2 * Copyright (c) 2002,2005 Apple Computer, Inc. All Rights Reserved.
4 * The contents of this file constitute Original Code as defined in and are
5 * subject to the Apple Public Source License Version 1.2 (the 'License').
6 * You may not use this file except in compliance with the License. Please obtain
7 * a copy of the License at http://www.apple.com/publicsource and read it before
10 * This Original Code and all software distributed under the License are
11 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS
12 * OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES, INCLUDING WITHOUT
13 * LIMITATION, ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR
14 * PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT. Please see the License for the
15 * specific language governing rights and limitations under the License.
20 * findOcspUrl.cpp - find URL for OCSP for aspecified cert.
23 #include <Security/SecAsn1Coder.h>
24 #include <clAppUtils/CertParser.h>
25 #include <utilLib/common.h>
28 * Examine cert, looking for AuthorityInfoAccess, with id-ad-ocsp URIs. Return
29 * the first URL found.
31 CSSM_DATA
*ocspUrlFromCert(
33 SecAsn1CoderRef coder
)
35 CE_AuthorityInfoAccess
*aia
= (CE_AuthorityInfoAccess
*)
36 subject
.extensionForOid(CSSMOID_AuthorityInfoAccess
);
38 printf("***No AIA extension found; OCSP aborted.\n");
41 CSSM_DATA
*url
= NULL
;
42 for(unsigned dex
=0; dex
<aia
->numAccessDescriptions
; dex
++) {
43 CE_AccessDescription
*ad
= &aia
->accessDescriptions
[dex
];
44 if(!appCompareCssmData(&ad
->accessMethod
, &CSSMOID_AD_OCSP
)) {
47 CE_GeneralName
*genName
= &ad
->accessLocation
;
48 if(genName
->nameType
!= GNT_URI
) {
49 printf("tpOcspUrlsFromCert: CSSMOID_AD_OCSP, but not type URI");
54 url
= (CSSM_DATA
*)SecAsn1Malloc(coder
, sizeof(CSSM_DATA
));
55 SecAsn1AllocCopyItem(coder
, &genName
->name
, url
);
59 printf("***No AIA extension with URI found; OCSP aborted.\n");