2017-09-06 23:07:16 +08:00
|
|
|
//
|
|
|
|
// OpenVPNCertificate.m
|
|
|
|
// OpenVPN Adapter
|
|
|
|
//
|
|
|
|
// Created by Sergey Abramchuk on 06.09.17.
|
|
|
|
//
|
|
|
|
//
|
|
|
|
|
|
|
|
#import <mbedtls/x509_crt.h>
|
2017-09-07 04:29:06 +08:00
|
|
|
#import <mbedtls/pem.h>
|
2017-09-06 23:07:16 +08:00
|
|
|
|
2017-09-07 03:58:41 +08:00
|
|
|
#import "NSError+Message.h"
|
|
|
|
#import "OpenVPNError.h"
|
2017-09-06 23:07:16 +08:00
|
|
|
#import "OpenVPNCertificate.h"
|
|
|
|
|
|
|
|
@interface OpenVPNCertificate ()
|
|
|
|
|
2017-09-07 00:04:03 +08:00
|
|
|
@property (nonatomic, assign) mbedtls_x509_crt *crt;
|
2017-09-06 23:07:16 +08:00
|
|
|
|
|
|
|
@end
|
|
|
|
|
|
|
|
@implementation OpenVPNCertificate
|
|
|
|
|
|
|
|
- (instancetype)init
|
|
|
|
{
|
|
|
|
self = [super init];
|
|
|
|
if (self) {
|
|
|
|
self.crt = malloc(sizeof(mbedtls_x509_crt));
|
|
|
|
mbedtls_x509_crt_init(self.crt);
|
|
|
|
}
|
|
|
|
return self;
|
|
|
|
}
|
|
|
|
|
2017-09-07 04:02:22 +08:00
|
|
|
+ (OpenVPNCertificate *)certificateWithPEM:(NSData *)pemData error:(out NSError **)error {
|
2017-09-06 23:07:16 +08:00
|
|
|
OpenVPNCertificate *certificate = [OpenVPNCertificate new];
|
|
|
|
|
2017-09-06 23:10:26 +08:00
|
|
|
NSString *pemString = [[NSString alloc] initWithData:pemData encoding:NSUTF8StringEncoding];
|
|
|
|
|
|
|
|
int result = mbedtls_x509_crt_parse(certificate.crt, (const unsigned char *)pemString.UTF8String, pemData.length + 1);
|
2017-09-07 03:58:41 +08:00
|
|
|
if (result < 0) {
|
2017-09-06 23:18:36 +08:00
|
|
|
if (error) {
|
2017-09-07 03:58:41 +08:00
|
|
|
NSString *reason = [NSError reasonFromResult:result];
|
|
|
|
*error = [NSError errorWithDomain:OpenVPNIdentityErrorDomain code:result userInfo:@{
|
2017-09-07 04:31:25 +08:00
|
|
|
NSLocalizedDescriptionKey: @"Failed to read PEM data.",
|
2017-09-07 03:58:41 +08:00
|
|
|
NSLocalizedFailureReasonErrorKey: reason
|
|
|
|
}];
|
2017-09-06 23:18:36 +08:00
|
|
|
}
|
|
|
|
|
2017-09-06 23:10:26 +08:00
|
|
|
return nil;
|
|
|
|
}
|
2017-09-06 23:07:16 +08:00
|
|
|
|
|
|
|
return certificate;
|
|
|
|
}
|
|
|
|
|
2017-09-07 04:02:22 +08:00
|
|
|
+ (OpenVPNCertificate *)certificateWithDER:(NSData *)derData error:(out NSError **)error {
|
2017-09-06 23:07:16 +08:00
|
|
|
OpenVPNCertificate *certificate = [OpenVPNCertificate new];
|
|
|
|
|
2017-09-06 23:18:36 +08:00
|
|
|
int result = mbedtls_x509_crt_parse_der(certificate.crt, derData.bytes, derData.length);
|
2017-09-07 03:58:41 +08:00
|
|
|
if (result < 0) {
|
2017-09-06 23:18:36 +08:00
|
|
|
if (error) {
|
2017-09-07 03:58:41 +08:00
|
|
|
NSString *reason = [NSError reasonFromResult:result];
|
|
|
|
*error = [NSError errorWithDomain:OpenVPNIdentityErrorDomain code:result userInfo:@{
|
2017-09-07 04:31:25 +08:00
|
|
|
NSLocalizedDescriptionKey: @"Failed to read DER data.",
|
2017-09-07 03:58:41 +08:00
|
|
|
NSLocalizedFailureReasonErrorKey: reason
|
|
|
|
}];
|
2017-09-06 23:18:36 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
return nil;
|
|
|
|
}
|
2017-09-06 23:07:16 +08:00
|
|
|
|
|
|
|
return certificate;
|
|
|
|
}
|
|
|
|
|
2017-09-07 04:29:06 +08:00
|
|
|
- (NSData *)pemData:(out NSError **)error {
|
|
|
|
NSString *header = @"-----BEGIN CERTIFICATE-----\n";
|
|
|
|
NSString *footer = @"-----END CERTIFICATE-----\n";
|
|
|
|
|
2017-09-08 01:08:54 +08:00
|
|
|
size_t buffer_length = self.crt->raw.len * 10;
|
2017-09-07 04:29:06 +08:00
|
|
|
unsigned char *pem_buffer = malloc(buffer_length);
|
|
|
|
|
|
|
|
size_t output_length = 0;
|
|
|
|
|
|
|
|
int result = mbedtls_pem_write_buffer(header.UTF8String, footer.UTF8String, self.crt->raw.p, self.crt->raw.len, pem_buffer, buffer_length, &output_length);
|
|
|
|
if (result < 0) {
|
|
|
|
if (error) {
|
|
|
|
NSString *reason = [NSError reasonFromResult:result];
|
|
|
|
*error = [NSError errorWithDomain:OpenVPNIdentityErrorDomain code:result userInfo:@{
|
|
|
|
NSLocalizedDescriptionKey: @"Failed to write PEM data.",
|
|
|
|
NSLocalizedFailureReasonErrorKey: reason
|
|
|
|
}];
|
|
|
|
}
|
|
|
|
|
2017-09-07 19:11:57 +08:00
|
|
|
free(pem_buffer);
|
2017-09-07 04:29:06 +08:00
|
|
|
return nil;
|
|
|
|
}
|
|
|
|
|
2017-09-07 19:11:57 +08:00
|
|
|
NSData *pemData = [NSData dataWithBytes:pem_buffer length:output_length - 1];
|
|
|
|
|
|
|
|
free(pem_buffer);
|
|
|
|
return pemData;
|
2017-09-07 04:29:06 +08:00
|
|
|
}
|
|
|
|
|
2017-09-07 15:21:10 +08:00
|
|
|
- (NSData *)derData:(out NSError **)error {
|
|
|
|
if (self.crt->raw.p == NULL || self.crt->raw.len == 0) {
|
2017-09-16 19:45:38 +08:00
|
|
|
if (error) {
|
|
|
|
NSString *reason = [NSError reasonFromResult:MBEDTLS_ERR_X509_BAD_INPUT_DATA];
|
|
|
|
*error = [NSError errorWithDomain:OpenVPNIdentityErrorDomain code:MBEDTLS_ERR_X509_BAD_INPUT_DATA userInfo:@{
|
|
|
|
NSLocalizedDescriptionKey: @"Failed to write DER data.",
|
|
|
|
NSLocalizedFailureReasonErrorKey:reason
|
|
|
|
}];
|
|
|
|
}
|
2017-09-07 15:21:10 +08:00
|
|
|
|
|
|
|
return nil;
|
|
|
|
}
|
|
|
|
|
|
|
|
return [NSData dataWithBytes:self.crt->raw.p length:self.crt->raw.len];
|
|
|
|
}
|
|
|
|
|
2017-09-06 23:07:16 +08:00
|
|
|
- (void)dealloc {
|
2017-09-07 04:05:15 +08:00
|
|
|
mbedtls_x509_crt_free(self.crt);
|
|
|
|
free(self.crt);
|
2017-09-06 23:07:16 +08:00
|
|
|
}
|
|
|
|
|
|
|
|
@end
|