diff --git a/mozilla/security/nss/lib/dev/devobject.c b/mozilla/security/nss/lib/dev/devobject.c index 2420d34a7d9..5d1bbf0f318 100644 --- a/mozilla/security/nss/lib/dev/devobject.c +++ b/mozilla/security/nss/lib/dev/devobject.c @@ -32,7 +32,7 @@ */ #ifdef DEBUG -static const char CVS_ID[] = "@(#) $RCSfile: devobject.c,v $ $Revision: 1.13 $ $Date: 2002-01-23 01:20:32 $ $Name: not supported by cvs2svn $"; +static const char CVS_ID[] = "@(#) $RCSfile: devobject.c,v $ $Revision: 1.14 $ $Date: 2002-01-23 17:00:34 $ $Name: not supported by cvs2svn $"; #endif /* DEBUG */ #ifndef DEV_H @@ -374,6 +374,25 @@ get_token_cert email = dc->getEmailAddress(dc); if (email) rvCert->email = nssUTF8_Duplicate(email, arena); + } else { + goto loser; + } + } + /* nss 3.4 must deal with tokens that do not follow the PKCS#11 + * standard and return decoded serial numbers. The easiest way to + * work around this is just to grab the serial # from the full encoding + */ + if (PR_TRUE) { + nssDecodedCert *dc; + dc = nssCertificate_GetDecoding(rvCert); + if (dc) { + PRStatus sn_stat; + sn_stat = dc->getDERSerialNumber(dc, &rvCert->serial, arena); + if (sn_stat != PR_SUCCESS) { + goto loser; + } + } else { + goto loser; } } #endif @@ -432,12 +451,11 @@ nssToken_ImportCertificate } static PRBool -compare_cert_by_issuer_sn(void *a, void *b) +compare_cert_by_encoding(void *a, void *b) { NSSCertificate *c1 = (NSSCertificate *)a; NSSCertificate *c2 = (NSSCertificate *)b; - return (nssItem_Equal(&c1->issuer, &c2->issuer, NULL) && - nssItem_Equal(&c1->serial, &c2->serial, NULL)); + return (nssItem_Equal(&c1->encoding, &c2->encoding, NULL)); } static PRStatus @@ -449,20 +467,14 @@ retrieve_cert(NSSToken *t, nssSession *session, CK_OBJECT_HANDLE h, void *arg) NSSCertificate *cert = NULL; nssListIterator *instances; nssCryptokiInstance *ci; - CK_ATTRIBUTE issuersn_tmpl[] = { - { CKA_ISSUER, NULL, 0 }, - { CKA_SERIAL_NUMBER, NULL, 0 } - }; - CK_ULONG ist_size = sizeof(issuersn_tmpl) / sizeof(issuersn_tmpl[0]); + CK_ATTRIBUTE derValue = { CKA_VALUE, NULL, 0 }; if (search->cached) { NSSCertificate csi; /* a fake cert for indexing */ - nssrv = nssCKObject_GetAttributes(h, issuersn_tmpl, ist_size, + nssrv = nssCKObject_GetAttributes(h, &derValue, 1, NULL, session, t->slot); - NSS_CK_ATTRIBUTE_TO_ITEM(&issuersn_tmpl[0], &csi.issuer); - NSS_CK_ATTRIBUTE_TO_ITEM(&issuersn_tmpl[1], &csi.serial); + NSS_CK_ATTRIBUTE_TO_ITEM(&derValue, &csi.encoding); cert = (NSSCertificate *)nssList_Get(search->cached, &csi); - nss_ZFreeIf(csi.issuer.data); - nss_ZFreeIf(csi.serial.data); + nss_ZFreeIf(csi.encoding.data); } found = PR_FALSE; if (cert) { @@ -527,7 +539,7 @@ nssToken_TraverseCertificates NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_CLASS, &g_ck_class_cert); NSS_CK_TEMPLATE_FINISH(cert_template, attr, ctsize); if (search->cached) { - nssList_SetCompareFunction(search->cached, compare_cert_by_issuer_sn); + nssList_SetCompareFunction(search->cached, compare_cert_by_encoding); } nssrv = traverse_objects_by_template(token, sessionOpt, cert_template, ctsize, @@ -559,7 +571,7 @@ nssToken_TraverseCertificatesBySubject NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_SUBJECT, subject); NSS_CK_TEMPLATE_FINISH(subj_template, attr, stsize); if (search->cached) { - nssList_SetCompareFunction(search->cached, compare_cert_by_issuer_sn); + nssList_SetCompareFunction(search->cached, compare_cert_by_encoding); } /* now traverse the token certs matching this template */ nssrv = traverse_objects_by_template(token, sessionOpt, @@ -592,7 +604,7 @@ nssToken_TraverseCertificatesByNickname NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_CLASS, &g_ck_class_cert); NSS_CK_TEMPLATE_FINISH(nick_template, attr, ntsize); if (search->cached) { - nssList_SetCompareFunction(search->cached, compare_cert_by_issuer_sn); + nssList_SetCompareFunction(search->cached, compare_cert_by_encoding); } /* now traverse the token certs matching this template */ nssrv = traverse_objects_by_template(token, sessionOpt, @@ -638,7 +650,7 @@ nssToken_TraverseCertificatesByEmail NSS_CK_SET_ATTRIBUTE_ITEM(attr, CKA_CLASS, &g_ck_class_cert); NSS_CK_TEMPLATE_FINISH(email_template, attr, etsize); if (search->cached) { - nssList_SetCompareFunction(search->cached, compare_cert_by_issuer_sn); + nssList_SetCompareFunction(search->cached, compare_cert_by_encoding); } /* now traverse the token certs matching this template */ nssrv = traverse_objects_by_template(token, sessionOpt, diff --git a/mozilla/security/nss/lib/pk11wrap/pk11util.c b/mozilla/security/nss/lib/pk11wrap/pk11util.c index 8c9e40d4b5b..ae4819ec7ca 100644 --- a/mozilla/security/nss/lib/pk11wrap/pk11util.c +++ b/mozilla/security/nss/lib/pk11wrap/pk11util.c @@ -245,7 +245,7 @@ SECMOD_DeleteModule(char *name, int *type) { if (!mlp->module->internal) { SECMOD_RemoveList(mlpp,mlp); /* delete it after we release the lock */ - rv = SECSuccess; + rv = STAN_RemoveModuleFromDefaultTrustDomain(mlp->module); } else if (mlp->module->isFIPS) { *type = SECMOD_FIPS; } else { @@ -279,8 +279,8 @@ SECMOD_DeleteInternalModule(char *name) { if (PORT_Strcmp(name,mlp->module->commonName) == 0) { /* don't delete the internal module */ if (mlp->module->internal) { - rv = SECSuccess; SECMOD_RemoveList(mlpp,mlp); + rv = STAN_RemoveModuleFromDefaultTrustDomain(mlp->module); } break; } @@ -323,6 +323,7 @@ SECMOD_DeleteInternalModule(char *name) { SECMOD_DestroyModule(oldModule); SECMOD_DeletePermDB(mlp->module); SECMOD_DestroyModuleListElement(mlp); + rv = STAN_AddModuleToDefaultTrustDomain(internalModule); } return rv; } @@ -331,7 +332,6 @@ SECStatus SECMOD_AddModule(SECMODModule *newModule) { SECStatus rv; SECMODModule *oldModule; - int i; /* Test if a module w/ the same name already exists */ /* and return SECWouldBlock if so. */ @@ -356,12 +356,9 @@ SECMOD_AddModule(SECMODModule *newModule) { SECMOD_AddPermDB(newModule); SECMOD_AddModuleToList(newModule); - for (i=0; i < newModule->slotCount; i++) { - PK11SlotInfo *slot = newModule->slots[i]; - STAN_AddNewSlotToDefaultTD(slot); - } + rv = STAN_AddModuleToDefaultTrustDomain(newModule); - return SECSuccess; + return rv; } PK11SlotInfo *SECMOD_FindSlot(SECMODModule *module,char *name) { diff --git a/mozilla/security/nss/lib/pki/pki3hack.c b/mozilla/security/nss/lib/pki/pki3hack.c index 6056cad16c8..70a5b809351 100644 --- a/mozilla/security/nss/lib/pki/pki3hack.c +++ b/mozilla/security/nss/lib/pki/pki3hack.c @@ -32,7 +32,7 @@ */ #ifdef DEBUG -static const char CVS_ID[] = "@(#) $RCSfile: pki3hack.c,v $ $Revision: 1.25 $ $Date: 2002-01-18 03:36:44 $ $Name: not supported by cvs2svn $"; +static const char CVS_ID[] = "@(#) $RCSfile: pki3hack.c,v $ $Revision: 1.26 $ $Date: 2002-01-23 17:00:38 $ $Name: not supported by cvs2svn $"; #endif /* DEBUG */ /* @@ -128,6 +128,45 @@ STAN_LoadDefaultNSS3TrustDomain g_default_crypto_context = NSSTrustDomain_CreateCryptoContext(td, NULL); } +NSS_IMPLEMENT SECStatus +STAN_AddModuleToDefaultTrustDomain +( + SECMODModule *module +) +{ + NSSToken *token; + NSSTrustDomain *td; + int i; + td = STAN_GetDefaultTrustDomain(); + for (i=0; islotCount; i++) { + token = nssToken_CreateFromPK11SlotInfo(td, module->slots[i]); + PK11Slot_SetNSSToken(module->slots[i], token); + nssList_Add(td->tokenList, token); + } + nssListIterator_Destroy(td->tokens); + td->tokens = nssList_CreateIterator(td->tokenList); + return SECSuccess; +} + +NSS_IMPLEMENT SECStatus +STAN_RemoveModuleFromDefaultTrustDomain +( + SECMODModule *module +) +{ + NSSToken *token; + NSSTrustDomain *td; + int i; + td = STAN_GetDefaultTrustDomain(); + for (i=0; islotCount; i++) { + token = PK11Slot_GetNSSToken(module->slots[i]); + nssList_Remove(td->tokenList, token); + } + nssListIterator_Destroy(td->tokens); + td->tokens = nssList_CreateIterator(td->tokenList); + return SECSuccess; +} + NSS_IMPLEMENT void STAN_Shutdown() { @@ -139,24 +178,6 @@ STAN_Shutdown() } } -NSS_IMPLEMENT PRStatus -STAN_AddNewSlotToDefaultTD -( - PK11SlotInfo *sl -) -{ - NSSTrustDomain *td =g_default_trust_domain; - NSSToken *token; - token = nssToken_CreateFromPK11SlotInfo(td, sl); - PK11Slot_SetNSSToken(sl, token); - nssList_Add(td->tokenList, token); - if (td->tokens) { - nssListIterator_Destroy(td->tokens); - } - td->tokens = nssList_CreateIterator(td->tokenList); - return PR_SUCCESS; -} - /* this function should not be a hack; it will be needed in 4.0 (rename) */ NSS_IMPLEMENT NSSItem * STAN_GetCertIdentifierFromDER(NSSArena *arenaOpt, NSSDER *der) @@ -321,6 +342,21 @@ nss3certificate_getEmailAddress(nssDecodedCert *dc) return cc ? (NSSASCII7 *)cc->emailAddr : NULL; } +static PRStatus +nss3certificate_getDERSerialNumber(nssDecodedCert *dc, + NSSDER *serial, NSSArena *arena) +{ + CERTCertificate *cc = (CERTCertificate *)dc->data; + SECItem derSerial = { 0 }; + SECStatus secrv; + secrv = CERT_SerialNumberFromDERCert(&cc->derCert, &derSerial); + if (secrv == SECSuccess) { + (void)nssItem_Create(arena, serial, derSerial.len, derSerial.data); + return PR_SUCCESS; + } + return PR_FAILURE; +} + NSS_IMPLEMENT nssDecodedCert * nssDecodedPKIXCertificate_Create ( @@ -342,6 +378,7 @@ nssDecodedPKIXCertificate_Create rvDC->isNewerThan = nss3certificate_isNewerThan; rvDC->matchUsage = nss3certificate_matchUsage; rvDC->getEmailAddress = nss3certificate_getEmailAddress; + rvDC->getDERSerialNumber = nss3certificate_getDERSerialNumber; return rvDC; } diff --git a/mozilla/security/nss/lib/pki/pki3hack.h b/mozilla/security/nss/lib/pki/pki3hack.h index d711bc1d1ef..5aea524146e 100644 --- a/mozilla/security/nss/lib/pki/pki3hack.h +++ b/mozilla/security/nss/lib/pki/pki3hack.h @@ -35,7 +35,7 @@ #define PKINSS3HACK_H #ifdef DEBUG -static const char PKINSS3HACK_CVS_ID[] = "@(#) $RCSfile: pki3hack.h,v $ $Revision: 1.3 $ $Date: 2001-11-29 19:34:06 $ $Name: not supported by cvs2svn $"; +static const char PKINSS3HACK_CVS_ID[] = "@(#) $RCSfile: pki3hack.h,v $ $Revision: 1.4 $ $Date: 2002-01-23 17:00:39 $ $Name: not supported by cvs2svn $"; #endif /* DEBUG */ #ifndef NSSPKIT_H @@ -69,10 +69,16 @@ STAN_LoadDefaultNSS3TrustDomain NSS_EXTERN void STAN_Shutdown(); -NSS_EXTERN PRStatus -STAN_AddNewSlotToDefaultTD +NSS_EXTERN SECStatus +STAN_AddModuleToDefaultTrustDomain ( - PK11SlotInfo *sl + SECMODModule *module +); + +NSS_IMPLEMENT SECStatus +STAN_RemoveModuleFromDefaultTrustDomain +( + SECMODModule *module ); NSS_EXTERN CERTCertificate * diff --git a/mozilla/security/nss/lib/pki/pkitm.h b/mozilla/security/nss/lib/pki/pkitm.h index 06787009bc4..481a42a5b0e 100644 --- a/mozilla/security/nss/lib/pki/pkitm.h +++ b/mozilla/security/nss/lib/pki/pkitm.h @@ -35,7 +35,7 @@ #define PKITM_H #ifdef DEBUG -static const char PKITM_CVS_ID[] = "@(#) $RCSfile: pkitm.h,v $ $Revision: 1.5 $ $Date: 2001-12-14 17:32:22 $ $Name: not supported by cvs2svn $"; +static const char PKITM_CVS_ID[] = "@(#) $RCSfile: pkitm.h,v $ $Revision: 1.6 $ $Date: 2002-01-23 17:00:39 $ $Name: not supported by cvs2svn $"; #endif /* DEBUG */ /* @@ -81,6 +81,9 @@ struct nssDecodedCertStr { PRBool (*matchUsage)(nssDecodedCert *dc, NSSUsage *usage); /* extract the email address */ NSSASCII7 *(*getEmailAddress)(nssDecodedCert *dc); + /* extract the DER-encoded serial number */ + PRStatus (*getDERSerialNumber)(nssDecodedCert *dc, + NSSDER *derSerial, NSSArena *arena); }; struct NSSUsageStr { diff --git a/mozilla/security/nss/lib/pki/trustdomain.c b/mozilla/security/nss/lib/pki/trustdomain.c index 2c57e606b3a..136f2c3e1bf 100644 --- a/mozilla/security/nss/lib/pki/trustdomain.c +++ b/mozilla/security/nss/lib/pki/trustdomain.c @@ -32,7 +32,7 @@ */ #ifdef DEBUG -static const char CVS_ID[] = "@(#) $RCSfile: trustdomain.c,v $ $Revision: 1.26 $ $Date: 2002-01-10 00:45:27 $ $Name: not supported by cvs2svn $"; +static const char CVS_ID[] = "@(#) $RCSfile: trustdomain.c,v $ $Revision: 1.27 $ $Date: 2002-01-23 17:00:39 $ $Name: not supported by cvs2svn $"; #endif /* DEBUG */ #ifndef NSSPKI_H @@ -511,6 +511,30 @@ NSSTrustDomain_FindCertificateByIssuerAndSerialNumber issuer, serialNumber, nssTokenSearchType_TokenOnly); +#ifdef NSS_3_4_CODE + if (!rvCert) { + /* Some tokens expect a decoded serial number. For compatibility, + * try the search again. + */ + NSSDER decodedSerial; + SECItem ds = { 0 }; + SECItem sn; + SECStatus secrv; + sn.data = serialNumber->data; + sn.len = serialNumber->size; + secrv = SEC_ASN1DecodeItem(NULL, &ds, SEC_IntegerTemplate, &sn); + if (secrv == SECSuccess) { + decodedSerial.data = ds.data; + decodedSerial.size = ds.len; + rvCert = nssToken_FindCertificateByIssuerAndSerialNumber(tok, + NULL, + issuer, + &decodedSerial, + nssTokenSearchType_TokenOnly); + PORT_Free(ds.data); + } + } +#endif if (rvCert) { /* cache it */ nssTrustDomain_AddCertsToCache(td, &rvCert, 1);