/* Licensed to the Apache Software Foundation (ASF) under one or more *contributorlicenseagreements.SeetheNOTICEfiledistributedwith *thisworkforadditionalinformationregardingcopyrightownership. *TheASFlicensesthisfiletoYouundertheApacheLicense,Version2.0 *(the"License");youmaynotusethisfileexceptincompliancewith *theLicense.YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
/* we initialize this index at startup time *andneverwritetoitatrequesttime, *sothisstaticisthreadsafe. *alsonotethatOpenSSLincrementsatstaticvariablewhen *SSL_get_ex_new_index()iscalled,sowe_must_dothisatstartup.
*/ staticint app_data2_idx = -1;
void modssl_init_app_data2_idx(void)
{ int i;
if (app_data2_idx > -1) { return;
}
/* we _do_ need to call this twice */ for (i = 0; i <= 1; i++) {
app_data2_idx =
SSL_get_ex_new_index(0, "Second Application Data for SSL",
NULL, NULL, NULL);
}
}
char *modssl_bio_free_read(apr_pool_t *p, BIO *bio)
{ int len = BIO_pending(bio); char *result = NULL;
if (len > 0) {
result = apr_palloc(p, len+1);
len = BIO_read(bio, result, len);
result[len] = NUL;
}
BIO_free(bio); return result;
}
/* Convert ASN.1 string to a pool-allocated char * string, escaping *controlcharacters.Ifrawiszero,converttoUTF-8,otherwise
* unchanged from the character set. */ staticchar *asn1_string_convert(apr_pool_t *p, ASN1_STRING *asn1str, int raw)
{
BIO *bio; int flags = ASN1_STRFLGS_ESC_CTRL;
if ((bio = BIO_new(BIO_s_mem())) == NULL) return NULL;
if (!raw) flags |= ASN1_STRFLGS_UTF8_CONVERT;
ASN1_STRING_print_ex(bio, asn1str, flags);
return modssl_bio_free_read(p, bio);
}
#define asn1_string_to_utf8(p, a) asn1_string_convert(p, a, 0)
/* convert a NAME_ENTRY to UTF8 string */ char *modssl_X509_NAME_ENTRY_to_string(apr_pool_t *p, X509_NAME_ENTRY *xsne, int raw)
{ char *result = asn1_string_convert(p, X509_NAME_ENTRY_get_data(xsne), raw);
ap_xlate_proto_from_ascii(result, len); return result;
}
/* *convertanX509_NAMEtoanRFC2253formattedstring,optionallytruncated *tomaxlencharacters(specifyamaxlenof0fornolengthlimit)
*/ char *modssl_X509_NAME_to_string(apr_pool_t *p, X509_NAME *dn, int maxlen)
{ char *result = NULL;
BIO *bio; int len;
if ((bio = BIO_new(BIO_s_mem())) == NULL) return NULL;
X509_NAME_print_ex(bio, dn, 0, XN_FLAG_RFC2253);
len = BIO_pending(bio); if (len > 0) {
result = apr_palloc(p, (maxlen > 0) ? maxlen+1 : len+1); if (maxlen > 0 && maxlen < len) {
len = BIO_read(bio, result, maxlen); if (maxlen > 2) { /* insert trailing ellipsis if there's enough space */
apr_snprintf(result + maxlen - 3, 4, "...");
}
} else {
len = BIO_read(bio, result, len);
}
result[len] = NUL;
}
BIO_free(bio);
return result;
}
staticvoid parse_otherName_value(apr_pool_t *p, ASN1_TYPE *value, constchar *onf, apr_array_header_t **entries)
{ constchar *str; int nid = onf ? OBJ_txt2nid(onf) : NID_undef;
if (!value || (nid == NID_undef) || !*entries) return;
/* return an array of (RFC 6125 coined) DNS-IDs and CN-IDs in a certificate */ staticBOOL getIDs(apr_pool_t *p, X509 *x509, apr_array_header_t **ids)
{
X509_NAME *subj; int i = -1;
/* First, the DNS-IDs (dNSName entries in the subjectAltName extension) */ if (!x509 ||
(modssl_X509_getSAN(p, x509, GEN_DNS, NULL, -1, ids) == FALSE && !*ids)) {
*ids = NULL; returnFALSE;
}
/* Second, the CN-IDs (commonName attributes in the subject DN) */
subj = X509_get_subject_name(x509); while ((i = X509_NAME_get_index_by_NID(subj, NID_commonName, i)) != -1) {
APR_ARRAY_PUSH(*ids, constchar *) =
modssl_X509_NAME_ENTRY_to_string(p, X509_NAME_get_entry(subj, i), 0);
}
char *modssl_SSL_SESSION_id2sz(IDCONST unsignedchar *id, int idlen, char *str, int strsize)
{ if (idlen > SSL_MAX_SSL_SESSION_ID_LENGTH)
idlen = SSL_MAX_SSL_SESSION_ID_LENGTH;
/* We must ensure not to process more than what would fit in the
* destination buffer, including terminating NULL */ if (idlen > (strsize-1) / 2)
idlen = (strsize-1) / 2;
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.