Source file src/crypto/x509/parser.go

     1  // Copyright 2021 The Go Authors. All rights reserved.
     2  // Use of this source code is governed by a BSD-style
     3  // license that can be found in the LICENSE file.
     4  
     5  package x509
     6  
     7  import (
     8  	"bytes"
     9  	"crypto/dsa"
    10  	"crypto/ecdh"
    11  	"crypto/ecdsa"
    12  	"crypto/ed25519"
    13  	"crypto/mldsa"
    14  	"crypto/rsa"
    15  	"crypto/x509/pkix"
    16  	"encoding/asn1"
    17  	"errors"
    18  	"fmt"
    19  	"internal/godebug"
    20  	"math"
    21  	"math/big"
    22  	"net"
    23  	"net/url"
    24  	"strconv"
    25  	"strings"
    26  	"time"
    27  	"unicode/utf16"
    28  	"unicode/utf8"
    29  
    30  	"golang.org/x/crypto/cryptobyte"
    31  	cryptobyte_asn1 "golang.org/x/crypto/cryptobyte/asn1"
    32  )
    33  
    34  // isPrintable reports whether the given b is in the ASN.1 PrintableString set.
    35  // This is a simplified version of encoding/asn1.isPrintable.
    36  func isPrintable(b byte) bool {
    37  	return 'a' <= b && b <= 'z' ||
    38  		'A' <= b && b <= 'Z' ||
    39  		'0' <= b && b <= '9' ||
    40  		'\'' <= b && b <= ')' ||
    41  		'+' <= b && b <= '/' ||
    42  		b == ' ' ||
    43  		b == ':' ||
    44  		b == '=' ||
    45  		b == '?' ||
    46  		// This is technically not allowed in a PrintableString.
    47  		// However, x509 certificates with wildcard strings don't
    48  		// always use the correct string type so we permit it.
    49  		b == '*' ||
    50  		// This is not technically allowed either. However, not
    51  		// only is it relatively common, but there are also a
    52  		// handful of CA certificates that contain it. At least
    53  		// one of which will not expire until 2027.
    54  		b == '&'
    55  }
    56  
    57  // parseASN1String parses the ASN.1 string types T61String, PrintableString,
    58  // UTF8String, BMPString, IA5String, and NumericString. This is mostly copied
    59  // from the respective encoding/asn1.parse... methods, rather than just
    60  // increasing the API surface of that package.
    61  func parseASN1String(tag cryptobyte_asn1.Tag, value []byte) (string, error) {
    62  	switch tag {
    63  	case cryptobyte_asn1.T61String:
    64  		// T.61 is a defunct ITU 8-bit character encoding which preceded Unicode.
    65  		// T.61 uses a code page layout that _almost_ exactly maps to the code
    66  		// page layout of the ISO 8859-1 (Latin-1) character encoding, with the
    67  		// exception that a number of characters in Latin-1 are not present
    68  		// in T.61.
    69  		//
    70  		// Instead of mapping which characters are present in Latin-1 but not T.61,
    71  		// we just treat these strings as being encoded using Latin-1. This matches
    72  		// what most of the world does, including BoringSSL.
    73  		buf := make([]byte, 0, len(value))
    74  		for _, v := range value {
    75  			// All the 1-byte UTF-8 runes map 1-1 with Latin-1.
    76  			buf = utf8.AppendRune(buf, rune(v))
    77  		}
    78  		return string(buf), nil
    79  	case cryptobyte_asn1.PrintableString:
    80  		for _, b := range value {
    81  			if !isPrintable(b) {
    82  				return "", errors.New("invalid PrintableString")
    83  			}
    84  		}
    85  		return string(value), nil
    86  	case cryptobyte_asn1.UTF8String:
    87  		if !utf8.Valid(value) {
    88  			return "", errors.New("invalid UTF-8 string")
    89  		}
    90  		return string(value), nil
    91  	case cryptobyte_asn1.Tag(asn1.TagBMPString):
    92  		// BMPString uses the defunct UCS-2 16-bit character encoding, which
    93  		// covers the Basic Multilingual Plane (BMP). UTF-16 was an extension of
    94  		// UCS-2, containing all of the same code points, but also including
    95  		// multi-code point characters (by using surrogate code points). We can
    96  		// treat a UCS-2 encoded string as a UTF-16 encoded string, as long as
    97  		// we reject out the UTF-16 specific code points. This matches the
    98  		// BoringSSL behavior.
    99  
   100  		if len(value)%2 != 0 {
   101  			return "", errors.New("invalid BMPString")
   102  		}
   103  
   104  		// Strip terminator if present.
   105  		if l := len(value); l >= 2 && value[l-1] == 0 && value[l-2] == 0 {
   106  			value = value[:l-2]
   107  		}
   108  
   109  		s := make([]uint16, 0, len(value)/2)
   110  		for len(value) > 0 {
   111  			point := uint16(value[0])<<8 + uint16(value[1])
   112  			// Reject UTF-16 code points that are permanently reserved
   113  			// noncharacters (0xfffe, 0xffff, and 0xfdd0-0xfdef) and surrogates
   114  			// (0xd800-0xdfff).
   115  			if point == 0xfffe || point == 0xffff ||
   116  				(point >= 0xfdd0 && point <= 0xfdef) ||
   117  				(point >= 0xd800 && point <= 0xdfff) {
   118  				return "", errors.New("invalid BMPString")
   119  			}
   120  			s = append(s, point)
   121  			value = value[2:]
   122  		}
   123  
   124  		return string(utf16.Decode(s)), nil
   125  	case cryptobyte_asn1.IA5String:
   126  		s := string(value)
   127  		if isIA5String(s) != nil {
   128  			return "", errors.New("invalid IA5String")
   129  		}
   130  		return s, nil
   131  	case cryptobyte_asn1.Tag(asn1.TagNumericString):
   132  		for _, b := range value {
   133  			if !('0' <= b && b <= '9' || b == ' ') {
   134  				return "", errors.New("invalid NumericString")
   135  			}
   136  		}
   137  		return string(value), nil
   138  	}
   139  	return "", fmt.Errorf("unsupported string type: %v", tag)
   140  }
   141  
   142  // readASN1Any parses types documented at [pkix.AttributeTypeAndValue].
   143  func readASN1Any(der *cryptobyte.String) (any, error) {
   144  	var fullValue cryptobyte.String
   145  	var valueTag cryptobyte_asn1.Tag
   146  	if !der.ReadAnyASN1Element(&fullValue, &valueTag) {
   147  		return nil, errors.New("invalid ASN.1 element")
   148  	}
   149  	switch valueTag {
   150  	case cryptobyte_asn1.T61String, cryptobyte_asn1.PrintableString,
   151  		cryptobyte_asn1.UTF8String, cryptobyte_asn1.Tag(asn1.TagBMPString),
   152  		cryptobyte_asn1.IA5String, cryptobyte_asn1.Tag(asn1.TagNumericString):
   153  		var rawValue []byte
   154  		if !fullValue.ReadASN1((*cryptobyte.String)(&rawValue), valueTag) {
   155  			return nil, errors.New("invalid ASN.1 element")
   156  		}
   157  		return parseASN1String(valueTag, rawValue)
   158  	case cryptobyte_asn1.INTEGER:
   159  		var i int64
   160  		if !fullValue.ReadASN1Integer(&i) {
   161  			return nil, errors.New("invalid ASN.1 integer")
   162  		}
   163  		return i, nil
   164  	case cryptobyte_asn1.BIT_STRING:
   165  		var bs asn1.BitString
   166  		if !fullValue.ReadASN1BitString(&bs) {
   167  			return nil, errors.New("invalid ASN.1 BIT STRING")
   168  		}
   169  		return bs, nil
   170  	case cryptobyte_asn1.OCTET_STRING:
   171  		var s []byte
   172  		if !fullValue.ReadASN1((*cryptobyte.String)(&s), cryptobyte_asn1.OCTET_STRING) {
   173  			return nil, errors.New("invalid ASN.1 OCTET STRING")
   174  		}
   175  		return s, nil
   176  	case cryptobyte_asn1.OBJECT_IDENTIFIER:
   177  		var oid asn1.ObjectIdentifier
   178  		if !fullValue.ReadASN1ObjectIdentifier(&oid) {
   179  			return nil, errors.New("invalid ASN.1 OBJECT IDENTIFIER")
   180  		}
   181  		return oid, nil
   182  	case cryptobyte_asn1.UTCTime, cryptobyte_asn1.GeneralizedTime:
   183  		out, err := readASN1Time(&fullValue)
   184  		return out, err
   185  	case cryptobyte_asn1.BOOLEAN:
   186  		var b bool
   187  		if !fullValue.ReadASN1Boolean(&b) {
   188  			return nil, errors.New("invalid ASN.1 BOOLEAN")
   189  		}
   190  		return b, nil
   191  	case cryptobyte_asn1.NULL:
   192  		return nil, nil
   193  	default:
   194  		var v asn1.RawValue
   195  		v.Class = int(valueTag >> 6)
   196  		v.IsCompound = valueTag&0x20 == 0x20
   197  		v.Tag = int(valueTag & 0x1f)
   198  		v.FullBytes = fullValue
   199  		if !fullValue.ReadAnyASN1((*cryptobyte.String)(&v.Bytes), &valueTag) {
   200  			return nil, errors.New("invalid ASN.1 element")
   201  		}
   202  		return v, nil
   203  	}
   204  }
   205  
   206  // parseName parses a DER encoded Name as defined in RFC 5280. We may
   207  // want to export this function in the future for use in crypto/tls.
   208  func parseName(raw cryptobyte.String) (*pkix.RDNSequence, error) {
   209  	if !raw.ReadASN1(&raw, cryptobyte_asn1.SEQUENCE) {
   210  		return nil, errors.New("x509: invalid RDNSequence")
   211  	}
   212  
   213  	var rdnSeq pkix.RDNSequence
   214  	for !raw.Empty() {
   215  		var rdnSet pkix.RelativeDistinguishedNameSET
   216  		var set cryptobyte.String
   217  		if !raw.ReadASN1(&set, cryptobyte_asn1.SET) {
   218  			return nil, errors.New("x509: invalid RDNSequence")
   219  		}
   220  		for !set.Empty() {
   221  			var atav cryptobyte.String
   222  			if !set.ReadASN1(&atav, cryptobyte_asn1.SEQUENCE) {
   223  				return nil, errors.New("x509: invalid RDNSequence: invalid attribute")
   224  			}
   225  			var attr pkix.AttributeTypeAndValue
   226  			if !atav.ReadASN1ObjectIdentifier(&attr.Type) {
   227  				return nil, errors.New("x509: invalid RDNSequence: invalid attribute type")
   228  			}
   229  			var err error
   230  			attr.Value, err = readASN1Any(&atav)
   231  			if err != nil {
   232  				return nil, fmt.Errorf("x509: invalid RDNSequence: invalid attribute value: %s", err)
   233  			}
   234  			rdnSet = append(rdnSet, attr)
   235  		}
   236  
   237  		rdnSeq = append(rdnSeq, rdnSet)
   238  	}
   239  
   240  	return &rdnSeq, nil
   241  }
   242  
   243  func parseAI(der cryptobyte.String) (pkix.AlgorithmIdentifier, error) {
   244  	ai := pkix.AlgorithmIdentifier{}
   245  	if !der.ReadASN1ObjectIdentifier(&ai.Algorithm) {
   246  		return ai, errors.New("x509: malformed OID")
   247  	}
   248  	if der.Empty() {
   249  		return ai, nil
   250  	}
   251  	var params cryptobyte.String
   252  	var tag cryptobyte_asn1.Tag
   253  	if !der.ReadAnyASN1Element(&params, &tag) {
   254  		return ai, errors.New("x509: malformed parameters")
   255  	}
   256  	ai.Parameters.Tag = int(tag)
   257  	ai.Parameters.FullBytes = params
   258  	return ai, nil
   259  }
   260  
   261  func readASN1Time(der *cryptobyte.String) (time.Time, error) {
   262  	var t time.Time
   263  	switch {
   264  	case der.PeekASN1Tag(cryptobyte_asn1.UTCTime):
   265  		if !der.ReadASN1UTCTime(&t) {
   266  			return t, errors.New("x509: malformed UTCTime")
   267  		}
   268  	case der.PeekASN1Tag(cryptobyte_asn1.GeneralizedTime):
   269  		if !der.ReadASN1GeneralizedTime(&t) {
   270  			return t, errors.New("x509: malformed GeneralizedTime")
   271  		}
   272  	default:
   273  		return t, errors.New("x509: unsupported time format")
   274  	}
   275  	return t, nil
   276  }
   277  
   278  func parseValidity(der cryptobyte.String) (time.Time, time.Time, error) {
   279  	notBefore, err := readASN1Time(&der)
   280  	if err != nil {
   281  		return time.Time{}, time.Time{}, err
   282  	}
   283  	notAfter, err := readASN1Time(&der)
   284  	if err != nil {
   285  		return time.Time{}, time.Time{}, err
   286  	}
   287  
   288  	return notBefore, notAfter, nil
   289  }
   290  
   291  func parseExtension(der cryptobyte.String) (pkix.Extension, error) {
   292  	var ext pkix.Extension
   293  	if !der.ReadASN1ObjectIdentifier(&ext.Id) {
   294  		return ext, errors.New("x509: malformed extension OID field")
   295  	}
   296  	if der.PeekASN1Tag(cryptobyte_asn1.BOOLEAN) {
   297  		if !der.ReadASN1Boolean(&ext.Critical) {
   298  			return ext, errors.New("x509: malformed extension critical field")
   299  		}
   300  	}
   301  	var val cryptobyte.String
   302  	if !der.ReadASN1(&val, cryptobyte_asn1.OCTET_STRING) {
   303  		return ext, errors.New("x509: malformed extension value field")
   304  	}
   305  	ext.Value = val
   306  	return ext, nil
   307  }
   308  
   309  func parsePublicKey(keyData *publicKeyInfo) (any, error) {
   310  	oid := keyData.Algorithm.Algorithm
   311  	params := keyData.Algorithm.Parameters
   312  	data := keyData.PublicKey.RightAlign()
   313  	switch {
   314  	case oid.Equal(oidPublicKeyRSA):
   315  		// RSA public keys must have a NULL in the parameters.
   316  		// See RFC 3279, Section 2.3.1.
   317  		if !bytes.Equal(params.FullBytes, asn1.NullBytes) {
   318  			return nil, errors.New("x509: RSA key missing NULL parameters")
   319  		}
   320  
   321  		der := cryptobyte.String(data)
   322  		p := &pkcs1PublicKey{N: new(big.Int)}
   323  		if !der.ReadASN1(&der, cryptobyte_asn1.SEQUENCE) {
   324  			return nil, errors.New("x509: invalid RSA public key")
   325  		}
   326  		if !der.ReadASN1Integer(p.N) {
   327  			return nil, errors.New("x509: invalid RSA modulus")
   328  		}
   329  		if !der.ReadASN1Integer(&p.E) {
   330  			return nil, errors.New("x509: invalid RSA public exponent")
   331  		}
   332  
   333  		if p.N.Sign() <= 0 {
   334  			return nil, errors.New("x509: RSA modulus is not a positive number")
   335  		}
   336  		if p.E <= 0 {
   337  			return nil, errors.New("x509: RSA public exponent is not a positive number")
   338  		}
   339  
   340  		pub := &rsa.PublicKey{
   341  			E: p.E,
   342  			N: p.N,
   343  		}
   344  		return pub, nil
   345  	case oid.Equal(oidPublicKeyECDSA):
   346  		paramsDer := cryptobyte.String(params.FullBytes)
   347  		namedCurveOID := new(asn1.ObjectIdentifier)
   348  		if !paramsDer.ReadASN1ObjectIdentifier(namedCurveOID) {
   349  			return nil, errors.New("x509: invalid ECDSA parameters")
   350  		}
   351  		namedCurve := namedCurveFromOID(*namedCurveOID)
   352  		if namedCurve == nil {
   353  			return nil, errors.New("x509: unsupported elliptic curve")
   354  		}
   355  		return ecdsa.ParseUncompressedPublicKey(namedCurve, data)
   356  	case oid.Equal(oidPublicKeyEd25519):
   357  		// RFC 8410, Section 3
   358  		// > For all of the OIDs, the parameters MUST be absent.
   359  		if len(params.FullBytes) != 0 {
   360  			return nil, errors.New("x509: Ed25519 key encoded with illegal parameters")
   361  		}
   362  		if len(data) != ed25519.PublicKeySize {
   363  			return nil, errors.New("x509: wrong Ed25519 public key size")
   364  		}
   365  		return ed25519.PublicKey(data), nil
   366  	case oid.Equal(oidPublicKeyMLDSA44), oid.Equal(oidPublicKeyMLDSA65), oid.Equal(oidPublicKeyMLDSA87):
   367  		if len(params.FullBytes) != 0 {
   368  			return nil, errors.New("x509: ML-DSA key encoded with illegal parameters")
   369  		}
   370  		params, ok := mldsaParametersFromOID(oid)
   371  		if !ok {
   372  			return nil, errors.New("x509: unsupported ML-DSA parameters")
   373  		}
   374  		return mldsa.NewPublicKey(params, data)
   375  	case oid.Equal(oidPublicKeyX25519):
   376  		// RFC 8410, Section 3
   377  		// > For all of the OIDs, the parameters MUST be absent.
   378  		if len(params.FullBytes) != 0 {
   379  			return nil, errors.New("x509: X25519 key encoded with illegal parameters")
   380  		}
   381  		return ecdh.X25519().NewPublicKey(data)
   382  	case oid.Equal(oidPublicKeyDSA):
   383  		der := cryptobyte.String(data)
   384  		y := new(big.Int)
   385  		if !der.ReadASN1Integer(y) {
   386  			return nil, errors.New("x509: invalid DSA public key")
   387  		}
   388  		pub := &dsa.PublicKey{
   389  			Y: y,
   390  			Parameters: dsa.Parameters{
   391  				P: new(big.Int),
   392  				Q: new(big.Int),
   393  				G: new(big.Int),
   394  			},
   395  		}
   396  		paramsDer := cryptobyte.String(params.FullBytes)
   397  		if !paramsDer.ReadASN1(&paramsDer, cryptobyte_asn1.SEQUENCE) ||
   398  			!paramsDer.ReadASN1Integer(pub.Parameters.P) ||
   399  			!paramsDer.ReadASN1Integer(pub.Parameters.Q) ||
   400  			!paramsDer.ReadASN1Integer(pub.Parameters.G) {
   401  			return nil, errors.New("x509: invalid DSA parameters")
   402  		}
   403  		if pub.Y.Sign() <= 0 || pub.Parameters.P.Sign() <= 0 ||
   404  			pub.Parameters.Q.Sign() <= 0 || pub.Parameters.G.Sign() <= 0 {
   405  			return nil, errors.New("x509: zero or negative DSA parameter")
   406  		}
   407  		return pub, nil
   408  	default:
   409  		return nil, errors.New("x509: unknown public key algorithm")
   410  	}
   411  }
   412  
   413  func parseKeyUsageExtension(der cryptobyte.String) (KeyUsage, error) {
   414  	var usageBits asn1.BitString
   415  	if !der.ReadASN1BitString(&usageBits) {
   416  		return 0, errors.New("x509: invalid key usage")
   417  	}
   418  
   419  	var usage int
   420  	for i := 0; i < 9; i++ {
   421  		if usageBits.At(i) != 0 {
   422  			usage |= 1 << uint(i)
   423  		}
   424  	}
   425  	return KeyUsage(usage), nil
   426  }
   427  
   428  func parseBasicConstraintsExtension(der cryptobyte.String) (bool, int, error) {
   429  	var isCA bool
   430  	if !der.ReadASN1(&der, cryptobyte_asn1.SEQUENCE) {
   431  		return false, 0, errors.New("x509: invalid basic constraints")
   432  	}
   433  	if der.PeekASN1Tag(cryptobyte_asn1.BOOLEAN) {
   434  		if !der.ReadASN1Boolean(&isCA) {
   435  			return false, 0, errors.New("x509: invalid basic constraints")
   436  		}
   437  	}
   438  
   439  	maxPathLen := -1
   440  	if der.PeekASN1Tag(cryptobyte_asn1.INTEGER) {
   441  		var mpl uint
   442  		if !der.ReadASN1Integer(&mpl) || mpl > math.MaxInt {
   443  			return false, 0, errors.New("x509: invalid basic constraints")
   444  		}
   445  		maxPathLen = int(mpl)
   446  	}
   447  
   448  	return isCA, maxPathLen, nil
   449  }
   450  
   451  func forEachSAN(der cryptobyte.String, callback func(tag int, data []byte) error) error {
   452  	if !der.ReadASN1(&der, cryptobyte_asn1.SEQUENCE) {
   453  		return errors.New("x509: invalid subject alternative names")
   454  	}
   455  	for !der.Empty() {
   456  		var san cryptobyte.String
   457  		var tag cryptobyte_asn1.Tag
   458  		if !der.ReadAnyASN1(&san, &tag) {
   459  			return errors.New("x509: invalid subject alternative name")
   460  		}
   461  		if err := callback(int(tag^0x80), san); err != nil {
   462  			return err
   463  		}
   464  	}
   465  
   466  	return nil
   467  }
   468  
   469  func parseSANExtension(der cryptobyte.String) (dnsNames, emailAddresses []string, ipAddresses []net.IP, uris []*url.URL, err error) {
   470  	err = forEachSAN(der, func(tag int, data []byte) error {
   471  		switch tag {
   472  		case nameTypeEmail:
   473  			email := string(data)
   474  			if err := isIA5String(email); err != nil {
   475  				return errors.New("x509: SAN rfc822Name is malformed")
   476  			}
   477  			emailAddresses = append(emailAddresses, email)
   478  		case nameTypeDNS:
   479  			name := string(data)
   480  			if err := isIA5String(name); err != nil {
   481  				return errors.New("x509: SAN dNSName is malformed")
   482  			}
   483  			dnsNames = append(dnsNames, string(name))
   484  		case nameTypeURI:
   485  			uriStr := string(data)
   486  			if err := isIA5String(uriStr); err != nil {
   487  				return errors.New("x509: SAN uniformResourceIdentifier is malformed")
   488  			}
   489  			uri, err := url.Parse(uriStr)
   490  			if err != nil {
   491  				return fmt.Errorf("x509: cannot parse URI %q: %s", uriStr, err)
   492  			}
   493  			if len(uri.Host) > 0 && !domainNameValid(uri.Host, false) {
   494  				return fmt.Errorf("x509: cannot parse URI %q: invalid domain", uriStr)
   495  			}
   496  			uris = append(uris, uri)
   497  		case nameTypeIP:
   498  			switch len(data) {
   499  			case net.IPv6len:
   500  				if net.IP(data).To4() != nil {
   501  					return errors.New("x509: SAN iPAddress contains IPv4-mapped IPv6 address")
   502  				}
   503  				ipAddresses = append(ipAddresses, data)
   504  			case net.IPv4len:
   505  				ipAddresses = append(ipAddresses, data)
   506  			default:
   507  				return errors.New("x509: cannot parse IP address of length " + strconv.Itoa(len(data)))
   508  			}
   509  		}
   510  
   511  		return nil
   512  	})
   513  
   514  	return
   515  }
   516  
   517  func parseAuthorityKeyIdentifier(e pkix.Extension) ([]byte, error) {
   518  	// RFC 5280, Section 4.2.1.1
   519  	if e.Critical {
   520  		// Conforming CAs MUST mark this extension as non-critical
   521  		return nil, errors.New("x509: authority key identifier incorrectly marked critical")
   522  	}
   523  	val := cryptobyte.String(e.Value)
   524  	var akid cryptobyte.String
   525  	if !val.ReadASN1(&akid, cryptobyte_asn1.SEQUENCE) {
   526  		return nil, errors.New("x509: invalid authority key identifier")
   527  	}
   528  	if akid.PeekASN1Tag(cryptobyte_asn1.Tag(0).ContextSpecific()) {
   529  		if !akid.ReadASN1(&akid, cryptobyte_asn1.Tag(0).ContextSpecific()) {
   530  			return nil, errors.New("x509: invalid authority key identifier")
   531  		}
   532  		return akid, nil
   533  	}
   534  	return nil, nil
   535  }
   536  
   537  func parseExtKeyUsageExtension(der cryptobyte.String) ([]ExtKeyUsage, []asn1.ObjectIdentifier, error) {
   538  	var extKeyUsages []ExtKeyUsage
   539  	var unknownUsages []asn1.ObjectIdentifier
   540  	if !der.ReadASN1(&der, cryptobyte_asn1.SEQUENCE) {
   541  		return nil, nil, errors.New("x509: invalid extended key usages")
   542  	}
   543  	for !der.Empty() {
   544  		var eku asn1.ObjectIdentifier
   545  		if !der.ReadASN1ObjectIdentifier(&eku) {
   546  			return nil, nil, errors.New("x509: invalid extended key usages")
   547  		}
   548  		if extKeyUsage, ok := extKeyUsageFromOID(eku); ok {
   549  			extKeyUsages = append(extKeyUsages, extKeyUsage)
   550  		} else {
   551  			unknownUsages = append(unknownUsages, eku)
   552  		}
   553  	}
   554  	return extKeyUsages, unknownUsages, nil
   555  }
   556  
   557  func parseCertificatePoliciesExtension(der cryptobyte.String) ([]OID, error) {
   558  	var oids []OID
   559  	seenOIDs := map[string]bool{}
   560  	if !der.ReadASN1(&der, cryptobyte_asn1.SEQUENCE) {
   561  		return nil, errors.New("x509: invalid certificate policies")
   562  	}
   563  	for !der.Empty() {
   564  		var cp cryptobyte.String
   565  		var OIDBytes cryptobyte.String
   566  		if !der.ReadASN1(&cp, cryptobyte_asn1.SEQUENCE) || !cp.ReadASN1(&OIDBytes, cryptobyte_asn1.OBJECT_IDENTIFIER) {
   567  			return nil, errors.New("x509: invalid certificate policies")
   568  		}
   569  		if seenOIDs[string(OIDBytes)] {
   570  			return nil, errors.New("x509: invalid certificate policies")
   571  		}
   572  		seenOIDs[string(OIDBytes)] = true
   573  		oid, ok := newOIDFromDER(OIDBytes)
   574  		if !ok {
   575  			return nil, errors.New("x509: invalid certificate policies")
   576  		}
   577  		oids = append(oids, oid)
   578  	}
   579  	return oids, nil
   580  }
   581  
   582  // isValidIPMask reports whether mask consists of zero or more 1 bits, followed by zero bits.
   583  func isValidIPMask(mask []byte) bool {
   584  	seenZero := false
   585  
   586  	for _, b := range mask {
   587  		if seenZero {
   588  			if b != 0 {
   589  				return false
   590  			}
   591  
   592  			continue
   593  		}
   594  
   595  		switch b {
   596  		case 0x00, 0x80, 0xc0, 0xe0, 0xf0, 0xf8, 0xfc, 0xfe:
   597  			seenZero = true
   598  		case 0xff:
   599  		default:
   600  			return false
   601  		}
   602  	}
   603  
   604  	return true
   605  }
   606  
   607  func parseNameConstraintsExtension(out *Certificate, e pkix.Extension) (unhandled bool, err error) {
   608  	// RFC 5280, 4.2.1.10
   609  
   610  	// NameConstraints ::= SEQUENCE {
   611  	//      permittedSubtrees       [0]     GeneralSubtrees OPTIONAL,
   612  	//      excludedSubtrees        [1]     GeneralSubtrees OPTIONAL }
   613  	//
   614  	// GeneralSubtrees ::= SEQUENCE SIZE (1..MAX) OF GeneralSubtree
   615  	//
   616  	// GeneralSubtree ::= SEQUENCE {
   617  	//      base                    GeneralName,
   618  	//      minimum         [0]     BaseDistance DEFAULT 0,
   619  	//      maximum         [1]     BaseDistance OPTIONAL }
   620  	//
   621  	// BaseDistance ::= INTEGER (0..MAX)
   622  
   623  	outer := cryptobyte.String(e.Value)
   624  	var toplevel, permitted, excluded cryptobyte.String
   625  	var havePermitted, haveExcluded bool
   626  	if !outer.ReadASN1(&toplevel, cryptobyte_asn1.SEQUENCE) ||
   627  		!outer.Empty() ||
   628  		!toplevel.ReadOptionalASN1(&permitted, &havePermitted, cryptobyte_asn1.Tag(0).ContextSpecific().Constructed()) ||
   629  		!toplevel.ReadOptionalASN1(&excluded, &haveExcluded, cryptobyte_asn1.Tag(1).ContextSpecific().Constructed()) ||
   630  		!toplevel.Empty() {
   631  		return false, errors.New("x509: invalid NameConstraints extension")
   632  	}
   633  
   634  	if !havePermitted && !haveExcluded || len(permitted) == 0 && len(excluded) == 0 {
   635  		// From RFC 5280, Section 4.2.1.10:
   636  		//   “either the permittedSubtrees field
   637  		//   or the excludedSubtrees MUST be
   638  		//   present”
   639  		return false, errors.New("x509: empty name constraints extension")
   640  	}
   641  
   642  	getValues := func(subtrees cryptobyte.String) (dnsNames []string, ips []*net.IPNet, emails, uriDomains []string, err error) {
   643  		for !subtrees.Empty() {
   644  			var seq, value cryptobyte.String
   645  			var tag cryptobyte_asn1.Tag
   646  			if !subtrees.ReadASN1(&seq, cryptobyte_asn1.SEQUENCE) ||
   647  				!seq.ReadAnyASN1(&value, &tag) {
   648  				return nil, nil, nil, nil, fmt.Errorf("x509: invalid NameConstraints extension")
   649  			}
   650  
   651  			var (
   652  				dnsTag   = cryptobyte_asn1.Tag(2).ContextSpecific()
   653  				emailTag = cryptobyte_asn1.Tag(1).ContextSpecific()
   654  				ipTag    = cryptobyte_asn1.Tag(7).ContextSpecific()
   655  				uriTag   = cryptobyte_asn1.Tag(6).ContextSpecific()
   656  			)
   657  
   658  			switch tag {
   659  			case dnsTag:
   660  				domain := string(value)
   661  				if err := isIA5String(domain); err != nil {
   662  					return nil, nil, nil, nil, errors.New("x509: invalid constraint value: " + err.Error())
   663  				}
   664  
   665  				if !domainNameValid(domain, true) {
   666  					return nil, nil, nil, nil, fmt.Errorf("x509: failed to parse dnsName constraint %q", domain)
   667  				}
   668  				dnsNames = append(dnsNames, domain)
   669  
   670  			case ipTag:
   671  				l := len(value)
   672  				var ip, mask []byte
   673  
   674  				switch l {
   675  				case 8:
   676  					ip = value[:4]
   677  					mask = value[4:]
   678  
   679  				case 32:
   680  					ip = value[:16]
   681  					mask = value[16:]
   682  
   683  				default:
   684  					return nil, nil, nil, nil, fmt.Errorf("x509: IP constraint contained value of length %d", l)
   685  				}
   686  
   687  				if !isValidIPMask(mask) {
   688  					return nil, nil, nil, nil, fmt.Errorf("x509: IP constraint contained invalid mask %x", mask)
   689  				}
   690  
   691  				if len(ip) == net.IPv6len && net.IP(ip).To4() != nil {
   692  					return nil, nil, nil, nil, errors.New("x509: IP constraint contained IPv4-mapped IPv6 address")
   693  				}
   694  
   695  				ips = append(ips, &net.IPNet{IP: net.IP(ip), Mask: net.IPMask(mask)})
   696  
   697  			case emailTag:
   698  				constraint := string(value)
   699  				if err := isIA5String(constraint); err != nil {
   700  					return nil, nil, nil, nil, errors.New("x509: invalid constraint value: " + err.Error())
   701  				}
   702  
   703  				// If the constraint contains an @ then
   704  				// it specifies an exact mailbox name.
   705  				if strings.Contains(constraint, "@") {
   706  					if _, ok := parseRFC2821Mailbox(constraint); !ok {
   707  						return nil, nil, nil, nil, fmt.Errorf("x509: failed to parse rfc822Name constraint %q", constraint)
   708  					}
   709  				} else {
   710  					if !domainNameValid(constraint, true) {
   711  						return nil, nil, nil, nil, fmt.Errorf("x509: failed to parse rfc822Name constraint %q", constraint)
   712  					}
   713  				}
   714  				emails = append(emails, constraint)
   715  
   716  			case uriTag:
   717  				domain := string(value)
   718  				if err := isIA5String(domain); err != nil {
   719  					return nil, nil, nil, nil, errors.New("x509: invalid constraint value: " + err.Error())
   720  				}
   721  
   722  				if net.ParseIP(domain) != nil {
   723  					return nil, nil, nil, nil, fmt.Errorf("x509: failed to parse URI constraint %q: cannot be IP address", domain)
   724  				}
   725  
   726  				if !domainNameValid(domain, true) {
   727  					return nil, nil, nil, nil, fmt.Errorf("x509: failed to parse URI constraint %q", domain)
   728  				}
   729  				uriDomains = append(uriDomains, domain)
   730  
   731  			default:
   732  				unhandled = true
   733  			}
   734  		}
   735  
   736  		return dnsNames, ips, emails, uriDomains, nil
   737  	}
   738  
   739  	if out.PermittedDNSDomains, out.PermittedIPRanges, out.PermittedEmailAddresses, out.PermittedURIDomains, err = getValues(permitted); err != nil {
   740  		return false, err
   741  	}
   742  	if out.ExcludedDNSDomains, out.ExcludedIPRanges, out.ExcludedEmailAddresses, out.ExcludedURIDomains, err = getValues(excluded); err != nil {
   743  		return false, err
   744  	}
   745  	out.PermittedDNSDomainsCritical = e.Critical
   746  
   747  	return unhandled, nil
   748  }
   749  
   750  func processExtensions(out *Certificate) error {
   751  	var err error
   752  	for _, e := range out.Extensions {
   753  		unhandled := false
   754  
   755  		if len(e.Id) == 4 && e.Id[0] == 2 && e.Id[1] == 5 && e.Id[2] == 29 {
   756  			switch e.Id[3] {
   757  			case 15:
   758  				out.KeyUsage, err = parseKeyUsageExtension(e.Value)
   759  				if err != nil {
   760  					return err
   761  				}
   762  			case 19:
   763  				out.IsCA, out.MaxPathLen, err = parseBasicConstraintsExtension(e.Value)
   764  				if err != nil {
   765  					return err
   766  				}
   767  				out.BasicConstraintsValid = true
   768  				out.MaxPathLenZero = out.MaxPathLen == 0
   769  			case 17:
   770  				out.DNSNames, out.EmailAddresses, out.IPAddresses, out.URIs, err = parseSANExtension(e.Value)
   771  				if err != nil {
   772  					return err
   773  				}
   774  
   775  				if len(out.DNSNames) == 0 && len(out.EmailAddresses) == 0 && len(out.IPAddresses) == 0 && len(out.URIs) == 0 {
   776  					// If we didn't parse anything then we do the critical check, below.
   777  					unhandled = true
   778  				}
   779  
   780  			case 30:
   781  				unhandled, err = parseNameConstraintsExtension(out, e)
   782  				if err != nil {
   783  					return err
   784  				}
   785  
   786  			case 31:
   787  				// RFC 5280, 4.2.1.13
   788  
   789  				// CRLDistributionPoints ::= SEQUENCE SIZE (1..MAX) OF DistributionPoint
   790  				//
   791  				// DistributionPoint ::= SEQUENCE {
   792  				//     distributionPoint       [0]     DistributionPointName OPTIONAL,
   793  				//     reasons                 [1]     ReasonFlags OPTIONAL,
   794  				//     cRLIssuer               [2]     GeneralNames OPTIONAL }
   795  				//
   796  				// DistributionPointName ::= CHOICE {
   797  				//     fullName                [0]     GeneralNames,
   798  				//     nameRelativeToCRLIssuer [1]     RelativeDistinguishedName }
   799  				val := cryptobyte.String(e.Value)
   800  				if !val.ReadASN1(&val, cryptobyte_asn1.SEQUENCE) {
   801  					return errors.New("x509: invalid CRL distribution points")
   802  				}
   803  				for !val.Empty() {
   804  					var dpDER cryptobyte.String
   805  					if !val.ReadASN1(&dpDER, cryptobyte_asn1.SEQUENCE) {
   806  						return errors.New("x509: invalid CRL distribution point")
   807  					}
   808  					var dpNameDER cryptobyte.String
   809  					var dpNamePresent bool
   810  					if !dpDER.ReadOptionalASN1(&dpNameDER, &dpNamePresent, cryptobyte_asn1.Tag(0).Constructed().ContextSpecific()) {
   811  						return errors.New("x509: invalid CRL distribution point")
   812  					}
   813  					if !dpNamePresent {
   814  						continue
   815  					}
   816  					if !dpNameDER.ReadASN1(&dpNameDER, cryptobyte_asn1.Tag(0).Constructed().ContextSpecific()) {
   817  						return errors.New("x509: invalid CRL distribution point")
   818  					}
   819  					for !dpNameDER.Empty() {
   820  						if !dpNameDER.PeekASN1Tag(cryptobyte_asn1.Tag(6).ContextSpecific()) {
   821  							break
   822  						}
   823  						var uri cryptobyte.String
   824  						if !dpNameDER.ReadASN1(&uri, cryptobyte_asn1.Tag(6).ContextSpecific()) {
   825  							return errors.New("x509: invalid CRL distribution point")
   826  						}
   827  						out.CRLDistributionPoints = append(out.CRLDistributionPoints, string(uri))
   828  					}
   829  				}
   830  
   831  			case 35:
   832  				out.AuthorityKeyId, err = parseAuthorityKeyIdentifier(e)
   833  				if err != nil {
   834  					return err
   835  				}
   836  			case 36:
   837  				val := cryptobyte.String(e.Value)
   838  				if !val.ReadASN1(&val, cryptobyte_asn1.SEQUENCE) {
   839  					return errors.New("x509: invalid policy constraints extension")
   840  				}
   841  				if val.PeekASN1Tag(cryptobyte_asn1.Tag(0).ContextSpecific()) {
   842  					var v int64
   843  					if !val.ReadASN1Int64WithTag(&v, cryptobyte_asn1.Tag(0).ContextSpecific()) {
   844  						return errors.New("x509: invalid policy constraints extension")
   845  					}
   846  					out.RequireExplicitPolicy = int(v)
   847  					// Check for overflow.
   848  					if int64(out.RequireExplicitPolicy) != v {
   849  						return errors.New("x509: policy constraints requireExplicitPolicy field overflows int")
   850  					}
   851  					out.RequireExplicitPolicyZero = out.RequireExplicitPolicy == 0
   852  				}
   853  				if val.PeekASN1Tag(cryptobyte_asn1.Tag(1).ContextSpecific()) {
   854  					var v int64
   855  					if !val.ReadASN1Int64WithTag(&v, cryptobyte_asn1.Tag(1).ContextSpecific()) {
   856  						return errors.New("x509: invalid policy constraints extension")
   857  					}
   858  					out.InhibitPolicyMapping = int(v)
   859  					// Check for overflow.
   860  					if int64(out.InhibitPolicyMapping) != v {
   861  						return errors.New("x509: policy constraints inhibitPolicyMapping field overflows int")
   862  					}
   863  					out.InhibitPolicyMappingZero = out.InhibitPolicyMapping == 0
   864  				}
   865  			case 37:
   866  				out.ExtKeyUsage, out.UnknownExtKeyUsage, err = parseExtKeyUsageExtension(e.Value)
   867  				if err != nil {
   868  					return err
   869  				}
   870  			case 14: // RFC 5280, 4.2.1.2
   871  				if e.Critical {
   872  					// Conforming CAs MUST mark this extension as non-critical
   873  					return errors.New("x509: subject key identifier incorrectly marked critical")
   874  				}
   875  				val := cryptobyte.String(e.Value)
   876  				var skid cryptobyte.String
   877  				if !val.ReadASN1(&skid, cryptobyte_asn1.OCTET_STRING) {
   878  					return errors.New("x509: invalid subject key identifier")
   879  				}
   880  				out.SubjectKeyId = skid
   881  			case 32:
   882  				out.Policies, err = parseCertificatePoliciesExtension(e.Value)
   883  				if err != nil {
   884  					return err
   885  				}
   886  				out.PolicyIdentifiers = make([]asn1.ObjectIdentifier, 0, len(out.Policies))
   887  				for _, oid := range out.Policies {
   888  					if oid, ok := oid.toASN1OID(); ok {
   889  						out.PolicyIdentifiers = append(out.PolicyIdentifiers, oid)
   890  					}
   891  				}
   892  			case 33:
   893  				val := cryptobyte.String(e.Value)
   894  				if !val.ReadASN1(&val, cryptobyte_asn1.SEQUENCE) {
   895  					return errors.New("x509: invalid policy mappings extension")
   896  				}
   897  				for !val.Empty() {
   898  					var s cryptobyte.String
   899  					var issuer, subject cryptobyte.String
   900  					if !val.ReadASN1(&s, cryptobyte_asn1.SEQUENCE) ||
   901  						!s.ReadASN1(&issuer, cryptobyte_asn1.OBJECT_IDENTIFIER) ||
   902  						!s.ReadASN1(&subject, cryptobyte_asn1.OBJECT_IDENTIFIER) {
   903  						return errors.New("x509: invalid policy mappings extension")
   904  					}
   905  					out.PolicyMappings = append(out.PolicyMappings, PolicyMapping{OID{issuer}, OID{subject}})
   906  				}
   907  			case 54:
   908  				val := cryptobyte.String(e.Value)
   909  				if !val.ReadASN1Integer(&out.InhibitAnyPolicy) {
   910  					return errors.New("x509: invalid inhibit any policy extension")
   911  				}
   912  				out.InhibitAnyPolicyZero = out.InhibitAnyPolicy == 0
   913  			default:
   914  				// Unknown extensions are recorded if critical.
   915  				unhandled = true
   916  			}
   917  		} else if e.Id.Equal(oidExtensionAuthorityInfoAccess) {
   918  			// RFC 5280 4.2.2.1: Authority Information Access
   919  			if e.Critical {
   920  				// Conforming CAs MUST mark this extension as non-critical
   921  				return errors.New("x509: authority info access incorrectly marked critical")
   922  			}
   923  			val := cryptobyte.String(e.Value)
   924  			if !val.ReadASN1(&val, cryptobyte_asn1.SEQUENCE) {
   925  				return errors.New("x509: invalid authority info access")
   926  			}
   927  			for !val.Empty() {
   928  				var aiaDER cryptobyte.String
   929  				if !val.ReadASN1(&aiaDER, cryptobyte_asn1.SEQUENCE) {
   930  					return errors.New("x509: invalid authority info access")
   931  				}
   932  				var method asn1.ObjectIdentifier
   933  				if !aiaDER.ReadASN1ObjectIdentifier(&method) {
   934  					return errors.New("x509: invalid authority info access")
   935  				}
   936  				if !aiaDER.PeekASN1Tag(cryptobyte_asn1.Tag(6).ContextSpecific()) {
   937  					continue
   938  				}
   939  				if !aiaDER.ReadASN1(&aiaDER, cryptobyte_asn1.Tag(6).ContextSpecific()) {
   940  					return errors.New("x509: invalid authority info access")
   941  				}
   942  				switch {
   943  				case method.Equal(oidAuthorityInfoAccessOcsp):
   944  					out.OCSPServer = append(out.OCSPServer, string(aiaDER))
   945  				case method.Equal(oidAuthorityInfoAccessIssuers):
   946  					out.IssuingCertificateURL = append(out.IssuingCertificateURL, string(aiaDER))
   947  				}
   948  			}
   949  		} else {
   950  			// Unknown extensions are recorded if critical.
   951  			unhandled = true
   952  		}
   953  
   954  		if e.Critical && unhandled {
   955  			out.UnhandledCriticalExtensions = append(out.UnhandledCriticalExtensions, e.Id)
   956  		}
   957  	}
   958  
   959  	return nil
   960  }
   961  
   962  var x509negativeserial = godebug.New("x509negativeserial")
   963  
   964  func parseCertificate(der []byte) (*Certificate, error) {
   965  	cert := &Certificate{}
   966  
   967  	input := cryptobyte.String(der)
   968  	// we read the SEQUENCE including length and tag bytes so that
   969  	// we can populate Certificate.Raw, before unwrapping the
   970  	// SEQUENCE so it can be operated on
   971  	if !input.ReadASN1Element(&input, cryptobyte_asn1.SEQUENCE) {
   972  		return nil, errors.New("x509: malformed certificate")
   973  	}
   974  	cert.Raw = input
   975  	if !input.ReadASN1(&input, cryptobyte_asn1.SEQUENCE) {
   976  		return nil, errors.New("x509: malformed certificate")
   977  	}
   978  
   979  	var tbs cryptobyte.String
   980  	// do the same trick again as above to extract the raw
   981  	// bytes for Certificate.RawTBSCertificate
   982  	if !input.ReadASN1Element(&tbs, cryptobyte_asn1.SEQUENCE) {
   983  		return nil, errors.New("x509: malformed tbs certificate")
   984  	}
   985  	cert.RawTBSCertificate = tbs
   986  	if !tbs.ReadASN1(&tbs, cryptobyte_asn1.SEQUENCE) {
   987  		return nil, errors.New("x509: malformed tbs certificate")
   988  	}
   989  
   990  	if !tbs.ReadOptionalASN1Integer(&cert.Version, cryptobyte_asn1.Tag(0).Constructed().ContextSpecific(), 0) {
   991  		return nil, errors.New("x509: malformed version")
   992  	}
   993  	if cert.Version < 0 {
   994  		return nil, errors.New("x509: malformed version")
   995  	}
   996  	// for backwards compat reasons Version is one-indexed,
   997  	// rather than zero-indexed as defined in 5280
   998  	cert.Version++
   999  	if cert.Version > 3 {
  1000  		return nil, errors.New("x509: invalid version")
  1001  	}
  1002  
  1003  	serial := new(big.Int)
  1004  	if !tbs.ReadASN1Integer(serial) {
  1005  		return nil, errors.New("x509: malformed serial number")
  1006  	}
  1007  	if serial.Sign() == -1 {
  1008  		if x509negativeserial.Value() != "1" {
  1009  			return nil, errors.New("x509: negative serial number")
  1010  		} else {
  1011  			x509negativeserial.IncNonDefault()
  1012  		}
  1013  	}
  1014  	cert.SerialNumber = serial
  1015  
  1016  	var sigAISeq cryptobyte.String
  1017  	if !tbs.ReadASN1Element(&sigAISeq, cryptobyte_asn1.SEQUENCE) {
  1018  		return nil, errors.New("x509: malformed signature algorithm identifier")
  1019  	}
  1020  	cert.RawSignatureAlgorithm = sigAISeq
  1021  	if !sigAISeq.ReadASN1(&sigAISeq, cryptobyte_asn1.SEQUENCE) {
  1022  		return nil, errors.New("x509: malformed signature algorithm identifier")
  1023  	}
  1024  	// Before parsing the inner algorithm identifier, extract
  1025  	// the outer algorithm identifier and make sure that they
  1026  	// match.
  1027  	var outerSigAISeq cryptobyte.String
  1028  	if !input.ReadASN1(&outerSigAISeq, cryptobyte_asn1.SEQUENCE) {
  1029  		return nil, errors.New("x509: malformed algorithm identifier")
  1030  	}
  1031  	if !bytes.Equal(outerSigAISeq, sigAISeq) {
  1032  		return nil, errors.New("x509: inner and outer signature algorithm identifiers don't match")
  1033  	}
  1034  	sigAI, err := parseAI(sigAISeq)
  1035  	if err != nil {
  1036  		return nil, err
  1037  	}
  1038  	cert.SignatureAlgorithm = getSignatureAlgorithmFromAI(sigAI)
  1039  
  1040  	var issuerSeq cryptobyte.String
  1041  	if !tbs.ReadASN1Element(&issuerSeq, cryptobyte_asn1.SEQUENCE) {
  1042  		return nil, errors.New("x509: malformed issuer")
  1043  	}
  1044  	cert.RawIssuer = issuerSeq
  1045  	issuerRDNs, err := parseName(issuerSeq)
  1046  	if err != nil {
  1047  		return nil, err
  1048  	}
  1049  	cert.Issuer.FillFromRDNSequence(issuerRDNs)
  1050  
  1051  	var validity cryptobyte.String
  1052  	if !tbs.ReadASN1(&validity, cryptobyte_asn1.SEQUENCE) {
  1053  		return nil, errors.New("x509: malformed validity")
  1054  	}
  1055  	cert.NotBefore, cert.NotAfter, err = parseValidity(validity)
  1056  	if err != nil {
  1057  		return nil, err
  1058  	}
  1059  
  1060  	var subjectSeq cryptobyte.String
  1061  	if !tbs.ReadASN1Element(&subjectSeq, cryptobyte_asn1.SEQUENCE) {
  1062  		return nil, errors.New("x509: malformed issuer")
  1063  	}
  1064  	cert.RawSubject = subjectSeq
  1065  	subjectRDNs, err := parseName(subjectSeq)
  1066  	if err != nil {
  1067  		return nil, err
  1068  	}
  1069  	cert.Subject.FillFromRDNSequence(subjectRDNs)
  1070  
  1071  	var spki cryptobyte.String
  1072  	if !tbs.ReadASN1Element(&spki, cryptobyte_asn1.SEQUENCE) {
  1073  		return nil, errors.New("x509: malformed spki")
  1074  	}
  1075  	cert.RawSubjectPublicKeyInfo = spki
  1076  	if !spki.ReadASN1(&spki, cryptobyte_asn1.SEQUENCE) {
  1077  		return nil, errors.New("x509: malformed spki")
  1078  	}
  1079  	var pkAISeq cryptobyte.String
  1080  	if !spki.ReadASN1(&pkAISeq, cryptobyte_asn1.SEQUENCE) {
  1081  		return nil, errors.New("x509: malformed public key algorithm identifier")
  1082  	}
  1083  	pkAI, err := parseAI(pkAISeq)
  1084  	if err != nil {
  1085  		return nil, err
  1086  	}
  1087  	cert.PublicKeyAlgorithm = getPublicKeyAlgorithmFromOID(pkAI.Algorithm)
  1088  	var spk asn1.BitString
  1089  	if !spki.ReadASN1BitString(&spk) {
  1090  		return nil, errors.New("x509: malformed subjectPublicKey")
  1091  	}
  1092  	if cert.PublicKeyAlgorithm != UnknownPublicKeyAlgorithm {
  1093  		cert.PublicKey, err = parsePublicKey(&publicKeyInfo{
  1094  			Algorithm: pkAI,
  1095  			PublicKey: spk,
  1096  		})
  1097  		if err != nil {
  1098  			return nil, err
  1099  		}
  1100  	}
  1101  
  1102  	if cert.Version > 1 {
  1103  		if !tbs.SkipOptionalASN1(cryptobyte_asn1.Tag(1).ContextSpecific()) {
  1104  			return nil, errors.New("x509: malformed issuerUniqueID")
  1105  		}
  1106  		if !tbs.SkipOptionalASN1(cryptobyte_asn1.Tag(2).ContextSpecific()) {
  1107  			return nil, errors.New("x509: malformed subjectUniqueID")
  1108  		}
  1109  		if cert.Version == 3 {
  1110  			var extensions cryptobyte.String
  1111  			var present bool
  1112  			if !tbs.ReadOptionalASN1(&extensions, &present, cryptobyte_asn1.Tag(3).Constructed().ContextSpecific()) {
  1113  				return nil, errors.New("x509: malformed extensions")
  1114  			}
  1115  			if present {
  1116  				seenExts := make(map[string]bool)
  1117  				if !extensions.ReadASN1(&extensions, cryptobyte_asn1.SEQUENCE) {
  1118  					return nil, errors.New("x509: malformed extensions")
  1119  				}
  1120  				for !extensions.Empty() {
  1121  					var extension cryptobyte.String
  1122  					if !extensions.ReadASN1(&extension, cryptobyte_asn1.SEQUENCE) {
  1123  						return nil, errors.New("x509: malformed extension")
  1124  					}
  1125  					ext, err := parseExtension(extension)
  1126  					if err != nil {
  1127  						return nil, err
  1128  					}
  1129  					oidStr := ext.Id.String()
  1130  					if seenExts[oidStr] {
  1131  						return nil, fmt.Errorf("x509: certificate contains duplicate extension with OID %q", oidStr)
  1132  					}
  1133  					seenExts[oidStr] = true
  1134  					cert.Extensions = append(cert.Extensions, ext)
  1135  				}
  1136  				err = processExtensions(cert)
  1137  				if err != nil {
  1138  					return nil, err
  1139  				}
  1140  			}
  1141  		}
  1142  	}
  1143  
  1144  	var signature asn1.BitString
  1145  	if !input.ReadASN1BitString(&signature) {
  1146  		return nil, errors.New("x509: malformed signature")
  1147  	}
  1148  	cert.Signature = signature.RightAlign()
  1149  
  1150  	return cert, nil
  1151  }
  1152  
  1153  // ParseCertificate parses a single certificate from the given ASN.1 DER data.
  1154  //
  1155  // Before Go 1.23, ParseCertificate accepted certificates with negative serial
  1156  // numbers. This behavior can be restored by including "x509negativeserial=1" in
  1157  // the GODEBUG environment variable.
  1158  func ParseCertificate(der []byte) (*Certificate, error) {
  1159  	cert, err := parseCertificate(der)
  1160  	if err != nil {
  1161  		return nil, err
  1162  	}
  1163  	if len(der) != len(cert.Raw) {
  1164  		return nil, errors.New("x509: trailing data")
  1165  	}
  1166  	return cert, nil
  1167  }
  1168  
  1169  // ParseCertificates parses one or more certificates from the given ASN.1 DER
  1170  // data. The certificates must be concatenated with no intermediate padding.
  1171  func ParseCertificates(der []byte) ([]*Certificate, error) {
  1172  	var certs []*Certificate
  1173  	for len(der) > 0 {
  1174  		cert, err := parseCertificate(der)
  1175  		if err != nil {
  1176  			return nil, err
  1177  		}
  1178  		certs = append(certs, cert)
  1179  		der = der[len(cert.Raw):]
  1180  	}
  1181  	return certs, nil
  1182  }
  1183  
  1184  // The X.509 standards confusingly 1-indexed the version names, but 0-indexed
  1185  // the actual encoded version, so the version for X.509v2 is 1.
  1186  const x509v2Version = 1
  1187  
  1188  // ParseRevocationList parses a X509 v2 [Certificate] Revocation List from the given
  1189  // ASN.1 DER data.
  1190  func ParseRevocationList(der []byte) (*RevocationList, error) {
  1191  	rl := &RevocationList{}
  1192  
  1193  	input := cryptobyte.String(der)
  1194  	// we read the SEQUENCE including length and tag bytes so that
  1195  	// we can populate RevocationList.Raw, before unwrapping the
  1196  	// SEQUENCE so it can be operated on
  1197  	if !input.ReadASN1Element(&input, cryptobyte_asn1.SEQUENCE) {
  1198  		return nil, errors.New("x509: malformed crl")
  1199  	}
  1200  	rl.Raw = input
  1201  	if !input.ReadASN1(&input, cryptobyte_asn1.SEQUENCE) {
  1202  		return nil, errors.New("x509: malformed crl")
  1203  	}
  1204  
  1205  	var tbs cryptobyte.String
  1206  	// do the same trick again as above to extract the raw
  1207  	// bytes for Certificate.RawTBSCertificate
  1208  	if !input.ReadASN1Element(&tbs, cryptobyte_asn1.SEQUENCE) {
  1209  		return nil, errors.New("x509: malformed tbs crl")
  1210  	}
  1211  	rl.RawTBSRevocationList = tbs
  1212  	if !tbs.ReadASN1(&tbs, cryptobyte_asn1.SEQUENCE) {
  1213  		return nil, errors.New("x509: malformed tbs crl")
  1214  	}
  1215  
  1216  	var version int
  1217  	if !tbs.PeekASN1Tag(cryptobyte_asn1.INTEGER) {
  1218  		return nil, errors.New("x509: unsupported crl version")
  1219  	}
  1220  	if !tbs.ReadASN1Integer(&version) {
  1221  		return nil, errors.New("x509: malformed crl")
  1222  	}
  1223  	if version != x509v2Version {
  1224  		return nil, fmt.Errorf("x509: unsupported crl version: %d", version)
  1225  	}
  1226  
  1227  	var sigAISeq cryptobyte.String
  1228  	if !tbs.ReadASN1Element(&sigAISeq, cryptobyte_asn1.SEQUENCE) {
  1229  		return nil, errors.New("x509: malformed signature algorithm identifier")
  1230  	}
  1231  	rl.RawSignatureAlgorithm = sigAISeq
  1232  	if !sigAISeq.ReadASN1(&sigAISeq, cryptobyte_asn1.SEQUENCE) {
  1233  		return nil, errors.New("x509: malformed signature algorithm identifier")
  1234  	}
  1235  	// Before parsing the inner algorithm identifier, extract
  1236  	// the outer algorithm identifier and make sure that they
  1237  	// match.
  1238  	var outerSigAISeq cryptobyte.String
  1239  	if !input.ReadASN1(&outerSigAISeq, cryptobyte_asn1.SEQUENCE) {
  1240  		return nil, errors.New("x509: malformed algorithm identifier")
  1241  	}
  1242  	if !bytes.Equal(outerSigAISeq, sigAISeq) {
  1243  		return nil, errors.New("x509: inner and outer signature algorithm identifiers don't match")
  1244  	}
  1245  	sigAI, err := parseAI(sigAISeq)
  1246  	if err != nil {
  1247  		return nil, err
  1248  	}
  1249  	rl.SignatureAlgorithm = getSignatureAlgorithmFromAI(sigAI)
  1250  
  1251  	var signature asn1.BitString
  1252  	if !input.ReadASN1BitString(&signature) {
  1253  		return nil, errors.New("x509: malformed signature")
  1254  	}
  1255  	rl.Signature = signature.RightAlign()
  1256  
  1257  	var issuerSeq cryptobyte.String
  1258  	if !tbs.ReadASN1Element(&issuerSeq, cryptobyte_asn1.SEQUENCE) {
  1259  		return nil, errors.New("x509: malformed issuer")
  1260  	}
  1261  	rl.RawIssuer = issuerSeq
  1262  	issuerRDNs, err := parseName(issuerSeq)
  1263  	if err != nil {
  1264  		return nil, err
  1265  	}
  1266  	rl.Issuer.FillFromRDNSequence(issuerRDNs)
  1267  
  1268  	rl.ThisUpdate, err = readASN1Time(&tbs)
  1269  	if err != nil {
  1270  		return nil, err
  1271  	}
  1272  	if tbs.PeekASN1Tag(cryptobyte_asn1.GeneralizedTime) || tbs.PeekASN1Tag(cryptobyte_asn1.UTCTime) {
  1273  		rl.NextUpdate, err = readASN1Time(&tbs)
  1274  		if err != nil {
  1275  			return nil, err
  1276  		}
  1277  	}
  1278  
  1279  	if tbs.PeekASN1Tag(cryptobyte_asn1.SEQUENCE) {
  1280  		var revokedSeq cryptobyte.String
  1281  		if !tbs.ReadASN1(&revokedSeq, cryptobyte_asn1.SEQUENCE) {
  1282  			return nil, errors.New("x509: malformed crl")
  1283  		}
  1284  		for !revokedSeq.Empty() {
  1285  			rce := RevocationListEntry{}
  1286  
  1287  			var certSeq cryptobyte.String
  1288  			if !revokedSeq.ReadASN1Element(&certSeq, cryptobyte_asn1.SEQUENCE) {
  1289  				return nil, errors.New("x509: malformed crl")
  1290  			}
  1291  			rce.Raw = certSeq
  1292  			if !certSeq.ReadASN1(&certSeq, cryptobyte_asn1.SEQUENCE) {
  1293  				return nil, errors.New("x509: malformed crl")
  1294  			}
  1295  
  1296  			rce.SerialNumber = new(big.Int)
  1297  			if !certSeq.ReadASN1Integer(rce.SerialNumber) {
  1298  				return nil, errors.New("x509: malformed serial number")
  1299  			}
  1300  			rce.RevocationTime, err = readASN1Time(&certSeq)
  1301  			if err != nil {
  1302  				return nil, err
  1303  			}
  1304  			var extensions cryptobyte.String
  1305  			var present bool
  1306  			if !certSeq.ReadOptionalASN1(&extensions, &present, cryptobyte_asn1.SEQUENCE) {
  1307  				return nil, errors.New("x509: malformed extensions")
  1308  			}
  1309  			if present {
  1310  				for !extensions.Empty() {
  1311  					var extension cryptobyte.String
  1312  					if !extensions.ReadASN1(&extension, cryptobyte_asn1.SEQUENCE) {
  1313  						return nil, errors.New("x509: malformed extension")
  1314  					}
  1315  					ext, err := parseExtension(extension)
  1316  					if err != nil {
  1317  						return nil, err
  1318  					}
  1319  					if ext.Id.Equal(oidExtensionReasonCode) {
  1320  						val := cryptobyte.String(ext.Value)
  1321  						if !val.ReadASN1Enum(&rce.ReasonCode) {
  1322  							return nil, fmt.Errorf("x509: malformed reasonCode extension")
  1323  						}
  1324  					}
  1325  					rce.Extensions = append(rce.Extensions, ext)
  1326  				}
  1327  			}
  1328  
  1329  			rl.RevokedCertificateEntries = append(rl.RevokedCertificateEntries, rce)
  1330  			rcDeprecated := pkix.RevokedCertificate{
  1331  				SerialNumber:   rce.SerialNumber,
  1332  				RevocationTime: rce.RevocationTime,
  1333  				Extensions:     rce.Extensions,
  1334  			}
  1335  			rl.RevokedCertificates = append(rl.RevokedCertificates, rcDeprecated)
  1336  		}
  1337  	}
  1338  
  1339  	var extensions cryptobyte.String
  1340  	var present bool
  1341  	if !tbs.ReadOptionalASN1(&extensions, &present, cryptobyte_asn1.Tag(0).Constructed().ContextSpecific()) {
  1342  		return nil, errors.New("x509: malformed extensions")
  1343  	}
  1344  	if present {
  1345  		if !extensions.ReadASN1(&extensions, cryptobyte_asn1.SEQUENCE) {
  1346  			return nil, errors.New("x509: malformed extensions")
  1347  		}
  1348  		for !extensions.Empty() {
  1349  			var extension cryptobyte.String
  1350  			if !extensions.ReadASN1(&extension, cryptobyte_asn1.SEQUENCE) {
  1351  				return nil, errors.New("x509: malformed extension")
  1352  			}
  1353  			ext, err := parseExtension(extension)
  1354  			if err != nil {
  1355  				return nil, err
  1356  			}
  1357  			if ext.Id.Equal(oidExtensionAuthorityKeyId) {
  1358  				rl.AuthorityKeyId, err = parseAuthorityKeyIdentifier(ext)
  1359  				if err != nil {
  1360  					return nil, err
  1361  				}
  1362  			} else if ext.Id.Equal(oidExtensionCRLNumber) {
  1363  				value := cryptobyte.String(ext.Value)
  1364  				rl.Number = new(big.Int)
  1365  				if !value.ReadASN1Integer(rl.Number) {
  1366  					return nil, errors.New("x509: malformed crl number")
  1367  				}
  1368  			}
  1369  			rl.Extensions = append(rl.Extensions, ext)
  1370  		}
  1371  	}
  1372  
  1373  	return rl, nil
  1374  }
  1375  
  1376  // domainNameValid is an alloc-less version of the checks that
  1377  // domainToReverseLabels does.
  1378  func domainNameValid(s string, constraint bool) bool {
  1379  	// TODO(#75835): This function omits a number of checks which we
  1380  	// really should be doing to enforce that domain names are valid names per
  1381  	// RFC 1034. We previously enabled these checks, but this broke a
  1382  	// significant number of certificates we previously considered valid, and we
  1383  	// happily create via CreateCertificate (et al). We should enable these
  1384  	// checks, but will need to gate them behind a GODEBUG.
  1385  	//
  1386  	// I have left the checks we previously enabled, noted with "TODO(#75835)" so
  1387  	// that we can easily re-enable them once we unbreak everyone.
  1388  
  1389  	// TODO(#75835): this should only be true for constraints.
  1390  	if len(s) == 0 {
  1391  		return true
  1392  	}
  1393  
  1394  	// Do not allow trailing period (FQDN format is not allowed in SANs or
  1395  	// constraints).
  1396  	if s[len(s)-1] == '.' {
  1397  		return false
  1398  	}
  1399  
  1400  	// TODO(#75835): domains must have at least one label, cannot have
  1401  	// a leading empty label, and cannot be longer than 253 characters.
  1402  	// if len(s) == 0 || (!constraint && s[0] == '.') || len(s) > 253 {
  1403  	// 	return false
  1404  	// }
  1405  
  1406  	lastDot := -1
  1407  	if constraint && s[0] == '.' {
  1408  		s = s[1:]
  1409  	}
  1410  
  1411  	for i := 0; i <= len(s); i++ {
  1412  		if i < len(s) && (s[i] < 33 || s[i] > 126) {
  1413  			// Invalid character.
  1414  			return false
  1415  		}
  1416  		if i == len(s) || s[i] == '.' {
  1417  			labelLen := i
  1418  			if lastDot >= 0 {
  1419  				labelLen -= lastDot + 1
  1420  			}
  1421  			if labelLen == 0 {
  1422  				return false
  1423  			}
  1424  			// TODO(#75835): labels cannot be longer than 63 characters.
  1425  			// if labelLen > 63 {
  1426  			// 	return false
  1427  			// }
  1428  			lastDot = i
  1429  		}
  1430  	}
  1431  
  1432  	return true
  1433  }
  1434  

View as plain text