1 /* SPDX-License-Identifier: GPL-2.0-or-later */ 2 /* X.509 certificate parser internal definitions 3 * 4 * Copyright (C) 2012 Red Hat, Inc. All Rights Reserved. 5 * Written by David Howells (dhowells@redhat.com) 6 */ 7 8 #include <linux/cleanup.h> 9 #include <linux/time.h> 10 #include <crypto/public_key.h> 11 #include <keys/asymmetric-type.h> 12 13 struct x509_certificate { 14 struct x509_certificate *next; 15 struct x509_certificate *signer; /* Certificate that signed this one */ 16 struct public_key *pub; /* Public key details */ 17 struct public_key_signature *sig; /* Signature parameters */ 18 char *issuer; /* Name of certificate issuer */ 19 char *subject; /* Name of certificate subject */ 20 struct asymmetric_key_id *id; /* Issuer + Serial number */ 21 struct asymmetric_key_id *skid; /* Subject + subjectKeyId (optional) */ 22 time64_t valid_from; 23 time64_t valid_to; 24 const void *tbs; /* Signed data */ 25 unsigned tbs_size; /* Size of signed data */ 26 unsigned raw_sig_size; /* Size of signature */ 27 const void *raw_sig; /* Signature data */ 28 const void *raw_serial; /* Raw serial number in ASN.1 */ 29 unsigned raw_serial_size; 30 unsigned raw_issuer_size; 31 const void *raw_issuer; /* Raw issuer name in ASN.1 */ 32 const void *raw_subject; /* Raw subject name in ASN.1 */ 33 unsigned raw_subject_size; 34 unsigned raw_skid_size; 35 const void *raw_skid; /* Raw subjectKeyId in ASN.1 */ 36 unsigned index; 37 bool seen; /* Infinite recursion prevention */ 38 bool verified; 39 bool self_signed; /* T if self-signed (check unsupported_sig too) */ 40 bool unsupported_sig; /* T if signature uses unsupported crypto */ 41 bool blacklisted; 42 }; 43 44 /* 45 * x509_cert_parser.c 46 */ 47 extern void x509_free_certificate(struct x509_certificate *cert); 48 DEFINE_FREE(x509_free_certificate, struct x509_certificate *, 49 if (!IS_ERR(_T)) x509_free_certificate(_T)) 50 extern struct x509_certificate *x509_cert_parse(const void *data, size_t datalen); 51 extern int x509_decode_time(time64_t *_t, size_t hdrlen, 52 unsigned char tag, 53 const unsigned char *value, size_t vlen); 54 55 /* 56 * x509_public_key.c 57 */ 58 extern int x509_get_sig_params(struct x509_certificate *cert); 59 extern int x509_check_for_self_signed(struct x509_certificate *cert); 60