-OCSP_BASICRESP *OCSP_basic_response_new(int type, X509* cert)
- {
- time_t t;
- OCSP_RESPID *rid;
- ASN1_BIT_STRING *bs;
- OCSP_BASICRESP *rsp = NULL;
- unsigned char md[SHA_DIGEST_LENGTH];
-
- if (!(rsp = OCSP_BASICRESP_new())) goto err;
- rid = rsp->tbsResponseData->responderId;
- switch (rid->type = type)
- {
- case V_OCSP_RESPID_NAME:
- /* cert is user cert */
- if (!(rid->value.byName =
- X509_NAME_dup(X509_get_subject_name(cert))))
- goto err;
- break;
- case V_OCSP_RESPID_KEY:
- /* cert is issuer cert */
- /* SHA-1 hash of responder's public key
- * (excluding the tag and length fields)
- */
- bs = cert->cert_info->key->public_key;
- SHA1(ASN1_STRING_data((ASN1_STRING*)bs),
- ASN1_STRING_length((ASN1_STRING*)bs), md);
- if (!(rid->value.byKey = ASN1_OCTET_STRING_new()))
- goto err;
- if (!(ASN1_OCTET_STRING_set(rid->value.byKey,
- md, sizeof md)))
- goto err;
- break;
- default:
- OCSPerr(OCSP_F_BASIC_RESPONSE_NEW,OCSP_R_BAD_TAG);
- goto err;
- break;
- }
- time(&t);
- if (!(ASN1_GENERALIZEDTIME_set(rsp->tbsResponseData->producedAt, t)))
- goto err;
- if (!(rsp->tbsResponseData->responses = sk_OCSP_SINGLERESP_new(NULL))) goto err;
- return rsp;
-err:
- if (rsp) OCSP_BASICRESP_free(rsp);
- return NULL;
- }