Partial addition of 1.1 KeyInfo extensions.
[shibboleth/xmltooling.git] / xmltooling / signature / impl / KeyInfoSchemaValidators.cpp
1 /*
2 *  Copyright 2001-2010 Internet2
3  * 
4 * Licensed under the Apache License, Version 2.0 (the "License");
5  * you may not use this file except in compliance with the License.
6  * You may obtain a copy of the License at
7  *
8  *     http://www.apache.org/licenses/LICENSE-2.0
9  *
10  * Unless required by applicable law or agreed to in writing, software
11  * distributed under the License is distributed on an "AS IS" BASIS,
12  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13  * See the License for the specific language governing permissions and
14  * limitations under the License.
15  */
16
17 /**
18  * KeyInfoSchemaValidators.cpp
19  * 
20  * Schema validators for KeyInfo schema.
21  */
22
23 #include "internal.h"
24 #include "exceptions.h"
25 #include "signature/KeyInfo.h"
26 #include "validation/Validator.h"
27 #include "validation/ValidatorSuite.h"
28
29 using namespace xmlsignature;
30 using namespace xmltooling;
31 using namespace std;
32 using xmlconstants::XMLSIG_NS;
33 using xmlconstants::XMLSIG11_NS;
34
35 namespace xmlsignature {
36
37     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,KeyName);
38     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,MgmtData);
39     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,Modulus);
40     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,Exponent);
41     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,Seed);
42     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,PgenCounter);
43     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,P);
44     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,Q);
45     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,G);
46     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,Y);
47     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,J);
48     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,XPath);
49     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,X509IssuerName);
50     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,X509SerialNumber);
51     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,X509SKI);
52     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,X509SubjectName);
53     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,X509Certificate);
54     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,X509CRL);
55     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,OCSPResponse);
56     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,SPKISexp);
57     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,PGPKeyID);
58     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,PGPKeyPacket);
59     XMLOBJECTVALIDATOR_SIMPLE(XMLTOOL_DLLLOCAL,DEREncodedKeyValue);
60     
61     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,RSAKeyValue);
62         XMLOBJECTVALIDATOR_REQUIRE(RSAKeyValue,Modulus);
63         XMLOBJECTVALIDATOR_REQUIRE(RSAKeyValue,Exponent);
64     END_XMLOBJECTVALIDATOR;
65
66     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,DSAKeyValue);
67         XMLOBJECTVALIDATOR_REQUIRE(DSAKeyValue,Y);
68         XMLOBJECTVALIDATOR_NONEORBOTH(DSKeyValue,P,Q);
69         XMLOBJECTVALIDATOR_NONEORBOTH(DSKeyValue,Seed,PgenCounter);
70     END_XMLOBJECTVALIDATOR;
71
72     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,KeyValue);
73         XMLOBJECTVALIDATOR_ONLYONEOF3(KeyValue,DSAKeyValue,RSAKeyValue,UnknownXMLObject);
74     END_XMLOBJECTVALIDATOR;
75
76     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,Transform);
77         XMLOBJECTVALIDATOR_REQUIRE(Transform,Algorithm);
78     END_XMLOBJECTVALIDATOR;
79
80     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,Transforms);
81         XMLOBJECTVALIDATOR_NONEMPTY(Transforms,Transform);
82     END_XMLOBJECTVALIDATOR;
83
84     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,RetrievalMethod);
85         XMLOBJECTVALIDATOR_REQUIRE(RetrievalMethod,URI);
86     END_XMLOBJECTVALIDATOR;
87
88     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,X509IssuerSerial);
89         XMLOBJECTVALIDATOR_REQUIRE(X509IssuerSerial,X509IssuerName);
90         XMLOBJECTVALIDATOR_REQUIRE(X509IssuerSerial,X509SerialNumber);
91     END_XMLOBJECTVALIDATOR;
92
93     class XMLTOOL_DLLLOCAL checkWildcardNS {
94     public:
95         void operator()(const XMLObject* xmlObject) const {
96             const XMLCh* ns=xmlObject->getElementQName().getNamespaceURI();
97             if (XMLString::equals(ns,XMLSIG_NS) || !ns || !*ns) {
98                 throw ValidationException(
99                     "Object contains an illegal extension child element ($1).",
100                     params(1,xmlObject->getElementQName().toString().c_str())
101                     );
102             }
103         }
104     };
105     
106     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,X509Data);
107         if (!ptr->hasChildren())
108             throw ValidationException("X509Data must have at least one child element.");
109         const vector<XMLObject*>& anys=ptr->getUnknownXMLObjects();
110         for_each(anys.begin(),anys.end(),checkWildcardNS());
111     END_XMLOBJECTVALIDATOR;
112
113     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,SPKIData);
114         XMLOBJECTVALIDATOR_NONEMPTY(SPKIData,SPKISexp);
115     END_XMLOBJECTVALIDATOR;
116
117     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,PGPData);
118         XMLOBJECTVALIDATOR_ONEOF(PGPData,PGPKeyID,PGPKeyPacket);
119     END_XMLOBJECTVALIDATOR;
120
121     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,KeyInfo);
122         if (!ptr->hasChildren())
123             throw ValidationException("KeyInfo must have at least one child element.");
124         const vector<XMLObject*>& anys=ptr->getUnknownXMLObjects();
125         for_each(anys.begin(),anys.end(),checkWildcardNS());
126     END_XMLOBJECTVALIDATOR;
127
128     BEGIN_XMLOBJECTVALIDATOR(XMLTOOL_DLLLOCAL,KeyInfoReference);
129         XMLOBJECTVALIDATOR_REQUIRE(KeyInfoReference,URI);
130     END_XMLOBJECTVALIDATOR;
131
132 };
133
134 #define REGISTER_ELEMENT(namespaceURI,cname) \
135     q=QName(namespaceURI,cname::LOCAL_NAME); \
136     XMLObjectBuilder::registerBuilder(q,new cname##Builder()); \
137     SchemaValidators.registerValidator(q,new cname##SchemaValidator())
138     
139 #define REGISTER_TYPE(namespaceURI,cname) \
140     q=QName(namespaceURI,cname::TYPE_NAME); \
141     XMLObjectBuilder::registerBuilder(q,new cname##Builder()); \
142     SchemaValidators.registerValidator(q,new cname##SchemaValidator())
143
144 void xmlsignature::registerKeyInfoClasses()
145 {
146     QName q;
147     REGISTER_ELEMENT(XMLSIG_NS,KeyInfo);
148     REGISTER_ELEMENT(XMLSIG_NS,KeyName);
149     REGISTER_ELEMENT(XMLSIG_NS,KeyValue);
150     REGISTER_ELEMENT(XMLSIG_NS,MgmtData);
151     REGISTER_ELEMENT(XMLSIG_NS,DSAKeyValue);
152     REGISTER_ELEMENT(XMLSIG_NS,RSAKeyValue);
153     REGISTER_ELEMENT(XMLSIG_NS,Exponent);
154     REGISTER_ELEMENT(XMLSIG_NS,Modulus);
155     REGISTER_ELEMENT(XMLSIG_NS,P);
156     REGISTER_ELEMENT(XMLSIG_NS,Q);
157     REGISTER_ELEMENT(XMLSIG_NS,G);
158     REGISTER_ELEMENT(XMLSIG_NS,Y);
159     REGISTER_ELEMENT(XMLSIG_NS,J);
160     REGISTER_ELEMENT(XMLSIG_NS,Seed);
161     REGISTER_ELEMENT(XMLSIG_NS,PgenCounter);
162     REGISTER_ELEMENT(XMLSIG_NS,XPath);
163     REGISTER_ELEMENT(XMLSIG_NS,Transform);
164     REGISTER_ELEMENT(XMLSIG_NS,Transforms);
165     REGISTER_ELEMENT(XMLSIG_NS,RetrievalMethod);
166     REGISTER_ELEMENT(XMLSIG_NS,X509IssuerSerial);
167     REGISTER_ELEMENT(XMLSIG_NS,X509IssuerName);
168     REGISTER_ELEMENT(XMLSIG_NS,X509SerialNumber);
169     REGISTER_ELEMENT(XMLSIG_NS,X509SKI);
170     REGISTER_ELEMENT(XMLSIG_NS,X509SubjectName);
171     REGISTER_ELEMENT(XMLSIG_NS,X509Certificate);
172     REGISTER_ELEMENT(XMLSIG_NS,X509CRL);
173     REGISTER_ELEMENT(XMLSIG_NS,X509Data);
174     REGISTER_ELEMENT(XMLSIG_NS,SPKISexp);
175     REGISTER_ELEMENT(XMLSIG_NS,SPKIData);
176     REGISTER_ELEMENT(XMLSIG_NS,PGPKeyID);
177     REGISTER_ELEMENT(XMLSIG_NS,PGPKeyPacket);
178     REGISTER_ELEMENT(XMLSIG_NS,PGPData);
179     REGISTER_TYPE(XMLSIG_NS,KeyInfo);
180     REGISTER_TYPE(XMLSIG_NS,KeyValue);
181     REGISTER_TYPE(XMLSIG_NS,DSAKeyValue);
182     REGISTER_TYPE(XMLSIG_NS,RSAKeyValue);
183     REGISTER_TYPE(XMLSIG_NS,Transform);
184     REGISTER_TYPE(XMLSIG_NS,Transforms);
185     REGISTER_TYPE(XMLSIG_NS,RetrievalMethod);
186     REGISTER_TYPE(XMLSIG_NS,X509IssuerSerial);
187     REGISTER_TYPE(XMLSIG_NS,X509Data);
188     REGISTER_TYPE(XMLSIG_NS,SPKIData);
189     REGISTER_TYPE(XMLSIG_NS,PGPData);
190
191     REGISTER_ELEMENT(XMLSIG11_NS,OCSPResponse);
192     REGISTER_ELEMENT(XMLSIG11_NS,DEREncodedKeyValue);
193     REGISTER_ELEMENT(XMLSIG11_NS,KeyInfoReference);
194     REGISTER_TYPE(XMLSIG11_NS,DEREncodedKeyValue);
195     REGISTER_TYPE(XMLSIG11_NS,KeyInfoReference);
196 }