blob: 39baa3e6157f7bc568fb97716de15a1bfe74dc67 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
|
/***************************************************************************
* Copyright (c) 2024 Microsoft Corporation
* Copyright (c) 2025-present Eclipse ThreadX Contributors
*
* This program and the accompanying materials are made available under the
* terms of the MIT License which is available at
* https://opensource.org/licenses/MIT.
*
* SPDX-License-Identifier: MIT
**************************************************************************/
/**************************************************************************/
/**************************************************************************/
/** */
/** NetX Secure Component */
/** */
/** Transport Layer Security (TLS) */
/** */
/**************************************************************************/
/**************************************************************************/
#define NX_SECURE_SOURCE_CODE
/* Include necessary system files. */
#include "nx_secure_tls.h"
/**************************************************************************/
/* */
/* FUNCTION RELEASE */
/* */
/* _nx_secure_tls_remote_certificate_buffer_allocate PORTABLE C */
/* 6.4.3 */
/* AUTHOR */
/* */
/* Timothy Stapko, Microsoft Corporation */
/* */
/* DESCRIPTION */
/* */
/* This function allocates buffer space to hold incoming certificates */
/* sent by the remote host. The provided buffer must have enough space */
/* allocated for the maximum size of a certificate that may be provided*/
/* by a remote host times the expected size of the provided certificate*/
/* chain. The size needed can be calculated using the following */
/* formula: */
/* */
/* size = (<# of certs>) * (sizeof(NX_SECURE_X509_CERT) + */
/* <expected max cert size (~2KB)>) */
/* */
/* The space will be divided equally amongst the number of certificates*/
/* that can be carved from the provided buffer. */
/* */
/* INPUT */
/* */
/* tls_session Pointer to TLS Session */
/* certs_number Number of client certs */
/* certificate_buffer Buffer allocated for certs */
/* buffer_size Buffer size in bytes */
/* */
/* OUTPUT */
/* */
/* status Completion status */
/* */
/* CALLS */
/* */
/* _nx_secure_tls_remote_certificate_allocate */
/* Allocate space for certs */
/* */
/* CALLED BY */
/* */
/* Application Code */
/* */
/**************************************************************************/
UINT _nx_secure_tls_remote_certificate_buffer_allocate(NX_SECURE_TLS_SESSION *tls_session, UINT certs_number, VOID *certificate_buffer, ULONG buffer_size)
{
#ifndef NX_SECURE_DISABLE_X509
UINT status;
UINT metadata_size;
UINT cert_buffer_size;
UCHAR *buffer_ptr;
NX_SECURE_X509_CERT *cert_ptr;
UINT count;
/* Calculate the size of the X509 control blocks needed. */
metadata_size = sizeof(NX_SECURE_X509_CERT) * certs_number;
/* Check that buffer is large enough. */
if(buffer_size < metadata_size)
{
return(NX_INVALID_PARAMETERS);
}
NX_ASSERT(certs_number != 0);
/* Calculate the per-certificate size allocated from the buffer. */
cert_buffer_size = (buffer_size - metadata_size) / certs_number;
/* Check that the certificate buffer size makes sense. */
if(cert_buffer_size < NX_SECURE_TLS_MINIMUM_CERTIFICATE_SIZE)
{
return(NX_INVALID_PARAMETERS);
}
/* Get a working pointer to our certificate buffer. */
buffer_ptr = (UCHAR*)(certificate_buffer);
for(count = 0; count < certs_number; count++)
{
/* Allocate space for the cert control block. */
cert_ptr = (NX_SECURE_X509_CERT*)(buffer_ptr);
/* Advance working pointer past control block. */
buffer_ptr += sizeof(NX_SECURE_X509_CERT);
/* Now allocate space for remote certificates. */
status = _nx_secure_tls_remote_certificate_allocate(tls_session, cert_ptr, buffer_ptr, cert_buffer_size);
if(status != NX_SUCCESS)
{
return(status);
}
/* Advance working pointer past certificate buffer. */
buffer_ptr += cert_buffer_size;
}
/* Return completion status. */
return(NX_SUCCESS);
#else
NX_PARAMETER_NOT_USED(tls_session);
NX_PARAMETER_NOT_USED(certs_number);
NX_PARAMETER_NOT_USED(certificate_buffer);
NX_PARAMETER_NOT_USED(buffer_size);
return(NX_NOT_SUPPORTED);
#endif
}
|