1*92c8ea4eSschwarze /* $OpenBSD: x509req_ext.c,v 1.1 2021/11/03 13:08:57 schwarze Exp $ */
2*92c8ea4eSschwarze /*
3*92c8ea4eSschwarze * Copyright (c) 2020, 2021 Ingo Schwarze <schwarze@openbsd.org>
4*92c8ea4eSschwarze *
5*92c8ea4eSschwarze * Permission to use, copy, modify, and distribute this software for any
6*92c8ea4eSschwarze * purpose with or without fee is hereby granted, provided that the above
7*92c8ea4eSschwarze * copyright notice and this permission notice appear in all copies.
8*92c8ea4eSschwarze *
9*92c8ea4eSschwarze * THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES
10*92c8ea4eSschwarze * WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF
11*92c8ea4eSschwarze * MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR
12*92c8ea4eSschwarze * ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES
13*92c8ea4eSschwarze * WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN
14*92c8ea4eSschwarze * ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15*92c8ea4eSschwarze * OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16*92c8ea4eSschwarze */
17*92c8ea4eSschwarze
18*92c8ea4eSschwarze #include <errno.h>
19*92c8ea4eSschwarze #include <stdio.h>
20*92c8ea4eSschwarze #include <string.h>
21*92c8ea4eSschwarze
22*92c8ea4eSschwarze #include <openssl/asn1.h>
23*92c8ea4eSschwarze #include <openssl/err.h>
24*92c8ea4eSschwarze #include <openssl/x509.h>
25*92c8ea4eSschwarze
26*92c8ea4eSschwarze void fail_head(const char *);
27*92c8ea4eSschwarze void fail_tail(void);
28*92c8ea4eSschwarze void fail_str(const char *, const char *);
29*92c8ea4eSschwarze void fail_int(const char *, int);
30*92c8ea4eSschwarze void fail_ptr(const char *, const void *);
31*92c8ea4eSschwarze
32*92c8ea4eSschwarze static const char *testname;
33*92c8ea4eSschwarze static int errcount;
34*92c8ea4eSschwarze
35*92c8ea4eSschwarze void
fail_head(const char * stepname)36*92c8ea4eSschwarze fail_head(const char *stepname)
37*92c8ea4eSschwarze {
38*92c8ea4eSschwarze fprintf(stderr, "failure#%d testname=%s stepname=%s ",
39*92c8ea4eSschwarze ++errcount, testname, stepname);
40*92c8ea4eSschwarze }
41*92c8ea4eSschwarze
42*92c8ea4eSschwarze void
fail_tail(void)43*92c8ea4eSschwarze fail_tail(void)
44*92c8ea4eSschwarze {
45*92c8ea4eSschwarze unsigned long errnum;
46*92c8ea4eSschwarze
47*92c8ea4eSschwarze if ((errnum = ERR_get_error()))
48*92c8ea4eSschwarze fprintf(stderr, "OpenSSL says: %s\n",
49*92c8ea4eSschwarze ERR_error_string(errnum, NULL));
50*92c8ea4eSschwarze if (errno)
51*92c8ea4eSschwarze fprintf(stderr, "libc says: %s\n", strerror(errno));
52*92c8ea4eSschwarze }
53*92c8ea4eSschwarze
54*92c8ea4eSschwarze void
fail_str(const char * stepname,const char * result)55*92c8ea4eSschwarze fail_str(const char *stepname, const char *result)
56*92c8ea4eSschwarze {
57*92c8ea4eSschwarze fail_head(stepname);
58*92c8ea4eSschwarze fprintf(stderr, "wrong result=%s\n", result);
59*92c8ea4eSschwarze fail_tail();
60*92c8ea4eSschwarze }
61*92c8ea4eSschwarze
62*92c8ea4eSschwarze void
fail_int(const char * stepname,int result)63*92c8ea4eSschwarze fail_int(const char *stepname, int result)
64*92c8ea4eSschwarze {
65*92c8ea4eSschwarze fail_head(stepname);
66*92c8ea4eSschwarze fprintf(stderr, "wrong result=%d\n", result);
67*92c8ea4eSschwarze fail_tail();
68*92c8ea4eSschwarze }
69*92c8ea4eSschwarze
70*92c8ea4eSschwarze void
fail_ptr(const char * stepname,const void * result)71*92c8ea4eSschwarze fail_ptr(const char *stepname, const void *result)
72*92c8ea4eSschwarze {
73*92c8ea4eSschwarze fail_head(stepname);
74*92c8ea4eSschwarze fprintf(stderr, "wrong result=%p\n", result);
75*92c8ea4eSschwarze fail_tail();
76*92c8ea4eSschwarze }
77*92c8ea4eSschwarze
78*92c8ea4eSschwarze int
main(void)79*92c8ea4eSschwarze main(void)
80*92c8ea4eSschwarze {
81*92c8ea4eSschwarze X509_REQ *req;
82*92c8ea4eSschwarze X509_EXTENSIONS *exts;
83*92c8ea4eSschwarze X509_ATTRIBUTE *attr;
84*92c8ea4eSschwarze ASN1_TYPE *aval;
85*92c8ea4eSschwarze int irc;
86*92c8ea4eSschwarze
87*92c8ea4eSschwarze testname = "exts=NULL";
88*92c8ea4eSschwarze if ((req = X509_REQ_new()) == NULL) {
89*92c8ea4eSschwarze fail_str("X509_REQ_new", "NULL");
90*92c8ea4eSschwarze return 1;
91*92c8ea4eSschwarze }
92*92c8ea4eSschwarze if ((irc = X509_REQ_add_extensions(req, NULL)) != 0)
93*92c8ea4eSschwarze fail_int("X509_REQ_add_extensions", irc);
94*92c8ea4eSschwarze if ((irc = X509_REQ_get_attr_count(req)) != 0)
95*92c8ea4eSschwarze fail_int("X509_REQ_get_attr_count", irc);
96*92c8ea4eSschwarze if ((attr = X509_REQ_get_attr(req, 0)) != NULL)
97*92c8ea4eSschwarze fail_ptr("X509_REQ_get_attr", attr);
98*92c8ea4eSschwarze X509_REQ_free(req);
99*92c8ea4eSschwarze
100*92c8ea4eSschwarze testname = "nid=-1";
101*92c8ea4eSschwarze if ((req = X509_REQ_new()) == NULL) {
102*92c8ea4eSschwarze fail_str("X509_REQ_new", "NULL");
103*92c8ea4eSschwarze return 1;
104*92c8ea4eSschwarze }
105*92c8ea4eSschwarze if ((exts = sk_X509_EXTENSION_new_null()) == NULL) {
106*92c8ea4eSschwarze fail_str("sk_X509_EXTENSION_new_null", "NULL");
107*92c8ea4eSschwarze return 1;
108*92c8ea4eSschwarze }
109*92c8ea4eSschwarze if ((irc = X509_REQ_add_extensions_nid(req, exts, -1)) != 0)
110*92c8ea4eSschwarze fail_int("X509_REQ_add_extensions", irc);
111*92c8ea4eSschwarze if ((irc = X509_REQ_get_attr_count(req)) != 0)
112*92c8ea4eSschwarze fail_int("X509_REQ_get_attr_count", irc);
113*92c8ea4eSschwarze if ((attr = X509_REQ_get_attr(req, 0)) != NULL)
114*92c8ea4eSschwarze fail_ptr("X509_REQ_get_attr", attr);
115*92c8ea4eSschwarze X509_REQ_free(req);
116*92c8ea4eSschwarze
117*92c8ea4eSschwarze testname = "valid";
118*92c8ea4eSschwarze if ((req = X509_REQ_new()) == NULL) {
119*92c8ea4eSschwarze fail_str("X509_REQ_new", "NULL");
120*92c8ea4eSschwarze return 1;
121*92c8ea4eSschwarze }
122*92c8ea4eSschwarze if ((irc = X509_REQ_add_extensions(req, exts)) != 1)
123*92c8ea4eSschwarze fail_int("X509_REQ_add_extensions", irc);
124*92c8ea4eSschwarze sk_X509_EXTENSION_free(exts);
125*92c8ea4eSschwarze if ((irc = X509_REQ_get_attr_count(req)) != 1)
126*92c8ea4eSschwarze fail_int("X509_REQ_get_attr_count", irc);
127*92c8ea4eSschwarze if ((attr = X509_REQ_get_attr(req, 0)) == NULL) {
128*92c8ea4eSschwarze fail_str("X509_REQ_get_attr", "NULL");
129*92c8ea4eSschwarze goto end_valid;
130*92c8ea4eSschwarze }
131*92c8ea4eSschwarze if ((irc = X509_ATTRIBUTE_count(attr)) != 1)
132*92c8ea4eSschwarze fail_int("X509_ATTRIBUTE_count", irc);
133*92c8ea4eSschwarze if ((aval = X509_ATTRIBUTE_get0_type(attr, 0)) == NULL) {
134*92c8ea4eSschwarze fail_str("X509_ATTRIBUTE_get0_type", "NULL");
135*92c8ea4eSschwarze goto end_valid;
136*92c8ea4eSschwarze }
137*92c8ea4eSschwarze if ((irc = ASN1_TYPE_get(aval)) != V_ASN1_SEQUENCE)
138*92c8ea4eSschwarze fail_int("ASN1_TYPE_get", irc);
139*92c8ea4eSschwarze exts = ASN1_item_unpack(aval->value.sequence, &X509_EXTENSIONS_it);
140*92c8ea4eSschwarze if (exts == NULL) {
141*92c8ea4eSschwarze fail_str("ASN1_item_unpack", "NULL");
142*92c8ea4eSschwarze goto end_valid;
143*92c8ea4eSschwarze }
144*92c8ea4eSschwarze if ((irc = sk_X509_EXTENSION_num(exts)) != 0)
145*92c8ea4eSschwarze fail_int("sk_X509_EXTENSION_num", irc);
146*92c8ea4eSschwarze sk_X509_EXTENSION_free(exts);
147*92c8ea4eSschwarze
148*92c8ea4eSschwarze end_valid:
149*92c8ea4eSschwarze testname = "getext";
150*92c8ea4eSschwarze if ((exts = X509_REQ_get_extensions(req)) == NULL) {
151*92c8ea4eSschwarze fail_str("X509_REQ_get_extensions", "NULL");
152*92c8ea4eSschwarze goto end_getext;
153*92c8ea4eSschwarze }
154*92c8ea4eSschwarze if ((irc = sk_X509_EXTENSION_num(exts)) != 0)
155*92c8ea4eSschwarze fail_int("sk_X509_EXTENSION_num", irc);
156*92c8ea4eSschwarze sk_X509_EXTENSION_free(exts);
157*92c8ea4eSschwarze
158*92c8ea4eSschwarze end_getext:
159*92c8ea4eSschwarze X509_REQ_free(req);
160*92c8ea4eSschwarze return errcount != 0;
161*92c8ea4eSschwarze }
162