⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 x509.c

📁 数字证书处理程序
💻 C
📖 第 1 页 / 共 3 页
字号:
/* apps/x509.c *//* Copyright (C) 1995-1998 Eric Young (eay@cryptsoft.com) * All rights reserved. * * This package is an SSL implementation written * by Eric Young (eay@cryptsoft.com). * The implementation was written so as to conform with Netscapes SSL. *  * This library is free for commercial and non-commercial use as long as * the following conditions are aheared to.  The following conditions * apply to all code found in this distribution, be it the RC4, RSA, * lhash, DES, etc., code; not just the SSL code.  The SSL documentation * included with this distribution is covered by the same copyright terms * except that the holder is Tim Hudson (tjh@cryptsoft.com). *  * Copyright remains Eric Young's, and as such any Copyright notices in * the code are not to be removed. * If this package is used in a product, Eric Young should be given attribution * as the author of the parts of the library used. * This can be in the form of a textual message at program startup or * in documentation (online or textual) provided with the package. *  * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions * are met: * 1. Redistributions of source code must retain the copyright *    notice, this list of conditions and the following disclaimer. * 2. Redistributions in binary form must reproduce the above copyright *    notice, this list of conditions and the following disclaimer in the *    documentation and/or other materials provided with the distribution. * 3. All advertising materials mentioning features or use of this software *    must display the following acknowledgement: *    "This product includes cryptographic software written by *     Eric Young (eay@cryptsoft.com)" *    The word 'cryptographic' can be left out if the rouines from the library *    being used are not cryptographic related :-). * 4. If you include any Windows specific code (or a derivative thereof) from  *    the apps directory (application code) you must include an acknowledgement: *    "This product includes software written by Tim Hudson (tjh@cryptsoft.com)" *  * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF * SUCH DAMAGE. *  * The licence and distribution terms for any publically available version or * derivative of this code cannot be changed.  i.e. this code cannot simply be * copied and put under another distribution licence * [including the GNU Public Licence.] */#include <assert.h>#include <stdio.h>#include <stdlib.h>#include <string.h>#ifdef NO_STDIO#define APPS_WIN16#endif#include "apps.h"#include <openssl/bio.h>#include <openssl/asn1.h>#include <openssl/err.h>#include <openssl/bn.h>#include <openssl/evp.h>#include <openssl/x509.h>#include <openssl/x509v3.h>#include <openssl/objects.h>#include <openssl/pem.h>#undef PROG#define PROG x509_main#undef POSTFIX#define	POSTFIX	".srl"#define DEF_DAYS	30static char *x509_usage[]={"usage: x509 args\n"," -inform arg     - input format - default PEM (one of DER, NET or PEM)\n"," -outform arg    - output format - default PEM (one of DER, NET or PEM)\n"," -keyform arg    - private key format - default PEM\n"," -CAform arg     - CA format - default PEM\n"," -CAkeyform arg  - CA key format - default PEM\n"," -in arg         - input file - default stdin\n"," -out arg        - output file - default stdout\n"," -passin arg     - private key password source\n"," -serial         - print serial number value\n"," -hash           - print hash value\n"," -subject        - print subject DN\n"," -issuer         - print issuer DN\n"," -email          - print email address(es)\n"," -startdate      - notBefore field\n"," -enddate        - notAfter field\n"," -purpose        - print out certificate purposes\n"," -dates          - both Before and After dates\n"," -modulus        - print the RSA key modulus\n"," -pubkey         - output the public key\n"," -fingerprint    - print the certificate fingerprint\n"," -alias          - output certificate alias\n"," -noout          - no certificate output\n"," -trustout       - output a \"trusted\" certificate\n"," -clrtrust       - clear all trusted purposes\n"," -clrreject      - clear all rejected purposes\n"," -addtrust arg   - trust certificate for a given purpose\n"," -addreject arg  - reject certificate for a given purpose\n"," -setalias arg   - set certificate alias\n"," -days arg       - How long till expiry of a signed certificate - def 30 days\n"," -checkend arg   - check whether the cert expires in the next arg seconds\n","                   exit 1 if so, 0 if not\n"," -signkey arg    - self sign cert with arg\n"," -x509toreq      - output a certification request object\n"," -req            - input is a certificate request, sign and output.\n"," -CA arg         - set the CA certificate, must be PEM format.\n"," -CAkey arg      - set the CA key, must be PEM format\n","                   missing, it is assumed to be in the CA file.\n"," -CAcreateserial - create serial number file if it does not exist\n"," -CAserial arg   - serial file\n"," -text           - print the certificate in text form\n"," -C              - print out C code forms\n"," -md2/-md5/-sha1/-mdc2 - digest to use\n"," -extfile        - configuration file with X509V3 extensions to add\n"," -extensions     - section from config file with X509V3 extensions to add\n"," -clrext         - delete extensions before signing and input certificate\n"," -nameopt arg    - various certificate name options\n",NULL};static int MS_CALLBACK callb(int ok, X509_STORE_CTX *ctx);static int sign (X509 *x, EVP_PKEY *pkey,int days,int clrext, const EVP_MD *digest,						LHASH *conf, char *section);static int x509_certify (X509_STORE *ctx,char *CAfile,const EVP_MD *digest,			 X509 *x,X509 *xca,EVP_PKEY *pkey,char *serial,			 int create,int days, int clrext, LHASH *conf, char *section);static int purpose_print(BIO *bio, X509 *cert, X509_PURPOSE *pt);static int reqfile=0;int MAIN(int, char **);int MAIN(int argc, char **argv)	{	int ret=1;	X509_REQ *req=NULL;	X509 *x=NULL,*xca=NULL;	ASN1_OBJECT *objtmp;	EVP_PKEY *Upkey=NULL,*CApkey=NULL;	int i,num,badops=0;	BIO *out=NULL;	BIO *STDout=NULL;	STACK_OF(ASN1_OBJECT) *trust = NULL, *reject = NULL;	int informat,outformat,keyformat,CAformat,CAkeyformat;	char *infile=NULL,*outfile=NULL,*keyfile=NULL,*CAfile=NULL;	char *CAkeyfile=NULL,*CAserial=NULL;	char *alias=NULL;	int text=0,serial=0,hash=0,subject=0,issuer=0,startdate=0,enddate=0;	int noout=0,sign_flag=0,CA_flag=0,CA_createserial=0,email=0;	int trustout=0,clrtrust=0,clrreject=0,aliasout=0,clrext=0;	int C=0;	int x509req=0,days=DEF_DAYS,modulus=0,pubkey=0;	int pprint = 0;	char **pp;	X509_STORE *ctx=NULL;	X509_REQ *rq=NULL;	int fingerprint=0;	char buf[256];	const EVP_MD *md_alg,*digest=EVP_md5();	LHASH *extconf = NULL;	char *extsect = NULL, *extfile = NULL, *passin = NULL, *passargin = NULL;	int need_rand = 0;	int checkend=0,checkoffset=0;	unsigned long nmflag = 0;	reqfile=0;	apps_startup();	if (bio_err == NULL)		bio_err=BIO_new_fp(stderr,BIO_NOCLOSE);	STDout=BIO_new_fp(stdout,BIO_NOCLOSE);#ifdef VMS	{	BIO *tmpbio = BIO_new(BIO_f_linebuffer());	STDout = BIO_push(tmpbio, STDout);	}#endif	informat=FORMAT_PEM;	outformat=FORMAT_PEM;	keyformat=FORMAT_PEM;	CAformat=FORMAT_PEM;	CAkeyformat=FORMAT_PEM;	ctx=X509_STORE_new();	if (ctx == NULL) goto end;	X509_STORE_set_verify_cb_func(ctx,callb);	argc--;	argv++;	num=0;	while (argc >= 1)		{		if 	(strcmp(*argv,"-inform") == 0)			{			if (--argc < 1) goto bad;			informat=str2fmt(*(++argv));			}		else if (strcmp(*argv,"-outform") == 0)			{			if (--argc < 1) goto bad;			outformat=str2fmt(*(++argv));			}		else if (strcmp(*argv,"-keyform") == 0)			{			if (--argc < 1) goto bad;			keyformat=str2fmt(*(++argv));			}		else if (strcmp(*argv,"-req") == 0)			{			reqfile=1;			need_rand = 1;			}		else if (strcmp(*argv,"-CAform") == 0)			{			if (--argc < 1) goto bad;			CAformat=str2fmt(*(++argv));			}		else if (strcmp(*argv,"-CAkeyform") == 0)			{			if (--argc < 1) goto bad;			CAkeyformat=str2fmt(*(++argv));			}		else if (strcmp(*argv,"-days") == 0)			{			if (--argc < 1) goto bad;			days=atoi(*(++argv));			if (days == 0)				{				BIO_printf(STDout,"bad number of days\n");				goto bad;				}			}		else if (strcmp(*argv,"-passin") == 0)			{			if (--argc < 1) goto bad;			passargin= *(++argv);			}		else if (strcmp(*argv,"-extfile") == 0)			{			if (--argc < 1) goto bad;			extfile= *(++argv);			}		else if (strcmp(*argv,"-extensions") == 0)			{			if (--argc < 1) goto bad;			extsect= *(++argv);			}		else if (strcmp(*argv,"-in") == 0)			{			if (--argc < 1) goto bad;			infile= *(++argv);			}		else if (strcmp(*argv,"-out") == 0)			{			if (--argc < 1) goto bad;			outfile= *(++argv);			}		else if (strcmp(*argv,"-signkey") == 0)			{			if (--argc < 1) goto bad;			keyfile= *(++argv);			sign_flag= ++num;			need_rand = 1;			}		else if (strcmp(*argv,"-CA") == 0)			{			if (--argc < 1) goto bad;			CAfile= *(++argv);			CA_flag= ++num;			need_rand = 1;			}		else if (strcmp(*argv,"-CAkey") == 0)			{			if (--argc < 1) goto bad;			CAkeyfile= *(++argv);			}		else if (strcmp(*argv,"-CAserial") == 0)			{			if (--argc < 1) goto bad;			CAserial= *(++argv);			}		else if (strcmp(*argv,"-addtrust") == 0)			{			if (--argc < 1) goto bad;			if (!(objtmp = OBJ_txt2obj(*(++argv), 0)))				{				BIO_printf(bio_err,					"Invalid trust object value %s\n", *argv);				goto bad;				}			if (!trust) trust = sk_ASN1_OBJECT_new_null();			sk_ASN1_OBJECT_push(trust, objtmp);			trustout = 1;			}		else if (strcmp(*argv,"-addreject") == 0)			{			if (--argc < 1) goto bad;			if (!(objtmp = OBJ_txt2obj(*(++argv), 0)))				{				BIO_printf(bio_err,					"Invalid reject object value %s\n", *argv);				goto bad;				}			if (!reject) reject = sk_ASN1_OBJECT_new_null();			sk_ASN1_OBJECT_push(reject, objtmp);			trustout = 1;			}		else if (strcmp(*argv,"-setalias") == 0)			{			if (--argc < 1) goto bad;			alias= *(++argv);			trustout = 1;			}		else if (strcmp(*argv,"-nameopt") == 0)			{			if (--argc < 1) goto bad;			if (!set_name_ex(&nmflag, *(++argv))) goto bad;			}		else if (strcmp(*argv,"-setalias") == 0)			{			if (--argc < 1) goto bad;			alias= *(++argv);			trustout = 1;			}		else if (strcmp(*argv,"-C") == 0)			C= ++num;		else if (strcmp(*argv,"-email") == 0)			email= ++num;		else if (strcmp(*argv,"-serial") == 0)			serial= ++num;		else if (strcmp(*argv,"-modulus") == 0)			modulus= ++num;		else if (strcmp(*argv,"-pubkey") == 0)			pubkey= ++num;		else if (strcmp(*argv,"-x509toreq") == 0)			x509req= ++num;		else if (strcmp(*argv,"-text") == 0)			text= ++num;		else if (strcmp(*argv,"-hash") == 0)			hash= ++num;		else if (strcmp(*argv,"-subject") == 0)			subject= ++num;		else if (strcmp(*argv,"-issuer") == 0)			issuer= ++num;		else if (strcmp(*argv,"-fingerprint") == 0)			fingerprint= ++num;		else if (strcmp(*argv,"-dates") == 0)			{			startdate= ++num;			enddate= ++num;			}		else if (strcmp(*argv,"-purpose") == 0)			pprint= ++num;		else if (strcmp(*argv,"-startdate") == 0)			startdate= ++num;		else if (strcmp(*argv,"-enddate") == 0)			enddate= ++num;		else if (strcmp(*argv,"-checkend") == 0)			{			if (--argc < 1) goto bad;			checkoffset=atoi(*(++argv));			checkend=1;			}		else if (strcmp(*argv,"-noout") == 0)			noout= ++num;		else if (strcmp(*argv,"-trustout") == 0)			trustout= 1;		else if (strcmp(*argv,"-clrtrust") == 0)			clrtrust= ++num;		else if (strcmp(*argv,"-clrreject") == 0)			clrreject= ++num;		else if (strcmp(*argv,"-alias") == 0)			aliasout= ++num;		else if (strcmp(*argv,"-CAcreateserial") == 0)			CA_createserial= ++num;		else if (strcmp(*argv,"-clrext") == 0)			clrext = 1;#if 1 /* stay backwards-compatible with 0.9.5; this should go away soon */		else if (strcmp(*argv,"-crlext") == 0)			{			BIO_printf(bio_err,"use -clrext instead of -crlext\n");			clrext = 1;			}#endif		else if ((md_alg=EVP_get_digestbyname(*argv + 1)))			{			/* ok */			digest=md_alg;

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -