21.03.2013 Views

Problem - Kevin Tafuro

Problem - Kevin Tafuro

Problem - Kevin Tafuro

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

the CRLthat corresponds to the certificate used to issue another certificate. Unfortunately,<br />

this extension is defined as being optional, and most root CAs do not use it.<br />

#include <br />

#include <br />

#include <br />

#include <br />

#include <br />

#include <br />

#include <br />

typedef struct {<br />

char *name;<br />

unsigned char *fingerprint;<br />

unsigned int fingerprint_length;<br />

char *crl_uri;<br />

char *ocsp_uri;<br />

} spc_cacert_t;<br />

spc_cacert_t *spc_lookup_cacert(X509 *cert);<br />

static char *get_distribution_point(X509 *cert) {<br />

int extcount, i, j;<br />

const char *extstr;<br />

CONF_VALUE *nval;<br />

unsigned char *data;<br />

X509_EXTENSION *ext;<br />

X509V3_EXT_METHOD *meth;<br />

STACK_OF(CONF_VALUE) *val;<br />

if ((extcount = X509_get_ext_count(cert)) > 0) {<br />

for (i = 0; i < extcount; i++) {<br />

ext = X509_get_ext(cert, i);<br />

extstr = OBJ_nid2sn(OBJ_obj2nid(X509_EXTENSION_get_object(ext)));<br />

if (strcasecmp(extstr, "crlDistributionPoints")) continue;<br />

if (!(meth = X509V3_EXT_get(ext))) break;<br />

data = ext->value->data;<br />

val = meth->i2v(meth, meth->d2i(0, &data, ext->value->length), 0);<br />

for (j = 0; j < sk_CONF_VALUE_num(val); j++) {<br />

nval = sk_CONF_VALUE_value(val, j);<br />

if (!strcasecmp(nval->name, "URI"))<br />

return strdup(nval->value);<br />

}<br />

}<br />

}<br />

return 0;<br />

}<br />

char *spc_getcert_crlurl(X509 *cert, X509 *issuer, int lookup_only) {<br />

char *uri;<br />

spc_cacert_t *cacert;<br />

if (!lookup_only) {<br />

548 | Chapter 10: Public Key Infrastructure<br />

This is the Title of the Book, eMatter Edition<br />

Copyright © 2007 O’Reilly & Associates, Inc. All rights reserved.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!