⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 ocsp.c

📁 mediastreamer2是开源的网络传输媒体流的库
💻 C
📖 第 1 页 / 共 2 页
字号:
/* ocsp.c *//* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL * project 2000. *//* ==================================================================== * Copyright (c) 1999 The OpenSSL Project.  All rights reserved. * * Redistribution and use in source and binary forms, with or without * modification, are permitted provided that the following conditions * are met: * * 1. Redistributions of source code must retain the above copyright *    notice, this list of conditions and the following disclaimer.  * * 2. Redistributions in binary form must reproduce the above copyright *    notice, this list of conditions and the following disclaimer in *    the documentation and/or other materials provided with the *    distribution. * * 3. All advertising materials mentioning features or use of this *    software must display the following acknowledgment: *    "This product includes software developed by the OpenSSL Project *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)" * * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to *    endorse or promote products derived from this software without *    prior written permission. For written permission, please contact *    licensing@OpenSSL.org. * * 5. Products derived from this software may not be called "OpenSSL" *    nor may "OpenSSL" appear in their names without prior written *    permission of the OpenSSL Project. * * 6. Redistributions of any form whatsoever must retain the following *    acknowledgment: *    "This product includes software developed by the OpenSSL Project *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)" * * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED * OF THE POSSIBILITY OF SUCH DAMAGE. * ==================================================================== * * This product includes cryptographic software written by Eric Young * (eay@cryptsoft.com).  This product includes software written by Tim * Hudson (tjh@cryptsoft.com). * */#ifndef OPENSSL_NO_OCSP#include <stdio.h>#include <string.h>#include "apps.h"#include <openssl/pem.h>#include <openssl/ocsp.h>#include <openssl/err.h>#include <openssl/ssl.h>#include <openssl/bn.h>/* Maximum leeway in validity period: default 5 minutes */#define MAX_VALIDITY_PERIOD	(5 * 60)static int add_ocsp_cert(OCSP_REQUEST **req, X509 *cert, X509 *issuer,				STACK_OF(OCSP_CERTID) *ids);static int add_ocsp_serial(OCSP_REQUEST **req, char *serial, X509 *issuer,				STACK_OF(OCSP_CERTID) *ids);static int print_ocsp_summary(BIO *out, OCSP_BASICRESP *bs, OCSP_REQUEST *req,				STACK *names, STACK_OF(OCSP_CERTID) *ids,				long nsec, long maxage);static int make_ocsp_response(OCSP_RESPONSE **resp, OCSP_REQUEST *req, CA_DB *db,			X509 *ca, X509 *rcert, EVP_PKEY *rkey,			STACK_OF(X509) *rother, unsigned long flags,			int nmin, int ndays);static char **lookup_serial(CA_DB *db, ASN1_INTEGER *ser);static BIO *init_responder(char *port);static int do_responder(OCSP_REQUEST **preq, BIO **pcbio, BIO *acbio, char *port);static int send_ocsp_response(BIO *cbio, OCSP_RESPONSE *resp);#undef PROG#define PROG ocsp_mainint MAIN(int, char **);int MAIN(int argc, char **argv)	{	ENGINE *e = NULL;	char **args;	char *host = NULL, *port = NULL, *path = "/";	char *reqin = NULL, *respin = NULL;	char *reqout = NULL, *respout = NULL;	char *signfile = NULL, *keyfile = NULL;	char *rsignfile = NULL, *rkeyfile = NULL;	char *outfile = NULL;	int add_nonce = 1, noverify = 0, use_ssl = -1;	OCSP_REQUEST *req = NULL;	OCSP_RESPONSE *resp = NULL;	OCSP_BASICRESP *bs = NULL;	X509 *issuer = NULL, *cert = NULL;	X509 *signer = NULL, *rsigner = NULL;	EVP_PKEY *key = NULL, *rkey = NULL;	BIO *acbio = NULL, *cbio = NULL;	BIO *derbio = NULL;	BIO *out = NULL;	int req_text = 0, resp_text = 0;	long nsec = MAX_VALIDITY_PERIOD, maxage = -1;	char *CAfile = NULL, *CApath = NULL;	X509_STORE *store = NULL;	SSL_CTX *ctx = NULL;	STACK_OF(X509) *sign_other = NULL, *verify_other = NULL, *rother = NULL;	char *sign_certfile = NULL, *verify_certfile = NULL, *rcertfile = NULL;	unsigned long sign_flags = 0, verify_flags = 0, rflags = 0;	int ret = 1;	int accept_count = -1;	int badarg = 0;	int i;	int ignore_err = 0;	STACK *reqnames = NULL;	STACK_OF(OCSP_CERTID) *ids = NULL;	X509 *rca_cert = NULL;	char *ridx_filename = NULL;	char *rca_filename = NULL;	CA_DB *rdb = NULL;	int nmin = 0, ndays = -1;	if (bio_err == NULL) bio_err = BIO_new_fp(stderr, BIO_NOCLOSE);	if (!load_config(bio_err, NULL))		goto end;	SSL_load_error_strings();	args = argv + 1;	reqnames = sk_new_null();	ids = sk_OCSP_CERTID_new_null();	while (!badarg && *args && *args[0] == '-')		{		if (!strcmp(*args, "-out"))			{			if (args[1])				{				args++;				outfile = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-url"))			{			if (args[1])				{				args++;				if (!OCSP_parse_url(*args, &host, &port, &path, &use_ssl))					{					BIO_printf(bio_err, "Error parsing URL\n");					badarg = 1;					}				}			else badarg = 1;			}		else if (!strcmp(*args, "-host"))			{			if (args[1])				{				args++;				host = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-port"))			{			if (args[1])				{				args++;				port = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-ignore_err"))			ignore_err = 1;		else if (!strcmp(*args, "-noverify"))			noverify = 1;		else if (!strcmp(*args, "-nonce"))			add_nonce = 2;		else if (!strcmp(*args, "-no_nonce"))			add_nonce = 0;		else if (!strcmp(*args, "-resp_no_certs"))			rflags |= OCSP_NOCERTS;		else if (!strcmp(*args, "-resp_key_id"))			rflags |= OCSP_RESPID_KEY;		else if (!strcmp(*args, "-no_certs"))			sign_flags |= OCSP_NOCERTS;		else if (!strcmp(*args, "-no_signature_verify"))			verify_flags |= OCSP_NOSIGS;		else if (!strcmp(*args, "-no_cert_verify"))			verify_flags |= OCSP_NOVERIFY;		else if (!strcmp(*args, "-no_chain"))			verify_flags |= OCSP_NOCHAIN;		else if (!strcmp(*args, "-no_cert_checks"))			verify_flags |= OCSP_NOCHECKS;		else if (!strcmp(*args, "-no_explicit"))			verify_flags |= OCSP_NOEXPLICIT;		else if (!strcmp(*args, "-trust_other"))			verify_flags |= OCSP_TRUSTOTHER;		else if (!strcmp(*args, "-no_intern"))			verify_flags |= OCSP_NOINTERN;		else if (!strcmp(*args, "-text"))			{			req_text = 1;			resp_text = 1;			}		else if (!strcmp(*args, "-req_text"))			req_text = 1;		else if (!strcmp(*args, "-resp_text"))			resp_text = 1;		else if (!strcmp(*args, "-reqin"))			{			if (args[1])				{				args++;				reqin = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-respin"))			{			if (args[1])				{				args++;				respin = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-signer"))			{			if (args[1])				{				args++;				signfile = *args;				}			else badarg = 1;			}		else if (!strcmp (*args, "-VAfile"))			{			if (args[1])				{				args++;				verify_certfile = *args;				verify_flags |= OCSP_TRUSTOTHER;				}			else badarg = 1;			}		else if (!strcmp(*args, "-sign_other"))			{			if (args[1])				{				args++;				sign_certfile = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-verify_other"))			{			if (args[1])				{				args++;				verify_certfile = *args;				}			else badarg = 1;			}		else if (!strcmp (*args, "-CAfile"))			{			if (args[1])				{				args++;				CAfile = *args;				}			else badarg = 1;			}		else if (!strcmp (*args, "-CApath"))			{			if (args[1])				{				args++;				CApath = *args;				}			else badarg = 1;			}		else if (!strcmp (*args, "-validity_period"))			{			if (args[1])				{				args++;				nsec = atol(*args);				if (nsec < 0)					{					BIO_printf(bio_err,						"Illegal validity period %s\n",						*args);					badarg = 1;					}				}			else badarg = 1;			}		else if (!strcmp (*args, "-status_age"))			{			if (args[1])				{				args++;				maxage = atol(*args);				if (maxage < 0)					{					BIO_printf(bio_err,						"Illegal validity age %s\n",						*args);					badarg = 1;					}				}			else badarg = 1;			}		 else if (!strcmp(*args, "-signkey"))			{			if (args[1])				{				args++;				keyfile = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-reqout"))			{			if (args[1])				{				args++;				reqout = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-respout"))			{			if (args[1])				{				args++;				respout = *args;				}			else badarg = 1;			}		 else if (!strcmp(*args, "-path"))			{			if (args[1])				{				args++;				path = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-issuer"))			{			if (args[1])				{				args++;				X509_free(issuer);				issuer = load_cert(bio_err, *args, FORMAT_PEM,					NULL, e, "issuer certificate");				if(!issuer) goto end;				}			else badarg = 1;			}		else if (!strcmp (*args, "-cert"))			{			if (args[1])				{				args++;				X509_free(cert);				cert = load_cert(bio_err, *args, FORMAT_PEM,					NULL, e, "certificate");				if(!cert) goto end;				if(!add_ocsp_cert(&req, cert, issuer, ids))					goto end;				if(!sk_push(reqnames, *args))					goto end;				}			else badarg = 1;			}		else if (!strcmp(*args, "-serial"))			{			if (args[1])				{				args++;				if(!add_ocsp_serial(&req, *args, issuer, ids))					goto end;				if(!sk_push(reqnames, *args))					goto end;				}			else badarg = 1;			}		else if (!strcmp(*args, "-index"))			{			if (args[1])				{				args++;				ridx_filename = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-CA"))			{			if (args[1])				{				args++;				rca_filename = *args;				}			else badarg = 1;			}		else if (!strcmp (*args, "-nmin"))			{			if (args[1])				{				args++;				nmin = atol(*args);				if (nmin < 0)					{					BIO_printf(bio_err,						"Illegal update period %s\n",						*args);					badarg = 1;					}				}				if (ndays == -1)					ndays = 0;			else badarg = 1;			}		else if (!strcmp (*args, "-nrequest"))			{			if (args[1])				{				args++;				accept_count = atol(*args);				if (accept_count < 0)					{					BIO_printf(bio_err,						"Illegal accept count %s\n",						*args);					badarg = 1;					}				}			else badarg = 1;			}		else if (!strcmp (*args, "-ndays"))			{			if (args[1])				{				args++;				ndays = atol(*args);				if (ndays < 0)					{					BIO_printf(bio_err,						"Illegal update period %s\n",						*args);					badarg = 1;					}				}			else badarg = 1;			}		else if (!strcmp(*args, "-rsigner"))			{			if (args[1])				{				args++;				rsignfile = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-rkey"))			{			if (args[1])				{				args++;				rkeyfile = *args;				}			else badarg = 1;			}		else if (!strcmp(*args, "-rother"))			{			if (args[1])				{				args++;				rcertfile = *args;				}			else badarg = 1;			}		else badarg = 1;		args++;		}	/* Have we anything to do? */	if (!req && !reqin && !respin && !(port && ridx_filename)) badarg = 1;	if (badarg)		{		BIO_printf (bio_err, "OCSP utility\n");		BIO_printf (bio_err, "Usage ocsp [options]\n");		BIO_printf (bio_err, "where options are\n");		BIO_printf (bio_err, "-out file          output filename\n");		BIO_printf (bio_err, "-issuer file       issuer certificate\n");		BIO_printf (bio_err, "-cert file         certificate to check\n");		BIO_printf (bio_err, "-serial n          serial number to check\n");		BIO_printf (bio_err, "-signer file       certificate to sign OCSP request with\n");		BIO_printf (bio_err, "-signkey file      private key to sign OCSP request with\n");		BIO_printf (bio_err, "-sign_other file   additional certificates to include in signed request\n");		BIO_printf (bio_err, "-no_certs          don't include any certificates in signed request\n");		BIO_printf (bio_err, "-req_text          print text form of request\n");		BIO_printf (bio_err, "-resp_text         print text form of response\n");		BIO_printf (bio_err, "-text              print text form of request and response\n");		BIO_printf (bio_err, "-reqout file       write DER encoded OCSP request to \"file\"\n");		BIO_printf (bio_err, "-respout file      write DER encoded OCSP reponse to \"file\"\n");		BIO_printf (bio_err, "-reqin file        read DER encoded OCSP request from \"file\"\n");		BIO_printf (bio_err, "-respin file       read DER encoded OCSP reponse from \"file\"\n");		BIO_printf (bio_err, "-nonce             add OCSP nonce to request\n");		BIO_printf (bio_err, "-no_nonce          don't add OCSP nonce to request\n");		BIO_printf (bio_err, "-url URL           OCSP responder URL\n");		BIO_printf (bio_err, "-host host:n       send OCSP request to host on port n\n");		BIO_printf (bio_err, "-path              path to use in OCSP request\n");		BIO_printf (bio_err, "-CApath dir        trusted certificates directory\n");		BIO_printf (bio_err, "-CAfile file       trusted certificates file\n");		BIO_printf (bio_err, "-VAfile file       validator certificates file\n");		BIO_printf (bio_err, "-validity_period n maximum validity discrepancy in seconds\n");		BIO_printf (bio_err, "-status_age n      maximum status age in seconds\n");		BIO_printf (bio_err, "-noverify          don't verify response at all\n");		BIO_printf (bio_err, "-verify_other file additional certificates to search for signer\n");		BIO_printf (bio_err, "-trust_other       don't verify additional certificates\n");		BIO_printf (bio_err, "-no_intern         don't search certificates contained in response for signer\n");		BIO_printf (bio_err, "-no_signature_verify don't check signature on response\n");		BIO_printf (bio_err, "-no_cert_verify    don't check signing certificate\n");		BIO_printf (bio_err, "-no_chain          don't chain verify response\n");		BIO_printf (bio_err, "-no_cert_checks    don't do additional checks on signing certificate\n");		BIO_printf (bio_err, "-port num		 port to run responder on\n");		BIO_printf (bio_err, "-index file	 certificate status index file\n");		BIO_printf (bio_err, "-CA file		 CA certificate\n");		BIO_printf (bio_err, "-rsigner file	 responder certificate to sign responses with\n");		BIO_printf (bio_err, "-rkey file	 responder key to sign responses with\n");		BIO_printf (bio_err, "-rother file	 other certificates to include in response\n");		BIO_printf (bio_err, "-resp_no_certs     don't include any certificates in response\n");		BIO_printf (bio_err, "-nmin n	 	 number of minutes before next update\n");		BIO_printf (bio_err, "-ndays n	 	 number of days before next update\n");		BIO_printf (bio_err, "-resp_key_id       identify reponse by signing certificate key ID\n");		BIO_printf (bio_err, "-nrequest n        number of requests to accept (default unlimited)\n");		goto end;		}	if(outfile) out = BIO_new_file(outfile, "w");	else out = BIO_new_fp(stdout, BIO_NOCLOSE);	if(!out)		{		BIO_printf(bio_err, "Error opening output file\n");		goto end;		}	if (!req && (add_nonce != 2)) add_nonce = 0;	if (!req && reqin)		{		derbio = BIO_new_file(reqin, "rb");		if (!derbio)			{			BIO_printf(bio_err, "Error Opening OCSP request file\n");			goto end;			}		req = d2i_OCSP_REQUEST_bio(derbio, NULL);		BIO_free(derbio);		if(!req)			{			BIO_printf(bio_err, "Error reading OCSP request\n");			goto end;			}		}	if (!req && port)		{		acbio = init_responder(port);		if (!acbio)			goto end;		}	if (rsignfile && !rdb)		{		if (!rkeyfile) rkeyfile = rsignfile;		rsigner = load_cert(bio_err, rsignfile, FORMAT_PEM,			NULL, e, "responder certificate");		if (!rsigner)			{			BIO_printf(bio_err, "Error loading responder certificate\n");			goto end;			}		rca_cert = load_cert(bio_err, rca_filename, FORMAT_PEM,			NULL, e, "CA certificate");		if (rcertfile)			{			rother = load_certs(bio_err, rcertfile, FORMAT_PEM,				NULL, e, "responder other certificates");			if (!rother) goto end;			}		rkey = load_key(bio_err, rkeyfile, FORMAT_PEM, 0, NULL, NULL,			"responder private key");		if (!rkey)			goto end;

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -