/*- *- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */ /* vim: set ts=8 sts=2 et sw=2 tw=80: */ /* This code is made available to you under your choice of the following sets *oflicensingterms:
*/ /* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.IfacopyoftheMPLwasnotdistributedwiththis *file,Youcanobtainoneathttp://mozilla.org/MPL/2.0/.
*/ /* Copyright 2013 Mozilla Contributors * *LicensedundertheApacheLicense,Version2.0(the"License"); *youmaynotusethisfileexceptincompliancewiththeLicense. *YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
Result
SubjectPublicKeyInfoToSECKEYPublicKey(Input subjectPublicKeyInfo,
ScopedSECKEYPublicKey& publicKey)
{
SECItem subjectPublicKeyInfoSECItem(
UnsafeMapInputToSECItem(subjectPublicKeyInfo));
ScopedCERTSubjectPublicKeyInfo spki(
SECKEY_DecodeDERSubjectPublicKeyInfo(&subjectPublicKeyInfoSECItem)); if (!spki) { return MapPRErrorCodeToResult(PR_GetError());
}
publicKey.reset(SECKEY_ExtractPublicKey(spki.get())); if (!publicKey) { return MapPRErrorCodeToResult(PR_GetError());
} return Success;
}
template<size_t N>
Result
VerifySignedData(SECKEYPublicKey* publicKey, CK_MECHANISM_TYPE mechanism,
SECItem* params, SECItem* signature, SECItem* data,
SECOidTag (&policyTags)[N], void* pkcs11PinArg)
{ // Hash and signature algorithms can be disabled by policy in NSS. However, // the policy engine in NSS is not currently sophisticated enough to, for // example, infer that disabling SEC_OID_SHA1 (i.e. the hash algorithm SHA1) // should also disable SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION. Thus, this // implementation checks the signature algorithm, the hash algorithm, and the // signature algorithm with the hash algorithm together. for (size_t i = 0; i < sizeof(policyTags) / sizeof(policyTags[0]); i++) {
SECOidTag policyTag = policyTags[i];
uint32_t policyFlags; if (NSS_GetAlgorithmPolicy(policyTag, &policyFlags) != SECSuccess) { return MapPRErrorCodeToResult(PR_GetError());
} if (!(policyFlags & NSS_USE_ALG_IN_ANY_SIGNATURE)) { return Result::ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED;
}
}
SECStatus srv = PK11_VerifyWithMechanism(publicKey, mechanism, params,
signature, data, pkcs11PinArg); if (srv != SECSuccess) { return MapPRErrorCodeToResult(PR_GetError());
} return Success;
}
} // namespace
void
RegisterErrorTable()
{ // Note that these error strings are not localizable. // When these strings change, update the localization information too. staticconst PRErrorMessage ErrorTableText[] = {
{ "MOZILLA_PKIX_ERROR_KEY_PINNING_FAILURE", "The server uses key pinning (HPKP) but no trusted certificate chain " "could be constructed that matches the pinset. Key pinning violations " "cannot be overridden." },
{ "MOZILLA_PKIX_ERROR_CA_CERT_USED_AS_END_ENTITY", "The server uses a certificate with a basic constraints extension " "identifying it as a certificate authority. For a properly-issued " "certificate, this should not be the case." },
{ "MOZILLA_PKIX_ERROR_INADEQUATE_KEY_SIZE", "The server presented a certificate with a key size that is too small " "to establish a secure connection." },
{ "MOZILLA_PKIX_ERROR_V1_CERT_USED_AS_CA", "An X.509 version 1 certificate that is not a trust anchor was used to " "issue the server's certificate. X.509 version 1 certificates are " "deprecated and should not be used to sign other certificates." },
{ "MOZILLA_PKIX_ERROR_NO_RFC822NAME_MATCH", "The certificate is not valid for the given email address." },
{ "MOZILLA_PKIX_ERROR_NOT_YET_VALID_CERTIFICATE", "The server presented a certificate that is not yet valid." },
{ "MOZILLA_PKIX_ERROR_NOT_YET_VALID_ISSUER_CERTIFICATE", "A certificate that is not yet valid was used to issue the server's " "certificate." },
{ "MOZILLA_PKIX_ERROR_SIGNATURE_ALGORITHM_MISMATCH", "The signature algorithm in the signature field of the certificate does " "not match the algorithm in its signatureAlgorithm field." },
{ "MOZILLA_PKIX_ERROR_OCSP_RESPONSE_FOR_CERT_MISSING", "The OCSP response does not include a status for the certificate being " "verified." },
{ "MOZILLA_PKIX_ERROR_VALIDITY_TOO_LONG", "The server presented a certificate that is valid for too long." },
{ "MOZILLA_PKIX_ERROR_REQUIRED_TLS_FEATURE_MISSING", "A required TLS feature is missing." },
{ "MOZILLA_PKIX_ERROR_INVALID_INTEGER_ENCODING", "The server presented a certificate that contains an invalid encoding of " "an integer. Common causes include negative serial numbers, negative RSA " "moduli, and encodings that are longer than necessary." },
{ "MOZILLA_PKIX_ERROR_EMPTY_ISSUER_NAME", "The server presented a certificate with an empty issuer distinguished " "name." },
{ "MOZILLA_PKIX_ERROR_ADDITIONAL_POLICY_CONSTRAINT_FAILED", "An additional policy constraint failed when validating this " "certificate." },
{ "MOZILLA_PKIX_ERROR_SELF_SIGNED_CERT", "The certificate is not trusted because it is self-signed." },
{ "MOZILLA_PKIX_ERROR_MITM_DETECTED", "Your connection is being intercepted by a TLS proxy. Uninstall it if " "possible or configure your device to trust its root certificate." },
{ "MOZILLA_PKIX_ERROR_INSUFFICIENT_CERTIFICATE_TRANSPARENCY", "The server presented insufficient certificate transparency information." " Its certificate may not have been publicly disclosed, and it may have " "been misissued." },
{ "MOZILLA_PKIX_ERROR_ISSUER_NO_LONGER_TRUSTED", "The certificate was issued by a certificate authority that is no longer" " trusted to issue new certificates." },
}; // Note that these error strings are not localizable. // When these strings change, update the localization information too.
¤ Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.0.1Bemerkung:
(vorverarbeitet am 2026-10-11)
¤
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.