2 X.509 Certificate Handler Wrapper Implementation which does not provide
5 Copyright (c) 2012 - 2020, Intel Corporation. All rights reserved.<BR>
6 SPDX-License-Identifier: BSD-2-Clause-Patent
10 #include "InternalCryptLib.h"
13 Construct a X509 object from DER-encoded certificate data.
15 Return FALSE to indicate this interface is not supported.
17 @param[in] Cert Pointer to the DER-encoded certificate data.
18 @param[in] CertSize The size of certificate data in bytes.
19 @param[out] SingleX509Cert The generated X509 object.
21 @retval FALSE This interface is not supported.
26 X509ConstructCertificate (
29 OUT UINT8
**SingleX509Cert
37 Construct a X509 stack object from a list of DER-encoded certificate data.
39 If X509Stack is NULL, then return FALSE.
40 If this interface is not supported, then return FALSE.
42 @param[in, out] X509Stack On input, pointer to an existing or NULL X509 stack object.
43 On output, pointer to the X509 stack object with new
44 inserted X509 certificate.
45 @param[in] Args VA_LIST marker for the variable argument list.
46 A list of DER-encoded single certificate data followed
47 by certificate size. A NULL terminates the list. The
48 pairs are the arguments to X509ConstructCertificate().
50 @retval TRUE The X509 stack construction succeeded.
51 @retval FALSE The construction operation failed.
52 @retval FALSE This interface is not supported.
57 X509ConstructCertificateStackV (
58 IN OUT UINT8
**X509Stack
,
67 Construct a X509 stack object from a list of DER-encoded certificate data.
69 Return FALSE to indicate this interface is not supported.
71 @param[in, out] X509Stack On input, pointer to an existing or NULL X509 stack object.
72 On output, pointer to the X509 stack object with new
73 inserted X509 certificate.
74 @param ... A list of DER-encoded single certificate data followed
75 by certificate size. A NULL terminates the list. The
76 pairs are the arguments to X509ConstructCertificate().
78 @retval FALSE This interface is not supported.
83 X509ConstructCertificateStack (
84 IN OUT UINT8
**X509Stack
,
93 Release the specified X509 object.
95 If the interface is not supported, then ASSERT().
97 @param[in] X509Cert Pointer to the X509 object to be released.
110 Release the specified X509 stack object.
112 If the interface is not supported, then ASSERT().
114 @param[in] X509Stack Pointer to the X509 stack object to be released.
127 Retrieve the subject bytes from one X.509 certificate.
129 Return FALSE to indicate this interface is not supported.
131 @param[in] Cert Pointer to the DER-encoded X509 certificate.
132 @param[in] CertSize Size of the X509 certificate in bytes.
133 @param[out] CertSubject Pointer to the retrieved certificate subject bytes.
134 @param[in, out] SubjectSize The size in bytes of the CertSubject buffer on input,
135 and the size of buffer returned CertSubject on output.
138 @retval FALSE This interface is not supported.
144 IN CONST UINT8
*Cert
,
146 OUT UINT8
*CertSubject
,
147 IN OUT UINTN
*SubjectSize
155 Retrieve the common name (CN) string from one X.509 certificate.
157 Return RETURN_UNSUPPORTED to indicate this interface is not supported.
159 @param[in] Cert Pointer to the DER-encoded X509 certificate.
160 @param[in] CertSize Size of the X509 certificate in bytes.
161 @param[out] CommonName Buffer to contain the retrieved certificate common
162 name string (UTF8). At most CommonNameSize bytes will be
163 written and the string will be null terminated. May be
164 NULL in order to determine the size buffer needed.
165 @param[in,out] CommonNameSize The size in bytes of the CommonName buffer on input,
166 and the size of buffer returned CommonName on output.
167 If CommonName is NULL then the amount of space needed
168 in buffer (including the final null) is returned.
170 @retval RETURN_UNSUPPORTED The operation is not supported.
176 IN CONST UINT8
*Cert
,
178 OUT CHAR8
*CommonName OPTIONAL
,
179 IN OUT UINTN
*CommonNameSize
183 return RETURN_UNSUPPORTED
;
187 Retrieve the organization name (ON) string from one X.509 certificate.
189 Return RETURN_UNSUPPORTED to indicate this interface is not supported.
191 @param[in] Cert Pointer to the DER-encoded X509 certificate.
192 @param[in] CertSize Size of the X509 certificate in bytes.
193 @param[out] NameBuffer Buffer to contain the retrieved certificate organization
194 name string. At most NameBufferSize bytes will be
195 written and the string will be null terminated. May be
196 NULL in order to determine the size buffer needed.
197 @param[in,out] NameBufferSize The size in bytes of the Name buffer on input,
198 and the size of buffer returned Name on output.
199 If NameBuffer is NULL then the amount of space needed
200 in buffer (including the final null) is returned.
202 @retval RETURN_UNSUPPORTED The operation is not supported.
207 X509GetOrganizationName (
208 IN CONST UINT8
*Cert
,
210 OUT CHAR8
*NameBuffer OPTIONAL
,
211 IN OUT UINTN
*NameBufferSize
215 return RETURN_UNSUPPORTED
;
219 Retrieve the RSA Public Key from one DER-encoded X509 certificate.
221 Return FALSE to indicate this interface is not supported.
223 @param[in] Cert Pointer to the DER-encoded X509 certificate.
224 @param[in] CertSize Size of the X509 certificate in bytes.
225 @param[out] RsaContext Pointer to new-generated RSA context which contain the retrieved
226 RSA public key component. Use RsaFree() function to free the
229 @retval FALSE This interface is not supported.
234 RsaGetPublicKeyFromX509 (
235 IN CONST UINT8
*Cert
,
237 OUT VOID
**RsaContext
245 Verify one X509 certificate was issued by the trusted CA.
247 Return FALSE to indicate this interface is not supported.
249 @param[in] Cert Pointer to the DER-encoded X509 certificate to be verified.
250 @param[in] CertSize Size of the X509 certificate in bytes.
251 @param[in] CACert Pointer to the DER-encoded trusted CA certificate.
252 @param[in] CACertSize Size of the CA Certificate in bytes.
254 @retval FALSE This interface is not supported.
260 IN CONST UINT8
*Cert
,
262 IN CONST UINT8
*CACert
,
271 Retrieve the TBSCertificate from one given X.509 certificate.
273 Return FALSE to indicate this interface is not supported.
275 @param[in] Cert Pointer to the given DER-encoded X509 certificate.
276 @param[in] CertSize Size of the X509 certificate in bytes.
277 @param[out] TBSCert DER-Encoded To-Be-Signed certificate.
278 @param[out] TBSCertSize Size of the TBS certificate in bytes.
280 @retval FALSE This interface is not supported.
286 IN CONST UINT8
*Cert
,
289 OUT UINTN
*TBSCertSize
297 Retrieve the EC Public Key from one DER-encoded X509 certificate.
299 @param[in] Cert Pointer to the DER-encoded X509 certificate.
300 @param[in] CertSize Size of the X509 certificate in bytes.
301 @param[out] EcContext Pointer to new-generated EC DSA context which contain the retrieved
302 EC public key component. Use EcFree() function to free the
305 If Cert is NULL, then return FALSE.
306 If EcContext is NULL, then return FALSE.
308 @retval TRUE EC Public Key was retrieved successfully.
309 @retval FALSE Fail to retrieve EC public key from X509 certificate.
314 EcGetPublicKeyFromX509 (
315 IN CONST UINT8
*Cert
,
325 Retrieve the version from one X.509 certificate.
327 If Cert is NULL, then return FALSE.
328 If CertSize is 0, then return FALSE.
329 If this interface is not supported, then return FALSE.
331 @param[in] Cert Pointer to the DER-encoded X509 certificate.
332 @param[in] CertSize Size of the X509 certificate in bytes.
333 @param[out] Version Pointer to the retrieved version integer.
335 @retval TRUE The certificate version retrieved successfully.
336 @retval FALSE If Cert is NULL or CertSize is Zero.
337 @retval FALSE The operation is not supported.
343 IN CONST UINT8
*Cert
,
353 Retrieve the serialNumber from one X.509 certificate.
355 If Cert is NULL, then return FALSE.
356 If CertSize is 0, then return FALSE.
357 If this interface is not supported, then return FALSE.
359 @param[in] Cert Pointer to the DER-encoded X509 certificate.
360 @param[in] CertSize Size of the X509 certificate in bytes.
361 @param[out] SerialNumber Pointer to the retrieved certificate SerialNumber bytes.
362 @param[in, out] SerialNumberSize The size in bytes of the SerialNumber buffer on input,
363 and the size of buffer returned SerialNumber on output.
365 @retval TRUE The certificate serialNumber retrieved successfully.
366 @retval FALSE If Cert is NULL or CertSize is Zero.
367 If SerialNumberSize is NULL.
368 If Certificate is invalid.
369 @retval FALSE If no SerialNumber exists.
370 @retval FALSE If the SerialNumber is NULL. The required buffer size
371 (including the final null) is returned in the
372 SerialNumberSize parameter.
373 @retval FALSE The operation is not supported.
377 X509GetSerialNumber (
378 IN CONST UINT8
*Cert
,
380 OUT UINT8
*SerialNumber
, OPTIONAL
381 IN OUT UINTN
*SerialNumberSize
389 Retrieve the issuer bytes from one X.509 certificate.
391 If Cert is NULL, then return FALSE.
392 If CertIssuerSize is NULL, then return FALSE.
393 If this interface is not supported, then return FALSE.
395 @param[in] Cert Pointer to the DER-encoded X509 certificate.
396 @param[in] CertSize Size of the X509 certificate in bytes.
397 @param[out] CertIssuer Pointer to the retrieved certificate subject bytes.
398 @param[in, out] CertIssuerSize The size in bytes of the CertIssuer buffer on input,
399 and the size of buffer returned CertSubject on output.
401 @retval TRUE The certificate issuer retrieved successfully.
402 @retval FALSE Invalid certificate, or the CertIssuerSize is too small for the result.
403 The CertIssuerSize will be updated with the required size.
404 @retval FALSE This interface is not supported.
410 IN CONST UINT8
*Cert
,
412 OUT UINT8
*CertIssuer
,
413 IN OUT UINTN
*CertIssuerSize
421 Retrieve the Signature Algorithm from one X.509 certificate.
423 @param[in] Cert Pointer to the DER-encoded X509 certificate.
424 @param[in] CertSize Size of the X509 certificate in bytes.
425 @param[out] Oid Signature Algorithm Object identifier buffer.
426 @param[in,out] OidSize Signature Algorithm Object identifier buffer size
428 @retval TRUE The certificate Extension data retrieved successfully.
429 @retval FALSE If Cert is NULL.
431 If Oid is not NULL and *OidSize is 0.
432 If Certificate is invalid.
433 @retval FALSE If no SignatureType.
434 @retval FALSE If the Oid is NULL. The required buffer size
435 is returned in the OidSize.
436 @retval FALSE The operation is not supported.
440 X509GetSignatureAlgorithm (
441 IN CONST UINT8
*Cert
,
443 OUT UINT8
*Oid
, OPTIONAL
444 IN OUT UINTN
*OidSize
452 Retrieve Extension data from one X.509 certificate.
454 @param[in] Cert Pointer to the DER-encoded X509 certificate.
455 @param[in] CertSize Size of the X509 certificate in bytes.
456 @param[in] Oid Object identifier buffer
457 @param[in] OidSize Object identifier buffer size
458 @param[out] ExtensionData Extension bytes.
459 @param[in, out] ExtensionDataSize Extension bytes size.
461 @retval TRUE The certificate Extension data retrieved successfully.
462 @retval FALSE If Cert is NULL.
463 If ExtensionDataSize is NULL.
464 If ExtensionData is not NULL and *ExtensionDataSize is 0.
465 If Certificate is invalid.
466 @retval FALSE If no Extension entry match Oid.
467 @retval FALSE If the ExtensionData is NULL. The required buffer size
468 is returned in the ExtensionDataSize parameter.
469 @retval FALSE The operation is not supported.
473 X509GetExtensionData (
474 IN CONST UINT8
*Cert
,
478 OUT UINT8
*ExtensionData
,
479 IN OUT UINTN
*ExtensionDataSize
487 Retrieve the Extended Key Usage from one X.509 certificate.
489 @param[in] Cert Pointer to the DER-encoded X509 certificate.
490 @param[in] CertSize Size of the X509 certificate in bytes.
491 @param[out] Usage Key Usage bytes.
492 @param[in, out] UsageSize Key Usage buffer sizs in bytes.
494 @retval TRUE The Usage bytes retrieve successfully.
495 @retval FALSE If Cert is NULL.
497 If Usage is not NULL and *UsageSize is 0.
499 @retval FALSE If the Usage is NULL. The required buffer size
500 is returned in the UsageSize parameter.
501 @retval FALSE The operation is not supported.
505 X509GetExtendedKeyUsage (
506 IN CONST UINT8
*Cert
,
509 IN OUT UINTN
*UsageSize
517 Retrieve the Validity from one X.509 certificate
519 If Cert is NULL, then return FALSE.
520 If CertIssuerSize is NULL, then return FALSE.
521 If this interface is not supported, then return FALSE.
523 @param[in] Cert Pointer to the DER-encoded X509 certificate.
524 @param[in] CertSize Size of the X509 certificate in bytes.
525 @param[in] From notBefore Pointer to DateTime object.
526 @param[in,out] FromSize notBefore DateTime object size.
527 @param[in] To notAfter Pointer to DateTime object.
528 @param[in,out] ToSize notAfter DateTime object size.
530 Note: X509CompareDateTime to compare DateTime oject
531 x509SetDateTime to get a DateTime object from a DateTimeStr
533 @retval TRUE The certificate Validity retrieved successfully.
534 @retval FALSE Invalid certificate, or Validity retrieve failed.
535 @retval FALSE This interface is not supported.
540 IN CONST UINT8
*Cert
,
543 IN OUT UINTN
*FromSize
,
553 Format a DateTimeStr to DataTime object in DataTime Buffer
555 If DateTimeStr is NULL, then return FALSE.
556 If DateTimeSize is NULL, then return FALSE.
557 If this interface is not supported, then return FALSE.
559 @param[in] DateTimeStr DateTime string like YYYYMMDDhhmmssZ
560 Ref: https://www.w3.org/TR/NOTE-datetime
562 @param[out] DateTime Pointer to a DateTime object.
563 @param[in,out] DateTimeSize DateTime object buffer size.
565 @retval TRUE The DateTime object create successfully.
566 @retval FALSE If DateTimeStr is NULL.
567 If DateTimeSize is NULL.
568 If DateTime is not NULL and *DateTimeSize is 0.
569 If Year Month Day Hour Minute Second combination is invalid datetime.
570 @retval FALSE If the DateTime is NULL. The required buffer size
571 (including the final null) is returned in the
572 DateTimeSize parameter.
573 @retval FALSE The operation is not supported.
578 IN CONST CHAR8
*DateTimeStr
,
580 IN OUT UINTN
*DateTimeSize
588 Compare DateTime1 object and DateTime2 object.
590 If DateTime1 is NULL, then return -2.
591 If DateTime2 is NULL, then return -2.
592 If DateTime1 == DateTime2, then return 0
593 If DateTime1 > DateTime2, then return 1
594 If DateTime1 < DateTime2, then return -1
596 @param[in] DateTime1 Pointer to a DateTime Ojbect
597 @param[in] DateTime2 Pointer to a DateTime Object
599 @retval 0 If DateTime1 == DateTime2
600 @retval 1 If DateTime1 > DateTime2
601 @retval -1 If DateTime1 < DateTime2
605 X509CompareDateTime (
606 IN CONST VOID
*DateTime1
,
607 IN CONST VOID
*DateTime2
615 Retrieve the Key Usage from one X.509 certificate.
617 @param[in] Cert Pointer to the DER-encoded X509 certificate.
618 @param[in] CertSize Size of the X509 certificate in bytes.
619 @param[out] Usage Key Usage (CRYPTO_X509_KU_*)
621 @retval TRUE The certificate Key Usage retrieved successfully.
622 @retval FALSE Invalid certificate, or Usage is NULL
623 @retval FALSE This interface is not supported.
628 IN CONST UINT8
*Cert
,
638 Verify one X509 certificate was issued by the trusted CA.
639 @param[in] RootCert Trusted Root Certificate buffer
641 @param[in] RootCertLength Trusted Root Certificate buffer length
642 @param[in] CertChain One or more ASN.1 DER-encoded X.509 certificates
643 where the first certificate is signed by the Root
644 Certificate or is the Root Cerificate itself. and
645 subsequent cerificate is signed by the preceding
647 @param[in] CertChainLength Total length of the certificate chain, in bytes.
649 @retval TRUE All cerificates was issued by the first certificate in X509Certchain.
650 @retval FALSE Invalid certificate or the certificate was not issued by the given
655 X509VerifyCertChain (
656 IN CONST UINT8
*RootCert
,
657 IN UINTN RootCertLength
,
658 IN CONST UINT8
*CertChain
,
659 IN UINTN CertChainLength
667 Get one X509 certificate from CertChain.
669 @param[in] CertChain One or more ASN.1 DER-encoded X.509 certificates
670 where the first certificate is signed by the Root
671 Certificate or is the Root Cerificate itself. and
672 subsequent cerificate is signed by the preceding
674 @param[in] CertChainLength Total length of the certificate chain, in bytes.
676 @param[in] CertIndex Index of certificate.
678 @param[out] Cert The certificate at the index of CertChain.
679 @param[out] CertLength The length certificate at the index of CertChain.
681 @retval TRUE Success.
682 @retval FALSE Failed to get certificate from certificate chain.
686 X509GetCertFromCertChain (
687 IN CONST UINT8
*CertChain
,
688 IN UINTN CertChainLength
,
689 IN CONST INT32 CertIndex
,
690 OUT CONST UINT8
**Cert
,
691 OUT UINTN
*CertLength
699 Retrieve the tag and length of the tag.
701 @param Ptr The position in the ASN.1 data
702 @param End End of data
703 @param Length The variable that will receive the length
704 @param Tag The expected tag
706 @retval TRUE Get tag successful
707 @retval FALSe Failed to get tag or tag not match
723 Retrieve the basic constraints from one X.509 certificate.
725 @param[in] Cert Pointer to the DER-encoded X509 certificate.
726 @param[in] CertSize size of the X509 certificate in bytes.
727 @param[out] BasicConstraints basic constraints bytes.
728 @param[in, out] BasicConstraintsSize basic constraints buffer sizs in bytes.
730 @retval TRUE The basic constraints retrieve successfully.
731 @retval FALSE If cert is NULL.
732 If cert_size is NULL.
733 If basic_constraints is not NULL and *basic_constraints_size is 0.
735 @retval FALSE The required buffer size is small.
736 The return buffer size is basic_constraints_size parameter.
737 @retval FALSE If no Extension entry match oid.
738 @retval FALSE The operation is not supported.
742 X509GetExtendedBasicConstraints (
745 UINT8
*BasicConstraints
,
746 UINTN
*BasicConstraintsSize