Coverage Report

Created: 2025-07-01 06:25

/src/nss/lib/util/secoid.c
Line
Count
Source (jump to first uncovered line)
1
/* This Source Code Form is subject to the terms of the Mozilla Public
2
 * License, v. 2.0. If a copy of the MPL was not distributed with this
3
 * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
4
5
#include "secoid.h"
6
#include "pkcs11t.h"
7
#include "secitem.h"
8
#include "secerr.h"
9
#include "prenv.h"
10
#include "plhash.h"
11
#include "nssrwlk.h"
12
#include "nssutil.h"
13
#include "secoidt.h"
14
15
/* Library identity and versioning */
16
17
#if defined(DEBUG)
18
#define _DEBUG_STRING " (debug)"
19
#else
20
#define _DEBUG_STRING ""
21
#endif
22
23
/*
24
 * Version information
25
 */
26
const char __nss_util_version[] = "Version: NSS " NSSUTIL_VERSION _DEBUG_STRING;
27
28
/* MISSI Mosaic Object ID space */
29
/* USGov algorithm OID space: { 2 16 840 1 101 } */
30
#define USGOV 0x60, 0x86, 0x48, 0x01, 0x65
31
#define MISSI USGOV, 0x02, 0x01, 0x01
32
#define MISSI_OLD_KEA_DSS MISSI, 0x0c
33
#define MISSI_OLD_DSS MISSI, 0x02
34
#define MISSI_KEA_DSS MISSI, 0x14
35
#define MISSI_DSS MISSI, 0x13
36
#define MISSI_KEA MISSI, 0x0a
37
#define MISSI_ALT_KEA MISSI, 0x16
38
39
#define NISTALGS USGOV, 3, 4
40
#define AES NISTALGS, 1
41
#define SHAXXX NISTALGS, 2
42
#define DSA2 NISTALGS, 3
43
44
/**
45
 ** The Netscape OID space is allocated by Terry Hayes.  If you need
46
 ** a piece of the space, contact him at thayes@netscape.com.
47
 **/
48
49
/* Netscape Communications Corporation Object ID space */
50
/* { 2 16 840 1 113730 } */
51
#define NETSCAPE_OID 0x60, 0x86, 0x48, 0x01, 0x86, 0xf8, 0x42
52
#define NETSCAPE_CERT_EXT NETSCAPE_OID, 0x01
53
#define NETSCAPE_DATA_TYPE NETSCAPE_OID, 0x02
54
/* netscape directory oid - owned by Mark Smith (mcs@netscape.com) */
55
#define NETSCAPE_DIRECTORY NETSCAPE_OID, 0x03
56
#define NETSCAPE_POLICY NETSCAPE_OID, 0x04
57
#define NETSCAPE_CERT_SERVER NETSCAPE_OID, 0x05
58
#define NETSCAPE_ALGS NETSCAPE_OID, 0x06 /* algorithm OIDs */
59
#define NETSCAPE_NAME_COMPONENTS NETSCAPE_OID, 0x07
60
61
#define NETSCAPE_CERT_EXT_AIA NETSCAPE_CERT_EXT, 0x10
62
#define NETSCAPE_CERT_SERVER_CRMF NETSCAPE_CERT_SERVER, 0x01
63
64
/* these are old and should go away soon */
65
#define OLD_NETSCAPE 0x60, 0x86, 0x48, 0xd8, 0x6a
66
#define NS_CERT_EXT OLD_NETSCAPE, 0x01
67
#define NS_FILE_TYPE OLD_NETSCAPE, 0x02
68
#define NS_IMAGE_TYPE OLD_NETSCAPE, 0x03
69
70
/* RSA OID name space */
71
#define RSADSI 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d
72
#define PKCS RSADSI, 0x01
73
#define DIGEST RSADSI, 0x02
74
#define CIPHER RSADSI, 0x03
75
#define PKCS1 PKCS, 0x01
76
#define PKCS5 PKCS, 0x05
77
#define PKCS7 PKCS, 0x07
78
#define PKCS9 PKCS, 0x09
79
#define PKCS12 PKCS, 0x0c
80
81
/* Other OID name spaces */
82
#define ALGORITHM 0x2b, 0x0e, 0x03, 0x02
83
#define X500 0x55
84
#define X520_ATTRIBUTE_TYPE X500, 0x04
85
#define X500_ALG X500, 0x08
86
#define X500_ALG_ENCRYPTION X500_ALG, 0x01
87
88
/** X.509 v3 Extension OID
89
 ** {joint-iso-ccitt (2) ds(5) 29}
90
 **/
91
#define ID_CE_OID X500, 0x1d
92
93
#define RFC1274_ATTR_TYPE 0x09, 0x92, 0x26, 0x89, 0x93, 0xf2, 0x2c, 0x64, 0x1
94
/* #define RFC2247_ATTR_TYPE  0x09, 0x92, 0x26, 0xf5, 0x98, 0x1e, 0x64, 0x1 this is WRONG! */
95
96
/* PKCS #12 name spaces */
97
#define PKCS12_MODE_IDS PKCS12, 0x01
98
#define PKCS12_ESPVK_IDS PKCS12, 0x02
99
#define PKCS12_BAG_IDS PKCS12, 0x03
100
#define PKCS12_CERT_BAG_IDS PKCS12, 0x04
101
#define PKCS12_OIDS PKCS12, 0x05
102
#define PKCS12_PBE_IDS PKCS12_OIDS, 0x01
103
#define PKCS12_ENVELOPING_IDS PKCS12_OIDS, 0x02
104
#define PKCS12_SIGNATURE_IDS PKCS12_OIDS, 0x03
105
#define PKCS12_V2_PBE_IDS PKCS12, 0x01
106
#define PKCS9_CERT_TYPES PKCS9, 0x16
107
#define PKCS9_CRL_TYPES PKCS9, 0x17
108
#define PKCS9_SMIME_IDS PKCS9, 0x10
109
#define PKCS9_SMIME_ATTRS PKCS9_SMIME_IDS, 2
110
#define PKCS9_SMIME_ALGS PKCS9_SMIME_IDS, 3
111
#define PKCS12_VERSION1 PKCS12, 0x0a
112
#define PKCS12_V1_BAG_IDS PKCS12_VERSION1, 1
113
114
/* for DSA algorithm */
115
/* { iso(1) member-body(2) us(840) x9-57(10040) x9algorithm(4) } */
116
#define ANSI_X9_ALGORITHM 0x2a, 0x86, 0x48, 0xce, 0x38, 0x4
117
118
/* for DH algorithm */
119
/* { iso(1) member-body(2) us(840) x9-57(10046) number-type(2) } */
120
/* need real OID person to look at this, copied the above line
121
 * and added 6 to second to last value (and changed '4' to '2' */
122
#define ANSI_X942_ALGORITHM 0x2a, 0x86, 0x48, 0xce, 0x3e, 0x2
123
124
#define VERISIGN 0x60, 0x86, 0x48, 0x01, 0x86, 0xf8, 0x45
125
126
#define INTERNET_SECURITY_MECH 0x2b, 0x06, 0x01, 0x05, 0x05
127
128
#define PKIX INTERNET_SECURITY_MECH, 0x07
129
#define PKIX_CERT_EXTENSIONS PKIX, 1
130
#define PKIX_POLICY_QUALIFIERS PKIX, 2
131
#define PKIX_KEY_USAGE PKIX, 3
132
#define PKIX_ACCESS_DESCRIPTION PKIX, 0x30
133
#define PKIX_OCSP PKIX_ACCESS_DESCRIPTION, 1
134
#define PKIX_CA_ISSUERS PKIX_ACCESS_DESCRIPTION, 2
135
136
#define PKIX_ID_PKIP PKIX, 5
137
#define PKIX_ID_REGCTRL PKIX_ID_PKIP, 1
138
#define PKIX_ID_REGINFO PKIX_ID_PKIP, 2
139
140
/* Microsoft Object ID space */
141
/* { 1.3.6.1.4.1.311 } */
142
#define MICROSOFT_OID 0x2b, 0x6, 0x1, 0x4, 0x1, 0x82, 0x37
143
#define EV_NAME_ATTRIBUTE MICROSOFT_OID, 60, 2, 1
144
145
/* Microsoft Crypto 2.0 ID space */
146
/* { 1.3.6.1.4.1.311.10 } */
147
#define MS_CRYPTO_20 MICROSOFT_OID, 10
148
/* Microsoft Crypto 2.0 Extended Key Usage ID space */
149
/* { 1.3.6.1.4.1.311.10.3 } */
150
#define MS_CRYPTO_EKU MS_CRYPTO_20, 3
151
152
#define CERTICOM_OID 0x2b, 0x81, 0x04
153
#define SECG_OID CERTICOM_OID, 0x00
154
155
#define ANSI_X962_OID 0x2a, 0x86, 0x48, 0xce, 0x3d
156
#define ANSI_X962_CURVE_OID ANSI_X962_OID, 0x03
157
#define ANSI_X962_GF2m_OID ANSI_X962_CURVE_OID, 0x00
158
#define ANSI_X962_GFp_OID ANSI_X962_CURVE_OID, 0x01
159
#define ANSI_X962_SIGNATURE_OID ANSI_X962_OID, 0x04
160
#define ANSI_X962_SPECIFY_OID ANSI_X962_SIGNATURE_OID, 0x03
161
162
#define X9_63_SCHEME 0x2B, 0x81, 0x05, 0x10, 0x86, 0x48, 0x3F, 0x00
163
#define SECG_SCHEME CERTICOM_OID, 0x01
164
165
/* for Camellia: iso(1) member-body(2) jisc(392)
166
 *    mitsubishi(200011) isl(61) security(1) algorithm(1)
167
 */
168
#define MITSUBISHI_ALG 0x2a, 0x83, 0x08, 0x8c, 0x9a, 0x4b, 0x3d, 0x01, 0x01
169
#define CAMELLIA_ENCRYPT_OID MITSUBISHI_ALG, 1
170
#define CAMELLIA_WRAP_OID MITSUBISHI_ALG, 3
171
172
/* For IDEA: 1.3.6.1.4.1.188.7.1.1
173
 */
174
#define ASCOM_OID 0x2b, 0x6, 0x1, 0x4, 0x1, 0xbc
175
#define ASCOM_IDEA_ALG ASCOM_OID, 0x7, 0x1, 0x1
176
177
/* for SEED : iso(1) member-body(2) korea(410)
178
 *    kisa(200004) algorithm(1)
179
 */
180
#define SEED_OID 0x2a, 0x83, 0x1a, 0x8c, 0x9a, 0x44, 0x01
181
182
#define CONST_OID static const unsigned char
183
184
CONST_OID md2[] = { DIGEST, 0x02 };
185
CONST_OID md4[] = { DIGEST, 0x04 };
186
CONST_OID md5[] = { DIGEST, 0x05 };
187
CONST_OID hmac_sha1[] = { DIGEST, 7 };
188
CONST_OID hmac_sha224[] = { DIGEST, 8 };
189
CONST_OID hmac_sha256[] = { DIGEST, 9 };
190
CONST_OID hmac_sha384[] = { DIGEST, 10 };
191
CONST_OID hmac_sha512[] = { DIGEST, 11 };
192
193
CONST_OID rc2cbc[] = { CIPHER, 0x02 };
194
CONST_OID rc4[] = { CIPHER, 0x04 };
195
CONST_OID desede3cbc[] = { CIPHER, 0x07 };
196
CONST_OID rc5cbcpad[] = { CIPHER, 0x09 };
197
198
CONST_OID desecb[] = { ALGORITHM, 0x06 };
199
CONST_OID descbc[] = { ALGORITHM, 0x07 };
200
CONST_OID desofb[] = { ALGORITHM, 0x08 };
201
CONST_OID descfb[] = { ALGORITHM, 0x09 };
202
CONST_OID desmac[] = { ALGORITHM, 0x0a };
203
CONST_OID sdn702DSASignature[] = { ALGORITHM, 0x0c };
204
CONST_OID isoSHAWithRSASignature[] = { ALGORITHM, 0x0f };
205
CONST_OID desede[] = { ALGORITHM, 0x11 };
206
CONST_OID sha1[] = { ALGORITHM, 0x1a };
207
CONST_OID bogusDSASignaturewithSHA1Digest[] = { ALGORITHM, 0x1b };
208
CONST_OID isoSHA1WithRSASignature[] = { ALGORITHM, 0x1d };
209
210
CONST_OID pkcs1RSAEncryption[] = { PKCS1, 0x01 };
211
CONST_OID pkcs1MD2WithRSAEncryption[] = { PKCS1, 0x02 };
212
CONST_OID pkcs1MD4WithRSAEncryption[] = { PKCS1, 0x03 };
213
CONST_OID pkcs1MD5WithRSAEncryption[] = { PKCS1, 0x04 };
214
CONST_OID pkcs1SHA1WithRSAEncryption[] = { PKCS1, 0x05 };
215
CONST_OID pkcs1RSAOAEPEncryption[] = { PKCS1, 0x07 };
216
CONST_OID pkcs1MGF1[] = { PKCS1, 0x08 };
217
CONST_OID pkcs1PSpecified[] = { PKCS1, 0x09 };
218
CONST_OID pkcs1RSAPSSSignature[] = { PKCS1, 10 };
219
CONST_OID pkcs1SHA256WithRSAEncryption[] = { PKCS1, 11 };
220
CONST_OID pkcs1SHA384WithRSAEncryption[] = { PKCS1, 12 };
221
CONST_OID pkcs1SHA512WithRSAEncryption[] = { PKCS1, 13 };
222
CONST_OID pkcs1SHA224WithRSAEncryption[] = { PKCS1, 14 };
223
224
CONST_OID pkcs5PbeWithMD2AndDEScbc[] = { PKCS5, 0x01 };
225
CONST_OID pkcs5PbeWithMD5AndDEScbc[] = { PKCS5, 0x03 };
226
CONST_OID pkcs5PbeWithSha1AndDEScbc[] = { PKCS5, 0x0a };
227
CONST_OID pkcs5Pbkdf2[] = { PKCS5, 12 };
228
CONST_OID pkcs5Pbes2[] = { PKCS5, 13 };
229
CONST_OID pkcs5Pbmac1[] = { PKCS5, 14 };
230
231
CONST_OID pkcs7[] = { PKCS7 };
232
CONST_OID pkcs7Data[] = { PKCS7, 0x01 };
233
CONST_OID pkcs7SignedData[] = { PKCS7, 0x02 };
234
CONST_OID pkcs7EnvelopedData[] = { PKCS7, 0x03 };
235
CONST_OID pkcs7SignedEnvelopedData[] = { PKCS7, 0x04 };
236
CONST_OID pkcs7DigestedData[] = { PKCS7, 0x05 };
237
CONST_OID pkcs7EncryptedData[] = { PKCS7, 0x06 };
238
239
CONST_OID pkcs9EmailAddress[] = { PKCS9, 0x01 };
240
CONST_OID pkcs9UnstructuredName[] = { PKCS9, 0x02 };
241
CONST_OID pkcs9ContentType[] = { PKCS9, 0x03 };
242
CONST_OID pkcs9MessageDigest[] = { PKCS9, 0x04 };
243
CONST_OID pkcs9SigningTime[] = { PKCS9, 0x05 };
244
CONST_OID pkcs9CounterSignature[] = { PKCS9, 0x06 };
245
CONST_OID pkcs9ChallengePassword[] = { PKCS9, 0x07 };
246
CONST_OID pkcs9UnstructuredAddress[] = { PKCS9, 0x08 };
247
CONST_OID pkcs9ExtendedCertificateAttributes[] = { PKCS9, 0x09 };
248
CONST_OID pkcs9ExtensionRequest[] = { PKCS9, 14 };
249
CONST_OID pkcs9SMIMECapabilities[] = { PKCS9, 15 };
250
CONST_OID pkcs9FriendlyName[] = { PKCS9, 20 };
251
CONST_OID pkcs9LocalKeyID[] = { PKCS9, 21 };
252
253
CONST_OID pkcs9X509Certificate[] = { PKCS9_CERT_TYPES, 1 };
254
CONST_OID pkcs9SDSICertificate[] = { PKCS9_CERT_TYPES, 2 };
255
CONST_OID pkcs9X509CRL[] = { PKCS9_CRL_TYPES, 1 };
256
257
/* RFC2630 (CMS) OIDs */
258
CONST_OID cmsESDH[] = { PKCS9_SMIME_ALGS, 5 };
259
CONST_OID cms3DESwrap[] = { PKCS9_SMIME_ALGS, 6 };
260
CONST_OID cmsRC2wrap[] = { PKCS9_SMIME_ALGS, 7 };
261
262
/* RFC2633 SMIME message attributes */
263
CONST_OID smimeEncryptionKeyPreference[] = { PKCS9_SMIME_ATTRS, 11 };
264
CONST_OID ms_smimeEncryptionKeyPreference[] = { MICROSOFT_OID, 0x10, 0x4 };
265
266
CONST_OID x520CommonName[] = { X520_ATTRIBUTE_TYPE, 3 };
267
CONST_OID x520SurName[] = { X520_ATTRIBUTE_TYPE, 4 };
268
CONST_OID x520SerialNumber[] = { X520_ATTRIBUTE_TYPE, 5 };
269
CONST_OID x520CountryName[] = { X520_ATTRIBUTE_TYPE, 6 };
270
CONST_OID x520LocalityName[] = { X520_ATTRIBUTE_TYPE, 7 };
271
CONST_OID x520StateOrProvinceName[] = { X520_ATTRIBUTE_TYPE, 8 };
272
CONST_OID x520StreetAddress[] = { X520_ATTRIBUTE_TYPE, 9 };
273
CONST_OID x520OrgName[] = { X520_ATTRIBUTE_TYPE, 10 };
274
CONST_OID x520OrgUnitName[] = { X520_ATTRIBUTE_TYPE, 11 };
275
CONST_OID x520Title[] = { X520_ATTRIBUTE_TYPE, 12 };
276
CONST_OID x520BusinessCategory[] = { X520_ATTRIBUTE_TYPE, 15 };
277
CONST_OID x520PostalAddress[] = { X520_ATTRIBUTE_TYPE, 16 };
278
CONST_OID x520PostalCode[] = { X520_ATTRIBUTE_TYPE, 17 };
279
CONST_OID x520PostOfficeBox[] = { X520_ATTRIBUTE_TYPE, 18 };
280
CONST_OID x520Name[] = { X520_ATTRIBUTE_TYPE, 41 };
281
CONST_OID x520GivenName[] = { X520_ATTRIBUTE_TYPE, 42 };
282
CONST_OID x520Initials[] = { X520_ATTRIBUTE_TYPE, 43 };
283
CONST_OID x520GenerationQualifier[] = { X520_ATTRIBUTE_TYPE, 44 };
284
CONST_OID x520DnQualifier[] = { X520_ATTRIBUTE_TYPE, 46 };
285
CONST_OID x520HouseIdentifier[] = { X520_ATTRIBUTE_TYPE, 51 };
286
CONST_OID x520Pseudonym[] = { X520_ATTRIBUTE_TYPE, 65 };
287
288
CONST_OID nsTypeGIF[] = { NETSCAPE_DATA_TYPE, 0x01 };
289
CONST_OID nsTypeJPEG[] = { NETSCAPE_DATA_TYPE, 0x02 };
290
CONST_OID nsTypeURL[] = { NETSCAPE_DATA_TYPE, 0x03 };
291
CONST_OID nsTypeHTML[] = { NETSCAPE_DATA_TYPE, 0x04 };
292
CONST_OID nsTypeCertSeq[] = { NETSCAPE_DATA_TYPE, 0x05 };
293
294
CONST_OID missiCertKEADSSOld[] = { MISSI_OLD_KEA_DSS };
295
CONST_OID missiCertDSSOld[] = { MISSI_OLD_DSS };
296
CONST_OID missiCertKEADSS[] = { MISSI_KEA_DSS };
297
CONST_OID missiCertDSS[] = { MISSI_DSS };
298
CONST_OID missiCertKEA[] = { MISSI_KEA };
299
CONST_OID missiCertAltKEA[] = { MISSI_ALT_KEA };
300
CONST_OID x500RSAEncryption[] = { X500_ALG_ENCRYPTION, 0x01 };
301
302
/* added for alg 1485 */
303
CONST_OID rfc1274Uid[] = { RFC1274_ATTR_TYPE, 1 };
304
CONST_OID rfc1274Mail[] = { RFC1274_ATTR_TYPE, 3 };
305
CONST_OID rfc2247DomainComponent[] = { RFC1274_ATTR_TYPE, 25 };
306
307
/* Netscape private certificate extensions */
308
CONST_OID nsCertExtNetscapeOK[] = { NS_CERT_EXT, 1 };
309
CONST_OID nsCertExtIssuerLogo[] = { NS_CERT_EXT, 2 };
310
CONST_OID nsCertExtSubjectLogo[] = { NS_CERT_EXT, 3 };
311
CONST_OID nsExtCertType[] = { NETSCAPE_CERT_EXT, 0x01 };
312
CONST_OID nsExtBaseURL[] = { NETSCAPE_CERT_EXT, 0x02 };
313
CONST_OID nsExtRevocationURL[] = { NETSCAPE_CERT_EXT, 0x03 };
314
CONST_OID nsExtCARevocationURL[] = { NETSCAPE_CERT_EXT, 0x04 };
315
CONST_OID nsExtCACRLURL[] = { NETSCAPE_CERT_EXT, 0x05 };
316
CONST_OID nsExtCACertURL[] = { NETSCAPE_CERT_EXT, 0x06 };
317
CONST_OID nsExtCertRenewalURL[] = { NETSCAPE_CERT_EXT, 0x07 };
318
CONST_OID nsExtCAPolicyURL[] = { NETSCAPE_CERT_EXT, 0x08 };
319
CONST_OID nsExtHomepageURL[] = { NETSCAPE_CERT_EXT, 0x09 };
320
CONST_OID nsExtEntityLogo[] = { NETSCAPE_CERT_EXT, 0x0a };
321
CONST_OID nsExtUserPicture[] = { NETSCAPE_CERT_EXT, 0x0b };
322
CONST_OID nsExtSSLServerName[] = { NETSCAPE_CERT_EXT, 0x0c };
323
CONST_OID nsExtComment[] = { NETSCAPE_CERT_EXT, 0x0d };
324
325
/* the following 2 extensions are defined for and used by Cartman(NSM) */
326
CONST_OID nsExtLostPasswordURL[] = { NETSCAPE_CERT_EXT, 0x0e };
327
CONST_OID nsExtCertRenewalTime[] = { NETSCAPE_CERT_EXT, 0x0f };
328
329
CONST_OID nsExtAIACertRenewal[] = { NETSCAPE_CERT_EXT_AIA, 0x01 };
330
CONST_OID nsExtCertScopeOfUse[] = { NETSCAPE_CERT_EXT, 0x11 };
331
/* Reserved Netscape (2 16 840 1 113730 1 18) = { NETSCAPE_CERT_EXT, 0x12 }; */
332
333
/* Netscape policy values */
334
CONST_OID nsKeyUsageGovtApproved[] = { NETSCAPE_POLICY, 0x01 };
335
336
/* Netscape other name types */
337
CONST_OID netscapeNickname[] = { NETSCAPE_NAME_COMPONENTS, 0x01 };
338
CONST_OID netscapeAOLScreenname[] = { NETSCAPE_NAME_COMPONENTS, 0x02 };
339
340
/* OIDs needed for cert server */
341
CONST_OID netscapeRecoveryRequest[] = { NETSCAPE_CERT_SERVER_CRMF, 0x01 };
342
343
/* Standard x.509 v3 Certificate & CRL Extensions */
344
CONST_OID x509SubjectDirectoryAttr[] = { ID_CE_OID, 9 };
345
CONST_OID x509SubjectKeyID[] = { ID_CE_OID, 14 };
346
CONST_OID x509KeyUsage[] = { ID_CE_OID, 15 };
347
CONST_OID x509PrivateKeyUsagePeriod[] = { ID_CE_OID, 16 };
348
CONST_OID x509SubjectAltName[] = { ID_CE_OID, 17 };
349
CONST_OID x509IssuerAltName[] = { ID_CE_OID, 18 };
350
CONST_OID x509BasicConstraints[] = { ID_CE_OID, 19 };
351
CONST_OID x509CRLNumber[] = { ID_CE_OID, 20 };
352
CONST_OID x509ReasonCode[] = { ID_CE_OID, 21 };
353
CONST_OID x509HoldInstructionCode[] = { ID_CE_OID, 23 };
354
CONST_OID x509InvalidDate[] = { ID_CE_OID, 24 };
355
CONST_OID x509DeltaCRLIndicator[] = { ID_CE_OID, 27 };
356
CONST_OID x509IssuingDistributionPoint[] = { ID_CE_OID, 28 };
357
CONST_OID x509CertIssuer[] = { ID_CE_OID, 29 };
358
CONST_OID x509NameConstraints[] = { ID_CE_OID, 30 };
359
CONST_OID x509CRLDistPoints[] = { ID_CE_OID, 31 };
360
CONST_OID x509CertificatePolicies[] = { ID_CE_OID, 32 };
361
CONST_OID x509PolicyMappings[] = { ID_CE_OID, 33 };
362
CONST_OID x509AuthKeyID[] = { ID_CE_OID, 35 };
363
CONST_OID x509PolicyConstraints[] = { ID_CE_OID, 36 };
364
CONST_OID x509ExtKeyUsage[] = { ID_CE_OID, 37 };
365
CONST_OID x509FreshestCRL[] = { ID_CE_OID, 46 };
366
CONST_OID x509InhibitAnyPolicy[] = { ID_CE_OID, 54 };
367
368
CONST_OID x509CertificatePoliciesAnyPolicy[] = { ID_CE_OID, 32, 0 };
369
CONST_OID x509ExtKeyUsageAnyUsage[] = { ID_CE_OID, 37, 0 };
370
371
CONST_OID x509AuthInfoAccess[] = { PKIX_CERT_EXTENSIONS, 1 };
372
CONST_OID x509SubjectInfoAccess[] = { PKIX_CERT_EXTENSIONS, 11 };
373
374
CONST_OID x509SIATimeStamping[] = { PKIX_ACCESS_DESCRIPTION, 0x03 };
375
CONST_OID x509SIACaRepository[] = { PKIX_ACCESS_DESCRIPTION, 0x05 };
376
377
/* pkcs 12 additions */
378
CONST_OID pkcs12[] = { PKCS12 };
379
CONST_OID pkcs12ModeIDs[] = { PKCS12_MODE_IDS };
380
CONST_OID pkcs12ESPVKIDs[] = { PKCS12_ESPVK_IDS };
381
CONST_OID pkcs12BagIDs[] = { PKCS12_BAG_IDS };
382
CONST_OID pkcs12CertBagIDs[] = { PKCS12_CERT_BAG_IDS };
383
CONST_OID pkcs12OIDs[] = { PKCS12_OIDS };
384
CONST_OID pkcs12PBEIDs[] = { PKCS12_PBE_IDS };
385
CONST_OID pkcs12EnvelopingIDs[] = { PKCS12_ENVELOPING_IDS };
386
CONST_OID pkcs12SignatureIDs[] = { PKCS12_SIGNATURE_IDS };
387
CONST_OID pkcs12PKCS8KeyShrouding[] = { PKCS12_ESPVK_IDS, 0x01 };
388
CONST_OID pkcs12KeyBagID[] = { PKCS12_BAG_IDS, 0x01 };
389
CONST_OID pkcs12CertAndCRLBagID[] = { PKCS12_BAG_IDS, 0x02 };
390
CONST_OID pkcs12SecretBagID[] = { PKCS12_BAG_IDS, 0x03 };
391
CONST_OID pkcs12X509CertCRLBag[] = { PKCS12_CERT_BAG_IDS, 0x01 };
392
CONST_OID pkcs12SDSICertBag[] = { PKCS12_CERT_BAG_IDS, 0x02 };
393
CONST_OID pkcs12PBEWithSha1And128BitRC4[] = { PKCS12_PBE_IDS, 0x01 };
394
CONST_OID pkcs12PBEWithSha1And40BitRC4[] = { PKCS12_PBE_IDS, 0x02 };
395
CONST_OID pkcs12PBEWithSha1AndTripleDESCBC[] = { PKCS12_PBE_IDS, 0x03 };
396
CONST_OID pkcs12PBEWithSha1And128BitRC2CBC[] = { PKCS12_PBE_IDS, 0x04 };
397
CONST_OID pkcs12PBEWithSha1And40BitRC2CBC[] = { PKCS12_PBE_IDS, 0x05 };
398
CONST_OID pkcs12RSAEncryptionWith128BitRC4[] = { PKCS12_ENVELOPING_IDS, 0x01 };
399
CONST_OID pkcs12RSAEncryptionWith40BitRC4[] = { PKCS12_ENVELOPING_IDS, 0x02 };
400
CONST_OID pkcs12RSAEncryptionWithTripleDES[] = { PKCS12_ENVELOPING_IDS, 0x03 };
401
CONST_OID pkcs12RSASignatureWithSHA1Digest[] = { PKCS12_SIGNATURE_IDS, 0x01 };
402
403
/* pkcs 12 version 1.0 ids */
404
CONST_OID pkcs12V2PBEWithSha1And128BitRC4[] = { PKCS12_V2_PBE_IDS, 0x01 };
405
CONST_OID pkcs12V2PBEWithSha1And40BitRC4[] = { PKCS12_V2_PBE_IDS, 0x02 };
406
CONST_OID pkcs12V2PBEWithSha1And3KeyTripleDEScbc[] = { PKCS12_V2_PBE_IDS, 0x03 };
407
CONST_OID pkcs12V2PBEWithSha1And2KeyTripleDEScbc[] = { PKCS12_V2_PBE_IDS, 0x04 };
408
CONST_OID pkcs12V2PBEWithSha1And128BitRC2cbc[] = { PKCS12_V2_PBE_IDS, 0x05 };
409
CONST_OID pkcs12V2PBEWithSha1And40BitRC2cbc[] = { PKCS12_V2_PBE_IDS, 0x06 };
410
411
CONST_OID pkcs12SafeContentsID[] = { PKCS12_BAG_IDS, 0x04 };
412
CONST_OID pkcs12PKCS8ShroudedKeyBagID[] = { PKCS12_BAG_IDS, 0x05 };
413
414
CONST_OID pkcs12V1KeyBag[] = { PKCS12_V1_BAG_IDS, 0x01 };
415
CONST_OID pkcs12V1PKCS8ShroudedKeyBag[] = { PKCS12_V1_BAG_IDS, 0x02 };
416
CONST_OID pkcs12V1CertBag[] = { PKCS12_V1_BAG_IDS, 0x03 };
417
CONST_OID pkcs12V1CRLBag[] = { PKCS12_V1_BAG_IDS, 0x04 };
418
CONST_OID pkcs12V1SecretBag[] = { PKCS12_V1_BAG_IDS, 0x05 };
419
CONST_OID pkcs12V1SafeContentsBag[] = { PKCS12_V1_BAG_IDS, 0x06 };
420
421
/* The following encoding is INCORRECT, but correcting it would create a
422
 * duplicate OID in the table.  So, we will leave it alone.
423
 */
424
CONST_OID pkcs12KeyUsageAttr[] = { 2, 5, 29, 15 };
425
426
CONST_OID ansix9DSASignature[] = { ANSI_X9_ALGORITHM, 0x01 };
427
CONST_OID ansix9DSASignaturewithSHA1Digest[] = { ANSI_X9_ALGORITHM, 0x03 };
428
CONST_OID nistDSASignaturewithSHA224Digest[] = { DSA2, 0x01 };
429
CONST_OID nistDSASignaturewithSHA256Digest[] = { DSA2, 0x02 };
430
431
/* verisign OIDs */
432
CONST_OID verisignUserNotices[] = { VERISIGN, 1, 7, 1, 1 };
433
434
/* pkix OIDs */
435
CONST_OID pkixCPSPointerQualifier[] = { PKIX_POLICY_QUALIFIERS, 1 };
436
CONST_OID pkixUserNoticeQualifier[] = { PKIX_POLICY_QUALIFIERS, 2 };
437
438
CONST_OID pkixOCSP[] = { PKIX_OCSP };
439
CONST_OID pkixOCSPBasicResponse[] = { PKIX_OCSP, 1 };
440
CONST_OID pkixOCSPNonce[] = { PKIX_OCSP, 2 };
441
CONST_OID pkixOCSPCRL[] = { PKIX_OCSP, 3 };
442
CONST_OID pkixOCSPResponse[] = { PKIX_OCSP, 4 };
443
CONST_OID pkixOCSPNoCheck[] = { PKIX_OCSP, 5 };
444
CONST_OID pkixOCSPArchiveCutoff[] = { PKIX_OCSP, 6 };
445
CONST_OID pkixOCSPServiceLocator[] = { PKIX_OCSP, 7 };
446
447
CONST_OID pkixCAIssuers[] = { PKIX_CA_ISSUERS };
448
449
CONST_OID pkixRegCtrlRegToken[] = { PKIX_ID_REGCTRL, 1 };
450
CONST_OID pkixRegCtrlAuthenticator[] = { PKIX_ID_REGCTRL, 2 };
451
CONST_OID pkixRegCtrlPKIPubInfo[] = { PKIX_ID_REGCTRL, 3 };
452
CONST_OID pkixRegCtrlPKIArchOptions[] = { PKIX_ID_REGCTRL, 4 };
453
CONST_OID pkixRegCtrlOldCertID[] = { PKIX_ID_REGCTRL, 5 };
454
CONST_OID pkixRegCtrlProtEncKey[] = { PKIX_ID_REGCTRL, 6 };
455
CONST_OID pkixRegInfoUTF8Pairs[] = { PKIX_ID_REGINFO, 1 };
456
CONST_OID pkixRegInfoCertReq[] = { PKIX_ID_REGINFO, 2 };
457
458
CONST_OID pkixExtendedKeyUsageServerAuth[] = { PKIX_KEY_USAGE, 1 };
459
CONST_OID pkixExtendedKeyUsageClientAuth[] = { PKIX_KEY_USAGE, 2 };
460
CONST_OID pkixExtendedKeyUsageCodeSign[] = { PKIX_KEY_USAGE, 3 };
461
CONST_OID pkixExtendedKeyUsageEMailProtect[] = { PKIX_KEY_USAGE, 4 };
462
/* IPsecEnd, IPsecTunnel, and IPsecUser are deprecated, but still in use
463
 * (see RFC4945) */
464
CONST_OID pkixExtendedKeyUsageIPsecEnd[] = { PKIX_KEY_USAGE, 5 };
465
CONST_OID pkixExtendedKeyUsageIPsecTunnel[] = { PKIX_KEY_USAGE, 6 };
466
CONST_OID pkixExtendedKeyUsageIPsecUser[] = { PKIX_KEY_USAGE, 7 };
467
CONST_OID pkixExtendedKeyUsageTimeStamp[] = { PKIX_KEY_USAGE, 8 };
468
CONST_OID pkixOCSPResponderExtendedKeyUsage[] = { PKIX_KEY_USAGE, 9 };
469
/* 17 replaces 5 + 6 + 7 (declared obsolete in RFC 4945) */
470
CONST_OID pkixExtendedKeyUsageIPsecIKE[] = { PKIX_KEY_USAGE, 17 };
471
CONST_OID msExtendedKeyUsageTrustListSigning[] = { MS_CRYPTO_EKU, 1 };
472
473
CONST_OID ipsecIKEEnd[] = { INTERNET_SECURITY_MECH, 0x08, 0x02, 0x01 };
474
CONST_OID ipsecIKEIntermediate[] = { INTERNET_SECURITY_MECH, 0x08, 0x02, 0x02 };
475
476
/* OIDs for Netscape defined algorithms */
477
CONST_OID netscapeSMimeKEA[] = { NETSCAPE_ALGS, 0x01 };
478
479
/* Fortezza algorithm OIDs */
480
CONST_OID skipjackCBC[] = { MISSI, 0x04 };
481
CONST_OID dhPublicKey[] = { ANSI_X942_ALGORITHM, 0x1 };
482
483
CONST_OID idea_CBC[] = { ASCOM_IDEA_ALG, 2 };
484
CONST_OID aes128_GCM[] = { AES, 0x6 };
485
CONST_OID aes192_GCM[] = { AES, 0x1a };
486
CONST_OID aes256_GCM[] = { AES, 0x2e };
487
CONST_OID aes128_ECB[] = { AES, 1 };
488
CONST_OID aes128_CBC[] = { AES, 2 };
489
#ifdef DEFINE_ALL_AES_CIPHERS
490
CONST_OID aes128_OFB[] = { AES, 3 };
491
CONST_OID aes128_CFB[] = { AES, 4 };
492
#endif
493
CONST_OID aes128_KEY_WRAP[] = { AES, 5 };
494
495
CONST_OID aes192_ECB[] = { AES, 21 };
496
CONST_OID aes192_CBC[] = { AES, 22 };
497
#ifdef DEFINE_ALL_AES_CIPHERS
498
CONST_OID aes192_OFB[] = { AES, 23 };
499
CONST_OID aes192_CFB[] = { AES, 24 };
500
#endif
501
CONST_OID aes192_KEY_WRAP[] = { AES, 25 };
502
503
CONST_OID aes256_ECB[] = { AES, 41 };
504
CONST_OID aes256_CBC[] = { AES, 42 };
505
#ifdef DEFINE_ALL_AES_CIPHERS
506
CONST_OID aes256_OFB[] = { AES, 43 };
507
CONST_OID aes256_CFB[] = { AES, 44 };
508
#endif
509
CONST_OID aes256_KEY_WRAP[] = { AES, 45 };
510
511
CONST_OID camellia128_CBC[] = { CAMELLIA_ENCRYPT_OID, 2 };
512
CONST_OID camellia192_CBC[] = { CAMELLIA_ENCRYPT_OID, 3 };
513
CONST_OID camellia256_CBC[] = { CAMELLIA_ENCRYPT_OID, 4 };
514
515
CONST_OID sha256[] = { SHAXXX, 1 };
516
CONST_OID sha384[] = { SHAXXX, 2 };
517
CONST_OID sha512[] = { SHAXXX, 3 };
518
CONST_OID sha224[] = { SHAXXX, 4 };
519
520
CONST_OID sha3_224[] = { SHAXXX, 7 };
521
CONST_OID sha3_256[] = { SHAXXX, 8 };
522
CONST_OID sha3_384[] = { SHAXXX, 9 };
523
CONST_OID sha3_512[] = { SHAXXX, 10 };
524
525
CONST_OID hmac_sha3_224[] = { SHAXXX, 13 };
526
CONST_OID hmac_sha3_256[] = { SHAXXX, 14 };
527
CONST_OID hmac_sha3_384[] = { SHAXXX, 15 };
528
CONST_OID hmac_sha3_512[] = { SHAXXX, 16 };
529
530
CONST_OID ansix962ECPublicKey[] = { ANSI_X962_OID, 0x02, 0x01 };
531
CONST_OID ansix962SignaturewithSHA1Digest[] = { ANSI_X962_SIGNATURE_OID, 0x01 };
532
CONST_OID ansix962SignatureRecommended[] = { ANSI_X962_SIGNATURE_OID, 0x02 };
533
CONST_OID ansix962SignatureSpecified[] = { ANSI_X962_SPECIFY_OID };
534
CONST_OID ansix962SignaturewithSHA224Digest[] = { ANSI_X962_SPECIFY_OID, 0x01 };
535
CONST_OID ansix962SignaturewithSHA256Digest[] = { ANSI_X962_SPECIFY_OID, 0x02 };
536
CONST_OID ansix962SignaturewithSHA384Digest[] = { ANSI_X962_SPECIFY_OID, 0x03 };
537
CONST_OID ansix962SignaturewithSHA512Digest[] = { ANSI_X962_SPECIFY_OID, 0x04 };
538
539
/* ANSI X9.62 prime curve OIDs */
540
/* NOTE: prime192v1 is the same as secp192r1, prime256v1 is the
541
 * same as secp256r1
542
 */
543
CONST_OID ansiX962prime192v1[] = { ANSI_X962_GFp_OID, 0x01 }; /* unsupported by freebl */
544
CONST_OID ansiX962prime192v2[] = { ANSI_X962_GFp_OID, 0x02 }; /* unsupported by freebl */
545
CONST_OID ansiX962prime192v3[] = { ANSI_X962_GFp_OID, 0x03 }; /* unsupported by freebl */
546
CONST_OID ansiX962prime239v1[] = { ANSI_X962_GFp_OID, 0x04 }; /* unsupported by freebl */
547
CONST_OID ansiX962prime239v2[] = { ANSI_X962_GFp_OID, 0x05 }; /* unsupported by freebl */
548
CONST_OID ansiX962prime239v3[] = { ANSI_X962_GFp_OID, 0x06 }; /* unsupported by freebl */
549
CONST_OID ansiX962prime256v1[] = { ANSI_X962_GFp_OID, 0x07 };
550
551
/* SECG prime curve OIDs */
552
CONST_OID secgECsecp112r1[] = { SECG_OID, 0x06 }; /* unsupported by freebl */
553
CONST_OID secgECsecp112r2[] = { SECG_OID, 0x07 }; /* unsupported by freebl */
554
CONST_OID secgECsecp128r1[] = { SECG_OID, 0x1c }; /* unsupported by freebl */
555
CONST_OID secgECsecp128r2[] = { SECG_OID, 0x1d }; /* unsupported by freebl */
556
CONST_OID secgECsecp160k1[] = { SECG_OID, 0x09 }; /* unsupported by freebl */
557
CONST_OID secgECsecp160r1[] = { SECG_OID, 0x08 }; /* unsupported by freebl */
558
CONST_OID secgECsecp160r2[] = { SECG_OID, 0x1e }; /* unsupported by freebl */
559
CONST_OID secgECsecp192k1[] = { SECG_OID, 0x1f }; /* unsupported by freebl */
560
CONST_OID secgECsecp224k1[] = { SECG_OID, 0x20 }; /* unsupported by freebl */
561
CONST_OID secgECsecp224r1[] = { SECG_OID, 0x21 }; /* unsupported by freebl */
562
CONST_OID secgECsecp256k1[] = { SECG_OID, 0x0a }; /* unsupported by freebl */
563
CONST_OID secgECsecp384r1[] = { SECG_OID, 0x22 };
564
CONST_OID secgECsecp521r1[] = { SECG_OID, 0x23 };
565
566
/* ANSI X9.62 characteristic two curve OIDs */
567
CONST_OID ansiX962c2pnb163v1[] = { ANSI_X962_GF2m_OID, 0x01 }; /* unsupported by freebl */
568
CONST_OID ansiX962c2pnb163v2[] = { ANSI_X962_GF2m_OID, 0x02 }; /* unsupported by freebl */
569
CONST_OID ansiX962c2pnb163v3[] = { ANSI_X962_GF2m_OID, 0x03 }; /* unsupported by freebl */
570
CONST_OID ansiX962c2pnb176v1[] = { ANSI_X962_GF2m_OID, 0x04 }; /* unsupported by freebl */
571
CONST_OID ansiX962c2tnb191v1[] = { ANSI_X962_GF2m_OID, 0x05 }; /* unsupported by freebl */
572
CONST_OID ansiX962c2tnb191v2[] = { ANSI_X962_GF2m_OID, 0x06 }; /* unsupported by freebl */
573
CONST_OID ansiX962c2tnb191v3[] = { ANSI_X962_GF2m_OID, 0x07 }; /* unsupported by freebl */
574
CONST_OID ansiX962c2onb191v4[] = { ANSI_X962_GF2m_OID, 0x08 }; /* unsupported by freebl */
575
CONST_OID ansiX962c2onb191v5[] = { ANSI_X962_GF2m_OID, 0x09 }; /* unsupported by freebl */
576
CONST_OID ansiX962c2pnb208w1[] = { ANSI_X962_GF2m_OID, 0x0a }; /* unsupported by freebl */
577
CONST_OID ansiX962c2tnb239v1[] = { ANSI_X962_GF2m_OID, 0x0b }; /* unsupported by freebl */
578
CONST_OID ansiX962c2tnb239v2[] = { ANSI_X962_GF2m_OID, 0x0c }; /* unsupported by freebl */
579
CONST_OID ansiX962c2tnb239v3[] = { ANSI_X962_GF2m_OID, 0x0d }; /* unsupported by freebl */
580
CONST_OID ansiX962c2onb239v4[] = { ANSI_X962_GF2m_OID, 0x0e }; /* unsupported by freebl */
581
CONST_OID ansiX962c2onb239v5[] = { ANSI_X962_GF2m_OID, 0x0f }; /* unsupported by freebl */
582
CONST_OID ansiX962c2pnb272w1[] = { ANSI_X962_GF2m_OID, 0x10 }; /* unsupported by freebl */
583
CONST_OID ansiX962c2pnb304w1[] = { ANSI_X962_GF2m_OID, 0x11 }; /* unsupported by freebl */
584
CONST_OID ansiX962c2tnb359v1[] = { ANSI_X962_GF2m_OID, 0x12 }; /* unsupported by freebl */
585
CONST_OID ansiX962c2pnb368w1[] = { ANSI_X962_GF2m_OID, 0x13 }; /* unsupported by freebl */
586
CONST_OID ansiX962c2tnb431r1[] = { ANSI_X962_GF2m_OID, 0x14 }; /* unsupported by freebl */
587
588
/* SECG characterisitic two curve OIDs */
589
CONST_OID secgECsect113r1[] = { SECG_OID, 0x04 }; /* unsupported by freebl */
590
CONST_OID secgECsect113r2[] = { SECG_OID, 0x05 }; /* unsupported by freebl */
591
CONST_OID secgECsect131r1[] = { SECG_OID, 0x16 }; /* unsupported by freebl */
592
CONST_OID secgECsect131r2[] = { SECG_OID, 0x17 }; /* unsupported by freebl */
593
CONST_OID secgECsect163k1[] = { SECG_OID, 0x01 }; /* unsupported by freebl */
594
CONST_OID secgECsect163r1[] = { SECG_OID, 0x02 }; /* unsupported by freebl */
595
CONST_OID secgECsect163r2[] = { SECG_OID, 0x0f }; /* unsupported by freebl */
596
CONST_OID secgECsect193r1[] = { SECG_OID, 0x18 }; /* unsupported by freebl */
597
CONST_OID secgECsect193r2[] = { SECG_OID, 0x19 }; /* unsupported by freebl */
598
CONST_OID secgECsect233k1[] = { SECG_OID, 0x1a }; /* unsupported by freebl */
599
CONST_OID secgECsect233r1[] = { SECG_OID, 0x1b }; /* unsupported by freebl */
600
CONST_OID secgECsect239k1[] = { SECG_OID, 0x03 }; /* unsupported by freebl */
601
CONST_OID secgECsect283k1[] = { SECG_OID, 0x10 }; /* unsupported by freebl */
602
CONST_OID secgECsect283r1[] = { SECG_OID, 0x11 }; /* unsupported by freebl */
603
CONST_OID secgECsect409k1[] = { SECG_OID, 0x24 }; /* unsupported by freebl */
604
CONST_OID secgECsect409r1[] = { SECG_OID, 0x25 }; /* unsupported by freebl */
605
CONST_OID secgECsect571k1[] = { SECG_OID, 0x26 }; /* unsupported by freebl */
606
CONST_OID secgECsect571r1[] = { SECG_OID, 0x27 }; /* unsupported by freebl */
607
608
/* Diffie-Hellman key agreement algorithms */
609
CONST_OID dhSinglePassstdDHsha1kdfscheme[] = { X9_63_SCHEME, 0x02 };
610
CONST_OID dhSinglePassstdDHsha224kdfscheme[] = { SECG_SCHEME, 0x0B, 0x00 };
611
CONST_OID dhSinglePassstdDHsha256kdfscheme[] = { SECG_SCHEME, 0x0B, 0x01 };
612
CONST_OID dhSinglePassstdDHsha384kdfscheme[] = { SECG_SCHEME, 0x0B, 0x02 };
613
CONST_OID dhSinglePassstdDHsha512kdfscheme[] = { SECG_SCHEME, 0x0B, 0x03 };
614
CONST_OID dhSinglePasscofactorDHsha1kdfscheme[] = { X9_63_SCHEME, 0x03 };
615
CONST_OID dhSinglePasscofactorDHsha224kdfscheme[] = { SECG_SCHEME, 0x0E, 0x00 };
616
CONST_OID dhSinglePasscofactorDHsha256kdfscheme[] = { SECG_SCHEME, 0x0E, 0x01 };
617
CONST_OID dhSinglePasscofactorDHsha384kdfscheme[] = { SECG_SCHEME, 0x0E, 0x02 };
618
CONST_OID dhSinglePasscofactorDHsha512kdfscheme[] = { SECG_SCHEME, 0x0E, 0x03 };
619
620
CONST_OID seed_CBC[] = { SEED_OID, 4 };
621
622
CONST_OID evIncorporationLocality[] = { EV_NAME_ATTRIBUTE, 1 };
623
CONST_OID evIncorporationState[] = { EV_NAME_ATTRIBUTE, 2 };
624
CONST_OID evIncorporationCountry[] = { EV_NAME_ATTRIBUTE, 3 };
625
626
/* https://tools.ietf.org/html/draft-josefsson-pkix-newcurves-01
627
 * 1.3.6.1.4.1.11591.15.1
628
 */
629
CONST_OID curve25519[] = { 0x2B, 0x06, 0x01, 0x04, 0x01, 0xDA, 0x47, 0x0F, 0x01 };
630
631
/*
632
        https://oid-rep.orange-labs.fr/get/1.3.101.112
633
        A.1.  ASN.1 Object for Ed25519
634
        id-Ed25519 OBJECT IDENTIFIER ::= { 1.3.101.112 }
635
        Parameters are absent.  Length is 7 bytes.
636
        Binary encoding: 3005 0603 2B65 70
637
638
        The same algorithm identifiers are used for identifying a public key,
639
        a private key, and a signature (for the two EdDSA related OIDs).
640
        Additional encoding information is provided below for each of these
641
        locations.
642
*/
643
644
CONST_OID ed25519PublicKey[] = { 0x2B, 0x65, 0x70 };
645
CONST_OID ed25519Signature[] = { 0x2B, 0x65, 0x70 };
646
647
/*https://www.rfc-editor.org/rfc/rfc8410#section-3*/
648
CONST_OID x25519PublicKey[] = { 0x2b, 0x65, 0x6e };
649
650
#define OI(x)                                  \
651
    {                                          \
652
        siDEROID, (unsigned char *)x, sizeof x \
653
    }
654
#ifndef SECOID_NO_STRINGS
655
#define OD(oid, tag, desc, mech, ext) \
656
    {                                 \
657
        OI(oid)                       \
658
        , tag, desc, mech, ext        \
659
    }
660
#define ODE(tag, desc, mech, ext)                   \
661
    {                                               \
662
        { siDEROID, NULL, 0 }, tag, desc, mech, ext \
663
    }
664
#else
665
#define OD(oid, tag, desc, mech, ext) \
666
    {                                 \
667
        OI(oid)                       \
668
        , tag, 0, mech, ext           \
669
    }
670
#define ODE(tag, desc, mech, ext)                \
671
    {                                            \
672
        { siDEROID, NULL, 0 }, tag, 0, mech, ext \
673
    }
674
#endif
675
676
#if defined(NSS_ALLOW_UNSUPPORTED_CRITICAL)
677
#define FAKE_SUPPORTED_CERT_EXTENSION SUPPORTED_CERT_EXTENSION
678
#else
679
#define FAKE_SUPPORTED_CERT_EXTENSION UNSUPPORTED_CERT_EXTENSION
680
#endif
681
682
/*
683
 * NOTE: the order of these entries must mach the SECOidTag enum in secoidt.h!
684
 */
685
const static SECOidData oids[SEC_OID_TOTAL] = {
686
    { { siDEROID, NULL, 0 }, SEC_OID_UNKNOWN, "Unknown OID", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION },
687
    OD(md2, SEC_OID_MD2, "MD2", CKM_MD2, INVALID_CERT_EXTENSION),
688
    OD(md4, SEC_OID_MD4,
689
       "MD4", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
690
    OD(md5, SEC_OID_MD5, "MD5", CKM_MD5, INVALID_CERT_EXTENSION),
691
    OD(sha1, SEC_OID_SHA1, "SHA-1", CKM_SHA_1, INVALID_CERT_EXTENSION),
692
    OD(rc2cbc, SEC_OID_RC2_CBC,
693
       "RC2-CBC", CKM_RC2_CBC, INVALID_CERT_EXTENSION),
694
    OD(rc4, SEC_OID_RC4, "RC4", CKM_RC4, INVALID_CERT_EXTENSION),
695
    OD(desede3cbc, SEC_OID_DES_EDE3_CBC,
696
       "DES-EDE3-CBC", CKM_DES3_CBC, INVALID_CERT_EXTENSION),
697
    OD(rc5cbcpad, SEC_OID_RC5_CBC_PAD,
698
       "RC5-CBCPad", CKM_RC5_CBC, INVALID_CERT_EXTENSION),
699
    OD(desecb, SEC_OID_DES_ECB,
700
       "DES-ECB", CKM_DES_ECB, INVALID_CERT_EXTENSION),
701
    OD(descbc, SEC_OID_DES_CBC,
702
       "DES-CBC", CKM_DES_CBC, INVALID_CERT_EXTENSION),
703
    OD(desofb, SEC_OID_DES_OFB,
704
       "DES-OFB", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
705
    OD(descfb, SEC_OID_DES_CFB,
706
       "DES-CFB", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
707
    OD(desmac, SEC_OID_DES_MAC,
708
       "DES-MAC", CKM_DES_MAC, INVALID_CERT_EXTENSION),
709
    OD(desede, SEC_OID_DES_EDE,
710
       "DES-EDE", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
711
    OD(isoSHAWithRSASignature, SEC_OID_ISO_SHA_WITH_RSA_SIGNATURE,
712
       "ISO SHA with RSA Signature",
713
       CKM_SHA1_RSA_PKCS, INVALID_CERT_EXTENSION),
714
    OD(pkcs1RSAEncryption, SEC_OID_PKCS1_RSA_ENCRYPTION,
715
       "PKCS #1 RSA Encryption", CKM_RSA_PKCS, INVALID_CERT_EXTENSION),
716
717
    /* the following Signing mechanisms should get new CKM_ values when
718
     * values for CKM_RSA_WITH_MDX and CKM_RSA_WITH_SHA_1 get defined in
719
     * PKCS #11.
720
     */
721
    OD(pkcs1MD2WithRSAEncryption, SEC_OID_PKCS1_MD2_WITH_RSA_ENCRYPTION,
722
       "PKCS #1 MD2 With RSA Encryption", CKM_MD2_RSA_PKCS,
723
       INVALID_CERT_EXTENSION),
724
    OD(pkcs1MD4WithRSAEncryption, SEC_OID_PKCS1_MD4_WITH_RSA_ENCRYPTION,
725
       "PKCS #1 MD4 With RSA Encryption",
726
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
727
    OD(pkcs1MD5WithRSAEncryption, SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION,
728
       "PKCS #1 MD5 With RSA Encryption", CKM_MD5_RSA_PKCS,
729
       INVALID_CERT_EXTENSION),
730
    OD(pkcs1SHA1WithRSAEncryption, SEC_OID_PKCS1_SHA1_WITH_RSA_ENCRYPTION,
731
       "PKCS #1 SHA-1 With RSA Encryption", CKM_SHA1_RSA_PKCS,
732
       INVALID_CERT_EXTENSION),
733
734
    OD(pkcs5PbeWithMD2AndDEScbc, SEC_OID_PKCS5_PBE_WITH_MD2_AND_DES_CBC,
735
       "PKCS #5 Password Based Encryption with MD2 and DES-CBC",
736
       CKM_PBE_MD2_DES_CBC, INVALID_CERT_EXTENSION),
737
    OD(pkcs5PbeWithMD5AndDEScbc, SEC_OID_PKCS5_PBE_WITH_MD5_AND_DES_CBC,
738
       "PKCS #5 Password Based Encryption with MD5 and DES-CBC",
739
       CKM_PBE_MD5_DES_CBC, INVALID_CERT_EXTENSION),
740
    OD(pkcs5PbeWithSha1AndDEScbc, SEC_OID_PKCS5_PBE_WITH_SHA1_AND_DES_CBC,
741
       "PKCS #5 Password Based Encryption with SHA-1 and DES-CBC",
742
       CKM_NSS_PBE_SHA1_DES_CBC, INVALID_CERT_EXTENSION),
743
    OD(pkcs7, SEC_OID_PKCS7,
744
       "PKCS #7", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
745
    OD(pkcs7Data, SEC_OID_PKCS7_DATA,
746
       "PKCS #7 Data", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
747
    OD(pkcs7SignedData, SEC_OID_PKCS7_SIGNED_DATA,
748
       "PKCS #7 Signed Data", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
749
    OD(pkcs7EnvelopedData, SEC_OID_PKCS7_ENVELOPED_DATA,
750
       "PKCS #7 Enveloped Data",
751
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
752
    OD(pkcs7SignedEnvelopedData, SEC_OID_PKCS7_SIGNED_ENVELOPED_DATA,
753
       "PKCS #7 Signed And Enveloped Data",
754
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
755
    OD(pkcs7DigestedData, SEC_OID_PKCS7_DIGESTED_DATA,
756
       "PKCS #7 Digested Data",
757
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
758
    OD(pkcs7EncryptedData, SEC_OID_PKCS7_ENCRYPTED_DATA,
759
       "PKCS #7 Encrypted Data",
760
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
761
    OD(pkcs9EmailAddress, SEC_OID_PKCS9_EMAIL_ADDRESS,
762
       "PKCS #9 Email Address",
763
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
764
    OD(pkcs9UnstructuredName, SEC_OID_PKCS9_UNSTRUCTURED_NAME,
765
       "PKCS #9 Unstructured Name",
766
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
767
    OD(pkcs9ContentType, SEC_OID_PKCS9_CONTENT_TYPE,
768
       "PKCS #9 Content Type",
769
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
770
    OD(pkcs9MessageDigest, SEC_OID_PKCS9_MESSAGE_DIGEST,
771
       "PKCS #9 Message Digest",
772
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
773
    OD(pkcs9SigningTime, SEC_OID_PKCS9_SIGNING_TIME,
774
       "PKCS #9 Signing Time",
775
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
776
    OD(pkcs9CounterSignature, SEC_OID_PKCS9_COUNTER_SIGNATURE,
777
       "PKCS #9 Counter Signature",
778
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
779
    OD(pkcs9ChallengePassword, SEC_OID_PKCS9_CHALLENGE_PASSWORD,
780
       "PKCS #9 Challenge Password",
781
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
782
    OD(pkcs9UnstructuredAddress, SEC_OID_PKCS9_UNSTRUCTURED_ADDRESS,
783
       "PKCS #9 Unstructured Address",
784
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
785
    OD(pkcs9ExtendedCertificateAttributes,
786
       SEC_OID_PKCS9_EXTENDED_CERTIFICATE_ATTRIBUTES,
787
       "PKCS #9 Extended Certificate Attributes",
788
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
789
    OD(pkcs9SMIMECapabilities, SEC_OID_PKCS9_SMIME_CAPABILITIES,
790
       "PKCS #9 S/MIME Capabilities",
791
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
792
    OD(x520CommonName, SEC_OID_AVA_COMMON_NAME,
793
       "X520 Common Name", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
794
    OD(x520CountryName, SEC_OID_AVA_COUNTRY_NAME,
795
       "X520 Country Name", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
796
    OD(x520LocalityName, SEC_OID_AVA_LOCALITY,
797
       "X520 Locality Name", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
798
    OD(x520StateOrProvinceName, SEC_OID_AVA_STATE_OR_PROVINCE,
799
       "X520 State Or Province Name",
800
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
801
    OD(x520OrgName, SEC_OID_AVA_ORGANIZATION_NAME,
802
       "X520 Organization Name",
803
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
804
    OD(x520OrgUnitName, SEC_OID_AVA_ORGANIZATIONAL_UNIT_NAME,
805
       "X520 Organizational Unit Name",
806
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
807
    OD(x520DnQualifier, SEC_OID_AVA_DN_QUALIFIER,
808
       "X520 DN Qualifier", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
809
    OD(rfc2247DomainComponent, SEC_OID_AVA_DC,
810
       "RFC 2247 Domain Component",
811
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
812
813
    OD(nsTypeGIF, SEC_OID_NS_TYPE_GIF,
814
       "GIF", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
815
    OD(nsTypeJPEG, SEC_OID_NS_TYPE_JPEG,
816
       "JPEG", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
817
    OD(nsTypeURL, SEC_OID_NS_TYPE_URL,
818
       "URL", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
819
    OD(nsTypeHTML, SEC_OID_NS_TYPE_HTML,
820
       "HTML", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
821
    OD(nsTypeCertSeq, SEC_OID_NS_TYPE_CERT_SEQUENCE,
822
       "Certificate Sequence",
823
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
824
    OD(missiCertKEADSSOld, SEC_OID_MISSI_KEA_DSS_OLD,
825
       "MISSI KEA and DSS Algorithm (Old)",
826
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
827
    OD(missiCertDSSOld, SEC_OID_MISSI_DSS_OLD,
828
       "MISSI DSS Algorithm (Old)",
829
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
830
    OD(missiCertKEADSS, SEC_OID_MISSI_KEA_DSS,
831
       "MISSI KEA and DSS Algorithm",
832
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
833
    OD(missiCertDSS, SEC_OID_MISSI_DSS,
834
       "MISSI DSS Algorithm",
835
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
836
    OD(missiCertKEA, SEC_OID_MISSI_KEA,
837
       "MISSI KEA Algorithm",
838
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
839
    OD(missiCertAltKEA, SEC_OID_MISSI_ALT_KEA,
840
       "MISSI Alternate KEA Algorithm",
841
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
842
843
    /* Netscape private extensions */
844
    OD(nsCertExtNetscapeOK, SEC_OID_NS_CERT_EXT_NETSCAPE_OK,
845
       "Netscape says this cert is OK",
846
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
847
    OD(nsCertExtIssuerLogo, SEC_OID_NS_CERT_EXT_ISSUER_LOGO,
848
       "Certificate Issuer Logo",
849
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
850
    OD(nsCertExtSubjectLogo, SEC_OID_NS_CERT_EXT_SUBJECT_LOGO,
851
       "Certificate Subject Logo",
852
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
853
    OD(nsExtCertType, SEC_OID_NS_CERT_EXT_CERT_TYPE,
854
       "Certificate Type",
855
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
856
    OD(nsExtBaseURL, SEC_OID_NS_CERT_EXT_BASE_URL,
857
       "Certificate Extension Base URL",
858
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
859
    OD(nsExtRevocationURL, SEC_OID_NS_CERT_EXT_REVOCATION_URL,
860
       "Certificate Revocation URL",
861
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
862
    OD(nsExtCARevocationURL, SEC_OID_NS_CERT_EXT_CA_REVOCATION_URL,
863
       "Certificate Authority Revocation URL",
864
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
865
    OD(nsExtCACRLURL, SEC_OID_NS_CERT_EXT_CA_CRL_URL,
866
       "Certificate Authority CRL Download URL",
867
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
868
    OD(nsExtCACertURL, SEC_OID_NS_CERT_EXT_CA_CERT_URL,
869
       "Certificate Authority Certificate Download URL",
870
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
871
    OD(nsExtCertRenewalURL, SEC_OID_NS_CERT_EXT_CERT_RENEWAL_URL,
872
       "Certificate Renewal URL",
873
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
874
    OD(nsExtCAPolicyURL, SEC_OID_NS_CERT_EXT_CA_POLICY_URL,
875
       "Certificate Authority Policy URL",
876
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
877
    OD(nsExtHomepageURL, SEC_OID_NS_CERT_EXT_HOMEPAGE_URL,
878
       "Certificate Homepage URL",
879
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
880
    OD(nsExtEntityLogo, SEC_OID_NS_CERT_EXT_ENTITY_LOGO,
881
       "Certificate Entity Logo",
882
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
883
    OD(nsExtUserPicture, SEC_OID_NS_CERT_EXT_USER_PICTURE,
884
       "Certificate User Picture",
885
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
886
    OD(nsExtSSLServerName, SEC_OID_NS_CERT_EXT_SSL_SERVER_NAME,
887
       "Certificate SSL Server Name",
888
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
889
    OD(nsExtComment, SEC_OID_NS_CERT_EXT_COMMENT,
890
       "Certificate Comment",
891
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
892
    OD(nsExtLostPasswordURL, SEC_OID_NS_CERT_EXT_LOST_PASSWORD_URL,
893
       "Lost Password URL",
894
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
895
    OD(nsExtCertRenewalTime, SEC_OID_NS_CERT_EXT_CERT_RENEWAL_TIME,
896
       "Certificate Renewal Time",
897
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
898
    OD(nsKeyUsageGovtApproved, SEC_OID_NS_KEY_USAGE_GOVT_APPROVED,
899
       "Strong Crypto Export Approved",
900
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
901
902
    /* x.509 v3 certificate extensions */
903
    OD(x509SubjectDirectoryAttr, SEC_OID_X509_SUBJECT_DIRECTORY_ATTR,
904
       "Certificate Subject Directory Attributes",
905
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
906
    OD(x509SubjectKeyID, SEC_OID_X509_SUBJECT_KEY_ID,
907
       "Certificate Subject Key ID",
908
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
909
    OD(x509KeyUsage, SEC_OID_X509_KEY_USAGE,
910
       "Certificate Key Usage",
911
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
912
    OD(x509PrivateKeyUsagePeriod, SEC_OID_X509_PRIVATE_KEY_USAGE_PERIOD,
913
       "Certificate Private Key Usage Period",
914
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
915
    OD(x509SubjectAltName, SEC_OID_X509_SUBJECT_ALT_NAME,
916
       "Certificate Subject Alt Name",
917
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
918
    OD(x509IssuerAltName, SEC_OID_X509_ISSUER_ALT_NAME,
919
       "Certificate Issuer Alt Name",
920
       CKM_INVALID_MECHANISM, FAKE_SUPPORTED_CERT_EXTENSION),
921
    OD(x509BasicConstraints, SEC_OID_X509_BASIC_CONSTRAINTS,
922
       "Certificate Basic Constraints",
923
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
924
    OD(x509NameConstraints, SEC_OID_X509_NAME_CONSTRAINTS,
925
       "Certificate Name Constraints",
926
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
927
    OD(x509CRLDistPoints, SEC_OID_X509_CRL_DIST_POINTS,
928
       "CRL Distribution Points",
929
       CKM_INVALID_MECHANISM, FAKE_SUPPORTED_CERT_EXTENSION),
930
    OD(x509CertificatePolicies, SEC_OID_X509_CERTIFICATE_POLICIES,
931
       "Certificate Policies",
932
       CKM_INVALID_MECHANISM, FAKE_SUPPORTED_CERT_EXTENSION),
933
    OD(x509PolicyMappings, SEC_OID_X509_POLICY_MAPPINGS,
934
       "Certificate Policy Mappings",
935
       CKM_INVALID_MECHANISM, UNSUPPORTED_CERT_EXTENSION),
936
    OD(x509PolicyConstraints, SEC_OID_X509_POLICY_CONSTRAINTS,
937
       "Certificate Policy Constraints",
938
       CKM_INVALID_MECHANISM, FAKE_SUPPORTED_CERT_EXTENSION),
939
    OD(x509AuthKeyID, SEC_OID_X509_AUTH_KEY_ID,
940
       "Certificate Authority Key Identifier",
941
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
942
    OD(x509ExtKeyUsage, SEC_OID_X509_EXT_KEY_USAGE,
943
       "Extended Key Usage",
944
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
945
    OD(x509AuthInfoAccess, SEC_OID_X509_AUTH_INFO_ACCESS,
946
       "Authority Information Access",
947
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
948
949
    /* x.509 v3 CRL extensions */
950
    OD(x509CRLNumber, SEC_OID_X509_CRL_NUMBER,
951
       "CRL Number", CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
952
    OD(x509ReasonCode, SEC_OID_X509_REASON_CODE,
953
       "CRL reason code", CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
954
    OD(x509InvalidDate, SEC_OID_X509_INVALID_DATE,
955
       "Invalid Date", CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
956
957
    OD(x500RSAEncryption, SEC_OID_X500_RSA_ENCRYPTION,
958
       "X500 RSA Encryption", CKM_RSA_X_509, INVALID_CERT_EXTENSION),
959
960
    /* added for alg 1485 */
961
    OD(rfc1274Uid, SEC_OID_RFC1274_UID,
962
       "RFC1274 User Id", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
963
    OD(rfc1274Mail, SEC_OID_RFC1274_MAIL,
964
       "RFC1274 E-mail Address",
965
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
966
967
    /* pkcs 12 additions */
968
    OD(pkcs12, SEC_OID_PKCS12,
969
       "PKCS #12", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
970
    OD(pkcs12ModeIDs, SEC_OID_PKCS12_MODE_IDS,
971
       "PKCS #12 Mode IDs", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
972
    OD(pkcs12ESPVKIDs, SEC_OID_PKCS12_ESPVK_IDS,
973
       "PKCS #12 ESPVK IDs", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
974
    OD(pkcs12BagIDs, SEC_OID_PKCS12_BAG_IDS,
975
       "PKCS #12 Bag IDs", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
976
    OD(pkcs12CertBagIDs, SEC_OID_PKCS12_CERT_BAG_IDS,
977
       "PKCS #12 Cert Bag IDs",
978
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
979
    OD(pkcs12OIDs, SEC_OID_PKCS12_OIDS,
980
       "PKCS #12 OIDs", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
981
    OD(pkcs12PBEIDs, SEC_OID_PKCS12_PBE_IDS,
982
       "PKCS #12 PBE IDs", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
983
    OD(pkcs12SignatureIDs, SEC_OID_PKCS12_SIGNATURE_IDS,
984
       "PKCS #12 Signature IDs",
985
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
986
    OD(pkcs12EnvelopingIDs, SEC_OID_PKCS12_ENVELOPING_IDS,
987
       "PKCS #12 Enveloping IDs",
988
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
989
    OD(pkcs12PKCS8KeyShrouding, SEC_OID_PKCS12_PKCS8_KEY_SHROUDING,
990
       "PKCS #12 Key Shrouding",
991
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
992
    OD(pkcs12KeyBagID, SEC_OID_PKCS12_KEY_BAG_ID,
993
       "PKCS #12 Key Bag ID",
994
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
995
    OD(pkcs12CertAndCRLBagID, SEC_OID_PKCS12_CERT_AND_CRL_BAG_ID,
996
       "PKCS #12 Cert And CRL Bag ID",
997
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
998
    OD(pkcs12SecretBagID, SEC_OID_PKCS12_SECRET_BAG_ID,
999
       "PKCS #12 Secret Bag ID",
1000
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1001
    OD(pkcs12X509CertCRLBag, SEC_OID_PKCS12_X509_CERT_CRL_BAG,
1002
       "PKCS #12 X509 Cert CRL Bag",
1003
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1004
    OD(pkcs12SDSICertBag, SEC_OID_PKCS12_SDSI_CERT_BAG,
1005
       "PKCS #12 SDSI Cert Bag",
1006
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1007
    OD(pkcs12PBEWithSha1And128BitRC4,
1008
       SEC_OID_PKCS12_PBE_WITH_SHA1_AND_128_BIT_RC4,
1009
       "PKCS #12 PBE With SHA-1 and 128 Bit RC4",
1010
       CKM_NSS_PBE_SHA1_128_BIT_RC4, INVALID_CERT_EXTENSION),
1011
    OD(pkcs12PBEWithSha1And40BitRC4,
1012
       SEC_OID_PKCS12_PBE_WITH_SHA1_AND_40_BIT_RC4,
1013
       "PKCS #12 PBE With SHA-1 and 40 Bit RC4",
1014
       CKM_NSS_PBE_SHA1_40_BIT_RC4, INVALID_CERT_EXTENSION),
1015
    OD(pkcs12PBEWithSha1AndTripleDESCBC,
1016
       SEC_OID_PKCS12_PBE_WITH_SHA1_AND_TRIPLE_DES_CBC,
1017
       "PKCS #12 PBE With SHA-1 and Triple DES-CBC",
1018
       CKM_NSS_PBE_SHA1_TRIPLE_DES_CBC, INVALID_CERT_EXTENSION),
1019
    OD(pkcs12PBEWithSha1And128BitRC2CBC,
1020
       SEC_OID_PKCS12_PBE_WITH_SHA1_AND_128_BIT_RC2_CBC,
1021
       "PKCS #12 PBE With SHA-1 and 128 Bit RC2 CBC",
1022
       CKM_NSS_PBE_SHA1_128_BIT_RC2_CBC, INVALID_CERT_EXTENSION),
1023
    OD(pkcs12PBEWithSha1And40BitRC2CBC,
1024
       SEC_OID_PKCS12_PBE_WITH_SHA1_AND_40_BIT_RC2_CBC,
1025
       "PKCS #12 PBE With SHA-1 and 40 Bit RC2 CBC",
1026
       CKM_NSS_PBE_SHA1_40_BIT_RC2_CBC, INVALID_CERT_EXTENSION),
1027
    OD(pkcs12RSAEncryptionWith128BitRC4,
1028
       SEC_OID_PKCS12_RSA_ENCRYPTION_WITH_128_BIT_RC4,
1029
       "PKCS #12 RSA Encryption with 128 Bit RC4",
1030
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1031
    OD(pkcs12RSAEncryptionWith40BitRC4,
1032
       SEC_OID_PKCS12_RSA_ENCRYPTION_WITH_40_BIT_RC4,
1033
       "PKCS #12 RSA Encryption with 40 Bit RC4",
1034
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1035
    OD(pkcs12RSAEncryptionWithTripleDES,
1036
       SEC_OID_PKCS12_RSA_ENCRYPTION_WITH_TRIPLE_DES,
1037
       "PKCS #12 RSA Encryption with Triple DES",
1038
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1039
    OD(pkcs12RSASignatureWithSHA1Digest,
1040
       SEC_OID_PKCS12_RSA_SIGNATURE_WITH_SHA1_DIGEST,
1041
       "PKCS #12 RSA Encryption with Triple DES",
1042
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1043
1044
    /* DSA signatures */
1045
    OD(ansix9DSASignature, SEC_OID_ANSIX9_DSA_SIGNATURE,
1046
       "ANSI X9.57 DSA Signature", CKM_DSA, INVALID_CERT_EXTENSION),
1047
    OD(ansix9DSASignaturewithSHA1Digest,
1048
       SEC_OID_ANSIX9_DSA_SIGNATURE_WITH_SHA1_DIGEST,
1049
       "ANSI X9.57 DSA Signature with SHA-1 Digest",
1050
       CKM_DSA_SHA1, INVALID_CERT_EXTENSION),
1051
    OD(bogusDSASignaturewithSHA1Digest,
1052
       SEC_OID_BOGUS_DSA_SIGNATURE_WITH_SHA1_DIGEST,
1053
       "FORTEZZA DSA Signature with SHA-1 Digest",
1054
       CKM_DSA_SHA1, INVALID_CERT_EXTENSION),
1055
1056
    /* verisign oids */
1057
    OD(verisignUserNotices, SEC_OID_VERISIGN_USER_NOTICES,
1058
       "Verisign User Notices",
1059
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1060
1061
    /* pkix oids */
1062
    OD(pkixCPSPointerQualifier, SEC_OID_PKIX_CPS_POINTER_QUALIFIER,
1063
       "PKIX CPS Pointer Qualifier",
1064
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1065
    OD(pkixUserNoticeQualifier, SEC_OID_PKIX_USER_NOTICE_QUALIFIER,
1066
       "PKIX User Notice Qualifier",
1067
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1068
1069
    OD(pkixOCSP, SEC_OID_PKIX_OCSP,
1070
       "PKIX Online Certificate Status Protocol",
1071
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1072
    OD(pkixOCSPBasicResponse, SEC_OID_PKIX_OCSP_BASIC_RESPONSE,
1073
       "OCSP Basic Response", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1074
    OD(pkixOCSPNonce, SEC_OID_PKIX_OCSP_NONCE,
1075
       "OCSP Nonce Extension", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1076
    OD(pkixOCSPCRL, SEC_OID_PKIX_OCSP_CRL,
1077
       "OCSP CRL Reference Extension",
1078
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1079
    OD(pkixOCSPResponse, SEC_OID_PKIX_OCSP_RESPONSE,
1080
       "OCSP Response Types Extension",
1081
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1082
    OD(pkixOCSPNoCheck, SEC_OID_PKIX_OCSP_NO_CHECK,
1083
       "OCSP No Check Extension",
1084
       CKM_INVALID_MECHANISM, SUPPORTED_CERT_EXTENSION),
1085
    OD(pkixOCSPArchiveCutoff, SEC_OID_PKIX_OCSP_ARCHIVE_CUTOFF,
1086
       "OCSP Archive Cutoff Extension",
1087
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1088
    OD(pkixOCSPServiceLocator, SEC_OID_PKIX_OCSP_SERVICE_LOCATOR,
1089
       "OCSP Service Locator Extension",
1090
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1091
1092
    OD(pkixRegCtrlRegToken, SEC_OID_PKIX_REGCTRL_REGTOKEN,
1093
       "PKIX CRMF Registration Control, Registration Token",
1094
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1095
    OD(pkixRegCtrlAuthenticator, SEC_OID_PKIX_REGCTRL_AUTHENTICATOR,
1096
       "PKIX CRMF Registration Control, Registration Authenticator",
1097
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1098
    OD(pkixRegCtrlPKIPubInfo, SEC_OID_PKIX_REGCTRL_PKIPUBINFO,
1099
       "PKIX CRMF Registration Control, PKI Publication Info",
1100
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1101
    OD(pkixRegCtrlPKIArchOptions,
1102
       SEC_OID_PKIX_REGCTRL_PKI_ARCH_OPTIONS,
1103
       "PKIX CRMF Registration Control, PKI Archive Options",
1104
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1105
    OD(pkixRegCtrlOldCertID, SEC_OID_PKIX_REGCTRL_OLD_CERT_ID,
1106
       "PKIX CRMF Registration Control, Old Certificate ID",
1107
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1108
    OD(pkixRegCtrlProtEncKey, SEC_OID_PKIX_REGCTRL_PROTOCOL_ENC_KEY,
1109
       "PKIX CRMF Registration Control, Protocol Encryption Key",
1110
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1111
    OD(pkixRegInfoUTF8Pairs, SEC_OID_PKIX_REGINFO_UTF8_PAIRS,
1112
       "PKIX CRMF Registration Info, UTF8 Pairs",
1113
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1114
    OD(pkixRegInfoCertReq, SEC_OID_PKIX_REGINFO_CERT_REQUEST,
1115
       "PKIX CRMF Registration Info, Certificate Request",
1116
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1117
    OD(pkixExtendedKeyUsageServerAuth,
1118
       SEC_OID_EXT_KEY_USAGE_SERVER_AUTH,
1119
       "TLS Web Server Authentication Certificate",
1120
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1121
    OD(pkixExtendedKeyUsageClientAuth,
1122
       SEC_OID_EXT_KEY_USAGE_CLIENT_AUTH,
1123
       "TLS Web Client Authentication Certificate",
1124
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1125
    OD(pkixExtendedKeyUsageCodeSign, SEC_OID_EXT_KEY_USAGE_CODE_SIGN,
1126
       "Code Signing Certificate",
1127
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1128
    OD(pkixExtendedKeyUsageEMailProtect,
1129
       SEC_OID_EXT_KEY_USAGE_EMAIL_PROTECT,
1130
       "E-Mail Protection Certificate",
1131
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1132
    OD(pkixExtendedKeyUsageTimeStamp,
1133
       SEC_OID_EXT_KEY_USAGE_TIME_STAMP,
1134
       "Time Stamping Certifcate",
1135
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1136
    OD(pkixOCSPResponderExtendedKeyUsage, SEC_OID_OCSP_RESPONDER,
1137
       "OCSP Responder Certificate",
1138
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1139
1140
    /* Netscape Algorithm OIDs */
1141
1142
    OD(netscapeSMimeKEA, SEC_OID_NETSCAPE_SMIME_KEA,
1143
       "Netscape S/MIME KEA", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1144
1145
    /* Skipjack OID -- ### mwelch temporary */
1146
    OD(skipjackCBC, SEC_OID_FORTEZZA_SKIPJACK,
1147
       "Skipjack CBC64", CKM_SKIPJACK_CBC64, INVALID_CERT_EXTENSION),
1148
1149
    /* pkcs12 v2 oids */
1150
    OD(pkcs12V2PBEWithSha1And128BitRC4,
1151
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_128_BIT_RC4,
1152
       "PKCS #12 V2 PBE With SHA-1 And 128 Bit RC4",
1153
       CKM_PBE_SHA1_RC4_128, INVALID_CERT_EXTENSION),
1154
    OD(pkcs12V2PBEWithSha1And40BitRC4,
1155
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_40_BIT_RC4,
1156
       "PKCS #12 V2 PBE With SHA-1 And 40 Bit RC4",
1157
       CKM_PBE_SHA1_RC4_40, INVALID_CERT_EXTENSION),
1158
    OD(pkcs12V2PBEWithSha1And3KeyTripleDEScbc,
1159
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_3KEY_TRIPLE_DES_CBC,
1160
       "PKCS #12 V2 PBE With SHA-1 And 3KEY Triple DES-CBC",
1161
       CKM_PBE_SHA1_DES3_EDE_CBC, INVALID_CERT_EXTENSION),
1162
    OD(pkcs12V2PBEWithSha1And2KeyTripleDEScbc,
1163
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_2KEY_TRIPLE_DES_CBC,
1164
       "PKCS #12 V2 PBE With SHA-1 And 2KEY Triple DES-CBC",
1165
       CKM_PBE_SHA1_DES2_EDE_CBC, INVALID_CERT_EXTENSION),
1166
    OD(pkcs12V2PBEWithSha1And128BitRC2cbc,
1167
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_128_BIT_RC2_CBC,
1168
       "PKCS #12 V2 PBE With SHA-1 And 128 Bit RC2 CBC",
1169
       CKM_PBE_SHA1_RC2_128_CBC, INVALID_CERT_EXTENSION),
1170
    OD(pkcs12V2PBEWithSha1And40BitRC2cbc,
1171
       SEC_OID_PKCS12_V2_PBE_WITH_SHA1_AND_40_BIT_RC2_CBC,
1172
       "PKCS #12 V2 PBE With SHA-1 And 40 Bit RC2 CBC",
1173
       CKM_PBE_SHA1_RC2_40_CBC, INVALID_CERT_EXTENSION),
1174
    OD(pkcs12SafeContentsID, SEC_OID_PKCS12_SAFE_CONTENTS_ID,
1175
       "PKCS #12 Safe Contents ID",
1176
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1177
    OD(pkcs12PKCS8ShroudedKeyBagID,
1178
       SEC_OID_PKCS12_PKCS8_SHROUDED_KEY_BAG_ID,
1179
       "PKCS #12 Safe Contents ID",
1180
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1181
    OD(pkcs12V1KeyBag, SEC_OID_PKCS12_V1_KEY_BAG_ID,
1182
       "PKCS #12 V1 Key Bag",
1183
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1184
    OD(pkcs12V1PKCS8ShroudedKeyBag,
1185
       SEC_OID_PKCS12_V1_PKCS8_SHROUDED_KEY_BAG_ID,
1186
       "PKCS #12 V1 PKCS8 Shrouded Key Bag",
1187
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1188
    OD(pkcs12V1CertBag, SEC_OID_PKCS12_V1_CERT_BAG_ID,
1189
       "PKCS #12 V1 Cert Bag",
1190
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1191
    OD(pkcs12V1CRLBag, SEC_OID_PKCS12_V1_CRL_BAG_ID,
1192
       "PKCS #12 V1 CRL Bag",
1193
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1194
    OD(pkcs12V1SecretBag, SEC_OID_PKCS12_V1_SECRET_BAG_ID,
1195
       "PKCS #12 V1 Secret Bag",
1196
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1197
    OD(pkcs12V1SafeContentsBag, SEC_OID_PKCS12_V1_SAFE_CONTENTS_BAG_ID,
1198
       "PKCS #12 V1 Safe Contents Bag",
1199
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1200
1201
    OD(pkcs9X509Certificate, SEC_OID_PKCS9_X509_CERT,
1202
       "PKCS #9 X509 Certificate",
1203
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1204
    OD(pkcs9SDSICertificate, SEC_OID_PKCS9_SDSI_CERT,
1205
       "PKCS #9 SDSI Certificate",
1206
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1207
    OD(pkcs9X509CRL, SEC_OID_PKCS9_X509_CRL,
1208
       "PKCS #9 X509 CRL", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1209
    OD(pkcs9FriendlyName, SEC_OID_PKCS9_FRIENDLY_NAME,
1210
       "PKCS #9 Friendly Name",
1211
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1212
    OD(pkcs9LocalKeyID, SEC_OID_PKCS9_LOCAL_KEY_ID,
1213
       "PKCS #9 Local Key ID",
1214
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1215
    OD(pkcs12KeyUsageAttr, SEC_OID_BOGUS_KEY_USAGE,
1216
       "Bogus Key Usage", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1217
    OD(dhPublicKey, SEC_OID_X942_DIFFIE_HELMAN_KEY,
1218
       "Diffie-Helman Public Key", CKM_DH_PKCS_DERIVE,
1219
       INVALID_CERT_EXTENSION),
1220
    OD(netscapeNickname, SEC_OID_NETSCAPE_NICKNAME,
1221
       "Netscape Nickname", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1222
1223
    /* Cert Server specific OIDs */
1224
    OD(netscapeRecoveryRequest, SEC_OID_NETSCAPE_RECOVERY_REQUEST,
1225
       "Recovery Request OID",
1226
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1227
1228
    OD(nsExtAIACertRenewal, SEC_OID_CERT_RENEWAL_LOCATOR,
1229
       "Certificate Renewal Locator OID", CKM_INVALID_MECHANISM,
1230
       INVALID_CERT_EXTENSION),
1231
1232
    OD(nsExtCertScopeOfUse, SEC_OID_NS_CERT_EXT_SCOPE_OF_USE,
1233
       "Certificate Scope-of-Use Extension", CKM_INVALID_MECHANISM,
1234
       SUPPORTED_CERT_EXTENSION),
1235
1236
    /* CMS stuff */
1237
    OD(cmsESDH, SEC_OID_CMS_EPHEMERAL_STATIC_DIFFIE_HELLMAN,
1238
       "Ephemeral-Static Diffie-Hellman", CKM_INVALID_MECHANISM /* XXX */,
1239
       INVALID_CERT_EXTENSION),
1240
    OD(cms3DESwrap, SEC_OID_CMS_3DES_KEY_WRAP,
1241
       "CMS Triple DES Key Wrap", CKM_INVALID_MECHANISM /* XXX */,
1242
       INVALID_CERT_EXTENSION),
1243
    OD(cmsRC2wrap, SEC_OID_CMS_RC2_KEY_WRAP,
1244
       "CMS RC2 Key Wrap", CKM_INVALID_MECHANISM /* XXX */,
1245
       INVALID_CERT_EXTENSION),
1246
    OD(smimeEncryptionKeyPreference, SEC_OID_SMIME_ENCRYPTION_KEY_PREFERENCE,
1247
       "S/MIME Encryption Key Preference",
1248
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1249
1250
    /* AES algorithm OIDs */
1251
    OD(aes128_ECB, SEC_OID_AES_128_ECB,
1252
       "AES-128-ECB", CKM_AES_ECB, INVALID_CERT_EXTENSION),
1253
    OD(aes128_CBC, SEC_OID_AES_128_CBC,
1254
       "AES-128-CBC", CKM_AES_CBC, INVALID_CERT_EXTENSION),
1255
    OD(aes192_ECB, SEC_OID_AES_192_ECB,
1256
       "AES-192-ECB", CKM_AES_ECB, INVALID_CERT_EXTENSION),
1257
    OD(aes192_CBC, SEC_OID_AES_192_CBC,
1258
       "AES-192-CBC", CKM_AES_CBC, INVALID_CERT_EXTENSION),
1259
    OD(aes256_ECB, SEC_OID_AES_256_ECB,
1260
       "AES-256-ECB", CKM_AES_ECB, INVALID_CERT_EXTENSION),
1261
    OD(aes256_CBC, SEC_OID_AES_256_CBC,
1262
       "AES-256-CBC", CKM_AES_CBC, INVALID_CERT_EXTENSION),
1263
1264
    /* More bogus DSA OIDs */
1265
    OD(sdn702DSASignature, SEC_OID_SDN702_DSA_SIGNATURE,
1266
       "SDN.702 DSA Signature", CKM_DSA_SHA1, INVALID_CERT_EXTENSION),
1267
1268
    OD(ms_smimeEncryptionKeyPreference,
1269
       SEC_OID_MS_SMIME_ENCRYPTION_KEY_PREFERENCE,
1270
       "Microsoft S/MIME Encryption Key Preference",
1271
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1272
1273
    OD(sha256, SEC_OID_SHA256, "SHA-256", CKM_SHA256, INVALID_CERT_EXTENSION),
1274
    OD(sha384, SEC_OID_SHA384, "SHA-384", CKM_SHA384, INVALID_CERT_EXTENSION),
1275
    OD(sha512, SEC_OID_SHA512, "SHA-512", CKM_SHA512, INVALID_CERT_EXTENSION),
1276
1277
    OD(pkcs1SHA256WithRSAEncryption, SEC_OID_PKCS1_SHA256_WITH_RSA_ENCRYPTION,
1278
       "PKCS #1 SHA-256 With RSA Encryption", CKM_SHA256_RSA_PKCS,
1279
       INVALID_CERT_EXTENSION),
1280
    OD(pkcs1SHA384WithRSAEncryption, SEC_OID_PKCS1_SHA384_WITH_RSA_ENCRYPTION,
1281
       "PKCS #1 SHA-384 With RSA Encryption", CKM_SHA384_RSA_PKCS,
1282
       INVALID_CERT_EXTENSION),
1283
    OD(pkcs1SHA512WithRSAEncryption, SEC_OID_PKCS1_SHA512_WITH_RSA_ENCRYPTION,
1284
       "PKCS #1 SHA-512 With RSA Encryption", CKM_SHA512_RSA_PKCS,
1285
       INVALID_CERT_EXTENSION),
1286
1287
    OD(aes128_KEY_WRAP, SEC_OID_AES_128_KEY_WRAP,
1288
       "AES-128 Key Wrap", CKM_NSS_AES_KEY_WRAP, INVALID_CERT_EXTENSION),
1289
    OD(aes192_KEY_WRAP, SEC_OID_AES_192_KEY_WRAP,
1290
       "AES-192 Key Wrap", CKM_NSS_AES_KEY_WRAP, INVALID_CERT_EXTENSION),
1291
    OD(aes256_KEY_WRAP, SEC_OID_AES_256_KEY_WRAP,
1292
       "AES-256 Key Wrap", CKM_NSS_AES_KEY_WRAP, INVALID_CERT_EXTENSION),
1293
1294
    /* Elliptic Curve Cryptography (ECC) OIDs */
1295
    OD(ansix962ECPublicKey, SEC_OID_ANSIX962_EC_PUBLIC_KEY,
1296
       "X9.62 elliptic curve public key", CKM_ECDH1_DERIVE,
1297
       INVALID_CERT_EXTENSION),
1298
    OD(ansix962SignaturewithSHA1Digest,
1299
       SEC_OID_ANSIX962_ECDSA_SHA1_SIGNATURE,
1300
       "X9.62 ECDSA signature with SHA-1", CKM_ECDSA_SHA1,
1301
       INVALID_CERT_EXTENSION),
1302
1303
    /* Named curves */
1304
    /* NOTE: Only P256, P384, P521, and 25519 are supported by softoken.
1305
     *       Using other curves requires an appropriate token. */
1306
1307
    /* ANSI X9.62 named elliptic curves (prime field) */
1308
    OD(ansiX962prime192v1, SEC_OID_ANSIX962_EC_PRIME192V1,
1309
       "ANSI X9.62 elliptic curve prime192v1 (aka secp192r1, NIST P-192)",
1310
       CKM_INVALID_MECHANISM,
1311
       INVALID_CERT_EXTENSION),
1312
    OD(ansiX962prime192v2, SEC_OID_ANSIX962_EC_PRIME192V2,
1313
       "ANSI X9.62 elliptic curve prime192v2",
1314
       CKM_INVALID_MECHANISM,
1315
       INVALID_CERT_EXTENSION),
1316
    OD(ansiX962prime192v3, SEC_OID_ANSIX962_EC_PRIME192V3,
1317
       "ANSI X9.62 elliptic curve prime192v3",
1318
       CKM_INVALID_MECHANISM,
1319
       INVALID_CERT_EXTENSION),
1320
    OD(ansiX962prime239v1, SEC_OID_ANSIX962_EC_PRIME239V1,
1321
       "ANSI X9.62 elliptic curve prime239v1",
1322
       CKM_INVALID_MECHANISM,
1323
       INVALID_CERT_EXTENSION),
1324
    OD(ansiX962prime239v2, SEC_OID_ANSIX962_EC_PRIME239V2,
1325
       "ANSI X9.62 elliptic curve prime239v2",
1326
       CKM_INVALID_MECHANISM,
1327
       INVALID_CERT_EXTENSION),
1328
    OD(ansiX962prime239v3, SEC_OID_ANSIX962_EC_PRIME239V3,
1329
       "ANSI X9.62 elliptic curve prime239v3",
1330
       CKM_INVALID_MECHANISM,
1331
       INVALID_CERT_EXTENSION),
1332
    OD(ansiX962prime256v1, SEC_OID_ANSIX962_EC_PRIME256V1,
1333
       "ANSI X9.62 elliptic curve prime256v1 (aka secp256r1, NIST P-256)",
1334
       CKM_INVALID_MECHANISM,
1335
       INVALID_CERT_EXTENSION),
1336
1337
    /* SECG named elliptic curves (prime field) */
1338
    OD(secgECsecp112r1, SEC_OID_SECG_EC_SECP112R1,
1339
       "SECG elliptic curve secp112r1",
1340
       CKM_INVALID_MECHANISM,
1341
       INVALID_CERT_EXTENSION),
1342
    OD(secgECsecp112r2, SEC_OID_SECG_EC_SECP112R2,
1343
       "SECG elliptic curve secp112r2",
1344
       CKM_INVALID_MECHANISM,
1345
       INVALID_CERT_EXTENSION),
1346
    OD(secgECsecp128r1, SEC_OID_SECG_EC_SECP128R1,
1347
       "SECG elliptic curve secp128r1",
1348
       CKM_INVALID_MECHANISM,
1349
       INVALID_CERT_EXTENSION),
1350
    OD(secgECsecp128r2, SEC_OID_SECG_EC_SECP128R2,
1351
       "SECG elliptic curve secp128r2",
1352
       CKM_INVALID_MECHANISM,
1353
       INVALID_CERT_EXTENSION),
1354
    OD(secgECsecp160k1, SEC_OID_SECG_EC_SECP160K1,
1355
       "SECG elliptic curve secp160k1",
1356
       CKM_INVALID_MECHANISM,
1357
       INVALID_CERT_EXTENSION),
1358
    OD(secgECsecp160r1, SEC_OID_SECG_EC_SECP160R1,
1359
       "SECG elliptic curve secp160r1",
1360
       CKM_INVALID_MECHANISM,
1361
       INVALID_CERT_EXTENSION),
1362
    OD(secgECsecp160r2, SEC_OID_SECG_EC_SECP160R2,
1363
       "SECG elliptic curve secp160r2",
1364
       CKM_INVALID_MECHANISM,
1365
       INVALID_CERT_EXTENSION),
1366
    OD(secgECsecp192k1, SEC_OID_SECG_EC_SECP192K1,
1367
       "SECG elliptic curve secp192k1",
1368
       CKM_INVALID_MECHANISM,
1369
       INVALID_CERT_EXTENSION),
1370
    OD(secgECsecp224k1, SEC_OID_SECG_EC_SECP224K1,
1371
       "SECG elliptic curve secp224k1",
1372
       CKM_INVALID_MECHANISM,
1373
       INVALID_CERT_EXTENSION),
1374
    OD(secgECsecp224r1, SEC_OID_SECG_EC_SECP224R1,
1375
       "SECG elliptic curve secp224r1 (aka NIST P-224)",
1376
       CKM_INVALID_MECHANISM,
1377
       INVALID_CERT_EXTENSION),
1378
    OD(secgECsecp256k1, SEC_OID_SECG_EC_SECP256K1,
1379
       "SECG elliptic curve secp256k1",
1380
       CKM_INVALID_MECHANISM,
1381
       INVALID_CERT_EXTENSION),
1382
    OD(secgECsecp384r1, SEC_OID_SECG_EC_SECP384R1,
1383
       "SECG elliptic curve secp384r1 (aka NIST P-384)",
1384
       CKM_INVALID_MECHANISM,
1385
       INVALID_CERT_EXTENSION),
1386
    OD(secgECsecp521r1, SEC_OID_SECG_EC_SECP521R1,
1387
       "SECG elliptic curve secp521r1 (aka NIST P-521)",
1388
       CKM_INVALID_MECHANISM,
1389
       INVALID_CERT_EXTENSION),
1390
1391
    /* ANSI X9.62 named elliptic curves (characteristic two field) */
1392
    OD(ansiX962c2pnb163v1, SEC_OID_ANSIX962_EC_C2PNB163V1,
1393
       "ANSI X9.62 elliptic curve c2pnb163v1",
1394
       CKM_INVALID_MECHANISM,
1395
       INVALID_CERT_EXTENSION),
1396
    OD(ansiX962c2pnb163v2, SEC_OID_ANSIX962_EC_C2PNB163V2,
1397
       "ANSI X9.62 elliptic curve c2pnb163v2",
1398
       CKM_INVALID_MECHANISM,
1399
       INVALID_CERT_EXTENSION),
1400
    OD(ansiX962c2pnb163v3, SEC_OID_ANSIX962_EC_C2PNB163V3,
1401
       "ANSI X9.62 elliptic curve c2pnb163v3",
1402
       CKM_INVALID_MECHANISM,
1403
       INVALID_CERT_EXTENSION),
1404
    OD(ansiX962c2pnb176v1, SEC_OID_ANSIX962_EC_C2PNB176V1,
1405
       "ANSI X9.62 elliptic curve c2pnb176v1",
1406
       CKM_INVALID_MECHANISM,
1407
       INVALID_CERT_EXTENSION),
1408
    OD(ansiX962c2tnb191v1, SEC_OID_ANSIX962_EC_C2TNB191V1,
1409
       "ANSI X9.62 elliptic curve c2tnb191v1",
1410
       CKM_INVALID_MECHANISM,
1411
       INVALID_CERT_EXTENSION),
1412
    OD(ansiX962c2tnb191v2, SEC_OID_ANSIX962_EC_C2TNB191V2,
1413
       "ANSI X9.62 elliptic curve c2tnb191v2",
1414
       CKM_INVALID_MECHANISM,
1415
       INVALID_CERT_EXTENSION),
1416
    OD(ansiX962c2tnb191v3, SEC_OID_ANSIX962_EC_C2TNB191V3,
1417
       "ANSI X9.62 elliptic curve c2tnb191v3",
1418
       CKM_INVALID_MECHANISM,
1419
       INVALID_CERT_EXTENSION),
1420
    OD(ansiX962c2onb191v4, SEC_OID_ANSIX962_EC_C2ONB191V4,
1421
       "ANSI X9.62 elliptic curve c2onb191v4",
1422
       CKM_INVALID_MECHANISM,
1423
       INVALID_CERT_EXTENSION),
1424
    OD(ansiX962c2onb191v5, SEC_OID_ANSIX962_EC_C2ONB191V5,
1425
       "ANSI X9.62 elliptic curve c2onb191v5",
1426
       CKM_INVALID_MECHANISM,
1427
       INVALID_CERT_EXTENSION),
1428
    OD(ansiX962c2pnb208w1, SEC_OID_ANSIX962_EC_C2PNB208W1,
1429
       "ANSI X9.62 elliptic curve c2pnb208w1",
1430
       CKM_INVALID_MECHANISM,
1431
       INVALID_CERT_EXTENSION),
1432
    OD(ansiX962c2tnb239v1, SEC_OID_ANSIX962_EC_C2TNB239V1,
1433
       "ANSI X9.62 elliptic curve c2tnb239v1",
1434
       CKM_INVALID_MECHANISM,
1435
       INVALID_CERT_EXTENSION),
1436
    OD(ansiX962c2tnb239v2, SEC_OID_ANSIX962_EC_C2TNB239V2,
1437
       "ANSI X9.62 elliptic curve c2tnb239v2",
1438
       CKM_INVALID_MECHANISM,
1439
       INVALID_CERT_EXTENSION),
1440
    OD(ansiX962c2tnb239v3, SEC_OID_ANSIX962_EC_C2TNB239V3,
1441
       "ANSI X9.62 elliptic curve c2tnb239v3",
1442
       CKM_INVALID_MECHANISM,
1443
       INVALID_CERT_EXTENSION),
1444
    OD(ansiX962c2onb239v4, SEC_OID_ANSIX962_EC_C2ONB239V4,
1445
       "ANSI X9.62 elliptic curve c2onb239v4",
1446
       CKM_INVALID_MECHANISM,
1447
       INVALID_CERT_EXTENSION),
1448
    OD(ansiX962c2onb239v5, SEC_OID_ANSIX962_EC_C2ONB239V5,
1449
       "ANSI X9.62 elliptic curve c2onb239v5",
1450
       CKM_INVALID_MECHANISM,
1451
       INVALID_CERT_EXTENSION),
1452
    OD(ansiX962c2pnb272w1, SEC_OID_ANSIX962_EC_C2PNB272W1,
1453
       "ANSI X9.62 elliptic curve c2pnb272w1",
1454
       CKM_INVALID_MECHANISM,
1455
       INVALID_CERT_EXTENSION),
1456
    OD(ansiX962c2pnb304w1, SEC_OID_ANSIX962_EC_C2PNB304W1,
1457
       "ANSI X9.62 elliptic curve c2pnb304w1",
1458
       CKM_INVALID_MECHANISM,
1459
       INVALID_CERT_EXTENSION),
1460
    OD(ansiX962c2tnb359v1, SEC_OID_ANSIX962_EC_C2TNB359V1,
1461
       "ANSI X9.62 elliptic curve c2tnb359v1",
1462
       CKM_INVALID_MECHANISM,
1463
       INVALID_CERT_EXTENSION),
1464
    OD(ansiX962c2pnb368w1, SEC_OID_ANSIX962_EC_C2PNB368W1,
1465
       "ANSI X9.62 elliptic curve c2pnb368w1",
1466
       CKM_INVALID_MECHANISM,
1467
       INVALID_CERT_EXTENSION),
1468
    OD(ansiX962c2tnb431r1, SEC_OID_ANSIX962_EC_C2TNB431R1,
1469
       "ANSI X9.62 elliptic curve c2tnb431r1",
1470
       CKM_INVALID_MECHANISM,
1471
       INVALID_CERT_EXTENSION),
1472
1473
    /* SECG named elliptic curves (characterisitic two field) */
1474
    OD(secgECsect113r1, SEC_OID_SECG_EC_SECT113R1,
1475
       "SECG elliptic curve sect113r1",
1476
       CKM_INVALID_MECHANISM,
1477
       INVALID_CERT_EXTENSION),
1478
    OD(secgECsect113r2, SEC_OID_SECG_EC_SECT113R2,
1479
       "SECG elliptic curve sect113r2",
1480
       CKM_INVALID_MECHANISM,
1481
       INVALID_CERT_EXTENSION),
1482
    OD(secgECsect131r1, SEC_OID_SECG_EC_SECT131R1,
1483
       "SECG elliptic curve sect131r1",
1484
       CKM_INVALID_MECHANISM,
1485
       INVALID_CERT_EXTENSION),
1486
    OD(secgECsect131r2, SEC_OID_SECG_EC_SECT131R2,
1487
       "SECG elliptic curve sect131r2",
1488
       CKM_INVALID_MECHANISM,
1489
       INVALID_CERT_EXTENSION),
1490
    OD(secgECsect163k1, SEC_OID_SECG_EC_SECT163K1,
1491
       "SECG elliptic curve sect163k1 (aka NIST K-163)",
1492
       CKM_INVALID_MECHANISM,
1493
       INVALID_CERT_EXTENSION),
1494
    OD(secgECsect163r1, SEC_OID_SECG_EC_SECT163R1,
1495
       "SECG elliptic curve sect163r1",
1496
       CKM_INVALID_MECHANISM,
1497
       INVALID_CERT_EXTENSION),
1498
    OD(secgECsect163r2, SEC_OID_SECG_EC_SECT163R2,
1499
       "SECG elliptic curve sect163r2 (aka NIST B-163)",
1500
       CKM_INVALID_MECHANISM,
1501
       INVALID_CERT_EXTENSION),
1502
    OD(secgECsect193r1, SEC_OID_SECG_EC_SECT193R1,
1503
       "SECG elliptic curve sect193r1",
1504
       CKM_INVALID_MECHANISM,
1505
       INVALID_CERT_EXTENSION),
1506
    OD(secgECsect193r2, SEC_OID_SECG_EC_SECT193R2,
1507
       "SECG elliptic curve sect193r2",
1508
       CKM_INVALID_MECHANISM,
1509
       INVALID_CERT_EXTENSION),
1510
    OD(secgECsect233k1, SEC_OID_SECG_EC_SECT233K1,
1511
       "SECG elliptic curve sect233k1 (aka NIST K-233)",
1512
       CKM_INVALID_MECHANISM,
1513
       INVALID_CERT_EXTENSION),
1514
    OD(secgECsect233r1, SEC_OID_SECG_EC_SECT233R1,
1515
       "SECG elliptic curve sect233r1 (aka NIST B-233)",
1516
       CKM_INVALID_MECHANISM,
1517
       INVALID_CERT_EXTENSION),
1518
    OD(secgECsect239k1, SEC_OID_SECG_EC_SECT239K1,
1519
       "SECG elliptic curve sect239k1",
1520
       CKM_INVALID_MECHANISM,
1521
       INVALID_CERT_EXTENSION),
1522
    OD(secgECsect283k1, SEC_OID_SECG_EC_SECT283K1,
1523
       "SECG elliptic curve sect283k1 (aka NIST K-283)",
1524
       CKM_INVALID_MECHANISM,
1525
       INVALID_CERT_EXTENSION),
1526
    OD(secgECsect283r1, SEC_OID_SECG_EC_SECT283R1,
1527
       "SECG elliptic curve sect283r1 (aka NIST B-283)",
1528
       CKM_INVALID_MECHANISM,
1529
       INVALID_CERT_EXTENSION),
1530
    OD(secgECsect409k1, SEC_OID_SECG_EC_SECT409K1,
1531
       "SECG elliptic curve sect409k1 (aka NIST K-409)",
1532
       CKM_INVALID_MECHANISM,
1533
       INVALID_CERT_EXTENSION),
1534
    OD(secgECsect409r1, SEC_OID_SECG_EC_SECT409R1,
1535
       "SECG elliptic curve sect409r1 (aka NIST B-409)",
1536
       CKM_INVALID_MECHANISM,
1537
       INVALID_CERT_EXTENSION),
1538
    OD(secgECsect571k1, SEC_OID_SECG_EC_SECT571K1,
1539
       "SECG elliptic curve sect571k1 (aka NIST K-571)",
1540
       CKM_INVALID_MECHANISM,
1541
       INVALID_CERT_EXTENSION),
1542
    OD(secgECsect571r1, SEC_OID_SECG_EC_SECT571R1,
1543
       "SECG elliptic curve sect571r1 (aka NIST B-571)",
1544
       CKM_INVALID_MECHANISM,
1545
       INVALID_CERT_EXTENSION),
1546
1547
    OD(netscapeAOLScreenname, SEC_OID_NETSCAPE_AOLSCREENNAME,
1548
       "AOL Screenname", CKM_INVALID_MECHANISM,
1549
       INVALID_CERT_EXTENSION),
1550
1551
    OD(x520SurName, SEC_OID_AVA_SURNAME,
1552
       "X520 Title", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1553
    OD(x520SerialNumber, SEC_OID_AVA_SERIAL_NUMBER,
1554
       "X520 Serial Number", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1555
    OD(x520StreetAddress, SEC_OID_AVA_STREET_ADDRESS,
1556
       "X520 Street Address", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1557
    OD(x520Title, SEC_OID_AVA_TITLE,
1558
       "X520 Title", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1559
    OD(x520PostalAddress, SEC_OID_AVA_POSTAL_ADDRESS,
1560
       "X520 Postal Address", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1561
    OD(x520PostalCode, SEC_OID_AVA_POSTAL_CODE,
1562
       "X520 Postal Code", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1563
    OD(x520PostOfficeBox, SEC_OID_AVA_POST_OFFICE_BOX,
1564
       "X520 Post Office Box", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1565
    OD(x520GivenName, SEC_OID_AVA_GIVEN_NAME,
1566
       "X520 Given Name", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1567
    OD(x520Initials, SEC_OID_AVA_INITIALS,
1568
       "X520 Initials", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1569
    OD(x520GenerationQualifier, SEC_OID_AVA_GENERATION_QUALIFIER,
1570
       "X520 Generation Qualifier",
1571
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1572
    OD(x520HouseIdentifier, SEC_OID_AVA_HOUSE_IDENTIFIER,
1573
       "X520 House Identifier",
1574
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1575
    OD(x520Pseudonym, SEC_OID_AVA_PSEUDONYM,
1576
       "X520 Pseudonym", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1577
1578
    /* More OIDs */
1579
    OD(pkixCAIssuers, SEC_OID_PKIX_CA_ISSUERS,
1580
       "PKIX CA issuers access method",
1581
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1582
    OD(pkcs9ExtensionRequest, SEC_OID_PKCS9_EXTENSION_REQUEST,
1583
       "PKCS #9 Extension Request",
1584
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1585
1586
    /* more ECC Signature Oids */
1587
    OD(ansix962SignatureRecommended,
1588
       SEC_OID_ANSIX962_ECDSA_SIGNATURE_RECOMMENDED_DIGEST,
1589
       "X9.62 ECDSA signature with recommended digest", CKM_INVALID_MECHANISM,
1590
       INVALID_CERT_EXTENSION),
1591
    OD(ansix962SignatureSpecified,
1592
       SEC_OID_ANSIX962_ECDSA_SIGNATURE_SPECIFIED_DIGEST,
1593
       "X9.62 ECDSA signature with specified digest", CKM_ECDSA,
1594
       INVALID_CERT_EXTENSION),
1595
    OD(ansix962SignaturewithSHA224Digest,
1596
       SEC_OID_ANSIX962_ECDSA_SHA224_SIGNATURE,
1597
       "X9.62 ECDSA signature with SHA224", CKM_ECDSA_SHA224,
1598
       INVALID_CERT_EXTENSION),
1599
    OD(ansix962SignaturewithSHA256Digest,
1600
       SEC_OID_ANSIX962_ECDSA_SHA256_SIGNATURE,
1601
       "X9.62 ECDSA signature with SHA256", CKM_ECDSA_SHA256,
1602
       INVALID_CERT_EXTENSION),
1603
    OD(ansix962SignaturewithSHA384Digest,
1604
       SEC_OID_ANSIX962_ECDSA_SHA384_SIGNATURE,
1605
       "X9.62 ECDSA signature with SHA384", CKM_ECDSA_SHA384,
1606
       INVALID_CERT_EXTENSION),
1607
    OD(ansix962SignaturewithSHA512Digest,
1608
       SEC_OID_ANSIX962_ECDSA_SHA512_SIGNATURE,
1609
       "X9.62 ECDSA signature with SHA512", CKM_ECDSA_SHA512,
1610
       INVALID_CERT_EXTENSION),
1611
1612
    /* More id-ce and id-pe OIDs from RFC 3280 */
1613
    OD(x509HoldInstructionCode, SEC_OID_X509_HOLD_INSTRUCTION_CODE,
1614
       "CRL Hold Instruction Code", CKM_INVALID_MECHANISM,
1615
       UNSUPPORTED_CERT_EXTENSION),
1616
    OD(x509DeltaCRLIndicator, SEC_OID_X509_DELTA_CRL_INDICATOR,
1617
       "Delta CRL Indicator", CKM_INVALID_MECHANISM,
1618
       FAKE_SUPPORTED_CERT_EXTENSION),
1619
    OD(x509IssuingDistributionPoint, SEC_OID_X509_ISSUING_DISTRIBUTION_POINT,
1620
       "Issuing Distribution Point", CKM_INVALID_MECHANISM,
1621
       FAKE_SUPPORTED_CERT_EXTENSION),
1622
    OD(x509CertIssuer, SEC_OID_X509_CERT_ISSUER,
1623
       "Certificate Issuer Extension", CKM_INVALID_MECHANISM,
1624
       FAKE_SUPPORTED_CERT_EXTENSION),
1625
    OD(x509FreshestCRL, SEC_OID_X509_FRESHEST_CRL,
1626
       "Freshest CRL", CKM_INVALID_MECHANISM,
1627
       UNSUPPORTED_CERT_EXTENSION),
1628
    OD(x509InhibitAnyPolicy, SEC_OID_X509_INHIBIT_ANY_POLICY,
1629
       "Inhibit Any Policy", CKM_INVALID_MECHANISM,
1630
       FAKE_SUPPORTED_CERT_EXTENSION),
1631
    OD(x509SubjectInfoAccess, SEC_OID_X509_SUBJECT_INFO_ACCESS,
1632
       "Subject Info Access", CKM_INVALID_MECHANISM,
1633
       UNSUPPORTED_CERT_EXTENSION),
1634
1635
    /* Camellia algorithm OIDs */
1636
    OD(camellia128_CBC, SEC_OID_CAMELLIA_128_CBC,
1637
       "CAMELLIA-128-CBC", CKM_CAMELLIA_CBC, INVALID_CERT_EXTENSION),
1638
    OD(camellia192_CBC, SEC_OID_CAMELLIA_192_CBC,
1639
       "CAMELLIA-192-CBC", CKM_CAMELLIA_CBC, INVALID_CERT_EXTENSION),
1640
    OD(camellia256_CBC, SEC_OID_CAMELLIA_256_CBC,
1641
       "CAMELLIA-256-CBC", CKM_CAMELLIA_CBC, INVALID_CERT_EXTENSION),
1642
1643
    /* PKCS 5 v2 OIDS */
1644
    OD(pkcs5Pbkdf2, SEC_OID_PKCS5_PBKDF2,
1645
       "PKCS #5 Password Based Key Derive Function v2 ",
1646
       CKM_PKCS5_PBKD2, INVALID_CERT_EXTENSION),
1647
    OD(pkcs5Pbes2, SEC_OID_PKCS5_PBES2,
1648
       "PKCS #5 Password Based Encryption v2 ",
1649
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1650
    OD(pkcs5Pbmac1, SEC_OID_PKCS5_PBMAC1,
1651
       "PKCS #5 Password Based Authentication v1 ",
1652
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1653
    OD(hmac_sha1, SEC_OID_HMAC_SHA1, "HMAC SHA-1",
1654
       CKM_SHA_1_HMAC, INVALID_CERT_EXTENSION),
1655
    OD(hmac_sha224, SEC_OID_HMAC_SHA224, "HMAC SHA-224",
1656
       CKM_SHA224_HMAC, INVALID_CERT_EXTENSION),
1657
    OD(hmac_sha256, SEC_OID_HMAC_SHA256, "HMAC SHA-256",
1658
       CKM_SHA256_HMAC, INVALID_CERT_EXTENSION),
1659
    OD(hmac_sha384, SEC_OID_HMAC_SHA384, "HMAC SHA-384",
1660
       CKM_SHA384_HMAC, INVALID_CERT_EXTENSION),
1661
    OD(hmac_sha512, SEC_OID_HMAC_SHA512, "HMAC SHA-512",
1662
       CKM_SHA512_HMAC, INVALID_CERT_EXTENSION),
1663
1664
    /* SIA extension OIDs */
1665
    OD(x509SIATimeStamping, SEC_OID_PKIX_TIMESTAMPING,
1666
       "SIA Time Stamping", CKM_INVALID_MECHANISM,
1667
       INVALID_CERT_EXTENSION),
1668
    OD(x509SIACaRepository, SEC_OID_PKIX_CA_REPOSITORY,
1669
       "SIA CA Repository", CKM_INVALID_MECHANISM,
1670
       INVALID_CERT_EXTENSION),
1671
1672
    OD(isoSHA1WithRSASignature, SEC_OID_ISO_SHA1_WITH_RSA_SIGNATURE,
1673
       "ISO SHA-1 with RSA Signature",
1674
       CKM_SHA1_RSA_PKCS, INVALID_CERT_EXTENSION),
1675
1676
    /* SEED algorithm OIDs */
1677
    OD(seed_CBC, SEC_OID_SEED_CBC,
1678
       "SEED-CBC", CKM_SEED_CBC, INVALID_CERT_EXTENSION),
1679
1680
    OD(x509CertificatePoliciesAnyPolicy, SEC_OID_X509_ANY_POLICY,
1681
       "Certificate Policies AnyPolicy",
1682
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1683
1684
    OD(pkcs1RSAOAEPEncryption, SEC_OID_PKCS1_RSA_OAEP_ENCRYPTION,
1685
       "PKCS #1 RSA-OAEP Encryption", CKM_RSA_PKCS_OAEP,
1686
       INVALID_CERT_EXTENSION),
1687
1688
    OD(pkcs1MGF1, SEC_OID_PKCS1_MGF1,
1689
       "PKCS #1 MGF1 Mask Generation Function", CKM_INVALID_MECHANISM,
1690
       INVALID_CERT_EXTENSION),
1691
1692
    OD(pkcs1PSpecified, SEC_OID_PKCS1_PSPECIFIED,
1693
       "PKCS #1 RSA-OAEP Explicitly Specified Encoding Parameters",
1694
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1695
1696
    OD(pkcs1RSAPSSSignature, SEC_OID_PKCS1_RSA_PSS_SIGNATURE,
1697
       "PKCS #1 RSA-PSS Signature", CKM_RSA_PKCS_PSS,
1698
       INVALID_CERT_EXTENSION),
1699
1700
    OD(pkcs1SHA224WithRSAEncryption, SEC_OID_PKCS1_SHA224_WITH_RSA_ENCRYPTION,
1701
       "PKCS #1 SHA-224 With RSA Encryption", CKM_SHA224_RSA_PKCS,
1702
       INVALID_CERT_EXTENSION),
1703
1704
    OD(sha224, SEC_OID_SHA224, "SHA-224", CKM_SHA224, INVALID_CERT_EXTENSION),
1705
1706
    OD(evIncorporationLocality, SEC_OID_EV_INCORPORATION_LOCALITY,
1707
       "Jurisdiction of Incorporation Locality Name",
1708
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1709
    OD(evIncorporationState, SEC_OID_EV_INCORPORATION_STATE,
1710
       "Jurisdiction of Incorporation State Name",
1711
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1712
    OD(evIncorporationCountry, SEC_OID_EV_INCORPORATION_COUNTRY,
1713
       "Jurisdiction of Incorporation Country Name",
1714
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1715
    OD(x520BusinessCategory, SEC_OID_BUSINESS_CATEGORY,
1716
       "Business Category",
1717
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1718
1719
    OD(nistDSASignaturewithSHA224Digest,
1720
       SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA224_DIGEST,
1721
       "DSA with SHA-224 Signature",
1722
       CKM_DSA_SHA224, INVALID_CERT_EXTENSION),
1723
    OD(nistDSASignaturewithSHA256Digest,
1724
       SEC_OID_NIST_DSA_SIGNATURE_WITH_SHA256_DIGEST,
1725
       "DSA with SHA-256 Signature",
1726
       CKM_DSA_SHA256, INVALID_CERT_EXTENSION),
1727
    OD(msExtendedKeyUsageTrustListSigning,
1728
       SEC_OID_MS_EXT_KEY_USAGE_CTL_SIGNING,
1729
       "Microsoft Trust List Signing",
1730
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1731
    OD(x520Name, SEC_OID_AVA_NAME,
1732
       "X520 Name", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1733
1734
    OD(aes128_GCM, SEC_OID_AES_128_GCM,
1735
       "AES-128-GCM", CKM_AES_GCM, INVALID_CERT_EXTENSION),
1736
    OD(aes192_GCM, SEC_OID_AES_192_GCM,
1737
       "AES-192-GCM", CKM_AES_GCM, INVALID_CERT_EXTENSION),
1738
    OD(aes256_GCM, SEC_OID_AES_256_GCM,
1739
       "AES-256-GCM", CKM_AES_GCM, INVALID_CERT_EXTENSION),
1740
    OD(idea_CBC, SEC_OID_IDEA_CBC,
1741
       "IDEA_CBC", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1742
1743
    ODE(SEC_OID_RC2_40_CBC,
1744
        "RC2-40-CBC", CKM_RC2_CBC, INVALID_CERT_EXTENSION),
1745
    ODE(SEC_OID_DES_40_CBC,
1746
        "DES-40-CBC", CKM_RC2_CBC, INVALID_CERT_EXTENSION),
1747
    ODE(SEC_OID_RC4_40,
1748
        "RC4-40", CKM_RC4, INVALID_CERT_EXTENSION),
1749
    ODE(SEC_OID_RC4_56,
1750
        "RC4-56", CKM_RC4, INVALID_CERT_EXTENSION),
1751
    ODE(SEC_OID_NULL_CIPHER,
1752
        "NULL cipher", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1753
    ODE(SEC_OID_HMAC_MD5,
1754
        "HMAC-MD5", CKM_MD5_HMAC, INVALID_CERT_EXTENSION),
1755
    ODE(SEC_OID_TLS_RSA,
1756
        "TLS RSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1757
    ODE(SEC_OID_TLS_DHE_RSA,
1758
        "TLS DHE-RSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1759
    ODE(SEC_OID_TLS_DHE_DSS,
1760
        "TLS DHE-DSS key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1761
    ODE(SEC_OID_TLS_DH_RSA,
1762
        "TLS DH-RSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1763
    ODE(SEC_OID_TLS_DH_DSS,
1764
        "TLS DH-DSS key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1765
    ODE(SEC_OID_TLS_DH_ANON,
1766
        "TLS DH-ANON key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1767
    ODE(SEC_OID_TLS_ECDHE_ECDSA,
1768
        "TLS ECDHE-ECDSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1769
    ODE(SEC_OID_TLS_ECDHE_RSA,
1770
        "TLS ECDHE-RSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1771
    ODE(SEC_OID_TLS_ECDH_ECDSA,
1772
        "TLS ECDH-ECDSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1773
    ODE(SEC_OID_TLS_ECDH_RSA,
1774
        "TLS ECDH-RSA key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1775
    ODE(SEC_OID_TLS_ECDH_ANON,
1776
        "TLS ECDH-ANON key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1777
    ODE(SEC_OID_TLS_RSA_EXPORT,
1778
        "TLS RSA-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1779
    ODE(SEC_OID_TLS_DHE_RSA_EXPORT,
1780
        "TLS DHE-RSA-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1781
    ODE(SEC_OID_TLS_DHE_DSS_EXPORT,
1782
        "TLS DHE-DSS-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1783
    ODE(SEC_OID_TLS_DH_RSA_EXPORT,
1784
        "TLS DH-RSA-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1785
    ODE(SEC_OID_TLS_DH_DSS_EXPORT,
1786
        "TLS DH-DSS-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1787
    ODE(SEC_OID_TLS_DH_ANON_EXPORT,
1788
        "TLS DH-ANON-EXPORT key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1789
    ODE(SEC_OID_APPLY_SSL_POLICY,
1790
        "Apply SSL policy (pseudo-OID)", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1791
    ODE(SEC_OID_CHACHA20_POLY1305,
1792
        "ChaCha20-Poly1305", CKM_NSS_CHACHA20_POLY1305, INVALID_CERT_EXTENSION),
1793
1794
    ODE(SEC_OID_TLS_ECDHE_PSK,
1795
        "TLS ECHDE-PSK key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1796
    ODE(SEC_OID_TLS_DHE_PSK,
1797
        "TLS DHE-PSK key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1798
1799
    ODE(SEC_OID_TLS_FFDHE_2048,
1800
        "TLS FFDHE 2048-bit key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1801
    ODE(SEC_OID_TLS_FFDHE_3072,
1802
        "TLS FFDHE 3072-bit key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1803
    ODE(SEC_OID_TLS_FFDHE_4096,
1804
        "TLS FFDHE 4096-bit key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1805
    ODE(SEC_OID_TLS_FFDHE_6144,
1806
        "TLS FFDHE 6144-bit key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1807
    ODE(SEC_OID_TLS_FFDHE_8192,
1808
        "TLS FFDHE 8192-bit key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1809
    ODE(SEC_OID_TLS_DHE_CUSTOM,
1810
        "TLS DHE custom group key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1811
    OD(curve25519, SEC_OID_CURVE25519,
1812
       "Curve25519", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1813
    ODE(SEC_OID_TLS13_KEA_ANY,
1814
        "TLS 1.3 fake key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1815
1816
    OD(x509ExtKeyUsageAnyUsage, SEC_OID_X509_ANY_EXT_KEY_USAGE,
1817
       "Any Extended Key Usage",
1818
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1819
    OD(pkixExtendedKeyUsageIPsecIKE,
1820
       SEC_OID_EXT_KEY_USAGE_IPSEC_IKE,
1821
       "IPsec IKE Certificate",
1822
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1823
    OD(ipsecIKEEnd,
1824
       SEC_OID_IPSEC_IKE_END,
1825
       "IPsec IKE End",
1826
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1827
    OD(ipsecIKEIntermediate,
1828
       SEC_OID_IPSEC_IKE_INTERMEDIATE,
1829
       "IPsec IKE Intermediate",
1830
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1831
    OD(pkixExtendedKeyUsageIPsecEnd,
1832
       SEC_OID_EXT_KEY_USAGE_IPSEC_END,
1833
       "IPsec Tunnel",
1834
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1835
    OD(pkixExtendedKeyUsageIPsecTunnel,
1836
       SEC_OID_EXT_KEY_USAGE_IPSEC_TUNNEL,
1837
       "IPsec Tunnel",
1838
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1839
    OD(pkixExtendedKeyUsageIPsecUser,
1840
       SEC_OID_EXT_KEY_USAGE_IPSEC_USER,
1841
       "IPsec User",
1842
       CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1843
1844
    OD(sha3_224, SEC_OID_SHA3_224, "SHA3-224", CKM_SHA3_224, INVALID_CERT_EXTENSION),
1845
    OD(sha3_256, SEC_OID_SHA3_256, "SHA3-256", CKM_SHA3_256, INVALID_CERT_EXTENSION),
1846
    OD(sha3_384, SEC_OID_SHA3_384, "SHA3-384", CKM_SHA3_384, INVALID_CERT_EXTENSION),
1847
    OD(sha3_512, SEC_OID_SHA3_512, "SHA3-512", CKM_SHA3_512, INVALID_CERT_EXTENSION),
1848
1849
    OD(hmac_sha3_224, SEC_OID_HMAC_SHA3_224, "HMAC SHA3-224", CKM_SHA3_224_HMAC, INVALID_CERT_EXTENSION),
1850
    OD(hmac_sha3_256, SEC_OID_HMAC_SHA3_256, "HMAC SHA3-256", CKM_SHA3_256_HMAC, INVALID_CERT_EXTENSION),
1851
    OD(hmac_sha3_384, SEC_OID_HMAC_SHA3_384, "HMAC SHA3-384", CKM_SHA3_384_HMAC, INVALID_CERT_EXTENSION),
1852
    OD(hmac_sha3_512, SEC_OID_HMAC_SHA3_512, "HMAC SHA3-512", CKM_SHA3_512_HMAC, INVALID_CERT_EXTENSION),
1853
1854
    ODE(SEC_OID_XYBER768D00,
1855
        "X25519+Kyber768 key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1856
1857
    OD(ed25519Signature, SEC_OID_ED25519_SIGNATURE, "X9.62 EDDSA signature", CKM_EDDSA,
1858
       INVALID_CERT_EXTENSION),
1859
1860
    OD(ed25519PublicKey, SEC_OID_ED25519_PUBLIC_KEY,
1861
       "X9.62 elliptic edwards curve public key", CKM_EC_EDWARDS_KEY_PAIR_GEN, INVALID_CERT_EXTENSION),
1862
1863
    OD(dhSinglePassstdDHsha1kdfscheme, SEC_OID_DHSINGLEPASS_STDDH_SHA1KDF_SCHEME,
1864
       "Eliptic Curve Diffie-Hellman Single Pass Standard with SHA1 KDF", CKM_ECDH1_DERIVE,
1865
       INVALID_CERT_EXTENSION),
1866
    OD(dhSinglePassstdDHsha224kdfscheme, SEC_OID_DHSINGLEPASS_STDDH_SHA224KDF_SCHEME,
1867
       "Eliptic Curve Diffie-Hellman Single Pass Standard with SHA224 KDF", CKM_ECDH1_DERIVE,
1868
       INVALID_CERT_EXTENSION),
1869
    OD(dhSinglePassstdDHsha256kdfscheme, SEC_OID_DHSINGLEPASS_STDDH_SHA256KDF_SCHEME,
1870
       "Eliptic Curve Diffie-Hellman Single Pass Standard with SHA256 KDF", CKM_ECDH1_DERIVE,
1871
       INVALID_CERT_EXTENSION),
1872
    OD(dhSinglePassstdDHsha384kdfscheme, SEC_OID_DHSINGLEPASS_STDDH_SHA384KDF_SCHEME,
1873
       "Eliptic Curve Diffie-Hellman Single Pass Standard with SHA384 KDF", CKM_ECDH1_DERIVE,
1874
       INVALID_CERT_EXTENSION),
1875
    OD(dhSinglePassstdDHsha512kdfscheme, SEC_OID_DHSINGLEPASS_STDDH_SHA512KDF_SCHEME,
1876
       "Eliptic Curve Diffie-Hellman Single Pass Standard with SHA512 KDF", CKM_ECDH1_DERIVE,
1877
       INVALID_CERT_EXTENSION),
1878
    OD(dhSinglePasscofactorDHsha1kdfscheme, SEC_OID_DHSINGLEPASS_COFACTORDH_SHA1KDF_SCHEME,
1879
       "Eliptic Curve Diffie-Hellman Single Pass Cofactor with SHA1 KDF", CKM_ECDH1_COFACTOR_DERIVE,
1880
       INVALID_CERT_EXTENSION),
1881
    OD(dhSinglePasscofactorDHsha224kdfscheme, SEC_OID_DHSINGLEPASS_COFACTORDH_SHA224KDF_SCHEME,
1882
       "Eliptic Curve Diffie-Hellman Single Pass Cofactor with SHA224 KDF", CKM_ECDH1_COFACTOR_DERIVE,
1883
       INVALID_CERT_EXTENSION),
1884
    OD(dhSinglePasscofactorDHsha256kdfscheme, SEC_OID_DHSINGLEPASS_COFACTORDH_SHA256KDF_SCHEME,
1885
       "Eliptic Curve Diffie-Hellman Single Pass Cofactor with SHA256 KDF", CKM_ECDH1_COFACTOR_DERIVE,
1886
       INVALID_CERT_EXTENSION),
1887
    OD(dhSinglePasscofactorDHsha384kdfscheme, SEC_OID_DHSINGLEPASS_COFACTORDH_SHA384KDF_SCHEME,
1888
       "Eliptic Curve Diffie-Hellman Single Pass Cofactor with SHA384 KDF", CKM_ECDH1_COFACTOR_DERIVE,
1889
       INVALID_CERT_EXTENSION),
1890
    OD(dhSinglePasscofactorDHsha512kdfscheme, SEC_OID_DHSINGLEPASS_COFACTORDH_SHA512KDF_SCHEME,
1891
       "Eliptic Curve Diffie-Hellman Single Pass Cofactor with SHA512 KDF", CKM_ECDH1_COFACTOR_DERIVE,
1892
       INVALID_CERT_EXTENSION),
1893
    ODE(SEC_OID_RC2_64_CBC, "RC2-64-CBC", CKM_RC2_CBC, INVALID_CERT_EXTENSION),
1894
    ODE(SEC_OID_RC2_128_CBC, "RC2-128-CBC", CKM_RC2_CBC, INVALID_CERT_EXTENSION),
1895
    ODE(SEC_OID_ECDH_KEA, "ECDH", CKM_ECDH1_DERIVE, INVALID_CERT_EXTENSION),
1896
    OD(x25519PublicKey, SEC_OID_X25519,
1897
       "X25519 key exchange", CKM_EC_MONTGOMERY_KEY_PAIR_GEN, INVALID_CERT_EXTENSION),
1898
1899
    ODE(SEC_OID_MLKEM768X25519,
1900
        "ML-KEM-768+X25519 key exchange", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1901
    ODE(SEC_OID_TLS_REQUIRE_EMS,
1902
        "TLS Require EMS", CKM_INVALID_MECHANISM, INVALID_CERT_EXTENSION),
1903
1904
};
1905
1906
/* PRIVATE EXTENDED SECOID Table
1907
 * This table is private. Its structure is opaque to the outside.
1908
 * It is indexed by the same SECOidTag as the oids table above.
1909
 * Every member of this struct must have accessor functions (set, get)
1910
 * and those functions must operate by value, not by reference.
1911
 * The addresses of the contents of this table must not be exposed
1912
 * by the accessor functions.
1913
 */
1914
typedef struct privXOidStr {
1915
    PRUint32 notPolicyFlags; /* ones complement of policy flags */
1916
} privXOid;
1917
1918
static privXOid xOids[SEC_OID_TOTAL];
1919
1920
/*
1921
 * now the dynamic table. The dynamic table gets build at init time.
1922
 * and conceivably gets modified if the user loads new crypto modules.
1923
 * All this static data, and the allocated data to which it points,
1924
 * is protected by a global reader/writer lock.
1925
 * The c language guarantees that global and static data that is not
1926
 * explicitly initialized will be initialized with zeros.  If we
1927
 * initialize it with zeros, the data goes into the initialized data
1928
 * secment, and increases the size of the library.  By leaving it
1929
 * uninitialized, it is allocated in BSS, and does NOT increase the
1930
 * library size.
1931
 */
1932
1933
typedef struct dynXOidStr {
1934
    SECOidData data;
1935
    privXOid priv;
1936
} dynXOid;
1937
1938
static NSSRWLock *dynOidLock;
1939
static PLArenaPool *dynOidPool;
1940
static PLHashTable *dynOidHash;
1941
static dynXOid **dynOidTable; /* not in the pool */
1942
static int dynOidEntriesAllocated;
1943
static int dynOidEntriesUsed;
1944
1945
/* Creates NSSRWLock and dynOidPool at initialization time.
1946
 */
1947
static SECStatus
1948
secoid_InitDynOidData(void)
1949
0
{
1950
0
    SECStatus rv = SECSuccess;
1951
1952
0
    dynOidLock = NSSRWLock_New(1, "dynamic OID data");
1953
0
    if (!dynOidLock) {
1954
0
        return SECFailure; /* Error code should already be set. */
1955
0
    }
1956
0
    dynOidPool = PORT_NewArena(2048);
1957
0
    if (!dynOidPool) {
1958
0
        rv = SECFailure /* Error code should already be set. */;
1959
0
    }
1960
0
    return rv;
1961
0
}
1962
1963
/* Add oidData to hash table.  Caller holds write lock dynOidLock. */
1964
static SECStatus
1965
secoid_HashDynamicOiddata(const SECOidData *oid)
1966
0
{
1967
0
    PLHashEntry *entry;
1968
1969
0
    if (!dynOidHash) {
1970
0
        dynOidHash = PL_NewHashTable(0, SECITEM_Hash, SECITEM_HashCompare,
1971
0
                                     PL_CompareValues, NULL, NULL);
1972
0
        if (!dynOidHash) {
1973
0
            return SECFailure;
1974
0
        }
1975
0
    }
1976
1977
0
    entry = PL_HashTableAdd(dynOidHash, &oid->oid, (void *)oid);
1978
0
    return entry ? SECSuccess : SECFailure;
1979
0
}
1980
1981
/*
1982
 * Lookup a Dynamic OID. Dynamic OID's still change slowly, so it's
1983
 * cheaper to rehash the table when it changes than it is to do the loop
1984
 * each time.
1985
 */
1986
static SECOidData *
1987
secoid_FindDynamic(const SECItem *key)
1988
0
{
1989
0
    SECOidData *ret = NULL;
1990
1991
0
    NSSRWLock_LockRead(dynOidLock);
1992
0
    if (dynOidHash) {
1993
0
        ret = (SECOidData *)PL_HashTableLookup(dynOidHash, key);
1994
0
    }
1995
0
    NSSRWLock_UnlockRead(dynOidLock);
1996
0
    if (ret == NULL) {
1997
0
        PORT_SetError(SEC_ERROR_UNRECOGNIZED_OID);
1998
0
    }
1999
0
    return ret;
2000
0
}
2001
2002
static dynXOid *
2003
secoid_FindDynamicByTag(SECOidTag tagnum)
2004
0
{
2005
0
    dynXOid *dxo = NULL;
2006
0
    int tagNumDiff;
2007
2008
0
    if (tagnum < SEC_OID_TOTAL) {
2009
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2010
0
        return NULL;
2011
0
    }
2012
0
    tagNumDiff = tagnum - SEC_OID_TOTAL;
2013
2014
0
    NSSRWLock_LockRead(dynOidLock);
2015
0
    if (dynOidTable != NULL &&
2016
0
        tagNumDiff < dynOidEntriesUsed) {
2017
0
        dxo = dynOidTable[tagNumDiff];
2018
0
    }
2019
0
    NSSRWLock_UnlockRead(dynOidLock);
2020
0
    if (dxo == NULL) {
2021
0
        PORT_SetError(SEC_ERROR_UNRECOGNIZED_OID);
2022
0
    }
2023
0
    return dxo;
2024
0
}
2025
2026
/*
2027
 * This routine is thread safe now.
2028
 */
2029
SECOidTag
2030
SECOID_AddEntry(const SECOidData *src)
2031
0
{
2032
0
    dynXOid *ddst;
2033
0
    SECOidData *dst;
2034
0
    dynXOid **table;
2035
0
    SECOidTag ret = SEC_OID_UNKNOWN;
2036
0
    SECStatus rv;
2037
0
    int used;
2038
2039
0
    if (!src || !src->oid.data || !src->oid.len ||
2040
0
        !src->desc || !strlen(src->desc)) {
2041
0
        PORT_SetError(SEC_ERROR_INVALID_ARGS);
2042
0
        return ret;
2043
0
    }
2044
0
    if (src->supportedExtension != INVALID_CERT_EXTENSION &&
2045
0
        src->supportedExtension != UNSUPPORTED_CERT_EXTENSION &&
2046
0
        src->supportedExtension != SUPPORTED_CERT_EXTENSION) {
2047
0
        PORT_SetError(SEC_ERROR_INVALID_ARGS);
2048
0
        return ret;
2049
0
    }
2050
2051
0
    if (!dynOidPool || !dynOidLock) {
2052
0
        PORT_SetError(SEC_ERROR_NOT_INITIALIZED);
2053
0
        return ret;
2054
0
    }
2055
2056
0
    NSSRWLock_LockWrite(dynOidLock);
2057
2058
    /* We've just acquired the write lock, and now we call FindOIDTag
2059
    ** which will acquire and release the read lock.  NSSRWLock has been
2060
    ** designed to allow this very case without deadlock.  This approach
2061
    ** makes the test for the presence of the OID, and the subsequent
2062
    ** addition of the OID to the table a single atomic write operation.
2063
    */
2064
0
    ret = SECOID_FindOIDTag(&src->oid);
2065
0
    if (ret != SEC_OID_UNKNOWN) {
2066
        /* we could return an error here, but I chose not to do that.
2067
        ** This way, if we add an OID to the shared library's built in
2068
        ** list of OIDs in some future release, and that OID is the same
2069
        ** as some OID that a program has been adding, the program will
2070
        ** not suddenly stop working.
2071
        */
2072
0
        goto done;
2073
0
    }
2074
2075
0
    table = dynOidTable;
2076
0
    used = dynOidEntriesUsed;
2077
2078
0
    if (used + 1 > dynOidEntriesAllocated) {
2079
0
        dynXOid **newTable;
2080
0
        int newTableEntries = dynOidEntriesAllocated + 16;
2081
2082
0
        newTable = (dynXOid **)PORT_Realloc(table,
2083
0
                                            newTableEntries * sizeof(dynXOid *));
2084
0
        if (newTable == NULL) {
2085
0
            goto done;
2086
0
        }
2087
0
        dynOidTable = table = newTable;
2088
0
        dynOidEntriesAllocated = newTableEntries;
2089
0
    }
2090
2091
    /* copy oid structure */
2092
0
    ddst = PORT_ArenaZNew(dynOidPool, dynXOid);
2093
0
    if (!ddst) {
2094
0
        goto done;
2095
0
    }
2096
0
    dst = &ddst->data;
2097
0
    rv = SECITEM_CopyItem(dynOidPool, &dst->oid, &src->oid);
2098
0
    if (rv != SECSuccess) {
2099
0
        goto done;
2100
0
    }
2101
0
    dst->desc = PORT_ArenaStrdup(dynOidPool, src->desc);
2102
0
    if (!dst->desc) {
2103
0
        goto done;
2104
0
    }
2105
0
    dst->offset = (SECOidTag)(used + SEC_OID_TOTAL);
2106
0
    dst->mechanism = src->mechanism;
2107
0
    dst->supportedExtension = src->supportedExtension;
2108
    /* disable S/MIME for new oids by default */
2109
0
    ddst->priv.notPolicyFlags = NSS_USE_ALG_IN_SMIME;
2110
2111
0
    rv = secoid_HashDynamicOiddata(dst);
2112
0
    if (rv == SECSuccess) {
2113
0
        table[used++] = ddst;
2114
0
        dynOidEntriesUsed = used;
2115
0
        ret = dst->offset;
2116
0
    }
2117
0
done:
2118
0
    NSSRWLock_UnlockWrite(dynOidLock);
2119
0
    return ret;
2120
0
}
2121
2122
/* normal static table processing */
2123
static PLHashTable *oidhash = NULL;
2124
static PLHashTable *oidmechhash = NULL;
2125
2126
static PLHashNumber
2127
secoid_HashNumber(const void *key)
2128
0
{
2129
0
    return (PLHashNumber)((char *)key - (char *)NULL);
2130
0
}
2131
2132
0
#define DEF_FLAGS (NSS_USE_ALG_IN_CERT_SIGNATURE | NSS_USE_ALG_IN_SSL_KX | \
2133
0
                   NSS_USE_ALG_IN_SMIME | NSS_USE_ALG_IN_PKCS12)
2134
static void
2135
handleHashAlgSupport(char *envVal)
2136
0
{
2137
0
    char *myVal = PORT_Strdup(envVal); /* Get a copy we can alter */
2138
0
    char *arg = myVal;
2139
2140
0
    while (arg && *arg) {
2141
0
        char *nextArg = PL_strpbrk(arg, ";");
2142
0
        PRUint32 notEnable;
2143
2144
0
        if (nextArg) {
2145
0
            while (*nextArg == ';') {
2146
0
                *nextArg++ = '\0';
2147
0
            }
2148
0
        }
2149
0
        notEnable = (*arg == '-') ? (DEF_FLAGS) : 0;
2150
0
        if ((*arg == '+' || *arg == '-') && *++arg) {
2151
0
            int i;
2152
2153
0
            for (i = 1; i < SEC_OID_TOTAL; i++) {
2154
0
                if (oids[i].desc && strstr(arg, oids[i].desc)) {
2155
0
                    xOids[i].notPolicyFlags = notEnable |
2156
0
                                              (xOids[i].notPolicyFlags & ~(DEF_FLAGS));
2157
0
                }
2158
0
            }
2159
0
        }
2160
0
        arg = nextArg;
2161
0
    }
2162
0
    PORT_Free(myVal); /* can handle NULL argument OK */
2163
0
}
2164
2165
SECStatus
2166
SECOID_Init(void)
2167
0
{
2168
0
    PLHashEntry *entry;
2169
0
    const SECOidData *oid;
2170
0
    SECOidTag i;
2171
0
    char *envVal;
2172
2173
0
#define NSS_VERSION_VARIABLE __nss_util_version
2174
0
#include "verref.h"
2175
2176
0
    if (oidhash) {
2177
0
        return SECSuccess; /* already initialized */
2178
0
    }
2179
2180
    /* xyber768d00 must be enabled explicitly */
2181
0
    xOids[SEC_OID_XYBER768D00].notPolicyFlags = NSS_USE_ALG_IN_SSL_KX;
2182
2183
0
    if (!PR_GetEnvSecure("NSS_ALLOW_WEAK_SIGNATURE_ALG")) {
2184
        /* initialize any policy flags that are disabled by default */
2185
0
        xOids[SEC_OID_MD2].notPolicyFlags = ~NSS_USE_ALG_IN_PKCS12_DECRYPT;
2186
0
        xOids[SEC_OID_MD4].notPolicyFlags = ~NSS_USE_ALG_IN_PKCS12_DECRYPT;
2187
0
        xOids[SEC_OID_MD5].notPolicyFlags = ~NSS_USE_ALG_IN_PKCS12_DECRYPT;
2188
0
        xOids[SEC_OID_PKCS1_MD2_WITH_RSA_ENCRYPTION].notPolicyFlags = ~0;
2189
0
        xOids[SEC_OID_PKCS1_MD4_WITH_RSA_ENCRYPTION].notPolicyFlags = ~0;
2190
0
        xOids[SEC_OID_PKCS1_MD5_WITH_RSA_ENCRYPTION].notPolicyFlags = ~0;
2191
0
        xOids[SEC_OID_PKCS5_PBE_WITH_MD2_AND_DES_CBC].notPolicyFlags = ~NSS_USE_ALG_IN_PKCS12_DECRYPT;
2192
0
        xOids[SEC_OID_PKCS5_PBE_WITH_MD5_AND_DES_CBC].notPolicyFlags = ~NSS_USE_ALG_IN_PKCS12_DECRYPT;
2193
0
    }
2194
2195
    /* turn off NSS_USE_POLICY_IN_SSL by default */
2196
0
    xOids[SEC_OID_APPLY_SSL_POLICY].notPolicyFlags = NSS_USE_POLICY_IN_SSL;
2197
    /* turn off TLS REQUIRE EMS by default */
2198
0
    xOids[SEC_OID_TLS_REQUIRE_EMS].notPolicyFlags = ~0;
2199
2200
0
    envVal = PR_GetEnvSecure("NSS_HASH_ALG_SUPPORT");
2201
0
    if (envVal)
2202
0
        handleHashAlgSupport(envVal);
2203
2204
0
    if (secoid_InitDynOidData() != SECSuccess) {
2205
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2206
0
        PORT_Assert(0); /* this function should never fail */
2207
0
        return SECFailure;
2208
0
    }
2209
2210
0
    oidhash = PL_NewHashTable(0, SECITEM_Hash, SECITEM_HashCompare,
2211
0
                              PL_CompareValues, NULL, NULL);
2212
0
    oidmechhash = PL_NewHashTable(0, secoid_HashNumber, PL_CompareValues,
2213
0
                                  PL_CompareValues, NULL, NULL);
2214
2215
0
    if (!oidhash || !oidmechhash) {
2216
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2217
0
        PORT_Assert(0); /*This function should never fail. */
2218
0
        return (SECFailure);
2219
0
    }
2220
2221
0
    for (i = 0; i < SEC_OID_TOTAL; i++) {
2222
0
        oid = &oids[i];
2223
0
        PORT_Assert(oid->offset == i);
2224
0
        entry = PL_HashTableAdd(oidhash, &oid->oid, (void *)oid);
2225
2226
0
        if (entry == NULL) {
2227
0
            PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2228
0
            PORT_Assert(0); /*This function should never fail. */
2229
0
            return (SECFailure);
2230
0
        }
2231
2232
0
        if (oid->mechanism != CKM_INVALID_MECHANISM) {
2233
0
            entry = PL_HashTableAdd(oidmechhash,
2234
0
                                    (void *)(uintptr_t)oid->mechanism, (void *)oid);
2235
0
            if (entry == NULL) {
2236
0
                PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2237
0
                PORT_Assert(0); /* This function should never fail. */
2238
0
                return (SECFailure);
2239
0
            }
2240
0
        }
2241
0
    }
2242
2243
0
    PORT_Assert(i == SEC_OID_TOTAL);
2244
    /* finally, clear S/MIME from the policy oids. If no one turns on any
2245
     * S/MIME policies after this, then S/MIME will enable the traditional
2246
     * algs when it initializes */
2247
0
    (void)NSS_SetAlgorithmPolicyAll(0, NSS_USE_ALG_IN_SMIME);
2248
2249
0
    return (SECSuccess);
2250
0
}
2251
2252
SECOidData *
2253
SECOID_FindOIDByMechanism(unsigned long mechanism)
2254
0
{
2255
0
    SECOidData *ret;
2256
2257
0
    PR_ASSERT(oidmechhash != NULL);
2258
0
    if (oidmechhash == NULL && SECOID_Init() != SECSuccess) {
2259
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2260
0
        return NULL;
2261
0
    }
2262
2263
0
    ret = PL_HashTableLookupConst(oidmechhash, (void *)(uintptr_t)mechanism);
2264
0
    if (ret == NULL) {
2265
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2266
0
    }
2267
2268
0
    return (ret);
2269
0
}
2270
2271
SECOidData *
2272
SECOID_FindOID(const SECItem *oid)
2273
0
{
2274
0
    SECOidData *ret;
2275
2276
0
    PR_ASSERT(oidhash != NULL);
2277
0
    if (oidhash == NULL && SECOID_Init() != SECSuccess) {
2278
0
        PORT_SetError(SEC_ERROR_LIBRARY_FAILURE);
2279
0
        return NULL;
2280
0
    }
2281
2282
0
    if ((oid == NULL) || (oid->data == NULL)) {
2283
0
        PORT_SetError(SEC_ERROR_UNRECOGNIZED_OID);
2284
0
        return NULL;
2285
0
    }
2286
2287
0
    ret = PL_HashTableLookupConst(oidhash, oid);
2288
0
    if (ret == NULL) {
2289
0
        ret = secoid_FindDynamic(oid);
2290
0
        if (ret == NULL) {
2291
0
            PORT_SetError(SEC_ERROR_UNRECOGNIZED_OID);
2292
0
        }
2293
0
    }
2294
0
    return (ret);
2295
0
}
2296
2297
SECOidTag
2298
SECOID_FindOIDTag(const SECItem *oid)
2299
0
{
2300
0
    SECOidData *oiddata;
2301
2302
0
    oiddata = SECOID_FindOID(oid);
2303
0
    if (oiddata == NULL) {
2304
0
        return SEC_OID_UNKNOWN;
2305
0
    }
2306
2307
0
    return oiddata->offset;
2308
0
}
2309
2310
/* This really should return const. */
2311
SECOidData *
2312
SECOID_FindOIDByTag(SECOidTag tagnum)
2313
0
{
2314
0
    if (tagnum >= SEC_OID_TOTAL) {
2315
0
        return (SECOidData *)secoid_FindDynamicByTag(tagnum);
2316
0
    }
2317
2318
0
    PORT_Assert((unsigned int)tagnum < SEC_OID_TOTAL);
2319
0
    return (SECOidData *)(&oids[tagnum]);
2320
0
}
2321
2322
PRBool
2323
SECOID_KnownCertExtenOID(SECItem *extenOid)
2324
0
{
2325
0
    SECOidData *oidData;
2326
2327
0
    oidData = SECOID_FindOID(extenOid);
2328
0
    if (oidData == (SECOidData *)NULL)
2329
0
        return (PR_FALSE);
2330
0
    return ((oidData->supportedExtension == SUPPORTED_CERT_EXTENSION) ? PR_TRUE : PR_FALSE);
2331
0
}
2332
2333
const char *
2334
SECOID_FindOIDTagDescription(SECOidTag tagnum)
2335
0
{
2336
0
    const SECOidData *oidData = SECOID_FindOIDByTag(tagnum);
2337
0
    return oidData ? oidData->desc : 0;
2338
0
}
2339
2340
/* return the total tags, including dymamic tags. NOTE: there is
2341
 * a race between getting this value and adding new tags, but that
2342
 * race is only a race against seeing the newly added tags, total
2343
 * tags only ever grows, so it's safe to use the output of this in
2344
 * loops. */
2345
SECOidTag
2346
SECOID_GetTotalTags(void)
2347
0
{
2348
0
    SECOidTag total;
2349
2350
    /* get the lock to make sure we don't catch and inconsistant value
2351
     * for dynOidEntriesUsed. */
2352
0
    NSSRWLock_LockRead(dynOidLock);
2353
0
    total = SEC_OID_TOTAL + dynOidEntriesUsed;
2354
0
    NSSRWLock_UnlockRead(dynOidLock);
2355
0
    return total;
2356
0
}
2357
2358
/* --------- opaque extended OID table accessor functions ---------------*/
2359
/*
2360
 * Any of these functions may return SECSuccess or SECFailure with the error
2361
 * code set to SEC_ERROR_UNKNOWN_OBJECT_TYPE if the SECOidTag is out of range.
2362
 */
2363
2364
static privXOid *
2365
secoid_FindXOidByTag(SECOidTag tagnum)
2366
0
{
2367
0
    if (tagnum >= SEC_OID_TOTAL) {
2368
0
        dynXOid *dxo = secoid_FindDynamicByTag(tagnum);
2369
0
        return (dxo ? &dxo->priv : NULL);
2370
0
    }
2371
2372
0
    PORT_Assert((unsigned int)tagnum < SEC_OID_TOTAL);
2373
0
    return &xOids[tagnum];
2374
0
}
2375
2376
/* The Get function outputs the 32-bit value associated with the SECOidTag.
2377
 * Flags bits are the NSS_USE_ALG_ #defines in "secoidt.h".
2378
 * Default value for any algorithm is 0xffffffff (enabled for all purposes).
2379
 * No value is output if function returns SECFailure.
2380
 */
2381
SECStatus
2382
NSS_GetAlgorithmPolicy(SECOidTag tag, PRUint32 *pValue)
2383
0
{
2384
0
    privXOid *pxo = secoid_FindXOidByTag(tag);
2385
0
    if (!pxo)
2386
0
        return SECFailure;
2387
0
    if (!pValue) {
2388
0
        PORT_SetError(SEC_ERROR_INVALID_ARGS);
2389
0
        return SECFailure;
2390
0
    }
2391
0
    *pValue = ~(pxo->notPolicyFlags);
2392
0
    return SECSuccess;
2393
0
}
2394
2395
static PRBool nss_policy_locked = PR_FALSE;
2396
2397
/* The Set function modifies the stored value according to the following
2398
 * algorithm:
2399
 *   policy[tag] = (policy[tag] & ~clearBits) | setBits;
2400
 */
2401
SECStatus
2402
NSS_SetAlgorithmPolicy(SECOidTag tag, PRUint32 setBits, PRUint32 clearBits)
2403
0
{
2404
0
    privXOid *pxo = secoid_FindXOidByTag(tag);
2405
0
    PRUint32 policyFlags;
2406
0
    if (!pxo)
2407
0
        return SECFailure;
2408
2409
0
    if (nss_policy_locked) {
2410
0
        PORT_SetError(SEC_ERROR_POLICY_LOCKED);
2411
0
        return SECFailure;
2412
0
    }
2413
    /* The stored policy flags are the ones complement of the flags as
2414
     * seen by the user.  This is not atomic, but these changes should
2415
     * be done rarely, e.g. at initialization time.
2416
     */
2417
0
    policyFlags = ~(pxo->notPolicyFlags);
2418
0
    policyFlags = (policyFlags & ~clearBits) | setBits;
2419
0
    pxo->notPolicyFlags = ~policyFlags;
2420
0
    return SECSuccess;
2421
0
}
2422
2423
/* set or clear a particular policy algorithm for all oids */
2424
SECStatus
2425
NSS_SetAlgorithmPolicyAll(PRUint32 setBits, PRUint32 clearBits)
2426
0
{
2427
0
    SECOidTag tag;
2428
    /* call this once,not once per loop */
2429
0
    SECOidTag lastTag = SECOID_GetTotalTags();
2430
2431
0
    for (tag = SEC_OID_UNKNOWN; tag < lastTag; tag++) {
2432
0
        SECStatus rv = NSS_SetAlgorithmPolicy(tag, setBits, clearBits);
2433
        /* there are only 2 reasons SetAlgorithmPolicy can fail:
2434
         *  1) we passed an invalid tag, or 2) policy is locked.
2435
         *  The first case should not happen because we are only looping
2436
         *  through known good tags. In the second case, we will always fail,
2437
         *  so there is no point continuing our loop */
2438
0
        if (rv != SECSuccess) {
2439
0
            return rv;
2440
0
        }
2441
0
    }
2442
0
    return SECSuccess;
2443
0
}
2444
2445
/* return all the tags whose valueBits match the mask. */
2446
SECStatus
2447
NSS_GetAlgorithmPolicyAll(PRUint32 maskBits, PRUint32 valueBits,
2448
                          SECOidTag **outTags, int *outTagCount)
2449
0
{
2450
0
    SECOidTag *tags;
2451
0
    SECOidTag tag;
2452
    /* call this once,not once per loop */
2453
0
    SECOidTag lastTag = SECOID_GetTotalTags();
2454
0
    int tagCount, tableSize;
2455
2456
0
    tags = *outTags = NULL;
2457
0
    tableSize = tagCount = *outTagCount = 0;
2458
2459
0
    for (tag = SEC_OID_UNKNOWN; tag < lastTag; tag++) {
2460
0
        PRUint32 policy;
2461
0
        SECStatus rv = NSS_GetAlgorithmPolicy(tag, &policy);
2462
0
        if (rv != SECSuccess) {
2463
0
            goto loser;
2464
0
        }
2465
0
        if ((policy & maskBits) == valueBits) {
2466
            /* add found tag to the table, grow it if necessary */
2467
0
            if (tagCount >= tableSize) {
2468
0
                int newTableSize = tableSize + 16;
2469
0
                SECOidTag *newTags;
2470
0
                newTags = (SECOidTag *)PORT_Realloc(tags,
2471
0
                                                    newTableSize *
2472
0
                                                        sizeof(SECOidTag));
2473
0
                if (newTags == NULL) {
2474
0
                    goto loser;
2475
0
                }
2476
0
                tags = newTags;
2477
0
                tableSize = newTableSize;
2478
0
            }
2479
0
            tags[tagCount++] = tag;
2480
0
        }
2481
0
    }
2482
0
    *outTags = tags;
2483
0
    *outTagCount = tagCount;
2484
0
    return SECSuccess;
2485
0
loser:
2486
0
    if (tags) {
2487
0
        PORT_Free(tags);
2488
0
    }
2489
    /* failing function already called PORT_SetError() */
2490
0
    return SECFailure;
2491
0
}
2492
2493
/* Get the state of nss_policy_locked */
2494
PRBool
2495
NSS_IsPolicyLocked(void)
2496
0
{
2497
0
    return nss_policy_locked;
2498
0
}
2499
2500
/* Once the policy is locked, it can't be unlocked */
2501
void
2502
NSS_LockPolicy(void)
2503
0
{
2504
0
    nss_policy_locked = PR_TRUE;
2505
0
}
2506
2507
/* --------- END OF opaque extended OID table accessor functions ---------*/
2508
2509
/* for now, this is only used in a single place, so it can remain static */
2510
static PRBool parentForkedAfterC_Initialize;
2511
2512
#define SKIP_AFTER_FORK(x)              \
2513
0
    if (!parentForkedAfterC_Initialize) \
2514
0
    x
2515
2516
/*
2517
 * free up the oid tables.
2518
 */
2519
SECStatus
2520
SECOID_Shutdown(void)
2521
0
{
2522
0
    if (oidhash) {
2523
0
        PL_HashTableDestroy(oidhash);
2524
0
        oidhash = NULL;
2525
0
    }
2526
0
    if (oidmechhash) {
2527
0
        PL_HashTableDestroy(oidmechhash);
2528
0
        oidmechhash = NULL;
2529
0
    }
2530
    /* Have to handle the case where the lock was created, but
2531
    ** the pool wasn't.
2532
    ** I'm not going to attempt to create the lock, just to protect
2533
    ** the destruction of data that probably isn't initialized anyway.
2534
    */
2535
0
    if (dynOidLock) {
2536
0
        SKIP_AFTER_FORK(NSSRWLock_LockWrite(dynOidLock));
2537
0
        if (dynOidHash) {
2538
0
            PL_HashTableDestroy(dynOidHash);
2539
0
            dynOidHash = NULL;
2540
0
        }
2541
0
        if (dynOidPool) {
2542
0
            PORT_FreeArena(dynOidPool, PR_FALSE);
2543
0
            dynOidPool = NULL;
2544
0
        }
2545
0
        if (dynOidTable) {
2546
0
            PORT_Free(dynOidTable);
2547
0
            dynOidTable = NULL;
2548
0
        }
2549
0
        dynOidEntriesAllocated = 0;
2550
0
        dynOidEntriesUsed = 0;
2551
2552
0
        SKIP_AFTER_FORK(NSSRWLock_UnlockWrite(dynOidLock));
2553
0
        SKIP_AFTER_FORK(NSSRWLock_Destroy(dynOidLock));
2554
0
        dynOidLock = NULL;
2555
0
    } else {
2556
        /* Since dynOidLock doesn't exist, then all the data it protects
2557
        ** should be uninitialized.  We'll check that (in DEBUG builds),
2558
        ** and then make sure it is so, in case NSS is reinitialized.
2559
        */
2560
0
        PORT_Assert(!dynOidHash && !dynOidPool && !dynOidTable &&
2561
0
                    !dynOidEntriesAllocated && !dynOidEntriesUsed);
2562
0
        dynOidHash = NULL;
2563
0
        dynOidPool = NULL;
2564
0
        dynOidTable = NULL;
2565
0
        dynOidEntriesAllocated = 0;
2566
0
        dynOidEntriesUsed = 0;
2567
0
    }
2568
    /* we are trashing the old policy state now, also reenable changing
2569
     * the policy as well */
2570
0
    nss_policy_locked = PR_FALSE;
2571
0
    memset(xOids, 0, sizeof xOids);
2572
0
    return SECSuccess;
2573
0
}
2574
2575
void
2576
UTIL_SetForkState(PRBool forked)
2577
0
{
2578
0
    parentForkedAfterC_Initialize = forked;
2579
0
}
2580
2581
const char *
2582
NSSUTIL_GetVersion(void)
2583
0
{
2584
0
    return NSSUTIL_VERSION;
2585
0
}