summaryrefslogtreecommitdiff
path: root/nx_secure/src/nx_secure_x509_certificate_list_find.c
blob: 5e36ebe416c8b9e9ee59cb2059308b0f6b39e618 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
/***************************************************************************
 * Copyright (c) 2024 Microsoft Corporation
 * Copyright (c) 2025-present Eclipse ThreadX Contributors
 *
 * This program and the accompanying materials are made available under the
 * terms of the MIT License which is available at
 * https://opensource.org/licenses/MIT.
 *
 * SPDX-License-Identifier: MIT
 **************************************************************************/


/**************************************************************************/
/**************************************************************************/
/**                                                                       */
/** NetX Secure Component                                                 */
/**                                                                       */
/**    X.509 Digital Certificates                                         */
/**                                                                       */
/**************************************************************************/
/**************************************************************************/

#define NX_SECURE_SOURCE_CODE

#include "nx_secure_x509.h"

/**************************************************************************/
/*                                                                        */
/*  FUNCTION                                               RELEASE        */
/*                                                                        */
/*    _nx_secure_x509_certificate_list_find               PORTABLE C      */
/*                                                           6.4.3        */
/*  AUTHOR                                                                */
/*                                                                        */
/*    Timothy Stapko, Microsoft Corporation                               */
/*                                                                        */
/*  DESCRIPTION                                                           */
/*                                                                        */
/*    This function finds a NX_SECURE_X509_CERT instance in a             */
/*    certificate linked list, based on the common name (CN) field.       */
/*                                                                        */
/*  INPUT                                                                 */
/*                                                                        */
/*    list_head                             Pointer to list head pointer  */
/*    name                                  Distinguished name            */
/*    cert_id                               ID of certificate             */
/*    certificate                           Pointer to return certificate */
/*                                                                        */
/*  OUTPUT                                                                */
/*                                                                        */
/*    status                                Completion status             */
/*                                                                        */
/*  CALLS                                                                 */
/*                                                                        */
/*    _nx_secure_x509_distinguished_name_compare                          */
/*                                          Compare distinguished name    */
/*                                                                        */
/*  CALLED BY                                                             */
/*                                                                        */
/*    _nx_secure_tls_local_certificate_find                               */
/*                                          Find local certificate        */
/*    _nx_secure_tls_remote_certificate_free                              */
/*                                          Free remote certificate       */
/*    _nx_secure_x509_local_device_certificate_get                        */
/*                                          Get the local certificate     */
/*    _nx_secure_x509_store_certificate_find                              */
/*                                          Find a cert in a store        */
/*                                                                        */
/**************************************************************************/
UINT _nx_secure_x509_certificate_list_find(NX_SECURE_X509_CERT **list_head,
                                           NX_SECURE_X509_DISTINGUISHED_NAME *name,
                                           UINT cert_id,
                                           NX_SECURE_X509_CERT **certificate)
{
NX_SECURE_X509_CERT *current_cert;
INT                  compare_result;


    /* Find out NULL pointers. */
    if (certificate == NX_CRYPTO_NULL)
    {
#ifdef NX_CRYPTO_STANDALONE_ENABLE
        return(NX_CRYPTO_PTR_ERROR);
#else
        return(NX_PTR_ERROR);
#endif /* NX_CRYPTO_STANDALONE_ENABLE */
    }

    /* Return NULL if certificate not found. */
    *certificate = NX_CRYPTO_NULL;

    if (list_head == NX_CRYPTO_NULL)
    {
#ifdef NX_CRYPTO_STANDALONE_ENABLE
        return(NX_CRYPTO_PTR_ERROR);
#else
        return(NX_PTR_ERROR);
#endif /* NX_CRYPTO_STANDALONE_ENABLE */
    }

    /* Walk the list until we find a certificate with a matching CN.
       Use a two-level pointer so we can modify the cert easily. */
    current_cert = *list_head;

    while (current_cert != NX_CRYPTO_NULL)
    {
        /* If name is passed as NX_NULL, use the cert_id to match. */
        if (name == NX_CRYPTO_NULL)
        {
            /* Check the cert_id against the ID in the certificate. */
            compare_result = (current_cert -> nx_secure_x509_cert_identifier == cert_id) ? 0 : 1;
        }
        else
        {
            /* Check the common name passed in against the parsed certificate CN. */
            compare_result = _nx_secure_x509_distinguished_name_compare(name, &current_cert -> nx_secure_x509_distinguished_name, NX_SECURE_X509_NAME_COMMON_NAME);
        }

        /* We found a match, return it. */
        if (!compare_result)
        {
            *certificate = current_cert;
            return(NX_SECURE_X509_SUCCESS);
        }

        /* Advance our current certificate pointer. */
        current_cert = current_cert -> nx_secure_x509_next_certificate;
    }

    return(NX_SECURE_X509_CERTIFICATE_NOT_FOUND);
}