/*- *- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */ /* vim: set ts=8 sts=2 et sw=2 tw=80: */ /* This code is made available to you under your choice of the following sets *oflicensingterms:
*/ /* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.IfacopyoftheMPLwasnotdistributedwiththis *file,Youcanobtainoneathttp://mozilla.org/MPL/2.0/.
*/ /* Copyright 2013 Mozilla Contributors * *LicensedundertheApacheLicense,Version2.0(the"License"); *youmaynotusethisfileexceptincompliancewiththeLicense. *YoumayobtainacopyoftheLicenseat * *http://www.apache.org/licenses/LICENSE-2.0 * *Unlessrequiredbyapplicablelaworagreedtoinwriting,software *distributedundertheLicenseisdistributedonan"ASIS"BASIS, *WITHOUTWARRANTIESORCONDITIONSOFANYKIND,eitherexpressorimplied. *SeetheLicenseforthespecificlanguagegoverningpermissionsand *limitationsundertheLicense.
*/
Result
SubjectPublicKeyInfoToSECKEYPublicKey(Input subjectPublicKeyInfo,
ScopedSECKEYPublicKey& publicKey)
{
SECItem subjectPublicKeyInfoSECItem(
UnsafeMapInputToSECItem(subjectPublicKeyInfo));
ScopedCERTSubjectPublicKeyInfo spki(
SECKEY_DecodeDERSubjectPublicKeyInfo(&subjectPublicKeyInfoSECItem)); if (!spki) { return MapPRErrorCodeToResult(PR_GetError());
}
publicKey.reset(SECKEY_ExtractPublicKey(spki.get())); if (!publicKey) { return MapPRErrorCodeToResult(PR_GetError());
} return Success;
}
template<size_t N>
Result
VerifySignedData(SECKEYPublicKey* publicKey, CK_MECHANISM_TYPE mechanism,
SECItem* params, SECItem* signature, SECItem* data,
SECOidTag (&policyTags)[N], void* pkcs11PinArg)
{ // Hash and signature algorithms can be disabled by policy in NSS. However, // the policy engine in NSS is not currently sophisticated enough to, for // example, infer that disabling SEC_OID_SHA1 (i.e. the hash algorithm SHA1) // should also disable SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION. Thus, this // implementation checks the signature algorithm, the hash algorithm, and the // signature algorithm with the hash algorithm together. for (size_t i = 0; i < sizeof(policyTags) / sizeof(policyTags[0]); i++) {
SECOidTag policyTag = policyTags[i];
uint32_t policyFlags; if (NSS_GetAlgorithmPolicy(policyTag, &policyFlags) != SECSuccess) { return MapPRErrorCodeToResult(PR_GetError());
} if (!(policyFlags & NSS_USE_ALG_IN_ANY_SIGNATURE)) { return Result::ERROR_CERT_SIGNATURE_ALGORITHM_DISABLED;
}
}
SECStatus srv = PK11_VerifyWithMechanism(publicKey, mechanism, params,
signature, data, pkcs11PinArg); if (srv != SECSuccess) { return MapPRErrorCodeToResult(PR_GetError());
} return Success;
}
} // namespace
void
RegisterErrorTable()
{ // Note that these error strings are not localizable. // When these strings change, update the localization information too. staticconst PRErrorMessage ErrorTableText[] = {
{ "MOZILLA_PKIX_ERROR_KEY_PINNING_FAILURE", "The server uses key pinning (HPKP) but no trusted certificate chain " "could be constructed that matches the pinset. Key pinning violations " "cannot be overridden." },
{ "MOZILLA_PKIX_ERROR_CA_CERT_USED_AS_END_ENTITY", "The server uses a certificate with a basic constraints extension " "identifying it as a certificate authority. For a properly-issued " "certificate, this should not be the case." },
{ "MOZILLA_PKIX_ERROR_INADEQUATE_KEY_SIZE", "The server presented a certificate with a key size that is too small " "to establish a secure connection." },
{ "MOZILLA_PKIX_ERROR_V1_CERT_USED_AS_CA", "An X.509 version 1 certificate that is not a trust anchor was used to " "issue the server's certificate. X.509 version 1 certificates are " "deprecated and should not be used to sign other certificates." },
{ "MOZILLA_PKIX_ERROR_NO_RFC822NAME_MATCH", "The certificate is not valid for the given email address." },
{ "MOZILLA_PKIX_ERROR_NOT_YET_VALID_CERTIFICATE", "The server presented a certificate that is not yet valid." },
{ "MOZILLA_PKIX_ERROR_NOT_YET_VALID_ISSUER_CERTIFICATE", "A certificate that is not yet valid was used to issue the server's " "certificate." },
{ "MOZILLA_PKIX_ERROR_SIGNATURE_ALGORITHM_MISMATCH", "The signature algorithm in the signature field of the certificate does " "not match the algorithm in its signatureAlgorithm field." },
{ "MOZILLA_PKIX_ERROR_OCSP_RESPONSE_FOR_CERT_MISSING", "The OCSP response does not include a status for the certificate being " "verified." },
{ "MOZILLA_PKIX_ERROR_VALIDITY_TOO_LONG", "The server presented a certificate that is valid for too long." },
{ "MOZILLA_PKIX_ERROR_REQUIRED_TLS_FEATURE_MISSING", "A required TLS feature is missing." },
{ "MOZILLA_PKIX_ERROR_INVALID_INTEGER_ENCODING", "The server presented a certificate that contains an invalid encoding of " "an integer. Common causes include negative serial numbers, negative RSA " "moduli, and encodings that are longer than necessary." },
{ "MOZILLA_PKIX_ERROR_EMPTY_ISSUER_NAME", "The server presented a certificate with an empty issuer distinguished " "name." },
{ "MOZILLA_PKIX_ERROR_ADDITIONAL_POLICY_CONSTRAINT_FAILED", "An additional policy constraint failed when validating this " "certificate." },
{ "MOZILLA_PKIX_ERROR_SELF_SIGNED_CERT", "The certificate is not trusted because it is self-signed." },
{ "MOZILLA_PKIX_ERROR_MITM_DETECTED", "Your connection is being intercepted by a TLS proxy. Uninstall it if " "possible or configure your device to trust its root certificate." },
{ "MOZILLA_PKIX_ERROR_INSUFFICIENT_CERTIFICATE_TRANSPARENCY", "The server presented insufficient certificate transparency information." " Its certificate may not have been publicly disclosed, and it may have " "been misissued." },
{ "MOZILLA_PKIX_ERROR_ISSUER_NO_LONGER_TRUSTED", "The certificate was issued by a certificate authority that is no longer" " trusted to issue new certificates." },
}; // Note that these error strings are not localizable. // When these strings change, update the localization information too.
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.