summaryrefslogtreecommitdiff
path: root/apps/cmp.c
diff options
context:
space:
mode:
authorEnji Cooper <ngie@FreeBSD.org>2026-01-29 01:27:53 +0000
committerEnji Cooper <ngie@FreeBSD.org>2026-01-29 01:27:53 +0000
commit808413da28df9fb93e1f304e6016b15e660f54c8 (patch)
treef3ecb4f928716223c9563ee34e044ab84549debb /apps/cmp.c
parent8e12a5c4eb3507846b507d0afe87d115af41df40 (diff)
Diffstat (limited to 'apps/cmp.c')
-rw-r--r--apps/cmp.c1411
1 files changed, 740 insertions, 671 deletions
diff --git a/apps/cmp.c b/apps/cmp.c
index 2b4340d9fb45..f1af0b6c2b42 100644
--- a/apps/cmp.c
+++ b/apps/cmp.c
@@ -24,10 +24,10 @@
/* tweaks needed due to missing unistd.h on Windows */
#if defined(_WIN32) && !defined(__BORLANDC__)
-# define access _access
+#define access _access
#endif
#ifndef F_OK
-# define F_OK 0
+#define F_OK 0
#endif
#include <openssl/ui.h>
@@ -151,7 +151,7 @@ static int opt_revreason = CRL_REASON_NONE;
/* credentials format */
static char *opt_certform_s = "PEM";
static int opt_certform = FORMAT_PEM;
-/*
+/*
* DER format is the preferred choice for saving a CRL because it allows for
* more efficient storage, especially when dealing with large CRLs.
*/
@@ -229,40 +229,85 @@ static X509_VERIFY_PARAM *vpm = NULL;
typedef enum OPTION_choice {
OPT_COMMON,
- OPT_CONFIG, OPT_SECTION, OPT_VERBOSITY,
+ OPT_CONFIG,
+ OPT_SECTION,
+ OPT_VERBOSITY,
- OPT_CMD, OPT_INFOTYPE, OPT_PROFILE, OPT_GENINFO,
- OPT_TEMPLATE, OPT_KEYSPEC,
+ OPT_CMD,
+ OPT_INFOTYPE,
+ OPT_PROFILE,
+ OPT_GENINFO,
+ OPT_TEMPLATE,
+ OPT_KEYSPEC,
- OPT_NEWKEY, OPT_NEWKEYPASS, OPT_CENTRALKEYGEN,
- OPT_NEWKEYOUT, OPT_SUBJECT,
- OPT_DAYS, OPT_REQEXTS,
- OPT_SANS, OPT_SAN_NODEFAULT,
- OPT_POLICIES, OPT_POLICY_OIDS, OPT_POLICY_OIDS_CRITICAL,
- OPT_POPO, OPT_CSR,
- OPT_OUT_TRUSTED, OPT_IMPLICIT_CONFIRM, OPT_DISABLE_CONFIRM,
- OPT_CERTOUT, OPT_CHAINOUT,
+ OPT_NEWKEY,
+ OPT_NEWKEYPASS,
+ OPT_CENTRALKEYGEN,
+ OPT_NEWKEYOUT,
+ OPT_SUBJECT,
+ OPT_DAYS,
+ OPT_REQEXTS,
+ OPT_SANS,
+ OPT_SAN_NODEFAULT,
+ OPT_POLICIES,
+ OPT_POLICY_OIDS,
+ OPT_POLICY_OIDS_CRITICAL,
+ OPT_POPO,
+ OPT_CSR,
+ OPT_OUT_TRUSTED,
+ OPT_IMPLICIT_CONFIRM,
+ OPT_DISABLE_CONFIRM,
+ OPT_CERTOUT,
+ OPT_CHAINOUT,
- OPT_OLDCERT, OPT_ISSUER, OPT_SERIAL, OPT_REVREASON,
+ OPT_OLDCERT,
+ OPT_ISSUER,
+ OPT_SERIAL,
+ OPT_REVREASON,
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
- OPT_SERVER, OPT_PROXY, OPT_NO_PROXY,
+ OPT_SERVER,
+ OPT_PROXY,
+ OPT_NO_PROXY,
#endif
- OPT_RECIPIENT, OPT_PATH,
- OPT_KEEP_ALIVE, OPT_MSG_TIMEOUT, OPT_TOTAL_TIMEOUT,
+ OPT_RECIPIENT,
+ OPT_PATH,
+ OPT_KEEP_ALIVE,
+ OPT_MSG_TIMEOUT,
+ OPT_TOTAL_TIMEOUT,
- OPT_TRUSTED, OPT_UNTRUSTED, OPT_SRVCERT,
+ OPT_TRUSTED,
+ OPT_UNTRUSTED,
+ OPT_SRVCERT,
OPT_EXPECT_SENDER,
- OPT_IGNORE_KEYUSAGE, OPT_UNPROTECTED_ERRORS, OPT_NO_CACHE_EXTRACERTS,
- OPT_SRVCERTOUT, OPT_EXTRACERTSOUT, OPT_CACERTSOUT,
- OPT_OLDWITHOLD, OPT_NEWWITHNEW, OPT_NEWWITHOLD, OPT_OLDWITHNEW,
- OPT_CRLCERT, OPT_OLDCRL, OPT_CRLOUT,
+ OPT_IGNORE_KEYUSAGE,
+ OPT_UNPROTECTED_ERRORS,
+ OPT_NO_CACHE_EXTRACERTS,
+ OPT_SRVCERTOUT,
+ OPT_EXTRACERTSOUT,
+ OPT_CACERTSOUT,
+ OPT_OLDWITHOLD,
+ OPT_NEWWITHNEW,
+ OPT_NEWWITHOLD,
+ OPT_OLDWITHNEW,
+ OPT_CRLCERT,
+ OPT_OLDCRL,
+ OPT_CRLOUT,
- OPT_REF, OPT_SECRET, OPT_CERT, OPT_OWN_TRUSTED, OPT_KEY, OPT_KEYPASS,
- OPT_DIGEST, OPT_MAC, OPT_EXTRACERTS,
+ OPT_REF,
+ OPT_SECRET,
+ OPT_CERT,
+ OPT_OWN_TRUSTED,
+ OPT_KEY,
+ OPT_KEYPASS,
+ OPT_DIGEST,
+ OPT_MAC,
+ OPT_EXTRACERTS,
OPT_UNPROTECTED_REQUESTS,
- OPT_CERTFORM, OPT_CRLFORM, OPT_KEYFORM,
+ OPT_CERTFORM,
+ OPT_CRLFORM,
+ OPT_KEYFORM,
OPT_OTHERPASS,
#ifndef OPENSSL_NO_ENGINE
OPT_ENGINE,
@@ -271,368 +316,395 @@ typedef enum OPTION_choice {
OPT_R_ENUM,
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
- OPT_TLS_USED, OPT_TLS_CERT, OPT_TLS_KEY,
+ OPT_TLS_USED,
+ OPT_TLS_CERT,
+ OPT_TLS_KEY,
OPT_TLS_KEYPASS,
- OPT_TLS_EXTRA, OPT_TLS_TRUSTED, OPT_TLS_HOST,
+ OPT_TLS_EXTRA,
+ OPT_TLS_TRUSTED,
+ OPT_TLS_HOST,
#endif
- OPT_BATCH, OPT_REPEAT,
- OPT_REQIN, OPT_REQIN_NEW_TID, OPT_REQOUT, OPT_REQOUT_ONLY,
- OPT_RSPIN, OPT_RSPOUT,
+ OPT_BATCH,
+ OPT_REPEAT,
+ OPT_REQIN,
+ OPT_REQIN_NEW_TID,
+ OPT_REQOUT,
+ OPT_REQOUT_ONLY,
+ OPT_RSPIN,
+ OPT_RSPOUT,
OPT_USE_MOCK_SRV,
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
- OPT_PORT, OPT_MAX_MSGS,
+ OPT_PORT,
+ OPT_MAX_MSGS,
#endif
- OPT_SRV_REF, OPT_SRV_SECRET,
- OPT_SRV_CERT, OPT_SRV_KEY, OPT_SRV_KEYPASS,
- OPT_SRV_TRUSTED, OPT_SRV_UNTRUSTED,
- OPT_REF_CERT, OPT_RSP_CERT, OPT_RSP_KEY, OPT_RSP_KEYPASS,
- OPT_RSP_CRL, OPT_RSP_EXTRACERTS, OPT_RSP_CAPUBS,
- OPT_RSP_NEWWITHNEW, OPT_RSP_NEWWITHOLD, OPT_RSP_OLDWITHNEW,
- OPT_POLL_COUNT, OPT_CHECK_AFTER,
+ OPT_SRV_REF,
+ OPT_SRV_SECRET,
+ OPT_SRV_CERT,
+ OPT_SRV_KEY,
+ OPT_SRV_KEYPASS,
+ OPT_SRV_TRUSTED,
+ OPT_SRV_UNTRUSTED,
+ OPT_REF_CERT,
+ OPT_RSP_CERT,
+ OPT_RSP_KEY,
+ OPT_RSP_KEYPASS,
+ OPT_RSP_CRL,
+ OPT_RSP_EXTRACERTS,
+ OPT_RSP_CAPUBS,
+ OPT_RSP_NEWWITHNEW,
+ OPT_RSP_NEWWITHOLD,
+ OPT_RSP_OLDWITHNEW,
+ OPT_POLL_COUNT,
+ OPT_CHECK_AFTER,
OPT_GRANT_IMPLICITCONF,
- OPT_PKISTATUS, OPT_FAILURE,
- OPT_FAILUREBITS, OPT_STATUSSTRING,
- OPT_SEND_ERROR, OPT_SEND_UNPROTECTED,
- OPT_SEND_UNPROT_ERR, OPT_ACCEPT_UNPROTECTED,
- OPT_ACCEPT_UNPROT_ERR, OPT_ACCEPT_RAVERIFIED,
+ OPT_PKISTATUS,
+ OPT_FAILURE,
+ OPT_FAILUREBITS,
+ OPT_STATUSSTRING,
+ OPT_SEND_ERROR,
+ OPT_SEND_UNPROTECTED,
+ OPT_SEND_UNPROT_ERR,
+ OPT_ACCEPT_UNPROTECTED,
+ OPT_ACCEPT_UNPROT_ERR,
+ OPT_ACCEPT_RAVERIFIED,
OPT_V_ENUM
} OPTION_CHOICE;
const OPTIONS cmp_options[] = {
/* entries must be in the same order as enumerated above!! */
- {"help", OPT_HELP, '-', "Display this summary"},
- {"config", OPT_CONFIG, 's',
- "Configuration file to use. \"\" = none. Default from env variable OPENSSL_CONF"},
- {"section", OPT_SECTION, 's',
- "Section(s) in config file to get options from. \"\" = 'default'. Default 'cmp'"},
- {"verbosity", OPT_VERBOSITY, 'N',
- "Log level; 3=ERR, 4=WARN, 6=INFO, 7=DEBUG, 8=TRACE. Default 6 = INFO"},
+ { "help", OPT_HELP, '-', "Display this summary" },
+ { "config", OPT_CONFIG, 's',
+ "Configuration file to use. \"\" = none. Default from env variable OPENSSL_CONF" },
+ { "section", OPT_SECTION, 's',
+ "Section(s) in config file to get options from. \"\" = 'default'. Default 'cmp'" },
+ { "verbosity", OPT_VERBOSITY, 'N',
+ "Log level; 3=ERR, 4=WARN, 6=INFO, 7=DEBUG, 8=TRACE. Default 6 = INFO" },
OPT_SECTION("Generic message"),
- {"cmd", OPT_CMD, 's', "CMP request to send: ir/cr/kur/p10cr/rr/genm"},
- {"infotype", OPT_INFOTYPE, 's',
- "InfoType name for requesting specific info in genm, with specific support"},
- {OPT_MORE_STR, 0, 0,
- "for 'caCerts' and 'rootCaCert'"},
- {"profile", OPT_PROFILE, 's',
- "Certificate profile name to place in generalInfo field of request PKIHeader"},
- {"geninfo", OPT_GENINFO, 's',
- "Comma-separated list of OID and value to place in generalInfo PKIHeader"},
- {OPT_MORE_STR, 0, 0,
- "of form <OID>:int:<n> or <OID>:str:<s>, e.g. \'1.2.3.4:int:56789, id-kp:str:name'"},
+ { "cmd", OPT_CMD, 's', "CMP request to send: ir/cr/kur/p10cr/rr/genm" },
+ { "infotype", OPT_INFOTYPE, 's',
+ "InfoType name for requesting specific info in genm, with specific support" },
+ { OPT_MORE_STR, 0, 0,
+ "for 'caCerts' and 'rootCaCert'" },
+ { "profile", OPT_PROFILE, 's',
+ "Certificate profile name to place in generalInfo field of request PKIHeader" },
+ { "geninfo", OPT_GENINFO, 's',
+ "Comma-separated list of OID and value to place in generalInfo PKIHeader" },
+ { OPT_MORE_STR, 0, 0,
+ "of form <OID>:int:<n> or <OID>:str:<s>, e.g. \'1.2.3.4:int:56789, id-kp:str:name'" },
{ "template", OPT_TEMPLATE, 's',
- "File to save certTemplate received in genp of type certReqTemplate"},
+ "File to save certTemplate received in genp of type certReqTemplate" },
{ "keyspec", OPT_KEYSPEC, 's',
- "Optional file to save Key specification received in genp of type certReqTemplate"},
+ "Optional file to save Key specification received in genp of type certReqTemplate" },
OPT_SECTION("Certificate enrollment"),
- {"newkey", OPT_NEWKEY, 's',
- "Private or public key for the requested cert. Default: CSR key or client key"},
- {"newkeypass", OPT_NEWKEYPASS, 's', "New private key pass phrase source"},
- {"centralkeygen", OPT_CENTRALKEYGEN, '-',
- "Request central (server-side) key generation. Default is local generation"},
- {"newkeyout", OPT_NEWKEYOUT, 's',
- "File to save centrally generated key, in PEM format"},
- {"subject", OPT_SUBJECT, 's',
- "Distinguished Name (DN) of subject to use in the requested cert template"},
- {OPT_MORE_STR, 0, 0,
- "For kur, default is subject of -csr arg or reference cert (see -oldcert)"},
- {OPT_MORE_STR, 0, 0,
- "this default is used for ir and cr only if no Subject Alt Names are set"},
- {"days", OPT_DAYS, 'N',
- "Requested validity time of the new certificate in number of days"},
- {"reqexts", OPT_REQEXTS, 's',
- "Name of config file section defining certificate request extensions."},
- {OPT_MORE_STR, 0, 0,
- "Augments or replaces any extensions contained CSR given with -csr"},
- {"sans", OPT_SANS, 's',
- "Subject Alt Names (IPADDR/DNS/URI) to add as (critical) cert req extension"},
- {"san_nodefault", OPT_SAN_NODEFAULT, '-',
- "Do not take default SANs from reference certificate (see -oldcert)"},
- {"policies", OPT_POLICIES, 's',
- "Name of config file section defining policies certificate request extension"},
- {"policy_oids", OPT_POLICY_OIDS, 's',
- "Policy OID(s) to add as policies certificate request extension"},
- {"policy_oids_critical", OPT_POLICY_OIDS_CRITICAL, '-',
- "Flag the policy OID(s) given with -policy_oids as critical"},
- {"popo", OPT_POPO, 'n',
- "Proof-of-Possession (POPO) method to use for ir/cr/kur where"},
- {OPT_MORE_STR, 0, 0,
- "-1 = NONE, 0 = RAVERIFIED, 1 = SIGNATURE (default), 2 = KEYENC"},
- {"csr", OPT_CSR, 's',
- "PKCS#10 CSR file in PEM or DER format to convert or to use in p10cr"},
- {"out_trusted", OPT_OUT_TRUSTED, 's',
- "Certificates to trust when verifying newly enrolled certificates"},
- {"implicit_confirm", OPT_IMPLICIT_CONFIRM, '-',
- "Request implicit confirmation of newly enrolled certificates"},
- {"disable_confirm", OPT_DISABLE_CONFIRM, '-',
- "Do not confirm newly enrolled certificate w/o requesting implicit"},
- {OPT_MORE_STR, 0, 0,
- "confirmation. WARNING: This leads to behavior violating RFC 4210"},
- {"certout", OPT_CERTOUT, 's',
- "File to save newly enrolled certificate"},
- {"chainout", OPT_CHAINOUT, 's',
- "File to save the chain of newly enrolled certificate"},
+ { "newkey", OPT_NEWKEY, 's',
+ "Private or public key for the requested cert. Default: CSR key or client key" },
+ { "newkeypass", OPT_NEWKEYPASS, 's', "New private key pass phrase source" },
+ { "centralkeygen", OPT_CENTRALKEYGEN, '-',
+ "Request central (server-side) key generation. Default is local generation" },
+ { "newkeyout", OPT_NEWKEYOUT, 's',
+ "File to save centrally generated key, in PEM format" },
+ { "subject", OPT_SUBJECT, 's',
+ "Distinguished Name (DN) of subject to use in the requested cert template" },
+ { OPT_MORE_STR, 0, 0,
+ "For kur, default is subject of -csr arg or reference cert (see -oldcert)" },
+ { OPT_MORE_STR, 0, 0,
+ "this default is used for ir and cr only if no Subject Alt Names are set" },
+ { "days", OPT_DAYS, 'N',
+ "Requested validity time of the new certificate in number of days" },
+ { "reqexts", OPT_REQEXTS, 's',
+ "Name of config file section defining certificate request extensions." },
+ { OPT_MORE_STR, 0, 0,
+ "Augments or replaces any extensions contained CSR given with -csr" },
+ { "sans", OPT_SANS, 's',
+ "Subject Alt Names (IPADDR/DNS/URI) to add as (critical) cert req extension" },
+ { "san_nodefault", OPT_SAN_NODEFAULT, '-',
+ "Do not take default SANs from reference certificate (see -oldcert)" },
+ { "policies", OPT_POLICIES, 's',
+ "Name of config file section defining policies certificate request extension" },
+ { "policy_oids", OPT_POLICY_OIDS, 's',
+ "Policy OID(s) to add as policies certificate request extension" },
+ { "policy_oids_critical", OPT_POLICY_OIDS_CRITICAL, '-',
+ "Flag the policy OID(s) given with -policy_oids as critical" },
+ { "popo", OPT_POPO, 'n',
+ "Proof-of-Possession (POPO) method to use for ir/cr/kur where" },
+ { OPT_MORE_STR, 0, 0,
+ "-1 = NONE, 0 = RAVERIFIED, 1 = SIGNATURE (default), 2 = KEYENC" },
+ { "csr", OPT_CSR, 's',
+ "PKCS#10 CSR file in PEM or DER format to convert or to use in p10cr" },
+ { "out_trusted", OPT_OUT_TRUSTED, 's',
+ "Certificates to trust when verifying newly enrolled certificates" },
+ { "implicit_confirm", OPT_IMPLICIT_CONFIRM, '-',
+ "Request implicit confirmation of newly enrolled certificates" },
+ { "disable_confirm", OPT_DISABLE_CONFIRM, '-',
+ "Do not confirm newly enrolled certificate w/o requesting implicit" },
+ { OPT_MORE_STR, 0, 0,
+ "confirmation. WARNING: This leads to behavior violating RFC 9810" },
+ { "certout", OPT_CERTOUT, 's',
+ "File to save newly enrolled certificate" },
+ { "chainout", OPT_CHAINOUT, 's',
+ "File to save the chain of newly enrolled certificate" },
OPT_SECTION("Certificate enrollment and revocation"),
- {"oldcert", OPT_OLDCERT, 's',
- "Certificate to be updated (defaulting to -cert) or to be revoked in rr;"},
- {OPT_MORE_STR, 0, 0,
- "also used as reference (defaulting to -cert) for subject DN and SANs."},
- {OPT_MORE_STR, 0, 0,
- "Issuer is used as recipient unless -recipient, -srvcert, or -issuer given"},
- {"issuer", OPT_ISSUER, 's',
- "DN of the issuer to place in the certificate template of ir/cr/kur/rr;"},
- {OPT_MORE_STR, 0, 0,
- "also used as recipient if neither -recipient nor -srvcert are given"},
- {"serial", OPT_SERIAL, 's',
- "Serial number of certificate to be revoked in revocation request (rr)"},
- {"revreason", OPT_REVREASON, 'n',
- "Reason code to include in revocation request (rr); possible values:"},
- {OPT_MORE_STR, 0, 0,
- "0..6, 8..10 (see RFC5280, 5.3.1) or -1. Default -1 = none included"},
+ { "oldcert", OPT_OLDCERT, 's',
+ "Certificate to be updated (defaulting to -cert) or to be revoked in rr;" },
+ { OPT_MORE_STR, 0, 0,
+ "also used as reference (defaulting to -cert) for subject DN and SANs." },
+ { OPT_MORE_STR, 0, 0,
+ "Issuer is used as recipient unless -recipient, -srvcert, or -issuer given" },
+ { "issuer", OPT_ISSUER, 's',
+ "DN of the issuer to place in the certificate template of ir/cr/kur/rr;" },
+ { OPT_MORE_STR, 0, 0,
+ "also used as recipient if neither -recipient nor -srvcert are given" },
+ { "serial", OPT_SERIAL, 's',
+ "Serial number of certificate to be revoked in revocation request (rr)" },
+ { "revreason", OPT_REVREASON, 'n',
+ "Reason code to include in revocation request (rr); possible values:" },
+ { OPT_MORE_STR, 0, 0,
+ "0..6, 8..10 (see RFC5280, 5.3.1) or -1. Default -1 = none included" },
OPT_SECTION("Message transfer"),
#if defined(OPENSSL_NO_SOCK) || defined(OPENSSL_NO_HTTP)
- {OPT_MORE_STR, 0, 0,
- "NOTE: -server, -proxy, and -no_proxy not supported due to no-sock/no-http build"},
+ { OPT_MORE_STR, 0, 0,
+ "NOTE: -server, -proxy, and -no_proxy not supported due to no-sock/no-http build" },
#else
- {"server", OPT_SERVER, 's',
- "[http[s]://]address[:port][/path] of CMP server. Default port 80 or 443."},
- {OPT_MORE_STR, 0, 0,
- "address may be a DNS name or an IP address; path can be overridden by -path"},
- {"proxy", OPT_PROXY, 's',
- "[http[s]://]address[:port][/path] of HTTP(S) proxy to use; path is ignored"},
- {"no_proxy", OPT_NO_PROXY, 's',
- "List of addresses of servers not to use HTTP(S) proxy for"},
- {OPT_MORE_STR, 0, 0,
- "Default from environment variable 'no_proxy', else 'NO_PROXY', else none"},
+ { "server", OPT_SERVER, 's',
+ "[http[s]://]address[:port][/path] of CMP server. Default port 80 or 443." },
+ { OPT_MORE_STR, 0, 0,
+ "address may be a DNS name or an IP address; path can be overridden by -path" },
+ { "proxy", OPT_PROXY, 's',
+ "[http[s]://]address[:port][/path] of HTTP(S) proxy to use; path is ignored" },
+ { "no_proxy", OPT_NO_PROXY, 's',
+ "List of addresses of servers not to use HTTP(S) proxy for" },
+ { OPT_MORE_STR, 0, 0,
+ "Default from environment variable 'no_proxy', else 'NO_PROXY', else none" },
#endif
- {"recipient", OPT_RECIPIENT, 's',
- "DN of CA. Default: subject of -srvcert, -issuer, issuer of -oldcert or -cert"},
- {"path", OPT_PATH, 's',
- "HTTP path (aka CMP alias) at the CMP server. Default from -server, else \"/\""},
- {"keep_alive", OPT_KEEP_ALIVE, 'N',
- "Persistent HTTP connections. 0: no, 1 (the default): request, 2: require"},
- {"msg_timeout", OPT_MSG_TIMEOUT, 'N',
- "Number of seconds allowed per CMP message round trip, or 0 for infinite"},
- {"total_timeout", OPT_TOTAL_TIMEOUT, 'N',
- "Overall time an enrollment incl. polling may take. Default 0 = infinite"},
+ { "recipient", OPT_RECIPIENT, 's',
+ "DN of CA. Default: subject of -srvcert, -issuer, issuer of -oldcert or -cert" },
+ { "path", OPT_PATH, 's',
+ "HTTP path (aka CMP alias) at the CMP server. Default from -server, else \"/\"" },
+ { "keep_alive", OPT_KEEP_ALIVE, 'N',
+ "Persistent HTTP connections. 0: no, 1 (the default): request, 2: require" },
+ { "msg_timeout", OPT_MSG_TIMEOUT, 'N',
+ "Number of seconds allowed per CMP message round trip, or 0 for infinite" },
+ { "total_timeout", OPT_TOTAL_TIMEOUT, 'N',
+ "Overall time an enrollment incl. polling may take. Default 0 = infinite" },
OPT_SECTION("Server authentication"),
- {"trusted", OPT_TRUSTED, 's',
- "Certificates to use as trust anchors when verifying signed CMP responses"},
- {OPT_MORE_STR, 0, 0, "unless -srvcert is given"},
- {"untrusted", OPT_UNTRUSTED, 's',
- "Intermediate CA certs for chain construction for CMP/TLS/enrolled certs"},
- {"srvcert", OPT_SRVCERT, 's',
- "Server cert to pin and trust directly when verifying signed CMP responses"},
- {"expect_sender", OPT_EXPECT_SENDER, 's',
- "DN of expected sender of responses. Defaults to subject of -srvcert, if any"},
- {"ignore_keyusage", OPT_IGNORE_KEYUSAGE, '-',
- "Ignore CMP signer cert key usage, else 'digitalSignature' must be allowed"},
- {"unprotected_errors", OPT_UNPROTECTED_ERRORS, '-',
- "Accept missing or invalid protection of regular error messages and negative"},
- {OPT_MORE_STR, 0, 0,
- "certificate responses (ip/cp/kup), revocation responses (rp), and PKIConf"},
- {OPT_MORE_STR, 0, 0,
- "WARNING: This setting leads to behavior allowing violation of RFC 4210"},
- {"no_cache_extracerts", OPT_NO_CACHE_EXTRACERTS, '-',
- "Do not keep certificates received in the extraCerts CMP message field"},
+ { "trusted", OPT_TRUSTED, 's',
+ "Certificates to use as trust anchors when verifying signed CMP responses" },
+ { OPT_MORE_STR, 0, 0, "unless -srvcert is given" },
+ { "untrusted", OPT_UNTRUSTED, 's',
+ "Intermediate CA certs for chain construction for CMP/TLS/enrolled certs" },
+ { "srvcert", OPT_SRVCERT, 's',
+ "Server cert to pin and trust directly when verifying signed CMP responses" },
+ { "expect_sender", OPT_EXPECT_SENDER, 's',
+ "DN of expected sender of responses. Defaults to subject of -srvcert, if any" },
+ { "ignore_keyusage", OPT_IGNORE_KEYUSAGE, '-',
+ "Ignore CMP signer cert key usage, else 'digitalSignature' must be allowed" },
+ { "unprotected_errors", OPT_UNPROTECTED_ERRORS, '-',
+ "Accept missing or invalid protection of regular error messages and negative" },
+ { OPT_MORE_STR, 0, 0,
+ "certificate responses (ip/cp/kup), revocation responses (rp), and PKIConf" },
+ { OPT_MORE_STR, 0, 0,
+ "WARNING: This setting leads to behavior allowing violation of RFC 9810" },
+ { "no_cache_extracerts", OPT_NO_CACHE_EXTRACERTS, '-',
+ "Do not keep certificates received in the extraCerts CMP message field" },
{ "srvcertout", OPT_SRVCERTOUT, 's',
- "File to save the server cert used and validated for CMP response protection"},
- {"extracertsout", OPT_EXTRACERTSOUT, 's',
- "File to save extra certificates received in the extraCerts field"},
- {"cacertsout", OPT_CACERTSOUT, 's',
- "File to save CA certs received in caPubs field or genp with id-it-caCerts"},
+ "File to save the server cert used and validated for CMP response protection" },
+ { "extracertsout", OPT_EXTRACERTSOUT, 's',
+ "File to save extra certificates received in the extraCerts field" },
+ { "cacertsout", OPT_CACERTSOUT, 's',
+ "File to save CA certs received in caPubs field or genp with id-it-caCerts" },
{ "oldwithold", OPT_OLDWITHOLD, 's',
- "Root CA certificate to request update for in genm of type rootCaCert"},
+ "Root CA certificate to request update for in genm of type rootCaCert" },
{ "newwithnew", OPT_NEWWITHNEW, 's',
- "File to save NewWithNew cert received in genp of type rootCaKeyUpdate"},
+ "File to save NewWithNew cert received in genp of type rootCaKeyUpdate" },
{ "newwithold", OPT_NEWWITHOLD, 's',
- "File to save NewWithOld cert received in genp of type rootCaKeyUpdate"},
+ "File to save NewWithOld cert received in genp of type rootCaKeyUpdate" },
{ "oldwithnew", OPT_OLDWITHNEW, 's',
- "File to save OldWithNew cert received in genp of type rootCaKeyUpdate"},
+ "File to save OldWithNew cert received in genp of type rootCaKeyUpdate" },
{ "crlcert", OPT_CRLCERT, 's',
- "certificate to request a CRL for in genm of type crlStatusList"},
+ "certificate to request a CRL for in genm of type crlStatusList" },
{ "oldcrl", OPT_OLDCRL, 's',
- "CRL to request update for in genm of type crlStatusList"},
+ "CRL to request update for in genm of type crlStatusList" },
{ "crlout", OPT_CRLOUT, 's',
- "File to save new CRL received in genp of type 'crls'"},
+ "File to save new CRL received in genp of type 'crls'" },
OPT_SECTION("Client authentication"),
- {"ref", OPT_REF, 's',
- "Reference value to use as senderKID in case no -cert is given"},
- {"secret", OPT_SECRET, 's',
- "Prefer PBM (over signatures) for protecting msgs with given password source"},
- {"cert", OPT_CERT, 's',
- "Client's CMP signer certificate; its public key must match the -key argument"},
- {OPT_MORE_STR, 0, 0,
- "This also used as default reference for subject DN and SANs."},
- {OPT_MORE_STR, 0, 0,
- "Any further certs included are appended to the untrusted certs"},
- {"own_trusted", OPT_OWN_TRUSTED, 's',
- "Optional certs to verify chain building for own CMP signer cert"},
- {"key", OPT_KEY, 's', "CMP signer private key, not used when -secret given"},
- {"keypass", OPT_KEYPASS, 's',
- "Client private key (and cert and old cert) pass phrase source"},
- {"digest", OPT_DIGEST, 's',
- "Digest to use in message protection and POPO signatures. Default \"sha256\""},
- {"mac", OPT_MAC, 's',
- "MAC algorithm to use in PBM-based message protection. Default \"hmac-sha1\""},
- {"extracerts", OPT_EXTRACERTS, 's',
- "Certificates to append in extraCerts field of outgoing messages."},
- {OPT_MORE_STR, 0, 0,
- "This can be used as the default CMP signer cert chain to include"},
- {"unprotected_requests", OPT_UNPROTECTED_REQUESTS, '-',
- "Send request messages without CMP-level protection"},
+ { "ref", OPT_REF, 's',
+ "Reference value to use as senderKID in case no -cert is given" },
+ { "secret", OPT_SECRET, 's',
+ "Prefer PBM (over signatures) for protecting msgs with given password source" },
+ { "cert", OPT_CERT, 's',
+ "Client's CMP signer certificate; its public key must match the -key argument" },
+ { OPT_MORE_STR, 0, 0,
+ "This also used as default reference for subject DN and SANs." },
+ { OPT_MORE_STR, 0, 0,
+ "Any further certs included are appended to the untrusted certs" },
+ { "own_trusted", OPT_OWN_TRUSTED, 's',
+ "Optional certs to verify chain building for own CMP signer cert" },
+ { "key", OPT_KEY, 's', "CMP signer private key, not used when -secret given" },
+ { "keypass", OPT_KEYPASS, 's',
+ "Client private key (and cert and old cert) pass phrase source" },
+ { "digest", OPT_DIGEST, 's',
+ "Digest to use in message protection and POPO signatures. Default \"sha256\"" },
+ { "mac", OPT_MAC, 's',
+ "MAC algorithm to use in PBM-based message protection. Default \"hmac-sha1\"" },
+ { "extracerts", OPT_EXTRACERTS, 's',
+ "Certificates to append in extraCerts field of outgoing messages." },
+ { OPT_MORE_STR, 0, 0,
+ "This can be used as the default CMP signer cert chain to include" },
+ { "unprotected_requests", OPT_UNPROTECTED_REQUESTS, '-',
+ "Send request messages without CMP-level protection" },
OPT_SECTION("Credentials format"),
- {"certform", OPT_CERTFORM, 's',
- "Format (PEM or DER) to use when saving a certificate to a file. Default PEM"},
- {"crlform", OPT_CRLFORM, 's',
- "Format (PEM or DER) to use when saving a CRL to a file. Default DER"},
- {"keyform", OPT_KEYFORM, 's',
- "Format of the key input (ENGINE, other values ignored)"},
- {"otherpass", OPT_OTHERPASS, 's',
- "Pass phrase source potentially needed for loading certificates of others"},
+ { "certform", OPT_CERTFORM, 's',
+ "Format (PEM or DER) to use when saving a certificate to a file. Default PEM" },
+ { "crlform", OPT_CRLFORM, 's',
+ "Format (PEM or DER) to use when saving a CRL to a file. Default DER" },
+ { "keyform", OPT_KEYFORM, 's',
+ "Format of the key input (ENGINE, other values ignored)" },
+ { "otherpass", OPT_OTHERPASS, 's',
+ "Pass phrase source potentially needed for loading certificates of others" },
#ifndef OPENSSL_NO_ENGINE
- {"engine", OPT_ENGINE, 's',
- "Use crypto engine with given identifier, possibly a hardware device."},
- {OPT_MORE_STR, 0, 0,
- "Engines may also be defined in OpenSSL config file engine section."},
+ { "engine", OPT_ENGINE, 's',
+ "Use crypto engine with given identifier, possibly a hardware device." },
+ { OPT_MORE_STR, 0, 0,
+ "Engines may also be defined in OpenSSL config file engine section." },
#endif
OPT_PROV_OPTIONS,
OPT_R_OPTIONS,
OPT_SECTION("TLS connection"),
#if defined(OPENSSL_NO_SOCK) || defined(OPENSSL_NO_HTTP)
- {OPT_MORE_STR, 0, 0,
- "NOTE: -tls_used and all other TLS options not supported due to no-sock/no-http build"},
+ { OPT_MORE_STR, 0, 0,
+ "NOTE: -tls_used and all other TLS options not supported due to no-sock/no-http build" },
#else
- {"tls_used", OPT_TLS_USED, '-',
- "Enable using TLS (also when other TLS options are not set)"},
- {"tls_cert", OPT_TLS_CERT, 's',
- "Client's TLS certificate. May include chain to be provided to TLS server"},
- {"tls_key", OPT_TLS_KEY, 's',
- "Private key for the client's TLS certificate"},
- {"tls_keypass", OPT_TLS_KEYPASS, 's',
- "Pass phrase source for the client's private TLS key (and TLS cert)"},
- {"tls_extra", OPT_TLS_EXTRA, 's',
- "Extra certificates to provide to TLS server during TLS handshake"},
- {"tls_trusted", OPT_TLS_TRUSTED, 's',
- "Trusted certificates to use for verifying the TLS server certificate;"},
- {OPT_MORE_STR, 0, 0, "this implies hostname validation"},
- {"tls_host", OPT_TLS_HOST, 's',
- "Address to be checked (rather than -server) during TLS hostname validation"},
+ { "tls_used", OPT_TLS_USED, '-',
+ "Enable using TLS (also when other TLS options are not set)" },
+ { "tls_cert", OPT_TLS_CERT, 's',
+ "Client's TLS certificate. May include chain to be provided to TLS server" },
+ { "tls_key", OPT_TLS_KEY, 's',
+ "Private key for the client's TLS certificate" },
+ { "tls_keypass", OPT_TLS_KEYPASS, 's',
+ "Pass phrase source for the client's private TLS key (and TLS cert)" },
+ { "tls_extra", OPT_TLS_EXTRA, 's',
+ "Extra certificates to provide to TLS server during TLS handshake" },
+ { "tls_trusted", OPT_TLS_TRUSTED, 's',
+ "Trusted certificates to use for verifying the TLS server certificate;" },
+ { OPT_MORE_STR, 0, 0, "this implies hostname validation" },
+ { "tls_host", OPT_TLS_HOST, 's',
+ "Address to be checked (rather than -server) during TLS hostname validation" },
#endif
OPT_SECTION("Client-side debugging"),
- {"batch", OPT_BATCH, '-',
- "Do not interactively prompt for input when a password is required etc."},
- {"repeat", OPT_REPEAT, 'p',
- "Invoke the transaction the given positive number of times. Default 1"},
- {"reqin", OPT_REQIN, 's',
- "Take sequence of CMP requests to send to server from file(s)"},
- {"reqin_new_tid", OPT_REQIN_NEW_TID, '-',
- "Use fresh transactionID for CMP requests read from -reqin"},
- {"reqout", OPT_REQOUT, 's',
- "Save sequence of CMP requests created by the client to file(s)"},
- {"reqout_only", OPT_REQOUT_ONLY, 's',
- "Save first CMP request created by the client to file and exit"},
- {"rspin", OPT_RSPIN, 's',
- "Process sequence of CMP responses provided in file(s), skipping server"},
- {"rspout", OPT_RSPOUT, 's',
- "Save sequence of actually used CMP responses to file(s)"},
+ { "batch", OPT_BATCH, '-',
+ "Do not interactively prompt for input when a password is required etc." },
+ { "repeat", OPT_REPEAT, 'p',
+ "Invoke the transaction the given positive number of times. Default 1" },
+ { "reqin", OPT_REQIN, 's',
+ "Take sequence of CMP requests to send to server from file(s)" },
+ { "reqin_new_tid", OPT_REQIN_NEW_TID, '-',
+ "Use fresh transactionID for CMP requests read from -reqin" },
+ { "reqout", OPT_REQOUT, 's',
+ "Save sequence of CMP requests created by the client to file(s)" },
+ { "reqout_only", OPT_REQOUT_ONLY, 's',
+ "Save first CMP request created by the client to file and exit" },
+ { "rspin", OPT_RSPIN, 's',
+ "Process sequence of CMP responses provided in file(s), skipping server" },
+ { "rspout", OPT_RSPOUT, 's',
+ "Save sequence of actually used CMP responses to file(s)" },
- {"use_mock_srv", OPT_USE_MOCK_SRV, '-',
- "Use internal mock server at API level, bypassing socket-based HTTP"},
+ { "use_mock_srv", OPT_USE_MOCK_SRV, '-',
+ "Use internal mock server at API level, bypassing socket-based HTTP" },
OPT_SECTION("Mock server"),
#if defined(OPENSSL_NO_SOCK) || defined(OPENSSL_NO_HTTP)
- {OPT_MORE_STR, 0, 0,
- "NOTE: -port and -max_msgs not supported due to no-sock/no-http build"},
+ { OPT_MORE_STR, 0, 0,
+ "NOTE: -port and -max_msgs not supported due to no-sock/no-http build" },
#else
- {"port", OPT_PORT, 's',
- "Act as HTTP-based mock server listening on given port"},
- {"max_msgs", OPT_MAX_MSGS, 'N',
- "max number of messages handled by HTTP mock server. Default: 0 = unlimited"},
+ { "port", OPT_PORT, 's',
+ "Act as HTTP-based mock server listening on given port" },
+ { "max_msgs", OPT_MAX_MSGS, 'N',
+ "max number of messages handled by HTTP mock server. Default: 0 = unlimited" },
#endif
- {"srv_ref", OPT_SRV_REF, 's',
- "Reference value to use as senderKID of server in case no -srv_cert is given"},
- {"srv_secret", OPT_SRV_SECRET, 's',
- "Password source for server authentication with a pre-shared key (secret)"},
- {"srv_cert", OPT_SRV_CERT, 's', "Certificate of the server"},
- {"srv_key", OPT_SRV_KEY, 's',
- "Private key used by the server for signing messages"},
- {"srv_keypass", OPT_SRV_KEYPASS, 's',
- "Server private key (and cert) pass phrase source"},
+ { "srv_ref", OPT_SRV_REF, 's',
+ "Reference value to use as senderKID of server in case no -srv_cert is given" },
+ { "srv_secret", OPT_SRV_SECRET, 's',
+ "Password source for server authentication with a pre-shared key (secret)" },
+ { "srv_cert", OPT_SRV_CERT, 's', "Certificate of the server" },
+ { "srv_key", OPT_SRV_KEY, 's',
+ "Private key used by the server for signing messages" },
+ { "srv_keypass", OPT_SRV_KEYPASS, 's',
+ "Server private key (and cert) pass phrase source" },
- {"srv_trusted", OPT_SRV_TRUSTED, 's',
- "Trusted certificates for client authentication"},
- {"srv_untrusted", OPT_SRV_UNTRUSTED, 's',
- "Intermediate certs that may be useful for verifying CMP protection"},
- {"ref_cert", OPT_RSP_CERT, 's',
- "Certificate to be expected for rr and any oldCertID in kur messages"},
- {"rsp_cert", OPT_RSP_CERT, 's',
- "Certificate to be returned as mock enrollment result"},
- {"rsp_key", OPT_RSP_KEY, 's',
- "Private key for the certificate to be returned as mock enrollment result"},
- {OPT_MORE_STR, 0, 0,
- "Key to be returned for central key pair generation"},
- {"rsp_keypass", OPT_RSP_KEYPASS, 's',
- "Response private key (and cert) pass phrase source"},
- {"rsp_crl", OPT_RSP_CRL, 's',
- "CRL to be returned in genp of type crls"},
- {"rsp_extracerts", OPT_RSP_EXTRACERTS, 's',
- "Extra certificates to be included in mock certification responses"},
- {"rsp_capubs", OPT_RSP_CAPUBS, 's',
- "CA certificates to be included in mock ip response"},
- {"rsp_newwithnew", OPT_RSP_NEWWITHNEW, 's',
- "New root CA certificate to include in genp of type rootCaKeyUpdate"},
- {"rsp_newwithold", OPT_RSP_NEWWITHOLD, 's',
- "NewWithOld transition cert to include in genp of type rootCaKeyUpdate"},
- {"rsp_oldwithnew", OPT_RSP_OLDWITHNEW, 's',
- "OldWithNew transition cert to include in genp of type rootCaKeyUpdate"},
- {"poll_count", OPT_POLL_COUNT, 'N',
- "Number of times the client must poll before receiving a certificate"},
- {"check_after", OPT_CHECK_AFTER, 'N',
- "The check_after value (time to wait) to include in poll response"},
- {"grant_implicitconf", OPT_GRANT_IMPLICITCONF, '-',
- "Grant implicit confirmation of newly enrolled certificate"},
+ { "srv_trusted", OPT_SRV_TRUSTED, 's',
+ "Trusted certificates for client authentication" },
+ { "srv_untrusted", OPT_SRV_UNTRUSTED, 's',
+ "Intermediate certs that may be useful for verifying CMP protection" },
+ { "ref_cert", OPT_RSP_CERT, 's',
+ "Certificate to be expected for rr and any oldCertID in kur messages" },
+ { "rsp_cert", OPT_RSP_CERT, 's',
+ "Certificate to be returned as mock enrollment result" },
+ { "rsp_key", OPT_RSP_KEY, 's',
+ "Private key for the certificate to be returned as mock enrollment result" },
+ { OPT_MORE_STR, 0, 0,
+ "Key to be returned for central key pair generation" },
+ { "rsp_keypass", OPT_RSP_KEYPASS, 's',
+ "Response private key (and cert) pass phrase source" },
+ { "rsp_crl", OPT_RSP_CRL, 's',
+ "CRL to be returned in genp of type crls" },
+ { "rsp_extracerts", OPT_RSP_EXTRACERTS, 's',
+ "Extra certificates to be included in mock certification responses" },
+ { "rsp_capubs", OPT_RSP_CAPUBS, 's',
+ "CA certificates to be included in mock ip response" },
+ { "rsp_newwithnew", OPT_RSP_NEWWITHNEW, 's',
+ "New root CA certificate to include in genp of type rootCaKeyUpdate" },
+ { "rsp_newwithold", OPT_RSP_NEWWITHOLD, 's',
+ "NewWithOld transition cert to include in genp of type rootCaKeyUpdate" },
+ { "rsp_oldwithnew", OPT_RSP_OLDWITHNEW, 's',
+ "OldWithNew transition cert to include in genp of type rootCaKeyUpdate" },
+ { "poll_count", OPT_POLL_COUNT, 'N',
+ "Number of times the client must poll before receiving a certificate" },
+ { "check_after", OPT_CHECK_AFTER, 'N',
+ "The check_after value (time to wait) to include in poll response" },
+ { "grant_implicitconf", OPT_GRANT_IMPLICITCONF, '-',
+ "Grant implicit confirmation of newly enrolled certificate" },
- {"pkistatus", OPT_PKISTATUS, 'N',
- "PKIStatus to be included in server response. Possible values: 0..6"},
- {"failure", OPT_FAILURE, 'N',
- "A single failure info bit number to include in server response, 0..26"},
- {"failurebits", OPT_FAILUREBITS, 'N',
- "Number representing failure bits to include in server response, 0..2^27 - 1"},
- {"statusstring", OPT_STATUSSTRING, 's',
- "Status string to be included in server response"},
- {"send_error", OPT_SEND_ERROR, '-',
- "Force server to reply with error message"},
- {"send_unprotected", OPT_SEND_UNPROTECTED, '-',
- "Send response messages without CMP-level protection"},
- {"send_unprot_err", OPT_SEND_UNPROT_ERR, '-',
- "In case of negative responses, server shall send unprotected error messages,"},
- {OPT_MORE_STR, 0, 0,
- "certificate responses (ip/cp/kup), and revocation responses (rp)."},
- {OPT_MORE_STR, 0, 0,
- "WARNING: This setting leads to behavior violating RFC 4210"},
- {"accept_unprotected", OPT_ACCEPT_UNPROTECTED, '-',
- "Accept missing or invalid protection of requests"},
- {"accept_unprot_err", OPT_ACCEPT_UNPROT_ERR, '-',
- "Accept unprotected error messages from client"},
- {"accept_raverified", OPT_ACCEPT_RAVERIFIED, '-',
- "Accept RAVERIFIED as proof-of-possession (POPO)"},
+ { "pkistatus", OPT_PKISTATUS, 'N',
+ "PKIStatus to be included in server response. Possible values: 0..6" },
+ { "failure", OPT_FAILURE, 'N',
+ "A single failure info bit number to include in server response, 0..26" },
+ { "failurebits", OPT_FAILUREBITS, 'N',
+ "Number representing failure bits to include in server response, 0..2^27 - 1" },
+ { "statusstring", OPT_STATUSSTRING, 's',
+ "Status string to be included in server response" },
+ { "send_error", OPT_SEND_ERROR, '-',
+ "Force server to reply with error message" },
+ { "send_unprotected", OPT_SEND_UNPROTECTED, '-',
+ "Send response messages without CMP-level protection" },
+ { "send_unprot_err", OPT_SEND_UNPROT_ERR, '-',
+ "In case of negative responses, server shall send unprotected error messages," },
+ { OPT_MORE_STR, 0, 0,
+ "certificate responses (ip/cp/kup), and revocation responses (rp)." },
+ { OPT_MORE_STR, 0, 0,
+ "WARNING: This setting leads to behavior violating RFC 9810" },
+ { "accept_unprotected", OPT_ACCEPT_UNPROTECTED, '-',
+ "Accept missing or invalid protection of requests" },
+ { "accept_unprot_err", OPT_ACCEPT_UNPROT_ERR, '-',
+ "Accept unprotected error messages from client" },
+ { "accept_raverified", OPT_ACCEPT_RAVERIFIED, '-',
+ "Accept RAVERIFIED as proof-of-possession (POPO)" },
OPT_V_OPTIONS,
- {NULL}
+ { NULL }
};
typedef union {
@@ -641,118 +713,117 @@ typedef union {
long *num_long;
} varref;
static varref cmp_vars[] = { /* must be in same order as enumerated above! */
- {&opt_config}, {&opt_section}, {(char **)&opt_verbosity},
+ { &opt_config }, { &opt_section }, { (char **)&opt_verbosity },
- {&opt_cmd_s}, {&opt_infotype_s}, {&opt_profile}, {&opt_geninfo},
- {&opt_template}, {&opt_keyspec},
+ { &opt_cmd_s }, { &opt_infotype_s }, { &opt_profile }, { &opt_geninfo },
+ { &opt_template }, { &opt_keyspec },
- {&opt_newkey}, {&opt_newkeypass}, {(char **)&opt_centralkeygen},
- {&opt_newkeyout}, {&opt_subject}, {(char **)&opt_days}, {&opt_reqexts},
- {&opt_sans}, {(char **)&opt_san_nodefault},
- {&opt_policies}, {&opt_policy_oids}, {(char **)&opt_policy_oids_critical},
- {(char **)&opt_popo}, {&opt_csr},
- {&opt_out_trusted},
- {(char **)&opt_implicit_confirm}, {(char **)&opt_disable_confirm},
- {&opt_certout}, {&opt_chainout},
+ { &opt_newkey }, { &opt_newkeypass }, { (char **)&opt_centralkeygen },
+ { &opt_newkeyout }, { &opt_subject }, { (char **)&opt_days }, { &opt_reqexts },
+ { &opt_sans }, { (char **)&opt_san_nodefault },
+ { &opt_policies }, { &opt_policy_oids }, { (char **)&opt_policy_oids_critical },
+ { (char **)&opt_popo }, { &opt_csr },
+ { &opt_out_trusted },
+ { (char **)&opt_implicit_confirm }, { (char **)&opt_disable_confirm },
+ { &opt_certout }, { &opt_chainout },
- {&opt_oldcert}, {&opt_issuer}, {&opt_serial}, {(char **)&opt_revreason},
+ { &opt_oldcert }, { &opt_issuer }, { &opt_serial }, { (char **)&opt_revreason },
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
- {&opt_server}, {&opt_proxy}, {&opt_no_proxy},
+ { &opt_server }, { &opt_proxy }, { &opt_no_proxy },
#endif
- {&opt_recipient}, {&opt_path}, {(char **)&opt_keep_alive},
- {(char **)&opt_msg_timeout}, {(char **)&opt_total_timeout},
+ { &opt_recipient }, { &opt_path }, { (char **)&opt_keep_alive },
+ { (char **)&opt_msg_timeout }, { (char **)&opt_total_timeout },
- {&opt_trusted}, {&opt_untrusted}, {&opt_srvcert},
- {&opt_expect_sender},
- {(char **)&opt_ignore_keyusage}, {(char **)&opt_unprotected_errors},
- {(char **)&opt_no_cache_extracerts},
- {&opt_srvcertout}, {&opt_extracertsout}, {&opt_cacertsout},
- {&opt_oldwithold}, {&opt_newwithnew}, {&opt_newwithold}, {&opt_oldwithnew},
- {&opt_crlcert}, {&opt_oldcrl}, {&opt_crlout},
+ { &opt_trusted }, { &opt_untrusted }, { &opt_srvcert },
+ { &opt_expect_sender },
+ { (char **)&opt_ignore_keyusage }, { (char **)&opt_unprotected_errors },
+ { (char **)&opt_no_cache_extracerts },
+ { &opt_srvcertout }, { &opt_extracertsout }, { &opt_cacertsout },
+ { &opt_oldwithold }, { &opt_newwithnew }, { &opt_newwithold }, { &opt_oldwithnew },
+ { &opt_crlcert }, { &opt_oldcrl }, { &opt_crlout },
- {&opt_ref}, {&opt_secret},
- {&opt_cert}, {&opt_own_trusted}, {&opt_key}, {&opt_keypass},
- {&opt_digest}, {&opt_mac}, {&opt_extracerts},
- {(char **)&opt_unprotected_requests},
+ { &opt_ref }, { &opt_secret },
+ { &opt_cert }, { &opt_own_trusted }, { &opt_key }, { &opt_keypass },
+ { &opt_digest }, { &opt_mac }, { &opt_extracerts },
+ { (char **)&opt_unprotected_requests },
- {&opt_certform_s}, {&opt_crlform_s}, {&opt_keyform_s},
- {&opt_otherpass},
+ { &opt_certform_s }, { &opt_crlform_s }, { &opt_keyform_s },
+ { &opt_otherpass },
#ifndef OPENSSL_NO_ENGINE
- {&opt_engine},
+ { &opt_engine },
#endif
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
- {(char **)&opt_tls_used}, {&opt_tls_cert}, {&opt_tls_key},
- {&opt_tls_keypass},
- {&opt_tls_extra}, {&opt_tls_trusted}, {&opt_tls_host},
+ { (char **)&opt_tls_used }, { &opt_tls_cert }, { &opt_tls_key },
+ { &opt_tls_keypass },
+ { &opt_tls_extra }, { &opt_tls_trusted }, { &opt_tls_host },
#endif
- {(char **)&opt_batch}, {(char **)&opt_repeat},
- {&opt_reqin}, {(char **)&opt_reqin_new_tid},
- {&opt_reqout}, {&opt_reqout_only}, {&opt_rspin}, {&opt_rspout},
+ { (char **)&opt_batch }, { (char **)&opt_repeat },
+ { &opt_reqin }, { (char **)&opt_reqin_new_tid },
+ { &opt_reqout }, { &opt_reqout_only }, { &opt_rspin }, { &opt_rspout },
- {(char **)&opt_use_mock_srv},
+ { (char **)&opt_use_mock_srv },
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
- {&opt_port}, {(char **)&opt_max_msgs},
+ { &opt_port }, { (char **)&opt_max_msgs },
#endif
- {&opt_srv_ref}, {&opt_srv_secret},
- {&opt_srv_cert}, {&opt_srv_key}, {&opt_srv_keypass},
- {&opt_srv_trusted}, {&opt_srv_untrusted},
- {&opt_ref_cert}, {&opt_rsp_cert}, {&opt_rsp_key}, {&opt_rsp_keypass},
- {&opt_rsp_crl}, {&opt_rsp_extracerts}, {&opt_rsp_capubs},
- {&opt_rsp_newwithnew}, {&opt_rsp_newwithold}, {&opt_rsp_oldwithnew},
+ { &opt_srv_ref }, { &opt_srv_secret },
+ { &opt_srv_cert }, { &opt_srv_key }, { &opt_srv_keypass },
+ { &opt_srv_trusted }, { &opt_srv_untrusted },
+ { &opt_ref_cert }, { &opt_rsp_cert }, { &opt_rsp_key }, { &opt_rsp_keypass },
+ { &opt_rsp_crl }, { &opt_rsp_extracerts }, { &opt_rsp_capubs },
+ { &opt_rsp_newwithnew }, { &opt_rsp_newwithold }, { &opt_rsp_oldwithnew },
- {(char **)&opt_poll_count}, {(char **)&opt_check_after},
- {(char **)&opt_grant_implicitconf},
- {(char **)&opt_pkistatus}, {(char **)&opt_failure},
- {(char **)&opt_failurebits}, {&opt_statusstring},
- {(char **)&opt_send_error}, {(char **)&opt_send_unprotected},
- {(char **)&opt_send_unprot_err}, {(char **)&opt_accept_unprotected},
- {(char **)&opt_accept_unprot_err}, {(char **)&opt_accept_raverified},
+ { (char **)&opt_poll_count }, { (char **)&opt_check_after },
+ { (char **)&opt_grant_implicitconf },
+ { (char **)&opt_pkistatus }, { (char **)&opt_failure },
+ { (char **)&opt_failurebits }, { &opt_statusstring },
+ { (char **)&opt_send_error }, { (char **)&opt_send_unprotected },
+ { (char **)&opt_send_unprot_err }, { (char **)&opt_accept_unprotected },
+ { (char **)&opt_accept_unprot_err }, { (char **)&opt_accept_raverified },
- {NULL}
+ { NULL }
};
-#define FUNC (strcmp(OPENSSL_FUNC, "(unknown function)") == 0 \
- ? "CMP" : OPENSSL_FUNC)
+#define FUNC (strcmp(OPENSSL_FUNC, "(unknown function)") == 0 \
+ ? "CMP" \
+ : OPENSSL_FUNC)
#define CMP_print(bio, level, prefix, msg, a1, a2, a3) \
- ((void)(level > opt_verbosity ? 0 : \
- (BIO_printf(bio, "%s:%s:%d:CMP %s: " msg "\n", \
- FUNC, OPENSSL_FILE, OPENSSL_LINE, prefix, a1, a2, a3))))
+ ((void)(level > opt_verbosity ? 0 : (BIO_printf(bio, "%s:%s:%d:CMP %s: " msg "\n", FUNC, OPENSSL_FILE, OPENSSL_LINE, prefix, a1, a2, a3))))
#define CMP_DEBUG(m, a1, a2, a3) \
CMP_print(bio_out, OSSL_CMP_LOG_DEBUG, "debug", m, a1, a2, a3)
-#define CMP_debug(msg) CMP_DEBUG(msg"%s%s%s", "", "", "")
-#define CMP_debug1(msg, a1) CMP_DEBUG(msg"%s%s", a1, "", "")
-#define CMP_debug2(msg, a1, a2) CMP_DEBUG(msg"%s", a1, a2, "")
-#define CMP_debug3(msg, a1, a2, a3) CMP_DEBUG(msg, a1, a2, a3)
+#define CMP_debug(msg) CMP_DEBUG(msg "%s%s%s", "", "", "")
+#define CMP_debug1(msg, a1) CMP_DEBUG(msg "%s%s", a1, "", "")
+#define CMP_debug2(msg, a1, a2) CMP_DEBUG(msg "%s", a1, a2, "")
+#define CMP_debug3(msg, a1, a2, a3) CMP_DEBUG(msg, a1, a2, a3)
#define CMP_INFO(msg, a1, a2, a3) \
CMP_print(bio_out, OSSL_CMP_LOG_INFO, "info", msg, a1, a2, a3)
-#define CMP_info(msg) CMP_INFO(msg"%s%s%s", "", "", "")
-#define CMP_info1(msg, a1) CMP_INFO(msg"%s%s", a1, "", "")
-#define CMP_info2(msg, a1, a2) CMP_INFO(msg"%s", a1, a2, "")
-#define CMP_info3(msg, a1, a2, a3) CMP_INFO(msg, a1, a2, a3)
+#define CMP_info(msg) CMP_INFO(msg "%s%s%s", "", "", "")
+#define CMP_info1(msg, a1) CMP_INFO(msg "%s%s", a1, "", "")
+#define CMP_info2(msg, a1, a2) CMP_INFO(msg "%s", a1, a2, "")
+#define CMP_info3(msg, a1, a2, a3) CMP_INFO(msg, a1, a2, a3)
#define CMP_WARN(m, a1, a2, a3) \
CMP_print(bio_out, OSSL_CMP_LOG_WARNING, "warning", m, a1, a2, a3)
-#define CMP_warn(msg) CMP_WARN(msg"%s%s%s", "", "", "")
-#define CMP_warn1(msg, a1) CMP_WARN(msg"%s%s", a1, "", "")
-#define CMP_warn2(msg, a1, a2) CMP_WARN(msg"%s", a1, a2, "")
-#define CMP_warn3(msg, a1, a2, a3) CMP_WARN(msg, a1, a2, a3)
+#define CMP_warn(msg) CMP_WARN(msg "%s%s%s", "", "", "")
+#define CMP_warn1(msg, a1) CMP_WARN(msg "%s%s", a1, "", "")
+#define CMP_warn2(msg, a1, a2) CMP_WARN(msg "%s", a1, a2, "")
+#define CMP_warn3(msg, a1, a2, a3) CMP_WARN(msg, a1, a2, a3)
#define CMP_ERR(msg, a1, a2, a3) \
CMP_print(bio_err, OSSL_CMP_LOG_ERR, "error", msg, a1, a2, a3)
-#define CMP_err(msg) CMP_ERR(msg"%s%s%s", "", "", "")
-#define CMP_err1(msg, a1) CMP_ERR(msg"%s%s", a1, "", "")
-#define CMP_err2(msg, a1, a2) CMP_ERR(msg"%s", a1, a2, "")
-#define CMP_err3(msg, a1, a2, a3) CMP_ERR(msg, a1, a2, a3)
+#define CMP_err(msg) CMP_ERR(msg "%s%s%s", "", "", "")
+#define CMP_err1(msg, a1) CMP_ERR(msg "%s%s", a1, "", "")
+#define CMP_err2(msg, a1, a2) CMP_ERR(msg "%s", a1, a2, "")
+#define CMP_err3(msg, a1, a2, a3) CMP_ERR(msg, a1, a2, a3)
static int print_to_bio_out(const char *func, const char *file, int line,
- OSSL_CMP_severity level, const char *msg)
+ OSSL_CMP_severity level, const char *msg)
{
return OSSL_CMP_print_to_bio(bio_out, func, file, line, level, msg);
}
static int print_to_bio_err(const char *func, const char *file, int line,
- OSSL_CMP_severity level, const char *msg)
+ OSSL_CMP_severity level, const char *msg)
{
return OSSL_CMP_print_to_bio(bio_err, func, file, line, level, msg);
}
@@ -768,7 +839,7 @@ static int set_verbosity(int level)
}
static EVP_PKEY *load_key_pwd(const char *uri, int format,
- const char *pass, ENGINE *eng, const char *desc)
+ const char *pass, ENGINE *eng, const char *desc)
{
char *pass_string = get_passwd(pass, desc);
EVP_PKEY *pkey = load_key(uri, format, 0, pass_string, eng, desc);
@@ -794,12 +865,11 @@ static int truststore_set_host_etc(X509_STORE *ts, const char *host)
/* first clear any hostnames, IP, and email addresses */
if (!X509_VERIFY_PARAM_set1_host(ts_vpm, NULL, 0)
- || !X509_VERIFY_PARAM_set1_ip(ts_vpm, NULL, 0)
- || !X509_VERIFY_PARAM_set1_email(ts_vpm, NULL, 0))
+ || !X509_VERIFY_PARAM_set1_ip(ts_vpm, NULL, 0)
+ || !X509_VERIFY_PARAM_set1_email(ts_vpm, NULL, 0))
return 0;
X509_VERIFY_PARAM_set_hostflags(ts_vpm,
- X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT |
- X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS);
+ X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT | X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS);
return (host != NULL && X509_VERIFY_PARAM_set1_ip_asc(ts_vpm, host))
|| X509_VERIFY_PARAM_set1_host(ts_vpm, host, 0);
}
@@ -860,7 +930,7 @@ static OSSL_CMP_MSG *read_PKIMESSAGE(const char *desc, char **filenames)
* to take the sequence of requests and responses from files.
*/
static OSSL_CMP_MSG *read_write_req_resp(OSSL_CMP_CTX *ctx,
- const OSSL_CMP_MSG *req)
+ const OSSL_CMP_MSG *req)
{
OSSL_CMP_MSG *req_new = NULL;
OSSL_CMP_MSG *res = NULL;
@@ -870,7 +940,7 @@ static OSSL_CMP_MSG *read_write_req_resp(OSSL_CMP_CTX *ctx,
if (opt_reqout_only != NULL) {
if (OSSL_CMP_MSG_write(opt_reqout_only, req) < 0)
CMP_err1("cannot write request PKIMessage to file '%s'",
- opt_reqout_only);
+ opt_reqout_only);
else
reqout_only_done = 1;
return NULL; /* stop at this point, not contacting any server */
@@ -886,7 +956,7 @@ static OSSL_CMP_MSG *read_write_req_resp(OSSL_CMP_CTX *ctx,
* The following workaround unfortunately requires re-protection.
*/
if (opt_reqin_new_tid
- && !OSSL_CMP_MSG_update_transactionID(ctx, req_new))
+ && !OSSL_CMP_MSG_update_transactionID(ctx, req_new))
goto err;
/*
@@ -933,7 +1003,7 @@ static OSSL_CMP_MSG *read_write_req_resp(OSSL_CMP_CTX *ctx,
nonce = OSSL_CMP_HDR_get0_recipNonce(hdr);
tid = OSSL_CMP_HDR_get0_transactionID(hdr);
if (!OSSL_CMP_CTX_set1_senderNonce(ctx, nonce)
- || !OSSL_CMP_CTX_set1_transactionID(ctx, tid)) {
+ || !OSSL_CMP_CTX_set1_transactionID(ctx, tid)) {
OSSL_CMP_MSG_free(res);
res = NULL;
goto err;
@@ -945,21 +1015,21 @@ static OSSL_CMP_MSG *read_write_req_resp(OSSL_CMP_CTX *ctx,
res = NULL;
}
- err:
+err:
OSSL_CMP_MSG_free(req_new);
return res;
}
static int set_name(const char *str,
- int (*set_fn) (OSSL_CMP_CTX *ctx, const X509_NAME *name),
- OSSL_CMP_CTX *ctx, const char *desc)
+ int (*set_fn)(OSSL_CMP_CTX *ctx, const X509_NAME *name),
+ OSSL_CMP_CTX *ctx, const char *desc)
{
if (str != NULL) {
X509_NAME *n = parse_name(str, MBSTRING_UTF8, 1, desc);
if (n == NULL)
return 0;
- if (!(*set_fn) (ctx, n)) {
+ if (!(*set_fn)(ctx, n)) {
X509_NAME_free(n);
CMP_err("out of memory");
return 0;
@@ -979,8 +1049,8 @@ static int set_gennames(OSSL_CMP_CTX *ctx, char *names, const char *desc)
next = next_item(names);
if (strcmp(names, "critical") == 0) {
(void)OSSL_CMP_CTX_set_option(ctx,
- OSSL_CMP_OPT_SUBJECTALTNAME_CRITICAL,
- 1);
+ OSSL_CMP_OPT_SUBJECTALTNAME_CRITICAL,
+ 1);
continue;
}
@@ -989,9 +1059,9 @@ static int set_gennames(OSSL_CMP_CTX *ctx, char *names, const char *desc)
n = a2i_GENERAL_NAME(NULL, NULL, NULL, GEN_IPADD, names, 0);
if (n == NULL)
n = a2i_GENERAL_NAME(NULL, NULL, NULL,
- strchr(names, '@') != NULL ? GEN_EMAIL :
- strchr(names, ':') != NULL ? GEN_URI : GEN_DNS,
- names, 0);
+ strchr(names, '@') != NULL ? GEN_EMAIL : strchr(names, ':') != NULL ? GEN_URI
+ : GEN_DNS,
+ names, 0);
(void)ERR_pop_to_mark();
if (n == NULL) {
@@ -1018,7 +1088,7 @@ static X509_STORE *load_trusted(char *input, int for_new_cert, const char *desc)
/* copy vpm to store */
if (X509_STORE_set1_param(ts, vpm /* may be NULL */)
- && (for_new_cert || truststore_set_host_etc(ts, NULL)))
+ && (for_new_cert || truststore_set_host_etc(ts, NULL)))
return ts;
BIO_printf(bio_err, "error setting verification parameters for %s\n", desc);
OSSL_CMP_CTX_print_errors(cmp_ctx);
@@ -1028,7 +1098,7 @@ static X509_STORE *load_trusted(char *input, int for_new_cert, const char *desc)
typedef int (*add_X509_fn_t)(void *ctx, const X509 *cert);
static int setup_cert(void *ctx, const char *file, const char *pass,
- const char *desc, add_X509_fn_t set1_fn)
+ const char *desc, add_X509_fn_t set1_fn)
{
X509 *cert;
int ok;
@@ -1044,7 +1114,7 @@ static int setup_cert(void *ctx, const char *file, const char *pass,
typedef int (*add_X509_stack_fn_t)(void *ctx, const STACK_OF(X509) *certs);
static int setup_certs(char *files, const char *desc, void *ctx,
- add_X509_stack_fn_t set1_fn)
+ add_X509_stack_fn_t set1_fn)
{
STACK_OF(X509) *certs;
int ok;
@@ -1100,13 +1170,13 @@ static int transform_opts(void)
}
#ifndef OPENSSL_NO_ENGINE
-# define FORMAT_OPTIONS (OPT_FMT_PEMDER | OPT_FMT_PKCS12 | OPT_FMT_ENGINE)
+#define FORMAT_OPTIONS (OPT_FMT_PEMDER | OPT_FMT_PKCS12 | OPT_FMT_ENGINE)
#else
-# define FORMAT_OPTIONS (OPT_FMT_PEMDER | OPT_FMT_PKCS12)
+#define FORMAT_OPTIONS (OPT_FMT_PEMDER | OPT_FMT_PKCS12)
#endif
if (opt_keyform_s != NULL
- && !opt_format(opt_keyform_s, FORMAT_OPTIONS, &opt_keyform)) {
+ && !opt_format(opt_keyform_s, FORMAT_OPTIONS, &opt_keyform)) {
CMP_err("unknown option given for key loading format");
return 0;
}
@@ -1114,12 +1184,12 @@ static int transform_opts(void)
#undef FORMAT_OPTIONS
if (opt_certform_s != NULL
- && !opt_format(opt_certform_s, OPT_FMT_PEMDER, &opt_certform)) {
+ && !opt_format(opt_certform_s, OPT_FMT_PEMDER, &opt_certform)) {
CMP_err("unknown option given for certificate storing format");
return 0;
}
if (opt_crlform_s != NULL
- && !opt_format(opt_crlform_s, OPT_FMT_PEMDER, &opt_crlform)) {
+ && !opt_format(opt_crlform_s, OPT_FMT_PEMDER, &opt_crlform)) {
CMP_err("unknown option given for CRL storing format");
return 0;
}
@@ -1131,7 +1201,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
{
OSSL_CMP_CTX *ctx; /* extra CMP (client) ctx partly used by server */
OSSL_CMP_SRV_CTX *srv_ctx = ossl_cmp_mock_srv_new(app_get0_libctx(),
- app_get0_propq());
+ app_get0_propq());
if (srv_ctx == NULL)
return NULL;
@@ -1145,7 +1215,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
}
} else {
if (!OSSL_CMP_CTX_set1_referenceValue(ctx, (unsigned char *)opt_srv_ref,
- strlen(opt_srv_ref)))
+ strlen(opt_srv_ref)))
goto err;
}
@@ -1156,7 +1226,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
if (pass_str != NULL) {
cleanse(opt_srv_secret);
res = OSSL_CMP_CTX_set1_secretValue(ctx, (unsigned char *)pass_str,
- strlen(pass_str));
+ strlen(pass_str));
clear_free(pass_str);
if (res == 0)
goto err;
@@ -1169,18 +1239,18 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
}
if (opt_srv_secret == NULL
- && ((opt_srv_cert == NULL) != (opt_srv_key == NULL))) {
+ && ((opt_srv_cert == NULL) != (opt_srv_key == NULL))) {
CMP_err("must give both -srv_cert and -srv_key options or neither");
goto err;
}
if (!setup_cert(ctx, opt_srv_cert, opt_srv_keypass,
- "signer certificate of the mock server",
- (add_X509_fn_t)OSSL_CMP_CTX_set1_cert))
+ "signer certificate of the mock server",
+ (add_X509_fn_t)OSSL_CMP_CTX_set1_cert))
goto err;
if (opt_srv_key != NULL) {
EVP_PKEY *pkey = load_key_pwd(opt_srv_key, opt_keyform,
- opt_srv_keypass,
- engine, "private key for mock server cert");
+ opt_srv_keypass,
+ engine, "private key for mock server cert");
if (pkey == NULL || !OSSL_CMP_CTX_set1_pkey(ctx, pkey)) {
EVP_PKEY_free(pkey);
@@ -1191,8 +1261,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
cleanse(opt_srv_keypass);
if (opt_srv_trusted != NULL) {
- X509_STORE *ts =
- load_trusted(opt_srv_trusted, 0, "certs trusted by mock server");
+ X509_STORE *ts = load_trusted(opt_srv_trusted, 0, "certs trusted by mock server");
if (ts == NULL || !OSSL_CMP_CTX_set0_trusted(ctx, ts)) {
X509_STORE_free(ts);
@@ -1202,26 +1271,26 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
CMP_warn("mock server will not be able to handle signature-protected requests since -srv_trusted is not given");
}
if (!setup_certs(opt_srv_untrusted,
- "untrusted certificates for mock server", ctx,
- (add_X509_stack_fn_t)OSSL_CMP_CTX_set1_untrusted))
+ "untrusted certificates for mock server", ctx,
+ (add_X509_stack_fn_t)OSSL_CMP_CTX_set1_untrusted))
goto err;
if (!setup_cert(srv_ctx, opt_ref_cert, opt_otherpass,
- "reference cert to be expected by the mock server",
- (add_X509_fn_t)ossl_cmp_mock_srv_set1_refCert))
+ "reference cert to be expected by the mock server",
+ (add_X509_fn_t)ossl_cmp_mock_srv_set1_refCert))
goto err;
if (opt_rsp_cert == NULL) {
CMP_warn("no -rsp_cert given for mock server");
} else {
if (!setup_cert(srv_ctx, opt_rsp_cert, opt_rsp_keypass,
- "cert the mock server returns on certificate requests",
- (add_X509_fn_t)ossl_cmp_mock_srv_set1_certOut))
+ "cert the mock server returns on certificate requests",
+ (add_X509_fn_t)ossl_cmp_mock_srv_set1_certOut))
goto err;
}
if (opt_rsp_key != NULL) {
EVP_PKEY *pkey = load_key_pwd(opt_rsp_key, opt_keyform,
- opt_rsp_keypass, engine,
- "private key for enrollment cert");
+ opt_rsp_keypass, engine,
+ "private key for enrollment cert");
if (pkey == NULL
|| !ossl_cmp_mock_srv_set1_keyOut(srv_ctx, pkey)) {
@@ -1233,24 +1302,24 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
cleanse(opt_rsp_keypass);
if (!setup_mock_crlout(srv_ctx, opt_rsp_crl,
- "CRL to be returned by the mock server"))
+ "CRL to be returned by the mock server"))
goto err;
if (!setup_certs(opt_rsp_extracerts,
- "CMP extra certificates for mock server", srv_ctx,
- (add_X509_stack_fn_t)ossl_cmp_mock_srv_set1_chainOut))
+ "CMP extra certificates for mock server", srv_ctx,
+ (add_X509_stack_fn_t)ossl_cmp_mock_srv_set1_chainOut))
goto err;
if (!setup_certs(opt_rsp_capubs, "caPubs for mock server", srv_ctx,
- (add_X509_stack_fn_t)ossl_cmp_mock_srv_set1_caPubsOut))
+ (add_X509_stack_fn_t)ossl_cmp_mock_srv_set1_caPubsOut))
goto err;
if (!setup_cert(srv_ctx, opt_rsp_newwithnew, opt_otherpass,
- "NewWithNew cert the mock server returns in rootCaKeyUpdate",
- (add_X509_fn_t)ossl_cmp_mock_srv_set1_newWithNew)
+ "NewWithNew cert the mock server returns in rootCaKeyUpdate",
+ (add_X509_fn_t)ossl_cmp_mock_srv_set1_newWithNew)
|| !setup_cert(srv_ctx, opt_rsp_newwithold, opt_otherpass,
- "NewWithOld cert the mock server returns in rootCaKeyUpdate",
- (add_X509_fn_t)ossl_cmp_mock_srv_set1_newWithOld)
+ "NewWithOld cert the mock server returns in rootCaKeyUpdate",
+ (add_X509_fn_t)ossl_cmp_mock_srv_set1_newWithOld)
|| !setup_cert(srv_ctx, opt_rsp_oldwithnew, opt_otherpass,
- "OldWithNew cert the mock server returns in rootCaKeyUpdate",
- (add_X509_fn_t)ossl_cmp_mock_srv_set1_oldWithNew))
+ "OldWithNew cert the mock server returns in rootCaKeyUpdate",
+ (add_X509_fn_t)ossl_cmp_mock_srv_set1_oldWithNew))
goto err;
(void)ossl_cmp_mock_srv_set_pollCount(srv_ctx, opt_poll_count);
(void)ossl_cmp_mock_srv_set_checkAfterTime(srv_ctx, opt_check_after);
@@ -1260,7 +1329,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
if (opt_failure != INT_MIN) { /* option has been set explicitly */
if (opt_failure < 0 || OSSL_CMP_PKIFAILUREINFO_MAX < opt_failure) {
CMP_err1("-failure out of range, should be >= 0 and <= %d",
- OSSL_CMP_PKIFAILUREINFO_MAX);
+ OSSL_CMP_PKIFAILUREINFO_MAX);
goto err;
}
if (opt_failurebits != 0)
@@ -1273,7 +1342,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
goto err;
}
if (!ossl_cmp_mock_srv_set_statusInfo(srv_ctx, opt_pkistatus,
- opt_failurebits, opt_statusstring))
+ opt_failurebits, opt_statusstring))
goto err;
if (opt_send_error)
@@ -1292,7 +1361,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
return srv_ctx;
- err:
+err:
ossl_cmp_mock_srv_free(srv_ctx);
return NULL;
}
@@ -1304,7 +1373,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(ENGINE *engine)
static int setup_verification_ctx(OSSL_CMP_CTX *ctx)
{
if (!setup_certs(opt_untrusted, "untrusted certificates", ctx,
- (add_X509_stack_fn_t)OSSL_CMP_CTX_set1_untrusted))
+ (add_X509_stack_fn_t)OSSL_CMP_CTX_set1_untrusted))
return 0;
if (opt_srvcert != NULL || opt_trusted != NULL) {
@@ -1318,8 +1387,8 @@ static int setup_verification_ctx(OSSL_CMP_CTX *ctx)
opt_recipient = NULL;
}
if (!setup_cert(ctx, opt_srvcert, opt_otherpass,
- "directly trusted CMP server certificate",
- (add_X509_fn_t)OSSL_CMP_CTX_set1_srvCert))
+ "directly trusted CMP server certificate",
+ (add_X509_fn_t)OSSL_CMP_CTX_set1_srvCert))
return 0;
}
if (opt_trusted != NULL) {
@@ -1343,9 +1412,8 @@ static int setup_verification_ctx(OSSL_CMP_CTX *ctx)
if (opt_out_trusted != NULL) { /* for use in OSSL_CMP_certConf_cb() */
X509_VERIFY_PARAM *out_vpm = NULL;
- X509_STORE *out_trusted =
- load_trusted(opt_out_trusted, 1,
- "trusted certs for verifying newly enrolled cert");
+ X509_STORE *out_trusted = load_trusted(opt_out_trusted, 1,
+ "trusted certs for verifying newly enrolled cert");
if (out_trusted == NULL)
return 0;
@@ -1371,7 +1439,7 @@ static int setup_verification_ctx(OSSL_CMP_CTX *ctx)
* Returns pointer on success, NULL on error
*/
static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host,
- ENGINE *engine)
+ ENGINE *engine)
{
STACK_OF(X509) *untrusted = OSSL_CMP_CTX_get0_untrusted(ctx);
EVP_PKEY *pkey = NULL;
@@ -1399,8 +1467,8 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host,
int ok;
if (!load_cert_certs(opt_tls_cert, &cert, &certs, 0, opt_tls_keypass,
- "TLS client certificate (optionally with chain)",
- vpm))
+ "TLS client certificate (optionally with chain)",
+ vpm))
/* need opt_tls_keypass if opt_tls_cert is encrypted PKCS#12 file */
goto err;
@@ -1413,7 +1481,7 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host,
*/
if (!ok || !SSL_CTX_set0_chain(ssl_ctx, certs)) {
CMP_err1("unable to use client TLS certificate file '%s'",
- opt_tls_cert);
+ opt_tls_cert);
OSSL_STACK_OF_X509_free(certs);
goto err;
}
@@ -1434,15 +1502,14 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host,
bak_flags = X509_VERIFY_PARAM_get_flags(tls_vpm);
/* disable any cert status/revocation checking etc. */
X509_VERIFY_PARAM_clear_flags(tls_vpm,
- ~(X509_V_FLAG_USE_CHECK_TIME
- | X509_V_FLAG_NO_CHECK_TIME
- | X509_V_FLAG_PARTIAL_CHAIN
- | X509_V_FLAG_POLICY_CHECK));
+ ~(X509_V_FLAG_USE_CHECK_TIME
+ | X509_V_FLAG_NO_CHECK_TIME
+ | X509_V_FLAG_PARTIAL_CHAIN
+ | X509_V_FLAG_POLICY_CHECK));
}
CMP_debug("trying to build cert chain for own TLS cert");
if (SSL_CTX_build_cert_chain(ssl_ctx,
- SSL_BUILD_CHAIN_FLAG_UNTRUSTED |
- SSL_BUILD_CHAIN_FLAG_NO_ROOT)) {
+ SSL_BUILD_CHAIN_FLAG_UNTRUSTED | SSL_BUILD_CHAIN_FLAG_NO_ROOT)) {
CMP_debug("success building cert chain for own TLS cert");
} else {
OSSL_CMP_CTX_print_errors(ctx);
@@ -1455,9 +1522,9 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host,
/* If present we append to the list also the certs from opt_tls_extra */
if (opt_tls_extra != NULL) {
STACK_OF(X509) *tls_extra = load_certs_multifile(opt_tls_extra,
- opt_otherpass,
- "extra certificates for TLS",
- vpm);
+ opt_otherpass,
+ "extra certificates for TLS",
+ vpm);
int res = 1;
if (tls_extra == NULL)
@@ -1477,7 +1544,7 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host,
}
pkey = load_key_pwd(opt_tls_key, opt_keyform, opt_tls_keypass,
- engine, "TLS client private key");
+ engine, "TLS client private key");
cleanse(opt_tls_keypass);
if (pkey == NULL)
goto err;
@@ -1487,9 +1554,9 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host,
* because it gives poor and sometimes misleading diagnostics
*/
if (!X509_check_private_key(SSL_CTX_get0_certificate(ssl_ctx),
- pkey)) {
+ pkey)) {
CMP_err2("TLS private key '%s' does not match the TLS certificate '%s'\n",
- opt_tls_key, opt_tls_cert);
+ opt_tls_key, opt_tls_cert);
EVP_PKEY_free(pkey);
pkey = NULL; /* otherwise, for some reason double free! */
goto err;
@@ -1511,11 +1578,11 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host,
* the expected hostname would mislead the check.
*/
if (!truststore_set_host_etc(trust_store,
- opt_tls_host != NULL ? opt_tls_host : host))
+ opt_tls_host != NULL ? opt_tls_host : host))
goto err;
}
return ssl_ctx;
- err:
+err:
SSL_CTX_free(ssl_ctx);
return NULL;
}
@@ -1549,8 +1616,8 @@ static int setup_protection_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
if (pass_string != NULL) {
cleanse(opt_secret);
res = OSSL_CMP_CTX_set1_secretValue(ctx,
- (unsigned char *)pass_string,
- strlen(pass_string));
+ (unsigned char *)pass_string,
+ strlen(pass_string));
clear_free(pass_string);
if (res == 0)
return 0;
@@ -1559,13 +1626,13 @@ static int setup_protection_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
CMP_warn("-cert and -key not used for protection since -secret is given");
}
if (opt_ref != NULL
- && !OSSL_CMP_CTX_set1_referenceValue(ctx, (unsigned char *)opt_ref,
- strlen(opt_ref)))
+ && !OSSL_CMP_CTX_set1_referenceValue(ctx, (unsigned char *)opt_ref,
+ strlen(opt_ref)))
return 0;
if (opt_key != NULL) {
EVP_PKEY *pkey = load_key_pwd(opt_key, opt_keyform, opt_keypass, engine,
- "private key for CMP client certificate");
+ "private key for CMP client certificate");
if (pkey == NULL || !OSSL_CMP_CTX_set1_pkey(ctx, pkey)) {
EVP_PKEY_free(pkey);
@@ -1583,8 +1650,8 @@ static int setup_protection_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
int ok;
if (!load_cert_certs(opt_cert, &cert, &certs, 0, opt_keypass,
- "CMP client certificate (optionally with chain)",
- vpm))
+ "CMP client certificate (optionally with chain)",
+ vpm))
/* opt_keypass is needed if opt_cert is an encrypted PKCS#12 file */
return 0;
ok = OSSL_CMP_CTX_set1_cert(ctx, cert);
@@ -1594,7 +1661,7 @@ static int setup_protection_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
} else {
if (opt_own_trusted != NULL) {
own_trusted = load_trusted(opt_own_trusted, 0,
- "trusted certs for verifying own CMP signer cert");
+ "trusted certs for verifying own CMP signer cert");
ok = own_trusted != NULL;
}
ok = ok && OSSL_CMP_CTX_build_cert_chain(ctx, own_trusted, certs);
@@ -1608,7 +1675,7 @@ static int setup_protection_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
}
if (!setup_certs(opt_extracerts, "extra certificates for CMP", ctx,
- (add_X509_stack_fn_t)OSSL_CMP_CTX_set1_extraCertsOut))
+ (add_X509_stack_fn_t)OSSL_CMP_CTX_set1_extraCertsOut))
return 0;
cleanse(opt_otherpass);
@@ -1660,25 +1727,25 @@ static int set_fallback_pubkey(OSSL_CMP_CTX *ctx)
if (req == NULL) {
CMP_err1("failed to load ir/cr/kur file '%s' attempting to get fallback public key",
- file);
+ file);
return 0;
}
if ((pubkey = OSSL_CMP_MSG_get0_certreq_publickey(req)) == NULL
|| (pkey = X509_PUBKEY_get0(pubkey)) == NULL) {
CMP_err1("failed to get fallback public key from ir/cr/kur file '%s'",
- file);
+ file);
goto err;
}
pkey1 = EVP_PKEY_dup(pkey);
if (pkey == NULL || !OSSL_CMP_CTX_set0_newPkey(ctx, 0 /* priv */, pkey1)) {
EVP_PKEY_free(pkey1);
CMP_err1("failed to get fallback public key obtained from ir/cr/kur file '%s'",
- file);
+ file);
goto err;
}
res = 1;
- err:
+err:
OSSL_CMP_MSG_free(req);
return res;
}
@@ -1695,8 +1762,8 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
X509V3_CTX ext_ctx;
if (opt_subject == NULL
- && opt_csr == NULL && opt_oldcert == NULL && opt_cert == NULL
- && opt_cmd != CMP_RR && opt_cmd != CMP_GENM)
+ && opt_csr == NULL && opt_oldcert == NULL && opt_cert == NULL
+ && opt_cmd != CMP_RR && opt_cmd != CMP_GENM)
CMP_warn("no -subject given; no -csr or -oldcert or -cert available for fallback");
if (!set_name(opt_issuer, OSSL_CMP_CTX_set1_issuer, ctx, "issuer"))
@@ -1728,8 +1795,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
&& opt_popo != OSSL_CRMF_POPO_RAVERIFIED) {
if (opt_csr != NULL) {
CMP_err1("no -newkey option given with private key for POPO, -csr option provides just public key%s",
- opt_key == NULL ? "" :
- ", and -key option superseded by -csr");
+ opt_key == NULL ? "" : ", and -key option superseded by -csr");
if (opt_reqin != NULL)
CMP_info("since -reqin is used, may use -popo -1 or -popo 0 to disable the needless generation of a POPO");
return 0;
@@ -1755,7 +1821,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
return 0;
} else {
CMP_warn1("-subject %s since sender is taken from -ref or -cert",
- msg);
+ msg);
}
}
if (opt_issuer != NULL && opt_cmd != CMP_RR)
@@ -1796,7 +1862,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
}
if (opt_subject != NULL)
CMP_warn2("given -subject '%s' overrides the subject of '%s' for KUR",
- opt_subject, ref_cert != NULL ? ref_cert : opt_csr);
+ opt_subject, ref_cert != NULL ? ref_cert : opt_csr);
}
if (opt_cmd == CMP_RR) {
if (opt_issuer == NULL && opt_serial == NULL) {
@@ -1833,7 +1899,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
}
if (opt_revreason > CRL_REASON_NONE)
(void)OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_REVOCATION_REASON,
- opt_revreason);
+ opt_revreason);
} else {
if (opt_serial != NULL)
CMP_warn("Ignoring -serial for command other than 'rr'");
@@ -1844,7 +1910,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
}
if (opt_recipient == NULL && opt_srvcert == NULL && opt_issuer == NULL
- && opt_oldcert == NULL && opt_cert == NULL)
+ && opt_oldcert == NULL && opt_cert == NULL)
CMP_warn("missing -recipient, -srvcert, -issuer, -oldcert or -cert; recipient for any requests not covered by -reqin will be set to \"NULL-DN\"");
if (opt_cmd == CMP_P10CR || opt_cmd == CMP_RR || opt_cmd == CMP_GENM) {
@@ -1886,15 +1952,15 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
return 0;
}
} else if (opt_reqin != NULL
- && opt_key == NULL && opt_csr == NULL && opt_oldcert == NULL
- && !opt_centralkeygen) {
+ && opt_key == NULL && opt_csr == NULL && opt_oldcert == NULL
+ && !opt_centralkeygen) {
if (!set_fallback_pubkey(ctx))
return 0;
}
if (opt_days > 0
- && !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_VALIDITY_DAYS,
- opt_days)) {
+ && !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_VALIDITY_DAYS,
+ opt_days)) {
CMP_err("could not set requested cert validity period");
return 0;
}
@@ -1923,13 +1989,13 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
if (opt_reqexts != NULL
&& !X509V3_EXT_add_nconf_sk(conf, &ext_ctx, opt_reqexts, &exts)) {
CMP_err1("cannot load certificate request extension section '%s'",
- opt_reqexts);
+ opt_reqexts);
goto exts_err;
}
if (opt_policies != NULL
&& !X509V3_EXT_add_nconf_sk(conf, &ext_ctx, opt_policies, &exts)) {
CMP_err1("cannot load policy cert request extension section '%s'",
- opt_policies);
+ opt_policies);
goto exts_err;
}
OSSL_CMP_CTX_set0_reqExtensions(ctx, exts);
@@ -1948,7 +2014,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
if (opt_sans != NULL)
CMP_warn("-opt_san_nodefault has no effect when -sans is used");
(void)OSSL_CMP_CTX_set_option(ctx,
- OSSL_CMP_OPT_SUBJECTALTNAME_NODEFAULT, 1);
+ OSSL_CMP_OPT_SUBJECTALTNAME_NODEFAULT, 1);
}
if (opt_policy_oids_critical) {
@@ -1990,11 +2056,10 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
CMP_warn("-oldcert option is ignored for 'genm' command");
} else {
if (!setup_cert(ctx, opt_oldcert, opt_keypass,
- /* needed if opt_oldcert is encrypted PKCS12 file */
- opt_cmd == CMP_KUR ? "certificate to be updated" :
- opt_cmd == CMP_RR ? "certificate to be revoked" :
- "reference certificate (oldcert)",
- (add_X509_fn_t)OSSL_CMP_CTX_set1_oldCert))
+ /* needed if opt_oldcert is encrypted PKCS12 file */
+ opt_cmd == CMP_KUR ? "certificate to be updated" : opt_cmd == CMP_RR ? "certificate to be revoked"
+ : "reference certificate (oldcert)",
+ (add_X509_fn_t)OSSL_CMP_CTX_set1_oldCert))
return 0;
}
}
@@ -2002,9 +2067,9 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
return 1;
- oom:
+oom:
CMP_err("out of memory");
- exts_err:
+exts_err:
sk_X509_EXTENSION_pop_free(exts, X509_EXTENSION_free);
X509_REQ_free(csr);
return 0;
@@ -2036,7 +2101,7 @@ static int add_certProfile(OSSL_CMP_CTX *ctx, const char *name)
OSSL_CMP_ITAV_free(itav);
return 0;
- err:
+err:
sk_ASN1_UTF8STRING_pop_free(sk, ASN1_UTF8STRING_free);
return 0;
}
@@ -2079,14 +2144,14 @@ static int handle_opt_geninfo(OSSL_CMP_CTX *ctx)
if (*ptr != '\0') {
if (*ptr != ',') {
CMP_err1("Missing ',' or end of -geninfo arg after int at %.40s",
- ptr);
+ ptr);
goto err;
}
ptr++;
}
if ((aint = ASN1_INTEGER_new()) == NULL
- || !ASN1_INTEGER_set(aint, value))
+ || !ASN1_INTEGER_set(aint, value))
goto oom;
ASN1_TYPE_set(type, V_ASN1_INTEGER, aint);
aint = NULL;
@@ -2098,7 +2163,7 @@ static int handle_opt_geninfo(OSSL_CMP_CTX *ctx)
else
*end++ = '\0';
if ((text = ASN1_UTF8STRING_new()) == NULL
- || !ASN1_STRING_set(text, ptr, -1))
+ || !ASN1_STRING_set(text, ptr, -1))
goto oom;
ptr = end;
ASN1_TYPE_set(type, V_ASN1_UTF8STRING, text);
@@ -2124,9 +2189,9 @@ static int handle_opt_geninfo(OSSL_CMP_CTX *ctx)
} while (*ptr != '\0');
return 1;
- oom:
+oom:
CMP_err("out of memory");
- err:
+err:
ASN1_OBJECT_free(obj);
ASN1_TYPE_free(type);
ASN1_INTEGER_free(aint);
@@ -2174,8 +2239,8 @@ static int setup_client_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
goto set_path;
}
if (!OSSL_HTTP_parse_url(opt_server, &use_ssl, NULL /* user */,
- &host, &port, &portnum,
- &path, NULL /* q */, NULL /* frag */)) {
+ &host, &port, &portnum,
+ &path, NULL /* q */, NULL /* frag */)) {
CMP_err1("cannot parse -server URL: %s", opt_server);
goto err;
}
@@ -2190,21 +2255,21 @@ static int setup_client_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
if (opt_path == NULL)
used_path = path;
if (!OSSL_CMP_CTX_set1_server(ctx, host)
- || !OSSL_CMP_CTX_set_serverPort(ctx, portnum))
+ || !OSSL_CMP_CTX_set_serverPort(ctx, portnum))
goto oom;
if (opt_proxy != NULL && !OSSL_CMP_CTX_set1_proxy(ctx, opt_proxy))
goto oom;
if (opt_no_proxy != NULL && !OSSL_CMP_CTX_set1_no_proxy(ctx, opt_no_proxy))
goto oom;
(void)BIO_snprintf(server_buf, sizeof(server_buf), "http%s://%s:%s/%s",
- opt_tls_used ? "s" : "", host, port,
- *used_path == '/' ? used_path + 1 : used_path);
+ opt_tls_used ? "s" : "", host, port,
+ *used_path == '/' ? used_path + 1 : used_path);
proxy_host = OSSL_HTTP_adapt_proxy(opt_proxy, opt_no_proxy, host, use_ssl);
if (proxy_host != NULL)
(void)BIO_snprintf(proxy_buf, sizeof(proxy_buf), " via %s", proxy_host);
- set_path:
+set_path:
#endif
if (!OSSL_CMP_CTX_set1_serverPath(ctx, used_path))
@@ -2255,19 +2320,19 @@ static int setup_client_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
if (opt_keep_alive != 1)
(void)OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_KEEP_ALIVE,
- opt_keep_alive);
+ opt_keep_alive);
if (opt_total_timeout > 0 && opt_msg_timeout > 0
- && opt_total_timeout < opt_msg_timeout) {
+ && opt_total_timeout < opt_msg_timeout) {
CMP_err2("-total_timeout argument = %d must not be < %d (-msg_timeout)",
- opt_total_timeout, opt_msg_timeout);
+ opt_total_timeout, opt_msg_timeout);
goto err;
}
if (opt_msg_timeout >= 0) /* must do this before setup_ssl_ctx() */
(void)OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_MSG_TIMEOUT,
- opt_msg_timeout);
+ opt_msg_timeout);
if (opt_total_timeout >= 0)
(void)OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_TOTAL_TIMEOUT,
- opt_total_timeout);
+ opt_total_timeout);
if (opt_rspin != NULL) {
rspin_in_use = 1;
@@ -2277,7 +2342,7 @@ static int setup_client_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
if (opt_reqin_new_tid && opt_reqin == NULL)
CMP_warn("-reqin_new_tid is ignored since -reqin is not present");
if (opt_reqin != NULL || opt_reqout != NULL
- || opt_rspin != NULL || opt_rspout != NULL || opt_use_mock_srv)
+ || opt_rspin != NULL || opt_rspout != NULL || opt_use_mock_srv)
(void)OSSL_CMP_CTX_set_transfer_cb(ctx, read_write_req_resp);
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
@@ -2321,8 +2386,8 @@ static int setup_client_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
goto err;
if (!set_name(opt_recipient, OSSL_CMP_CTX_set1_recipient, ctx, "recipient")
- || !set_name(opt_expect_sender, OSSL_CMP_CTX_set1_expected_sender,
- ctx, "expected sender"))
+ || !set_name(opt_expect_sender, OSSL_CMP_CTX_set1_expected_sender,
+ ctx, "expected sender"))
goto err;
if (opt_geninfo != NULL && !handle_opt_geninfo(ctx))
@@ -2333,17 +2398,16 @@ static int setup_client_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
/* not printing earlier, to minimize confusion in case setup fails before */
if (opt_reqout_only == NULL)
CMP_info3("will contact %s%s%s ", server_buf, proxy_buf,
- opt_rspin == NULL ? "" :
- " only if -rspin argument gives too few filenames");
+ opt_rspin == NULL ? "" : " only if -rspin argument gives too few filenames");
ret = 1;
- err:
+err:
OPENSSL_free(host);
OPENSSL_free(port);
OPENSSL_free(path);
return ret;
- oom:
+oom:
CMP_err("out of memory");
goto err;
}
@@ -2356,12 +2420,12 @@ static int setup_client_ctx(OSSL_CMP_CTX *ctx, ENGINE *engine)
static int write_cert(BIO *bio, X509 *cert)
{
if ((opt_certform == FORMAT_PEM && PEM_write_bio_X509(bio, cert))
- || (opt_certform == FORMAT_ASN1 && i2d_X509_bio(bio, cert)))
+ || (opt_certform == FORMAT_ASN1 && i2d_X509_bio(bio, cert)))
return 1;
if (opt_certform != FORMAT_PEM && opt_certform != FORMAT_ASN1)
BIO_printf(bio_err,
- "error: unsupported type '%s' for writing certificates\n",
- opt_certform_s);
+ "error: unsupported type '%s' for writing certificates\n",
+ opt_certform_s);
return 0;
}
@@ -2369,12 +2433,12 @@ static int write_crl(BIO *bio, X509_CRL *crl)
{
if (opt_crlform != FORMAT_PEM && opt_crlform != FORMAT_ASN1) {
BIO_printf(bio_err, "error: unsupported type '%s' for writing CRLs\n",
- opt_crlform_s);
+ opt_crlform_s);
return 0;
}
return opt_crlform == FORMAT_PEM ? PEM_write_bio_X509_CRL(bio, crl)
- : i2d_X509_CRL_bio(bio, crl);
+ : i2d_X509_CRL_bio(bio, crl);
}
/*
@@ -2386,7 +2450,7 @@ static int write_crl(BIO *bio, X509_CRL *crl)
* Returns number of written certificates on success, -1 on error.
*/
static int save_free_certs(STACK_OF(X509) *certs,
- const char *file, const char *desc)
+ const char *file, const char *desc)
{
BIO *bio = NULL;
int i;
@@ -2398,14 +2462,14 @@ static int save_free_certs(STACK_OF(X509) *certs,
goto end;
if (certs != NULL)
CMP_info3("received %d %s certificate(s), saving to file '%s'",
- n, desc, file);
+ n, desc, file);
if (n > 1 && opt_certform != FORMAT_PEM)
CMP_warn("saving more than one certificate in non-PEM format");
if ((bio = BIO_new(BIO_s_file())) == NULL
- || !BIO_write_filename(bio, (char *)file)) {
+ || !BIO_write_filename(bio, (char *)file)) {
CMP_err3("could not open file '%s' for %s %s certificate(s)",
- file, certs == NULL ? "deleting" : "writing", desc);
+ file, certs == NULL ? "deleting" : "writing", desc);
n = -1;
goto end;
}
@@ -2418,14 +2482,14 @@ static int save_free_certs(STACK_OF(X509) *certs,
}
}
- end:
+end:
BIO_free(bio);
OSSL_STACK_OF_X509_free(certs);
return n;
}
static int save_crl(X509_CRL *crl,
- const char *file, const char *desc)
+ const char *file, const char *desc)
{
BIO *bio = NULL;
int res = 0;
@@ -2436,9 +2500,9 @@ static int save_crl(X509_CRL *crl,
CMP_info2("received %s, saving to file '%s'", desc, file);
if ((bio = BIO_new(BIO_s_file())) == NULL
- || !BIO_write_filename(bio, (char *)file)) {
+ || !BIO_write_filename(bio, (char *)file)) {
CMP_err2("could not open file '%s' for writing %s",
- file, desc);
+ file, desc);
goto end;
}
@@ -2448,7 +2512,7 @@ static int save_crl(X509_CRL *crl,
}
res = 1;
- end:
+end:
BIO_free(bio);
return res;
}
@@ -2460,7 +2524,7 @@ static int delete_file(const char *file, const char *desc)
if (unlink(file) != 0 && errno != ENOENT) {
CMP_err2("Failed to delete %s, which should be done to indicate there is no %s",
- file, desc);
+ file, desc);
return 0;
}
return 1;
@@ -2499,13 +2563,13 @@ static int save_template(const char *file, const OSSL_CRMF_CERTTEMPLATE *tmpl)
if (bio == NULL) {
CMP_err1("error saving certTemplate from genp: cannot open file %s",
- file);
+ file);
return 0;
}
if (!ASN1_i2d_bio_of(OSSL_CRMF_CERTTEMPLATE, i2d_OSSL_CRMF_CERTTEMPLATE,
- bio, tmpl)) {
+ bio, tmpl)) {
CMP_err1("error saving certTemplate from genp: cannot write file %s",
- file);
+ file);
BIO_free(bio);
return 0;
} else {
@@ -2596,7 +2660,7 @@ static const char *prev_item(const char *opt, const char *end)
len = end - beg;
if (len > SECTION_NAME_MAX) {
CMP_warn3("using only first %d characters of section name starting with \"%.*s\"",
- SECTION_NAME_MAX, SECTION_NAME_MAX, beg);
+ SECTION_NAME_MAX, SECTION_NAME_MAX, beg);
len = SECTION_NAME_MAX;
}
memcpy(opt_item, beg, len);
@@ -2613,7 +2677,7 @@ static const char *prev_item(const char *opt, const char *end)
/* get str value for name from a comma-separated hierarchy of config sections */
static char *conf_get_string(const CONF *src_conf, const char *groups,
- const char *name)
+ const char *name)
{
char *res = NULL;
const char *end = groups + strlen(groups);
@@ -2627,7 +2691,7 @@ static char *conf_get_string(const CONF *src_conf, const char *groups,
/* get long val for name from a comma-separated hierarchy of config sections */
static int conf_get_number_e(const CONF *conf_, const char *groups,
- const char *name, long *result)
+ const char *name, long *result)
{
char *str = conf_get_string(conf_, groups, name);
char *tailptr;
@@ -2664,25 +2728,22 @@ static int read_config(void)
int n_options = OSSL_NELEM(cmp_options) - 1;
for (opt = &cmp_options[start_opt], i = start_idx;
- opt->name != NULL; i++, opt++)
+ opt->name != NULL; i++, opt++)
if (!strcmp(opt->name, OPT_SECTION_STR)
- || !strcmp(opt->name, OPT_MORE_STR))
+ || !strcmp(opt->name, OPT_MORE_STR))
n_options--;
- OPENSSL_assert(OSSL_NELEM(cmp_vars) == n_options
- + OPT_PROV__FIRST + 1 - OPT_PROV__LAST
- + OPT_R__FIRST + 1 - OPT_R__LAST
- + OPT_V__FIRST + 1 - OPT_V__LAST);
+ OPENSSL_assert(OSSL_NELEM(cmp_vars) == n_options + OPT_PROV__FIRST + 1 - OPT_PROV__LAST + OPT_R__FIRST + 1 - OPT_R__LAST + OPT_V__FIRST + 1 - OPT_V__LAST);
for (opt = &cmp_options[start_opt], i = start_idx;
- opt->name != NULL; i++, opt++) {
+ opt->name != NULL; i++, opt++) {
int provider_option = (OPT_PROV__FIRST <= opt->retval
- && opt->retval < OPT_PROV__LAST);
+ && opt->retval < OPT_PROV__LAST);
int rand_state_option = (OPT_R__FIRST <= opt->retval
- && opt->retval < OPT_R__LAST);
+ && opt->retval < OPT_R__LAST);
int verification_option = (OPT_V__FIRST <= opt->retval
- && opt->retval < OPT_V__LAST);
+ && opt->retval < OPT_V__LAST);
if (strcmp(opt->name, OPT_SECTION_STR) == 0
- || strcmp(opt->name, OPT_MORE_STR) == 0) {
+ || strcmp(opt->name, OPT_MORE_STR) == 0) {
i--;
continue;
}
@@ -2700,12 +2761,12 @@ static int read_config(void)
}
if (opt->valtype == 'p' && num <= 0) {
opt_printf_stderr("Non-positive number \"%ld\" for config option -%s\n",
- num, opt->name);
+ num, opt->name);
return -1;
}
if (opt->valtype == 'N' && num < 0) {
opt_printf_stderr("Negative number \"%ld\" for config option -%s\n",
- num, opt->name);
+ num, opt->name);
return -1;
}
break;
@@ -2720,7 +2781,7 @@ static int read_config(void)
break;
default:
CMP_err2("internal: unsupported type '%c' for option '%s'",
- opt->valtype, opt->name);
+ opt->valtype, opt->name);
return 0;
break;
}
@@ -2744,10 +2805,10 @@ static int read_config(void)
(void)opt_init(conf_argc, conf_argv, cmp_options);
if (provider_option
- ? !opt_provider(opt_next())
- : !opt_verify(opt_next(), vpm)) {
+ ? !opt_provider(opt_next())
+ : !opt_verify(opt_next(), vpm)) {
CMP_err2("for option '%s' in config file section '%s'",
- opt->name, opt_section);
+ opt->name, opt_section);
return 0;
}
}
@@ -2759,8 +2820,8 @@ static int read_config(void)
case 'N':
if (num < INT_MIN || INT_MAX < num) {
BIO_printf(bio_err,
- "integer value out of range for option '%s'\n",
- opt->name);
+ "integer value out of range for option '%s'\n",
+ opt->name);
return 0;
}
*cmp_vars[i].num = (int)num;
@@ -2786,7 +2847,7 @@ static char *opt_str(void)
if (arg[0] == '\0') {
CMP_warn1("%s option argument is empty string, resetting option",
- opt_flag());
+ opt_flag());
arg = NULL;
} else if (arg[0] == '-') {
CMP_warn1("%s option argument starts with hyphen", opt_flag());
@@ -2805,7 +2866,7 @@ static int get_opts(int argc, char **argv)
switch (o) {
case OPT_EOF:
case OPT_ERR:
- opthelp:
+ opthelp:
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
return 0;
case OPT_HELP:
@@ -3016,7 +3077,7 @@ static int get_opts(int argc, char **argv)
case OPT_POPO:
opt_popo = opt_int_arg();
if (opt_popo < OSSL_CRMF_POPO_NONE
- || opt_popo > OSSL_CRMF_POPO_KEYENC) {
+ || opt_popo > OSSL_CRMF_POPO_KEYENC) {
CMP_err("invalid popo spec. Valid values are -1 .. 2");
goto opthelp;
}
@@ -3045,8 +3106,8 @@ static int get_opts(int argc, char **argv)
case OPT_REVREASON:
opt_revreason = opt_int_arg();
if (opt_revreason < CRL_REASON_NONE
- || opt_revreason > CRL_REASON_AA_COMPROMISE
- || opt_revreason == 7) {
+ || opt_revreason > CRL_REASON_AA_COMPROMISE
+ || opt_revreason == 7) {
CMP_err("invalid revreason. Valid values are -1 .. 6, 8 .. 10");
goto opthelp;
}
@@ -3236,9 +3297,9 @@ static int cmp_server(OSSL_CMP_CTX *srv_cmp_ctx)
OSSL_CMP_MSG *resp = NULL;
ret = http_server_get_asn1_req(ASN1_ITEM_rptr(OSSL_CMP_MSG),
- (ASN1_VALUE **)&req, &path,
- &cbio, acbio, &keep_alive,
- prog, 0, 0);
+ (ASN1_VALUE **)&req, &path,
+ &cbio, acbio, &keep_alive,
+ prog, 0, 0);
if (ret == 0) { /* no request yet */
if (retry) {
OSSL_sleep(1000);
@@ -3257,23 +3318,23 @@ static int cmp_server(OSSL_CMP_CTX *srv_cmp_ctx)
if (strcmp(path, "") != 0 && strcmp(path, "pkix/") != 0) {
(void)http_server_send_status(prog, cbio, 404, "Not Found");
CMP_err1("expecting empty path or 'pkix/' but got '%s'",
- path);
+ path);
OPENSSL_free(path);
OSSL_CMP_MSG_free(req);
goto next;
}
OPENSSL_free(path);
- resp = OSSL_CMP_CTX_server_perform(cmp_ctx, req);
+ resp = OSSL_CMP_CTX_server_perform(cmp_ctx /* of client */, req);
OSSL_CMP_MSG_free(req);
if (resp == NULL) {
(void)http_server_send_status(prog, cbio,
- 500, "Internal Server Error");
+ 500, "Internal Server Error");
break; /* treated as fatal error */
}
ret = http_server_send_asn1_resp(prog, cbio, keep_alive,
- "application/pkixcmp",
- ASN1_ITEM_rptr(OSSL_CMP_MSG),
- (const ASN1_VALUE *)resp);
+ "application/pkixcmp",
+ ASN1_ITEM_rptr(OSSL_CMP_MSG),
+ (const ASN1_VALUE *)resp);
OSSL_CMP_MSG_free(resp);
if (!ret)
break; /* treated as fatal error */
@@ -3323,28 +3384,26 @@ static void print_keyspec(OSSL_CMP_ATAVS *keySpec)
int nid = OBJ_obj2nid(type);
switch (nid) {
- case NID_id_regCtrl_algId:
- {
- X509_ALGOR *alg = OSSL_CMP_ATAV_get0_algId(atav);
- const ASN1_OBJECT *oid;
- int paramtype;
- const void *param;
+ case NID_id_regCtrl_algId: {
+ X509_ALGOR *alg = OSSL_CMP_ATAV_get0_algId(atav);
+ const ASN1_OBJECT *oid;
+ int paramtype;
+ const void *param;
- X509_ALGOR_get0(&oid, &paramtype, &param, alg);
- BIO_printf(mem, "Key algorithm: ");
- i2a_ASN1_OBJECT(mem, oid);
- if (paramtype == V_ASN1_UNDEF || alg->parameter == NULL) {
- BIO_printf(mem, "\n");
- } else {
- BIO_printf(mem, " - ");
- ASN1_item_print(mem, (ASN1_VALUE *)alg,
- 0, ASN1_ITEM_rptr(X509_ALGOR), NULL);
- }
+ X509_ALGOR_get0(&oid, &paramtype, &param, alg);
+ BIO_printf(mem, "Key algorithm: ");
+ i2a_ASN1_OBJECT(mem, oid);
+ if (paramtype == V_ASN1_UNDEF || alg->parameter == NULL) {
+ BIO_printf(mem, "\n");
+ } else {
+ BIO_printf(mem, " - ");
+ ASN1_item_print(mem, (ASN1_VALUE *)alg,
+ 0, ASN1_ITEM_rptr(X509_ALGOR), NULL);
}
- break;
+ } break;
case NID_id_regCtrl_rsaKeyLen:
BIO_printf(mem, "Key algorithm: RSA %d\n",
- OSSL_CMP_ATAV_get_rsaKeyLen(atav));
+ OSSL_CMP_ATAV_get_rsaKeyLen(atav));
break;
default:
BIO_printf(mem, "Invalid key spec: %s\n", nid_name(nid));
@@ -3367,8 +3426,7 @@ static void print_status(void)
/* print PKIStatusInfo */
int status = OSSL_CMP_CTX_get_status(cmp_ctx);
char *buf = app_malloc(OSSL_CMP_PKISI_BUFLEN, "PKIStatusInfo buf");
- const char *string =
- OSSL_CMP_CTX_snprint_PKIStatus(cmp_ctx, buf, OSSL_CMP_PKISI_BUFLEN);
+ const char *string = OSSL_CMP_CTX_snprint_PKIStatus(cmp_ctx, buf, OSSL_CMP_PKISI_BUFLEN);
const char *from = "", *server = "";
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
@@ -3378,16 +3436,17 @@ static void print_status(void)
}
#endif
CMP_print(bio_err,
- status == OSSL_CMP_PKISTATUS_accepted
- ? OSSL_CMP_LOG_INFO :
- status == OSSL_CMP_PKISTATUS_rejection
- || status == OSSL_CMP_PKISTATUS_waiting
- ? OSSL_CMP_LOG_ERR : OSSL_CMP_LOG_WARNING,
- status == OSSL_CMP_PKISTATUS_accepted ? "info" :
- status == OSSL_CMP_PKISTATUS_rejection ? "server error" :
- status == OSSL_CMP_PKISTATUS_waiting ? "internal error"
- : "warning", "received%s%s %s", from, server,
- string != NULL ? string : "<unknown PKIStatus>");
+ status == OSSL_CMP_PKISTATUS_accepted
+ ? OSSL_CMP_LOG_INFO
+ : status == OSSL_CMP_PKISTATUS_rejection
+ || status == OSSL_CMP_PKISTATUS_waiting
+ ? OSSL_CMP_LOG_ERR
+ : OSSL_CMP_LOG_WARNING,
+ status == OSSL_CMP_PKISTATUS_accepted ? "info" : status == OSSL_CMP_PKISTATUS_rejection ? "server error"
+ : status == OSSL_CMP_PKISTATUS_waiting ? "internal error"
+ : "warning",
+ "received%s%s %s", from, server,
+ string != NULL ? string : "<unknown PKIStatus>");
OPENSSL_free(buf);
}
@@ -3409,7 +3468,7 @@ static int do_genm(OSSL_CMP_CTX *ctx)
CMP_warn("no CA certificates provided by server");
} else if (save_free_certs(cacerts, opt_cacertsout, "CA") < 0) {
CMP_err1("Failed to store CA certificates from genp in %s",
- opt_cacertsout);
+ opt_cacertsout);
return 0;
}
return 1;
@@ -3428,12 +3487,12 @@ static int do_genm(OSSL_CMP_CTX *ctx)
CMP_warn("No -oldwithold given, will use all certs given with -trusted as trust anchors for verifying the newWithNew cert");
} else {
oldwithold = load_cert_pwd(opt_oldwithold, opt_otherpass,
- "OldWithOld cert for genm with -infotype rootCaCert");
+ "OldWithOld cert for genm with -infotype rootCaCert");
if (oldwithold == NULL)
goto end_upd;
}
if (!OSSL_CMP_get1_rootCaKeyUpdate(ctx, oldwithold, &newwithnew,
- &newwithold, &oldwithnew))
+ &newwithold, &oldwithnew))
goto end_upd;
/* At this point might check authorization of response sender/origin */
@@ -3443,11 +3502,11 @@ static int do_genm(OSSL_CMP_CTX *ctx)
CMP_warn("oldWithNew certificate received in genp for verifying oldWithOld, but oldWithOld was not provided");
if (save_cert_or_delete(newwithnew, opt_newwithnew,
- "NewWithNew cert from genp")
+ "NewWithNew cert from genp")
&& save_cert_or_delete(newwithold, opt_newwithold,
- "NewWithOld cert from genp")
+ "NewWithOld cert from genp")
&& save_cert_or_delete(oldwithnew, opt_oldwithnew,
- "OldWithNew cert from genp"))
+ "OldWithNew cert from genp"))
res = 1;
X509_free(newwithnew);
@@ -3473,21 +3532,21 @@ static int do_genm(OSSL_CMP_CTX *ctx)
if (opt_crlcert != NULL) {
crlcert = load_cert_pwd(opt_crlcert, opt_otherpass,
- "Cert for genm with -infotype crlStatusList");
+ "Cert for genm with -infotype crlStatusList");
if (crlcert == NULL)
goto end_crlupd;
}
if (opt_oldcrl != NULL) {
oldcrl = load_crl(opt_oldcrl, FORMAT_UNDEF, 0,
- "CRL for genm with -infotype crlStatusList");
+ "CRL for genm with -infotype crlStatusList");
if (oldcrl == NULL)
goto end_crlupd;
}
if (opt_oldcrl != NULL && opt_crlcert != NULL) {
if (X509_NAME_cmp(X509_CRL_get_issuer(oldcrl),
- X509_get_issuer_name(crlcert))
+ X509_get_issuer_name(crlcert))
!= 0)
CMP_warn("-oldcrl and -crlcert have different issuer");
}
@@ -3550,12 +3609,12 @@ static int do_genm(OSSL_CMP_CTX *ctx)
if (opt_infotype != NID_undef) {
CMP_warn1("No specific support for -infotype %s available",
- opt_infotype_s);
+ opt_infotype_s);
req = OSSL_CMP_ITAV_create(OBJ_nid2obj(opt_infotype), NULL);
if (req == NULL || !OSSL_CMP_CTX_push0_genm_ITAV(ctx, req)) {
CMP_err1("Failed to create genm for -infotype %s",
- opt_infotype_s);
+ opt_infotype_s);
return 0;
}
}
@@ -3588,11 +3647,12 @@ static int handle_opts_upfront(int argc, char **argv)
if (!strcmp(argv[i] + 1, cmp_options[OPT_CONFIG - OPT_HELP].name))
opt_config = argv[++i];
else if (!strcmp(argv[i] + 1,
- cmp_options[OPT_SECTION - OPT_HELP].name))
+ cmp_options[OPT_SECTION - OPT_HELP].name))
opt_section = argv[++i];
else if (strcmp(argv[i] + 1,
- cmp_options[OPT_VERBOSITY - OPT_HELP].name) == 0
- && !set_verbosity(atoi(argv[++i])))
+ cmp_options[OPT_VERBOSITY - OPT_HELP].name)
+ == 0
+ && !set_verbosity(atoi(argv[++i])))
return 0;
}
}
@@ -3607,7 +3667,6 @@ int cmp_main(int argc, char **argv)
int i;
X509 *newcert = NULL;
ENGINE *engine = NULL;
- OSSL_CMP_CTX *srv_cmp_ctx = NULL;
int ret = 0; /* default: failure */
if (!handle_opts_upfront(argc, argv))
@@ -3622,10 +3681,10 @@ int cmp_main(int argc, char **argv)
/* read default values for options from config file */
configfile = opt_config != NULL ? opt_config : default_config_file;
if (configfile != NULL && configfile[0] != '\0' /* non-empty string */
- && (configfile != default_config_file
- || access(configfile, F_OK) != -1)) {
+ && (configfile != default_config_file
+ || access(configfile, F_OK) != -1)) {
CMP_info2("using section(s) '%s' of OpenSSL configuration file '%s'",
- opt_section, configfile);
+ opt_section, configfile);
conf = app_load_config(configfile);
if (conf == NULL) {
goto err;
@@ -3634,14 +3693,14 @@ int cmp_main(int argc, char **argv)
if (!NCONF_get_section(conf, opt_section))
CMP_info2("no [%s] section found in config file '%s';"
" will thus use just [default] and unnamed section if present",
- opt_section, configfile);
+ opt_section, configfile);
} else {
const char *end = opt_section + strlen(opt_section);
while ((end = prev_item(opt_section, end)) != NULL) {
if (!NCONF_get_section(conf, opt_item)) {
CMP_err2("no [%s] section found in config file '%s'",
- opt_item, configfile);
+ opt_item, configfile);
goto err;
}
}
@@ -3675,7 +3734,7 @@ int cmp_main(int argc, char **argv)
if (opt_engine != NULL) {
engine = setup_engine_methods(opt_engine,
- 0 /* not: ENGINE_METHOD_ALL */, 0);
+ 0 /* not: ENGINE_METHOD_ALL */, 0);
if (engine == NULL) {
CMP_err1("cannot load engine %s", opt_engine);
goto err;
@@ -3690,8 +3749,8 @@ int cmp_main(int argc, char **argv)
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
if (opt_tls_cert == NULL && opt_tls_key == NULL && opt_tls_keypass == NULL
- && opt_tls_extra == NULL && opt_tls_trusted == NULL
- && opt_tls_host == NULL) {
+ && opt_tls_extra == NULL && opt_tls_trusted == NULL
+ && opt_tls_host == NULL) {
if (opt_tls_used)
CMP_warn("-tls_used given without any other TLS options");
} else if (!opt_tls_used) {
@@ -3715,45 +3774,49 @@ int cmp_main(int argc, char **argv)
goto err;
}
}
+
if (opt_server != NULL && opt_use_mock_srv) {
CMP_err("cannot use both -server and -use_mock_srv options");
goto err;
}
+ if ((opt_server == NULL || opt_use_mock_srv) && opt_tls_used) {
+ CMP_warn("ignoring -tls_used option since -server is not given or -use_mock_srv is given");
+ opt_tls_used = 0;
+ }
+
#endif
if (opt_ignore_keyusage)
(void)OSSL_CMP_CTX_set_option(cmp_ctx, OSSL_CMP_OPT_IGNORE_KEYUSAGE, 1);
if (opt_no_cache_extracerts)
(void)OSSL_CMP_CTX_set_option(cmp_ctx, OSSL_CMP_OPT_NO_CACHE_EXTRACERTS,
- 1);
+ 1);
if (opt_reqout_only == NULL && (opt_use_mock_srv
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
- || opt_port != NULL
+ || opt_port != NULL
#endif
- )) {
+ )) {
OSSL_CMP_SRV_CTX *srv_ctx;
+ OSSL_CMP_CTX *srv_cmp_ctx;
if ((srv_ctx = setup_srv_ctx(engine)) == NULL)
goto err;
+ OSSL_CMP_CTX_set_transfer_cb_arg(cmp_ctx /* of client */, srv_ctx);
+
srv_cmp_ctx = OSSL_CMP_SRV_CTX_get0_cmp_ctx(srv_ctx);
- OSSL_CMP_CTX_set_transfer_cb_arg(cmp_ctx, srv_ctx);
if (!OSSL_CMP_CTX_set_log_cb(srv_cmp_ctx, print_to_bio_err)) {
CMP_err1("cannot set up error reporting and logging for %s", prog);
goto err;
}
OSSL_CMP_CTX_set_log_verbosity(srv_cmp_ctx, opt_verbosity);
- }
#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
- if (opt_tls_used && (opt_use_mock_srv || opt_server == NULL)) {
- CMP_warn("ignoring -tls_used option since -use_mock_srv is given or -server is not given");
- opt_tls_used = 0;
- }
-
- if (opt_port != NULL) { /* act as very basic CMP HTTP server */
- ret = cmp_server(srv_cmp_ctx);
- goto err;
+ if (opt_port != NULL) { /* act as very basic CMP HTTP server only */
+ ret = cmp_server(srv_cmp_ctx);
+ goto err;
+ }
+#endif
}
/* act as CMP client, possibly using internal mock server */
@@ -3761,10 +3824,14 @@ int cmp_main(int argc, char **argv)
if (opt_reqout_only != NULL) {
const char *msg = "option is ignored since -reqout_only option is given";
-# if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
+#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
+ if (opt_port != NULL) {
+ CMP_err("the -reqout_only client option does not combine with -port implying server behavior");
+ goto err;
+ }
if (opt_server != NULL)
CMP_warn1("-server %s", msg);
-# endif
+#endif
if (opt_use_mock_srv)
CMP_warn1("-use_mock_srv %s", msg);
if (opt_reqout != NULL)
@@ -3776,12 +3843,13 @@ int cmp_main(int argc, char **argv)
opt_reqout = opt_reqout_only;
}
if (opt_rspin != NULL) {
+#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP)
if (opt_server != NULL)
CMP_warn("-server option is not used if enough filenames given for -rspin");
+#endif
if (opt_use_mock_srv)
CMP_warn("-use_mock_srv option is not used if enough filenames given for -rspin");
}
-#endif
if (!setup_client_ctx(cmp_ctx, engine)) {
CMP_err("cannot set up CMP context");
@@ -3829,23 +3897,22 @@ int cmp_main(int argc, char **argv)
}
print_status();
if (!save_cert_or_delete(OSSL_CMP_CTX_get0_validatedSrvCert(cmp_ctx),
- opt_srvcertout, "validated server"))
+ opt_srvcertout, "validated server"))
ret = 0;
if (!ret)
goto err;
ret = 0;
if (save_free_certs(OSSL_CMP_CTX_get1_extraCertsIn(cmp_ctx),
- opt_extracertsout, "extra") < 0)
+ opt_extracertsout, "extra")
+ < 0)
goto err;
- if (newcert != NULL && (opt_cmd == CMP_IR || opt_cmd == CMP_CR
- || opt_cmd == CMP_KUR || opt_cmd == CMP_P10CR)) {
+ if (newcert != NULL && (opt_cmd == CMP_IR || opt_cmd == CMP_CR || opt_cmd == CMP_KUR || opt_cmd == CMP_P10CR)) {
STACK_OF(X509) *newchain = OSSL_CMP_CTX_get1_newChain(cmp_ctx);
if (newcert != NULL && newchain != NULL /* NULL is on error only */
&& opt_certout != NULL && opt_chainout != NULL
&& strcmp(opt_certout, opt_chainout) == 0) {
- if (!X509_add_cert(newchain, newcert, X509_ADD_FLAG_PREPEND
- | X509_ADD_FLAG_UP_REF)) {
+ if (!X509_add_cert(newchain, newcert, X509_ADD_FLAG_PREPEND | X509_ADD_FLAG_UP_REF)) {
sk_X509_pop_free(newchain, X509_free);
goto err;
}
@@ -3857,7 +3924,8 @@ int cmp_main(int argc, char **argv)
goto err;
}
if (save_free_certs(OSSL_CMP_CTX_get1_caPubs(cmp_ctx),
- opt_cacertsout, "CA") < 0)
+ opt_cacertsout, "CA")
+ < 0)
goto err;
if (opt_centralkeygen) {
EVP_CIPHER *cipher = NULL;
@@ -3872,13 +3940,14 @@ int cmp_main(int argc, char **argv)
goto err;
if (opt_newkeypass != NULL) {
pass_string = get_passwd(opt_newkeypass,
- "Centrally generated private key password");
+ "Centrally generated private key password");
cipher = EVP_CIPHER_fetch(app_get0_libctx(), SN_aes_256_cbc, app_get0_propq());
}
CMP_info1("saving centrally generated key to file '%s'", opt_newkeyout);
if (PEM_write_bio_PrivateKey(out, new_key, cipher, NULL, 0, NULL,
- (void *)pass_string) <= 0)
+ (void *)pass_string)
+ <= 0)
result = 0;
BIO_free(out);
@@ -3893,7 +3962,7 @@ int cmp_main(int argc, char **argv)
}
ret = 1;
- err:
+err:
/* in case we ended up here on error without proper cleaning */
cleanse(opt_keypass);
cleanse(opt_newkeypass);