Coverage Report

Created: 2024-05-20 06:23

/src/nss/lib/util/secoid.c
Line
Count
Source (jump to first uncovered line)
1
/* This Source Code Form is subject to the terms of the Mozilla Public
2
 * License, v. 2.0. If a copy of the MPL was not distributed with this
3
 * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
4
5
#include "secoid.h"
6
#include "pkcs11t.h"
7
#include "secitem.h"
8
#include "secerr.h"
9
#include "prenv.h"
10
#include "plhash.h"
11
#include "nssrwlk.h"
12
#include "nssutil.h"
13
#include "secoidt.h"
14
15
/* Library identity and versioning */
16
17
#if defined(DEBUG)
18
#define _DEBUG_STRING " (debug)"
19
#else
20
#define _DEBUG_STRING ""
21
#endif
22
23
/*
24
 * Version information
25
 */
26
const char __nss_util_version[] = "Version: NSS " NSSUTIL_VERSION _DEBUG_STRING;
27
28
/* MISSI Mosaic Object ID space */
29
/* USGov algorithm OID space: { 2 16 840 1 101 } */
30
#define USGOV 0x60, 0x86, 0x48, 0x01, 0x65
31
#define MISSI USGOV, 0x02, 0x01, 0x01
32
#define MISSI_OLD_KEA_DSS MISSI, 0x0c
33
#define MISSI_OLD_DSS MISSI, 0x02
34
#define MISSI_KEA_DSS MISSI, 0x14
35
#define MISSI_DSS MISSI, 0x13
36
#define MISSI_KEA MISSI, 0x0a
37
#define MISSI_ALT_KEA MISSI, 0x16
38
39
#define NISTALGS USGOV, 3, 4
40
#define AES NISTALGS, 1
41
#define SHAXXX NISTALGS, 2
42
#define DSA2 NISTALGS, 3
43
44
/**
45
 ** The Netscape OID space is allocated by Terry Hayes.  If you need
46
 ** a piece of the space, contact him at thayes@netscape.com.
47
 **/
48
49
/* Netscape Communications Corporation Object ID space */
50
/* { 2 16 840 1 113730 } */
51
#define NETSCAPE_OID 0x60, 0x86, 0x48, 0x01, 0x86, 0xf8, 0x42
52
#define NETSCAPE_CERT_EXT NETSCAPE_OID, 0x01
53
#define NETSCAPE_DATA_TYPE NETSCAPE_OID, 0x02
54
/* netscape directory oid - owned by Mark Smith (mcs@netscape.com) */
55
#define NETSCAPE_DIRECTORY NETSCAPE_OID, 0x03
56
#define NETSCAPE_POLICY NETSCAPE_OID, 0x04
57
#define NETSCAPE_CERT_SERVER NETSCAPE_OID, 0x05
58
#define NETSCAPE_ALGS NETSCAPE_OID, 0x06 /* algorithm OIDs */
59
#define NETSCAPE_NAME_COMPONENTS NETSCAPE_OID, 0x07
60
61
#define NETSCAPE_CERT_EXT_AIA NETSCAPE_CERT_EXT, 0x10
62
#define NETSCAPE_CERT_SERVER_CRMF NETSCAPE_CERT_SERVER, 0x01
63
64
/* these are old and should go away soon */
65
#define OLD_NETSCAPE 0x60, 0x86, 0x48, 0xd8, 0x6a
66
#define NS_CERT_EXT OLD_NETSCAPE, 0x01
67
#define NS_FILE_TYPE OLD_NETSCAPE, 0x02
68
#define NS_IMAGE_TYPE OLD_NETSCAPE, 0x03
69
70
/* RSA OID name space */
71
#define RSADSI 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d
72
#define PKCS RSADSI, 0x01
73
#define DIGEST RSADSI, 0x02
74
#define CIPHER RSADSI, 0x03
75
#define PKCS1 PKCS, 0x01
76
#define PKCS5 PKCS, 0x05
77
#define PKCS7 PKCS, 0x07
78
#define PKCS9 PKCS, 0x09
79
#define PKCS12 PKCS, 0x0c
80
81
/* Other OID name spaces */
82
#define ALGORITHM 0x2b, 0x0e, 0x03, 0x02
83
#define X500 0x55
84
#define X520_ATTRIBUTE_TYPE X500, 0x04
85
#define X500_ALG X500, 0x08
86
#define X500_ALG_ENCRYPTION X500_ALG, 0x01
87
88
/** X.509 v3 Extension OID
89
 ** {joint-iso-ccitt (2) ds(5) 29}
90
 **/
91
#define ID_CE_OID X500, 0x1d
92
93
#define RFC1274_ATTR_TYPE 0x09, 0x92, 0x26, 0x89, 0x93, 0xf2, 0x2c, 0x64, 0x1
94
/* #define RFC2247_ATTR_TYPE  0x09, 0x92, 0x26, 0xf5, 0x98, 0x1e, 0x64, 0x1 this is WRONG! */
95
96
/* PKCS #12 name spaces */
97
#define PKCS12_MODE_IDS PKCS12, 0x01
98
#define PKCS12_ESPVK_IDS PKCS12, 0x02
99
#define PKCS12_BAG_IDS PKCS12, 0x03
100
#define PKCS12_CERT_BAG_IDS PKCS12, 0x04
101
#define PKCS12_OIDS PKCS12, 0x05
102
#define PKCS12_PBE_IDS PKCS12_OIDS, 0x01
103
#define PKCS12_ENVELOPING_IDS PKCS12_OIDS, 0x02
104
#define PKCS12_SIGNATURE_IDS PKCS12_OIDS, 0x03
105
#define PKCS12_V2_PBE_IDS PKCS12, 0x01
106
#define PKCS9_CERT_TYPES PKCS9, 0x16
107
#define PKCS9_CRL_TYPES PKCS9, 0x17
108
#define PKCS9_SMIME_IDS PKCS9, 0x10
109
#define PKCS9_SMIME_ATTRS PKCS9_SMIME_IDS, 2
110
#define PKCS9_SMIME_ALGS PKCS9_SMIME_IDS, 3
111
#define PKCS12_VERSION1 PKCS12, 0x0a
112
#define PKCS12_V1_BAG_IDS PKCS12_VERSION1, 1
113
114
/* for DSA algorithm */
115
/* { iso(1) member-body(2) us(840) x9-57(10040) x9algorithm(4) } */
116
#define ANSI_X9_ALGORITHM 0x2a, 0x86, 0x48, 0xce, 0x38, 0x4
117
118
/* for DH algorithm */
119
/* { iso(1) member-body(2) us(840) x9-57(10046) number-type(2) } */
120
/* need real OID person to look at this, copied the above line
121
 * and added 6 to second to last value (and changed '4' to '2' */
122
#define ANSI_X942_ALGORITHM 0x2a, 0x86, 0x48, 0xce, 0x3e, 0x2
123
124
#define VERISIGN 0x60, 0x86, 0x48, 0x01, 0x86, 0xf8, 0x45
125
126
#define INTERNET_SECURITY_MECH 0x2b, 0x06, 0x01, 0x05, 0x05
127
128
#define PKIX INTERNET_SECURITY_MECH, 0x07
129
#define PKIX_CERT_EXTENSIONS PKIX, 1
130
#define PKIX_POLICY_QUALIFIERS PKIX, 2
131
#define PKIX_KEY_USAGE PKIX, 3
132
#define PKIX_ACCESS_DESCRIPTION PKIX, 0x30
133
#define PKIX_OCSP PKIX_ACCESS_DESCRIPTION, 1
134
#define PKIX_CA_ISSUERS PKIX_ACCESS_DESCRIPTION, 2
135
136
#define PKIX_ID_PKIP PKIX, 5
137
#define PKIX_ID_REGCTRL PKIX_ID_PKIP, 1
138
#define PKIX_ID_REGINFO PKIX_ID_PKIP, 2
139
140
/* Microsoft Object ID space */
141
/* { 1.3.6.1.4.1.311 } */
142
#define MICROSOFT_OID 0x2b, 0x6, 0x1, 0x4, 0x1, 0x82, 0x37
143
#define EV_NAME_ATTRIBUTE MICROSOFT_OID, 60, 2, 1
144
145
/* Microsoft Crypto 2.0 ID space */
146
/* { 1.3.6.1.4.1.311.10 } */
147
#define MS_CRYPTO_20 MICROSOFT_OID, 10
148
/* Microsoft Crypto 2.0 Extended Key Usage ID space */
149
/* { 1.3.6.1.4.1.311.10.3 } */
150
#define MS_CRYPTO_EKU MS_CRYPTO_20, 3
151
152
#define CERTICOM_OID 0x2b, 0x81, 0x04
153
#define SECG_OID CERTICOM_OID, 0x00
154
155
#define ANSI_X962_OID 0x2a, 0x86, 0x48, 0xce, 0x3d
156
#define ANSI_X962_CURVE_OID ANSI_X962_OID, 0x03
157
#define ANSI_X962_GF2m_OID ANSI_X962_CURVE_OID, 0x00
158
#define ANSI_X962_GFp_OID ANSI_X962_CURVE_OID, 0x01
159
#define ANSI_X962_SIGNATURE_OID ANSI_X962_OID, 0x04
160
#define ANSI_X962_SPECIFY_OID ANSI_X962_SIGNATURE_OID, 0x03
161
162
#define X9_63_SCHEME 0x2B, 0x81, 0x05, 0x10, 0x86, 0x48, 0x3F, 0x00
163
#define SECG_SCHEME CERTICOM_OID, 0x01
164
165
/* for Camellia: iso(1) member-body(2) jisc(392)
166
 *    mitsubishi(200011) isl(61) security(1) algorithm(1)
167
 */
168
#define MITSUBISHI_ALG 0x2a, 0x83, 0x08, 0x8c, 0x9a, 0x4b, 0x3d, 0x01, 0x01
169
#define CAMELLIA_ENCRYPT_OID MITSUBISHI_ALG, 1
170
#define CAMELLIA_WRAP_OID MITSUBISHI_ALG, 3
171
172
/* For IDEA: 1.3.6.1.4.1.188.7.1.1
173
 */
174
#define ASCOM_OID 0x2b, 0x6, 0x1, 0x4, 0x1, 0xbc
175
#define ASCOM_IDEA_ALG ASCOM_OID, 0x7, 0x1, 0x1
176
177
/* for SEED : iso(1) member-body(2) korea(410)
178
 *    kisa(200004) algorithm(1)
179
 */
180
#define SEED_OID 0x2a, 0x83, 0x1a, 0x8c, 0x9a, 0x44, 0x01
181
182
#define CONST_OID static const unsigned char
183
184
CONST_OID md2[] = { DIGEST, 0x02 };
185
CONST_OID md4[] = { DIGEST, 0x04 };
186
CONST_OID md5[] = { DIGEST, 0x05 };
187
CONST_OID hmac_sha1[] = { DIGEST, 7 };
188
CONST_OID hmac_sha224[] = { DIGEST, 8 };
189
CONST_OID hmac_sha256[] = { DIGEST, 9 };
190
CONST_OID hmac_sha384[] = { DIGEST, 10 };
191
CONST_OID hmac_sha512[] = { DIGEST, 11 };
192
193
CONST_OID rc2cbc[] = { CIPHER, 0x02 };
194
CONST_OID rc4[] = { CIPHER, 0x04 };
195
CONST_OID desede3cbc[] = { CIPHER, 0x07 };
196
CONST_OID rc5cbcpad[] = { CIPHER, 0x09 };
197
198
CONST_OID desecb[] = { ALGORITHM, 0x06 };
199
CONST_OID descbc[] = { ALGORITHM, 0x07 };
200
CONST_OID desofb[] = { ALGORITHM, 0x08 };
201
CONST_OID descfb[] = { ALGORITHM, 0x09 };
202
CONST_OID desmac[] = { ALGORITHM, 0x0a };
203
CONST_OID sdn702DSASignature[] = { ALGORITHM, 0x0c };
204
CONST_OID isoSHAWithRSASignature[] = { ALGORITHM, 0x0f };
205
CONST_OID desede[] = { ALGORITHM, 0x11 };
206
CONST_OID sha1[] = { ALGORITHM, 0x1a };
207
CONST_OID bogusDSASignaturewithSHA1Digest[] = { ALGORITHM, 0x1b };
208
CONST_OID isoSHA1WithRSASignature[] = { ALGORITHM, 0x1d };
209
210
CONST_OID pkcs1RSAEncryption[] = { PKCS1, 0x01 };
211
CONST_OID pkcs1MD2WithRSAEncryption[] = { PKCS1, 0x02 };
212
CONST_OID pkcs1MD4WithRSAEncryption[] = { PKCS1, 0x03 };
213
CONST_OID pkcs1MD5WithRSAEncryption[] = { PKCS1, 0x04 };
214
CONST_OID pkcs1SHA1WithRSAEncryption[] = { PKCS1, 0x05 };
215
CONST_OID pkcs1RSAOAEPEncryption[] = { PKCS1, 0x07 };
216
CONST_OID pkcs1MGF1[] = { PKCS1, 0x08 };
217
CONST_OID pkcs1PSpecified[] = { PKCS1, 0x09 };
218
CONST_OID pkcs1RSAPSSSignature[] = { PKCS1, 10 };
219
CONST_OID pkcs1SHA256WithRSAEncryption[] = { PKCS1, 11 };
220
CONST_OID pkcs1SHA384WithRSAEncryption[] = { PKCS1, 12 };
221
CONST_OID pkcs1SHA512WithRSAEncryption[] = { PKCS1, 13 };
222
CONST_OID pkcs1SHA224WithRSAEncryption[] = { PKCS1, 14 };
223
224
CONST_OID pkcs5PbeWithMD2AndDEScbc[] = { PKCS5, 0x01 };
225
CONST_OID pkcs5PbeWithMD5AndDEScbc[] = { PKCS5, 0x03 };
226
CONST_OID pkcs5PbeWithSha1AndDEScbc[] = { PKCS5, 0x0a };
227
CONST_OID pkcs5Pbkdf2[] = { PKCS5, 12 };
228
CONST_OID pkcs5Pbes2[] = { PKCS5, 13 };
229
CONST_OID pkcs5Pbmac1[] = { PKCS5, 14 };
230
231
CONST_OID pkcs7[] = { PKCS7 };
232
CONST_OID pkcs7Data[] = { PKCS7, 0x01 };
233
CONST_OID pkcs7SignedData[] = { PKCS7, 0x02 };
234
CONST_OID pkcs7EnvelopedData[] = { PKCS7, 0x03 };
235
CONST_OID pkcs7SignedEnvelopedData[] = { PKCS7, 0x04 };
236
CONST_OID pkcs7DigestedData[] = { PKCS7, 0x05 };
237
CONST_OID pkcs7EncryptedData[] = { PKCS7, 0x06 };
238
239
CONST_OID pkcs9EmailAddress[] = { PKCS9, 0x01 };
240
CONST_OID pkcs9UnstructuredName[] = { PKCS9, 0x02 };
241
CONST_OID pkcs9ContentType[] = { PKCS9, 0x03 };
242
CONST_OID pkcs9MessageDigest[] = { PKCS9, 0x04 };
243
CONST_OID pkcs9SigningTime[] = { PKCS9, 0x05 };
244
CONST_OID pkcs9CounterSignature[] = { PKCS9, 0x06 };
245
CONST_OID pkcs9ChallengePassword[] = { PKCS9, 0x07 };
246
CONST_OID pkcs9UnstructuredAddress[] = { PKCS9, 0x08 };
247
CONST_OID pkcs9ExtendedCertificateAttributes[] = { PKCS9, 0x09 };
248
CONST_OID pkcs9ExtensionRequest[] = { PKCS9, 14 };
249
CONST_OID pkcs9SMIMECapabilities[] = { PKCS9, 15 };
250
CONST_OID pkcs9FriendlyName[] = { PKCS9, 20 };
251
CONST_OID pkcs9LocalKeyID[] = { PKCS9, 21 };
252
253
CONST_OID pkcs9X509Certificate[] = { PKCS9_CERT_TYPES, 1 };
254
CONST_OID pkcs9SDSICertificate[] = { PKCS9_CERT_TYPES, 2 };
255
CONST_OID pkcs9X509CRL[] = { PKCS9_CRL_TYPES, 1 };
256
257
/* RFC2630 (CMS) OIDs */
258
CONST_OID cmsESDH[] = { PKCS9_SMIME_ALGS, 5 };
259
CONST_OID cms3DESwrap[] = { PKCS9_SMIME_ALGS, 6 };
260
CONST_OID cmsRC2wrap[] = { PKCS9_SMIME_ALGS, 7 };
261
262
/* RFC2633 SMIME message attributes */
263
CONST_OID smimeEncryptionKeyPreference[] = { PKCS9_SMIME_ATTRS, 11 };
264
CONST_OID ms_smimeEncryptionKeyPreference[] = { MICROSOFT_OID, 0x10, 0x4 };
265
266
CONST_OID x520CommonName[] = { X520_ATTRIBUTE_TYPE, 3 };
267
CONST_OID x520SurName[] = { X520_ATTRIBUTE_TYPE, 4 };
268
CONST_OID x520SerialNumber[] = { X520_ATTRIBUTE_TYPE, 5 };
269
CONST_OID x520CountryName[] = { X520_ATTRIBUTE_TYPE, 6 };
270
CONST_OID x520LocalityName[] = { X520_ATTRIBUTE_TYPE, 7 };
271
CONST_OID x520StateOrProvinceName[] = { X520_ATTRIBUTE_TYPE, 8 };
272
CONST_OID x520StreetAddress[] = { X520_ATTRIBUTE_TYPE, 9 };
273
CONST_OID x520OrgName[] = { X520_ATTRIBUTE_TYPE, 10 };
274
CONST_OID x520OrgUnitName[] = { X520_ATTRIBUTE_TYPE, 11 };
275
CONST_OID x520Title[] = { X520_ATTRIBUTE_TYPE, 12 };
276
CONST_OID x520BusinessCategory[] = { X520_ATTRIBUTE_TYPE, 15 };
277
CONST_OID x520PostalAddress[] = { X520_ATTRIBUTE_TYPE, 16 };
278
CONST_OID x520PostalCode[] = { X520_ATTRIBUTE_TYPE, 17 };
279
CONST_OID x520PostOfficeBox[] = { X520_ATTRIBUTE_TYPE, 18 };
280
CONST_OID x520Name[] = { X520_ATTRIBUTE_TYPE, 41 };
281
CONST_OID x520GivenName[] = { X520_ATTRIBUTE_TYPE, 42 };
282
CONST_OID x520Initials[] = { X520_ATTRIBUTE_TYPE, 43 };
283
CONST_OID x520GenerationQualifier[] = { X520_ATTRIBUTE_TYPE, 44 };
284
CONST_OID x520DnQualifier[] = { X520_ATTRIBUTE_TYPE, 46 };
285
CONST_OID x520HouseIdentifier[] = { X520_ATTRIBUTE_TYPE, 51 };
286
CONST_OID x520Pseudonym[] = { X520_ATTRIBUTE_TYPE, 65 };
287
288
CONST_OID nsTypeGIF[] = { NETSCAPE_DATA_TYPE, 0x01 };
289
CONST_OID nsTypeJPEG[] = { NETSCAPE_DATA_TYPE, 0x02 };
290
CONST_OID nsTypeURL[] = { NETSCAPE_DATA_TYPE, 0x03 };
291
CONST_OID nsTypeHTML[] = { NETSCAPE_DATA_TYPE, 0x04 };
292
CONST_OID nsTypeCertSeq[] = { NETSCAPE_DATA_TYPE, 0x05 };
293
294
CONST_OID missiCertKEADSSOld[] = { MISSI_OLD_KEA_DSS };
295
CONST_OID missiCertDSSOld[] = { MISSI_OLD_DSS };
296
CONST_OID missiCertKEADSS[] = { MISSI_KEA_DSS };
297
CONST_OID missiCertDSS[] = { MISSI_DSS };
298
CONST_OID missiCertKEA[] = { MISSI_KEA };
299
CONST_OID missiCertAltKEA[] = { MISSI_ALT_KEA };
300
CONST_OID x500RSAEncryption[] = { X500_ALG_ENCRYPTION, 0x01 };
301
302
/* added for alg 1485 */
303
CONST_OID rfc1274Uid[] = { RFC1274_ATTR_TYPE, 1 };
304
CONST_OID rfc1274Mail[] = { RFC1274_ATTR_TYPE, 3 };
305
CONST_OID rfc2247DomainComponent[] = { RFC1274_ATTR_TYPE, 25 };
306
307
/* Netscape private certificate extensions */
308
CONST_OID nsCertExtNetscapeOK[] = { NS_CERT_EXT, 1 };
309
CONST_OID nsCertExtIssuerLogo[] = { NS_CERT_EXT, 2 };
310
CONST_OID nsCertExtSubjectLogo[] = { NS_CERT_EXT, 3 };
311
CONST_OID nsExtCertType[] = { NETSCAPE_CERT_EXT, 0x01 };
312
CONST_OID nsExtBaseURL[] = { NETSCAPE_CERT_EXT, 0x02 };
313
CONST_OID nsExtRevocationURL[] = { NETSCAPE_CERT_EXT, 0x03 };
314
CONST_OID nsExtCARevocationURL[] = { NETSCAPE_CERT_EXT, 0x04 };
315
CONST_OID nsExtCACRLURL[] = { NETSCAPE_CERT_EXT, 0x05 };
316
CONST_OID nsExtCACertURL[] = { NETSCAPE_CERT_EXT, 0x06 };
317
CONST_OID nsExtCertRenewalURL[] = { NETSCAPE_CERT_EXT, 0x07 };
318
CONST_OID nsExtCAPolicyURL[] = { NETSCAPE_CERT_EXT, 0x08 };
319
CONST_OID nsExtHomepageURL[] = { NETSCAPE_CERT_EXT, 0x09 };
320
CONST_OID nsExtEntityLogo[] = { NETSCAPE_CERT_EXT, 0x0a };
321
CONST_OID nsExtUserPicture[] = { NETSCAPE_CERT_EXT, 0x0b };
322
CONST_OID nsExtSSLServerName[] = { NETSCAPE_CERT_EXT, 0x0c };
323
CONST_OID nsExtComment[] = { NETSCAPE_CERT_EXT, 0x0d };
324
325
/* the following 2 extensions are defined for and used by Cartman(NSM) */
326
CONST_OID nsExtLostPasswordURL[] = { NETSCAPE_CERT_EXT, 0x0e };
327
CONST_OID nsExtCertRenewalTime[] = { NETSCAPE_CERT_EXT, 0x0f };
328
329
CONST_OID nsExtAIACertRenewal[] = { NETSCAPE_CERT_EXT_AIA, 0x01 };
330
CONST_OID nsExtCertScopeOfUse[] = { NETSCAPE_CERT_EXT, 0x11 };
331
/* Reserved Netscape (2 16 840 1 113730 1 18) = { NETSCAPE_CERT_EXT, 0x12 }; */
332
333
/* Netscape policy values */
334
CONST_OID nsKeyUsageGovtApproved[] = { NETSCAPE_POLICY, 0x01 };
335
336
/* Netscape other name types */
337
CONST_OID netscapeNickname[] = { NETSCAPE_NAME_COMPONENTS, 0x01 };
338
CONST_OID netscapeAOLScreenname[] = { NETSCAPE_NAME_COMPONENTS, 0x02 };
339
340
/* OIDs needed for cert server */
341
CONST_OID netscapeRecoveryRequest[] = { NETSCAPE_CERT_SERVER_CRMF, 0x01 };
342
343
/* Standard x.509 v3 Certificate & CRL Extensions */
344
CONST_OID x509SubjectDirectoryAttr[] = { ID_CE_OID, 9 };
345
CONST_OID x509SubjectKeyID[] = { ID_CE_OID, 14 };
346
CONST_OID x509KeyUsage[] = { ID_CE_OID, 15 };
347
CONST_OID x509PrivateKeyUsagePeriod[] = { ID_CE_OID, 16 };
348
CONST_OID x509SubjectAltName[] = { ID_CE_OID, 17 };
349
CONST_OID x509IssuerAltName[] = { ID_CE_OID, 18 };
350
CONST_OID x509BasicConstraints[] = { ID_CE_OID, 19 };
351
CONST_OID x509CRLNumber[] = { ID_CE_OID, 20 };
352
CONST_OID x509ReasonCode[] = { ID_CE_OID, 21 };
353
CONST_OID x509HoldInstructionCode[] = { ID_CE_OID, 23 };
354
CONST_OID x509InvalidDate[] = { ID_CE_OID, 24 };
355
CONST_OID x509DeltaCRLIndicator[] = { ID_CE_OID, 27 };
356
CONST_OID x509IssuingDistributionPoint[] = { ID_CE_OID, 28 };
357
CONST_OID x509CertIssuer[] = { ID_CE_OID, 29 };
358
CONST_OID x509NameConstraints[] = { ID_CE_OID, 30 };
359
CONST_OID x509CRLDistPoints[] = { ID_CE_OID, 31 };
360
CONST_OID x509CertificatePolicies[] = { ID_CE_OID, 32 };
361
CONST_OID x509PolicyMappings[] = { ID_CE_OID, 33 };
362
CONST_OID x509AuthKeyID[] = { ID_CE_OID, 35 };
363
CONST_OID x509PolicyConstraints[] = { ID_CE_OID, 36 };
364
CONST_OID x509ExtKeyUsage[] = { ID_CE_OID, 37 };
365
CONST_OID x509FreshestCRL[] = { ID_CE_OID, 46 };
366
CONST_OID x509InhibitAnyPolicy[] = { ID_CE_OID, 54 };
367
368
CONST_OID x509CertificatePoliciesAnyPolicy[] = { ID_CE_OID, 32, 0 };
369
CONST_OID x509ExtKeyUsageAnyUsage[] = { ID_CE_OID, 37, 0 };
370
371
CONST_OID x509AuthInfoAccess[] = { PKIX_CERT_EXTENSIONS, 1 };
372
CONST_OID x509SubjectInfoAccess[] = { PKIX_CERT_EXTENSIONS, 11 };
373
374
CONST_OID x509SIATimeStamping[] = { PKIX_ACCESS_DESCRIPTION, 0x03 };
375
CONST_OID x509SIACaRepository[] = { PKIX_ACCESS_DESCRIPTION, 0x05 };
376
377
/* pkcs 12 additions */
378
CONST_OID pkcs12[] = { PKCS12 };
379
CONST_OID pkcs12ModeIDs[] = { PKCS12_MODE_IDS };
380
CONST_OID pkcs12ESPVKIDs[] = { PKCS12_ESPVK_IDS };
381
CONST_OID pkcs12BagIDs[] = { PKCS12_BAG_IDS };
382
CONST_OID pkcs12CertBagIDs[] = { PKCS12_CERT_BAG_IDS };
383
CONST_OID pkcs12OIDs[] = { PKCS12_OIDS };
384
CONST_OID pkcs12PBEIDs[] = { PKCS12_PBE_IDS };
385
CONST_OID pkcs12EnvelopingIDs[] = { PKCS12_ENVELOPING_IDS };
386
CONST_OID pkcs12SignatureIDs[] = { PKCS12_SIGNATURE_IDS };
387
CONST_OID pkcs12PKCS8KeyShrouding[] = { PKCS12_ESPVK_IDS, 0x01 };
388
CONST_OID pkcs12KeyBagID[] = { PKCS12_BAG_IDS, 0x01 };
389
CONST_OID pkcs12CertAndCRLBagID[] = { PKCS12_BAG_IDS, 0x02 };
390
CONST_OID pkcs12SecretBagID[] = { PKCS12_BAG_IDS, 0x03 };
391
CONST_OID pkcs12X509CertCRLBag[] = { PKCS12_CERT_BAG_IDS, 0x01 };
392
CONST_OID pkcs12SDSICertBag[] = { PKCS12_CERT_BAG_IDS, 0x02 };
393
CONST_OID pkcs12PBEWithSha1And128BitRC4[] = { PKCS12_PBE_IDS, 0x01 };
394
CONST_OID pkcs12PBEWithSha1And40BitRC4[] = { PKCS12_PBE_IDS, 0x02 };
395
CONST_OID pkcs12PBEWithSha1AndTripleDESCBC[] = { PKCS12_PBE_IDS, 0x03 };
396
CONST_OID pkcs12PBEWithSha1And128BitRC2CBC[] = { PKCS12_PBE_IDS, 0x04 };
397
CONST_OID pkcs12PBEWithSha1And40BitRC2CBC[] = { PKCS12_PBE_IDS, 0x05 };
398
CONST_OID pkcs12RSAEncryptionWith128BitRC4[] = { PKCS12_ENVELOPING_IDS, 0x01 };
399
CONST_OID pkcs12RSAEncryptionWith40BitRC4[] = { PKCS12_ENVELOPING_IDS, 0x02 };
400
CONST_OID pkcs12RSAEncryptionWithTripleDES[] = { PKCS12_ENVELOPING_IDS, 0x03 };
401
CONST_OID pkcs12RSASignatureWithSHA1Digest[] = { PKCS12_SIGNATURE_IDS, 0x01 };
402
403
/* pkcs 12 version 1.0 ids */
404
CONST_OID pkcs12V2PBEWithSha1And128BitRC4[] = { PKCS12_V2_PBE_IDS, 0x01 };
405
CONST_OID pkcs12V2PBEWithSha1And40BitRC4[] = { PKCS12_V2_PBE_IDS, 0x02 };
406
CONST_OID pkcs12V2PBEWithSha1And3KeyTripleDEScbc[] = { PKCS12_V2_PBE_IDS, 0x03 };
407
CONST_OID pkcs12V2PBEWithSha1And2KeyTripleDEScbc[] = { PKCS12_V2_PBE_IDS, 0x04 };
408
CONST_OID pkcs12V2PBEWithSha1And128BitRC2cbc[] = { PKCS12_V2_PBE_IDS, 0x05 };
409
CONST_OID pkcs12V2PBEWithSha1And40BitRC2cbc[] = { PKCS12_V2_PBE_IDS, 0x06 };
410
411
CONST_OID pkcs12SafeContentsID[] = { PKCS12_BAG_IDS, 0x04 };
412
CONST_OID pkcs12PKCS8ShroudedKeyBagID[] = { PKCS12_BAG_IDS, 0x05 };
413
414
CONST_OID pkcs12V1KeyBag[] = { PKCS12_V1_BAG_IDS, 0x01 };
415
CONST_OID pkcs12V1PKCS8ShroudedKeyBag[] = { PKCS12_V1_BAG_IDS, 0x02 };
416
CONST_OID pkcs12V1CertBag[] = { PKCS12_V1_BAG_IDS, 0x03 };
417
CONST_OID pkcs12V1CRLBag[] = { PKCS12_V1_BAG_IDS, 0x04 };
418
CONST_OID pkcs12V1SecretBag[] = { PKCS12_V1_BAG_IDS, 0x05 };
419
CONST_OID pkcs12V1SafeContentsBag[] = { PKCS12_V1_BAG_IDS, 0x06 };
420
421
/* The following encoding is INCORRECT, but correcting it would create a
422
 * duplicate OID in the table.  So, we will leave it alone.
423
 */
424
CONST_OID pkcs12KeyUsageAttr[] = { 2, 5, 29, 15 };
425
426
CONST_OID ansix9DSASignature[] = { ANSI_X9_ALGORITHM, 0x01 };
427
CONST_OID ansix9DSASignaturewithSHA1Digest[] = { ANSI_X9_ALGORITHM, 0x03 };
428
CONST_OID nistDSASignaturewithSHA224Digest[] = { DSA2, 0x01 };
429
CONST_OID nistDSASignaturewithSHA256Digest[] = { DSA2, 0x02 };
430
431
/* verisign OIDs */
432
CONST_OID verisignUserNotices[] = { VERISIGN, 1, 7, 1, 1 };
433
434
/* pkix OIDs */
435
CONST_OID pkixCPSPointerQualifier[] = { PKIX_POLICY_QUALIFIERS, 1 };
436
CONST_OID pkixUserNoticeQualifier[] = { PKIX_POLICY_QUALIFIERS, 2 };
437
438
CONST_OID pkixOCSP[] = { PKIX_OCSP };
439
CONST_OID pkixOCSPBasicResponse[] = { PKIX_OCSP, 1 };
440
CONST_OID pkixOCSPNonce[] = { PKIX_OCSP, 2 };
441
CONST_OID pkixOCSPCRL[] = { PKIX_OCSP, 3 };
442
CONST_OID pkixOCSPResponse[] = { PKIX_OCSP, 4 };
443
CONST_OID pkixOCSPNoCheck[] = { PKIX_OCSP, 5 };
444
CONST_OID pkixOCSPArchiveCutoff[] = { PKIX_OCSP, 6 };
445
CONST_OID pkixOCSPServiceLocator[] = { PKIX_OCSP, 7 };
446
447
CONST_OID pkixCAIssuers[] = { PKIX_CA_ISSUERS };
448
449
CONST_OID pkixRegCtrlRegToken[] = { PKIX_ID_REGCTRL, 1 };
450
CONST_OID pkixRegCtrlAuthenticator[] = { PKIX_ID_REGCTRL, 2 };
451
CONST_OID pkixRegCtrlPKIPubInfo[] = { PKIX_ID_REGCTRL, 3 };
452
CONST_OID pkixRegCtrlPKIArchOptions[] = { PKIX_ID_REGCTRL, 4 };
453
CONST_OID pkixRegCtrlOldCertID[] = { PKIX_ID_REGCTRL, 5 };
454
CONST_OID pkixRegCtrlProtEncKey[] = { PKIX_ID_REGCTRL, 6 };
455
CONST_OID pkixRegInfoUTF8Pairs[] = { PKIX_ID_REGINFO, 1 };
456
CONST_OID pkixRegInfoCertReq[] = { PKIX_ID_REGINFO, 2 };
457
458
CONST_OID pkixExtendedKeyUsageServerAuth[] = { PKIX_KEY_USAGE, 1 };
459
CONST_OID pkixExtendedKeyUsageClientAuth[] = { PKIX_KEY_USAGE, 2 };
460
CONST_OID pkixExtendedKeyUsageCodeSign[] = { PKIX_KEY_USAGE, 3 };
461
CONST_OID pkixExtendedKeyUsageEMailProtect[] = { PKIX_KEY_USAGE, 4 };
462
/* IPsecEnd, IPsecTunnel, and IPsecUser are deprecated, but still in use
463
 * (see RFC4945) */
464
CONST_OID pkixExtendedKeyUsageIPsecEnd[] = { PKIX_KEY_USAGE, 5 };
465
CONST_OID pkixExtendedKeyUsageIPsecTunnel[] = { PKIX_KEY_USAGE, 6 };
466
CONST_OID pkixExtendedKeyUsageIPsecUser[] = { PKIX_KEY_USAGE, 7 };
467
CONST_OID pkixExtendedKeyUsageTimeStamp[] = { PKIX_KEY_USAGE, 8 };
468
CONST_OID pkixOCSPResponderExtendedKeyUsage[] = { PKIX_KEY_USAGE, 9 };
469
/* 17 replaces 5 + 6 + 7 (declared obsolete in RFC 4945) */
470
CONST_OID pkixExtendedKeyUsageIPsecIKE[] = { PKIX_KEY_USAGE, 17 };
471
CONST_OID msExtendedKeyUsageTrustListSigning[] = { MS_CRYPTO_EKU, 1 };
472
473
CONST_OID ipsecIKEEnd[] = { INTERNET_SECURITY_MECH, 0x08, 0x02, 0x01 };
474
CONST_OID ipsecIKEIntermediate[] = { INTERNET_SECURITY_MECH, 0x08, 0x02, 0x02 };
475
476
/* OIDs for Netscape defined algorithms */
477
CONST_OID netscapeSMimeKEA[] = { NETSCAPE_ALGS, 0x01 };
478
479
/* Fortezza algorithm OIDs */
480
CONST_OID skipjackCBC[] = { MISSI, 0x04 };
481
CONST_OID dhPublicKey[] = { ANSI_X942_ALGORITHM, 0x1 };
482
483
CONST_OID idea_CBC[] = { ASCOM_IDEA_ALG, 2 };
484
CONST_OID aes128_GCM[] = { AES, 0x6 };
485
CONST_OID aes192_GCM[] = { AES, 0x1a };
486
CONST_OID aes256_GCM[] = { AES, 0x2e };
487
CONST_OID aes128_ECB[] = { AES, 1 };
488
CONST_OID aes128_CBC[] = { AES, 2 };
489
#ifdef DEFINE_ALL_AES_CIPHERS
490
CONST_OID aes128_OFB[] = { AES, 3 };
491
CONST_OID aes128_CFB[] = { AES, 4 };
492
#endif
493
CONST_OID aes128_KEY_WRAP[] = { AES, 5 };
494
495
CONST_OID aes192_ECB[] = { AES, 21 };
496
CONST_OID aes192_CBC[] = { AES, 22 };
497
#ifdef DEFINE_ALL_AES_CIPHERS
498
CONST_OID aes192_OFB[] = { AES, 23 };
499
CONST_OID aes192_CFB[] = { AES, 24 };
500
#endif
501
CONST_OID aes192_KEY_WRAP[] = { AES, 25 };
502
503
CONST_OID aes256_ECB[] = { AES, 41 };
504
CONST_OID aes256_CBC[] = { AES, 42 };
505
#ifdef DEFINE_ALL_AES_CIPHERS
506
CONST_OID aes256_OFB[] = { AES, 43 };
507
CONST_OID aes256_CFB[] = { AES, 44 };
508
#endif
509
CONST_OID aes256_KEY_WRAP[] = { AES, 45 };
510
511
CONST_OID camellia128_CBC[] = { CAMELLIA_ENCRYPT_OID, 2 };
512
CONST_OID camellia192_CBC[] = { CAMELLIA_ENCRYPT_OID, 3 };
513
CONST_OID camellia256_CBC[] = { CAMELLIA_ENCRYPT_OID, 4 };
514
515
CONST_OID sha256[] = { SHAXXX, 1 };
516
CONST_OID sha384[] = { SHAXXX, 2 };
517
CONST_OID sha512[] = { SHAXXX, 3 };
518
CONST_OID sha224[] = { SHAXXX, 4 };
519
520
CONST_OID sha3_224[] = { SHAXXX, 7 };
521
CONST_OID sha3_256[] = { SHAXXX, 8 };
522
CONST_OID sha3_384[] = { SHAXXX, 9 };
523
CONST_OID sha3_512[] = { SHAXXX, 10 };
524
525
CONST_OID hmac_sha3_224[] = { SHAXXX, 13 };
526
CONST_OID hmac_sha3_256[] = { SHAXXX, 14 };
527
CONST_OID hmac_sha3_384[] = { SHAXXX, 15 };
528
CONST_OID hmac_sha3_512[] = { SHAXXX, 16 };
529
530
CONST_OID ansix962ECPublicKey[] = { ANSI_X962_OID, 0x02, 0x01 };
531
CONST_OID ansix962SignaturewithSHA1Digest[] = { ANSI_X962_SIGNATURE_OID, 0x01 };
532
CONST_OID ansix962SignatureRecommended[] = { ANSI_X962_SIGNATURE_OID, 0x02 };
533
CONST_OID ansix962SignatureSpecified[] = { ANSI_X962_SPECIFY_OID };
534
CONST_OID ansix962SignaturewithSHA224Digest[] = { ANSI_X962_SPECIFY_OID, 0x01 };
535
CONST_OID ansix962SignaturewithSHA256Digest[] = { ANSI_X962_SPECIFY_OID, 0x02 };
536
CONST_OID ansix962SignaturewithSHA384Digest[] = { ANSI_X962_SPECIFY_OID, 0x03 };
537
CONST_OID ansix962SignaturewithSHA512Digest[] = { ANSI_X962_SPECIFY_OID, 0x04 };
538
539
/* ANSI X9.62 prime curve OIDs */
540
/* NOTE: prime192v1 is the same as secp192r1, prime256v1 is the
541
 * same as secp256r1
542
 */
543
CONST_OID ansiX962prime192v1[] = { ANSI_X962_GFp_OID, 0x01 }; /* unsupported by freebl */
544
CONST_OID ansiX962prime192v2[] = { ANSI_X962_GFp_OID, 0x02 }; /* unsupported by freebl */
545
CONST_OID ansiX962prime192v3[] = { ANSI_X962_GFp_OID, 0x03 }; /* unsupported by freebl */
546
CONST_OID ansiX962prime239v1[] = { ANSI_X962_GFp_OID, 0x04 }; /* unsupported by freebl */
547
CONST_OID ansiX962prime239v2[] = { ANSI_X962_GFp_OID, 0x05 }; /* unsupported by freebl */
548
CONST_OID ansiX962prime239v3[] = { ANSI_X962_GFp_OID, 0x06 }; /* unsupported by freebl */
549
CONST_OID ansiX962prime256v1[] = { ANSI_X962_GFp_OID, 0x07 };
550
551
/* SECG prime curve OIDs */
552
CONST_OID secgECsecp112r1[] = { SECG_OID, 0x06 }; /* unsupported by freebl */
553
CONST_OID secgECsecp112r2[] = { SECG_OID, 0x07 }; /* unsupported by freebl */
554
CONST_OID secgECsecp128r1[] = { SECG_OID, 0x1c }; /* unsupported by freebl */
555
CONST_OID secgECsecp128r2[] = { SECG_OID, 0x1d }; /* unsupported by freebl */
556
CONST_OID secgECsecp160k1[] = { SECG_OID, 0x09 }; /* unsupported by freebl */
557
CONST_OID secgECsecp160r1[] = { SECG_OID, 0x08 }; /* unsupported by freebl */
558
CONST_OID secgECsecp160r2[] = { SECG_OID, 0x1e }; /* unsupported by freebl */
559
CONST_OID secgECsecp192k1[] = { SECG_OID, 0x1f }; /* unsupported by freebl */
560
CONST_OID secgECsecp224k1[] = { SECG_OID, 0x20 }; /* unsupported by freebl */
561
CONST_OID secgECsecp224r1[] = { SECG_OID, 0x21 }; /* unsupported by freebl */
562
CONST_OID secgECsecp256k1[] = { SECG_OID, 0x0a }; /* unsupported by freebl */
563
CONST_OID secgECsecp384r1[] = { SECG_OID, 0x22 };
564
CONST_OID secgECsecp521r1[] = { SECG_OID, 0x23 };
565
566
/* ANSI X9.62 characteristic two curve OIDs */
567
CONST_OID ansiX962c2pnb163v1[] = { ANSI_X962_GF2m_OID, 0x01 }; /* unsupported by freebl */
568
CONST_OID ansiX962c2pnb163v2[] = { ANSI_X962_GF2m_OID, 0x02 }; /* unsupported by freebl */
569
CONST_OID ansiX962c2pnb163v3[] = { ANSI_X962_GF2m_OID, 0x03 }; /* unsupported by freebl */
570
CONST_OID ansiX962c2pnb176v1[] = { ANSI_X962_GF2m_OID, 0x04 }; /* unsupported by freebl */
571
CONST_OID ansiX962c2tnb191v1[] = { ANSI_X962_GF2m_OID, 0x05 }; /* unsupported by freebl */
572
CONST_OID ansiX962c2tnb191v2[] = { ANSI_X962_GF2m_OID, 0x06 }; /* unsupported by freebl */
573
CONST_OID ansiX962c2tnb191v3[] = { ANSI_X962_GF2m_OID, 0x07 }; /* unsupported by freebl */
574
CONST_OID ansiX962c2onb191v4[] = { ANSI_X962_GF2m_OID, 0x08 }; /* unsupported by freebl */
575
CONST_OID ansiX962c2onb191v5[] = { ANSI_X962_GF2m_OID, 0x09 }; /* unsupported by freebl */
576
CONST_OID ansiX962c2pnb208w1[] = { ANSI_X962_GF2m_OID, 0x0a }; /* unsupported by freebl */
577
CONST_OID ansiX962c2tnb239v1[] = { ANSI_X962_GF2m_OID, 0x0b }; /* unsupported by freebl */
578
CONST_OID ansiX962c2tnb239v2[] = { ANSI_X962_GF2m_OID, 0x0c }; /* unsupported by freebl */
579
CONST_OID ansiX962c2tnb239v3[] = { ANSI_X962_GF2m_OID, 0x0d }; /* unsupported by freebl */
580
CONST_OID ansiX962c2onb239v4[] = { ANSI_X962_GF2m_OID, 0x0e }; /* unsupported by freebl */
581
CONST_OID ansiX962c2onb239v5[] = { ANSI_X962_GF2m_OID, 0x0f }; /* unsupported by freebl */
582
CONST_OID ansiX962c2pnb272w1[] = { ANSI_X962_GF2m_OID, 0x10 }; /* unsupported by freebl */
583
CONST_OID ansiX962c2pnb304w1[] = { ANSI_X962_GF2m_OID, 0x11 }; /* unsupported by freebl */
584
CONST_OID ansiX962c2tnb359v1[] = { ANSI_X962_GF2m_OID, 0x12 }; /* unsupported by freebl */
585
CONST_OID ansiX962c2pnb368w1[] = { ANSI_X962_GF2m_OID, 0x13 }; /* unsupported by freebl */
586
CONST_OID ansiX962c2tnb431r1[] = { ANSI_X962_GF2m_OID, 0x14 }; /* unsupported by freebl */
587
588
/* SECG characterisitic two curve OIDs */
589
CONST_OID secgECsect113r1[] = { SECG_OID, 0x04 }; /* unsupported by freebl */
590
CONST_OID secgECsect113r2[] = { SECG_OID, 0x05 }; /* unsupported by freebl */
591
CONST_OID secgECsect131r1[] = { SECG_OID, 0x16 }; /* unsupported by freebl */
592
CONST_OID secgECsect131r2[] = { SECG_OID, 0x17 }; /* unsupported by freebl */
593
CONST_OID secgECsect163k1[] = { SECG_OID, 0x01 }; /* unsupported by freebl */
594
CONST_OID secgECsect163r1[] = { SECG_OID, 0x02 }; /* unsupported by freebl */
595
CONST_OID secgECsect163r2[] = { SECG_OID, 0x0f }; /* unsupported by freebl */
596
CONST_OID secgECsect193r1[] = { SECG_OID, 0x18 }; /* unsupported by freebl */
597
CONST_OID secgECsect193r2[] = { SECG_OID, 0x19 }; /* unsupported by freebl */
598
CONST_OID secgECsect233k1[] = { SECG_OID, 0x1a }; /* unsupported by freebl */
599
CONST_OID secgECsect233r1[] = { SECG_OID, 0x1b }; /* unsupported by freebl */
600
CONST_OID secgECsect239k1[] = { SECG_OID, 0x03 }; /* unsupported by freebl */
601
CONST_OID secgECsect283k1[] = { SECG_OID, 0x10 }; /* unsupported by freebl */
602
CONST_OID secgECsect283r1[] = { SECG_OID, 0x11 }; /* unsupported by freebl */
603
CONST_OID secgECsect409k1[] = { SECG_OID, 0x24 }; /* unsupported by freebl */
604
CONST_OID secgECsect409r1[] = { SECG_OID, 0x25 }; /* unsupported by freebl */
605
CONST_OID secgECsect571k1[] = { SECG_OID, 0x26 }; /* unsupported by freebl */
606
CONST_OID secgECsect571r1[] = { SECG_OID, 0x27 }; /* unsupported by freebl */
607
608
/* Diffie-Hellman key agreement algorithms */
609
CONST_OID dhSinglePassstdDHsha1kdfscheme[] = { X9_63_SCHEME, 0x02 };
610
CONST_OID dhSinglePassstdDHsha224kdfscheme[] = { SECG_SCHEME, 0x0B, 0x00 };
611
CONST_OID dhSinglePassstdDHsha256kdfscheme[] = { SECG_SCHEME, 0x0B, 0x01 };
612
CONST_OID dhSinglePassstdDHsha384kdfscheme[] = { SECG_SCHEME, 0x0B, 0x02 };
613
CONST_OID dhSinglePassstdDHsha512kdfscheme[] = { SECG_SCHEME, 0x0B, 0x03 };
614
CONST_OID dhSinglePasscofactorDHsha1kdfscheme[] = { X9_63_SCHEME, 0x03 };
615
CONST_OID dhSinglePasscofactorDHsha224kdfscheme[] = { SECG_SCHEME, 0x0E, 0x00 };
616
CONST_OID dhSinglePasscofactorDHsha256kdfscheme[] = { SECG_SCHEME, 0x0E, 0x01 };
617
CONST_OID dhSinglePasscofactorDHsha384kdfscheme[] = { SECG_SCHEME, 0x0E, 0x02 };
618
CONST_OID dhSinglePasscofactorDHsha512kdfscheme[] = { SECG_SCHEME, 0x0E, 0x03 };
619
620
CONST_OID seed_CBC[] = { SEED_OID, 4 };
621
622
CONST_OID evIncorporationLocality[] = { EV_NAME_ATTRIBUTE, 1 };
623
CONST_OID evIncorporationState[] = { EV_NAME_ATTRIBUTE, 2 };
624
CONST_OID evIncorporationCountry[] = { EV_NAME_ATTRIBUTE, 3 };
625
626
/* https://tools.ietf.org/html/draft-josefsson-pkix-newcurves-01
627
 * 1.3.6.1.4.1.11591.15.1
628
 */
629
CONST_OID curve25519[] = { 0x2B, 0x06, 0x01, 0x04, 0x01, 0xDA, 0x47, 0x0F, 0x01 };
630
631
/*
632
  https://oid-rep.orange-labs.fr/get/1.3.101.112
633
  A.1.  ASN.1 Object for Ed25519
634
  id-Ed25519 OBJECT IDENTIFIER ::= { 1.3.101.112 }
635
  Parameters are absent.  Length is 7 bytes.
636
  Binary encoding: 3005 0603 2B65 70
637
  
638
  The same algorithm identifiers are used for identifying a public key,
639
  a private key, and a signature (for the two EdDSA related OIDs).
640
  Additional encoding information is provided below for each of these
641
  locations.
642
*/
643
644
CONST_OID ed25519PublicKey[] = { 0x2B, 0x65, 0x70 };
645
CONST_OID ed25519Signature[] = { 0x2B, 0x65, 0x70 };
646
647
#define OI(x)                                  \
648
    {                                          \
649
        siDEROID, (unsigned char *)x, sizeof x \
650
    }
651
#ifndef SECOID_NO_STRINGS
652
#define OD(oid, tag, desc, mech, ext) \
653
    {                                 \
654
        OI(oid)                       \
655
        , tag, desc, mech, ext        \
656
    }
657
#define ODE(tag, desc, mech, ext)                   \
658
    {                                               \
659
        { siDEROID, NULL, 0 }, tag, desc, mech, ext \
660
    }
661
#else
662
#define OD(oid, tag, desc, mech, ext) \
663
    {                                 \
664
        OI(oid)                       \
665
        , tag, 0, mech, ext           \
666
    }
667
#define ODE(tag, desc, mech, ext)                \
668
    {                                            \
669
        { siDEROID, NULL, 0 }, tag, 0, mech, ext \
670
    }
671
#endif
672
673
#if defined(NSS_ALLOW_UNSUPPORTED_CRITICAL)
674
#define FAKE_SUPPORTED_CERT_EXTENSION SUPPORTED_CERT_EXTENSION
675
#else
676
#define FAKE_SUPPORTED_CERT_EXTENSION UNSUPPORTED_CERT_EXTENSION
677
#endif
678
679
/*
680
 * NOTE: the order of these entries must mach the SECOidTag enum in secoidt.h!
681
 */
682
const static SECOidData oids[SEC_OID_TOTAL] = {
683
    { { siDEROID, NULL, 0 }, SEC_OID_UNKNOWN, "Unknown OID", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION },
684
    OD(md2, SEC_OID_MD2, "MD2", CKM_MD2, INVALID_CERT_EXTENSION),
685
    OD(md4, SEC_OID_MD4,
686
       "MD4", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
687
    OD(md5, SEC_OID_MD5, "MD5", CKM_MD5, INVALID_CERT_EXTENSION),
688
    OD(sha1, SEC_OID_SHA1, "SHA-1", CKM_SHA_1, INVALID_CERT_EXTENSION),
689
    OD(rc2cbc, SEC_OID_RC2_CBC,
690
       "RC2-CBC", CKM_RC2_CBC, INVALID_CERT_EXTENSION),
691
    OD(rc4, SEC_OID_RC4, "RC4", CKM_RC4, INVALID_CERT_EXTENSION),
692
    OD(desede3cbc, SEC_OID_DES_EDE3_CBC,
693
       "DES-EDE3-CBC", CKM_DES3_CBC, INVALID_CERT_EXTENSION),
694
    OD(rc5cbcpad, SEC_OID_RC5_CBC_PAD,
695
       "RC5-CBCPad", CKM_RC5_CBC, INVALID_CERT_EXTENSION),
696
    OD(desecb, SEC_OID_DES_ECB,
697
       "DES-ECB", CKM_DES_ECB, INVALID_CERT_EXTENSION),
698
    OD(descbc, SEC_OID_DES_CBC,
699
       "DES-CBC", CKM_DES_CBC, INVALID_CERT_EXTENSION),
700
    OD(desofb, SEC_OID_DES_OFB,
701
       "DES-OFB", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
702
    OD(descfb, SEC_OID_DES_CFB,
703
       "DES-CFB", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
704
    OD(desmac, SEC_OID_DES_MAC,
705
       "DES-MAC", CKM_DES_MAC, INVALID_CERT_EXTENSION),
706
    OD(desede, SEC_OID_DES_EDE,
707
       "DES-EDE", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
708
    OD(isoSHAWithRSASignature, SEC_OID_ISO_SHA_WITH_RSA_SIGNATURE,
709
       "ISO SHA with RSA Signature",
710
       CKM_SHA1_RSA_PKCS, INVALID_CERT_EXTENSION),
711
    OD(pkcs1RSAEncryption, SEC_OID_PKCS1_RSA_ENCRYPTION,
712
       "PKCS #1 RSA Encryption", CKM_RSA_PKCS, INVALID_CERT_EXTENSION),
713
714
    /* the following Signing mechanisms should get new CKM_ values when
715
     * values for CKM_RSA_WITH_MDX and CKM_RSA_WITH_SHA_1 get defined in
716
     * PKCS #11.
717
     */
718
    OD(pkcs1MD2WithRSAEncryption, SEC_OID_PKCS1_MD2_WITH_RSA_ENCRYPTION,
719
       "PKCS #1 MD2 With RSA Encryption", CKM_MD2_RSA_PKCS,
720
       INVALID_CERT_EXTENSION),
721
    OD(pkcs1MD4WithRSAEncryption, SEC_OID_PKCS1_MD4_WITH_RSA_ENCRYPTION,
722
       "PKCS #1 MD4 With RSA Encryption",
723
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
724
    OD(pkcs1MD5WithRSAEncryption, SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION,
725
       "PKCS #1 MD5 With RSA Encryption", CKM_MD5_RSA_PKCS,
726
       INVALID_CERT_EXTENSION),
727
    OD(pkcs1SHA1WithRSAEncryption, SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION,
728
       "PKCS #1 SHA-1 With RSA Encryption", CKM_SHA1_RSA_PKCS,
729
       INVALID_CERT_EXTENSION),
730
731
    OD(pkcs5PbeWithMD2AndDEScbc, SEC_OID_PKCS5_PBE_WITH_MD2_AND_DES_CBC,
732
       "PKCS #5 Password Based Encryption with MD2 and DES-CBC",
733
       CKM_PBE_MD2_DES_CBC, INVALID_CERT_EXTENSION),
734
    OD(pkcs5PbeWithMD5AndDEScbc, SEC_OID_PKCS5_PBE_WITH_MD5_AND_DES_CBC,
735
       "PKCS #5 Password Based Encryption with MD5 and DES-CBC",
736
       CKM_PBE_MD5_DES_CBC, INVALID_CERT_EXTENSION),
737
    OD(pkcs5PbeWithSha1AndDEScbc, SEC_OID_PKCS5_PBE_WITH_SHA1_AND_DES_CBC,
738
       "PKCS #5 Password Based Encryption with SHA-1 and DES-CBC",
739
       CKM_NSS_PBE_SHA1_DES_CBC, INVALID_CERT_EXTENSION),
740
    OD(pkcs7, SEC_OID_PKCS7,
741
       "PKCS #7", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
742
    OD(pkcs7Data, SEC_OID_PKCS7_DATA,
743
       "PKCS #7 Data", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
744
    OD(pkcs7SignedData, SEC_OID_PKCS7_SIGNED_DATA,
745
       "PKCS #7 Signed Data", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
746
    OD(pkcs7EnvelopedData, SEC_OID_PKCS7_ENVELOPED_DATA,
747
       "PKCS #7 Enveloped Data",
748
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
749
    OD(pkcs7SignedEnvelopedData, SEC_OID_PKCS7_SIGNED_ENVELOPED_DATA,
750
       "PKCS #7 Signed And Enveloped Data",
751
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
752
    OD(pkcs7DigestedData, SEC_OID_PKCS7_DIGESTED_DATA,
753
       "PKCS #7 Digested Data",
754
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
755
    OD(pkcs7EncryptedData, SEC_OID_PKCS7_ENCRYPTED_DATA,
756
       "PKCS #7 Encrypted Data",
757
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
758
    OD(pkcs9EmailAddress, SEC_OID_PKCS9_EMAIL_ADDRESS,
759
       "PKCS #9 Email Address",
760
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
761
    OD(pkcs9UnstructuredName, SEC_OID_PKCS9_UNSTRUCTURED_NAME,
762
       "PKCS #9 Unstructured Name",
763
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
764
    OD(pkcs9ContentType, SEC_OID_PKCS9_CONTENT_TYPE,
765
       "PKCS #9 Content Type",
766
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
767
    OD(pkcs9MessageDigest, SEC_OID_PKCS9_MESSAGE_DIGEST,
768
       "PKCS #9 Message Digest",
769
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
770
    OD(pkcs9SigningTime, SEC_OID_PKCS9_SIGNING_TIME,
771
       "PKCS #9 Signing Time",
772
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
773
    OD(pkcs9CounterSignature, SEC_OID_PKCS9_COUNTER_SIGNATURE,
774
       "PKCS #9 Counter Signature",
775
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
776
    OD(pkcs9ChallengePassword, SEC_OID_PKCS9_CHALLENGE_PASSWORD,
777
       "PKCS #9 Challenge Password",
778
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
779
    OD(pkcs9UnstructuredAddress, SEC_OID_PKCS9_UNSTRUCTURED_ADDRESS,
780
       "PKCS #9 Unstructured Address",
781
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
782
    OD(pkcs9ExtendedCertificateAttributes,
783
       SEC_OID_PKCS9_EXTENDED_CERTIFICATE_ATTRIBUTES,
784
       "PKCS #9 Extended Certificate Attributes",
785
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
786
    OD(pkcs9SMIMECapabilities, SEC_OID_PKCS9_SMIME_CAPABILITIES,
787
       "PKCS #9 S/MIME Capabilities",
788
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
789
    OD(x520CommonName, SEC_OID_AVA_COMMON_NAME,
790
       "X520 Common Name", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
791
    OD(x520CountryName, SEC_OID_AVA_COUNTRY_NAME,
792
       "X520 Country Name", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
793
    OD(x520LocalityName, SEC_OID_AVA_LOCALITY,
794
       "X520 Locality Name", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
795
    OD(x520StateOrProvinceName, SEC_OID_AVA_STATE_OR_PROVINCE,
796
       "X520 State Or Province Name",
797
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
798
    OD(x520OrgName, SEC_OID_AVA_ORGANIZATION_NAME,
799
       "X520 Organization Name",
800
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
801
    OD(x520OrgUnitName, SEC_OID_AVA_ORGANIZATIONAL_UNIT_NAME,
802
       "X520 Organizational Unit Name",
803
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
804
    OD(x520DnQualifier, SEC_OID_AVA_DN_QUALIFIER,
805
       "X520 DN Qualifier", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
806
    OD(rfc2247DomainComponent, SEC_OID_AVA_DC,
807
       "RFC 2247 Domain Component",
808
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
809
810
    OD(nsTypeGIF, SEC_OID_NS_TYPE_GIF,
811
       "GIF", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
812
    OD(nsTypeJPEG, SEC_OID_NS_TYPE_JPEG,
813
       "JPEG", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
814
    OD(nsTypeURL, SEC_OID_NS_TYPE_URL,
815
       "URL", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
816
    OD(nsTypeHTML, SEC_OID_NS_TYPE_HTML,
817
       "HTML", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
818
    OD(nsTypeCertSeq, SEC_OID_NS_TYPE_CERT_SEQUENCE,
819
       "Certificate Sequence",
820
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
821
    OD(missiCertKEADSSOld, SEC_OID_MISSI_KEA_DSS_OLD,
822
       "MISSI KEA and DSS Algorithm (Old)",
823
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
824
    OD(missiCertDSSOld, SEC_OID_MISSI_DSS_OLD,
825
       "MISSI DSS Algorithm (Old)",
826
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
827
    OD(missiCertKEADSS, SEC_OID_MISSI_KEA_DSS,
828
       "MISSI KEA and DSS Algorithm",
829
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
830
    OD(missiCertDSS, SEC_OID_MISSI_DSS,
831
       "MISSI DSS Algorithm",
832
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
833
    OD(missiCertKEA, SEC_OID_MISSI_KEA,
834
       "MISSI KEA Algorithm",
835
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
836
    OD(missiCertAltKEA, SEC_OID_MISSI_ALT_KEA,
837
       "MISSI Alternate KEA Algorithm",
838
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
839
840
    /* Netscape private extensions */
841
    OD(nsCertExtNetscapeOK, SEC_OID_NS_CERT_EXT_NETSCAPE_OK,
842
       "Netscape says this cert is OK",
843
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
844
    OD(nsCertExtIssuerLogo, SEC_OID_NS_CERT_EXT_ISSUER_LOGO,
845
       "Certificate Issuer Logo",
846
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
847
    OD(nsCertExtSubjectLogo, SEC_OID_NS_CERT_EXT_SUBJECT_LOGO,
848
       "Certificate Subject Logo",
849
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
850
    OD(nsExtCertType, SEC_OID_NS_CERT_EXT_CERT_TYPE,
851
       "Certificate Type",
852
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
853
    OD(nsExtBaseURL, SEC_OID_NS_CERT_EXT_BASE_URL,
854
       "Certificate Extension Base URL",
855
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
856
    OD(nsExtRevocationURL, SEC_OID_NS_CERT_EXT_REVOCATION_URL,
857
       "Certificate Revocation URL",
858
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
859
    OD(nsExtCARevocationURL, SEC_OID_NS_CERT_EXT_CA_REVOCATION_URL,
860
       "Certificate Authority Revocation URL",
861
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
862
    OD(nsExtCACRLURL, SEC_OID_NS_CERT_EXT_CA_CRL_URL,
863
       "Certificate Authority CRL Download URL",
864
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
865
    OD(nsExtCACertURL, SEC_OID_NS_CERT_EXT_CA_CERT_URL,
866
       "Certificate Authority Certificate Download URL",
867
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
868
    OD(nsExtCertRenewalURL, SEC_OID_NS_CERT_EXT_CERT_RENEWAL_URL,
869
       "Certificate Renewal URL",
870
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
871
    OD(nsExtCAPolicyURL, SEC_OID_NS_CERT_EXT_CA_POLICY_URL,
872
       "Certificate Authority Policy URL",
873
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
874
    OD(nsExtHomepageURL, SEC_OID_NS_CERT_EXT_HOMEPAGE_URL,
875
       "Certificate Homepage URL",
876
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
877
    OD(nsExtEntityLogo, SEC_OID_NS_CERT_EXT_ENTITY_LOGO,
878
       "Certificate Entity Logo",
879
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
880
    OD(nsExtUserPicture, SEC_OID_NS_CERT_EXT_USER_PICTURE,
881
       "Certificate User Picture",
882
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
883
    OD(nsExtSSLServerName, SEC_OID_NS_CERT_EXT_SSL_SERVER_NAME,
884
       "Certificate SSL Server Name",
885
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
886
    OD(nsExtComment, SEC_OID_NS_CERT_EXT_COMMENT,
887
       "Certificate Comment",
888
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
889
    OD(nsExtLostPasswordURL, SEC_OID_NS_CERT_EXT_LOST_PASSWORD_URL,
890
       "Lost Password URL",
891
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
892
    OD(nsExtCertRenewalTime, SEC_OID_NS_CERT_EXT_CERT_RENEWAL_TIME,
893
       "Certificate Renewal Time",
894
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
895
    OD(nsKeyUsageGovtApproved, SEC_OID_NS_KEY_USAGE_GOVT_APPROVED,
896
       "Strong Crypto Export Approved",
897
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
898
899
    /* x.509 v3 certificate extensions */
900
    OD(x509SubjectDirectoryAttr, SEC_OID_X509_SUBJECT_DIRECTORY_ATTR,
901
       "Certificate Subject Directory Attributes",
902
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
903
    OD(x509SubjectKeyID, SEC_OID_X509_SUBJECT_KEY_ID,
904
       "Certificate Subject Key ID",
905
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
906
    OD(x509KeyUsage, SEC_OID_X509_KEY_USAGE,
907
       "Certificate Key Usage",
908
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
909
    OD(x509PrivateKeyUsagePeriod, SEC_OID_X509_PRIVATE_KEY_USAGE_PERIOD,
910
       "Certificate Private Key Usage Period",
911
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
912
    OD(x509SubjectAltName, SEC_OID_X509_SUBJECT_ALT_NAME,
913
       "Certificate Subject Alt Name",
914
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
915
    OD(x509IssuerAltName, SEC_OID_X509_ISSUER_ALT_NAME,
916
       "Certificate Issuer Alt Name",
917
       CKM_INVALID_MECHANISM, FAKE_SUPPORTED_CERT_EXTENSION),
918
    OD(x509BasicConstraints, SEC_OID_X509_BASIC_CONSTRAINTS,
919
       "Certificate Basic Constraints",
920
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
921
    OD(x509NameConstraints, SEC_OID_X509_NAME_CONSTRAINTS,
922
       "Certificate Name Constraints",
923
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
924
    OD(x509CRLDistPoints, SEC_OID_X509_CRL_DIST_POINTS,
925
       "CRL Distribution Points",
926
       CKM_INVALID_MECHANISM, FAKE_SUPPORTED_CERT_EXTENSION),
927
    OD(x509CertificatePolicies, SEC_OID_X509_CERTIFICATE_POLICIES,
928
       "Certificate Policies",
929
       CKM_INVALID_MECHANISM, FAKE_SUPPORTED_CERT_EXTENSION),
930
    OD(x509PolicyMappings, SEC_OID_X509_POLICY_MAPPINGS,
931
       "Certificate Policy Mappings",
932
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
933
    OD(x509PolicyConstraints, SEC_OID_X509_POLICY_CONSTRAINTS,
934
       "Certificate Policy Constraints",
935
       CKM_INVALID_MECHANISM, FAKE_SUPPORTED_CERT_EXTENSION),
936
    OD(x509AuthKeyID, SEC_OID_X509_AUTH_KEY_ID,
937
       "Certificate Authority Key Identifier",
938
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
939
    OD(x509ExtKeyUsage, SEC_OID_X509_EXT_KEY_USAGE,
940
       "Extended Key Usage",
941
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
942
    OD(x509AuthInfoAccess, SEC_OID_X509_AUTH_INFO_ACCESS,
943
       "Authority Information Access",
944
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
945
946
    /* x.509 v3 CRL extensions */
947
    OD(x509CRLNumber, SEC_OID_X509_CRL_NUMBER,
948
       "CRL Number", CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
949
    OD(x509ReasonCode, SEC_OID_X509_REASON_CODE,
950
       "CRL reason code", CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
951
    OD(x509InvalidDate, SEC_OID_X509_INVALID_DATE,
952
       "Invalid Date", CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
953
954
    OD(x500RSAEncryption, SEC_OID_X500_RSA_ENCRYPTION,
955
       "X500 RSA Encryption", CKM_RSA_X_509, INVALID_CERT_EXTENSION),
956
957
    /* added for alg 1485 */
958
    OD(rfc1274Uid, SEC_OID_RFC1274_UID,
959
       "RFC1274 User Id", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
960
    OD(rfc1274Mail, SEC_OID_RFC1274_MAIL,
961
       "RFC1274 E-mail Address",
962
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
963
964
    /* pkcs 12 additions */
965
    OD(pkcs12, SEC_OID_PKCS12,
966
       "PKCS #12", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
967
    OD(pkcs12ModeIDs, SEC_OID_PKCS12_MODE_IDS,
968
       "PKCS #12 Mode IDs", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
969
    OD(pkcs12ESPVKIDs, SEC_OID_PKCS12_ESPVK_IDS,
970
       "PKCS #12 ESPVK IDs", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
971
    OD(pkcs12BagIDs, SEC_OID_PKCS12_BAG_IDS,
972
       "PKCS #12 Bag IDs", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
973
    OD(pkcs12CertBagIDs, SEC_OID_PKCS12_CERT_BAG_IDS,
974
       "PKCS #12 Cert Bag IDs",
975
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
976
    OD(pkcs12OIDs, SEC_OID_PKCS12_OIDS,
977
       "PKCS #12 OIDs", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
978
    OD(pkcs12PBEIDs, SEC_OID_PKCS12_PBE_IDS,
979
       "PKCS #12 PBE IDs", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
980
    OD(pkcs12SignatureIDs, SEC_OID_PKCS12_SIGNATURE_IDS,
981
       "PKCS #12 Signature IDs",
982
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
983
    OD(pkcs12EnvelopingIDs, SEC_OID_PKCS12_ENVELOPING_IDS,
984
       "PKCS #12 Enveloping IDs",
985
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
986
    OD(pkcs12PKCS8KeyShrouding, SEC_OID_PKCS12_PKCS8_KEY_SHROUDING,
987
       "PKCS #12 Key Shrouding",
988
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
989
    OD(pkcs12KeyBagID, SEC_OID_PKCS12_KEY_BAG_ID,
990
       "PKCS #12 Key Bag ID",
991
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
992
    OD(pkcs12CertAndCRLBagID, SEC_OID_PKCS12_CERT_AND_CRL_BAG_ID,
993
       "PKCS #12 Cert And CRL Bag ID",
994
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
995
    OD(pkcs12SecretBagID, SEC_OID_PKCS12_SECRET_BAG_ID,
996
       "PKCS #12 Secret Bag ID",
997
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
998
    OD(pkcs12X509CertCRLBag, SEC_OID_PKCS12_X509_CERT_CRL_BAG,
999
       "PKCS #12 X509 Cert CRL Bag",
1000
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1001
    OD(pkcs12SDSICertBag, SEC_OID_PKCS12_SDSI_CERT_BAG,
1002
       "PKCS #12 SDSI Cert Bag",
1003
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1004
    OD(pkcs12PBEWithSha1And128BitRC4,
1005
       SEC_OID_PKCS12_PBE_WITH_SHA1_AND_128_BIT_RC4,
1006
       "PKCS #12 PBE With SHA-1 and 128 Bit RC4",
1007
       CKM_NSS_PBE_SHA1_128_BIT_RC4, INVALID_CERT_EXTENSION),
1008
    OD(pkcs12PBEWithSha1And40BitRC4,
1009
       SEC_OID_PKCS12_PBE_WITH_SHA1_AND_40_BIT_RC4,
1010
       "PKCS #12 PBE With SHA-1 and 40 Bit RC4",
1011
       CKM_NSS_PBE_SHA1_40_BIT_RC4, INVALID_CERT_EXTENSION),
1012
    OD(pkcs12PBEWithSha1AndTripleDESCBC,
1013
       SEC_OID_PKCS12_PBE_WITH_SHA1_AND_TRIPLE_DES_CBC,
1014
       "PKCS #12 PBE With SHA-1 and Triple DES-CBC",
1015
       CKM_NSS_PBE_SHA1_TRIPLE_DES_CBC, INVALID_CERT_EXTENSION),
1016
    OD(pkcs12PBEWithSha1And128BitRC2CBC,
1017
       SEC_OID_PKCS12_PBE_WITH_SHA1_AND_128_BIT_RC2_CBC,
1018
       "PKCS #12 PBE With SHA-1 and 128 Bit RC2 CBC",
1019
       CKM_NSS_PBE_SHA1_128_BIT_RC2_CBC, INVALID_CERT_EXTENSION),
1020
    OD(pkcs12PBEWithSha1And40BitRC2CBC,
1021
       SEC_OID_PKCS12_PBE_WITH_SHA1_AND_40_BIT_RC2_CBC,
1022
       "PKCS #12 PBE With SHA-1 and 40 Bit RC2 CBC",
1023
       CKM_NSS_PBE_SHA1_40_BIT_RC2_CBC, INVALID_CERT_EXTENSION),
1024
    OD(pkcs12RSAEncryptionWith128BitRC4,
1025
       SEC_OID_PKCS12_RSA_ENCRYPTION_WITH_128_BIT_RC4,
1026
       "PKCS #12 RSA Encryption with 128 Bit RC4",
1027
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1028
    OD(pkcs12RSAEncryptionWith40BitRC4,
1029
       SEC_OID_PKCS12_RSA_ENCRYPTION_WITH_40_BIT_RC4,
1030
       "PKCS #12 RSA Encryption with 40 Bit RC4",
1031
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1032
    OD(pkcs12RSAEncryptionWithTripleDES,
1033
       SEC_OID_PKCS12_RSA_ENCRYPTION_WITH_TRIPLE_DES,
1034
       "PKCS #12 RSA Encryption with Triple DES",
1035
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1036
    OD(pkcs12RSASignatureWithSHA1Digest,
1037
       SEC_OID_PKCS12_RSA_SIGNATURE_WITH_SHA1_DIGEST,
1038
       "PKCS #12 RSA Encryption with Triple DES",
1039
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1040
1041
    /* DSA signatures */
1042
    OD(ansix9DSASignature, SEC_OID_ANSIX9_DSA_SIGNATURE,
1043
       "ANSI X9.57 DSA Signature", CKM_DSA, INVALID_CERT_EXTENSION),
1044
    OD(ansix9DSASignaturewithSHA1Digest,
1045
       SEC_OID_ANSIX9_DSA_SIGNATURE_WITH_SHA1_DIGEST,
1046
       "ANSI X9.57 DSA Signature with SHA-1 Digest",
1047
       CKM_DSA_SHA1, INVALID_CERT_EXTENSION),
1048
    OD(bogusDSASignaturewithSHA1Digest,
1049
       SEC_OID_BOGUS_DSA_SIGNATURE_WITH_SHA1_DIGEST,
1050
       "FORTEZZA DSA Signature with SHA-1 Digest",
1051
       CKM_DSA_SHA1, INVALID_CERT_EXTENSION),
1052
1053
    /* verisign oids */
1054
    OD(verisignUserNotices, SEC_OID_VERISIGN_USER_NOTICES,
1055
       "Verisign User Notices",
1056
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1057
1058
    /* pkix oids */
1059
    OD(pkixCPSPointerQualifier, SEC_OID_PKIX_CPS_POINTER_QUALIFIER,
1060
       "PKIX CPS Pointer Qualifier",
1061
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1062
    OD(pkixUserNoticeQualifier, SEC_OID_PKIX_USER_NOTICE_QUALIFIER,
1063
       "PKIX User Notice Qualifier",
1064
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1065
1066
    OD(pkixOCSP, SEC_OID_PKIX_OCSP,
1067
       "PKIX Online Certificate Status Protocol",
1068
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1069
    OD(pkixOCSPBasicResponse, SEC_OID_PKIX_OCSP_BASIC_RESPONSE,
1070
       "OCSP Basic Response", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1071
    OD(pkixOCSPNonce, SEC_OID_PKIX_OCSP_NONCE,
1072
       "OCSP Nonce Extension", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1073
    OD(pkixOCSPCRL, SEC_OID_PKIX_OCSP_CRL,
1074
       "OCSP CRL Reference Extension",
1075
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1076
    OD(pkixOCSPResponse, SEC_OID_PKIX_OCSP_RESPONSE,
1077
       "OCSP Response Types Extension",
1078
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1079
    OD(pkixOCSPNoCheck, SEC_OID_PKIX_OCSP_NO_CHECK,
1080
       "OCSP No Check Extension",
1081
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
1082
    OD(pkixOCSPArchiveCutoff, SEC_OID_PKIX_OCSP_ARCHIVE_CUTOFF,
1083
       "OCSP Archive Cutoff Extension",
1084
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1085
    OD(pkixOCSPServiceLocator, SEC_OID_PKIX_OCSP_SERVICE_LOCATOR,
1086
       "OCSP Service Locator Extension",
1087
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1088
1089
    OD(pkixRegCtrlRegToken, SEC_OID_PKIX_REGCTRL_REGTOKEN,
1090
       "PKIX CRMF Registration Control, Registration Token",
1091
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1092
    OD(pkixRegCtrlAuthenticator, SEC_OID_PKIX_REGCTRL_AUTHENTICATOR,
1093
       "PKIX CRMF Registration Control, Registration Authenticator",
1094
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1095
    OD(pkixRegCtrlPKIPubInfo, SEC_OID_PKIX_REGCTRL_PKIPUBINFO,
1096
       "PKIX CRMF Registration Control, PKI Publication Info",
1097
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1098
    OD(pkixRegCtrlPKIArchOptions,
1099
       SEC_OID_PKIX_REGCTRL_PKI_ARCH_OPTIONS,
1100
       "PKIX CRMF Registration Control, PKI Archive Options",
1101
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1102
    OD(pkixRegCtrlOldCertID, SEC_OID_PKIX_REGCTRL_OLD_CERT_ID,
1103
       "PKIX CRMF Registration Control, Old Certificate ID",
1104
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1105
    OD(pkixRegCtrlProtEncKey, SEC_OID_PKIX_REGCTRL_PROTOCOL_ENC_KEY,
1106
       "PKIX CRMF Registration Control, Protocol Encryption Key",
1107
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1108
    OD(pkixRegInfoUTF8Pairs, SEC_OID_PKIX_REGINFO_UTF8_PAIRS,
1109
       "PKIX CRMF Registration Info, UTF8 Pairs",
1110
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1111
    OD(pkixRegInfoCertReq, SEC_OID_PKIX_REGINFO_CERT_REQUEST,
1112
       "PKIX CRMF Registration Info, Certificate Request",
1113
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1114
    OD(pkixExtendedKeyUsageServerAuth,
1115
       SEC_OID_EXT_KEY_USAGE_SERVER_AUTH,
1116
       "TLS Web Server Authentication Certificate",
1117
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1118
    OD(pkixExtendedKeyUsageClientAuth,
1119
       SEC_OID_EXT_KEY_USAGE_CLIENT_AUTH,
1120
       "TLS Web Client Authentication Certificate",
1121
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1122
    OD(pkixExtendedKeyUsageCodeSign, SEC_OID_EXT_KEY_USAGE_CODE_SIGN,
1123
       "Code Signing Certificate",
1124
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1125
    OD(pkixExtendedKeyUsageEMailProtect,
1126
       SEC_OID_EXT_KEY_USAGE_EMAIL_PROTECT,
1127
       "E-Mail Protection Certificate",
1128
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1129
    OD(pkixExtendedKeyUsageTimeStamp,
1130
       SEC_OID_EXT_KEY_USAGE_TIME_STAMP,
1131
       "Time Stamping Certifcate",
1132
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1133
    OD(pkixOCSPResponderExtendedKeyUsage, SEC_OID_OCSP_RESPONDER,
1134
       "OCSP Responder Certificate",
1135
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1136
1137
    /* Netscape Algorithm OIDs */
1138
1139
    OD(netscapeSMimeKEA, SEC_OID_NETSCAPE_SMIME_KEA,
1140
       "Netscape S/MIME KEA", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1141
1142
    /* Skipjack OID -- ### mwelch temporary */
1143
    OD(skipjackCBC, SEC_OID_FORTEZZA_SKIPJACK,
1144
       "Skipjack CBC64", CKM_SKIPJACK_CBC64, INVALID_CERT_EXTENSION),
1145
1146
    /* pkcs12 v2 oids */
1147
    OD(pkcs12V2PBEWithSha1And128BitRC4,
1148
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_128_BIT_RC4,
1149
       "PKCS #12 V2 PBE With SHA-1 And 128 Bit RC4",
1150
       CKM_PBE_SHA1_RC4_128, INVALID_CERT_EXTENSION),
1151
    OD(pkcs12V2PBEWithSha1And40BitRC4,
1152
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_40_BIT_RC4,
1153
       "PKCS #12 V2 PBE With SHA-1 And 40 Bit RC4",
1154
       CKM_PBE_SHA1_RC4_40, INVALID_CERT_EXTENSION),
1155
    OD(pkcs12V2PBEWithSha1And3KeyTripleDEScbc,
1156
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_3KEY_TRIPLE_DES_CBC,
1157
       "PKCS #12 V2 PBE With SHA-1 And 3KEY Triple DES-CBC",
1158
       CKM_PBE_SHA1_DES3_EDE_CBC, INVALID_CERT_EXTENSION),
1159
    OD(pkcs12V2PBEWithSha1And2KeyTripleDEScbc,
1160
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_2KEY_TRIPLE_DES_CBC,
1161
       "PKCS #12 V2 PBE With SHA-1 And 2KEY Triple DES-CBC",
1162
       CKM_PBE_SHA1_DES2_EDE_CBC, INVALID_CERT_EXTENSION),
1163
    OD(pkcs12V2PBEWithSha1And128BitRC2cbc,
1164
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_128_BIT_RC2_CBC,
1165
       "PKCS #12 V2 PBE With SHA-1 And 128 Bit RC2 CBC",
1166
       CKM_PBE_SHA1_RC2_128_CBC, INVALID_CERT_EXTENSION),
1167
    OD(pkcs12V2PBEWithSha1And40BitRC2cbc,
1168
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_40_BIT_RC2_CBC,
1169
       "PKCS #12 V2 PBE With SHA-1 And 40 Bit RC2 CBC",
1170
       CKM_PBE_SHA1_RC2_40_CBC, INVALID_CERT_EXTENSION),
1171
    OD(pkcs12SafeContentsID, SEC_OID_PKCS12_SAFE_CONTENTS_ID,
1172
       "PKCS #12 Safe Contents ID",
1173
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1174
    OD(pkcs12PKCS8ShroudedKeyBagID,
1175
       SEC_OID_PKCS12_PKCS8_SHROUDED_KEY_BAG_ID,
1176
       "PKCS #12 Safe Contents ID",
1177
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1178
    OD(pkcs12V1KeyBag, SEC_OID_PKCS12_V1_KEY_BAG_ID,
1179
       "PKCS #12 V1 Key Bag",
1180
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1181
    OD(pkcs12V1PKCS8ShroudedKeyBag,
1182
       SEC_OID_PKCS12_V1_PKCS8_SHROUDED_KEY_BAG_ID,
1183
       "PKCS #12 V1 PKCS8 Shrouded Key Bag",
1184
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1185
    OD(pkcs12V1CertBag, SEC_OID_PKCS12_V1_CERT_BAG_ID,
1186
       "PKCS #12 V1 Cert Bag",
1187
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1188
    OD(pkcs12V1CRLBag, SEC_OID_PKCS12_V1_CRL_BAG_ID,
1189
       "PKCS #12 V1 CRL Bag",
1190
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1191
    OD(pkcs12V1SecretBag, SEC_OID_PKCS12_V1_SECRET_BAG_ID,
1192
       "PKCS #12 V1 Secret Bag",
1193
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1194
    OD(pkcs12V1SafeContentsBag, SEC_OID_PKCS12_V1_SAFE_CONTENTS_BAG_ID,
1195
       "PKCS #12 V1 Safe Contents Bag",
1196
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1197
1198
    OD(pkcs9X509Certificate, SEC_OID_PKCS9_X509_CERT,
1199
       "PKCS #9 X509 Certificate",
1200
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1201
    OD(pkcs9SDSICertificate, SEC_OID_PKCS9_SDSI_CERT,
1202
       "PKCS #9 SDSI Certificate",
1203
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1204
    OD(pkcs9X509CRL, SEC_OID_PKCS9_X509_CRL,
1205
       "PKCS #9 X509 CRL", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1206
    OD(pkcs9FriendlyName, SEC_OID_PKCS9_FRIENDLY_NAME,
1207
       "PKCS #9 Friendly Name",
1208
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1209
    OD(pkcs9LocalKeyID, SEC_OID_PKCS9_LOCAL_KEY_ID,
1210
       "PKCS #9 Local Key ID",
1211
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1212
    OD(pkcs12KeyUsageAttr, SEC_OID_BOGUS_KEY_USAGE,
1213
       "Bogus Key Usage", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1214
    OD(dhPublicKey, SEC_OID_X942_DIFFIE_HELMAN_KEY,
1215
       "Diffie-Helman Public Key", CKM_DH_PKCS_DERIVE,
1216
       INVALID_CERT_EXTENSION),
1217
    OD(netscapeNickname, SEC_OID_NETSCAPE_NICKNAME,
1218
       "Netscape Nickname", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1219
1220
    /* Cert Server specific OIDs */
1221
    OD(netscapeRecoveryRequest, SEC_OID_NETSCAPE_RECOVERY_REQUEST,
1222
       "Recovery Request OID",
1223
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1224
1225
    OD(nsExtAIACertRenewal, SEC_OID_CERT_RENEWAL_LOCATOR,
1226
       "Certificate Renewal Locator OID", CKM_INVALID_MECHANISM,
1227
       INVALID_CERT_EXTENSION),
1228
1229
    OD(nsExtCertScopeOfUse, SEC_OID_NS_CERT_EXT_SCOPE_OF_USE,
1230
       "Certificate Scope-of-Use Extension", CKM_INVALID_MECHANISM,
1231
       SUPPORTED_CERT_EXTENSION),
1232
1233
    /* CMS stuff */
1234
    OD(cmsESDH, SEC_OID_CMS_EPHEMERAL_STATIC_DIFFIE_HELLMAN,
1235
       "Ephemeral-Static Diffie-Hellman", CKM_INVALID_MECHANISM /* XXX */,
1236
       INVALID_CERT_EXTENSION),
1237
    OD(cms3DESwrap, SEC_OID_CMS_3DES_KEY_WRAP,
1238
       "CMS Triple DES Key Wrap", CKM_INVALID_MECHANISM /* XXX */,
1239
       INVALID_CERT_EXTENSION),
1240
    OD(cmsRC2wrap, SEC_OID_CMS_RC2_KEY_WRAP,
1241
       "CMS RC2 Key Wrap", CKM_INVALID_MECHANISM /* XXX */,
1242
       INVALID_CERT_EXTENSION),
1243
    OD(smimeEncryptionKeyPreference, SEC_OID_SMIME_ENCRYPTION_KEY_PREFERENCE,
1244
       "S/MIME Encryption Key Preference",
1245
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1246
1247
    /* AES algorithm OIDs */
1248
    OD(aes128_ECB, SEC_OID_AES_128_ECB,
1249
       "AES-128-ECB", CKM_AES_ECB, INVALID_CERT_EXTENSION),
1250
    OD(aes128_CBC, SEC_OID_AES_128_CBC,
1251
       "AES-128-CBC", CKM_AES_CBC, INVALID_CERT_EXTENSION),
1252
    OD(aes192_ECB, SEC_OID_AES_192_ECB,
1253
       "AES-192-ECB", CKM_AES_ECB, INVALID_CERT_EXTENSION),
1254
    OD(aes192_CBC, SEC_OID_AES_192_CBC,
1255
       "AES-192-CBC", CKM_AES_CBC, INVALID_CERT_EXTENSION),
1256
    OD(aes256_ECB, SEC_OID_AES_256_ECB,
1257
       "AES-256-ECB", CKM_AES_ECB, INVALID_CERT_EXTENSION),
1258
    OD(aes256_CBC, SEC_OID_AES_256_CBC,
1259
       "AES-256-CBC", CKM_AES_CBC, INVALID_CERT_EXTENSION),
1260
1261
    /* More bogus DSA OIDs */
1262
    OD(sdn702DSASignature, SEC_OID_SDN702_DSA_SIGNATURE,
1263
       "SDN.702 DSA Signature", CKM_DSA_SHA1, INVALID_CERT_EXTENSION),
1264
1265
    OD(ms_smimeEncryptionKeyPreference,
1266
       SEC_OID_MS_SMIME_ENCRYPTION_KEY_PREFERENCE,
1267
       "Microsoft S/MIME Encryption Key Preference",
1268
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1269
1270
    OD(sha256, SEC_OID_SHA256, "SHA-256", CKM_SHA256, INVALID_CERT_EXTENSION),
1271
    OD(sha384, SEC_OID_SHA384, "SHA-384", CKM_SHA384, INVALID_CERT_EXTENSION),
1272
    OD(sha512, SEC_OID_SHA512, "SHA-512", CKM_SHA512, INVALID_CERT_EXTENSION),
1273
1274
    OD(pkcs1SHA256WithRSAEncryption, SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION,
1275
       "PKCS #1 SHA-256 With RSA Encryption", CKM_SHA256_RSA_PKCS,
1276
       INVALID_CERT_EXTENSION),
1277
    OD(pkcs1SHA384WithRSAEncryption, SEC_OID_PKCS1_SHA384_WITH_RSA_ENCRYPTION,
1278
       "PKCS #1 SHA-384 With RSA Encryption", CKM_SHA384_RSA_PKCS,
1279
       INVALID_CERT_EXTENSION),
1280
    OD(pkcs1SHA512WithRSAEncryption, SEC_OID_PKCS1_SHA512_WITH_RSA_ENCRYPTION,
1281
       "PKCS #1 SHA-512 With RSA Encryption", CKM_SHA512_RSA_PKCS,
1282
       INVALID_CERT_EXTENSION),
1283
1284
    OD(aes128_KEY_WRAP, SEC_OID_AES_128_KEY_WRAP,
1285
       "AES-128 Key Wrap", CKM_NSS_AES_KEY_WRAP, INVALID_CERT_EXTENSION),
1286
    OD(aes192_KEY_WRAP, SEC_OID_AES_192_KEY_WRAP,
1287
       "AES-192 Key Wrap", CKM_NSS_AES_KEY_WRAP, INVALID_CERT_EXTENSION),
1288
    OD(aes256_KEY_WRAP, SEC_OID_AES_256_KEY_WRAP,
1289
       "AES-256 Key Wrap", CKM_NSS_AES_KEY_WRAP, INVALID_CERT_EXTENSION),
1290
1291
    /* Elliptic Curve Cryptography (ECC) OIDs */
1292
    OD(ansix962ECPublicKey, SEC_OID_ANSIX962_EC_PUBLIC_KEY,
1293
       "X9.62 elliptic curve public key", CKM_ECDH1_DERIVE,
1294
       INVALID_CERT_EXTENSION),
1295
    OD(ansix962SignaturewithSHA1Digest,
1296
       SEC_OID_ANSIX962_ECDSA_SHA1_SIGNATURE,
1297
       "X9.62 ECDSA signature with SHA-1", CKM_ECDSA_SHA1,
1298
       INVALID_CERT_EXTENSION),
1299
1300
    /* Named curves */
1301
    /* NOTE: Only P256, P384, P521, and 25519 are supported by softoken.
1302
     *       Using other curves requires an appropriate token. */
1303
1304
    /* ANSI X9.62 named elliptic curves (prime field) */
1305
    OD(ansiX962prime192v1, SEC_OID_ANSIX962_EC_PRIME192V1,
1306
       "ANSI X9.62 elliptic curve prime192v1 (aka secp192r1, NIST P-192)",
1307
       CKM_INVALID_MECHANISM,
1308
       INVALID_CERT_EXTENSION),
1309
    OD(ansiX962prime192v2, SEC_OID_ANSIX962_EC_PRIME192V2,
1310
       "ANSI X9.62 elliptic curve prime192v2",
1311
       CKM_INVALID_MECHANISM,
1312
       INVALID_CERT_EXTENSION),
1313
    OD(ansiX962prime192v3, SEC_OID_ANSIX962_EC_PRIME192V3,
1314
       "ANSI X9.62 elliptic curve prime192v3",
1315
       CKM_INVALID_MECHANISM,
1316
       INVALID_CERT_EXTENSION),
1317
    OD(ansiX962prime239v1, SEC_OID_ANSIX962_EC_PRIME239V1,
1318
       "ANSI X9.62 elliptic curve prime239v1",
1319
       CKM_INVALID_MECHANISM,
1320
       INVALID_CERT_EXTENSION),
1321
    OD(ansiX962prime239v2, SEC_OID_ANSIX962_EC_PRIME239V2,
1322
       "ANSI X9.62 elliptic curve prime239v2",
1323
       CKM_INVALID_MECHANISM,
1324
       INVALID_CERT_EXTENSION),
1325
    OD(ansiX962prime239v3, SEC_OID_ANSIX962_EC_PRIME239V3,
1326
       "ANSI X9.62 elliptic curve prime239v3",
1327
       CKM_INVALID_MECHANISM,
1328
       INVALID_CERT_EXTENSION),
1329
    OD(ansiX962prime256v1, SEC_OID_ANSIX962_EC_PRIME256V1,
1330
       "ANSI X9.62 elliptic curve prime256v1 (aka secp256r1, NIST P-256)",
1331
       CKM_INVALID_MECHANISM,
1332
       INVALID_CERT_EXTENSION),
1333
1334
    /* SECG named elliptic curves (prime field) */
1335
    OD(secgECsecp112r1, SEC_OID_SECG_EC_SECP112R1,
1336
       "SECG elliptic curve secp112r1",
1337
       CKM_INVALID_MECHANISM,
1338
       INVALID_CERT_EXTENSION),
1339
    OD(secgECsecp112r2, SEC_OID_SECG_EC_SECP112R2,
1340
       "SECG elliptic curve secp112r2",
1341
       CKM_INVALID_MECHANISM,
1342
       INVALID_CERT_EXTENSION),
1343
    OD(secgECsecp128r1, SEC_OID_SECG_EC_SECP128R1,
1344
       "SECG elliptic curve secp128r1",
1345
       CKM_INVALID_MECHANISM,
1346
       INVALID_CERT_EXTENSION),
1347
    OD(secgECsecp128r2, SEC_OID_SECG_EC_SECP128R2,
1348
       "SECG elliptic curve secp128r2",
1349
       CKM_INVALID_MECHANISM,
1350
       INVALID_CERT_EXTENSION),
1351
    OD(secgECsecp160k1, SEC_OID_SECG_EC_SECP160K1,
1352
       "SECG elliptic curve secp160k1",
1353
       CKM_INVALID_MECHANISM,
1354
       INVALID_CERT_EXTENSION),
1355
    OD(secgECsecp160r1, SEC_OID_SECG_EC_SECP160R1,
1356
       "SECG elliptic curve secp160r1",
1357
       CKM_INVALID_MECHANISM,
1358
       INVALID_CERT_EXTENSION),
1359
    OD(secgECsecp160r2, SEC_OID_SECG_EC_SECP160R2,
1360
       "SECG elliptic curve secp160r2",
1361
       CKM_INVALID_MECHANISM,
1362
       INVALID_CERT_EXTENSION),
1363
    OD(secgECsecp192k1, SEC_OID_SECG_EC_SECP192K1,
1364
       "SECG elliptic curve secp192k1",
1365
       CKM_INVALID_MECHANISM,
1366
       INVALID_CERT_EXTENSION),
1367
    OD(secgECsecp224k1, SEC_OID_SECG_EC_SECP224K1,
1368
       "SECG elliptic curve secp224k1",
1369
       CKM_INVALID_MECHANISM,
1370
       INVALID_CERT_EXTENSION),
1371
    OD(secgECsecp224r1, SEC_OID_SECG_EC_SECP224R1,
1372
       "SECG elliptic curve secp224r1 (aka NIST P-224)",
1373
       CKM_INVALID_MECHANISM,
1374
       INVALID_CERT_EXTENSION),
1375
    OD(secgECsecp256k1, SEC_OID_SECG_EC_SECP256K1,
1376
       "SECG elliptic curve secp256k1",
1377
       CKM_INVALID_MECHANISM,
1378
       INVALID_CERT_EXTENSION),
1379
    OD(secgECsecp384r1, SEC_OID_SECG_EC_SECP384R1,
1380
       "SECG elliptic curve secp384r1 (aka NIST P-384)",
1381
       CKM_INVALID_MECHANISM,
1382
       INVALID_CERT_EXTENSION),
1383
    OD(secgECsecp521r1, SEC_OID_SECG_EC_SECP521R1,
1384
       "SECG elliptic curve secp521r1 (aka NIST P-521)",
1385
       CKM_INVALID_MECHANISM,
1386
       INVALID_CERT_EXTENSION),
1387
1388
    /* ANSI X9.62 named elliptic curves (characteristic two field) */
1389
    OD(ansiX962c2pnb163v1, SEC_OID_ANSIX962_EC_C2PNB163V1,
1390
       "ANSI X9.62 elliptic curve c2pnb163v1",
1391
       CKM_INVALID_MECHANISM,
1392
       INVALID_CERT_EXTENSION),
1393
    OD(ansiX962c2pnb163v2, SEC_OID_ANSIX962_EC_C2PNB163V2,
1394
       "ANSI X9.62 elliptic curve c2pnb163v2",
1395
       CKM_INVALID_MECHANISM,
1396
       INVALID_CERT_EXTENSION),
1397
    OD(ansiX962c2pnb163v3, SEC_OID_ANSIX962_EC_C2PNB163V3,
1398
       "ANSI X9.62 elliptic curve c2pnb163v3",
1399
       CKM_INVALID_MECHANISM,
1400
       INVALID_CERT_EXTENSION),
1401
    OD(ansiX962c2pnb176v1, SEC_OID_ANSIX962_EC_C2PNB176V1,
1402
       "ANSI X9.62 elliptic curve c2pnb176v1",
1403
       CKM_INVALID_MECHANISM,
1404
       INVALID_CERT_EXTENSION),
1405
    OD(ansiX962c2tnb191v1, SEC_OID_ANSIX962_EC_C2TNB191V1,
1406
       "ANSI X9.62 elliptic curve c2tnb191v1",
1407
       CKM_INVALID_MECHANISM,
1408
       INVALID_CERT_EXTENSION),
1409
    OD(ansiX962c2tnb191v2, SEC_OID_ANSIX962_EC_C2TNB191V2,
1410
       "ANSI X9.62 elliptic curve c2tnb191v2",
1411
       CKM_INVALID_MECHANISM,
1412
       INVALID_CERT_EXTENSION),
1413
    OD(ansiX962c2tnb191v3, SEC_OID_ANSIX962_EC_C2TNB191V3,
1414
       "ANSI X9.62 elliptic curve c2tnb191v3",
1415
       CKM_INVALID_MECHANISM,
1416
       INVALID_CERT_EXTENSION),
1417
    OD(ansiX962c2onb191v4, SEC_OID_ANSIX962_EC_C2ONB191V4,
1418
       "ANSI X9.62 elliptic curve c2onb191v4",
1419
       CKM_INVALID_MECHANISM,
1420
       INVALID_CERT_EXTENSION),
1421
    OD(ansiX962c2onb191v5, SEC_OID_ANSIX962_EC_C2ONB191V5,
1422
       "ANSI X9.62 elliptic curve c2onb191v5",
1423
       CKM_INVALID_MECHANISM,
1424
       INVALID_CERT_EXTENSION),
1425
    OD(ansiX962c2pnb208w1, SEC_OID_ANSIX962_EC_C2PNB208W1,
1426
       "ANSI X9.62 elliptic curve c2pnb208w1",
1427
       CKM_INVALID_MECHANISM,
1428
       INVALID_CERT_EXTENSION),
1429
    OD(ansiX962c2tnb239v1, SEC_OID_ANSIX962_EC_C2TNB239V1,
1430
       "ANSI X9.62 elliptic curve c2tnb239v1",
1431
       CKM_INVALID_MECHANISM,
1432
       INVALID_CERT_EXTENSION),
1433
    OD(ansiX962c2tnb239v2, SEC_OID_ANSIX962_EC_C2TNB239V2,
1434
       "ANSI X9.62 elliptic curve c2tnb239v2",
1435
       CKM_INVALID_MECHANISM,
1436
       INVALID_CERT_EXTENSION),
1437
    OD(ansiX962c2tnb239v3, SEC_OID_ANSIX962_EC_C2TNB239V3,
1438
       "ANSI X9.62 elliptic curve c2tnb239v3",
1439
       CKM_INVALID_MECHANISM,
1440
       INVALID_CERT_EXTENSION),
1441
    OD(ansiX962c2onb239v4, SEC_OID_ANSIX962_EC_C2ONB239V4,
1442
       "ANSI X9.62 elliptic curve c2onb239v4",
1443
       CKM_INVALID_MECHANISM,
1444
       INVALID_CERT_EXTENSION),
1445
    OD(ansiX962c2onb239v5, SEC_OID_ANSIX962_EC_C2ONB239V5,
1446
       "ANSI X9.62 elliptic curve c2onb239v5",
1447
       CKM_INVALID_MECHANISM,
1448
       INVALID_CERT_EXTENSION),
1449
    OD(ansiX962c2pnb272w1, SEC_OID_ANSIX962_EC_C2PNB272W1,
1450
       "ANSI X9.62 elliptic curve c2pnb272w1",
1451
       CKM_INVALID_MECHANISM,
1452
       INVALID_CERT_EXTENSION),
1453
    OD(ansiX962c2pnb304w1, SEC_OID_ANSIX962_EC_C2PNB304W1,
1454
       "ANSI X9.62 elliptic curve c2pnb304w1",
1455
       CKM_INVALID_MECHANISM,
1456
       INVALID_CERT_EXTENSION),
1457
    OD(ansiX962c2tnb359v1, SEC_OID_ANSIX962_EC_C2TNB359V1,
1458
       "ANSI X9.62 elliptic curve c2tnb359v1",
1459
       CKM_INVALID_MECHANISM,
1460
       INVALID_CERT_EXTENSION),
1461
    OD(ansiX962c2pnb368w1, SEC_OID_ANSIX962_EC_C2PNB368W1,
1462
       "ANSI X9.62 elliptic curve c2pnb368w1",
1463
       CKM_INVALID_MECHANISM,
1464
       INVALID_CERT_EXTENSION),
1465
    OD(ansiX962c2tnb431r1, SEC_OID_ANSIX962_EC_C2TNB431R1,
1466
       "ANSI X9.62 elliptic curve c2tnb431r1",
1467
       CKM_INVALID_MECHANISM,
1468
       INVALID_CERT_EXTENSION),
1469
1470
    /* SECG named elliptic curves (characterisitic two field) */
1471
    OD(secgECsect113r1, SEC_OID_SECG_EC_SECT113R1,
1472
       "SECG elliptic curve sect113r1",
1473
       CKM_INVALID_MECHANISM,
1474
       INVALID_CERT_EXTENSION),
1475
    OD(secgECsect113r2, SEC_OID_SECG_EC_SECT113R2,
1476
       "SECG elliptic curve sect113r2",
1477
       CKM_INVALID_MECHANISM,
1478
       INVALID_CERT_EXTENSION),
1479
    OD(secgECsect131r1, SEC_OID_SECG_EC_SECT131R1,
1480
       "SECG elliptic curve sect131r1",
1481
       CKM_INVALID_MECHANISM,
1482
       INVALID_CERT_EXTENSION),
1483
    OD(secgECsect131r2, SEC_OID_SECG_EC_SECT131R2,
1484
       "SECG elliptic curve sect131r2",
1485
       CKM_INVALID_MECHANISM,
1486
       INVALID_CERT_EXTENSION),
1487
    OD(secgECsect163k1, SEC_OID_SECG_EC_SECT163K1,
1488
       "SECG elliptic curve sect163k1 (aka NIST K-163)",
1489
       CKM_INVALID_MECHANISM,
1490
       INVALID_CERT_EXTENSION),
1491
    OD(secgECsect163r1, SEC_OID_SECG_EC_SECT163R1,
1492
       "SECG elliptic curve sect163r1",
1493
       CKM_INVALID_MECHANISM,
1494
       INVALID_CERT_EXTENSION),
1495
    OD(secgECsect163r2, SEC_OID_SECG_EC_SECT163R2,
1496
       "SECG elliptic curve sect163r2 (aka NIST B-163)",
1497
       CKM_INVALID_MECHANISM,
1498
       INVALID_CERT_EXTENSION),
1499
    OD(secgECsect193r1, SEC_OID_SECG_EC_SECT193R1,
1500
       "SECG elliptic curve sect193r1",
1501
       CKM_INVALID_MECHANISM,
1502
       INVALID_CERT_EXTENSION),
1503
    OD(secgECsect193r2, SEC_OID_SECG_EC_SECT193R2,
1504
       "SECG elliptic curve sect193r2",
1505
       CKM_INVALID_MECHANISM,
1506
       INVALID_CERT_EXTENSION),
1507
    OD(secgECsect233k1, SEC_OID_SECG_EC_SECT233K1,
1508
       "SECG elliptic curve sect233k1 (aka NIST K-233)",
1509
       CKM_INVALID_MECHANISM,
1510
       INVALID_CERT_EXTENSION),
1511
    OD(secgECsect233r1, SEC_OID_SECG_EC_SECT233R1,
1512
       "SECG elliptic curve sect233r1 (aka NIST B-233)",
1513
       CKM_INVALID_MECHANISM,
1514
       INVALID_CERT_EXTENSION),
1515
    OD(secgECsect239k1, SEC_OID_SECG_EC_SECT239K1,
1516
       "SECG elliptic curve sect239k1",
1517
       CKM_INVALID_MECHANISM,
1518
       INVALID_CERT_EXTENSION),
1519
    OD(secgECsect283k1, SEC_OID_SECG_EC_SECT283K1,
1520
       "SECG elliptic curve sect283k1 (aka NIST K-283)",
1521
       CKM_INVALID_MECHANISM,
1522
       INVALID_CERT_EXTENSION),
1523
    OD(secgECsect283r1, SEC_OID_SECG_EC_SECT283R1,
1524
       "SECG elliptic curve sect283r1 (aka NIST B-283)",
1525
       CKM_INVALID_MECHANISM,
1526
       INVALID_CERT_EXTENSION),
1527
    OD(secgECsect409k1, SEC_OID_SECG_EC_SECT409K1,
1528
       "SECG elliptic curve sect409k1 (aka NIST K-409)",
1529
       CKM_INVALID_MECHANISM,
1530
       INVALID_CERT_EXTENSION),
1531
    OD(secgECsect409r1, SEC_OID_SECG_EC_SECT409R1,
1532
       "SECG elliptic curve sect409r1 (aka NIST B-409)",
1533
       CKM_INVALID_MECHANISM,
1534
       INVALID_CERT_EXTENSION),
1535
    OD(secgECsect571k1, SEC_OID_SECG_EC_SECT571K1,
1536
       "SECG elliptic curve sect571k1 (aka NIST K-571)",
1537
       CKM_INVALID_MECHANISM,
1538
       INVALID_CERT_EXTENSION),
1539
    OD(secgECsect571r1, SEC_OID_SECG_EC_SECT571R1,
1540
       "SECG elliptic curve sect571r1 (aka NIST B-571)",
1541
       CKM_INVALID_MECHANISM,
1542
       INVALID_CERT_EXTENSION),
1543
1544
    OD(netscapeAOLScreenname, SEC_OID_NETSCAPE_AOLSCREENNAME,
1545
       "AOL Screenname", CKM_INVALID_MECHANISM,
1546
       INVALID_CERT_EXTENSION),
1547
1548
    OD(x520SurName, SEC_OID_AVA_SURNAME,
1549
       "X520 Title", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1550
    OD(x520SerialNumber, SEC_OID_AVA_SERIAL_NUMBER,
1551
       "X520 Serial Number", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1552
    OD(x520StreetAddress, SEC_OID_AVA_STREET_ADDRESS,
1553
       "X520 Street Address", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1554
    OD(x520Title, SEC_OID_AVA_TITLE,
1555
       "X520 Title", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1556
    OD(x520PostalAddress, SEC_OID_AVA_POSTAL_ADDRESS,
1557
       "X520 Postal Address", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1558
    OD(x520PostalCode, SEC_OID_AVA_POSTAL_CODE,
1559
       "X520 Postal Code", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1560
    OD(x520PostOfficeBox, SEC_OID_AVA_POST_OFFICE_BOX,
1561
       "X520 Post Office Box", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1562
    OD(x520GivenName, SEC_OID_AVA_GIVEN_NAME,
1563
       "X520 Given Name", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1564
    OD(x520Initials, SEC_OID_AVA_INITIALS,
1565
       "X520 Initials", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1566
    OD(x520GenerationQualifier, SEC_OID_AVA_GENERATION_QUALIFIER,
1567
       "X520 Generation Qualifier",
1568
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1569
    OD(x520HouseIdentifier, SEC_OID_AVA_HOUSE_IDENTIFIER,
1570
       "X520 House Identifier",
1571
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1572
    OD(x520Pseudonym, SEC_OID_AVA_PSEUDONYM,
1573
       "X520 Pseudonym", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1574
1575
    /* More OIDs */
1576
    OD(pkixCAIssuers, SEC_OID_PKIX_CA_ISSUERS,
1577
       "PKIX CA issuers access method",
1578
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1579
    OD(pkcs9ExtensionRequest, SEC_OID_PKCS9_EXTENSION_REQUEST,
1580
       "PKCS #9 Extension Request",
1581
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1582
1583
    /* more ECC Signature Oids */
1584
    OD(ansix962SignatureRecommended,
1585
       SEC_OID_ANSIX962_ECDSA_SIGNATURE_RECOMMENDED_DIGEST,
1586
       "X9.62 ECDSA signature with recommended digest", CKM_INVALID_MECHANISM,
1587
       INVALID_CERT_EXTENSION),
1588
    OD(ansix962SignatureSpecified,
1589
       SEC_OID_ANSIX962_ECDSA_SIGNATURE_SPECIFIED_DIGEST,
1590
       "X9.62 ECDSA signature with specified digest", CKM_ECDSA,
1591
       INVALID_CERT_EXTENSION),
1592
    OD(ansix962SignaturewithSHA224Digest,
1593
       SEC_OID_ANSIX962_ECDSA_SHA224_SIGNATURE,
1594
       "X9.62 ECDSA signature with SHA224", CKM_ECDSA_SHA224,
1595
       INVALID_CERT_EXTENSION),
1596
    OD(ansix962SignaturewithSHA256Digest,
1597
       SEC_OID_ANSIX962_ECDSA_SHA256_SIGNATURE,
1598
       "X9.62 ECDSA signature with SHA256", CKM_ECDSA_SHA256,
1599
       INVALID_CERT_EXTENSION),
1600
    OD(ansix962SignaturewithSHA384Digest,
1601
       SEC_OID_ANSIX962_ECDSA_SHA384_SIGNATURE,
1602
       "X9.62 ECDSA signature with SHA384", CKM_ECDSA_SHA384,
1603
       INVALID_CERT_EXTENSION),
1604
    OD(ansix962SignaturewithSHA512Digest,
1605
       SEC_OID_ANSIX962_ECDSA_SHA512_SIGNATURE,
1606
       "X9.62 ECDSA signature with SHA512", CKM_ECDSA_SHA512,
1607
       INVALID_CERT_EXTENSION),
1608
1609
    /* More id-ce and id-pe OIDs from RFC 3280 */
1610
    OD(x509HoldInstructionCode, SEC_OID_X509_HOLD_INSTRUCTION_CODE,
1611
       "CRL Hold Instruction Code", CKM_INVALID_MECHANISM,
1612
       UNSUPPORTED_CERT_EXTENSION),
1613
    OD(x509DeltaCRLIndicator, SEC_OID_X509_DELTA_CRL_INDICATOR,
1614
       "Delta CRL Indicator", CKM_INVALID_MECHANISM,
1615
       FAKE_SUPPORTED_CERT_EXTENSION),
1616
    OD(x509IssuingDistributionPoint, SEC_OID_X509_ISSUING_DISTRIBUTION_POINT,
1617
       "Issuing Distribution Point", CKM_INVALID_MECHANISM,
1618
       FAKE_SUPPORTED_CERT_EXTENSION),
1619
    OD(x509CertIssuer, SEC_OID_X509_CERT_ISSUER,
1620
       "Certificate Issuer Extension", CKM_INVALID_MECHANISM,
1621
       FAKE_SUPPORTED_CERT_EXTENSION),
1622
    OD(x509FreshestCRL, SEC_OID_X509_FRESHEST_CRL,
1623
       "Freshest CRL", CKM_INVALID_MECHANISM,
1624
       UNSUPPORTED_CERT_EXTENSION),
1625
    OD(x509InhibitAnyPolicy, SEC_OID_X509_INHIBIT_ANY_POLICY,
1626
       "Inhibit Any Policy", CKM_INVALID_MECHANISM,
1627
       FAKE_SUPPORTED_CERT_EXTENSION),
1628
    OD(x509SubjectInfoAccess, SEC_OID_X509_SUBJECT_INFO_ACCESS,
1629
       "Subject Info Access", CKM_INVALID_MECHANISM,
1630
       UNSUPPORTED_CERT_EXTENSION),
1631
1632
    /* Camellia algorithm OIDs */
1633
    OD(camellia128_CBC, SEC_OID_CAMELLIA_128_CBC,
1634
       "CAMELLIA-128-CBC", CKM_CAMELLIA_CBC, INVALID_CERT_EXTENSION),
1635
    OD(camellia192_CBC, SEC_OID_CAMELLIA_192_CBC,
1636
       "CAMELLIA-192-CBC", CKM_CAMELLIA_CBC, INVALID_CERT_EXTENSION),
1637
    OD(camellia256_CBC, SEC_OID_CAMELLIA_256_CBC,
1638
       "CAMELLIA-256-CBC", CKM_CAMELLIA_CBC, INVALID_CERT_EXTENSION),
1639
1640
    /* PKCS 5 v2 OIDS */
1641
    OD(pkcs5Pbkdf2, SEC_OID_PKCS5_PBKDF2,
1642
       "PKCS #5 Password Based Key Dervive Function v2 ",
1643
       CKM_PKCS5_PBKD2, INVALID_CERT_EXTENSION),
1644
    OD(pkcs5Pbes2, SEC_OID_PKCS5_PBES2,
1645
       "PKCS #5 Password Based Encryption v2 ",
1646
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1647
    OD(pkcs5Pbmac1, SEC_OID_PKCS5_PBMAC1,
1648
       "PKCS #5 Password Based Authentication v1 ",
1649
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1650
    OD(hmac_sha1, SEC_OID_HMAC_SHA1, "HMAC SHA-1",
1651
       CKM_SHA_1_HMAC, INVALID_CERT_EXTENSION),
1652
    OD(hmac_sha224, SEC_OID_HMAC_SHA224, "HMAC SHA-224",
1653
       CKM_SHA224_HMAC, INVALID_CERT_EXTENSION),
1654
    OD(hmac_sha256, SEC_OID_HMAC_SHA256, "HMAC SHA-256",
1655
       CKM_SHA256_HMAC, INVALID_CERT_EXTENSION),
1656
    OD(hmac_sha384, SEC_OID_HMAC_SHA384, "HMAC SHA-384",
1657
       CKM_SHA384_HMAC, INVALID_CERT_EXTENSION),
1658
    OD(hmac_sha512, SEC_OID_HMAC_SHA512, "HMAC SHA-512",
1659
       CKM_SHA512_HMAC, INVALID_CERT_EXTENSION),
1660
1661
    /* SIA extension OIDs */
1662
    OD(x509SIATimeStamping, SEC_OID_PKIX_TIMESTAMPING,
1663
       "SIA Time Stamping", CKM_INVALID_MECHANISM,
1664
       INVALID_CERT_EXTENSION),
1665
    OD(x509SIACaRepository, SEC_OID_PKIX_CA_REPOSITORY,
1666
       "SIA CA Repository", CKM_INVALID_MECHANISM,
1667
       INVALID_CERT_EXTENSION),
1668
1669
    OD(isoSHA1WithRSASignature, SEC_OID_ISO_SHA1_WITH_RSA_SIGNATURE,
1670
       "ISO SHA-1 with RSA Signature",
1671
       CKM_SHA1_RSA_PKCS, INVALID_CERT_EXTENSION),
1672
1673
    /* SEED algorithm OIDs */
1674
    OD(seed_CBC, SEC_OID_SEED_CBC,
1675
       "SEED-CBC", CKM_SEED_CBC, INVALID_CERT_EXTENSION),
1676
1677
    OD(x509CertificatePoliciesAnyPolicy, SEC_OID_X509_ANY_POLICY,
1678
       "Certificate Policies AnyPolicy",
1679
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1680
1681
    OD(pkcs1RSAOAEPEncryption, SEC_OID_PKCS1_RSA_OAEP_ENCRYPTION,
1682
       "PKCS #1 RSA-OAEP Encryption", CKM_RSA_PKCS_OAEP,
1683
       INVALID_CERT_EXTENSION),
1684
1685
    OD(pkcs1MGF1, SEC_OID_PKCS1_MGF1,
1686
       "PKCS #1 MGF1 Mask Generation Function", CKM_INVALID_MECHANISM,
1687
       INVALID_CERT_EXTENSION),
1688
1689
    OD(pkcs1PSpecified, SEC_OID_PKCS1_PSPECIFIED,
1690
       "PKCS #1 RSA-OAEP Explicitly Specified Encoding Parameters",
1691
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1692
1693
    OD(pkcs1RSAPSSSignature, SEC_OID_PKCS1_RSA_PSS_SIGNATURE,
1694
       "PKCS #1 RSA-PSS Signature", CKM_RSA_PKCS_PSS,
1695
       INVALID_CERT_EXTENSION),
1696
1697
    OD(pkcs1SHA224WithRSAEncryption, SEC_OID_PKCS1_SHA224_WITH_RSA_ENCRYPTION,
1698
       "PKCS #1 SHA-224 With RSA Encryption", CKM_SHA224_RSA_PKCS,
1699
       INVALID_CERT_EXTENSION),
1700
1701
    OD(sha224, SEC_OID_SHA224, "SHA-224", CKM_SHA224, INVALID_CERT_EXTENSION),
1702
1703
    OD(evIncorporationLocality, SEC_OID_EV_INCORPORATION_LOCALITY,
1704
       "Jurisdiction of Incorporation Locality Name",
1705
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1706
    OD(evIncorporationState, SEC_OID_EV_INCORPORATION_STATE,
1707
       "Jurisdiction of Incorporation State Name",
1708
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1709
    OD(evIncorporationCountry, SEC_OID_EV_INCORPORATION_COUNTRY,
1710
       "Jurisdiction of Incorporation Country Name",
1711
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1712
    OD(x520BusinessCategory, SEC_OID_BUSINESS_CATEGORY,
1713
       "Business Category",
1714
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1715
1716
    OD(nistDSASignaturewithSHA224Digest,
1717
       SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA224_DIGEST,
1718
       "DSA with SHA-224 Signature",
1719
       CKM_DSA_SHA224, INVALID_CERT_EXTENSION),
1720
    OD(nistDSASignaturewithSHA256Digest,
1721
       SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA256_DIGEST,
1722
       "DSA with SHA-256 Signature",
1723
       CKM_DSA_SHA256, INVALID_CERT_EXTENSION),
1724
    OD(msExtendedKeyUsageTrustListSigning,
1725
       SEC_OID_MS_EXT_KEY_USAGE_CTL_SIGNING,
1726
       "Microsoft Trust List Signing",
1727
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1728
    OD(x520Name, SEC_OID_AVA_NAME,
1729
       "X520 Name", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1730
1731
    OD(aes128_GCM, SEC_OID_AES_128_GCM,
1732
       "AES-128-GCM", CKM_AES_GCM, INVALID_CERT_EXTENSION),
1733
    OD(aes192_GCM, SEC_OID_AES_192_GCM,
1734
       "AES-192-GCM", CKM_AES_GCM, INVALID_CERT_EXTENSION),
1735
    OD(aes256_GCM, SEC_OID_AES_256_GCM,
1736
       "AES-256-GCM", CKM_AES_GCM, INVALID_CERT_EXTENSION),
1737
    OD(idea_CBC, SEC_OID_IDEA_CBC,
1738
       "IDEA_CBC", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1739
1740
    ODE(SEC_OID_RC2_40_CBC,
1741
        "RC2-40-CBC", CKM_RC2_CBC, INVALID_CERT_EXTENSION),
1742
    ODE(SEC_OID_DES_40_CBC,
1743
        "DES-40-CBC", CKM_RC2_CBC, INVALID_CERT_EXTENSION),
1744
    ODE(SEC_OID_RC4_40,
1745
        "RC4-40", CKM_RC4, INVALID_CERT_EXTENSION),
1746
    ODE(SEC_OID_RC4_56,
1747
        "RC4-56", CKM_RC4, INVALID_CERT_EXTENSION),
1748
    ODE(SEC_OID_NULL_CIPHER,
1749
        "NULL cipher", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1750
    ODE(SEC_OID_HMAC_MD5,
1751
        "HMAC-MD5", CKM_MD5_HMAC, INVALID_CERT_EXTENSION),
1752
    ODE(SEC_OID_TLS_RSA,
1753
        "TLS RSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1754
    ODE(SEC_OID_TLS_DHE_RSA,
1755
        "TLS DHE-RSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1756
    ODE(SEC_OID_TLS_DHE_DSS,
1757
        "TLS DHE-DSS key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1758
    ODE(SEC_OID_TLS_DH_RSA,
1759
        "TLS DH-RSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1760
    ODE(SEC_OID_TLS_DH_DSS,
1761
        "TLS DH-DSS key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1762
    ODE(SEC_OID_TLS_DH_ANON,
1763
        "TLS DH-ANON key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1764
    ODE(SEC_OID_TLS_ECDHE_ECDSA,
1765
        "TLS ECDHE-ECDSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1766
    ODE(SEC_OID_TLS_ECDHE_RSA,
1767
        "TLS ECDHE-RSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1768
    ODE(SEC_OID_TLS_ECDH_ECDSA,
1769
        "TLS ECDH-ECDSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1770
    ODE(SEC_OID_TLS_ECDH_RSA,
1771
        "TLS ECDH-RSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1772
    ODE(SEC_OID_TLS_ECDH_ANON,
1773
        "TLS ECDH-ANON key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1774
    ODE(SEC_OID_TLS_RSA_EXPORT,
1775
        "TLS RSA-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1776
    ODE(SEC_OID_TLS_DHE_RSA_EXPORT,
1777
        "TLS DHE-RSA-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1778
    ODE(SEC_OID_TLS_DHE_DSS_EXPORT,
1779
        "TLS DHE-DSS-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1780
    ODE(SEC_OID_TLS_DH_RSA_EXPORT,
1781
        "TLS DH-RSA-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1782
    ODE(SEC_OID_TLS_DH_DSS_EXPORT,
1783
        "TLS DH-DSS-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1784
    ODE(SEC_OID_TLS_DH_ANON_EXPORT,
1785
        "TLS DH-ANON-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1786
    ODE(SEC_OID_APPLY_SSL_POLICY,
1787
        "Apply SSL policy (pseudo-OID)", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1788
    ODE(SEC_OID_CHACHA20_POLY1305,
1789
        "ChaCha20-Poly1305", CKM_NSS_CHACHA20_POLY1305, INVALID_CERT_EXTENSION),
1790
1791
    ODE(SEC_OID_TLS_ECDHE_PSK,
1792
        "TLS ECHDE-PSK key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1793
    ODE(SEC_OID_TLS_DHE_PSK,
1794
        "TLS DHE-PSK key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1795
1796
    ODE(SEC_OID_TLS_FFDHE_2048,
1797
        "TLS FFDHE 2048-bit key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1798
    ODE(SEC_OID_TLS_FFDHE_3072,
1799
        "TLS FFDHE 3072-bit key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1800
    ODE(SEC_OID_TLS_FFDHE_4096,
1801
        "TLS FFDHE 4096-bit key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1802
    ODE(SEC_OID_TLS_FFDHE_6144,
1803
        "TLS FFDHE 6144-bit key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1804
    ODE(SEC_OID_TLS_FFDHE_8192,
1805
        "TLS FFDHE 8192-bit key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1806
    ODE(SEC_OID_TLS_DHE_CUSTOM,
1807
        "TLS DHE custom group key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1808
    OD(curve25519, SEC_OID_CURVE25519,
1809
       "Curve25519", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1810
    ODE(SEC_OID_TLS13_KEA_ANY,
1811
        "TLS 1.3 fake key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1812
1813
    OD(x509ExtKeyUsageAnyUsage, SEC_OID_X509_ANY_EXT_KEY_USAGE,
1814
       "Any Extended Key Usage",
1815
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1816
    OD(pkixExtendedKeyUsageIPsecIKE,
1817
       SEC_OID_EXT_KEY_USAGE_IPSEC_IKE,
1818
       "IPsec IKE Certificate",
1819
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1820
    OD(ipsecIKEEnd,
1821
       SEC_OID_IPSEC_IKE_END,
1822
       "IPsec IKE End",
1823
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1824
    OD(ipsecIKEIntermediate,
1825
       SEC_OID_IPSEC_IKE_INTERMEDIATE,
1826
       "IPsec IKE Intermediate",
1827
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1828
    OD(pkixExtendedKeyUsageIPsecEnd,
1829
       SEC_OID_EXT_KEY_USAGE_IPSEC_END,
1830
       "IPsec Tunnel",
1831
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1832
    OD(pkixExtendedKeyUsageIPsecTunnel,
1833
       SEC_OID_EXT_KEY_USAGE_IPSEC_TUNNEL,
1834
       "IPsec Tunnel",
1835
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1836
    OD(pkixExtendedKeyUsageIPsecUser,
1837
       SEC_OID_EXT_KEY_USAGE_IPSEC_USER,
1838
       "IPsec User",
1839
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1840
1841
    OD(sha3_224, SEC_OID_SHA3_224, "SHA3-224", CKM_SHA3_224, INVALID_CERT_EXTENSION),
1842
    OD(sha3_256, SEC_OID_SHA3_256, "SHA3-256", CKM_SHA3_256, INVALID_CERT_EXTENSION),
1843
    OD(sha3_384, SEC_OID_SHA3_384, "SHA3-384", CKM_SHA3_384, INVALID_CERT_EXTENSION),
1844
    OD(sha3_512, SEC_OID_SHA3_512, "SHA3-512", CKM_SHA3_512, INVALID_CERT_EXTENSION),
1845
1846
    OD(hmac_sha3_224, SEC_OID_HMAC_SHA3_224, "HMAC SHA3-224", CKM_SHA3_224_HMAC, INVALID_CERT_EXTENSION),
1847
    OD(hmac_sha3_256, SEC_OID_HMAC_SHA3_256, "HMAC SHA3-256", CKM_SHA3_256_HMAC, INVALID_CERT_EXTENSION),
1848
    OD(hmac_sha3_384, SEC_OID_HMAC_SHA3_384, "HMAC SHA3-384", CKM_SHA3_384_HMAC, INVALID_CERT_EXTENSION),
1849
    OD(hmac_sha3_512, SEC_OID_HMAC_SHA3_512, "HMAC SHA3-512", CKM_SHA3_512_HMAC, INVALID_CERT_EXTENSION),
1850
1851
    ODE(SEC_OID_XYBER768D00,
1852
        "X25519+Kyber768 key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1853
1854
    OD(ed25519Signature, SEC_OID_ED25519_SIGNATURE, "X9.62 EDDSA signature", CKM_EDDSA,
1855
       INVALID_CERT_EXTENSION),
1856
1857
    OD(ed25519PublicKey, SEC_OID_ED25519_PUBLIC_KEY,
1858
       "X9.62 elliptic edwards curve public key", CKM_EC_EDWARDS_KEY_PAIR_GEN, INVALID_CERT_EXTENSION),
1859
1860
    OD(dhSinglePassstdDHsha1kdfscheme, SEC_OID_DHSINGLEPASS_STDDH_SHA1KDF_SCHEME,
1861
       "Eliptic Curve Diffie-Hellman Single Pass Standard with SHA1 KDF", CKM_ECDH1_DERIVE,
1862
       INVALID_CERT_EXTENSION),
1863
    OD(dhSinglePassstdDHsha224kdfscheme, SEC_OID_DHSINGLEPASS_STDDH_SHA224KDF_SCHEME,
1864
       "Eliptic Curve Diffie-Hellman Single Pass Standard with SHA224 KDF", CKM_ECDH1_DERIVE,
1865
       INVALID_CERT_EXTENSION),
1866
    OD(dhSinglePassstdDHsha256kdfscheme, SEC_OID_DHSINGLEPASS_STDDH_SHA256KDF_SCHEME,
1867
       "Eliptic Curve Diffie-Hellman Single Pass Standard with SHA256 KDF", CKM_ECDH1_DERIVE,
1868
       INVALID_CERT_EXTENSION),
1869
    OD(dhSinglePassstdDHsha384kdfscheme, SEC_OID_DHSINGLEPASS_STDDH_SHA384KDF_SCHEME,
1870
       "Eliptic Curve Diffie-Hellman Single Pass Standard with SHA384 KDF", CKM_ECDH1_DERIVE,
1871
       INVALID_CERT_EXTENSION),
1872
    OD(dhSinglePassstdDHsha512kdfscheme, SEC_OID_DHSINGLEPASS_STDDH_SHA512KDF_SCHEME,
1873
       "Eliptic Curve Diffie-Hellman Single Pass Standard with SHA512 KDF", CKM_ECDH1_DERIVE,
1874
       INVALID_CERT_EXTENSION),
1875
    OD(dhSinglePasscofactorDHsha1kdfscheme, SEC_OID_DHSINGLEPASS_COFACTORDH_SHA1KDF_SCHEME,
1876
       "Eliptic Curve Diffie-Hellman Single Pass Cofactor with SHA1 KDF", CKM_ECDH1_COFACTOR_DERIVE,
1877
       INVALID_CERT_EXTENSION),
1878
    OD(dhSinglePasscofactorDHsha224kdfscheme, SEC_OID_DHSINGLEPASS_COFACTORDH_SHA224KDF_SCHEME,
1879
       "Eliptic Curve Diffie-Hellman Single Pass Cofactor with SHA224 KDF", CKM_ECDH1_COFACTOR_DERIVE,
1880
       INVALID_CERT_EXTENSION),
1881
    OD(dhSinglePasscofactorDHsha256kdfscheme, SEC_OID_DHSINGLEPASS_COFACTORDH_SHA256KDF_SCHEME,
1882
       "Eliptic Curve Diffie-Hellman Single Pass Cofactor with SHA256 KDF", CKM_ECDH1_COFACTOR_DERIVE,
1883
       INVALID_CERT_EXTENSION),
1884
    OD(dhSinglePasscofactorDHsha384kdfscheme, SEC_OID_DHSINGLEPASS_COFACTORDH_SHA384KDF_SCHEME,
1885
       "Eliptic Curve Diffie-Hellman Single Pass Cofactor with SHA384 KDF", CKM_ECDH1_COFACTOR_DERIVE,
1886
       INVALID_CERT_EXTENSION),
1887
    OD(dhSinglePasscofactorDHsha512kdfscheme, SEC_OID_DHSINGLEPASS_COFACTORDH_SHA512KDF_SCHEME,
1888
       "Eliptic Curve Diffie-Hellman Single Pass Cofactor with SHA512 KDF", CKM_ECDH1_COFACTOR_DERIVE,
1889
       INVALID_CERT_EXTENSION),
1890
};
1891
1892
/* PRIVATE EXTENDED SECOID Table
1893
 * This table is private. Its structure is opaque to the outside.
1894
 * It is indexed by the same SECOidTag as the oids table above.
1895
 * Every member of this struct must have accessor functions (set, get)
1896
 * and those functions must operate by value, not by reference.
1897
 * The addresses of the contents of this table must not be exposed
1898
 * by the accessor functions.
1899
 */
1900
typedef struct privXOidStr {
1901
    PRUint32 notPolicyFlags; /* ones complement of policy flags */
1902
} privXOid;
1903
1904
static privXOid xOids[SEC_OID_TOTAL];
1905
1906
/*
1907
 * now the dynamic table. The dynamic table gets build at init time.
1908
 * and conceivably gets modified if the user loads new crypto modules.
1909
 * All this static data, and the allocated data to which it points,
1910
 * is protected by a global reader/writer lock.
1911
 * The c language guarantees that global and static data that is not
1912
 * explicitly initialized will be initialized with zeros.  If we
1913
 * initialize it with zeros, the data goes into the initialized data
1914
 * secment, and increases the size of the library.  By leaving it
1915
 * uninitialized, it is allocated in BSS, and does NOT increase the
1916
 * library size.
1917
 */
1918
1919
typedef struct dynXOidStr {
1920
    SECOidData data;
1921
    privXOid priv;
1922
} dynXOid;
1923
1924
static NSSRWLock *dynOidLock;
1925
static PLArenaPool *dynOidPool;
1926
static PLHashTable *dynOidHash;
1927
static dynXOid **dynOidTable; /* not in the pool */
1928
static int dynOidEntriesAllocated;
1929
static int dynOidEntriesUsed;
1930
1931
/* Creates NSSRWLock and dynOidPool at initialization time.
1932
*/
1933
static SECStatus
1934
secoid_InitDynOidData(void)
1935
1
{
1936
1
    SECStatus rv = SECSuccess;
1937
1938
1
    dynOidLock = NSSRWLock_New(1, "dynamic OID data");
1939
1
    if (!dynOidLock) {
1940
0
        return SECFailure; /* Error code should already be set. */
1941
0
    }
1942
1
    dynOidPool = PORT_NewArena(2048);
1943
1
    if (!dynOidPool) {
1944
0
        rv = SECFailure /* Error code should already be set. */;
1945
0
    }
1946
1
    return rv;
1947
1
}
1948
1949
/* Add oidData to hash table.  Caller holds write lock dynOidLock. */
1950
static SECStatus
1951
secoid_HashDynamicOiddata(const SECOidData *oid)
1952
0
{
1953
0
    PLHashEntry *entry;
1954
1955
0
    if (!dynOidHash) {
1956
0
        dynOidHash = PL_NewHashTable(0, SECITEM_Hash, SECITEM_HashCompare,
1957
0
                                     PL_CompareValues, NULL, NULL);
1958
0
        if (!dynOidHash) {
1959
0
            return SECFailure;
1960
0
        }
1961
0
    }
1962
1963
0
    entry = PL_HashTableAdd(dynOidHash, &oid->oid, (void *)oid);
1964
0
    return entry ? SECSuccess : SECFailure;
1965
0
}
1966
1967
/*
1968
 * Lookup a Dynamic OID. Dynamic OID's still change slowly, so it's
1969
 * cheaper to rehash the table when it changes than it is to do the loop
1970
 * each time.
1971
 */
1972
static SECOidData *
1973
secoid_FindDynamic(const SECItem *key)
1974
4
{
1975
4
    SECOidData *ret = NULL;
1976
1977
4
    NSSRWLock_LockRead(dynOidLock);
1978
4
    if (dynOidHash) {
1979
0
        ret = (SECOidData *)PL_HashTableLookup(dynOidHash, key);
1980
0
    }
1981
4
    NSSRWLock_UnlockRead(dynOidLock);
1982
4
    if (ret == NULL) {
1983
4
        PORT_SetError(SEC_ERROR_UNRECOGNIZED_OID);
1984
4
    }
1985
4
    return ret;
1986
4
}
1987
1988
static dynXOid *
1989
secoid_FindDynamicByTag(SECOidTag tagnum)
1990
0
{
1991
0
    dynXOid *dxo = NULL;
1992
0
    int tagNumDiff;
1993
1994
0
    if (tagnum < SEC_OID_TOTAL) {
1995
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
1996
0
        return NULL;
1997
0
    }
1998
0
    tagNumDiff = tagnum - SEC_OID_TOTAL;
1999
2000
0
    NSSRWLock_LockRead(dynOidLock);
2001
0
    if (dynOidTable != NULL &&
2002
0
        tagNumDiff < dynOidEntriesUsed) {
2003
0
        dxo = dynOidTable[tagNumDiff];
2004
0
    }
2005
0
    NSSRWLock_UnlockRead(dynOidLock);
2006
0
    if (dxo == NULL) {
2007
0
        PORT_SetError(SEC_ERROR_UNRECOGNIZED_OID);
2008
0
    }
2009
0
    return dxo;
2010
0
}
2011
2012
/*
2013
 * This routine is thread safe now.
2014
 */
2015
SECOidTag
2016
SECOID_AddEntry(const SECOidData *src)
2017
0
{
2018
0
    SECOidData *dst;
2019
0
    dynXOid **table;
2020
0
    SECOidTag ret = SEC_OID_UNKNOWN;
2021
0
    SECStatus rv;
2022
0
    int tableEntries;
2023
0
    int used;
2024
2025
0
    if (!src || !src->oid.data || !src->oid.len ||
2026
0
        !src->desc || !strlen(src->desc)) {
2027
0
        PORT_SetError(SEC_ERROR_INVALID_ARGS);
2028
0
        return ret;
2029
0
    }
2030
0
    if (src->supportedExtension != INVALID_CERT_EXTENSION &&
2031
0
        src->supportedExtension != UNSUPPORTED_CERT_EXTENSION &&
2032
0
        src->supportedExtension != SUPPORTED_CERT_EXTENSION) {
2033
0
        PORT_SetError(SEC_ERROR_INVALID_ARGS);
2034
0
        return ret;
2035
0
    }
2036
2037
0
    if (!dynOidPool || !dynOidLock) {
2038
0
        PORT_SetError(SEC_ERROR_NOT_INITIALIZED);
2039
0
        return ret;
2040
0
    }
2041
2042
0
    NSSRWLock_LockWrite(dynOidLock);
2043
2044
    /* We've just acquired the write lock, and now we call FindOIDTag
2045
    ** which will acquire and release the read lock.  NSSRWLock has been
2046
    ** designed to allow this very case without deadlock.  This approach
2047
    ** makes the test for the presence of the OID, and the subsequent
2048
    ** addition of the OID to the table a single atomic write operation.
2049
    */
2050
0
    ret = SECOID_FindOIDTag(&src->oid);
2051
0
    if (ret != SEC_OID_UNKNOWN) {
2052
        /* we could return an error here, but I chose not to do that.
2053
        ** This way, if we add an OID to the shared library's built in
2054
        ** list of OIDs in some future release, and that OID is the same
2055
        ** as some OID that a program has been adding, the program will
2056
        ** not suddenly stop working.
2057
        */
2058
0
        goto done;
2059
0
    }
2060
2061
0
    table = dynOidTable;
2062
0
    tableEntries = dynOidEntriesAllocated;
2063
0
    used = dynOidEntriesUsed;
2064
2065
0
    if (used + 1 > tableEntries) {
2066
0
        dynXOid **newTable;
2067
0
        int newTableEntries = tableEntries + 16;
2068
2069
0
        newTable = (dynXOid **)PORT_Realloc(table,
2070
0
                                            newTableEntries * sizeof(dynXOid *));
2071
0
        if (newTable == NULL) {
2072
0
            goto done;
2073
0
        }
2074
0
        dynOidTable = table = newTable;
2075
0
        dynOidEntriesAllocated = tableEntries = newTableEntries;
2076
0
    }
2077
2078
    /* copy oid structure */
2079
0
    dst = (SECOidData *)PORT_ArenaZNew(dynOidPool, dynXOid);
2080
0
    if (!dst) {
2081
0
        goto done;
2082
0
    }
2083
0
    rv = SECITEM_CopyItem(dynOidPool, &dst->oid, &src->oid);
2084
0
    if (rv != SECSuccess) {
2085
0
        goto done;
2086
0
    }
2087
0
    dst->desc = PORT_ArenaStrdup(dynOidPool, src->desc);
2088
0
    if (!dst->desc) {
2089
0
        goto done;
2090
0
    }
2091
0
    dst->offset = (SECOidTag)(used + SEC_OID_TOTAL);
2092
0
    dst->mechanism = src->mechanism;
2093
0
    dst->supportedExtension = src->supportedExtension;
2094
2095
0
    rv = secoid_HashDynamicOiddata(dst);
2096
0
    if (rv == SECSuccess) {
2097
0
        table[used++] = (dynXOid *)dst;
2098
0
        dynOidEntriesUsed = used;
2099
0
        ret = dst->offset;
2100
0
    }
2101
0
done:
2102
0
    NSSRWLock_UnlockWrite(dynOidLock);
2103
0
    return ret;
2104
0
}
2105
2106
/* normal static table processing */
2107
static PLHashTable *oidhash = NULL;
2108
static PLHashTable *oidmechhash = NULL;
2109
2110
static PLHashNumber
2111
secoid_HashNumber(const void *key)
2112
104
{
2113
104
    return (PLHashNumber)((char *)key - (char *)NULL);
2114
104
}
2115
2116
0
#define DEF_FLAGS (NSS_USE_ALG_IN_CERT_SIGNATURE | NSS_USE_ALG_IN_SSL_KX | NSS_USE_ALG_IN_SSL_KX)
2117
static void
2118
handleHashAlgSupport(char *envVal)
2119
0
{
2120
0
    char *myVal = PORT_Strdup(envVal); /* Get a copy we can alter */
2121
0
    char *arg = myVal;
2122
2123
0
    while (arg && *arg) {
2124
0
        char *nextArg = PL_strpbrk(arg, ";");
2125
0
        PRUint32 notEnable;
2126
2127
0
        if (nextArg) {
2128
0
            while (*nextArg == ';') {
2129
0
                *nextArg++ = '\0';
2130
0
            }
2131
0
        }
2132
0
        notEnable = (*arg == '-') ? (DEF_FLAGS) : 0;
2133
0
        if ((*arg == '+' || *arg == '-') && *++arg) {
2134
0
            int i;
2135
2136
0
            for (i = 1; i < SEC_OID_TOTAL; i++) {
2137
0
                if (oids[i].desc && strstr(arg, oids[i].desc)) {
2138
0
                    xOids[i].notPolicyFlags = notEnable |
2139
0
                                              (xOids[i].notPolicyFlags & ~(DEF_FLAGS));
2140
0
                }
2141
0
            }
2142
0
        }
2143
0
        arg = nextArg;
2144
0
    }
2145
0
    PORT_Free(myVal); /* can handle NULL argument OK */
2146
0
}
2147
2148
SECStatus
2149
SECOID_Init(void)
2150
2
{
2151
2
    PLHashEntry *entry;
2152
2
    const SECOidData *oid;
2153
2
    SECOidTag i;
2154
2
    char *envVal;
2155
2156
2
#define NSS_VERSION_VARIABLE __nss_util_version
2157
2
#include "verref.h"
2158
2159
2
    if (oidhash) {
2160
1
        return SECSuccess; /* already initialized */
2161
1
    }
2162
2163
    /* xyber768d00 must be enabled explicitly */
2164
1
    xOids[SEC_OID_XYBER768D00].notPolicyFlags = NSS_USE_ALG_IN_SSL_KX;
2165
2166
1
    if (!PR_GetEnvSecure("NSS_ALLOW_WEAK_SIGNATURE_ALG")) {
2167
        /* initialize any policy flags that are disabled by default */
2168
1
        xOids[SEC_OID_MD2].notPolicyFlags = ~0;
2169
1
        xOids[SEC_OID_MD4].notPolicyFlags = ~0;
2170
1
        xOids[SEC_OID_MD5].notPolicyFlags = ~0;
2171
1
        xOids[SEC_OID_PKCS1_MD2_WITH_RSA_ENCRYPTION].notPolicyFlags = ~0;
2172
1
        xOids[SEC_OID_PKCS1_MD4_WITH_RSA_ENCRYPTION].notPolicyFlags = ~0;
2173
1
        xOids[SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION].notPolicyFlags = ~0;
2174
1
        xOids[SEC_OID_PKCS5_PBE_WITH_MD2_AND_DES_CBC].notPolicyFlags = ~0;
2175
1
        xOids[SEC_OID_PKCS5_PBE_WITH_MD5_AND_DES_CBC].notPolicyFlags = ~0;
2176
1
    }
2177
2178
    /* turn off NSS_USE_POLICY_IN_SSL by default */
2179
1
    xOids[SEC_OID_APPLY_SSL_POLICY].notPolicyFlags = NSS_USE_POLICY_IN_SSL;
2180
2181
1
    envVal = PR_GetEnvSecure("NSS_HASH_ALG_SUPPORT");
2182
1
    if (envVal)
2183
0
        handleHashAlgSupport(envVal);
2184
2185
1
    if (secoid_InitDynOidData() != SECSuccess) {
2186
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2187
0
        PORT_Assert(0); /* this function should never fail */
2188
0
        return SECFailure;
2189
0
    }
2190
2191
1
    oidhash = PL_NewHashTable(0, SECITEM_Hash, SECITEM_HashCompare,
2192
1
                              PL_CompareValues, NULL, NULL);
2193
1
    oidmechhash = PL_NewHashTable(0, secoid_HashNumber, PL_CompareValues,
2194
1
                                  PL_CompareValues, NULL, NULL);
2195
2196
1
    if (!oidhash || !oidmechhash) {
2197
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2198
0
        PORT_Assert(0); /*This function should never fail. */
2199
0
        return (SECFailure);
2200
0
    }
2201
2202
386
    for (i = 0; i < SEC_OID_TOTAL; i++) {
2203
385
        oid = &oids[i];
2204
385
        PORT_Assert(oid->offset == i);
2205
385
        entry = PL_HashTableAdd(oidhash, &oid->oid, (void *)oid);
2206
2207
385
        if (entry == NULL) {
2208
0
            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2209
0
            PORT_Assert(0); /*This function should never fail. */
2210
0
            return (SECFailure);
2211
0
        }
2212
2213
385
        if (oid->mechanism != CKM_INVALID_MECHANISM) {
2214
104
            entry = PL_HashTableAdd(oidmechhash,
2215
104
                                    (void *)(uintptr_t)oid->mechanism, (void *)oid);
2216
104
            if (entry == NULL) {
2217
0
                PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2218
0
                PORT_Assert(0); /* This function should never fail. */
2219
0
                return (SECFailure);
2220
0
            }
2221
104
        }
2222
385
    }
2223
2224
1
    PORT_Assert(i == SEC_OID_TOTAL);
2225
2226
1
    return (SECSuccess);
2227
1
}
2228
2229
SECOidData *
2230
SECOID_FindOIDByMechanism(unsigned long mechanism)
2231
0
{
2232
0
    SECOidData *ret;
2233
2234
0
    PR_ASSERT(oidmechhash != NULL);
2235
0
    if (oidmechhash == NULL && SECOID_Init() != SECSuccess) {
2236
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2237
0
        return NULL;
2238
0
    }
2239
2240
0
    ret = PL_HashTableLookupConst(oidmechhash, (void *)(uintptr_t)mechanism);
2241
0
    if (ret == NULL) {
2242
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2243
0
    }
2244
2245
0
    return (ret);
2246
0
}
2247
2248
SECOidData *
2249
SECOID_FindOID(const SECItem *oid)
2250
16.7k
{
2251
16.7k
    SECOidData *ret;
2252
2253
16.7k
    PR_ASSERT(oidhash != NULL);
2254
16.7k
    if (oidhash == NULL && SECOID_Init() != SECSuccess) {
2255
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2256
0
        return NULL;
2257
0
    }
2258
2259
16.7k
    ret = PL_HashTableLookupConst(oidhash, oid);
2260
16.7k
    if (ret == NULL) {
2261
4
        ret = secoid_FindDynamic(oid);
2262
4
        if (ret == NULL) {
2263
4
            PORT_SetError(SEC_ERROR_UNRECOGNIZED_OID);
2264
4
        }
2265
4
    }
2266
16.7k
    return (ret);
2267
16.7k
}
2268
2269
SECOidTag
2270
SECOID_FindOIDTag(const SECItem *oid)
2271
16.7k
{
2272
16.7k
    SECOidData *oiddata;
2273
2274
16.7k
    oiddata = SECOID_FindOID(oid);
2275
16.7k
    if (oiddata == NULL) {
2276
0
        return SEC_OID_UNKNOWN;
2277
0
    }
2278
2279
16.7k
    return oiddata->offset;
2280
16.7k
}
2281
2282
/* This really should return const. */
2283
SECOidData *
2284
SECOID_FindOIDByTag(SECOidTag tagnum)
2285
18.6k
{
2286
18.6k
    if (tagnum >= SEC_OID_TOTAL) {
2287
0
        return (SECOidData *)secoid_FindDynamicByTag(tagnum);
2288
0
    }
2289
2290
18.6k
    PORT_Assert((unsigned int)tagnum < SEC_OID_TOTAL);
2291
18.6k
    return (SECOidData *)(&oids[tagnum]);
2292
18.6k
}
2293
2294
PRBool
2295
SECOID_KnownCertExtenOID(SECItem *extenOid)
2296
0
{
2297
0
    SECOidData *oidData;
2298
2299
0
    oidData = SECOID_FindOID(extenOid);
2300
0
    if (oidData == (SECOidData *)NULL)
2301
0
        return (PR_FALSE);
2302
0
    return ((oidData->supportedExtension == SUPPORTED_CERT_EXTENSION) ? PR_TRUE : PR_FALSE);
2303
0
}
2304
2305
const char *
2306
SECOID_FindOIDTagDescription(SECOidTag tagnum)
2307
0
{
2308
0
    const SECOidData *oidData = SECOID_FindOIDByTag(tagnum);
2309
0
    return oidData ? oidData->desc : 0;
2310
0
}
2311
2312
/* --------- opaque extended OID table accessor functions ---------------*/
2313
/*
2314
 * Any of these functions may return SECSuccess or SECFailure with the error
2315
 * code set to SEC_ERROR_UNKNOWN_OBJECT_TYPE if the SECOidTag is out of range.
2316
 */
2317
2318
static privXOid *
2319
secoid_FindXOidByTag(SECOidTag tagnum)
2320
619k
{
2321
619k
    if (tagnum >= SEC_OID_TOTAL) {
2322
0
        dynXOid *dxo = secoid_FindDynamicByTag(tagnum);
2323
0
        return (dxo ? &dxo->priv : NULL);
2324
0
    }
2325
2326
619k
    PORT_Assert((unsigned int)tagnum < SEC_OID_TOTAL);
2327
619k
    return &xOids[tagnum];
2328
619k
}
2329
2330
/* The Get function outputs the 32-bit value associated with the SECOidTag.
2331
 * Flags bits are the NSS_USE_ALG_ #defines in "secoidt.h".
2332
 * Default value for any algorithm is 0xffffffff (enabled for all purposes).
2333
 * No value is output if function returns SECFailure.
2334
 */
2335
SECStatus
2336
NSS_GetAlgorithmPolicy(SECOidTag tag, PRUint32 *pValue)
2337
619k
{
2338
619k
    privXOid *pxo = secoid_FindXOidByTag(tag);
2339
619k
    if (!pxo)
2340
0
        return SECFailure;
2341
619k
    if (!pValue) {
2342
0
        PORT_SetError(SEC_ERROR_INVALID_ARGS);
2343
0
        return SECFailure;
2344
0
    }
2345
619k
    *pValue = ~(pxo->notPolicyFlags);
2346
619k
    return SECSuccess;
2347
619k
}
2348
2349
static PRBool nss_policy_locked = PR_FALSE;
2350
2351
/* The Set function modifies the stored value according to the following
2352
 * algorithm:
2353
 *   policy[tag] = (policy[tag] & ~clearBits) | setBits;
2354
 */
2355
SECStatus
2356
NSS_SetAlgorithmPolicy(SECOidTag tag, PRUint32 setBits, PRUint32 clearBits)
2357
0
{
2358
0
    privXOid *pxo = secoid_FindXOidByTag(tag);
2359
0
    PRUint32 policyFlags;
2360
0
    if (!pxo)
2361
0
        return SECFailure;
2362
2363
0
    if (nss_policy_locked) {
2364
0
        PORT_SetError(SEC_ERROR_POLICY_LOCKED);
2365
0
        return SECFailure;
2366
0
    }
2367
    /* The stored policy flags are the ones complement of the flags as
2368
     * seen by the user.  This is not atomic, but these changes should
2369
     * be done rarely, e.g. at initialization time.
2370
     */
2371
0
    policyFlags = ~(pxo->notPolicyFlags);
2372
0
    policyFlags = (policyFlags & ~clearBits) | setBits;
2373
0
    pxo->notPolicyFlags = ~policyFlags;
2374
0
    return SECSuccess;
2375
0
}
2376
2377
/* Get the state of nss_policy_locked */
2378
PRBool
2379
NSS_IsPolicyLocked(void)
2380
0
{
2381
0
    return nss_policy_locked;
2382
0
}
2383
2384
/* Once the policy is locked, it can't be unlocked */
2385
void
2386
NSS_LockPolicy(void)
2387
0
{
2388
0
    nss_policy_locked = PR_TRUE;
2389
0
}
2390
2391
/* --------- END OF opaque extended OID table accessor functions ---------*/
2392
2393
/* for now, this is only used in a single place, so it can remain static */
2394
static PRBool parentForkedAfterC_Initialize;
2395
2396
#define SKIP_AFTER_FORK(x)              \
2397
3
    if (!parentForkedAfterC_Initialize) \
2398
3
    x
2399
2400
/*
2401
 * free up the oid tables.
2402
 */
2403
SECStatus
2404
SECOID_Shutdown(void)
2405
2
{
2406
2
    if (oidhash) {
2407
1
        PL_HashTableDestroy(oidhash);
2408
1
        oidhash = NULL;
2409
1
    }
2410
2
    if (oidmechhash) {
2411
1
        PL_HashTableDestroy(oidmechhash);
2412
1
        oidmechhash = NULL;
2413
1
    }
2414
    /* Have to handle the case where the lock was created, but
2415
    ** the pool wasn't.
2416
    ** I'm not going to attempt to create the lock, just to protect
2417
    ** the destruction of data that probably isn't initialized anyway.
2418
    */
2419
2
    if (dynOidLock) {
2420
1
        SKIP_AFTER_FORK(NSSRWLock_LockWrite(dynOidLock));
2421
1
        if (dynOidHash) {
2422
0
            PL_HashTableDestroy(dynOidHash);
2423
0
            dynOidHash = NULL;
2424
0
        }
2425
1
        if (dynOidPool) {
2426
1
            PORT_FreeArena(dynOidPool, PR_FALSE);
2427
1
            dynOidPool = NULL;
2428
1
        }
2429
1
        if (dynOidTable) {
2430
0
            PORT_Free(dynOidTable);
2431
0
            dynOidTable = NULL;
2432
0
        }
2433
1
        dynOidEntriesAllocated = 0;
2434
1
        dynOidEntriesUsed = 0;
2435
2436
1
        SKIP_AFTER_FORK(NSSRWLock_UnlockWrite(dynOidLock));
2437
1
        SKIP_AFTER_FORK(NSSRWLock_Destroy(dynOidLock));
2438
1
        dynOidLock = NULL;
2439
1
    } else {
2440
        /* Since dynOidLock doesn't exist, then all the data it protects
2441
        ** should be uninitialized.  We'll check that (in DEBUG builds),
2442
        ** and then make sure it is so, in case NSS is reinitialized.
2443
        */
2444
1
        PORT_Assert(!dynOidHash && !dynOidPool && !dynOidTable &&
2445
1
                    !dynOidEntriesAllocated && !dynOidEntriesUsed);
2446
1
        dynOidHash = NULL;
2447
1
        dynOidPool = NULL;
2448
1
        dynOidTable = NULL;
2449
1
        dynOidEntriesAllocated = 0;
2450
1
        dynOidEntriesUsed = 0;
2451
1
    }
2452
    /* we are trashing the old policy state now, also reenable changing
2453
     * the policy as well */
2454
2
    nss_policy_locked = PR_FALSE;
2455
2
    memset(xOids, 0, sizeof xOids);
2456
2
    return SECSuccess;
2457
2
}
2458
2459
void
2460
UTIL_SetForkState(PRBool forked)
2461
2
{
2462
2
    parentForkedAfterC_Initialize = forked;
2463
2
}
2464
2465
const char *
2466
NSSUTIL_GetVersion(void)
2467
0
{
2468
0
    return NSSUTIL_VERSION;
2469
0
}