/* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */ /* vim: set ts=8 sts=2 et sw=2 tw=80: */ /* This code is made available to you under your choice of the following sets *oflicensingterms:
*/ /* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.IfacopyoftheMPLwasnotdistributedwiththis *file,Youcanobtainoneathttp://mozilla.org/MPL/2.0/.
*/ /* Copyright 2013 Mozilla Contributors * *LicensedundertheApacheLicense,Version2.0(the"License"); *youmaynotusethisfileexceptincompliancewiththeLicense. *YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
// During path building and verification, we build a linked list of BackCerts // from the current cert toward the end-entity certificate. The linked list // is used to verify properties that aren't local to the current certificate // and/or the direct link between the current certificate and its issuer, // such as name constraints. // // Each BackCert contains pointers to all the given certificate's extensions // so that we can parse the extension block once and then process the // extensions in an order that may be different than they appear in the cert. class BackCert final { public: // certDER and childCert must be valid for the lifetime of BackCert.
BackCert(Input aCertDER, EndEntityOrCA aEndEntityOrCA, const BackCert* aChildCert)
: der(aCertDER),
endEntityOrCA(aEndEntityOrCA),
childCert(aChildCert),
version(der::Version::Uninitialized) {}
private: // When parsing certificates in BackCert::Init, we don't accept empty // extensions. Consequently, we don't have to store a distinction between // empty extensions and extensions that weren't included. However, when // *processing* extensions, we distinguish between whether an extension was // included or not based on whetehr the GetXXX function for the extension // returns nullptr. staticinlineconst Input* MaybeInput(const Input& item) { return item.GetLength() > 0 ? &item : nullptr;
}
der::SignedDataWithSignature signedData;
der::Version version;
Input serialNumber;
Input signature;
Input issuer; // XXX: "validity" is a horrible name for the structure that holds // notBefore & notAfter, but that is the name used in RFC 5280 and we use the // RFC 5280 names for everything.
Input validity;
Input subject;
Input subjectPublicKeyInfo;
class NonOwningDERArray final : public DERArray { public:
NonOwningDERArray() : numItems(0) { // we don't need to initialize the items array because we always check // numItems before accessing i.
}
// Extracts the SignedCertificateTimestampList structure which is encoded as an // OCTET STRING within the X.509v3 / OCSP extensions (see RFC 6962 section 3.3).
Result ExtractSignedCertificateTimestampListFromExtension(Input extnValue,
Input& sctList);
inlineunsignedint DaysBeforeYear(unsignedint year) {
assert(year <= 9999); return ((year - 1u) * 365u) +
((year - 1u) / 4u) // leap years are every 4 years,
- ((year - 1u) / 100u) // except years divisible by 100,
+ ((year - 1u) / 400u); // except years divisible by 400.
}
Result VerifySignedData(TrustDomain& trustDomain, const der::SignedDataWithSignature& signedData,
Input signerSubjectPublicKeyInfo);
// Extracts the key parameters from |subjectPublicKeyInfo|, invoking // the relevant methods of |trustDomain|.
Result CheckSubjectPublicKeyInfo(Input subjectPublicKeyInfo,
TrustDomain& trustDomain,
EndEntityOrCA endEntityOrCA);
// In a switch over an enum, sometimes some compilers are not satisfied that // all control flow paths have been considered unless there is a default case. // However, in our code, such a default case is almost always unreachable dead // code. That can be particularly problematic when the compiler wants the code // to choose a value, such as a return value, for the default case, but there's // no appropriate "impossible case" value to choose. // // MOZILLA_PKIX_UNREACHABLE_DEFAULT_ENUM accounts for this. Example: // // // In xy.cpp // #include "xt.h" // // enum class XY { X, Y }; // // int func(XY xy) { // switch (xy) { // case XY::X: return 1; // case XY::Y; return 2; // MOZILLA_PKIX_UNREACHABLE_DEFAULT_ENUM // } // } #ifdefined(__clang__) // Clang will warn if not all cases are covered (-Wswitch-enum) AND it will // warn if a switch statement that covers every enum label has a default case // (-W-covered-switch-default). Versions prior to 3.5 warned about unreachable // code in such default cases (-Wunreachable-code) even when // -W-covered-switch-default was disabled, but that changed in Clang 3.5. #define MOZILLA_PKIX_UNREACHABLE_DEFAULT_ENUM // empty #elifdefined(__GNUC__) // GCC will warn if not all cases are covered (-Wswitch-enum). It does not // assume that the default case is unreachable. #define MOZILLA_PKIX_UNREACHABLE_DEFAULT_ENUM \ default: \
assert(false); \
__builtin_unreachable(); #elifdefined(_MSC_VER) // MSVC will warn if not all cases are covered (C4061, level 4). It does not // assume that the default case is unreachable. #define MOZILLA_PKIX_UNREACHABLE_DEFAULT_ENUM \ default: \
assert(false); \
__assume(0); #else #error Unsupported compiler for MOZILLA_PKIX_UNREACHABLE_DEFAULT. #endif
inline size_t DigestAlgorithmToSizeInBytes(DigestAlgorithm digestAlgorithm) { switch (digestAlgorithm) { case DigestAlgorithm::sha1: return160 / 8; case DigestAlgorithm::sha256: return256 / 8; case DigestAlgorithm::sha384: return384 / 8; case DigestAlgorithm::sha512: return512 / 8;
MOZILLA_PKIX_UNREACHABLE_DEFAULT_ENUM
}
}
} // namespace pkix
} // namespace mozilla
#endif// mozilla_pkix_pkixutil_h
Messung V0.5 in Prozent
¤ Dauer der Verarbeitung: 0.11 Sekunden
(vorverarbeitet am 2026-10-11)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.