Nayna Jain | c9deb18 | 2020-11-16 19:03:12 +0000 | [diff] [blame^] | 1 | /** |
| 2 | * \file pkcs7.h |
| 3 | * |
| 4 | * \brief PKCS7 generic defines and structures |
| 5 | * https://tools.ietf.org/html/rfc2315 |
| 6 | */ |
| 7 | /* |
| 8 | * Copyright (C) 2019, IBM Corp, All Rights Reserved |
| 9 | * SPDX-License-Identifier: Apache-2.0 |
| 10 | * |
| 11 | * Licensed under the Apache License, Version 2.0 (the "License"); you may |
| 12 | * not use this file except in compliance with the License. |
| 13 | * You may obtain a copy of the License at |
| 14 | * |
| 15 | * http://www.apache.org/licenses/LICENSE-2.0 |
| 16 | * |
| 17 | * Unless required by applicable law or agreed to in writing, software |
| 18 | * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT |
| 19 | * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. |
| 20 | * See the License for the specific language governing permissions and |
| 21 | * limitations under the License. |
| 22 | * |
| 23 | * This file is part of mbed TLS (https://tls.mbed.org) |
| 24 | */ |
| 25 | |
| 26 | /** |
| 27 | * Note: For the time being, this application of the PKCS7 cryptographic |
| 28 | * message syntax is a partial implementation of RFC 2315. |
| 29 | * Differences include: |
| 30 | * - The RFC specifies 6 different content types. The only type currently |
| 31 | * supported in MbedTLS is the signed data content type. |
| 32 | * - The only supported PKCS7 Signed Data syntax version is version 1 |
| 33 | * - The RFC specifies support for BER. This application is limited to |
| 34 | * DER only. |
| 35 | * - The RFC specifies that multiple digest algorithms can be specified |
| 36 | * in the Signed Data type. Only one digest algorithm is supported in MbedTLS. |
| 37 | * - The RFC specifies the Signed Data certificate format can be |
| 38 | * X509 or PKCS6. The only type currently supported in MbedTLS is X509. |
| 39 | * - The RFC specifies the Signed Data type can contain |
| 40 | * certificate-revocation lists (crls). This application has no support |
| 41 | * for crls so it is assumed to be an empty list. |
| 42 | * - The RFC specifies support for multiple signers. This application only |
| 43 | * supports the Signed Data type with a single signer. |
| 44 | */ |
| 45 | |
| 46 | #ifndef MBEDTLS_PKCS7_H |
| 47 | #define MBEDTLS_PKCS7_H |
| 48 | |
| 49 | #include "mbedtls/build_info.h" |
| 50 | |
| 51 | #include "asn1.h" |
| 52 | #include "x509.h" |
| 53 | #include "x509_crt.h" |
| 54 | |
| 55 | /** |
| 56 | * \name PKCS7 Module Error codes |
| 57 | * \{ |
| 58 | */ |
| 59 | #define MBEDTLS_ERR_PKCS7_INVALID_FORMAT -0x5300 /**< The format is invalid, e.g. different type expected. */ |
| 60 | #define MBEDTLS_ERR_PKCS7_FEATURE_UNAVAILABLE -0x53F0 /**< Unavailable feature, e.g. anything other than signed data. */ |
| 61 | #define MBEDTLS_ERR_PKCS7_INVALID_VERSION -0x5400 /**< The PKCS7 version element is invalid or cannot be parsed. */ |
| 62 | #define MBEDTLS_ERR_PKCS7_INVALID_CONTENT_INFO -0x54F0 /**< The PKCS7 content info invalid or cannot be parsed. */ |
| 63 | #define MBEDTLS_ERR_PKCS7_INVALID_ALG -0x5500 /**< The algorithm tag or value is invalid or cannot be parsed. */ |
| 64 | #define MBEDTLS_ERR_PKCS7_INVALID_CERT -0x55F0 /**< The certificate tag or value is invalid or cannot be parsed. */ |
| 65 | #define MBEDTLS_ERR_PKCS7_INVALID_SIGNATURE -0x5600 /**< Error parsing the signature */ |
| 66 | #define MBEDTLS_ERR_PKCS7_INVALID_SIGNER_INFO -0x56F0 /**< Error parsing the signer's info */ |
| 67 | #define MBEDTLS_ERR_PKCS7_BAD_INPUT_DATA -0x5700 /**< Input invalid. */ |
| 68 | #define MBEDTLS_ERR_PKCS7_ALLOC_FAILED -0x57F0 /**< Allocation of memory failed. */ |
| 69 | #define MBEDTLS_ERR_PKCS7_VERIFY_FAIL -0x5800 /**< Verification Failed */ |
| 70 | /* \} name */ |
| 71 | |
| 72 | /** |
| 73 | * \name PKCS7 Supported Version |
| 74 | * \{ |
| 75 | */ |
| 76 | #define MBEDTLS_PKCS7_SUPPORTED_VERSION 0x01 |
| 77 | /* \} name */ |
| 78 | |
| 79 | #ifdef __cplusplus |
| 80 | extern "C" { |
| 81 | #endif |
| 82 | |
| 83 | /** |
| 84 | * Type-length-value structure that allows for ASN1 using DER. |
| 85 | */ |
| 86 | typedef mbedtls_asn1_buf mbedtls_pkcs7_buf; |
| 87 | |
| 88 | /** |
| 89 | * Container for ASN1 named information objects. |
| 90 | * It allows for Relative Distinguished Names (e.g. cn=localhost,ou=code,etc.). |
| 91 | */ |
| 92 | typedef mbedtls_asn1_named_data mbedtls_pkcs7_name; |
| 93 | |
| 94 | /** |
| 95 | * Container for a sequence of ASN.1 items |
| 96 | */ |
| 97 | typedef mbedtls_asn1_sequence mbedtls_pkcs7_sequence; |
| 98 | |
| 99 | /** |
| 100 | * Structure holding PKCS7 signer info |
| 101 | */ |
| 102 | typedef struct mbedtls_pkcs7_signer_info |
| 103 | { |
| 104 | int version; |
| 105 | mbedtls_x509_buf serial; |
| 106 | mbedtls_x509_name issuer; |
| 107 | mbedtls_x509_buf issuer_raw; |
| 108 | mbedtls_x509_buf alg_identifier; |
| 109 | mbedtls_x509_buf sig_alg_identifier; |
| 110 | mbedtls_x509_buf sig; |
| 111 | struct mbedtls_pkcs7_signer_info *next; |
| 112 | } |
| 113 | mbedtls_pkcs7_signer_info; |
| 114 | |
| 115 | /** |
| 116 | * Structure holding attached data as part of PKCS7 signed data format |
| 117 | */ |
| 118 | typedef struct mbedtls_pkcs7_data |
| 119 | { |
| 120 | mbedtls_pkcs7_buf oid; |
| 121 | mbedtls_pkcs7_buf data; |
| 122 | } |
| 123 | mbedtls_pkcs7_data; |
| 124 | |
| 125 | /** |
| 126 | * Structure holding the signed data section |
| 127 | */ |
| 128 | typedef struct mbedtls_pkcs7_signed_data |
| 129 | { |
| 130 | int version; |
| 131 | mbedtls_pkcs7_buf digest_alg_identifiers; |
| 132 | struct mbedtls_pkcs7_data content; |
| 133 | int no_of_certs; |
| 134 | mbedtls_x509_crt certs; |
| 135 | int no_of_crls; |
| 136 | mbedtls_x509_crl crl; |
| 137 | int no_of_signers; |
| 138 | mbedtls_pkcs7_signer_info signers; |
| 139 | } |
| 140 | mbedtls_pkcs7_signed_data; |
| 141 | |
| 142 | /** |
| 143 | * Structure holding PKCS7 structure, only signed data for now |
| 144 | */ |
| 145 | typedef struct mbedtls_pkcs7 |
| 146 | { |
| 147 | mbedtls_pkcs7_buf raw; |
| 148 | mbedtls_pkcs7_buf content_type_oid; |
| 149 | mbedtls_pkcs7_signed_data signed_data; |
| 150 | } |
| 151 | mbedtls_pkcs7; |
| 152 | |
| 153 | /** |
| 154 | * \brief Initialize pkcs7 structure. |
| 155 | * |
| 156 | * \param pkcs7 pkcs7 structure. |
| 157 | */ |
| 158 | void mbedtls_pkcs7_init( mbedtls_pkcs7 *pkcs7 ); |
| 159 | |
| 160 | /** |
| 161 | * \brief Parse a single DER formatted pkcs7 content. |
| 162 | * |
| 163 | * \param pkcs7 The pkcs7 structure to be filled by parser for the output. |
| 164 | * \param buf The buffer holding the DER encoded pkcs7. |
| 165 | * \param buflen The size in Bytes of \p buf. |
| 166 | * |
| 167 | * \note This function makes an internal copy of the PKCS7 buffer |
| 168 | * \p buf. In particular, \p buf may be destroyed or reused |
| 169 | * after this call returns. |
| 170 | * |
| 171 | * \return \c 0, if successful. |
| 172 | * \return A negative error code on failure. |
| 173 | */ |
| 174 | int mbedtls_pkcs7_parse_der( mbedtls_pkcs7 *pkcs7, const unsigned char *buf, |
| 175 | const size_t buflen ); |
| 176 | |
| 177 | /** |
| 178 | * \brief Verification of PKCS7 signature. |
| 179 | * |
| 180 | * \param pkcs7 PKCS7 structure containing signature. |
| 181 | * \param cert Certificate containing key to verify signature. |
| 182 | * \param data Plain data on which signature has to be verified. |
| 183 | * \param datalen Length of the data. |
| 184 | * |
| 185 | * \note This function internally calculates the hash on the supplied |
| 186 | * plain data for signature verification. |
| 187 | * |
| 188 | * \return A negative error code on failure. |
| 189 | */ |
| 190 | int mbedtls_pkcs7_signed_data_verify( mbedtls_pkcs7 *pkcs7, |
| 191 | const mbedtls_x509_crt *cert, |
| 192 | const unsigned char *data, |
| 193 | size_t datalen ); |
| 194 | |
| 195 | /** |
| 196 | * \brief Verification of PKCS7 signature. |
| 197 | * |
| 198 | * \param pkcs7 PKCS7 structure containing signature. |
| 199 | * \param cert Certificate containing key to verify signature. |
| 200 | * \param hash Hash of the plain data on which signature has to be verified. |
| 201 | * \param hashlen Length of the hash. |
| 202 | * |
| 203 | * \note This function is different from mbedtls_pkcs7_signed_data_verify() |
| 204 | * in a way that it directly recieves the hash of the data. |
| 205 | * |
| 206 | * \return A negative error code on failure. |
| 207 | */ |
| 208 | int mbedtls_pkcs7_signed_hash_verify( mbedtls_pkcs7 *pkcs7, |
| 209 | const mbedtls_x509_crt *cert, |
| 210 | const unsigned char *hash, size_t hashlen); |
| 211 | |
| 212 | /** |
| 213 | * \brief Unallocate all PKCS7 data and zeroize the memory. |
| 214 | * It doesn't free pkcs7 itself. It should be done by the caller. |
| 215 | * |
| 216 | * \param pkcs7 PKCS7 structure to free. |
| 217 | */ |
| 218 | void mbedtls_pkcs7_free( mbedtls_pkcs7 *pkcs7 ); |
| 219 | |
| 220 | #ifdef __cplusplus |
| 221 | } |
| 222 | #endif |
| 223 | |
| 224 | #endif /* pkcs7.h */ |