diff options
| author | Enji Cooper <ngie@FreeBSD.org> | 2026-01-29 01:27:53 +0000 |
|---|---|---|
| committer | Enji Cooper <ngie@FreeBSD.org> | 2026-01-29 01:27:53 +0000 |
| commit | 808413da28df9fb93e1f304e6016b15e660f54c8 (patch) | |
| tree | f3ecb4f928716223c9563ee34e044ab84549debb /crypto/cms/cms_smime.c | |
| parent | 8e12a5c4eb3507846b507d0afe87d115af41df40 (diff) | |
Diffstat (limited to 'crypto/cms/cms_smime.c')
| -rw-r--r-- | crypto/cms/cms_smime.c | 140 |
1 files changed, 65 insertions, 75 deletions
diff --git a/crypto/cms/cms_smime.c b/crypto/cms/cms_smime.c index 3f3d93fa0095..920464b3deec 100644 --- a/crypto/cms/cms_smime.c +++ b/crypto/cms/cms_smime.c @@ -69,11 +69,10 @@ static int cms_copy_content(BIO *out, BIO *in, unsigned int flags) } r = 1; - err: +err: if (tmpout != out) BIO_free(tmpout); return r; - } static int check_content(CMS_ContentInfo *cms) @@ -120,7 +119,7 @@ int CMS_data(CMS_ContentInfo *cms, BIO *out, unsigned int flags) } CMS_ContentInfo *CMS_data_create_ex(BIO *in, unsigned int flags, - OSSL_LIB_CTX *libctx, const char *propq) + OSSL_LIB_CTX *libctx, const char *propq) { CMS_ContentInfo *cms = ossl_cms_Data_create(libctx, propq); @@ -140,7 +139,7 @@ CMS_ContentInfo *CMS_data_create(BIO *in, unsigned int flags) } int CMS_digest_verify(CMS_ContentInfo *cms, BIO *dcont, BIO *out, - unsigned int flags) + unsigned int flags) { BIO *cont; int r; @@ -165,8 +164,8 @@ int CMS_digest_verify(CMS_ContentInfo *cms, BIO *dcont, BIO *out, } CMS_ContentInfo *CMS_digest_create_ex(BIO *in, const EVP_MD *md, - unsigned int flags, OSSL_LIB_CTX *ctx, - const char *propq) + unsigned int flags, OSSL_LIB_CTX *ctx, + const char *propq) { CMS_ContentInfo *cms; @@ -191,14 +190,14 @@ CMS_ContentInfo *CMS_digest_create_ex(BIO *in, const EVP_MD *md, } CMS_ContentInfo *CMS_digest_create(BIO *in, const EVP_MD *md, - unsigned int flags) + unsigned int flags) { return CMS_digest_create_ex(in, md, flags, NULL, NULL); } int CMS_EncryptedData_decrypt(CMS_ContentInfo *cms, - const unsigned char *key, size_t keylen, - BIO *dcont, BIO *out, unsigned int flags) + const unsigned char *key, size_t keylen, + BIO *dcont, BIO *out, unsigned int flags) { BIO *cont; int r; @@ -222,10 +221,10 @@ int CMS_EncryptedData_decrypt(CMS_ContentInfo *cms, } CMS_ContentInfo *CMS_EncryptedData_encrypt_ex(BIO *in, const EVP_CIPHER *cipher, - const unsigned char *key, - size_t keylen, unsigned int flags, - OSSL_LIB_CTX *libctx, - const char *propq) + const unsigned char *key, + size_t keylen, unsigned int flags, + OSSL_LIB_CTX *libctx, + const char *propq) { CMS_ContentInfo *cms; @@ -246,32 +245,32 @@ CMS_ContentInfo *CMS_EncryptedData_encrypt_ex(BIO *in, const EVP_CIPHER *cipher, || CMS_final(cms, in, NULL, flags)) return cms; - err: +err: CMS_ContentInfo_free(cms); return NULL; } CMS_ContentInfo *CMS_EncryptedData_encrypt(BIO *in, const EVP_CIPHER *cipher, - const unsigned char *key, - size_t keylen, unsigned int flags) + const unsigned char *key, + size_t keylen, unsigned int flags) { return CMS_EncryptedData_encrypt_ex(in, cipher, key, keylen, flags, NULL, - NULL); + NULL); } static int cms_signerinfo_verify_cert(CMS_SignerInfo *si, - X509_STORE *store, - STACK_OF(X509) *untrusted, - STACK_OF(X509_CRL) *crls, - STACK_OF(X509) **chain, - const CMS_CTX *cms_ctx) + X509_STORE *store, + STACK_OF(X509) *untrusted, + STACK_OF(X509_CRL) *crls, + STACK_OF(X509) **chain, + const CMS_CTX *cms_ctx) { X509_STORE_CTX *ctx; X509 *signer; int i, j, r = 0; ctx = X509_STORE_CTX_new_ex(ossl_cms_ctx_get0_libctx(cms_ctx), - ossl_cms_ctx_get0_propq(cms_ctx)); + ossl_cms_ctx_get0_propq(cms_ctx)); if (ctx == NULL) { ERR_raise(ERR_LIB_CMS, ERR_R_X509_LIB); goto err; @@ -289,7 +288,7 @@ static int cms_signerinfo_verify_cert(CMS_SignerInfo *si, if (i <= 0) { j = X509_STORE_CTX_get_error(ctx); ERR_raise_data(ERR_LIB_CMS, CMS_R_CERTIFICATE_VERIFY_ERROR, - "Verify error: %s", X509_verify_cert_error_string(j)); + "Verify error: %s", X509_verify_cert_error_string(j)); goto err; } r = 1; @@ -297,15 +296,14 @@ static int cms_signerinfo_verify_cert(CMS_SignerInfo *si, /* also send back the trust chain when required */ if (chain != NULL) *chain = X509_STORE_CTX_get1_chain(ctx); - err: +err: X509_STORE_CTX_free(ctx); return r; - } /* This strongly overlaps with PKCS7_verify() */ int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, - X509_STORE *store, BIO *dcont, BIO *out, unsigned int flags) + X509_STORE *store, BIO *dcont, BIO *out, unsigned int flags) { CMS_SignerInfo *si; STACK_OF(CMS_SignerInfo) *sinfos; @@ -365,8 +363,7 @@ int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, goto err; if (sk_X509_num(certs) > 0 && !ossl_x509_add_certs_new(&untrusted, certs, - X509_ADD_FLAG_UP_REF | - X509_ADD_FLAG_NO_DUP)) + X509_ADD_FLAG_UP_REF | X509_ADD_FLAG_NO_DUP)) goto err; if ((flags & CMS_NOCRL) == 0 @@ -376,8 +373,8 @@ int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, si = sk_CMS_SignerInfo_value(sinfos, i); if (!cms_signerinfo_verify_cert(si, store, untrusted, crls, - si_chains ? &si_chains[i] : NULL, - ctx)) + si_chains ? &si_chains[i] : NULL, + ctx)) goto err; } } @@ -457,7 +454,6 @@ int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, if (!cms_copy_content(out, cmsbio, flags)) goto err; - } if (!(flags & CMS_NO_CONTENT_VERIFY)) { for (i = 0; i < sk_CMS_SignerInfo_num(sinfos); i++) { @@ -470,7 +466,7 @@ int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, } ret = 1; - err: +err: if (!(flags & SMIME_BINARY) && dcont) { do_free_upto(cmsbio, tmpout); if (tmpin != dcont) @@ -485,7 +481,7 @@ int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, if (out != tmpout) BIO_free_all(tmpout); - err2: +err2: if (si_chains != NULL) { for (i = 0; i < scount; ++i) OSSL_STACK_OF_X509_free(si_chains[i]); @@ -498,8 +494,8 @@ int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, } int CMS_verify_receipt(CMS_ContentInfo *rcms, CMS_ContentInfo *ocms, - STACK_OF(X509) *certs, - X509_STORE *store, unsigned int flags) + STACK_OF(X509) *certs, + X509_STORE *store, unsigned int flags) { int r; @@ -511,9 +507,9 @@ int CMS_verify_receipt(CMS_ContentInfo *rcms, CMS_ContentInfo *ocms, } CMS_ContentInfo *CMS_sign_ex(X509 *signcert, EVP_PKEY *pkey, - STACK_OF(X509) *certs, BIO *data, - unsigned int flags, OSSL_LIB_CTX *libctx, - const char *propq) + STACK_OF(X509) *certs, BIO *data, + unsigned int flags, OSSL_LIB_CTX *libctx, + const char *propq) { CMS_ContentInfo *cms; int i; @@ -525,7 +521,7 @@ CMS_ContentInfo *CMS_sign_ex(X509 *signcert, EVP_PKEY *pkey, } if (flags & CMS_ASCIICRLF && !CMS_set1_eContentType(cms, - OBJ_nid2obj(NID_id_ct_asciiTextWithCRLF))) { + OBJ_nid2obj(NID_id_ct_asciiTextWithCRLF))) { ERR_raise(ERR_LIB_CMS, ERR_R_CMS_LIB); goto err; } @@ -553,20 +549,20 @@ CMS_ContentInfo *CMS_sign_ex(X509 *signcert, EVP_PKEY *pkey, else goto err; - err: +err: CMS_ContentInfo_free(cms); return NULL; } CMS_ContentInfo *CMS_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs, - BIO *data, unsigned int flags) + BIO *data, unsigned int flags) { return CMS_sign_ex(signcert, pkey, certs, data, flags, NULL, NULL); } CMS_ContentInfo *CMS_sign_receipt(CMS_SignerInfo *si, - X509 *signcert, EVP_PKEY *pkey, - STACK_OF(X509) *certs, unsigned int flags) + X509 *signcert, EVP_PKEY *pkey, + STACK_OF(X509) *certs, unsigned int flags) { CMS_SignerInfo *rct_si; CMS_ContentInfo *cms = NULL; @@ -586,8 +582,8 @@ CMS_ContentInfo *CMS_sign_receipt(CMS_SignerInfo *si, /* Initialize signed data */ cms = CMS_sign_ex(NULL, NULL, certs, NULL, flags, - ossl_cms_ctx_get0_libctx(ctx), - ossl_cms_ctx_get0_propq(ctx)); + ossl_cms_ctx_get0_libctx(ctx), + ossl_cms_ctx_get0_propq(ctx)); if (cms == NULL) goto err; @@ -627,28 +623,26 @@ CMS_ContentInfo *CMS_sign_receipt(CMS_SignerInfo *si, r = 1; - err: +err: BIO_free(rct_cont); if (r) return cms; CMS_ContentInfo_free(cms); ASN1_OCTET_STRING_free(os); return NULL; - } CMS_ContentInfo *CMS_encrypt_ex(STACK_OF(X509) *certs, BIO *data, - const EVP_CIPHER *cipher, unsigned int flags, - OSSL_LIB_CTX *libctx, const char *propq) + const EVP_CIPHER *cipher, unsigned int flags, + OSSL_LIB_CTX *libctx, const char *propq) { CMS_ContentInfo *cms; int i; X509 *recip; - cms = (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER) - ? CMS_AuthEnvelopedData_create_ex(cipher, libctx, propq) - : CMS_EnvelopedData_create_ex(cipher, libctx, propq); + ? CMS_AuthEnvelopedData_create_ex(cipher, libctx, propq) + : CMS_EnvelopedData_create_ex(cipher, libctx, propq); if (cms == NULL) { ERR_raise(ERR_LIB_CMS, ERR_R_CMS_LIB); goto err; @@ -670,20 +664,20 @@ CMS_ContentInfo *CMS_encrypt_ex(STACK_OF(X509) *certs, BIO *data, else ERR_raise(ERR_LIB_CMS, ERR_R_CMS_LIB); - err: +err: CMS_ContentInfo_free(cms); return NULL; } CMS_ContentInfo *CMS_encrypt(STACK_OF(X509) *certs, BIO *data, - const EVP_CIPHER *cipher, unsigned int flags) + const EVP_CIPHER *cipher, unsigned int flags) { return CMS_encrypt_ex(certs, data, cipher, flags, NULL, NULL); } static int cms_kari_set1_pkey_and_peer(CMS_ContentInfo *cms, - CMS_RecipientInfo *ri, - EVP_PKEY *pk, X509 *cert, X509 *peer) + CMS_RecipientInfo *ri, + EVP_PKEY *pk, X509 *cert, X509 *peer) { int i; STACK_OF(CMS_RecipientEncryptedKey) *reks; @@ -708,11 +702,11 @@ static int cms_kari_set1_pkey_and_peer(CMS_ContentInfo *cms, int CMS_decrypt_set1_pkey(CMS_ContentInfo *cms, EVP_PKEY *pk, X509 *cert) { - return CMS_decrypt_set1_pkey_and_peer(cms, pk, cert, NULL); + return CMS_decrypt_set1_pkey_and_peer(cms, pk, cert, NULL); } int CMS_decrypt_set1_pkey_and_peer(CMS_ContentInfo *cms, EVP_PKEY *pk, - X509 *cert, X509 *peer) + X509 *cert, X509 *peer) { STACK_OF(CMS_RecipientInfo) *ris = CMS_get0_RecipientInfos(cms); CMS_RecipientInfo *ri; @@ -732,8 +726,8 @@ int CMS_decrypt_set1_pkey_and_peer(CMS_ContentInfo *cms, EVP_PKEY *pk, cms_pkey_ri_type = ossl_cms_pkey_get_ri_type(pk); if (cms_pkey_ri_type == CMS_RECIPINFO_NONE) { - ERR_raise(ERR_LIB_CMS, CMS_R_NOT_SUPPORTED_FOR_THIS_KEY_TYPE); - return 0; + ERR_raise(ERR_LIB_CMS, CMS_R_NOT_SUPPORTED_FOR_THIS_KEY_TYPE); + return 0; } for (i = 0; i < sk_CMS_RecipientInfo_num(ris); i++) { @@ -793,12 +787,11 @@ int CMS_decrypt_set1_pkey_and_peer(CMS_ContentInfo *cms, EVP_PKEY *pk, if (!match_ri) ERR_raise(ERR_LIB_CMS, CMS_R_NO_MATCHING_RECIPIENT); return 0; - } int CMS_decrypt_set1_key(CMS_ContentInfo *cms, - unsigned char *key, size_t keylen, - const unsigned char *id, size_t idlen) + unsigned char *key, size_t keylen, + const unsigned char *id, size_t idlen) { STACK_OF(CMS_RecipientInfo) *ris; CMS_RecipientInfo *ri; @@ -812,7 +805,7 @@ int CMS_decrypt_set1_key(CMS_ContentInfo *cms, /* If we have an id, try matching RecipientInfo, else try them all */ if (id == NULL - || (CMS_RecipientInfo_kekri_id_cmp(ri, id, idlen) == 0)) { + || (CMS_RecipientInfo_kekri_id_cmp(ri, id, idlen) == 0)) { match_ri = 1; CMS_RecipientInfo_set0_key(ri, key, keylen); r = CMS_RecipientInfo_decrypt(cms, ri); @@ -830,11 +823,10 @@ int CMS_decrypt_set1_key(CMS_ContentInfo *cms, if (!match_ri) ERR_raise(ERR_LIB_CMS, CMS_R_NO_MATCHING_RECIPIENT); return 0; - } int CMS_decrypt_set1_password(CMS_ContentInfo *cms, - unsigned char *pass, ossl_ssize_t passlen) + unsigned char *pass, ossl_ssize_t passlen) { STACK_OF(CMS_RecipientInfo) *ris = CMS_get0_RecipientInfos(cms); CMS_RecipientInfo *ri; @@ -865,11 +857,10 @@ int CMS_decrypt_set1_password(CMS_ContentInfo *cms, if (!match_ri) ERR_raise(ERR_LIB_CMS, CMS_R_NO_MATCHING_RECIPIENT); return 0; - } int CMS_decrypt(CMS_ContentInfo *cms, EVP_PKEY *pk, X509 *cert, - BIO *dcont, BIO *out, unsigned int flags) + BIO *dcont, BIO *out, unsigned int flags) { int r; BIO *cont; @@ -877,7 +868,7 @@ int CMS_decrypt(CMS_ContentInfo *cms, EVP_PKEY *pk, X509 *cert, int nid = OBJ_obj2nid(CMS_get0_type(cms)); if (nid != NID_pkcs7_enveloped - && nid != NID_id_smime_ct_authEnvelopedData) { + && nid != NID_id_smime_ct_authEnvelopedData) { ERR_raise(ERR_LIB_CMS, CMS_R_TYPE_NOT_ENVELOPED_DATA); return 0; } @@ -925,12 +916,11 @@ err: do_free_upto(cmsbio, dcont); return ret; - } int CMS_final_digest(CMS_ContentInfo *cms, - const unsigned char *md, unsigned int mdlen, - BIO *dcont, unsigned int flags) + const unsigned char *md, unsigned int mdlen, + BIO *dcont, unsigned int flags) { BIO *cmsbio; int ret = 0; @@ -956,7 +946,7 @@ err: #ifndef OPENSSL_NO_ZLIB int CMS_uncompress(CMS_ContentInfo *cms, BIO *dcont, BIO *out, - unsigned int flags) + unsigned int flags) { BIO *cont; int r; @@ -1000,7 +990,7 @@ CMS_ContentInfo *CMS_compress(BIO *in, int comp_nid, unsigned int flags) #else int CMS_uncompress(CMS_ContentInfo *cms, BIO *dcont, BIO *out, - unsigned int flags) + unsigned int flags) { ERR_raise(ERR_LIB_CMS, CMS_R_UNSUPPORTED_COMPRESSION_ALGORITHM); return 0; |
