summaryrefslogtreecommitdiff
path: root/nx_secure/src/nx_secure_tls_remote_certificate_free.c
blob: 08416ed5145f41f04cbdf5dd1e687a61c0697227 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
/***************************************************************************
 * Copyright (c) 2024 Microsoft Corporation
 * Copyright (c) 2025-present Eclipse ThreadX Contributors
 *
 * This program and the accompanying materials are made available under the
 * terms of the MIT License which is available at
 * https://opensource.org/licenses/MIT.
 *
 * SPDX-License-Identifier: MIT
 **************************************************************************/


/**************************************************************************/
/**************************************************************************/
/**                                                                       */
/** NetX Secure Component                                                 */
/**                                                                       */
/**    Transport Layer Security (TLS)                                     */
/**                                                                       */
/**************************************************************************/
/**************************************************************************/

#define NX_SECURE_SOURCE_CODE

/* Include necessary system files.  */

#include "nx_secure_tls.h"

/**************************************************************************/
/*                                                                        */
/*  FUNCTION                                               RELEASE        */
/*                                                                        */
/*    _nx_secure_tls_remote_certificate_free              PORTABLE C      */
/*                                                           6.4.3        */
/*  AUTHOR                                                                */
/*                                                                        */
/*    Timothy Stapko, Microsoft Corporation                               */
/*                                                                        */
/*  DESCRIPTION                                                           */
/*                                                                        */
/*    This function moves a remote certificate buffer back into the free  */
/*    store. It is used when the remote certificate is no longer needed,  */
/*    such as when a TLS session is ended.                                */
/*                                                                        */
/*  INPUT                                                                 */
/*                                                                        */
/*    tls_session                           Pointer to TLS Session        */
/*    name                                  Certificate distinguished name*/
/*                                                                        */
/*  OUTPUT                                                                */
/*                                                                        */
/*    status                                Completion status             */
/*                                                                        */
/*  CALLS                                                                 */
/*                                                                        */
/*    _nx_secure_x509_certificate_list_find                               */
/*                                          Find certificate by name      */
/*    _nx_secure_x509_store_certificate_remove                            */
/*                                          Remove certificate from store */
/*    _nx_secure_x509_store_certificate_add                               */
/*                                          Add certificate to store      */
/*                                                                        */
/*  CALLED BY                                                             */
/*                                                                        */
/*    _nx_secure_tls_remote_certificate_free_all                          */
/*                                          Free all remote certificates  */
/*                                                                        */
/**************************************************************************/
UINT _nx_secure_tls_remote_certificate_free(NX_SECURE_TLS_SESSION *tls_session,
                                            NX_SECURE_X509_DISTINGUISHED_NAME *name)
{
#ifndef NX_SECURE_DISABLE_X509
UINT                              status;
NX_SECURE_X509_CERT              *list_head;
NX_SECURE_X509_CERTIFICATE_STORE *store;
NX_SECURE_X509_CERT              *certificate;

    /* Get the remote certificate store from our TLS session. */
    store = &tls_session -> nx_secure_tls_credentials.nx_secure_tls_certificate_store;

    /* Get the first certificate in the remote store. */
    list_head = store -> nx_secure_x509_remote_certificates;

    /* Find the certificate using it's name. */
    status = _nx_secure_x509_certificate_list_find(&list_head, name, 0, &certificate);

    /* Now status can only be NX_SECURE_X509_CERTIFICATE_NOT_FOUND or NX_SECURE_X509_SUCCESS as
       "&list_head" and "&certificate" are not NULL.
       Translate X.509 return values into TLS return values. */
    if (status == NX_SECURE_X509_CERTIFICATE_NOT_FOUND)
    {
        return(NX_SECURE_TLS_CERTIFICATE_NOT_FOUND);
    }

    /* Make sure status is NX_SECURE_X509_SUCCESS here. */
    NX_ASSERT(status == NX_SECURE_X509_SUCCESS);

    /* Remove the certificate from the remote store. */
    _nx_secure_x509_store_certificate_remove(store, name, NX_SECURE_X509_CERT_LOCATION_REMOTE, 0);

    /* Only user allocated certificate is added back to the free store. */
    if (certificate -> nx_secure_x509_user_allocated_cert)
    {

        /* Add the certificate back to the free store. */
        status = _nx_secure_x509_store_certificate_add(certificate, store, NX_SECURE_X509_CERT_LOCATION_FREE);

        if (status != NX_SUCCESS)
        {

            /* Translate some X.509 return values into TLS return values. */
            if (status == NX_SECURE_X509_CERT_ID_DUPLICATE)
            {
                return(NX_SECURE_TLS_CERT_ID_DUPLICATE);
            }

            return(status);
        }
    }

    /* Return completion status.  */
    return(status);
#else
    NX_PARAMETER_NOT_USED(tls_session);
    NX_PARAMETER_NOT_USED(name);

    return(NX_NOT_SUPPORTED);
#endif
}