1 /* $NetBSD: dnssec.c,v 1.6 2025/03/07 15:55:28 christos Exp $ */ 2 3 /* $KAME: dnssec.c,v 1.2 2001/08/05 18:46:07 itojun Exp $ */ 4 5 /* 6 * Copyright (C) 1995, 1996, 1997, and 1998 WIDE Project. 7 * All rights reserved. 8 * 9 * Redistribution and use in source and binary forms, with or without 10 * modification, are permitted provided that the following conditions 11 * are met: 12 * 1. Redistributions of source code must retain the above copyright 13 * notice, this list of conditions and the following disclaimer. 14 * 2. Redistributions in binary form must reproduce the above copyright 15 * notice, this list of conditions and the following disclaimer in the 16 * documentation and/or other materials provided with the distribution. 17 * 3. Neither the name of the project nor the names of its contributors 18 * may be used to endorse or promote products derived from this software 19 * without specific prior written permission. 20 * 21 * THIS SOFTWARE IS PROVIDED BY THE PROJECT AND CONTRIBUTORS ``AS IS'' AND 22 * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE 23 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE 24 * ARE DISCLAIMED. IN NO EVENT SHALL THE PROJECT OR CONTRIBUTORS BE LIABLE 25 * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL 26 * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS 27 * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) 28 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT 29 * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY 30 * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF 31 * SUCH DAMAGE. 32 */ 33 34 #include "config.h" 35 36 #include <sys/types.h> 37 #include <sys/param.h> 38 #include <stdlib.h> 39 #include <string.h> 40 41 #include "var.h" 42 #include "vmbuf.h" 43 #include "misc.h" 44 #include "plog.h" 45 #include "debug.h" 46 47 #include "isakmp_var.h" 48 #include "isakmp.h" 49 #include "ipsec_doi.h" 50 #include "oakley.h" 51 #include "netdb_dnssec.h" 52 #include "strnames.h" 53 #include "dnssec.h" 54 #include "gcmalloc.h" 55 56 extern int h_errno; 57 58 vchar_t * 59 dnssec_getcert(vchar_t *id) 60 { 61 vchar_t *cert = NULL; 62 struct certinfo *res = NULL; 63 struct ipsecdoi_id_b *id_b; 64 int type; 65 char *name = NULL; 66 size_t namelen; 67 int error; 68 69 id_b = (struct ipsecdoi_id_b *)id->v; 70 71 namelen = id->l - sizeof(*id_b); 72 name = racoon_malloc(namelen + 1); 73 if (!name) { 74 plog(LLV_ERROR, LOCATION, NULL, 75 "failed to get buffer.\n"); 76 return NULL; 77 } 78 memcpy(name, id_b + 1, namelen); 79 name[namelen] = '\0'; 80 81 switch (id_b->type) { 82 case IPSECDOI_ID_FQDN: 83 error = getcertsbyname(name, &res); 84 if (error != 0) { 85 plog(LLV_ERROR, LOCATION, NULL, 86 "getcertsbyname(\"%s\") failed.\n", name); 87 goto err; 88 } 89 break; 90 case IPSECDOI_ID_IPV4_ADDR: 91 case IPSECDOI_ID_IPV6_ADDR: 92 /* XXX should be processed to query PTR ? */ 93 default: 94 plog(LLV_ERROR, LOCATION, NULL, 95 "inpropper ID type passed %s " 96 "though getcert method is dnssec.\n", 97 s_ipsecdoi_ident(id_b->type)); 98 goto err; 99 } 100 101 /* check response */ 102 if (res->ci_next != NULL) { 103 plog(LLV_WARNING, LOCATION, NULL, 104 "not supported multiple CERT RR.\n"); 105 } 106 switch (res->ci_type) { 107 case DNSSEC_TYPE_PKIX: 108 /* XXX is it enough condition to set this type ? */ 109 type = ISAKMP_CERT_X509SIGN; 110 break; 111 default: 112 plog(LLV_ERROR, LOCATION, NULL, 113 "not supported CERT RR type %d.\n", res->ci_type); 114 goto err; 115 } 116 117 /* create cert holder */ 118 cert = vmalloc(res->ci_certlen + 1); 119 if (cert == NULL) { 120 plog(LLV_ERROR, LOCATION, NULL, 121 "failed to get cert buffer.\n"); 122 goto err; 123 } 124 cert->v[0] = type; 125 memcpy(&cert->v[1], res->ci_cert, res->ci_certlen); 126 127 plog(LLV_DEBUG, LOCATION, NULL, "created CERT payload:\n"); 128 plogdump(LLV_DEBUG, cert->v, cert->l); 129 130 err: 131 if (name) 132 racoon_free(name); 133 if (res) 134 freecertinfo(res); 135 return cert; 136 } 137