Line data Source code
1 : #ifndef HEADER_fd_src_ballet_x509_fd_x509_ca_store_h 2 : #define HEADER_fd_src_ballet_x509_fd_x509_ca_store_h 3 : 4 : /* fd_x509_ca_store.h implements a CA trust store for verifying X.509 5 : certificate chains. */ 6 : 7 : #include "fd_x509.h" 8 : 9 1545 : #define FD_X509_CA_STORE_MAX (512UL) 10 1734 : #define FD_X509_CA_SUBJECT_MAX (512UL) 11 1728 : #define FD_X509_CA_NAME_CONSTRAINTS_MAX (1024UL) 12 : 13 : struct fd_x509_ca_entry { 14 : uchar subject[ FD_X509_CA_SUBJECT_MAX ]; 15 : ulong subject_len; 16 : 17 : uchar pubkey[ FD_X509_PUBKEY_MAX ]; 18 : ulong pubkey_len; 19 : uchar key_type; /* FD_X509_KEY_{...} */ 20 : 21 : /* basicConstraints pathLenConstraint of the anchor cert, if any. 22 : RFC 5280 Section 6.2 leaves enforcing trust anchor constraints to 23 : the implementation; OpenSSL does, so fd_x509 does too. */ 24 : ulong path_len_constraint; 25 : uchar has_path_len_constraint; 26 : 27 : /* GeneralSubtrees contents: permittedSubtrees at [0,permitted_len), 28 : excludedSubtrees at [permitted_len,permitted_len+excluded_len) */ 29 : uchar name_constraints[ FD_X509_CA_NAME_CONSTRAINTS_MAX ]; 30 : ulong name_constraints_permitted_len; 31 : ulong name_constraints_excluded_len; 32 : uchar has_name_constraints; 33 : }; 34 : 35 : typedef struct fd_x509_ca_entry fd_x509_ca_entry_t; 36 : 37 : /* fd_x509_ca_store_t holds the complete trust store. */ 38 : 39 : struct fd_x509_ca_store { 40 : fd_x509_ca_entry_t entries[ FD_X509_CA_STORE_MAX ]; 41 : ulong cnt; 42 : }; 43 : 44 : typedef struct fd_x509_ca_store fd_x509_ca_store_t; 45 : 46 : FD_PROTOTYPES_BEGIN 47 : 48 : #if FD_HAS_HOSTED 49 : 50 : /* fd_x509_ca_store_load clears store, then loads supported CA certificates 51 : from the PEM bundle at pem_path. Malformed, unsupported, non-CA, and 52 : unusable entries are skipped, as are CA certs whose extKeyUsage does 53 : not permit TLS server authentication (the store's only use). Bundles 54 : exceeding FD_X509_CA_STORE_MAX are truncated. 55 : 56 : Returns the number of loaded trust anchors, or -1 for a file-level error. 57 : store and pem_path must be non-NULL. */ 58 : 59 : long 60 : fd_x509_ca_store_load( fd_x509_ca_store_t * store, 61 : char const * pem_path ); 62 : 63 : /* fd_x509_ca_store_load_system loads the host's system CA bundle into 64 : store, trying the well known bundle paths of the common distros in 65 : order. Returns the number of trust anchors loaded from the first bundle 66 : that could be read and held at least one usable anchor, or -1 if there 67 : was no such bundle. */ 68 : 69 : long 70 : fd_x509_ca_store_load_system( fd_x509_ca_store_t * store ); 71 : 72 : #endif /* FD_HAS_HOSTED */ 73 : 74 : /* fd_x509_ca_store_find_next returns the trust anchor at index *idx or 75 : later whose subject matches, and advances *idx past it. Returns NULL 76 : when no further match exists. *idx should be 0 on the first call. */ 77 : 78 : fd_x509_ca_entry_t const * 79 : fd_x509_ca_store_find_next( fd_x509_ca_store_t const * store, 80 : uchar const * subject, 81 : ulong subject_len, 82 : ulong * idx ); 83 : 84 : FD_PROTOTYPES_END 85 : 86 : #endif /* HEADER_fd_src_ballet_x509_fd_x509_ca_store_h */