v3_alt.c 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622
  1. /* v3_alt.c */
  2. /*
  3. * Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
  4. * project.
  5. */
  6. /* ====================================================================
  7. * Copyright (c) 1999-2003 The OpenSSL Project. All rights reserved.
  8. *
  9. * Redistribution and use in source and binary forms, with or without
  10. * modification, are permitted provided that the following conditions
  11. * are met:
  12. *
  13. * 1. Redistributions of source code must retain the above copyright
  14. * notice, this list of conditions and the following disclaimer.
  15. *
  16. * 2. Redistributions in binary form must reproduce the above copyright
  17. * notice, this list of conditions and the following disclaimer in
  18. * the documentation and/or other materials provided with the
  19. * distribution.
  20. *
  21. * 3. All advertising materials mentioning features or use of this
  22. * software must display the following acknowledgment:
  23. * "This product includes software developed by the OpenSSL Project
  24. * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
  25. *
  26. * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
  27. * endorse or promote products derived from this software without
  28. * prior written permission. For written permission, please contact
  29. * licensing@OpenSSL.org.
  30. *
  31. * 5. Products derived from this software may not be called "OpenSSL"
  32. * nor may "OpenSSL" appear in their names without prior written
  33. * permission of the OpenSSL Project.
  34. *
  35. * 6. Redistributions of any form whatsoever must retain the following
  36. * acknowledgment:
  37. * "This product includes software developed by the OpenSSL Project
  38. * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
  39. *
  40. * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
  41. * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
  42. * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
  43. * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
  44. * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  45. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  46. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  47. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
  48. * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  49. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  50. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
  51. * OF THE POSSIBILITY OF SUCH DAMAGE.
  52. * ====================================================================
  53. *
  54. * This product includes cryptographic software written by Eric Young
  55. * (eay@cryptsoft.com). This product includes software written by Tim
  56. * Hudson (tjh@cryptsoft.com).
  57. *
  58. */
  59. #include <stdio.h>
  60. #include "cryptlib.h"
  61. #include <openssl/conf.h>
  62. #include <openssl/x509v3.h>
  63. static GENERAL_NAMES *v2i_subject_alt(X509V3_EXT_METHOD *method,
  64. X509V3_CTX *ctx,
  65. STACK_OF(CONF_VALUE) *nval);
  66. static GENERAL_NAMES *v2i_issuer_alt(X509V3_EXT_METHOD *method,
  67. X509V3_CTX *ctx,
  68. STACK_OF(CONF_VALUE) *nval);
  69. static int copy_email(X509V3_CTX *ctx, GENERAL_NAMES *gens, int move_p);
  70. static int copy_issuer(X509V3_CTX *ctx, GENERAL_NAMES *gens);
  71. static int do_othername(GENERAL_NAME *gen, char *value, X509V3_CTX *ctx);
  72. static int do_dirname(GENERAL_NAME *gen, char *value, X509V3_CTX *ctx);
  73. const X509V3_EXT_METHOD v3_alt[] = {
  74. {NID_subject_alt_name, 0, ASN1_ITEM_ref(GENERAL_NAMES),
  75. 0, 0, 0, 0,
  76. 0, 0,
  77. (X509V3_EXT_I2V) i2v_GENERAL_NAMES,
  78. (X509V3_EXT_V2I)v2i_subject_alt,
  79. NULL, NULL, NULL},
  80. {NID_issuer_alt_name, 0, ASN1_ITEM_ref(GENERAL_NAMES),
  81. 0, 0, 0, 0,
  82. 0, 0,
  83. (X509V3_EXT_I2V) i2v_GENERAL_NAMES,
  84. (X509V3_EXT_V2I)v2i_issuer_alt,
  85. NULL, NULL, NULL},
  86. {NID_certificate_issuer, 0, ASN1_ITEM_ref(GENERAL_NAMES),
  87. 0, 0, 0, 0,
  88. 0, 0,
  89. (X509V3_EXT_I2V) i2v_GENERAL_NAMES,
  90. NULL, NULL, NULL, NULL},
  91. };
  92. STACK_OF(CONF_VALUE) *i2v_GENERAL_NAMES(X509V3_EXT_METHOD *method,
  93. GENERAL_NAMES *gens,
  94. STACK_OF(CONF_VALUE) *ret)
  95. {
  96. int i;
  97. GENERAL_NAME *gen;
  98. for (i = 0; i < sk_GENERAL_NAME_num(gens); i++) {
  99. gen = sk_GENERAL_NAME_value(gens, i);
  100. ret = i2v_GENERAL_NAME(method, gen, ret);
  101. }
  102. if (!ret)
  103. return sk_CONF_VALUE_new_null();
  104. return ret;
  105. }
  106. STACK_OF(CONF_VALUE) *i2v_GENERAL_NAME(X509V3_EXT_METHOD *method,
  107. GENERAL_NAME *gen,
  108. STACK_OF(CONF_VALUE) *ret)
  109. {
  110. unsigned char *p;
  111. char oline[256], htmp[5];
  112. int i;
  113. switch (gen->type) {
  114. case GEN_OTHERNAME:
  115. if (!X509V3_add_value("othername", "<unsupported>", &ret))
  116. return NULL;
  117. break;
  118. case GEN_X400:
  119. if (!X509V3_add_value("X400Name", "<unsupported>", &ret))
  120. return NULL;
  121. break;
  122. case GEN_EDIPARTY:
  123. if (!X509V3_add_value("EdiPartyName", "<unsupported>", &ret))
  124. return NULL;
  125. break;
  126. case GEN_EMAIL:
  127. if (!X509V3_add_value_uchar("email", gen->d.ia5->data, &ret))
  128. return NULL;
  129. break;
  130. case GEN_DNS:
  131. if (!X509V3_add_value_uchar("DNS", gen->d.ia5->data, &ret))
  132. return NULL;
  133. break;
  134. case GEN_URI:
  135. if (!X509V3_add_value_uchar("URI", gen->d.ia5->data, &ret))
  136. return NULL;
  137. break;
  138. case GEN_DIRNAME:
  139. if (X509_NAME_oneline(gen->d.dirn, oline, 256) == NULL
  140. || !X509V3_add_value("DirName", oline, &ret))
  141. return NULL;
  142. break;
  143. case GEN_IPADD:
  144. p = gen->d.ip->data;
  145. if (gen->d.ip->length == 4)
  146. BIO_snprintf(oline, sizeof oline,
  147. "%d.%d.%d.%d", p[0], p[1], p[2], p[3]);
  148. else if (gen->d.ip->length == 16) {
  149. oline[0] = 0;
  150. for (i = 0; i < 8; i++) {
  151. BIO_snprintf(htmp, sizeof htmp, "%X", p[0] << 8 | p[1]);
  152. p += 2;
  153. strcat(oline, htmp);
  154. if (i != 7)
  155. strcat(oline, ":");
  156. }
  157. } else {
  158. if (!X509V3_add_value("IP Address", "<invalid>", &ret))
  159. return NULL;
  160. break;
  161. }
  162. if (!X509V3_add_value("IP Address", oline, &ret))
  163. return NULL;
  164. break;
  165. case GEN_RID:
  166. i2t_ASN1_OBJECT(oline, 256, gen->d.rid);
  167. if (!X509V3_add_value("Registered ID", oline, &ret))
  168. return NULL;
  169. break;
  170. }
  171. return ret;
  172. }
  173. int GENERAL_NAME_print(BIO *out, GENERAL_NAME *gen)
  174. {
  175. unsigned char *p;
  176. int i;
  177. switch (gen->type) {
  178. case GEN_OTHERNAME:
  179. BIO_printf(out, "othername:<unsupported>");
  180. break;
  181. case GEN_X400:
  182. BIO_printf(out, "X400Name:<unsupported>");
  183. break;
  184. case GEN_EDIPARTY:
  185. /* Maybe fix this: it is supported now */
  186. BIO_printf(out, "EdiPartyName:<unsupported>");
  187. break;
  188. case GEN_EMAIL:
  189. BIO_printf(out, "email:%s", gen->d.ia5->data);
  190. break;
  191. case GEN_DNS:
  192. BIO_printf(out, "DNS:%s", gen->d.ia5->data);
  193. break;
  194. case GEN_URI:
  195. BIO_printf(out, "URI:%s", gen->d.ia5->data);
  196. break;
  197. case GEN_DIRNAME:
  198. BIO_printf(out, "DirName: ");
  199. X509_NAME_print_ex(out, gen->d.dirn, 0, XN_FLAG_ONELINE);
  200. break;
  201. case GEN_IPADD:
  202. p = gen->d.ip->data;
  203. if (gen->d.ip->length == 4)
  204. BIO_printf(out, "IP Address:%d.%d.%d.%d", p[0], p[1], p[2], p[3]);
  205. else if (gen->d.ip->length == 16) {
  206. BIO_printf(out, "IP Address");
  207. for (i = 0; i < 8; i++) {
  208. BIO_printf(out, ":%X", p[0] << 8 | p[1]);
  209. p += 2;
  210. }
  211. BIO_puts(out, "\n");
  212. } else {
  213. BIO_printf(out, "IP Address:<invalid>");
  214. break;
  215. }
  216. break;
  217. case GEN_RID:
  218. BIO_printf(out, "Registered ID");
  219. i2a_ASN1_OBJECT(out, gen->d.rid);
  220. break;
  221. }
  222. return 1;
  223. }
  224. static GENERAL_NAMES *v2i_issuer_alt(X509V3_EXT_METHOD *method,
  225. X509V3_CTX *ctx,
  226. STACK_OF(CONF_VALUE) *nval)
  227. {
  228. GENERAL_NAMES *gens = NULL;
  229. CONF_VALUE *cnf;
  230. int i;
  231. if (!(gens = sk_GENERAL_NAME_new_null())) {
  232. X509V3err(X509V3_F_V2I_ISSUER_ALT, ERR_R_MALLOC_FAILURE);
  233. return NULL;
  234. }
  235. for (i = 0; i < sk_CONF_VALUE_num(nval); i++) {
  236. cnf = sk_CONF_VALUE_value(nval, i);
  237. if (!name_cmp(cnf->name, "issuer") && cnf->value &&
  238. !strcmp(cnf->value, "copy")) {
  239. if (!copy_issuer(ctx, gens))
  240. goto err;
  241. } else {
  242. GENERAL_NAME *gen;
  243. if (!(gen = v2i_GENERAL_NAME(method, ctx, cnf)))
  244. goto err;
  245. sk_GENERAL_NAME_push(gens, gen);
  246. }
  247. }
  248. return gens;
  249. err:
  250. sk_GENERAL_NAME_pop_free(gens, GENERAL_NAME_free);
  251. return NULL;
  252. }
  253. /* Append subject altname of issuer to issuer alt name of subject */
  254. static int copy_issuer(X509V3_CTX *ctx, GENERAL_NAMES *gens)
  255. {
  256. GENERAL_NAMES *ialt;
  257. GENERAL_NAME *gen;
  258. X509_EXTENSION *ext;
  259. int i;
  260. if (ctx && (ctx->flags == CTX_TEST))
  261. return 1;
  262. if (!ctx || !ctx->issuer_cert) {
  263. X509V3err(X509V3_F_COPY_ISSUER, X509V3_R_NO_ISSUER_DETAILS);
  264. goto err;
  265. }
  266. i = X509_get_ext_by_NID(ctx->issuer_cert, NID_subject_alt_name, -1);
  267. if (i < 0)
  268. return 1;
  269. if (!(ext = X509_get_ext(ctx->issuer_cert, i)) ||
  270. !(ialt = X509V3_EXT_d2i(ext))) {
  271. X509V3err(X509V3_F_COPY_ISSUER, X509V3_R_ISSUER_DECODE_ERROR);
  272. goto err;
  273. }
  274. for (i = 0; i < sk_GENERAL_NAME_num(ialt); i++) {
  275. gen = sk_GENERAL_NAME_value(ialt, i);
  276. if (!sk_GENERAL_NAME_push(gens, gen)) {
  277. X509V3err(X509V3_F_COPY_ISSUER, ERR_R_MALLOC_FAILURE);
  278. goto err;
  279. }
  280. }
  281. sk_GENERAL_NAME_free(ialt);
  282. return 1;
  283. err:
  284. return 0;
  285. }
  286. static GENERAL_NAMES *v2i_subject_alt(X509V3_EXT_METHOD *method,
  287. X509V3_CTX *ctx,
  288. STACK_OF(CONF_VALUE) *nval)
  289. {
  290. GENERAL_NAMES *gens = NULL;
  291. CONF_VALUE *cnf;
  292. int i;
  293. if (!(gens = sk_GENERAL_NAME_new_null())) {
  294. X509V3err(X509V3_F_V2I_SUBJECT_ALT, ERR_R_MALLOC_FAILURE);
  295. return NULL;
  296. }
  297. for (i = 0; i < sk_CONF_VALUE_num(nval); i++) {
  298. cnf = sk_CONF_VALUE_value(nval, i);
  299. if (!name_cmp(cnf->name, "email") && cnf->value &&
  300. !strcmp(cnf->value, "copy")) {
  301. if (!copy_email(ctx, gens, 0))
  302. goto err;
  303. } else if (!name_cmp(cnf->name, "email") && cnf->value &&
  304. !strcmp(cnf->value, "move")) {
  305. if (!copy_email(ctx, gens, 1))
  306. goto err;
  307. } else {
  308. GENERAL_NAME *gen;
  309. if (!(gen = v2i_GENERAL_NAME(method, ctx, cnf)))
  310. goto err;
  311. sk_GENERAL_NAME_push(gens, gen);
  312. }
  313. }
  314. return gens;
  315. err:
  316. sk_GENERAL_NAME_pop_free(gens, GENERAL_NAME_free);
  317. return NULL;
  318. }
  319. /*
  320. * Copy any email addresses in a certificate or request to GENERAL_NAMES
  321. */
  322. static int copy_email(X509V3_CTX *ctx, GENERAL_NAMES *gens, int move_p)
  323. {
  324. X509_NAME *nm;
  325. ASN1_IA5STRING *email = NULL;
  326. X509_NAME_ENTRY *ne;
  327. GENERAL_NAME *gen = NULL;
  328. int i;
  329. if (ctx != NULL && ctx->flags == CTX_TEST)
  330. return 1;
  331. if (!ctx || (!ctx->subject_cert && !ctx->subject_req)) {
  332. X509V3err(X509V3_F_COPY_EMAIL, X509V3_R_NO_SUBJECT_DETAILS);
  333. goto err;
  334. }
  335. /* Find the subject name */
  336. if (ctx->subject_cert)
  337. nm = X509_get_subject_name(ctx->subject_cert);
  338. else
  339. nm = X509_REQ_get_subject_name(ctx->subject_req);
  340. /* Now add any email address(es) to STACK */
  341. i = -1;
  342. while ((i = X509_NAME_get_index_by_NID(nm,
  343. NID_pkcs9_emailAddress, i)) >= 0) {
  344. ne = X509_NAME_get_entry(nm, i);
  345. email = M_ASN1_IA5STRING_dup(X509_NAME_ENTRY_get_data(ne));
  346. if (move_p) {
  347. X509_NAME_delete_entry(nm, i);
  348. X509_NAME_ENTRY_free(ne);
  349. i--;
  350. }
  351. if (!email || !(gen = GENERAL_NAME_new())) {
  352. X509V3err(X509V3_F_COPY_EMAIL, ERR_R_MALLOC_FAILURE);
  353. goto err;
  354. }
  355. gen->d.ia5 = email;
  356. email = NULL;
  357. gen->type = GEN_EMAIL;
  358. if (!sk_GENERAL_NAME_push(gens, gen)) {
  359. X509V3err(X509V3_F_COPY_EMAIL, ERR_R_MALLOC_FAILURE);
  360. goto err;
  361. }
  362. gen = NULL;
  363. }
  364. return 1;
  365. err:
  366. GENERAL_NAME_free(gen);
  367. M_ASN1_IA5STRING_free(email);
  368. return 0;
  369. }
  370. GENERAL_NAMES *v2i_GENERAL_NAMES(const X509V3_EXT_METHOD *method,
  371. X509V3_CTX *ctx, STACK_OF(CONF_VALUE) *nval)
  372. {
  373. GENERAL_NAME *gen;
  374. GENERAL_NAMES *gens = NULL;
  375. CONF_VALUE *cnf;
  376. int i;
  377. if (!(gens = sk_GENERAL_NAME_new_null())) {
  378. X509V3err(X509V3_F_V2I_GENERAL_NAMES, ERR_R_MALLOC_FAILURE);
  379. return NULL;
  380. }
  381. for (i = 0; i < sk_CONF_VALUE_num(nval); i++) {
  382. cnf = sk_CONF_VALUE_value(nval, i);
  383. if (!(gen = v2i_GENERAL_NAME(method, ctx, cnf)))
  384. goto err;
  385. sk_GENERAL_NAME_push(gens, gen);
  386. }
  387. return gens;
  388. err:
  389. sk_GENERAL_NAME_pop_free(gens, GENERAL_NAME_free);
  390. return NULL;
  391. }
  392. GENERAL_NAME *v2i_GENERAL_NAME(const X509V3_EXT_METHOD *method,
  393. X509V3_CTX *ctx, CONF_VALUE *cnf)
  394. {
  395. return v2i_GENERAL_NAME_ex(NULL, method, ctx, cnf, 0);
  396. }
  397. GENERAL_NAME *a2i_GENERAL_NAME(GENERAL_NAME *out,
  398. const X509V3_EXT_METHOD *method,
  399. X509V3_CTX *ctx, int gen_type, char *value,
  400. int is_nc)
  401. {
  402. char is_string = 0;
  403. GENERAL_NAME *gen = NULL;
  404. if (!value) {
  405. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_MISSING_VALUE);
  406. return NULL;
  407. }
  408. if (out)
  409. gen = out;
  410. else {
  411. gen = GENERAL_NAME_new();
  412. if (gen == NULL) {
  413. X509V3err(X509V3_F_A2I_GENERAL_NAME, ERR_R_MALLOC_FAILURE);
  414. return NULL;
  415. }
  416. }
  417. switch (gen_type) {
  418. case GEN_URI:
  419. case GEN_EMAIL:
  420. case GEN_DNS:
  421. is_string = 1;
  422. break;
  423. case GEN_RID:
  424. {
  425. ASN1_OBJECT *obj;
  426. if (!(obj = OBJ_txt2obj(value, 0))) {
  427. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_BAD_OBJECT);
  428. ERR_add_error_data(2, "value=", value);
  429. goto err;
  430. }
  431. gen->d.rid = obj;
  432. }
  433. break;
  434. case GEN_IPADD:
  435. if (is_nc)
  436. gen->d.ip = a2i_IPADDRESS_NC(value);
  437. else
  438. gen->d.ip = a2i_IPADDRESS(value);
  439. if (gen->d.ip == NULL) {
  440. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_BAD_IP_ADDRESS);
  441. ERR_add_error_data(2, "value=", value);
  442. goto err;
  443. }
  444. break;
  445. case GEN_DIRNAME:
  446. if (!do_dirname(gen, value, ctx)) {
  447. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_DIRNAME_ERROR);
  448. goto err;
  449. }
  450. break;
  451. case GEN_OTHERNAME:
  452. if (!do_othername(gen, value, ctx)) {
  453. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_OTHERNAME_ERROR);
  454. goto err;
  455. }
  456. break;
  457. default:
  458. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_UNSUPPORTED_TYPE);
  459. goto err;
  460. }
  461. if (is_string) {
  462. if (!(gen->d.ia5 = M_ASN1_IA5STRING_new()) ||
  463. !ASN1_STRING_set(gen->d.ia5, (unsigned char *)value,
  464. strlen(value))) {
  465. X509V3err(X509V3_F_A2I_GENERAL_NAME, ERR_R_MALLOC_FAILURE);
  466. goto err;
  467. }
  468. }
  469. gen->type = gen_type;
  470. return gen;
  471. err:
  472. if (!out)
  473. GENERAL_NAME_free(gen);
  474. return NULL;
  475. }
  476. GENERAL_NAME *v2i_GENERAL_NAME_ex(GENERAL_NAME *out,
  477. const X509V3_EXT_METHOD *method,
  478. X509V3_CTX *ctx, CONF_VALUE *cnf, int is_nc)
  479. {
  480. int type;
  481. char *name, *value;
  482. name = cnf->name;
  483. value = cnf->value;
  484. if (!value) {
  485. X509V3err(X509V3_F_V2I_GENERAL_NAME_EX, X509V3_R_MISSING_VALUE);
  486. return NULL;
  487. }
  488. if (!name_cmp(name, "email"))
  489. type = GEN_EMAIL;
  490. else if (!name_cmp(name, "URI"))
  491. type = GEN_URI;
  492. else if (!name_cmp(name, "DNS"))
  493. type = GEN_DNS;
  494. else if (!name_cmp(name, "RID"))
  495. type = GEN_RID;
  496. else if (!name_cmp(name, "IP"))
  497. type = GEN_IPADD;
  498. else if (!name_cmp(name, "dirName"))
  499. type = GEN_DIRNAME;
  500. else if (!name_cmp(name, "otherName"))
  501. type = GEN_OTHERNAME;
  502. else {
  503. X509V3err(X509V3_F_V2I_GENERAL_NAME_EX, X509V3_R_UNSUPPORTED_OPTION);
  504. ERR_add_error_data(2, "name=", name);
  505. return NULL;
  506. }
  507. return a2i_GENERAL_NAME(out, method, ctx, type, value, is_nc);
  508. }
  509. static int do_othername(GENERAL_NAME *gen, char *value, X509V3_CTX *ctx)
  510. {
  511. char *objtmp = NULL, *p;
  512. int objlen;
  513. if (!(p = strchr(value, ';')))
  514. return 0;
  515. if (!(gen->d.otherName = OTHERNAME_new()))
  516. return 0;
  517. /*
  518. * Free this up because we will overwrite it. no need to free type_id
  519. * because it is static
  520. */
  521. ASN1_TYPE_free(gen->d.otherName->value);
  522. if (!(gen->d.otherName->value = ASN1_generate_v3(p + 1, ctx)))
  523. return 0;
  524. objlen = p - value;
  525. objtmp = OPENSSL_malloc(objlen + 1);
  526. if (objtmp == NULL)
  527. return 0;
  528. strncpy(objtmp, value, objlen);
  529. objtmp[objlen] = 0;
  530. gen->d.otherName->type_id = OBJ_txt2obj(objtmp, 0);
  531. OPENSSL_free(objtmp);
  532. if (!gen->d.otherName->type_id)
  533. return 0;
  534. return 1;
  535. }
  536. static int do_dirname(GENERAL_NAME *gen, char *value, X509V3_CTX *ctx)
  537. {
  538. int ret = 0;
  539. STACK_OF(CONF_VALUE) *sk = NULL;
  540. X509_NAME *nm = NULL;
  541. if (!(nm = X509_NAME_new()))
  542. goto err;
  543. sk = X509V3_get_section(ctx, value);
  544. if (!sk) {
  545. X509V3err(X509V3_F_DO_DIRNAME, X509V3_R_SECTION_NOT_FOUND);
  546. ERR_add_error_data(2, "section=", value);
  547. goto err;
  548. }
  549. /* FIXME: should allow other character types... */
  550. ret = X509V3_NAME_from_section(nm, sk, MBSTRING_ASC);
  551. if (!ret)
  552. goto err;
  553. gen->d.dirn = nm;
  554. err:
  555. if (ret == 0)
  556. X509_NAME_free(nm);
  557. X509V3_section_free(ctx, sk);
  558. return ret;
  559. }