blob: adab7a1a331a2772e8872e225bc35283fad9cbef [file] [log] [blame]
Paul Bakkerefc30292011-11-10 14:43:23 +00001/**
2 * \file asn1.h
3 *
4 * \brief Generic ASN.1 parsing
Darryl Greena40a1012018-01-05 15:33:17 +00005 */
6/*
Manuel Pégourié-Gonnard6fb81872015-07-27 11:11:48 +02007 * Copyright (C) 2006-2015, ARM Limited, All Rights Reserved
Manuel Pégourié-Gonnard37ff1402015-09-04 14:21:07 +02008 * SPDX-License-Identifier: Apache-2.0
9 *
10 * Licensed under the Apache License, Version 2.0 (the "License"); you may
11 * not use this file except in compliance with the License.
12 * You may obtain a copy of the License at
13 *
14 * http://www.apache.org/licenses/LICENSE-2.0
15 *
16 * Unless required by applicable law or agreed to in writing, software
17 * distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
18 * WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
19 * See the License for the specific language governing permissions and
20 * limitations under the License.
Paul Bakkerefc30292011-11-10 14:43:23 +000021 *
Manuel Pégourié-Gonnardfe446432015-03-06 13:17:10 +000022 * This file is part of mbed TLS (https://tls.mbed.org)
Paul Bakkerefc30292011-11-10 14:43:23 +000023 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020024#ifndef MBEDTLS_ASN1_H
25#define MBEDTLS_ASN1_H
Paul Bakkerefc30292011-11-10 14:43:23 +000026
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020027#if !defined(MBEDTLS_CONFIG_FILE)
Paul Bakkerccdb0282011-12-15 19:49:51 +000028#include "config.h"
Manuel Pégourié-Gonnardcef4ad22014-04-29 12:39:06 +020029#else
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020030#include MBEDTLS_CONFIG_FILE
Manuel Pégourié-Gonnardcef4ad22014-04-29 12:39:06 +020031#endif
Paul Bakkerefc30292011-11-10 14:43:23 +000032
Rich Evans00ab4702015-02-06 13:43:58 +000033#include <stddef.h>
Hanno Beckerd82f60d2019-08-23 15:23:46 +010034#include <stdint.h>
Rich Evans00ab4702015-02-06 13:43:58 +000035
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020036#if defined(MBEDTLS_BIGNUM_C)
Paul Bakkerccdb0282011-12-15 19:49:51 +000037#include "bignum.h"
Paul Bakkerefc30292011-11-10 14:43:23 +000038#endif
39
Paul Bakker9af723c2014-05-01 13:03:14 +020040/**
Paul Bakkerefc30292011-11-10 14:43:23 +000041 * \addtogroup asn1_module
Paul Bakker9af723c2014-05-01 13:03:14 +020042 * \{
Paul Bakkerefc30292011-11-10 14:43:23 +000043 */
Paul Bakker9af723c2014-05-01 13:03:14 +020044
Paul Bakkerefc30292011-11-10 14:43:23 +000045/**
46 * \name ASN1 Error codes
47 * These error codes are OR'ed to X509 error codes for
Paul Bakker9af723c2014-05-01 13:03:14 +020048 * higher error granularity.
Paul Bakkerefc30292011-11-10 14:43:23 +000049 * ASN1 is a standard to specify data structures.
50 * \{
51 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020052#define MBEDTLS_ERR_ASN1_OUT_OF_DATA -0x0060 /**< Out of data when parsing an ASN1 data structure. */
53#define MBEDTLS_ERR_ASN1_UNEXPECTED_TAG -0x0062 /**< ASN1 tag was of an unexpected value. */
54#define MBEDTLS_ERR_ASN1_INVALID_LENGTH -0x0064 /**< Error when trying to determine the length or invalid length. */
55#define MBEDTLS_ERR_ASN1_LENGTH_MISMATCH -0x0066 /**< Actual length differs from expected length. */
56#define MBEDTLS_ERR_ASN1_INVALID_DATA -0x0068 /**< Data is invalid. (not used) */
Manuel Pégourié-Gonnard6a8ca332015-05-28 09:33:39 +020057#define MBEDTLS_ERR_ASN1_ALLOC_FAILED -0x006A /**< Memory allocation failed */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020058#define MBEDTLS_ERR_ASN1_BUF_TOO_SMALL -0x006C /**< Buffer too small when writing ASN.1 data structure. */
Paul Bakker05888152012-02-16 10:26:57 +000059
Paul Bakkerefc30292011-11-10 14:43:23 +000060/* \} name */
61
62/**
63 * \name DER constants
Andres Amaya Garcia9fb02052017-08-25 17:24:44 +010064 * These constants comply with the DER encoded ASN.1 type tags.
Paul Bakkerefc30292011-11-10 14:43:23 +000065 * DER encoding uses hexadecimal representation.
66 * An example DER sequence is:\n
67 * - 0x02 -- tag indicating INTEGER
68 * - 0x01 -- length in octets
69 * - 0x05 -- value
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020070 * Such sequences are typically read into \c ::mbedtls_x509_buf.
Paul Bakkerefc30292011-11-10 14:43:23 +000071 * \{
72 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +020073#define MBEDTLS_ASN1_BOOLEAN 0x01
74#define MBEDTLS_ASN1_INTEGER 0x02
75#define MBEDTLS_ASN1_BIT_STRING 0x03
76#define MBEDTLS_ASN1_OCTET_STRING 0x04
77#define MBEDTLS_ASN1_NULL 0x05
78#define MBEDTLS_ASN1_OID 0x06
79#define MBEDTLS_ASN1_UTF8_STRING 0x0C
80#define MBEDTLS_ASN1_SEQUENCE 0x10
81#define MBEDTLS_ASN1_SET 0x11
82#define MBEDTLS_ASN1_PRINTABLE_STRING 0x13
83#define MBEDTLS_ASN1_T61_STRING 0x14
84#define MBEDTLS_ASN1_IA5_STRING 0x16
85#define MBEDTLS_ASN1_UTC_TIME 0x17
86#define MBEDTLS_ASN1_GENERALIZED_TIME 0x18
87#define MBEDTLS_ASN1_UNIVERSAL_STRING 0x1C
88#define MBEDTLS_ASN1_BMP_STRING 0x1E
89#define MBEDTLS_ASN1_PRIMITIVE 0x00
90#define MBEDTLS_ASN1_CONSTRUCTED 0x20
91#define MBEDTLS_ASN1_CONTEXT_SPECIFIC 0x80
Andres Amaya Garcia7512bf72017-08-25 17:12:11 +010092
Hanno Beckerb40dc582019-02-20 09:38:45 +000093/* Slightly smaller way to check if tag is a string tag
94 * compared to canonical implementation. */
95#define MBEDTLS_ASN1_IS_STRING_TAG( tag ) \
96 ( ( tag ) < 32u && ( \
97 ( ( 1u << ( tag ) ) & ( ( 1u << MBEDTLS_ASN1_BMP_STRING ) | \
98 ( 1u << MBEDTLS_ASN1_UTF8_STRING ) | \
99 ( 1u << MBEDTLS_ASN1_T61_STRING ) | \
100 ( 1u << MBEDTLS_ASN1_IA5_STRING ) | \
101 ( 1u << MBEDTLS_ASN1_UNIVERSAL_STRING ) | \
102 ( 1u << MBEDTLS_ASN1_PRINTABLE_STRING ) | \
103 ( 1u << MBEDTLS_ASN1_BIT_STRING ) ) ) != 0 ) )
104
Andres Amaya Garcia7512bf72017-08-25 17:12:11 +0100105/*
106 * Bit masks for each of the components of an ASN.1 tag as specified in
Gilles Peskine1ed45ea2018-03-08 18:16:45 +0100107 * ITU X.690 (08/2015), section 8.1 "General rules for encoding",
108 * paragraph 8.1.2.2:
Andres Amaya Garcia7512bf72017-08-25 17:12:11 +0100109 *
110 * Bit 8 7 6 5 1
111 * +-------+-----+------------+
112 * | Class | P/C | Tag number |
113 * +-------+-----+------------+
114 */
Andres Amaya Garcia7786abc2017-11-07 20:21:56 +0000115#define MBEDTLS_ASN1_TAG_CLASS_MASK 0xC0
116#define MBEDTLS_ASN1_TAG_PC_MASK 0x20
117#define MBEDTLS_ASN1_TAG_VALUE_MASK 0x1F
Andres Amaya Garcia7512bf72017-08-25 17:12:11 +0100118
Paul Bakkerefc30292011-11-10 14:43:23 +0000119/* \} name */
120/* \} addtogroup asn1_module */
121
122/** Returns the size of the binary string, without the trailing \\0 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200123#define MBEDTLS_OID_SIZE(x) (sizeof(x) - 1)
Paul Bakkerefc30292011-11-10 14:43:23 +0000124
Manuel Pégourié-Gonnarde76b7502014-01-23 19:15:29 +0100125/**
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200126 * Compares an mbedtls_asn1_buf structure to a reference OID.
Manuel Pégourié-Gonnarde76b7502014-01-23 19:15:29 +0100127 *
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200128 * Only works for 'defined' oid_str values (MBEDTLS_OID_HMAC_SHA1), you cannot use a
Manuel Pégourié-Gonnarde76b7502014-01-23 19:15:29 +0100129 * 'unsigned char *oid' here!
Paul Bakkere5eae762013-08-26 12:05:14 +0200130 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200131#define MBEDTLS_OID_CMP(oid_str, oid_buf) \
132 ( ( MBEDTLS_OID_SIZE(oid_str) != (oid_buf)->len ) || \
Teppo Järvelin61f412e2019-10-03 12:25:22 +0300133 mbedtls_platform_memcmp( (oid_str), (oid_buf)->p, (oid_buf)->len) != 0 )
Paul Bakkerc70b9822013-04-07 22:00:46 +0200134
Hanno Beckere1956af2019-02-21 14:28:12 +0000135#define MBEDTLS_OID_CMP_RAW(oid_str, oid_buf, oid_buf_len) \
136 ( ( MBEDTLS_OID_SIZE(oid_str) != (oid_buf_len) ) || \
Teppo Järvelin61f412e2019-10-03 12:25:22 +0300137 mbedtls_platform_memcmp( (oid_str), (oid_buf), (oid_buf_len) ) != 0 )
Hanno Beckere1956af2019-02-21 14:28:12 +0000138
Paul Bakkerefc30292011-11-10 14:43:23 +0000139#ifdef __cplusplus
140extern "C" {
141#endif
142
143/**
144 * \name Functions to parse ASN.1 data structures
145 * \{
146 */
147
148/**
149 * Type-length-value structure that allows for ASN1 using DER.
150 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200151typedef struct mbedtls_asn1_buf
Paul Bakkerefc30292011-11-10 14:43:23 +0000152{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200153 int tag; /**< ASN1 type, e.g. MBEDTLS_ASN1_UTF8_STRING. */
Manuel Pégourié-Gonnardb8186a52015-06-18 14:58:58 +0200154 size_t len; /**< ASN1 length, in octets. */
Paul Bakkerefc30292011-11-10 14:43:23 +0000155 unsigned char *p; /**< ASN1 data, e.g. in ASCII. */
156}
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200157mbedtls_asn1_buf;
Paul Bakkerefc30292011-11-10 14:43:23 +0000158
159/**
160 * Container for ASN1 bit strings.
161 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200162typedef struct mbedtls_asn1_bitstring
Paul Bakkerefc30292011-11-10 14:43:23 +0000163{
Manuel Pégourié-Gonnardb8186a52015-06-18 14:58:58 +0200164 size_t len; /**< ASN1 length, in octets. */
Paul Bakkerefc30292011-11-10 14:43:23 +0000165 unsigned char unused_bits; /**< Number of unused bits at the end of the string */
166 unsigned char *p; /**< Raw ASN1 data for the bit string */
167}
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200168mbedtls_asn1_bitstring;
Paul Bakkerefc30292011-11-10 14:43:23 +0000169
170/**
171 * Container for a sequence of ASN.1 items
172 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200173typedef struct mbedtls_asn1_sequence
Paul Bakkerefc30292011-11-10 14:43:23 +0000174{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200175 mbedtls_asn1_buf buf; /**< Buffer containing the given ASN.1 item. */
176 struct mbedtls_asn1_sequence *next; /**< The next entry in the sequence. */
Paul Bakkerefc30292011-11-10 14:43:23 +0000177}
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200178mbedtls_asn1_sequence;
Paul Bakkerefc30292011-11-10 14:43:23 +0000179
180/**
Paul Bakkere5eae762013-08-26 12:05:14 +0200181 * Container for a sequence or list of 'named' ASN.1 data items
182 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200183typedef struct mbedtls_asn1_named_data
Paul Bakkere5eae762013-08-26 12:05:14 +0200184{
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200185 mbedtls_asn1_buf oid; /**< The object identifier. */
186 mbedtls_asn1_buf val; /**< The named value. */
187 struct mbedtls_asn1_named_data *next; /**< The next entry in the sequence. */
Manuel Pégourié-Gonnard555fbf82015-02-04 17:11:55 +0000188 unsigned char next_merged; /**< Merge next item into the current one? */
Paul Bakkere5eae762013-08-26 12:05:14 +0200189}
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200190mbedtls_asn1_named_data;
Paul Bakkere5eae762013-08-26 12:05:14 +0200191
192/**
Paul Bakkercdda0972013-09-09 12:51:29 +0200193 * \brief Get the length of an ASN.1 element.
194 * Updates the pointer to immediately behind the length.
Paul Bakkerefc30292011-11-10 14:43:23 +0000195 *
196 * \param p The position in the ASN.1 data
197 * \param end End of data
198 * \param len The variable that will receive the value
199 *
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200200 * \return 0 if successful, MBEDTLS_ERR_ASN1_OUT_OF_DATA on reaching
201 * end of data, MBEDTLS_ERR_ASN1_INVALID_LENGTH if length is
Paul Bakkerefc30292011-11-10 14:43:23 +0000202 * unparseable.
203 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200204int mbedtls_asn1_get_len( unsigned char **p,
Paul Bakkerefc30292011-11-10 14:43:23 +0000205 const unsigned char *end,
206 size_t *len );
207
208/**
Paul Bakkercdda0972013-09-09 12:51:29 +0200209 * \brief Get the tag and length of the tag. Check for the requested tag.
210 * Updates the pointer to immediately behind the tag and length.
Paul Bakkerefc30292011-11-10 14:43:23 +0000211 *
212 * \param p The position in the ASN.1 data
213 * \param end End of data
214 * \param len The variable that will receive the length
215 * \param tag The expected tag
216 *
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200217 * \return 0 if successful, MBEDTLS_ERR_ASN1_UNEXPECTED_TAG if tag did
Paul Bakkerefc30292011-11-10 14:43:23 +0000218 * not match requested tag, or another specific ASN.1 error code.
219 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200220int mbedtls_asn1_get_tag( unsigned char **p,
Paul Bakkerefc30292011-11-10 14:43:23 +0000221 const unsigned char *end,
222 size_t *len, int tag );
223
224/**
Paul Bakkercdda0972013-09-09 12:51:29 +0200225 * \brief Retrieve a boolean ASN.1 tag and its value.
226 * Updates the pointer to immediately behind the full tag.
Paul Bakkerefc30292011-11-10 14:43:23 +0000227 *
228 * \param p The position in the ASN.1 data
229 * \param end End of data
230 * \param val The variable that will receive the value
231 *
232 * \return 0 if successful or a specific ASN.1 error code.
233 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200234int mbedtls_asn1_get_bool( unsigned char **p,
Paul Bakkerefc30292011-11-10 14:43:23 +0000235 const unsigned char *end,
236 int *val );
237
238/**
Paul Bakkercdda0972013-09-09 12:51:29 +0200239 * \brief Retrieve an integer ASN.1 tag and its value.
240 * Updates the pointer to immediately behind the full tag.
Paul Bakkerefc30292011-11-10 14:43:23 +0000241 *
242 * \param p The position in the ASN.1 data
243 * \param end End of data
244 * \param val The variable that will receive the value
245 *
246 * \return 0 if successful or a specific ASN.1 error code.
247 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200248int mbedtls_asn1_get_int( unsigned char **p,
Paul Bakkerefc30292011-11-10 14:43:23 +0000249 const unsigned char *end,
250 int *val );
251
252/**
Paul Bakkercdda0972013-09-09 12:51:29 +0200253 * \brief Retrieve a bitstring ASN.1 tag and its value.
254 * Updates the pointer to immediately behind the full tag.
Paul Bakkerefc30292011-11-10 14:43:23 +0000255 *
256 * \param p The position in the ASN.1 data
257 * \param end End of data
258 * \param bs The variable that will receive the value
259 *
260 * \return 0 if successful or a specific ASN.1 error code.
261 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200262int mbedtls_asn1_get_bitstring( unsigned char **p, const unsigned char *end,
263 mbedtls_asn1_bitstring *bs);
Paul Bakkerefc30292011-11-10 14:43:23 +0000264
265/**
Paul Bakkercdda0972013-09-09 12:51:29 +0200266 * \brief Retrieve a bitstring ASN.1 tag without unused bits and its
267 * value.
268 * Updates the pointer to the beginning of the bit/octet string.
Manuel Pégourié-Gonnarda2d4e642013-07-11 13:59:02 +0200269 *
270 * \param p The position in the ASN.1 data
271 * \param end End of data
272 * \param len Length of the actual bit/octect string in bytes
273 *
274 * \return 0 if successful or a specific ASN.1 error code.
275 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200276int mbedtls_asn1_get_bitstring_null( unsigned char **p, const unsigned char *end,
Manuel Pégourié-Gonnarda2d4e642013-07-11 13:59:02 +0200277 size_t *len );
278
279/**
Hanno Beckerf332a972019-05-13 11:56:21 +0100280 * \brief Free a heap-allocated linked list presentation of
281 * an ASN.1 sequence, including the first element.
Paul Bakkerefc30292011-11-10 14:43:23 +0000282 *
Hanno Beckerf332a972019-05-13 11:56:21 +0100283 * \param seq The address of the first sequence component. This may
284 * be \c NULL, in which case this functions returns
285 * immediately.
286 */
287void mbedtls_asn1_sequence_free( mbedtls_asn1_sequence *seq );
288
289/**
290 * \brief This function parses and splits an ASN.1 "SEQUENCE OF <tag>"
291 * and updates the source buffer pointer to immediately behind
292 * the full sequence.
293 *
294 * \param p The address of the pointer to the beginning of the
295 * ASN.1 SEQUENCE OF structure, including ASN.1 tag+length header.
296 * On success, `*p` is advanced to point to the first byte
297 * following the parsed ASN.1 sequence.
298 * \param end The end of the ASN.1 input buffer starting at \p p. This is
299 * used for bounds checking.
300 * \param cur The address at which to store the first entry in the parsed
301 * sequence. Further entries are heap-allocated and referenced
302 * from \p cur.
303 * \param tag The common tag of the entries in the ASN.1 sequence.
304 *
305 * \note Ownership for the heap-allocated elements \c cur->next,
306 * \c cur->next->next, ..., is passed to the caller. It
307 * is hence the caller's responsibility to free them when
308 * no longer needed, and mbedtls_asn1_sequence_free() can
309 * be used for that, passing \c cur->next as the \c seq
310 * argument (or \p cur if \p cur itself was heap-allocated
311 * by the caller).
Paul Bakkerefc30292011-11-10 14:43:23 +0000312 *
313 * \return 0 if successful or a specific ASN.1 error code.
314 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200315int mbedtls_asn1_get_sequence_of( unsigned char **p,
Paul Bakkerefc30292011-11-10 14:43:23 +0000316 const unsigned char *end,
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200317 mbedtls_asn1_sequence *cur,
Hanno Becker3c3d5c52019-05-13 13:38:40 +0100318 int tag );
Paul Bakkerefc30292011-11-10 14:43:23 +0000319
Hanno Becker87306102019-02-21 20:52:09 +0000320/**
321 * \brief Traverse an ASN.1 SEQUENCE container and
322 * call a callback for each entry.
323 *
324 * \warning This function is still experimental and may change
325 * at any time.
326 *
327 * \param p The address of the pointer to the beginning of
328 * the ASN.1 SEQUENCE header. This is updated to
329 * point to the end of the ASN.1 SEQUENCE container
330 * on a successful invocation.
331 * \param end The end of the ASN.1 SEQUENCE container.
332 * \param tag_must_mask A mask to be applied to the ASN.1 tags found within
333 * the SEQUENCE before comparing to \p tag_must_value.
334 * \param tag_must_val The required value of each ASN.1 tag found in the
335 * SEQUENCE, after masking with \p tag_must_mask.
336 * Mismatching tags lead to an error.
337 * For example, a value of \c 0 for both \p tag_must_mask
338 * and \p tag_must_val means that every tag is allowed,
339 * while a value of \c 0xFF for \p tag_must_mask means
340 * that \p tag_must_val is the only allowed tag.
341 * \param tag_may_mask A mask to be applied to the ASN.1 tags found within
342 * the SEQUENCE before comparing to \p tag_may_value.
343 * \param tag_may_val The desired value of each ASN.1 tag found in the
344 * SEQUENCE, after masking with \p tag_may_mask.
345 * Mismatching tags will be silently ignored.
346 * For example, a value of \c 0 for \p tag_may_mask and
347 * \p tag_may_val means that any tag will be considered,
348 * while a value of \c 0xFF for \p tag_may_mask means
349 * that all tags with value different from \p tag_may_val
350 * will be ignored.
351 * \param cb The callback to trigger for each component
352 * in the ASN.1 SEQUENCE. If the callback returns
353 * a non-zero value, the function stops immediately,
354 * forwarding the callback's return value.
355 * \param ctx The context to be passed to the callback \p cb.
356 *
357 * \return \c 0 if successful the entire ASN.1 SEQUENCE
358 * was traversed without parsing or callback errors.
359 * \return A negative ASN.1 error code on a parsing failure.
360 * \return A non-zero error code forwarded from the callback
361 * \p cb in case the latter returns a non-zero value.
362 */
363int mbedtls_asn1_traverse_sequence_of(
364 unsigned char **p,
365 const unsigned char *end,
366 uint8_t tag_must_mask, uint8_t tag_must_val,
367 uint8_t tag_may_mask, uint8_t tag_may_val,
368 int (*cb)( void *ctx, int tag,
369 unsigned char* start, size_t len ),
370 void *ctx );
371
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200372#if defined(MBEDTLS_BIGNUM_C)
Paul Bakkerefc30292011-11-10 14:43:23 +0000373/**
Paul Bakkercdda0972013-09-09 12:51:29 +0200374 * \brief Retrieve a MPI value from an integer ASN.1 tag.
375 * Updates the pointer to immediately behind the full tag.
Paul Bakkerefc30292011-11-10 14:43:23 +0000376 *
377 * \param p The position in the ASN.1 data
378 * \param end End of data
379 * \param X The MPI that will receive the value
380 *
381 * \return 0 if successful or a specific ASN.1 or MPI error code.
382 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200383int mbedtls_asn1_get_mpi( unsigned char **p,
Paul Bakkerefc30292011-11-10 14:43:23 +0000384 const unsigned char *end,
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200385 mbedtls_mpi *X );
386#endif /* MBEDTLS_BIGNUM_C */
Paul Bakkerefc30292011-11-10 14:43:23 +0000387
Paul Bakkerf8d018a2013-06-29 12:16:17 +0200388/**
Paul Bakkercdda0972013-09-09 12:51:29 +0200389 * \brief Retrieve an AlgorithmIdentifier ASN.1 sequence.
390 * Updates the pointer to immediately behind the full
391 * AlgorithmIdentifier.
Paul Bakkerf8d018a2013-06-29 12:16:17 +0200392 *
393 * \param p The position in the ASN.1 data
394 * \param end End of data
395 * \param alg The buffer to receive the OID
396 * \param params The buffer to receive the params (if any)
397 *
398 * \return 0 if successful or a specific ASN.1 or MPI error code.
399 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200400int mbedtls_asn1_get_alg( unsigned char **p,
Paul Bakkerf8d018a2013-06-29 12:16:17 +0200401 const unsigned char *end,
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200402 mbedtls_asn1_buf *alg, mbedtls_asn1_buf *params );
Paul Bakkerf8d018a2013-06-29 12:16:17 +0200403
404/**
Paul Bakkercdda0972013-09-09 12:51:29 +0200405 * \brief Retrieve an AlgorithmIdentifier ASN.1 sequence with NULL or no
406 * params.
407 * Updates the pointer to immediately behind the full
408 * AlgorithmIdentifier.
Paul Bakkerf8d018a2013-06-29 12:16:17 +0200409 *
410 * \param p The position in the ASN.1 data
411 * \param end End of data
412 * \param alg The buffer to receive the OID
413 *
414 * \return 0 if successful or a specific ASN.1 or MPI error code.
415 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200416int mbedtls_asn1_get_alg_null( unsigned char **p,
Paul Bakkerf8d018a2013-06-29 12:16:17 +0200417 const unsigned char *end,
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200418 mbedtls_asn1_buf *alg );
Paul Bakkerf8d018a2013-06-29 12:16:17 +0200419
Paul Bakkere5eae762013-08-26 12:05:14 +0200420/**
Paul Bakkercdda0972013-09-09 12:51:29 +0200421 * \brief Find a specific named_data entry in a sequence or list based on
422 * the OID.
Paul Bakkere5eae762013-08-26 12:05:14 +0200423 *
424 * \param list The list to seek through
425 * \param oid The OID to look for
426 * \param len Size of the OID
427 *
428 * \return NULL if not found, or a pointer to the existing entry.
429 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200430mbedtls_asn1_named_data *mbedtls_asn1_find_named_data( mbedtls_asn1_named_data *list,
Paul Bakkere5eae762013-08-26 12:05:14 +0200431 const char *oid, size_t len );
432
433/**
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200434 * \brief Free a mbedtls_asn1_named_data entry
Paul Bakkere5eae762013-08-26 12:05:14 +0200435 *
436 * \param entry The named data entry to free
437 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200438void mbedtls_asn1_free_named_data( mbedtls_asn1_named_data *entry );
Paul Bakkere5eae762013-08-26 12:05:14 +0200439
Paul Bakkerc547cc92013-09-09 12:01:23 +0200440/**
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200441 * \brief Free all entries in a mbedtls_asn1_named_data list
Paul Bakkercdda0972013-09-09 12:51:29 +0200442 * Head will be set to NULL
Paul Bakkerc547cc92013-09-09 12:01:23 +0200443 *
444 * \param head Pointer to the head of the list of named data entries to free
445 */
Manuel Pégourié-Gonnard2cf5a7c2015-04-08 12:49:31 +0200446void mbedtls_asn1_free_named_data_list( mbedtls_asn1_named_data **head );
Paul Bakkerc547cc92013-09-09 12:01:23 +0200447
Paul Bakkerefc30292011-11-10 14:43:23 +0000448#ifdef __cplusplus
449}
450#endif
451
452#endif /* asn1.h */