Botan  2.7.0
Crypto and TLS for C++11
Public Member Functions | Static Public Member Functions | List of all members
Botan::Cert_Extension::Name_Constraints Class Referencefinal

#include <x509_ext.h>

Inheritance diagram for Botan::Cert_Extension::Name_Constraints:
Botan::Certificate_Extension

Public Member Functions

Name_Constraintscopy () const override
 
const NameConstraintsget_name_constraints () const
 
 Name_Constraints ()=default
 
 Name_Constraints (const NameConstraints &nc)
 
OID oid_of () const override
 
void validate (const X509_Certificate &subject, const X509_Certificate &issuer, const std::vector< std::shared_ptr< const X509_Certificate >> &cert_path, std::vector< std::set< Certificate_Status_Code >> &cert_status, size_t pos) override
 

Static Public Member Functions

static OID static_oid ()
 

Detailed Description

Name Constraints

Definition at line 491 of file x509_ext.h.

Constructor & Destructor Documentation

◆ Name_Constraints() [1/2]

Botan::Cert_Extension::Name_Constraints::Name_Constraints ( )
default

◆ Name_Constraints() [2/2]

Botan::Cert_Extension::Name_Constraints::Name_Constraints ( const NameConstraints nc)
inline

Definition at line 498 of file x509_ext.h.

498 : m_name_constraints(nc) {}

Member Function Documentation

◆ copy()

Name_Constraints* Botan::Cert_Extension::Name_Constraints::copy ( ) const
inlineoverridevirtual

Make a copy of this extension

Returns
copy of this

Implements Botan::Certificate_Extension.

Definition at line 494 of file x509_ext.h.

495  { return new Name_Constraints(m_name_constraints); }

◆ get_name_constraints()

const NameConstraints& Botan::Cert_Extension::Name_Constraints::get_name_constraints ( ) const
inline

Definition at line 505 of file x509_ext.h.

505 { return m_name_constraints; }

◆ oid_of()

OID Botan::Cert_Extension::Name_Constraints::oid_of ( ) const
inlineoverridevirtual
Returns
OID representing this extension

Implements Botan::Certificate_Extension.

Definition at line 508 of file x509_ext.h.

508 { return static_oid(); }

◆ static_oid()

static OID Botan::Cert_Extension::Name_Constraints::static_oid ( )
inlinestatic

Definition at line 507 of file x509_ext.h.

507 { return OID("2.5.29.30"); }

◆ validate()

void Botan::Cert_Extension::Name_Constraints::validate ( const X509_Certificate subject,
const X509_Certificate issuer,
const std::vector< std::shared_ptr< const X509_Certificate >> &  cert_path,
std::vector< std::set< Certificate_Status_Code >> &  cert_status,
size_t  pos 
)
overridevirtual

Reimplemented from Botan::Certificate_Extension.

Definition at line 627 of file x509_ext.cpp.

References Botan::NameConstraints::excluded(), Botan::X509_Certificate::is_CA_cert(), Botan::X509_Certificate::is_critical(), Botan::NAME_CONSTRAINT_ERROR, and Botan::NameConstraints::permitted().

631  {
632  if(!m_name_constraints.permitted().empty() || !m_name_constraints.excluded().empty())
633  {
634  if(!subject.is_CA_cert() || !subject.is_critical("X509v3.NameConstraints"))
635  cert_status.at(pos).insert(Certificate_Status_Code::NAME_CONSTRAINT_ERROR);
636 
637  const bool issuer_name_constraint_critical =
638  issuer.is_critical("X509v3.NameConstraints");
639 
640  const bool at_self_signed_root = (pos == cert_path.size() - 1);
641 
642  // Check that all subordinate certs pass the name constraint
643  for(size_t j = 0; j <= pos; ++j)
644  {
645  if(pos == j && at_self_signed_root)
646  continue;
647 
648  bool permitted = m_name_constraints.permitted().empty();
649  bool failed = false;
650 
651  for(auto c: m_name_constraints.permitted())
652  {
653  switch(c.base().matches(*cert_path.at(j)))
654  {
655  case GeneralName::MatchResult::NotFound:
656  case GeneralName::MatchResult::All:
657  permitted = true;
658  break;
659  case GeneralName::MatchResult::UnknownType:
660  failed = issuer_name_constraint_critical;
661  permitted = true;
662  break;
663  default:
664  break;
665  }
666  }
667 
668  for(auto c: m_name_constraints.excluded())
669  {
670  switch(c.base().matches(*cert_path.at(j)))
671  {
672  case GeneralName::MatchResult::All:
673  case GeneralName::MatchResult::Some:
674  failed = true;
675  break;
676  case GeneralName::MatchResult::UnknownType:
677  failed = issuer_name_constraint_critical;
678  break;
679  default:
680  break;
681  }
682  }
683 
684  if(failed || !permitted)
685  {
686  cert_status.at(j).insert(Certificate_Status_Code::NAME_CONSTRAINT_ERROR);
687  }
688  }
689  }
690  }
const std::vector< GeneralSubtree > & excluded() const
const std::vector< GeneralSubtree > & permitted() const

The documentation for this class was generated from the following files: