X-Git-Url: http://www.project-moonshot.org/gitweb/?a=blobdiff_plain;f=xmltooling%2Fsignature%2Fimpl%2FKeyInfoSchemaValidators.cpp;h=334173adc03f5b920e4909f55dc57fdc68c46ed1;hb=81b488b2790e7bdeb2f43560b1d4a7d22c3dfdf5;hp=47da2fe5643eca2b647c3661d39440a9ba6a0812;hpb=aca509e6b9c8e0859c20723a231052e5a17f756a;p=shibboleth%2Fcpp-xmltooling.git diff --git a/xmltooling/signature/impl/KeyInfoSchemaValidators.cpp b/xmltooling/signature/impl/KeyInfoSchemaValidators.cpp index 47da2fe..334173a 100644 --- a/xmltooling/signature/impl/KeyInfoSchemaValidators.cpp +++ b/xmltooling/signature/impl/KeyInfoSchemaValidators.cpp @@ -1,17 +1,21 @@ -/* -* Copyright 2001-2010 Internet2 - * -* Licensed under the Apache License, Version 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at +/** + * Licensed to the University Corporation for Advanced Internet + * Development, Inc. (UCAID) under one or more contributor license + * agreements. See the NOTICE file distributed with this work for + * additional information regarding copyright ownership. * - * http://www.apache.org/licenses/LICENSE-2.0 + * UCAID licenses this file to you under the Apache License, + * Version 2.0 (the "License"); you may not use this file except + * in compliance with the License. You may obtain a copy of the + * License at * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. + * http://www.apache.org/licenses/LICENSE-2.0 + * + * Unless required by applicable law or agreed to in writing, + * software distributed under the License is distributed on an + * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, + * either express or implied. See the License for the specific + * language governing permissions and limitations under the License. */ /** @@ -32,6 +36,19 @@ using namespace std; using xmlconstants::XMLSIG_NS; using xmlconstants::XMLSIG11_NS; +#define XMLOBJECTVALIDATOR_ONLYONEOF4(cname,proper1,proper2,proper3,proper4) \ + int c##proper1##proper2##proper3##proper4=0; \ + if (ptr->get##proper1()!=nullptr) \ + c##proper1##proper2##proper3##proper4++; \ + if (ptr->get##proper2()!=nullptr) \ + c##proper1##proper2##proper3##proper4++; \ + if (ptr->get##proper3()!=nullptr) \ + c##proper1##proper2##proper3##proper4++; \ + if (ptr->get##proper4()!=nullptr) \ + c##proper1##proper2##proper3##proper4++; \ + if (c##proper1##proper2##proper3##proper4 != 1) \ + throw xmltooling::ValidationException(#cname" must have only one of "#proper1", "#proper2", "#proper3", or "#proper4".") + namespace xmlsignature { XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,KeyName); @@ -52,11 +69,13 @@ namespace xmlsignature { XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,X509SubjectName); XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,X509Certificate); XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,X509CRL); - XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,OCSPResponse); XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,SPKISexp); XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,PGPKeyID); XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,PGPKeyPacket); + XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,DEREncodedKeyValue); + XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,OCSPResponse); + XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,PublicKey); BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,RSAKeyValue); XMLOBJECTVALIDATOR_REQUIRE(RSAKeyValue,Modulus); @@ -70,7 +89,7 @@ namespace xmlsignature { END_XMLOBJECTVALIDATOR; BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,KeyValue); - XMLOBJECTVALIDATOR_ONLYONEOF3(KeyValue,DSAKeyValue,RSAKeyValue,UnknownXMLObject); + XMLOBJECTVALIDATOR_ONLYONEOF4(KeyValue,DSAKeyValue,RSAKeyValue,ECKeyValue,UnknownXMLObject); END_XMLOBJECTVALIDATOR; BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,Transform); @@ -129,6 +148,18 @@ namespace xmlsignature { XMLOBJECTVALIDATOR_REQUIRE(KeyInfoReference,URI); END_XMLOBJECTVALIDATOR; + BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,NamedCurve); + XMLOBJECTVALIDATOR_REQUIRE(NamedCurve,URI); + END_XMLOBJECTVALIDATOR; + + BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,ECKeyValue); + XMLOBJECTVALIDATOR_ONEOF(ECKeyValue,ECParameters,NamedCurve); + XMLOBJECTVALIDATOR_REQUIRE(ECKeyValue,PublicKey); + END_XMLOBJECTVALIDATOR; + + BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,X509Digest); + XMLOBJECTVALIDATOR_REQUIRE(X509Digest,Algorithm); + END_XMLOBJECTVALIDATOR; }; #define REGISTER_ELEMENT(namespaceURI,cname) \ @@ -188,9 +219,16 @@ void xmlsignature::registerKeyInfoClasses() REGISTER_TYPE(XMLSIG_NS,SPKIData); REGISTER_TYPE(XMLSIG_NS,PGPData); - REGISTER_ELEMENT(XMLSIG11_NS,OCSPResponse); REGISTER_ELEMENT(XMLSIG11_NS,DEREncodedKeyValue); + REGISTER_ELEMENT(XMLSIG11_NS,ECKeyValue); REGISTER_ELEMENT(XMLSIG11_NS,KeyInfoReference); + REGISTER_ELEMENT(XMLSIG11_NS,NamedCurve); + REGISTER_ELEMENT(XMLSIG11_NS,OCSPResponse); + REGISTER_ELEMENT(XMLSIG11_NS,PublicKey); + REGISTER_ELEMENT(XMLSIG11_NS,X509Digest); REGISTER_TYPE(XMLSIG11_NS,DEREncodedKeyValue); + REGISTER_TYPE(XMLSIG11_NS,ECKeyValue); REGISTER_TYPE(XMLSIG11_NS,KeyInfoReference); + REGISTER_TYPE(XMLSIG11_NS,NamedCurve); + REGISTER_TYPE(XMLSIG11_NS,X509Digest); }