v3_alt.c 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609
  1. /* v3_alt.c */
  2. /*
  3. * Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
  4. * project.
  5. */
  6. /* ====================================================================
  7. * Copyright (c) 1999-2003 The OpenSSL Project. All rights reserved.
  8. *
  9. * Redistribution and use in source and binary forms, with or without
  10. * modification, are permitted provided that the following conditions
  11. * are met:
  12. *
  13. * 1. Redistributions of source code must retain the above copyright
  14. * notice, this list of conditions and the following disclaimer.
  15. *
  16. * 2. Redistributions in binary form must reproduce the above copyright
  17. * notice, this list of conditions and the following disclaimer in
  18. * the documentation and/or other materials provided with the
  19. * distribution.
  20. *
  21. * 3. All advertising materials mentioning features or use of this
  22. * software must display the following acknowledgment:
  23. * "This product includes software developed by the OpenSSL Project
  24. * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
  25. *
  26. * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
  27. * endorse or promote products derived from this software without
  28. * prior written permission. For written permission, please contact
  29. * licensing@OpenSSL.org.
  30. *
  31. * 5. Products derived from this software may not be called "OpenSSL"
  32. * nor may "OpenSSL" appear in their names without prior written
  33. * permission of the OpenSSL Project.
  34. *
  35. * 6. Redistributions of any form whatsoever must retain the following
  36. * acknowledgment:
  37. * "This product includes software developed by the OpenSSL Project
  38. * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
  39. *
  40. * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
  41. * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
  42. * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
  43. * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
  44. * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
  45. * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
  46. * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
  47. * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
  48. * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
  49. * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
  50. * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
  51. * OF THE POSSIBILITY OF SUCH DAMAGE.
  52. * ====================================================================
  53. *
  54. * This product includes cryptographic software written by Eric Young
  55. * (eay@cryptsoft.com). This product includes software written by Tim
  56. * Hudson (tjh@cryptsoft.com).
  57. *
  58. */
  59. #include <stdio.h>
  60. #include "cryptlib.h"
  61. #include <openssl/conf.h>
  62. #include <openssl/x509v3.h>
  63. static GENERAL_NAMES *v2i_subject_alt(X509V3_EXT_METHOD *method,
  64. X509V3_CTX *ctx,
  65. STACK_OF(CONF_VALUE) *nval);
  66. static GENERAL_NAMES *v2i_issuer_alt(X509V3_EXT_METHOD *method,
  67. X509V3_CTX *ctx,
  68. STACK_OF(CONF_VALUE) *nval);
  69. static int copy_email(X509V3_CTX *ctx, GENERAL_NAMES *gens, int move_p);
  70. static int copy_issuer(X509V3_CTX *ctx, GENERAL_NAMES *gens);
  71. static int do_othername(GENERAL_NAME *gen, char *value, X509V3_CTX *ctx);
  72. static int do_dirname(GENERAL_NAME *gen, char *value, X509V3_CTX *ctx);
  73. const X509V3_EXT_METHOD v3_alt[] = {
  74. {NID_subject_alt_name, 0, ASN1_ITEM_ref(GENERAL_NAMES),
  75. 0, 0, 0, 0,
  76. 0, 0,
  77. (X509V3_EXT_I2V) i2v_GENERAL_NAMES,
  78. (X509V3_EXT_V2I)v2i_subject_alt,
  79. NULL, NULL, NULL},
  80. {NID_issuer_alt_name, 0, ASN1_ITEM_ref(GENERAL_NAMES),
  81. 0, 0, 0, 0,
  82. 0, 0,
  83. (X509V3_EXT_I2V) i2v_GENERAL_NAMES,
  84. (X509V3_EXT_V2I)v2i_issuer_alt,
  85. NULL, NULL, NULL},
  86. {NID_certificate_issuer, 0, ASN1_ITEM_ref(GENERAL_NAMES),
  87. 0, 0, 0, 0,
  88. 0, 0,
  89. (X509V3_EXT_I2V) i2v_GENERAL_NAMES,
  90. NULL, NULL, NULL, NULL},
  91. };
  92. STACK_OF(CONF_VALUE) *i2v_GENERAL_NAMES(X509V3_EXT_METHOD *method,
  93. GENERAL_NAMES *gens,
  94. STACK_OF(CONF_VALUE) *ret)
  95. {
  96. int i;
  97. GENERAL_NAME *gen;
  98. for (i = 0; i < sk_GENERAL_NAME_num(gens); i++) {
  99. gen = sk_GENERAL_NAME_value(gens, i);
  100. ret = i2v_GENERAL_NAME(method, gen, ret);
  101. }
  102. if (!ret)
  103. return sk_CONF_VALUE_new_null();
  104. return ret;
  105. }
  106. STACK_OF(CONF_VALUE) *i2v_GENERAL_NAME(X509V3_EXT_METHOD *method,
  107. GENERAL_NAME *gen,
  108. STACK_OF(CONF_VALUE) *ret)
  109. {
  110. unsigned char *p;
  111. char oline[256], htmp[5];
  112. int i;
  113. switch (gen->type) {
  114. case GEN_OTHERNAME:
  115. X509V3_add_value("othername", "<unsupported>", &ret);
  116. break;
  117. case GEN_X400:
  118. X509V3_add_value("X400Name", "<unsupported>", &ret);
  119. break;
  120. case GEN_EDIPARTY:
  121. X509V3_add_value("EdiPartyName", "<unsupported>", &ret);
  122. break;
  123. case GEN_EMAIL:
  124. X509V3_add_value_uchar("email", gen->d.ia5->data, &ret);
  125. break;
  126. case GEN_DNS:
  127. X509V3_add_value_uchar("DNS", gen->d.ia5->data, &ret);
  128. break;
  129. case GEN_URI:
  130. X509V3_add_value_uchar("URI", gen->d.ia5->data, &ret);
  131. break;
  132. case GEN_DIRNAME:
  133. X509_NAME_oneline(gen->d.dirn, oline, 256);
  134. X509V3_add_value("DirName", oline, &ret);
  135. break;
  136. case GEN_IPADD:
  137. p = gen->d.ip->data;
  138. if (gen->d.ip->length == 4)
  139. BIO_snprintf(oline, sizeof oline,
  140. "%d.%d.%d.%d", p[0], p[1], p[2], p[3]);
  141. else if (gen->d.ip->length == 16) {
  142. oline[0] = 0;
  143. for (i = 0; i < 8; i++) {
  144. BIO_snprintf(htmp, sizeof htmp, "%X", p[0] << 8 | p[1]);
  145. p += 2;
  146. strcat(oline, htmp);
  147. if (i != 7)
  148. strcat(oline, ":");
  149. }
  150. } else {
  151. X509V3_add_value("IP Address", "<invalid>", &ret);
  152. break;
  153. }
  154. X509V3_add_value("IP Address", oline, &ret);
  155. break;
  156. case GEN_RID:
  157. i2t_ASN1_OBJECT(oline, 256, gen->d.rid);
  158. X509V3_add_value("Registered ID", oline, &ret);
  159. break;
  160. }
  161. return ret;
  162. }
  163. int GENERAL_NAME_print(BIO *out, GENERAL_NAME *gen)
  164. {
  165. unsigned char *p;
  166. int i;
  167. switch (gen->type) {
  168. case GEN_OTHERNAME:
  169. BIO_printf(out, "othername:<unsupported>");
  170. break;
  171. case GEN_X400:
  172. BIO_printf(out, "X400Name:<unsupported>");
  173. break;
  174. case GEN_EDIPARTY:
  175. /* Maybe fix this: it is supported now */
  176. BIO_printf(out, "EdiPartyName:<unsupported>");
  177. break;
  178. case GEN_EMAIL:
  179. BIO_printf(out, "email:%s", gen->d.ia5->data);
  180. break;
  181. case GEN_DNS:
  182. BIO_printf(out, "DNS:%s", gen->d.ia5->data);
  183. break;
  184. case GEN_URI:
  185. BIO_printf(out, "URI:%s", gen->d.ia5->data);
  186. break;
  187. case GEN_DIRNAME:
  188. BIO_printf(out, "DirName: ");
  189. X509_NAME_print_ex(out, gen->d.dirn, 0, XN_FLAG_ONELINE);
  190. break;
  191. case GEN_IPADD:
  192. p = gen->d.ip->data;
  193. if (gen->d.ip->length == 4)
  194. BIO_printf(out, "IP Address:%d.%d.%d.%d", p[0], p[1], p[2], p[3]);
  195. else if (gen->d.ip->length == 16) {
  196. BIO_printf(out, "IP Address");
  197. for (i = 0; i < 8; i++) {
  198. BIO_printf(out, ":%X", p[0] << 8 | p[1]);
  199. p += 2;
  200. }
  201. BIO_puts(out, "\n");
  202. } else {
  203. BIO_printf(out, "IP Address:<invalid>");
  204. break;
  205. }
  206. break;
  207. case GEN_RID:
  208. BIO_printf(out, "Registered ID");
  209. i2a_ASN1_OBJECT(out, gen->d.rid);
  210. break;
  211. }
  212. return 1;
  213. }
  214. static GENERAL_NAMES *v2i_issuer_alt(X509V3_EXT_METHOD *method,
  215. X509V3_CTX *ctx,
  216. STACK_OF(CONF_VALUE) *nval)
  217. {
  218. GENERAL_NAMES *gens = NULL;
  219. CONF_VALUE *cnf;
  220. int i;
  221. if (!(gens = sk_GENERAL_NAME_new_null())) {
  222. X509V3err(X509V3_F_V2I_ISSUER_ALT, ERR_R_MALLOC_FAILURE);
  223. return NULL;
  224. }
  225. for (i = 0; i < sk_CONF_VALUE_num(nval); i++) {
  226. cnf = sk_CONF_VALUE_value(nval, i);
  227. if (!name_cmp(cnf->name, "issuer") && cnf->value &&
  228. !strcmp(cnf->value, "copy")) {
  229. if (!copy_issuer(ctx, gens))
  230. goto err;
  231. } else {
  232. GENERAL_NAME *gen;
  233. if (!(gen = v2i_GENERAL_NAME(method, ctx, cnf)))
  234. goto err;
  235. sk_GENERAL_NAME_push(gens, gen);
  236. }
  237. }
  238. return gens;
  239. err:
  240. sk_GENERAL_NAME_pop_free(gens, GENERAL_NAME_free);
  241. return NULL;
  242. }
  243. /* Append subject altname of issuer to issuer alt name of subject */
  244. static int copy_issuer(X509V3_CTX *ctx, GENERAL_NAMES *gens)
  245. {
  246. GENERAL_NAMES *ialt;
  247. GENERAL_NAME *gen;
  248. X509_EXTENSION *ext;
  249. int i;
  250. if (ctx && (ctx->flags == CTX_TEST))
  251. return 1;
  252. if (!ctx || !ctx->issuer_cert) {
  253. X509V3err(X509V3_F_COPY_ISSUER, X509V3_R_NO_ISSUER_DETAILS);
  254. goto err;
  255. }
  256. i = X509_get_ext_by_NID(ctx->issuer_cert, NID_subject_alt_name, -1);
  257. if (i < 0)
  258. return 1;
  259. if (!(ext = X509_get_ext(ctx->issuer_cert, i)) ||
  260. !(ialt = X509V3_EXT_d2i(ext))) {
  261. X509V3err(X509V3_F_COPY_ISSUER, X509V3_R_ISSUER_DECODE_ERROR);
  262. goto err;
  263. }
  264. for (i = 0; i < sk_GENERAL_NAME_num(ialt); i++) {
  265. gen = sk_GENERAL_NAME_value(ialt, i);
  266. if (!sk_GENERAL_NAME_push(gens, gen)) {
  267. X509V3err(X509V3_F_COPY_ISSUER, ERR_R_MALLOC_FAILURE);
  268. goto err;
  269. }
  270. }
  271. sk_GENERAL_NAME_free(ialt);
  272. return 1;
  273. err:
  274. return 0;
  275. }
  276. static GENERAL_NAMES *v2i_subject_alt(X509V3_EXT_METHOD *method,
  277. X509V3_CTX *ctx,
  278. STACK_OF(CONF_VALUE) *nval)
  279. {
  280. GENERAL_NAMES *gens = NULL;
  281. CONF_VALUE *cnf;
  282. int i;
  283. if (!(gens = sk_GENERAL_NAME_new_null())) {
  284. X509V3err(X509V3_F_V2I_SUBJECT_ALT, ERR_R_MALLOC_FAILURE);
  285. return NULL;
  286. }
  287. for (i = 0; i < sk_CONF_VALUE_num(nval); i++) {
  288. cnf = sk_CONF_VALUE_value(nval, i);
  289. if (!name_cmp(cnf->name, "email") && cnf->value &&
  290. !strcmp(cnf->value, "copy")) {
  291. if (!copy_email(ctx, gens, 0))
  292. goto err;
  293. } else if (!name_cmp(cnf->name, "email") && cnf->value &&
  294. !strcmp(cnf->value, "move")) {
  295. if (!copy_email(ctx, gens, 1))
  296. goto err;
  297. } else {
  298. GENERAL_NAME *gen;
  299. if (!(gen = v2i_GENERAL_NAME(method, ctx, cnf)))
  300. goto err;
  301. sk_GENERAL_NAME_push(gens, gen);
  302. }
  303. }
  304. return gens;
  305. err:
  306. sk_GENERAL_NAME_pop_free(gens, GENERAL_NAME_free);
  307. return NULL;
  308. }
  309. /*
  310. * Copy any email addresses in a certificate or request to GENERAL_NAMES
  311. */
  312. static int copy_email(X509V3_CTX *ctx, GENERAL_NAMES *gens, int move_p)
  313. {
  314. X509_NAME *nm;
  315. ASN1_IA5STRING *email = NULL;
  316. X509_NAME_ENTRY *ne;
  317. GENERAL_NAME *gen = NULL;
  318. int i;
  319. if (ctx != NULL && ctx->flags == CTX_TEST)
  320. return 1;
  321. if (!ctx || (!ctx->subject_cert && !ctx->subject_req)) {
  322. X509V3err(X509V3_F_COPY_EMAIL, X509V3_R_NO_SUBJECT_DETAILS);
  323. goto err;
  324. }
  325. /* Find the subject name */
  326. if (ctx->subject_cert)
  327. nm = X509_get_subject_name(ctx->subject_cert);
  328. else
  329. nm = X509_REQ_get_subject_name(ctx->subject_req);
  330. /* Now add any email address(es) to STACK */
  331. i = -1;
  332. while ((i = X509_NAME_get_index_by_NID(nm,
  333. NID_pkcs9_emailAddress, i)) >= 0) {
  334. ne = X509_NAME_get_entry(nm, i);
  335. email = M_ASN1_IA5STRING_dup(X509_NAME_ENTRY_get_data(ne));
  336. if (move_p) {
  337. X509_NAME_delete_entry(nm, i);
  338. X509_NAME_ENTRY_free(ne);
  339. i--;
  340. }
  341. if (!email || !(gen = GENERAL_NAME_new())) {
  342. X509V3err(X509V3_F_COPY_EMAIL, ERR_R_MALLOC_FAILURE);
  343. goto err;
  344. }
  345. gen->d.ia5 = email;
  346. email = NULL;
  347. gen->type = GEN_EMAIL;
  348. if (!sk_GENERAL_NAME_push(gens, gen)) {
  349. X509V3err(X509V3_F_COPY_EMAIL, ERR_R_MALLOC_FAILURE);
  350. goto err;
  351. }
  352. gen = NULL;
  353. }
  354. return 1;
  355. err:
  356. GENERAL_NAME_free(gen);
  357. M_ASN1_IA5STRING_free(email);
  358. return 0;
  359. }
  360. GENERAL_NAMES *v2i_GENERAL_NAMES(const X509V3_EXT_METHOD *method,
  361. X509V3_CTX *ctx, STACK_OF(CONF_VALUE) *nval)
  362. {
  363. GENERAL_NAME *gen;
  364. GENERAL_NAMES *gens = NULL;
  365. CONF_VALUE *cnf;
  366. int i;
  367. if (!(gens = sk_GENERAL_NAME_new_null())) {
  368. X509V3err(X509V3_F_V2I_GENERAL_NAMES, ERR_R_MALLOC_FAILURE);
  369. return NULL;
  370. }
  371. for (i = 0; i < sk_CONF_VALUE_num(nval); i++) {
  372. cnf = sk_CONF_VALUE_value(nval, i);
  373. if (!(gen = v2i_GENERAL_NAME(method, ctx, cnf)))
  374. goto err;
  375. sk_GENERAL_NAME_push(gens, gen);
  376. }
  377. return gens;
  378. err:
  379. sk_GENERAL_NAME_pop_free(gens, GENERAL_NAME_free);
  380. return NULL;
  381. }
  382. GENERAL_NAME *v2i_GENERAL_NAME(const X509V3_EXT_METHOD *method,
  383. X509V3_CTX *ctx, CONF_VALUE *cnf)
  384. {
  385. return v2i_GENERAL_NAME_ex(NULL, method, ctx, cnf, 0);
  386. }
  387. GENERAL_NAME *a2i_GENERAL_NAME(GENERAL_NAME *out,
  388. const X509V3_EXT_METHOD *method,
  389. X509V3_CTX *ctx, int gen_type, char *value,
  390. int is_nc)
  391. {
  392. char is_string = 0;
  393. GENERAL_NAME *gen = NULL;
  394. if (!value) {
  395. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_MISSING_VALUE);
  396. return NULL;
  397. }
  398. if (out)
  399. gen = out;
  400. else {
  401. gen = GENERAL_NAME_new();
  402. if (gen == NULL) {
  403. X509V3err(X509V3_F_A2I_GENERAL_NAME, ERR_R_MALLOC_FAILURE);
  404. return NULL;
  405. }
  406. }
  407. switch (gen_type) {
  408. case GEN_URI:
  409. case GEN_EMAIL:
  410. case GEN_DNS:
  411. is_string = 1;
  412. break;
  413. case GEN_RID:
  414. {
  415. ASN1_OBJECT *obj;
  416. if (!(obj = OBJ_txt2obj(value, 0))) {
  417. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_BAD_OBJECT);
  418. ERR_add_error_data(2, "value=", value);
  419. goto err;
  420. }
  421. gen->d.rid = obj;
  422. }
  423. break;
  424. case GEN_IPADD:
  425. if (is_nc)
  426. gen->d.ip = a2i_IPADDRESS_NC(value);
  427. else
  428. gen->d.ip = a2i_IPADDRESS(value);
  429. if (gen->d.ip == NULL) {
  430. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_BAD_IP_ADDRESS);
  431. ERR_add_error_data(2, "value=", value);
  432. goto err;
  433. }
  434. break;
  435. case GEN_DIRNAME:
  436. if (!do_dirname(gen, value, ctx)) {
  437. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_DIRNAME_ERROR);
  438. goto err;
  439. }
  440. break;
  441. case GEN_OTHERNAME:
  442. if (!do_othername(gen, value, ctx)) {
  443. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_OTHERNAME_ERROR);
  444. goto err;
  445. }
  446. break;
  447. default:
  448. X509V3err(X509V3_F_A2I_GENERAL_NAME, X509V3_R_UNSUPPORTED_TYPE);
  449. goto err;
  450. }
  451. if (is_string) {
  452. if (!(gen->d.ia5 = M_ASN1_IA5STRING_new()) ||
  453. !ASN1_STRING_set(gen->d.ia5, (unsigned char *)value,
  454. strlen(value))) {
  455. X509V3err(X509V3_F_A2I_GENERAL_NAME, ERR_R_MALLOC_FAILURE);
  456. goto err;
  457. }
  458. }
  459. gen->type = gen_type;
  460. return gen;
  461. err:
  462. if (!out)
  463. GENERAL_NAME_free(gen);
  464. return NULL;
  465. }
  466. GENERAL_NAME *v2i_GENERAL_NAME_ex(GENERAL_NAME *out,
  467. const X509V3_EXT_METHOD *method,
  468. X509V3_CTX *ctx, CONF_VALUE *cnf, int is_nc)
  469. {
  470. int type;
  471. char *name, *value;
  472. name = cnf->name;
  473. value = cnf->value;
  474. if (!value) {
  475. X509V3err(X509V3_F_V2I_GENERAL_NAME_EX, X509V3_R_MISSING_VALUE);
  476. return NULL;
  477. }
  478. if (!name_cmp(name, "email"))
  479. type = GEN_EMAIL;
  480. else if (!name_cmp(name, "URI"))
  481. type = GEN_URI;
  482. else if (!name_cmp(name, "DNS"))
  483. type = GEN_DNS;
  484. else if (!name_cmp(name, "RID"))
  485. type = GEN_RID;
  486. else if (!name_cmp(name, "IP"))
  487. type = GEN_IPADD;
  488. else if (!name_cmp(name, "dirName"))
  489. type = GEN_DIRNAME;
  490. else if (!name_cmp(name, "otherName"))
  491. type = GEN_OTHERNAME;
  492. else {
  493. X509V3err(X509V3_F_V2I_GENERAL_NAME_EX, X509V3_R_UNSUPPORTED_OPTION);
  494. ERR_add_error_data(2, "name=", name);
  495. return NULL;
  496. }
  497. return a2i_GENERAL_NAME(out, method, ctx, type, value, is_nc);
  498. }
  499. static int do_othername(GENERAL_NAME *gen, char *value, X509V3_CTX *ctx)
  500. {
  501. char *objtmp = NULL, *p;
  502. int objlen;
  503. if (!(p = strchr(value, ';')))
  504. return 0;
  505. if (!(gen->d.otherName = OTHERNAME_new()))
  506. return 0;
  507. /*
  508. * Free this up because we will overwrite it. no need to free type_id
  509. * because it is static
  510. */
  511. ASN1_TYPE_free(gen->d.otherName->value);
  512. if (!(gen->d.otherName->value = ASN1_generate_v3(p + 1, ctx)))
  513. return 0;
  514. objlen = p - value;
  515. objtmp = OPENSSL_malloc(objlen + 1);
  516. strncpy(objtmp, value, objlen);
  517. objtmp[objlen] = 0;
  518. gen->d.otherName->type_id = OBJ_txt2obj(objtmp, 0);
  519. OPENSSL_free(objtmp);
  520. if (!gen->d.otherName->type_id)
  521. return 0;
  522. return 1;
  523. }
  524. static int do_dirname(GENERAL_NAME *gen, char *value, X509V3_CTX *ctx)
  525. {
  526. int ret = 0;
  527. STACK_OF(CONF_VALUE) *sk = NULL;
  528. X509_NAME *nm = NULL;
  529. if (!(nm = X509_NAME_new()))
  530. goto err;
  531. sk = X509V3_get_section(ctx, value);
  532. if (!sk) {
  533. X509V3err(X509V3_F_DO_DIRNAME, X509V3_R_SECTION_NOT_FOUND);
  534. ERR_add_error_data(2, "section=", value);
  535. goto err;
  536. }
  537. /* FIXME: should allow other character types... */
  538. ret = X509V3_NAME_from_section(nm, sk, MBSTRING_ASC);
  539. if (!ret)
  540. goto err;
  541. gen->d.dirn = nm;
  542. err:
  543. if (ret == 0)
  544. X509_NAME_free(nm);
  545. X509V3_section_free(ctx, sk);
  546. return ret;
  547. }