2018-05-04 16:08:28 +02:00
|
|
|
/* This Source Code Form is subject to the terms of the Mozilla Public
|
|
|
|
* License, v. 2.0. If a copy of the MPL was not distributed with this
|
|
|
|
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
|
2015-10-21 05:03:22 +02:00
|
|
|
/*
|
|
|
|
* pkix_build.h
|
|
|
|
*
|
|
|
|
* Header file for buildChain function
|
|
|
|
*
|
|
|
|
*/
|
|
|
|
|
|
|
|
#ifndef _PKIX_BUILD_H
|
|
|
|
#define _PKIX_BUILD_H
|
|
|
|
#include "pkix_tools.h"
|
cherry-picked mozilla NSS upstream changes (to rev f7a4c771997e, which is on par with 3.16.1 but without windows rand() changes):
9934c8faef29, 3c3b381c4865, 5a67f6beee9a, 1b1eb6d77728, a8b668fd72f7, bug962760, bug743700, bug857304, bug972653, bug972450, bug971358, bug903885, bug977073, bug976111, bug949939, bug947653, bug947572, bug903885, bug979106, bug966596, bug979004, bug979752, bug980848, bug938369, bug981170, bug668130, bug974693, bug975056, bug979132, bug370717, bug979070, bug985070, bug900067, bug977673, bug519255, bug989558, bug557299, bug987263, bug369802, a751a5146718, bug992343, bug952572, bug979703, bug994883, bug994869, bug993489, bug984608, bug977869, bug667371, bug672828, bug793347, bug977869
2018-07-10 17:07:31 +02:00
|
|
|
#ifndef NSS_PKIX_NO_LDAP
|
2015-10-21 05:03:22 +02:00
|
|
|
#include "pkix_pl_ldapt.h"
|
cherry-picked mozilla NSS upstream changes (to rev f7a4c771997e, which is on par with 3.16.1 but without windows rand() changes):
9934c8faef29, 3c3b381c4865, 5a67f6beee9a, 1b1eb6d77728, a8b668fd72f7, bug962760, bug743700, bug857304, bug972653, bug972450, bug971358, bug903885, bug977073, bug976111, bug949939, bug947653, bug947572, bug903885, bug979106, bug966596, bug979004, bug979752, bug980848, bug938369, bug981170, bug668130, bug974693, bug975056, bug979132, bug370717, bug979070, bug985070, bug900067, bug977673, bug519255, bug989558, bug557299, bug987263, bug369802, a751a5146718, bug992343, bug952572, bug979703, bug994883, bug994869, bug993489, bug984608, bug977869, bug667371, bug672828, bug793347, bug977869
2018-07-10 17:07:31 +02:00
|
|
|
#endif
|
2015-10-21 05:03:22 +02:00
|
|
|
#include "pkix_ekuchecker.h"
|
|
|
|
|
|
|
|
#ifdef __cplusplus
|
|
|
|
extern "C" {
|
|
|
|
#endif
|
|
|
|
|
|
|
|
typedef enum {
|
|
|
|
BUILD_SHORTCUTPENDING,
|
|
|
|
BUILD_INITIAL,
|
|
|
|
BUILD_TRYAIA,
|
|
|
|
BUILD_AIAPENDING,
|
|
|
|
BUILD_COLLECTINGCERTS,
|
|
|
|
BUILD_GATHERPENDING,
|
|
|
|
BUILD_CERTVALIDATING,
|
|
|
|
BUILD_ABANDONNODE,
|
|
|
|
BUILD_DATEPREP,
|
|
|
|
BUILD_CHECKTRUSTED,
|
|
|
|
BUILD_CHECKTRUSTED2,
|
|
|
|
BUILD_ADDTOCHAIN,
|
|
|
|
BUILD_VALCHAIN,
|
|
|
|
BUILD_VALCHAIN2,
|
|
|
|
BUILD_EXTENDCHAIN,
|
|
|
|
BUILD_GETNEXTCERT
|
|
|
|
} BuildStatus;
|
|
|
|
|
|
|
|
typedef struct BuildConstantsStruct BuildConstants;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* These fields (the ones that are objects) are not reference-counted
|
|
|
|
* in *each* state, but only in the root, the state that has no parent.
|
|
|
|
* That saves time in creation and destruction of child states, but is
|
|
|
|
* safe enough since they are constants.
|
|
|
|
*/
|
|
|
|
struct BuildConstantsStruct {
|
|
|
|
PKIX_UInt32 numAnchors;
|
|
|
|
PKIX_UInt32 numCertStores;
|
|
|
|
PKIX_UInt32 numHintCerts;
|
|
|
|
PKIX_UInt32 maxDepth;
|
|
|
|
PKIX_UInt32 maxFanout;
|
|
|
|
PKIX_UInt32 maxTime;
|
|
|
|
PKIX_ProcessingParams *procParams;
|
|
|
|
PKIX_PL_Date *testDate;
|
|
|
|
PKIX_PL_Date *timeLimit;
|
|
|
|
PKIX_PL_Cert *targetCert;
|
|
|
|
PKIX_PL_PublicKey *targetPubKey;
|
|
|
|
PKIX_List *certStores;
|
|
|
|
PKIX_List *anchors;
|
|
|
|
PKIX_List *userCheckers;
|
|
|
|
PKIX_List *hintCerts;
|
|
|
|
PKIX_RevocationChecker *revChecker;
|
|
|
|
PKIX_PL_AIAMgr *aiaMgr;
|
|
|
|
PKIX_Boolean useAIAForCertFetching;
|
2018-05-04 16:08:28 +02:00
|
|
|
PKIX_Boolean trustOnlyUserAnchors;
|
2015-10-21 05:03:22 +02:00
|
|
|
};
|
|
|
|
|
|
|
|
struct PKIX_ForwardBuilderStateStruct{
|
|
|
|
BuildStatus status;
|
|
|
|
PKIX_Int32 traversedCACerts;
|
|
|
|
PKIX_UInt32 certStoreIndex;
|
|
|
|
PKIX_UInt32 numCerts;
|
|
|
|
PKIX_UInt32 numAias;
|
|
|
|
PKIX_UInt32 certIndex;
|
|
|
|
PKIX_UInt32 aiaIndex;
|
|
|
|
PKIX_UInt32 certCheckedIndex;
|
|
|
|
PKIX_UInt32 checkerIndex;
|
|
|
|
PKIX_UInt32 hintCertIndex;
|
|
|
|
PKIX_UInt32 numFanout;
|
|
|
|
PKIX_UInt32 numDepth;
|
|
|
|
PKIX_UInt32 reasonCode;
|
|
|
|
PKIX_Boolean canBeCached;
|
|
|
|
PKIX_Boolean useOnlyLocal;
|
|
|
|
PKIX_Boolean revChecking;
|
|
|
|
PKIX_Boolean usingHintCerts;
|
|
|
|
PKIX_Boolean certLoopingDetected;
|
|
|
|
PKIX_PL_Date *validityDate;
|
|
|
|
PKIX_PL_Cert *prevCert;
|
|
|
|
PKIX_PL_Cert *candidateCert;
|
|
|
|
PKIX_List *traversedSubjNames;
|
|
|
|
PKIX_List *trustChain;
|
|
|
|
PKIX_List *aia;
|
|
|
|
PKIX_List *candidateCerts;
|
|
|
|
PKIX_List *reversedCertChain;
|
|
|
|
PKIX_List *checkedCritExtOIDs;
|
|
|
|
PKIX_List *checkerChain;
|
|
|
|
PKIX_CertSelector *certSel;
|
|
|
|
PKIX_VerifyNode *verifyNode;
|
|
|
|
void *client; /* messageHandler, such as LDAPClient */
|
|
|
|
PKIX_ForwardBuilderState *parentState;
|
|
|
|
BuildConstants buildConstants;
|
|
|
|
};
|
|
|
|
|
|
|
|
/* --Private-Functions-------------------------------------------- */
|
|
|
|
|
|
|
|
PKIX_Error *
|
|
|
|
pkix_ForwardBuilderState_RegisterSelf(void *plContext);
|
|
|
|
|
|
|
|
PKIX_Error *
|
|
|
|
PKIX_Build_GetNBIOContext(void *state, void **pNBIOContext, void *plContext);
|
|
|
|
|
|
|
|
#ifdef __cplusplus
|
|
|
|
}
|
|
|
|
#endif
|
|
|
|
|
|
|
|
#endif /* _PKIX_BUILD_H */
|