2 /* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
5 /* ====================================================================
6 * Copyright (c) 2008 The OpenSSL Project. All rights reserved.
8 * Redistribution and use in source and binary forms, with or without
9 * modification, are permitted provided that the following conditions
12 * 1. Redistributions of source code must retain the above copyright
13 * notice, this list of conditions and the following disclaimer.
15 * 2. Redistributions in binary form must reproduce the above copyright
16 * notice, this list of conditions and the following disclaimer in
17 * the documentation and/or other materials provided with the
20 * 3. All advertising materials mentioning features or use of this
21 * software must display the following acknowledgment:
22 * "This product includes software developed by the OpenSSL Project
23 * for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
25 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
26 * endorse or promote products derived from this software without
27 * prior written permission. For written permission, please contact
28 * licensing@OpenSSL.org.
30 * 5. Products derived from this software may not be called "OpenSSL"
31 * nor may "OpenSSL" appear in their names without prior written
32 * permission of the OpenSSL Project.
34 * 6. Redistributions of any form whatsoever must retain the following
36 * "This product includes software developed by the OpenSSL Project
37 * for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
39 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
40 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
41 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
42 * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR
43 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
44 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
45 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
46 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
47 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
48 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
49 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
50 * OF THE POSSIBILITY OF SUCH DAMAGE.
51 * ====================================================================
58 #include <openssl/x509.h>
61 #error CMS is disabled.
69 typedef struct CMS_ContentInfo_st CMS_ContentInfo;
70 typedef struct CMS_SignerInfo_st CMS_SignerInfo;
71 typedef struct CMS_CertificateChoices CMS_CertificateChoices;
72 typedef struct CMS_RevocationInfoChoice_st CMS_RevocationInfoChoice;
73 typedef struct CMS_RecipientInfo_st CMS_RecipientInfo;
75 DECLARE_STACK_OF(CMS_SignerInfo)
76 DECLARE_ASN1_FUNCTIONS(CMS_ContentInfo)
77 DECLARE_ASN1_PRINT_FUNCTION(CMS_ContentInfo)
79 #define CMS_SIGNERINFO_ISSUER_SERIAL 0
80 #define CMS_SIGNERINFO_KEYIDENTIFIER 1
82 #define CMS_RECIPINFO_TRANS 0
83 #define CMS_RECIPINFO_AGREE 1
84 #define CMS_RECIPINFO_KEK 2
85 #define CMS_RECIPINFO_PASS 3
86 #define CMS_RECIPINFO_OTHER 4
88 /* S/MIME related flags */
91 #define CMS_NOCERTS 0x2
92 #define CMS_NO_CONTENT_VERIFY 0x4
93 #define CMS_NO_ATTR_VERIFY 0x8
95 (CMS_NO_CONTENT_VERIFY|CMS_NO_ATTR_VERIFY)
96 #define CMS_NOINTERN 0x10
97 #define CMS_NO_SIGNER_CERT_VERIFY 0x20
98 #define CMS_NOVERIFY 0x20
99 #define CMS_DETACHED 0x40
100 #define CMS_BINARY 0x80
101 #define CMS_NOATTR 0x100
102 #define CMS_NOSMIMECAP 0x200
103 #define CMS_NOOLDMIMETYPE 0x400
104 #define CMS_CRLFEOL 0x800
105 #define CMS_STREAM 0x1000
106 #define CMS_NOCRL 0x2000
107 #define CMS_PARTIAL 0x4000
108 #define CMS_REUSE_DIGEST 0x8000
109 #define CMS_USE_KEYID 0x10000
111 const ASN1_OBJECT *CMS_get0_type(CMS_ContentInfo *cms);
113 BIO *CMS_dataInit(CMS_ContentInfo *cms, BIO *icont);
114 int CMS_dataFinal(CMS_ContentInfo *cms, BIO *bio);
116 ASN1_OCTET_STRING **CMS_get0_content(CMS_ContentInfo *cms);
117 int CMS_is_detached(CMS_ContentInfo *cms);
118 int CMS_set_detached(CMS_ContentInfo *cms, int detached);
121 DECLARE_PEM_rw_const(CMS, CMS_ContentInfo)
124 int CMS_stream(unsigned char ***boundary, CMS_ContentInfo *cms);
125 CMS_ContentInfo *d2i_CMS_bio(BIO *bp, CMS_ContentInfo **cms);
126 int i2d_CMS_bio(BIO *bp, CMS_ContentInfo *cms);
128 BIO *BIO_new_CMS(BIO *out, CMS_ContentInfo *cms);
129 int i2d_CMS_bio_stream(BIO *out, CMS_ContentInfo *cms, BIO *in, int flags);
130 int PEM_write_bio_CMS_stream(BIO *out, CMS_ContentInfo *cms, BIO *in, int flags);
131 CMS_ContentInfo *SMIME_read_CMS(BIO *bio, BIO **bcont);
132 int SMIME_write_CMS(BIO *bio, CMS_ContentInfo *cms, BIO *data, int flags);
134 int CMS_final(CMS_ContentInfo *cms, BIO *data, int flags);
136 CMS_ContentInfo *CMS_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs,
137 BIO *data, unsigned int flags);
139 int CMS_data(CMS_ContentInfo *cms, BIO *out, unsigned int flags);
140 CMS_ContentInfo *CMS_data_create(BIO *in, unsigned int flags);
142 int CMS_digest_verify(CMS_ContentInfo *cms, BIO *dcont, BIO *out,
144 CMS_ContentInfo *CMS_digest_create(BIO *in, const EVP_MD *md,
147 int CMS_EncryptedData_decrypt(CMS_ContentInfo *cms,
148 const unsigned char *key, size_t keylen,
149 BIO *dcont, BIO *out, unsigned int flags);
151 CMS_ContentInfo *CMS_EncryptedData_encrypt(BIO *in, const EVP_CIPHER *cipher,
152 const unsigned char *key, size_t keylen,
155 int CMS_EncryptedData_set1_key(CMS_ContentInfo *cms, const EVP_CIPHER *ciph,
156 const unsigned char *key, size_t keylen);
158 int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs,
159 X509_STORE *store, BIO *dcont, BIO *out, unsigned int flags);
161 STACK_OF(X509) *CMS_get0_signers(CMS_ContentInfo *cms);
163 CMS_ContentInfo *CMS_encrypt(STACK_OF(X509) *certs, BIO *in,
164 const EVP_CIPHER *cipher, unsigned int flags);
166 int CMS_decrypt(CMS_ContentInfo *cms, EVP_PKEY *pkey, X509 *cert,
167 BIO *data, BIO *dcont,
170 int CMS_decrypt_set1_pkey(CMS_ContentInfo *cms, EVP_PKEY *pk, X509 *cert);
171 int CMS_decrypt_set1_key(CMS_ContentInfo *cms,
172 unsigned char *key, size_t keylen,
173 unsigned char *id, size_t idlen);
175 STACK_OF(CMS_RecipientInfo) *CMS_get0_RecipientInfos(CMS_ContentInfo *cms);
176 int CMS_RecipientInfo_type(CMS_RecipientInfo *ri);
177 CMS_ContentInfo *CMS_EnvelopedData_create(const EVP_CIPHER *cipher);
178 CMS_RecipientInfo *CMS_add1_recipient_cert(CMS_ContentInfo *cms,
179 X509 *recip, unsigned int flags);
180 int CMS_RecipientInfo_set0_pkey(CMS_RecipientInfo *ri, EVP_PKEY *pkey);
181 int CMS_RecipientInfo_ktri_cert_cmp(CMS_RecipientInfo *ri, X509 *cert);
182 int CMS_RecipientInfo_ktri_get0_algs(CMS_RecipientInfo *ri,
183 EVP_PKEY **pk, X509 **recip,
185 int CMS_RecipientInfo_ktri_get0_signer_id(CMS_RecipientInfo *ri,
186 ASN1_OCTET_STRING **keyid,
187 X509_NAME **issuer, ASN1_INTEGER **sno);
189 CMS_RecipientInfo *CMS_add0_recipient_key(CMS_ContentInfo *cms, int nid,
190 unsigned char *key, size_t keylen,
191 unsigned char *id, size_t idlen,
192 ASN1_GENERALIZEDTIME *date,
193 ASN1_OBJECT *otherTypeId,
194 ASN1_TYPE *otherType);
196 int CMS_RecipientInfo_set0_key(CMS_RecipientInfo *ri,
197 unsigned char *key, size_t keylen);
199 int CMS_RecipientInfo_kekri_id_cmp(CMS_RecipientInfo *ri,
200 const unsigned char *id, size_t idlen);
202 int CMS_RecipientInfo_decrypt(CMS_ContentInfo *cms, CMS_RecipientInfo *ri);
204 int CMS_uncompress(CMS_ContentInfo *cms, BIO *dcont, BIO *out,
206 CMS_ContentInfo *CMS_compress(BIO *in, int comp_nid, unsigned int flags);
208 int CMS_set1_eContentType(CMS_ContentInfo *cms, const ASN1_OBJECT *oid);
209 const ASN1_OBJECT *CMS_get0_eContentType(CMS_ContentInfo *cms);
211 CMS_CertificateChoices *CMS_add0_CertificateChoices(CMS_ContentInfo *cms);
212 int CMS_add0_cert(CMS_ContentInfo *cms, X509 *cert);
213 int CMS_add1_cert(CMS_ContentInfo *cms, X509 *cert);
214 STACK_OF(X509) *CMS_get1_certs(CMS_ContentInfo *cms);
216 CMS_RevocationInfoChoice *CMS_add0_RevocationInfoChoice(CMS_ContentInfo *cms);
217 int CMS_add0_crl(CMS_ContentInfo *cms, X509_CRL *crl);
218 STACK_OF(X509_CRL) *CMS_get1_crls(CMS_ContentInfo *cms);
220 int CMS_SignedData_init(CMS_ContentInfo *cms);
221 CMS_SignerInfo *CMS_add1_signer(CMS_ContentInfo *cms,
222 X509 *signer, EVP_PKEY *pk, const EVP_MD *md,
224 STACK_OF(CMS_SignerInfo) *CMS_get0_SignerInfos(CMS_ContentInfo *cms);
226 void CMS_SignerInfo_set1_signer_cert(CMS_SignerInfo *si, X509 *signer);
227 int CMS_SignerInfo_get0_signer_id(CMS_SignerInfo *si,
228 ASN1_OCTET_STRING **keyid,
229 X509_NAME **issuer, ASN1_INTEGER **sno);
230 int CMS_SignerInfo_cert_cmp(CMS_SignerInfo *si, X509 *cert);
231 int CMS_set1_signers_certs(CMS_ContentInfo *cms, STACK_OF(X509) *certs,
233 void CMS_SignerInfo_get0_algs(CMS_SignerInfo *si, EVP_PKEY **pk, X509 **signer,
234 X509_ALGOR **pdig, X509_ALGOR **psig);
235 int CMS_SignerInfo_sign(CMS_SignerInfo *si);
236 int CMS_SignerInfo_verify(CMS_SignerInfo *si);
237 int CMS_SignerInfo_verify_content(CMS_SignerInfo *si, BIO *chain);
239 int CMS_add_smimecap(CMS_SignerInfo *si, STACK_OF(X509_ALGOR) *algs);
240 int CMS_add_simple_smimecap(STACK_OF(X509_ALGOR) **algs,
241 int algnid, int keysize);
242 int CMS_add_standard_smimecap(STACK_OF(X509_ALGOR) **smcap);
244 int CMS_signed_get_attr_count(const CMS_SignerInfo *si);
245 int CMS_signed_get_attr_by_NID(const CMS_SignerInfo *si, int nid,
247 int CMS_signed_get_attr_by_OBJ(const CMS_SignerInfo *si, ASN1_OBJECT *obj,
249 X509_ATTRIBUTE *CMS_signed_get_attr(const CMS_SignerInfo *si, int loc);
250 X509_ATTRIBUTE *CMS_signed_delete_attr(CMS_SignerInfo *si, int loc);
251 int CMS_signed_add1_attr(CMS_SignerInfo *si, X509_ATTRIBUTE *attr);
252 int CMS_signed_add1_attr_by_OBJ(CMS_SignerInfo *si,
253 const ASN1_OBJECT *obj, int type,
254 const void *bytes, int len);
255 int CMS_signed_add1_attr_by_NID(CMS_SignerInfo *si,
257 const void *bytes, int len);
258 int CMS_signed_add1_attr_by_txt(CMS_SignerInfo *si,
259 const char *attrname, int type,
260 const void *bytes, int len);
261 void *CMS_signed_get0_data_by_OBJ(CMS_SignerInfo *si, ASN1_OBJECT *oid,
262 int lastpos, int type);
264 int CMS_unsigned_get_attr_count(const CMS_SignerInfo *si);
265 int CMS_unsigned_get_attr_by_NID(const CMS_SignerInfo *si, int nid,
267 int CMS_unsigned_get_attr_by_OBJ(const CMS_SignerInfo *si, ASN1_OBJECT *obj,
269 X509_ATTRIBUTE *CMS_unsigned_get_attr(const CMS_SignerInfo *si, int loc);
270 X509_ATTRIBUTE *CMS_unsigned_delete_attr(CMS_SignerInfo *si, int loc);
271 int CMS_unsigned_add1_attr(CMS_SignerInfo *si, X509_ATTRIBUTE *attr);
272 int CMS_unsigned_add1_attr_by_OBJ(CMS_SignerInfo *si,
273 const ASN1_OBJECT *obj, int type,
274 const void *bytes, int len);
275 int CMS_unsigned_add1_attr_by_NID(CMS_SignerInfo *si,
277 const void *bytes, int len);
278 int CMS_unsigned_add1_attr_by_txt(CMS_SignerInfo *si,
279 const char *attrname, int type,
280 const void *bytes, int len);
281 void *CMS_unsigned_get0_data_by_OBJ(CMS_SignerInfo *si, ASN1_OBJECT *oid,
282 int lastpos, int type);
284 /* BEGIN ERROR CODES */
285 /* The following lines are auto generated by the script mkerr.pl. Any changes
286 * made after this point may be overwritten when the script is next run.
288 void ERR_load_CMS_strings(void);
290 /* Error codes for the CMS functions. */
292 /* Function codes. */
293 #define CMS_F_CHECK_CONTENT 99
294 #define CMS_F_CMS_ADD0_RECIPIENT_KEY 100
295 #define CMS_F_CMS_ADD1_RECIPIENT_CERT 101
296 #define CMS_F_CMS_ADD1_SIGNER 102
297 #define CMS_F_CMS_ADD1_SIGNINGTIME 103
298 #define CMS_F_CMS_COMPRESS 104
299 #define CMS_F_CMS_COMPRESSEDDATA_CREATE 105
300 #define CMS_F_CMS_COMPRESSEDDATA_INIT_BIO 106
301 #define CMS_F_CMS_COPY_CONTENT 107
302 #define CMS_F_CMS_COPY_MESSAGEDIGEST 108
303 #define CMS_F_CMS_DATA 109
304 #define CMS_F_CMS_DATAFINAL 110
305 #define CMS_F_CMS_DATAINIT 111
306 #define CMS_F_CMS_DECRYPT 112
307 #define CMS_F_CMS_DECRYPT_SET1_KEY 113
308 #define CMS_F_CMS_DECRYPT_SET1_PKEY 114
309 #define CMS_F_CMS_DIGESTALGORITHM_FIND_CTX 115
310 #define CMS_F_CMS_DIGESTALGORITHM_INIT_BIO 116
311 #define CMS_F_CMS_DIGESTEDDATA_DO_FINAL 117
312 #define CMS_F_CMS_DIGEST_VERIFY 118
313 #define CMS_F_CMS_ENCRYPT 119
314 #define CMS_F_CMS_ENCRYPTEDCONTENT_INIT_BIO 120
315 #define CMS_F_CMS_ENCRYPTEDDATA_DECRYPT 121
316 #define CMS_F_CMS_ENCRYPTEDDATA_ENCRYPT 122
317 #define CMS_F_CMS_ENCRYPTEDDATA_SET1_KEY 123
318 #define CMS_F_CMS_ENVELOPEDDATA_CREATE 124
319 #define CMS_F_CMS_ENVELOPEDDATA_INIT_BIO 125
320 #define CMS_F_CMS_ENVELOPED_DATA_INIT 126
321 #define CMS_F_CMS_FINAL 127
322 #define CMS_F_CMS_GET0_CERTIFICATE_CHOICES 128
323 #define CMS_F_CMS_GET0_CONTENT 129
324 #define CMS_F_CMS_GET0_ECONTENT_TYPE 130
325 #define CMS_F_CMS_GET0_ENVELOPED 131
326 #define CMS_F_CMS_GET0_REVOCATION_CHOICES 132
327 #define CMS_F_CMS_GET0_SIGNED 133
328 #define CMS_F_CMS_RECIPIENTINFO_DECRYPT 134
329 #define CMS_F_CMS_RECIPIENTINFO_KEKRI_DECRYPT 135
330 #define CMS_F_CMS_RECIPIENTINFO_KEKRI_ENCRYPT 136
331 #define CMS_F_CMS_RECIPIENTINFO_KEKRI_GET0_ID 137
332 #define CMS_F_CMS_RECIPIENTINFO_KEKRI_ID_CMP 138
333 #define CMS_F_CMS_RECIPIENTINFO_KTRI_CERT_CMP 139
334 #define CMS_F_CMS_RECIPIENTINFO_KTRI_DECRYPT 140
335 #define CMS_F_CMS_RECIPIENTINFO_KTRI_ENCRYPT 141
336 #define CMS_F_CMS_RECIPIENTINFO_KTRI_GET0_ALGS 142
337 #define CMS_F_CMS_RECIPIENTINFO_KTRI_GET0_SIGNER_ID 143
338 #define CMS_F_CMS_RECIPIENTINFO_SET0_KEY 144
339 #define CMS_F_CMS_RECIPIENTINFO_SET0_PKEY 145
340 #define CMS_F_CMS_SET1_SIGNERIDENTIFIER 146
341 #define CMS_F_CMS_SET_DETACHED 147
342 #define CMS_F_CMS_SIGN 148
343 #define CMS_F_CMS_SIGNED_DATA_INIT 149
344 #define CMS_F_CMS_SIGNERINFO_CONTENT_SIGN 150
345 #define CMS_F_CMS_SIGNERINFO_SIGN 151
346 #define CMS_F_CMS_SIGNERINFO_VERIFY 152
347 #define CMS_F_CMS_SIGNERINFO_VERIFY_CERT 153
348 #define CMS_F_CMS_SIGNERINFO_VERIFY_CONTENT 154
349 #define CMS_F_CMS_STREAM 155
350 #define CMS_F_CMS_UNCOMPRESS 156
351 #define CMS_F_CMS_VERIFY 157
354 #define CMS_R_ADD_SIGNER_ERROR 99
355 #define CMS_R_CERTIFICATE_HAS_NO_KEYID 160
356 #define CMS_R_CERTIFICATE_VERIFY_ERROR 100
357 #define CMS_R_CIPHER_INITIALISATION_ERROR 101
358 #define CMS_R_CIPHER_PARAMETER_INITIALISATION_ERROR 102
359 #define CMS_R_CMS_DATAFINAL_ERROR 103
360 #define CMS_R_CMS_LIB 104
361 #define CMS_R_CONTENT_NOT_FOUND 105
362 #define CMS_R_CONTENT_TYPE_NOT_COMPRESSED_DATA 106
363 #define CMS_R_CONTENT_TYPE_NOT_ENVELOPED_DATA 107
364 #define CMS_R_CONTENT_TYPE_NOT_SIGNED_DATA 108
365 #define CMS_R_CONTENT_VERIFY_ERROR 109
366 #define CMS_R_CTRL_ERROR 110
367 #define CMS_R_CTRL_FAILURE 111
368 #define CMS_R_DECRYPT_ERROR 112
369 #define CMS_R_ERROR_GETTING_PUBLIC_KEY 113
370 #define CMS_R_ERROR_READING_MESSAGEDIGEST_ATTRIBUTE 114
371 #define CMS_R_ERROR_SETTING_KEY 115
372 #define CMS_R_ERROR_SETTING_RECIPIENTINFO 116
373 #define CMS_R_INVALID_ENCRYPTED_KEY_LENGTH 117
374 #define CMS_R_INVALID_KEY_LENGTH 118
375 #define CMS_R_MD_BIO_INIT_ERROR 119
376 #define CMS_R_MESSAGEDIGEST_ATTRIBUTE_WRONG_LENGTH 120
377 #define CMS_R_MESSAGEDIGEST_WRONG_LENGTH 121
378 #define CMS_R_NOT_ENCRYPTED_DATA 122
379 #define CMS_R_NOT_KEK 123
380 #define CMS_R_NOT_KEY_TRANSPORT 124
381 #define CMS_R_NOT_SUPPORTED_FOR_THIS_KEY_TYPE 125
382 #define CMS_R_NO_CIPHER 126
383 #define CMS_R_NO_CONTENT 127
384 #define CMS_R_NO_DEFAULT_DIGEST 128
385 #define CMS_R_NO_DIGEST_SET 129
386 #define CMS_R_NO_KEY 130
387 #define CMS_R_NO_MATCHING_DIGEST 131
388 #define CMS_R_NO_MATCHING_RECIPIENT 132
389 #define CMS_R_NO_PRIVATE_KEY 133
390 #define CMS_R_NO_PUBLIC_KEY 134
391 #define CMS_R_NO_SIGNERS 135
392 #define CMS_R_PRIVATE_KEY_DOES_NOT_MATCH_CERTIFICATE 136
393 #define CMS_R_RECIPIENT_ERROR 137
394 #define CMS_R_SIGNER_CERTIFICATE_NOT_FOUND 138
395 #define CMS_R_SIGNFINAL_ERROR 139
396 #define CMS_R_SMIME_TEXT_ERROR 140
397 #define CMS_R_STORE_INIT_ERROR 141
398 #define CMS_R_TYPE_NOT_COMPRESSED_DATA 142
399 #define CMS_R_TYPE_NOT_DATA 143
400 #define CMS_R_TYPE_NOT_DIGESTED_DATA 144
401 #define CMS_R_TYPE_NOT_ENCRYPTED_DATA 145
402 #define CMS_R_TYPE_NOT_ENVELOPED_DATA 146
403 #define CMS_R_UNABLE_TO_FINALIZE_CONTEXT 147
404 #define CMS_R_UNKNOWN_CIPHER 148
405 #define CMS_R_UNKNOWN_DIGEST_ALGORIHM 149
406 #define CMS_R_UNKNOWN_ID 150
407 #define CMS_R_UNSUPPORTED_COMPRESSION_ALGORITHM 151
408 #define CMS_R_UNSUPPORTED_CONTENT_TYPE 152
409 #define CMS_R_UNSUPPORTED_KEK_ALGORITHM 153
410 #define CMS_R_UNSUPPORTED_RECIPIENT_TYPE 154
411 #define CMS_R_UNSUPPORTED_RECPIENTINFO_TYPE 155
412 #define CMS_R_UNSUPPORTED_TYPE 156
413 #define CMS_R_UNWRAP_ERROR 157
414 #define CMS_R_VERIFICATION_FAILURE 158
415 #define CMS_R_WRAP_ERROR 159