Home | History | Annotate | Line # | Download | only in racoon
      1 /*	$NetBSD: dnssec.c,v 1.6 2025/03/07 15:55:28 christos Exp $	*/
      2 
      3 /*	$KAME: dnssec.c,v 1.2 2001/08/05 18:46:07 itojun Exp $	*/
      4 
      5 /*
      6  * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project.
      7  * All rights reserved.
      8  *
      9  * Redistribution and use in source and binary forms, with or without
     10  * modification, are permitted provided that the following conditions
     11  * are met:
     12  * 1. Redistributions of source code must retain the above copyright
     13  *    notice, this list of conditions and the following disclaimer.
     14  * 2. Redistributions in binary form must reproduce the above copyright
     15  *    notice, this list of conditions and the following disclaimer in the
     16  *    documentation and/or other materials provided with the distribution.
     17  * 3. Neither the name of the project nor the names of its contributors
     18  *    may be used to endorse or promote products derived from this software
     19  *    without specific prior written permission.
     20  *
     21  * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND
     22  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
     23  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
     24  * ARE DISCLAIMED.  IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE
     25  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
     26  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
     27  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
     28  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
     29  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
     30  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
     31  * SUCH DAMAGE.
     32  */
     33 
     34 #include "config.h"
     35 
     36 #include <sys/types.h>
     37 #include <sys/param.h>
     38 #include <stdlib.h>
     39 #include <string.h>
     40 
     41 #include "var.h"
     42 #include "vmbuf.h"
     43 #include "misc.h"
     44 #include "plog.h"
     45 #include "debug.h"
     46 
     47 #include "isakmp_var.h"
     48 #include "isakmp.h"
     49 #include "ipsec_doi.h"
     50 #include "oakley.h"
     51 #include "netdb_dnssec.h"
     52 #include "strnames.h"
     53 #include "dnssec.h"
     54 #include "gcmalloc.h"
     55 
     56 extern int h_errno;
     57 
     58 vchar_t *
     59 dnssec_getcert(vchar_t *id)
     60 {
     61 	vchar_t *cert = NULL;
     62 	struct certinfo *res = NULL;
     63 	struct ipsecdoi_id_b *id_b;
     64 	int type;
     65 	char *name = NULL;
     66 	size_t namelen;
     67 	int error;
     68 
     69 	id_b = (struct ipsecdoi_id_b *)id->v;
     70 
     71 	namelen = id->l - sizeof(*id_b);
     72 	name = racoon_malloc(namelen + 1);
     73 	if (!name) {
     74 		plog(LLV_ERROR, LOCATION, NULL,
     75 			"failed to get buffer.\n");
     76 		return NULL;
     77 	}
     78 	memcpy(name, id_b + 1, namelen);
     79 	name[namelen] = '\0';
     80 
     81 	switch (id_b->type) {
     82 	case IPSECDOI_ID_FQDN:
     83 		error = getcertsbyname(name, &res);
     84 		if (error != 0) {
     85 			plog(LLV_ERROR, LOCATION, NULL,
     86 				"getcertsbyname(\"%s\") failed.\n", name);
     87 			goto err;
     88 		}
     89 		break;
     90 	case IPSECDOI_ID_IPV4_ADDR:
     91 	case IPSECDOI_ID_IPV6_ADDR:
     92 		/* XXX should be processed to query PTR ? */
     93 	default:
     94 		plog(LLV_ERROR, LOCATION, NULL,
     95 			"inpropper ID type passed %s "
     96 			"though getcert method is dnssec.\n",
     97 			s_ipsecdoi_ident(id_b->type));
     98 		goto err;
     99 	}
    100 
    101 	/* check response */
    102 	if (res->ci_next != NULL) {
    103 		plog(LLV_WARNING, LOCATION, NULL,
    104 			"not supported multiple CERT RR.\n");
    105 	}
    106 	switch (res->ci_type) {
    107 	case DNSSEC_TYPE_PKIX:
    108 		/* XXX is it enough condition to set this type ? */
    109 		type = ISAKMP_CERT_X509SIGN;
    110 		break;
    111 	default:
    112 		plog(LLV_ERROR, LOCATION, NULL,
    113 			"not supported CERT RR type %d.\n", res->ci_type);
    114 		goto err;
    115 	}
    116 
    117 	/* create cert holder */
    118 	cert = vmalloc(res->ci_certlen + 1);
    119 	if (cert == NULL) {
    120 		plog(LLV_ERROR, LOCATION, NULL,
    121 			"failed to get cert buffer.\n");
    122 		goto err;
    123 	}
    124 	cert->v[0] = type;
    125 	memcpy(&cert->v[1], res->ci_cert, res->ci_certlen);
    126 
    127 	plog(LLV_DEBUG, LOCATION, NULL, "created CERT payload:\n");
    128 	plogdump(LLV_DEBUG, cert->v, cert->l);
    129 
    130 err:
    131 	if (name)
    132 		racoon_free(name);
    133 	if (res)
    134 		freecertinfo(res);
    135 	return cert;
    136 }
    137