/src/wireshark/epan/dissectors/packet-x509af.c
Line | Count | Source |
1 | | /* Do not modify this file. Changes will be overwritten. */ |
2 | | /* Generated automatically by the ASN.1 to Wireshark dissector compiler */ |
3 | | /* packet-x509af.c */ |
4 | | /* asn2wrs.py -b -q -L -p x509af -c ./x509af.cnf -s ./packet-x509af-template -D . -O ../.. AuthenticationFramework.asn */ |
5 | | |
6 | | /* packet-x509af.c |
7 | | * Routines for X.509 Authentication Framework packet dissection |
8 | | * Ronnie Sahlberg 2004 |
9 | | * |
10 | | * Wireshark - Network traffic analyzer |
11 | | * By Gerald Combs <gerald@wireshark.org> |
12 | | * Copyright 1998 Gerald Combs |
13 | | * |
14 | | * SPDX-License-Identifier: GPL-2.0-or-later |
15 | | */ |
16 | | |
17 | | #include "config.h" |
18 | | |
19 | | #include <epan/packet.h> |
20 | | #include <epan/oids.h> |
21 | | #include <epan/asn1.h> |
22 | | #include <epan/expert.h> |
23 | | #include <epan/strutil.h> |
24 | | #include <epan/export_object.h> |
25 | | #include <epan/proto_data.h> |
26 | | #include <wsutil/array.h> |
27 | | #include <wsutil/wsgcrypt.h> |
28 | | |
29 | | #include "packet-ber.h" |
30 | | #include "packet-x509af.h" |
31 | | #include "packet-x509ce.h" |
32 | | #include "packet-x509if.h" |
33 | | #include "packet-x509sat.h" |
34 | | #include "packet-ldap.h" |
35 | | #include "packet-pkixalgs.h" |
36 | | #if defined(HAVE_LIBGNUTLS) |
37 | | #include <gnutls/gnutls.h> |
38 | | #endif |
39 | | |
40 | | void proto_register_x509af(void); |
41 | | void proto_reg_handoff_x509af(void); |
42 | | |
43 | | static dissector_handle_t pkix_crl_handle; |
44 | | |
45 | | static int x509af_eo_tap; |
46 | | |
47 | | /* Initialize the protocol and registered fields */ |
48 | | static int proto_x509af; |
49 | | static int hf_x509af_algorithm_id; |
50 | | static int hf_x509af_extension_id; |
51 | | static int hf_x509af_subjectPublicKey_dh; |
52 | | static int hf_x509af_subjectPublicKey_dsa; |
53 | | static int hf_x509af_subjectPublicKey_rsa; |
54 | | static int hf_x509af_x509af_Certificate_PDU; /* Certificate */ |
55 | | static int hf_x509af_SubjectPublicKeyInfo_PDU; /* SubjectPublicKeyInfo */ |
56 | | static int hf_x509af_CertificatePair_PDU; /* CertificatePair */ |
57 | | static int hf_x509af_CertificateList_PDU; /* CertificateList */ |
58 | | static int hf_x509af_AttributeCertificate_PDU; /* AttributeCertificate */ |
59 | | static int hf_x509af_DSS_Params_PDU; /* DSS_Params */ |
60 | | static int hf_x509af_Userid_PDU; /* Userid */ |
61 | | static int hf_x509af_signedCertificate; /* T_signedCertificate */ |
62 | | static int hf_x509af_version; /* Version */ |
63 | | static int hf_x509af_serialNumber; /* CertificateSerialNumber */ |
64 | | static int hf_x509af_signature; /* AlgorithmIdentifier */ |
65 | | static int hf_x509af_issuer; /* Name */ |
66 | | static int hf_x509af_validity; /* Validity */ |
67 | | static int hf_x509af_subject; /* SubjectName */ |
68 | | static int hf_x509af_subjectPublicKeyInfo; /* SubjectPublicKeyInfo */ |
69 | | static int hf_x509af_issuerUniqueIdentifier; /* UniqueIdentifier */ |
70 | | static int hf_x509af_subjectUniqueIdentifier; /* UniqueIdentifier */ |
71 | | static int hf_x509af_extensions; /* Extensions */ |
72 | | static int hf_x509af_algorithmIdentifier; /* AlgorithmIdentifier */ |
73 | | static int hf_x509af_encrypted; /* BIT_STRING */ |
74 | | static int hf_x509af_rdnSequence; /* RDNSequence */ |
75 | | static int hf_x509af_algorithmId; /* T_algorithmId */ |
76 | | static int hf_x509af_parameters; /* T_parameters */ |
77 | | static int hf_x509af_notBefore; /* T_notBefore */ |
78 | | static int hf_x509af_notAfter; /* T_notAfter */ |
79 | | static int hf_x509af_algorithm; /* AlgorithmIdentifier */ |
80 | | static int hf_x509af_subjectPublicKey; /* T_subjectPublicKey */ |
81 | | static int hf_x509af_utcTime; /* T_utcTime */ |
82 | | static int hf_x509af_generalizedTime; /* GeneralizedTime */ |
83 | | static int hf_x509af_Extensions_item; /* Extension */ |
84 | | static int hf_x509af_extnId; /* T_extnId */ |
85 | | static int hf_x509af_critical; /* BOOLEAN */ |
86 | | static int hf_x509af_extnValue; /* T_extnValue */ |
87 | | static int hf_x509af_userCertificate; /* Certificate */ |
88 | | static int hf_x509af_certificationPath; /* ForwardCertificationPath */ |
89 | | static int hf_x509af_ForwardCertificationPath_item; /* CrossCertificates */ |
90 | | static int hf_x509af_CrossCertificates_item; /* Certificate */ |
91 | | static int hf_x509af_theCACertificates; /* SEQUENCE_OF_CertificatePair */ |
92 | | static int hf_x509af_theCACertificates_item; /* CertificatePair */ |
93 | | static int hf_x509af_issuedByThisCA; /* Certificate */ |
94 | | static int hf_x509af_issuedToThisCA; /* Certificate */ |
95 | | static int hf_x509af_signedCertificateList; /* T_signedCertificateList */ |
96 | | static int hf_x509af_thisUpdate; /* Time */ |
97 | | static int hf_x509af_nextUpdate; /* Time */ |
98 | | static int hf_x509af_revokedCertificates; /* T_revokedCertificates */ |
99 | | static int hf_x509af_revokedCertificates_item; /* T_revokedCertificates_item */ |
100 | | static int hf_x509af_revokedUserCertificate; /* CertificateSerialNumber */ |
101 | | static int hf_x509af_revocationDate; /* Time */ |
102 | | static int hf_x509af_crlEntryExtensions; /* Extensions */ |
103 | | static int hf_x509af_crlExtensions; /* Extensions */ |
104 | | static int hf_x509af_attributeCertificate; /* AttributeCertificate */ |
105 | | static int hf_x509af_acPath; /* SEQUENCE_OF_ACPathData */ |
106 | | static int hf_x509af_acPath_item; /* ACPathData */ |
107 | | static int hf_x509af_certificate; /* Certificate */ |
108 | | static int hf_x509af_signedAttributeCertificateInfo; /* AttributeCertificateInfo */ |
109 | | static int hf_x509af_info_subject; /* InfoSubject */ |
110 | | static int hf_x509af_baseCertificateID; /* IssuerSerial */ |
111 | | static int hf_x509af_infoSubjectName; /* GeneralNames */ |
112 | | static int hf_x509af_issuerName; /* GeneralNames */ |
113 | | static int hf_x509af_attCertValidityPeriod; /* AttCertValidityPeriod */ |
114 | | static int hf_x509af_attributes; /* SEQUENCE_OF_Attribute */ |
115 | | static int hf_x509af_attributes_item; /* Attribute */ |
116 | | static int hf_x509af_issuerUniqueID; /* UniqueIdentifier */ |
117 | | static int hf_x509af_serial; /* CertificateSerialNumber */ |
118 | | static int hf_x509af_issuerUID; /* UniqueIdentifier */ |
119 | | static int hf_x509af_notBeforeTime; /* GeneralizedTime */ |
120 | | static int hf_x509af_notAfterTime; /* GeneralizedTime */ |
121 | | static int hf_x509af_assertion_subject; /* AssertionSubject */ |
122 | | static int hf_x509af_assertionSubjectName; /* SubjectName */ |
123 | | static int hf_x509af_assertionIssuer; /* Name */ |
124 | | static int hf_x509af_attCertValidity; /* GeneralizedTime */ |
125 | | static int hf_x509af_attType; /* SET_OF_AttributeType */ |
126 | | static int hf_x509af_attType_item; /* AttributeType */ |
127 | | static int hf_x509af_p; /* INTEGER */ |
128 | | static int hf_x509af_q; /* INTEGER */ |
129 | | static int hf_x509af_g; /* INTEGER */ |
130 | | |
131 | | /* Initialize the subtree pointers */ |
132 | | static int ett_pkix_crl; |
133 | | static int ett_x509af_SubjectPublicKey; |
134 | | static int ett_x509af_Certificate; |
135 | | static int ett_x509af_T_signedCertificate; |
136 | | static int ett_x509af_SubjectName; |
137 | | static int ett_x509af_AlgorithmIdentifier; |
138 | | static int ett_x509af_Validity; |
139 | | static int ett_x509af_SubjectPublicKeyInfo; |
140 | | static int ett_x509af_Time; |
141 | | static int ett_x509af_Extensions; |
142 | | static int ett_x509af_Extension; |
143 | | static int ett_x509af_Certificates; |
144 | | static int ett_x509af_ForwardCertificationPath; |
145 | | static int ett_x509af_CrossCertificates; |
146 | | static int ett_x509af_CertificationPath; |
147 | | static int ett_x509af_SEQUENCE_OF_CertificatePair; |
148 | | static int ett_x509af_CertificatePair; |
149 | | static int ett_x509af_CertificateList; |
150 | | static int ett_x509af_T_signedCertificateList; |
151 | | static int ett_x509af_T_revokedCertificates; |
152 | | static int ett_x509af_T_revokedCertificates_item; |
153 | | static int ett_x509af_AttributeCertificationPath; |
154 | | static int ett_x509af_SEQUENCE_OF_ACPathData; |
155 | | static int ett_x509af_ACPathData; |
156 | | static int ett_x509af_AttributeCertificate; |
157 | | static int ett_x509af_AttributeCertificateInfo; |
158 | | static int ett_x509af_InfoSubject; |
159 | | static int ett_x509af_SEQUENCE_OF_Attribute; |
160 | | static int ett_x509af_IssuerSerial; |
161 | | static int ett_x509af_AttCertValidityPeriod; |
162 | | static int ett_x509af_AttributeCertificateAssertion; |
163 | | static int ett_x509af_AssertionSubject; |
164 | | static int ett_x509af_SET_OF_AttributeType; |
165 | | static int ett_x509af_DSS_Params; |
166 | | |
167 | | static expert_field ei_x509af_certificate_invalid; |
168 | | |
169 | | static const char *algorithm_id; |
170 | | static void |
171 | | x509af_export_publickey(tvbuff_t *tvb, asn1_ctx_t *actx, int offset, int len); |
172 | | |
173 | | /* proto_data keys */ |
174 | 82 | #define X509AF_EO_INFO_KEY 0 |
175 | 655 | #define X509AF_PRIVATE_DATA_KEY 1 |
176 | | |
177 | | typedef struct _x509af_eo_t { |
178 | | const char *subjectname; |
179 | | tvbuff_t *payload; |
180 | | } x509af_eo_t; |
181 | | |
182 | | typedef struct _x509af_private_data_t { |
183 | | nstime_t last_time; |
184 | | nstime_t not_before; |
185 | | nstime_t not_after; |
186 | | #if 0 |
187 | | // TODO: Move static global algorithm_id here. |
188 | | // (Why is the algorithm_id string wmem_file_scope()? That makes |
189 | | // no sense as a global common to all conversations.) |
190 | | const char *algorithm_id; |
191 | | #endif |
192 | | } x509af_private_data_t; |
193 | | |
194 | | static x509af_private_data_t * |
195 | | x509af_get_private_data(packet_info *pinfo) |
196 | 534 | { |
197 | 534 | x509af_private_data_t *x509af_data = (x509af_private_data_t*)p_get_proto_data(pinfo->pool, pinfo, proto_x509af, X509AF_PRIVATE_DATA_KEY); |
198 | 534 | if (!x509af_data) { |
199 | 121 | x509af_data = wmem_new0(pinfo->pool, x509af_private_data_t); |
200 | 121 | nstime_set_unset(&x509af_data->not_before); |
201 | 121 | nstime_set_unset(&x509af_data->not_after); |
202 | 121 | p_add_proto_data(pinfo->pool, pinfo, proto_x509af, X509AF_PRIVATE_DATA_KEY, x509af_data); |
203 | 121 | } |
204 | 534 | return x509af_data; |
205 | 534 | } |
206 | | |
207 | | |
208 | | const value_string x509af_Version_vals[] = { |
209 | | { 0, "v1" }, |
210 | | { 1, "v2" }, |
211 | | { 2, "v3" }, |
212 | | { 0, NULL } |
213 | | }; |
214 | | |
215 | | |
216 | | unsigned |
217 | 7 | dissect_x509af_Version(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
218 | 7 | offset = dissect_ber_integer(implicit_tag, actx, tree, tvb, offset, hf_index, |
219 | 7 | NULL); |
220 | | |
221 | 7 | return offset; |
222 | 7 | } |
223 | | |
224 | | |
225 | | |
226 | | unsigned |
227 | 21 | dissect_x509af_CertificateSerialNumber(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
228 | 21 | offset = dissect_ber_integer64(implicit_tag, actx, tree, tvb, offset, hf_index, |
229 | 21 | NULL); |
230 | | |
231 | 21 | return offset; |
232 | 21 | } |
233 | | |
234 | | |
235 | | |
236 | | static unsigned |
237 | 8.71k | dissect_x509af_T_algorithmId(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
238 | 8.71k | const char *name; |
239 | | |
240 | 8.71k | offset = dissect_ber_object_identifier_str(implicit_tag, actx, tree, tvb, offset, hf_x509af_algorithm_id, &actx->external.direct_reference); |
241 | | |
242 | | |
243 | 8.71k | if(actx->external.direct_reference) { |
244 | 8.71k | algorithm_id = (const char *)wmem_strdup(wmem_file_scope(), actx->external.direct_reference); |
245 | | |
246 | 8.71k | name = oid_resolved_from_string(actx->pinfo->pool, actx->external.direct_reference); |
247 | | |
248 | 8.71k | proto_item_append_text(tree, " (%s)", name ? name : actx->external.direct_reference); |
249 | 8.71k | } |
250 | | |
251 | | |
252 | 8.71k | return offset; |
253 | 8.71k | } |
254 | | |
255 | | |
256 | | |
257 | | static unsigned |
258 | 8.70k | dissect_x509af_T_parameters(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
259 | 8.70k | offset=call_ber_oid_callback(actx->external.direct_reference, tvb, offset, actx->pinfo, tree, NULL); |
260 | | |
261 | | |
262 | 8.70k | return offset; |
263 | 8.70k | } |
264 | | |
265 | | |
266 | | static const ber_sequence_t AlgorithmIdentifier_sequence[] = { |
267 | | { &hf_x509af_algorithmId , BER_CLASS_UNI, BER_UNI_TAG_OID, BER_FLAGS_NOOWNTAG, dissect_x509af_T_algorithmId }, |
268 | | { &hf_x509af_parameters , BER_CLASS_ANY, 0, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_T_parameters }, |
269 | | { NULL, 0, 0, 0, NULL } |
270 | | }; |
271 | | |
272 | | unsigned |
273 | 8.76k | dissect_x509af_AlgorithmIdentifier(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
274 | 8.76k | if (algorithm_id) { |
275 | 8.71k | wmem_free(wmem_file_scope(), (void*)algorithm_id); |
276 | 8.71k | algorithm_id = NULL; |
277 | 8.71k | } |
278 | | |
279 | 8.76k | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
280 | 8.76k | AlgorithmIdentifier_sequence, hf_index, ett_x509af_AlgorithmIdentifier); |
281 | | |
282 | 8.76k | return offset; |
283 | 8.76k | } |
284 | | |
285 | | |
286 | | |
287 | | static unsigned |
288 | 54 | dissect_x509af_T_utcTime(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
289 | 54 | char *outstr, *newstr; |
290 | 54 | int old_offset = offset; |
291 | | |
292 | 54 | x509af_private_data_t *x509af_data = x509af_get_private_data(actx->pinfo); |
293 | | |
294 | | /* the 2-digit year can only be in the range 1950..2049 https://tools.ietf.org/html/rfc5280#section-4.1.2.5.1 */ |
295 | 54 | offset = dissect_ber_UTCTime(implicit_tag, actx, tree, tvb, offset, -1, &outstr, NULL); |
296 | | |
297 | 54 | if (hf_index > 0 && outstr) { |
298 | 0 | nstime_t time_val; |
299 | 0 | newstr = wmem_strconcat(actx->pinfo->pool, outstr[0] < '5' ? "20": "19", outstr, NULL); |
300 | |
|
301 | 0 | iso8601_to_nstime(&time_val, newstr, ISO8601_DATETIME_AUTO); |
302 | | |
303 | | /* move past TLV */ |
304 | 0 | old_offset = get_ber_identifier(tvb, old_offset, NULL, NULL, NULL); |
305 | 0 | old_offset = get_ber_length(tvb, old_offset, NULL, NULL); |
306 | |
|
307 | 0 | proto_tree_add_time(tree, hf_index, tvb, old_offset, offset - old_offset, &time_val); |
308 | |
|
309 | 0 | nstime_copy(&x509af_data->last_time, &time_val); |
310 | 0 | } |
311 | | |
312 | | |
313 | 54 | return offset; |
314 | 54 | } |
315 | | |
316 | | |
317 | | |
318 | | static unsigned |
319 | 66 | dissect_x509af_GeneralizedTime(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
320 | 66 | offset = dissect_ber_GeneralizedTime(implicit_tag, actx, tree, tvb, offset, hf_index); |
321 | | |
322 | 66 | return offset; |
323 | 66 | } |
324 | | |
325 | | |
326 | | const value_string x509af_Time_vals[] = { |
327 | | { 0, "utcTime" }, |
328 | | { 1, "generalizedTime" }, |
329 | | { 0, NULL } |
330 | | }; |
331 | | |
332 | | static const ber_choice_t Time_choice[] = { |
333 | | { 0, &hf_x509af_utcTime , BER_CLASS_UNI, BER_UNI_TAG_UTCTime, BER_FLAGS_NOOWNTAG, dissect_x509af_T_utcTime }, |
334 | | { 1, &hf_x509af_generalizedTime, BER_CLASS_UNI, BER_UNI_TAG_GeneralizedTime, BER_FLAGS_NOOWNTAG, dissect_x509af_GeneralizedTime }, |
335 | | { 0, NULL, 0, 0, 0, NULL } |
336 | | }; |
337 | | |
338 | | unsigned |
339 | 255 | dissect_x509af_Time(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
340 | 255 | x509af_private_data_t *x509af_data = x509af_get_private_data(actx->pinfo); |
341 | 255 | nstime_set_unset(&x509af_data->last_time); |
342 | | |
343 | 255 | offset = dissect_ber_choice(actx, tree, tvb, offset, |
344 | 255 | Time_choice, hf_index, ett_x509af_Time, |
345 | 255 | NULL); |
346 | | |
347 | 255 | return offset; |
348 | 255 | } |
349 | | |
350 | | |
351 | | |
352 | | static unsigned |
353 | 136 | dissect_x509af_T_notBefore(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
354 | 136 | offset = dissect_x509af_Time(implicit_tag, tvb, offset, actx, tree, hf_index); |
355 | | |
356 | 136 | x509af_private_data_t *x509af_data = x509af_get_private_data(actx->pinfo); |
357 | 136 | nstime_copy(&x509af_data->not_before, &x509af_data->last_time); |
358 | | |
359 | 136 | return offset; |
360 | 136 | } |
361 | | |
362 | | |
363 | | |
364 | | static unsigned |
365 | 111 | dissect_x509af_T_notAfter(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
366 | 111 | offset = dissect_x509af_Time(implicit_tag, tvb, offset, actx, tree, hf_index); |
367 | | |
368 | 111 | x509af_private_data_t *x509af_data = x509af_get_private_data(actx->pinfo); |
369 | 111 | nstime_copy(&x509af_data->not_after, &x509af_data->last_time); |
370 | 111 | if (actx->pinfo->presence_flags & PINFO_HAS_TS && |
371 | 109 | !nstime_is_unset(&x509af_data->not_before) && |
372 | 0 | !nstime_is_unset(&x509af_data->not_after)) { |
373 | |
|
374 | 0 | if (nstime_cmp(&x509af_data->not_before, &x509af_data->not_after) > 0) { |
375 | 0 | expert_add_info_format(actx->pinfo, proto_tree_get_parent(tree), &ei_x509af_certificate_invalid, "Invalid certificate (notBefore time is after notAfter time)"); |
376 | 0 | } else if ((nstime_cmp(&x509af_data->not_before, &actx->pinfo->abs_ts) > 0) || (nstime_cmp(&actx->pinfo->abs_ts, &x509af_data->not_after) > 0)) { |
377 | 0 | expert_add_info_format(actx->pinfo, proto_tree_get_parent(tree), &ei_x509af_certificate_invalid, "Invalid certificate (frame arrival time %s not in valid interval)", abs_time_to_str(actx->pinfo->pool, &actx->pinfo->abs_ts, ABSOLUTE_TIME_UTC, true)); |
378 | 0 | } |
379 | 0 | } |
380 | | |
381 | 111 | return offset; |
382 | 111 | } |
383 | | |
384 | | |
385 | | static const ber_sequence_t Validity_sequence[] = { |
386 | | { &hf_x509af_notBefore , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_T_notBefore }, |
387 | | { &hf_x509af_notAfter , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_T_notAfter }, |
388 | | { NULL, 0, 0, 0, NULL } |
389 | | }; |
390 | | |
391 | | unsigned |
392 | 142 | dissect_x509af_Validity(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
393 | 142 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
394 | 142 | Validity_sequence, hf_index, ett_x509af_Validity); |
395 | | |
396 | 142 | return offset; |
397 | 142 | } |
398 | | |
399 | | |
400 | | static const value_string x509af_SubjectName_vals[] = { |
401 | | { 0, "rdnSequence" }, |
402 | | { 0, NULL } |
403 | | }; |
404 | | |
405 | | static const ber_choice_t SubjectName_choice[] = { |
406 | | { 0, &hf_x509af_rdnSequence , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509if_RDNSequence }, |
407 | | { 0, NULL, 0, 0, 0, NULL } |
408 | | }; |
409 | | |
410 | | static unsigned |
411 | 82 | dissect_x509af_SubjectName(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
412 | | |
413 | 82 | const char* str; |
414 | 82 | offset = dissect_ber_choice(actx, tree, tvb, offset, |
415 | 82 | SubjectName_choice, hf_index, ett_x509af_SubjectName, |
416 | 82 | NULL); |
417 | | |
418 | | |
419 | 82 | str = x509if_get_last_dn(); |
420 | 82 | proto_item_append_text(proto_item_get_parent(tree), " (%s)", str?str:""); |
421 | 82 | x509af_eo_t *eo_info = p_get_proto_data(actx->pinfo->pool, actx->pinfo, proto_x509af, X509AF_EO_INFO_KEY); |
422 | 82 | if (eo_info) { |
423 | 0 | eo_info->subjectname = str; |
424 | 0 | } |
425 | | |
426 | | |
427 | 82 | return offset; |
428 | 82 | } |
429 | | |
430 | | |
431 | | |
432 | | static unsigned |
433 | 8 | dissect_x509af_T_subjectPublicKey(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
434 | 8 | tvbuff_t *bs_tvb = NULL; |
435 | | |
436 | 8 | offset = dissect_ber_bitstring(false, actx, tree, tvb, offset, |
437 | 8 | NULL, 0, hf_index, -1, &bs_tvb); |
438 | | |
439 | | /* See RFC 3279 for possible subjectPublicKey values given an Algorithm ID. |
440 | | * The contents of subjectPublicKey are always explicitly tagged. */ |
441 | 8 | if (bs_tvb && !g_strcmp0(algorithm_id, "1.2.840.113549.1.1.1")) { /* id-rsa */ |
442 | 0 | proto_tree *subtree = proto_item_add_subtree(actx->created_item, ett_x509af_SubjectPublicKey); |
443 | 0 | dissect_pkixalgs_RSAPublicKey(false, bs_tvb, 0, actx, subtree, hf_x509af_subjectPublicKey_rsa); |
444 | |
|
445 | 8 | } else if (bs_tvb && !g_strcmp0(algorithm_id, "1.2.840.10040.4.1")) { /* id-dsa */ |
446 | 0 | proto_tree *subtree = proto_item_add_subtree(actx->created_item, ett_x509af_SubjectPublicKey); |
447 | 0 | dissect_pkixalgs_DSAPublicKey(false, bs_tvb, 0, actx, subtree, hf_x509af_subjectPublicKey_dsa); |
448 | |
|
449 | 8 | } else if (bs_tvb && !g_strcmp0(algorithm_id, "1.2.840.10046.2.1")) { /* dhpublicnumber */ |
450 | 0 | proto_tree *subtree = proto_item_add_subtree(actx->created_item, ett_x509af_SubjectPublicKey); |
451 | 0 | dissect_pkixalgs_DHPublicKey(false, bs_tvb, 0, actx, subtree, hf_x509af_subjectPublicKey_dh); |
452 | |
|
453 | 0 | } |
454 | | |
455 | | |
456 | 8 | return offset; |
457 | 8 | } |
458 | | |
459 | | |
460 | | static const ber_sequence_t SubjectPublicKeyInfo_sequence[] = { |
461 | | { &hf_x509af_algorithm , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier }, |
462 | | { &hf_x509af_subjectPublicKey, BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_NOOWNTAG, dissect_x509af_T_subjectPublicKey }, |
463 | | { NULL, 0, 0, 0, NULL } |
464 | | }; |
465 | | |
466 | | unsigned |
467 | 73 | dissect_x509af_SubjectPublicKeyInfo(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
468 | 73 | int orig_offset = offset; |
469 | 73 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
470 | 73 | SubjectPublicKeyInfo_sequence, hf_index, ett_x509af_SubjectPublicKeyInfo); |
471 | | |
472 | 73 | x509af_export_publickey(tvb, actx, orig_offset, offset - orig_offset); |
473 | 73 | return offset; |
474 | 73 | } |
475 | | |
476 | | |
477 | | |
478 | | static unsigned |
479 | 0 | dissect_x509af_T_extnId(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
480 | 0 | const char *name; |
481 | |
|
482 | 0 | offset = dissect_ber_object_identifier_str(implicit_tag, actx, tree, tvb, offset, hf_x509af_extension_id, &actx->external.direct_reference); |
483 | | |
484 | |
|
485 | 0 | if(actx->external.direct_reference) { |
486 | 0 | name = oid_resolved_from_string(actx->pinfo->pool, actx->external.direct_reference); |
487 | |
|
488 | 0 | proto_item_append_text(tree, " (%s)", name ? name : actx->external.direct_reference); |
489 | 0 | } |
490 | | |
491 | |
|
492 | 0 | return offset; |
493 | 0 | } |
494 | | |
495 | | |
496 | | |
497 | | static unsigned |
498 | 0 | dissect_x509af_BOOLEAN(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
499 | 0 | offset = dissect_ber_boolean(implicit_tag, actx, tree, tvb, offset, hf_index, NULL); |
500 | |
|
501 | 0 | return offset; |
502 | 0 | } |
503 | | |
504 | | |
505 | | |
506 | | static unsigned |
507 | 0 | dissect_x509af_T_extnValue(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
508 | 0 | int8_t ber_class; |
509 | 0 | bool pc, ind; |
510 | 0 | int32_t tag; |
511 | 0 | uint32_t len; |
512 | | /* skip past the T and L */ |
513 | 0 | offset = dissect_ber_identifier(actx->pinfo, tree, tvb, offset, &ber_class, &pc, &tag); |
514 | 0 | offset = dissect_ber_length(actx->pinfo, tree, tvb, offset, &len, &ind); |
515 | 0 | offset=call_ber_oid_callback(actx->external.direct_reference, tvb, offset, actx->pinfo, tree, NULL); |
516 | | |
517 | |
|
518 | 0 | return offset; |
519 | 0 | } |
520 | | |
521 | | |
522 | | static const ber_sequence_t Extension_sequence[] = { |
523 | | { &hf_x509af_extnId , BER_CLASS_UNI, BER_UNI_TAG_OID, BER_FLAGS_NOOWNTAG, dissect_x509af_T_extnId }, |
524 | | { &hf_x509af_critical , BER_CLASS_UNI, BER_UNI_TAG_BOOLEAN, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_BOOLEAN }, |
525 | | { &hf_x509af_extnValue , BER_CLASS_UNI, BER_UNI_TAG_OCTETSTRING, BER_FLAGS_NOOWNTAG, dissect_x509af_T_extnValue }, |
526 | | { NULL, 0, 0, 0, NULL } |
527 | | }; |
528 | | |
529 | | unsigned |
530 | 0 | dissect_x509af_Extension(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
531 | 0 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
532 | 0 | Extension_sequence, hf_index, ett_x509af_Extension); |
533 | |
|
534 | 0 | return offset; |
535 | 0 | } |
536 | | |
537 | | |
538 | | static const ber_sequence_t Extensions_sequence_of[1] = { |
539 | | { &hf_x509af_Extensions_item, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_Extension }, |
540 | | }; |
541 | | |
542 | | unsigned |
543 | 12 | dissect_x509af_Extensions(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
544 | 12 | offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset, |
545 | 12 | Extensions_sequence_of, hf_index, ett_x509af_Extensions); |
546 | | |
547 | 12 | return offset; |
548 | 12 | } |
549 | | |
550 | | |
551 | | static const ber_sequence_t T_signedCertificate_sequence[] = { |
552 | | { &hf_x509af_version , BER_CLASS_CON, 0, BER_FLAGS_OPTIONAL, dissect_x509af_Version }, |
553 | | { &hf_x509af_serialNumber , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_CertificateSerialNumber }, |
554 | | { &hf_x509af_signature , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier }, |
555 | | { &hf_x509af_issuer , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG, dissect_x509if_Name }, |
556 | | { &hf_x509af_validity , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_Validity }, |
557 | | { &hf_x509af_subject , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_SubjectName }, |
558 | | { &hf_x509af_subjectPublicKeyInfo, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_SubjectPublicKeyInfo }, |
559 | | { &hf_x509af_issuerUniqueIdentifier, BER_CLASS_CON, 1, BER_FLAGS_OPTIONAL|BER_FLAGS_IMPLTAG, dissect_x509sat_UniqueIdentifier }, |
560 | | { &hf_x509af_subjectUniqueIdentifier, BER_CLASS_CON, 2, BER_FLAGS_OPTIONAL|BER_FLAGS_IMPLTAG, dissect_x509sat_UniqueIdentifier }, |
561 | | { &hf_x509af_extensions , BER_CLASS_CON, 3, BER_FLAGS_OPTIONAL, dissect_x509af_Extensions }, |
562 | | { NULL, 0, 0, 0, NULL } |
563 | | }; |
564 | | |
565 | | static unsigned |
566 | 307 | dissect_x509af_T_signedCertificate(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
567 | 307 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
568 | 307 | T_signedCertificate_sequence, hf_index, ett_x509af_T_signedCertificate); |
569 | | |
570 | 307 | return offset; |
571 | 307 | } |
572 | | |
573 | | |
574 | | |
575 | | static unsigned |
576 | 21 | dissect_x509af_BIT_STRING(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
577 | 21 | offset = dissect_ber_bitstring(implicit_tag, actx, tree, tvb, offset, |
578 | 21 | NULL, 0, hf_index, -1, |
579 | 21 | NULL); |
580 | | |
581 | 21 | return offset; |
582 | 21 | } |
583 | | |
584 | | |
585 | | static const ber_sequence_t Certificate_sequence[] = { |
586 | | { &hf_x509af_signedCertificate, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_T_signedCertificate }, |
587 | | { &hf_x509af_algorithmIdentifier, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier }, |
588 | | { &hf_x509af_encrypted , BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_NOOWNTAG, dissect_x509af_BIT_STRING }, |
589 | | { NULL, 0, 0, 0, NULL } |
590 | | }; |
591 | | |
592 | | unsigned |
593 | 9.46k | dissect_x509af_Certificate(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
594 | 9.46k | int start_offset = offset; |
595 | 9.46k | x509af_eo_t *eo_info = NULL; |
596 | 9.46k | if (have_tap_listener(x509af_eo_tap)) { |
597 | 0 | eo_info = wmem_new0(actx->pinfo->pool, x509af_eo_t); |
598 | 0 | p_add_proto_data(actx->pinfo->pool, actx->pinfo, proto_x509af, X509AF_EO_INFO_KEY, eo_info); |
599 | 0 | } |
600 | | |
601 | 9.46k | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
602 | 9.46k | Certificate_sequence, hf_index, ett_x509af_Certificate); |
603 | | |
604 | | |
605 | 9.46k | if (eo_info) { |
606 | 0 | eo_info->payload = tvb_new_subset_length(tvb, start_offset, offset - start_offset); |
607 | 0 | tap_queue_packet(x509af_eo_tap, actx->pinfo, eo_info); |
608 | 0 | } |
609 | | |
610 | | |
611 | 9.46k | return offset; |
612 | 9.46k | } |
613 | | |
614 | | |
615 | | static const ber_sequence_t CrossCertificates_set_of[1] = { |
616 | | { &hf_x509af_CrossCertificates_item, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_Certificate }, |
617 | | }; |
618 | | |
619 | | unsigned |
620 | 0 | dissect_x509af_CrossCertificates(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
621 | 0 | offset = dissect_ber_set_of(implicit_tag, actx, tree, tvb, offset, |
622 | 0 | CrossCertificates_set_of, hf_index, ett_x509af_CrossCertificates); |
623 | |
|
624 | 0 | return offset; |
625 | 0 | } |
626 | | |
627 | | |
628 | | static const ber_sequence_t ForwardCertificationPath_sequence_of[1] = { |
629 | | { &hf_x509af_ForwardCertificationPath_item, BER_CLASS_UNI, BER_UNI_TAG_SET, BER_FLAGS_NOOWNTAG, dissect_x509af_CrossCertificates }, |
630 | | }; |
631 | | |
632 | | unsigned |
633 | 0 | dissect_x509af_ForwardCertificationPath(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
634 | 0 | offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset, |
635 | 0 | ForwardCertificationPath_sequence_of, hf_index, ett_x509af_ForwardCertificationPath); |
636 | |
|
637 | 0 | return offset; |
638 | 0 | } |
639 | | |
640 | | |
641 | | static const ber_sequence_t Certificates_sequence[] = { |
642 | | { &hf_x509af_userCertificate, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_Certificate }, |
643 | | { &hf_x509af_certificationPath, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_ForwardCertificationPath }, |
644 | | { NULL, 0, 0, 0, NULL } |
645 | | }; |
646 | | |
647 | | unsigned |
648 | 0 | dissect_x509af_Certificates(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
649 | 0 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
650 | 0 | Certificates_sequence, hf_index, ett_x509af_Certificates); |
651 | |
|
652 | 0 | return offset; |
653 | 0 | } |
654 | | |
655 | | |
656 | | static const ber_sequence_t CertificatePair_sequence[] = { |
657 | | { &hf_x509af_issuedByThisCA, BER_CLASS_CON, 0, BER_FLAGS_OPTIONAL, dissect_x509af_Certificate }, |
658 | | { &hf_x509af_issuedToThisCA, BER_CLASS_CON, 1, BER_FLAGS_OPTIONAL, dissect_x509af_Certificate }, |
659 | | { NULL, 0, 0, 0, NULL } |
660 | | }; |
661 | | |
662 | | unsigned |
663 | 0 | dissect_x509af_CertificatePair(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
664 | 0 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
665 | 0 | CertificatePair_sequence, hf_index, ett_x509af_CertificatePair); |
666 | |
|
667 | 0 | return offset; |
668 | 0 | } |
669 | | |
670 | | |
671 | | static const ber_sequence_t SEQUENCE_OF_CertificatePair_sequence_of[1] = { |
672 | | { &hf_x509af_theCACertificates_item, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_CertificatePair }, |
673 | | }; |
674 | | |
675 | | static unsigned |
676 | 0 | dissect_x509af_SEQUENCE_OF_CertificatePair(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
677 | 0 | offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset, |
678 | 0 | SEQUENCE_OF_CertificatePair_sequence_of, hf_index, ett_x509af_SEQUENCE_OF_CertificatePair); |
679 | |
|
680 | 0 | return offset; |
681 | 0 | } |
682 | | |
683 | | |
684 | | static const ber_sequence_t CertificationPath_sequence[] = { |
685 | | { &hf_x509af_userCertificate, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_Certificate }, |
686 | | { &hf_x509af_theCACertificates, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_SEQUENCE_OF_CertificatePair }, |
687 | | { NULL, 0, 0, 0, NULL } |
688 | | }; |
689 | | |
690 | | unsigned |
691 | 0 | dissect_x509af_CertificationPath(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
692 | 0 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
693 | 0 | CertificationPath_sequence, hf_index, ett_x509af_CertificationPath); |
694 | |
|
695 | 0 | return offset; |
696 | 0 | } |
697 | | |
698 | | |
699 | | static const ber_sequence_t T_revokedCertificates_item_sequence[] = { |
700 | | { &hf_x509af_revokedUserCertificate, BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_CertificateSerialNumber }, |
701 | | { &hf_x509af_revocationDate, BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_Time }, |
702 | | { &hf_x509af_crlEntryExtensions, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_Extensions }, |
703 | | { NULL, 0, 0, 0, NULL } |
704 | | }; |
705 | | |
706 | | static unsigned |
707 | 1 | dissect_x509af_T_revokedCertificates_item(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
708 | 1 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
709 | 1 | T_revokedCertificates_item_sequence, hf_index, ett_x509af_T_revokedCertificates_item); |
710 | | |
711 | 1 | return offset; |
712 | 1 | } |
713 | | |
714 | | |
715 | | static const ber_sequence_t T_revokedCertificates_sequence_of[1] = { |
716 | | { &hf_x509af_revokedCertificates_item, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_T_revokedCertificates_item }, |
717 | | }; |
718 | | |
719 | | static unsigned |
720 | 1 | dissect_x509af_T_revokedCertificates(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
721 | 1 | offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset, |
722 | 1 | T_revokedCertificates_sequence_of, hf_index, ett_x509af_T_revokedCertificates); |
723 | | |
724 | 1 | return offset; |
725 | 1 | } |
726 | | |
727 | | |
728 | | static const ber_sequence_t T_signedCertificateList_sequence[] = { |
729 | | { &hf_x509af_version , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_Version }, |
730 | | { &hf_x509af_signature , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier }, |
731 | | { &hf_x509af_issuer , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG, dissect_x509if_Name }, |
732 | | { &hf_x509af_thisUpdate , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_Time }, |
733 | | { &hf_x509af_nextUpdate , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_Time }, |
734 | | { &hf_x509af_revokedCertificates, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_T_revokedCertificates }, |
735 | | { &hf_x509af_crlExtensions, BER_CLASS_CON, 0, BER_FLAGS_OPTIONAL, dissect_x509af_Extensions }, |
736 | | { NULL, 0, 0, 0, NULL } |
737 | | }; |
738 | | |
739 | | static unsigned |
740 | 3 | dissect_x509af_T_signedCertificateList(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
741 | 3 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
742 | 3 | T_signedCertificateList_sequence, hf_index, ett_x509af_T_signedCertificateList); |
743 | | |
744 | 3 | return offset; |
745 | 3 | } |
746 | | |
747 | | |
748 | | static const ber_sequence_t CertificateList_sequence[] = { |
749 | | { &hf_x509af_signedCertificateList, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_T_signedCertificateList }, |
750 | | { &hf_x509af_algorithmIdentifier, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier }, |
751 | | { &hf_x509af_encrypted , BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_NOOWNTAG, dissect_x509af_BIT_STRING }, |
752 | | { NULL, 0, 0, 0, NULL } |
753 | | }; |
754 | | |
755 | | unsigned |
756 | 4 | dissect_x509af_CertificateList(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
757 | 4 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
758 | 4 | CertificateList_sequence, hf_index, ett_x509af_CertificateList); |
759 | | |
760 | 4 | return offset; |
761 | 4 | } |
762 | | |
763 | | |
764 | | static const ber_sequence_t IssuerSerial_sequence[] = { |
765 | | { &hf_x509af_issuerName , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509ce_GeneralNames }, |
766 | | { &hf_x509af_serial , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_CertificateSerialNumber }, |
767 | | { &hf_x509af_issuerUID , BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509sat_UniqueIdentifier }, |
768 | | { NULL, 0, 0, 0, NULL } |
769 | | }; |
770 | | |
771 | | unsigned |
772 | 0 | dissect_x509af_IssuerSerial(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
773 | 0 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
774 | 0 | IssuerSerial_sequence, hf_index, ett_x509af_IssuerSerial); |
775 | |
|
776 | 0 | return offset; |
777 | 0 | } |
778 | | |
779 | | |
780 | | static const value_string x509af_InfoSubject_vals[] = { |
781 | | { 0, "baseCertificateID" }, |
782 | | { 1, "subjectName" }, |
783 | | { 0, NULL } |
784 | | }; |
785 | | |
786 | | static const ber_choice_t InfoSubject_choice[] = { |
787 | | { 0, &hf_x509af_baseCertificateID, BER_CLASS_CON, 0, 0, dissect_x509af_IssuerSerial }, |
788 | | { 1, &hf_x509af_infoSubjectName, BER_CLASS_CON, 1, 0, dissect_x509ce_GeneralNames }, |
789 | | { 0, NULL, 0, 0, 0, NULL } |
790 | | }; |
791 | | |
792 | | static unsigned |
793 | 33 | dissect_x509af_InfoSubject(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
794 | 33 | offset = dissect_ber_choice(actx, tree, tvb, offset, |
795 | 33 | InfoSubject_choice, hf_index, ett_x509af_InfoSubject, |
796 | 33 | NULL); |
797 | | |
798 | 33 | return offset; |
799 | 33 | } |
800 | | |
801 | | |
802 | | static const ber_sequence_t AttCertValidityPeriod_sequence[] = { |
803 | | { &hf_x509af_notBeforeTime, BER_CLASS_UNI, BER_UNI_TAG_GeneralizedTime, BER_FLAGS_NOOWNTAG, dissect_x509af_GeneralizedTime }, |
804 | | { &hf_x509af_notAfterTime , BER_CLASS_UNI, BER_UNI_TAG_GeneralizedTime, BER_FLAGS_NOOWNTAG, dissect_x509af_GeneralizedTime }, |
805 | | { NULL, 0, 0, 0, NULL } |
806 | | }; |
807 | | |
808 | | unsigned |
809 | 0 | dissect_x509af_AttCertValidityPeriod(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
810 | 0 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
811 | 0 | AttCertValidityPeriod_sequence, hf_index, ett_x509af_AttCertValidityPeriod); |
812 | |
|
813 | 0 | return offset; |
814 | 0 | } |
815 | | |
816 | | |
817 | | static const ber_sequence_t SEQUENCE_OF_Attribute_sequence_of[1] = { |
818 | | { &hf_x509af_attributes_item, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509if_Attribute }, |
819 | | }; |
820 | | |
821 | | static unsigned |
822 | 3 | dissect_x509af_SEQUENCE_OF_Attribute(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
823 | 3 | offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset, |
824 | 3 | SEQUENCE_OF_Attribute_sequence_of, hf_index, ett_x509af_SEQUENCE_OF_Attribute); |
825 | | |
826 | 3 | return offset; |
827 | 3 | } |
828 | | |
829 | | |
830 | | static const ber_sequence_t AttributeCertificateInfo_sequence[] = { |
831 | | { &hf_x509af_version , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_Version }, |
832 | | { &hf_x509af_info_subject , BER_CLASS_ANY/*choice*/, -1/*choice*/, BER_FLAGS_NOOWNTAG|BER_FLAGS_NOTCHKTAG, dissect_x509af_InfoSubject }, |
833 | | { &hf_x509af_issuerName , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509ce_GeneralNames }, |
834 | | { &hf_x509af_signature , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier }, |
835 | | { &hf_x509af_serialNumber , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_CertificateSerialNumber }, |
836 | | { &hf_x509af_attCertValidityPeriod, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AttCertValidityPeriod }, |
837 | | { &hf_x509af_attributes , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_SEQUENCE_OF_Attribute }, |
838 | | { &hf_x509af_issuerUniqueID, BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509sat_UniqueIdentifier }, |
839 | | { &hf_x509af_extensions , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_Extensions }, |
840 | | { NULL, 0, 0, 0, NULL } |
841 | | }; |
842 | | |
843 | | unsigned |
844 | 33 | dissect_x509af_AttributeCertificateInfo(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
845 | 33 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
846 | 33 | AttributeCertificateInfo_sequence, hf_index, ett_x509af_AttributeCertificateInfo); |
847 | | |
848 | 33 | return offset; |
849 | 33 | } |
850 | | |
851 | | |
852 | | static const ber_sequence_t AttributeCertificate_sequence[] = { |
853 | | { &hf_x509af_signedAttributeCertificateInfo, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AttributeCertificateInfo }, |
854 | | { &hf_x509af_algorithmIdentifier, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AlgorithmIdentifier }, |
855 | | { &hf_x509af_encrypted , BER_CLASS_UNI, BER_UNI_TAG_BITSTRING, BER_FLAGS_NOOWNTAG, dissect_x509af_BIT_STRING }, |
856 | | { NULL, 0, 0, 0, NULL } |
857 | | }; |
858 | | |
859 | | unsigned |
860 | 33 | dissect_x509af_AttributeCertificate(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
861 | 33 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
862 | 33 | AttributeCertificate_sequence, hf_index, ett_x509af_AttributeCertificate); |
863 | | |
864 | 33 | return offset; |
865 | 33 | } |
866 | | |
867 | | |
868 | | static const ber_sequence_t ACPathData_sequence[] = { |
869 | | { &hf_x509af_certificate , BER_CLASS_CON, 0, BER_FLAGS_OPTIONAL, dissect_x509af_Certificate }, |
870 | | { &hf_x509af_attributeCertificate, BER_CLASS_CON, 1, BER_FLAGS_OPTIONAL, dissect_x509af_AttributeCertificate }, |
871 | | { NULL, 0, 0, 0, NULL } |
872 | | }; |
873 | | |
874 | | unsigned |
875 | 0 | dissect_x509af_ACPathData(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
876 | 0 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
877 | 0 | ACPathData_sequence, hf_index, ett_x509af_ACPathData); |
878 | |
|
879 | 0 | return offset; |
880 | 0 | } |
881 | | |
882 | | |
883 | | static const ber_sequence_t SEQUENCE_OF_ACPathData_sequence_of[1] = { |
884 | | { &hf_x509af_acPath_item , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_ACPathData }, |
885 | | }; |
886 | | |
887 | | static unsigned |
888 | 0 | dissect_x509af_SEQUENCE_OF_ACPathData(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
889 | 0 | offset = dissect_ber_sequence_of(implicit_tag, actx, tree, tvb, offset, |
890 | 0 | SEQUENCE_OF_ACPathData_sequence_of, hf_index, ett_x509af_SEQUENCE_OF_ACPathData); |
891 | |
|
892 | 0 | return offset; |
893 | 0 | } |
894 | | |
895 | | |
896 | | static const ber_sequence_t AttributeCertificationPath_sequence[] = { |
897 | | { &hf_x509af_attributeCertificate, BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_NOOWNTAG, dissect_x509af_AttributeCertificate }, |
898 | | { &hf_x509af_acPath , BER_CLASS_UNI, BER_UNI_TAG_SEQUENCE, BER_FLAGS_OPTIONAL|BER_FLAGS_NOOWNTAG, dissect_x509af_SEQUENCE_OF_ACPathData }, |
899 | | { NULL, 0, 0, 0, NULL } |
900 | | }; |
901 | | |
902 | | unsigned |
903 | 0 | dissect_x509af_AttributeCertificationPath(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
904 | 0 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
905 | 0 | AttributeCertificationPath_sequence, hf_index, ett_x509af_AttributeCertificationPath); |
906 | |
|
907 | 0 | return offset; |
908 | 0 | } |
909 | | |
910 | | |
911 | | static const value_string x509af_AssertionSubject_vals[] = { |
912 | | { 0, "baseCertificateID" }, |
913 | | { 1, "subjectName" }, |
914 | | { 0, NULL } |
915 | | }; |
916 | | |
917 | | static const ber_choice_t AssertionSubject_choice[] = { |
918 | | { 0, &hf_x509af_baseCertificateID, BER_CLASS_CON, 0, 0, dissect_x509af_IssuerSerial }, |
919 | | { 1, &hf_x509af_assertionSubjectName, BER_CLASS_CON, 1, 0, dissect_x509af_SubjectName }, |
920 | | { 0, NULL, 0, 0, 0, NULL } |
921 | | }; |
922 | | |
923 | | static unsigned |
924 | 0 | dissect_x509af_AssertionSubject(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
925 | 0 | offset = dissect_ber_choice(actx, tree, tvb, offset, |
926 | 0 | AssertionSubject_choice, hf_index, ett_x509af_AssertionSubject, |
927 | 0 | NULL); |
928 | |
|
929 | 0 | return offset; |
930 | 0 | } |
931 | | |
932 | | |
933 | | static const ber_sequence_t SET_OF_AttributeType_set_of[1] = { |
934 | | { &hf_x509af_attType_item , BER_CLASS_UNI, BER_UNI_TAG_OID, BER_FLAGS_NOOWNTAG, dissect_x509if_AttributeType }, |
935 | | }; |
936 | | |
937 | | static unsigned |
938 | 0 | dissect_x509af_SET_OF_AttributeType(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
939 | 0 | offset = dissect_ber_set_of(implicit_tag, actx, tree, tvb, offset, |
940 | 0 | SET_OF_AttributeType_set_of, hf_index, ett_x509af_SET_OF_AttributeType); |
941 | |
|
942 | 0 | return offset; |
943 | 0 | } |
944 | | |
945 | | |
946 | | static const ber_sequence_t AttributeCertificateAssertion_sequence[] = { |
947 | | { &hf_x509af_assertion_subject, BER_CLASS_CON, 0, BER_FLAGS_OPTIONAL, dissect_x509af_AssertionSubject }, |
948 | | { &hf_x509af_assertionIssuer, BER_CLASS_CON, 1, BER_FLAGS_OPTIONAL, dissect_x509if_Name }, |
949 | | { &hf_x509af_attCertValidity, BER_CLASS_CON, 2, BER_FLAGS_OPTIONAL, dissect_x509af_GeneralizedTime }, |
950 | | { &hf_x509af_attType , BER_CLASS_CON, 3, BER_FLAGS_OPTIONAL, dissect_x509af_SET_OF_AttributeType }, |
951 | | { NULL, 0, 0, 0, NULL } |
952 | | }; |
953 | | |
954 | | unsigned |
955 | 0 | dissect_x509af_AttributeCertificateAssertion(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
956 | 0 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
957 | 0 | AttributeCertificateAssertion_sequence, hf_index, ett_x509af_AttributeCertificateAssertion); |
958 | |
|
959 | 0 | return offset; |
960 | 0 | } |
961 | | |
962 | | |
963 | | |
964 | | static unsigned |
965 | 0 | dissect_x509af_INTEGER(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
966 | 0 | offset = dissect_ber_integer(implicit_tag, actx, tree, tvb, offset, hf_index, |
967 | 0 | NULL); |
968 | |
|
969 | 0 | return offset; |
970 | 0 | } |
971 | | |
972 | | |
973 | | static const ber_sequence_t DSS_Params_sequence[] = { |
974 | | { &hf_x509af_p , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_INTEGER }, |
975 | | { &hf_x509af_q , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_INTEGER }, |
976 | | { &hf_x509af_g , BER_CLASS_UNI, BER_UNI_TAG_INTEGER, BER_FLAGS_NOOWNTAG, dissect_x509af_INTEGER }, |
977 | | { NULL, 0, 0, 0, NULL } |
978 | | }; |
979 | | |
980 | | static unsigned |
981 | 0 | dissect_x509af_DSS_Params(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
982 | 0 | offset = dissect_ber_sequence(implicit_tag, actx, tree, tvb, offset, |
983 | 0 | DSS_Params_sequence, hf_index, ett_x509af_DSS_Params); |
984 | |
|
985 | 0 | return offset; |
986 | 0 | } |
987 | | |
988 | | |
989 | | |
990 | | static unsigned |
991 | 0 | dissect_x509af_Userid(bool implicit_tag _U_, tvbuff_t *tvb _U_, unsigned offset _U_, asn1_ctx_t *actx _U_, proto_tree *tree _U_, int hf_index _U_) { |
992 | 0 | offset = dissect_ber_constrained_restricted_string(implicit_tag, BER_UNI_TAG_UTF8String, |
993 | 0 | actx, tree, tvb, offset, |
994 | 0 | 1, ub_user_identifier, hf_index, NULL); |
995 | |
|
996 | 0 | return offset; |
997 | 0 | } |
998 | | |
999 | | /*--- PDUs ---*/ |
1000 | | |
1001 | 3 | int dissect_x509af_Certificate_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) { |
1002 | 3 | unsigned offset = 0; |
1003 | 3 | asn1_ctx_t asn1_ctx; |
1004 | 3 | asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo); |
1005 | 3 | offset = dissect_x509af_Certificate(false, tvb, offset, &asn1_ctx, tree, hf_x509af_x509af_Certificate_PDU); |
1006 | 3 | return offset; |
1007 | 3 | } |
1008 | 0 | static int dissect_SubjectPublicKeyInfo_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) { |
1009 | 0 | unsigned offset = 0; |
1010 | 0 | asn1_ctx_t asn1_ctx; |
1011 | 0 | asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo); |
1012 | 0 | offset = dissect_x509af_SubjectPublicKeyInfo(false, tvb, offset, &asn1_ctx, tree, hf_x509af_SubjectPublicKeyInfo_PDU); |
1013 | 0 | return offset; |
1014 | 0 | } |
1015 | 0 | static int dissect_CertificatePair_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) { |
1016 | 0 | unsigned offset = 0; |
1017 | 0 | asn1_ctx_t asn1_ctx; |
1018 | 0 | asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo); |
1019 | 0 | offset = dissect_x509af_CertificatePair(false, tvb, offset, &asn1_ctx, tree, hf_x509af_CertificatePair_PDU); |
1020 | 0 | return offset; |
1021 | 0 | } |
1022 | 4 | static int dissect_CertificateList_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) { |
1023 | 4 | unsigned offset = 0; |
1024 | 4 | asn1_ctx_t asn1_ctx; |
1025 | 4 | asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo); |
1026 | 4 | offset = dissect_x509af_CertificateList(false, tvb, offset, &asn1_ctx, tree, hf_x509af_CertificateList_PDU); |
1027 | 4 | return offset; |
1028 | 4 | } |
1029 | 33 | static int dissect_AttributeCertificate_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) { |
1030 | 33 | unsigned offset = 0; |
1031 | 33 | asn1_ctx_t asn1_ctx; |
1032 | 33 | asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo); |
1033 | 33 | offset = dissect_x509af_AttributeCertificate(false, tvb, offset, &asn1_ctx, tree, hf_x509af_AttributeCertificate_PDU); |
1034 | 33 | return offset; |
1035 | 33 | } |
1036 | 0 | static int dissect_DSS_Params_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) { |
1037 | 0 | unsigned offset = 0; |
1038 | 0 | asn1_ctx_t asn1_ctx; |
1039 | 0 | asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo); |
1040 | 0 | offset = dissect_x509af_DSS_Params(false, tvb, offset, &asn1_ctx, tree, hf_x509af_DSS_Params_PDU); |
1041 | 0 | return offset; |
1042 | 0 | } |
1043 | 0 | static int dissect_Userid_PDU(tvbuff_t *tvb _U_, packet_info *pinfo _U_, proto_tree *tree _U_, void *data _U_) { |
1044 | 0 | unsigned offset = 0; |
1045 | 0 | asn1_ctx_t asn1_ctx; |
1046 | 0 | asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo); |
1047 | 0 | offset = dissect_x509af_Userid(false, tvb, offset, &asn1_ctx, tree, hf_x509af_Userid_PDU); |
1048 | 0 | return offset; |
1049 | 0 | } |
1050 | | |
1051 | | |
1052 | | static tap_packet_status |
1053 | | x509af_eo_packet(void *tapdata, packet_info *pinfo, epan_dissect_t *edt _U_, const void *data, tap_flags_t flags _U_) |
1054 | 0 | { |
1055 | 0 | export_object_list_t *object_list = (export_object_list_t *)tapdata; |
1056 | 0 | const x509af_eo_t *eo_info = (const x509af_eo_t *)data; |
1057 | 0 | export_object_entry_t *entry; |
1058 | |
|
1059 | 0 | if (data) { |
1060 | 0 | entry = g_new0(export_object_entry_t, 1); |
1061 | |
|
1062 | 0 | entry->pkt_num = pinfo->num; |
1063 | | |
1064 | | // There should be a commonName |
1065 | 0 | const char *name = eo_info->subjectname ? strstr(eo_info->subjectname, "id-at-commonName=") : NULL; |
1066 | 0 | if (name) { |
1067 | 0 | name += strlen("id-at-commonName="); |
1068 | 0 | entry->hostname = g_strndup(name, strcspn(name, ",")); |
1069 | 0 | } |
1070 | 0 | entry->content_type = g_strdup("application/pkix-cert"); |
1071 | |
|
1072 | 0 | entry->payload_len = tvb_captured_length(eo_info->payload); |
1073 | 0 | entry->payload_data = (uint8_t *)tvb_memdup(NULL, eo_info->payload, 0, entry->payload_len); |
1074 | |
|
1075 | 0 | uint8_t sha256sum[HASH_SHA2_256_LENGTH] = {0}; |
1076 | 0 | gcry_md_hash_buffer(GCRY_MD_SHA256, sha256sum, entry->payload_data, entry->payload_len); |
1077 | 0 | entry->filename = g_strdup_printf("%s.cer", bytes_to_str(pinfo->pool, sha256sum, HASH_SHA2_256_LENGTH)); |
1078 | |
|
1079 | 0 | object_list->add_entry(object_list->gui_data, entry); |
1080 | |
|
1081 | 0 | return TAP_PACKET_REDRAW; |
1082 | 0 | } else { |
1083 | 0 | return TAP_PACKET_DONT_REDRAW; |
1084 | 0 | } |
1085 | 0 | } |
1086 | | |
1087 | | /* Exports the SubjectPublicKeyInfo structure as gnutls_datum_t. |
1088 | | * actx->private_data is assumed to be a gnutls_datum_t pointer which will be |
1089 | | * filled in if non-NULL. */ |
1090 | | static void |
1091 | | x509af_export_publickey(tvbuff_t *tvb _U_, asn1_ctx_t *actx _U_, int offset _U_, int len _U_) |
1092 | 63 | { |
1093 | | #if defined(HAVE_LIBGNUTLS) |
1094 | | gnutls_datum_t *subjectPublicKeyInfo = (gnutls_datum_t *)actx->private_data; |
1095 | | if (subjectPublicKeyInfo) { |
1096 | | /* This is only passed to ssh_find_private_key_by_pubkey, which uses it |
1097 | | * with gnutls_pubkey_import, which treats the data as const, so this |
1098 | | * cast is acceptable. */ |
1099 | | subjectPublicKeyInfo->data = (unsigned char *) tvb_get_ptr(tvb, offset, len); |
1100 | | subjectPublicKeyInfo->size = len; |
1101 | | actx->private_data = NULL; |
1102 | | } |
1103 | | #endif |
1104 | 63 | } |
1105 | | |
1106 | 0 | const char *x509af_get_last_algorithm_id(void) { |
1107 | 0 | return algorithm_id; |
1108 | 0 | } |
1109 | | |
1110 | | |
1111 | | static int |
1112 | | dissect_pkix_crl(tvbuff_t *tvb, packet_info *pinfo, proto_tree *parent_tree, void *data _U_) |
1113 | 0 | { |
1114 | 0 | proto_tree *tree; |
1115 | 0 | asn1_ctx_t asn1_ctx; |
1116 | 0 | asn1_ctx_init(&asn1_ctx, ASN1_ENC_BER, true, pinfo); |
1117 | |
|
1118 | 0 | col_set_str(pinfo->cinfo, COL_PROTOCOL, "PKIX-CRL"); |
1119 | |
|
1120 | 0 | col_set_str(pinfo->cinfo, COL_INFO, "Certificate Revocation List"); |
1121 | | |
1122 | |
|
1123 | 0 | tree=proto_tree_add_subtree(parent_tree, tvb, 0, -1, ett_pkix_crl, NULL, "Certificate Revocation List"); |
1124 | |
|
1125 | 0 | return dissect_x509af_CertificateList(false, tvb, 0, &asn1_ctx, tree, -1); |
1126 | 0 | } |
1127 | | |
1128 | | static void |
1129 | | x509af_cleanup_protocol(void) |
1130 | 0 | { |
1131 | 0 | algorithm_id = NULL; |
1132 | 0 | } |
1133 | | |
1134 | | /*--- proto_register_x509af ----------------------------------------------*/ |
1135 | 16 | void proto_register_x509af(void) { |
1136 | | |
1137 | | /* List of fields */ |
1138 | 16 | static hf_register_info hf[] = { |
1139 | 16 | { &hf_x509af_algorithm_id, |
1140 | 16 | { "Algorithm Id", "x509af.algorithm.id", |
1141 | 16 | FT_OID, BASE_NONE, NULL, 0, |
1142 | 16 | NULL, HFILL }}, |
1143 | 16 | { &hf_x509af_extension_id, |
1144 | 16 | { "Extension Id", "x509af.extension.id", |
1145 | 16 | FT_OID, BASE_NONE, NULL, 0, |
1146 | 16 | NULL, HFILL }}, |
1147 | 16 | { &hf_x509af_subjectPublicKey_dh, |
1148 | 16 | { "DH Public Key", "x509af.subjectPublicKey.dh", |
1149 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1150 | 16 | NULL, HFILL }}, |
1151 | 16 | { &hf_x509af_subjectPublicKey_dsa, |
1152 | 16 | { "DSA Public Key", "x509af.subjectPublicKey.dsa", |
1153 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1154 | 16 | NULL, HFILL }}, |
1155 | 16 | { &hf_x509af_subjectPublicKey_rsa, |
1156 | 16 | { "RSA Public Key", "x509af.subjectPublicKey.rsa", |
1157 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1158 | 16 | NULL, HFILL }}, |
1159 | 16 | { &hf_x509af_x509af_Certificate_PDU, |
1160 | 16 | { "Certificate", "x509af.Certificate_element", |
1161 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1162 | 16 | NULL, HFILL }}, |
1163 | 16 | { &hf_x509af_SubjectPublicKeyInfo_PDU, |
1164 | 16 | { "SubjectPublicKeyInfo", "x509af.SubjectPublicKeyInfo_element", |
1165 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1166 | 16 | NULL, HFILL }}, |
1167 | 16 | { &hf_x509af_CertificatePair_PDU, |
1168 | 16 | { "CertificatePair", "x509af.CertificatePair_element", |
1169 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1170 | 16 | NULL, HFILL }}, |
1171 | 16 | { &hf_x509af_CertificateList_PDU, |
1172 | 16 | { "CertificateList", "x509af.CertificateList_element", |
1173 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1174 | 16 | NULL, HFILL }}, |
1175 | 16 | { &hf_x509af_AttributeCertificate_PDU, |
1176 | 16 | { "AttributeCertificate", "x509af.AttributeCertificate_element", |
1177 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1178 | 16 | NULL, HFILL }}, |
1179 | 16 | { &hf_x509af_DSS_Params_PDU, |
1180 | 16 | { "DSS-Params", "x509af.DSS_Params_element", |
1181 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1182 | 16 | NULL, HFILL }}, |
1183 | 16 | { &hf_x509af_Userid_PDU, |
1184 | 16 | { "Userid", "x509af.Userid", |
1185 | 16 | FT_STRING, BASE_NONE, NULL, 0, |
1186 | 16 | NULL, HFILL }}, |
1187 | 16 | { &hf_x509af_signedCertificate, |
1188 | 16 | { "signedCertificate", "x509af.signedCertificate_element", |
1189 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1190 | 16 | NULL, HFILL }}, |
1191 | 16 | { &hf_x509af_version, |
1192 | 16 | { "version", "x509af.version", |
1193 | 16 | FT_INT32, BASE_DEC, VALS(x509af_Version_vals), 0, |
1194 | 16 | NULL, HFILL }}, |
1195 | 16 | { &hf_x509af_serialNumber, |
1196 | 16 | { "serialNumber", "x509af.serialNumber", |
1197 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1198 | 16 | "CertificateSerialNumber", HFILL }}, |
1199 | 16 | { &hf_x509af_signature, |
1200 | 16 | { "signature", "x509af.signature_element", |
1201 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1202 | 16 | "AlgorithmIdentifier", HFILL }}, |
1203 | 16 | { &hf_x509af_issuer, |
1204 | 16 | { "issuer", "x509af.issuer", |
1205 | 16 | FT_UINT32, BASE_DEC, VALS(x509if_Name_vals), 0, |
1206 | 16 | "Name", HFILL }}, |
1207 | 16 | { &hf_x509af_validity, |
1208 | 16 | { "validity", "x509af.validity_element", |
1209 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1210 | 16 | NULL, HFILL }}, |
1211 | 16 | { &hf_x509af_subject, |
1212 | 16 | { "subject", "x509af.subject", |
1213 | 16 | FT_UINT32, BASE_DEC, VALS(x509af_SubjectName_vals), 0, |
1214 | 16 | "SubjectName", HFILL }}, |
1215 | 16 | { &hf_x509af_subjectPublicKeyInfo, |
1216 | 16 | { "subjectPublicKeyInfo", "x509af.subjectPublicKeyInfo_element", |
1217 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1218 | 16 | NULL, HFILL }}, |
1219 | 16 | { &hf_x509af_issuerUniqueIdentifier, |
1220 | 16 | { "issuerUniqueIdentifier", "x509af.issuerUniqueIdentifier", |
1221 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1222 | 16 | "UniqueIdentifier", HFILL }}, |
1223 | 16 | { &hf_x509af_subjectUniqueIdentifier, |
1224 | 16 | { "subjectUniqueIdentifier", "x509af.subjectUniqueIdentifier", |
1225 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1226 | 16 | "UniqueIdentifier", HFILL }}, |
1227 | 16 | { &hf_x509af_extensions, |
1228 | 16 | { "extensions", "x509af.extensions", |
1229 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1230 | 16 | NULL, HFILL }}, |
1231 | 16 | { &hf_x509af_algorithmIdentifier, |
1232 | 16 | { "algorithmIdentifier", "x509af.algorithmIdentifier_element", |
1233 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1234 | 16 | NULL, HFILL }}, |
1235 | 16 | { &hf_x509af_encrypted, |
1236 | 16 | { "encrypted", "x509af.encrypted", |
1237 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1238 | 16 | "BIT_STRING", HFILL }}, |
1239 | 16 | { &hf_x509af_rdnSequence, |
1240 | 16 | { "rdnSequence", "x509af.rdnSequence", |
1241 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1242 | 16 | NULL, HFILL }}, |
1243 | 16 | { &hf_x509af_algorithmId, |
1244 | 16 | { "algorithmId", "x509af.algorithmId", |
1245 | 16 | FT_OID, BASE_NONE, NULL, 0, |
1246 | 16 | NULL, HFILL }}, |
1247 | 16 | { &hf_x509af_parameters, |
1248 | 16 | { "parameters", "x509af.parameters_element", |
1249 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1250 | 16 | NULL, HFILL }}, |
1251 | 16 | { &hf_x509af_notBefore, |
1252 | 16 | { "notBefore", "x509af.notBefore", |
1253 | 16 | FT_UINT32, BASE_DEC, VALS(x509af_Time_vals), 0, |
1254 | 16 | NULL, HFILL }}, |
1255 | 16 | { &hf_x509af_notAfter, |
1256 | 16 | { "notAfter", "x509af.notAfter", |
1257 | 16 | FT_UINT32, BASE_DEC, VALS(x509af_Time_vals), 0, |
1258 | 16 | NULL, HFILL }}, |
1259 | 16 | { &hf_x509af_algorithm, |
1260 | 16 | { "algorithm", "x509af.algorithm_element", |
1261 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1262 | 16 | "AlgorithmIdentifier", HFILL }}, |
1263 | 16 | { &hf_x509af_subjectPublicKey, |
1264 | 16 | { "subjectPublicKey", "x509af.subjectPublicKey", |
1265 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1266 | 16 | NULL, HFILL }}, |
1267 | 16 | { &hf_x509af_utcTime, |
1268 | 16 | { "utcTime", "x509af.utcTime", |
1269 | 16 | FT_ABSOLUTE_TIME, ABSOLUTE_TIME_UTC, NULL, 0, |
1270 | 16 | NULL, HFILL }}, |
1271 | 16 | { &hf_x509af_generalizedTime, |
1272 | 16 | { "generalizedTime", "x509af.generalizedTime", |
1273 | 16 | FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0, |
1274 | 16 | NULL, HFILL }}, |
1275 | 16 | { &hf_x509af_Extensions_item, |
1276 | 16 | { "Extension", "x509af.Extension_element", |
1277 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1278 | 16 | NULL, HFILL }}, |
1279 | 16 | { &hf_x509af_extnId, |
1280 | 16 | { "extnId", "x509af.extnId", |
1281 | 16 | FT_OID, BASE_NONE, NULL, 0, |
1282 | 16 | NULL, HFILL }}, |
1283 | 16 | { &hf_x509af_critical, |
1284 | 16 | { "critical", "x509af.critical", |
1285 | 16 | FT_BOOLEAN, BASE_NONE, NULL, 0, |
1286 | 16 | "BOOLEAN", HFILL }}, |
1287 | 16 | { &hf_x509af_extnValue, |
1288 | 16 | { "extnValue", "x509af.extnValue", |
1289 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1290 | 16 | NULL, HFILL }}, |
1291 | 16 | { &hf_x509af_userCertificate, |
1292 | 16 | { "userCertificate", "x509af.userCertificate_element", |
1293 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1294 | 16 | "Certificate", HFILL }}, |
1295 | 16 | { &hf_x509af_certificationPath, |
1296 | 16 | { "certificationPath", "x509af.certificationPath", |
1297 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1298 | 16 | "ForwardCertificationPath", HFILL }}, |
1299 | 16 | { &hf_x509af_ForwardCertificationPath_item, |
1300 | 16 | { "CrossCertificates", "x509af.CrossCertificates", |
1301 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1302 | 16 | NULL, HFILL }}, |
1303 | 16 | { &hf_x509af_CrossCertificates_item, |
1304 | 16 | { "Certificate", "x509af.Certificate_element", |
1305 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1306 | 16 | NULL, HFILL }}, |
1307 | 16 | { &hf_x509af_theCACertificates, |
1308 | 16 | { "theCACertificates", "x509af.theCACertificates", |
1309 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1310 | 16 | "SEQUENCE_OF_CertificatePair", HFILL }}, |
1311 | 16 | { &hf_x509af_theCACertificates_item, |
1312 | 16 | { "CertificatePair", "x509af.CertificatePair_element", |
1313 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1314 | 16 | NULL, HFILL }}, |
1315 | 16 | { &hf_x509af_issuedByThisCA, |
1316 | 16 | { "issuedByThisCA", "x509af.issuedByThisCA_element", |
1317 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1318 | 16 | "Certificate", HFILL }}, |
1319 | 16 | { &hf_x509af_issuedToThisCA, |
1320 | 16 | { "issuedToThisCA", "x509af.issuedToThisCA_element", |
1321 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1322 | 16 | "Certificate", HFILL }}, |
1323 | 16 | { &hf_x509af_signedCertificateList, |
1324 | 16 | { "signedCertificateList", "x509af.signedCertificateList_element", |
1325 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1326 | 16 | NULL, HFILL }}, |
1327 | 16 | { &hf_x509af_thisUpdate, |
1328 | 16 | { "thisUpdate", "x509af.thisUpdate", |
1329 | 16 | FT_UINT32, BASE_DEC, VALS(x509af_Time_vals), 0, |
1330 | 16 | "Time", HFILL }}, |
1331 | 16 | { &hf_x509af_nextUpdate, |
1332 | 16 | { "nextUpdate", "x509af.nextUpdate", |
1333 | 16 | FT_UINT32, BASE_DEC, VALS(x509af_Time_vals), 0, |
1334 | 16 | "Time", HFILL }}, |
1335 | 16 | { &hf_x509af_revokedCertificates, |
1336 | 16 | { "revokedCertificates", "x509af.revokedCertificates", |
1337 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1338 | 16 | NULL, HFILL }}, |
1339 | 16 | { &hf_x509af_revokedCertificates_item, |
1340 | 16 | { "revokedCertificates item", "x509af.revokedCertificates_item_element", |
1341 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1342 | 16 | NULL, HFILL }}, |
1343 | 16 | { &hf_x509af_revokedUserCertificate, |
1344 | 16 | { "userCertificate", "x509af.revokedUserCertificate", |
1345 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1346 | 16 | "CertificateSerialNumber", HFILL }}, |
1347 | 16 | { &hf_x509af_revocationDate, |
1348 | 16 | { "revocationDate", "x509af.revocationDate", |
1349 | 16 | FT_UINT32, BASE_DEC, VALS(x509af_Time_vals), 0, |
1350 | 16 | "Time", HFILL }}, |
1351 | 16 | { &hf_x509af_crlEntryExtensions, |
1352 | 16 | { "crlEntryExtensions", "x509af.crlEntryExtensions", |
1353 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1354 | 16 | "Extensions", HFILL }}, |
1355 | 16 | { &hf_x509af_crlExtensions, |
1356 | 16 | { "crlExtensions", "x509af.crlExtensions", |
1357 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1358 | 16 | "Extensions", HFILL }}, |
1359 | 16 | { &hf_x509af_attributeCertificate, |
1360 | 16 | { "attributeCertificate", "x509af.attributeCertificate_element", |
1361 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1362 | 16 | NULL, HFILL }}, |
1363 | 16 | { &hf_x509af_acPath, |
1364 | 16 | { "acPath", "x509af.acPath", |
1365 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1366 | 16 | "SEQUENCE_OF_ACPathData", HFILL }}, |
1367 | 16 | { &hf_x509af_acPath_item, |
1368 | 16 | { "ACPathData", "x509af.ACPathData_element", |
1369 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1370 | 16 | NULL, HFILL }}, |
1371 | 16 | { &hf_x509af_certificate, |
1372 | 16 | { "certificate", "x509af.certificate_element", |
1373 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1374 | 16 | NULL, HFILL }}, |
1375 | 16 | { &hf_x509af_signedAttributeCertificateInfo, |
1376 | 16 | { "signedAttributeCertificateInfo", "x509af.signedAttributeCertificateInfo_element", |
1377 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1378 | 16 | "AttributeCertificateInfo", HFILL }}, |
1379 | 16 | { &hf_x509af_info_subject, |
1380 | 16 | { "subject", "x509af.info_subject", |
1381 | 16 | FT_UINT32, BASE_DEC, VALS(x509af_InfoSubject_vals), 0, |
1382 | 16 | "InfoSubject", HFILL }}, |
1383 | 16 | { &hf_x509af_baseCertificateID, |
1384 | 16 | { "baseCertificateID", "x509af.baseCertificateID_element", |
1385 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1386 | 16 | "IssuerSerial", HFILL }}, |
1387 | 16 | { &hf_x509af_infoSubjectName, |
1388 | 16 | { "subjectName", "x509af.infoSubjectName", |
1389 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1390 | 16 | "GeneralNames", HFILL }}, |
1391 | 16 | { &hf_x509af_issuerName, |
1392 | 16 | { "issuer", "x509af.issuerName", |
1393 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1394 | 16 | "GeneralNames", HFILL }}, |
1395 | 16 | { &hf_x509af_attCertValidityPeriod, |
1396 | 16 | { "attCertValidityPeriod", "x509af.attCertValidityPeriod_element", |
1397 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1398 | 16 | NULL, HFILL }}, |
1399 | 16 | { &hf_x509af_attributes, |
1400 | 16 | { "attributes", "x509af.attributes", |
1401 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1402 | 16 | "SEQUENCE_OF_Attribute", HFILL }}, |
1403 | 16 | { &hf_x509af_attributes_item, |
1404 | 16 | { "Attribute", "x509af.Attribute_element", |
1405 | 16 | FT_NONE, BASE_NONE, NULL, 0, |
1406 | 16 | NULL, HFILL }}, |
1407 | 16 | { &hf_x509af_issuerUniqueID, |
1408 | 16 | { "issuerUniqueID", "x509af.issuerUniqueID", |
1409 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1410 | 16 | "UniqueIdentifier", HFILL }}, |
1411 | 16 | { &hf_x509af_serial, |
1412 | 16 | { "serial", "x509af.serial", |
1413 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1414 | 16 | "CertificateSerialNumber", HFILL }}, |
1415 | 16 | { &hf_x509af_issuerUID, |
1416 | 16 | { "issuerUID", "x509af.issuerUID", |
1417 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1418 | 16 | "UniqueIdentifier", HFILL }}, |
1419 | 16 | { &hf_x509af_notBeforeTime, |
1420 | 16 | { "notBeforeTime", "x509af.notBeforeTime", |
1421 | 16 | FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0, |
1422 | 16 | "GeneralizedTime", HFILL }}, |
1423 | 16 | { &hf_x509af_notAfterTime, |
1424 | 16 | { "notAfterTime", "x509af.notAfterTime", |
1425 | 16 | FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0, |
1426 | 16 | "GeneralizedTime", HFILL }}, |
1427 | 16 | { &hf_x509af_assertion_subject, |
1428 | 16 | { "subject", "x509af.assertion_subject", |
1429 | 16 | FT_UINT32, BASE_DEC, VALS(x509af_AssertionSubject_vals), 0, |
1430 | 16 | "AssertionSubject", HFILL }}, |
1431 | 16 | { &hf_x509af_assertionSubjectName, |
1432 | 16 | { "subjectName", "x509af.assertionSubjectName", |
1433 | 16 | FT_UINT32, BASE_DEC, VALS(x509af_SubjectName_vals), 0, |
1434 | 16 | NULL, HFILL }}, |
1435 | 16 | { &hf_x509af_assertionIssuer, |
1436 | 16 | { "issuer", "x509af.assertionIssuer", |
1437 | 16 | FT_UINT32, BASE_DEC, VALS(x509if_Name_vals), 0, |
1438 | 16 | "Name", HFILL }}, |
1439 | 16 | { &hf_x509af_attCertValidity, |
1440 | 16 | { "attCertValidity", "x509af.attCertValidity", |
1441 | 16 | FT_ABSOLUTE_TIME, ABSOLUTE_TIME_LOCAL, NULL, 0, |
1442 | 16 | "GeneralizedTime", HFILL }}, |
1443 | 16 | { &hf_x509af_attType, |
1444 | 16 | { "attType", "x509af.attType", |
1445 | 16 | FT_UINT32, BASE_DEC, NULL, 0, |
1446 | 16 | "SET_OF_AttributeType", HFILL }}, |
1447 | 16 | { &hf_x509af_attType_item, |
1448 | 16 | { "AttributeType", "x509af.AttributeType", |
1449 | 16 | FT_OID, BASE_NONE, NULL, 0, |
1450 | 16 | NULL, HFILL }}, |
1451 | 16 | { &hf_x509af_p, |
1452 | 16 | { "p", "x509af.p", |
1453 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1454 | 16 | "INTEGER", HFILL }}, |
1455 | 16 | { &hf_x509af_q, |
1456 | 16 | { "q", "x509af.q", |
1457 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1458 | 16 | "INTEGER", HFILL }}, |
1459 | 16 | { &hf_x509af_g, |
1460 | 16 | { "g", "x509af.g", |
1461 | 16 | FT_BYTES, BASE_NONE, NULL, 0, |
1462 | 16 | "INTEGER", HFILL }}, |
1463 | 16 | }; |
1464 | | |
1465 | | /* List of subtrees */ |
1466 | 16 | static int *ett[] = { |
1467 | 16 | &ett_pkix_crl, |
1468 | 16 | &ett_x509af_SubjectPublicKey, |
1469 | 16 | &ett_x509af_Certificate, |
1470 | 16 | &ett_x509af_T_signedCertificate, |
1471 | 16 | &ett_x509af_SubjectName, |
1472 | 16 | &ett_x509af_AlgorithmIdentifier, |
1473 | 16 | &ett_x509af_Validity, |
1474 | 16 | &ett_x509af_SubjectPublicKeyInfo, |
1475 | 16 | &ett_x509af_Time, |
1476 | 16 | &ett_x509af_Extensions, |
1477 | 16 | &ett_x509af_Extension, |
1478 | 16 | &ett_x509af_Certificates, |
1479 | 16 | &ett_x509af_ForwardCertificationPath, |
1480 | 16 | &ett_x509af_CrossCertificates, |
1481 | 16 | &ett_x509af_CertificationPath, |
1482 | 16 | &ett_x509af_SEQUENCE_OF_CertificatePair, |
1483 | 16 | &ett_x509af_CertificatePair, |
1484 | 16 | &ett_x509af_CertificateList, |
1485 | 16 | &ett_x509af_T_signedCertificateList, |
1486 | 16 | &ett_x509af_T_revokedCertificates, |
1487 | 16 | &ett_x509af_T_revokedCertificates_item, |
1488 | 16 | &ett_x509af_AttributeCertificationPath, |
1489 | 16 | &ett_x509af_SEQUENCE_OF_ACPathData, |
1490 | 16 | &ett_x509af_ACPathData, |
1491 | 16 | &ett_x509af_AttributeCertificate, |
1492 | 16 | &ett_x509af_AttributeCertificateInfo, |
1493 | 16 | &ett_x509af_InfoSubject, |
1494 | 16 | &ett_x509af_SEQUENCE_OF_Attribute, |
1495 | 16 | &ett_x509af_IssuerSerial, |
1496 | 16 | &ett_x509af_AttCertValidityPeriod, |
1497 | 16 | &ett_x509af_AttributeCertificateAssertion, |
1498 | 16 | &ett_x509af_AssertionSubject, |
1499 | 16 | &ett_x509af_SET_OF_AttributeType, |
1500 | 16 | &ett_x509af_DSS_Params, |
1501 | 16 | }; |
1502 | | |
1503 | 16 | static ei_register_info ei[] = { |
1504 | 16 | { &ei_x509af_certificate_invalid, { "x509af.signedCertificate.invalid", PI_SECURITY, PI_WARN, "Invalid certificate", EXPFILL }}, |
1505 | 16 | }; |
1506 | | |
1507 | 16 | expert_module_t *expert_x509af; |
1508 | | |
1509 | | /* Register protocol */ |
1510 | 16 | proto_x509af = proto_register_protocol("X.509 Authentication Framework", "X509AF", "x509af"); |
1511 | | |
1512 | | /* Register fields and subtrees */ |
1513 | 16 | proto_register_field_array(proto_x509af, hf, array_length(hf)); |
1514 | 16 | proto_register_subtree_array(ett, array_length(ett)); |
1515 | | |
1516 | 16 | expert_x509af = expert_register_protocol(proto_x509af); |
1517 | 16 | expert_register_field_array(expert_x509af, ei, array_length(ei)); |
1518 | | |
1519 | 16 | x509af_eo_tap = register_export_object(proto_x509af, x509af_eo_packet, NULL); |
1520 | | |
1521 | 16 | register_cleanup_routine(&x509af_cleanup_protocol); |
1522 | | |
1523 | 16 | pkix_crl_handle = register_dissector("x509af", dissect_pkix_crl, proto_x509af); |
1524 | | |
1525 | 16 | register_ber_syntax_dissector("Certificate", proto_x509af, dissect_x509af_Certificate_PDU); |
1526 | 16 | register_ber_syntax_dissector("CertificateList", proto_x509af, dissect_CertificateList_PDU); |
1527 | 16 | register_ber_syntax_dissector("CrossCertificatePair", proto_x509af, dissect_CertificatePair_PDU); |
1528 | | |
1529 | 16 | register_ber_oid_syntax(".cer", NULL, "Certificate"); |
1530 | 16 | register_ber_oid_syntax(".crt", NULL, "Certificate"); |
1531 | 16 | register_ber_oid_syntax(".crl", NULL, "CertificateList"); |
1532 | 16 | } |
1533 | | |
1534 | | |
1535 | | /*--- proto_reg_handoff_x509af -------------------------------------------*/ |
1536 | 16 | void proto_reg_handoff_x509af(void) { |
1537 | | |
1538 | 16 | dissector_add_string("media_type", "application/pkix-crl", pkix_crl_handle); |
1539 | | |
1540 | 16 | register_ber_oid_dissector("2.5.4.36", dissect_x509af_Certificate_PDU, proto_x509af, "id-at-userCertificate"); |
1541 | 16 | register_ber_oid_dissector("2.5.4.37", dissect_x509af_Certificate_PDU, proto_x509af, "id-at-cAcertificate"); |
1542 | 16 | register_ber_oid_dissector("2.5.4.38", dissect_CertificateList_PDU, proto_x509af, "id-at-authorityRevocationList"); |
1543 | 16 | register_ber_oid_dissector("2.5.4.39", dissect_CertificateList_PDU, proto_x509af, "id-at-certificateRevocationList"); |
1544 | 16 | register_ber_oid_dissector("2.5.4.40", dissect_CertificatePair_PDU, proto_x509af, "id-at-crossCertificatePair"); |
1545 | 16 | register_ber_oid_dissector("2.5.4.53", dissect_CertificateList_PDU, proto_x509af, "id-at-deltaRevocationList"); |
1546 | 16 | register_ber_oid_dissector("2.5.4.58", dissect_AttributeCertificate_PDU, proto_x509af, "id-at-attributeCertificate"); |
1547 | 16 | register_ber_oid_dissector("2.5.4.59", dissect_CertificateList_PDU, proto_x509af, "id-at-attributeCertificateRevocationList"); |
1548 | 16 | register_ber_oid_dissector("1.2.840.10040.4.1", dissect_DSS_Params_PDU, proto_x509af, "id-dsa"); |
1549 | 16 | register_ber_oid_dissector("0.9.2342.19200300.100.1.1", dissect_Userid_PDU, proto_x509af, "id-userid"); |
1550 | | |
1551 | | |
1552 | | /*XXX these should really go to a better place but since |
1553 | | I have not that ITU standard, I'll put it here for the time |
1554 | | being. |
1555 | | Only implemented those algorithms that take no parameters |
1556 | | for the time being, ronnie |
1557 | | */ |
1558 | | /* from http://www.alvestrand.no/objectid/1.3.14.3.2.html */ |
1559 | 16 | register_ber_oid_dissector("1.3.14.3.2.2", dissect_ber_oid_NULL_callback, proto_x509af, "md4WithRSA"); |
1560 | 16 | register_ber_oid_dissector("1.3.14.3.2.3", dissect_ber_oid_NULL_callback, proto_x509af, "md5WithRSA"); |
1561 | 16 | register_ber_oid_dissector("1.3.14.3.2.4", dissect_ber_oid_NULL_callback, proto_x509af, "md4WithRSAEncryption"); |
1562 | 16 | register_ber_oid_dissector("1.3.14.3.2.6", dissect_ber_oid_NULL_callback, proto_x509af, "desECB"); |
1563 | 16 | register_ber_oid_dissector("1.3.14.3.2.11", dissect_ber_oid_NULL_callback, proto_x509af, "rsaSignature"); |
1564 | 16 | register_ber_oid_dissector("1.3.14.3.2.14", dissect_ber_oid_NULL_callback, proto_x509af, "mdc2WithRSASignature"); |
1565 | 16 | register_ber_oid_dissector("1.3.14.3.2.15", dissect_ber_oid_NULL_callback, proto_x509af, "shaWithRSASignature"); |
1566 | 16 | register_ber_oid_dissector("1.3.14.3.2.16", dissect_ber_oid_NULL_callback, proto_x509af, "dhWithCommonModulus"); |
1567 | 16 | register_ber_oid_dissector("1.3.14.3.2.17", dissect_ber_oid_NULL_callback, proto_x509af, "desEDE"); |
1568 | 16 | register_ber_oid_dissector("1.3.14.3.2.18", dissect_ber_oid_NULL_callback, proto_x509af, "sha"); |
1569 | 16 | register_ber_oid_dissector("1.3.14.3.2.19", dissect_ber_oid_NULL_callback, proto_x509af, "mdc-2"); |
1570 | 16 | register_ber_oid_dissector("1.3.14.3.2.20", dissect_ber_oid_NULL_callback, proto_x509af, "dsaCommon"); |
1571 | 16 | register_ber_oid_dissector("1.3.14.3.2.21", dissect_ber_oid_NULL_callback, proto_x509af, "dsaCommonWithSHA"); |
1572 | 16 | register_ber_oid_dissector("1.3.14.3.2.22", dissect_ber_oid_NULL_callback, proto_x509af, "rsaKeyTransport"); |
1573 | 16 | register_ber_oid_dissector("1.3.14.3.2.23", dissect_ber_oid_NULL_callback, proto_x509af, "keyed-hash-seal"); |
1574 | 16 | register_ber_oid_dissector("1.3.14.3.2.24", dissect_ber_oid_NULL_callback, proto_x509af, "md2WithRSASignature"); |
1575 | 16 | register_ber_oid_dissector("1.3.14.3.2.25", dissect_ber_oid_NULL_callback, proto_x509af, "md5WithRSASignature"); |
1576 | 16 | register_ber_oid_dissector("1.3.14.3.2.26", dissect_ber_oid_NULL_callback, proto_x509af, "SHA-1"); |
1577 | 16 | register_ber_oid_dissector("1.3.14.3.2.27", dissect_ber_oid_NULL_callback, proto_x509af, "dsaWithSHA1"); |
1578 | 16 | register_ber_oid_dissector("1.3.14.3.2.28", dissect_ber_oid_NULL_callback, proto_x509af, "dsaWithCommonSHA1"); |
1579 | 16 | register_ber_oid_dissector("1.3.14.3.2.29", dissect_ber_oid_NULL_callback, proto_x509af, "sha-1WithRSAEncryption"); |
1580 | | |
1581 | | /* these will generally be encoded as ";binary" in LDAP */ |
1582 | | |
1583 | 16 | dissector_add_string("ldap.name", "cACertificate", create_dissector_handle(dissect_x509af_Certificate_PDU, proto_x509af)); |
1584 | 16 | dissector_add_string("ldap.name", "userCertificate", create_dissector_handle(dissect_x509af_Certificate_PDU, proto_x509af)); |
1585 | | |
1586 | 16 | dissector_add_string("ldap.name", "certificateRevocationList", create_dissector_handle(dissect_CertificateList_PDU, proto_x509af)); |
1587 | 16 | dissector_add_string("ldap.name", "crl", create_dissector_handle(dissect_CertificateList_PDU, proto_x509af)); |
1588 | | |
1589 | 16 | dissector_add_string("ldap.name", "authorityRevocationList", create_dissector_handle(dissect_CertificateList_PDU, proto_x509af)); |
1590 | 16 | dissector_add_string("ldap.name", "arl", create_dissector_handle(dissect_CertificateList_PDU, proto_x509af)); |
1591 | | |
1592 | 16 | dissector_add_string("ldap.name", "crossCertificatePair", create_dissector_handle(dissect_CertificatePair_PDU, proto_x509af)); |
1593 | | |
1594 | | /* RFC 7468 files */ |
1595 | 16 | dissector_add_string("rfc7468.preeb_label", "CERTIFICATE", create_dissector_handle(dissect_x509af_Certificate_PDU, proto_x509af)); |
1596 | 16 | dissector_add_string("rfc7468.preeb_label", "X509 CRL", create_dissector_handle(dissect_CertificateList_PDU, proto_x509af)); |
1597 | 16 | dissector_add_string("rfc7468.preeb_label", "ATTRIBUTE CERTIFICATE", create_dissector_handle(dissect_AttributeCertificate_PDU, proto_x509af)); |
1598 | 16 | dissector_add_string("rfc7468.preeb_label", "PUBLIC KEY", create_dissector_handle(dissect_SubjectPublicKeyInfo_PDU, proto_x509af)); |
1599 | 16 | } |