sig_24.c 11.7 KB
Newer Older
1
/*
Brian Wellington's avatar
Brian Wellington committed
2
 * Copyright (C) 1999-2001  Internet Software Consortium.
3
 *
4 5 6
 * Permission to use, copy, modify, and distribute this software for any
 * purpose with or without fee is hereby granted, provided that the above
 * copyright notice and this permission notice appear in all copies.
7
 *
8 9 10 11 12 13 14 15
 * THE SOFTWARE IS PROVIDED "AS IS" AND INTERNET SOFTWARE CONSORTIUM
 * DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL
 * INTERNET SOFTWARE CONSORTIUM BE LIABLE FOR ANY SPECIAL, DIRECT,
 * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING
 * FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT,
 * NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION
 * WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16 17
 */

18
/* $Id: sig_24.c,v 1.50 2001/02/12 03:04:55 bwelling Exp $ */
19

20 21 22
/* Reviewed: Fri Mar 17 09:05:02 PST 2000 by gson */

/* RFC 2535 */
23

24 25
#ifndef RDATA_GENERIC_SIG_24_C
#define RDATA_GENERIC_SIG_24_C
26

27 28
#define RRTYPE_SIG_ATTRIBUTES (DNS_RDATATYPEATTR_DNSSEC)

29
static inline isc_result_t
David Lawrence's avatar
David Lawrence committed
30
fromtext_sig(ARGS_FROMTEXT) {
31
	isc_token_t token;
32
	unsigned char c;
33
	long i;
34 35
	dns_rdatatype_t covered;
	char *e;
36
	isc_result_t result;
37 38
	dns_name_t name;
	isc_buffer_t buffer;
39
	isc_uint32_t time_signed, time_expire;
40 41 42

	REQUIRE(type == 24);

43
	UNUSED(rdclass);
44

David Lawrence's avatar
David Lawrence committed
45 46 47
	/*
	 * Type covered.
	 */
48 49
	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
				      ISC_FALSE));
50
	result = dns_rdatatype_fromtext(&covered, &token.value.as_textregion);
51
	if (result != ISC_R_SUCCESS && result != ISC_R_NOTIMPLEMENTED) {
52 53
		i = strtol(token.value.as_pointer, &e, 10);
		if (i < 0 || i > 65535)
David Lawrence's avatar
David Lawrence committed
54
			return (ISC_R_RANGE);
55
		if (*e != 0)
56
			return (result);
57
		covered = (dns_rdatatype_t)i;
58 59 60
	}
	RETERR(uint16_tobuffer(covered, target));

David Lawrence's avatar
David Lawrence committed
61 62 63
	/*
	 * Algorithm.
	 */
64 65
	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
				      ISC_FALSE));
66
	RETERR(dns_secalg_fromtext(&c, &token.value.as_textregion));
67 68
	RETERR(mem_tobuffer(target, &c, 1));

David Lawrence's avatar
David Lawrence committed
69 70 71
	/*
	 * Labels.
	 */
72 73
	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_number,
				      ISC_FALSE));
74
	if (token.value.as_ulong > 0xff)
David Lawrence's avatar
David Lawrence committed
75
		return (ISC_R_RANGE);
76
	c = (unsigned char)token.value.as_ulong;
77 78
	RETERR(mem_tobuffer(target, &c, 1));

David Lawrence's avatar
David Lawrence committed
79 80 81
	/*
	 * Original ttl.
	 */
82 83
	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_number,
				      ISC_FALSE));
84 85
	RETERR(uint32_tobuffer(token.value.as_ulong, target));

David Lawrence's avatar
David Lawrence committed
86 87 88
	/*
	 * Signature expiration.
	 */
89 90
	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
				      ISC_FALSE));
91 92
	RETERR(dns_time32_fromtext(token.value.as_pointer, &time_expire));
	RETERR(uint32_tobuffer(time_expire, target));
93

David Lawrence's avatar
David Lawrence committed
94 95 96
	/*
	 * Time signed.
	 */
97 98
	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
				      ISC_FALSE));
99 100
	RETERR(dns_time32_fromtext(token.value.as_pointer, &time_signed));
	RETERR(uint32_tobuffer(time_signed, target));
101

David Lawrence's avatar
David Lawrence committed
102 103 104
	/*
	 * Key footprint.
	 */
105 106
	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_number,
				      ISC_FALSE));
107
	RETERR(uint16_tobuffer(token.value.as_ulong, target));
108

David Lawrence's avatar
David Lawrence committed
109 110 111
	/*
	 * Signer.
	 */
112 113
	RETERR(isc_lex_getmastertoken(lexer, &token, isc_tokentype_string,
				      ISC_FALSE));
114
	dns_name_init(&name, NULL);
115
	buffer_fromregion(&buffer, &token.value.as_region);
116 117 118
	origin = (origin != NULL) ? origin : dns_rootname;
	RETERR(dns_name_fromtext(&name, &buffer, origin, downcase, target));

David Lawrence's avatar
David Lawrence committed
119 120 121
	/*
	 * Sig.
	 */
122
	return (isc_base64_tobuffer(lexer, target, -1));
123 124
}

125
static inline isc_result_t
David Lawrence's avatar
David Lawrence committed
126
totext_sig(ARGS_TOTEXT) {
127 128 129 130 131 132 133 134 135 136 137 138
	isc_region_t sr;
	char buf[sizeof "4294967295"];
	dns_rdatatype_t covered;
	unsigned long ttl;
	unsigned long when;
	unsigned long exp;
	unsigned long foot;
	dns_name_t name;
	dns_name_t prefix;
	isc_boolean_t sub;

	REQUIRE(rdata->type == 24);
139
	REQUIRE(rdata->length != 0);
140 141 142

	dns_rdata_toregion(rdata, &sr);

David Lawrence's avatar
David Lawrence committed
143 144 145
	/*
	 * Type covered.
	 */
146 147
	covered = uint16_fromregion(&sr);
	isc_region_consume(&sr, 2);
148 149 150 151 152 153 154 155 156 157 158
	/*
	 * XXXAG We should have something like dns_rdatatype_isknown()
	 * that does the right thing with type 0.
	 */
	if (dns_rdatatype_isknown(covered) && covered != 0) {
		RETERR(dns_rdatatype_totext(covered, target));
	} else {
		char buf[sizeof "65535"];
		sprintf(buf, "%u", covered);
		RETERR(str_totext(buf, target));
	}
159 160
	RETERR(str_totext(" ", target));

David Lawrence's avatar
David Lawrence committed
161 162 163
	/*
	 * Algorithm.
	 */
164 165 166 167 168
	sprintf(buf, "%u", sr.base[0]);
	isc_region_consume(&sr, 1);
	RETERR(str_totext(buf, target));
	RETERR(str_totext(" ", target));

David Lawrence's avatar
David Lawrence committed
169 170 171
	/*
	 * Labels.
	 */
172 173 174 175 176
	sprintf(buf, "%u", sr.base[0]);
	isc_region_consume(&sr, 1);
	RETERR(str_totext(buf, target));
	RETERR(str_totext(" ", target));

David Lawrence's avatar
David Lawrence committed
177 178 179
	/*
	 * Ttl.
	 */
180 181
	ttl = uint32_fromregion(&sr);
	isc_region_consume(&sr, 4);
182
	sprintf(buf, "%lu", ttl);
183 184 185
	RETERR(str_totext(buf, target));
	RETERR(str_totext(" ", target));

David Lawrence's avatar
David Lawrence committed
186 187 188
	/*
	 * Sig exp.
	 */
189 190
	exp = uint32_fromregion(&sr);
	isc_region_consume(&sr, 4);
191
	RETERR(dns_time32_totext(exp, target));
192

193 194
	if ((tctx->flags & DNS_STYLEFLAG_MULTILINE) != 0)
		RETERR(str_totext(" (", target));
195 196
	RETERR(str_totext(tctx->linebreak, target));

David Lawrence's avatar
David Lawrence committed
197 198 199
	/*
	 * Time signed.
	 */
200 201
	when = uint32_fromregion(&sr);
	isc_region_consume(&sr, 4);
202
	RETERR(dns_time32_totext(when, target));
203 204
	RETERR(str_totext(" ", target));

David Lawrence's avatar
David Lawrence committed
205 206 207
	/*
	 * Footprint.
	 */
208 209
	foot = uint16_fromregion(&sr);
	isc_region_consume(&sr, 2);
210
	sprintf(buf, "%lu", foot);
211 212 213
	RETERR(str_totext(buf, target));
	RETERR(str_totext(" ", target));

David Lawrence's avatar
David Lawrence committed
214 215 216
	/*
	 * Signer.
	 */
217 218 219
	dns_name_init(&name, NULL);
	dns_name_init(&prefix, NULL);
	dns_name_fromregion(&name, &sr);
Mark Andrews's avatar
Mark Andrews committed
220
	isc_region_consume(&sr, name_length(&name));
221
	sub = name_prefix(&name, tctx->origin, &prefix);
222 223
	RETERR(dns_name_totext(&prefix, sub, target));

David Lawrence's avatar
David Lawrence committed
224 225 226
	/*
	 * Sig.
	 */
227 228 229
	RETERR(str_totext(tctx->linebreak, target));
	RETERR(isc_base64_totext(&sr, tctx->width - 2,
				    tctx->linebreak, target));
230 231
	if ((tctx->flags & DNS_STYLEFLAG_MULTILINE) != 0)
		RETERR(str_totext(" )", target));
232

233
	return (ISC_R_SUCCESS);
234 235
}

236
static inline isc_result_t
David Lawrence's avatar
David Lawrence committed
237
fromwire_sig(ARGS_FROMWIRE) {
238 239 240 241
	isc_region_t sr;
	dns_name_t name;

	REQUIRE(type == 24);
Mark Andrews's avatar
Mark Andrews committed
242

243
	dns_decompress_setmethods(dctx, DNS_COMPRESS_NONE);
244

245
	UNUSED(rdclass);
246

247
	isc_buffer_activeregion(source, &sr);
248 249 250 251 252 253 254 255 256 257
	/*
	 * type covered: 2
	 * algorithm: 1
	 * labels: 1
	 * original ttl: 4
	 * signature expiration: 4
	 * time signed: 4
	 * key footprint: 2
	 */
	if (sr.length < 18)
258
		return (ISC_R_UNEXPECTEDEND);
259 260

	isc_buffer_forward(source, 18);
Mark Andrews's avatar
Mark Andrews committed
261
	RETERR(mem_tobuffer(target, sr.base, 18));
262

David Lawrence's avatar
David Lawrence committed
263 264 265
	/*
	 * Signer.
	 */
266 267 268
	dns_name_init(&name, NULL);
	RETERR(dns_name_fromwire(&name, source, dctx, downcase, target));

David Lawrence's avatar
David Lawrence committed
269 270 271
	/*
	 * Sig.
	 */
272
	isc_buffer_activeregion(source, &sr);
Mark Andrews's avatar
Mark Andrews committed
273
	isc_buffer_forward(source, sr.length);
274
	return (mem_tobuffer(target, sr.base, sr.length));
275 276
}

277
static inline isc_result_t
David Lawrence's avatar
David Lawrence committed
278
towire_sig(ARGS_TOWIRE) {
279 280
	isc_region_t sr;
	dns_name_t name;
281
	dns_offsets_t offsets;
282 283

	REQUIRE(rdata->type == 24);
284
	REQUIRE(rdata->length != 0);
285

286
	dns_compress_setmethods(cctx, DNS_COMPRESS_NONE);
287 288 289 290 291 292 293 294 295 296 297 298 299
	dns_rdata_toregion(rdata, &sr);
	/*
	 * type covered: 2
	 * algorithm: 1
	 * labels: 1
	 * original ttl: 4
	 * signature expiration: 4
	 * time signed: 4
	 * key footprint: 2
	 */
	RETERR(mem_tobuffer(target, sr.base, 18));
	isc_region_consume(&sr, 18);

David Lawrence's avatar
David Lawrence committed
300 301 302
	/*
	 * Signer.
	 */
303
	dns_name_init(&name, offsets);
304
	dns_name_fromregion(&name, &sr);
305
	isc_region_consume(&sr, name_length(&name));
306 307
	RETERR(dns_name_towire(&name, cctx, target));

David Lawrence's avatar
David Lawrence committed
308 309 310
	/*
	 * Signature.
	 */
311 312 313
	return (mem_tobuffer(target, sr.base, sr.length));
}

314
static inline int
David Lawrence's avatar
David Lawrence committed
315
compare_sig(ARGS_COMPARE) {
316 317 318 319
	isc_region_t r1;
	isc_region_t r2;
	dns_name_t name1;
	dns_name_t name2;
320
	int order;
321 322

	REQUIRE(rdata1->type == rdata2->type);
323
	REQUIRE(rdata1->rdclass == rdata2->rdclass);
324
	REQUIRE(rdata1->type == 24);
325 326
	REQUIRE(rdata1->length != 0);
	REQUIRE(rdata2->length != 0);
327 328 329 330 331 332 333 334

	dns_rdata_toregion(rdata1, &r1);
	dns_rdata_toregion(rdata2, &r2);

	INSIST(r1.length > 18);
	INSIST(r2.length > 18);
	r1.length = 18;
	r2.length = 18;
335 336 337
	order = compare_region(&r1, &r2);
	if (order != 0)
		return (order);
338 339 340 341 342 343 344 345 346

	dns_name_init(&name1, NULL);
	dns_name_init(&name2, NULL);
	dns_rdata_toregion(rdata1, &r1);
	dns_rdata_toregion(rdata2, &r2);
	isc_region_consume(&r1, 18);
	isc_region_consume(&r2, 18);
	dns_name_fromregion(&name1, &r1);
	dns_name_fromregion(&name2, &r2);
347 348 349
	order = dns_name_rdatacompare(&name1, &name2);
	if (order != 0)
		return (order);
350

351 352 353 354 355 356
	isc_region_consume(&r1, name_length(&name1));
	isc_region_consume(&r2, name_length(&name2));

	return (compare_region(&r1, &r2));
}

357
static inline isc_result_t
David Lawrence's avatar
David Lawrence committed
358
fromstruct_sig(ARGS_FROMSTRUCT) {
359
	dns_rdata_sig_t *sig = source;
360 361

	REQUIRE(type == 24);
362 363 364 365 366
	REQUIRE(source != NULL);
	REQUIRE(sig->common.rdtype == type);
	REQUIRE(sig->common.rdclass == rdclass);
	REQUIRE((sig->signature != NULL && sig->siglen != 0) ||
		(sig->signature == NULL && sig->siglen == 0));
367

368 369
	UNUSED(rdclass);

David Lawrence's avatar
David Lawrence committed
370 371 372
	/*
	 * Type covered.
	 */
373 374
	RETERR(uint16_tobuffer(sig->covered, target));

David Lawrence's avatar
David Lawrence committed
375 376 377
	/*
	 * Algorithm.
	 */
378 379
	RETERR(uint8_tobuffer(sig->algorithm, target));

David Lawrence's avatar
David Lawrence committed
380 381 382
	/*
	 * Labels.
	 */
383 384
	RETERR(uint8_tobuffer(sig->labels, target));

David Lawrence's avatar
David Lawrence committed
385 386 387
	/*
	 * Original TTL.
	 */
388 389
	RETERR(uint32_tobuffer(sig->originalttl, target));

David Lawrence's avatar
David Lawrence committed
390 391 392
	/*
	 * Expire time.
	 */
393 394
	RETERR(uint32_tobuffer(sig->timeexpire, target));

David Lawrence's avatar
David Lawrence committed
395 396 397
	/*
	 * Time signed.
	 */
398 399
	RETERR(uint32_tobuffer(sig->timesigned, target));

David Lawrence's avatar
David Lawrence committed
400 401 402
	/*
	 * Key ID.
	 */
403 404
	RETERR(uint16_tobuffer(sig->keyid, target));

David Lawrence's avatar
David Lawrence committed
405 406 407
	/*
	 * Signer name.
	 */
408
	RETERR(name_tobuffer(&sig->signer, target));
409

David Lawrence's avatar
David Lawrence committed
410 411 412
	/*
	 * Signature.
	 */
413
	return (mem_tobuffer(target, sig->signature, sig->siglen));
414 415
}

416
static inline isc_result_t
David Lawrence's avatar
David Lawrence committed
417
tostruct_sig(ARGS_TOSTRUCT) {
418
	isc_region_t sr;
419
	dns_rdata_sig_t *sig = target;
420
	dns_name_t signer;
421 422

	REQUIRE(rdata->type == 24);
423
	REQUIRE(target != NULL);
424
	REQUIRE(rdata->length != 0);
425

426 427 428
	sig->common.rdclass = rdata->rdclass;
	sig->common.rdtype = rdata->type;
	ISC_LINK_INIT(&sig->common, link);
429

430 431
	dns_rdata_toregion(rdata, &sr);

David Lawrence's avatar
David Lawrence committed
432 433 434
	/*
	 * Type covered.
	 */
435 436 437
	sig->covered = uint16_fromregion(&sr);
	isc_region_consume(&sr, 2);

David Lawrence's avatar
David Lawrence committed
438 439 440
	/*
	 * Algorithm.
	 */
441 442 443
	sig->algorithm = uint8_fromregion(&sr);
	isc_region_consume(&sr, 1);

David Lawrence's avatar
David Lawrence committed
444 445 446
	/*
	 * Labels.
	 */
447 448 449
	sig->labels = uint8_fromregion(&sr);
	isc_region_consume(&sr, 1);

David Lawrence's avatar
David Lawrence committed
450 451 452
	/*
	 * Original TTL.
	 */
453 454 455
	sig->originalttl = uint32_fromregion(&sr);
	isc_region_consume(&sr, 4);

David Lawrence's avatar
David Lawrence committed
456 457 458
	/*
	 * Expire time.
	 */
459 460 461
	sig->timeexpire = uint32_fromregion(&sr);
	isc_region_consume(&sr, 4);

David Lawrence's avatar
David Lawrence committed
462 463 464
	/*
	 * Time signed.
	 */
465 466 467
	sig->timesigned = uint32_fromregion(&sr);
	isc_region_consume(&sr, 4);

David Lawrence's avatar
David Lawrence committed
468 469 470
	/*
	 * Key ID.
	 */
471 472 473 474 475
	sig->keyid = uint16_fromregion(&sr);
	isc_region_consume(&sr, 2);

	dns_name_init(&signer, NULL);
	dns_name_fromregion(&signer, &sr);
476
	dns_name_init(&sig->signer, NULL);
477
	RETERR(name_duporclone(&signer, mctx, &sig->signer));
478
	isc_region_consume(&sr, name_length(&sig->signer));
479

David Lawrence's avatar
David Lawrence committed
480 481 482
	/*
	 * Signature.
	 */
483
	sig->siglen = sr.length;
484 485 486 487 488 489 490
	if (sig->siglen > 0) {
		sig->signature = mem_maybedup(mctx, sr.base, sig->siglen);
		if (sig->signature == NULL)
			goto cleanup;
	} else
		sig->signature = NULL;

491

492
	sig->mctx = mctx;
493
	return (ISC_R_SUCCESS);
494 495 496 497 498

 cleanup:
	if (mctx != NULL)
		dns_name_free(&sig->signer, mctx);
	return (ISC_R_NOMEMORY);
499
}
500

501
static inline void
David Lawrence's avatar
David Lawrence committed
502
freestruct_sig(ARGS_FREESTRUCT) {
503
	dns_rdata_sig_t *sig = (dns_rdata_sig_t *) source;
504

505
	REQUIRE(source != NULL);
506 507
	REQUIRE(sig->common.rdtype == 24);

508 509 510
	if (sig->mctx == NULL)
		return;

511
	dns_name_free(&sig->signer, sig->mctx);
512
	if (sig->signature != NULL)
513 514
		isc_mem_free(sig->mctx, sig->signature);
	sig->mctx = NULL;
515
}
516

517
static inline isc_result_t
David Lawrence's avatar
David Lawrence committed
518
additionaldata_sig(ARGS_ADDLDATA) {
519 520
	REQUIRE(rdata->type == 24);

521
	UNUSED(rdata);
522 523
	UNUSED(add);
	UNUSED(arg);
524

525
	return (ISC_R_SUCCESS);
526 527
}

528
static inline isc_result_t
David Lawrence's avatar
David Lawrence committed
529
digest_sig(ARGS_DIGEST) {
Bob Halley's avatar
Bob Halley committed
530 531 532

	REQUIRE(rdata->type == 24);

533
	UNUSED(rdata);
534 535
	UNUSED(digest);
	UNUSED(arg);
Bob Halley's avatar
Bob Halley committed
536

537
	return (ISC_R_NOTIMPLEMENTED);
Bob Halley's avatar
Bob Halley committed
538 539 540 541 542 543 544 545 546 547 548 549 550 551 552
}

static inline dns_rdatatype_t
covers_sig(dns_rdata_t *rdata) {
	dns_rdatatype_t type;
	isc_region_t r;

	REQUIRE(rdata->type == 24);

	dns_rdata_toregion(rdata, &r);
	type = uint16_fromregion(&r);

	return (type);
}

553
#endif	/* RDATA_GENERIC_SIG_24_C */