CSTrustDomain.h 3.3 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182
  1. /* -*- Mode: C++; tab-width: 8; indent-tabs-mode: nil; c-basic-offset: 2 -*- */
  2. /* This Source Code Form is subject to the terms of the Mozilla Public
  3. * License, v. 2.0. If a copy of the MPL was not distributed with this
  4. * file, You can obtain one at http://mozilla.org/MPL/2.0/. */
  5. #ifndef CSTrustDomain_h
  6. #define CSTrustDomain_h
  7. #include "pkix/pkixtypes.h"
  8. #include "mozilla/StaticMutex.h"
  9. #include "mozilla/UniquePtr.h"
  10. #include "nsDebug.h"
  11. #include "nsICertBlocklist.h"
  12. #include "nsIX509CertDB.h"
  13. #include "ScopedNSSTypes.h"
  14. namespace mozilla { namespace psm {
  15. class CSTrustDomain final : public mozilla::pkix::TrustDomain
  16. {
  17. public:
  18. typedef mozilla::pkix::Result Result;
  19. explicit CSTrustDomain(UniqueCERTCertList& certChain);
  20. virtual Result GetCertTrust(
  21. mozilla::pkix::EndEntityOrCA endEntityOrCA,
  22. const mozilla::pkix::CertPolicyId& policy,
  23. mozilla::pkix::Input candidateCertDER,
  24. /*out*/ mozilla::pkix::TrustLevel& trustLevel) override;
  25. virtual Result FindIssuer(mozilla::pkix::Input encodedIssuerName,
  26. IssuerChecker& checker,
  27. mozilla::pkix::Time time) override;
  28. virtual Result CheckRevocation(
  29. mozilla::pkix::EndEntityOrCA endEntityOrCA,
  30. const mozilla::pkix::CertID& certID, mozilla::pkix::Time time,
  31. mozilla::pkix::Duration validityDuration,
  32. /*optional*/ const mozilla::pkix::Input* stapledOCSPresponse,
  33. /*optional*/ const mozilla::pkix::Input* aiaExtension,
  34. /*optional*/ const mozilla::pkix::Input* sctExtension) override;
  35. virtual Result IsChainValid(const mozilla::pkix::DERArray& certChain,
  36. mozilla::pkix::Time time,
  37. const mozilla::pkix::CertPolicyId& requiredPolicy) override;
  38. virtual Result CheckSignatureDigestAlgorithm(
  39. mozilla::pkix::DigestAlgorithm digestAlg,
  40. mozilla::pkix::EndEntityOrCA endEntityOrCA,
  41. mozilla::pkix::Time notBefore) override;
  42. virtual Result CheckRSAPublicKeyModulusSizeInBits(
  43. mozilla::pkix::EndEntityOrCA endEntityOrCA,
  44. unsigned int modulusSizeInBits) override;
  45. virtual Result VerifyRSAPKCS1SignedDigest(
  46. const mozilla::pkix::SignedDigest& signedDigest,
  47. mozilla::pkix::Input subjectPublicKeyInfo) override;
  48. virtual Result CheckECDSACurveIsAcceptable(
  49. mozilla::pkix::EndEntityOrCA endEntityOrCA,
  50. mozilla::pkix::NamedCurve curve) override;
  51. virtual Result VerifyECDSASignedDigest(
  52. const mozilla::pkix::SignedDigest& signedDigest,
  53. mozilla::pkix::Input subjectPublicKeyInfo) override;
  54. virtual Result CheckValidityIsAcceptable(
  55. mozilla::pkix::Time notBefore, mozilla::pkix::Time notAfter,
  56. mozilla::pkix::EndEntityOrCA endEntityOrCA,
  57. mozilla::pkix::KeyPurposeId keyPurpose) override;
  58. virtual Result NetscapeStepUpMatchesServerAuth(
  59. mozilla::pkix::Time notBefore, /*out*/ bool& matches) override;
  60. virtual void NoteAuxiliaryExtension(
  61. mozilla::pkix::AuxiliaryExtension extension,
  62. mozilla::pkix::Input extensionData) override;
  63. virtual Result DigestBuf(mozilla::pkix::Input item,
  64. mozilla::pkix::DigestAlgorithm digestAlg,
  65. /*out*/ uint8_t* digestBuf,
  66. size_t digestBufLen) override;
  67. private:
  68. /*out*/ UniqueCERTCertList& mCertChain;
  69. nsCOMPtr<nsICertBlocklist> mCertBlocklist;
  70. };
  71. } } // namespace mozilla::psm
  72. #endif // CSTrustDomain_h