTLS_OID_PKCS1_MD5), "md5WithRSAEncryption" , "RSA with MD5" }, |
360 | MBEDTLS_MD_MD5, MBEDTLS_PK_RSA, |
361 | }, |
362 | #endif /* MBEDTLS_MD5_C */ |
363 | #if defined(MBEDTLS_SHA1_C) |
364 | { |
365 | { ADD_LEN(MBEDTLS_OID_PKCS1_SHA1), "sha-1WithRSAEncryption" , "RSA with SHA1" }, |
366 | MBEDTLS_MD_SHA1, MBEDTLS_PK_RSA, |
367 | }, |
368 | #endif /* MBEDTLS_SHA1_C */ |
369 | #if defined(MBEDTLS_SHA256_C) |
370 | { |
371 | { ADD_LEN(MBEDTLS_OID_PKCS1_SHA224), "sha224WithRSAEncryption" , "RSA with SHA-224" }, |
372 | MBEDTLS_MD_SHA224, MBEDTLS_PK_RSA, |
373 | }, |
374 | { |
375 | { ADD_LEN(MBEDTLS_OID_PKCS1_SHA256), "sha256WithRSAEncryption" , "RSA with SHA-256" }, |
376 | MBEDTLS_MD_SHA256, MBEDTLS_PK_RSA, |
377 | }, |
378 | #endif /* MBEDTLS_SHA256_C */ |
379 | #if defined(MBEDTLS_SHA512_C) |
380 | { |
381 | { ADD_LEN(MBEDTLS_OID_PKCS1_SHA384), "sha384WithRSAEncryption" , "RSA with SHA-384" }, |
382 | MBEDTLS_MD_SHA384, MBEDTLS_PK_RSA, |
383 | }, |
384 | { |
385 | { ADD_LEN(MBEDTLS_OID_PKCS1_SHA512), "sha512WithRSAEncryption" , "RSA with SHA-512" }, |
386 | MBEDTLS_MD_SHA512, MBEDTLS_PK_RSA, |
387 | }, |
388 | #endif /* MBEDTLS_SHA512_C */ |
389 | #if defined(MBEDTLS_SHA1_C) |
390 | { |
391 | { ADD_LEN(MBEDTLS_OID_RSA_SHA_OBS), "sha-1WithRSAEncryption" , "RSA with SHA1" }, |
392 | MBEDTLS_MD_SHA1, MBEDTLS_PK_RSA, |
393 | }, |
394 | #endif /* MBEDTLS_SHA1_C */ |
395 | #endif /* MBEDTLS_RSA_C */ |
396 | #if defined(MBEDTLS_ECDSA_C) |
397 | #if defined(MBEDTLS_SHA1_C) |
398 | { |
399 | { ADD_LEN(MBEDTLS_OID_ECDSA_SHA1), "ecdsa-with-SHA1" , "ECDSA with SHA1" }, |
400 | MBEDTLS_MD_SHA1, MBEDTLS_PK_ECDSA, |
401 | }, |
402 | #endif /* MBEDTLS_SHA1_C */ |
403 | #if defined(MBEDTLS_SHA256_C) |
404 | { |
405 | { ADD_LEN(MBEDTLS_OID_ECDSA_SHA224), "ecdsa-with-SHA224" , "ECDSA with SHA224" }, |
406 | MBEDTLS_MD_SHA224, MBEDTLS_PK_ECDSA, |
407 | }, |
408 | { |
409 | { ADD_LEN(MBEDTLS_OID_ECDSA_SHA256), "ecdsa-with-SHA256" , "ECDSA with SHA256" }, |
410 | MBEDTLS_MD_SHA256, MBEDTLS_PK_ECDSA, |
411 | }, |
412 | #endif /* MBEDTLS_SHA256_C */ |
413 | #if defined(MBEDTLS_SHA512_C) |
414 | { |
415 | { ADD_LEN(MBEDTLS_OID_ECDSA_SHA384), "ecdsa-with-SHA384" , "ECDSA with SHA384" }, |
416 | MBEDTLS_MD_SHA384, MBEDTLS_PK_ECDSA, |
417 | }, |
418 | { |
419 | { ADD_LEN(MBEDTLS_OID_ECDSA_SHA512), "ecdsa-with-SHA512" , "ECDSA with SHA512" }, |
420 | MBEDTLS_MD_SHA512, MBEDTLS_PK_ECDSA, |
421 | }, |
422 | #endif /* MBEDTLS_SHA512_C */ |
423 | #endif /* MBEDTLS_ECDSA_C */ |
424 | #if defined(MBEDTLS_RSA_C) |
425 | { |
426 | { ADD_LEN(MBEDTLS_OID_RSASSA_PSS), "RSASSA-PSS" , "RSASSA-PSS" }, |
427 | MBEDTLS_MD_NONE, MBEDTLS_PK_RSASSA_PSS, |
428 | }, |
429 | #endif /* MBEDTLS_RSA_C */ |
430 | { |
431 | { NULL, 0, NULL, NULL }, |
432 | MBEDTLS_MD_NONE, MBEDTLS_PK_NONE, |
433 | }, |
434 | }; |
435 | |
436 | FN_OID_TYPED_FROM_ASN1(oid_sig_alg_t, sig_alg, oid_sig_alg) |
437 | FN_OID_GET_DESCRIPTOR_ATTR1(mbedtls_oid_get_sig_alg_desc, |
438 | oid_sig_alg_t, |
439 | sig_alg, |
440 | const char *, |
441 | description) |
442 | FN_OID_GET_ATTR2(mbedtls_oid_get_sig_alg, |
443 | oid_sig_alg_t, |
444 | sig_alg, |
445 | mbedtls_md_type_t, |
446 | md_alg, |
447 | mbedtls_pk_type_t, |
448 | pk_alg) |
449 | FN_OID_GET_OID_BY_ATTR2(mbedtls_oid_get_oid_by_sig_alg, |
450 | oid_sig_alg_t, |
451 | oid_sig_alg, |
452 | mbedtls_pk_type_t, |
453 | pk_alg, |
454 | mbedtls_md_type_t, |
455 | md_alg) |
456 | #endif /* MBEDTLS_MD_C */ |
457 | |
458 | /* |
459 | * For PublicKeyInfo (PKCS1, RFC 5480) |
460 | */ |
461 | typedef struct { |
462 | mbedtls_oid_descriptor_t descriptor; |
463 | mbedtls_pk_type_t pk_alg; |
464 | } oid_pk_alg_t; |
465 | |
466 | static const oid_pk_alg_t oid_pk_alg[] = |
467 | { |
468 | { |
469 | { ADD_LEN(MBEDTLS_OID_PKCS1_RSA), "rsaEncryption" , "RSA" }, |
470 | MBEDTLS_PK_RSA, |
471 | }, |
472 | { |
473 | { ADD_LEN(MBEDTLS_OID_EC_ALG_UNRESTRICTED), "id-ecPublicKey" , "Generic EC key" }, |
474 | MBEDTLS_PK_ECKEY, |
475 | }, |
476 | { |
477 | { ADD_LEN(MBEDTLS_OID_EC_ALG_ECDH), "id-ecDH" , "EC key for ECDH" }, |
478 | MBEDTLS_PK_ECKEY_DH, |
479 | }, |
480 | { |
481 | { NULL, 0, NULL, NULL }, |
482 | MBEDTLS_PK_NONE, |
483 | }, |
484 | }; |
485 | |
486 | FN_OID_TYPED_FROM_ASN1(oid_pk_alg_t, pk_alg, oid_pk_alg) |
487 | FN_OID_GET_ATTR1(mbedtls_oid_get_pk_alg, oid_pk_alg_t, pk_alg, mbedtls_pk_type_t, pk_alg) |
488 | FN_OID_GET_OID_BY_ATTR1(mbedtls_oid_get_oid_by_pk_alg, |
489 | oid_pk_alg_t, |
490 | oid_pk_alg, |
491 | mbedtls_pk_type_t, |
492 | pk_alg) |
493 | |
494 | #if defined(MBEDTLS_ECP_C) |
495 | /* |
496 | * For namedCurve (RFC 5480) |
497 | */ |
498 | typedef struct { |
499 | mbedtls_oid_descriptor_t descriptor; |
500 | mbedtls_ecp_group_id grp_id; |
501 | } oid_ecp_grp_t; |
502 | |
503 | static const oid_ecp_grp_t oid_ecp_grp[] = |
504 | { |
505 | #if defined(MBEDTLS_ECP_DP_SECP192R1_ENABLED) |
506 | { |
507 | { ADD_LEN(MBEDTLS_OID_EC_GRP_SECP192R1), "secp192r1" , "secp192r1" }, |
508 | MBEDTLS_ECP_DP_SECP192R1, |
509 | }, |
510 | #endif /* MBEDTLS_ECP_DP_SECP192R1_ENABLED */ |
511 | #if defined(MBEDTLS_ECP_DP_SECP224R1_ENABLED) |
512 | { |
513 | { ADD_LEN(MBEDTLS_OID_EC_GRP_SECP224R1), "secp224r1" , "secp224r1" }, |
514 | MBEDTLS_ECP_DP_SECP224R1, |
515 | }, |
516 | #endif /* MBEDTLS_ECP_DP_SECP224R1_ENABLED */ |
517 | #if defined(MBEDTLS_ECP_DP_SECP256R1_ENABLED) |
518 | { |
519 | { ADD_LEN(MBEDTLS_OID_EC_GRP_SECP256R1), "secp256r1" , "secp256r1" }, |
520 | MBEDTLS_ECP_DP_SECP256R1, |
521 | }, |
522 | #endif /* MBEDTLS_ECP_DP_SECP256R1_ENABLED */ |
523 | #if defined(MBEDTLS_ECP_DP_SECP384R1_ENABLED) |
524 | { |
525 | { ADD_LEN(MBEDTLS_OID_EC_GRP_SECP384R1), "secp384r1" , "secp384r1" }, |
526 | MBEDTLS_ECP_DP_SECP384R1, |
527 | }, |
528 | #endif /* MBEDTLS_ECP_DP_SECP384R1_ENABLED */ |
529 | #if defined(MBEDTLS_ECP_DP_SECP521R1_ENABLED) |
530 | { |
531 | { ADD_LEN(MBEDTLS_OID_EC_GRP_SECP521R1), "secp521r1" , "secp521r1" }, |
532 | MBEDTLS_ECP_DP_SECP521R1, |
533 | }, |
534 | #endif /* MBEDTLS_ECP_DP_SECP521R1_ENABLED */ |
535 | #if defined(MBEDTLS_ECP_DP_SECP192K1_ENABLED) |
536 | { |
537 | { ADD_LEN(MBEDTLS_OID_EC_GRP_SECP192K1), "secp192k1" , "secp192k1" }, |
538 | MBEDTLS_ECP_DP_SECP192K1, |
539 | }, |
540 | #endif /* MBEDTLS_ECP_DP_SECP192K1_ENABLED */ |
541 | #if defined(MBEDTLS_ECP_DP_SECP224K1_ENABLED) |
542 | { |
543 | { ADD_LEN(MBEDTLS_OID_EC_GRP_SECP224K1), "secp224k1" , "secp224k1" }, |
544 | MBEDTLS_ECP_DP_SECP224K1, |
545 | }, |
546 | #endif /* MBEDTLS_ECP_DP_SECP224K1_ENABLED */ |
547 | #if defined(MBEDTLS_ECP_DP_SECP256K1_ENABLED) |
548 | { |
549 | { ADD_LEN(MBEDTLS_OID_EC_GRP_SECP256K1), "secp256k1" , "secp256k1" }, |
550 | MBEDTLS_ECP_DP_SECP256K1, |
551 | }, |
552 | #endif /* MBEDTLS_ECP_DP_SECP256K1_ENABLED */ |
553 | #if defined(MBEDTLS_ECP_DP_BP256R1_ENABLED) |
554 | { |
555 | { ADD_LEN(MBEDTLS_OID_EC_GRP_BP256R1), "brainpoolP256r1" , "brainpool256r1" }, |
556 | MBEDTLS_ECP_DP_BP256R1, |
557 | }, |
558 | #endif /* MBEDTLS_ECP_DP_BP256R1_ENABLED */ |
559 | #if defined(MBEDTLS_ECP_DP_BP384R1_ENABLED) |
560 | { |
561 | { ADD_LEN(MBEDTLS_OID_EC_GRP_BP384R1), "brainpoolP384r1" , "brainpool384r1" }, |
562 | MBEDTLS_ECP_DP_BP384R1, |
563 | }, |
564 | #endif /* MBEDTLS_ECP_DP_BP384R1_ENABLED */ |
565 | #if defined(MBEDTLS_ECP_DP_BP512R1_ENABLED) |
566 | { |
567 | { ADD_LEN(MBEDTLS_OID_EC_GRP_BP512R1), "brainpoolP512r1" , "brainpool512r1" }, |
568 | MBEDTLS_ECP_DP_BP512R1, |
569 | }, |
570 | #endif /* MBEDTLS_ECP_DP_BP512R1_ENABLED */ |
571 | { |
572 | { NULL, 0, NULL, NULL }, |
573 | MBEDTLS_ECP_DP_NONE, |
574 | }, |
575 | }; |
576 | |
577 | FN_OID_TYPED_FROM_ASN1(oid_ecp_grp_t, grp_id, oid_ecp_grp) |
578 | FN_OID_GET_ATTR1(mbedtls_oid_get_ec_grp, oid_ecp_grp_t, grp_id, mbedtls_ecp_group_id, grp_id) |
579 | FN_OID_GET_OID_BY_ATTR1(mbedtls_oid_get_oid_by_ec_grp, |
580 | oid_ecp_grp_t, |
581 | oid_ecp_grp, |
582 | mbedtls_ecp_group_id, |
583 | grp_id) |
584 | #endif /* MBEDTLS_ECP_C */ |
585 | |
586 | #if defined(MBEDTLS_CIPHER_C) |
587 | /* |
588 | * For PKCS#5 PBES2 encryption algorithm |
589 | */ |
590 | typedef struct { |
591 | mbedtls_oid_descriptor_t descriptor; |
592 | mbedtls_cipher_type_t cipher_alg; |
593 | } oid_cipher_alg_t; |
594 | |
595 | static const oid_cipher_alg_t oid_cipher_alg[] = |
596 | { |
597 | { |
598 | { ADD_LEN(MBEDTLS_OID_DES_CBC), "desCBC" , "DES-CBC" }, |
599 | MBEDTLS_CIPHER_DES_CBC, |
600 | }, |
601 | { |
602 | { ADD_LEN(MBEDTLS_OID_DES_EDE3_CBC), "des-ede3-cbc" , "DES-EDE3-CBC" }, |
603 | MBEDTLS_CIPHER_DES_EDE3_CBC, |
604 | }, |
605 | { |
606 | { NULL, 0, NULL, NULL }, |
607 | MBEDTLS_CIPHER_NONE, |
608 | }, |
609 | }; |
610 | |
611 | FN_OID_TYPED_FROM_ASN1(oid_cipher_alg_t, cipher_alg, oid_cipher_alg) |
612 | FN_OID_GET_ATTR1(mbedtls_oid_get_cipher_alg, |
613 | oid_cipher_alg_t, |
614 | cipher_alg, |
615 | mbedtls_cipher_type_t, |
616 | cipher_alg) |
617 | #endif /* MBEDTLS_CIPHER_C */ |
618 | |
619 | #if defined(MBEDTLS_MD_C) |
620 | /* |
621 | * For digestAlgorithm |
622 | */ |
623 | typedef struct { |
624 | mbedtls_oid_descriptor_t descriptor; |
625 | mbedtls_md_type_t md_alg; |
626 | } oid_md_alg_t; |
627 | |
628 | static const oid_md_alg_t oid_md_alg[] = |
629 | { |
630 | #if defined(MBEDTLS_MD2_C) |
631 | { |
632 | { ADD_LEN(MBEDTLS_OID_DIGEST_ALG_MD2), "id-md2" , "MD2" }, |
633 | MBEDTLS_MD_MD2, |
634 | }, |
635 | #endif /* MBEDTLS_MD2_C */ |
636 | #if defined(MBEDTLS_MD4_C) |
637 | { |
638 | { ADD_LEN(MBEDTLS_OID_DIGEST_ALG_MD4), "id-md4" , "MD4" }, |
639 | MBEDTLS_MD_MD4, |
640 | }, |
641 | #endif /* MBEDTLS_MD4_C */ |
642 | #if defined(MBEDTLS_MD5_C) |
643 | { |
644 | { ADD_LEN(MBEDTLS_OID_DIGEST_ALG_MD5), "id-md5" , "MD5" }, |
645 | MBEDTLS_MD_MD5, |
646 | }, |
647 | #endif /* MBEDTLS_MD5_C */ |
648 | #if defined(MBEDTLS_SHA1_C) |
649 | { |
650 | { ADD_LEN(MBEDTLS_OID_DIGEST_ALG_SHA1), "id-sha1" , "SHA-1" }, |
651 | MBEDTLS_MD_SHA1, |
652 | }, |
653 | #endif /* MBEDTLS_SHA1_C */ |
654 | #if defined(MBEDTLS_SHA256_C) |
655 | { |
656 | { ADD_LEN(MBEDTLS_OID_DIGEST_ALG_SHA224), "id-sha224" , "SHA-224" }, |
657 | MBEDTLS_MD_SHA224, |
658 | }, |
659 | { |
660 | { ADD_LEN(MBEDTLS_OID_DIGEST_ALG_SHA256), "id-sha256" , "SHA-256" }, |
661 | MBEDTLS_MD_SHA256, |
662 | }, |
663 | #endif /* MBEDTLS_SHA256_C */ |
664 | #if defined(MBEDTLS_SHA512_C) |
665 | { |
666 | { ADD_LEN(MBEDTLS_OID_DIGEST_ALG_SHA384), "id-sha384" , "SHA-384" }, |
667 | MBEDTLS_MD_SHA384, |
668 | }, |
669 | { |
670 | { ADD_LEN(MBEDTLS_OID_DIGEST_ALG_SHA512), "id-sha512" , "SHA-512" }, |
671 | MBEDTLS_MD_SHA512, |
672 | }, |
673 | #endif /* MBEDTLS_SHA512_C */ |
674 | #if defined(MBEDTLS_RIPEMD160_C) |
675 | { |
676 | { ADD_LEN(MBEDTLS_OID_DIGEST_ALG_RIPEMD160), "id-ripemd160" , "RIPEMD-160" }, |
677 | MBEDTLS_MD_RIPEMD160, |
678 | }, |
679 | #endif /* MBEDTLS_RIPEMD160_C */ |
680 | { |
681 | { NULL, 0, NULL, NULL }, |
682 | MBEDTLS_MD_NONE, |
683 | }, |
684 | }; |
685 | |
686 | FN_OID_TYPED_FROM_ASN1(oid_md_alg_t, md_alg, oid_md_alg) |
687 | FN_OID_GET_ATTR1(mbedtls_oid_get_md_alg, oid_md_alg_t, md_alg, mbedtls_md_type_t, md_alg) |
688 | FN_OID_GET_OID_BY_ATTR1(mbedtls_oid_get_oid_by_md, |
689 | oid_md_alg_t, |
690 | oid_md_alg, |
691 | mbedtls_md_type_t, |
692 | md_alg) |
693 | |
694 | /* |
695 | * For HMAC digestAlgorithm |
696 | */ |
697 | typedef struct { |
698 | mbedtls_oid_descriptor_t descriptor; |
699 | mbedtls_md_type_t md_hmac; |
700 | } oid_md_hmac_t; |
701 | |
702 | static const oid_md_hmac_t oid_md_hmac[] = |
703 | { |
704 | #if defined(MBEDTLS_SHA1_C) |
705 | { |
706 | { ADD_LEN(MBEDTLS_OID_HMAC_SHA1), "hmacSHA1" , "HMAC-SHA-1" }, |
707 | MBEDTLS_MD_SHA1, |
708 | }, |
709 | #endif /* MBEDTLS_SHA1_C */ |
710 | #if defined(MBEDTLS_SHA256_C) |
711 | { |
712 | { ADD_LEN(MBEDTLS_OID_HMAC_SHA224), "hmacSHA224" , "HMAC-SHA-224" }, |
713 | MBEDTLS_MD_SHA224, |
714 | }, |
715 | { |
716 | { ADD_LEN(MBEDTLS_OID_HMAC_SHA256), "hmacSHA256" , "HMAC-SHA-256" }, |
717 | MBEDTLS_MD_SHA256, |
718 | }, |
719 | #endif /* MBEDTLS_SHA256_C */ |
720 | #if defined(MBEDTLS_SHA512_C) |
721 | { |
722 | { ADD_LEN(MBEDTLS_OID_HMAC_SHA384), "hmacSHA384" , "HMAC-SHA-384" }, |
723 | MBEDTLS_MD_SHA384, |
724 | }, |
725 | { |
726 | { ADD_LEN(MBEDTLS_OID_HMAC_SHA512), "hmacSHA512" , "HMAC-SHA-512" }, |
727 | MBEDTLS_MD_SHA512, |
728 | }, |
729 | #endif /* MBEDTLS_SHA512_C */ |
730 | { |
731 | { NULL, 0, NULL, NULL }, |
732 | MBEDTLS_MD_NONE, |
733 | }, |
734 | }; |
735 | |
736 | FN_OID_TYPED_FROM_ASN1(oid_md_hmac_t, md_hmac, oid_md_hmac) |
737 | FN_OID_GET_ATTR1(mbedtls_oid_get_md_hmac, oid_md_hmac_t, md_hmac, mbedtls_md_type_t, md_hmac) |
738 | #endif /* MBEDTLS_MD_C */ |
739 | |
740 | #if defined(MBEDTLS_PKCS12_C) |
741 | /* |
742 | * For PKCS#12 PBEs |
743 | */ |
744 | typedef struct { |
745 | mbedtls_oid_descriptor_t descriptor; |
746 | mbedtls_md_type_t md_alg; |
747 | mbedtls_cipher_type_t cipher_alg; |
748 | } oid_pkcs12_pbe_alg_t; |
749 | |
750 | static const oid_pkcs12_pbe_alg_t oid_pkcs12_pbe_alg[] = |
751 | { |
752 | { |
753 | { ADD_LEN(MBEDTLS_OID_PKCS12_PBE_SHA1_DES3_EDE_CBC), "pbeWithSHAAnd3-KeyTripleDES-CBC" , |
754 | "PBE with SHA1 and 3-Key 3DES" }, |
755 | MBEDTLS_MD_SHA1, MBEDTLS_CIPHER_DES_EDE3_CBC, |
756 | }, |
757 | { |
758 | { ADD_LEN(MBEDTLS_OID_PKCS12_PBE_SHA1_DES2_EDE_CBC), "pbeWithSHAAnd2-KeyTripleDES-CBC" , |
759 | "PBE with SHA1 and 2-Key 3DES" }, |
760 | MBEDTLS_MD_SHA1, MBEDTLS_CIPHER_DES_EDE_CBC, |
761 | }, |
762 | { |
763 | { NULL, 0, NULL, NULL }, |
764 | MBEDTLS_MD_NONE, MBEDTLS_CIPHER_NONE, |
765 | }, |
766 | }; |
767 | |
768 | FN_OID_TYPED_FROM_ASN1(oid_pkcs12_pbe_alg_t, pkcs12_pbe_alg, oid_pkcs12_pbe_alg) |
769 | FN_OID_GET_ATTR2(mbedtls_oid_get_pkcs12_pbe_alg, |
770 | oid_pkcs12_pbe_alg_t, |
771 | pkcs12_pbe_alg, |
772 | mbedtls_md_type_t, |
773 | md_alg, |
774 | mbedtls_cipher_type_t, |
775 | cipher_alg) |
776 | #endif /* MBEDTLS_PKCS12_C */ |
777 | |
778 | /* Return the x.y.z.... style numeric string for the given OID */ |
779 | int mbedtls_oid_get_numeric_string(char *buf, size_t size, |
780 | const mbedtls_asn1_buf *oid) |
781 | { |
782 | int ret = MBEDTLS_ERR_ERROR_CORRUPTION_DETECTED; |
783 | char *p = buf; |
784 | size_t n = size; |
785 | unsigned int value = 0; |
786 | |
787 | if (size > INT_MAX) { |
788 | /* Avoid overflow computing return value */ |
789 | return MBEDTLS_ERR_ASN1_INVALID_LENGTH; |
790 | } |
791 | |
792 | if (oid->len <= 0) { |
793 | /* OID must not be empty */ |
794 | return MBEDTLS_ERR_ASN1_OUT_OF_DATA; |
795 | } |
796 | |
797 | for (size_t i = 0; i < oid->len; i++) { |
798 | /* Prevent overflow in value. */ |
799 | if (value > (UINT_MAX >> 7)) { |
800 | return MBEDTLS_ERR_ASN1_INVALID_DATA; |
801 | } |
802 | if ((value == 0) && ((oid->p[i]) == 0x80)) { |
803 | /* Overlong encoding is not allowed */ |
804 | return MBEDTLS_ERR_ASN1_INVALID_DATA; |
805 | } |
806 | |
807 | value <<= 7; |
808 | value |= oid->p[i] & 0x7F; |
809 | |
810 | if (!(oid->p[i] & 0x80)) { |
811 | /* Last byte */ |
812 | if (n == size) { |
813 | int component1; |
814 | unsigned int component2; |
815 | /* First subidentifier contains first two OID components */ |
816 | if (value >= 80) { |
817 | component1 = '2'; |
818 | component2 = value - 80; |
819 | } else if (value >= 40) { |
820 | component1 = '1'; |
821 | component2 = value - 40; |
822 | } else { |
823 | component1 = '0'; |
824 | component2 = value; |
825 | } |
826 | ret = mbedtls_snprintf(p, n, "%c.%u" , component1, component2); |
827 | } else { |
828 | ret = mbedtls_snprintf(p, n, ".%u" , value); |
829 | } |
830 | if (ret < 2 || (size_t) ret >= n) { |
831 | return MBEDTLS_ERR_OID_BUF_TOO_SMALL; |
832 | } |
833 | n -= (size_t) ret; |
834 | p += ret; |
835 | value = 0; |
836 | } |
837 | } |
838 | |
839 | if (value != 0) { |
840 | /* Unterminated subidentifier */ |
841 | return MBEDTLS_ERR_ASN1_OUT_OF_DATA; |
842 | } |
843 | |
844 | return (int) (size - n); |
845 | } |
846 | |
847 | #endif /* MBEDTLS_OID_C */ |
848 | |