]> git.saurik.com Git - apple/security.git/blob - SecurityTests/clxutils/ocspTool/findOcspUrl.cpp
Security-57031.1.35.tar.gz
[apple/security.git] / SecurityTests / clxutils / ocspTool / findOcspUrl.cpp
1 /*
2 * Copyright (c) 2002,2005 Apple Computer, Inc. All Rights Reserved.
3 *
4 * The contents of this file constitute Original Code as defined in and are
5 * subject to the Apple Public Source License Version 1.2 (the 'License').
6 * You may not use this file except in compliance with the License. Please obtain
7 * a copy of the License at http://www.apple.com/publicsource and read it before
8 * using this file.
9 *
10 * This Original Code and all software distributed under the License are
11 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS
12 * OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, INCLUDING WITHOUT
13 * LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR
14 * PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. Please see the License for the
15 * specific language governing rights and limitations under the License.
16 */
17
18
19 /*
20 * findOcspUrl.cpp - find URL for OCSP for aspecified cert.
21 */
22
23 #include <Security/SecAsn1Coder.h>
24 #include <clAppUtils/CertParser.h>
25 #include <utilLib/common.h>
26
27 /*
28 * Examine cert, looking for AuthorityInfoAccess, with id-ad-ocsp URIs. Return
29 * the first URL found.
30 */
31 CSSM_DATA *ocspUrlFromCert(
32 CertParser &subject,
33 SecAsn1CoderRef coder)
34 {
35 CE_AuthorityInfoAccess *aia = (CE_AuthorityInfoAccess *)
36 subject.extensionForOid(CSSMOID_AuthorityInfoAccess);
37 if(aia == NULL) {
38 printf("***No AIA extension found; OCSP aborted.\n");
39 return NULL;
40 }
41 CSSM_DATA *url = NULL;
42 for(unsigned dex=0; dex<aia->numAccessDescriptions; dex++) {
43 CE_AccessDescription *ad = &aia->accessDescriptions[dex];
44 if(!appCompareCssmData(&ad->accessMethod, &CSSMOID_AD_OCSP)) {
45 continue;
46 }
47 CE_GeneralName *genName = &ad->accessLocation;
48 if(genName->nameType != GNT_URI) {
49 printf("tpOcspUrlsFromCert: CSSMOID_AD_OCSP, but not type URI");
50 continue;
51 }
52
53 /* got one */
54 url = (CSSM_DATA *)SecAsn1Malloc(coder, sizeof(CSSM_DATA));
55 SecAsn1AllocCopyItem(coder, &genName->name, url);
56 return url;
57 }
58
59 printf("***No AIA extension with URI found; OCSP aborted.\n");
60 return NULL;
61 }