Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 1 | // Copyright 2016 The Chromium Authors |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
| 5 | #include "cert_errors.h" |
| 6 | |
| 7 | #include "cert_error_params.h" |
| 8 | #include "parse_name.h" |
| 9 | #include "parsed_certificate.h" |
| 10 | |
| 11 | #include <sstream> |
| 12 | |
| 13 | namespace bssl { |
| 14 | |
| 15 | namespace { |
| 16 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 17 | void AppendLinesWithIndentation(const std::string &text, |
| 18 | const std::string &indentation, |
| 19 | std::string *out) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 20 | std::istringstream stream(text); |
| 21 | for (std::string line; std::getline(stream, line, '\n');) { |
| 22 | out->append(indentation); |
| 23 | out->append(line); |
| 24 | out->append("\n"); |
| 25 | } |
| 26 | } |
| 27 | |
| 28 | } // namespace |
| 29 | |
| 30 | CertError::CertError() = default; |
| 31 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 32 | CertError::CertError(Severity in_severity, CertErrorId in_id, |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 33 | std::unique_ptr<CertErrorParams> in_params) |
| 34 | : severity(in_severity), id(in_id), params(std::move(in_params)) {} |
| 35 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 36 | CertError::CertError(CertError &&other) = default; |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 37 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 38 | CertError &CertError::operator=(CertError &&) = default; |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 39 | |
| 40 | CertError::~CertError() = default; |
| 41 | |
| 42 | std::string CertError::ToDebugString() const { |
| 43 | std::string result; |
| 44 | switch (severity) { |
| 45 | case SEVERITY_WARNING: |
| 46 | result += "WARNING: "; |
| 47 | break; |
| 48 | case SEVERITY_HIGH: |
| 49 | result += "ERROR: "; |
| 50 | break; |
| 51 | } |
| 52 | result += CertErrorIdToDebugString(id); |
| 53 | result += +"\n"; |
| 54 | |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 55 | if (params) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 56 | AppendLinesWithIndentation(params->ToDebugString(), " ", &result); |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 57 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 58 | |
| 59 | return result; |
| 60 | } |
| 61 | |
| 62 | CertErrors::CertErrors() = default; |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 63 | CertErrors::CertErrors(CertErrors &&other) = default; |
| 64 | CertErrors &CertErrors::operator=(CertErrors &&) = default; |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 65 | CertErrors::~CertErrors() = default; |
| 66 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 67 | void CertErrors::Add(CertError::Severity severity, CertErrorId id, |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 68 | std::unique_ptr<CertErrorParams> params) { |
| 69 | nodes_.emplace_back(severity, id, std::move(params)); |
| 70 | } |
| 71 | |
| 72 | void CertErrors::AddError(CertErrorId id, |
| 73 | std::unique_ptr<CertErrorParams> params) { |
| 74 | Add(CertError::SEVERITY_HIGH, id, std::move(params)); |
| 75 | } |
| 76 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 77 | void CertErrors::AddError(CertErrorId id) { AddError(id, nullptr); } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 78 | |
| 79 | void CertErrors::AddWarning(CertErrorId id, |
| 80 | std::unique_ptr<CertErrorParams> params) { |
| 81 | Add(CertError::SEVERITY_WARNING, id, std::move(params)); |
| 82 | } |
| 83 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 84 | void CertErrors::AddWarning(CertErrorId id) { AddWarning(id, nullptr); } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 85 | |
| 86 | std::string CertErrors::ToDebugString() const { |
| 87 | std::string result; |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 88 | for (const CertError &node : nodes_) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 89 | result += node.ToDebugString(); |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 90 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 91 | |
| 92 | return result; |
| 93 | } |
| 94 | |
Bob Beck | 58a318e | 2024-02-13 22:54:29 +0000 | [diff] [blame] | 95 | bool CertErrors::ContainsErrorWithSeverity(CertErrorId id, |
| 96 | CertError::Severity severity) const { |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 97 | for (const CertError &node : nodes_) { |
Bob Beck | 58a318e | 2024-02-13 22:54:29 +0000 | [diff] [blame] | 98 | if (node.id == id && node.severity == severity) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 99 | return true; |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 100 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 101 | } |
| 102 | return false; |
| 103 | } |
| 104 | |
Bob Beck | 58a318e | 2024-02-13 22:54:29 +0000 | [diff] [blame] | 105 | bool CertErrors::ContainsError(CertErrorId id) const { |
| 106 | return ContainsErrorWithSeverity(id, CertError::SEVERITY_HIGH); |
| 107 | } |
| 108 | |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 109 | bool CertErrors::ContainsAnyErrorWithSeverity( |
| 110 | CertError::Severity severity) const { |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 111 | for (const CertError &node : nodes_) { |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 112 | if (node.severity == severity) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 113 | return true; |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 114 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 115 | } |
| 116 | return false; |
| 117 | } |
| 118 | |
| 119 | CertPathErrors::CertPathErrors() = default; |
| 120 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 121 | CertPathErrors::CertPathErrors(CertPathErrors &&other) = default; |
| 122 | CertPathErrors &CertPathErrors::operator=(CertPathErrors &&) = default; |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 123 | |
| 124 | CertPathErrors::~CertPathErrors() = default; |
| 125 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 126 | CertErrors *CertPathErrors::GetErrorsForCert(size_t cert_index) { |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 127 | if (cert_index >= cert_errors_.size()) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 128 | cert_errors_.resize(cert_index + 1); |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 129 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 130 | return &cert_errors_[cert_index]; |
| 131 | } |
| 132 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 133 | const CertErrors *CertPathErrors::GetErrorsForCert(size_t cert_index) const { |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 134 | if (cert_index >= cert_errors_.size()) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 135 | return nullptr; |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 136 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 137 | return &cert_errors_[cert_index]; |
| 138 | } |
| 139 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 140 | CertErrors *CertPathErrors::GetOtherErrors() { return &other_errors_; } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 141 | |
| 142 | bool CertPathErrors::ContainsError(CertErrorId id) const { |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 143 | for (const CertErrors &errors : cert_errors_) { |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 144 | if (errors.ContainsError(id)) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 145 | return true; |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 146 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 147 | } |
| 148 | |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 149 | if (other_errors_.ContainsError(id)) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 150 | return true; |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 151 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 152 | |
| 153 | return false; |
| 154 | } |
| 155 | |
| 156 | bool CertPathErrors::ContainsAnyErrorWithSeverity( |
| 157 | CertError::Severity severity) const { |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 158 | for (const CertErrors &errors : cert_errors_) { |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 159 | if (errors.ContainsAnyErrorWithSeverity(severity)) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 160 | return true; |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 161 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 162 | } |
| 163 | |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 164 | if (other_errors_.ContainsAnyErrorWithSeverity(severity)) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 165 | return true; |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 166 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 167 | |
| 168 | return false; |
| 169 | } |
| 170 | |
| 171 | std::string CertPathErrors::ToDebugString( |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 172 | const ParsedCertificateList &certs) const { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 173 | std::ostringstream result; |
| 174 | |
| 175 | for (size_t i = 0; i < cert_errors_.size(); ++i) { |
| 176 | // Pretty print the current CertErrors. If there were no errors/warnings, |
| 177 | // then continue. |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 178 | const CertErrors &errors = cert_errors_[i]; |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 179 | std::string cert_errors_string = errors.ToDebugString(); |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 180 | if (cert_errors_string.empty()) { |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 181 | continue; |
Bob Beck | 6beabf3 | 2023-11-21 09:43:52 -0700 | [diff] [blame] | 182 | } |
Bob Beck | bc97b7a | 2023-04-18 08:35:15 -0600 | [diff] [blame] | 183 | |
| 184 | // Add a header that identifies which certificate this CertErrors pertains |
| 185 | // to. |
| 186 | std::string cert_name_debug_str; |
| 187 | if (i < certs.size() && certs[i]) { |
| 188 | RDNSequence subject; |
| 189 | if (ParseName(certs[i]->tbs().subject_tlv, &subject) && |
| 190 | ConvertToRFC2253(subject, &cert_name_debug_str)) { |
| 191 | cert_name_debug_str = " (" + cert_name_debug_str + ")"; |
| 192 | } |
| 193 | } |
| 194 | result << "----- Certificate i=" << i << cert_name_debug_str << " -----\n"; |
| 195 | result << cert_errors_string << "\n"; |
| 196 | } |
| 197 | |
| 198 | // Print any other errors that aren't associated with a particular certificate |
| 199 | // in the chain. |
| 200 | std::string other_errors = other_errors_.ToDebugString(); |
| 201 | if (!other_errors.empty()) { |
| 202 | result << "----- Other errors (not certificate specific) -----\n"; |
| 203 | result << other_errors << "\n"; |
| 204 | } |
| 205 | |
| 206 | return result.str(); |
| 207 | } |
| 208 | |
Bob Beck | 5c7a2a0 | 2023-11-20 17:28:21 -0700 | [diff] [blame] | 209 | } // namespace bssl |