Coverage Report

Created: 2026-08-14 06:45

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
/src/wireshark/epan/dissectors/packet-x509af.c
Line
Count
Source
1
/* Do not modify this file. Changes will be overwritten.                      */
2
/* Generated automatically by the ASN.1 to Wireshark dissector compiler       */
3
/* packet-x509af.c                                                            */
4
/* asn2wrs.py -b -q -L -p x509af -c ./x509af.cnf -s ./packet-x509af-template -D . -O ../.. AuthenticationFramework.asn */
5
6
/* packet-x509af.c
7
 * Routines for X.509 Authentication Framework packet dissection
8
 *  Ronnie Sahlberg 2004
9
 *
10
 * Wireshark - Network traffic analyzer
11
 * By Gerald Combs <gerald@wireshark.org>
12
 * Copyright 1998 Gerald Combs
13
 *
14
 * SPDX-License-Identifier: GPL-2.0-or-later
15
 */
16
17
#include "config.h"
18
19
#include <epan/packet.h>
20
#include <epan/oids.h>
21
#include <epan/asn1.h>
22
#include <epan/expert.h>
23
#include <epan/strutil.h>
24
#include <epan/export_object.h>
25
#include <epan/proto_data.h>
26
#include <wsutil/array.h>
27
#include <wsutil/wsgcrypt.h>
28
29
#include "packet-ber.h"
30
#include "packet-x509af.h"
31
#include "packet-x509ce.h"
32
#include "packet-x509if.h"
33
#include "packet-x509sat.h"
34
#include "packet-ldap.h"
35
#include "packet-pkixalgs.h"
36
#if defined(HAVE_LIBGNUTLS)
37
#include <gnutls/gnutls.h>
38
#endif
39
40
void proto_register_x509af(void);
41
void proto_reg_handoff_x509af(void);
42
43
static dissector_handle_t pkix_crl_handle;
44
45
static int x509af_eo_tap;
46
47
/* Initialize the protocol and registered fields */
48
static int proto_x509af;
49
static int hf_x509af_algorithm_id;
50
static int hf_x509af_extension_id;
51
static int hf_x509af_subjectPublicKey_dh;
52
static int hf_x509af_subjectPublicKey_dsa;
53
static int hf_x509af_subjectPublicKey_rsa;
54
static int hf_x509af_x509af_Certificate_PDU;      /* Certificate */
55
static int hf_x509af_SubjectPublicKeyInfo_PDU;    /* SubjectPublicKeyInfo */
56
static int hf_x509af_CertificatePair_PDU;         /* CertificatePair */
57
static int hf_x509af_CertificateList_PDU;         /* CertificateList */
58
static int hf_x509af_AttributeCertificate_PDU;    /* AttributeCertificate */
59
static int hf_x509af_DSS_Params_PDU;              /* DSS_Params */
60
static int hf_x509af_Userid_PDU;                  /* Userid */
61
static int hf_x509af_signedCertificate;           /* T_signedCertificate */
62
static int hf_x509af_version;                     /* Version */
63
static int hf_x509af_serialNumber;                /* CertificateSerialNumber */
64
static int hf_x509af_signature;                   /* AlgorithmIdentifier */
65
static int hf_x509af_issuer;                      /* Name */
66
static int hf_x509af_validity;                    /* Validity */
67
static int hf_x509af_subject;                     /* SubjectName */
68
static int hf_x509af_subjectPublicKeyInfo;        /* SubjectPublicKeyInfo */
69
static int hf_x509af_issuerUniqueIdentifier;      /* UniqueIdentifier */
70
static int hf_x509af_subjectUniqueIdentifier;     /* UniqueIdentifier */
71
static int hf_x509af_extensions;                  /* Extensions */
72
static int hf_x509af_algorithmIdentifier;         /* AlgorithmIdentifier */
73
static int hf_x509af_encrypted;                   /* BIT_STRING */
74
static int hf_x509af_rdnSequence;                 /* RDNSequence */
75
static int hf_x509af_algorithmId;                 /* T_algorithmId */
76
static int hf_x509af_parameters;                  /* T_parameters */
77
static int hf_x509af_notBefore;                   /* T_notBefore */
78
static int hf_x509af_notAfter;                    /* T_notAfter */
79
static int hf_x509af_algorithm;                   /* AlgorithmIdentifier */
80
static int hf_x509af_subjectPublicKey;            /* T_subjectPublicKey */
81
static int hf_x509af_utcTime;                     /* T_utcTime */
82
static int hf_x509af_generalizedTime;             /* GeneralizedTime */
83
static int hf_x509af_Extensions_item;             /* Extension */
84
static int hf_x509af_extnId;                      /* T_extnId */
85
static int hf_x509af_critical;                    /* BOOLEAN */
86
static int hf_x509af_extnValue;                   /* T_extnValue */
87
static int hf_x509af_userCertificate;             /* Certificate */
88
static int hf_x509af_certificationPath;           /* ForwardCertificationPath */
89
static int hf_x509af_ForwardCertificationPath_item;  /* CrossCertificates */
90
static int hf_x509af_CrossCertificates_item;      /* Certificate */
91
static int hf_x509af_theCACertificates;           /* SEQUENCE_OF_CertificatePair */
92
static int hf_x509af_theCACertificates_item;      /* CertificatePair */
93
static int hf_x509af_issuedByThisCA;              /* Certificate */
94
static int hf_x509af_issuedToThisCA;              /* Certificate */
95
static int hf_x509af_signedCertificateList;       /* T_signedCertificateList */
96
static int hf_x509af_thisUpdate;                  /* Time */
97
static int hf_x509af_nextUpdate;                  /* Time */
98
static int hf_x509af_revokedCertificates;         /* T_revokedCertificates */
99
static int hf_x509af_revokedCertificates_item;    /* T_revokedCertificates_item */
100
static int hf_x509af_revokedUserCertificate;      /* CertificateSerialNumber */
101
static int hf_x509af_revocationDate;              /* Time */
102
static int hf_x509af_crlEntryExtensions;          /* Extensions */
103
static int hf_x509af_crlExtensions;               /* Extensions */
104
static int hf_x509af_attributeCertificate;        /* AttributeCertificate */
105
static int hf_x509af_acPath;                      /* SEQUENCE_OF_ACPathData */
106
static int hf_x509af_acPath_item;                 /* ACPathData */
107
static int hf_x509af_certificate;                 /* Certificate */
108
static int hf_x509af_signedAttributeCertificateInfo;  /* AttributeCertificateInfo */
109
static int hf_x509af_info_subject;                /* InfoSubject */
110
static int hf_x509af_baseCertificateID;           /* IssuerSerial */
111
static int hf_x509af_infoSubjectName;             /* GeneralNames */
112
static int hf_x509af_issuerName;                  /* GeneralNames */
113
static int hf_x509af_attCertValidityPeriod;       /* AttCertValidityPeriod */
114
static int hf_x509af_attributes;                  /* SEQUENCE_OF_Attribute */
115
static int hf_x509af_attributes_item;             /* Attribute */
116
static int hf_x509af_issuerUniqueID;              /* UniqueIdentifier */
117
static int hf_x509af_serial;                      /* CertificateSerialNumber */
118
static int hf_x509af_issuerUID;                   /* UniqueIdentifier */
119
static int hf_x509af_notBeforeTime;               /* GeneralizedTime */
120
static int hf_x509af_notAfterTime;                /* GeneralizedTime */
121
static int hf_x509af_assertion_subject;           /* AssertionSubject */
122
static int hf_x509af_assertionSubjectName;        /* SubjectName */
123
static int hf_x509af_assertionIssuer;             /* Name */
124
static int hf_x509af_attCertValidity;             /* GeneralizedTime */
125
static int hf_x509af_attType;                     /* SET_OF_AttributeType */
126
static int hf_x509af_attType_item;                /* AttributeType */
127
static int hf_x509af_p;                           /* INTEGER */
128
static int hf_x509af_q;                           /* INTEGER */
129
static int hf_x509af_g;                           /* INTEGER */
130
131
/* Initialize the subtree pointers */
132
static int ett_pkix_crl;
133
static int ett_x509af_SubjectPublicKey;
134
static int ett_x509af_Certificate;
135
static int ett_x509af_T_signedCertificate;
136
static int ett_x509af_SubjectName;
137
static int ett_x509af_AlgorithmIdentifier;
138
static int ett_x509af_Validity;
139
static int ett_x509af_SubjectPublicKeyInfo;
140
static int ett_x509af_Time;
141
static int ett_x509af_Extensions;
142
static int ett_x509af_Extension;
143
static int ett_x509af_Certificates;
144
static int ett_x509af_ForwardCertificationPath;
145
static int ett_x509af_CrossCertificates;
146
static int ett_x509af_CertificationPath;
147
static int ett_x509af_SEQUENCE_OF_CertificatePair;
148
static int ett_x509af_CertificatePair;
149
static int ett_x509af_CertificateList;
150
static int ett_x509af_T_signedCertificateList;
151
static int ett_x509af_T_revokedCertificates;
152
static int ett_x509af_T_revokedCertificates_item;
153
static int ett_x509af_AttributeCertificationPath;
154
static int ett_x509af_SEQUENCE_OF_ACPathData;
155
static int ett_x509af_ACPathData;
156
static int ett_x509af_AttributeCertificate;
157
static int ett_x509af_AttributeCertificateInfo;
158
static int ett_x509af_InfoSubject;
159
static int ett_x509af_SEQUENCE_OF_Attribute;
160
static int ett_x509af_IssuerSerial;
161
static int ett_x509af_AttCertValidityPeriod;
162
static int ett_x509af_AttributeCertificateAssertion;
163
static int ett_x509af_AssertionSubject;
164
static int ett_x509af_SET_OF_AttributeType;
165
static int ett_x509af_DSS_Params;
166
167
static expert_field ei_x509af_certificate_invalid;
168
169
static const char *algorithm_id;
170
static void
171
x509af_export_publickey(tvbuff_t *tvb, asn1_ctx_t *actx, int offset, int len);
172
173
/* proto_data keys */
174
82
#define X509AF_EO_INFO_KEY      0
175
655
#define X509AF_PRIVATE_DATA_KEY 1
176
177
typedef struct _x509af_eo_t {
178
  const char *subjectname;
179
  tvbuff_t *payload;
180
} x509af_eo_t;
181
182
typedef struct _x509af_private_data_t {
183
  nstime_t last_time;
184
  nstime_t not_before;
185
  nstime_t not_after;
186
#if 0
187
  // TODO: Move static global algorithm_id here.
188
  // (Why is the algorithm_id string wmem_file_scope()? That makes
189
  // no sense as a global common to all conversations.)
190
  const char *algorithm_id;
191
#endif
192
} x509af_private_data_t;
193
194
static x509af_private_data_t *
195
x509af_get_private_data(packet_info *pinfo)
196
534
{
197
534
  x509af_private_data_t *x509af_data = (x509af_private_data_t*)p_get_proto_data(pinfo->pool, pinfo, proto_x509af, X509AF_PRIVATE_DATA_KEY);
198
534
  if (!x509af_data) {
199
121
    x509af_data = wmem_new0(pinfo->pool, x509af_private_data_t);
200
121
    nstime_set_unset(&x509af_data->not_before);
201
121
    nstime_set_unset(&x509af_data->not_after);
202
121
    p_add_proto_data(pinfo->pool, pinfo, proto_x509af, X509AF_PRIVATE_DATA_KEY, x509af_data);
203
121
  }
204
534
  return x509af_data;
205
534
}
206
207
208
const value_string x509af_Version_vals[] = {
209
  {   0, "v1" },
210
  {   1, "v2" },
211
  {   2, "v3" },
212
  { 0, NULL }
213
};
214
215
216
unsigned
217
7
dissect_x509af_Version(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
218
7
  offset = dissect_ber_integer(implicit_tag, actx, tree, tvb, offset, hf_index,
219
7
                                                NULL);
220
221
7
  return offset;
222
7
}
223
224
225
226
unsigned
227
21
dissect_x509af_CertificateSerialNumber(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
228
21
  offset = dissect_ber_integer64(implicit_tag, actx, tree, tvb, offset, hf_index,
229
21
                                                NULL);
230
231
21
  return offset;
232
21
}
233
234
235
236
static unsigned
237
8.71k
dissect_x509af_T_algorithmId(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
238
8.71k
  const char *name;
239
240
8.71k
    offset = dissect_ber_object_identifier_str(implicit_tag, actx, tree, tvb, offset, hf_x509af_algorithm_id, &actx->external.direct_reference);
241
242
243
8.71k
  if(actx->external.direct_reference) {
244
8.71k
    algorithm_id = (const char *)wmem_strdup(wmem_file_scope(), actx->external.direct_reference);
245
246
8.71k
    name = oid_resolved_from_string(actx->pinfo->pool, actx->external.direct_reference);
247
248
8.71k
    proto_item_append_text(tree, " (%s)", name ? name : actx->external.direct_reference);
249
8.71k
  }
250
251
252
8.71k
  return offset;
253
8.71k
}
254
255
256
257
static unsigned
258
8.70k
dissect_x509af_T_parameters(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
259
8.70k
  offset=call_ber_oid_callback(actx->external.direct_reference, tvb, offset, actx->pinfo, tree, NULL);
260
261
262
8.70k
  return offset;
263
8.70k
}
264
265
266
static const ber_sequence_t AlgorithmIdentifier_sequence[] = {
267
  { &hf_x509af_algorithmId  , BER_CLASS_UNI, BER_UNI_TAG_OID, BER_FLAGS_NOOWNTAG, dissect_x509af_T_algorithmId },
268
  { &hf_x509af_parameters   , BER_CLASS_ANY, 0, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_T_parameters },
269
  { NULL, 0, 0, 0, NULL }
270
};
271
272
unsigned
273
8.76k
dissect_x509af_AlgorithmIdentifier(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
274
8.76k
  if (algorithm_id) {
275
8.71k
    wmem_free(wmem_file_scope(), (void*)algorithm_id);
276
8.71k
    algorithm_id = NULL;
277
8.71k
  }
278
279
8.76k
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
280
8.76k
                                   AlgorithmIdentifier_sequence, hf_index, ett_x509af_AlgorithmIdentifier);
281
282
8.76k
  return offset;
283
8.76k
}
284
285
286
287
static unsigned
288
54
dissect_x509af_T_utcTime(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
289
54
  char *outstr, *newstr;
290
54
  int old_offset = offset;
291
292
54
  x509af_private_data_t *x509af_data = x509af_get_private_data(actx->pinfo);
293
294
  /* the 2-digit year can only be in the range 1950..2049 https://tools.ietf.org/html/rfc5280#section-4.1.2.5.1 */
295
54
  offset = dissect_ber_UTCTime(implicit_tag, actx, tree, tvb, offset, -1, &outstr, NULL);
296
297
54
  if (hf_index > 0 && outstr) {
298
0
    nstime_t time_val;
299
0
    newstr = wmem_strconcat(actx->pinfo->pool, outstr[0] < '5' ? "20": "19", outstr, NULL);
300
301
0
    iso8601_to_nstime(&time_val, newstr, ISO8601_DATETIME_AUTO);
302
303
    /* move past TLV */
304
0
    old_offset = get_ber_identifier(tvb, old_offset, NULL, NULL, NULL);
305
0
    old_offset = get_ber_length(tvb, old_offset, NULL, NULL);
306
307
0
    proto_tree_add_time(tree, hf_index, tvb, old_offset, offset - old_offset, &time_val);
308
309
0
    nstime_copy(&x509af_data->last_time, &time_val);
310
0
  }
311
312
313
54
  return offset;
314
54
}
315
316
317
318
static unsigned
319
66
dissect_x509af_GeneralizedTime(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
320
66
  offset = dissect_ber_GeneralizedTime(implicit_tag, actx, tree, tvb, offset, hf_index);
321
322
66
  return offset;
323
66
}
324
325
326
const value_string x509af_Time_vals[] = {
327
  {   0, "utcTime" },
328
  {   1, "generalizedTime" },
329
  { 0, NULL }
330
};
331
332
static const ber_choice_t Time_choice[] = {
333
  {   0, &hf_x509af_utcTime      , BER_CLASS_UNI, BER_UNI_TAG_UTCTime, BER_FLAGS_NOOWNTAG, dissect_x509af_T_utcTime },
334
  {   1, &hf_x509af_generalizedTime, BER_CLASS_UNI, BER_UNI_TAG_GeneralizedTime, BER_FLAGS_NOOWNTAG, dissect_x509af_GeneralizedTime },
335
  { 0, NULL, 0, 0, 0, NULL }
336
};
337
338
unsigned
339
255
dissect_x509af_Time(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
340
255
  x509af_private_data_t *x509af_data = x509af_get_private_data(actx->pinfo);
341
255
  nstime_set_unset(&x509af_data->last_time);
342
343
255
  offset = dissect_ber_choice(actx, tree, tvb, offset,
344
255
                                 Time_choice, hf_index, ett_x509af_Time,
345
255
                                 NULL);
346
347
255
  return offset;
348
255
}
349
350
351
352
static unsigned
353
136
dissect_x509af_T_notBefore(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
354
136
  offset = dissect_x509af_Time(implicit_tag, tvb, offset, actx, tree, hf_index);
355
356
136
  x509af_private_data_t *x509af_data = x509af_get_private_data(actx->pinfo);
357
136
  nstime_copy(&x509af_data->not_before, &x509af_data->last_time);
358
359
136
  return offset;
360
136
}
361
362
363
364
static unsigned
365
111
dissect_x509af_T_notAfter(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
366
111
  offset = dissect_x509af_Time(implicit_tag, tvb, offset, actx, tree, hf_index);
367
368
111
  x509af_private_data_t *x509af_data = x509af_get_private_data(actx->pinfo);
369
111
  nstime_copy(&x509af_data->not_after, &x509af_data->last_time);
370
111
  if (actx->pinfo->presence_flags & PINFO_HAS_TS &&
371
109
      !nstime_is_unset(&x509af_data->not_before) &&
372
0
      !nstime_is_unset(&x509af_data->not_after)) {
373
374
0
    if (nstime_cmp(&x509af_data->not_before, &x509af_data->not_after) > 0) {
375
0
      expert_add_info_format(actx->pinfo, proto_tree_get_parent(tree), &ei_x509af_certificate_invalid, "Invalid certificate (notBefore time is after notAfter time)");
376
0
    } else if ((nstime_cmp(&x509af_data->not_before, &actx->pinfo->abs_ts) > 0) || (nstime_cmp(&actx->pinfo->abs_ts, &x509af_data->not_after) > 0)) {
377
0
      expert_add_info_format(actx->pinfo, proto_tree_get_parent(tree), &ei_x509af_certificate_invalid, "Invalid certificate (frame arrival time %s not in valid interval)", abs_time_to_str(actx->pinfo->pool, &actx->pinfo->abs_ts, ABSOLUTE_TIME_UTC, true));
378
0
    }
379
0
  }
380
381
111
  return offset;
382
111
}
383
384
385
static const ber_sequence_t Validity_sequence[] = {
386
  { &hf_x509af_notBefore    , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_T_notBefore },
387
  { &hf_x509af_notAfter     , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_T_notAfter },
388
  { NULL, 0, 0, 0, NULL }
389
};
390
391
unsigned
392
142
dissect_x509af_Validity(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
393
142
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
394
142
                                   Validity_sequence, hf_index, ett_x509af_Validity);
395
396
142
  return offset;
397
142
}
398
399
400
static const value_string x509af_SubjectName_vals[] = {
401
  {   0, "rdnSequence" },
402
  { 0, NULL }
403
};
404
405
static const ber_choice_t SubjectName_choice[] = {
406
  {   0, &hf_x509af_rdnSequence  , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509if_RDNSequence },
407
  { 0, NULL, 0, 0, 0, NULL }
408
};
409
410
static unsigned
411
82
dissect_x509af_SubjectName(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
412
413
82
  const char* str;
414
82
    offset = dissect_ber_choice(actx, tree, tvb, offset,
415
82
                                 SubjectName_choice, hf_index, ett_x509af_SubjectName,
416
82
                                 NULL);
417
418
419
82
  str = x509if_get_last_dn();
420
82
  proto_item_append_text(proto_item_get_parent(tree), " (%s)", str?str:"");
421
82
  x509af_eo_t *eo_info = p_get_proto_data(actx->pinfo->pool, actx->pinfo, proto_x509af, X509AF_EO_INFO_KEY);
422
82
  if (eo_info) {
423
0
    eo_info->subjectname = str;
424
0
  }
425
426
427
82
  return offset;
428
82
}
429
430
431
432
static unsigned
433
8
dissect_x509af_T_subjectPublicKey(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
434
8
  tvbuff_t *bs_tvb = NULL;
435
436
8
  offset = dissect_ber_bitstring(false, actx, tree, tvb, offset,
437
8
                                 NULL, 0, hf_index, -1, &bs_tvb);
438
439
  /* See RFC 3279 for possible subjectPublicKey values given an Algorithm ID.
440
   * The contents of subjectPublicKey are always explicitly tagged. */
441
8
  if (bs_tvb && !g_strcmp0(algorithm_id, "1.2.840.113549.1.1.1")) { /* id-rsa */
442
0
    proto_tree *subtree = proto_item_add_subtree(actx->created_item, ett_x509af_SubjectPublicKey);
443
0
    dissect_pkixalgs_RSAPublicKey(false, bs_tvb, 0, actx, subtree, hf_x509af_subjectPublicKey_rsa);
444
445
8
  } else if (bs_tvb && !g_strcmp0(algorithm_id, "1.2.840.10040.4.1")) { /* id-dsa */
446
0
    proto_tree *subtree = proto_item_add_subtree(actx->created_item, ett_x509af_SubjectPublicKey);
447
0
    dissect_pkixalgs_DSAPublicKey(false, bs_tvb, 0, actx, subtree, hf_x509af_subjectPublicKey_dsa);
448
449
8
  } else if (bs_tvb && !g_strcmp0(algorithm_id, "1.2.840.10046.2.1")) { /* dhpublicnumber */
450
0
    proto_tree *subtree = proto_item_add_subtree(actx->created_item, ett_x509af_SubjectPublicKey);
451
0
    dissect_pkixalgs_DHPublicKey(false, bs_tvb, 0, actx, subtree, hf_x509af_subjectPublicKey_dh);
452
453
0
  }
454
455
456
8
  return offset;
457
8
}
458
459
460
static const ber_sequence_t SubjectPublicKeyInfo_sequence[] = {
461
  { &hf_x509af_algorithm    , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier },
462
  { &hf_x509af_subjectPublicKey, BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_NOOWNTAG, dissect_x509af_T_subjectPublicKey },
463
  { NULL, 0, 0, 0, NULL }
464
};
465
466
unsigned
467
73
dissect_x509af_SubjectPublicKeyInfo(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
468
73
  int orig_offset = offset;
469
73
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
470
73
                                   SubjectPublicKeyInfo_sequence, hf_index, ett_x509af_SubjectPublicKeyInfo);
471
472
73
  x509af_export_publickey(tvb, actx, orig_offset, offset - orig_offset);
473
73
  return offset;
474
73
}
475
476
477
478
static unsigned
479
0
dissect_x509af_T_extnId(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
480
0
  const char *name;
481
482
0
    offset = dissect_ber_object_identifier_str(implicit_tag, actx, tree, tvb, offset, hf_x509af_extension_id, &actx->external.direct_reference);
483
484
485
0
  if(actx->external.direct_reference) {
486
0
    name = oid_resolved_from_string(actx->pinfo->pool, actx->external.direct_reference);
487
488
0
    proto_item_append_text(tree, " (%s)", name ? name : actx->external.direct_reference);
489
0
  }
490
491
492
0
  return offset;
493
0
}
494
495
496
497
static unsigned
498
0
dissect_x509af_BOOLEAN(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
499
0
  offset = dissect_ber_boolean(implicit_tag, actx, tree, tvb, offset, hf_index, NULL);
500
501
0
  return offset;
502
0
}
503
504
505
506
static unsigned
507
0
dissect_x509af_T_extnValue(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
508
0
  int8_t ber_class;
509
0
  bool pc, ind;
510
0
  int32_t tag;
511
0
  uint32_t len;
512
  /* skip past the T and L  */
513
0
  offset = dissect_ber_identifier(actx->pinfo, tree, tvb, offset, &ber_class, &pc, &tag);
514
0
  offset = dissect_ber_length(actx->pinfo, tree, tvb, offset, &len, &ind);
515
0
  offset=call_ber_oid_callback(actx->external.direct_reference, tvb, offset, actx->pinfo, tree, NULL);
516
517
518
0
  return offset;
519
0
}
520
521
522
static const ber_sequence_t Extension_sequence[] = {
523
  { &hf_x509af_extnId       , BER_CLASS_UNI, BER_UNI_TAG_OID, BER_FLAGS_NOOWNTAG, dissect_x509af_T_extnId },
524
  { &hf_x509af_critical     , BER_CLASS_UNI, BER_UNI_TAG_BOOLEAN, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_BOOLEAN },
525
  { &hf_x509af_extnValue    , BER_CLASS_UNI, BER_UNI_TAG_OCTETSTRING, BER_FLAGS_NOOWNTAG, dissect_x509af_T_extnValue },
526
  { NULL, 0, 0, 0, NULL }
527
};
528
529
unsigned
530
0
dissect_x509af_Extension(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
531
0
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
532
0
                                   Extension_sequence, hf_index, ett_x509af_Extension);
533
534
0
  return offset;
535
0
}
536
537
538
static const ber_sequence_t Extensions_sequence_of[1] = {
539
  { &hf_x509af_Extensions_item, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_Extension },
540
};
541
542
unsigned
543
12
dissect_x509af_Extensions(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
544
12
  offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset,
545
12
                                      Extensions_sequence_of, hf_index, ett_x509af_Extensions);
546
547
12
  return offset;
548
12
}
549
550
551
static const ber_sequence_t T_signedCertificate_sequence[] = {
552
  { &hf_x509af_version      , BER_CLASS_CON, 0, BER_FLAGS_OPTIONAL, dissect_x509af_Version },
553
  { &hf_x509af_serialNumber , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_CertificateSerialNumber },
554
  { &hf_x509af_signature    , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier },
555
  { &hf_x509af_issuer       , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG, dissect_x509if_Name },
556
  { &hf_x509af_validity     , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_Validity },
557
  { &hf_x509af_subject      , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_SubjectName },
558
  { &hf_x509af_subjectPublicKeyInfo, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_SubjectPublicKeyInfo },
559
  { &hf_x509af_issuerUniqueIdentifier, BER_CLASS_CON, 1, BER_FLAGS_OPTIONAL|BER_FLAGS_IMPLTAG, dissect_x509sat_UniqueIdentifier },
560
  { &hf_x509af_subjectUniqueIdentifier, BER_CLASS_CON, 2, BER_FLAGS_OPTIONAL|BER_FLAGS_IMPLTAG, dissect_x509sat_UniqueIdentifier },
561
  { &hf_x509af_extensions   , BER_CLASS_CON, 3, BER_FLAGS_OPTIONAL, dissect_x509af_Extensions },
562
  { NULL, 0, 0, 0, NULL }
563
};
564
565
static unsigned
566
307
dissect_x509af_T_signedCertificate(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
567
307
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
568
307
                                   T_signedCertificate_sequence, hf_index, ett_x509af_T_signedCertificate);
569
570
307
  return offset;
571
307
}
572
573
574
575
static unsigned
576
21
dissect_x509af_BIT_STRING(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
577
21
  offset = dissect_ber_bitstring(implicit_tag, actx, tree, tvb, offset,
578
21
                                    NULL, 0, hf_index, -1,
579
21
                                    NULL);
580
581
21
  return offset;
582
21
}
583
584
585
static const ber_sequence_t Certificate_sequence[] = {
586
  { &hf_x509af_signedCertificate, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_T_signedCertificate },
587
  { &hf_x509af_algorithmIdentifier, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier },
588
  { &hf_x509af_encrypted    , BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_NOOWNTAG, dissect_x509af_BIT_STRING },
589
  { NULL, 0, 0, 0, NULL }
590
};
591
592
unsigned
593
9.46k
dissect_x509af_Certificate(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
594
9.46k
  int start_offset = offset;
595
9.46k
  x509af_eo_t *eo_info = NULL;
596
9.46k
  if (have_tap_listener(x509af_eo_tap)) {
597
0
    eo_info = wmem_new0(actx->pinfo->pool, x509af_eo_t);
598
0
    p_add_proto_data(actx->pinfo->pool, actx->pinfo, proto_x509af, X509AF_EO_INFO_KEY, eo_info);
599
0
  }
600
601
9.46k
    offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
602
9.46k
                                   Certificate_sequence, hf_index, ett_x509af_Certificate);
603
604
605
9.46k
  if (eo_info) {
606
0
    eo_info->payload = tvb_new_subset_length(tvb, start_offset, offset - start_offset);
607
0
    tap_queue_packet(x509af_eo_tap, actx->pinfo, eo_info);
608
0
  }
609
610
611
9.46k
  return offset;
612
9.46k
}
613
614
615
static const ber_sequence_t CrossCertificates_set_of[1] = {
616
  { &hf_x509af_CrossCertificates_item, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_Certificate },
617
};
618
619
unsigned
620
0
dissect_x509af_CrossCertificates(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
621
0
  offset = dissect_ber_set_of(implicit_tag, actx, tree, tvb, offset,
622
0
                                 CrossCertificates_set_of, hf_index, ett_x509af_CrossCertificates);
623
624
0
  return offset;
625
0
}
626
627
628
static const ber_sequence_t ForwardCertificationPath_sequence_of[1] = {
629
  { &hf_x509af_ForwardCertificationPath_item, BER_CLASS_UNI, BER_UNI_TAG_SET, BER_FLAGS_NOOWNTAG, dissect_x509af_CrossCertificates },
630
};
631
632
unsigned
633
0
dissect_x509af_ForwardCertificationPath(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
634
0
  offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset,
635
0
                                      ForwardCertificationPath_sequence_of, hf_index, ett_x509af_ForwardCertificationPath);
636
637
0
  return offset;
638
0
}
639
640
641
static const ber_sequence_t Certificates_sequence[] = {
642
  { &hf_x509af_userCertificate, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_Certificate },
643
  { &hf_x509af_certificationPath, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_ForwardCertificationPath },
644
  { NULL, 0, 0, 0, NULL }
645
};
646
647
unsigned
648
0
dissect_x509af_Certificates(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
649
0
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
650
0
                                   Certificates_sequence, hf_index, ett_x509af_Certificates);
651
652
0
  return offset;
653
0
}
654
655
656
static const ber_sequence_t CertificatePair_sequence[] = {
657
  { &hf_x509af_issuedByThisCA, BER_CLASS_CON, 0, BER_FLAGS_OPTIONAL, dissect_x509af_Certificate },
658
  { &hf_x509af_issuedToThisCA, BER_CLASS_CON, 1, BER_FLAGS_OPTIONAL, dissect_x509af_Certificate },
659
  { NULL, 0, 0, 0, NULL }
660
};
661
662
unsigned
663
0
dissect_x509af_CertificatePair(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
664
0
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
665
0
                                   CertificatePair_sequence, hf_index, ett_x509af_CertificatePair);
666
667
0
  return offset;
668
0
}
669
670
671
static const ber_sequence_t SEQUENCE_OF_CertificatePair_sequence_of[1] = {
672
  { &hf_x509af_theCACertificates_item, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_CertificatePair },
673
};
674
675
static unsigned
676
0
dissect_x509af_SEQUENCE_OF_CertificatePair(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
677
0
  offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset,
678
0
                                      SEQUENCE_OF_CertificatePair_sequence_of, hf_index, ett_x509af_SEQUENCE_OF_CertificatePair);
679
680
0
  return offset;
681
0
}
682
683
684
static const ber_sequence_t CertificationPath_sequence[] = {
685
  { &hf_x509af_userCertificate, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_Certificate },
686
  { &hf_x509af_theCACertificates, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_SEQUENCE_OF_CertificatePair },
687
  { NULL, 0, 0, 0, NULL }
688
};
689
690
unsigned
691
0
dissect_x509af_CertificationPath(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
692
0
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
693
0
                                   CertificationPath_sequence, hf_index, ett_x509af_CertificationPath);
694
695
0
  return offset;
696
0
}
697
698
699
static const ber_sequence_t T_revokedCertificates_item_sequence[] = {
700
  { &hf_x509af_revokedUserCertificate, BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_CertificateSerialNumber },
701
  { &hf_x509af_revocationDate, BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_Time },
702
  { &hf_x509af_crlEntryExtensions, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_Extensions },
703
  { NULL, 0, 0, 0, NULL }
704
};
705
706
static unsigned
707
1
dissect_x509af_T_revokedCertificates_item(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
708
1
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
709
1
                                   T_revokedCertificates_item_sequence, hf_index, ett_x509af_T_revokedCertificates_item);
710
711
1
  return offset;
712
1
}
713
714
715
static const ber_sequence_t T_revokedCertificates_sequence_of[1] = {
716
  { &hf_x509af_revokedCertificates_item, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_T_revokedCertificates_item },
717
};
718
719
static unsigned
720
1
dissect_x509af_T_revokedCertificates(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
721
1
  offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset,
722
1
                                      T_revokedCertificates_sequence_of, hf_index, ett_x509af_T_revokedCertificates);
723
724
1
  return offset;
725
1
}
726
727
728
static const ber_sequence_t T_signedCertificateList_sequence[] = {
729
  { &hf_x509af_version      , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_Version },
730
  { &hf_x509af_signature    , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier },
731
  { &hf_x509af_issuer       , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG, dissect_x509if_Name },
732
  { &hf_x509af_thisUpdate   , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_Time },
733
  { &hf_x509af_nextUpdate   , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_Time },
734
  { &hf_x509af_revokedCertificates, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_T_revokedCertificates },
735
  { &hf_x509af_crlExtensions, BER_CLASS_CON, 0, BER_FLAGS_OPTIONAL, dissect_x509af_Extensions },
736
  { NULL, 0, 0, 0, NULL }
737
};
738
739
static unsigned
740
3
dissect_x509af_T_signedCertificateList(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
741
3
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
742
3
                                   T_signedCertificateList_sequence, hf_index, ett_x509af_T_signedCertificateList);
743
744
3
  return offset;
745
3
}
746
747
748
static const ber_sequence_t CertificateList_sequence[] = {
749
  { &hf_x509af_signedCertificateList, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_T_signedCertificateList },
750
  { &hf_x509af_algorithmIdentifier, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier },
751
  { &hf_x509af_encrypted    , BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_NOOWNTAG, dissect_x509af_BIT_STRING },
752
  { NULL, 0, 0, 0, NULL }
753
};
754
755
unsigned
756
4
dissect_x509af_CertificateList(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
757
4
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
758
4
                                   CertificateList_sequence, hf_index, ett_x509af_CertificateList);
759
760
4
  return offset;
761
4
}
762
763
764
static const ber_sequence_t IssuerSerial_sequence[] = {
765
  { &hf_x509af_issuerName   , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509ce_GeneralNames },
766
  { &hf_x509af_serial       , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_CertificateSerialNumber },
767
  { &hf_x509af_issuerUID    , BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509sat_UniqueIdentifier },
768
  { NULL, 0, 0, 0, NULL }
769
};
770
771
unsigned
772
0
dissect_x509af_IssuerSerial(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
773
0
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
774
0
                                   IssuerSerial_sequence, hf_index, ett_x509af_IssuerSerial);
775
776
0
  return offset;
777
0
}
778
779
780
static const value_string x509af_InfoSubject_vals[] = {
781
  {   0, "baseCertificateID" },
782
  {   1, "subjectName" },
783
  { 0, NULL }
784
};
785
786
static const ber_choice_t InfoSubject_choice[] = {
787
  {   0, &hf_x509af_baseCertificateID, BER_CLASS_CON, 0, 0, dissect_x509af_IssuerSerial },
788
  {   1, &hf_x509af_infoSubjectName, BER_CLASS_CON, 1, 0, dissect_x509ce_GeneralNames },
789
  { 0, NULL, 0, 0, 0, NULL }
790
};
791
792
static unsigned
793
33
dissect_x509af_InfoSubject(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
794
33
  offset = dissect_ber_choice(actx, tree, tvb, offset,
795
33
                                 InfoSubject_choice, hf_index, ett_x509af_InfoSubject,
796
33
                                 NULL);
797
798
33
  return offset;
799
33
}
800
801
802
static const ber_sequence_t AttCertValidityPeriod_sequence[] = {
803
  { &hf_x509af_notBeforeTime, BER_CLASS_UNI, BER_UNI_TAG_GeneralizedTime, BER_FLAGS_NOOWNTAG, dissect_x509af_GeneralizedTime },
804
  { &hf_x509af_notAfterTime , BER_CLASS_UNI, BER_UNI_TAG_GeneralizedTime, BER_FLAGS_NOOWNTAG, dissect_x509af_GeneralizedTime },
805
  { NULL, 0, 0, 0, NULL }
806
};
807
808
unsigned
809
0
dissect_x509af_AttCertValidityPeriod(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
810
0
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
811
0
                                   AttCertValidityPeriod_sequence, hf_index, ett_x509af_AttCertValidityPeriod);
812
813
0
  return offset;
814
0
}
815
816
817
static const ber_sequence_t SEQUENCE_OF_Attribute_sequence_of[1] = {
818
  { &hf_x509af_attributes_item, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509if_Attribute },
819
};
820
821
static unsigned
822
3
dissect_x509af_SEQUENCE_OF_Attribute(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
823
3
  offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset,
824
3
                                      SEQUENCE_OF_Attribute_sequence_of, hf_index, ett_x509af_SEQUENCE_OF_Attribute);
825
826
3
  return offset;
827
3
}
828
829
830
static const ber_sequence_t AttributeCertificateInfo_sequence[] = {
831
  { &hf_x509af_version      , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_Version },
832
  { &hf_x509af_info_subject , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_InfoSubject },
833
  { &hf_x509af_issuerName   , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509ce_GeneralNames },
834
  { &hf_x509af_signature    , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier },
835
  { &hf_x509af_serialNumber , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_CertificateSerialNumber },
836
  { &hf_x509af_attCertValidityPeriod, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AttCertValidityPeriod },
837
  { &hf_x509af_attributes   , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_SEQUENCE_OF_Attribute },
838
  { &hf_x509af_issuerUniqueID, BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509sat_UniqueIdentifier },
839
  { &hf_x509af_extensions   , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_Extensions },
840
  { NULL, 0, 0, 0, NULL }
841
};
842
843
unsigned
844
33
dissect_x509af_AttributeCertificateInfo(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
845
33
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
846
33
                                   AttributeCertificateInfo_sequence, hf_index, ett_x509af_AttributeCertificateInfo);
847
848
33
  return offset;
849
33
}
850
851
852
static const ber_sequence_t AttributeCertificate_sequence[] = {
853
  { &hf_x509af_signedAttributeCertificateInfo, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AttributeCertificateInfo },
854
  { &hf_x509af_algorithmIdentifier, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier },
855
  { &hf_x509af_encrypted    , BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_NOOWNTAG, dissect_x509af_BIT_STRING },
856
  { NULL, 0, 0, 0, NULL }
857
};
858
859
unsigned
860
33
dissect_x509af_AttributeCertificate(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
861
33
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
862
33
                                   AttributeCertificate_sequence, hf_index, ett_x509af_AttributeCertificate);
863
864
33
  return offset;
865
33
}
866
867
868
static const ber_sequence_t ACPathData_sequence[] = {
869
  { &hf_x509af_certificate  , BER_CLASS_CON, 0, BER_FLAGS_OPTIONAL, dissect_x509af_Certificate },
870
  { &hf_x509af_attributeCertificate, BER_CLASS_CON, 1, BER_FLAGS_OPTIONAL, dissect_x509af_AttributeCertificate },
871
  { NULL, 0, 0, 0, NULL }
872
};
873
874
unsigned
875
0
dissect_x509af_ACPathData(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
876
0
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
877
0
                                   ACPathData_sequence, hf_index, ett_x509af_ACPathData);
878
879
0
  return offset;
880
0
}
881
882
883
static const ber_sequence_t SEQUENCE_OF_ACPathData_sequence_of[1] = {
884
  { &hf_x509af_acPath_item  , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_ACPathData },
885
};
886
887
static unsigned
888
0
dissect_x509af_SEQUENCE_OF_ACPathData(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
889
0
  offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset,
890
0
                                      SEQUENCE_OF_ACPathData_sequence_of, hf_index, ett_x509af_SEQUENCE_OF_ACPathData);
891
892
0
  return offset;
893
0
}
894
895
896
static const ber_sequence_t AttributeCertificationPath_sequence[] = {
897
  { &hf_x509af_attributeCertificate, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AttributeCertificate },
898
  { &hf_x509af_acPath       , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_SEQUENCE_OF_ACPathData },
899
  { NULL, 0, 0, 0, NULL }
900
};
901
902
unsigned
903
0
dissect_x509af_AttributeCertificationPath(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
904
0
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
905
0
                                   AttributeCertificationPath_sequence, hf_index, ett_x509af_AttributeCertificationPath);
906
907
0
  return offset;
908
0
}
909
910
911
static const value_string x509af_AssertionSubject_vals[] = {
912
  {   0, "baseCertificateID" },
913
  {   1, "subjectName" },
914
  { 0, NULL }
915
};
916
917
static const ber_choice_t AssertionSubject_choice[] = {
918
  {   0, &hf_x509af_baseCertificateID, BER_CLASS_CON, 0, 0, dissect_x509af_IssuerSerial },
919
  {   1, &hf_x509af_assertionSubjectName, BER_CLASS_CON, 1, 0, dissect_x509af_SubjectName },
920
  { 0, NULL, 0, 0, 0, NULL }
921
};
922
923
static unsigned
924
0
dissect_x509af_AssertionSubject(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
925
0
  offset = dissect_ber_choice(actx, tree, tvb, offset,
926
0
                                 AssertionSubject_choice, hf_index, ett_x509af_AssertionSubject,
927
0
                                 NULL);
928
929
0
  return offset;
930
0
}
931
932
933
static const ber_sequence_t SET_OF_AttributeType_set_of[1] = {
934
  { &hf_x509af_attType_item , BER_CLASS_UNI, BER_UNI_TAG_OID, BER_FLAGS_NOOWNTAG, dissect_x509if_AttributeType },
935
};
936
937
static unsigned
938
0
dissect_x509af_SET_OF_AttributeType(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
939
0
  offset = dissect_ber_set_of(implicit_tag, actx, tree, tvb, offset,
940
0
                                 SET_OF_AttributeType_set_of, hf_index, ett_x509af_SET_OF_AttributeType);
941
942
0
  return offset;
943
0
}
944
945
946
static const ber_sequence_t AttributeCertificateAssertion_sequence[] = {
947
  { &hf_x509af_assertion_subject, BER_CLASS_CON, 0, BER_FLAGS_OPTIONAL, dissect_x509af_AssertionSubject },
948
  { &hf_x509af_assertionIssuer, BER_CLASS_CON, 1, BER_FLAGS_OPTIONAL, dissect_x509if_Name },
949
  { &hf_x509af_attCertValidity, BER_CLASS_CON, 2, BER_FLAGS_OPTIONAL, dissect_x509af_GeneralizedTime },
950
  { &hf_x509af_attType      , BER_CLASS_CON, 3, BER_FLAGS_OPTIONAL, dissect_x509af_SET_OF_AttributeType },
951
  { NULL, 0, 0, 0, NULL }
952
};
953
954
unsigned
955
0
dissect_x509af_AttributeCertificateAssertion(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
956
0
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
957
0
                                   AttributeCertificateAssertion_sequence, hf_index, ett_x509af_AttributeCertificateAssertion);
958
959
0
  return offset;
960
0
}
961
962
963
964
static unsigned
965
0
dissect_x509af_INTEGER(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
966
0
  offset = dissect_ber_integer(implicit_tag, actx, tree, tvb, offset, hf_index,
967
0
                                                NULL);
968
969
0
  return offset;
970
0
}
971
972
973
static const ber_sequence_t DSS_Params_sequence[] = {
974
  { &hf_x509af_p            , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_INTEGER },
975
  { &hf_x509af_q            , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_INTEGER },
976
  { &hf_x509af_g            , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_INTEGER },
977
  { NULL, 0, 0, 0, NULL }
978
};
979
980
static unsigned
981
0
dissect_x509af_DSS_Params(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
982
0
  offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset,
983
0
                                   DSS_Params_sequence, hf_index, ett_x509af_DSS_Params);
984
985
0
  return offset;
986
0
}
987
988
989
990
static unsigned
991
0
dissect_x509af_Userid(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) {
992
0
  offset = dissect_ber_constrained_restricted_string(implicit_tag, BER_UNI_TAG_UTF8String,
993
0
                                                        actx, tree, tvb, offset,
994
0
                                                        1, ub_user_identifier, hf_index, NULL);
995
996
0
  return offset;
997
0
}
998
999
/*--- PDUs ---*/
1000
1001
3
int dissect_x509af_Certificate_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) {
1002
3
  unsigned offset = 0;
1003
3
  asn1_ctx_t asn1_ctx;
1004
3
  asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo);
1005
3
  offset = dissect_x509af_Certificate(false, tvb, offset, &asn1_ctx, tree, hf_x509af_x509af_Certificate_PDU);
1006
3
  return offset;
1007
3
}
1008
0
static int dissect_SubjectPublicKeyInfo_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) {
1009
0
  unsigned offset = 0;
1010
0
  asn1_ctx_t asn1_ctx;
1011
0
  asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo);
1012
0
  offset = dissect_x509af_SubjectPublicKeyInfo(false, tvb, offset, &asn1_ctx, tree, hf_x509af_SubjectPublicKeyInfo_PDU);
1013
0
  return offset;
1014
0
}
1015
0
static int dissect_CertificatePair_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) {
1016
0
  unsigned offset = 0;
1017
0
  asn1_ctx_t asn1_ctx;
1018
0
  asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo);
1019
0
  offset = dissect_x509af_CertificatePair(false, tvb, offset, &asn1_ctx, tree, hf_x509af_CertificatePair_PDU);
1020
0
  return offset;
1021
0
}
1022
4
static int dissect_CertificateList_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) {
1023
4
  unsigned offset = 0;
1024
4
  asn1_ctx_t asn1_ctx;
1025
4
  asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo);
1026
4
  offset = dissect_x509af_CertificateList(false, tvb, offset, &asn1_ctx, tree, hf_x509af_CertificateList_PDU);
1027
4
  return offset;
1028
4
}
1029
33
static int dissect_AttributeCertificate_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) {
1030
33
  unsigned offset = 0;
1031
33
  asn1_ctx_t asn1_ctx;
1032
33
  asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo);
1033
33
  offset = dissect_x509af_AttributeCertificate(false, tvb, offset, &asn1_ctx, tree, hf_x509af_AttributeCertificate_PDU);
1034
33
  return offset;
1035
33
}
1036
0
static int dissect_DSS_Params_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) {
1037
0
  unsigned offset = 0;
1038
0
  asn1_ctx_t asn1_ctx;
1039
0
  asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo);
1040
0
  offset = dissect_x509af_DSS_Params(false, tvb, offset, &asn1_ctx, tree, hf_x509af_DSS_Params_PDU);
1041
0
  return offset;
1042
0
}
1043
0
static int dissect_Userid_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) {
1044
0
  unsigned offset = 0;
1045
0
  asn1_ctx_t asn1_ctx;
1046
0
  asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo);
1047
0
  offset = dissect_x509af_Userid(false, tvb, offset, &asn1_ctx, tree, hf_x509af_Userid_PDU);
1048
0
  return offset;
1049
0
}
1050
1051
1052
static tap_packet_status
1053
x509af_eo_packet(void *tapdata, packet_info *pinfo, epan_dissect_t *edt _U_, const void *data, tap_flags_t flags _U_)
1054
0
{
1055
0
  export_object_list_t *object_list = (export_object_list_t *)tapdata;
1056
0
  const x509af_eo_t *eo_info = (const x509af_eo_t *)data;
1057
0
  export_object_entry_t *entry;
1058
1059
0
  if (data) {
1060
0
    entry = g_new0(export_object_entry_t, 1);
1061
1062
0
    entry->pkt_num = pinfo->num;
1063
1064
    // There should be a commonName
1065
0
    const char *name = eo_info->subjectname ? strstr(eo_info->subjectname, "id-at-commonName=") : NULL;
1066
0
    if (name) {
1067
0
      name += strlen("id-at-commonName=");
1068
0
      entry->hostname = g_strndup(name, strcspn(name, ","));
1069
0
    }
1070
0
    entry->content_type = g_strdup("application/pkix-cert");
1071
1072
0
    entry->payload_len = tvb_captured_length(eo_info->payload);
1073
0
    entry->payload_data = (uint8_t *)tvb_memdup(NULL, eo_info->payload, 0, entry->payload_len);
1074
1075
0
    uint8_t sha256sum[HASH_SHA2_256_LENGTH] = {0};
1076
0
    gcry_md_hash_buffer(GCRY_MD_SHA256, sha256sum, entry->payload_data, entry->payload_len);
1077
0
    entry->filename = g_strdup_printf("%s.cer", bytes_to_str(pinfo->pool, sha256sum, HASH_SHA2_256_LENGTH));
1078
1079
0
    object_list->add_entry(object_list->gui_data, entry);
1080
1081
0
    return TAP_PACKET_REDRAW;
1082
0
  } else {
1083
0
    return TAP_PACKET_DONT_REDRAW;
1084
0
  }
1085
0
}
1086
1087
/* Exports the SubjectPublicKeyInfo structure as gnutls_datum_t.
1088
 * actx->private_data is assumed to be a gnutls_datum_t pointer which will be
1089
 * filled in if non-NULL. */
1090
static void
1091
x509af_export_publickey(tvbuff_t *tvb _U_, asn1_ctx_t *actx _U_, int offset _U_, int len _U_)
1092
63
{
1093
#if defined(HAVE_LIBGNUTLS)
1094
  gnutls_datum_t *subjectPublicKeyInfo = (gnutls_datum_t *)actx->private_data;
1095
  if (subjectPublicKeyInfo) {
1096
    /* This is only passed to ssh_find_private_key_by_pubkey, which uses it
1097
     * with gnutls_pubkey_import, which treats the data as const, so this
1098
     * cast is acceptable. */
1099
    subjectPublicKeyInfo->data = (unsigned char *) tvb_get_ptr(tvb, offset, len);
1100
    subjectPublicKeyInfo->size = len;
1101
    actx->private_data = NULL;
1102
  }
1103
#endif
1104
63
}
1105
1106
0
const char *x509af_get_last_algorithm_id(void) {
1107
0
  return algorithm_id;
1108
0
}
1109
1110
1111
static int
1112
dissect_pkix_crl(tvbuff_t *tvb, packet_info *pinfo, proto_tree *parent_tree, void *data _U_)
1113
0
{
1114
0
  proto_tree *tree;
1115
0
  asn1_ctx_t asn1_ctx;
1116
0
  asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo);
1117
1118
0
  col_set_str(pinfo->cinfo, COL_PROTOCOL, "PKIX-CRL");
1119
1120
0
  col_set_str(pinfo->cinfo, COL_INFO, "Certificate Revocation List");
1121
1122
1123
0
  tree=proto_tree_add_subtree(parent_tree, tvb, 0, -1, ett_pkix_crl, NULL, "Certificate Revocation List");
1124
1125
0
  return dissect_x509af_CertificateList(false, tvb, 0, &asn1_ctx, tree, -1);
1126
0
}
1127
1128
static void
1129
x509af_cleanup_protocol(void)
1130
0
{
1131
0
  algorithm_id = NULL;
1132
0
}
1133
1134
/*--- proto_register_x509af ----------------------------------------------*/
1135
16
void proto_register_x509af(void) {
1136
1137
  /* List of fields */
1138
16
  static hf_register_info hf[] = {
1139
16
    { &hf_x509af_algorithm_id,
1140
16
      { "Algorithm Id", "x509af.algorithm.id",
1141
16
        FT_OID, BASE_NONE, NULL, 0,
1142
16
        NULL, HFILL }},
1143
16
    { &hf_x509af_extension_id,
1144
16
      { "Extension Id", "x509af.extension.id",
1145
16
        FT_OID, BASE_NONE, NULL, 0,
1146
16
        NULL, HFILL }},
1147
16
    { &hf_x509af_subjectPublicKey_dh,
1148
16
      { "DH Public Key", "x509af.subjectPublicKey.dh",
1149
16
        FT_BYTES, BASE_NONE, NULL, 0,
1150
16
        NULL, HFILL }},
1151
16
    { &hf_x509af_subjectPublicKey_dsa,
1152
16
      { "DSA Public Key", "x509af.subjectPublicKey.dsa",
1153
16
        FT_BYTES, BASE_NONE, NULL, 0,
1154
16
        NULL, HFILL }},
1155
16
    { &hf_x509af_subjectPublicKey_rsa,
1156
16
      { "RSA Public Key", "x509af.subjectPublicKey.rsa",
1157
16
        FT_NONE, BASE_NONE, NULL, 0,
1158
16
        NULL, HFILL }},
1159
16
    { &hf_x509af_x509af_Certificate_PDU,
1160
16
      { "Certificate", "x509af.Certificate_element",
1161
16
        FT_NONE, BASE_NONE, NULL, 0,
1162
16
        NULL, HFILL }},
1163
16
    { &hf_x509af_SubjectPublicKeyInfo_PDU,
1164
16
      { "SubjectPublicKeyInfo", "x509af.SubjectPublicKeyInfo_element",
1165
16
        FT_NONE, BASE_NONE, NULL, 0,
1166
16
        NULL, HFILL }},
1167
16
    { &hf_x509af_CertificatePair_PDU,
1168
16
      { "CertificatePair", "x509af.CertificatePair_element",
1169
16
        FT_NONE, BASE_NONE, NULL, 0,
1170
16
        NULL, HFILL }},
1171
16
    { &hf_x509af_CertificateList_PDU,
1172
16
      { "CertificateList", "x509af.CertificateList_element",
1173
16
        FT_NONE, BASE_NONE, NULL, 0,
1174
16
        NULL, HFILL }},
1175
16
    { &hf_x509af_AttributeCertificate_PDU,
1176
16
      { "AttributeCertificate", "x509af.AttributeCertificate_element",
1177
16
        FT_NONE, BASE_NONE, NULL, 0,
1178
16
        NULL, HFILL }},
1179
16
    { &hf_x509af_DSS_Params_PDU,
1180
16
      { "DSS-Params", "x509af.DSS_Params_element",
1181
16
        FT_NONE, BASE_NONE, NULL, 0,
1182
16
        NULL, HFILL }},
1183
16
    { &hf_x509af_Userid_PDU,
1184
16
      { "Userid", "x509af.Userid",
1185
16
        FT_STRING, BASE_NONE, NULL, 0,
1186
16
        NULL, HFILL }},
1187
16
    { &hf_x509af_signedCertificate,
1188
16
      { "signedCertificate", "x509af.signedCertificate_element",
1189
16
        FT_NONE, BASE_NONE, NULL, 0,
1190
16
        NULL, HFILL }},
1191
16
    { &hf_x509af_version,
1192
16
      { "version", "x509af.version",
1193
16
        FT_INT32, BASE_DEC, VALS(x509af_Version_vals), 0,
1194
16
        NULL, HFILL }},
1195
16
    { &hf_x509af_serialNumber,
1196
16
      { "serialNumber", "x509af.serialNumber",
1197
16
        FT_BYTES, BASE_NONE, NULL, 0,
1198
16
        "CertificateSerialNumber", HFILL }},
1199
16
    { &hf_x509af_signature,
1200
16
      { "signature", "x509af.signature_element",
1201
16
        FT_NONE, BASE_NONE, NULL, 0,
1202
16
        "AlgorithmIdentifier", HFILL }},
1203
16
    { &hf_x509af_issuer,
1204
16
      { "issuer", "x509af.issuer",
1205
16
        FT_UINT32, BASE_DEC, VALS(x509if_Name_vals), 0,
1206
16
        "Name", HFILL }},
1207
16
    { &hf_x509af_validity,
1208
16
      { "validity", "x509af.validity_element",
1209
16
        FT_NONE, BASE_NONE, NULL, 0,
1210
16
        NULL, HFILL }},
1211
16
    { &hf_x509af_subject,
1212
16
      { "subject", "x509af.subject",
1213
16
        FT_UINT32, BASE_DEC, VALS(x509af_SubjectName_vals), 0,
1214
16
        "SubjectName", HFILL }},
1215
16
    { &hf_x509af_subjectPublicKeyInfo,
1216
16
      { "subjectPublicKeyInfo", "x509af.subjectPublicKeyInfo_element",
1217
16
        FT_NONE, BASE_NONE, NULL, 0,
1218
16
        NULL, HFILL }},
1219
16
    { &hf_x509af_issuerUniqueIdentifier,
1220
16
      { "issuerUniqueIdentifier", "x509af.issuerUniqueIdentifier",
1221
16
        FT_BYTES, BASE_NONE, NULL, 0,
1222
16
        "UniqueIdentifier", HFILL }},
1223
16
    { &hf_x509af_subjectUniqueIdentifier,
1224
16
      { "subjectUniqueIdentifier", "x509af.subjectUniqueIdentifier",
1225
16
        FT_BYTES, BASE_NONE, NULL, 0,
1226
16
        "UniqueIdentifier", HFILL }},
1227
16
    { &hf_x509af_extensions,
1228
16
      { "extensions", "x509af.extensions",
1229
16
        FT_UINT32, BASE_DEC, NULL, 0,
1230
16
        NULL, HFILL }},
1231
16
    { &hf_x509af_algorithmIdentifier,
1232
16
      { "algorithmIdentifier", "x509af.algorithmIdentifier_element",
1233
16
        FT_NONE, BASE_NONE, NULL, 0,
1234
16
        NULL, HFILL }},
1235
16
    { &hf_x509af_encrypted,
1236
16
      { "encrypted", "x509af.encrypted",
1237
16
        FT_BYTES, BASE_NONE, NULL, 0,
1238
16
        "BIT_STRING", HFILL }},
1239
16
    { &hf_x509af_rdnSequence,
1240
16
      { "rdnSequence", "x509af.rdnSequence",
1241
16
        FT_UINT32, BASE_DEC, NULL, 0,
1242
16
        NULL, HFILL }},
1243
16
    { &hf_x509af_algorithmId,
1244
16
      { "algorithmId", "x509af.algorithmId",
1245
16
        FT_OID, BASE_NONE, NULL, 0,
1246
16
        NULL, HFILL }},
1247
16
    { &hf_x509af_parameters,
1248
16
      { "parameters", "x509af.parameters_element",
1249
16
        FT_NONE, BASE_NONE, NULL, 0,
1250
16
        NULL, HFILL }},
1251
16
    { &hf_x509af_notBefore,
1252
16
      { "notBefore", "x509af.notBefore",
1253
16
        FT_UINT32, BASE_DEC, VALS(x509af_Time_vals), 0,
1254
16
        NULL, HFILL }},
1255
16
    { &hf_x509af_notAfter,
1256
16
      { "notAfter", "x509af.notAfter",
1257
16
        FT_UINT32, BASE_DEC, VALS(x509af_Time_vals), 0,
1258
16
        NULL, HFILL }},
1259
16
    { &hf_x509af_algorithm,
1260
16
      { "algorithm", "x509af.algorithm_element",
1261
16
        FT_NONE, BASE_NONE, NULL, 0,
1262
16
        "AlgorithmIdentifier", HFILL }},
1263
16
    { &hf_x509af_subjectPublicKey,
1264
16
      { "subjectPublicKey", "x509af.subjectPublicKey",
1265
16
        FT_BYTES, BASE_NONE, NULL, 0,
1266
16
        NULL, HFILL }},
1267
16
    { &hf_x509af_utcTime,
1268
16
      { "utcTime", "x509af.utcTime",
1269
16
        FT_ABSOLUTE_TIME, ABSOLUTE_TIME_UTC, NULL, 0,
1270
16
        NULL, HFILL }},
1271
16
    { &hf_x509af_generalizedTime,
1272
16
      { "generalizedTime", "x509af.generalizedTime",
1273
16
        FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0,
1274
16
        NULL, HFILL }},
1275
16
    { &hf_x509af_Extensions_item,
1276
16
      { "Extension", "x509af.Extension_element",
1277
16
        FT_NONE, BASE_NONE, NULL, 0,
1278
16
        NULL, HFILL }},
1279
16
    { &hf_x509af_extnId,
1280
16
      { "extnId", "x509af.extnId",
1281
16
        FT_OID, BASE_NONE, NULL, 0,
1282
16
        NULL, HFILL }},
1283
16
    { &hf_x509af_critical,
1284
16
      { "critical", "x509af.critical",
1285
16
        FT_BOOLEAN, BASE_NONE, NULL, 0,
1286
16
        "BOOLEAN", HFILL }},
1287
16
    { &hf_x509af_extnValue,
1288
16
      { "extnValue", "x509af.extnValue",
1289
16
        FT_BYTES, BASE_NONE, NULL, 0,
1290
16
        NULL, HFILL }},
1291
16
    { &hf_x509af_userCertificate,
1292
16
      { "userCertificate", "x509af.userCertificate_element",
1293
16
        FT_NONE, BASE_NONE, NULL, 0,
1294
16
        "Certificate", HFILL }},
1295
16
    { &hf_x509af_certificationPath,
1296
16
      { "certificationPath", "x509af.certificationPath",
1297
16
        FT_UINT32, BASE_DEC, NULL, 0,
1298
16
        "ForwardCertificationPath", HFILL }},
1299
16
    { &hf_x509af_ForwardCertificationPath_item,
1300
16
      { "CrossCertificates", "x509af.CrossCertificates",
1301
16
        FT_UINT32, BASE_DEC, NULL, 0,
1302
16
        NULL, HFILL }},
1303
16
    { &hf_x509af_CrossCertificates_item,
1304
16
      { "Certificate", "x509af.Certificate_element",
1305
16
        FT_NONE, BASE_NONE, NULL, 0,
1306
16
        NULL, HFILL }},
1307
16
    { &hf_x509af_theCACertificates,
1308
16
      { "theCACertificates", "x509af.theCACertificates",
1309
16
        FT_UINT32, BASE_DEC, NULL, 0,
1310
16
        "SEQUENCE_OF_CertificatePair", HFILL }},
1311
16
    { &hf_x509af_theCACertificates_item,
1312
16
      { "CertificatePair", "x509af.CertificatePair_element",
1313
16
        FT_NONE, BASE_NONE, NULL, 0,
1314
16
        NULL, HFILL }},
1315
16
    { &hf_x509af_issuedByThisCA,
1316
16
      { "issuedByThisCA", "x509af.issuedByThisCA_element",
1317
16
        FT_NONE, BASE_NONE, NULL, 0,
1318
16
        "Certificate", HFILL }},
1319
16
    { &hf_x509af_issuedToThisCA,
1320
16
      { "issuedToThisCA", "x509af.issuedToThisCA_element",
1321
16
        FT_NONE, BASE_NONE, NULL, 0,
1322
16
        "Certificate", HFILL }},
1323
16
    { &hf_x509af_signedCertificateList,
1324
16
      { "signedCertificateList", "x509af.signedCertificateList_element",
1325
16
        FT_NONE, BASE_NONE, NULL, 0,
1326
16
        NULL, HFILL }},
1327
16
    { &hf_x509af_thisUpdate,
1328
16
      { "thisUpdate", "x509af.thisUpdate",
1329
16
        FT_UINT32, BASE_DEC, VALS(x509af_Time_vals), 0,
1330
16
        "Time", HFILL }},
1331
16
    { &hf_x509af_nextUpdate,
1332
16
      { "nextUpdate", "x509af.nextUpdate",
1333
16
        FT_UINT32, BASE_DEC, VALS(x509af_Time_vals), 0,
1334
16
        "Time", HFILL }},
1335
16
    { &hf_x509af_revokedCertificates,
1336
16
      { "revokedCertificates", "x509af.revokedCertificates",
1337
16
        FT_UINT32, BASE_DEC, NULL, 0,
1338
16
        NULL, HFILL }},
1339
16
    { &hf_x509af_revokedCertificates_item,
1340
16
      { "revokedCertificates item", "x509af.revokedCertificates_item_element",
1341
16
        FT_NONE, BASE_NONE, NULL, 0,
1342
16
        NULL, HFILL }},
1343
16
    { &hf_x509af_revokedUserCertificate,
1344
16
      { "userCertificate", "x509af.revokedUserCertificate",
1345
16
        FT_BYTES, BASE_NONE, NULL, 0,
1346
16
        "CertificateSerialNumber", HFILL }},
1347
16
    { &hf_x509af_revocationDate,
1348
16
      { "revocationDate", "x509af.revocationDate",
1349
16
        FT_UINT32, BASE_DEC, VALS(x509af_Time_vals), 0,
1350
16
        "Time", HFILL }},
1351
16
    { &hf_x509af_crlEntryExtensions,
1352
16
      { "crlEntryExtensions", "x509af.crlEntryExtensions",
1353
16
        FT_UINT32, BASE_DEC, NULL, 0,
1354
16
        "Extensions", HFILL }},
1355
16
    { &hf_x509af_crlExtensions,
1356
16
      { "crlExtensions", "x509af.crlExtensions",
1357
16
        FT_UINT32, BASE_DEC, NULL, 0,
1358
16
        "Extensions", HFILL }},
1359
16
    { &hf_x509af_attributeCertificate,
1360
16
      { "attributeCertificate", "x509af.attributeCertificate_element",
1361
16
        FT_NONE, BASE_NONE, NULL, 0,
1362
16
        NULL, HFILL }},
1363
16
    { &hf_x509af_acPath,
1364
16
      { "acPath", "x509af.acPath",
1365
16
        FT_UINT32, BASE_DEC, NULL, 0,
1366
16
        "SEQUENCE_OF_ACPathData", HFILL }},
1367
16
    { &hf_x509af_acPath_item,
1368
16
      { "ACPathData", "x509af.ACPathData_element",
1369
16
        FT_NONE, BASE_NONE, NULL, 0,
1370
16
        NULL, HFILL }},
1371
16
    { &hf_x509af_certificate,
1372
16
      { "certificate", "x509af.certificate_element",
1373
16
        FT_NONE, BASE_NONE, NULL, 0,
1374
16
        NULL, HFILL }},
1375
16
    { &hf_x509af_signedAttributeCertificateInfo,
1376
16
      { "signedAttributeCertificateInfo", "x509af.signedAttributeCertificateInfo_element",
1377
16
        FT_NONE, BASE_NONE, NULL, 0,
1378
16
        "AttributeCertificateInfo", HFILL }},
1379
16
    { &hf_x509af_info_subject,
1380
16
      { "subject", "x509af.info_subject",
1381
16
        FT_UINT32, BASE_DEC, VALS(x509af_InfoSubject_vals), 0,
1382
16
        "InfoSubject", HFILL }},
1383
16
    { &hf_x509af_baseCertificateID,
1384
16
      { "baseCertificateID", "x509af.baseCertificateID_element",
1385
16
        FT_NONE, BASE_NONE, NULL, 0,
1386
16
        "IssuerSerial", HFILL }},
1387
16
    { &hf_x509af_infoSubjectName,
1388
16
      { "subjectName", "x509af.infoSubjectName",
1389
16
        FT_UINT32, BASE_DEC, NULL, 0,
1390
16
        "GeneralNames", HFILL }},
1391
16
    { &hf_x509af_issuerName,
1392
16
      { "issuer", "x509af.issuerName",
1393
16
        FT_UINT32, BASE_DEC, NULL, 0,
1394
16
        "GeneralNames", HFILL }},
1395
16
    { &hf_x509af_attCertValidityPeriod,
1396
16
      { "attCertValidityPeriod", "x509af.attCertValidityPeriod_element",
1397
16
        FT_NONE, BASE_NONE, NULL, 0,
1398
16
        NULL, HFILL }},
1399
16
    { &hf_x509af_attributes,
1400
16
      { "attributes", "x509af.attributes",
1401
16
        FT_UINT32, BASE_DEC, NULL, 0,
1402
16
        "SEQUENCE_OF_Attribute", HFILL }},
1403
16
    { &hf_x509af_attributes_item,
1404
16
      { "Attribute", "x509af.Attribute_element",
1405
16
        FT_NONE, BASE_NONE, NULL, 0,
1406
16
        NULL, HFILL }},
1407
16
    { &hf_x509af_issuerUniqueID,
1408
16
      { "issuerUniqueID", "x509af.issuerUniqueID",
1409
16
        FT_BYTES, BASE_NONE, NULL, 0,
1410
16
        "UniqueIdentifier", HFILL }},
1411
16
    { &hf_x509af_serial,
1412
16
      { "serial", "x509af.serial",
1413
16
        FT_BYTES, BASE_NONE, NULL, 0,
1414
16
        "CertificateSerialNumber", HFILL }},
1415
16
    { &hf_x509af_issuerUID,
1416
16
      { "issuerUID", "x509af.issuerUID",
1417
16
        FT_BYTES, BASE_NONE, NULL, 0,
1418
16
        "UniqueIdentifier", HFILL }},
1419
16
    { &hf_x509af_notBeforeTime,
1420
16
      { "notBeforeTime", "x509af.notBeforeTime",
1421
16
        FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0,
1422
16
        "GeneralizedTime", HFILL }},
1423
16
    { &hf_x509af_notAfterTime,
1424
16
      { "notAfterTime", "x509af.notAfterTime",
1425
16
        FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0,
1426
16
        "GeneralizedTime", HFILL }},
1427
16
    { &hf_x509af_assertion_subject,
1428
16
      { "subject", "x509af.assertion_subject",
1429
16
        FT_UINT32, BASE_DEC, VALS(x509af_AssertionSubject_vals), 0,
1430
16
        "AssertionSubject", HFILL }},
1431
16
    { &hf_x509af_assertionSubjectName,
1432
16
      { "subjectName", "x509af.assertionSubjectName",
1433
16
        FT_UINT32, BASE_DEC, VALS(x509af_SubjectName_vals), 0,
1434
16
        NULL, HFILL }},
1435
16
    { &hf_x509af_assertionIssuer,
1436
16
      { "issuer", "x509af.assertionIssuer",
1437
16
        FT_UINT32, BASE_DEC, VALS(x509if_Name_vals), 0,
1438
16
        "Name", HFILL }},
1439
16
    { &hf_x509af_attCertValidity,
1440
16
      { "attCertValidity", "x509af.attCertValidity",
1441
16
        FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0,
1442
16
        "GeneralizedTime", HFILL }},
1443
16
    { &hf_x509af_attType,
1444
16
      { "attType", "x509af.attType",
1445
16
        FT_UINT32, BASE_DEC, NULL, 0,
1446
16
        "SET_OF_AttributeType", HFILL }},
1447
16
    { &hf_x509af_attType_item,
1448
16
      { "AttributeType", "x509af.AttributeType",
1449
16
        FT_OID, BASE_NONE, NULL, 0,
1450
16
        NULL, HFILL }},
1451
16
    { &hf_x509af_p,
1452
16
      { "p", "x509af.p",
1453
16
        FT_BYTES, BASE_NONE, NULL, 0,
1454
16
        "INTEGER", HFILL }},
1455
16
    { &hf_x509af_q,
1456
16
      { "q", "x509af.q",
1457
16
        FT_BYTES, BASE_NONE, NULL, 0,
1458
16
        "INTEGER", HFILL }},
1459
16
    { &hf_x509af_g,
1460
16
      { "g", "x509af.g",
1461
16
        FT_BYTES, BASE_NONE, NULL, 0,
1462
16
        "INTEGER", HFILL }},
1463
16
  };
1464
1465
  /* List of subtrees */
1466
16
  static int *ett[] = {
1467
16
    &ett_pkix_crl,
1468
16
    &ett_x509af_SubjectPublicKey,
1469
16
    &ett_x509af_Certificate,
1470
16
    &ett_x509af_T_signedCertificate,
1471
16
    &ett_x509af_SubjectName,
1472
16
    &ett_x509af_AlgorithmIdentifier,
1473
16
    &ett_x509af_Validity,
1474
16
    &ett_x509af_SubjectPublicKeyInfo,
1475
16
    &ett_x509af_Time,
1476
16
    &ett_x509af_Extensions,
1477
16
    &ett_x509af_Extension,
1478
16
    &ett_x509af_Certificates,
1479
16
    &ett_x509af_ForwardCertificationPath,
1480
16
    &ett_x509af_CrossCertificates,
1481
16
    &ett_x509af_CertificationPath,
1482
16
    &ett_x509af_SEQUENCE_OF_CertificatePair,
1483
16
    &ett_x509af_CertificatePair,
1484
16
    &ett_x509af_CertificateList,
1485
16
    &ett_x509af_T_signedCertificateList,
1486
16
    &ett_x509af_T_revokedCertificates,
1487
16
    &ett_x509af_T_revokedCertificates_item,
1488
16
    &ett_x509af_AttributeCertificationPath,
1489
16
    &ett_x509af_SEQUENCE_OF_ACPathData,
1490
16
    &ett_x509af_ACPathData,
1491
16
    &ett_x509af_AttributeCertificate,
1492
16
    &ett_x509af_AttributeCertificateInfo,
1493
16
    &ett_x509af_InfoSubject,
1494
16
    &ett_x509af_SEQUENCE_OF_Attribute,
1495
16
    &ett_x509af_IssuerSerial,
1496
16
    &ett_x509af_AttCertValidityPeriod,
1497
16
    &ett_x509af_AttributeCertificateAssertion,
1498
16
    &ett_x509af_AssertionSubject,
1499
16
    &ett_x509af_SET_OF_AttributeType,
1500
16
    &ett_x509af_DSS_Params,
1501
16
  };
1502
1503
16
  static ei_register_info ei[] = {
1504
16
    { &ei_x509af_certificate_invalid, { "x509af.signedCertificate.invalid", PI_SECURITY, PI_WARN, "Invalid certificate", EXPFILL }},
1505
16
  };
1506
1507
16
  expert_module_t *expert_x509af;
1508
1509
  /* Register protocol */
1510
16
  proto_x509af = proto_register_protocol("X.509 Authentication Framework", "X509AF", "x509af");
1511
1512
  /* Register fields and subtrees */
1513
16
  proto_register_field_array(proto_x509af, hf, array_length(hf));
1514
16
  proto_register_subtree_array(ett, array_length(ett));
1515
1516
16
  expert_x509af = expert_register_protocol(proto_x509af);
1517
16
  expert_register_field_array(expert_x509af, ei, array_length(ei));
1518
1519
16
  x509af_eo_tap = register_export_object(proto_x509af, x509af_eo_packet, NULL);
1520
1521
16
  register_cleanup_routine(&x509af_cleanup_protocol);
1522
1523
16
  pkix_crl_handle = register_dissector("x509af", dissect_pkix_crl, proto_x509af);
1524
1525
16
  register_ber_syntax_dissector("Certificate", proto_x509af, dissect_x509af_Certificate_PDU);
1526
16
  register_ber_syntax_dissector("CertificateList", proto_x509af, dissect_CertificateList_PDU);
1527
16
  register_ber_syntax_dissector("CrossCertificatePair", proto_x509af, dissect_CertificatePair_PDU);
1528
1529
16
  register_ber_oid_syntax(".cer", NULL, "Certificate");
1530
16
  register_ber_oid_syntax(".crt", NULL, "Certificate");
1531
16
  register_ber_oid_syntax(".crl", NULL, "CertificateList");
1532
16
}
1533
1534
1535
/*--- proto_reg_handoff_x509af -------------------------------------------*/
1536
16
void proto_reg_handoff_x509af(void) {
1537
1538
16
  dissector_add_string("media_type", "application/pkix-crl", pkix_crl_handle);
1539
1540
16
  register_ber_oid_dissector("2.5.4.36", dissect_x509af_Certificate_PDU, proto_x509af, "id-at-userCertificate");
1541
16
  register_ber_oid_dissector("2.5.4.37", dissect_x509af_Certificate_PDU, proto_x509af, "id-at-cAcertificate");
1542
16
  register_ber_oid_dissector("2.5.4.38", dissect_CertificateList_PDU, proto_x509af, "id-at-authorityRevocationList");
1543
16
  register_ber_oid_dissector("2.5.4.39", dissect_CertificateList_PDU, proto_x509af, "id-at-certificateRevocationList");
1544
16
  register_ber_oid_dissector("2.5.4.40", dissect_CertificatePair_PDU, proto_x509af, "id-at-crossCertificatePair");
1545
16
  register_ber_oid_dissector("2.5.4.53", dissect_CertificateList_PDU, proto_x509af, "id-at-deltaRevocationList");
1546
16
  register_ber_oid_dissector("2.5.4.58", dissect_AttributeCertificate_PDU, proto_x509af, "id-at-attributeCertificate");
1547
16
  register_ber_oid_dissector("2.5.4.59", dissect_CertificateList_PDU, proto_x509af, "id-at-attributeCertificateRevocationList");
1548
16
  register_ber_oid_dissector("1.2.840.10040.4.1", dissect_DSS_Params_PDU, proto_x509af, "id-dsa");
1549
16
  register_ber_oid_dissector("0.9.2342.19200300.100.1.1", dissect_Userid_PDU, proto_x509af, "id-userid");
1550
1551
1552
  /*XXX these should really go to a better place but since
1553
    I have not that ITU standard, I'll put it here for the time
1554
    being.
1555
    Only implemented those algorithms that take no parameters
1556
    for the time being,   ronnie
1557
  */
1558
  /* from http://www.alvestrand.no/objectid/1.3.14.3.2.html */
1559
16
  register_ber_oid_dissector("1.3.14.3.2.2", dissect_ber_oid_NULL_callback, proto_x509af, "md4WithRSA");
1560
16
  register_ber_oid_dissector("1.3.14.3.2.3", dissect_ber_oid_NULL_callback, proto_x509af, "md5WithRSA");
1561
16
  register_ber_oid_dissector("1.3.14.3.2.4", dissect_ber_oid_NULL_callback, proto_x509af, "md4WithRSAEncryption");
1562
16
  register_ber_oid_dissector("1.3.14.3.2.6", dissect_ber_oid_NULL_callback, proto_x509af, "desECB");
1563
16
  register_ber_oid_dissector("1.3.14.3.2.11", dissect_ber_oid_NULL_callback, proto_x509af, "rsaSignature");
1564
16
  register_ber_oid_dissector("1.3.14.3.2.14", dissect_ber_oid_NULL_callback, proto_x509af, "mdc2WithRSASignature");
1565
16
  register_ber_oid_dissector("1.3.14.3.2.15", dissect_ber_oid_NULL_callback, proto_x509af, "shaWithRSASignature");
1566
16
  register_ber_oid_dissector("1.3.14.3.2.16", dissect_ber_oid_NULL_callback, proto_x509af, "dhWithCommonModulus");
1567
16
  register_ber_oid_dissector("1.3.14.3.2.17", dissect_ber_oid_NULL_callback, proto_x509af, "desEDE");
1568
16
  register_ber_oid_dissector("1.3.14.3.2.18", dissect_ber_oid_NULL_callback, proto_x509af, "sha");
1569
16
  register_ber_oid_dissector("1.3.14.3.2.19", dissect_ber_oid_NULL_callback, proto_x509af, "mdc-2");
1570
16
  register_ber_oid_dissector("1.3.14.3.2.20", dissect_ber_oid_NULL_callback, proto_x509af, "dsaCommon");
1571
16
  register_ber_oid_dissector("1.3.14.3.2.21", dissect_ber_oid_NULL_callback, proto_x509af, "dsaCommonWithSHA");
1572
16
  register_ber_oid_dissector("1.3.14.3.2.22", dissect_ber_oid_NULL_callback, proto_x509af, "rsaKeyTransport");
1573
16
  register_ber_oid_dissector("1.3.14.3.2.23", dissect_ber_oid_NULL_callback, proto_x509af, "keyed-hash-seal");
1574
16
  register_ber_oid_dissector("1.3.14.3.2.24", dissect_ber_oid_NULL_callback, proto_x509af, "md2WithRSASignature");
1575
16
  register_ber_oid_dissector("1.3.14.3.2.25", dissect_ber_oid_NULL_callback, proto_x509af, "md5WithRSASignature");
1576
16
  register_ber_oid_dissector("1.3.14.3.2.26", dissect_ber_oid_NULL_callback, proto_x509af, "SHA-1");
1577
16
  register_ber_oid_dissector("1.3.14.3.2.27", dissect_ber_oid_NULL_callback, proto_x509af, "dsaWithSHA1");
1578
16
  register_ber_oid_dissector("1.3.14.3.2.28", dissect_ber_oid_NULL_callback, proto_x509af, "dsaWithCommonSHA1");
1579
16
  register_ber_oid_dissector("1.3.14.3.2.29", dissect_ber_oid_NULL_callback, proto_x509af, "sha-1WithRSAEncryption");
1580
1581
  /* these will generally be encoded as ";binary" in LDAP */
1582
1583
16
  dissector_add_string("ldap.name", "cACertificate", create_dissector_handle(dissect_x509af_Certificate_PDU, proto_x509af));
1584
16
  dissector_add_string("ldap.name", "userCertificate", create_dissector_handle(dissect_x509af_Certificate_PDU, proto_x509af));
1585
1586
16
  dissector_add_string("ldap.name", "certificateRevocationList", create_dissector_handle(dissect_CertificateList_PDU, proto_x509af));
1587
16
  dissector_add_string("ldap.name", "crl", create_dissector_handle(dissect_CertificateList_PDU, proto_x509af));
1588
1589
16
  dissector_add_string("ldap.name", "authorityRevocationList", create_dissector_handle(dissect_CertificateList_PDU, proto_x509af));
1590
16
  dissector_add_string("ldap.name", "arl", create_dissector_handle(dissect_CertificateList_PDU, proto_x509af));
1591
1592
16
  dissector_add_string("ldap.name", "crossCertificatePair", create_dissector_handle(dissect_CertificatePair_PDU, proto_x509af));
1593
1594
  /* RFC 7468 files */
1595
16
  dissector_add_string("rfc7468.preeb_label", "CERTIFICATE", create_dissector_handle(dissect_x509af_Certificate_PDU, proto_x509af));
1596
16
  dissector_add_string("rfc7468.preeb_label", "X509 CRL", create_dissector_handle(dissect_CertificateList_PDU, proto_x509af));
1597
16
  dissector_add_string("rfc7468.preeb_label", "ATTRIBUTE CERTIFICATE", create_dissector_handle(dissect_AttributeCertificate_PDU, proto_x509af));
1598
16
  dissector_add_string("rfc7468.preeb_label", "PUBLIC KEY", create_dissector_handle(dissect_SubjectPublicKeyInfo_PDU, proto_x509af));
1599
16
}