if(operation == ASN1_OP_FREE_POST) { CMS_SignerInfo *si = (CMS_SignerInfo *)*pval; if (si->pkey) EVP_PKEY_free(si->pkey); if (si->signer) X509_free(si->signer); } return 1; } ASN1_SEQUENCE_cb(CMS_SignerInfo, cms_si_cb) = { ASN1_SIMPLE(CMS_SignerInfo, version, LONG), ASN1_SIMPLE(CMS_SignerInfo, sid, CMS_SignerIdentifier), ASN1_SIMPLE(CMS_SignerInfo, digestAlgorithm, X509_ALGOR), ASN1_IMP_SET_OF_OPT(CMS_SignerInfo, signedAttrs, X509_ATTRIBUTE, 0), ASN1_SIMPLE(CMS_SignerInfo, signatureAlgorithm, X509_ALGOR), ASN1_SIMPLE(CMS_SignerInfo, signature, ASN1_OCTET_STRING), ASN1_IMP_SET_OF_OPT(CMS_SignerInfo, unsignedAttrs, X509_ATTRIBUTE, 1) } ASN1_SEQUENCE_END_cb(CMS_SignerInfo, CMS_SignerInfo) ASN1_SEQUENCE(CMS_OtherRevocationInfoFormat) = { ASN1_SIMPLE(CMS_OtherRevocationInfoFormat, otherRevInfoFormat, ASN1_OBJECT), ASN1_OPT(CMS_OtherRevocationInfoFormat, otherRevInfo, ASN1_ANY) } ASN1_SEQUENCE_END(CMS_OtherRevocationInfoFormat) ASN1_CHOICE(CMS_RevocationInfoChoice) = { ASN1_SIMPLE(CMS_RevocationInfoChoice, d.crl, X509_CRL), ASN1_IMP(CMS_RevocationInfoChoice, d.other, CMS_OtherRevocationInfoFormat, 1) } ASN1_CHOICE_END(CMS_RevocationInfoChoice)
if (operation == ASN1_OP_NEW_POST) { rinf->attributes = sk_X509_ATTRIBUTE_new_null(); if (!rinf->attributes) return 0; } return 1; } ASN1_SEQUENCE_enc(X509_REQ_INFO, enc, rinf_cb) = { ASN1_SIMPLE(X509_REQ_INFO, version, ASN1_INTEGER), ASN1_SIMPLE(X509_REQ_INFO, subject, X509_NAME), ASN1_SIMPLE(X509_REQ_INFO, pubkey, X509_PUBKEY), /* This isn't really OPTIONAL but it gets round invalid * encodings */ ASN1_IMP_SET_OF_OPT(X509_REQ_INFO, attributes, X509_ATTRIBUTE, 0) } ASN1_SEQUENCE_END_enc(X509_REQ_INFO, X509_REQ_INFO) IMPLEMENT_ASN1_FUNCTIONS(X509_REQ_INFO) ASN1_SEQUENCE_ref(X509_REQ, 0) = { ASN1_EMBED(X509_REQ, req_info, X509_REQ_INFO), ASN1_EMBED(X509_REQ, sig_alg, X509_ALGOR), ASN1_SIMPLE(X509_REQ, signature, ASN1_BIT_STRING) } ASN1_SEQUENCE_END_ref(X509_REQ, X509_REQ) IMPLEMENT_ASN1_FUNCTIONS(X509_REQ) IMPLEMENT_ASN1_DUP_FUNCTION(X509_REQ)
* ([email protected]). This product includes software written by Tim * Hudson ([email protected]). * */ #include "cryptlib.h" #include <openssl/asn1t.h> #include <openssl/x509.h> /* Minor tweak to operation: zero private key data */ static int pkey_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it) { /* Since the structure must still be valid use ASN1_OP_FREE_PRE */ if(operation == ASN1_OP_FREE_PRE) { PKCS8_PRIV_KEY_INFO *key = (PKCS8_PRIV_KEY_INFO *)*pval; if (key->pkey->value.octet_string) OPENSSL_cleanse(key->pkey->value.octet_string->data, key->pkey->value.octet_string->length); } return 1; } ASN1_SEQUENCE_cb(PKCS8_PRIV_KEY_INFO, pkey_cb) = { ASN1_SIMPLE(PKCS8_PRIV_KEY_INFO, version, ASN1_INTEGER), ASN1_SIMPLE(PKCS8_PRIV_KEY_INFO, pkeyalg, X509_ALGOR), ASN1_SIMPLE(PKCS8_PRIV_KEY_INFO, pkey, ASN1_ANY), ASN1_IMP_SET_OF_OPT(PKCS8_PRIV_KEY_INFO, attributes, X509_ATTRIBUTE, 0) } ASN1_SEQUENCE_END_cb(PKCS8_PRIV_KEY_INFO, PKCS8_PRIV_KEY_INFO) IMPLEMENT_ASN1_FUNCTIONS(PKCS8_PRIV_KEY_INFO)
ASN1_NDEF_SEQUENCE(CPK_CMS) = { ASN1_SIMPLE(CPK_CMS, type, ASN1_OBJECT), ASN1_ADB_OBJECT(CPK_CMS) }ASN1_NDEF_SEQUENCE_END(CPK_CMS) IMPLEMENT_ASN1_FUNCTIONS(CPK_CMS) IMPLEMENT_ASN1_NDEF_FUNCTION(CPK_CMS) IMPLEMENT_ASN1_DUP_FUNCTION(CPK_CMS) ASN1_NDEF_SEQUENCE(CPK_SIGNED) = { ASN1_SIMPLE(CPK_SIGNED, version, LONG), ASN1_SET_OF(CPK_SIGNED, digest_algors, X509_ALGOR), ASN1_SIMPLE(CPK_SIGNED, contents, CPK_CMS), ASN1_IMP_SEQUENCE_OF_OPT(CPK_SIGNED, cert, X509, 0), ASN1_IMP_SET_OF_OPT(CPK_SIGNED, crl, X509_CRL, 1), ASN1_SET_OF(CPK_SIGNED, signer_infos, CPK_SIGNER_INFO) } ASN1_NDEF_SEQUENCE_END(CPK_SIGNED) IMPLEMENT_ASN1_FUNCTIONS(CPK_SIGNED) ASN1_SEQUENCE(CPK_SIGNER_INFO) = { ASN1_SIMPLE(CPK_SIGNER_INFO, version, LONG), ASN1_SIMPLE(CPK_SIGNER_INFO, signer, X509_NAME), ASN1_SIMPLE(CPK_SIGNER_INFO, digest_algor, X509_ALGOR), ASN1_IMP_SEQUENCE_OF_OPT(CPK_SIGNER_INFO, signed_attr, X509_ATTRIBUTE, 0), ASN1_SIMPLE(CPK_SIGNER_INFO, sign_algor, X509_ALGOR), ASN1_SIMPLE(CPK_SIGNER_INFO, signature, ASN1_OCTET_STRING), ASN1_IMP_SET_OF_OPT(CPK_SIGNER_INFO, unsigned_attr, X509_ATTRIBUTE, 1) } ASN1_SEQUENCE_END(CPK_SIGNER_INFO) IMPLEMENT_ASN1_FUNCTIONS(CPK_SIGNER_INFO)