xref: /openbmc/qemu/crypto/x509-utils.c (revision b8eada54b2ad8a7d98d93d5ab4d3e888c5880097)
110a1d34fSDorjoy Chowdhury /*
210a1d34fSDorjoy Chowdhury  * X.509 certificate related helpers
310a1d34fSDorjoy Chowdhury  *
410a1d34fSDorjoy Chowdhury  * Copyright (c) 2024 Dorjoy Chowdhury <dorjoychy111@gmail.com>
510a1d34fSDorjoy Chowdhury  *
610a1d34fSDorjoy Chowdhury  * This work is licensed under the terms of the GNU GPL, version 2 or
710a1d34fSDorjoy Chowdhury  * (at your option) any later version.  See the COPYING file in the
810a1d34fSDorjoy Chowdhury  * top-level directory.
910a1d34fSDorjoy Chowdhury  */
1010a1d34fSDorjoy Chowdhury 
1110a1d34fSDorjoy Chowdhury #include "qemu/osdep.h"
1210a1d34fSDorjoy Chowdhury #include "qapi/error.h"
1310a1d34fSDorjoy Chowdhury #include "crypto/x509-utils.h"
1410a1d34fSDorjoy Chowdhury #include <gnutls/gnutls.h>
1510a1d34fSDorjoy Chowdhury #include <gnutls/crypto.h>
1610a1d34fSDorjoy Chowdhury #include <gnutls/x509.h>
1710a1d34fSDorjoy Chowdhury 
18*ef834aa2SMarkus Armbruster static const int qcrypto_to_gnutls_hash_alg_map[QCRYPTO_HASH_ALGO__MAX] = {
19*ef834aa2SMarkus Armbruster     [QCRYPTO_HASH_ALGO_MD5] = GNUTLS_DIG_MD5,
20*ef834aa2SMarkus Armbruster     [QCRYPTO_HASH_ALGO_SHA1] = GNUTLS_DIG_SHA1,
21*ef834aa2SMarkus Armbruster     [QCRYPTO_HASH_ALGO_SHA224] = GNUTLS_DIG_SHA224,
22*ef834aa2SMarkus Armbruster     [QCRYPTO_HASH_ALGO_SHA256] = GNUTLS_DIG_SHA256,
23*ef834aa2SMarkus Armbruster     [QCRYPTO_HASH_ALGO_SHA384] = GNUTLS_DIG_SHA384,
24*ef834aa2SMarkus Armbruster     [QCRYPTO_HASH_ALGO_SHA512] = GNUTLS_DIG_SHA512,
25*ef834aa2SMarkus Armbruster     [QCRYPTO_HASH_ALGO_RIPEMD160] = GNUTLS_DIG_RMD160,
2610a1d34fSDorjoy Chowdhury };
2710a1d34fSDorjoy Chowdhury 
qcrypto_get_x509_cert_fingerprint(uint8_t * cert,size_t size,QCryptoHashAlgo alg,uint8_t * result,size_t * resultlen,Error ** errp)2810a1d34fSDorjoy Chowdhury int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, size_t size,
29*ef834aa2SMarkus Armbruster                                       QCryptoHashAlgo alg,
3010a1d34fSDorjoy Chowdhury                                       uint8_t *result,
3110a1d34fSDorjoy Chowdhury                                       size_t *resultlen,
3210a1d34fSDorjoy Chowdhury                                       Error **errp)
3310a1d34fSDorjoy Chowdhury {
3410a1d34fSDorjoy Chowdhury     int ret = -1;
3510a1d34fSDorjoy Chowdhury     int hlen;
3610a1d34fSDorjoy Chowdhury     gnutls_x509_crt_t crt;
3710a1d34fSDorjoy Chowdhury     gnutls_datum_t datum = {.data = cert, .size = size};
3810a1d34fSDorjoy Chowdhury 
3910a1d34fSDorjoy Chowdhury     if (alg >= G_N_ELEMENTS(qcrypto_to_gnutls_hash_alg_map)) {
4010a1d34fSDorjoy Chowdhury         error_setg(errp, "Unknown hash algorithm");
4110a1d34fSDorjoy Chowdhury         return -1;
4210a1d34fSDorjoy Chowdhury     }
4310a1d34fSDorjoy Chowdhury 
4410a1d34fSDorjoy Chowdhury     if (result == NULL) {
4510a1d34fSDorjoy Chowdhury         error_setg(errp, "No valid buffer given");
4610a1d34fSDorjoy Chowdhury         return -1;
4710a1d34fSDorjoy Chowdhury     }
4810a1d34fSDorjoy Chowdhury 
4910a1d34fSDorjoy Chowdhury     gnutls_x509_crt_init(&crt);
5010a1d34fSDorjoy Chowdhury 
5110a1d34fSDorjoy Chowdhury     if (gnutls_x509_crt_import(crt, &datum, GNUTLS_X509_FMT_PEM) != 0) {
5210a1d34fSDorjoy Chowdhury         error_setg(errp, "Failed to import certificate");
5310a1d34fSDorjoy Chowdhury         goto cleanup;
5410a1d34fSDorjoy Chowdhury     }
5510a1d34fSDorjoy Chowdhury 
5610a1d34fSDorjoy Chowdhury     hlen = gnutls_hash_get_len(qcrypto_to_gnutls_hash_alg_map[alg]);
5710a1d34fSDorjoy Chowdhury     if (*resultlen < hlen) {
5810a1d34fSDorjoy Chowdhury         error_setg(errp,
5910a1d34fSDorjoy Chowdhury                    "Result buffer size %zu is smaller than hash %d",
6010a1d34fSDorjoy Chowdhury                    *resultlen, hlen);
6110a1d34fSDorjoy Chowdhury         goto cleanup;
6210a1d34fSDorjoy Chowdhury     }
6310a1d34fSDorjoy Chowdhury 
6410a1d34fSDorjoy Chowdhury     if (gnutls_x509_crt_get_fingerprint(crt,
6510a1d34fSDorjoy Chowdhury                                         qcrypto_to_gnutls_hash_alg_map[alg],
6610a1d34fSDorjoy Chowdhury                                         result, resultlen) != 0) {
6710a1d34fSDorjoy Chowdhury         error_setg(errp, "Failed to get fingerprint from certificate");
6810a1d34fSDorjoy Chowdhury         goto cleanup;
6910a1d34fSDorjoy Chowdhury     }
7010a1d34fSDorjoy Chowdhury 
7110a1d34fSDorjoy Chowdhury     ret = 0;
7210a1d34fSDorjoy Chowdhury 
7310a1d34fSDorjoy Chowdhury  cleanup:
7410a1d34fSDorjoy Chowdhury     gnutls_x509_crt_deinit(crt);
7510a1d34fSDorjoy Chowdhury     return ret;
7610a1d34fSDorjoy Chowdhury }
77