1*4724848cSchristos /*
2*4724848cSchristos * Copyright 1995-2019 The OpenSSL Project Authors. All Rights Reserved.
3*4724848cSchristos *
4*4724848cSchristos * Licensed under the OpenSSL license (the "License"). You may not use
5*4724848cSchristos * this file except in compliance with the License. You can obtain a copy
6*4724848cSchristos * in the file LICENSE in the source distribution or at
7*4724848cSchristos * https://www.openssl.org/source/license.html
8*4724848cSchristos */
9*4724848cSchristos
10*4724848cSchristos #include <stdio.h>
11*4724848cSchristos #include "internal/cryptlib.h"
12*4724848cSchristos #include <openssl/buffer.h>
13*4724848cSchristos #include <openssl/bn.h>
14*4724848cSchristos #include <openssl/objects.h>
15*4724848cSchristos #include <openssl/x509.h>
16*4724848cSchristos #include <openssl/x509v3.h>
17*4724848cSchristos #include <openssl/rsa.h>
18*4724848cSchristos #include <openssl/dsa.h>
19*4724848cSchristos
20*4724848cSchristos #ifndef OPENSSL_NO_STDIO
X509_REQ_print_fp(FILE * fp,X509_REQ * x)21*4724848cSchristos int X509_REQ_print_fp(FILE *fp, X509_REQ *x)
22*4724848cSchristos {
23*4724848cSchristos BIO *b;
24*4724848cSchristos int ret;
25*4724848cSchristos
26*4724848cSchristos if ((b = BIO_new(BIO_s_file())) == NULL) {
27*4724848cSchristos X509err(X509_F_X509_REQ_PRINT_FP, ERR_R_BUF_LIB);
28*4724848cSchristos return 0;
29*4724848cSchristos }
30*4724848cSchristos BIO_set_fp(b, fp, BIO_NOCLOSE);
31*4724848cSchristos ret = X509_REQ_print(b, x);
32*4724848cSchristos BIO_free(b);
33*4724848cSchristos return ret;
34*4724848cSchristos }
35*4724848cSchristos #endif
36*4724848cSchristos
X509_REQ_print_ex(BIO * bp,X509_REQ * x,unsigned long nmflags,unsigned long cflag)37*4724848cSchristos int X509_REQ_print_ex(BIO *bp, X509_REQ *x, unsigned long nmflags,
38*4724848cSchristos unsigned long cflag)
39*4724848cSchristos {
40*4724848cSchristos long l;
41*4724848cSchristos int i;
42*4724848cSchristos EVP_PKEY *pkey;
43*4724848cSchristos STACK_OF(X509_EXTENSION) *exts;
44*4724848cSchristos char mlch = ' ';
45*4724848cSchristos int nmindent = 0;
46*4724848cSchristos
47*4724848cSchristos if ((nmflags & XN_FLAG_SEP_MASK) == XN_FLAG_SEP_MULTILINE) {
48*4724848cSchristos mlch = '\n';
49*4724848cSchristos nmindent = 12;
50*4724848cSchristos }
51*4724848cSchristos
52*4724848cSchristos if (nmflags == X509_FLAG_COMPAT)
53*4724848cSchristos nmindent = 16;
54*4724848cSchristos
55*4724848cSchristos if (!(cflag & X509_FLAG_NO_HEADER)) {
56*4724848cSchristos if (BIO_write(bp, "Certificate Request:\n", 21) <= 0)
57*4724848cSchristos goto err;
58*4724848cSchristos if (BIO_write(bp, " Data:\n", 10) <= 0)
59*4724848cSchristos goto err;
60*4724848cSchristos }
61*4724848cSchristos if (!(cflag & X509_FLAG_NO_VERSION)) {
62*4724848cSchristos l = X509_REQ_get_version(x);
63*4724848cSchristos if (l >= 0 && l <= 2) {
64*4724848cSchristos if (BIO_printf(bp, "%8sVersion: %ld (0x%lx)\n", "", l + 1, (unsigned long)l) <= 0)
65*4724848cSchristos goto err;
66*4724848cSchristos } else {
67*4724848cSchristos if (BIO_printf(bp, "%8sVersion: Unknown (%ld)\n", "", l) <= 0)
68*4724848cSchristos goto err;
69*4724848cSchristos }
70*4724848cSchristos }
71*4724848cSchristos if (!(cflag & X509_FLAG_NO_SUBJECT)) {
72*4724848cSchristos if (BIO_printf(bp, " Subject:%c", mlch) <= 0)
73*4724848cSchristos goto err;
74*4724848cSchristos if (X509_NAME_print_ex(bp, X509_REQ_get_subject_name(x),
75*4724848cSchristos nmindent, nmflags) < 0)
76*4724848cSchristos goto err;
77*4724848cSchristos if (BIO_write(bp, "\n", 1) <= 0)
78*4724848cSchristos goto err;
79*4724848cSchristos }
80*4724848cSchristos if (!(cflag & X509_FLAG_NO_PUBKEY)) {
81*4724848cSchristos X509_PUBKEY *xpkey;
82*4724848cSchristos ASN1_OBJECT *koid;
83*4724848cSchristos if (BIO_write(bp, " Subject Public Key Info:\n", 33) <= 0)
84*4724848cSchristos goto err;
85*4724848cSchristos if (BIO_printf(bp, "%12sPublic Key Algorithm: ", "") <= 0)
86*4724848cSchristos goto err;
87*4724848cSchristos xpkey = X509_REQ_get_X509_PUBKEY(x);
88*4724848cSchristos X509_PUBKEY_get0_param(&koid, NULL, NULL, NULL, xpkey);
89*4724848cSchristos if (i2a_ASN1_OBJECT(bp, koid) <= 0)
90*4724848cSchristos goto err;
91*4724848cSchristos if (BIO_puts(bp, "\n") <= 0)
92*4724848cSchristos goto err;
93*4724848cSchristos
94*4724848cSchristos pkey = X509_REQ_get0_pubkey(x);
95*4724848cSchristos if (pkey == NULL) {
96*4724848cSchristos if (BIO_printf(bp, "%12sUnable to load Public Key\n", "") <= 0)
97*4724848cSchristos goto err;
98*4724848cSchristos ERR_print_errors(bp);
99*4724848cSchristos } else {
100*4724848cSchristos if (EVP_PKEY_print_public(bp, pkey, 16, NULL) <= 0)
101*4724848cSchristos goto err;
102*4724848cSchristos }
103*4724848cSchristos }
104*4724848cSchristos
105*4724848cSchristos if (!(cflag & X509_FLAG_NO_ATTRIBUTES)) {
106*4724848cSchristos /* may not be */
107*4724848cSchristos if (BIO_printf(bp, "%8sAttributes:\n", "") <= 0)
108*4724848cSchristos goto err;
109*4724848cSchristos
110*4724848cSchristos if (X509_REQ_get_attr_count(x) == 0) {
111*4724848cSchristos if (BIO_printf(bp, "%12sa0:00\n", "") <= 0)
112*4724848cSchristos goto err;
113*4724848cSchristos } else {
114*4724848cSchristos for (i = 0; i < X509_REQ_get_attr_count(x); i++) {
115*4724848cSchristos ASN1_TYPE *at;
116*4724848cSchristos X509_ATTRIBUTE *a;
117*4724848cSchristos ASN1_BIT_STRING *bs = NULL;
118*4724848cSchristos ASN1_OBJECT *aobj;
119*4724848cSchristos int j, type = 0, count = 1, ii = 0;
120*4724848cSchristos
121*4724848cSchristos a = X509_REQ_get_attr(x, i);
122*4724848cSchristos aobj = X509_ATTRIBUTE_get0_object(a);
123*4724848cSchristos if (X509_REQ_extension_nid(OBJ_obj2nid(aobj)))
124*4724848cSchristos continue;
125*4724848cSchristos if (BIO_printf(bp, "%12s", "") <= 0)
126*4724848cSchristos goto err;
127*4724848cSchristos if ((j = i2a_ASN1_OBJECT(bp, aobj)) > 0) {
128*4724848cSchristos ii = 0;
129*4724848cSchristos count = X509_ATTRIBUTE_count(a);
130*4724848cSchristos if (count == 0) {
131*4724848cSchristos X509err(X509_F_X509_REQ_PRINT_EX, X509_R_INVALID_ATTRIBUTES);
132*4724848cSchristos return 0;
133*4724848cSchristos }
134*4724848cSchristos get_next:
135*4724848cSchristos at = X509_ATTRIBUTE_get0_type(a, ii);
136*4724848cSchristos type = at->type;
137*4724848cSchristos bs = at->value.asn1_string;
138*4724848cSchristos }
139*4724848cSchristos for (j = 25 - j; j > 0; j--)
140*4724848cSchristos if (BIO_write(bp, " ", 1) != 1)
141*4724848cSchristos goto err;
142*4724848cSchristos if (BIO_puts(bp, ":") <= 0)
143*4724848cSchristos goto err;
144*4724848cSchristos switch (type) {
145*4724848cSchristos case V_ASN1_PRINTABLESTRING:
146*4724848cSchristos case V_ASN1_T61STRING:
147*4724848cSchristos case V_ASN1_NUMERICSTRING:
148*4724848cSchristos case V_ASN1_UTF8STRING:
149*4724848cSchristos case V_ASN1_IA5STRING:
150*4724848cSchristos if (BIO_write(bp, (char *)bs->data, bs->length)
151*4724848cSchristos != bs->length)
152*4724848cSchristos goto err;
153*4724848cSchristos if (BIO_puts(bp, "\n") <= 0)
154*4724848cSchristos goto err;
155*4724848cSchristos break;
156*4724848cSchristos default:
157*4724848cSchristos if (BIO_puts(bp, "unable to print attribute\n") <= 0)
158*4724848cSchristos goto err;
159*4724848cSchristos break;
160*4724848cSchristos }
161*4724848cSchristos if (++ii < count)
162*4724848cSchristos goto get_next;
163*4724848cSchristos }
164*4724848cSchristos }
165*4724848cSchristos }
166*4724848cSchristos if (!(cflag & X509_FLAG_NO_EXTENSIONS)) {
167*4724848cSchristos exts = X509_REQ_get_extensions(x);
168*4724848cSchristos if (exts) {
169*4724848cSchristos if (BIO_printf(bp, "%8sRequested Extensions:\n", "") <= 0)
170*4724848cSchristos goto err;
171*4724848cSchristos for (i = 0; i < sk_X509_EXTENSION_num(exts); i++) {
172*4724848cSchristos ASN1_OBJECT *obj;
173*4724848cSchristos X509_EXTENSION *ex;
174*4724848cSchristos int critical;
175*4724848cSchristos ex = sk_X509_EXTENSION_value(exts, i);
176*4724848cSchristos if (BIO_printf(bp, "%12s", "") <= 0)
177*4724848cSchristos goto err;
178*4724848cSchristos obj = X509_EXTENSION_get_object(ex);
179*4724848cSchristos if (i2a_ASN1_OBJECT(bp, obj) <= 0)
180*4724848cSchristos goto err;
181*4724848cSchristos critical = X509_EXTENSION_get_critical(ex);
182*4724848cSchristos if (BIO_printf(bp, ": %s\n", critical ? "critical" : "") <= 0)
183*4724848cSchristos goto err;
184*4724848cSchristos if (!X509V3_EXT_print(bp, ex, cflag, 16)) {
185*4724848cSchristos if (BIO_printf(bp, "%16s", "") <= 0
186*4724848cSchristos || ASN1_STRING_print(bp,
187*4724848cSchristos X509_EXTENSION_get_data(ex)) <= 0)
188*4724848cSchristos goto err;
189*4724848cSchristos }
190*4724848cSchristos if (BIO_write(bp, "\n", 1) <= 0)
191*4724848cSchristos goto err;
192*4724848cSchristos }
193*4724848cSchristos sk_X509_EXTENSION_pop_free(exts, X509_EXTENSION_free);
194*4724848cSchristos }
195*4724848cSchristos }
196*4724848cSchristos
197*4724848cSchristos if (!(cflag & X509_FLAG_NO_SIGDUMP)) {
198*4724848cSchristos const X509_ALGOR *sig_alg;
199*4724848cSchristos const ASN1_BIT_STRING *sig;
200*4724848cSchristos X509_REQ_get0_signature(x, &sig, &sig_alg);
201*4724848cSchristos if (!X509_signature_print(bp, sig_alg, sig))
202*4724848cSchristos goto err;
203*4724848cSchristos }
204*4724848cSchristos
205*4724848cSchristos return 1;
206*4724848cSchristos err:
207*4724848cSchristos X509err(X509_F_X509_REQ_PRINT_EX, ERR_R_BUF_LIB);
208*4724848cSchristos return 0;
209*4724848cSchristos }
210*4724848cSchristos
X509_REQ_print(BIO * bp,X509_REQ * x)211*4724848cSchristos int X509_REQ_print(BIO *bp, X509_REQ *x)
212*4724848cSchristos {
213*4724848cSchristos return X509_REQ_print_ex(bp, x, XN_FLAG_COMPAT, X509_FLAG_COMPAT);
214*4724848cSchristos }
215