375124b162
CBS_asn1_ber_to_der currently uses heuristics because implicitly-tagged constructed strings in BER are ambiguous with implicitly-tagged sequences. It's not possible to convert BER to DER without knowing the schema. Fortunately, implicitly tagged strings don't appear often so instead split the job up: CBS_asn1_ber_to_der fixes indefinite-length elements and constructed strings it can see. Implicitly-tagged strings it leaves uncoverted, but they will only nest one level down (because BER kindly allows one to nest constructed strings arbitrarily!). CBS_get_asn1_implicit_string then performs the final concatenation at parse time. This isn't much more complex and lets us parse BER more accurately and also reject a number of mis-encoded values (e.g. constructed INTEGERs are not a thing) we'd previously let through. The downside is the post-conversion parsing code must be aware of this limitation of CBS_asn1_ber_to_der. Fortunately, there's only one implicitly-tagged string in our PKCS#12 code. (In the category of things that really really don't matter, but I had spare cycles and the old BER converter is weird.) Change-Id: Iebdd13b08559fa158b308ef83a5bb07bfdf80ae8 Reviewed-on: https://boringssl-review.googlesource.com/7052 Reviewed-by: Adam Langley <agl@google.com>
67 lines
2.9 KiB
C
67 lines
2.9 KiB
C
/* Copyright (c) 2014, Google Inc.
|
|
*
|
|
* Permission to use, copy, modify, and/or distribute this software for any
|
|
* purpose with or without fee is hereby granted, provided that the above
|
|
* copyright notice and this permission notice appear in all copies.
|
|
*
|
|
* THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
|
|
* WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
|
|
* MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY
|
|
* SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
|
|
* WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION
|
|
* OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN
|
|
* CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. */
|
|
|
|
#ifndef OPENSSL_HEADER_BYTESTRING_INTERNAL_H
|
|
#define OPENSSL_HEADER_BYTESTRING_INTERNAL_H
|
|
|
|
#include <openssl/base.h>
|
|
|
|
#if defined(__cplusplus)
|
|
extern "C" {
|
|
#endif
|
|
|
|
|
|
/* CBS_asn1_ber_to_der reads a BER element from |in|. If it finds
|
|
* indefinite-length elements or constructed strings then it converts the BER
|
|
* data to DER and sets |*out| and |*out_length| to describe a malloced buffer
|
|
* containing the DER data. Additionally, |*in| will be advanced over the BER
|
|
* element.
|
|
*
|
|
* If it doesn't find any indefinite-length elements or constructed strings then
|
|
* it sets |*out| to NULL and |*in| is unmodified.
|
|
*
|
|
* This function should successfully process any valid BER input, however it
|
|
* will not convert all of BER's deviations from DER. BER is ambiguous between
|
|
* implicitly-tagged SEQUENCEs of strings and implicitly-tagged constructed
|
|
* strings. Implicitly-tagged strings must be parsed with
|
|
* |CBS_get_ber_implicitly_tagged_string| instead of |CBS_get_asn1|. The caller
|
|
* must also account for BER variations in the contents of a primitive.
|
|
*
|
|
* It returns one on success and zero otherwise. */
|
|
OPENSSL_EXPORT int CBS_asn1_ber_to_der(CBS *in, uint8_t **out, size_t *out_len);
|
|
|
|
/* CBS_get_asn1_implicit_string parses a BER string of primitive type
|
|
* |inner_tag| implicitly-tagged with |outer_tag|. It sets |out| to the
|
|
* contents. If concatenation was needed, it sets |*out_storage| to a buffer
|
|
* which the caller must release with |OPENSSL_free|. Otherwise, it sets
|
|
* |*out_storage| to NULL.
|
|
*
|
|
* This function does not parse all of BER. It requires the string be
|
|
* definite-length. Constructed strings are allowed, but all children of the
|
|
* outermost element must be primitive. The caller should use
|
|
* |CBS_asn1_ber_to_der| before running this function.
|
|
*
|
|
* It returns one on success and zero otherwise. */
|
|
OPENSSL_EXPORT int CBS_get_asn1_implicit_string(CBS *in, CBS *out,
|
|
uint8_t **out_storage,
|
|
unsigned outer_tag,
|
|
unsigned inner_tag);
|
|
|
|
|
|
#if defined(__cplusplus)
|
|
} /* extern C */
|
|
#endif
|
|
|
|
#endif /* OPENSSL_HEADER_BYTESTRING_INTERNAL_H */
|