1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
|
/***************************************************************************
* Copyright (c) 2024 Microsoft Corporation
* Copyright (c) 2025-present Eclipse ThreadX Contributors
*
* This program and the accompanying materials are made available under the
* terms of the MIT License which is available at
* https://opensource.org/licenses/MIT.
*
* SPDX-License-Identifier: MIT
**************************************************************************/
/**************************************************************************/
/**************************************************************************/
/** */
/** NetX Secure Component */
/** */
/** X.509 Digital Certificates */
/** */
/**************************************************************************/
/**************************************************************************/
#define NX_SECURE_SOURCE_CODE
#include "nx_secure_x509.h"
/**************************************************************************/
/* */
/* FUNCTION RELEASE */
/* */
/* _nx_secure_x509_store_certificate_find PORTABLE C */
/* 6.4.3 */
/* AUTHOR */
/* */
/* Timothy Stapko, Microsoft Corporation */
/* */
/* DESCRIPTION */
/* */
/* This function finds a certificate in an X509 certificate store */
/* based on the Distinguished Name only. The actual position of the */
/* certificate is returned along with the certificate itself. */
/* */
/* INPUT */
/* */
/* store Pointer to certificate store */
/* name Distinguished name of cert */
/* cert_id Certificate ID */
/* certificate (Return) Pointer to cert */
/* location (Return) Location of cert */
/* */
/* OUTPUT */
/* */
/* status Completion status */
/* */
/* CALLS */
/* */
/* _nx_secure_x509_certificate_list_find Find certificate in list */
/* */
/* CALLED BY */
/* */
/* _nx_secure_x509_certificate_chain_verify */
/* Verify cert against stores */
/* _nx_secure_x509_crl_revocation_check Check revocation in crl */
/* */
/**************************************************************************/
UINT _nx_secure_x509_store_certificate_find(NX_SECURE_X509_CERTIFICATE_STORE *store,
NX_SECURE_X509_DISTINGUISHED_NAME *name,
UINT cert_id,
NX_SECURE_X509_CERT **certificate, UINT *location)
{
UINT status;
/* Name and store must be non-NULL. */
if (name == NX_CRYPTO_NULL || store == NX_CRYPTO_NULL || certificate == NX_CRYPTO_NULL || location == NX_CRYPTO_NULL)
{
#ifdef NX_CRYPTO_STANDALONE_ENABLE
return(NX_CRYPTO_PTR_ERROR);
#else
return(NX_PTR_ERROR);
#endif /* NX_CRYPTO_STANDALONE_ENABLE */
}
/* Search each location in turn. */
/* Start with trusted certificates - if we find one, we are probably done! */
status = _nx_secure_x509_certificate_list_find(&store -> nx_secure_x509_trusted_certificates, name, cert_id, certificate);
if (status == NX_SECURE_X509_SUCCESS)
{
*location = NX_SECURE_X509_CERT_LOCATION_TRUSTED;
return(NX_SECURE_X509_SUCCESS);
}
/* Next, local certificates. */
status = _nx_secure_x509_certificate_list_find(&store -> nx_secure_x509_local_certificates, name, cert_id, certificate);
if (status == NX_SECURE_X509_SUCCESS)
{
*location = NX_SECURE_X509_CERT_LOCATION_LOCAL;
return(NX_SECURE_X509_SUCCESS);
}
/* Finally, check remote certs. */
status = _nx_secure_x509_certificate_list_find(&store -> nx_secure_x509_remote_certificates, name, cert_id, certificate);
if (status == NX_SECURE_X509_SUCCESS)
{
*location = NX_SECURE_X509_CERT_LOCATION_REMOTE;
return(NX_SECURE_X509_SUCCESS);
}
/* If we get here, the certificate was not found in any of the stores. */
*location = NX_SECURE_X509_CERT_LOCATION_NONE;
return(NX_SECURE_X509_CERTIFICATE_NOT_FOUND);
}
|