1 // SPDX-License-Identifier: GPL-2.0-or-later 2 /* X.509 certificate parser 3 * 4 * Copyright (C) 2012 Red Hat, Inc. All Rights Reserved. 5 * Written by David Howells (dhowells@redhat.com) 6 */ 7 8 #define pr_fmt(fmt) "X.509: "fmt 9 #include <linux/kernel.h> 10 #include <linux/export.h> 11 #include <linux/slab.h> 12 #include <linux/err.h> 13 #include <linux/oid_registry.h> 14 #include <crypto/public_key.h> 15 #include "x509_parser.h" 16 #include "x509.asn1.h" 17 #include "x509_akid.asn1.h" 18 19 struct x509_parse_context { 20 struct x509_certificate *cert; /* Certificate being constructed */ 21 unsigned long data; /* Start of data */ 22 const void *key; /* Key data */ 23 size_t key_size; /* Size of key data */ 24 const void *params; /* Key parameters */ 25 size_t params_size; /* Size of key parameters */ 26 enum OID key_algo; /* Algorithm used by the cert's key */ 27 enum OID last_oid; /* Last OID encountered */ 28 enum OID sig_algo; /* Algorithm used to sign the cert */ 29 u8 o_size; /* Size of organizationName (O) */ 30 u8 cn_size; /* Size of commonName (CN) */ 31 u8 email_size; /* Size of emailAddress */ 32 u16 o_offset; /* Offset of organizationName (O) */ 33 u16 cn_offset; /* Offset of commonName (CN) */ 34 u16 email_offset; /* Offset of emailAddress */ 35 unsigned raw_akid_size; 36 const void *raw_akid; /* Raw authorityKeyId in ASN.1 */ 37 const void *akid_raw_issuer; /* Raw directoryName in authorityKeyId */ 38 unsigned akid_raw_issuer_size; 39 }; 40 41 /* 42 * Free an X.509 certificate 43 */ 44 void x509_free_certificate(struct x509_certificate *cert) 45 { 46 if (cert) { 47 public_key_free(cert->pub); 48 public_key_signature_free(cert->sig); 49 kfree(cert->issuer); 50 kfree(cert->subject); 51 kfree(cert->id); 52 kfree(cert->skid); 53 kfree(cert); 54 } 55 } 56 EXPORT_SYMBOL_GPL(x509_free_certificate); 57 58 /* 59 * Parse an X.509 certificate 60 */ 61 struct x509_certificate *x509_cert_parse(const void *data, size_t datalen) 62 { 63 struct x509_certificate *cert __free(x509_free_certificate); 64 struct x509_parse_context *ctx __free(kfree) = NULL; 65 struct asymmetric_key_id *kid; 66 long ret; 67 68 cert = kzalloc(sizeof(struct x509_certificate), GFP_KERNEL); 69 assume(!IS_ERR(cert)); /* Avoid gratuitous IS_ERR() check on return */ 70 if (!cert) 71 return ERR_PTR(-ENOMEM); 72 cert->pub = kzalloc(sizeof(struct public_key), GFP_KERNEL); 73 if (!cert->pub) 74 return ERR_PTR(-ENOMEM); 75 cert->sig = kzalloc(sizeof(struct public_key_signature), GFP_KERNEL); 76 if (!cert->sig) 77 return ERR_PTR(-ENOMEM); 78 ctx = kzalloc(sizeof(struct x509_parse_context), GFP_KERNEL); 79 if (!ctx) 80 return ERR_PTR(-ENOMEM); 81 82 ctx->cert = cert; 83 ctx->data = (unsigned long)data; 84 85 /* Attempt to decode the certificate */ 86 ret = asn1_ber_decoder(&x509_decoder, ctx, data, datalen); 87 if (ret < 0) 88 return ERR_PTR(ret); 89 90 /* Decode the AuthorityKeyIdentifier */ 91 if (ctx->raw_akid) { 92 pr_devel("AKID: %u %*phN\n", 93 ctx->raw_akid_size, ctx->raw_akid_size, ctx->raw_akid); 94 ret = asn1_ber_decoder(&x509_akid_decoder, ctx, 95 ctx->raw_akid, ctx->raw_akid_size); 96 if (ret < 0) { 97 pr_warn("Couldn't decode AuthKeyIdentifier\n"); 98 return ERR_PTR(ret); 99 } 100 } 101 102 cert->pub->key = kmemdup(ctx->key, ctx->key_size, GFP_KERNEL); 103 if (!cert->pub->key) 104 return ERR_PTR(-ENOMEM); 105 106 cert->pub->keylen = ctx->key_size; 107 108 cert->pub->params = kmemdup(ctx->params, ctx->params_size, GFP_KERNEL); 109 if (!cert->pub->params) 110 return ERR_PTR(-ENOMEM); 111 112 cert->pub->paramlen = ctx->params_size; 113 cert->pub->algo = ctx->key_algo; 114 115 /* Grab the signature bits */ 116 ret = x509_get_sig_params(cert); 117 if (ret < 0) 118 return ERR_PTR(ret); 119 120 /* Generate cert issuer + serial number key ID */ 121 kid = asymmetric_key_generate_id(cert->raw_serial, 122 cert->raw_serial_size, 123 cert->raw_issuer, 124 cert->raw_issuer_size); 125 if (IS_ERR(kid)) 126 return ERR_CAST(kid); 127 cert->id = kid; 128 129 /* Detect self-signed certificates */ 130 ret = x509_check_for_self_signed(cert); 131 if (ret < 0) 132 return ERR_PTR(ret); 133 134 return_ptr(cert); 135 } 136 EXPORT_SYMBOL_GPL(x509_cert_parse); 137 138 /* 139 * Note an OID when we find one for later processing when we know how 140 * to interpret it. 141 */ 142 int x509_note_OID(void *context, size_t hdrlen, 143 unsigned char tag, 144 const void *value, size_t vlen) 145 { 146 struct x509_parse_context *ctx = context; 147 148 ctx->last_oid = look_up_OID(value, vlen); 149 if (ctx->last_oid == OID__NR) { 150 char buffer[50]; 151 sprint_oid(value, vlen, buffer, sizeof(buffer)); 152 pr_debug("Unknown OID: [%lu] %s\n", 153 (unsigned long)value - ctx->data, buffer); 154 } 155 return 0; 156 } 157 158 /* 159 * Save the position of the TBS data so that we can check the signature over it 160 * later. 161 */ 162 int x509_note_tbs_certificate(void *context, size_t hdrlen, 163 unsigned char tag, 164 const void *value, size_t vlen) 165 { 166 struct x509_parse_context *ctx = context; 167 168 pr_debug("x509_note_tbs_certificate(,%zu,%02x,%ld,%zu)!\n", 169 hdrlen, tag, (unsigned long)value - ctx->data, vlen); 170 171 ctx->cert->tbs = value - hdrlen; 172 ctx->cert->tbs_size = vlen + hdrlen; 173 return 0; 174 } 175 176 /* 177 * Record the algorithm that was used to sign this certificate. 178 */ 179 int x509_note_sig_algo(void *context, size_t hdrlen, unsigned char tag, 180 const void *value, size_t vlen) 181 { 182 struct x509_parse_context *ctx = context; 183 184 pr_debug("PubKey Algo: %u\n", ctx->last_oid); 185 186 switch (ctx->last_oid) { 187 default: 188 return -ENOPKG; /* Unsupported combination */ 189 190 case OID_sha1WithRSAEncryption: 191 ctx->cert->sig->hash_algo = "sha1"; 192 goto rsa_pkcs1; 193 194 case OID_sha256WithRSAEncryption: 195 ctx->cert->sig->hash_algo = "sha256"; 196 goto rsa_pkcs1; 197 198 case OID_sha384WithRSAEncryption: 199 ctx->cert->sig->hash_algo = "sha384"; 200 goto rsa_pkcs1; 201 202 case OID_sha512WithRSAEncryption: 203 ctx->cert->sig->hash_algo = "sha512"; 204 goto rsa_pkcs1; 205 206 case OID_sha224WithRSAEncryption: 207 ctx->cert->sig->hash_algo = "sha224"; 208 goto rsa_pkcs1; 209 210 case OID_id_ecdsa_with_sha1: 211 ctx->cert->sig->hash_algo = "sha1"; 212 goto ecdsa; 213 214 case OID_id_rsassa_pkcs1_v1_5_with_sha3_256: 215 ctx->cert->sig->hash_algo = "sha3-256"; 216 goto rsa_pkcs1; 217 218 case OID_id_rsassa_pkcs1_v1_5_with_sha3_384: 219 ctx->cert->sig->hash_algo = "sha3-384"; 220 goto rsa_pkcs1; 221 222 case OID_id_rsassa_pkcs1_v1_5_with_sha3_512: 223 ctx->cert->sig->hash_algo = "sha3-512"; 224 goto rsa_pkcs1; 225 226 case OID_id_ecdsa_with_sha224: 227 ctx->cert->sig->hash_algo = "sha224"; 228 goto ecdsa; 229 230 case OID_id_ecdsa_with_sha256: 231 ctx->cert->sig->hash_algo = "sha256"; 232 goto ecdsa; 233 234 case OID_id_ecdsa_with_sha384: 235 ctx->cert->sig->hash_algo = "sha384"; 236 goto ecdsa; 237 238 case OID_id_ecdsa_with_sha512: 239 ctx->cert->sig->hash_algo = "sha512"; 240 goto ecdsa; 241 242 case OID_id_ecdsa_with_sha3_256: 243 ctx->cert->sig->hash_algo = "sha3-256"; 244 goto ecdsa; 245 246 case OID_id_ecdsa_with_sha3_384: 247 ctx->cert->sig->hash_algo = "sha3-384"; 248 goto ecdsa; 249 250 case OID_id_ecdsa_with_sha3_512: 251 ctx->cert->sig->hash_algo = "sha3-512"; 252 goto ecdsa; 253 254 case OID_gost2012Signature256: 255 ctx->cert->sig->hash_algo = "streebog256"; 256 goto ecrdsa; 257 258 case OID_gost2012Signature512: 259 ctx->cert->sig->hash_algo = "streebog512"; 260 goto ecrdsa; 261 262 case OID_SM2_with_SM3: 263 ctx->cert->sig->hash_algo = "sm3"; 264 goto sm2; 265 } 266 267 rsa_pkcs1: 268 ctx->cert->sig->pkey_algo = "rsa"; 269 ctx->cert->sig->encoding = "pkcs1"; 270 ctx->sig_algo = ctx->last_oid; 271 return 0; 272 ecrdsa: 273 ctx->cert->sig->pkey_algo = "ecrdsa"; 274 ctx->cert->sig->encoding = "raw"; 275 ctx->sig_algo = ctx->last_oid; 276 return 0; 277 sm2: 278 ctx->cert->sig->pkey_algo = "sm2"; 279 ctx->cert->sig->encoding = "raw"; 280 ctx->sig_algo = ctx->last_oid; 281 return 0; 282 ecdsa: 283 ctx->cert->sig->pkey_algo = "ecdsa"; 284 ctx->cert->sig->encoding = "x962"; 285 ctx->sig_algo = ctx->last_oid; 286 return 0; 287 } 288 289 /* 290 * Note the whereabouts and type of the signature. 291 */ 292 int x509_note_signature(void *context, size_t hdrlen, 293 unsigned char tag, 294 const void *value, size_t vlen) 295 { 296 struct x509_parse_context *ctx = context; 297 298 pr_debug("Signature: alg=%u, size=%zu\n", ctx->last_oid, vlen); 299 300 /* 301 * In X.509 certificates, the signature's algorithm is stored in two 302 * places: inside the TBSCertificate (the data that is signed), and 303 * alongside the signature. These *must* match. 304 */ 305 if (ctx->last_oid != ctx->sig_algo) { 306 pr_warn("signatureAlgorithm (%u) differs from tbsCertificate.signature (%u)\n", 307 ctx->last_oid, ctx->sig_algo); 308 return -EINVAL; 309 } 310 311 if (strcmp(ctx->cert->sig->pkey_algo, "rsa") == 0 || 312 strcmp(ctx->cert->sig->pkey_algo, "ecrdsa") == 0 || 313 strcmp(ctx->cert->sig->pkey_algo, "sm2") == 0 || 314 strcmp(ctx->cert->sig->pkey_algo, "ecdsa") == 0) { 315 /* Discard the BIT STRING metadata */ 316 if (vlen < 1 || *(const u8 *)value != 0) 317 return -EBADMSG; 318 319 value++; 320 vlen--; 321 } 322 323 ctx->cert->raw_sig = value; 324 ctx->cert->raw_sig_size = vlen; 325 return 0; 326 } 327 328 /* 329 * Note the certificate serial number 330 */ 331 int x509_note_serial(void *context, size_t hdrlen, 332 unsigned char tag, 333 const void *value, size_t vlen) 334 { 335 struct x509_parse_context *ctx = context; 336 ctx->cert->raw_serial = value; 337 ctx->cert->raw_serial_size = vlen; 338 return 0; 339 } 340 341 /* 342 * Note some of the name segments from which we'll fabricate a name. 343 */ 344 int x509_extract_name_segment(void *context, size_t hdrlen, 345 unsigned char tag, 346 const void *value, size_t vlen) 347 { 348 struct x509_parse_context *ctx = context; 349 350 switch (ctx->last_oid) { 351 case OID_commonName: 352 ctx->cn_size = vlen; 353 ctx->cn_offset = (unsigned long)value - ctx->data; 354 break; 355 case OID_organizationName: 356 ctx->o_size = vlen; 357 ctx->o_offset = (unsigned long)value - ctx->data; 358 break; 359 case OID_email_address: 360 ctx->email_size = vlen; 361 ctx->email_offset = (unsigned long)value - ctx->data; 362 break; 363 default: 364 break; 365 } 366 367 return 0; 368 } 369 370 /* 371 * Fabricate and save the issuer and subject names 372 */ 373 static int x509_fabricate_name(struct x509_parse_context *ctx, size_t hdrlen, 374 unsigned char tag, 375 char **_name, size_t vlen) 376 { 377 const void *name, *data = (const void *)ctx->data; 378 size_t namesize; 379 char *buffer; 380 381 if (*_name) 382 return -EINVAL; 383 384 /* Empty name string if no material */ 385 if (!ctx->cn_size && !ctx->o_size && !ctx->email_size) { 386 buffer = kmalloc(1, GFP_KERNEL); 387 if (!buffer) 388 return -ENOMEM; 389 buffer[0] = 0; 390 goto done; 391 } 392 393 if (ctx->cn_size && ctx->o_size) { 394 /* Consider combining O and CN, but use only the CN if it is 395 * prefixed by the O, or a significant portion thereof. 396 */ 397 namesize = ctx->cn_size; 398 name = data + ctx->cn_offset; 399 if (ctx->cn_size >= ctx->o_size && 400 memcmp(data + ctx->cn_offset, data + ctx->o_offset, 401 ctx->o_size) == 0) 402 goto single_component; 403 if (ctx->cn_size >= 7 && 404 ctx->o_size >= 7 && 405 memcmp(data + ctx->cn_offset, data + ctx->o_offset, 7) == 0) 406 goto single_component; 407 408 buffer = kmalloc(ctx->o_size + 2 + ctx->cn_size + 1, 409 GFP_KERNEL); 410 if (!buffer) 411 return -ENOMEM; 412 413 memcpy(buffer, 414 data + ctx->o_offset, ctx->o_size); 415 buffer[ctx->o_size + 0] = ':'; 416 buffer[ctx->o_size + 1] = ' '; 417 memcpy(buffer + ctx->o_size + 2, 418 data + ctx->cn_offset, ctx->cn_size); 419 buffer[ctx->o_size + 2 + ctx->cn_size] = 0; 420 goto done; 421 422 } else if (ctx->cn_size) { 423 namesize = ctx->cn_size; 424 name = data + ctx->cn_offset; 425 } else if (ctx->o_size) { 426 namesize = ctx->o_size; 427 name = data + ctx->o_offset; 428 } else { 429 namesize = ctx->email_size; 430 name = data + ctx->email_offset; 431 } 432 433 single_component: 434 buffer = kmalloc(namesize + 1, GFP_KERNEL); 435 if (!buffer) 436 return -ENOMEM; 437 memcpy(buffer, name, namesize); 438 buffer[namesize] = 0; 439 440 done: 441 *_name = buffer; 442 ctx->cn_size = 0; 443 ctx->o_size = 0; 444 ctx->email_size = 0; 445 return 0; 446 } 447 448 int x509_note_issuer(void *context, size_t hdrlen, 449 unsigned char tag, 450 const void *value, size_t vlen) 451 { 452 struct x509_parse_context *ctx = context; 453 struct asymmetric_key_id *kid; 454 455 ctx->cert->raw_issuer = value; 456 ctx->cert->raw_issuer_size = vlen; 457 458 if (!ctx->cert->sig->auth_ids[2]) { 459 kid = asymmetric_key_generate_id(value, vlen, "", 0); 460 if (IS_ERR(kid)) 461 return PTR_ERR(kid); 462 ctx->cert->sig->auth_ids[2] = kid; 463 } 464 465 return x509_fabricate_name(ctx, hdrlen, tag, &ctx->cert->issuer, vlen); 466 } 467 468 int x509_note_subject(void *context, size_t hdrlen, 469 unsigned char tag, 470 const void *value, size_t vlen) 471 { 472 struct x509_parse_context *ctx = context; 473 ctx->cert->raw_subject = value; 474 ctx->cert->raw_subject_size = vlen; 475 return x509_fabricate_name(ctx, hdrlen, tag, &ctx->cert->subject, vlen); 476 } 477 478 /* 479 * Extract the parameters for the public key 480 */ 481 int x509_note_params(void *context, size_t hdrlen, 482 unsigned char tag, 483 const void *value, size_t vlen) 484 { 485 struct x509_parse_context *ctx = context; 486 487 /* 488 * AlgorithmIdentifier is used three times in the x509, we should skip 489 * first and ignore third, using second one which is after subject and 490 * before subjectPublicKey. 491 */ 492 if (!ctx->cert->raw_subject || ctx->key) 493 return 0; 494 ctx->params = value - hdrlen; 495 ctx->params_size = vlen + hdrlen; 496 return 0; 497 } 498 499 /* 500 * Extract the data for the public key algorithm 501 */ 502 int x509_extract_key_data(void *context, size_t hdrlen, 503 unsigned char tag, 504 const void *value, size_t vlen) 505 { 506 struct x509_parse_context *ctx = context; 507 enum OID oid; 508 509 ctx->key_algo = ctx->last_oid; 510 switch (ctx->last_oid) { 511 case OID_rsaEncryption: 512 ctx->cert->pub->pkey_algo = "rsa"; 513 break; 514 case OID_gost2012PKey256: 515 case OID_gost2012PKey512: 516 ctx->cert->pub->pkey_algo = "ecrdsa"; 517 break; 518 case OID_sm2: 519 ctx->cert->pub->pkey_algo = "sm2"; 520 break; 521 case OID_id_ecPublicKey: 522 if (parse_OID(ctx->params, ctx->params_size, &oid) != 0) 523 return -EBADMSG; 524 525 switch (oid) { 526 case OID_sm2: 527 ctx->cert->pub->pkey_algo = "sm2"; 528 break; 529 case OID_id_prime192v1: 530 ctx->cert->pub->pkey_algo = "ecdsa-nist-p192"; 531 break; 532 case OID_id_prime256v1: 533 ctx->cert->pub->pkey_algo = "ecdsa-nist-p256"; 534 break; 535 case OID_id_ansip384r1: 536 ctx->cert->pub->pkey_algo = "ecdsa-nist-p384"; 537 break; 538 case OID_id_ansip521r1: 539 ctx->cert->pub->pkey_algo = "ecdsa-nist-p521"; 540 break; 541 default: 542 return -ENOPKG; 543 } 544 break; 545 default: 546 return -ENOPKG; 547 } 548 549 /* Discard the BIT STRING metadata */ 550 if (vlen < 1 || *(const u8 *)value != 0) 551 return -EBADMSG; 552 ctx->key = value + 1; 553 ctx->key_size = vlen - 1; 554 return 0; 555 } 556 557 /* The keyIdentifier in AuthorityKeyIdentifier SEQUENCE is tag(CONT,PRIM,0) */ 558 #define SEQ_TAG_KEYID (ASN1_CONT << 6) 559 560 /* 561 * Process certificate extensions that are used to qualify the certificate. 562 */ 563 int x509_process_extension(void *context, size_t hdrlen, 564 unsigned char tag, 565 const void *value, size_t vlen) 566 { 567 struct x509_parse_context *ctx = context; 568 struct asymmetric_key_id *kid; 569 const unsigned char *v = value; 570 571 pr_debug("Extension: %u\n", ctx->last_oid); 572 573 if (ctx->last_oid == OID_subjectKeyIdentifier) { 574 /* Get hold of the key fingerprint */ 575 if (ctx->cert->skid || vlen < 3) 576 return -EBADMSG; 577 if (v[0] != ASN1_OTS || v[1] != vlen - 2) 578 return -EBADMSG; 579 v += 2; 580 vlen -= 2; 581 582 ctx->cert->raw_skid_size = vlen; 583 ctx->cert->raw_skid = v; 584 kid = asymmetric_key_generate_id(v, vlen, "", 0); 585 if (IS_ERR(kid)) 586 return PTR_ERR(kid); 587 ctx->cert->skid = kid; 588 pr_debug("subjkeyid %*phN\n", kid->len, kid->data); 589 return 0; 590 } 591 592 if (ctx->last_oid == OID_keyUsage) { 593 /* 594 * Get hold of the keyUsage bit string 595 * v[1] is the encoding size 596 * (Expect either 0x02 or 0x03, making it 1 or 2 bytes) 597 * v[2] is the number of unused bits in the bit string 598 * (If >= 3 keyCertSign is missing when v[1] = 0x02) 599 * v[3] and possibly v[4] contain the bit string 600 * 601 * From RFC 5280 4.2.1.3: 602 * 0x04 is where keyCertSign lands in this bit string 603 * 0x80 is where digitalSignature lands in this bit string 604 */ 605 if (v[0] != ASN1_BTS) 606 return -EBADMSG; 607 if (vlen < 4) 608 return -EBADMSG; 609 if (v[2] >= 8) 610 return -EBADMSG; 611 if (v[3] & 0x80) 612 ctx->cert->pub->key_eflags |= 1 << KEY_EFLAG_DIGITALSIG; 613 if (v[1] == 0x02 && v[2] <= 2 && (v[3] & 0x04)) 614 ctx->cert->pub->key_eflags |= 1 << KEY_EFLAG_KEYCERTSIGN; 615 else if (vlen > 4 && v[1] == 0x03 && (v[3] & 0x04)) 616 ctx->cert->pub->key_eflags |= 1 << KEY_EFLAG_KEYCERTSIGN; 617 return 0; 618 } 619 620 if (ctx->last_oid == OID_authorityKeyIdentifier) { 621 /* Get hold of the CA key fingerprint */ 622 ctx->raw_akid = v; 623 ctx->raw_akid_size = vlen; 624 return 0; 625 } 626 627 if (ctx->last_oid == OID_basicConstraints) { 628 /* 629 * Get hold of the basicConstraints 630 * v[1] is the encoding size 631 * (Expect 0x2 or greater, making it 1 or more bytes) 632 * v[2] is the encoding type 633 * (Expect an ASN1_BOOL for the CA) 634 * v[3] is the contents of the ASN1_BOOL 635 * (Expect 1 if the CA is TRUE) 636 * vlen should match the entire extension size 637 */ 638 if (v[0] != (ASN1_CONS_BIT | ASN1_SEQ)) 639 return -EBADMSG; 640 if (vlen < 2) 641 return -EBADMSG; 642 if (v[1] != vlen - 2) 643 return -EBADMSG; 644 if (vlen >= 4 && v[1] != 0 && v[2] == ASN1_BOOL && v[3] == 1) 645 ctx->cert->pub->key_eflags |= 1 << KEY_EFLAG_CA; 646 return 0; 647 } 648 649 return 0; 650 } 651 652 /** 653 * x509_decode_time - Decode an X.509 time ASN.1 object 654 * @_t: The time to fill in 655 * @hdrlen: The length of the object header 656 * @tag: The object tag 657 * @value: The object value 658 * @vlen: The size of the object value 659 * 660 * Decode an ASN.1 universal time or generalised time field into a struct the 661 * kernel can handle and check it for validity. The time is decoded thus: 662 * 663 * [RFC5280 §4.1.2.5] 664 * CAs conforming to this profile MUST always encode certificate validity 665 * dates through the year 2049 as UTCTime; certificate validity dates in 666 * 2050 or later MUST be encoded as GeneralizedTime. Conforming 667 * applications MUST be able to process validity dates that are encoded in 668 * either UTCTime or GeneralizedTime. 669 */ 670 int x509_decode_time(time64_t *_t, size_t hdrlen, 671 unsigned char tag, 672 const unsigned char *value, size_t vlen) 673 { 674 static const unsigned char month_lengths[] = { 31, 28, 31, 30, 31, 30, 675 31, 31, 30, 31, 30, 31 }; 676 const unsigned char *p = value; 677 unsigned year, mon, day, hour, min, sec, mon_len; 678 679 #define dec2bin(X) ({ unsigned char x = (X) - '0'; if (x > 9) goto invalid_time; x; }) 680 #define DD2bin(P) ({ unsigned x = dec2bin(P[0]) * 10 + dec2bin(P[1]); P += 2; x; }) 681 682 if (tag == ASN1_UNITIM) { 683 /* UTCTime: YYMMDDHHMMSSZ */ 684 if (vlen != 13) 685 goto unsupported_time; 686 year = DD2bin(p); 687 if (year >= 50) 688 year += 1900; 689 else 690 year += 2000; 691 } else if (tag == ASN1_GENTIM) { 692 /* GenTime: YYYYMMDDHHMMSSZ */ 693 if (vlen != 15) 694 goto unsupported_time; 695 year = DD2bin(p) * 100 + DD2bin(p); 696 if (year >= 1950 && year <= 2049) 697 goto invalid_time; 698 } else { 699 goto unsupported_time; 700 } 701 702 mon = DD2bin(p); 703 day = DD2bin(p); 704 hour = DD2bin(p); 705 min = DD2bin(p); 706 sec = DD2bin(p); 707 708 if (*p != 'Z') 709 goto unsupported_time; 710 711 if (year < 1970 || 712 mon < 1 || mon > 12) 713 goto invalid_time; 714 715 mon_len = month_lengths[mon - 1]; 716 if (mon == 2) { 717 if (year % 4 == 0) { 718 mon_len = 29; 719 if (year % 100 == 0) { 720 mon_len = 28; 721 if (year % 400 == 0) 722 mon_len = 29; 723 } 724 } 725 } 726 727 if (day < 1 || day > mon_len || 728 hour > 24 || /* ISO 8601 permits 24:00:00 as midnight tomorrow */ 729 min > 59 || 730 sec > 60) /* ISO 8601 permits leap seconds [X.680 46.3] */ 731 goto invalid_time; 732 733 *_t = mktime64(year, mon, day, hour, min, sec); 734 return 0; 735 736 unsupported_time: 737 pr_debug("Got unsupported time [tag %02x]: '%*phN'\n", 738 tag, (int)vlen, value); 739 return -EBADMSG; 740 invalid_time: 741 pr_debug("Got invalid time [tag %02x]: '%*phN'\n", 742 tag, (int)vlen, value); 743 return -EBADMSG; 744 } 745 EXPORT_SYMBOL_GPL(x509_decode_time); 746 747 int x509_note_not_before(void *context, size_t hdrlen, 748 unsigned char tag, 749 const void *value, size_t vlen) 750 { 751 struct x509_parse_context *ctx = context; 752 return x509_decode_time(&ctx->cert->valid_from, hdrlen, tag, value, vlen); 753 } 754 755 int x509_note_not_after(void *context, size_t hdrlen, 756 unsigned char tag, 757 const void *value, size_t vlen) 758 { 759 struct x509_parse_context *ctx = context; 760 return x509_decode_time(&ctx->cert->valid_to, hdrlen, tag, value, vlen); 761 } 762 763 /* 764 * Note a key identifier-based AuthorityKeyIdentifier 765 */ 766 int x509_akid_note_kid(void *context, size_t hdrlen, 767 unsigned char tag, 768 const void *value, size_t vlen) 769 { 770 struct x509_parse_context *ctx = context; 771 struct asymmetric_key_id *kid; 772 773 pr_debug("AKID: keyid: %*phN\n", (int)vlen, value); 774 775 if (ctx->cert->sig->auth_ids[1]) 776 return 0; 777 778 kid = asymmetric_key_generate_id(value, vlen, "", 0); 779 if (IS_ERR(kid)) 780 return PTR_ERR(kid); 781 pr_debug("authkeyid %*phN\n", kid->len, kid->data); 782 ctx->cert->sig->auth_ids[1] = kid; 783 return 0; 784 } 785 786 /* 787 * Note a directoryName in an AuthorityKeyIdentifier 788 */ 789 int x509_akid_note_name(void *context, size_t hdrlen, 790 unsigned char tag, 791 const void *value, size_t vlen) 792 { 793 struct x509_parse_context *ctx = context; 794 795 pr_debug("AKID: name: %*phN\n", (int)vlen, value); 796 797 ctx->akid_raw_issuer = value; 798 ctx->akid_raw_issuer_size = vlen; 799 return 0; 800 } 801 802 /* 803 * Note a serial number in an AuthorityKeyIdentifier 804 */ 805 int x509_akid_note_serial(void *context, size_t hdrlen, 806 unsigned char tag, 807 const void *value, size_t vlen) 808 { 809 struct x509_parse_context *ctx = context; 810 struct asymmetric_key_id *kid; 811 812 pr_debug("AKID: serial: %*phN\n", (int)vlen, value); 813 814 if (!ctx->akid_raw_issuer || ctx->cert->sig->auth_ids[0]) 815 return 0; 816 817 kid = asymmetric_key_generate_id(value, 818 vlen, 819 ctx->akid_raw_issuer, 820 ctx->akid_raw_issuer_size); 821 if (IS_ERR(kid)) 822 return PTR_ERR(kid); 823 824 pr_debug("authkeyid %*phN\n", kid->len, kid->data); 825 ctx->cert->sig->auth_ids[0] = kid; 826 return 0; 827 } 828