• Home
  • Raw
  • Download

Lines Matching refs:dane

170 static void dane_final(SSL_DANE *dane)  in dane_final()  argument
172 sk_danetls_record_pop_free(dane->trecs, tlsa_free); in dane_final()
173 dane->trecs = NULL; in dane_final()
175 sk_X509_pop_free(dane->certs, X509_free); in dane_final()
176 dane->certs = NULL; in dane_final()
178 X509_free(dane->mcert); in dane_final()
179 dane->mcert = NULL; in dane_final()
180 dane->mtlsa = NULL; in dane_final()
181 dane->mdpth = -1; in dane_final()
182 dane->pdpth = -1; in dane_final()
193 if (!DANETLS_ENABLED(&from->dane)) in ssl_dane_dup()
196 num = sk_danetls_record_num(from->dane.trecs); in ssl_dane_dup()
197 dane_final(&to->dane); in ssl_dane_dup()
198 to->dane.flags = from->dane.flags; in ssl_dane_dup()
199 to->dane.dctx = &to->ctx->dane; in ssl_dane_dup()
200 to->dane.trecs = sk_danetls_record_new_reserve(NULL, num); in ssl_dane_dup()
202 if (to->dane.trecs == NULL) { in ssl_dane_dup()
208 danetls_record *t = sk_danetls_record_value(from->dane.trecs, i); in ssl_dane_dup()
262 static const EVP_MD *tlsa_md_get(SSL_DANE *dane, uint8_t mtype) in tlsa_md_get() argument
264 if (mtype > dane->dctx->mdmax) in tlsa_md_get()
266 return dane->dctx->mdevp[mtype]; in tlsa_md_get()
269 static int dane_tlsa_add(SSL_DANE *dane, in dane_tlsa_add() argument
280 if (dane->trecs == NULL) { in dane_tlsa_add()
301 md = tlsa_md_get(dane, mtype); in dane_tlsa_add()
366 if ((dane->certs == NULL && in dane_tlsa_add()
367 (dane->certs = sk_X509_new_null()) == NULL) || in dane_tlsa_add()
368 !sk_X509_push(dane->certs, cert)) { in dane_tlsa_add()
411 num = sk_danetls_record_num(dane->trecs); in dane_tlsa_add()
413 danetls_record *rec = sk_danetls_record_value(dane->trecs, i); in dane_tlsa_add()
423 if (dane->dctx->mdord[rec->mtype] > dane->dctx->mdord[mtype]) in dane_tlsa_add()
428 if (!sk_danetls_record_insert(dane->trecs, t, i)) { in dane_tlsa_add()
433 dane->umask |= DANETLS_USAGE_BIT(usage); in dane_tlsa_add()
614 s->dane.mdpth = -1; in SSL_clear()
615 s->dane.pdpth = -1; in SSL_clear()
616 X509_free(s->dane.mcert); in SSL_clear()
617 s->dane.mcert = NULL; in SSL_clear()
618 s->dane.mtlsa = NULL; in SSL_clear()
700 s->dane.flags = ctx->dane.flags; in SSL_new()
1015 return dane_ctx_enable(&ctx->dane); in SSL_CTX_dane_enable()
1020 unsigned long orig = ctx->dane.flags; in SSL_CTX_dane_set_flags()
1022 ctx->dane.flags |= flags; in SSL_CTX_dane_set_flags()
1028 unsigned long orig = ctx->dane.flags; in SSL_CTX_dane_clear_flags()
1030 ctx->dane.flags &= ~flags; in SSL_CTX_dane_clear_flags()
1036 SSL_DANE *dane = &s->dane; in SSL_dane_enable() local
1038 if (s->ctx->dane.mdmax == 0) { in SSL_dane_enable()
1042 if (dane->trecs != NULL) { in SSL_dane_enable()
1065 dane->mdpth = -1; in SSL_dane_enable()
1066 dane->pdpth = -1; in SSL_dane_enable()
1067 dane->dctx = &s->ctx->dane; in SSL_dane_enable()
1068 dane->trecs = sk_danetls_record_new_null(); in SSL_dane_enable()
1070 if (dane->trecs == NULL) { in SSL_dane_enable()
1079 unsigned long orig = ssl->dane.flags; in SSL_dane_set_flags()
1081 ssl->dane.flags |= flags; in SSL_dane_set_flags()
1087 unsigned long orig = ssl->dane.flags; in SSL_dane_clear_flags()
1089 ssl->dane.flags &= ~flags; in SSL_dane_clear_flags()
1095 SSL_DANE *dane = &s->dane; in SSL_get0_dane_authority() local
1097 if (!DANETLS_ENABLED(dane) || s->verify_result != X509_V_OK) in SSL_get0_dane_authority()
1099 if (dane->mtlsa) { in SSL_get0_dane_authority()
1101 *mcert = dane->mcert; in SSL_get0_dane_authority()
1103 *mspki = (dane->mcert == NULL) ? dane->mtlsa->spki : NULL; in SSL_get0_dane_authority()
1105 return dane->mdpth; in SSL_get0_dane_authority()
1111 SSL_DANE *dane = &s->dane; in SSL_get0_dane_tlsa() local
1113 if (!DANETLS_ENABLED(dane) || s->verify_result != X509_V_OK) in SSL_get0_dane_tlsa()
1115 if (dane->mtlsa) { in SSL_get0_dane_tlsa()
1117 *usage = dane->mtlsa->usage; in SSL_get0_dane_tlsa()
1119 *selector = dane->mtlsa->selector; in SSL_get0_dane_tlsa()
1121 *mtype = dane->mtlsa->mtype; in SSL_get0_dane_tlsa()
1123 *data = dane->mtlsa->data; in SSL_get0_dane_tlsa()
1125 *dlen = dane->mtlsa->dlen; in SSL_get0_dane_tlsa()
1127 return dane->mdpth; in SSL_get0_dane_tlsa()
1132 return &s->dane; in SSL_get0_dane()
1138 return dane_tlsa_add(&s->dane, usage, selector, mtype, data, dlen); in SSL_dane_tlsa_add()
1144 return dane_mtype_set(&ctx->dane, md, mtype, ord); in SSL_CTX_dane_mtype_set()
1185 dane_final(&s->dane); in SSL_free()
3444 dane_ctx_final(&a->dane); in SSL_CTX_free()
5208 SSL_DANE *dane = &s->dane; in ssl_validate_ct() local
5232 if (DANETLS_ENABLED(dane) && dane->mtlsa != NULL) { in ssl_validate_ct()
5233 switch (dane->mtlsa->usage) { in ssl_validate_ct()