summaryrefslogtreecommitdiff
path: root/nx_secure/src/nx_secure_x509_store_certificate_add.c
blob: adfc3beecbf4a83046c0faa8bb46dd9f76742901 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
/***************************************************************************
 * Copyright (c) 2024 Microsoft Corporation
 * Copyright (c) 2025-present Eclipse ThreadX Contributors
 *
 * This program and the accompanying materials are made available under the
 * terms of the MIT License which is available at
 * https://opensource.org/licenses/MIT.
 *
 * SPDX-License-Identifier: MIT
 **************************************************************************/


/**************************************************************************/
/**************************************************************************/
/**                                                                       */
/** NetX Secure Component                                                 */
/**                                                                       */
/**    X.509 Digital Certificates                                         */
/**                                                                       */
/**************************************************************************/
/**************************************************************************/

#define NX_SECURE_SOURCE_CODE

#include "nx_secure_x509.h"

/**************************************************************************/
/*                                                                        */
/*  FUNCTION                                               RELEASE        */
/*                                                                        */
/*    _nx_secure_x509_store_certificate_add               PORTABLE C      */
/*                                                           6.4.3        */
/*  AUTHOR                                                                */
/*                                                                        */
/*    Timothy Stapko, Microsoft Corporation                               */
/*                                                                        */
/*  DESCRIPTION                                                           */
/*                                                                        */
/*    This function adds a certificate to an X509 certificate store in a  */
/*    caller-specified position (local device certificates, remote certs, */
/*    or the trusted store).                                              */
/*                                                                        */
/*  INPUT                                                                 */
/*                                                                        */
/*    certificate                           Pointer to certificate        */
/*    store                                 Pointer to certificate store  */
/*    location                              Location to put certificate   */
/*                                                                        */
/*  OUTPUT                                                                */
/*                                                                        */
/*    status                                Completion status             */
/*                                                                        */
/*  CALLS                                                                 */
/*                                                                        */
/*    _nx_secure_x509_certificate_list_add  Add certificate to list       */
/*                                                                        */
/*  CALLED BY                                                             */
/*                                                                        */
/*    _nx_secure_tls_local_certificate_add  Add local certificate to      */
/*                                            TLS session                 */
/*    _nx_secure_tls_remote_certificate_allocate                          */
/*                                          Allocate remote certificate   */
/*    _nx_secure_tls_remote_certificate_free                              */
/*                                          Free remote certificate       */
/*    _nx_secure_tls_trusted_certificate_add                              */
/*                                          Add trusted certificate to    */
/*                                            TLS session                 */
/*                                                                        */
/**************************************************************************/
UINT _nx_secure_x509_store_certificate_add(NX_SECURE_X509_CERT *certificate,
                                           NX_SECURE_X509_CERTIFICATE_STORE *store, UINT location)
{
UINT                  status;
NX_SECURE_X509_CERT **store_ptr = NX_CRYPTO_NULL;
UINT                  duplicates_ok = NX_CRYPTO_FALSE;

    /* Certificate and store must be non-NULL. */
    if (certificate == NX_CRYPTO_NULL || store == NX_CRYPTO_NULL)
    {
#ifdef NX_CRYPTO_STANDALONE_ENABLE
        return(NX_CRYPTO_PTR_ERROR);
#else
        return(NX_PTR_ERROR);
#endif /* NX_CRYPTO_STANDALONE_ENABLE */
    }

    status = NX_SECURE_X509_SUCCESS;

    /* Pick our store based on location. */
    switch (location)
    {
    case NX_SECURE_X509_CERT_LOCATION_LOCAL:
        store_ptr = &store -> nx_secure_x509_local_certificates;
        break;
    case NX_SECURE_X509_CERT_LOCATION_REMOTE:
        store_ptr = &store -> nx_secure_x509_remote_certificates;
        break;
    case NX_SECURE_X509_CERT_LOCATION_TRUSTED:
        store_ptr = &store -> nx_secure_x509_trusted_certificates;
        break;
    case NX_SECURE_X509_CERT_LOCATION_EXCEPTIONS:
        store_ptr = &store -> nx_secure_x509_certificate_exceptions;
        break;
    case NX_SECURE_X509_CERT_LOCATION_FREE:
        store_ptr = &store -> nx_secure_x509_free_certificates;
        duplicates_ok = NX_CRYPTO_TRUE;
        break;
    case NX_SECURE_X509_CERT_LOCATION_NONE:     /* Deliberate fall-through. */
    default:
#ifdef NX_CRYPTO_STANDALONE_ENABLE
        status = NX_CRYPTO_INVALID_PARAMETER;
#else
        status = NX_INVALID_PARAMETERS;
#endif /* NX_CRYPTO_STANDALONE_ENABLE */
        break;
    }

    /* If we are adding a certificate with a numeric identifier, it is OK to add duplicates. */
    if (certificate -> nx_secure_x509_cert_identifier != 0)
    {
        duplicates_ok = NX_CRYPTO_TRUE;
    }

    /* Invalid certificate location or other issue. */
    if (status)
    {
        return(status);
    }

    /* Add the certificate to the selected store. */
    status = _nx_secure_x509_certificate_list_add(store_ptr, certificate, duplicates_ok);

    return(status);
}