/src/openssl30/crypto/asn1/asn1_gen.c
| Line | Count | Source (jump to first uncovered line) | 
| 1 |  | /* | 
| 2 |  |  * Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved. | 
| 3 |  |  * | 
| 4 |  |  * Licensed under the Apache License 2.0 (the "License").  You may not use | 
| 5 |  |  * this file except in compliance with the License.  You can obtain a copy | 
| 6 |  |  * in the file LICENSE in the source distribution or at | 
| 7 |  |  * https://www.openssl.org/source/license.html | 
| 8 |  |  */ | 
| 9 |  |  | 
| 10 |  | #include "internal/cryptlib.h" | 
| 11 |  | #include <openssl/asn1.h> | 
| 12 |  | #include <openssl/x509v3.h> | 
| 13 |  |  | 
| 14 | 0 | #define ASN1_GEN_FLAG           0x10000 | 
| 15 | 0 | #define ASN1_GEN_FLAG_IMP       (ASN1_GEN_FLAG|1) | 
| 16 | 0 | #define ASN1_GEN_FLAG_EXP       (ASN1_GEN_FLAG|2) | 
| 17 |  | #define ASN1_GEN_FLAG_TAG       (ASN1_GEN_FLAG|3) | 
| 18 | 0 | #define ASN1_GEN_FLAG_BITWRAP   (ASN1_GEN_FLAG|4) | 
| 19 | 0 | #define ASN1_GEN_FLAG_OCTWRAP   (ASN1_GEN_FLAG|5) | 
| 20 | 0 | #define ASN1_GEN_FLAG_SEQWRAP   (ASN1_GEN_FLAG|6) | 
| 21 | 0 | #define ASN1_GEN_FLAG_SETWRAP   (ASN1_GEN_FLAG|7) | 
| 22 | 0 | #define ASN1_GEN_FLAG_FORMAT    (ASN1_GEN_FLAG|8) | 
| 23 |  |  | 
| 24 | 0 | #define ASN1_GEN_STR(str,val)   {str, sizeof(str) - 1, val} | 
| 25 |  |  | 
| 26 | 0 | #define ASN1_FLAG_EXP_MAX       20 | 
| 27 |  | /* Maximum number of nested sequences */ | 
| 28 | 0 | #define ASN1_GEN_SEQ_MAX_DEPTH  50 | 
| 29 |  |  | 
| 30 |  | /* Input formats */ | 
| 31 |  |  | 
| 32 |  | /* ASCII: default */ | 
| 33 | 0 | #define ASN1_GEN_FORMAT_ASCII   1 | 
| 34 |  | /* UTF8 */ | 
| 35 | 0 | #define ASN1_GEN_FORMAT_UTF8    2 | 
| 36 |  | /* Hex */ | 
| 37 | 0 | #define ASN1_GEN_FORMAT_HEX     3 | 
| 38 |  | /* List of bits */ | 
| 39 | 0 | #define ASN1_GEN_FORMAT_BITLIST 4 | 
| 40 |  |  | 
| 41 |  | struct tag_name_st { | 
| 42 |  |     const char *strnam; | 
| 43 |  |     int len; | 
| 44 |  |     int tag; | 
| 45 |  | }; | 
| 46 |  |  | 
| 47 |  | typedef struct { | 
| 48 |  |     int exp_tag; | 
| 49 |  |     int exp_class; | 
| 50 |  |     int exp_constructed; | 
| 51 |  |     int exp_pad; | 
| 52 |  |     long exp_len; | 
| 53 |  | } tag_exp_type; | 
| 54 |  |  | 
| 55 |  | typedef struct { | 
| 56 |  |     int imp_tag; | 
| 57 |  |     int imp_class; | 
| 58 |  |     int utype; | 
| 59 |  |     int format; | 
| 60 |  |     const char *str; | 
| 61 |  |     tag_exp_type exp_list[ASN1_FLAG_EXP_MAX]; | 
| 62 |  |     int exp_count; | 
| 63 |  | } tag_exp_arg; | 
| 64 |  |  | 
| 65 |  | static ASN1_TYPE *generate_v3(const char *str, X509V3_CTX *cnf, int depth, | 
| 66 |  |                               int *perr); | 
| 67 |  | static int bitstr_cb(const char *elem, int len, void *bitstr); | 
| 68 |  | static int asn1_cb(const char *elem, int len, void *bitstr); | 
| 69 |  | static int append_exp(tag_exp_arg *arg, int exp_tag, int exp_class, | 
| 70 |  |                       int exp_constructed, int exp_pad, int imp_ok); | 
| 71 |  | static int parse_tagging(const char *vstart, int vlen, int *ptag, | 
| 72 |  |                          int *pclass); | 
| 73 |  | static ASN1_TYPE *asn1_multi(int utype, const char *section, X509V3_CTX *cnf, | 
| 74 |  |                              int depth, int *perr); | 
| 75 |  | static ASN1_TYPE *asn1_str2type(const char *str, int format, int utype); | 
| 76 |  | static int asn1_str2tag(const char *tagstr, int len); | 
| 77 |  |  | 
| 78 |  | ASN1_TYPE *ASN1_generate_nconf(const char *str, CONF *nconf) | 
| 79 | 0 | { | 
| 80 | 0 |     X509V3_CTX cnf; | 
| 81 |  | 
 | 
| 82 | 0 |     if (!nconf) | 
| 83 | 0 |         return ASN1_generate_v3(str, NULL); | 
| 84 |  |  | 
| 85 | 0 |     X509V3_set_nconf(&cnf, nconf); | 
| 86 | 0 |     return ASN1_generate_v3(str, &cnf); | 
| 87 | 0 | } | 
| 88 |  |  | 
| 89 |  | ASN1_TYPE *ASN1_generate_v3(const char *str, X509V3_CTX *cnf) | 
| 90 | 0 | { | 
| 91 | 0 |     int err = 0; | 
| 92 | 0 |     ASN1_TYPE *ret = generate_v3(str, cnf, 0, &err); | 
| 93 | 0 |     if (err) | 
| 94 | 0 |         ERR_raise(ERR_LIB_ASN1, err); | 
| 95 | 0 |     return ret; | 
| 96 | 0 | } | 
| 97 |  |  | 
| 98 |  | static ASN1_TYPE *generate_v3(const char *str, X509V3_CTX *cnf, int depth, | 
| 99 |  |                               int *perr) | 
| 100 | 0 | { | 
| 101 | 0 |     ASN1_TYPE *ret; | 
| 102 | 0 |     tag_exp_arg asn1_tags; | 
| 103 | 0 |     tag_exp_type *etmp; | 
| 104 |  | 
 | 
| 105 | 0 |     int i, len; | 
| 106 |  | 
 | 
| 107 | 0 |     unsigned char *orig_der = NULL, *new_der = NULL; | 
| 108 | 0 |     const unsigned char *cpy_start; | 
| 109 | 0 |     unsigned char *p; | 
| 110 | 0 |     const unsigned char *cp; | 
| 111 | 0 |     int cpy_len; | 
| 112 | 0 |     long hdr_len = 0; | 
| 113 | 0 |     int hdr_constructed = 0, hdr_tag, hdr_class; | 
| 114 | 0 |     int r; | 
| 115 |  | 
 | 
| 116 | 0 |     asn1_tags.imp_tag = -1; | 
| 117 | 0 |     asn1_tags.imp_class = -1; | 
| 118 | 0 |     asn1_tags.format = ASN1_GEN_FORMAT_ASCII; | 
| 119 | 0 |     asn1_tags.exp_count = 0; | 
| 120 | 0 |     if (CONF_parse_list(str, ',', 1, asn1_cb, &asn1_tags) != 0) { | 
| 121 | 0 |         *perr = ASN1_R_UNKNOWN_TAG; | 
| 122 | 0 |         return NULL; | 
| 123 | 0 |     } | 
| 124 |  |  | 
| 125 | 0 |     if ((asn1_tags.utype == V_ASN1_SEQUENCE) | 
| 126 | 0 |         || (asn1_tags.utype == V_ASN1_SET)) { | 
| 127 | 0 |         if (!cnf) { | 
| 128 | 0 |             *perr = ASN1_R_SEQUENCE_OR_SET_NEEDS_CONFIG; | 
| 129 | 0 |             return NULL; | 
| 130 | 0 |         } | 
| 131 | 0 |         if (depth >= ASN1_GEN_SEQ_MAX_DEPTH) { | 
| 132 | 0 |             *perr = ASN1_R_ILLEGAL_NESTED_TAGGING; | 
| 133 | 0 |             return NULL; | 
| 134 | 0 |         } | 
| 135 | 0 |         ret = asn1_multi(asn1_tags.utype, asn1_tags.str, cnf, depth, perr); | 
| 136 | 0 |     } else | 
| 137 | 0 |         ret = asn1_str2type(asn1_tags.str, asn1_tags.format, asn1_tags.utype); | 
| 138 |  |  | 
| 139 | 0 |     if (!ret) | 
| 140 | 0 |         return NULL; | 
| 141 |  |  | 
| 142 |  |     /* If no tagging return base type */ | 
| 143 | 0 |     if ((asn1_tags.imp_tag == -1) && (asn1_tags.exp_count == 0)) | 
| 144 | 0 |         return ret; | 
| 145 |  |  | 
| 146 |  |     /* Generate the encoding */ | 
| 147 | 0 |     cpy_len = i2d_ASN1_TYPE(ret, &orig_der); | 
| 148 | 0 |     ASN1_TYPE_free(ret); | 
| 149 | 0 |     ret = NULL; | 
| 150 |  |     /* Set point to start copying for modified encoding */ | 
| 151 | 0 |     cpy_start = orig_der; | 
| 152 |  |  | 
| 153 |  |     /* Do we need IMPLICIT tagging? */ | 
| 154 | 0 |     if (asn1_tags.imp_tag != -1) { | 
| 155 |  |         /* If IMPLICIT we will replace the underlying tag */ | 
| 156 |  |         /* Skip existing tag+len */ | 
| 157 | 0 |         r = ASN1_get_object(&cpy_start, &hdr_len, &hdr_tag, &hdr_class, | 
| 158 | 0 |                             cpy_len); | 
| 159 | 0 |         if (r & 0x80) | 
| 160 | 0 |             goto err; | 
| 161 |  |         /* Update copy length */ | 
| 162 | 0 |         cpy_len -= cpy_start - orig_der; | 
| 163 |  |         /* | 
| 164 |  |          * For IMPLICIT tagging the length should match the original length | 
| 165 |  |          * and constructed flag should be consistent. | 
| 166 |  |          */ | 
| 167 | 0 |         if (r & 0x1) { | 
| 168 |  |             /* Indefinite length constructed */ | 
| 169 | 0 |             hdr_constructed = 2; | 
| 170 | 0 |             hdr_len = 0; | 
| 171 | 0 |         } else | 
| 172 |  |             /* Just retain constructed flag */ | 
| 173 | 0 |             hdr_constructed = r & V_ASN1_CONSTRUCTED; | 
| 174 |  |         /* | 
| 175 |  |          * Work out new length with IMPLICIT tag: ignore constructed because | 
| 176 |  |          * it will mess up if indefinite length | 
| 177 |  |          */ | 
| 178 | 0 |         len = ASN1_object_size(0, hdr_len, asn1_tags.imp_tag); | 
| 179 | 0 |     } else | 
| 180 | 0 |         len = cpy_len; | 
| 181 |  |  | 
| 182 |  |     /* Work out length in any EXPLICIT, starting from end */ | 
| 183 |  |  | 
| 184 | 0 |     for (i = 0, etmp = asn1_tags.exp_list + asn1_tags.exp_count - 1; | 
| 185 | 0 |          i < asn1_tags.exp_count; i++, etmp--) { | 
| 186 |  |         /* Content length: number of content octets + any padding */ | 
| 187 | 0 |         len += etmp->exp_pad; | 
| 188 | 0 |         etmp->exp_len = len; | 
| 189 |  |         /* Total object length: length including new header */ | 
| 190 | 0 |         len = ASN1_object_size(0, len, etmp->exp_tag); | 
| 191 | 0 |     } | 
| 192 |  |  | 
| 193 |  |     /* Allocate buffer for new encoding */ | 
| 194 |  | 
 | 
| 195 | 0 |     new_der = OPENSSL_malloc(len); | 
| 196 | 0 |     if (new_der == NULL) | 
| 197 | 0 |         goto err; | 
| 198 |  |  | 
| 199 |  |     /* Generate tagged encoding */ | 
| 200 |  |  | 
| 201 | 0 |     p = new_der; | 
| 202 |  |  | 
| 203 |  |     /* Output explicit tags first */ | 
| 204 |  | 
 | 
| 205 | 0 |     for (i = 0, etmp = asn1_tags.exp_list; i < asn1_tags.exp_count; | 
| 206 | 0 |          i++, etmp++) { | 
| 207 | 0 |         ASN1_put_object(&p, etmp->exp_constructed, etmp->exp_len, | 
| 208 | 0 |                         etmp->exp_tag, etmp->exp_class); | 
| 209 | 0 |         if (etmp->exp_pad) | 
| 210 | 0 |             *p++ = 0; | 
| 211 | 0 |     } | 
| 212 |  |  | 
| 213 |  |     /* If IMPLICIT, output tag */ | 
| 214 |  | 
 | 
| 215 | 0 |     if (asn1_tags.imp_tag != -1) { | 
| 216 | 0 |         if (asn1_tags.imp_class == V_ASN1_UNIVERSAL | 
| 217 | 0 |             && (asn1_tags.imp_tag == V_ASN1_SEQUENCE | 
| 218 | 0 |                 || asn1_tags.imp_tag == V_ASN1_SET)) | 
| 219 | 0 |             hdr_constructed = V_ASN1_CONSTRUCTED; | 
| 220 | 0 |         ASN1_put_object(&p, hdr_constructed, hdr_len, | 
| 221 | 0 |                         asn1_tags.imp_tag, asn1_tags.imp_class); | 
| 222 | 0 |     } | 
| 223 |  |  | 
| 224 |  |     /* Copy across original encoding */ | 
| 225 | 0 |     memcpy(p, cpy_start, cpy_len); | 
| 226 |  | 
 | 
| 227 | 0 |     cp = new_der; | 
| 228 |  |  | 
| 229 |  |     /* Obtain new ASN1_TYPE structure */ | 
| 230 | 0 |     ret = d2i_ASN1_TYPE(NULL, &cp, len); | 
| 231 |  | 
 | 
| 232 | 0 |  err: | 
| 233 | 0 |     OPENSSL_free(orig_der); | 
| 234 | 0 |     OPENSSL_free(new_der); | 
| 235 |  | 
 | 
| 236 | 0 |     return ret; | 
| 237 |  | 
 | 
| 238 | 0 | } | 
| 239 |  |  | 
| 240 |  | static int asn1_cb(const char *elem, int len, void *bitstr) | 
| 241 | 0 | { | 
| 242 | 0 |     tag_exp_arg *arg = bitstr; | 
| 243 | 0 |     int i; | 
| 244 | 0 |     int utype; | 
| 245 | 0 |     int vlen = 0; | 
| 246 | 0 |     const char *p, *vstart = NULL; | 
| 247 |  | 
 | 
| 248 | 0 |     int tmp_tag, tmp_class; | 
| 249 |  | 
 | 
| 250 | 0 |     if (elem == NULL) | 
| 251 | 0 |         return -1; | 
| 252 |  |  | 
| 253 | 0 |     for (i = 0, p = elem; i < len; p++, i++) { | 
| 254 |  |         /* Look for the ':' in name value pairs */ | 
| 255 | 0 |         if (*p == ':') { | 
| 256 | 0 |             vstart = p + 1; | 
| 257 | 0 |             vlen = len - (vstart - elem); | 
| 258 | 0 |             len = p - elem; | 
| 259 | 0 |             break; | 
| 260 | 0 |         } | 
| 261 | 0 |     } | 
| 262 |  | 
 | 
| 263 | 0 |     utype = asn1_str2tag(elem, len); | 
| 264 |  | 
 | 
| 265 | 0 |     if (utype == -1) { | 
| 266 | 0 |         ERR_raise_data(ERR_LIB_ASN1, ASN1_R_UNKNOWN_TAG, "tag=%s", elem); | 
| 267 | 0 |         return -1; | 
| 268 | 0 |     } | 
| 269 |  |  | 
| 270 |  |     /* If this is not a modifier mark end of string and exit */ | 
| 271 | 0 |     if (!(utype & ASN1_GEN_FLAG)) { | 
| 272 | 0 |         arg->utype = utype; | 
| 273 | 0 |         arg->str = vstart; | 
| 274 |  |         /* If no value and not end of string, error */ | 
| 275 | 0 |         if (!vstart && elem[len]) { | 
| 276 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_MISSING_VALUE); | 
| 277 | 0 |             return -1; | 
| 278 | 0 |         } | 
| 279 | 0 |         return 0; | 
| 280 | 0 |     } | 
| 281 |  |  | 
| 282 | 0 |     switch (utype) { | 
| 283 |  |  | 
| 284 | 0 |     case ASN1_GEN_FLAG_IMP: | 
| 285 |  |         /* Check for illegal multiple IMPLICIT tagging */ | 
| 286 | 0 |         if (arg->imp_tag != -1) { | 
| 287 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_NESTED_TAGGING); | 
| 288 | 0 |             return -1; | 
| 289 | 0 |         } | 
| 290 | 0 |         if (!parse_tagging(vstart, vlen, &arg->imp_tag, &arg->imp_class)) | 
| 291 | 0 |             return -1; | 
| 292 | 0 |         break; | 
| 293 |  |  | 
| 294 | 0 |     case ASN1_GEN_FLAG_EXP: | 
| 295 |  | 
 | 
| 296 | 0 |         if (!parse_tagging(vstart, vlen, &tmp_tag, &tmp_class)) | 
| 297 | 0 |             return -1; | 
| 298 | 0 |         if (!append_exp(arg, tmp_tag, tmp_class, 1, 0, 0)) | 
| 299 | 0 |             return -1; | 
| 300 | 0 |         break; | 
| 301 |  |  | 
| 302 | 0 |     case ASN1_GEN_FLAG_SEQWRAP: | 
| 303 | 0 |         if (!append_exp(arg, V_ASN1_SEQUENCE, V_ASN1_UNIVERSAL, 1, 0, 1)) | 
| 304 | 0 |             return -1; | 
| 305 | 0 |         break; | 
| 306 |  |  | 
| 307 | 0 |     case ASN1_GEN_FLAG_SETWRAP: | 
| 308 | 0 |         if (!append_exp(arg, V_ASN1_SET, V_ASN1_UNIVERSAL, 1, 0, 1)) | 
| 309 | 0 |             return -1; | 
| 310 | 0 |         break; | 
| 311 |  |  | 
| 312 | 0 |     case ASN1_GEN_FLAG_BITWRAP: | 
| 313 | 0 |         if (!append_exp(arg, V_ASN1_BIT_STRING, V_ASN1_UNIVERSAL, 0, 1, 1)) | 
| 314 | 0 |             return -1; | 
| 315 | 0 |         break; | 
| 316 |  |  | 
| 317 | 0 |     case ASN1_GEN_FLAG_OCTWRAP: | 
| 318 | 0 |         if (!append_exp(arg, V_ASN1_OCTET_STRING, V_ASN1_UNIVERSAL, 0, 0, 1)) | 
| 319 | 0 |             return -1; | 
| 320 | 0 |         break; | 
| 321 |  |  | 
| 322 | 0 |     case ASN1_GEN_FLAG_FORMAT: | 
| 323 | 0 |         if (!vstart) { | 
| 324 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_UNKNOWN_FORMAT); | 
| 325 | 0 |             return -1; | 
| 326 | 0 |         } | 
| 327 | 0 |         if (strncmp(vstart, "ASCII", 5) == 0) | 
| 328 | 0 |             arg->format = ASN1_GEN_FORMAT_ASCII; | 
| 329 | 0 |         else if (strncmp(vstart, "UTF8", 4) == 0) | 
| 330 | 0 |             arg->format = ASN1_GEN_FORMAT_UTF8; | 
| 331 | 0 |         else if (strncmp(vstart, "HEX", 3) == 0) | 
| 332 | 0 |             arg->format = ASN1_GEN_FORMAT_HEX; | 
| 333 | 0 |         else if (strncmp(vstart, "BITLIST", 7) == 0) | 
| 334 | 0 |             arg->format = ASN1_GEN_FORMAT_BITLIST; | 
| 335 | 0 |         else { | 
| 336 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_UNKNOWN_FORMAT); | 
| 337 | 0 |             return -1; | 
| 338 | 0 |         } | 
| 339 | 0 |         break; | 
| 340 |  | 
 | 
| 341 | 0 |     } | 
| 342 |  |  | 
| 343 | 0 |     return 1; | 
| 344 |  | 
 | 
| 345 | 0 | } | 
| 346 |  |  | 
| 347 |  | static int parse_tagging(const char *vstart, int vlen, int *ptag, int *pclass) | 
| 348 | 0 | { | 
| 349 | 0 |     long tag_num; | 
| 350 | 0 |     char *eptr; | 
| 351 | 0 |     if (!vstart) | 
| 352 | 0 |         return 0; | 
| 353 | 0 |     tag_num = strtoul(vstart, &eptr, 10); | 
| 354 |  |     /* Check we haven't gone past max length: should be impossible */ | 
| 355 | 0 |     if (eptr && *eptr && (eptr > vstart + vlen)) | 
| 356 | 0 |         return 0; | 
| 357 | 0 |     if (tag_num < 0) { | 
| 358 | 0 |         ERR_raise(ERR_LIB_ASN1, ASN1_R_INVALID_NUMBER); | 
| 359 | 0 |         return 0; | 
| 360 | 0 |     } | 
| 361 | 0 |     *ptag = tag_num; | 
| 362 |  |     /* If we have non numeric characters, parse them */ | 
| 363 | 0 |     if (eptr) | 
| 364 | 0 |         vlen -= eptr - vstart; | 
| 365 | 0 |     else | 
| 366 | 0 |         vlen = 0; | 
| 367 | 0 |     if (vlen) { | 
| 368 | 0 |         switch (*eptr) { | 
| 369 |  |  | 
| 370 | 0 |         case 'U': | 
| 371 | 0 |             *pclass = V_ASN1_UNIVERSAL; | 
| 372 | 0 |             break; | 
| 373 |  |  | 
| 374 | 0 |         case 'A': | 
| 375 | 0 |             *pclass = V_ASN1_APPLICATION; | 
| 376 | 0 |             break; | 
| 377 |  |  | 
| 378 | 0 |         case 'P': | 
| 379 | 0 |             *pclass = V_ASN1_PRIVATE; | 
| 380 | 0 |             break; | 
| 381 |  |  | 
| 382 | 0 |         case 'C': | 
| 383 | 0 |             *pclass = V_ASN1_CONTEXT_SPECIFIC; | 
| 384 | 0 |             break; | 
| 385 |  |  | 
| 386 | 0 |         default: | 
| 387 | 0 |             ERR_raise_data(ERR_LIB_ASN1, ASN1_R_INVALID_MODIFIER, | 
| 388 | 0 |                            "Char=%c", *eptr); | 
| 389 | 0 |             return 0; | 
| 390 |  | 
 | 
| 391 | 0 |         } | 
| 392 | 0 |     } else | 
| 393 | 0 |         *pclass = V_ASN1_CONTEXT_SPECIFIC; | 
| 394 |  |  | 
| 395 | 0 |     return 1; | 
| 396 |  | 
 | 
| 397 | 0 | } | 
| 398 |  |  | 
| 399 |  | /* Handle multiple types: SET and SEQUENCE */ | 
| 400 |  |  | 
| 401 |  | static ASN1_TYPE *asn1_multi(int utype, const char *section, X509V3_CTX *cnf, | 
| 402 |  |                              int depth, int *perr) | 
| 403 | 0 | { | 
| 404 | 0 |     ASN1_TYPE *ret = NULL; | 
| 405 | 0 |     STACK_OF(ASN1_TYPE) *sk = NULL; | 
| 406 | 0 |     STACK_OF(CONF_VALUE) *sect = NULL; | 
| 407 | 0 |     unsigned char *der = NULL; | 
| 408 | 0 |     int derlen; | 
| 409 | 0 |     int i; | 
| 410 | 0 |     sk = sk_ASN1_TYPE_new_null(); | 
| 411 | 0 |     if (!sk) | 
| 412 | 0 |         goto bad; | 
| 413 | 0 |     if (section) { | 
| 414 | 0 |         if (!cnf) | 
| 415 | 0 |             goto bad; | 
| 416 | 0 |         sect = X509V3_get_section(cnf, (char *)section); | 
| 417 | 0 |         if (!sect) | 
| 418 | 0 |             goto bad; | 
| 419 | 0 |         for (i = 0; i < sk_CONF_VALUE_num(sect); i++) { | 
| 420 | 0 |             ASN1_TYPE *typ = | 
| 421 | 0 |                 generate_v3(sk_CONF_VALUE_value(sect, i)->value, cnf, | 
| 422 | 0 |                             depth + 1, perr); | 
| 423 | 0 |             if (!typ) | 
| 424 | 0 |                 goto bad; | 
| 425 | 0 |             if (!sk_ASN1_TYPE_push(sk, typ)) | 
| 426 | 0 |                 goto bad; | 
| 427 | 0 |         } | 
| 428 | 0 |     } | 
| 429 |  |  | 
| 430 |  |     /* | 
| 431 |  |      * Now we has a STACK of the components, convert to the correct form | 
| 432 |  |      */ | 
| 433 |  |  | 
| 434 | 0 |     if (utype == V_ASN1_SET) | 
| 435 | 0 |         derlen = i2d_ASN1_SET_ANY(sk, &der); | 
| 436 | 0 |     else | 
| 437 | 0 |         derlen = i2d_ASN1_SEQUENCE_ANY(sk, &der); | 
| 438 |  | 
 | 
| 439 | 0 |     if (derlen < 0) | 
| 440 | 0 |         goto bad; | 
| 441 | 0 |     if ((ret = ASN1_TYPE_new()) == NULL) | 
| 442 | 0 |         goto bad; | 
| 443 | 0 |     if ((ret->value.asn1_string = ASN1_STRING_type_new(utype)) == NULL) | 
| 444 | 0 |         goto bad; | 
| 445 |  |  | 
| 446 | 0 |     ret->type = utype; | 
| 447 | 0 |     ret->value.asn1_string->data = der; | 
| 448 | 0 |     ret->value.asn1_string->length = derlen; | 
| 449 |  | 
 | 
| 450 | 0 |     der = NULL; | 
| 451 |  | 
 | 
| 452 | 0 |  bad: | 
| 453 |  | 
 | 
| 454 | 0 |     OPENSSL_free(der); | 
| 455 |  | 
 | 
| 456 | 0 |     sk_ASN1_TYPE_pop_free(sk, ASN1_TYPE_free); | 
| 457 | 0 |     X509V3_section_free(cnf, sect); | 
| 458 |  | 
 | 
| 459 | 0 |     return ret; | 
| 460 | 0 | } | 
| 461 |  |  | 
| 462 |  | static int append_exp(tag_exp_arg *arg, int exp_tag, int exp_class, | 
| 463 |  |                       int exp_constructed, int exp_pad, int imp_ok) | 
| 464 | 0 | { | 
| 465 | 0 |     tag_exp_type *exp_tmp; | 
| 466 |  |     /* Can only have IMPLICIT if permitted */ | 
| 467 | 0 |     if ((arg->imp_tag != -1) && !imp_ok) { | 
| 468 | 0 |         ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_IMPLICIT_TAG); | 
| 469 | 0 |         return 0; | 
| 470 | 0 |     } | 
| 471 |  |  | 
| 472 | 0 |     if (arg->exp_count == ASN1_FLAG_EXP_MAX) { | 
| 473 | 0 |         ERR_raise(ERR_LIB_ASN1, ASN1_R_DEPTH_EXCEEDED); | 
| 474 | 0 |         return 0; | 
| 475 | 0 |     } | 
| 476 |  |  | 
| 477 | 0 |     exp_tmp = &arg->exp_list[arg->exp_count++]; | 
| 478 |  |  | 
| 479 |  |     /* | 
| 480 |  |      * If IMPLICIT set tag to implicit value then reset implicit tag since it | 
| 481 |  |      * has been used. | 
| 482 |  |      */ | 
| 483 | 0 |     if (arg->imp_tag != -1) { | 
| 484 | 0 |         exp_tmp->exp_tag = arg->imp_tag; | 
| 485 | 0 |         exp_tmp->exp_class = arg->imp_class; | 
| 486 | 0 |         arg->imp_tag = -1; | 
| 487 | 0 |         arg->imp_class = -1; | 
| 488 | 0 |     } else { | 
| 489 | 0 |         exp_tmp->exp_tag = exp_tag; | 
| 490 | 0 |         exp_tmp->exp_class = exp_class; | 
| 491 | 0 |     } | 
| 492 | 0 |     exp_tmp->exp_constructed = exp_constructed; | 
| 493 | 0 |     exp_tmp->exp_pad = exp_pad; | 
| 494 |  | 
 | 
| 495 | 0 |     return 1; | 
| 496 | 0 | } | 
| 497 |  |  | 
| 498 |  | static int asn1_str2tag(const char *tagstr, int len) | 
| 499 | 0 | { | 
| 500 | 0 |     unsigned int i; | 
| 501 | 0 |     static const struct tag_name_st *tntmp, tnst[] = { | 
| 502 | 0 |         ASN1_GEN_STR("BOOL", V_ASN1_BOOLEAN), | 
| 503 | 0 |         ASN1_GEN_STR("BOOLEAN", V_ASN1_BOOLEAN), | 
| 504 | 0 |         ASN1_GEN_STR("NULL", V_ASN1_NULL), | 
| 505 | 0 |         ASN1_GEN_STR("INT", V_ASN1_INTEGER), | 
| 506 | 0 |         ASN1_GEN_STR("INTEGER", V_ASN1_INTEGER), | 
| 507 | 0 |         ASN1_GEN_STR("ENUM", V_ASN1_ENUMERATED), | 
| 508 | 0 |         ASN1_GEN_STR("ENUMERATED", V_ASN1_ENUMERATED), | 
| 509 | 0 |         ASN1_GEN_STR("OID", V_ASN1_OBJECT), | 
| 510 | 0 |         ASN1_GEN_STR("OBJECT", V_ASN1_OBJECT), | 
| 511 | 0 |         ASN1_GEN_STR("UTCTIME", V_ASN1_UTCTIME), | 
| 512 | 0 |         ASN1_GEN_STR("UTC", V_ASN1_UTCTIME), | 
| 513 | 0 |         ASN1_GEN_STR("GENERALIZEDTIME", V_ASN1_GENERALIZEDTIME), | 
| 514 | 0 |         ASN1_GEN_STR("GENTIME", V_ASN1_GENERALIZEDTIME), | 
| 515 | 0 |         ASN1_GEN_STR("OCT", V_ASN1_OCTET_STRING), | 
| 516 | 0 |         ASN1_GEN_STR("OCTETSTRING", V_ASN1_OCTET_STRING), | 
| 517 | 0 |         ASN1_GEN_STR("BITSTR", V_ASN1_BIT_STRING), | 
| 518 | 0 |         ASN1_GEN_STR("BITSTRING", V_ASN1_BIT_STRING), | 
| 519 | 0 |         ASN1_GEN_STR("UNIVERSALSTRING", V_ASN1_UNIVERSALSTRING), | 
| 520 | 0 |         ASN1_GEN_STR("UNIV", V_ASN1_UNIVERSALSTRING), | 
| 521 | 0 |         ASN1_GEN_STR("IA5", V_ASN1_IA5STRING), | 
| 522 | 0 |         ASN1_GEN_STR("IA5STRING", V_ASN1_IA5STRING), | 
| 523 | 0 |         ASN1_GEN_STR("UTF8", V_ASN1_UTF8STRING), | 
| 524 | 0 |         ASN1_GEN_STR("UTF8String", V_ASN1_UTF8STRING), | 
| 525 | 0 |         ASN1_GEN_STR("BMP", V_ASN1_BMPSTRING), | 
| 526 | 0 |         ASN1_GEN_STR("BMPSTRING", V_ASN1_BMPSTRING), | 
| 527 | 0 |         ASN1_GEN_STR("VISIBLESTRING", V_ASN1_VISIBLESTRING), | 
| 528 | 0 |         ASN1_GEN_STR("VISIBLE", V_ASN1_VISIBLESTRING), | 
| 529 | 0 |         ASN1_GEN_STR("PRINTABLESTRING", V_ASN1_PRINTABLESTRING), | 
| 530 | 0 |         ASN1_GEN_STR("PRINTABLE", V_ASN1_PRINTABLESTRING), | 
| 531 | 0 |         ASN1_GEN_STR("T61", V_ASN1_T61STRING), | 
| 532 | 0 |         ASN1_GEN_STR("T61STRING", V_ASN1_T61STRING), | 
| 533 | 0 |         ASN1_GEN_STR("TELETEXSTRING", V_ASN1_T61STRING), | 
| 534 | 0 |         ASN1_GEN_STR("GeneralString", V_ASN1_GENERALSTRING), | 
| 535 | 0 |         ASN1_GEN_STR("GENSTR", V_ASN1_GENERALSTRING), | 
| 536 | 0 |         ASN1_GEN_STR("NUMERIC", V_ASN1_NUMERICSTRING), | 
| 537 | 0 |         ASN1_GEN_STR("NUMERICSTRING", V_ASN1_NUMERICSTRING), | 
| 538 |  |  | 
| 539 |  |         /* Special cases */ | 
| 540 | 0 |         ASN1_GEN_STR("SEQUENCE", V_ASN1_SEQUENCE), | 
| 541 | 0 |         ASN1_GEN_STR("SEQ", V_ASN1_SEQUENCE), | 
| 542 | 0 |         ASN1_GEN_STR("SET", V_ASN1_SET), | 
| 543 |  |         /* type modifiers */ | 
| 544 |  |         /* Explicit tag */ | 
| 545 | 0 |         ASN1_GEN_STR("EXP", ASN1_GEN_FLAG_EXP), | 
| 546 | 0 |         ASN1_GEN_STR("EXPLICIT", ASN1_GEN_FLAG_EXP), | 
| 547 |  |         /* Implicit tag */ | 
| 548 | 0 |         ASN1_GEN_STR("IMP", ASN1_GEN_FLAG_IMP), | 
| 549 | 0 |         ASN1_GEN_STR("IMPLICIT", ASN1_GEN_FLAG_IMP), | 
| 550 |  |         /* OCTET STRING wrapper */ | 
| 551 | 0 |         ASN1_GEN_STR("OCTWRAP", ASN1_GEN_FLAG_OCTWRAP), | 
| 552 |  |         /* SEQUENCE wrapper */ | 
| 553 | 0 |         ASN1_GEN_STR("SEQWRAP", ASN1_GEN_FLAG_SEQWRAP), | 
| 554 |  |         /* SET wrapper */ | 
| 555 | 0 |         ASN1_GEN_STR("SETWRAP", ASN1_GEN_FLAG_SETWRAP), | 
| 556 |  |         /* BIT STRING wrapper */ | 
| 557 | 0 |         ASN1_GEN_STR("BITWRAP", ASN1_GEN_FLAG_BITWRAP), | 
| 558 | 0 |         ASN1_GEN_STR("FORM", ASN1_GEN_FLAG_FORMAT), | 
| 559 | 0 |         ASN1_GEN_STR("FORMAT", ASN1_GEN_FLAG_FORMAT), | 
| 560 | 0 |     }; | 
| 561 |  | 
 | 
| 562 | 0 |     if (len == -1) | 
| 563 | 0 |         len = strlen(tagstr); | 
| 564 |  | 
 | 
| 565 | 0 |     tntmp = tnst; | 
| 566 | 0 |     for (i = 0; i < OSSL_NELEM(tnst); i++, tntmp++) { | 
| 567 | 0 |         if ((len == tntmp->len) | 
| 568 | 0 |             && (OPENSSL_strncasecmp(tntmp->strnam, tagstr, len) == 0)) | 
| 569 | 0 |             return tntmp->tag; | 
| 570 | 0 |     } | 
| 571 |  |  | 
| 572 | 0 |     return -1; | 
| 573 | 0 | } | 
| 574 |  |  | 
| 575 |  | static ASN1_TYPE *asn1_str2type(const char *str, int format, int utype) | 
| 576 | 0 | { | 
| 577 | 0 |     ASN1_TYPE *atmp = NULL; | 
| 578 | 0 |     CONF_VALUE vtmp; | 
| 579 | 0 |     unsigned char *rdata; | 
| 580 | 0 |     long rdlen; | 
| 581 | 0 |     int no_unused = 1; | 
| 582 |  | 
 | 
| 583 | 0 |     if ((atmp = ASN1_TYPE_new()) == NULL) { | 
| 584 | 0 |         ERR_raise(ERR_LIB_ASN1, ERR_R_MALLOC_FAILURE); | 
| 585 | 0 |         return NULL; | 
| 586 | 0 |     } | 
| 587 |  |  | 
| 588 | 0 |     if (!str) | 
| 589 | 0 |         str = ""; | 
| 590 |  | 
 | 
| 591 | 0 |     switch (utype) { | 
| 592 |  |  | 
| 593 | 0 |     case V_ASN1_NULL: | 
| 594 | 0 |         if (str && *str) { | 
| 595 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_NULL_VALUE); | 
| 596 | 0 |             goto bad_form; | 
| 597 | 0 |         } | 
| 598 | 0 |         break; | 
| 599 |  |  | 
| 600 | 0 |     case V_ASN1_BOOLEAN: | 
| 601 | 0 |         if (format != ASN1_GEN_FORMAT_ASCII) { | 
| 602 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_NOT_ASCII_FORMAT); | 
| 603 | 0 |             goto bad_form; | 
| 604 | 0 |         } | 
| 605 | 0 |         vtmp.name = NULL; | 
| 606 | 0 |         vtmp.section = NULL; | 
| 607 | 0 |         vtmp.value = (char *)str; | 
| 608 | 0 |         if (!X509V3_get_value_bool(&vtmp, &atmp->value.boolean)) { | 
| 609 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_BOOLEAN); | 
| 610 | 0 |             goto bad_str; | 
| 611 | 0 |         } | 
| 612 | 0 |         break; | 
| 613 |  |  | 
| 614 | 0 |     case V_ASN1_INTEGER: | 
| 615 | 0 |     case V_ASN1_ENUMERATED: | 
| 616 | 0 |         if (format != ASN1_GEN_FORMAT_ASCII) { | 
| 617 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_INTEGER_NOT_ASCII_FORMAT); | 
| 618 | 0 |             goto bad_form; | 
| 619 | 0 |         } | 
| 620 | 0 |         if ((atmp->value.integer | 
| 621 | 0 |                     = s2i_ASN1_INTEGER(NULL, str)) == NULL) { | 
| 622 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_INTEGER); | 
| 623 | 0 |             goto bad_str; | 
| 624 | 0 |         } | 
| 625 | 0 |         break; | 
| 626 |  |  | 
| 627 | 0 |     case V_ASN1_OBJECT: | 
| 628 | 0 |         if (format != ASN1_GEN_FORMAT_ASCII) { | 
| 629 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_OBJECT_NOT_ASCII_FORMAT); | 
| 630 | 0 |             goto bad_form; | 
| 631 | 0 |         } | 
| 632 | 0 |         if ((atmp->value.object = OBJ_txt2obj(str, 0)) == NULL) { | 
| 633 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_OBJECT); | 
| 634 | 0 |             goto bad_str; | 
| 635 | 0 |         } | 
| 636 | 0 |         break; | 
| 637 |  |  | 
| 638 | 0 |     case V_ASN1_UTCTIME: | 
| 639 | 0 |     case V_ASN1_GENERALIZEDTIME: | 
| 640 | 0 |         if (format != ASN1_GEN_FORMAT_ASCII) { | 
| 641 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_TIME_NOT_ASCII_FORMAT); | 
| 642 | 0 |             goto bad_form; | 
| 643 | 0 |         } | 
| 644 | 0 |         if ((atmp->value.asn1_string = ASN1_STRING_new()) == NULL) { | 
| 645 | 0 |             ERR_raise(ERR_LIB_ASN1, ERR_R_MALLOC_FAILURE); | 
| 646 | 0 |             goto bad_str; | 
| 647 | 0 |         } | 
| 648 | 0 |         if (!ASN1_STRING_set(atmp->value.asn1_string, str, -1)) { | 
| 649 | 0 |             ERR_raise(ERR_LIB_ASN1, ERR_R_MALLOC_FAILURE); | 
| 650 | 0 |             goto bad_str; | 
| 651 | 0 |         } | 
| 652 | 0 |         atmp->value.asn1_string->type = utype; | 
| 653 | 0 |         if (!ASN1_TIME_check(atmp->value.asn1_string)) { | 
| 654 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_TIME_VALUE); | 
| 655 | 0 |             goto bad_str; | 
| 656 | 0 |         } | 
| 657 |  |  | 
| 658 | 0 |         break; | 
| 659 |  |  | 
| 660 | 0 |     case V_ASN1_BMPSTRING: | 
| 661 | 0 |     case V_ASN1_PRINTABLESTRING: | 
| 662 | 0 |     case V_ASN1_IA5STRING: | 
| 663 | 0 |     case V_ASN1_T61STRING: | 
| 664 | 0 |     case V_ASN1_UTF8STRING: | 
| 665 | 0 |     case V_ASN1_VISIBLESTRING: | 
| 666 | 0 |     case V_ASN1_UNIVERSALSTRING: | 
| 667 | 0 |     case V_ASN1_GENERALSTRING: | 
| 668 | 0 |     case V_ASN1_NUMERICSTRING: | 
| 669 | 0 |         if (format == ASN1_GEN_FORMAT_ASCII) | 
| 670 | 0 |             format = MBSTRING_ASC; | 
| 671 | 0 |         else if (format == ASN1_GEN_FORMAT_UTF8) | 
| 672 | 0 |             format = MBSTRING_UTF8; | 
| 673 | 0 |         else { | 
| 674 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_FORMAT); | 
| 675 | 0 |             goto bad_form; | 
| 676 | 0 |         } | 
| 677 |  |  | 
| 678 | 0 |         if (ASN1_mbstring_copy(&atmp->value.asn1_string, (unsigned char *)str, | 
| 679 | 0 |                                -1, format, ASN1_tag2bit(utype)) <= 0) { | 
| 680 | 0 |             ERR_raise(ERR_LIB_ASN1, ERR_R_MALLOC_FAILURE); | 
| 681 | 0 |             goto bad_str; | 
| 682 | 0 |         } | 
| 683 |  |  | 
| 684 | 0 |         break; | 
| 685 |  |  | 
| 686 | 0 |     case V_ASN1_BIT_STRING: | 
| 687 | 0 |     case V_ASN1_OCTET_STRING: | 
| 688 | 0 |         if ((atmp->value.asn1_string = ASN1_STRING_new()) == NULL) { | 
| 689 | 0 |             ERR_raise(ERR_LIB_ASN1, ERR_R_MALLOC_FAILURE); | 
| 690 | 0 |             goto bad_form; | 
| 691 | 0 |         } | 
| 692 |  |  | 
| 693 | 0 |         if (format == ASN1_GEN_FORMAT_HEX) { | 
| 694 | 0 |             if ((rdata = OPENSSL_hexstr2buf(str, &rdlen)) == NULL) { | 
| 695 | 0 |                 ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_HEX); | 
| 696 | 0 |                 goto bad_str; | 
| 697 | 0 |             } | 
| 698 | 0 |             atmp->value.asn1_string->data = rdata; | 
| 699 | 0 |             atmp->value.asn1_string->length = rdlen; | 
| 700 | 0 |             atmp->value.asn1_string->type = utype; | 
| 701 | 0 |         } else if (format == ASN1_GEN_FORMAT_ASCII) { | 
| 702 | 0 |             if (!ASN1_STRING_set(atmp->value.asn1_string, str, -1)) { | 
| 703 | 0 |                 ERR_raise(ERR_LIB_ASN1, ERR_R_MALLOC_FAILURE); | 
| 704 | 0 |                 goto bad_str; | 
| 705 | 0 |             } | 
| 706 | 0 |         } else if ((format == ASN1_GEN_FORMAT_BITLIST) | 
| 707 | 0 |                  && (utype == V_ASN1_BIT_STRING)) { | 
| 708 | 0 |             if (!CONF_parse_list | 
| 709 | 0 |                 (str, ',', 1, bitstr_cb, atmp->value.bit_string)) { | 
| 710 | 0 |                 ERR_raise(ERR_LIB_ASN1, ASN1_R_LIST_ERROR); | 
| 711 | 0 |                 goto bad_str; | 
| 712 | 0 |             } | 
| 713 | 0 |             no_unused = 0; | 
| 714 |  | 
 | 
| 715 | 0 |         } else { | 
| 716 | 0 |             ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_BITSTRING_FORMAT); | 
| 717 | 0 |             goto bad_form; | 
| 718 | 0 |         } | 
| 719 |  |  | 
| 720 | 0 |         if ((utype == V_ASN1_BIT_STRING) && no_unused) { | 
| 721 | 0 |             atmp->value.asn1_string->flags | 
| 722 | 0 |                 &= ~(ASN1_STRING_FLAG_BITS_LEFT | 0x07); | 
| 723 | 0 |             atmp->value.asn1_string->flags |= ASN1_STRING_FLAG_BITS_LEFT; | 
| 724 | 0 |         } | 
| 725 |  | 
 | 
| 726 | 0 |         break; | 
| 727 |  |  | 
| 728 | 0 |     default: | 
| 729 | 0 |         ERR_raise(ERR_LIB_ASN1, ASN1_R_UNSUPPORTED_TYPE); | 
| 730 | 0 |         goto bad_str; | 
| 731 | 0 |     } | 
| 732 |  |  | 
| 733 | 0 |     atmp->type = utype; | 
| 734 | 0 |     return atmp; | 
| 735 |  |  | 
| 736 | 0 |  bad_str: | 
| 737 | 0 |     ERR_add_error_data(2, "string=", str); | 
| 738 | 0 |  bad_form: | 
| 739 |  | 
 | 
| 740 | 0 |     ASN1_TYPE_free(atmp); | 
| 741 | 0 |     return NULL; | 
| 742 |  | 
 | 
| 743 | 0 | } | 
| 744 |  |  | 
| 745 |  | static int bitstr_cb(const char *elem, int len, void *bitstr) | 
| 746 | 0 | { | 
| 747 | 0 |     long bitnum; | 
| 748 | 0 |     char *eptr; | 
| 749 | 0 |     if (!elem) | 
| 750 | 0 |         return 0; | 
| 751 | 0 |     bitnum = strtoul(elem, &eptr, 10); | 
| 752 | 0 |     if (eptr && *eptr && (eptr != elem + len)) | 
| 753 | 0 |         return 0; | 
| 754 | 0 |     if (bitnum < 0) { | 
| 755 | 0 |         ERR_raise(ERR_LIB_ASN1, ASN1_R_INVALID_NUMBER); | 
| 756 | 0 |         return 0; | 
| 757 | 0 |     } | 
| 758 | 0 |     if (!ASN1_BIT_STRING_set_bit(bitstr, bitnum, 1)) { | 
| 759 | 0 |         ERR_raise(ERR_LIB_ASN1, ERR_R_MALLOC_FAILURE); | 
| 760 | 0 |         return 0; | 
| 761 | 0 |     } | 
| 762 | 0 |     return 1; | 
| 763 | 0 | } | 
| 764 |  |  | 
| 765 |  | static int mask_cb(const char *elem, int len, void *arg) | 
| 766 | 0 | { | 
| 767 | 0 |     unsigned long *pmask = arg, tmpmask; | 
| 768 | 0 |     int tag; | 
| 769 | 0 |     if (elem == NULL) | 
| 770 | 0 |         return 0; | 
| 771 | 0 |     if ((len == 3) && (strncmp(elem, "DIR", 3) == 0)) { | 
| 772 | 0 |         *pmask |= B_ASN1_DIRECTORYSTRING; | 
| 773 | 0 |         return 1; | 
| 774 | 0 |     } | 
| 775 | 0 |     tag = asn1_str2tag(elem, len); | 
| 776 | 0 |     if (!tag || (tag & ASN1_GEN_FLAG)) | 
| 777 | 0 |         return 0; | 
| 778 | 0 |     tmpmask = ASN1_tag2bit(tag); | 
| 779 | 0 |     if (!tmpmask) | 
| 780 | 0 |         return 0; | 
| 781 | 0 |     *pmask |= tmpmask; | 
| 782 | 0 |     return 1; | 
| 783 | 0 | } | 
| 784 |  |  | 
| 785 |  | int ASN1_str2mask(const char *str, unsigned long *pmask) | 
| 786 | 0 | { | 
| 787 | 0 |     *pmask = 0; | 
| 788 | 0 |     return CONF_parse_list(str, '|', 1, mask_cb, pmask); | 
| 789 | 0 | } |