Lines Matching refs:cert

91 	int cert;  member
179 return kt->cert; in sshkey_type_is_cert()
205 (!kt->cert && strcasecmp(kt->shortname, name) == 0)) in sshkey_type_from_name()
237 if ((certs_only && !kt->cert) || (plain_only && kt->cert)) in sshkey_alg_list()
454 cert_free(struct sshkey_cert *cert) in cert_free() argument
458 if (cert == NULL) in cert_free()
460 sshbuf_free(cert->certblob); in cert_free()
461 sshbuf_free(cert->critical); in cert_free()
462 sshbuf_free(cert->extensions); in cert_free()
463 free(cert->key_id); in cert_free()
464 for (i = 0; i < cert->nprincipals; i++) in cert_free()
465 free(cert->principals[i]); in cert_free()
466 free(cert->principals); in cert_free()
467 sshkey_free(cert->signature_key); in cert_free()
468 freezero(cert, sizeof(*cert)); in cert_free()
474 struct sshkey_cert *cert; in cert_new() local
476 if ((cert = calloc(1, sizeof(*cert))) == NULL) in cert_new()
478 if ((cert->certblob = sshbuf_new()) == NULL || in cert_new()
479 (cert->critical = sshbuf_new()) == NULL || in cert_new()
480 (cert->extensions = sshbuf_new()) == NULL) { in cert_new()
481 cert_free(cert); in cert_new()
484 cert->key_id = NULL; in cert_new()
485 cert->principals = NULL; in cert_new()
486 cert->signature_key = NULL; in cert_new()
487 return cert; in cert_new()
506 k->cert = NULL; in sshkey_new()
548 if ((k->cert = cert_new()) == NULL) { in sshkey_new()
620 cert_free(k->cert); in sshkey_free()
726 if (!cert_compare(a->cert, b->cert)) in sshkey_equal()
746 if (key->cert == NULL) in to_blob_buf()
748 if (sshbuf_len(key->cert->certblob) == 0) in to_blob_buf()
766 if ((ret = sshbuf_putb(b, key->cert->certblob)) != 0) in to_blob_buf()
1323 if (ret->cert != NULL) in sshkey_read()
1324 cert_free(ret->cert); in sshkey_read()
1325 ret->cert = k->cert; in sshkey_read()
1326 k->cert = NULL; in sshkey_read()
1470 switch (k->cert->type) { in sshkey_cert_type()
1680 if (to_key->cert != NULL) { in sshkey_cert_copy()
1681 cert_free(to_key->cert); in sshkey_cert_copy()
1682 to_key->cert = NULL; in sshkey_cert_copy()
1685 if ((from = from_key->cert) == NULL) in sshkey_cert_copy()
1688 if ((to = to_key->cert = cert_new()) == NULL) in sshkey_cert_copy()
1882 if ((ret = sshbuf_putb(key->cert->certblob, certbuf)) != 0) in cert_parse()
1886 if ((ret = sshbuf_get_u64(b, &key->cert->serial)) != 0 || in cert_parse()
1887 (ret = sshbuf_get_u32(b, &key->cert->type)) != 0 || in cert_parse()
1888 (ret = sshbuf_get_cstring(b, &key->cert->key_id, &kidlen)) != 0 || in cert_parse()
1890 (ret = sshbuf_get_u64(b, &key->cert->valid_after)) != 0 || in cert_parse()
1891 (ret = sshbuf_get_u64(b, &key->cert->valid_before)) != 0 || in cert_parse()
1902 signed_len = sshbuf_len(key->cert->certblob) - sshbuf_len(b); in cert_parse()
1909 if (key->cert->type != SSH2_CERT_TYPE_USER && in cert_parse()
1910 key->cert->type != SSH2_CERT_TYPE_HOST) { in cert_parse()
1920 if (key->cert->nprincipals >= SSHKEY_CERT_MAX_PRINCIPALS) { in cert_parse()
1929 oprincipals = key->cert->principals; in cert_parse()
1930 key->cert->principals = recallocarray(key->cert->principals, in cert_parse()
1931 key->cert->nprincipals, key->cert->nprincipals + 1, in cert_parse()
1932 sizeof(*key->cert->principals)); in cert_parse()
1933 if (key->cert->principals == NULL) { in cert_parse()
1935 key->cert->principals = oprincipals; in cert_parse()
1939 key->cert->principals[key->cert->nprincipals++] = principal; in cert_parse()
1946 if ((ret = sshbuf_putb(key->cert->critical, crit)) != 0 || in cert_parse()
1948 (ret = sshbuf_putb(key->cert->extensions, exts)) != 0)) in cert_parse()
1957 sshbuf_reset(key->cert->critical); in cert_parse()
1965 sshbuf_reset(key->cert->extensions); in cert_parse()
1972 if (sshkey_from_blob_internal(ca, &key->cert->signature_key, 0) != 0) { in cert_parse()
1976 if (!sshkey_type_is_valid_ca(key->cert->signature_key->type)) { in cert_parse()
1980 if ((ret = sshkey_verify(key->cert->signature_key, sig, slen, in cert_parse()
1981 sshbuf_ptr(key->cert->certblob), signed_len, NULL, 0)) != 0) in cert_parse()
2333 if (!kt->cert) in sshkey_sigalg_by_name()
2469 if ((k->cert = cert_new()) == NULL) in sshkey_to_certified()
2481 cert_free(k->cert); in sshkey_drop_cert()
2482 k->cert = NULL; in sshkey_drop_cert()
2496 struct sshbuf *cert; in sshkey_certify_custom() local
2501 if (k == NULL || k->cert == NULL || in sshkey_certify_custom()
2502 k->cert->certblob == NULL || ca == NULL) in sshkey_certify_custom()
2512 cert = k->cert->certblob; /* for readability */ in sshkey_certify_custom()
2513 sshbuf_reset(cert); in sshkey_certify_custom()
2514 if ((ret = sshbuf_put_cstring(cert, sshkey_ssh_name(k))) != 0) in sshkey_certify_custom()
2519 if ((ret = sshbuf_put_string(cert, nonce, sizeof(nonce))) != 0) in sshkey_certify_custom()
2528 if ((ret = sshbuf_put_bignum2(cert, dsa_p)) != 0 || in sshkey_certify_custom()
2529 (ret = sshbuf_put_bignum2(cert, dsa_q)) != 0 || in sshkey_certify_custom()
2530 (ret = sshbuf_put_bignum2(cert, dsa_g)) != 0 || in sshkey_certify_custom()
2531 (ret = sshbuf_put_bignum2(cert, dsa_pub_key)) != 0) in sshkey_certify_custom()
2536 if ((ret = sshbuf_put_cstring(cert, in sshkey_certify_custom()
2538 (ret = sshbuf_put_ec(cert, in sshkey_certify_custom()
2546 if ((ret = sshbuf_put_bignum2(cert, rsa_e)) != 0 || in sshkey_certify_custom()
2547 (ret = sshbuf_put_bignum2(cert, rsa_n)) != 0) in sshkey_certify_custom()
2552 if ((ret = sshbuf_put_string(cert, in sshkey_certify_custom()
2562 if ((ret = sshbuf_put_cstring(cert, k->xmss_name)) || in sshkey_certify_custom()
2563 (ret = sshbuf_put_string(cert, in sshkey_certify_custom()
2573 if ((ret = sshbuf_put_u64(cert, k->cert->serial)) != 0 || in sshkey_certify_custom()
2574 (ret = sshbuf_put_u32(cert, k->cert->type)) != 0 || in sshkey_certify_custom()
2575 (ret = sshbuf_put_cstring(cert, k->cert->key_id)) != 0) in sshkey_certify_custom()
2582 for (i = 0; i < k->cert->nprincipals; i++) { in sshkey_certify_custom()
2584 k->cert->principals[i])) != 0) in sshkey_certify_custom()
2587 if ((ret = sshbuf_put_stringb(cert, principals)) != 0 || in sshkey_certify_custom()
2588 (ret = sshbuf_put_u64(cert, k->cert->valid_after)) != 0 || in sshkey_certify_custom()
2589 (ret = sshbuf_put_u64(cert, k->cert->valid_before)) != 0 || in sshkey_certify_custom()
2590 (ret = sshbuf_put_stringb(cert, k->cert->critical)) != 0 || in sshkey_certify_custom()
2591 (ret = sshbuf_put_stringb(cert, k->cert->extensions)) != 0 || in sshkey_certify_custom()
2592 (ret = sshbuf_put_string(cert, NULL, 0)) != 0 || /* Reserved */ in sshkey_certify_custom()
2593 (ret = sshbuf_put_string(cert, ca_blob, ca_len)) != 0) in sshkey_certify_custom()
2597 if ((ret = signer(ca, &sig_blob, &sig_len, sshbuf_ptr(cert), in sshkey_certify_custom()
2598 sshbuf_len(cert), alg, 0, signer_ctx)) != 0) in sshkey_certify_custom()
2602 if ((ret = sshbuf_put_string(cert, sig_blob, sig_len)) != 0) in sshkey_certify_custom()
2607 sshbuf_reset(cert); in sshkey_certify_custom()
2642 if (k->cert->type != SSH2_CERT_TYPE_HOST) { in sshkey_cert_check_authority()
2647 if (k->cert->type != SSH2_CERT_TYPE_USER) { in sshkey_cert_check_authority()
2657 if ((u_int64_t)now < k->cert->valid_after) { in sshkey_cert_check_authority()
2661 if ((u_int64_t)now >= k->cert->valid_before) { in sshkey_cert_check_authority()
2665 if (k->cert->nprincipals == 0) { in sshkey_cert_check_authority()
2672 for (i = 0; i < k->cert->nprincipals; i++) { in sshkey_cert_check_authority()
2673 if (strcmp(name, k->cert->principals[i]) == 0) { in sshkey_cert_check_authority()
2688 sshkey_format_cert_validity(const struct sshkey_cert *cert, char *s, size_t l) in sshkey_format_cert_validity() argument
2695 if (cert->valid_after == 0 && in sshkey_format_cert_validity()
2696 cert->valid_before == 0xffffffffffffffffULL) in sshkey_format_cert_validity()
2699 if (cert->valid_after != 0) { in sshkey_format_cert_validity()
2701 tt = cert->valid_after > INT_MAX ? in sshkey_format_cert_validity()
2702 INT_MAX : cert->valid_after; in sshkey_format_cert_validity()
2706 if (cert->valid_before != 0xffffffffffffffffULL) { in sshkey_format_cert_validity()
2708 tt = cert->valid_before > INT_MAX ? in sshkey_format_cert_validity()
2709 INT_MAX : cert->valid_before; in sshkey_format_cert_validity()
2714 if (cert->valid_after == 0) in sshkey_format_cert_validity()
2716 else if (cert->valid_before == 0xffffffffffffffffULL) in sshkey_format_cert_validity()
2751 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0) { in sshkey_private_serialize_opt()
2758 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()
2776 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0) { in sshkey_private_serialize_opt()
2781 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()
2795 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0) { in sshkey_private_serialize_opt()
2799 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()
2814 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0) { in sshkey_private_serialize_opt()
2818 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()
2840 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0 || in sshkey_private_serialize_opt()
2845 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()