Lines Matching refs:cert
103 int cert; member
193 return kt->cert; in sshkey_type_is_cert()
219 (!kt->cert && strcasecmp(kt->shortname, name) == 0)) in sshkey_type_from_name()
264 if ((certs_only && !kt->cert) || (plain_only && kt->cert)) in sshkey_alg_list()
505 cert_free(struct sshkey_cert *cert) in cert_free() argument
509 if (cert == NULL) in cert_free()
511 sshbuf_free(cert->certblob); in cert_free()
512 sshbuf_free(cert->critical); in cert_free()
513 sshbuf_free(cert->extensions); in cert_free()
514 free(cert->key_id); in cert_free()
515 for (i = 0; i < cert->nprincipals; i++) in cert_free()
516 free(cert->principals[i]); in cert_free()
517 free(cert->principals); in cert_free()
518 sshkey_free(cert->signature_key); in cert_free()
519 free(cert->signature_type); in cert_free()
520 freezero(cert, sizeof(*cert)); in cert_free()
526 struct sshkey_cert *cert; in cert_new() local
528 if ((cert = calloc(1, sizeof(*cert))) == NULL) in cert_new()
530 if ((cert->certblob = sshbuf_new()) == NULL || in cert_new()
531 (cert->critical = sshbuf_new()) == NULL || in cert_new()
532 (cert->extensions = sshbuf_new()) == NULL) { in cert_new()
533 cert_free(cert); in cert_new()
536 cert->key_id = NULL; in cert_new()
537 cert->principals = NULL; in cert_new()
538 cert->signature_key = NULL; in cert_new()
539 cert->signature_type = NULL; in cert_new()
540 return cert; in cert_new()
559 k->cert = NULL; in sshkey_new()
605 if ((k->cert = cert_new()) == NULL) { in sshkey_new()
678 cert_free(k->cert); in sshkey_free()
792 if (!cert_compare(a->cert, b->cert)) in sshkey_equal()
812 if (key->cert == NULL) in to_blob_buf()
814 if (sshbuf_len(key->cert->certblob) == 0) in to_blob_buf()
834 if ((ret = sshbuf_putb(b, key->cert->certblob)) != 0) in to_blob_buf()
1401 if (ret->cert != NULL) in sshkey_read()
1402 cert_free(ret->cert); in sshkey_read()
1403 ret->cert = k->cert; in sshkey_read()
1404 k->cert = NULL; in sshkey_read()
1568 switch (k->cert->type) { in sshkey_cert_type()
1772 if (to_key == NULL || (from = from_key->cert) == NULL) in sshkey_cert_copy()
1825 cert_free(to_key->cert); in sshkey_cert_copy()
1826 to_key->cert = to; in sshkey_cert_copy()
2206 if ((ret = sshbuf_putb(key->cert->certblob, certbuf)) != 0) in cert_parse()
2210 if ((ret = sshbuf_get_u64(b, &key->cert->serial)) != 0 || in cert_parse()
2211 (ret = sshbuf_get_u32(b, &key->cert->type)) != 0 || in cert_parse()
2212 (ret = sshbuf_get_cstring(b, &key->cert->key_id, &kidlen)) != 0 || in cert_parse()
2214 (ret = sshbuf_get_u64(b, &key->cert->valid_after)) != 0 || in cert_parse()
2215 (ret = sshbuf_get_u64(b, &key->cert->valid_before)) != 0 || in cert_parse()
2226 signed_len = sshbuf_len(key->cert->certblob) - sshbuf_len(b); in cert_parse()
2233 if (key->cert->type != SSH2_CERT_TYPE_USER && in cert_parse()
2234 key->cert->type != SSH2_CERT_TYPE_HOST) { in cert_parse()
2244 if (key->cert->nprincipals >= SSHKEY_CERT_MAX_PRINCIPALS) { in cert_parse()
2253 oprincipals = key->cert->principals; in cert_parse()
2254 key->cert->principals = recallocarray(key->cert->principals, in cert_parse()
2255 key->cert->nprincipals, key->cert->nprincipals + 1, in cert_parse()
2256 sizeof(*key->cert->principals)); in cert_parse()
2257 if (key->cert->principals == NULL) { in cert_parse()
2259 key->cert->principals = oprincipals; in cert_parse()
2263 key->cert->principals[key->cert->nprincipals++] = principal; in cert_parse()
2270 if ((ret = sshbuf_putb(key->cert->critical, crit)) != 0 || in cert_parse()
2272 (ret = sshbuf_putb(key->cert->extensions, exts)) != 0)) in cert_parse()
2281 sshbuf_reset(key->cert->critical); in cert_parse()
2289 sshbuf_reset(key->cert->extensions); in cert_parse()
2296 if (sshkey_from_blob_internal(ca, &key->cert->signature_key, 0) != 0) { in cert_parse()
2300 if (!sshkey_type_is_valid_ca(key->cert->signature_key->type)) { in cert_parse()
2304 if ((ret = sshkey_verify(key->cert->signature_key, sig, slen, in cert_parse()
2305 sshbuf_ptr(key->cert->certblob), signed_len, NULL, 0, NULL)) != 0) in cert_parse()
2308 &key->cert->signature_type)) != 0) in cert_parse()
2675 if (key->cert == NULL || key->cert->signature_type == NULL) in sshkey_check_cert_sigtype()
2677 if (match_pattern_list(key->cert->signature_type, allowed, 0) != 1) in sshkey_check_cert_sigtype()
2695 if (!kt->cert) in sshkey_sigalg_by_name()
2870 if ((k->cert = cert_new()) == NULL) in sshkey_to_certified()
2882 cert_free(k->cert); in sshkey_drop_cert()
2883 k->cert = NULL; in sshkey_drop_cert()
2898 struct sshbuf *cert = NULL; in sshkey_certify_custom() local
2904 if (k == NULL || k->cert == NULL || in sshkey_certify_custom()
2905 k->cert->certblob == NULL || ca == NULL) in sshkey_certify_custom()
2917 alg = k->cert->signature_type; in sshkey_certify_custom()
2918 else if (k->cert->signature_type != NULL && in sshkey_certify_custom()
2919 strcmp(alg, k->cert->signature_type) != 0) in sshkey_certify_custom()
2932 cert = k->cert->certblob; /* for readability */ in sshkey_certify_custom()
2933 sshbuf_reset(cert); in sshkey_certify_custom()
2934 if ((ret = sshbuf_put_cstring(cert, sshkey_ssh_name(k))) != 0) in sshkey_certify_custom()
2939 if ((ret = sshbuf_put_string(cert, nonce, sizeof(nonce))) != 0) in sshkey_certify_custom()
2948 if ((ret = sshbuf_put_bignum2(cert, dsa_p)) != 0 || in sshkey_certify_custom()
2949 (ret = sshbuf_put_bignum2(cert, dsa_q)) != 0 || in sshkey_certify_custom()
2950 (ret = sshbuf_put_bignum2(cert, dsa_g)) != 0 || in sshkey_certify_custom()
2951 (ret = sshbuf_put_bignum2(cert, dsa_pub_key)) != 0) in sshkey_certify_custom()
2957 if ((ret = sshbuf_put_cstring(cert, in sshkey_certify_custom()
2959 (ret = sshbuf_put_ec(cert, in sshkey_certify_custom()
2964 if ((ret = sshbuf_put_cstring(cert, in sshkey_certify_custom()
2972 if ((ret = sshbuf_put_bignum2(cert, rsa_e)) != 0 || in sshkey_certify_custom()
2973 (ret = sshbuf_put_bignum2(cert, rsa_n)) != 0) in sshkey_certify_custom()
2979 if ((ret = sshbuf_put_string(cert, in sshkey_certify_custom()
2983 if ((ret = sshbuf_put_cstring(cert, in sshkey_certify_custom()
2994 if ((ret = sshbuf_put_cstring(cert, k->xmss_name)) || in sshkey_certify_custom()
2995 (ret = sshbuf_put_string(cert, in sshkey_certify_custom()
3005 if ((ret = sshbuf_put_u64(cert, k->cert->serial)) != 0 || in sshkey_certify_custom()
3006 (ret = sshbuf_put_u32(cert, k->cert->type)) != 0 || in sshkey_certify_custom()
3007 (ret = sshbuf_put_cstring(cert, k->cert->key_id)) != 0) in sshkey_certify_custom()
3014 for (i = 0; i < k->cert->nprincipals; i++) { in sshkey_certify_custom()
3016 k->cert->principals[i])) != 0) in sshkey_certify_custom()
3019 if ((ret = sshbuf_put_stringb(cert, principals)) != 0 || in sshkey_certify_custom()
3020 (ret = sshbuf_put_u64(cert, k->cert->valid_after)) != 0 || in sshkey_certify_custom()
3021 (ret = sshbuf_put_u64(cert, k->cert->valid_before)) != 0 || in sshkey_certify_custom()
3022 (ret = sshbuf_put_stringb(cert, k->cert->critical)) != 0 || in sshkey_certify_custom()
3023 (ret = sshbuf_put_stringb(cert, k->cert->extensions)) != 0 || in sshkey_certify_custom()
3024 (ret = sshbuf_put_string(cert, NULL, 0)) != 0 || /* Reserved */ in sshkey_certify_custom()
3025 (ret = sshbuf_put_string(cert, ca_blob, ca_len)) != 0) in sshkey_certify_custom()
3029 if ((ret = signer(ca, &sig_blob, &sig_len, sshbuf_ptr(cert), in sshkey_certify_custom()
3030 sshbuf_len(cert), alg, sk_provider, sk_pin, 0, signer_ctx)) != 0) in sshkey_certify_custom()
3039 if (k->cert->signature_type == NULL) { in sshkey_certify_custom()
3040 k->cert->signature_type = sigtype; in sshkey_certify_custom()
3044 if ((ret = sshbuf_put_string(cert, sig_blob, sig_len)) != 0) in sshkey_certify_custom()
3049 sshbuf_reset(cert); in sshkey_certify_custom()
3091 if (k->cert->type != SSH2_CERT_TYPE_HOST) { in sshkey_cert_check_authority()
3096 if (k->cert->type != SSH2_CERT_TYPE_USER) { in sshkey_cert_check_authority()
3101 if (verify_time < k->cert->valid_after) { in sshkey_cert_check_authority()
3105 if (verify_time >= k->cert->valid_before) { in sshkey_cert_check_authority()
3109 if (k->cert->nprincipals == 0) { in sshkey_cert_check_authority()
3116 for (i = 0; i < k->cert->nprincipals; i++) { in sshkey_cert_check_authority()
3118 if (match_pattern(k->cert->principals[i], in sshkey_cert_check_authority()
3123 } else if (strcmp(name, k->cert->principals[i]) == 0) { in sshkey_cert_check_authority()
3163 if (sshbuf_len(key->cert->critical) != 0) { in sshkey_cert_check_host()
3176 sshkey_format_cert_validity(const struct sshkey_cert *cert, char *s, size_t l) in sshkey_format_cert_validity() argument
3181 if (cert->valid_after == 0 && in sshkey_format_cert_validity()
3182 cert->valid_before == 0xffffffffffffffffULL) in sshkey_format_cert_validity()
3185 if (cert->valid_after != 0) in sshkey_format_cert_validity()
3186 format_absolute_time(cert->valid_after, from, sizeof(from)); in sshkey_format_cert_validity()
3187 if (cert->valid_before != 0xffffffffffffffffULL) in sshkey_format_cert_validity()
3188 format_absolute_time(cert->valid_before, to, sizeof(to)); in sshkey_format_cert_validity()
3190 if (cert->valid_after == 0) in sshkey_format_cert_validity()
3192 else if (cert->valid_before == 0xffffffffffffffffULL) in sshkey_format_cert_validity()
3233 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0) { in sshkey_private_serialize_opt()
3240 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()
3258 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0) { in sshkey_private_serialize_opt()
3263 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()
3277 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0) { in sshkey_private_serialize_opt()
3281 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()
3297 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0) { in sshkey_private_serialize_opt()
3301 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()
3318 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0) { in sshkey_private_serialize_opt()
3322 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()
3339 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0) { in sshkey_private_serialize_opt()
3343 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()
3367 if (key->cert == NULL || sshbuf_len(key->cert->certblob) == 0 || in sshkey_private_serialize_opt()
3372 if ((r = sshbuf_put_stringb(b, key->cert->certblob)) != 0 || in sshkey_private_serialize_opt()